Vulnerability GO-2026-6106
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
1 month ago
August 18, 2026 at 02:32 PM UTC
Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests in github.com/cloudreve/Cloudreve
>=0.0.0
>=0.0.0
Summary
Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests in github.com/cloudreve/Cloudreve
Details
Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests in github.com/cloudreve/Cloudreve
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
5 days ago
Cloudreve: SSRF guard bypass: checkIP does not decode IPv6-transition wrappers (NAT64, IPv4-compatible, 6to4) reaching internal and cloud-metadata addresses
<4.0.0-20260715072853-1c5cad6dec7e GHSA-jvh5-97xg-v99f
<4.0.0-20260715072853-1c5cad6dec7e GHSA-jvh5-97xg-v99f
Low Risk
5 days ago
Cloudreve: Privilege Scope Bypass: State-Mutating Admin Operations Accessible via Read-Only OAuth Scope
<4.0.0-20260715070110-bce08f88e9d8 GHSA-w89x-c962-c44g
<4.0.0-20260715070110-bce08f88e9d8 GHSA-w89x-c962-c44g
High Risk
5 days ago
Cloudreve: Storage-quota TOCTOU race allows quota bypass and storage-based denial of service
<4.0.0-20260715025621-7329602751c0 GHSA-xj3h-wwxq-gfcj
<4.0.0-20260715025621-7329602751c0 GHSA-xj3h-wwxq-gfcj
Unknown
1 month ago
Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root in github.com/cloudreve/Cloudreve
v3.0.0-20250225100611-da4e44b77af4 GO-2026-6298
v3.0.0-20250225100611-da4e44b77af4 GO-2026-6298
Unknown
1 month ago
Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root in github.com/cloudreve/Cloudreve
v3.0.0-20250225100611-da4e44b77af4 GO-2026-6298
v3.0.0-20250225100611-da4e44b77af4 GO-2026-6298
Impacted packages
Timeline
Published
1 month ago
August 18, 2026 at 02:32 PM UTC
Last Modified
7 hours ago
September 28, 2026 at 03:55 AM UTC