9router
Decolua · 21 CVEs
decolua 9Router Search Endpoint ssrfGuard.js fetch server-side request forgery
Sep 30, 2026
9Router: Login Brute-Force Lockout Bypass via Spoofable X-9r-Real-Ip Header
Sep 22, 2026
9Router: Authentication Bypass in Public LLM API via Spoofable X-9r-Real-Ip Header
Sep 22, 2026
9router Server-Side Request Forgery via /api/provider-nodes/validate Because the IPv4-Mapped IPv6 Denylist Check Is Unr…
Aug 20, 2026
9Router: Authenticated Server-Side Request Forgery (SSRF) via OIDC Provider Test Endpoint
Aug 17, 2026
9router before 0.4.60 Remote Code Execution via default password
Jul 23, 2026
9Router before 0.4.72 Server-Side Request Forgery via /v1/web/fetch
Jul 23, 2026
9Router: Authenticated RCE via Unvalidated MCP Plugin Arguments
Jul 15, 2026
9Router: Kiro region injection allows authenticated SSRF with Authorization header forwarding
Jul 15, 2026
9Router: Mass assignment in PATCH /api/settings allows authenticated authorization downgrade
Jul 15, 2026
9Router: Local-Only Access Gate Bypass in 9router via Host Header SpoofING
Jul 15, 2026
9Router: Hardcoded Default fallback JWT Secret Allows Authentication Bypass
Jul 15, 2026
9Router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes
Jul 15, 2026
9Router 0.4.41 - Unauthenticated Information Disclosure via API Usage Endpoints
Jul 13, 2026
9Router 0.4.41 - Unauthenticated API Key Exposure via /api/usage/stats
Jul 13, 2026
9Router 0.4.41 - Unauthenticated API Exposure via /api/providers
Jul 13, 2026
9router: Reverse proxy locality collapse allows unauthenticated access to 9router /v1 APIs
Jul 10, 2026
9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass
Jul 10, 2026
9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF
Jul 10, 2026
9router: Image prefetch DNS rebinding allows SSRF to internal services
Jul 10, 2026
9router: Exposure of Sensitive Information and Unprotected Database Import/Export Allows Complete Credential Theft and…
Jul 10, 2026
9router: Login brute-force protection bypass via spoofed X-Forwarded-For header
Jul 10, 2026
9Router < 0.4.44 - OS Command Injection via sudoPassword Parameter in Tailscale Install Endpoint
Jul 7, 2026
decolua 9router HTTP Header dashboardGuard.js isAuthenticated improper authorization
Jun 1, 2026
decolua 9router Administrative API Endpoint api authorization
Apr 9, 2026
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-103530 | decolua 9Router Search Endpoint ssrfGuard.js fetch server-side request forgery | MEDIUM | 0.30% | Sep 30, 2026 |
| CVE-2026-56682 | 9Router: Login Brute-Force Lockout Bypass via Spoofable X-9r-Real-Ip Header | MEDIUM | 0.47% | Sep 22, 2026 |
| CVE-2026-56681 | 9Router: Authentication Bypass in Public LLM API via Spoofable X-9r-Real-Ip Header | HIGH | 0.97% | Sep 22, 2026 |
| CVE-2026-72860 | 9router Server-Side Request Forgery via /api/provider-nodes/validate Because the IPv4-Mapped IPv6 Denylist Check Is Unreachable | MEDIUM | 0.38% | Aug 20, 2026 |
| CVE-2026-56677 | 9Router: Authenticated Server-Side Request Forgery (SSRF) via OIDC Provider Test Endpoint | HIGH | 0.38% | Aug 17, 2026 |
| CVE-2026-63732 | 9router before 0.4.60 Remote Code Execution via default password | CRITICAL | 1.01% | Jul 23, 2026 |
| CVE-2026-63313 | 9Router before 0.4.72 Server-Side Request Forgery via /v1/web/fetch | HIGH | 0.46% | Jul 23, 2026 |
| CVE-2026-62312 | 9Router: Authenticated RCE via Unvalidated MCP Plugin Arguments | HIGH | 1.30% | Jul 15, 2026 |
| CVE-2026-56678 | 9Router: Kiro region injection allows authenticated SSRF with Authorization header forwarding | MEDIUM | 0.29% | Jul 15, 2026 |
| CVE-2026-56679 | 9Router: Mass assignment in PATCH /api/settings allows authenticated authorization downgrade | HIGH | 0.52% | Jul 15, 2026 |
| CVE-2026-49353 | 9Router: Local-Only Access Gate Bypass in 9router via Host Header SpoofING | HIGH | 0.36% | Jul 15, 2026 |
| CVE-2026-49352 | 9Router: Hardcoded Default fallback JWT Secret Allows Authentication Bypass | CRITICAL | 0.60% | Jul 15, 2026 |
| CVE-2026-46339 | 9Router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes | CRITICAL | 3.35% | Jul 15, 2026 |
| CVE-2026-62328 | 9Router 0.4.41 - Unauthenticated Information Disclosure via API Usage Endpoints | HIGH | 0.62% | Jul 13, 2026 |
| CVE-2026-62327 | 9Router 0.4.41 - Unauthenticated API Key Exposure via /api/usage/stats | CRITICAL | 0.64% | Jul 13, 2026 |
| CVE-2026-59801 | 9Router 0.4.41 - Unauthenticated API Exposure via /api/providers | CRITICAL | 2.91% | Jul 13, 2026 |
| CVE-2026-56675 | 9router: Reverse proxy locality collapse allows unauthenticated access to 9router /v1 APIs | HIGH | 0.50% | Jul 10, 2026 |
| CVE-2026-55638 | 9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass | HIGH | 0.61% | Jul 10, 2026 |
| CVE-2026-55641 | 9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF | HIGH | 0.32% | Jul 10, 2026 |
| CVE-2026-56676 | 9router: Image prefetch DNS rebinding allows SSRF to internal services | HIGH | 0.26% | Jul 10, 2026 |
| CVE-2026-55500 | 9router: Exposure of Sensitive Information and Unprotected Database Import/Export Allows Complete Credential Theft and Database Takeover | CRITICAL | 0.69% | Jul 10, 2026 |
| CVE-2026-55501 | 9router: Login brute-force protection bypass via spoofed X-Forwarded-For header | HIGH | 0.52% | Jul 10, 2026 |
| CVE-2026-59800 | 9Router < 0.4.44 - OS Command Injection via sudoPassword Parameter in Tailscale Install Endpoint | CRITICAL | 2.04% | Jul 7, 2026 |
| CVE-2026-10269 | decolua 9router HTTP Header dashboardGuard.js isAuthenticated improper authorization | MEDIUM | 0.28% | Jun 1, 2026 |
| CVE-2026-5842 | decolua 9router Administrative API Endpoint api authorization | MEDIUM | 0.54% | Apr 9, 2026 |
Showing 1 to 21 of 21 CVEs