Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-36852— Build Cache Poisoning via Untrusted Pull Requests

EPSS 0.17% · P37
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-36852

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Build Cache Poisoning via Untrusted Pull Requests
Source: NVD (National Vulnerability Database)
Vulnerability Description
A critical security vulnerability exists in remote cache extensions for common build systems utilizing bucket-based remote cache (such as those using Amazon S3, Google Cloud Storage, or similar object storage) that allows any contributor with pull request privileges to inject compromised artifacts from an untrusted environment into trusted production environments without detection.  The vulnerability exploits a fundamental design flaw in the "first-to-cache wins" principle, where artifacts built in untrusted environments (feature branches, pull requests) can poison the cache used by trusted environments (protected branches, production deployments).  This attack bypasses all traditional security measures including encryption, access controls, and checksum validation because the poisoning occurs during the artifact construction phase, before any security measures are applied.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
从非可信控制范围包含功能例程
Source: NVD (National Vulnerability Database)
Vulnerability Title
Nx 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Nx是Nx的一个应用软件。 Nx存在安全漏洞,该漏洞源于基于桶的远程缓存存在设计缺陷,可能导致将受损构件注入受信任的生产环境。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Niklas PortmannAzure Based Remote Cache Plugin for Nx 0 cpe:2.3:a:niklas_portmann:nx-remotecache-azure:0:*:*:*:*:*:*:*
Niklas PortmannMinio Based Remote Cache Plugin for Nx 0 cpe:2.3:a:niklas_portmann:nx-remotecache-minio:0:*:*:*:*:*:*:*
Niklas PortmannNx Remote Cache Utilities 0 cpe:2.3:a:niklas_portmann:nx-remotecache-custom:0:*:*:*:*:*:*:*
NxAWS S3 Remote Cache Plugin for Nx 0 cpe:2.3:a:nx:s3-cache:0:*:*:*:*:*:*:*
NxGCS Remote Cache Plugin for Nx 0 cpe:2.3:a:nx:gcs-cache:0:*:*:*:*:*:*:*
NxAzure Blob Remote Cache Plugin for Nx 0 cpe:2.3:a:nx:azure-cache:0:*:*:*:*:*:*:*
NxShared File System Cache Plugin for Nx 0 cpe:2.3:a:nx:shared-fs-cache:0:*:*:*:*:*:*:*

II. Public POCs for CVE-2025-36852

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-36852

登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2025-36852

No comments yet


Leave a comment