Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

warp-tech — Vulnerabilities & Security Advisories 12

Browse all 12 CVE security advisories affecting warp-tech. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Warp-tech primarily provides a distributed computing platform for complex data processing tasks. Historically, the technology has been susceptible to remote code execution vulnerabilities, cross-site scripting flaws, and privilege escalation issues, accounting for its four recorded CVEs. The platform's distributed architecture introduces unique attack surfaces, with past incidents involving unauthorized access through exposed management interfaces and insecure inter-node communication. Security researchers have noted that default configurations often leave systems vulnerable, requiring hardening before deployment. While no major public breaches have been attributed to warp-tech, the consistent pattern of similar vulnerability types suggests potential weaknesses in input validation and access control mechanisms within its core components.

Top products by warp-tech: warpgate russh
CVE ID Title CVSS Severity Published
CVE-2026-91167 Warpgate: Missing authorization check on `PUT /users/:id/roles/:role_id` allows any admin to bypass the `AccessRolesAssign` permission boundary — warpgate CWE-862 6.0 Medium 2026-09-21
CVE-2026-91166 Warpgate: Web SSH stores a jump host's key against the target's address, so it validates as the target — warpgate CWE-297 5.7 Medium 2026-09-21
CVE-2026-91165 Warpgate: Markup injection in SSO form_post return page via unencoded redirect/error values — warpgate CWE-79 2.4 Low 2026-09-21
CVE-2026-91164 Warpgate: API tokens bypass the user's allowed_ip_ranges restriction — warpgate CWE-284 4.3 Medium 2026-09-21
CVE-2026-63330 Warpgate: Missing Admin Authorization on Live Recording Stream WebSocket Allows Any Authenticated User to Eavesdrop on Terminal Sessions — warpgate CWE-285 7.7 High 2026-09-21
CVE-2026-63329 Warpgate: x-warpgate-username Header Not Stripped from Client Requests Enables Identity Spoofing to WebSocket Backend Targets — warpgate CWE-116 4.9 Medium 2026-09-21
CVE-2026-58491 Warpgate: Reflected XSS in SSO return endpoint via attacker-controlled next parameter — warpgate CWE-79 9.3 Critical 2026-09-21
CVE-2026-44347 Warpgate: SSO CSRF -- State Token Not Validated on Return — warpgate CWE-352 5.8 Medium 2026-05-12
CVE-2023-48712 User authorization bug leading to privilege escalation in warpgate — warpgate CWE-863 7.1 High 2023-11-24
CVE-2023-43660 SSH key password bypassed in warpgate — warpgate CWE-287 4.8 Medium 2023-09-27
CVE-2023-37268 User login confusion with SSO in warpgate — warpgate CWE-287 6.4 Medium 2023-07-14
CVE-2023-28113 russh may use insecure Diffie-Hellman keys — russh CWE-20 5.9 Medium 2023-03-16

This page lists every published CVE security advisory associated with warp-tech. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.