1. StubZero:在 Google Cloud 生产环境中发现价值 148,337 美元的远程代码执行漏洞 brutecat.com | 博客 | 2026-05-22 00:00 | 原文 ↗ | #bug-bounty | #cloud | #rce | #information-disclosure 一个内部调试端点信息泄露(可获取 google3 仓库中任意 protobuf 消息定义,被戏称为 req2proto as a Service)逐步升级为 Google Cloud 生产环境的远程代码执行,编号 CVE-2026-2031,赏金 148,337 美元;三个月后作者再次复现了同类漏洞。