SQL Injection Vulnerability in Drogon Framework by Drogon
CVE-2026-94144
Key Information:
- Vendor
Drogonframework
- Status
- Vendor
- CVE Published:
- 21 September 2026
Badges
What is CVE-2026-94144?
A vulnerability exists in the Drogon Framework's ORM component, specifically within the makeCriteria function of orm_lib/src/Criteria.cc. This flaw allows remote attackers to manipulate the filter argument, potentially leading to SQL injection attacks. The exploit is actively known and can be executed from a distance, posing risks to applications utilizing the affected version of the framework. Despite early notification efforts, there has been no response from the vendor regarding this security issue.
Affected Version(s)
drogon 1.9.0
drogon 1.9.1
drogon 1.9.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
