Inteligencia de amenazas

Vulnerabilidades en seguimiento

Monitoreamos continuamente la evolución de las amenazas y vulnerabilidades que pueden afectar a las tecnologías utilizadas por las organizaciones.

Cómo leer esta sección

Cada aviso se identifica con un código CVE. La severidad corresponde al puntaje CVSS publicado por la fuente. El riesgo y la recomendación son una orientación general de Gonard según esa severidad; la prioridad real depende de si el producto está presente y expuesto en su infraestructura.

9.0+Crítica7.0+Alta4.0+Media0.1+Baja
CVE-2026-107724 —En análisis Parche disponible

fast-jwt treats raw public JWK JSON as an HMAC secret, enabling HS256 token forgery

Descripción técnica (fuente, en inglés)

fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.2.4, fast-jwt can classify raw serialized public JWK or JWKS JSON as an HMAC secret because src/crypto.js performDetectPublicKeyAlgorithms treats non-PEM strings as symmetric key material. If HS256 is explicitly allowed or inferred, an attacker who knows the exact serialized public-key bytes can use those bytes as an HMAC key and create a token containing arbitrary claims that createVerifier accepts. Serialization ordering or whitespace differences can prevent exploitation, and applications using supported PEM keys with an asymmetric-only algorithm allowlist are not affected. This issue is fixed in version 6.3.0.

Riesgo
Sin puntaje CVSS asignado todavía por la fuente.
Recomendación
Seguir la evolución del aviso y consultar al fabricante del producto.
Publicado Oct. 8, 2026, 9:53 p.m. · Fuente cvefeed.io
CVE-2026-107831 5.3Media En seguimiento

Jivejdon through 5.0 CSRF via GET-based Account and Thread Actions

Descripción técnica (fuente, en inglés)

Jivejdon through 5.0 contains a cross-site request forgery vulnerability that allows remote attackers to perform state-changing actions by abusing GET endpoints lacking anti-CSRF tokens. Attackers can lure authenticated users to crafted links targeting /account/protected/delAll, /account/protected/sub/delSub, or /message/updateAction to delete private messages and subscriptions or rename threads.

Riesgo
Requiere condiciones específicas para ser explotada; el impacto suele ser acotado.
Recomendación
Incluir en el ciclo regular de actualizaciones y verificar configuraciones relacionadas.
Publicado Oct. 8, 2026, 9:51 p.m. · Fuente cvefeed.io
CVE-2026-107830 6.9Media En seguimiento

Jivejdon through commit ee67a65e Missing Rate Limiting via /account/smsVRAction SMS Endpoint

Descripción técnica (fuente, en inglés)

Jivejdon from commit e0306088 through commit ee67a65e lacks rate limiting on the unauthenticated /account/smsVRAction endpoint handled by SmsQQAction, allowing unlimited SMS sending. Attackers can load newAccount.jsp to set session attributes, then repeatedly call the endpoint to harass arbitrary phone numbers and exhaust the operator's Tencent Cloud SMS balance.

Riesgo
Requiere condiciones específicas para ser explotada; el impacto suele ser acotado.
Recomendación
Incluir en el ciclo regular de actualizaciones y verificar configuraciones relacionadas.
Publicado Oct. 8, 2026, 9:51 p.m. · Fuente cvefeed.io
CVE-2026-107829 8.2Alta En seguimiento

Jivejdon through 5.0 Unsalted MD5 Password Storage via AccountDaoSql

Descripción técnica (fuente, en inglés)

Jivejdon through 5.0 contains a weak password storage vulnerability that stores account passwords as unsalted MD5 digests via ToolsUtil.hash() in AccountDaoSql. Attackers who obtain the user table through database access or SQL injection can crack passwords with precomputed tables or GPU attacks.

Riesgo
Puede comprometer la confidencialidad, integridad o disponibilidad del sistema afectado.
Recomendación
Planificar la actualización en el corto plazo y revisar la exposición del servicio a Internet.
Publicado Oct. 8, 2026, 9:51 p.m. · Fuente cvefeed.io
CVE-2026-107828 6.9Media En seguimiento

Jivejdon through 5.0 Predictable Passwords via Sina Weibo OAuth Login

Descripción técnica (fuente, en inglés)

Jivejdon through 5.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to access Weibo-created accounts by deriving predictable credentials from public Weibo user IDs. OAuthAccountServiceImp.transferSina() sets the password to the first four digits of the Weibo ID, letting attackers log in through normal form login to read or post as victims.

Riesgo
Requiere condiciones específicas para ser explotada; el impacto suele ser acotado.
Recomendación
Incluir en el ciclo regular de actualizaciones y verificar configuraciones relacionadas.
Publicado Oct. 8, 2026, 9:51 p.m. · Fuente cvefeed.io
CVE-2026-107801 5.4Media En seguimiento

Jivejdon through 5.0 Stored XSS via Attachment Upload Content-Type

Descripción técnica (fuente, en inglés)

Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to execute JavaScript by uploading attachments with an attacker-supplied Content-Type. Attackers can upload a file declared as text/html, which UploadShowAction serves inline, and share its link to run JavaScript on the application's origin for viewing users.

Riesgo
Requiere condiciones específicas para ser explotada; el impacto suele ser acotado.
Recomendación
Incluir en el ciclo regular de actualizaciones y verificar configuraciones relacionadas.
Publicado Oct. 8, 2026, 9:51 p.m. · Fuente cvefeed.io
CVE-2026-107800 5.4Media En seguimiento

Jivejdon through 5.0 Stored XSS via Private Short Messages

Descripción técnica (fuente, en inglés)

Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject script into private short messages because receiveshortmessage.jsp renders unfiltered message bodies. Attackers can send a short message containing script, which ToolsUtil.convertURL() passes through unchanged, to execute code in the recipient's browser when opened.

Riesgo
Requiere condiciones específicas para ser explotada; el impacto suele ser acotado.
Recomendación
Incluir en el ciclo regular de actualizaciones y verificar configuraciones relacionadas.
Publicado Oct. 8, 2026, 9:51 p.m. · Fuente cvefeed.io
CVE-2026-107799 5.4Media En seguimiento

Jivejdon through 5.0 Stored XSS via messageListBody.jsp Forum Message Rendering

Descripción técnica (fuente, en inglés)

Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject script by posting unsanitized forum message bodies. Message bodies are rendered by messageListBody.jsp with filter="false" and non-escaping default filters, executing script in the browser of every user viewing the thread.

Riesgo
Requiere condiciones específicas para ser explotada; el impacto suele ser acotado.
Recomendación
Incluir en el ciclo regular de actualizaciones y verificar configuraciones relacionadas.
Publicado Oct. 8, 2026, 9:51 p.m. · Fuente cvefeed.io
CVE-2026-107798 5.4Media En seguimiento

Jivejdon through commit ee67a65e Stored XSS via Markdown Links in TextStyle Rendering Filter

Descripción técnica (fuente, en inglés)

jivejdon from commit 595d8d22 through commit ee67a65e contains a stored cross-site scripting vulnerability in the default-enabled TextStyle filter that inserts unvalidated URLs into anchor href attributes. Authenticated attackers can post messages with javascript: links or quote-breaking URLs to execute JavaScript when other users click or hover over rendered links.

Riesgo
Requiere condiciones específicas para ser explotada; el impacto suele ser acotado.
Recomendación
Incluir en el ciclo regular de actualizaciones y verificar configuraciones relacionadas.
Publicado Oct. 8, 2026, 9:51 p.m. · Fuente cvefeed.io
CVE-2026-107797 6.1Media En seguimiento

Jivejdon through 5.0 Reflected XSS via postThread.jsp to and tag Parameters

Descripción técnica (fuente, en inglés)

Jivejdon through 5.0 contains a reflected cross-site scripting vulnerability in application/message/postThread.jsp that allows attackers to inject script via the to and tag parameters. Attackers can send crafted links to authenticated users, breaking out of unencoded inline JavaScript string literals to execute arbitrary JavaScript in the victim's session.

Riesgo
Requiere condiciones específicas para ser explotada; el impacto suele ser acotado.
Recomendación
Incluir en el ciclo regular de actualizaciones y verificar configuraciones relacionadas.
Publicado Oct. 8, 2026, 9:51 p.m. · Fuente cvefeed.io
CVE-2026-107796 6.1Media En seguimiento

Jivejdon through commit ee67a65e Reflected XSS via taggedThreadList.jsp tagID and count Parameters

Descripción técnica (fuente, en inglés)

Jivejdon from commit 5489372d through commit ee67a65e contains a reflected cross-site scripting vulnerability in application/query/taggedThreadList.jsp that allows unauthenticated attackers to inject script via unencoded tagID and count parameters. Attackers can craft a link with a script-closing payload in tagID or count, triggered when start exceeds zero, to execute JavaScript in victims' browsers.

Riesgo
Requiere condiciones específicas para ser explotada; el impacto suele ser acotado.
Recomendación
Incluir en el ciclo regular de actualizaciones y verificar configuraciones relacionadas.
Publicado Oct. 8, 2026, 9:51 p.m. · Fuente cvefeed.io
CVE-2026-107793 5.3Media En seguimiento

Jivejdon through 5.0 IDOR via subSaveAction Subscription Delete

Descripción técnica (fuente, en inglés)

Jivejdon through 5.0 contains an authorization bypass vulnerability in SubscriptionServiceImp.deleteSubscription that allows authenticated users to delete other users' subscriptions by ID. Attackers can submit a delete action to /account/protected/sub/subSaveAction with another user's subscriptionId to remove their thread, forum, tag or account subscriptions.

Riesgo
Requiere condiciones específicas para ser explotada; el impacto suele ser acotado.
Recomendación
Incluir en el ciclo regular de actualizaciones y verificar configuraciones relacionadas.
Publicado Oct. 8, 2026, 9:51 p.m. · Fuente cvefeed.io
CVE-2026-107792 5.3Media En seguimiento

Jivejdon through commit ee67a65e Missing Authorization via /message/threadToForum/save Thread Move

Descripción técnica (fuente, en inglés)

Jivejdon from commit d58a36b0 through commit ee67a65e contains a missing authorization vulnerability in UpdateThreadToForumAction that allows authenticated users to move other users' threads. Attackers can send crafted threadId and forumId values to /message/threadToForum/save to relocate any reply-less thread into an arbitrary forum.

Riesgo
Requiere condiciones específicas para ser explotada; el impacto suele ser acotado.
Recomendación
Incluir en el ciclo regular de actualizaciones y verificar configuraciones relacionadas.
Publicado Oct. 8, 2026, 9:51 p.m. · Fuente cvefeed.io
CVE-2025-71428 6.9Media En seguimiento

Jivejdon through 5.0 SQL Injection via username in userListAction

Descripción técnica (fuente, en inglés)

Jivejdon through 5.0 contains a sql injection vulnerability in AccountDaoSql.getAccountByNameLike() that allows authenticated administrators to inject SQL via the username parameter. Attackers with the Admin role can submit crafted input to /admin/user/userListAction to read database contents, including other accounts' password hashes.

Riesgo
Requiere condiciones específicas para ser explotada; el impacto suele ser acotado.
Recomendación
Incluir en el ciclo regular de actualizaciones y verificar configuraciones relacionadas.
Publicado Oct. 8, 2026, 9:51 p.m. · Fuente cvefeed.io
CVE-2026-107723 —En análisis Parche disponible

fast-jwt

Silent claim-validator bypass when JWT payload is a JSON array

Descripción técnica (fuente, en inglés)

fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.3.0, fast-jwt createVerifier accepts a validly signed JWT whose payload is a JSON array because src/decoder.js checks that the payload is an object but does not reject arrays. The claim validator loop then finds no named exp, nbf, iss, aud, sub, jti, or nonce properties and silently skips those configured checks, returning the array as a successfully verified payload. An attacker who can produce or influence a validly signed token may bypass expiry, issuer, audience, subject, revocation, and replay protections. The opt-in requiredClaims option can block missing claims, and signature verification itself is not bypassed. This issue is fixed in version 6.3.0.

Riesgo
Sin puntaje CVSS asignado todavía por la fuente.
Recomendación
Seguir la evolución del aviso y consultar al fabricante del producto.
Publicado Oct. 8, 2026, 9:51 p.m. · Fuente cvefeed.io
CVE-2026-107722 9.8Crítica Parche disponible

fast-jwt

Incomplete patch of CVE-2026-34950: Non-whitespace key-prefix re-enables RSA→HS256 algorithm confusion

Descripción técnica (fuente, en inglés)

fast-jwt provides fast JSON Web Token (JWT) implementation. From 6.2.0 until 6.3.0, fast-jwt can misclassify RSA public-key text as an HMAC secret when the key has non-whitespace content before its PEM header. In src/crypto.js, performDetectPublicKeyAlgorithms trims whitespace but publicKeyPemMatcher remains start-anchored, so comments, control characters, zero-width characters, or wrapper text can prevent PEM detection and reach the HMAC fallback. An attacker who knows the public key bytes can sign arbitrary HS256 claims with that public material when HS256 is inferred or allowed, resulting in authentication or authorization bypass. An asymmetric-only algorithm allowlist prevents the attack. This issue is fixed in version 6.3.0.

Riesgo
Explotación probable con impacto grave: ejecución remota, toma de control o filtración masiva.
Recomendación
Aplicar el parche o la mitigación del fabricante de inmediato; si no es posible, aislar el servicio.
Publicado Oct. 8, 2026, 9:49 p.m. · Fuente cvefeed.io

Actualizado 08/10/2026 19:17 · Ver listado completo en cvefeed.io

Investigaciones y alertas

Lo que analiza el laboratorio de ESET

Análisis, investigaciones y alertas publicadas por WeLiveSecurity, el portal de noticias e investigación del laboratorio de ESET, con foco en América Latina. Los enlaces abren el artículo original.

Ir a WeLiveSecurity

Fuente: WeLiveSecurity (ESET). Los títulos y resúmenes pertenecen a sus autores. Actualizado 08/10/2026 19:17.

¿Usa alguno de estos productos?

Un análisis de vulnerabilidades determina qué avisos aplican realmente a su infraestructura y en qué orden conviene resolverlos.

Primer paso

Conozca el estado real de su infraestructura.

Un diagnóstico inicial identifica los riesgos prioritarios y ordena las decisiones. Sin compromiso de contratar soluciones.