{"id":"GO-2026-6523","summary":"Convoy: Cross-Tenant Source IDOR Leaks Plaintext Message Broker Credentials in github.com/frain-dev/convoy","details":"Convoy: Cross-Tenant Source IDOR Leaks Plaintext Message Broker Credentials in github.com/frain-dev/convoy","aliases":["CVE-2026-81505","GHSA-p5vg-v7mj-f6q4"],"modified":"2026-09-28T17:00:17.495324138Z","published":"2026-09-28T16:43:40Z","database_specific":{"review_status":"UNREVIEWED","url":"https://pkg.go.dev/vuln/GO-2026-6523"},"references":[{"type":"ADVISORY","url":"https://github.com/frain-dev/convoy/security/advisories/GHSA-p5vg-v7mj-f6q4"},{"type":"FIX","url":"https://github.com/frain-dev/convoy/commit/1cc67cd16fb1f8890cc83a3998d3f92dceb7fd06"},{"type":"FIX","url":"https://github.com/frain-dev/convoy/pull/2755"},{"type":"WEB","url":"https://github.com/frain-dev/convoy/releases/tag/v26.6.8"}],"affected":[{"package":{"name":"github.com/frain-dev/convoy","ecosystem":"Go","purl":"pkg:golang/github.com/frain-dev/convoy"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.9.3-0.20260724092134-1cc67cd16fb1"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-6523.json"}}],"schema_version":"1.9.0"}