CVE lookup
CVE-2026-62382
Pruva has a verified reproduction for CVE-2026-62382: PasswordPusher allows unauthenticated deletion of anonymous pushes due to a nil==nil ownership check that bypasses viewer-deletion restrictions.. The canonical evidence record is REPRO-2026-00328.
REPRO
REPRO-2026-00328
Package
pglombardo/PasswordPusher · Ruby on Rails self-hosted application, also shipped as Docker image pglombardo/pwpush
Severity
MEDIUM
Status
published