CVE-2026-63406 | AnyCable up to 1.6.14 Telemetry Subsystem telemetry/config.go generateDigest secret/jwt_secret/http_rpc_secret information disclosure

SecurityVulns

A vulnerability labeled as problematic has been found in AnyCable up to 1.6.14. Affected is the function generateDigest of the file telemetry/config.go of the component Telemetry Subsystem. Such manipulation of the argument secret/jwt_secret/http_rpc_secret leads to information disclosure.

This vulnerability is listed as CVE-2026-63406. The attack may be performed from remote. There is no available exploit.

The affected component should be upgraded.VulDB Recent EntriesRead More