OpenBao是OpenBao开源的一个敏感数据管理软件。 OpenBao 2.5.3之前版本存在SQL注入漏洞,该漏洞源于在PostgreSQL数据库密钥引擎中撤销角色权限时,未对模式名称使用正确的数据库引用,可能导致角色撤销失败或SQL注入攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-39396 | 3.1 LOW | OpenBao has Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS) |
| CVE-2026-39388 | OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate | |
| CVE-2026-40264 | OpenBao's Token Store Allows Cross-Namespace Renewal, Revocation |
No comments yet