Cloudreve是中国Cloudreve团队开源的一个支持多家云存储驱动的公有云文件系统。 Cloudreve 4.17.0之前版本存在资源管理错误漏洞,该漏洞源于内置缩略图和头像图像解码器限制压缩文件大小但未限制解码像素尺寸,可能导致经过身份验证的用户提交小型PNG、JPEG或GIF触发无界分配,造成内存耗尽并使Cloudreve进程终止。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55502 | 7.1 HIGH | Cloudreve: OAuth Admin.Read scope can update OneDrive storage policy credentials |
| CVE-2026-62323 | 6.3 MEDIUM | Cloudreve: Unauthorized file write via WOPI view sessions whose access token secret is ign |
| CVE-2026-55495 | 4.3 MEDIUM | Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Acc |
| CVE-2026-55496 | 4.3 MEDIUM | Cloudreve: Inactive/banned account emails leaked via GET /api/v4/user/search because Searc |
| CVE-2026-55499 | 4.3 MEDIUM | Cloudreve: Broken access control in file event stream leaks activity events for unshared s |
No comments yet