SQL Injection Vulnerability in TDuckCloud's Pagination Inner Interceptor Component
CVE-2026-95829

5.3MEDIUM

Key Information:

Vendor

Tduckcloud

Vendor
CVE Published:
22 September 2026

What is CVE-2026-95829?

A vulnerability exists in TDuckCloud tduck-platform, specifically within the Pagination Inner Interceptor component. This issue arises from improper handling of the 'orders' parameter within the concatOrderBy function, which allows remote attackers to execute SQL injection attacks by manipulating the orders[0].column argument. This could potentially lead to exposure of sensitive data and system compromise. Users are encouraged to apply the patch identified as ea7f0fae7cb0fd998a3284c11addce689350cd69 to mitigate this vulnerability.

Affected Version(s)

tduck-platform 5.0

tduck-platform 5.1

tduck-platform 5.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

p5092 (VulDB User)
VulDB Vulnerability Moderation Team
.