CVE-2026-26069

Source
https://cve.org/CVERecord?id=CVE-2026-26069
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-26069.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-26069
Aliases
  • GHSA-hx24-222f-w5cj
Published
2026-02-12T21:33:47.845Z
Modified
2026-04-10T05:42:15.883436Z
Severity
  • 9.1 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:L CVSS Calculator
Summary
Scraparr Readarr Integration exposes sensitive values as metric labels.
Details

Scraparr is a Prometheus Exporter for various components of the *arr Suite. From 3.0.0-beta to before 3.0.2, when the Readarr integration was enabled, the exporter exposed the configured Readarr API key as the alias metric label value. Users were affected only if all of the following conditions are met, Readarr scraping feature was enabled and no alias configured, the exporter’s /metrics endpoint was accessible to external or unauthorized users, and the Readarr instance is externally accessible. If the /metrics endpoint was publicly accessible, the Readarr API key could have been disclosed via exported metrics data. This vulnerability is fixed in 3.0.2.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/26xxx/CVE-2026-26069.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-200"
    ]
}
References

Affected packages

Git / github.com/thecfu/scraparr

Affected ranges

Type
GIT
Repo
https://github.com/thecfu/scraparr
Events

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-26069.json"