CVE-2026-75601

MEDIUM CVSS 3.1: 4.3 EPSS 0.23%
Updated Sep 10, 2026
Static-Web-Server
Parameter Value
CVSS 4.3 (MEDIUM)
Fixed In 2.44.0
Type CWE-306 (Missing Authentication for Critical Function)
Vendor Static-Web-Server
Public PoC No

Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. Through 2.43.0, instances with both basic-auth and metrics features enabled process the /metrics endpoint before the basic-auth check in src/handler.rs, allowing an unauthenticated remote attacker to retrieve Prometheus metrics that disclose virtual host names, request volumes, error rates, latency distributions, and active connections. This issue is fixed in version 2.44.0.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v3.1

Vulnerable Products

static-web-server:static-web-server