CVE-2026-28807 | gleam-wisp prior 2.2.1 serve_static path traversal (GHSA-h7cj-j2vv-qw8r)
A vulnerability was found in gleam-wisp wisp. It has been classified as critical. The impacted element is the function serve_static. The manipulation leads to path traversal.
This vulnerability is traded as CVE-2026-28807. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.