Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 31 Aug 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 30 Aug 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Chatgptnextweb
Chatgptnextweb nextchat |
|
| Vendors & Products |
Chatgptnextweb
Chatgptnextweb nextchat |
Sun, 30 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy endpoint that allows attackers to obtain the server's OpenAI API key. The x-base-url header is validated using substring matching instead of hostname parsing, allowing any URL containing 'api.openai.com' to pass validation and receive the server's credentials in the Authorization header. | |
| Title | NextChat 2.15.8 through 2.16.1 OpenAI API Key Disclosure | |
| First Time appeared |
Nextchat
Nextchat nextchat |
|
| Weaknesses | CWE-20 | |
| CPEs | cpe:2.3:a:nextchat:nextchat:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nextchat
Nextchat nextchat |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-31T16:51:17.973Z
Reserved: 2026-08-30T13:06:02.366Z
Link: CVE-2026-82639
Updated: 2026-08-31T16:50:36.617Z
Status : Deferred
Published: 2026-08-30T14:17:03.750
Modified: 2026-09-10T15:53:23.707
Link: CVE-2026-82639
No data.
OpenCVE Enrichment
Updated: 2026-08-30T17:15:04Z