CVE-2026-55882EPSS p42.4%
CVE-2026-55882CVE-2026-55882
Description
Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.19.5 through 0.37.3, the Tilt HUD server mounts Go net/http/pprof handlers under /debug with no access control. When the HUD or apiserver listener is network-exposed, an unauthenticated caller can read process memory through /debug/pprof/heap and /debug/pprof/goroutine, including session and apiserver tokens, and degrade performance through /debug/pprof/profile or /debug/pprof/trace. This issue is fixed in version 0.37.4.
Scoring
| EPSS | 0.52% probability of exploitation · percentile 42.4% · 2026-10-05T12:00:23Z |
| Last modified | 2026-07-13 |