Server-Side Event Exposure in Algernon Web Server by xyproto
CVE-2026-46430
4.3MEDIUM
What is CVE-2026-46430?
The Algernon web server, developed by xyproto, is vulnerable prior to version 1.17.7 due to its default configuration that binds the SSE event server to all network interfaces (0.0.0.0:5553) on Linux and macOS. This setup allows unauthorized users to potentially access event streams, leading to information disclosure. The issue arises from the way host defaults are set in the code, which needs adjustment to improve security. Users are advised to upgrade to version 1.17.7 or later to mitigate this exposure.
Affected Version(s)
algernon < 1.17.7
