目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1000 CNY

100.0%

安全情报专区 11+

厳選されたセキュリティアドバイザリ、脆弱性分析、エクスプロイト情報を日本語で提供。継続更新中。

示例:RCE · SSRF · GHSA · 反序列化
フィルター
フィルターをクリア
Critical
GitLab gitlab-shell RCE Vulnerability CVE-2024-39934 Analysis and Fix
CVE-2024-39934 · github.com · 2026-04-03
GitLab 16.0.0 to 16.7.0 · GitLab 15.0.0 to 15.11.0 …
続きを読む
High
MCP Go SDK Default DNS Rebinding Protection Disabled on Localhost
github.com · 2026-04-03
Model Context Protocol Go SDK < 1.4.0
続きを読む
High
fio: Fix for DNS rebinding attack on localhost server
github.com · 2026-04-03
fio (all versions prior to the fix in PR #760 / #7150)
続きを読む
Critical
Apache Log4j2 JNDI Injection RCE Vulnerability (CVE-2021-44228) Analysis and Exploitation
CVE-2021-44228 · github.com · 2026-04-02
Apache Log4j2 2.0-beta9 to 2.14.1
続きを読む
Medium
CVE-2024-34337: Hardcoded Wildcard CORS in Java MCP SDK
CVE-2024-34337 · github.com · 2026-04-02
io.modelcontextprotocol.sdk:mcp-core < 1.0.0 · io.modelcontextprotocol.sdk:mcp-core < 1.1.1
続きを読む
High
MCP TypeScript SDK Cross-client Response Data Leak (CVE-2026-25536)
CVE-2026-25536 · github.com · 2026-02-05
modelcontextprotocol/typescript-sdk
続きを読む
CVE-2025-66414: MCP TypeScript SDK DNS Rebinding Protection Disabled by Default
github.com · 2025-12-04

### 关键信息 #### 漏洞描述 - **漏洞类型**: DNS Rebinding Protection Disabled by Default - **影响范围**: Model Context Protocol TypeScript SDK for servers running on localhost - **CVSS Score**: 7.6 (High) - **CVE ID**…

続きを読む
MCP Inspector Pre-Auth XSS Leading to RCE (CVE-2025-58444)
github.com · 2025-09-10

### 关键漏洞信息 #### 漏洞标题 - **Potential Command Execution in MCP Inspector via XSS When Connecting to an Untrusted MCP Server** #### 严重性 - **Severity**: High (8.6/10) #### 影响版本与修复版本 - **Affected versions**…

続きを読む
DoS Vulnerability in mcp Python Library Streamable HTTP Transport (CVE-2025-53365)
github.com · 2025-07-06

### 关键漏洞信息 #### 漏洞标题 - **Unhandeled Exception in Streamable HTTP Transport Leading to Denial of Service** #### 严重性 - **High** - **CVSS v4 base metrics: 8.7 / 10** #### 影响的包和版本 - **Package:** mcp (pip)…

続きを読む
CVE-2025-53109: Path validation bypass via symlink handling in @modelcontextprotocol/server-filesystem
github.com · 2025-07-06

### 关键漏洞信息 #### 漏洞标题 - **Path validation bypass via symlink handling** #### 严重性 - **High** - **CVSS v4 base metrics**: 8.4 / 10 #### 影响的包和版本 - **Package**: @modelcontextprotocol/server-filesystem (npm…

続きを読む

每篇文章经过自动 HTML→Markdown 清洗 + LLM 去噪 + 中英双语翻译。原始链接保留在文章末尾。

想看哪个安全博客 / 公告源?邮件告诉我们,每周新接 1-2 个。