CVE-2026-1813
published 2026-02-04CVE-2026-1813: A vulnerability was found in bolo-blog bolo-solo up to 2.6.4. Affected is an unknown function of the file…
PriorityP260critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.35%
28.3th percentile
A vulnerability was found in bolo-blog bolo-solo up to 2.6.4. Affected is an unknown function of the file src/main/java/org/b3log/solo/bolo/pic/PicUploadProcessor.java of the component FreeMarker Template Handler. The manipulation of the argument File results in unrestricted upload. It is possible to launch the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adlered | bolo-solo | <= 2.6.4 | — |
| bolo-blog | bolo-solo | — | — |
| bolo-blog | bolo-solo | — | — |
| bolo-blog | bolo-solo | — | — |
| bolo-blog | bolo-solo | — | — |
| bolo-blog | bolo-solo | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.02.1LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_redhat7.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2hmq-qjp7-8j88: A vulnerability was found in bolo-blog bolo-solo up to 2
ghsa_unreviewed·2026-02-04
CVE-2026-1813 [MEDIUM] CWE-284 GHSA-2hmq-qjp7-8j88: A vulnerability was found in bolo-blog bolo-solo up to 2
A vulnerability was found in bolo-blog bolo-solo up to 2.6.4. Affected is an unknown function of the file src/main/java/org/b3log/solo/bolo/pic/PicUploadProcessor.java of the component FreeMarker Template Handler. The manipulation of the argument File results in unrestricted upload. It is possible to launch the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
Red Hat
kernel: nfsd: reset write verifier on deferred writeback errors
vendor_redhat·2026-07-19·CVSS 7.0
CVE-2026-53393 [MEDIUM] CWE-390 kernel: nfsd: reset write verifier on deferred writeback errors
kernel: nfsd: reset write verifier on deferred writeback errors
In the Linux kernel, the following vulnerability has been resolved:
nfsd: reset write verifier on deferred writeback errors
nfsd_vfs_write() and nfsd_commit() both call filemap_check_wb_err() to
detect deferred writeback errors, but neither rotates the server's write
verifier (nn->writeverf) when this check fails. Every other
durable-storage-failure path in these functions calls
commit_reset_write_verifier() before returning an error.
The missing rotation means clients holding UNSTABLE write data under the
current verifier will COMMIT, receive the unchanged verifier back, and
conclude their data is durable — silently dropping data that failed
writeback. This violates the UNSTABLE+COMMIT durability contract
(RFC 1813 §3.3.7, R
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-02-04
Published