๐Ÿ” CVE Alert

CVE-2026-75608

HIGH 7.7

Frigate: Viewer-Role User Can Access go2rtc Internal API to obtain sensitive information

CVSS Score
7.7
EPSS Score
0.0%
EPSS Percentile
0th

Frigate is an open source network video recorder. Prior to 0.18.0, the prefix-matched location /api/go2rtc/api in docker/main/rootfs/usr/local/nginx/conf/nginx.conf requires authentication but does not require an administrator role for GET requests, exposing the proxied go2rtc API to viewer users. An authenticated viewer can request the streams, config, log, and stack subpaths to obtain internal addresses, configuration paths, application logs, goroutine stack data, and RTSP stream URLs that may contain camera credentials. Non-GET methods remain blocked by limit_except GET. This issue is fixed in version 0.18.0.

CWE CWE-863
Vendor blakeblackshear
Product frigate
Published Sep 22, 2026
Stay Ahead of the Next One

Get instant alerts for blakeblackshear frigate

Be the first to know when new high vulnerabilities affecting blakeblackshear frigate are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

blakeblackshear / frigate
< 0.18.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/blakeblackshear/frigate/security/advisories/GHSA-mgh5-cr9h-g6hr github.com: https://github.com/blakeblackshear/frigate/pull/22735 github.com: https://github.com/blakeblackshear/frigate/commit/520d9eeb7f0fe46021f29fb8169741dd1d429271 github.com: https://github.com/blakeblackshear/frigate/releases/tag/v0.18.0