{"id":"CVE-2026-82641","summary":"keploy 3.1.0 through 3.6.25 Unauthenticated TLS Key Exposure","details":"keploy versions 3.1.0 through 3.6.25 bind the agent control-plane HTTP server to all interfaces without authentication, exposing endpoints that stream TLS session keys and traffic data. Attackers can access the /agent/pcap/keylog endpoint to retrieve NSS keylog lines and decrypt recorded TLS traffic, or invoke /agent/stop and /agent/storemocks to manipulate recording sessions.","modified":"2026-09-02T03:30:46.189150432Z","published":"2026-08-30T13:23:40.516Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-306"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82641.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82641.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-82641"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/keploy-3.1.0-through-3.6.25-unauthenticated-tls-key-exposure"},{"type":"REPORT","url":"https://github.com/keploy/keploy/issues/4394"},{"type":"FIX","url":"https://github.com/keploy/keploy/commit/a6257d2b3184b85eb30edad345464aa292297b83"},{"type":"PACKAGE","url":"https://github.com/keploy/keploy"},{"type":"ARTICLE","url":"https://github.com/keploy/keploy/blob/v3.6.25/pkg/agent/routes/server.go"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/keploy/keploy","events":[{"introduced":"7beb63ece4ca44b78bab0850f2836dd2738f9a9d"},{"fixed":"054136bf818fb02cfb671341324b5e2b6ae82308"},{"fixed":"a6257d2b3184b85eb30edad345464aa292297b83"}],"database_specific":{"source":["DESCRIPTION","REFERENCES"],"extracted_events":[{"introduced":"3.1.0"},{"fixed":"3.6.25"}]}}],"versions":["v3.6.25","v3.6.24","v3.6.23","v3.6.22","v3.6.21","v3.6.20","v3.6.19","v3.6.18","v3.6.17","v3.6.16","v3.6.15","v3.6.14","v3.6.13","v3.6.12","v3.6.11","v3.6.10","v3.6.9","v3.6.8","v3.6.7","v3.6.6","v3.6.5","v3.6.4","v3.6.3","v3.6.2","v3.6.1","v3.6.0","v3.5.99","v3.5.98","v3.5.97","v3.5.96","v3.5.95","v3.5.94","v3.5.93","v3.5.90","v3.5.92","v3.5.91","v3.5.89","v3.5.88","v3.5.87","v3.5.86","v3.5.85","v3.5.84","v3.5.83","v3.5.82","v3.5.63","v3.5.81","v3.5.80","v3.5.79","v3.5.78","v3.5.77","v3.5.76","v3.5.75","v3.5.74","v3.5.73","v3.5.72","v3.5.71","v3.5.70","v3.5.69","v3.5.68","v3.5.67","v3.5.66","v3.5.65","v3.5.64","v3.5.62","v3.5.61","v3.5.60","v3.5.59","v3.5.58","v3.5.57","v3.5.56","v3.5.55","v3.5.54","v3.5.51","v3.5.53","v3.5.52","v3.5.50","v3.5.47","v3.5.49","v3.5.48","v3.5.37","v3.5.46","v3.5.45","v3.5.44","v3.5.43","v3.5.42","v3.5.41","v3.5.40","v3.5.39","v3.5.38","v3.5.36","v3.5.35","v3.5.34","v3.5.33","v3.5.32","v3.5.31","v3.5.30","v3.5.29","v3.5.28","v3.5.27","v3.5.26","v3.5.25","v3.5.24","v3.5.23","v3.5.22","v3.5.21","v3.5.20","v3.5.19","v3.5.18","v3.5.17","v3.5.16","v3.5.15","v3.5.14","v3.5.13","v3.5.12","v3.5.11","v3.5.10","v3.5.9","v3.5.8","v3.5.7","v3.5.6","v3.5.5","v3.5.4","v3.5.3","v3.5.2","v3.5.1","v3.5.0","v3.4.10","v3.4.9","v3.4.8","v3.4.7","v3.4.6","v3.3.72","v3.4.5","v3.4.4","v3.4.3","v3.4.2","v3.4.1","v3.4.0","v3.3.77","v3.3.76","v3.3.75","v3.3.74","v3.3.73","v3.3.70","v3.3.71","v3.3.69","v3.3.68","v3.3.66","v3.3.67","v3.3.65","v3.3.64","v3.3.63","v3.3.62","v3.3.61","v3.3.60","v2.12.8","v3.3.47","v3.3.59","v3.3.58","v3.3.57","v3.3.56","v3.3.55","v3.3.54","v3.3.53","v3.3.52","v3.3.51","v3.3.50","v3.3.49","v3.3.48","v3.3.46","v3.3.45","v3.3.44","v3.3.43","v3.3.42","v3.3.41","v3.3.40","v3.3.34","v3.3.39","v3.3.38","v3.3.37","v3.3.36","v3.3.35","v3.3.33","v3.3.32","v3.3.29","v3.3.31","v3.3.30","v3.3.28","v3.3.27","v3.3.26","v3.3.25","v3.3.24","v3.3.23","v3.3.22","v3.3.21","v3.3.20","v3.3.19","v3.3.18","v3.3.17","v3.3.16","v3.3.15","v3.3.14","v3.3.13","v3.3.12","v3.3.11","v3.3.10","v3.3.9","v3.3.8","v3.3.7","v3.3.6","v3.3.5","v3.3.4","v3.3.3","v3.3.2","v3.3.1","v3.3.0","v3.2.8","v3.2.7","v3.2.6","v3.2.5","v3.2.4","v3.2.3","v3.2.2","v3.2.1","v3.2.0","v3.1.3","v3.1.2","v3.1.1","v3.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82641.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N"}]}