Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 14 Jul 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kidocode
Kidocode crawl4ai |
|
| CPEs | cpe:2.3:a:kidocode:crawl4ai:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Kidocode
Kidocode crawl4ai |
Tue, 23 Jun 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Crawl4ai
Crawl4ai crawl4ai |
|
| Vendors & Products |
Crawl4ai
Crawl4ai crawl4ai |
Mon, 22 Jun 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 21 Jun 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server. Attackers who know the default key can forge valid authentication tokens for any user, bypassing authentication and gaining full access to protected functionality. | |
| Title | Crawl4AI - Authentication Bypass via Hardcoded JWT Signing Key | |
| Weaknesses | CWE-798 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-07-14T21:34:12.797Z
Reserved: 2026-06-20T01:42:20.615Z
Link: CVE-2026-56265
Updated: 2026-06-22T10:43:04.969Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-23T21:03:49Z