HIGH7.5Go
GHSA-2g4x-fq3j-cgq4· CVE-2026-45090, GO-2026-4999Dalfox has an Unauthenticated Remote DoS via Closed-Channel Write in `ParameterAnalysis` (server mode)
Modified: 6/8/2026
package
pkg:go/github.com/hahwul/dalfox
Dalfox has an Unauthenticated Remote DoS via Closed-Channel Write in `ParameterAnalysis` (server mode)
Modified: 6/8/2026
Dalfox has an Unauthenticated Remote DoS via Closed-Channel Write in `ParameterAnalysis` (server mode) in github.com/hahwul/dalfox
Modified: 5/20/2026
Dalfox Server Mode has an Unauthenticated Arbitrary File Read with Out-of-Band Exfiltration via `custom-payload-file` in github.com/hahwul/dalfox
Modified: 6/25/2026
Dalfox Server Mode has an Unauthenticated Arbitrary File Create/Append via `output` Option in github.com/hahwul/dalfox
Modified: 6/25/2026
Dalfox Server Mode Vulnerable to Unauthenticated Remote Code Execution via `found-action` in github.com/hahwul/dalfox
Modified: 6/25/2026