Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

decolua — Vulnerabilities & Security Advisories 18

Browse all 18 CVE security advisories affecting decolua. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page serves as a vulnerability aggregation index for decolua, focusing on its software products and associated security weaknesses. It collects data on known flaws, ranging from critical remote code execution risks to lower-severity information disclosure issues, covering a continuous time range from the earliest recorded incidents to the most recent disclosures. By visiting this resource, users can effectively track decolua’s security advisories to stay informed about newly released patches and mitigation strategies. Additionally, this page allows for a deeper understanding of specific weakness classes prevalent in the vendor’s ecosystem, helping analysts identify patterns in how different types of defects are introduced and resolved over time. Users may also look up individual product versions to review their complete vulnerability history, providing a comprehensive view of the attack surface as it has evolved. This centralized view aids security professionals, developers, and system administrators in assessing risk exposure and prioritizing remediation efforts without needing to visit multiple disparate sources. The content is structured to facilitate quick reference and historical analysis, ensuring that stakeholders have access to accurate and timely information regarding decolua’s security posture. This approach supports proactive defense mechanisms and helps organizations make informed decisions about software procurement and deployment within their environments.

Top products by decolua: 9router
CVE IDTitleCVSSSeverityPublished
CVE-2026-62312 9Router: Authenticated RCE via Unvalidated MCP Plugin Arguments — 9routerCWE-78 8.8 High2026-07-15
CVE-2026-56678 9Router: Kiro region injection allows authenticated SSRF with Authorization header forwarding — 9routerCWE-20 6.4 Medium2026-07-15
CVE-2026-56679 9Router: Mass assignment in PATCH /api/settings allows authenticated authorization downgrade — 9routerCWE-915--2026-07-15
CVE-2026-49353 9Router: Local-Only Access Gate Bypass in 9router via Host Header SpoofING — 9routerCWE-290 7.5 High2026-07-15
CVE-2026-49352 9Router: Hardcoded Default fallback JWT Secret Allows Authentication Bypass — 9routerCWE-798 9.8 Critical2026-07-15
CVE-2026-46339 9Router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes — 9routerCWE-78 10.0 Critical2026-07-15
CVE-2026-62328 9Router 0.4.41 - Unauthenticated Information Disclosure via API Usage Endpoints — 9RouterCWE-862 7.5 High2026-07-13
CVE-2026-62327 9Router 0.4.41 - Unauthenticated API Key Exposure via /api/usage/stats — 9RouterCWE-306 9.1 Critical2026-07-13
CVE-2026-59801 9Router 0.4.41 - Unauthenticated API Exposure via /api/providers — 9RouterCWE-306 9.8 Critical2026-07-13
CVE-2026-56675 9router: Reverse proxy locality collapse allows unauthenticated access to 9router /v1 APIs — 9routerCWE-287 8.3 High2026-07-10
CVE-2026-55638 9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass — 9routerCWE-862 8.6 High2026-07-10
CVE-2026-55641 9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF — 9routerCWE-290 8.2 High2026-07-10
CVE-2026-56676 9router: Image prefetch DNS rebinding allows SSRF to internal services — 9routerCWE-367 7.4 High2026-07-10
CVE-2026-55500 9router: Exposure of Sensitive Information and Unprotected Database Import/Export Allows Complete Credential Theft and Database Takeover — 9routerCWE-200 9.9 Critical2026-07-10
CVE-2026-55501 9router: Login brute-force protection bypass via spoofed X-Forwarded-For header — 9routerCWE-307 7.3 High2026-07-10
CVE-2026-59800 9Router < 0.4.44 - OS Command Injection via sudoPassword Parameter in Tailscale Install Endpoint — 9routerCWE-78 9.8 Critical2026-07-07
CVE-2026-10269 decolua 9router HTTP Header dashboardGuard.js isAuthenticated improper authorization — 9routerCWE-285 6.3 Medium2026-06-01
CVE-2026-5842 decolua 9router Administrative API Endpoint api authorization — 9routerCWE-639 7.3 High2026-04-09

This page lists every published CVE security advisory associated with decolua. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.