Go modules package
github.com/cloudreve/cloudreve/v4
pkg:golang/github.com/cloudreve/cloudreve/v4
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-54563 | Hig | 7.1 | < 4.0.0-20260606032813-26b6b1044b02 | 4.0.0-20260606032813-26b6b1044b02 | Jul 15, 2026 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.16.1, a Cloudreve WebDAV account rooted at a configured folder can send paths such as /dav/%2e%2e/outside.txt because stripPrefix in pkg/webdav/webdav.go joins the decoded request suffix to the account root | |
| CVE-2026-25726 | Hig | 8.1 | < 4.0.0-20260205113604-ec9fdd33bc54 | 4.0.0-20260205113604-ec9fdd33bc54 | Apr 3, 2026 | Cloudreve is a self-hosted file management and sharing system. Prior to version 4.13.0, the application uses the weak pseudo-random number generator math/rand seeded with time.Now().UnixNano() to generate critical security secrets, including the secret_key, and hash_id_salt. Thes |
- affected < 4.0.0-20260606032813-26b6b1044b02fixed 4.0.0-20260606032813-26b6b1044b02
Cloudreve is a self-hosted file management and sharing system. Prior to 4.16.1, a Cloudreve WebDAV account rooted at a configured folder can send paths such as /dav/%2e%2e/outside.txt because stripPrefix in pkg/webdav/webdav.go joins the decoded request suffix to the account root
- affected < 4.0.0-20260205113604-ec9fdd33bc54fixed 4.0.0-20260205113604-ec9fdd33bc54
Cloudreve is a self-hosted file management and sharing system. Prior to version 4.13.0, the application uses the weak pseudo-random number generator math/rand seeded with time.Now().UnixNano() to generate critical security secrets, including the secret_key, and hash_id_salt. Thes