在 2024 年 10 月 28 日 00 时至 2026 年 9 月 28 日 00 时之间发布的 ProxyGen 版本中, 和 这两个 API 可能会返回流处理器(stream handler)已经释放的流句柄(stream handles)。随后, 会将这些句柄安装为传输层读取回调函数,从而导致已释放内存的非法访问(use of freed memory,即常见的“释放后使用”漏洞)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84895 | Proxygen v2026.04-09 Use-After-Free漏洞 | |
| CVE-2026-91096 | Proxygen 2024.10-2026.09 远程代码执行 |
No comments yet