腾讯朱雀实验室历史披露的漏洞(CVE / GHSA)汇总。
-
open_in_new高危 CVE-2026-74609 CWE-825
A race condition exists in Linux kernel's TIPC
deployed_code 影响范围:Linux < 5.10.265, < 5.15.216, < 6.1.183, < 6.6.152, < 6.12.104, < 6.18.45, < 7.1.9 or < 7.2 calendar_today 发布日期:2026年8月22日 -
open_in_new高危 CVE-2026-74580 CWE-825
Local privilege escalation in Linux's vhost subsystem
deployed_code 影响范围:Linux < 5.10.265, < 5.15.216, < 6.1.183, < 6.6.152, < 6.12.104, < 6.18.45, < 7.1.9 or < 7.2 calendar_today 发布日期:2026年8月21日 -
open_in_new高危 CVE-2026-64564 CWE-416
[SCTPhantom] sctp: don't free the ASCONF's own transport in DEL-IP processing
deployed_code 影响范围:linux >= 2.6.25 calendar_today 发布日期:2026年8月4日 -
open_in_new高危 CVE-2026-69257 CWE-918/CWE-1389
Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses
deployed_code 影响范围:flowise <= 3.1.2 calendar_today 发布日期:2026年8月4日 -
open_in_new中危 CVE-2026-12491 CWE-436
vLLM: image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations
deployed_code 影响范围:vllm >= 0.11.0, <= 0.23.0 calendar_today 发布日期:2026年6月17日 -
open_in_new中危 CVE-2026-45386 CWE-639
An IDOR vulnerability exists in the pin_channel_message API endpoint
deployed_code 影响范围:open-webui < 0.9.5 calendar_today 发布日期:2026年5月11日 -
open_in_new中危 CVE-2026-45385 CWE-639
An IDOR vulnerability exists in the update_message_by_id API endpoint
deployed_code 影响范围:open-webui < 0.9.5 calendar_today 发布日期:2026年5月11日 -
open_in_new低危 CVE-2026-43529 CWE-367
OpenClaw: TOCTOU read in exec script preflight
deployed_code 影响范围:OpenClaw < 2026.4.10 calendar_today 发布日期:2026年5月5日 -
open_in_new中危 CVE-2026-42310 CWE-835
Pillow has a PDF Parsing Trailer Infinite Loop (DoS)
deployed_code 影响范围:pillow >= 4.2.0, < 12.2.0 calendar_today 发布日期:2026年5月4日 -
open_in_new低危 GHSA-j4c5-89f5-f3pm CWE-918
OpenClaw: Browser CDP profile creation skipped strict-mode SSRF checks
deployed_code 影响范围:openclaw < 2026.4.20 calendar_today 发布日期:2026年4月25日
每页
