Boletines de Vulnerabilidades

CVE-2026-45627

   
Software afectado DOCKER
 
Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, the unauthenticated GET /api/app-images/logo endpoint reflects a user-supplied color query parameter into the body of an SVG document via strings.ReplaceAll with no escaping. The substitution lands inside a

Link:

https://nvd.nist.gov/vuln/detail/CVE-2026-45627