Nuclio 是一个用于实时事件和数据处理(Real-Time Events and Data Processing)的“无服务器”(Serverless)框架。在 1.16.5 版本之前,Nuclio 的 Java 运行时在构建函数时会生成 文件,其中使用了 Go 语言中的 包。该模板使用 动作来渲染 的值,但并未进行任何转义处理。攻击者可以通过嵌入一个闭合花括号( )来跳出 块,从而添加在 Gradle 配置阶段无条件执行的任意 Groovy 语句。此问题已在 1.16.5 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-79756 | 8.7 HIGH | Nuclio: Unauthenticated OS command injection via namespace header in list-all resource pat |
| CVE-2026-45730 | 8.3 HIGH | Nuclio: Missing authorization on project write paths allows any authenticated user to modi |
| CVE-2026-52831 | 8.0 HIGH | Nuclio: Unsanitized cron trigger event headers/body injected into CronJob shell command le |
| CVE-2026-79755 | 8.0 HIGH | Nuclio: Unauthenticated OS command injection via function namespace in docker ps --filter |
| CVE-2026-79754 | 7.1 HIGH | Nuclio: Kaniko build tempDir command injection |
| CVE-2026-52832 | 4.9 MEDIUM | Nuclio: Unauthenticated path traversal in spec.handler allows arbitrary file write in Dash |
No comments yet