Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

decolua — Vulnerabilities & Security Advisories 21

Browse all 21 CVE security advisories affecting decolua. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page documents software weaknesses associated with the vendor decolua, categorized by common vulnerability types and security tags. It aggregates a comprehensive collection of security issues reported for decolua products, covering historical data from initial disclosures through recent patches. The dataset focuses on diverse weakness classes, including input validation errors, authentication flaws, and configuration mistakes, ensuring a broad view of the vendor’s security landscape. Here, researchers and security professionals can systematically track decolua’s advisory history to identify patterns in how the vendor responds to emerging threats. Users can dive deep into specific weakness classes to understand the root causes and impact scopes of recurring issues within the ecosystem. Additionally, the page allows for detailed lookup of individual products, revealing their unique vulnerability timelines and remediation statuses over time. This structured approach facilitates better risk assessment by highlighting which components remain susceptible and which have been effectively hardened. The information is organized to support both broad trend analysis and granular investigation, making it easier to correlate new findings with past incidents. By centralizing these details, the page serves as a critical resource for evaluating the overall security posture of decolua offerings and understanding the evolution of their patch management practices.

Found 21 results / 21Clear Filters
Top products by decolua: 9router
CVE IDTitleCVSSSeverityPublished
CVE-2026-56677 9Router: Authenticated Server-Side Request Forgery (SSRF) via OIDC Provider Test Endpoint — 9routerCWE-306 8.6 High2026-08-17
CVE-2026-63313 9Router before 0.4.72 Server-Side Request Forgery via /v1/web/fetch — 9routerCWE-918 7.7 High2026-07-23
CVE-2026-63732 9router before 0.4.60 Remote Code Execution via default password — 9routerCWE-78 9.9 Critical2026-07-23
CVE-2026-62312 9Router: Authenticated RCE via Unvalidated MCP Plugin Arguments — 9routerCWE-78 8.8 High2026-07-15
CVE-2026-56678 9Router: Kiro region injection allows authenticated SSRF with Authorization header forwarding — 9routerCWE-20 6.4 Medium2026-07-15
CVE-2026-56679 9Router: Mass assignment in PATCH /api/settings allows authenticated authorization downgrade — 9routerCWE-915--2026-07-15
CVE-2026-49353 9Router: Local-Only Access Gate Bypass in 9router via Host Header SpoofING — 9routerCWE-290 7.5 High2026-07-15
CVE-2026-49352 9Router: Hardcoded Default fallback JWT Secret Allows Authentication Bypass — 9routerCWE-798 9.8 Critical2026-07-15
CVE-2026-46339 9Router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes — 9routerCWE-78 10.0 Critical2026-07-15
CVE-2026-62328 9Router 0.4.41 - Unauthenticated Information Disclosure via API Usage Endpoints — 9RouterCWE-862 7.5 High2026-07-13
CVE-2026-62327 9Router 0.4.41 - Unauthenticated API Key Exposure via /api/usage/stats — 9RouterCWE-306 9.1 Critical2026-07-13
CVE-2026-59801 9Router 0.4.41 - Unauthenticated API Exposure via /api/providers — 9RouterCWE-306 9.8 Critical2026-07-13
CVE-2026-56675 9router: Reverse proxy locality collapse allows unauthenticated access to 9router /v1 APIs — 9routerCWE-287 8.3 High2026-07-10
CVE-2026-55638 9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass — 9routerCWE-862 8.6 High2026-07-10
CVE-2026-55641 9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF — 9routerCWE-290 8.2 High2026-07-10
CVE-2026-56676 9router: Image prefetch DNS rebinding allows SSRF to internal services — 9routerCWE-367 7.4 High2026-07-10
CVE-2026-55500 9router: Exposure of Sensitive Information and Unprotected Database Import/Export Allows Complete Credential Theft and Database Takeover — 9routerCWE-200 9.9 Critical2026-07-10
CVE-2026-55501 9router: Login brute-force protection bypass via spoofed X-Forwarded-For header — 9routerCWE-307 7.3 High2026-07-10
CVE-2026-59800 9Router < 0.4.44 - OS Command Injection via sudoPassword Parameter in Tailscale Install Endpoint — 9routerCWE-78 9.8 Critical2026-07-07
CVE-2026-10269 decolua 9router HTTP Header dashboardGuard.js isAuthenticated improper authorization — 9routerCWE-285 6.3 Medium2026-06-01
CVE-2026-5842 decolua 9router Administrative API Endpoint api authorization — 9routerCWE-639 7.3 High2026-04-09

This page lists every published CVE security advisory associated with decolua. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.