CVE-2026-101056
- EPSS 0.2%
- Veröffentlicht 27.09.2026 17:02:38
- Zuletzt bearbeitet 08.10.2026 16:17:01
Cloudreve before 4.16.1 fails to revalidate share access when restoring cached navigator state from a context_hint UUID. Attackers who previously had valid share access can replay the cached hint to generate signed file URLs for up to 300 seconds aft...
CVE-2026-101051
- EPSS 0.22%
- Veröffentlicht 27.09.2026 17:02:37
- Zuletzt bearbeitet 28.09.2026 15:17:12
Cloudreve before 4.16.1 fails to properly sanitize file paths returned by remote downloaders, allowing authenticated users to create files outside the selected destination directory. Attackers can exploit path traversal sequences in downloader metada...
CVE-2026-101048
- EPSS 0.19%
- Veröffentlicht 27.09.2026 17:02:36
- Zuletzt bearbeitet 08.10.2026 16:17:00
Cloudreve before 4.17.0 registers the administrative node test endpoints (POST /api/v4/admin/node/test and POST /api/v4/admin/node/test/downloader) without requiring the Admin.Write OAuth scope, unlike the node create/update/delete routes. An OAuth c...
CVE-2026-77637
- EPSS 0.33%
- Veröffentlicht 22.09.2026 15:30:59
- Zuletzt bearbeitet 22.09.2026 18:17:19
Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, tool.GET("wopi") and tool.POST("mail") in routers/router.go inherit ScopeAdminRead but omit the RequiredScopes(types.ScopeAdminWrite) middleware applied to neighboring st...
CVE-2026-77633
- EPSS 0.37%
- Veröffentlicht 22.09.2026 15:28:56
- Zuletzt bearbeitet 26.09.2026 00:16:35
Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, PrepareUpload in pkg/filemanager/fs/dbfs/upload.go checks a stale in-memory user storage value through validateUserCapacity and later applies an unconditional storage cha...
CVE-2026-79913
- EPSS 0.4%
- Veröffentlicht 22.09.2026 15:24:33
- Zuletzt bearbeitet 22.09.2026 18:17:19
Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, the ValidateExternalURL server-side request forgery guard in pkg/request/ssrf.go passes resolved addresses to checkIP without decoding NAT64, IPv4-compatible, and 6to4 IP...
CVE-2026-62323
- EPSS 0.31%
- Veröffentlicht 31.07.2026 03:43:14
- Zuletzt bearbeitet 08.09.2026 20:51:43
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, ViewerSessionValidation uses only the session-id prefix of a WOPI access token and does not enforce the requested viewer action, allowing a malicious or compromised WOPI ...
CVE-2026-55502
- EPSS 0.34%
- Veröffentlicht 31.07.2026 03:35:59
- Zuletzt bearbeitet 08.09.2026 20:51:43
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, POST /api/v4/admin/policy/oauth/signin requires only Admin.Read even though GetOauthRedirectService persists caller-supplied OneDrive secret and app_id values, allowing a...
CVE-2026-55499
- EPSS 0.33%
- Veröffentlicht 31.07.2026 03:34:33
- Zuletzt bearbeitet 08.09.2026 20:51:43
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, a single-file share event-stream subscription resolves the share root to the owner’s parent folder and subscribes to that folder topic, allowing an authenticated share re...
CVE-2026-55497
- EPSS 0.53%
- Veröffentlicht 31.07.2026 03:28:59
- Zuletzt bearbeitet 08.09.2026 20:51:43
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the built-in thumbnail and avatar image decoders limit compressed file size but do not limit decoded pixel dimensions, allowing an authenticated user to submit a small PN...