LemmyNet lemmy是LemmyNet组织的一个去中心化的链接聚合与讨论社区平台。 LemmyNet lemmy 0.19.19之前版本和1.0.0-beta.1之前版本存在侧信道信息泄露漏洞,该漏洞源于登录端点根据用户名或邮箱是否存在返回不同错误响应,导致未认证攻击者能够确认已注册的用户名或邮箱地址,并用于定向凭证攻击或社会工程学。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54740 | 6.5 MEDIUM | Lemmy: Lower-ranked federated moderator can remove higher-ranked moderators |
| CVE-2026-54738 | 6.5 MEDIUM | Lemmy: Rate limit bypass via X-Forwarded-For header spoofing in actix-web ConnectionInfo |
| CVE-2026-54743 | 6.4 MEDIUM | Lemmy: Stored XSS via markdown image alt-text in lemmy-ui html5-embed |
| CVE-2026-54741 | 5.3 MEDIUM | Lemmy: Blocked users can edit private messages sent before the block |
| CVE-2026-54742 | 5.1 MEDIUM | Lemmy: `CollectionAdd::Featured` does not check the post is in the community |
No comments yet