CVE-2026-49357: Insecure Hardcoded Bind To All Interfaces
Hardcoding the server to bind to '0.0.0.0' or '::' unconditionally exposes it to all available network interfaces. For local integrations or automated desktop tools lacking uniform authentication, this allows any device on the network to connect, potentially leading to unauthorized data access or remote command execution. Ensure the bind address is configura
greprules fetch cve-2026-49357-insecure-hardcoded-bind-to-all-interfaces --engine opengrepDescription
Hardcoding the server to bind to '0.0.0.0' or '::' unconditionally exposes it to all available network interfaces. For local integrations or automated desktop tools lacking uniform authentication, this allows any device on the network to connect, potentially leading to unauthorized data access or remote command execution. Ensure the bind address is configura
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.