CVE-2026-4200
A security flaw has been discovered in glowxq glowxq-oj up to 6f7c723090472057252040fd2bbbdaa1b5ed2393. This affects the function uploadTestcaseZipUrl of the file business/business-oj/src/main/java/com/glowxq/oj/problem/controller/ProblemCaseController.java. Performing a manipulation results in server-side request forgery. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.
EPSS 0.47% · 38.9th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| glowxq | glowxq-oj | 6f7c723090472057252040fd2bbbdaa1b5ed2393, 6f7c723090472057252040fd2bbbdaa1b5ed2393, 6f7c723090472057252040fd2bbbdaa1b5ed2393 |
Timeline
- Mar 16, 2026 EPSS Score
- Mar 16, 2026 CVE Published
- Mar 16, 2026 CVE Updated
- Mar 17, 2026 EPSS Score
- Mar 17, 2026 Coalition ESS Score
- Mar 19, 2026 EPSS Score
- Mar 20, 2026 EPSS Score
- Mar 22, 2026 EPSS Score
- Mar 23, 2026 EPSS Score
- Mar 24, 2026 EPSS Score
- Mar 29, 2026 Security Advisory
- May 18, 2026 EPSS Score
References
- https://vuldb.com/?submit.770476 url
- https://vuldb.com/?ctiid.351112 technical
- VDB-351112 | glowxq glowxq-oj ProblemCaseController.java uploadTestcaseZipUrl server-side request forgery vdb
- https://fx4tqqfvdw4.feishu.cn/docx/K0SjdZTPRo31LExSdlfcC3jwn1c?from=from_copylink url
- https://nvd.nist.gov/vuln/detail/CVE-2026-4200 advisory