CVE-2026-55882: Tilt: Unauthenticated pprof debug endpoints on the Tilt HUD server
The Tilt HUD server mounts Go’s net/http/pprof handlers under /debug with no access control. When the HUD is network-exposed, an attacker can read process memory — including session and apiserver tokens — and hold the process under profiling.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-55882 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →