CVE Feed

    Dashboard / CVE / CVE-2026-32810

    CVE-2026-32810

    Halloy is an IRC application written in Rust. In versions on \*nix and macOS prior to commit f180e41061db393acf65bc99f5c5e7397586d9cb, halloy creates its config directory and files using default umask permissions, which typically results in `0644` on files and `0755` on directories. This allows any local user on the system to read plaintext credentials stored in `config.toml` or referenced `password_file` paths. Commit f180e41061db393acf65bc99f5c5e7397586d9cb patches the issue.

    Published:Mar 20, 2026
    Last Modified:Mar 25, 2026
    EPS:Mar 20, 2026
    EPSS Score:0.00009
    CVSS Score:5.5

    Affected Products

    Vendor
    Halloy
    Product
    Halloy
    Vendor
    Squidowl
    Product
    Halloy

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High