Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-105144— Drogon Static File Router StaticFileRouter.cc route path traversal

Quick assessment

Affected
n/a Drogon
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Windows 系统上的 Drogon(最高版本至 1.9.13-1/10.0-beta.3)中发现了一个漏洞。受影响的是组件“静态文件路由器(Static File Router)”中的 文件里的 函数。该漏洞允许攻击者通过执行某种操纵操作实现路径遍历。攻击可以从远程发起。目前该漏洞的利用代码已被公开,并可被实际使用。厂商在漏洞披露前早期已被联系,但未作出任何回应。

CVSS 5.3 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-105144

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Drogon Static File Router StaticFileRouter.cc route path traversal
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw has been found in Drogon up to 1.9.13-1/10.0-beta.3 on Windows. Affected is the function StaticFileRouter::route of the file lib/src/StaticFileRouter.cc of the component Static File Router. Executing a manipulation can lead to path traversal. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
- Drogon 1.9.13-1 cpe:2.3:a:drogon:drogon:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-105144

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-105144

请登录查看更多情报信息。

Other References for CVE-2026-105144 (3)

IV. Related Vulnerabilities

V. Comments for CVE-2026-105144

No comments yet


Leave a comment