CVE Explorer
CVE-2026-32309
Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.1, the Hub-based unlock flow explicitly supports hub+http and consumes Hub endpoints from vault metadata without enforcing HTTPS. As a result, a vault configuration can drive OAuth and key-loading traffic over plaintext HTTP or other insecure endpoint combinations. An active network attacker can tamper with or observe this traffic. Even when the vault key is encrypted for the device, bearer tokens and endpoint-
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"cryptomator","vendor":"cryptomator","versions":[{"status":"affected","version":"< 1.19.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:6307ab96b4dd77c4e26f65993db37527b3cfa8bf5197a20adc10ae9936bdf686 · sha256:2fd6d3ded36652a3… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.7,"baseSeverity":"HIGH","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"PASSIVE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"LOW","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:6307ab96b4dd77c4e26f65993db37527b3cfa8bf5197a20adc10ae9936bdf686 · sha256:2fd6d3ded36652a3… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-319","description":"CWE-319: Cleartext Transmission of Sensitive Information","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:6307ab96b4dd77c4e26f65993db37527b3cfa8bf5197a20adc10ae9936bdf686 · sha256:2fd6d3ded36652a3… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/cryptomator/cryptomator/releases/tag/1.19.1","tags":["x_refsource_MISC"],"url":"https://github.com/cryptomator/cryptomator/releases/tag/1.19.1"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6307ab96b4dd77c4e26f65993db37527b3cfa8bf5197a20adc10ae9936bdf686 · sha256:2fd6d3ded36652a3… · /containers/cna/references/1
{"name":"https://github.com/cryptomator/cryptomator/security/advisories/GHSA-vv33-h7qx-c264","tags":["x_refsource_CONFIRM"],"url":"https://github.com/cryptomator/cryptomator/security/advisories/GHSA-vv33-h7qx-c264"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6307ab96b4dd77c4e26f65993db37527b3cfa8bf5197a20adc10ae9936bdf686 · sha256:2fd6d3ded36652a3… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.