CosmicBytez@CosmicBytezDisclosure
The advisory announces CVE‑2026‑34162, an unauthenticated HTTP proxy vulnerability that allows full SSRF, providing technical details but no patch or exploit information.
CVEFind.com@CveFindComPatch
FastGPT’s pre‑4.14.9.5 releases expose an unauthenticated HTTP testing endpoint; the vendor recommends updating to the latest version to remediate the flaw.
CVE@CVEnewPatch
FastGPT’s HTTP tools endpoint was exposed before version 4.14.9.5; this version’s release fixes the issue, providing an available patch.
The Hacker Wire@TheHackerWireDisclosure
FastGPT versions before 4.12.9.5 expose an HTTP tools test endpoint without authentication, creating a critical vulnerability.
0day Signal@0dayPublishingGeneral
The post references CVE‑2026‑34162, detailing an unauthenticated SSRF that can lead to RCE, but offers no PoC, exploit code, patch, or evidence of active exploitation.
CCB Alert@CCBalertPatch
FastGPT suffers a critical missing authentication flaw (CVE‑2026‑34162) that enables token exfiltration and arbitrary requests; an advisory urges users to apply the available patch immediately.
CTIWatch@ctiwatchcloudDisclosure
The post announces several newly disclosed vulnerabilities with very high CVSS scores, but provides no further details on exploitation, patches, or false positives.