| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-p5vg-v7mj-f6q4 | Convoy: Cross-Tenant Source IDOR Leaks Plaintext Message Broker Credentials |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sat, 19 Sep 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Frain-dev
Frain-dev convoy |
|
| Vendors & Products |
Frain-dev
Frain-dev convoy |
Fri, 18 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 18 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Convoy is a cloud native webhooks gateway. Prior to 26.6.8, Convoy's GET /api/v1/projects/{projectID}/sources/{sourceID} endpoint authorizes access to the project in the URL, but Handler.GetSource calls sources.Service.FindSourceByID() and fetches the Source only by sourceID without confirming that its ProjectID matches the authorized project. An authenticated user or project-scoped API key holder can substitute another tenant's Source identifier and receive that Source's complete record, including unredacted AMQP, Kafka, SQS, or Google PubSub credentials. The list endpoint remains project-scoped; the single-item Source lookup is affected. This issue is fixed in version 26.6.8. | |
| Title | Convoy: Cross-Tenant Source IDOR Leaks Plaintext Message Broker Credentials | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-18T17:15:48.985Z
Reserved: 2026-08-26T20:58:58.083Z
Link: CVE-2026-81505
Updated: 2026-09-18T17:15:42.701Z
Status : Received
Published: 2026-09-18T17:17:02.103
Modified: 2026-09-18T18:17:16.290
Link: CVE-2026-81505
No data.
OpenCVE Enrichment
Updated: 2026-09-19T22:28:43Z
Github GHSA