Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Tag: inventree-project Clear
ID Title
CVE-2026-39362 SSRF (Server-Side Request Forgery) in django (CVE-2026-39362)
SSRF in django (CVE-2026-39362). Data can be tampered with by attackers. Mitigation: upgrade to `1.2.7` or later.
CVE-2026-35476 Vulnerability in inventree-project (CVE-2026-35476)
vulnerability in inventree-project (CVE-2026-35476). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.2.7` or later.
CVE-2026-35477 Vulnerability in inventree-project (CVE-2026-35477)
vulnerability in inventree-project (CVE-2026-35477). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.2.7` or later.
CVE-2026-35478 Vulnerability in inventree-project (CVE-2026-35478)
vulnerability in inventree-project (CVE-2026-35478). Confidential information can be exposed externally. Exploitable via `POST /api/user/tokens/`. Mitigation: upgrade to `1.2.7` or later.
CVE-2026-35479 Vulnerability in inventree-project (CVE-2026-35479)
vulnerability in inventree-project (CVE-2026-35479). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.2.7` or later.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →