CVE-2026-82641: keploy 3.1.0 through 3.6.25 exposes an unauthenticated agent control plane that streams TLS session keys
NVD·medium signal
Published to NVD on 2026-08-30 at 8.6 HIGH. The keploy agent binds its control-plane HTTP server to all interfaces with no authentication, and /agent/pcap/keylog returns NSS keylog lines that let anyone on the network decrypt recorded TLS traffic. The same surface exposes /agent/stop and /agent/storemocks for manipulating recording sessions. This is the second bind-to-0.0.0.0-with-no-auth agent CVE in three days after argocd-mcp's 10.0.