GO-2026-6523

Source
https://pkg.go.dev/vuln/GO-2026-6523
Import Source
https://vuln.go.dev/ID/GO-2026-6523.json
JSON Data
https://api.osv.dev/v1/vulns/GO-2026-6523
Aliases
Published
2026-09-28T16:43:40Z
Modified
2026-09-28T17:00:17Z
Summary
Convoy: Cross-Tenant Source IDOR Leaks Plaintext Message Broker Credentials in github.com/frain-dev/convoy
Details

Convoy: Cross-Tenant Source IDOR Leaks Plaintext Message Broker Credentials in github.com/frain-dev/convoy

Database specific
{
    "review_status":  "UNREVIEWED",
    "url":  "https://pkg.go.dev/vuln/GO-2026-6523"
}
References

Affected packages

Go / github.com/frain-dev/convoy

Package

Name
github.com/frain-dev/convoy
View open source insights on deps.dev
Purl
pkg:golang/github.com/frain-dev/convoy

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.9.3-0.20260724092134-1cc67cd16fb1

Database specific

source
"https://vuln.go.dev/ID/GO-2026-6523.json"