Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-39362 |
|
SSRF (Server-Side Request Forgery) in django (CVE-2026-39362)
SSRF in django (CVE-2026-39362). Data can be tampered with by attackers. Mitigation: upgrade to `1.2.7` or later.
|
| CVE-2026-35476 |
|
Vulnerability in inventree-project (CVE-2026-35476)
vulnerability in inventree-project (CVE-2026-35476). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.2.7` or later.
|
| CVE-2026-35477 |
|
Vulnerability in inventree-project (CVE-2026-35477)
vulnerability in inventree-project (CVE-2026-35477). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.2.7` or later.
|
| CVE-2026-35478 |
|
Vulnerability in inventree-project (CVE-2026-35478)
vulnerability in inventree-project (CVE-2026-35478). Confidential information can be exposed externally. Exploitable via `POST /api/user/tokens/`. Mitigation: upgrade to `1.2.7` or later.
|
| CVE-2026-35479 |
|
Vulnerability in inventree-project (CVE-2026-35479)
vulnerability in inventree-project (CVE-2026-35479). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.2.7` or later.
|