CVE-2026-105144
Last modified
CVE-2026-105144 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. A flaw has been found in Drogon up to 1.9.13-1/10.0-beta.3 on Windows. Affected is the function StaticFileRouter::route of the file lib/src/StaticFileRouter.cc of the component Static File Router.
Description
A flaw has been found in Drogon up to 1.9.13-1/10.0-beta.3 on Windows. Affected is the function StaticFileRouter::route of the file lib/src/StaticFileRouter.cc of the component Static File Router. Executing a manipulation can lead to path traversal. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| — | Drogon | 1.9.13-1; 10.0-beta.0; 10.0-beta.1; 10.0-beta.2; 10.0-beta.3 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-105144?
How severe is CVE-2026-105144?
How do I fix CVE-2026-105144?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-105133A vulnerability was detected in Ahsay AhsayCBS up to 10.3.2.…7.3
- CVE-2026-105134A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This v…10
- CVE-2026-105135A vulnerability has been found in InternLM MindSearch 0.1.0.…10
- CVE-2026-105137A vulnerability was found in Laradock up to 20.4. Impacted i…5
- CVE-2026-10514A vulnerability has been found in 1Panel-dev CordysCRM up to…2.4
- CVE-2026-105141A security flaw has been discovered in topoteretes cognee up…6.3
- CVE-2026-105145A vulnerability has been found in Weaviate Verba up to 2.1.3…5.3
- CVE-2026-105146A vulnerability was found in Comsenz Discuz! X5.0-20260801/X…4.7
- CVE-2026-105147A vulnerability was determined in SciPhi-AI R2R up to 3.6.6.…7.3
- CVE-2026-105148A vulnerability was identified in SciPhi-AI R2R up to 3.6.6.…7.3
- CVE-2026-105149A security flaw has been discovered in mooSocial up to 3.2.4…7.3
- CVE-2026-105156A weakness has been identified in YzmCMS up to 7.6. Impacted…3.7
Are you affected by CVE-2026-105144?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
