Vulnerability Digest — July 27, 2026 · 76 Critical · 6 Exploited






Vulnerability Digest — Monday, July 27, 2026


Security Report

Monday, July 27, 2026  ·  Last 7 days  ·  Min severity: MEDIUM
Total Findings
534
Critical
76
High
242
Actively Exploited
6
CISA-KEV6
NVD187
GitHub-GHSA341
Findings sorted by severity
CISA-KEV

CRITICAL
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
CVE-2026-50522
pkg: Microsoft SharePoint

published: Jul 22, 2026

Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Check Point SmartConsole Improper Authentication Vulnerability
CVE-2026-16232
pkg: Check Point SmartConsole

published: Jul 22, 2026

Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
WordPress Core SQL Injection Vulnerability
CVE-2026-60137
pkg: WordPress Core

published: Jul 21, 2026

WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
WordPress Core Interpretation Conflict Vulnerability
CVE-2026-63030
pkg: WordPress Core

published: Jul 21, 2026

WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
CVE-2026-0770
pkg: Langflow Langflow

published: Jul 21, 2026

Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
DD-WRT Stack-Based Buffer Overflow Vulnerability
CVE-2021-27137
pkg: DD-WRT DD-WRT

published: Jul 21, 2026

DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
NVD

CRITICAL
CVE-2026-66012
CVE-2026-66012
pkg: jwt

published: Jul 25, 2026

SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This exposes 31 MCP tools, including a file tool with list/read/write/delete/rename/copy ac…
CWE: CWE-862
GitHub-GHSA

CRITICAL
Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer
GHSA-w28w-gp39-m4p6
pkg: @prompty/core, @prompty/core
eco: npm
published: Jul 24, 2026
## Summary
The TypeScript Nunjucks renderer evaluated untrusted `.prompty` template bodies with unrestricted JavaScript member access. An attacker-controlled template could traverse constructor and prototype properties to execute JavaScript in the host Node.js process.

## Affected packages
– npm `@…

NVD

CRITICAL
CVE-2026-56163
CVE-2026-56163
pkg: kubernetes

published: Jul 24, 2026

Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
CWE: CWE-306
NVD

CRITICAL
CVE-2025-71389
CVE-2025-71389
pkg: react

published: Jul 23, 2026

Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) request handling deserializes attacker-controlled input. A remote attacker can send a crafted RSC request to the server and cause a…
CWE: CWE-94
NVD

CRITICAL
CVE-2026-47668
CVE-2026-47668
pkg: node

published: Jul 23, 2026

DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection in the `functionName` parameter of JSON script `assign` commands. The `functionName` value is interpolated directly into dynamic…
CWE: CWE-20, CWE-94, CWE-1188
NVD

CRITICAL
CVE-2026-46412
CVE-2026-46412
pkg: oauth

published: Jul 20, 2026

@beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support. Between 2026-05-11 20:19 UTC and 22:56 UTC, an attacker used a compromised npm publish token to publish 18 malicious versions of `@beproduct/nestjs-auth` (0.1.2 through 0.1.19). …
CWE: CWE-506
GitHub-GHSA

CRITICAL
@better-auth/scim: account takeover and stale access via SCIM provider-id collision
GHSA-rjg6-39jm-rgg4
pkg: @better-auth/scim, @better-auth/scim
eco: npm
published: Jul 24, 2026
### Am I affected?

You are affected if your application registers the `@better-auth/scim` plugin and lets authenticated users generate SCIM tokens. The default `canGenerateToken` policy was affected, and custom policies were affected when they did not reject provider IDs already used by other accou…

NVD

CRITICAL
CVE-2026-63732
CVE-2026-63732
pkg: node

published: Jul 23, 2026

9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default password (123456) that authenticates any fresh installation, a bypass of the LOCAL_ONLY network gate via a spoofed Host header, and unvalidated arguments passed to child_process.spawn() when registering MCP plu…
CWE: CWE-78
NVD

CRITICAL
CVE-2026-47752
CVE-2026-47752
pkg: docker

published: Jul 23, 2026

Tugtainer is a self-hosted app for automating updates of Docker containers. Versions prior to 1.30.2 are vulnerable to Server-Side Template Injection (SSTI) in the notification template feature. The `title_template` and `body_template` fields are rendered using an unsandboxed `jinja2.Environment`, a…
CWE: CWE-1336
NVD

CRITICAL
CVE-2026-60402
CVE-2026-60402
pkg: kubernetes

published: Jul 21, 2026

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTe…
CWE: CWE-284
NVD

CRITICAL
CVE-2026-47392
CVE-2026-47392
pkg: python

published: Jul 21, 2026

PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praisonaiagents, `execute_code()` in `praisonaiagents/tools/python_tools.py` (v1.6.37, subprocess sandbox mode) can be fully bypassed using `print.__self__` to retrieve the real Python `…
CWE: CWE-184, CWE-693
NVD

CRITICAL
CVE-2026-64459
CVE-2026-64459
pkg: node

published: Jul 25, 2026

In the Linux kernel, the following vulnerability has been resolved:

tcp: restore RCU grace period in tcp_ao_destroy_sock

Commit 51e547e8c89c ("tcp: Free TCP-AO/TCP-MD5 info/keys without RCU")
removed the call_rcu() callback from tcp_ao_destroy_sock(), arguing that
"the destruction of info/keys is …

GitHub-GHSA

CRITICAL
OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback
GHSA-wg5r-wc3x-39vc
pkg: org.openidentityplatform.openam:openam-core
eco: maven
published: Jul 24, 2026
## Summary
A pre-authentication remote code execution vulnerability affects OpenAM. The
remote authentication endpoint (`/authservice`, PLL) accepts an XML element
that names an arbitrary Java class, which the server then loads and
instantiates without validation. On a default configuration this is …
CVE-2026-62379
GitHub-GHSA

CRITICAL
Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix)
GHSA-7gfh-x38p-prh3
pkg: velocityjs
eco: npm
published: Jul 24, 2026
### Summary

Remote Code Execution (RCE) in velocityjs v2.1.6 via property-read to the Function constructor. This bypasses the fix for GHSA-j658-c2gf-x6pq ("Prototype Pollution in #set path assignment") — that advisory blocked constructor/__proto__/prototype only in the #set assignment handler (se…

NVD

CRITICAL
CVE-2026-64232
CVE-2026-64232
pkg: linux

published: Jul 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

block: recompute nr_integrity_segments in blk_insert_cloned_request

blk_insert_cloned_request() already recomputes nr_phys_segments
against the bottom queue, because "the queue settings related to
segment counting may differ from …

NVD

CRITICAL
CVE-2026-64216
CVE-2026-64216
pkg: linux

published: Jul 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

netfs: Fix potential UAF in netfs_unlock_abandoned_read_pages()

netfs_unlock_abandoned_read_pages(rreq) accesses the index of the folios it
is wanting to unlock and compares that to rreq->no_unlock_folio so that it
doesn't unlock …

GitHub-GHSA

CRITICAL
seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization
GHSA-mv8w-475r-vwqw
pkg: seroval
eco: npm
published: Jul 24, 2026
## Summary

A type confusion issue in `seroval.fromJSON()` allowed attacker-controlled JSON input to cause Promise control nodes to operate on values from the general deserialization reference table without first verifying that those values were genuine internal promise resolver records.

In applica…

CVE-2026-59940
NVD

CRITICAL
CVE-2026-15981
CVE-2026-15981
pkg: openssl

published: Jul 23, 2026

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.4. This is due to the mo_saml_validate_signature() function performing a loose boolean check on the raw tri-state integer returned by PHP's openssl_verify(), ca…
CWE: CWE-287
NVD

CRITICAL
CVE-2026-15015
CVE-2026-15015
pkg: oauth

published: Jul 23, 2026

The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to…
CWE: CWE-862
NVD

CRITICAL
CVE-2026-14282
CVE-2026-14282
pkg: go

published: Jul 23, 2026

The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 1.12.2. This is due to insufficient file type validation in the save_video_file() function hoo…
CWE: CWE-434
NVD

CRITICAL
CVE-2026-16606
CVE-2026-16606
pkg: linux

published: Jul 22, 2026

A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for unauthenticated remote code execution (pre-auth RCE) on GNU/Linux or Oracle Solaris. The Fsas Technologies PSIRT obtained that intelligence internally and covers the CVE b…
CWE: CWE-94
GitHub-GHSA

CRITICAL
Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER`
GHSA-f75j-4cw6-rmx4
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
# Summary

The Gitea Docker images ship an `app.ini` template that hard-codes:

“`
REVERSE_PROXY_TRUSTED_PROXIES = *
“`

The documented default for this setting, in `custom/conf/app.example.ini`, is `127.0.0.0/8,::1/128`, i.e. only loopback is trusted.

When an admin enables `ENABLE_REVERSE_PROXY_…

CVE-2026-20896
NVD

CRITICAL
CVE-2026-59147
CVE-2026-59147
pkg: node

published: Jul 21, 2026

Data::DisjointSet::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via an unvalidated parent index in dsu_find.

The attach-time validator dsu_validate_header checks the header scalars and region layout against the file size, but does not validate the array contents it then…

CWE: CWE-125, CWE-787
NVD

CRITICAL
CVE-2026-47410
CVE-2026-47410
pkg: jwt

published: Jul 21, 2026

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an insecure default cryptographic key. The JWT signing secret defaults to the hardcoded literal `"dev-secret-change-me"` when `PLATFORM_JWT_SECRET` is unset. A safety check exists but on…
CWE: CWE-321, CWE-798
NVD

CRITICAL
CVE-2026-47391
CVE-2026-47391
pkg: python

published: Jul 21, 2026

PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's first-party A2A server example exposes an unauthenticated A2A JSON-RPC endpoint and registers a `calculate(expression)` tool implemented with Python `eval()`. The example also binds to `0.0.0.0`. A remote unauthenticated a…
CWE: CWE-95, CWE-306
GitHub-GHSA

CRITICAL
OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check
GHSA-p279-2cqp-84jg
pkg: org.openidentityplatform.opendj:opendj-server-legacy
eco: maven
published: Jul 24, 2026
### Summary
When a SASL PLAIN bind supplies an authorization identity (authzid) that resolves to a **different** user, PlainSASLMechanismHandler verified only the PROXIED_AUTH privilege and never evaluated the "proxy" access-control right (the mayProxy ACI scope check). As a result, any account hold…
GitHub-GHSA

CRITICAL
Budibase: SQL Injection via `multipleStatements: true`
GHSA-q6x4-v3qx-85qw
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
## Summary
A critical SQL injection vulnerability was discovered in Budibase's MySQL integration that allows remote attackers to execute arbitrary SQL commands.

## Details
### Vulnerability Type
SQL Injection

### Description
The MySQL integration component in Budibase is configured with `multipleS…

NVD

CRITICAL
CVE-2026-65606
CVE-2026-65606
pkg: node

published: Jul 23, 2026

SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler. When a siyuan://plugins/<name> link references a name that is not an installed plugin, the application opens a custom tab and inserts the link's icon parameter into the tab header via innerHTML with…
CWE: CWE-79
NVD

CRITICAL
CVE-2026-65605
CVE-2026-65605
pkg: node

published: Jul 23, 2026

SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell rendering. A Template column value is rendered as HTML via text/template without auto-escaping, and EscapeHTML is only applied when HasUnclosedHtmlTag returns true; because balanced self-closi…
CWE: CWE-79
NVD

CRITICAL
CVE-2026-16424
CVE-2026-16424
pkg: google chrome, google android

published: Jul 21, 2026

Use after free in GPU in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

CRITICAL
CVE-2026-16419
CVE-2026-16419
pkg: google chrome, google android

published: Jul 21, 2026

Out of bounds read and write in ANGLE in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-125, CWE-787
GitHub-GHSA

CRITICAL
Gitea: Public-only repository tokens can update private PR head branches
GHSA-xxjv-752h-3vp2
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary
Gitea allows a `public-only,write:repository` token to update a private pull request head branch through a public base repository route.

The vulnerable endpoint is:

“`text
POST /api/v1/repos/{public-owner}/{public-repo}/pulls/{index}/update
“`

Gitea checks the token's public-only re…

CVE-2026-58443
GitHub-GHSA

CRITICAL
Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write
GHSA-hg5r-vq93-9fv6
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary

Gitea Actions Artifacts V4 signed upload/download URLs can be rewritten to access a different running task and repository context while preserving the original HMAC signature. An attacker with permission to run a Gitea Actions job can turn a signed URL for an attacker-controlled artifac…

CVE-2026-58426
GitHub-GHSA

CRITICAL
Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter
GHSA-2r5c-gw76-rh3w
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
## Summary

Gitea's default SSRF allow-list ([`MatchBuiltinExternal`](https://github.com/go-gitea/gitea/blob/4c37f4dacbac022f7beca75272439331f0368830/modules/hostmatcher/hostmatcher.go#L26-L27), used by both webhook delivery and repository migrations) relies on Go's standard library [`net.IP.IsPriva…

CVE-2026-22874
NVD

CRITICAL
CVE-2026-15901
CVE-2026-15901
pkg: google chrome

published: Jul 20, 2026

Use after free in Network in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

CRITICAL
CVE-2026-15900
CVE-2026-15900
pkg: google chrome, google android

published: Jul 20, 2026

Use after free in GPU in Google Chrome on Android prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

CRITICAL
CVE-2026-15899
CVE-2026-15899
pkg: go

published: Jul 20, 2026

Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
GitHub-GHSA

CRITICAL
OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway
GHSA-68r5-9hpg-7qw9
pkg: org.openidentityplatform.opendj:opendj-dsml-servlet
eco: maven
published: Jul 24, 2026
The DSMLv2 SOAP gateway (opendj-dsml-servlet) in OpenIdentityPlatform OpenDJ through 5.1.1 dereferences attacker-supplied xsd:anyURI values server-side without a scheme allowlist, egress filtering, or a size cap, and is reachable without authentication by default. A remote unauthenticated attacker c…
GitHub-GHSA

CRITICAL
LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests
GHSA-6x6h-qqr7-855w
pkg: lightrag-hku
eco: pip
published: Jul 20, 2026
### Summary
The server defaults to CORS_ORIGINS=* combined with allow_credentials=True. Starlette's CORSMiddleware echoes the requesting origin in preflight responses when credentials are enabled, meaning every origin is effectively whitelisted for credentialed cross-origin requests. Any malicious w…
CVE-2026-61736
GitHub-GHSA

CRITICAL
sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock
GHSA-vh45-f885-3848
pkg: sm-crypto
eco: npm
published: Jul 24, 2026
## Summary

`sm-crypto` (npm package **0.4.0**, the latest release, published 2026-01-20)
generates SM2 private keys and signing ephemeral scalars from a single
module-wide RNG instance (`src/sm2/utils.js`: `const rng = new SecureRandom()`).
`SecureRandom` is jsbn's PRNG, which seeds an **ARC4** str…

NVD

CRITICAL
CVE-2026-48021
CVE-2026-48021
pkg: tls

published: Jul 24, 2026

In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU handshake with attacker-controlled keys and obtain the session encryption keys. All inner HTTP traffic (patient consent decisions, medication data, docum…
CWE: CWE-295, CWE-347
GitHub-GHSA

CRITICAL
kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default
GHSA-r277-6w6q-xmqw
pkg: github.com/getkin/kin-openapi
eco: go
published: Jul 24, 2026
### Summary
`ValidationHandler.Load()` in `getkin/kin-openapi` silently replaces a nil `AuthenticationFunc` with `NoopAuthenticationFunc`, which always returns `nil` without performing any credential check. Because this substitution happens unconditionally when the caller omits the field, every Open…
NVD

CRITICAL
CVE-2026-60267
CVE-2026-60267
pkg: tls

published: Jul 21, 2026

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle…
CWE: CWE-284
NVD

CRITICAL
CVE-2026-47731
CVE-2026-47731
pkg: python

published: Jul 21, 2026

The AMMOS Instrument Toolkit (Formerly the Bespoke Links to Instruments for Surface and Space (BLISS)) is a Python-based software suite developed to handle Ground Data System (GDS), Electronic Ground Support Equipment (EGSE), commanding, telemetry uplink/downlink, and sequencing for instrument and C…
CWE: CWE-22
NVD

CRITICAL
CVE-2026-59141
CVE-2026-59141
pkg: node

published: Jul 21, 2026

Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated node and arena indices in rdx_find_locked.

The attach-time validator rdx_validate_header checks the header scalars and region layout against the file size, but does not validate the node records it the…

CWE: CWE-125
NVD

CRITICAL
CVE-2026-59140
CVE-2026-59140
pkg: node

published: Jul 21, 2026

Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds read via unvalidated node indices in the rank and min/max query paths.

The attach-time validator ss_validate_header bounds only the root index against the node pool (node_capacity). The order-statistics and min/max queries…

CWE: CWE-125
NVD

CRITICAL
CVE-2026-28321
CVE-2026-28321
pkg: solarwinds serv-u

published: Jul 21, 2026

SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate privileges and execute code as root. A domain administrator access is required, and the impact is lower in Windows installations.
CWE: CWE-284
NVD

CRITICAL
CVE-2026-28317
CVE-2026-28317
pkg: solarwinds serv-u

published: Jul 21, 2026

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires domain administrator access. The impact is lower in Windows deployments.
CWE: CWE-639
NVD

CRITICAL
CVE-2026-28316
CVE-2026-28316
pkg: solarwinds serv-u

published: Jul 21, 2026

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability to execute commands as the root user. This issue requires a domain account with administrator access. The impact is lower in Wind…
CWE: CWE-639
NVD

CRITICAL
CVE-2026-28314
CVE-2026-28314
pkg: solarwinds serv-u

published: Jul 21, 2026

SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. User authentication is required. The impact is lower in Windows deployments.
CWE: CWE-639
NVD

CRITICAL
CVE-2026-28313
CVE-2026-28313
pkg: solarwinds serv-u

published: Jul 21, 2026

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary account takeover. The impact is lower in Windows deployments.
CWE: CWE-639
NVD

CRITICAL
CVE-2026-28312
CVE-2026-28312
pkg: solarwinds serv-u

published: Jul 21, 2026

SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system administrator and allow code execution as root. The impact is lower in Windows deployments.
CWE: CWE-285
NVD

CRITICAL
CVE-2026-28310
CVE-2026-28310
pkg: solarwinds serv-u

published: Jul 21, 2026

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate their user type to that of a system administrator. The impact is lower in Windows deployments.
CWE: CWE-862
NVD

CRITICAL
CVE-2026-28309
CVE-2026-28309
pkg: solarwinds serv-u

published: Jul 21, 2026

SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts. The impact is lower in Windows deployments.
CWE: CWE-862
NVD

CRITICAL
CVE-2026-28308
CVE-2026-28308
pkg: solarwinds serv-u

published: Jul 21, 2026

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrator access is required. The impact is lower in Windows deployments.
CWE: CWE-639
NVD

CRITICAL
CVE-2026-28307
CVE-2026-28307
pkg: solarwinds serv-u

published: Jul 21, 2026

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an administrator group. The impact is lower in Windows deployments.
CWE: CWE-284
NVD

CRITICAL
CVE-2026-28306
CVE-2026-28306
pkg: solarwinds serv-u

published: Jul 21, 2026

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a system administrator. The impact is lower in Windows deployments.
CWE: CWE-284
NVD

CRITICAL
CVE-2026-28305
CVE-2026-28305
pkg: solarwinds serv-u

published: Jul 21, 2026

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution as root. A domain account with admin privileges and read and write access to the home directory is required. The impact is lower in Windows deployments.
CWE: CWE-639
NVD

CRITICAL
CVE-2026-28304
CVE-2026-28304
pkg: solarwinds serv-u

published: Jul 21, 2026

SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary execution of code remotely as root. The impact is lower in Windows deployments.
CWE: CWE-284
NVD

CRITICAL
CVE-2026-28302
CVE-2026-28302
pkg: solarwinds serv-u

published: Jul 21, 2026

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root. This issue requires group administrator access. The impact is lower in Windows deployments.
CWE: CWE-639
GitHub-GHSA

CRITICAL
Shescape: Shell injection via unescaped parentheses on Windows with CMD
GHSA-w4hw-qcx7-56pr
pkg: shescape, shescape
eco: npm
published: Jul 24, 2026
### Impact

This impacts users of Shescape on Windows that explicitly configure `shell` to CMD, or `true` with the default shell being CMD, using the `escape` and `escapeAll` APIs.

An attacker may be able to achieve shell injection depending on the original command.

“`javascript
import * as cp fr…

GitHub-GHSA

CRITICAL
Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak
GHSA-mqhr-6j6h-74p5
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
## Summary
Budibase attaches a REST datasource's stored credentials (Bearer/Basic tokens and static headers) to an outgoing request before it decides which host the request goes to, and never checks that the destination host matches the datasource. A query's request path can be pointed at any host (…
GitHub-GHSA

CRITICAL
Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified
GHSA-hp6v-6jw7-gv2f
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
### Summary
Budibase's OIDC SSO login links an incoming SSO identity to an existing Budibase account **by email address alone**, without ever checking the `email_verified` claim of the OIDC ID token. Budibase first tries to match the IdP `sub`; when that misses (any fresh attacker IdP account) it si…
GitHub-GHSA

CRITICAL
OpenAM: WebAuthn Java deserialization RCE via ObjectInputFilter depth>1 bypass
GHSA-gf8h-gq53-288j
pkg: org.openidentityplatform.openam:openam-auth-webauthn
eco: maven
published: Jul 24, 2026
### Summary
The GHSA-6c99-87fr-6q7r fix wrapped WebAuthn authenticator deserialization in an `ObjectInputFilter` meant to allow only `AuthenticatorImpl`, but it short-circuits to `ALLOWED` for any object at stream `depth > 1`. Because the Java serialization filter is consulted for every class in the…
CVE-2026-62263
GitHub-GHSA

CRITICAL
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
GHSA-hq9q-27g5-qwpj
pkg: Microsoft.OpenApi.Kiota, Microsoft.OpenApi.Kiota.Builder
eco: nuget
published: Jul 24, 2026
### Summary

`kiota info` — the command developers run to learn which packages to install after generating a client —
read the `x-ms-kiota-info` extension from the OpenAPI description and presented the spec-supplied
`dependencyInstallCommand` (and dependency `name`/`version`) **as the tool's own…

CVE-2026-59865
GitHub-GHSA

CRITICAL
Microsoft Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions
GHSA-4jwf-m4wg-8p66
pkg: Microsoft.OpenApi.Kiota, Microsoft.OpenApi.Kiota.Builder
eco: nuget
published: Jul 24, 2026
### Summary

`kiota plugin add` / `kiota plugin generate` (with `-t APIPlugin`) emits an attacker-controlled `static_template.file` path from the AI-plugin extensions (`x-ai-adaptive-card`, `x-ai-capabilities`) **verbatim**, with no path validation, into the generated Microsoft 365 Copilot / Teams p…

CVE-2026-59864
GitHub-GHSA

CRITICAL
Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)
GHSA-8fpg-xm3f-6cx3
pkg: next-auth
eco: npm
published: Jul 23, 2026
### Impact

`next-auth` (Auth.js) v5 applications that gate access by checking only for the **existence** of the `auth` object — the pattern shown in the official [session management / protecting resources guide](https://authjs.dev/getting-started/session-management/protecting) — are affected.

GitHub-GHSA

CRITICAL
Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
GHSA-7rqj-j65f-68wh
pkg: @auth/core, next-auth, next-auth
eco: npm
published: Jul 23, 2026
## Summary

The default email-address normalizer used by the email/magic-link sign-in flow validates the address **before** applying Unicode normalization. An address can contain a Unicode character that is not an ASCII `@` (U+0040) but canonicalizes to one under NFKC/NFKD normalization (the normali…

GitHub-GHSA

CRITICAL
Gitea Remember-Me Token Theft Not Invalidating Attacker Session
GHSA-rgv6-xp99-6mgj
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
The vulnerability is in the Remember-Me (gitea_incredible) token validation logic, specifically when handling a compromised token (hash mismatch).

The vulnerable function is this one:

https://github.com/go-gitea/gitea/blob/689ace1ce28fd74244b8aa335d9928cdbf6b22f9/services/auth/auth_token.go#L33-L6…

CVE-2026-56750
GitHub-GHSA

CRITICAL
LightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection
GHSA-f4vv-55c2-5789
pkg: lightrag-hku
eco: pip
published: Jul 20, 2026
## Summary

When LightRAG is deployed with `LIGHTRAG_API_KEY` set but `AUTH_ACCOUNTS` unset (an officially documented "API-Key authentication" mode), the `X-API-Key` protection can be bypassed by any remote unauthenticated attacker. The bypass does not require network contact with the victim server …

CVE-2026-61740
NVD

HIGH
CVE-2024-58355
CVE-2024-58355
pkg: react

published: Jul 23, 2026

Cal.com (calcom/cal.diy) versions through 4.7.15 contain a stored cross-site scripting vulnerability. The single booking view (e.g., https://app.cal.com/booking/<id>) renders booking-question field labels via React's dangerouslySetInnerHTML without sanitizing or escaping user input. An attacker who …
CWE: CWE-80
NVD

HIGH
CVE-2024-58353
CVE-2024-58353
pkg: react

published: Jul 23, 2026

Cal.com (repository calcom/cal.diy) in versions <= 4.7.15 is vulnerable to cross-site scripting (XSS) on the publicly accessible single booking view (e.g., /booking/<id>). Booking question (form field) labels are rendered via React's dangerouslySetInnerHTML without proper input sanitization or CSP, …
CWE: CWE-80
GitHub-GHSA

HIGH
Gitea: Permanent Fork PR Workflow Approval Gate Bypass
GHSA-777r-4v59-6486
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
| Field | Value |
|——-|——-|
| **Identifier (researcher-assigned)** | GITEA-2026-004 |
| **Product** | Gitea (self-hosted Git service) |
| **Component** | Gitea Actions — fork pull request approval gate |
| **Affected versions** | All Gitea releases **`v1.20.0` and later**, including the la…
CVE-2026-58424
NVD

HIGH
CVE-2026-64467
CVE-2026-64467
pkg: node

published: Jul 25, 2026

In the Linux kernel, the following vulnerability has been resolved:

rust_binder: use a u64 stride when cleaning up the offsets array

Allocation's Drop walks the offsets array (binder_size_t = u64 entries),
cleaning up the objects, but it used usize instead of u64 for both the
stride and the per-en…

NVD

HIGH
CVE-2026-64394
CVE-2026-64394
pkg: windows

published: Jul 25, 2026

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: add a WRITE_DAC/WRITE_OWNER check to SMB2 SET_INFO SECURITY

commit cc57232cae23 ("ksmbd: fix FSCTL permission bypass by adding a
permission check for FSCTL_SET_SPARSE") added a fp->daccess gate to
fsctl_set_sparse and noted…

GitHub-GHSA

HIGH
Budibase: Privilege escalation via public role assignment API missing app-level authorization
GHSA-j9fc-w3mr-x6mv
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
### Summary

Budibase `3.39.19` (commit `03fbabae4`) is affected by a privilege-escalation / missing-authorization flaw in the public role-assignment API. An **app-scoped builder** (a user who builds only specific apps — `user.builder.apps = [appA]`, not a global builder or admin) can grant **them…

GitHub-GHSA

HIGH
GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution
GHSA-r9mr-m37c-5fr3
pkg: GitPython
eco: pip
published: Jul 24, 2026
## Summary
GitPython's `check_unsafe_options` guard (the control introduced by CVE-2026-42215 / GHSA-2f96 and hardened since) can be bypassed for **every** guarded method (`clone`/`clone_from`, `fetch`/`pull`/`push`, `ls_remote`, `iter_commits`, `blame`, `archive`) by smuggling an option token insid…
GitHub-GHSA

HIGH
Ray: Arbitrary code execution via ray.data.read_webdataset default decoder: pickle.loads(value) and torch.load(weights_only=False)
GHSA-hhrp-gw25-jr43
pkg: ray
eco: pip
published: Jul 24, 2026
## Summary

`ray.data.read_webdataset(paths=…)` is a `@PublicAPI(stability="alpha")`
reader for WebDataset-format TAR files. Its default `decoder=True` invokes
`_default_decoder` on every sample's keys, which routes file extension to a
decoder by extension. Two of those branches deserialize attack…

CVE-2026-57516
NVD

HIGH
CVE-2026-16745
CVE-2026-16745
pkg: kubernetes

published: Jul 23, 2026

A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized…
CWE: CWE-346
NVD

HIGH
CVE-2025-44089
CVE-2025-44089
pkg: express

published: Jul 22, 2026

An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.
CWE: CWE-693
NVD

HIGH
CVE-2026-16423
CVE-2026-16423
pkg: google chrome

published: Jul 21, 2026

Use after free in UI in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-16421
CVE-2026-16421
pkg: google chrome

published: Jul 21, 2026

Inappropriate implementation in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-20
NVD

HIGH
CVE-2026-16420
CVE-2026-16420
pkg: google chrome

published: Jul 21, 2026

Type Confusion in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-843
NVD

HIGH
CVE-2026-16418
CVE-2026-16418
pkg: google chrome

published: Jul 21, 2026

Stack buffer overflow in V8 in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-121
NVD

HIGH
CVE-2026-60400
CVE-2026-60400
pkg: go

published: Jul 21, 2026

Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle GoldenGate. Succe…
CWE: CWE-284
NVD

HIGH
CVE-2026-60398
CVE-2026-60398
pkg: go

published: Jul 21, 2026

Vulnerability in Oracle GoldenGate (component: Oracle GoldenGate Microservices). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle GoldenGate.…
CWE: CWE-306
NVD

HIGH
CVE-2026-60157
CVE-2026-60157
pkg: go

published: Jul 21, 2026

Vulnerability in Oracle GoldenGate (component: Service Manager). Supported versions that are affected are 19.1.0.0.0-19.29.0.0, 21.3-21.21 and 23.4-23.26.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle GoldenGate. Successful…
CWE: CWE-284
GitHub-GHSA

HIGH
Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write
GHSA-649p-mmhf-85c7
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
## Vulnerability Header

| Field | Value |
| ——————- | ———————————————————————————– |
| Vulnerability Title | Cached Per-Branch Permission Ch…

CVE-2026-27775
GitHub-GHSA

HIGH
GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
GHSA-2f96-g7mh-g2hx
pkg: GitPython
eco: pip
published: Jul 21, 2026
## Command injection via long-option prefix abbreviation bypassing `check_unsafe_options` (incomplete fix of CVE-2026-42215 / GHSA-rpm5-65cw-6hj4)

**Component:** gitpython-developers/GitPython (PyPI: GitPython)
**Affected:** all versions carrying the 3.1.47 blocklist fix, through current `main` (ve…

NVD

HIGH
CVE-2026-55084
CVE-2026-55084
pkg: express

published: Jul 21, 2026

DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. A SQL injection vulnerability was identified in the SqlView API endpoint of the DHIS2 application in the `filter` parameter used by the
`/api/sqlViews/{viewId}/data.json` endpoint. An authen…
CWE: CWE-89
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-47300 – .NET Elevation of Privilege Vulnerability
GHSA-8prm-248r-h957
pkg: Microsoft.AspNetCore.Authentication.Negotiate, Microsoft.AspNetCore.Authentication.Negotiate, Microsoft.AspNetCore.Authentication.Negotiate
eco: nuget
published: Jul 21, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core Negotiate Authentication (Microsoft.AspNetCore.Authentication.Negotiate). This advisory also provides guidance on what developers can do to update their applications to re…

CVE-2026-47300
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-47303 – .NET Elevation of Privilege Vulnerability
GHSA-2p3q-h3hg-jcqq
pkg: Microsoft.AspNetCore.Authentication.Negotiate, Microsoft.AspNetCore.Authentication.Negotiate, Microsoft.AspNetCore.Authentication.Negotiate
eco: nuget
published: Jul 21, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core Negotiate Authentication (Microsoft.AspNetCore.Authentication.Negotiate). This advisory also provides guidance on what developers can do to update their applications to re…

CVE-2026-47303
NVD

HIGH
CVE-2026-15904
CVE-2026-15904
pkg: google chrome, linux linux_kernel

published: Jul 20, 2026

Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.128 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-15903
CVE-2026-15903
pkg: google chrome

published: Jul 20, 2026

Out of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-125, CWE-787, CWE-125, CWE-787
NVD

HIGH
CVE-2026-15902
CVE-2026-15902
pkg: google chrome

published: Jul 20, 2026

Use after free in Cast in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-12341
CVE-2026-12341
pkg: oauth

published: Jul 20, 2026

This vulnerability
impacts all versions of IdentityIQ and allows an unauthenticated attacker
unauthorized access to protected APIs and data due to improper validation of
OAuth bearer tokens.
CWE: CWE-287
NVD

HIGH
CVE-2026-64206
CVE-2026-64206
pkg: linux

published: Jul 20, 2026

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock

l2cap_conn_del() takes conn->lock and then calls cancel_work_sync() for
pending_rx_work. process_pending_rx() takes the same mutex, so teardown
can deadlock agains…

NVD

HIGH
CVE-2026-25039
CVE-2026-25039
pkg: windows

published: Jul 20, 2026

Parsec is a cloud-based application for simple and cryptographically secure file sharing. The application does not sanitize the workspace name, creating a vulnerability if that workspace name is a UNC path. When creating mountpoint in the windows filesystem to mount the workspace of an organization,…
CWE: CWE-40
NVD

HIGH
CVE-2026-65908
CVE-2026-65908
pkg: python

published: Jul 23, 2026

In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open
CWE: CWE-829
GitHub-GHSA

HIGH
Budibase: SSRF via DNS rebinding in the REST datasource integration
GHSA-v42f-v8xc-j435
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
### Summary
Budibase's central outbound-fetch guard (`fetchWithBlacklist`) prevents SSRF/DNS-rebinding by resolving the target hostname, checking every resolved IP against the blacklist, and **pinning** the connection to the validated IP. The pin is implemented as a Node `http(s).Agent` (`makePinned…
GitHub-GHSA

HIGH
Budibase: DNS rebinding SSRF bypasses remain in OpenAPI import and REST query execution
GHSA-xg5g-26×8-cvf4
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
## Impact

A builder-level user can make Budibase issue server-side HTTP requests to loopback or private-network targets by using DNS rebinding against two outbound fetch paths that are still not pinned to the validated DNS answer.

The first path is OpenAPI query import. It validates the supplied h…

NVD

HIGH
CVE-2026-17107
CVE-2026-17107
pkg: kubernetes

published: Jul 24, 2026

A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first removing caller-supplied values, and the spoke Servi…
CWE: CWE-441
GitHub-GHSA

HIGH
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration
GHSA-82f7-87hm-852x
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
# Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration

## Summary

Gitea validates the user-supplied repository migration URL, but the actual clone and later mirror fetch operations are performed by the Git command-line clie…

CVE-2026-57894
NVD

HIGH
CVE-2026-64806
CVE-2026-64806
pkg: node

published: Jul 23, 2026

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter
CWE: CWE-829
GitHub-GHSA

HIGH
GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`
GHSA-956x-8gvw-wg5v
pkg: GitPython
eco: pip
published: Jul 21, 2026
## Summary

GitPython spawns the real `git` binary with an argument vector built from caller-supplied values. To prevent argument injection, GitPython maintains denylists of "unsafe" Git options (`–upload-pack`, `–receive-pack`, `–exec`, `-c`, `–config`, …) that can be abused to run arbitrary …

NVD

HIGH
CVE-2026-64824
CVE-2026-64824
pkg: docker

published: Jul 21, 2026

Home Assistant Core before 2026.7.0 contains a path traversal vulnerability in the backup-restore function that allows attackers to write files to arbitrary absolute filesystem paths by supplying a crafted tar archive with a SYMTYPE entry containing a benign member name paired with an absolute linkn…
CWE: CWE-22
NVD

HIGH
CVE-2026-28220
CVE-2026-28220
pkg: node

published: Jul 20, 2026

Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.14.5, issues in the Cluster Distributed API (DAPI) handling allow a cluster peer, or any actor able to authenticate to the cluster channel using the shared cluster key, to make the master…
CWE: CWE-502
NVD

HIGH
CVE-2026-17497
CVE-2026-17497
pkg: python

published: Jul 26, 2026

NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore invoke plugin:shell|execute to run attacker-controlled operating …
CWE: CWE-78, CWE-276, CWE-1249
GitHub-GHSA

HIGH
Budibase: NoSQL Injection via JSON Parameter Interpolation in MongoDB Query Execution
GHSA-qw6m-8fw2-2v64
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
## Summary

Budibase's MongoDB query execution endpoint (`POST /api/v2/queries/:queryId`) is vulnerable to NoSQL injection through user-supplied query parameters. The `enrichContext()` function interpolates parameter values into JSON query templates using Handlebars with `noEscaping: true`, then par…

GitHub-GHSA

HIGH
Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in
GHSA-qq9h-g4jm-xgf3
pkg: better-auth, better-auth
eco: npm
published: Jul 24, 2026
### Am I affected

You are affected if all of the following hold:

– You run a `better-auth` version below 1.6.22, or a `1.7.0-beta` below `1.7.0-beta.10`.
– You enable the magic-link plugin or the email-OTP plugin.
– You also enable email and password sign-up with open registration.
– An account ca…

NVD

HIGH
CVE-2026-16416
CVE-2026-16416
pkg: google chrome

published: Jul 21, 2026

Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High)
CWE: CWE-190
NVD

HIGH
CVE-2026-16413
CVE-2026-16413
pkg: google chrome

published: Jul 21, 2026

Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-787
NVD

HIGH
CVE-2026-47688
CVE-2026-47688
pkg: node

published: Jul 21, 2026

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `clearAES` and `clearPMTasks` methods in `FOGPage` can be invoked by an unauthenticated attacker via a single HTTP GET request through the public `client` node e…
CWE: CWE-862
GitHub-GHSA

HIGH
Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`
GHSA-xj96-63gp-2gmr
pkg: Pillow
eco: pip
published: Jul 20, 2026
### Summary

Pillow's public rank-filter API can trigger a native heap out-of-bounds write
when given a very large odd filter size.

Minimal public API trigger:

“`python
from PIL import Image, ImageFilter

im = Image.new("L", (3, 3), 128)
im.filter(ImageFilter.MedianFilter(4294967295))
“`

`Image…

CVE-2026-59197
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-50528 – .NET Security Feature Bypass Vulnerability
GHSA-qvw7-jm5c-6hqw
pkg: Microsoft.NetCore.App.Runtime.linux-arm, Microsoft.NetCore.App.Runtime.linux-arm64, Microsoft.NetCore.App.Runtime.linux-musl-arm
eco: nuget
published: Jul 20, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET TLS/SSL (System.Net.Security). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A security feature bypass…

CVE-2026-50528
NVD

HIGH
CVE-2026-47255
CVE-2026-47255
pkg: tls

published: Jul 20, 2026

AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0.9.10 had weakness related to validation and and binding of inactive-agent hour filtering; storage SQL identifier validation; metadata-backed ownership…
CWE: CWE-20, CWE-89, CWE-284, CWE-319, CWE-798
GitHub-GHSA

HIGH
File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup
GHSA-fmm7-x4gx-8jhr
pkg: github.com/filebrowser/filebrowser/v2
eco: go
published: Jul 20, 2026
## Summary

A scoped, non-admin File Browser user holding only the **Create** permission can delete arbitrary files outside their scope (other tenants' data, and the application's own database) via the upload failure-cleanup path. This is an incomplete fix of CVE-2026-54094: the v2.63.14 `ScopedFs` …

CVE-2026-55667
NVD

HIGH
CVE-2026-54342
CVE-2026-54342
pkg: tls

published: Jul 24, 2026

In epa4all, prior to version 2026-05-20, an attacker on the network path between epa4all and any backend (ePA Aktensystem, Konnektor, IDP, TSS) can present a self-signed TLS certificate and intercept the connection. For non-VAU connections (Konnektor, IDP), this allows direct read and modification o…
CWE: CWE-295
GitHub-GHSA

HIGH
GitPython: Arbitrary file overwrite via git diff –output argument injection in Diffable.diff (key- and value-controlled)
GHSA-fjr4-x663-mwxc
pkg: GitPython
eco: pip
published: Jul 24, 2026
## Summary
`Diffable.diff()` forwards `**kwargs` straight into `diff`/`diff_tree` with **no** `check_unsafe_options` guard. `Diffable` is mixed into `Commit`, `Tree`, `IndexFile`, and `Submodule`, giving a broad surface. `git diff –output=<path>` writes real patch content to an attacker-chosen path…
NVD

HIGH
CVE-2026-64235
CVE-2026-64235
pkg: linux

published: Jul 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

x86/ftrace: Relocate %rip-relative percpu refs in dynamic trampolines

With CONFIG_CALL_DEPTH_TRACKING enabled on an x86 retbleed-affected platform
(eg: Skylake), with retbleed=stuff, registering a dynamic ftrace trampoline
crashes…

NVD

HIGH
CVE-2026-64223
CVE-2026-64223
pkg: linux

published: Jul 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

wifi: mac80211: consume only present negotiated TTLM maps

ieee80211_tid_to_link_map_size_ok() validates negotiated TTLM elements
against the number of link-map entries indicated by link_map_presence.
ieee80211_parse_neg_ttlm() mus…

NVD

HIGH
CVE-2026-61106
CVE-2026-61106
pkg: go

published: Jul 21, 2026

Vulnerability in Oracle GoldenGate (component: Config Service Executable). Supported versions that are affected are 23.4-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GoldenGate. Successful attacks of this vulnerabilit…
CWE: CWE-284, CWE-306
GitHub-GHSA

HIGH
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)
GHSA-vrhc-jjfc-m3m3
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
## Description

Gitea's OAuth2 sign-in callback reactivates a deactivated user account (`IsActive=false`) when the user signs in through an authentication source that does not issue refresh tokens (notably GitHub, and any OIDC/OAuth2 source configured without `offline_access`). PR #38009 added a gat…

CVE-2026-55987
GitHub-GHSA

HIGH
Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
GHSA-w5pg-649r-p6gg
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
## Summary

Gitea does not re-evaluate the `official` flag on existing pull request reviews when a PR's target branch is changed. An attacker with write access to a repository can obtain an `official: true` approval on a PR targeting an unprotected branch, then retarget the PR to a protected branch …

CVE-2026-58439
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-47304 – .NET Security Feature Bypass Vulnerability
GHSA-g8r8-53c2-pm3f
pkg: System.Security.Cryptography.Xml, System.Security.Cryptography.Xml, System.Security.Cryptography.Xml
eco: nuget
published: Jul 20, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET XML Encryption (System.Security.Cryptography.Xml). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A sec…

CVE-2026-47304
GitHub-GHSA

HIGH
File Browser: Colliding username normalization gives two users the same home directory
GHSA-7rc3-g7h6-22m7
pkg: github.com/filebrowser/filebrowser/v2
eco: go
published: Jul 20, 2026
## Summary

FileBrowser confines each user to a *scope*: a home directory that acts as the boundary for everything they can read or write. When self-registration and automatic home-directory creation are both enabled (`Signup=true` and `CreateUserDir=true`), a new user's scope is built from their us…

CVE-2026-62685
GitHub-GHSA

HIGH
Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)
GHSA-j657-m4c4-24jq
pkg: open-webui
eco: pip
published: Jul 24, 2026
## Summary

The terminal proxy in `backend/open_webui/routers/terminals.py` forwards the Open WebUI user's identity to the upstream terminal server / backend coordinator as an authorization claim, with no cryptographic binding to the session that produced it. The forwarded identity is attacker-influ…

CVE-2026-59224
NVD

HIGH
CVE-2026-61224
CVE-2026-61224
pkg: tls

published: Jul 21, 2026

Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Security). The supported version that is affected is 8.3. Difficult to exploit vulnerability allows high privileged attacker with network access via TLS to compromise Oracle Communi…
CWE: CWE-284
NVD

HIGH
CVE-2026-47237
CVE-2026-47237
pkg: kubernetes

published: Jul 21, 2026

Kubeflow Community Distribution helps users to install Kubeflow Platform in popular Kubernetes clusters. Prior to version 26.03-rc.1, a Kubeflow setup based on the official manifests or most other packaged Kubeflow distributions is vulnerable to authorization token stealing from any user of the Kube…
CWE: CWE-266
NVD

HIGH
CVE-2026-64418
CVE-2026-64418
pkg: node

published: Jul 25, 2026

In the Linux kernel, the following vulnerability has been resolved:

mm: shrinker: fix shrinker_info teardown race with expansion

expand_shrinker_info() iterates all visible memcgs under shrinker_mutex,
including memcgs that have not finished ->css_online() yet.

Once pn->shrinker_info has been pub…

NVD

HIGH
CVE-2026-64361
CVE-2026-64361
pkg: node

published: Jul 25, 2026

In the Linux kernel, the following vulnerability has been resolved:

hfs/hfsplus: fix u32 overflow in check_and_correct_requested_length

check_and_correct_requested_length() compares (off + len) against
node_size using u32 arithmetic. When the caller passes a large len
value (e.g. from an underflo…

NVD

HIGH
CVE-2026-64293
CVE-2026-64293
pkg: express

published: Jul 25, 2026

In the Linux kernel, the following vulnerability has been resolved:

iommufd: Use sizeof(*hdr) instead of sizeof(hdr) in veventq read

The bound-check in iommufd_veventq_fops_read() for the normal vEVENT
path uses sizeof(hdr) where the surrounding code uses sizeof(*hdr):

if (!vevent_for_lost_event…

NVD

HIGH
CVE-2026-64277
CVE-2026-64277
pkg: node

published: Jul 25, 2026

In the Linux kernel, the following vulnerability has been resolved:

Input: synaptics-rmi4 – bound the F3A keymap to the GPIO count

rmi_f3a_initialize() takes the GPIO count from the device query register
(f3a->gpio_count = buf & RMI_F3A_GPIO_COUNT, range 0..127).
rmi_f3a_map_gpios() then allocates…

GitHub-GHSA

HIGH
Oh My Posh: Arbitrary command execution via template injection in the path segment
GHSA-6xj8-qv9j-xcjq
pkg: github.com/jandedobbeleer/oh-my-posh
eco: go
published: Jul 24, 2026
### Summary
Oh My Posh re-renders the resolved path string, which contains the raw folder names taken from the filesystem, through the Go `text/template` engine. That engine's function map exposes a `cmd` function that runs arbitrary OS commands. A directory whose name contains a Go template express…
NVD

HIGH
CVE-2025-71408
CVE-2025-71408
pkg: express

published: Jul 24, 2026

NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls command-line arguments to execute arbitrary Python code. When collocations.py is invoked directly, the __main__ block passes command-line…
CWE: CWE-95
NVD

HIGH
CVE-2026-64226
CVE-2026-64226
pkg: linux

published: Jul 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

sched_ext: Avoid UAF in scx_root_enable_workfn() init failure path

In scx_root_enable_workfn(), put_task_struct(p) is called before scx_error()
dereferences p->comm and p->pid. If the iterator's reference is the last
drop, the tas…

NVD

HIGH
CVE-2026-64221
CVE-2026-64221
pkg: linux

published: Jul 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

spi: ti-qspi: fix use-after-free after DMA setup failure

The driver falls back to PIO mode if DMA setup fails during probe.

Make sure to clear the DMA channel pointer also if buffer allocation
fails to avoid passing a pointer to …

NVD

HIGH
CVE-2026-64218
CVE-2026-64218
pkg: linux

published: Jul 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

batman-adv: bla: fix report_work leak on backbone_gw purge

batadv_bla_purge_backbone_gw() removes stale backbone gateway entries,
but fails to properly handle their associated report_work:

– If report_work is running, the purge m…

NVD

HIGH
CVE-2026-64217
CVE-2026-64217
pkg: linux

published: Jul 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

netfs: Fix overrun check in netfs_extract_user_iter()

Fix netfs_extract_user_iter() so that if iov_iter_extract_pages() overfills
pages[], then those pages don't get included in the iterator constructed at
the end of the function.…

GitHub-GHSA

HIGH
electron-updater: Uncontrolled search path elements within `AppImage` built by `app-builder-lib`
GHSA-7g7r-gx96-252g
pkg: app-builder-lib
eco: npm
published: Jul 24, 2026
### Summary

`AppImage` targets built by `app-builder-lib` could use an empty path component when setting the `LD_LIBRARY_PATH` environment variable at runtime. This causes the current working directory to be added to the dynamic linker search path, which may allow an attacker to execute arbitrary c…

CVE-2026-54672
NVD

HIGH
CVE-2026-64802
CVE-2026-64802
pkg: go

published: Jul 23, 2026

In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration
CWE: CWE-94
NVD

HIGH
CVE-2026-64600
CVE-2026-64600
pkg: linux

published: Jul 23, 2026

In the Linux kernel, the following vulnerability has been resolved:

xfs: resample the data fork mapping after cycling ILOCK

xfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode,
a data fork mapping, and a cow fork mapping. Unfortunately, these two
helpers cycle the ILOCK to grab …

NVD

HIGH
CVE-2026-16607
CVE-2026-16607
pkg: linux

published: Jul 22, 2026

A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for local privilege escalation to root of an already authenticated user on GNU/Linux or Oracle Solaris. The Fsas Technologies PSIRT obtained that intelligence internally and…
CWE: CWE-269
NVD

HIGH
CVE-2026-16414
CVE-2026-16414
pkg: google chrome

published: Jul 21, 2026

Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High)
CWE: CWE-20
NVD

HIGH
CVE-2026-60570
CVE-2026-60570
pkg: go

published: Jul 21, 2026

Vulnerability in Oracle GoldenGate (component: Libraries). Supported versions that are affected are 23.4-23.26.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle GoldenGate executes to compromise Oracle GoldenGate. Successful attacks of…
NVD

HIGH
CVE-2026-47054
CVE-2026-47054
pkg: windows

published: Jul 21, 2026

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle …
CWE: CWE-269
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-50650 – .NET Elevation of Privilege Vulnerability
GHSA-2969-4q4w-w5h3
pkg: Microsoft.WindowsDesktop.App.Runtime.win-x64, Microsoft.WindowsDesktop.App.Runtime.win-x86, Microsoft.WindowsDesktop.App.Runtime.win-arm64
eco: nuget
published: Jul 21, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in Windows Presentation Foundation (WPF). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

An elevation of privil…

CVE-2026-50650
NVD

HIGH
CVE-2026-15905
CVE-2026-15905
pkg: google chrome

published: Jul 20, 2026

Use after free in Aura in Google Chrome prior to 150.0.7871.128 allowed a local attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-64191
CVE-2026-64191
pkg: linux

published: Jul 20, 2026

In the Linux kernel, the following vulnerability has been resolved:

i2c: stub: Reject I2C block transfers with invalid length

The I2C_SMBUS_I2C_BLOCK_DATA case in stub_xfer() uses data->block[0]
as the transfer length. The existing check only clamps it to avoid
overrunning the chip->words[256] reg…

NVD

HIGH
CVE-2026-64189
CVE-2026-64189
pkg: linux

published: Jul 20, 2026

In the Linux kernel, the following vulnerability has been resolved:

netfilter: ipset: fix race between dump and ip_set_list resize

The release path of ip_set_dump_do() and ip_set_dump_done() read
inst->ip_set_list via ip_set_ref_netlink(), a plain rcu_dereference_raw()
of the array pointer. These …

NVD

HIGH
CVE-2026-64188
CVE-2026-64188
pkg: linux

published: Jul 20, 2026

In the Linux kernel, the following vulnerability has been resolved:

net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink()

rmnet_dellink() removes the endpoint from the hash table with
hlist_del_init_rcu() and then immediately frees it with kfree(). However,
RCU readers on the receiv…

GitHub-GHSA

HIGH
Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF)
GHSA-pvcr-8mvp-w8qr
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
### Summary

The Budibase AI chat-link handoff flow (`GET/POST /api/chat-links/:instance/:token/handoff`) binds an **external chat identity** (Slack/Discord/MS Teams/Telegram) to a **Budibase user account**. The confirmation endpoint is on a **public route** (no CSRF middleware, no auth-group gate) …

GitHub-GHSA

HIGH
Budibase: S3 presigned URL endpoint authorization regression in v3.39.4 allows BASIC users to obtain S3 PutObject presigned URLs
GHSA-xcx6-4f2g-hhgx
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
## Impact

In Budibase v3.39.4, a regression in the authorization level for the S3 attachment upload endpoint allows any BASIC app user to obtain S3 PutObject presigned URLs. The endpoint uses TABLE/WRITE permission level instead of the intended BUILDER level defined in v3.39.3. Additionally, the co…

GitHub-GHSA

HIGH
open-webui terminal proxy path traversal guard bypass via 9x encoded traversal
GHSA-frvj-c5qp-xj4w
pkg: open-webui
eco: pip
published: Jul 24, 2026
AI assistance was used to help inspect the code and prepare this report.

## Summary

The fix for GHSA-r2wg-2mcr-66rv is incomplete in v0.9.6 and current main. `backend/open_webui/routers/terminals.py` documents `_sanitize_proxy_path()` as decoding until stable, but the implementation stops after 8 …

CVE-2026-59221
GitHub-GHSA

HIGH
Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id
GHSA-74h3-cxq7-vc5q
pkg: open-webui
eco: pip
published: Jul 24, 2026
## Summary

An authenticated low-privilege user can execute arbitrary code-interpreter Python and tools inside **another** user's authenticated session. The Socket.IO event-caller (`get_event_call`) delivers `execute:python` / `execute:tool` events to a **client-supplied** `session_id` after only ch…

CVE-2026-59216
GitHub-GHSA

HIGH
Gitea: Two SSRF findings
GHSA-2fcr-jfvc-vgg2
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
| — | — |
| Versions tested | `gitea/gitea:1.26.2` (digest `sha256:7d13848af12645600a5f9d93ee2560daa9c6fa6b5b859b7bff3a5e1c0b661031`); `gitea/gitea:latest` resolves to the same digest at time of writing |
| Source review | `git checkout v1.26.2` (commit `2c749ce`) |
| Reproduction | `bash run_po…
CVE-2026-58314
GitHub-GHSA

HIGH
Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories
GHSA-7wvc-rvp7-w99x
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary

A flaw in SSH LFS sub-verb handling allows any authenticated SSH user to obtain valid LFS credentials for any repository on the instance, including private repositories they have no access to. This enables unauthorized download of all LFS objects from any private repository.

### Detail…

CVE-2026-58423
NVD

HIGH
CVE-2026-46555
CVE-2026-46555
pkg: docker

published: Jul 20, 2026

WhatsApp MCP Server is a Model Context Protocol (MCP) server for WhatsApp, enabling Claude to read and send WhatsApp messages. Prior to version 0.2.1, the `whatsapp-bridge` HTTP API listens on `127.0.0.1:8080` without authentication and without Host header validation, and the `/api/send` endpoint ac…
CWE: CWE-22, CWE-306, CWE-346
NVD

HIGH
CVE-2026-54910
CVE-2026-54910
pkg: jwt

published: Jul 20, 2026

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.4.3-beta, the `subtitlesHandler` endpoint (`GET /api/media/subtitles`) accepts two user-controlled query parameters: `path` and `name`, both of which are used in filesystem operations without sanitization, creatin…
CWE: CWE-22, CWE-23
GitHub-GHSA

HIGH
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal
GHSA-95cv-r8x4-vh75
pkg: github.com/OpenListTeam/OpenList/v4
eco: go
published: Jul 24, 2026
### Summary

The `/api/fs/batch_rename` handler validates and authorizes only the requested source directory. It rejects path separators in `new_name`, but it does not validate `src_name`. The handler concatenates `src_dir` and attacker-controlled `src_name`, then passes the result to the filesystem…

GitHub-GHSA

HIGH
Budibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database Connector
GHSA-2xgg-r2wc-c5r2
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
### Summary
**This is a related but independently fixable vulnerability to GHSA-qqf5-x7mj-v43p
(PostgreSQL SQL injection), reported in the same original disclosure and
split per GitHub CNA guidance (rule 4.2.11) since it affects a separate
integration, has a distinct attack precondition, and require…
GitHub-GHSA

HIGH
Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim
GHSA-vgj4-345g-jcf8
pkg: github.com/cloudreve/Cloudreve/v4
eco: go
published: Jul 20, 2026
## Summary

Cloudreve's OAuth access tokens can bypass OAuth scope enforcement.

This does not appear to be the intended design. The documentation describes OAuth client permissions/scopes, the API
has an insufficient-scope error code, and the code comments say `RequiredScopes(…)` should ver…

CVE-2026-54560
NVD

HIGH
CVE-2026-63720
CVE-2026-63720
pkg: express

published: Jul 26, 2026

datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who control input schemas to achieve remote code execution by supplying a malicious customBasePath value containing embedded newlines and a dot-free Python expression. The crafted value is …
CWE: CWE-94
GitHub-GHSA

HIGH
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
GHSA-jvxp-qmx7-gjpx
pkg: aws-smithy-http-server
eco: rust
published: Jul 24, 2026
## Summary
Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits…
CVE-2026-16756
GitHub-GHSA

HIGH
libp2p: yamux connection DoS via oversized data frame
GHSA-hmj8-5xmh-5573
pkg: libp2p
eco: pip
published: Jul 24, 2026
### Summary
The yamux stream multiplexer in py-libp2p does not validate incoming DATA frame lengths against the receive window before reading the frame body. Any peer that completes a standard libp2p handshake can send a single 12-byte frame claiming a 4 GB body, causing the victim's yamux read loop…
GitHub-GHSA

HIGH
OmniFaces: Forged combined-resource IDs and related output/push boundaries
GHSA-fp43-vj7g-pg92
pkg: org.omnifaces:omnifaces, org.omnifaces:omnifaces, org.omnifaces:omnifaces
eco: maven
published: Jul 24, 2026
## 1. Forged combined-resource IDs
`CombinedResourceInfo` accepts a path-derived ID without an authenticity check,
inflates it without an output limit, converts it to attacker-selected resource
identifiers, and retains unique IDs in an unbounded static cache. In bounded
tests, 20,754 encoded bytes i…
GitHub-GHSA

HIGH
blaze: Unbounded WebSocket message aggregation in http4s-blaze-server
GHSA-7ppr-r889-mcf2
pkg: org.http4s:http4s-blaze-server_2.13, org.http4s:http4s-blaze-server_2.13, org.http4s:http4s-blaze-server_2.12
eco: maven
published: Jul 24, 2026
## Summary

`http4s-blaze-server` aggregates the fragments of an incoming WebSocket
message with no limit on total size or fragment count. A client that
completes a WebSocket handshake can send an unterminated fragmented
message and drive unbounded heap growth in the server JVM, resulting in
denial …

GitHub-GHSA

HIGH
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
GHSA-mh99-v99m-4gvg
pkg: brace-expansion
eco: npm
published: Jul 24, 2026
### Summary

`expand()` bounds the *number* of results it produces (the `max` option,
`100_000` by default) but not their *length*. By chaining many brace groups,
an attacker keeps the result count under `max` while making every result grow
with the number of groups. Building `max` long results — …

CVE-2026-14257
GitHub-GHSA

HIGH
@anephenix/hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion
GHSA-g5vv-q72c-7j78
pkg: @anephenix/hub
eco: npm
published: Jul 24, 2026
### Summary

`@anephenix/hub` starts a `setInterval` polling loop for every incoming WebSocket connection to request a client ID via RPC. If the remote client never replies — which requires no authentication or special configuration — the interval and the pending request object are never cleaned…

GitHub-GHSA

HIGH
GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)
GHSA-94p4-4cq8-9g67
pkg: GitPython
eco: pip
published: Jul 24, 2026
## Summary

The fix for [GHSA-rwj8-pgh3-r573](https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-rwj8-pgh3-r573) stopped `Repo.clone_from()` from running caller-supplied URLs through `os.path.expandvars()`, but it guarded only that one caller. `Remote.create()` — reached fr…

GitHub-GHSA

HIGH
Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint
GHSA-hr66-5mqr-8mpx
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
#### Summary
The Budibase Worker service exposes a public, unauthenticated API endpoint (`GET /api/global/users/tenant/:id`) that returns sensitive user information including `tenantId`, `userId`, `email`, and `ssoId`. The endpoint is registered in the `PUBLIC_ENDPOINTS` list with a `TODO` comment a…
GitHub-GHSA

HIGH
react-server-dom: Denial of Service in Server Functions
GHSA-wx67-qw84-cm4g
pkg: react-server-dom-webpack, react-server-dom-turbopack, react-server-dom-turbopack
eco: npm
published: Jul 24, 2026
### Impact

A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to out-of-memory exceptions or excessive CPU usage.

We recommend updating immediately.

The vulnerability exists in versions 19.0.0 through 19.0.…

CVE-2026-44907
GitHub-GHSA

HIGH
yt-dlp: Downstream command injection via improper sanitization of yt-dlp –write-link output
GHSA-6v4j-43gg-vj32
pkg: yt-dlp
eco: pip
published: Jul 24, 2026
### Summary
If the `–write-link`, `–write-url-link` or `–write-desktop-link` options are used with yt-dlp, it may produce output that can lead to downstream remote code execution. An attacker can craft a malicious metadata payload to achieve arbitrary command injection in the `.url` and `.desktop…
CVE-2026-55404
NVD

HIGH
CVE-2026-66033
CVE-2026-66033
pkg: express

published: Jul 24, 2026

libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AES-GCM ciphers during handshake. Attackers can exploit…
CWE: CWE-125, CWE-191
GitHub-GHSA

HIGH
Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion
GHSA-v74w-7mr3-4qg3
pkg: io.netty:netty-codec-xml, io.netty:netty-codec-xml
eco: maven
published: Jul 24, 2026
### Summary
An attacker can cause Denial of Service by sending a specially crafted malicious XML payload (e.g., repeated `</` characters) to a Netty server utilizing XmlFrameDecoder, causing the server's EventLoop thread to exhaust CPU resources and become unresponsive.

### Details
`io.netty.handle…

GitHub-GHSA

HIGH
js-yaml: Exponential parsing time in flow collections leads to denial of service
GHSA-pm4m-ph32-ghv5
pkg: js-yaml
eco: npm
published: Jul 24, 2026
### Summary
Parsing a small YAML document can take exponential time. An application that calls `load()` or `loadAll()` on untrusted input can be hung by a payload under 200 bytes.

### Details
When an entry in a flow sequence turns out to be a `key: value` pair, the parser rewinds and parses that en…

GitHub-GHSA

HIGH
@fastify/static vulnerable to route guard bypass via path traversal
GHSA-83w8-p2f5-377r
pkg: @fastify/static
eco: npm
published: Jul 24, 2026
### Impact

`@fastify/static` is vulnerable to a bypass of route-based middleware and guards via non-leading `..` and `%2E%2E` path segments. `find-my-way` does not normalize `..` when matching routes, so a request such as `/foo/../deep/secret.txt` matches the static plugin's catch-all instead of th…

CVE-2026-15074
GitHub-GHSA

HIGH
GitPython: Incomplete unsafe_git_clone_options denylist omits –template enabling arbitrary command execution via clone hooks
GHSA-6p8h-3wgx-97gf
pkg: GitPython
eco: pip
published: Jul 24, 2026
## Summary
GitPython's `unsafe_git_clone_options` denylist omits `–template`. `git clone –template=<dir>` copies `<dir>/hooks/` into the new repository and runs them (`post-checkout` fires during clone), so a caller who can influence clone options can achieve arbitrary command execution in the def…
GitHub-GHSA

HIGH
PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
GHSA-r28c-9q8g-f849
pkg: postcss
eco: npm
published: Jul 24, 2026
## Vulnerability Details

**File**: `lib/previous-map.js`
**Line**: 87-98 (`loadFile`), 129-144 (`loadMap`)

### Root Cause
PostCSS auto-detects a `/*# sourceMappingURL=… */` comment inside the CSS text it is asked to parse and, unless the caller explicitly passes `map: false`, attempts to load t…

NVD

HIGH
CVE-2026-64210
CVE-2026-64210
pkg: linux

published: Jul 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

net/mlx5e: xsk: Fix unlocked writing to ICOSQ

During napi poll, when the affinity changes and there's still XSK work
to be done, we trigger an ICOSQ interrupt on the new CPU. However, this
triggering on the ICOSQ is done unprotect…

NVD

HIGH
CVE-2026-64208
CVE-2026-64208
pkg: linux

published: Jul 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks

Change the krb5 crypto library to provide facilities to precheck the length
of the message about to be decrypted or verified.

Fix AF_RXRPC to make use of this t…

GitHub-GHSA

HIGH
Microsoft Kiota: Code Generation Literal Injection in Kiota Python Generator
GHSA-7f3j-j7jj-r3vr
pkg: Microsoft.OpenAPI.Kiota, Microsoft.OpenAPI.Kiota.Builder
eco: nuget
published: Jul 24, 2026
Code Generation Literal Injection in Kiota Python Generator Leads to Arbitrary Code Execution at Import Time.

The Kiota Python code generator is vulnerable to a code generation literal injection issue when processing malicious or untrusted OpenAPI specifications. Specifically, attacker-controlled e…

CVE-2026-59862
GitHub-GHSA

HIGH
Microsoft Kiota: Code Generation Literal Injection in Kiota Ruby Generator
GHSA-xg2h-5xr2-29jw
pkg: Microsoft.OpenAPI.Kiota, Microsoft.OpenAPI.Kiota.Builder
eco: nuget
published: Jul 24, 2026
Code Generation Literal Injection in Kiota Ruby Generator Leads to Arbitrary Code Execution

# Impact

The Kiota Ruby code generator is vulnerable to a code generation literal injection attack. The generator embeds string values from OpenAPI default fields and property names directly into Ruby doubl…

CVE-2026-59861
GitHub-GHSA

HIGH
httplib2: Decompression Bomb Denial of Service via Unbounded gzip/deflate Response Handling
GHSA-j5g9-f88f-gfj3
pkg: httplib2
eco: pip
published: Jul 24, 2026
### Summary

The `httplib2` HTTP client library performs unbounded decompression of HTTP response bodies encoded with `Content-Encoding: gzip` or `deflate`. A malicious or compromised HTTP server can return a small compressed payload (approximately 150 KB) that expands to an arbitrarily large size i…

CVE-2026-59939
GitHub-GHSA

HIGH
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
GHSA-4w2j-m93h-cj5j
pkg: quinn-proto
eco: rust
published: Jul 24, 2026
## Summary

The `Assembler` component that assembles unordered stream fragments into consecutive chunks of the stream incurs some overhead for non-contiguous fragments. Readers that read from a `RecvStream` in order (through an `AsyncRead` impl for example) will be sensitive to peers that send fragm…

GitHub-GHSA

HIGH
find-my-way: DDoS with HTTP2
GHSA-c96f-x56v-gq3h
pkg: find-my-way
eco: npm
published: Jul 23, 2026
### Impact
Remotely triggerable DoS in find-my-way when it is used with Node's HTTP/2 server.

The short version is that `lookup()` passes `req.method` into `find()`, and `find()` indexes `this.trees[method]`. Since `this.trees` is a normal object, HTTP/2 method values like constructor, `toString`, …

CVE-2026-47219
GitHub-GHSA

HIGH
PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments
GHSA-6g55-p6wh-862q
pkg: postcss
eco: npm
published: Jul 23, 2026
## Summary

PostCSS's `PreviousMap` parses the `/*# sourceMappingURL=PATH */` comment from any CSS string passed to `process()` and dereferences `PATH` against the local filesystem with no scheme, allowlist, or traversal check. An attacker who controls the CSS input can cause the host process to rea…

CVE-2026-45623
GitHub-GHSA

HIGH
Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers
GHSA-xmf8-cvqr-rfgj
pkg: @auth/core, next-auth, next-auth
eco: npm
published: Jul 23, 2026
## Summary

The exported `getToken()` helper (`next-auth/jwt` and `@auth/core/jwt`) can throw an uncaught exception when it reads a malformed `Authorization: Bearer …` header. When no session cookie is present, `getToken()` URL-decodes the bearer value before validating it, and malformed percent-e…

NVD

HIGH
CVE-2026-14257
CVE-2026-14257
pkg: node

published: Jul 23, 2026

brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max option (default 100,000) but does not bound the length of each result string. By chaining multiple brace groups, an attacker keeps the result count un…
CWE: CWE-400, CWE-770
GitHub-GHSA

HIGH
Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requests
GHSA-9299-c6m4-mjhc
pkg: org.eclipse.jetty:jetty-server, org.eclipse.jetty:jetty-server
eco: maven
published: Jul 22, 2026
### Impact
The original report:

> Server handling of 100-Continue requests can lead to memory leak that can be abused to cause a Denial of Service state.

After investigation, turns out that every request that has a body, but reading the body may end up in reading 0 bytes, leaks a buffer.
This is p…

CVE-2024-7708
GitHub-GHSA

HIGH
Netty: Memory Exhaustion via HTTP/3 Reserved Frame Types
GHSA-hpcc-26xq-25fv
pkg: io.netty:netty-codec-http3
eco: maven
published: Jul 22, 2026
### Summary
Netty's Http3FrameCodec buffers incoming data for HTTP/3 reserved frame types up to the specified payload length without any limits. The payload length is read directly from the wire and trusted without validation. A bad actor can send a reserved frame with a payload length of up to Inte…
CVE-2026-56816
GitHub-GHSA

HIGH
Netty SPDY zlib header block continues decoded expansion after maxHeaderSize truncation
GHSA-mvh2-crg5-v77c
pkg: io.netty:netty-codec-http, io.netty:netty-codec-http
eco: maven
published: Jul 22, 2026
### Summary
Netty SPDY header decoding continues inflating zlib-compressed header blocks after the raw header parser has already exceeded maxHeaderSize and marked the frame truncated. At commit b2d2137c4404af425bf9d5d601a62576f5c06925, a 12,253-byte compressed SPDY header block can declare and infla…
CVE-2026-55833
GitHub-GHSA

HIGH
Netty SPDY SETTINGS frame count materializes unbounded settings map
GHSA-6jqx-86gh-f27w
pkg: io.netty:netty-codec-http, io.netty:netty-codec-http
eco: maven
published: Jul 22, 2026
### Summary
Netty's SPDY SETTINGS decoder accepts a peer-declared SETTINGS entry count up to the 24-bit frame-length limit and materializes every unique setting ID in `DefaultSpdySettingsFrame` without an implementation-level count cap. A remote SPDY/3.1 peer can send one syntactically valid roughly…
CVE-2026-55831
NVD

HIGH
CVE-2026-16422
CVE-2026-16422
pkg: google chrome, linux linux_kernel

published: Jul 21, 2026

Insufficient validation of untrusted input in Certificate in Google Chrome on Linux prior to 150.0.7871.182 allowed an attacker in a privileged network position to perform domain spoofing via malicious network traffic. (Chromium security severity: High)
CWE: CWE-20
NVD

HIGH
CVE-2026-65315
CVE-2026-65315
pkg: go

published: Jul 21, 2026

Ollama (HEAD f0078ae) contains an uncontrolled memory allocation vulnerability in the GGUF metadata parser that allows remote attackers to crash the server by supplying a crafted GGUF file with attacker-controlled length and count fields in string lengths, tensor dimension counts, and metadata array…
CWE: CWE-789
GitHub-GHSA

HIGH
GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL
GHSA-rwj8-pgh3-r573
pkg: gitpython
eco: pip
published: Jul 21, 2026
### Summary
`Repo.clone_from()` passes the caller-supplied remote URL through `Git.polish_url()`, which on every non-Cygwin platform calls `os.path.expandvars()` on the URL before handing it to `git clone`. An attacker who controls the URL argument — the documented use case for `clone_from()` in "…
GitHub-GHSA

HIGH
Gitea: Notification API leaks private issue metadata after access revocation
GHSA-44qc-pgvp-wx7v
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
# Summary

An information disclosure issue in the Gitea Notification API allows users who have lost access to a private repository to continue accessing private issue or pull request information through existing notification threads. Although repository information is hidden after access revocation,…

CVE-2026-58419
GitHub-GHSA

HIGH
Gitea: Unauthorized Access to Labels of Private Organizations
GHSA-v73x-hx65-6pf4
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
## Summary

Gitea 1.26.2 does not properly enforce organization visibility restrictions on organization label read endpoints.

A user without access to a private organization can retrieve labels belonging to that organization through the Organization Labels API. As a result, label metadata intended …

CVE-2026-25038
GitHub-GHSA

HIGH
Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private
GHSA-wrf9-r3h7-7x5v
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary

The `POST /api/v1/repos/{owner}/{repo}/merge-upstream` endpoint continues to synchronize commits from a parent repository after the parent repository has been changed from public to private.

A fork created while the parent repository was public can still receive commits made after the …

CVE-2026-24451
GitHub-GHSA

HIGH
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override
GHSA-94v3-77j7-vm48
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
Summary

Gitea's internal API HTTP client (modules/private/internal.go) hardcodes
TLSClientConfig.InsecureSkipVerify = true with no configuration override. It is the only
outbound TLS client in the codebase that cannot be made to verify its peer's certificate —
webhook, migrations, MinIO, LDAP, SM…

CVE-2026-54481
GitHub-GHSA

HIGH
Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service
GHSA-v96j-25gv-g2w9
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
This issue has been found by a security agent and review by myself.

Gitea's CODEOWNERS feature uses the regexp2 library to match file paths against ownership rules. User-supplied patterns are passed directly to regexp2.Compile with no sanitisation and no match timeout. This allows an attacker to wr…

CVE-2026-58421
GitHub-GHSA

HIGH
pyasn1: Uncontrolled resource consumption when converting decoded REAL values
GHSA-hm4w-wwcw-mr6r
pkg: pyasn1
eco: pip
published: Jul 21, 2026
### Impact
The univ.Real type converted its (mantissa, base, exponent) value to a Python float using exact big-integer exponentiation. A BER/CER/DER-encoded REAL value only a few bytes long can carry a very large exponent, causing this computation to attempt to materialize an astronomically large in…
CVE-2026-59886
GitHub-GHSA

HIGH
pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service
GHSA-8ppf-4f7h-5ppj
pkg: pyasn1
eco: pip
published: Jul 21, 2026
### Impact
The BER/CER/DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs. A small crafted payload (tens of kilobytes) containing an OID with many arcs consumes seconds of CPU per decode() call, allowing denial of service in any applicatio…
CVE-2026-59885
GitHub-GHSA

HIGH
pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs
GHSA-m4p7-r5rc-7g4j
pkg: pyssn1
eco: pip
published: Jul 21, 2026
### Impact
The BER decoder (shared by the CER and DER codecs) parses long-form tags by accumulating continuation octets in a loop with no upper bound on the size of the tag ID. A crafted input can force the decoder to build an arbitrarily large integer, with CPU cost growing quadratically in input s…
CVE-2026-59884
NVD

HIGH
CVE-2026-44907
CVE-2026-44907
pkg: react

published: Jul 21, 2026

A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack (versions 19.0.0 throu…
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-56170 – .NET Denial of Service Vulnerability
GHSA-j8gr-8fp3-5q5h
pkg: Microsoft.AspNetCore.App.Runtime.linux-arm, Microsoft.AspNetCore.App.Runtime.linux-arm64, Microsoft.AspNetCore.App.Runtime.linux-musl-arm
eco: nuget
published: Jul 21, 2026
# Microsoft Security Advisory CVE-2026-56170 – .NET Denial of Service Vulnerability

## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core SignalR (Microsoft.AspNetCore.App.Runtime). This advisory also provides guidance on …

CVE-2026-56170
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-50527 – .NET Denial of Service Vulnerability
GHSA-mmjf-rqrv-855v
pkg: System.Security.Cryptography.Xml, System.Security.Cryptography.Xml, System.Security.Cryptography.Xml
eco: nuget
published: Jul 21, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET XML Encryption (System.Security.Cryptography.Xml). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A den…

CVE-2026-50527
GitHub-GHSA

HIGH
Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch
GHSA-9hw9-ch79-4vh6
pkg: pillow
eco: pip
published: Jul 20, 2026
### Summary

Pillow's public `ImageCms.ImageCmsTransform.apply(im, imOut)` API can trigger
controlled native heap corruption when the caller supplies an output image whose
mode does not match the transform's declared output mode.

For example, a transform built as `RGBA -> RGBA` can be applied to an…

CVE-2026-59205
GitHub-GHSA

HIGH
Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()
GHSA-jjj6-mw9f-p565
pkg: Pillow
eco: pip
published: Jul 20, 2026
### Summary
`PdfParser.PdfStream.decode()` in Pillow's `PdfParser.py` calls `zlib.decompress()` with the `bufsize` parameter set to the value of the PDF stream's `Length` field, without any upper bound on the actual decompressed output size. Python's `zlib.decompress()` `bufsize` argument is an *ini…
CVE-2026-59200
GitHub-GHSA

HIGH
Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow
GHSA-6r8x-57c9-28j4
pkg: Pillow
eco: pip
published: Jul 20, 2026
### Summary

Pillow's public image coordinate APIs can trigger a native heap out-of-bounds
write when given coordinates near the signed 32-bit integer limits. In 4-byte
pixel modes such as `RGBA`, this becomes a controlled backward heap underwrite:
for a source image of width `W`, Pillow writes `4 *…

CVE-2026-59199
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-50651 – .NET Denial of Service Vulnerability
GHSA-wp74-jgxh-gv4q
pkg: Microsoft.NetCore.App.Runtime.linux-arm, Microsoft.NetCore.App.Runtime.linux-arm64, Microsoft.NetCore.App.Runtime.linux-musl-arm
eco: nuget
published: Jul 20, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET HTTP client (System.Net.Http). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A denial of service vulne…

CVE-2026-50651
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-50525 – .NET Denial of Service Vulnerability
GHSA-8q5v-6pqq-x66h
pkg: System.Security.Cryptography.Xml, System.Security.Cryptography.Xml, System.Security.Cryptography.Xml
eco: nuget
published: Jul 20, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET XML Encryption (System.Security.Cryptography.Xml). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A den…

CVE-2026-50525
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-50648 – .NET Denial of Service Vulnerability
GHSA-23rf-6693-g89p
pkg: System.Security.Cryptography.Xml, System.Security.Cryptography.Xml, System.Security.Cryptography.Xml
eco: nuget
published: Jul 20, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET XML Encryption (System.Security.Cryptography.Xml). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A den…

CVE-2026-50648
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-50524 – .NET Denial of Service Vulnerability
GHSA-w7cw-xp7h-6j5j
pkg: Microsoft.NetCore.App.Runtime.linux-arm, Microsoft.NetCore.App.Runtime.linux-arm64, Microsoft.NetCore.App.Runtime.linux-musl-arm
eco: nuget
published: Jul 20, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET TLS/SSL (System.Net.Security). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A denial of service vulne…

CVE-2026-50524
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-47302 – .NET Denial of Service Vulnerability
GHSA-cvvh-rhrc-wg4q
pkg: System.Security.Cryptography.Xml, Microsoft.NetCore.App.Runtime.linux-arm, Microsoft.NetCore.App.Runtime.linux-arm64
eco: nuget
published: Jul 20, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET XML processing (System.Security.Cryptography.Xml, System.Xml). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerabi…

CVE-2026-47302
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-57108 – .NET Denial of Service Vulnerability
GHSA-rp2p-6cmp-jxj9
pkg: Microsoft.NetCore.App.Runtime.linux-arm, Microsoft.NetCore.App.Runtime.linux-arm64, Microsoft.NetCore.App.Runtime.linux-musl-arm
eco: nuget
published: Jul 20, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in the .NET runtime cryptography layer (CryptoNative_GetX509NameInfo). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerabi…

CVE-2026-57108
GitHub-GHSA

HIGH
Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert)
GHSA-c8j7-8cv4-2xmq
pkg: mistune
eco: pip
published: Jul 20, 2026
## Summary

**Type:** Algorithmic-complexity denial of service. A run of N closed pairs `~~x~~~~x~~…` (or the analogous `==x==` for `mark`, `^^x^^` for `insert`) causes O(N²) work in the formatting parser. With the `strikethrough`, `mark`, or `insert` plugin enabled, an 8 KB input pegs the CPU fo…

CVE-2026-59922
GitHub-GHSA

HIGH
Mistune inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs
GHSA-4j32-57v6-6g45
pkg: mistune
eco: pip
published: Jul 20, 2026
## Summary

**Type:** Algorithmic-complexity DoS in core emphasis parsing. A long sequence of well-formed `**x**` (strong) or `***x***` (strong-emphasis combined) pairs causes O(N²) parser work. Distinct from the bracket-bomb DoS (`[` repetition) and from the formatting-plugin DoS (`~~`/`==`/`^^`);…

CVE-2026-59925
GitHub-GHSA

HIGH
Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions
GHSA-ffq3-xpv3-j92q
pkg: mistune
eco: pip
published: Jul 20, 2026
## Summary

**Type:** Algorithmic-complexity DoS in reference-link definition handling. A markdown document with N reference-link definitions of the same key (or many distinct keys) takes O(N²) parser time. 5000 repeated `[a]: u\n` definitions take ~1.1 second; 10000 → ~4.5 seconds.
**File:** `sr…

CVE-2026-59928
GitHub-GHSA

HIGH
Pillow `GdImageFile._open()`: image dimensions accepted without `_decompression_bomb_check()`
GHSA-phj9-mv4w-65pm
pkg: pillow
eco: pip
published: Jul 20, 2026
## Description

`PIL/GdImageFile.py` `GdImageFile._open()` reads image dimensions from the GD 2.x header and stores them in `self._size` without calling `Image._decompression_bomb_check()`. Because `GdImageFile` is **not registered with `Image.register_open()`**, it never passes through the standard…

CVE-2026-55380
GitHub-GHSA

HIGH
Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading
GHSA-45hq-cxwh-f6vc
pkg: pillow
eco: pip
published: Jul 20, 2026
### Summary
`PIL/BdfFontFile.py` `bdf_char()` (lines 84–88) reads the `BBX width height` field from a BDF font file and passes the dimensions directly to `Image.new()` without calling `Image._decompression_bomb_check()`. This completely bypasses Pillow's documented decompression bomb protection.

CVE-2026-55379
GitHub-GHSA

HIGH
Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`
GHSA-5×94-69rx-g8h2
pkg: pillow
eco: pip
published: Jul 20, 2026
## Description

`PIL/FontFile.py` `FontFile.compile()` assembles per-glyph images into a single combined bitmap using `Image.new("1", (xsize, ysize))` without calling `Image._decompression_bomb_check()`. This is the base-class method shared by both `BdfFontFile` and `PcfFontFile`, and it is triggere…

CVE-2026-54060
GitHub-GHSA

HIGH
Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading
GHSA-8v84-f9pq-wr9x
pkg: pillow
eco: pip
published: Jul 20, 2026
## Description
`PIL/PcfFontFile.py` `_load_bitmaps()` (line 227) reads glyph dimensions from the PCF `METRICS` section and passes them directly to `Image.frombytes()` without calling `Image._decompression_bomb_check()`. Dimensions originate from unsigned 16-bit values:

“`
xsize = right – left …

CVE-2026-54059
GitHub-GHSA

HIGH
Tornado: Quadratic DoS via Crafted Multipart Parameters
GHSA-jhmp-mqwm-3gq8
pkg: tornado
eco: pip
published: Jul 20, 2026
## Summary

The `_parseparam` function in Tornado's `httputil.py` is used to parse specific HTTP header values, such as those in `multipart/form-data`. This function uses an inefficient algorithm that repeatedly calls `string.count()` within a nested loop while processing quoted semicolons (e.g., `p…

CVE-2025-67726
GitHub-GHSA

HIGH
Tornado: Quadratic DoS via Repeated Header Coalescing
GHSA-c98p-7wgm-6p64
pkg: tornado
eco: pip
published: Jul 20, 2026
## Summary

The `HTTPHeaders.add` method in Tornado accumulates values using string concatenation when the same header name is repeated. Due to Python string immutability, each concatenation copies the entire string, resulting in O(n²) time complexity.

Given Tornado's single event loop architectur…

CVE-2025-67725
NVD

HIGH
CVE-2026-45713
CVE-2026-45713
pkg: go

published: Jul 20, 2026

Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the Mailpit SMTP server has a Server.MaxSize int field that controls the maximum allowed DATA payload size, but the field is never assigned anywhere outside test code, leaving it at Go's zero value (0 ⇒ "no limit"). …
CWE: CWE-400, CWE-770
GitHub-GHSA

HIGH
blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)
GHSA-46q4-43ph-c6fr
pkg: org.http4s:blaze-http_2.13, org.http4s:blaze-http_2.12, org.http4s:blaze-http_3
eco: maven
published: Jul 24, 2026
### Summary
blaze-server can merge HTTP/1.1 chunked-body trailer fields into `Request.headers`. Because trailer fields are attacker-controlled, an unauthenticated remote client can inject arbitrary header names/values (e.g. `X-Forwarded-For`, internal-auth headers) that a fronting proxy sanitized …
GitHub-GHSA

HIGH
blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser
GHSA-mhvj-jhpq-885v
pkg: org.http4s:http4s-blaze-server_2.13, org.http4s:blaze-http_2.13, org.http4s:blaze-http_3
eco: maven
published: Jul 24, 2026
### Summary
Five independent HTTP/1.1 conformance laxities in blaze's hand-written Java parser (`http/src/main/java/org/http4s/blaze/http/parser/`) cause request-boundary disagreement with a stricter intermediary. All are reachable from a default `BlazeServerBuilder` with no non-default configurat…
GitHub-GHSA

HIGH
Netty: TOCTOU in OcspServerCertificateValidator
GHSA-wc96-39fc-566f
pkg: io.netty:netty-handler-ssl-ocsp, io.netty:netty-handler-ssl-ocsp
eco: maven
published: Jul 22, 2026
### Summary
Netty's OcspServerCertificateValidator forwards the SslHandshakeCompletionEvent before the asynchronous OCSP validation completes. This allows the client's downstream handlers to send sensitive application data (e.g., HTTP requests) to a revoked server before the channel is closed by the…
CVE-2026-56822
GitHub-GHSA

HIGH
Netty: Out-of-date OCSP Responses Accepted by OcspServerCertificateValidator
GHSA-g7hg-vrcf-mvmr
pkg: io.netty:netty-handler-ssl-ocsp, io.netty:netty-handler-ssl-ocsp
eco: maven
published: Jul 22, 2026
### Summary
`OcspServerCertificateValidator` flags an out-of-date OCSP response but does not stop processing it, so an expired GOOD response is still reported as `VALID`, letting an on-path attacker replay a stale GOOD response to bypass revocation of a since-revoked certificate.

### Details
In `io…

CVE-2026-56821
GitHub-GHSA

HIGH
Netty: Missing CertificateID Validation in OCSP Response Allows Replay Attacks
GHSA-272m-gcwp-mpwg
pkg: io.netty:netty-handler-ssl-ocsp, io.netty:netty-handler-ssl-ocsp
eco: maven
published: Jul 22, 2026
### Summary
Netty's OcspClient does not validate that the CertificateID in an OCSP response matches the requested CertificateID. A bad actor can replay a `GOOD` status response issued for an unrelated certificate (by the same CA) to bypass revocation checks for any certificate.

### Details
`io.nett…

CVE-2026-56820
GitHub-GHSA

HIGH
AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()
GHSA-j6g5-3hh3-pgw8
pkg: bedrock-agentcore
eco: pip
published: Jul 24, 2026
### Summary

The AWS Bedrock AgentCore Python SDK (bedrock-agentcore) provides tools for building AI agents, including a Code Interpreter client that installs Python packages into a managed sandbox. An issue exists where, under certain circumstances, improper neutralization of argument delimiters in…

CVE-2026-16796
GitHub-GHSA

HIGH
Open WebUI: Stored web worker XSS via Pyodide
GHSA-4r2p-27mh-5m22
pkg: open-webui
eco: pip
published: Jul 24, 2026
**Title:** Same-origin Pyodide code execution allows server-side RCE via a shared chat

### Summary

Open WebUI runs client-side Python (Pyodide) in a same-origin web worker. Through Pyodide's JavaScript API (`pyodide.http.pyfetch`, or the `js` module which exposes the page's `fetch` / `XMLHttpReque…

CVE-2026-59214
NVD

HIGH
CVE-2026-16796
CVE-2026-16796
pkg: python

published: Jul 23, 2026

Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK before 1.18.1 might allow a remote authenticated user to execute arbitrary commands within the Code Interpreter sandbox via crafted package name arguments.

To mitigate this issue, u…

CWE: CWE-88
NVD

HIGH
CVE-2026-56624
CVE-2026-56624
pkg: openssh

published: Jul 20, 2026

Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a Java library for client-side and server-side SSH.

Server-side OpenSSH user certificate validation during user authentication in an Apache MINA SSHD server did not check for the unsupported force-command or …

CWE: CWE-295
NVD

HIGH
CVE-2026-32825
CVE-2026-32825
pkg: jwt

published: Jul 20, 2026

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, the application accepts unlimited password guesses against both the brow…
CWE: CWE-307
NVD

HIGH
CVE-2026-16247
CVE-2026-16247
pkg: windows

published: Jul 20, 2026

In _connect.BRAIN versions prior to 5.06,
the application LogPathConfig.exe is executed during setup. During this
process, existing permissions on %ProgramData% are deleted and replaced,
granting the Windows group Everyone full control instead of restricting
access to %ProgramData%\Bizerba\_connect.…
CWE: CWE-276
NVD

HIGH
CVE-2026-16246
CVE-2026-16246
pkg: windows

published: Jul 20, 2026

In BRAIN2 versions prior to 3.09, the
application LogPathConfig.exe is executed during setup. As a result, the
Windows group Everyone is granted full control over %ProgramData% instead of
being restricted to %ProgramData%\Bizerba\BRAIN2\.

Starting with BRAIN2 3.09, the setup no
longer executes …

CWE: CWE-276
NVD

HIGH
CVE-2026-65693
CVE-2026-65693
pkg: express

published: Jul 24, 2026

Microweber CMS through 2.0.20 contains a server-side template injection vulnerability that allows authenticated administrators to achieve arbitrary OS command execution by injecting Twig expressions into mail templates. Attackers can exploit the unsandboxed Twig environment in TwigView::render(), wh…
CWE: CWE-94
NVD

HIGH
CVE-2026-66138
CVE-2026-66138
pkg: python

published: Jul 24, 2026

In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic-Python-Agent via a maliciously constructed configuration, because the value of ntp_server is passed to a shell.
CWE: CWE-78
NVD

HIGH
CVE-2026-60396
CVE-2026-60396
pkg: go

published: Jul 21, 2026

Vulnerability in Oracle GoldenGate (component: Distribution Server executable). Supported versions that are affected are 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle GoldenGate. Successful attacks …
CWE: CWE-306
GitHub-GHSA

HIGH
Budibase: NoSQL injection in MongoDB integration: collection dump, $where JS exec, cross-collection pivot, arbitrary update/delete
GHSA-pmpg-2mxq-6xwr
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
## Summary

An end-user injection in Budibase's MongoDB datasource lets any BASIC app user bypass the builder's query-level access controls. Builders scope MongoDB reads per-user with bindings like `{"email": "{{ currentUser.email }}"}` so each app user only sees their own rows. Because the binding …

GitHub-GHSA

HIGH
Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials
GHSA-hq88-5×99-x3gf
pkg: github.com/cloudreve/Cloudreve/v4, github.com/cloudreve/Cloudreve/v3
eco: go
published: Jul 24, 2026
## Summary

Cloudreve 4.16.1 has an OAuth scope authorization bypass in the admin storage policy routes. An OAuth bearer token scoped to `Admin.Read` but not `Admin.Write` can call `POST /api/v4/admin/policy/oauth/signin` and update OneDrive storage policy credentials.

The route is inside the admin…

CVE-2026-55502
GitHub-GHSA

HIGH
Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids)
GHSA-x2ff-v5v8-m75m
pkg: open-webui
eco: pip
published: Jul 24, 2026
## Summary

Any authenticated user can overwrite the content of a message in a channel they do not belong to (including private and DM channels) by sending a chat completion request with a `channel:`-prefixed `chat_id` and a target `message_id`. The `channel:` path routes pipeline output through `_m…

CVE-2026-59714
GitHub-GHSA

HIGH
Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout
GHSA-855v-hq7w-jmjw
pkg: open-webui
eco: pip
published: Jul 24, 2026
## Summary

With Redis configured, Open WebUI supports JWT revocation: `POST /api/v1/auths/signout` (per-token `jti`) and OIDC back-channel logout (per-user `revoked_at`) record revocations in Redis, and HTTP auth (`get_current_user`) rejects revoked tokens with 401. The realtime authentication surf…

CVE-2026-59219
GitHub-GHSA

HIGH
Microsoft Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
GHSA-rg4h-fpcp-2qm8
pkg: Microsoft.OpenApi.Kiota, Microsoft.OpenApi.Kiota.Builder
eco: nuget
published: Jul 24, 2026
## Summary

Microsoft Kiota resolved OpenAPI `$ref`s by fetching remote `http(s)` URLs and reading local files
(including absolute / out-of-tree paths), inlining the referenced schema into the generated client.
Running `kiota generate` on a spec whose `$ref` pointed at an attacker/internal URL or an…

CVE-2026-59867
GitHub-GHSA

HIGH
@better-auth/stripe: cross-organization billing tampering in organization subscription actions
GHSA-h3rm-78g3-j7cp
pkg: @better-auth/stripe, @better-auth/stripe
eco: npm
published: Jul 24, 2026
### Am I affected?

You are affected if all of these are true:

– You use `@better-auth/stripe` from version 1.4.11 up to a patched version below. This covers the stable line through 1.6.20 and every 1.7.0 beta through 1.7.0-beta.9.
– The Stripe plugin has subscriptions turned on (`subscription.enab…

NVD

HIGH
CVE-2026-57767
CVE-2026-57767
pkg: go

published: Jul 23, 2026

Unauthenticated Cross Site Scripting (XSS) in WP Google Maps Pro <= 10.1.02 versions.
CWE: CWE-79
GitHub-GHSA

HIGH
Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface
GHSA-gx3v-q759-g323
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary

I'm reporting **two related TOTP one-time-use defects** in Gitea that survive the CVE-2021-45331 fix. The 2018 fix (PR #3878) introduced the `TwoFactor.LastUsedPasscode` field and added an in-memory inequality check on the web 2FA login path. That check works correctly in the single-req…

CVE-2026-20779
GitHub-GHSA

HIGH
Gitea: Repository Visibility Manipulation via Git Push Options
GHSA-8p9h-49rc-qgxj
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Repository Visibility Manipulation via Git Push Options

| Field | Value |
|——-|——-|
| **Affected File** | `routers/private/hook_post_receive.go` |
| **Affected Function** | `HookPostReceive()` |
| **Affected Lines** | 173–225 |
| **Prerequisite** | Attacker must have owner-level or ad…

CVE-2026-58437
GitHub-GHSA

HIGH
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
GHSA-2m9v-5q2g-58vq
pkg: gitea.dev
eco: go
published: Jul 21, 2026
## Summary

A user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object.

The issue appears to be …

CVE-2026-28740
NVD

HIGH
CVE-2026-21575
CVE-2026-21575
pkg: windows

published: Jul 21, 2026

This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.11 of Sourcetree for Mac and Sourcetree for Windows.

This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to execute arbitrary code which has high impa…

CWE: CWE-94
NVD

HIGH
CVE-2026-56623
CVE-2026-56623
pkg: windows

published: Jul 20, 2026

Path traversal on Windows in Apache MINA SSHD component sshd-git. Apache MINA SSHD is a Java library for client-side and server-side SSH.

A git server implemented with Apache MINA SSHD component sshd-git and running on Windows could allow an authenticated remote user access to git repositories …

CWE: CWE-22
GitHub-GHSA

HIGH
AWS API MCP Server Security Policy Bypass via Startup Initialization Failure
GHSA-29w2-fq35-v728
pkg: awslabs.aws-api-mcp-server
eco: pip
published: Jul 24, 2026
## Summary
The AWS API MCP Server is an open source Model Context Protocol (MCP) server that enables AI assistants to interact with AWS services and resources through AWS CLI commands. It provides programmatic access to manage your AWS infrastructure while maintaining proper security controls. It in…
CVE-2026-16584
GitHub-GHSA

HIGH
GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)
GHSA-3rp5-jjmw-4wv2
pkg: gitpython
eco: pip
published: Jul 24, 2026
### Summary

In GitPython `<= 3.1.52`, the config writer neutralizes only CR, LF, and NUL in configuration **names**, but writes section names into the `[…]` header with no other escaping. A section/subsection name that contains `] [ "` closes the intended header and opens a second same-line secti…

NVD

HIGH
CVE-2026-64222
CVE-2026-64222
pkg: linux

published: Jul 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

octeontx2-pf: avoid double free of pool->stack on AQ init failure

otx2_pool_aq_init() frees pool->stack when mailbox sync or retry
allocation fails, but leaves the pointer unchanged. Later,
otx2_sq_aura_pool_init() unwinds the par…

NVD

HIGH
CVE-2026-64219
CVE-2026-64219
pkg: linux

published: Jul 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async

[Why&How]
dc_process_dmub_aux_transfer_async() copies payload->length bytes into a
16-byte stack buffer (dpaux.data[16]) guarded only by…

GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-50526 – .NET Tampering Vulnerability
GHSA-55jh-fwmh-39m4
pkg: Microsoft.NET.Build.Containers, Microsoft.NET.Build.Containers, Microsoft.NET.Build.Containers
eco: nuget
published: Jul 21, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET SDK (Microsoft.NET.Build.Containers). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A tampering vulner…

CVE-2026-50526
GitHub-GHSA

HIGH
etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline
GHSA-6vch-q96h-7gc3
pkg: go.etcd.io/etcd/v3, go.etcd.io/etcd/v3, go.etcd.io/etcd/v3
eco: go
published: Jul 24, 2026
### Impact
_What kind of vulnerability is it? Who is impacted?_

A network attacker who can reach an etcd TLS listener can open many TCP connections and never send a ClientHello. Each connection spawns a goroutine in the etcd server process that blocks indefinitely inside tls.Conn.Handshake(), and e…

GitHub-GHSA

HIGH
etcd: Watch API authorization bypass via open-ended range requests
GHSA-xg4h-6gfc-h4m8
pkg: go.etcd.io/etcd/v3, go.etcd.io/etcd/v3, go.etcd.io/etcd/v3
eco: go
published: Jul 24, 2026
### Impact
_What kind of vulnerability is it? Who is impacted?_

A user granted READ permission on a single, exact key can use the Watch gRPC API with `clientv3.WithFromKey()` (an open-ended, "from this key to the end of the keyspace" watch) to receive watch events for every key lexicographically gr…

GitHub-GHSA

HIGH
Shescape: Quadratic-time denial of service in the flag-protection
GHSA-gm3r-q2wp-hw87
pkg: shescape, shescape
eco: npm
published: Jul 24, 2026
### Impact

This impacts users of Shescape that have flag protection enabled, which is on by default, regardless of the API being used.

An attacker can cause a runtime quadratic in the input size, causing denial of service for large inputs.

“`javascript
import { Shescape } from "shescape";

// 1.…

GitHub-GHSA

HIGH
vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review
GHSA-47w6-gwp4-w6vc
pkg: vantage6
eco: pip
published: Jul 24, 2026
### Impact
Edit permission lacks ownership check, so another developer could alter metadata that is later trusted by nodes.

Worst they could do is update the image or image tag. If that is not noted, another image is approved than the one actually under review

### Patches
No

### Workarounds
No

GitHub-GHSA

HIGH
frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow
GHSA-26gq-p25f-99cp
pkg: github.com/fatedier/frp
eco: go
published: Jul 24, 2026
## Summary

An integer-overflow vulnerability in the frp server's optional SSH Tunnel Gateway lets any unauthenticated remote attacker crash the entire `frps` process with a single five-byte message. When the gateway parses an SSH `exec` channel request in `pkg/ssh/server.go`, it adds a small consta…

GitHub-GHSA

HIGH
Budibase: Server Filesystem Existence/Read Oracle via Builder-Controlled MongoDB tlsCertificateKeyFile
GHSA-ppr4-5f46-j9c6
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
## Summary
When creating a MongoDB datasource, Budibase passes the `tlsCertificateKeyFile` and `tlsCAFile` fields straight to the MongoDB driver as server-side file paths. On Budibase Cloud a customer cannot place files on the server, so these fields only let a builder reference arbitrary absolute p…
GitHub-GHSA

HIGH
Budibase: Email Change IDOR via POST /api/v2/email allows full Account Takeover (accountId not validated against session)
GHSA-c8vc-7pv3-g98p
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
## Summary

`POST /api/v2/email` on the account portal (`account.budibase.app`) starts an email-change workflow using a client-supplied `accountId` that is **not validated against the authenticated session**. A logged-in attacker supplies a victim's `accountId` and an email address they control; the…

GitHub-GHSA

HIGH
Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution
GHSA-7835-87q9-rgvv
pkg: @anthropic-ai/claude-code
eco: npm
published: Jul 24, 2026
Claude Code's worktree handling allowed creation of worktrees named ".git" and navigation to worktrees outside the sandbox context, enabling git directory confusion attacks. By exploiting symlink manipulation and git fsmonitor execution during worktree operations, an attacker could overwrite files i…
CVE-2026-55607
GitHub-GHSA

HIGH
React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response
GHSA-qwww-vcr4-c8h2
pkg: react-router
eco: npm
published: Jul 24, 2026
This is a follow up to CVE-2026-22030 to address related CSRF flows in unstable RSC code paths.

> [!NOTE]
> This only affects your application if you are using the unstable RSC APIs

GitHub-GHSA

HIGH
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
GHSA-4vv7-jj25-4gh6
pkg: Microsoft.OpenApi.Kiota, Microsoft.OpenApi.Kiota.Builder
eco: nuget
published: Jul 24, 2026
### Summary

Microsoft Kiota emitted the `x-ms-kiota-info` extension's `clientClassName` or `clientNamespaceName` value
**raw**, with no identifier or path sanitization, as **both** the generated client's class/namespace name
**and** part of the generated output path. When `kiota generate` is run **…

CVE-2026-59866
GitHub-GHSA

HIGH
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
GHSA-4rj6-vrwv-wr8m
pkg: Microsoft.OpenApi.Kiota, Microsoft.OpenApi.Kiota.Builder
eco: nuget
published: Jul 24, 2026
### Summary

Microsoft Kiota honors a poisoned `.kiota/workspace.json` — the workspace configuration that Kiota's
documented team workflow has developers commit to their repository — **unvalidated** on
`kiota client generate` / `kiota plugin generate`. A repository (or pull request) containing a…

CVE-2026-59863
GitHub-GHSA

HIGH
Microsoft Kiota: Code Generation Literal Injection in Kiota PHP Generator
GHSA-jqwh-526h-c92j
pkg: Microsoft.OpenApi.Kiota, Microsoft.OpenApi.Kiota.Builder
eco: nuget
published: Jul 24, 2026
# Impact

The Kiota PHP code generator is vulnerable to a code generation literal injection attack. The generator embeds string values from OpenAPI fields (e.g. `description`, default values, and property names) directly into PHP double-quoted string literals without properly escaping the `$` charac…

CVE-2026-59859
GitHub-GHSA

HIGH
Microsoft Kiota: XML Doc-Comment Newline Breakout Code Injection
GHSA-3hrf-2gc2-mx32
pkg: Microsoft.OpenApi.Kiota, Microsoft.OpenApi.Kiota.Builder
eco: nuget
published: Jul 24, 2026
### Summary

Kiota versions **prior to 1.32.3** are affected by a code-generation injection vulnerability in the C# XML documentation-comment sink (the `description`, `externalDocs` label, and `externalDocs` link fields emitted as `/// …` comments).

When text from an OpenAPI description is writte…

CVE-2026-59860
GitHub-GHSA

HIGH
React Router: Unauthenticated Denial of Service via Inefficient Route Matching
GHSA-chx6-hx7r-mcp5
pkg: react-router
eco: npm
published: Jul 24, 2026
This is a follow up to https://github.com/remix-run/react-router/security/advisories/GHSA-8x6r-g9mw-2r78 that covers additional reported scenarios in which the manifest endpoint could be accessed via unauthenticated targeted requests that would put heavy load on the server and slow down response tim…
CVE-2026-55685
GitHub-GHSA

HIGH
LiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce
GHSA-g357-x5c3-c72p
pkg: liquidjs
eco: npm
published: Jul 24, 2026
# `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce

**CWE**: CWE-770 (Allocation of Resources Without Limits or Throttling) — sibling class of GHSA-8xx9-69p8-7jp3 and GHSA-2546-xv4c-mc8g, applied to `memoryLimit` instead of `renderLimit`

## Summary

The `pop` …

CVE-2026-55575
GitHub-GHSA

HIGH
electron-updater: Cross-origin redirect leaks `PRIVATE-TOKEN` and mixed-case `Authorization` credentials in `builder-util-runtime`
GHSA-p2f4-r6v6-j797
pkg: builder-util-runtime
eco: npm
published: Jul 24, 2026
## Summary

In `electron-builder`'s `builder-util-runtime` package, the HTTP redirect handler (`HttpExecutor.prepareRedirectUrlOptions`) only stripped a credential header whose key string matched exactly lowercase `"authorization"`. Other credential-bearing headers — most notably `PRIVATE-TOKEN` (…

CVE-2026-54673
GitHub-GHSA

HIGH
pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)
GHSA-g867-7843-wf8q
pkg: pypdf
eco: pip
published: Jul 23, 2026
### Impact

An attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires parsing the content stream of a page with a not terminated inline image, as done when extracting the page text for example. It only affects the ASCII85 and ASCIIHex filters.

### Patche…

CVE-2026-59935
GitHub-GHSA

HIGH
pypdf: Possible infinite loop for not terminated inline images
GHSA-5xf7-4p34-54qr
pkg: pypdf
eco: pip
published: Jul 23, 2026
### Impact

An attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires parsing the content stream of a page with a not terminated inline image, as done when extracting the page text for example.

### Patches

This has been fixed in [pypdf==6.14.1](https://…

CVE-2026-59936
GitHub-GHSA

HIGH
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
GHSA-pppj-hq3g-57pj
pkg: jupyterlab, jupyterlab
eco: pip
published: Jul 22, 2026
JupyterLab 4.5+ allows notebook settings to be shared and applied through an `overrides.json` file using the `Import` button in the Settings Editor.

Certain notebook display settings were not properly validated before being applied. As a result, a crafted settings file could contain hidden instruct…

GitHub-GHSA

HIGH
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
GHSA-gx64-gj6p-pc4c
pkg: jupyterlab, jupyterlab
eco: pip
published: Jul 22, 2026
JupyterLab's image viewer allows for cross-site scripting (XSS) when a specially-crafted image file is opened through the image viewer and then opened in a new tab. This XSS issue can be used to cause remote code execution (RCE) on the JupyterLab server.

### Impact

This vulnerability allows for ar…

GitHub-GHSA

HIGH
Next.js: Server-Side Request Forgery in Server Actions on custom servers
GHSA-89xv-2m56-2m9x
pkg: next, next
eco: npm
published: Jul 22, 2026
## Impact

When a Server Action forwards or redirects a request, an attacker can cause the server to send that outbound request to a malicious host (Server-Side Request Forgery). This requires the attacker's request to control Host-associated headers. In some configurations, it's also possible to ob…

CVE-2026-64649
GitHub-GHSA

HIGH
Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname
GHSA-p9j2-gv94-2wf4
pkg: next, next
eco: npm
published: Jul 22, 2026
## Impact

A `rewrites()` or `redirects()` rule that builds its external destination hostname from request-controlled input can be pointed at an arbitrary hostname, regardless of the rule's hostname suffix. For a rewrite, Next.js proxies the request to that arbitrary host and serves the response fr…

CVE-2026-64645
GitHub-GHSA

HIGH
Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale
GHSA-6gpp-xcg3-4w24
pkg: next
eco: npm
published: Jul 22, 2026
## Impact

Crafted requests targeting Next.js applications using App Router built with Turbopack and a **single** entry in `config.i18n.locales` can bypass middleware/proxy based authentication.

## Workarounds

If you cannot upgrade immediately, enforce authorization in the page's server-side data …

CVE-2026-64642
GitHub-GHSA

HIGH
Next.js: Denial of Service in App Router using Server Actions
GHSA-m99w-x7hq-7vfj
pkg: next, next
eco: npm
published: Jul 22, 2026
## Impact

Crafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processing of further requests in the same process.

## Workarounds

No workaround exists besides upgrading. Applications using Pages Router or not usi…

CVE-2026-64641
GitHub-GHSA

HIGH
Eclipse Jetty Digest Authentication: ISO-8859-1 lossy encoding allows authentication bypass via character substitution
GHSA-2fvj-hgj9-j2gr
pkg: org.eclipse.jetty:jetty-security, org.eclipse.jetty:jetty-security, org.eclipse.jetty:jetty-security
eco: maven
published: Jul 22, 2026
### Summary
The `DigestAuthentication.apply()` method in Jetty's HTTP client uses `getBytes(StandardCharsets.ISO_8859_1)` at three locations (lines 171, 179, 196) to compute Digest auth response hashes. ISO-8859-1 silently replaces any character above U+00FF (Chinese, Japanese, Cyrillic, Arabic, Emo…
CVE-2026-10050
GitHub-GHSA

HIGH
LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback
GHSA-7488-6r32-c95q
pkg: litellm
eco: pip
published: Jul 22, 2026
### Impact

LiteLLM's MCP Streamable HTTP endpoint could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.

The MCP auth handler supported OAuth2 passthrough for upstream MCP servers, but the fallback path could replace failed LiteLLM key va…

CVE-2026-59822
GitHub-GHSA

HIGH
n8n: Prototype Pollution via Dot-Notation Field Names Leads To Instance-Wide Denial of Service
GHSA-xwx6-jjhv-84p8
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact

The Edit Fields (Set) node assigned output fields through a dot-notation path setter without restricting the field name, so an authenticated user could name a field after an inherited built-in method path and corrupt a shared global in the main Node.js process. Because that global was use…

GitHub-GHSA

HIGH
n8n: Edit Image Node Format Injection Allows Arbitrary File Write
GHSA-xmc9-4f2h-jf9c
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact

The n8n Edit Image node passed its output format to the underlying image library without validation, so a crafted value could write bytes to a location outside the node's working directory. An authenticated user able to run workflows could use this to write arbitrary files in the n8n inst…

GitHub-GHSA

HIGH
n8n: Shared-Workflow Editor Can Exfiltrate Credentials via Inline Sub-Workflow JSON
GHSA-cj9h-qx8g-pq2g
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact

n8n's credential-access checks validated only a node's top-level credentials, not credentials referenced inside an Execute Sub-workflow node's inline workflow JSON. A member with editor access to a shared workflow could reference a credential they were not permitted to use inside that inl…

GitHub-GHSA

HIGH
n8n: Credential Authorization Bypass via Expression in HTTP Request Node `genericAuthType`
GHSA-6qc9-mqvw-jg7x
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact

An authenticated member with edit access to a shared workflow could reference another user's credential in an HTTP Request node while specifying the credential type through an expression. Because the pre-execution permission check compared the unresolved expression instead of the real cre…

GitHub-GHSA

HIGH
n8n: Expression sandbox escape via arrow-function bodies enabling command execution
GHSA-gv7g-jm28-cr3m
pkg: n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact

An authenticated user with permission to create or modify workflows could abuse crafted expressions using arrow functions to bypass the expression sandbox, triggering unintended system command execution on the host running n8n.

## Patches

The issue has been fixed in n8n versions 2.31.5 …

GitHub-GHSA

HIGH
n8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion
GHSA-2×35-3fw4-9jr4
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact

The n8n Send Email node did not enforce that its message fields were strings, so a crafted untrusted non-string value from a workflow expression could be treated by the underlying mail library as a file path or URL. This could allow disclosure of local files on the n8n host.

Exploitation…

GitHub-GHSA

HIGH
n8n: Authenticated code execution in the n8n Git node
GHSA-rcv6-pvrj-4xcg
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact

Authenticated n8n users with rights to create and execute workflows could achieve code execution on the n8n host. Using the Git node, under the default `git` security settings, by staging a crafted local repository, an attacker could cause `git` to run hooks, executing arbitrary commands …

GitHub-GHSA

HIGH
n8n: Git Node fetch/pull/pushTags Operations Bypass Sandbox Path Restriction
GHSA-gf29-4f56-r2jf
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact

Authenticated n8n users with workflow create/execute rights could use the Git node's fetch, pull, or push-tags operations to bypass the repository-path containment checks that already protected clone and push. By pointing an allowlisted remote configuration value at a local path outside t…

GitHub-GHSA

HIGH
n8n: Bypass "Allowed HTTP Request Domains" Credential Restriction in Multiple AI and LLM Nodes
GHSA-64xh-79j6-r5v8
pkg: n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact

The credential "Allowed HTTP Request Domains" allowlist was intended to restrict which hosts a credential's secret could be sent to, protecting shared credentials from users who could use but not view them. Several AI/LLM nodes did not enforce this allowlist when a user-supplied base or e…

GitHub-GHSA

HIGH
n8n: Account Takeover via Unverified Email Claim in Token Exchange Embed Login
GHSA-8342-988q-86cr
pkg: n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact

In an n8n instance, when a validly-signed incoming token was matched to a local account by its email claim, the service did not check that the trusted key's permitted role ceiling covered that account, nor that the email claim was verified. As a result, anyone able to obtain a token accep…

GitHub-GHSA

HIGH
n8n: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner
GHSA-35q8-9mj6-wjmf
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact
n8n's Enterprise SSO instance-role provisioning maps a role claim asserted by the configured Identity Provider (IdP) to an n8n global role and applies it during authentication. The provisioning path did not prevent assignment of the `global:owner` role, unlike the token-exchange identity p…
CVE-2026-65016
GitHub-GHSA

HIGH
n8n: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution
GHSA-pm35-fqvh-cq5g
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact
The legacy expression evaluator's computed-member sanitizer can be bypassed by an authenticated user with workflow create or modify permissions. Successful exploitation grants the attacker host-level code execution as the n8n process.

The legacy expression engine is the default engine in …

CVE-2026-65591
GitHub-GHSA

HIGH
Netty: [Bzip2Decoder] Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang
GHSA-558v-64gr-wgg4
pkg: io.netty:netty-codec-compression, io.netty:netty-codec
eco: maven
published: Jul 22, 2026
The `Bzip2Decoder` handler in Netty's compression codec pipeline is vulnerable to a denial-of-service attack through a malformed bzip2 stream that permanently captures the event-loop thread in an infinite loop. The vulnerability exists in the run-length encoding (RLE) state machine within [`Bzip2Blo…
CVE-2026-59901
GitHub-GHSA

HIGH
Netty XML: Injection / Risky Sink — unconfigured XML factory with active DTD and entity handling
GHSA-4qhr-g3c6-fcfx
pkg: io.netty:netty-codec-xml, io.netty:netty-codec-xml
eco: maven
published: Jul 22, 2026
Any caller that can deliver bytes to a Netty channel pipeline containing `XmlDecoder` can send XML with a DOCTYPE declaration to a parser instantiated with no security configuration — but whether external entities are actually resolved depends on Aalto XML's async parser behavior, making this a co…
CVE-2026-56817
GitHub-GHSA

HIGH
Netty: [SpdyHttpDecoder] ByteBuf Reference Leak on RST_STREAM Leads to Native Memory Exhaustion
GHSA-jppx-w49h-x2qq
pkg: io.netty:netty-codec-http, io.netty:netty-codec-http
eco: maven
published: Jul 22, 2026
The `SpdyHttpDecoder` handler in Netty's SPDY-to-HTTP codec allocates a pooled `ByteBuf` when processing a client-initiated `SYN_STREAM` frame with `FLAG_FIN=0`, storing the partially-constructed `FullHttpRequest` in an internal map (`messageMap`) to accumulate subsequent `DATA` frames. When the rem…
CVE-2026-56745
GitHub-GHSA

HIGH
Netty: [codec-haproxy] Signed-Byte Sentinel Collision in HAProxyMessageDecoder Leads to Unbounded Memory Exhaustion
GHSA-q6cq-mhr2-jmr5
pkg: io.netty:netty-codec-haproxy, io.netty:netty-codec-haproxy
eco: maven
published: Jul 22, 2026
The `HAProxyMessageDecoder` in netty's `codec-haproxy` module performs protocol version detection by reading the 13th byte of the inbound stream as a signed Java `byte` and widening it to `int` without masking. When an attacker sends a PROXY protocol v2 binary prefix (`0D 0A 0D 0A 00 0D 0A 51 55 49 …
CVE-2026-55851
GitHub-GHSA

HIGH
gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
GHSA-hrxh-6v49-42gf
pkg: google.golang.org/grpc
eco: go
published: Jul 21, 2026
Multiple security vulnerabilities have been identified and addressed in grpc-go affecting the xDS RBAC authorization engine (internal/xds/rbac) and the HTTP/2 transport server implementation (internal/transport). These vulnerabilities could result in:

– Authorization Bypass (Fail-Open) when transla…

GitHub-GHSA

HIGH
jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
GHSA-r7wm-3cxj-wff9
pkg: com.fasterxml.jackson.core:jackson-core, com.fasterxml.jackson.core:jackson-core, com.fasterxml.jackson.core:jackson-core
eco: maven
published: Jul 21, 2026
## Summary

The fix released in jackson-core `2.18.6` and `2.21.1` for [GHSA-72hv-8253-57qq](https://github.com/FasterXML/jackson-core/security/advisories/GHSA-72hv-8253-57qq) (Number Length Constraint Bypass in Async Parser, published 2026-02-28) is incomplete. The fix commit `b0c428e6` (#1555) wir…

GitHub-GHSA

HIGH
Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts
GHSA-g9g6-qhrc-p3qc
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary

The OAuth2 sign-in callback in Gitea 1.26.1 unconditionally re-enables a locally-disabled account whenever the user authenticates through a linked external identity provider, silently undoing any administrator-initiated `Disable Account` action and issuing a fresh authenticated session …

CVE-2026-58422
GitHub-GHSA

HIGH
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests
GHSA-fw57-jgch-pgf3
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary

The Locale middleware that runs in front of every unauthenticated request
calls `golang.org/x/text/language.ParseAcceptLanguage` on the raw
`Accept-Language` header without imposing a size or shape filter. The
underlying parser has quadratic-time behaviour on long lists of malformed
lan…

CVE-2026-58436
GitHub-GHSA

HIGH
Gitea: Privilege Escalation via Access Token Scope Escalation in API
GHSA-683j-3ff6-hh2x
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
Gitea's API endpoint for creating Personal Access Tokens (`POST /users/{username}/tokens`) is protected by a middleware (`reqBasicOrRevProxyAuth`) that is intended to require password-based authentication, preventing a compromised token from being used to mint new ones. However, when a token is pass…
CVE-2026-56654
GitHub-GHSA

HIGH
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload
GHSA-6hm7-3pwj-22rm
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
Gitea's Debian package registry parser contains an unbounded decompression vulnerability in [ParseControlFile](https://github.com/go-gitea/gitea/blob/689ace1ce28fd74244b8aa335d9928cdbf6b22f9/modules/packages/debian/metadata.go#L140). When processing an uploaded `.deb` file, the parser decompresses `…
CVE-2026-56755
GitHub-GHSA

HIGH
GitPython unsafe clone option gate bypass through joined short options
GHSA-v396-v7q4-x2qj
pkg: GitPython
eco: pip
published: Jul 21, 2026
`GitPython` version `3.1.50` blocks unsafe `git clone` options such as `–upload-pack`, `-u`, `–config`, and `-c` unless callers explicitly pass `allow_unsafe_options=True`. However, the default unsafe-option gate does not recognize joined short-option forms such as `-u/path/to/helper`.

Git itself…

GitHub-GHSA

HIGH
websocket-driver-ruby: Denial of service via malformed Host header
GHSA-2×63-gw47-w4mm
pkg: websocket-driver
eco: rubygems
published: Jul 21, 2026
### Impact

If this library is used to implement a WebSocket server on top of a TCP server, by using the `WebSocket::Driver.server()` method, then a client can cause the server to crash by sending a `Host` header that is not a valid `host[:port]` string. When this happens, a `URI::InvalidURIError` e…

CVE-2026-61666
GitHub-GHSA

HIGH
PostgreSQL JDBC Driver: Silent channel-binding authentication downgrade via unsupported certificate algorithms
GHSA-j92g-9f8w-j867
pkg: org.postgresql:postgresql
eco: maven
published: Jul 21, 2026
### Impact

`channelBinding=require` connections can be silently downgraded from `SCRAM-SHA-256-PLUS` (with channel binding) to plain `SCRAM-SHA-256` (without it), losing the man-in-the-middle protection the setting is meant to guarantee. An attacker who can intercept the TLS connection triggers the…

CVE-2026-54291
GitHub-GHSA

HIGH
Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service
GHSA-vjc4-5qp5-m44j
pkg: pillow
eco: pip
published: Jul 20, 2026
### Summary
`src/libImaging/Jpeg2KDecode.c:853` accumulates `total_component_width` across every tile in a JPEG2000 image instead of recomputing it per tile. That accumulated value is then used in the `tile_bytes` calculation at `src/libImaging/Jpeg2KDecode.c:868`, which can make the decoder grow `s…
CVE-2026-59204
GitHub-GHSA

HIGH
Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)
GHSA-62p4-gmf7-7g93
pkg: pillow
eco: pip
published: Jul 20, 2026
## Summary

When Pillow loads an uncompressed image whose tile uses the `raw` codec and a mode in `Image._MAPMODES`, and the image was opened **from a filename**, it memory-maps the file and builds the image's row pointers directly into the mapping via `PyImaging_MapBuffer` (`src/map.c`). The per-ro…

CVE-2026-54058
GitHub-GHSA

HIGH
vLLM denial of service via prompt embeds on M-RoPE models
GHSA-33cg-gxv8-3p8g
pkg: vllm
eco: pip
published: Jul 20, 2026
### Summary
_Short summary of the problem. Make the impact and severity as clear as possible. For example: An unsafe deserialization vulnerability allows any unauthenticated user to execute arbitrary code on the server._

Sending a pure prompt embeds payload in a `/v1/completions` request with a mod…

CVE-2026-55514
GitHub-GHSA

MEDIUM
React Router: Open redirect leading to XSS
GHSA-jjmj-jmhj-qwj2
pkg: react-router-dom, react-router
eco: npm
published: Jul 23, 2026
Applications with open redirects could permit attacker crafted links to result in redirects to unexpected external location or XSS vectors.
CVE-2026-53668
GitHub-GHSA

MEDIUM
React Router: RSCErrorHandler Missing Protocol Validation (XSS)
GHSA-h8fp-f39c-q6mh
pkg: react-router
eco: npm
published: Jul 23, 2026
This is a follow up to https://github.com/remix-run/react-router/security/advisories/GHSA-8646-j5j9-6r62. React Router was alerted of a code path in the (unstable) RSC error handling path in which redirects from untrusted sources could still result in an XSS vector via attacker-supplied redirect ta…
CVE-2026-53667
GitHub-GHSA

MEDIUM
Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them
GHSA-x445-f3h2-j279
pkg: @auth/core, next-auth, next-auth
eco: npm
published: Jul 23, 2026
## Summary

Auth.js stores the OAuth/OIDC anti-CSRF checks (`state`, `nonce`, and the PKCE verifier) in global cookies that are not bound to the provider that created them. On callback, a check value minted during a sign-in started with one provider can satisfy the callback for a different provider,…

NVD

MEDIUM
CVE-2026-16615
CVE-2026-16615
pkg: oauth

published: Jul 22, 2026

A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated "code verifier" lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer th…
CWE: CWE-338
GitHub-GHSA

MEDIUM
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content
GHSA-66m4-5jjr-2rg5
pkg: gitea.dev
eco: go
published: Jul 21, 2026
## Affected product
Gitea — `services/repository/collaboration.go` (`DeleteCollaboration`) + webhook delivery

## Summary
When a collaborator with admin permission on a private repo creates a webhook, that webhook keeps firing
after the collaborator's access is revoked. Gitea's revocation cleanup …

CVE-2026-58440
GitHub-GHSA

MEDIUM
File Browser: Archive builder turns backslash filenames into path traversal (zip-slip)
GHSA-83xp-526h-j3ww
pkg: github.com/filebrowser/filebrowser/v2
eco: go
published: Jul 20, 2026
## Summary

The fix for `GHSA-gxjx-7m74-hcq8` / `CVE-2026-54093` (shipped in v2.63.6) added a `strings.ReplaceAll(nameInArchive, "\\", "/")` step to the archive builder; this was the advisory's recommended "Primary Fix." On a Linux host a backslash is a legal, non-separator filename character, so re…

CVE-2026-62843
NVD

MEDIUM
CVE-2026-60406
CVE-2026-60406
pkg: kubernetes

published: Jul 21, 2026

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where TimesTen In…
CWE: CWE-269
NVD

MEDIUM
CVE-2026-63729
CVE-2026-63729
pkg: node

published: Jul 21, 2026

The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedded by downstream consumers such as GNOME Evince contains a heap use-after-free vulnerability that allows attackers to crash applications or potentially execute arbitrary code by supplying a malformed .synctex or .synctex.gz file. …
CWE: CWE-416
GitHub-GHSA

MEDIUM
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API
GHSA-86cx-wwf4-phq4
pkg: github.com/OpenListTeam/OpenList/v4
eco: go
published: Jul 24, 2026
### Summary
An authorization bypass vulnerability exists in the file sharing mechanism of `Openlist`. Due to a flawed, non-separator-aware path validation check, an authenticated user can create share links for files outside their restricted base directory. This allows an attacker to bypass tenant/u…
GitHub-GHSA

MEDIUM
Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources
GHSA-c534-2w9c-x7fm
pkg: github.com/zxh326/kite
eco: go
published: Jul 24, 2026
## Summary

Kite versions 0.6.9 through 0.14.0 authorize Kubernetes proxy requests against the pod or service identified by the original route parameters. Encoded path traversal segments can cause the upstream URL to resolve to a different Kubernetes API endpoint after authorization.

## Impact

An …

GitHub-GHSA

MEDIUM
Cloudreve: Denial of Service – Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server
GHSA-g9j2-8w95-3vwv
pkg: github.com/cloudreve/Cloudreve/v4, github.com/cloudreve/Cloudreve/v3
eco: go
published: Jul 24, 2026
## Summary

Cloudreve's built-in image processor decodes user-supplied images with Go's standard-library decoders (`image/png`, `image/jpeg`, `image/gif`) and guards **only the compressed file size** — never the *decoded* pixel dimensions. Go's decoders allocate a pixel buffer sized `bytesPerPixel…

CVE-2026-55497
GitHub-GHSA

MEDIUM
Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config
GHSA-ffpj-xv5c-p3gw
pkg: open-webui
eco: pip
published: Jul 24, 2026
## Summary
Two regexes in `backend/open_webui/utils/middleware.py` that parse `<$skillId|label>` skill-mention tags backtrack in O(n²) on input that contains `<$` followed by a long run with no closing `>`. Both run synchronously, on the asyncio event loop, on **every** chat completion with no feat…
CVE-2026-59220
GitHub-GHSA

MEDIUM
Mongoose: Prototype pollution in mongoose update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter)
GHSA-664h-wqgq-64gw
pkg: mongoose, mongoose, mongoose
eco: npm
published: Jul 24, 2026
### Impact
_What kind of vulnerability is it? Who is impacted?_

Prototype pollution in update casting: passing a user-controlled update to a Mongoose update, like `MyModel.updateOne(filter, req.body)`, can cause Mongoose to set `$fullPath` and `$parentSchemaDocArray` on `Object.prototype`.

Example…

GitHub-GHSA

MEDIUM
LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges
GHSA-xx22-p4ch-683r
pkg: at.yawk.lz4:lz4-java, org.lz4:lz4-java
eco: maven
published: Jul 24, 2026
### Summary

Insufficient validation of byte array arguments in JNI-based XXHash implementations in lz4-java 1.11.0 and earlier allows callers to crash the JVM by passing an invalid array reference or invalid range to native XXHash methods.

This affects applications where an attacker can influence …

CVE-2026-59949
NVD

MEDIUM
CVE-2026-16798
CVE-2026-16798
pkg: oauth

published: Jul 24, 2026

Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with scoped job or script read permission to obtain another user's stored OAuth refresh token via job read responses that fail to strip t…
CWE: CWE-201
GitHub-GHSA

MEDIUM
Netty: STOMP CONNECT Frame Header Injection in Netty
GHSA-3g8r-4pfx-jmfh
pkg: io.netty:netty-codec-stomp, io.netty:netty-codec-stomp
eco: maven
published: Jul 22, 2026
# Security Vulnerability Report: STOMP CONNECT Frame Header Injection in Netty

## 1. Vulnerability Summary

| Field | Value |
|——-|——-|
| **Product** | Netty |
| **Version** | 4.2.12.Final (and all prior versions with codec-stomp) |
| **Component** | `io.netty.handler.codec.stomp.StompSubfr…

CVE-2026-59920
GitHub-GHSA

MEDIUM
Netty: Security Control Bypass via CORS Short-Circuit Failure
GHSA-6cqp-g7gg-8hr5
pkg: io.netty:netty-codec-http, io.netty:netty-codec-http
eco: maven
published: Jul 22, 2026
### Summary
Netty's CorsHandler provides a `shortCircuit()` configuration designed to reject unauthorized cross-origin requests immediately, acting as a security control before requests reach the application. However, due to a logical operator error in the origin evaluation process, this protection …
CVE-2026-56746
NVD

MEDIUM
CVE-2026-9737
CVE-2026-9737
pkg: express

published: Jul 22, 2026

During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly handle the meta expression case. This may lead to incorrect transformations leading to invariant failure.
CWE: CWE-617
NVD

MEDIUM
CVE-2026-13071
CVE-2026-13071
pkg: express

published: Jul 22, 2026

An authenticated user with read access can cause the mongod process to be terminated through certain aggregation expressions that execute server-side JavaScript. The issue involves improper memory handling during document processing.
CWE: CWE-416
NVD

MEDIUM
CVE-2026-13065
CVE-2026-13065
pkg: express

published: Jul 22, 2026

A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window function operator with a specific sortBy expression type to cause the mongod process to terminate abnormally, resulting in denial of service. The issue stems from insufficient validation of sort sp…
CWE: CWE-476
NVD

MEDIUM
CVE-2026-13056
CVE-2026-13056
pkg: express

published: Jul 22, 2026

Using expressions that generate large arrays it is possible to craft a query that creates very large intermediate objects in memory, causing the server to crash with OOM error.
CWE: CWE-1325
NVD

MEDIUM
CVE-2026-13055
CVE-2026-13055
pkg: express

published: Jul 22, 2026

The `$_internalIndexKey` aggregation expression can be used by any authenticated user to crash a MongoDB server (mongod). The expression fails to handle compound wildcard index specifications, triggering an internal consistency check that aborts the server process. The user must be able to run an ag…
CWE: CWE-617
NVD

MEDIUM
CVE-2026-13192
CVE-2026-13192
pkg: windows

published: Jul 22, 2026

In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of content submitted to the RadEditor PDF export feature may allow an authenticated attacker to trigger server-side requests to arbitrary hosts, resulting in outbound network connections and potential exposure of Windo…
CWE: CWE-918
NVD

MEDIUM
CVE-2026-63263
CVE-2026-63263
pkg: node

published: Jul 22, 2026

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Data Expansion (CAPEC-197). An authenticated user may submit a specially crafted query to the ES|QL engine that causes exponential CPU consumption during query evaluation. Because the resource …
CWE: CWE-400
NVD

MEDIUM
CVE-2026-63144
CVE-2026-63144
pkg: node

published: Jul 21, 2026

Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a specially crafted search request submitted by a low-privileged authenticated user. A user with read-level index access can submit a request that triggers unbounded recursive processing within the Elasticsearch quer…
CWE: CWE-674
NVD

MEDIUM
CVE-2026-60404
CVE-2026-60404
pkg: kubernetes

published: Jul 21, 2026

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTe…
CWE: CWE-400
NVD

MEDIUM
CVE-2026-60403
CVE-2026-60403
pkg: kubernetes

published: Jul 21, 2026

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTe…
CWE: CWE-400
NVD

MEDIUM
CVE-2026-60401
CVE-2026-60401
pkg: kubernetes

published: Jul 21, 2026

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where TimesTen In-…
CWE: CWE-284
NVD

MEDIUM
CVE-2026-60399
CVE-2026-60399
pkg: go

published: Jul 21, 2026

Vulnerability in Oracle GoldenGate (component: Receiver Service Executable). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle GoldenGate. Su…
CWE: CWE-400
NVD

MEDIUM
CVE-2026-10677
CVE-2026-10677
pkg: node

published: Jul 21, 2026

The CONFIG_USERSPACE syscall verifier z_vrfy_k_poll() in kernel/poll.c allocates a kernel-side copy of the user-supplied k_poll_event[] via z_thread_malloc() and then validates each event's object handle. Before this fix, validation used K_OOPS(K_SYSCALL_OBJ(…)) inline inside the loop, which kills…
CWE: CWE-401
GitHub-GHSA

MEDIUM
jackson-databind: @JsonView ypassed for @JsonUnwrapped container properties on deserialization
GHSA-5gvw-p9qm-jgwh
pkg: com.fasterxml.jackson.core:jackson-databind, tools.jackson.core:jackson-databind, com.fasterxml.jackson.core:jackson-databind
eco: maven
published: Jul 21, 2026
## Summary
`UnwrappedPropertyHandler.processUnwrapped()` replays the buffered JSON for a `@JsonUnwrapped` property by iterating its properties and calling `prop.deserializeAndSet()` with **no `prop.visibleInView(ctxt.getActiveView())` guard** — the exact guard `processUnwrappedCreatorProperties()`…
CVE-2026-59889
GitHub-GHSA

MEDIUM
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs
GHSA-frpw-3h2q-4jj6
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
**Author:** Prakhar Porwal
**Date:** 2026-05-24
**Target:** Gitea (self-hosted Git service)
**Branch tested:** `main` @ `b7e95cc48c` (development build, go1.26.3)
**Component:** `routers/api/v1/org/action.go` (org-level Actions API)
**OWASP:** API3:2023 Broken Object Property Level Authorization

–…

CVE-2026-57897
NVD

MEDIUM
CVE-2026-63140
CVE-2026-63140
pkg: node

published: Jul 21, 2026

Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted search request containing a null value in a specific query clause causes an internal assertion to be raised during query parsing. Because Elasticsearch treats ass…
CWE: CWE-617
NVD

MEDIUM
CVE-2026-63136
CVE-2026-63136
pkg: node

published: Jul 21, 2026

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A user with search privileges can submit a specially crafted search request that causes a data node to exhaust available heap memory, resulting in node unavailability and …
CWE: CWE-400
NVD

MEDIUM
CVE-2026-46556
CVE-2026-46556
pkg: python

published: Jul 21, 2026

FlaskBB is a Forum Software written in Python using the micro framework Flask. Prior to version 2.2.1, a Server-Side Request Forgery (SSRF) vulnerability in get_image_info() allows any authenticated user to force the server to send HTTP requests to arbitrary internal endpoints, including cloud metad…
CWE: CWE-918
NVD

MEDIUM
CVE-2026-16317
CVE-2026-16317
pkg: tls

published: Jul 21, 2026

Missing validation of the outer content_type byte on TLS 1.3 encrypted records in s2n-tls allows an active man-in-the-middle to silently discard individual application data records without either endpoint detecting the modification. RFC 8446 Section 5.2 requires that the outer content_type of all en…
CWE: CWE-354
GitHub-GHSA

MEDIUM
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint
GHSA-wwqq-x6w4-frm2
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary
An unbounded `io.ReadAll(ctx.Req.Body)` call in the NPM package tag API endpoint allows any authenticated user to crash the Gitea server by sending a single large HTTP request. The request body is read entirely into memory with no size limit, causing an Out-of-Memory (OOM) kill. With con…
CVE-2026-42931
GitHub-GHSA

MEDIUM
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass
GHSA-h2x6-g7q6-344v
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary

Gitea's repository migration URL validation can be bypassed when a migration hostname resolves to multiple IP addresses. The validation logic accepts the destination if **any** resolved IP is allowed, even if another resolved IP is loopback, private, or otherwise blocked. The later `git…

CVE-2026-58442
GitHub-GHSA

MEDIUM
Gitea: SSRF via HTTP Redirect in Repository Migration
GHSA-rqhx-647v-wx32
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
## Summary

Gitea 1.25.4 validates the initial URL provided to the repository migration endpoint (`POST /api/v1/repos/migrate`) and correctly blocks requests to internal addresses like `127.0.0.1` or RFC1918 ranges. However, if the initial URL points to an attacker-controlled server that responds wi…

CVE-2026-58418
GitHub-GHSA

MEDIUM
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
GHSA-25gq-j9jx-43pg
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
## Summary

The web handler `EditReleasePost` (`routers/web/repo/release.go`) reads form fields with prefix `attachment-edit-{uuid}` into a `map[uuid]newName`, passes that map to `release_service.UpdateRelease`, which writes the new name to the database via `repo_model.UpdateAttachmentByUUID` WITHOU…

CVE-2026-58428
NVD

MEDIUM
CVE-2026-56145
CVE-2026-56145
pkg: node

published: Jul 21, 2026

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user with permission to execute EQL sequence queries against an index they control can send a specially crafted query that triggers excessiv…
CWE: CWE-400
GitHub-GHSA

MEDIUM
jackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)`
GHSA-mhm7-754m-9p8w
pkg: com.fasterxml.jackson.core:jackson-databind, com.fasterxml.jackson.core:jackson-databind
eco: maven
published: Jul 21, 2026
## Summary

In `BeanDeserializer.deserializeUsingPropertyBasedWithExternalTypeId`, the active-view (`@JsonView`) filter was applied only to the regular bean-property branch; the creator-property branch performed no `creatorProp.visibleInView(activeView)` check. A constructor parameter annotated with…

GitHub-GHSA

MEDIUM
jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategy
GHSA-3pjw-73gf-8qr5
pkg: com.fasterxml.jackson.core:jackson-databind, com.fasterxml.jackson.core:jackson-databind, tools.jackson.core:jackson-databind
eco: maven
published: Jul 21, 2026
## Summary
For Java Records, `POJOPropertiesCollector._removeUnwantedIgnorals()` records a `@JsonIgnore`-annotated component under its original implicit name before `_renameUsing()` applies the `PropertyNamingStrategy`. After the rename, `_ignoredPropertyNames` still holds only the pre-rename name, …
CVE-2026-59888
GitHub-GHSA

MEDIUM
Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images
GHSA-fj7v-r99m-22gq
pkg: Pillow
eco: pip
published: Jul 20, 2026
### Summary

Pillow's TGA RLE encoder reads past its row buffer when saving a mode `"1"`
image. Adjacent process heap bytes can be copied into the generated TGA file.

The bug is reachable through the public save API:

“`python
im.save(out, format="TGA", compression="tga_rle")
“`

Older affected P…

CVE-2026-59198
GitHub-GHSA

MEDIUM
Microsoft Security Advisory CVE-2026-50659 – .NET Spoofing Vulnerability
GHSA-74jp-vm22-8q8x
pkg: Microsoft.NetCore.App.Runtime.linux-arm, Microsoft.NetCore.App.Runtime.linux-arm64, Microsoft.NetCore.App.Runtime.linux-musl-arm
eco: nuget
published: Jul 20, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET SMTP client (System.Net.Mail). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A spoofing vulnerability …

CVE-2026-50659
GitHub-GHSA

MEDIUM
Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses
GHSA-x756-g4x3-c64m
pkg: github.com/cloudreve/Cloudreve/v4, github.com/cloudreve/Cloudreve/v3
eco: go
published: Jul 20, 2026
## Summary

Cloudreve's remote download workflow accepts user-supplied URLs and passes them to the configured downloader without blocking loopback, localhost, IPv6 localhost, or redirect-to-loopback targets.

When the remote download permission is granted to a non-admin user group, a normal authenti…

CVE-2026-54562
NVD

MEDIUM
CVE-2026-63737
CVE-2026-63737
pkg: surrealdb surrealdb

published: Jul 20, 2026

SurrealDB versions before 3.1.5 contain a denial of service vulnerability where authenticated users can crash the server with queries containing long chains of operators. Attackers can submit queries with tens of thousands of chained operators that create unbounded expression trees, causing stack ov…
CWE: CWE-674
NVD

MEDIUM
CVE-2026-61217
CVE-2026-61217
pkg: ssl

published: Jul 21, 2026

Vulnerability in the Oracle Security Service product of Oracle Fusion Middleware (component: Oracle SSL API). The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows low privileged attacker with network access via TLS to compromise Oracle Security Service. …
CWE: CWE-284, CWE-290, CWE-352
GitHub-GHSA

MEDIUM
Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored
GHSA-c3jm-gv5r-9wcp
pkg: github.com/cloudreve/Cloudreve/v4, github.com/cloudreve/Cloudreve/v3
eco: go
published: Jul 24, 2026
## Summary

Cloudreve WOPI access tokens are generated as `<session-id>.<random-secret>`, but the WOPI middleware validates only the session id prefix and never compares the supplied token to the stored token. In addition, a WOPI viewer session does not store or enforce the requested viewer action. …

CVE-2026-62323
NVD

MEDIUM
CVE-2026-13067
CVE-2026-13067
pkg: tls

published: Jul 22, 2026

When PROXY protocol v2 is used on the Unix domain socket path, roles derived from X.509 client certificates may not be validated against the configured tlsCATrusts allow-list. This can result in unintended role assignments following MONGODB-X509 authentication. Affected scenarios require local acces…
CWE: CWE-863
GitHub-GHSA

MEDIUM
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)
GHSA-fj8v-hjwv-qm88
pkg: gitea.dev
eco: go
published: Jul 21, 2026
### Summary

`GetActionsUserRepoPermission` (`models/perm/access/repo_permission.go`) decides whether an Actions
task token may access a target repo. Its cross-repo branches each enforce a fork-PR discriminator —
**except the collaborative-owner branch**, which is missing the `!task.IsForkPullRequ…

CVE-2026-58416
GitHub-GHSA

MEDIUM
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL
GHSA-xmj7-xj85-hfc3
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary
Gitea's `restore-repo` CLI command restores a repository from a dump
directory/archive. When parsing `pull_request.yml` from that dump, the
`Head.CloneURL` field is used to add a git remote and fetch from it with
no validation, because the safety check that's supposed to guard it
(`Check…
CVE-2026-58441
NVD

MEDIUM
CVE-2026-46403
CVE-2026-46403
pkg: go

published: Jul 21, 2026

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, KVM exposes `ExecuteReadOnlyWithTypedArguments` as a read-only execution mechanism. The hook saves the previous read-only state, sets `runtime.SetReadOnly(true)`, executes the destination context, and then restore…
CWE: CWE-693
GitHub-GHSA

MEDIUM
File Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scope
GHSA-8wc8-hf36-mjh9
pkg: github.com/filebrowser/filebrowser/v2
eco: go
published: Jul 20, 2026
## Summary

`ScopedFs` confines every File Browser user to a scope directory. Its `within()` guard is meant to reject any operation that follows a symbolic link out of that scope. When the link target does not exist yet, the guard walks up to the nearest existing ancestor and validates that instead.…

CVE-2026-55668
GitHub-GHSA

MEDIUM
Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data
GHSA-fwjx-9p69-h25h
pkg: github.com/jandedobbeleer/oh-my-posh
eco: go
published: Jul 24, 2026
### Summary
Oh My Posh renders dynamic, potentially attacker-controlled strings (the current directory name, Git commit metadata, environment variable values, command output) into the prompt without neutralizing raw terminal control characters. An attacker who controls one of these values can inject…
GitHub-GHSA

MEDIUM
OpenAM Reflected XSS in the OAuth2/OIDC `wap` consent page
GHSA-vqxv-6xrh-49cp
pkg: org.openidentityplatform.openam:openam-oauth2
eco: maven
published: Jul 24, 2026
### Description
The OAuth2/OIDC consent page rendered for `display=wap` authorize requests reflected several request-derived values into the HTML response without escaping. An attacker who induces a user with an active OpenAM session to follow a crafted authorize link can execute arbitrary JavaScrip…
CVE-2026-62280
GitHub-GHSA

MEDIUM
ImageMagick: Policy Bypass in concatenate operation due to missing checks
GHSA-82mp-vp5c-9pf7
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Jul 24, 2026
The `-concatenate` operation is missing policy checks and that could result in both reading and writing to paths disallowed by the security policy.
CVE-2026-55628
GitHub-GHSA

MEDIUM
React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration
GHSA-337j-9hxr-rhxg
pkg: react-router
eco: npm
published: Jul 23, 2026
If application code allows attacker supplied input to overwrite certain aspects of errors caught by the SSR process, then it was possible for attacker to trigger unexpected constructor execution on the client which would trigger outbound network traffic. This is only possible with very specific (an…
CVE-2026-53666
NVD

MEDIUM
CVE-2026-65901
CVE-2026-65901
pkg: node

published: Jul 23, 2026

DOMPurify through 3.4.6 contains a cross-site scripting vulnerability in IN_PLACE mode that trusts attacker-controlled nodeName on live non-form nodes. Attackers can supply hostile live DOM objects with real script children whose observable nodeName is clobbered to appear as allowed elements, causin…
CWE: CWE-79
NVD

MEDIUM
CVE-2026-65900
CVE-2026-65900
pkg: express

published: Jul 23, 2026

DOMPurify versions >=3.0.0 and before 3.4.8, when configured with SAFE_FOR_TEMPLATES together with a DOM output mode (RETURN_DOM, RETURN_DOM_FRAGMENT, or IN_PLACE), fail to strip template expressions (e.g. ${evil}, {{evil}}, <%evil%>) inside <template> element content. The final normalization/scrub …
CWE: CWE-79
GitHub-GHSA

MEDIUM
setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+
GHSA-h35f-9h28-mq5c
pkg: setuptools
eco: pip
published: Jul 21, 2026
## Summary

When building a source distribution (`python -m build –sdist` / `setup.py sdist`), setuptools' `FileList` applies `MANIFEST.in` directives (`exclude`, `global-exclude`, `recursive-exclude`, `prune`) by matching a compiled glob against on-disk file names **byte-for-byte, with no Unicode …

CVE-2026-59890
GitHub-GHSA

MEDIUM
Mistune renderers/html.safe_url: HARMFUL_PROTOCOLS list misses legacy and chained schemes that historically chain to `javascript:` execution
GHSA-qfrw-5rxm-mhh2
pkg: mistune
eco: pip
published: Jul 20, 2026
## Summary

**Type:** URL-scheme allowlist gap. The `safe_url` filter only blocks the four schemes `javascript:`, `vbscript:`, `file:`, `data:`. Several other schemes are accepted into rendered `<a href="…">` and `<img src="…">` tags despite being known XSS vectors in legacy or chain-handling br…

CVE-2026-59929
GitHub-GHSA

MEDIUM
Mistune: XSS via percent-encoded javascript URI bypass in safe_url()
GHSA-8c25-4j27-2rv3
pkg: mistune
eco: pip
published: Jul 20, 2026
### Summary
An XSS vulnerability in Mistune allows bypassing of safe_url() protections via percent-encoded javascript URIs.

### Details
The vulnerability exists in HTMLRenderer.safe_url() in Mistune.

The function is intended to block harmful URL schemes such as "javascript:" by checking the prefi…

CVE-2026-59923
GitHub-GHSA

MEDIUM
FrontMCP: Server-Side Request Forgery (SSRF) in the OpenAPI adapter spec-change poller
GHSA-8q49-2h5h-434x
pkg: @frontmcp/adapters
eco: npm
published: Jul 24, 2026
## Summary

The OpenAPI adapter's spec-change **poller** (`OpenApiSpecPoller`) re-fetched the
configured spec `url` on a timer using a raw global `fetch()`, bypassing the SSRF
guard (`safeFetch` / `assertUrlSafe`) that `OpenAPIToolGenerator.fromURL()` applies
to the initial spec load. As a result, t…

NVD

MEDIUM
CVE-2026-55990
CVE-2026-55990
pkg: nlnetlabs unbound

published: Jul 22, 2026

In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' clause lists more 'dnscrypt-provider-cert:' files than there are matching 'dnscrypt-secret-key:' files, Unbound fills only the matched prefix and leaves the tail slots at the '0xdb' fill that libsodium's allocator writes in…
CWE: CWE-457
NVD

MEDIUM
CVE-2026-50046
CVE-2026-50046
pkg: nlnetlabs unbound

published: Jul 22, 2026

In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS server name used for DNS-over-TLS (DoT) forwarded queries is tied to a struct's ('serviced_query') lifetime but also referenced by another struct ('waiting_tcp'). When the owning struct is jostled out of the mesh while the DoT TCP stre…
CWE: CWE-416
NVD

MEDIUM
CVE-2026-60266
CVE-2026-60266
pkg: tls

published: Jul 21, 2026

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Orac…
CWE: CWE-200
NVD

MEDIUM
CVE-2026-46968
CVE-2026-46968
pkg: tls

published: Jul 21, 2026

Vulnerability in Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit vulnerability allo…
CWE: CWE-284
GitHub-GHSA

MEDIUM
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content
GHSA-6c6r-5xr4-cr5m
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
## Summary

Gitea's issue and comment attachment update paths accept attachment UUIDs without verifying that each attachment belongs to the target issue/comment repository. If an authenticated attacker knows a victim attachment UUID, they can re-link that attachment to an attacker-controlled issue o…

CVE-2026-57886
GitHub-GHSA

MEDIUM
Gitea: draft release attachment disclosure via missing web authorization
GHSA-q9pg-jj6x-j9p6
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary

Gitea's draft-release access control is enforced only on the API release endpoints (`/api/v1/repos/{owner}/{repo}/releases/{id}` and its `/assets/…` sub-routes) but not on the web-level UUID-based attachment endpoints (`/attachments/{uuid}`, `/{owner}/{repo}/attachments/{uuid}`, `/{ow…

CVE-2026-58432
NVD

MEDIUM
CVE-2026-59847
CVE-2026-59847
pkg: openssl

published: Jul 21, 2026

A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection.
CWE: CWE-1310
GitHub-GHSA

MEDIUM
Mistune: Arbitrary File Read via Include directive path traversal
GHSA-r4rv-85jg-w4mf
pkg: mistune
eco: pip
published: Jul 20, 2026
### Summary

A path traversal issue exists in mistune's `Include` directive when markdown files are processed using `md.read()`. A crafted include path can cause files outside the intended markdown directory to be accessed.

### Details

The issue occurs in the `Include.parse()` method where user-su…

CVE-2026-59924
NVD

MEDIUM
CVE-2026-45712
CVE-2026-45712
pkg: go

published: Jul 20, 2026

Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the screenshot/print proxy (/proxy?data=…) maintains a package-level assets map[string]MessageAssets cache, but reads the map without holding assetsMutex while a long-running cleanup goroutine and (re-entrant) CSS-re…
CWE: CWE-362, CWE-770
NVD

MEDIUM
CVE-2026-63226
CVE-2026-63226
pkg: node

published: Jul 23, 2026

Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement restrictions on SSH port forwarding, allowing to connect to arbitrary destinations. When SSH is enabled on an affected product, SSH port forwarding may be leveraged to connect to other node on the LAN.
CWE: CWE-923
NVD

MEDIUM
CVE-2026-61079
CVE-2026-61079
pkg: go

published: Jul 21, 2026

Vulnerability in Oracle GoldenGate (component: Libraries). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.2. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle GoldenGate executes to compromise …
CWE: CWE-20, CWE-284, CWE-362
GitHub-GHSA

MEDIUM
Budibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other Builders
GHSA-gh4h-34gr-87r7
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
## Summary

When an SSO-authenticated user tests an automation in the Budibase builder, their OAuth2 access token and refresh token are included in the automation test results. These results are broadcast via WebSocket to all builders connected to the same dev app and stored in an in-memory cache ac…

GitHub-GHSA

MEDIUM
ImageMagick: Code injection in HTML encoder due to incomplete fix of CVE-2026-25797
GHSA-hc76-7mpc-qjqh
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Jul 24, 2026
An incomplete fix of CVE-2026-25797 can result in code injection in the HTML encoder.
GitHub-GHSA

MEDIUM
Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder
GHSA-gcjf-9mgh-3p7g
pkg: io.netty:netty-codec-http, io.netty:netty-codec-http
eco: maven
published: Jul 22, 2026
# Security Vulnerability Report: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder

## 1. Vulnerability Summary

| Field | Value |
|——-|——-|
| **Product** | Netty |
| **Version** | 4.2.12.Final (and all prior versions with codec-http multipart) |
| **Component** | `io.net…

CVE-2026-59921
NVD

MEDIUM
CVE-2026-60409
CVE-2026-60409
pkg: kubernetes

published: Jul 21, 2026

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where TimesTen In…
CWE: CWE-284
GitHub-GHSA

MEDIUM
Quasar: Prototype pollution in the extend() utility
GHSA-3r53-75j5-3g7j
pkg: quasar
eco: npm
published: Jul 24, 2026
### Summary

`quasar@2.20.1`, the latest published version at the time of testing, appears to be vulnerable to prototype pollution through the public `extend()` utility exported from the package root.

When `extend(true, target, source)` is used for a deep merge, attacker-controlled object keys are …

NVD

MEDIUM
CVE-2026-60407
CVE-2026-60407
pkg: kubernetes

published: Jul 21, 2026

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where TimesTen I…
CWE: CWE-284
GitHub-GHSA

MEDIUM
AWS CLI: Overly permissive File Permissions
GHSA-wfp6-f47h-hxc3
pkg: awscli
eco: pip
published: Jul 24, 2026
### Summary
The AWS Command Line Interface (AWS CLI) is a unified tool for managing AWS services from the command line. Certain CLI subcommands wrote credential and configuration files with world-readable permissions on Unix-like systems with a default umask, allowing other local users on the same h…
CVE-2026-13769
GitHub-GHSA

MEDIUM
ImageMagick: Heap Buffer Over-Write in JP2 encoder when due to incorrect handling of arguments
GHSA-c4v7-w88g-m6c4
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Jul 24, 2026
Due to incorrect handling of arguments a heap buffer over-write can occur in the JP2 encoder.
CVE-2026-55597
GitHub-GHSA

MEDIUM
ImageMagick: Use-After-Free in crafted 8BIM when identifying an image
GHSA-ff5c-8x9r-8qcw
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Jul 24, 2026
When identifying an image with a crafted 8BIM profile with a specific format string a use-after-free will occur.
CVE-2026-55510
NVD

MEDIUM
CVE-2026-54422
CVE-2026-54422
pkg: python

published: Jul 24, 2026

In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.
CWE: CWE-522
GitHub-GHSA

MEDIUM
Netty: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address
GHSA-wh89-7897-x99h
pkg: io.netty:netty-codec-haproxy, io.netty:netty-codec-haproxy
eco: maven
published: Jul 22, 2026
# Security Vulnerability Report: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address in Netty

## 1. Vulnerability Summary

| Field | Value |
|——-|——-|
| **Product** | Netty |
| **Version** | 4.2.12.Final (and all prior versions with codec-haproxy) |
| **Component** | `io.netty.handler.co…

CVE-2026-59919
GitHub-GHSA

MEDIUM
Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests
GHSA-v6w6-358x-2433
pkg: github.com/cloudreve/Cloudreve/v4, github.com/cloudreve/Cloudreve/v3
eco: go
published: Jul 24, 2026
## Summary

Cloudreve exposes two admin node test endpoints under the `Admin.Read` OAuth scope. These endpoints accept attacker-controlled node definitions and cause Cloudreve to make outbound server-side network requests. This allows an OAuth client authorized only for `Admin.Read` to trigger opera…

GitHub-GHSA

MEDIUM
Open WebUI: Arena task endpoints can bypass underlying model access controls
GHSA-m3qf-58wf-w979
pkg: open-webui
eco: pip
published: Jul 24, 2026
## Summary

An authenticated non-admin user with read access to an arena wrapper model can reach a restricted underlying model through task endpoints such as `/api/v1/tasks/moa/completions`.

The normal chat route resolves arena models before the final chat dispatch and therefore re-checks the selec…

CVE-2026-59225
GitHub-GHSA

MEDIUM
Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete
GHSA-2xwm-4h2q-ggfx
pkg: open-webui
eco: pip
published: Jul 24, 2026
## Summary

Current `main` and `v0.9.6` still allow an authenticated user to turn read-only access to another user's file into write/delete access by attaching that file ID to an attacker-controlled workspace model.

This is an incomplete-fix variant of `GHSA-vjqm-6gcc-62cr`. The current fix adds `_…

CVE-2026-59212
NVD

MEDIUM
CVE-2026-57530
CVE-2026-57530
pkg: node

published: Jul 24, 2026

Milkdown before 7.21.3 contains a stored cross-site scripting vulnerability in the @milkdown/preset-commonmark and @milkdown/components packages that allows attackers with document write access to execute arbitrary JavaScript in the browser context of any user who opens the document or clicks a rend…
CWE: CWE-79
NVD

MEDIUM
CVE-2026-16415
CVE-2026-16415
pkg: google chrome

published: Jul 21, 2026

Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-20
GitHub-GHSA

MEDIUM
Gitea LFS Deploy-Key Privilege Escalation
GHSA-rh79-75qm-gwjr
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
## Vulnerability Header

| Field | Value |
| ——————- | ———————————————————– |
| Vulnerability Title | Gitea LFS Deploy-Key Privilege Escalation |
| Severity Rating…

CVE-2026-58435
NVD

MEDIUM
CVE-2026-47671
CVE-2026-47671
pkg: jwt

published: Jul 21, 2026

Nhost is an open source Firebase alternative with GraphQL. In versions of Nhost CLI prior to 1.46.0, the hidden `nhost configserver` used by `nhost dev` exposes the Mimir GraphQL API with dummy authorization directives and permissive CORS. When a developer is running the local development environmen…
CWE: CWE-306
GitHub-GHSA

MEDIUM
Tornado vulnerable to Header Injection and XSS via reason argument
GHSA-pr2v-jx2c-wg9f
pkg: tornado
eco: pip
published: Jul 20, 2026
# Header injection and XSS via `reason` argument

## Summary

The `reason` argument (used by both `RequestHandler.set_status` and `tornado.web.HTTPError` is designed to allow applications to pass custom "reason" phrases (the "Not Found" in `HTTP/1.1 404 Not Found`) to the HTTP status line (mainly fo…

CVE-2025-67724
GitHub-GHSA

MEDIUM
kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating a request against a `content` parameter whose media type has no schema
GHSA-jpcw-4wr7-c3vq
pkg: github.com/getkin/kin-openapi
eco: go
published: Jul 24, 2026
| Field | Value |
|—|—|
| Ecosystem | Go |
| Package | `github.com/getkin/kin-openapi` |
| Affected versions | `<= 0.143.0` (introduced in `v0.2.0`, PR #90, 2019-05-07; reproduced on `HEAD` `30e2923`) |
| Patched versions | 0.144.0 |

### Summary

`openapi3filter.ValidateRequest` contains a …

GitHub-GHSA

MEDIUM
Budibase: Account Enumeration via Login Lockout Response Differential
GHSA-cr7p-cr3q-h5cm
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
## Summary

The login lockout mechanism in Budibase creates an observable response discrepancy that allows unauthenticated attackers to enumerate valid email addresses. When an existing user's account is locked after 5 failed login attempts, the server returns a distinct `403` response with `X-Accou…

GitHub-GHSA

MEDIUM
webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules
GHSA-g35j-m5xg-vh3q
pkg: github.com/quic-go/webtransport-go
eco: go
published: Jul 24, 2026
## Summary

An attacker can cause excessive memory allocation in webtransport-go by sending an unknown WebTransport capsule with a large payload. The implementation skips unknown capsules by reading the entire capsule body into memory, instead of draining it without retaining the data. This can lead…

CVE-2026-57497
GitHub-GHSA

MEDIUM
Open WebUI: Account enumeration via observable login timing discrepancy
GHSA-7rw5-9f7q-xj36
pkg: open-webui
eco: pip
published: Jul 24, 2026
### Summary

The `/api/v1/auths/signin` endpoint leaked whether an email address belonged to a registered account through a response-time side channel. Password verification ran bcrypt only when the email was found in the database; for a non-existent email the request returned early without hashing.…

CVE-2026-59218
GitHub-GHSA

MEDIUM
Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names
GHSA-mfg7-5gfp-c4w3
pkg: io.netty:netty-codec-dns, io.netty:netty-codec-dns
eco: maven
published: Jul 24, 2026
### Summary
A memory leak can be caused in Netty's DNS codec by sending malicious DNS packets containing invalid domain names. Because the leak occurs incrementally per packet, sustained malicious requests will cause a gradual Denial of Service.

### Details
Inside `io.netty.handler.codec.dns.Abstra…

GitHub-GHSA

MEDIUM
Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)
GHSA-g9hv-x236-4qp3
pkg: russh
eco: rust
published: Jul 24, 2026
### Summary
A malicious SSH server can crash a `russh` client session with a single
malformed key-exchange reply, causing a pre-authentication Denial-of-Service
before the server host key is verified. The embedding process itself stays
up, but the connection is killed deterministically.

### Details…

GitHub-GHSA

MEDIUM
Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB)
GHSA-5xvq-cp9x-6p6r
pkg: russh
eco: rust
published: Jul 24, 2026
A pre-authentication denial-of-service panic in `russh` 0.62.2 (commit
`c4be19f1915c8682f4615c3fd50008512b474491`, current default branch `main` as
of 2026-07-22). An unauthenticated client sends a single `SSH_MSG_KEX_ECDH_INIT`
whose `Q_C` is 32 zero bytes. russh's Curve25519 KEX does not reject th…
GitHub-GHSA

MEDIUM
@fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths
GHSA-8pvw-jcv7-9cmj
pkg: @fastify/static
eco: npm
published: Jul 24, 2026
### Impact

`@fastify/static` evaluates the `allowedPath` callback before normalizing dot segments and duplicate slashes in the pathname used for file resolution. Non-canonical pathnames such as `//file`, `/./file`, or `/public/../private/file` bypass `allowedPath` filtering while resolving to the i…

CVE-2026-7120
GitHub-GHSA

MEDIUM
node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection
GHSA-r292-9mhp-454m
pkg: tar
eco: npm
published: Jul 24, 2026
## Summary
`node-tar` (npm `tar`) contains an uncontrolled-recursion stack-exhaustion DoS in the internal `mapHas` helper used by `filesFilter`. When a consumer calls `tar.t(…)` or `tar.x(…)` with a non-empty member-selection list, node-tar installs a filter that closes over the recursive `mapHa…
GitHub-GHSA

MEDIUM
PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path
GHSA-9xwg-3r6f-jcx2
pkg: pymdown-extensions
eco: pip
published: Jul 24, 2026
### Summary

The `b64` extension inlines images referenced by `<img src="…">` as base64 data URIs. When resolving the `src` path it joins it onto the configured `base_path` with `os.path.normpath` and opens the result directly, with no check that the resolved path stays inside `base_path`. A `src`…

CVE-2026-61632
GitHub-GHSA

MEDIUM
SvelteKit: Big remote form function payloads can cause Node process to crash
GHSA-wqjv-9729-c5q2
pkg: @sveltejs/kit
eco: npm
published: Jul 24, 2026
Big remote form function payloads can cause the Node process to crash. Doing this repeatedly can cause DoS.
GitHub-GHSA

MEDIUM
ImageMagick: Stack Overflow in MVG decoder due to missing depth check.
GHSA-mx48-2qq3-23hf
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Jul 24, 2026
A missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided.
CVE-2026-55594
NVD

MEDIUM
CVE-2026-12353
CVE-2026-12353
pkg: tls

published: Jul 23, 2026

An unauthenticated attacker could trigger an Out of Memory condition to crash the Java process for RHCS by repeatedly sending HTTP requests to the TLS endpoint. Depending on how the RHCS server is configured, a manual intervention to restart it may prove necessary.
CWE: CWE-772
GitHub-GHSA

MEDIUM
ImageMagick: Information Disclosure in MNG decoder because allocated memory is left unchanged
GHSA-8g53-9m3c-69xg
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Jul 23, 2026
In the MNG decoder there is a possible heap information disclosure because part of the pixels are left unchanged.
CVE-2026-53467
NVD

MEDIUM
CVE-2026-25466
CVE-2026-25466
pkg: go

published: Jul 23, 2026

Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04 versions.
CWE: CWE-862
GitHub-GHSA

MEDIUM
Eclipse Jetty: Path parameter traversal
GHSA-w7x5-g22v-xqhr
pkg: org.eclipse.jetty:jetty-util, org.eclipse.jetty:jetty-util
eco: maven
published: Jul 22, 2026
### Description (as reported)

#### Summary

In Jetty 12.1.8, org.eclipse.jetty.util.URIUtil.canonicalPath() may leave dot-dot path segments unnormalized when a semicolon path parameter marker is followed by a slash and a dot
segment.

A minimal example is:

`/public;/../admin/secret`

In my local…

CVE-2026-8384
GitHub-GHSA

MEDIUM
Eclipse Jetty: HTTP Authority/Host mismatch
GHSA-7p3p-8qv8-m2vh
pkg: org.eclipse.jetty:jetty-server, org.eclipse.jetty:jetty-server, org.eclipse.jetty:jetty-server
eco: maven
published: Jul 22, 2026
#### Summary

Jetty currently accepts HTTP/2 and HTTP/3 requests where the regular
Host header and the pseudo-header :authority
do not match. As a result, the same request can carry two different host identities
through Jetty:

– logic based on `HttpURI` / `Request.getServerName(request)` uses `:aut…

CVE-2026-6790
NVD

MEDIUM
CVE-2026-13070
CVE-2026-13070
pkg: tls

published: Jul 22, 2026

A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP response from a remote peer during the TLS handshake. OCSP stapling validation is enabled by default for outgoing TLS connections. Affected scenarios require the remote peer to hold a cer…
CWE: CWE-476
NVD

MEDIUM
CVE-2026-50251
CVE-2026-50251
pkg: nlnetlabs unbound

published: Jul 22, 2026

In NLnet Labs Unbound up to and including version 1.25.1, when 'unwanted-reply-threshold' is enabled (set to any value greater than zero), glue records of 0.0.0.0/::0 can short-circuit Unbound, on systems that can direct such traffic, by issuing DNS queries and receiving seemingly unwanted replies s…
CWE: CWE-184
NVD

MEDIUM
CVE-2026-60394
CVE-2026-60394
pkg: go

published: Jul 21, 2026

Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle GoldenGate. Successful attacks of this…
CWE: CWE-200
NVD

MEDIUM
CVE-2026-46917
CVE-2026-46917
pkg: tls

published: Jul 21, 2026

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalV…
CWE: CWE-284
NVD

MEDIUM
CVE-2026-16318
CVE-2026-16318
pkg: tls

published: Jul 21, 2026

The QUIC transport parameters extension handler in s2n-tls incorrectly uses s2n_alloc instead of s2n_realloc to store the peer's transport parameters. When a TLS 1.3 connection goes through a HelloRetryRequest, the handler is called twice on the same connection. On the second call, s2n_alloc zeroes …
CWE: CWE-401
GitHub-GHSA

MEDIUM
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint
GHSA-p4mj-98mv-xq26
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
| Field | Value |
|——-|——-|
| **Affected File** | `routers/web/repo/githttp.go`, `services/context/repo.go` |
| **Affected Functions** | `httpBase()`, `EarlyResponseForGoGetMeta()` |
| **Affected Lines** | `githttp.go:63–66`, `services/context/repo.go:374–396` |
| **Prerequisite** | None…
CVE-2026-58507
GitHub-GHSA

MEDIUM
Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service
GHSA-pg7v-jwj7-p798
pkg: pillow
eco: pip
published: Jul 20, 2026
### Summary

Pillow's EPS parser (PIL/EpsImagePlugin.py) accepts a negative byte count in the %%BeginBinary directive. A crafted EPS file can cause Image.open() to seek backwards to the same directive and parse it repeatedly, resulting in an infinite loop and CPU denial of service.

The issue is tri…

CVE-2026-59203
GitHub-GHSA

MEDIUM
Mistune directives/include: mutual `.. include::` recursion crashes the renderer with `RecursionError`, denial of service via two attacker-controlled markdown files
GHSA-8mpj-m6qm-5qr8
pkg: mistune
eco: pip
published: Jul 20, 2026
## Summary

**Type:** Uncontrolled recursion via mutual include. The `Include` directive checks for direct self-reference (`a.md` cannot include `a.md`), but does not detect indirect cycles. Two markdown files that include each other (`a.md` → includes `b.md` → includes `a.md`) cause unbounded r…

CVE-2026-59927
NVD

MEDIUM
CVE-2026-55219
CVE-2026-55219
pkg: go

published: Jul 20, 2026

Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.5, the credit payment implementation in app/Livewire/Invoices/Show.php executes a pessimistic row lock (lockForUpdate()) outside of an active database transaction. Because MySQL/MariaDB …
CWE: CWE-362
GitHub-GHSA

MEDIUM
changedetection.io is vulnerable to unauthenticated static path traversal
GHSA-9jj8-v89v-xjvw
pkg: changedetection.io
eco: pip
published: Jul 20, 2026
## Summary
The `/static/<group>/<filename>` route accepts `group=".."`, which causes `send_from_directory("static/..", filename)` to execute. This moves the base directory up to `/app/changedetectionio`, enabling **unauthenticated local file read** of application source files (e.g., `flask_app.py`).…
CVE-2026-25527
NVD

MEDIUM
CVE-2026-11804
CVE-2026-11804
pkg: linux

published: Jul 23, 2026

Improper handling of insufficient permissions or privileges vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Privilege Abuse.

This issue affects Niagara Framework: before 4.14.6, before 4.15.5; Niagara Enterprise Se…

CWE: CWE-280
GitHub-GHSA

MEDIUM
ImageMagick: Integer Overflow in JNX decoder causes heap buffer over-write when processing extremly large files on 32-bit builds
GHSA-h22j-f9xw-xjjm
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-x86
eco: nuget
published: Jul 24, 2026
When processing an extremely large JNX file on 32-bit platforms an integer overflow will happen that can cause a heap buffer over-write.
CVE-2026-62946
GitHub-GHSA

MEDIUM
ImageMagick: Heap Buffer Over-Write in fx operation
GHSA-422r-8c97-xcg4
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Jul 24, 2026
A heap buffer over-write can occur in the fx operation by passing a crafted argument.
CVE-2026-62363
GitHub-GHSA

MEDIUM
Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role Users
GHSA-fcrw-f7gg-6g9f
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
## Summary

The `/api/users/metadata` and `/api/users/metadata/:id` endpoints in `@budibase/server` return full global user profiles to any user with POWER role or above. For SSO-authenticated users (OIDC, Google), the response includes `oauth2.accessToken` and `oauth2.refreshToken` fields, leaking …

GitHub-GHSA

MEDIUM
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
GHSA-fq2p-5p22-8g6j
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary
A personal access token restricted with the public-only scope can still retrieve private organization membership and organization permission details for its own account through organization-listing endpoints. This bypass breaks the intended guarantee that such tokens are limited to publi…
CVE-2026-58429
GitHub-GHSA

MEDIUM
@backstage/plugin-auth-backend: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass
GHSA-38hq-7×33-php4
pkg: @backstage/plugin-auth-backend
eco: npm
published: Jul 24, 2026
### Impact
The allowlist matching used by the experimental dynamic client registration and client ID metadata document (CIMD) features in `@backstage/plugin-auth-backend` matched glob patterns against the full URL string. A * wildcard could therefore match across URL component boundaries: a pattern …
GitHub-GHSA

MEDIUM
ImageMagick: Heap Buffer Over-Write in morphology operation when an invalid kernel is provided
GHSA-f5m7-cqgw-8hm7
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Jul 24, 2026
An invalid kernel can cause a heap buffer over-write when performing a morphology operation with a user supplied kernel.
CVE-2026-62343
GitHub-GHSA

MEDIUM
ImageMagick: Policy Bypass due to an incomplete fix of CVE-2026-49219
GHSA-56m6-8q75-f2rw
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Jul 24, 2026
An incomplete fix of CVE-2026-49219 could result in a policy bypass.
GitHub-GHSA

MEDIUM
ImageMagick: Infinite Loop in connected-components when providing invalid arguments
GHSA-qhmf-7fc4-8q3h
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Jul 24, 2026
When providing invalid arguments to the connected-components option an infinite loop will occur.
CVE-2026-55595
NVD

MEDIUM
CVE-2026-65904
CVE-2026-65904
pkg: node

published: Jul 23, 2026

DOMPurify through 3.3.3 fails to sanitize DOM elements passed via IN_PLACE mode when the element originates from a different window/realm (e.g., an iframe's contentDocument). A cross-realm instanceof check in the private _isNode() function returns false for foreign-realm nodes, causing DOMPurify to …
CWE: CWE-754
GitHub-GHSA

MEDIUM
Loofah: SVG `href` attribute bypasses local-reference restriction
GHSA-9wjq-cp2p-hrgf
pkg: loofah
eco: rubygems
published: Jul 21, 2026
## Summary

Loofah's HTML5 sanitizer restricted only the `xlink:href` attribute on certain SVG elements to local, same-document references. Browsers also accept a plain `href` attribute as an alternative to the deprecated `xlink:href` per the SVG 2 spec, but Loofah did not apply the same restriction…

GitHub-GHSA

MEDIUM
Trix: Stored XSS via HTMLParser attribute injection on paste
GHSA-53g2-mvcc-q9x3
pkg: trix, action_text-trix
eco: npm
published: Jul 24, 2026
### Impact

The Trix editor, in versions prior to 2.1.18, is vulnerable to XSS when crafted HTML is pasted into the editor. The `HTMLParser` processed a mock attachment, a `<span>` carrying an empty `data-trix-attachment="{}"`. The empty attachment object caused the element to bypass attachment hand…

GitHub-GHSA

MEDIUM
Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path
GHSA-4x4j-2g7c-83w6
pkg: Pillow
eco: pip
published: Jul 20, 2026
### 1. Summary

`WindowsViewer.get_command()` constructs a `cmd.exe` shell command by directly embedding a
file path into an f-string without escaping. The result is passed to
`subprocess.Popen(…, shell=True)`. Shell metacharacters in the file path — most
importantly a double-quote (`"`) that br…

CVE-2026-55798
NVD

MEDIUM
CVE-2026-15786
CVE-2026-15786
pkg: ssl

published: Jul 23, 2026

The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 7.8.6.6 via the 'imploded' parameter parameter. This makes it possible for authenticated attackers, with ad…
CWE: CWE-22
NVD

MEDIUM
CVE-2026-61084
CVE-2026-61084
pkg: go

published: Jul 21, 2026

Vulnerability in Oracle GoldenGate (component: Libraries). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle GoldenGate executes to compromise Ora…
CWE: CWE-284
GitHub-GHSA

MEDIUM
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search
GHSA-p6ph-3jx2-3337
pkg: github.com/OpenListTeam/OpenList/v4
eco: go
published: Jul 24, 2026
### Summary
An authorization bypass and information disclosure vulnerability exists in the search API of `Openlist`. Due to a non-separator-aware path check and unfiltered backend counting, a low-privileged user can bypass their assigned `BasePath` restrictions to discover and access metadata of fil…
GitHub-GHSA

MEDIUM
Budibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappings
GHSA-4qcj-m5wp-jmf4
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
## Summary

The `GET /api/global/groups` endpoint on the worker service has no role-based authorization middleware. Any authenticated user (including BASIC role) can enumerate all user groups in the tenant, including their role mappings, user memberships, builder permissions, and the isDefault flag.…

GitHub-GHSA

MEDIUM
Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching
GHSA-qg3f-8x3j-ggf2
pkg: open-webui
eco: pip
published: Jul 24, 2026
## Summary

The administrator-configured `WEB_FETCH_FILTER_LIST` (the allow/block list applied to server-side web fetches: RAG URL ingestion, URL-to-markdown, web-search content fetch) matches hostnames incorrectly, so the filter can be bypassed.

## Details

`is_string_allowed` (`backend/open_webui…

CVE-2026-59223
GitHub-GHSA

MEDIUM
Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and receives activity events for unshared siblings
GHSA-w8x7-h2px-xmq8
pkg: github.com/cloudreve/Cloudreve/v4, github.com/cloudreve/Cloudreve/v3
eco: go
published: Jul 24, 2026
## Summary

When an authenticated recipient of a **single-file** share opens the file event stream (`GET /api/v4/file/events?uri=<share-root>`), Cloudreve validates the URI by listing it and then subscribes the caller to `parent.ID()`. For a single-file share, the share navigator resolves the bare …

CVE-2026-55499
GitHub-GHSA

MEDIUM
Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails
GHSA-8r7f-r8hj-r3rv
pkg: github.com/cloudreve/Cloudreve/v4, github.com/cloudreve/Cloudreve/v3
eco: go
published: Jul 24, 2026
## Summary

`GET /api/v4/user/search` is available to any logged-in user. The service calls `userClient.SearchActive`, but despite its name that method filters only by email/nickname keyword and **never adds a `StatusActive` predicate** — while the sibling lookups `GetActiveByID` and `GetActiveBy…

CVE-2026-55496
GitHub-GHSA

MEDIUM
Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account
GHSA-49h3-cwhj-4737
pkg: github.com/cloudreve/Cloudreve/v4, github.com/cloudreve/Cloudreve/v3
eco: go
published: Jul 24, 2026
## Summary

Cloudreve's WOPI `PUT_RELATIVE` handler treats `X-WOPI-SuggestedTarget` as a path, not a filename. It splits the header on `/` and joins the segments onto the source file's directory with `URI.JoinRaw`, which feeds Go's `url.JoinPath`. `url.JoinPath` resolves `.`/`..` segments, so a sla…

CVE-2026-55495
GitHub-GHSA

MEDIUM
Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)
GHSA-7r7x-gjvr-448g
pkg: open-webui
eco: pip
published: Jul 24, 2026
# Open WebUI upload metadata can add files to knowledge bases without write permission

## Summary

Open WebUI's file upload background processing trusts the client-supplied `metadata.knowledge_id` value and inserts a `knowledge_file` association before validating that the uploading user has write a…

CVE-2026-59217
GitHub-GHSA

MEDIUM
Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission
GHSA-rqj7-6wrp-6g2g
pkg: open-webui
eco: pip
published: Jul 24, 2026
## Summary

`POST /api/v1/images/edit` performed no authorization beyond requiring a verified account. Every other image-editing surface in Open WebUI enforces the global image-edit switch and the per-user image-generation permission — the `/api/v1/images/generations` route, the built-in `edit_ima…

CVE-2026-59227
GitHub-GHSA

MEDIUM
Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records
GHSA-cqjc-rmpq-xprq
pkg: russh
eco: rust
published: Jul 24, 2026
## Summary

A post-authentication denial-of-service panic in `russh` 0.62.2 (commit
`c4be19f1915c8682f4615c3fd50008512b474491`, current default branch `main` as
of 2026-07-22). An authenticated client sends a `pty-req` channel request
carrying more than 130 terminal-mode records. The parser uses a f…

GitHub-GHSA

MEDIUM
SvelteKit: Prototype pollution in file input deletion path in remote-function forms
GHSA-866w-xmhq-wj7x
pkg: @sveltejs/kit
eco: npm
published: Jul 24, 2026
If you use remote form functions, have an input field of type `file`, and accept arbitrary user-controlled path names for the field, then you are vulnerable to a prototype pollution attack where the attacker can remove e.g. methods on the prototype.
NVD

MEDIUM
CVE-2026-60410
CVE-2026-60410
pkg: kubernetes

published: Jul 21, 2026

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTe…
CWE: CWE-400
NVD

MEDIUM
CVE-2026-60408
CVE-2026-60408
pkg: kubernetes

published: Jul 21, 2026

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTe…
CWE: CWE-200
NVD

MEDIUM
CVE-2026-60397
CVE-2026-60397
pkg: go

published: Jul 21, 2026

Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the ha…
CWE: CWE-404
NVD

MEDIUM
CVE-2026-60395
CVE-2026-60395
pkg: go

published: Jul 21, 2026

Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle GoldenGate. Succe…
CWE: CWE-200
GitHub-GHSA

MEDIUM
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private
GHSA-q423-49rw-g9mh
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
## Summary

GHSA-8fwc-qjw5-rvgp ("Gitea may send release notification emails for private repositories to users whose access has been revoked", fix in PR #36319 / commit 8a98ac22) added `repo_model.ClearRepoWatches` as a defense for the state transition public→private. The cleanup was wired into `s…

CVE-2026-58510
GitHub-GHSA

MEDIUM
Gitea: Public-only API token restriction is not enforced on team API routes
GHSA-h56g-4qw7-2mxg
pkg: gitea.dev
eco: go
published: Jul 21, 2026
### Summary

Gitea's `/api/v1/teams/{id}` API routes do not correctly enforce the `public-only` access token restriction.

A `public-only` token is intended to limit API access to public repositories and public organizations. However, several team API routes continue to return private team repositor…

CVE-2026-58431
GitHub-GHSA

MEDIUM
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)
GHSA-6cqf-375w-639g
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary

Gitea's RSS/Atom feed handlers accept API-token Basic auth but perform **no token-scope or
public-only enforcement**. A personal access token that is correctly blocked (HTTP 403) from a
private repository on `/raw`, `/media`, `/archive`, and `/releases/download/…` — because it is
ma…

CVE-2026-50105
GitHub-GHSA

MEDIUM
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents
GHSA-cp3q-vrj2-ghhh
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary
A personal access token (PAT) or OAuth2 token that does **not** carry the
`repository` scope or that is **public-only** is correctly rejected (HTTP 403)
by the recently hardened web content routes (archive download, raw/media file
download, and repository RSS/Atom feeds). However, the re…
CVE-2026-58444
GitHub-GHSA

MEDIUM
Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data
GHSA-3pww-vcvm-3gmj
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary
A Gitea personal access token (PAT) restricted to a non-repository scope (e.g. `read:issue`) can read the commit history of any private repository the token owner can access, via the repository RSS/Atom feed endpoints. The same token is correctly denied (403) on `/raw`, `/media`, `/archi…
CVE-2026-27761
GitHub-GHSA

MEDIUM
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)
GHSA-vxv2-8j6r-pcpg
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
## Live reproduction against Gitea 1.26.1

Setup: Gitea 1.26.1 docker stack with two users (`admin` and `victim`) and two OAuth applications owned by different users:

“`
Client A: id=5dda747d-7fdd-4694-85ff-ce4f893ce51e owner=admin
Client B: id=588f778f-4a41-4914-ae01-85d776c369db owner=victim…

CVE-2026-58425
GitHub-GHSA

MEDIUM
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118
GHSA-7p4h-3gxq-x3h3
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
## Summary

After [PR #37118](https://github.com/go-gitea/gitea/pull/37118) / **CVE-2026-25714**
(`fix: Unify public-only token filtering in API queries and repo access checks`,
merged 2026-05-18, backport `#37773` to 1.26.2 — the May 2026 unification pass
for public-only token filtering, reporter…

CVE-2026-56443
GitHub-GHSA

MEDIUM
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times`
GHSA-qf2f-qh6p-7v89
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
## Summary
CVE-2026-20800 fixed private-info leakage to revoked users only for the notification endpoint. Two
sibling endpoints that return data keyed on the caller's own relationship still do not re-check repo
access at output time:
– `GET /api/v1/user/starred` — `getStarredRepos()` computes a pe…
CVE-2026-59766
NVD

MEDIUM
CVE-2026-16336
CVE-2026-16336
pkg: oauth

published: Jul 21, 2026

A vulnerability was found in trinodb trino 481. Affected is an unknown function of the file core/trino-main/src/main/java/io/trino/server/ExternalUriInfo.java of the component OAuth2/OIDC. Performing a manipulation of the argument redirect_uri results in open redirect. It is possible to initiate the…
CWE: CWE-601
GitHub-GHSA

MEDIUM
Mistune toc / TableOfContents directive: heading IDs use predictable `toc_N` numbering with no slugification, allowing collision with attacker-controlled `id="toc_N"` content
GHSA-2hm2-hc3v-44h9
pkg: mistune
eco: pip
published: Jul 20, 2026
## Summary

**Type:** Predictable identifier generation. The `toc` plugin and `TableOfContents` directive both default to generating heading IDs of the form `toc_1`, `toc_2`, `toc_3`, … with no input-derived component. An attacker who can place a heading anywhere in the document can predict which …

CVE-2026-59930
NVD

MEDIUM
CVE-2026-63768
CVE-2026-63768
pkg: oauth

published: Jul 20, 2026

cal.diy through 6.2.0 contains an open redirect vulnerability in the conferencing OAuth callback endpoint that allows attackers to redirect users to arbitrary URLs by crafting malicious state parameters. Attackers can exploit the unsigned state parameter and onErrorReturnTo field to silently redirec…
CWE: CWE-601
NVD

MEDIUM
CVE-2026-13724
CVE-2026-13724
pkg: go

published: Jul 20, 2026

Client-Side Enforcement of Server-Side Security vulnerability in Gobito Informatics Technologies Engineering Industry and Trade Ltd. Co. Corporate Training Management System allows Input Data Manipulation.

This issue affects Corporate Training Management System: before dd1a9df64.

CWE: CWE-602
NVD

MEDIUM
CVE-2026-63761
CVE-2026-63761
pkg: surrealdb surrealdb

published: Jul 20, 2026

SurrealDB before 3.1.0 silently substitutes the ES384 algorithm when a JWT access method is configured with ALGORITHM ES512 (DEFINE ACCESS … TYPE JWT ALGORITHM ES512), because the underlying jsonwebtoken crate (v10.x) has no ES512 variant and the mapping defaults to ES384 without any error, warnin…
CWE: CWE-327
NVD

MEDIUM
CVE-2026-63749
CVE-2026-63749
pkg: surrealdb surrealdb

published: Jul 20, 2026

SurrealDB versions before 3.1.0 contain an authentication bypass vulnerability in LIVE SELECT subscriptions where permission expressions referencing $value, $before, $after, or $event are evaluated against attacker-controlled bindings instead of actual documents. Authenticated subscribers can bind c…
CWE: CWE-863
GitHub-GHSA

MEDIUM
Shescape: Home-directory disclosure in assignment context on Unix with Dash
GHSA-q53c-4prm-w95q
pkg: shescape, shescape
eco: npm
published: Jul 24, 2026
### Impact

This impacts users of Shescape on Unix systems that explicitly configure `shell` to Dash, or `true` when the default shell is Dash, using the `escape` and `escapeAll` APIs in assignments prefixed to a command.

An attacker may be able to obtain the location of the home directory and, dep…

GitHub-GHSA

MEDIUM
Shescape: Path disclosure on Unix with Zsh
GHSA-6v4m-fw66-8r4x
pkg: shescape, shescape
eco: npm
published: Jul 24, 2026
### Impact

This impacts users of Shescape on Unix systems that explicitly configure `shell` to Zsh, or `true` when the default shell is Zsh, using the `escape` and `escapeAll`. The Zsh options `EXTENDED_GLOB` and `MAGIC_EQUAL_SUBST` exacerbate the problem.

In certain case, an attacker can leverage…

GitHub-GHSA

MEDIUM
Hubuum client library (Rust): Configured custom transports may be bypassed, exposing credentials and network traffic
GHSA-qqc3-94qv-7fw3
pkg: hubuum_client
eco: rust
published: Jul 24, 2026
## Summary

When an application configures hubuum_client with ClientBuilder::with_transport, several client operations still use the built-in reqwest client directly. The bypass includes password login, bearer-token validation, authentication-provider discovery, health and readiness probes, export-o…

GitHub-GHSA

MEDIUM
Hubuum client library (Rust): Authenticated requests may escape the configured base path through redirects
GHSA-f45q-w629-wr25
pkg: hubuum_client
eco: rust
published: Jul 24, 2026
## Impact

The built-in async and blocking clients used reqwest's default redirect policy. `BaseUrl` constrains the initial request to the configured origin and path prefix, but redirect processing occurs after that validation. reqwest retains sensitive headers when a redirect changes only the path …

GitHub-GHSA

MEDIUM
Budibase: SSRF via bare fetch() in uploadUrl during AI table generation
GHSA-hfhx-w8p8-4hc7
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
# Budibase: SSRF via bare fetch() in uploadUrl during AI table generation

## Summary

The `uploadUrl()` function in `packages/server/src/utilities/fileUtils.ts` uses a bare `fetch(url)` call without any SSRF protection. This function is invoked when the AI table generation feature processes LLM-gen…

GitHub-GHSA

MEDIUM
Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials
GHSA-gh7p-78×6-jw6m
pkg: open-webui
eco: pip
published: Jul 24, 2026
### Summary

The channel members endpoint serializes and returns **full user models** for channel participants, including settings objects. A normal user in a DM can retrieve admin-only sensitive configuration such as webhook URLs and tool server key material (`settings.ui.toolServers[].key`), which…

CVE-2026-59222
GitHub-GHSA

MEDIUM
cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag
GHSA-gcjh-h69q-9w9g
pkg: github.com/google/cel-go
eco: go
published: Jul 24, 2026
The function `ext.NativeTypes(ParseStructTag("json"))` does not honour the `encoding/json` skip directive `json:"-"`. Fields tagged `json:"-"` are registered in the CEL type system under the literal name `"-"` and are readable from any user-submitted CEL expression via `dyn(obj)["-"]`.

Additionall…

GitHub-GHSA

MEDIUM
Microsoft Kiota: Path traversal in generated plugin manifest static_template.file reference (percent-encoding bypass)
GHSA-p5rm-jg5c-8c77
pkg: Microsoft.OpenApi.Kiota
eco: nuget
published: Jul 24, 2026
### Impact

Kiota generates AI plugin manifests from an OpenAPI description. When the description contains an `x-ai-capabilities` response semantics `static_template` (or the adaptive-card extension `x-ai-adaptive-card`), the `file` reference is written into the generated manifest's `response_semant…

GitHub-GHSA

MEDIUM
Valibot: record() issue paths can make flatten() throw for inherited Object property names
GHSA-5qjj-4xww-7phc
pkg: valibot
eco: npm
published: Jul 24, 2026
## Summary

`valibot` 1.4.1 can throw a `TypeError` inside its `flatten()` helper when validation issues contain attacker-controlled object keys such as `toString`, `valueOf`, or `hasOwnProperty`.

The issue is reachable through normal `record()` validation. `record()` intentionally filters `__proto…

CVE-2026-59952
GitHub-GHSA

MEDIUM
c3p0 can, in combination with other libraries, compose to a "sink" for deserialization gadgets
GHSA-w6w4-rjh9-9r58
pkg: com.mchange:c3p0
eco: maven
published: Jul 23, 2026
### Impact

The JDBC spec defines the interface `DataSource`, with a method called `getConnection()`, and `ConnectionPoolDataSource`, with a method called `getPooledConnection()`. These methods are potentially dangerous. One way or another they trigger calls into JDBC drivers, which themselves are c…

CVE-2026-55223
GitHub-GHSA

MEDIUM
React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)
GHSA-wrjc-x8rr-h8h6
pkg: react-router
eco: npm
published: Jul 23, 2026
This is a follow up to [CVE-2025-68470](https://github.com/remix-run/react-router/security/advisories/GHSA-9jcx-v3wj-wh4m). React Router was alerted to certain scenarios in which the fix there was incomplete so there still existed some scenarios where attacker supplied paths passed to navigation me…
CVE-2026-53669
GitHub-GHSA

MEDIUM
pypdf: Possible long runtimes for repeated malformed cross-reference entries
GHSA-55h5-xmcq-c37v
pkg: pypdf
eco: pip
published: Jul 23, 2026
### Impact

An attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires cross-reference streams with repeated malformed cross-reference streams.

### Patches

This has been fixed in [pypdf==6.14.0](https://github.com/py-pdf/pypdf/releases/tag/6.14.0).

### Wor…

CVE-2026-59937
GitHub-GHSA

MEDIUM
pypdf: Possible large memory usage for wrong image dimensions
GHSA-5qjq-93h5-hrgp
pkg: pypdf
eco: pip
published: Jul 23, 2026
### Impact

An attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires loading images where the declared size values are much too large compared to the actual data.

### Patches

This has been fixed in [pypdf==6.14.0](https://github.com/py-pdf/pypdf/rele…

CVE-2026-59938
GitHub-GHSA

MEDIUM
n8n: Snowflake Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation
GHSA-652q-gvq3-74qv
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact

The n8n Snowflake node's Execute Query operation interpolated expression values directly into the SQL string, making queries built with untrusted data susceptible to SQL injection.

Exploitation requires that a workflow author has already embedded untrusted expression data directly in a r…

GitHub-GHSA

MEDIUM
n8n: PostgresTrigger Node SQL Injection Allows Authenticated Users to Execute Arbitrary SQL on Connected PostgreSQL Instances
GHSA-jqwr-vx3p-r266
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact

The Postgres Trigger node interpolated user-supplied identifier parameters (channel, function, and trigger names) into SQL statements without proper escaping, so an authenticated user could inject arbitrary SQL executed against the connected PostgreSQL database with the configured credent…

GitHub-GHSA

MEDIUM
n8n: Cross-Tenant Module-Cache Poisoning in the JS Task Runner
GHSA-9cmh-xcqm-5hqr
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact

n8n's JavaScript task runner shared one module cache across all users' Code-node executions, so a user able to run a Code node could poison a cached module and alter other users' Code-node executions on the same runner, affecting their confidentiality, integrity, or availability.

This is…

GitHub-GHSA

MEDIUM
JupyterLab: PyPI extension blocklist package-name canonicalization bypass
GHSA-89vp-jrxv-24w8
pkg: jupyterlab, jupyterlab
eco: pip
published: Jul 22, 2026
JupyterLab's PyPI extension manager enforces `blocked_extensions_uris` by comparing the requested install name to blocklist entries with a custom string normalization that is weaker than PyPI package-name canonicalization. An authenticated user can request a PyPI-equivalent spelling such as `Jupyter…
GitHub-GHSA

MEDIUM
JupyterLab PluginManager lock-rule enforcement bypass
GHSA-h5v5-8746-g7mm
pkg: jupyterlab, jupyterlab
eco: pip
published: Jul 22, 2026
JupyterLab's plugin manager exposes administrator controls intended to prevent users from enabling or disabling selected plugins. Two server-side enforcement gaps let an authenticated user bypass those controls with direct requests to `/lab/api/plugins`.

### Impact

Users could workaround the plugi…

GitHub-GHSA

MEDIUM
Next.js: Cache confusion of response bodies for requests with bodies
GHSA-68g3-v927-f742
pkg: next, next
eco: npm
published: Jul 22, 2026
## Impact

A server-side `fetch` with a request body may return a cached **response** body from a different request to the same URL but different body. Confidential data in the `POST`'s **response** body would then leak to unauthorized requests. Though the request itself will not be deduped.

This o…

CVE-2026-64648
GitHub-GHSA

MEDIUM
Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences
GHSA-4633-3j49-mh5q
pkg: next, next
eco: npm
published: Jul 22, 2026
## Impact

A server-side `fetch` with a request body may return a cached **response** body from a different request to the same URL but different body. Confidential data in the `POST`'s **response** body would then leak to unauthorized requests. Though the request itself will not be deduped.

This i…

CVE-2026-64647
GitHub-GHSA

MEDIUM
Next.js: Unbounded Server Action payload in Edge runtime
GHSA-4c39-4ccg-62r3
pkg: next, next
eco: npm
published: Jul 22, 2026
## Impact

Requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive memory consumption if that Server Actions uses the Edge runtime

## Workarounds

If you cannot upgrade, ensure your hosting provider limits the request's body size. 5 MiB should …

CVE-2026-64646
GitHub-GHSA

MEDIUM
Next.js: Denial of Service in the Image Optimization API using SVGs
GHSA-q8wf-6r8g-63ch
pkg: next, next
eco: npm
published: Jul 22, 2026
### Impact

When self-hosting Next.js with the default image loader, the Image Optimization API can optimize remotely hosted images if configured (not enabled by default). If those images contain malicious content, they can cause CPU exhaustion in `/_next/image` endpoints.

– If you are using `conf…

CVE-2026-64644
GitHub-GHSA

MEDIUM
Next.js: Unauthenticated disclosure of internal Server Function endpoints
GHSA-955p-x3mx-jcvp
pkg: next, next
eco: npm
published: Jul 22, 2026
## Impact

In Next.js applications using App Router, Server Actions (`use server`) or `use cache` endpoints can be disclosed bypassing any authentication on the pages where these endpoints are usually used.

Server Action IDs can be disclosed to unauthenticated users via publicly served client artif…

CVE-2026-64643
GitHub-GHSA

MEDIUM
Eclipse Jetty: Cross-Request Leakage for trailers on HTTP/1.1 keep-alive connections
GHSA-f4v5-65jj-pcr2
pkg: org.eclipse.jetty:jetty-server, org.eclipse.jetty:jetty-server
eco: maven
published: Jul 22, 2026
### Description

> FINDING — MEDIUM (HTTP/1.1 keep-alive connections with trailers)
> HttpConnection._trailers Cross-Request Leakage (Never Reset Between Requests)
>
> Location:
> jetty-core/jetty-server/src/main/java/org/eclipse/jetty/server/internal/
> HttpConnection.java:107, 1157-1161, 11…

CVE-2026-10051
GitHub-GHSA

MEDIUM
n8n: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data
GHSA-89gh-3pgc-v5h2
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact
Custom HTTP headers configured in credentials for certain LLM sub-nodes (including OpenAI, Anthropic, and Lemonade) are masked in the n8n UI but are written in plaintext into execution data during workflow runs. Any authenticated user with access to the execution data for an affected workf…
CVE-2026-65589
GitHub-GHSA

MEDIUM
LiteLLM: Arbitrary file write via path traversal in Skills archive extraction
GHSA-5jmr-gcrj-2c9q
pkg: litellm
eco: pip
published: Jul 22, 2026
### Impact

LiteLLM Skills archive extraction did not sufficiently validate file paths from uploaded skill ZIP archives. An authenticated user with access to LiteLLM LLM API routes, or a key whose `allowed_routes` includes `/v1/skills`, `anthropic_routes`, or `llm_api_routes`, could upload a crafted…

CVE-2026-59820
GitHub-GHSA

MEDIUM
n8n: Unauthenticated Endpoint Allows Cancellation of Any User's Active Test Webhook
GHSA-33q9-f52j-gc75
pkg: n8n
eco: npm
published: Jul 22, 2026
## Impact
The `DELETE /${restEndpoint}/test-webhook/:id` route is registered before the authentication middleware is applied, allowing any unauthenticated network caller who knows a workflow ID to cancel that workflow's active test webhook registration.

The impact is limited to disrupting in-progr…

CVE-2026-65014
GitHub-GHSA

MEDIUM
n8n: GraphQL Node Bypasses "Allowed HTTP Request Domains" Restriction
GHSA-gq66-9cw5-j5jm
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact
The GraphQL node did not enforce the "Allowed HTTP Request Domains" restriction on HTTP-based credentials (such as Header Auth, Basic Auth, Query Auth, and OAuth), unlike the HTTP Request node. An authenticated user able to create or edit workflows could therefore point the node's endpoint…
CVE-2026-65596
GitHub-GHSA

MEDIUM
n8n: Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows via Missing OAuth Authorization Check
GHSA-q5xf-xhwf-cwqf
pkg: n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact
The OAuth 2.1 consent and token-issuance flow introduced in n8n 2.27.0 does not verify that the authenticated user has access to the workflow referenced as the OAuth resource. A member-level user can register an OAuth client, self-approve consent for another user's `n8n OAuth2`-protected M…
CVE-2026-65594
GitHub-GHSA

MEDIUM
n8n: computer-use Shell Sandbox Not Enforced on Linux and Windows
GHSA-fpg6-x68q-5793
pkg: n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact
The shell tool in the `@n8n/computer-use` package applied its sandbox restrictions only on macOS. On Linux and Windows, shell commands executed by the tool ran without any filesystem or network restrictions, allowing unrestricted access to the host filesystem and network from within the co…
CVE-2026-65590
GitHub-GHSA

MEDIUM
n8n: Authenticated Users Can Exhaust Temporary Disk Storage via Data-Table File Uploads
GHSA-w867-jm58-p9pv
pkg: n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact
An authenticated user can repeatedly upload files to the data-table upload endpoint, bypassing the per-request quota check, which does not account for files already written to the shared temporary directory. This causes temporary files to accumulate on disk until the periodic cleanup runs,…
CVE-2026-58661
GitHub-GHSA

MEDIUM
n8n: Improper Authorization Allows Authenticated Users to Assign Workflows to Folders in Other Projects
GHSA-2xgm-wc4g-5jvg
pkg: n8n
eco: npm
published: Jul 22, 2026
## Impact
An authenticated user with permission to create workflows in one project could bypass project/folder authorization boundaries during workflow creation. By supplying a crafted request payload, the user could associate a newly created workflow with a folder belonging to a different project t…
CVE-2026-59253
GitHub-GHSA

MEDIUM
n8n: External Secrets Accessible via Workflow Expressions Outside Credentials
GHSA-2434-3x6q-8r99
pkg: n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact
External secrets were incorrectly resolved in workflow node expressions, where they are not intended to be available. An authenticated user with project editor access could read the plaintext value of external secrets by referencing them in a node expression, without needing explicit secre…
CVE-2026-59254
GitHub-GHSA

MEDIUM
n8n: MySQL v1 Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation
GHSA-hwmj-qg4v-cvg9
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact
The legacy MySQL v1 node's `executeQuery` operation substitutes evaluated `{{ … }}` expression values directly into the raw SQL string without parameterization. If a workflow uses this operation with expression-sourced values in the query and is connected to an externally-reachable trigg…
CVE-2026-59257
GitHub-GHSA

MEDIUM
n8n: External Secrets Permission Bypass via Expression Parser Mismatch
GHSA-jp7m-xcgx-57qm
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact
Due to a mismatch between the static validation check and the runtime expression engine, an authenticated user with credential create or update permissions, but without the `externalSecret:list` scope, could embed external secret references into credentials in forms the validation did not …
CVE-2026-59259
GitHub-GHSA

MEDIUM
n8n: Path-Confinement Bypass in computer-use search_files Allows Reading Files Outside the Base Directory
GHSA-pf2q-pxhf-hgmw
pkg: n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact

The component `@n8n/computer-use` file-search tool confined searches to a configured base directory. A crafted search pattern could bypass the confinement check and expand to locations outside that directory, causing the tool to return the names and contents of files anywhere the daemon's…

GitHub-GHSA

MEDIUM
n8n: Prototype Pollution via VM Expression Engine Sandbox Escape Leads to Denial of Service
GHSA-hx4h-vr3m-45vh
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact

An authenticated user able to create or edit a workflow expression could abuse the expression engine's array-element access to obtain a reference to a host built-in and pollute its prototype in the main n8n process, leading to a denial of service.

Both self-hosted and cloud instances run…

GitHub-GHSA

MEDIUM
n8n: SSRF Protection Bypass via MCP Client Node
GHSA-vhf8-cg2h-cg3p
pkg: n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact

On an n8n instance with SSRF protection enabled, the MCP Client node sent requests to a user-supplied endpoint without routing them through that protection and without pinning the resolved address. An authenticated user who could create or edit a workflow could therefore cause the server …

GitHub-GHSA

MEDIUM
Netty: [codec-http2] Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass
GHSA-c69g-56f8-xwqj
pkg: io.netty:netty-codec-http2, io.netty:netty-codec-http2
eco: maven
published: Jul 22, 2026
Netty's HTTP/2-to-HTTP/1.x translation layer (`Http2StreamFrameToHttpObjectCodec` and `InboundHttp2ToHttpAdapter`) fails to deduplicate or validate `Host` headers when an HTTP/2 client supplies both the `:authority` pseudo-header and a literal `host` header in a single HEADERS frame. The translator …
CVE-2026-59900
GitHub-GHSA

MEDIUM
Netty: [HttpContentEncoder] Unbounded Per-Connection Queue Growth via HTTP/1.1 Pipelining Leads to Denial of Service
GHSA-q4f6-jm68-57ww
pkg: io.netty:netty-codec-http, io.netty:netty-codec-http
eco: maven
published: Jul 22, 2026
### Impact
`HttpContentEncoder` (the superclass of the production handler `HttpContentCompressor`) maintains a per-channel `ArrayDeque<CharSequence>` named `acceptEncodingQueue` that accumulates attacker-controlled data without any size limit. The queue is filled on the I/O thread for every inbound …
CVE-2026-59899
GitHub-GHSA

MEDIUM
Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation
GHSA-4mp9-239f-g9hg
pkg: io.netty:netty-codec-http, io.netty:netty-codec-http
eco: maven
published: Jul 22, 2026
## Summary
An attacker can force WebSocket upgrade via the lax V07 (or V08) handshaker by sending `Sec-WebSocket-Version: 7` and omitting `Connection: Upgrade` / `Upgrade: websocket` headers, completing a protocol switch that a proxy would not recognize as an Upgrade request and enabling HTTP reques…
CVE-2026-59898
GitHub-GHSA

MEDIUM
Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations
GHSA-cj75-f6xr-r4g7
pkg: rails-html-sanitizer
eco: rubygems
published: Jul 21, 2026
## Summary

There is a possible cross-site scripting vulnerability in rails-html-sanitizer when the sanitizer is configured to allow an SVG reference element such as `<use>`. See related [GHSA-9wjq-cp2p-hrgf](https://github.com/flavorjones/loofah/security/advisories/GHSA-9wjq-cp2p-hrgf) in Loofah, w…

GitHub-GHSA

MEDIUM
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata
GHSA-2wm4-vwp6-v7xc
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary

Gitea has robust SSRF protection via `hostmatcher.NewDialContext()` for webhook and migration clone URLs, which validates resolved IPs at the TCP dial level. However, three code paths use raw `http.Get()` (Go's `DefaultClient`) which completely bypasses this protection, enabling SSRF to…

CVE-2026-59765
GitHub-GHSA

MEDIUM
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145
GHSA-prr9-9mp4-5gp2
pkg: gitea.dev
eco: go
published: Jul 21, 2026
## Summary
PR #38145 fixed ListPublicMembers and IsPublicMember but missed
ListMembers. Any authenticated user can enumerate ALL members
(not just public ones) of a private organization.

## Affected Versions
<= v1.26.4 (latest) and main branch

## Root Cause
routers/api/v1/org/member.go — ListM…

CVE-2026-58427
GitHub-GHSA

MEDIUM
Gitea SSH Key Parser Denial of Service
GHSA-4xjf-493q-98p3
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
Gitea's SSH key ingestion endpoint accepts keys in RFC 4716 (SSH2) format and normalises them before storage. The normalisation function contains an O(N²) string concatenation loop with no input size limit, meaning a single malicious key submission can force the server to perform an amount of work …
CVE-2026-56657
GitHub-GHSA

MEDIUM
Gitea: Local File Inclusion via file:// URI in Migration Restore
GHSA-5ggr-2f2h-jmvm
pkg: gitea.dev
eco: go
published: Jul 21, 2026
# Local File Inclusion via file:// URI in Migration Restore

Target: go-gitea/gitea
Component: services/migrations/gitea_uploader.go, modules/uri/uri.go
Severity: High
Affected Versions: <= v1.22.x (all releases), master as of latest commit
Researchers:
– Isa Can — Eresus Security (https://github.…

CVE-2026-58420
GitHub-GHSA

MEDIUM
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes
GHSA-mg4f-x9v4-6h2p
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary

The OIDC userinfo endpoint (`GET /login/oauth/userinfo`) accepts Gitea API tokens as bearer credentials but does not enforce API token scopes before returning identity claims.

A personal access token scoped only to `read:misc` can successfully retrieve user information from the OIDC us…

CVE-2026-55982
GitHub-GHSA

MEDIUM
Gitea: REST API exposes organization membership of private organizations to public
GHSA-jr5x-6h83-wrxf
pkg: gitea.dev
eco: go
published: Jul 21, 2026
### Summary

The endpoint "/orgs/{org}/public_members/{username}" + GET exposes organization membership of public members in a private organization.

### PoC

1. Spin up the nightly container of Gitea.
2. Perform the default installation.
3. Register a new user (let's call this user "user1").
4. Cr…

CVE-2026-58417
GitHub-GHSA

MEDIUM
Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions
GHSA-rjvx-x5h2-6px5
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary

The API endpoint used to fork repositories into organizations performs a weaker authorization check than the corresponding web UI and other repository creation endpoints.

When a repository is forked into an organization through the API, the endpoint only verifies that the user is an or…

GitHub-GHSA

MEDIUM
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads
GHSA-9mq6-mqjj-c2c5
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
## Summary

Hello Gitea Security Team,

Thank you for your continued work on Gitea. I would like to responsibly report a potential availability-impact issue that I observed in Gitea’s Arch package registry implementation.

During local testing, I noticed that Gitea records non-dot regular file ent…

CVE-2026-59763
GitHub-GHSA

MEDIUM
Mistune: XSS via unescaped class option in Admonition directive
GHSA-g97x-gvcm-x72h
pkg: mistune
eco: pip
published: Jul 20, 2026
In `src/mistune/directives/admonition.py`, the `render_admonition()` function concatenates the `:class:` option directly into the HTML class attribute without escaping (lines 63-68).

This allows attribute injection and XSS even when `HTMLRenderer(escape=True)` is used.

The directive name parameter…

CVE-2026-59926
GitHub-GHSA

MEDIUM
pillow-heif: Integer Overflow in Encode Path Buffer Validation Leads to Heap Out-of-Bounds Read
GHSA-5gjj-6r7v-ph3x
pkg: pi-heif, pillow-heif
eco: pip
published: Jul 20, 2026
### Summary

An integer overflow in the encode path buffer validation of `_pillow_heif.c` allows an attacker to bypass bounds checks by providing large image dimensions, resulting in a heap out-of-bounds read. This can lead to information disclosure (server heap memory leaking into encoded images) o…

CVE-2026-28231


Vulnerability Digest — July 13, 2026 · 52 Critical · 6 Exploited






Vulnerability Digest — Monday, July 13, 2026


Security Report

Monday, July 13, 2026  ·  Last 7 days  ·  Min severity: MEDIUM
Total Findings
358
Critical
52
High
156
Actively Exploited
6
CISA-KEV6
NVD199
GitHub-GHSA153
Findings sorted by severity
CISA-KEV

CRITICAL
Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability
CVE-2026-56291
pkg: Balbooa Forms

published: Jul 10, 2026

Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability
CVE-2026-48939
pkg: iCagenda iCagenda

published: Jul 10, 2026

iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Adobe ColdFusion Path Traversal Vulnerability
CVE-2026-48282
pkg: Adobe ColdFusion

published: Jul 7, 2026

Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Joomlack Page Builder Improper Access Control Vulnerability
CVE-2026-56290
pkg: Joomlack Page Builder

published: Jul 7, 2026

Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability
CVE-2026-48908
pkg: JoomShaper SP Page Builder

published: Jul 7, 2026

JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Langflow Authorization Bypass Through User-Controlled Key Vulnerability
CVE-2026-55255
pkg: Langflow Langflow

published: Jul 7, 2026

Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
NVD

CRITICAL
CVE-2026-61447
CVE-2026-61447
pkg: python

published: Jul 11, 2026

PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement. Attackers can influence LLM output through prompt injection to exfiltrate all environment…
CWE: CWE-94
NVD

CRITICAL
CVE-2026-54769
CVE-2026-54769
pkg: python

published: Jul 10, 2026

Langroid is a framework for building large-language-model-powered applications. Versions prior to 0.65.2 are vulnerable to a critical Sandbox Escape leading to Remote Code Execution (RCE) in its `TableChatAgent` and `VectorStore` capabilities. When these agents evaluate LLM-generated tool messages w…
CWE: CWE-94
NVD

CRITICAL
CVE-2026-59726
CVE-2026-59726
pkg: docker

published: Jul 9, 2026

Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-compose deployment exposed the MCP bridge POST /mcp and POST /mcp/:group endpoints without authentication, allowing an unauthenticated network attacker to invoke tools/call to terminal_execute, obtain a…
CWE: CWE-78, CWE-306, CWE-942
NVD

CRITICAL
CVE-2026-54782
CVE-2026-54782
pkg: windows

published: Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML 1.1 and SAML 2.0 token validation does not correctly resolve the issuer signing key or require signed tokens when IdentityConfiguration is used with federated bindings…
CWE: CWE-290, CWE-347
GitHub-GHSA

CRITICAL
Nuclio: Unsanitized cron trigger event headers/body injected into CronJob shell command leads to persistent RCE
GHSA-v5px-423j-pf7p
pkg: github.com/nuclio/nuclio
eco: go
published: Jul 8, 2026
## Summary

Nuclio controller builds a `curl` invocation string for each cron trigger and stores it as the `args` of a Kubernetes CronJob container (`/bin/sh`, `-c`, `<command>`). Two fields in the trigger specification flow into this string without adequate sanitization:

– `event.headers` keys —…

CVE-2026-52831
GitHub-GHSA

CRITICAL
9router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats
GHSA-vjc7-jrh9-9j86
pkg: 9router
eco: npm
published: Jul 6, 2026

title: Unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats
product: 9Router
version: <= 0.4.41
severity: critical
cve_request: true

## Summary

Multiple critical API security vulnerabilities were discovered in 9Router's Next.js dashboard. The `/api/providers` e…

NVD

CRITICAL
CVE-2026-57572
CVE-2026-57572
pkg: kidocode crawl4ai

published: Jul 6, 2026

Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server accepted request-supplied browser_config.extra_args, which flowed into Chromium's launch arguments. An attacker could inject Chromium switches that replace a child-process launch command together w…
CWE: CWE-88, CWE-94
GitHub-GHSA

CRITICAL
Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent
GHSA-q9p7-wqxg-mrhc
pkg: langroid
eco: pip
published: Jul 6, 2026
### Advisory Details
**Title**: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent

**Description**:
### Summary
Langroid is vulnerable to a critical Sandbox Escape leading to Remote Code Execution (RCE) in its `TableChatAgent` and `VectorStore` capabilities…

CVE-2026-54769
NVD

CRITICAL
CVE-2026-14480
CVE-2026-14480
pkg: python

published: Jul 10, 2026

OpenPLC Runtime v3 contains an authenticated arbitrary file write
vulnerability in the legacy web UI program‑upload workflow. The
application stores an attacker‑supplied filename (prog_file) directly
into the Programs.File database field and later uses this value as the
destination path for …
CWE: CWE-73
GitHub-GHSA

CRITICAL
SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content
GHSA-56mp-4f3v-fgj2
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: Jul 10, 2026
SiYuan v3.6.5 and earlier versions contain a stored cross-site scripting (XSS) vulnerability in the Attribute View (database) asset cell renderer that escalates to remote code execution (RCE) in the Electron desktop client. This is a neighbor-bug of CVE-2026-44588: the fix for -44588 used `escapeAri…
CVE-2026-50551
GitHub-GHSA

CRITICAL
SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML()
GHSA-5xfx-xj4h-5p7r
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: Jul 10, 2026
### Summary

The attribute-view (database) cell renderer `genAVValueHTML` interpolates cell content raw in four of its branches: `text`, `url`, `phone`, and `mAsset`. A cell value like `</textarea><img src=x onerror="…">` or `"><img src=x onerror="…">` breaks out of its surrounding tag and runs …

CVE-2026-54158
GitHub-GHSA

CRITICAL
SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet()
GHSA-mvjr-vv3c-w4qv
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: Jul 10, 2026
### Summary

A CSS snippet body containing `</style>` breaks out of its surrounding `<style>` tag when `renderSnippet()` interpolates it via `insertAdjacentHTML`. A payload like `</style><img src=x onerror="…">` runs arbitrary JavaScript in the renderer. On Electron desktop builds the renderer run…

CVE-2026-54067
NVD

CRITICAL
CVE-2026-55500
CVE-2026-55500
pkg: jwt

published: Jul 10, 2026

9Router is an AI router & token saver. Prior to 0.4.80, the /api/settings/database endpoint allows full database export (containing all credentials, API keys, OAuth tokens, and settings) and full database import (complete overwrite) without any authentication requirement beyond the ALWAYS_PROTECTED …
CWE: CWE-200
GitHub-GHSA

CRITICAL
9routers has Exposure of Sensitive Information and Unprotected Database Import/Export, Allowing Complete Credential Theft and Database Takeover
GHSA-qvfm-67h2-2qfx
pkg: 9router
eco: npm
published: Jul 6, 2026
## Summary

The `/api/settings/database` endpoint allows full database export (containing all credentials, API keys, OAuth tokens, and settings) and full database import (complete overwrite) without any authentication requirement beyond the `ALWAYS_PROTECTED` middleware check, which only validates J…

CVE-2026-55500
NVD

CRITICAL
CVE-2026-34038
CVE-2026-34038
pkg: docker

published: Jul 6, 2026

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, an authenticated remote command injection vulnerability in application deployment handling allows users with application write permissions to achieve remote code execution and…
CWE: CWE-78
NVD

CRITICAL
CVE-2026-56271
CVE-2026-56271
pkg: jwt

published: Jul 12, 2026

Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience and issuer values ('AUDIENCE', 'ISSUER') in the enterprise passport authentication middleware (packages/server/src/enterprise/middleware/passport/i…
CWE: CWE-321
NVD

CRITICAL
CVE-2026-57807
CVE-2026-57807
pkg: oauth

published: Jul 10, 2026

Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd. OAuth Single Sign On – SSO (OAuth Client) allows Password Recovery Exploitation.

This issue affects OAuth Single Sign On – SSO (OAuth Client): from n/a through 38.5.8.

CWE: CWE-288
NVD

CRITICAL
CVE-2026-12761
CVE-2026-12761
pkg: oauth

published: Jul 10, 2026

The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass leading to account takeover in versions up to and including 7.7.0. This is due to the Profile Completion flow accepting an arbitrary email address via the 'email_…
CWE: CWE-287
NVD

CRITICAL
CVE-2026-61459
CVE-2026-61459
pkg: kubernetes

published: Jul 10, 2026

MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) that allows attackers to bypass the assertNoDangerousFlags security check by supplying resourceType and name parameters with leading dashes. Attackers c…
CWE: CWE-88
NVD

CRITICAL
CVE-2026-13019
CVE-2026-13019
pkg: esri portal_for_arcgis, kubernetes kubernetes, linux linux_kernel

published: Jul 7, 2026

Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API.
CWE: CWE-640
NVD

CRITICAL
CVE-2026-9182
CVE-2026-9182
pkg: esri arcgis_server, linux linux_kernel, microsoft windows

published: Jul 6, 2026

Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endpoint. Successful exploitation could allow arbitrary file upload, potentially allowing for other attacks. This issue impacts all …
CWE: CWE-434
NVD

CRITICAL
CVE-2026-9181
CVE-2026-9181
pkg: esri arcgis_server, linux linux_kernel, microsoft windows

published: Jul 6, 2026

Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An unauthenticated attacker could exploit this issue by sending crafted path parameters. Successful exploitation could allow overwriting sensitive files on the system. Abuse of this issu…
CWE: CWE-22
NVD

CRITICAL
CVE-2026-59151
CVE-2026-59151
pkg: jwt

published: Jul 10, 2026

Prowler is a cloud security platform. Prior to 5.30.3, Prowler's SAML authentication flow trusted the email domain asserted in a SAMLResponse when deciding which tenant should receive the final token, and the ACS finish logic in api/src/backend/api/v1/views.py recalculated the tenant from user.email…
CWE: CWE-287
NVD

CRITICAL
CVE-2026-13461
CVE-2026-13461
pkg: ssl

published: Jul 9, 2026

When coupled with the SSL bypass vulnerability, JavaScript can be injected into a WebView in the PayRange version 7.0.7 app. The injection of specific JavaScript function calls allows the attacker to escape the WebView sandbox and perform a number of dangerous actions on the user's device.
NVD

CRITICAL
CVE-2026-15113
CVE-2026-15113
pkg: google chrome, google android

published: Jul 8, 2026

Use after free in Autofill in Google Chrome on Android prior to 150.0.7871.115 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
GitHub-GHSA

CRITICAL
Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE
GHSA-xqhv-chqm-fhcc
pkg: github.com/BishopFox/joro
eco: go
published: Jul 8, 2026
# Unauthenticated Cross-Origin Plugin Upload Leads to RCE (Joro ≤ v1.1.0)

**Severity:** Critical
**CVSS v3.1:** 9.6 (AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H)
**Affected versions:** Joro ≤ v1.1.0, proxy mode (default), Linux/macOS
**Reporter:** cstover
**Date:** 2026-05-27

## Summary

Joro's d…

CVE-2026-53649
NVD

CRITICAL
CVE-2026-15062
CVE-2026-15062
pkg: python

published: Jul 8, 2026

SQL injection vulnerabilities in the Snowflake Snowpark Python SDK (snowpark-python) versions prior to 1.53.0 could allow authenticated low-privilege users to execute SQL beyond their authorization scope. An attacker could exploit these vulnerabilities by embedding SQL payloads in source database co…
CWE: CWE-89
GitHub-GHSA

CRITICAL
Goploy: Cross-namespace IDOR and RCE via body-supplied row id in project and project_file handlers
GHSA-26rh-24rg-j3vv
pkg: github.com/zhenorzz/goploy
eco: go
published: Jul 7, 2026
### Summary

`Project.AddFile`, `Project.EditFile`, `Project.RemoveFile`, and `Project.Edit` in `cmd/server/api/project/handler.go` accept a project or project-file row id from the JSON body and act on it without checking that the project belongs to the caller's namespace. The corresponding `model.P…

CVE-2026-53552
GitHub-GHSA

CRITICAL
@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints
GHSA-5rr4-8452-hf4v
pkg: @better-auth/sso
eco: npm
published: Jul 7, 2026
### Am I affected?

Users are affected if all of the following are true:

– Their application uses `@better-auth/sso` at a version `>= 0.1.0, < 1.6.11` on the stable line, or any `1.7.0-beta.x` on the pre-release line.
– The `sso()` plugin is added to their application's `betterAuth({ plugins: […]…

CVE-2026-53513
NVD

CRITICAL
CVE-2026-55879
CVE-2026-55879
pkg: jwt

published: Jul 10, 2026

OpenReplay is a self-hosted session replay suite. From 1.24.0 before 1.25.0, the OpenReplay tracking SDK accepts custom event names and captured page URLs from any visitor using a public project key, stores them in ClickHouse without output encoding, and later renders them in the authenticated dashb…
CWE: CWE-79
GitHub-GHSA

CRITICAL
Authorizer: Unvalidated redirect_uri in /authorize leaks OAuth2 tokens to attacker-controlled URL
GHSA-h29v-hj44-q8cv
pkg: github.com/authorizerdev/authorizer
eco: go
published: Jul 10, 2026
## Summary

The `/authorize` endpoint accepts any `redirect_uri` without validating it against `AllowedOrigins`. When `response_type=token` or `response_type=id_token`, the server appends `access_token`, `id_token`, and `refresh_token` as query parameters and issues a 302 redirect to the attacker-su…

CVE-2026-54072
NVD

CRITICAL
CVE-2026-15378
CVE-2026-15378
pkg: kubernetes

published: Jul 10, 2026

A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind Server-Side Request Forgery (SSRF) by submitting a specially crafted XML Schema Definition (XSD) string. This can lead to unauthorized access to sensitive information, including c…
CWE: CWE-918
GitHub-GHSA

CRITICAL
Zebra: Missing copy constraint in halo2_gadgets variable-base scalar multiplication allows under-constrained base, breaking Orchard Action circuit soundness
GHSA-ww9q-8r59-xv46
pkg: zebrad, halo2_gadgets, orchard
eco: rust
published: Jul 6, 2026
### Summary

A soundness vulnerability in the variable-base scalar multiplication gadget of `halo2_gadgets` allowed a malicious prover to produce a valid proof for an Orchard Action with an *under-constrained* base point. Because this gadget enforces the diversified-address-integrity condition of th…

CVE-2026-54496
GitHub-GHSA

CRITICAL
Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access
GHSA-3fcv-jvfp-m4q9
pkg: github.com/cilium/cilium, github.com/cilium/cilium, github.com/cilium/cilium
eco: go
published: Jul 6, 2026
### Impact

When Cilium L7 functionality is enabled on a cluster, the Envoy instance supporting this functionality creates a world-accessible socket on cluster nodes. A local attacker would be able to access Envoy admin endpoints. Depending on deployment configuration, this can expose sensitive info…

CVE-2026-49445
NVD

CRITICAL
CVE-2026-56260
CVE-2026-56260
pkg: docker

published: Jul 12, 2026

Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. The output_path parameter accepts arbitrary filesystem paths without validation, allowing an attacker to supply absolute or path-traversal values to write to any location w…
CWE: CWE-22
GitHub-GHSA

CRITICAL
File Browser: Authentication Bypass via Proxy Auth Header Forgery
GHSA-xqp3-jq6g-x3qm
pkg: github.com/filebrowser/filebrowser/v2
eco: go
published: Jul 10, 2026
## Summary

When FileBrowser is configured with proxy authentication (`auth.method=proxy`), any unauthenticated attacker who can reach the server directly can impersonate **any user – including admin** – by sending a single forged HTTP header. No credentials are required. Additionally, specifying a …

CVE-2026-54089
NVD

CRITICAL
CVE-2026-61444
CVE-2026-61444
pkg: python

published: Jul 10, 2026

PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file parameter is directly interpolated into an f-string without sanitization. Attackers can inject arbitrary Python code that executes when the generated server code runs via subprocess.Popen()…
CWE: CWE-94
NVD

CRITICAL
CVE-2026-58122
CVE-2026-58122
pkg: oauth

published: Jul 9, 2026

Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to circumvent local-origin IP restrictions on onboarding endpoints by supplying a spoofed X-Forwarded-For header with a loopback address. Attackers can exploit this bypass to per…
CWE: CWE-348
GitHub-GHSA

CRITICAL
Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins
GHSA-pw9m-5jxm-xr6h
pkg: better-auth
eco: npm
published: Jul 7, 2026
### Am I affected?

Users are affected if all of the following are true:

– Their application uses `better-auth` and has enabled at least one of: `oidcProvider()` (imported from `better-auth/plugins/oidc-provider`), or `mcp()` (imported from `better-auth/plugins/mcp`).
– Their application has at lea…

CVE-2026-53512
GitHub-GHSA

CRITICAL
Decompress: Archive extraction can create files and links outside of the target directory
GHSA-mp2f-45pm-3cg9
pkg: @xhmikosr/decompress, @xhmikosr/decompress, decompress
eco: npm
published: Jul 6, 2026
### Impact

When extracting an archive to a directory, a crafted archive can read or write files outside that directory. The flaw is in the code that writes the parsed entries, so it affects every format decompress handles: tar, tar.gz, tar.bz2, and zip by default, plus any others added through the …

CVE-2026-53486
GitHub-GHSA

CRITICAL
TSDProxy: Internal proxy auth token forwarded to backend services enables management API escalation
GHSA-g936-7jqj-mwv8
pkg: github.com/almeidapaulopt/tsdproxy
eco: go
published: Jul 10, 2026
## Description

A vulnerability was discovered in TSDProxy where it forwards its internal per-process authentication token to all proxied backend services. When `identityHeaders` is enabled (the default), tsdproxy injects `x-tsdproxy-auth-token` into every upstream HTTP request alongside user identi…

GitHub-GHSA

CRITICAL
File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)
GHSA-m93h-4hw7-5qcm
pkg: github.com/filebrowser/filebrowser/v2
eco: go
published: Jul 10, 2026
## Overview

The Hook Authentication feature in File Browser allows administrators to delegate login verification to an external shell command. User-supplied credentials (username and password) are interpolated into this command string using `os.Expand` without sanitization. An **unauthenticated rem…

CVE-2026-54088
GitHub-GHSA

CRITICAL
`exploration` was removed from crates.io for malicious code
GHSA-99j7-fhr2-xfj4
pkg: exploration
eco: rust
published: Jul 10, 2026
A method within the `exploration` crate attempted to download and execute a payload from a remote site.

The malicious crate had 1 version published on 2026-06-02, approximately 1 hour before removal, and had no evidence of actual usage. This crate had no dependencies on crates.io.

Rustsec to Kiril…

GitHub-GHSA

CRITICAL
SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist
GHSA-hvr9-72v2-fff3
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: Jul 10, 2026
## Summary

SiYuan Note's kernel HTTP server unconditionally trusts all `chrome-extension://` origins, granting `RoleAdministrator` access to every installed browser extension without any authentication. Combined with the default empty `AccessAuthCode` on desktop installs, any Chrome/Chromium extens…

CVE-2026-54069
GitHub-GHSA

CRITICAL
Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditional RCE), mirroring the SQLChatAgent bug fixed in CVE-2026-25879
GHSA-2pq5-3q89-j7cc
pkg: langroid
eco: pip
published: Jul 6, 2026
Neo4jChatAgent passes LLM-generated Cypher queries straight to the Neo4j driver with no validation, no statement-type allowlist, and no opt-out gate. The query text is influenceable by prompt injection (direct user input or indirect content the agent reads back via RAG), so an attacker who can influ…
CVE-2026-55615
GitHub-GHSA

CRITICAL
Langroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema-qualified pg_read_file calls
GHSA-6xc5-4r68-67fc
pkg: langroid
eco: pip
published: Jul 6, 2026
# SQLChatAgent `_validate_query` dangerous-pattern regex is bypassable via quoted/commented/qualified function names

## Summary

The `SQLChatAgent` SQL-injection mitigation, with default `allow_dangerous_operations=False`, combines a raw-text regex blocklist (`_DANGEROUS_SQL_PATTERNS`) with a `sqlg…

CVE-2026-54760
NVD

HIGH
CVE-2026-14262
CVE-2026-14262
pkg: jwt

published: Jul 11, 2026

The Simple JWT Login – Allows you to use JWT on REST endpoints. plugin for WordPress is vulnerable to Authentication Bypass to Privilege Escalation in all versions up to, and including, 3.6.6 via the `payload` parameter. The vulnerability exists because `AuthenticateService::generatePayload()` onl…
CWE: CWE-269
NVD

HIGH
CVE-2026-13353
CVE-2026-13353
pkg: express

published: Jul 11, 2026

The WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.0.1 via the 'MappedFields' parameter. This is due to missing capability checks on the AJAX handlers for install_addon, s…
CWE: CWE-94
GitHub-GHSA

HIGH
SafeInstall agent guard shell parsing can miss raw package execution
GHSA-xrmc-c5cg-rv7x
pkg: safeinstall-cli
eco: npm
published: Jul 10, 2026
## Summary

SafeInstall CLI through 0.10.1 can fail to recognize some package-manager and registry-runner commands in its agent guard. Case-variant launcher names, leading file-descriptor redirections, and supported shell wrappers with options can cause a raw install command to receive no guard deci…

NVD

HIGH
CVE-2026-54149
CVE-2026-54149
pkg: node

published: Jul 10, 2026

MaxKB is an open-source AI assistant for enterprise. Prior to 2.10.0-lts, MaxKB tool import functionality in apps/tools/serializers/tool.py and MCP referencing mode in apps/application/chat_pipeline/step/chat_step/impl/base_chat_step.py do not consistently validate MCP transport type, allowing an au…
CWE: CWE-78
NVD

HIGH
CVE-2026-59148
CVE-2026-59148
pkg: express

published: Jul 9, 2026

Mockoon provides way to design and run mock APIs. Prior to 9.7.0, Mockoon's admin API in commons-server/src/libs/server/admin-api.ts is mounted on the same Express listener as user-defined mock routes, enabled by default in shipped runtimes, serves Access-Control-Allow-Origin: * with write methods a…
CWE: CWE-306, CWE-352, CWE-732, CWE-942
NVD

HIGH
CVE-2026-15133
CVE-2026-15133
pkg: google chrome

published: Jul 8, 2026

Use after free in InterestGroups in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-15132
CVE-2026-15132
pkg: google chrome

published: Jul 8, 2026

Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-457
NVD

HIGH
CVE-2026-15129
CVE-2026-15129
pkg: google chrome

published: Jul 8, 2026

Use after free in Views in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-15126
CVE-2026-15126
pkg: google chrome

published: Jul 8, 2026

Use after free in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-15125
CVE-2026-15125
pkg: google chrome

published: Jul 8, 2026

Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-863
NVD

HIGH
CVE-2026-15123
CVE-2026-15123
pkg: google chrome

published: Jul 8, 2026

Inappropriate implementation in DOM in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-122
NVD

HIGH
CVE-2026-15121
CVE-2026-15121
pkg: google chrome

published: Jul 8, 2026

Use after free in WebRTC in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-15118
CVE-2026-15118
pkg: google chrome

published: Jul 8, 2026

Use after free in Input in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-15116
CVE-2026-15116
pkg: google chrome

published: Jul 8, 2026

Use after free in Actor in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-15114
CVE-2026-15114
pkg: google chrome

published: Jul 8, 2026

Out of bounds read and write in Codecs in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. (Chromium security severity: High)
CWE: CWE-125, CWE-787
NVD

HIGH
CVE-2026-15112
CVE-2026-15112
pkg: google chrome

published: Jul 8, 2026

Use after free in Ozone in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-15110
CVE-2026-15110
pkg: google chrome

published: Jul 8, 2026

Use after free in Extensions in Google Chrome prior to 150.0.7871.115 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-15107
CVE-2026-15107
pkg: google chrome

published: Jul 8, 2026

Use after free in IndexedDB in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-416
NVD

HIGH
CVE-2026-59257
CVE-2026-59257
pkg: n8n n8n

published: Jul 8, 2026

n8n before 1.123.61, 2.x before 2.27.4, and 2.28.x before 2.28.1 contains a SQL injection vulnerability in the legacy MySQL v1 node's executeQuery operation. The operation substitutes evaluated {{ … }} expression values directly into the raw SQL string without parameterization. When a workflow use…
CWE: CWE-89
NVD

HIGH
CVE-2026-34158
CVE-2026-34158
pkg: docker

published: Jul 7, 2026

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, the executeInDocker() helper wraps user-controlled commands in single quotes without escaping embedded single quotes. Attackers who can edit application settings can inject a …
CWE: CWE-78
NVD

HIGH
CVE-2026-34168
CVE-2026-34168
pkg: docker

published: Jul 7, 2026

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the LocalPersistentVolume.name field is interpolated directly into docker volume shell commands without shell argument escaping, allowing an authenticated user to set a storag…
CWE: CWE-78
NVD

HIGH
CVE-2026-42204
CVE-2026-42204
pkg: docker

published: Jul 6, 2026

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. From 4.0.0-beta.471 through 4.0.0-beta.473, a regression in SHELL_SAFE_COMMAND_PATTERN allowed ampersands in custom Docker Compose build, start, and pre/post-deployment command fields, allowing an aut…
CWE: CWE-78
NVD

HIGH
CVE-2026-34599
CVE-2026-34599
pkg: docker

published: Jul 6, 2026

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, there is an authenticated command injection vulnerability in the GetLogs Livewire component which allows users with team membership (lowest privilege member role) to execute a…
CWE: CWE-78
GitHub-GHSA

HIGH
Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requests
GHSA-659f-rgp5-w4wf
pkg: github.com/zalando/skipper
eco: go
published: Jul 8, 2026
### Summary

`zalando/skipper`'s OpenPolicyAgent integration silently bypasses request-body
inspection on HTTP/1.1 `Transfer-Encoding: chunked` and HTTP/2 requests that
omit the `content-length` pseudo-header. When the
`opaAuthorizeRequestWithBody` filter is configured, the
`OpenPolicyAgentInstance.…

CVE-2026-50197
NVD

HIGH
CVE-2026-14891
CVE-2026-14891
pkg: docker

published: Jul 8, 2026

HashiCorp Nomad and Nomad Enterprise are vulnerable to a sandbox escape in the Docker task driver that may allow a job submitter to bind-mount a host path into a container even when volume bind mounts are disabled, potentially leading to reading and writing files on the host. This vulnerability, CVE…
CWE: CWE-59
GitHub-GHSA

HIGH
Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default
GHSA-9h47-pqcx-hjr4
pkg: better-auth
eco: npm
published: Jul 7, 2026
### Am I affected?

Users are affected if all of the following are true:

– Their application uses `better-auth` at a version below the patched release.
– Their application enables `oidcProvider()` from `better-auth/plugins/oidc-provider` or `mcp()` from `better-auth/plugins/mcp` (the mcp plugin del…

GitHub-GHSA

HIGH
Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID
GHSA-9rjw-3gwp-f59v
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

`UpsertWorkspaceApp` overwrites an existing app's `agent_id` on a primary-key conflict and `insertAgentApp` accepts the app ID from the provisioner's `CompleteJob` payload without verifying it belongs to the workspace being built. `CompleteJob` runs under `dbauthz.AsProvisionerd` so the…

CVE-2026-55429
NVD

HIGH
CVE-2026-52747
CVE-2026-52747
pkg: nginx

published: Jul 10, 2026

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Prior to 3.0.16, the multipart/form-data request body parser in libmodsecurity silently removes embedded line breaks from non-file form-field values before exporting them to ARGS and ARGS_P…
CWE: CWE-180
NVD

HIGH
CVE-2026-56261
CVE-2026-56261
pkg: docker

published: Jul 10, 2026

Crawl4AI before 0.8.7 contains a server-side request forgery (SSRF) vulnerability in the Docker API server's /crawl/job and /llm/job endpoints, which accept webhook URLs without destination validation. An attacker can supply webhook URLs pointing to private or internal IP ranges, Docker networks, or…
CWE: CWE-918
NVD

HIGH
CVE-2026-57573
CVE-2026-57573
pkg: kidocode crawl4ai

published: Jul 6, 2026

Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server applied its SSRF destination check on the non-streaming /crawl path but not on the streaming path. handle_stream_crawl_request passed seed URLs straight to the crawler with no destination validatio…
CWE: CWE-918
NVD

HIGH
CVE-2026-54765
CVE-2026-54765
pkg: traefik traefik

published: Jul 6, 2026

Traefik is an open source HTTP reverse proxy and load balancer. From v3.7.0 prior to v3.7.6, Traefik's Kubernetes Gateway API provider may resolve two accepted HTTPRoutes that target the same backend Service:port but configure different backendRef filters to the same child service and apply only one…
CWE: CWE-284, CWE-863
GitHub-GHSA

HIGH
flyto-core has Unauthenticated Command Execution via HTTP MCP `execute_module`
GHSA-h9f9-h6gm-wc85
pkg: flyto-core
eco: pip
published: Jul 6, 2026
## Unauthenticated Command Execution via HTTP MCP `execute_module`

### Summary

The HTTP MCP endpoint (`POST /mcp`) in flyto-core accepts unauthenticated JSON-RPC `tools/call` requests and dispatches them to arbitrary registered modules, including `sandbox.execute_shell`, which passes attacker-cont…

CVE-2026-55786
GitHub-GHSA

HIGH
melange: Incomplete package integrity verification allows data section substitution
GHSA-fpg8-7664-jc5q
pkg: chainguard.dev/apko, chainguard.dev/melange
eco: go
published: Jul 10, 2026
Previously, Apko verified the control section hash (`.PKGINFO` etc.) against the signed `APKINDEX`, but never verified the data section hash (the actual package files that get installed). An attacker who could compromise a mirror, poison a cache, or MITM a package fetch could substitute arbitrary fi…
CVE-2026-54174
NVD

HIGH
CVE-2026-47829
CVE-2026-47829
pkg: openssh

published: Jul 9, 2026

Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-spawned ssh process when an operator runs bosh ssh -c, bosh logs -f, or other non-interactive SSH paths, leading to local command execution on the operator's workstation.
Affected v…
NVD

HIGH
CVE-2026-15122
CVE-2026-15122
pkg: google chrome, microsoft windows

published: Jul 8, 2026

Insufficient validation of untrusted input in Codecs in Google Chrome on Windows prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-20
NVD

HIGH
CVE-2026-15120
CVE-2026-15120
pkg: google chrome, microsoft windows

published: Jul 8, 2026

Use after free in Core in Google Chrome on Windows prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-15119
CVE-2026-15119
pkg: google chrome

published: Jul 8, 2026

Race in GetUserMedia in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-362
NVD

HIGH
CVE-2026-55830
CVE-2026-55830
pkg: python

published: Jul 8, 2026

RestrictedPython is a tool that helps to define a subset of the Python language which allows to provide a program input into a trusted environment. Prior to 8.3, check_function_argument_names() rejected protected guard hook names for regular, variadic, and keyword-only arguments but omitted position…
CWE: CWE-184
GitHub-GHSA

HIGH
Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE
GHSA-37h2-6p4f-mp3q
pkg: serena-agent
eco: pip
published: Jul 8, 2026
### Summary

Serena's built-in web dashboard exposes an unauthenticated Flask API on a fixed, predictable port (TCP 24282, hardcoded as `0x5EDA` in `constants.py`). The server has no authentication, no CSRF protection, and no Host header validation. A DNS rebinding attack allows a malicious webpage …

CVE-2026-49471
GitHub-GHSA

HIGH
@better-auth/scim: Account/provider takeover via missing owner binding on non-org SCIM providers
GHSA-j8v8-g9cx-5qf4
pkg: @better-auth/scim
eco: npm
published: Jul 7, 2026
### Am I affected?

Users are affected if all of these hold:

– They install and register the `@better-auth/scim` plugin (`plugins: [scim()]`).
– They create SCIM providers without an `organizationId`, that is, non-organization ("personal") providers. Organization-scoped providers are not affected b…

GitHub-GHSA

HIGH
Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email
GHSA-g38m-r43w-p2q7
pkg: better-auth
eco: npm
published: Jul 7, 2026
### Am I affected?

Users are affected if all of the following are true:

– Their application uses `better-auth` at a version `< 1.6.11` on the stable line, or any current `next` pre-release.
– `emailAndPassword.enabled: true` is set in their application's `betterAuth({ … })` configuration.
– At l…

CVE-2026-53516
GitHub-GHSA

HIGH
Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write
GHSA-qrwj-vh9x-gw5v
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

`agentConn.apiClient()` used the default redirect behavior of `http.Client` while its custom transport dialed the host from the request URL as long as the port was the workspace agent HTTP API port (`4`). Agent tailnet IPs are deterministic from agent UUIDs, so a malicious workspace age…

GitHub-GHSA

HIGH
Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`
GHSA-mcqq-fqgf-rxwm
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

`coder config-ssh` wrote server-supplied SSH settings (`HostnameSuffix`, `SSHConfigOptions`) into the user's `~/.ssh/config` without sanitizing embedded newlines or restricting directives so a malicious or compromised Coder server could inject arbitrary SSH configuration.

> **Note:** P…

CVE-2026-55427
NVD

HIGH
CVE-2026-56259
CVE-2026-56259
pkg: docker

published: Jul 12, 2026

Crawl4AI before 0.8.8 contains credential exfiltration vulnerabilities in the Docker API server that allow attackers to redirect LLM API calls to attacker-controlled endpoints and read arbitrary environment variables. Attackers can exploit the unauthenticated /md, /llm, and /llm/job endpoints by sup…
CWE: CWE-200
NVD

HIGH
CVE-2026-53657
CVE-2026-53657
pkg: linux

published: Jul 10, 2026

Lima launches Linux virtual machines, typically on macOS, for running containerd. Prior to 2.1.3, on an instance of Lima running with the qemu driver, an arbitrary user in the VM could access /run/lima-guestagent.sock when the guest agent is enabled, which could result in running arbitrary commands …
CWE: CWE-276, CWE-668
NVD

HIGH
CVE-2026-54423
CVE-2026-54423
pkg: node

published: Jul 10, 2026

In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI commands to a node, bypassing Ironic's access control.
CWE: CWE-424
GitHub-GHSA

HIGH
`lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes
GHSA-4jhm-jv67-739f
pkg: lxml_html_clean
eco: pip
published: Jul 8, 2026
# `lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes (`xlink:href`)

**Reporter:** Guillem Lefait <guillem@datamq.com> · **Date:** 2026-05-10
**Affected:** `lxml` ≤ 6.1.0 and `lxml_html_clean` ≤ 0.4.4 (latest stable)
**Confirmed against:** lxml 6.1.0 + lx…

CVE-2026-49825
GitHub-GHSA

HIGH
Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator
GHSA-wrq8-fcv5-8hvp
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

The tailnet coordinator validates that an agent's `Addresses` derive from its authenticated UUID but applies no equivalent check to `AllowedIPs`. The coordinator forwards agent-supplied `AllowedIPs` verbatim to tunnel peers which install them into the WireGuard peer configuration.

### …

CVE-2026-55428
NVD

HIGH
CVE-2026-59195
CVE-2026-59195
pkg: pnpm pnpm

published: Jul 6, 2026

pnpm is a package manager. Prior to 10.34.4 and 11.8.0, pnpm accepts package names from the env lockfile configDependencies section and uses those names directly when creating config dependency symlinks under node_modules/.pnpm-config. A malicious repository can commit a crafted pnpm-lock.yaml whose…
CWE: CWE-22
NVD

HIGH
CVE-2026-56668
CVE-2026-56668
pkg: oauth

published: Jul 10, 2026

ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's OAuth2 Token Exchange endpoint for urn:ietf:params:oauth:grant-type:token-exchange does not verify that the subject token belongs to the requesting client or that requested scopes remain within the original token's sc…
CWE: CWE-862
NVD

HIGH
CVE-2026-12597
CVE-2026-12597
pkg: oauth

published: Jul 10, 2026

The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via the GitHub OAuth callback in versions up to, and including, 6.2.3. The vulnerability exists in the loginpress_on_github_login() function, which blindly trusts the first element (profile[0]['email']) of the array retur…
CWE: CWE-287
NVD

HIGH
CVE-2026-12595
CVE-2026-12595
pkg: oauth

published: Jul 10, 2026

The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via Unverified OAuth Email in all versions up to and including 6.2.3. The vulnerability exists in the loginpress_on_discord_login() Discord OAuth callback handler, which accepts the email field returned by Discord's /user…
CWE: CWE-287
NVD

HIGH
CVE-2026-31985
CVE-2026-31985
pkg: tls

published: Jul 9, 2026

When the upstream Guardian or CMC was configured in the Remote Collector via n2os-tui, the generated configuration disabled TLS certificate verification, and no option was provided to enable it. A malicious actor could perform a man-in-the-middle attack and intercept the communication between the Re…
CWE: CWE-671
NVD

HIGH
CVE-2026-54591
CVE-2026-54591
pkg: python

published: Jul 8, 2026

AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Prior to 2.23.1, a malicious SSH server can write arbitrary files on the asyncssh SCP client's filesystem by sending filenames containing ../ tra…
CWE: CWE-22
GitHub-GHSA

HIGH
NL Portal: IDOR allows any authenticated user to complete and tamper with another user's taak
GHSA-6h3c-r723-7fx3
pkg: nl.nl-portal:taak
eco: maven
published: Jul 8, 2026
## Impact

In versions from 1.5.0 up to and including 3.0.0, any authenticated portal user could complete and tamper with another user's open task by submitting it on their behalf. The task submission endpoint accepted a task ID and a payload, but it never checked whether the task actually belonged …

CVE-2026-49464
NVD

HIGH
CVE-2026-54652
CVE-2026-54652
pkg: nginx

published: Jul 8, 2026

Frigate is an open source network video recorder. In version 0.17.1, the GET /api/logs/{service} endpoint allows any authenticated user including the viewer role to download Frigate and nginx logs, exposing auto-generated admin passwords and camera credentials logged in request query strings and ena…
CWE: CWE-269, CWE-532, CWE-598, CWE-863
GitHub-GHSA

HIGH
@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive
GHSA-7w99-5wm4-3g79
pkg: @better-auth/oauth-provider, better-auth
eco: npm
published: Jul 7, 2026
### Am I affected?

Users are affected if all of the following are true:

– Their project depends on `@better-auth/oauth-provider` at a version `>= 1.6.0, < 1.6.11`, or uses the embedded plugin in `better-auth >= 1.4.8-beta.7, < 1.6.0`, or enables the legacy `oidc-provider` or `mcp` plugins from `be…

CVE-2026-53518
GitHub-GHSA

HIGH
Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption
GHSA-392p-2q2v-4372
pkg: @better-auth/oauth-provider, better-auth
eco: npm
published: Jul 7, 2026
### Am I affected?

Users are affected if all of the following are true:

– Their project depends on `@better-auth/oauth-provider` at a version `>= 1.6.0, < 1.6.11`, or uses the embedded plugin in `better-auth >= 1.4.8-beta.7, < 1.6.0`.
– At least one OAuth client served by their application's autho…

CVE-2026-53517
NVD

HIGH
CVE-2026-13020
CVE-2026-13020
pkg: esri portal_for_arcgis, kubernetes kubernetes, linux linux_kernel

published: Jul 7, 2026

A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. ArcGIS Administrators should configure an …
CWE: CWE-640
GitHub-GHSA

HIGH
Langroid: handle_message() executes user-supplied tool JSON without sender verification
GHSA-gjgq-w2m6-wr5q
pkg: langroid
eco: pip
published: Jul 6, 2026
## Summary

A Langroid application exposing a chat interface to untrusted users may allow direct tool invocation via raw JSON payloads, even when tools are registered with `use=False, handle=True`.

## Details

`enable_message(…, use=False, handle=True)` only prevents the LLM from being instructed…

CVE-2026-54771
NVD

HIGH
CVE-2026-49297
CVE-2026-49297
pkg: apache apache-airflow-providers-google

published: Jul 6, 2026

Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object names returned by the bucket listing API directly to a destination filesystem path without normalisation or containment check. A user with write access to the source GCS bucket (ty…
CWE: CWE-22
GitHub-GHSA

HIGH
DSpace has possible Remote Code Execution (RCE) through Velocity Templates used by LDN
GHSA-9×82-rm84-c6x7
pkg: org.dspace:dspace-api, org.dspace:dspace-api, org.dspace:dspace-api
eco: maven
published: Jul 8, 2026
## Overview

Remote Code Execution (RCE) is possible via Velocity Templates used by DSpace for [COAR Notify/LDN messages](https://wiki.lyrasis.org/spaces/DSDOC9x/pages/379126679/COAR+Notify). _This vulnerability impacts DSpace versions 8.0 <= 8.3, 9.0 <= 9.2._ The attacker MUST already have DSpace a…

CVE-2026-49832
NVD

HIGH
CVE-2026-10667
CVE-2026-10667
pkg: node

published: Jul 12, 2026

Zephyr's dynamic kernel-object tracking (kernel/userspace/userspace.c, formerly kernel/userspace.c) maintains a doubly-linked list (obj_list) of dynamically allocated kernel objects. Iteration over this list in k_object_wordlist_foreach() was performed under lists_lock using the SAFE iterator (which…
CWE: CWE-416
GitHub-GHSA

HIGH
BabelDOC: Arbitrary Code Execution via CMap Pickle Deserialization in babeldoc/pdfminer/cmapdb.py
GHSA-m8gf-v64p-gfmg
pkg: BabelDOC
eco: pip
published: Jul 10, 2026
## Arbitrary Code Execution via CMap Pickle Deserialization in babeldoc/pdfminer/cmapdb.py

### Summary

BabelDOC's vendored PDF parser (`babeldoc/pdfminer/cmapdb.py`) deserializes untrusted pickle data when loading CMap files. The `_load_data()` method strips only NUL bytes from a PDF-controlled CM…

CVE-2026-54071
NVD

HIGH
CVE-2026-61437
CVE-2026-61437
pkg: python

published: Jul 10, 2026

PraisonAI (pip package praisonaiagents) before 1.6.78 contains an unsafe dynamic module loading vulnerability in AgentFlow._resolve_pydantic_class (src/praisonai-agents/praisonaiagents/workflows/workflows.py). When a workflow step uses a string output_pydantic reference, the framework locates and im…
CWE: CWE-693
NVD

HIGH
CVE-2026-22927
CVE-2026-22927
pkg: omnissa workspace_one_tunnel, microsoft windows

published: Jul 8, 2026

Omnissa Workspace ONE® Tunnel for Windows addresses a Local Privilege Escalation Vulnerability.
CWE: CWE-22
GitHub-GHSA

HIGH
Linuxfabrik Monitoring Plugins have local privilege escalation using embedded command
GHSA-798h-hpph-m24j
pkg: linuxfabrik-lib
eco: pip
published: Jul 6, 2026
### Summary
When a check plugin places user provided input inside a command which is passed to `shell_exec`, an attacker can abuse this to run arbitrary commands. This is mainly dangerous for plugins which are listed in the sudoers file, because this allows an attacker controlling the nagios user to…
CVE-2026-55426
GitHub-GHSA

HIGH
Open Babel has out-of-bounds write in MOPAC translationVectors[] (UNIT CELL TRANSLATION)
GHSA-55f6-pf8r-c2f4
pkg: openbabel
eco: pip
published: Jul 6, 2026
### Summary

A memory-safety vulnerability in Open Babel's MOPAC output parser
allowed an out-of-bounds write into the `translationVectors[]` array
when reading the "UNIT CELL TRANSLATION" block of a crafted input
file.

### Details

The MOPAC output reader stored translation vectors from the UNIT C…

CVE-2022-46292
NVD

HIGH
CVE-2026-55659
CVE-2026-55659
pkg: oauth

published: Jul 10, 2026

Grist is spreadsheet software using Python as its formula language. Prior to 1.7.15, several server-rendered Grist pages embedded user-controlled values into the page and into inline scripts without fully escaping them, allowing cross-site scripting. On the main application page, a document's name o…
CWE: CWE-79, CWE-116
GitHub-GHSA

HIGH
mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment
GHSA-g5r6-gv6m-f5jv
pkg: mcp-atlassian
eco: pip
published: Jul 10, 2026
### Summary
`confluence_upload_attachment` passes `file_path` directly to `open(file_path, "rb")` with no path validation. Any authenticated MCP client — or an AI agent manipulated via prompt injection — can read any file the server process can access and exfiltrate it to Confluence as an attach…
GitHub-GHSA

HIGH
mcp-atlassian: Arbitrary server-side file read via attachment upload
GHSA-wm45-qh3g-v83f
pkg: mcp-atlassian
eco: pip
published: Jul 10, 2026
### Summary

A client that can invoke MCP tools can read **arbitrary files from the server host** and exfiltrate them as Atlassian attachments. The attachment-upload tools take a client-supplied `file_path` and `open()` it on the **server's** filesystem.

The upload tools are meant to attach a file …

NVD

HIGH
CVE-2026-33655
CVE-2026-33655
pkg: go

published: Jul 9, 2026

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0-alpha.1, the default SSRF protection configuration did not apply IP filtering to hostnames; with ApplyIPFilterForDomain disabled by default, URL validation checked domain allow/bl…
CWE: CWE-918
NVD

HIGH
CVE-2026-59216
CVE-2026-59216
pkg: python

published: Jul 9, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call delivered execute:python and execute:tool Socket.IO events to a client-supplied session_id after checking only that the session was connected, allowing authenticated users who learne…
CWE: CWE-94, CWE-200, CWE-639, CWE-862
GitHub-GHSA

HIGH
Phantom: Arbitrary file write and decode-bomb DoS via unconfined MCP tool paths
GHSA-52vm-mxx8-f227
pkg: phantom-audio
eco: pip
published: Jul 9, 2026
### Impact

In Phantom <= 1.3.0, when `PHANTOM_OUTPUT_DIR` was unset (the default), the MCP tools accepted arbitrary absolute output paths with no confinement. Anything able to send tool calls (e.g. an AI agent driving the MCP interface) could **write or overwrite arbitrary files** the process user …

NVD

HIGH
CVE-2026-14373
CVE-2026-14373
pkg: docker

published: Jul 8, 2026

HashiCorp Nomad and Nomad Enterprise did not enforce the allow_privileged restriction for the Docker task driver's host namespace mode options. This may allow an authenticated job submitter to run a container in a host namespace and access information belonging to the host or to other workloads on t…
CWE: CWE-862
NVD

HIGH
CVE-2026-60002
CVE-2026-60002
pkg: openbsd openssh

published: Jul 8, 2026

ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)
CWE: CWE-416
GitHub-GHSA

HIGH
Goploy: Arbitrary File Read via Path Traversal in /deploy/fileDiff allows Remote Server Compromise
GHSA-4g5x-hcwm-82jw
pkg: github.com/zhenorzz/goploy
eco: go
published: Jul 7, 2026
> [ Click here to jump to the Simplified Chinese version (点击跳转到简体中文版本)](#goploy-系统任意文件读取)
# Goploy System Arbitrary File Read Vulnerability

## Basic Information
– **Vulnerability Name**: Goploy Endpoints Arbitrary File Read via Path Traversal
– **Vulnerability …

CVE-2026-53553
GitHub-GHSA

HIGH
Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp
GHSA-86j7-9j95-vpqj
pkg: better-auth, better-auth
eco: npm
published: Jul 7, 2026
### Am I affected?

Check each condition. Users are affected when all of the first three hold.

– Their application enables the `oidc-provider` plugin or the `mcp` plugin from `better-auth/plugins`. The `mcp` plugin wraps the same provider and carries the same defect. Both are on the migration path …

GitHub-GHSA

HIGH
Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin
GHSA-fmh4-wcc4-5jm3
pkg: better-auth
eco: npm
published: Jul 7, 2026
### Am I affected?

Users are affected if all of the following are true:

– Their application uses `better-auth` with the `organization` plugin (`import { organization } from "better-auth/plugins/organization"`).
– Their application enables a sign-up surface that allows arbitrary unverified email re…

CVE-2026-53514
GitHub-GHSA

HIGH
New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs
GHSA-6qcr-qxgr-m7fv
pkg: github.com/QuantumNous/new-api
eco: go
published: Jul 7, 2026
## Summary

The default SSRF protection configuration did not apply IP filtering to hostnames. With `ApplyIPFilterForDomain` disabled by default, URL validation checked domain allow/block rules but did not resolve a hostname and validate the resolved IP address. Authenticated users could configure n…

CVE-2026-33655
GitHub-GHSA

HIGH
Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps
GHSA-v54h-cp2w-9x4g
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

`coder open app` opens external workspace-app URLs without validating the scheme or host. When an external app URL contains the `$SESSION_TOKEN` placeholder the CLI replaces it with the user's real session token before handing the URL to the OS open handler.

> **Note:** Practical explo…

CVE-2026-55431
GitHub-GHSA

HIGH
OpenRemote has Cross-Realm User Information Disclosure in UserResourceImpl
GHSA-xqr9-4wvv-gvch
pkg: io.openremote:openremote-manager
eco: maven
published: Jul 6, 2026
### Summary

A realm admin of tenant B can read the profile, client roles, and realm roles of any user in any other realm (including the master realm) by supplying the target user's UUID in the REST API path. Three read endpoints in UserResourceImpl check whether the caller holds the read:admin role…

CVE-2026-54641
GitHub-GHSA

HIGH
OpenRemote has an incomplete fix for CVE-2026-40882: XXE in KNXProtocol.startAssetImport() allows arbitrary file read via unprotected XMLInputFactory
GHSA-7v6w-c3f4-9wpq
pkg: io.openremote:openremote-agent
eco: maven
published: Jul 6, 2026
### Summary
The fix for CVE-2026-40882 addressed only the Velbus asset import handler. The KNX asset import handler (`KNXProtocol`) processes user-uploaded ETS project ZIP files through Saxon XSLT and `XMLInputFactory.newInstance()` with no XXE protection, allowing any authenticated user to read arb…
CVE-2026-54640
NVD

HIGH
CVE-2026-55229
CVE-2026-55229
pkg: docker

published: Jul 10, 2026

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.34.0, Gotenberg's /forms/libreoffice/convert endpoint allows a specially crafted document to cause LibreOffice to automatically retrieve external HTTP(S) resources and local file resources during document conversion, enabling blin…
CWE: CWE-918
GitHub-GHSA

HIGH
Excelize: Unbounded Row Index Allocation in Worksheet Parser (checkSheet OOM/Panic DoS)
GHSA-h69g-9hx6-f3v4
pkg: github.com/xuri/excelize/v2
eco: go
published: Jul 10, 2026
## Unbounded Row Index Allocation in Worksheet Parser (checkSheet OOM/Panic DoS)

### Summary
The `checkSheet()` function in `github.com/xuri/excelize/v2` uses an attacker-controlled `<row r="N">` XML attribute value directly as the length argument to `make([]xlsxRow, row)` without validating it aga…

CVE-2026-54063
GitHub-GHSA

HIGH
SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894
GHSA-p4m3-mgmm-c664
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: Jul 10, 2026
## Summary
The patch for CVE-2026-41894 ("Path Traversal via Double URL Encoding") sanitized the `/export/` route but the
**identical root cause remains in the `/assets/*path` route**. In publish mode (anonymous read-only HTTP endpoint,
default port 6808), an unauthenticated remote attacker ca…
CVE-2026-54066
NVD

HIGH
CVE-2026-54063
CVE-2026-54063
pkg: go

published: Jul 10, 2026

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, the checkSheet() function in github.com/xuri/excelize/v2 uses an attacker-controlled <row r="N"> XML attribute value directly as the length argument to make([]xlsxRow, row) without validating it …
CWE: CWE-770
GitHub-GHSA

HIGH
libp2p: CPU DoS via oversized IHAVE and IWANT control message arrays
GHSA-cwc9-cp4j-mcvv
pkg: @libp2p/gossipsub
eco: npm
published: Jul 10, 2026
### Summary
gossipsub processes IHAVE and IWANT control messages by iterating every received message ID synchronously before doing anything with the results. There is no cap on how many IDs a single frame may contain. The default LP frame limit is 4MB, which fits roughly 180,000 message IDs. Iterati…
CVE-2026-49866
GitHub-GHSA

HIGH
Mistune: Potential DoS via quadratic-time parsing in parse_link_text
GHSA-qcq2-496w-v96p
pkg: mistune
eco: pip
published: Jul 9, 2026
### Summary
Mistune is vulnerable to a CPU exhaustion DoS due to superlinear (approximately O(n²)) behavior in parse_link_text. A relatively small input consisting of repeated [ characters causes significant parsing slowdown.

### Affected component
mistune/inline_parser.py → **parse_link_text**

CVE-2026-49851
NVD

HIGH
CVE-2026-54695
CVE-2026-54695
pkg: python

published: Jul 9, 2026

Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. Prior to 1.4.0, the pipecat development runner registers a /ws WebSocket endpoint for telephony testing that accepts connections without authentication, reads an attacker-supplied callSid fr…
CWE: CWE-862
NVD

HIGH
CVE-2026-13462
CVE-2026-13462
pkg: ssl

published: Jul 9, 2026

PayRange Android app, version 7.0.7 and below, contains an SSL bypass vulnerability that allows invalid certificates to be accepted in application webviews. A remote and unauthenticated attacker can steal information that the user sends.
NVD

HIGH
CVE-2026-11404
CVE-2026-11404
pkg: tls

published: Jul 9, 2026

Cesanta Mongoose before 7.22 contains an out-of-bounds read in the built-in TLS server function mg_tls_server_recv_hello(), which uses an attacker-controlled session_id_len byte from a TLS ClientHello as a buffer index without validating it against the length of received data. A remote, unauthentica…
CWE: CWE-125
GitHub-GHSA

HIGH
org.hl7.fhir.core: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint
GHSA-7cmj-v6x8-frvv
pkg: ca.uhn.hapi.fhir:org.hl7.fhir.dstu2, ca.uhn.hapi.fhir:org.hl7.fhir.dstu2016may, ca.uhn.hapi.fhir:org.hl7.fhir.dstu3
eco: maven
published: Jul 9, 2026
# Summary
All implementations of FHIRPathEngine accept arbitrary FHIRPath expressions and evaluate them without input validation. The utility intended to secure this evaluation did so incorrectly, and did not fully cover all places in which evaluation was being done. An attacker can send a resource …
CVE-2026-49485
GitHub-GHSA

HIGH
Soup Sieve: Regular Expression Denial of Service (ReDoS) via Selector Parser
GHSA-836r-79rf-4m37
pkg: soupsieve
eco: pip
published: Jul 9, 2026
### Summary

The CSS selector parser in soupsieve (the CSS selector engine for Beautiful Soup 4) contains a regular expression vulnerable to catastrophic backtracking. When processing an attribute selector with an unterminated quoted value, the `VALUE` regex pattern in `css_parser.py` enters exponen…

CVE-2026-49477
GitHub-GHSA

HIGH
Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists
GHSA-2wc2-fm75-p42x
pkg: soupsieve
eco: pip
published: Jul 9, 2026
### Summary

The CSS selector parser in soupsieve (the CSS selector engine for Beautiful Soup 4) allocates unbounded memory when compiling large comma-separated selector lists. An attacker who can supply a crafted CSS selector string to `soupsieve.compile()` or Beautiful Soup's `.select()` / `.selec…

CVE-2026-49476
GitHub-GHSA

HIGH
Micronaut doesn't set a maximum redirect count for its HTTP Client, enabling infinite loop DoS
GHSA-387m-935m-c4vw
pkg: io.micronaut:micronaut-http-client, io.micronaut:micronaut-http-client, io.micronaut:micronaut-http-client
eco: maven
published: Jul 9, 2026
The Netty-based Micronaut HTTP Client does not impose a limit on HTTP redirections, potentially allowing an infinite redirect loop that could lead to a denial-of-service attack.

### Patches

The following versions are patched:

– For Micronaut 5, versions equal or greater than [5.0.1](https://gith…

NVD

HIGH
CVE-2026-54772
CVE-2026-54772
pkg: windows

published: Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, an unauthenticated remote attacker that can reach a NetTcpBinding, NetNamedPipeBinding, or UnixDomainSocketBinding endpoint can trigger premature EOF handling in the CoreWCF net.tc…
CWE: CWE-400, CWE-835
NVD

HIGH
CVE-2026-54499
CVE-2026-54499
pkg: python

published: Jul 8, 2026

Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human languages. Prior to 1.12.2, Stanza model loaders such as stanza.models.common.pretrain.Pretrain.load() attempt torch.load(…, weights_only=True) but fall back to torch.load(…, weights_o…
CWE: CWE-502, CWE-676
NVD

HIGH
CVE-2026-15117
CVE-2026-15117
pkg: google chrome

published: Jul 8, 2026

Use after free in Payments in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-15111
CVE-2026-15111
pkg: google chrome

published: Jul 8, 2026

Use after free in Views in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-31309
CVE-2026-31309
pkg: node

published: Jul 8, 2026

Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node before v1.36.0 allows unauthenticated attackers to arbitrarily overwrite the node's configuration and achieve a full node takeover via supplying a crafted POST request.
CWE: CWE-862
NVD

HIGH
CVE-2026-49866
CVE-2026-49866
pkg: node

published: Jul 8, 2026

libp2p is a JavaScript Implementation of libp2p networking stack. Prior to 16.0.0, @libp2p/gossipsub defaultDecodeRpcLimits set maxIhaveMessageIDs and maxIwantMessageIDs to Infinity, allowing oversized IHAVE and IWANT control message arrays in message/decodeRpc.ts and gossipsub.ts to synchronously i…
CWE: CWE-770
NVD

HIGH
CVE-2026-59939
CVE-2026-59939
pkg: python

published: Jul 8, 2026

httplib2 is a comprehensive HTTP client library for Python. Prior to 0.32.0, httplib2 performs unbounded decompression of HTTP response bodies encoded with Content-Encoding: gzip or deflate in _decompressContent in httplib2/init.py, allowing a malicious or compromised HTTP server to return a small c…
CWE: CWE-409
NVD

HIGH
CVE-2026-55404
CVE-2026-55404
pkg: linux

published: Jul 8, 2026

yt-dlp and youtube-dl are command-line audio/video downloaders. Prior to 2026.7.4, the –write-link, –write-url-link, and –write-desktop-link options can write .url or .desktop shortcut files using attacker-controlled webpage_url or filename metadata without sufficient validation or escaping, allo…
CWE: CWE-74
NVD

HIGH
CVE-2026-59928
CVE-2026-59928
pkg: mistune_project mistune

published: Jul 8, 2026

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a Markdown document containing many repeated or distinct reference-link definitions causes quadratic work in src/mistune/block_parser.py and the ref_links environment dictionary handling, allowing denial of service throu…
CWE: CWE-407, CWE-1333
NVD

HIGH
CVE-2026-59925
CVE-2026-59925
pkg: mistune_project mistune

published: Jul 8, 2026

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, long sequences of well-formed double-asterisk or triple-asterisk emphasis pairs around a character cause quadratic work in src/mistune/inline_parser.py because the parser scans forward for matching close markers from eve…
CWE: CWE-407, CWE-1333, CWE-407
NVD

HIGH
CVE-2026-59922
CVE-2026-59922
pkg: mistune_project mistune

published: Jul 8, 2026

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a run of closed tilde, equals-sign, or caret marker pairs around a character causes quadratic work in src/mistune/plugins/formatting.py when the strikethrough, mark, or insert plugin scans for matching markers from each …
CWE: CWE-407, CWE-1333, CWE-407
NVD

HIGH
CVE-2026-59892
CVE-2026-59892
pkg: node

published: Jul 8, 2026

OpenTelemetry JavaScript is the OpenTelemetry JavaScript client. Prior to 2.9.0, @opentelemetry/propagator-jaeger decodes incoming uber-trace-id and uberctx-* HTTP header values with decodeURIComponent() without handling decode errors, allowing an unauthenticated remote attacker to send a malformed …
CWE: CWE-248
NVD

HIGH
CVE-2026-59874
CVE-2026-59874
pkg: isaacs tar

published: Jul 8, 2026

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeatedly parsing the same header. This issue is fixed in version 7.5.18.
CWE: CWE-835
NVD

HIGH
CVE-2026-59873
CVE-2026-59873
pkg: isaacs tar

published: Jul 8, 2026

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to exhaust disk space a…
CWE: CWE-770
NVD

HIGH
CVE-2026-10708
CVE-2026-10708
pkg: jwt

published: Jul 8, 2026

This vulnerability enables large‑scale data harvesting without requiring app‑specific secrets. A single request to a minimal leaderboard component may return user records containing emails, UUIDs, and custom fields. The combination of wildcard CORS behavior, long‑lived twenty‑day JWTs, and t…
NVD

HIGH
CVE-2026-58656
CVE-2026-58656
pkg: jwt

published: Jul 8, 2026

Grav API plugin before v1.0.0-rc.16 accepts JWT tokens via the ?token= URL query parameter and responds with Access-Control-Allow-Origin: *, allowing unauthenticated attackers to make fully authenticated cross-origin API requests from any malicious website. Attackers who obtain a leaked JWT token fr…
CWE: CWE-598
NVD

HIGH
CVE-2026-14895
CVE-2026-14895
pkg: express

published: Jul 7, 2026

String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service.

The trim and rtrim functions stripped trailing whitespace with s/\s*$//u. Because \s* matches greedily and the $ anchor fails whenever a non-whitespace character follows the whitespace, the regex e…

CWE: CWE-1333
NVD

HIGH
CVE-2026-56811
CVE-2026-56811
pkg: phoenixframework phoenix

published: Jul 7, 2026

Allocation of Resources Without Limits or Throttling vulnerability in phoenixframework phoenix (Phoenix.Socket module) allows an unauthenticated attacker to cause a denial of service against any endpoint that mounts a Phoenix socket with a reachable channel transport (WebSocket or LongPoll).

This v…

CWE: CWE-770
NVD

HIGH
CVE-2026-55574
CVE-2026-55574
pkg: vllm vllm

published: Jul 6, 2026

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, the structured_outputs.regex API parameter passes a user-supplied regular expression string directly to the grammar compiler backends with no compilation timeout; in the xgrammar backend the string…
CWE: CWE-1333
NVD

HIGH
CVE-2026-55380
CVE-2026-55380
pkg: python pillow

published: Jul 6, 2026

Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompression_bomb_check(), allowing a crafted .gd file to trigger excessive C-heap allocation when loaded. Th…
CWE: CWE-789
NVD

HIGH
CVE-2026-55379
CVE-2026-55379
pkg: python pillow

published: Jul 6, 2026

Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling Image._decompression_bomb_check(), bypassing Pillow's documented decompression bomb pro…
CWE: CWE-789
NVD

HIGH
CVE-2026-54060
CVE-2026-54060
pkg: python pillow

published: Jul 6, 2026

Pillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.new("1", (xsize, ysize)) without calling Image._decompression_bomb_check(), allowing a font to trigger excessive allocation during conversion or saving…
CWE: CWE-789
NVD

HIGH
CVE-2026-54059
CVE-2026-54059
pkg: python pillow

published: Jul 6, 2026

Pillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without calling Image._decompression_bomb_check(), allowing crafted PCF font data to cause excessive memory allocat…
CWE: CWE-789
NVD

HIGH
CVE-2026-13698
CVE-2026-13698
pkg: openvpn openvpn

published: Jul 6, 2026

A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers with a valid tls-crypt-v2 client key to potentially cause a denial of service
CWE: CWE-401, CWE-770, CWE-401
NVD

HIGH
CVE-2026-55672
CVE-2026-55672
pkg: oauth

published: Jul 10, 2026

ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's OAuth2 and OIDC CodeExchange, RefreshToken, and device token flows fail to verify that the requesting client matches the client that initiated the authorization flow, allowing intercepted grants or refresh …
CWE: CWE-287, CWE-863
NVD

HIGH
CVE-2026-54919
CVE-2026-54919
pkg: ssl

published: Jul 10, 2026

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. In affected Mbed TLS backend versions from 0.31.0 through 0.46.1 and wolfSSL backend versions from 0.33.0 through 0.46.1, when cpp-httplib is built with CPPHTTPLIB_MBEDTLS_SUPPORT or CPPHTTPLIB_WOLFSSL_SUPPORT and a cl…
CWE: CWE-295
NVD

HIGH
CVE-2026-54784
CVE-2026-54784
pkg: windows

published: Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. In version 1.9.0, CoreWCF SPNEGO SecurityContextToken negotiation can expose the proof key recovered from the RSTR when TransportWithMessageCredential with Windows client credentials and session establishme…
CWE: CWE-311, CWE-523
NVD

HIGH
CVE-2026-54783
CVE-2026-54783
pkg: windows

published: Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF WS-Security endorsing and supporting signature verification does not ensure the selected ds:Signature covers the expected Security header target, allowing an attacker with …
CWE: CWE-294, CWE-345, CWE-347
NVD

HIGH
CVE-2026-54781
CVE-2026-54781
pkg: windows

published: Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML token validation does not enforce SubjectConfirmation method URIs or holder-of-key proof keys in SamlSecurityTokenHandler, allowing holder-of-key downgrade or custom c…
CWE: CWE-287, CWE-345
NVD

HIGH
CVE-2026-54774
CVE-2026-54774
pkg: windows

published: Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, SamlSerializer skips final SignatureValue verification when a CoreWCF service validates SAML tokens using a non-X.509 signing token, allowing an attacker to reference a non-X.509 S…
CWE: CWE-345, CWE-347
NVD

HIGH
CVE-2026-55436
CVE-2026-55436
pkg: coder coder

published: Jul 8, 2026

Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and prior to versions 2.32.7, 2.33.8, and 2.34.2, the AI Bridge Proxy (`aibridgeproxyd`) created a goproxy server whose default transport set `InsecureSkipVerify: true` and only assigned…
CWE: CWE-295
NVD

HIGH
CVE-2026-55076
CVE-2026-55076
pkg: coder coder

published: Jul 7, 2026

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, Coder's OIDC callback checked `email_verified` with a direct Go `bool` type assertion. When an IdP returned the claim as a non-boolean (for example the string …
CWE: CWE-287, CWE-704
GitHub-GHSA

HIGH
Coder's AI Bridge Proxy skips TLS certificate verification in default configuration
GHSA-84rm-42xw-mx52
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

The AI Bridge Proxy (`aibridgeproxyd`) created a goproxy server whose default transport set `InsecureSkipVerify: true` and only assigned a secure transport when an upstream proxy was configured. In the default configuration (no upstream proxy), outbound HTTPS to the Coder access URL acc…

CVE-2026-55436
GitHub-GHSA

HIGH
Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass
GHSA-9r87-mvcw-x35f
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

Two flaws in Coder's OIDC login chained into account takeover: email-based user matching fell back to linking by email without checking for an existing link to a different IdP subject and the `email_verified` claim was only enforced when present as a boolean `false` so an absent or non-…

CVE-2026-55075
GitHub-GHSA

HIGH
Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking
GHSA-75vm-6w67-gwvp
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

Coder's OIDC callback checked `email_verified` with a direct Go `bool` type assertion. When an IdP returned the claim as a non-boolean (for example the string `"false"`) or omitted it, the assertion failed open and the email was treated as verified. Combined with an unconditional email-…

CVE-2026-55076
NVD

HIGH
CVE-2026-15497
CVE-2026-15497
pkg: jwt

published: Jul 12, 2026

A vulnerability was determined in SonicCloudOrg sonic-agent up to 2.7.2. This affects an unknown function of the file sonic-server-controller/src/main/java/org/cloud/sonic/controller/controller/ExchangeController.java of the component JWT Authentication Filter. This manipulation causes code injectio…
CWE: CWE-74, CWE-94
NVD

HIGH
CVE-2026-59214
CVE-2026-59214
pkg: openwebui open_webui

published: Jul 9, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, Open WebUI runs client-side Python with Pyodide in a same-origin web worker, allowing stored chat payloads that use pyodide.http.pyfetch or the js module fetch and XMLHttpRequest APIs to issue auth…
CWE: CWE-79
GitHub-GHSA

HIGH
Open WebUI vulnerable to Stored XSS via iFrame embeds in response messages
GHSA-vjm7-m4xh-7wrc
pkg: open-webui
eco: pip
published: Jul 7, 2026
### Summary
Manually modifying chat history allows setting the `embeds` property on a response message, the content of which is loaded into an iFrame with a sandbox that has `allow-scripts` and `allow-same-origin` set, ignoring the "iframe Sandbox Allow Same Origin" configuration. This enables store…
CVE-2026-26193
GitHub-GHSA

HIGH
Open WebUI vulnerable to Stored XSS via iFrame in citations model
GHSA-xc8p-9rr6-97r2
pkg: open-webui
eco: pip
published: Jul 7, 2026
### Summary
Manually modifying chat history allows setting the `html` property within document metadata. This causes the frontend to enter a code path that treats document contents as HTML, and render them in an iFrame when the citation is previewed. This allows stored XSS via a weaponised document …
CVE-2026-26192
GitHub-GHSA

HIGH
9router: Login brute-force protection bypass via spoofed X-Forwarded-For header
GHSA-7cfm-pqrj-xgq7
pkg: 9router
eco: npm
published: Jul 6, 2026
## Summary

The 9router dashboard login rate limiter derives the client identity from the attacker-controlled `X-Forwarded-For` HTTP header. When 9router is directly exposed, or deployed behind a reverse proxy that does not overwrite untrusted forwarding headers, a remote attacker can rotate the `X-…

CVE-2026-55501
GitHub-GHSA

HIGH
chmod: –preserve-root bypassed by any path that resolves to root (e.g. /../)
GHSA-4c7q-4928-8445
pkg: uu_chmod
eco: rust
published: Jul 6, 2026
`Chmoder::chmod()` only compares the literal argument against `Path::new("/")`, so the `–preserve-root` guard is bypassed by any path that *resolves* to root — a symlink to `/` or simply `/../`.

“`
if self.recursive && self.preserve_root && file == Path::new("/") {
return Err(ChmodError::Pr…

CVE-2026-35338
NVD

HIGH
CVE-2026-3576
CVE-2026-3576
pkg: curl

published: Jul 11, 2026

The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forgery leading to Local File Inclusion in all versions up to, and including, 3.0. The ulap.php file acts as an AJAX proxy and is directly accessible without WordPress bootstrapping or any authentication. …
CWE: CWE-20
NVD

HIGH
CVE-2026-59721
CVE-2026-59721
pkg: node

published: Jul 9, 2026

Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the updateInfraConfigs GraphQL mutation in admin/infra.resolver.ts accepts an attacker-controlled MAILER_SMTP_URL value, and validateSMTPUrl in utils.ts permits path, query, or fragment content that nodemailer parses into sen…
CWE: CWE-77, CWE-78, CWE-915
GitHub-GHSA

HIGH
Coder: User-admin role can reset owner account password
GHSA-29xf-69gq-m9jx
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

The `PUT /api/v2/users/{user}/password` endpoint authorized only `ActionUpdatePersonal` and did not prevent a `user-admin` from resetting an `owner` account's password. It also did not require the current password when an admin reset another user's password.

> **Note:** Exploitation re…

CVE-2026-55077
GitHub-GHSA

HIGH
SiYuan: Stored XSS in Bazaar marketplace via package README event handlers
GHSA-w7cg-whh7-xp28
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: Jul 10, 2026
## Summary

`renderPackageREADME` in `kernel/bazaar/readme.go` renders a Bazaar package README from Markdown to HTML with the lute engine and `SetSanitize(true)`. The lute sanitizer is an event-handler blocklist: `allowAttr` rejects only attribute names present in a fixed `eventAttrs` map copied fro…

CVE-2026-54070
NVD

HIGH
CVE-2026-59219
CVE-2026-59219
pkg: openwebui open_webui

published: Jul 9, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 before 0.10.0 with Redis configured, Socket.IO connect, user-join, join-channels, join-note, and the terminal websocket first-message authentication used decode_token without the Redis-backed is_valid_to…
CWE: CWE-613
NVD

HIGH
CVE-2026-47828
CVE-2026-47828
pkg: tls

published: Jul 9, 2026

During bosh create-env and bosh delete-env, the CLI uploads compiled CPI packages and rendered job templates to the new VM's DAV blobstore over HTTPS without verifying the server certificate, even though a CA certificate for that endpoint is available in the installation manifest. A network attacker…
NVD

HIGH
CVE-2026-58583
CVE-2026-58583
pkg: windows

published: Jul 7, 2026

FluxInk (formerly Sunia SPB Peripheral) Color Management Driver (TcnPeripheral64.sys) 1.0.7.2 allows local privilege escalation for a standard user account via arbitrary physical memory mapping at \Device\PhysicalMemory. Fixed in version 1.0.7.6. The fixed driver is currently available in the Window…
CWE: CWE-269
GitHub-GHSA

HIGH
mkfifo: permissions of an existing file are changed after FIFO creation fails
GHSA-pmf6-rcx4-v53v
pkg: uu_mkfifo
eco: rust
published: Jul 6, 2026
When `mkfifo()` fails (e.g. target already exists), the code shows an error but is missing a `continue;`, so it falls through to `fs::set_permissions` and changes the permissions of the pre-existing file to the default FIFO mode (`0o666` & umask -> `0644`).

“`
$ touch secret; chmod 000 secret
$ co…

CVE-2026-35341
GitHub-GHSA

HIGH
flyto-core has SSRF guard bypass via IPv6 transition addresses (IPv4-mapped / 6to4 / NAT64) in validate_url_ssrf
GHSA-794r-5rp2-fpg8
pkg: flyto-core
eco: pip
published: Jul 6, 2026
## Summary

`flyto-core`'s SSRF protection (`validate_url_ssrf` / `is_private_ip` in `src/core/utils.py`) blocks private and metadata destinations by resolving the host and testing the resulting IP for membership in a hardcoded `PRIVATE_IP_RANGES` list. That list contains only the *native* RFC 1918 …

CVE-2026-55787
NVD

HIGH
CVE-2026-59196
CVE-2026-59196
pkg: pnpm pnpm

published: Jul 6, 2026

pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted lockfile alias could be joined directly under a hoisted node_modules directory. Traversal aliases could escape that directory, while reserved aliases such as .bin or .pnpm could overwrite pnpm-owned layout. This vulnerability is fixe…
CWE: CWE-22, CWE-73
GitHub-GHSA

HIGH
Clauster: Non-loopback deployments can serve the dashboard unauthenticated when auth.enabled is unset
GHSA-h4g2-xfmw-q2c9
pkg: clauster
eco: pip
published: Jul 10, 2026
### Summary
A Clauster instance bound to a **non-loopback** address (e.g. `0.0.0.0` or a LAN IP) can serve the entire dashboard and its API **without any authentication** — even when the operator has configured a password — if `auth.enabled` is left at its default (`false`). The operator believe…
GitHub-GHSA

HIGH
Ruby CSS Parser: SSRF and Local File Disclosure in `CssParser::Parser#read_remote_file`
GHSA-9pmc-p236-855h
pkg: css_parser
eco: rubygems
published: Jul 9, 2026
## Summary

`CssParser::Parser#read_remote_file` (and therefore `load_uri!`, and the `@import`-following branch of `add_block!`) issues HTTP/HTTPS requests against any host, port and URI it is handed, with no scheme allowlist, no host / IP filtering, and no protection against link-local, loopback or…

CVE-2026-53727
GitHub-GHSA

HIGH
Note Mark: Path traversal via unsanitized book/note slug in migrate export (sibling of GHSA-g49p)
GHSA-rqrh-8wpv-x7hh
pkg: github.com/enchant97/note-mark/backend
eco: go
published: Jul 9, 2026
## Summary

Note Mark validates book and note `slug` values with the OpenAPI/huma tag `pattern:"[a-z0-9-]+"`. huma compiles this with `regexp.MustCompile(s.Pattern)` and tests it with `patternRe.MatchString(str)`, an UNANCHORED match. Because the pattern is not anchored (`^…$`), any string that me…

CVE-2026-50553
GitHub-GHSA

HIGH
ratex-parser panics on `\verb` with a multibyte delimiter (UTF-8 byte-boundary slice)
GHSA-4hgp-59h5-gvrj
pkg: ratex-parser
eco: rust
published: Jul 7, 2026
### Summary

The public parser entrypoint `ratex_parser::parse(&str)` panics on the **9-byte** input `\verbéxé` (i.e. `\verb` followed by the non-ASCII delimiter `é`). When handling a `\verb` command, the parser slices the verbatim argument with **byte** indices (`arg[1..arg.len() – 1]`); if the …

CVE-2026-53530
GitHub-GHSA

HIGH
uutils coreutils: cp/install/mv/ln –suffix alone does not enable backup mode (silent data loss vs GNU)
GHSA-fqf6-gxhh-2xhw
pkg: uucore
eco: rust
published: Jul 7, 2026
`determine_backup_mode` in `src/uucore/src/lib/features/backup_control.rs` only checks `–backup`/`-b` and returns `BackupMode::None` when only `–suffix` is given. GNU enables backup mode when `–suffix` is used alone (defaulting to existing/numbered, or `$VERSION_CONTROL`). Affects `cp`, `install`…
GitHub-GHSA

HIGH
Open WebUI vulnerable to stored XSS via unescaped markdown token in MarkdownTokens.svelte leading to full account takeover and RCE via functions
GHSA-9f4f-jv96-8766
pkg: open-webui
eco: pip
published: Jul 7, 2026
### Summary

A vulnerability in the way certain html tags in chat messages are rendered allows attackers to inject JavaScript code into a chat transcript. The JavaScript code will be executed in the user's browser every time that chat transcript is opened, allowing attackers to retrieve the user's a…

CVE-2025-46719
GitHub-GHSA

HIGH
XWiki Platform Old Core: Resource path traversal via /skin/ action endpoint in Jetty 12+
GHSA-qj4x-9g63-25g6
pkg: org.xwiki.platform:xwiki-platform-oldcore, org.xwiki.platform:xwiki-platform-oldcore
eco: maven
published: Jul 7, 2026
### Impact

With Jetty 12+ a user can craft a URL to access any resource the Jetty instance is allowed to access.

For example `http://[host]/xwiki/bin/skin/..%252f/..%252f..%252f..%252f..%252f..%252f..%252f..%252fetc/passwd` allows downloading the content of the /etc/passwd file, provided Jetty is …

CVE-2026-34151
GitHub-GHSA

HIGH
OpenRemote has Authenticated SQL Injection via Datapoint Crosstab Export
GHSA-cgfv-jrfp-2r7v
pkg: io.openremote:openremote-manager
eco: maven
published: Jul 6, 2026
## Summary

The datapoint export API builds a PostgreSQL crosstab export query by concatenating asset display names into raw SQL. An authenticated user who can create or rename an asset and then request a crosstab datapoint export can inject SQL through the asset name. The injected query output is s…

GitHub-GHSA

HIGH
Scriban: Template Writes to Arbitrary CLR Properties via `TypedObjectAccessor` (Mass Assignment + `private` / `init` / `internal` Setter Bypass)
GHSA-7jvp-hj45-2f2m
pkg: Scriban
eco: nuget
published: Jul 6, 2026
<!– obsidian –><h2 data-heading="Description">Description</h2>
<p>When a host pushes a CLR object into a Scriban <code>TemplateContext</code> via the standard, documented pattern —</p>
<pre><code class="language-csharp">var so = new ScriptObject();
so["user"] = currentUser; // direct CLR refer…
GitHub-GHSA

MEDIUM
CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation
GHSA-q6h5-q3q6-f87x
pkg: github.com/cilium/cilium, github.com/cilium/cilium, github.com/cilium/cilium
eco: go
published: Jul 6, 2026
### Impact

Users with the ability to create CiliumLocalRedirectPolicies can specify arbitrary ClusterIPs via addressMatcher, which enables hijacking traffic to Services in any namespace, bypassing the namespace-scoping guarantees enforced by serviceMatcher.

In addition, deleting such a policy can …

CVE-2026-53935
NVD

MEDIUM
CVE-2026-55689
CVE-2026-55689
pkg: jwt

published: Jul 9, 2026

OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, OpenFGA's OIDC authenticator skipped JWT audience validation when authn.method was set to oidc, authn.oidc.issuer was configured, and authn.oidc.audience was not set, allowing a token minted for an unrelated service…
CWE: CWE-287
NVD

MEDIUM
CVE-2026-59208
CVE-2026-59208
pkg: n8n n8n

published: Jul 9, 2026

n8n is an open source workflow automation platform. Prior to 2.27.4 and from 2.28.0 prior to 2.28.1, n8n instances configured with more than one trusted token-exchange issuer resolved external identities to local accounts using only the JWT sub claim and ignored the iss claim, allowing an attacker w…
CWE: CWE-287, CWE-346, CWE-346
GitHub-GHSA

MEDIUM
Micronaut: DefaultHttpClient follows redirects, forwarding Authorization, Cookie, and Proxy-Authorization headers
GHSA-q6gh-6v2r-hjv3
pkg: io.micronaut:micronaut-http-client, io.micronaut:micronaut-http-client, io.micronaut:micronaut-http-client
eco: maven
published: Jul 9, 2026
### Impact

> DefaultHttpClient follows redirects and forwards Authorization, Cookie, and Proxy-Authorization headers to redirect targets across domain boundaries. The blocklist only filters Host/Connection/TE/CT/CL.
> Additionally, no maximum redirect count exists, enabling infinite loop DoS.
> Aff…

GitHub-GHSA

MEDIUM
rm: –preserve-root bypassed via a symlink to / (string check instead of dev/inode)
GHSA-7cr3-h577-g38j
pkg: uu_rm
eco: rust
published: Jul 6, 2026
The `–preserve-root` check uses a path-string test (`path.has_root() && path.parent().is_none()`) rather than comparing device/inode. A symlink to `/` (e.g. `/tmp/rootlink -> /`) has a parent component, so it passes the check. GNU caches `/`'s dev/inode at startup and compares every traversed direc…
CVE-2026-35349
GitHub-GHSA

MEDIUM
mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)
GHSA-h444-6j9x-p8vh
pkg: uu_mv
eco: rust
published: Jul 6, 2026
When moving directories across filesystems, uutils `mv` dereferences symlinks inside the tree, copying their targets as real files/dirs instead of preserving the symlinks. GNU preserves symlinks by default. E.g. a `etc_link -> /etc` inside the source becomes a full copy of `/etc` at the destination.…
CVE-2026-35365
NVD

MEDIUM
CVE-2026-57211
CVE-2026-57211
pkg: windows

published: Jul 10, 2026

RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm_static can pass URL-encoded backslashes to erl_prim_loader:read_file_info before path validation when multiple management extension plugins are enable…
CWE: CWE-36, CWE-918
GitHub-GHSA

MEDIUM
Excon does not redact additional sensitive/risky headers when following redirects
GHSA-48rx-c7pg-q66r
pkg: excon
eco: rubygems
published: Jul 10, 2026
### Impact
The redirect follower middleware previously failed to strip a number of headers that are known to be sensitive and did not provide a way to provide a custom list of headers to strip.

_What kind of vulnerability is it? Who is impacted?_
This could cause inadvertent leakage of sensitive d…

CVE-2026-54171
GitHub-GHSA

MEDIUM
MCP Atlassian: DNS-rebinding TOCTOU bypass of the SSRF fix (CVE-2026-27826)
GHSA-489g-7rxv-6c8q
pkg: mcp-atlassian
eco: pip
published: Jul 10, 2026
### Summary
GHSA-7r34-79r5-rcc9's fix added `validate_url_for_ssrf`, which resolves the attacker-controlled `X-Atlassian-{Jira,Confluence}-Url` header host **once at middleware time** and trusts the result. But the outbound request is later built with the **raw hostname** and **re-resolves at connec…
GitHub-GHSA

MEDIUM
Avo: Direct attachment upload endpoint lacks upload authorization and bypasses field-level upload policy
GHSA-pqpw-cvm4-8mv9
pkg: avo
eco: rubygems
published: Jul 9, 2026
### Summary

Avo's direct attachment upload endpoint lacks server-side upload authorization and bypasses the documented field-level upload policy methods such as `upload_{FIELD_ID}?`.

An authenticated Avo user who can reach the Avo attachment upload endpoint can replace or add attachment content, i…

CVE-2026-53769
NVD

MEDIUM
CVE-2026-59220
CVE-2026-59220
pkg: openwebui open_webui

published: Jul 9, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.2 before 0.10.0, the SKILL_MENTION_RE and strip_re regular expressions in backend/open_webui/utils/middleware.py parsed <$skillId|label> skill mentions with overlapping quantifiers, allowing an authenticat…
CWE: CWE-1333
GitHub-GHSA

MEDIUM
Gittensory: Missing contributor-scoped access control on profile endpoint and MCP tool leaks miner financial data
GHSA-382c-vx95-w3p5
pkg: @jsonbored/gittensory-mcp
eco: npm
published: Jul 9, 2026
### Summary

`GET /v1/contributors/:login/profile` and the `gittensory_get_contributor_profile` MCP tool skip the contributor-scoped access check that every sibling endpoint enforces. Any authenticated session/API/MCP token holder can read any contributor's profile; for confirmed Gittensor miners t…

GitHub-GHSA

MEDIUM
pyLoad: Unbounded Memory Growth Leading to DoS and Potential DDoS in EventManager
GHSA-c2f9-4mc8-j656
pkg: pyload-ng
eco: pip
published: Jul 9, 2026
## Description:
The `EventManager` module in `pyload` manages a list of `Client` instances for subscribing to events. The addition of each unique `uuid` from the `get_events` API causes the creation of a `Client` instance that gets appended to the `clients` list. Although there is a `clean()` method…
CVE-2026-48987
NVD

MEDIUM
CVE-2026-54775
CVE-2026-54775
pkg: windows

published: Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, a CoreWCF service listening on a Kafka topic stops processing new records from that topic when KafkaTransportPump receives a null-value tombstone record, causing a persistent endpo…
CWE: CWE-248, CWE-754, CWE-755
NVD

MEDIUM
CVE-2026-15109
CVE-2026-15109
pkg: google chrome

published: Jul 8, 2026

Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-457
NVD

MEDIUM
CVE-2026-54777
CVE-2026-54777
pkg: windows

published: Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF NetNamedPipe transport accepts attachment to a pre-existing named pipe instance, allowing local interception of NetNamedPipe traffic when an attacker races NamedPipeListene…
CWE: CWE-367, CWE-665
GitHub-GHSA

MEDIUM
NL Portal: Missing per-user authorization on document and decision GraphQL queries in nl-portal-backend-libraries
GHSA-qpm9-h556-mwxm
pkg: nl.nl-portal:documenten-api, nl.nl-portal:besluiten
eco: maven
published: Jul 8, 2026
## Impact

In versions up to and including 3.0.0, two parts of the GraphQL API returned data without checking whether the data belonged to the logged-in user:

– **Document content.** A logged-in user could download the raw content of any document by its ID, regardless of who owned it. The resolver …

CVE-2026-49463
GitHub-GHSA

MEDIUM
Waku: Cross-Origin CSRF on RSC Server Action Dispatch
GHSA-75w3-gmqx-993q
pkg: waku
eco: npm
published: Jul 8, 2026
## Summary

Waku's RSC request dispatcher invokes server actions without validating the request's `Origin` (or `Sec-Fetch-Site`) header. A cross-origin web attacker can therefore cause a victim browser to issue an authenticated `POST` to a registered server action endpoint using a CORS-safelisted co…

CVE-2026-49455
NVD

MEDIUM
CVE-2026-15154
CVE-2026-15154
pkg: redhat openshift_ai

published: Jul 8, 2026

A flaw was found in `guardrails-detectors`, a component of Red Hat OpenShift AI. This vulnerability, known as Regular Expression Denial of Service (ReDoS), allows a remote attacker to provide specially crafted regular expressions to the public detection API. This can cause catastrophic backtracking,…
CWE: CWE-1333
NVD

MEDIUM
CVE-2026-60001
CVE-2026-60001
pkg: openbsd openssh

published: Jul 8, 2026

sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.
CWE: CWE-770
GitHub-GHSA

MEDIUM
ha-mcp: Add-on settings and policy routes are reachable without authentication at the bare root path
GHSA-q855-8rh5-jfgq
pkg: ha-mcp
eco: pip
published: Jul 7, 2026
### Summary

In add-on mode, the ha-mcp settings UI routes are mounted both under the MCP secret path **and** at the bare root of the published port (`:9583`), so Home Assistant ingress can serve the "Open Web UI" button. The root-mounted routes perform no authentication — no secret, no `Origin` c…

NVD

MEDIUM
CVE-2026-55490
CVE-2026-55490
pkg: openwrt openwrt

published: Jul 7, 2026

OpenWrt is a Linux operating system targeting embedded devices. Before v25.12.5, an integer underflow in handle_send_a() of the Emergency Access Daemon allows any unauthenticated attacker on the local network to crash the daemon by sending a single crafted UDP packet. The message length underflows b…
CWE: CWE-191
GitHub-GHSA

MEDIUM
Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpoints
GHSA-f5vp-w269-392g
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

AI Bridge provider handlers read request bodies with `io.ReadAll` without a maximum size so an authenticated user with AI Bridge access could send an arbitrarily large body and exhaust memory.

> **Note:** Exploitation requires authenticated access to the AI Bridge endpoints and the imp…

CVE-2026-55434
GitHub-GHSA

MEDIUM
Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service
GHSA-2mg2-p7r7-g27f
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

`POST /api/v2/files` converts zip uploads to tar in memory via `CreateTarFromZip`, which enforced a per-entry size limit but no aggregate limit on total decompressed output, writing to an unbounded in-memory buffer.

> **Note:** Exploitation requires authenticated file-upload access and…

CVE-2026-55078
GitHub-GHSA

MEDIUM
WeasyPrint has CSS Injection via Presentational Hints
GHSA-jhhc-3hcp-qhm5
pkg: weasyprint
eco: pip
published: Jul 6, 2026
### Summary
A CSS injection issue exists in WeasyPrint when HTML presentational hints are enabled. Unescaped attribute values are embedded into CSS, allowing injection of arbitrary CSS declarations. This affects applications processing untrusted HTML input.

### Details
File: weasyprint/css/__init__…

CVE-2026-49452
NVD

MEDIUM
CVE-2026-11321
CVE-2026-11321
pkg: express

published: Jul 10, 2026

The DataInjection plugin for GLPI 2.15.6 (GLPI 11 builds) concatenates user-supplied CSV field values directly into SQL queries during CSV import, without parameterization or escaping, resulting in authenticated SQL injection. An authenticated user with access to the Data injection feature can embed…
CWE: CWE-89
GitHub-GHSA

MEDIUM
@better-auth/oauth-provider may provide access tokens for unauthorized audiences via unbound resource indicators
GHSA-p2fr-6hmx-4528
pkg: @better-auth/oauth-provider
eco: npm
published: Jul 7, 2026
### Am I affected?

Users are affected if all of the following hold:

– Their application depends on `@better-auth/oauth-provider` on any stable `1.6.x` release (the stable line is not patched) or on a pre-release before `1.7.0-beta.4`.
– Their application either configures validAudiences` with mor…

NVD

MEDIUM
CVE-2026-12154
CVE-2026-12154
pkg: go

published: Jul 6, 2026

The Reviews Widgets for Google, Yelp & TripAdvisor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_id' shortcode attribute of the [fbrev] shortcode in versions up to and including 2.7.3. This is due to insufficient input sanitization and output escaping in the Feed_Sh…
CWE: CWE-79
NVD

MEDIUM
CVE-2026-15063
CVE-2026-15063
pkg: go

published: Jul 8, 2026

A flaw was found in the gorch service template, which is part of the trustyai-service-operator. Even when authentication is enabled, the gorch service exposes unproxied orchestrator and detector metrics ports. This allows any pod on the cluster network to directly access these ports, bypassing the k…
CWE: CWE-306
NVD

MEDIUM
CVE-2026-15044
CVE-2026-15044
pkg: go

published: Jul 8, 2026

A flaw was found in the TrustyAI Service Operator. When deploying services like gorch or NemoGuardrails, if a specific security setting is not enabled, these services can expose their communication channels without requiring users to prove their identity. This allows any other program within the clu…
GitHub-GHSA

MEDIUM
install -D: symlink race in directory creation allows arbitrary file overwrite
GHSA-gwm6-q8ch-hcfr
pkg: uu_install
eco: rust
published: Jul 6, 2026
The `-D` path runs `fs::create_dir_all` on a pathname then later opens the destination via path-based `File::create`/`fs::copy`, neither anchored to a directory fd. Between the two, an attacker can replace a path component with a symlink, redirecting the write.

**Impact:** an attacker with concurre…

CVE-2026-35356
GitHub-GHSA

MEDIUM
install: TOCTOU symlink race (unlink-then-create without O_EXCL) allows arbitrary file overwrite
GHSA-239g-2685-54×3
pkg: uu_install
eco: rust
published: Jul 6, 2026
`copy_file` in `install/src/install.rs` removes the destination then recreates it by pathname via `File::create` / `fs::copy` without `O_EXCL`/`create_new`. Between the unlink and the recreate, a local attacker with write access to the destination directory can drop in a symlink and redirect the wri…
CVE-2026-35355
NVD

MEDIUM
CVE-2026-54778
CVE-2026-54778
pkg: windows

published: Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF UnixDomainSocket POSIX peer identity resolution uses non-reentrant getpwuid and getgrgid calls, allowing concurrent connections to attribute one connection's identity to an…
CWE: CWE-362, CWE-825
NVD

MEDIUM
CVE-2026-10663
CVE-2026-10663
pkg: node

published: Jul 12, 2026

In Zephyr's experimental USB host stack (CONFIG_USB_HOST_STACK), usbh_device_disconnect() (subsys/usb/host/usbh_device.c) freed the root usb_device slab object without clearing the cached pointer ctx->root. The bus removal handler dev_removed_handler() (subsys/usb/host/usbh_core.c) decides what to t…
CWE: CWE-416
NVD

MEDIUM
CVE-2026-15128
CVE-2026-15128
pkg: google chrome

published: Jul 8, 2026

Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-79
NVD

MEDIUM
CVE-2026-15127
CVE-2026-15127
pkg: google chrome

published: Jul 8, 2026

Inappropriate implementation in WebGL in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-79
NVD

MEDIUM
CVE-2026-59929
CVE-2026-59929
pkg: mistune_project mistune

published: Jul 8, 2026

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the safe_url filter in src/mistune/renderers/html.py blocks only javascript:, vbscript:, file:, and data: schemes, allowing legacy or chained schemes such as feed:, view-source:, jar:, livescript:, mocha:, ms-its:, mk:, …
CWE: CWE-79, CWE-184
NVD

MEDIUM
CVE-2026-59926
CVE-2026-59926
pkg: mistune_project mistune

published: Jul 8, 2026

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, render_admonition() in src/mistune/directives/admonition.py concatenates the Admonition directive :class: option into the HTML class attribute without escaping, allowing attribute injection and cross-site scripting even …
CWE: CWE-79
NVD

MEDIUM
CVE-2026-59923
CVE-2026-59923
pkg: mistune_project mistune

published: Jul 8, 2026

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, HTMLRenderer.safe_url() does not block percent-encoded javascript URIs, allowing attacker-supplied Markdown links or images to bypass URL protections and execute script in rendered HTML. This issue is fixed in version 3.…
CWE: CWE-79
NVD

MEDIUM
CVE-2026-59890
CVE-2026-59890
pkg: python

published: Jul 8, 2026

setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compiled glob patterns against on-disk file names without Unicode …
CWE: CWE-176, CWE-697
GitHub-GHSA

MEDIUM
Kiwi TCMS has an Open Redirect via unvalidated next parameter in account confirmation endpoint
GHSA-hmj5-jm8h-h9fh
pkg: kiwitcms
eco: pip
published: Jul 6, 2026
### Summary

An open redirect vulnerability in the account confirmation endpoint allows an unauthenticated attacker to craft a URL hosted on a legitimate Kiwi TCMS instance that redirects victims to an arbitrary external domain. The attack surface is particularly relevant for phishing campaigns targ…

CVE-2026-54724
NVD

MEDIUM
CVE-2026-9571
CVE-2026-9571
pkg: oauth

published: Jul 13, 2026

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth refresh tokens upon user account deactivation, which allows a deactivated user or an attacker in possession of a valid refresh token to obtain new functional access tokens via the OAuth refresh token…
CWE: CWE-305
GitHub-GHSA

MEDIUM
SiYuan: Unauthenticated SQLite Data Exfiltration via Template Injection in /api/icon/getDynamicIcon
GHSA-gcm7-57gf-953c
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: Jul 10, 2026
### Summary

The `/api/icon/getDynamicIcon` endpoint is explicitly excluded from authentication in SiYuan's kernel router (`router.go`, "不需要鉴权" — no auth needed). When called with `type=8` and a valid block `id` parameter, this endpoint invokes `RenderDynamicIconContentTemplate`, which ex…

CVE-2026-54068
GitHub-GHSA

MEDIUM
GoBGP confederation validation panics on empty AS_PATH attribute
GHSA-frrj-87jh-2772
pkg: github.com/osrg/gobgp/v4
eco: go
published: Jul 9, 2026
Found through variant analysis based on `CVE-2026-41643`

## Summary
GoBGP accepts a zero-length AS_PATH during UPDATE decoding and later panics while validating that attribute for a confederation eBGP peer. The vulnerable path is in the BGP UPDATE validator: a malformed UPDATE that should be reject…

CVE-2026-49838
GitHub-GHSA

MEDIUM
GoBGP: BGP OPEN capability parser may read capability values outside declared CapLen boundaries
GHSA-gjrg-jjr3-56cm
pkg: github.com/osrg/gobgp/v4
eco: go
published: Jul 9, 2026
### Summary
GoBGP contains a BGP OPEN capability parsing issue where several concrete capability decoders may parse data from the full remaining capability buffer instead of the slice bounded by the declared capability length, `CapLen`.
A malformed BGP OPEN message can cause bytes from a fol…
CVE-2026-49837
GitHub-GHSA

MEDIUM
sigstore-go has a multi-log threshold bypass via single compromised log
GHSA-9vcr-p3rj-q5q6
pkg: github.com/sigstore/sigstore-go
eco: go
published: Jul 9, 2026
### Impact
_What kind of vulnerability is it? Who is impacted?_

A verifier configured with WithTransparencyLog(N>1) or WithSignedCertificateTimestamps(N>1) expected defense-in-depth against the compromise of a single log instance. However, threshold counting counted verified witnesses per-entry or …

CVE-2026-49834
NVD

MEDIUM
CVE-2026-57022
CVE-2026-57022
pkg: ssl

published: Jul 9, 2026

An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX with SPC3 and SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).

When an affected device initiates a TCP conne…

CWE: CWE-754
NVD

MEDIUM
CVE-2026-54779
CVE-2026-54779
pkg: windows

published: Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML token replay protection is inoperative because DefaultTokenReplayCache.TryAdd does not reject duplicate tokens when DetectReplayedTokens is enabled, allowing a capture…
CWE: CWE-294, CWE-613
NVD

MEDIUM
CVE-2026-54773
CVE-2026-54773
pkg: windows

published: Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF WS-Security signature verification performs a document-wide ds:Signature lookup, allowing an unauthenticated remote attacker to place a SOAP header before wsse:Security and…
CWE: CWE-347
NVD

MEDIUM
CVE-2026-54590
CVE-2026-54590
pkg: python

published: Jul 8, 2026

AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Version 2.23.0 contains an incomplete fix for CVE-2026-45309 in SSHServerConfig._set_tokens that blocks /, , and .. before %u substitution in Aut…
CWE: CWE-22, CWE-639
NVD

MEDIUM
CVE-2026-58501
CVE-2026-58501
pkg: python-zeep zeep

published: Jul 8, 2026

Zeep is a Python SOAP client. From 4.0.0 before 4.3.3, Settings.forbid_external is defined but not enforced when parsing WSDL or XSD documents, allowing transitive xsd:import, xsd:include, wsdl:import, and lxml entity or DTD references to fetch attacker-chosen HTTP or HTTPS URLs. This issue is fixed…
CWE: CWE-918
NVD

MEDIUM
CVE-2026-59924
CVE-2026-59924
pkg: mistune_project mistune

published: Jul 8, 2026

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Include.parse() joins and normalizes user-supplied include paths without verifying that the result remains within the intended markdown directory, allowing crafted include paths to access files outside that directory whe…
CWE: CWE-22
NVD

MEDIUM
CVE-2026-55761
CVE-2026-55761
pkg: portainer portainer

published: Jul 8, 2026

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. In versions 2.39.0 through 2.39.3 and 2.40.0 until 2.43.0, unauthenticated restore and administrator initialization endpoin…
CWE: CWE-287
NVD

MEDIUM
CVE-2026-59999
CVE-2026-59999
pkg: openbsd openssh

published: Jul 8, 2026

In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.
CWE: CWE-348
GitHub-GHSA

MEDIUM
Weblate SSRF: outbound URL guard misses some private ranges
GHSA-vmfc-9982-2m45
pkg: weblate
eco: pip
published: Jul 7, 2026
### Impact

Weblate's `VCS_RESTRICT_PRIVATE` did not properly account for some transitional IPv6 ranges, multicast addresses, or some semi-private IPv4 ranges, which allowed some addresses to bypass private range restrictions.

### Patches

* https://github.com/WeblateOrg/weblate/pull/19768

### Res…

CVE-2026-50127
GitHub-GHSA

MEDIUM
KEDA has PostgreSQL connection string parameter injection via incomplete whitespace escaping
GHSA-6w3m-4hhp-775q
pkg: github.com/kedacore/keda/v2
eco: go
published: Jul 7, 2026
### Summary
`pkg/scalers/postgresql_scaler.go` builds libpq-style connection strings by concatenating `key=value` pairs separated by spaces. Each tenant-controllable field (`host`, `port`, `userName`, `dbName`, `sslmode`) is passed through `escapePostgreConnectionParameter`:
“`go
func escapePostgre…
CVE-2026-53572
NVD

MEDIUM
CVE-2026-54291
CVE-2026-54291
pkg: postgresql postgresql_jdbc_driver

published: Jul 6, 2026

pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections can be silently downgraded from SCRAM-SHA-256-PLUS with channel binding to plain SCRAM-SHA-256 without it, losing the man-in-the-middle protection the setting is meant to guarantee…
CWE: CWE-636, CWE-757
NVD

MEDIUM
CVE-2026-52761
CVE-2026-52761
pkg: nginx

published: Jul 10, 2026

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 through 3.0.15, the t:utf8toUnicode transformation in src/actions/transformations/utf8_to_unicode.cc produces wrong output on i386 architecture because snprintf uses sizeof on a …
CWE: CWE-467
GitHub-GHSA

MEDIUM
Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing
GHSA-5wg6-jmq2-53pw
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

Coder's subdomain-based workspace app proxy allowed the same-owner CORS check to be bypassed. When a workspace-name subdomain segment parsed as a UUID, the workspace was resolved by ID without confirming the URL's username matched the real owner, while the CORS middleware trusted the un…

CVE-2026-55438
GitHub-GHSA

MEDIUM
Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access
GHSA-5g4w-3vw9-478w
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

The workspace app proxy resolves the target app from `httpapi.RequestHost()` which prefers the `X-Forwarded-Host` header over the real `Host` header. No middleware strips `X-Forwarded-Host` before routing and the header is not browser-forbidden so client-side JavaScript can set it on `f…

CVE-2026-55430
GitHub-GHSA

MEDIUM
@aborruso/ckan-mcp-server: SSRF via base_url allows access to internal networks (Potential fix bypass of CVE-2026-33060)
GHSA-g84h-j7jj-x32p
pkg: @aborruso/ckan-mcp-server
eco: npm
published: Jul 7, 2026
### Summary
A known vulnerability CVE-2026-33060 indicated tools including ckan_package_search and sparql_query that accept a base_url parameter had the risk of making HTTP requests to arbitrary endpoints without restriction. A fix was applied to filter out ip addresses. However, a method to bypass …
CVE-2026-53509
GitHub-GHSA

MEDIUM
rm: 'rm -rf ./' (and ./// variants) silently deletes current directory contents, bypassing dot protection
GHSA-89p7-7cq3-hhr2
pkg: uu_rm
eco: rust
published: Jul 6, 2026
`rm -rf .` is correctly refused, but `clean_trailing_slashes` normalizes `.///` to `./` while `path_is_current_or_parent_directory` only matches `.`/`..` (and `/.`/`/..`), not `./` or `../`. So `rm -rf ./` recursively deletes the directory's contents and then prints a misleading `cannot remove './':…
CVE-2026-35363
GitHub-GHSA

MEDIUM
CredSweeper: Recursive archive size-limit bypass in deep scanner allows crafted compressed inputs to exhaust resources
GHSA-9mqm-qcwf-5qhg
pkg: credsweeper
eco: pip
published: Jul 10, 2026
### Summary
CredSweeper's deep scanner does not enforce `recursive_limit_size` as a hard limit. Several recursive scanners fully decompress or fully read attacker-controlled content before the remaining budget is validated, and `AbstractScanner.recursive_scan()` continues processing even when the re…
NVD

MEDIUM
CVE-2026-44918
CVE-2026-44918
pkg: node

published: Jul 10, 2026

OpenStack Ironic through before 37.0.1 allows creation or modification of nodes cross-project without authorization.
CWE: CWE-862
NVD

MEDIUM
CVE-2026-15165
CVE-2026-15165
pkg: wireshark wireshark

published: Jul 8, 2026

TLS ECH decryptor crash in Wireshark 4.6.0 to 4.6.6 allows denial of service
CWE: CWE-122
GitHub-GHSA

MEDIUM
DSpace: Path Traversal is possible through LDN message generation
GHSA-9qm4-rh6w-pq5x
pkg: org.dspace:dspace-api, org.dspace:dspace-api, org.dspace:dspace-api
eco: maven
published: Jul 8, 2026
## Overview

A path traversal vulnerability is possible via the [COAR Notify / LDN](https://wiki.lyrasis.org/spaces/DSDOC9x/pages/379126679/COAR+Notify) service in DSpace. _This vulnerability impacts DSpace versions 8.0 <= 8.3, 9.0 <= 9.2._ The attacker MUST already have DSpace administrator creden…

CVE-2026-49833
GitHub-GHSA

MEDIUM
DSpace has a possible Path Traversal Vulnerability in its Curation Task Reporter output path
GHSA-v66x-68f2-pxf5
pkg: org.dspace:dspace-api, org.dspace:dspace-api, org.dspace:dspace-api
eco: maven
published: Jul 8, 2026
## Overview

The [Curation Task](https://wiki.lyrasis.org/spaces/DSDOC9x/pages/379126845/Curation+Tasks) feature allows an output path to be used by the reporter (`-r` parameter), typically used to stream results and status of curation task operations. It is not restricted to any particular base pat…

CVE-2026-49831
NVD

MEDIUM
CVE-2026-44512
CVE-2026-44512
pkg: node

published: Jul 8, 2026

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.9.0 before 1.22.0, onnx.version_converter.convert_version() can dereference a null pointer in Upsample_6_7::adapt_upsample_6_7() in onnx/version_converter/adapters/upsample_6_7.h when processing an …
CWE: CWE-476
NVD

MEDIUM
CVE-2026-58468
CVE-2026-58468
pkg: node

published: Jul 7, 2026

NocoBase through 2.1.20 contains a server-side request forgery vulnerability in the serverRequest wrapper that allows authenticated administrators to issue arbitrary outbound HTTP requests by supplying malicious URLs to workflow request nodes, custom request action buttons, or the AI plugin. Attacke…
CWE: CWE-918
GitHub-GHSA

MEDIUM
ONNX has Null Pointer Dereference in Upsample Version Converter Adapter (Zero Inputs)
GHSA-hwpq-hmq9-wj77
pkg: onnx
eco: pip
published: Jul 7, 2026
### Summary

Null pointer dereference (SIGSEGV) in `Upsample_6_7::adapt_upsample_6_7()` (`onnx/version_converter/adapters/upsample_6_7.h:31`) when `convert_version()` processes a model with an Upsample node that has zero inputs. The adapter accesses `node->inputs()[0]->sizes()` without checking inpu…

CVE-2026-44512
NVD

MEDIUM
CVE-2026-50135
CVE-2026-50135
pkg: gohugo hugo

published: Jul 6, 2026

Hugo is a static site generator. From 0.123.0 to 0.161.1, a regression made  RootMappingFs.statRoot  use  Stat  (follows symlinks) instead of  Lstat , so a direct  resources.Get  of a symlink pointing outside its mount returned the target's contents — letting a symlink planted in a local m…
CWE: CWE-59
NVD

MEDIUM
CVE-2026-44362
CVE-2026-44362
pkg: trustedfirmware op-tee

published: Jul 6, 2026

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.20.0 and prior to version 4.11.0, a vulnerability in OP-TEE’s subkey rollback protection allows the use of revoked…
CWE: CWE-285
GitHub-GHSA

MEDIUM
kill: 'kill -1' parsed as PID -1, sending SIGTERM to all processes (system crash / DoS)
GHSA-p6rv-2qpm-fwvg
pkg: uu_kill
eco: rust
published: Jul 6, 2026
`kill -1` is incorrectly parsed as a positional `pid = -1`; combined with the default SIGTERM this calls `kill(-1, SIGTERM)`, signaling nearly every process the caller can see. GNU `kill` recognizes `-1`/`-9` as signals and reports "not enough arguments".

“`
$ kill -1 # uutils: kill(-1, SIG…

CVE-2026-35369
GitHub-GHSA

MEDIUM
chmod: recursive mode returns exit code 0 even when some files fail (last-file-wins)
GHSA-4×34-chg5-mwjj
pkg: uu_chmod
eco: rust
published: Jul 6, 2026
In `Chmoder::chmod()` the recursive branch overwrites the running result instead of accumulating it, so the exit code reflects only the *last* file processed:

“`
if self.recursive {
r = self.walk_dir_with_context(file, true); // overwrites r
} else {
r = self.chmod_file(file).and(r);
}
`…

CVE-2026-35339
NVD

MEDIUM
CVE-2026-40257
CVE-2026-40257
pkg: trustedfirmware op-tee

published: Jul 6, 2026

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.21.0 and prior to version 4.11.0, the ARM Crypto Extensions accelerated SHA-3 implementation has an off-by-one error…
CWE: CWE-787
GitHub-GHSA

MEDIUM
Rattler vulnerable to package cache path traversal via conda package build string
GHSA-h672-p7h7-97v9
pkg: rattler_cache, py_rattler
eco: pip
published: Jul 9, 2026
`rattler_cache` and `py-rattler` were vulnerable to package-cache path traversal when handling package metadata from conda channels.

During cache materialization, the `ratter_cache` code used the package record `build` string as part of a cache key that was joined into a filesystem path. A maliciou…

CVE-2026-53956
NVD

MEDIUM
CVE-2026-60120
CVE-2026-60120
pkg: vue

published: Jul 9, 2026

Bagisto before 2.4.4 contains a stored cross-site scripting vulnerability via client-side template injection that allows unauthenticated attackers to execute arbitrary JavaScript in administrator browsers by registering a customer account with malicious payload in the first or last name field. The c…
CWE: CWE-79
NVD

MEDIUM
CVE-2026-5005
CVE-2026-5005
pkg: go

published: Jul 9, 2026

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Twiser Informatics Technology Consulting, Trade and Education Inc. OKRs & Goals allows Stored XSS.

This issue affects OKRs & Goals: from 28220 before 28398.

CWE: CWE-79
NVD

MEDIUM
CVE-2026-56359
CVE-2026-56359
pkg: n8n n8n

published: Jul 8, 2026

n8n before 2.8.0 contains a cross-site scripting vulnerability in the credential management flow where authenticated users can inject malicious JavaScript URLs into OAuth2 credential Authorization URL fields. Attackers can craft malicious credentials and trick victims into clicking the OAuth authori…
CWE: CWE-79
GitHub-GHSA

MEDIUM
Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component
GHSA-7qw2-f75v-62f7
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

The `AgentLogLine` dashboard component instantiated `ansi-to-html` without `escapeXML: true` and inserted the result via `dangerouslySetInnerHTML` so HTML embedded in workspace agent log lines was rendered as live markup. Server-side sanitization did not neutralize HTML metacharacters.

CVE-2026-55437
GitHub-GHSA

MEDIUM
Suspended Coder users retain access to AI Bridge LLM proxy endpoints
GHSA-wqxv-w64v-5wh6
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

AI Bridge proxy endpoints authenticate via `Server.IsAuthorized` in `coderd/aibridgedserver`, which validates key format, expiry, secret and deleted or system users but does not check whether the account is suspended. Because suspension does not revoke existing API keys, a suspended use…

CVE-2026-55435
GitHub-GHSA

MEDIUM
Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers
GHSA-jqj2-x4c5-jfxm
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

The devcontainer recreate endpoint relied on route middleware that checked only `ActionRead` on the workspace and, unlike the sibling delete endpoint, performed no `ActionUpdate` check before triggering the destructive rebuild.

> **Note:** Exploitation requires an existing low-privileg…

CVE-2026-55433
GitHub-GHSA

MEDIUM
Coder's sub-agent app registration bypasses template port-sharing policy enforcement
GHSA-x9qq-2qh5-8rxf
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

The `CreateSubAgent` RPC did not validate a requested app sharing level against the template's `MaxPortSharingLevel` before persisting workspace apps, letting a workspace owner exceed the administrator's configured maximum.

> **Note:** Exploitation requires the ability to register sub-…

CVE-2026-55432
NVD

MEDIUM
CVE-2026-8609
CVE-2026-8609
pkg: oauth

published: Jul 10, 2026

An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service).
CWE: CWE-400, CWE-400
GitHub-GHSA

MEDIUM
morgan vulnerable to Log Forging via unneutralized control characters in :remote-user
GHSA-4vj7-5mj6-jm8m
pkg: morgan
eco: npm
published: Jul 10, 2026
### Impact

Morgan's `:remote-user` token extracts the Basic auth username from the `Authorization` header and writes it to the log stream without neutralizing control characters. An attacker can send a crafted `Authorization: Basic` header containing CR/LF characters to inject forged log lines, cor…

CVE-2026-5078
NVD

MEDIUM
CVE-2026-44342
CVE-2026-44342
pkg: oauth

published: Jul 9, 2026

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0-alpha.1, the email and WeChat account binding endpoints GET /api/oauth/email/bind and GET /api/oauth/wechat/bind used GET requests for state-changing account operations, allowing …
CWE: CWE-352
NVD

MEDIUM
CVE-2026-59817
CVE-2026-59817
pkg: node

published: Jul 9, 2026

Ghost is a Node.js content management system. From 6.27.0 before 6.44.0, Ghost's public donation checkout flow allowed an unauthenticated attacker to control donation checkout metadata and obtain full paid gift memberships for a minimal payment without exposing customer or member data or stealing mo…
CWE: CWE-472, CWE-639
GitHub-GHSA

MEDIUM
Note Mark: Unauthenticated disclosure of soft-deleted note metadata via deleted=true on public books
GHSA-588f-fvcv-xhvf
pkg: github.com/enchant97/note-mark/backend
eco: go
published: Jul 9, 2026
Summary

GET /api/books/{bookID}/notes is an unauthenticated endpoint that accepts a "deleted" query parameter. When the request is ?deleted=true, the
service runs the query with Unscoped() (bypassing GORM's soft-delete scope) but keeps the read-authorization clause as "owner_id = ? OR is_public…

CVE-2026-50554
NVD

MEDIUM
CVE-2026-9027
CVE-2026-9027
pkg: go

published: Jul 9, 2026

The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Payment Bypass via Improper Verification of Cryptographic Signature in all versions up to, and including, 2.7.4. The `corvuspay_success_handler` function registers the REST endpoint `POST /wp-json/corvuspay/success/` wit…
CWE: CWE-347
GitHub-GHSA

MEDIUM
Trapster Community: Unauthenticated malformed DNS compression pointers crash per-packet honeypot handler
GHSA-mxwc-wh95-pw4g
pkg: trapster
eco: pip
published: Jul 8, 2026
## Summary

`trapster.libs.dns.decode_labels()` decodes DNS names from attacker-supplied UDP packets and recurses **once per RFC 1035 compression pointer** with **no cycle detection and no depth bound**. A single unauthenticated UDP datagram sent to the DNS honeypot drives the function past CPython'…

NVD

MEDIUM
CVE-2026-45045
CVE-2026-45045
pkg: express

published: Jul 8, 2026

Fiber is an Express inspired web framework written in Go. Prior to 3.3.0 and 2.52.14, the BalancerForward proxy helper in middleware/proxy/proxy.go uses Header.Add() instead of Header.Set() when injecting X-Real-IP, allowing an attacker-supplied first X-Real-IP value to be forwarded to upstream serv…
CWE: CWE-290
NVD

MEDIUM
CVE-2026-44332
CVE-2026-44332
pkg: express

published: Jul 8, 2026

Fiber is an Express inspired web framework written in Go. Prior to 3.3.0, the default Authorizer function in the BasicAuth middleware in middleware/basicauth/config.go uses short-circuit evaluation that skips password hash comparison for non-existent usernames, enabling reliable remote username enum…
CWE: CWE-203
NVD

MEDIUM
CVE-2026-59927
CVE-2026-59927
pkg: mistune_project mistune

published: Jul 8, 2026

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the Include directive in src/mistune/directives/include.py detects only direct self-includes and not indirect cycles, allowing two markdown files that include each other to trigger unbounded recursion, raise RecursionErr…
CWE: CWE-674, CWE-755, CWE-674
NVD

MEDIUM
CVE-2026-59875
CVE-2026-59875
pkg: node

published: Jul 8, 2026

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.17, node-tar does not strip NUL bytes from PAX path and linkpath records in src/pax.ts, allowing a crafted archive with values to reach fs.lstat or fs.open and terminate the process with an uncaught exception. This issue is fix…
CWE: CWE-248
NVD

MEDIUM
CVE-2026-59871
CVE-2026-59871
pkg: isaacs tar

published: Jul 8, 2026

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, node-tar coerces all-digit PAX path and linkpath values in src/pax.ts to JavaScript numbers, causing downstream path handling such as normalizeWindowsPath(entry.path).split('/') to throw an uncaught TypeError. This issue is…
CWE: CWE-704
GitHub-GHSA

MEDIUM
New API is vulnerable to CSRF through user email binding
GHSA-26v7-h57m-gh9m
pkg: github.com/QuantumNous/new-api
eco: go
published: Jul 7, 2026
## Summary

The email and WeChat account binding endpoints used GET requests for state-changing account operations. In deployments where session cookies could be sent on cross-site navigations, an attacker could trigger a logged-in user's browser to bind an attacker-controlled email address or OAuth…

CVE-2026-44342
GitHub-GHSA

MEDIUM
pyLoad: SSRF guard bypass via IPv6 6to4/NAT64 transition wrappers of internal IPs
GHSA-m5x5-28jr-gpjj
pkg: pyload-ng
eco: pip
published: Jul 9, 2026
## Summary

`is_global_address` in [`src/pyload/core/utils/web/check.py`](https://github.com/pyload/pyload/blob/1b12dc7f348db8c144e0f39215680415e90ca4d2/src/pyload/core/utils/web/check.py) is the central guard against SSRF-style outbound connections in pyload-ng. It tests whether a given IP is "glob…

CVE-2026-48737
NVD

MEDIUM
CVE-2026-14362
CVE-2026-14362
pkg: node

published: Jul 8, 2026

HashiCorp memberlist before version 0.6.0 is vulnerable to a denial-of-service issue in its push/pull state handling that may allow an attacker with network access to the gossip port to exhaust memory on a receiving node and cause the process to terminate. This vulnerability (CVE-2026-14362) is fixe…
CWE: CWE-770
GitHub-GHSA

MEDIUM
Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service
GHSA-f962-qm93-mj4c
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

`NewDataBuilder` in `provisionersdk/proto/dataupload.go` allocated a byte slice using the client-supplied `FileSize` from a `DataUpload` message without an upper-bound check. Although the DRPC wire limit is 4 MiB, the `FileSize` value itself was unconstrained

### Impact

An authenticat…

CVE-2026-55079
NVD

MEDIUM
CVE-2026-53624
CVE-2026-53624
pkg: express

published: Jul 8, 2026

Fiber is an Express inspired web framework written in Go. Prior to 3.4.0, the helmet middleware in middleware/helmet/helmet.go never sets the Strict-Transport-Security response header even when HSTSMaxAge is configured because it checks c.Protocol() for https instead of c.Scheme(). This issue is fix…
CWE: CWE-319
NVD

MEDIUM
CVE-2026-59998
CVE-2026-59998
pkg: openbsd openssh

published: Jul 8, 2026

sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.
CWE: CWE-573
GitHub-GHSA

MEDIUM
GoFiber never set HSTS header in helmet middleware due to incorrect protocol check
GHSA-gv83-gqw6-9j2c
pkg: github.com/gofiber/fiber
eco: go
published: Jul 6, 2026
### Summary

The `helmet` middleware in gofiber/fiber never sets the `Strict-Transport-Security` (HSTS) response header, even when `HSTSMaxAge` is explicitly configured, because the condition check at `helmet.go:67` uses `c.Protocol()` — which returns the HTTP protocol version string (e.g., `"HTTP…

CVE-2026-53624
GitHub-GHSA

MEDIUM
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
GHSA-rqq5-2gf9-4w4q
pkg: secure_headers
eco: rubygems
published: Jul 10, 2026
## Summary

`secure_headers` builds the `Content-Security-Policy` value by stitching every configured directive together with `; ` separators. Three directive builders (`build_sandbox_list_directive`, `build_media_type_list_directive`, `build_report_to_directive`) interpolate caller-supplied strings…

CVE-2026-54163
NVD

MEDIUM
CVE-2026-46672
CVE-2026-46672
pkg: go

published: Jul 7, 2026

Actual is a local-first personal finance app. Prior to 26.6.0, @actual-app/cli ships a hand-rolled CSV serializer in packages/cli/src/output.ts used whenever the global –format csv option is passed, whose escapeCsv helper only handles RFC 4180 delimiter, quote, and newline escaping and does not neu…
CWE: CWE-1236
NVD

MEDIUM
CVE-2026-55798
CVE-2026-55798
pkg: python pillow

published: Jul 6, 2026

Pillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get_command() constructed a cmd.exe shell command by directly embedding a file path into an f-string without escaping and passed the result to subprocess.Popen(…, shell=True), allowing shell metacharacters in the file path to injec…
CWE: CWE-78
NVD

MEDIUM
CVE-2026-3367
CVE-2026-3367
pkg: oauth

published: Jul 11, 2026

The Lockme OAuth2 calendars integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'App ID' setting in all versions up to, and including, 2.11.0. This is due to insufficient input sanitization and output escaping. The register_setting() call on line 197 lacks a sanitiz…
CWE: CWE-79
NVD

MEDIUM
CVE-2026-54776
CVE-2026-54776
pkg: windows

published: Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, a CoreWCF service hosted on Unix Domain Sockets with PosixIdentity client credentials can accept connections that skip the application/unixposix stream upgrade before dispatching m…
CWE: CWE-306
GitHub-GHSA

MEDIUM
DSpace: ORE resource URI does not validate scheme for non-web resources
GHSA-c827-pw3m-67w7
pkg: org.dspace:dspace-api, org.dspace:dspace-api, org.dspace:dspace-api
eco: maven
published: Jul 8, 2026
## Overview

When ingesting an aggregated ORE resource by URI (using the [OAI-ORE Harvester](https://wiki.lyrasis.org/spaces/DSDOC9x/pages/379125906/OAI#OAI-OAI-PMH/OAI-OREHarvester(Client))), the ORE Ingestion Crosswalk does not validate the URI scheme. This may allow for local file inclusion via m…

CVE-2026-49830
GitHub-GHSA

MEDIUM
printenv: environment variables with invalid UTF-8 are silently skipped (evades inspection)
GHSA-p7h3-7q52-72w8
pkg: uu_printenv
eco: rust
published: Jul 6, 2026
The printenv utility in uutils coreutils fails to display environment variables containing invalid UTF-8 byte sequences. While POSIX permits arbitrary bytes in environment strings, the uutils implementation silently skips these entries rather than printing the raw bytes. This vulnerability allows ma…
CVE-2026-35366
GitHub-GHSA

MEDIUM
cp: -R reads device nodes as streams, destroying device semantics
GHSA-8vrf-r662-2w2v
pkg: uu_cp
eco: rust
published: Jul 6, 2026
The cp utility in uutils coreutils, when performing recursive copies (-R), incorrectly treats character and block device nodes as stream sources rather than preserving them. Because the implementation reads bytes into regular files at the destination instead of using mknod, device semantics are dest…
CVE-2026-35358
GitHub-GHSA

MEDIUM
comm: FIFO/pipe inputs are drained before comparison (data loss / hang)
GHSA-3wfc-mgpm-9rq6
pkg: uu_comm
eco: rust
published: Jul 6, 2026
The comm utility in uutils coreutils incorrectly consumes data from non-regular file inputs before performing comparison operations. The are_files_identical function opens and reads from both input paths to compare content without first verifying if the paths refer to regular files. If an input path…
CVE-2026-35347
GitHub-GHSA

MEDIUM
id: groups= computed from real GID instead of effective GID
GHSA-47c7-qrm7-mqw7
pkg: uu_id
eco: rust
published: Jul 6, 2026
The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and automated processes rely…
CVE-2026-35370
NVD

MEDIUM
CVE-2026-56240
CVE-2026-56240
pkg: express

published: Jul 11, 2026

Capgo before 12.128.12 contains a billing authorization bypass vulnerability in the plan_valid calculation that allows organizations with exhausted or expired usage credit grants to bypass billing gates. Attackers can exploit the divergence between the plugin hot-path plan_valid expression and the a…
CWE: CWE-285
NVD

MEDIUM
CVE-2026-55664
CVE-2026-55664
pkg: python

published: Jul 10, 2026

Grist is spreadsheet software using Python as its formula language. Prior to 1.7.15, the GET /forms endpoint read table and column metadata without applying the document's access rules and did not check that the requested section was actually a form. A user with only partial read access, including p…
CWE: CWE-200, CWE-285
GitHub-GHSA

MEDIUM
tarteaucitron: data-cookie attribute can be used to delete arbitrary cookies
GHSA-jxj7-g6gm-49j7
pkg: tarteaucitronjs
eco: npm
published: Jul 10, 2026
### Summary

tarteaucitron provides a list of cookies and buttons to delete them. If an attacker can write HTML with data attributes, they could create an element that silently deletes a cookie when clicked and trick a user to delete this cookie.

### Details

`tarteaucitron.cookie.purge()` is calle…

CVE-2026-49977
NVD

MEDIUM
CVE-2026-6440
CVE-2026-6440
pkg: oauth

published: Jul 10, 2026

The GoodMeet – Google Meet Integration for Webinar, Meeting & Video Conference plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.1.8. This is due to a missing nonce verification in the reset_credential() function, which handles the wp_ajax_goodmeet_…
CWE: CWE-352
NVD

MEDIUM
CVE-2026-4298
CVE-2026-4298
pkg: go

published: Jul 9, 2026

The DSGVO All in one for WP plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 4.9. This is due to the dsgvo_reset_policy_service_func() function lacking both capability checks and nonce verification while processing user-supplied parameters to reset plug…
CWE: CWE-862
NVD

MEDIUM
CVE-2026-15131
CVE-2026-15131
pkg: google chrome

published: Jul 8, 2026

Inappropriate implementation in Navigation in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-20
NVD

MEDIUM
CVE-2026-15130
CVE-2026-15130
pkg: google chrome

published: Jul 8, 2026

Insufficient policy enforcement in Navigation in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-602
NVD

MEDIUM
CVE-2026-15124
CVE-2026-15124
pkg: google chrome

published: Jul 8, 2026

Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-20
NVD

MEDIUM
CVE-2026-15108
CVE-2026-15108
pkg: google chrome

published: Jul 8, 2026

Integer overflow in Extensions API in Google Chrome prior to 150.0.7871.115 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory read via a crafted Chrome Extension. (Chromium security severity: High)
CWE: CWE-190
NVD

MEDIUM
CVE-2026-59930
CVE-2026-59930
pkg: mistune_project mistune

published: Jul 8, 2026

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the toc plugin and TableOfContents directive generate heading IDs as predictable toc_N values without slugifying the heading text, allowing attacker-controlled id="toc_N" content to collide with generated anchors and red…
CWE: CWE-345, CWE-1284
GitHub-GHSA

MEDIUM
Kite has an authenticated cluster RBAC bypass in /api/v1/overview
GHSA-gvhc-wv3v-7pf8
pkg: github.com/zxh326/kite
eco: go
published: Jul 7, 2026
## Summary

Authenticated Kite users with any role can request `/api/v1/overview` for a cluster that their roles do not permit by selecting that cluster with `x-cluster-name`. The overview route is registered before `middleware.RBACMiddleware()` and `GetOverview` only checks `len(user.Roles) > 0`, s…

CVE-2026-53487
NVD

MEDIUM
CVE-2026-46700
CVE-2026-46700
pkg: go

published: Jul 7, 2026

Actual is a local-first personal finance tool. Prior to 26.6.0, the GET /secret/:name endpoint in @actual-app/sync-server checks only that the caller has a valid session and does not verify the caller is an admin, while the sibling POST /secret/ handler enforces an admin check in OpenID mode. Any au…
CWE: CWE-285
GitHub-GHSA

MEDIUM
Open WebUI has Blind Server Side Request Forgery in its Image Edit Functionality
GHSA-jgx9-jr5x-mvpv
pkg: open-webui
eco: pip
published: Jul 7, 2026
### Summary
There is a blind server side request forgery in the functionality that allows editing an image via a prompt. The affected function will perform a GET request on the URL provided by the user. There is no restriction on the domain of the provided URL allowing the local address space to be …
CVE-2026-34225
GitHub-GHSA

MEDIUM
OpenRemote read-only asset users can write predicted datapoints
GHSA-xj53-j257-hxvg
pkg: io.openremote:openremote-manager
eco: maven
published: Jul 6, 2026
# Summary

The predicted datapoint write endpoint allows users with only `read:assets` privileges to write predicted datapoints.

The endpoint:

“`text
PUT /api/{realm}/asset/predicted/{assetId}/{attributeName}
“`

accepts write requests from users lacking `write:assets`.

The implementation appea…

CVE-2026-49439
NVD

MEDIUM
CVE-2026-56665
CVE-2026-56665
pkg: jwt

published: Jul 10, 2026

ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL is an open source identity management platform. From 3.0.0-rc.1 through 3.4.11 and from 4.0.0-rc.1 through 4.15.1, ZITADEL's external JWT Identity Provider validation in internal/idp/providers/jwt/session.go …
CWE: CWE-613
NVD

MEDIUM
CVE-2026-56664
CVE-2026-56664
pkg: jwt

published: Jul 10, 2026

ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's external JWT Identity Provider validation in internal/idp/providers/jwt/session.go skips the maximum token age freshness check when an incoming token omits the iat claim, allowing arbitrarily old tokens fro…
CWE: CWE-613
NVD

MEDIUM
CVE-2026-55669
CVE-2026-55669
pkg: jwt

published: Jul 10, 2026

ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's external JWT Identity Provider validates a token's signature and issuer (iss) but not the audience (aud) claim, allowing a validly signed token from a trusted issuer for another relying party to be accepted…
CWE: CWE-346
NVD

MEDIUM
CVE-2026-59997
CVE-2026-59997
pkg: openbsd openssh

published: Jul 8, 2026

internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.
CWE: CWE-1284
NVD

MEDIUM
CVE-2026-59996
CVE-2026-59996
pkg: openbsd openssh

published: Jul 8, 2026

scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.
CWE: CWE-23
NVD

MEDIUM
CVE-2026-59995
CVE-2026-59995
pkg: openbsd openssh

published: Jul 8, 2026

sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.
CWE: CWE-23
NVD

MEDIUM
CVE-2026-50179
CVE-2026-50179
pkg: go

published: Jul 7, 2026

Actual is a local-first personal finance tool. Prior to 26.6.0, exportToCSV and exportQueryToCSV in packages/loot-core/src/server/transactions/export/export-to-csv.ts pass user-controlled Payee, Notes, Account, and Category strings to csv-stringify with no cast callback and no formula-prefix neutral…
CWE: CWE-1236
NVD

MEDIUM
CVE-2026-56354
CVE-2026-56354
pkg: node

published: Jul 10, 2026

n8n before 1.123.24, 2.10.4, and 2.12.0 (across its 1.x and 2.x branches) contains cross-site scripting and open redirect vulnerabilities in the Form Node due to unsanitized HTML description fields and overly permissive iframe sandbox policies. Authenticated users with workflow creation permissions …
CWE: CWE-79
NVD

MEDIUM
CVE-2026-56360
CVE-2026-56360
pkg: n8n n8n

published: Jul 8, 2026

n8n before versions 1.123.18 and 2.6.2 fails to verify HMAC-SHA256 signatures on Zendesk webhooks in the ZendeskTrigger node. Attackers who know the webhook URL can send unsigned POST requests to trigger workflows with arbitrary malicious data.
CWE: CWE-290
GitHub-GHSA

MEDIUM
Windmill: Resource-scoped API tokens can read script contents outside their allowed path via scripts/list_search
GHSA-2ppx-66jv-wpw5
pkg: windmill-api
eco: rust
published: Jul 10, 2026
### Summary

A resource-scoped API token can read script contents outside its allowed path scope via `GET /api/w/{workspace}/scripts/list_search`.

This appears to be a remaining variant of the scoped-token authorization class previously addressed for other endpoints. The route-level scope middlewar…

CVE-2026-54136
GitHub-GHSA

MEDIUM
psd-tools vulnerable to arbitrary file write via smart-object filename
GHSA-2rmg-vrx8-9j2f
pkg: psd-tools
eco: pip
published: Jul 9, 2026
# psd-tools: arbitrary file write/read via smart-object path traversal

## Summary

In `psd-tools` (all releases exposing the `SmartObject` API through **v1.17.0**), `SmartObject.save()` writes an embedded smart object to a path taken verbatim from the PSD file. Because that name is attacker-control…

CVE-2026-49836
GitHub-GHSA

MEDIUM
OpenRun: Redirect URL validation bypass using  //host  paths leads to Open Redirect
GHSA-h5g6-xmh4-hc37
pkg: github.com/openrundev/openrun
eco: go
published: Jul 9, 2026
### Summary
The restrictions on redirect URLs in `openrun` can be bypassed by attackers, leading to open redirect attacks.

### Details

In the current project, the referrer header value is used for subsequent redirects, so there is currently a validation for this redirect value. The current validat…

CVE-2026-55252
GitHub-GHSA

MEDIUM
pypdf: Possible infinite loop when processing threads/articles in writer
GHSA-g9xf-7f8q-9mcj
pkg: pypdf
eco: pip
published: Jul 9, 2026
### Impact

An attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires merging a file with threads/articles into a writer.

### Patches

This has been fixed in [pypdf==6.13.1](https://github.com/py-pdf/pypdf/releases/tag/6.13.1).

### Workarounds

If users…

CVE-2026-54651
GitHub-GHSA

MEDIUM
nebula-mesh: Host revocation is not durable – blocked/offboarded hosts can regain a valid certificate
GHSA-339v-266x-79xr
pkg: github.com/forgekeep/nebula-mesh
eco: go
published: Jul 9, 2026
## Summary

Two related authorization gaps let a host that should no longer be trusted obtain a fresh, valid Nebula certificate, because nebula-mgmt does not re-evaluate revocation/authorization state at certificate *issuance* time — only at poll time.

## 1. Blocklist not enforced at sign / re-en…

CVE-2026-53602
GitHub-GHSA

MEDIUM
pymonocypher: Potential heap buffer overflow on nb_blocks in argon2i_32 when provided buffer is too small
GHSA-8f95-v3jq-cj86
pkg: pymonocypher
eco: pip
published: Jul 9, 2026
### Impact
The argon2i_32 implementation does not check the nb_blocks size. If the caller does not provide a sufficiently large buffer based on the API contract, then argon2i_32 will write past the end of the buffer and possibly corrupt the heap.

### Patches
Fixed in 4.0.2.8, which now verifies th…

CVE-2026-53720
GitHub-GHSA

MEDIUM
OneRingBuf has a Use After Free Vulnerability
GHSA-q95x-7g78-rccv
pkg: oneringbuf
eco: rust
published: Jul 8, 2026
Affected versions of `oneringbuf` exposed the obsolete `IntoRef::into_ref` method through the public `IntoRef` trait. For heap-backed ring buffers, this method returned a `DroppableRef` handle.

`DroppableRef` stored an owning raw pointer created from `Box::into_raw`. Its `Clone` implementation copi…

GitHub-GHSA

MEDIUM
async-tar PAX extension-header desync enables tar entry/content smuggling
GHSA-35rm-7j9c-2f7m
pkg: async-tar
eco: rust
published: Jul 8, 2026
## Summary

`async-tar` v0.6.0 mis-applies a buffered PAX `size` extension to an intermediary
extension header (a GNU longname `L`, a GNU longlink `K`, or a PAX `x`/`g`
header) instead of to the next *file* entry. POSIX requires a PAX extended-header
record set to describe the next file entry, never…

CVE-2026-53600
GitHub-GHSA

MEDIUM
oasdiff does not enforce –allow-external-refs=false on the git-revision load path (SSRF / local file read)
GHSA-2jcc-mxv7-p3f9
pkg: github.com/oasdiff/oasdiff
eco: go
published: Jul 7, 2026
## Summary

From **v1.13.2** through **v1.18.0**, oasdiff did not enforce `–allow-external-refs=false` (library: `openapi3.Loader.IsExternalRefsAllowed = false`) when loading a spec from a **git revision** (the `rev:path` form, e.g. `main:openapi.yaml`). External `$ref`s were resolved on that load …

CVE-2026-53508
GitHub-GHSA

MEDIUM
Flask-Security-Too: WebAuthn reauthentication freshness bypass via cross-user assertion
GHSA-f66q-9rf6-8795
pkg: Flask-Security-Too
eco: pip
published: Jul 7, 2026
### Summary

Flask-Security-Too 5.8.0 and 5.8.1 mark a session as reauthentication-fresh after processing a WebAuthn assertion whose proven credential belongs to a different user than the currently authenticated session user. The check that `GHSA-97r5-pg8x-p63p` added on the OAuth reauthentication p…

GitHub-GHSA

MEDIUM
aiosmtplib vulnerable to SMTP command injection via CR/LF in sender/recipient address
GHSA-v3q9-hj7j-63hq
pkg: aiosmtplib
eco: pip
published: Jul 7, 2026
### Summary

`aiosmtplib`'s `SMTP.mail()`, `SMTP.rcpt()`, `SMTP.vrfy()` and `SMTP.expn()` send the caller-supplied email address to the server without rejecting embedded CR/LF (`\r\n`) bytes. An address that contains a CR/LF is written verbatim onto the SMTP control connection, so the bytes after th…

CVE-2026-53533
GitHub-GHSA

MEDIUM
ratex-parser has unbounded parser recursion that leads to stack overflow (process abort)
GHSA-4w5h-hx6r-28q7
pkg: ratex-parser
eco: rust
published: Jul 7, 2026
### Summary

RaTeX’s recursive-descent parser recurses one (or more) native stack frame per nesting level at `{`, `\left`, `\sqrt{`, `^{`, etc, with **no maximum depth limit**. A short, ~10 KB input of nested groups overflows the 8 MB main-thread stack and aborts the process. With `panic = "abort…

CVE-2026-53531
GitHub-GHSA

MEDIUM
netfoil has a domain name filter bypass via multiple questions
GHSA-59qp-cfj3-rp64
pkg: github.com/tinfoil-factory/netfoil
eco: go
published: Jul 7, 2026
### Summary
Potential bypass of domain name filter by crafting a DNS request with multiple questions, with the first question being legitimate.

### Impact
Depends on a local attackers ability to craft multiple questions and the remote DoH server supporting them.

GitHub-GHSA

MEDIUM
Open WebUI allows limited stored XSS vila uploaded html file
GHSA-8gh5-qqh8-hq3x
pkg: open-webui
eco: pip
published: Jul 7, 2026
### Summary
Low privileged users can upload HTML files which contain JavaScript code via the `/api/v1/files/` backend endpoint. This endpoint returns a file id, which can be used to open the file in the browser and trigger the JavaScript code in the user's browser. Under the default settings, files …
CVE-2025-46571
GitHub-GHSA

MEDIUM
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile
GHSA-chwm-m7g7-685g
pkg: d7y.io/dragonfly/v2
eco: go
published: Jul 6, 2026
## Summary

The Dragonfly **scheduler**'s v1 gRPC service contains an unauthenticated Server-Side Request Forgery (SSRF). When a peer reports a successful download of a TINY task, the scheduler calls `Peer.DownloadTinyFile()` and issues an HTTP `GET` to a host and port taken verbatim from the attack…

CVE-2026-54637


Vulnerability Digest — July 10, 2026 · 34 Critical · 4 Exploited






Vulnerability Digest — Friday, July 10, 2026


Security Report

Friday, July 10, 2026  ·  Last 7 days  ·  Min severity: MEDIUM
Total Findings
308
Critical
34
High
140
Actively Exploited
4
CISA-KEV4
NVD178
GitHub-GHSA126
Findings sorted by severity
CISA-KEV

CRITICAL
Langflow Authorization Bypass Through User-Controlled Key Vulnerability
CVE-2026-55255
pkg: Langflow Langflow

published: Jul 7, 2026

Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Joomlack Page Builder Improper Access Control Vulnerability
CVE-2026-56290
pkg: Joomlack Page Builder

published: Jul 7, 2026

Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Adobe ColdFusion Path Traversal Vulnerability
CVE-2026-48282
pkg: Adobe ColdFusion

published: Jul 7, 2026

Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability
CVE-2026-48908
pkg: JoomShaper SP Page Builder

published: Jul 7, 2026

JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
NVD

CRITICAL
CVE-2026-54769
CVE-2026-54769
pkg: python

published: Jul 10, 2026

Langroid is a framework for building large-language-model-powered applications. Versions prior to 0.65.2 are vulnerable to a critical Sandbox Escape leading to Remote Code Execution (RCE) in its `TableChatAgent` and `VectorStore` capabilities. When these agents evaluate LLM-generated tool messages w…
CWE: CWE-94
NVD

CRITICAL
CVE-2026-59726
CVE-2026-59726
pkg: docker

published: Jul 9, 2026

Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-compose deployment exposed the MCP bridge POST /mcp and POST /mcp/:group endpoints without authentication, allowing an unauthenticated network attacker to invoke tools/call to terminal_execute, obtain a…
CWE: CWE-78, CWE-306, CWE-942
NVD

CRITICAL
CVE-2026-54782
CVE-2026-54782
pkg: windows

published: Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML 1.1 and SAML 2.0 token validation does not correctly resolve the issuer signing key or require signed tokens when IdentityConfiguration is used with federated bindings…
CWE: CWE-290, CWE-347
GitHub-GHSA

CRITICAL
Nuclio: Unsanitized cron trigger event headers/body injected into CronJob shell command leads to persistent RCE
GHSA-v5px-423j-pf7p
pkg: github.com/nuclio/nuclio
eco: go
published: Jul 8, 2026
## Summary

Nuclio controller builds a `curl` invocation string for each cron trigger and stores it as the `args` of a Kubernetes CronJob container (`/bin/sh`, `-c`, `<command>`). Two fields in the trigger specification flow into this string without adequate sanitization:

– `event.headers` keys —…

CVE-2026-52831
GitHub-GHSA

CRITICAL
9router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats
GHSA-vjc7-jrh9-9j86
pkg: 9router
eco: npm
published: Jul 6, 2026

title: Unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats
product: 9Router
version: <= 0.4.41
severity: critical
cve_request: true

## Summary

Multiple critical API security vulnerabilities were discovered in 9Router's Next.js dashboard. The `/api/providers` e…

NVD

CRITICAL
CVE-2026-57572
CVE-2026-57572
pkg: kidocode crawl4ai

published: Jul 6, 2026

Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server accepted request-supplied browser_config.extra_args, which flowed into Chromium's launch arguments. An attacker could inject Chromium switches that replace a child-process launch command together w…
CWE: CWE-88, CWE-94
GitHub-GHSA

CRITICAL
Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent
GHSA-q9p7-wqxg-mrhc
pkg: langroid
eco: pip
published: Jul 6, 2026
### Advisory Details
**Title**: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent

**Description**:
### Summary
Langroid is vulnerable to a critical Sandbox Escape leading to Remote Code Execution (RCE) in its `TableChatAgent` and `VectorStore` capabilities…

CVE-2026-54769
GitHub-GHSA

CRITICAL
9routers has Exposure of Sensitive Information and Unprotected Database Import/Export, Allowing Complete Credential Theft and Database Takeover
GHSA-qvfm-67h2-2qfx
pkg: 9router
eco: npm
published: Jul 6, 2026
## Summary

The `/api/settings/database` endpoint allows full database export (containing all credentials, API keys, OAuth tokens, and settings) and full database import (complete overwrite) without any authentication requirement beyond the `ALWAYS_PROTECTED` middleware check, which only validates J…

CVE-2026-55500
NVD

CRITICAL
CVE-2026-34038
CVE-2026-34038
pkg: docker

published: Jul 6, 2026

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, an authenticated remote command injection vulnerability in application deployment handling allows users with application write permissions to achieve remote code execution and…
CWE: CWE-78
NVD

CRITICAL
CVE-2026-13019
CVE-2026-13019
pkg: esri portal_for_arcgis, kubernetes kubernetes, linux linux_kernel

published: Jul 7, 2026

Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API.
CWE: CWE-640
NVD

CRITICAL
CVE-2026-9182
CVE-2026-9182
pkg: esri arcgis_server, linux linux_kernel, microsoft windows

published: Jul 6, 2026

Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endpoint. Successful exploitation could allow arbitrary file upload, potentially allowing for other attacks. This issue impacts all …
CWE: CWE-434
NVD

CRITICAL
CVE-2026-9181
CVE-2026-9181
pkg: esri arcgis_server, linux linux_kernel, microsoft windows

published: Jul 6, 2026

Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An unauthenticated attacker could exploit this issue by sending crafted path parameters. Successful exploitation could allow overwriting sensitive files on the system. Abuse of this issu…
CWE: CWE-22
NVD

CRITICAL
CVE-2026-53913
CVE-2026-53913
pkg: apache camel

published: Jul 6, 2026

Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulnerability in Apache Camel Keycloak Component.

The KeycloakSecurityPolicy of camel-keycloak guards a route by running KeycloakSecurityProcessor.beforeProcess(), which performs three check…

CWE: CWE-287, CWE-306, CWE-636
NVD

CRITICAL
CVE-2026-58422
CVE-2026-58422
pkg: oauth

published: Jul 3, 2026

Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts
CWE: CWE-284
NVD

CRITICAL
CVE-2026-20896
CVE-2026-20896
pkg: docker

published: Jul 3, 2026

Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled.
CWE: CWE-284
NVD

CRITICAL
CVE-2026-15113
CVE-2026-15113
pkg: google chrome, google android

published: Jul 8, 2026

Use after free in Autofill in Google Chrome on Android prior to 150.0.7871.115 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
GitHub-GHSA

CRITICAL
Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE
GHSA-xqhv-chqm-fhcc
pkg: github.com/BishopFox/joro
eco: go
published: Jul 8, 2026
# Unauthenticated Cross-Origin Plugin Upload Leads to RCE (Joro ≤ v1.1.0)

**Severity:** Critical
**CVSS v3.1:** 9.6 (AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H)
**Affected versions:** Joro ≤ v1.1.0, proxy mode (default), Linux/macOS
**Reporter:** cstover
**Date:** 2026-05-27

## Summary

Joro's d…

CVE-2026-53649
NVD

CRITICAL
CVE-2026-15062
CVE-2026-15062
pkg: python

published: Jul 8, 2026

SQL injection vulnerabilities in the Snowflake Snowpark Python SDK (snowpark-python) versions prior to 1.53.0 could allow authenticated low-privilege users to execute SQL beyond their authorization scope. An attacker could exploit these vulnerabilities by embedding SQL payloads in source database co…
CWE: CWE-89
GitHub-GHSA

CRITICAL
Goploy: Cross-namespace IDOR and RCE via body-supplied row id in project and project_file handlers
GHSA-26rh-24rg-j3vv
pkg: github.com/zhenorzz/goploy
eco: go
published: Jul 7, 2026
### Summary

`Project.AddFile`, `Project.EditFile`, `Project.RemoveFile`, and `Project.Edit` in `cmd/server/api/project/handler.go` accept a project or project-file row id from the JSON body and act on it without checking that the project belongs to the caller's namespace. The corresponding `model.P…

CVE-2026-53552
GitHub-GHSA

CRITICAL
@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints
GHSA-5rr4-8452-hf4v
pkg: @better-auth/sso
eco: npm
published: Jul 7, 2026
### Am I affected?

Users are affected if all of the following are true:

– Their application uses `@better-auth/sso` at a version `>= 0.1.0, < 1.6.11` on the stable line, or any `1.7.0-beta.x` on the pre-release line.
– The `sso()` plugin is added to their application's `betterAuth({ plugins: […]…

CVE-2026-53513
NVD

CRITICAL
CVE-2026-15378
CVE-2026-15378
pkg: kubernetes

published: Jul 10, 2026

A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind Server-Side Request Forgery (SSRF) by submitting a specially crafted XML Schema Definition (XSD) string. This can lead to unauthorized access to sensitive information, including c…
CWE: CWE-918
GitHub-GHSA

CRITICAL
Zebra: Missing copy constraint in halo2_gadgets variable-base scalar multiplication allows under-constrained base, breaking Orchard Action circuit soundness
GHSA-ww9q-8r59-xv46
pkg: zebrad, halo2_gadgets, orchard
eco: rust
published: Jul 6, 2026
### Summary

A soundness vulnerability in the variable-base scalar multiplication gadget of `halo2_gadgets` allowed a malicious prover to produce a valid proof for an Orchard Action with an *under-constrained* base point. Because this gadget enforces the diversified-address-integrity condition of th…

CVE-2026-54496
GitHub-GHSA

CRITICAL
Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access
GHSA-3fcv-jvfp-m4q9
pkg: github.com/cilium/cilium, github.com/cilium/cilium, github.com/cilium/cilium
eco: go
published: Jul 6, 2026
### Impact

When Cilium L7 functionality is enabled on a cluster, the Envoy instance supporting this functionality creates a world-accessible socket on cluster nodes. A local attacker would be able to access Envoy admin endpoints. Depending on deployment configuration, this can expose sensitive info…

CVE-2026-49445
NVD

CRITICAL
CVE-2026-58122
CVE-2026-58122
pkg: oauth

published: Jul 9, 2026

Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to circumvent local-origin IP restrictions on onboarding endpoints by supplying a spoofed X-Forwarded-For header with a loopback address. Attackers can exploit this bypass to per…
CWE: CWE-348
GitHub-GHSA

CRITICAL
Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins
GHSA-pw9m-5jxm-xr6h
pkg: better-auth
eco: npm
published: Jul 7, 2026
### Am I affected?

Users are affected if all of the following are true:

– Their application uses `better-auth` and has enabled at least one of: `oidcProvider()` (imported from `better-auth/plugins/oidc-provider`), or `mcp()` (imported from `better-auth/plugins/mcp`).
– Their application has at lea…

CVE-2026-53512
GitHub-GHSA

CRITICAL
Decompress: Archive extraction can create files and links outside of the target directory
GHSA-mp2f-45pm-3cg9
pkg: @xhmikosr/decompress, @xhmikosr/decompress, decompress
eco: npm
published: Jul 6, 2026
### Impact

When extracting an archive to a directory, a crafted archive can read or write files outside that directory. The flaw is in the code that writes the parsed entries, so it affects every format decompress handles: tar, tar.gz, tar.bz2, and zip by default, plus any others added through the …

CVE-2026-53486
NVD

CRITICAL
CVE-2026-26247
CVE-2026-26247
pkg: oauth

published: Jul 3, 2026

Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowing token exchange without the expected verifier check.
CWE: CWE-284
NVD

CRITICAL
CVE-2026-26232
CVE-2026-26232
pkg: oauth

published: Jul 3, 2026

Gitea versions before 1.25.5 do not consistently enforce OAuth2 authorization code expiry and single-use behavior during token exchange.
CWE: CWE-294
GitHub-GHSA

CRITICAL
Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditional RCE), mirroring the SQLChatAgent bug fixed in CVE-2026-25879
GHSA-2pq5-3q89-j7cc
pkg: langroid
eco: pip
published: Jul 6, 2026
Neo4jChatAgent passes LLM-generated Cypher queries straight to the Neo4j driver with no validation, no statement-type allowlist, and no opt-out gate. The query text is influenceable by prompt injection (direct user input or indirect content the agent reads back via RAG), so an attacker who can influ…
CVE-2026-55615
GitHub-GHSA

CRITICAL
Langroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema-qualified pg_read_file calls
GHSA-6xc5-4r68-67fc
pkg: langroid
eco: pip
published: Jul 6, 2026
# SQLChatAgent `_validate_query` dangerous-pattern regex is bypassable via quoted/commented/qualified function names

## Summary

The `SQLChatAgent` SQL-injection mitigation, with default `allow_dangerous_operations=False`, combines a raw-text regex blocklist (`_DANGEROUS_SQL_PATTERNS`) with a `sqlg…

CVE-2026-54760
NVD

HIGH
CVE-2026-59148
CVE-2026-59148
pkg: express

published: Jul 9, 2026

Mockoon provides way to design and run mock APIs. Prior to 9.7.0, Mockoon's admin API in commons-server/src/libs/server/admin-api.ts is mounted on the same Express listener as user-defined mock routes, enabled by default in shipped runtimes, serves Access-Control-Allow-Origin: * with write methods a…
CWE: CWE-306, CWE-352, CWE-732, CWE-942
NVD

HIGH
CVE-2026-15133
CVE-2026-15133
pkg: google chrome

published: Jul 8, 2026

Use after free in InterestGroups in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-15132
CVE-2026-15132
pkg: google chrome

published: Jul 8, 2026

Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-457
NVD

HIGH
CVE-2026-15129
CVE-2026-15129
pkg: google chrome

published: Jul 8, 2026

Use after free in Views in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-15126
CVE-2026-15126
pkg: google chrome

published: Jul 8, 2026

Use after free in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-15125
CVE-2026-15125
pkg: google chrome

published: Jul 8, 2026

Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-863
NVD

HIGH
CVE-2026-15123
CVE-2026-15123
pkg: google chrome

published: Jul 8, 2026

Inappropriate implementation in DOM in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-122
NVD

HIGH
CVE-2026-15121
CVE-2026-15121
pkg: google chrome

published: Jul 8, 2026

Use after free in WebRTC in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-15118
CVE-2026-15118
pkg: google chrome

published: Jul 8, 2026

Use after free in Input in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-15116
CVE-2026-15116
pkg: google chrome

published: Jul 8, 2026

Use after free in Actor in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-15114
CVE-2026-15114
pkg: google chrome

published: Jul 8, 2026

Out of bounds read and write in Codecs in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. (Chromium security severity: High)
CWE: CWE-125, CWE-787
NVD

HIGH
CVE-2026-15112
CVE-2026-15112
pkg: google chrome

published: Jul 8, 2026

Use after free in Ozone in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-15110
CVE-2026-15110
pkg: google chrome

published: Jul 8, 2026

Use after free in Extensions in Google Chrome prior to 150.0.7871.115 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-15107
CVE-2026-15107
pkg: google chrome

published: Jul 8, 2026

Use after free in IndexedDB in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-416
NVD

HIGH
CVE-2026-59257
CVE-2026-59257
pkg: n8n n8n

published: Jul 8, 2026

n8n before 1.123.61, 2.x before 2.27.4, and 2.28.x before 2.28.1 contains a SQL injection vulnerability in the legacy MySQL v1 node's executeQuery operation. The operation substitutes evaluated {{ … }} expression values directly into the raw SQL string without parameterization. When a workflow use…
CWE: CWE-89
NVD

HIGH
CVE-2026-34158
CVE-2026-34158
pkg: docker

published: Jul 7, 2026

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, the executeInDocker() helper wraps user-controlled commands in single quotes without escaping embedded single quotes. Attackers who can edit application settings can inject a …
CWE: CWE-78
NVD

HIGH
CVE-2026-34168
CVE-2026-34168
pkg: docker

published: Jul 7, 2026

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the LocalPersistentVolume.name field is interpolated directly into docker volume shell commands without shell argument escaping, allowing an authenticated user to set a storag…
CWE: CWE-78
NVD

HIGH
CVE-2026-42204
CVE-2026-42204
pkg: docker

published: Jul 6, 2026

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. From 4.0.0-beta.471 through 4.0.0-beta.473, a regression in SHELL_SAFE_COMMAND_PATTERN allowed ampersands in custom Docker Compose build, start, and pre/post-deployment command fields, allowing an aut…
CWE: CWE-78
NVD

HIGH
CVE-2026-34599
CVE-2026-34599
pkg: docker

published: Jul 6, 2026

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, there is an authenticated command injection vulnerability in the GetLogs Livewire component which allows users with team membership (lowest privilege member role) to execute a…
CWE: CWE-78
NVD

HIGH
CVE-2026-14535
CVE-2026-14535
pkg: node

published: Jul 4, 2026

In Trail of Bits fickling versions up to and including 0.1.11, the UnsafeImportsML analysis pass unconditionally calls AnalysisContext.shorten_code(node) on every import node it inspects, regardless of whether the import is flagged as unsafe. This call registers the shortened code representation in …
CWE: CWE-693
NVD

HIGH
CVE-2026-14534
CVE-2026-14534
pkg: python

published: Jul 4, 2026

Trail of Bits fickling versions up to and including 0.1.10 do not include the Python standard library modules _posixsubprocess, site, and atexit in the UNSAFE_IMPORTS denylist (fickle.py). Because these modules are absent from the denylist, fickling's check_safety() function returns LIKELY_SAFE with…
CWE: CWE-184, CWE-502
NVD

HIGH
CVE-2025-71380
CVE-2025-71380
pkg: node

published: Jul 4, 2026

The Execute Command node in n8n allows authenticated users to execute arbitrary commands on the host system where n8n runs. Attackers with user access or compromised credentials can exploit this node to run malicious commands, potentially leading to data exfiltration, service disruption, or complete…
CWE: CWE-284
GitHub-GHSA

HIGH
Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requests
GHSA-659f-rgp5-w4wf
pkg: github.com/zalando/skipper
eco: go
published: Jul 8, 2026
### Summary

`zalando/skipper`'s OpenPolicyAgent integration silently bypasses request-body
inspection on HTTP/1.1 `Transfer-Encoding: chunked` and HTTP/2 requests that
omit the `content-length` pseudo-header. When the
`opaAuthorizeRequestWithBody` filter is configured, the
`OpenPolicyAgentInstance.…

CVE-2026-50197
NVD

HIGH
CVE-2026-14891
CVE-2026-14891
pkg: docker

published: Jul 8, 2026

HashiCorp Nomad and Nomad Enterprise are vulnerable to a sandbox escape in the Docker task driver that may allow a job submitter to bind-mount a host path into a container even when volume bind mounts are disabled, potentially leading to reading and writing files on the host. This vulnerability, CVE…
CWE: CWE-59
GitHub-GHSA

HIGH
Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default
GHSA-9h47-pqcx-hjr4
pkg: better-auth
eco: npm
published: Jul 7, 2026
### Am I affected?

Users are affected if all of the following are true:

– Their application uses `better-auth` at a version below the patched release.
– Their application enables `oidcProvider()` from `better-auth/plugins/oidc-provider` or `mcp()` from `better-auth/plugins/mcp` (the mcp plugin del…

GitHub-GHSA

HIGH
Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID
GHSA-9rjw-3gwp-f59v
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

`UpsertWorkspaceApp` overwrites an existing app's `agent_id` on a primary-key conflict and `insertAgentApp` accepts the app ID from the provisioner's `CompleteJob` payload without verifying it belongs to the workspace being built. `CompleteJob` runs under `dbauthz.AsProvisionerd` so the…

CVE-2026-55429
NVD

HIGH
CVE-2026-57573
CVE-2026-57573
pkg: kidocode crawl4ai

published: Jul 6, 2026

Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server applied its SSRF destination check on the non-streaming /crawl path but not on the streaming path. handle_stream_crawl_request passed seed URLs straight to the crawler with no destination validatio…
CWE: CWE-918
NVD

HIGH
CVE-2026-54765
CVE-2026-54765
pkg: traefik traefik

published: Jul 6, 2026

Traefik is an open source HTTP reverse proxy and load balancer. From v3.7.0 prior to v3.7.6, Traefik's Kubernetes Gateway API provider may resolve two accepted HTTPRoutes that target the same backend Service:port but configure different backendRef filters to the same child service and apply only one…
CWE: CWE-284, CWE-863
GitHub-GHSA

HIGH
flyto-core has Unauthenticated Command Execution via HTTP MCP `execute_module`
GHSA-h9f9-h6gm-wc85
pkg: flyto-core
eco: pip
published: Jul 6, 2026
## Unauthenticated Command Execution via HTTP MCP `execute_module`

### Summary

The HTTP MCP endpoint (`POST /mcp`) in flyto-core accepts unauthenticated JSON-RPC `tools/call` requests and dispatches them to arbitrary registered modules, including `sandbox.execute_shell`, which passes attacker-cont…

CVE-2026-55786
NVD

HIGH
CVE-2026-54424
CVE-2026-54424
pkg: windows

published: Jul 4, 2026

An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege. This issue affects Parsec through v2026-05-04.0. The patched version is Parsec for Windows version 150-104a. A user can generate a situation where there is an instance of …
CWE: CWE-648
NVD

HIGH
CVE-2026-47829
CVE-2026-47829
pkg: openssh

published: Jul 9, 2026

Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-spawned ssh process when an operator runs bosh ssh -c, bosh logs -f, or other non-interactive SSH paths, leading to local command execution on the operator's workstation.
Affected v…
NVD

HIGH
CVE-2026-15122
CVE-2026-15122
pkg: google chrome, microsoft windows

published: Jul 8, 2026

Insufficient validation of untrusted input in Codecs in Google Chrome on Windows prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-20
NVD

HIGH
CVE-2026-15120
CVE-2026-15120
pkg: google chrome, microsoft windows

published: Jul 8, 2026

Use after free in Core in Google Chrome on Windows prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-15119
CVE-2026-15119
pkg: google chrome

published: Jul 8, 2026

Race in GetUserMedia in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-362
NVD

HIGH
CVE-2026-55830
CVE-2026-55830
pkg: python

published: Jul 8, 2026

RestrictedPython is a tool that helps to define a subset of the Python language which allows to provide a program input into a trusted environment. Prior to 8.3, check_function_argument_names() rejected protected guard hook names for regular, variadic, and keyword-only arguments but omitted position…
CWE: CWE-184
GitHub-GHSA

HIGH
Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE
GHSA-37h2-6p4f-mp3q
pkg: serena-agent
eco: pip
published: Jul 8, 2026
### Summary

Serena's built-in web dashboard exposes an unauthenticated Flask API on a fixed, predictable port (TCP 24282, hardcoded as `0x5EDA` in `constants.py`). The server has no authentication, no CSRF protection, and no Host header validation. A DNS rebinding attack allows a malicious webpage …

CVE-2026-49471
GitHub-GHSA

HIGH
@better-auth/scim: Account/provider takeover via missing owner binding on non-org SCIM providers
GHSA-j8v8-g9cx-5qf4
pkg: @better-auth/scim
eco: npm
published: Jul 7, 2026
### Am I affected?

Users are affected if all of these hold:

– They install and register the `@better-auth/scim` plugin (`plugins: [scim()]`).
– They create SCIM providers without an `organizationId`, that is, non-organization ("personal") providers. Organization-scoped providers are not affected b…

GitHub-GHSA

HIGH
Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email
GHSA-g38m-r43w-p2q7
pkg: better-auth
eco: npm
published: Jul 7, 2026
### Am I affected?

Users are affected if all of the following are true:

– Their application uses `better-auth` at a version `< 1.6.11` on the stable line, or any current `next` pre-release.
– `emailAndPassword.enabled: true` is set in their application's `betterAuth({ … })` configuration.
– At l…

CVE-2026-53516
GitHub-GHSA

HIGH
Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write
GHSA-qrwj-vh9x-gw5v
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

`agentConn.apiClient()` used the default redirect behavior of `http.Client` while its custom transport dialed the host from the request URL as long as the port was the workspace agent HTTP API port (`4`). Agent tailnet IPs are deterministic from agent UUIDs, so a malicious workspace age…

GitHub-GHSA

HIGH
Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`
GHSA-mcqq-fqgf-rxwm
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

`coder config-ssh` wrote server-supplied SSH settings (`HostnameSuffix`, `SSHConfigOptions`) into the user's `~/.ssh/config` without sanitizing embedded newlines or restricting directives so a malicious or compromised Coder server could inject arbitrary SSH configuration.

> **Note:** P…

CVE-2026-55427
NVD

HIGH
CVE-2026-54423
CVE-2026-54423
pkg: node

published: Jul 10, 2026

In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI commands to a node, bypassing Ironic's access control.
CWE: CWE-424
GitHub-GHSA

HIGH
`lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes
GHSA-4jhm-jv67-739f
pkg: lxml_html_clean
eco: pip
published: Jul 8, 2026
# `lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes (`xlink:href`)

**Reporter:** Guillem Lefait <guillem@datamq.com> · **Date:** 2026-05-10
**Affected:** `lxml` ≤ 6.1.0 and `lxml_html_clean` ≤ 0.4.4 (latest stable)
**Confirmed against:** lxml 6.1.0 + lx…

CVE-2026-49825
GitHub-GHSA

HIGH
Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator
GHSA-wrq8-fcv5-8hvp
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

The tailnet coordinator validates that an agent's `Addresses` derive from its authenticated UUID but applies no equivalent check to `AllowedIPs`. The coordinator forwards agent-supplied `AllowedIPs` verbatim to tunnel peers which install them into the WireGuard peer configuration.

### …

CVE-2026-55428
NVD

HIGH
CVE-2026-59195
CVE-2026-59195
pkg: pnpm pnpm

published: Jul 6, 2026

pnpm is a package manager. Prior to 10.34.4 and 11.8.0, pnpm accepts package names from the env lockfile configDependencies section and uses those names directly when creating config dependency symlinks under node_modules/.pnpm-config. A malicious repository can commit a crafted pnpm-lock.yaml whose…
CWE: CWE-22
NVD

HIGH
CVE-2026-46591
CVE-2026-46591
pkg: apache camel

published: Jul 6, 2026

Improper Neutralization of Special Elements in Data Query Logic vulnerability in Apache Camel Neo4J component.

The camel-neo4j producer builds the Cypher WHERE clause for its match/retrieve and delete operations from the CamelNeo4jMatchProperties map. CVE-2025-66169 addressed Cypher injection throu…

CWE: CWE-943
NVD

HIGH
CVE-2026-12597
CVE-2026-12597
pkg: oauth

published: Jul 10, 2026

The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via the GitHub OAuth callback in versions up to, and including, 6.2.3. The vulnerability exists in the loginpress_on_github_login() function, which blindly trusts the first element (profile[0]['email']) of the array retur…
CWE: CWE-287
NVD

HIGH
CVE-2026-12595
CVE-2026-12595
pkg: oauth

published: Jul 10, 2026

The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via Unverified OAuth Email in all versions up to and including 6.2.3. The vulnerability exists in the loginpress_on_discord_login() Discord OAuth callback handler, which accepts the email field returned by Discord's /user…
CWE: CWE-287
NVD

HIGH
CVE-2026-31985
CVE-2026-31985
pkg: tls

published: Jul 9, 2026

When the upstream Guardian or CMC was configured in the Remote Collector via n2os-tui, the generated configuration disabled TLS certificate verification, and no option was provided to enable it. A malicious actor could perform a man-in-the-middle attack and intercept the communication between the Re…
CWE: CWE-671
NVD

HIGH
CVE-2026-54591
CVE-2026-54591
pkg: python

published: Jul 8, 2026

AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Prior to 2.23.1, a malicious SSH server can write arbitrary files on the asyncssh SCP client's filesystem by sending filenames containing ../ tra…
CWE: CWE-22
GitHub-GHSA

HIGH
NL Portal: IDOR allows any authenticated user to complete and tamper with another user's taak
GHSA-6h3c-r723-7fx3
pkg: nl.nl-portal:taak
eco: maven
published: Jul 8, 2026
## Impact

In versions from 1.5.0 up to and including 3.0.0, any authenticated portal user could complete and tamper with another user's open task by submitting it on their behalf. The task submission endpoint accepted a task ID and a payload, but it never checked whether the task actually belonged …

CVE-2026-49464
NVD

HIGH
CVE-2026-54652
CVE-2026-54652
pkg: nginx

published: Jul 8, 2026

Frigate is an open source network video recorder. In version 0.17.1, the GET /api/logs/{service} endpoint allows any authenticated user including the viewer role to download Frigate and nginx logs, exposing auto-generated admin passwords and camera credentials logged in request query strings and ena…
CWE: CWE-269, CWE-532, CWE-598, CWE-863
GitHub-GHSA

HIGH
@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive
GHSA-7w99-5wm4-3g79
pkg: @better-auth/oauth-provider, better-auth
eco: npm
published: Jul 7, 2026
### Am I affected?

Users are affected if all of the following are true:

– Their project depends on `@better-auth/oauth-provider` at a version `>= 1.6.0, < 1.6.11`, or uses the embedded plugin in `better-auth >= 1.4.8-beta.7, < 1.6.0`, or enables the legacy `oidc-provider` or `mcp` plugins from `be…

CVE-2026-53518
GitHub-GHSA

HIGH
Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption
GHSA-392p-2q2v-4372
pkg: @better-auth/oauth-provider, better-auth
eco: npm
published: Jul 7, 2026
### Am I affected?

Users are affected if all of the following are true:

– Their project depends on `@better-auth/oauth-provider` at a version `>= 1.6.0, < 1.6.11`, or uses the embedded plugin in `better-auth >= 1.4.8-beta.7, < 1.6.0`.
– At least one OAuth client served by their application's autho…

CVE-2026-53517
NVD

HIGH
CVE-2026-13020
CVE-2026-13020
pkg: esri portal_for_arcgis, kubernetes kubernetes, linux linux_kernel

published: Jul 7, 2026

A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. ArcGIS Administrators should configure an …
CWE: CWE-640
GitHub-GHSA

HIGH
Langroid: handle_message() executes user-supplied tool JSON without sender verification
GHSA-gjgq-w2m6-wr5q
pkg: langroid
eco: pip
published: Jul 6, 2026
## Summary

A Langroid application exposing a chat interface to untrusted users may allow direct tool invocation via raw JSON payloads, even when tools are registered with `use=False, handle=True`.

## Details

`enable_message(…, use=False, handle=True)` only prevents the LLM from being instructed…

CVE-2026-54771
NVD

HIGH
CVE-2026-49297
CVE-2026-49297
pkg: apache apache-airflow-providers-google

published: Jul 6, 2026

Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object names returned by the bucket listing API directly to a destination filesystem path without normalisation or containment check. A user with write access to the source GCS bucket (ty…
CWE: CWE-22
NVD

HIGH
CVE-2026-43865
CVE-2026-43865
pkg: apache camel

published: Jul 6, 2026

Deserialization of Untrusted Data vulnerability in Apache Camel Hazelcast component.

The camel-hazelcast component creates and manages Hazelcast instances using a default configuration that applies no Java deserialization filter. When Camel builds the Hazelcast Config itself – that is, when no user…

CWE: CWE-502
NVD

HIGH
CVE-2026-40859
CVE-2026-40859
pkg: apache camel

published: Jul 6, 2026

Deserialization of Untrusted Data vulnerability in Apache Camel.

The camel-vertx-http component deserializes HTTP response bodies carrying the Content-Type application/x-java-serialized-object using a raw java.io.ObjectInputStream, without applying any ObjectInputFilter (VertxHttpHelper.deserialize…

CWE: CWE-502
NVD

HIGH
CVE-2026-12746
CVE-2026-12746
pkg: oauth

published: Jul 4, 2026

Dancer2::Plugin::Auth::OAuth::Provider versions before 0.23 for Perl do not support the OAuth 2.0 state parameter.

The authentication_url method builds the provider authorization redirect without issuing a state value, and the callback method exchanges the callback code and registers the resulting …

CWE: CWE-352
NVD

HIGH
CVE-2026-12740
CVE-2026-12740
pkg: oauth

published: Jul 4, 2026

Plack::Middleware::OAuth versions through 0.10 for Perl do not support the OAuth 2.0 state parameter.

RequestTokenV2 builds the provider authorization redirect without issuing a state value, and AccessTokenV2 exchanges the callback code and registers the resulting token into the session (register_s…

CWE: CWE-352
NVD

HIGH
CVE-2025-71372
CVE-2025-71372
pkg: python

published: Jul 4, 2026

Picklescan before 0.0.33 fails to detect the numpy.f2py.crackfortran.getlincoef gadget in pickle __reduce__ methods, allowing arbitrary code execution. Attackers can craft malicious pickle files that execute arbitrary Python code when loaded, bypassing Picklescan's safety checks and enabling supply-…
CWE: CWE-502
NVD

HIGH
CVE-2026-28699
CVE-2026-28699
pkg: oauth

published: Jul 3, 2026

Gitea versions up to and including 1.26.1 allow OAuth2 access token scope enforcement to be bypassed through HTTP Basic authentication.
CWE: CWE-284, CWE-863
GitHub-GHSA

HIGH
DSpace has possible Remote Code Execution (RCE) through Velocity Templates used by LDN
GHSA-9×82-rm84-c6x7
pkg: org.dspace:dspace-api, org.dspace:dspace-api, org.dspace:dspace-api
eco: maven
published: Jul 8, 2026
## Overview

Remote Code Execution (RCE) is possible via Velocity Templates used by DSpace for [COAR Notify/LDN messages](https://wiki.lyrasis.org/spaces/DSDOC9x/pages/379126679/COAR+Notify). _This vulnerability impacts DSpace versions 8.0 <= 8.3, 9.0 <= 9.2._ The attacker MUST already have DSpace a…

CVE-2026-49832
NVD

HIGH
CVE-2026-22927
CVE-2026-22927
pkg: windows

published: Jul 8, 2026

Omnissa Workspace ONE® Tunnel for Windows addresses a Local Privilege Escalation Vulnerability.
CWE: CWE-22
GitHub-GHSA

HIGH
Linuxfabrik Monitoring Plugins have local privilege escalation using embedded command
GHSA-798h-hpph-m24j
pkg: linuxfabrik-lib
eco: pip
published: Jul 6, 2026
### Summary
When a check plugin places user provided input inside a command which is passed to `shell_exec`, an attacker can abuse this to run arbitrary commands. This is mainly dangerous for plugins which are listed in the sudoers file, because this allows an attacker controlling the nagios user to…
CVE-2026-55426
GitHub-GHSA

HIGH
Open Babel has out-of-bounds write in MOPAC translationVectors[] (UNIT CELL TRANSLATION)
GHSA-55f6-pf8r-c2f4
pkg: openbabel
eco: pip
published: Jul 6, 2026
### Summary

A memory-safety vulnerability in Open Babel's MOPAC output parser
allowed an out-of-bounds write into the `translationVectors[]` array
when reading the "UNIT CELL TRANSLATION" block of a crafted input
file.

### Details

The MOPAC output reader stored translation vectors from the UNIT C…

CVE-2022-46292
NVD

HIGH
CVE-2026-33655
CVE-2026-33655
pkg: go

published: Jul 9, 2026

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0-alpha.1, the default SSRF protection configuration did not apply IP filtering to hostnames; with ApplyIPFilterForDomain disabled by default, URL validation checked domain allow/bl…
CWE: CWE-918
NVD

HIGH
CVE-2026-59216
CVE-2026-59216
pkg: python

published: Jul 9, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call delivered execute:python and execute:tool Socket.IO events to a client-supplied session_id after checking only that the session was connected, allowing authenticated users who learne…
CWE: CWE-94, CWE-200, CWE-639, CWE-862
GitHub-GHSA

HIGH
Phantom: Arbitrary file write and decode-bomb DoS via unconfined MCP tool paths
GHSA-52vm-mxx8-f227
pkg: phantom-audio
eco: pip
published: Jul 9, 2026
### Impact

In Phantom <= 1.3.0, when `PHANTOM_OUTPUT_DIR` was unset (the default), the MCP tools accepted arbitrary absolute output paths with no confinement. Anything able to send tool calls (e.g. an AI agent driving the MCP interface) could **write or overwrite arbitrary files** the process user …

NVD

HIGH
CVE-2026-14373
CVE-2026-14373
pkg: docker

published: Jul 8, 2026

HashiCorp Nomad and Nomad Enterprise did not enforce the allow_privileged restriction for the Docker task driver's host namespace mode options. This may allow an authenticated job submitter to run a container in a host namespace and access information belonging to the host or to other workloads on t…
CWE: CWE-862
NVD

HIGH
CVE-2026-60002
CVE-2026-60002
pkg: openbsd openssh

published: Jul 8, 2026

ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)
CWE: CWE-416
GitHub-GHSA

HIGH
Goploy: Arbitrary File Read via Path Traversal in /deploy/fileDiff allows Remote Server Compromise
GHSA-4g5x-hcwm-82jw
pkg: github.com/zhenorzz/goploy
eco: go
published: Jul 7, 2026
> [ Click here to jump to the Simplified Chinese version (点击跳转到简体中文版本)](#goploy-系统任意文件读取)
# Goploy System Arbitrary File Read Vulnerability

## Basic Information
– **Vulnerability Name**: Goploy Endpoints Arbitrary File Read via Path Traversal
– **Vulnerability …

CVE-2026-53553
GitHub-GHSA

HIGH
Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp
GHSA-86j7-9j95-vpqj
pkg: better-auth, better-auth
eco: npm
published: Jul 7, 2026
### Am I affected?

Check each condition. Users are affected when all of the first three hold.

– Their application enables the `oidc-provider` plugin or the `mcp` plugin from `better-auth/plugins`. The `mcp` plugin wraps the same provider and carries the same defect. Both are on the migration path …

GitHub-GHSA

HIGH
Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin
GHSA-fmh4-wcc4-5jm3
pkg: better-auth
eco: npm
published: Jul 7, 2026
### Am I affected?

Users are affected if all of the following are true:

– Their application uses `better-auth` with the `organization` plugin (`import { organization } from "better-auth/plugins/organization"`).
– Their application enables a sign-up surface that allows arbitrary unverified email re…

CVE-2026-53514
GitHub-GHSA

HIGH
New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs
GHSA-6qcr-qxgr-m7fv
pkg: github.com/QuantumNous/new-api
eco: go
published: Jul 7, 2026
## Summary

The default SSRF protection configuration did not apply IP filtering to hostnames. With `ApplyIPFilterForDomain` disabled by default, URL validation checked domain allow/block rules but did not resolve a hostname and validate the resolved IP address. Authenticated users could configure n…

CVE-2026-33655
GitHub-GHSA

HIGH
Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps
GHSA-v54h-cp2w-9x4g
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

`coder open app` opens external workspace-app URLs without validating the scheme or host. When an external app URL contains the `$SESSION_TOKEN` placeholder the CLI replaces it with the user's real session token before handing the URL to the OS open handler.

> **Note:** Practical explo…

CVE-2026-55431
GitHub-GHSA

HIGH
OpenRemote has Cross-Realm User Information Disclosure in UserResourceImpl
GHSA-xqr9-4wvv-gvch
pkg: io.openremote:openremote-manager
eco: maven
published: Jul 6, 2026
### Summary

A realm admin of tenant B can read the profile, client roles, and realm roles of any user in any other realm (including the master realm) by supplying the target user's UUID in the REST API path. Three read endpoints in UserResourceImpl check whether the caller holds the read:admin role…

CVE-2026-54641
NVD

HIGH
CVE-2026-9165
CVE-2026-9165
pkg: kubernetes

published: Jul 6, 2026

A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQL queries served on the authenticated GraphQL API. An authenticated user with a valid API token can send deeply nested queries that cause excessive resource consumption in Central,…
CWE: CWE-400
GitHub-GHSA

HIGH
OpenRemote has an incomplete fix for CVE-2026-40882: XXE in KNXProtocol.startAssetImport() allows arbitrary file read via unprotected XMLInputFactory
GHSA-7v6w-c3f4-9wpq
pkg: io.openremote:openremote-agent
eco: maven
published: Jul 6, 2026
### Summary
The fix for CVE-2026-40882 addressed only the Velbus asset import handler. The KNX asset import handler (`KNXProtocol`) processes user-uploaded ETS project ZIP files through Saxon XSLT and `XMLInputFactory.newInstance()` with no XXE protection, allowing any authenticated user to read arb…
CVE-2026-54640
GitHub-GHSA

HIGH
Mistune: Potential DoS via quadratic-time parsing in parse_link_text
GHSA-qcq2-496w-v96p
pkg: mistune
eco: pip
published: Jul 9, 2026
### Summary
Mistune is vulnerable to a CPU exhaustion DoS due to superlinear (approximately O(n²)) behavior in parse_link_text. A relatively small input consisting of repeated [ characters causes significant parsing slowdown.

### Affected component
mistune/inline_parser.py → **parse_link_text**

CVE-2026-49851
NVD

HIGH
CVE-2026-54695
CVE-2026-54695
pkg: python

published: Jul 9, 2026

Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. Prior to 1.4.0, the pipecat development runner registers a /ws WebSocket endpoint for telephony testing that accepts connections without authentication, reads an attacker-supplied callSid fr…
CWE: CWE-862
NVD

HIGH
CVE-2026-13462
CVE-2026-13462
pkg: ssl

published: Jul 9, 2026

PayRange Android app, version 7.0.7 and below, contains an SSL bypass vulnerability that allows invalid certificates to be accepted in application webviews. A remote and unauthenticated attacker can steal information that the user sends.
NVD

HIGH
CVE-2026-11404
CVE-2026-11404
pkg: tls

published: Jul 9, 2026

Cesanta Mongoose before 7.22 contains an out-of-bounds read in the built-in TLS server function mg_tls_server_recv_hello(), which uses an attacker-controlled session_id_len byte from a TLS ClientHello as a buffer index without validating it against the length of received data. A remote, unauthentica…
CWE: CWE-125
GitHub-GHSA

HIGH
org.hl7.fhir.core: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint
GHSA-7cmj-v6x8-frvv
pkg: ca.uhn.hapi.fhir:org.hl7.fhir.dstu2, ca.uhn.hapi.fhir:org.hl7.fhir.dstu2016may, ca.uhn.hapi.fhir:org.hl7.fhir.dstu3
eco: maven
published: Jul 9, 2026
# Summary
All implementations of FHIRPathEngine accept arbitrary FHIRPath expressions and evaluate them without input validation. The utility intended to secure this evaluation did so incorrectly, and did not fully cover all places in which evaluation was being done. An attacker can send a resource …
CVE-2026-49485
GitHub-GHSA

HIGH
Soup Sieve: Regular Expression Denial of Service (ReDoS) via Selector Parser
GHSA-836r-79rf-4m37
pkg: soupsieve
eco: pip
published: Jul 9, 2026
### Summary

The CSS selector parser in soupsieve (the CSS selector engine for Beautiful Soup 4) contains a regular expression vulnerable to catastrophic backtracking. When processing an attribute selector with an unterminated quoted value, the `VALUE` regex pattern in `css_parser.py` enters exponen…

CVE-2026-49477
GitHub-GHSA

HIGH
Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists
GHSA-2wc2-fm75-p42x
pkg: soupsieve
eco: pip
published: Jul 9, 2026
### Summary

The CSS selector parser in soupsieve (the CSS selector engine for Beautiful Soup 4) allocates unbounded memory when compiling large comma-separated selector lists. An attacker who can supply a crafted CSS selector string to `soupsieve.compile()` or Beautiful Soup's `.select()` / `.selec…

CVE-2026-49476
GitHub-GHSA

HIGH
Micronaut doesn't set a maximum redirect count for its HTTP Client, enabling infinite loop DoS
GHSA-387m-935m-c4vw
pkg: io.micronaut:micronaut-http-client, io.micronaut:micronaut-http-client, io.micronaut:micronaut-http-client
eco: maven
published: Jul 9, 2026
The Netty-based Micronaut HTTP Client does not impose a limit on HTTP redirections, potentially allowing an infinite redirect loop that could lead to a denial-of-service attack.

### Patches

The following versions are patched:

– For Micronaut 5, versions equal or greater than [5.0.1](https://gith…

NVD

HIGH
CVE-2026-54772
CVE-2026-54772
pkg: windows

published: Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, an unauthenticated remote attacker that can reach a NetTcpBinding, NetNamedPipeBinding, or UnixDomainSocketBinding endpoint can trigger premature EOF handling in the CoreWCF net.tc…
CWE: CWE-400, CWE-835
NVD

HIGH
CVE-2026-54499
CVE-2026-54499
pkg: python

published: Jul 8, 2026

Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human languages. Prior to 1.12.2, Stanza model loaders such as stanza.models.common.pretrain.Pretrain.load() attempt torch.load(…, weights_only=True) but fall back to torch.load(…, weights_o…
CWE: CWE-502, CWE-676
NVD

HIGH
CVE-2026-15117
CVE-2026-15117
pkg: google chrome

published: Jul 8, 2026

Use after free in Payments in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-15111
CVE-2026-15111
pkg: google chrome

published: Jul 8, 2026

Use after free in Views in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-31309
CVE-2026-31309
pkg: node

published: Jul 8, 2026

Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node before v1.36.0 allows unauthenticated attackers to arbitrarily overwrite the node's configuration and achieve a full node takeover via supplying a crafted POST request.
CWE: CWE-862
NVD

HIGH
CVE-2026-49866
CVE-2026-49866
pkg: node

published: Jul 8, 2026

libp2p is a JavaScript Implementation of libp2p networking stack. Prior to 16.0.0, @libp2p/gossipsub defaultDecodeRpcLimits set maxIhaveMessageIDs and maxIwantMessageIDs to Infinity, allowing oversized IHAVE and IWANT control message arrays in message/decodeRpc.ts and gossipsub.ts to synchronously i…
CWE: CWE-770
NVD

HIGH
CVE-2026-59939
CVE-2026-59939
pkg: python

published: Jul 8, 2026

httplib2 is a comprehensive HTTP client library for Python. Prior to 0.32.0, httplib2 performs unbounded decompression of HTTP response bodies encoded with Content-Encoding: gzip or deflate in _decompressContent in httplib2/init.py, allowing a malicious or compromised HTTP server to return a small c…
CWE: CWE-409
NVD

HIGH
CVE-2026-55404
CVE-2026-55404
pkg: linux

published: Jul 8, 2026

yt-dlp and youtube-dl are command-line audio/video downloaders. Prior to 2026.7.4, the –write-link, –write-url-link, and –write-desktop-link options can write .url or .desktop shortcut files using attacker-controlled webpage_url or filename metadata without sufficient validation or escaping, allo…
CWE: CWE-74
NVD

HIGH
CVE-2026-59928
CVE-2026-59928
pkg: mistune_project mistune

published: Jul 8, 2026

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a Markdown document containing many repeated or distinct reference-link definitions causes quadratic work in src/mistune/block_parser.py and the ref_links environment dictionary handling, allowing denial of service throu…
CWE: CWE-407, CWE-1333
NVD

HIGH
CVE-2026-59925
CVE-2026-59925
pkg: mistune_project mistune

published: Jul 8, 2026

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, long sequences of well-formed double-asterisk or triple-asterisk emphasis pairs around a character cause quadratic work in src/mistune/inline_parser.py because the parser scans forward for matching close markers from eve…
CWE: CWE-407, CWE-1333, CWE-407
NVD

HIGH
CVE-2026-59922
CVE-2026-59922
pkg: mistune_project mistune

published: Jul 8, 2026

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a run of closed tilde, equals-sign, or caret marker pairs around a character causes quadratic work in src/mistune/plugins/formatting.py when the strikethrough, mark, or insert plugin scans for matching markers from each …
CWE: CWE-407, CWE-1333, CWE-407
NVD

HIGH
CVE-2026-59892
CVE-2026-59892
pkg: node

published: Jul 8, 2026

OpenTelemetry JavaScript is the OpenTelemetry JavaScript client. Prior to 2.9.0, @opentelemetry/propagator-jaeger decodes incoming uber-trace-id and uberctx-* HTTP header values with decodeURIComponent() without handling decode errors, allowing an unauthenticated remote attacker to send a malformed …
CWE: CWE-248
NVD

HIGH
CVE-2026-10708
CVE-2026-10708
pkg: jwt

published: Jul 8, 2026

This vulnerability enables large‑scale data harvesting without requiring app‑specific secrets. A single request to a minimal leaderboard component may return user records containing emails, UUIDs, and custom fields. The combination of wildcard CORS behavior, long‑lived twenty‑day JWTs, and t…
NVD

HIGH
CVE-2026-58656
CVE-2026-58656
pkg: jwt

published: Jul 8, 2026

Grav API plugin before v1.0.0-rc.16 accepts JWT tokens via the ?token= URL query parameter and responds with Access-Control-Allow-Origin: *, allowing unauthenticated attackers to make fully authenticated cross-origin API requests from any malicious website. Attackers who obtain a leaked JWT token fr…
CWE: CWE-598
NVD

HIGH
CVE-2026-14895
CVE-2026-14895
pkg: express

published: Jul 7, 2026

String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service.

The trim and rtrim functions stripped trailing whitespace with s/\s*$//u. Because \s* matches greedily and the $ anchor fails whenever a non-whitespace character follows the whitespace, the regex e…

CWE: CWE-1333
NVD

HIGH
CVE-2026-56811
CVE-2026-56811
pkg: phoenixframework phoenix

published: Jul 7, 2026

Allocation of Resources Without Limits or Throttling vulnerability in phoenixframework phoenix (Phoenix.Socket module) allows an unauthenticated attacker to cause a denial of service against any endpoint that mounts a Phoenix socket with a reachable channel transport (WebSocket or LongPoll).

This v…

CWE: CWE-770
NVD

HIGH
CVE-2026-55574
CVE-2026-55574
pkg: vllm vllm

published: Jul 6, 2026

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, the structured_outputs.regex API parameter passes a user-supplied regular expression string directly to the grammar compiler backends with no compilation timeout; in the xgrammar backend the string…
CWE: CWE-1333
NVD

HIGH
CVE-2026-55380
CVE-2026-55380
pkg: python pillow

published: Jul 6, 2026

Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompression_bomb_check(), allowing a crafted .gd file to trigger excessive C-heap allocation when loaded. Th…
CWE: CWE-789
NVD

HIGH
CVE-2026-55379
CVE-2026-55379
pkg: python pillow

published: Jul 6, 2026

Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling Image._decompression_bomb_check(), bypassing Pillow's documented decompression bomb pro…
CWE: CWE-789
NVD

HIGH
CVE-2026-54060
CVE-2026-54060
pkg: python pillow

published: Jul 6, 2026

Pillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.new("1", (xsize, ysize)) without calling Image._decompression_bomb_check(), allowing a font to trigger excessive allocation during conversion or saving…
CWE: CWE-789
NVD

HIGH
CVE-2026-54059
CVE-2026-54059
pkg: python pillow

published: Jul 6, 2026

Pillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without calling Image._decompression_bomb_check(), allowing crafted PCF font data to cause excessive memory allocat…
CWE: CWE-789
NVD

HIGH
CVE-2026-13698
CVE-2026-13698
pkg: openvpn openvpn

published: Jul 6, 2026

A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers with a valid tls-crypt-v2 client key to potentially cause a denial of service
CWE: CWE-401, CWE-770, CWE-401
NVD

HIGH
CVE-2026-54784
CVE-2026-54784
pkg: windows

published: Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. In version 1.9.0, CoreWCF SPNEGO SecurityContextToken negotiation can expose the proof key recovered from the RSTR when TransportWithMessageCredential with Windows client credentials and session establishme…
CWE: CWE-311, CWE-523
NVD

HIGH
CVE-2026-54783
CVE-2026-54783
pkg: windows

published: Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF WS-Security endorsing and supporting signature verification does not ensure the selected ds:Signature covers the expected Security header target, allowing an attacker with …
CWE: CWE-294, CWE-345, CWE-347
NVD

HIGH
CVE-2026-54781
CVE-2026-54781
pkg: windows

published: Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML token validation does not enforce SubjectConfirmation method URIs or holder-of-key proof keys in SamlSecurityTokenHandler, allowing holder-of-key downgrade or custom c…
CWE: CWE-287, CWE-345
NVD

HIGH
CVE-2026-54774
CVE-2026-54774
pkg: windows

published: Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, SamlSerializer skips final SignatureValue verification when a CoreWCF service validates SAML tokens using a non-X.509 signing token, allowing an attacker to reference a non-X.509 S…
CWE: CWE-345, CWE-347
NVD

HIGH
CVE-2026-55436
CVE-2026-55436
pkg: coder coder

published: Jul 8, 2026

Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and prior to versions 2.32.7, 2.33.8, and 2.34.2, the AI Bridge Proxy (`aibridgeproxyd`) created a goproxy server whose default transport set `InsecureSkipVerify: true` and only assigned…
CWE: CWE-295
NVD

HIGH
CVE-2026-55076
CVE-2026-55076
pkg: coder coder

published: Jul 7, 2026

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, Coder's OIDC callback checked `email_verified` with a direct Go `bool` type assertion. When an IdP returned the claim as a non-boolean (for example the string …
CWE: CWE-287, CWE-704
GitHub-GHSA

HIGH
Coder's AI Bridge Proxy skips TLS certificate verification in default configuration
GHSA-84rm-42xw-mx52
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

The AI Bridge Proxy (`aibridgeproxyd`) created a goproxy server whose default transport set `InsecureSkipVerify: true` and only assigned a secure transport when an upstream proxy was configured. In the default configuration (no upstream proxy), outbound HTTPS to the Coder access URL acc…

CVE-2026-55436
GitHub-GHSA

HIGH
Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass
GHSA-9r87-mvcw-x35f
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

Two flaws in Coder's OIDC login chained into account takeover: email-based user matching fell back to linking by email without checking for an existing link to a different IdP subject and the `email_verified` claim was only enforced when present as a boolean `false` so an absent or non-…

CVE-2026-55075
GitHub-GHSA

HIGH
Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking
GHSA-75vm-6w67-gwvp
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

Coder's OIDC callback checked `email_verified` with a direct Go `bool` type assertion. When an IdP returned the claim as a non-boolean (for example the string `"false"`) or omitted it, the assertion failed open and the email was treated as verified. Combined with an unconditional email-…

CVE-2026-55076
NVD

HIGH
CVE-2026-59214
CVE-2026-59214
pkg: python

published: Jul 9, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, Open WebUI runs client-side Python with Pyodide in a same-origin web worker, allowing stored chat payloads that use pyodide.http.pyfetch or the js module fetch and XMLHttpRequest APIs to issue auth…
CWE: CWE-79
GitHub-GHSA

HIGH
Open WebUI vulnerable to Stored XSS via iFrame embeds in response messages
GHSA-vjm7-m4xh-7wrc
pkg: open-webui
eco: pip
published: Jul 7, 2026
### Summary
Manually modifying chat history allows setting the `embeds` property on a response message, the content of which is loaded into an iFrame with a sandbox that has `allow-scripts` and `allow-same-origin` set, ignoring the "iframe Sandbox Allow Same Origin" configuration. This enables store…
CVE-2026-26193
GitHub-GHSA

HIGH
Open WebUI vulnerable to Stored XSS via iFrame in citations model
GHSA-xc8p-9rr6-97r2
pkg: open-webui
eco: pip
published: Jul 7, 2026
### Summary
Manually modifying chat history allows setting the `html` property within document metadata. This causes the frontend to enter a code path that treats document contents as HTML, and render them in an iFrame when the citation is previewed. This allows stored XSS via a weaponised document …
CVE-2026-26192
GitHub-GHSA

HIGH
9router: Login brute-force protection bypass via spoofed X-Forwarded-For header
GHSA-7cfm-pqrj-xgq7
pkg: 9router
eco: npm
published: Jul 6, 2026
## Summary

The 9router dashboard login rate limiter derives the client identity from the attacker-controlled `X-Forwarded-For` HTTP header. When 9router is directly exposed, or deployed behind a reverse proxy that does not overwrite untrusted forwarding headers, a remote attacker can rotate the `X-…

CVE-2026-55501
GitHub-GHSA

HIGH
chmod: –preserve-root bypassed by any path that resolves to root (e.g. /../)
GHSA-4c7q-4928-8445
pkg: uu_chmod
eco: rust
published: Jul 6, 2026
`Chmoder::chmod()` only compares the literal argument against `Path::new("/")`, so the `–preserve-root` guard is bypassed by any path that *resolves* to root — a symlink to `/` or simply `/../`.

“`
if self.recursive && self.preserve_root && file == Path::new("/") {
return Err(ChmodError::Pr…

CVE-2026-35338
NVD

HIGH
CVE-2026-14802
CVE-2026-14802
pkg: react

published: Jul 6, 2026

A vulnerability was detected in react create-react-app up to 5.0.1 on macOS. This affects the function startBrowserProcess of the file openBrowser.js of the component react-dev-utils. Performing a manipulation results in os command injection. Remote exploitation of the attack is possible. The exploi…
CWE: CWE-77, CWE-78
NVD

HIGH
CVE-2026-59721
CVE-2026-59721
pkg: node

published: Jul 9, 2026

Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the updateInfraConfigs GraphQL mutation in admin/infra.resolver.ts accepts an attacker-controlled MAILER_SMTP_URL value, and validateSMTPUrl in utils.ts permits path, query, or fragment content that nodemailer parses into sen…
CWE: CWE-77, CWE-78, CWE-915
GitHub-GHSA

HIGH
Coder: User-admin role can reset owner account password
GHSA-29xf-69gq-m9jx
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

The `PUT /api/v2/users/{user}/password` endpoint authorized only `ActionUpdatePersonal` and did not prevent a `user-admin` from resetting an `owner` account's password. It also did not require the current password when an admin reset another user's password.

> **Note:** Exploitation re…

CVE-2026-55077
NVD

HIGH
CVE-2026-59219
CVE-2026-59219
pkg: jwt

published: Jul 9, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 before 0.10.0 with Redis configured, Socket.IO connect, user-join, join-channels, join-note, and the terminal websocket first-message authentication used decode_token without the Redis-backed is_valid_to…
CWE: CWE-613
NVD

HIGH
CVE-2026-47828
CVE-2026-47828
pkg: tls

published: Jul 9, 2026

During bosh create-env and bosh delete-env, the CLI uploads compiled CPI packages and rendered job templates to the new VM's DAV blobstore over HTTPS without verifying the server certificate, even though a CA certificate for that endpoint is available in the installation manifest. A network attacker…
NVD

HIGH
CVE-2026-58583
CVE-2026-58583
pkg: windows

published: Jul 7, 2026

FluxInk (formerly Sunia SPB Peripheral) Color Management Driver (TcnPeripheral64.sys) 1.0.7.2 allows local privilege escalation for a standard user account via arbitrary physical memory mapping at \Device\PhysicalMemory. Fixed in version 1.0.7.6. The fixed driver is currently available in the Window…
CWE: CWE-269
GitHub-GHSA

HIGH
mkfifo: permissions of an existing file are changed after FIFO creation fails
GHSA-pmf6-rcx4-v53v
pkg: uu_mkfifo
eco: rust
published: Jul 6, 2026
When `mkfifo()` fails (e.g. target already exists), the code shows an error but is missing a `continue;`, so it falls through to `fs::set_permissions` and changes the permissions of the pre-existing file to the default FIFO mode (`0o666` & umask -> `0644`).

“`
$ touch secret; chmod 000 secret
$ co…

CVE-2026-35341
GitHub-GHSA

HIGH
flyto-core has SSRF guard bypass via IPv6 transition addresses (IPv4-mapped / 6to4 / NAT64) in validate_url_ssrf
GHSA-794r-5rp2-fpg8
pkg: flyto-core
eco: pip
published: Jul 6, 2026
## Summary

`flyto-core`'s SSRF protection (`validate_url_ssrf` / `is_private_ip` in `src/core/utils.py`) blocks private and metadata destinations by resolving the host and testing the resulting IP for membership in a hardcoded `PRIVATE_IP_RANGES` list. That list contains only the *native* RFC 1918 …

CVE-2026-55787
NVD

HIGH
CVE-2026-59196
CVE-2026-59196
pkg: pnpm pnpm

published: Jul 6, 2026

pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted lockfile alias could be joined directly under a hoisted node_modules directory. Traversal aliases could escape that directory, while reserved aliases such as .bin or .pnpm could overwrite pnpm-owned layout. This vulnerability is fixe…
CWE: CWE-22, CWE-73
GitHub-GHSA

HIGH
Ruby CSS Parser: SSRF and Local File Disclosure in `CssParser::Parser#read_remote_file`
GHSA-9pmc-p236-855h
pkg: css_parser
eco: rubygems
published: Jul 9, 2026
## Summary

`CssParser::Parser#read_remote_file` (and therefore `load_uri!`, and the `@import`-following branch of `add_block!`) issues HTTP/HTTPS requests against any host, port and URI it is handed, with no scheme allowlist, no host / IP filtering, and no protection against link-local, loopback or…

CVE-2026-53727
GitHub-GHSA

HIGH
Note Mark: Path traversal via unsanitized book/note slug in migrate export (sibling of GHSA-g49p)
GHSA-rqrh-8wpv-x7hh
pkg: github.com/enchant97/note-mark/backend
eco: go
published: Jul 9, 2026
## Summary

Note Mark validates book and note `slug` values with the OpenAPI/huma tag `pattern:"[a-z0-9-]+"`. huma compiles this with `regexp.MustCompile(s.Pattern)` and tests it with `patternRe.MatchString(str)`, an UNANCHORED match. Because the pattern is not anchored (`^…$`), any string that me…

CVE-2026-50553
GitHub-GHSA

HIGH
ratex-parser panics on `\verb` with a multibyte delimiter (UTF-8 byte-boundary slice)
GHSA-4hgp-59h5-gvrj
pkg: ratex-parser
eco: rust
published: Jul 7, 2026
### Summary

The public parser entrypoint `ratex_parser::parse(&str)` panics on the **9-byte** input `\verbéxé` (i.e. `\verb` followed by the non-ASCII delimiter `é`). When handling a `\verb` command, the parser slices the verbatim argument with **byte** indices (`arg[1..arg.len() – 1]`); if the …

CVE-2026-53530
GitHub-GHSA

HIGH
uutils coreutils: cp/install/mv/ln –suffix alone does not enable backup mode (silent data loss vs GNU)
GHSA-fqf6-gxhh-2xhw
pkg: uucore
eco: rust
published: Jul 7, 2026
`determine_backup_mode` in `src/uucore/src/lib/features/backup_control.rs` only checks `–backup`/`-b` and returns `BackupMode::None` when only `–suffix` is given. GNU enables backup mode when `–suffix` is used alone (defaulting to existing/numbered, or `$VERSION_CONTROL`). Affects `cp`, `install`…
GitHub-GHSA

HIGH
Open WebUI vulnerable to stored XSS via unescaped markdown token in MarkdownTokens.svelte leading to full account takeover and RCE via functions
GHSA-9f4f-jv96-8766
pkg: open-webui
eco: pip
published: Jul 7, 2026
### Summary

A vulnerability in the way certain html tags in chat messages are rendered allows attackers to inject JavaScript code into a chat transcript. The JavaScript code will be executed in the user's browser every time that chat transcript is opened, allowing attackers to retrieve the user's a…

CVE-2025-46719
GitHub-GHSA

HIGH
XWiki Platform Old Core: Resource path traversal via /skin/ action endpoint in Jetty 12+
GHSA-qj4x-9g63-25g6
pkg: org.xwiki.platform:xwiki-platform-oldcore, org.xwiki.platform:xwiki-platform-oldcore
eco: maven
published: Jul 7, 2026
### Impact

With Jetty 12+ a user can craft a URL to access any resource the Jetty instance is allowed to access.

For example `http://[host]/xwiki/bin/skin/..%252f/..%252f..%252f..%252f..%252f..%252f..%252f..%252fetc/passwd` allows downloading the content of the /etc/passwd file, provided Jetty is …

CVE-2026-34151
GitHub-GHSA

HIGH
OpenRemote has Authenticated SQL Injection via Datapoint Crosstab Export
GHSA-cgfv-jrfp-2r7v
pkg: io.openremote:openremote-manager
eco: maven
published: Jul 6, 2026
## Summary

The datapoint export API builds a PostgreSQL crosstab export query by concatenating asset display names into raw SQL. An authenticated user who can create or rename an asset and then request a crosstab datapoint export can inject SQL through the asset name. The injected query output is s…

GitHub-GHSA

HIGH
Scriban: Template Writes to Arbitrary CLR Properties via `TypedObjectAccessor` (Mass Assignment + `private` / `init` / `internal` Setter Bypass)
GHSA-7jvp-hj45-2f2m
pkg: Scriban
eco: nuget
published: Jul 6, 2026
<!– obsidian –><h2 data-heading="Description">Description</h2>
<p>When a host pushes a CLR object into a Scriban <code>TemplateContext</code> via the standard, documented pattern —</p>
<pre><code class="language-csharp">var so = new ScriptObject();
so["user"] = currentUser; // direct CLR refer…
GitHub-GHSA

MEDIUM
CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation
GHSA-q6h5-q3q6-f87x
pkg: github.com/cilium/cilium, github.com/cilium/cilium, github.com/cilium/cilium
eco: go
published: Jul 6, 2026
### Impact

Users with the ability to create CiliumLocalRedirectPolicies can specify arbitrary ClusterIPs via addressMatcher, which enables hijacking traffic to Services in any namespace, bypassing the namespace-scoping guarantees enforced by serviceMatcher.

In addition, deleting such a policy can …

CVE-2026-53935
NVD

MEDIUM
CVE-2026-55689
CVE-2026-55689
pkg: jwt

published: Jul 9, 2026

OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, OpenFGA's OIDC authenticator skipped JWT audience validation when authn.method was set to oidc, authn.oidc.issuer was configured, and authn.oidc.audience was not set, allowing a token minted for an unrelated service…
CWE: CWE-287
NVD

MEDIUM
CVE-2026-59208
CVE-2026-59208
pkg: n8n n8n

published: Jul 9, 2026

n8n is an open source workflow automation platform. Prior to 2.27.4 and from 2.28.0 prior to 2.28.1, n8n instances configured with more than one trusted token-exchange issuer resolved external identities to local accounts using only the JWT sub claim and ignored the iss claim, allowing an attacker w…
CWE: CWE-287, CWE-346, CWE-346
GitHub-GHSA

MEDIUM
Micronaut: DefaultHttpClient follows redirects, forwarding Authorization, Cookie, and Proxy-Authorization headers
GHSA-q6gh-6v2r-hjv3
pkg: io.micronaut:micronaut-http-client, io.micronaut:micronaut-http-client, io.micronaut:micronaut-http-client
eco: maven
published: Jul 9, 2026
### Impact

> DefaultHttpClient follows redirects and forwards Authorization, Cookie, and Proxy-Authorization headers to redirect targets across domain boundaries. The blocklist only filters Host/Connection/TE/CT/CL.
> Additionally, no maximum redirect count exists, enabling infinite loop DoS.
> Aff…

GitHub-GHSA

MEDIUM
rm: –preserve-root bypassed via a symlink to / (string check instead of dev/inode)
GHSA-7cr3-h577-g38j
pkg: uu_rm
eco: rust
published: Jul 6, 2026
The `–preserve-root` check uses a path-string test (`path.has_root() && path.parent().is_none()`) rather than comparing device/inode. A symlink to `/` (e.g. `/tmp/rootlink -> /`) has a parent component, so it passes the check. GNU caches `/`'s dev/inode at startup and compares every traversed direc…
CVE-2026-35349
GitHub-GHSA

MEDIUM
mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)
GHSA-h444-6j9x-p8vh
pkg: uu_mv
eco: rust
published: Jul 6, 2026
When moving directories across filesystems, uutils `mv` dereferences symlinks inside the tree, copying their targets as real files/dirs instead of preserving the symlinks. GNU preserves symlinks by default. E.g. a `etc_link -> /etc` inside the source becomes a full copy of `/etc` at the destination.…
CVE-2026-35365
GitHub-GHSA

MEDIUM
Avo: Direct attachment upload endpoint lacks upload authorization and bypasses field-level upload policy
GHSA-pqpw-cvm4-8mv9
pkg: avo
eco: rubygems
published: Jul 9, 2026
### Summary

Avo's direct attachment upload endpoint lacks server-side upload authorization and bypasses the documented field-level upload policy methods such as `upload_{FIELD_ID}?`.

An authenticated Avo user who can reach the Avo attachment upload endpoint can replace or add attachment content, i…

CVE-2026-53769
NVD

MEDIUM
CVE-2026-59220
CVE-2026-59220
pkg: express

published: Jul 9, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.2 before 0.10.0, the SKILL_MENTION_RE and strip_re regular expressions in backend/open_webui/utils/middleware.py parsed <$skillId|label> skill mentions with overlapping quantifiers, allowing an authenticat…
CWE: CWE-1333
GitHub-GHSA

MEDIUM
Gittensory: Missing contributor-scoped access control on profile endpoint and MCP tool leaks miner financial data
GHSA-382c-vx95-w3p5
pkg: @jsonbored/gittensory-mcp
eco: npm
published: Jul 9, 2026
### Summary

`GET /v1/contributors/:login/profile` and the `gittensory_get_contributor_profile` MCP tool skip the contributor-scoped access check that every sibling endpoint enforces. Any authenticated session/API/MCP token holder can read any contributor's profile; for confirmed Gittensor miners t…

GitHub-GHSA

MEDIUM
pyLoad: Unbounded Memory Growth Leading to DoS and Potential DDoS in EventManager
GHSA-c2f9-4mc8-j656
pkg: pyload-ng
eco: pip
published: Jul 9, 2026
## Description:
The `EventManager` module in `pyload` manages a list of `Client` instances for subscribing to events. The addition of each unique `uuid` from the `get_events` API causes the creation of a `Client` instance that gets appended to the `clients` list. Although there is a `clean()` method…
CVE-2026-48987
NVD

MEDIUM
CVE-2026-54775
CVE-2026-54775
pkg: windows

published: Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, a CoreWCF service listening on a Kafka topic stops processing new records from that topic when KafkaTransportPump receives a null-value tombstone record, causing a persistent endpo…
CWE: CWE-248, CWE-754, CWE-755
NVD

MEDIUM
CVE-2026-15109
CVE-2026-15109
pkg: google chrome

published: Jul 8, 2026

Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-457
NVD

MEDIUM
CVE-2026-54777
CVE-2026-54777
pkg: windows

published: Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF NetNamedPipe transport accepts attachment to a pre-existing named pipe instance, allowing local interception of NetNamedPipe traffic when an attacker races NamedPipeListene…
CWE: CWE-367, CWE-665
GitHub-GHSA

MEDIUM
NL Portal: Missing per-user authorization on document and decision GraphQL queries in nl-portal-backend-libraries
GHSA-qpm9-h556-mwxm
pkg: nl.nl-portal:documenten-api, nl.nl-portal:besluiten
eco: maven
published: Jul 8, 2026
## Impact

In versions up to and including 3.0.0, two parts of the GraphQL API returned data without checking whether the data belonged to the logged-in user:

– **Document content.** A logged-in user could download the raw content of any document by its ID, regardless of who owned it. The resolver …

CVE-2026-49463
GitHub-GHSA

MEDIUM
Waku: Cross-Origin CSRF on RSC Server Action Dispatch
GHSA-75w3-gmqx-993q
pkg: waku
eco: npm
published: Jul 8, 2026
## Summary

Waku's RSC request dispatcher invokes server actions without validating the request's `Origin` (or `Sec-Fetch-Site`) header. A cross-origin web attacker can therefore cause a victim browser to issue an authenticated `POST` to a registered server action endpoint using a CORS-safelisted co…

CVE-2026-49455
NVD

MEDIUM
CVE-2026-15154
CVE-2026-15154
pkg: express

published: Jul 8, 2026

A flaw was found in `guardrails-detectors`, a component of Red Hat OpenShift AI. This vulnerability, known as Regular Expression Denial of Service (ReDoS), allows a remote attacker to provide specially crafted regular expressions to the public detection API. This can cause catastrophic backtracking,…
CWE: CWE-1333
NVD

MEDIUM
CVE-2026-60001
CVE-2026-60001
pkg: openbsd openssh

published: Jul 8, 2026

sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.
CWE: CWE-770
GitHub-GHSA

MEDIUM
ha-mcp: Add-on settings and policy routes are reachable without authentication at the bare root path
GHSA-q855-8rh5-jfgq
pkg: ha-mcp
eco: pip
published: Jul 7, 2026
### Summary

In add-on mode, the ha-mcp settings UI routes are mounted both under the MCP secret path **and** at the bare root of the published port (`:9583`), so Home Assistant ingress can serve the "Open Web UI" button. The root-mounted routes perform no authentication — no secret, no `Origin` c…

NVD

MEDIUM
CVE-2026-55490
CVE-2026-55490
pkg: linux

published: Jul 7, 2026

OpenWrt is a Linux operating system targeting embedded devices. Before v25.12.5, an integer underflow in handle_send_a() of the Emergency Access Daemon allows any unauthenticated attacker on the local network to crash the daemon by sending a single crafted UDP packet. The message length underflows b…
CWE: CWE-191
GitHub-GHSA

MEDIUM
Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpoints
GHSA-f5vp-w269-392g
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

AI Bridge provider handlers read request bodies with `io.ReadAll` without a maximum size so an authenticated user with AI Bridge access could send an arbitrarily large body and exhaust memory.

> **Note:** Exploitation requires authenticated access to the AI Bridge endpoints and the imp…

CVE-2026-55434
GitHub-GHSA

MEDIUM
Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service
GHSA-2mg2-p7r7-g27f
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

`POST /api/v2/files` converts zip uploads to tar in memory via `CreateTarFromZip`, which enforced a per-entry size limit but no aggregate limit on total decompressed output, writing to an unbounded in-memory buffer.

> **Note:** Exploitation requires authenticated file-upload access and…

CVE-2026-55078
GitHub-GHSA

MEDIUM
WeasyPrint has CSS Injection via Presentational Hints
GHSA-jhhc-3hcp-qhm5
pkg: weasyprint
eco: pip
published: Jul 6, 2026
### Summary
A CSS injection issue exists in WeasyPrint when HTML presentational hints are enabled. Unescaped attribute values are embedded into CSS, allowing injection of arbitrary CSS declarations. This affects applications processing untrusted HTML input.

### Details
File: weasyprint/css/__init__…

CVE-2026-49452
GitHub-GHSA

MEDIUM
@better-auth/oauth-provider may provide access tokens for unauthorized audiences via unbound resource indicators
GHSA-p2fr-6hmx-4528
pkg: @better-auth/oauth-provider
eco: npm
published: Jul 7, 2026
### Am I affected?

Users are affected if all of the following hold:

– Their application depends on `@better-auth/oauth-provider` on any stable `1.6.x` release (the stable line is not patched) or on a pre-release before `1.7.0-beta.4`.
– Their application either configures validAudiences` with mor…

NVD

MEDIUM
CVE-2026-12154
CVE-2026-12154
pkg: go

published: Jul 6, 2026

The Reviews Widgets for Google, Yelp & TripAdvisor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_id' shortcode attribute of the [fbrev] shortcode in versions up to and including 2.7.3. This is due to insufficient input sanitization and output escaping in the Feed_Sh…
CWE: CWE-79
NVD

MEDIUM
CVE-2026-15063
CVE-2026-15063
pkg: go

published: Jul 8, 2026

A flaw was found in the gorch service template, which is part of the trustyai-service-operator. Even when authentication is enabled, the gorch service exposes unproxied orchestrator and detector metrics ports. This allows any pod on the cluster network to directly access these ports, bypassing the k…
CWE: CWE-306
NVD

MEDIUM
CVE-2026-15044
CVE-2026-15044
pkg: go

published: Jul 8, 2026

A flaw was found in the TrustyAI Service Operator. When deploying services like gorch or NemoGuardrails, if a specific security setting is not enabled, these services can expose their communication channels without requiring users to prove their identity. This allows any other program within the clu…
GitHub-GHSA

MEDIUM
install -D: symlink race in directory creation allows arbitrary file overwrite
GHSA-gwm6-q8ch-hcfr
pkg: uu_install
eco: rust
published: Jul 6, 2026
The `-D` path runs `fs::create_dir_all` on a pathname then later opens the destination via path-based `File::create`/`fs::copy`, neither anchored to a directory fd. Between the two, an attacker can replace a path component with a symlink, redirecting the write.

**Impact:** an attacker with concurre…

CVE-2026-35356
GitHub-GHSA

MEDIUM
install: TOCTOU symlink race (unlink-then-create without O_EXCL) allows arbitrary file overwrite
GHSA-239g-2685-54×3
pkg: uu_install
eco: rust
published: Jul 6, 2026
`copy_file` in `install/src/install.rs` removes the destination then recreates it by pathname via `File::create` / `fs::copy` without `O_EXCL`/`create_new`. Between the unlink and the recreate, a local attacker with write access to the destination directory can drop in a symlink and redirect the wri…
CVE-2026-35355
NVD

MEDIUM
CVE-2026-14784
CVE-2026-14784
pkg: docker

published: Jul 6, 2026

A vulnerability was identified in vxcontrol PentAGI up to 2.1.0. This affects an unknown function of the file backend/pkg/docker/client.go of the component Docker API. The manipulation leads to sandbox issue. The attack may be initiated remotely. The pull request to fix this issue awaits acceptance.
CWE: CWE-264, CWE-265
NVD

MEDIUM
CVE-2026-14716
CVE-2026-14716
pkg: go

published: Jul 5, 2026

A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.13.0-beta.2. Impacted is the function MethodRouter.Handle of the file internal/gateway/router.go of the component WebSocket RPC Handler. Such manipulation leads to incorrect authorization. The attack may be launched remote…
CWE: CWE-285, CWE-863
NVD

MEDIUM
CVE-2026-54778
CVE-2026-54778
pkg: windows

published: Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF UnixDomainSocket POSIX peer identity resolution uses non-reentrant getpwuid and getgrgid calls, allowing concurrent connections to attribute one connection's identity to an…
CWE: CWE-362, CWE-825
NVD

MEDIUM
CVE-2026-15128
CVE-2026-15128
pkg: google chrome

published: Jul 8, 2026

Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-79
NVD

MEDIUM
CVE-2026-15127
CVE-2026-15127
pkg: google chrome

published: Jul 8, 2026

Inappropriate implementation in WebGL in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-79
NVD

MEDIUM
CVE-2026-59929
CVE-2026-59929
pkg: mistune_project mistune

published: Jul 8, 2026

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the safe_url filter in src/mistune/renderers/html.py blocks only javascript:, vbscript:, file:, and data: schemes, allowing legacy or chained schemes such as feed:, view-source:, jar:, livescript:, mocha:, ms-its:, mk:, …
CWE: CWE-79, CWE-184
NVD

MEDIUM
CVE-2026-59926
CVE-2026-59926
pkg: mistune_project mistune

published: Jul 8, 2026

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, render_admonition() in src/mistune/directives/admonition.py concatenates the Admonition directive :class: option into the HTML class attribute without escaping, allowing attribute injection and cross-site scripting even …
CWE: CWE-79
NVD

MEDIUM
CVE-2026-59923
CVE-2026-59923
pkg: mistune_project mistune

published: Jul 8, 2026

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, HTMLRenderer.safe_url() does not block percent-encoded javascript URIs, allowing attacker-supplied Markdown links or images to bypass URL protections and execute script in rendered HTML. This issue is fixed in version 3.…
CWE: CWE-79
NVD

MEDIUM
CVE-2026-59890
CVE-2026-59890
pkg: python

published: Jul 8, 2026

setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compiled glob patterns against on-disk file names without Unicode …
CWE: CWE-176, CWE-697
GitHub-GHSA

MEDIUM
Kiwi TCMS has an Open Redirect via unvalidated next parameter in account confirmation endpoint
GHSA-hmj5-jm8h-h9fh
pkg: kiwitcms
eco: pip
published: Jul 6, 2026
### Summary

An open redirect vulnerability in the account confirmation endpoint allows an unauthenticated attacker to craft a URL hosted on a legitimate Kiwi TCMS instance that redirects victims to an arbitrary external domain. The attack surface is particularly relevant for phishing campaigns targ…

CVE-2026-54724
GitHub-GHSA

MEDIUM
GoBGP confederation validation panics on empty AS_PATH attribute
GHSA-frrj-87jh-2772
pkg: github.com/osrg/gobgp/v4
eco: go
published: Jul 9, 2026
Found through variant analysis based on `CVE-2026-41643`

## Summary
GoBGP accepts a zero-length AS_PATH during UPDATE decoding and later panics while validating that attribute for a confederation eBGP peer. The vulnerable path is in the BGP UPDATE validator: a malformed UPDATE that should be reject…

CVE-2026-49838
GitHub-GHSA

MEDIUM
GoBGP: BGP OPEN capability parser may read capability values outside declared CapLen boundaries
GHSA-gjrg-jjr3-56cm
pkg: github.com/osrg/gobgp/v4
eco: go
published: Jul 9, 2026
### Summary
GoBGP contains a BGP OPEN capability parsing issue where several concrete capability decoders may parse data from the full remaining capability buffer instead of the slice bounded by the declared capability length, `CapLen`.
A malformed BGP OPEN message can cause bytes from a fol…
CVE-2026-49837
GitHub-GHSA

MEDIUM
sigstore-go has a multi-log threshold bypass via single compromised log
GHSA-9vcr-p3rj-q5q6
pkg: github.com/sigstore/sigstore-go
eco: go
published: Jul 9, 2026
### Impact
_What kind of vulnerability is it? Who is impacted?_

A verifier configured with WithTransparencyLog(N>1) or WithSignedCertificateTimestamps(N>1) expected defense-in-depth against the compromise of a single log instance. However, threshold counting counted verified witnesses per-entry or …

CVE-2026-49834
NVD

MEDIUM
CVE-2026-57022
CVE-2026-57022
pkg: ssl

published: Jul 9, 2026

An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX with SPC3 and SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).

When an affected device initiates a TCP conne…

CWE: CWE-754
NVD

MEDIUM
CVE-2026-54779
CVE-2026-54779
pkg: windows

published: Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML token replay protection is inoperative because DefaultTokenReplayCache.TryAdd does not reject duplicate tokens when DetectReplayedTokens is enabled, allowing a capture…
CWE: CWE-294, CWE-613
NVD

MEDIUM
CVE-2026-54773
CVE-2026-54773
pkg: windows

published: Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF WS-Security signature verification performs a document-wide ds:Signature lookup, allowing an unauthenticated remote attacker to place a SOAP header before wsse:Security and…
CWE: CWE-347
NVD

MEDIUM
CVE-2026-54590
CVE-2026-54590
pkg: python

published: Jul 8, 2026

AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Version 2.23.0 contains an incomplete fix for CVE-2026-45309 in SSHServerConfig._set_tokens that blocks /, , and .. before %u substitution in Aut…
CWE: CWE-22, CWE-639
NVD

MEDIUM
CVE-2026-58501
CVE-2026-58501
pkg: python

published: Jul 8, 2026

Zeep is a Python SOAP client. From 4.0.0 before 4.3.3, Settings.forbid_external is defined but not enforced when parsing WSDL or XSD documents, allowing transitive xsd:import, xsd:include, wsdl:import, and lxml entity or DTD references to fetch attacker-chosen HTTP or HTTPS URLs. This issue is fixed…
CWE: CWE-918
NVD

MEDIUM
CVE-2026-59924
CVE-2026-59924
pkg: mistune_project mistune

published: Jul 8, 2026

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Include.parse() joins and normalizes user-supplied include paths without verifying that the result remains within the intended markdown directory, allowing crafted include paths to access files outside that directory whe…
CWE: CWE-22
NVD

MEDIUM
CVE-2026-59999
CVE-2026-59999
pkg: openbsd openssh

published: Jul 8, 2026

In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.
CWE: CWE-348
GitHub-GHSA

MEDIUM
Weblate SSRF: outbound URL guard misses some private ranges
GHSA-vmfc-9982-2m45
pkg: weblate
eco: pip
published: Jul 7, 2026
### Impact

Weblate's `VCS_RESTRICT_PRIVATE` did not properly account for some transitional IPv6 ranges, multicast addresses, or some semi-private IPv4 ranges, which allowed some addresses to bypass private range restrictions.

### Patches

* https://github.com/WeblateOrg/weblate/pull/19768

### Res…

CVE-2026-50127
GitHub-GHSA

MEDIUM
KEDA has PostgreSQL connection string parameter injection via incomplete whitespace escaping
GHSA-6w3m-4hhp-775q
pkg: github.com/kedacore/keda/v2
eco: go
published: Jul 7, 2026
### Summary
`pkg/scalers/postgresql_scaler.go` builds libpq-style connection strings by concatenating `key=value` pairs separated by spaces. Each tenant-controllable field (`host`, `port`, `userName`, `dbName`, `sslmode`) is passed through `escapePostgreConnectionParameter`:
“`go
func escapePostgre…
CVE-2026-53572
NVD

MEDIUM
CVE-2026-54291
CVE-2026-54291
pkg: postgresql postgresql_jdbc_driver

published: Jul 6, 2026

pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections can be silently downgraded from SCRAM-SHA-256-PLUS with channel binding to plain SCRAM-SHA-256 without it, losing the man-in-the-middle protection the setting is meant to guarantee…
CWE: CWE-636, CWE-757
GitHub-GHSA

MEDIUM
Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing
GHSA-5wg6-jmq2-53pw
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

Coder's subdomain-based workspace app proxy allowed the same-owner CORS check to be bypassed. When a workspace-name subdomain segment parsed as a UUID, the workspace was resolved by ID without confirming the URL's username matched the real owner, while the CORS middleware trusted the un…

CVE-2026-55438
GitHub-GHSA

MEDIUM
Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access
GHSA-5g4w-3vw9-478w
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

The workspace app proxy resolves the target app from `httpapi.RequestHost()` which prefers the `X-Forwarded-Host` header over the real `Host` header. No middleware strips `X-Forwarded-Host` before routing and the header is not browser-forbidden so client-side JavaScript can set it on `f…

CVE-2026-55430
GitHub-GHSA

MEDIUM
@aborruso/ckan-mcp-server: SSRF via base_url allows access to internal networks (Potential fix bypass of CVE-2026-33060)
GHSA-g84h-j7jj-x32p
pkg: @aborruso/ckan-mcp-server
eco: npm
published: Jul 7, 2026
### Summary
A known vulnerability CVE-2026-33060 indicated tools including ckan_package_search and sparql_query that accept a base_url parameter had the risk of making HTTP requests to arbitrary endpoints without restriction. A fix was applied to filter out ip addresses. However, a method to bypass …
CVE-2026-53509
GitHub-GHSA

MEDIUM
rm: 'rm -rf ./' (and ./// variants) silently deletes current directory contents, bypassing dot protection
GHSA-89p7-7cq3-hhr2
pkg: uu_rm
eco: rust
published: Jul 6, 2026
`rm -rf .` is correctly refused, but `clean_trailing_slashes` normalizes `.///` to `./` while `path_is_current_or_parent_directory` only matches `.`/`..` (and `/.`/`/..`), not `./` or `../`. So `rm -rf ./` recursively deletes the directory's contents and then prints a misleading `cannot remove './':…
CVE-2026-35363
NVD

MEDIUM
CVE-2026-14355
CVE-2026-14355
pkg: php php, debian debian_linux

published: Jul 3, 2026

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length withou…
CWE: CWE-122
NVD

MEDIUM
CVE-2026-44918
CVE-2026-44918
pkg: node

published: Jul 10, 2026

OpenStack Ironic through before 37.0.1 allows creation or modification of nodes cross-project without authorization.
CWE: CWE-862
NVD

MEDIUM
CVE-2026-15165
CVE-2026-15165
pkg: wireshark wireshark

published: Jul 8, 2026

TLS ECH decryptor crash in Wireshark 4.6.0 to 4.6.6 allows denial of service
CWE: CWE-122
GitHub-GHSA

MEDIUM
DSpace: Path Traversal is possible through LDN message generation
GHSA-9qm4-rh6w-pq5x
pkg: org.dspace:dspace-api, org.dspace:dspace-api, org.dspace:dspace-api
eco: maven
published: Jul 8, 2026
## Overview

A path traversal vulnerability is possible via the [COAR Notify / LDN](https://wiki.lyrasis.org/spaces/DSDOC9x/pages/379126679/COAR+Notify) service in DSpace. _This vulnerability impacts DSpace versions 8.0 <= 8.3, 9.0 <= 9.2._ The attacker MUST already have DSpace administrator creden…

CVE-2026-49833
GitHub-GHSA

MEDIUM
DSpace has a possible Path Traversal Vulnerability in its Curation Task Reporter output path
GHSA-v66x-68f2-pxf5
pkg: org.dspace:dspace-api, org.dspace:dspace-api, org.dspace:dspace-api
eco: maven
published: Jul 8, 2026
## Overview

The [Curation Task](https://wiki.lyrasis.org/spaces/DSDOC9x/pages/379126845/Curation+Tasks) feature allows an output path to be used by the reporter (`-r` parameter), typically used to stream results and status of curation task operations. It is not restricted to any particular base pat…

CVE-2026-49831
NVD

MEDIUM
CVE-2026-44512
CVE-2026-44512
pkg: node

published: Jul 8, 2026

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.9.0 before 1.22.0, onnx.version_converter.convert_version() can dereference a null pointer in Upsample_6_7::adapt_upsample_6_7() in onnx/version_converter/adapters/upsample_6_7.h when processing an …
CWE: CWE-476
NVD

MEDIUM
CVE-2026-58468
CVE-2026-58468
pkg: node

published: Jul 7, 2026

NocoBase through 2.1.20 contains a server-side request forgery vulnerability in the serverRequest wrapper that allows authenticated administrators to issue arbitrary outbound HTTP requests by supplying malicious URLs to workflow request nodes, custom request action buttons, or the AI plugin. Attacke…
CWE: CWE-918
GitHub-GHSA

MEDIUM
ONNX has Null Pointer Dereference in Upsample Version Converter Adapter (Zero Inputs)
GHSA-hwpq-hmq9-wj77
pkg: onnx
eco: pip
published: Jul 7, 2026
### Summary

Null pointer dereference (SIGSEGV) in `Upsample_6_7::adapt_upsample_6_7()` (`onnx/version_converter/adapters/upsample_6_7.h:31`) when `convert_version()` processes a model with an Upsample node that has zero inputs. The adapter accesses `node->inputs()[0]->sizes()` without checking inpu…

CVE-2026-44512
NVD

MEDIUM
CVE-2026-50135
CVE-2026-50135
pkg: gohugo hugo

published: Jul 6, 2026

Hugo is a static site generator. From 0.123.0 to 0.161.1, a regression made  RootMappingFs.statRoot  use  Stat  (follows symlinks) instead of  Lstat , so a direct  resources.Get  of a symlink pointing outside its mount returned the target's contents — letting a symlink planted in a local m…
CWE: CWE-59
NVD

MEDIUM
CVE-2026-44362
CVE-2026-44362
pkg: trustedfirmware op-tee

published: Jul 6, 2026

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.20.0 and prior to version 4.11.0, a vulnerability in OP-TEE’s subkey rollback protection allows the use of revoked…
CWE: CWE-285
GitHub-GHSA

MEDIUM
kill: 'kill -1' parsed as PID -1, sending SIGTERM to all processes (system crash / DoS)
GHSA-p6rv-2qpm-fwvg
pkg: uu_kill
eco: rust
published: Jul 6, 2026
`kill -1` is incorrectly parsed as a positional `pid = -1`; combined with the default SIGTERM this calls `kill(-1, SIGTERM)`, signaling nearly every process the caller can see. GNU `kill` recognizes `-1`/`-9` as signals and reports "not enough arguments".

“`
$ kill -1 # uutils: kill(-1, SIG…

CVE-2026-35369
GitHub-GHSA

MEDIUM
chmod: recursive mode returns exit code 0 even when some files fail (last-file-wins)
GHSA-4×34-chg5-mwjj
pkg: uu_chmod
eco: rust
published: Jul 6, 2026
In `Chmoder::chmod()` the recursive branch overwrites the running result instead of accumulating it, so the exit code reflects only the *last* file processed:

“`
if self.recursive {
r = self.walk_dir_with_context(file, true); // overwrites r
} else {
r = self.chmod_file(file).and(r);
}
`…

CVE-2026-35339
NVD

MEDIUM
CVE-2026-40257
CVE-2026-40257
pkg: trustedfirmware op-tee

published: Jul 6, 2026

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.21.0 and prior to version 4.11.0, the ARM Crypto Extensions accelerated SHA-3 implementation has an off-by-one error…
CWE: CWE-787
GitHub-GHSA

MEDIUM
Rattler vulnerable to package cache path traversal via conda package build string
GHSA-h672-p7h7-97v9
pkg: rattler_cache, py_rattler
eco: pip
published: Jul 9, 2026
`rattler_cache` and `py-rattler` were vulnerable to package-cache path traversal when handling package metadata from conda channels.

During cache materialization, the `ratter_cache` code used the package record `build` string as part of a cache key that was joined into a filesystem path. A maliciou…

CVE-2026-53956
NVD

MEDIUM
CVE-2026-60120
CVE-2026-60120
pkg: vue

published: Jul 9, 2026

Bagisto before 2.4.4 contains a stored cross-site scripting vulnerability via client-side template injection that allows unauthenticated attackers to execute arbitrary JavaScript in administrator browsers by registering a customer account with malicious payload in the first or last name field. The c…
CWE: CWE-79
NVD

MEDIUM
CVE-2026-5005
CVE-2026-5005
pkg: go

published: Jul 9, 2026

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Twiser Informatics Technology Consulting, Trade and Education Inc. OKRs & Goals allows Stored XSS.

This issue affects OKRs & Goals: from 28220 before 28398.

CWE: CWE-79
NVD

MEDIUM
CVE-2026-56359
CVE-2026-56359
pkg: n8n n8n

published: Jul 8, 2026

n8n before 2.8.0 contains a cross-site scripting vulnerability in the credential management flow where authenticated users can inject malicious JavaScript URLs into OAuth2 credential Authorization URL fields. Attackers can craft malicious credentials and trick victims into clicking the OAuth authori…
CWE: CWE-79
GitHub-GHSA

MEDIUM
Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component
GHSA-7qw2-f75v-62f7
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

The `AgentLogLine` dashboard component instantiated `ansi-to-html` without `escapeXML: true` and inserted the result via `dangerouslySetInnerHTML` so HTML embedded in workspace agent log lines was rendered as live markup. Server-side sanitization did not neutralize HTML metacharacters.

CVE-2026-55437
GitHub-GHSA

MEDIUM
Suspended Coder users retain access to AI Bridge LLM proxy endpoints
GHSA-wqxv-w64v-5wh6
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

AI Bridge proxy endpoints authenticate via `Server.IsAuthorized` in `coderd/aibridgedserver`, which validates key format, expiry, secret and deleted or system users but does not check whether the account is suspended. Because suspension does not revoke existing API keys, a suspended use…

CVE-2026-55435
GitHub-GHSA

MEDIUM
Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers
GHSA-jqj2-x4c5-jfxm
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

The devcontainer recreate endpoint relied on route middleware that checked only `ActionRead` on the workspace and, unlike the sibling delete endpoint, performed no `ActionUpdate` check before triggering the destructive rebuild.

> **Note:** Exploitation requires an existing low-privileg…

CVE-2026-55433
GitHub-GHSA

MEDIUM
Coder's sub-agent app registration bypasses template port-sharing policy enforcement
GHSA-x9qq-2qh5-8rxf
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

The `CreateSubAgent` RPC did not validate a requested app sharing level against the template's `MaxPortSharingLevel` before persisting workspace apps, letting a workspace owner exceed the administrator's configured maximum.

> **Note:** Exploitation requires the ability to register sub-…

CVE-2026-55432
NVD

MEDIUM
CVE-2026-44342
CVE-2026-44342
pkg: oauth

published: Jul 9, 2026

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0-alpha.1, the email and WeChat account binding endpoints GET /api/oauth/email/bind and GET /api/oauth/wechat/bind used GET requests for state-changing account operations, allowing …
CWE: CWE-352
NVD

MEDIUM
CVE-2026-59817
CVE-2026-59817
pkg: node

published: Jul 9, 2026

Ghost is a Node.js content management system. From 6.27.0 before 6.44.0, Ghost's public donation checkout flow allowed an unauthenticated attacker to control donation checkout metadata and obtain full paid gift memberships for a minimal payment without exposing customer or member data or stealing mo…
CWE: CWE-472, CWE-639
GitHub-GHSA

MEDIUM
Note Mark: Unauthenticated disclosure of soft-deleted note metadata via deleted=true on public books
GHSA-588f-fvcv-xhvf
pkg: github.com/enchant97/note-mark/backend
eco: go
published: Jul 9, 2026
Summary

GET /api/books/{bookID}/notes is an unauthenticated endpoint that accepts a "deleted" query parameter. When the request is ?deleted=true, the
service runs the query with Unscoped() (bypassing GORM's soft-delete scope) but keeps the read-authorization clause as "owner_id = ? OR is_public…

CVE-2026-50554
NVD

MEDIUM
CVE-2026-9027
CVE-2026-9027
pkg: go

published: Jul 9, 2026

The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Payment Bypass via Improper Verification of Cryptographic Signature in all versions up to, and including, 2.7.4. The `corvuspay_success_handler` function registers the REST endpoint `POST /wp-json/corvuspay/success/` wit…
CWE: CWE-347
GitHub-GHSA

MEDIUM
Trapster Community: Unauthenticated malformed DNS compression pointers crash per-packet honeypot handler
GHSA-mxwc-wh95-pw4g
pkg: trapster
eco: pip
published: Jul 8, 2026
## Summary

`trapster.libs.dns.decode_labels()` decodes DNS names from attacker-supplied UDP packets and recurses **once per RFC 1035 compression pointer** with **no cycle detection and no depth bound**. A single unauthenticated UDP datagram sent to the DNS honeypot drives the function past CPython'…

NVD

MEDIUM
CVE-2026-45045
CVE-2026-45045
pkg: express

published: Jul 8, 2026

Fiber is an Express inspired web framework written in Go. Prior to 3.3.0 and 2.52.14, the BalancerForward proxy helper in middleware/proxy/proxy.go uses Header.Add() instead of Header.Set() when injecting X-Real-IP, allowing an attacker-supplied first X-Real-IP value to be forwarded to upstream serv…
CWE: CWE-290
NVD

MEDIUM
CVE-2026-44332
CVE-2026-44332
pkg: express

published: Jul 8, 2026

Fiber is an Express inspired web framework written in Go. Prior to 3.3.0, the default Authorizer function in the BasicAuth middleware in middleware/basicauth/config.go uses short-circuit evaluation that skips password hash comparison for non-existent usernames, enabling reliable remote username enum…
CWE: CWE-203
NVD

MEDIUM
CVE-2026-59927
CVE-2026-59927
pkg: mistune_project mistune

published: Jul 8, 2026

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the Include directive in src/mistune/directives/include.py detects only direct self-includes and not indirect cycles, allowing two markdown files that include each other to trigger unbounded recursion, raise RecursionErr…
CWE: CWE-674, CWE-755, CWE-674
NVD

MEDIUM
CVE-2026-59875
CVE-2026-59875
pkg: node

published: Jul 8, 2026

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.17, node-tar does not strip NUL bytes from PAX path and linkpath records in src/pax.ts, allowing a crafted archive with values to reach fs.lstat or fs.open and terminate the process with an uncaught exception. This issue is fix…
CWE: CWE-248
NVD

MEDIUM
CVE-2026-59871
CVE-2026-59871
pkg: node

published: Jul 8, 2026

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, node-tar coerces all-digit PAX path and linkpath values in src/pax.ts to JavaScript numbers, causing downstream path handling such as normalizeWindowsPath(entry.path).split('/') to throw an uncaught TypeError. This issue is…
CWE: CWE-704
GitHub-GHSA

MEDIUM
New API is vulnerable to CSRF through user email binding
GHSA-26v7-h57m-gh9m
pkg: github.com/QuantumNous/new-api
eco: go
published: Jul 7, 2026
## Summary

The email and WeChat account binding endpoints used GET requests for state-changing account operations. In deployments where session cookies could be sent on cross-site navigations, an attacker could trigger a logged-in user's browser to bind an attacker-controlled email address or OAuth…

CVE-2026-44342
NVD

MEDIUM
CVE-2026-14631
CVE-2026-14631
pkg: webpack.js webpack-dev-server

published: Jul 3, 2026

webpack-dev-server versions 5.2.5 and earlier terminate the whole Node.js process when an unauthenticated peer sends either a normal HTTP request with a malformed Host header or a WebSocket upgrade to the default /ws endpoint with a malformed Origin header. The malformed value causes an uncaught exc…
CWE: CWE-20, CWE-248
GitHub-GHSA

MEDIUM
pyLoad: SSRF guard bypass via IPv6 6to4/NAT64 transition wrappers of internal IPs
GHSA-m5x5-28jr-gpjj
pkg: pyload-ng
eco: pip
published: Jul 9, 2026
## Summary

`is_global_address` in [`src/pyload/core/utils/web/check.py`](https://github.com/pyload/pyload/blob/1b12dc7f348db8c144e0f39215680415e90ca4d2/src/pyload/core/utils/web/check.py) is the central guard against SSRF-style outbound connections in pyload-ng. It tests whether a given IP is "glob…

CVE-2026-48737
NVD

MEDIUM
CVE-2026-14362
CVE-2026-14362
pkg: node

published: Jul 8, 2026

HashiCorp memberlist before version 0.6.0 is vulnerable to a denial-of-service issue in its push/pull state handling that may allow an attacker with network access to the gossip port to exhaust memory on a receiving node and cause the process to terminate. This vulnerability (CVE-2026-14362) is fixe…
CWE: CWE-770
GitHub-GHSA

MEDIUM
Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service
GHSA-f962-qm93-mj4c
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

`NewDataBuilder` in `provisionersdk/proto/dataupload.go` allocated a byte slice using the client-supplied `FileSize` from a `DataUpload` message without an upper-bound check. Although the DRPC wire limit is 4 MiB, the `FileSize` value itself was unconstrained

### Impact

An authenticat…

CVE-2026-55079
NVD

MEDIUM
CVE-2026-53624
CVE-2026-53624
pkg: express

published: Jul 8, 2026

Fiber is an Express inspired web framework written in Go. Prior to 3.4.0, the helmet middleware in middleware/helmet/helmet.go never sets the Strict-Transport-Security response header even when HSTSMaxAge is configured because it checks c.Protocol() for https instead of c.Scheme(). This issue is fix…
CWE: CWE-319
NVD

MEDIUM
CVE-2026-59998
CVE-2026-59998
pkg: openbsd openssh

published: Jul 8, 2026

sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.
CWE: CWE-573
GitHub-GHSA

MEDIUM
GoFiber never set HSTS header in helmet middleware due to incorrect protocol check
GHSA-gv83-gqw6-9j2c
pkg: github.com/gofiber/fiber
eco: go
published: Jul 6, 2026
### Summary

The `helmet` middleware in gofiber/fiber never sets the `Strict-Transport-Security` (HSTS) response header, even when `HSTSMaxAge` is explicitly configured, because the condition check at `helmet.go:67` uses `c.Protocol()` — which returns the HTTP protocol version string (e.g., `"HTTP…

CVE-2026-53624
NVD

MEDIUM
CVE-2026-14620
CVE-2026-14620
pkg: webpack.js webpack-dev-server

published: Jul 3, 2026

webpack-dev-server versions 5.2.5 and earlier expose two internal developer endpoints, /webpack-dev-server/open-editor and /webpack-dev-server/invalidate, that perform state-changing actions on any GET request without verifying that the request originated from the dev server's own page. Any website …
CWE: CWE-352, CWE-749
NVD

MEDIUM
CVE-2026-46672
CVE-2026-46672
pkg: go

published: Jul 7, 2026

Actual is a local-first personal finance app. Prior to 26.6.0, @actual-app/cli ships a hand-rolled CSV serializer in packages/cli/src/output.ts used whenever the global –format csv option is passed, whose escapeCsv helper only handles RFC 4180 delimiter, quote, and newline escaping and does not neu…
CWE: CWE-1236
NVD

MEDIUM
CVE-2026-55798
CVE-2026-55798
pkg: python pillow

published: Jul 6, 2026

Pillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get_command() constructed a cmd.exe shell command by directly embedding a file path into an f-string without escaping and passed the result to subprocess.Popen(…, shell=True), allowing shell metacharacters in the file path to injec…
CWE: CWE-78
NVD

MEDIUM
CVE-2026-54776
CVE-2026-54776
pkg: windows

published: Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, a CoreWCF service hosted on Unix Domain Sockets with PosixIdentity client credentials can accept connections that skip the application/unixposix stream upgrade before dispatching m…
CWE: CWE-306
GitHub-GHSA

MEDIUM
DSpace: ORE resource URI does not validate scheme for non-web resources
GHSA-c827-pw3m-67w7
pkg: org.dspace:dspace-api, org.dspace:dspace-api, org.dspace:dspace-api
eco: maven
published: Jul 8, 2026
## Overview

When ingesting an aggregated ORE resource by URI (using the [OAI-ORE Harvester](https://wiki.lyrasis.org/spaces/DSDOC9x/pages/379125906/OAI#OAI-OAI-PMH/OAI-OREHarvester(Client))), the ORE Ingestion Crosswalk does not validate the URI scheme. This may allow for local file inclusion via m…

CVE-2026-49830
GitHub-GHSA

MEDIUM
printenv: environment variables with invalid UTF-8 are silently skipped (evades inspection)
GHSA-p7h3-7q52-72w8
pkg: uu_printenv
eco: rust
published: Jul 6, 2026
The printenv utility in uutils coreutils fails to display environment variables containing invalid UTF-8 byte sequences. While POSIX permits arbitrary bytes in environment strings, the uutils implementation silently skips these entries rather than printing the raw bytes. This vulnerability allows ma…
CVE-2026-35366
GitHub-GHSA

MEDIUM
cp: -R reads device nodes as streams, destroying device semantics
GHSA-8vrf-r662-2w2v
pkg: uu_cp
eco: rust
published: Jul 6, 2026
The cp utility in uutils coreutils, when performing recursive copies (-R), incorrectly treats character and block device nodes as stream sources rather than preserving them. Because the implementation reads bytes into regular files at the destination instead of using mknod, device semantics are dest…
CVE-2026-35358
GitHub-GHSA

MEDIUM
comm: FIFO/pipe inputs are drained before comparison (data loss / hang)
GHSA-3wfc-mgpm-9rq6
pkg: uu_comm
eco: rust
published: Jul 6, 2026
The comm utility in uutils coreutils incorrectly consumes data from non-regular file inputs before performing comparison operations. The are_files_identical function opens and reads from both input paths to compare content without first verifying if the paths refer to regular files. If an input path…
CVE-2026-35347
GitHub-GHSA

MEDIUM
id: groups= computed from real GID instead of effective GID
GHSA-47c7-qrm7-mqw7
pkg: uu_id
eco: rust
published: Jul 6, 2026
The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and automated processes rely…
CVE-2026-35370
NVD

MEDIUM
CVE-2026-6440
CVE-2026-6440
pkg: oauth

published: Jul 10, 2026

The GoodMeet – Google Meet Integration for Webinar, Meeting & Video Conference plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.1.8. This is due to a missing nonce verification in the reset_credential() function, which handles the wp_ajax_goodmeet_…
CWE: CWE-352
NVD

MEDIUM
CVE-2026-4298
CVE-2026-4298
pkg: go

published: Jul 9, 2026

The DSGVO All in one for WP plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 4.9. This is due to the dsgvo_reset_policy_service_func() function lacking both capability checks and nonce verification while processing user-supplied parameters to reset plug…
CWE: CWE-862
NVD

MEDIUM
CVE-2026-15131
CVE-2026-15131
pkg: google chrome

published: Jul 8, 2026

Inappropriate implementation in Navigation in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-20
NVD

MEDIUM
CVE-2026-15130
CVE-2026-15130
pkg: google chrome

published: Jul 8, 2026

Insufficient policy enforcement in Navigation in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-602
NVD

MEDIUM
CVE-2026-15124
CVE-2026-15124
pkg: google chrome

published: Jul 8, 2026

Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-20
NVD

MEDIUM
CVE-2026-15108
CVE-2026-15108
pkg: google chrome

published: Jul 8, 2026

Integer overflow in Extensions API in Google Chrome prior to 150.0.7871.115 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory read via a crafted Chrome Extension. (Chromium security severity: High)
CWE: CWE-190
NVD

MEDIUM
CVE-2026-59930
CVE-2026-59930
pkg: mistune_project mistune

published: Jul 8, 2026

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the toc plugin and TableOfContents directive generate heading IDs as predictable toc_N values without slugifying the heading text, allowing attacker-controlled id="toc_N" content to collide with generated anchors and red…
CWE: CWE-345, CWE-1284
GitHub-GHSA

MEDIUM
Kite has an authenticated cluster RBAC bypass in /api/v1/overview
GHSA-gvhc-wv3v-7pf8
pkg: github.com/zxh326/kite
eco: go
published: Jul 7, 2026
## Summary

Authenticated Kite users with any role can request `/api/v1/overview` for a cluster that their roles do not permit by selecting that cluster with `x-cluster-name`. The overview route is registered before `middleware.RBACMiddleware()` and `GetOverview` only checks `len(user.Roles) > 0`, s…

CVE-2026-53487
NVD

MEDIUM
CVE-2026-46700
CVE-2026-46700
pkg: go

published: Jul 7, 2026

Actual is a local-first personal finance tool. Prior to 26.6.0, the GET /secret/:name endpoint in @actual-app/sync-server checks only that the caller has a valid session and does not verify the caller is an admin, while the sibling POST /secret/ handler enforces an admin check in OpenID mode. Any au…
CWE: CWE-285
GitHub-GHSA

MEDIUM
Open WebUI has Blind Server Side Request Forgery in its Image Edit Functionality
GHSA-jgx9-jr5x-mvpv
pkg: open-webui
eco: pip
published: Jul 7, 2026
### Summary
There is a blind server side request forgery in the functionality that allows editing an image via a prompt. The affected function will perform a GET request on the URL provided by the user. There is no restriction on the domain of the provided URL allowing the local address space to be …
CVE-2026-34225
GitHub-GHSA

MEDIUM
OpenRemote read-only asset users can write predicted datapoints
GHSA-xj53-j257-hxvg
pkg: io.openremote:openremote-manager
eco: maven
published: Jul 6, 2026
# Summary

The predicted datapoint write endpoint allows users with only `read:assets` privileges to write predicted datapoints.

The endpoint:

“`text
PUT /api/{realm}/asset/predicted/{assetId}/{attributeName}
“`

accepts write requests from users lacking `write:assets`.

The implementation appea…

CVE-2026-49439
NVD

MEDIUM
CVE-2026-59997
CVE-2026-59997
pkg: openbsd openssh

published: Jul 8, 2026

internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.
CWE: CWE-1284
NVD

MEDIUM
CVE-2026-59996
CVE-2026-59996
pkg: openbsd openssh

published: Jul 8, 2026

scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.
CWE: CWE-23
NVD

MEDIUM
CVE-2026-59995
CVE-2026-59995
pkg: openbsd openssh

published: Jul 8, 2026

sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.
CWE: CWE-23
NVD

MEDIUM
CVE-2026-50179
CVE-2026-50179
pkg: go

published: Jul 7, 2026

Actual is a local-first personal finance tool. Prior to 26.6.0, exportToCSV and exportQueryToCSV in packages/loot-core/src/server/transactions/export/export-to-csv.ts pass user-controlled Payee, Notes, Account, and Category strings to csv-stringify with no cast callback and no formula-prefix neutral…
CWE: CWE-1236
NVD

MEDIUM
CVE-2026-14612
CVE-2026-14612
pkg: oauth

published: Jul 3, 2026

Two off-by-one errors in the FreeIPA ipa-otpd daemon's OAuth2 device authorization handler can cause out-of-bounds memory access when processing an oversized response from a configured external OAuth2/OIDC Identity Provider. An attacker who controls or can man-in-the-middle the IdP endpoint may be a…
CWE: CWE-787
NVD

MEDIUM
CVE-2026-56360
CVE-2026-56360
pkg: n8n n8n

published: Jul 8, 2026

n8n before versions 1.123.18 and 2.6.2 fails to verify HMAC-SHA256 signatures on Zendesk webhooks in the ZendeskTrigger node. Attackers who know the webhook URL can send unsigned POST requests to trigger workflows with arbitrary malicious data.
CWE: CWE-290
GitHub-GHSA

MEDIUM
psd-tools vulnerable to arbitrary file write via smart-object filename
GHSA-2rmg-vrx8-9j2f
pkg: psd-tools
eco: pip
published: Jul 9, 2026
# psd-tools: arbitrary file write/read via smart-object path traversal

## Summary

In `psd-tools` (all releases exposing the `SmartObject` API through **v1.17.0**), `SmartObject.save()` writes an embedded smart object to a path taken verbatim from the PSD file. Because that name is attacker-control…

CVE-2026-49836
GitHub-GHSA

MEDIUM
OpenRun: Redirect URL validation bypass using  //host  paths leads to Open Redirect
GHSA-h5g6-xmh4-hc37
pkg: github.com/openrundev/openrun
eco: go
published: Jul 9, 2026
### Summary
The restrictions on redirect URLs in `openrun` can be bypassed by attackers, leading to open redirect attacks.

### Details

In the current project, the referrer header value is used for subsequent redirects, so there is currently a validation for this redirect value. The current validat…

CVE-2026-55252
GitHub-GHSA

MEDIUM
pypdf: Possible infinite loop when processing threads/articles in writer
GHSA-g9xf-7f8q-9mcj
pkg: pypdf
eco: pip
published: Jul 9, 2026
### Impact

An attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires merging a file with threads/articles into a writer.

### Patches

This has been fixed in [pypdf==6.13.1](https://github.com/py-pdf/pypdf/releases/tag/6.13.1).

### Workarounds

If users…

CVE-2026-54651
GitHub-GHSA

MEDIUM
nebula-mesh: Host revocation is not durable – blocked/offboarded hosts can regain a valid certificate
GHSA-339v-266x-79xr
pkg: github.com/forgekeep/nebula-mesh
eco: go
published: Jul 9, 2026
## Summary

Two related authorization gaps let a host that should no longer be trusted obtain a fresh, valid Nebula certificate, because nebula-mgmt does not re-evaluate revocation/authorization state at certificate *issuance* time — only at poll time.

## 1. Blocklist not enforced at sign / re-en…

CVE-2026-53602
GitHub-GHSA

MEDIUM
pymonocypher: Potential heap buffer overflow on nb_blocks in argon2i_32 when provided buffer is too small
GHSA-8f95-v3jq-cj86
pkg: pymonocypher
eco: pip
published: Jul 9, 2026
### Impact
The argon2i_32 implementation does not check the nb_blocks size. If the caller does not provide a sufficiently large buffer based on the API contract, then argon2i_32 will write past the end of the buffer and possibly corrupt the heap.

### Patches
Fixed in 4.0.2.8, which now verifies th…

CVE-2026-53720
GitHub-GHSA

MEDIUM
OneRingBuf has a Use After Free Vulnerability
GHSA-q95x-7g78-rccv
pkg: oneringbuf
eco: rust
published: Jul 8, 2026
Affected versions of `oneringbuf` exposed the obsolete `IntoRef::into_ref` method through the public `IntoRef` trait. For heap-backed ring buffers, this method returned a `DroppableRef` handle.

`DroppableRef` stored an owning raw pointer created from `Box::into_raw`. Its `Clone` implementation copi…

GitHub-GHSA

MEDIUM
async-tar PAX extension-header desync enables tar entry/content smuggling
GHSA-35rm-7j9c-2f7m
pkg: async-tar
eco: rust
published: Jul 8, 2026
## Summary

`async-tar` v0.6.0 mis-applies a buffered PAX `size` extension to an intermediary
extension header (a GNU longname `L`, a GNU longlink `K`, or a PAX `x`/`g`
header) instead of to the next *file* entry. POSIX requires a PAX extended-header
record set to describe the next file entry, never…

CVE-2026-53600
GitHub-GHSA

MEDIUM
oasdiff does not enforce –allow-external-refs=false on the git-revision load path (SSRF / local file read)
GHSA-2jcc-mxv7-p3f9
pkg: github.com/oasdiff/oasdiff
eco: go
published: Jul 7, 2026
## Summary

From **v1.13.2** through **v1.18.0**, oasdiff did not enforce `–allow-external-refs=false` (library: `openapi3.Loader.IsExternalRefsAllowed = false`) when loading a spec from a **git revision** (the `rev:path` form, e.g. `main:openapi.yaml`). External `$ref`s were resolved on that load …

CVE-2026-53508
GitHub-GHSA

MEDIUM
Flask-Security-Too: WebAuthn reauthentication freshness bypass via cross-user assertion
GHSA-f66q-9rf6-8795
pkg: Flask-Security-Too
eco: pip
published: Jul 7, 2026
### Summary

Flask-Security-Too 5.8.0 and 5.8.1 mark a session as reauthentication-fresh after processing a WebAuthn assertion whose proven credential belongs to a different user than the currently authenticated session user. The check that `GHSA-97r5-pg8x-p63p` added on the OAuth reauthentication p…

GitHub-GHSA

MEDIUM
aiosmtplib vulnerable to SMTP command injection via CR/LF in sender/recipient address
GHSA-v3q9-hj7j-63hq
pkg: aiosmtplib
eco: pip
published: Jul 7, 2026
### Summary

`aiosmtplib`'s `SMTP.mail()`, `SMTP.rcpt()`, `SMTP.vrfy()` and `SMTP.expn()` send the caller-supplied email address to the server without rejecting embedded CR/LF (`\r\n`) bytes. An address that contains a CR/LF is written verbatim onto the SMTP control connection, so the bytes after th…

CVE-2026-53533
GitHub-GHSA

MEDIUM
ratex-parser has unbounded parser recursion that leads to stack overflow (process abort)
GHSA-4w5h-hx6r-28q7
pkg: ratex-parser
eco: rust
published: Jul 7, 2026
### Summary

RaTeX’s recursive-descent parser recurses one (or more) native stack frame per nesting level at `{`, `\left`, `\sqrt{`, `^{`, etc, with **no maximum depth limit**. A short, ~10 KB input of nested groups overflows the 8 MB main-thread stack and aborts the process. With `panic = "abort…

CVE-2026-53531
GitHub-GHSA

MEDIUM
netfoil has a domain name filter bypass via multiple questions
GHSA-59qp-cfj3-rp64
pkg: github.com/tinfoil-factory/netfoil
eco: go
published: Jul 7, 2026
### Summary
Potential bypass of domain name filter by crafting a DNS request with multiple questions, with the first question being legitimate.

### Impact
Depends on a local attackers ability to craft multiple questions and the remote DoH server supporting them.

GitHub-GHSA

MEDIUM
Open WebUI allows limited stored XSS vila uploaded html file
GHSA-8gh5-qqh8-hq3x
pkg: open-webui
eco: pip
published: Jul 7, 2026
### Summary
Low privileged users can upload HTML files which contain JavaScript code via the `/api/v1/files/` backend endpoint. This endpoint returns a file id, which can be used to open the file in the browser and trigger the JavaScript code in the user's browser. Under the default settings, files …
CVE-2025-46571
GitHub-GHSA

MEDIUM
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile
GHSA-chwm-m7g7-685g
pkg: d7y.io/dragonfly/v2
eco: go
published: Jul 6, 2026
## Summary

The Dragonfly **scheduler**'s v1 gRPC service contains an unauthenticated Server-Side Request Forgery (SSRF). When a peer reports a successful download of a TINY task, the scheduler calls `Peer.DownloadTinyFile()` and issues an HTTP `GET` to a host and port taken verbatim from the attack…

CVE-2026-54637