CVE-2026-33284
GlobalLeaks has insufficient URL validation in user support API
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
GlobaLeaks is free and open-source whistleblowing software. Prior to version 5.0.89, the /api/support endpoint of GlobaLeaks performs minimal validation on user-submitted support requests. As a result, arbitrary URLs can be included in support emails sent to administrators. Version 5.0.89 patches the issue.
| CWE | CWE-20 |
| Vendor | globaleaks |
| Product | globaleaks-whistleblowing-software |
| Published | Mar 27, 2026 |
| Last Updated | Mar 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for globaleaks globaleaks-whistleblowing-software
Be the first to know when new unknown vulnerabilities affecting globaleaks globaleaks-whistleblowing-software are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
globaleaks / globaleaks-whistleblowing-software
< 5.0.89