CVE-2026-94144: SQL Injection in drogonframework drogon
CVE-2026-94144 is a medium severity SQL injection vulnerability in the drogonframework drogon ORM component, specifically in the makeCriteria function of orm_lib/src/Criteria.cc. It affects versions 1.9.0 through 1.9.13. The flaw allows remote attackers to manipulate the filter argument to execute SQL injection attacks. Exploit code has been published, but no vendor response or patch is currently available.
AI Analysis
Technical Summary
A SQL injection vulnerability exists in drogonframework drogon up to version 1.9.13 within the makeCriteria function of the ORM component. The vulnerability arises from improper handling of the filter argument, which can be manipulated remotely to inject SQL commands. This flaw has been publicly disclosed with exploit code available. The vendor was notified but has not issued any response or fix.
Potential Impact
Successful exploitation allows remote attackers to perform SQL injection attacks, potentially leading to unauthorized data access or manipulation within affected versions of drogonframework drogon. The CVSS 4.0 score is 6.9 (medium severity), indicating a significant but not critical risk.
Mitigation Recommendations
No official patch or vendor advisory is available at this time. Users should monitor the vendor's communications for updates. Until a fix is released, avoid using affected versions or implement application-level input validation and filtering on the filter argument to reduce risk.
CVE-2026-94144: SQL Injection in drogonframework drogon
Description
CVE-2026-94144 is a medium severity SQL injection vulnerability in the drogonframework drogon ORM component, specifically in the makeCriteria function of orm_lib/src/Criteria.cc. It affects versions 1.9.0 through 1.9.13. The flaw allows remote attackers to manipulate the filter argument to execute SQL injection attacks. Exploit code has been published, but no vendor response or patch is currently available.
CVSS v4.0
Score 6.9medium
Affected software
drogonframework
drogon
pkg:github/drogonframework/drogoncpe:2.3:a:drogon:drogon:*:*:*:*:*:*:*:*Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
A SQL injection vulnerability exists in drogonframework drogon up to version 1.9.13 within the makeCriteria function of the ORM component. The vulnerability arises from improper handling of the filter argument, which can be manipulated remotely to inject SQL commands. This flaw has been publicly disclosed with exploit code available. The vendor was notified but has not issued any response or fix.
Potential Impact
Successful exploitation allows remote attackers to perform SQL injection attacks, potentially leading to unauthorized data access or manipulation within affected versions of drogonframework drogon. The CVSS 4.0 score is 6.9 (medium severity), indicating a significant but not critical risk.
Mitigation Recommendations
No official patch or vendor advisory is available at this time. Users should monitor the vendor's communications for updates. Until a fix is released, avoid using affected versions or implement application-level input validation and filtering on the filter argument to reduce risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-09-20T20:14:48.196Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab0d9f455bf5e2cf570178a
Added to database: 09/21/2026, 07:17:08 UTC
Last enriched: 09/21/2026, 07:31:57 UTC
Last updated: 09/21/2026, 07:31:57 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.