Vulnerability Digest — May 25, 2026 · 29 Critical · 10 Exploited






Vulnerability Digest — Monday, May 25, 2026


Security Report

Monday, May 25, 2026  ·  Last 7 days  ·  Min severity: MEDIUM
Total Findings
216
Critical
29
High
90
Actively Exploited
10
CISA-KEV10
GitHub-GHSA206
Findings sorted by severity
CISA-KEV

CRITICAL
Drupal Core SQL Injection Vulnerability
CVE-2026-9082
pkg: Drupal Core

published: May 22, 2026

Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
Langflow Origin Validation Error Vulnerability
CVE-2025-34291
pkg: Langflow Langflow

published: May 21, 2026

Langflow contains an origin validation error vulnerability in which an overly permissive CORS configuration combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint…
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability
CVE-2026-34926
pkg: Trend Micro Apex One

published: May 21, 2026

Trend Micro Apex One (on-premise) contains a directory traversal vulnerability that could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
Microsoft Windows Buffer Overflow Vulnerability
CVE-2008-4250
pkg: Microsoft Windows

published: May 20, 2026

Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
Microsoft DirectX NULL Byte Overwrite Vulnerability
CVE-2009-1537
pkg: Microsoft DirectX

published: May 20, 2026

Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability
CVE-2009-3459
pkg: Adobe Acrobat and Reader

published: May 20, 2026

Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
Microsoft Internet Explorer Use-After-Free Vulnerability
CVE-2010-0249
pkg: Microsoft Internet Explorer

published: May 20, 2026

Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product util…
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
Microsoft Internet Explorer Use-After-Free Vulnerability
CVE-2010-0806
pkg: Microsoft Internet Explorer

published: May 20, 2026

Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users shou…
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
Microsoft Defender Link Following Vulnerability
CVE-2026-41091
pkg: Microsoft Defender

published: May 20, 2026

Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
Microsoft Defender Denial of Service Vulnerability
CVE-2026-45498
pkg: Microsoft Defender

published: May 20, 2026

Microsoft Defender contains an unspecified vulnerability that allows for denial of service.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
GitHub-GHSA

CRITICAL
BoxLite: Permission Bypass Allows Modification of Read-Only Files
GHSA-g6ww-w5j2-r7x3
pkg: boxlite, @boxlite-ai/boxlite, github.com/boxlite-ai/boxlite/sdks/go
eco: npm
published: May 21, 2026
#### Summary

Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code.

One of the core security features claimed by Boxlite is the ability to mount host directories in read-only mode (read_only=True) i…

CVE-2026-46695
GitHub-GHSA

CRITICAL
Malicious code in @beproduct/nestjs-auth (0.1.2 through 0.1.19) — Mini Shai-Hulud worm
GHSA-6xwp-cp5h-q856
pkg: @beproduct/nestjs-auth
eco: npm
published: May 19, 2026
## Summary

Between 2026-05-11 20:19 UTC and 22:56 UTC, an attacker used a compromised npm publish token to publish 18 malicious versions of `@beproduct/nestjs-auth` (0.1.2 through 0.1.19). The packages contained payloads from the **Mini Shai-Hulud** npm supply-chain worm campaign described by [Aiki…

CVE-2026-46412
GitHub-GHSA

CRITICAL
9router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes
GHSA-fhh6-4qxv-rpqj
pkg: 9router
eco: npm
published: May 19, 2026
## Summary

9router exposes two unauthenticated API endpoints that, when chained together, allow any network-adjacent attacker to execute arbitrary OS commands as the user running the 9router process — with **zero prerequisites** and **no credentials required**.

The vulnerability exists because t…

CVE-2026-46339
GitHub-GHSA

CRITICAL
Nezha Monitoring: RoleMember can run shell on every server (cross-tenant RCE) via POST /api/v1/cron
GHSA-99gv-2m7h-3hh9
pkg: github.com/nezhahq/nezha
eco: go
published: May 23, 2026
## Summary

`nezha`'s dashboard supports two user roles: `RoleAdmin` (Role==0) and `RoleMember` (Role==1). The cron routes `POST /api/v1/cron` and `PATCH /api/v1/cron/:id` are wired through `commonHandler` (any authenticated user) rather than `adminHandler`, and the per-server permission check on cr…

CVE-2026-46716
GitHub-GHSA

CRITICAL
Arcane Backend: Missing admin authorization on git repository endpoints allows non-admin users to exfiltrate stored Git credentials and tamper with GitOps configs
GHSA-7h26-hg47-p9hx
pkg: github.com/getarcaneapp/arcane/backend
eco: go
published: May 18, 2026
## Summary

Arcane's huma-based REST API exposes nine endpoints under `/api/customize/git-repositories` and `/api/git-repositories/sync` for managing GitOps source repositories and their stored credentials. Eight of those endpoints (`list`, `create`, `get`, `update`, `delete`, `test`, `listBranches`…

CVE-2026-45625
GitHub-GHSA

CRITICAL
Fission router exposes /fission-function/<ns>/<name> on its public listener, allowing invocation of any function without an HTTPTrigger
GHSA-3g33-6vg6-27m8
pkg: github.com/fission/fission
eco: go
published: May 21, 2026
### Summary

The Fission router registers an internal-style route — `/fission-function/<name>` and `/fission-function/<ns>/<name>` — for every `Function` object, independent of whether any `HTTPTrigger` exists for that function. The route was mounted on the same listener as user-defined `HTTPTri…

CVE-2026-46614
GitHub-GHSA

CRITICAL
Kopia: RCE via SSH ProxyCommand Injection
GHSA-2q4c-3mrw-63c3
pkg: github.com/kopia/kopia
eco: go
published: May 19, 2026
## Summary

Kopia's HTTP server, when started with `–without-password `, accepts unauthenticated requests to `/api/v1/repo/exists`. The handler forwards an attacker-supplied storage configuration to `blob.NewStorage`. For SFTP backends with `externalSSH: true`, that path constructs a process comman…

CVE-2026-45695
GitHub-GHSA

CRITICAL
Boxlite: Path Traversal Vulnerability Leads to Arbitrary File Write on the Host
GHSA-f396-4rp4-7v2j
pkg: boxlite, boxlite-cli, boxlite
eco: npm
published: May 21, 2026
#### Summary

Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and run OCI containers within them. Boxlite allows users to specify the OCI image used by containers in the sandbox. However, when processing tar entries in OCI images, Boxlite does not accoun…

CVE-2026-46703
GitHub-GHSA

CRITICAL
Malicious code in guardrails-ai 0.10.1 (supply chain compromise)
GHSA-xmpw-2vmm-p4p6
pkg: guardrails-ai
eco: pip
published: May 19, 2026
### Impact

On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of `guardrails-ai` (0.10.1) to PyPI.

**Affected:** any user who installed `guardrails-ai==0.10.1` from PyPI on May 11, 2026.

Security researchers identified the malicious package within approxim…

CVE-2026-45758
GitHub-GHSA

CRITICAL
Malware in @opensearch-project/opensearch
GHSA-27f5-xjrr-q9ff
pkg: @opensearch-project/opensearch, @opensearch-project/opensearch, @opensearch-project/opensearch
eco: npm
published: May 19, 2026
## Overview

The OpenSearch Project has sustained a security incident involving an external actor gaining force-push permissions within the project's CI infrastructure to embed malicious packages into four release versions of `@opensearch-project/opensearch`. Users are instructed to immediately take…

GitHub-GHSA

CRITICAL
Malicious dropper in mistralai 2.4.6 PyPI package
GHSA-wx9m-wx4f-4cmg
pkg: mistralai
eco: pip
published: May 18, 2026
The `mistralai` PyPI package version `2.4.6` contains a malicious dropper that executes on import on Linux. No `v2.4.6` tag, commit, or release workflow run exists in this repository, the legitimate latest version before the upload was `2.4.5`, and the upload bypassed this repository's normal releas…
GitHub-GHSA

CRITICAL
Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft
GHSA-6×44-w3xg-hqqf
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: May 19, 2026
## Summary

`azureidentity.Validate()` verifies that the PKCS#7 signer certificate chains to a trusted Azure CA but never verifies the PKCS#7 signature itself. An attacker can embed a legitimate Azure certificate alongside arbitrary content e.g. `{"vmId":"<target>"}` and the forged `vmId` will be ac…

CVE-2026-46354
GitHub-GHSA

CRITICAL
Algernon: handler.lua discovery walks parent directories above the server root
GHSA-xwcr-wm99-g9jc
pkg: github.com/xyproto/algernon
eco: go
published: May 19, 2026
### Summary

When Algernon is asked for any URL path that resolves to a directory *without* an index file, `DirPage` walks **upward through parent directories — past the configured server root** — looking for a file named `handler.lua` to execute as the request handler. The loop terminates only …

CVE-2026-45721
GitHub-GHSA

CRITICAL
FileBrowser Quantum: Path traversal in public share PATCH allows file ops outside shared directory
GHSA-qqqm-5547-774x
pkg: github.com/gtsteffaniak/filebrowser/backend
eco: go
published: May 22, 2026
## Summary

`publicPatchHandler` in `backend/http/public.go` joins user-controlled `fromPath` and `toPath` body fields with the trusted `d.share.Path` BEFORE the downstream sanitizer runs. Because `filepath.Join` collapses `..` segments during the join, the sanitizer in `resourcePatchHandler` never …

GitHub-GHSA

CRITICAL
@hulumi/policies: GitHub OIDC trust policy bypass via AWS set-qualified condition operators
GHSA-q2f7-m237-v562
pkg: @hulumi/policies
eco: npm
published: May 21, 2026
Impact: @hulumi/policies versions before 1.3.2 only checked exact AWS IAM StringLike/StringEquals condition operator keys in G_OIDC_1. Set-qualified operators such as ForAnyValue:StringLike could hide wildcard GitHub Actions OIDC sub conditions from the mandatory guardrail.

Patched in 1.3.2: the AW…

GitHub-GHSA

CRITICAL
Supply chain compromise via malicious package versions (@cap-js/sqlite, @cap-js/postgres, @cap-js/db-service)
GHSA-pvw4-cvr4-97p8
pkg: @cap-js/sqlite, @cap-js/postgres, @cap-js/db-service
eco: npm
published: May 20, 2026
## Impact

On April 29, 2026, compromised versions of `@cap-js/sqlite@2.2.2`, `@cap-js/postgres@2.2.2`, and `@cap-js/db-service@2.10.1` were published.
The malicious packages harvested credentials and attempted self-propagation.
If a compromised version was installed, all credentials accessible on t…

CVE-2026-46421
GitHub-GHSA

CRITICAL
MCP Gateway: Authority-injection and JWT/session bypass via the unauthenticated router hair-pin "router-key" / "mcp-init-host" path
GHSA-g53w-w6mj-hrpp
pkg: github.com/Kuadrant/mcp-gateway
eco: go
published: May 19, 2026
## Summary

The MCP router (ext_proc) exposes an `initialize`-method code path that, when a
request carries an `mcp-init-host` header, bypasses the gateway JWT session
validator and rewrites the upstream `:authority` header to whatever the caller
chooses, gated only by a single shared header value …

GitHub-GHSA

CRITICAL
rok Python ProxyShare can be used as an SSRF proxy through absolute URL paths
GHSA-jh67-hwqw-m5r7
pkg: zrok
eco: pip
published: May 19, 2026
## Summary

Alice exposes a Python SDK `ProxyShare` with a fixed target URL. Bob sends a request to the share with an absolute URL in the path. The Flask handler passes that path to `urllib.parse.urljoin`, which replaces Alice's configured target host with Bob's host and returns the server-side resp…

CVE-2026-45568
GitHub-GHSA

CRITICAL
HAXcms: Private Key Disclosure via Broken HMAC Implementation
GHSA-6c8g-9hfh-pq5h
pkg: @haxtheweb/haxcms-nodejs
eco: npm
published: May 19, 2026
### Summary
The `hmacBase64()` function in the HAXcms Node.js backend contains two critical cryptographic implementation errors that together allow any unauthenticated attacker to extract the system’s private signing key and forge arbitrary admin-level JSON Web Tokens (JWTs) allowing them to get f…
CVE-2026-46395
GitHub-GHSA

HIGH
Arcane: Missing admin authorization on global variables endpoint
GHSA-jpjh-jm2p-39hh
pkg: github.com/getarcaneapp/arcane/backend
eco: go
published: May 23, 2026
## Summary

The `PUT /api/environments/{id}/templates/variables` endpoint, which writes the system-wide `.env.global` file used for variable substitution in every project's compose file, is missing an admin authorization check. Any authenticated non-admin user can call this endpoint with their beare…

CVE-2026-47125
GitHub-GHSA

HIGH
MCP Server Kubernetes: Tool Access Control Bypass via Presentation-Layer Filtering Without Execution-Layer Enforcement
GHSA-cr22-wjx7-2w6m
pkg: mcp-server-kubernetes
eco: npm
published: May 21, 2026
## Summary

`mcp-server-kubernetes` exposes three environment variables (`ALLOW_ONLY_READONLY_TOOLS`, `ALLOW_ONLY_NON_DESTRUCTIVE_TOOLS`, `ALLOWED_TOOLS`) documented as access controls for restricting which Kubernetes operations are available. These controls are enforced at the tool discovery layer …

CVE-2026-46519
GitHub-GHSA

HIGH
Fission StorageSvc /v1/archive endpoint exposes unauthenticated CRUD over all function archives
GHSA-chf8-4hv6-8pg6
pkg: github.com/fission/fission
eco: go
published: May 21, 2026
### Summary

The Fission `storagesvc` component registers archive CRUD handlers (`/v1/archive` GET / POST / DELETE and `/v1/archives` list) directly on its HTTP router without performing any authentication or authorization. Any caller able to reach the `storagesvc` ClusterIP — including any other…

CVE-2026-46612
GitHub-GHSA

HIGH
PenPot MCP REPL server binds to 0.0.0.0 with unauthenticated /execute endpoint — RCE
GHSA-22qr-rp27-j9wm
pkg: @penpot/mcp
eco: npm
published: May 19, 2026
### Summary

The MCP module's `ReplServer` binds to all interfaces (`0.0.0.0:4403`) and exposes a `/execute` endpoint that runs arbitrary code with zero authentication. Anyone on the network can POST JavaScript and it runs on the server. The main `PenpotMcpServer` was partially fixed for a similar b…

CVE-2026-45805
GitHub-GHSA

HIGH
Budibase: Builder-to-Admin Privilege Escalation via onboardUsers Endpoint Without SMTP Configuration
GHSA-c54j-xp92-wh28
pkg: @budibase/worker
eco: npm
published: May 18, 2026
## Summary

The `POST /api/global/users/onboard` endpoint is protected by `workspaceBuilderOrAdmin` middleware, allowing any user with builder permissions to access it. When SMTP email is not configured (the default for self-hosted Budibase instances), this endpoint bypasses the admin-restricted inv…

CVE-2026-45716
GitHub-GHSA

HIGH
Dozzle: Pre-auth SSRF with response-body reflection via POST /api/notifications/test-webhook (default no-auth deploy)
GHSA-3v9w-6365-9w54
pkg: github.com/amir20/dozzle
eco: go
published: May 18, 2026
## Summary

In a default dozzle deploy (the documented quickstart, no `DOZZLE_AUTH_PROVIDER` set), `POST /api/notifications/test-webhook` is reachable without authentication and forwards an attacker-controlled URL into a `WebhookDispatcher` that:

– Sends an HTTP POST to the supplied URL with attack…

CVE-2026-45298
GitHub-GHSA

HIGH
Nezha Monitoring: RoleMember-reachable SSRF with full response-body reflection via POST /api/v1/notification
GHSA-w4g9-mxgg-j532
pkg: github.com/nezhahq/nezha
eco: go
published: May 23, 2026
## Summary

nezha's dashboard supports two user roles: `RoleAdmin` (Role==0) and `RoleMember` (Role==1). The notification routes `POST /api/v1/notification` and `PATCH /api/v1/notification/:id` are wired through `commonHandler` rather than `adminHandler` — so a `RoleMember` user can call them. The…

CVE-2026-46717
GitHub-GHSA

HIGH
wger: cross-tenant account deletion / deactivation / activation by gym.manage_gym + gym=None
GHSA-mw8f-w6p8-xrf4
pkg: wger
eco: pip
published: May 20, 2026
## Summary

GHSA-mhc8-p3jx-84mm (CVE-2026-43948) reported that wger's `reset_user_password` and `gym_permissions_user_edit` views in `wger/gym/views/user.py` performed a gym-scope authorization check using Django ORM object comparison (`if request.user.userprofile.gym != user.userprofile.gym`) which…

GitHub-GHSA

HIGH
SillyTavern: SSRF in SearXNG Search Proxy via Unvalidated baseUrl
GHSA-qg89-qwwh-5f3j
pkg: sillytavern
eco: npm
published: May 19, 2026
## Resolution

SillyTavern 1.18.0 added a generic server-side request filter (Private Request Whitelisting). Since we expect users to use the application in a trusted environment, the filter is disabled by default, however it is strongly advised to be enabled and properly configured when an instance…

CVE-2026-46372
GitHub-GHSA

HIGH
OpenMetadata: TEST_CONNECTION workflow leaks ingestion-bot JWT and database password to regular users
GHSA-9vmh-whc4-7phg
pkg: org.open-metadata:openmetadata-service
eco: maven
published: May 21, 2026
**This is not applicable if an application is configuring the Secrets Store to store credentials. Please make sure to follow the best practices when deploying in production**
In OpenMetadata 1.12.1, a non-admin SSO user can trigger a `TEST_CONNECTION` workflow for a Database Service and receive, in …
CVE-2026-46481
GitHub-GHSA

HIGH
Caddy Defender trusted proxy client IP bypass
GHSA-3h23-rrpc-3p87
pkg: pkg.jsn.cam/caddy-defender
eco: go
published: May 19, 2026
### Impact

Caddy Defender used `r.RemoteAddr` when evaluating whether a request should be blocked. `RemoteAddr` is the address of the immediate peer connected to Caddy.

In deployments where Caddy is behind a trusted proxy, CDN, or load balancer, the immediate peer is usually the proxy, not the ori…

CVE-2026-46415
GitHub-GHSA

HIGH
auth-fetch-mcp: SSRF and disk exfiltration via unvalidated auth_fetch and download_media URLs
GHSA-hv85-774v-26fg
pkg: auth-fetch-mcp
eco: npm
published: May 19, 2026
# SSRF + disk-exfil in `download_media` and `auth_fetch` tools — ymw0407/auth-fetch-mcp

## Severity
The `download_media` and `auth_fetch` MCP tools accept arbitrary URLs and reach them as the MCP server process, with `download_media` additionally persisting the fetched response body to a user-con…

GitHub-GHSA

HIGH
TinyIce: Missing authentication on WebRTC ingest endpoint allows unauthorized stream injection
GHSA-p7c4-8×34-8j8f
pkg: github.com/DatanoiseTV/tinyice
eco: go
published: May 18, 2026
## Title

Missing authentication on WebRTC ingest endpoint allows unauthenticated stream injection in TinyIce

## Ecosystem / Package

– **Ecosystem:** `Go` (or "Other" — TinyIce is shipped as a Go binary, not a Go module published to a registry)
– **Package name:** `github.com/DatanoiseTV/tinyice…

CVE-2026-45327
GitHub-GHSA

HIGH
@tmlmobilidade/utils has prototype pollution in its setValueAtPath
GHSA-cmxg-94mg-jq94
pkg: @tmlmobilidade/utils
eco: npm
published: May 18, 2026
### Impact
Prototype pollution vulnerability in @tmlmobilidade/utils for setValueAtPath().

### Patches
A fix is available in versions 20260509.0340.15 and up.

CVE-2026-45325
GitHub-GHSA

HIGH
parse-nested-form-data has Prototype Pollution via `__proto__` in FormData field names
GHSA-xp7r-j8r6-j9h3
pkg: parse-nested-form-data
eco: npm
published: May 18, 2026
## Summary

`parseFormData()` walks bracket and dot-notation FormData field names into nested objects without filtering reserved property keys. A single FormData field whose name begins with `__proto__`, or contains `.__proto__.` mid-path, causes the parser to traverse onto `Object.prototype` and as…

CVE-2026-45302
GitHub-GHSA

HIGH
Arcane Backend: Unauthenticated reflected XSS via SVG color parameter enables admin account takeover
GHSA-q2pj-8v84-9mh5
pkg: github.com/getarcaneapp/arcane/backend
eco: go
published: May 18, 2026
## Summary

The unauthenticated `GET /api/app-images/logo` endpoint reflects a user-supplied `color` query parameter into the body of an SVG document via `strings.ReplaceAll` with no escaping. The substitution lands inside a `<style>` element of the embedded `logo.svg`, allowing an attacker to close…

CVE-2026-45627
GitHub-GHSA

HIGH
form-data-objectizer: Prototype pollution in form-data-objectizer via bracket-notation form keys
GHSA-m2hg-wjq3-28wq
pkg: form-data-objectizer
eco: npm
published: May 18, 2026
## Summary

`form-data-objectizer` walks bracket-notation form keys (e.g. `name[sub]`) into nested objects without filtering `__proto__`, `constructor`, or `prototype`. A single HTTP form field whose name starts with `__proto__[…]` causes the library to mutate `Object.prototype`, which is a protot…

CVE-2026-46510
GitHub-GHSA

HIGH
ORAS Java: Path traversal in pullArtifact via attacker-controlled org.opencontainers.image.title annotation
GHSA-xm96-gfjx-jcrc
pkg: land.oras:oras-java-sdk
eco: maven
published: May 19, 2026
### Summary

The `pullArtifact` methods in `Registry` and `OCILayout` use the `org.opencontainers.image.title` annotation from a pulled manifest as a filename, resolving it against the caller supplied output directory without normalization or a containment check. A manifest publisher can set this an…

GitHub-GHSA

HIGH
n8n-MCP: Multi-tenant MCP requests fall back to process-level n8n credentials when tenant headers are absent or incomplete
GHSA-jxx9-px88-pj69
pkg: n8n-mcp
eco: npm
published: May 18, 2026
## Summary

When `ENABLE_MULTI_TENANT=true`, the HTTP transport documents that the target n8n instance is selected per-request from `x-n8n-url` / `x-n8n-key` headers. Requests that omitted those headers — or supplied only one of them — silently fell back to the process-level `N8N_API_URL` / `N8N…

CVE-2026-45707
GitHub-GHSA

HIGH
Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Files
GHSA-m675-2p33-xv9g
pkg: github.com/caddyserver/caddy/v2
eco: go
published: May 18, 2026
### Summary

The FastCGI transport's `splitPos()` in [`modules/caddyhttp/reverseproxy/fastcgi/fastcgi.go`](https://github.com/caddyserver/caddy/blob/master/modules/caddyhttp/reverseproxy/fastcgi/fastcgi.go) misuses `golang.org/x/text/search` with `search.IgnoreCase` when the request path contains a …

CVE-2026-45135
GitHub-GHSA

HIGH
lmdeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out
GHSA-9xq9-36w5-q796
pkg: lmdeploy
eco: pip
published: May 21, 2026
> ## 📋 Reframing (2026-05-02): implicit unsafe remote-code path, not "supply-chain"
>
> The accurate description of this vulnerability is:
> **"`get_model_arch` and related helpers hardcode `trust_remote_code=True`
> with no opt-out, creating an implicit unsafe remote-code load path
> on every mo…
CVE-2026-46517
GitHub-GHSA

HIGH
LMDeploy: Arbitrary code execution via hardcoded trust_remote_code=True in lmdeploy model initialization
GHSA-m549-qq94-fvhg
pkg: lmdeploy
eco: pip
published: May 21, 2026
## Summary

lmdeploy hardcodes `trust_remote_code=True` in multiple HuggingFace model-loading call sites.

The affected code paths are in:

“`text
lmdeploy/archs.py
lmdeploy/utils.py
““

The vulnerable call sites pass `trust_remote_code=True` into HuggingFace Transformers APIs such as `AutoConfig…

CVE-2026-46432
GitHub-GHSA

HIGH
Graphite Has a Pickle Deserialization Vulnerability
GHSA-qw48-84f6-28gv
pkg: graphitedb
eco: pip
published: May 18, 2026
### Impact
**Type of vulnerability:** Insecure Deserialization via Python's `pickle` module.

**Who is impacted:**
Users of *Graphite graph database engine* versions **before 0.2** who load database files from untrusted or third-party sources.
An attacker could craft a malicious database file th…

GitHub-GHSA

HIGH
Network-AI: Unauthenticated Cross-Origin MCP Tool Invocation via Empty Default Secret
GHSA-j3vx-cx2r-pvg8
pkg: network-ai
eco: npm
published: May 21, 2026
# Unauthenticated Cross-Origin MCP Tool Invocation via Empty Default Secret

| Field | Value |
| —————- | —– |
| Repository | Jovancoding/Network-AI |
| Affected version | v5.4.4 (commit c12686e181f231cf8d7bcf836a96d78f0f0877ac) |

## Summary

The MCP SSE server default…

CVE-2026-46701
GitHub-GHSA

HIGH
Budibase: Unrestricted Upload of File with Dangerous Type
GHSA-82rc-gxrg-v4gf
pkg: budibase
eco: npm
published: May 19, 2026
### Summary
The file upload endpoint `POST /api/attachments/process` does not enforce active-content restrictions for authenticated users. The checks for dangerous file extensions (`html`, `svg`, `js`, `php`, etc.) are conditionally wrapped inside `if (isPublicUser)` or `if (isPublicUser || !env.SEL…
CVE-2026-46426
GitHub-GHSA

HIGH
aiosend: Deserialization of request body before signature verification (Pre-auth DoS) in webhook handler
GHSA-7m8f-hgjq-8gc9
pkg: aiosend
eco: pip
published: May 22, 2026
# Vulnerability Description

In `aiosend/webhook/base.py`, the `WebhookHandler.feed_update()` method performs full deserialization of the incoming JSON via Pydantic **before** verifying the HMAC signature. Anyone can send a request with an arbitrary body — the server will parse it, spend CPU and m…

GitHub-GHSA

HIGH
js-libp2p: Memory DoS via subscription flood of unique topics
GHSA-4f8r-922h-2vgv
pkg: @libp2p/gossipsub
eco: npm
published: May 21, 2026
### Summary
Three cooperating omissions in `@libp2p/gossipsub` allow an unauthenticated single peer to exhaust the Node.js heap of any gossipsub node with default options.

1. **`defaultDecodeRpcLimits.maxSubscriptions = Infinity`** (`packages/gossipsub/src/message/decodeRpc.ts:11`): no decode-level…

CVE-2026-46679
GitHub-GHSA

HIGH
JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection
GHSA-qjx8-664m-686j
pkg: js-cookie
eco: npm
published: May 21, 2026
## Summary

`js-cookie`'s internal `assign()` helper copies properties with `for…in` + plain assignment. When the source object is produced by `JSON.parse`, the JSON object's `"__proto__"` member is an *own enumerable* property, so the `for…in` enumerates it and the `target[key] = source[key]` w…

CVE-2026-46625
GitHub-GHSA

HIGH
Russh: Unchecked CryptoVec allocation and growth handling is reachable
GHSA-g9f8-wqj9-fjw5
pkg: russh-cryptovec, russh
eco: rust
published: May 21, 2026
### Title
Unchecked `CryptoVec` allocation and growth handling was reachable from local agent inputs in current `russh` releases and from remote SSH traffic in historical pre-`0.58.0` releases

### Summary
`CryptoVec` used unchecked capacity growth, unchecked length arithmetic, and unsafe allocation…

CVE-2026-46673
GitHub-GHSA

HIGH
nimiq-primitives: Panic DoS in trie chunk processing via ROOT-keyed item
GHSA-mw3q-r9wh-h2ff
pkg: nimiq-primitives
eco: rust
published: May 21, 2026
### Impact

A remote, unauthenticated denial-of-service vulnerability in `MerkleRadixTrie::put_chunk` allows any state-sync peer to crash any node performing state synchronization (freshly joining nodes and recovering nodes).

A malicious peer can respond to a `RequestChunk` with a `ResponseChunk::C…

CVE-2026-46545
GitHub-GHSA

HIGH
Diffusers: TOCTOU Trust Remote Code Bypass
GHSA-7wx4-6vff-v64p
pkg: diffusers
eco: pip
published: May 20, 2026
## Background

This vulnerability is found in the `diffusers` package – the `transformers`-equivalent library for diffusion models.

It is found in the `DiffusionPipeline.from_pretrained` flow, which is used to load a pipeline from the HuggingFace Hub.

This function has a `trust_remote_code` guard:…

CVE-2026-45804
GitHub-GHSA

HIGH
SQLFluff: Uncontrolled Resource Consumption in SQLFluff Parser
GHSA-73jc-5mrq-prw7
pkg: sqlfluff
eco: pip
published: May 19, 2026
### Impact

In deployments where untrusted users can provide SQL queries to be linted, an untrusted user can submit a malicious long query to any application using the parser to trigger a Denial of Service through resource exhaustion.

### Patches

Versions 4.2.0 and up contain a configurable parse …

CVE-2026-46374
GitHub-GHSA

HIGH
SQLFluff: Recursive Stack Overflow in Parser
GHSA-wmhf-fqc8-vxhh
pkg: sqlfluff
eco: pip
published: May 19, 2026
### Impact

In deployments where untrusted users can provide SQL queries to be linted, an untrusted user can submit a malicious query with deliberate excessive nesting to any application using the parser to trigger a Denial of Service through resource exhaustion.

### Patches

Versions 4.1.0 and up …

CVE-2026-46373
GitHub-GHSA

HIGH
Dasel: Denial of service in dasel selector lexer due to infinite loop on unterminated regex literal
GHSA-m6xr-fvfg-5g64
pkg: github.com/tomwright/dasel/v3
eco: go
published: May 19, 2026
### Summary

`dasel`'s selector lexer enters a non-terminating loop when tokenizing an unterminated regex pattern such as `r/abc`. A 2-byte input (`r/`) is sufficient to cause the tokenizer to consume 100% CPU on one core indefinitely.

I confirmed the issue on `v3.3.1` (`fba653c7f248aff10f2b89fca93…

CVE-2026-46378
GitHub-GHSA

HIGH
Dasel: Index-out-of-range panic in dasel selector lexer on trailing backslash in quoted string
GHSA-m5j3-4634-c2vq
pkg: github.com/tomwright/dasel/v3
eco: go
published: May 19, 2026
### Summary

`dasel`'s selector lexer panics with an index-out-of-range error when tokenizing a quoted string that ends with a trailing backslash (e.g., `"\` or `'\`). A 2-byte input causes an immediate process crash via Go runtime panic.

I confirmed the issue on `v3.3.1` (`fba653c7f248aff10f2b89fc…

CVE-2026-46377
GitHub-GHSA

HIGH
@libp2p/kad-dht: Unvalidated PUT_VALUE records allow unbounded disk exhaustion on DHT server nodes
GHSA-32mq-hpph-xfvr
pkg: @libp2p/kad-dht
eco: npm
published: May 19, 2026
### Summary
An unauthenticated remote peer can exhaust the disk storage of any `@libp2p/kad-dht` node running in server mode by sending an unbounded stream of `PUT_VALUE` messages whose keys bypass all content validation. No credentials, no prior relationship, and no protocol deviation beyond a craf…
CVE-2026-45783
GitHub-GHSA

HIGH
Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service
GHSA-7xpr-hc2w-34m9
pkg: com.squareup.wire:wire-runtime-jvm, com.squareup.wire:wire-runtime, com.squareup.wire:wire-runtime
eco: maven
published: May 19, 2026
# CVE-2026-45799

## Maintainer summary

Wire's protobuf group-skipping logic did not reject negative lengths before skipping a
length-delimited field inside a group. A crafted protobuf payload could cause Wire to throw an
unchecked runtime exception during decoding instead of the documented `IOExce…

CVE-2026-45799
GitHub-GHSA

HIGH
Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes
GHSA-fpxj-m5q8-fphw
pkg: github.com/axllent/mailpit
eco: go
published: May 19, 2026
### Summary
The Mailpit SMTP server has a Server.MaxSize int field that controls the maximum allowed DATA payload size, but the field is never assigned anywhere outside test code, leaving it at Go's zero value (0 ⇒ "no limit"). The same applies to the HTTP /api/v1/send endpoint, whose request body…
CVE-2026-45713
GitHub-GHSA

HIGH
Algernon: Single-file mode unconditionally enables debug mode
GHSA-fwqx-8365-9983
pkg: github.com/xyproto/algernon
eco: go
published: May 19, 2026
### Summary

When Algernon is invoked with a single file path instead of a directory — the documented "quick demo" workflow (`algernon foo.lua`, `algernon page.po2`, `algernon index.html`, `algernon mywebsite.alg`) — `singleFileMode` is set to true and **`debugMode` is forcibly enabled** with no…

CVE-2026-45728
GitHub-GHSA

HIGH
ImageMagick: Infinite Loop in the MIFF decoder can lead to CPU exhaustion
GHSA-7gg8-qqx7-92g5
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 18, 2026
Due to a missing check in the MIFF decoder a crafted file could cause an infinite loop resulting in CPU exhaustion.
CVE-2026-46522
GitHub-GHSA

HIGH
ImageMagick: Heap Buffer Over-Write in IPL decoder when reading multiple images of different dimensions
GHSA-36wm-hprc-mcf5
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 18, 2026
When reading multiple images with different dimensions an out of bounds heap write can occur.
CVE-2026-46520
GitHub-GHSA

HIGH
HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint
GHSA-3653-68v6-rq57
pkg: ca.uhn.hapi.fhir:org.hl7.fhir.dstu2, ca.uhn.hapi.fhir:org.hl7.fhir.dstu2016may, ca.uhn.hapi.fhir:org.hl7.fhir.dstu3
eco: maven
published: May 18, 2026
## Summary

All implementations of FHIRPathEngine accept arbitrary FHIRPath expressions and evaluate them without input validation. The FHIRPath functions `matches()`, `matchesFull()`, and `replaceMatches()` pass user-controlled regular expressions directly to Java's `Pattern.compile()` and `String.…

CVE-2026-45367
GitHub-GHSA

HIGH
NiceGUI: Local file disclosure via Docutils file insertion in ui.restructured_text()
GHSA-jfrm-rx66-g536
pkg: nicegui
eco: pip
published: May 18, 2026
### Summary

`ui.restructured_text()` renders reStructuredText server-side with Docutils without disabling file insertion directives.

When a NiceGUI application passes attacker-controlled content to `ui.restructured_text()`, an attacker can use standard Docutils directives (`include`, `csv-table` w…

CVE-2026-45553
GitHub-GHSA

HIGH
OpenTelemetry eBPF Instrumentation: Memcached payload length overflow can crash OBI
GHSA-43g7-cwr8-q3jh
pkg: go.opentelemetry.io/obi
eco: go
published: May 18, 2026
### Summary

A remotely reachable integer overflow in OBI's memcached text protocol parser can crash the OBI process and cause denial of service. When parsing memcached storage commands such as `set`, `add`, `replace`, `append`, `prepend`, or `cas`, OBI accepts extremely large `<bytes>` values and a…

CVE-2026-45686
GitHub-GHSA

HIGH
OpenTelemetry eBPF Instrumentation: MongoDB parser panics on malformed wire messages
GHSA-j8p6-96vp-f3r9
pkg: go.opentelemetry.io/obi
eco: go
published: May 18, 2026
### Summary

Malformed MongoDB wire messages can trigger uncaught panics in the MongoDB TCP parser, allowing a remote unauthenticated attacker to crash the telemetry agent and cause a denial of service. The parser operates on raw attacker-controlled network payloads before the input is fully validat…

CVE-2026-45685
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-42899 – ASP.NET Core Denial of Service Vulnerability
GHSA-9v76-4qcc-frgh
pkg: Microsoft.AspNetCore.App.Runtime.win-arm, Microsoft.AspNetCore.App.Runtime.win-arm64, Microsoft.AspNetCore.App.Runtime.win-x64
eco: nuget
published: May 18, 2026
## Executive Summary:

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 8.0, .NET 9.0, and .NET 10.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

Loop with unreachable ex…

CVE-2026-42899
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-32175 – .NET Core Tampering Vulnerability
GHSA-rg75-q538-x34v
pkg: Microsoft.NetCore.App.Runtime.win-arm, Microsoft.NetCore.App.Runtime.win-arm, Microsoft.NetCore.App.Runtime.win-arm
eco: nuget
published: May 18, 2026
## Executive Summary:

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 8.0, .NET 9.0, and .NET 10.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A tampering vulnerabil…

CVE-2026-32175
GitHub-GHSA

HIGH
OpenTelemetry eBPF Instrumentation: Postgres BIND parsing can panic on malformed payloads
GHSA-pgvv-q3wf-mm9m
pkg: go.opentelemetry.io/obi
eco: go
published: May 18, 2026
### Summary

The Postgres protocol parser assumes `BIND` message payloads contain a valid NUL-terminated portal name. A crafted empty or unterminated payload can make OBI slice beyond the end of the captured buffer and panic.

### Details

The vulnerable logic is in [pkg/ebpf/common/sql_detect_postg…

CVE-2026-45678
GitHub-GHSA

HIGH
multiparty vulnerable to ReDoS via filename parsing
GHSA-65×3-rw7q-gx94
pkg: multiparty
eco: npm
published: May 18, 2026
### Impact

multiparty@4.2.3 and lower versions are vulnerable to denial of service via regular expression backtracking in the `Content-Disposition` filename parameter parser. A multipart upload with a long header value containing `!filename="1` repeated can cause regex matching to take seconds, blo…

CVE-2026-8159
GitHub-GHSA

HIGH
multiparty vulnerable to Denial of Service via Uncaught Exception in filename* parameter parsing
GHSA-xh3c-6gcq-g4rv
pkg: multiparty
eco: npm
published: May 18, 2026
### Impact

multiparty@4.2.3 and lower versions are vulnerable to denial of service via uncaught exception. By sending a `multipart/form-data` request with a `Content-Disposition: filename*=utf-8''` header containing a malformed percent-encoding (e.g., `%FF`, `%GG`), the parser invokes `decodeURI` o…

CVE-2026-8162
GitHub-GHSA

HIGH
multiparty: Denial of Service via Prototype Pollution leads to Uncaught Exception
GHSA-qxch-whhj-8956
pkg: multiparty
eco: npm
published: May 18, 2026
### Impact

multiparty@4.2.3 and lower versions are vulnerable to denial of service via uncaught exception. By sending a `multipart/form-data` request with a field name that collides with an inherited `Object.prototype` property (e.g., `__proto__`, `constructor`, `toString`), the parser invokes `.pu…

CVE-2026-8161
GitHub-GHSA

HIGH
dynoxide: DNS rebinding and cross-origin CSRF via MCP HTTP transport
GHSA-fvh2-gm75-j4j7
pkg: dynoxide-rs, dynoxide
eco: npm
published: May 18, 2026
## Summary

dynoxide's MCP HTTP transport was vulnerable to DNS rebinding via its transitive `rmcp` dependency, plus a related cross-origin CSRF gap. A malicious web page could make the user's browser send requests to a local `dynoxide mcp –http` or `dynoxide serve –mcp` server with a non-loopback…

GitHub-GHSA

HIGH
iskorotkov/avro: CPU Exhaustion in Decoder
GHSA-w8j3-pq8g-8m7w
pkg: github.com/iskorotkov/avro/v2
eco: go
published: May 18, 2026
# CPU Exhaustion in Avro Decoder via Unbounded Block-Count Iteration

## Summary

The Avro array and map decoders looped over an attacker-controlled block-count value without checking the underlying reader's error state inside the loop body. `Reader.ReadBlockHeader` returns the count as a Go `int`, …

CVE-2026-46385
GitHub-GHSA

HIGH
iskorotkov/avro: Integer Overflow in Decoder
GHSA-mc57-h6j3-3hmv
pkg: github.com/iskorotkov/avro/v2
eco: go
published: May 18, 2026
# Integer Overflow in Avro Decoder

## Summary

Several Avro decoder paths read attacker-controlled 64-bit values from the wire format and either narrowed them to platform-sized `int` before bounds-checking, or summed them with overflow-prone signed-`int` arithmetic. On 32-bit targets (`GOARCH=386`,…

CVE-2026-46384
GitHub-GHSA

HIGH
iskorotkov/avro: Denial-of-Service Vulnerability in Decoder
GHSA-mx64-mj3q-7prj
pkg: github.com/iskorotkov/avro/v2
eco: go
published: May 18, 2026
# Memory Exhaustion via Unbounded Map Allocations in Avro Decoder

## Summary

The Avro map decoder accepted attacker-controlled block-element counts from the wire format and grew the destination map without enforcing an upper bound. The slice decoder already had `Config.MaxSliceAllocSize` for the e…

GitHub-GHSA

HIGH
ruby-jwt: Empty-key HMAC bypass; cross-language sibling of CVE-2026-44351
GHSA-c32j-vqhx-rx3x
pkg: jwt
eco: rubygems
published: May 18, 2026
`JWT.decode(token, '', true, algorithm: 'HS256')` accepts an attacker-forged token.
`OpenSSL::HMAC.digest('SHA256', '', payload)` returns a valid digest under an empty key, and no `raise
InvalidKeyError if key.empty?` precondition exists in the HMAC algorithm.

“`
JWT.decode(token, "", true, algo…

CVE-2026-45363
GitHub-GHSA

HIGH
async-http-client: Cookie header not stripped on cross-origin redirect
GHSA-fmxf-pm6p-7xgm
pkg: org.asynchttpclient:async-http-client, org.asynchttpclient:async-http-client
eco: maven
published: May 18, 2026
## Summary

async-http-client leaks `Cookie` headers to cross-origin redirect targets. When following a redirect across a security boundary (different origin, or HTTPS→HTTP downgrade), the `propagatedHeaders()` method in `Redirect30xInterceptor.java` strips `Authorization` and `Proxy-Authorization…

CVE-2026-45300
GitHub-GHSA

HIGH
Microsoft APM: Symlinks under `.apm/prompts/` and `.apm/agents/` are dereferenced during `apm install`, copying host-local file contents into the project tree
GHSA-q5pp-gvjg-h7v4
pkg: apm
eco: pip
published: May 18, 2026
## Summary

Two primitive integrators in `apm-cli` enumerate package files with bare `Path.glob()` / `Path.rglob()` calls and read each match with `Path.read_text()`, transparently following symbolic links.

A symlink committed inside a remote APM dependency under `.apm/prompts/<x>.prompt.md` or `.a…

CVE-2026-45539
GitHub-GHSA

HIGH
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation
GHSA-h98r-wv3h-fr38
pkg: github.com/argoproj/argo-cd/v3, github.com/argoproj/argo-cd/v3, github.com/argoproj/argo-cd/v3
eco: go
published: May 19, 2026
### Summary

A user with **application write access (developer role)** can set `link.argocd.argoproj.io/*` annotations on any ArgoCD Application. These annotation values are rendered in the Summary tab's **URLs section** as `<a href>` elements without URL validation. Using the pipe-separator trick (…

CVE-2026-45738
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-35433 – .NET Elevation of Privilege Vulnerability
GHSA-8x9c-mqxv-q2pp
pkg: Microsoft.WindowsDesktop.App.Runtime.win-arm64, Microsoft.WindowsDesktop.App.Runtime.win-x64, Microsoft.WindowsDesktop.App.Runtime.win-x86
eco: nuget
published: May 18, 2026
## Executive Summary:

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 8.0, .NET 9.0, and .NET 10.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

Improper input validatio…

CVE-2026-35433
GitHub-GHSA

HIGH
md-fileserver: Stored/Reflected XSS when viewing Markdown (raw HTML allowed)
GHSA-32q2-hhr5-6qvv
pkg: md-fileserver
eco: npm
published: May 21, 2026
### Summary
A cross-site scripting (XSS) vulnerability exists in the application’s Markdown rendering logic. When user-supplied Markdown content is rendered, embedded raw HTML—including <script> tags—is processed and injected into the resulting page without sanitization, allowing arbitrary Jav…
CVE-2026-46492
GitHub-GHSA

HIGH
Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK ModelBuilder/Serve path
GHSA-7hh5-prp2-mfh5
pkg: sagemaker, sagemaker
eco: pip
published: May 21, 2026
## Summary
Amazon SageMaker Python SDK is an open-source library for training and deploying machine learning models on Amazon SageMaker. An issue exists where, under certain circumstances, the ModelBuilder/Serve component stores an HMAC signing key in cleartext as a container environment variable, w…
CVE-2026-8596
GitHub-GHSA

HIGH
Docker: Race condition in docker cp allows bind mount redirection to host path
GHSA-rg2x-37c3-w2rh
pkg: github.com/docker/docker, github.com/moby/moby/v2, github.com/moby/moby
eco: go
published: May 18, 2026
## Summary

A race condition during `docker cp` mount setup allows a malicious container to redirect a bind mount target to an arbitrary host path, potentially overwriting host files or causing denial of service.

## Details

When copying files into a container, the daemon sets up a temporary filesy…

CVE-2026-42306
GitHub-GHSA

HIGH
Docker: `PUT /containers/{id}/archive` executes container binary on the host
GHSA-x86f-5xw2-fm2r
pkg: github.com/moby/moby/v2, github.com/docker/docker, github.com/moby/moby
eco: go
published: May 18, 2026
## Summary

When a user uploads a compressed archive into a container, a malicious image can execute arbitrary code with daemon (host root) privileges.

## Details

When handling `PUT /containers/{id}/archive` requests with compressed archives, the daemon decompresses them using external system bina…

CVE-2026-41567
GitHub-GHSA

HIGH
Spring AI MCP Security: Unvalidated URL Fetching (SSRF)
GHSA-qjp4-4jvr-xqg3
pkg: org.springaicommunity:mcp-client-security
eco: maven
published: May 18, 2026
### Summary

The mcp-security framework fails to implement the mandatory SSRF mitigations outlined in the Model Context Protocol (MCP) [security specifications](https://modelcontextprotocol.io/docs/tutorials/security/security_best_practices#mitigation-3). Specifically, it processes untrusted URLs fo…

CVE-2026-45609
GitHub-GHSA

HIGH
Parse Server: Pre-authentication denial of service via client version header regex backtracking
GHSA-38m6-82c8-4xfm
pkg: parse-server, parse-server
eco: npm
published: May 23, 2026
### Impact

An unauthenticated attacker who knows a publicly-known Parse Application ID can submit a single HTTP request whose client SDK version field contains adversarial input that triggers polynomial backtracking in a request-header parser. The parsing runs before session authentication and befo…

CVE-2026-47138
GitHub-GHSA

HIGH
@nevware21/ts-utils: Prototype Pollution in objDeepCopy/objCopyProps via for…in without hasOwnProperty
GHSA-x7j8-49r8-mr43
pkg: @nevware21/ts-utils
eco: npm
published: May 21, 2026
## Summary

The _copyProps function in lib/src/object/copy.ts uses for…in to iterate over source object properties without an Object.hasOwnProperty check, and does not filter dangerous keys (__proto__, constructor, prototype). This allows an attacker to pollute the prototype chain of all objects i…

CVE-2026-46681
GitHub-GHSA

HIGH
containerd user ID handling bypass allows runAsNonRoot evasion
GHSA-fqw6-gf59-qr4w
pkg: github.com/containerd/containerd, github.com/containerd/containerd/v2, github.com/containerd/containerd/v2
eco: go
published: May 21, 2026
### Impact
A bug was found in containerd where containers launched with a numeric `User` directive that cannot be parsed as a 32-bit integer are incorrectly treated as a username. If a crafted image provides an `/etc/passwd` file mapping this large numeric string to root, the container ultimately ru…
CVE-2026-46680
GitHub-GHSA

HIGH
@hulumi/policies: Stack-wide evidence bypassed Cloudflare and deployment-governance guardrails
GHSA-59f3-7227-wmh4
pkg: @hulumi/policies
eco: npm
published: May 21, 2026
Impact: @hulumi/policies versions before 1.3.2 used stack-wide evidence shortcuts in several Cloudflare and deployment-governance validators. Unrelated compliant-looking evidence could suppress violations for different zones, hostnames, origins, or repositories in the same stack.

Patched in 1.3.2: …

GitHub-GHSA

HIGH
@hulumi/policies: CIS 1.16 admin policy bypass for inline and attached IAM policies
GHSA-4xrh-5m3m-328w
pkg: @hulumi/policies
eco: npm
published: May 21, 2026
Impact: @hulumi/policies versions before 1.3.2 did not fully inspect inline and attached IAM policy evidence for the administrator-policy guardrail, so some admin-equivalent policy paths could pass policy evaluation.

Patched in 1.3.2: the validator inspects the affected policy shapes and includes r…

GitHub-GHSA

HIGH
@hulumi/policies: HULUMI-H1 SecureBucket parent spoof bypass
GHSA-g43v-9x7q-83pq
pkg: @hulumi/policies
eco: npm
published: May 21, 2026
Impact: @hulumi/policies versions before 1.3.2 could accept spoofed SecureBucket parent evidence for HULUMI-H1, allowing policy evaluation to miss an unsafe bucket shape.

Patched in 1.3.2: the validator now correlates evidence to the expected component/resource relationship and includes regression …

GitHub-GHSA

HIGH
@hulumi/drift: Orphan reconciler accepted externally supplied execute plans
GHSA-2ffm-hxrq-qqmm
pkg: @hulumi/drift
eco: npm
published: May 21, 2026
Impact: @hulumi/drift versions before 1.3.2 could accept externally supplied execute plans without sufficient provenance checks, allowing unsafe reconciliation input to be treated as trusted.

Patched in 1.3.2: execute-plan handling now validates provenance and rejects untrusted plans, with regressi…

GitHub-GHSA

HIGH
Plonky3 MultiField32Challenger: transcript malleability and challenge entropy loss
GHSA-vj64-rjf3-w3v7
pkg: p3-challenger, p3-challenger
eco: rust
published: May 21, 2026
### Impact

– **Key**: `challenger/src/multi_field_challenger.rs` | `MultiField32Challenger::duplexing` | `transcript_malleability`
– **Affected files**: `challenger/src/multi_field_challenger.rs`, `field/src/helpers.rs`
– **Violated invariant**: The Fiat-Shamir sponge must bind challenges to the ex…

CVE-2026-46654
GitHub-GHSA

HIGH
Fission runtime pods automount the fission-fetcher service-account token into the user function container, granting function code namespace-wide secret / configmap read
GHSA-85g2-pmrx-r49q
pkg: github.com/fission/fission
eco: go
published: May 21, 2026
### Summary

Fission runtime pods were created with `ServiceAccountName: fission-fetcher`, and the `fission-fetcher` ServiceAccount was granted namespace-wide `get` on `secrets` and `configmaps` (it needs that to load function code, env vars, and config). The runtime pod's automounted token was reac…

CVE-2026-46617
GitHub-GHSA

HIGH
samlify: XML Injection in AttributeValue Allows Privilege Escalation in Signed SAML Assertions
GHSA-34r5-q4jw-r36m
pkg: samlify
eco: npm
published: May 21, 2026
## Summary

samlify’s template substitution only escapes attribute contexts. Values inserted into element text (e.g., `<saml:AttributeValue>`) are not escaped. A normal user can inject XML markup into an attribute value (e.g., email, name) and add new `<saml:Attribute>` elements inside the signed …

CVE-2026-46490
GitHub-GHSA

HIGH
Windows-MCP: HTTP transports expose unauthenticated PowerShell control with wildcard CORS
GHSA-vrxg-gm77-7q5g
pkg: windows-mcp
eco: pip
published: May 21, 2026
HTTP transports expose unauthenticated PowerShell control with wildcard CORS

There is an issue in the SSE and Streamable HTTP transport modes. The default stdio mode is not affected, but the documented HTTP modes expose the MCP control plane without authentication and add wildcard CORS handling aro…

GitHub-GHSA

HIGH
@angular/platform-server: SSRF via Hostname Hijacking
GHSA-rfh7-fxqc-q52v
pkg: @angular/platform-server, @angular/platform-server, @angular/platform-server
eco: npm
published: May 19, 2026
### Impact

A Server-Side Request Forgery (SSRF) vulnerability exists in `@angular/platform-server`. The issue stems from how the server-side rendering (SSR) engine processes the request URL provided to the rendering entry points.

When an absolute-form URL (e.g., `http://evil.com`) is passed to the…

CVE-2026-46417
GitHub-GHSA

HIGH
FileBrowser Quantum: unauthenticated user share share info
GHSA-3jmg-p96m-m328
pkg: github.com/gtsteffaniak/filebrowser/backend, github.com/gtsteffaniak/filebrowser
eco: go
published: May 19, 2026
### Impact
Some sensitive info — such as source and path can get exposed.

### Patches
Update to the latest version

### Workarounds
no

CVE-2026-46410
GitHub-GHSA

HIGH
CamoFox MCP: Unauthenticated HTTP MCP browser-control surface
GHSA-7hgr-7h44-33w2
pkg: camofox-mcp
eco: npm
published: May 19, 2026
# Unauthenticated HTTP MCP browser-control surface in `camofox-mcp`

## Summary

`camofox-mcp` exposed a Streamable HTTP MCP endpoint at `/mcp` with rate limiting but no inbound MCP-layer authentication. When HTTP mode was enabled, any client that could reach `/mcp` could list and invoke browser-con…

GitHub-GHSA

HIGH
libcrux-ml-dsa: Signature Verification on AVX2 Platforms Mishandles Edge Case
GHSA-fhvh-vw7h-9xf3
pkg: libcrux-ml-dsa
eco: rust
published: May 19, 2026
The AVX2 implementation of ML-DSA verification incorrectly implemented
the `use_hint` function, mishandling an edge case that should lead to
signature rejection.

## Impact
An attacker could make the ML-DSA verifier accept a crafted invalid
signature under a maliciously generated verification key, i…

GitHub-GHSA

HIGH
libcrux: Potential Panic on Overlong Ciphertext Buffer
GHSA-hc3c-63hc-2r9f
pkg: libcrux-chacha20poly1305
eco: rust
published: May 19, 2026
An application that passes in a ciphertext buffer of length greater
than `ptxt.len() + TAG_LEN` to `libcrux_chacha20poly1305::encrypt` or
`libcrux_chacha20poly1305::xchacha20_poly1305::encrypt` would
experience a panic.

## Impact
An application where the length of the ciphertext buffer is under
att…

GitHub-GHSA

HIGH
zrok copy writes attacker-controlled WebDAV paths outside the destination root
GHSA-c656-jcx2-7pqj
pkg: github.com/openziti/zrok/v2, github.com/openziti/zrok
eco: go
published: May 19, 2026
## Summary

Alice runs `zrok2 copy` from a WebDAV or zrok drive controlled by Bob into a local filesystem target. Bob returns a DAV `href` such as `/../outside.txt`. The sync pipeline stores that path in the source inventory and passes it to `FilesystemTarget.WriteStream`, which joins it with the ta…

CVE-2026-45576
GitHub-GHSA

HIGH
HAXcms: Mass Token Exfiltration and Cross-Tenant Hijack
GHSA-x3x5-7h4h-gwxg
pkg: @haxtheweb/haxcms-nodejs
eco: npm
published: May 19, 2026
### Summary
An attack chain utilizing **Stored XSS** alongside dynamic token exposure in the `/system/api/connectionSettings` endpoint allows an authenticated attacker to perform a complete cross-tenant account takeover. The API dynamically leaks the active session's authentication tokens (including…
CVE-2026-46511
GitHub-GHSA

HIGH
Stored XSS via <iframe> in HAX CMS allows access to sensitive client-side data and account takeover
GHSA-jh3h-rpxg-fr36
pkg: @haxtheweb/haxcms-nodejs, @haxtheweb/video-player, @haxtheweb/iframe-loader
eco: npm
published: May 19, 2026
### Summary
A stored cross-site scripting (XSS) vulnerability exists in HAX CMS due to improper sanitization of `<iframe>` elements.

The application allows `javascript:` URIs in the `src` attribute, which are executed when a malicious page is viewed. This enables attackers to execute arbitrary Java…

CVE-2026-46396
GitHub-GHSA

HIGH
HAX open-apis: Credential Theft via Server-Side Request Forgery (SSRF) in open-apis
GHSA-4fg7-f244-3j49
pkg: @haxtheweb/open-apis
eco: npm
published: May 19, 2026
### Summary
Multiple functions conduct substring-only matching to validate hostnames to which basic authorization should be sent. An attacker can append the matched substrings to an attacker-controlled endpoint and capture authentication.

### Details
[api/services/website/cacheAddress.js](https://g…

CVE-2026-46391
GitHub-GHSA

HIGH
HAXcms createSite SSRF Enables Arbitrary File Read
GHSA-q862-gcgq-5m6g
pkg: @haxtheweb/haxcms-nodejs
eco: npm
published: May 19, 2026
### Summary
An authenticated Server-Side Request Forgery (SSRF) vulnerability in HAXcms allows users to fetch arbitrary internal or local resources and write the responses to a web-accessible directory, enabling arbitrary file read and internal network access.

### Details
The `createSite` endpo…

CVE-2026-46393
GitHub-GHSA

HIGH
Scriban: array.insert_at index parameter DoS bypasses LoopLimit and LimitToString
GHSA-24c8-4792-22hx
pkg: scriban
eco: nuget
published: May 19, 2026
## Summary

`ArrayFunctions.InsertAt` in Scriban allocates `index – list.Count` null entries in a tight C# `for` loop with no bound on `index`. The function is exposed to template authors as `array.insert_at`, and the fill loop ignores every existing safety control: `LoopLimit`, `LimitToString`, `Ob…

GitHub-GHSA

HIGH
CloakBrowser: Unauthenticated path traversal via fingerprint parameter in cloakserve leads to arbitrary directory deletion
GHSA-mf33-gv72-w2h5
pkg: cloakbrowser
eco: pip
published: May 18, 2026
The `cloakserve` CDP multiplexer uses the user-supplied `fingerprint` query parameter directly as a filesystem path component when creating Chrome profile directories. An unauthenticated attacker who can reach the cloakserve port can supply a crafted `fingerprint` value containing path traversal seq…
CVE-2026-45727
GitHub-GHSA

HIGH
eduMFA Passkeys: missing expiration flag may allow replay attacks and reuse of old challenges
GHSA-j5rm-v3vh-vx94
pkg: edumfa
eco: pip
published: May 18, 2026
### Impact
In eduMFA < 2.9.1 userless Passkey/WebAuthn challenges might be replayed and do not expire

### Patches
Fixed in eduMFA >= 2.9.1 by adding validity information to the userless challenges.

### Workarounds
No known workarounds besides disabling userless login altogether.

GitHub-GHSA

HIGH
eduMFA: Incorrect InnoDB snapshot isolation possibly allows token reusage
GHSA-qq2p-4282-cfc5
pkg: edumfa
eco: pip
published: May 18, 2026
### Impact

For deployments using MySQL or MariaDB < 11.6.2 (or newer with innodb_snapshot_isolation=off) reusage of token values might be possible due to faulty transaction isolation inside the database. Exploiting this requires racing this transaction.
Affected are all tokentypes whose values are …

GitHub-GHSA

MEDIUM
n8n: Credential exfiltration via Allowed HTTP Request Domains Bypass
GHSA-3875-8gcx-7v46
pkg: n8n
eco: npm
published: May 19, 2026
## Impact
The `POST /rest/dynamic-node-parameters/options` endpoint allowed any authenticated user to cause the n8n server to issue HTTP requests including credentials bypassing the intended restrictions on which hosts could be contacted for that credential (Allowed HTTP Request Domains). The user n…
GitHub-GHSA

MEDIUM
Amazon SageMaker Python SDK is missing integrity verification in its Triton inference handler
GHSA-rq6v-x3j8-7qgf
pkg: sagemaker, sagemaker
eco: pip
published: May 21, 2026
## Summary
Amazon SageMaker Python SDK is an open-source library for training and deploying machine learning models on Amazon SageMaker. An issue exists where, under certain circumstances, the Triton inference handler deserializes model artifacts without performing integrity verification, allowing s…
CVE-2026-8597
GitHub-GHSA

MEDIUM
Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of CVE-2026-25580)
GHSA-cqp8-fcvh-x7r3
pkg: pydantic-ai, pydantic-ai-slim
eco: pip
published: May 21, 2026
## Summary

When an application using Pydantic AI opts a URL into `force_download='allow-local'` (which disables the default block on private/internal IPs), the cloud-metadata blocklist could be bypassed by encoding the metadata IP in an IPv6 transition form (IPv4-mapped IPv6, 6to4, or NAT64). Dual-…

CVE-2026-46678
GitHub-GHSA

MEDIUM
Nezha Monitoring: Nezha WebSocket server stream discloses cross-tenant server telemetry to authenticated members
GHSA-hvv7-hfrh-7gxj
pkg: github.com/nezhahq/nezha
eco: go
published: May 23, 2026
### Summary

Any authenticated non-admin member can connect to the server-status WebSocket and receive telemetry for all servers, including servers owned by other users. The normal server list API filters objects by `HasPermission`, but the WebSocket stream treats the presence of any authenticated u…

CVE-2026-47124
GitHub-GHSA

MEDIUM
instagrapi: Unsafe signup challenge path handling in instagrapi
GHSA-ggxf-37hm-9wqf
pkg: instagrapi
eco: pip
published: May 23, 2026
instagrapi versions before 2.6.9 accepted server-supplied signup challenge paths and used them to build request URLs before validating that the paths were relative Instagram API paths. A malicious or tampered challenge payload could cause challenge handling requests to be sent outside the intended I…
GitHub-GHSA

MEDIUM
aiograpi: Unsafe signup challenge path handling
GHSA-jh37-x3fv-4×72
pkg: aiograpi
eco: pip
published: May 23, 2026
aiograpi versions before 0.9.10 accepted server-supplied signup challenge paths and used them to build request URLs before validating that the paths were relative Instagram API paths. A malicious or tampered challenge payload could cause challenge handling requests to be sent outside the intended In…
CVE-2026-47157
GitHub-GHSA

MEDIUM
FlaskBB: SSRF in get_image_info() via unrestricted avatar URL
GHSA-xq32-9g7q-7297
pkg: flaskbb
eco: pip
published: May 21, 2026
###Summary
A Server-Side Request Forgery (SSRF) vulnerability in get_image_info() allows any authenticated user to force the server to send HTTP requests to arbitrary internal endpoints, including cloud metadata services (e.g., AWS 169.254.169.254). This is a blind SSRF with confirmed internal port …
CVE-2026-46556
GitHub-GHSA

MEDIUM
NocoDB: Missing File Size Enforcement in Upload-by-URL Allows Denial of Service via Disk Exhaustion
GHSA-99vc-2jx2-688p
pkg: nocodb
eco: npm
published: May 21, 2026
### Summary

The `uploadViaURL` path in the v1/v2 attachment API did not enforce `NC_ATTACHMENT_FIELD_SIZE` against the remote `content-length` or against the response stream. An authenticated user (Editor+) could direct the server to download arbitrarily large files, exhausting disk space and causi…

CVE-2026-46551
GitHub-GHSA

MEDIUM
Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint
GHSA-686c-7vgv-v3fx
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: May 19, 2026
## Summary

Unauthenticated semi-blind Server-Side Request Forgery (SSRF) via the Azure instance identity endpoint (`POST /api/v2/workspaceagents/azure-instance-identity`). An external attacker can force the Coder server to issue HTTP GET requests to arbitrary internal or external hosts by submittin…

CVE-2026-45796
GitHub-GHSA

MEDIUM
HAX CMS: Denial of Service using Malicious Import Request
GHSA-9r33-xhw8-4qqp
pkg: @haxtheweb/haxcms-nodejs
eco: npm
published: May 19, 2026
### Summary

The HAX CMS NodeJS application crashes when an authenticated attacker sends a specially crafted site creation request to the createSite endpoint. A single request is sufficient to take the entire application offline, requiring a manual server restart to restore service.

### Details

Th…

CVE-2026-46357
GitHub-GHSA

MEDIUM
OpenTelemetry eBPF Instrumentation: Redis error text is exported in span status messages
GHSA-8rrq-wcg8-cv5q
pkg: go.opentelemetry.io/obi
eco: go
published: May 18, 2026
### Summary

OBI exports raw Redis error text as the span status message. Because Redis error replies can contain attacker-controlled or sensitive values, this behavior can exfiltrate tokens, PII, or other confidential input into telemetry backends and inject untrusted text into downstream analysis …

CVE-2026-45679
GitHub-GHSA

MEDIUM
Budibase: CouchDB Reduce Injection via Unsanitized Calculation Parameter in V1 Views API
GHSA-363w-hvwh-w7m6
pkg: @budibase/server
eco: npm
published: May 18, 2026
# Security Advisory: CouchDB Reduce Injection via Unsanitized Calculation Parameter in V1 Views API

**Affected Software:** Budibase
**Affected Component:** `packages/server/src/api/controllers/view/viewBuilder.ts`, `packages/server/src/api/routes/view.ts`
**CWE:** CWE-94 (Improper Control of Genera…

CVE-2026-45719
GitHub-GHSA

MEDIUM
brace-expansion: Large numeric range defeats documented `max` DoS protection
GHSA-jxxr-4gwj-5jf2
pkg: brace-expansion
eco: npm
published: May 18, 2026
The `max` option was being applied too late:

When expanding a single large numeric range like `{1..10000000}`, the sequence generation loop generates all 10 million intermediate elements before the `max` limit is applied With `max=10`, the output is correctly limited to 10 items, but the process st…

CVE-2026-45149
GitHub-GHSA

MEDIUM
eduMFA: Unauthenticated Failcounter Increment on Resolver Tokens via /validate/check
GHSA-74r7-3mjm-jc5v
pkg: edumfa
eco: pip
published: May 18, 2026
### Impact
If the resolver parameter is passed, but the user does not exist, all failcounters of tokens in that resolver will be increased.

### Patches
This, along with other issues, was fixed in eduMFA v2.9.1.

### Workarounds
Limiting access to `/validate/check` to client applications (i.e. Shibb…

GitHub-GHSA

MEDIUM
n8n-MCP: Workflow telemetry sanitizer could retain partial values from URL-shaped node parameters
GHSA-f3rg-xqjj-cj9w
pkg: n8n-mcp
eco: npm
published: May 18, 2026
## Summary

In affected versions of n8n-mcp, the workflow telemetry sanitizer could retain partial fragments of URL-shaped node parameters before sending workflow data to the project's anonymous telemetry backend. Values placed in HTTP-Request-style node parameters — such as customer or tenant ide…

CVE-2026-45582
GitHub-GHSA

MEDIUM
n8n: Legacy ExecuteWorkflow Node Bypassed File Path Restrictions
GHSA-2vx9-7wpg-88jq
pkg: n8n
eco: npm
published: May 19, 2026
## Impact
The `ExecuteWorkflow` node's `localFile` source option read workflow files from disk without applying checks enforced by other file-reading nodes. An authenticated user with permission to create or modify workflows could supply an arbitrary file path via the REST API, bypassing the `N8N_RE…
GitHub-GHSA

MEDIUM
Klever-Go KVM read-only execution can commit contract delete and upgrade side effects
GHSA-jc6w-wmfc-fh33
pkg: github.com/klever-io/klever-go
eco: go
published: May 21, 2026
## Publisher note

**Fixed in `v1.7.17`.** Operators running `< v1.7.17` should upgrade. Contract delete and upgrade host-core paths now reject execution when `runtime.ReadOnly()` is true. The invariant is regression-tested for delete, upgrade, storage writes, value transfers, and any VM output fiel…

CVE-2026-46403
GitHub-GHSA

MEDIUM
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations
GHSA-rg3g-4rw9-gqrp
pkg: github.com/argoproj/argo-cd/v3, github.com/argoproj/argo-cd/v3, github.com/argoproj/argo-cd/v3
eco: go
published: May 19, 2026
### Summary
The original fix for [GHSA-3v3m-wc6v-x4x3](https://github.com/argoproj/argo-cd/security/advisories/GHSA-3v3m-wc6v-x4x3) is incomplete. argocd app diff –server-side-diff can still expose Kubernetes Secret values embedded in the kubectl.kubernetes.io/last-applied-configuration annotation.…
CVE-2026-45737
GitHub-GHSA

MEDIUM
Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameter
GHSA-9mvm-4gwg-v8mp
pkg: github.com/getarcaneapp/arcane/backend
eco: go
published: May 18, 2026
## Summary

`GET /environments/{id}/volumes/{volumeName}/browse` accepts a `path` query parameter that is passed to a shell command (`sh -c "find … | while …"`) inside an Arcane helper container. The path sanitiser blocks `../` traversal but does not strip Bourne-shell metacharacters such as `$(…

CVE-2026-45626
GitHub-GHSA

MEDIUM
ImageMagick: Heap Buffer Over-Write in json and yaml encoder of a single byte due to incorrect fix
GHSA-jqq5-8px3-9m6m
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 21, 2026
An incorrect fix that was applied in GHSA-5592-p365-24xh could result in a heap buffer over-write of a single byte.
GitHub-GHSA

MEDIUM
OpenMcdf: Uncatchable infinite loop in DirectoryTree.TryGetDirectoryEntry on crafted CFB directory cycle
GHSA-5qwm-7pvp-w988
pkg: OpenMcdf
eco: nuget
published: May 19, 2026
### Summary
The BST name-lookup loop in `DirectoryTree.TryGetDirectoryEntry` (`OpenMcdf/DirectoryTree.cs:35-46`) walks directory entries by repeatedly calling `directories.TryGetSibling(child, siblingType, validateColor)`. A crafted CFB file with cyclic Left/Right sibling links among directory entri…
CVE-2026-45785
GitHub-GHSA

MEDIUM
ImageMagick: Stack overflow in fx operation
GHSA-rcr6-g7jc-f57g
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 18, 2026
Due to a missing depth check a stack overflow can occur in the fx operation by passing a crafted argument.
CVE-2026-46557
GitHub-GHSA

MEDIUM
ImageMagick: Use-After-Free in MSL decoder.
GHSA-5r4x-w6p5-222q
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 18, 2026
A crafted MSL image can trigger a heap-use-after-free.
CVE-2026-46523
GitHub-GHSA

MEDIUM
NocoDB: Reflected Cross-Site Scripting via Page Leaving Redirect URL
GHSA-9qgr-6vpg-9gh9
pkg: nocodb
eco: npm
published: May 21, 2026
### Summary
A reflected XSS vulnerability exists in the Page Leaving Warning page. The `ncRedirectUrl` and `ncBackUrl` query parameters are used in `window.location.href` and `<a>` tag bindings without validation, allowing `javascript:` URI injection.

### Details
`PageLeavingWarning.vue` reads `ncR…

CVE-2026-46547
GitHub-GHSA

MEDIUM
Apify Model Context Protocol (MCP) server: Domain Allowlist Bypass in fetch-apify-docs via String Prefix Matching
GHSA-jwp7-wg77-3w9v
pkg: @apify/actors-mcp-server
eco: npm
published: May 19, 2026
### Summary
The `fetch-apify-docs` tool validates URLs against a domain allowlist using `String.startsWith()` instead of proper URL hostname comparison. This allows bypass via attacker-controlled subdomains (e.g., `https://docs.apify.com.evil.com/`), enabling the tool to fetch and return arbitrary w…
CVE-2026-46341
GitHub-GHSA

MEDIUM
Docker: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swap
GHSA-vp62-88p7-qqf5
pkg: github.com/docker/docker, github.com/moby/moby/v2, github.com/moby/moby
eco: go
published: May 18, 2026
## Summary

A race condition during `docker cp` mount setup allows a malicious container to create empty files or directories at arbitrary absolute paths on the host filesystem.

This advisory covers the race during mountpoint creation. The related race during the subsequent mount syscall is tracked…

CVE-2026-41568
GitHub-GHSA

MEDIUM
nimiq-primitives: BlockInclusionProof interlink issue when hops are empty
GHSA-799f-29jm-gr6c
pkg: nimiq-primitives
eco: rust
published: May 21, 2026
### Impact
A logic flaw in `BlockInclusionProof::is_block_proven` causes the function to return true without performing any cryptographic verification when `get_interlink_hops` yields an empty hop list. This occurs when the target block is at the election block position immediately preceding the ele…
CVE-2026-46539
GitHub-GHSA

MEDIUM
Mailpit: Concurrent map read & write in proxy CSS rewriter – remote unauth crash (fatal error: concurrent map read and map write)
GHSA-w4vj-r5pg-3722
pkg: github.com/axllent/mailpit
eco: go
published: May 19, 2026
### Summary
The screenshot/print proxy (/proxy?data=…) maintains a package-level assets map[string]MessageAssets cache, but reads the map without holding assetsMutex while a long-running cleanup goroutine and (re-entrant) CSS-rewriting code path concurrently write to it under the lock. When the un…
CVE-2026-45712
GitHub-GHSA

MEDIUM
Mailpit: Path traversal & arbitrary file write in mailpit dump –http via attacker-controlled message IDs
GHSA-qx5x-85p8-vg4j
pkg: github.com/axllent/mailpit
eco: go
published: May 19, 2026
### Summary
The mailpit dump –http <base-url> <out-dir> sub-command downloads every message from a remote Mailpit instance and writes each one as <id>.eml inside the user-supplied output directory. The message ID field is taken verbatim from the JSON response of the remote server and concatenated i…
CVE-2026-45711
GitHub-GHSA

MEDIUM
OpenTelemetry eBPF Instrumentation: CPU-mismatch fallback uses 256-byte buffer with 8KB size
GHSA-r6c9-g6q5-qrf9
pkg: go.opentelemetry.io/obi
eco: go
published: May 18, 2026
### Summary

The per-CPU message-buffer fallback path uses a 256-byte backup buffer but preserves the original payload size, which can be up to 8KB. If a CPU mismatch occurs, OBI can read beyond the fallback buffer and leak adjacent memory into telemetry.

### Details

https://github.com/open-teleme…

CVE-2026-45681
GitHub-GHSA

MEDIUM
OpenTelemetry eBPF Instrumentation: Unbounded BPF internal metrics replay can exhaust CPU
GHSA-89c6-vpcj-7vj4
pkg: go.opentelemetry.io/obi
eco: go
published: May 18, 2026
### Summary

OBI replays BPF probe hits into histogram observations by looping once per recorded run count. On busy systems, the run-count delta can become very large, causing the metrics exporter to spend excessive CPU time in a tight loop every collection interval.

### Details

The vulnerable loo…

CVE-2026-45680
GitHub-GHSA

MEDIUM
NocoDB: Shared-base link access can invite arbitrary users as persistent base members
GHSA-chqv-vrj7-qffp
pkg: nocodb
eco: npm
published: May 21, 2026
### Summary

Shared-base sessions were granted the same base-member capabilities as authenticated viewers. Using only the shared-base UUID (`xc-shared-base-id`), an attacker could enumerate base members and invite an arbitrary email into the base as a real member. The invited user could then redeem …

CVE-2026-46552
GitHub-GHSA

MEDIUM
Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer
GHSA-j3fj-qppj-fmmc
pkg: github.com/axllent/mailpit
eco: go
published: May 19, 2026
## Summary

The fix for GHSA-6jxm-fv7w-rw5j (CVE-2026-23845, "Server-Side Request Forgery (SSRF) via HTML Check API"), shipped in mailpit `v1.28.3`, hardened `internal/htmlcheck/css.go::downloadCSSToBytes` with a 5MB size cap, a `text/css` content-type check, login-info stripping in `isValidURL`, an…

CVE-2026-45709
GitHub-GHSA

MEDIUM
ImageMagick: Heap Buffer Over-Read in distributed pixel cache server
GHSA-6gxq-f64p-5w6f
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 22, 2026
An attacker who can connect to a magick -distribute-cache service can cause a heap buffer over-read in the server process.
CVE-2026-47166
GitHub-GHSA

MEDIUM
ImageMagick: Out-of-Bounds Read in connected components when the user supplies an invalid keep-top define
GHSA-vhrh-72hq-w8m7
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 18, 2026
An invalid `connected-components:keep-top` value could result in a heap buffer over-read when performing the connected components operation.
CVE-2026-45359
GitHub-GHSA

MEDIUM
fabric-chaincode-java: TLS Private Key Password Disclosed in INFO Startup Logs in Chaincode-as-a-Service Mode
GHSA-wg5x-3g47-v38r
pkg: org.hyperledger.fabric-chaincode-java:fabric-chaincode-shim
eco: maven
published: May 19, 2026
When chaincode is deployed in chaincode-as-a-service mode with TLS enabled, the chaincode server INFO level logging includes the TLS private key password in plaintext. An attacker with access to the chaincode server logs could recover the TLS private key password. If the attacker can also obtain the…
CVE-2026-45581
GitHub-GHSA

MEDIUM
ImageMagick: Heap Buffer Over-Write in MIFF encoder when using LZMA compression
GHSA-jcqp-6r6f-3mfx
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 18, 2026
When using LZMA compression in the MIFF encoder an out of bounds write can occur due to a missing check.
CVE-2026-46521
GitHub-GHSA

MEDIUM
OpenTelemetry eBPF Instrumentation: Unsafe fastelf parsing allows malformed ELF to crash agent
GHSA-wp73-mwgf-4jq9
pkg: go.opentelemetry.io/obi
eco: go
published: May 18, 2026
### Summary

OBI's replacement ELF parser trusts section offsets, counts, and string offsets from the executable file. A crafted local ELF can make OBI dereference invalid section pointers or slice past string tables, causing the agent to panic while determining the process language.

### Details

`…

CVE-2026-45676
GitHub-GHSA

MEDIUM
Nezha Monitoring: RoleMember can fire other users' cron tasks via AlertRule.FailTriggerTasks (no ownership check)
GHSA-rxf6-wjh4-jfj6
pkg: github.com/nezhahq/nezha
eco: go
published: May 23, 2026
## Summary

`createAlertRule` and `createService` (and their `update*` siblings) accept `FailTriggerTasks []uint64` and `RecoverTriggerTasks []uint64` — IDs of cron tasks to fire when the alert/service trips. The validation function only validates the alert's `Rules.Ignore` server map; it never ch…

CVE-2026-47120
GitHub-GHSA

MEDIUM
NocoDB: Refresh Token Cookie Set Without `secure` and `sameSite` Flags
GHSA-f74w-272x-mqcv
pkg: nocodb
eco: npm
published: May 21, 2026
### Summary

The refresh-token cookie was set with `httpOnly: true` but missing both the `secure` flag and the `sameSite` attribute. Over plain HTTP the cookie could be intercepted on the network; without `sameSite`, browsers attached it to cross-site POSTs, enabling CSRF against the token-refresh e…

CVE-2026-46550
GitHub-GHSA

MEDIUM
Umbraco.Cms: Open Redirect Vulnerability in Surface Controllers
GHSA-2qjj-h6wp-c7h7
pkg: Umbraco.Cms, Umbraco.Cms
eco: nuget
published: May 21, 2026
### Impact
Some of the Surface Controllers in the CMS provide to support member related operations fail to validate redirect URLs, making Razor templates that derive 'RedirectUrl' from user-controlled query parameters vulnerable to malicious redirect attacks.

### Patches
The issue is resolved in ve…

CVE-2026-46616
GitHub-GHSA

MEDIUM
Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalization
GHSA-x5w9-xh9r-mvfc
pkg: github.com/caddyserver/caddy/v2
eco: go
published: May 19, 2026
This report is not about a normal textual prefix-expansion case.

The issue here is that the authorization layer and the `/config` traversal layer do **not agree on what object the path refers to**.

In this case, a path authorized for one config object is accepted, but then resolves to a **diffe…

CVE-2026-45692
GitHub-GHSA

MEDIUM
go-git: Crafted repositories may modify main and submodule .git directories
GHSA-crhj-59gh-8×96
pkg: github.com/go-git/go-git/v5, github.com/go-git/go-git/v6, github.com/go-git/go-git
eco: go
published: May 19, 2026
### Impact
A path validation issue in `go-git` could allow crafted repository data to affect files outside the intended checkout target, including the repository's `.git` directory.

These validations were introduced in upstream Git years ago, so the vulnerability arose from go-git drifting from tho…

CVE-2026-45571
GitHub-GHSA

MEDIUM
Budibase: Row Action Trigger Bypasses View Row Filter Security Boundary Allowing Action on Out-of-Scope Rows
GHSA-3263-v5v9-xq8q
pkg: budibase
eco: npm
published: May 18, 2026
## Summary

The row action trigger endpoint (`POST /api/tables/:sourceId/actions/:actionId/trigger`) fails to validate that the user-supplied `rowId` is within the scope of the view's row filters. A user with access to a filtered view can trigger row actions on any row in the underlying table, inclu…

CVE-2026-45718
GitHub-GHSA

MEDIUM
qs has a remotely triggerable DoS: qs.stringify crashes with TypeError on null/undefined entries in comma-format arrays when encodeValuesOnly is set
GHSA-q8mj-m7cp-5q26
pkg: qs
eco: npm
published: May 22, 2026
### Summary

`qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is synchronous and not handled by any of qs's null-related options (`skipNulls`, `strictNullHandling`).

### Details

In the com…

CVE-2026-8723
GitHub-GHSA

MEDIUM
nimiq-blockchain: Genesis batch set request
GHSA-vghx-352f-93jm
pkg: nimiq-blockchain
eco: rust
published: May 21, 2026
### Impact
A remote peer can crash any full node by sending a RequestBatchSet message containing the genesis block's hash. The handler calls `get_epoch_chunks` which iterates backwards through macro blocks using `Policy::macro_block_before`. When it reaches the genesis block number, `macro_block_bef…
CVE-2026-46543
GitHub-GHSA

MEDIUM
protobufjs: Denial of Service via unbounded recursive JSON descriptor expansion
GHSA-jggg-4jg4-v7c6
pkg: protobufjs, protobufjs
eco: npm
published: May 19, 2026
## Summary

protobufjs could recurse without a depth limit while expanding nested JSON descriptors through `Root.fromJSON()` and `Namespace.addJSON()`.

A crafted JSON descriptor with deeply nested namespace definitions could cause the JavaScript call stack to be exhausted during descriptor loading.…

CVE-2026-45740
GitHub-GHSA

MEDIUM
Algernon: Auto-refresh SSE event server binds to all interfaces with Access-Control-Allow-Origin: * and no authentication
GHSA-9v4j-7g44-qcqw
pkg: github.com/xyproto/algernon
eco: go
published: May 19, 2026
### Summary

When auto-refresh is enabled, Algernon spins up an SSE handler that streams a `data:` line for every filesystem event under the watched directory. The handler performs **no authentication** of any kind — no shared token, no cookie check against the `permissions2` userstate, no IP allo…

GitHub-GHSA

MEDIUM
ImageMagick: Policy Bypass in MNG coder could
GHSA-g5mf-wqq5-vwg6
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 18, 2026
Because of a missing check in the MNG coder it would be possible to read more images than the list limit policy would allow resulting in excessive resource use.
CVE-2026-45664
GitHub-GHSA

MEDIUM
NiceGUI: Unauthenticated log-volume denial of service in dynamic resource routes
GHSA-pq7c-x8g4-rvp6
pkg: nicegui
eco: pip
published: May 18, 2026
### Summary

Two FastAPI routes that serve per-component static assets in NiceGUI accept a sub-path parameter that may resolve to a directory rather than a file. Requests that resolve to a directory raise an unhandled `RuntimeError` inside Starlette's `FileResponse`, which Uvicorn writes to the serv…

CVE-2026-45554
GitHub-GHSA

MEDIUM
ImageMagick: Policy Bypass in PSD decoder
GHSA-cwpj-h54c-xjpx
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 18, 2026
Due to a missing check in the PSD decoder it would be possible to bypass the `list-length` resource policy when decoding a PSD image. Other security limits would still apply.
CVE-2026-45031
GitHub-GHSA

MEDIUM
ImageMagick: Out-of-Bounds Read of a single byte in meta encoder
GHSA-cr6r-hmj8-pr7r
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 18, 2026
An of by one in the meta encoder could result in an out of bounds read of a single byte in the meta encoder.
CVE-2026-45358
GitHub-GHSA

MEDIUM
webpack-dev-server vulnerable to cross-origin source code exposure on non-HTTPS origins
GHSA-79cf-xcqc-c78w
pkg: webpack-dev-server
eco: npm
published: May 18, 2026
### Impact

When webpack-dev-server is running on a non-HTTPS origin (the default), cross-origin requests from malicious websites can load the dev server's JavaScript bundles via `<script>` tags. The fix introduced in v5.2.1 (CVE-2025-30359) relied on `Sec-Fetch-Mode` and `Sec-Fetch-Site` request he…

CVE-2026-6402
GitHub-GHSA

MEDIUM
ImageMagick: Heap Buffer Over-Read of a 4 bytes in distort operation.
GHSA-pfvh-m9xv-8966
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 18, 2026
When performing a polynomial distortion an out of bounds over-read of 24 bytes can occur when specifying specific arguments.
CVE-2026-45624
GitHub-GHSA

MEDIUM
OpenTelemetry eBPF Instrumentation: CappedConcurrentHashMap leaks keys after removals
GHSA-962q-hwm5-52×5
pkg: go.opentelemetry.io/obi
eco: go
published: May 18, 2026
### Summary

The custom `CappedConcurrentHashMap` introduced for Java TLS state tracking never removes keys from its insertion-order queue when entries are deleted. In long-running instrumented JVMs, repeated connection churn can therefore grow the queue without bound and exhaust heap memory.

### D…

CVE-2026-45682
GitHub-GHSA

MEDIUM
ImageMagick: Heap Buffer Over-Read in IPTC encoder
GHSA-7wff-wpr6-vmhm
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 18, 2026
When writing an IPTC output file a malicious input file could cause an out of bounds read of a single byte.
CVE-2026-42326
GitHub-GHSA

MEDIUM
pyload-ng: SSRF via HTTP Redirect Bypass in parse_urls API
GHSA-8rp3-xc6w-5qp5
pkg: pyload-ng
eco: pip
published: May 21, 2026
## Summary

The SSRF mitigation added in commit `33c55da` for GHSA-7gvf-3w72-p2pg is incomplete. The `PREREQFUNCTION`-based private IP check was correctly applied to `HTTPChunk` (download path) but not to `HTTPRequest` (used by the `parse_urls` API). An authenticated attacker can supply a URL pointi…

CVE-2026-46561
GitHub-GHSA

MEDIUM
OpenTelemetry eBPF Instrumentation: Log enricher writev path can overread and overwrite user buffers
GHSA-vvmg-8mjr-g6q3
pkg: go.opentelemetry.io/obi
eco: go
published: May 18, 2026
### Summary

OBI's log enricher mishandles `writev` buffers by reading only the first `iovec` entry but using the total `iov_iter.count` as the copy length. When log injection is enabled, a crafted multi-segment `writev` call can make OBI read and overwrite memory beyond the first segment.

### Deta…

CVE-2026-45684
GitHub-GHSA

MEDIUM
Umbraco.Cms: XSS/HTML Injection in Umbraco Backoffice confirmation dialog
GHSA-vr9v-27gg-qgx4
pkg: Umbraco.Cms
eco: nuget
published: May 21, 2026
### Impact
Authenticated users are able to inject HTML vulnerability into an input field, which is rendered in the confirmation dialog without proper output encoding.

### Patches
This issue has been patched in 17.4.0

CVE-2026-46609
GitHub-GHSA

MEDIUM
Rust OneNote File Parser: Path traversal in `Parser::parse_notebook` allows reading files outside the notebook directory
GHSA-4j5m-wc25-pvh7
pkg: onenote_parser
eco: rust
published: May 21, 2026
### Impact
A maliciously crafted `.onetoc2` table-of-contents file can cause `Parser::parse_notebook` to open arbitrary files on the host filesystem outside the notebook's directory. The parser reads entry names listed inside the `.onetoc2` and joins them against the notebook's base directory withou…
CVE-2026-46671
GitHub-GHSA

MEDIUM
ws: Uninitialized memory disclosure
GHSA-58qx-3vcg-4xpx
pkg: ws
eco: npm
published: May 18, 2026
### Impact

The `websocket.close()` implementation is vulnerable to uninitialized memory disclosure when a `TypedArray` is passed as the reason argument.

### Proof of concept

“`js
import { deepStrictEqual } from 'node:assert';
import { WebSocket, WebSocketServer } from 'ws';

const wss = new WebS…

CVE-2026-45736
GitHub-GHSA

MEDIUM
SQLAdmin: Authorization Bypass on `ajax_lookup`
GHSA-54mc-gghv-4cfj
pkg: sqladmin
eco: pip
published: May 21, 2026
### Impact

The `ajax_lookup` endpoint in `application.py` bypasses the `is_accessible()` access control check that all other endpoints enforce.

If a developer restricts model access by overriding `is_accessible()`, an authenticated user can still query that model's data through the `ajax_lookup` e…

CVE-2026-46645
GitHub-GHSA

MEDIUM
NocoDB: SSRF Protection Bypass in Notification Webhook Plugins (Slack, Discord, Mattermost, Teams)
GHSA-2c5x-4jgf-88mj
pkg: nocodb
eco: npm
published: May 21, 2026
### Summary

The `request-filtering-agent` SSRF protection was non-functional in the four notification webhook plugins (Slack, Discord, Mattermost, Teams) because `httpAgent` / `httpsAgent` were passed as part of the request **body** rather than the axios **config**. An authenticated user with hook-…

CVE-2026-46548
GitHub-GHSA

MEDIUM
nimiq-keys: Denial of service in Ed25519 multisig delinearization via invalid curve points
GHSA-h9cc-w26m-j342
pkg: nimiq-keys
eco: rust
published: May 21, 2026
### Impact

A denial-of-service vulnerability exists in the Ed25519 multisig delinearization code path. `Ed25519PublicKey::delinearize()` in `keys/src/multisig/mod.rs` called `.unwrap()` on curve point decompression, which panics when a public key is
constructed from 32 bytes that do not represent a…

CVE-2026-46542
GitHub-GHSA

MEDIUM
Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: *
GHSA-hw27-4v2q-5qff
pkg: github.com/xyproto/algernon
eco: go
published: May 20, 2026
### Summary

The SSE event server's `Access-Control-Allow-Origin` response header was hardcoded to the wildcard `*` regardless of the caller's `Origin`. Because `EventSource` does not preflight and does not send cookies, the wildcard is sufficient to let any third-party page the developer visits ope…

CVE-2026-46431
GitHub-GHSA

MEDIUM
Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS
GHSA-gj84-924c-48fx
pkg: github.com/xyproto/algernon
eco: go
published: May 20, 2026
### Summary

The SSE event server bound to `0.0.0.0:5553` on Linux/macOS by default because the platform-dependent host default in `engine/flags.go:39-46` set `host = ""` for non-Windows, and `utils.JoinHostPort("", ":5553")` resolves to `":5553"` — a Go `http.Server.Addr` of `":5553"` listens on …

CVE-2026-46430
GitHub-GHSA

MEDIUM
Regression in pymdownx.snippets reintroduces sibling-prefix path traversal bypass despite restrict_base_path
GHSA-62q4-447f-wv8h
pkg: pymdown-extensions
eco: pip
published: May 19, 2026
# Summary

`pymdownx.snippets` has a regression of the CVE-2023-32309 / GHSA-jh85-wwv9-24hv fix. With `restrict_base_path: True` (the default), the current `filename.startswith(base)` containment check does not enforce a directory boundary. As a result, a markdown snippet directive can read files fr…

CVE-2026-46338
GitHub-GHSA

MEDIUM
Caddy: Remote Admin Authorization Bypass on PKI Endpoints via Prefix-Based Path Matching
GHSA-gx7w-56w6-g48x
pkg: github.com/caddyserver/caddy/v2
eco: go
published: May 19, 2026
## AI Disclosure

I used an LLM to help review the source code, reason about attack surface, and help draft and refine this report.
I manually validated the finding by reproducing it locally, confirming the vulnerable code path, and verifying the HTTP behavior with `curl -v`.

## Summary

Ca…

GitHub-GHSA

MEDIUM
Budibase: Missing Cache Invalidation on Public API Role Unassignment Allows Revoked Users to Retain Privileges for Up to 1 Hour
GHSA-6vp2-6r7m-2jvx
pkg: @budibase/backend-core
eco: npm
published: May 19, 2026
## Summary

The public API role unassignment endpoint (`POST /api/public/v1/roles/unassign`) updates user documents in CouchDB but does not invalidate the corresponding Redis user cache entries. Because the authentication middleware resolves user identity and permissions from this cache (TTL: 3600 s…

CVE-2026-46424
GitHub-GHSA

MEDIUM
ImageMagick: Information Disclosure in distributed pixel cache server because it is not using a challenge–response authentication model
GHSA-2rgj-gx5x-f62w
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 22, 2026
The distributed pixel cache was originally designed to operate without a challenge–response authentication model. However, given today’s heightened security expectations, we have changed our implementation.
CVE-2026-47165
GitHub-GHSA

MEDIUM
ImageMagick: Race Condition in distributed pixel cache server can result in file descriptor hijacking
GHSA-4g75-9r48-jf92
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 22, 2026
An attacker who can connect to a magick -distribute-cache service can hijack a file descriptor in the server process when a race condition is met.
CVE-2026-46693
GitHub-GHSA

MEDIUM
ImageMagick: Heap Buffer Over-Write in distributed pixel cache server
GHSA-p93h-f2jc-477j
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 22, 2026
An attacker who can connect to a `magick -distribute-cache` service can cause a heap buffer over-write in the server process.
CVE-2026-46692
GitHub-GHSA

MEDIUM
ImageMagick: Heap Buffer Over-Write of a single byte in the JP2 encoder.
GHSA-533m-3wf6-c33v
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 18, 2026
An incorrect check in the JP2 will result in an heap buffer over-write of a single byte when specifying certain options.
CVE-2026-46559
GitHub-GHSA

MEDIUM
Flask-Security-Too OAuth reauthentication freshness bypass via cross- user OAuth identity acceptance
GHSA-97r5-pg8x-p63p
pkg: Flask-Security-Too
eco: pip
published: May 22, 2026
### Summary

Flask-Security-Too 5.8.0's OAuth reauthentication flow can mark a
session as fresh after verifying an OAuth account that belongs to a
different user.

If an attacker can operate an already-authenticated but stale victim
session, they can complete OAuth verification using their…

CVE-2026-46715
GitHub-GHSA

MEDIUM
@hulumi/baseline: CloudTrail selector tampering events were not fully detected
GHSA-gfp8-mp24-5vxg
pkg: @hulumi/baseline
eco: npm
published: May 21, 2026
Impact: @hulumi/baseline versions before 1.3.2 could miss some CloudTrail event-selector tampering evidence, reducing coverage for changes to audit logging configuration.

Patched in 1.3.2: detection coverage and regression tests were expanded.

Remediation: upgrade @hulumi/baseline to 1.3.2 or late…

GitHub-GHSA

MEDIUM
Fission builder accepts arbitrary buildcmd strings from Environment.spec.builder.command, allowing the builder pod to invoke arbitrary executables
GHSA-7pjr-qpvh-m339
pkg: github.com/fission/fission
eco: go
published: May 21, 2026
### Summary

Before the round-1 security sweep, `pkg/builder/builder.go` passed `Environment.spec.builder.command` directly into `exec.Command(…)` after a `strings.Fields` split, with no validation of the executable path or its arguments. A user who could create or update `Environment` CRDs in a n…

CVE-2026-46618
GitHub-GHSA

MEDIUM
@sveltejs/kit: `query.batch` cross-talk
GHSA-hgv7-v322-mmgr
pkg: @sveltejs/kit
eco: npm
published: May 21, 2026
`query.batch()` could, under very rare and specific timings, cause concurrent requests from different users to merge and resolve under single request context, enabling cross-user data disclosure.
GitHub-GHSA

MEDIUM
Mobile Verification Toolkit (MVT): Path Traversal via unsanitized File identifiers in iOS Backup processing
GHSA-5h3g-px23-w6vw
pkg: mvt
eco: pip
published: May 21, 2026
### Summary

The `fileID` field from `Manifest.db` (a SQLite database inside iOS backups, generated by the device) is used directly in filesystem path construction without validation. This affects two commands through a shared code path:

– **`mvt-ios decrypt-backup`** (`decrypt.py`): `file_id` is u…

CVE-2026-46486
GitHub-GHSA

MEDIUM
Flowise: Cross-Workspace Chatflow Disclosure via chatflows/apikey Endpoint Returns All Unprotected Chatflows
GHSA-c2c9-mfw7-p8hw
pkg: flowise
eco: npm
published: May 20, 2026
## Summary

The `/api/v1/chatflows/apikey/:apikey` endpoint (whitelisted, accessible with API key auth only) returns all chatflows bound to the provided API key AND all chatflows across the entire system that have no API key assigned. This crosses workspace boundaries, allowing a user in Workspace A…

GitHub-GHSA

MEDIUM
Flowise: Mass Assignment in PUT /api/v1/user Allows Authenticated Users to Override Password Hash and Bypass Password Change Verification
GHSA-59fh-9f3p-7m39
pkg: flowise
eco: npm
published: May 20, 2026
### Summary
A Mass Assignment vulnerability in the PUT /api/v1/user endpoint allows authenticated users to directly modify restricted user fields, including the credential (password hash), bypassing the intended password change workflow.

Because the endpoint forwards the entire request body to the …

GitHub-GHSA

MEDIUM
Flowise: Hardcoded CORS wildcard on TTS endpoint enables cross-origin credential abuse from any webpage
GHSA-m837-xvxr-vqwg
pkg: flowise
eco: npm
published: May 20, 2026
### Summary

The TTS generation endpoint sets `Access-Control-Allow-Origin: *` as a hardcoded response header, independent of the server's CORS configuration. This enables any webpage to make cross-origin requests to generate speech using stored credentials.

### Root Cause

“`typescript
// package…

GitHub-GHSA

MEDIUM
RTK improperly trusts project-local filter configuration, allowing silent tampering of command output shown to LLM
GHSA-fvvm-949w-qj4w
pkg: rtk
eco: rust
published: May 20, 2026
RTK (Rust Token Killer) improperly trusts project-local configuration files. In versions prior to 0.32.0, RTK automatically loads `.rtk/filters.toml` from the working directory with highest priority and without user notification. An attacker can place a malicious filter file in a repository to apply…
CVE-2026-45792
GitHub-GHSA

MEDIUM
rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
GHSA-phqj-4mhp-q6mq
pkg: openssl
eco: rust
published: May 19, 2026
`CipherCtxRef::cipher_update_inplace` incorrectly sized output buffers when used with AES key-wrap-with-padding ciphers (EVP_aes_{128,192,256}_wrap_pad). For a non-multiple-of-8 input, OpenSSL writes up to 7 bytes past the end of the caller's buffer or Vec, producing attacker-controllable heap corru…
CVE-2026-45784
GitHub-GHSA

MEDIUM
Trubo: Login callback CSRF/session fixation
GHSA-hcf7-66rw-9f5r
pkg: turbo
eco: npm
published: May 19, 2026
### Impact

Turborepo's self-hosted login and SSO browser flows did not validate a CSRF state value on the localhost callback. While the CLI was waiting for authentication, a malicious web page could send a request to the local callback server with an attacker-controlled token. If accepted before th…

CVE-2026-45773
GitHub-GHSA

MEDIUM
Diesel: Command injection in Diesel's implementation of `COPY FROM`/`COPY TO`
GHSA-m9p2-fxp5-v3fp
pkg: diesel
eco: rust
published: May 19, 2026
Diesel allows users to configure various options for PostgreSQL's `COPY FROM` and `COPY TO` statements. These configurations are partially provided as strings or characters.

Diesel did not check if any these user-provided options contain a quote character `'`, which can lead to the injection of ad…

GitHub-GHSA

MEDIUM
Diesel: Possible unaligned data access for implementations of `SqliteAggregate`
GHSA-q8x8-jrhj-fh9p
pkg: diesel
eco: rust
published: May 19, 2026
Diesel allows to register custom aggregate SQL functions for SQLite via the `SqliteAggregate` interface.

To store an instance of the custom aggregate processor Diesel relied on the `sqlite3_aggregate_context` function provided by sqlite. This function doesn't provide any guarantees about alignment …

GitHub-GHSA

MEDIUM
Caddy CVE-2026-30852 Fix Bypass
GHSA-wwhq-w58m-w29c
pkg: github.com/caddyserver/caddy/v2
eco: go
published: May 19, 2026
#

## TL;DR

CVE-2026-30852 fixed double expansion in `vars_regexp` when the variable key is a placeholder (e.g. `{http.vars.x}`). The fix does NOT protect literal key names (e.g. `tenant_id`). An attacker injects `{env.AWS_SECRET_ACCESS_KEY}` or `{file./etc/passwd}` via a request header → Caddy …

GitHub-GHSA

MEDIUM
Kong Ingress Controller for Kubernetes (KIC): Cross-namespace TLS Secret Exfiltration in Gateways with GatewayClass missing `konghq.com/gatewayclass-unmanaged: 'true'` annotation
GHSA-m23h-6mwm-39m8
pkg: github.com/kong/kubernetes-ingress-controller/v3, github.com/kong/kubernetes-ingress-controller/v3, github.com/kong/kubernetes-ingress-controller/v2
eco: go
published: May 19, 2026
## Summary

A vulnerability in the Kong Ingress Controller (KIC) allows for the unauthorized exfiltration of TLS certificates and private keys across Kubernetes namespace boundaries. In "managed" mode (where the `GatewayClass` lacks an unmanaged annotation), the Gateway TLS translator skips critical…

GitHub-GHSA

MEDIUM
Kong Ingress Controller for Kubernetes (KIC): Secret-backed plugin configurations leak through non-sensitive diagnostics endpoint
GHSA-3278-c88v-xrh4
pkg: github.com/kong/kubernetes-ingress-controller/v3, github.com/kong/kubernetes-ingress-controller/v2, github.com/kong/kubernetes-ingress-controller
eco: go
published: May 19, 2026
## Summary

A vulnerability in the Kong Ingress Controller (KIC) allows for the unauthorized exposure of sensitive plugin credentials through the diagnostics interface. Even when configured to redact sensitive information (using `–dump-sensitive-config=false`), KIC fails to sanitize the `Plugins` f…

GitHub-GHSA

MEDIUM
Envoy AI Proxy – MCP Message Smuggling Vulnerability
GHSA-4gph-2hhr-5mwg
pkg: github.com/envoyproxy/ai-gateway
eco: go
published: May 19, 2026
Envoy AI Gateway was found to be affected by a protocol parser differential vulnerability due to improper implementation of the JSON-RPC 2.0 specification. Such differential causes a MCP message alteration, potentially causing a bypass of security controls in a multi-layered architecture.

According…

GitHub-GHSA

MEDIUM
Nuxt: Dev server exposes built source over LAN to malicious sites (incomplete fix for GHSA-4gf7-ff8x-hq99)
GHSA-6m52-m754-pw2g
pkg: @nuxt/rspack-builder, @nuxt/rspack-builder, @nuxt/webpack-builder
eco: npm
published: May 19, 2026
### Summary
This is an incomplete fix for [GHSA-4gf7-ff8x-hq99](https://github.com/nuxt/nuxt/security/advisories/GHSA-4gf7-ff8x-hq99). Source code may be stolen during dev when using the webpack / rspack builder if the dev server is bound to a non-loopback address (e.g. `nuxt dev –host`) and the de…
CVE-2026-45670
GitHub-GHSA

MEDIUM
Nuxt: Reflected XSS in `navigateTo()` external redirect
GHSA-fx6j-w5w5-h468
pkg: nuxt, nuxt
eco: npm
published: May 19, 2026
### Summary
`navigateTo()` with `external: true` generates a server-side HTML redirect body containing a `<meta http-equiv="refresh">` tag. The destination URL is only sanitized by replacing `"` with `%22`, leaving `<`, `>`, `&`, and `'` unencoded. An attacker who can influence the URL passed to `na…
CVE-2026-45669
GitHub-GHSA

MEDIUM
HAX CMS: Stored XSS via '<video-player>' component allows arbitrary JavaScript execution and token theft
GHSA-2m6p-hm3w-6jm3
pkg: @haxtheweb/haxcms-nodejs, @haxtheweb/video-player
eco: npm
published: May 19, 2026
### Summary
A stored cross-site scripting (XSS) vulnerability exists in HAX CMS due to improper sanitization of the `<video-player>` component.

The component allows `javascript:` URIs in the `source` attribute, which are executed when the page is viewed. This enables attackers to execute arbitrary …

CVE-2026-46496
GitHub-GHSA

MEDIUM
Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix
GHSA-65pc-fj4g-8rjx
pkg: idna
eco: pip
published: May 19, 2026
This is the same issue as CVE-2024-3651, however the original remediation in 2024 was not a complete fix. Payloads such as `"\u0660" * N` or `"\u30fb" * N + "\u6f22"` utilize the `valid_contexto` function prior to length rejection, and for high values of `N` will take a long time to process.

### Im…

CVE-2026-45409
GitHub-GHSA

MEDIUM
Microsoft DirectX12: .spritefont multiply overflow only in 32-bit builds
GHSA-5r97-79vw-qvm4
pkg: directxtk12_desktop_win10, directxtk12_uwp
eco: nuget
published: May 18, 2026
### Impact
The spritefont reader can be induced to perform a 32-bit overflow multiply that could in theory result in a RCE.

This impacts the use of the *DirectX Tool Kit* **SpriteFont** class file loading ctor if given untrusted data files.

> Note this only applies to x86/ARM builds of the library…

GitHub-GHSA

MEDIUM
Microsoft DirectX: .spritefont multiply overflow only in 32-bit builds
GHSA-c55g-rp4x-fx84
pkg: directxtk_desktop_win10, directxtk_uwp
eco: nuget
published: May 18, 2026
### Impact
The spritefont reader can be induced to perform a 32-bit overflow multiply that could in theory result in a RCE.

This impacts the use of the *DirectX Tool Kit* **SpriteFont** class file loading ctor if given untrusted data files.

> Note this only applies to x86/ARM builds of the library…

GitHub-GHSA

MEDIUM
Neotoma: Unauthenticated Inspector/API access via reverse-proxy loopback auth bypass
GHSA-5cvp-p7p4-mcx9
pkg: neotoma
eco: npm
published: May 18, 2026
Neotoma versions starting at v0.6.0 can treat public reverse-proxied requests as local when the app receives them over a loopback socket and no Bearer token is present.

In affected deployments, the REST auth middleware can resolve unauthenticated requests as the local development user, making the h…

CVE-2026-45577


Vulnerability Digest — May 18, 2026 · 77 Critical · 2 Exploited






Vulnerability Digest — Monday, May 18, 2026


Security Report

Monday, May 18, 2026  ·  Last 7 days  ·  Min severity: MEDIUM
Total Findings
490
Critical
77
High
257
Actively Exploited
2
CISA-KEV2
NVD254
GitHub-GHSA234
Findings sorted by severity
CISA-KEV

CRITICAL
Microsoft Exchange Server Cross-Site Scripting Vulnerability
CVE-2026-42897
pkg: Microsoft Microsoft

published: May 15, 2026

Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
CVE-2026-20182
pkg: Cisco Catalyst SD-WAN

published: May 14, 2026

Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.
Required action: Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlined in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.
GitHub-GHSA

CRITICAL
utcp-cli Vulnerable to Command Injection via Unsanitized Argument Substitution in CLI Communication Protocol
GHSA-33p6-5jxp-p3x4
pkg: utcp-cli
eco: pip
published: May 14, 2026
## Summary

The `_substitute_utcp_args` method in `cli_communication_protocol.py` inserts user-controlled `tool_args` values directly into shell command strings without any sanitization or escaping. These commands are then executed via `/bin/bash -c` (Unix) or `powershell.exe -Command` (Windows), al…

CVE-2026-45369
NVD

CRITICAL
CVE-2026-44523
CVE-2026-44523
pkg: jwt

published: May 14, 2026

Note Mark is an open-source note-taking application. Prior to 0.19.4, no minimum length or entropy is enforced on the JWT_SECRET configuration value. The application accepts any base64-decodable secret regardless of size, including secrets as short as 1 byte. This vulnerability is fixed in 0.19.4.
CWE: CWE-326, CWE-345
NVD

CRITICAL
CVE-2026-44006
CVE-2026-44006
pkg: vm2_project vm2

published: May 13, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, It is possible to reach BaseHandler.getPrototypeOf, which can be used to get arbitrary prototypes. This vulnerability is fixed in 3.11.0.
CWE: CWE-94
NVD

CRITICAL
CVE-2026-44005
CVE-2026-44005
pkg: vm2_project vm2

published: May 13, 2026

vm2 is an open source vm/sandbox for Node.js. From 3.9.6 to 3.10.5, vm2's bridge exposes mutable proxies for real host-realm intrinsic prototypes and then forwards sandbox writes into the underlying host objects with otherReflectSet() and otherReflectDefineProperty(), which lets attacker-controlled …
CWE: CWE-94, CWE-1321
NVD

CRITICAL
CVE-2026-43997
CVE-2026-43997
pkg: vm2_project vm2

published: May 13, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, it is possible to obtain the host Object. There are various ways to use the host Object, to escape the sandbox, one example would be using HostObject.getOwnPropertySymbols to obtain Symbol(nodejs.util.inspect.custom). This vulnerability …
CWE: CWE-94
GitHub-GHSA

CRITICAL
Dalfox Server Mode Vulnerable to Unauthenticated Remote Code Execution via `found-action`
GHSA-v25v-m36w-jp4h
pkg: github.com/hahwul/dalfox/v2
eco: go
published: May 12, 2026
# GHSA: Unauthenticated Remote Code Execution via `found-action` in Dalfox Server Mode

## Summary

When dalfox is started in REST API server mode (`dalfox server`), the server binds to `0.0.0.0:6664` by default and requires no API key unless the operator explicitly passes `–api-key`. Because `mode…

CVE-2026-45087
NVD

CRITICAL
CVE-2026-42869
CVE-2026-42869
pkg: docker

published: May 11, 2026

SOCFortress CoPilot focuses on providing a single pane of glass for all your security operations needs. Prior to 0.1.57, SOCFortress CoPilot ships a hardcoded JWT signing secret as a fallback value in backend/app/auth/utils.py:28 and ships it verbatim in .env.example. Any deployment where JWT_SECRET…
CWE: CWE-287, CWE-522, CWE-798
GitHub-GHSA

CRITICAL
SandboxJS has a sandbox escape via Function.caller leakage of internal call op
GHSA-g8f2-4f4f-5jqw
pkg: @nyariv/sandboxjs
eco: npm
published: May 11, 2026
### Summary
Sandbox-defined functions expose `Function.caller`, allowing sandboxed code to recover the internal `LispType.Call` runtime callback. That callback can then be invoked with attacker-controlled fake context and obj values to extract blocked host statics, recover the real host Function con…
CVE-2026-43898
NVD

CRITICAL
CVE-2026-44643
CVE-2026-44643
pkg: peerigon angular-expressions

published: May 11, 2026

Angular Expressions provides expressions for the Angular.JS web framework as a standalone module. Prior to 1.5.2, an attacker can write a malicious expression using filters that escapes the sandbox to execute arbitrary code on the system. This vulnerability is fixed in 1.5.2.
CWE: CWE-95
NVD

CRITICAL
CVE-2026-43999
CVE-2026-43999
pkg: vm2_project vm2

published: May 13, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, NodeVM's builtin allowlist can be bypassed when the module builtin is allowed (including via the '*' wildcard). The module builtin exposes Node's Module._load(), which loads any module by name directly in the host context, completely byp…
CWE: CWE-863
NVD

CRITICAL
CVE-2026-43948
CVE-2026-43948
pkg: python

published: May 12, 2026

wger is a free, open-source workout and fitness manager. Prior to 2.6, the reset_user_password and gym_permissions_user_edit views in wger perform a gym-scope authorization check using Python object comparison (!=) that evaluates None != None as False, silently bypassing the guard when both the atta…
CWE: CWE-863
NVD

CRITICAL
CVE-2026-7813
CVE-2026-7813
pkg: ssl

published: May 11, 2026

Authorization vulnerability in pgAdmin 4 server mode affecting Server Groups, Servers, Shared Servers, Background Processes, and Debugger modules.

Multiple endpoints fetched user-owned objects without filtering by the requesting user's identity. An authenticated user could access another user's pri…

CWE: CWE-284
NVD

CRITICAL
CVE-2026-44717
CVE-2026-44717
pkg: express

published: May 15, 2026

MCP Calculate Server is a mathematical calculation service based on MCP protocol and SymPy library. Prior to 0.1.1, the use of eval() to evaluate mathematical expressions without proper input sanitization leads to remote code execution. This vulnerability is fixed in 0.1.1.
CWE: CWE-94
NVD

CRITICAL
CVE-2026-5229
CVE-2026-5229
pkg: oauth

published: May 15, 2026

The Form Notify plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.1.10. This is due to the plugin trusting user-controlled cookie data to determine which WordPress account to authenticate after a LINE OAuth login. When LINE doesn't provide an email address…
CWE: CWE-287
GitHub-GHSA

CRITICAL
vm2 Has a Sandbox Breakout Using Async Generator
GHSA-248r-7h7q-cr24
pkg: vm2
eco: npm
published: May 14, 2026
### Summary

VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system.

### Details

It is possible to catch a host exception using the `yield*` expression inside an async generator.…

CVE-2026-45411
GitHub-GHSA

CRITICAL
Marten has an injection vulnerability in its full-text search regConfig parameter
GHSA-vmw2-qwm8-x84c
pkg: Marten
eco: nuget
published: May 14, 2026
## Summary

Marten's full-text search APIs interpolated the user-supplied `regConfig` parameter directly into the generated SQL without parameterization or validation, making every code path that exposes `regConfig` to untrusted input a SQL injection sink.

## Affected APIs

– `IQuerySession.SearchA…

CVE-2026-45288
NVD

CRITICAL
CVE-2026-42589
CVE-2026-42589
pkg: express

published: May 14, 2026

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg's /forms/pdfengines/metadata/write HTTP endpoint accepts a JSON metadata object and passes its keys directly to ExifTool via the go-exiftool library. No validation is performed on key characters. A \n embedded in a…
CWE: CWE-78
NVD

CRITICAL
CVE-2026-45411
CVE-2026-45411
pkg: vm2_project vm2

published: May 13, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.3, it is possible to catch a host exception using the yield* expression inside an async generator. When the generator is closed using the return function, the value is awaited on and exceptions thrown in the then call will be caught by the …
CWE: CWE-668
NVD

CRITICAL
CVE-2026-44009
CVE-2026-44009
pkg: vm2_project vm2

published: May 13, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, This vulnerability is fixed in 3.11.2.
CWE: CWE-668
NVD

CRITICAL
CVE-2026-44008
CVE-2026-44008
pkg: vm2_project vm2

published: May 13, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, the new method neutralizeArraySpeciesBatch works with objects from the other side but can call into this side via getter on the array prototype exposing objects of the wrong side into the sandbox. This can be used to get host objects and…
CWE: CWE-668
GitHub-GHSA

CRITICAL
Goobi viewer – Core: Unauthenticated Solr Streaming Expression Proxy
GHSA-2rgp-f66f-4499
pkg: io.goobi.viewer:viewer-core
eco: maven
published: May 13, 2026
### Summary

The Goobi viewer REST endpoint `POST /api/v1/index/stream` accepted an arbitrary Solr streaming
expression from unauthenticated network clients and forwarded it to the backend Solr server without restriction.
An attacker could read the complete Solr index and, in default Solr deployment…

CVE-2026-45083
GitHub-GHSA

CRITICAL
SillyTavern has Authentication Bypass via SSO Header Injection
GHSA-gxx6-h3g6-vwjh
pkg: sillytavern
eco: npm
published: May 12, 2026
## Resolution

SillyTavern 1.18.0 now includes a configuration option to limit which IP addresses can authorize using SSO headers, limiting to just loopback addresses by default. A setting can be customized according to user's needs.

Documentation: https://docs.sillytavern.app/administration/sso/

CVE-2026-44649
NVD

CRITICAL
CVE-2026-45185
CVE-2026-45185
pkg: tls

published: May 12, 2026

Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CHUNKING transfer, followed by a final cleartext byte on the same TCP connection. This can lead to hea…
CWE: CWE-416
NVD

CRITICAL
CVE-2026-31239
CVE-2026-31239
pkg: python

published: May 12, 2026

The mamba language model framework thru 2.2.6 is vulnerable to insecure deserialization (CWE-502) when loading pre-trained models from HuggingFace Hub. The MambaLMHeadModel.from_pretrained() method uses torch.load() to load the pytorch_model.bin weight file without enabling the security-restrictive …
CWE: CWE-502
NVD

CRITICAL
CVE-2026-31238
CVE-2026-31238
pkg: python

published: May 12, 2026

The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) in its model serving component. When starting a model server with the ludwig serve command, the framework loads model weight files using torch.load() without enabling the security-restrictive weights_only=True param…
CWE: CWE-502
NVD

CRITICAL
CVE-2026-31237
CVE-2026-31237
pkg: python

published: May 12, 2026

The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) through its predict() method. When a user provides a dataset file path to the predict() method, the framework automatically determines the file format. If the file is a pickle (.pkl) file, it is loaded using pandas.…
CWE: CWE-502
NVD

CRITICAL
CVE-2026-31236
CVE-2026-31236
pkg: python

published: May 12, 2026

The llm CLI tool thru 0.27.1 contains a critical code injection vulnerability via its –functions command-line argument. This argument is intended to allow users to provide custom Python function definitions. However, the tool directly executes the provided code using the unsafe exec() function with…
CWE: CWE-94
NVD

CRITICAL
CVE-2026-31235
CVE-2026-31235
pkg: python

published: May 12, 2026

The imgaug library thru 0.4.0 contains an insecure deserialization vulnerability in its BackgroundAugmenter class within the multicore.py module. The class uses Python's pickle module to deserialize data received via a multiprocessing queue in the _augment_images_worker() method without any safety c…
CWE: CWE-502
NVD

CRITICAL
CVE-2026-31231
CVE-2026-31231
pkg: python

published: May 12, 2026

Cognee thru v0.4.0 contains a critical remote code execution vulnerability in its notebook cell execution API endpoint. The endpoint is designed to execute arbitrary Python code provided by the user, but it does so using the unsafe exec() function without any sandboxing, validation, or security cont…
CWE: CWE-94
NVD

CRITICAL
CVE-2026-31230
CVE-2026-31230
pkg: python

published: May 12, 2026

The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a command-line argument injection vulnerability in its Kubeflow component (robustness_evaluation_fgsm_pytorch.py). The script uses the unsafe eval() function to parse string values provided via the –clip_values and –input_shape command-…
CWE: CWE-88
NVD

CRITICAL
CVE-2026-31229
CVE-2026-31229
pkg: python

published: May 12, 2026

The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains an insecure deserialization vulnerability (CWE-502) in its Kubeflow component's model loading functionality. When loading model weights from a file (e.g., model.pt) during robustness evaluation, the code uses torch.load() without the secu…
CWE: CWE-502
NVD

CRITICAL
CVE-2026-31228
CVE-2026-31228
pkg: python

published: May 12, 2026

The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a remote code execution vulnerability in its Kubeflow component. The robustness evaluation function for PyTorch models uses the unsafe eval() function to dynamically evaluate user-supplied strings for the LossFn and Optimizer parameters w…
CWE: CWE-94
NVD

CRITICAL
CVE-2026-31220
CVE-2026-31220
pkg: python

published: May 12, 2026

PySyft (Syft Datasite/Server) versions 0.9.5 and earlier are vulnerable to remote code execution due to insufficient validation and sandboxing of user-submitted code. The system allows low-privileged users to submit Python functions (via @sy.syft_function()) for remote execution on the server. While…
CWE: CWE-94
NVD

CRITICAL
CVE-2026-31217
CVE-2026-31217
pkg: python

published: May 12, 2026

The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370811af6b11402f51d377f (2024-07-21) allows arbitrary code execution. When a user supplies a directory path via the –model command-line argument, the function reads a module.py file …
CWE: CWE-94
NVD

CRITICAL
CVE-2026-31214
CVE-2026-31214
pkg: python

published: May 12, 2026

The torch-checkpoint-shrink.py script in the ml-engineering project in commit 0099885db36a8f06556efe1faf552518852cb1e0 (2025-20-27) contains an insecure deserialization vulnerability (CWE-502). The script uses torch.load() to process PyTorch checkpoint files (.pt) without enabling the security-restr…
CWE: CWE-502
GitHub-GHSA

CRITICAL
WebdriverIO BrowserStack Service has a Command Injection issue
GHSA-5c46-x3qw-q7j7
pkg: @wdio/browserstack-service
eco: npm
published: May 11, 2026
### Summary
A command injection vulnerability exists in `@wdio/browserstack-service` that allows remote code execution (RCE) when processing git branch names in test orchestration. An attacker can exploit this by providing a malicious git repository with a branch name containing shell command inject…
CVE-2026-25244
GitHub-GHSA

CRITICAL
DeepSeek TUI: task_create Insecure Defaults Enable RCE via Prompt Injection in Project Files
GHSA-72w5-pf8h-xfp4
pkg: deepseek-tui
eco: rust
published: May 14, 2026
### Summary

The `task_create` tool spawns durable sub-agents that inherit two insecure defaults:

– `allow_shell` defaults to `true` (`config.rs:1499`: `self.allow_shell.unwrap_or(true)`)
– `auto_approve` defaults to `true` (`task_manager.rs:297`: `auto_approve: Some(true)`)

When a user approves a…

CVE-2026-45374
GitHub-GHSA

CRITICAL
DeepSeek TUI: run_tests Tool Enables RCE via Malicious Repository Without Approval
GHSA-wx44-2q6h-j6p8
pkg: deepseek-tui, deepseek-tui-cli, deepseek-tui
eco: npm
published: May 14, 2026
### Summary
The `run_tests` tool executes `cargo test` in the workspace with `ApprovalRequirement::Auto`, meaning it runs without any user approval prompt. The source code explicitly states this design choice:

“`rust
fn approval_requirement(&self) -> ApprovalRequirement {
// Tests are encoura…

CVE-2026-45311
NVD

CRITICAL
CVE-2026-8511
CVE-2026-8511
pkg: go

published: May 14, 2026

Use after free in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

CRITICAL
CVE-2026-44482
CVE-2026-44482
pkg: node

published: May 14, 2026

soundcloud-rpc is a SoundCloud Client with Discord Rich Presence, Dark Mode, Last.fm and AdBlock support. Prior to 0.1.8, a track title containing an HTML payload executed locally in the Electron app. This means attacker-controlled SoundCloud track metadata can lead to local command execution on the…
CWE: CWE-20, CWE-79, CWE-94, CWE-862
GitHub-GHSA

CRITICAL
Obot has an authorization bypass in /mcp-connect/{id} that allows any authenticated user to use any registered MCP server
GHSA-vw82-7fv8-r6gp
pkg: github.com/obot-platform/obot
eco: go
published: May 13, 2026
## Summary

If you have the MCP Server ID, you can connect to the MCP server even if you don't have permissions to the server.

The MCP gateway endpoint `/mcp-connect/{mcp_id}` does not enforce Access Control Rules (ACRs). Any authenticated Obot user who possesses an MCP Server ID can connect to tha…

GitHub-GHSA

CRITICAL
Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys
GHSA-g7cv-rxg3-hmpx
pkg: @tanstack/arktype-adapter, @tanstack/eslint-plugin-router, @tanstack/eslint-plugin-start
eco: npm
published: May 12, 2026
## Summary

On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 `@tanstack/*` packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for `TanStack/router`, but the publish wo…

CVE-2026-45321
GitHub-GHSA

CRITICAL
PraisonAI MCP `tools/call` path-traversal => RCE via Python `.pth` injection
GHSA-9mqq-jqxf-grvw
pkg: PraisonAI
eco: pip
published: May 11, 2026
## Summary

PraisonAI's MCP (Model Context Protocol) server (`praisonai mcp serve`) registers four file-handling tools by default — `praisonai.rules.create`, `praisonai.rules.show`, `praisonai.rules.delete`, and `praisonai.workflow.show`. Each accepts a path or filename string from MCP `tools/call…

CVE-2026-44336
NVD

CRITICAL
CVE-2026-42596
CVE-2026-42596
pkg: docker

published: May 14, 2026

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, the default deny-lists used by Gotenberg's downloadFrom feature and webhook feature are bypassable. Because the filter is regex-based and case-sensitive, an unauthenticated attacker can supply URLs such as http://[::ffff:127…
CWE: CWE-918
NVD

CRITICAL
CVE-2026-42882
CVE-2026-42882
pkg: go

published: May 11, 2026

oxyno-zeta/s3-proxy is an aws s3 proxy written in go. Prior to 5.0.0, s3-proxy contains an authentication bypass caused by inconsistent URL path interpretation between the authentication middleware and the bucket handler. The authentication middleware evaluates resource path patterns against the per…
CWE: CWE-22, CWE-863
GitHub-GHSA

CRITICAL
Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`
GHSA-rpr9-rxv7-x643
pkg: sanitize-html
eco: npm
published: May 14, 2026
### Summary
Under the default configuration, `sanitize-html` can turn attacker-controlled content inside a disallowed `xmp` element into live HTML or JavaScript. This is a sanitizer bypass in the default `disallowedTagsMode: 'discard'` path and can lead to stored XSS in applications that render sani…
CVE-2026-44990
NVD

CRITICAL
CVE-2026-43900
CVE-2026-43900
pkg: vue

published: May 11, 2026

DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to v1.0.4-beta.1, a Cross-Site Scripting (XSS) vulnerability exists due to a discrepancy between the backend validation layer and the frontend browser rendering engine. The SVGSanitizer (s…
CWE: CWE-79
NVD

CRITICAL
CVE-2026-41258
CVE-2026-41258
pkg: express

published: May 15, 2026

OpenMRS is an open source electronic medical record system platform. From 2.7.0 to before 2.7.9 and 2.8.6, the ConceptReferenceRangeUtility.evaluateCriteria() method in OpenMRS Core evaluates database-stored criteria strings as Apache Velocity templates without any sandbox configuration. The Velocit…
CWE: CWE-94
GitHub-GHSA

CRITICAL
@samanhappy/mcphub: SSE Endpoint Accepts Arbitrary Username from URL Path Without Authentication, Enabling User Impersonation
GHSA-wf8q-wvv8-p8jf
pkg: @samanhappy/mcphub
eco: npm
published: May 14, 2026
### Summary

A critical identity spoofing vulnerability in MCPHub allows any unauthenticated user to impersonate any other user — including administrators — on SSE (Server-Sent Events) and MCP transport endpoints. The server accepts a username from the URL path parameter and creates an internal …

NVD

CRITICAL
CVE-2026-42555
CVE-2026-42555
pkg: express

published: May 14, 2026

Valtimo is an open-source business process automation platform. com.ritense.valtimo:document from 12.0.0 to before 12.32.0, com.ritense.valtimo:case from 13.0.0 to before 13.23.0, and com.ritense.valtimo:contract from 13.4.0 to before 13.23.0 evaluate Spring Expression Language (SpEL) expressions fr…
CWE: CWE-94
NVD

CRITICAL
CVE-2026-44351
CVE-2026-44351
pkg: jwt

published: May 13, 2026

fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.2.4, a critical authentication-bypass vulnerability in fast-jwt's async key-resolver flow allows any unauthenticated attacker to forge arbitrary JWTs that are accepted as authentic. When the application's key resolver returns an …
CWE: CWE-287, CWE-326, CWE-1391
NVD

CRITICAL
CVE-2026-44007
CVE-2026-44007
pkg: vm2_project vm2

published: May 13, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.1, when a NodeVM is created with nesting: true, sandbox code can unconditionally require('vm2') regardless of the outer VM's require configuration — including require: false. With access to vm2, the sandbox constructs a new inner NodeVM w…
CWE: CWE-284
GitHub-GHSA

CRITICAL
SillyTavern has a Path Traversal issue
GHSA-886q-f44j-h6wh
pkg: sillytavern
eco: npm
published: May 12, 2026
## Summary

`POST /api/extensions/delete` endpoint accepts `extensionName: "."` which bypasses
`sanitize-filename` validation, causing the entire user extensions directory to be
recursively deleted. No authentication is required in the default configuration.

## Affected File

`src/endpoints/exten…

CVE-2026-44650
GitHub-GHSA

CRITICAL
sealed-env: TOTP secret embedded in unseal token payload (enterprise mode)
GHSA-x3r2-fj3r-g5mv
pkg: sealed-env, io.github.davidalmeidac:sealed-env-core
eco: npm
published: May 12, 2026
In sealed-env enterprise mode, versions 0.1.0-alpha.1 through 0.1.0-alpha.3 embedded the operator's literal TOTP secret in the JWS payload of every minted unseal token. JWS payload is base64-encoded JSON, NOT encrypted. Any party who could observe a minted token (CI build logs, container env dumps, …
CVE-2026-45091
NVD

CRITICAL
CVE-2026-45091
CVE-2026-45091
pkg: node

published: May 12, 2026

sealed-env is a cross-stack, zero-trust secret management library for Node.js and Java/Spring Boot. In sealed-env enterprise mode, versions 0.1.0-alpha.1 through 0.1.0-alpha.3 embedded the operator's literal TOTP secret in the JWS payload of every minted unseal token. JWS payload is base64-encoded J…
CWE: CWE-200, CWE-522
GitHub-GHSA

CRITICAL
Unity Catalog has a JWT Issuer Validation Bypass tht Allows Complete User Impersonation
GHSA-qqcj-rghw-829x
pkg: io.unitycatalog:unitycatalog-server
eco: maven
published: May 11, 2026
**Context:**
A critical authentication bypass vulnerability exists in the Unity Catalog token exchange endpoint (/api/1.0/unity-control/auth/tokens). The endpoint extracts the issuer (iss) claim from incoming JWTs and uses it to dynamically fetch the JWKS endpoint for signature validation without va…
CVE-2026-27478
NVD

CRITICAL
CVE-2026-42457
CVE-2026-42457
pkg: kubernetes

published: May 14, 2026

vCluster Platform provides a Kubernetes platform for managing virtual clusters, multi-tenancy, and cluster sharing. Prior to 4.4.3, 4.5.5, 4.6.2, 4.7.1, and 4.8.0, there is a Stored XSS attack vulnerability via the name field of a templateRef. This can lead to the execution of arbitrary external scr…
CWE: CWE-79
GitHub-GHSA

CRITICAL
SiYuan Bazaar marketplace renders unescaped package `name` and `version` metadata, allowing stored XSS and Electron code execution
GHSA-27qc-m5gf-jv5r
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: May 13, 2026
### Summary

SiYuan's Bazaar (community marketplace) renders the `name` and `version` fields of a package's `plugin.json` (and the equivalent `theme.json` / `template.json` / `widget.json` / `icon.json`) into the Settings → Marketplace UI without HTML escaping. The kernel-side helper `sanitizePack…

CVE-2026-45375
NVD

CRITICAL
CVE-2026-41901
CVE-2026-41901
pkg: express

published: May 12, 2026

Thymeleaf is a server-side Java template engine for web and standalone environments. Prior to 3.1.5.RELEASE, a security bypass vulnerability exists in the expression execution mechanisms of Thymeleaf. Although the library provides mechanisms to avoid the execution of potentially dangerous expression…
CWE: CWE-917, CWE-1336
GitHub-GHSA

CRITICAL
Amazon Redshift Vulnerable to Remote Code Execution via Unsafe Class Loading
GHSA-wmmv-vvg5-993q
pkg: com.amazon.redshift:redshift-jdbc42
eco: maven
published: May 14, 2026
### Summary
Amazon Redshift JDBC Driver is a Type 4 JDBC driver that provides database connectivity through the standard JDBC application program interfaces (APIs). An issue exists in versions prior to 2.2.2 where the driver could load arbitrary classes when processing certain connection URL paramet…
CVE-2026-8178
GitHub-GHSA

CRITICAL
Electerm Local code through electerm's single-instance socket
GHSA-7p5m-v798-f8vv
pkg: electerm
eco: npm
published: May 14, 2026
### Impact
_Local code execution without UI interaction: any same-user process can send a JSON payload to electerm's single-instance socket/pipe, causing the app to create tabs and potentially spawn attacker-controlled local processes. Affects electerm single-instance installs on the machine._

### …

CVE-2026-45353
GitHub-GHSA

CRITICAL
Electerm: Importing unsafe bookmark data could lead to unsafe operation when clicking local type bookmark
GHSA-jgg9-rw32-44pj
pkg: electerm
eco: npm
published: May 14, 2026
### Impact
_Persistent local-pty code execution via imported bookmarks or compromised sync targets. Affects users who import bookmark JSON files or who have electerm sync configured (gist/WebDAV). The attacker can inject `exec*` fields or global config to cause remote code to run when a bookmark is …
CVE-2026-45058
GitHub-GHSA

CRITICAL
Portainer has an endpoint security bypass via Swarm service create/update
GHSA-5fxq-qcf3-244w
pkg: github.com/portainer/portainer, github.com/portainer/portainer, github.com/portainer/portainer
eco: go
published: May 14, 2026
## Summary

Portainer enforces seven `EndpointSecuritySettings` restrictions that administrators configure to restrict the container configurations non-admin users can launch: **privileged mode**, **host PID namespace**, **device mapping**, **capabilities**, **sysctls**, **security-opt (Seccomp / Ap…

CVE-2026-44849
GitHub-GHSA

CRITICAL
Portainer missing authorization on Docker plugin endpoints, which allows host RCE
GHSA-rrmm-9v76-h3p4
pkg: github.com/portainer/portainer, github.com/portainer/portainer, github.com/portainer/portainer
eco: go
published: May 14, 2026
## Summary

Portainer enforces Role-Based Access Control (RBAC) on top of the Docker API. The proxy layer routes incoming Docker API requests to per-resource handlers (containers, images, services, volumes, etc.) that apply authorization checks.

The Docker plugin management endpoints (`/plugins/*`)…

CVE-2026-44848
GitHub-GHSA

CRITICAL
n8n Has an XML Node Prototype Pollution Patch Bypass
GHSA-wrwr-h859-xh2r
pkg: n8n, n8n, n8n
eco: npm
published: May 14, 2026
## Impact
An authenticated user with permission to create or modify workflows could bypass the patch for GHSA-hqr4-h3xv-9m3r in the XML node. When combined with other nodes, this could lead to RCE on the n8n host.

## Patches
The issue has been fixed in n8n versions 1.123.43, 2.20.7, and 2.22.1. Use…

CVE-2026-44791
GitHub-GHSA

CRITICAL
n8n Has an Arbitrary File Read via Git Node
GHSA-57g9-58c2-xjg3
pkg: n8n, n8n, n8n
eco: npm
published: May 14, 2026
## Impact
An authenticated user with permission to create or modify workflows could inject CLI flags on the Git node's Push operation allowing an attacker to read arbitrary files from the n8n server potentially leading to full compromise.

## Patches
The issue has been fixed in n8n versions 1.123.43…

CVE-2026-44790
GitHub-GHSA

CRITICAL
n8n: HTTP Request Node Pagination Prototype Pollution to RCE
GHSA-c8xv-5998-g76h
pkg: n8n, n8n, n8n
eco: npm
published: May 14, 2026
## Impact
An authenticated user with permission to create or modify workflows could achieve global prototype pollution via an unvalidated pagination parameter in the HTTP Request node. Combined with other techniques this could lead to RCE on the instance.

## Patches
The issue has been fixed in n8n …

CVE-2026-44789
GitHub-GHSA

CRITICAL
FlowiseAI: Authenticated Host RCE via POST /api/v1/node-custom-function and NodeVM Sandbox Escape
GHSA-9rvc-vf7m-pgm2
pkg: flowise
eco: npm
published: May 14, 2026
### Summary

`POST /api/v1/node-custom-function` lacks route-level authorization, allowing any authenticated user or API key to submit arbitrary JavaScript to the `Custom JS Function` node.

When `E2B_APIKEY` is not configured — the common deployment case — Flowise executes this code inside a `N…

CVE-2026-46442
GitHub-GHSA

CRITICAL
Strapi may leak sensitive data via relational filtering due to lack of query sanitization
GHSA-rjg2-95×7-8qmx
pkg: @strapi/strapi
eco: npm
published: May 14, 2026
### Summary of CVE-2026-27886 Vulnerability Details

– CVE: CVE-2026-27886
– CVSS v3.1 Vector: `CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N` (9.3 — Critical)
– Affected Versions: `@strapi/strapi` <=5.36.1
– How to Patch: Immediately update your Strapi to >=5.37.0

### Descripti…

CVE-2026-27886
GitHub-GHSA

CRITICAL
Strapi Vulnerable to SQL Injection in Content Type Builder
GHSA-3xcq-8mjw-h6mx
pkg: @strapi/content-type-builder, @strapi/plugin-content-type-builder
eco: npm
published: May 13, 2026
### Summary of CVE-2026-22599 Vulnerability Details

– CVE: CVE-2026-22599
– CVSS v3.1 Vector: `CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N` (9.3 — Critical)
– Affected Versions: `@strapi/content-type-builder` <=5.33.1 (v5), `@strapi/plugin-content-type-builder` <=4.26.0 (v4)
-…

CVE-2026-22599
GitHub-GHSA

CRITICAL
Mapfish Print: Remote Code Injection (RCE) in Dynamic table
GHSA-q7m6-wpvf-mvwx
pkg: org.mapfish.print:print-lib, org.mapfish.print:print-lib, org.mapfish.print:print-lib
eco: maven
published: May 13, 2026
### Impact

The attacker can execute arbitrary code without being authenticated

### Mitigation

Upgrade to a patched version (please check affected/patched version matrix)

### Credits

Bug Bounty of Canton du Jura

CVE-2026-44672
GitHub-GHSA

CRITICAL
esm.sh: Legacy Route Path Traversal Can Lead to RCE
GHSA-3636-h3vx-6465
pkg: github.com/esm-dev/esm.sh
eco: go
published: May 12, 2026
### Impact
– Arbitrary File Write – An attacker can cause the server to write data to any file path it has write permission for.
– Privilege Escalation / RCE – By overwriting critical binaries or scripts, the attacker can execute arbitrary code with the server’s privileges.

### Exploit

The l…

CVE-2026-44593
GitHub-GHSA

CRITICAL
OpenClaude Sandbox Bypass via Model-Controlled `dangerouslyDisableSandbox` Input
GHSA-m77w-p5jj-xmhg
pkg: openclaude
eco: npm
published: May 12, 2026
### Summary
The `dangerouslyDisableSandbox` parameter is exposed as part of the BashTool input schema, meaning the LLM (an untrusted principal per the project's own threat model) can set it to `true` in any `tool_use` response. Combined with the default `allowUnsandboxedCommands: true` setting, a pr…
CVE-2026-42074
GitHub-GHSA

CRITICAL
Angular Expressions – Remote Code Execution using filters
GHSA-pw8r-6689-xvf4
pkg: angular-expressions
eco: npm
published: May 11, 2026
## Impact

An attacker can write a malicious expression that escapes the sandbox to execute arbitrary code on the system.

Example of vulnerable code:

“`
const expressions = require("angular-expressions");
const result = expressions.compile("a | __proto__")({}, {});
“`

This should throw the erro…

CVE-2026-44643
GitHub-GHSA

CRITICAL
CloudNativePG's metrics exporter allows privilege escalation to PostgreSQL superuser and OS RCE
GHSA-423p-g724-fr39
pkg: github.com/cloudnative-pg/cloudnative-pg, github.com/cloudnative-pg/cloudnative-pg
eco: go
published: May 11, 2026
### Impact

The CloudNativePG metrics exporter opens its PostgreSQL connection as the `postgres` superuser via the pod-local Unix socket, then demotes the session with `SET ROLE pg_monitor`. `SET ROLE` changes only `current_user`; `session_user` remains `postgres`. That residual superuser identity i…

CVE-2026-44477
NVD

HIGH
CVE-2026-8719
CVE-2026-8719
pkg: oauth

published: May 17, 2026

The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Privilege Escalation in version 3.4.9. This is due to missing WordPress capability enforcement in the MCP OAuth bearer-token authorization path, where any valid OAuth token causes MCP access to be g…
CWE: CWE-269
GitHub-GHSA

HIGH
Budibase: `PUT /api/datasources/:datasourceId` is protected only by `TABLE/READ` permission instead of builder access, allowing any authenticated app user to overwrite datasource connection parameters including host, port, and URL
GHSA-44m2-crh7-f4q2
pkg: @budibase/server
eco: npm
published: May 15, 2026
## Summary

Budibase exposes a REST API for datasource management. The route `PUT /api/datasources/:datasourceId` is registered in the `authorizedRoutes` group with `TABLE/READ` permission. This is the same authorization level as the read endpoint (`GET /api/datasources/:datasourceId`). Every authen…

CVE-2026-45717
GitHub-GHSA

HIGH
Open WebUI: Jupyter code execution works despite `ENABLE_CODE_EXECUTION=false` — feature gate bypassed
GHSA-482j-2pq6-q5w4
pkg: open-webui
eco: pip
published: May 14, 2026
### Summary

The `/api/v1/utils/code/execute` endpoint executes arbitrary Python code via Jupyter for any verified user, even when the admin has set `ENABLE_CODE_EXECUTION=false`. The feature gate is not enforced on the API endpoint — the configuration says "disabled" but code still executes.

###…

CVE-2026-45672
NVD

HIGH
CVE-2026-8532
CVE-2026-8532
pkg: go

published: May 14, 2026

Integer overflow in XML in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-472
NVD

HIGH
CVE-2026-8531
CVE-2026-8531
pkg: go

published: May 14, 2026

Heap buffer overflow in WebML in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-122
NVD

HIGH
CVE-2026-8529
CVE-2026-8529
pkg: go

published: May 14, 2026

Heap buffer overflow in Codecs in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted video file. (Chromium security severity: High)
CWE: CWE-122
NVD

HIGH
CVE-2026-8527
CVE-2026-8527
pkg: go

published: May 14, 2026

Insufficient validation of untrusted input in Downloads in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-20
NVD

HIGH
CVE-2026-8526
CVE-2026-8526
pkg: go

published: May 14, 2026

Out of bounds write in WebRTC in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-787
NVD

HIGH
CVE-2026-8524
CVE-2026-8524
pkg: go

published: May 14, 2026

Out of bounds write in WebAudio in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-787
NVD

HIGH
CVE-2026-8522
CVE-2026-8522
pkg: go

published: May 14, 2026

Use after free in Downloads in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-8519
CVE-2026-8519
pkg: go

published: May 14, 2026

Integer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-472
NVD

HIGH
CVE-2026-8518
CVE-2026-8518
pkg: go

published: May 14, 2026

Use after free in Blink in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-8517
CVE-2026-8517
pkg: go

published: May 14, 2026

Object lifecycle issue in WebShare in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-664
NVD

HIGH
CVE-2026-8509
CVE-2026-8509
pkg: go

published: May 14, 2026

Heap buffer overflow in WebML in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-122
NVD

HIGH
CVE-2026-43909
CVE-2026-43909
pkg: openimageio openimageio

published: May 14, 2026

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, a signed 32-bit integer overflow in the loop index expression i * 4 inside SwapRGBABytes() causes the function to compute a large negative…
CWE: CWE-125, CWE-190, CWE-787
NVD

HIGH
CVE-2026-43908
CVE-2026-43908
pkg: openimageio openimageio

published: May 14, 2026

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, a signed 32-bit integer overflow in the pixel-loop index expression i * 3 inside ConvertCbYCrYToRGB() causes the function to compute a lar…
CWE: CWE-190, CWE-787
NVD

HIGH
CVE-2026-44827
CVE-2026-44827
pkg: python

published: May 14, 2026

Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, diffusers 0.37.0 allows remote code execution without the trust_remote_code=True safeguard when loading pipelines from Hugging Face Hub repositories. The _resolve_custom_pipeline_and_cls function in pipeline_loading_utils.…
CWE: CWE-94
NVD

HIGH
CVE-2026-44293
CVE-2026-44293
pkg: protobufjs_project protobufjs

published: May 13, 2026

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated JavaScript for toObject conversion could include an unsafe expression derived from a schema-controlled bytes field default value. A crafted descriptor with a non-string default val…
CWE: CWE-94
NVD

HIGH
CVE-2026-45227
CVE-2026-45227
pkg: python

published: May 12, 2026

Heym before 0.0.21 contains a sandbox escape vulnerability in the custom Python tool executor that allows authenticated workflow authors to bypass sandbox restrictions by using object-graph introspection primitives. Attackers can use Python introspection techniques to recover the unrestricted __impo…
CWE: CWE-693
NVD

HIGH
CVE-2026-44224
CVE-2026-44224
pkg: requarks wiki.js

published: May 12, 2026

Wiki.js is an open source wiki app built on Node.js. Prior to 2.5.313, the users.update GraphQL mutation accepts an arbitrary groups array and applies it directly to the database with no validation of the group IDs supplied. The resolver passes the caller's arguments straight to the model without an…
CWE: CWE-269
NVD

HIGH
CVE-2026-34329
CVE-2026-34329
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over an adjacent network.
CWE: CWE-122
NVD

HIGH
CVE-2026-31232
CVE-2026-31232
pkg: python

published: May 12, 2026

The CosyVoice project thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its model loading process. When loading model files (.pt) from a user-specified directory (via the –model_dir argument), the code uses torch.load()…
CWE: CWE-502
NVD

HIGH
CVE-2026-31225
CVE-2026-31225
pkg: python

published: May 12, 2026

The superduper project thru v0.10.0 contains a critical remote code execution vulnerability in its query parsing component. The _parse_op_part() function in query.py uses the unsafe eval() function to dynamically evaluate user-supplied query operands without proper sanitization or restriction. Altho…
CWE: CWE-94
NVD

HIGH
CVE-2026-31224
CVE-2026-31224
pkg: snorkel snorkel

published: May 12, 2026

The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the MultitaskClassifier.load() method of the MultitaskClassifier class. The method loads model weight files using torch.load() without enabling the security-restrictive weights_only=True parameter. This …
CWE: CWE-502
NVD

HIGH
CVE-2026-31223
CVE-2026-31223
pkg: snorkel snorkel

published: May 12, 2026

The snorkel library thru v0.10.0 contains a critical insecure deserialization vulnerability (CWE-502) in the BaseLabeler.load() method of the BaseLabeler class. The method loads serialized labeler models using the unsafe pickle.load() function on user-supplied file paths without any validation or se…
CWE: CWE-502, CWE-502
NVD

HIGH
CVE-2026-31222
CVE-2026-31222
pkg: snorkel snorkel

published: May 12, 2026

The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the Trainer.load() method of the Trainer class. The method loads model checkpoint files using torch.load() without enabling the security-restrictive weights_only=True parameter. This default behavior all…
CWE: CWE-502, CWE-502
NVD

HIGH
CVE-2026-31219
CVE-2026-31219
pkg: python

published: May 12, 2026

The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370811af6b11402f51d377f (2024-07-21) is vulnerable to insecure deserialization (CWE-502). When a user provides a single model file path (e.g., .pt or .pth) via the –model command-lin…
CWE: CWE-502
NVD

HIGH
CVE-2026-31218
CVE-2026-31218
pkg: python

published: May 12, 2026

The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370811af6b11402f51d377f (2024-07-21) is vulnerable to insecure deserialization (CWE-502). When loading a model state dictionary from a state_dict.pt file via torch.load(), the functio…
CWE: CWE-502
GitHub-GHSA

HIGH
LiteLLM has a sandbox escape in custom-code guardrail
GHSA-wxxx-gvqv-xp7p
pkg: litellm
eco: pip
published: May 11, 2026
### Impact

The `POST /guardrails/test_custom_code` endpoint runs user-supplied Python inside a hand-rolled sandbox. The sandbox can be escaped using bytecode-level techniques, allowing arbitrary code execution in the proxy process — which runs as root in the default Docker image.

**Reaching the …

CVE-2026-40217
GitHub-GHSA

HIGH
Dockerfile command injection via envs[*].name in bentofile.yaml (sibling fix-bypass of CVE-2026-33744 and CVE-2026-35043)
GHSA-w2pm-x38x-jp44
pkg: bentoml
eco: pip
published: May 11, 2026
# BentoML `envs[*].name` Dockerfile command injection — sibling of CVE-2026-33744 / CVE-2026-35043

A malicious `bentofile.yaml` containing a newline-injected value in `envs[*].name` produces unquoted `RUN` directives in the BentoML-generated Dockerfile. When the victim runs `bentoml containerize`…

CVE-2026-44346
GitHub-GHSA

HIGH
BentoML Dockerfile command injection via docker.base_image (sister of pending GHSA-w2pm-x38x-jp44 / CVE-2026-33744 / CVE-2026-35043)
GHSA-78f9-r8mh-4xm2
pkg: bentoml
eco: pip
published: May 11, 2026
The same Dockerfile template that mishandles `envs[*].name` (pending GHSA-w2pm-x38x-jp44) also interpolates `docker.base_image` raw with no escaping, newline filtering, or validation. A malicious bento.yaml with a multi-line `docker.base_image` value smuggles arbitrary Dockerfile directives into the…
CVE-2026-44345
GitHub-GHSA

HIGH
pyLoad is vulnerable to stored XSS in Downloads view via unsanitized link URL in packages.js template literal
GHSA-fcjq-435v-jx94
pkg: pyload-ng
eco: pip
published: May 14, 2026
## Summary

The `packages.js` template at `src/pyload/webui/app/themes/modern/templates/js/packages.js:172` interpolates a stored link URL into a template literal inside single-quoted HTML and then writes the result to the DOM via `$(div).html(html)`. No escaping runs between the API value and `inne…

CVE-2026-45348
GitHub-GHSA

HIGH
Open WebUI has stored XSS via attacker-controlled file extension in /api/v1/audio/transcriptions
GHSA-m8f9-9whg-f4xr
pkg: open-webui
eco: pip
published: May 14, 2026
## Summary

The audio transcription upload endpoint takes the file extension from the user-supplied filename and saves the file under CACHE_DIR/audio/tran…

CVE-2026-45315
GitHub-GHSA

HIGH
protobuf.js: Code injection in pbjs static output from crafted schema names
GHSA-6r35-46g8-jcw9
pkg: protobufjs-cli, protobufjs-cli
eco: npm
published: May 12, 2026
## Summary

`pbjs` static code generation could emit unsafe JavaScript identifiers derived from schema-controlled names. When generating static JavaScript from a crafted schema or JSON descriptor, certain namespace, enum, service, or derived full names could be written into the generated output with…

CVE-2026-44295
GitHub-GHSA

HIGH
Local Path Provisioner Vulnerable to HelperPod Template Injection
GHSA-7fxv-8wr2-mfc4
pkg: github.com/rancher/local-path-provisioner
eco: go
published: May 11, 2026
### Impact

A malicious user with permission to edit the `local-path-config` ConfigMap in the `local-path-storage` namespace can manipulate the `helperPod.yaml` template used by `rancher/local-path-provisioner`.

The `helperPod.yaml` template is loaded by the provisioner and used to create HelperPod…

CVE-2026-44543
NVD

HIGH
CVE-2026-42595
CVE-2026-42595
pkg: docker

published: May 14, 2026

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, Gotenberg's Chromium URL-to-PDF endpoint (/forms/chromium/convert/url) has no default protection against HTTP/HTTPS-based SSRF. The default deny-list regex only blocks file:// URIs. An unauthenticated attacker can point Chro…
CWE: CWE-918
NVD

HIGH
CVE-2026-44578
CVE-2026-44578
pkg: vercel next.js

published: May 13, 2026

Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket upgrade requests. An attacker can cause the server t…
CWE: CWE-918
NVD

HIGH
CVE-2026-44001
CVE-2026-44001
pkg: vm2_project vm2

published: May 13, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, a sandbox escape vulnerability in vm2 v3.10.5 allows any sandboxed code to crash the host Node.js process via a single Promise constructor that triggers an unhandled rejection propagating to the host. The fix for CVE-2026-22709 (v3.10.2)…
CWE: CWE-248
GitHub-GHSA

HIGH
Klever-Go MultiDataInterceptor has remote OOM via crafted compressed P2P payload
GHSA-87m7-qffr-542v
pkg: github.com/klever-io/klever-go
eco: go
published: May 13, 2026
## Summary

A remote, unauthenticated denial-of-service vulnerability in
`Batch.Decompress` (`data/batch/batch.go`) allows any peer that
participates in a topic served by `MultiDataInterceptor` to allocate
multi-gigabyte heaps on the receiving node from a sub-50 KiB gossip
payload. A single packet i…

CVE-2026-44697
GitHub-GHSA

HIGH
Next.js vulnerable to server-side request forgery in applications using WebSocket upgrades
GHSA-c4j6-fc7j-m34r
pkg: next, next
eco: npm
published: May 11, 2026
### Impact

Self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket upgrade requests. An attacker can cause the server to proxy requests to arbitrary internal or external destinations, which may expose internal services or…

CVE-2026-44578
GitHub-GHSA

HIGH
PraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables execute
GHSA-gmjg-hv98-qggq
pkg: praisonaiagents, PraisonAI
eco: pip
published: May 11, 2026
### Summary
`praisonaiagents` resolves unresolved tool names against module globals and `__main__` after it fails to match the declared tool list and the registry. With the default agent configuration, `_perm_allow` is `None`, so undeclared non-dangerous tool names are not rejected by the permission…
CVE-2026-44339
GitHub-GHSA

HIGH
Gotenberg: Server-Side Request Forgery via Chromium URL Endpoint with Redirect-Based Deny-List Bypass
GHSA-chwh-f6gm-r836
pkg: github.com/gotenberg/gotenberg/v8
eco: go
published: May 11, 2026
A review of 4 published Gotenberg security advisories exposed an SSRF issue. GHSA-pjrr-jgp4-v2fm covers SSRF via the `downloadFrom` endpoint. GHSA-pcrp-7g9h-7qhp covers SSRF via the `webhook` endpoint. Neither advisory addresses SSRF through the primary Chromium URL-to-PDF conversion endpoint (`/for…
CVE-2026-42595
GitHub-GHSA

HIGH
Open WebUI has a SSRF Bypass via HTTP Redirect Following in Web-Fetch and Image-Load Endpoints (not addressed by CVE-2025-65958)
GHSA-rh5x-h6pp-cjj6
pkg: open-webui
eco: pip
published: May 14, 2026
# Server-Side Request Forgery (SSRF) Bypass via HTTP Redirect Following in Web-Fetch, Image-Load, and Chat-Completion Endpoints

## Summary

The `validate_url()` function in `backend/open_webui/retrieval/web/utils.py` only validates the *initial* URL submitted by the caller. The HTTP clients used do…

CVE-2026-45401
GitHub-GHSA

HIGH
Open WebUI has a Server-Side Request Forgery (SSRF) bypass in `validate_url`
GHSA-8w7q-q5jp-jvgx
pkg: open-webui
eco: pip
published: May 14, 2026
### Summary
In the open-webui project, a parsing difference between the urlparse and requests libraries led to an SSRF bypass vulnerability.

### Details
In the current project, URL validation is performed using the function validate_url.

<img width="1323" height="1145" alt="QQ20260322-202854-22-1"…

CVE-2026-45400
GitHub-GHSA

HIGH
Open WebUI has a full SSRF Vulnerability in the RAG Web Search Feature
GHSA-4v7r-f4w8-8972
pkg: open-webui
eco: pip
published: May 14, 2026
# SSRF Bypass via IPv6/IPv4-mapped IPv6/IPv4-reserved-ranges in `validate_url()`

## Summary

`validate_url()` in `backend/open_webui/retrieval/web/utils.py` calls `validators.ipv6(ip, private=True)`, but the `validators` library does NOT implement the `private` keyword for IPv6 — the call raises …

CVE-2026-45331
GitHub-GHSA

HIGH
Portainer has a bind-mount restriction bypass via HostConfig.Mounts
GHSA-7fw3-x4r2-g7wc
pkg: github.com/portainer/portainer, github.com/portainer/portainer, github.com/portainer/portainer
eco: go
published: May 14, 2026
## Summary

Portainer offers an environment-level **Disable bind mounts for non-administrators** security setting that blocks regular users from binding host paths into containers they create through the Portainer-mediated Docker API. The check that enforces this setting only inspected the legacy `H…

CVE-2026-44850
NVD

HIGH
CVE-2026-43998
CVE-2026-43998
pkg: vm2_project vm2

published: May 13, 2026

vm2 is an open source vm/sandbox for Node.js. In 3.10.5, NodeVM's require.root path restriction can be bypassed using filesystem symlinks, allowing sandboxed code to load modules from outside the allowed root directory in host context. Because path validation uses path.resolve() (which does not dere…
CWE: CWE-59
GitHub-GHSA

HIGH
Nautobot: Webhook definitions could be used for server-side request forgery (SSRF)
GHSA-c35q-vxrp-ph26
pkg: nautobot, nautobot
eco: pip
published: May 13, 2026
### Impact

Nautobot's `Webhook` data model and associated feature set could be configured by users with sufficient access to perform requests to various hosts and IP addresses that should not be permitted, allowing for various behaviors similar to server-side request forgery (SSRF).

### Patches

F…

CVE-2026-44797
NVD

HIGH
CVE-2026-44015
CVE-2026-44015
pkg: nginxui nginx_ui

published: May 12, 2026

Nginx UI is a web user interface for the Nginx web server. In 2.3.4 and earlier, an authenticated user can perform Server-Side Request Forgery (SSRF) by creating a cluster node pointing to an arbitrary internal URL and then sending API requests with the X-Node-ID header. The Proxy middleware forward…
CWE: CWE-918
NVD

HIGH
CVE-2026-25705
CVE-2026-25705
pkg: node

published: May 13, 2026

A vulnerability has been identified in [Rancher's Extensions](https://ranchermanager.docs.rancher.com/integrations-in-rancher/rancher-extensions) where malicious code can be injected in Rancher through a path traversal in the `compressedEndpoint` field inside a `UIPlugin` deployment. A malicious UI …
CWE: CWE-35
NVD

HIGH
CVE-2026-45369
CVE-2026-45369
pkg: python

published: May 14, 2026

python-utcp is the python implementation of UTCP. Prior to 1.1.3, the _substitute_utcp_args method in cli_communication_protocol.py inserts user-controlled tool_args values directly into shell command strings without any sanitization or escaping. These commands are then executed via /bin/bash -c (Un…
CWE: CWE-78
NVD

HIGH
CVE-2026-8534
CVE-2026-8534
pkg: linux

published: May 14, 2026

Integer overflow in GPU in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-472
NVD

HIGH
CVE-2026-8533
CVE-2026-8533
pkg: go

published: May 14, 2026

Use after free in Accessibility in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-8530
CVE-2026-8530
pkg: go

published: May 14, 2026

Use after free in Network in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-8525
CVE-2026-8525
pkg: go

published: May 14, 2026

Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-122
NVD

HIGH
CVE-2026-8523
CVE-2026-8523
pkg: go

published: May 14, 2026

Use after free in Mojo in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-8520
CVE-2026-8520
pkg: go

published: May 14, 2026

Race in Payments in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-362
NVD

HIGH
CVE-2026-8515
CVE-2026-8515
pkg: go

published: May 14, 2026

Use after free in HID in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-8514
CVE-2026-8514
pkg: go

published: May 14, 2026

Use after free in Aura in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-8513
CVE-2026-8513
pkg: go

published: May 14, 2026

Use after free in Input in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-8512
CVE-2026-8512
pkg: go

published: May 14, 2026

Use after free in FileSystem in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-44586
CVE-2026-44586
pkg: node

published: May 14, 2026

SiYuan is an open-source personal knowledge management system. From 2.1.12 to before 3.7.0. SiYuan's Bazaar marketplace renders package author metadata from the public bazaar stage feed into HTML without escaping. In the desktop app this becomes stored XSS, and because SiYuan's Electron windows are …
CWE: CWE-79, CWE-94
NVD

HIGH
CVE-2026-42313
CVE-2026-42313
pkg: pyload-ng_project pyload-ng

published: May 11, 2026

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API method (@permission(Perms.SETTINGS)) in src/pyload/core/api/__init__.py gates security-sensitive options behind a hand-maintained allowlist ADMIN_ONLY_CORE_OPTIONS. The allowlist …
CWE: CWE-441, CWE-863, CWE-918
GitHub-GHSA

HIGH
Open WebUI has inconsistent authorization controls within memories API
GHSA-hmjq-crxp-7rjw
pkg: open-webui
eco: pip
published: May 11, 2026
### Summary

Authorization controls surrounding the memories API were inconsistent, resulting in the ability of a standard user to delete, restore, and view the contents of other users' memories.

### Details

Using a newly created non-admin user with no existing memories, it is possible to view ex…

CVE-2026-44570
GitHub-GHSA

HIGH
Open WebUI has a CORS misconfiguration and session validation issue
GHSA-6xcp-7mpr-m7wm
pkg: open-webui
eco: pip
published: May 11, 2026
# GitHub Security Lab (GHSL) Vulnerability Report, open-webui: `GHSL-2024-174`, `GHSL-2024-175`

The [GitHub Security Lab](https://securitylab.github.com) team has identified potential security vulnerabilities in [open-webui](https://github.com/open-webui/open-webui).

We are committed to working wi…

GitHub-GHSA

HIGH
@joplin/onenote-converter: Path traversal in OneNote importer allows overwriting arbitrary files
GHSA-gcmj-c9gg-9vh6
pkg: @joplin/onenote-converter
eco: npm
published: May 15, 2026
### Summary
A path traversal vulnerability in the OneNote importer allows overwriting arbitrary files on disk.

### Details
The OneNote converter does not sanitize the names of embedded files before writing them to disk. As a result, it's possible for an attacker to create a malicious `.one` file th…

CVE-2026-22810
GitHub-GHSA

HIGH
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in @ranfdev/deepobj
GHSA-x7q7-fchv-8h2j
pkg: @ranfdev/deepobj
eco: npm
published: May 14, 2026
### Impact
Prototype pollution is possible when property paths contain `__proto__`/`constructor`/`prototype`. The property path must not be exposed as user input.
CVE-2026-46509
NVD

HIGH
CVE-2026-42591
CVE-2026-42591
pkg: docker

published: May 14, 2026

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the LibreOffice conversion endpoint (/forms/libreoffice/convert) passes uploaded documents directly to LibreOffice without inspecting their content. LibreOffice then fetches any embedded external URLs on its own, completely …
CWE: CWE-918
NVD

HIGH
CVE-2026-42590
CVE-2026-42590
pkg: docker

published: May 14, 2026

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.30.0, The ExifTool metadata write blocklist in Gotenberg can be bypassed using ExifTool's group-prefix syntax, enabling arbitrary file rename, move, hardlink, and symlink creation on the server. ExifTool supports group-prefix synt…
CWE: CWE-184
NVD

HIGH
CVE-2026-40893
CVE-2026-40893
pkg: docker

published: May 14, 2026

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg only checks if the tag is exactly FileName, so System:FileName slips right through and ExifTool happily renames the file. This allows remote attackers to move, rename, and change permissions for arbitrary files. Th…
CWE: CWE-73, CWE-184
NVD

HIGH
CVE-2026-32992
CVE-2026-32992
pkg: ssl

published: May 13, 2026

SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and capture credentials.
CWE: CWE-295
GitHub-GHSA

HIGH
Anchor: Program<'info, System> is not properly validated
GHSA-c6rc-8jpp-2fgc
pkg: anchor-lang
eco: rust
published: May 13, 2026
### Summary
An logic error causes anchor programs to accept any program id when requiring the system program id, causing false assumptions resulting in potential arbitrary cpi in programs that invoke system program instructions.

### Details
In the TryFrom<&'a AccountInfo<'a>> implementation for Pro…

CVE-2026-45137
NVD

HIGH
CVE-2026-43929
CVE-2026-43929
pkg: node

published: May 12, 2026

ssrfcheck is a library that checks if a string contains a potential SSRF attack. In 1.3.0 and earlier, ssrfcheck fails to block Server-Side Request Forgery attacks when the target private IP address is encoded as an IPv4-mapped IPv6 address (e.g. http://[::ffff:127.0.0.1]/). The WHATWG URL parser bu…
CWE: CWE-184, CWE-918
GitHub-GHSA

HIGH
Dalfox Server Mode has an Unauthenticated Arbitrary File Create/Append via `output` Option
GHSA-8hf9-3q64-q2qf
pkg: github.com/hahwul/dalfox/v2
eco: go
published: May 12, 2026
## Summary

When dalfox is run in REST API server mode, the `output`, `output-all`, and `debug` fields in `model.Options` are JSON-tagged and deserialized directly from the attacker's request body, then propagated unchanged through `dalfox.Initialize` into the scan engine's logging path. The logger …

CVE-2026-45089
NVD

HIGH
CVE-2026-43893
CVE-2026-43893
pkg: node

published: May 11, 2026

exiftool-vendored provides cross-platform Node.js access to ExifTool. Prior to 35.19.0, exiftool-vendored starts ExifTool in -stay_open True -@ – mode, where arguments are read from stdin one per line. In affected versions, several caller-supplied strings were interpolated into ExifTool arguments wi…
CWE: CWE-88
NVD

HIGH
CVE-2026-43886
CVE-2026-43886
pkg: oauth

published: May 11, 2026

Outline is a service that allows for collaborative documentation. From 0.84.0 to 1.6.1, a logic error in OAuthInterface.validateScope() uses Array.some() to validate requested OAuth scopes, causing the function to accept the entire scope array if any single scope is valid. An attacker can smuggle th…
CWE: CWE-269
GitHub-GHSA

HIGH
@rvf/set-get has a prototype pollution issue that's reachable via @rvf/core preprocessFormData (HTTP form data)
GHSA-c567-44rc-m5hq
pkg: @rvf/set-get, @rvf/set-get
eco: npm
published: May 11, 2026
## Summary

`setPath` in `@rvf/set-get` (used by `@rvf/core` to flatten incoming form data into a nested object) does not block the keys `__proto__`, `constructor`, or `prototype` when walking a path. Because field names in submitted form data are passed directly to `setPath` via `preprocessFormData…

CVE-2026-44483
GitHub-GHSA

HIGH
GuardDog has a blind GitHub URL rewrite in remote project scanning causes SSRF and `GH_TOKEN` exfiltration
GHSA-587r-mc96-6f2p
pkg: guarddog
eco: pip
published: May 11, 2026
# Summary
The programmatic remote project scanning path rewrites attacker-controlled repository URLs using a blind string replacement and then sends the caller's GitHub credentials with the resulting request. This allows an attacker who can influence the scanned repository URL to trigger SSRF and ca…
CVE-2026-44971
NVD

HIGH
CVE-2026-45675
CVE-2026-45675
pkg: oauth

published: May 15, 2026

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, he LDAP and OAuth authentication flows use a TOCTOU (Time-of-Check-Time-of-Use) pattern for first-user admin role assignment. The regular signup handler (signup_handler in auths.py, lin…
CWE: CWE-269, CWE-362
GitHub-GHSA

HIGH
epa4all-client: TLS Certificate Validation Disabled in Production
GHSA-5hhf-xmfx-4vvr
pkg: com.oviva.telematik:epa4all-client
eco: maven
published: May 15, 2026
### Impact
An attacker on the network path between the ePA service and the Konnektor can present any TLS certificate (self-signed, expired, wrong CN) and intercept all SOAP traffic. This includes patient identifiers (KVNR), SMC-B card operations (authentication, signing),
document content, and crede…
CVE-2026-45574
GitHub-GHSA

HIGH
FrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP Files
GHSA-3g8v-8r37-cgjm
pkg: github.com/dunglas/frankenphp
eco: go
published: May 15, 2026
### Summary

The `splitPos()` function in [`cgi.go`](https://github.com/php/frankenphp/blob/main/cgi.go) misuses `golang.org/x/text/search` with `search.IgnoreCase` when the request path contains a non-ASCII byte. Two distinct flaws in that fallback let an attacker mislead FrankenPHP into treating a…

CVE-2026-45062
NVD

HIGH
CVE-2026-35194
CVE-2026-35194
pkg: express

published: May 15, 2026

Code injection in SQL code generation in Apache Flink 1.15.0 through 1.20.x and 2.0.0 through 2.x allows authenticated users with query submission privileges to execute arbitrary code on TaskManagers via maliciously crafted SQL queries. The vulnerability affects JSON functions (1.15.0+) and LIKE exp…
CWE: CWE-94
GitHub-GHSA

HIGH
Open WebUI: LDAP and OAuth First-User Race Condition Allows Multiple Admin Accounts
GHSA-h3ww-q6xx-w7x3
pkg: open-webui
eco: pip
published: May 14, 2026
## Summary

The LDAP and OAuth authentication flows use a TOCTOU (Time-of-Check-Time-of-Use) pattern for first-user admin role assignment. The regular signup handler (`signup_handler` in auths.py, line 663) was explicitly patched to prevent this race with the comment *"Insert with default role first…

CVE-2026-45675
GitHub-GHSA

HIGH
Open WebUI has Stored XSS in Banner Component via Improper Sanitization Order
GHSA-cqp4-qqvg-3787
pkg: open-webui
eco: npm
published: May 14, 2026
### Summary
A Stored Cross-Site Scripting (XSS) vulnerability exists in the Banner component due to an improper sanitization order (specifically, DOMPurify is executed before the marked library).

This vulnerability allows a compromised or malicious administrator to plant a malicious payload in the …

CVE-2026-45665
GitHub-GHSA

HIGH
Open WebUI: Cross-User File Access via Unchecked file_id in Folder Knowledge and Knowledge-Base Attach Endpoints
GHSA-r472-mw7m-967f
pkg: open-webui
eco: pip
published: May 14, 2026
# Cross-User File Access via Unchecked file_id in Folder Knowledge and Knowledge-Base Attach Endpoints

## Summary

Multiple endpoints accept a user-supplied `file_id` and attach the referenced file to a resource the caller controls (folder knowledge, knowledge-base contents) without verifying that …

CVE-2026-45402
GitHub-GHSA

HIGH
Open WebUI: Missing permission check in files API allows authenticated users to list, access and delete every uploaded file
GHSA-r8wh-8m7r-fh33
pkg: open-webui
eco: pip
published: May 14, 2026
### Summary
A missing permission check in all files related API endpoints allows any authenticated user to list, access and delete every file uploaded by every user to the platform.

### Details
All `files/` related endpoints lack permission checks.

#### Listing all files
For example, let's see how…

CVE-2026-45301
GitHub-GHSA

HIGH
Apostrophe has a Weak Password Recovery Mechanism for Forgotten Password and Improper Input Validation
GHSA-gf43-24g3-5hw2
pkg: apostrophe
eco: npm
published: May 14, 2026
## Summary

ApostropheCMS's password reset flow constructs the reset URL using `req.hostname`,
which is derived directly from the attacker-controlled HTTP `Host` header when
`apos.baseUrl` is not explicitly configured. An unauthenticated attacker who knows
a victim's email address can send a craf…

CVE-2026-45013
GitHub-GHSA

HIGH
go-billy has path traversal vulnerabilities
GHSA-qw64-3×98-g7q2
pkg: github.com/go-git/go-billy/v5, github.com/go-git/go-billy/v6
eco: go
published: May 14, 2026
### Impact
Multiple path traversal issues exist across different components of `go-billy`. Insufficient path sanitization and boundary enforcement may allow crafted paths (e.g., using `..`) to escape intended base directories.

While go-billy was not originally designed to provide a strong security …

CVE-2026-44973
GitHub-GHSA

HIGH
Portainer's Kubernetes middleware continues after token validation failure, bypassing endpoint authorization
GHSA-mgq6-4×29-88r3
pkg: github.com/portainer/portainer
eco: go
published: May 14, 2026
## Summary

Portainer proxies requests to Kubernetes clusters through a middleware layer (`kubeClientMiddleware`) that validates the requesting user's token before forwarding traffic to the cluster. When `security.RetrieveTokenData` returned an error, the middleware wrote an HTTP 403 response but wa…

CVE-2026-44882
GitHub-GHSA

HIGH
wger: Privilege escalation via trainer-login session chaining allows gym trainer to impersonate gym manager
GHSA-9qpr-vc49-hqg2
pkg: wger
eco: pip
published: May 14, 2026
### Summary
A gym trainer can escalate their session to any higher-privileged account (gym manager, general manager) by chaining two calls to the trainer-login endpoint. Once a trainer performs a legitimate switch into a low-privileged user, the session flag `trainer.identity`
is set and this flag a…
CVE-2026-43978
NVD

HIGH
CVE-2026-42602
CVE-2026-42602
pkg: jwt

published: May 13, 2026

azureauthextension is the Azure Authenticator Extension. From 0.124.0 to 0.150.0, a server-side authentication bypass in azureauthextension allows any party who holds a single valid Azure access token for any scope the collector's configured identity can mint for to authenticate to any OpenTelemetry…
CWE: CWE-208, CWE-287, CWE-290, CWE-294, CWE-347
NVD

HIGH
CVE-2026-44574
CVE-2026-44574
pkg: vercel next.js

published: May 13, 2026

Next.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applications that rely on middleware to protect dynamic routes can be vulnerable to authorization bypass. In affected deployments, specially crafted query parameters can alter the dynamic…
CWE: CWE-288
NVD

HIGH
CVE-2026-42945
CVE-2026-42945
pkg: express

published: May 13, 2026

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacemen…
CWE: CWE-122
NVD

HIGH
CVE-2026-44304
CVE-2026-44304
pkg: tls

published: May 12, 2026

Lemur manages TLS certificate creation. Prior to 1.9.0, Lemur's LDAP authentication module (lemur/auth/ldap.py) constructs LDAP search filters using unsanitized user input via Python string interpolation. An authenticated LDAP user can inject LDAP filter metacharacters through the username field to …
CWE: CWE-90
NVD

HIGH
CVE-2026-8430
CVE-2026-8430
pkg: nginx

published: May 12, 2026

SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the public space that is limited to certain nginx configurations, allowing attackers to execute arbitrary code in the context of the web server. Attackers can exploit this vulnerability through specific nginx configuratio…
CWE: CWE-94
GitHub-GHSA

HIGH
protobuf.js: Code generation gadget after prototype pollution
GHSA-75px-5xx7-5xc7
pkg: protobufjs, protobufjs
eco: npm
published: May 12, 2026
## Summary

protobufjs used plain objects with inherited prototypes for internal type lookup tables used by generated encode and decode functions. If `Object.prototype` had already been polluted, those lookup tables could resolve attacker-controlled inherited properties as valid protobuf type inform…

CVE-2026-44291
NVD

HIGH
CVE-2026-42315
CVE-2026-42315
pkg: pyload-ng_project pyload-ng

published: May 11, 2026

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, when passing a folder name in the set_package_data() API function call inside the data object with key "_folder", there is no sanitization at all, allowing a user with Perms.MODIFY to specify arbitrary dire…
CWE: CWE-22, CWE-36
GitHub-GHSA

HIGH
Open WebUI Arbitrary File Write, Delete via Path Traversal
GHSA-j3fw-wc48-29g3
pkg: open-webui
eco: pip
published: May 11, 2026
** CONFIDENTIAL **

Vulnerability Disclosure Analysis Documentation
———————————————–

Vulnerability Details
———————
1. Discoverer: Taylor Pennington of KoreLogic, Inc.
2. Date Submitted: June 11, 2024
3. Title: Open WebUI Arbitrary File Write, Delete via …

CVE-2026-44565
GitHub-GHSA

HIGH
Open WebUI: shared-chat branch ignores access_type, allowing unauthorized file deletion
GHSA-26g9-27vm-x3q8
pkg: open-webui
eco: pip
published: May 14, 2026
### Summary

Any authenticated user can permanently delete files owned by other users via `DELETE /api/v1/files/{id}` when the target file is referenced in any shared chat. The `has_access_to_file()` authorization gate unconditionally grants access through its shared-chat branch. It checks neither t…

CVE-2026-45671
NVD

HIGH
CVE-2026-34332
CVE-2026-34332
pkg: microsoft windows_server_2025

published: May 12, 2026

Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to execute code over a network.
CWE: CWE-416
GitHub-GHSA

HIGH
uniget is Vulnerable to Command Injection in tool.Check Leading to Arbitrary Code Execution
GHSA-qqq4-5773-pmw5
pkg: gitlab.com/uniget-org/cli
eco: go
published: May 13, 2026
I discovered a command injection vulnerability in uniget that allows arbitrary command execution through the metadata loading and version check mechanism.

### Summary

A command injection vulnerability exists in uniget due to unsafe execution of the `check` field from metadata files using `/bin/bas…

CVE-2026-45152
GitHub-GHSA

HIGH
Systeminformation vulnerable to Linux command injection in networkInterfaces() via unsanitized NetworkManager connection profile name
GHSA-hvx9-hwr7-wjj9
pkg: systeminformation
eco: npm
published: May 13, 2026
## Summary

On Linux, `systeminformation` is vulnerable to command injection in `networkInterfaces()` when an **active NetworkManager connection profile name** contains shell metacharacters.

This is not caused by a caller passing attacker-controlled arguments into `networkInterfaces()`. The vulnera…

CVE-2026-44724
NVD

HIGH
CVE-2026-35421
CVE-2026-35421
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Heap-based buffer overflow in Windows GDI allows an unauthorized attacker to execute code locally.
CWE: CWE-122
NVD

HIGH
CVE-2026-35420
CVE-2026-35420
pkg: microsoft windows_server_2012, microsoft windows_server_2016, microsoft windows_server_2019

published: May 12, 2026

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
CWE: CWE-122
NVD

HIGH
CVE-2026-35418
CVE-2026-35418
pkg: microsoft windows_10_1809, microsoft windows_10_21h2, microsoft windows_10_22h2

published: May 12, 2026

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
CWE: CWE-367, CWE-416
NVD

HIGH
CVE-2026-35417
CVE-2026-35417
pkg: microsoft windows_10_1809, microsoft windows_10_21h2, microsoft windows_10_22h2

published: May 12, 2026

Access of resource using incompatible type ('type confusion') in Windows Win32K – ICOMP allows an authorized attacker to elevate privileges locally.
CWE: CWE-843
NVD

HIGH
CVE-2026-35415
CVE-2026-35415
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Integer overflow or wraparound in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.
CWE: CWE-190
NVD

HIGH
CVE-2026-34351
CVE-2026-34351
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
CWE: CWE-362
NVD

HIGH
CVE-2026-34344
CVE-2026-34344
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CWE: CWE-843
NVD

HIGH
CVE-2026-34343
CVE-2026-34343
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Heap-based buffer overflow in Windows Application Identity (AppID) Subsystem allows an authorized attacker to elevate privileges locally.
CWE: CWE-122
NVD

HIGH
CVE-2026-34338
CVE-2026-34338
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CWE: CWE-416
NVD

HIGH
CVE-2026-34337
CVE-2026-34337
pkg: microsoft windows_10_1809, microsoft windows_10_21h2, microsoft windows_10_22h2

published: May 12, 2026

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
CWE: CWE-362, CWE-416
NVD

HIGH
CVE-2026-34336
CVE-2026-34336
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Buffer over-read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
CWE: CWE-126
NVD

HIGH
CVE-2026-34334
CVE-2026-34334
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
CWE: CWE-362
NVD

HIGH
CVE-2026-34333
CVE-2026-34333
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Use after free in Windows Win32K – GRFX allows an authorized attacker to elevate privileges locally.
CWE: CWE-190, CWE-416
NVD

HIGH
CVE-2026-34330
CVE-2026-34330
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Integer overflow or wraparound in Windows Win32K – GRFX allows an authorized attacker to elevate privileges locally.
CWE: CWE-190, CWE-416
NVD

HIGH
CVE-2026-33841
CVE-2026-33841
pkg: microsoft windows_10_21h2, microsoft windows_10_22h2, microsoft windows_11_23h2

published: May 12, 2026

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
CWE: CWE-122
NVD

HIGH
CVE-2026-33840
CVE-2026-33840
pkg: microsoft windows_11_24h2, microsoft windows_11_25h2, microsoft windows_11_26h1

published: May 12, 2026

Use after free in Windows Win32K – ICOMP allows an authorized attacker to elevate privileges locally.
CWE: CWE-416
NVD

HIGH
CVE-2026-33838
CVE-2026-33838
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Double free in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
CWE: CWE-415
NVD

HIGH
CVE-2026-33837
CVE-2026-33837
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Heap-based buffer overflow in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
CWE: CWE-122
NVD

HIGH
CVE-2026-33835
CVE-2026-33835
pkg: microsoft windows_10_1809, microsoft windows_10_21h2, microsoft windows_10_22h2

published: May 12, 2026

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
CWE: CWE-416
NVD

HIGH
CVE-2026-33834
CVE-2026-33834
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Improper access control in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.
CWE: CWE-284
NVD

HIGH
CVE-2026-20767
CVE-2026-20767
pkg: intel quickassist_technology

published: May 12, 2026

Improper input validation for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable escalation of privilege.…
CWE: CWE-20
NVD

HIGH
CVE-2026-20714
CVE-2026-20714
pkg: intel quickassist_technology

published: May 12, 2026

Out-of-bounds write for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable escalation of privilege. This r…
CWE: CWE-787
NVD

HIGH
CVE-2026-31221
CVE-2026-31221
pkg: lightningai pytorch_lightning

published: May 12, 2026

PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the securi…
CWE: CWE-502, CWE-502
GitHub-GHSA

HIGH
protobuf.js is Vulnerable to OS Command Injection in the CLI
GHSA-f84p-cvgm-xgjj
pkg: protobufjs-cli, protobufjs-cli
eco: npm
published: May 12, 2026
## Summary

`pbts` invoked JSDoc by building a shell command string from input file paths and executing it through `child_process.exec`. File paths containing shell metacharacters could therefore be interpreted by the shell instead of being passed to JSDoc as plain arguments.

## Impact

An attacker…

CVE-2026-42290
NVD

HIGH
CVE-2026-45338
CVE-2026-45338
pkg: oauth

published: May 15, 2026

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, a Server-Side Request Forgery (SSRF) vulnerability exists in _process_picture_url() in backend/open_webui/utils/oauth.py (line ~1338). The function fetches arbitrary URLs from OAuth pic…
CWE: CWE-918
GitHub-GHSA

HIGH
Budibase: SSRF Bypass via HTTP Redirect in REST Datasource Integration
GHSA-fgqv-jh4g-pvg2
pkg: @budibase/server
eco: npm
published: May 15, 2026
### Summary

The REST datasource integration follows HTTP redirects without re-checking the IP blacklist, allowing an authenticated Builder to access internal services (cloud metadata, databases) by redirecting through an attacker-controlled server. The same vulnerability class was already patched i…

CVE-2026-45715
GitHub-GHSA

HIGH
Budibase: SSRF in AI Extract File Automation Step via Missing IP Blacklist Validation
GHSA-rpj4-7x2v-wjrf
pkg: @budibase/server
eco: npm
published: May 15, 2026
## Vulnerability Details

**CWE-918**: Server-Side Request Forgery (SSRF)

The `processUrlFile` function in `packages/server/src/automations/steps/ai/extract.ts` uses `fetch(fileUrl)` directly **without the IP blacklist validation** that is consistently applied to all other automation steps. This al…

CVE-2026-45548
NVD

HIGH
CVE-2026-45370
CVE-2026-45370
pkg: python

published: May 14, 2026

python-utcp is the python implementation of UTCP. Prior to 1.1.3, _prepare_environment() in cli_communication_protocol.py passes a full copy of os.environ to every CLI subprocess. When combined with CVE-2026-45369, an attacker can exfiltrate all process-level secrets in a single tool call. This vuln…
CWE: CWE-526
GitHub-GHSA

HIGH
python-utcp: Full Process Environment Exposed to CLI Subprocess – Secrets Leakage via Command Injection
GHSA-5v57-8rxj-3p2r
pkg: utcp-cli
eco: pip
published: May 14, 2026
## Summary

`_prepare_environment()` in `cli_communication_protocol.py` passes a full copy of `os.environ` to every CLI subprocess. When combined with the Command Injection vulnerability (CWE-78) in `_substitute_utcp_args()` tracked as GHSA-33p6-5jxp-p3x4, an attacker can exfiltrate all process-leve…

CVE-2026-45370
GitHub-GHSA

HIGH
Open WebUI Vulnerable to SSRF via OAuth Profile Picture URL in _process_picture_url (oauth.py)
GHSA-24c9-2m8q-qhmh
pkg: open-webui
eco: pip
published: May 14, 2026
## Summary

A Server-Side Request Forgery (SSRF) vulnerability exists in `_process_picture_url()` in `backend/open_webui/utils/oauth.py` (line ~1338). The function fetches arbitrary URLs from OAuth `picture` claims without applying `validate_url()`, allowing an attacker to force the server to make H…

CVE-2026-45338
GitHub-GHSA

HIGH
Open WebUI has stored XSS via the HTML renedering view
GHSA-4vrc-m9ch-6m3r
pkg: open-webui
eco: pip
published: May 14, 2026
### Summary
Through the HTML rendering view, scripts can be injected and executed.
The finding resulted from a penetration test for a customer. It is suspected that the root cause of the issue lies within the core of Open WebUI, which is why it is being reported as a security issue here. Tested on …
CVE-2026-45303
NVD

HIGH
CVE-2026-42283
CVE-2026-42283
pkg: kubernetes

published: May 14, 2026

DevSpace is a client-only developer tool for cloud-native development with Kubernetes. Prior to 6.3.21, DevSpace's UI server WebSocket accepts connections from all origins by default, and therefore several endpoints are exposed via this WebSocket. When a developer runs the DevSpace UI and at the sam…
CWE: CWE-200, CWE-306
NVD

HIGH
CVE-2026-44738
CVE-2026-44738
pkg: getgrav grav

published: May 11, 2026

Grav is a file-based Web platform. Prior to 2.0.0-rc.2, the Twig sandbox allow-list permits any user with the admin.pages role to call config.toArray() from within a page body, dumping the entire merged site configuration — including all plugin secrets (SMTP passwords, AWS keys, OAuth client secre…
CWE: CWE-200
GitHub-GHSA

HIGH
Budibase vulnerable to SSRF via trivial `.tar.gz` substring bypass in Plugin URL upload (`/api/plugin`)
GHSA-xh5j-727m-w6gg
pkg: budibase
eco: npm
published: May 11, 2026
## 1. Summary

| Field | Value |
|——-|——-|
| **Title** | SSRF via trivial `.tar.gz` substring bypass in Plugin URL upload |
| **Product** | Budibase (Self-Hosted) |
| **Version** | ≤ 3.34.11 (latest stable as of 2026-03-30) |
| **Component** | `packages/server/src/api/controllers/plugin/ur…

CVE-2026-45061
GitHub-GHSA

HIGH
Apostrophe has authenticated SSRF in rich-text widget import via @apostrophecms/area/validate-widget
GHSA-pr28-mf3q-qpg6
pkg: apostrophe
eco: npm
published: May 14, 2026
### Summary
ApostropheCMS contains an authenticated server-side request forgery (SSRF) in the rich-text widget import flow. An authenticated user who can submit/edit rich-text widget content can cause the server to fetch attacker-controlled URLs during widget validation. For image-compatible respons…
CVE-2026-45012
GitHub-GHSA

HIGH
Valtimo has sensitive data exposure through HTTP request/response logging in LoggingRestClientCustomizer
GHSA-3jh5-rr2q-xfv7
pkg: com.ritense.valtimo:web, com.ritense.valtimo:web
eco: maven
published: May 11, 2026
### Summary

The `LoggingRestClientCustomizer` in the `web` module automatically intercepts all outgoing HTTP calls made via Spring's `RestClient` and logs the full request body, response body, and response headers. When an error response is received, this information is included in the thrown `Http…

CVE-2026-44516
NVD

HIGH
CVE-2021-47942
CVE-2021-47942
pkg: jwt

published: May 16, 2026

Home Assistant Community Store (HACS) 1.10.0 contains a path traversal vulnerability that allows unauthenticated attackers to read sensitive files by traversing directories via the /hacsfiles/ endpoint. Attackers can retrieve the .storage/auth file containing user credentials and refresh tokens, the…
CWE: CWE-22
NVD

HIGH
CVE-2026-46359
CVE-2026-46359
pkg: jwt

published: May 15, 2026

phpMyFAQ before 4.1.2 contains a sql injection vulnerability in CurrentUser::setTokenData that allows authenticated attackers to execute arbitrary SQL by injecting malicious OAuth token claims. Attackers with Azure AD accounts containing SQL metacharacters in display names or JWT claims can break ou…
CWE: CWE-89
GitHub-GHSA

HIGH
Pipecat: Path Traversal in Pipecat Runner `/files` Endpoint — Arbitrary File Read via `%2F`-Encoded Separator
GHSA-3363-2ph6-35wh
pkg: pipecat-ai
eco: pip
published: May 15, 2026
## Summary

A path traversal vulnerability exists in Pipecat's development runner (`src/pipecat/runner/run.py`). When the runner is started with the `–folder` flag, it exposes a `GET /files/{filename:path}` download endpoint. The `filename` path parameter is concatenated directly onto `args.folder`…

CVE-2026-44716
GitHub-GHSA

HIGH
nimiq-keys: Unchecked Ed25519 signature length in TaggedPublicKey::verify causes remote node panic via DHT
GHSA-27w2-87xv-37c6
pkg: nimiq-keys
eco: rust
published: May 15, 2026
### Impact
A malicious network peer can crash any Nimiq full node by publishing a crafted Kademlia DHT record containing a `TaggedSigned<ValidatorRecord, KeyPair>` with a signature field whose byte length is not exactly 64. When the victim node's DHT verifier calls `TaggedSigned::verify`, execution …
CVE-2026-40092
NVD

HIGH
CVE-2026-38728
CVE-2026-38728
pkg: node

published: May 15, 2026

An issue in Nodemailer smtp_server before v.3.18.3 allows a remote attacker to cause a denial of service via the SMTPStream._write, lib/smtp-stream.js components
CWE: CWE-400
GitHub-GHSA

HIGH
Open WebUI Vulnerable to IDOR: Retrieval API Bypasses Knowledge Base Access Controls
GHSA-4g37-7p2c-38r9
pkg: open-webui
eco: pip
published: May 14, 2026
# IDOR: Retrieval API Bypasses Knowledge Base Access Controls

**Author:** Andrew Orr <aorr@tenable.com>

## Summary

`_validate_collection_access()` ([PR #22109](https://github.com/open-webui/open-webui/pull/22109)) checks the `user-memory-*` and `file-*` collection name prefixes but does not check…

CVE-2026-45398
GitHub-GHSA

HIGH
Svelte devalue: DoS via sparse array deserialization
GHSA-77vg-94rm-hx3p
pkg: devalue
eco: npm
published: May 14, 2026
`devalue.parse` could, due to quirks in some JavaScript engines, be convinced to allocate much more memory than was needed when deserializing sparse arrays, leading to excessive memory consumption.
CVE-2026-42570
NVD

HIGH
CVE-2026-8521
CVE-2026-8521
pkg: go

published: May 14, 2026

Use after free in Tab Groups in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-8510
CVE-2026-8510
pkg: go

published: May 14, 2026

Integer overflow in Skia in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-472
NVD

HIGH
CVE-2026-23998
CVE-2026-23998
pkg: fleetdm fleet

published: May 14, 2026

Fleet is open source device management software. Prior to version 4.81.0, a vulnerability in Fleet’s Windows MDM management endpoint could allow requests to be processed without proper client certificate validation. In certain circumstances, this could allow an attacker to impersonate an enrolled …
CWE: CWE-295
NVD

HIGH
CVE-2026-42594
CVE-2026-42594
pkg: docker

published: May 14, 2026

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the webhook middleware spawns a goroutine that holds a reference to the request's echo.Context after the synchronous handler returns ErrAsyncProcess and Echo recycles the context back to its sync.Pool. When a concurrent requ…
CWE: CWE-362
GitHub-GHSA

HIGH
wger Vulnerable to IDOR: Authenticated Users Can Read Any User's Private Workout Session Data via Template Routine API
GHSA-cj9g-27ph-4cgv
pkg: wger
eco: pip
published: May 14, 2026
### Summary
Any authenticated user can read another user's private workout session notes, exercise history, and training statistics by calling the /logs/ and /stats/ actions on a routine they do not own.

The RoutinePermission class grants read access to any authenticated user when a routine has is…

CVE-2026-43977
GitHub-GHSA

HIGH
FlowiseAI Exposes Basic Auth Credentials via API
GHSA-php6-83fg-gw3g
pkg: flowise
eco: npm
published: May 14, 2026
**Detection Method:** Kolega.dev Deep Code Scan

| Attribute | Value |
|—|—|
| Severity | Medium |
| CWE | CWE-522 (Insufficiently Protected Credentials) |
| Location | packages/server/src/enterprise/controllers/account.controller.ts:128-135 |
| Practical Exploitability | Medium |
| Developer Ap…

CVE-2026-46440
NVD

HIGH
CVE-2026-6479
CVE-2026-6479
pkg: ssl

published: May 14, 2026

Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket. Versions before PostgreSQL 18.…
CWE: CWE-674
GitHub-GHSA

HIGH
Fleet has a Windows MDM management endpoint authentication bypass
GHSA-2rc4-7jc6-qffh
pkg: github.com/fleetdm/fleet/v4
eco: go
published: May 14, 2026
### Summary

A vulnerability in Fleet’s Windows MDM management endpoint could allow requests to be processed without proper client certificate validation. In certain circumstances, this could allow an attacker to impersonate an enrolled Windows device and retrieve sensitive configuration data.

##…

CVE-2026-23998
NVD

HIGH
CVE-2026-42561
CVE-2026-42561
pkg: python

published: May 13, 2026

Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.27, python-multipart has a denial of service vulnerability in multipart part header parsing. When parsing multipart/form-data, MultipartParser previously had no limit on the number of part headers or the size of an individual …
CWE: CWE-770
NVD

HIGH
CVE-2026-42304
CVE-2026-42304
pkg: react

published: May 13, 2026

Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 26.4.0rc2, the twisted.names module is vulnerable to a Denial of Service (DoS) attack via resource exhaustion during DNS name decompression. A remote, unauthenticated attacker can exploit this by sending …
CWE: CWE-400, CWE-407
NVD

HIGH
CVE-2026-42582
CVE-2026-42582
pkg: express

published: May 13, 2026

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for a string literal before verifying that length byt…
CWE: CWE-770, CWE-789
NVD

HIGH
CVE-2026-45109
CVE-2026-45109
pkg: vercel next.js

published: May 13, 2026

Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.18 and 16.2.6, it was found that the fix addressing CVE-2026-44575 did not apply to middleware.ts with Turbopack. This vulnerability is fixed in 15.5.18 and 16.2.6.
CWE: CWE-288
NVD

HIGH
CVE-2026-44579
CVE-2026-44579
pkg: vercel next.js

published: May 13, 2026

Next.js is a React framework for building full-stack web applications. From to before 15.5.16 and 16.2.5, applications using Partial Prerendering through the Cache Components feature can be vulnerable to connection exhaustion through crafted POST requests to a server action. In affected configurati…
CWE: CWE-770
NVD

HIGH
CVE-2026-44004
CVE-2026-44004
pkg: vm2_project vm2

published: May 13, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, sandboxed code can call Buffer.alloc() with an arbitrary size to allocate memory directly on the host heap. Because Buffer.alloc is a synchronous C++ native call, vm2's timeout option cannot interrupt it. A single request can exhaust hos…
CWE: CWE-770
NVD

HIGH
CVE-2026-44575
CVE-2026-44575
pkg: vercel next.js

published: May 13, 2026

Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Router applications that rely on middleware or proxy-based checks for authorization can allow unauthorized access through transport-specific route variants used for segment prefetchin…
CWE: CWE-288
NVD

HIGH
CVE-2026-44573
CVE-2026-44573
pkg: vercel next.js

published: May 13, 2026

Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authorization can allow unauthorized access to protected page data through locale-less /_next/data/<bui…
CWE: CWE-863
NVD

HIGH
CVE-2026-44432
CVE-2026-44432
pkg: python urllib3

published: May 13, 2026

urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the response was decompressed using the official Brotli library or (2) when HTTPResponse.dra…
CWE: CWE-409
NVD

HIGH
CVE-2026-42920
CVE-2026-42920
pkg: ssl

published: May 13, 2026

When a Client SSL profile is configured with Allow Dynamic Record Sizing on a UDP virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.
 Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CWE: CWE-835
NVD

HIGH
CVE-2026-40629
CVE-2026-40629
pkg: ssl

published: May 13, 2026

When SSL profiles are configured on a virtual server, undisclosed traffic can cause the virtual server to stop processing new client connections.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CWE: CWE-770
NVD

HIGH
CVE-2026-40618
CVE-2026-40618
pkg: ssl

published: May 13, 2026

When an SSL profile is configured on a virtual server on BIG-IP Virtual Edition (VE) without Intel QuickAssist Technology (QAT) or on BIG-IP hardware platforms with the database variable crypto.hwacceleration set to disabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to…
CWE: CWE-131
GitHub-GHSA

HIGH
SillyTavern: Existing sessions are not invalidated after password change, allowing session reuse and account takeover
GHSA-wmm3-h9qj-p5v6
pkg: sillytavern
eco: npm
published: May 12, 2026
### Summary
Changing a user’s password does not invalidate existing sessions, allowing an attacker with a stolen cookie to retain access even after the victim resets their password.

### Details
SillyTavern relies on cookie-session for authentication, storing all session data (user handle, permiss…

CVE-2026-44648
GitHub-GHSA

HIGH
esm.sh: Path Traversal via package.json browser field allows reading arbitrary server files
GHSA-rg65-45m7-hq57
pkg: github.com/esm-dev/esm.sh
eco: go
published: May 12, 2026
### Summary

A Local File Inclusion (LFI) vulnerability exists in the esbuild plugin's handling of the `browser` field in `package.json`. An attacker can publish an npm package that causes the server to read and return arbitrary files from the host filesystem during the build process.

### Details

CVE-2026-44594
NVD

HIGH
CVE-2026-44296
CVE-2026-44296
pkg: tls

published: May 12, 2026

Deskflow is a keyboard and mouse sharing app. Prior to 1.26.0.167, a remote, unauthenticated denial of service (DoS) vulnerability affects Deskflow servers running with TLS enabled (the default). When any TCP peer connects to the listening port and its first bytes do not parse as a valid TLS ClientH…
CWE: CWE-400, CWE-405
NVD

HIGH
CVE-2026-42544
CVE-2026-42544
pkg: python

published: May 12, 2026

Granian is a Rust HTTP server for Python applications. From 1.2.0 to 2.7.4, Granian aborts a worker process when an unauthenticated client sends a WebSocket upgrade request whose Sec-WebSocket-Protocol header contains non-ASCII bytes. The crash happens in Granian's WebSocket scope construction path,…
CWE: CWE-20, CWE-248, CWE-400
NVD

HIGH
CVE-2026-42268
CVE-2026-42268
pkg: owasp modsecurity

published: May 12, 2026

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 to before 3.0.15, there is an unhandled exception (std::out_of_range) caused by unsigned integer underflow in libmodsecurity3 if the user (administrator) uses a rule any of @veri…
CWE: CWE-191, CWE-248
NVD

HIGH
CVE-2026-44240
CVE-2026-44240
pkg: node

published: May 12, 2026

basic-ftp is an FTP client for Node.js. Prior to 5.3.1, basic-ftp is vulnerable to client-side denial of service when parsing FTP control-channel multiline responses. A malicious or compromised FTP server can send an unterminated multiline response during the initial FTP banner phase, before authent…
CWE: CWE-400, CWE-770
NVD

HIGH
CVE-2026-35424
CVE-2026-35424
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Missing release of memory after effective lifetime in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network.
CWE: CWE-401
NVD

HIGH
CVE-2026-32161
CVE-2026-32161
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Native WiFi Miniport Driver allows an unauthorized attacker to execute code over an adjacent network.
CWE: CWE-362, CWE-416
GitHub-GHSA

HIGH
Dalfox has an Unauthenticated Remote DoS via Closed-Channel Write in `ParameterAnalysis` (server mode)
GHSA-2g4x-fq3j-cgq4
pkg: github.com/hahwul/dalfox/v2
eco: go
published: May 12, 2026
## Summary

`ParameterAnalysis` in `pkg/scanning/parameterAnalysis.go` runs two sequential worker stages that both write to the same `results` channel. The channel is correctly closed after the first stage completes (`close(results)` at line 438), but the second stage — which processes POST-body p…

CVE-2026-45090
GitHub-GHSA

HIGH
Dalfox Server Mode has an Unauthenticated Arbitrary File Read with Out-of-Band Exfiltration via `custom-payload-file`
GHSA-35wr-x7v6-9fv2
pkg: github.com/hahwul/dalfox/v2
eco: go
published: May 12, 2026
## Summary

When dalfox is run in REST API server mode, the `custom-payload-file` field in `model.Options` is JSON-tagged and deserialized directly from the attacker's request body, then propagated unchanged through `dalfox.Initialize` into the scan engine. The engine passes the value to `voltFile.R…

CVE-2026-45088
GitHub-GHSA

HIGH
protobuf.js: Process-wide denial of service through unsafe option paths
GHSA-jvwf-75h9-cwgg
pkg: protobufjs, protobufjs
eco: npm
published: May 12, 2026
## Summary

protobufjs allowed certain schema option paths to traverse through inherited object properties while applying options. A crafted protobuf schema or JSON descriptor could cause option handling to write to properties on global JavaScript constructors, corrupting process-wide built-in funct…

CVE-2026-44290
GitHub-GHSA

HIGH
protobuf.js: Denial of service through unbounded protobuf recursion
GHSA-685m-2w69-288q
pkg: protobufjs, protobufjs
eco: npm
published: May 12, 2026
## Summary

protobufjs could recurse without a depth limit while decoding nested protobuf data. This affected both skipping unknown group fields and generated decoding of nested message fields.

A crafted protobuf binary payload could cause the JavaScript call stack to be exhausted during decoding.

CVE-2026-44289
NVD

HIGH
CVE-2026-8159
CVE-2026-8159
pkg: pillarjs multiparty

published: May 12, 2026

multiparty@4.2.3 and lower versions are vulnerable to denial of service via regular expression backtracking in the Content-Disposition filename parameter parser. A crafted multipart upload with a long header value can cause regex matching to take seconds, blocking the event loop. Impact: any service…
CWE: CWE-1333
GitHub-GHSA

HIGH
Kysely: JSON-path traversal injection via unsanitized path-leg metacharacters in `JSONPathBuilder.key()` / `.at()`
GHSA-pv5w-4p9q-p3v2
pkg: kysely
eco: npm
published: May 11, 2026
## Summary

Kysely 0.28.12 added a `sanitizeStringLiteral()` call inside `DefaultQueryCompiler.visitJSONPathLeg` (commit `0a602bf`, PR #1727) to fix CVE-2026-32763 (`GHSA-wmrf-hv6w-mr66`). The fix only doubles single quotes (`'` → `''`); it does **not** escape JSON-path metacharacters (`.`, `[`, `…

CVE-2026-44635
NVD

HIGH
CVE-2026-33359
CVE-2026-33359
pkg: windows

published: May 11, 2026

In Meari IoT Cloud alert image storage on Alibaba OSS (latest observed; storage service version not disclosed), motion snapshots are retrievable without authentication, signed URLs, or expiry enforcement. URLs function as direct object references and remain valid beyond expected operational windows.
CWE: CWE-862
GitHub-GHSA

HIGH
Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes – Incomplete Fix Follow-Up
GHSA-26hh-7cqf-hhc6
pkg: next, next
eco: npm
published: May 11, 2026
### Impact

It was found that the fix addressing [CVE-2026-44575](https://github.com/vercel/next.js/security/advisories/GHSA-267c-6grr-h53f) did not apply to `middleware.ts` with Turbopack. Refer to [CVE-2026-44575](https://github.com/vercel/next.js/security/advisories/GHSA-267c-6grr-h53f) for fur…

CVE-2026-45109
GitHub-GHSA

HIGH
Bird-lg-go has a Fatal Out-of-Memory (OOM) Denial of Service via Unbounded JSON Decoding
GHSA-39qr-rc93-vhqm
pkg: github.com/xddxdd/bird-lg-go
eco: go
published: May 11, 2026
### Summary
The `apiHandler` (and similarly `webHandlerTelegramBot`) processes user-provided JSON payloads by directly using `json.NewDecoder(r.Body).Decode(&request)` without restricting the maximum read size. An unauthenticated remote attacker can stream an extremely large, endless JSON payload (e…
CVE-2026-45047
GitHub-GHSA

HIGH
@theecryptochad/merge-guard has Prototype Pollution in its deepMerge() function
GHSA-mhwj-73qx-jqxm
pkg: @theecryptochad/merge-guard
eco: npm
published: May 11, 2026
## Summary

`@theecryptochad/merge-guard` versions prior to 1.0.1 are vulnerable to Prototype Pollution via the `deepMerge()` function. An attacker who controls the source object can inject `__proto__` keys that mutate `Object.prototype`, affecting all objects in the Node.js runtime.

## Details

Th…

GitHub-GHSA

HIGH
Next.js vulnerable to Denial of Service via connection exhaustion in applications using Cache Components
GHSA-mg66-mrh9-m8jx
pkg: next, next
eco: npm
published: May 11, 2026
### Impact

Applications using Partial Prerendering through the Cache Components feature can be vulnerable to connection exhaustion through crafted POST requests to a server action. In affected configurations, a malicious request can trigger a request-body handling deadlock that leaves connections o…

CVE-2026-44579
GitHub-GHSA

HIGH
Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes
GHSA-267c-6grr-h53f
pkg: next, next
eco: npm
published: May 11, 2026
### Impact

App Router applications that rely on middleware or proxy-based checks for authorization can allow unauthorized access through transport-specific route variants used for segment prefetching. In affected configurations, specially crafted `.rsc` and segment-prefetch URLs can resolve to the …

CVE-2026-44575
GitHub-GHSA

HIGH
urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API
GHSA-mf9v-mfxr-j63j
pkg: urllib3
eco: pip
published: May 11, 2026
### Impact

urllib3's [streaming API](https://urllib3.readthedocs.io/en/2.7.0/advanced-usage.html#streaming-and-i-o) is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once.

urllib3 can perform…

CVE-2026-44432
GitHub-GHSA

HIGH
PraisonAI's symlink-extraction bypass of `_safe_extractall` writes outside `dest_dir`
GHSA-9q28-ghcr-c4x3
pkg: PraisonAI
eco: pip
published: May 11, 2026
### Summary
The `_safe_extractall` helper that all `recipe pull`, `recipe publish`, and `recipe unpack` flows route through validates each archive member's `name` for absolute paths, `..` segments, and resolved-path escape — but does **not** validate `member.linkname`, does not reject symlink/hard…
CVE-2026-44340
GitHub-GHSA

HIGH
Improper Verification of Cryptographic Signature in com.oviva.telematik:epa4all-client
GHSA-gqx7-6552-67hf
pkg: com.oviva.telematik:epa4all-client
eco: maven
published: May 15, 2026
### Impact
An attacker who can MITM the TLS connection between the client and the IDP (within the TI network) can substitute a forged discovery document. The forged document redirects u ri_puk_idp_enc and uri_puk_idp_sig to attacker-controlled URLs. The client then encrypts the SMC-B-signed challeng…
CVE-2026-45575
GitHub-GHSA

HIGH
goshs: SSH host key verification disabled, allowing transparent MITM of every tunnelled HTTP request
GHSA-mxg3-432p-mr72
pkg: goshs.de/goshs/v2
eco: go
published: May 15, 2026
### Summary

The `–tunnel` / `-t` flag opens an outbound SSH connection to `localhost.run:22` with `HostKeyCallback: ssh.InsecureIgnoreHostKey()`. The Go documentation for that function states verbatim: *"It should not be used for production code."* With the callback disabled the client accepts any…

GitHub-GHSA

HIGH
DeepSeek TUI has SSRF‌ IPV6 bypass
GHSA-88gh-2526-gfrr
pkg: deepseek-tui
eco: rust
published: May 14, 2026
### Summary
Although SSRF is validated against hostnames that resolve to private IPv6 addresses, when providing the IPV6 in‌‌ URL‌ as `http://[::1]`, the SSRF defenses do not work.

### Details
https://github.com/Hmbown/DeepSeek-TUI/blob/15f62e3e93d842f30b428877819ebc1c8cb96814/crates/tui/src/…

CVE-2026-45373
GitHub-GHSA

HIGH
DeepSeek TUI has SSRF via HTTP Redirect Bypass in fetch_url Tool
GHSA-96ff-gc8g-wpvg
pkg: deepseek-tui, deepseek-tui-cli, deepseek-tui
eco: npm
published: May 14, 2026
### Summary
The `fetch_url` tool validates the initial URL's resolved IP address against a restricted-IP blocklist (`is_restricted_ip()`) to prevent SSRF attacks against internal services (cloud metadata endpoints, localhost, private networks). However, the HTTP client (`reqwest`) is configured to a…
CVE-2026-45310
NVD

HIGH
CVE-2026-8759
CVE-2026-8759
pkg: express

published: May 17, 2026

A vulnerability was identified in xiandafu beetl up to 3.20.2. Affected is an unknown function of the file beetl-classic-integration/beetl-spring-classic/src/main/java/org/beetl/ext/spring/SpELFunction.java of the component SpELFunction. The manipulation leads to improper neutralization of special e…
CWE: CWE-20, CWE-917
GitHub-GHSA

HIGH
Better Auth: Rate limiter keys IPv6 addresses individually and is bypassable via prefix rotation
GHSA-p6v2-xcpg-h6xw
pkg: better-auth, better-auth
eco: npm
published: May 15, 2026
### Am I affected?

Users are affected if all of the following are true:

– Their app uses `better-auth` at a version `< 1.4.17`, or at a v1.5 prerelease tagged `<= 1.5.0-beta.8`.
– The apps authentication endpoints serve clients reachable over IPv6. Most managed hosts including Cloudflare, Vercel, …

CVE-2026-45364
GitHub-GHSA

HIGH
Open WebUI vulnerable to stored XSS via OAuth picture claim stored as SVG data URI in profile_image_url
GHSA-3wgj-c2hg-vm6q
pkg: open-webui
eco: pip
published: May 14, 2026
# Summary

When a user signs in via OAuth, Open WebUI fetches the `picture` claim URL, infers a MIME type from the URL extension via `mimetypes.guess_type`, and stores `data:<mime>;base64,…` as the user's profile image. The OAuth code path does not go through the `validate_profile_image_url` Pydan…

GitHub-GHSA

HIGH
Apostrophe has stored XSS via javascript: URL in Image Widget Link
GHSA-5f64-7vfc-rcx6
pkg: apostrophe
eco: npm
published: May 14, 2026
### Summary
A stored cross-site scripting vulnerability was identified in the image widget functionality. A user with the Editor role can configure an image widget link to use a javascript: URL payload.

Because editors have permission to publish pages, the malicious widget can be published to the l…

CVE-2026-45011
NVD

HIGH
CVE-2026-44995
CVE-2026-44995
pkg: openclaw openclaw

published: May 11, 2026

OpenClaw before 2026.4.20 contains an improper environment variable validation vulnerability in MCP stdio server configuration that allows attackers to execute arbitrary code. Malicious workspace configurations can pass dangerous startup variables like NODE_OPTIONS, LD_PRELOAD, or BASH_ENV to spawne…
CWE: CWE-829
NVD

HIGH
CVE-2026-31254
CVE-2026-31254
pkg: python

published: May 11, 2026

The flash-attention project thru commit e724e2588cbe754beb97cf7c011b5e7e34119e62 (2025-13-04) contains a code injection vulnerability (CWE-94) in its training script. The script registers the Python eval() function as a Hydra configuration resolver under the name eval. This allows configuration file…
CWE: CWE-95
NVD

HIGH
CVE-2026-31253
CVE-2026-31253
pkg: python

published: May 11, 2026

The flash-attention training framework thru commit e724e2588cbe754beb97cf7c011b5e7e34119e62 (2025-13-04) contains an insecure deserialization vulnerability (CWE-502) in its checkpoint loading mechanism. The load_checkpoint() function in checkpoint.py and the checkpoint loading code in eval.py use to…
CWE: CWE-94, CWE-502
NVD

HIGH
CVE-2026-31251
CVE-2026-31251
pkg: python

published: May 11, 2026

CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its gRPC server component. When the server starts, it loads the speech synthesis model from a user-specified directory using torch.load() without enabling the w…
CWE: CWE-20, CWE-94, CWE-915
NVD

HIGH
CVE-2026-31250
CVE-2026-31250
pkg: python

published: May 11, 2026

CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its average_model.py model averaging tool. The script loads PyTorch checkpoint files (epoch_*.pt) for model averaging using torch.load() without enabling the we…
CWE: CWE-502
NVD

HIGH
CVE-2026-31249
CVE-2026-31249
pkg: python

published: May 11, 2026

CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its make_parquet_list.py data processing tool. The script loads PyTorch .pt files (utterance embeddings, speaker embeddings, speech tokens) using torch.load() w…
CWE: CWE-502
GitHub-GHSA

HIGH
PraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow execution
GHSA-6rmh-7xcm-cpxj
pkg: PraisonAI
eco: pip
published: May 11, 2026
### Summary
PraisonAI ships a legacy Flask API server with authentication disabled by default. When that server is used, any caller that can reach it can access `/agents` and trigger the configured `agents.yaml` workflow through `/chat` without providing a token.

### Details
The vulnerable server i…

CVE-2026-44338
GitHub-GHSA

HIGH
Open WebUI: Missing `workspace.tools` Authorization Check on Tool Update Endpoint Allows Privilege Escalation to Code Execution
GHSA-p4fx-23fq-jfg6
pkg: open-webui
eco: npm
published: May 14, 2026
### Summary

The tool update endpoint (`POST /api/v1/tools/id/{id}/update`) is missing the `workspace.tools` permission check that is present on the tool create endpoint. This allows a user who has been explicitly **denied** tool management capabilities ( and who the administrator considers **untrus…

CVE-2026-45395
NVD

HIGH
CVE-2026-8597
CVE-2026-8597
pkg: python

published: May 14, 2026

Missing integrity verification in the Triton inference handler in Amazon SageMaker Python SDK v2 before v2.257.2 and v3 before v3.8.0 might allow a remote authenticated actor to achieve code execution in inference containers via replacement of model artifacts in S3 with a specially crafted pickle pa…
CWE: CWE-354
NVD

HIGH
CVE-2026-8596
CVE-2026-8596
pkg: python

published: May 14, 2026

Cleartext storage of sensitive information in the ModelBuilder/Serve component in Amazon SageMaker Python SDK before v2.257.2 and v3 before v3.8.0 might allow a remote authenticated actor to extract the HMAC signing key from SageMaker API responses and forge valid integrity signatures for specially …
CWE: CWE-312
GitHub-GHSA

HIGH
Open WebUI: Low-privilege authenticated users can enumerate and stop global background tasks, causing system-wide chat disruption
GHSA-8jjp-r2w2-4v22
pkg: open-webui
eco: pip
published: May 14, 2026
### Summary
Any authenticated user with low privileges can enumerate active background tasks across the system and stop tasks belonging to other users via the GET /api/tasks and POST /api/tasks/stop/{task_id} methods. This allows a casual user to disrupt system-wide chat usage by continuously cancel…
CVE-2026-45399
GitHub-GHSA

HIGH
Open WebUI's chat completion API allows tool restrictions to be bypassed
GHSA-4pcg-253r-rf9w
pkg: open-webui
eco: pip
published: May 14, 2026
### Summary
Open WebUI v0.6.43 contains a vulnerability in its chat completion API, which allows attackers to bypass tool restrictions, potentially enabling unauthorized actions or access.

### Details
In the [chat_completion](https://github.com/open-webui/open-webui/blob/a7271532f8a38da46785afcaa7…

CVE-2026-45350
GitHub-GHSA

HIGH
Open WebUI has Broken Access Control for Completions API
GHSA-gfm2-xm6c-37qc
pkg: open-webui
eco: pip
published: May 14, 2026
### Summary
Any user `X` can continue the conversation of any other user `Y`, as long as the Chat ID of `Y` is known. User `X` does not even need to be an admin to do so.

### Details
A user just needs to use the API endpoint: `/api/chat/completions` with their own API key (generated in OWUI) and t…

CVE-2026-45349
NVD

HIGH
CVE-2026-44637
CVE-2026-44637
pkg: saitoha libsixel

published: May 14, 2026

libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, a signed integer overflow in the SIXEL parser's image-buffer doubling loop can lead to an out-of-bounds heap write in sixel_decode_raw_impl. context->pos_x grows by repeat_count on every sixel character…
CWE: CWE-190, CWE-787, CWE-787
GitHub-GHSA

HIGH
Nautobot: GitRepository.current_head field should not be writable through REST API
GHSA-p3hx-pwf3-j8wr
pkg: nautobot, nautobot
eco: pip
published: May 13, 2026
### Impact

A user with access to add/change a GitRepository record could use the REST API to directly set the `current_head` field on the record, which was not intended to be user-editable. Doing so could cause Nautobot's local clone(s) of the relevant repository to checkout a commit other than the…

CVE-2026-44798
GitHub-GHSA

HIGH
LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning
GHSA-3644-q5cj-c5c7
pkg: langsmith, langsmith, langchain-classic
eco: npm
published: May 13, 2026
## Description

The LangSmith SDK's prompt pull methods (`pull_prompt` / `pull_prompt_commit` in Python, `pullPrompt` / `pullPromptCommit` in JS/TS) fetch and deserialize prompt manifests from the LangSmith Hub. These manifests may contain serialized LangChain objects and model configuration that af…

CVE-2026-45134
NVD

HIGH
CVE-2026-5371
CVE-2026-5371
pkg: oauth

published: May 12, 2026

The MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability checks on the get_ads_access_token() and reset_experience() functions in all versions up to, and i…
CWE: CWE-862
NVD

HIGH
CVE-2026-45226
CVE-2026-45226
pkg: node

published: May 12, 2026

Heym before 0.0.21 contains an authorization bypass vulnerability in workflow execution that allows authenticated users to execute arbitrary workflows by referencing victim workflow UUIDs without proper access validation. Attackers can create workflows with execute nodes or agent subWorkflowIds poin…
CWE: CWE-863
GitHub-GHSA

HIGH
Ella Core Vulnerable to UE Downlink Redirection via Forged PDUSessionResourceSetupResponse
GHSA-qfxw-v8qx-vj3v
pkg: github.com/ellanetworks/core
eco: go
published: May 11, 2026
## Summary

A radio with a valid NG Setup can send a forged PDUSessionResourceSetupResponse carrying any UE's AMF-UE-NGAP-ID. Ella Core does not verify the message arrived on the SCTP association bound to that UE's logical NG-connection, then creates a GTP tunnel towards that radio.

## Impact

Down…

CVE-2026-44473
GitHub-GHSA

HIGH
Open WebUI's Insecure Message Access Breaks Authorization
GHSA-jxwr-g6r6-j3fx
pkg: open-webui
eco: pip
published: May 11, 2026
### Description

There's an IDOR in the channels message management system that allows authenticated users to modify or delete any message within channels they have read access to. The vulnerability exists in the message update and delete endpoints, which implement channel-level authorization but co…

CVE-2026-44569
NVD

HIGH
CVE-2026-35416
CVE-2026-35416
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CWE: CWE-416
NVD

HIGH
CVE-2026-34347
CVE-2026-34347
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Use after free in Windows Win32K – GRFX allows an authorized attacker to elevate privileges locally.
CWE: CWE-416
NVD

HIGH
CVE-2026-34345
CVE-2026-34345
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CWE: CWE-362, CWE-416
NVD

HIGH
CVE-2026-34342
CVE-2026-34342
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.
CWE: CWE-362
NVD

HIGH
CVE-2026-34341
CVE-2026-34341
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Double free in Windows Link-Layer Discovery Protocol (LLDP) allows an authorized attacker to elevate privileges locally.
CWE: CWE-415
NVD

HIGH
CVE-2026-34340
CVE-2026-34340
pkg: microsoft windows_10_1809, microsoft windows_10_21h2, microsoft windows_10_22h2

published: May 12, 2026

Use after free in Windows Projected File System allows an authorized attacker to elevate privileges locally.
CWE: CWE-416
NVD

HIGH
CVE-2026-34331
CVE-2026-34331
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K – GRFX allows an authorized attacker to elevate privileges locally.
CWE: CWE-362, CWE-416
NVD

HIGH
CVE-2026-33839
CVE-2026-33839
pkg: microsoft windows_10_1809, microsoft windows_10_21h2, microsoft windows_10_22h2

published: May 12, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K – GRFX allows an authorized attacker to elevate privileges locally.
CWE: CWE-362
NVD

HIGH
CVE-2026-7818
CVE-2026-7818
pkg: python

published: May 11, 2026

Deserialization of untrusted data (CWE-502) in pgAdmin 4 FileBackedSessionManager.

The session manager performed unsafe deserialization of session-file contents (using Python's standard object-serialization module) before performing any HMAC integrity check. Any file dropped into the sessions direc…

CWE: CWE-502
GitHub-GHSA

HIGH
urllib3: Sensitive headers forwarded across origins in proxied low-level redirects
GHSA-qccp-gfcp-xxvc
pkg: urllib3
eco: pip
published: May 11, 2026
### Impact

When following cross-origin redirects for requests made using urllib3’s high-level APIs, such as `urllib3.request()`, `PoolManager.request()`, and `ProxyManager.request()`, sensitive headers — `Authorization`, `Cookie`, and `Proxy-Authorization` (defined in `Retry.DEFAULT_REMOVE_HEAD…

CVE-2026-44431
GitHub-GHSA

HIGH
Open WebUI has XSS via SVG in /api/v1/channels/webhooks/{webhook_id}/profile/image
GHSA-3856-3vxq-m6fc
pkg: open-webui
eco: pip
published: May 14, 2026
As part of our research on improving our [AI pentest](https://www.aikido.dev/attack/aipentest), we have uncovered the following issue in Open WebUI. We've manually verified and tided up the report, but you can also find the original agent finding at the bottom of this report.

### Summary

The chann…

CVE-2026-45314
GitHub-GHSA

HIGH
ethyca-fides has a DOM-based XSS vulnerability in fides.js via fides_description override
GHSA-5qrq-9645-g5g2
pkg: ethyca-fides
eco: pip
published: May 14, 2026
### Summary

`fides.js` is the script that renders Fides's consent banner on customer websites. It lets the embedding page override the banner's description text at runtime via a URL query parameter, a JavaScript global, or a cookie. On sites that have opted into HTML-formatted descriptions, the ove…

CVE-2026-44541
GitHub-GHSA

HIGH
Karakeep SDK has SSRF via metascraper-logo-favicon that bypasses validateUrl protections
GHSA-7rx4-c5vx-g8w3
pkg: @karakeep/sdk
eco: npm
published: May 14, 2026
## Summary

The `metascraper-logo-favicon` plugin makes HTTP requests to URLs extracted from attacker-controlled HTML without going through the application's `validateUrl()` SSRF protections. This allows any authenticated user to make the server fetch arbitrary internal URLs by bookmarking a page co…

GitHub-GHSA

HIGH
Portainer: JWT accepted in URL query leaks tokens to logs and referers
GHSA-jvp4-q659-95mj
pkg: github.com/portainer/portainer, github.com/portainer/portainer, github.com/portainer/portainer
eco: go
published: May 14, 2026
## Summary
Portainer's authentication middleware accepts JWT bearer tokens passed as the `?token=<JWT>` URL query parameter on any authenticated API endpoint, in addition to the standard `Authorization: Bearer` header. URLs are recorded in reverse-proxy access logs, browser history, and HTTP `Refere…
CVE-2026-44883
GitHub-GHSA

HIGH
Portainer Has an Arbitrary File Read via Git Symlink Injection in Stack Auto-Update
GHSA-rpgq-m5fp-32wr
pkg: github.com/portainer/portainer, github.com/portainer/portainer, github.com/portainer/portainer
eco: go
published: May 14, 2026
## Summary
Portainer supports deploying stacks from Git repositories. When a Git-backed stack is created or updated, Portainer clones the repository using `go-git` v5, which translates Git blob entries with mode `0o120000` (symlink) into real OS symlinks on the host filesystem via `os.Symlink`. The …
CVE-2026-44881
GitHub-GHSA

HIGH
FlowiseAI: Evaluator create+update mass-assignment allows cross-workspace evaluator takeover
GHSA-wxrr-jp8m-qq7f
pkg: flowise
eco: npm
published: May 14, 2026
## Summary

**Type:** Mass assignment via `Object.assign(entity, body)` -> client-controlled `workspaceId` (and on create, `id`) overwritten on the Evaluator entity -> cross-workspace data takeover and IDOR.
**File:** `packages/server/src/Interface.Evaluation.ts`
**Root cause:** The Evaluator contro…

CVE-2026-46480
GitHub-GHSA

HIGH
FlowiseAI: Evaluation create+update mass-assignment allows cross-workspace evaluation takeover
GHSA-mq53-pc65-wjc4
pkg: flowise
eco: npm
published: May 14, 2026
## Summary

**Type:** Mass assignment via `Object.assign(entity, body)` -> client-controlled `workspaceId` (and on create, `id`) overwritten on the Evaluation entity -> cross-workspace data takeover and IDOR.
**File:** `packages/server/src/services/evaluations/index.ts`
**Root cause:** The Evaluatio…

CVE-2026-46479
GitHub-GHSA

HIGH
FlowiseAI: DatasetRow create+update mass-assignment allows cross-workspace row takeover
GHSA-7j65-65cr-6644
pkg: flowise
eco: npm
published: May 14, 2026
## Summary

**Type:** Mass assignment via `Object.assign(entity, body)` -> client-controlled `workspaceId` (and on create, `id`) overwritten on the DatasetRow entity -> cross-workspace data takeover and IDOR.
**File:** `packages/server/src/services/dataset/index.ts`
**Root cause:** The DatasetRow co…

CVE-2026-46478
GitHub-GHSA

HIGH
FlowiseAI: Dataset create+update mass-assignment allows cross-workspace dataset takeover
GHSA-5h9v-837x-m97r
pkg: flowise
eco: npm
published: May 14, 2026
## Summary

**Type:** Mass assignment via `Object.assign(entity, body)` -> client-controlled `workspaceId` (and on create, `id`) overwritten on the Dataset entity -> cross-workspace data takeover and IDOR.
**File:** `packages/server/src/services/dataset/index.ts`
**Root cause:** The Dataset controll…

CVE-2026-46477
GitHub-GHSA

HIGH
FlowiseAI: CustomTemplate create+update mass-assignment allows cross-workspace template takeover
GHSA-728h-4mwj-f2p4
pkg: flowise
eco: npm
published: May 14, 2026
## Summary

**Type:** Mass assignment via `Object.assign(entity, body)` -> client-controlled `workspaceId` (and on create, `id`) overwritten on the CustomTemplate entity -> cross-workspace data takeover and IDOR.
**File:** `packages/server/src/services/marketplaces/index.ts`
**Root cause:** The Cust…

CVE-2026-46476
GitHub-GHSA

HIGH
FlowiseAI: Assistant create+update mass-assignment allows cross-workspace assistant takeover
GHSA-78pr-c5x5-jggc
pkg: flowise
eco: npm
published: May 14, 2026
## Summary

**Type:** Mass assignment via `Object.assign(entity, body)` -> client-controlled `workspaceId` (and on create, `id`) overwritten on the Assistant entity -> cross-workspace data takeover and IDOR.
**File:** `packages/server/src/services/assistants/index.ts`
**Root cause:** The Assistant c…

CVE-2026-46475
GitHub-GHSA

HIGH
FlowiseAI: Vector Store No Permission Checks
GHSA-hmg2-jjjx-jcp2
pkg: flowise
eco: npm
published: May 14, 2026
### FINDING 4: OpenAI Assistants Vector Store – No Auth on CRUD Operations
**Severity**: HIGH (CVSS ~8.1)
**Type**: CWE-306 (Missing Authentication for Critical Function)
**File**: `packages/server/src/routes/openai-assistants-vector-store/index.ts`

**Description**: ALL CRUD endpoints for OpenAI As…

CVE-2026-46444
GitHub-GHSA

HIGH
Synapse CPU starvation (Denial of Service)
GHSA-8q93-326v-3m7g
pkg: matrix-synapse
eco: pip
published: May 14, 2026
### Impact

Local authenticated users can cause Synapse to starve other requests of CPU and lead to other requests failing, causing other users to be denied service.

Homeservers that trust all their local users are not at risk.

### Patches

Update to Synapse 1.152.1 or later.

### Workarounds

If …

CVE-2026-45078
GitHub-GHSA

HIGH
n8n Has a Cross-user Authorization Bypass in Dynamic Credential OAuth Endpoints
GHSA-6h4j-wcr9-2vg7
pkg: n8n, n8n, n8n
eco: npm
published: May 14, 2026
## Impact
The OAuth1 and OAuth2 credential reconnect endpoints authorized access using `credential:read` rather than `credential:update`. An authenticated user with read-only access to a shared credential could initiate an OAuth reconnect flow and overwrite the stored token material for that credent…
CVE-2026-45732
GitHub-GHSA

HIGH
n8n Has a Source Control Pull SQL Injection
GHSA-mhrx-qhrj-673w
pkg: n8n, n8n, n8n
eco: npm
published: May 14, 2026
## Impact
An attacker with write access to the git repository connected to an n8n Source Control configuration could commit a malicious Data Table JSON file containing a crafted column name. When an administrator performed a Source Control Pull, n8n imported the file and could lead to SQL injection …
CVE-2026-44792
GitHub-GHSA

HIGH
FlowiseAI Vulnerable to Credential Data Leak
GHSA-7g73-99r4-m4mj
pkg: flowise
eco: npm
published: May 14, 2026
**Severity**: HIGH (CVSS ~7.5)
**Type**: CWE-200 (Exposure of Sensitive Information)
**File**: `packages/server/src/services/credentials/index.ts:62-71`

**Description**: When credentials are fetched with a `credentialName` filter parameter, the `encryptedData` field is NOT stripped from the respons…

CVE-2026-46443
GitHub-GHSA

HIGH
FlowiseAI has Mass Assignment in Assistant Update Endpoint that Allows Cross-Workspace Resource Reassignment
GHSA-hp26-q66v-q2w7
pkg: flowise
eco: npm
published: May 14, 2026
### Summary
A Mass Assignment vulnerability exists in the assistant update endpoint of FlowiseAI.

The endpoint allows authenticated users to modify server-controlled properties such as workspaceId, createdDate, and updatedDate when updating an assistant resource.

Due to missing server-side validat…

CVE-2026-46441
GitHub-GHSA

HIGH
Flowise has an MCP Security Bypass that Enables RCE
GHSA-m99r-2hxc-cp3q
pkg: flowise, flowise-components
eco: npm
published: May 14, 2026
## Summary
There are three bypass methods for the security limitations of the Flowise MCP feature, and attackers can execute arbitrary commands by combining these three methods

## Details

### 【Vulnerability one】The Docker build subcommand not being on the blocklist leads to remote code execu…

GitHub-GHSA

HIGH
FlowiseAI has Mass Assignment in Chatflow Update Endpoint that Allows Cross-Workspace AgentFlow Reassignment
GHSA-5wxp-qjgq-fx6m
pkg: flowise
eco: npm
published: May 14, 2026
### Summary
A Mass Assignment vulnerability exists in the chatflow update endpoint of FlowiseAI.

The endpoint allows clients to modify server-controlled properties such as deployed, isPublic, workspaceId, createdDate, and updatedDate when updating a chatflow object.

Due to missing server-side vali…

CVE-2026-42863
GitHub-GHSA

HIGH
FlowiseAI has Mass Assignment in Tool Update Endpoint that Allows Cross-Workspace Resource Reassignment
GHSA-x5v6-pj28-cwwm
pkg: flowise
eco: npm
published: May 14, 2026
### Summary
A Mass Assignment vulnerability exists in the tool update endpoint of FlowiseAI.

The endpoint allows authenticated users to modify server-controlled properties such as workspaceId, createdDate, and updatedDate when updating a tool resource.

Due to missing server-side validation and aut…

CVE-2026-42862
GitHub-GHSA

HIGH
FlowiseAI has Mass Assignment in Variable Update Endpoint that Allows Cross-Workspace Resource Reassignment
GHSA-6fw7-3q8r-m5vj
pkg: flowise
eco: npm
published: May 14, 2026
### Summary
A Mass Assignment vulnerability exists in the variable update endpoint of FlowiseAI.

The endpoint allows authenticated users to modify server-controlled properties such as workspaceId, createdDate, and updatedDate when updating a variable resource.

Due to missing server-side validation…

CVE-2026-42861
GitHub-GHSA

HIGH
Fleet server may terminate unexpectedly when handling certain gRPC requests
GHSA-x67p-9m2r-fxqv
pkg: github.com/fleetdm/fleet/v4
eco: go
published: May 14, 2026
### Summary

Fleet contained a denial-of-service (DoS) issue in the gRPC Launcher `PublishLogs` endpoint. In affected versions, certain unexpected input values were not handled gracefully, which could cause the Fleet server process to terminate while processing an authenticated request from an enrol…

CVE-2026-26062
GitHub-GHSA

HIGH
Fleet Windows MDM Azure AD JWT Authentication Bypass
GHSA-ffg9-j72f-j6xm
pkg: github.com/fleetdm/fleet/v4
eco: go
published: May 14, 2026
### Summary

A vulnerability in Fleet's Windows MDM enrollment flow allows authentication tokens from any Azure AD tenant to be accepted. Because Fleet validates JWT signatures using Microsoft's multi-tenant JWKS endpoint but does not enforce the `aud` (audience) or `iss` (issuer) claims, any Micros…

CVE-2026-24899
GitHub-GHSA

HIGH
SiYuan publish-mode Reader can mutate Conf and SQL index via 8 ungated APIs
GHSA-gmmv-4cc5-wr9r
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: May 13, 2026
### Summary

SiYuan publish-mode Reader can mutate Conf and SQL index via 8 ungated APIs

`POST /api/graph/getGraph`, `POST /api/graph/getLocalGraph`, `POST /api/sync/setSyncInterval`, `POST /api/storage/updateRecentDocViewTime`, `POST /api/storage/updateRecentDocCloseTime`, `POST /api/storage/updat…

CVE-2026-45371
GitHub-GHSA

HIGH
Anchor: `InterfaceAccount` allows account substitution between unexpected types
GHSA-429q-fhh4-r6hj
pkg: anchor-lang
eco: rust
published: May 13, 2026
### Impact
Any uses of `InterfaceAccount` allows another unexpected account type to be passed, after https://github.com/solana-foundation/anchor/pull/3837 disabled discriminator checking for this type.

The bug was originally reported and fixed in https://github.com/solana-foundation/anchor/pull/413…

GitHub-GHSA

HIGH
claude-code-cache-fix vulnerable to local code execution via Python triple-quote injection in tools/quota-statusline.sh
GHSA-g3xq-3gmv-qq8g
pkg: claude-code-cache-fix
eco: npm
published: May 13, 2026
## Summary

`tools/quota-statusline.sh` (introduced in v3.5.0) interpolates Claude Code's hook stdin payload directly into a Python triple-quoted string literal. A `'''` byte sequence in any user-controlled field of the payload closes the literal early and lets following bytes execute as Python in t…

CVE-2026-45136
GitHub-GHSA

HIGH
UltraJSON has a Memory Leak in ujson.dump() on Write Failure
GHSA-c38f-wx89-p2xg
pkg: ujson
eco: pip
published: May 12, 2026
### Summary

When `ujson.dump()` writes to a file-like object and the write operation raises an exception, the serialized JSON string object is not decremented, leaking memory. Each failed write operation leaks the full size of the serialized payload.

Code that uses `ujson.dumps()` rather than `ujs…

CVE-2026-44660
GitHub-GHSA

HIGH
protobuf.js: Code injection through bytes field defaults in generated toObject code
GHSA-66ff-xgx4-vchm
pkg: protobufjs, protobufjs
eco: npm
published: May 12, 2026
## Summary

protobufjs generated JavaScript for `toObject` conversion could include an unsafe expression derived from a schema-controlled `bytes` field default value. A crafted descriptor with a non-string default value for a `bytes` field could cause attacker-controlled code to be emitted into the …

CVE-2026-44293
GitHub-GHSA

HIGH
GitHub Copilot CLI: Nested Bare Repository Can Execute Arbitrary Commands via core.fsmonitor
GHSA-9ccr-r5hg-74gf
pkg: @github/copilot
eco: npm
published: May 11, 2026
## Summary

A security vulnerability has been identified in GitHub Copilot CLI where a malicious bare git repository nested inside a project directory can achieve arbitrary code execution when the agent performs git operations. By exploiting git's automatic bare repository discovery during directory…

CVE-2026-45033
GitHub-GHSA

HIGH
python-liquid: Absolute paths escape filesystem loader search path
GHSA-8p4x-wr7x-3788
pkg: python-liquid
eco: pip
published: May 11, 2026
### Impact
The built-in `FileSystemLoader` and `CachingFileSystemLoader` do not guard against reading files outside their search paths when given an absolute path to resolve. This allows malicious template authors to load and render arbitrary files via the `{% include %}` and `{% render %}` tags. Ta…
CVE-2026-45017
GitHub-GHSA

HIGH
go-git's improper parsing of specially crafted objects may lead to inconsistent interpretation compared to upstream Git
GHSA-389r-gv7p-r3rp
pkg: github.com/go-git/go-git/v6, github.com/go-git/go-git/v5
eco: go
published: May 11, 2026
### Impact
`go-git` may parse malformed Git objects in a way that differs from upstream Git. When `commit` or `tag` objects contain ambiguous or malformed headers, `go-git`’s decoded representation may expose values differently from how Git itself would interpret or reject the same object.

Additi…

CVE-2026-45022
GitHub-GHSA

HIGH
Dozzle's Cross-Site WebSocket Hijacking (CSWSH) on exec/attach endpointsbypasses authentication
GHSA-j643-x8pv-8m67
pkg: github.com/amir20/dozzle
eco: go
published: May 11, 2026
## Summary

The WebSocket upgrader for the `/exec` and `/attach` endpoints uses `CheckOrigin: func(r *http.Request) bool { return true }`, accepting upgrade requests from any origin. Combined with the JWT cookie using `SameSite: Lax`, this enables Cross-Site WebSocket Hijacking (CSWSH) — **even wh…

CVE-2026-44985
NVD

MEDIUM
CVE-2026-1322
CVE-2026-1322
pkg: gitlab gitlab

published: May 14, 2026

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.0 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with a read_api scoped OAuth application to create issues and add comments to issues in private projects due to …
CWE: CWE-840
NVD

MEDIUM
CVE-2026-44305
CVE-2026-44305
pkg: tls

published: May 12, 2026

Lemur manages TLS certificate creation. Prior to 1.9.0, when LDAP TLS is enabled (LDAP_USE_TLS = True), Lemur's LDAP authentication module unconditionally disables TLS certificate verification at the global ldap module level. This allows a man-in-the-middle attacker positioned between Lemur and the …
CWE: CWE-295
NVD

MEDIUM
CVE-2026-33603
CVE-2026-33603
pkg: tls

published: May 12, 2026

Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This requires that the attacker is able to position itself between Dovecot and the client connection. If successful, the attacker can eavesdrop communications between Dovecot and client…
CWE: CWE-99
NVD

MEDIUM
CVE-2026-43875
CVE-2026-43875
pkg: oauth

published: May 11, 2026

WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/MobileManager/oauth2.php completes an OAuth login by sending an HTTP 302 Location: oauth2Success.php?user=<email>&pass=<HASH> where <HASH> is the victim's stored password hash (md5(hash("whirlpool", sha1(passw…
CWE: CWE-598
NVD

MEDIUM
CVE-2026-42312
CVE-2026-42312
pkg: pyload-ng_project pyload-ng

published: May 11, 2026

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API method (@permission(Perms.SETTINGS)) in src/pyload/core/api/__init__.py gates security-sensitive options behind a hand-maintained allowlist ADMIN_ONLY_CORE_OPTIONS. The option ("g…
CWE: CWE-295, CWE-306, CWE-863
NVD

MEDIUM
CVE-2026-32170
CVE-2026-32170
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Double free in Windows Rich Text Edit Control allows an authorized attacker to elevate privileges locally.
CWE: CWE-415
NVD

MEDIUM
CVE-2026-21530
CVE-2026-21530
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.
CWE: CWE-415
NVD

MEDIUM
CVE-2026-20905
CVE-2026-20905
pkg: intel quickassist_technology

published: May 12, 2026

Improper input validation for some Intel(R) QAT software drivers for Windows before version 2.6 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result m…
CWE: CWE-20
NVD

MEDIUM
CVE-2026-20782
CVE-2026-20782
pkg: intel quickassist_technology

published: May 12, 2026

Buffer overflow for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potent…
CWE: CWE-120
NVD

MEDIUM
CVE-2026-20717
CVE-2026-20717
pkg: intel quickassist_technology

published: May 12, 2026

Improper input validation for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result …
CWE: CWE-20
NVD

MEDIUM
CVE-2026-39052
CVE-2026-39052
pkg: express

published: May 15, 2026

Oinone Pamirs 7.0.0 contains a code execution vulnerability via ScriptRunner. The method ScriptRunner.run(String expression, String type, Map<String, Object> context) evaluates attacker-controlled script expressions through the underlying script engine without sandboxing or allowlist restrictions.
CWE: CWE-94
GitHub-GHSA

MEDIUM
Open WebUI: Unauthenticated endpoint can trigger embedding generation (cost/DoS)
GHSA-m69w-p7m4-585j
pkg: open-webui
eco: pip
published: May 14, 2026
### Summary
GET `/api/v1/memories/ef` is accessible without authentication and executes `request.app.state.EMBEDDING_FUNCTION(…)`. This allows any unauthenticated caller to trigger embedding generation which can lead to direct cost exposure if a paid provider is used.
Code reference: `backend/open…
CVE-2026-45667
GitHub-GHSA

MEDIUM
Open WebUI has an Indirect Object Reference (IDOR) in user notes
GHSA-x3qm-p8hr-3c3h
pkg: open-webui
eco: pip
published: May 14, 2026
### Summary
The API /api/v1/notes/{note_id} endpoint lacks proper authorization checks, allowing authenticated users to retrieve notes belonging to other users by guessing or enumerating UUIDs. This results in unauthorized disclosure of potentially sensitive or private user data.

### Details
– if …

CVE-2026-45666
GitHub-GHSA

MEDIUM
Open WebUI Exposes System Prompt to Regular User [Non-Admin]
GHSA-jh9g-8jqw-m2qx
pkg: open-webui
eco: pip
published: May 14, 2026
### Summary
_A regular user [non-admin] can view the system prompt of the model which is set by an admin._

### Details
_When a regular user [non-admin] logs into the application, a http://IP:8080/api/models? web request is initiated by the application and in response, it reveals the system prompt o…

CVE-2026-45351
GitHub-GHSA

MEDIUM
Open WebUI missing authorization check at the model update function – models from other users can be updated
GHSA-gm54-m39w-grjp
pkg: open-webui
eco: pip
published: May 14, 2026
### Summary
A user can modify another user's model even if its visibility is set to `Private`.
The finding resulted from a penetration test for a customer. It is suspected that the root cause of the issue lies within the core of Open WebUI, which is why it is being reported as a security issue here.…
CVE-2026-45345
GitHub-GHSA

MEDIUM
Open WebUI's API key endpoint restrictions bypassed via `x-api-key` header — full message processing on restricted endpoints
GHSA-57q6-fvp4-pqmm
pkg: open-webu
eco: pip
published: May 14, 2026
### Summary

Open WebUI allows admins to restrict which API endpoints an API key can access. When an API key is restricted from `/api/v1/messages`, requests using the `Authorization: Bearer sk-…` header are correctly blocked with 403. However, the same key sent via the `x-api-key` header bypasses …

CVE-2026-45339
GitHub-GHSA

MEDIUM
pyLoad Has Incomplete Fix for CVE-2026-33509 -storage_folder Bypass via Session Directory in pyLoad
GHSA-w727-595x-pc3r
pkg: pyload-ng
eco: pip
published: May 14, 2026
## Summary
The fix for CVE-2026-33509 prevents setting `storage_folder` inside `PKGDIR` or `userdir`, but does NOT protect the Flask session directory (`/tmp/pyLoad/flask`). An authenticated attacker can set `storage_folder` to the session directory and download session files of other users via `/fi…
CVE-2026-45306
GitHub-GHSA

MEDIUM
Home Assistant MCP Server: YAML config backups written under www/ are served unauthenticated at /local/
GHSA-g39v-cvjh-8fpf
pkg: ha-mcp
eco: pip
published: May 14, 2026
### Summary

When `ENABLE_YAML_CONFIG_EDITING=true`, every `ha_config_set_yaml` call backs up the pre-edit file to `<config>/www/yaml_backups/`, which Home Assistant serves at `/local/` with **no authentication**. Anyone who can reach the HA web interface can download the most recent pre-edit `confi…

NVD

MEDIUM
CVE-2026-44514
CVE-2026-44514
pkg: kubernetes

published: May 14, 2026

Kubetail is a real-time logging dashboard for Kubernetes. Prior to 0.14.0, Kubetail's dashboard exposes WebSocket endpoints that did not adequately validate the Origin header on connection upgrade. A malicious web page visited by a user with an active Kubetail session could open a WebSocket to the u…
CWE: CWE-1385
GitHub-GHSA

MEDIUM
@apostrophecms/cli: Command Injection in apos create via Unsanitized Password Input
GHSA-hcwq-x9fw-8cfq
pkg: @apostrophecms/cli
eco: npm
published: May 14, 2026
Summary

The @apostrophecms/cli package contains a command injection vulnerability in the apos create command.
User-supplied input from the password prompt is embedded directly into a shell command without proper sanitization or escaping.
This allows execution of arbitrary commands on the host syste…

CVE-2026-42853
NVD

MEDIUM
CVE-2026-44000
CVE-2026-44000
pkg: vm2_project vm2

published: May 13, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, a sandbox boundary violation in vm2 allows host object identity to cross into the sandbox through host Promise resolution. When a host-side Promise that resolves to a host object is exposed to the sandbox, the value delivered to the sand…
CWE: CWE-693
NVD

MEDIUM
CVE-2026-42946
CVE-2026-42946
pkg: nginx

published: May 13, 2026

A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive memory allocation or an over-read of data. When scgi_pass or uwsgi_pass is configured, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an …
CWE: CWE-789, CWE-823
NVD

MEDIUM
CVE-2026-40460
CVE-2026-40460
pkg: nginx

published: May 13, 2026

When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluate…
CWE: CWE-290
GitHub-GHSA

MEDIUM
wger has an Uncontrolled Resource Consumption issue
GHSA-v25j-wqcw-fvhj
pkg: wger
eco: pip
published: May 13, 2026
### Summary

Any authenticated user can create a routine spanning an arbitrarily long date range (e.g. 100 years) and then trigger the `date_sequence` computation via any of the routine detail endpoints. The server iterates once per day in an unbounded `while` loop with no maximum duration validatio…

GitHub-GHSA

MEDIUM
Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS)
GHSA-qrpw-gjvh-x5gm
pkg: nautobot, nautobot
eco: pip
published: May 13, 2026
### Impact

Nautobot UI object-bulk-rename endpoints (for example, `/dcim/interfaces/rename/`) were vulnerable to application-wide denial of service via maliciously crafted regular expressions in the `find` field in combination with the `use_regex` flag.

### Patches

A general-purpose timeout has b…

CVE-2026-44796
GitHub-GHSA

MEDIUM
go-billy: Lack of depth and cycle detection in symlink resolution may lead to infinite loops and resource exhaustion
GHSA-m3xc-h892-ggx6
pkg: github.com/go-git/go-billy/v5, github.com/go-git/go-billy/v6
eco: go
published: May 13, 2026
### Impact
Multiple components may improperly handle crafted or malformed input, resulting in panics, infinite loops, uncontrolled recursion, or excessive resource consumption.

These issues arise from insufficient validation and missing safety mechanisms such as cycle detection, recursion limits, o…

CVE-2026-44740
NVD

MEDIUM
CVE-2026-8199
CVE-2026-8199
pkg: mongodb mongodb

published: May 13, 2026

An authenticated user can cause excess memory usage via bitwise match expression AST processing of $bitsAllSet, $bitsAnySet, $bitsAllClear, and $bitsAnyClear. This contributes to memory pressure and may lead to availability loss by OOM.

This issue impacts MongoDB Server v7.0 versions prior to 7.0.3…

CWE: CWE-1325
NVD

MEDIUM
CVE-2026-35422
CVE-2026-35422
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Authentication bypass using an alternate path or channel in Windows TCP/IP allows an authorized attacker to bypass a security feature over a network.
CWE: CWE-288
NVD

MEDIUM
CVE-2026-34350
CVE-2026-34350
pkg: microsoft windows_server_2025

published: May 12, 2026

Null pointer dereference in Windows Storport Miniport Driver allows an unauthorized attacker to deny service over a network.
CWE: CWE-476
GitHub-GHSA

MEDIUM
OpenClaude MCP OAuth Callback: State Check Bypass via error Param Leads to DoS
GHSA-c73c-x77g-854r
pkg: @gitlawb/openclaude
eco: npm
published: May 12, 2026
# OAuth State Validation Bypass via `error` Parameter Causes Local Server DoS in MCP Auth Callback

## Description

The OpenClaude MCP authentication flow starts a temporary local HTTP server to handle OAuth callbacks. To prevent CSRF attacks, the server validates a `state` parameter against an …

CVE-2026-42073
NVD

MEDIUM
CVE-2026-42314
CVE-2026-42314
pkg: pyload-ng_project pyload-ng

published: May 11, 2026

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, package folder names are sanitized using insufficient string replacement. The pattern ….// becomes .._ after replacement (partial removal), leaving .. which can be exploited when the path is later resolve…
CWE: CWE-22
NVD

MEDIUM
CVE-2026-7820
CVE-2026-7820
pkg: oauth

published: May 11, 2026

Improper restriction of excessive authentication attempts (CWE-307) in pgAdmin 4.

pgAdmin enforces MAX_LOGIN_ATTEMPTS only inside its custom /authenticate/login view. Flask-Security's default /login view, which is registered automatically by security.init_app() and is reachable on every server, nev…

CWE: CWE-307
GitHub-GHSA

MEDIUM
Streamlink has an arbitrary local file read via file:// URI in HLS and DASH
GHSA-hgqw-6m45-hw5f
pkg: streamlink
eco: pip
published: May 11, 2026
## Summary

Streamlink's HLS and DASH parsers do not validate the URI scheme of segment entries and other resources. A remote `.m3u8` HLS playlist or `.mpd` DASH manifest can list `file:///path/to/file` as a segment, and streamlink will read that local file and write its contents to the output strea…

CVE-2026-44353
GitHub-GHSA

MEDIUM
Open WebUI's Improper Authorization in Standard Channels Allows Message Updates with Read Permission
GHSA-jgj3-r8hr-9pjw
pkg: open-webui
eco: pip
published: May 11, 2026
## Vulnerability Description

In standard channels (i.e., channels whose `channel.type` is neither `group` nor `dm`), the endpoint

`POST /api/v1/channels/{channel_id}/messages/{message_id}/update` can be accessed with **read permission only**.

When `access_control` is set to `None`, the authorizat…

CVE-2026-44571
NVD

MEDIUM
CVE-2026-5361
CVE-2026-5361
pkg: express

published: May 14, 2026

The Envira Gallery Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST API in versions up to and including 1.12.4. This is due to insufficient input sanitization in the update_gallery_data() function and improper output escaping in the gallery_init() function. The san…
CWE: CWE-79
NVD

MEDIUM
CVE-2026-6962
CVE-2026-6962
pkg: go

published: May 13, 2026

The Cost of Goods: Product Cost & Profit Calculator for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'alg_wc_cog_product_cost' and 'alg_wc_cog_product_profit' shortcodes in all versions up to, and including, 4.1.0 due to insufficient input sanitizati…
CWE: CWE-79
GitHub-GHSA

MEDIUM
dbt MCP Server has an Argument Injection in dbt CLI Tool Wrappers via node_selection and resource_type Parameters
GHSA-xpww-f6pm-cfhq
pkg: dbt-mcp
eco: pip
published: May 14, 2026
*Discovered through manual source code review. Verified by PoC execution against a local dbt-mcp v1.15.1 installation.**

## Summary

`_run_dbt_command()` in `src/dbt_mcp/dbt_cli/tools.py` constructs the dbt subprocess argument list by appending user-supplied MCP tool parameters without sanitization…

CVE-2026-44968
NVD

MEDIUM
CVE-2026-33380
CVE-2026-33380
pkg: express

published: May 13, 2026

A vulnerability in SQL Expressions allows an authenticated attacker to read arbitrary files from the Grafana server's filesystem. Only instances with the sqlExpressions feature toggle enabled are vulnerable.
CWE: CWE-552
GitHub-GHSA

MEDIUM
Keylime has a hardcoded attestation challenge nonce that allows replay attacks
GHSA-q8w6-w55c-ccv5
pkg: keylime
eco: pip
published: May 11, 2026
## CVE-2026-6420: Hardcoded attestation challenge nonce allows replay attacks

### Impact

The `CertificationParameters.generate_challenge()` method in the push attestation protocol uses a hardcoded challenge nonce instead of generating a cryptographically random value. This removes the nonce-based …

CVE-2026-6420
GitHub-GHSA

MEDIUM
PraisonAI knowledge-store backends interpolate unvalidated collection names into SQL and CQL queries
GHSA-3643-7v76-5cj2
pkg: PraisonAI
eco: pip
published: May 11, 2026
### Summary
PraisonAI exposes optional SQL/CQL-backed knowledge-store implementations that build table and index identifiers from unvalidated `name` and `collection` arguments. Applications that pass untrusted collection names into these backends can trigger SQL or CQL injection.

### Details
This i…

CVE-2026-44337
GitHub-GHSA

MEDIUM
pyzipper has an encryption bypass for small files encrypted using it
GHSA-crqm-m339-7m2p
pkg: pyzipper
eco: pip
published: May 14, 2026
### Impact
A Python operator precedence bug in pyzipper/zipfile_aes.py caused the AE-2 format to never be automatically selected during encryption, regardless of file size or compression type. As a result, all encrypted entries are written in AE-1 format unless AE-2 is explicitly forced by the calle…
CVE-2026-44722
GitHub-GHSA

MEDIUM
Mistune TOC Anchor Injection XSS
GHSA-6269-cqxg-mhhv
pkg: mistune
eco: pip
published: May 14, 2026
## Summary
`render_toc_ul()` builds a `<ul>` table-of-contents tree from a list of `(level, id, text)` tuples. Both the `id` value (used as `href="#<id>"`) and the `text` value (used as the visible link label) are inserted into `<a>` tags via a plain Python format string — with no HTML escaping ap…
CVE-2026-44898
NVD

MEDIUM
CVE-2026-44580
CVE-2026-44580
pkg: vercel next.js

published: May 13, 2026

Next.js is a React framework for building full-stack web applications. From 13.0.0 to before 15.5.16 and 16.2.5, applications that use beforeInteractive scripts together with untrusted content can be vulnerable to cross-site scripting. In affected versions, serialized script content was not escaped …
CWE: CWE-79
GitHub-GHSA

MEDIUM
Authlib OIDC Implicit/Hybrid Authorization Vulnerable to Open Redirect
GHSA-r95x-qfjj-fjj2
pkg: authlib, authlib
eco: pip
published: May 13, 2026
### Summary

An unauthenticated open redirect in Authlib's `OpenIDImplicitGrant` and `OpenIDHybridGrant` authorization endpoint lets a remote attacker cause the authorization server to issue an HTTP 302 to an attacker-chosen URL by submitting an authorization request that omits the `openid` scope.

CVE-2026-44681
NVD

MEDIUM
CVE-2026-44245
CVE-2026-44245
pkg: vue

published: May 12, 2026

Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to 2.5.2, Vue 3's v-html directive is the framework-documented mechanism for injecting raw HTML, and it intentionally disables the auto-escaping that {{ }} interpolation provides. The PropertyCard.vue component us…
CWE: CWE-79
NVD

MEDIUM
CVE-2026-20771
CVE-2026-20771
pkg: intel quickassist_technology

published: May 12, 2026

Null pointer dereference for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result m…
CWE: CWE-476
NVD

MEDIUM
CVE-2026-7464
CVE-2026-7464
pkg: go

published: May 12, 2026

The WP Google Maps Integration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `page` parameter in all versions up to, and including, 1.2. This is due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject a…
CWE: CWE-79
GitHub-GHSA

MEDIUM
Next.js has cross-site scripting in beforeInteractive scripts with untrusted input
GHSA-gx5p-jg67-6x7h
pkg: next, next
eco: npm
published: May 11, 2026
### Impact

Applications that use `beforeInteractive` scripts together with untrusted content can be vulnerable to cross-site scripting. In affected versions, serialized script content was not escaped safely before being embedded into the document, which could allow attacker-controlled input to brea…

CVE-2026-44580
GitHub-GHSA

MEDIUM
Ella Core has a UE Security Capability bypass on NGAP PathSwitchRequest
GHSA-pwfh-mqp3-pqwj
pkg: github.com/ellanetworks/core
eco: go
published: May 11, 2026
## Summary

Ella Core does not verify the UE Security Capabilities received in NGAP PathSwitchRequest messages against its locally stored values. A malicious gNB can overwrite Ella Core's stored UE security capabilities for any UE with arbitrary values by sending a single crafted PathSwitchRequest.

CVE-2026-44475
NVD

MEDIUM
CVE-2026-42597
CVE-2026-42597
pkg: docker

published: May 14, 2026

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the /forms/chromium/convert/url and /forms/chromium/screenshot/url routes accept url=file:///tmp/… from anonymous callers. The default Chromium deny-list intentionally exempts file:///tmp/ so HTML/Markdown routes can load …
CWE: CWE-73, CWE-918
NVD

MEDIUM
CVE-2026-44577
CVE-2026-44577
pkg: vercel next.js

published: May 13, 2026

Next.js is a React framework for building full-stack web applications. From 10.0.0 to before 15.5.16 and 16.2.5, when self-hosting Next.js with the default image loader, the Image Optimization API fetches local images entirely into memory without enforcing a maximum size limit. An attacker could cau…
CWE: CWE-770
NVD

MEDIUM
CVE-2026-6253
CVE-2026-6253
pkg: haxx curl

published: May 13, 2026

curl might erroneously pass on credentials for a first proxy to a second
proxy.

This can happen when the following conditions are true:

1. curl is setup to use specific different proxies for different URL schemes
2. the first proxy needs credentials
3. the second proxy uses no credentials
4. while…

CWE: CWE-522
NVD

MEDIUM
CVE-2026-4873
CVE-2026-4873
pkg: haxx curl

published: May 13, 2026

A vulnerability exists where a connection requiring TLS incorrectly reuses an
existing unencrypted connection from the same connection pool. If an initial
transfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request
to that same host bypasses the TLS requirement and instead transmi…
CWE: CWE-295, CWE-319
NVD

MEDIUM
CVE-2026-42545
CVE-2026-42545
pkg: python

published: May 12, 2026

Granian is a Rust HTTP server for Python applications. From 0.2.0 to 2.7.4, Granian aborts a worker process if a WSGI application returns an invalid HTTP response header name or value. The WSGI response conversion path uses .unwrap() on both the header name and header value constructors, so malforme…
CWE: CWE-248, CWE-755
GitHub-GHSA

MEDIUM
Next.js has a Denial of Service in the Image Optimization API
GHSA-h64f-5h5j-jqjh
pkg: next, next
eco: npm
published: May 11, 2026
### Impact

When self-hosting Next.js with the default image loader, the Image Optimization API fetches local images entirely into memory without enforcing a maximum size limit. An attacker could cause out-of-memory conditions by requesting large local assets from the `/_next/image` endpoint that ma…

CVE-2026-44577
NVD

MEDIUM
CVE-2026-44312
CVE-2026-44312
pkg: openssl

published: May 14, 2026

css_parser is a Ruby CSS parser. Prior to 2.1.0 and 1.22.0, the CSS Parser gem does not validate HTTPS connections, allowing a Man-in-the-Middle (MITM) attacker to inject or modify CSS content when stylesheets are loaded via HTTPS. The connection is established with OpenSSL::SSL::VERIFY_NONE, meanin…
CWE: CWE-295, CWE-829
NVD

MEDIUM
CVE-2026-44002
CVE-2026-44002
pkg: vm2_project vm2

published: May 13, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, vm2's CallSite wrapper class (intended as a safe wrapper for V8's native CallSite) blocks getThis() and getFunction() to prevent host object leakage, but allows getFileName() to return unsanitized host absolute paths. Any sandboxed code …
CWE: CWE-209
NVD

MEDIUM
CVE-2026-42926
CVE-2026-42926
pkg: nginx

published: May 13, 2026

When NGINX Open Source is configured to proxy HTTP/2 traffic by setting proxy_http_version to 2, and also uses proxy_set_body, an attacker may be able to inject frame headers and payload bytes to the upstream peer.  Note: Software versions which have reached End of Technical Support (EoTS) are not…
CWE: CWE-172
NVD

MEDIUM
CVE-2026-44347
CVE-2026-44347
pkg: warpgate_project warpgate

published: May 12, 2026

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.23.3, the SSO flow does not validate the state parameter, which makes it possible for an attacker to trick a user into logging into the attacker's account, possibly convincing them to perform sensitive actions on the …
CWE: CWE-352
NVD

MEDIUM
CVE-2026-44695
CVE-2026-44695
pkg: getoutline outline

published: May 11, 2026

Outline is a service that allows for collaborative documentation. Prior to 1.7.1, the Slack integration callback for GET /auth/slack.post accepts an unsigned, session-independent OAuth state value. A third party who can obtain a Slack OAuth code for the same Outline Slack client can make a logged-in…
CWE: CWE-352
NVD

MEDIUM
CVE-2026-31252
CVE-2026-31252
pkg: python

published: May 11, 2026

CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its model loading component. The framework uses torch.load() to load model weight files (e.g., llm.pt, flow.pt, hift.pt) without enabling the security-restricti…
CWE: CWE-94, CWE-915
GitHub-GHSA

MEDIUM
Microsoft APM: Windows absolute-path tar member overwrite during legacy-bundle probing in `apm install`
GHSA-mq5j-pw29-jcv3
pkg: apm-cli
eco: pip
published: May 15, 2026
### Summary

Microsoft APM contains a Windows-specific archive extraction boundary failure in the legacy-bundle probe used by `apm install <bundle>` on supported Python 3.10 and 3.11 runtimes. When `apm install` is given a local `.tar.gz` that is not recognized as a plugin-format bundle, APM probes …

CVE-2026-46383
NVD

MEDIUM
CVE-2026-46383
CVE-2026-46383
pkg: python

published: May 15, 2026

Microsoft APM is an open-source, community-driven dependency manager for AI agents. Prior to 0.13.0, Microsoft APM contains a Windows-specific archive extraction boundary failure in the legacy-bundle probe used by apm install <bundle> on supported Python 3.10 and 3.11 runtimes. When apm install is g…
CWE: CWE-22, CWE-73
GitHub-GHSA

MEDIUM
Portainer has a path traversal in backup archive extraction that allows arbitrary file write
GHSA-m8fg-67j7-cx4v
pkg: github.com/portainer/portainer
eco: go
published: May 14, 2026
### Summary
Portainer's backup restore feature accepts a `.tar.gz` archive and extracts it to a target directory on the server. The extraction function (`ExtractTarGz` in `api/archive/targz.go`) constructed output paths using `filepath.Clean(filepath.Join(outputDirPath, header.Name))`. This combinat…
CVE-2026-44885
NVD

MEDIUM
CVE-2026-35419
CVE-2026-35419
pkg: microsoft windows_11_24h2, microsoft windows_11_25h2, microsoft windows_11_26h1

published: May 12, 2026

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
CWE: CWE-125
NVD

MEDIUM
CVE-2026-34339
CVE-2026-34339
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Null pointer dereference in Windows LDAP – Lightweight Directory Access Protocol allows an authorized attacker to deny service locally.
CWE: CWE-476
NVD

MEDIUM
CVE-2026-20914
CVE-2026-20914
pkg: intel quickassist_technology

published: May 12, 2026

Null pointer dereference for some Intel(R) QAT software drivers for Windows before version 2.6.0 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result …
CWE: CWE-476
NVD

MEDIUM
CVE-2026-20881
CVE-2026-20881
pkg: intel quickassist_technology

published: May 12, 2026

Divide by zero for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potenti…
CWE: CWE-369
GitHub-GHSA

MEDIUM
Gryph Agents Payload Filter Fails to Strip Tool Payload for Sensitive Content
GHSA-f3jg-756w-gm35
pkg: github.com/safedep/gryph
eco: go
published: May 11, 2026
Gryph implements logging levels that determine what content is logged to a local sqlite database. The README incorrectly mentions that the default log level is minimal while it is standard. Source code review shows sensitive `file-write` content remains in the stored `payload` as `ContentPreview`, …
CVE-2026-45046
NVD

MEDIUM
CVE-2026-23695
CVE-2026-23695
pkg: vue

published: May 15, 2026

Cockpit CMS through version 2.14.0, patched in commit 72a83fc, contains a stored cross-site scripting vulnerability in the Set field type's Display template option, where the template string is processed by the $interpolate function using new Function() and rendered via Vue's v-html directive withou…
CWE: CWE-79
NVD

MEDIUM
CVE-2026-44429
CVE-2026-44429
pkg: lfprojects mcp_registry

published: May 14, 2026

The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.7, the public catalogue UI served at GET / (file internal/api/handlers/v0/ui_index.html) is vulnerable to stored cross-site scripting via the server.websiteUrl field of any published ser…
CWE: CWE-79, CWE-116
GitHub-GHSA

MEDIUM
Open WebUI: Mass Assignment via FeedbackForm extra=allow Allows Feedback User ID Spoofing and Evaluation Data Manipulation
GHSA-rjmp-vjf2-qf4g
pkg: open-webui
eco: pip
published: May 14, 2026
# Mass Assignment in Feedback Creation Allows User ID Spoofing and Evaluation Data Manipulation

## Summary

The `POST /api/v1/evaluations/feedback` endpoint in Open WebUI v0.9.2 is vulnerable to mass assignment via `FeedbackForm`, which uses `model_config = ConfigDict(extra='allow')`. Due to an ins…

CVE-2026-45396
GitHub-GHSA

MEDIUM
Open WebUI: Authenticated users can bypass model access control via exposed query parameter [AI-ASSISTED]
GHSA-v6qf-75pr-p96m
pkg: open-webui
eco: pip
published: May 14, 2026
### Summary

An internal-only bypass_filter parameter is exposed on the /openai/chat/completions and /ollama/api/chat HTTP endpoints via FastAPI query string binding, allowing any authenticated user to append ?bypass_filter=true and bypass model access control checks to invoke admin-restricted model…

CVE-2026-45365
GitHub-GHSA

MEDIUM
Open WebUI has stored XSS via unsanitized Office/Excel/DOCX file preview rendering ({@html} without DOMPurify)
GHSA-hcwp-82g6-8wxc
pkg: open-webui
eco: pip
published: May 14, 2026
## Related advisory

This advisory tracks a regression of the original Excel-preview XSS that was
publicly disclosed and patched under [GHSA-jwf8-pv5p-vhmc](https://github.com/open-webui/open-webui/security/advisories/GHSA-jwf8-pv5p-vhmc)
(patched in v0.8.0). The same root cause — `XLSX.utils.sh…

CVE-2026-45318
GitHub-GHSA

MEDIUM
Open WebUI has Stored Cross-Site Scripting In Profile Picture
GHSA-6gh2-q7cp-9qf6
pkg: open-webui
eco: pip
published: May 14, 2026
## Summary

The `profile_image_url` field on the user profile update form accepted arbitrary `data:` URI values without MIME-type validation. Two distinct attack paths were independently demonstrated by separate reporters:

1. **`data:text/html;base64,…` in a new browser tab** (raresvis, 2025-04-1…

CVE-2026-45299
NVD

MEDIUM
CVE-2026-43644
CVE-2026-43644
pkg: go

published: May 14, 2026

podinfo through 6.11.2 contains a reflected cross-site scripting vulnerability in the /echo and /api/echo endpoints where the echoHandler writes request body content directly to the response without setting explicit Content-Type or X-Content-Type-Options headers. Attackers can craft cross-origin HTM…
CWE: CWE-79
NVD

MEDIUM
CVE-2026-3829
CVE-2026-3829
pkg: ssl

published: May 14, 2026

The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the 'wple_basic_get_requests' function in all versions up to, and including, 7.8.5.10. This mak…
CWE: CWE-862
NVD

MEDIUM
CVE-2026-45228
CVE-2026-45228
pkg: vue

published: May 13, 2026

Quark Drive before 0.8.5 contains a stored cross-site scripting vulnerability in the System Configuration page where the template renders push_config key names using Vue.js's v-html directive without escaping. Authenticated attackers can inject HTML or JavaScript payloads as key names through the PO…
CWE: CWE-79
NVD

MEDIUM
CVE-2026-44576
CVE-2026-44576
pkg: vercel next.js

published: May 13, 2026

Next.js is a React framework for building full-stack web applications. From 14.2.0 to before 15.5.16 and 16.2.5, applications using React Server Components can be vulnerable to cache poisoning when shared caches do not correctly partition response variants. Under affected conditions, an attacker can…
CWE: CWE-436
GitHub-GHSA

MEDIUM
Nautobot: REST API permits creation of GenericForeignKey references to objects that the user should not be able to reference
GHSA-wpxj-44w3-2j6x
pkg: nautobot, nautobot
eco: pip
published: May 13, 2026
### Impact

In the case of inter-object references via `GenericForeignKey` (a pattern allowing an object to reference another object that may belong to one of several different "content types" or database tables), when creating or updating an object containing a `GenericForeignKey`, Nautobot's REST …

CVE-2026-44794
NVD

MEDIUM
CVE-2026-43879
CVE-2026-43879
pkg: curl

published: May 11, 2026

WWBN AVideo is an open source video platform. In versions up to and including 29.0, an authenticated user can configure their own donation-notification webhook URL to point at internal/loopback/metadata hosts (e.g. http://127.0.0.1:8080/…, http://169.254.169.254/latest/…, RFC1918 addresses). Whe…
CWE: CWE-918
GitHub-GHSA

MEDIUM
Next.js vulnerable to cache poisoning in React Server Component responses
GHSA-wfc6-r584-vfw7
pkg: next, next
eco: npm
published: May 11, 2026
### Impact

Applications using React Server Components can be vulnerable to cache poisoning when shared caches do not correctly partition response variants. Under affected conditions, an attacker can cause an RSC response to be served from the original URL and poison shared cache entries so later vi…

CVE-2026-44576
NVD

MEDIUM
CVE-2026-8723
CVE-2026-8723
pkg: node

published: May 17, 2026

### Summary

`qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is synchronous and not handled by any of qs's null-related options (`skipNulls`, `strictNullHandling`).

### Details

In t…

CWE: CWE-476
GitHub-GHSA

MEDIUM
Better Auth: OAuth callback accepts mismatched `state` when cookie-backed state storage is used without PKCE
GHSA-wxw3-q3m9-c3jr
pkg: better-auth
eco: npm
published: May 15, 2026
### Am I affected?

Users are affected if all of the following are true:

– The application uses `better-auth` at a version below `1.6.2` (or `@better-auth/sso` paired with such a version).
– `betterAuth({ account: { storeStateStrategy } })` is set to `"cookie"`. The default `"database"` is not affe…

GitHub-GHSA

MEDIUM
Open WebUI Vulnerable to Unauthenticated RAG Configuration Disclosure
GHSA-65pg-qhhw-mxwg
pkg: open-webui
eco: pip
published: May 14, 2026
**Vulnerability Type:** Information Disclosure / Missing Authentication
**Severity:** Medium
**Component:** `backend/open_webui/routers/retrieval.py` — `get_status()` (`GET /`)
**Affected Endpoint:** `GET /api/v1/retrieval/`
**Affected Version:** Open WebUI `main` branch — confirmed unpa…
CVE-2026-45397
NVD

MEDIUM
CVE-2026-8535
CVE-2026-8535
pkg: linux

published: May 14, 2026

Out of bounds read in Media in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted JPEG file. (Chromium security severity: High)
CWE: CWE-125
NVD

MEDIUM
CVE-2026-8516
CVE-2026-8516
pkg: go

published: May 14, 2026

Insufficient validation of untrusted input in DataTransfer in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: C…
CWE: CWE-20
NVD

MEDIUM
CVE-2025-64526
CVE-2025-64526
pkg: strapi strapi

published: May 14, 2026

Strapi is an open source headless content management system. In Strapi versions prior to 5.45.0, the rate-limit middleware in the users-permissions plugin derived its rate-limit key in part from `ctx.request.body.email`, including on routes whose body schema does not contain an `email` field (`/auth…
CWE: CWE-307
GitHub-GHSA

MEDIUM
OpenTelemetry Java SDK has Unbounded Memory Allocation in W3C Baggage Propagation
GHSA-rcgg-9c38-7xpx
pkg: io.opentelemetry:opentelemetry-api, io.opentelemetry:opentelemetry-extension-trace-propagators
eco: maven
published: May 14, 2026
## Overview

A vulnerability affects the baggage propagation implementation in
`opentelemetry-api` and `opentelemetry-extension-trace-propagators`. Parsing oversized baggage
causes unbounded memory allocation and CPU consumption. Because baggage is automatically
re-injected into every outgoing reque…

CVE-2026-45292
NVD

MEDIUM
CVE-2026-42593
CVE-2026-42593
pkg: express

published: May 14, 2026

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, pdfengines/merge, pdfengines/split, libreoffice/convert, chromium/convert/url, chromium/convert/html, and chromium/convert/markdown accept stampSource=pdf + stampExpression=/path and watermarkSource=pdf + watermarkExpression…
CWE: CWE-22, CWE-73
NVD

MEDIUM
CVE-2026-42592
CVE-2026-42592
pkg: docker

published: May 14, 2026

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, FilterOutboundURL resolves the hostname, checks the resolved IPs against the private-address deny-list, and returns only the error. It discards the resolved addresses. Chromium later performs its own DNS resolution when it n…
CWE: CWE-367, CWE-918
GitHub-GHSA

MEDIUM
Fleet has a rate limiting bypass via untrusted client IP headers
GHSA-j8h8-75h3-jg53
pkg: github.com/fleetdm/fleet/v4
eco: go
published: May 14, 2026
### Impact

Fleet trusted client-supplied IP address headers when determining the source IP for incoming requests. This allowed authenticated and unauthenticated clients to spoof their apparent IP address and bypass per-IP rate limiting controls.

Fleet determines a client’s public IP address usin…

CVE-2026-24000
NVD

MEDIUM
CVE-2026-44003
CVE-2026-44003
pkg: vm2_project vm2

published: May 13, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, vm2's code transformer has a performance optimization that skips AST analysis when the code does not contain catch, import, or async keywords. This fast-path bypass allows sandboxed code to directly access the internal VM2_INTERNAL_STATE…
CWE: CWE-693
NVD

MEDIUM
CVE-2026-44431
CVE-2026-44431
pkg: python urllib3

published: May 13, 2026

urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(…, assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.
CWE: CWE-200
NVD

MEDIUM
CVE-2026-7009
CVE-2026-7009
pkg: haxx curl

published: May 13, 2026

When curl is told to use the Certificate Status Request TLS extension, often
referred to as *OCSP stapling*, to verify that the server certificate is
valid, it fails to detect OCSP problems and instead wrongly consider the
response as fine.
CWE: CWE-295
NVD

MEDIUM
CVE-2026-44341
CVE-2026-44341
pkg: go

published: May 12, 2026

GoJobs is a REST API for a Job Board platform. The application exposes a job retrieval endpoint that allows unauthenticated users to access job details by directly manipulating object identifiers. The endpoint lacks proper authentication and authorization checks, resulting in unauthorized access to …
CWE: CWE-284, CWE-639
NVD

MEDIUM
CVE-2026-42177
CVE-2026-42177
pkg: linux

published: May 12, 2026

linux-entra-sso is a browser plugin for Linux to SSO on Microsoft Entra ID. Prior to 1.8.1, platform/chrome/js/platform-chrome.js:69-88 registers a single declarativeNetRequest rule whose urlFilter is Platform.SSO_URL + "/*", i.e. "https://login.microsoftonline.com/*". Chrome's urlFilter without a |…
CWE: CWE-284, CWE-436
GitHub-GHSA

MEDIUM
protobuf.js: Denial of service from crafted field names in generated code
GHSA-2pr8-phx7-x9h3
pkg: protobufjs, protobufjs
eco: npm
published: May 12, 2026
## Summary

protobufjs generated JavaScript property accessors from schema-controlled field and oneof names. Certain control characters in field names were not escaped before being embedded into generated function bodies. A crafted schema or JSON descriptor could therefore cause generated encode, de…

CVE-2026-44294
GitHub-GHSA

MEDIUM
protobuf.js: Prototype injection in generated message constructors
GHSA-fx83-v9x8-x52w
pkg: protobufjs, protobufjs
eco: npm
published: May 12, 2026
## Summary

protobufjs generated message constructors copied enumerable properties from a provided properties object without filtering the `__proto__` key. If an application constructed a message from an attacker-controlled plain object, an own enumerable `__proto__` property could alter the prototy…

CVE-2026-44292
GitHub-GHSA

MEDIUM
protobufjs has overlong UTF-8 decoding
GHSA-q6x5-8v7m-xcrf
pkg: protobufjs, protobufjs, @protobufjs/utf8
eco: npm
published: May 12, 2026
## Summary

protobufjs includes a minimal UTF-8 decoder used in non-Node and fallback decoding paths. The affected decoder accepted overlong UTF-8 byte sequences and decoded them to their canonical characters instead of replacing them.

The issue concerns overlong encodings and code points outside t…

CVE-2026-44288
NVD

MEDIUM
CVE-2026-6402
CVE-2026-6402
pkg: webpack

published: May 12, 2026

webpack-dev-server versions up to and including 5.2.3 are vulnerable to cross-origin source code exposure when serving over a non-potentially trustworthy origin such as plain HTTP. The previous fix relied on the Sec-Fetch-Mode and Sec-Fetch-Site request headers, which browsers omit for non-trustwort…
CWE: CWE-749
NVD

MEDIUM
CVE-2026-44226
CVE-2026-44226
pkg: python

published: May 11, 2026

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, pyload-ng WebUI returns full Python traceback details to clients on unhandled exceptions. Because /web/<path:filename> is reachable without authentication and renders attacker-controlled template names, an …
CWE: CWE-209
GitHub-GHSA

MEDIUM
local-deep-research is Vulnerable to HTML Injection via Unescaped User Input in PDF Export (`pdf_service.py:_markdown_to_html`)
GHSA-fj2m-qvh9-jq4q
pkg: local-deep-research
eco: pip
published: May 11, 2026
## Summary

`PDFService._markdown_to_html()` constructs an HTML document by interpolating user-controlled values — specifically `title` (sourced from `research.title` or `research.query`) and `metadata` key-value pairs — directly into an f-string without any HTML escaping. An authenticated attac…

CVE-2026-43979
GitHub-GHSA

MEDIUM
GuardDog: Unsanitized human-readable scan output allows terminal escape injection from malicious package content
GHSA-m5p4-gvpx-4mvr
pkg: guarddog
eco: pip
published: May 11, 2026
# Summary
GuardDog includes attacker-controlled filenames, file locations, messages, and code snippets in its default human-readable output without escaping terminal control characters. A malicious package can therefore inject ANSI or OSC escape sequences into analyst terminals or CI logs.

# Descri…

CVE-2026-44972
NVD

MEDIUM
CVE-2026-42780
CVE-2026-42780
pkg: ssl

published: May 13, 2026

A directory traversal vulnerability exists in BIG-IP SSL Orchestrator that allows an authenticated attacker with high privilege to overwrite, delete or corrupt arbitrary local files.
 Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CWE: CWE-22
NVD

MEDIUM
CVE-2026-42876
CVE-2026-42876
pkg: kubernetes

published: May 11, 2026

External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Prior to 2.4.1, a user who only has permission to create ExternalSecret resources can cause the operator to create a Secret that Kubernetes will automatically populate w…
CWE: CWE-285
NVD

MEDIUM
CVE-2026-8367
CVE-2026-8367
pkg: tls

published: May 13, 2026

aria2c accepts a server certificate with incorrect Extended Key Usage (EKU). If the attackers compromise a certificate (with the associated private key) issued for a different purpose, they may be able to reuse it for TLS server authentication.
CWE: CWE-295
NVD

MEDIUM
CVE-2026-42934
CVE-2026-42934
pkg: nginx

published: May 13, 2026

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When charset, source_charset, and charset_map and proxy_pass with disabled buffering ("off") directives are configured, unauthenticated attackers can send requests that with conditions beyond the attackers…
CWE: CWE-125
NVD

MEDIUM
CVE-2026-40701
CVE-2026-40701
pkg: ssl

published: May 13, 2026

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured with a resolver. With this configuration, an unauthenticated …
CWE: CWE-416
NVD

MEDIUM
CVE-2026-44661
CVE-2026-44661
pkg: python

published: May 14, 2026

python-utcp is the python implementation of UTCP. Prior to 1.1.3, the utcp-http plugin is vulnerable to a blind Server-Side Request Forgery (SSRF) caused by a trust-boundary inconsistency between manual discovery and tool invocation. register_manual() validates the discovery URL against an HTTPS / l…
CWE: CWE-918
GitHub-GHSA

MEDIUM
@utcp/http: SSRF via attacker-controlled OpenAPI servers[0].url in HTTP communication protocol
GHSA-r8j5-8747-88cm
pkg: @utcp/http
eco: npm
published: May 14, 2026
## Summary

The `@utcp/http` package is vulnerable to a blind Server-Side Request Forgery (SSRF) caused by a trust-boundary inconsistency between manual discovery and tool invocation. `registerManual()` validates the discovery URL against an HTTPS / loopback allowlist, but `callTool()` reuses the re…

CVE-2026-45366
GitHub-GHSA

MEDIUM
Mistune Image Directive CSS Injection Vulnerability
GHSA-ccfx-mfmx-2fx9
pkg: mistune
eco: pip
published: May 14, 2026
## Summary
The Image directive plugin validates the `:width:` and `:height:` options with a regex compiled as `_num_re = re.compile(r"^\d+(?:\.\d*)?")`. This pattern is applied via `re.match()` (which anchors only at the **start** of the string, not the end). Any value that begins with one or more d…
CVE-2026-44899
NVD

MEDIUM
CVE-2026-44581
CVE-2026-44581
pkg: vercel next.js

published: May 13, 2026

Next.js is a React framework for building full-stack web applications. From 13.4.0 to before 15.5.16 and 16.2.5, App Router applications that rely on CSP nonces can be vulnerable to stored cross-site scripting when deployed behind shared caches. In affected versions, malformed nonce values derived f…
CWE: CWE-79
GitHub-GHSA

MEDIUM
Next.js vulnerable to cross-site scripting in App Router applications using CSP nonces
GHSA-ffhc-5mcf-pf4q
pkg: next, next
eco: npm
published: May 11, 2026
### Impact

App Router applications that rely on CSP nonces can be vulnerable to stored cross-site scripting when deployed behind shared caches. In affected versions, malformed nonce values derived from request headers could be reflected into rendered HTML in an unsafe way, allowing an attacker to p…

CVE-2026-44581
GitHub-GHSA

MEDIUM
Weblate: Stored HTML injection in editor search preview
GHSA-6wxc-8mgq-w26m
pkg: weblate
eco: pip
published: May 15, 2026
### Impact
Weblate's live search preview renders unit `source` and `context` as HTML without escaping. Any contributor whose content reaches those fields stores HTML and CSS that runs inside the authenticated editor of every user who runs a matching search.

### Patches
* https://github.com/WeblateO…

CVE-2026-45106
GitHub-GHSA

MEDIUM
Open WebUI Vulnerable to Cross-Site Request Forgery (CSRF) via Image URL Manipulation
GHSA-j6w6-986j-2m2m
pkg: open-webui
eco: pip
published: May 14, 2026
## Summary

An application-wide Cross-Site Request Forgery (CSRF) vulnerability was found Open-WebUl's image uploading functionality. An attacker can set an image URL to a malicious endpoint, allowing them to perform actions on behalf of a victim user. Any authenticated user can exploit this vulner…

CVE-2026-45317
NVD

MEDIUM
CVE-2026-45736
CVE-2026-45736
pkg: node

published: May 15, 2026

ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability is fixed in 8.20.1.
CWE: CWE-908
NVD

MEDIUM
CVE-2026-32209
CVE-2026-32209
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass a security feature locally.
CWE: CWE-284
GitHub-GHSA

MEDIUM
Open WebUI: Sharing models for others to use (read permission) also exposes model details (system prompt leakage)
GHSA-h2cw-7qw9-56xr
pkg: open-webui
eco: pip
published: May 14, 2026
### Summary
When setting model permissions so that a group has read access to it, intending for other users to use it, those users also can read the model's system prompt.

However users may consider their system prompt confidential, so we consider this a security issue.

Compare https://genai.owasp…

CVE-2026-45387
GitHub-GHSA

MEDIUM
Open WebUI has an IDOR vulnerability in the pin_channel_message API endpoint
GHSA-5gc6-xhv4-2wg6
pkg: open-webui
eco: pip
published: May 14, 2026
### Summary
`Pin/Unpin` is a write operation (modifies the message's `is_pinned `, `pinned_by`, `pinned_at` fields), but in standard channels it only checks `read` permission, allowing users with read-only access to pin/unpin any message.

### Details
https://github.com/open-webui/open-webui/blob/9b…

CVE-2026-45386
GitHub-GHSA

MEDIUM
Open WebUI has an IDOR vulnerability in the update_message_by_id API endpoint
GHSA-wwhq-cx22-f7vv
pkg: open-webui
eco: pip
published: May 14, 2026
### Summary
An IDOR vulnerability exists in the Channels feature of `Open WebUI`, allowing any channel member to modify messages sent by other members (including administrators) within the same channel. This vulnerability affects the latest version (`v0.8.12`) of `Open WebUI`.

### Details
In the `u…

CVE-2026-45385
GitHub-GHSA

MEDIUM
Open WebUI vulnerable to blind server side request forgery (SSRF) via the PDF generate function
GHSA-f776-fp4w-266c
pkg: open-webui
eco: pip
published: May 14, 2026
### Summary
Blind server side request forgery (SSRF) via the PDF generate function.
The finding resulted from a penetration test for a customer. It is suspected that the root cause of the issue lies within the core of Open WebUI, which is why it is being reported as a security issue here. Tested on…
CVE-2026-45347
NVD

MEDIUM
CVE-2026-8576
CVE-2026-8576
pkg: linux

published: May 14, 2026

Inappropriate implementation in CORS in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-942
NVD

MEDIUM
CVE-2026-8537
CVE-2026-8537
pkg: go

published: May 14, 2026

Insufficient policy enforcement in ViewTransitions in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-942
NVD

MEDIUM
CVE-2026-8528
CVE-2026-8528
pkg: go

published: May 14, 2026

Insufficient validation of untrusted input in SiteIsolation in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to bypass Site Isolation via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-20, CWE-20
GitHub-GHSA

MEDIUM
SiYuan has broken access control in `/api/search/{searchAsset,searchTag,searchWidget,searchTemplate}` publish-mode
GHSA-fmh9-gpqh-g53g
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: May 13, 2026
### Summary

The advisory `GHSA-c77m-r996-jr3q` patched `getBookmark` so that, when invoked by a publish-mode `RoleReader`, results are filtered through `FilterBlocksByPublishAccess` to remove entries from password-protected / publish-ignored notebooks. Four sibling search handlers in the same file …

CVE-2026-45148
GitHub-GHSA

MEDIUM
SiYuan: Broken access control in `/api/tag/getTag` — Reader role can mutate `Conf.Tag.Sort` and persist to disk
GHSA-6r88-8v7q-q4p2
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: May 13, 2026
### Summary

`POST /api/tag/getTag` is registered with `model.CheckAuth` only, omitting both `model.CheckAdminRole` and `model.CheckReadonly`, despite the handler performing a configuration write that is normally guarded by both. Any authenticated user — including publish-service `RoleReader` acco…

CVE-2026-45147
NVD

MEDIUM
CVE-2026-42541
CVE-2026-42541
pkg: kubernetes

published: May 12, 2026

Kubewarden is a policy engine for Kubernetes. Prior to , An attacker with privileged AdmissionPolicy or AdmissionPolicyGroup create permissions (which isn't the default) can craft a policy that makes use of the can_i host callback. The callback issues a SubjectAccessReview (SAR) requests to enumerat…
CWE: CWE-862
NVD

MEDIUM
CVE-2026-42565
CVE-2026-42565
pkg: oauth

published: May 11, 2026

@workos/authkit-session is a toolkit for building WorkOS AuthKit framework integrations. Prior to 0.5.1, an open redirect vulnerability exists in AuthService.handleCallback due to insufficient validation of the returnPathname value derived from the OAuth state parameter. The state parameter is round…
CWE: CWE-601
GitHub-GHSA

MEDIUM
oxidize-pdf: NaN/inf bypass in colour content-stream emission causes PDF rejection (DoS)
GHSA-88q9-cmp2-c2vq
pkg: oxidize-pdf, OxidizePdf.NET, oxidize-pdf
eco: pip
published: May 11, 2026
### Impact

`oxidize-pdf` defines `Color` as a `pub enum` with public tuple-struct variants `Rgb(f64, f64, f64)`, `Gray(f64)`, and `Cmyk(f64, f64, f64, f64)`. The constructors `Color::rgb`, `Color::gray`, and `Color::cmyk` clamp incoming
components to `[0.0, 1.0]`, but because the variants are `…

GitHub-GHSA

MEDIUM
arnika is affected by medium-severity issues in UDP rotation, PQC handling, and KMS TLS
GHSA-rc6v-5rmx-w5mv
pkg: github.com/arnika-project/arnika
eco: go
published: May 15, 2026
### Summary
Three medium-severity issues in arnika affecting the UDP key-rotation protocol, PQC key file handling, and KMS TLS client. All require specific preconditions to exploit and do not allow direct code execution or immediate key extraction. A self-contained PoC is attached.

### Details
1) A…

GitHub-GHSA

MEDIUM
rkyv: Panic safety bugs in `InlineVec::clear` and `SerVec::clear` enable arbitrary code execution
GHSA-vfvv-c25p-m7mm
pkg: rkyv
eco: rust
published: May 15, 2026
`InlineVec::clear()` and `SerVec::clear()` in `rkyv` were not panic-safe. Both functions iterate over their elements and call `drop_in_place` on each, updating `self.len` only *after* the loop. If an element's `Drop` implementation panics during the loop, `self.len` is left at its original value.

A…

GitHub-GHSA

MEDIUM
slack-go `SecretsVerifier` accepts empty signing secret without precondition
GHSA-gxhx-2686-5h9g
pkg: github.com/slack-go/slack
eco: go
published: May 14, 2026
“`go
func NewSecretsVerifier(header http.Header, secret string) (SecretsVerifier, error) {
hash := hmac.New(sha256.New, []byte(secret)) // raw secret, no precondition
}
“`
GitHub-GHSA

MEDIUM
Svelte: SSR XSS via Insecure Promise Serialization in hydratable
GHSA-f3cj-j4f6-wq85
pkg: svelte
eco: npm
published: May 14, 2026
Contents of `hydratable` promises were not properly stringified, potentially leading to an XSS exploit. You are vulnerable if all of the following is true:
– you are using `hydratable` (an experimental feature at the time of this report)
– you are passing attacker-controlled input such that a synchr…
GitHub-GHSA

MEDIUM
electerm's encrypt method not safe enough
GHSA-g29v-q6h7-76wh
pkg: electerm
eco: npm
published: May 14, 2026
### Impact
_Insecure sync encryption: deterministic AES-192-CBC with a fixed zero IV, constant KDF salt, and no MAC leads to confidentiality and integrity failures for synced bookmark/profile data. Attackers can crack common passwords across installs and perform undetected ciphertext bit-flips to al…
CVE-2026-45787
GitHub-GHSA

MEDIUM
Svelte Vulnerable to XSS via DOM Clobbering of Internal Framework State
GHSA-rcqx-6q8c-2c42
pkg: svelte
eco: npm
published: May 14, 2026
Svelte was vulnerable to DOM clobbering of its internal framework state on elements, potentially leading to XSS attacks.

You are vulnerable if all of the following is true:
– you are using attribute spreading on a form element
– you are using attribute spreading or allow a dynamic value for the `na…

CVE-2026-42573
GitHub-GHSA

MEDIUM
Svelte: ReDoS in `<svelte:element>` Tag Validation
GHSA-9rmh-mm8f-r9h6
pkg: svelte
eco: npm
published: May 14, 2026
An internal regex in the Svelte runtime can take exponential time to test in `<svelte:element this={tag}></svelte:element>`. You are only vulnerable to this if you allow tags of unconstrained length. If your application only allows a predetermined list of tags or trims their length before passing th…
CVE-2026-42567
GitHub-GHSA

MEDIUM
Open WebUI Has Stored Cross-Site Scripting in SVG Renderer
GHSA-r29h-37fj-x2w6
pkg: open-webui
eco: npm
published: May 14, 2026
### Summary
There is a Cross-Site Scripting vulnerability in Open WebUI SVG renderer implementation.

### Details

It is possible permanently save any HTML/JavaScript code in the application, which can be then executed in the context of the application domain. This behaviour can be used to extract …

CVE-2026-45346
GitHub-GHSA

MEDIUM
Svelte SSR vulnerable to cross-site scripting via spread attributes
GHSA-pr6f-5x2q-rwfp
pkg: svelte
eco: npm
published: May 14, 2026
When using spread syntax to render attributes from untrusted data, event handler properties are included in the rendered HTML output. If an application spreads user-controlled or external data as element attributes, an attacker can inject malicious event handlers that execute in victims' browsers. N…
CVE-2026-42599
GitHub-GHSA

MEDIUM
Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin
GHSA-3vcp-chfh-f6r2
pkg: github.com/kumahq/kuma, github.com/kumahq/kuma, github.com/kumahq/kuma
eco: go
published: May 14, 2026
## Summary

Default `kuma-cp` config leaks the admin bootstrap token and signing keys to any webpage the operator visits while the control plane is reachable from their browser. `CorsAllowedDomains: [".*"]` reflects any `Origin`, and `LocalhostIsAdmin: true` promotes requests from `127.0.0.1` to `me…

CVE-2026-45021
GitHub-GHSA

MEDIUM
TanStack Start – Server Core: Inbound server-function request deserialization could invoke a sibling client-referenced server function
GHSA-9m65-766c-r333
pkg: @tanstack/start-server-core
eco: npm
published: May 14, 2026
### Summary
A type-confusion bug in seroval ≤ 1.5.2 ([upstream advisory](https://github.com/lxsmnsyc/seroval/security/advisories)) allowed a crafted JSON body sent to one TanStack Start server function to trigger invocation of a different client-referenced server function as a side effect of deser…
GitHub-GHSA

MEDIUM
Portainer missing authorization on custom template file endpoint, which exposes template content
GHSA-cqpq-2fgr-8mvc
pkg: github.com/portainer/portainer, github.com/portainer/portainer
eco: go
published: May 14, 2026
## Summary
A missing authorization vulnerability in the Custom Template file endpoint (`GET /api/custom_templates/{id}/file`) allows any authenticated user to read the file content of any custom template by enumerating sequential integer IDs, bypassing Resource Control access restrictions. Template …
CVE-2026-44884
GitHub-GHSA

MEDIUM
Synapse pagination Denial of Service
GHSA-6qf2-7×63-mm6v
pkg: matrix-synapse
eco: pip
published: May 14, 2026
### Impact

In federated rooms, malicious homeservers can craft room events in such a way that prevents Synapse from providing full history to paginating clients.

Clients could therefore fail to display room history.

### Patches

Update to Synapse 1.152.1 or later.

### Workarounds

There are no k…

CVE-2026-45076
GitHub-GHSA

MEDIUM
Fleet: IP spoofing allows bypassing API rate limiting
GHSA-mxmp-wr3w-rvqx
pkg: github.com/fleetdm/fleet/v4
eco: go
published: May 14, 2026
### Summary
A vulnerability in Fleet's IP extraction logic allows unauthenticated attackers to bypass API rate limiting by spoofing client IP headers. This may allow brute-force login attempts or other abuse against Fleet instances exposed to the public internet.

### Impact
Fleet extracted client I…

CVE-2026-46356
GitHub-GHSA

MEDIUM
Fleet vulnerable to OS command injection in software packages
GHSA-9vcr-g537-3w5v
pkg: github.com/fleetdm/fleet/v4
eco: go
published: May 14, 2026
### Summary

A vulnerability in Fleet's software installer pipeline could allow a crafted software package to execute arbitrary commands as root (macOS/Linux) or SYSTEM (Windows) on managed endpoints when an uninstall is triggered.

### Impact

When a software package (.pkg, .deb, .rpm, .exe, or .ms…

CVE-2026-26191
GitHub-GHSA

MEDIUM
Strapi Upload Plugin MIME Validation Bypass via Content API
GHSA-pcw7-5633-82vv
pkg: @strapi/upload
eco: npm
published: May 14, 2026
### Summary of CVE-2026-22707 Vulnerability Details

– CVE: CVE-2026-22707
– CVSS v3.1 Vector: `CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N` (5.3 — Medium)
– Affected Versions: `@strapi/upload` <=5.33.2
– How to Patch: Immediately update your Strapi to >=5.33.3

### Description…

CVE-2026-22707
GitHub-GHSA

MEDIUM
Strapi has a rate limit bypass on users-permissions plugin via attacker-controlled email keying
GHSA-7mqx-wwh4-f9fw
pkg: @strapi/plugin-users-permissions
eco: npm
published: May 13, 2026
### Summary of CVE-2025-64526 Vulnerability Details

– CVE: CVE-2025-64526
– CVSS v3.1 Vector: `CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N` (6.9 — Medium)
– Affected Versions: `@strapi/plugin-users-permissions` <=5.44.0
– How to Patch: Immediately update your Strapi to >=5.45.…

CVE-2025-64526
GitHub-GHSA

MEDIUM
Traefik: Gateway API TraefikService backend accepts rest@internal, allowing unauthorized exposure of the REST provider despite providers.rest.insecure=false
GHSA-96qj-4jj5-wcjc
pkg: github.com/traefik/traefik/v3, github.com/traefik/traefik/v3, github.com/traefik/traefik/v2
eco: go
published: May 13, 2026
## Summary

There is a medium severity vulnerability in Traefik's Kubernetes Gateway API provider that allows a tenant with `HTTPRoute` creation permissions to expose the REST provider handler, bypassing the `providers.rest.insecure=false` setting. The Gateway provider accepts any `TraefikService` b…

CVE-2026-44774
GitHub-GHSA

MEDIUM
OpenLearnX: Critical Authentication Bypass via JWT Signature Verification Disabled Leading to Account Takeover
GHSA-223g-f5mq-gw33
pkg: openlearnx
eco: npm
published: May 13, 2026
### Overview

A critical authentication vulnerability was identified in OpenLearnX that could allow unauthorized access to user accounts under specific conditions. The issue has been fixed.

**Advisory**: https://github.com/th30d4y/OpenLearnX/security/advisories/GHSA-223g-f5mq-gw33

CVE-2026-44720
GitHub-GHSA

MEDIUM
SillyTavern has a SSRF vulnerability in the CORS proxy middleware
GHSA-ccfq-2454-f5xw
pkg: sillytavern
eco: npm
published: May 12, 2026
## Resolution

SillyTavern 1.18.0 added a generic server-side request filter (Private Request Whitelisting). Since we expect users to use the application in a trusted environment, the filter is disabled by default, however it is strongly advised to be enabled and properly configured when an instance…

CVE-2026-44652
GitHub-GHSA

MEDIUM
SillyTavern has a reflected XSS vulnerability in the CORS proxy middleware
GHSA-xc4x-2452-5gc9
pkg: sillytavern
eco: npm
published: May 12, 2026
## Resolution

Fixed in SillyTavern 1.18.0: a user-provided URL is no longer reflected in the HTTP response body.

## Overview
– Vulnerability Type: XSS
– Affected Location: `src/middleware/corsProxy.js:40`
– Trigger Scenario: reflected XSS in CORS proxy error response

## Root Cause
When `fetch(url…

CVE-2026-44651
GitHub-GHSA

MEDIUM
Mermaid: Improper sanitization of configuration leads to CSS injection
GHSA-87f9-hvmw-gh4p
pkg: mermaid, mermaid
eco: npm
published: May 11, 2026
### Impact

Mermaid's default configuration allows injecting CSS that applies outside of the Mermaid diagram via the `fontFamily`, `themeCSS`, and `altFontFamily` configuration options.

Live demo: [mermaid.live](https://mermaid.live/edit#pako:eNpNjktLxDAUhf9KvFBR6JS-60QQfODKlUvJ5k6TtsEmKTHFGUP-u-mI…

CVE-2026-41159
GitHub-GHSA

MEDIUM
Mermaid Gantt Charts are vulnerable to an Infinite Loop DoS
GHSA-6m6c-36f7-fhxh
pkg: mermaid, mermaid
eco: npm
published: May 11, 2026
### Impact

Mermaid v11.14.0 and earlier are vulnerable to a denial-of-service attack when rendering gantt charts, if they use the [`excludes` attribute](https://mermaid.js.org/syntax/gantt.html?#excludes) to exclude all dates.

Example:

“`
gantt
excludes monday,tuesday,wednesday,thursday,friday…

CVE-2026-41150
GitHub-GHSA

MEDIUM
Mermaid: Improper sanitization of `classDef` in state diagrams leads to HTML injection
GHSA-ghcm-xqfw-q4vr
pkg: mermaid, mermaid
eco: npm
published: May 11, 2026
### Impact

Under the default configuration, Mermaid state diagram's `classDef` allow DOM injection that escapes the SVG, although `<script>` tags are removed, preventing XSS.

#### Proof-of-concept

“`
stateDiagram-v2
classDef xss fill:red</style></svg><style>*{x:x;y:y;overflow:visible!important…

CVE-2026-41149
GitHub-GHSA

MEDIUM
Mermaid: Improper sanitization of `classDefs` in diagrams leads to CSS injection
GHSA-xcj9-5m2h-648r
pkg: mermaid, mermaid
eco: npm
published: May 11, 2026
### Details

The state diagram and any other diagram type that routes user-controlled style strings through createCssStyles parser for Mermaid v11.14.0 and earlier captures `classDef` values with an unrestricted regex:

“`jison
// packages/mermaid/src/diagrams/state/parser/stateDiagram.jison:83
<CL…

CVE-2026-41148
GitHub-GHSA

MEDIUM
Steamworks game clients/servers using P2P authentication vulnerable to denial of service
GHSA-g588-cjg3-6g78
pkg: steamworks
eco: rust
published: May 11, 2026
Processing the raw `ValidateAuthTicketResponse_t` callback data panics when the `m_eAuthSessionResponse` field is `k_EAuthSessionResponseAuthTicketNetworkIdentityFailure`. This can lead to denial of service in game clients and servers using the `begin_authentication_session` API to authenticate play…


Vulnerability Digest — May 11, 2026 · 99 Critical · 3 Exploited






Vulnerability Digest — Monday, May 11, 2026


Security Report

Monday, May 11, 2026  ·  Last 7 days  ·  Min severity: MEDIUM
Total Findings
557
Critical
99
High
259
Actively Exploited
3
CISA-KEV3
NVD179
GitHub-GHSA375
Findings sorted by severity
CISA-KEV

CRITICAL
BerriAI LiteLLM SQL Injection Vulnerability
CVE-2026-42208
pkg: BerriAI LiteLLM

published: May 8, 2026

BerriAI LiteLLM contains a SQL injection vulnerability that allows an attacker to read data from the proxy's database and potentially modify it, leading to unauthorised access to the proxy and the credentials it manages.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability
CVE-2026-6973
pkg: Ivanti Endpoint Manager Mobile (EPMM)

published: May 7, 2026

Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with administrative access to achieve remote code execution.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability
CVE-2026-0300
pkg: Palo Alto Networks PAN-OS

published: May 6, 2026

Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted pa…
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Until the vendor releases an official fix, the following workaround should be implemented: – Restrict User-ID Authentication Portal access to only trusted zones. – Disable User-ID Authentication Portal if not required.
NVD

CRITICAL
CVE-2026-42298
CVE-2026-42298
pkg: docker

published: May 8, 2026

Postiz is an AI social media scheduling tool. Prior to commit da44801, a "Pwn Request" vulnerability in the Build and Publish PR Docker Image workflow (.github/workflows/pr-docker-build.yml) allows any unauthenticated user to execute arbitrary code during the Docker build process and exfiltrate a hi…
CWE: CWE-94
GitHub-GHSA

CRITICAL
free5GC's NEF nnef-pfdmanagement API is unauthenticated; forged bearer tokens can read PFD data and create/delete PFD subscriptions
GHSA-rwww-x45w-p52w
pkg: github.com/free5gc/nef
eco: go
published: May 8, 2026
### Summary
free5GC's NEF mounts the `nnef-pfdmanagement` route group without inbound OAuth2/bearer-token authorization. A network attacker who can reach NEF on the SBI can use a forged or arbitrary bearer token (e.g. `Authorization: Bearer not-a-real-token`) to read PFD application data via `GET /a…
CVE-2026-44330
GitHub-GHSA

CRITICAL
free5GC's SMF UPI management interface lacks auth middleware; unauthenticated topology read/write requests reach handlers
GHSA-3258-qmv8-frp3
pkg: github.com/free5gc/smf
eco: go
published: May 8, 2026
### Summary
free5GC's SMF mounts the `UPI` management route group without OAuth2/bearer-token authorization middleware. A network attacker who can reach SMF on the SBI can hit `UPI` endpoints with no `Authorization` header at all, and the requests reach the SMF business handlers. In the running Dock…
CVE-2026-44329
GitHub-GHSA

CRITICAL
free5GC's NEF nnef-oam route group is unauthenticated; no-token requests reach the OAM handler
GHSA-cmpj-2x3g-m7g3
pkg: github.com/free5gc/nef
eco: go
published: May 8, 2026
### Summary
free5GC's NEF mounts the `nnef-oam` route group without inbound OAuth2/bearer-token authorization. A network attacker who can reach NEF on the SBI can hit the OAM route with no `Authorization` header at all and the handler returns `200 OK`. The current OAM handler is a stub that returns …
CVE-2026-44327
GitHub-GHSA

CRITICAL
Note Mark has a JWT Secret Weakness that allows Full Account Takeover via Token Forgery
GHSA-q6mh-rqwh-g786
pkg: github.com/enchant97/note-mark/backend
eco: go
published: May 7, 2026
#### Summary

No minimum length or entropy is enforced on the `JWT_SECRET` configuration value. The application accepts any base64-decodable secret regardless of size, including secrets as short as 1 byte.

HS256 secrets below 32 bytes are brute-forceable offline, allowing attackers to recover the s…

CVE-2026-44523
NVD

CRITICAL
CVE-2026-33587
CVE-2026-33587
pkg: lfnovo open-notebook

published: May 7, 2026

Lack of user input sanitisation in Open Notebook v1.8.3 allows the application user to execute Python code (and subsequently OS commands) on the docker container via Server-Side Template Injection (SSTI) for user-created transformations.
CWE: CWE-20
GitHub-GHSA

CRITICAL
vm2: Mutable Proxies for Host Intrinsic Prototypes Allows Sandbox Escape
GHSA-vwrp-x96c-mhwq
pkg: vm2
eco: npm
published: May 7, 2026
### Summary
vm2's bridge exposes mutable proxies for real host-realm intrinsic prototypes and then forwards sandbox writes into the underlying host objects with otherReflectSet() and otherReflectDefineProperty(), which lets attacker-controlled JavaScript running in a default VM or inherited NodeVM m…
CVE-2026-44005
GitHub-GHSA

CRITICAL
vm2 Access to Host Object Enables Sandbox Escape
GHSA-47×8-96vw-5wg6
pkg: vm2
eco: npm
published: May 7, 2026
### Summary

It is possible to obtain the host `Object`, https://github.com/patriksimek/vm2/commit/ebcfe94ad2f864f0bc35e78cff1d921107cfd160 added some protections, but the implementation is incomplete.

### Details

There are various ways to use the host `Object`, to escape the sandbox, one example …

CVE-2026-43997
GitHub-GHSA

CRITICAL
vm2 has a Sandbox Escape Vulnerability
GHSA-qcp4-v2jj-fjx8
pkg: vm2
eco: npm
published: May 7, 2026
### Summary

It is possible to reach `BaseHandler.getPrototypeOf`, which can be used to get arbitrary prototypes

### Details

https://github.com/patriksimek/vm2/blob/408fc855f1cc1bbc2985b029465ee0e732ada433/lib/bridge.js#L655-L658

`BaseHandler` can be reached via `util.inspect` (same as https://gi…

CVE-2026-44006
NVD

CRITICAL
CVE-2026-40281
CVE-2026-40281
pkg: docker

published: May 6, 2026

Gotenberg is a Docker-powered stateless API for PDF files. In versions 8.30.1 and earlier, the metadata write endpoint validates metadata keys for control characters but leaves metadata values unsanitized. A newline character in a metadata value splits the ExifTool stdin line into two separate argum…
CWE: CWE-88
NVD

CRITICAL
CVE-2026-42454
CVE-2026-42454
pkg: docker

published: May 8, 2026

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.1.0, all Docker container management endpoints in Termix interpolate the containerId URL path parameter and WebSocket message field directly into shell commands executed v…
CWE: CWE-78
GitHub-GHSA

CRITICAL
vm2 has a NodeVM builtin allowlist bypass via `module` builtin's `Module._load` that allows sandbox escape
GHSA-947f-4v7f-x2v8
pkg: vm2
eco: npm
published: May 7, 2026
## Summary
NodeVM's `builtin` allowlist can be bypassed when the `module` builtin is allowed (including via the `'*'` wildcard). The `module` builtin exposes Node's `Module._load()`, which loads any module by name directly in the host context, completely bypassing vm2's builtin restriction. This all…
CVE-2026-43999
GitHub-GHSA

CRITICAL
Fleet: Helm impersonation bypass of `RESTClientGetter` retains `cluster-admin` during template rendering
GHSA-765j-qfrp-hm3j
pkg: github.com/rancher/fleet, github.com/rancher/fleet, github.com/rancher/fleet
eco: go
published: May 7, 2026
### Impact

Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git push access to a Fleet-monitored repository to read secrets from any namespace on every downstream cluster targeted by their `GitRepo`.

**Helm `lookup` bypass:** The Helm…

CVE-2026-41050
GitHub-GHSA

CRITICAL
wger: cross-tenant password reset and plaintext disclosure via gym=None bypass
GHSA-mhc8-p3jx-84mm
pkg: wger
eco: pip
published: May 6, 2026
### Summary

The `reset_user_password` and `gym_permissions_user_edit` views in wger perform a gym-scope authorization check using Python object comparison (`!=`) that evaluates `None != None` as `False`, silently bypassing the guard when both the attacker and victim have no gym assignment (`gym=Non…

CVE-2026-43948
GitHub-GHSA

CRITICAL
Rucio has SQL Injection in FilterEngine PostgreSQL Query Builder via DID Search API
GHSA-6j7p-qjhg-9947
pkg: rucio, rucio, rucio
eco: pip
published: May 6, 2026
### Summary

A SQL injection vulnerability in `FilterEngine.create_postgres_query` allows any authenticated Rucio user to execute arbitrary SQL against the configured PostgreSQL metadata database through the DID search endpoint (`GET /dids/<scope>/dids/search`). When the external metadata plugin `po…

CVE-2026-29090
GitHub-GHSA

CRITICAL
Rucio has SQL Injection in FilterEngine Oracle JSON Path via DID Search API
GHSA-vjr5-c9qv-hgm3
pkg: rucio, rucio, rucio
eco: pip
published: May 6, 2026
### Summary

A SQL injection vulnerability in the Oracle path of `FilterEngine.create_sqla_query` allows any authenticated Rucio user to execute arbitrary SQL against the backend database through the DID search endpoint (`GET /dids/<scope>/dids/search`). Attacker-controlled filter keys and values ar…

CVE-2026-29080
GitHub-GHSA

CRITICAL
Apache Polaris has an Improper Input Validation Issue
GHSA-vxgg-mqx2-3w59
pkg: org.apache.polaris:polaris-core
eco: maven
published: May 4, 2026
Apache Polaris accepts literal `*` characters in namespace and table names. When it later builds temporary S3 access policies for delegated table access, those same characters appear to be reused unescaped in S3 IAM resource patterns and `s3:prefix` conditions.

In S3 IAM policy matching, `*` is tre…

CVE-2026-42810
GitHub-GHSA

CRITICAL
Apache Polaris has an Improper Input Validation Issue
GHSA-8ggj-j522-h5qf
pkg: org.apache.polaris:polaris-runtime-service
eco: maven
published: May 4, 2026
Apache Polaris can issue broad temporary ("vended") storage credentials during staged table creation before the effective table location has been validated or durably reserved. Those temporary credentials are meant to limit the scope of accessible table data and metadata, but this scope limitation b…
CVE-2026-42809
GitHub-GHSA

CRITICAL
Apache Polaris has an Improper Input Validation issue
GHSA-w76p-3cgp-qfcm
pkg: org.apache.polaris:polaris-runtime-service
eco: maven
published: May 4, 2026
In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table and which table version to read.

`write.metadata.path` is an optional table property that tells Polaris where to write those metadata files. For a table already registered in a Po…

CVE-2026-42812
GitHub-GHSA

CRITICAL
Apache Polaris has an Improper Input Validation issue
GHSA-fc3h-c6h7-r83j
pkg: org.apache.polaris:polaris-core
eco: maven
published: May 4, 2026
In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, but a crafted namespace or table name can cause those credentials to work across the configured bucket instead.

Apache Polaris builds Google Cloud Storage downscoped credentials by …

CVE-2026-42811
NVD

CRITICAL
CVE-2026-42811
CVE-2026-42811
pkg: express

published: May 4, 2026

In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials
that
only work for one table's files, but a crafted namespace or table name can
cause those credentials to work across the configured bucket instead.

Apache Polaris builds Google Cloud Storage downscoped credentials by…

CWE: CWE-20, CWE-917
GitHub-GHSA

CRITICAL
@profullstack/mcp-server vulnerable to OS Command Injection in domain_lookup Module
GHSA-v6wj-c83f-v46x
pkg: @profullstack/mcp-server
eco: npm
published: May 9, 2026
<html>
<body>
<!–StartFragment–><html><head></head><body><h1>Security Advisory: OS Command Injection in <code>profullstack/mcp-server</code> <code>domain_lookup</code> Module</h1>

Field | Value
— | —
Project | profullstack/mcp-server
Repository | https://github.com/profullstack/mcp-server
Affec…

GitHub-GHSA

CRITICAL
Electerm runWidget has a path traversal that leads to arbitrary code execution
GHSA-f77v-9vpc-6pjm
pkg: electerm
eco: npm
published: May 8, 2026
### Impact
The `runWidget` function in `src/app/widgets/load-widget.js` constructs a file path by directly concatenating user‑supplied widget identifiers without any sanitisation:

“`javascript
const file = `widget-${widgetId}.js`
const widget = require(path.join(__dirname, file))
“`

Because `r…

CVE-2026-43940
GitHub-GHSA

CRITICAL
vm2 has Sandbox Breakout Through Null Proto Exception
GHSA-9vg3-4rfj-wgcm
pkg: vm2
eco: npm
published: May 8, 2026
### Summary

VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system.

### Details

In `handleException` due to “// SECURITY (post-GHSA-mpf8 hardening): use `from` (not `ensureThis…

CVE-2026-44009
GitHub-GHSA

CRITICAL
vm2 has sandbox breakout via `neutralizeArraySpeciesBatch`
GHSA-9qj6-qjgg-37qq
pkg: vm2
eco: npm
published: May 8, 2026
### Summary

VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system.

### Details

The new method `neutralizeArraySpeciesBatch` works with objects from the other side but can call …

CVE-2026-44008
NVD

CRITICAL
CVE-2026-43402
CVE-2026-43402
pkg: node

published: May 8, 2026

In the Linux kernel, the following vulnerability has been resolved:

kthread: consolidate kthread exit paths to prevent use-after-free

Guillaume reported crashes via corrupted RCU callback function pointers
during KUnit testing. The crash was traced back to the pidfs rhashtable
conversion which rep…

NVD

CRITICAL
CVE-2026-41507
CVE-2026-41507
pkg: express

published: May 8, 2026

math-codegen generates code from mathematical expressions. Prior to version 0.4.3, string literal content passed to cg.parse() is injected verbatim into a new Function() body without sanitization. This allows an attacker to execute arbitrary system commands when user-controlled input reaches the par…
CWE: CWE-94
NVD

CRITICAL
CVE-2026-41497
CVE-2026-41497
pkg: praison praisonai

published: May 8, 2026

PraisonAI is a multi-agent teams system. Prior to version 4.6.9, the fix for PraisonAI's MCP command handling does not add a command allowlist or argument validation to parse_mcp_command(), allowing arbitrary executables like bash, python, or /bin/sh with inline code execution flags to pass through …
CWE: CWE-77, CWE-78
NVD

CRITICAL
CVE-2023-46453
CVE-2023-46453
pkg: express

published: May 8, 2026

Certain GL.iNet devices with 4.x firmware allow authentication bypass (resulting in administrative control of the device) via a username that is both a valid SQL statement and a valid regular expression. For example, this affects version 4.3.7 on GL-MT3000 GL-AR300M GL-B1300 GL-AX1800 GL-AR750S GL-M…
CWE: CWE-89
GitHub-GHSA

CRITICAL
Gotenberg has Unauthenticated RCE via ExifTool Metadata Key Injection
GHSA-rqgh-gxv4-6657
pkg: github.com/gotenberg/gotenberg/v8
eco: go
published: May 7, 2026
# Unauthenticated RCE in Gotenberg via Metadata Key Newline Injection

## Summary

Gotenberg's `/forms/pdfengines/metadata/write` HTTP endpoint accepts a JSON metadata object and passes its keys directly to ExifTool via the go-exiftool library. No validation is performed on key characters. A `\n` em…

CVE-2026-42589
NVD

CRITICAL
CVE-2026-41930
CVE-2026-41930
pkg: docker

published: May 6, 2026

Vvveb before version 1.0.8.2 contains a hard-coded credentials vulnerability in its docker-compose-apache.yaml configuration that allows unauthenticated attackers to access the bundled phpMyAdmin container with pre-configured database credentials. Attackers can connect to the phpMyAdmin port to gain…
CWE: CWE-306
GitHub-GHSA

CRITICAL
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore
GHSA-4pvg-prr3-9cxr
pkg: github.com/0xJacky/nginx-ui
eco: go
published: May 6, 2026
**Product:** nginx-ui
**Repository:** `0xJacky/nginx-ui` (branch: `dev`)
**Vulnerability Class:** Authentication Bypass → Arbitrary File Write → OS Command Injection
**Affected Component:** `POST /api/restore`

## 1. Vulnerability Summary

nginx-ui exposes a backup restore endpoint (`POST /…

CVE-2026-42238
NVD

CRITICAL
CVE-2026-43186
CVE-2026-43186
pkg: node

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

ipv6: ioam: fix heap buffer overflow in __ioam6_fill_trace_data()

On the receive path, __ioam6_fill_trace_data() uses trace->nodelen
to decide how much data to write for each node. It trusts this field
as-is from the incoming pack…

NVD

CRITICAL
CVE-2026-35579
CVE-2026-35579
pkg: coredns.io coredns

published: May 5, 2026

CoreDNS is a DNS server written in Go. In versions prior to 1.14.3, the gRPC, QUIC, DoH, and DoH3 transport implementations incorrectly handle TSIG authentication. For gRPC and QUIC, the server checks whether the TSIG key name exists in the configuration but never calls dns.TsigVerify() to validate …
CWE: CWE-287
NVD

CRITICAL
CVE-2026-38428
CVE-2026-38428
pkg: kestra kestra

published: May 5, 2026

Kestra v1.3.3 and before is vulnerable to SQL Injection. The vulnerability occurs because user-controlled input from a GET parameter is directly concatenated into an SQL query without proper sanitization or parameterization. As a result, attackers can inject arbitrary SQL expressions into the databa…
CWE: CWE-89
NVD

CRITICAL
CVE-2026-38431
CVE-2026-38431
pkg: frappe erpnext

published: May 5, 2026

ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or edit email templates can inject template expressions that are executed on the server when the template is rendered.
CWE: CWE-94
GitHub-GHSA

CRITICAL
VM2 Has a WASM Sandbox Escape (Node 25 only)
GHSA-ffh4-j6h5-pg66
pkg: vm2
eco: npm
published: May 5, 2026
## Summary

Full sandbox escape with arbitrary code execution. Attacker code inside `VM.run()` obtains host process object and runs host commands with zero host cooperation.

## Details

**Confirmed on:** vm2 3.10.4, Node.js v25.6.1 (x64 Linux)
**Trigger:** Attacker-controlled code passed to `VM.run…

CVE-2026-26956
GitHub-GHSA

CRITICAL
VM2 Has a Sandbox Escape Issue via SuppressedError
GHSA-55hx-c926-fr95
pkg: vm2
eco: npm
published: May 5, 2026
In vm2 v3.10.4 on Node.js v24.13.0, `SuppressedError` allows attackers to escape the sandbox and run arbitrary code.

### PoC
“`js
const { VM } = require("vm2");

const vm = new VM();

vm.run(`
const ds = new DisposableStack();
ds.defer(() => { throw null; });
ds.defer(() => {
const e = Error();

CVE-2026-26332
GitHub-GHSA

CRITICAL
VM2 Has Sandbox Breakout Through Inspect Function
GHSA-v37h-5mfm-c47c
pkg: vm2
eco: npm
published: May 5, 2026
### Summary

VM2 suffers from a sandbox breakout vulnerability through the `inspect` function. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system.

### Details

The node `inspect` method allows to log details of objects. To get…

CVE-2026-24781
GitHub-GHSA

CRITICAL
VM2 Has Sandbox Breakout Through Promise Species
GHSA-qvjj-29qf-hp7p
pkg: vm2
eco: npm
published: May 5, 2026
### Summary

The fix for https://github.com/patriksimek/vm2/security/advisories/GHSA-cchq-frgv-rjh5 is insufficient and can be circumvented allowing attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system.

### Details

The fix for https://gith…

CVE-2026-24120
NVD

CRITICAL
CVE-2026-43067
CVE-2026-43067
pkg: linux

published: May 5, 2026

In the Linux kernel, the following vulnerability has been resolved:

ext4: handle wraparound when searching for blocks for indirect mapped blocks

Commit 4865c768b563 ("ext4: always allocate blocks only from groups
inode can use") restricts what blocks will be allocated for indirect
block based file…

NVD

CRITICAL
CVE-2026-42238
CVE-2026-42238
pkg: nginxui nginx_ui

published: May 4, 2026

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, nginx-ui exposes a backup restore endpoint (POST /api/restore) that is completely unauthenticated during the first 10 minutes after process startup on any fresh installation. An unauthenticated remote attacker can upl…
CWE: CWE-94
NVD

CRITICAL
CVE-2026-42233
CVE-2026-42233
pkg: n8n n8n

published: May 4, 2026

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the Oracle Database node's select operation allowed user-controlled input passed into the Limit field via expressions to be interpolated directly into the SQL query without sanitization or p…
CWE: CWE-89
GitHub-GHSA

CRITICAL
Apache OpenNLP ExtensionLoader Vulnerable to Arbitrary Class Instantiation via Model Manifest
GHSA-cx4m-2p55-rw7j
pkg: org.apache.opennlp:opennlp-tools, org.apache.opennlp:opennlp-tools
eco: maven
published: May 4, 2026
Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader

Versions Affected: before 2.5.9, before 3.0.0-M3

Description: 

The ExtensionLoader.instantiateExtension(Class, String) method loads a class by its fully-qualified name via Class.forName() and invokes its…

CVE-2026-42027
NVD

CRITICAL
CVE-2026-42796
CVE-2026-42796
pkg: python

published: May 4, 2026

Arelle before 2.39.10 contains an unauthenticated remote code execution vulnerability in the /rest/configure REST endpoint that accepts a plugins query parameter and forwards it to the plugin manager without authentication or authorization. Attackers can supply a URL to a malicious Python file throu…
CWE: CWE-306
NVD

CRITICAL
CVE-2026-42076
CVE-2026-42076
pkg: curl

published: May 4, 2026

Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a command injection vulnerability in the _extractLLM() function allows attackers to execute arbitrary shell commands on the server. The function constructs a curl command using string concatenation and passes it to…
CWE: CWE-78
NVD

CRITICAL
CVE-2026-26956
CVE-2026-26956
pkg: vm2_project vm2

published: May 4, 2026

vm2 is an open source vm/sandbox for Node.js. In version 3.10.4, vm2 is vulnerable to full sandbox escape with arbitrary code execution. Attacker code inside VM.run() obtains host process object and runs host commands with zero host cooperation. This issue has been patched in version 3.10.5.
CWE: CWE-693
NVD

CRITICAL
CVE-2026-26332
CVE-2026-26332
pkg: vm2_project vm2

published: May 4, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, SuppressedError allows attackers to escape the sandbox and run arbitrary code. This issue has been patched in version 3.11.0.
CWE: CWE-94, CWE-693
NVD

CRITICAL
CVE-2026-24781
CVE-2026-24781
pkg: vm2_project vm2

published: May 4, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability through the inspect function. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system. This issue has been patc…
CWE: CWE-94, CWE-693
NVD

CRITICAL
CVE-2026-24120
CVE-2026-24120
pkg: vm2_project vm2

published: May 4, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.10.5, the fix for CVE-2023-37466 is insufficient and can be circumvented allowing attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system. This issue has been patched in version 3…
CWE: CWE-94, CWE-693
NVD

CRITICAL
CVE-2026-24118
CVE-2026-24118
pkg: vm2_project vm2

published: May 4, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system. This issue has been patched in version 3.11.0.
CWE: CWE-94, CWE-693
GitHub-GHSA

CRITICAL
Cline Kanban Server has a Cross-Origin WebSocket Hijacking Vulnerability
GHSA-5c57-rqjx-35g2
pkg: cline
eco: npm
published: May 8, 2026
## Summary

The `kanban` npm package (used by the `cline` CLI) starts a WebSocket server on `127.0.0.1:3484` with no Origin header validation. Any website a developer visits can silently connect to the kanban server via WebSocket and:

1. Leak sensitive data in real-time: workspace filesystem paths,…

CVE-2026-44211
NVD

CRITICAL
CVE-2026-44336
CVE-2026-44336
pkg: praison praisonai

published: May 8, 2026

PraisonAI is a multi-agent teams system. Prior to version 4.6.34, PraisonAI's MCP (Model Context Protocol) server (praisonai mcp serve) registers four file-handling tools by default — praisonai.rules.create, praisonai.rules.show, praisonai.rules.delete, and praisonai.workflow.show. Each accepts a …
CWE: CWE-20, CWE-22, CWE-94, CWE-829, CWE-913
NVD

CRITICAL
CVE-2026-42880
CVE-2026-42880
pkg: kubernetes

published: May 7, 2026

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.0 to before 3.3.9, there is a missing authorization and data-masking gap in Argo CD's ServerSideDiff endpoint that allows an attacker with read-only access to extract plaintext Kube…
CWE: CWE-200, CWE-212
GitHub-GHSA

CRITICAL
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction
GHSA-3v3m-wc6v-x4x3
pkg: github.com/argoproj/argo-cd/v3, github.com/argoproj/argo-cd/v3
eco: go
published: May 7, 2026
### Summary
There is a missing authorization and data-masking gap in Argo CD's ServerSideDiff endpoint that allows an attacker with read-only access to extract plaintext Kubernetes Secret data from etcd via the Kubernetes API server's Server-Side Apply dry-run mechanism.

### Details
Argo CD masks S…

CVE-2026-42880
NVD

CRITICAL
CVE-2026-7910
CVE-2026-7910
pkg: google chrome, apple macos, linux linux_kernel

published: May 6, 2026

Use after free in Views in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

CRITICAL
CVE-2026-7908
CVE-2026-7908
pkg: google chrome, apple macos, linux linux_kernel

published: May 6, 2026

Use after free in Fullscreen in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

CRITICAL
CVE-2026-42235
CVE-2026-42235
pkg: n8n n8n

published: May 4, 2026

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an unauthenticated attacker could register a malicious MCP OAuth client with a crafted client_name. If a victim user authorized the OAuth consent dialog and a second user subsequently revoked that acc…
CWE: CWE-79, CWE-87
NVD

CRITICAL
CVE-2026-42088
CVE-2026-42088
pkg: docker

published: May 4, 2026

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the do…
CWE: CWE-250
NVD

CRITICAL
CVE-2026-42090
CVE-2026-42090
pkg: node

published: May 4, 2026

Notesnook is a note-taking app focused on user privacy & ease of use. Prior to Notesnook Web/Desktop version 3.3.15 and prior to Notesnook iOS/Android version 3.3.20, a stored XSS vulnerability in the note export flow can be escalated to remote code execution in the desktop app. The root cause is th…
CWE: CWE-79, CWE-94
GitHub-GHSA

CRITICAL
free5GC's NEF 3gpp-traffic-influence API is unauthenticated; missing or forged bearer tokens can create, read, patch, and delete subscriptions
GHSA-3p28-73q7-45xp
pkg: github.com/free5gc/nef
eco: go
published: May 8, 2026
### Summary
free5GC's NEF mounts the `3gpp-traffic-influence` API without inbound OAuth2/bearer-token authorization. A network attacker who can reach NEF on the SBI can create, read, patch, and delete traffic-influence subscriptions either with no `Authorization` header at all, or with a forged bear…
CVE-2026-44326
GitHub-GHSA

CRITICAL
free5GC's NEF 3gpp-pfd-management API is unauthenticated; forged bearer tokens can create, read, and delete PFD transactions
GHSA-5f62-53r8-qrqf
pkg: github.com/free5gc/nef
eco: go
published: May 8, 2026
### Summary
free5GC's NEF mounts the `3gpp-pfd-management` API without inbound OAuth2/bearer-token authorization. A network attacker who can reach NEF on the SBI can create, read, and delete PFD-management transaction state with a forged or arbitrary bearer token (e.g. `Authorization: Bearer not-a-r…
CVE-2026-44315
GitHub-GHSA

CRITICAL
Gotenberg vulnerable to unauthenticated SSRF via default deny-list bypass in downloadFrom and webhook
GHSA-4vmc-gm8v-m35h
pkg: github.com/gotenberg/gotenberg/v8
eco: go
published: May 7, 2026
### Summary
The default deny-lists used by Gotenberg's `downloadFrom` feature and `webhook` feature are bypassable. Because the filter is regex-based and case-sensitive, an unauthenticated attacker can supply URLs such as `http://[::ffff:127.0.0.1]:…` and reach loopback or private HTTP services th…
CVE-2026-42596
GitHub-GHSA

CRITICAL
S3-Proxy has Security Issues in its Resource Path Matching Implementation
GHSA-rfgq-wgg8-662p
pkg: github.com/oxyno-zeta/s3-proxy
eco: go
published: May 5, 2026
## Background

The original concern is functional: a resource pattern should treat a percent-encoded segment like some%2Fvalue as a single opaque token rather than splitting it into two path segments at the decoded /. Investigation into why %2F was being decoded and how routes matched against the re…

CVE-2026-42882
GitHub-GHSA

CRITICAL
Compromised version of intercom-client published to npm
GHSA-54pg-9963-v8vg
pkg: intercom-client
eco: npm
published: May 7, 2026
### Impact

On April 30, 2026, version 7.0.4 of intercom-client was published to npm using credentials obtained from a compromised developer account. This version was not produced by Intercom's build pipeline.

The malicious version contained an obfuscated JavaScript payload that executed during pac…

NVD

CRITICAL
CVE-2026-42560
CVE-2026-42560
pkg: oauth

published: May 9, 2026

auth provides authentication via oauth2, direct and email. From versions 1.18.0 to before 1.25.2 and 2.0.0 to before 2.1.2, the Patreon OAuth provider maps every authenticated Patreon account to the same local user.ID, instead of deriving a unique ID from the Patreon account returned by Patreon. In …
CWE: CWE-287
GitHub-GHSA

CRITICAL
Open WebUI has an LDAP Empty Password Authentication Bypass
GHSA-2r4p-jpmg-48f4
pkg: open-webui
eco: pip
published: May 8, 2026
# LDAP Empty Password Authentication Bypass

## Affected Component

LDAP authentication endpoint:
– `backend/open_webui/routers/auths.py` (lines 468-477, user bind with empty password)
– `backend/open_webui/models/auths.py` (lines 58-60, `LdapForm` model)

## Affected Versions

Current main branch (…

CVE-2026-44551
NVD

CRITICAL
CVE-2026-44497
CVE-2026-44497
pkg: zfnd zebra-script, zfnd zebrad

published: May 8, 2026

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.4.0 and prior to zebra-script version 6.0.0, the fix for CVE-2026-41583 introduced a separate issue due to insufficient error handling of the case where the sighash type is invalid, during sighash computation. Instead of retur…
CWE: CWE-347
NVD

CRITICAL
CVE-2026-41583
CVE-2026-41583
pkg: zfnd zebra-script, zfnd zebrad

published: May 8, 2026

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and prior to zebra-script version 5.0.2, after a refactoring, Zebra failed to validate a consensus rule that restricted the possible values of sighash hash types for V5 transactions which were enabled in the NU5 network up…
CWE: CWE-573
GitHub-GHSA

CRITICAL
vm2 NodeVM `nesting: true` bypasses `require: false` allowing sandbox escape and arbitrary OS command execution
GHSA-8hg8-63c5-gwmx
pkg: vm2
eco: npm
published: May 7, 2026
### Summary

When a `NodeVM` is created with `nesting: true`, sandbox code can unconditionally `require('vm2')` regardless of the outer VM's `require` configuration — including `require: false`. With access to `vm2`, the sandbox constructs a new inner `NodeVM` with its own unrestricted `require` s…

CVE-2026-44007
GitHub-GHSA

CRITICAL
FileBrowser Public Share DELETE API Path Traversal Allows Unauthenticated Arbitrary File Deletion
GHSA-fwj3-42wh-8673
pkg: github.com/gtsteffaniak/filebrowser
eco: go
published: May 7, 2026
### **Summary**

Attacker-controlled path input is joined with a trusted base path prior to sanitization, allowing traversal sequences (e.g., ../) to escape the intended shared directory. As a result, an unauthenticated attacker possessing a valid public share hash with delete permissions enabled ca…

CVE-2026-44542
GitHub-GHSA

CRITICAL
Axonflow fixed bugs by implementing multi-tenant isolation and access-control hardening
GHSA-9h64-2846-7x7f
pkg: github.com/getaxonflow/axonflow
eco: go
published: May 6, 2026
## Summary

Eight independently-filed bug fixes in the v7.1.3 → v7.5.0 release window collectively close a set of multi-tenant isolation, access-control, and policy-enforcement defects in the AxonFlow platform. They are filed as a single consolidated advisory because the recommended remediation is…

GitHub-GHSA

CRITICAL
fast-jwt: JWT auth bypass due to empty HMAC secret accepted by async key resolver
GHSA-gmvf-9v4p-v8jc
pkg: fast-jwt
eco: npm
published: May 6, 2026
### Summary

A critical authentication-bypass vulnerability in `fast-jwt`'s async key-resolver flow allows any unauthenticated attacker to forge arbitrary JWTs that are accepted as authentic. When the application's key resolver returns an empty string (`''`), for example via the common `keys[decoded…

CVE-2026-44351
GitHub-GHSA

CRITICAL
Valtimo has SpEL injection via StandardEvaluationContext that allows Remote Code Execution by admin users
GHSA-j7j9-5253-f7vh
pkg: com.ritense.valtimo:document, com.ritense.valtimo:case, com.ritense.valtimo:contract
eco: maven
published: May 6, 2026
### Summary

Multiple classes evaluate Spring Expression Language (SpEL) expressions from user-supplied input using `StandardEvaluationContext`, which provides unrestricted access to Java types and methods. An authenticated user with the ADMIN role can achieve Remote Code Execution and credential ex…

CVE-2026-42555
NVD

CRITICAL
CVE-2026-43083
CVE-2026-43083
pkg: linux

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

net: ioam6: fix OOB and missing lock

When trace->type.bit6 is set:

if (trace->type.bit6) {

queue = skb_get_tx_queue(dev, skb);
qdisc = rcu_dereference(queue->qdisc);

This code can lead to an out-o…

NVD

CRITICAL
CVE-2026-43071
CVE-2026-43071
pkg: linux

published: May 5, 2026

In the Linux kernel, the following vulnerability has been resolved:

dcache: Limit the minimal number of bucket to two

There is an OOB read problem on dentry_hashtable when user sets
'dhash_entries=1':
BUG: unable to handle page fault for address: ffff888b30b774b0
#PF: supervisor read access in…

NVD

CRITICAL
CVE-2026-36356
CVE-2026-36356
pkg: go

published: May 5, 2026

The GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthenticated OS command injection via the /action/SetRemoteAccessCfg endpoint.
CWE: CWE-78, CWE-306
GitHub-GHSA

CRITICAL
OpenMRS has Stored Velocity SSTI to RCE via ConceptReferenceRange
GHSA-xj4f-8jjg-vx4q
pkg: org.openmrs.api:openmrs-api, org.openmrs.api:openmrs-api
eco: maven
published: May 4, 2026
### Impact

The `ConceptReferenceRangeUtility.evaluateCriteria()` method in OpenMRS Core
evaluates database-stored criteria strings as Apache Velocity templates without any sandbox configuration. The `VelocityEngine` is initialized with only logging properties and no`SecureUberspector`, leaving the …

CVE-2026-41258
GitHub-GHSA

CRITICAL
Apache OpenNLP DictionaryEntryPersistor Vulnerable to XML External Entity (XXE) via Unsanitized Dictionary Parsing
GHSA-4v8g-86×5-3vrc
pkg: org.apache.opennlp:opennlp-tools, org.apache.opennlp:opennlp-tools
eco: maven
published: May 4, 2026
XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor

Versions Affected: before 2.5.9, before 3.0.0-M3

Description: The DictionaryEntryPersistor class initializes a static SAXParserFactory at class-load time without enabling FEATURE_SECURE_PROCES…

CVE-2026-40682
GitHub-GHSA

CRITICAL
ArcadeDB vulnerable to cross-database authorization bypass and unsecured newly-created databases
GHSA-fxc7-fm93-6q77
pkg: com.arcadedb:arcadedb-server
eco: maven
published: May 5, 2026
### Impact
Authenticated users and API tokens scoped to a specific database could read, write, and mutate schema on any other database on the same server. Two distinct defects contributed: (1) ServerSecurityUser.getDatabaseUser() returned a DB user with an uninitialized fileAccessMap, which requestA…
CVE-2026-44221
GitHub-GHSA

CRITICAL
Sandboxed Thymeleaf expressions vulnerable to improper recognition of unauthorized syntax patterns
GHSA-c9ph-gxww-7744
pkg: org.thymeleaf:thymeleaf, org.thymeleaf:thymeleaf-spring5, org.thymeleaf:thymeleaf-spring6
eco: maven
published: May 4, 2026
### Impact

A security bypass vulnerability exists in the expression execution mechanisms of Thymeleaf up to and including 3.1.4.RELEASE. Although the library provides mechanisms to avoid the execution of potentially dangerous expressions in some specific sandboxed (restricted) contexts, it fails to…

CVE-2026-41901
GitHub-GHSA

CRITICAL
OpenMRS Module Upload Vulnerable to Path Traversal (Zip Slip)
GHSA-78fc-9688-w8xw
pkg: org.openmrs.web:openmrs-web, org.openmrs.web:openmrs-web
eco: maven
published: May 4, 2026
## Affected Versions

version ≤ 2.7.8 (latest version at time of disclosure)

https://github.com/openmrs/openmrs-core

## Impact

The endpoint `POST /openmrs/ws/rest/v1/module` is vulnerable to a path traversal (Zip Slip) attack. An authenticated attacker can upload a crafted `.omod` archive conta…

CVE-2026-40076
GitHub-GHSA

CRITICAL
SiYuan: Electron Renderer RCE via decodeURIComponent-driven tooltip XSS in aria-label sink (incomplete fix for CVE-2026-34585)
GHSA-25rp-h46x-2hjm
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: May 8, 2026
## Summary

The tooltip mouseover handler in `app/src/block/popover.ts` reads `aria-label` via `getAttribute` and passes it through `decodeURIComponent` before assigning to `messageElement.innerHTML` in `app/src/dialog/tooltip.ts:41`. The encoder used at the producer side, `escapeAriaLabel` in `app/…

CVE-2026-44588
GitHub-GHSA

CRITICAL
Electerm users can run dangrous code through link or command line
GHSA-mpm8-cx2p-626q
pkg: electerm
eco: npm
published: May 8, 2026
### Impact
_Arbitrary local code execution via deep links, CLI `–opts`, or crafted shortcuts. Affected users: electerm installs that accept protocol URLs or CLI options (affected versions listed in the original report). Exploit requires clicking a crafted `electerm://…` link or opening a crafted …
CVE-2026-43944
GitHub-GHSA

CRITICAL
Zebra v4.4.0 still accepts V5 SIGHASH_SINGLE without a corresponding output
GHSA-pvmv-cwg8-v6c8
pkg: zebrad, zebra-script
eco: rust
published: May 8, 2026
# Consensus Divergence in V5 Transparent SIGHASH_SINGLE With No Corresponding Output

## Summary

Zebra failed to enforce a ZIP-244 consensus rule for V5 transparent transactions: when an input is signed with `SIGHASH_SINGLE` and there is no transparent output at the same index as that input, valida…

GitHub-GHSA

CRITICAL
SiYuan Affected by Stored XSS via Attribute View Name to Electron Renderer RCE
GHSA-2h64-c999-c9r6
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: May 8, 2026
## Summary

The kernel stores Attribute View (AV / database) names without any HTML escape, then a render template uses raw `strings.ReplaceAll(tpl, "${avName}", nodeAvName)` to embed the name in HTML before pushing to all clients via WebSocket. Three independent client paths (`render.ts:120` → `o…

CVE-2026-44670
GitHub-GHSA

CRITICAL
Zebra's Transparent SIGHASH_SINGLE Handling Diverges from zcashd for Corresponding Outputs
GHSA-cwfq-rfcr-8hmp
pkg: zebrad
eco: rust
published: May 7, 2026
# `Zebra` Transparent `SIGHASH_SINGLE` Corresponding-Output Handling Diverges From `zcashd`

### Summary
For V5+ transparent spends, `Zebra` and `zcashd` disagree on the same consensus rule: `SIGHASH_SINGLE` must fail when the input index has no corresponding output. `zcashd` treats this as consensu…

GitHub-GHSA

CRITICAL
Zebra has Consensus Divergence in Transparent Sighash Hash-Type Handling due to Stale Buffer
GHSA-gq4h-3grw-2rhv
pkg: zebra-script, zebrad
eco: rust
published: May 7, 2026
# CVE-2026-44497: Consensus Divergence in Transparent Sighash Hash-Type Handling due to Stale Buffer

## Summary

The fix for https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-8m29-fpq5-89jj introduced a separate issue due to insuficient error handling of the case where the sighash t…

CVE-2026-44497
GitHub-GHSA

CRITICAL
Zebra's Block Validator Undercounts Coinbase and P2SH Sigops
GHSA-jv4h-j224-23cc
pkg: zebrad
eco: rust
published: May 7, 2026
Zebra's block validator undercounts transparent signature operations against the 20000-sigop block limit (`MAX_BLOCK_SIGOPS`), allowing it to accept blocks that `zcashd` rejects with `bad-blk-sigops`. A miner who produces such a block can split the network: Zebra nodes follow the offending chain whi…
CVE-2026-44498
GitHub-GHSA

CRITICAL
Compromise of PyTorch Lightning PyPi Package Versions
GHSA-w37p-236h-pfx3
pkg: pytorch-lightning, pytorch-lightning
eco: pip
published: May 7, 2026
# Security Advisory: Compromise of PyTorch Lightning PyPI Package Versions

**Published:** 2026-04-30
**Last Updated:** 2026-04-30

Lightning AI has identified a security incident affecting certain versions of a PyPI package.

## What happened

Lightning AI has determined that one or more releas…

CVE-2026-44484
GitHub-GHSA

CRITICAL
misp-modules website – Missing CSRF protection in the website home blueprint
GHSA-j4rh-7jcr-qm69
pkg: misp-modules
eco: pip
published: May 6, 2026
A Cross-Site Request Forgery vulnerability in the MISP Modules website allowed an attacker to cause an authenticated user to submit unintended requests to the home endpoint. The vulnerability was due to the home blueprint being exempted from CSRF protection. This could allow modification of session …
CVE-2026-44364
GitHub-GHSA

CRITICAL
DevGuard has an unauthenticated identity assertion via `X-Admin-Token` header
GHSA-2g9v-7mr5-fgjg
pkg: github.com/l3montree-dev/devguard
eco: go
published: May 5, 2026
### Impact
The `SessionMiddleware` accepts a client-supplied `X-Admin-Token` HTTP request header and uses its raw string value as the authenticated `userID` when no Kratos session cookie is present. An unauthenticated attacker who knows or can guess a target user's Kratos identity UUID can issue req…
CVE-2026-42300
GitHub-GHSA

CRITICAL
MagicMirror vulnerable to unauthenticated SSRF via /cors endpoint
GHSA-ph6f-2cvq-79hq
pkg: magicmirror
eco: npm
published: May 5, 2026
### Summary

An unauthenticated Server-Side Request Forgery (SSRF) vulnerability in the `/cors` endpoint allows any remote attacker to force the MagicMirror² server to perform arbitrary HTTP requests to internal networks, cloud metadata services, and localhost services. The endpoint also expands en…

CVE-2026-42281
GitHub-GHSA

CRITICAL
django-s3file is vulnerable to relative path traversal
GHSA-67qg-7284-2277
pkg: django-s3file
eco: pip
published: May 5, 2026
### Impact
`S3FileMiddleware` is vulnerable to relative path traversal attacks, where an attacker can use a modified request to escape pre-signed upload locations and have the Django application load files from random locations into `request.FILES`

Depending on how files are handled, this may lead …

CVE-2026-42196
GitHub-GHSA

CRITICAL
`mysten-metrics` was removed from crates.io for malicious code
GHSA-g38r-8gmr-ghrf
pkg: mysten-metrics
eco: rust
published: May 4, 2026
`mysten-metrics` included a build script that attempted to exfiltrate data from the build machine.

The malicious crate had 1 version published on 2026-04-20 and had no evidence of actual usage. This crate had no dependencies on crates.io.

GitHub-GHSA

CRITICAL
`sui-execution-cut` was removed from crates.io for malicious code
GHSA-qprh-m6p3-hwxc
pkg: sui-execution-cut
eco: rust
published: May 4, 2026
`sui-execution-cut` included a build script that attempted to exfiltrate data from the build machine.

The malicious crate had 1 version published on 2026-04-20 and had no evidence of actual usage. This crate had no dependencies on crates.io.

GitHub-GHSA

HIGH
Electerm Security Vulnerability: RCE via malicious SSH server filename in openFileWithEditor
GHSA-q4p8-8j9m-8hxj
pkg: electerm
eco: npm
published: May 8, 2026
### Impact

A code execution (RCE) vulnerability exists in electerm's SFTP open with system editor or "Edit with custom editor" feature. When a user opts to edit a file using open with system editor or open with a custom editor, the filename is passed directly into a command line without sanitizatio…

CVE-2026-43943
GitHub-GHSA

HIGH
Electerm has an unvalidated shell.openExternal that allows arbitrary protocol execution via terminal link click
GHSA-fwf6-j56g-m97c
pkg: electerm
eco: npm
published: May 8, 2026
### Impact

Electerm's terminal hyperlink handler passes any URL clicked in the terminal directly to `shell.openExternal` without any protocol validation.

When a user connects to a malicious SSH server, the attacker can print a crafted URI in the terminal output. If the victim clicks the link, `she…

CVE-2026-43941
NVD

HIGH
CVE-2026-42215
CVE-2026-42215
pkg: python

published: May 7, 2026

GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as –upload-pack and –receive-pack by default, but the equivalent Python kwargs upload_pack and receive_pack bypass that check. If an appli…
CWE: CWE-78
NVD

HIGH
CVE-2025-63705
CVE-2025-63705
pkg: node

published: May 7, 2026

NPM package node-ts-ocr 1.0.15 is vulnerable to OS Command Injection via the invokeImageOcr function in src/index.js.
CWE: CWE-78
NVD

HIGH
CVE-2026-41139
CVE-2026-41139
pkg: mathjs mathjs

published: May 7, 2026

Math.js is an extensive math library for JavaScript and Node.js. From version 13.1.0 to before version 15.2.0, arbitrary JavaScript can be executed via the expression parser of mathjs. This issue has been patched in version 15.2.0.
CWE: CWE-915
GitHub-GHSA

HIGH
Diffusers has a `trust_remote_code` bypass via `custom_pipeline` and local custom components
GHSA-98h9-4798-4q5v
pkg: diffusers
eco: pip
published: May 7, 2026
### Impact

A `trust_remote_code` bypass in `DiffusionPipeline.from_pretrained` allows arbitrary remote code execution despite the user passing `trust_remote_code=False` (or omitting it, which is the default). The vulnerability has three variants, all sharing the same root cause — the `trust_remot…

CVE-2026-44513
GitHub-GHSA

HIGH
Diffusers has a `trust_remote_code` bypass via `custom_pipeline` and local custom components
GHSA-j7w6-vpvq-j3gm
pkg: diffusers
eco: pip
published: May 7, 2026
## Background

This vulnerability is found in the `DiffusionPipeline.from_pretrained` flow, which is used to load a pipeline from the HuggingFace Hub.

This function accepts an optional `custom_pipeline` keyword argument: the name of a Python file in the repo that contains a custom class inheriting …

CVE-2026-44827
GitHub-GHSA

HIGH
rmcp Streamable HTTP server transport has a DNS rebinding vulnerability
GHSA-89vp-x53w-74fx
pkg: rmcp
eco: rust
published: May 6, 2026
## Summary

Prior to version 1.4.0, the `rmcp` crate's Streamable HTTP server transport (`crates/rmcp/src/transport/streamable_http_server/`) did not validate the incoming `Host` header. This allowed a malicious public website, via a DNS rebinding attack, to send authenticated requests to an MCP ser…

CVE-2026-42559
NVD

HIGH
CVE-2026-8000
CVE-2026-8000
pkg: google chrome, apple macos, linux linux_kernel

published: May 6, 2026

Insufficient validation of untrusted input in ChromeDriver in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)
CWE: CWE-20
NVD

HIGH
CVE-2026-7973
CVE-2026-7973
pkg: google chrome, microsoft windows

published: May 6, 2026

Integer overflow in Dawn in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-472
NVD

HIGH
CVE-2026-7928
CVE-2026-7928
pkg: google chrome, microsoft windows

published: May 6, 2026

Use after free in WebRTC in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-7907
CVE-2026-7907
pkg: google chrome, apple macos, linux linux_kernel

published: May 6, 2026

Use after free in DOM in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-7906
CVE-2026-7906
pkg: google chrome, apple macos, linux linux_kernel

published: May 6, 2026

Use after free in SVG in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-7903
CVE-2026-7903
pkg: google chrome, apple macos, microsoft windows

published: May 6, 2026

Integer overflow in ANGLE in Google Chrome on Mac,Windows prior to 148.0.7778.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-472
NVD

HIGH
CVE-2026-7902
CVE-2026-7902
pkg: google chrome, apple macos, linux linux_kernel

published: May 6, 2026

Out of bounds memory access in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-787, CWE-125
NVD

HIGH
CVE-2026-7901
CVE-2026-7901
pkg: google chrome, apple macos

published: May 6, 2026

Use after free in ANGLE in Google Chrome on Mac prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-7899
CVE-2026-7899
pkg: google chrome, apple macos, linux linux_kernel

published: May 6, 2026

Out of bounds read and write in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-125, CWE-787
NVD

HIGH
CVE-2026-7898
CVE-2026-7898
pkg: google chrome, linux linux_kernel

published: May 6, 2026

Use after free in Chromoting in Google Chrome on Linux prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-7896
CVE-2026-7896
pkg: google chrome, apple macos, linux linux_kernel

published: May 6, 2026

Integer overflow in Blink in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-472
NVD

HIGH
CVE-2026-42503
CVE-2026-42503
pkg: go

published: May 6, 2026

gopls by default communicates via pipe. However, -port and -listen flags are supported as means of debugging.
If -listen is given a value without an explicit host (e.g. :8080), or -port is used, gopls will listen on 0.0.0.0. 
As a result, users might inadvertently cause gopls to bind 0.0.0.0.
This…
CWE: CWE-1327
NVD

HIGH
CVE-2026-43158
CVE-2026-43158
pkg: go

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

xfs: fix freemap adjustments when adding xattrs to leaf blocks

xfs/592 and xfs/794 both trip this assertion in the leaf block freemap
adjustment code after ~20 minutes of running on my test VMs:

ASSERT(ichdr->firstused >= ichdr-…

GitHub-GHSA

HIGH
@evomap/evolver: Path Traversal in `evolver fetch` default-branch `safeId` allows Hub-controlled overwrite of project files (RCE)
GHSA-cfcj-hqpf-hccf
pkg: @evomap/evolver
eco: npm
published: May 5, 2026
## Summary

The `evolver fetch` subcommand in `index.js` writes Hub-supplied `bundled_files[]` into a directory derived from a Hub-supplied `skill_id`. When `–out` is not used, the path-sanitizing regex permits `.` characters, allowing a `skill_id` of `..` to escape the `skills/` subdirectory and r…

GitHub-GHSA

HIGH
Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled
GHSA-9fw6-xgg2-mq9q
pkg: github.com/apernet/hysteria/core/v2
eco: go
published: May 5, 2026
### Summary

A specially constructed quic package can crash the server OOM when the sniff is enabled.

### Details

When the server has sniff enabled, a valid connection can request the server to forward UDP traffic and construct a huge crypto length. The server will allocate memory according to thi…

GitHub-GHSA

HIGH
JupyterHub has an Extension Manager API/GUI Policy Discrepancy, allowing 3rd party (malicious) extensions install via POST request
GHSA-37w4-hwhx-4rc4
pkg: jupyterlab
eco: pip
published: May 5, 2026
The allow-list of extensions that can be installed from PyPI Extension Manager (`allowed_extensions_uris`) is not correctly enforced by JupyterLab prior to 4.5.X. The PyPI Extension Manager was not contained to packages listed on the default PyPI index.

This has security implications for deployment…

CVE-2026-42266
GitHub-GHSA

HIGH
YAFNET: Pre-Handler Authorization Bypass on Admin Pages Enables Blind SQL Execution via `/Admin/RunSql`
GHSA-xhw7-j96h-c3g5
pkg: YAFNET.Core
eco: nuget
published: May 5, 2026
**Issue Details:**
YAFNET's only admin authorization gate is `PageSecurityCheckAttribute`, implemented as a `ResultFilterAttribute` that runs *after* the page handler completes rather than before it. No other gate exists. Any admin `OnPost…` handler therefore executes its side effects before the f…
CVE-2026-43937
NVD

HIGH
CVE-2026-34464
CVE-2026-34464
pkg: sandboxie-plus sandboxie

published: May 5, 2026

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, NamedPipeServer::OpenHandler copies the server field from NAMED_PIPE_OPEN_REQ into a fixed WCHAR pipename[160] stack buffer using wcscat without verifying null termination. The handler only…
CWE: CWE-121, CWE-170
NVD

HIGH
CVE-2026-34459
CVE-2026-34459
pkg: sandboxie-plus sandboxie

published: May 5, 2026

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, the SbieSvc proxy service's GetRawInputDeviceInfoSlave handler contains two vulnerabilities that can be chained for sandbox escape. First, when a sandboxed process sends an IPC request with…
CWE: CWE-121
NVD

HIGH
CVE-2026-34458
CVE-2026-34458
pkg: sandboxie-plus sandboxie

published: May 5, 2026

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, an INI injection vulnerability allows any standard local user to bypass configuration restrictions (EditAdminOnly and ConfigPassword) and inject arbitrary directives into the global Sandbox…
CWE: CWE-93
GitHub-GHSA

HIGH
OpenClaw's gateway config mutation guard allowed unsafe model-driven config writes
GHSA-cwj3-vqpp-pmxr
pkg: openclaw
eco: npm
published: May 5, 2026
## Summary

The agent-facing `gateway` tool protects `config.apply` and `config.patch` with a model-to-operator trust boundary. That guard used a hand-maintained denylist of protected config paths. The config schema outgrew that denylist, leaving sensitive subtrees writable through model-driven gate…

NVD

HIGH
CVE-2026-42434
CVE-2026-42434
pkg: node

published: May 5, 2026

OpenClaw versions 2026.4.5 before 2026.4.10 contain a sandbox escape vulnerability allowing sandboxed agents to override exec routing by specifying host=node. Attackers can bypass sandbox boundaries and route execution to remote nodes instead of intended sandbox paths.
CWE: CWE-863
NVD

HIGH
CVE-2026-42237
CVE-2026-42237
pkg: n8n n8n

published: May 4, 2026

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the fix for GHSA-f3f2-mcxc-pwjx did not cover the Snowflake node or the legacy MySQL v1 node. Both nodes construct SQL queries by directly interpolating user-controlled table names, column names, and …
CWE: CWE-89
NVD

HIGH
CVE-2026-42234
CVE-2026-42234
pkg: n8n n8n

published: May 4, 2026

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated user with permission to create or modify workflows containing a Python Code Node could escape the sandbox and achieve arbitrary code execution on the task runner container. This issue…
CWE: CWE-94
NVD

HIGH
CVE-2026-42232
CVE-2026-42232
pkg: n8n n8n

published: May 4, 2026

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated user with permission to create or modify workflows could achieve global prototype pollution via the XML Node leading to RCE when combined with other nodes exploiting the prototype pol…
CWE: CWE-1321
NVD

HIGH
CVE-2026-42231
CVE-2026-42231
pkg: n8n n8n

published: May 4, 2026

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the xml2js library used to parse XML request bodies in n8n's webhook handler allowed prototype pollution via a crafted XML payload. An authenticated user with permission to create or modify …
CWE: CWE-1321
NVD

HIGH
CVE-2026-42229
CVE-2026-42229
pkg: n8n n8n

published: May 4, 2026

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the SeaTable node's row:search and row:get operations allowed user-controlled input to be concatenated directly into SQL query strings without escaping or parameterization. In workflows wher…
CWE: CWE-89
NVD

HIGH
CVE-2026-29514
CVE-2026-29514
pkg: express

published: May 4, 2026

NetBox versions 4.3.5 through 4.5.4 contain a remote code execution vulnerability in the RenderTemplateMixin.get_environment_params() method that allows authenticated users with exporttemplate or configtemplate permissions to execute arbitrary code by specifying malicious Python callables in the env…
CWE: CWE-183
GitHub-GHSA

HIGH
Open WebUI: Redis Cache Keys tool_servers and terminal_servers Missing Instance Prefix Enable Cross-Instance Cache Poisoning
GHSA-3x8w-4f7p-xxc2
pkg: open-webui
eco: pip
published: May 8, 2026
# Redis Cache Keys tool_servers and terminal_servers Missing Instance Prefix Enable Cross-Instance Cache Poisoning

## Affected Component

Tool server and terminal server Redis cache:
– `backend/open_webui/utils/tools.py` (line 841, tool_servers SET)
– `backend/open_webui/utils/tools.py` (line 850, …

CVE-2026-44552
GitHub-GHSA

HIGH
netbox-data-flows has stored XSS in ObjectAlias names rendered inside DataFlow tables
GHSA-v7qw-hx66-4w9x
pkg: netbox-data-flows
eco: pip
published: May 7, 2026
### Summary
An authenticated user who can create or edit `ObjectAlias` objects can store arbitrary HTML/JavaScript in an alias name. That payload is later rendered unescaped in `DataFlow` table views, causing a stored XSS when another user views the affected page.

### Details
The issue is caused by…

NVD

HIGH
CVE-2026-42352
CVE-2026-42352
pkg: python

published: May 8, 2026

pygeoapi is a Python server implementation of the OGC API suite of standards. From version 0.23.0 to before version 0.23.3, OGC API process execution requests can use the subscriber object to requests to internal HTTP services. This issue has been patched in version 0.23.3.
CWE: CWE-918
NVD

HIGH
CVE-2026-41690
CVE-2026-41690
pkg: express

published: May 8, 2026

18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. Versions prior to 3.9.3 allow an unauthenticated HTTP client to pollute Object.prototype in the Node.js process hosting the middleware, via two unvalidated entry points that reach…
CWE: CWE-22, CWE-1321
NVD

HIGH
CVE-2026-41683
CVE-2026-41683
pkg: express

published: May 8, 2026

i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. Prior to version 3.9.3, i18next-http-middleware wrote user-controlled language values into the Content-Language response header after passing them through utils.escape(), which i…
CWE: CWE-79, CWE-113
NVD

HIGH
CVE-2026-42047
CVE-2026-42047
pkg: express

published: May 7, 2026

Inngest is a platform for running event-driven and scheduled background functions with queueing, retries, and step orchestration. Versions 3.22.0 through 3.53.1 contain a vulnerability that allows unauthenticated remote attackers to exfiltrate environment variables from the host process via the serv…
CWE: CWE-200, CWE-497
GitHub-GHSA

HIGH
vm2 has a Sandbox Escape via Promise Constructor Unhandled Rejection (Process Crash DoS)
GHSA-hw58-p9xv-2mjh
pkg: vm2
eco: npm
published: May 7, 2026
### Summary
A sandbox escape vulnerability in vm2 v3.10.5 allows any sandboxed code to crash the host Node.js process via a single Promise constructor that triggers an unhandled rejection propagating to the host. The fix for CVE-2026-22709 (v3.10.2) only sanitized the `onRejected` callback in `.then…
CVE-2026-44001
GitHub-GHSA

HIGH
Harvester's SUSE Virtualization Registration Client Vulnerable to MITM and DOS
GHSA-pgh9-mpwc-8jjf
pkg: github.com/harvester/harvester
eco: go
published: May 6, 2026
### Impact

A vulnerability has been identified in the [SUSE Virtualization (Harvester) Rancher integration mechanism](https://docs.harvesterhci.io/v1.7/rancher/rancher-integration) where by default the registration client uses an insecure TLS option that fails to verify the remote server’s certi…

CVE-2025-71261
GitHub-GHSA

HIGH
PPTAgent: Arbitrary Code Execution via Python eval() of LLM-Generated Code with Builtins in Scope
GHSA-89g2-xw5c-v95p
pkg: pptagent
eco: pip
published: May 5, 2026
## Summary

> This vulnerability has been fixed in https://github.com/icip-cas/PPTAgent/commit/418491a9a1c02d9d93194b5973bb58df35cf9d00.

`CodeExecutor.execute_actions` (pptagent/apis.py:126-205) processes LLM-generated slide editing actions using Python's `eval()`:

“`python
# pptagent/apis.py:18…

CVE-2026-42079
GitHub-GHSA

HIGH
Inngest TypeScript SDK exposes environment variables via serve() handler on unhandled HTTP methods
GHSA-2jf5-6wwv-vhxx
pkg: inngest
eco: npm
published: May 5, 2026
# Summary

A vulnerability in the Inngest TypeScript SDK versions `3.22.0` through `3.53.1` allows unauthenticated remote attackers to exfiltrate environment variables from the host process via the `serve()` HTTP handler.

The `serve()` handler implements `GET`, `POST`, and `PUT` methods. Requests u…

CVE-2026-42047
NVD

HIGH
CVE-2026-42079
CVE-2026-42079
pkg: python

published: May 4, 2026

PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, PPTAgent is vulnerable to arbitrary code execution via Python eval() of LLM-generated code with builtins in scope. This issue has been patched via commit 418491a.
CWE: CWE-95
NVD

HIGH
CVE-2026-42449
CVE-2026-42449
pkg: node

published: May 7, 2026

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. In versions 2.47.4 through 2.47.13, the SDK embedder path (N8NDocumentationMCPServer constructor, getN8nApiClient(), and validateInstanceContext()), the synchronous URL validator in SSR…
CWE: CWE-918
GitHub-GHSA

HIGH
vm2 has a NodeVM require.root bypass via symlink traversal that allows sandbox escape
GHSA-cp6g-6699-wx9c
pkg: vm2
eco: npm
published: May 7, 2026
## Summary
NodeVM's `require.root` path restriction can be bypassed using filesystem symlinks, allowing sandboxed code to load modules from outside the allowed root directory in host context. Because path validation uses `path.resolve()` (which does not dereference symlinks) but module loading uses …
CVE-2026-43998
GitHub-GHSA

HIGH
Rancher Extensions have arbitrary file access via path traversal
GHSA-5v3h-x4wf-5c35
pkg: github.com/rancher/rancher, github.com/rancher/rancher, github.com/rancher/rancher
eco: go
published: May 7, 2026
### Impact

A vulnerability has been identified in [Rancher's Extensions](https://ranchermanager.docs.rancher.com/integrations-in-rancher/rancher-extensions) where malicious code can be injected in Rancher through a path traversal in the `compressedEndpoint` field inside a `UIPlugin` deployment. A m…

CVE-2026-25705
GitHub-GHSA

HIGH
PraisonAI has unauthenticated RCE via `tool_override.py` (CVE-2026-40287 patch bypass)
GHSA-xcmw-grxf-wjhj
pkg: praisonai
eco: pip
published: May 6, 2026
## TL;DR

CVE-2026-40287's fix gated `tools.py` auto-import behind `PRAISONAI_ALLOW_LOCAL_TOOLS=true` in **two** files (`tool_resolver.py`, `api/call.py`). A **third** import sink in `praisonai/templates/tool_override.py` was missed and remains unguarded. It is reached by the recipe runner on every …

CVE-2026-44334
GitHub-GHSA

HIGH
Velocity.js has a Prototype Pollution vulnerability through #set path assignment
GHSA-j658-c2gf-x6pq
pkg: velocityjs
eco: npm
published: May 9, 2026
### Summary
A prototype pollution vulnerability was discovered in Velocity.js <= 2.1.5. This issue occurs during the processing of #set directives in Velocity templates. If an application renders a template controlled by an attacker, it is possible to modify Object.prototype, potentially leading to …
CVE-2026-44966
GitHub-GHSA

HIGH
n8n-mcp affected by path traversal, redirect-following SSRF, and telemetry payload exposure
GHSA-8g7g-hmwm-6rv2
pkg: n8n-mcp
eco: npm
published: May 8, 2026
## Impact

`n8n-mcp` versions before 2.50.1 contained three independently-reported issues affecting deployments that run the n8n API integration:

1. **Caller-supplied identifiers were not validated before being used as URL path segments** by the n8n API client. An authenticated MCP caller passing a…

NVD

HIGH
CVE-2026-41422
CVE-2026-41422
pkg: express

published: May 7, 2026

Daptin is a GraphQL/JSON-API headless CMS. Prior to version 0.11.4, the /aggregate/:typename endpoint accepted column and group query parameters that were passed verbatim to goqu.L() — a raw SQL literal expression builder — without any validation. This bypassed all parameterization and allowed a…
CWE: CWE-89
NVD

HIGH
CVE-2026-7917
CVE-2026-7917
pkg: google chrome, microsoft windows

published: May 6, 2026

Use after free in Fullscreen in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-7914
CVE-2026-7914
pkg: google chrome, microsoft windows

published: May 6, 2026

Type Confusion in Accessibility in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-843
NVD

HIGH
CVE-2026-7911
CVE-2026-7911
pkg: google chrome, microsoft windows

published: May 6, 2026

Use after free in Aura in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-7905
CVE-2026-7905
pkg: google chrome, google android

published: May 6, 2026

Insufficient validation of untrusted input in Media in Google Chrome on Android prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-20
NVD

HIGH
CVE-2026-7900
CVE-2026-7900
pkg: google chrome, apple macos, linux linux_kernel

published: May 6, 2026

Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-122
GitHub-GHSA

HIGH
LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists
GHSA-pjwx-r37v-7724
pkg: langchain-core, langchain-core
eco: pip
published: May 8, 2026
LangChain contains older runtime code paths that deserialize run inputs, run outputs, or other application-controlled payloads using overly broad object allowlists. These paths may call `load()` with `allowed_objects="all"`. This does not enable arbitrary Python object deserialization, but it does a…
CVE-2026-44843
GitHub-GHSA

HIGH
free5GC's SMF UPI DELETE /upi/v1/upNodesLinks/{ref} panics on AN-node deletion via nil UPF dereference; unauthenticated, state-mutating
GHSA-p9mg-74mg-cwwr
pkg: github.com/free5gc/smf
eco: go
published: May 8, 2026
### Summary
free5GC's SMF mounts the `UPI` management route group without inbound OAuth2 middleware (same root cause as the broader UPI auth gap reported in free5gc/free5gc#887). On top of that, the `DELETE /upi/v1/upNodesLinks/{upNodeRef}` handler unconditionally dereferences `upNode.UPF` after the…
CVE-2026-44328
GitHub-GHSA

HIGH
@babel/plugin-transform-modules-systemjs generates arbitrary code when compiling malicious input
GHSA-fv7c-fp4j-7gwp
pkg: @babel/plugin-transform-modules-systemjs, @babel/plugin-transform-modules-systemjs
eco: npm
published: May 8, 2026
### Impact

Using Babel to compile code that was specifically crafted by an attacker can cause Babel to generate output code that executes arbitrary code.

Known affected plugins are:
– `@babel/plugin-transform-modules-systemjs`
– `@babel/preset-env` when using the [`modules: "systemjs"` option](htt…

CVE-2026-44728
NVD

HIGH
CVE-2026-42353
CVE-2026-42353
pkg: express

published: May 8, 2026

i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. Prior to version 3.9.3, i18next-http-middleware passes the user-controlled lng and ns values from getResourcesHandler directly into i18next.services.backendConnector.load(languag…
CWE: CWE-22, CWE-918
GitHub-GHSA

HIGH
Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosure of subscriber SUPI
GHSA-6rgm-gr97-x3j5
pkg: github.com/free5gc/pcf
eco: go
published: May 7, 2026
### Summary
PCF Npcf_SMPolicyControl missing authentication middleware allows unauthenticated access to SM policy handlers and disclosure of subscriber SUPI
### Details
In `NewServer()`, the `smPolicyGroup` route group is created and routes are applied without attaching the router authorization midd…
CVE-2026-42083
GitHub-GHSA

HIGH
Gotenberg has a Server-Side Request Forgery (SSRF) Issue
GHSA-rm4c-xj6x-49mw
pkg: github.com/gotenberg/gotenberg/v8
eco: go
published: May 7, 2026
### Summary

The SSRF hardening shipped in v8.31.0 only covers outbound URLs that Gotenberg's Go code handles — Chromium asset fetches, webhook delivery, and download-from. The LibreOffice conversion endpoint (`/forms/libreoffice/convert`) passes uploaded documents directly to LibreOffice without …

CVE-2026-42591
GitHub-GHSA

HIGH
Gotenberg's ExifTool group-prefix syntax bypasses dangerous-tag blocklist
GHSA-7v3r-m9c8-r855
pkg: github.com/gotenberg/gotenberg/v8
eco: go
published: May 7, 2026
**Summary**

The ExifTool metadata write blocklist in Gotenberg v8 can be bypassed using ExifTool's group-prefix syntax, enabling arbitrary file rename, move, hardlink, and symlink creation on the server. This is a bypass of the fix for GHSA-qmwh-9m9c-h36m.

**Details**

The blocklist in `pkg/module…

CVE-2026-42590
NVD

HIGH
CVE-2026-39852
CVE-2026-39852
pkg: quarkus quarkus

published: May 5, 2026

Quarkus is a Java framework for building cloud-native applications. In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3.35.1.1, 3.34.7, and 3.35.2, a path normalization inconsistency between the security layer and the routing layer allows unauthenticated or lower-privileged users to bypass HTTP pat…
CWE: CWE-863
GitHub-GHSA

HIGH
open-websearch has SSRF in `fetchWebContent` MCP tool: bracketed IPv6 literals and non-resolving hostname check bypass `isPrivateOrLocalHostname`
GHSA-v228-72c7-fx8j
pkg: open-websearch
eco: npm
published: May 5, 2026
### Summary
`src/utils/urlSafety.ts` exposes `isPublicHttpUrl` / `assertPublicHttpUrl`, used to gate the MCP `fetchWebContent` tool against private-network targets. The check has two defects that together allow **non-blind SSRF with the response body returned to the caller**:

1. **Bracketed IPv6 li…

CVE-2026-42260
GitHub-GHSA

HIGH
ssrfcheck Vulnerable to Server-Side Request Forgery (SSRF) and Incomplete List of Disallowed Inputs
GHSA-j4rj-2jr5-m439
pkg: ssrfcheck
eco: npm
published: May 5, 2026
### Summary

`ssrfcheck` v1.3.0 (latest) fails to block Server-Side Request Forgery attacks when the target private IP address is encoded as an IPv4-mapped IPv6 address (e.g. `http://[::ffff:127.0.0.1]/`). The WHATWG URL parser built into Node.js silently normalizes the IPv4 notation inside the brac…

CVE-2026-43929
GitHub-GHSA

HIGH
exiftool-vendored vulnerable to argument injection via newline characters in tag names
GHSA-cw26-7653-2rp5
pkg: exiftool-vendored
eco: npm
published: May 5, 2026
### Impact

`exiftool-vendored` starts ExifTool in `-stay_open True -@ -` mode, where arguments are read from stdin one per line. In affected versions, several caller-supplied strings were interpolated into ExifTool arguments without rejecting line delimiters. A newline or carriage return inside one…

CVE-2026-43893
GitHub-GHSA

HIGH
Quarkus has Authentication/Authorization bypasses
GHSA-rc95-pcm8-65v9
pkg: io.quarkus:quarkus-vertx-http, io.quarkus:quarkus-vertx-http, io.quarkus:quarkus-vertx-http
eco: maven
published: May 4, 2026
Quarkus version 3.32.4 is vulnerable to an authorization bypass issue (GHSL-2026-099), in which semicolons (matrix parameters) in HTTP requests can be used to bypass security constraints, potentially allowing unauthorized access to protected resources.

Unauthenticated or lower-privileged users can …

CVE-2026-39852
NVD

HIGH
CVE-2026-42296
CVE-2026-42296
pkg: kubernetes

published: May 9, 2026

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to versions 3.7.14 and 4.0.5, a user with create Workflow permission can bypass templateReferencing: Strict to get host network access, switch service accounts, override pod securit…
CWE: CWE-863
GitHub-GHSA

HIGH
epa4all-client has a VAU Signature bypass
GHSA-g8r3-5hwf-qp96
pkg: com.oviva.telematik:epa4all-client
eco: maven
published: May 8, 2026
### Impact
In SignedPublicKeysTrustValidatorImpl.isTrusted(), the ECDSA signature verification at line 45 discards the boolean return value of Signature.verify(). The method performs certificate chain validation, OCSP check, and signature algorithm setup, but never checks whether the signature actua…
CVE-2026-44900
NVD

HIGH
CVE-2026-42452
CVE-2026-42452
pkg: jwt

published: May 8, 2026

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.1.0, /users/login issues a temporary JWT (temp_token) for TOTP-enabled accounts. That token carries a pendingTOTP state and should only be valid for the second-factor flow…
CWE: CWE-304
GitHub-GHSA

HIGH
Open WebUI has Knowledge Base Destruction and RAG Poisoning via Unauthorized Collection Overwrite
GHSA-7r82-qhg4-6wvj
pkg: open-webui
eco: pip
published: May 8, 2026
# Knowledge Base Destruction and RAG Poisoning via Unauthorized Collection Overwrite

## Affected Component

Retrieval web/YouTube processing endpoints:
– `backend/open_webui/routers/retrieval.py` (lines 1810-1837, `process_web`)
– `backend/open_webui/routers/retrieval.py` (the parallel `process_you…

CVE-2026-44554
GitHub-GHSA

HIGH
Open WebUI: Stale Admin Role in Socket.IO Session Pool Enables Post-Demotion Cross-User Note Access
GHSA-45m8-cpm2-3v65
pkg: open-webui
eco: pip
published: May 8, 2026
# Stale Admin Role in Socket.IO Session Pool Enables Post-Demotion Cross-User Note Access

## Affected Component

Socket.IO session state and role-check callsites:
– `backend/open_webui/socket/main.py` (lines 330-351, `connect` handler — role snapshotted into SESSION_POOL)
– `backend/open_webui/so…

CVE-2026-44553
NVD

HIGH
CVE-2026-41883
CVE-2026-41883
pkg: express

published: May 8, 2026

OmniFaces is a utility library for Faces. Prior to versions 1.14.2, 2.7.32, 3.14.16, 4.7.5, and 5.2.3, there is a server-side EL injection leading to Remote Code Execution (RCE). This affects applications that use CDNResourceHandler with a wildcard CDN mapping (e.g. libraryName:*=https://cdn.example…
CWE: CWE-917
NVD

HIGH
CVE-2026-42239
CVE-2026-42239
pkg: jwt

published: May 7, 2026

Budibase is an open-source low-code platform. Prior to version 3.35.10, the budibase:auth cookie containing the JWT session token is set with httpOnly: false at packages/backend-core/src/utils/utils.ts:218. JavaScript can read this cookie via document.cookie. This means every XSS becomes a full acco…
CWE: CWE-1004
NVD

HIGH
CVE-2026-42284
CVE-2026-42284
pkg: gitpython_project gitpython

published: May 7, 2026

GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_options as the original list, then executes shlex.split(" ".join(multi_options)). A string like "–branch main –config core.hooksPath=/x" passes validation (starts with –branch),…
CWE: CWE-88
NVD

HIGH
CVE-2026-33588
CVE-2026-33588
pkg: lfnovo open-notebook

published: May 7, 2026

Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to create or modify files on the docker container via path traversal.
CWE: CWE-20
GitHub-GHSA

HIGH
opentelemetry-collector-contrib's azureauthextension Authenticate method does not validate bearer tokens, allowing auth bypass via replay
GHSA-pjv4-3c63-699f
pkg: github.com/open-telemetry/opentelemetry-collector-contrib/extension/azureauthextension
eco: go
published: May 6, 2026
### Summary

A server-side authentication bypass in `azureauthextension` allows any party who holds a single valid Azure access token for *any scope the collector's configured identity can mint for* to authenticate to any OpenTelemetry receiver that uses `auth: azure_auth`. The extension's `Authenti…

CVE-2026-42602
GitHub-GHSA

HIGH
Lemur: LDAP Filter Injection enables post-authentication privilege escalation
GHSA-3r34-vq8m-39gh
pkg: lemur
eco: pip
published: May 6, 2026
## Description

### Overview

Lemur's LDAP authentication module (`lemur/auth/ldap.py`) constructs LDAP search filters using unsanitized user input via Python string interpolation. An authenticated LDAP user can inject LDAP filter metacharacters through the username field to manipulate group members…

CVE-2026-44304
GitHub-GHSA

HIGH
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover
GHSA-mxqh-q9h6-v8pq
pkg: github.com/0xJacky/nginx-ui
eco: go
published: May 6, 2026
## Summary

An unauthenticated bootstrap takeover exists in `nginx-ui` during the initial installation window exposed by `POST /api/install`.

When the instance is still uninitialized, `POST /api/install` is reachable without authentication and accepts attacker-controlled bootstrap data. The handler…

CVE-2026-42222
GitHub-GHSA

HIGH
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim
GHSA-h27v-ph7w-m9fp
pkg: github.com/0xJacky/Nginx-UI
eco: go
published: May 6, 2026
### Summary
An unauthenticated network attacker can claim the initial administrator account on a fresh `nginx-ui` instance during the first-run setup window. The public `/api/install` endpoint is reachable without authentication, and the request-encryption flow only protects payload confidentiality …
CVE-2026-42221
GitHub-GHSA

HIGH
PyLoad vulnerable to Path Traversal via Package Folder Name in set_package_data
GHSA-838g-gr43-qqg9
pkg: pyload-ng
eco: pip
published: May 5, 2026
### Summary
No sanitization of package folder name allows writing files anywhere outside the intended download directory.

#### Affected Component
– `src/pyload/core/api/__init__.py`
– Function: `set_package_data()`

### Details
When passing a folder name in the `set_package_data()` API function cal…

CVE-2026-42315
GitHub-GHSA

HIGH
@evomap/evolver's validator sandbox allowlist permits `npm`/`npx`, yielding RCE from Hub-delivered validation tasks via lifecycle scripts
GHSA-jxh8-jh77-xh6g
pkg: @evomap/evolver
eco: npm
published: May 5, 2026
## Summary

The validator-mode sandbox executor (`src/gep/validator/sandboxExecutor.js`) places `npm` and `npx` in its hard executable allowlist. Because `npm install <pkg>` and `npx -y -p <pkg> <bin>` execute arbitrary code by design (preinstall/install/postinstall lifecycle scripts and remote-pack…

GitHub-GHSA

HIGH
YAFNET has Unauthenticated Stored Second-Order XSS in Admin Event Log via Reflected `User-Agent` Header
GHSA-33gv-fc78-qgf5
pkg: YAFNET.Core, YAFNET.Core
eco: nuget
published: May 5, 2026
**Description:**
Stored (second-order) Cross-Site Scripting (XSS) occurs when attacker-controlled input is persisted through one component of an application and later rendered, without proper sanitization or contextual output encoding, by a completely different component — often one that implicitl…
CVE-2026-43938
GitHub-GHSA

HIGH
@tdurieux/anonymous_github Vulnerable to XSS via Unsanitized GitHub Repository Content Rendering in Anonymous GitHub Origin
GHSA-g485-8j3v-p6x8
pkg: @tdurieux/anonymous_github
eco: npm
published: May 5, 2026
### Summary

Anonymous GitHub fetches repository content (e.g., markdown files) from GitHub's API and renders it without sanitization. On the client side, markdown is parsed with `marked` (with `sanitize: false`) and injected into the DOM via `$sce.trustAsHtml()` + `ng-bind-html`, bypassing AngularJ…

NVD

HIGH
CVE-2026-42222
CVE-2026-42222
pkg: nginxui nginx_ui

published: May 4, 2026

Nginx UI is a web user interface for the Nginx web server. In version 2.3.5, an unauthenticated bootstrap takeover exists in nginx-ui during the initial installation window exposed by POST /api/install. At time of publication no public patches are available.
CWE: CWE-284, CWE-306
NVD

HIGH
CVE-2026-42221
CVE-2026-42221
pkg: nginxui nginx_ui

published: May 4, 2026

Nginx UI is a web user interface for the Nginx web server. From version 2.0.0 to before version 2.3.8, an unauthenticated network attacker can claim the initial administrator account on a fresh nginx-ui instance during the first-run setup window. The public /api/install endpoint is reachable without…
CWE: CWE-306
GitHub-GHSA

HIGH
Ech0's OAuth redirect URI validation ignores path component, enables exchange-code theft
GHSA-p64j-f4x9-wq66
pkg: github.com/lin-snow/Ech0
eco: go
published: May 7, 2026
## Summary

`parseAndValidateClientRedirect` at `internal/service/auth/auth.go:448` validates OAuth client-redirect URIs by comparing only scheme and host against the admin-configured allowlist. Path, query, and fragment are ignored. The initiator at `/oauth/:provider/login` embeds the caller-suppli…

NVD

HIGH
CVE-2026-42301
CVE-2026-42301
pkg: python

published: May 9, 2026

pyp2spec generates working Fedora RPM spec file for Python projects. Prior to version 0.14.1, pyp2spec was writing PyPI package metadata (e.g. the summary field) into the generated spec file without escaping RPM macro directives. When a packager then runs rpmbuild, those directives get evaluated, so…
CWE: CWE-20, CWE-94
NVD

HIGH
CVE-2026-8148
CVE-2026-8148
pkg: windows

published: May 8, 2026

NAVER MYBOX Explorer for Windows before 3.0.11.160 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM via registry manipulation due to improper privilege checks.
CWE: CWE-266
NVD

HIGH
CVE-2022-26522
CVE-2022-26522
pkg: windows

published: May 8, 2026

The socket connection handler in aswArPot.sys in the Avast and AVG Windows Anti Rootkit driver before 22.1 allows local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) due to a double fetch vulnerability at aswArPot+0xc4a3.
CWE: CWE-367
NVD

HIGH
CVE-2026-44244
CVE-2026-44244
pkg: python

published: May 7, 2026

GitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value() passes values to Python's configparser without validating for newlines. GitPython's own _write() converts embedded newlines into indented continuation lines (e.g. \n becomes \n\…
CWE: CWE-94
GitHub-GHSA

HIGH
gix-fs: Symlink prefix-reuse allows worktree escape during checkout
GHSA-f89h-2fjh-2r9q
pkg: gix-fs
eco: rust
published: May 7, 2026
### Summary

A malicious tree can be constructed that will, when checked out with gitoxide, permit writing an attacker-controlled symlink into any existing directory the user has write access to.

### Details

During checkout, all symlink index entries are deferred and created after regular files us…

CVE-2026-44471
GitHub-GHSA

HIGH
GitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPath
GHSA-v87r-6q3f-2j67
pkg: GitPython
eco: pip
published: May 6, 2026
`GitConfigParser.set_value()` passes values to Python's `configparser` without validating for newlines. GitPython's own `_write()` converts embedded newlines into indented continuation lines (e.g. `\n` becomes `\n\t`), but Git still accepts an indented `[core]` stanza as a section header — so the …
CVE-2026-44244
NVD

HIGH
CVE-2026-7994
CVE-2026-7994
pkg: google chrome, microsoft windows

published: May 6, 2026

Inappropriate implementation in Chromoting in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium)
CWE: CWE-269
NVD

HIGH
CVE-2026-7990
CVE-2026-7990
pkg: google chrome, microsoft windows

published: May 6, 2026

Insufficient validation of untrusted input in Updater in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium)
CWE: CWE-20
NVD

HIGH
CVE-2026-7925
CVE-2026-7925
pkg: google chrome, microsoft windows

published: May 6, 2026

Use after free in Chromoting in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-7913
CVE-2026-7913
pkg: google chrome, google android

published: May 6, 2026

Insufficient policy enforcement in DevTools in Google Chrome on Android prior to 148.0.7778.96 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: High)
CWE: CWE-693
NVD

HIGH
CVE-2026-43236
CVE-2026-43236
pkg: node

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

drm/atmel-hlcdc: fix use-after-free of drm_crtc_commit after release

The atmel_hlcdc_plane_atomic_duplicate_state() callback was copying
the atmel_hlcdc_plane state structure without properly duplicating the
drm_plane_state. In pa…

NVD

HIGH
CVE-2026-43211
CVE-2026-43211
pkg: go

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

PCI: Fix pci_slot_trylock() error handling

Commit a4e772898f8b ("PCI: Add missing bridge lock to pci_bus_lock()")
delegates the bridge device's pci_dev_trylock() to pci_bus_trylock() in
pci_slot_trylock(), but it forgets to remove…

NVD

HIGH
CVE-2026-43178
CVE-2026-43178
pkg: go

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

procfs: fix possible double mmput() in do_procmap_query()

When user provides incorrectly sized buffer for build ID for PROCMAP_QUERY
we return with -ENAMETOOLONG error. After recent changes this condition
happens later, after we …

NVD

HIGH
CVE-2026-43150
CVE-2026-43150
pkg: node

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

perf/arm-cmn: Reject unsupported hardware configurations

So far we've been fairly lax about accepting both unknown CMN models
(at least with a warning), and unknown revisions of those which we
do know, as although things do freque…

NVD

HIGH
CVE-2026-43116
CVE-2026-43116
pkg: linux linux_kernel

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

netfilter: ctnetlink: ensure safe access to master conntrack

Holding reference on the expectation is not sufficient, the master
conntrack object can just go away, making exp->master invalid.

To access exp->master safely:

– Grab …

CWE: CWE-362
NVD

HIGH
CVE-2026-43106
CVE-2026-43106
pkg: linux

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

cachefiles: fix incorrect dentry refcount in cachefiles_cull()

The patch mentioned below changed cachefiles_bury_object() to expect 2
references to the 'rep' dentry. Three of the callers were changed to
use start_removing_dentry(…

NVD

HIGH
CVE-2026-43093
CVE-2026-43093
pkg: linux

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

xsk: tighten UMEM headroom validation to account for tailroom and min frame

The current headroom validation in xdp_umem_reg() could leave us with
insufficient space dedicated to even receive minimum-sized ethernet
frame. Furthermo…

NVD

HIGH
CVE-2026-43091
CVE-2026-43091
pkg: linux

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

xfrm: Wait for RCU readers during policy netns exit

xfrm_policy_fini() frees the policy_bydst hash tables after flushing the
policy work items and deleting all policies, but it does not wait for
concurrent RCU readers to leave the…

NVD

HIGH
CVE-2026-43084
CVE-2026-43084
pkg: linux

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nfnetlink_queue: make hash table per queue

Sharing a global hash table among all queues is tempting, but
it can cause crash:

BUG: KASAN: slab-use-after-free in nfqnl_recv_verdict+0x11ac/0x15e0 [nfnetlink_queue]
[..]
n…

NVD

HIGH
CVE-2026-43078
CVE-2026-43078
pkg: linux

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

crypto: af_alg – Fix page reassignment overflow in af_alg_pull_tsgl

When page reassignment was added to af_alg_pull_tsgl the original
loop wasn't updated so it may try to reassign one more page than
necessary.

Add the check to th…

NVD

HIGH
CVE-2026-43076
CVE-2026-43076
pkg: linux

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

ocfs2: validate inline data i_size during inode read

When reading an inode from disk, ocfs2_validate_inode_block() performs
various sanity checks but does not validate the size of inline data. If
the filesystem is corrupted, an i…

NVD

HIGH
CVE-2026-43075
CVE-2026-43075
pkg: linux

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

ocfs2: fix out-of-bounds write in ocfs2_write_end_inline

KASAN reports a use-after-free write of 4086 bytes in
ocfs2_write_end_inline, called from ocfs2_write_end_nolock during a
copy_file_range splice fallback on a corrupted ocfs…

NVD

HIGH
CVE-2026-43074
CVE-2026-43074
pkg: linux

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

eventpoll: defer struct eventpoll free to RCU grace period

In certain situations, ep_free() in eventpoll.c will kfree the epi->ep
eventpoll struct while it still being used by another concurrent thread.
Defer the kfree() to an RCU…

NVD

HIGH
CVE-2026-34462
CVE-2026-34462
pkg: sandboxie-plus sandboxie

published: May 5, 2026

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, several ProcessServer handlers (KillAllHandler, SuspendAllHandler, and RunSandboxedHandler) copy a WCHAR boxname[34] field from request structures into WCHAR[40] stack buffers using wcscpy …
CWE: CWE-121, CWE-170
NVD

HIGH
CVE-2026-34461
CVE-2026-34461
pkg: sandboxie-plus sandboxie

published: May 5, 2026

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, the SbieIniServer RunSbieCtrl handler contains a stack buffer overflow. The MSGID_SBIE_INI_RUN_SBIE_CTRL message is handled before normal sandbox and impersonation checks, and for non-sandb…
CWE: CWE-121
GitHub-GHSA

HIGH
gitoxide: CommandForbiddenInModulesConfiguration Bypass in gix_submodule::File::update() Enables Arbitrary Command Execution via .gitmodules
GHSA-f26g-jm89-4g65
pkg: gix
eco: rust
published: May 5, 2026
### Summary

[`gix_submodule::File::update()`](https://github.com/GitoxideLabs/gitoxide/blob/main/gix-submodule/src/access.rs#L168) is the API that gates whether an attacker-supplied `.gitmodules` file may set `update = !<shell command>`. The function is designed to return `Err(CommandForbiddenInMod…

GitHub-GHSA

HIGH
OpenClaw vulnerable to arbitrary code execution via attacker-controlled setup-api.js loaded from cwd during env-key resolution
GHSA-r39h-4c2p-3jxp
pkg: openclaw
eco: npm
published: May 5, 2026
## Summary

OpenClaw's bundled plugin setup resolver could fall back to `process.cwd()` while resolving provider setup metadata. If a user ran an OpenClaw command from an attacker-controlled repository containing `extensions/<plugin>/setup-api.js`, OpenClaw could load and execute that JavaScript dur…

NVD

HIGH
CVE-2026-43070
CVE-2026-43070
pkg: linux

published: May 5, 2026

In the Linux kernel, the following vulnerability has been resolved:

bpf: Reset register ID for BPF_END value tracking

When a register undergoes a BPF_END (byte swap) operation, its scalar
value is mutated in-place. If this register previously shared a scalar ID
with another register (e.g., after a…

NVD

HIGH
CVE-2026-43063
CVE-2026-43063
pkg: linux

published: May 5, 2026

In the Linux kernel, the following vulnerability has been resolved:

xfs: don't irele after failing to iget in xfs_attri_recover_work

xlog_recovery_iget* never set @ip to a valid pointer if they return
an error, so this irele will walk off a dangling pointer. Fix that.

NVD

HIGH
CVE-2026-43060
CVE-2026-43060
pkg: linux

published: May 5, 2026

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nft_ct: drop pending enqueued packets on removal

Packets sitting in nfqueue might hold a reference to:

– templates that specify the conntrack zone, because a percpu area is
used and module removal is possible.
– conn…

NVD

HIGH
CVE-2026-7791
CVE-2026-7791
pkg: windows

published: May 4, 2026

Improper privilege management in the log rotation mechanism of the Skylight Workspace Config Service in Amazon WorkSpaces for Windows before 2.6.2034.0 allows a local non-admin authenticated user to place arbitrary files into arbitrary locations bypassing file system permission protections, leading …
CWE: CWE-367
GitHub-GHSA

HIGH
Ech0 has Server-Side Request Forgery (SSRF) via Connect Handler fetchPeerConnectInfo
GHSA-8mc6-xjpr-h98x
pkg: github.com/lin-snow/ech0
eco: go
published: May 7, 2026
## Summary
The `fetchPeerConnectInfo` function in `internal/service/connect/connect.go:214-239` uses `httpUtil.SendRequest` (no SSRF protection) instead of `SendSafeRequest` (which has `ValidatePublicHTTPURL` with private IP blocking). This allows authenticated users to make the server request arbit…
NVD

HIGH
CVE-2026-41905
CVE-2026-41905
pkg: curl

published: May 7, 2026

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, Helper::sanitizeRemoteUrl() in app/Misc/Helper.php follows HTTP redirects via curlGetLastRedirectedUrl() but then re-validates the original URL instead of the final redirect destination. An a…
CWE: CWE-918
NVD

HIGH
CVE-2026-41688
CVE-2026-41688
pkg: curl

published: May 7, 2026

Wallos is an open-source, self-hostable personal subscription tracker. In versions 4.8.4 and prior, the incomplete SSRF fix in Wallos validates webhook URLs via gethostbyname() but passes the original hostname to cURL without CURLOPT_RESOLVE pinning on 10 of 11 outbound HTTP endpoints, leaving a DNS…
CWE: CWE-918
GitHub-GHSA

HIGH
DevSpace UI Server WebSocket CheckOrigin does not validate source
GHSA-hqwm-7x7x-8379
pkg: github.com/loft-sh/devspace
eco: go
published: May 6, 2026
### Description

DevSpace's UI server WebSocket accepts connections from all origins by default, and therefore several endpoints are exposed via this WebSocket. When a developer runs the DevSpace UI and at the same time uses a browser to access the internet, a malicious website they visit can use th…

CVE-2026-42283
GitHub-GHSA

HIGH
OpenStack Ironic has an Incorrect Resource Transfer Between Spheres
GHSA-54w4-233h-x86g
pkg: ironic-python-agent, ironic-python-agent, ironic-python-agent
eco: pip
published: May 5, 2026
An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a remote endpoint. The credential forwarded is a time-limited Keystone token (which provides access to all OpenStack services Ironic is authorized for); or…
CVE-2026-42997
GitHub-GHSA

HIGH
Open WebUI's Base Model Routing Bypasses Access Control via Model Chaining
GHSA-9vvh-qmjx-p4q8
pkg: open-webui
eco: pip
published: May 8, 2026
# Base Model Routing Bypasses Access Control via Model Chaining

## Affected Component

Model chaining via `base_model_id`:
– `backend/open_webui/routers/models.py` (lines 170-214, `create_new_model`)
– `backend/open_webui/routers/models.py` (lines 254-308, `import_models`)
– `backend/open_webui/mai…

CVE-2026-44555
GitHub-GHSA

HIGH
MikroORM has SQL injection via runtime-controlled identifiers and JSON-path keys
GHSA-cfw5-68c4-ffqp
pkg: @mikro-orm/sql, @mikro-orm/knex
eco: npm
published: May 8, 2026
## Summary

MikroORM's identifier-quoting helper (`Platform.quoteIdentifier` and the postgres/mssql overrides) and its JSON-path emitters (`Platform.getSearchJsonPropertyKey`, `quoteJsonKey`) did not properly escape characters that delimit the SQL identifier or string-literal context they emit into.…

CVE-2026-44680
NVD

HIGH
CVE-2026-42351
CVE-2026-42351
pkg: python

published: May 8, 2026

pygeoapi is a Python server implementation of the OGC API suite of standards. From version 0.23.0 to before version 0.23.3, a raw string path concatenation vulnerability in pygeoapi's STAC FileSystemProvider plugin can allow for requests to STAC collection based collections to expose directories wit…
CWE: CWE-22
GitHub-GHSA

HIGH
free5GC NRF: type-confusion panic in POST /oauth2/token structured-form parser via Reflect.Set on incompatible types
GHSA-f8qv-7x5w-qr48
pkg: github.com/free5gc/nrf
eco: go
published: May 8, 2026
### Summary
free5GC's NRF root SBI endpoint `POST /oauth2/token` contains a parser-level type-confusion bug family. The handler in `NFs/nrf/internal/sbi/api_accesstoken.go` reflects over `models.NrfAccessTokenAccessTokenReq`, special-cases only plain `string` and `NrfNfManagementNfType` fields, and …
CVE-2026-44325
GitHub-GHSA

HIGH
free5GC's NEF 3gpp-pfd-management PATCH applications/{appId} panics on UDR access failure due to nil ProblemDetails dereference
GHSA-j59f-x285-69jx
pkg: github.com/free5gc/nef
eco: go
published: May 8, 2026
### Summary
free5GC's NEF `PATCH /3gpp-pfd-management/v1/{afId}/transactions/{transId}/applications/{appId}` handler panics with a nil-pointer dereference when the upstream UDR call fails AND the consumer wrapper returns `err != nil` together with a nil `*ProblemDetails`. The handler's `errPfdData !…
CVE-2026-44322
GitHub-GHSA

HIGH
free5GC's SMF UPI POST /upi/v1/upNodesLinks exits the SMF process on overlapping UE pools (unauthenticated, reachable Fatalf)
GHSA-44qj-cghf-9p97
pkg: github.com/free5gc/smf
eco: go
published: May 8, 2026
### Summary
free5GC's SMF mounts the `UPI` management route group without inbound OAuth2 middleware (same root cause as free5gc/free5gc#887). The `POST /upi/v1/upNodesLinks` create-or-update handler accepts attacker-controlled JSON and passes it directly into `UpNodesFromConfiguration()`, which call…
CVE-2026-44321
GitHub-GHSA

HIGH
free5GC's NEF crashes via logger.Fatal on PFD notification delivery failure (attacker-controlled notifyUri)
GHSA-rxrq-fv76-26pr
pkg: github.com/free5gc/nef
eco: go
published: May 8, 2026
### Summary
free5GC's NEF terminates the entire process when a stored PFD-subscription `notifyUri` cannot be reached. In `PfdChangeNotifier.FlushNotifications()`, the notifier calls `NnefPFDmanagementNotify(…)` and on any delivery error invokes `logger.PFDManageLog.Fatal(err)`, which is `os.Exit(1…
CVE-2026-44319
GitHub-GHSA

HIGH
free5GC's PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 via nil pointer dereference
GHSA-wr8j-6chw-gm6p
pkg: github.com/free5gc/pcf
eco: go
published: May 8, 2026
### Summary
free5GC's PCF `POST /npcf-smpolicycontrol/v1/sm-policies` handler (`HandleCreateSmPolicyRequest`) panics with a nil-pointer dereference when a downstream OpenAPI consumer call (UDR lookup) returns `404 Not Found` and the consumer wrapper returns `err != nil` together with a nil response …
CVE-2026-44316
GitHub-GHSA

HIGH
banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI
GHSA-gphh-9q3h-jgpp
pkg: banks
eco: pip
published: May 8, 2026
## Summary

`banks <= 2.4.1` uses `jinja2.Environment()` (unsandboxed) to render prompt templates. Applications that pass user-supplied strings as the template argument to `Prompt()` are vulnerable to Server-Side Template Injection (SSTI), which can lead to Remote Code Execution (RCE) on the host sy…

CVE-2026-44209
GitHub-GHSA

HIGH
fast-uri vulnerable to host confusion via percent-encoded authority delimiters
GHSA-v39h-62p7-jpjc
pkg: fast-uri
eco: npm
published: May 8, 2026
### Impact

`fast-uri` v3.1.1 and earlier decodes percent-encoded authority delimiters (`%40` as `@`, `%3A` as `:`) inside the host component and serializes them back as raw characters. This changes the URI structure, turning a hostname into userinfo plus a different host.

For example, `http://trus…

CVE-2026-6322
GitHub-GHSA

HIGH
bitcoinj has a ScriptExecution P2PKH/P2WPKH Verification Bypass
GHSA-hfcf-v2f8-x9pc
pkg: org.bitcoinj:bitcoinj-core
eco: maven
published: May 8, 2026
### Summary
`ScriptExecution.correctlySpends()` contains two fast-path verification bugs for standard `P2PKH` and native `P2WPKH` spends in `core/src/main/java/org/bitcoinj/script/ScriptExecution.java`.

In both branches, bitcoinj verifies an attacker-controlled signature/public-key pair but fails t…

CVE-2026-44714
GitHub-GHSA

HIGH
fast-uri vulnerable to path traversal via percent-encoded dot segments
GHSA-q3j6-qgpj-74h6
pkg: fast-uri
eco: npm
published: May 8, 2026
### Impact

`fast-uri` v3.1.0 and earlier decodes percent-encoded path separators (`%2F`) and dot segments (`%2E`) before applying dot-segment removal in `normalize()` and `equal()`. This makes encoded path data behave like real `/` and `..`, so distinct URIs collapse onto the same normalized path.

CVE-2026-6321
GitHub-GHSA

HIGH
@fastify/accepts-serializer Vulnerable to Denial of Service via Unbounded Accept Header Cache Growth
GHSA-qxhc-wx3p-2wmg
pkg: @fastify/accepts-serializer
eco: npm
published: May 8, 2026
### Impact

`@fastify/accepts-serializer` cached serializer-selection results keyed by the request `Accept` header without a size limit or eviction policy. A remote unauthenticated client could send many distinct but matching `Accept` header variants to make the cache grow unbounded. Under sustained…

CVE-2026-7768
GitHub-GHSA

HIGH
ZITADEL has LDAP Filter Injection in Login Flow
GHSA-rxvx-hhpj-q6px
pkg: github.com/zitadel/zitadel, github.com/zitadel/zitadel, github.com/zitadel/zitadel
eco: go
published: May 8, 2026
## Summary

A vulnerability was discovered in Zitadel's LDAP identity provider implementation, which fails to properly escape user-provided usernames before incorporating them into LDAP search filters. This allows unauthenticated attackers to perform LDAP Filter Injection during the login process.

CVE-2026-44671
NVD

HIGH
CVE-2026-44498
CVE-2026-44498
pkg: zfnd zebrad

published: May 8, 2026

ZEBRA is a Zcash node written entirely in Rust. Prior to version 4.4.0, Zebra's block validator undercounts transparent signature operations against the 20000-sigop block limit (MAX_BLOCK_SIGOPS), allowing it to accept blocks that zcashd rejects with bad-blk-sigops. A miner who produces such a block…
CWE: CWE-682
NVD

HIGH
CVE-2026-41584
CVE-2026-41584
pkg: zfnd zebra-chain, zfnd zebrad

published: May 8, 2026

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and prior to zebra-chain version 6.0.2, Orchard transactions contain a rk field which is a randomized validating key and also an elliptic curve point. The Zcash specification allows the field to be the identity (a "zero" v…
CWE: CWE-617
NVD

HIGH
CVE-2024-46508
CVE-2024-46508
pkg: yeti-platform yeti

published: May 8, 2026

yeti-platform yeti before 2.1.12 allows attackers to generate valid JWT tokens is the secret is not changed (by setting YETI_AUTH_SECRET_KEY to a value other than SECRET).
CWE: CWE-798
NVD

HIGH
CVE-2026-39836
CVE-2026-39836
pkg: windows

published: May 7, 2026

The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).
GitHub-GHSA

HIGH
vm2 Sandbox Access to Host Buffer.alloc Allows timeout Bypass Resulting in Memory Exhaustion
GHSA-6785-pvv7-mvg7
pkg: vm2
eco: npm
published: May 7, 2026
### Summary
Sandboxed code can call `Buffer.alloc()` with an arbitrary size to allocate memory directly on the host heap. Because `Buffer.alloc` is a synchronous C++ native call, vm2's `timeout` option cannot interrupt it. A single request can exhaust host memory and crash the process with a `FATAL …
CVE-2026-44004
NVD

HIGH
CVE-2026-41640
CVE-2026-41640
pkg: node

published: May 7, 2026

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.39, the queryParentSQL() function in the core database package constructs a recursive CTE query by joining nodeIds with string concatenation instead of using paramete…
CWE: CWE-89
GitHub-GHSA

HIGH
Talos Linux has a local privilege escalation from untrusted workloads
GHSA-m38g-vww2-mvgx
pkg: github.com/siderolabs/talos
eco: go
published: May 7, 2026
### Summary

A vulnerability in the Linux kernel's algif_aead subsystem (CVE-2026-31431, "copy.fail") allows an unprivileged container workload to corrupt arbitrary file page-cache pages via the AF_ALG crypto interface and splice(). On Talos Linux, this vulnerability can be chained into a complete n…

GitHub-GHSA

HIGH
rust-zserio has Unbounded Memory Allocation
GHSA-fpf5-4jw8-67×8
pkg: rust-zserio
eco: rust
published: May 7, 2026
### Impact

When deserializing arrays, strings or bytes (blob) types zserio first reads the size of the variable, and then allocates sufficient memory to load data. Since the size is always trusted this can be abused by creating a data file with a large size value, causing the zserio runtime to allo…

GitHub-GHSA

HIGH
Gotenberg has an unauthenticated denial of service via echo.Context pool reuse in webhook async goroutine
GHSA-r33j-c622-r6qp
pkg: github.com/gotenberg/gotenberg/v8
eco: go
published: May 7, 2026
## Summary

The webhook middleware spawns a goroutine that holds a reference to the request's `echo.Context` after the synchronous handler returns `ErrAsyncProcess` and Echo recycles the context back to its `sync.Pool`. When a concurrent request claims the recycled context, `c.Reset()` clears the st…

CVE-2026-42594
GitHub-GHSA

HIGH
Netty: HttpContentDecompressor maxAllocation bypass when Content-Encoding set to br/zstd/snappy leads to decompression bomb DoS
GHSA-f6hv-jmp6-3vwv
pkg: io.netty:netty-codec-http, io.netty:netty-codec-http2, io.netty:netty-codec-http
eco: maven
published: May 7, 2026
## Summary

`HttpContentDecompressor` accepts a `maxAllocation` parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via `ZlibDecoder`, but is silently ignored when the content encoding is `br` (Brotli), …

CVE-2026-42587
GitHub-GHSA

HIGH
Netty Lz4FrameDecoder is vulnerable to resource exhaustion
GHSA-mj4r-2hfc-f8p6
pkg: io.netty:netty-codec-compression, io.netty:netty-codec
eco: maven
published: May 7, 2026
### Summary
Lz4FrameDecoder allocates a ByteBuf of size `decompressedLength` (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus `compressedLength` payload bytes – 22 bytes if `compressedLength == 1` – to force that allocation.

### Details
io.netty.handler.codec.compres…

CVE-2026-42583
GitHub-GHSA

HIGH
Netty HTTP/3 QPACK literal unbounded allocation
GHSA-2c5c-chwr-9hqw
pkg: io.netty:netty-codec-http3
eco: maven
published: May 7, 2026
### Summary
When Netty decodes HTTP/3 headers, it sometimes runs `new byte[length]` using a length from the wire before checking that many bytes are really there. A small malicious header can claim a huge length (on the order of a gigabyte).

### Details
When decoding header blocks, the non-Huffman …

CVE-2026-42582
GitHub-GHSA

HIGH
Netty has a DNS Codec Input Validation Bypass (Encoder + Decoder)
GHSA-cm33-6792-r9fm
pkg: io.netty:netty-codec-dns, io.netty:netty-codec-dns
eco: maven
published: May 7, 2026
# Security Vulnerability Report: DNS Codec Input Validation Bypass in Netty (Encoder + Decoder)

## 1. Vulnerability Summary

| Field | Value |
|——-|——-|
| **Product** | Netty |
| **Version** | 4.2.12.Final (and all prior versions with codec-dns) |
| **Component** | `io.netty.handler.codec.d…

CVE-2026-42579
GitHub-GHSA

HIGH
Netty epoll transport denial of service via RST on half-closed TCP connection
GHSA-rwm7-x88c-3g2p
pkg: io.netty:netty-transport-native-epoll
eco: maven
published: May 6, 2026
## Summary

Netty's epoll transport fails to detect and close TCP connections that receive a RST after being half-closed, leading to stale channels that are never cleaned up and, in some code paths, a 100% CPU busy-loop in the event loop thread.

## Affected versions

All versions of 4.2.x `netty-tr…

CVE-2026-42577
GitHub-GHSA

HIGH
Nerdbank.MessagePack: Attacker-controlled stackalloc in DateTime decoding causes process-terminating StackOverflowException
GHSA-2cwq-pwfr-wcw3
pkg: Nerdbank.MessagePack
eco: nuget
published: May 6, 2026
### Summary

Nerdbank.MessagePack contains an uncontrolled stack allocation vulnerability in DateTime decoding. A malicious MessagePack payload can declare an oversized timestamp extension length, causing the reader to allocate an attacker-controlled number of bytes on the stack. This can trigger a …

CVE-2026-44375
GitHub-GHSA

HIGH
python-multipart has Denial of Service via unbounded multipart part headers
GHSA-pp6c-gr5w-3c5g
pkg: python-multipart
eco: pip
published: May 6, 2026
### Summary

`python-multipart` has a denial of service vulnerability in multipart part header parsing. When parsing `multipart/form-data`, `MultipartParser` previously had no limit on the number of part headers or the size of an individual part header. An attacker could send a request with either m…

CVE-2026-42561
GitHub-GHSA

HIGH
Granian vulnerable to unauthenticated DoS via WebSocket subprotocol header panic
GHSA-vrg7-482j-p6f6
pkg: granian
eco: pip
published: May 6, 2026
### Summary

Granian aborts a worker process when an unauthenticated client sends a WebSocket upgrade request whose `Sec-WebSocket-Protocol` header contains non-ASCII bytes.

The crash happens in Granian's WebSocket scope construction path, before the ASGI application is invoked.

This is a single-r…

CVE-2026-42544
GitHub-GHSA

HIGH
Snappier has an infinite loop during SnappyStream decompression with malformed framed input
GHSA-pggp-6c3x-2xmx
pkg: Snappier
eco: nuget
published: May 6, 2026
### Summary
`Snappier.SnappyStream` enters an uncatchable infinite loop when decompressing a malformed framed-format Snappy stream as small as 15 bytes.

### Details
The hang manifests as a userspace busy loop with SnappyStreamDecompressor.Decompress repeatedly calling Crc32CAlgorithm.Append. The ex…

CVE-2026-44302
GitHub-GHSA

HIGH
Micronaut has unbounded `formattersCache` in `TimeConverterRegistrar` that Allows Memory Exhaustion via `Accept-Language` Header
GHSA-8hjv-92q9-g4xj
pkg: io.micronaut:micronaut-context
eco: maven
published: May 6, 2026
## Summary

`TimeConverterRegistrar` caches `DateTimeFormatter` instances in an unbounded `ConcurrentHashMap<String, DateTimeFormatter>` whose key is derived from the `@Format` annotation pattern concatenated with the locale from the HTTP `Accept-Language` header. Because `Locale.forLanguageTag()` a…

CVE-2026-44241
GitHub-GHSA

HIGH
basic-ftp allows a malicious FTP server to cause client-side denial of service via unbounded multiline control response buffering
GHSA-rpmf-866q-6p89
pkg: basic-ftp
eco: npm
published: May 6, 2026
## Summary

`basic-ftp` is vulnerable to client-side denial of service when parsing FTP control-channel multiline responses.

A malicious or compromised FTP server can send an unterminated multiline response during the initial FTP banner phase, before authentication. The client keeps appending attac…

CVE-2026-44240
NVD

HIGH
CVE-2026-7948
CVE-2026-7948
pkg: google chrome, microsoft windows

published: May 6, 2026

Race in Chromoting in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Medium)
CWE: CWE-362
NVD

HIGH
CVE-2026-7897
CVE-2026-7897
pkg: google chrome, apple iphone_os

published: May 6, 2026

Use after free in Mobile in Google Chrome on iOS prior to 148.0.7778.96 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
GitHub-GHSA

HIGH
Nokogiri CSS selector tokenizer has regular expression backtracking
GHSA-c4rq-3m3g-8wgx
pkg: nokogiri
eco: rubygems
published: May 6, 2026
## Summary

Nokogiri's CSS selector tokenizer contains regular expressions whose construction may result in exponential regex backtracking on adversarial selectors. Three ReDoS vectors are addressed in this release:

1. String-literal tokenization on certain unterminated quoted-string input.
2. Stri…

NVD

HIGH
CVE-2026-23870
CVE-2026-23870
pkg: react

published: May 6, 2026

A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to server crashes, out-of-memory exceptions or excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel, react…
NVD

HIGH
CVE-2026-43226
CVE-2026-43226
pkg: linux linux_kernel

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

net/rds: No shortcut out of RDS_CONN_ERROR

RDS connections carry a state "rds_conn_path::cp_state"
and transitions from one state to another and are conditional
upon an expected state: "rds_conn_path_transition."

There is one exc…

NVD

HIGH
CVE-2026-43164
CVE-2026-43164
pkg: go

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

udplite: Fix null-ptr-deref in __udp_enqueue_schedule_skb().

syzbot reported null-ptr-deref of udp_sk(sk)->udp_prod_queue. [0]

Since the cited commit, udp_lib_init_sock() can fail, as can
udp_init_sock() and udpv6_init_sock().

L…

NVD

HIGH
CVE-2026-43101
CVE-2026-43101
pkg: linux

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data()

We need to check __in6_dev_get() for possible NULL value, as
suggested by Yiming Qian.

Also add skb_dst_dev_rcu() instead of skb_dst_dev(),
and two missing …

NVD

HIGH
CVE-2026-43099
CVE-2026-43099
pkg: linux

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

ipv4: icmp: fix null-ptr-deref in icmp_build_probe()

ipv6_stub->ipv6_dev_find() may return ERR_PTR(-EAFNOSUPPORT) when the
IPv6 stack is not active (CONFIG_IPV6=m and not loaded), and passing
this error pointer to dev_hold() will …

GitHub-GHSA

HIGH
Mongoose's Improper Sanitization of $nor in sanitizeFilter May Allow NoSQL Injection
GHSA-wpg9-53fq-2r8h
pkg: mongoose, mongoose, mongoose
eco: npm
published: May 5, 2026
### Impact

This vulnerability allows bypassing Mongoose’s sanitizeFilter query sanitization mechanism via the `$nor` operator.

When sanitizeFilter is enabled, Mongoose wraps query operators in `$eq` to neutralize them. However, prior to the fix, `$nor` was not included in the set of logical oper…

CVE-2026-42334
GitHub-GHSA

HIGH
changedetection.io has an Arbitrary Local File Read via a crafted backup restore
GHSA-8757-69j2-hx56
pkg: changedetection.io
eco: pip
published: May 5, 2026
### Details
The vulnerability is caused by trusting attacker-controlled snapshot paths restored from backup files.

The vulnerable flow starts in the backup restore logic. When a backup ZIP is restored, the application extracts the archive and copies each restored watch UUID directory directly into …

CVE-2026-43891
GitHub-GHSA

HIGH
Twisted has a Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chains
GHSA-grgv-6hw6-v9g4
pkg: Twisted
eco: pip
published: May 5, 2026
### Details

The twisted.names module is vulnerable to a Denial of Service (DoS) attack via resource exhaustion during DNS name decompression. A remote, unauthenticated attacker can exploit this by sending a crafted TCP DNS packet containing deeply chained compression pointers. This flaw bypasses pr…

CVE-2026-42304
GitHub-GHSA

HIGH
GoBGP has a panic in AdjRib.Update via malformed BGP Update message (Nil Pointer Dereference)
GHSA-p3w2-64xm-833j
pkg: github.com/osrg/gobgp/v4
eco: go
published: May 5, 2026
### Summary
Remote Denial of Service (DoS) via Nil Pointer Dereference in BGP Update Processing
An unauthenticated remote BGP peer can trigger a fatal panic in GoBGP by sending a specially crafted BGP UPDATE message. When the server receives a message with inconsistent attribute lengths, it improper…
CVE-2026-42285
GitHub-GHSA

HIGH
ssrfcheck: SSRF Bypass Caused by Failure to Classify Reserved IP Address Space as Invalid
GHSA-p4hc-9pjh-55c8
pkg: ssrfcheck
eco: npm
published: May 5, 2026
# SSRF Bypass in `ssrfcheck` – fails to classify reserved IP address space as invalid

`ssrfcheck` is an npm package that serves to provide protection from SSRF by validating URLs or hostname inputs.

Resources:
* Project's GitHub code repository: https://github.com/felippe-regazio/ssrfcheck
* Pr…

CVE-2025-8267
NVD

HIGH
CVE-2026-40280
CVE-2026-40280
pkg: thecodingmachine gotenberg

published: May 5, 2026

Gotenberg is an API-based document conversion tool. In versions 8.30.1 and earlier, the default private-IP deny-lists for the –webhook-deny-list and –api-download-from-deny-list flags use a case-sensitive regular expression (^https?://) to match URL schemes. Because Go's net/url.Parse() normalizes…
CWE: CWE-918
NVD

HIGH
CVE-2026-32934
CVE-2026-32934
pkg: coredns.io coredns

published: May 5, 2026

CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-QUIC (DoQ) server can be driven into unbounded goroutine and memory growth by a remote client that opens many QUIC streams and sends only 1 byte per stream. When the worker pool is full, CoreDNS still spawns a gor…
CWE: CWE-770
GitHub-GHSA

HIGH
pgjdbc: Unbounded PBKDF2 iterations in SCRAM authentication allows CPU exhaustion DoS
GHSA-98qh-xjc8-98pq
pkg: org.postgresql:postgresql
eco: maven
published: May 5, 2026
## Summary
pgjdbc is vulnerable to a client-side denial of service during SCRAM-SHA-256 authentication.

### Impact
A malicious server can instruct the driver to perform SCRAM authentication with a very large iteration count.
With a large enough value, the client spends an unbounded amount of CPU ti…

CVE-2026-42198
GitHub-GHSA

HIGH
Prometheus: Remote read endpoint allows denial of service via crafted snappy payload
GHSA-8rm2-7qqf-34qm
pkg: github.com/prometheus/prometheus
eco: go
published: May 5, 2026
### Impact

The remote read endpoint (`/api/v1/read`) does not validate the declared decoded length in a snappy-compressed request body before allocating memory.
An unauthenticated attacker can send a small payload that causes a huge heap allocation per request. Under concurrent load this can exhaus…

CVE-2026-42154
GitHub-GHSA

HIGH
Prometheus Azure AD remote write OAuth client secret exposed via config API
GHSA-wg65-39gg-5wfj
pkg: github.com/prometheus/prometheus
eco: go
published: May 5, 2026
### Impact

Users who use Azure AD remote write with OAuth authentication are impacted.

The `client_secret` field in the Azure AD remote write OAuth configuration (`storage/remote/azuread`) was typed as `string` instead of `Secret`. Prometheus redacts fields of type `Secret` when serving the config…

CVE-2026-42151
NVD

HIGH
CVE-2026-30923
CVE-2026-30923
pkg: owasp modsecurity

published: May 5, 2026

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Libmodsecurity is one component of the ModSecurity v3 project. A segmentation fault occurs when a rule using the t:hexDecode transformation inspects a query string parameter containing a si…
CWE: CWE-125
NVD

HIGH
CVE-2026-7776
CVE-2026-7776
pkg: tls

published: May 4, 2026

Boundary Community Edition and Boundary Enterprise (“Boundary”) workers are vulnerable to a denial-of-service condition during node enrollment TLS handshakes. An attacker with network access to the worker authentication listener may open a connection and delay or withhold the client certificate …
CWE: CWE-770
NVD

HIGH
CVE-2026-7768
CVE-2026-7768
pkg: node

published: May 4, 2026

@fastify/accepts-serializer cached serializer-selection results keyed by the request Accept header without a size limit or eviction policy. A remote unauthenticated client could send many distinct but matching Accept header variants to make the cache grow unbounded, eventually exhausting the Node.js…
CWE: CWE-770
NVD

HIGH
CVE-2026-42236
CVE-2026-42236
pkg: n8n n8n

published: May 4, 2026

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the MCP OAuth client registration endpoint accepted unauthenticated requests and stored client data without adequate resource controls. An unauthenticated remote attacker could exhaust server memory r…
CWE: CWE-770
NVD

HIGH
CVE-2026-42226
CVE-2026-42226
pkg: n8n n8n

published: May 4, 2026

n8n is an open source workflow automation platform. Prior to versions 1.123.33 and 2.17.5, the dynamic-node-parameters endpoints did not verify whether the authenticated caller was authorized to use a supplied credential reference. An authenticated user with access to a shared workflow could supply …
CWE: CWE-862
NVD

HIGH
CVE-2026-42151
CVE-2026-42151
pkg: oauth

published: May 4, 2026

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of Secret. Prometheus redacts fields of type Secret when serving …
CWE: CWE-200, CWE-312
GitHub-GHSA

HIGH
Apache OpenNLP AbstractModelReader has an OOM Denial of Service via Unbounded Array Allocation
GHSA-659w-93r5-9j6m
pkg: org.apache.opennlp:opennlp-tools, org.apache.opennlp:opennlp-tools
eco: maven
published: May 4, 2026
OOM Denial of Service via Unbounded Array Allocation in Apache OpenNLP AbstractModelReader 

Versions Affected: 

Before 2.5.9

Before 3.0.0-M3 

Description:

The AbstractModelReader methods getOutcomes(), getOutcomePatterns(), and getPredicates() each read a 32-bit signed integer count field f…

CVE-2026-42440
GitHub-GHSA

HIGH
OpenMRS ModuleResourcesServlet has Path Traversal that Leads to Arbitrary File Read
GHSA-jjgj-cx3q-pw4w
pkg: org.openmrs.web:openmrs-web, org.openmrs.web:openmrs-web
eco: maven
published: May 4, 2026
## Affected Versions

version ≤ 2.7.8 (latest version at time of disclosure)

https://github.com/openmrs/openmrs-core

## Impact

The `/openmrs/moduleResources/{moduleid}` endpoint in OpenMRS Core is vulnerable to a path traversal attack. The `ModuleResourcesServlet` does not properly validate use…

CVE-2026-40075
NVD

HIGH
CVE-2026-37461
CVE-2026-37461
pkg: go

published: May 4, 2026

An out-of-bounds read in the ParseIP6Extended function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.
CWE: CWE-125
NVD

HIGH
CVE-2026-34354
CVE-2026-34354
pkg: windows

published: May 8, 2026

Akamai Guardicore Platform Agent (GPA) and Zero Trust Client on Linux and macOS allow TOCTOU-based local privilege escalation. The GPA service creates an IPC socket in the world-writable /tmp directory. It accepts unauthenticated IPC control messages. This enables a TOCTOU vulnerability in the Handl…
CWE: CWE-367
NVD

HIGH
CVE-2026-42264
CVE-2026-42264
pkg: axios

published: May 8, 2026

Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPath, beforeRedirect, and insecureHTTPParser) in the HTTP adapter are read via direct property access without hasOwnProperty guards, making the…
CWE: CWE-1321
NVD

HIGH
CVE-2026-40213
CVE-2026-40213
pkg: node

published: May 7, 2026

OpenStack Cyborg before 16.0.1 uses rule:allow (check_str='@') as the default policy for multiple API endpoints. This unconditionally authorizes any request carrying a valid Keystone token regardless of roles, project membership, or scope. An authenticated user with zero role assignments can complet…
CWE: CWE-863
GitHub-GHSA

HIGH
ech0's acess tokens with expiry=never cannot be revoked: logout panics, delete does not blacklist JTI
GHSA-fpw6-hrg5-q5x5
pkg: github.com/lin-snow/Ech0
eco: go
published: May 7, 2026
## Summary

Access tokens created with the "never expire" option have no `exp` JWT claim. Three independent revocation mechanisms fail for this token type. Logout at `internal/handler/auth/auth.go:154` and `:163` dereferences `claims.ExpiresAt.Time`, panicking on the nil field so the token never hit…

GitHub-GHSA

HIGH
katalyst-koi: Session cookies can be replayed after user logout
GHSA-4cx3-3c38-j9vv
pkg: katalyst-koi, katalyst-koi
eco: rubygems
published: May 7, 2026
### Impact

Admin session cookies were not invalidated when an admin user logged out. An attacker with access to a valid admin session cookie could continue to access admin functionality after logout, until the cookie expired or session secrets were rotated.

This affects applications using Koi admi…

CVE-2026-44511
GitHub-GHSA

HIGH
wger: CSV/TSV formula injection in gym member export (first_name/last_name)
GHSA-xq9m-hmp9-fw87
pkg: wger
eco: pip
published: May 6, 2026
### Summary

The gym member TSV export endpoint in wger writes `first_name` and `last_name` profile fields verbatim to TSV cells with no formula-prefix sanitization. Any gym member (including newly self-registered users) can pre-load a spreadsheet formula into their own profile. When a gym admin lat…

GitHub-GHSA

HIGH
Axios: Prototype Pollution Gadgets – Response Tampering, Data Exfiltration, and Request Hijacking
GHSA-pf86-5×62-jrwf
pkg: axios, axios
eco: npm
published: May 5, 2026
## Summary

When `Object.prototype` has been polluted by any co-dependency with keys that axios reads without a `hasOwnProperty` guard, an attacker can (a) silently intercept and modify every JSON response before the application sees it, or (b) fully hijack the underlying HTTP transport, gaining acc…

CVE-2026-42033
GitHub-GHSA

HIGH
Axios: Header Injection via Prototype Pollution
GHSA-6chq-wfr3-2hj9
pkg: axios, axios
eco: npm
published: May 5, 2026
### Summary

A prototype pollution gadget exists in the Axios HTTP adapter (lib/adapters/http.js) that allows an attacker to inject arbitrary HTTP headers into outgoing requests. The vulnerability exploits duck-type checking of the data payload, where if Object.prototype is polluted with getHeaders,…

CVE-2026-42035
GitHub-GHSA

HIGH
Axios has prototype pollution read-side gadgets in HTTP adapter that allow credential injection and request hijacking
GHSA-q8qp-cvcw-x6jj
pkg: axios
eco: npm
published: May 5, 2026
## Summary

Five config properties in the HTTP adapter are read via direct property access without `hasOwnProperty` guards, making them exploitable as prototype pollution gadgets. When `Object.prototype` is polluted by another dependency in the same process, axios silently picks up these polluted va…

CVE-2026-42264
GitHub-GHSA

HIGH
smallbitvec: Integer overflow in safe API leads to heap buffer overflow
GHSA-97wc-2hqc-cjgr
pkg: smallbitvec
eco: rust
published: May 9, 2026
### Summary
An integer overflow in the internal capacity calculation of `smallbitvec` can lead to an undersized heap allocation, resulting in a heap buffer overflow through safe APIs only. This allows memory corruption without requiring `unsafe` code from the caller.

### Details
The issue originate…

CVE-2026-44983
GitHub-GHSA

HIGH
free5GC's NEF nnef-callback route group is unauthenticated; forged callback requests are accepted into the processing path
GHSA-wqfh-gq79-j8mf
pkg: github.com/free5gc/nef
eco: go
published: May 8, 2026
### Summary
free5GC's NEF mounts the `nnef-callback` route group without inbound OAuth2/bearer-token authorization. A forged or arbitrary bearer token (e.g. `Authorization: Bearer not-a-real-token`) is enough to reach the SMF-callback handler — the callback body is parsed and dispatched into NEF bu…
CVE-2026-44320
GitHub-GHSA

HIGH
Open WebUI Vulnerable to Arbitrary File Upload and Path Traversal
GHSA-9pgh-j74g-qj6m
pkg: open-webui
eco: pip
published: May 8, 2026
# **CONFIDENTIAL**

# KL-CAN-2024-002

## Vulnerability Details

| # | Field | Value |
|—|——-|——-|
| 1 | **Discoverer** | Jaggar Henry & Sean Segreti of KoreLogic, Inc. |
| 2 | **Date Submitted** | 2024.03.12 |
| 3 | **Title** | Open WebUI Arbitrary File Upload + Path Traversal |
| 5 | **A…

CVE-2026-44566
GitHub-GHSA

HIGH
Open WebUI has Improper Authorization Control
GHSA-4vg5-rp28-gvjf
pkg: open-webui
eco: pip
published: May 8, 2026
# **CONFIDENTIAL**

# Vulnerability Disclosure Analysis Documentation

## Vulnerability Details

| # | Field | Value |
|—|——-|——-|
| 1 | **Discoverer** | Taylor Pennington of KoreLogic, Inc. |
| 2 | **Date Submitted** | June 11, 2024 |
| 3 | **Title** | Open WebUI Improper Authorizati…

CVE-2026-44567
GitHub-GHSA

HIGH
Open WebUI has stored XSS in Excel file preview
GHSA-jwf8-pv5p-vhmc
pkg: open-webui
eco: pip
published: May 8, 2026
### Summary
Excel file attachments are previewed in an unsafe way. A crafted XLSX file payload can be used to cause the [sheetjs](https://git.sheetjs.com/sheetjs/sheetjs) function [sheet_to_html](https://git.sheetjs.com/sheetjs/sheetjs/src/commit/66cf8d2117d271f89e4f47b5fed35a3e1ea93f67/bits/79_html…
CVE-2026-44549
GitHub-GHSA

HIGH
open-webui Vulnerable to Stored XSS via Model Description
GHSA-gf5m-wcrh-7928
pkg: open-webui, open-webui
eco: npm
published: May 8, 2026
> [!IMPORTANT]
> Relationship to CVE-2024-7990

> CVE-2024-7990 (issued by huntr.dev, March 2025) describes a stored XSS in the same field — the model description — but exploits a different bypass mechanism: a second-order injection through the sanitizeResponseContent function's video-tag place…

CVE-2026-44721
NVD

HIGH
CVE-2025-55449
CVE-2025-55449
pkg: jwt

published: May 8, 2026

AstrBotDevs AstrBot 3.5.15 has Advanced_System_for_Text_Response_and_Bot_Operations_Tool as the hardcoded private key used to sign a JWT.
CWE: CWE-321
GitHub-GHSA

HIGH
Netty has HttpClientCodec response desynchronization
GHSA-57rv-r2g8-2cj3
pkg: io.netty:netty-codec-http, io.netty:netty-codec-http
eco: maven
published: May 7, 2026
### Summary
If HttpClientCodec is configured, there are use cases when a response body from one request, can be parsed as another's.

### Details
HttpClientCodec pairs each inbound response with an outbound request by `queue.poll()` once per response, including for `1xx`. If the client pipelines GE…

CVE-2026-42584
GitHub-GHSA

HIGH
YAFNET has Stored XSS in Forum Thread Posts/Replies that Allows Arbitrary JavaScript Execution for All Thread Viewers
GHSA-8rq5-wwpp-fmj2
pkg: YAFNET.Core, YAFNET.Core
eco: nuget
published: May 5, 2026
**Description:**
Stored Cross-Site Scripting (XSS) occurs when user-supplied input is persisted by the application and later rendered in another user's browser without proper sanitization or contextual output encoding. When the vulnerable sink is a high-traffic surface such as a public forum thread,…
CVE-2026-43939
GitHub-GHSA

HIGH
Apache Thrift vulnerable to Path Traversal, HTTP Request/Response Splitting, Uncontrolled Resource Consumption
GHSA-526f-jxpj-jmg2
pkg: thrift
eco: npm
published: May 5, 2026
Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting'), Uncontrolled Resource Consumption vulnerability in Apache Thrift.

This issue affects Apache Thrift:…

CVE-2026-43870
GitHub-GHSA

HIGH
Apache Thrift has an Improper Validation of Certificate with Host Mismatch Vulnerability
GHSA-7pwc-h2j2-rjgj
pkg: org.apache.thrift:libthrift
eco: maven
published: May 5, 2026
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift.

This issue affects Apache Thrift: before 0.23.0.

Users are recommended to upgrade to version [0.23.0](https://github.com/apache/thrift/releases/tag/v0.23.0), which fixes the issue.

CVE-2026-43869
NVD

HIGH
CVE-2026-7810
CVE-2026-7810
pkg: python

published: May 5, 2026

A flaw has been found in UsamaK98 python-notebook-mcp up to a05a232815809a7e425b5fa7be26e0d4369894c2. Impacted is the function create_notebook/read_notebook/edit_cell/add_cell of the file server.py. This manipulation causes path traversal. It is possible to initiate the attack remotely. The exploit …
CWE: CWE-22
GitHub-GHSA

HIGH
Amazon ECS Container Agent (Windows) is vulnerable to Information Disclosure
GHSA-fc67-c4hg-q653
pkg: github.com/aws/amazon-ecs-agent
eco: go
published: May 7, 2026
### Summary
[Amazon Elastic Container Service (Amazon ECS)](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/Welcome.html) is a fully managed container orchestration service that enables customers to deploy, manage, and scale containerized applications. An issue exists where, under certai…
NVD

HIGH
CVE-2026-39383
CVE-2026-39383
pkg: thecodingmachine gotenberg

published: May 5, 2026

Gotenberg is an API-based document conversion tool. In version 8.29.1, an unauthenticated attacker with network access can force the server to make outbound HTTP POST requests to arbitrary internal or external destinations by supplying a crafted URL in the Gotenberg-Webhook-Url request header. The F…
CWE: CWE-918
GitHub-GHSA

HIGH
Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0
GHSA-pmwg-cvhr-8vh7
pkg: axios, axios
eco: npm
published: May 5, 2026
**1. Executive Summary**
This report documents an **incomplete security patch** for the previously disclosed vulnerability **GHSA-3p68-rc4w-qgx5 (CVE-2025-62718)**, which affects the `NO_PROXY` hostname resolution logic in the Axios HTTP library.

**Background — The Original Vulnerability**
The or…

CVE-2026-42043
GitHub-GHSA

HIGH
Open WebUI's responses passthrough endpoint lacks access control authorization
GHSA-hp5m-24vp-vq2q
pkg: open-webui
eco: pip
published: May 8, 2026
## Summary

The /responses endpoint in the OpenAI router accepts any authenticated user and forwards requests directly to upstream LLM providers without enforcing per-model access control. While the primary chat completion endpoint (generate_chat_completion) checks model ownership, group membership,…

CVE-2026-44556
GitHub-GHSA

HIGH
Microsoft APM CLI's plugin.json component paths escape plugin root and copy arbitrary host files during install
GHSA-xhrw-5qxx-jpwr
pkg: apm-cli
eco: pip
published: May 7, 2026
### Summary
Microsoft APM normalizes marketplace plugins by copying plugin components referenced in `plugin.json` into `.apm/`. The manifest fields `agents`, `skills`, `commands`, and `hooks` are attacker-controlled, but the implementation does not enforce that those paths remain inside the plugin d…
CVE-2026-44641
NVD

HIGH
CVE-2026-44243
CVE-2026-44243
pkg: gitpython_project gitpython

published: May 7, 2026

GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython allows attackers who can supply a crafted reference path to an application using GitPython to write, overwrite, move, or delete files outside the repository’s .git directory …
CWE: CWE-22
GitHub-GHSA

HIGH
GitPython reference APIs has a path traversal vulnerability that allows arbitrary file write and delete outside the repository
GHSA-7545-fcxq-7j24
pkg: GitPython
eco: pip
published: May 6, 2026
## 🧾 Summary

A vulnerability in **GitPython** allows **attackers who can supply a crafted reference path to an application using GitPython** to **write, overwrite, move, or delete files outside the repository’s `.git` directory** via **insufficient validation of reference paths in reference cr…

CVE-2026-44243
GitHub-GHSA

HIGH
Auth.js SDK has Improper Permission Checking
GHSA-8qjv-jj2q-x832
pkg: auth0-js
eco: npm
published: May 6, 2026
### Description
Under specific preconditions, the Auth0.js SDK may improperly return user profile information using a valid access token when a specifically crafted invalid ID token is provided.

### Am I Affected?
Users are affected if they meet each of the following preconditions:
– Applications b…

CVE-2026-42280
NVD

HIGH
CVE-2026-43062
CVE-2026-43062
pkg: linux

published: May 5, 2026

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: L2CAP: Fix type confusion in l2cap_ecred_reconf_rsp()

l2cap_ecred_reconf_rsp() casts the incoming data to struct
l2cap_ecred_conn_rsp (the ECRED *connection* response, 8 bytes with
result at offset 6) instead of struct …

GitHub-GHSA

HIGH
Apache Atlas has a Code Injection Vulnerability
GHSA-35xx-9xrg-gwhf
pkg: org.apache.atlas:apache-atlas
eco: maven
published: May 4, 2026
### Description:
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Atlas.

Apache Atlas exposes a DSL search endpoint that accepts user-supplied query strings. Attacker can alter Gremlin traversal logic within grammar-allowed characters to access unintended data.

##…

CVE-2026-40563
GitHub-GHSA

HIGH
GitPython: Newline injection in config_writer() section parameter bypasses CVE-2026-42215 patch, enabling RCE via core.hooksPath
GHSA-mv93-w799-cj2w
pkg: GitPython
eco: pip
published: May 8, 2026
Summary

The patch for CVE-2026-42215 (GitPython 3.1.49) validates newlines only in the value parameter of set_value(). The section and option parameters are passed to configparser without any newline validation. An attacker who controls the section argument can inject \n to write arbitrary section …

NVD

HIGH
CVE-2026-34596
CVE-2026-34596
pkg: sandboxie-plus sandboxie

published: May 5, 2026

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, a Time-of-Check-to-Time-of-Use (TOCTOU) race condition exists during addon installation. When a user installs an addon through the SandMan interface, UpdUtil.exe is spawned as SYSTEM by Sbi…
CWE: CWE-367
GitHub-GHSA

HIGH
awslabs/tough is Missing Delegated Metadata Validation
GHSA-4v58-8p28-2rq3
pkg: tough, tuftool
eco: rust
published: May 5, 2026
### Summary
Missing expiration, hash, and length enforcement in delegated metadata validation in awslabs/tough before tough-v0.22.0 allows remote authenticated users with delegated signing authority to bypass TUF specification integrity checks for delegated targets metadata and poison the local meta…
CVE-2026-6967
GitHub-GHSA

HIGH
awslabs/tough Delegated Roles have a Signature Threshold Bypass
GHSA-8m7c-8m39-rv4x
pkg: tough, tuftool
eco: rust
published: May 5, 2026
### Summary
Improper verification of cryptographic signature uniqueness in delegated role validation in awslabs/tough before tough-v0.22.0 allows remote authenticated users to bypass the TUF signature threshold requirement by duplicating a valid signature, causing the client to accept forged delegat…
CVE-2026-6966
GitHub-GHSA

HIGH
@yoda.digital/gitlab-mcp-server's SSE transport has no authentication and wildcard CORS, exposing all 86 GitLab tools
GHSA-8jr5-6gvj-rfpf
pkg: @yoda.digital/gitlab-mcp-server
eco: npm
published: May 9, 2026
## SSE Transport Has No Authentication and Wildcard CORS, Exposing All 86 GitLab Tools Including Destructive Operations

A review of `mcp-gitlab-server` at commit `80a7b4cf3fba6b55389c0ef491a48190f7c8996a` uncovered that the SSE HTTP transport — advertised in the README and comparison table as a d…

CVE-2026-44895
GitHub-GHSA

HIGH
Zebra has Permanent Block Discovery Halt via Gossip Queue Saturation and Syncer Poisoning
GHSA-h9hm-m2xj-4rq9
pkg: zebrad
eco: rust
published: May 8, 2026
## Summary

A composite denial-of-service vulnerability in Zebra's block discovery pipeline allows an unauthenticated remote attacker to permanently halt all new block discovery on a targeted node. The attack exploits three independent weaknesses in the gossip, syncer, and download subsystems — al…

CVE-2026-44499
GitHub-GHSA

HIGH
n8n-mcp webhook and API client paths has an authenticated SSRF
GHSA-cmrh-wvq6-wm9r
pkg: n8n-mcp
eco: npm
published: May 8, 2026
### Summary

Authenticated Server-Side Request Forgery affecting the webhook trigger tools, the n8n API client (`N8N_API_URL`), and per-request URLs supplied via the `x-n8n-url` header in multi-tenant HTTP mode.

### Impact

A caller with access to the MCP session can drive HTTP requests from the n8…

CVE-2026-44694
GitHub-GHSA

HIGH
gmaps-mcp's unauthenticated HTTP transport allows unlimited Google Maps API calls at operator expense
GHSA-52cq-7v8r-62c6
pkg: gmaps-mcp
eco: pip
published: May 8, 2026
## Unauthenticated HTTP Transport Allows Unlimited Google Maps API Calls at Operator Expense

The `gmaps-mcp` codebase was reviewed at commit `e671db68c804c9e67d51582d3280839ffa65f127` and three issues worth flagging were discovered — one high-severity, one medium, one structural. There were no pr…

GitHub-GHSA

HIGH
fast-xml-builder allows attribute values with unwanted quotes to bypass malicious or unwanted attributes
GHSA-5wm8-gmm8-39j9
pkg: fast-xml-builder
eco: npm
published: May 8, 2026
# Summary
When an input data has quotes in attribute values but process entities is not enabled, it breaks the attribute value into multiple attributes. This gives the room for an attacker to insert unwanted attributes to the XML/HTML.

## Detail

Malicious Input
“`
{
a: {
"@_attr": '…

CVE-2026-44665
GitHub-GHSA

HIGH
mcp-ssh-tool has file transfer path policy bypass and bearer token comparison hardening
GHSA-j7h9-2jh7-g967
pkg: mcp-ssh-tool
eco: npm
published: May 7, 2026
## Summary

`mcp-ssh-tool` has released version `2.1.1` with security hardening for transfer path authorization and HTTP bearer authentication.

The release addresses:

– insufficient local path policy enforcement in transfer-related filesystem handling
– incomplete canonicalization and segment-boun…

GitHub-GHSA

HIGH
Note Mark: Arbitrary File Write via Path Traversal in Asset Names Leads to Remote Code Execution
GHSA-g49p-4qxj-88v3
pkg: github.com/enchant97/note-mark/backend
eco: go
published: May 7, 2026
### Description

The Note Mark application allows authenticated users to upload assets to notes via `POST /api/notes/{noteID}/assets`, where the asset filename is provided through the `X-Name` HTTP request header. This value is stored directly in the database without any sanitization or validation -…

CVE-2026-44522
GitHub-GHSA

HIGH
Cinny vulnerable to access token disclosure via invalidated emoji pack avatar URL in service worker
GHSA-j944-w549-3453
pkg: cinny
eco: npm
published: May 7, 2026
### Impact
A remote authenticated attacker who shares a room with a victim and has permissions to create room emotes (for example in a DM) can cause the victim's client to send their Matrix access token to an attacker-controlled server. This occurs when the victim opens the emoji or sticker picker f…
CVE-2026-42553
GitHub-GHSA

HIGH
hickory-proto: NSEC3 closest-encloser proof validation enters unbounded loop on cross-zone responses
GHSA-3v94-mw7p-v465
pkg: hickory-proto, hickory-net
eco: rust
published: May 7, 2026
The NSEC3 closest-encloser proof validation in `hickory-proto`'s (0.25.0-alpha.3 … 0.25.2) and `hickory-net`'s (0.26.0-alpha.1 .. 0.26.0) `DnssecDnsHandle` walks from the QNAME up to the SOA owner name, building a list of candidate encloser names. The iterator used assumes the QNAME is a descenda…
GitHub-GHSA

HIGH
Free5GC UDM has Improper Input Validation and Generation of Error Messages Containing Sensitive Information
GHSA-585v-hcgf-jhfr
pkg: github.com/free5gc/udm
eco: go
published: May 7, 2026
## Summary

The free5GC UDM component fails to validate the `supi` path parameter in six GET handlers of the `nudm-sdm` (Subscriber Data Management) service. An unauthenticated attacker can inject control characters into the SUPI parameter, causing UDM to forward a malformed request to UDR and retur…

CVE-2026-42459
GitHub-GHSA

HIGH
Aegra has cross-user run injection in /threads/{thread_id}/runs (IDOR)
GHSA-m98r-6667-4wq7
pkg: aegra-api
eco: pip
published: May 7, 2026
## Impact

Aegra deployments running 0.9.0 through 0.9.6 with multiple authenticated users on a shared instance are vulnerable to a cross-tenant IDOR. Any authenticated user (User A), given another user's `thread_id` (User B), can:

– Execute graph runs against User B's thread via `POST /threads/{th…

CVE-2026-44504
GitHub-GHSA

HIGH
Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host redirect
GHSA-7j59-v9qr-6fq9
pkg: com.microsoft.kiota:microsoft-kiota-abstractions, Microsoft.Kiota.Abstractions, microsoft-kiota-http
eco: npm
published: May 7, 2026
### Summary
The RedirectHandler middleware in microsoft/kiota-java (com.microsoft.kiota:microsoft-kiota-http-okHttp v1.9.0) and other Kiota libraries fails to strip sensitive HTTP headers when following 3xx redirects to a different host or scheme.

This vulnerability is present in the RedirectHandl…

CVE-2026-44503
GitHub-GHSA

HIGH
ldap3_proto has LDAP Filter stack exhaustion
GHSA-qcxq-75wr-5cm8
pkg: ldap3_proto
eco: rust
published: May 6, 2026
### Impact
LDAP queries are not validated for depth, which can cause the parser (both PEG and ASN) to exhaust the stack. This *may* cause a denial of service in applications that process queries.

### Workarounds
N/A

### Resources
Related to GHSA-r5fr-9gmv-jggh

GitHub-GHSA

HIGH
scim_proton and kanidm_proto have an authenticated process abort via SCIM filter stack exhaustion
GHSA-r5fr-9gmv-jggh
pkg: scim_proto, kanidm_proto
eco: rust
published: May 6, 2026
### Summary

A single unauthenticated `GET` to any `/scim/v1/…` endpoint with a `?filter=` query string of a few thousand nested parentheses (≈ 4–12 KB) drives the recursive-descent PEG parser past the worker thread's stack guard page. Rust responds to stack overflow with `std::process::abort(…

GitHub-GHSA

HIGH
Keras vulnerable to DoS via Malicious .keras Model (HDF5 Shape Bomb Causes Petabyte Allocation in KerasFileEditor)
GHSA-mgx6-5cf9-rr43
pkg: keras, keras
eco: pip
published: May 6, 2026
### Summary
Keras’s model loader (KerasFileEditor) unsafely loads user-supplied .keras model files containing HDF5-based weight files without performing any validation on HDF5 dataset metadata. An attacker can craft a .keras archive containing a valid model.weights.h5 file whose dataset declares a…
CVE-2026-0897
GitHub-GHSA

HIGH
Daptin fuzzy search injects unvalidated column name into raw SQL
GHSA-pwqg-q8pg-pp6r
pkg: github.com/daptin/daptin
eco: go
published: May 6, 2026
## Summary

`processFuzzySearch` in `server/resource/resource_findallpaginated.go:1484` splits the user-supplied `column` parameter by comma and interpolates each segment directly into `goqu.L(fmt.Sprintf("LOWER(%s) LIKE ?", prefix+col))` raw SQL with no column whitelist check. The entry point is `G…

CVE-2026-44349
GitHub-GHSA

HIGH
PraisonAI has an SSRF bypass
GHSA-q9pw-vmhh-384g
pkg: praisonaiagents
eco: pip
published: May 6, 2026
### Summary
The URL checking logic in PraisonAI has a logical flaw that could be bypassed by attackers, leading to SSRF attacks.

### Details
The current PraisonAI project uses _validate_url to validate the input URL. The main logic is to perform security checks on the host portion of the URL extrac…

CVE-2026-44335
GitHub-GHSA

HIGH
Mako vulnerable to path traversal via backslash URI on Windows in TemplateLookup
GHSA-2h4p-vjrc-8xpq
pkg: Mako
eco: pip
published: May 6, 2026
## Summary

On Windows, a URI using backslash traversal (e.g. `\..\..\ secret.txt`) bypasses the directory traversal check in `Template.__init__` and the `posixpath`-based normalization in `TemplateLookup.get_template()`, allowing reads of files outside the configured template directory.

## Detail…

CVE-2026-44307
GitHub-GHSA

HIGH
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
GHSA-mqcg-5×36-vfcg
pkg: jupyterlab, notebook
eco: pip
published: May 6, 2026
JupyterLab's HTML sanitizer allowlists `data-commandlinker-command` and `data-commandlinker-args` on `button` elements, while `CommandLinker` listens for all click events on `document.body` and executes the named command without checking whether the element came from trusted JupyterLab UI. A noteboo…
CVE-2026-42557
GitHub-GHSA

HIGH
Mezo: ERC-20 bridgeOut burn can be erased by a stale StateDB overwrite leading to full L1 bridge drain
GHSA-6447-269v-g68m
pkg: github.com/mezo-org/mezod
eco: go
published: May 6, 2026
**Note: the fixed version of the validator client has been deployed for some time.**

### Impact

Potential full drain of L1 bridge without changing bridged balance on Mezo.

## Brief/Intro

A malicious user can steal all ERC-20 tokens locked in the L1 bridge by repeatedly calling the `bridgeOut` pr…

GitHub-GHSA

HIGH
dssrf: every IPv6 category bypasses is_url_safe
GHSA-8p33-q827-ghj5
pkg: dssrf
eco: npm
published: May 6, 2026
A vulnerability in dssrf allows an attacker to bypass its SSRF protections by supplying one of the following IPv6 addresses, resulting in a successful SSRF. This contradicts dssrf documentation, which incorrectly claims that IPv6 is disabled entirely. See below:

“`rust
Input Category
http://[::1]/…

CVE-2026-44232
GitHub-GHSA

HIGH
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0
GHSA-v5c3-6wvc-pc2q
pkg: github.com/QuantumNous/new-api
eco: go
published: May 6, 2026
# SSRF Filter Bypass via `0.0.0.0`

### Summary

The SSRF protection introduced in v0.9.0.5 (CVE-2025-59146) and hardened in v0.9.6 (CVE-2025-62155) does not block the unspecified address `0.0.0.0`. A regular (non-admin) user holding any valid API token can send a multimodal request to `/v1/chat/co…

CVE-2026-42339
GitHub-GHSA

HIGH
Duplicate Advisory: Mistune has a ReDoS in LINK_TITLE_RE that allows denial of service via crafted Markdown input
GHSA-hjph-f4mc-wx4c
pkg: mistune
eco: pip
published: May 6, 2026
### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-8mp2-v27r-99xp. This link is maintained to preserve external references.

### Original Description

### Summary
**Denial-of-Service (DoS)** vulnerability in the Mistune Markdown parser. The issue occurs when pr…

GitHub-GHSA

HIGH
Mistune has a ReDoS in LINK_TITLE_RE that allows denial of service via crafted Markdown input
GHSA-8mp2-v27r-99xp
pkg: mistune
eco: pip
published: May 6, 2026
### Summary

A ReDoS (Regular Expression Denial of Service) vulnerability in `LINK_TITLE_RE` allows an attacker who can supply Markdown for parsing to cause denial of service. A crafted 58-byte Markdown document blocks the parser for approximately 6 seconds (measured on Apple M2, Python 3.14.3), wit…

CVE-2026-33079
GitHub-GHSA

HIGH
jdbi3-freemarker Vulnerable to Improper Neutralization of Special Elements Used in FreeMarker Template Engine
GHSA-mggx-p7jf-jgw4
pkg: org.jdbi:jdbi3-freemarker
eco: maven
published: May 5, 2026
# Summary

**Description**

An Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) vulnerability in Jdbi allows arbitrary command execution when an application using `jdbi3-freemarker` permits attacker-influenced text to reach `FreemarkerEngine.parse()` as template sourc…

GitHub-GHSA

HIGH
authd: Primary group ID is incorrectly set to value of UID
GHSA-fg3j-5w9g-hmg7
pkg: github.com/canonical/authd
eco: go
published: May 5, 2026
authd 0.6.0 contains [a bug](https://github.com/canonical/authd/issues/1482) which can lead to an incorrect primary group ID.

It affects users whose primary group ID (i.e. the GID in the user record) differs from their UID. There are two ways which can lead to this:

1. The user was created with au…

CVE-2026-6970
GitHub-GHSA

HIGH
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
GHSA-xp3w-r5p5-63rr
pkg: openssl
eco: rust
published: May 5, 2026
`X509Ref::ocsp_responders` returns OCSP responder URLs from a certificate's AIA extension as `OpensslString`, whose `Deref<Target = str>` wraps the raw bytes with `str::from_utf8_unchecked`. OpenSSL does not enforce that the underlying IA5String is ASCII, so a certificate with non-UTF-8 bytes in its…
CVE-2026-42327
GitHub-GHSA

HIGH
RustFS: ListServiceAccount authorizes against wrong admin action, enabling cross-user enumeration and root service account takeover
GHSA-mm2q-qcmx-gw4w
pkg: rustfs
eco: rust
published: May 5, 2026
## Summary

`ListServiceAccount` (`GET /rustfs/admin/v3/list-service-accounts?user=<other>`) authorizes cross-user requests against `UpdateServiceAccountAdminAction` instead of `ListServiceAccountsAdminAction` at `rustfs/src/admin/handlers/service_account.rs:936`. The handler accepts the **wrong** a…

GitHub-GHSA

HIGH
link-preview-js vulnerable to IPv6 and internal loopback attacks
GHSA-4gp8-rjrq-ch6q
pkg: link-preview-js
eco: npm
published: May 5, 2026
### Impact
The library did not check for IPv6 loopback attacks. There was also a DNS attack, where an address could be resolved into an internal IP. This could cause internal data leaks.

### Patches
Problem has been patched in version 4.0.1. However, it cannot be completely solved by the package al…

CVE-2026-43897
GitHub-GHSA

HIGH
gix and gitoxide: unvalidated submodule name traverses out of .git/modules and redirects state() / open() to another repository
GHSA-fr8x-3vfx-f45h
pkg: gitoxide, gix
eco: rust
published: May 5, 2026
## **Summary**
attachments:
[pocs.zip](https://github.com/user-attachments/files/26431422/pocs.zip)

Submodule names coming from `.gitmodules` are exposed as unvalidated names and are later reused to derive the submodule git directory as:

“`
<superproject common_dir>/modules/<submodule name>
“`

GitHub-GHSA

HIGH
gix and gitoxide's symlinked .gitmodules are followed and parsed from outside of the repository
GHSA-pg4w-g64p-qwhj
pkg: gitoxide, gix
eco: rust
published: May 5, 2026
## Summary
attachments:
[pocs.zip](https://github.com/user-attachments/files/26431422/pocs.zip)

When `Repository::submodules()` loads submodule metadata, it prefers the worktree `.gitmodules` file if that path exists. In the current implementation, the path is read with `std::fs::read()`, which fo…

GitHub-GHSA

HIGH
gix-pack has multiple DoS vectors: unchecked indexing panics and uncapped OOM allocations from crafted pack data
GHSA-x494-mj8g-cj27
pkg: gix-pack
eco: rust
published: May 5, 2026
### Summary

Multiple denial-of-service vectors in `gix-pack`: unchecked array indexing causes panics on crafted delta data, and uncapped attacker-controlled size headers enable OOM process kills. Both are triggered by malicious pack data received during clone/fetch.

### Details

**Bug 1: Unchecked…

GitHub-GHSA

HIGH
gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure
GHSA-p3hw-mv63-rf9w
pkg: gix, gix-validate
eco: rust
published: May 5, 2026
### Summary

Submodule name validation bypass plus missing validation in production code paths allows path traversal via crafted `.gitmodules`. Combined with a trust inheritance flaw in `Submodule::open()`, this enables reading arbitrary git repository configs (including credentials) from traversed …

GitHub-GHSA

HIGH
Diesel's SQLite backend has possible UTF-8 corruption
GHSA-h5x4-m2qf-r4f2
pkg: diesel
eco: rust
published: May 5, 2026
Diesel uses the `sqlite3_value_text` function to receive strings from SQLite while deserializing query results. We misinterpreted the corresponding [SQLite](https://sqlite.org/c3ref/value_blob.html) documentation that this function always returns a UTF-8 encoded string values as `*const c_char`. Bas…
GitHub-GHSA

HIGH
Network-AI missing authentication on MCP HTTP endpoint, which allows unauthenticated privileged tool calls
GHSA-fj4g-2p96-q6m3
pkg: network-ai
eco: npm
published: May 5, 2026
# Security Advisory: Missing Authentication for Critical Function in `Jovancoding/Network-AI`

| Field | Value |
|—|—|
| Project | `Jovancoding/Network-AI` |
| Repository | https://github.com/Jovancoding/Network-AI |
| Affected commit | `c344f2053eb0d49395988f803bf92f2a86b2a0d0` |
| Affected tes…

CVE-2026-42856
GitHub-GHSA

HIGH
net-imap vulnerable to STARTTLS stripping via invalid response timing
GHSA-vcgp-9326-pqcp
pkg: net-imap, net-imap, net-imap
eco: rubygems
published: May 4, 2026
### Summary

A man-in-the-middle attacker can cause `Net::IMAP#starttls` to return "successfully", without starting TLS.

### Details

When using `Net::IMAP#starttls` to upgrade a plaintext connection to use TLS, a man-in-the-middle attacker can inject a tagged `OK` response with an easily predictab…

CVE-2026-42246
GitHub-GHSA

MEDIUM
Axios: unbounded recursion in toFormData causes DoS via deeply nested request data
GHSA-62hf-57xw-28j9
pkg: axios, axios
eco: npm
published: May 5, 2026
### Summary
toFormData recursively walks nested objects with no depth limit, so a deeply nested value passed as request data crashes the Node.js process with a RangeError.

### Details
lib/helpers/toFormData.js:210 defines an inner `build(value, path)` that recurses into every object/array child (li…

CVE-2026-42039
GitHub-GHSA

MEDIUM
Volcano's webhook server vulnerable to OOM due to unbounded HTTP request body size
GHSA-8wxp-xxp2-rcgx
pkg: volcano.sh/volcano, volcano.sh/volcano, volcano.sh/volcano
eco: go
published: May 8, 2026
### Impact
The Volcano webhook server does not enforce a size limit on incoming HTTP request bodies. Any in-cluster pod that can reach the webhook endpoint may send an arbitrarily large request body, potentially causing the webhook server to be killed by OOM. All Volcano deployments with the webhook…
CVE-2026-44247
NVD

MEDIUM
CVE-2026-42194
CVE-2026-42194
pkg: curl

published: May 7, 2026

Admidio is an open-source user management solution. Prior to version 5.0.9, the incomplete SSRF fix in Admidio's fetch_metadata.php validates the resolved IP address but passes the original hostname-based URL to curl_init(), leaving a DNS rebinding TOCTOU window that allows redirecting requests to i…
CWE: CWE-918
GitHub-GHSA

MEDIUM
Netty Redis Codec Encoder has a CRLF Injection Issue
GHSA-rgrr-p7gp-5xj7
pkg: io.netty:netty-codec-redis, io.netty:netty-codec-redis
eco: maven
published: May 7, 2026
# Security Vulnerability Report: CRLF Injection in Netty Redis Codec Encoder

## 1. Vulnerability Summary

| Field | Value |
|——-|——-|
| **Product** | Netty |
| **Version** | 4.2.12.Final (and all prior versions with codec-redis) |
| **Component** | `io.netty.handler.codec.redis.RedisEncoder…

CVE-2026-42586
GitHub-GHSA

MEDIUM
Lemur: LDAP Authentication Globally Disables TLS Certificate Verification When LDAP_USE_TLS Is Enabled
GHSA-vr7c-r5gj-j3w5
pkg: lemur
eco: pip
published: May 6, 2026
## Description

### Overview

When LDAP TLS is enabled (`LDAP_USE_TLS = True`), Lemur's LDAP authentication module unconditionally disables TLS certificate verification at the **global** `ldap` module level. This allows a man-in-the-middle attacker positioned between Lemur and the LDAP server to int…

CVE-2026-44305
GitHub-GHSA

MEDIUM
wireshark-mcp vulnerable to arbitrary file write via export_objects when WIRESHARK_MCP_ALLOWED_DIRS is not configured
GHSA-3r68-x3xc-rxpg
pkg: wireshark-mcp
eco: pip
published: May 5, 2026
## Description

### Impact

`wireshark-mcp` exposes a `wireshark_export_objects` MCP tool that accepts an attacker-controlled `dest_dir` parameter and passes it to tshark's `–export-objects` flag with **no mandatory path restriction**.

The path sandbox (`_allowed_dirs`) is `None` by default and on…

CVE-2026-43901
GitHub-GHSA

MEDIUM
gix-transport: HTTP credentials leaked to redirected host in curl backend
GHSA-9857-6mw7-fq2m
pkg: gix-transport
eco: rust
published: May 5, 2026
## Summary

The curl-based HTTP transport in `gix-transport` sends user credentials (passwords, tokens) to an attacker-controlled server after an HTTP redirect. When a server responds with a 302 redirect during the initial `GET /info/refs`, gitoxide records the redirected base URL and rewrites all s…

GitHub-GHSA

MEDIUM
Axios: no_proxy bypass via IP alias allows SSRF
GHSA-m7pr-hjqh-92cm
pkg: axios, axios
eco: npm
published: May 5, 2026
The fix for no_proxy hostname normalization bypass (#10661) is incomplete.When no_proxy=localhost is set, requests to 127.0.0.1 and [::1] still route through the proxy instead of bypassing it.

The shouldBypassProxy() function does pure string matching — it does not
resolve IP aliases or loopback…

CVE-2026-42038
GitHub-GHSA

MEDIUM
view_component: Preview Route Can Dispatch Inherited Helper Methods
GHSA-7f3r-gwc9-2995
pkg: view_component
eco: rubygems
published: May 8, 2026
### Summary

The preview route derives an example name from the URL and calls it with `public_send`. The code does not verify that the requested method is one of the preview examples explicitly defined by the preview class.

As a result, inherited public methods on `ViewComponent::Preview` are route…

CVE-2026-44836
GitHub-GHSA

MEDIUM
free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface type assertion (single authenticated request)
GHSA-jqfc-gwj5-3w63
pkg: github.com/free5gc/udr
eco: go
published: May 8, 2026
### Summary
free5GC's UDR `nudr-dr` `DELETE /subscription-data/{ueId}/{servingPlmnId}/ee-subscriptions/{subsId}/amf-subscriptions` handler panics on a single authenticated request against a fresh UDR instance when the supplied `ueId` does not exist in `UESubsCollection`. The processor checks `value,…
CVE-2026-44324
GitHub-GHSA

MEDIUM
free5GC's BSF concurrent PUT /nbsf-management/v1/subscriptions/{subId} crashes the BSF process via concurrent map read/write on Subscriptions
GHSA-27ph-8q4f-h7m7
pkg: github.com/free5gc/bsf
eco: go
published: May 8, 2026
### Summary
free5GC's BSF `PUT /nbsf-management/v1/subscriptions/{subId}` handler has an unsynchronized write on the global `Subscriptions` map. The handler first reads the map under `RLock()` via `BSFContext.GetSubscription(subId)`, but if the subscription does not exist, `ReplaceIndividualSubcript…
CVE-2026-44318
GitHub-GHSA

MEDIUM
free5GC's PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing AfRoutReq via nil pointer dereference
GHSA-wwqh-7jm5-gj7w
pkg: github.com/free5gc/pcf
eco: go
published: May 8, 2026
### Summary
free5GC's PCF `POST /npcf-policyauthorization/v1/app-sessions` handler panics on a single authenticated request whose `ascReqData.suppFeat == "1"` (enabling traffic-routing feature negotiation) and whose `medComponents` entries supply an `afAppId` but NO `AfRoutReq`. The create path then…
CVE-2026-44317
GitHub-GHSA

MEDIUM
OpenTelemetry.Exporter.Instana bypasses TLS certificate validation when a proxy is configured
GHSA-wfr5-454p-mjc2
pkg: OpenTelemetry.Exporter.Instana
eco: nuget
published: May 8, 2026
### Summary

The `OpenTelemetry.Exporter.Instana` NuGet package does not validate HTTPS/TLS certificates are valid when sending telemetry to a configured Instana back-end when a proxy is configured using the `INSTANA_ENDPOINT_PROXY` environment variable.

If a network attacker can Man-in-the-Middle …

CVE-2026-44213
GitHub-GHSA

MEDIUM
Wagtail has improper permission handling when copying pages
GHSA-67rv-mg8q-5pf3
pkg: wagtail, wagtail
eco: pip
published: May 8, 2026
### Impact

A CMS user with limited access to pages could copy a page they don't have access to to an area of the site they do. Once copied, they'd be able to view its contents, and potentially publish it. Permissions were correctly checked for the copy destination, but not for the source page.

###…

CVE-2026-44200
GitHub-GHSA

MEDIUM
Wagtail has improper permission handling when deleting form submissions
GHSA-pwm3-7fv4-g6xx
pkg: wagtail, wagtail
eco: pip
published: May 8, 2026
### Impact

A CMS user with limited access to form pages could delete submissions to form pages they don't have access to by crafting a form submission to delete submissions on a page they do have access to for submissions they don't.

The vulnerability is not exploitable by an ordinary site visito…

CVE-2026-44199
GitHub-GHSA

MEDIUM
Wagtail has improper permission handling when comparing revisions
GHSA-c6wj-9vcj-75pj
pkg: wagtail, wagtail
eco: pip
published: May 8, 2026
### Impact

A CMS user without the ability to edit a page could access revisions of the page through the revision compare view if they knew the primary key of two revisions. This could potentially result in disclosure of sensitive information.

### Patches

Patched versions have been released as Wag…

CVE-2026-44197
GitHub-GHSA

MEDIUM
Open WebUI has Unauthorized File and Knowledge Base Content Access via RAG Vector Search
GHSA-h36f-rqpx-j5wx
pkg: open-webui
eco: pip
published: May 8, 2026
# Unauthorized File and Knowledge Base Content Access via RAG Vector Search

## Affected Component

RAG source resolution in chat completion pipeline:
– `backend/open_webui/retrieval/utils.py` (lines 963-965, 1063-1068, 1126-1131 in `get_sources_from_items`)

## Affected Versions

Current main branc…

CVE-2026-44560
GitHub-GHSA

MEDIUM
Open WebUI's Model Import Overwrites Any Model Without Ownership Check
GHSA-mqq6-cqcx-38vg
pkg: open-webui
eco: pip
published: May 8, 2026
# Model Import Overwrites Any Model Without Ownership Check

## Affected Component

Model import endpoint:
– `backend/open_webui/routers/models.py` (lines 254-308, `import_models`)

## Affected Versions

Current main branch (commit `6fdd19bf1`) and likely all versions with model import functionality…

CVE-2026-44562
GitHub-GHSA

MEDIUM
Electerm's full process.env exposed to renderer via window.pre.env
GHSA-37j4-88rp-2f6h
pkg: electerm
eco: npm
published: May 8, 2026
### Impact

The `getConstants()` IPC handler in `src/app/lib/ipc-sync.js` serialises the entire `process.env` object and sends it to the renderer. The data is stored as `window.pre.env` and is accessible from any JavaScript running in the renderer (e.g., via the DevTools console or a compromised web…

CVE-2026-43942
NVD

MEDIUM
CVE-2026-41585
CVE-2026-41585
pkg: zfnd zebra-rpc, zfnd zebrad

published: May 8, 2026

ZEBRA is a Zcash node written entirely in Rust. From zebrad versions 2.2.0 to before 4.3.1 and from zebra-rpc versions 1.0.0-beta.45 to before 6.0.2, a vulnerability in Zebra's JSON-RPC HTTP middleware allows an authenticated RPC client to cause a Zebra node to crash by disconnecting before the requ…
CWE: CWE-248, CWE-617
GitHub-GHSA

MEDIUM
Ech0 allows PUT /api/echo/like/:id unauthenticated: anonymous callers to modify any echo's fav_count
GHSA-pj6q-4vq4-r8cg
pkg: github.com/lin-snow/Ech0
eco: go
published: May 7, 2026
## Summary

`PUT /api/echo/like/:id` at `internal/router/echo.go:12` is registered on `PublicRouterGroup` with no authentication and no rate limit. Anonymous callers increment the `fav_count` counter on any echo (including private echoes) by UUID, repeat the request without deduplication, and trigge…

NVD

MEDIUM
CVE-2026-33589
CVE-2026-33589
pkg: lfnovo open-notebook

published: May 7, 2026

Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to access local files content from the docker container via path traversal.
CWE: CWE-20
GitHub-GHSA

MEDIUM
vm2 Host Promise Resolution Preserves Object Identity Across Sandbox Boundary
GHSA-mpf8-4hx2-7cjg
pkg: vm2
eco: npm
published: May 7, 2026
### Summary

A sandbox boundary violation in **vm2** allows host object identity to cross into the sandbox through host Promise resolution.

When a host-side Promise that resolves to a host object is exposed to the sandbox, the value delivered to the sandbox `.then()` callback preserves host identit…

CVE-2026-44000
GitHub-GHSA

MEDIUM
ShellHub has cross-tenant IDOR in `GET /api/namespaces/:tenant` via API Key bypasses membership check
GHSA-vwx9-7qcf-gg7f
pkg: github.com/shellhub-io/shellhub
eco: go
published: May 7, 2026
## Summary
`GET /api/namespaces/:tenant` returns the full namespace object — including the members list (user IDs, e-mails, roles), settings, and device counts — to any caller authenticated by an **API Key**, for any tenant, regardless of the API Key's own tenant scope.

The handler conditionall…

CVE-2026-44426
GitHub-GHSA

MEDIUM
Daptin's Session Management Vulnerability Leads to Insufficient Session Expiration After Password Change
GHSA-258c-965c-p3hc
pkg: github.com/daptin/daptin
eco: go
published: May 7, 2026
### Summary

A session invalidation vulnerability exists in daptin's authentication system where JSON Web Tokens (JWTs) remain fully valid after a user changes their password. The JWT validation middleware (`CheckJWT`) only verifies token signature, expiry, issuer, and signing algorithm — it does …

GitHub-GHSA

MEDIUM
Kubetail has a Cross-Site WebSocket Hijacking issue that allows attacker to read Kubernetes logs from authenticated users
GHSA-v8j7-hp7c-738f
pkg: github.com/kubetail-org/kubetail/modules/dashboard, github.com/kubetail-org/kubetail/modules/cli
eco: go
published: May 7, 2026
### Summary

Kubetail's dashboard exposes WebSocket endpoints that did not adequately validate the Origin header on connection upgrade. A malicious web page visited by a user with an active Kubetail session could open a WebSocket to the user's dashboard and read their Kubernetes logs in real time. T…

CVE-2026-44514
GitHub-GHSA

MEDIUM
Netty vulnerable to HTTP Request Smuggling due to malformed Transfer-Encoding
GHSA-38f8-5428-x5cv
pkg: io.netty:netty-codec-http, io.netty:netty-codec-http
eco: maven
published: May 7, 2026
### Summary
Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks.

### Details
Netty incorrectly marks a request as chunked when malformed "Transfer-Encoding: chunked, identity" is present.
According to RFC https://datatracker.ietf.org/doc/html/rfc9112#name-messag…

CVE-2026-42585
GitHub-GHSA

MEDIUM
Netty vulnerable to HTTP Request Smuggling due to incorrect chunk size parsing
GHSA-m4cv-j2px-7723
pkg: io.netty:netty-codec-http, io.netty:netty-codec-http
eco: maven
published: May 7, 2026
### Summary
Netty's chunk size parser silently overflows int, enabling request smuggling attacks.

### Details
io.netty.handler.codec.http.HttpObjectDecoder#getChunkSize silently overflows int.

The size is accumulated as follows:

result *= 16;
result += digit;

The result is checked only for negat…

CVE-2026-42580
GitHub-GHSA

MEDIUM
Hono: bodyLimit() can be bypassed for chunked / unknown-length requests
GHSA-9vqf-7f2p-gf9v
pkg: hono
eco: npm
published: May 6, 2026
## Summary

`bodyLimit()` does not reliably enforce `maxSize` for requests without a usable `Content-Length` (e.g. `Transfer-Encoding: chunked`). Oversized requests can reach handlers and return `200` instead of `413`.

## Details

For chunked / unknown-length requests, `bodyLimit()` wraps the body …

CVE-2026-44456
GitHub-GHSA

MEDIUM
ShellHub has cross-tenant IDOR in `GET /api/sessions/:uid` that discloses SSH session data
GHSA-9w9c-9w8m-w89q
pkg: github.com/shellhub-io/shellhub
eco: go
published: May 6, 2026
## Summary
`GET /api/sessions/:uid` returns the full session object for any authenticated caller, without scoping by the caller's tenant. An authenticated user can read session records (SSH username, device UID, remote IP, terminal type, authenticated flag, timestamps) belonging to any other namespa…
CVE-2026-44423
GitHub-GHSA

MEDIUM
ShellHub has cross-tenant IDOR in `GET /api/devices/:uid` that discloses device data of any namespace
GHSA-j72x-xfwg-783f
pkg: github.com/shellhub-io/shellhub
eco: go
published: May 6, 2026
## Summary
`GET /api/devices/:uid` returns the full device object whenever the caller is authenticated, without verifying that the device belongs to the caller's namespace (tenant). Any authenticated user (JWT or API Key) who knows or can guess a device UID can read device metadata from any other na…
CVE-2026-44424
GitHub-GHSA

MEDIUM
vLLM: extract_hidden_states speculative decoding crashes server on any request with penalty parameters
GHSA-83vm-p52w-f9pw
pkg: vllm
eco: pip
published: May 6, 2026
### Summary

The `extract_hidden_states` speculative decoding proposer in vLLM returns a tensor with an incorrect shape after the first decode step, causing a `RuntimeError` that crashes the EngineCore process. The crash is triggered when any request in the batch uses sampling penalty parameters (`r…

CVE-2026-44223
NVD

MEDIUM
CVE-2026-40197
CVE-2026-40197
pkg: linuxcontainers incus

published: May 6, 2026

Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage volume import logic allows an authenticated user with access to the storage volume feature to cause the Incus daemon to crash. The custom volume backup import subsystem contains…
CWE: CWE-476
GitHub-GHSA

MEDIUM
Nginx-UI Settings API Exposes Protected Secrets
GHSA-q4w7-56hr-83rm
pkg: github.com/0xJacky/nginx-ui
eco: go
published: May 6, 2026
### Summary
The `GetSettings` API handler (`api/settings/settings.go:24-65`) serializes all settings structs to JSON and returns them to authenticated users. Many sensitive fields are tagged with `protected:"true"` – however, this tag is only enforced during writes (via `ProtectedFill` in `SaveSetti…
CVE-2026-42223
GitHub-GHSA

MEDIUM
vLLM Vulnerable to Remote DoS via Special-Token Placeholders
GHSA-hpv8-x276-m59f
pkg: vllm
eco: pip
published: May 5, 2026
## Summary
This report explains a Token Injection vulnerability in vLLM’s multimodal processing. Unauthenticated, text-only prompts that spell special tokens are interpreted as control. Image and video placeholder sequences supplied without matching data cause vLLM to index into empty grids during…
CVE-2026-44222
GitHub-GHSA

MEDIUM
PyLoad Vulnerable to Path Traversal via Package Folder Name
GHSA-97r3-5w84-r4q8
pkg: pyload-ng
eco: pip
published: May 5, 2026
Insufficient sanitization of package folder names allows writing files outside the intended download directory.

## Affected Component
– `src/pyload/core/api/__init__.py`
– Function: `add_package()`

## Description
Package folder names are sanitized using insufficient string replacement:

“`python

CVE-2026-42314
GitHub-GHSA

MEDIUM
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback
GHSA-7jrr-xw9c-mj39
pkg: github.com/0xJacky/Nginx-UI
eco: go
published: May 5, 2026
## Summary
An authenticated user can call `GET /api/settings` and retrieve sensitive configuration values, including `node.secret`. The same `node.secret` is accepted by `AuthRequired()` through the `X-Node-Secret` header (or `node_secret` query parameter), causing the request to be treated as authe…
CVE-2026-42220
NVD

MEDIUM
CVE-2026-32603
CVE-2026-32603
pkg: sandboxie-plus sandboxie

published: May 5, 2026

Sandboxie is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, a local denial of service vulnerability exists in the Sandboxie kernel driver. An unprivileged process running inside a Standard Sandbox can send a malformed IOCTL to the \Device\SandboxieDriver…
CWE: CWE-20
GitHub-GHSA

MEDIUM
requests-hardened is Vulnerable to Server-Side Request Forgery
GHSA-vh75-fwv3-pqrh
pkg: requests-hardened
eco: pip
published: May 5, 2026
The SSRF protection in `requests-hardened` prior to version 1.2.1 fails to block IP addresses within the RFC 6598 Shared Address Space (`100.64.0.0/10`). An attacker who can supply arbitrary URLs to `requests-hardened` could exploit this gap to access internal services hosted within `100.64.0.0/10`.…
CVE-2026-42175
NVD

MEDIUM
CVE-2026-30246
CVE-2026-30246
pkg: go

published: May 5, 2026

Fiber is a web framework for Go. In github.com/gofiber/fiber/v3 versions through 3.1.0, the default key generator in the cache middleware uses only the request path and does not include the query string. As a result, requests for the same path with different query parameters can share a cache key an…
CWE: CWE-436
GitHub-GHSA

MEDIUM
OpenClaw contains a symlink traversal vulnerability
GHSA-35mw-5vvr-vrxc
pkg: openclaw
eco: npm
published: May 5, 2026
OpenClaw versions 2026.3.22 before 2026.4.5 contain a symlink traversal vulnerability in remote marketplace repository path handling that allows attackers to escape the expected repository root. Attackers can exploit this by providing crafted symlink paths to access files outside the intended reposi…
CVE-2026-43570
GitHub-GHSA

MEDIUM
Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`
GHSA-3w6x-2g7m-8v23
pkg: axios
eco: npm
published: May 5, 2026
# Vulnerability Disclosure: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`

## Summary

The Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any `Object.prototype` pollution in the application's dependency tree to be escalated into …

CVE-2026-42044
NVD

MEDIUM
CVE-2026-42223
CVE-2026-42223
pkg: nginxui nginx_ui

published: May 4, 2026

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, the GetSettings API handler (api/settings/settings.go:24-65) serializes all settings structs to JSON and returns them to authenticated users. Many sensitive fields are tagged with protected:"true" – however, this tag …
CWE: CWE-200
NVD

MEDIUM
CVE-2026-42220
CVE-2026-42220
pkg: nginxui nginx_ui

published: May 4, 2026

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, an authenticated user can call GET /api/settings and retrieve sensitive configuration values, including node.secret. The same node.secret is accepted by AuthRequired() through the X-Node-Secret header (or node_secret …
CWE: CWE-200, CWE-863
NVD

MEDIUM
CVE-2026-42228
CVE-2026-42228
pkg: n8n n8n

published: May 4, 2026

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the /chat WebSocket endpoint used by the Chat Trigger node's Hosted Chat feature did not verify that an incoming connection was authorized to interact with the target execution. An unauthenticated rem…
CWE: CWE-862
NVD

MEDIUM
CVE-2026-42092
CVE-2026-42092
pkg: go

published: May 4, 2026

titra is an open source time tracking project. In version 0.99.52, the globalsettings Meteor publication returns all global settings without any admin or role check. Any authenticated user can subscribe via DDP and receive sensitive configuration fields such as google_secret, openai_apikey, and goog…
CWE: CWE-200
NVD

MEDIUM
CVE-2026-42091
CVE-2026-42091
pkg: go

published: May 4, 2026

goshs is a SimpleHTTPServer written in Go. Prior to version 2.0.2, the PUT upload handler (httpserver/updown.go) lacks the CSRF token validation that was added to the POST upload handler during the CVE-2026-40883 fix. Combined with the unconditional Access-Control-Allow-Origin: * on the OPTIONS pref…
CWE: CWE-352
GitHub-GHSA

MEDIUM
kube-router: GoBGP gRPC Admin Port Exposed on Node Primary IP Without Authentication, Allowing Cluster-Wide BGP Route Injection
GHSA-v5mh-h5hx-7v92
pkg: github.com/cloudnativelabs/kube-router
eco: go
published: May 6, 2026
## Summary

When the kube-router routing controller starts (`–run-router`), it binds the GoBGP gRPC management server to the node's primary IP (e.g., `192.168.1.10:50051`) in addition to `127.0.0.1:50051`. The default admin port is `50051` and the server is enabled by default with no TLS and no aut…

GitHub-GHSA

MEDIUM
go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth
GHSA-w239-58×2-q8p5
pkg: github.com/ipld/go-ipld-prime
eco: go
published: May 7, 2026
The DAG-CBOR and DAG-JSON decoders recurse on each nested map or list without a depth limit. A payload containing deeply nested collections causes the decoder to recurse once per level, growing the goroutine stack until the Go runtime terminates the process with a fatal stack overflow (distinct from…
CVE-2026-42328
GitHub-GHSA

MEDIUM
@evomap/evolver has an unbounded request body in proxy /asset/submit that causes persistent disk-exhaustion DoS
GHSA-7xp7-m392-h92c
pkg: @evomap/evolver
eco: npm
published: May 5, 2026
## Summary

The EvoMap proxy daemon's HTTP body parser accepts requests of any size, and the `POST /asset/submit` route persists the full request body — verbatim and uncapped — as a JSONL line in `<dataDir>/messages.jsonl`. An unauthenticated local attacker (other local user, container neighbor,…

GitHub-GHSA

MEDIUM
LobeHub has a Cross-Site Scripting issue that escalates to Remote Code Execution
GHSA-xq4x-622m-q8fq
pkg: @lobehub/lobehub
eco: npm
published: May 5, 2026
### Summary
The vulnerability was automatically discovered by an ai agent and then manually verified.

LobeChat's message rendering mechanism has a stored cross-site scripting (XSS) vulnerability. Combined with the Electron main process's exposed insecure IPC interface, attackers can construct malic…

CVE-2026-42045
GitHub-GHSA

MEDIUM
Mistune Heading ID Attribute has Injection XSS
GHSA-v87v-83h2-53w7
pkg: mistune
eco: pip
published: May 9, 2026
## Summary
`HTMLRenderer.heading()` builds the opening `<hN>` tag by string-concatenating the `id` attribute value directly into the HTML — with no call to `escape()`, `safe_entity()`, or any other sanitisation function. A double-quote character `"` in the `id` value terminates the attribute, allo…
CVE-2026-44897
GitHub-GHSA

MEDIUM
Mistune Math Plugin has an XSS Escape Bypass
GHSA-8g87-j6q8-g93x
pkg: mistune
eco: pip
published: May 8, 2026
## Summary
The mistune math plugin renders inline math (`$…$`) and block math (`$$…$$`) by concatenating the raw user-supplied content directly into the HTML output **without any HTML escaping**. This occurs even when the parser is explicitly created with `escape=True`, which is supposed to guar…
CVE-2026-44708
GitHub-GHSA

MEDIUM
fast-xml-builder Comment Value regex can be bypassed
GHSA-45c6-75p6-83cc
pkg: fast-xml-builder
eco: npm
published: May 8, 2026
# Summary
The fix for https://github.com/advisories/GHSA-gh4j-gqv2-49f6 in fast-xml-parser sanitizes `–` sequences in XML comment content using .replace(/–/g, '- -'). This skip the values containing three consecutive dashes (e.g., —>…), allowing an attacker to break out of an XML comment and i…
CVE-2026-44664
GitHub-GHSA

MEDIUM
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
GHSA-jp94-3292-c3xv
pkg: devise
eco: rubygems
published: May 8, 2026
## Summary

When the `Timeoutable` module is enabled in Devise, the `FailureApp#redirect_url` method returns `request.referrer` — the HTTP `Referer` header, which is attacker-controllable — without validation for any non-GET request that results in a session timeout. An attacker who hosts a page…

CVE-2026-40295
GitHub-GHSA

MEDIUM
Free5GC AMF Bypasses UE Security Capabilities on NGAP PathSwitchRequest
GHSA-77×9-rf64-92gv
pkg: github.com/free5gc/amf
eco: go
published: May 7, 2026
### Summary
The AMF in Free5GC v4.2.1 does not verify the UE Security Capabilities received in NGAP PathSwitchRequest messages against its locally stored values, as mandated by 3GPP TS 33.501 §6.7.3.1. A malicious gNB can overwrite the AMF's stored UE security capabilities with arbitrary values, wh…
CVE-2026-42081
GitHub-GHSA

MEDIUM
Kanidm: Stored HTML injection in "passkey-enrolment" partial via displayname → htmx-driven authenticated request forgery
GHSA-gpxg-fx2g-qxj2
pkg: kanidm
eco: rust
published: May 6, 2026
### Summary

The kanidmd web UI renders the WebAuthn passkey-registration challenge as raw JSON inside an inline `<script id="data">` element using the Askama `|safe` filter. The challenge embeds the account's `displayname`, which `serde_json` serialises without escaping `<`/`>`. A `displayname` con…

GitHub-GHSA

MEDIUM
Kyverno policy-reporter-ui has XSS via Stored Property Values in PropertyCard Component
GHSA-q98m-7w8c-w388
pkg: github.com/kyverno/policy-reporter-ui
eco: go
published: May 6, 2026
### Summary
Vue 3's v-html directive is the framework-documented mechanism for injecting raw HTML, and it intentionally disables the auto-escaping that {{ }} interpolation provides. The PropertyCard.vue component uses v-html for the else branch of the URL check, meaning any non-URL string value flow…
CVE-2026-44245
NVD

MEDIUM
CVE-2026-42230
CVE-2026-42230
pkg: n8n n8n

published: May 4, 2026

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the /mcp-oauth/register endpoint accepted OAuth client registrations without authentication, allowing arbitrary redirect_uri values to be registered. When a user denies the MCP OAuth consent dialog, t…
CWE: CWE-601
GitHub-GHSA

MEDIUM
OpenClaw's Webhooks SecretRef route secret remains valid after rotation/reload
GHSA-q8ff-7ffm-m3r9
pkg: openclaw
eco: npm
published: May 5, 2026
## Summary

OpenClaw webhooks allowed route secrets to be backed by `SecretRef` values, but cached the resolved secret for a route. After an operator rotated the underlying secret and ran `openclaw secrets reload`, the previous resolved webhook secret could remain valid until the plugin or gateway r…

GitHub-GHSA

MEDIUM
SharpCompress has directory traversal via directory entries in WriteToDirectory (zip slip variant)
GHSA-6c8g-7p36-r338
pkg: SharpCompress
eco: nuget
published: May 8, 2026
### Summary

A path traversal vulnerability in `IArchive.WriteToDirectory()` allows a malicious archive to create directories outside the intended extraction root. For TAR archives, this can be escalated to arbitrary file writes by chaining with a symlink entry, giving a full write primitive on the …

CVE-2026-44788
GitHub-GHSA

MEDIUM
view_component: System Test Entry Point Path Check Allows Sibling Directory Escape
GHSA-hg3h-g7xc-f7vp
pkg: view_component
eco: rubygems
published: May 8, 2026
### Summary

The system test entrypoint canonicalizes a user-controlled file path with `File.realpath`, then checks whether the resolved path starts with the temp directory path. This is not a safe containment check because sibling directories can share the same string prefix.

Severity: Medium; tes…

CVE-2026-44837
GitHub-GHSA

MEDIUM
Gotenberg allows Chromium URL conversion routes to read arbitrary files under /tmp via file:// scheme
GHSA-g924-cjx7-2rjw
pkg: github.com/gotenberg/gotenberg/v8
eco: go
published: May 7, 2026
## Summary

The `/forms/chromium/convert/url` and `/forms/chromium/screenshot/url` routes accept `url=file:///tmp/…` from anonymous callers. The default Chromium deny-list intentionally exempts `file:///tmp/` so HTML/Markdown routes can load their own request-local assets, and those routes apply a…

CVE-2026-42597
GitHub-GHSA

MEDIUM
axonflow-sdk-java: Webhook signing-key (HMAC-SHA256) not exposed by SDK type, preventing signature verification
GHSA-248h-974q-xrc2
pkg: com.getaxonflow:axonflow-sdk
eco: maven
published: May 6, 2026
## Summary

The AxonFlow SDK's `WebhookSubscription` (or equivalent) type did not expose the HMAC-SHA256 signing key returned by the platform's `CreateWebhook` endpoint. Without access to the secret through the typed SDK API, callers had no path to verify the `X-AxonFlow-Signature` header on incomin…

GitHub-GHSA

MEDIUM
axonflow-sdk-typescript: Webhook signing-key (HMAC-SHA256) not exposed by SDK type, preventing signature verification
GHSA-mph8-9v29-pm42
pkg: @axonflow/sdk
eco: npm
published: May 6, 2026
## Summary

The AxonFlow SDK's `WebhookSubscription` (or equivalent) type did not expose the HMAC-SHA256 signing key returned by the platform's `CreateWebhook` endpoint. Without access to the secret through the typed SDK API, callers had no path to verify the `X-AxonFlow-Signature` header on incomin…

GitHub-GHSA

MEDIUM
axonflow-sdk-go: Webhook signing-key (HMAC-SHA256) not exposed by SDK type, preventing signature verification
GHSA-mhc4-qq83-fmrr
pkg: github.com/getaxonflow/axonflow-sdk-go/v5
eco: go
published: May 6, 2026
## Summary

The AxonFlow SDK's `WebhookSubscription` (or equivalent) type did not expose the HMAC-SHA256 signing key returned by the platform's `CreateWebhook` endpoint. Without access to the secret through the typed SDK API, callers had no path to verify the `X-AxonFlow-Signature` header on incomin…

GitHub-GHSA

MEDIUM
axonflow-sdk-python: Webhook signing-key (HMAC-SHA256) not exposed by SDK type, preventing signature verification
GHSA-7f4h-6264-89fr
pkg: axonflow
eco: pip
published: May 6, 2026
## Summary

The AxonFlow SDK's `WebhookSubscription` (or equivalent) type did not expose the HMAC-SHA256 signing key returned by the platform's `CreateWebhook` endpoint. Without access to the secret through the typed SDK API, callers had no path to verify the `X-AxonFlow-Signature` header on incomin…

GitHub-GHSA

MEDIUM
Granian vulnerable to DoS via WSGI response header panic
GHSA-f5p7-9fr5-8jmj
pkg: granian
eco: pip
published: May 6, 2026
### Summary

Granian aborts a worker process if a WSGI application returns an invalid HTTP response header name or value. The WSGI response conversion path uses `.unwrap()` on both the header name and header value constructors, so malformed output from the application becomes a process abort instead…

CVE-2026-42545
GitHub-GHSA

MEDIUM
OpAMP client reads unbounded HTTP response bodies
GHSA-w2jh-77fq-7gp8
pkg: OpenTelemetry.OpAmp.Client
eco: nuget
published: May 5, 2026
### Summary

When receiving responses from the OpAMP server over HTTP, the OpAMP client allocates an unbounded buffer to read all bytes from the server, with no upper-bound on the number of bytes consumed.

This could cause memory exhaustion in the consuming application if the configured OpAMP serve…

CVE-2026-42348
GitHub-GHSA

MEDIUM
eventsource-encoder vulnerable to SSE event injection via unsanitized `event` and `id` fields
GHSA-m9g3-3g99-mhpx
pkg: eventsource-encoder
eco: npm
published: May 8, 2026
### Summary

`eventsource-encoder` does not sanitize the `event` or `id` fields of an `EventSourceMessage` before serializing them. An attacker who controls either field can inject arbitrary Server-Sent Events line terminators (`\n`, `\r`, or `\r\n`) and thereby forge additional SSE fields or entire…

CVE-2026-44214
GitHub-GHSA

MEDIUM
vm2 is Vulnerable to Host File Path Disclosure via Stack Trace Information Leak
GHSA-v27g-jcqj-v8rw
pkg: vm2
eco: npm
published: May 7, 2026
### Summary
vm2's `CallSite` wrapper class (intended as a safe wrapper for V8's native CallSite) blocks `getThis()` and `getFunction()` to prevent host object leakage, but allows `getFileName()` to return unsanitized host absolute paths. Any sandboxed code can extract the full directory structure, l…
CVE-2026-44002
GitHub-GHSA

MEDIUM
CSS Parser: Improper Certificate Validation allows MITM injection of remote CSS content
GHSA-ff6c-w6qf-7xqc
pkg: css_parser, css_parser
eco: rubygems
published: May 7, 2026
### Summary

The CSS Parser gem does not validate HTTPS connections, allowing a Man-in-the-Middle (MITM) attacker to inject or modify CSS content when stylesheets are loaded via HTTPS. The connection is established with `OpenSSL::SSL::VERIFY_NONE`, meaning any HTTPS certificate—even entirely untru…

CVE-2026-44312
GitHub-GHSA

MEDIUM
Netty HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitization
GHSA-xxqh-mfjm-7mv9
pkg: io.netty:netty-codec-http, io.netty:netty-codec-http
eco: maven
published: May 7, 2026
# NETTY HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitization

| Field | Value |
|———–|——-|
| Library | `io.netty:netty-codec-http` |
| Component | `codec-http` — `HttpObjectDecoder` |
| Severity | **HIGH** |
| Affects | HEAD, commit `4f3533ae` confirmed |

## Summary…

CVE-2026-42581
GitHub-GHSA

MEDIUM
docling-graph has SSRF via Missing Internal IP Validation in URLInputHandler
GHSA-fqph-j6v6-jvgx
pkg: docling-graph
eco: pip
published: May 7, 2026
### Impact

The `URLInputHandler` class in `docling_graph/core/input/handlers.py` makes HTTP requests to user-supplied URLs without validating whether the target resolves to a private, loopback, or link-local IP address. The `URLValidator` only checks for a valid scheme and non-empty `netloc`, perfo…

CVE-2026-44520
GitHub-GHSA

MEDIUM
BentoML has Information Disclosure in `bentoml build` via symlink traversal in the build context
GHSA-mcfx-4vc6-qgxv
pkg: bentoml
eco: pip
published: May 7, 2026
### Summary
BentoML's `bentoml build` packaging workflow follows attacker-controlled symlinks inside the build context and copies the referenced file contents into the generated Bento artifact.

If a victim builds an untrusted repository or other attacker-supplied build context, the attacker can pla…

CVE-2026-40610
NVD

MEDIUM
CVE-2026-40004
CVE-2026-40004
pkg: openssl

published: May 7, 2026

There exists an openssl.cnf privilege escalation vulnerability in ZTE Cloud PC client uSmartview. An attacker can execute arbitrary code locally and escalate privileges.
CWE: CWE-427
GitHub-GHSA

MEDIUM
Vercel: Non-interactive mode includes CLI arguments in suggested command output
GHSA-pgf8-2hgj-grqg
pkg: vercel
eco: npm
published: May 7, 2026
# Summary

When the Vercel CLI runs in non-interactive mode (`–non-interactive` or auto-detected AI agent), commands that cannot complete autonomously emit JSON payloads with suggested follow-up commands. If the user authenticated via `–token` or `-t` on the command line, the token value is includ…

CVE-2026-44479
GitHub-GHSA

MEDIUM
@axonflow/openclaw fix introduces plugin cache and credential-file permission hardening
GHSA-cqmh-pcgr-q42f
pkg: @axonflow/openclaw
eco: npm
published: May 6, 2026
## Summary

Two related permission defects in this AxonFlow plugin allowed registration credentials and cache state to be readable by other local users on hosts where the calling user's home directory was at the conventional `0755` mode.

## Affected versions

Versions 1.3.2 and below.

## Impact

1…

NVD

MEDIUM
CVE-2026-43277
CVE-2026-43277
pkg: linux linux_kernel

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

APEI/GHES: ensure that won't go past CPER allocated record

The logic at ghes_new() prevents allocating too large records, by
checking if they're bigger than GHES_ESTATUS_MAX_SIZE (currently, 64KB).
Yet, the allocation is done with…

NVD

MEDIUM
CVE-2026-43271
CVE-2026-43271
pkg: linux linux_kernel

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

md-cluster: fix NULL pointer dereference in process_metadata_update

The function process_metadata_update() blindly dereferences the 'thread'
pointer (acquired via rcu_dereference_protected) within the wait_event()
macro.

While th…

CWE: CWE-476
NVD

MEDIUM
CVE-2026-43266
CVE-2026-43266
pkg: linux linux_kernel

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

EFI/CPER: don't go past the ARM processor CPER record buffer

There's a logic inside GHES/CPER to detect if the section_length
is too small, but it doesn't detect if it is too big.

Currently, if the firmware receives an ARM proces…

NVD

MEDIUM
CVE-2026-43265
CVE-2026-43265
pkg: linux linux_kernel

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

KVM: x86: Ignore -EBUSY when checking nested events from vcpu_block()

Ignore -EBUSY when checking nested events after exiting a blocking state
while L2 is active, as exiting to userspace will generate a spurious
userspace exit, us…

NVD

MEDIUM
CVE-2026-43264
CVE-2026-43264
pkg: linux linux_kernel

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

fbdev: of: display_timing: fix refcount leak in of_get_display_timings()

of_parse_phandle() returns a device_node with refcount incremented,
which is stored in 'entry' and then copied to 'native_mode'. When the
error paths at line…

NVD

MEDIUM
CVE-2026-42192
CVE-2026-42192
pkg: react

published: May 8, 2026

Plunk is an open-source email platform built on top of AWS SES. Prior to version 0.9.0, a stored cross-site scripting (XSS) vulnerability exists in the campaign management feature, where the email body content created by authenticated project members is stored and later rendered in the admin dashboa…
CWE: CWE-79
GitHub-GHSA

MEDIUM
Open WebUI: Deactivated Channel Members Retain Full Access to Group/DM Channels
GHSA-hmgr-67hw-j2cq
pkg: open-webui
eco: pip
published: May 8, 2026
# Deactivated Channel Members Retain Full Access to Group/DM Channels

## Affected Component

Channel membership authorization check:
– `backend/open_webui/models/channels.py` (lines 663-673, `is_user_channel_member`)
– Used at 15 locations in `backend/open_webui/routers/channels.py`

## Affected Ve…

CVE-2026-44561
GitHub-GHSA

MEDIUM
Read-Only Open WebUI Users Can Modify Collaborative Documents via Socket.IO
GHSA-vrfh-rj4q-rmhr
pkg: open-webui
eco: pip
published: May 8, 2026
# Read-Only Users Can Modify Collaborative Documents via Socket.IO

## Affected Component

Socket.IO collaborative document editing handler:
– `backend/open_webui/socket/main.py` (lines 667-721, `ydoc:document:update` handler)

## Affected Versions

Current main branch and likely all versions with c…

CVE-2026-44564
GitHub-GHSA

MEDIUM
Open WebUI's Ollama Model Access Control Bypass via /api/generate, /api/embed, /api/embeddings, and /api/show
GHSA-rcvp-6fgw-c7fh
pkg: open-webui
eco: pip
published: May 8, 2026
# Ollama Model Access Control Bypass via /api/generate, /api/embed, /api/embeddings, and /api/show

## Affected Component

Ollama proxy endpoints missing model access control:
– `backend/open_webui/routers/ollama.py` (lines 955-995, `generate_completion`)
– `backend/open_webui/routers/ollama.py` (li…

CVE-2026-44563
GitHub-GHSA

MEDIUM
Open WebUI's Channel Access Grants Bypass filter_allowed_access_grants
GHSA-7rjh-px4v-5w55
pkg: open-webui
eco: pip
published: May 8, 2026
# Channel Access Grants Bypass filter_allowed_access_grants

## Affected Component

Channel creation and update endpoints:
– `backend/open_webui/routers/channels.py` (lines 291-340, `create_new_channel`)
– `backend/open_webui/routers/channels.py` (lines 617-638, `update_channel_by_id`)
– `backend/op…

CVE-2026-44558
GitHub-GHSA

MEDIUM
gitsign –verify panics on empty-certificate PKCS7 and exits 0, bypassing exit-code callers
GHSA-7c37-gx6w-8vc5
pkg: github.com/sigstore/gitsign
eco: go
published: May 8, 2026
## Summary

`CertVerifier.Verify()` in `pkg/git/verifier.go` unconditionally dereferences `certs[0]` after `sd.GetCertificates()` without checking the slice length. A CMS/PKCS7 signed message with an empty certificate set is a structurally valid DER payload; `GetCertificates()` returns an empty slic…

CVE-2026-44310
GitHub-GHSA

MEDIUM
FileBrowser Vulnerable to Stored XSS via SVG File in Public Share (Missing CSP Header)
GHSA-mmpx-jh39-wrv6
pkg: github.com/gtsteffaniak/filebrowser
eco: go
published: May 7, 2026
## Summary

FileBrowser Quantum serves inline SVG files without a `Content-Security-Policy` header, allowing embedded JavaScript in SVG files to execute when accessed via public share links.

Verified on v1.3.0-stable.

## Affected product

– **Product:** FileBrowser Quantum (`gtsteffaniak/filebrows…

GitHub-GHSA

MEDIUM
ShellHub has crash-DoS via field injection in filter and sort-by parameters
GHSA-47r2-v3x6-wff9
pkg: github.com/shellhub-io/shellhub
eco: go
published: May 6, 2026
## Summary
The device list endpoint accepts user-controlled identifiers in two places that are passed directly as BSON/SQL keys in the database layer without validation:

1. The `name` field of each filter property in the base64-encoded `filter`
query parameter.
2. The `sort_by` query param…

CVE-2026-44425
GitHub-GHSA

MEDIUM
wger: trainer_login open redirect – ?next= parameter not validated against host
GHSA-vqv8-j3mj-wjxj
pkg: wger
eco: pip
published: May 6, 2026
### Summary

The `trainer_login` view in wger redirects to `request.GET['next']` directly via `HttpResponseRedirect()` without calling `url_has_allowed_host_and_scheme()`. After the trainer successfully enters impersonation mode, their browser is redirected to any attacker-controlled URL supplied in…

GitHub-GHSA

MEDIUM
Axios: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `withXSRFToken` Boolean Coercion
GHSA-xx6v-rp6x-q39c
pkg: axios, axios
eco: npm
published: May 5, 2026
# Vulnerability Disclosure: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `withXSRFToken` Boolean Coercion

## Summary

The Axios library's XSRF token protection logic uses JavaScript truthy/falsy semantics instead of strict boolean comparison for the `withXSRFToken` config prope…

CVE-2026-42042
NVD

MEDIUM
CVE-2026-1677
CVE-2026-1677
pkg: tls

published: May 11, 2026

Zephyr sockets created with `IPPROTO_TLS_1_3` can still negotiate a TLS 1.2 connection when both TLS versions are enabled in Kconfig, because the socket-level protocol selection is not propagated to mbedTLS (e.g. via `mbedtls_ssl_conf_min_tls_version`). The ClientHello advertises both versions and t…
CWE: CWE-757
GitHub-GHSA

MEDIUM
Vert.x has a DoS via unbounded server-side SNI SslContext cache growth
GHSA-3g76-f9xq-8vp6
pkg: io.vertx:vertx-core, io.vertx:vertx-core, io.vertx:vertx-core
eco: maven
published: May 9, 2026
Potential unbounded server-side SNI `SslContext` cache growth in Vert.x TLS handling, with possible resource-exhaustion / DoS impact.

On affected versions, matching server-side SNI names are cached via `computeIfAbsent(serverName, …)` in a serverName-keyed `SslContext` cache, and I could not find…

CVE-2026-6860
GitHub-GHSA

MEDIUM
Hono's Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakage
GHSA-p77w-8qqv-26rm
pkg: hono
eco: npm
published: May 9, 2026
### Summary

Cache Middleware does not skip caching for responses that declare per-user variance via `Vary: Authorization` or `Vary: Cookie`. As a result, a response cached for one authenticated user may be served to subsequent requests from different users.

### Details

The Cache Middleware skips …

CVE-2026-44457
GitHub-GHSA

MEDIUM
gitsign verify accepts signatures over go-git-normalized bytes, enabling trust confusion on malformed commits
GHSA-7rmh-48mx-2vwc
pkg: github.com/sigstore/gitsign
eco: go
published: May 8, 2026
## Summary

`gitsign verify` and `gitsign verify-tag` re-encode commit/tag objects through go-git's `EncodeWithoutSignature` before checking the signature, instead of verifying against the raw git object bytes. For malformed objects with duplicate `tree` headers, git-core and go-git parse different …

CVE-2026-44309
GitHub-GHSA

MEDIUM
Wagtail has improper restriction handling on Documents and Images API
GHSA-p5gm-92h4-6pv6
pkg: wagtail, wagtail
eco: pip
published: May 8, 2026
### Impact

The Documents and Images [API](https://docs.wagtail.org/en/stable/advanced_topics/api/index.html) incorrectly listed items in private collections. A user with access to the API could see the filename and name of documents and images in private collections.

### Patches

Patched versions …

CVE-2026-44201
NVD

MEDIUM
CVE-2026-42190
CVE-2026-42190
pkg: react

published: May 8, 2026

RedwoodSDK is a server-first React framework. From version 1.0.0-beta.50 to before version 1.2.3, server actions in rwsdk apply HTTP method enforcement but no origin validation. A request originating from a different origin that the browser treats as same-site can invoke a server action with the vic…
CWE: CWE-352
GitHub-GHSA

MEDIUM
vm2 has access to `VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL`
GHSA-2cm2-m3w5-gp2f
pkg: vm2
eco: npm
published: May 8, 2026
### Summary

https://github.com/patriksimek/vm2/security/advisories/GHSA-wp5r-2gw5-m7q7 is not fully patched.

### Details

It is still possible to get access to `VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL`.

### PoC

“`js
const {VM} = require("vm2");
const vm = new VM();
console.log(vm.run…

NVD

MEDIUM
CVE-2026-44500
CVE-2026-44500
pkg: zfnd zebra-chain, zfnd zebra-network, zfnd zebrad

published: May 8, 2026

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.4.0, prior to zebra-chain version 7.0.0, and prior to zebra-network version 6.0.0, several inbound deserialization paths in Zebra allocated buffers sized against generic transport or block-size ceilings before the tighter prot…
CWE: CWE-770
NVD

MEDIUM
CVE-2022-26523
CVE-2022-26523
pkg: windows

published: May 8, 2026

The socket connection handler in aswArPot.sys in the Avast and AVG Windows Anti Rootkit driver before 22.1 allows local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) due to a double fetch vulnerability at aswArPot+0xbb94.
CWE: CWE-400
NVD

MEDIUM
CVE-2026-41645
CVE-2026-41645
pkg: projectdiscovery nuclei

published: May 8, 2026

Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From version 3.0.0 to before version 3.8.0, a vulnerability in Nuclei's expression evaluation engine makes it possible for a malicious target server to inject and execute supported DSL expressions. This happens when HTTP response da…
CWE: CWE-94
GitHub-GHSA

MEDIUM
Ech0's Unauthenticated Like Endpoint Enables Arbitrary Engagement Metric Inflation
GHSA-rgj7-vg8v-j4wr
pkg: github.com/lin-snow/ech0
eco: go
published: May 7, 2026
### Summary

**No authentication** is required to invoke **`PUT /api/echo/like/:id`**. The handler is registered on the **public** router group. The service increments **`fav_count`** for the given echo **without** checking identity, **without** a per-user limit, and **without** CSRF tokens. A remot…

GitHub-GHSA

MEDIUM
Ech0 comment model's Email field returned on public /api/comments endpoints
GHSA-rj4g-rqgh-rx9h
pkg: github.com/lin-snow/Ech0
eco: go
published: May 7, 2026
## Summary

The `Comment` model serializes its `Email` field through the public comment-listing API. `internal/model/comment/comment.go:33` uses `json:"email"`, while adjacent PII fields (`IPHash`, `UserAgent`) correctly use `json:"-"`. The public endpoints `GET /api/comments?echo_id=X` and `GET /ap…

GitHub-GHSA

MEDIUM
Zebra Vulnerable to Allocation Amplification in Inbound Network Deserializers
GHSA-438q-jx8f-cccv
pkg: zebra-network, zebrad, zebra-chain
eco: rust
published: May 7, 2026
# CVE-2026-44500: Allocation Amplification in Inbound Network Deserializers

## Summary

Several inbound deserialization paths in Zebra allocated buffers sized against generic transport or block-size ceilings before the tighter protocol or consensus limits were enforced. An unauthenticated or post-h…

CVE-2026-44500
GitHub-GHSA

MEDIUM
Netty MQTT: Resource exhaustion in MqttDecoder
GHSA-jfg9-48mv-9qgx
pkg: io.netty:netty-codec-mqtt, io.netty:netty-codec-mqtt
eco: maven
published: May 7, 2026
### Impact
The MQTT 5 header Properties section is parsed and buffered _before_ any message size limit is applied.

Specifically, in `MqttDecoder`, the `decodeVariableHeader()` method is called before the `bytesRemainingBeforeVariableHeader > maxBytesInMessage` check. The `decodeVariableHeader()` ca…

CVE-2026-44248
GitHub-GHSA

MEDIUM
vm2's Transformer Fast-Path Bypass Exposes Internal State Variable
GHSA-wp5r-2gw5-m7q7
pkg: vm2
eco: npm
published: May 7, 2026
### Summary
vm2's code transformer has a performance optimization that skips AST analysis when the code does not contain `catch`, `import`, or `async` keywords. This fast-path bypass allows sandboxed code to directly access the internal `VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL` variable, …
CVE-2026-44003
GitHub-GHSA

MEDIUM
Goteberg has arbitrary PDF read via stampExpression and watermarkExpression in merge, split, and convert routes
GHSA-3cv5-q585-h563
pkg: github.com/gotenberg/gotenberg/v8
eco: go
published: May 7, 2026
## Summary

Six conversion routes (`pdfengines/merge`, `pdfengines/split`, `libreoffice/convert`, `chromium/convert/url`, `chromium/convert/html`, `chromium/convert/markdown`) accept `stampSource=pdf` + `stampExpression=/path` and `watermarkSource=pdf` + `watermarkExpression=/path` from anonymous ca…

CVE-2026-42593
GitHub-GHSA

MEDIUM
Gotenberg's DNS rebinding bypasses SSRF validation on Chromium URL conversion routes
GHSA-2pmr-289p-44r3
pkg: github.com/gotenberg/gotenberg/v8
eco: go
published: May 7, 2026
## Summary

`FilterOutboundURL` resolves the hostname, checks the resolved IPs against the private-address deny-list, and returns only the error. It discards the resolved addresses. Chromium later performs its own DNS resolution when it navigates to the URL. An attacker who controls DNS for a hostna…

CVE-2026-42592
GitHub-GHSA

MEDIUM
OpenSearch Security plugin: DLS not applied on documents linked by has_child or has_parent relation
GHSA-x83w-23jp-g6pw
pkg: org.opensearch.plugin:opensearch-security, org.opensearch.plugin:opensearch-security
eco: maven
published: May 7, 2026
### Description

A flaw was identified in the OpenSearch Security plugin's document-level security (DLS) implementation. DLS restrictions were not correctly applied to search queries that use has_parent or has_child join relations. This could allow an authenticated user to access document contents t…

GitHub-GHSA

MEDIUM
Nitro has a proxy scope bypass via percent-encoded path traversal in `routeRules`
GHSA-5w89-w975-hf9q
pkg: nitro, nitropack
eco: npm
published: May 6, 2026
A proxy route rule like:

“`ts
routeRules: {
"/api/orders/**": { proxy: { to: "http://upstream/orders/**" } }
}
“`

is intended to limit the proxy to URLs under `/api/orders/`. Before the patch, an attacker could bypass that scope by sending percent-encoded path traversal (`..%2f`) in the URL, c…

CVE-2026-44373
GitHub-GHSA

MEDIUM
Lemmy may expose private community data through community, saved, liked, and modlog API views
GHSA-95q8-x6r6-672m
pkg: lemmy_api
eco: rust
published: May 6, 2026
## Summary

Lemmy applies private-community checks in `PostView` and `CommentView`, but several adjacent API views skip the accepted-follower filter. Bob, a registered user who is not an accepted follower, can read private community `sidebar` and `summary` fields. Alice, a former accepted follower, …

GitHub-GHSA

MEDIUM
Private Lemmy instances expose multi-community metadata without authentication
GHSA-jmxc-hhwx-gvv3
pkg: lemmy_api
eco: rust
published: May 6, 2026
## Summary

`read_multi_community()` does not enforce the private-instance setting. On a private instance, an unauthenticated visitor can read multi-community names, titles, summaries, sidebars, owner identities, and member community lists.

## Details

Other read handlers load `local_site` and call…

GitHub-GHSA

MEDIUM
Hatchet affected by cross-tenant information disclosure in `listTasksByDAGIds`
GHSA-55gc-6fmc-fpx9
pkg: github.com/hatchet-dev/hatchet
eco: go
published: May 6, 2026
## Summary

A missing authorization directive on the `GET /api/v1/stable/dags/tasks` endpoint caused Hatchet's tenant-membership check to be skipped for this route. A user authenticated to any tenant on the same Hatchet instance could query the endpoint with another tenant's UUID and a DAG UUID belo…

CVE-2026-42572
GitHub-GHSA

MEDIUM
Nokogiri XSLT transform has a memory leak
GHSA-v2fc-qm4h-8hqv
pkg: nokogiri
eco: rubygems
published: May 6, 2026
## Summary

Nokogiri's `Nokogiri::XSLT::Stylesheet#transform` leaks a small heap allocation when passed a Ruby string parameter containing a null byte.

For applications that pass attacker-controlled input through `XSLT.transform` parameters, this may be a vector for a denial of service attack again…

GitHub-GHSA

MEDIUM
PyLoad vulnerable to unauthenticated traceback disclosure via global exception handler in WebUI
GHSA-c3gc-9pf2-84gg
pkg: pyload-ng
eco: pip
published: May 6, 2026
### Summary
`pyload-ng` WebUI returns full Python traceback details to clients on unhandled exceptions.

Because `/web/<path:filename>` is reachable without authentication and renders attacker-controlled template names, an unauthenticated user can reliably trigger a server exception (for example by …

CVE-2026-44226
GitHub-GHSA

MEDIUM
GraphQL-Ruby's Ruby lexer does not count comment tokens for the purposes of max_query_string_tokens
GHSA-3h96-34p3-xm76
pkg: graphql, graphql, graphql
eco: rubygems
published: May 5, 2026
GraphQL-Ruby's `max_query_string_tokens` configuration didn't count comment tokens against the limit, allowing strings to be processed even after the configured maximum had actually been reached.

In patched versions, the Ruby lexer does count these tokens.

GraphQL-CParser is not affected by this…

NVD

MEDIUM
CVE-2026-34527
CVE-2026-34527
pkg: sandboxie-plus sandboxie

published: May 5, 2026

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, SbieIniServer::HashPassword converts a SHA-1 digest to hexadecimal incorrectly. The high nibble of each byte is shifted right by 8 instead of 4, which always produces zero for an 8-bit valu…
CWE: CWE-328
GitHub-GHSA

MEDIUM
OpenStack Horizon has Incorrect Behavior Order
GHSA-vxvf-xvm3-p8j5
pkg: horizon
eco: pip
published: May 5, 2026
An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauthenticated requests. This is a regression of the CVE-2014-8124 fix.
CVE-2026-43002
GitHub-GHSA

MEDIUM
Django has an Improper Handling of Length Parameter Inconsistency
GHSA-w26r-rmm8-9c29
pkg: Django, Django
eco: pip
published: May 5, 2026
An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. ASGI requests with a missing or understated `Content-Length` header can bypass the `FILE_UPLOAD_MAX_MEMORY_SIZE` limit, potentially loading large files into memory and causing service degradation.

As a reminder, Django expects a li…

CVE-2026-5766
GitHub-GHSA

MEDIUM
Netty: Start-Line Injection in DefaultHttpRequest.setUri() Allows HTTP Request Smuggling and RTSP Request Injection
GHSA-v8h7-rr48-vmmv
pkg: io.netty:netty-codec-http, io.netty:netty-codec-http
eco: maven
published: May 5, 2026
### Summary
Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`.

The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply…

CVE-2026-41417
GitHub-GHSA

MEDIUM
ots has a negative expire override that can bypass its secret retention policy
GHSA-h5fq-653g-gxrm
pkg: github.com/Luzifer/ots
eco: go
published: May 5, 2026
## Summary

The `/api/create` endpoint accepted negative `expire` query values. For the memory storage backend, negative values were passed to secret creation as a negative duration and treated as no expiry, allowing callers to create secrets that persisted longer than intended.

## Impact

Unauthen…

GitHub-GHSA

MEDIUM
Apache Thrift has a Memory Allocation with Excessive Size Value Vulnerability
GHSA-2f9f-gq7v-9h6m
pkg: thrift
eco: rust
published: May 5, 2026
Memory Allocation with Excessive Size Value vulnerability in Apache Thrift.

This issue affects Apache Thrift: before 0.23.0.

Users are recommended to upgrade to version [0.23.0](https://github.com/apache/thrift/releases/tag/v0.23.0), which fixes the issue.

CVE-2026-43868
GitHub-GHSA

MEDIUM
Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStream
GHSA-445q-vr5w-6q77
pkg: axios
eco: npm
published: May 5, 2026
### Summary
The `FormDataPart` constructor in `lib/helpers/formDataToStream.js` interpolates `value.type` directly into the `Content-Type` header of each multipart part without sanitizing CRLF (`\r\n`) sequences. An attacker who controls the `.type` property of a Blob/File-like object (e.g., via a u…
CVE-2026-42037
GitHub-GHSA

MEDIUM
Axios' HTTP adapter-streamed uploads bypass maxBodyLength when maxRedirects: 0
GHSA-5c9x-8gcm-mpgx
pkg: axios, axios
eco: npm
published: May 5, 2026
### Summary

For stream request bodies, maxBodyLength is bypassed when maxRedirects is set to 0 (native http/https transport path). Oversized streamed uploads are sent fully even when the caller sets strict body limits.

### Details

Relevant flow in lib/adapters/http.js:
– 556-564: maxBodyLength …

CVE-2026-42034
GitHub-GHSA

MEDIUM
Axios: HTTP adapter streamed responses bypass maxContentLength
GHSA-vf2m-468p-8v99
pkg: axios, axios
eco: npm
published: May 5, 2026
### Summary

When responseType: 'stream' is used, Axios returns the response stream without enforcing maxContentLength. This bypasses configured response-size limits and allows unbounded downstream consumption.

### Details
In lib/adapters/http.js:
– 786-789: for responseType === 'stream', Axios i…

CVE-2026-42036
NVD

MEDIUM
CVE-2026-41572
CVE-2026-41572
pkg: go

published: May 4, 2026

Note Mark is an open-source note-taking application. Prior to version 0.19.3, after a note-mark owner soft-deletes a public book, its notes and uploaded assets stay readable at /api/notes/{id}, /api/notes/{id}/content, the slug URL, and the asset endpoints. Unauthenticated callers who hold the note …
CWE: CWE-285
GitHub-GHSA

MEDIUM
`potato-annotation` has a Project-Boundary Bypass
GHSA-q9m2-fhv9-3jcf
pkg: potato-annotation
eco: pip
published: May 8, 2026
## Summary
`validate_path_security` uses string-prefix containment (`startswith`) for boundary checks. This allows paths that are **outside** the intended project directory but share its prefix string (e.g., `/tmp/potato_proj_demo_evil/…` vs `/tmp/potato_proj_demo`) to be accepted.

## Details
###…

GitHub-GHSA

MEDIUM
Open WebUI's Mass Assignment via Pydantic extra='allow' Allows Creating Folders in Other Users' Accounts
GHSA-hr43-rjmr-7wmm
pkg: open-webui
eco: pip
published: May 8, 2026
# Mass Assignment via Pydantic extra='allow' Allows Creating Folders in Other Users' Accounts

## Affected Component

Folder creation endpoint and form model:
– `backend/open_webui/models/folders.py` (lines 72-77, `FolderForm` with `extra='allow'`)
– `backend/open_webui/models/folders.py` (lines 95-…

CVE-2026-44550
GitHub-GHSA

MEDIUM
ExternalSecrets vulnerable to privilege escalation with secret overwriting
GHSA-fq7h-9×26-6j22
pkg: github.com/external-secrets/external-secrets/apis
eco: go
published: May 8, 2026
ExternalSecrets allows users to craft Service Account tokens for misconfigured Service Accounts in namespaces the users have access to.

### Impact

A user who only has permission to create ExternalSecret resources can cause the operator to create a Secret that Kubernetes will automatically populate…

CVE-2026-42876
GitHub-GHSA

MEDIUM
Open WebUI has Stored XSS in Pending User Overlay via Incorrect DOMPurify Application Order
GHSA-fq3v-xjjx-95rc
pkg: open-webui
eco: pip
published: May 8, 2026
## Vulnerability Details

**CWE-79**: Cross-site Scripting (XSS)

The `AccountPending.svelte` component renders the admin-configured "Pending User Overlay Content" using `marked.parse()` inside `{@html}` with an incorrect DOMPurify application order:

### Vulnerable Code

**`src/lib/components/layou…

CVE-2026-44568
GitHub-GHSA

MEDIUM
Ech0's RSS feed renders unescaped tag names and raw-HTML markdown, stored XSS against subscribers
GHSA-3v85-fqvh-7rxf
pkg: github.com/lin-snow/Ech0
eco: go
published: May 7, 2026
## Summary

The public RSS/Atom feed at `/rss` renders two attacker-controlled surfaces without HTML escaping. Tag names flow through `fmt.Appendf(renderedContent, "<br /><span class=\"tag\">#%s</span>", tag.Name)` at `internal/service/common/common.go:120`, and the Markdown renderer at `internal/ut…

NVD

MEDIUM
CVE-2026-40243
CVE-2026-40243
pkg: linuxcontainers incus

published: May 6, 2026

Incus is a system container and virtual machine manager. In versions before 7.0.0, broken TLS validation logic in the OVN database connection logic can allow connections to an attacker's OVN database. The OVN client implementations disable Go standard TLS server verification and replace it with cust…
CWE: CWE-295
GitHub-GHSA

MEDIUM
Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy
GHSA-w9j2-pvgh-6h63
pkg: axios, axios
eco: npm
published: May 5, 2026
# Vulnerability Disclosure: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy

## Summary

The Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any `Object.prototype` pollution to **silently suppress all HTTP error responses** (40…

CVE-2026-42041
GitHub-GHSA

MEDIUM
utcp-http vulnerable to SSRF via attacker-controlled OpenAPI servers[0].url in HTTP communication protocol
GHSA-39j6-4867-gg4w
pkg: utcp-http
eco: pip
published: May 7, 2026
## Summary

The `utcp-http` plugin is vulnerable to a blind Server-Side Request Forgery (SSRF) caused by a trust-boundary inconsistency between manual discovery and tool invocation. `register_manual()` validates the discovery URL against an HTTPS / loopback allowlist, but `call_tool()` and `call_too…

CVE-2026-44661
GitHub-GHSA

MEDIUM
hono/jsx has Unvalidated JSX Tag Names that May Allow HTML Injection
GHSA-69xw-7hcm-h432
pkg: hono
eco: npm
published: May 6, 2026
## Summary

Improper handling of JSX element tag names in hono/jsx allowed unvalidated tag names to be directly inserted into the generated HTML output.

When untrusted input is used as a tag name via the programmatic `jsx()` or `createElement()` APIs during server-side rendering, specially crafted …

CVE-2026-44455
GitHub-GHSA

MEDIUM
PPTAgent: Arbitrary File Write via `save_generated_slides`
GHSA-pxhg-7xr2-w7xg
pkg: pptagent
eco: pip
published: May 5, 2026
## Summary

> This vulnerability has been fixed in https://github.com/icip-cas/PPTAgent/commit/418491a9a1c02d9d93194b5973bb58df35cf9d00.

The `save_generated_slides` MCP tool accepts a pptx_path argument and writes the generated PPTX file to that path without any workspace restriction or path valida…

CVE-2026-42080
GitHub-GHSA

MEDIUM
PPTAgent: Arbitrary File Write + Directory Creation via markdown_table_to_image
GHSA-hrcw-xc63-g29m
pkg: pptagent
eco: pip
published: May 5, 2026
### Summary

The `markdown_table_to_image` tool accepts a caller-controlled path parameter and passes it directly to `get_html_table_image`:

“`python
# pptagent/mcp_server.py:127-143
def markdown_table_to_image(markdown_table: str, path: str, css: str) -> str:
"""
Args:
path (str):…

CVE-2026-42078
NVD

MEDIUM
CVE-2026-7572
CVE-2026-7572
pkg: linux

published: May 6, 2026

An off-by-one error (CWE-193) in the ConsumeUnit16Array and ConsumeUnit64Array functions in Velocidex Velociraptor before version 0.76.5 on Windows and Linux allows a local attacker to cause a Denial of Service (DoS) via a process crash by providing a specially crafted .evtx file to the parse_evtx V…
CWE: CWE-193
GitHub-GHSA

MEDIUM
XWiki PlantUML Macro Vulnerable to Server-Side Request Forgery (SSRF) via 'server' parameter
GHSA-42fc-7w97-8vrc
pkg: org.xwiki.contrib.plantuml:macro-plantuml-macro
eco: maven
published: May 5, 2026
### Impact

The [PlantUML Macro](https://extensions.xwiki.org/xwiki/bin/view/Extension/PlantUML+Macro) is vulnerable to Server-Side Request Forgery (SSRF). The macro allows users to specify an alternative PlantUML server via the `server` parameter. However, the application does not validate the supp…

CVE-2026-42140
NVD

MEDIUM
CVE-2026-8194
CVE-2026-8194
pkg: react

published: May 9, 2026

A security vulnerability has been detected in osTicket up to 1.18.3. Impacted is an unknown function of the file include/class.dispatcher.php of the component Dispatcher. The manipulation of the argument _method leads to cross-site request forgery. Remote exploitation of the attack is possible. The …
CWE: CWE-352, CWE-862
GitHub-GHSA

MEDIUM
Hono has CSS Declaration Injection via Style Object Values in JSX SSR
GHSA-qp7p-654g-cw7p
pkg: hono
eco: npm
published: May 9, 2026
### Summary

The JSX renderer escapes `style` attribute object values for HTML but not for CSS. Untrusted input in a `style` object value or property name can therefore inject additional CSS declarations into the rendered `style` attribute. The impact is limited to CSS and does not allow JavaScript …

CVE-2026-44458
GitHub-GHSA

MEDIUM
free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing subsId when UE state exists (nil pointer dereference)
GHSA-4rqf-grm6-vf75
pkg: github.com/free5gc/udr
eco: go
published: May 8, 2026
### Summary
free5GC's UDR `nudr-dr` `DELETE /subscription-data/{ueId}/{servingPlmnId}/ee-subscriptions/{subsId}/amf-subscriptions` handler contains a nil-pointer dereference reachable from a single authenticated request, after one preparatory authenticated EE-subscription create. The handler checks …
CVE-2026-44323
GitHub-GHSA

MEDIUM
Wagtail has improper permission handling when viewing page history
GHSA-c4mr-889m-vgf6
pkg: wagtail, wagtail
eco: pip
published: May 8, 2026
### Impact

A CMS user without the ability to edit a page could still access the history report for the page, potentially resulting in disclosure of sensitive information.

### Patches
Patched versions have been released as Wagtail 7.0.7 and 7.3.2. The new 7.4 LTS feature release also incorporates t…

CVE-2026-44198
NVD

MEDIUM
CVE-2026-42282
CVE-2026-42282
pkg: oauth

published: May 8, 2026

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to version 2.47.13, when n8n-mcp runs in HTTP transport mode, authenticated MCP tools/call requests had their full arguments and JSON-RPC params written to server logs by the requ…
CWE: CWE-532
GitHub-GHSA

MEDIUM
Open WebUI Missing Access Check on Channel Members Endpoint for Standard Channels
GHSA-c7wp-3qh5-55pv
pkg: open-webui
eco: pip
published: May 8, 2026
# Missing Access Check on Channel Members Endpoint for Standard Channels

## Affected Component

Channel members listing endpoint:
– `backend/open_webui/routers/channels.py` (lines 445-507, `get_channel_members_by_id`)

## Affected Versions

Current main branch and likely all versions with the chann…

CVE-2026-44559
GitHub-GHSA

MEDIUM
Open WebUI vulnerable to Global Knowledge Base Enumeration via knowledge-bases Meta-Collection
GHSA-6c2x-gcp3-gp73
pkg: open-webui
eco: pip
published: May 8, 2026
# Global Knowledge Base Enumeration via knowledge-bases Meta-Collection

## Affected Component

Retrieval collection access validation:
– `backend/open_webui/routers/retrieval.py` (lines 2330-2355, `_validate_collection_access`)
– `backend/open_webui/routers/retrieval.py` (query endpoints, e.g. `POS…

CVE-2026-44557
GitHub-GHSA

MEDIUM
Bunsink has an SSRF bypass in `validate_webhook_url`
GHSA-fp53-qcf8-2xx2
pkg: bugsink
eco: pip
published: May 8, 2026
## Summary

Bugsink’s webhook URL validation in versions 2.1.2 and earlier could be (partially) bypassed because of a mismatch in URL parsing.

In some malformed URLs, Python’s standard URL parser (urllib) and the HTTP client stack (requests / urllib3) do not agree on which host is actually bei…

CVE-2026-44502
GitHub-GHSA

MEDIUM
Weblate vulnerable to XSS via crafted Markdown
GHSA-5cmv-3rc4-7279
pkg: weblate
eco: pip
published: May 7, 2026
### Impact
The Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes.

### Patches
* https://github.com/WeblateOrg/weblate/pull/19259

### Workarounds
Even though the attacker might be able to inject code into the HTML, the Weblate's strict …

CVE-2026-44264
GitHub-GHSA

MEDIUM
Weblate Vulnerable to Private Translation Enumeration via Screenshot API
GHSA-gcg5-86jr-f7jg
pkg: weblate
eco: pip
published: May 7, 2026
### Impact

The screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user.

### Patches
* https://github.com/WeblateOrg/weblate/pull/19258

### Acknowledgement
Weblate thanks Luay for reporting this vulnerability according to the org…

CVE-2026-44263
GitHub-GHSA

MEDIUM
Backstage: Catalog unprocessed read endpoints allow authenticated cross-owner data access without permission checks
GHSA-p7g9-rp3g-mgfg
pkg: @backstage/plugin-catalog-unprocessed-entities-common, @backstage/plugin-catalog-unprocessed-entities, @backstage/plugin-catalog-backend-module-unprocessed
eco: npm
published: May 6, 2026
### Impact

The unprocessed entities read endpoints in `@backstage/plugin-catalog-backend-module-unprocessed` do not enforce permission authorization checks. Any authenticated user can access unprocessed entity records regardless of ownership. This is
an information disclosure vulnerability …

CVE-2026-44374
NVD

MEDIUM
CVE-2026-7946
CVE-2026-7946
pkg: google chrome, apple macos, google chrome_os

published: May 6, 2026

Insufficient policy enforcement in WebUI in Google Chrome on Linux, Mac, Windows, ChromeOS prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-693
NVD

MEDIUM
CVE-2026-7904
CVE-2026-7904
pkg: google chrome, apple macos, linux linux_kernel

published: May 6, 2026

Out of bounds read in Fonts in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-125
GitHub-GHSA

MEDIUM
Kubewarden vulnerable to RBAC Reconnaissance via unchecked can_i host capability call
GHSA-wqcw-g35j-j578
pkg: github.com/kubewarden/kubewarden-controller
eco: go
published: May 5, 2026
### Impact
Kubewarden is a policy engine for Kubernetes. Kubewarden cluster operators can grant permissions to users to deploy namespaced AdmissionPolicies and AdmissionPolicyGroups in their Namespaces. One of Kubewarden promises is that configured users can deploy namespaced policies in a safe mann…
CVE-2026-42541
GitHub-GHSA

MEDIUM
@workos/authkit-session has an Open Redirect via state-derived redirect target
GHSA-vvvv-983w-r7pv
pkg: @workos/authkit-session
eco: npm
published: May 5, 2026
An open redirect vulnerability exists in `AuthService.handleCallback` due to insufficient validation of the `returnPathname` value derived from the OAuth `state` parameter.

The `state` parameter is round-tripped through the identity provider (IdP) and can be influenced by an attacker. The handleCal…

CVE-2026-42565
NVD

MEDIUM
CVE-2026-7996
CVE-2026-7996
pkg: google chrome, apple macos, linux linux_kernel

published: May 6, 2026

Insufficient validation of untrusted input in SSL in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
CWE: CWE-20
NVD

MEDIUM
CVE-2026-7912
CVE-2026-7912
pkg: google chrome, google android

published: May 6, 2026

Integer overflow in GPU in Google Chrome on Android prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-472
GitHub-GHSA

MEDIUM
next-intl has prototype pollution with `experimental.messages.precompile` via attacker-controlled translation catalog keys
GHSA-4c35-wcg5-mm9h
pkg: next-intl
eco: npm
published: May 6, 2026
## Summary

`setNestedProperty` in `packages/next-intl/src/extractor/utils.tsx` walks a dotted key path and assigns the final value without blocking the reserved keys `__proto__`, `constructor`, or `prototype`. When the next-intl Next.js plugin is configured with `experimental.messages` and `message…

GitHub-GHSA

MEDIUM
in-toto-golang and in-toto-python have inconsistent negation behavior
GHSA-pmwq-pjrm-6p5r
pkg: github.com/in-toto/in-toto-golang
eco: go
published: May 8, 2026
### Impact
_What kind of vulnerability is it? Who is impacted?_

in-toto-golang and in-toto-python both support glob patterns in artifact rules to indicate the artifacts that a rule applies to. Both support negations in character classes to indicate what should *not* be matched, but they used differ…

GitHub-GHSA

MEDIUM
ciguard: SCA HTTP client reads response body without size cap
GHSA-xw8c-rrvx-f7xq
pkg: ciguard
eco: pip
published: May 5, 2026
## Summary

Both SCA HTTP clients (`src/ciguard/analyzer/sca/osv.py` and `src/ciguard/analyzer/sca/endoflife.py`) call `payload = json.loads(resp.read().decode('utf-8'))` without a maximum-bytes cap. A hostile or compromised endoflife.date / OSV.dev (or a successful TLS MITM) could return a multi-GB…

CVE-2026-44219
GitHub-GHSA

MEDIUM
Mistune has XSS via unescaped figclass/figwidth in Figure directive
GHSA-58cw-g322-p94v
pkg: mistune
eco: pip
published: May 8, 2026
In `src/mistune/directives/image.py`, the `render_figure()` function concatenates `figclass` and `figwidth` options directly into HTML attributes without escaping (lines 152-168).

This allows attribute injection and XSS even when `HTMLRenderer(escape=True)` is used, because these values bypass the …

CVE-2026-44896
GitHub-GHSA

MEDIUM
eml_parser has recursion DoS via nested message/rfc822 attachments
GHSA-g47v-rwmh-r9f8
pkg: eml_parser
eco: pip
published: May 8, 2026
### Summary

`EmlParser.get_raw_body_text()` recurses unconditionally for every nested `message/rfc822` attachment without any depth limit. An attacker who can supply a badly crafted EML file with approximately 120 nested `message/rfc822` parts triggers an unhandled `RecursionError` and aborts parsi…

CVE-2026-44844
GitHub-GHSA

MEDIUM
@cyclonedx/cdxgen: Docker registry auth substring match forwards credentials to a different registry
GHSA-qhh4-458h-xwh2
pkg: @cyclonedx/cdxgen
eco: npm
published: May 8, 2026
# Docker registry auth substring match forwards credentials to a different registry

## Repository

`cdxgen/cdxgen`

## Affected product/package

– Ecosystem: npm
– Package: `@cyclonedx/cdxgen`
– Reviewed tree version: `12.3.3`
– Reviewed commit: `b1e179869fd7c6032c3d483c3f7bd4d7154ec22b`
– Affected…

GitHub-GHSA

MEDIUM
MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist
GHSA-r48c-v28r-pf6v
pkg: github.com/modelcontextprotocol/registry
eco: go
published: May 8, 2026
### Summary

The Registry's HTTP-based namespace verification (`POST /v0/auth/http`, `POST /v0.1/auth/http`) uses `safeDialContext` (`internal/api/handlers/v0/auth/http.go:67-110`) to refuse dialling private/internal addresses when fetching the well-known public-key file from a publisher-supplied do…

CVE-2026-44430
GitHub-GHSA

MEDIUM
MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl`
GHSA-rqv2-m695-f8j4
pkg: github.com/modelcontextprotocol/registry
eco: go
published: May 8, 2026
## Summary

The public catalogue UI served at `GET /` (file `internal/api/handlers/v0/ui_index.html`) is vulnerable to stored cross-site scripting via the `server.websiteUrl` field of any published `server.json`. Server-side validation in `internal/validators/validators.go` (`validateWebsiteURL`) on…

CVE-2026-44429
GitHub-GHSA

MEDIUM
MCP Registry has open redirect via protocol-relative path in trailing-slash middleware
GHSA-v8vw-gw5j-w7m6
pkg: github.com/modelcontextprotocol/registry
eco: go
published: May 8, 2026
### Summary
The TrailingSlashMiddleware in internal/api/server.go is vulnerable to an open redirect attack. An attacker can craft a URL with a protocol-relative path (e.g., //evil.com/) that, after trailing slash removal, results in a Location header of //evil.com — which browsers interpret as an …
CVE-2026-44427
GitHub-GHSA

MEDIUM
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
GHSA-xv59-967r-8726
pkg: openssl
eco: rust
published: May 7, 2026
`CipherCtxRef::cipher_update`, `CipherCtxRef::cipher_update_vec`, and `symm::Crypter::update` incorrectly sized output buffers when used with AES key-wrap-with-padding ciphers (`EVP_aes_{128,192,256}_wrap_pad`). For a non-multiple-of-8 input, OpenSSL writes up to 7 bytes past the end of the caller's…
CVE-2026-44662
GitHub-GHSA

MEDIUM
gittuf's policy can be rolled back to prior valid versions
GHSA-vxvc-cg7j-rwqj
pkg: github.com/gittuf/gittuf
eco: go
published: May 7, 2026
## Summary

An attacker with push access to gittuf's Reference State Log (RSL) can roll back the current policy to any previous policy trusted by the current set of root keys.

## Impact

gittuf determines the policy to load by inspecting the RSL. Except for the very first policy (which is automatic…

CVE-2026-44544
GitHub-GHSA

MEDIUM
imageproc: integer overflow in kernel size check leads to out-of-bounds read
GHSA-w5p8-4jcx-2j6r
pkg: imageproc, imageproc, imageproc
eco: rust
published: May 7, 2026
A bounds verification of a slice storage of a 2-dimensional matrix's coefficients (a kernel) would compare the total size against the product of individual dimensions. This would erroneously cast *after* the multiplication and consequently fail to detect possible violations when overflow occurs.

Af…

GitHub-GHSA

MEDIUM
imageproc: Out-of-bounds read via NaN coordinates in bilinear/bicubic sampling
GHSA-qg8r-f7x3-25f7
pkg: imageproc, imageproc, imageproc
eco: rust
published: May 7, 2026
A bounds check was performed in floating points before a cast to the index passed to an unchecked access function. This checked considered `NaN` cases improperly, causing them to succeed the check instead of failing it. The floating point coordinate is under caller control by passing a selected proj…
GitHub-GHSA

MEDIUM
imageproc has fragile bounds check when sampling from image
GHSA-5qv7-j6w5-fr4m
pkg: imageproc, imageproc, imageproc
eco: rust
published: May 7, 2026
A read of pixels was coded as modifying coordinates to lie within the image bounds. It would calculate a coordinate by adding a constant to an input and taking the minimum of the resulting coordinate and 'dimension – 1'. This would not protect against malicious inputs that could overflow the additio…
GitHub-GHSA

MEDIUM
hickory-proto vulnerable to CPU exhaustion during message encoding due to O(n²) name compression
GHSA-q2qq-hmj6-3wpp
pkg: hickory-proto
eco: rust
published: May 7, 2026
During message encoding, `hickory-proto`'s `BinEncoder` stores pointers to labels that are candidates for name compression in a `Vec<(usize, Vec<u8>)>`. The name compression logic then searches for matches with a linear scan.

A malicious message with many records can both introduce many candidate l…

GitHub-GHSA

MEDIUM
wasmtime has a panic when allocating a table exceeding the size of the host's address space
GHSA-p8xm-42r7-89xg
pkg: wasmtime, wasmtime
eco: rust
published: May 7, 2026
### Impact

Wasmtime's allocation logic for a WebAssembly table contained checked arithmetic which panicked on overflow. This overflow is possible to trigger, and thus panic, when a table with an extremely large size is allocated. This is possible with the WebAssembly memory64 proposal where tables …

CVE-2026-44216
GitHub-GHSA

MEDIUM
Spring Cloud AWS missing SNS message signature verification allows spoofing of HTTP/HTTPS endpoint notifications
GHSA-r4w4-wv68-qv85
pkg: io.awspring.cloud:spring-cloud-aws-sns, io.awspring.cloud:spring-cloud-aws-sns
eco: maven
published: May 7, 2026
### Impact

Applications using Spring Cloud AWS SNS HTTP/HTTPS endpoint support (@NotificationMessageMapping, @NotificationSubscriptionMapping, @NotificationUnsubscribeConfirmationMapping) did not verify the signature of incoming SNS messages.

An unauthenticated attacker who knows the endpoint …

CVE-2026-44308
GitHub-GHSA

MEDIUM
Lemmy resend-verification endpoint exposes registered email addresses to unauthenticated users
GHSA-qxrw-f6fh-34r7
pkg: lemmy_api
eco: rust
published: May 6, 2026
## Summary

The unauthenticated resend-verification endpoint returns different responses for registered and unregistered email addresses. A malicious third party can submit candidate addresses to `/api/v4/account/auth/resend_verification_email` and distinguish accounts from misses.

## Details

`res…

GitHub-GHSA

MEDIUM
Playwright Capture permits access to local files and internal network resources during page capture
GHSA-687h-xw6f-q2qw
pkg: PlaywrightCapture
eco: pip
published: May 6, 2026
Playwright Capture did not sufficiently restrict navigations and resource requests initiated by rendered pages. An attacker-controlled page could abuse browser-side redirection mechanisms, such as window.location.href, to make the capture process open file:// URLs or request resources hosted on priv…
CVE-2026-44439
GitHub-GHSA

MEDIUM
Angular SSR has Open Redirect and Request Steering via Encoded X-Forwarded-Prefix
GHSA-69xr-m8h6-h664
pkg: @angular/ssr, @angular/ssr, @angular/ssr
eco: npm
published: May 6, 2026
### Description
A vulnerability exists in the `X-Forwarded-Prefix` header processing logic within Angular SSR. The internal validation mechanism fails to properly account for URL-encoded characters, specifically dots (`%2e%2e`). This allows an attacker to bypass security filters by injecting encoded…
CVE-2026-44437
GitHub-GHSA

MEDIUM
kanidmd_lib: Image upload validators run before authorization; PNG validator panics on malformed input
GHSA-84jc-3hj2-hwc7
pkg: kanidmd_lib
eco: rust
published: May 6, 2026
### Summary
The `POST /v1/domain/_image` and `POST /v1/oauth2/{rs_name}/_image` handlers call `validate_image()` on the uploaded body **before** the ACL check that restricts image upload to admins. Any bug in an image validator is therefore reachable by an unauthenticated remote client rather than b…
GitHub-GHSA

MEDIUM
Nitro has an Open Redirect via Protocol-Relative URL Bypass in Wildcard Route Rules
GHSA-9phm-9p8f-hw5m
pkg: nitro, nitropack
eco: npm
published: May 6, 2026
A redirect route rule like:

“`ts
routeRules: {
"/legacy/**": { redirect: "/**" }
}
“`

is intended to rewrite paths within the same host. Before the patch, an attacker could turn the rewrite into a cross-host redirect by sliding an extra slash in after the rule prefix. Example exploit:

“`
GET…

CVE-2026-44372
GitHub-GHSA

MEDIUM
pyquorum: Timing side‑channel in mul_mod
GHSA-7r92-3jgr-r65q
pkg: pyquorum
eco: pip
published: May 6, 2026
### Impact
The `mul_mod` function implements multiplication via a binary expansion loop whose execution time depends on the Hamming weight of the second operand (the exponent). An attacker who can measure the time of secret‑sharing operations (e.g., via a remote service) could progressively recove…
CVE-2026-44368
GitHub-GHSA

MEDIUM
misp-modules has nsafe remote resource fetching in expansion
GHSA-fhq3-2gf3-8f3j
pkg: misp-modules
eco: pip
published: May 6, 2026
An unsafe remote resource fetching vulnerability existed in MISP Modules expansion modules. The html_to_markdown module accepted arbitrary HTTP(S) URLs without sufficient validation, which could allow Server-Side Request Forgery against loopback, private, or link-local network resources. Additionall…
CVE-2026-44363
GitHub-GHSA

MEDIUM
Hugo's Node tool execution allows file system access outside the project directory
GHSA-x597-9fr4-5857
pkg: github.com/gohugoio/hugo
eco: go
published: May 6, 2026
## Impact
When building a Hugo site that uses Node-based asset pipelines (PostCSS, Babel, TailwindCSS), Hugo invoked the configured Node tools without restrictions on file system access. As a result, executing hugo against an untrusted site could allow code running through these tools to read or wr…
CVE-2026-44301
GitHub-GHSA

MEDIUM
astral-tokio-tar is Vulnerable to PAX Header Desynchronization
GHSA-fp55-jw48-c537
pkg: astral-tokio-tar
eco: rust
published: May 6, 2026
### Impact

Versions of astral-tokio-tar prior to 0.6.1 contain a PAX header interpretation bug that allows manipulated entries to be made selectively visible or invisible during extraction with astral-tokio-tar versus other tar implementations. An attacker could use this differential to smuggle une…

GitHub-GHSA

MEDIUM
Tauri has an Origin Confusion Issue that Allows Remote Pages to Invoke Local-Only IPC Commands
GHSA-7gmj-67g7-phm9
pkg: tauri
eco: rust
published: May 6, 2026
### Summary
A flaw in Tauri's `is_local_url()` function causes it to incorrectly classify remote URLs as trusted local origins on Windows and Android. On these systems, Tauri maps custom URI scheme protocols to `http://<scheme>.localhost/` because those platforms' WebView implementations cannot serv…
CVE-2026-42184
GitHub-GHSA

MEDIUM
sse-channel: SSE Injection via unsanitized event fields
GHSA-84hm-wfh8-c5pg
pkg: sse-channel
eco: npm
published: May 5, 2026
### Impact

Implementations that allows user-provided values to be passed to `event`, `retry` or `id` fields would be susceptible to event spoofing, where an attacker could inject arbitrary messages into the stream.

– **Event Spoofing:** Attacker can inject arbitrary SSE events into the stream
– **…

CVE-2026-44217
GitHub-GHSA

MEDIUM
Prometheus vulnerable to stored XSS via crafted histogram bucket label values in the old web UI heatmap display
GHSA-fw8g-cg8f-9j28
pkg: github.com/prometheus/prometheus
eco: go
published: May 5, 2026
### Impact

In the Prometheus server's legacy web UI (enabled via the command-line flag `–enable-feature=old-ui`), the histogram heatmap chart view does not escape `le` label values when inserting them into the HTML for use as axis tick mark labels.

An attacker who can inject crafted metrics (e.g.…

GitHub-GHSA

MEDIUM
ip-address has XSS in Address6 HTML-emitting methods
GHSA-v2v4-37r5-5v8g
pkg: ip-address
eco: npm
published: May 5, 2026
### Summary

`Address6.group()` and `Address6.link()` do not HTML-escape attacker-controlled content before embedding it in the HTML strings they return, and `AddressError.parseMessage` (emitted by the `Address6` constructor for invalid input) can contain unescaped attacker-controlled content in one…

CVE-2026-42338
GitHub-GHSA

MEDIUM
PocketBase vulnerable to account pre-hijacking via OAuth2 unverfied->verified autolinking upgrade
GHSA-pq7p-mc74-g65w
pkg: github.com/pocketbase/pocketbase, github.com/pocketbase/pocketbase
eco: go
published: May 5, 2026
A pre-hijacking issue was discovered with the OAuth2 autolinking by [Alardiians](https://github.com/Alardiians).

In some situations, if an attacker knows the email address of the victim they can create and link an **unverified** PocketBase user in advance by authenticating with one of the OAuth2 ap…

CVE-2026-44166
GitHub-GHSA

MEDIUM
Ethyca Fides has a Privacy Request Identity Verification Bypass Vulnerability via Duplicate Detection
GHSA-qx5f-ghc2-7g5c
pkg: ethyca-fides
eco: pip
published: May 5, 2026
### Summary

Fides deployments that enable both subject identity verification and duplicate privacy request detection are affected by a vulnerability in which an administrator can approve a privacy request whose identity was never verified. For erasure policies, this can result in unauthorized delet…

CVE-2026-42303
GitHub-GHSA

MEDIUM
Fiber vulnerable to XSS in AutoFormat Content Negotiation
GHSA-qjv7-627w-8qjv
pkg: github.com/gofiber/fiber/v3, github.com/gofiber/fiber/v2
eco: go
published: May 5, 2026
## Summary

**Description**

A Cross-Site Scripting (CWE-79) vulnerability in Go Fiber allows a remote attacker to inject arbitrary HTML/JavaScript by supplying `Accept: text/html` on any request whose handler passes attacker-influenced data to the AutoFormat() feature. This affects `github.com/gofi…

CVE-2026-42554
GitHub-GHSA

MEDIUM
MinIO vulnerable to Path Traversal via msgpack Body in `ReadMultiple` Storage-REST Endpoint
GHSA-xh8f-g2qw-gcm7
pkg: github.com/minio/minio
eco: go
published: May 5, 2026
### Impact

_What kind of vulnerability is it? Who is impacted?_

A path traversal vulnerability in MinIO's `ReadMultiple` internode storage-REST
endpoint allows a caller holding the cluster root JWT to read files from
outside the configured drive roots, bounded only by the MinIO process UID.

Distr…

CVE-2026-42600
GitHub-GHSA

MEDIUM
net-imap vulnerable to command Injection via "raw" arguments to multiple commands
GHSA-hm49-wcqc-g2xg
pkg: net-imap, net-imap, net-imap
eco: rubygems
published: May 4, 2026
### Summary
Several `Net::IMAP` commands accept a raw string argument that is sent to the server without validation or escaping. If this string is derived from user-controlled input, it may contain contain `CRLF` sequences, which an attacker can use to inject arbitrary IMAP commands.

### Details

CVE-2026-42257
GitHub-GHSA

MEDIUM
net-imap vulnerable to command Injection via unvalidated Symbol inputs
GHSA-75xq-5h9v-w6px
pkg: net-imap, net-imap, net-imap
eco: rubygems
published: May 4, 2026
### Summary

Symbol arguments to commands are vulnerable to a CRLF Injection / IMAP Command injection via Symbol arguments passed to IMAP commands.

### Details

Symbol arguments represent IMAP "system flags", which are formatted as "atoms" (with no quoting) with a `"\"` prefix. Vulnerable versions…

CVE-2026-42258
GitHub-GHSA

MEDIUM
net-imap vulnerable to denial of service via high iteration count for `SCRAM-*` authentication
GHSA-87pf-fpwv-p7m7
pkg: net-imap, net-imap, net-imap
eco: rubygems
published: May 4, 2026
### Summary

When authenticating a connection with `SCRAM-SHA1` or `SCRAM-SHA256`, a hostile server can perform a computational denial-of-service attack on the client process by sending a big iteration count value.

### Details

A hostile IMAP server can send an arbitrarily large PBKDF2 iteration co…

CVE-2026-42256
GitHub-GHSA

MEDIUM
quarkus-openapi-generator has overly broad path-parameter matching that sends authentication headers to unintended operations
GHSA-fr8f-rwjx-f32v
pkg: io.quarkiverse.openapi.generator:quarkus-openapi-generator, io.quarkiverse.openapi.generator:quarkus-openapi-generator
eco: maven
published: May 4, 2026
### Summary

The generated authentication filter matches OpenAPI path templates too broadly when deciding whether to attach credentials. A security scheme configured for one operation can therefore be applied to a different same-method operation whose path only partially resembles the protected temp…

CVE-2026-42333
GitHub-GHSA

MEDIUM
OpenClaw's Gateway Control UI bootstrap config required Gateway auth
GHSA-93rg-2xm5-2p9v
pkg: openclaw
eco: npm
published: May 4, 2026
## Summary
Gateway Control UI bootstrap config required Gateway auth.

## Affected Packages / Versions
– Package: openclaw (npm)
– Affected versions: <= 2026.4.21
– Fixed version: 2026.4.22

## Impact
When Gateway authentication was enabled, the Control UI bootstrap config endpoint could still be re…

GitHub-GHSA

MEDIUM
OpenClaw: OpenShell FS bridge reads pin and verify the opened file before returning bytes
GHSA-5h3g-6xhh-rg6p
pkg: openclaw
eco: npm
published: May 4, 2026
## Summary
OpenShell FS bridge reads pin and verify the opened file before returning bytes

## Affected Packages / Versions
– Package: openclaw (npm)
– Affected versions: <= 2026.4.21
– Fixed version: 2026.4.22

## Impact
A time-of-check/time-of-use race around OpenShell sandbox filesystem reads cou…

GitHub-GHSA

MEDIUM
jOpenDocument has an improper restriction of XML external entity reference vulnerability
GHSA-j9rh-p96m-mhhp
pkg: org.jopendocument:jOpenDocument
eco: maven
published: May 4, 2026
Improper restriction of XML external entity reference vulnerability in ILM Informatique jOpenDocument allows Data Serialization External Entities Blowup.

This issue affects jOpenDocument: 1.5.

CVE-2026-6501


Vulnerability Digest — May 4, 2026 · 20 Critical · 4 Exploited






Vulnerability Digest — Monday, May 4, 2026


Security Report

Monday, May 4, 2026  ·  Last 7 days  ·  Min severity: MEDIUM
Total Findings
175
Critical
20
High
99
Actively Exploited
4
CISA-KEV4
NVD117
GitHub-GHSA54
Findings sorted by severity
CISA-KEV

CRITICAL
Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability
CVE-2026-31431
pkg: Linux Kernel

published: May 1, 2026

Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation.
Required action: "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability
CVE-2026-41940
pkg: WebPros cPanel & WHM and WP2 (WordPress Squared)

published: Apr 30, 2026

WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
ConnectWise ScreenConnect Path Traversal Vulnerability
CVE-2024-1708
pkg: ConnectWise ScreenConnect

published: Apr 28, 2026

ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
Microsoft Windows Protection Mechanism Failure Vulnerability
CVE-2026-32202
pkg: Microsoft Windows

published: Apr 28, 2026

Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
GitHub-GHSA

CRITICAL
Gotenberg has ExifTool stdin argument injection via metadata value newlines (bypass of key sanitization fix)
GHSA-q7r4-hc83-hf2q
pkg: github.com/gotenberg/gotenberg/v8
eco: go
published: Apr 30, 2026
## Vulnerability Details

**CWE**: CWE-20 – Improper Input Validation

The metadata value sanitization introduced in v8.30.1 (commit 405f106) only validates metadata KEYS via safeKeyPattern regex. Metadata VALUES are passed unsanitized to go-exiftool SetString(), which writes them as fmt.Fprintln(e.…

CVE-2026-40281
GitHub-GHSA

CRITICAL
n8n has Prototype Pollution in XML Webhook Body Parser that Leads to RCE
GHSA-q5f4-99jv-pgg5
pkg: n8n, n8n, n8n
eco: npm
published: Apr 29, 2026
## Impact
A flaw in the `xml2js` library used to parse XML request bodies in n8n's webhook handler allowed prototype pollution via a crafted XML payload. An authenticated user with permission to create or modify workflows could exploit this to pollute the JavaScript object prototype and, by chaining…
CVE-2026-42231
GitHub-GHSA

CRITICAL
n8n has XML Node Prototype Pollution that to RCE
GHSA-hqr4-h3xv-9m3r
pkg: n8n, n8n, n8n
eco: npm
published: Apr 29, 2026
## Impact
An authenticated user with permission to create or modify workflows could achieve global prototype pollution via the XML Node leading to RCE when combined with other nodes exploiting the prototype pollution.

## Patches
The issue has been fixed in n8n versions 1.123.32, 2.17.4, and 2.18.1.…

CVE-2026-42232
NVD

CRITICAL
CVE-2026-31718
CVE-2026-31718
pkg: linux

published: May 1, 2026

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix use-after-free in __ksmbd_close_fd() via durable scavenger

When a durable file handle survives session disconnect (TCP close without
SMB2_LOGOFF), session_fd_check() sets fp->conn = NULL to preserve the
handle for later…

NVD

CRITICAL
CVE-2026-31705
CVE-2026-31705
pkg: linux

published: May 1, 2026

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix out-of-bounds write in smb2_get_ea() EA alignment

smb2_get_ea() applies 4-byte alignment padding via memset() after
writing each EA entry. The bounds check on buf_free_len is performed
before the value memcpy, but the a…

NVD

CRITICAL
CVE-2018-25316
CVE-2018-25316
pkg: go

published: Apr 29, 2026

Tenda W308R v2 V5.07.48 contains a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient session validation. Attackers can send GET requests to the goform/AdvSetDns endpoint with a crafted admin language cookie to change DNS ser…
CWE: CWE-290
NVD

CRITICAL
CVE-2026-41873
CVE-2026-41873
pkg: apache pony_mail

published: Apr 28, 2026

** UNSUPPORTED WHEN ASSIGNED ** Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Pony Mail leading to admin account takeover.

This issue affects all versions of the Lua implementation of Pony Mail. There is a Python implementation under development u…

CWE: CWE-444
NVD

CRITICAL
CVE-2026-32644
CVE-2026-32644
pkg: ssl

published: Apr 28, 2026

Specific firmware versions of Milesight AIOT cameras use SSL certificates with default private keys.
CWE: CWE-321
NVD

CRITICAL
CVE-2026-41462
CVE-2026-41462
pkg: express

published: Apr 27, 2026

ProjeQtor versions 7.0 through 12.4.3 contain an unauthenticated SQL injection vulnerability in the login functionality where the login variable is directly concatenated into a SQL query without parameterization or sanitization. Attackers can inject arbitrary SQL expressions through the username fie…
CWE: CWE-89
NVD

CRITICAL
CVE-2026-7333
CVE-2026-7333
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Use after free in GPU in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
GitHub-GHSA

CRITICAL
Gotenberg has case-insensitive URL scheme that bypasses webhook and downloadFrom deny-list SSRF protection
GHSA-5q7p-7jgv-ww56
pkg: github.com/gotenberg/gotenberg/v8
eco: go
published: Apr 30, 2026
## Vulnerability Details

**CWE**: CWE-918 – Server-Side Request Forgery (SSRF)

The default private-IP deny-lists for –webhook-deny-list and –api-download-from-deny-list use a case-sensitive regex (^https?://). Any uppercase URL scheme variant (HTTP://, HTTPS://, Http://) bypasses the pattern. Go…

CVE-2026-40280
GitHub-GHSA

CRITICAL
auth: Patreon provider assigns the same local user ID to every authenticated Patreon account, enabling cross‑user impersonation
GHSA-f6qq-3m3h-4g42
pkg: github.com/go-pkgz/auth, github.com/go-pkgz/auth/v2
eco: go
published: Apr 30, 2026
### Summary
The Patreon OAuth provider maps every authenticated Patreon account to the same local `user.ID`, instead of deriving a unique ID from the Patreon account returned by Patreon.

In practice, this means all Patreon-authenticated users of an application using this library are collapsed into …

CVE-2026-42560
GitHub-GHSA

CRITICAL
Sentry's improper authentication on SAML SSO process allows user identity linking
GHSA-rcmw-7mc7-3rj7
pkg: sentry
eco: pip
published: Apr 30, 2026
### Impact
A critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via Sentry's private bug bounty program.

The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the …

CVE-2026-42354
NVD

CRITICAL
CVE-2026-7381
CVE-2026-7381
pkg: express

published: Apr 29, 2026

Plack::Middleware::XSendfile versions through 1.0053 for Perl can allow client-controlled path rewriting.

Plack::Middleware::XSendfile allows the variation setting (sendfile type) to be set by the client via the X-Sendfile-Type header, if it is not considered in the middleware constructor or the Pl…

CWE: CWE-200, CWE-441, CWE-913
NVD

CRITICAL
CVE-2026-30893
CVE-2026-30893
pkg: wazuh wazuh

published: Apr 29, 2026

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.4.0 to before version 4.14.4, a path traversal vulnerability in Wazuh's cluster synchronization extraction routine allows an authenticated cluster peer to write arbitrary files outside the in…
CWE: CWE-22, CWE-73
GitHub-GHSA

CRITICAL
fabric-sdk-java has ObjectInputStream.readObject() without ObjectInputFilter, which allows Java deserialization RCE
GHSA-prf8-cf2x-rhx7
pkg: org.hyperledger.fabric-sdk-java:fabric-sdk-java
eco: maven
published: Apr 29, 2026
## Summary

This advisory covers the deprecated `fabric-sdk-java` client SDK. `Channel.java` implements `readObject()` and exposes `deSerializeChannel()` which call `ObjectInputStream.readObject()` on untrusted byte arrays without configuring an `ObjectInputFilter`. This is the classic Java deserial…

CVE-2026-41586
NVD

HIGH
CVE-2026-2052
CVE-2026-2052
pkg: express

published: May 2, 2026

The Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.2.2 via the Display Logic feature. This is due to the plugin using eval() on user-supplied Display Logic e…
CWE: CWE-94
NVD

HIGH
CVE-2026-43048
CVE-2026-43048
pkg: go

published: May 1, 2026

In the Linux kernel, the following vulnerability has been resolved:

HID: core: Mitigate potential OOB by removing bogus memset()

The memset() in hid_report_raw_event() has the good intention of
clearing out bogus data by zeroing the area from the end of the incoming
data string to the assumed end …

NVD

HIGH
CVE-2026-31735
CVE-2026-31735
pkg: go

published: May 1, 2026

In the Linux kernel, the following vulnerability has been resolved:

iommupt: Fix short gather if the unmap goes into a large mapping

unmap has the odd behavior that it can unmap more than requested if the
ending point lands within the middle of a large or contiguous IOPTE.

In this case the gather…

NVD

HIGH
CVE-2026-31717
CVE-2026-31717
pkg: linux

published: May 1, 2026

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: validate owner of durable handle on reconnect

Currently, ksmbd does not verify if the user attempting to reconnect
to a durable handle is the same user who originally opened the file.
This allows any authenticated user to h…

NVD

HIGH
CVE-2026-31709
CVE-2026-31709
pkg: linux

published: May 1, 2026

In the Linux kernel, the following vulnerability has been resolved:

smb: client: validate the whole DACL before rewriting it in cifsacl

build_sec_desc() and id_mode_to_cifs_acl() derive a DACL pointer from a
server-supplied dacloffset and then use the incoming ACL to rebuild the
chmod/chown securi…

NVD

HIGH
CVE-2026-31706
CVE-2026-31706
pkg: linux

published: May 1, 2026

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: validate num_aces and harden ACE walk in smb_inherit_dacl()

smb_inherit_dacl() trusts the on-disk num_aces value from the parent
directory's DACL xattr and uses it to size a heap allocation:

aces_base = kmalloc(sizeof(st…

NVD

HIGH
CVE-2026-5402
CVE-2026-5402
pkg: wireshark wireshark

published: Apr 30, 2026

TLS protocol dissector heap overflow in Wireshark 4.6.0 to 4.6.4 allows denial of service and possible code execution
CWE: CWE-122
NVD

HIGH
CVE-2026-7466
CVE-2026-7466
pkg: python

published: Apr 29, 2026

AgentFlow contains an arbitrary code execution vulnerability that allows attackers to execute local Python pipeline files by supplying a user-controlled pipeline_path parameter to the POST /api/runs and POST /api/runs/validate endpoints. Attackers can induce requests to the local AgentFlow API to lo…
CWE: CWE-94
NVD

HIGH
CVE-2026-7363
CVE-2026-7363
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Use after free in Canvas in Google Chrome on Linux, ChromeOS prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-7361
CVE-2026-7361
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Use after free in iOS in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-7359
CVE-2026-7359
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Use after free in ANGLE in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416, CWE-416
NVD

HIGH
CVE-2026-7358
CVE-2026-7358
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Use after free in Animation in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-7356
CVE-2026-7356
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Use after free in Navigation in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-7355
CVE-2026-7355
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Use after free in Media in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-416
NVD

HIGH
CVE-2026-7354
CVE-2026-7354
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Out of bounds read and write in Angle in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-125, CWE-787
NVD

HIGH
CVE-2026-7348
CVE-2026-7348
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Use after free in Codecs in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-7344
CVE-2026-7344
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Use after free in Accessibility in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-7342
CVE-2026-7342
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Use after free in WebView in Google Chrome on Android prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-7341
CVE-2026-7341
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Use after free in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-7339
CVE-2026-7339
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Heap buffer overflow in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-122
NVD

HIGH
CVE-2026-7337
CVE-2026-7337
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Type Confusion in V8 in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-843
NVD

HIGH
CVE-2026-7336
CVE-2026-7336
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Use after free in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-7335
CVE-2026-7335
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Use after free in media in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-7334
CVE-2026-7334
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Use after free in Views in Google Chrome on Mac prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-42426
CVE-2026-42426
pkg: openclaw openclaw

published: Apr 28, 2026

OpenClaw before 2026.4.8 contains an improper authorization vulnerability where the node.pair.approve method accepts operator.write scope instead of the narrower operator.pairing scope, allowing unprivileged users to approve node pairing. Attackers with operator.write permissions can bypass pairing …
CWE: CWE-863
NVD

HIGH
CVE-2026-41378
CVE-2026-41378
pkg: openclaw openclaw

published: Apr 28, 2026

OpenClaw before 2026.3.31 contains a privilege escalation vulnerability allowing paired nodes with role=node to dispatch node.event agent requests with unrestricted gateway-side tool access. Attackers with trusted paired node credentials can escalate privileges by leveraging unrestricted agent.reque…
CWE: CWE-862
GitHub-GHSA

HIGH
Gotenberg Vulnerable to Unauthenticated SSRF via Unfiltered Webhook URL
GHSA-5vh4-rgv7-p9g4
pkg: github.com/gotenberg/gotenberg/v8
eco: go
published: Apr 30, 2026
# CVE Report — Unauthenticated SSRF via Unfiltered Webhook URL in Gotenberg

## Severity

| Field | Value |
|———–|—————————————-|
| CVSS v3.1 | **8.6 High** |
| Vector | `AV:N/AC:L/PR:N/UI:N/S:C/C:H/…

CVE-2026-39383
GitHub-GHSA

HIGH
pygeoapi 0.23.x: Unauthenticated SSRF via OGC API – Processes Subscriber
GHSA-jgvc-94c8-3chc
pkg: pygeoapi
eco: pip
published: Apr 29, 2026
### Impact
OGC API – Process execution requests can use the `subscriber` object to requests to internal HTTP services.

### Patches
The issue has been patched in master branch and made available as part of the 0.23.3 release. The patch disables any HTTP requests made to internal resources by defaul…

CVE-2026-42352
NVD

HIGH
CVE-2026-40967
CVE-2026-40967
pkg: vmware spring_ai

published: Apr 28, 2026

In Spring AI, various FilterExpressionConverter implementations accept a filter expression object and translate them to specific vector store query languages. In several cases, keys and values are not properly escaped, leading to the ability to alter the query.

Affected versions:
Spring AI: 1.0.0 -…

CWE: CWE-94
GitHub-GHSA

HIGH
n8n-mcp's IPv4-mapped IPv6 addresses bypass SSRF protection in validateUrlSync(), enabling full SSRF for SDK embedders
GHSA-56c3-vfp2-5qqj
pkg: n8n-mcp
eco: npm
published: Apr 30, 2026
### Impact

In the SDK embedder path (`N8NDocumentationMCPServer` constructor, `getN8nApiClient()`, and `validateInstanceContext()`), the synchronous URL validator in `SSRFProtection.validateUrlSync()` had no IPv6 checks. IPv4-mapped IPv6 addresses such as `http://[::ffff:169.254.169.254]` bypassed …

CVE-2026-42449
GitHub-GHSA

HIGH
n8n's Credential Authorization Bypass in dynamic-node-parameters Allows Foreign API Key Replay
GHSA-r4v6-9fqc-w5jr
pkg: n8n, n8n
eco: npm
published: Apr 29, 2026
## Impact
The `dynamic-node-parameters` endpoints did not verify whether the authenticated caller was authorized to use a supplied credential reference. An authenticated user with access to a shared workflow could supply a foreign credential ID in the request body, causing the backend to decrypt and…
CVE-2026-42226
GitHub-GHSA

HIGH
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services
GHSA-wr32-99hh-6f35
pkg: github.com/0xJacky/Nginx-UI
eco: go
published: Apr 29, 2026
### Summary

An authenticated user can perform Server-Side Request Forgery (SSRF) by creating a cluster node pointing to an arbitrary internal URL and then sending API requests with the `X-Node-ID` header. The Proxy middleware forwards these requests to the attacker-specified internal address, bypas…

NVD

HIGH
CVE-2026-31712
CVE-2026-31712
pkg: linux

published: May 1, 2026

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: require minimum ACE size in smb_check_perm_dacl()

Both ACE-walk loops in smb_check_perm_dacl() only guard against an
under-sized remaining buffer, not against an ACE whose declared
`ace->size` is smaller than the struct it …

NVD

HIGH
CVE-2026-7353
CVE-2026-7353
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Heap buffer overflow in Skia in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-122
NVD

HIGH
CVE-2026-7352
CVE-2026-7352
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Use after free in Media in Google Chrome on Android prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-7350
CVE-2026-7350
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Use after free in WebMIDI in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-7345
CVE-2026-7345
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Insufficient validation of untrusted input in Feedback in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-20
GitHub-GHSA

HIGH
i18next-http-middleware has path traversal / SSRF via user-controlled language and namespace parameters
GHSA-jfgf-83c5-2c4m
pkg: i18next-http-middleware
eco: npm
published: Apr 29, 2026
### Summary

Versions of `i18next-http-middleware` prior to 3.9.3 pass the user-controlled `lng` and `ns` values from `getResourcesHandler` directly into `i18next.services.backendConnector.load(languages, namespaces, …)` without any sanitisation. Depending on which backend is configured, the unval…

CVE-2026-42353
GitHub-GHSA

HIGH
n8n Vulnerable to XSS via MCP OAuth client
GHSA-537j-gqpc-p7fq
pkg: n8n, n8n, n8n
eco: npm
published: Apr 29, 2026
## Impact
An unauthenticated attacker could register a malicious MCP OAuth client with a crafted `client_name`. If a victim user authorized the OAuth consent dialog and a second user subsequently revoked that access, a toast notification would render the injected script. Clicking the link would exec…
CVE-2026-42235
NVD

HIGH
CVE-2026-38651
CVE-2026-38651
pkg: jwt

published: Apr 28, 2026

Authentication Bypass vulnerability exists in Netmaker versions prior to 1.5.0. The VerifyHostToken function in logic/jwts.go fails to validate the JWT signature when verifying host tokens. An attacker can forge a JWT signed with any arbitrary key and use it to impersonate any host in the network, g…
CWE: CWE-347
NVD

HIGH
CVE-2026-40022
CVE-2026-40022
pkg: apache camel

published: Apr 27, 2026

When authentication is enabled on the Apache Camel embedded HTTP server or embedded management server (camel-platform-http-main) and a non-root context path such as /api or /admin is configured via camel.server.path or camel.management.path, the BasicAuthenticationConfigurer and JWTAuthenticationCon…
CWE: CWE-288
NVD

HIGH
CVE-2026-31708
CVE-2026-31708
pkg: linux

published: May 1, 2026

In the Linux kernel, the following vulnerability has been resolved:

smb: client: fix OOB read in smb2_ioctl_query_info QUERY_INFO path

smb2_ioctl_query_info() has two response-copy branches: PASSTHRU_FSCTL
and the default QUERY_INFO path. The QUERY_INFO branch clamps
qi.input_buffer_length to the…

GitHub-GHSA

HIGH
Contras Affected by CopyFile Policy Subversion via Symlinks
GHSA-rh99-wc69-c255
pkg: github.com/edgelesssys/contrast
eco: go
published: Apr 30, 2026
### Impact

The [Kata agent policies](https://docs.edgeless.systems/contrast/architecture/components/policies) generated by the Contrast CLI had an issue in the `CopyFile` verification, which allowed arbitrary writes to the guest root filesytem. A malicious process on the host with the capability to…

NVD

HIGH
CVE-2026-7347
CVE-2026-7347
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Use after free in Chromoting in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-7346
CVE-2026-7346
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Inappropriate implementation in Tint in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-119
NVD

HIGH
CVE-2026-42431
CVE-2026-42431
pkg: openclaw openclaw

published: Apr 28, 2026

OpenClaw before 2026.4.8 contains a security bypass vulnerability in node.invoke(browser.proxy) that allows mutation of persistent browser profiles. Attackers can exploit this path to circumvent the browser.request persistent profile-mutation guard and modify browser configurations.
CWE: CWE-863
NVD

HIGH
CVE-2026-43003
CVE-2026-43003
pkg: python

published: May 1, 2026

An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install from within a chroot of the deployed partition image, leading to code execution in the case of a malicious image.
CWE: CWE-829
NVD

HIGH
CVE-2026-43016
CVE-2026-43016
pkg: go

published: May 1, 2026

In the Linux kernel, the following vulnerability has been resolved:

bpf: sockmap: Fix use-after-free of sk->sk_socket in sk_psock_verdict_data_ready().

syzbot reported use-after-free of AF_UNIX socket's sk->sk_socket
in sk_psock_verdict_data_ready(). [0]

In unix_stream_sendmsg(), the peer socket'…

NVD

HIGH
CVE-2026-31716
CVE-2026-31716
pkg: linux

published: May 1, 2026

In the Linux kernel, the following vulnerability has been resolved:

fs/ntfs3: validate rec->used in journal-replay file record check

check_file_record() validates rec->total against the record size but
never validates rec->used. The do_action() journal-replay handlers read
rec->used from disk and…

NVD

HIGH
CVE-2026-31703
CVE-2026-31703
pkg: linux

published: May 1, 2026

In the Linux kernel, the following vulnerability has been resolved:

writeback: Fix use after free in inode_switch_wbs_work_fn()

inode_switch_wbs_work_fn() has a loop like:

wb_get(new_wb);
while (1) {
list = llist_del_all(&new_wb->switch_wbs_ctxs);
/* Nothing to do? */
if (!list)

NVD

HIGH
CVE-2026-31700
CVE-2026-31700
pkg: linux

published: May 1, 2026

In the Linux kernel, the following vulnerability has been resolved:

net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd()

In tpacket_snd(), when PACKET_VNET_HDR is enabled, vnet_hdr points
directly into the mmap'd TX ring buffer shared with userspace. The
kernel validates the header via …

NVD

HIGH
CVE-2026-31695
CVE-2026-31695
pkg: linux

published: May 1, 2026

In the Linux kernel, the following vulnerability has been resolved:

wifi: virt_wifi: remove SET_NETDEV_DEV to avoid use-after-free

Currently we execute `SET_NETDEV_DEV(dev, &priv->lowerdev->dev)` for
the virt_wifi net devices. However, unregistering a virt_wifi device in
netdev_run_todo() can happ…

NVD

HIGH
CVE-2026-31694
CVE-2026-31694
pkg: linux

published: May 1, 2026

In the Linux kernel, the following vulnerability has been resolved:

fuse: reject oversized dirents in page cache

fuse_add_dirent_to_cache() computes a serialized dirent size from the
server-controlled namelen field and copies the dirent into a single
page-cache page. The existing logic only checks…

NVD

HIGH
CVE-2026-7584
CVE-2026-7584
pkg: python

published: May 1, 2026

The LabOne Q serialization framework uses a class-loading mechanism (import_cls) to dynamically import and instantiate Python classes during deserialization. Prior to the fix, this mechanism accepted arbitrary fully-qualified class names from the serialized data without any validation of the target …
CWE: CWE-502
NVD

HIGH
CVE-2026-31693
CVE-2026-31693
pkg: linux

published: Apr 30, 2026

In the Linux kernel, the following vulnerability has been resolved:

cifs: some missing initializations on replay

In several places in the code, we have a label to signify
the start of the code where a request can be replayed if
necessary. However, some of these places were missing the
necessary re…

NVD

HIGH
CVE-2026-31786
CVE-2026-31786
pkg: linux

published: Apr 30, 2026

In the Linux kernel, the following vulnerability has been resolved:

Buffer overflow in drivers/xen/sys-hypervisor.c

The build id returned by HYPERVISOR_xen_version(XENVER_build_id) is
neither NUL terminated nor a string.

The first causes a buffer overflow as sprintf in buildid_show will
read and …

NVD

HIGH
CVE-2026-42432
CVE-2026-42432
pkg: openclaw openclaw

published: Apr 28, 2026

OpenClaw before 2026.4.8 contains a privilege escalation vulnerability allowing previously paired nodes to reconnect with exec-capable commands without operator.admin scope requirement. Attackers can bypass re-pairing authentication to execute privileged commands on the local assistant system.
CWE: CWE-863
NVD

HIGH
CVE-2026-43824
CVE-2026-43824
pkg: kubernetes

published: May 2, 2026

In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data.
CWE: CWE-212
NVD

HIGH
CVE-2026-37554
CVE-2026-37554
pkg: openssl

published: May 1, 2026

An issue was discovered in Vanetza V2X v26.02 allowing remote unauthorized attackers to cause a denial of service. The vulnerability exists in the GeoNetworking packet processing pipeline where OpenSSL exceptions from ECC point validation (invalid compressed point, point not on curve) are not proper…
CWE: CWE-248
NVD

HIGH
CVE-2026-31719
CVE-2026-31719
pkg: linux

published: May 1, 2026

In the Linux kernel, the following vulnerability has been resolved:

crypto: krb5enc – fix async decrypt skipping hash verification

krb5enc_dispatch_decrypt() sets req->base.complete as the skcipher
callback, which is the caller's own completion handler. When the
skcipher completes asynchronously, …

NVD

HIGH
CVE-2026-31711
CVE-2026-31711
pkg: linux

published: May 1, 2026

In the Linux kernel, the following vulnerability has been resolved:

smb: server: fix active_num_conn leak on transport allocation failure

Commit 77ffbcac4e56 ("smb: server: fix leak of active_num_conn in
ksmbd_tcp_new_connection()") addressed the kthread_run() failure
path. The earlier alloc_tran…

NVD

HIGH
CVE-2026-40595
CVE-2026-40595
pkg: go

published: Apr 30, 2026

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Chartbrew exposes public chart retrieval and export routes that only verify project-level public access and, for exports, a team-level export toggle. The r…
CWE: CWE-284
GitHub-GHSA

HIGH
pygeoapi 0.23.x: Path Traversal in STAC FileSystemProvider
GHSA-f6pr-83pg-ghh6
pkg: pygeoapi
eco: pip
published: Apr 29, 2026
### Impact
A raw string path concatenation vulnerability in pygeoapi's STAC FileSystemProvider plugin can allow for requests to STAC collection based collections to expose directories without authentication. The issue manifests when pygeoapi is deployed without a proxy or web front end that would n…
CVE-2026-42351
GitHub-GHSA

HIGH
Marked Vulnerable to OOM Denial of Service via Infinite Recursion in marked Tokenizer
GHSA-6v9c-7cg6-27q7
pkg: marked
eco: npm
published: Apr 29, 2026
### Summary
A critical Denial of Service (DoS) vulnerability exists in `marked@18.0.0`. By providing a specific 3-byte input sequence a tab, a vertical tab, and a newline (`\x09\x0b\n`)—an unauthenticated attacker can trigger an infinite recursion loop during parsing. This leads to unbounded memor…
CVE-2026-41680
GitHub-GHSA

HIGH
n8n has a Python Task Runner Sandbox Escape Vulnerability
GHSA-44v6-jhgm-p3m4
pkg: n8n, n8n, n8n
eco: npm
published: Apr 29, 2026
## Impact
An authenticated user with permission to create or modify workflows containing a Python Code Node could escape the sandbox and achieve arbitrary code execution on the task runner container.

– This issue only affects instances where the Python Task Runner is enabled.

## Patches
The issue …

CVE-2026-42234
GitHub-GHSA

HIGH
GoBGP has Remote Denial of Service (Panic) in UpdatePathAttrs4ByteAs via Malformed BGP UPDATE
GHSA-8rxh-r2p6-7f2q
pkg: github.com/osrg/gobgp/v4
eco: go
published: Apr 29, 2026
### Summary
A remote Denial of Service (DoS) vulnerability exists in GoBGP where a malformed BGP UPDATE message can trigger a runtime error: index out of range panic. This occurs during the processing of 4-byte AS attributes when the message structure causes an internal slice index shift that is not…
CVE-2026-41643
GitHub-GHSA

HIGH
GoBGP has Remote Denial of Service (Panic) via Malformed Well-known Path Attribute
GHSA-7235-89m6-f4px
pkg: github.com/osrg/gobgp/v4
eco: go
published: Apr 29, 2026
### Summary
A remote Denial of Service (DoS) vulnerability exists in GoBGP due to a nil pointer dereference. When a malformed BGP UPDATE message contains an unrecognized Path Attribute marked as "Well-known," the daemon fails to interrupt the message handling flow. This results in an illegal memory …
CVE-2026-41642
NVD

HIGH
CVE-2026-42520
CVE-2026-42520
pkg: node

published: Apr 29, 2026

Jenkins Credentials Binding Plugin 719.v80e905ef14eb_ and earlier does not sanitize file names for file and zip file credentials, allowing attackers able to provide credentials to a job to write files to arbitrary locations on the node filesystem, which can lead to remote code execution if Jenkins i…
CWE: CWE-22
NVD

HIGH
CVE-2026-7357
CVE-2026-7357
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Use after free in GPU in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-7349
CVE-2026-7349
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Use after free in Cast in Google Chrome prior to 147.0.7727.138 allowed an attacker on the local network segment to execute arbitrary code inside a sandbox via malicious network traffic. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-7343
CVE-2026-7343
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Use after free in Views in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-7338
CVE-2026-7338
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Use after free in Cast in Google Chrome prior to 147.0.7727.138 allowed an attacker on the local network segment to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: High)
CWE: CWE-416
GitHub-GHSA

HIGH
CoreDNS has TSIG authentication bypass on gRPC and QUIC transports
GHSA-vp29-5652-4fw9
pkg: github.com/coredns/coredns
eco: go
published: Apr 28, 2026
### Summary

The gRPC, QUIC, DoH, and DoH3 transports in CoreDNS incorrectly handle TSIG authentication.

For gRPC and QUIC, CoreDNS checks whether the TSIG key name exists in the config, but does not actually verify the TSIG HMAC. If the key name matches, `tsigStatus` remains nil and the tsig plugi…

CVE-2026-35579
GitHub-GHSA

HIGH
CoreDNS has TSIG authentication bypass on DoT, DoH, DoH3, DoQ, and gRPC
GHSA-qhmp-q7xh-99rh
pkg: github.com/coredns/coredns
eco: go
published: Apr 28, 2026
### Summary
CoreDNS' tsig plugin can be bypassed on non-plain-DNS transports because it trusts the transport writer's TsigStatus() instead of performing verification itself. In the attached PoC, plain DNS/TCP correctly rejects an invalid TSIG (NOTAUTH), while the same invalid-TSIG request is accepte…
CVE-2026-33190
GitHub-GHSA

HIGH
CoreDNS' transfer stanza selection uses lexicographic compare (subzone ACL bypass)
GHSA-h8mm-c463-wjq3
pkg: github.com/coredns/coredns
eco: go
published: Apr 28, 2026
### Summary
CoreDNS' transfer plugin can select the wrong ACL stanza when both a parent zone and a more-specific subzone are configured. A permissive parent-zone transfer rule can override a restrictive subzone rule (name-dependent), allowing an unauthorized client to perform AXFR/IXFR for the subzo…
CVE-2026-33489
GitHub-GHSA

HIGH
CoreDNS DoH GET oversized dns= query parameter causes pre-validation CPU and memory amplification
GHSA-63cw-r7xf-jmwr
pkg: github.com/coredns/coredns
eco: go
published: Apr 28, 2026
### Summary

CoreDNS's DNS-over-HTTPS (DoH) GET path accepts oversized `dns=` query values and performs substantial request parsing, query unescaping, base64 decoding, and message unpacking work before returning `400 Bad Request`.

A remote, unauthenticated attacker can repeatedly send oversized DoH…

CVE-2026-32936
GitHub-GHSA

HIGH
CoreDNS' DoQ worker pool does not bound stream backlog
GHSA-2wpx-qpw2-g5h5
pkg: github.com/coredns/coredns
eco: go
published: Apr 28, 2026
### Summary
CoreDNS' DNS-over-QUIC (DoQ) server can be driven into large goroutine and memory growth by a remote client that opens many QUIC streams and stalls after sending only 1 byte. Even with a small configured quic { worker_pool_size … }, CoreDNS still spawns a goroutine per accepted stream …
CVE-2026-32934
NVD

HIGH
CVE-2026-42423
CVE-2026-42423
pkg: openclaw openclaw

published: Apr 28, 2026

OpenClaw before 2026.4.8 contains an approval-timeout fallback mechanism that bypasses strictInlineEval explicit-approval requirements on gateway and node exec hosts. Attackers can exploit this timeout fallback to execute inline eval commands that should require explicit user approval, circumventing…
CWE: CWE-636
NVD

HIGH
CVE-2026-41405
CVE-2026-41405
pkg: openclaw openclaw

published: Apr 28, 2026

OpenClaw before 2026.3.31 parses MS Teams webhook request bodies before performing JWT validation, allowing unauthenticated attackers to trigger resource exhaustion. Remote attackers can send malicious Teams webhook payloads to exhaust server resources by bypassing authentication checks.
CWE: CWE-408
NVD

HIGH
CVE-2026-41636
CVE-2026-41636
pkg: apache thrift

published: Apr 28, 2026

Uncontrolled Recursion vulnerability in Apache Thrift Node.js bindings

This issue affects Apache Thrift: before 0.23.0.

Users are recommended to upgrade to version 0.23.0, which fixes the issue.

CWE: CWE-674
NVD

HIGH
CVE-2026-41602
CVE-2026-41602
pkg: apache thrift

published: Apr 28, 2026

Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation

This issue affects Apache Thrift: before 0.23.0.

Users are recommended to upgrade to version 0.23.0, which fixes the issue.

CWE: CWE-190
NVD

HIGH
CVE-2026-42800
CVE-2026-42800
pkg: linux

published: Apr 30, 2026

NULL pointer dereference vulnerability in ASR1903 in ASR Lapwing_Linux on Linux (ims_client modules) allows Pointer Manipulation.

This vulnerability is associated with program files sip/utils/src/sipuri.c.

CWE: CWE-476
NVD

HIGH
CVE-2026-7710
CVE-2026-7710
pkg: jwt

published: May 4, 2026

A security flaw has been discovered in YunaiV yudao-cloud up to 3.8.0. This affects the function doFilterInternal of the file JwtAuthenticationTokenFilter.java of the component Ruoyi-Vue-Pro. Performing a manipulation of the argument mock-token results in improper authentication. Remote exploitation…
CWE: CWE-287
NVD

HIGH
CVE-2026-7505
CVE-2026-7505
pkg: go

published: Apr 30, 2026

A flaw has been found in nextlevelbuilder GoClaw and GoClaw Lite up to 3.8.5. This affects an unknown function of the component RPC Handler. This manipulation causes improper authorization. The attack may be initiated remotely. The exploit has been published and may be used. Upgrading to version 3.9…
CWE: CWE-266, CWE-285
NVD

HIGH
CVE-2025-50328
CVE-2025-50328
pkg: windows

published: Apr 29, 2026

A vulnerability in B1 Free Archiver v1.5.86 allows files extracted from downloaded archives to bypass Windows Mark of the Web (MotW) protections. When an archive is downloaded from the internet and extracted using B1 Free Archiver, the software fails to propagate the 'Zone.Identifier' alternate data…
CWE: CWE-290
NVD

HIGH
CVE-2026-7146
CVE-2026-7146
pkg: axios

published: Apr 27, 2026

A security vulnerability has been detected in AlejandroArciniegas mcp-data-vis up to de5a51525a69822290eaee569a1ab447b490746d. Affected by this vulnerability is the function axios of the file src/servers/web-scraper/server.js of the component HTTP Request Handler. Such manipulation leads to server-s…
CWE: CWE-918
NVD

HIGH
CVE-2026-7461
CVE-2026-7461
pkg: windows

published: Apr 30, 2026

Improper neutralization of inputs used in an OS command in the FSx Windows File Server volume mounting component in Amazon ECS Agent on Windows before version 1.103.0 might allow a remote authenticated threat actor to execute shell commands with SYSTEM privileges on the underlying host via a special…
CWE: CWE-78
GitHub-GHSA

HIGH
appsmith has SQL Injection in FilterDataService via Unsafe DROP TABLE Execution
GHSA-h8cj-hpmg-636v
pkg: com.appsmith:interfaces
eco: maven
published: Apr 29, 2026
### Summary
A SQL injection vulnerability exists in `FilterDataServiceCE.java` where the `dropTable` method constructs a SQL `DROP TABLE` statement using string concatenation with the table name. If the table name is derived from user input, this allows for arbitrary SQL command execution.

### Deta…

NVD

HIGH
CVE-2026-7191
CVE-2026-7191
pkg: express

published: Apr 27, 2026

Improper use of the static-eval npm package in the open source solution qnabot-on-aws versions 7.2.4 and earlier may allow an authenticated administrator to execute arbitrary code within the fulfillment Lambda execution context by injecting a crafted conditional chaining expression via the Content D…
CWE: CWE-94
NVD

HIGH
CVE-2026-31707
CVE-2026-31707
pkg: linux

published: May 1, 2026

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: validate response sizes in ipc_validate_msg()

ipc_validate_msg() computes the expected message size for each
response type by adding (or multiplying) attacker-controlled fields
from the daemon response to a fixed struct siz…

NVD

HIGH
CVE-2026-31699
CVE-2026-31699
pkg: linux

published: May 1, 2026

In the Linux kernel, the following vulnerability has been resolved:

crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed

When retrieving the PEK CSR, don't attempt to copy the blob to userspace
if the firmware command failed. If the failure was due to an invalid
length, i.e. …

NVD

HIGH
CVE-2026-31698
CVE-2026-31698
pkg: linux

published: May 1, 2026

In the Linux kernel, the following vulnerability has been resolved:

crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed

When retrieving the PDH cert, don't attempt to copy the blobs to userspace
if the firmware command failed. If the failure was due to an invalid
length…

NVD

HIGH
CVE-2026-31697
CVE-2026-31697
pkg: linux

published: May 1, 2026

In the Linux kernel, the following vulnerability has been resolved:

crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed

When retrieving the ID for the CPU, don't attempt to copy the ID blob to
userspace if the firmware command failed. If the failure was due to an
invalid leng…

GitHub-GHSA

HIGH
Arcane Vulnerable to Unauthenticated Disclosure of Custom Compose Template Content (incl. `.env` secrets)
GHSA-cxx3-hr75-4q96
pkg: github.com/getarcaneapp/arcane/backend
eco: go
published: Apr 30, 2026
### Summary
Four `GET` endpoints under `/api/templates*` in Arcane's Huma backend are registered without any `Security` requirement, allowing any unauthenticated network client to list and read the full Compose YAML and `.env` content of every custom template stored in the instance. Because Arcane's…
CVE-2026-42461
GitHub-GHSA

HIGH
Clerk has an authorization bypass when combining organization, billing, or reverification checks
GHSA-w24r-5266-9c3c
pkg: @clerk/shared, @clerk/shared, @clerk/backend
eco: npm
published: Apr 30, 2026
### Summary

`has()`, `auth.protect()`, and related authorization predicates in `@clerk/shared`, `@clerk/nextjs`, `@clerk/backend`, and other framework SDKs can return true for certain combined authorization checks when the result should be false, allowing a gated action to proceed for a user who do…

CVE-2026-42349
GitHub-GHSA

HIGH
Hickory DNS's Record Cache Accepts AUTHORITY-Section NS from Sibling Zone via Parent-Pool Zone-Context Elevation
GHSA-83hf-93m4-rgwq
pkg: hickory-recursor, hickory-recursor
eco: rust
published: Apr 30, 2026
# Summary

The Hickory DNS project's experimental `hickory-recursor` crate's record cache (`DnsLru`) stores records from DNS responses keyed by each record's own (name, type), not by the query that triggered the response. `cache_response()` in `crates/recursor/src/lib.rs` chains `ANSWER`, `AUTHORITY…

GitHub-GHSA

HIGH
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
GHSA-rch3-82jr-f9w9
pkg: @jupyter-notebook/help-extension, notebook, jupyterlab
eco: npm
published: Apr 30, 2026
### Impact

A stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interacti…

CVE-2026-40171
GitHub-GHSA

HIGH
CKAN has Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`
GHSA-h7j7-3rx6-xvcg
pkg: ckan, ckan
eco: pip
published: Apr 29, 2026
### Impact

A vulnerability in `datastore_search_sql` allowed attackers to inject SQL in order to gain access to private resources and PostgreSQL system information.

### Patches
The issue has been patched in CKAN 2.10.10 and CKAN 2.11.5

### Workarounds
Disable the DataStore SQL search (`ckan.datas…

CVE-2026-42031
GitHub-GHSA

HIGH
n8n Vulnerable to Unauthenticated Denial of Service via MCP Client Registration
GHSA-49m9-pgww-9vq6
pkg: n8n, n8n, n8n
eco: npm
published: Apr 29, 2026
## Impact
The MCP OAuth client registration endpoint accepted unauthenticated requests and stored client data without adequate resource controls. An unauthenticated remote attacker could exhaust server memory resources by sending large registration payloads, rendering the n8n instance unavailable. T…
CVE-2026-42236
GitHub-GHSA

MEDIUM
n8n has SQL Injection in Snowflake and MySQL Nodes
GHSA-hp3c-vfpm-q4f7
pkg: n8n, n8n, n8n
eco: npm
published: Apr 29, 2026
## Impact
The fix for [GHSA-f3f2-mcxc-pwjx](https://github.com/advisories/GHSA-f3f2-mcxc-pwjx) did not cover the Snowflake node or the legacy MySQL v1 node. Both nodes construct SQL queries by directly interpolating user-controlled table names, column names, and update keys into query strings withou…
CVE-2026-42237
GitHub-GHSA

MEDIUM
n8n has Public API Variables IDOR that Allows Cross-Project Secret Disclosure
GHSA-756q-gq9h-fp22
pkg: n8n, n8n, n8n
eco: npm
published: Apr 29, 2026
## Impact
An authenticated user with a valid API key scoped to `variable:list` could read variables from projects they are not a member of by supplying an arbitrary `projectId` query parameter to the public API variables endpoint. The handler queried the variables repository directly without enforci…
CVE-2026-42227
GitHub-GHSA

MEDIUM
n8n has SQL Injection in SeaTable Node
GHSA-mp4j-h6gh-f6mp
pkg: n8n, n8n, n8n
eco: npm
published: Apr 29, 2026
## Impact
A flaw in the SeaTable node's `row:search` and `row:get` operations allowed user-controlled input to be concatenated directly into SQL query strings without escaping or parameterization. In workflows where external user input is passed via expressions into the SeaTable node's search or row…
CVE-2026-42229
NVD

MEDIUM
CVE-2026-7714
CVE-2026-7714
pkg: react

published: May 4, 2026

A flaw has been found in crocodilestick Calibre-Web-Automated up to 4.0.6. Affected by this issue is some unknown functionality of the file cps/cwa_functions.py of the component Admin Endpoint. This manipulation causes missing authentication. It is possible to initiate the attack remotely. The explo…
CWE: CWE-287, CWE-306
NVD

MEDIUM
CVE-2026-23863
CVE-2026-23863
pkg: windows

published: May 1, 2026

An attachment spoofing issue in WhatsApp for Windows prior to v2.3000.1032164386.258709 could have allowed maliciously formatted documents with embedded NUL bytes in the filename to be shown in the application as one type of file but run as an executable when opened. We have not seen evidence of exp…
CWE: CWE-158
NVD

MEDIUM
CVE-2026-1577
CVE-2026-1577
pkg: ibm db2

published: Apr 30, 2026

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic.
CWE: CWE-1284
NVD

MEDIUM
CVE-2025-36122
CVE-2025-36122
pkg: ibm db2

published: Apr 30, 2026

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of service using a specially crafted SQL query due to improper allocation of system resources.
CWE: CWE-770
NVD

MEDIUM
CVE-2026-35514
CVE-2026-35514
pkg: jwt

published: Apr 30, 2026

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, the endpoint POST /user/invited does not validate any invite token, authentication header, or session. Any unauthenticated attacker can call this endpoint …
CWE: CWE-306
GitHub-GHSA

MEDIUM
OpenTelemetry's disk retry default temp path enables local blob injection via OTLP Exporter
GHSA-4625-4j76-fww9
pkg: OpenTelemetry.Exporter.OpenTelemetryProtocol
eco: nuget
published: Apr 30, 2026
### Summary

The OTLP disk retry feature in `OpenTelemetry.Exporter.OpenTelemetryProtocol` silently fell back to `Path.GetTempPath()` when `OTEL_DOTNET_EXPERIMENTAL_OTLP_RETRY=disk` was set but `OTEL_DOTNET_EXPERIMENTAL_OTLP_DISK_RETRY_DIRECTORY_PATH` was not configured.

The exporter stored and loa…

CVE-2026-42191
GitHub-GHSA

MEDIUM
Fiber's cache middleware default key generator ignores query string, causing response mix-up across distinct query parameters
GHSA-35hp-hqmv-8qg8
pkg: github.com/gofiber/fiber/v3
eco: go
published: Apr 28, 2026
### Summary
Fiber cache middleware's default key generator uses only `c.Path()` and does not include the query string.
As a result, requests like `/?id=1` and `/?id=2` can map to the same cache key and share the same cached response.

This can cause response mix-up (cache poisoning-like behavior) fo…

CVE-2026-30246
NVD

MEDIUM
CVE-2026-41369
CVE-2026-41369
pkg: openclaw openclaw

published: Apr 28, 2026

OpenClaw before 2026.3.31 contains insufficient environment variable sanitization in host exec operations, failing to filter package, registry, Docker, compiler, and TLS override variables. Attackers can exploit this by injecting malicious environment variables to override critical system configurat…
CWE: CWE-668
NVD

MEDIUM
CVE-2026-41081
CVE-2026-41081
pkg: apache storm

published: Apr 27, 2026

Improper Handling of TLS Client Authentication Failure Leading to Anonymous Principal Assignment in Apache Storm

Versions Affected: up to 2.8.7

Description: When TLS transport is enabled in Apache Storm without requiring client certificate authentication (the default configuration), the TlsTranspo…

CWE: CWE-287
NVD

MEDIUM
CVE-2026-41174
CVE-2026-41174
pkg: traefik traefik

published: Apr 30, 2026

Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a potential vulnerability in Traefik's Kubernetes CRD provider cross-namespace isolation enforcement. When providers.kubernetesCRD.allowCrossNamespace=false, Traefik correctly rejects dire…
CWE: CWE-653, CWE-863
NVD

MEDIUM
CVE-2026-7716
CVE-2026-7716
pkg: windows

published: May 4, 2026

A vulnerability was found in code-projects Gym Management System In PHP and Windows NT 1.0. This vulnerability affects unknown code of the file /index.php. Performing a manipulation of the argument day results in sql injection. The attack can be initiated remotely. The exploit has been made public a…
CWE: CWE-74, CWE-89
NVD

MEDIUM
CVE-2026-7629
CVE-2026-7629
pkg: react

published: May 2, 2026

A flaw has been found in kleneway awesome-cursor-mpc-server up to 2.0.1. Impacted is the function runCodeReviewTool of the file src/tools/codeReview.ts of the component Ccode-Review Tool. Executing a manipulation can lead to command injection. The attack may be launched remotely. The exploit has bee…
CWE: CWE-74, CWE-77
NVD

MEDIUM
CVE-2026-7628
CVE-2026-7628
pkg: react

published: May 2, 2026

A vulnerability was detected in crazyrabbitLTC mcp-code-review-server up to 0.1.0. This issue affects the function executeRepomix of the file src/repomix.ts of the component RepoMix Command Handler. Performing a manipulation results in command injection. The attack may be initiated remotely. The exp…
CWE: CWE-74, CWE-77
NVD

MEDIUM
CVE-2026-7595
CVE-2026-7595
pkg: react

published: May 1, 2026

A flaw has been found in nextlevelbuilder ui-ux-pro-max-skill up to 2.5.0. Affected by this vulnerability is the function _format_plugins of the file .claude/skills/ui-styling/scripts/tailwind_config_gen.py of the component Tailwind Config Generator. This manipulation causes code injection. The atta…
CWE: CWE-74, CWE-94
NVD

MEDIUM
CVE-2026-7305
CVE-2026-7305
pkg: go

published: Apr 28, 2026

A weakness has been identified in Xuxueli xxl-job up to 3.3.2. The affected element is the function triggerJob of the file xxl-job-admin/src/main/java/com/xxl/job/admin/service/impl/XxlJobServiceImpl.java of the component trigger Endpoint. This manipulation of the argument addressList causes server-…
CWE: CWE-918
NVD

MEDIUM
CVE-2026-7163
CVE-2026-7163
pkg: jwt

published: Apr 30, 2026

A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multicluster Engine (MCE), allows an authenticated user with minimal namespace-scoped privileges to obtain administrative credentials for arbitrary clusters provisioned through the hu…
CWE: CWE-312
GitHub-GHSA

MEDIUM
CKAN has CSRF exemption primed by anonymous requests
GHSA-mcvf-jxcw-vj73
pkg: ckan, ckan
eco: pip
published: Apr 29, 2026
Views can be marked as exempt from CSRF protection

Access to the views via tokens or unauthenticated requests marked the endpoint as not requiring CSRF protection.

The marking was a member variable in flask-wtf.csrf.CSRFProtect(), which was stored as a module level variable in the flask_app midd…

CVE-2026-41255
NVD

MEDIUM
CVE-2026-41016
CVE-2026-41016
pkg: apache airflow

published: Apr 30, 2026

Apache Airflow's SMTP provider `SmtpHook` called Python's `smtplib.SMTP.starttls()` without an SSL context, so no certificate validation was performed on the TLS upgrade. A man-in-the-middle between the Airflow worker and the SMTP server could present a self-signed certificate, complete the STARTTLS…
CWE: CWE-295
GitHub-GHSA

MEDIUM
OpenTelemetry.Resources.Azure has an unbounded HTTP response body read
GHSA-vc24-j8c5-2vw4
pkg: OpenTelemetry.Resources.Azure
eco: nuget
published: Apr 29, 2026
### Summary

`OpenTelemetry.Resources.Azure` reads unbounded HTTP response bodies from the Azure VM remote instance metadata service endpoint into memory.

This would allow an attacker-controlled endpoint or one acting as a Man-in-the-Middle (MitM) to cause excessive memory allocation and possible p…

CVE-2026-41483
NVD

MEDIUM
CVE-2026-7669
CVE-2026-7669
pkg: python

published: May 2, 2026

A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation of the argument trust_remote_code with the input False as part of Boo…
CWE: CWE-74, CWE-94
NVD

MEDIUM
CVE-2026-7292
CVE-2026-7292
pkg: node

published: Apr 28, 2026

A security vulnerability has been detected in o2oa up to 10.0. This impacts the function syncFile of the file NodeAgent.java of the component NodeAgent. The manipulation leads to improper authorization. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitabil…
CWE: CWE-266, CWE-285
NVD

MEDIUM
CVE-2026-7113
CVE-2026-7113
pkg: react

published: Apr 27, 2026

A vulnerability was found in NousResearch hermes-agent 0.8.0. Affected by this issue is some unknown functionality of the file gateway/platforms/webhook.py of the component Webhooks Endpoint. The manipulation of the argument _INSECURE_NO_AUTH results in missing authentication. The attack can be laun…
CWE: CWE-287, CWE-306
NVD

MEDIUM
CVE-2026-7112
CVE-2026-7112
pkg: react

published: Apr 27, 2026

A vulnerability has been found in NousResearch hermes-agent 0.8.0. Affected by this vulnerability is the function _check_auth of the file gateway/platforms/api_server.py of the component API_SERVER_KEY Handler. The manipulation leads to improper authentication. The attack can be initiated remotely. …
CWE: CWE-287
NVD

MEDIUM
CVE-2026-6528
CVE-2026-6528
pkg: wireshark wireshark

published: Apr 30, 2026

TLS protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 allows denial of service
CWE: CWE-835
NVD

MEDIUM
CVE-2026-6446
CVE-2026-6446
pkg: oauth

published: May 2, 2026

The My Social Feeds – Social Feeds Embedder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to and including 1.0.4 via the 'ttp_get_accounts' AJAX action. This is due to the complete absence of authorization checks (no capability verification) and nonce veri…
CWE: CWE-522
GitHub-GHSA

MEDIUM
n8n Vulnerable to Hijacking of Unauthenticated Chat Execution
GHSA-f77h-j2v7-g6mw
pkg: n8n, n8n, n8n
eco: npm
published: Apr 29, 2026
## Impact
The `/chat` WebSocket endpoint used by the Chat Trigger node's Hosted Chat feature did not verify that an incoming connection was authorized to interact with the target execution. An unauthenticated remote attacker who could identify a valid execution ID for a workflow in a waiting state c…
CVE-2026-42228
NVD

MEDIUM
CVE-2026-37504
CVE-2026-37504
pkg: node

published: May 1, 2026

Sensitive server_token exposed via GET parameter in V2Board thru 1.7.4. In app/Http/Controllers/Server/UniProxyController.php, the server authentication token is accepted via GET parameter transmission. The token appears in URLs such as /api/v1/server/UniProxy/user?token=SECRET, causing it to be rec…
CWE: CWE-598
NVD

MEDIUM
CVE-2025-14688
CVE-2025-14688
pkg: ibm db2

published: Apr 30, 2026

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic when certain configurations exist.
CWE: CWE-1284
GitHub-GHSA

MEDIUM
OneCollector exporter reads unbounded HTTP response bodies
GHSA-55m9-299j-53c7
pkg: OpenTelemetry.Exporter.OneCollector
eco: nuget
published: Apr 29, 2026
### Summary

When exporting telemetry to a back-end/collector over HTTP using the OpenTelemetry.Exporter.OneCollector exporter, if the request results in a unsuccessful request (i.e. HTTP 4xx or 5xx), the response is read into memory with no upper-bound on the number of bytes consumed.

This could c…

CVE-2026-41484
NVD

MEDIUM
CVE-2026-22745
CVE-2026-22745
pkg: windows

published: Apr 29, 2026

Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources.

More precisely, an application can be vulnerable when all the following are true:

* the application is using Spring MVC or Spring WebFlux
* the application is serving static reso…

CWE: CWE-400
GitHub-GHSA

MEDIUM
OpenTelemetry's Zipkin remote endpoint cache could grow without bounds and increase memory pressure
GHSA-88hf-wf7h-7w4m
pkg: OpenTelemetry.Exporter.Zipkin
eco: nuget
published: Apr 28, 2026
### Summary

The Zipkin exporter remote endpoint cache accepted unbounded key growth derived from span attributes. In high-cardinality scenarios, this could increase process memory usage over time and degrade availability.

### Details

– Introduce a bounded, thread-safe LRU cache for remote endpoin…

CVE-2026-41310
NVD

MEDIUM
CVE-2026-41391
CVE-2026-41391
pkg: openclaw openclaw

published: Apr 28, 2026

OpenClaw before 2026.3.31 fails to properly sanitize PIP_INDEX_URL and UV_INDEX_URL environment variables in host execution contexts, allowing attackers to redirect Python package-index traffic. Attackers can exploit this bypass to intercept or manipulate package management operations by injecting m…
CWE: CWE-184
NVD

MEDIUM
CVE-2026-22726
CVE-2026-22726
pkg: go

published: May 1, 2026

Route Services can be leveraged to send app traffic to network destinations outside of an app's configured egress rules. As a result, a malicious developer with access to Cloudfoundry could configure a route-service that would allow it to send requests to HTTP services on internal networks reachable…
CWE: CWE-923
NVD

MEDIUM
CVE-2026-40974
CVE-2026-40974
pkg: ssl

published: Apr 28, 2026

Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to Cassandra.

Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); Ca…

CWE: CWE-295
NVD

MEDIUM
CVE-2026-40971
CVE-2026-40971
pkg: ssl

published: Apr 27, 2026

When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification when connecting to the RabbitMQ broker.

Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14) per vendor advisory.

CWE: CWE-295
NVD

MEDIUM
CVE-2026-40970
CVE-2026-40970
pkg: ssl

published: Apr 27, 2026

When configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perform hostname verification when connecting to the Elasticsearch server.

Affected: Spring Boot 4.0.0–4.0.5; upgrade to 4.0.6 or later per vendor advisory.

CWE: CWE-295
NVD

MEDIUM
CVE-2026-1858
CVE-2026-1858
pkg: tls

published: Apr 29, 2026

wget2 accepts a server certificate with incorrect Key Usage (KU) or Extended Key Usage (EKU). If the attackers compromise a certificate (with the associated private key) issued for a different purpose, they may be able to reuse it for TLS server authentication.
CWE: CWE-20
NVD

MEDIUM
CVE-2025-10539
CVE-2025-10539
pkg: tls

published: Apr 28, 2026

Due to improper TLS certificate validation in the DeskTime Time Tracking App before version 1.3.674, attackers who can position themselves in the network path between the client and the DeskTime update servers can return a malicious executable in response to an update request. This allows the attack…
CWE: CWE-295, CWE-296, CWE-494
NVD

MEDIUM
CVE-2026-40557
CVE-2026-40557
pkg: ssl

published: Apr 27, 2026

Improper Certificate Validation via Global SSL Context Downgrade in Apache Storm Prometheus Reporter

Versions Affected: from 2.6.3 to 2.8.6

Description: 

In production deployments where an administrator enables storm.daemon.metrics.reporter.plugin.prometheus.skip_tls_validation (by default it…

CWE: CWE-295
GitHub-GHSA

MEDIUM
n8n has Open Redirect in MCP OAuth Consent Flow
GHSA-f6x8-65q6-j9m9
pkg: n8n, n8n, n8n
eco: npm
published: Apr 29, 2026
## Impact
The `/mcp-oauth/register` endpoint accepted OAuth client registrations without authentication, allowing arbitrary `redirect_uri` values to be registered. When a user denies the MCP OAuth consent dialog, the `handleDeny` handler redirects the user to the registered `redirect_uri` without va…
CVE-2026-42230
NVD

MEDIUM
CVE-2026-7596
CVE-2026-7596
pkg: react

published: May 1, 2026

A vulnerability has been found in nextlevelbuilder ui-ux-pro-max-skill up to 2.5.0. Affected by this issue is the function data.get of the file .claude/skills/design-system/scripts/generate-slide.py of the component Slide Generator. Such manipulation leads to cross site scripting. The attack may be …
CWE: CWE-79, CWE-94
NVD

MEDIUM
CVE-2026-7340
CVE-2026-7340
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Integer overflow in ANGLE in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-472
GitHub-GHSA

MEDIUM
Weblate Doesn't Invalidate API Token on Password Change
GHSA-6j8j-4qp3-36p2
pkg: weblate
eco: pip
published: Apr 30, 2026
### Impact
When a user changes their password, browser sessions are correctly invalidated via `cycle_session_keys()`, but DRF API tokens (`wlu_*` prefix) stored in `authtoken_token` are not revoked.

### Patches
* https://github.com/WeblateOrg/weblate/pull/19057

### Resources
Weblate thanks Sang Yu…

CVE-2026-41519
GitHub-GHSA

MEDIUM
CKAN has Unauthenticated Authorization Bypass in `datastore_search_sql`
GHSA-cg4x-64p3-x59h
pkg: ckan, ckan
eco: pip
published: Apr 30, 2026
### Impact

A vulnerability in `datastore_search_sql` allowed attackers to bypass authorization in order to gain access to private resources and PostgreSQL system information

### Patches
The issue has been patched in CKAN 2.10.10 and CKAN 2.11.5

### Workarounds
Disable the DataStore SQL search (`c…

CVE-2026-42032
GitHub-GHSA

MEDIUM
Weblate Vulnerable to Authenticated SSRF via Project Backup Import bypassing validate_repo_url
GHSA-cwcx-382v-8m9g
pkg: weblate
eco: pip
published: Apr 30, 2026
### Impact
An authenticated user with `project.add` permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose `components/<name>.json` contains an attacker-chosen `repo` URL pointing at a **private address** (e.g. …
CVE-2026-41654
GitHub-GHSA

MEDIUM
Claude SDK for TypeScript has Insecure Default File Permissions in Local Filesystem Memory Tool
GHSA-p7fg-763f-g4gf
pkg: @anthropic-ai/sdk
eco: npm
published: Apr 29, 2026
The `BetaLocalFilesystemMemoryTool` in the Anthropic TypeScript SDK created memory files and directories using the Node.js default modes (`0o666` for files, `0o777` for directories), leaving them world-readable on systems with a standard umask and world-writable in environments with a permissive uma…
CVE-2026-41686
GitHub-GHSA

MEDIUM
netfoil's optional seccomp sandboxing was not applied
GHSA-vjgj-42f6-7997
pkg: github.com/tinfoil-factory/netfoil
eco: go
published: Apr 29, 2026
### Summary
The optional flag `–filter-system-calls` was not applied even if specified.

### Details
This is a defense in depth feature to apply additional seccomp filters after the binary has started. The example config also sandboxes the binary with systemd.

### Impact
Reduced sandboxing of the …

GitHub-GHSA

MEDIUM
Netfoil has incorrect allowlist enforcement
GHSA-84g5-x8j3-7235
pkg: github.com/tinfoil-factory/netfoil
eco: go
published: Apr 29, 2026
### Summary
Rules could be bypassed by changing the first character: `example.com` could be be bypassed by e.g. `fxample.com`.

### Details
Off-by-one error in the suffixtrie implementation.

### Impact
The domain filter could be bypassed. Please note that DNS filtering alone is not enough to block …

GitHub-GHSA

MEDIUM
OpenClaw: Webchat audio embedding could read local files without local-root containment
GHSA-gfg9-5357-hv4c
pkg: openclaw
eco: npm
published: Apr 29, 2026
## Impact

OpenClaw deployments before `2026.4.15` could embed host-local audio files into webchat responses without applying the local media root containment check used by other media-serving paths.

If an attacker could influence an agent or tool-produced `ReplyPayload.mediaUrl`, the webchat audio…

GitHub-GHSA

MEDIUM
OpenClaw: Owner-enforced commands could accept wildcard channel senders as command owners
GHSA-c28g-vh7m-fm7v
pkg: openclaw
eco: npm
published: Apr 29, 2026
## Impact

OpenClaw deployments before `2026.4.21` could treat a non-owner sender as authorized for owner-enforced slash commands when all of the following were true:

– a channel plugin declared `commands.enforceOwnerForCommands: true`;
– the channel accepted wildcard inbound senders with `allowFro…

GitHub-GHSA

MEDIUM
n8n has SQL Injection in Oracle Database Node via Limit Field
GHSA-r6jc-mpqw-m755
pkg: n8n, n8n, n8n
eco: npm
published: Apr 29, 2026
## Impact
A flaw in the Oracle Database node's select operation allowed user-controlled input passed into the `Limit` field via expressions to be interpolated directly into the SQL query without sanitization or parameterization. In workflows where external input is passed into the `Limit` field (e.g…
CVE-2026-42233
GitHub-GHSA

MEDIUM
CKAN has no certificate validation on STMP connection
GHSA-mpfm-fpgx-647q
pkg: ckan, ckan
eco: pip
published: Apr 29, 2026
### Impact
Configured SMTP server may be spoofed with any certificate (e.g. self-signed), leaving credentials and all emails sent open to MITM attacks.

### Patches
The vulnerability has been patched in CKAN 2.10.10 and CKAN 2.11.5

CVE-2026-41132
GitHub-GHSA

MEDIUM
beets has a Cross-site Scripting vulnerability
GHSA-3gxm-wfjx-m847
pkg: beets
eco: pip
published: Apr 29, 2026
During code logic analyis, an area that may lead to unintended behavior under specific conditions was discovered.

## Overview
– Verified Version: `80cd21554124da07d17a4f962c7d770a4f70d0f2`
– Vulnerability Type: Stored XSS
– Affected Location: `beetsplug/web/templates/index.html:42`
– Trigger Scena…

CVE-2026-42052