Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 12 May 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 12 May 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download clients like qBittorrent. Prior to 2.9.10, Cleanuparr's global CORS policy reflects every request Origin and combines it with AllowCredentials(). When DisableAuthForLocalAddresses is enabled, the API also authenticates requests purely by source IP via TrustedNetworkAuthenticationHandler. The combination lets any website that an admin (or any user on a trusted IP) visits read authenticated API responses cross-origin — including the admin's permanent API key. This vulnerability is fixed in 2.9.10. | |
| Title | Cleanuparr: Reflective CORS combined with trusted-network auth allows cross-origin admin API reads | |
| Weaknesses | CWE-346 CWE-942 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-12T18:38:28.447Z
Reserved: 2026-05-05T14:39:34.924Z
Link: CVE-2026-44184
Updated: 2026-05-12T18:37:43.949Z
Status : Received
Published: 2026-05-12T18:17:29.583
Modified: 2026-05-12T19:16:33.937
Link: CVE-2026-44184
No data.
OpenCVE Enrichment
Updated: 2026-05-12T19:45:15Z