CVE-2026-62323
- EPSS 0.31%
- Veröffentlicht 31.07.2026 03:43:14
- Zuletzt bearbeitet 31.07.2026 20:16:53
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, ViewerSessionValidation uses only the session-id prefix of a WOPI access token and does not enforce the requested viewer action, allowing a malicious or compromised WOPI ...
CVE-2026-55502
- EPSS 0.34%
- Veröffentlicht 31.07.2026 03:35:59
- Zuletzt bearbeitet 31.07.2026 11:17:10
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, POST /api/v4/admin/policy/oauth/signin requires only Admin.Read even though GetOauthRedirectService persists caller-supplied OneDrive secret and app_id values, allowing a...
CVE-2026-55499
- EPSS 0.33%
- Veröffentlicht 31.07.2026 03:34:33
- Zuletzt bearbeitet 01.08.2026 00:17:17
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, a single-file share event-stream subscription resolves the share root to the owner’s parent folder and subscribes to that folder topic, allowing an authenticated share re...
CVE-2026-55497
- EPSS 0.53%
- Veröffentlicht 31.07.2026 03:28:59
- Zuletzt bearbeitet 31.07.2026 16:17:07
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the built-in thumbnail and avatar image decoders limit compressed file size but do not limit decoded pixel dimensions, allowing an authenticated user to submit a small PN...
CVE-2026-55496
- EPSS 0.36%
- Veröffentlicht 31.07.2026 03:23:33
- Zuletzt bearbeitet 31.07.2026 14:16:50
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, GET /api/v4/user/search calls SearchActive without adding a StatusActive predicate and serializes matches at RedactLevelUser, allowing any logged-in user to enumerate ema...
CVE-2026-55495
- EPSS 0.38%
- Veröffentlicht 31.07.2026 02:58:14
- Zuletzt bearbeitet 31.07.2026 20:16:52
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the WOPI PUT_RELATIVE handler passes X-WOPI-SuggestedTarget to URI.JoinRaw as a path rather than a filename, allowing slash and dot-dot segments to escape the source file...
CVE-2026-54560
- EPSS 0.25%
- Veröffentlicht 15.07.2026 14:40:24
- Zuletzt bearbeitet 15.07.2026 18:15:13
Cloudreve is a self-hosted file management and sharing system. From 4.12.0 until 4.16.1, Cloudreve's OAuth access tokens are issued without the OAuth client_id claim, so the JWT verifier does not load token scopes into request context and RequiredSco...
CVE-2026-54563
- EPSS 0.19%
- Veröffentlicht 15.07.2026 14:38:54
- Zuletzt bearbeitet 15.07.2026 18:15:13
Cloudreve is a self-hosted file management and sharing system. Prior to 4.16.1, a Cloudreve WebDAV account rooted at a configured folder can send paths such as /dav/%2e%2e/outside.txt because stripPrefix in pkg/webdav/webdav.go joins the decoded requ...
CVE-2026-54562
- EPSS 0.24%
- Veröffentlicht 15.07.2026 14:37:37
- Zuletzt bearbeitet 15.07.2026 18:15:13
Cloudreve is a self-hosted file management and sharing system. Prior to 4.16.1, Cloudreve's remote download workflow accepts user-supplied URLs at POST /api/v4/workflow/download and passes them to the configured downloader without blocking loopback, ...
CVE-2026-25726
- EPSS 0.38%
- Veröffentlicht 03.04.2026 20:06:21
- Zuletzt bearbeitet 24.07.2026 22:10:00
Cloudreve is a self-hosted file management and sharing system. Prior to version 4.13.0, the application uses the weak pseudo-random number generator math/rand seeded with time.Now().UnixNano() to generate critical security secrets, including the secr...