CVE-2026-28807 describes a high-severity path traversal vulnerability (CWE-22) in gleam-wisp wisp versions 2.1.1 through 2.2.0, specifically within the `wisp.serve_static` function. This flaw allows an unauthenticated attacker to read arbitrary files on the server, including sensitive data like source code, configuration files, and secrets, by exploiting improper sanitization of percent-encoded path traversal sequences. With a CVSS score of 8.7 (High), the vulnerability requires no authentication or user interaction and has low attack complexity, posing a significant risk to confidentiality. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed on CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.1.1, < 2.2.1CPE match | cpe:2.3:a:gleam-wisp:wisp:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.