Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.8
CVE-2026-82641: Keploy 3.1.0‑3.6.25 lets anyone grab TLS keys
CVE-2026-82641 · published 4 days ago
Summary
Versions 3.1.0 through 3.6.25 of Keploy run a control‑plane web server that anyone on the network can reach. Through this server an attacker could download the TLS session keys used to encrypt traffic and could also stop or alter recording sessions. Upgrade to a newer Keploy release or block the control‑plane port with a firewall and require authentication.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| keploy | keploy | <= 3.6.25 |
Original advisory text
Keploy versions 3.1.0 through 3.6.25, fixed in 3.6.26, bind the agent control-plane HTTP server to all interfaces without authentication, exposing endpoints that stream TLS session keys and traffic...
Keploy versions 3.1.0 through 3.6.25, fixed in 3.6.26, bind the agent control-plane HTTP server to all interfaces without authentication, exposing endpoints that stream TLS session keys and traffic data. Attackers can access the /agent/pcap/keylog endpoint to retrieve NSS keylog lines and decrypt recorded TLS traffic, or invoke /agent/stop and /agent/storemocks to manipulate recording sessions.
References
- https://github.com/keploy/keploy/issues/4394 issue-tracking
- https://github.com/keploy/keploy product
- https://github.com/keploy/keploy/blob/v3.6.25/pkg/agent/routes/server.go technical-description
- https://github.com/keploy/keploy/commit/a6257d2b3184b85eb30edad345464aa292297b83 patch
- https://www.vulncheck.com/advisories/keploy-3.1.0-through-3.6.25-unauthenticated... third-party-advisory
- https://github.com/keploy/keploy/security/advisories/GHSA-p79c-x224-cv8h vendor-advisory
- https://github.com/keploy/keploy/releases/tag/v3.6.26 release-notes
- https://github.com/keploy/keploy/pull/4451 issue-tracking
Severity
8.8
High
CVSS 3.1: 8.6 (MITRE)
Exploitation
EPSS <1%
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published30 Aug 2026
Updated2 Sep 2026
First seen30 Aug 2026
Monitor software like this
Free during beta