Логотип exploitDog
bind:CVE-2026-25628
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-25628

Количество 2

Количество 2

nvd логотип

CVE-2026-25628

2 дня назад

Qdrant is a vector similarity search engine and vector database. From 1.9.3 to before 1.16.0, it is possible to append to arbitrary files via /logger endpoint using an attacker-controlled on_disk.log_file path. Minimal privileges are required (read-only access). This vulnerability is fixed in 1.16.0.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-f632-vm87-2m2f

3 дня назад

qdrant has arbitrary file write via `/logger` endpoint

CVSS3: 8.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-25628

Qdrant is a vector similarity search engine and vector database. From 1.9.3 to before 1.16.0, it is possible to append to arbitrary files via /logger endpoint using an attacker-controlled on_disk.log_file path. Minimal privileges are required (read-only access). This vulnerability is fixed in 1.16.0.

CVSS3: 8.5
0%
Низкий
2 дня назад
github логотип
GHSA-f632-vm87-2m2f

qdrant has arbitrary file write via `/logger` endpoint

CVSS3: 8.5
0%
Низкий
3 дня назад

Уязвимостей на страницу