CVE-2026-7605Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A security flaw has been discovered in JeecgBoot up to 3.9.1. This vulnerability affects the function CommonController.uploadImgByHttp/HttpFileToMultipartFileUtil.httpFileToMultipartFile/HttpFileToMultipartFileUtil.downloadImageData of the file CommonController.java of the component uploadImgByHttpEndpoint. Performing a manipulation results in server-side request forgery. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. Upgrading the affected component is recommended. The vendor confirmed the issue and will provide a fix in the upcoming release.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-02: 3Technical Details · 2026-05-02: 305-02
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7605 Server-Side Request Forgery in JeecgBoot Up To 3.9.1 CommonController https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7605

    Post summary

    The entry announces a Server‑Side Request Forgery flaw (CVE‑2026‑7605) affecting JeecgBoot up to version 3.9.1, but provides no evidence of exploitation, PoC, or available fixes.

    0000054
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-7605 A security flaw has been discovered in JeecgBoot up to 3.9.1. This vulnerability affects the function CommonController.uploadImgByHttp/HttpFileToMultipartFileUtil.httpF… https://www.cve.org/CVERecord?id=CVE-2026-7605 ----- Traducción: CVE-2026-7605 Se … http://infoflow.cloud`

    Post summary

    Disclosed a security flaw in JeecgBoot affecting specific upload functions, with reference to the CVE record, but without PoC, exploit, or mitigation details.

    0000030
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7605 A security flaw has been discovered in JeecgBoot up to 3.9.1. This vulnerability affects the function CommonController.uploadImgByHttp/HttpFileToMultipartFileUtil.httpF… https://www.cve.org/CVERecord?id=CVE-2026-7605

    Post summary

    A new vulnerability (CVE‑2026‑7605) has been identified in JeecgBoot up to version 3.9.1, affecting a specific upload function; no PoC, exploit, or patch details are provided.

    00000185
    57.4K followersView on X

Explore more