decolua
Networking Infrastructurecommercial
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting decolua.
- CVE-2026-566829Router: Login Brute-Force Lockout Bypass via Spoofable X-9r-Real-Ip Header5.3
- CVE-2026-566819Router: Authentication Bypass in Public LLM API via Spoofable X-9r-Real-Ip Header7.3
- CVE-2026-728609router Server-Side Request Forgery via /api/provider-nodes/validate Because the IPv4-Mapped IPv6 Denylist Check Is Unreachable8.5
- CVE-2026-566779Router: Authenticated Server-Side Request Forgery (SSRF) via OIDC Provider Test Endpoint8.6
- CVE-2026-637329router before 0.4.60 Remote Code Execution via default password9.9
- CVE-2026-633139Router before 0.4.72 Server-Side Request Forgery via /v1/web/fetch7.7
- CVE-2026-623129Router: Authenticated RCE via Unvalidated MCP Plugin Arguments8.8
- CVE-2026-566789Router: Kiro region injection allows authenticated SSRF with Authorization header forwarding6.4
- CVE-2026-566799Router: Mass assignment in PATCH /api/settings allows authenticated authorization downgrade
- CVE-2026-493539Router: Local-Only Access Gate Bypass in 9router via Host Header SpoofING7.5
- CVE-2026-493529Router: Hardcoded Default fallback JWT Secret Allows Authentication Bypass9.8
- CVE-2026-463399Router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes10.0
- CVE-2026-623289Router 0.4.41 - Unauthenticated Information Disclosure via API Usage Endpoints7.5
- CVE-2026-623279Router 0.4.41 - Unauthenticated API Key Exposure via /api/usage/stats9.1
- CVE-2026-598019Router 0.4.41 - Unauthenticated API Exposure via /api/providers9.8