PatchSiren

Drogon CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Drogon CVE published 2026-10-04

CVE-2026-105144

A path traversal vulnerability has been identified in Drogon up to 1.9.13-1/10.0-beta.3 on Windows, specifically in the StaticFileRouter::route function. This issue allows remote attackers to manipulate the application, potentially leading to unauthorized access or data exposure. The exploit has been published, and although the vendor was notified, no response was received.