Skip to content

DTStack vulnerabilities

3 CVEs tracked

DTStack Taier 1.4.0 appears in our reporting with multiple path traversal vulnerabilities. Key events involve flaws in the file upload (UploadController), chunk-check (FileChunkController), and cluster creation (ClusterController) components. The listed CVEs—CVE-2026-19761, CVE-2026-19762, CVE-2026-19763—allow a remote attacker to manipulate file arguments. Defenders should strictly validate incoming filename values and implement controls against path traversal attacks.

Azərbaycanca: DTStack Taier 1.4.0 hesabatlarımızda bir neçə path traversal zəifliyi ilə bağlı görünür. Əsas hadisələr fayl yükləmə (UploadController), fayl yoxlama (FileChunkController) və klaster yaradılması (ClusterController) komponentlərindəki zəifliklərdir. Sadalanan CVE-2026-19761, CVE-2026-19762, CVE-2026-19763 qüsurları remote attacker tərəfindən fayl arqumentlərinin manipulyasiyasına imkan verir. Müdafiəçilər daxil olan fayl adı dəyərlərini ciddi şəkildə yoxlamalı, path traversal hücumlarına qarşı nəzarət tətbiq etməlidir.

This vendor's CVEs3

This hub is built from skopnix's own reporting on DTStack: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.