CVE-2026-44425Patch(shellhub / shellhub)

LOWCVSS 5.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch shellhub shellhub systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

ShellHub is a centralized SSH gateway. Prior to 0.24.2, the device list endpoint accepts user-controlled identifiers in the the name field of each filter property in the base64-encoded filter query parameter and the sort_by query parameter, which are then passed directly as BSON/SQL keys in the database layer without validation. Any authenticated user can craft payloads that cause the aggregation / query to fail and the API to return HTTP 500 with no body, with no rate limiting applied. This vulnerability is fixed in 0.24.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-943CWE-1333

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • shellhub

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-13); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
shellhub

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-13: 1Mentions · 2026-05-14: 1Patch / Workaround · 2026-05-13: 1Technical Details · 2026-05-13: 1Technical Details · 2026-05-14: 105-1305-14
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-131
Patch1
2026-05-141
Disclosure1
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-44425 Unauthenticated NoSQL Injection in ShellHub SSH Gateway Versions Below 0.24.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-44425

    Post summary

    CVE‑2026‑44425 is a newly disclosed unauthenticated NoSQL injection vulnerability affecting ShellHub SSH Gateway versions below 0.24.2; the text provides the vulnerability type and affected versions, but no PoC, exploit, patch, or evidence of active exploitation.

    0101055
    4.0K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-44425 ShellHub is a centralized SSH gateway. Prior to 0.24.2, the device list endpoint accepts user-controlled identifiers in the the name field of each filter property in … https://www.cve.org/CVERecord?id=CVE-2026-44425

    Post summary

    CVE-2026-44425 allows user‑controlled identifiers in ShellHub’s device list endpoint, and the issue is resolved in release 0.24.2.

    00000115
    57.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appshellhubshellhub---

Explore more