PatchDay Alert

CVE

CVE-2026-42864

0field notes · 1digest CVSS 9.9


Daily digests

FireFighter's Jira bot endpoint is wide open: no authentication despite what the docstring claims. An unauthenticated attacker who can reach the ingress can make the pod fetch any URL they choose, then read the response back as a Jira attachment. On EC2/EKS clusters that haven't enforced IMDSv2, this is a straight path to stealing the pod's AWS IAM credentials.

Get the digest

Free. Weekday mornings. Plain English CVE triage.

Check your inbox to confirm.