Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-441 (未有动机的代理或中间人(混淆代理)) — Vulnerability Class 31

31 vulnerabilities classified as CWE-441 (未有动机的代理或中间人(混淆代理)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-6993 go-kratos http.DefaultServeMux Fallback server.go NewServer confused deputy — kratos 5.3 Medium2026-04-25
CVE-2026-39906 Unisys WebPerfect Image Suite 3.0 NTLMv2 Hash Leakage via .NET Remoting — WebPerfect Image Suite 9.8 -2026-04-14
CVE-2025-62718 Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF — axios 7.4AIHighAI2026-04-09
CVE-2026-27124 FastMCP: Missing Consent Verification in OAuth Proxy Callback Facilitates Confused Deputy Vulnerabilities — fastmcp 9.1AICriticalAI2026-04-03
CVE-2026-33768 Astro: Unauthenticated Path Override via `x-astro-path` / `x_astro_path` — astro 6.5 Medium2026-03-24
CVE-2026-30225 OliveTin: RestartAction always runs actions as guest — OliveTin 5.3 Medium2026-03-06
CVE-2023-31313 AMD Instinct MI210和AMD Instinct MI250 安全漏洞 — AMD Instinct™ MI210 7.2 High2026-02-12
CVE-2026-24471 Improper Validation in Conduit-derived homeservers resulting in Unintended Proxy or Intermediary ('Confused Deputy') — continuwuity 7.1AIHighAI2026-02-02
CVE-2026-24470 Skipper Ingress Controller Allows Unauthorized Access to Internal Services via ExternalName — skipper 8.1 High2026-01-26
CVE-2025-64125 Nuvation Energy nCloud Client-to-Client Communication — nCloud VPN Service 10.0 -2026-01-03
CVE-2025-64123 Nuvation Energy Multi-Stack Controller Proxy service allows arbitrary BMS access — Multi-Stack Controller (MSC) 8.6 -2026-01-02
CVE-2025-68944 Gitea 安全漏洞 — Gitea 5.0 Medium2025-12-26
CVE-2025-11393 Insights-runtimes-tech-preview/runtimes-inventory-rhel8-operator: improper proxy configuration allows unauthorized administrative commands — Red Hat Lightspeed (formerly Insights) for Runtimes 1 8.7 High2025-12-15
CVE-2025-66415 fastify-reply-from bypass of reply forwarding — fastify-reply-from 6.5AIMediumAI2025-12-01
CVE-2025-48710 kro(Kube Resource Orchestrator) 安全漏洞 — kro 4.1 Medium2025-06-04
CVE-2025-47269 code-server session cookie can be extracted by having user visit specially crafted proxy URL — code-server 8.3 High2025-05-09
CVE-2025-25061 JTEKT ELECTRONICS HMI ViewJet C-more 安全漏洞 — HMI ViewJet C-more series 8.2AIHighAI2025-04-04
CVE-2024-9870 Unintended Proxy or Intermediary ('Confused Deputy') in GitLab — GitLab 4.3 Medium2025-02-12
CVE-2023-33188 Uncontrolled data used in content resolution — Omni-Notes 6.3 Medium2023-05-27
CVE-2022-39349 Tasks.org vulnerable to data exfiltration by malicous app or adb — tasks 5.5 Medium2022-10-25
CVE-2015-10003 FileZilla Server PORT confused deputy — Server 4.3 Medium2022-07-17
CVE-2021-20042 SonicWall SMA100 安全漏洞 — SonicWall SMA100 9.3 -2021-12-08
CVE-2021-25740 Holes in EndpointSlice Validation Enable Host Network Hijack — Kubernetes 3.1 Low2021-09-20
CVE-2020-8561 Webhook redirect in kube-apiserver — Kubernetes 4.1 Medium2021-09-20
CVE-2021-32783 Authorization bypass in Contour — contour 8.5 High2021-07-23
CVE-2021-32773 Confused deputy attack in sandbox module resolution — racket 6.1 Medium2021-07-19
CVE-2020-26262 Loopback bypass in Coturn — coturn 7.2 High2021-01-13
CVE-2020-5412 Hystrix Dashboard Proxy In spring-cloud-netflix-hystrix-dashboard — Spring Cloud Netflix 6.5 -2020-08-07
CVE-2019-3996 ELOG 安全漏洞 — ELOG 5.3 -2019-12-17
CVE-2019-1841 Cisco DNA Center Unintended Proxy Via SWIM Import Interface Vulnerability — Cisco Digital Network Architecture Center (DNA Center) 8.1 -2019-04-18

Vulnerabilities classified as CWE-441 (未有动机的代理或中间人(混淆代理)) represent 31 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.