Salvo

Salvo

4 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.02%
  • Veröffentlicht 23.03.2026 23:41:50
  • Zuletzt bearbeitet 24.03.2026 19:37:58

Salvo is a Rust web framework. Prior to version 0.89.3, Salvo's form data parsing implementations (`form_data()` method and `Extractible` macro) do not enforce payload size limits before reading request bodies into memory. This allows attackers to ca...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 23.03.2026 23:40:39
  • Zuletzt bearbeitet 24.03.2026 19:37:42

Salvo is a Rust web framework. Versions 0.39.0 through 0.89.2 have a Path Traversal and Access Control Bypass vulnerability in the salvo-proxy component. The vulnerability allows an unauthenticated external attacker to bypass proxy routing constraint...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 08.01.2026 18:22:05
  • Zuletzt bearbeitet 05.03.2026 17:42:52

Salvo is a Rust web backend framework. Prior to version 0.88.1, the function list_html generates a file view of a folder without sanitizing the files or folders names, this may potentially lead to XSS in cases where a website allow the access to publ...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 08.01.2026 18:21:57
  • Zuletzt bearbeitet 05.03.2026 17:43:05

Salvo is a Rust web backend framework. Prior to version 0.88.1, the function list_html generate an file view of a folder which include a render of the current path, in which its inserted in the HTML without proper sanitation, this leads to reflected ...