CVE-2026-15542: Will-Moss Isaiah

High severity, CVSS 7.3. EPSS: 0.7% chance of exploitation in the next 30 days.

A vulnerability has been found in will-moss Isaiah up to 1.36.9. This affects an unknown function of the file app/main.go of the component Websocket Connection Authentication. The manipulation leads to improper authentication. The attack can be initiated remotely. The pull request to fix this issue awaits acceptance.

Affected products

  • Will-Moss Isaiah: version 1.36.0 only; version 1.36.1 only; version 1.36.2 only; version 1.36.3 only; version 1.36.4 only; version 1.36.5 only; …

Published 2026-07-13. Last modified 2026-07-15.