CVE-2026-75329
The Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication mechanism. Attackers can directly obtain the full configuration of any project (including database passwords, API keys, etc.) by sending a TCP request without any credential.
- Published Aug 26, 2026
- CVSS 9.8 critical
- 0.6% chance of exploitation in the next 30 days (EPSS)