go

github.com/cloudreve/Cloudreve/v4

View on go registry
29 Total advisories
29 Vulnerabilities
0 Malware

Dependency scanning

Check whether github.com/cloudreve/Cloudreve/v4 is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

HIGH 7.1
Go

CVE-2026-77633

Cloudreve: Storage-quota TOCTOU race allows quota bypass and storage-based denial of service

MEDIUM 6.5
Go

CVE-2026-79913

Cloudreve: SSRF guard bypass: checkIP does not decode IPv6-transition wrappers (NAT64, IPv4-compatible, 6to4) reaching internal and cloud-metadata addresses

LOW 3.8
Go

CVE-2026-77637

Cloudreve: Privilege Scope Bypass: State-Mutating Admin Operations Accessible via Read-Only OAuth Scope

UNKNOWN
Go

GO-2026-6289

Cloudreve's remote download file paths can escape the selected destination directory

HIGH 7.1
Go

CVE-2026-54563

Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root

UNKNOWN
Go

CVE-2026-54563

Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root in github.com/cloudreve/Cloudreve

MEDIUM 5.3
Go

GO-2026-6287

Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint

UNKNOWN
Go

GHSA-vx2m-jpxr-xv7w

Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint in github.com/cloudreve/Cloudreve

UNKNOWN
Go

GHSA-w8j7-39hp-8x59

Cloudreve's remote download file paths can escape the selected destination directory in github.com/cloudreve/Cloudreve

MEDIUM 5.4
Go

GO-2026-6106

Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests

MEDIUM 6.5
Go

CVE-2026-55497

Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server

MEDIUM 4.3
Go

CVE-2026-55499

Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and receives activity events for unshared siblings

MEDIUM 4.3
Go

CVE-2026-55496

Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails

MEDIUM 4.3
Go

CVE-2026-55495

Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account

HIGH 7.1
Go

CVE-2026-55502

Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials

MEDIUM 6.3
Go

CVE-2026-62323

Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored

UNKNOWN
Go

CVE-2026-55495

Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account in github.com/cloudreve/Cloudreve

UNKNOWN
Go

CVE-2026-55502

Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials in github.com/cloudreve/Cloudreve

UNKNOWN
Go

CVE-2026-55499

Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and receives activity events for unshared siblings in github.com/cloudreve/Cloudreve

UNKNOWN
Go

CVE-2026-55496

Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails in github.com/cloudreve/Cloudreve

UNKNOWN
Go

GHSA-v6w6-358x-2433

Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests in github.com/cloudreve/Cloudreve

UNKNOWN
Go

CVE-2026-55497

Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server in github.com/cloudreve/Cloudreve

UNKNOWN
Go

CVE-2026-62323

Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored in github.com/cloudreve/Cloudreve

HIGH 7.6
Go

CVE-2026-54560

Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim

MEDIUM 6.5
Go

CVE-2026-54562

Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses

UNKNOWN
Go

CVE-2026-54560

Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim in github.com/cloudreve/Cloudreve

UNKNOWN
Go

CVE-2026-54562

Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses in github.com/cloudreve/Cloudreve

HIGH 8.1
Go

CVE-2026-25726

Cloudreve is vulnerable to Account Takeover via Weak Cryptographic Token Generation (Insecure PRNG Seeding)

UNKNOWN
Go

CVE-2026-25726

Cloudreve is vulnerable to Account Takeover via Weak Cryptographic Token Generation (Insecure PRNG Seeding) in github.com/cloudreve/Cloudreve

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes