FixVibe

// 脆弱性リサーチ

AI で構築されたウェブサイトとアプリのための脆弱性リサーチ。

AI 生成のウェブアプリ、BaaS スタック、フロントエンドバンドル、認証、依存関係セキュリティに関連する脆弱性についての出典付きノート。

研究記事には、公開されている脆弱性の傾向がまとめられています。スキャン範囲は、FixVibe チェックがすでに利用可能な場合にのみ説明されます。
60
公開済み
60
ライブチェック
60
一致
最新のリサーチFixVibe がカバーhigh

runc ファイル記述子リークによるコンテナ ブレークアウト (CVE-2024-21626)

CVE-2024-21626 は、悪意のあるイメージやコンテナ プロセスがホスト ファイル システムに到達する可能性がある、重大度の高い runc ファイル記述子リークです。 FixVibe リポジトリ スキャンは、ソースの証拠をデプロイされたランタイムの悪用可能性から明確に分離しながら、ブレイクアウト条件に関連付けられたコンテナーの作業ディレクトリ構成にフラグを立てるようになりました。

記事を読む

すべてのリサーチ

60 件の記事

FixVibe がカバーcriticalJul 25, 2026

MLflow ジョブ エンドポイントでの認証バイパス (CVE-2026-0545)

CVE-2026-0545 は、Basic 認証とジョブの実行が有効になっている場合に FastAPI ジョブ ルートに影響を与える MLflow 認証境界の欠陥です。 FixVibe は、ジョブの一覧表示、読み取り、送信、実行、検索、キャンセルを行わずに、欠落している認証境界を確認する、検証済みの読み取り専用アクティブ チェックでこの露出をカバーするようになりました。

CVE-2026-0545CWE-306
リサーチを表示
FixVibe がカバーhighJul 25, 2026

CVE-2025-56005: PLY における安全でない逆シリアル化のリスクが議論されています

PLY パーサー構築では、Python pickle を介してパーサー テーブルをロードすることを選択できます。これがコード実行のリスクとなるのは、信頼性の低いアクターが既存の pickle ファイルまたはそのパスに影響を与える可能性がある場合に限られます。 CVE-2025-56005 は議論されているため、FixVibe は、元の重要な RCE 主張を証明されたものとして扱うのではなく、明示的なリポジトリ構成を問題の可能性があるとして報告しています。

CVE-2025-56005GHSA-qc6m-pwr3-g72pCWE-502
リサーチを表示
FixVibe がカバーhighJul 20, 2026

Next.js WebSocket SSRF 脆弱性 (CVE-2026-44578)

CVE-2026-44578 これは、組み込みの Next.js サーバー。 Vercel-hosted デプロイメントには影響しません。 FixVibe 影響を受けた依存関係の証拠を承認された形式で報告するようになりました GitHub リポジトリ スキャンは、実際の悪用の証拠ではなく、バージョンベースの勧告として行われます。

CVE-2026-44578GHSA-c4j6-fc7j-m34rGHSA-c4j6-fc7j-m34r
リサーチを表示
FixVibe がカバーhighJul 20, 2026

Apache ActiveMQ Artemis リソース消費によるサービス拒否 (CVE-2022-23913)

CVE-2022-23913 重大度は高いです Apache ActiveMQ Artemis 制御されていないメモリ消費に関連する可用性の問題。 FixVibe 現在、影響を受けていると報告されています org.apache.activemq:artemis-core-client ブローカーに接続したり、サービス拒否を試行したりすることなく、承認されたリポジトリ スキャンで依存関係の証拠を収集します。

CVE-2022-23913GHSA-pr38-qpxm-g88xGHSA-pr38-qpxm-g88x
リサーチを表示
FixVibe がカバーhighJul 20, 2026

条件付き NGINX HTTP/2 および gRPC プロキシ バッファ オーバーフロー (CVE-2026-42055)

CVE-2026-42055 は、NGINX HTTP/2 および gRPC アップストリーム プロキシにおける条件付きヒープベースのバッファ オーバーフローです。 F5 では CVSS v3.1 で 8.1 High とスコア付けされていますが、nginx.org では Medium に分類されています。悪用には、特大のクライアント ヘッダー バッファーなど、いくつかの一般的ではない構成の前提条件が必要です。ワーカーの再起動は文書化された直接的な影響であり、コードの実行にはさらに ASLR を無効にするかバイパスする必要があります。 FixVibe は、影響を受ける公式 NGINX オープン ソース コンテナ デプロイメントに関する保守的なリポジトリ証拠を報告し、危険なアクティブ プルーフは実行しません。

CVE-2026-42055CWE-122CWE-787
リサーチを表示
FixVibe がカバーcriticalJul 20, 2026

vLLM ビデオ処理 RCE アドバイザリー (CVE-2026-22778)

CVE-2026-22778 は、展開でビデオ対応モデルを提供し、攻撃者が制御するビデオ入力を処理する場合、0.8.3 から 0.14.0 までの vLLM リリースに影響します。 vLLM 0.14.1 ではこの問題が修正されています。 FixVibe は、ライブエクスプロイトの確認ではなく、安全なリポジトリの依存関係の証拠を報告します。

CVE-2026-22778GHSA-4r2x-xpjr-7cvvPYSEC-2026-565
リサーチを表示
FixVibe がカバーcriticalJul 20, 2026

ChromaDB Python バックエンド事前認証 RCE (CVE-2026-45829)

CVE-2026-45829 は、攻撃者が制御する埋め込み設定が承認前に処理されると、ChromaDB's optional Python FastAPI backend に影響します。 デフォルトの Rust フロントエンドは影響を受けません。

CVE-2026-45829CWE-94CWE-502
リサーチを表示
FixVibe がカバーhighJun 11, 2026

Mbed TLS Double-Free Vulnerability (CVE-2021-44732)

CVE-2021-44732 affects older Mbed TLS releases in a session-handling error path. FixVibe repo scans can now flag affected version evidence in source and build metadata, while making clear that the scan did not run Mbed TLS, force out-of-memory behavior, or prove exploitation.

CVE-2021-44732GHSA-7g56-f7p4-fmcqCWE-415
リサーチを表示
FixVibe がカバーcriticalJun 10, 2026

Missing Authentication in Moxa NPort Series Devices (CVE-2016-9369)

Moxa NPort serial device servers before vendor fixed firmware releases are associated with CVE-2016-9369. FixVibe can flag strong HTTP model and firmware-version evidence as a version-based advisory during verified active scans without attempting firmware updates, unauthenticated administrative actions, or exploit confirmation.

CVE-2016-9369CWE-287CWE-306
リサーチを表示
FixVibe がカバーcriticalJun 10, 2026

Schneider Electric Modicon M221 Authentication Replay Advisory (CVE-2018-7790)

FixVibe can flag public Modicon M221 HTTP product and firmware-version evidence associated with CVE-2018-7790 as a version-based advisory. The scan does not replay authentication, query industrial protocols, upload PLC programs, or prove unauthorized access.

CVE-2018-7790CWE-294
リサーチを表示
FixVibe がカバーcriticalJun 10, 2026

Langflow CORS Misconfiguration Enables Account Takeover and RCE (CVE-2025-34291)

GitHub, NVD, and CISA describe CVE-2025-34291 as a critical Langflow CORS issue affecting versions 1.6.9 and earlier. FixVibe covers it with a verified-target check that combines Langflow version and fingerprint evidence with credentialed CORS header reflection, without authenticating, reading tokens, triggering refresh flows, or proving code execution.

CVE-2025-34291GHSA-577h-p2hh-v4mvCWE-346
リサーチを表示
FixVibe がカバーhighJun 10, 2026

PickleScan ZIP Archive Scan Bypass (CVE-2025-10156)

FixVibe can flag repositories that declare PickleScan versions before 0.0.31, which public advisories associate with a ZIP archive scan-bypass issue. The scanner reports dependency evidence, affected range, fixed version, confidence, and what was not verified; it does not run PickleScan, create corrupted archives, load models, or prove code execution.

CVE-2025-10156GHSA-mjqp-26hc-grxgPYSEC-2025-152
リサーチを表示
FixVibe がカバーcriticalJun 10, 2026

Malware in @tanstack/arktype-adapter Exfiltrates Credentials (CVE-2026-45321)

The TanStack npm supply-chain compromise included @tanstack/arktype-adapter versions 1.166.12 and 1.166.15. These package versions contained embedded malware; teams should remove them, rebuild cached install environments, and rotate credentials if either version was installed.

CVE-2026-45321GHSA-g7cv-rxg3-hmpxCWE-506
リサーチを表示
FixVibe がカバーcriticalJun 9, 2026

Arbitrary Code Execution in NLTK via Zip Slip (CVE-2025-14009)

NLTK versions through 3.9.2 are associated with CVE-2025-14009, a downloader Zip Slip advisory that can lead to arbitrary code execution when malicious or compromised packages are extracted. Upgrade to 3.9.3 or newer.

CVE-2025-14009GHSA-7p94-766c-hgjpPYSEC-2026-96
リサーチを表示
FixVibe がカバーhighJun 9, 2026

Apache Tomcat Sensitive Information Disclosure (CVE-2021-25122)

Apache Tomcat h2c request handling in affected 8.5.x, 9.0.x, and 10.0.x release lines can mix request headers and limited body data between users. Upgrade to 8.5.63, 9.0.43, 10.0.2, or newer for the release line in use.

CVE-2021-25122GHSA-j39c-c8hj-x4j3CWE-200
リサーチを表示
FixVibe がカバーhighJun 4, 2026

Information Disclosure via Undocumented TRACK Method in Microsoft IIS 5.0

CVE-2003-1567 covers Microsoft IIS 5.0 TRACK behavior that can echo request content. FixVibe now reports this as a verified active-scan finding when target-specific, non-sensitive evidence shows legacy TRACK echo behavior, while clearly separating that evidence from proof of cookie theft or compromise.

CVE-2003-1567CWE-200
リサーチを表示
FixVibe がカバーcriticalJun 4, 2026

Stack-Based Buffer Overflow in Orpak SiteOmat CGI Components (CVE-2017-14854)

FixVibe verified active scans can now identify strong Orpak SiteOmat BOS product and version evidence associated with CVE-2017-14854. Findings are reported as version-based advisories: FixVibe verifies the exposed SiteOmat version, not CGI crash behavior or code execution.

CVE-2017-14854CWE-119CWE-121
リサーチを表示
FixVibe がカバーhighJun 4, 2026

Microsoft ATL COM Initialization Advisory (CVE-2009-2493)

Microsoft ATL components and controls built with affected ATL headers can be exposed to CVE-2009-2493 under COM initialization conditions. FixVibe now treats this as covered by its repo source/build advisory for legacy Visual C++ ATL projects, without claiming build-machine patch state, deployed ActiveX or COM exposure, or live code-execution proof.

CVE-2009-2493CWE-264CWE-94
リサーチを表示
FixVibe がカバーhighJun 4, 2026

Apache Tomcat EncryptInterceptor Bypass (CVE-2026-34486)

FixVibe covers CVE-2026-34486 as a repo-scan version advisory for exact Apache Tomcat releases, while keeping clustering and plaintext-disclosure conditions explicit.

CVE-2026-34486GHSA-69r9-qgr7-g2wjCWE-311
リサーチを表示