Vulnerability GO-2026-6619
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
6 hours ago
October 01, 2026 at 08:24 PM UTC
Portainer CE allows username enumeration through authentication response timing in github.com/portainer/portainer
v0.6.0
v0.6.0
Summary
Portainer CE allows username enumeration through authentication response timing in github.com/portainer/portainer
Details
Portainer CE allows username enumeration through authentication response timing in github.com/portainer/portainer
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
29 days ago
Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances in github.com/portainer/portainer
v0.6.0 - v0.10.1 GO-2026-6324
v0.6.0 - v0.10.1 GO-2026-6324
Medium Risk
1 month ago
Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances
>=2.39.0 <2.39.4, >=2.40.0 <2.43.0 GHSA-x626-fcwx-f5pc
>=2.39.0 <2.39.4, >=2.40.0 <2.43.0 GHSA-x626-fcwx-f5pc
Unknown
2 months ago
Portainer has a path traversal in backup archive extraction that allows arbitrary file write in github.com/portainer/portainer
v0.6.0 - v0.10.1 GO-2026-5498
v0.6.0 - v0.10.1 GO-2026-5498
Unknown
3 months ago
Portainer Has an Arbitrary File Read via Git Symlink Injection in Stack Auto-Update in github.com/portainer/portainer
v0.6.0 - v0.10.1 GO-2026-5633
v0.6.0 - v0.10.1 GO-2026-5633
Unknown
3 months ago
Portainer missing authorization on Docker plugin endpoints, which allows host RCE in github.com/portainer/portainer
v0.6.0 - v0.10.1 GO-2026-5639
v0.6.0 - v0.10.1 GO-2026-5639
Impacted packages
Timeline
Published
6 hours ago
October 01, 2026 at 08:24 PM UTC
Last Modified
6 hours ago
October 01, 2026 at 08:45 PM UTC