{"id":"CVE-2026-78378","summary":"Redis Glob Pattern Injection Allows Unauthorized Enumeration of Private Ransomlook Data","details":"Ransomlook contains a Redis glob pattern injection vulnerability caused by insufficient neutralization of user-controlled input before it is incorporated into Redis SCAN MATCH patterns.\n\n\nThe /api/health/\u003cname\u003e endpoint attempted to resolve the supplied name to a known group or market, but when resolution failed it fell back to using the attacker-controlled value directly in a Redis key pattern. An unauthenticated attacker could therefore supply Redis glob metacharacters such as *, ?, [ or ] to broaden the SCAN operation beyond the intended group. For example, requesting /api/health/* could enumerate health information, mirror slugs, and uptime series belonging to all groups and markets, including entities marked as private.\n\n\nSimilar unsafe interpolation was present in /api/crypto/chain/\u003cchain\u003e and in the delete_manual_torrent() function. The latter represents a potentially destructive sink because a crafted infohash containing glob metacharacters could cause the scan to match torrent-health keys belonging to other torrents if attacker-controlled input can reach that function.\n\n\nThe patch removes the unsafe fallback from the health endpoint and introduces glob escaping for user-controlled values before they are incorporated into Redis SCAN MATCH expressions.","modified":"2026-08-28T11:30:55.946350249Z","published":"2026-08-24T13:19:02.108Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/78xxx/CVE-2026-78378.json","cna_assigner":"CIRCL","cwe_ids":["CWE-200"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/78xxx/CVE-2026-78378.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-78378"},{"type":"FIX","url":"https://github.com/RansomLook/RansomLook/commit/1f14c01b6fdf8d534edfb2790cf76f5bac6e73f8."},{"type":"PACKAGE","url":"https://github.com/RansomLook/RansomLook"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ransomlook/ransomlook","events":[{"introduced":"0"},{"last_affected":"ac648c1b3882c6c3c1a17b9e80c7d0a831646f62"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"2.0.0"}],"source":"AFFECTED_FIELD"}}],"versions":["2.0.0","1.9.0","1.8.0","1.6.0","1.5.0","1.4.0","1.3.0","1.2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-78378.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}]}