[CVE-2026-2031] StubZero:在 Google Cloud 生产环境中发现价值 148,337 美元的远程代码执行漏洞
brutecat.com | 博客 | CVE-2026-2031 | #bug-bounty | #cloud | #rce | #information-disclosure | #cve | #google-cloud | #protobuf
摘要
一个内部调试端点信息泄露(可获取 google3 仓库中任意 protobuf 消息定义,被戏称为 req2proto as a Service)逐步升级为 Google Cloud 生产环境的远程代码执行,编号 CVE-2026-2031,赏金 148,337 美元;三个月后作者再次复现了同类漏洞。
- 发布时间
- 收录时间
Skip to content