GoCD is a continuous deliver server. From 18.7.0 until 26.1.0, the Get Template Config API compares HTTP method names case-sensitively when selecting authorization filters. A lower-privileged authenticated user can send a request with nonstandard HTTP method c
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-52741 | 7.5 HIGH | GoCD has stored XSS possible via tracking tool link highlighting on Compare Pipeline pages |
| CVE-2026-68919 | 7.0 HIGH | GoCD has stored XSS possible via forged package material comments on Stage/Job/VSM pages |
| CVE-2026-52742 | 5.1 MEDIUM | GoCD is vulnerable to historical server configuration API authorization bypass |
| CVE-2026-55625 | 4.9 MEDIUM | GoCD is vulnerable to authorization bypass via material connection test APIs |
| CVE-2026-52743 | 4.3 MEDIUM | GoCD before 26.1.0 is vulnerable to authorization bypass via job status API |
| CVE-2026-55060 | 3.7 LOW | GoCD is vulnerable to authorization bypass via support process list API |
| CVE-2026-55870 | 2.3 LOW | GoCD is vulnerable to credential exposure when admins insecurely configure material URLs |
No comments yet