在 Pixelfed 0.12.11 及更早版本中发现了一个漏洞。受影响的是组件 OAuth Scope Handler 中文件 的 函数。对参数 ID 的异常操作会导致认证缺失。该攻击可远程发起。利用该漏洞的方法已公开,并可能被实际利用。建议将版本升级到 0.12.10 以修复此问题。该补丁的名称为 。建议升级受影响组件以解决该问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | Pixelfed | 0.12.0 |
cpe:2.3:a:pixelfed:pixelfed:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93962 | 8.3 HIGH | Kamailio CDP Diameter Receiver receiver.c shm_malloc heap-based overflow |
| CVE-2026-94004 | 7.3 HIGH | DedeCMS mytag_js.php code injection |
No comments yet