Known Vulnerabilities for Chat by Synology
Listed below are 3 of the newest known vulnerabilities associated with "Chat" by "Synology".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-100685 json | Budibase before 3.45.0 fails to properly scope the GET /api/chat-links endpoint by workspace, allowing builders to enumerate ... | Not Provided | 2026-09-26 | 2026-09-30 |
| CVE-2026-100654 json | vLLM before 0.29.0 accepts user-controlled stop_token_ids on the OpenAI-compatible POST /v1/completions and POST /v1/chat/com... | Not Provided | 2026-09-26 | 2026-09-30 |
| CVE-2026-100650 json | vLLM through 0.29.0 fetches and fully materializes remote or inline media before enforcing its documented media controls (the... | Not Provided | 2026-09-26 | 2026-09-30 |
| CVE-2026-100648 json | vllm before 0.29.0 fails to enforce VLLM_MAX_AUDIO_CLIP_FILESIZE_MB limit in multimodal chat audio decoding, allowing unauthe... | Not Provided | 2026-09-26 | 2026-09-28 |
| CVE-2026-100608 json | Flowise through 3.1.4 does not enforce authorization on the BullMQ admin dashboard. When the server runs in queue mode with t... | Not Provided | 2026-09-26 | 2026-09-26 |
| CVE-2026-100605 json | Flowise through 3.1.4 contains missing route-level RBAC checks on chat message endpoints that allow low-privileged API keys t... | Not Provided | 2026-09-26 | 2026-09-30 |
| CVE-2026-100578 json | OpenClaw (npm package `openclaw`) before 2026.7.1 fails to restrict owner-only infrastructure tools exposed through the chat.... | Not Provided | 2026-09-26 | 2026-09-28 |
| CVE-2026-100572 json | OpenClaw versions >= 2026.3.25 and < 2026.8.1 apply invalid-token rate limiting for Synology Chat webhooks before authenticat... | Not Provided | 2026-09-26 | 2026-09-26 |
| CVE-2026-100555 json | OpenClaw is an npm-distributed gateway application. In versions >= 2026.7.1 and < 2026.8.1, Synology Chat attachment delivery... | Not Provided | 2026-09-26 | 2026-09-26 |
| CVE-2026-100552 json | OpenClaw (npm package 'openclaw') before 2026.8.1 does not correctly enforce per-chat tool policies for Codex app-server runt... | Not Provided | 2026-09-26 | 2026-09-30 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Synology | Chat | 2.1.0-1228 | |||
| Application | Synology | Chat | 2.1.0-1225 | |||
| Application | Synology | Chat | 2.0.0-1124 | |||
| Application | Synology | Chat | 1.1.1-0902 | |||
| Application | Synology | Chat | 1.1.0-0806 | |||
| Application | Synology | Chat | 1.0.2-0159 | |||
| Application | Synology | Chat | 1.0.2-0158 | |||
| Application | Synology | Chat | 1.0.0-0127 | |||
| Application | Synology | Chat | 1.0.0-0126 |