GlobaLeaks is free and open-source whistleblowing software. Prior to version 5.0.89, the /api/support endpoint of GlobaLeaks performs minimal validation on user-submitted support requests. As a result, arbitrary URLs can be included in support emails sent to administrators. Version 5.0.89 patches the issue.
Metrics
Affected Vendors & Products
References
History
Fri, 27 Mar 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GlobaLeaks is free and open-source whistleblowing software. Prior to version 5.0.89, the /api/support endpoint of GlobaLeaks performs minimal validation on user-submitted support requests. As a result, arbitrary URLs can be included in support emails sent to administrators. Version 5.0.89 patches the issue. | |
| Title | GlobalLeaks has insufficient URL validation in user support API | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-27T13:58:54.085Z
Reserved: 2026-03-18T18:55:47.425Z
Link: CVE-2026-33284
No data.
Status : Received
Published: 2026-03-27T15:16:54.643
Modified: 2026-03-27T15:16:54.643
Link: CVE-2026-33284
No data.
OpenCVE Enrichment
No data.