CVE-2026-1810
published 2026-02-03CVE-2026-1810: A vulnerability was detected in bolo-blog bolo-solo up to 2.6.4. The impacted element is the function unpackFilteredZip of the file…
PriorityP359high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.41%
34.8th percentile
A vulnerability was detected in bolo-blog bolo-solo up to 2.6.4. The impacted element is the function unpackFilteredZip of the file src/main/java/org/b3log/solo/bolo/prop/BackupService.java of the component ZIP File Handler. Performing a manipulation of the argument File results in path traversal. The attack is possible to be carried out remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adlered | bolo-solo | <= 2.6.4 | — |
| bolo-blog | bolo-solo | — | — |
| bolo-blog | bolo-solo | — | — |
| bolo-blog | bolo-solo | — | — |
| bolo-blog | bolo-solo | — | — |
| bolo-blog | bolo-solo | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.02.1LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8gmc-c3g8-vc4p: A vulnerability was detected in bolo-blog bolo-solo up to 2
ghsa_unreviewed·2026-02-03
CVE-2026-1810 [MEDIUM] CWE-22 GHSA-8gmc-c3g8-vc4p: A vulnerability was detected in bolo-blog bolo-solo up to 2
A vulnerability was detected in bolo-blog bolo-solo up to 2.6.4. The impacted element is the function unpackFilteredZip of the file src/main/java/org/b3log/solo/bolo/prop/BackupService.java of the component ZIP File Handler. Performing a manipulation of the argument File results in path traversal. The attack is possible to be carried out remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Red Hat
kernel: riscv: mm: Fix out-of-bounds page-table walk during memory hot-remove
vendor_redhat·2026-08-15·CVSS 5.5
CVE-2026-74524 [MEDIUM] CWE-787 kernel: riscv: mm: Fix out-of-bounds page-table walk during memory hot-remove
kernel: riscv: mm: Fix out-of-bounds page-table walk during memory hot-remove
In the Linux kernel, the following vulnerability has been resolved:
riscv: mm: Fix out-of-bounds page-table walk during memory hot-remove
remove_pud_mapping() and remove_p4d_mapping() obtain a child table base
with pud_offset(p4dp, 0) and p4d_offset(pgd, 0), then add the index for
addr.
RISC-V folds page-table levels at runtime. When a level is folded, its
offset helper returns the parent entry itself, but the index can still be
nonzero. Adding it walks past the parent table. Sv48 folds P4D, while Sv39
folds both P4D and PUD, so memory hot-remove can descend into unrelated
memory and pass an invalid page to __free_pages(). This can trigger:
kernel BUG at include/linux/mm.h:1810!
VM_BUG_ON_PAGE(page_ref_count(pag
No detection rules found.
No public exploits indexed.
2026-02-03
Published