{"schema_version":1,"title":"Xyproto Algernon vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 9 vulnerabilities in Xyproto Algernon: 0 in the last 7 days and 1 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-52792, was published on 2 July 2026.","url":"https://junglewise.ai/threats/technologies/algernon","json_url":"https://junglewise.ai/threats/technologies/algernon.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/algernon","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":3,"all_time":9,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":1,"last_365_days":9},"latest":[{"cve":"CVE-2026-52792","cvss":4,"epss":0.0063,"slug":"cve-2026-52792-xyproto-algernon-source-disclosure-via-ntfs-filename-manipulation","title":"xyproto Algernon source disclosure via NTFS filename manipulation","severity":"high","exploited":false,"published_at":"2026-07-02T20:46:42+00:00","url":"https://junglewise.ai/threats/cve-2026-52792-xyproto-algernon-source-disclosure-via-ntfs-filename-manipulation"},{"cve":"CVE-2026-48126","cvss":8.2,"epss":0.005,"slug":"cve-2026-48126-xyproto-algernon-path-traversal-and-rce-via-host-header","title":"xyproto Algernon path traversal and RCE via Host header","severity":"high","exploited":false,"published_at":"2026-05-26T17:16:53.36+00:00","url":"https://junglewise.ai/threats/cve-2026-48126-xyproto-algernon-path-traversal-and-rce-via-host-header"},{"cve":"CVE-2026-46431","cvss":4.3,"epss":0.0031,"slug":"cve-2026-46431-xyproto-algernon-permissive-cors-policy-in-sse-event-server","title":"xyproto Algernon permissive CORS policy in SSE event server","severity":"medium","exploited":false,"published_at":"2026-05-26T17:16:51.1+00:00","url":"https://junglewise.ai/threats/cve-2026-46431-xyproto-algernon-permissive-cors-policy-in-sse-event-server"},{"cve":"CVE-2026-45728","cvss":7.5,"epss":0.0042,"slug":"cve-2026-45728-xyproto-algernon-information-disclosure-in-single-file-mode","title":"xyproto Algernon information disclosure in single-file mode","severity":"high","exploited":false,"published_at":"2026-05-26T17:16:47.9+00:00","url":"https://junglewise.ai/threats/cve-2026-45728-xyproto-algernon-information-disclosure-in-single-file-mode"},{"cve":"CVE-2026-45721","cvss":9,"epss":0.0074,"slug":"cve-2026-45721-xyproto-algernon-remote-code-execution-via-handler-lua-path","title":"xyproto Algernon remote code execution via handler.lua path traversal","severity":"critical","exploited":false,"published_at":"2026-05-26T17:16:47.75+00:00","url":"https://junglewise.ai/threats/cve-2026-45721-xyproto-algernon-remote-code-execution-via-handler-lua-path"},{"cve":"CVE-2026-43982","cvss":8.7,"slug":"cve-2026-43982-xyproto-algernon-path-traversal-in-uploadedfilesavein","title":"xyproto Algernon path traversal in uploadedFileSaveIn","severity":"info","exploited":false,"published_at":"2026-05-26T17:16:46.107+00:00","url":"https://junglewise.ai/threats/cve-2026-43982-xyproto-algernon-path-traversal-in-uploadedfilesavein"},{"cve":"CVE-2026-43981","cvss":8.2,"slug":"cve-2026-43981-xyproto-algernon-race-condition-in-lua-handler","title":"xyproto Algernon race condition in Lua handler","severity":"info","exploited":false,"published_at":"2026-05-26T17:16:45.95+00:00","url":"https://junglewise.ai/threats/cve-2026-43981-xyproto-algernon-race-condition-in-lua-handler"},{"cve":"CVE-2026-46430","cvss":4.3,"epss":0.0023,"slug":"cve-2026-46430-xyproto-algernon-insecure-default-bind-address-in-sse-server","title":"xyproto Algernon insecure default bind address in SSE server","severity":"medium","exploited":false,"published_at":"2026-05-20T15:33:56+00:00","url":"https://junglewise.ai/threats/cve-2026-46430-xyproto-algernon-insecure-default-bind-address-in-sse-server"},{"cvss":5.3,"slug":"xyproto-algernon-missing-authentication-in-auto-refresh-sse-server-2a3e2f07","title":"Xyproto Algernon missing authentication in auto-refresh SSE server","severity":"medium","exploited":false,"published_at":"2026-05-19T14:36:34+00:00","url":"https://junglewise.ai/threats/xyproto-algernon-missing-authentication-in-auto-refresh-sse-server-2a3e2f07"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[],"technology":{"hub":true,"name":"Xyproto Algernon","slug":"algernon","vendor":{"name":"Xyproto","slug":"xyproto","url":"https://junglewise.ai/threats/vendors/xyproto"},"aliases":[],"category":"web-server","homepage":"https://algernon.roboticoverlords.org/","repo_url":"https://github.com/xyproto/algernon","description":"A HTTP/2 web server with built-in support for Lua, Markdown, SASS, and QUIC.","url":"https://junglewise.ai/threats/technologies/algernon"},"most_severe":[{"cve":"CVE-2026-45721","cvss":9,"epss":0.0074,"slug":"cve-2026-45721-xyproto-algernon-remote-code-execution-via-handler-lua-path","title":"xyproto Algernon remote code execution via handler.lua path traversal","severity":"critical","exploited":false,"published_at":"2026-05-26T17:16:47.75+00:00","url":"https://junglewise.ai/threats/cve-2026-45721-xyproto-algernon-remote-code-execution-via-handler-lua-path"},{"cve":"CVE-2026-48126","cvss":8.2,"epss":0.005,"slug":"cve-2026-48126-xyproto-algernon-path-traversal-and-rce-via-host-header","title":"xyproto Algernon path traversal and RCE via Host header","severity":"high","exploited":false,"published_at":"2026-05-26T17:16:53.36+00:00","url":"https://junglewise.ai/threats/cve-2026-48126-xyproto-algernon-path-traversal-and-rce-via-host-header"},{"cve":"CVE-2026-45728","cvss":7.5,"epss":0.0042,"slug":"cve-2026-45728-xyproto-algernon-information-disclosure-in-single-file-mode","title":"xyproto Algernon information disclosure in single-file mode","severity":"high","exploited":false,"published_at":"2026-05-26T17:16:47.9+00:00","url":"https://junglewise.ai/threats/cve-2026-45728-xyproto-algernon-information-disclosure-in-single-file-mode"},{"cve":"CVE-2026-52792","cvss":4,"epss":0.0063,"slug":"cve-2026-52792-xyproto-algernon-source-disclosure-via-ntfs-filename-manipulation","title":"xyproto Algernon source disclosure via NTFS filename manipulation","severity":"high","exploited":false,"published_at":"2026-07-02T20:46:42+00:00","url":"https://junglewise.ai/threats/cve-2026-52792-xyproto-algernon-source-disclosure-via-ntfs-filename-manipulation"},{"cvss":5.3,"slug":"xyproto-algernon-missing-authentication-in-auto-refresh-sse-server-2a3e2f07","title":"Xyproto Algernon missing authentication in auto-refresh SSE server","severity":"medium","exploited":false,"published_at":"2026-05-19T14:36:34+00:00","url":"https://junglewise.ai/threats/xyproto-algernon-missing-authentication-in-auto-refresh-sse-server-2a3e2f07"},{"cve":"CVE-2026-46431","cvss":4.3,"epss":0.0031,"slug":"cve-2026-46431-xyproto-algernon-permissive-cors-policy-in-sse-event-server","title":"xyproto Algernon permissive CORS policy in SSE event server","severity":"medium","exploited":false,"published_at":"2026-05-26T17:16:51.1+00:00","url":"https://junglewise.ai/threats/cve-2026-46431-xyproto-algernon-permissive-cors-policy-in-sse-event-server"},{"cve":"CVE-2026-46430","cvss":4.3,"epss":0.0023,"slug":"cve-2026-46430-xyproto-algernon-insecure-default-bind-address-in-sse-server","title":"xyproto Algernon insecure default bind address in SSE server","severity":"medium","exploited":false,"published_at":"2026-05-20T15:33:56+00:00","url":"https://junglewise.ai/threats/cve-2026-46430-xyproto-algernon-insecure-default-bind-address-in-sse-server"},{"cve":"CVE-2026-43982","cvss":8.7,"slug":"cve-2026-43982-xyproto-algernon-path-traversal-in-uploadedfilesavein","title":"xyproto Algernon path traversal in uploadedFileSaveIn","severity":"info","exploited":false,"published_at":"2026-05-26T17:16:46.107+00:00","url":"https://junglewise.ai/threats/cve-2026-43982-xyproto-algernon-path-traversal-in-uploadedfilesavein"},{"cve":"CVE-2026-43981","cvss":8.2,"slug":"cve-2026-43981-xyproto-algernon-race-condition-in-lua-handler","title":"xyproto Algernon race condition in Lua handler","severity":"info","exploited":false,"published_at":"2026-05-26T17:16:45.95+00:00","url":"https://junglewise.ai/threats/cve-2026-43981-xyproto-algernon-race-condition-in-lua-handler"}],"generated_at":"2026-09-26T16:07:00.132667+00:00"}