Skip to content

Add vpatch-CVE-2026-42596 rule and test - #74

Closed
crowdsec-automation wants to merge 5 commits into
masterfrom
1790347000-vpatch-CVE-2026-42596
Closed

crowdsec-automation wants to merge 5 commits into
masterfrom
1790347000-vpatch-CVE-2026-42596

Conversation

@crowdsec-automation

Copy link
Copy Markdown

The rule checks for the Gotenberg LibreOffice conversion endpoint and, within its downloadFrom body argument, the IPv4-mapped IPv6 marker ::ffff:. This keeps detection scoped to the vulnerable request field and avoids matching unrelated addresses elsewhere in a request. Both URL decoding and lowercase normalization are applied before matching. The test template preserves the relevant multipart request and uses only a 403 response-status matcher, as required.

Exploit URL: https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-42596.yaml

@github-actions

Copy link
Copy Markdown

Hello @crowdsec-automation and thank you for your contribution!

❗ It seems that the following scenarios are not part of the 'crowdsecurity/appsec-virtual-patching' collection:

🔴 crowdsecurity/vpatch-CVE-2026-42596 🔴

@github-actions

Copy link
Copy Markdown

Hello @crowdsec-automation,

Scenarios/AppSec Rule are compliant with the taxonomy, thank you for your contribution!

@github-actions

Copy link
Copy Markdown

Hello @crowdsec-automation,

✅ The new VPATCH Rule is compliant, thank you for your contribution!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants