CVE-2026-55846 Overview
CVE-2026-55846 is a path traversal vulnerability [CWE-22] in Allure 2, the 2.x branch of the Allure Report multi-language test reporting tool. Versions prior to 2.39.0 expose an HTTP server through the allure serve and allure open commands that fails to normalize request paths. An unauthenticated client that can reach the server can request parent-directory segments and retrieve any regular file readable by the Allure process. This can disclose credentials, configuration, source code, and CI/CD build secrets. The fix ships in version 2.39.0.
Critical Impact
Unauthenticated attackers who reach the local Allure HTTP server can read arbitrary files, including credentials, configuration, source code, and CI/CD secrets accessible to the Allure process.
Affected Products
- Allure 2 (Allure Report) versions prior to 2.39.0
- allure-commandline component, specifically Commands.setUpServer() in allure-commandline/src/main/java/io/qameta/allure/Commands.java
- Deployments running allure serve or allure open, including those bound to non-localhost interfaces via --host
Discovery Timeline
- 2026-09-14 - CVE-2026-55846 published to NVD
- 2026-09-16 - Last updated in NVD database
Technical Details for CVE-2026-55846
Vulnerability Analysis
Allure 2 starts a lightweight HTTP server to serve generated test reports. In Commands.setUpServer(), the server calls URI.getPath() on the incoming request and passes the percent-decoded path directly to reportDirectory.resolve(). The resulting path is handed to serveFile() without normalization and without verifying that it stays within the intended report directory.
Because the decoded path is trusted, an attacker can inject .. segments, including percent-encoded variants such as %2e%2e, to escape the report directory. The server then returns any regular file the Allure process can read. Sensitive targets include SSH keys, cloud credential files, CI runner tokens, and application source code checked out on the same host.
The listener binds to localhost by default, which limits network exposure. However, operators frequently use --host to expose reports across a CI environment, which widens the reachable surface. Even in localhost-only configurations, adjacent containers, other local users, or cross-origin browser requests can reach the endpoint.
Root Cause
The root cause is missing path canonicalization and containment checks. Path.resolve() accepts traversal sequences as-is, and the code omits a subsequent normalize() plus a prefix check against the report directory. This is a textbook instance of [CWE-22] Improper Limitation of a Pathname to a Restricted Directory.
Attack Vector
An attacker sends an HTTP GET request to the Allure listener with a path containing parent-directory traversal, for example a URL-encoded sequence targeting /etc/passwd or a CI secrets file. The server percent-decodes the path, resolves it outside the report directory, and returns the file contents. No authentication is required and no user interaction on the victim host is needed. See the GitHub Security Advisory GHSA-82cg-3hv7-74gc for full technical details.
Detection Methods for CVE-2026-55846
Indicators of Compromise
- HTTP requests to the Allure listener containing .., %2e%2e, or mixed-case percent-encoded traversal sequences in the URI path.
- Access log entries showing successful 200 responses for paths that resolve outside the served report directory.
- Unexpected allure process file reads targeting home directories, /etc, ~/.ssh, cloud credential paths, or CI environment files.
Detection Strategies
- Inspect Allure HTTP access logs for path segments outside the report directory and for encoded traversal patterns.
- Correlate allure serve or allure open process activity with reads of sensitive files using endpoint telemetry.
- Alert on Allure listeners bound to non-loopback interfaces, which indicates --host usage that expands reachable exposure.
Monitoring Recommendations
- Monitor CI/CD hosts and developer workstations for allure processes that open files outside project directories.
- Track outbound HTTP responses from Allure listeners for anomalously large payloads or non-report MIME types.
- Baseline expected client IPs for any Allure listener exposed beyond localhost and alert on deviations.
How to Mitigate CVE-2026-55846
Immediate Actions Required
- Upgrade Allure 2 to version 2.39.0 or later on all developer, tester, and CI/CD systems that run allure serve or allure open.
- Audit CI/CD pipelines and scripts for use of the --host option and restrict listeners to loopback where possible.
- Rotate credentials, tokens, and secrets accessible to any Allure process that was reachable from untrusted networks.
Patch Information
The fix is included in Allure 2 version 2.39.0. Review the Allure Release 2.39.0 notes, the GitHub Pull Request Discussion, and the GitHub Commit Overview for implementation details of the normalization and containment check.
Workarounds
- Do not use --host to expose the Allure server to non-loopback interfaces; keep the listener on 127.0.0.1.
- Run allure serve under a dedicated low-privilege account with access limited to the report directory.
- Place a reverse proxy in front of Allure that rejects request paths containing .. or percent-encoded traversal sequences.
- Terminate allure serve processes immediately after report review rather than leaving them running on shared hosts.
# Configuration example: upgrade and run Allure safely
npm install -g allure-commandline@2.39.0
allure --version
# Bind only to localhost (default) and avoid --host on shared systems
allure serve ./allure-results
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.