CVE-2026-81505

Source
https://cve.org/CVERecord?id=CVE-2026-81505
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-81505.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-81505
Aliases
Published
2026-09-18T16:21:17Z
Modified
2026-09-20T11:47:27Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Convoy: Cross-Tenant Source IDOR Leaks Plaintext Message Broker Credentials
Details

Convoy is a cloud native webhooks gateway. Prior to 26.6.8, Convoy's GET /api/v1/projects/{projectID}/sources/{sourceID} endpoint authorizes access to the project in the URL, but Handler.GetSource calls sources.Service.FindSourceByID() and fetches the Source only by sourceID without confirming that its ProjectID matches the authorized project. An authenticated user or project-scoped API key holder can substitute another tenant's Source identifier and receive that Source's complete record, including unredacted AMQP, Kafka, SQS, or Google PubSub credentials. The list endpoint remains project-scoped; the single-item Source lookup is affected. This issue is fixed in version 26.6.8.

Database specific
{
    "cna_assigner":  "GitHub_M",
    "cwe_ids":  [
        "CWE-639"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/81xxx/CVE-2026-81505.json"
}
References

Affected packages

Git / github.com/frain-dev/convoy

Affected ranges

Type
GIT
Repo
https://github.com/frain-dev/convoy
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "26.6.8"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

Other
release-cutoff-2026-03
release-cutoff-2026-04
release-cutoff-2026-05
release-cutoff-2026-06
v0.*
v0.9.0
v0.9.0-rc.1
v0.9.0-rc.2
v0.9.0-rc.3
v0.9.1
v0.9.2
v23.*
v23.05.1
v23.05.2
v23.05.3
v23.05.4
v23.05.5
v23.06.1
v23.06.2
v23.06.3
v23.08.1
v23.08.2
v23.09.1
v23.10.1
v23.11.1
v23.9.2
v24.*
v24.1.1
v24.1.2
v24.1.3
v24.1.4
v24.1.5
v24.11.1
v24.11.2
v24.11.3
v24.4.1
v24.5.1
v24.6.1
v24.8.1
v24.8.2
v24.9.1
v24.9.2
v25.*
v25.1.1
v25.10.0-alpha.1
v25.10.1-alpha.1
v25.10.1-alpha.2
v25.11.1
v25.11.2
v25.11.3
v25.11.9
v25.12.1
v25.12.10
v25.12.2
v25.12.4
v25.12.5
v25.12.6
v25.12.7
v25.12.8
v25.12.9
v25.2.1
v25.2.2
v25.5.1-hotfix.1
v25.9.1
v25.9.2
v26.*
v26.1.1
v26.1.2
v26.1.3
v26.1.4
v26.2.0
v26.2.1
v26.3.5
v26.3.6
v26.3.7
v26.6.0
v26.6.1
v26.6.2
v26.6.3
v26.6.4
v26.6.5
v26.6.6
v26.6.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-81505.json"