dani-garcia vaultwarden是dani-garcia个人开发者开源的一个密码管理服务。 dani-garcia vaultwarden 1.36.0之前版本存在安全漏洞,该漏洞源于在/src/icons/{domain}/icon.png端点使用的src/http_client.rs检查(包括should_block_address()和post_resolve())中遗漏了对十进制、十六进制和八进制IP表示的校验,允许通过图标获取HTTP客户端进行SSRF攻击,从而导致盲内部网络或端口
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| dani-garcia | vaultwarden | < 1.36.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| dani-garcia | vaultwarden | < 1.36.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-47158 | 8.3 HIGH | Vaultwarden: CSRF in SSO Authorization Flow |
| CVE-2026-47164 | 7.7 HIGH | Vaultwarden: SSO Email Auto-Link Can Bind an Existing Local Account to an Attacker-Control |
| CVE-2026-47159 | Vaultwarden: Authentication Flow Information Disclosure in SSO Discovery Allows Organizati |
No comments yet