Explore

Rule Explorer

Search the public rule index by CVE, GHSA, CWE, language, framework, author, or rule slug. Filter by language, framework, severity, confidence, license, and validation status.

Public rules
2917
Downloads
3.3M
Verified
2917
Authors
2
Search the rule indexUse CVE, GHSA, CWE, language, framework, package, or rule slug.
1 rules matched. Showing 1 loaded rules.
Publish rule
CVE-2026-28360: Generic Idor Presigned Urlcve-2026-28360-generic-idor-presigned-url

Generating a presigned URL directly from an unvalidated user input path can lead to an Insecure Direct Object Reference (IDOR). An attacker could exploit this by providing a path to another user's file or an internal system file, leading to arbitrary file disclosure. Validate the file path by mapping it to a database record owned by the authenticated user be

by Provallyupdated 2026-06-23Apache-2.0
7490 direct749 via packs
downloads
73quality
All matching rules loaded.