漏洞描述 在 Netty 消息处理管线中,Worker 的 Netty 消息解码器被安装在 SASL 认证处理器之前,因此在任何认证发生之前就会处理接收到的帧。该解码器根据帧中携带的长度字段来分配缓冲区,因此来自未认证对等方的单个帧,如果该对等方能够访问 Worker 插槽端口,就可能触发大内存分配。 默认为 ,且解码器在任何情况下都运行在强制认证的处理程序之前,因此无需凭证即可触发。攻击者只需具备到 Worker 端口的 TCP 可达性即可利用此漏洞。 在默认 768 MB Worker 堆内存配置下,单个帧的影
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Storm Worker | 3.0.0 ~ 3.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82434 | 10.0 CRITICAL | Apache Storm Nimbus, Apache Storm Client: Disclosure of the Topology ZooKeeper Credential |
| CVE-2026-78330 | Apache Syncope: Privilege escalation for admin user via JWT authentication | |
| CVE-2026-73579 | Apache Syncope: Non-recursive Any search could skip Realms restrictions | |
| CVE-2026-75015 | Apache Syncope: Nested secrets leak cleartext into audit records readable | |
| CVE-2026-75030 | Apache Syncope: Incomplete authorization checks for Group members deprovisioning | |
| CVE-2026-77051 | Apache Syncope: SQL injection via unsanitized entityKey and opEvent in Audit Events search | |
| CVE-2026-73668 | Apache Syncope: Cross-realm disclosure of confidential ConnId bundles configuration values | |
| CVE-2026-77147 | Apache Syncope: Groovy Sandbox escape for empty CommandArgs | |
| CVE-2026-77181 | Apache Syncope: ClientApp update entitlement not effective | |
| CVE-2026-77883 | Apache Syncope: Information disclosure via one-hop JEXL navigation past the JexlContextBui | |
| CVE-2026-78318 | Apache Syncope: Unauthenticated reflected XSS in Console and Enduser | |
| CVE-2026-73470 | Apache Syncope: Delegating users can grant unowned Roles | |
| CVE-2026-78336 | Apache Syncope: OIDCC4UI provider list discloses client secrets to any authenticated user | |
| CVE-2026-82232 | Apache Syncope: SQL injection via sort parameter in Task search | |
| CVE-2026-86460 | Apache Syncope: Cypher Injection via FIQL Search on Neo4j Persistence | |
| CVE-2026-87779 | Apache Syncope: AES Secret Key disclosure via log output | |
| CVE-2026-87785 | Apache Syncope: JWT subject spoofing | |
| CVE-2026-87802 | Apache Syncope: SRA OAuth2 JWT signature verification bypass | |
| CVE-2026-68570 | Apache Doris: Authorization bypass leading to unauthorized data access | |
| CVE-2026-72524 | Apache Doris: Authorization bypass allowing a low-privilege user to read/write/drop arbitr |
Showing top 20 of 39 CVEs. View all on vendor page → →
No comments yet