← All CVEs NewScan detects
medium

CVE-2026-19898

vmauth authentication-endpoint brute force (requestHandler)

Severity
medium
Affected product
vmauth
Affected versions
vmauth ≤ 1.146.0
Fixed in
vmauth 1.147.0
Added to NewScan
2026-08-16
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints vmauth from its response and reports this CVE when the detected version falls inside the affected range below.

Added 2026-08-23 with the vmauth fingerprint (tech_signatures body row reading the vmauth- build stamp off /metrics - measured against v1.150.0 on loopback, i.e. the patched side). The row D130 was filed for: CVE-2026-19898 is a bug in the vmauth PROXY binary, and keying it under 'VictoriaMetrics' would have flagged single-node storage installs for a proxy bug they do not run - hence the separate product key and its own fingerprint. CVSS is reported as 3.7 (Strix/cve.org) and 6.3 (OpenCVE/Snyk); medium is the honest middle. Affected up to 1.146.0, fixed 1.147.0 - same version series the tags-v capture reads. vmagent/vmalert/vminsert/vmselect still have no fingerprints (backlog, same entry).

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →