往事不回首,安全不停步。AiRedTeam 的安全随笔,记录那些与代码和漏洞博弈的深夜。代码为剑,漏洞为砺,守一方数字净土。以此笔墨,化作守望万物的白泽。

安全情报

CVE-2026-44837 - view_component: System Test Entry Point Path Check Allows Sibling Directory Esca

📡 GitHub-Advisory · 2026-05-08 CVE-2026-44837 - view_component: System Test Entry Point Path Check Allows Sibling Directory Esca CVE-2026-44837 GHSA-hg3h-g7xc-f7vp MEDIUM rubygems/view_component CVE: CVE-2026-44837 Summary The system test entrypoint canonicalizes a user-controlled file path with File.realpath, then checks whether the resolved path starts with the temp directory path. This
阅读时间 1 分钟
安全情报

GHSA-mv93-w799-cj2w - GitPython: Newline injection in config_writer() section parameter bypasses CVE-2

📡 GitHub-Advisory · 2026-05-08 GHSA-mv93-w799-cj2w - GitPython: Newline injection in config_writer() section parameter bypasses CVE-2 CVE-2026-42215 GHSA-mv93-w799-cj2w HIGH pip/GitPython CVE: Summary The patch for CVE-2026-42215 (GitPython 3.1.49) validates newlines only in the value parameter of set_value(). The section and option parameters are passed to configparser without any
阅读时间 1 分钟
安全情报

CVE-2026-44844 - eml_parser has recursion DoS via nested message/rfc822 attachments

📡 GitHub-Advisory · 2026-05-08 CVE-2026-44844 - eml_parser has recursion DoS via nested message/rfc822 attachments CVE-2026-44844 GHSA-g47v-rwmh-r9f8 MEDIUM pip/eml_parser CVE: CVE-2026-44844 Summary EmlParser.get_raw_body_text() recurses unconditionally for every nested message/rfc822 attachment without any depth limit. An attacker who can supply a badly crafted EML file
阅读时间 1 分钟
安全情报

CVE-2026-44843 - LangChain vulnerable to unsafe deserialization of attacker-controlled objects th

📡 GitHub-Advisory · 2026-05-08 CVE-2026-44843 - LangChain vulnerable to unsafe deserialization of attacker-controlled objects th CVE-2026-44843 GHSA-pjwx-r37v-7724 HIGH pip/langchain-core CVE: CVE-2026-44843 LangChain contains older runtime code paths that deserialize run inputs, run outputs, or other application-controlled payloads using overly broad object allowlists. These paths may call load() with allowed_objects="
阅读时间 1 分钟
安全情报

CVE-2026-44330 - free5GC's NEF nnef-pfdmanagement API is unauthenticated; forged bearer tokens ca

📡 GitHub-Advisory · 2026-05-08 CVE-2026-44330 - free5GC's NEF nnef-pfdmanagement API is unauthenticated; forged bearer tokens ca CVE-2026-44330 GHSA-rwww-x45w-p52w CRITICAL go/github.com/free5gc/nef CVE: CVE-2026-44330 Summary free5GC's NEF mounts the nnef-pfdmanagement route group without inbound OAuth2/bearer-token authorization. A network attacker who can reach NEF on the
阅读时间 1 分钟
安全情报

CVE-2026-44329 - free5GC's SMF UPI management interface lacks auth middleware; unauthenticated to

📡 GitHub-Advisory · 2026-05-08 CVE-2026-44329 - free5GC's SMF UPI management interface lacks auth middleware; unauthenticated to CVE-2026-44329 GHSA-3258-qmv8-frp3 CRITICAL go/github.com/free5gc/smf CVE: CVE-2026-44329 Summary free5GC's SMF mounts the UPI management route group without OAuth2/bearer-token authorization middleware. A network attacker who can reach SMF on
阅读时间 1 分钟
安全情报

CVE-2026-44327 - free5GC's NEF nnef-oam route group is unauthenticated; no-token requests reach t

📡 GitHub-Advisory · 2026-05-08 CVE-2026-44327 - free5GC's NEF nnef-oam route group is unauthenticated; no-token requests reach t CVE-2026-44327 GHSA-cmpj-2x3g-m7g3 CRITICAL go/github.com/free5gc/nef CVE: CVE-2026-44327 Summary free5GC's NEF mounts the nnef-oam route group without inbound OAuth2/bearer-token authorization. A network attacker who can reach NEF on
阅读时间 1 分钟
安全情报

CVE-2026-44326 - free5GC's NEF 3gpp-traffic-influence API is unauthenticated; missing or forged b

📡 GitHub-Advisory · 2026-05-08 CVE-2026-44326 - free5GC's NEF 3gpp-traffic-influence API is unauthenticated; missing or forged b CVE-2026-44326 GHSA-3p28-73q7-45xp CRITICAL go/github.com/free5gc/nef CVE: CVE-2026-44326 Summary free5GC's NEF mounts the 3gpp-traffic-influence API without inbound OAuth2/bearer-token authorization. A network attacker who can reach NEF on the SBI
阅读时间 1 分钟
安全情报

CVE-2026-44325 - free5GC NRF: type-confusion panic in POST /oauth2/token structured-form parser v

📡 GitHub-Advisory · 2026-05-08 CVE-2026-44325 - free5GC NRF: type-confusion panic in POST /oauth2/token structured-form parser v CVE-2026-44325 GHSA-f8qv-7x5w-qr48 HIGH go/github.com/free5gc/nrf CVE: CVE-2026-44325 Summary free5GC's NRF root SBI endpoint POST /oauth2/token contains a parser-level type-confusion bug family. The handler in NFs/nrf/internal/sbi/api_
阅读时间 1 分钟
安全情报

CVE-2026-44324 - free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via ni

📡 GitHub-Advisory · 2026-05-08 CVE-2026-44324 - free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via ni CVE-2026-44324 GHSA-jqfc-gwj5-3w63 MEDIUM go/github.com/free5gc/udr CVE: CVE-2026-44324 Summary free5GC's UDR nudr-dr DELETE /subscription-data/{ueId}/{servingPlmnId}/ee-subscriptions/{subsId}/amf-subscriptions handler panics on a single authenticated request against a
阅读时间 1 分钟
安全情报

CVE-2026-44323 - free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing subsId when UE

📡 GitHub-Advisory · 2026-05-08 CVE-2026-44323 - free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing subsId when UE CVE-2026-44323 GHSA-4rqf-grm6-vf75 MEDIUM go/github.com/free5gc/udr CVE: CVE-2026-44323 Summary free5GC's UDR nudr-dr DELETE /subscription-data/{ueId}/{servingPlmnId}/ee-subscriptions/{subsId}/amf-subscriptions handler contains a nil-pointer dereference reachable from a single authenticated
阅读时间 1 分钟
安全情报

CVE-2026-44322 - free5GC's NEF 3gpp-pfd-management PATCH applications/{appId} panics on UDR acces

📡 GitHub-Advisory · 2026-05-08 CVE-2026-44322 - free5GC's NEF 3gpp-pfd-management PATCH applications/{appId} panics on UDR acces CVE-2026-44322 GHSA-j59f-x285-69jx HIGH go/github.com/free5gc/nef CVE: CVE-2026-44322 Summary free5GC's NEF PATCH /3gpp-pfd-management/v1/{afId}/transactions/{transId}/applications/{appId} handler panics with a nil-pointer dereference when the upstream UDR call
阅读时间 1 分钟
安全情报

CVE-2026-44320 - free5GC's NEF nnef-callback route group is unauthenticated; forged callback requ

📡 GitHub-Advisory · 2026-05-08 CVE-2026-44320 - free5GC's NEF nnef-callback route group is unauthenticated; forged callback requ CVE-2026-44320 GHSA-wqfh-gq79-j8mf HIGH go/github.com/free5gc/nef CVE: CVE-2026-44320 Summary free5GC's NEF mounts the nnef-callback route group without inbound OAuth2/bearer-token authorization. A forged or arbitrary bearer token (e.g. Authorization:
阅读时间 1 分钟
安全情报

CVE-2026-44318 - free5GC's BSF concurrent PUT /nbsf-management/v1/subscriptions/{subId} crashes t

📡 GitHub-Advisory · 2026-05-08 CVE-2026-44318 - free5GC's BSF concurrent PUT /nbsf-management/v1/subscriptions/{subId} crashes t CVE-2026-44318 GHSA-27ph-8q4f-h7m7 MEDIUM go/github.com/free5gc/bsf CVE: CVE-2026-44318 Summary free5GC's BSF PUT /nbsf-management/v1/subscriptions/{subId} handler has an unsynchronized write on the global Subscriptions map. The handler first reads
阅读时间 1 分钟
安全情报

CVE-2026-44317 - free5GC's PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 w

📡 GitHub-Advisory · 2026-05-08 CVE-2026-44317 - free5GC's PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 w CVE-2026-44317 GHSA-wwqh-7jm5-gj7w MEDIUM go/github.com/free5gc/pcf CVE: CVE-2026-44317 Summary free5GC's PCF POST /npcf-policyauthorization/v1/app-sessions handler panics on a single authenticated request whose ascReqData.suppFeat == "1" (enabling traffic-routing
阅读时间 1 分钟
安全情报

CVE-2026-44316 - free5GC's PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/Op

📡 GitHub-Advisory · 2026-05-08 CVE-2026-44316 - free5GC's PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/Op CVE-2026-44316 GHSA-wr8j-6chw-gm6p HIGH go/github.com/free5gc/pcf CVE: CVE-2026-44316 Summary free5GC's PCF POST /npcf-smpolicycontrol/v1/sm-policies handler (HandleCreateSmPolicyRequest) panics with a nil-pointer dereference when a downstream OpenAPI consumer call (UDR lookup)
阅读时间 1 分钟
安全情报

CVE-2026-44315 - free5GC's NEF 3gpp-pfd-management API is unauthenticated; forged bearer tokens c

📡 GitHub-Advisory · 2026-05-08 CVE-2026-44315 - free5GC's NEF 3gpp-pfd-management API is unauthenticated; forged bearer tokens c CVE-2026-44315 GHSA-5f62-53r8-qrqf CRITICAL go/github.com/free5gc/nef CVE: CVE-2026-44315 Summary free5GC's NEF mounts the 3gpp-pfd-management API without inbound OAuth2/bearer-token authorization. A network attacker who can reach NEF on the SBI
阅读时间 1 分钟
安全情报

CVE-2026-44309 - gitsign verify accepts signatures over go-git-normalized bytes, enabling trust c

📡 GitHub-Advisory · 2026-05-08 CVE-2026-44309 - gitsign verify accepts signatures over go-git-normalized bytes, enabling trust c CVE-2026-44309 GHSA-7rmh-48mx-2vwc MEDIUM go/github.com/sigstore/gitsign CVE: CVE-2026-44309 Summary gitsign verify and gitsign verify-tag re-encode commit/tag objects through go-git's EncodeWithoutSignature before checking the signature, instead of verifying against the raw git
阅读时间 1 分钟
安全情报

CVE-2026-44566 - Open WebUI Vulnerable to Arbitrary File Upload and Path Traversal

📡 GitHub-Advisory · 2026-05-08 CVE-2026-44566 - Open WebUI Vulnerable to Arbitrary File Upload and Path Traversal CVE-2026-44566 GHSA-9pgh-j74g-qj6m HIGH pip/open-webui CVE: CVE-2026-44566 **CONFIDENTIAL** KL-CAN-2024-002 Vulnerability Details #FieldValue 1**Discoverer**Jaggar Henry & Sean Segreti of KoreLogic, Inc. 2**Date Submitted**2024.03.12 3**Title**Open WebUI Arbitrary File Upload + Path
阅读时间 1 分钟
安全情报

CVE-2026-44567 - Open WebUI has Improper Authorization Control

📡 GitHub-Advisory · 2026-05-08 CVE-2026-44567 - Open WebUI has Improper Authorization Control CVE-2026-44567 GHSA-4vg5-rp28-gvjf HIGH pip/open-webui CVE: CVE-2026-44567 **CONFIDENTIAL** Vulnerability Disclosure Analysis Documentation Vulnerability Details #FieldValue 1**Discoverer**Taylor Pennington of KoreLogic, Inc. 2**Date Submitted**June 11, 2024 3**Title**Open WebUI Improper Authorization Control 5**Affected Vendor**Open WebUI
阅读时间 1 分钟
[!] CONTACT_CHANNELS

如需商务合作、技术咨询或漏洞反馈,请通过以下离岸节点联系作者。

> PING_AUTHOR (@A1RedTeam)