Server-Side Event Exposure in Algernon Web Server by xyproto
CVE-2026-46430

4.3MEDIUM

Key Information:

Vendor

Xyproto

Status
Vendor
CVE Published:
26 May 2026

What is CVE-2026-46430?

The Algernon web server, developed by xyproto, is vulnerable prior to version 1.17.7 due to its default configuration that binds the SSE event server to all network interfaces (0.0.0.0:5553) on Linux and macOS. This setup allows unauthorized users to potentially access event streams, leading to information disclosure. The issue arises from the way host defaults are set in the code, which needs adjustment to improve security. Users are advised to upgrade to version 1.17.7 or later to mitigate this exposure.

Affected Version(s)

algernon < 1.17.7

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.