GHSA-vhh6-v828-x62f

Suggest an improvement
Source
https://github.com/advisories/GHSA-vhh6-v828-x62f
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-vhh6-v828-x62f/GHSA-vhh6-v828-x62f.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-vhh6-v828-x62f
Aliases
  • CVE-2026-58230
Published
2026-08-11T03:31:56Z
Modified
2026-09-01T21:40:52Z
Severity
  • 7.0 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L CVSS Calculator
Summary
SAP Approuter has an Information Disclosure vulnerability
Details

SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated attacker could send a specially crafted token to cause sensitive credential material to be sent to an attacker-controlled destination. The attack complexity is high due to non-default preconditions required in the target environment. This results in a high impact on confidentiality and a low impact on integrity and availability.

Database specific
{
    "cwe_ids": [
        "CWE-601"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-09-01T21:20:40Z",
    "nvd_published_at": "2026-08-11T01:17:21Z",
    "severity": "HIGH"
}
References

Affected packages

npm / @sap/approuter

Package

Name
@sap/approuter
View open source insights on deps.dev
Purl
pkg:npm/%40sap/approuter

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
23.0.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-vhh6-v828-x62f/GHSA-vhh6-v828-x62f.json"