oban_web
🧭 Oban Web live dashboard
Activity
- Latest release
- 2w ago
- Total releases
- 17
- Cadence
- ~23 days
- Last 12 months
- 12
Reach
- Stars
- 184
Details
- License
- Apache-2.0
- First release
- Jan 16, 2025
| Version | Released | |
|---|---|---|
2.12.7
patch
| ||
2.12.6
patch
| ||
2.12.5
patch
| ||
2.12.4
patch
2 CVEs
CVE-2026-48592
GHSA-389x-rgxr-8m33
EEF-CVE-2026-48592
Jun 30, 2026
oban_web missing authorization check on `save-job` event handler
Medium
Network
Low
Low
None
Summary
DetailsIn The The attacker is constrained to substituting an existing PoC
ImpactCVSS 4.0 score 5.3 (Medium). Any application running References
Affected versions
2.12.0
2.12.1
2.12.2
2.12.3
2.12.4
Fixed in
2.12.5
References
Updated Jun 30, 2026 · Source: OSV.dev
CVE-2026-48593
GHSA-6xh2-93p9-vqh4
EEF-CVE-2026-48593
Jun 30, 2026
oban_web: Unbounded range expansion in cron describe causes memory exhaustion
Medium
Network
Low
Low
Summary
Details1. Scheduling: The attacker submits a cron job with a malicious expression such as 2. Parsing: When the cron list is rendered in the dashboard, 3. Eager expansion: PoC
ImpactCVSS 4.0 score 5.9 (Medium). Affects References
Affected versions
2.12.0
2.12.1
2.12.2
2.12.3
2.12.4
Fixed in
2.12.5
References
Updated Jun 30, 2026 · Source: OSV.dev | ||
2.12.3
patch
2 CVEs
CVE-2026-48592
GHSA-389x-rgxr-8m33
EEF-CVE-2026-48592
Jun 30, 2026
oban_web missing authorization check on `save-job` event handler
Medium
Network
Low
Low
None
Summary
DetailsIn The The attacker is constrained to substituting an existing PoC
ImpactCVSS 4.0 score 5.3 (Medium). Any application running References
Affected versions
2.12.0
2.12.1
2.12.2
2.12.3
2.12.4
Fixed in
2.12.5
References
Updated Jun 30, 2026 · Source: OSV.dev
CVE-2026-48593
GHSA-6xh2-93p9-vqh4
EEF-CVE-2026-48593
Jun 30, 2026
oban_web: Unbounded range expansion in cron describe causes memory exhaustion
Medium
Network
Low
Low
Summary
Details1. Scheduling: The attacker submits a cron job with a malicious expression such as 2. Parsing: When the cron list is rendered in the dashboard, 3. Eager expansion: PoC
ImpactCVSS 4.0 score 5.9 (Medium). Affects References
Affected versions
2.12.0
2.12.1
2.12.2
2.12.3
2.12.4
Fixed in
2.12.5
References
Updated Jun 30, 2026 · Source: OSV.dev | ||
2.12.2
patch
2 CVEs
CVE-2026-48592
GHSA-389x-rgxr-8m33
EEF-CVE-2026-48592
Jun 30, 2026
oban_web missing authorization check on `save-job` event handler
Medium
Network
Low
Low
None
Summary
DetailsIn The The attacker is constrained to substituting an existing PoC
ImpactCVSS 4.0 score 5.3 (Medium). Any application running References
Affected versions
2.12.0
2.12.1
2.12.2
2.12.3
2.12.4
Fixed in
2.12.5
References
Updated Jun 30, 2026 · Source: OSV.dev
CVE-2026-48593
GHSA-6xh2-93p9-vqh4
EEF-CVE-2026-48593
Jun 30, 2026
oban_web: Unbounded range expansion in cron describe causes memory exhaustion
Medium
Network
Low
Low
Summary
Details1. Scheduling: The attacker submits a cron job with a malicious expression such as 2. Parsing: When the cron list is rendered in the dashboard, 3. Eager expansion: PoC
ImpactCVSS 4.0 score 5.9 (Medium). Affects References
Affected versions
2.12.0
2.12.1
2.12.2
2.12.3
2.12.4
Fixed in
2.12.5
References
Updated Jun 30, 2026 · Source: OSV.dev | ||
2.12.1
patch
2 CVEs
CVE-2026-48592
GHSA-389x-rgxr-8m33
EEF-CVE-2026-48592
Jun 30, 2026
oban_web missing authorization check on `save-job` event handler
Medium
Network
Low
Low
None
Summary
DetailsIn The The attacker is constrained to substituting an existing PoC
ImpactCVSS 4.0 score 5.3 (Medium). Any application running References
Affected versions
2.12.0
2.12.1
2.12.2
2.12.3
2.12.4
Fixed in
2.12.5
References
Updated Jun 30, 2026 · Source: OSV.dev
CVE-2026-48593
GHSA-6xh2-93p9-vqh4
EEF-CVE-2026-48593
Jun 30, 2026
oban_web: Unbounded range expansion in cron describe causes memory exhaustion
Medium
Network
Low
Low
Summary
Details1. Scheduling: The attacker submits a cron job with a malicious expression such as 2. Parsing: When the cron list is rendered in the dashboard, 3. Eager expansion: PoC
ImpactCVSS 4.0 score 5.9 (Medium). Affects References
Affected versions
2.12.0
2.12.1
2.12.2
2.12.3
2.12.4
Fixed in
2.12.5
References
Updated Jun 30, 2026 · Source: OSV.dev | ||
2.12.0
minor
2 CVEs
CVE-2026-48592
GHSA-389x-rgxr-8m33
EEF-CVE-2026-48592
Jun 30, 2026
oban_web missing authorization check on `save-job` event handler
Medium
Network
Low
Low
None
Summary
DetailsIn The The attacker is constrained to substituting an existing PoC
ImpactCVSS 4.0 score 5.3 (Medium). Any application running References
Affected versions
2.12.0
2.12.1
2.12.2
2.12.3
2.12.4
Fixed in
2.12.5
References
Updated Jun 30, 2026 · Source: OSV.dev
CVE-2026-48593
GHSA-6xh2-93p9-vqh4
EEF-CVE-2026-48593
Jun 30, 2026
oban_web: Unbounded range expansion in cron describe causes memory exhaustion
Medium
Network
Low
Low
Summary
Details1. Scheduling: The attacker submits a cron job with a malicious expression such as 2. Parsing: When the cron list is rendered in the dashboard, 3. Eager expansion: PoC
ImpactCVSS 4.0 score 5.9 (Medium). Affects References
Affected versions
2.12.0
2.12.1
2.12.2
2.12.3
2.12.4
Fixed in
2.12.5
References
Updated Jun 30, 2026 · Source: OSV.dev | ||
2.11.8
patch
| ||
2.11.7
patch
| ||
2.11.6
patch
| ||
2.11.5
patch
| ||
2.11.4
patch
| ||
2.11.3
patch
| ||
2.11.2
patch
| ||
2.11.1
patch
| ||
2.11.0
initial
|