CVE-2023-35839: Solon

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

A bypass in the component sofa-hessian of Solon before v2.3.3 allows attackers to execute arbitrary code via providing crafted payload.

Affected products

  • Solon Solon: before 2.3.3 (fixed in 2.3.3)

Published 2023-06-19. Last modified 2026-06-17.