Unleash 是一个开源的功能管理(Feature Management)平台。在版本 7.5.2、7.6.5 和 8.0.2 之前,位于 中的共享 OpenAPI 验证错误处理路径存在安全漏洞。该路径在 和 函数中,会将通过 获取的原始请求值直接传递给 ,且未对调用栈深度进行限制,从而导致栈溢出风险。 未经验证的攻击者可以向 、 或其他经过 OpenAPI 验证的端点发送 POST 请求,并在请求体中嵌入一个嵌套深度达数千层的约 10 KB JSON 数据。这将导致 中出现 (最大调用栈大小超出范围)错误,并导
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-63004 | 5.5 MEDIUM | Unleash: Addon webhook URL is dialed server-side with no internal-address filtering, enabl |
| CVE-2026-63466 | 4.1 MEDIUM | Unleash: Global Mustache.escape override disables HTML escaping process-wide, enabling Sla |
No comments yet