Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
CVE-2026-103530
  • github.com/decolua/9router
decolua 9Router Search Endpoint ssrfGuard.js fetch server-side request forgery 5 days ago
  • No fix available
  • Severity - 6.9 (Medium)
GHSA-vmjq-hvgq-2wv4
  • npm/9router
9router: Mass assignment in PATCH /api/settings allows authenticated authorization downgrade 23 Sep
  • Fix available
  • Severity - 8.7 (High)
GHSA-6mwv-4mrm-5p3m
  • npm/9router
9router: Kiro region injection allows authenticated SSRF with Authorization header forwarding 23 Sep
  • Fix available
  • Severity - 6.4 (Medium)
GHSA-cmhj-wh2f-9cgx
  • npm/9router
9router: Image prefetch DNS rebinding allows SSRF to internal services 23 Sep
  • Fix available
  • Severity - 7.4 (High)
GHSA-x5c9-v98j-722r
  • npm/9router
9router /v1 APIs has unauthenticated access via reverse proxy locality collapse 23 Sep
  • Fix available
  • Severity - 8.3 (High)
GHSA-32gc-64m7-hj7v
  • npm/9router
9Router has a Login Brute-Force Lockout Bypass via Spoofable X-9r-Real-Ip Header 22 Sep
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-5mj8-gf6m-fhw8
  • npm/9router
9Router has an Authentication Bypass in Public LLM API via Spoofable X-9r-Real-Ip Header 22 Sep
  • Fix available
  • Severity - 7.3 (High)
CVE-2026-56682
  • github.com/decolua/9router
9Router: Login Brute-Force Lockout Bypass via Spoofable X-9r-Real-Ip Header 22 Sep
  • Fix available
  • Severity - 5.3 (Medium)
CVE-2026-56681
  • github.com/decolua/9router
9Router: Authentication Bypass in Public LLM API via Spoofable X-9r-Real-Ip Header 22 Sep
  • Fix available
  • Severity - 7.3 (High)
GHSA-86m2-fcxq-5q7c
  • npm/9router
9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF 28 Aug
  • Fix available
  • Severity - 8.2 (High)
GHSA-8gmq-j984-vp4r
  • npm/9router
9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass 28 Aug
  • Fix available
  • Severity - 8.6 (High)
CVE-2026-72860
  • github.com/decolua/9router
9router Server-Side Request Forgery via /api/provider-nodes/validate Because the IPv4-Mapped IPv6 Denylist Check Is Unreachable 20 Aug
  • No fix available
  • Severity - 6.3 (Medium)
GHSA-8g4w-4ffg-8vgx
  • npm/9router
9Router: Authenticated Server-Side Request Forgery (SSRF) via OIDC Provider Test Endpoint 17 Aug
  • No fix available
  • Severity - 8.6 (High)
CVE-2026-56677
  • github.com/decolua/9router
9Router: Authenticated Server-Side Request Forgery (SSRF) via OIDC Provider Test Endpoint 17 Aug
  • No fix available
  • Severity - 8.6 (High)
CVE-2026-62312
  • github.com/decolua/9router
9Router: Authenticated RCE via Unvalidated MCP Plugin Arguments 15 Jul
  • Fix available
  • Severity - 8.8 (High)
CVE-2026-56678
  • github.com/decolua/9router
9Router: Kiro region injection allows authenticated SSRF with Authorization header forwarding 15 Jul
  • Fix available
  • Severity - 6.4 (Medium)