CVE-2026-55884

Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.20.8 through 0.37.3, the Tilt HUD HTTP server registers handlers on a gorilla/mux router with no authenticating middleware. When the HUD is bound to a non-loopback address, an unauthenticated network caller can trigger developer-defined resources, tamper with Tiltfile arguments, read full engine state including the session token, and invoke apiserver resources through the token-attaching /proxy handler. This issue is fixed in version 0.37.4.
CVSS

No CVSS.

Configurations

No configuration.

History

10 Jul 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-10 22:16

Updated : 2026-07-29 20:17


NVD link : CVE-2026-55884

Mitre link : CVE-2026-55884

CVE.ORG link : CVE-2026-55884


JSON object : View

Products Affected

No product.

CWE
CWE-306

Missing Authentication for Critical Function