Attackers Probe Vite Servers 32,000 Times via CVE-2026-39364 for Cloud Credentials
Updated
Updated · InfoWorld · Sep 15
Attackers Probe Vite Servers 32,000 Times via CVE-2026-39364 for Cloud Credentials
3 articles · Updated · InfoWorld · Sep 15
Summary
F5 logged more than 32,000 scan attempts in August across 807 attack sessions targeting exposed Vite servers for environment files, cloud tokens and infrastructure state data.
CVE-2026-39364, rated CVSS 8.2, lets unauthenticated attackers bypass Vite’s file-access deny list by appending parameters such as ?raw, causing sensitive files to be returned with HTTP 200 responses.
Double-encoded path traversal in some requests suggested efforts to slip past reverse proxies and WAFs, while exposed servers were often reachable through --host settings, container port mappings or other deployment mistakes.
Vulnerable versions include Vite 7.1.0 through before 7.3.2 and Vite 8 before 8.0.5; F5 urged patching, rotating secrets and auditing Docker, Kubernetes and cloud exposure.
The campaign also tested older Vite flaws and a Next.js middleware bypass, pointing to broader framework-focused scanning even as older bugs like PHPUnit’s CVE-2017-9841 still drew more attacks on F5 honeypots.
Why are attackers using Google Cloud to quietly drain secrets from exposed Vite servers, and could your project be next?
Are modern frontend tools prioritizing developer convenience over security, leaving your infrastructure completely defenseless against automated scanning botnets?