CVE-2026-75601
Static Web Server: Authentication bypass on /metrics endpoint when --basic-auth is enabled
CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th
Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. Through 2.43.0, instances with both basic-auth and metrics features enabled process the /metrics endpoint before the basic-auth check in src/handler.rs, allowing an unauthenticated remote attacker to retrieve Prometheus metrics that disclose virtual host names, request volumes, error rates, latency distributions, and active connections. This issue is fixed in version 2.44.0.
| CWE | CWE-306 |
| Vendor | static-web-server |
| Product | static-web-server |
| Published | Aug 26, 2026 |
Stay Ahead of the Next One
Get instant alerts for static-web-server static-web-server
Be the first to know when new medium vulnerabilities affecting static-web-server static-web-server are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Affected Versions
static-web-server / static-web-server
< 2.44.0