decolua
Networking Infrastructurecommercial
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting decolua.
- CVE-2026-623129Router: Authenticated RCE via Unvalidated MCP Plugin Arguments8.8
- CVE-2026-566789Router: Kiro region injection allows authenticated SSRF with Authorization header forwarding6.4
- CVE-2026-493539Router: Local-Only Access Gate Bypass in 9router via Host Header SpoofING7.5
- CVE-2026-493529Router: Hardcoded Default fallback JWT Secret Allows Authentication Bypass9.8
- CVE-2026-463399Router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes10.0
- CVE-2026-623289Router 0.4.41 - Unauthenticated Information Disclosure via API Usage Endpoints7.5
- CVE-2026-623279Router 0.4.41 - Unauthenticated API Key Exposure via /api/usage/stats9.1
- CVE-2026-598019Router 0.4.41 - Unauthenticated API Exposure via /api/providers9.8
- CVE-2026-566759router: Reverse proxy locality collapse allows unauthenticated access to 9router /v1 APIs8.3
- CVE-2026-556389router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass8.6
- CVE-2026-556419router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF8.2
- CVE-2026-566769router: Image prefetch DNS rebinding allows SSRF to internal services7.4
- CVE-2026-555009router: Exposure of Sensitive Information and Unprotected Database Import/Export Allows Complete Credential Theft and Database Takeover9.9
- CVE-2026-555019router: Login brute-force protection bypass via spoofed X-Forwarded-For header7.3
- CVE-2026-598009Router < 0.4.44 - OS Command Injection via sudoPassword Parameter in Tailscale Install Endpoint9.8