CVE detail
CVE-2026-19000
A vulnerability was identified in JeecgBoot up to 3.9.2. The affected element is an unknown function of the file /airag/chat/send of the component Anonymous Chat Attachment Parser. The manipulation leads to server-side request forgery. The attack can be initiated remotely. The exploit is publicly available and might be used. A fix is planned for the upcoming release.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 20.8 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 7
- within the 30d window
- Peak daily
- 7
- highest bucket
Evidence
Source links by recency
7 source links · newest first
- https://vuldb.com/vuln/386382/ctivuldb.com
No excerpt available.
Exploitvuldb.comAug 6, 2026, 6:16 AM - https://vuldb.com/vuln/386382vuldb.com
No excerpt available.
Exploitvuldb.comAug 6, 2026, 6:16 AM - https://vuldb.com/submit/862635vuldb.com
No excerpt available.
Exploitvuldb.comAug 6, 2026, 6:16 AM - https://vuldb.com/cve/CVE-2026-19000vuldb.com
No excerpt available.
Exploitvuldb.comAug 6, 2026, 6:16 AM No excerpt available.
Exploitgithub.comAug 6, 2026, 6:16 AMNo excerpt available.
Exploitgithub.comAug 6, 2026, 6:16 AM- https://github.com/jeecgboot/JeecgBoot/github.com
No excerpt available.
Exploitgithub.comAug 6, 2026, 6:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-73160CVSS 8.7 · High
Affected versions of cti-transmute contain an SSRF vulnerability in the /fetch_misp_event and /misp_search_events endpoints. The URL validation routine checked whether a supplie…
- CVE-2026-19516CVSS 9.1 · Critical
A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the grafana_api_request tool lets the caller also choose the HTTP m…
- CVE-2026-72916CVSS 6.3 · Medium
Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-beta.1, PrivateAddressCheck.private_address? in app/lib/priva…
- CVE-2026-72761CVSS 6.9 · Medium
The webhook URL validator in `website/notifications/webhooks.py` uses `ip.is_global` to reject non-public addresses after DNS resolution. IPv6 transition addresses (NAT64 `64:ff9b…
- CVE-2026-72591CVSS 7.7 · High
A server-side request forgery (SSRF) vulnerability in gabehf/Koito through v0.3.2 allows an authenticated user to make the server perform HTTP requests to arbitrary internal or ex…
- CVE-2026-72581CVSS 8.6 · High
A server-side request forgery (SSRF) vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker to make the Xiaomi smart speaker perform HTTP requests to…