CRITICAL GitHub

CVE-2026-55445

Qinglong has an incomplete fix for CVE-2026-3965: Improper Authentication

### Summary The init guard middleware in Qinglong only checks `/api/user/init` paths but not `/open/user/init`, which is whitelisted from JWT authentication and rewritten to `/api/user/init` after the guard has already passed, allowing unauthenticated admin credential reset on initialized instances. ### Affected Package - **Ecosystem:** npm - **Package:** whyour/qinglong - **Affected versions:** < 6bec52dca158 - **Patched versions:** >= 6bec52dca158 ### Severity Medium ### CWE CWE-287 — I

Affected Products

References

Published: 2026-08-20 · Source: GitHub · Feed updated: 2026-08-20
This critical severity vulnerability was published on 2026-08-20 via GitHub. Affected: npm/@whyour/qinglong < 2.20.1.
vulnfeed aggregates 11796 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.