Skip to content

CVE lookup

CVE-2026-62382

Pruva has a verified reproduction for CVE-2026-62382: PasswordPusher allows unauthenticated deletion of anonymous pushes due to a nil==nil ownership check that bypasses viewer-deletion restrictions.. The canonical evidence record is REPRO-2026-00328.

REPRO

REPRO-2026-00328

Package

pglombardo/PasswordPusher · Ruby on Rails self-hosted application, also shipped as Docker image pglombardo/pwpush

Severity

MEDIUM

Status

published