目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-91154— 电商模板产品缓存无认证拒绝服务漏洞

一分钟漏洞结论

影响对象
MarcosCamara01 Ecommerce Template
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

关键函数缺失身份验证(CWE-306)存在于 MarcosCamara01 电子商务模板中、在提交 ec97209 之前的产品缓存重新验证 Server Action(src/app/actions.ts 中的 revalidateProducts)中。该漏洞允许远程、未认证的攻击者随意强制使整个 storefront 的产品缓存失效。 该文件在文件作用域声明了 ,因此其中导出的每个函数都会编译为一个可通过 POST 调用的 Server Action。 函数调用了 ,但未进行任何会话(session)或角色(ro

CVSS 6.9 · Medium
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-91154 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Missing authentication in Ecommerce Template product cache revalidation allows unauthenticated denial of service
来源: CVE Program / CVE List V5
Vulnerability Description
Missing Authentication for Critical Function (CWE-306) in the product cache revalidation Server Action (src/app/actions.ts, revalidateProducts) in MarcosCamara01 Ecommerce Template before commit ec97209 allows a remote, unauthenticated attacker to force expiration of the entire storefront product cache at will. The file declares "use server" at file scope, so every exported function compiles into a POST-invokable Server Action; revalidateProducts calls updateTag("products") with no session or role check, unlike the read-only actions in the same file which are safe by construction. Two client components under src/components/admin import the function, which causes its Server Action id to be compiled into a public /_next/static chunk that the application's admin middleware (proxy.ts) does not gate, so any unauthenticated user can extract that id from the public bundle and invoke the action directly. With cacheComponents enabled, the entire storefront (home, categories, product pages, search) is served from "use cache" entries produced by getAllProducts, getCategoryProducts and getProduct, all tagged products with an hours-long cacheLife. Repeated unauthenticated invocation of revalidateProducts keeps that cache permanently cold, forcing every visitor's request to read the full product catalog from Postgres instead of serving from cache, degrading storefront availability at near-zero attacker cost.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
来源: CVE Program / CVE List V5
Vulnerability Type
关键功能的认证机制缺失
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
MarcosCamara01 Ecommerce Template 0 ~ ec97209 -

二、漏洞 CVE-2026-91154 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-91154 的情报信息

请登录查看更多情报信息。

CVE-2026-91154 其他参考 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-91154

暂无评论


发表评论