Vulnerability Description
Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.19.5 through 0.37.3, the Tilt HUD server mounts Go net/http/pprof handlers under /debug with no access control. When the HUD or apiserver listener is network-exposed, an unauthenticated caller can read process memory through /debug/pprof/heap and /debug/pprof/goroutine, including session and apiserver tokens, and degrade performance through /debug/pprof/profile or /debug/pprof/trace. This issue is fixed in version 0.37.4.
Related Weaknesses (CWE)
References
- https://github.com/tilt-dev/tilt/commit/47393fba7f6ef5e305d5e814551feef8e4acbc0a
- https://github.com/tilt-dev/tilt/pull/6776
- https://github.com/tilt-dev/tilt/releases/tag/v0.37.4
- https://github.com/tilt-dev/tilt/security/advisories/GHSA-p749-9w62-w533
FAQ
What is CVE-2026-55882?
CVE-2026-55882 is a documented vulnerability. Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.19.5 through 0.37.3, the Tilt HUD server mounts Go net/http/pprof handlers under /debug with no access control. When t...
How severe is CVE-2026-55882?
CVSS scoring is not yet available for CVE-2026-55882. Check NVD for updates.
Is there a patch for CVE-2026-55882?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.