قاعدة الثغرات (CVE)
CVE-2026-28318
استهلاك موارد غير محكوم يُسقط SolarWinds Serv-U
عاليةمُستغلة فعليًاKEVالتصحيح متوفر: غير متوفر بعد
طلبات POST مصمَّمة برأس Content-Encoding: deflate تُسقط خدمة Serv-U دون مصادقة — ثغرة حجب خدمة في خادم نقل الملفات المؤسسي.
SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure customer environments in the SolarWinds Trust Center if you are unable to deploy the update
المنتجات المتأثرة
| Product | الإصدارات المتأثرة | تم الإصلاح في |
|---|---|---|
| Serv-U | — | — |
التغطية على سيبرانا
—