FreeTAKServer
An open source server for the TAK family of applications.
Activity
- Latest release
- 2y ago
- Total releases
- 114
- Cadence
- ~6 days
- Last 12 months
- 0
Details
- License
- EPL-2.0
- First release
- Jun 17, 2020
| Version | Released | |
|---|---|---|
2.2.1
patch
|
2.2.1
patch
Dependencies (50)
+ 42 more |
|
2.2.0.1
patch
|
2.2.0.1
patch
Dependencies (50)
+ 42 more |
|
2.2
minor
|
2.2
minor
Dependencies (50)
+ 42 more |
|
2.1.4.5
patch
|
2.1.4.5
patch
Dependencies (50)
+ 42 more |
|
2.1.3
patch
|
2.1.3
patch
Dependencies (50)
+ 42 more |
|
2.1.2
patch
|
2.1.2
patch
Dependencies (50)
+ 42 more |
|
2.1.1
patch
|
2.1.1
patch
Dependencies (50)
+ 42 more |
|
2.1
minor
|
2.1
minor
Dependencies (50)
+ 42 more |
|
0.2.1a1
pre
2 CVEs
CVE-2022-25508
GHSA-hggv-mcp4-vxc5
PYSEC-2022-43054
Mar 12, 2022
Improper Authentication in FreeTAKServer
High
Network
Low
None
None
FreeTAKServer is an open source, lightweight Server for connect TAK clients. An access control issue in the component /ManageRoute/postRoute of FreeTAKServer version 1.9.8 allows unauthenticated attackers to cause a Denial of Service (DoS) via an unusually large amount of created routes, or create unsafe or false routes for legitimate users. There is currently no known workaround. This issue was fixed in version 1.9.8.5. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Jun 10, 2026 · Source: OSV.dev
CVE-2022-25510
GHSA-f897-875p-23x7
PYSEC-2022-43135
Mar 12, 2022
Hard coded credentials in FreeTAKServer
High
Network
Low
Low
None
FreeTAKServer 1.9.8 contains a hardcoded Flask secret key which allows attackers to create crafted cookies to bypass authentication or escalate privileges. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Nov 26, 2024 · Source: OSV.dev |
0.2.1a1
pre
Dependencies (48)
+ 40 more |
|
0.2a1
pre
2 CVEs
CVE-2022-25508
GHSA-hggv-mcp4-vxc5
PYSEC-2022-43054
Mar 12, 2022
Improper Authentication in FreeTAKServer
High
Network
Low
None
None
FreeTAKServer is an open source, lightweight Server for connect TAK clients. An access control issue in the component /ManageRoute/postRoute of FreeTAKServer version 1.9.8 allows unauthenticated attackers to cause a Denial of Service (DoS) via an unusually large amount of created routes, or create unsafe or false routes for legitimate users. There is currently no known workaround. This issue was fixed in version 1.9.8.5. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Jun 10, 2026 · Source: OSV.dev
CVE-2022-25510
GHSA-f897-875p-23x7
PYSEC-2022-43135
Mar 12, 2022
Hard coded credentials in FreeTAKServer
High
Network
Low
Low
None
FreeTAKServer 1.9.8 contains a hardcoded Flask secret key which allows attackers to create crafted cookies to bypass authentication or escalate privileges. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Nov 26, 2024 · Source: OSV.dev |
0.2a1
pre
Dependencies (48)
+ 40 more |
|
0.2.1.2
patch
2 CVEs
CVE-2022-25508
GHSA-hggv-mcp4-vxc5
PYSEC-2022-43054
Mar 12, 2022
Improper Authentication in FreeTAKServer
High
Network
Low
None
None
FreeTAKServer is an open source, lightweight Server for connect TAK clients. An access control issue in the component /ManageRoute/postRoute of FreeTAKServer version 1.9.8 allows unauthenticated attackers to cause a Denial of Service (DoS) via an unusually large amount of created routes, or create unsafe or false routes for legitimate users. There is currently no known workaround. This issue was fixed in version 1.9.8.5. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Jun 10, 2026 · Source: OSV.dev
CVE-2022-25510
GHSA-f897-875p-23x7
PYSEC-2022-43135
Mar 12, 2022
Hard coded credentials in FreeTAKServer
High
Network
Low
Low
None
FreeTAKServer 1.9.8 contains a hardcoded Flask secret key which allows attackers to create crafted cookies to bypass authentication or escalate privileges. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Nov 26, 2024 · Source: OSV.dev |
0.2.1.2
patch
Dependencies (48)
+ 40 more |
|
0.2.1.1
patch
2 CVEs
CVE-2022-25508
GHSA-hggv-mcp4-vxc5
PYSEC-2022-43054
Mar 12, 2022
Improper Authentication in FreeTAKServer
High
Network
Low
None
None
FreeTAKServer is an open source, lightweight Server for connect TAK clients. An access control issue in the component /ManageRoute/postRoute of FreeTAKServer version 1.9.8 allows unauthenticated attackers to cause a Denial of Service (DoS) via an unusually large amount of created routes, or create unsafe or false routes for legitimate users. There is currently no known workaround. This issue was fixed in version 1.9.8.5. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Jun 10, 2026 · Source: OSV.dev
CVE-2022-25510
GHSA-f897-875p-23x7
PYSEC-2022-43135
Mar 12, 2022
Hard coded credentials in FreeTAKServer
High
Network
Low
Low
None
FreeTAKServer 1.9.8 contains a hardcoded Flask secret key which allows attackers to create crafted cookies to bypass authentication or escalate privileges. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Nov 26, 2024 · Source: OSV.dev |
0.2.1.1
patch
Dependencies (48)
+ 40 more |
|
0.2.1.0
patch
2 CVEs
CVE-2022-25508
GHSA-hggv-mcp4-vxc5
PYSEC-2022-43054
Mar 12, 2022
Improper Authentication in FreeTAKServer
High
Network
Low
None
None
FreeTAKServer is an open source, lightweight Server for connect TAK clients. An access control issue in the component /ManageRoute/postRoute of FreeTAKServer version 1.9.8 allows unauthenticated attackers to cause a Denial of Service (DoS) via an unusually large amount of created routes, or create unsafe or false routes for legitimate users. There is currently no known workaround. This issue was fixed in version 1.9.8.5. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Jun 10, 2026 · Source: OSV.dev
CVE-2022-25510
GHSA-f897-875p-23x7
PYSEC-2022-43135
Mar 12, 2022
Hard coded credentials in FreeTAKServer
High
Network
Low
Low
None
FreeTAKServer 1.9.8 contains a hardcoded Flask secret key which allows attackers to create crafted cookies to bypass authentication or escalate privileges. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Nov 26, 2024 · Source: OSV.dev |
0.2.1.0
patch
Dependencies (44)
+ 36 more |
|
2.0.69
patch
|
2.0.69
patch
Dependencies (48)
+ 40 more |
|
2.0.66
patch
|
2.0.66
patch
Dependencies (48)
+ 40 more |
|
2.0.21
major
|
2.0.21
major
Dependencies (48)
+ 40 more |
|
0.2.0.17b0
pre
2 CVEs
CVE-2022-25508
GHSA-hggv-mcp4-vxc5
PYSEC-2022-43054
Mar 12, 2022
Improper Authentication in FreeTAKServer
High
Network
Low
None
None
FreeTAKServer is an open source, lightweight Server for connect TAK clients. An access control issue in the component /ManageRoute/postRoute of FreeTAKServer version 1.9.8 allows unauthenticated attackers to cause a Denial of Service (DoS) via an unusually large amount of created routes, or create unsafe or false routes for legitimate users. There is currently no known workaround. This issue was fixed in version 1.9.8.5. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Jun 10, 2026 · Source: OSV.dev
CVE-2022-25510
GHSA-f897-875p-23x7
PYSEC-2022-43135
Mar 12, 2022
Hard coded credentials in FreeTAKServer
High
Network
Low
Low
None
FreeTAKServer 1.9.8 contains a hardcoded Flask secret key which allows attackers to create crafted cookies to bypass authentication or escalate privileges. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Nov 26, 2024 · Source: OSV.dev |
0.2.0.17b0
pre
Dependencies (48)
+ 40 more |
|
0.2.0.13
minor
2 CVEs
CVE-2022-25508
GHSA-hggv-mcp4-vxc5
PYSEC-2022-43054
Mar 12, 2022
Improper Authentication in FreeTAKServer
High
Network
Low
None
None
FreeTAKServer is an open source, lightweight Server for connect TAK clients. An access control issue in the component /ManageRoute/postRoute of FreeTAKServer version 1.9.8 allows unauthenticated attackers to cause a Denial of Service (DoS) via an unusually large amount of created routes, or create unsafe or false routes for legitimate users. There is currently no known workaround. This issue was fixed in version 1.9.8.5. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Jun 10, 2026 · Source: OSV.dev
CVE-2022-25510
GHSA-f897-875p-23x7
PYSEC-2022-43135
Mar 12, 2022
Hard coded credentials in FreeTAKServer
High
Network
Low
Low
None
FreeTAKServer 1.9.8 contains a hardcoded Flask secret key which allows attackers to create crafted cookies to bypass authentication or escalate privileges. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Nov 26, 2024 · Source: OSV.dev |
0.2.0.13
minor
Dependencies (48)
+ 40 more |
|
0.2.0.11a0
pre
2 CVEs
CVE-2022-25508
GHSA-hggv-mcp4-vxc5
PYSEC-2022-43054
Mar 12, 2022
Improper Authentication in FreeTAKServer
High
Network
Low
None
None
FreeTAKServer is an open source, lightweight Server for connect TAK clients. An access control issue in the component /ManageRoute/postRoute of FreeTAKServer version 1.9.8 allows unauthenticated attackers to cause a Denial of Service (DoS) via an unusually large amount of created routes, or create unsafe or false routes for legitimate users. There is currently no known workaround. This issue was fixed in version 1.9.8.5. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Jun 10, 2026 · Source: OSV.dev
CVE-2022-25510
GHSA-f897-875p-23x7
PYSEC-2022-43135
Mar 12, 2022
Hard coded credentials in FreeTAKServer
High
Network
Low
Low
None
FreeTAKServer 1.9.8 contains a hardcoded Flask secret key which allows attackers to create crafted cookies to bypass authentication or escalate privileges. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Nov 26, 2024 · Source: OSV.dev |
0.2.0.11a0
pre
Dependencies (48)
+ 40 more |
|
1.9.9.6
patch
|
1.9.9.6
patch
Dependencies (40)
+ 32 more |
|
0.1.9.9.5.5
patch
2 CVEs
CVE-2022-25508
GHSA-hggv-mcp4-vxc5
PYSEC-2022-43054
Mar 12, 2022
Improper Authentication in FreeTAKServer
High
Network
Low
None
None
FreeTAKServer is an open source, lightweight Server for connect TAK clients. An access control issue in the component /ManageRoute/postRoute of FreeTAKServer version 1.9.8 allows unauthenticated attackers to cause a Denial of Service (DoS) via an unusually large amount of created routes, or create unsafe or false routes for legitimate users. There is currently no known workaround. This issue was fixed in version 1.9.8.5. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Jun 10, 2026 · Source: OSV.dev
CVE-2022-25510
GHSA-f897-875p-23x7
PYSEC-2022-43135
Mar 12, 2022
Hard coded credentials in FreeTAKServer
High
Network
Low
Low
None
FreeTAKServer 1.9.8 contains a hardcoded Flask secret key which allows attackers to create crafted cookies to bypass authentication or escalate privileges. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Nov 26, 2024 · Source: OSV.dev |
0.1.9.9.5.5
patch
Dependencies (40)
+ 32 more |
|
1.9.9.5
patch
|
1.9.9.5
patch
Dependencies (40)
+ 32 more |
|
1.9.9.4
patch
|
1.9.9.4
patch
Dependencies (40)
+ 32 more |
|
1.9.9.3
patch
|
1.9.9.3
patch
Dependencies (40)
+ 32 more |
|
1.9.9.2
patch
|
1.9.9.2
patch
Dependencies (40)
+ 32 more |
|
1.9.9.1.0.1
patch
|
1.9.9.1.0.1
patch
Dependencies (38)
+ 30 more |
|
1.9.9.1
patch
|
1.9.9.1
patch
Dependencies (37)
+ 29 more |
|
0.1.9.9.1
patch
2 CVEs
CVE-2022-25508
GHSA-hggv-mcp4-vxc5
PYSEC-2022-43054
Mar 12, 2022
Improper Authentication in FreeTAKServer
High
Network
Low
None
None
FreeTAKServer is an open source, lightweight Server for connect TAK clients. An access control issue in the component /ManageRoute/postRoute of FreeTAKServer version 1.9.8 allows unauthenticated attackers to cause a Denial of Service (DoS) via an unusually large amount of created routes, or create unsafe or false routes for legitimate users. There is currently no known workaround. This issue was fixed in version 1.9.8.5. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Jun 10, 2026 · Source: OSV.dev
CVE-2022-25510
GHSA-f897-875p-23x7
PYSEC-2022-43135
Mar 12, 2022
Hard coded credentials in FreeTAKServer
High
Network
Low
Low
None
FreeTAKServer 1.9.8 contains a hardcoded Flask secret key which allows attackers to create crafted cookies to bypass authentication or escalate privileges. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Nov 26, 2024 · Source: OSV.dev |
0.1.9.9.1
patch
Dependencies (37)
+ 29 more |
|
1.9.9
patch
|
1.9.9
patch
Dependencies (36)
+ 28 more |
|
1.9.8.8
patch
|
1.9.8.8
patch
Dependencies (36)
+ 28 more |
|
1.9.8.7
patch
|
1.9.8.7
patch
Dependencies (36)
+ 28 more |
|
1.9.8.6
patch
|
1.9.8.6
patch
Dependencies (36)
+ 28 more |
|
1.9.8.5
patch
|
1.9.8.5
patch
Dependencies (35)
+ 27 more |
|
0.1.9.8.5
patch
2 CVEs
CVE-2022-25508
GHSA-hggv-mcp4-vxc5
PYSEC-2022-43054
Mar 12, 2022
Improper Authentication in FreeTAKServer
High
Network
Low
None
None
FreeTAKServer is an open source, lightweight Server for connect TAK clients. An access control issue in the component /ManageRoute/postRoute of FreeTAKServer version 1.9.8 allows unauthenticated attackers to cause a Denial of Service (DoS) via an unusually large amount of created routes, or create unsafe or false routes for legitimate users. There is currently no known workaround. This issue was fixed in version 1.9.8.5. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Jun 10, 2026 · Source: OSV.dev
CVE-2022-25510
GHSA-f897-875p-23x7
PYSEC-2022-43135
Mar 12, 2022
Hard coded credentials in FreeTAKServer
High
Network
Low
Low
None
FreeTAKServer 1.9.8 contains a hardcoded Flask secret key which allows attackers to create crafted cookies to bypass authentication or escalate privileges. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Nov 26, 2024 · Source: OSV.dev |
0.1.9.8.5
patch
Dependencies (24)
+ 16 more |
|
1.9.8
patch
2 CVEs
CVE-2022-25508
GHSA-hggv-mcp4-vxc5
PYSEC-2022-43054
Mar 12, 2022
Improper Authentication in FreeTAKServer
High
Network
Low
None
None
FreeTAKServer is an open source, lightweight Server for connect TAK clients. An access control issue in the component /ManageRoute/postRoute of FreeTAKServer version 1.9.8 allows unauthenticated attackers to cause a Denial of Service (DoS) via an unusually large amount of created routes, or create unsafe or false routes for legitimate users. There is currently no known workaround. This issue was fixed in version 1.9.8.5. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Jun 10, 2026 · Source: OSV.dev
CVE-2022-25510
GHSA-f897-875p-23x7
PYSEC-2022-43135
Mar 12, 2022
Hard coded credentials in FreeTAKServer
High
Network
Low
Low
None
FreeTAKServer 1.9.8 contains a hardcoded Flask secret key which allows attackers to create crafted cookies to bypass authentication or escalate privileges. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Nov 26, 2024 · Source: OSV.dev |
1.9.8
patch
Dependencies (24)
+ 16 more |
|
1.9.7
patch
2 CVEs
CVE-2022-25508
GHSA-hggv-mcp4-vxc5
PYSEC-2022-43054
Mar 12, 2022
Improper Authentication in FreeTAKServer
High
Network
Low
None
None
FreeTAKServer is an open source, lightweight Server for connect TAK clients. An access control issue in the component /ManageRoute/postRoute of FreeTAKServer version 1.9.8 allows unauthenticated attackers to cause a Denial of Service (DoS) via an unusually large amount of created routes, or create unsafe or false routes for legitimate users. There is currently no known workaround. This issue was fixed in version 1.9.8.5. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Jun 10, 2026 · Source: OSV.dev
CVE-2022-25510
GHSA-f897-875p-23x7
PYSEC-2022-43135
Mar 12, 2022
Hard coded credentials in FreeTAKServer
High
Network
Low
Low
None
FreeTAKServer 1.9.8 contains a hardcoded Flask secret key which allows attackers to create crafted cookies to bypass authentication or escalate privileges. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Nov 26, 2024 · Source: OSV.dev |
1.9.7
patch
Dependencies (24)
+ 16 more |
|
1.9.6.1
patch
2 CVEs
CVE-2022-25508
GHSA-hggv-mcp4-vxc5
PYSEC-2022-43054
Mar 12, 2022
Improper Authentication in FreeTAKServer
High
Network
Low
None
None
FreeTAKServer is an open source, lightweight Server for connect TAK clients. An access control issue in the component /ManageRoute/postRoute of FreeTAKServer version 1.9.8 allows unauthenticated attackers to cause a Denial of Service (DoS) via an unusually large amount of created routes, or create unsafe or false routes for legitimate users. There is currently no known workaround. This issue was fixed in version 1.9.8.5. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Jun 10, 2026 · Source: OSV.dev
CVE-2022-25510
GHSA-f897-875p-23x7
PYSEC-2022-43135
Mar 12, 2022
Hard coded credentials in FreeTAKServer
High
Network
Low
Low
None
FreeTAKServer 1.9.8 contains a hardcoded Flask secret key which allows attackers to create crafted cookies to bypass authentication or escalate privileges. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Nov 26, 2024 · Source: OSV.dev |
1.9.6.1
patch
Dependencies (23)
+ 15 more |
|
1.9.6
patch
2 CVEs
CVE-2022-25508
GHSA-hggv-mcp4-vxc5
PYSEC-2022-43054
Mar 12, 2022
Improper Authentication in FreeTAKServer
High
Network
Low
None
None
FreeTAKServer is an open source, lightweight Server for connect TAK clients. An access control issue in the component /ManageRoute/postRoute of FreeTAKServer version 1.9.8 allows unauthenticated attackers to cause a Denial of Service (DoS) via an unusually large amount of created routes, or create unsafe or false routes for legitimate users. There is currently no known workaround. This issue was fixed in version 1.9.8.5. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Jun 10, 2026 · Source: OSV.dev
CVE-2022-25510
GHSA-f897-875p-23x7
PYSEC-2022-43135
Mar 12, 2022
Hard coded credentials in FreeTAKServer
High
Network
Low
Low
None
FreeTAKServer 1.9.8 contains a hardcoded Flask secret key which allows attackers to create crafted cookies to bypass authentication or escalate privileges. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Nov 26, 2024 · Source: OSV.dev |
1.9.6
patch
Dependencies (23)
+ 15 more |
|
1.9.5.1
patch
2 CVEs
CVE-2022-25508
GHSA-hggv-mcp4-vxc5
PYSEC-2022-43054
Mar 12, 2022
Improper Authentication in FreeTAKServer
High
Network
Low
None
None
FreeTAKServer is an open source, lightweight Server for connect TAK clients. An access control issue in the component /ManageRoute/postRoute of FreeTAKServer version 1.9.8 allows unauthenticated attackers to cause a Denial of Service (DoS) via an unusually large amount of created routes, or create unsafe or false routes for legitimate users. There is currently no known workaround. This issue was fixed in version 1.9.8.5. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Jun 10, 2026 · Source: OSV.dev
CVE-2022-25510
GHSA-f897-875p-23x7
PYSEC-2022-43135
Mar 12, 2022
Hard coded credentials in FreeTAKServer
High
Network
Low
Low
None
FreeTAKServer 1.9.8 contains a hardcoded Flask secret key which allows attackers to create crafted cookies to bypass authentication or escalate privileges. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Nov 26, 2024 · Source: OSV.dev |
1.9.5.1
patch
|
|
1.9.5
patch
2 CVEs
CVE-2022-25508
GHSA-hggv-mcp4-vxc5
PYSEC-2022-43054
Mar 12, 2022
Improper Authentication in FreeTAKServer
High
Network
Low
None
None
FreeTAKServer is an open source, lightweight Server for connect TAK clients. An access control issue in the component /ManageRoute/postRoute of FreeTAKServer version 1.9.8 allows unauthenticated attackers to cause a Denial of Service (DoS) via an unusually large amount of created routes, or create unsafe or false routes for legitimate users. There is currently no known workaround. This issue was fixed in version 1.9.8.5. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Jun 10, 2026 · Source: OSV.dev
CVE-2022-25510
GHSA-f897-875p-23x7
PYSEC-2022-43135
Mar 12, 2022
Hard coded credentials in FreeTAKServer
High
Network
Low
Low
None
FreeTAKServer 1.9.8 contains a hardcoded Flask secret key which allows attackers to create crafted cookies to bypass authentication or escalate privileges. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Nov 26, 2024 · Source: OSV.dev |
1.9.5
patch
|
|
0.1.9.5.6
patch
2 CVEs
CVE-2022-25508
GHSA-hggv-mcp4-vxc5
PYSEC-2022-43054
Mar 12, 2022
Improper Authentication in FreeTAKServer
High
Network
Low
None
None
FreeTAKServer is an open source, lightweight Server for connect TAK clients. An access control issue in the component /ManageRoute/postRoute of FreeTAKServer version 1.9.8 allows unauthenticated attackers to cause a Denial of Service (DoS) via an unusually large amount of created routes, or create unsafe or false routes for legitimate users. There is currently no known workaround. This issue was fixed in version 1.9.8.5. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Jun 10, 2026 · Source: OSV.dev
CVE-2022-25510
GHSA-f897-875p-23x7
PYSEC-2022-43135
Mar 12, 2022
Hard coded credentials in FreeTAKServer
High
Network
Low
Low
None
FreeTAKServer 1.9.8 contains a hardcoded Flask secret key which allows attackers to create crafted cookies to bypass authentication or escalate privileges. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Nov 26, 2024 · Source: OSV.dev |
0.1.9.5.6
patch
|
|
1.9.1.5
patch
2 CVEs
CVE-2022-25508
GHSA-hggv-mcp4-vxc5
PYSEC-2022-43054
Mar 12, 2022
Improper Authentication in FreeTAKServer
High
Network
Low
None
None
FreeTAKServer is an open source, lightweight Server for connect TAK clients. An access control issue in the component /ManageRoute/postRoute of FreeTAKServer version 1.9.8 allows unauthenticated attackers to cause a Denial of Service (DoS) via an unusually large amount of created routes, or create unsafe or false routes for legitimate users. There is currently no known workaround. This issue was fixed in version 1.9.8.5. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Jun 10, 2026 · Source: OSV.dev
CVE-2022-25510
GHSA-f897-875p-23x7
PYSEC-2022-43135
Mar 12, 2022
Hard coded credentials in FreeTAKServer
High
Network
Low
Low
None
FreeTAKServer 1.9.8 contains a hardcoded Flask secret key which allows attackers to create crafted cookies to bypass authentication or escalate privileges. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Nov 26, 2024 · Source: OSV.dev |
1.9.1.5
patch
Dependencies (23)
+ 15 more |
|
0.1.9.1.5
patch
2 CVEs
CVE-2022-25508
GHSA-hggv-mcp4-vxc5
PYSEC-2022-43054
Mar 12, 2022
Improper Authentication in FreeTAKServer
High
Network
Low
None
None
FreeTAKServer is an open source, lightweight Server for connect TAK clients. An access control issue in the component /ManageRoute/postRoute of FreeTAKServer version 1.9.8 allows unauthenticated attackers to cause a Denial of Service (DoS) via an unusually large amount of created routes, or create unsafe or false routes for legitimate users. There is currently no known workaround. This issue was fixed in version 1.9.8.5. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Jun 10, 2026 · Source: OSV.dev
CVE-2022-25510
GHSA-f897-875p-23x7
PYSEC-2022-43135
Mar 12, 2022
Hard coded credentials in FreeTAKServer
High
Network
Low
Low
None
FreeTAKServer 1.9.8 contains a hardcoded Flask secret key which allows attackers to create crafted cookies to bypass authentication or escalate privileges. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Nov 26, 2024 · Source: OSV.dev |
0.1.9.1.5
patch
Dependencies (22)
+ 14 more |
|
1.9.1
patch
2 CVEs
CVE-2022-25508
GHSA-hggv-mcp4-vxc5
PYSEC-2022-43054
Mar 12, 2022
Improper Authentication in FreeTAKServer
High
Network
Low
None
None
FreeTAKServer is an open source, lightweight Server for connect TAK clients. An access control issue in the component /ManageRoute/postRoute of FreeTAKServer version 1.9.8 allows unauthenticated attackers to cause a Denial of Service (DoS) via an unusually large amount of created routes, or create unsafe or false routes for legitimate users. There is currently no known workaround. This issue was fixed in version 1.9.8.5. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Jun 10, 2026 · Source: OSV.dev
CVE-2022-25510
GHSA-f897-875p-23x7
PYSEC-2022-43135
Mar 12, 2022
Hard coded credentials in FreeTAKServer
High
Network
Low
Low
None
FreeTAKServer 1.9.8 contains a hardcoded Flask secret key which allows attackers to create crafted cookies to bypass authentication or escalate privileges. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Nov 26, 2024 · Source: OSV.dev |
1.9.1
patch
Dependencies (22)
+ 14 more |
|
1.9
minor
2 CVEs
CVE-2022-25508
GHSA-hggv-mcp4-vxc5
PYSEC-2022-43054
Mar 12, 2022
Improper Authentication in FreeTAKServer
High
Network
Low
None
None
FreeTAKServer is an open source, lightweight Server for connect TAK clients. An access control issue in the component /ManageRoute/postRoute of FreeTAKServer version 1.9.8 allows unauthenticated attackers to cause a Denial of Service (DoS) via an unusually large amount of created routes, or create unsafe or false routes for legitimate users. There is currently no known workaround. This issue was fixed in version 1.9.8.5. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Jun 10, 2026 · Source: OSV.dev
CVE-2022-25510
GHSA-f897-875p-23x7
PYSEC-2022-43135
Mar 12, 2022
Hard coded credentials in FreeTAKServer
High
Network
Low
Low
None
FreeTAKServer 1.9.8 contains a hardcoded Flask secret key which allows attackers to create crafted cookies to bypass authentication or escalate privileges. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Nov 26, 2024 · Source: OSV.dev |
1.9
minor
Dependencies (22)
+ 14 more |
|
0.1.9.2.5
patch
2 CVEs
CVE-2022-25508
GHSA-hggv-mcp4-vxc5
PYSEC-2022-43054
Mar 12, 2022
Improper Authentication in FreeTAKServer
High
Network
Low
None
None
FreeTAKServer is an open source, lightweight Server for connect TAK clients. An access control issue in the component /ManageRoute/postRoute of FreeTAKServer version 1.9.8 allows unauthenticated attackers to cause a Denial of Service (DoS) via an unusually large amount of created routes, or create unsafe or false routes for legitimate users. There is currently no known workaround. This issue was fixed in version 1.9.8.5. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Jun 10, 2026 · Source: OSV.dev
CVE-2022-25510
GHSA-f897-875p-23x7
PYSEC-2022-43135
Mar 12, 2022
Hard coded credentials in FreeTAKServer
High
Network
Low
Low
None
FreeTAKServer 1.9.8 contains a hardcoded Flask secret key which allows attackers to create crafted cookies to bypass authentication or escalate privileges. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Nov 26, 2024 · Source: OSV.dev |
0.1.9.2.5
patch
|
|
0.1.9.2
patch
2 CVEs
CVE-2022-25508
GHSA-hggv-mcp4-vxc5
PYSEC-2022-43054
Mar 12, 2022
Improper Authentication in FreeTAKServer
High
Network
Low
None
None
FreeTAKServer is an open source, lightweight Server for connect TAK clients. An access control issue in the component /ManageRoute/postRoute of FreeTAKServer version 1.9.8 allows unauthenticated attackers to cause a Denial of Service (DoS) via an unusually large amount of created routes, or create unsafe or false routes for legitimate users. There is currently no known workaround. This issue was fixed in version 1.9.8.5. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Jun 10, 2026 · Source: OSV.dev
CVE-2022-25510
GHSA-f897-875p-23x7
PYSEC-2022-43135
Mar 12, 2022
Hard coded credentials in FreeTAKServer
High
Network
Low
Low
None
FreeTAKServer 1.9.8 contains a hardcoded Flask secret key which allows attackers to create crafted cookies to bypass authentication or escalate privileges. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Nov 26, 2024 · Source: OSV.dev |
0.1.9.2
patch
|
|
0.1.9.1
patch
2 CVEs
CVE-2022-25508
GHSA-hggv-mcp4-vxc5
PYSEC-2022-43054
Mar 12, 2022
Improper Authentication in FreeTAKServer
High
Network
Low
None
None
FreeTAKServer is an open source, lightweight Server for connect TAK clients. An access control issue in the component /ManageRoute/postRoute of FreeTAKServer version 1.9.8 allows unauthenticated attackers to cause a Denial of Service (DoS) via an unusually large amount of created routes, or create unsafe or false routes for legitimate users. There is currently no known workaround. This issue was fixed in version 1.9.8.5. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Jun 10, 2026 · Source: OSV.dev
CVE-2022-25510
GHSA-f897-875p-23x7
PYSEC-2022-43135
Mar 12, 2022
Hard coded credentials in FreeTAKServer
High
Network
Low
Low
None
FreeTAKServer 1.9.8 contains a hardcoded Flask secret key which allows attackers to create crafted cookies to bypass authentication or escalate privileges. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Nov 26, 2024 · Source: OSV.dev |
0.1.9.1
patch
|
|
0.1.9
patch
2 CVEs
CVE-2022-25508
GHSA-hggv-mcp4-vxc5
PYSEC-2022-43054
Mar 12, 2022
Improper Authentication in FreeTAKServer
High
Network
Low
None
None
FreeTAKServer is an open source, lightweight Server for connect TAK clients. An access control issue in the component /ManageRoute/postRoute of FreeTAKServer version 1.9.8 allows unauthenticated attackers to cause a Denial of Service (DoS) via an unusually large amount of created routes, or create unsafe or false routes for legitimate users. There is currently no known workaround. This issue was fixed in version 1.9.8.5. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Jun 10, 2026 · Source: OSV.dev
CVE-2022-25510
GHSA-f897-875p-23x7
PYSEC-2022-43135
Mar 12, 2022
Hard coded credentials in FreeTAKServer
High
Network
Low
Low
None
FreeTAKServer 1.9.8 contains a hardcoded Flask secret key which allows attackers to create crafted cookies to bypass authentication or escalate privileges. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Nov 26, 2024 · Source: OSV.dev |
0.1.9
patch
|
|
1.8.1
patch
2 CVEs
CVE-2022-25508
GHSA-hggv-mcp4-vxc5
PYSEC-2022-43054
Mar 12, 2022
Improper Authentication in FreeTAKServer
High
Network
Low
None
None
FreeTAKServer is an open source, lightweight Server for connect TAK clients. An access control issue in the component /ManageRoute/postRoute of FreeTAKServer version 1.9.8 allows unauthenticated attackers to cause a Denial of Service (DoS) via an unusually large amount of created routes, or create unsafe or false routes for legitimate users. There is currently no known workaround. This issue was fixed in version 1.9.8.5. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Jun 10, 2026 · Source: OSV.dev
CVE-2022-25510
GHSA-f897-875p-23x7
PYSEC-2022-43135
Mar 12, 2022
Hard coded credentials in FreeTAKServer
High
Network
Low
Low
None
FreeTAKServer 1.9.8 contains a hardcoded Flask secret key which allows attackers to create crafted cookies to bypass authentication or escalate privileges. Affected versions
0.0.1.5
0.1.0
0.1.1
0.1.1.0.1
0.1.1.0.2
0.1.1.0.3
0.1.2
0.1.3
0.1.3.9.4
0.1.4
0.1.5
0.1.5.1
+ 79 more Show less
0.1.5.2
0.1.5.3
0.1.5.4
0.1.5.5
0.1.5.5.1
0.1.5.5.2
0.1.5.6
0.1.5.7
0.1.5.8
0.1.6
0.1.7.3
0.1.8
0.1.8.1
0.1.9
0.1.9.1
0.1.9.1.5
0.1.9.2
0.1.9.2.5
0.1.9.5.6
0.1.9.8.5
0.1.9.9.1
0.1.9.9.5.5
0.111
0.112
0.2.0.11a0
0.2.0.13
0.2.0.17b0
0.2.1.0
0.2.1.1
0.2.1.2
0.2.1a1
0.2a1
0.8.13
0.8.19
0.8.19.6
0.8.19.6.1
0.8.19.6.2
0.8.19.6.3
0.8.20
0.8.20.1
0.8.21
0.8.22
0.8.23
0.8.50
0.8.50.1
0.8.75
0.8.75.1
0.8.76
0.9.9
0.9.9.1
0.9.9.2
1.0.3
1.1
1.1.1
1.1.2
1.2
1.2.0.1
1.2.0.2
1.2.5
1.3
1.3.0.5
1.3.0.6
1.5.10
1.5.10.1
1.5.10.2
1.5.12
1.7.1
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.1.5
1.9.5
1.9.5.1
1.9.6
1.9.6.1
1.9.7
1.9.8
Fixed in
1.9.8.5
References Updated Nov 26, 2024 · Source: OSV.dev |
1.8.1
patch
Dependencies (20)
+ 12 more |