HFS2 2.4.0 及更早版本存在一个拒绝服务漏洞,允许未经身份验证的攻击者通过发送一个精心构造的请求,导致服务完全且持久地不可用。攻击者可以触发一个卡住的服务器线程,该线程会进入忙等待循环,从而使整个文件服务器对所有客户端无响应,且系统无法自行恢复,必须由操作员手动重启服务才能恢复正常。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-97359 | 10.0 CRITICAL | HFS2 2.4.0 RCE via Multipart Upload Filename Template Injection |
| CVE-2026-97360 | 10.0 CRITICAL | HFS2 2.4.0 Unauthenticated Arbitrary File Read/Write via Template Engine |
No comments yet