Known Vulnerabilities for Chat by Synology
Listed below are 3 of the newest known vulnerabilities associated with "Chat" by "Synology".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-34999 | OpenViking versions 0.2.5 prior to 0.2.14 contain a missing authentication vulnerability in the bot proxy router that allows ... | Not Provided | 2026-04-01 | 2026-04-01 |
| CVE-2026-34172 | Giskard is an open-source Python library for testing and evaluating agentic systems. Prior to versions 0.3.4 and 1.0.2b1, Cha... | Not Provided | 2026-03-31 | 2026-03-31 |
| CVE-2026-33578 | OpenClaw before 2026.3.28 contains a sender policy bypass vulnerability in the Google Chat and Zalouser extensions where rout... | Not Provided | 2026-03-31 | 2026-04-01 |
| CVE-2026-33575 | OpenClaw before 2026.3.12 embeds long-lived shared gateway credentials directly in pairing setup codes generated by /pair end... | Not Provided | 2026-03-29 | 2026-03-30 |
| CVE-2026-32924 | OpenClaw before 2026.3.12 contains an authorization bypass vulnerability where Feishu reaction events with omitted chat_type ... | Not Provided | 2026-03-29 | 2026-03-30 |
| CVE-2026-32618 | Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before ... | Not Provided | 2026-03-31 | 2026-03-31 |
| CVE-2026-31950 | LibreChat is a ChatGPT clone with additional features. In versions 0.8.2-rc2 through 0.8.2-rc3, the SSE streaming endpoint `/... | Not Provided | 2026-03-27 | 2026-03-27 |
| CVE-2026-25377 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eyecix Addon Jobsearch ... | Not Provided | 2026-03-25 | 2026-03-26 |
| CVE-2026-25376 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyecix Addon Jobsearch ... | Not Provided | 2026-03-25 | 2026-03-25 |
| CVE-2026-5320 | A vulnerability was detected in vanna-ai vanna up to 2.0.2. Affected by this vulnerability is an unknown functionality of the... | Not Provided | 2026-04-02 | 2026-04-02 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Synology | Chat | 2.1.0-1228 | All | All | All |
| Application | Synology | Chat | 2.1.0-1225 | All | All | All |
| Application | Synology | Chat | 2.0.0-1124 | All | All | All |
| Application | Synology | Chat | 1.1.1-0902 | All | All | All |
| Application | Synology | Chat | 1.1.0-0806 | All | All | All |
| Application | Synology | Chat | 1.0.2-0159 | All | All | All |
| Application | Synology | Chat | 1.0.2-0158 | All | All | All |
| Application | Synology | Chat | 1.0.0-0127 | All | All | All |
| Application | Synology | Chat | 1.0.0-0126 | All | All | All |