CVE-2026-22820mediumCWE-367

CVE-2026-22820: medium-severity vulnerability in akinloluwami outray

Outray cli is vulnerable to race conditions in tunnels creation

Published

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.3epss 0.2%
exploitation probability
0.2%top 91% of all CVEs
observed exploitation
nono source reports it
Outray openSource ngrok alternative. Prior to 0.1.5, a TOCTOU race condition vulnerability allows a user to exceed the set number of active tunnels in their subscription plan. This vulnerability is fixed in 0.1.5.
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Affected products
akinloluwami · outray
Related CVEs — akinloluwami outray

In the same product, most dangerous first.