A vulnerability in SpiceJet’s booking API allows...
High severity
Unreviewed
Published
Apr 23, 2026
to the GitHub Advisory Database
•
Updated Apr 23, 2026
Description
Published by the National Vulnerability Database
Apr 23, 2026
Published to the GitHub Advisory Database
Apr 23, 2026
Last updated
Apr 23, 2026
A vulnerability in SpiceJet’s booking API allows unauthenticated users to query passenger name records (PNRs) without any access controls. Because PNR identifiers follow a predictable pattern, an attacker could systematically enumerate valid records and obtain associated passenger names. This flaw stems from missing authorization checks on an endpoint intended for authenticated profile access.
References