diff --git a/CVE-2026-29905.md b/CVE-2026-29905.md index f2c4310..b2a24e5 100644 --- a/CVE-2026-29905.md +++ b/CVE-2026-29905.md @@ -1,4 +1,5 @@ ![CVE](https://img.shields.io/badge/CVE-2026--29905-red) + # CVE-2026-29905 — Kirby CMS Persistent DoS via Malformed Image Upload > CVE-2026-29905 has been officially published by MITRE. @@ -7,10 +8,10 @@ A authenticated user with **Editor** permissions can upload a malformed file with an image extension to cause a persistent Denial of Service in Kirby CMS. -**CVE ID:** CVE-2026-29905 -**Affected Version:** Kirby CMS ≤ 5.1.4 -**Fixed In:** Kirby CMS 5.2.0-rc.1 -**Severity:** Medium +**CVE ID:** CVE-2026-29905 +**Affected Version:** Kirby CMS ≤ 5.1.4 +**Fixed In:** Kirby CMS 5.2.0-rc.1 +**Severity:** Medium **CWE:** CWE-252 (Unchecked Return Value), CWE-20 (Improper Input Validation) --- @@ -36,7 +37,7 @@ Patched in [Kirby CMS 5.2.0-rc.1](https://github.com/getkirby/kirby/releases/tag --- -# References +## References - [CVE-2026-29905 on cve.org](https://www.cve.org/CVERecord?id=CVE-2026-29905) - [CVE-2026-29905 on NVD](https://nvd.nist.gov/vuln/detail/CVE-2026-29905) diff --git a/README.md b/README.md new file mode 100644 index 0000000..4bd26b4 --- /dev/null +++ b/README.md @@ -0,0 +1,9 @@ +# CVE Research + +A collection of CVE disclosures by **Stalin S**. + +| CVE | Description | Severity | +|-----|-------------|----------| +| [CVE-2026-29905](CVE-2026-29905.md) | Kirby CMS — Persistent DoS via Malformed Image Upload | Medium | +| [CVE-2026-41037](CVE-2026-41037.md) | Quantum Networks Router — Missing Rate Limiting | High | +| [CVE-2026-41039](CVE-2026-41039.md) | Quantum Networks Router — Information Disclosure | High |