Vulnerability Digest — August 31, 2026 · 73 Critical · 10 Exploited






Vulnerability Digest — Monday, August 31, 2026


Security Report

Monday, August 31, 2026  ·  Last 7 days  ·  Min severity: MEDIUM
Total Findings
456
Critical
73
High
239
Actively Exploited
10
CISA-KEV10
NVD293
GitHub-GHSA153
Findings sorted by severity
CISA-KEV

CRITICAL
ownCloud Improper Authentication Vulnerability
CVE-2023-49105
pkg: ownCloud ownCloud

published: Aug 27, 2026

ownCloud contains an improper authentication vulnerability that allows an attacker to access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Linux Kernel Unspecified Vulnerability
CVE-2026-53362
pkg: Linux Kernel

published: Aug 27, 2026

Linux Kernel contains an unspecified vulnerability that can allow for privilege escalation via IPv6 networking subsystem. This vulnerability can impact multiple products, including but not limited to Suse, Red Hat, and other products using Linux.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
CVE-2026-66384
pkg: JFrog Artifactory

published: Aug 27, 2026

JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2019-1068
pkg: Microsoft SQL Server

published: Aug 26, 2026

Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Red Hat Libuser Race Condition Vulnerability
CVE-2015-3246
pkg: Red Hat Libuser

published: Aug 26, 2026

Red Hat libuser contains a race condition vulnerability that allows authenticated local users to corrupt the /etc/passwd file to cause a denial of service or privilege escalation.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
CVE-2015-5287
pkg: Red Hat Automatic Bug Reporting Tool

published: Aug 26, 2026

Red Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). U…
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Linux Kernel Out-of-Bounds Write Vulnerability
CVE-2022-0995
pkg: Linux Kernel

published: Aug 26, 2026

Linux Kernel contains an out-of-bounds memory write vulnerability which could allow a local user to gain privileged access or cause a denial of service on the system.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
CVE-2026-8452
pkg: Citrix NetScaler ADC and NetScaler Gateway

published: Aug 26, 2026

Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability which could lead to denial of service.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
CVE-2021-23758
pkg: Ajax.NET Professional Ajax.NET Professional

published: Aug 26, 2026

Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to …
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Gitea Code Injection Vulnerability
CVE-2026-60004
pkg: Gitea Gitea

published: Aug 25, 2026

Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
NVD

CRITICAL
CVE-2026-54745
CVE-2026-54745
pkg: kubernetes

published: Aug 28, 2026

Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0, the Kubeflow Pipelines frontend exposes an unauthenticated server-side request forgery vulnerability through the /_proxy/ route in frontend/server/proxy-middleware.ts. The _routePathW…
CWE: CWE-284, CWE-918
NVD

CRITICAL
CVE-2026-81096
CVE-2026-81096
pkg: python

published: Aug 27, 2026

ToolUniverse ran caller-supplied Python inside a sandbox that could be escaped, on a server that required no authentication. The executor behind the python_code_executor tool, in python_executor_tool.py, inspected the submitted source for a denied list of attribute names and calls but left the attri…
CWE: CWE-94
NVD

CRITICAL
CVE-2026-55565
CVE-2026-55565
pkg: express

published: Aug 28, 2026

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs LikeExpression.fillCode_getValueReturn in yamcs-core/src/main/java/org/yamcs/yarch/streamsql/LikeExpression.java inserts an unescaped LIKE pattern into Java source compiled by Expression.getCompiledExpression through SimpleCompi…
CWE: CWE-94
GitHub-GHSA

CRITICAL
Yamcs vulnerable to authenticated remote code execution via unescaped StreamSQL `LIKE` pattern compiled by Janino (`LikeExpression`)
GHSA-c64q-hj4j-375f
pkg: org.yamcs:yamcs-core, org.yamcs:yamcs-core
eco: maven
published: Aug 28, 2026
## Summary
Yamcs compiles StreamSQL query expressions to Java at runtime with Janino. The `LIKE` operator inserts the user-supplied pattern into the generated Java **unescaped**, inside a `"…"` literal, so a pattern containing `"` breaks out and injects arbitrary Java (e.g. a `static{}` block that…
CVE-2026-55565
NVD

CRITICAL
CVE-2026-65093
CVE-2026-65093
pkg: linux

published: Aug 25, 2026

NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
CWE: CWE-427
NVD

CRITICAL
CVE-2026-65083
CVE-2026-65083
pkg: linux

published: Aug 25, 2026

NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of disallowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, data tampering, and d…
CWE: CWE-184
GitHub-GHSA

CRITICAL
Yamcs vulnerable to Remote Code Execution via instance-template argument YAML injection (createInstance)
GHSA-73mf-m39p-wpm9
pkg: org.yamcs:yamcs-core, org.yamcs:yamcs-core
eco: maven
published: Aug 28, 2026
### Summary

`templateArgs` sent to `POST /api/instances` (and `PATCH /api/instances/{instance}`) are written into the rendered instance config as raw text, then parsed as YAML and loaded. Yamcs instantiates each `services:` entry by its `class:`, so injecting YAML through a template arg lets you ad…

CVE-2026-55559
NVD

CRITICAL
CVE-2026-80714
CVE-2026-80714
pkg: node

published: Aug 28, 2026

In the Linux kernel, the following vulnerability has been resolved:

ipvs: do not propagate one-packet flag to synced conns

Synced connections can be created before their destination exists. When
the destination is later added, ip_vs_bind_dest() copies connection flags
from the destination into cp-…

NVD

CRITICAL
CVE-2026-81934
CVE-2026-81934
pkg: tls

published: Aug 27, 2026

Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated attacker may be able to execute arbitrary commands with the privileges of the Redis server. Fixed in Red…
CWE: CWE-416
NVD

CRITICAL
CVE-2026-81707
CVE-2026-81707
pkg: openssl

published: Aug 27, 2026

openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attackers to inject ANSI escape sequences that forge the fingerprint verification line displayed to users. Attackers can deliver a crafted identity bundle through normal contact-exchange flows or …
CWE: CWE-20
NVD

CRITICAL
CVE-2026-81702
CVE-2026-81702
pkg: openssl

published: Aug 27, 2026

openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, allowing attackers to substitute public keys in identity stores. Attackers can replace legitimate public keys with their own while maintaining the claimed fingerprint, enabling silen…
CWE: CWE-345
NVD

CRITICAL
CVE-2026-81701
CVE-2026-81701
pkg: openssl

published: Aug 27, 2026

openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in top-level plugins/ directories and unknown subdirectories to bypass signature verification. Attackers can place malicious unsigned plugins following documented installation paths t…
CWE: CWE-347
NVD

CRITICAL
CVE-2026-81700
CVE-2026-81700
pkg: openssl

published: Aug 27, 2026

openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that accepts revoked and expired keys by only checking VALIDSIG status without inspecting REVKEYSIG, EXPKEYSIG, or gpg exit codes. Attackers holding compromised-then-revoked signing key…
CWE: CWE-347
NVD

CRITICAL
CVE-2026-54569
CVE-2026-54569
pkg: python

published: Aug 26, 2026

SENAITE.CORE is the core framework for the SENAITE laboratory information management system. From 2.0.0 to 2.6.0, the SENAITE.CORE JSON API permits unauthenticated remote code execution through a two-request chain involving missing authorization and unsafe evaluation. The state-changing routes in sr…
CWE: CWE-95, CWE-862
GitHub-GHSA

CRITICAL
senaite.core Vulnerable to Eval Injection and Missing Authorization
GHSA-jrw6-7x4q-w25j
pkg: senaite.core
eco: pip
published: Aug 26, 2026
### Summary

An unauthenticated remote code execution vulnerability in the SENAITE JSON API allows any network-reachable attacker to execute arbitrary Python on the Zope worker process via a two-request anonymous chain. The `/@@API/update` route is reachable to anonymous callers and runs `eval()` on…

CVE-2026-54569
NVD

CRITICAL
CVE-2026-80519
CVE-2026-80519
pkg: linux

published: Aug 26, 2026

In the Linux kernel, the following vulnerability has been resolved:

ovpn: finish crypto callback cleanup before peer release

Crypto completion callbacks hold both key-slot and peer references. The
peer reference pins the netdev, and dropping the last peer reference can
let netdev unregistration an…

NVD

CRITICAL
CVE-2026-74752
CVE-2026-74752
pkg: linux

published: Aug 26, 2026

In the Linux kernel, the following vulnerability has been resolved:

sctp: validate cookie AUTH state before use

When cookie authentication is disabled, COOKIE_ECHO restores fixed-size
AUTH fields directly from peer-controlled cookie bytes. A forged RANDOM
length, HMAC list, or CHUNKS list can the…

NVD

CRITICAL
CVE-2026-74746
CVE-2026-74746
pkg: linux

published: Aug 26, 2026

In the Linux kernel, the following vulnerability has been resolved:

netfilter: flowtable: publish GC-visible tuple last

nf_flow_table_iterate() only treats original-direction tuple nodes as
owning entries. Publishing the original node first lets GC observe and
free a flow while flow_offload_add() …

NVD

CRITICAL
CVE-2026-74744
CVE-2026-74744
pkg: linux

published: Aug 26, 2026

In the Linux kernel, the following vulnerability has been resolved:

ipvlan: inherit needed_headroom and needed_tailroom from phy_dev

ipvlan devices inherit hard_header_len from phy_dev during ipvlan_init(),
but leave needed_headroom and needed_tailroom set to 0.

When the underlying phy_dev (or st…

NVD

CRITICAL
CVE-2026-74743
CVE-2026-74743
pkg: linux

published: Aug 26, 2026

In the Linux kernel, the following vulnerability has been resolved:

macvlan: inherit needed_headroom and needed_tailroom from lowerdev

macvlan devices inherit hard_header_len from lowerdev during macvlan_init(),
but leave needed_headroom and needed_tailroom set to 0.

When the underlying lowerdev …

NVD

CRITICAL
CVE-2026-74737
CVE-2026-74737
pkg: linux

published: Aug 26, 2026

In the Linux kernel, the following vulnerability has been resolved:

net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG

On the packet reception path, the ID of the MAC Port on which the packet
was received, is embedded in the RX DMA Descriptor's metadata. The ID is
extracted usi…

NVD

CRITICAL
CVE-2026-65905
CVE-2026-65905
pkg: apache tomcat

published: Aug 25, 2026

Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made, a client makes a DIGEST
authenticated request with a nonceCount on the upper boundary of the
replay window then that request is replayable once only while t…
CWE: CWE-294
NVD

CRITICAL
CVE-2026-80104
CVE-2026-80104
pkg: python

published: Aug 25, 2026

DB-GPT builds the destination path for an uploaded skill from the multipart filename without constraining it to the upload directory. skill_upload in packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py takes file.filename as given and writes the request body to upload_dir / filename.…
CWE: CWE-22
NVD

CRITICAL
CVE-2026-45018
CVE-2026-45018
pkg: python

published: Aug 25, 2026

Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose the POST /mcp endpoint without requiring authentication. For stdio transport, the endpoi…
CWE: CWE-78
GitHub-GHSA

CRITICAL
Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution
GHSA-w3fx-mc44-mf6j
pkg: chainlit
eco: pip
published: Aug 25, 2026
### Am I affected?

Only if your deployment sets `features.mcp.enabled = true` in `.chainlit/config.toml`. **MCP has been disabled by default since v2.7.0**, so most Chainlit deployments are not affected. No authentication is required: `/mcp` is reachable by any client that can open a session.

### …

CVE-2026-45018
NVD

CRITICAL
CVE-2026-55546
CVE-2026-55546
pkg: express

published: Aug 25, 2026

QWED-MCP is a deterministic verification gateway for MCP. Prior to 0.2.1, verify_math_expression() in src/qwed_mcp/engines/math_engine.py passes attacker-controlled expression and claimed_result strings directly to SymPy's parse_expr() after only normalizing caret syntax to Python exponent syntax, w…
CWE: CWE-94
GitHub-GHSA

CRITICAL
qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input
GHSA-mw6r-2hvm-4rp2
pkg: qwed-mcp
eco: pip
published: Aug 25, 2026
### Summary

`verify_math_expression()` in `qwed-mcp` v0.2.0 passes attacker-controlled strings directly to SymPy's `parse_expr()` without restricting `global_dict` or validating the expression's AST. Because `parse_expr()` internally calls `eval()` and Python automatically injects the current modul…

CVE-2026-55546
GitHub-GHSA

CRITICAL
Apache Camel-Undertow: the endpoint discarded the undertow-specific header filter strategy in favour of the base HTTP one, so the undertow filtering never ran on endpoint-configured routes
GHSA-v7h8-xhh6-gfj4
pkg: org.apache.camel:camel-undertow, org.apache.camel:camel-undertow, org.apache.camel:camel-undertow
eco: maven
published: Aug 24, 2026
Improper input validation vulnerability in Apache Camel Undertow component.

This issue affects Apache Camel: from 4.11.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0.

UndertowEndpoint defaulted its headerFilterStrategy field to the base HttpHeaderFilterStrategy and pushed th…

CVE-2026-78329
GitHub-GHSA

CRITICAL
Apache Camel-Atmosphere-Websocket: WebSocket dispatch header injection – the producer selected its target peers through Exchange headers whose names sat outside the filtered Camel namespace
GHSA-m5r8-w65q-8wjf
pkg: org.apache.camel:camel-atmosphere-websocket, org.apache.camel:camel-atmosphere-websocket, org.apache.camel:camel-atmosphere-websocket
eco: maven
published: Aug 24, 2026
Improper input validation vulnerability in Apache Camel Atmosphere Websocket component.

This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0.

The camel-atmosphere-websocket producer selects which connected WebSocket peers a message is deli…

CVE-2026-71300
GitHub-GHSA

CRITICAL
Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token)
GHSA-cgc5-v3f2-8m2v
pkg: github.com/klever-io/klever-go
eco: go
published: Aug 28, 2026
## Summary

The per-entry percentages of a KDA asset's **split royalties** are validated by summing
them into a **`uint32`** accumulator and checking the *sum* against `HundredPercent (10000)`,
with **no upper bound on each individual entry**. Two split entries whose percentages sum to
just over `2^…

CVE-2026-54755
GitHub-GHSA

CRITICAL
Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped)
GHSA-p7gw-2pcp-5pf8
pkg: github.com/klever-io/klever-go
eco: go
published: Aug 28, 2026
## Summary

When a marketplace order is settled (`MarketBuy` / `BuyItNow`, and auction `Claim`), the buyer's
payment is split three ways — **referral**, **royalties**, and the **seller (market-order owner)
remainder**:

“`
marketOwnerAmount = CurrentBid − referralAmount − royaltiesAmount
“`

CVE-2026-54754
NVD

CRITICAL
CVE-2026-59354
CVE-2026-59354
pkg: oauth

published: Aug 27, 2026

In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client Registration is explicitly enabled, the registration endpoint performs insufficient validation of certain client metadata fields supplied by the registering client. An attacker who possesses …
CWE: CWE-20
GitHub-GHSA

CRITICAL
Kyverno's NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated — background controller creates RoleBindings in any namespace including kube-system
GHSA-79gf-7frw-68m9
pkg: github.com/kyverno/kyverno
eco: go
published: Aug 26, 2026
## Summary

In Kyverno v1.18.1, a tenant who can create a `NamespacedMutatingPolicy` in their own namespace can instruct the admission controller to generate resources in any namespace by passing an arbitrary namespace string to the CEL `generator.apply(namespace, resources)` function.

## Details

CVE-2026-54523
NVD

CRITICAL
CVE-2026-79138
CVE-2026-79138
pkg: google chrome, microsoft windows

published: Aug 25, 2026

Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-787
NVD

CRITICAL
CVE-2026-79019
CVE-2026-79019
pkg: google chrome, microsoft windows

published: Aug 25, 2026

Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-787
NVD

CRITICAL
CVE-2026-78989
CVE-2026-78989
pkg: google chrome, microsoft windows

published: Aug 25, 2026

Out of bounds read in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-125
NVD

CRITICAL
CVE-2026-78948
CVE-2026-78948
pkg: google chrome

published: Aug 25, 2026

Buffer overflow in WebGL in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-122
NVD

CRITICAL
CVE-2026-78945
CVE-2026-78945
pkg: google chrome

published: Aug 25, 2026

Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-416
NVD

CRITICAL
CVE-2026-78939
CVE-2026-78939
pkg: google chrome

published: Aug 25, 2026

Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

CRITICAL
CVE-2026-78937
CVE-2026-78937
pkg: google chrome, google android

published: Aug 25, 2026

Use after free in Search in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-416
NVD

CRITICAL
CVE-2026-78935
CVE-2026-78935
pkg: google chrome, apple iphone_os

published: Aug 25, 2026

Use of uninitialized variable in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-457
NVD

CRITICAL
CVE-2026-78909
CVE-2026-78909
pkg: google chrome

published: Aug 25, 2026

Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-416
NVD

CRITICAL
CVE-2026-78904
CVE-2026-78904
pkg: google chrome

published: Aug 25, 2026

Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-843
NVD

CRITICAL
CVE-2026-78900
CVE-2026-78900
pkg: google chrome

published: Aug 25, 2026

Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-20
NVD

CRITICAL
CVE-2026-78683
CVE-2026-78683
pkg: python

published: Aug 25, 2026

NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deserialization vulnerability in the TransitionParser.parse() method (nltk/parse/transitionparser.py). The method calls pickle_load() with the default restricted=False, routing deserialization through WarningUnpickler, which do…
CWE: CWE-502
NVD

CRITICAL
CVE-2026-76840
CVE-2026-76840
pkg: windows

published: Aug 24, 2026

RustDesk's Windows clipboard redirection copies a peer-supplied length into a fixed-size caller buffer without an upper bound check. When an OLE paste consumer such as explorer.exe calls IStream::Read with a buffer of cb bytes, CliprdrStream_Read in libs/clipboard/src/windows/wf_cliprdr.c requests t…
CWE: CWE-20, CWE-787
NVD

CRITICAL
CVE-2026-74751
CVE-2026-74751
pkg: linux

published: Aug 26, 2026

In the Linux kernel, the following vulnerability has been resolved:

riscv: lib: Fix ZBB strnlen reading past count boundary

The ZBB-optimized strnlen loop loads one word ahead before checking the
aligned boundary:

REG_L t1, SZREG(t0) // load next word
addi t0, t0, SZREG /…

NVD

CRITICAL
CVE-2026-82454
CVE-2026-82454
pkg: jwt

published: Aug 29, 2026

The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-in token verification. The decodeAppleToken function extracted the 'alg' field from the attacker-supplied JWT header and passed it as the sole allowed algorithm to jwt.verify(). Using jso…
CWE: CWE-347
NVD

CRITICAL
CVE-2026-55511
CVE-2026-55511
pkg: express

published: Aug 28, 2026

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs allows a user with SystemPrivilege.ControlArchiving to create a double-quoted StreamSQL column name that is interpolated into generated Java source by Expression.fillCode_InputDefVars and Expression.sanitizeName. A sum aggregate…
CWE: CWE-94
GitHub-GHSA

CRITICAL
plone.app.event vulnerable to denial of service via iCalendar import
GHSA-r82h-mqw3-fc56
pkg: plone.app.event, plone.app.event
eco: pip
published: Aug 28, 2026
### Impact
By abusing the iCalendar import functionality, a logged-in editor could take the whole site offline, make the server reach into the internal network and read calendar files off disk (SSRF), and store XSS.

### Patches
The problem has been patched in `plone.app.event`.

* For Plone 6.2: up…

CVE-2026-55247
GitHub-GHSA

CRITICAL
plone.app.portlets vulnerable to denial of service via RSS feed portlet
GHSA-x5g3-w747-2h8q
pkg: plone.app.portlets, plone.app.portlets, plone.app.portlets
eco: pip
published: Aug 28, 2026
### Impact
By adding an RSS portlet, and giving this a link to a very large file, a member can cause a denial of service attack, because Plone will use lots of memory. The member could also use different urls to try to get information about the internal network and open port numbers (SSRF). A malici…
CVE-2026-55248
GitHub-GHSA

CRITICAL
Yamcs vulnerable to authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs `executeSql`
GHSA-3g44-3m7x-cgg2
pkg: org.yamcs:yamcs-core, org.yamcs:yamcs-core
eco: maven
published: Aug 28, 2026
## Overview

Yamcs compiles StreamSQL expressions to Java on the fly with the Janino `SimpleCompiler` (no restrictive class-loading policy or expression sandbox). When a StreamSQL aggregate such as `sum(…)` is applied to a **column**, the column's *name* is interpolated **unescaped** into the gene…

CVE-2026-55511
NVD

CRITICAL
CVE-2026-82244
CVE-2026-82244
pkg: node

published: Aug 28, 2026

Budibase versions before 3.41.3 contain a remote code execution vulnerability in plugin handling that allows authenticated admin users to execute arbitrary code by uploading a malicious plugin tarball. The server calls eval() on plugin JavaScript files without sandboxing in the main Node.js process,…
CWE: CWE-94
NVD

CRITICAL
CVE-2026-61800
CVE-2026-61800
pkg: node

published: Aug 28, 2026

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.4.0 through 4.14.6, a party holding the cluster key can write, overwrite, or delete arbitrary files under /var/ossec on worker nodes, leading to remote code execution …
CWE: CWE-22
NVD

CRITICAL
CVE-2026-50152
CVE-2026-50152
pkg: node

published: Aug 28, 2026

Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Monitor subscription handler fails to properly authorize access to the configuration-key store, allowing any CephX user with only  `mon allow r` capabilities to…
CWE: CWE-285
NVD

CRITICAL
CVE-2026-59283
CVE-2026-59283
pkg: express

published: Aug 27, 2026

Applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationContext may be vulnerable to a safety guard bypass when the SpEL expression compiler is active.
Spring Framework 7.0.0 – 7.0.8
Spring Framework 6.2.0 – 6.2.19
Spring Framework 6.1.0 – 6.1.28
Spring Framewo…
CWE: CWE-913
NVD

CRITICAL
CVE-2026-55536
CVE-2026-55536
pkg: express

published: Aug 25, 2026

PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, Browser Server _handle_connection() checks Chrome extension origins with re.match() and the unanchored expression chrome-extension://[a-z0-9]{32}. Extra trailing characters pass before websocket.accept(), allowing start_session comm…
CWE: CWE-284, CWE-625
GitHub-GHSA

CRITICAL
nextcloud-mcp-server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default )
GHSA-8vh3-g2qg-2h2c
pkg: nextcloud-mcp-server
eco: pip
published: Aug 25, 2026
## Summary
The `POST /webhooks/nextcloud` endpoint has no authentication by default: `WEBHOOK_SECRET` defaults to `None` and is never required by startup validation. When unset, the receiver accepts any unauthenticated POST. The `user_id` is taken directly from the attacker-supplied payload and pass…
CVE-2026-55640
GitHub-GHSA

CRITICAL
PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92)
GHSA-6g6r-q6gw-w8fg
pkg: PraisonAI
eco: pip
published: Aug 25, 2026
### Summary

`praisonai/browser/server.py` validates incoming WebSocket connections using a Chrome
extension Origin check. The regex `chrome-extension://[a-z0-9]{32}` is applied with
`re.match()`, which **only anchors at the start of the string, not the end**. Any Origin
header with more than 32 alp…

CVE-2026-55536
GitHub-GHSA

CRITICAL
Apache Camel-Azure-Storage-Blob: the downloadBlobToFile operation built the local download target from the remote blob name without constraining it to the configured fileDir
GHSA-2×37-89hj-2j95
pkg: org.apache.camel:camel-azure-storage-blob, org.apache.camel:camel-azure-storage-blob, org.apache.camel:camel-azure-storage-blob
eco: maven
published: Aug 24, 2026
Relative path traversal vulnerability in Apache Camel Azure Storage Blob component.

This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0.

The camel-azure-storage-blob component can download an Azure Storage blob to the local filesystem thr…

CVE-2026-66906
NVD

CRITICAL
CVE-2026-76835
CVE-2026-76835
pkg: oauth

published: Aug 24, 2026

OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, because the guard added for CVE-2026-40575 is inert in the default reverse-proxy configuration. GetRequestURI in pkg/requests/util/util.go prefers that header over the real request …
CWE: CWE-290
GitHub-GHSA

CRITICAL
free5GC NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpoints
GHSA-x8mj-6p3q-g5pp
pkg: github.com/free5gc/free5gc
eco: go
published: Aug 28, 2026
### Summary

free5GC NRF (Docker image free5gc-fuzz:latest) accepts NF registration requests without validating any field constraints against 3GPP TS 29.510, allowing unauthenticated attackers to inject fake NF profiles with arbitrary service endpoint IP addresses. All 17 constraint violations teste…

CVE-2026-55068
GitHub-GHSA

CRITICAL
Trojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise)
GHSA-93qj-5q5v-3c2h
pkg: pantheon-agents
eco: pip
published: Aug 26, 2026
## Summary
The PyPI account that publishes `pantheon-agents` was compromised in the June 2026 "Hades" PyPI supply-chain attack (Mini Shai-Hulud / Miasma lineage). The attacker used a stolen, long-lived PyPI API token to upload **trojanized releases `pantheon-agents` 0.6.1 and 0.6.2 directly to PyPI*…
NVD

HIGH
CVE-2026-82635
CVE-2026-82635
pkg: windows

published: Aug 30, 2026

Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file Tauri command onto the user's Downloads directory with no sanitization. A filename containing path traversal sequences (for example ../Library/LaunchAgents/com.evil.plist) or an absolute path resolves outside ~/Downloads…
CWE: CWE-22
NVD

HIGH
CVE-2026-82278
CVE-2026-82278
pkg: node

published: Aug 28, 2026

BISHENG before 2.6.0 contains a remote code execution vulnerability in the workflow run_once endpoint that allows authenticated users to execute arbitrary Python code. Attackers can submit crafted Code node definitions to the POST /api/v1/workflow/run_once endpoint, which executes them with exec() w…
CWE: CWE-94
NVD

HIGH
CVE-2026-55485
CVE-2026-55485
pkg: python

published: Aug 28, 2026

Piccolo Admin is an admin interface and content management system for Python, built on top of Piccolo. Prior to 1.14.0, piccolo_admin/endpoints.py uses superuser_validators to block PUT, PATCH, DELETE, and POST requests by non-superusers but permits GET requests to configured user and session tables…
CWE: CWE-200, CWE-269, CWE-863
GitHub-GHSA

HIGH
piccolo-admin has a privilege escalation issue – admin to superuser via session-token disclosure in GET /api/tables/sessions/.
GHSA-2gh4-jmwq-rr8w
pkg: piccolo-admin
eco: pip
published: Aug 28, 2026
## Summary

`piccolo_admin` uses a helper called `superuser_validators` to gate access to the user and session tables for non-superusers. The helper rejects `PUT`, `PATCH`, `DELETE`, and `POST`, but **does not reject `GET`**.

The `sessions` table stores live session tokens **in plaintext**, and the…

CVE-2026-55485
GitHub-GHSA

HIGH
Yamcs Core API has Multiple Missing Function Level Access Control vulnerabilities
GHSA-962x-ccwf-8x6p
pkg: org.yamcs:yamcs-core, org.yamcs:yamcs-core
eco: maven
published: Aug 28, 2026
### Summary
Multiple Missing Function Level Access Control vulnerabilities exist in the Yamcs Core API. These vulnerabilities allow any authenticated user, regardless of their assigned roles or privileges (e.g., an unprivileged "Guest"), to bypass intended access controls. An attacker can exploit th…
CVE-2026-55521
NVD

HIGH
CVE-2026-10036
CVE-2026-10036
pkg: python

published: Aug 27, 2026

SpeechBrain before 1.1.1 contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary code by supplying a crafted CKPT.yaml checkpoint metadata file parsed with PyYAML's unsafe loader during candidate enumeration in Checkpointer.recover_if_possible(). Attackers can e…
CWE: CWE-502
NVD

HIGH
CVE-2026-81581
CVE-2026-81581
pkg: windows

published: Aug 27, 2026

Improper validation of memory boundaries in WibuKey64.sys of WibuKey up to 6.70 for Windows can be exploited by an attacker by setting the pointers outside the scope of the program. This usually results in a denial of service, yet we cannot rule out the possibility of exploits that can cause Remote …
CWE: CWE-119
NVD

HIGH
CVE-2026-81579
CVE-2026-81579
pkg: windows

published: Aug 27, 2026

In WibuKey for Windows before version 6.71, an untrusted pointer dereference in the WibuKey2_64.sys kernel driver for 64-bit Windows allows an attacker to exploit a write-what-where primitive, enabling local privilege escalation. This can be leveraged to execute arbitrary code, run an administrator …
CWE: CWE-123
NVD

HIGH
CVE-2026-58474
CVE-2026-58474
pkg: python

published: Aug 26, 2026

whichllm before 0.5.16 contains a code injection vulnerability in the run and snippet commands that allows a remote attacker who controls a HuggingFace repository to achieve arbitrary code execution by crafting a malicious GGUF filename containing double quotes or other special characters. The scrip…
CWE: CWE-94
NVD

HIGH
CVE-2026-80548
CVE-2026-80548
pkg: windows

published: Aug 26, 2026

In the Linux kernel, the following vulnerability has been resolved:

s390/vfio_ccw: Selectively expand io_mutex

The io_mutex was defined to serialize the io_regions, but then has
also sort of been associated with the I/O themselves because of
the close relationship they share.

With the handful of …

NVD

HIGH
CVE-2026-19042
CVE-2026-19042
pkg: linux

published: Aug 26, 2026

A command injection vulnerability in TeamViewer Full
Client and Host for Linux prior to version 15.81.5 allows a remote attacker to
execute arbitrary commands in the context of the current user via a specially
crafted URL sent through the out-of-session chat feature. Exploitation requires
user inter…
CWE: CWE-78
NVD

HIGH
CVE-2026-79240
CVE-2026-79240
pkg: windows

published: Aug 25, 2026

Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-787
NVD

HIGH
CVE-2026-79048
CVE-2026-79048
pkg: google chrome, microsoft windows

published: Aug 25, 2026

Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-787
NVD

HIGH
CVE-2026-78978
CVE-2026-78978
pkg: google chrome, microsoft windows

published: Aug 25, 2026

Out of bounds read in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-125
NVD

HIGH
CVE-2026-78944
CVE-2026-78944
pkg: google chrome

published: Aug 25, 2026

Use after free in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium)
CWE: CWE-416
NVD

HIGH
CVE-2026-78938
CVE-2026-78938
pkg: google chrome

published: Aug 25, 2026

Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-843
NVD

HIGH
CVE-2026-78910
CVE-2026-78910
pkg: google chrome

published: Aug 25, 2026

Buffer overflow in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-121
NVD

HIGH
CVE-2026-78905
CVE-2026-78905
pkg: google chrome

published: Aug 25, 2026

Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-843
NVD

HIGH
CVE-2026-78899
CVE-2026-78899
pkg: google chrome

published: Aug 25, 2026

Use after free in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-78891
CVE-2026-78891
pkg: google chrome

published: Aug 25, 2026

Buffer overflow in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-122
NVD

HIGH
CVE-2026-66152
CVE-2026-66152
pkg: linux

published: Aug 25, 2026

A Path traversal vulnerability in OPSWAT tarball in the SonicWall NetExtender Linux client allows an attacker to write arbitrary file as root.
CWE: CWE-29
NVD

HIGH
CVE-2026-55585
CVE-2026-55585
pkg: express

published: Aug 25, 2026

QWED is open-source AI verification infrastructure for deterministic verification of LLM outputs, tool calls, code, schemas, and agent state before production execution. Prior to 5.1.2, the qwed package passes caller-controlled math expressions directly to SymPy parse_expr() without restricted globa…
CWE: CWE-94
GitHub-GHSA

HIGH
qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`
GHSA-q27q-98j4-9pfv
pkg: qwed
eco: pip
published: Aug 25, 2026
### Summary

The `qwed` package (version 5.1.1) passes attacker-controlled input directly to SymPy's `parse_expr()` function without a restricted namespace. Because `parse_expr()` internally calls Python's `eval()`, any authenticated tenant can execute arbitrary Python code inside the API server pro…

CVE-2026-55585
NVD

HIGH
CVE-2026-75574
CVE-2026-75574
pkg: express

published: Aug 25, 2026

The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled Email action parameters as unsandboxed Twig templates. An authenticated remote user with only api.access and api.pages.write permissions can place a Twig expression in header.form.process.email.body, publis…
CWE: CWE-1336
NVD

HIGH
CVE-2026-76841
CVE-2026-76841
pkg: python

published: Aug 24, 2026

Xinference loads models with Hugging Face remote code execution unconditionally enabled, and before version 2.12.0 exposes no setting to disable it. Six loader call sites pass trust_remote_code=True as a literal or as an unconditional default: RerankModel._get_tokenizer in xinference/model/rerank/co…
CWE: CWE-94
NVD

HIGH
CVE-2026-59565
CVE-2026-59565
pkg: windows

published: Aug 24, 2026

A remotely exploitable buffer overflow bug can cause a local and kernel denial-of-service attack on affected versions of Zscaler Client Connector on Windows.
CWE: CWE-229
GitHub-GHSA

HIGH
Plate: Media embed provider metadata can bypass URL sanitization and execute iframe JavaScript
GHSA-qj6x-xx2h-8hvv
pkg: @platejs/media
eco: npm
published: Aug 25, 2026
## Summary

The media embed renderer trusts serialized `provider` or `sourceUrl` metadata and skips the URL protocol validation that normally blocks unsafe media embed URLs. A crafted Plate document can set a known video provider while keeping `url` as a `javascript:` iframe source. When a victim op…

CVE-2026-55596
NVD

HIGH
CVE-2026-59335
CVE-2026-59335
pkg: jwt

published: Aug 25, 2026

Improper handling of case sensitivity (CWE-178) in the identity zone authorization check in the Identity Zone Endpoint in Cloud Foundry UAA allows a remote authenticated attacker holding only the zones.write authority to bypass the intended restriction that this authority does not grant access to th…
CWE: CWE-178
GitHub-GHSA

HIGH
Sakai Conversations has a Stored XSS Issue
GHSA-w2x5-gv52-9ccv
pkg: org.sakaiproject.conversations:sakai-conversations-impl, org.sakaiproject.kernel:sakai-kernel-impl, org.sakaiproject.rubrics:rubrics-impl
eco: maven
published: Aug 24, 2026
### Summary

The Sakai Conversations tool stores topic and post messages without HTML sanitization, and the frontend renders them using LitElement's `unsafeHTML()` directive, resulting in stored cross-site scripting (XSS). Any authenticated user with access to a site that has the Conversations tool …

CVE-2026-54049
NVD

HIGH
CVE-2026-82641
CVE-2026-82641
pkg: tls

published: Aug 30, 2026

keploy versions 3.1.0 through 3.6.25 bind the agent control-plane HTTP server to all interfaces without authentication, exposing endpoints that stream TLS session keys and traffic data. Attackers can access the /agent/pcap/keylog endpoint to retrieve NSS keylog lines and decrypt recorded TLS traffic…
CWE: CWE-306
NVD

HIGH
CVE-2026-55848
CVE-2026-55848
pkg: kubernetes

published: Aug 28, 2026

mapfish-print is a component of MapFish for printing templated cartographic maps. Prior to 3.28.30, 3.30.32, 3.31.24, 3.33.16, and 4.0.5, MapFish Print accepts an attacker-controlled GML layer url in requests to the /api/print3/print endpoint and fetches XML parsed by core/src/main/java/org/mapfish/…
CWE: CWE-611
GitHub-GHSA

HIGH
MapFish Print has XXE that allows reading arbitrary files of certain types
GHSA-5v29-34h8-v68r
pkg: org.mapfish.print:print-lib, org.mapfish:print.print-servlet, org.mapfish.print:print-lib
eco: maven
published: Aug 28, 2026
### Summary
XXE on MapFish Print allows reading arbitrary files of certain types. Eg /etc/passwd or k8 secrets and certs.

https://github.com/mapfish/mapfish-print/commit/13020c0fbc299e5f604e4e66066311c4bf04d507

### Details
To trigger the XXE it is required to host a remote script and dtd file. Whe…

CVE-2026-55848
GitHub-GHSA

HIGH
9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass
GHSA-8gmq-j984-vp4r
pkg: 9router
eco: npm
published: Aug 28, 2026
## Summary

9router exposes an OpenAI/Anthropic-compatible LLM proxy. Remote access to this proxy is intended to be protected by an API-key check in the Next.js middleware.

However, 9router also defines a rewrite that maps `/codex/*` to the backend LLM endpoint `/api/v1/responses`. The middleware a…

CVE-2026-55638
GitHub-GHSA

HIGH
@logtape/syslog: syslog log injection via unescaped control characters and unvalidated SD-NAME keys
GHSA-8h6h-x5pq-56fq
pkg: @logtape/syslog, @logtape/syslog, @logtape/syslog
eco: npm
published: Aug 26, 2026
`@logtape/syslog` contains two related output-encoding bugs in the structured data formatting code. Both only affect deployments with `includeStructuredData: true`, which is non-default.

## 1. Unescaped C0 control characters in structured data values

`escapeStructuredDataValue()` in `packages/sysl…

CVE-2026-54511
GitHub-GHSA

HIGH
@arikusi/deepseek-mcp-server has an Authorization Bypass Through User-Controlled Key
GHSA-fh3r-g96v-f578
pkg: @arikusi/deepseek-mcp-server
eco: npm
published: Aug 25, 2026
# Cross-Session Data Exposure via Caller-Controlled `session_id`

Project / Repository: `arikusi/deepseek-mcp-server`
Affected version / commit tested: `1.6.0` / `04f28be2c6e99d3d4e443a6ae37cc35f0a71554a`
Vulnerability type: Authorization bypass / cross-session data exposure
Authentication requ…

CVE-2026-55604
GitHub-GHSA

HIGH
PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, cancel and delete
GHSA-2jgc-f764-c5r2
pkg: PraisonAI
eco: pip
published: Aug 25, 2026
### Summary
PraisonAI's async **Jobs API** (the FastAPI service in `praisonai/jobs/`) installs its router with no authentication middleware, no router-level dependency, and no per-route auth check. Any caller who can reach the jobs server can submit agent jobs (executed against the operator's config…
CVE-2026-55539
GitHub-GHSA

HIGH
PraisonAI serve agents –api-key is ignored, allowing unauthenticated remote agent execution
GHSA-7ww9-85pg-cv4x
pkg: PraisonAI
eco: pip
published: Aug 25, 2026
### Summary

PraisonAI's `praisonai serve agents` command exposes `–api-key` as the documented
authentication control for production/external deployments, but the configured key is not
enforced on the public agent invocation compatibility endpoints.

An operator can start the server with `-…

CVE-2026-55534
NVD

HIGH
CVE-2026-55108
CVE-2026-55108
pkg: node

published: Aug 28, 2026

KubeVela is an open source application delivery platform. Prior to 1.9.14, from 1.10.0-alpha.1 until 1.10.9, and from 1.11.0-alpha.1 until 1.11.0-alpha.4, the Terraform remote configuration loader in pkg/controller/utils/capability.go, GetTerraformConfigurationFromRemote, clones a repository supplie…
CWE: CWE-59, CWE-400
GitHub-GHSA

HIGH
KubeVela Terraform remote loader DoS via unbounded file read
GHSA-fmgp-q6jx-gg3x
pkg: github.com/oam-dev/kubevela, github.com/oam-dev/kubevela, github.com/oam-dev/kubevela
eco: go
published: Aug 28, 2026
### Summary

KubeVela's Terraform remote configuration loader can be abused to make `vela-core` read an unbounded byte stream into memory, causing an out-of-memory kill and a control-plane denial of service.

The issue is reachable when a user with permission to create or update a `core.oam.dev/v1be…

CVE-2026-55108
NVD

HIGH
CVE-2026-65092
CVE-2026-65092
pkg: linux

published: Aug 25, 2026

NVIDIA OpenShell Sandbox for Linux contains a vulnerability where an attacker could cause a path traversal bypass of L7 REST network policy. A successful exploit of this vulnerability might lead to information disclosure and data tampering.
CWE: CWE-22
GitHub-GHSA

HIGH
praisonaiagents has an SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)
GHSA-x44h-65qv-cw74
pkg: praisonaiagents
eco: pip
published: Aug 25, 2026
### Summary

`praisonaiagents/tools/spider_tools.py` contains an SSRF protection bypass. The function
`_host_is_blocked()` validates URLs against a list of blocked IP literals and hostname
aliases, but **never performs DNS resolution**. Any hostname that resolves to a private or
loopback IP address …

CVE-2026-55526
NVD

HIGH
CVE-2026-68960
CVE-2026-68960
pkg: windows

published: Aug 25, 2026

A stack-based buffer overflow vulnerability exists in SKYSEA Client View and SKYMEC IT Manager. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may be able to execute arbitrary code on another Windows system that has the a…
CWE: CWE-121
NVD

HIGH
CVE-2026-68959
CVE-2026-68959
pkg: windows

published: Aug 25, 2026

SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may be able to execute arbitrary code on another Windows system that has the affected product…
CWE: CWE-25
NVD

HIGH
CVE-2026-68062
CVE-2026-68062
pkg: windows

published: Aug 25, 2026

SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may be able to execute arbitrary code on another Windows system that has the affected product…
CWE: CWE-22
NVD

HIGH
CVE-2026-81683
CVE-2026-81683
pkg: openssl

published: Aug 27, 2026

openssl_encrypt (pip package openssl-encrypt) versions 1.4.8 and earlier store an mTLS client private key in cleartext within a world-readable (0644) SharedPreferences file via the desktop GUI's Settings screen 'combined certificate and private key' PEM field. A local attacker with file system acces…
CWE: CWE-312
NVD

HIGH
CVE-2026-55582
CVE-2026-55582
pkg: docker

published: Aug 25, 2026

mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default security.yaml allows /usr/bin/git, while security.go omits ! from containsShellMetacharacters and containsDangerousShellConstructs and applies no per-executable argument policy. A ca…
CWE: CWE-78
NVD

HIGH
CVE-2026-55581
CVE-2026-55581
pkg: docker

published: Aug 25, 2026

mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default Docker security.yaml includes /bin/bash in allowed_executables, while security.go validates only the first token and checkBlockedPatternsAndCommands does not reject the shell command…
CWE: CWE-78, CWE-183, CWE-1188
GitHub-GHSA

HIGH
mcp-shell has a Secure Mode Allowlist Bypass via Default `/bin/bash` Executable
GHSA-3×77-wg38-92r3
pkg: github.com/sonirico/mcp-shell
eco: go
published: Aug 25, 2026
### Summary

`mcp-shell` ships a default Docker configuration (`security.yaml`) that includes `/bin/bash` in the `allowed_executables` allowlist. The command validator (`security.go`) only checks whether the first token of the supplied command matches an allowed executable; it does not inspect or re…

CVE-2026-55581
GitHub-GHSA

HIGH
mcp-shell has a Secure Mode Allowlist Bypass via Git Shell Alias
GHSA-74hp-mggr-hv58
pkg: github.com/sonirico/mcp-shell
eco: go
published: Aug 25, 2026
### Summary

`mcp-shell`'s "secure mode" is designed to restrict command execution to an allowlist of executables defined in `security.yaml`. The default configuration includes `/usr/bin/git`. The security validator in `security.go` blocks common shell metacharacters (`|&;<>(){}[]$\“) but omits `!`…

CVE-2026-55582
GitHub-GHSA

HIGH
RestrictedPython guard hooks can be shadowed via positional-only arguments
GHSA-ffg3-p8fm-mjx2
pkg: RestrictedPython
eco: pip
published: Aug 28, 2026
### Impact

RestrictedPython rewrites sensitive operations to go through guard hooks. Attribute access becomes `_getattr_(obj, name)`, item access becomes `_getitem_(obj, key)`, writes go through `_write_`, and print goes through `_print_`. The embedding application supplies these hooks to enforce i…

CVE-2026-55830
NVD

HIGH
CVE-2026-79247
CVE-2026-79247
pkg: google chrome, microsoft windows

published: Aug 25, 2026

Use after free in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-79175
CVE-2026-79175
pkg: google chrome, microsoft windows

published: Aug 25, 2026

Type confusion in Accessibility in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-843
NVD

HIGH
CVE-2026-78952
CVE-2026-78952
pkg: google chrome, microsoft windows

published: Aug 25, 2026

Out of bounds write in Crashpad in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-787
NVD

HIGH
CVE-2026-78934
CVE-2026-78934
pkg: google chrome

published: Aug 25, 2026

Race condition in ReadAloud in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-362
NVD

HIGH
CVE-2026-78911
CVE-2026-78911
pkg: google chrome

published: Aug 25, 2026

Incorrect authorization in USB in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-863
GitHub-GHSA

HIGH
9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF
GHSA-86m2-fcxq-5q7c
pkg: 9router
eco: npm
published: Aug 28, 2026
## Summary

9router's request guard decides a request is "local" (and therefore exempt from API-key auth on the `/v1` LLM proxy) by reading the **client-controlled `Host` header**. Because 9router binds `0.0.0.0` by default (and the CLI misleadingly prints "localhost"), a remote, unauthenticated att…

CVE-2026-55641
NVD

HIGH
CVE-2026-59316
CVE-2026-59316
pkg: oauth

published: Aug 27, 2026

Spring Authorization Server's default consent page renders user-controlled values without HTML entity encoding. When using the DefaultConsentPage, an attacker can craft an OAuth2 authorization request containing a malicious value that is stored server-side and later rendered unencoded in the default…
CWE: CWE-79
NVD

HIGH
CVE-2026-80208
CVE-2026-80208
pkg: nginx

published: Aug 27, 2026

APITable through 1.13.0-beta.1 annotates both getUserHistories and closePausedUserAccount in InternalUserController with requiredLogin = false. ResourceInterceptor honours that annotation by returning before any session or API key is validated, and the nginx gateway shipped with the product proxies …
CWE: CWE-306
NVD

HIGH
CVE-2026-55571
CVE-2026-55571
pkg: react

published: Aug 25, 2026

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to 1.0.4, LiveViewConsumer.handle_mount sends a `{"type":"navigate","to":…}` frame when login_required, permission_required, or a redirecting on_mount hook denies a LiveView mount, …
CWE: CWE-285, CWE-306
NVD

HIGH
CVE-2026-55533
CVE-2026-55533
pkg: jwt

published: Aug 25, 2026

PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, create_auth_middleware() allows requests when auth=api-key lacks PRAISONAI_API_KEY or JWT authentication lacks PRAISONAI_JWT_SECRET. An externally bound Recipe server can therefore accept unauthenticated POST /v1/recipes/run request…
CWE: CWE-287, CWE-306
GitHub-GHSA

HIGH
djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls
GHSA-xx4j-w367-7247
pkg: djust
eco: pip
published: Aug 25, 2026
### Impact

djust's `LiveViewConsumer` mounts a `LiveView` over a WebSocket. When a view is gated (`login_required` / `permission_required`, or an `on_mount` hook that returns a redirect) and the connecting user is not authorized, the consumer sent the client a `{"type":"navigate","to":…}` redirec…

CVE-2026-55571
GitHub-GHSA

HIGH
utcp-http SSRF: HTTP tool invocation follows redirects without re-validating the target
GHSA-9qhg-99ww-9mqc
pkg: utcp-http
eco: pip
published: Aug 25, 2026
## Summary

`HttpCommunicationProtocol.call_tool` validates only the pre-redirect tool URL, then issues the request with redirects enabled and never re-checks where it lands. A tool whose endpoint is an attacker-controlled public URL can therefore `302`-redirect the UTCP client into an internal serv…

GitHub-GHSA

HIGH
PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret
GHSA-gfq8-hmph-9gjv
pkg: PraisonAI
eco: pip
published: Aug 25, 2026
### Summary

The PraisonAI Recipe HTTP server silently allows unauthenticated requests when `auth` is configured as `api-key` or `jwt` but the corresponding secret is missing.

This creates an authentication fail-open condition. An operator can start the Recipe server with authentication enabled, in…

CVE-2026-55533
GitHub-GHSA

HIGH
praisonaiagents: AgentServer declares auth_token but never enforces it on any route
GHSA-7g3p-92qq-8wvh
pkg: praisonaiagents
eco: pip
published: Aug 25, 2026
**Researcher:** Kai Aizen — SnailSploit (@SnailSploit), Adversarial & Offensive Security Research
**Target:** https://github.com/MervinPraison/PraisonAI

**Package:** `praisonaiagents` on PyPI
**Affected version (empirically tested):** 1.6.48
**Component:** `praisonaiagents.server.AgentServer…

CVE-2026-55528
NVD

HIGH
CVE-2026-76842
CVE-2026-76842
pkg: node

published: Aug 24, 2026

The Mercado Pago Node.js SDK interpolates caller-supplied identifiers into API request paths without percent-encoding them, so characters that are structural in a URL survive into the outgoing request. The payment (get, capture, cancel), paymentRefund (create, total, list, get), advancedPayment (get…
CWE: CWE-22
NVD

HIGH
CVE-2026-56100
CVE-2026-56100
pkg: jwt

published: Aug 28, 2026

SpringBlade versions from 2.7.3 up to but not including 5.0.0 contain a privilege escalation vulnerability that allows authenticated attackers to create system administrator accounts by sending crafted POST requests to an unprotected internal Feign user-creation endpoint exposed via @RestController …
CWE: CWE-862
GitHub-GHSA

HIGH
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
GHSA-2q2q-jr9g-v9rf
pkg: Weblate
eco: pip
published: Aug 28, 2026
### Impact
The API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to.

### Patches
* https://github.com/WeblateOrg/weblate/pull/19970

### References

Parts of this issue were indep…

CVE-2026-55228
GitHub-GHSA

HIGH
Vikunja vulnerable to Improper Authorization and Authorization Bypass Through User-Controlled Key
GHSA-gg93-x632-9ccv
pkg: code.vikunja.io/api
eco: go
published: Aug 28, 2026
### Summary

A user with only a single self-owned project can permanently destroy the Kanban bucket assignments (`task_buckets`) and task ordering (`task_positions`) of **any other project view in the entire instance**. The `ProjectView.Delete` model method runs three SQL statements: the first is pr…

CVE-2026-55065
NVD

HIGH
CVE-2026-81036
CVE-2026-81036
pkg: oauth

published: Aug 26, 2026

Stalwart Mail Server does not compare an OAuth redirect target against any registered destination in its default configuration. The validation routine in crates/http/src/auth/oauth/registration.rs returns success immediately when the client-authentication requirement is disabled, and that requiremen…
CWE: CWE-601
NVD

HIGH
CVE-2026-81029
CVE-2026-81029
pkg: jwt

published: Aug 26, 2026

OpenMetadata accepts a caller-supplied post-authentication redirect target and appends the issued token to it. SamlLoginServlet reads the callback request parameter and stores it in the HTTP session without comparing it against any configured or registered destination, and the assertion consumer ser…
CWE: CWE-601
GitHub-GHSA

HIGH
asyncssh has SCP Path Traversal to Arbitrary File Write
GHSA-2wxc-x7rj-hg8f
pkg: asyncssh
eco: pip
published: Aug 26, 2026
| | |
|—|—|
| Product | asyncssh (all versions through 2.23.0) |
| Related | CVE-2019-6111 (same class in OpenSSH) |
| Fix | AsyncSSH 2.23.1 |

A malicious SSH server can write arbitrary files on the asyncssh SCP client's filesystem by sending filenames containing `../` traversal sequences. The …

CVE-2026-54591
NVD

HIGH
CVE-2026-79194
CVE-2026-79194
pkg: google chrome, microsoft windows

published: Aug 25, 2026

Use after free in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-78913
CVE-2026-78913
pkg: google chrome

published: Aug 25, 2026

Use after free in Chromoting in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)
CWE: CWE-416
NVD

HIGH
CVE-2026-65105
CVE-2026-65105
pkg: linux

published: Aug 25, 2026

NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote attacker may access the inference service without authentication. A successful exploit of this vulnerability may lead to information disclosure and denial of service.
CWE: CWE-306
NVD

HIGH
CVE-2026-65098
CVE-2026-65098
pkg: linux

published: Aug 25, 2026

NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering.
CWE: CWE-1390
NVD

HIGH
CVE-2026-65084
CVE-2026-65084
pkg: linux

published: Aug 25, 2026

NVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, code execution, and escalation of privileges.
CWE: CWE-295
NVD

HIGH
CVE-2026-65081
CVE-2026-65081
pkg: linux

published: Aug 25, 2026

NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker could cause execution of untrusted code. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, information disclosure, and denial of service.
CWE: CWE-494
NVD

HIGH
CVE-2026-78379
CVE-2026-78379
pkg: python

published: Aug 25, 2026

Improper neutralization of input used for LLM prompting in the python_repl tool in Amazon Strands Agents Tools before 0.8.5 might allow remote actors to execute arbitrary Python code on the agent's host by bypassing the human consent gate, via a crafted prompt that forwards non_interactive_mode as a…
NVD

HIGH
CVE-2026-16231
CVE-2026-16231
pkg: express

published: Aug 25, 2026

hbs is an Express view engine that wraps Handlebars. Its registerAsyncHelper API bypasses Handlebars' automatic HTML escaping: an async helper returns an opaque placeholder during the first render pass, so the double-brace expression escapes only the placeholder, and after rendering hbs substitutes …
CWE: CWE-79
NVD

HIGH
CVE-2026-79662
CVE-2026-79662
pkg: jwt

published: Aug 25, 2026

Ech0 through 4.5.6 contains an OAuth redirect URI validation vulnerability in parseAndValidateClientRedirect (internal/service/auth/auth.go) that compares only the scheme and host of the client-supplied redirect_uri against the admin-configured allowlist, ignoring path, query, and fragment component…
CWE: CWE-601
NVD

HIGH
CVE-2026-78414
CVE-2026-78414
pkg: linux

published: Aug 24, 2026

Cross-site scripting in the Web Administration interface of Network Optix Nx Witness VMS before version 6.1.3 on Linux, Windows and MacOS allows an adjacent-network attacker to execute arbitrary JavaScript in the browser of an authenticated administrator and steal the administrator's session token, …
CWE: CWE-79
NVD

HIGH
CVE-2026-44629
CVE-2026-44629
pkg: windows

published: Aug 28, 2026

Improper access control to the Synergis Softwire installation folder. This vulnerability affects Streamvault all-in-one appliances (SV-100E and SV-300E series) and Synergis Softwire installed on Windows servers.
CWE: CWE-922
GitHub-GHSA

HIGH
Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data
GHSA-jw39-3688-r4rx
pkg: compliance-trestle, compliance-trestle
eco: pip
published: Aug 28, 2026
### Impact

A Server-Side Template Injection (SSTI) vulnerability exists in multiple locations of trestle's Jinja2 rendering pipeline due to a systemic pattern: **untrusted data is re-parsed as Jinja2 template source code without sandboxing**. This advisory tracks the root cause across all affected …

CVE-2026-54757
NVD

HIGH
CVE-2026-80710
CVE-2026-80710
pkg: express

published: Aug 28, 2026

In the Linux kernel, the following vulnerability has been resolved:

s390/dasd: Fix undersized format-check buffer

fmt_buffer_size in dasd_eckd_check_device_format() is declared as
int, even though one of the multiplicands, sizeof(struct eckd_count),
is a size_t. The expression

trkcount * rpt_…

NVD

HIGH
CVE-2026-80709
CVE-2026-80709
pkg: node

published: Aug 28, 2026

In the Linux kernel, the following vulnerability has been resolved:

s390/zcrypt: Fix wrong domain value verification with EP11 CPRBs

There is a wrong upper limit check for the domain value when an EP11
CPRB is processed for sending to a crypto card. This check is only
active on custom device nodes…

NVD

HIGH
CVE-2026-80682
CVE-2026-80682
pkg: express

published: Aug 28, 2026

In the Linux kernel, the following vulnerability has been resolved:

riscv/mm: use physical alignment for vmemmap_start_pfn

RISC-V computes vmemmap_start_pfn by rounding phys_ram_base down to
VMEMMAP_ADDR_ALIGN. That alignment must therefore be expressed in the
physical-address domain.

Commit 476…

NVD

HIGH
CVE-2026-80656
CVE-2026-80656
pkg: express

published: Aug 28, 2026

In the Linux kernel, the following vulnerability has been resolved:

hfsplus: Add a sanity check for btree node size

Syzbot reported an uninit-value bug in [1] with a corrupted HFS+ image,
during the file system mounting process, specifically while loading the
catalog, a corrupted node_size value o…

NVD

HIGH
CVE-2026-81719
CVE-2026-81719
pkg: openssl

published: Aug 27, 2026

openssl_encrypt before 1.4.9 executes untrusted third-party plugins with insufficient controls: the plugin signature policy defaulted to WARN, so an unsigned/unverifiable non-built-in plugin was compiled and executed in the host process at import time, before the runtime sandbox is installed. The on…
CWE: CWE-94
NVD

HIGH
CVE-2026-80522
CVE-2026-80522
pkg: linux

published: Aug 26, 2026

In the Linux kernel, the following vulnerability has been resolved:

crypto: tegra – fix rctx->cryptlen calculation in tegra_gcm_do_one_req()

Perform rctx->cryptlen calculation in tegra_gcm_do_one_req() the same way
it is done in tegra_ccm_crypt_init(). The current formulae may lead to a
crash if a…

NVD

HIGH
CVE-2026-80521
CVE-2026-80521
pkg: linux

published: Aug 26, 2026

In the Linux kernel, the following vulnerability has been resolved:

af_unix: Unlink scc_entry in unix_del_edge().

Kyle Zeng reported that GC could free a dead SCC partially.

The scenario is as follows:

1) Create two SCCs:

X -. A <-> B
^–'

2) Run the following concurrentl…

NVD

HIGH
CVE-2026-74753
CVE-2026-74753
pkg: linux

published: Aug 26, 2026

In the Linux kernel, the following vulnerability has been resolved:

perf: Reject exited events as group leaders

perf_event_remove_on_exec() sets remove-on-exec events to the EXIT state
and detaches their group relationships. The event's file descriptor can
remain open, however, and perf_event_ope…

NVD

HIGH
CVE-2026-74748
CVE-2026-74748
pkg: linux

published: Aug 26, 2026

In the Linux kernel, the following vulnerability has been resolved:

netfilter: ipset: fix refcount race between list:set GC and swap

__ip_set_put_byindex() resolved the index to a set pointer under RCU,
then took ip_set_ref_lock in __ip_set_put() to decrement set->ref.
ip_set_swap() holds that sam…

NVD

HIGH
CVE-2026-74747
CVE-2026-74747
pkg: linux

published: Aug 26, 2026

In the Linux kernel, the following vulnerability has been resolved:

ipvs: revalidate ihl to prevent out-of-bounds access

While the outer IP header is already pulled into the skb head,
we must be careful and revalidate the embedded headers after
reading them from the skb frags to prevent out-of-bou…

NVD

HIGH
CVE-2026-74739
CVE-2026-74739
pkg: linux

published: Aug 26, 2026

In the Linux kernel, the following vulnerability has been resolved:

net/sched: cls_u32: skip hash tables in u32_bind_class()

u32_walk() enumerates both struct tc_u_hnode and struct tc_u_knode
through the walker callback. u32_bind_class() unconditionally casts the
passed fh to tc_u_knode and access…

NVD

HIGH
CVE-2026-74736
CVE-2026-74736
pkg: linux

published: Aug 26, 2026

In the Linux kernel, the following vulnerability has been resolved:

net/sched: cls_bpf: reject dev-bound programs bound to a different device

cls_bpf_prog_from_efd() obtained a SCHED_CLS program via
bpf_prog_get_type_dev() but never verified that a device-bound (offloaded)
program's bound netdev m…

NVD

HIGH
CVE-2026-77658
CVE-2026-77658
pkg: linux

published: Aug 26, 2026

A stack-based buffer overflow vulnerability exists in the Dia diagram editor when processing Network Bus objects from Dia XML project files.

In objects/network/bus.c, bus_load() reads the number of bus handles from the file attribute "bus_handles" using attribute_num_data() without validating an up…

CWE: CWE-121
NVD

HIGH
CVE-2026-57170
CVE-2026-57170
pkg: express

published: Aug 26, 2026

Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions prior to 3.12.4 and 4.0.0 through 4.0.3, the custom Jinja2 include tags mdsection_include and md_clean_include re-parse the content of an included Markdown file as Jinja2 template …
CWE: CWE-94, CWE-1336
NVD

HIGH
CVE-2026-54757
CVE-2026-54757
pkg: express

published: Aug 25, 2026

Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, Trestle is vulnerable to server-side template injection that can lead to remote code execution. This occurs because the MDCleanInclu…
CWE: CWE-94
NVD

HIGH
CVE-2026-65099
CVE-2026-65099
pkg: linux

published: Aug 25, 2026

NVIDIA NemoClaw for Linux contains a vulnerability in its command-line interface, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.
CWE: CWE-78
NVD

HIGH
CVE-2026-65096
CVE-2026-65096
pkg: linux

published: Aug 25, 2026

NVIDIA NemoClaw for Linux contains a vulnerability in the Telegram bridge component, where an attacker could cause an OS command injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
CWE: CWE-78
NVD

HIGH
CVE-2026-65090
CVE-2026-65090
pkg: linux

published: Aug 25, 2026

NVIDIA NemoClaw for Linux contains a vulnerability in its NIM management component, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.
CWE: CWE-78
NVD

HIGH
CVE-2026-65089
CVE-2026-65089
pkg: linux

published: Aug 25, 2026

NVIDIA NemoClaw for Linux contains a vulnerability in its status and logs plugin commands, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.
CWE: CWE-78
NVD

HIGH
CVE-2025-71406
CVE-2025-71406
pkg: node

published: Aug 25, 2026

Nokogiri before 1.18.4 bundles a vulnerable version of libxslt (prior to 1.1.43) that contains two use-after-free vulnerabilities: CVE-2025-24855 (use-after-free of the XPath context node due to xsltEvalXPathStringNs leaking xpathCtxt->node) and CVE-2024-55549 (use-after-free related to excluded res…
CWE: CWE-416
GitHub-GHSA

HIGH
PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code
GHSA-hxmv-c4g6-5fqc
pkg: praisonaiagents, PraisonAI
eco: pip
published: Aug 25, 2026
## Summary

PraisonAI's workflow include implementation implicitly imports and executes an included recipe's `tools.py` file even when the documented `tools.py` autoload opt-in is unset.

This bypasses the hardening added for the prior automatic `tools.py` RCE advisory family. A workflow that includ…

CVE-2026-55522
NVD

HIGH
CVE-2026-69665
CVE-2026-69665
pkg: windows

published: Aug 25, 2026

SKYSEA Client View and SKYMEC IT Manager contain an issue with incorrect default permissions. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may execute arbitrary code with SYSTEM privilege.
CWE: CWE-276
NVD

HIGH
CVE-2026-66109
CVE-2026-66109
pkg: windows

published: Aug 25, 2026

A missing authorization vulnerability exists in SKYSEA Client View and SKYMEC IT Manager. If this vulnerability is exploited, an attacker who can log in to the Windows system on which the affected product is installed may execute arbitrary code with SYSTEM privilege.
CWE: CWE-862
NVD

HIGH
CVE-2026-78680
CVE-2026-78680
pkg: windows

published: Aug 25, 2026

NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot binary in dependencygraph.dot2img and AlignedSent._repr_svg_, allowing attackers to execute arbitrary code by placing a malicious dot binary in the search path or current working directory. Attackers can …
CWE: CWE-426
NVD

HIGH
CVE-2026-76843
CVE-2026-76843
pkg: python

published: Aug 24, 2026

The official Flair wheels for 0.15.0 and 0.15.1 still contain flair/models/clustering.py, whose ClusteringModel.load static method returns pickle.loads(joblib.load(str(model_file))) and so executes arbitrary Python while loading a model file. Loading a model supplied by an attacker therefore runs th…
CWE: CWE-502
NVD

HIGH
CVE-2026-30512
CVE-2026-30512
pkg: windows

published: Aug 24, 2026

A local privilege escalation vulnerability exists in the Restricted Access (Kiosk) Mode implementation of Scheidt & Bachmann entervo HMI prior to V2 R5 P0 M5. The vulnerability affects the external PDF viewer functionality used to display the application manual and its interaction with the underlyin…
CWE: CWE-250
GitHub-GHSA

HIGH
SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read
GHSA-56wq-x3wv-3ff4
pkg: github.com/seaweedfs/seaweedfs
eco: go
published: Aug 28, 2026
### Summary
The SeaweedFS S3 API gateway did not reject `..` path segments in the `X-Amz-Copy-Source` header used by `CopyObject` and `UploadPartCopy`. The request URL path was hardened against traversal in 4.30 (CVE-2026-54917), but the copy-source header was only checked for emptiness, so a `..` s…
CVE-2026-55874
GitHub-GHSA

HIGH
Incus has a project restriction bypass in instance copy across projects
GHSA-c9f5-j9c3-mhrg
pkg: github.com/lxc/incus/v7/cmd/incusd
eco: go
published: Aug 28, 2026
### Summary
Missing authorization checks exist for instance copying where an attacker knowing the name of a project that they don't have access to and the name of an instance in that project can copy the instance to a new project. This issue could allow an attacker to access secrets in instances the…
CVE-2026-55622
GitHub-GHSA

HIGH
Incus has a project restriction bypass for custom volume copy across projects
GHSA-64f3-v33m-w89f
pkg: github.com/lxc/incus/v7, github.com/lxc/incus/v6, github.com/lxc/incus
eco: go
published: Aug 28, 2026
### Summary

Missing authorization checks exist for custom volume copying where an attacker who knows the name of a project that they don't have access to and the name of a custom volume in that project can copy the custom volume to a new project. This issue could allow an attacker to access secrets…

CVE-2026-55621
NVD

HIGH
CVE-2026-75889
CVE-2026-75889
pkg: kubernetes

published: Aug 27, 2026

Grafana Alloy’s prometheus.operator.servicemonitors component allows a user who can create or modify ServiceMonitor resources in a watched namespace to specify an arbitrary local file through bearerTokenFile. Alloy reads the file and sends its contents as a bearer token to an attacker-controlled s…
CWE: CWE-552
NVD

HIGH
CVE-2026-61617
CVE-2026-61617
pkg: node

published: Aug 26, 2026

Wings is the server control plane for the Pterodactyl game-server management panel. In versions up to and including 1.13.2, the SFTP write path does not enforce a server's disk quota during a transfer, allowing a tenant with SFTP write access to a single server to exhaust the host node's physical di…
CWE: CWE-400, CWE-770
NVD

HIGH
CVE-2026-57171
CVE-2026-57171
pkg: python

published: Aug 26, 2026

Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, the catalog-generate, profile-generate, and ssp-generate author commands write generated Markdown to an attacker-influenced output p…
CWE: CWE-22
NVD

HIGH
CVE-2026-71366
CVE-2026-71366
pkg: node

published: Aug 24, 2026

A server-side request forgery (SSRF) vulnerability was found in multiple AWX notification backends. The webhook, Mattermost, Rocket.Chat, and Grafana notification backends use notification template URLs as direct HTTP request targets without validating the target address against private, loopback, o…
CWE: CWE-918
NVD

HIGH
CVE-2026-77368
CVE-2026-77368
pkg: jwt

published: Aug 26, 2026

SeaweedFS is a distributed storage system for files and blobs. In version 4.39, the filer's TUS resumable-upload handler checks JWT allowed_prefixes scoping only when a session is created, letting a low-privilege tenant hijack another tenant's upload session to write content to filer paths their own…
CWE: CWE-639
NVD

HIGH
CVE-2026-80186
CVE-2026-80186
pkg: linux

published: Aug 25, 2026

A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vuln…
CWE: CWE-120
GitHub-GHSA

HIGH
PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server
GHSA-pvph-5j39-v8qc
pkg: PraisonAI
eco: pip
published: Aug 25, 2026
### Summary

The PraisonAI MCP server exposes an HTTP-stream transport (praisonai mcp serve –transport http-stream) that binds to localhost and, by default, has no API key. Its only access control for browser-originated requests is an Origin allowlist, which the code implements as required by the M…

CVE-2026-55532
NVD

HIGH
CVE-2026-82644
CVE-2026-82644
pkg: curl

published: Aug 30, 2026

WWBN AVideo (current e01e41ecc and earlier) contains a brute-force rate limiting bypass in enforceRateLimit(), which protects login.json.php and 13 other endpoints. The function stores its attempt counter via a cache layer (ObjectYPT::setCacheGlobal) that silently discards writes for any client iden…
CWE: CWE-307
GitHub-GHSA

HIGH
free5GC AUSF authentication contexts can be overwritten by concurrent requests for the same SUPI
GHSA-334q-h5g3-fpxv
pkg: github.com/free5gc/ausf
eco: go
published: Aug 28, 2026
### Summary

The AUSF component of free5GC stores per-subscriber authentication state in a global `sync.Map` keyed only by SUPI. Every incoming authentication request creates a new `AusfUeContext` and stores it under that SUPI key without checking whether an authentication procedure is already in pr…

CVE-2026-55784
NVD

HIGH
CVE-2026-82333
CVE-2026-82333
pkg: node

published: Aug 28, 2026

multer is a middleware for handling multipart/form-data in Node.js. A small multipart request with two specially crafted text field names can make multer's field parser synchronously iterate a maximum-length sparse array, blocking the event loop so the process cannot handle other requests. A large n…
CWE: CWE-400
NVD

HIGH
CVE-2026-81518
CVE-2026-81518
pkg: tls

published: Aug 28, 2026

When mongosqld is configured with a client certificate authority file, the listener requests a client certificate during the TLS handshake but does not require one, so a client that presents no certificate is still accepted. In deployments that rely on client certificates as the sole means of identi…
CWE: CWE-295
NVD

HIGH
CVE-2026-77078
CVE-2026-77078
pkg: node

published: Aug 28, 2026

multer is a middleware for handling multipart/form-data in Node.js. A small multipart request containing two specially crafted text field names can cause an uncaught RangeError (Invalid array length) that terminates the Node.js process. The first field uses a very large numeric array index to alloca…
CWE: CWE-248
NVD

HIGH
CVE-2026-77037
CVE-2026-77037
pkg: node

published: Aug 28, 2026

multer is a middleware for handling multipart/form-data in Node.js. In version 2.2.0, when a disk-backed upload is aborted or truncated before the write stream finishes, multer's disk storage engine removes the visible file but does not close the underlying write file descriptor, leaving a deleted b…
CWE: CWE-400, CWE-459
GitHub-GHSA

HIGH
Fortigate syslog message parser can be exploited to modify or delete fields from the original message
GHSA-gqr6-r77p-c2pj
pkg: org.graylog2:graylog2-server, org.graylog2:graylog2-server, org.graylog2:graylog2-server
eco: maven
published: Aug 28, 2026
### Impact

A security issue has been identified in Graylog affecting the parsing of syslog messages that use a key-value format, such as those generated by Fortigate devices.

The vulnerability allows attackers to overwrite individual message fields, or to produce invalid messages which Graylog wil…

CVE-2026-55841
NVD

HIGH
CVE-2026-55215
CVE-2026-55215
pkg: ssl

published: Aug 28, 2026

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to versions 3.3.3, 3.4.6, and 3.5.3, when ssl is enabled without a pinned CA or server certificate, MariaDB Connector/Node.js sends credentials before completing certificate fingerpri…
CWE: CWE-295, CWE-522
GitHub-GHSA

HIGH
alos-http has unauthenticated remote DoS: malformed path starting with "?" triggers out-of-bounds panic in sanitizeRequestPath, crashing entire server
GHSA-hr6j-w4mw-g9mj
pkg: github.com/guno1928/alos-http
eco: go
published: Aug 28, 2026
### Summary
A single unauthenticated HTTP request to a path starting with `?` (e.g. `GET ? HTTP/1.1`) crashes the entire server process.
The request line parser passes the path to `sanitizeRequestPath` which indexes the first byte of the path after stripping the query string. It does so without chec…
CVE-2026-55484
GitHub-GHSA

HIGH
MariaDB's connector leaks the cleartext password to an MitM despite `ssl: true`
GHSA-cqhc-2h57-wpxf
pkg: mariadb, mariadb, mariadb
eco: npm
published: Aug 28, 2026
### Summary
When SSL/TLS is enabled but no CA / server certificate is provided, the
connector verifies the server's identity using fingerprint validation. The
check is effective, the connection is ultimately rejected when it fails,
but it happens *after* the authentication exchange. As a result, t…
CVE-2026-55215
GitHub-GHSA

HIGH
Spinnaker: Improper yaml processing on kustomize bake operations
GHSA-p68j-q7hf-3qcp
pkg: io.spinnaker.rosco:rosco-manifests, io.spinnaker.rosco:rosco-manifests, io.spinnaker.rosco:rosco-manifests
eco: maven
published: Aug 28, 2026
### Impact
Kustomize bake operations allow unsafe tag processing. This can lead to RCE type exploits on the rosco pods when doing kustomize bakes. This ONLY is possible when using Kustomize. The simple solution is to block kustomize operations and instead use another provider.

### Workarounds
Di…

CVE-2026-55175
GitHub-GHSA

HIGH
Yamcs has Unauthenticated Directory Traversal
GHSA-9jg3-g3wh-w9pj
pkg: org.yamcs:yamcs-core
eco: maven
published: Aug 28, 2026
### Attack type: 
Unauthenticated remote 

### Impact:
Attackers can access any system files from the underlying host.

### Affected components: HttpRequestHandler.java, StaticFileHandler.java

An Unauthenticated Directory Traversal vulnerability exists in Yamcs <=5.8.6, allowing anyone to acc…

CVE-2026-55552
GitHub-GHSA

HIGH
datadog-opentelemetry has unbounded W3C tracestate parsing that may lead to DoS
GHSA-gpwf-4h98-v82q
pkg: datadog-opentelemetry
eco: rust
published: Aug 28, 2026
### Impact
Datadog tracing libraries that implement W3C Trace Context (`tracecontext`) propagation parse the incoming `tracestate` header without enforcing a size cap on the Datadog vendor entry (`dd=…`). The `dd=` value contains semicolon-separated `key:value` pairs, and the parser allocates a ha…
CVE-2026-54788
NVD

HIGH
CVE-2026-75418
CVE-2026-75418
pkg: windows

published: Aug 28, 2026

A path traversal vulnerability exists in the built-in preview/development web server of Lektor <3.3.14 on Windows. An attacker with network access to the server can send a crafted HTTP request containing path traversal sequences to read arbitrary files accessible to the process, disclosing sensitive…
NVD

HIGH
CVE-2026-81721
CVE-2026-81721
pkg: openssl

published: Aug 27, 2026

openssl_encrypt before 1.4.9 fails to validate KDF cost parameters in encrypted file metadata and keystore headers, allowing attackers to trigger unbounded memory allocation. Attackers can craft malicious encrypted files declaring arbitrarily large Argon2, scrypt, or balloon KDF parameters to exhaus…
CWE: CWE-400
NVD

HIGH
CVE-2026-81718
CVE-2026-81718
pkg: openssl

published: Aug 27, 2026

openssl_encrypt versions before 1.4.9 use under-parameterized PBKDF2-HMAC-SHA256 with only 100,000 iterations to protect PQC keyfile private keys and 10,000 iterations for dual-encryption file-password verification. Attackers who obtain keyfiles or encrypted files can brute-force wrapping passwords …
CWE: CWE-326
NVD

HIGH
CVE-2026-81705
CVE-2026-81705
pkg: openssl

published: Aug 27, 2026

openssl-encrypt before 1.4.9 fails to redact the file password in its –debug argv dump when the password is supplied via bundled short-option spellings (e.g. -apHunter2) or abbreviated long-option spellings (e.g. –passw). The sanitizer only recognized exact option names, –option=value forms, and …
CWE: CWE-532
NVD

HIGH
CVE-2026-81704
CVE-2026-81704
pkg: openssl

published: Aug 27, 2026

openssl_encrypt versions before 1.4.9 contain a weak key derivation vulnerability in the D-Bus CryptoService.EncryptFile handler that uses unstretched SHA-256 instead of Argon2id. Attackers can perform offline password guessing against encrypted files roughly six to seven orders of magnitude faster …
CWE: CWE-916
NVD

HIGH
CVE-2026-81699
CVE-2026-81699
pkg: openssl

published: Aug 27, 2026

openssl_encrypt versions before 1.4.9 fail to properly validate key derivation function costs in crafted files, allowing attackers to trigger unbounded memory and CPU exhaustion during pre-authentication processing. Attackers can supply malicious files with excessive KDF parameters to exhaust system…
CWE: CWE-770
NVD

HIGH
CVE-2026-81698
CVE-2026-81698
pkg: openssl

published: Aug 27, 2026

openssl_encrypt versions before 1.4.9 contain a shell injection vulnerability in the info command's reconstructed CLI block that interpolates untrusted metadata fields without quoting. Attackers can craft metadata values like pepper_name containing shell commands that execute when users copy the pri…
CWE: CWE-78
NVD

HIGH
CVE-2026-81693
CVE-2026-81693
pkg: openssl

published: Aug 27, 2026

openssl_encrypt before 1.4.9 fails to validate the total field from QR JSON payloads before materializing ranges. Attackers can supply crafted QR images with extremely large total values to trigger unbounded memory allocation and cause denial of service through out-of-memory conditions.
CWE: CWE-789
NVD

HIGH
CVE-2026-81692
CVE-2026-81692
pkg: openssl

published: Aug 27, 2026

openssl_encrypt (pip: openssl-encrypt) versions 1.4.8 and earlier fail to validate the 36-bit STREAMINFO total_samples field of FLAC files before using it to size an allocation (np.random.randint(size=(total_samples, channels))). A ~50-byte crafted FLAC file declaring ~100 million samples causes a m…
CWE: CWE-789
NVD

HIGH
CVE-2026-81691
CVE-2026-81691
pkg: openssl

published: Aug 27, 2026

openssl_encrypt versions before 1.4.9 fail to validate server URLs in login and register_with_email functions, accepting unencrypted http:// URLs and unconfigured hosts. Attackers on the network path can intercept cleartext credentials including client_id, passwords, and JWTs to achieve full keyserv…
CWE: CWE-319
NVD

HIGH
CVE-2026-81689
CVE-2026-81689
pkg: openssl

published: Aug 27, 2026

openssl_encrypt versions before 1.4.9 derive the remote-pepper wrap key using unsalted HKDF-SHA256 or bare SHA-256 of the password, allowing identical keys across all users and files. Attackers with access to wrapped pepper blobs can precompute a single dictionary table and perform fleet-wide offlin…
CWE: CWE-916
NVD

HIGH
CVE-2026-81688
CVE-2026-81688
pkg: openssl

published: Aug 27, 2026

openssl_encrypt versions before 1.4.9 store an unkeyed SHA-256 hash of the plaintext in the cleartext file header metadata. Attackers can read this hash without the password to confirm guessed plaintexts offline or fingerprint identical plaintexts across separately-encrypted files.
CWE: CWE-311
NVD

HIGH
CVE-2026-47889
CVE-2026-47889
pkg: react

published: Aug 27, 2026

A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute.
Spring Framework 7.0.0 – 7.0.8
Spring Framework 6.2.0 – 6.2.19
CWE: CWE-1275
NVD

HIGH
CVE-2026-47886
CVE-2026-47886
pkg: express

published: Aug 27, 2026

Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power operator (^) is used with a BigDecimal or BigInteger operand and a large exponent value.
Spring Framework 7.0.0 – 7.0.8
Spring Framework 6.2.0 -…
CWE: CWE-400
NVD

HIGH
CVE-2026-19715
CVE-2026-19715
pkg: oauth

published: Aug 27, 2026

The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.3.1 does not restrict access to the debug log it writes, which is stored at a fixed and publicly reachable location, allowing unauthenticated users to read the OAuth tokens and authorisation codes it has issued as well as user re…
CWE: CWE-200
NVD

HIGH
CVE-2026-80520
CVE-2026-80520
pkg: linux

published: Aug 26, 2026

In the Linux kernel, the following vulnerability has been resolved:

ovpn: fix NULL dereference when killing missing key

ovpn_crypto_kill_key assumes both crypto slots are populated and
dereferences each slot before checking it. That is not guaranteed: a
peer can have only one installed key, and th…

NVD

HIGH
CVE-2026-74750
CVE-2026-74750
pkg: linux

published: Aug 26, 2026

In the Linux kernel, the following vulnerability has been resolved:

ovpn: defer key slot crypto freeing to workqueue

Key slots are released through a kref and the existing release path
frees the AEAD transforms from an RCU callback. That is not safe for all
crypto implementations: crypto_free_aead…

NVD

HIGH
CVE-2026-74745
CVE-2026-74745
pkg: linux

published: Aug 26, 2026

In the Linux kernel, the following vulnerability has been resolved:

eth: bnxt: avoid deadlock when canceling IRQ affinity notifier

Unregistering IRQ affinity notifiers waits for the callback synchronously.
bnxt takes the netdev instance lock in the notifier (to restart the queue)
and cancels the w…

NVD

HIGH
CVE-2026-74742
CVE-2026-74742
pkg: linux

published: Aug 26, 2026

In the Linux kernel, the following vulnerability has been resolved:

veth: fix queue index used to wake the peer txq in veth_poll

veth_poll() derives the index of the peer TX queue to wake from
rq->xdp_rxq.queue_index. That field is only initialized by
xdp_rxq_info_reg() in veth_enable_xdp_range(),…

NVD

HIGH
CVE-2026-74741
CVE-2026-74741
pkg: linux

published: Aug 26, 2026

In the Linux kernel, the following vulnerability has been resolved:

net: ngbe: fix NULL pointer dereference in non-MSI-X interrupt enabling

In non-MSI-X mode (such as legacy INTx or single MSI), wx->msix_entry is
not allocated or initialized. Calling NGBE_INTR_MISC(wx) dereferences
wx->msix_entry-…

NVD

HIGH
CVE-2026-80205
CVE-2026-80205
pkg: express

published: Aug 26, 2026

NLTK versions before 3.10.0 contain a regular expression denial of service vulnerability in Text.findall() and TokenSearcher.findall() methods that accept user-supplied regular expressions without validation or timeout. Attackers can supply crafted regex patterns that cause catastrophic backtracking…
CWE: CWE-1333
NVD

HIGH
CVE-2026-79139
CVE-2026-79139
pkg: google chrome, microsoft windows

published: Aug 25, 2026

Improper input validation in Media in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-20
NVD

HIGH
CVE-2026-78915
CVE-2026-78915
pkg: google chrome, microsoft windows

published: Aug 25, 2026

Race condition in Enterprise in Google Chrome on on Windows prior to 152.0.7977.65 allowed an adjacent attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Low)
CWE: CWE-362
NVD

HIGH
CVE-2026-78906
CVE-2026-78906
pkg: google chrome

published: Aug 25, 2026

Race condition in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-362
NVD

HIGH
CVE-2026-78901
CVE-2026-78901
pkg: google chrome

published: Aug 25, 2026

Race condition in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-362
NVD

HIGH
CVE-2026-65097
CVE-2026-65097
pkg: linux

published: Aug 25, 2026

NVIDIA NemoClaw for Linux contains a vulnerability in its installation scripts, where an attacker could cause a download of code without integrity check. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
CWE: CWE-494
NVD

HIGH
CVE-2026-55099
CVE-2026-55099
pkg: python

published: Aug 25, 2026

icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python. From 7.1.0 until 7.1.3, the Component equality method in src/icalendar/cal/component.py compares nested subcomponents with two membership loops, and each membership test invokes the same method on child component…
CWE: CWE-400, CWE-407
GitHub-GHSA

HIGH
icalendar has Algorithmic Complexity in Equality
GHSA-cv84-9p8j-fj68
pkg: icalendar
eco: pip
published: Aug 25, 2026
### Summary

`Component.__eq__` compares subcomponents in `O(2^n)` time relative to nesting depth. Because the parser accepts arbitrarily nested components, a sub-kilobyte `.ics` file is enough to make a single equality check run for minutes or hang indefinitely. Any application that compares parsed…

CVE-2026-55099
NVD

HIGH
CVE-2026-55620
CVE-2026-55620
pkg: python

published: Aug 25, 2026

eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information. Prior to 3.0.2, eml_parser.routing.noparenthesis in eml_parser/routing.py removes parenthesized CFWS comments from Received: headers with a regex-based fi…
CWE: CWE-770, CWE-1124
GitHub-GHSA

HIGH
eml_parser vulnerable to DoS via deeply nested parens in Received headers
GHSA-g7gc-gmgp-wgqg
pkg: eml_parser
eco: pip
published: Aug 25, 2026
### Summary

`eml_parser` strips parenthesised CFWS comments from `Received:` headers using a regex-based fix-point loop. The loop has quadratic time complexity in the number of nested parens. A single `Received:` header containing 5,000 nested parens causes ~1.3 seconds of CPU saturation per parsed…

CVE-2026-55620
GitHub-GHSA

HIGH
Trivy has a path traversal via a crafted vulnerability database or other downloaded artifacts
GHSA-mcj4-mphf-j9ff
pkg: github.com/aquasecurity/trivy
eco: go
published: Aug 25, 2026
## Summary

When Trivy downloads an OCI artifact, it uses the `org.opencontainers.image.title` annotation from the artifact manifest as the destination filename without validation. An attacker who can make Trivy fetch an attacker-controlled artifact can supply a crafted annotation that resolves to a…

CVE-2026-55092
NVD

HIGH
CVE-2026-55553
CVE-2026-55553
pkg: node

published: Aug 25, 2026

urllib is an HTTP client for Node.js that supports authentication, redirects, timeouts, and other request features. Prior to 4.9.1 and 2.44.1, urllib follows redirects through followRedirect but reuses caller-supplied options across origins. In src/HttpClient.ts, #requestInternal recursively calls t…
CWE: CWE-200, CWE-201, CWE-522
GitHub-GHSA

HIGH
urllib's cross-origin redirects preserve credential-bearing request headers, leading to potential credential leakage
GHSA-hq3h-g68c-hp78
pkg: urllib, urllib
eco: npm
published: Aug 25, 2026
## Summary

urllib supports redirect-following through `followRedirect`, which is expected behavior for an HTTP client. The issue is that, when following a redirect to a **different origin**, urllib preserves the caller-supplied request headers verbatim, including credential-bearing headers such as …

CVE-2026-55553
NVD

HIGH
CVE-2026-79770
CVE-2026-79770
pkg: express

published: Aug 25, 2026

Nokogiri versions before 1.19.3 contain regular expression denial of service vulnerabilities in the CSS selector tokenizer affecting string-literal and identifier tokenization. Attackers can inject adversarial CSS selectors into methods like Node#css, Node#at_css, and Searchable#search to cause expo…
CWE: CWE-1333
GitHub-GHSA

HIGH
Echo: Encoded slash (%2F) bypasses route-level protection and exposes static files
GHSA-vfp3-v2gw-7wfq
pkg: github.com/labstack/echo/v5, github.com/labstack/echo/v4, github.com/labstack/echo
eco: go
published: Aug 25, 2026
### Summary

Echo's router and static file handler disagree on URL path decoding. The router matches routes using the raw encoded path (preserving `%2F` as-is), while `StaticDirectoryHandler` unescapes `%2F` to `/` before resolving filesystem paths. This allows an attacker to bypass route-level acce…

CVE-2026-55677
GitHub-GHSA

HIGH
praisonaiagents vulnerable to SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap)
GHSA-vg6p-v9vm-6fgj
pkg: praisonaiagents
eco: pip
published: Aug 25, 2026
The web_crawl tool performs its SSRF check only on the initial URL: it resolves the hostname once
with socket.gethostbyname and rejects private/loopback/link-local results. It then passes the URL to
a fetcher that uses httpx.Client(follow_redirects=True) – or urllib.request.urlopen when httpx is
abs…
CVE-2026-55524
GitHub-GHSA

HIGH
praisonaiagents web_crawl vulnerable to SSRF via redirect-following
GHSA-5r34-2g38-6569
pkg: praisonaiagents
eco: pip
published: Aug 25, 2026
### Summary
`web_crawl` (an exported, model-callable tool) validates only the INITIAL URL's resolved IP against a private/loopback blocklist, then fetches with `httpx.Client(follow_redirects=True)` and never re-validates redirect targets.

An attacker who controls the agent's crawl target (a malici…

CVE-2026-55525
NVD

HIGH
CVE-2026-63076
CVE-2026-63076
pkg: openssl

published: Aug 25, 2026

Issue summary: OpenSSL CMP password based protection verification only
checks whether the protectionAlg parameter was not NULL and not its
ASN.1 type, before treating it as a PBMParameter. A crafted message can
contain a parameter of a different type, which is then dereferenced as an
invalid pointer…
CWE: CWE-476
NVD

HIGH
CVE-2026-63075
CVE-2026-63075
pkg: openssl

published: Aug 25, 2026

Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly
sends ack-eliciting packets while not acknowledging ACK-only responses, the
QUIC stack can retain ACK-only packet metadata for the lifetime of the
connection.

Impact summary: A remote peer that can complete a QUIC handsh…

CWE: CWE-770
NVD

HIGH
CVE-2026-63072
CVE-2026-63072
pkg: openssl

published: Aug 25, 2026

Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based
on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive
can write and cleanse more bytes than that query reports, causing an 8-byte
out-of-bounds heap write.

Impact summary: An attacker who supplies a c…

CWE: CWE-787
NVD

HIGH
CVE-2026-54874
CVE-2026-54874
pkg: openssl

published: Aug 25, 2026

Issue summary: Receiving a DTLS record for a future epoch while a handshake
is in progress causes OpenSSL to buffer far more memory than the record
itself requires.

Impact summary: A peer can use a small amount of network traffic to make an
OpenSSL DTLS endpoint retain a disproportionately large am…

CWE: CWE-405
NVD

HIGH
CVE-2026-18798
CVE-2026-18798
pkg: openssl

published: Aug 25, 2026

Issue summary: QUIC server may double free QRX (QUIC record layer RX) object
when channel creation fails for initial packet.

Impact summary: Double free leads to heap corruption, which typically results in
termination of QUIC server process, leading to Denial of Service. There is so
far no evidenc…

CWE: CWE-415
NVD

HIGH
CVE-2026-14457
CVE-2026-14457
pkg: ssl

published: Aug 25, 2026

Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs)
enabled, and only the private key (with no associated certificate) configured locally,
a NULL pointer dereference may occur when the remote peer solicits raw public keys and
also sends the typically omitted "signa…
CWE: CWE-476
NVD

HIGH
CVE-2026-79658
CVE-2026-79658
pkg: go

published: Aug 25, 2026

Ech0 before 5.0.1 does not impose any size or shape limit on the Accept-Language header processed by its i18n middleware, which runs on every HTTP request. The header is passed unfiltered to go-i18n's NewLocalizer, which internally calls golang.org/x/text/language.ParseAcceptLanguage. The CVE-2022-3…
CWE: CWE-400
NVD

HIGH
CVE-2026-66766
CVE-2026-66766
pkg: express

published: Aug 25, 2026

SAP S/4HANA (Private Cloud) uses a third-party component that contains a Regular Expression Denial of Service (ReDoS) vulnerability. An unauthenticated attacker could supply specially crafted input that triggers excessive processing within the affected functionality. Successful exploitation could ex…
CWE: CWE-1333
NVD

HIGH
CVE-2026-76098
CVE-2026-76098
pkg: python

published: Aug 24, 2026

Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates deeply nested emphasis tokens from consecutive asterisk characters, and recursive rendering in HTMLRenderer.render_token() can excee…
CWE: CWE-674
GitHub-GHSA

HIGH
Apache Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never validated, so any unexpired token signed by a trusted key was accepted
GHSA-fpm2-m4qq-wghr
pkg: org.apache.camel:camel-platform-http-main
eco: maven
published: Aug 24, 2026
Improper Authentication vulnerability in Apache Camel Platform HTTP Main component.

This issue affects Apache Camel: from 4.8.0 before 4.22.0.

The camel-main embedded HTTP server can protect its endpoints with JWT authentication, configured through authenticationEnabled together with the JWT keyst…

CVE-2026-66908
GitHub-GHSA

HIGH
Apache Camel-Google-Storage: the consumer appended the remote object name to the configured downloadFileName directory without constraining the result
GHSA-f78g-9385-qxqj
pkg: org.apache.camel:camel-google-storage, org.apache.camel:camel-google-storage, org.apache.camel:camel-google-storage
eco: maven
published: Aug 24, 2026
Relative path traversal vulnerability in Apache Camel Google Storage component.

This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0.

The camel-google-storage consumer downloads Google Cloud Storage objects to the local filesystem when the…

CVE-2026-66907
NVD

HIGH
CVE-2026-66908
CVE-2026-66908
pkg: apache camel

published: Aug 24, 2026

Improper Authentication vulnerability in Apache Camel Platform HTTP Main component.

This issue affects Apache Camel: from 4.8.0 before 4.22.0.

The camel-main embedded HTTP server can protect its endpoints with JWT authentication, configured through authenticationEnabled together with the JWT k…

CWE: CWE-287
NVD

HIGH
CVE-2026-66907
CVE-2026-66907
pkg: apache camel

published: Aug 24, 2026

Relative path traversal vulnerability in Apache Camel Google Storage component.

This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0.

The camel-google-storage consumer downloads Google Cloud Storage objects to the local filesystem when…

CWE: CWE-23
NVD

HIGH
CVE-2026-76848
CVE-2026-76848
pkg: express

published: Aug 24, 2026

TypeORM's SelectQueryBuilder.distinctOn accepts an array of strings and stores it on the expression map without validation. For PostgreSQL-family drivers, createSelectDistinctExpression in src/query-builder/SelectQueryBuilder.ts joins that array and interpolates the result into the generated stateme…
CWE: CWE-89
NVD

HIGH
CVE-2026-76172
CVE-2026-76172
pkg: node

published: Aug 24, 2026

fast-uri is a URI parser for Node.js. During parsing it runs a legacy decoding pass over the scheme component and never re-escapes the result, and serialization writes the scheme back out verbatim, unlike the host component which is re-escaped. As a result an input whose scheme carries percent-encod…
CWE: CWE-177
NVD

HIGH
CVE-2026-75975
CVE-2026-75975
pkg: node

published: Aug 24, 2026

fast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not validate the complete IPv6 grammar, so invalid trailing text in an authority can be silently discarded and a malformed attacker-controlled host is turned into a different valid IPv6 destination. For example,…
CWE: CWE-20, CWE-918
NVD

HIGH
CVE-2026-75931
CVE-2026-75931
pkg: node

published: Aug 24, 2026

fast-uri is a URI parser for Node.js. It canonicalizes a host to its ASCII form only when the input carries an explicit scheme, so a scheme-relative reference such as a host preceded by two slashes is returned with its host verbatim and no error set. As a result fast-uri's own entry points disagree …
CWE: CWE-436
NVD

HIGH
CVE-2026-75899
CVE-2026-75899
pkg: node

published: Aug 24, 2026

fast-uri is a URI parser for Node.js. It decodes percent escapes in a hostname during parsing and then decodes the parsed hostname a second time during authority recomposition, so a single call to normalize or resolve can turn nested percent-encoded input into a different network destination such as…
CWE: CWE-174, CWE-918
NVD

HIGH
CVE-2026-81020
CVE-2026-81020
pkg: tls

published: Aug 28, 2026

wolfEngine before 1.4.1 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record. As a result every TLS 1.2 and DTLS 1.2 AES-GCM record within a connection is encrypted under an identical key and nonce pair. Reusing a GCM key and nonce disclos…
CWE: CWE-323
NVD

HIGH
CVE-2026-81019
CVE-2026-81019
pkg: tls

published: Aug 28, 2026

wolfProvider before 1.2.2 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record. As a result every TLS 1.2 and DTLS 1.2 AES-GCM record within a connection is encrypted under an identical key and nonce pair. Reusing a GCM key and nonce discl…
CWE: CWE-323
NVD

HIGH
CVE-2026-73208
CVE-2026-73208
pkg: oauth

published: Aug 28, 2026

An attacker that holds a token intended for a different purpose can authenticate, because when an OAuth2 token response does not contain a scope claim, the audience claim is used in its place and checked against the configured required scopes. These are different concepts, and the audience claim doe…
CWE: CWE-287
NVD

HIGH
CVE-2026-18717
CVE-2026-18717
pkg: tls

published: Aug 28, 2026

ASE2000 2.35 through 2.37 is vulnerable to an improper certificate validation vulnerability, which may allow an attacker to impersonate the trusted peer, complete the TLS handshake, and read or modify protected communications.
CWE: CWE-295
GitHub-GHSA

HIGH
IzPack has Path Traversal in UnpackerBase that allows writing files outside the installation directory via malicious pack entries
GHSA-f63g-88cj-hjf9
pkg: org.codehaus.izpack:izpack-installer
eco: maven
published: Aug 26, 2026
### Summary

IzPack's `UnpackerBase.unpack()` resolves pack-file target paths without any
canonical-path or directory-containment check. An attacker who distributes a
trojanized installer JAR (the format is unsigned) can include pack entries whose
`targetPath` contains `../` sequences. When a victim…

CVE-2026-54550
NVD

HIGH
CVE-2026-41707
CVE-2026-41707
pkg: jwt

published: Aug 25, 2026

Authentication Bypass by Capture-replay vulnerability in Spring Spring Security allows Spring Security's DPoPProofJwtDecoderFactory contains a cache-based replay attack vulnerability. The internal cache storing JWT ID claims has a strict size limit, allowing attackers to evict legitimate entries by …
CWE: CWE-294
NVD

HIGH
CVE-2026-79664
CVE-2026-79664
pkg: jwt

published: Aug 25, 2026

Ech0 before 4.7.3 fails to properly revoke access tokens created with never-expire option, allowing attackers to maintain perpetual authenticated access after token theft. Three independent revocation mechanisms fail: logout panics on nil ExpiresAt field, RevokeToken skips when remainTTL is zero, an…
CWE: CWE-613
NVD

HIGH
CVE-2026-76844
CVE-2026-76844
pkg: webpack

published: Aug 24, 2026

webpack-dev-middleware resolves a request to a local file in getFilenameFromUrl by testing the request pathname against a traversal guard and then slicing it at a fixed character offset. The guard, UP_PATH_REGEXP applied to path.normalize(`./${pathname}`), only matches ".." that stands as a whole pa…
CWE: CWE-22
NVD

HIGH
CVE-2026-81690
CVE-2026-81690
pkg: openssl

published: Aug 27, 2026

openssl-encrypt (pip package) before 1.4.9 contains a symlink-following flaw in its verify-usb v2 added-file allowlist scan. The scan enumerated the drive with rglob(), which in CPython does not descend into symlinked directories and treats the symlink as an ordinary directory, while O_NOFOLLOW on t…
CWE: CWE-59
GitHub-GHSA

HIGH
PraisonAI: [Auth Bypass] `praisonai serve agents –api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticated
GHSA-r7v3-x45f-g7hp
pkg: PraisonAI
eco: pip
published: Aug 25, 2026
### Summary
`praisonai serve agents` exposes HTTP routes that invoke registered agents. The CLI advertises `–api-key` with help text "API key for authentication", parses it, and forwards it into `ServeHandler`. But `_create_agents_app()` **never reads `config["api_key"]` again** and installs no aut…
CVE-2026-55538
NVD

HIGH
CVE-2026-78637
CVE-2026-78637
pkg: node

published: Aug 25, 2026

A vulnerability was detected in Fdawgs node-poppler up to 9.1.2/10.0.1. The impacted element is the function pdfInfo/pdfToText/pdfToCairo/pdfToPpm/pdfImages/pdfToHtml/pdfToPs/pdfFonts/pdfDetach/pdfAttach/pdfSeparate/pdfUnite of the file src/index.js of the component Argument Injection Handler. Perfo…
CWE: CWE-74, CWE-88
NVD

HIGH
CVE-2026-45019
CVE-2026-45019
pkg: python

published: Aug 25, 2026

Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose the POST /mcp endpoint without requiring authentication. For sse and streamable-http tra…
CWE: CWE-918
GitHub-GHSA

HIGH
Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access
GHSA-hvfh-5mj3-5f3j
pkg: chainlit
eco: pip
published: Aug 25, 2026
### Am I affected?

Only if your deployment sets `features.mcp.enabled = true` in `.chainlit/config.toml`. **MCP has been disabled by default since v2.7.0**, so most Chainlit deployments are not affected. No authentication is required: `/mcp` is reachable by any client that can open a session.

### …

CVE-2026-45019
GitHub-GHSA

HIGH
3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation
GHSA-jm48-m3rr-9hgg
pkg: github.com/mhsanaei/3x-ui/v3, github.com/mhsanaei/3x-ui/v2
eco: go
published: Aug 24, 2026
# Summary

An authenticated administrator can abuse the database import functionality to achieve arbitrary file write on the host by modifying Xray configuration values stored in the database. This can be leveraged to obtain code execution and persistent access as the user running Xray (including ro…

CVE-2026-55477
NVD

HIGH
CVE-2026-71364
CVE-2026-71364
pkg: node

published: Aug 24, 2026

A path traversal vulnerability was found in AWX's project archive extraction. The project_archive action plugin extracts zip and tar archive members by joining the project directory path with the member filename without performing path normalization, boundary validation, or rejecting directory trave…
CWE: CWE-22
GitHub-GHSA

HIGH
Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id
GHSA-5pg6-m483-7vrg
pkg: code.vikunja.io/api
eco: go
published: Aug 28, 2026
## Summary

The kanban endpoint `POST /api/v1/projects/{project}/views/{view}/buckets/{bucket}/tasks`
moves a task into a bucket. The task is identified by `task_id` in the **request
body**. The endpoint's authorization check (`TaskBucket.CanUpdate`) only verifies
that the caller may update the *pro…

CVE-2026-55066
NVD

HIGH
CVE-2026-54085
CVE-2026-54085
pkg: windows

published: Aug 28, 2026

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.2.0 through 4.14.6, multiple active response scripts pass attacker-influenced alert fields to privileged system commands without validating their format, allowing argu…
CWE: CWE-88
NVD

HIGH
CVE-2026-80426
CVE-2026-80426
pkg: react

published: Aug 26, 2026

FiftyOne renders a dataset field's description as markup. The sidebar field-information component at app/packages/core/src/components/FieldLabelAndInfo/index.tsx passes the description string to React's dangerouslySetInnerHTML, and no layer between storage and render escapes or sanitises it; the nei…
CWE: CWE-79
GitHub-GHSA

HIGH
Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root
GHSA-w5fv-7x5q-g8qp
pkg: github.com/cloudreve/Cloudreve/v4, github.com/cloudreve/Cloudreve/v3
eco: go
published: Aug 26, 2026
## Summary

A Cloudreve WebDAV account stores a `uri` that defines the account's root folder. The WebDAV request handler (`stripPrefix` in `pkg/webdav/webdav.go`) trims the `/dav` prefix from the request path and joins the remainder to that root with `fs.URI.JoinRaw`, but never checks that the joine…

CVE-2026-54563
GitHub-GHSA

HIGH
Budibase authenticated arbitrary S3 signed upload URL issuance via `/api/attachments/:datasourceId/url`
GHSA-6x9p-4r67-5gjx
pkg: @budibase/server
eco: npm
published: Aug 26, 2026
### Summary
Budibase 3.39.7 allows a low-privilege authenticated published-app user with the built-in BASIC role to obtain arbitrary S3 pre-signed upload URLs backed by a workspace datasource's stored server-side credentials.

The affected endpoint is:

`POST /api/attachments/:datasourceId/url`

The…

CVE-2026-54356
NVD

HIGH
CVE-2026-78892
CVE-2026-78892
pkg: windows

published: Aug 25, 2026

Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a local attacker to bypass system access restrictions via a local program. (Chromium security severity: Medium)
CWE: CWE-863
NVD

HIGH
CVE-2026-79786
CVE-2026-79786
pkg: oauth

published: Aug 25, 2026

Coroot's unauthenticated MCP OAuth dynamic client registration endpoint accepts any syntactically valid redirect URI without validation, allowing attackers to register clients pointing to attacker-controlled hosts. Attackers can send authorization URLs to signed-in users, capture their authorization…
CWE: CWE-601
GitHub-GHSA

HIGH
consciousness-explorer / sublinear-time-solver MCP export_state has an arbitrary file write
GHSA-xc9g-j69q-37xw
pkg: consciousness-explorer, sublinear-time-solver
eco: npm
published: Aug 25, 2026
### Impact
An arbitrary file write vulnerability (CWE-73, External Control of File Name or Path) exists in the `consciousness-explorer` component of `sublinear-time-solver`. The MCP `export_state` (and `import_state`) tool accepted a user-supplied `filepath` argument and passed it directly to `fs.wr…
CVE-2026-55609
GitHub-GHSA

HIGH
utcp-http has an OAuth2 `tokenUrl` Trust Boundary Bypass in OpenAPI Conversion
GHSA-8cp3-qxj6-px34
pkg: utcp-http
eco: pip
published: Aug 25, 2026
### Summary

The `utcp-http` library (<= 1.1.3) unconditionally trusts the `tokenUrl` field embedded in remote OpenAPI security schemes. When a victim registers an attacker-controlled OpenAPI spec and invokes any generated OAuth2-protected tool, the library POSTs the victim's `client_id` and `client…

GitHub-GHSA

HIGH
praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location
GHSA-gxmw-5f7x-6g22
pkg: praisonaiagents
eco: pip
published: Aug 25, 2026
### Summary

`praisonaiagents/memory/file_memory.py::FileMemory.__init__()` constructs all
memory file paths by directly joining the `user_id` parameter to a base path:

“`python
self.user_path = self.base_path / user_id # LINE 145 — no sanitization
“`

No validation or normalization is app…

CVE-2026-55527
GitHub-GHSA

HIGH
PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114
GHSA-rg5q-pp8p-f7jm
pkg: PraisonAI
eco: pip
published: Aug 25, 2026
### Summary

`praisonai/jobs/models.py::JobSubmitRequest.validate_webhook_url()` validates webhook
URLs by resolving the hostname and checking whether the IP is private. When DNS
resolution fails (`socket.gaierror`), the validator **silently passes** the URL via
`except socket.gaierror: pass`. Addit…

CVE-2026-55537
GitHub-GHSA

HIGH
PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks
GHSA-ch89-h4r2-c8f8
pkg: PraisonAI
eco: pip
published: Aug 25, 2026
### Summary
PraisonAI's `praisonai.code` tool wrappers (exported as `CODE_TOOLS` for agents) expose a `workspace` setting that the module itself treats as a path-traversal **security boundary** — `read_file`, `write_file`, `apply_diff`, and `search_replace` explicitly call `is_path_within_director…
CVE-2026-55540
GitHub-GHSA

HIGH
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
GHSA-8jj7-4v57-frf5
pkg: django-cms
eco: pip
published: Aug 24, 2026
### Summary
The `move_plugin` admin endpoint does not prevent a plugin from being reparented under itself or one of its own descendants. Doing so creates a cycle in the plugin tree, after which the recursive descendant/ancestor SQL queries loop without terminating, stalling the request worker.

CVE-2026-54623
NVD

HIGH
CVE-2026-81714
CVE-2026-81714
pkg: openssl

published: Aug 27, 2026

openssl_encrypt (pip: openssl-encrypt) versions <= 1.4.8 use suffix-tolerant fingerprint matching in enroll_trust_key when binding a plugin-signing trust anchor. An operator who confirms a short (forgeable, ~32-bit) GPG key id could unknowingly enroll an attacker's colliding key as a trusted anchor,…
CWE: CWE-347
NVD

HIGH
CVE-2026-65082
CVE-2026-65082
pkg: linux

published: Aug 25, 2026

NVIDIA NemoClaw for Linux contains a vulnerability in its migration command, where a local attacker could cause code injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.
CWE: CWE-94
NVD

HIGH
CVE-2026-66153
CVE-2026-66153
pkg: linux

published: Aug 25, 2026

The NEService auto-upgrade process insecurely handles temporary files in SonicWall NetExtender Linux client which allows an attacker to manipulate file paths.
CWE: CWE-59
NVD

HIGH
CVE-2026-75037
CVE-2026-75037
pkg: linux

published: Aug 25, 2026

Polkit Authentication Based on UnixProcessSubject / Peer PID in LACT on Linux allows an Authentication Bypass. This issue affects LACT through 0.10.0. Fixed by commit d0478fe42c2219454e272f96b1cbd29ab37ee566.
CWE: CWE-290
NVD

HIGH
CVE-2026-78367
CVE-2026-78367
pkg: express

published: Aug 24, 2026

A vulnerability was found in RPM's rpmbuild tarball processing. When processing a crafted source archive, the getTarSpec() function in tools/rpmbuild.cc passes an attacker-controlled tar archive member name to rpmExpand() as part of a %{basename:…} macro expression. A specially crafted .spec membe…
CWE: CWE-94
GitHub-GHSA

HIGH
Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances
GHSA-x626-fcwx-f5pc
pkg: github.com/portainer/portainer, github.com/portainer/portainer
eco: go
published: Aug 28, 2026
## Summary
Portainer supports restoring an instance from a backup archive via the /api/restore endpoint. This endpoint is intentionally unauthenticated to allow restoring before the first admin account is created, and remains accessible for the five-minute initialization window that opens each time …
CVE-2026-55761
GitHub-GHSA

HIGH
klever-go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupply
GHSA-mrpp-v6pg-p54x
pkg: github.com/klever-io/klever-go
eco: go
published: Aug 28, 2026
## Summary
On the SFT add-quantity path the only supply bound is `SFTAddCirculation`, which does
`meta.Circulation += amount` with **no overflow guard**, then checks
`if meta.Circulation > meta.MaxSupply && meta.MaxSupply != 0`. If `amount` overflows `int64` and wraps
**negative**, `negative > MaxSu…
CVE-2026-55764
GitHub-GHSA

HIGH
klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits
GHSA-v358-wf77-39xv
pkg: github.com/klever-io/klever-go
eco: go
published: Aug 28, 2026
## Summary
In `processPercentageRoyaltiesTransfer` the royalty pool is collected from the sender by `SubFromBalance` that is
ordered **after** the split loop and after `if royaltiesToPay <= 0 { return Ok }`. The split-payout guard rejects
only an allocation that *exceeds* the pool (a strict `splitTo…
CVE-2026-55763
GitHub-GHSA

HIGH
Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching
GHSA-wjmf-p669-5m5p
pkg: Protego
eco: pip
published: Aug 28, 2026
### Problem description

Protego constructs regular expressions to match URLs against `robots.txt` `Allow:` and `Disallow:` directives, see `protego._urlpattern._URLPattern._prepare_pattern_for_regex()`. Every `*` in the directive value is translated into a lazy `.*?` regex piece, thus a specially c…

CVE-2026-55520
GitHub-GHSA

HIGH
PowSyBl Core has Command Injection in LocalCommandExecutor-s
GHSA-jqvf-j3ww-r8c7
pkg: com.powsybl:powsybl-computation-local
eco: maven
published: Aug 28, 2026
### Impact

#### Description
Both `AbstractLocalCommandExecutor` OS-dependent implementations are subject to **CWE-78** (OS Command Injection), with a secondary **CWE-88** (Argument Injection) concern via environment variables.

The local command executor build command strings via concatenation and …

CVE-2026-55673
GitHub-GHSA

HIGH
Bifrost's SSRF deny-list is incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL
GHSA-w98g-5w9p-p3rc
pkg: github.com/maximhq/bifrost/core
eco: go
published: Aug 28, 2026
## Summary

`isPublicIP` in `core/providers/utils/fetch.go` — the SSRF deny-list that gates `FetchAndEncodeURL` — does not reject several routable address ranges that map onto internal infrastructure. Carrier-Grade NAT (`100.64.0.0/10`, RFC 6598), IPv6 6to4 (`2002::/16`), NAT64 (`64:ff9b::/96` a…

CVE-2026-55245
GitHub-GHSA

HIGH
WsgiDAV MySQL provider has a blind SQL injection
GHSA-p6gw-4frg-j7jw
pkg: WsgiDAV
eco: pip
published: Aug 28, 2026
### Summary

The sample `MySQLBrowserProvider` builds its SQL queries by concatenating strings, and the record key from the request URL goes straight into the WHERE clause with no escaping. Any user who can reach a share backed by this provider can inject SQL through the URL. Since these read shares…

CVE-2026-55509
GitHub-GHSA

HIGH
Crossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature check
GHSA-mf7q-r4rv-jv94
pkg: github.com/crossplane/crossplane-runtime/v2, github.com/crossplane/crossplane-runtime/v2
eco: go
published: Aug 27, 2026
## Summary

Crossplane allows package signature verification to be configured via the `ImageConfig` mechanism. When enabled, the package manager uses cosign to verify that packages are correctly signed before pulling and installing them.

When a package is installed using a tag reference (e.g., a se…

GitHub-GHSA

HIGH
SunEditor Embed Plugin has DOM XSS via External Script Element After Iframe Embed
GHSA-w93q-cq9w-58p7
pkg: suneditor
eco: npm
published: Aug 26, 2026
Summary

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the SunEditor Embed plugin. Crafted iframe embed HTML followed by an external <script src=…> element bypasses the plugin’s sanitization logic. The plugin recreates and appends the attacker-controlled script element to the li…

CVE-2026-54606
GitHub-GHSA

HIGH
http4s has HTTP/2 Denial of Service with Ember Backend
GHSA-vmm3-xgcx-67hm
pkg: org.http4s:http4s-ember-core_2.12, org.http4s:http4s-ember-core_2.13, org.http4s:http4s-ember-core_3
eco: maven
published: Aug 26, 2026
### Summary

http4s 0.23.x and 1.0 servers running ember with http2 enabled are vulnerable to a denial of service attack using a HPACK bomb vulnerability recently disclosed as affecting other http2 servers.

### Impact

Denial of Service:
– Affects any http4s server running the ember backend with HT…

CVE-2026-54556
GitHub-GHSA

HIGH
Whistle vulnerable to path traversal
GHSA-3vfr-4gwf-qxfp
pkg: whistle
eco: npm
published: Aug 25, 2026
This bug was found by nova, which is an automated tool from group of Song Wu, intern, Zhejiang University; BoWang, independent researcher; Xingwei Lin, Zhejiang University.

**Vulnerability detail**:

In service.js, inside
`app.get('/cgi-bin/temp/get', …):
var filename = req.query.filename;
if (T…

CVE-2026-55629
GitHub-GHSA

HIGH
genieacs-mcp: DNS rebinding reaches local GenieACS MCP Streamable HTTP transport
GHSA-cmwv-wf9p-p8wx
pkg: github.com/geiserx/genieacs-mcp
eco: go
published: Aug 25, 2026
`genieacs-mcp` exposes a local Streamable HTTP MCP endpoint that accepts attacker-controlled `Host` and `Origin` headers. A malicious web page can use DNS rebinding to route browser requests to a victim's loopback MCP listener while preserving the attacker origin. The server accepts the request, ini…
CVE-2026-55637
GitHub-GHSA

HIGH
mcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment
GHSA-vwf3-4xxj-qg6h
pkg: mcp-contextforge-gateway
eco: pip
published: Aug 25, 2026
### Summary

`mcpgateway.services.prompt_service.PromptService` renders user-supplied prompt templates using Jinja2's plain `Environment()` rather than `SandboxedEnvironment`. An authenticated user with permission to register or update prompt templates can store a malicious template that, on subsequ…

GitHub-GHSA

HIGH
browse-mcp has an arbitrary file write via unconfined download and state paths
GHSA-m9mq-7m7q-xc6p
pkg: browse-mcp
eco: npm
published: Aug 25, 2026
### Impact
`browser_download` wrote a fetched file to `join(save_dir, filename)` with no validation of `save_dir`, and `browser_save_state` / `browser_load_state` honored an explicit `path` unchanged. The MCP caller controls these arguments (a malicious MCP client, or an autonomous agent steered by …
CVE-2026-55557
GitHub-GHSA

HIGH
pickem vulnerable to terminal escape-sequence injection via unsanitized item text
GHSA-8qx3-8gm5-9cj2
pkg: pickem
eco: npm
published: Aug 25, 2026
### Impact
pickem rendered item text (label, description, group, meta, name) to the terminal with no control-character sanitization. `chrome.row` only stripped ANSI from the **active** row; inactive rows, the public `createFormatter`, and selection-summary lines printed labels **raw**, and the ANSI …
GitHub-GHSA

HIGH
mcp-shell — Security Disabled by Default in Bare-Binary Deploy Path + Shell Interpreter in Secure-Mode Allowlist
GHSA-f5pj-2738-996m
pkg: github.com/sonirico/mcp-shell
eco: go
published: Aug 25, 2026
mcp-shell` at commit `17ac0eef5c9a5a42b8fb132d3d034973d55a5433` has two issues that together mean neither the default deploy path nor the recommended "secure mode" delivers the restriction they're marketed as providing. Filing these together because the two failure modes bracket the full intended au…
CVE-2026-55580
GitHub-GHSA

HIGH
PraisonAI: `–api-key` flag on `praisonai serve` is not properly enforced
GHSA-pvxx-r596-f5qj
pkg: PraisonAI
eco: pip
published: Aug 25, 2026
## Summary

`praisonai serve agents` and `praisonai serve unified` both accept `–api-key` for authentication. The flag is parsed but never wired into the FastAPI app — no middleware, no header check, nothing. The server runs wide open regardless of what key you set. Tested on 4.6.50 from PyPI.

#…

CVE-2026-55541
GitHub-GHSA

HIGH
praisonaiagents has a `web_crawl` SSRF protection bypass via unchecked redirect targets
GHSA-8hjw-25cg-g52h
pkg: praisonaiagents
eco: pip
published: Aug 25, 2026
## Summary

`praisonaiagents.tools.web_crawl_tools.web_crawl()` validates the initial URL and blocks direct loopback/private destinations by default, but the default httpx fallback still uses `httpx.Client(follow_redirects=True)` and does not revalidate redirect targets.

An attacker-controlled publ…

CVE-2026-55523
GitHub-GHSA

HIGH
postgres-protocol: Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service
GHSA-5×78-73v4-xg6w
pkg: postgres-protocol
eco: rust
published: Aug 24, 2026
A malicious, compromised, or man-in-the-middle server can supply an arbitrarily
large SCRAM-SHA-256 PBKDF2 iteration count during authentication. The client
runs it inline with no upper bound, pinning a `tokio` worker thread for minutes
per connection, possibly stalling the whole async runtime.

App…

GitHub-GHSA

MEDIUM
PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on local MCP server
GHSA-wj6g-v78p-6fx3
pkg: PraisonAI
eco: pip
published: Aug 25, 2026
### Summary

PraisonAI's MCP HTTP Stream transport uses an unsafe prefix match when validating the `Origin` header. The default localhost allowlist includes origins such as `http://localhost`, and the validation accepts any origin that starts with an allowed value.

As a result, an attacker-controll…

CVE-2026-55529
NVD

MEDIUM
CVE-2026-82255
CVE-2026-82255
pkg: curl

published: Aug 28, 2026

gitoxide versions from 0.25.4 contain an HTTP credential leak vulnerability in the curl-based transport backend where credentials are sent to attacker-controlled servers after HTTP redirects. The vulnerability occurs because credential validation checks the original URL instead of the effective URL …
CWE: CWE-522
NVD

MEDIUM
CVE-2026-81706
CVE-2026-81706
pkg: openssl

published: Aug 27, 2026

openssl_encrypt before 1.4.9 fails to prevent namespace collisions between own identities and contacts in IdentityStore, allowing attackers to create shadowed contact entries invisible until the corresponding own identity is deleted. When the own identity is deleted, the shadowed contact becomes vis…
CWE: CWE-345
NVD

MEDIUM
CVE-2026-59272
CVE-2026-59272
pkg: tls

published: Aug 27, 2026

Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of every log event.
Spring AMQP 4.1.0
Spring AMQP 4.0.0 – 4.0.4
Spring AMQP 3.2.0 – 3.2.12
Spring AMQP 2.4.18 and earlier
CWE: CWE-297
NVD

MEDIUM
CVE-2026-65086
CVE-2026-65086
pkg: linux

published: Aug 25, 2026

NVIDIA OpenShell for Linux contains a vulnerability in its sandbox exec handler, where an attacker could cause an OS command injection. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering.
CWE: CWE-78
GitHub-GHSA

MEDIUM
PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation
GHSA-hmfx-4v44-9qw9
pkg: PraisonAI
eco: pip
published: Aug 25, 2026
### Summary
The `webhook_url` field in the Jobs API silently passes validation when DNS resolution fails (`socket.gaierror`), enabling DNS rebinding attacks. An attacker's domain can initially resolve to a public IP (passing validation) then switch to an internal IP before the server makes the HTTP …
CVE-2026-55535
GitHub-GHSA

MEDIUM
Aqua's archive extraction follows attacker-planted symlinks, allowing writes outside the install directory
GHSA-mf5c-hw34-4hpp
pkg: github.com/aquaproj/aqua/v2
eco: go
published: Aug 28, 2026
### Summary

`aquaproj/aqua` extracts downloaded tool archives through `pkg/unarchive/archives.go` using `github.com/mholt/archives`. The archive handler creates symlink entries with `os.Symlink(f.LinkTarget, dstPath)` without validating that the symlink target resolves inside the extraction destina…

CVE-2026-55569
NVD

MEDIUM
CVE-2026-82662
CVE-2026-82662
pkg: tls

published: Aug 31, 2026

Nodemailer before 8.0.8 disables TLS certificate verification in lib/fetch/index.js through rejectUnauthorized: false, allowing attackers to intercept OAuth2 token requests. Attackers in a machine-in-the-middle position can capture OAuth client secrets, refresh tokens, and access tokens transmitted …
CWE: CWE-295
GitHub-GHSA

MEDIUM
MariaDB has possible SQL injection in Buffer parameter escaping under big5/gbk/sjis/cp932/gb18030 client charsets
GHSA-g5xc-5w98-jfvm
pkg: mariadb, mariadb, mariadb
eco: npm
published: Aug 28, 2026
### Summary

A SQL injection is possible when the connector escapes Buffer parameters client-side under a multi-byte client character set whose trail-byte range overlaps the ASCII backslash (0x5C): big5, gbk, sjis, cp932, and gb18030. Under these charsets, an attacker-controlled lead byte can absorb…

CVE-2026-55855
NVD

MEDIUM
CVE-2026-77939
CVE-2026-77939
pkg: express

published: Aug 28, 2026

Flextype CMS through v1.0.0-dev contains an expression language injection vulnerability that allows authenticated attackers with a valid API token to read arbitrary files by passing unsanitized user-supplied input to the Symfony ExpressionLanguage engine via the POST /api/v1/query endpoint. Attacker…
CWE: CWE-94, CWE-1336
GitHub-GHSA

MEDIUM
Yamcs has Reflected XSS in the URL of the Authorize Endpoint
GHSA-rxpg-wjf8-qv9c
pkg: org.yamcs:yamcs-core
eco: maven
published: Aug 28, 2026
### Attack type: 
Unauthenticated remote 

### Impact:
Attackers can execute arbitrary JavaScript in a user's browser, including obtaining a user's session token and refresh token.

### Affected components: authorize.html, AuthHandler.java, HandlerContext.java

A Reflected Cross-Site Scripting…

CVE-2026-55549
GitHub-GHSA

MEDIUM
Yamcs's WebSocket subscription handlers omit the privilege checks their REST siblings enforce
GHSA-fwww-cp23-7f5g
pkg: org.yamcs:yamcs-core, org.yamcs:yamcs-core
eco: maven
published: Aug 28, 2026
**Asset / scope:** Yamcs 5.12.7 WebSocket topics (`packets`, `algorithm-status`, `mdb-changes`)

## Summary

Several WebSocket subscription handlers do not perform the privilege check that their REST counterparts
enforce, so a principal subscribing over WebSocket receives data the REST API would hav…

CVE-2026-55545
NVD

MEDIUM
CVE-2026-81341
CVE-2026-81341
pkg: tls

published: Aug 28, 2026

wolfEngine before 1.4.1 sources the explicit AES-CCM nonce for TLS 1.2 and DTLS 1.2 records from the record input buffer instead of the TLS sequence number carried in the additional authenticated data. Because the record layer leaves the explicit-nonce field for the cipher to populate, the value rea…
CWE: CWE-323
GitHub-GHSA

MEDIUM
gix-packetline: reachable panic on empty side-band packet (pre-auth network DoS)
GHSA-2vh6-hw4j-32ww
pkg: gix-packetline
eco: rust
published: Aug 28, 2026
### Summary
`gix-packetline` panics when it receives a side-band packet line that contains only the band-id byte with an empty payload. A malicious Git server – or any remote a victim clones/fetches from – can abort the `gix` client process during a normal fetch. This is a pre-authentication, networ…
NVD

MEDIUM
CVE-2026-61802
CVE-2026-61802
pkg: node

published: Aug 28, 2026

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.14.0 through 4.14.6, a low-privilege API user can read the cleartext cluster key from a configuration endpoint that fails to redact it. The REST API provides a masking…
CWE: CWE-200, CWE-522
NVD

MEDIUM
CVE-2026-81527
CVE-2026-81527
pkg: express

published: Aug 27, 2026

A NoSQL/expression injection weakness exists in the LINQ-to-aggregation query translation layer of the MongoDB C# Driver, in both aggregation expression and query filter translation. When application-supplied values are embedded in certain query constructs, special elements contained within those va…
CWE: CWE-943
NVD

MEDIUM
CVE-2026-54732
CVE-2026-54732
pkg: node

published: Aug 27, 2026

libreoffice-convert is a Node.js module for converting office documents to different formats. Prior to 1.8.2, index.js uses the caller-controlled options.fileName value in path.join(tempDir.name, fileName) without reducing it to a base name. A filename containing ../ can escape the temporary directo…
CWE: CWE-22
GitHub-GHSA

MEDIUM
libreoffice-convert vulnerable to path traversal / arbitrary file write
GHSA-gmxc-r82q-347r
pkg: libreoffice-convert
eco: npm
published: Aug 27, 2026
### Impact
options.fileName is used to build a filesystem path
(path.join(tempDir.name, fileName)) and the caller-supplied document buffer is
written there, but fileName is never reduced to a base name. A fileName containing
"../" escapes the temporary directory, so a caller can write arbitrary cont…
CVE-2026-54732
NVD

MEDIUM
CVE-2026-62326
CVE-2026-62326
pkg: express

published: Aug 26, 2026

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a user with the built-in "Edit source" role can store a malicious regular expression in a source string's flags that is executed without any timeout, allowing them to stall requ…
CWE: CWE-400
NVD

MEDIUM
CVE-2026-46371
CVE-2026-46371
pkg: node

published: Aug 26, 2026

Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the Apple MDM commands listing endpoint (GET /api/v1/fleet/mdm/apple/commands) allowed an authenticated user with the lowest-privilege Observer role to extract sensitive values from joined da…
CWE: CWE-89, CWE-200
NVD

MEDIUM
CVE-2026-46370
CVE-2026-46370
pkg: node

published: Aug 26, 2026

Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the labels host-listing endpoint (GET /api/v1/fleet/labels/{id}/hosts) allowed an authenticated user with the lowest-privilege Observer role to extract host enrollment secrets through a sort-…
CWE: CWE-89, CWE-200
NVD

MEDIUM
CVE-2026-81034
CVE-2026-81034
pkg: tls

published: Aug 26, 2026

Netmaker disables certificate verification on the connection to the configured mail server. The sender in pro/email/smtp.go assigns a TLS configuration whose skip-verify field is set to true unconditionally, directly beneath a comment stating that the setting should be false in production. No config…
CWE: CWE-295
NVD

MEDIUM
CVE-2026-79285
CVE-2026-79285
pkg: windows

published: Aug 25, 2026

Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-908
NVD

MEDIUM
CVE-2026-79253
CVE-2026-79253
pkg: google chrome, microsoft windows

published: Aug 25, 2026

Improper input validation in Network in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)
CWE: CWE-20
NVD

MEDIUM
CVE-2026-79243
CVE-2026-79243
pkg: google chrome, microsoft windows

published: Aug 25, 2026

Improper input validation in ReadingList in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
CWE: CWE-20
NVD

MEDIUM
CVE-2026-79177
CVE-2026-79177
pkg: google chrome, microsoft windows

published: Aug 25, 2026

Incorrect authorization in Media in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
CWE: CWE-863
NVD

MEDIUM
CVE-2026-79123
CVE-2026-79123
pkg: google chrome, microsoft windows

published: Aug 25, 2026

Improper input validation in NTP Footer in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
CWE: CWE-20
NVD

MEDIUM
CVE-2026-78947
CVE-2026-78947
pkg: google chrome

published: Aug 25, 2026

Incomplete cleanup in Chromium in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Low)
CWE: CWE-459
NVD

MEDIUM
CVE-2026-78914
CVE-2026-78914
pkg: google chrome

published: Aug 25, 2026

Uninitialized resource in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
CWE: CWE-908
NVD

MEDIUM
CVE-2026-78907
CVE-2026-78907
pkg: google chrome

published: Aug 25, 2026

Incorrect authorization in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-863
NVD

MEDIUM
CVE-2026-78897
CVE-2026-78897
pkg: google chrome

published: Aug 25, 2026

Missing authorization in BrowserTag in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted Chrome extension. (Chromium security severity: Low)
CWE: CWE-862
NVD

MEDIUM
CVE-2026-78893
CVE-2026-78893
pkg: google chrome

published: Aug 25, 2026

Information leak in QUIC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-200
NVD

MEDIUM
CVE-2026-55618
CVE-2026-55618
pkg: python

published: Aug 25, 2026

eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information. Prior to 3.0.2, the clean_found_uri function in eml_parser/parser.py validates potential URL strings before unescaping HTML entities used for colon, slash…
CWE: CWE-116
GitHub-GHSA

MEDIUM
eml_parser has a URL extraction bypass via HTML entities in URLs
GHSA-fxgq-9m89-cxj9
pkg: eml_parser
eco: pip
published: Aug 25, 2026
## Summary

`eml_parser` performs certain validations on potential URL strings to discard bogus values. In versions prior to `3.0.2`, this validation was performed before unescaping any HTML entities that might occur in the string. This caused the library to wrongfully reject valid URLs that use HTM…

CVE-2026-55618
GitHub-GHSA

MEDIUM
PraisonAI MCP HTTP server has unauthenticated unbounded session accumulation (memory exhaustion; session TTL never enforced)
GHSA-wv94-5qcp-6m36
pkg: PraisonAI
eco: pip
published: Aug 25, 2026
### Summary

The PraisonAI MCP HTTP-stream server creates a new in-memory session on every initialize request and never removes it. The cleanup routine that would expire sessions (_cleanup_sessions) is defined but never called anywhere in the codebase, and the configured session TTL is never enforce…

CVE-2026-55531
NVD

MEDIUM
CVE-2026-75509
CVE-2026-75509
pkg: jwt

published: Aug 24, 2026

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. Prior to version 1.7.3, JWTClaimsRegistry applies membership matching to list-valued iss and sub claims, allowing an array-valued iss that contains the expected issuer to pass …
CWE: CWE-290, CWE-345
GitHub-GHSA

MEDIUM
Sakai Profile Image Deletion has an IDOR
GHSA-9284-fjc3-fmmj
pkg: org.sakaiproject.profile2:profile2-api, org.sakaiproject.profile2:profile2-api, org.sakaiproject.profile2:profile2-impl
eco: maven
published: Aug 24, 2026
### Summary

The Sakai REST API endpoint `DELETE /api/users/{userId}/profile/image` does not verify that the requesting user is authorized to modify the target user's profile. Any authenticated user can delete the profile image of any other user, including administrators, by supplying a different `u…

CVE-2026-54050
GitHub-GHSA

MEDIUM
Apache Camel-Mail: the MimeMultipart data format copied MIME headers onto the Camel message without a header filter strategy when unmarshalling with headersInline enabled
GHSA-cx47-qxp5-mmh2
pkg: org.apache.camel:camel-mail, org.apache.camel:camel-mail, org.apache.camel:camel-mail
eco: maven
published: Aug 24, 2026
Improper input validation vulnerability in Apache Camel.

This issue affects Apache Camel: from 2.17.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0.

The camel-mail component ships a MimeMultipart data format that can unmarshal a MIME multipart message. When it is configured w…

CVE-2026-59230
NVD

MEDIUM
CVE-2026-78323
CVE-2026-78323
pkg: tls

published: Aug 24, 2026

A flaw was found in JSS (Java Security Services). The JSSTrustManager class does not verify NSS trust flags when validating CA certificates, allowing certificates present in the NSS database without TRUSTED_CA flags to be accepted as trust anchors for TLS connections. In non-default configurations w…
CWE: CWE-295
GitHub-GHSA

MEDIUM
Hatchet allows cross-tenant write/DoS to other tenants' workers via Dispatcher gRPC UpsertWorkerLabels and Unsubscribe
GHSA-8x7x-83cf-c3pg
pkg: github.com/hatchet-dev/hatchet
eco: go
published: Aug 28, 2026
### Summary

A **cross-tenant write / DoS** vulnerability in the Hatchet `Dispatcher` gRPC service allows any holder of a normal tenant-scoped API token (the lowest credential Hatchet issues — an `OWNER` of a brand-new tenant) to overwrite the affinity labels of, or disconnect from the dispatcher,…

CVE-2026-54746
NVD

MEDIUM
CVE-2026-3129
CVE-2026-3129
pkg: express

published: Aug 28, 2026

The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted `<img>` tag attributes in all versions up to, and including, 7.7. This is due to a flawed regular expression that is used to strip `width` and `height` attributes from images when the "Lazy Load Images"…
CWE: CWE-79
NVD

MEDIUM
CVE-2026-18100
CVE-2026-18100
pkg: express

published: Aug 25, 2026

The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'mf_form_id' Widget Setting in all versions up to, and including, 4.1.8 due to insufficient input sanitization and output escaping. This makes it poss…
CWE: CWE-79
NVD

MEDIUM
CVE-2026-81720
CVE-2026-81720
pkg: openssl

published: Aug 27, 2026

openssl_encrypt before 1.4.9 fails to validate the memory_cost parameter from identity file protection blocks, allowing attackers to trigger out-of-memory conditions during key derivation. Attackers with write access to local identity stores can craft malicious identity files with excessive memory_c…
CWE: CWE-400
NVD

MEDIUM
CVE-2026-81686
CVE-2026-81686
pkg: openssl

published: Aug 27, 2026

openssl_encrypt 1.4.x before 1.4.9 contains an optional D-Bus crypto service whose org.freedesktop.DBus.Properties.Set method performs neither a polkit authorization check nor value validation. Any local user on the system bus can call Set without authorization and set MaxConcurrentOperations (to 0/…
CWE: CWE-20
NVD

MEDIUM
CVE-2026-81684
CVE-2026-81684
pkg: openssl

published: Aug 27, 2026

In openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8, the desktop GUI passes the steganography password to the CLI child process on the command line via the –stego-password argument (on both encrypt and decrypt paths) instead of via an environment variable as done for the main passwor…
CWE: CWE-214
NVD

MEDIUM
CVE-2026-81682
CVE-2026-81682
pkg: openssl

published: Aug 27, 2026

openssl_encrypt versions before 1.4.9 contain an insecure file permissions vulnerability in the desktop GUI that writes decrypted plaintext with world-readable default permissions. Attackers can read decrypted output files created by the GUI as unprivileged local users on multi-user systems.
CWE: CWE-276
GitHub-GHSA

MEDIUM
WebOb: Open redirect in Location header normalization via leading C0 control / space characters
GHSA-6hx8-3wjj-gr8g
pkg: webob
eco: pip
published: Aug 27, 2026
## Summary

This is a third follow-up to **CVE-2024-42353 / GHSA-mg3v-6m49-jhp3**
and **CVE-2026-44889 / GHSA-fh3h-vg37-cc95**.

WebOb makes the `Location` header absolute when it serves a redirect. To stop a
relative or protocol-relative target from redirecting users off-host, it checks
the value f…

CVE-2026-54770
NVD

MEDIUM
CVE-2026-19854
CVE-2026-19854
pkg: tls

published: Aug 27, 2026

When the ClickHouse plugin uses Native protocol (the default) with PDC or secure SOCKS, it asks for TLS but the connection library ignores that and talks to ClickHouse in the clear. Username, password, queries, and results can be read on the hop after the proxy. The server certificate is never check…
CWE: CWE-319
NVD

MEDIUM
CVE-2026-47848
CVE-2026-47848
pkg: react

published: Aug 26, 2026

In specific scenarios involving WebSocket handshake redirects to a different origin, the Reactor Netty WebSocket client may leak credentials. In order for this to happen, the HTTP client must have been explicitly configured to follow redirects.
Reactor Netty 1.3.0 – 1.3.6
Reactor Netty 1.1.0 – 1.2.1…
GitHub-GHSA

MEDIUM
praisonaiagents: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool
GHSA-cfxv-8fw8-rwpv
pkg: praisonaiagents
eco: pip
published: Aug 25, 2026
**Target:** PraisonAI (`MervinPraison/PraisonAI`)
**Affected component:** `praisonaiagents/tools/ast_grep_tool.py` — `ast_grep_rewrite`
**Affected versions:** master at `ce97667156a116c50b4a3d1aa21e09f048903fda`; reproduced against the current `praisonaiagents` PyPI release (`praisonaiagents` <= 1…
CVE-2026-55530
NVD

MEDIUM
CVE-2026-17113
CVE-2026-17113
pkg: node

published: Aug 24, 2026

A flaw was found in CRI-O's container-creation environment-variable handling
(`mergeEnvs` in `server/utils.go`, consumed by `setupContainerEnvironmentAndWorkdir` in
`server/container_create.go`). When a `CreateContainer` request supplies a `nil` CRI
`Envs` field, CRI-O falls back to using the target…
CWE: CWE-1287
NVD

MEDIUM
CVE-2026-55857
CVE-2026-55857
pkg: ssl

published: Aug 28, 2026

MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, PAM dialog authentication can be coerced into transmitting the account password over an insecure connection. The mysql_clear_password plugin is gated behind…
CWE: CWE-319, CWE-522
NVD

MEDIUM
CVE-2026-55856
CVE-2026-55856
pkg: ssl

published: Aug 28, 2026

MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, when a Java application connects with sslMode=verify-full or sslMode=verify-ca, supplies a password, and does not configure serverSslCert or trustStore, Con…
CWE: CWE-522
NVD

MEDIUM
CVE-2026-55854
CVE-2026-55854
pkg: ssl

published: Aug 28, 2026

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.4, 3.3.3, 3.4.6, and 3.5.3, MariaDB Connector/Node.js can disclose an account password when PAM dialog authentication is negotiated over an insecure transport. In lib/cmd/hands…
CWE: CWE-319, CWE-522
GitHub-GHSA

MEDIUM
org.mariadb:r2dbc-mariadb vulnerable to cleartext password disclosure to a man-in-the-middle server (clear-text auth plugins not gated on a secure transport)
GHSA-c857-9x2m-cvh2
pkg: org.mariadb:r2dbc-mariadb
eco: maven
published: Aug 28, 2026
### Summary

The connector does not gate clear-text password authentication plugins on transport encryption. A hostile or man-in-the-middle MariaDB server can request a clear-text plugin over an unencrypted (plain-TCP) connection, and the driver responds with the user's password in cleartext on the …

CVE-2026-55860
GitHub-GHSA

MEDIUM
org.mariadb:r2dbc-mariadb has Inappropriate Encoding for Output Context and Improper Encoding or Escaping of Output
GHSA-5rqc-86vf-g8r2
pkg: org.mariadb:r2dbc-mariadb
eco: maven
published: Aug 28, 2026
### Summary

The connector encodes and decodes all character data assuming the connection character set is UTF-8. A server can change character_set_client mid-session to a non-UTF-8 charset, after which the driver and server interpret the same bytes under different encodings, causing silent data cor…

CVE-2026-55859
GitHub-GHSA

MEDIUM
org.mariadb.jdbc:mariadb-java-client has Inappropriate Encoding for Output Context
GHSA-xvr9-35cr-46v9
pkg: org.mariadb.jdbc:mariadb-java-client, org.mariadb.jdbc:mariadb-java-client, org.mariadb.jdbc:mariadb-java-client
eco: maven
published: Aug 28, 2026
### Summary

The connector encodes and decodes all character data assuming the connection character set is UTF-8. A server can change character_set_client mid-session to a non-UTF-8 charset, after which the driver and server interpret the same bytes under different encodings, causing silent data cor…

CVE-2026-55858
GitHub-GHSA

MEDIUM
org.mariadb.jdbc:mariadb-java-client has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials
GHSA-qxvw-fvwx-5cp7
pkg: org.mariadb.jdbc:mariadb-java-client, org.mariadb.jdbc:mariadb-java-client, org.mariadb.jdbc:mariadb-java-client
eco: maven
published: Aug 28, 2026
### Summary

When PAM (dialog) authentication is used, the connector can be coerced into sending the account password in cleartext over an insecure connection. A hostile or man-in-the-middle server can trigger this with the default configuration, disclosing the user's password.

### Details

The my…

CVE-2026-55857
GitHub-GHSA

MEDIUM
MariaDB has cleartext password disclosure to a MITM on the initial-handshake
GHSA-g9jj-cgmh-9f38
pkg: org.mariadb.jdbc:mariadb-java-client, org.mariadb.jdbc:mariadb-java-client, org.mariadb.jdbc:mariadb-java-client
eco: maven
published: Aug 28, 2026
### Summary

When a Java application connects with sslMode=verify-full (or verify-ca) and a password but does not pin a server certificate, Connector/J deliberately accepts an untrusted/self-signed certificate at the TLS layer (the "MITM-proof without a CA" feature) and proves the server's identity …

CVE-2026-55856
NVD

MEDIUM
CVE-2025-36290
CVE-2025-36290
pkg: tls

published: Aug 28, 2026

IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques.
CWE: CWE-295
GitHub-GHSA

MEDIUM
MariaDB has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials
GHSA-42r5-vhpq-m858
pkg: mariadb, mariadb, mariadb
eco: npm
published: Aug 28, 2026
### Summary

When PAM (dialog) authentication is used, the connector can be coerced into sending the account password in cleartext over an insecure connection. A hostile or man-in-the-middle server can trigger this with the default configuration, disclosing the user's password.

### Details

The mys…

CVE-2026-55854
NVD

MEDIUM
CVE-2026-40205
CVE-2026-40205
pkg: oauth

published: Aug 28, 2026

An attacker that holds an OAuth2 token granting only part of the required scopes can authenticate, because when more than one scope is required in the configuration, the remote token validation paths accept a token that carries only one of them, while the local token validation path correctly requir…
CWE: CWE-287
GitHub-GHSA

MEDIUM
aiosmtplib: STARTTLS response injection
GHSA-vxj7-4xrp-5vr4
pkg: aiosmtplib
eco: pip
published: Aug 27, 2026
## Impact

When a connection is upgraded with STARTTLS, aiosmtplib reads the server's 220 go-ahead reply and immediately performs the TLS handshake without discarding any data still sitting in the receive buffer. Bytes the protocol read off the plaintext socket before the handshake survive across th…

CVE-2026-55558
NVD

MEDIUM
CVE-2026-47863
CVE-2026-47863
pkg: react

published: Aug 27, 2026

In Reactor Core, applications that use the Flux.bufferTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition.
Reactor Core 3.8.0 – 3.8.6
Reactor Core 3.7.19 and earlier
CWE: CWE-835
NVD

MEDIUM
CVE-2026-47857
CVE-2026-47857
pkg: react

published: Aug 27, 2026

In Reactor Core, applications that use the Flux.windowTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition.
Reactor Core 3.8.0 – 3.8.6
Reactor Core 3.5.0 – 3.7.19
Reactor Core 3.4.41 and earlier
CWE: CWE-190
GitHub-GHSA

MEDIUM
asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution
GHSA-qr67-gv47-xwwh
pkg: asyncssh
eco: pip
published: Aug 26, 2026
**Incomplete fix for CVE-2026-45309 (GHSA-g794-3fmp-753h).** The
2.23.0 guard that sanitises the SSH username before `%u` substitution
in `AuthorizedKeysFile` blocks `/`, `\` and `..`, but does not block a
leading `~` (or `${ENV}`), both of which are re-introduced by later
expansion and reac…
CVE-2026-54590
NVD

MEDIUM
CVE-2026-80206
CVE-2026-80206
pkg: express

published: Aug 26, 2026

NLTK before 3.10.3 contains a regular expression denial of service (ReDoS) vulnerability in the tgrep module. The _tgrep_node_action function compiles user-supplied regular expressions embedded in /regex/ pattern nodes and executes them via re.search against tree node labels without any validation o…
CWE: CWE-1333
NVD

MEDIUM
CVE-2026-79126
CVE-2026-79126
pkg: google chrome, microsoft windows

published: Aug 25, 2026

Incorrect provision of specified functionality in Proxy in Google Chrome on on Windows prior to 152.0.7977.65 allowed an adjacent attacker to potentially obtain sensitive information via crafted network traffic. (Chromium security severity: Low)
CWE: CWE-684
NVD

MEDIUM
CVE-2026-79785
CVE-2026-79785
pkg: ssl

published: Aug 25, 2026

X-AnyLabeling's model downloader disabled TLS certificate verification. download_with_retry in anylabeling/services/auto_labeling/model.py built a context with ssl._create_unverified_context() and passed it to urllib.request.urlopen, so neither the certificate chain nor the hostname was checked on a…
CWE: CWE-295
NVD

MEDIUM
CVE-2026-63074
CVE-2026-63074
pkg: openssl

published: Aug 25, 2026

Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches
additional certificates (extraCerts) sent in a CMP message, but never expunges
them (for instance if they are invalid). If a server reuses an OSSL_CMP_CTX
frequently, this cache of extraCerts may grow unboundedly, and a malicio…
CWE: CWE-770
NVD

MEDIUM
CVE-2026-79652
CVE-2026-79652
pkg: jwt

published: Aug 25, 2026

A flaw was found in the JWT Bearer authorization grant implementation within the keycloak-services component of Red Hat Build of Keycloak. This component handles various OAuth2 and OpenID Connect grant types used for issuing access tokens. The issue occurs because the JWT Bearer grant fails to check…
CWE: CWE-862
GitHub-GHSA

MEDIUM
mediasoup: SCTP state cookie lacks cryptographic authentication, enabling unauthorized association establishment (RFC 9260 violation)
GHSA-p7x2-g5cq-fhmq
pkg: mediasoup, mediasoup
eco: npm
published: Aug 25, 2026
### Summary

mediasoup's built-in SCTP stack (introduced in v3.20.0) authenticates SCTP state cookies using only hardcoded magic byte sequences rather than a per-instance HMAC keyed with a secret, violating RFC 9260 Section 5.1.3. An on-path attacker targeting a PlainTransport with SCTP enabled (and…

CVE-2026-55663
NVD

MEDIUM
CVE-2026-81703
CVE-2026-81703
pkg: openssl

published: Aug 27, 2026

openssl_encrypt versions before 1.4.9 fail to validate encryption status of embedded post-quantum private keys in file metadata. Attackers can craft files with unencrypted embedded PQC keys that decrypt under any password, bypassing authentication and producing attacker-chosen plaintext with false i…
CWE: CWE-287
NVD

MEDIUM
CVE-2026-81697
CVE-2026-81697
pkg: openssl

published: Aug 27, 2026

openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 contain a CWD-relative configuration file resolution flaw in crypt_settings.py, where CONFIG_FILE (originally the absolute per-user path ~/.crypt_settings.json) is reassigned at line 84 to the bare relative name 'crypt_settings.json'. A…
CWE: CWE-426
NVD

MEDIUM
CVE-2026-81687
CVE-2026-81687
pkg: openssl

published: Aug 27, 2026

openssl_encrypt versions before 1.4.9 fail to enforce a time ceiling on key derivation function iteration counts specified in file metadata. Attackers can craft files with extremely high KDF iteration counts to consume CPU resources for unbounded periods before password verification occurs.
CWE: CWE-400
NVD

MEDIUM
CVE-2026-68514
CVE-2026-68514
pkg: python

published: Aug 25, 2026

OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13, the PyOpenEXR Python bindings contain a heap out-of-bounds write triggered when reading a crafted deep scanl…
CWE: CWE-122, CWE-787
NVD

MEDIUM
CVE-2026-79769
CVE-2026-79769
pkg: node

published: Aug 25, 2026

Nokogiri versions before 1.19.4 contain a possible invalid (out-of-bounds) memory read in the protected internal Node#initialize_copy_with_args helper behind Node#dup and #clone, which unwrapped its source argument as an xmlNode without a type check. If application code calls this protected method w…
CWE: CWE-843
GitHub-GHSA

MEDIUM
Apache Camel-Azure-Storage-DataLake: the downloadToFile operation built the local download target from the remote path name without constraining it to the configured fileDir
GHSA-7jwc-q3fj-c9pq
pkg: org.apache.camel:camel-azure-storage-datalake, org.apache.camel:camel-azure-storage-datalake, org.apache.camel:camel-azure-storage-datalake
eco: maven
published: Aug 24, 2026
Relative path traversal vulnerability in Apache Camel Azure-Storage Datalake component

This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0.

The camel-azure-storage-datalake component can download an Azure Data Lake Storage Gen2 file to th…

CVE-2026-60093
NVD

MEDIUM
CVE-2026-82469
CVE-2026-82469
pkg: jwt

published: Aug 29, 2026

Rodauth before 2.47.0 contains an authentication bypass vulnerability in the jwt_refresh route that issues new JWT access tokens without requiring a refresh token. Attackers can present an access token to the refresh route via non-POST methods to obtain a new valid access token, enabling indefinite …
CWE: CWE-613
NVD

MEDIUM
CVE-2026-54553
CVE-2026-54553
pkg: python

published: Aug 26, 2026

Starlette-Admin is a fast, beautiful and extensible administrative interface framework for FastAPI and Starlette applications. Prior to 0.16.1, the list API does not validate user-supplied order_by and structured where field names against the configured sortable_fields and searchable_fields allowlis…
CWE: CWE-200, CWE-248, CWE-639
GitHub-GHSA

MEDIUM
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
GHSA-6753-gr46-6wpr
pkg: starlette-admin
eco: pip
published: Aug 26, 2026
## Summary

Affected versions of Starlette-Admin prior to 0.16.1 do not properly validate user-supplied sort and search parameters against the configured field allowlists. While the administrative UI restricts available fields based on field configuration, the backend accepts arbitrary field names s…

CVE-2026-54553
NVD

MEDIUM
CVE-2026-78912
CVE-2026-78912
pkg: google chrome

published: Aug 25, 2026

UI misrepresentation in Browser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-451
NVD

MEDIUM
CVE-2026-10618
CVE-2026-10618
pkg: go

published: Aug 24, 2026

Hugo's default fenced-code-block renderer writes attribute values taken from the code-fence info string into the rendered HTML without escaping them. New in markup/internal/attributes/attributes.go converts every attribute value from a byte slice to a string as it is stored, deliberately dropping th…
CWE: CWE-79
NVD

MEDIUM
CVE-2024-58379
CVE-2024-58379
pkg: express

published: Aug 31, 2026

nodemailer before 6.9.9 contains a regular expression denial of service vulnerability in email parsing when attachDataUrls parameter is set or processing embedded file attachments. Attackers can send specially crafted emails with malicious data URLs or embedded attachments to cause the event loop to…
CWE: CWE-1333
NVD

MEDIUM
CVE-2026-82417
CVE-2026-82417
pkg: express

published: Aug 30, 2026

### Summary

`qs.stringify` throws a `TypeError` when it serializes an object whose own `constructor` property has a truthy, non-callable `isBuffer` member. `utils.isBuffer` duck-types buffers by calling `obj.constructor.isBuffer(obj)` after checking only that the property is truthy, so a value su…

CWE: CWE-248, CWE-703
NVD

MEDIUM
CVE-2026-15603
CVE-2026-15603
pkg: node

published: Aug 28, 2026

morgan is an HTTP request logger middleware for Node.js. In versions prior to 1.12.0, the internal helper that escapes log token values did not neutralize the Unicode line separator characters U+0085 (Next Line), U+2028 (Line Separator), and U+2029 (Paragraph Separator). An unauthenticated remote cl…
CWE: CWE-117
NVD

MEDIUM
CVE-2026-82256
CVE-2026-82256
pkg: node

published: Aug 28, 2026

SvelteKit before 2.69.1 fails to properly validate remote form function payload sizes, allowing attackers to crash the Node process by sending large payloads. Repeated exploitation causes denial of service by repeatedly crashing the application process.
CWE: CWE-400
NVD

MEDIUM
CVE-2026-82248
CVE-2026-82248
pkg: windows

published: Aug 28, 2026

gix-worktree-state before 0.33.0 (part of gitoxide) allows writing files outside the worktree on Windows. gix_worktree_state::checkout() follows an existing terminal symlink during non-exclusive (incremental) materialization (destination_is_initially_empty: false) when core.symlinks is true. If a sy…
CWE: CWE-59
NVD

MEDIUM
CVE-2026-81724
CVE-2026-81724
pkg: python

published: Aug 27, 2026

NLTK before 3.10.3 contains an uncontrolled recursion vulnerability in nltk.featstruct.FeatStructReader that allows unauthenticated attackers to cause a denial of service by supplying deeply nested feature-structure input. Attackers can craft trivial payloads with nested brackets that exceed Python'…
CWE: CWE-674
NVD

MEDIUM
CVE-2026-80207
CVE-2026-80207
pkg: nginx

published: Aug 27, 2026

APITable through 1.13.0-beta.1 annotates the create handler of InternalNotifyController with requiredLogin = false. ResourceInterceptor honours that annotation by returning before any session or API key is validated, and the nginx gateway shipped with the product proxies every /api request to the ba…
CWE: CWE-306
NVD

MEDIUM
CVE-2026-47874
CVE-2026-47874
pkg: react

published: Aug 27, 2026

The vulnerability occurs when a client sends HTTP/1.1 pipelined requests over a single connection, causing the Reactor Netty HTTP server to consume an excessive amount of memory.
Reactor Netty 1.3.0 – 1.3.6
Reactor Netty 1.1.0 – 1.2.18
Reactor Netty 1.0.52 and earlier
CWE: CWE-770
NVD

MEDIUM
CVE-2026-47845
CVE-2026-47845
pkg: react

published: Aug 27, 2026

In specific scenarios, Reactor Netty HTTP Server may incorrectly evaluate the remote IP address when HAProxy Protocol is enabled. In order for this to happen, the application must be configured to use HAProxy Protocol.
Reactor Netty 1.3.0 – 1.3.6
Reactor Netty 1.1.0 – 1.2.18
Reactor Netty 1.0.52 and…
CWE: CWE-290
NVD

MEDIUM
CVE-2026-47844
CVE-2026-47844
pkg: react

published: Aug 26, 2026

In specific scenarios, the Reactor Netty HTTP Server may leak exception details across unrelated requests. In order for this to happen, the server must be configured with Brave Tracing.
Reactor Netty 1.3.0 – 1.3.6
Reactor Netty 1.1.0 – 1.2.18
Reactor Netty 1.0.52 and earlier
GitHub-GHSA

MEDIUM
OpenWISP IPAM has broken object-level authorization: ExportSubnetView lets a member of one organization export another organization's subnet and all its IP addresses
GHSA-x287-5c68-36wp
pkg: openwisp-ipam
eco: pip
published: Aug 26, 2026
## Summary

OpenWISP IPAM is multi-tenant: every `Subnet` belongs to an `organization`, and API access is scoped to the organizations a user belongs to. The CSV **export** endpoint, `ExportSubnetView`, omits the organization-membership check that its **import** sibling performs, and loads the subnet…

GitHub-GHSA

MEDIUM
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
GHSA-p43p-whwx-q52h
pkg: jupyterhub
eco: pip
published: Aug 25, 2026
### Impact

Invalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected.

### Patches

Upgrade to 5.5.0.

### Workarounds

Use an Authenticator that doesn't use a login form, suc…

CVE-2026-54338
NVD

MEDIUM
CVE-2026-55619
CVE-2026-55619
pkg: python

published: Aug 25, 2026

eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information. Prior to 3.0.2, eml_parser.parser.HeaderParser.header_fetch_parse in eml_parser/parser.py uses email.utils.getaddresses() to parse address-bearing e-mail …
CWE: CWE-770, CWE-1124
GitHub-GHSA

MEDIUM
@arikusi/deepseek-mcp-server: Missing Authentication on Self-Hosted HTTP MCP Endpoint
GHSA-72f3-6w86-7rv3
pkg: @arikusi/deepseek-mcp-server
eco: npm
published: Aug 25, 2026
## Summary
The self-hosted HTTP transport of `@arikusi/deepseek-mcp-server` exposes `POST /mcp` without any authentication: `createMcpExpressApp` is called without an `authProvider` and no middleware guards the route, so any network-reachable client can issue an unauthenticated `initialize` request …
CVE-2026-55605
GitHub-GHSA

MEDIUM
eml_parser has parser DoS via deeply nested parentheses in e-mail headers
GHSA-m66c-fw79-6359
pkg: eml_parser
eco: pip
published: Aug 25, 2026
### Summary

`eml_parser` uses the `email.utils.getaddresses()` function from the CPython standard library to parse e-mail headers that contain e-mail addresses (such as `To`, `Cc`, `Bcc`, `From`, `Reply-To`, `Sender`, …). When the input header contains a deeply nested CFWS (comment / folding whit…

CVE-2026-55619
GitHub-GHSA

MEDIUM
reachy_mini Allows Unrestricted Upload of File with Dangerous Type
GHSA-m2pc-3q4q-w6jr
pkg: reachy-mini
eco: pip
published: Aug 25, 2026
## Summary

The Reachy Mini daemon exposes the “/api/media/sounds/upload” endpoint without authentication and file validation mechanisms.
An attacker can use this endpoint to upload malicious files into the file system that will propagate in future attacks.

## Compromise Chain: Unauthenticate…

CVE-2026-55419
NVD

MEDIUM
CVE-2026-79778
CVE-2026-79778
pkg: go

published: Aug 25, 2026

rclone before v1.75.0 contains a denial of service vulnerability in the WebDAV TUS creation handler that dereferences a nil response before checking for transport errors. A malicious or compromised configured endpoint can reset connections during TUS uploads to trigger a panic that terminates unreco…
CWE: CWE-248
GitHub-GHSA

MEDIUM
Cloudreve has Broken Access Control – Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint
GHSA-vx2m-jpxr-xv7w
pkg: github.com/cloudreve/Cloudreve/v4
eco: go
published: Aug 24, 2026
## Summary

Cloudreve's file-listing responses hand the client a `context_hint` (UUID) that is meant to speed up follow-up operations. When that hint is replayed on the `file/url` (and `file/thumb`) routes, DBFS caches a `shareNavigatorState` containing the already-loaded share root and share row.

GitHub-GHSA

MEDIUM
Apache Camel-Knative: CloudEvent extension fields received in structured content mode were mapped onto message headers without applying any header filter strategy
GHSA-vvwm-3j43-7pfm
pkg: org.apache.camel:camel-knative, org.apache.camel:camel-knative, org.apache.camel:camel-knative
eco: maven
published: Aug 24, 2026
Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache Camel Knative component

The Knative consumer in camel-knative maps inbound CloudEvent attributes onto Camel message headers. In binary content mode t…

CVE-2026-63621
NVD

MEDIUM
CVE-2026-81716
CVE-2026-81716
pkg: openssl

published: Aug 27, 2026

openssl_encrypt (pip: openssl-encrypt) versions before 1.4.9 contain a path traversal flaw in PluginSandbox._is_safe_path, which authorized file access using a bare string-prefix match. A sandboxed plugin without the READ_FILES permission could read or write another plugin's directory that merely sh…
CWE: CWE-22
NVD

MEDIUM
CVE-2026-65085
CVE-2026-65085
pkg: linux

published: Aug 25, 2026

NVIDIA OpenShell for Linux contains a vulnerability in its inference proxy, where an attacker could cause an improper encoding or escaping of output. A successful exploit of this vulnerability might lead to information disclosure and data tampering.
CWE: CWE-116
GitHub-GHSA

MEDIUM
Graylog Server: System Catalog titles endpoint can be used to retrieve values of protected database fields
GHSA-q79r-r9xg-r863
pkg: org.graylog2:graylog2-server
eco: maven
published: Aug 28, 2026
### Impact

A vulnerability was found in Graylog's API endpoint for retrieving system catalog entity titles. Authenticated users could retrieve database fields of supported entities by sending a custom API request. These fields can include e.g. the password hash of a user (but not the password itsel…

CVE-2026-55425
GitHub-GHSA

MEDIUM
Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment
GHSA-569v-q83c-3j3g
pkg: code.vikunja.io/api
eco: go
published: Aug 28, 2026
## Summary

`POST /api/v1/projects/{project}/views/{view}/buckets/{bucket}` mass-assigns the request body's `project_view_id` onto the bucket row. The permission check only verifies that the URL-supplied bucket already belongs to the URL-supplied `(project, view)` pair; the body's `project_view_id` …

CVE-2026-55067
GitHub-GHSA

MEDIUM
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
GHSA-fwjf-m4qw-9f2x
pkg: django-cms
eco: pip
published: Aug 24, 2026
### Summary
The CMS page cache key ignores the request headers that plugins declare via `get_vary_cache_on()`. The header is added to the response `Vary` header, but the CMS's own cache key does not incorporate the header values, so the first visitor's variant is served to all subsequent visitors re…
CVE-2026-54625
NVD

MEDIUM
CVE-2026-82274
CVE-2026-82274
pkg: oauth

published: Aug 28, 2026

Twenty through 2.35.0 contains an open redirect vulnerability in the OAuthPropagatorController.propagateOAuthCallback endpoint that treats the state query parameter as a redirect URL. Attackers can craft malicious requests to redirect users to arbitrary hosts while forwarding OAuth authorization cod…
CWE: CWE-601
GitHub-GHSA

MEDIUM
utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins
GHSA-ppx3-28rw-8fpf
pkg: utcp-gql, utcp-websocket
eco: pip
published: Aug 25, 2026
### Summary

The fix for CVE-2026-44661 (commit `5b16e43`) added the `ensure_secure_url()` / `is_secure_url()` helpers and wired them into the three HTTP-family plugins, but it did not reach the GraphQL or WebSocket plugins. The GraphQL plugin (`utcp-gql`) still uses the `startswith` prefix check th…

CVE-2026-12210
NVD

MEDIUM
CVE-2026-81681
CVE-2026-81681
pkg: openssl

published: Aug 27, 2026

openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 advertise a portable USB workspace as an 'Encrypted USB Workspace' with AES-256-GCM encryption and write a marker declaring the workspace encrypted, but the workspace directory is actually stored in cleartext and the derived encryption …
CWE: CWE-311
NVD

MEDIUM
CVE-2026-75573
CVE-2026-75573
pkg: tls

published: Aug 27, 2026

In MongoDB Connector for BI, mongodrdl may write a TLS private-key password to standard error when the password is supplied through both the connection URI and the corresponding command-line option. A local user with access to the captured command output and encrypted key file may use the disclosed …
CWE: CWE-532
GitHub-GHSA

MEDIUM
SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets
GHSA-hgpf-8634-g44c
pkg: github.com/seaweedfs/seaweedfs
eco: go
published: Aug 28, 2026
### Summary
SeaweedFS routes requests signed with SigV4 service `s3tables` to the S3Tables
management API. Authorization on that path collapsed account-less S3 identities
into the shared `admin` account and failed open, so a user holding only ordinary
S3 `Read` credentials — and no S3Tables-specif…
CVE-2026-55873
GitHub-GHSA

MEDIUM
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
GHSA-2p9g-x3cv-5hh4
pkg: weblate
eco: pip
published: Aug 28, 2026
### Impact
The several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404.

### Patches
* https://github.com/WeblateOrg/weblate/pull/19971

### References
Thanks to Yaohui Wang for reporting this via GitHub.

CVE-2026-55227
GitHub-GHSA

MEDIUM
Yamcs has DOM XSS in Extension Routing
GHSA-9272-wg2r-7xmx
pkg: org.yamcs:yamcs-core, org.yamcs:yamcs-core
eco: maven
published: Aug 28, 2026
**Attack type**: Unauthenticated remote
**Impact**: Execution of arbitrary JavaScript in a user’s browser.
**Affected components**: extension.matcher.ts:12, extension.component.ts:40, app.component.ts:134.

Yamcs is vulnerable to cross-site scripting in the /ext URL endpoint. By inputting special…

CVE-2026-55566
GitHub-GHSA

MEDIUM
Yamcs: Insecure Direct Object Reference (IDOR) in PacketsApi allows unprivileged users to dump all telemetry packets
GHSA-8xjq-pr36-ccgf
pkg: org.yamcs:yamcs-core, org.yamcs:yamcs-core
eco: maven
published: Aug 28, 2026
## Summary
The `PacketsApi.exportPackets` endpoint in Yamcs fails to properly enforce object-level privileges (`ReadPacket`) when an API request omits specific packet names. As a result, an attacker with a low-privileged account (or any authenticated user with zero privileges) can dump the entire ar…
CVE-2026-55548
GitHub-GHSA

MEDIUM
Yamcs's Missing Authorization on Role and Privilege Enumeration Endpoints Allows Any Authenticated User to Disclose Full Security Configuration
GHSA-cvw4-55pp-3hfq
pkg: org.yamcs:yamcs-core, org.yamcs:yamcs-core
eco: maven
published: Aug 28, 2026
## Summary

Missing authorization checks on three IAM API endpoints (`GET /api/roles`, `GET /api/roles/{name}`, `GET /api/privileges`) allow any authenticated user — regardless of their assigned permissions — to enumerate the complete list of system privileges and role definitions. An attacker w…

CVE-2026-55547
GitHub-GHSA

MEDIUM
Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0
GHSA-44v6-7fxq-vgf4
pkg: code.vikunja.io/api
eco: go
published: Aug 28, 2026
## Summary

The fix for CVE-2026-35595 (project re-parenting privilege escalation) only gates reparent operations when `parent_project_id > 0`. A user with Write (but not Admin) permission on a shared child project can detach it from its parent by sending `parent_project_id: 0`, bypassing the Admin …

CVE-2026-55064
GitHub-GHSA

MEDIUM
Pocket-ID has an Open Redirect on the OIDC /authorize page via unvalidated redirect_uri with prompt=none
GHSA-2wvm-8mvp-22qv
pkg: github.com/pocket-id/pocket-id/backend
eco: go
published: Aug 28, 2026
### Summary
The OIDC authorization page in the pocket-id frontend redirects the browser to an attacker-controlled URL without consulting the backend redirect_uri allow-list when the request uses prompt=none. An attacker who knows a valid client_id can craft an /authorize link that sends a victim (or…
CVE-2026-55834
NVD

MEDIUM
CVE-2026-33263
CVE-2026-33263
pkg: tls

published: Aug 28, 2026

When mail_max_userip_connections is set (default 10) and reached, submission-login can crash with epoll() panic caused by file descriptor handling issues. If running in high-security mode (default for community releases), only the new submission connection gets terminated. If running in high-perform…
CWE: CWE-403
NVD

MEDIUM
CVE-2026-77789
CVE-2026-77789
pkg: react

published: Aug 26, 2026

The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.1 does not verify that a subscription belongs to the customer bound to the requesting customer-portal session before acting on it, allowing a user with a confirmed portal session to cancel, reactivate or modify subscriptions belong…
CWE: CWE-639
NVD

MEDIUM
CVE-2026-79084
CVE-2026-79084
pkg: google chrome, microsoft windows

published: Aug 25, 2026

Inadequate encryption strength in Notifications in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-326
NVD

MEDIUM
CVE-2026-78979
CVE-2026-78979
pkg: google chrome, microsoft windows

published: Aug 25, 2026

Race condition in Core in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
CWE: CWE-362
NVD

MEDIUM
CVE-2026-78946
CVE-2026-78946
pkg: google chrome

published: Aug 25, 2026

Incorrect authorization in Select in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
CWE: CWE-863
NVD

MEDIUM
CVE-2026-78942
CVE-2026-78942
pkg: google chrome

published: Aug 25, 2026

Incorrect reference resolution in Loader in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via crafted network traffic. (Chromium security severity: Medium)
CWE: CWE-706
NVD

MEDIUM
CVE-2026-78940
CVE-2026-78940
pkg: google chrome

published: Aug 25, 2026

Improper initialization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-665
NVD

MEDIUM
CVE-2026-78908
CVE-2026-78908
pkg: google chrome

published: Aug 25, 2026

Information leak in Canvas in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-200
NVD

MEDIUM
CVE-2026-78896
CVE-2026-78896
pkg: google chrome

published: Aug 25, 2026

Information leak in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Low)
CWE: CWE-200
NVD

MEDIUM
CVE-2026-78895
CVE-2026-78895
pkg: google chrome

published: Aug 25, 2026

Information leak in Paint in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-200
NVD

MEDIUM
CVE-2026-62986
CVE-2026-62986
pkg: python

published: Aug 25, 2026

OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13, the PyOpenEXR Python bindings return stale heap data when reading a crafted deep scanline EXR that uses laye…
CWE: CWE-200, CWE-457, CWE-908
NVD

MEDIUM
CVE-2026-21753
CVE-2026-21753
pkg: go

published: Aug 25, 2026

HCL Hive is affected by weak software supply chain governance, which could lead to the inclusion of vulnerable, unmaintained, or malicious third-party dependencies within the application environment.
CWE: CWE-1104
NVD

MEDIUM
CVE-2026-81680
CVE-2026-81680
pkg: openssl

published: Aug 27, 2026

openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presence in envelope-format encrypted files, allowing attackers to remove recovery slots without re-encrypting the payload. Attackers can modify the file header to delete recovery-slot fields and bypass authentication, silently…
CWE: CWE-347
GitHub-GHSA

MEDIUM
AsyncHttpClient stores cookie for an unrelated domain (cookie tossing) via ThreadSafeCookieStore
GHSA-m452-q8c9-rg2f
pkg: org.asynchttpclient:async-http-client, org.asynchttpclient:async-http-client
eco: maven
published: Aug 26, 2026
### Impact
A **cookie tossing / cookie injection** issue (CWE-1275). `ThreadSafeCookieStore` stored a cookie under the value of its `Domain` attribute without verifying that the responding host is allowed to set a cookie for that domain (RFC 6265 §5.3 step 6). A host the client connects to can the…
CVE-2026-55688
GitHub-GHSA

MEDIUM
Graylog token revocation endpoint allows authenticated users to delete other users’ access tokens
GHSA-j769-9gv9-65gr
pkg: org.graylog2:graylog2-server, org.graylog2:graylog2-server, org.graylog2:graylog2-server
eco: maven
published: Aug 28, 2026
### Impact

Graylog contains an insecure direct object reference (IDOR) vulnerability in the token revocation endpoint. An authenticated user can delete access tokens belonging to other users, including service account tokens and administrator tokens, if they know or can guess a valid token identifi…

CVE-2026-55867
GitHub-GHSA

MEDIUM
arc has unauthenticated cluster node admission when `cluster.shared_secret` is unset
GHSA-p378-jp5r-gpgw
pkg: github.com/basekick-labs/arc
eco: go
published: Aug 28, 2026
## Summary

Arc Enterprise clustering accepts cluster join requests without authentication when `cluster.enabled=true` but `cluster.shared_secret` is not configured. The coordinator validates HMAC authentication only if a shared secret is non-empty; otherwise, a network attacker who can reach the co…

CVE-2026-55678
GitHub-GHSA

MEDIUM
AIIR verification and policy gates could report success without enforcing the control (fail-open)
GHSA-73p9-6hrp-8qhr
pkg: aiir
eco: pip
published: Aug 28, 2026
### Summary
Several of AIIR's verification and policy paths could return a success/"verified" result without actually enforcing the control they represent — they could **fail open** rather than fail closed. For a tool whose purpose is trustworthy verification, a consumer relying on these gates may…
GitHub-GHSA

MEDIUM
Buffa Vulnerable to Memory Exhaustion Denial of Service in decode_unknown_field via Unbounded Allocation
GHSA-f9qc-qg88-7pq5
pkg: buffa
eco: rust
published: Aug 28, 2026
The `decode_unknown_field` function in buffa's protobuf decoder allocated heap memory in proportion to untrusted input (unknown fields in the serialized protobuf) without enforcing an allocation budget. Any message decoded from untrusted input using code generated with `preserve_unknown_fields=true`…
CVE-2026-55407
GitHub-GHSA

MEDIUM
Buffa has a Use-After-Free in OwnedView via Unsound 'static Lifetime Promotion in Deref
GHSA-9pwq-gcrx-wghh
pkg: buffa
eco: rust
published: Aug 28, 2026
A soundness bug in `buffa`'s `OwnedView<V>` allowed safe Rust code to trigger a use-after-free. The `OwnedView::decode` constructor transmuted a borrowed slice to `&'static [u8]`, and the `Deref` implementation exposed the promoted `'static` lifetime on borrowed view fields (such as `&'static str` a…
CVE-2026-55406
GitHub-GHSA

MEDIUM
Vikunja has a project duplication bypasses write-permission check on the target parent project
GHSA-f27p-pw2p-9pr4
pkg: code.vikunja.io/api
eco: go
published: Aug 28, 2026
## Summary

The project-duplication endpoint fails to enforce write access to the target parent project. Any authenticated (non-link-share) user can duplicate a project they can read into **any** parent project on the instance, regardless of whether they have write access to that parent — injectin…

CVE-2026-54766
GitHub-GHSA

MEDIUM
n8n-nodes-sqlite3 vulnerable to path traversal via user-controlled database file path (db_path parameter)
GHSA-q7m3-rhxg-7vxr
pkg: n8n-nodes-sqlite3
eco: npm
published: Aug 27, 2026
## Affected versions
< 1.0.0

## Patched version
1.0.0

## Description
In versions prior to 1.0.0, the SQLite node accepted the database file
path as a direct node parameter visible and editable in the workflow.
A workflow author who mapped untrusted user input to the db_path field
could allow an at…

CVE-2026-54687
GitHub-GHSA

MEDIUM
vibeio-http has a DoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously crafted chunk lengths
GHSA-fx4f-mhw4-qm7j
pkg: vibeio-http
eco: rust
published: Aug 24, 2026
When using the affected versions of the `vibeio-http` crate, an attacker could craft a malicious HTTP/1.x request with a large chunk length (between `usize::MAX – 1` and `usize::MAX` inclusive) and send it, causing the server to crash (integer overflow panic in debug builds, split_to out of bounds p…
GitHub-GHSA

MEDIUM
Cloudreve's remote download file paths can escape the selected destination directory
GHSA-w8j7-39hp-8×59
pkg: github.com/cloudreve/Cloudreve/v4
eco: go
published: Aug 24, 2026
### Summary

Cloudreve trusts file paths returned by the configured remote downloader. A downloader-reported path such as `../../escaped.txt` can cause a downloaded file to be created outside the user-selected destination directory.

### Details

In the remote download master transfer path, Cloudrev…

GitHub-GHSA

MEDIUM
Gorilla WebSocket Uses Cryptographically Weak PRNG for WebSocket Mask Key
GHSA-w67g-5rqw-f597
pkg: github.com/gorilla/websocket
eco: go
published: Aug 24, 2026
gorilla/websocket used `math/rand` (cryptographically weak pseudo-random number generator) to generate WebSocket frame mask keys prior to commit d67f4185. WebSocket masking keys MUST be unpredictable to prevent frame content injection attacks. math/rand produces deterministic output when seeded with…
GitHub-GHSA

MEDIUM
tokio-postgres: Panic on a `DataRow` with fewer fields than columns allows denial of service
GHSA-3gjw-f78c-vvpw
pkg: tokio-postgres
eco: rust
published: Aug 24, 2026
A malicious or compromised server can send a row containing fewer fields than
its row description declares columns. Reading one of the missing columns then
panics with an out-of-bounds index, aborting the calling task. This affects even
the otherwise non-panicking `try_get`, and both `Row` and `Simp…
GitHub-GHSA

MEDIUM
postgres-protocol: Panic decoding a malformed `hstore` value allows denial of service
GHSA-rgqc-3x5p-6gwg
pkg: postgres-protocol
eco: rust
published: Aug 24, 2026
A malicious or compromised server can return a binary `hstore` value with an
invalid internal length field, causing the client to panic while decoding it.

Applications that connect only to a trusted database are not exposed; the risk
applies to clients that may connect to untrusted or user-supplied…


Vulnerability Digest — August 24, 2026 · 63 Critical · 8 Exploited






Vulnerability Digest — Monday, August 24, 2026


Security Report

Monday, August 24, 2026  ·  Last 7 days  ·  Min severity: MEDIUM
Total Findings
398
Critical
63
High
183
Actively Exploited
8
CISA-KEV8
NVD236
GitHub-GHSA154
Findings sorted by severity
CISA-KEV

CRITICAL
Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
CVE-2026-73570
pkg: Synacor Zimbra Collaboration Suite (ZCS)

published: Aug 21, 2026

Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
TrueConf Server Code Injection Vulnerability
CVE-2026-72530
pkg: TrueConf Server

published: Aug 20, 2026

TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
TrueConf Server Missing Authentication for Critical Function Vulnerability
CVE-2026-72529
pkg: TrueConf Server

published: Aug 20, 2026

TrueConf Server contains a missing authentication for critical function vulnerability which could allow a remote unauthorized attacker with network access via port 4307/TCP to execute an arbitrary script.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
MLflow Server-Side Request Forgery Vulnerability
CVE-2026-64849
pkg: MLflow MLflow

published: Aug 19, 2026

MLflow contains a server-side request forgery vulnerability that can allow attackers to reach internal or cloud metadata services and receive response_status and response_body.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability
CVE-2026-33824
pkg: Microsoft Internet Key Exchange (IKE) Service Extensions

published: Aug 18, 2026

Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Microsoft SharePoint Weak Authentication Vulnerability
CVE-2026-55040
pkg: Microsoft SharePoint

published: Aug 18, 2026

Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Apple macOS Improper Authentication Vulnerability
CVE-2026-65400
pkg: Apple macOS

published: Aug 18, 2026

Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Broadcom VMware vCenter Path Traversal Vulnerability
CVE-2026-59310
pkg: Broadcom VMware vCenter

published: Aug 18, 2026

Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
NVD

CRITICAL
CVE-2026-61539
CVE-2026-61539
pkg: express

published: Aug 21, 2026

Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and earlier, Xinference passes attacker-influenced Llama3 tool-call output to eval() in xinference/model/llm/tool_parsers/llama3_tool_parser.py and xinference/model/llm/utils.py. Requests to /v1/chat/comp…
CWE: CWE-95
GitHub-GHSA

CRITICAL
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
GHSA-x2rj-828p-hx9m
pkg: xinference
eco: pip
published: Aug 21, 2026
### Summary

Xinference used Python's unsafe `eval()` function when parsing Llama3 tool-call output generated by a large language model. Because the model output can be influenced by attacker-controlled prompts sent to the chat completion API, a remote attacker can craft prompts that cause the model…

CVE-2026-61539
NVD

CRITICAL
CVE-2026-22306
CVE-2026-22306
pkg: windows

published: Aug 19, 2026

Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext
transmission of sensitive information vulnerability in Ozols Grupa OZOLS
on Windows caused by an abandoned auto-update domain. Affected
component: the automatic update channel – Ozo…
CWE: CWE-319, CWE-494, CWE-829
NVD

CRITICAL
CVE-2026-70921
CVE-2026-70921
pkg: tls

published: Aug 18, 2026

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Hyperion Financial …
CWE: CWE-284
GitHub-GHSA

CRITICAL
kobako Sandbox Escape: guest eval reaches host RCE via method_missing → public_send (any bound Service)
GHSA-7pwq-q9jf-539h
pkg: kobako
eco: rubygems
published: Aug 18, 2026
### Summary
A guest mruby script running inside the Kobako sandbox can execute arbitrary
Ruby in the host process, fully escaping the sandbox.

### Details
A host embeds bound "Service" objects that guest scripts call across the wasm
boundary through the transport dispatcher. The dispatcher passed t…

CVE-2026-55107
GitHub-GHSA

CRITICAL
vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)
GHSA-m5w8-4gq2-6f8x
pkg: vm2
eco: npm
published: Aug 17, 2026
# NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)

**CWE**: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) chained with CWE-732 (Incorrect Permission Assignment for Critic…

NVD

CRITICAL
CVE-2026-63125
CVE-2026-63125
pkg: tls

published: Aug 21, 2026

Incus is a system container and virtual machine manager. Prior to version 7.3.0, an unprivileged, project-confined Incus user (a non-admin TLS/RBAC identity with `can_create_images` and `can_create_instances`) can execute arbitrary code as root on the host. A crafted image ships `backup.yaml` as a s…
CWE: CWE-59, CWE-61
NVD

CRITICAL
CVE-2026-55089
CVE-2026-55089
pkg: oauth

published: Aug 19, 2026

Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad's src/node/handler/APIHandler.ts authorizes requests to /api/2/* in the authorization_code OAuth path by using requiredClaims with the admin claim. This check requires only that the claim exists, while src/node/security/O…
CWE: CWE-863
NVD

CRITICAL
CVE-2026-60995
CVE-2026-60995
pkg: tls

published: Aug 18, 2026

Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via TLS to compromise Oracle Identit…
CWE: CWE-284
NVD

CRITICAL
CVE-2026-60990
CVE-2026-60990
pkg: oracle identity_manager_connector

published: Aug 18, 2026

Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via TLS to compromise Oracle Identit…
CWE: CWE-284
NVD

CRITICAL
CVE-2026-55166
CVE-2026-55166
pkg: tls

published: Aug 18, 2026

Lemur manages TLS certificate creation. Prior to 1.9.2, authenticated users could influence an ACME authority acme_url without an effective server-side destination restriction and trigger AcmeHandler.setup_acme_client to make backend requests. An attacker could target cloud instance metadata or inte…
CWE: CWE-285, CWE-639, CWE-918
NVD

CRITICAL
CVE-2026-47686
CVE-2026-47686
pkg: node

published: Aug 17, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, handleException() in lib/setup-sandbox.js sanitizes SuppressedError.error, SuppressedError.suppressed, and AggregateError.errors but does not sanitize Error.cause, allowing sandbox code to obtain a powerful host object such as process fr…
CWE: CWE-693
GitHub-GHSA

CRITICAL
VM2 has Missing Error.cause Sanitization that Enables Sandbox Escape to RCE
GHSA-m283-3h24-438v
pkg: vm2
eco: npm
published: Aug 17, 2026
**Affected:** vm2 <= 3.11.3
**CVSS 3.1:** 9.9 HIGH (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
**CWE:** CWE-693 (Protection Mechanism Failure)
**Prerequisite:** Embedder exposes a host function that throws an Error with `.cause` referencing a powerful host object (e.g., `process`)

## Summary

I …

CVE-2026-47686
GitHub-GHSA

CRITICAL
GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers
GHSA-mqjf-5f49-2fjh
pkg: org.geotools.jdbc:gt-jdbc-postgis, org.geotools.jdbc:gt-jdbc-postgis, org.geotools.jdbc:gt-jdbc-postgis
eco: maven
published: Aug 21, 2026
### Summary

An SQL Injection Vulnerability has been found when executing OGC Filters with PostGIS DataStore implementation:

* `jsonArrayContains` function
Requires PostGIS 12 or greater with a String or JSON field

For PostGIS 12 and greater `jsonArrayContains(<column>, <pointer>, <value>)` …

CVE-2026-76904
GitHub-GHSA

CRITICAL
surfio has an out-of-bounds read
GHSA-rcr2-hggw-43wm
pkg: surfio
eco: pip
published: Aug 18, 2026
### Impact
Prior to version 0.0.19, surfio would not correctly validate size fields in irap files, leading to a buffer overflow . The severity rating assumes that surfio is used to parse untrused files in a networking context such as a web service.

### Patches
The bug has been patched in version 0…

CVE-2026-55211
GitHub-GHSA

CRITICAL
resdata has Classic Buffer Overflow, Improper Validation of Array Index, NULL Pointer Dereference and Out-of-bounds Read
GHSA-pr85-w493-9w3x
pkg: resdata
eco: pip
published: Aug 18, 2026
### Impact
Prior to version 6.2.9 resdata would not correctly validate input in GRDECL files. The severity rating assumes that resdata is used to parse untrused files in a networking context such as a webservice.

### Patches
The bug has been patched starting with version 6.2.9.

CVE-2026-55209
NVD

CRITICAL
CVE-2026-47627
CVE-2026-47627
pkg: linux

published: Aug 18, 2026

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause path traversal. A successful exploit might lead to denial of service.
CWE: CWE-22
NVD

CRITICAL
CVE-2026-73366
CVE-2026-73366
pkg: go

published: Aug 18, 2026

Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions.
CWE: CWE-502
NVD

CRITICAL
CVE-2026-59940
CVE-2026-59940
pkg: node

published: Aug 18, 2026

Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() allows attacker-controlled JSON Promise control nodes to operate on values from the general deserialization reference table without verifying genuine inte…
CWE: CWE-502, CWE-843
NVD

CRITICAL
CVE-2026-34884
CVE-2026-34884
pkg: express

published: Aug 18, 2026

SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP.

This issue affects Apache SkyWalking MCP: 0.1.0.

Users are recommended to upgrade to version 0.2.0, which fixes this issue.

CWE: CWE-918
NVD

CRITICAL
CVE-2026-38165
CVE-2026-38165
pkg: express

published: Aug 17, 2026

A Server-Side Template Injection (SSTI) vulnerability in the Velocity template engine configuration of xdocreport v0.9.2 to v2.2.0 allows attackers to execute arbitrary code via a crafted expression.
CWE: CWE-94
NVD

CRITICAL
CVE-2026-47698
CVE-2026-47698
pkg: node

published: Aug 17, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, lib/bridge.js and lib/setup-sandbox.js fail to block stacked indirection through Function.prototype.call around dangerous host prototype getter and setter mutators, allowing sandbox code to sever a host intrinsic's prototype chain and re…
CWE: CWE-913
GitHub-GHSA

CRITICAL
vm2: Sandbox Breakout Using Dangerous Host Proto Mutators
GHSA-cfcw-xp6x-25gj
pkg: vm2
eco: npm
published: Aug 17, 2026
### Summary

VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system.

### Details

The fix for https://github.com/patriksimek/vm2/security/advisories/GHSA-v6mx-mf47-r5wg is insuffi…

CVE-2026-47698
NVD

CRITICAL
CVE-2026-74901
CVE-2026-74901
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM decryption failures trigger fallback to unauthenticated AES-CTR mode. Attackers can modify ciphertext in transit to bypass integrity verification and perform bit-flipping attacks without dete…
CWE: CWE-347
NVD

CRITICAL
CVE-2026-74900
CVE-2026-74900
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 contain a critical vulnerability in pqc.py where KEM decapsulation failures silently fall back to simulation mode, generating a deterministic shared secret from only 16 bytes of the private key and publicly available encapsulated key data. Attackers who obtain 1…
CWE: CWE-391
NVD

CRITICAL
CVE-2026-74899
CVE-2026-74899
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecutor that exposes Python type objects in restricted exec() builtins. Attackers can traverse the Python class hierarchy via __class__.__mro__.__subclasses__() to access system functions and execute arbit…
CWE: CWE-95
NVD

CRITICAL
CVE-2026-74896
CVE-2026-74896
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in the DangerousPatternVisitor AST analyzer that fails to detect dunder attribute traversal techniques. Attackers can use __class__, __bases__, __subclasses__(), and __globals__ chains to access restricted functions and exe…
CWE: CWE-693
NVD

CRITICAL
CVE-2026-74895
CVE-2026-74895
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default process isolation mode for plugin execution. Attackers can execute malicious plugins with unrestricted access to the filesystem, network, subprocess execution, and all Python modules.
CWE: CWE-693
NVD

CRITICAL
CVE-2026-74894
CVE-2026-74894
pkg: openssl

published: Aug 17, 2026

openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token function that accepts any non-empty Bearer token string without validation. Attackers can upload arbitrary public keys, enumerate all keys, and revoke keys belonging to any user by providing any Bear…
CWE: CWE-287
NVD

CRITICAL
CVE-2026-74891
CVE-2026-74891
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server configuration files. Attackers on the same network can access PostgreSQL databases using well-known default credentials to retrieve sensitive data.
CWE: CWE-798
NVD

CRITICAL
CVE-2026-74889
CVE-2026-74889
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, reducing entropy extraction and determinism. Attackers can exploit predictable key derivation with identical inputs to weaken cryptographic security against multi-target attacks.
CWE: CWE-326
NVD

CRITICAL
CVE-2026-74886
CVE-2026-74886
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the PluginImportGuard blocks a different set of modules than the AST analyzer's DANGEROUS_MODULES set. Attackers can bypass AST analysis through string obfuscation or encoding to import unblocked dangerous modu…
CWE: CWE-184
NVD

CRITICAL
CVE-2026-74880
CVE-2026-74880
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and telemetry server routes. Attackers can extract tokens from server logs, proxy logs, browser history, and HTTP Referer headers to gain unauthorized access.
CWE: CWE-598
NVD

CRITICAL
CVE-2026-74878
CVE-2026-74878
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection that is not shared across workers and is lost on server restart. Attackers can distribute authentication attempts across multiple server instances or retry immediately after a restart to bypass rate l…
CWE: CWE-770
NVD

CRITICAL
CVE-2026-74876
CVE-2026-74876
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict() that creates key bundles from untrusted data without verifying signatures. Attackers can call from_dict() followed by to_identity() without signature verification to encrypt data using attacker-controlled pu…
CWE: CWE-347
NVD

CRITICAL
CVE-2026-74875
CVE-2026-74875
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema library is not installed, allowing malformed metadata to be accepted. Attackers can remove the jsonschema package or supply unknown metadata format versions to bypass all schema checks and process maliciou…
CWE: CWE-345
NVD

CRITICAL
CVE-2026-74872
CVE-2026-74872
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementation that uses broad glob patterns to load .so modules without integrity verification. Attackers can place malicious .so files matching the whirlpool*py313*.so pattern in site-pack…
CWE: CWE-426
NVD

CRITICAL
CVE-2026-53548
CVE-2026-53548
pkg: jwt

published: Aug 19, 2026

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.6.1, the GET /host/db/host/:id/password endpoint in src/backend/database/routes/host.ts accepts an authenticated user's numeric host ID and the field=password or field=sudoPasswor…
CWE: CWE-285, CWE-639
NVD

CRITICAL
CVE-2026-76036
CVE-2026-76036
pkg: google chrome, google android

published: Aug 18, 2026

Buffer overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-122
NVD

CRITICAL
CVE-2026-76035
CVE-2026-76035
pkg: go

published: Aug 18, 2026

Inappropriate implementation in Media in Google Chrome on on Mac prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-20
NVD

CRITICAL
CVE-2026-12564
CVE-2026-12564
pkg: kubernetes

published: Aug 18, 2026

A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service account token and sends it to an attacker-controlled URL when a HashiCorp Vault Secret Lookup credential w…
CWE: CWE-918
NVD

CRITICAL
CVE-2026-71424
CVE-2026-71424
pkg: oauth

published: Aug 17, 2026

Onyx is an open-source AI platform. Prior to 3.1.10, 3.2.14, and 4.0.0, Onyx's GET /api/mcp/servers and GET /api/mcp/servers/persona/{persona_id} endpoints expose another user's OAuth Authorization header because OnyxTokenStorage.set_tokens and OnyxTokenStorage.set_client_info in backend/onyx/server…
CWE: CWE-200, CWE-863
NVD

CRITICAL
CVE-2026-66794
CVE-2026-66794
pkg: kubernetes

published: Aug 19, 2026

A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker, who can access the user-facing route, to bypass authentication and authorization checks. By manipulating URL path segments, the attacker can proxy req…
CWE: CWE-918
GitHub-GHSA

CRITICAL
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
GHSA-7gwp-5pfp-969j
pkg: mlflow
eco: pip
published: Aug 17, 2026
### Summary
The default MLflow Tracking Server (`mlflow server`, no authentication, default SQLite backend) exposes the model-registry webhooks API unauthenticated, including a synchronous `POST /api/2.0/mlflow/webhooks/{id}/test` endpoint that returns the upstream response status and body to the ca…
CVE-2026-64849
NVD

CRITICAL
CVE-2026-74799
CVE-2026-74799
pkg: go

published: Aug 17, 2026

SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints including heap and goroutine dumps without authentication when –mode flag is not set to exactly prod. Attackers can access /debug/pprof/heap and related endpoints to extract in-memory secrets including AccessAuthCode and AI provider AP…
CWE: CWE-215
NVD

CRITICAL
CVE-2026-77776
CVE-2026-77776
pkg: docker

published: Aug 21, 2026

Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The header is read directly at several points in headroom/proxy/handlers/openai.py, including the chat completion and websocket paths, and nothing binds the value to the caller. A client can therefore name anot…
CWE: CWE-639
GitHub-GHSA

CRITICAL
Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import
GHSA-rrwh-6jrq-wp5v
pkg: github.com/dgraph-io/dgraph/v25
eco: go
published: Aug 20, 2026
## Summary

Dgraph Alpha exposes the RPCs used for external snapshot import on the public gRPC port `:9080` without authentication or authorization. As a result, an unauthenticated network client can open `StreamExtSnapshot` and send Badger stream data to the target group’s store. In addition, the…

CVE-2026-54061
NVD

CRITICAL
CVE-2026-71960
CVE-2026-71960
pkg: jwt

published: Aug 19, 2026

Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnerability in the Mosquitto MQTT broker's authentication plugin that allows unauthenticated attackers to forge valid JWT tokens by extracting the secret from the firmware image. Attackers can use the extr…
CWE: CWE-798
NVD

CRITICAL
CVE-2026-52723
CVE-2026-52723
pkg: tls

published: Aug 18, 2026

ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3.0, ePA 3.x Integration performs VAU server certificate validation in app/vau/VAUProtokoll.py without anchoring the signed_vau_server_pub_keys and AUT_…
CWE: CWE-295
GitHub-GHSA

CRITICAL
New API: Integer overflow in quota billing yields negative charges (self-crediting)
GHSA-8r8v-xf7q-rcpr
pkg: github.com/QuantumNous/new-api
eco: go
published: Aug 17, 2026
## Summary

Multiple billing paths multiplied **user-controlled quantity parameters** into the quota calculation without an upper bound or overflow-safe integer conversion. A crafted extreme value (e.g. image `n = 18446744073686646784`, a wrapped-negative accepted by a `*uint` field) makes conversio…

CVE-2026-71479
GitHub-GHSA

CRITICAL
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation
GHSA-6x2c-phff-wx57
pkg: github.com/QuantumNous/new-api
eco: go
published: Aug 17, 2026
## Vulnerability Information

– **Product**: new-api
– **Affected versions**: versions before `v1.0.0-rc.7` that serialize `User.AccessToken` as `access_token`; the issue was confirmed in `v0.12.14`
– **Patched version**: `v1.0.0-rc.7`
– **Fixed commit**: `0936e2504655a5cbf7bc3c388f6d3e2bb24916d3`
-…

CVE-2026-64859
GitHub-GHSA

CRITICAL
JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions
GHSA-66mm-25pp-rfff
pkg: jsonata, jsonata
eco: npm
published: Aug 21, 2026
Before JSONata `2.2.1` and `1.8.8` it was possible to execute arbitrary code with
crafted expressions, due to:
– overwriting `$clone` allowing mutation of objects via transforms (see
[`evaluateTransformExpression`](https://github.com/jsonata-js/jsonata/blob/8ee4476f8a228bfc7a62979ae0a9c13a4043cd03/s…
CVE-2026-77415
GitHub-GHSA

CRITICAL
JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions
GHSA-2943-5xfg-gq5f
pkg: jsonata, jsonata
eco: npm
published: Aug 21, 2026
Before JSONata `2.2.1` and `1.8.8` it was possible to execute arbitrary code with
crafted expressions, due to a bypassable `hasOwnProperty` check in
`environment.lookup`
https://github.com/jsonata-js/jsonata/blob/8ee4476f8a228bfc7a62979ae0a9c13a4043cd03/src/jsonata.js#L1863-L1871

This was fixed in …

CVE-2026-77414
GitHub-GHSA

CRITICAL
JSONata: Arbitrary Code Execution via crafted JSONata expressions
GHSA-8gq3-vp5j-2grp
pkg: jsonata, jsonata
eco: npm
published: Aug 21, 2026
## Impact

Before JSONata `2.2.0` and `1.8.8` it was possible to execute arbitrary code with crafted expressions, due to a missing `hasOwnProperty` check in the `lookup` function:
https://github.com/jsonata-js/jsonata/blob/f9632e01e6e67d4f9f00593f9795420cb4b57f48/src/functions.js#L1686-L1705

This w…

CVE-2026-77413
GitHub-GHSA

CRITICAL
Qinglong has an incomplete fix for CVE-2026-3965: Improper Authentication
GHSA-v667-gc2r-2xm7
pkg: @whyour/qinglong
eco: npm
published: Aug 20, 2026
### Summary

The init guard middleware in Qinglong only checks `/api/user/init` paths but not `/open/user/init`, which is whitelisted from JWT authentication and rewritten to `/api/user/init` after the guard has already passed, allowing unauthenticated admin credential reset on initialized instances…

CVE-2026-55445
NVD

HIGH
CVE-2026-62675
CVE-2026-62675
pkg: python

published: Aug 21, 2026

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, multipart POST /v1/sessions accepts an authenticated user's agent bundle and omnigent/server/bundles.py validate_agent_bundle does not reject a tools..callable dotted Python path. omnigent…
CWE: CWE-94
NVD

HIGH
CVE-2026-76023
CVE-2026-76023
pkg: linux

published: Aug 20, 2026

Improper resource control in Linux Toolkit Theming in Google Chrome prior to 151.0.7922.173 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-913
NVD

HIGH
CVE-2026-76022
CVE-2026-76022
pkg: go

published: Aug 20, 2026

Buffer overflow in Network in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-122
NVD

HIGH
CVE-2026-76021
CVE-2026-76021
pkg: go

published: Aug 20, 2026

Use after free in DOM in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-76018
CVE-2026-76018
pkg: go

published: Aug 20, 2026

Privilege elevation in Import in Google Chrome prior to 151.0.7922.173 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted file. (Chromium security severity: High)
CWE: CWE-250
NVD

HIGH
CVE-2026-76017
CVE-2026-76017
pkg: go

published: Aug 20, 2026

Use after free in Chromoting in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-73040
CVE-2026-73040
pkg: docker

published: Aug 20, 2026

Dockge validates a stack name only on the write path. In backend/stack.ts the allow-list check in validate(), which requires the name to match ^[a-z0-9_-]+$, is reached from save() alone, while the path getter returns path.join(this.server.stacksDir, this.name) and Stack.getStack builds path.join(se…
CWE: CWE-22
NVD

HIGH
CVE-2026-76832
CVE-2026-76832
pkg: python

published: Aug 19, 2026

Agno's PythonTools in libs/agno/agno/tools/python.py contains a path traversal vulnerability that allows attackers to read, write, or execute arbitrary files by supplying parent-directory traversal sequences in the file_name argument passed to read_file, save_to_file, or run_python_file tool actions…
CWE: CWE-22
NVD

HIGH
CVE-2026-76314
CVE-2026-76314
pkg: splunk splunk

published: Aug 19, 2026

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could perform Remote Code Execution (RCE) by submitting crafted Splunk Web Manager Configuration content. The user could then access all relevant data and affect syste…
CWE: CWE-94
NVD

HIGH
CVE-2026-76259
CVE-2026-76259
pkg: splunk splunk, microsoft windows

published: Aug 19, 2026

In Splunk Enterprise for Windows versions below 10.4.2, 10.2.6, 10.0.9, 9.4.13, and 9.3.14, a local user with access to the Windows host could bind to the management port before Splunk Enterprise starts, intercept authentication tokens from child processes, and use those tokens to compromise all rel…
CWE: CWE-269
NVD

HIGH
CVE-2026-49255
CVE-2026-49255
pkg: windows

published: Aug 19, 2026

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.11.11, electerm constructs operating system commands in src/app/lib/fs.js by interpolating untrusted file paths into the rmrf(), mv(), and cp() functions. A malicious SSH or SFTP server can provide a…
CWE: CWE-78
NVD

HIGH
CVE-2026-44829
CVE-2026-44829
pkg: docker

published: Aug 19, 2026

Gotenberg is a Docker-powered stateless API for PDF files. In 8.32.0 and earlier, filename handling in pkg/modules/api/context.go uses filepath.Base on Linux, which does not treat backslashes as path separators, so a multipart filename containing Windows-style parent directory components survives sa…
CWE: CWE-22
NVD

HIGH
CVE-2026-50191
CVE-2026-50191
pkg: go

published: Aug 18, 2026

4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards is vulnerable to pre-account takeover when registrationEnabled, localRegistrationEnabled, and ssoRegistrationEnabled are enabled and Google, GitHub, Microsoft, or OIDC SSO is configured. The POST /api/register en…
CWE: CWE-287, CWE-288
NVD

HIGH
CVE-2026-76047
CVE-2026-76047
pkg: google chrome

published: Aug 18, 2026

Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-843
NVD

HIGH
CVE-2026-76045
CVE-2026-76045
pkg: google chrome

published: Aug 18, 2026

Use after free in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-76043
CVE-2026-76043
pkg: google chrome

published: Aug 18, 2026

Incorrect calculation in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-682
NVD

HIGH
CVE-2026-76040
CVE-2026-76040
pkg: google chrome, apple macos

published: Aug 18, 2026

Use after free in Browser in Google Chrome on on Mac prior to 151.0.7922.169 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-76038
CVE-2026-76038
pkg: google chrome

published: Aug 18, 2026

Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-843
NVD

HIGH
CVE-2026-76034
CVE-2026-76034
pkg: google chrome

published: Aug 18, 2026

Buffer overflow in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-122
NVD

HIGH
CVE-2026-48508
CVE-2026-48508
pkg: tls

published: Aug 18, 2026

Lemur manages TLS certificate creation. Prior to 1.9.1, StrictRolePermission and AuthorityCreatorPermission in lemur/auth/permissions.py call flask_principal.Permission.__init__() with zero Need objects when ADMIN_ONLY_AUTHORITY_CREATION and LEMUR_STRICT_ROLE_ENFORCEMENT are unset because both flags…
CWE: CWE-863
NVD

HIGH
CVE-2026-61574
CVE-2026-61574
pkg: go

published: Aug 18, 2026

authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the Remote Access Control endpoint list returns every configured endpoint to any authenticated user regardless of which applications the user may access, and the response includes connection settings that can contain stor…
CWE: CWE-639, CWE-863
NVD

HIGH
CVE-2026-66793
CVE-2026-66793
pkg: kubernetes

published: Aug 18, 2026

A flaw was found in the governance-policy-addon-controller component of Red Hat Advanced Cluster Management for Kubernetes. A user with permissions to annotate the namespaced ManagedClusterAddOn resource can override the governance-policy container image. This allows an attacker to run a controlled …
CWE: CWE-20
GitHub-GHSA

HIGH
Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command injection
GHSA-73wf-9vmv-5pv9
pkg: glances
eco: pip
published: Aug 17, 2026
## Summary
CVE-2026-32608 ("Command Injection via Process Names in Action Command Templates") was fixed (commit `5680a5d`) by adding `_sanitize_mustache_dict`, which replaces the shell operators `&&`, `|`, `>>`, `>` with spaces in the values rendered into action command templates.

The sanitizer onl…

CVE-2026-62982
NVD

HIGH
CVE-2026-74893
CVE-2026-74893
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 contain hardcoded default JWT signing secrets in config.py that pass validation checks. Attackers with access to source code can forge valid JWT tokens for any client_id to gain authenticated access to keyserver and telemetry APIs.
CWE: CWE-798
NVD

HIGH
CVE-2026-74883
CVE-2026-74883
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability where the plugin sandbox fails to restrict alternative file access methods like pathlib.Path and io.open. Attackers can import pathlib or io modules to read and write arbitrary files, completely bypassing the restricted_ope…
CWE: CWE-693
NVD

HIGH
CVE-2026-74877
CVE-2026-74877
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerability in the revoke_key method that allows authenticated clients to revoke any other client's key. Attackers can revoke arbitrary keys by providing a valid ML-DSA signature, bypassing the intended ownership restri…
CWE: CWE-639
NVD

HIGH
CVE-2026-66787
CVE-2026-66787
pkg: kubernetes

published: Aug 20, 2026

A flaw was found in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability stems from insufficient validation of advertised IP addresses within EndpointSlice objects. A compromised spoke cluster can exploit this by creating EndpointSlices with attacker-con…
CWE: CWE-345
NVD

HIGH
CVE-2026-49283
CVE-2026-49283
pkg: tls

published: Aug 19, 2026

The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.19.3, 4.20.2, 5.0.6, and 6.2.1, the HTTPArtifact::receive() flow can treat an unsigned embedded SAML Response as cryptographically valid for the wrong identity provider. SOAPClient::addSSLValidator(…
CWE: CWE-295
GitHub-GHSA

HIGH
Kestra vulnerable to stored XSS via custom Markdown [[link]] attribute injection
GHSA-34pm-923j-7wf8
pkg: io.kestra:kestra
eco: maven
published: Aug 18, 2026
## Summary

Kestra’s Markdown renderer supports a custom `[[link …]]` syntax that is converted into a custom HTML element. The custom Markdown parser allows attacker-controlled attributes to be rendered into the generated element without proper allowlisting or sanitization.

As a result, a user …

CVE-2026-55839
NVD

HIGH
CVE-2026-74798
CVE-2026-74798
pkg: node

published: Aug 17, 2026

SiYuan kernel before v3.7.4 contains a path traversal vulnerability in the database_clean MCP tool. The tool performs only an empty-string check on the id parameter before passing it to RemoveUnusedAttributeView (kernel/model/attribute_view.go), which builds a filesystem path via filepath.Join witho…
CWE: CWE-22
NVD

HIGH
CVE-2026-75932
CVE-2026-75932
pkg: oauth

published: Aug 21, 2026

Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom domain, edit the authentication configuration, and reroute traffic to the attacker-controlled app. Once connected to the target domain, the attacker's workspace is populated with the victim's OAuth Client…
CWE: CWE-862
NVD

HIGH
CVE-2026-77775
CVE-2026-77775
pkg: docker

published: Aug 21, 2026

Headroom's LLM proxy lets a client choose the upstream destination with the x-headroom-base-url request header. _resolve_openai_upstream_base in headroom/proxy/handlers/openai.py accepts the header value, requires only that it parse with an http or https scheme and a hostname, and returns it for use…
CWE: CWE-918
NVD

HIGH
CVE-2026-75916
CVE-2026-75916
pkg: windows

published: Aug 19, 2026

SiYuan through 3.7.3 contains a cross-site scripting vulnerability in the '((' block-reference autocomplete hint popup. In genHintItemHTML() (app/src/protyle/hint/extend.ts), a candidate block's name, alias, and memo fields are concatenated into the popup's HTML without escaping. An attacker who can…
CWE: CWE-79
NVD

HIGH
CVE-2026-75926
CVE-2026-75926
pkg: node

published: Aug 18, 2026

Hugo 0.161.0 placed the Node asset pipelines behind the Node.js permission model so that code running through PostCSS, Babel, or TailwindCSS could not reach the file system outside the project directory. Hugo 0.162.0 added tailwindcss to the AllowChildProcess default in config/security/securityConfi…
CWE: CWE-1188
GitHub-GHSA

HIGH
9Router: Authenticated Server-Side Request Forgery (SSRF) via OIDC Provider Test Endpoint
GHSA-8g4w-4ffg-8vgx
pkg: 9router
eco: npm
published: Aug 17, 2026
### Summary

A Server-Side Request Forgery (SSRF) vulnerability exists in the 9Router dashboard via the `/api/auth/oidc/test` endpoint. The application accepts a user-controlled URL string through the `issuerUrl` parameter and performs an outbound HTTP request without validating if the destination I…

CVE-2026-56677
NVD

HIGH
CVE-2026-55765
CVE-2026-55765
pkg: kubernetes

published: Aug 20, 2026

CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG embedded cleartext role passwords in `ALTER ROLE` and `CREATE ROLE` statements generated by SetUserPassword in pkg/management/postgres/utils/roles.go and appe…
CWE: CWE-256, CWE-522
NVD

HIGH
CVE-2026-68558
CVE-2026-68558
pkg: express

published: Aug 19, 2026

Wekan is open source kanban built with Meteor. From 8.36 until 9.74, the outgoing webhook Integration URL validator in models/integrations.js checked only the literal URL.hostname against regular expressions, so DNS names such as 169-254-169-254.nip.io passed that first-line check. The delivery path…
CWE: CWE-918
NVD

HIGH
CVE-2026-73410
CVE-2026-73410
pkg: node

published: Aug 17, 2026

Budibase is an open-source low-code platform. Prior to 3.40.0, packages/backend-core/src/utils/outboundFetch.ts pinned a validated address through a Node agent, but the REST integration used getDispatcher from packages/backend-core/src/utils/fetch.ts, causing undici to ignore that agent and resolve …
CWE: CWE-367, CWE-918
NVD

HIGH
CVE-2026-44901
CVE-2026-44901
pkg: python

published: Aug 19, 2026

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta2, AffectedItemsWazuhResult.merge() in framework/wazuh/core/results.py trusts the sort_casting field in a cluster worker's JSON response. During a distributed API merge…
CWE: CWE-502
NVD

HIGH
CVE-2026-76037
CVE-2026-76037
pkg: google chrome, microsoft windows

published: Aug 18, 2026

Link following in CredentialProvider in Google Chrome on on Windows prior to 151.0.7922.169 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
CWE: CWE-59
NVD

HIGH
CVE-2026-76046
CVE-2026-76046
pkg: google chrome, google android

published: Aug 18, 2026

Buffer overflow in ANGLE in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-122
NVD

HIGH
CVE-2026-76044
CVE-2026-76044
pkg: google chrome

published: Aug 18, 2026

Race condition in USB in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-367
GitHub-GHSA

HIGH
MeshCentral has unsanitized data fields
GHSA-c7hr-448w-65px
pkg: meshcentral
eco: npm
published: Aug 18, 2026
### Description

A rogue or compromised MeshAgent can inject arbitrary HTML/JavaScript via the osdesc (OS description) field in its coreinfo message. The server stores this value with zero HTML sanitization (meshagent.js:1903 only checks typeof == 'string'). When an admin views the
device details pa…

NVD

HIGH
CVE-2026-45733
CVE-2026-45733
pkg: node

published: Aug 18, 2026

Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.103.0, the #iconClass label value is returned raw by getNoteIcon() and inserted without HTML attribute encoding into class attributes in apps/client/src/widgets/quic…
CWE: CWE-79, CWE-83, CWE-693
GitHub-GHSA

HIGH
Defuddle vulnerable to XSS via unescaped attribute interpolation in site extractors
GHSA-jg4p-g6xj-4qmf
pkg: defuddle
eco: npm
published: Aug 21, 2026
## Summary

An Improper Neutralization of Input During Web Page Generation issue in the site extractor component allows an attacker-controlled attribute value to be injected into output HTML without escaping. An attacker who crafts a malicious HTML page or controls content on a matching domain can e…

CVE-2026-61824
GitHub-GHSA

HIGH
Pipelines-as-Code GitHub App token request can be redirected via untrusted Enterprise Host header
GHSA-f5f4-3hh4-f54m
pkg: github.com/openshift-pipelines/pipelines-as-code, github.com/openshift-pipelines/pipelines-as-code, github.com/openshift-pipelines/pipelines-as-code
eco: go
published: Aug 20, 2026
## Impact

Pipelines-as-Code installations using the GitHub App provider are vulnerable to GitHub App credential exfiltration through the webhook endpoint.

Affected versions accepted the `X-GitHub-Enterprise-Host` request header as the GitHub Enterprise API host during GitHub App token generation. …

CVE-2026-54167
NVD

HIGH
CVE-2026-49825
CVE-2026-49825
pkg: python

published: Aug 20, 2026

lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in “lxml.html.defs.link_attrs“ were missing “xlink:href“, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_c…
CWE: CWE-79, CWE-184
NVD

HIGH
CVE-2026-63407
CVE-2026-63407
pkg: jwt

published: Aug 19, 2026

Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.0-rc.16, the Grav API plugin CorsMiddleware returns Access-Control-Allow-Origin: * and permissive OPTIONS responses for authenticated /api/v1 endpoints. JavaScript from any origin ca…
CWE: CWE-942
NVD

HIGH
CVE-2026-47719
CVE-2026-47719
pkg: axios

published: Aug 18, 2026

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the DEVICE_WEBAPI_REQUEST and DEVICE_PROPERTY Socket.IO handlers in server/runtime/index.js omit isSocketWriteAuthorized and accept attacker-controlled property.address or endpoint connection data. A remote una…
CWE: CWE-918
NVD

HIGH
CVE-2026-66783
CVE-2026-66783
pkg: kubernetes

published: Aug 18, 2026

A flaw was found in the `submariner-operator` component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability allows a cluster administrator, or any user with permissions to modify the Submariner Custom Resource (CR), to specify an unvalidated image path. This lack of validation …
CWE: CWE-20
NVD

HIGH
CVE-2026-64679
CVE-2026-64679
pkg: go

published: Aug 21, 2026

Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. From 0.19.8 until 0.45.0, Atlantis does not consistently validate user-controlled workspace values supplied through accepted repository-level atlantis.yaml configuration or authenticated /api/pl…
CWE: CWE-22, CWE-73
GitHub-GHSA

HIGH
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation
GHSA-26w5-6g95-gj28
pkg: github.com/runatlantis/atlantis
eco: go
published: Aug 21, 2026
### Summary
Atlantis versions `>= 0.19.8` and `< 0.45.0` did not consistently validate user-controlled `workspace` values before using them to construct local workspace paths.

A crafted workspace value containing path traversal segments could cause Atlantis to resolve workspace paths outside the in…

CVE-2026-64679
NVD

HIGH
CVE-2026-76019
CVE-2026-76019
pkg: go

published: Aug 20, 2026

Incorrect authorization in Workers in Google Chrome prior to 151.0.7922.173 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-863
GitHub-GHSA

HIGH
netty-incubator-codec-ohttp: BoringSSL HPKE private key bytes exposed through toString() and exception messages
GHSA-2mc4-j865-9q4r
pkg: io.netty.incubator:netty-incubator-codec-ohttp-hpke-classes-boringssl
eco: maven
published: Aug 20, 2026
## Summary

`io.netty.incubator:netty-incubator-codec-ohttp-hpke-classes-boringssl` exposes raw HPKE private key bytes in string representations and error messages. `BoringSSLAsymmetricCipherKeyPair.toString()` includes the private-key parameter object, and `BoringSSLAsymmetricKeyParameter.toString(…

CVE-2026-61798
NVD

HIGH
CVE-2026-28150
CVE-2026-28150
pkg: go

published: Aug 20, 2026

Unauthenticated Local File Inclusion in Golo Framework < 1.7.5 versions.
CWE: CWE-98
NVD

HIGH
CVE-2026-15078
CVE-2026-15078
pkg: ibm vios, ibm aix

published: Aug 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to gain unauthorized access to AIX systems due to improper validation of TLS certificates.
CWE: CWE-295
NVD

HIGH
CVE-2026-61265
CVE-2026-61265
pkg: tls

published: Aug 18, 2026

Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component: E1 IOT Orchestrator Security). Supported versions that are affected are 9.2.0.0-9.2.26.4. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise …
CWE: CWE-284
NVD

HIGH
CVE-2026-60992
CVE-2026-60992
pkg: oracle identity_manager_connector

published: Aug 18, 2026

Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Iden…
CWE: CWE-284
GitHub-GHSA

HIGH
Lemur: Unchecked `replaces[]` lets any user silence notifications and hijack auto-rotation for arbitrary certificates
GHSA-cfh6-pv5c-38jv
pkg: lemur
eco: pip
published: Aug 18, 2026
## Summary

Repo under test: https://github.com/Netflix/lemur

The certificate create and upload endpoints accept a `replaces[]` (alias `replacements`) array that is resolved to live `Certificate` ORM objects with no ownership or `CertificatePermission` check on the referenced certificates. The SQLA…

CVE-2026-71308
NVD

HIGH
CVE-2026-71308
CVE-2026-71308
pkg: tls

published: Aug 18, 2026

Lemur manages TLS certificate creation. From 0.5.0 until 1.9.3, certificate create, upload, and edit requests accepted replaces[] or replacements identifiers that AssociatedCertificateSchema resolved with fetch_objects without a CertificatePermission check. Assigning those objects to Certificate.rep…
CWE: CWE-639, CWE-862
NVD

HIGH
CVE-2025-9210
CVE-2025-9210
pkg: jwt

published: Aug 18, 2026

Missing signature validation in JSON Web Tokens in Otalio Ship Property Management System versions before 2.22.0 allows authenticated attackers to escalate privileges via tampering with JWTs
CWE: CWE-347
NVD

HIGH
CVE-2026-50138
CVE-2026-50138
pkg: go

published: Aug 18, 2026

goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, when `goshs` is launched with WebDAV enabled (`-w`), the mode-restriction flags `–read-only`, `–upload-only`, and `–no-delete` are enforced only on the primary HTTP port. The WebDAV port is wired straight to `golang.org/x/net/webd…
CWE: CWE-284
GitHub-GHSA

HIGH
http4k: `DigestAuthProvider.verify` did not bind to request URI
GHSA-p28p-j94q-pg32
pkg: org.http4k:http4k-security-digest, org.http4k:http4k-security-digest, org.http4k:http4k-security-digest
eco: maven
published: Aug 17, 2026
### Impact

An issue in `DigestAuthProvider.verify`:

The `uri` parameter in the client's `Authorization: Digest …` response was not checked against the actual request URL. A captured Digest authentication response could be replayed against any other URL served by the same realm, breaking the per-…

CVE-2026-54148
NVD

HIGH
CVE-2026-54552
CVE-2026-54552
pkg: docker

published: Aug 18, 2026

sh provides Python process launching. Prior to 2.2.4, the _uid option in sh.py performs an incomplete privilege drop on Linux and Unix-like systems. When sh runs from an elevated process and launches a command with _uid set to an unprivileged user, the child changes its UID but can retain the parent…
CWE: CWE-273
NVD

HIGH
CVE-2026-68508
CVE-2026-68508
pkg: python

published: Aug 21, 2026

Hydra is a framework for elegantly configuring complex applications. Prior to 1.3.4, hydra.utils.instantiate() resolves and calls Python objects selected by configuration through _resolve_target() in hydra/_internal/instantiate/_instantiate2.py, allowing attacker-controlled target values and argumen…
CWE: CWE-94, CWE-470
GitHub-GHSA

HIGH
Hydra: hydra.utils.instantiate with untrusted config can lead to code execution
GHSA-2cp2-2r3c-7p7r
pkg: hydra-core
eco: pip
published: Aug 21, 2026
## Summary

`hydra.utils.instantiate()` resolves and calls Python objects from config. If an
application passes untrusted config to `instantiate()`, an attacker who controls
`_target_` and its arguments can cause arbitrary code execution in the consuming
process.

Hydra is not a network service. Exp…

CVE-2026-68508
NVD

HIGH
CVE-2026-54071
CVE-2026-54071
pkg: python

published: Aug 21, 2026

BabelDOC is a document translation tool. Prior to 0.6.3, BabelDOC's vendored PDF parser in babeldoc/pdfminer/cmapdb.py deserializes untrusted pickle data when CMapDB._load_data() loads CMap files. PDF-controlled Encoding or CMapName values and embedded PostScript usecmap operators can reach this sin…
CWE: CWE-502
NVD

HIGH
CVE-2026-18287
CVE-2026-18287
pkg: python

published: Aug 20, 2026

Aeon load_time_series_segmentation_benchmark Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of aeon. User interaction is required to exploit this vulnerability in that the target must visit a maliciou…
CWE: CWE-94
NVD

HIGH
CVE-2026-18286
CVE-2026-18286
pkg: python

published: Aug 20, 2026

Aeon load_human_activity_segmentation_datasets Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of aeon. User interaction is required to exploit this vulnerability in that the target must visit a malici…
CWE: CWE-94
NVD

HIGH
CVE-2026-61898
CVE-2026-61898
pkg: express

published: Aug 20, 2026

The Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accountsservice before 23.13.9-8ubuntu7 treat the user-controlled LANGUAGE entry in ~/.pam_environment as trusted input. The value is interpolated unescaped into a GNU sed replacement expression, allowing an …
CWE: CWE-78
NVD

HIGH
CVE-2026-43961
CVE-2026-43961
pkg: express

published: Aug 19, 2026

A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context during mark/unmark operations, allowing arbitrary Vimscript execution. This can be leveraged to run shell commands with the privileges of the user runni…
CWE: CWE-94
NVD

HIGH
CVE-2026-55426
CVE-2026-55426
pkg: linux

published: Aug 18, 2026

linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses those modules to run external monitoring commands. From the earliest affected releases until linuxfabrik-lib 5.0.0 and Linuxfabrik Monitoring Plugins 6…
CWE: CWE-78
GitHub-GHSA

HIGH
MONAI: Unsafe deserialization in NumpyReader allows arbitrary code execution via malicious .npy files
GHSA-wg9g-w2j2-8pgr
pkg: monai
eco: pip
published: Aug 18, 2026
### Summary

The `NumpyReader` class in `monai/data/image_reader.py` unconditionally uses `np.load(name, allow_pickle=True)` (line 1276), enabling arbitrary code execution when loading a crafted `.npy` or `.npz` file. This affects all MONAI versions up to and including the latest commit (5b71547). T…

GitHub-GHSA

HIGH
Incomplete Fix in MONAI: algo_from_pickle() pickle.loads() RCE still present in v1.5.2 despite GHSA-89gg-p5r5-q6r4 claiming patch
GHSA-qxq5-qhx6-94qw
pkg: monai
eco: pip
published: Aug 18, 2026
## Summary

GHSA-89gg-p5r5-q6r4 claims the pickle deserialization vulnerability in
`algo_from_pickle()` was fixed in v1.5.2. However, `monai/auto3dseg/utils.py`
has not been modified since 2024-07-12 — 18 months before v1.5.2 was released
(2026-01-29). All three `pickle.loads()` calls rema…

NVD

HIGH
CVE-2026-24183
CVE-2026-24183
pkg: linux

published: Aug 18, 2026

NVIDIA Cumulus Linux contains a vulnerability in the user management component, where an unprivileged user could use improper privilege management on the system. A successful exploit of this vulnerability might lead to escalation of privileges.
CWE: CWE-250
NVD

HIGH
CVE-2026-71551
CVE-2026-71551
pkg: node

published: Aug 18, 2026

Super Productivity is an advanced todo list app with integrated timeboxing and time tracking capabilities. Prior to 18.13.0, the EXEC IPC handler in electron/ipc-handlers/exec.ts accepts a command string from the renderer through the IPC.EXEC channel and executes it with child_process.exec(). The el…
CWE: CWE-78
NVD

HIGH
CVE-2026-75858
CVE-2026-75858
pkg: python

published: Aug 18, 2026

CodeWhale (packages codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain a remote code execution vulnerability in the rlm_eval tool. The tool's approval_requirement() returns ApprovalRequirement::Auto, which the engine treats as 'never prompt,' causing arbitrary model-supplied Python c…
CWE: CWE-94
NVD

HIGH
CVE-2026-34399
CVE-2026-34399
pkg: python

published: Aug 17, 2026

FreeCAD is a free and open-source multiplatform 3D parametric modeler. From 0.19 until 1.1.1, FreeCAD's BIM Workbench contains an eval() call on untrusted data from SVG template files. When a user creates a TechDraw page from a malicious SVG template, arbitrary Python code executes. The vulnerable c…
CWE: CWE-95
NVD

HIGH
CVE-2026-34398
CVE-2026-34398
pkg: python

published: Aug 17, 2026

FreeCAD is a free and open-source multiplatform 3D parametric modeler. From 0.19 until 1.1.1, src/Mod/BIM/bimcommands/BimProjectManager.py in the BIM Project Manager Load Template flow passes attacker-controlled FCStd Meta property values for wpposition, wpu, wpv, and wpaxis directly to eval(), allo…
CWE: CWE-95
GitHub-GHSA

HIGH
uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set
GHSA-fhgh-wq4q-r37x
pkg: gitlab.com/uniget-org/cli
eco: go
published: Aug 17, 2026
## Summary

The sigstore check on `metadata.json` is gated on the wrong side of the condition. `LoadMetadata` in `internal/config/update.go:81` verifies the bundle only when `UNIGET_IGNORE_METADATA_SIGNATURE` is non-empty, so in a normal run, where nobody sets that variable, the signature is never c…

GitHub-GHSA

HIGH
node-opcua missing nonce verification in UserNameIdentityToken authentication
GHSA-mq36-523m-x7vv
pkg: node-opcua
eco: npm
published: Aug 20, 2026
**Summary**
A missing nonce verification in the UserNameIdentityToken authentication handler allows an unauthenticated remote attacker to forge a password token that extracts as an empty string, and to replay captured authentication tokens across sessions.

**Affected versions:** <= 2.165.0
**Tested…

CVE-2026-54155
GitHub-GHSA

HIGH
LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure
GHSA-533j-2v4q-mw5h
pkg: langgraph-checkpoint-mongodb, langgraph-store-mongodb
eco: pip
published: Aug 20, 2026
# Executive Summary

A NoSQL injection issue exists in the langgraph-checkpoint-mongodb and
langgraph-store-mongodb libraries. MongoDBSaver.list() and MongoDBStore.search() methods
accept a filter parameter that is incorporated into MongoDB queries without sufficient validation.
Because MongoDB quer…

CVE-2026-55253
NVD

HIGH
CVE-2026-54493
CVE-2026-54493
pkg: docker

published: Aug 19, 2026

Koel is a free, open-source music streaming solution. Prior to 9.7.0, the Subsonic-compatible createInternetRadioStation.view and updateInternetRadioStation.view routes accept an authenticated user's streamUrl without the SafeUrl and HasAudioContentType checks used by the regular radio API. app/Http…
CWE: CWE-918
GitHub-GHSA

HIGH
Contentful MCP Server: export_space/import_space tools pass LLM-controlled `host`/`proxy` args to CMA client, redirecting server PAT to attacker-controlled endpoint
GHSA-2xhg-73j7-rrgx
pkg: @contentful/mcp-server, @contentful/mcp-tools
eco: npm
published: Aug 19, 2026
### Summary

`export_space` and `import_space` tools in `@contentful/mcp-tools` accept LLM-controlled `host` and `proxy` parameters that are spread directly into the options object passed to `contentful-export` / `contentful-import`. These libraries pass the merged options — including the attacker…

CVE-2026-53957
GitHub-GHSA

HIGH
Lemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP password / private-key passphrase) via the destinations API
GHSA-6c8m-q6g9-vrw3
pkg: lemur
eco: pip
published: Aug 18, 2026
### Summary
Lemur's destination read endpoints — `GET /api/1/destinations` and `GET /api/1/destinations/<id>` — return the full set of stored plugin option values to any authenticated user, with no authorization check and no redaction of secret-bearing options. The sibling write endpoints (`POST`/…
CVE-2026-71307
GitHub-GHSA

HIGH
Lemur: Incomplete fix for GHSA-v2wp-frmc-5q3v — ACME authority update endpoint allows non-admin to replace `acme_url` with internal IP, bypassing allowlist
GHSA-v5rc-cpwc-cfpr
pkg: lemur
eco: pip
published: Aug 18, 2026
### Summary

The fix for GHSA-v2wp-frmc-5q3v added `_validate_acme_url()` to reject `acme_url` values not in `ACME_DIRECTORY_HOST_ALLOWLIST`, but the validation is only called at **authority creation time** (POST). The authority **update** endpoint (`PUT /api/1/authorities/<id>`) accepts and stores …

CVE-2026-71303
NVD

HIGH
CVE-2026-71307
CVE-2026-71307
pkg: tls

published: Aug 18, 2026

Lemur manages TLS certificate creation. Prior to 1.9.3, GET /api/1/destinations and GET /api/1/destinations/ relied only on authentication while sibling write handlers required admin_permission. DestinationOutputSchema returned raw options and copied them into pluginOptions without redacting sensiti…
CWE: CWE-862
NVD

HIGH
CVE-2026-71303
CVE-2026-71303
pkg: tls

published: Aug 18, 2026

Lemur manages TLS certificate creation. Prior to 1.9.3, _validate_acme_url enforced ACME_DIRECTORY_HOST_ALLOWLIST when an authority was created, but PUT /api/1/authorities/ passed options to lemur/authorities/service.py without applying the same check. A user holding an authority role could replace …
CWE: CWE-918
NVD

HIGH
CVE-2026-66393
CVE-2026-66393
pkg: python

published: Aug 22, 2026

NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONTaggedDecoder.decode_obj() that allows attackers to cause denial of service by supplying deeply nested JSON structures. Attackers can craft JSON payloads exceeding the recursion limit to trigger an unhandled RecursionErro…
CWE: CWE-674
NVD

HIGH
CVE-2026-62243
CVE-2026-62243
pkg: ssl

published: Aug 22, 2026

Netty (io.netty:netty-handler) versions from 4.2.0.Final through 4.2.16.Final and versions through 4.1.136.Final disable TLS hostname verification on the SslProvider.OPENSSL client path when a plain (non-extended) X509TrustManager is used and Unsafe-based trust-manager wrapping is unavailable (Java …
CWE: CWE-297
GitHub-GHSA

HIGH
kin-openapi openai3filter: nil-pointer panic in ConvertErrors on malformed multipart/form-data body enables unauthenticated DoS
GHSA-mmfr-pmjx-hw9w
pkg: github.com/getkin/kin-openapi
eco: go
published: Aug 21, 2026
### Summary

A nil-pointer dereference in `openapi3filter.ConvertErrors` lets any unauthenticated client crash a server with a single HTTP request. When an application validates a `multipart/form-data` request body and renders the resulting validation error through the library-provided `ValidationEr…

CVE-2026-76905
GitHub-GHSA

HIGH
Keystone vulnerable to `graphql.maxTake` bypass with negative `take`
GHSA-cqmq-8755-7xvh
pkg: @keystone-6/core
eco: npm
published: Aug 21, 2026
# Summary
The value of `graphql.maxTake` can be bypassed by providing a negative input.
This can be used to exceed the developer's intended `graphql.maxTake` value, allowing queries to return results in excess of the `graphql.maxTake` value set.

# Impact
This affects any project relying on `graphql…

CVE-2026-63421
GitHub-GHSA

HIGH
Unleash: Unauthenticated single-request DoS via OpenAPI validation error formatter
GHSA-r5pq-6chh-j3xp
pkg: unleash-server, unleash-server, unleash-server
eco: npm
published: Aug 21, 2026
## Summary

An unauthenticated `POST` to any OpenAPI-validated endpoint, including the anonymous `POST /edge/validate` and `POST /edge/issue-token`, crashes the entire Unleash server with one request body of deeply-nested JSON.

When request-body validation fails, Unleash builds the error message by…

CVE-2026-63462
NVD

HIGH
CVE-2026-47827
CVE-2026-47827
pkg: windows

published: Aug 21, 2026

Command Injection in BOSH CLI tool on windows in Cloud Foundry allows a remote attacker to execute arbitrary shell commands via command injection vulnerabilities
CWE: CWE-77
NVD

HIGH
CVE-2026-72818
CVE-2026-72818
pkg: express

published: Aug 20, 2026

The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and applied by TweetTokenizer.tokenize, contains a naked-domain branch whose domain-label prefix [a-z0-9]+(?:[.\-][a-z0-9]+)* is unbounded. Input consisting of many alternating label separators can be partit…
CWE: CWE-1333
NVD

HIGH
CVE-2026-49217
CVE-2026-49217
pkg: docker

published: Aug 20, 2026

Mailu is a mail server as a set of Docker images. Prior to version 2024.06.52, a missing authorization check in the Mailu admin REST API allows any unauthenticated attacker to remove any potential IP restriction or update the comment field from any existing user token provided the REST API is enable…
CWE: CWE-306
NVD

HIGH
CVE-2026-76020
CVE-2026-76020
pkg: go

published: Aug 20, 2026

Race condition in V8 in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-367
GitHub-GHSA

HIGH
netty-incubator-codec-ohttp BinaryHttpParser: Unauthenticated CPU-exhaustion DoS via infinite loop in field-section decoding
GHSA-4899-mpch-38p3
pkg: io.netty.incubator:netty-incubator-codec-bhttp
eco: maven
published: Aug 20, 2026
# BinaryHttpParser: Unauthenticated CPU-exhaustion DoS via infinite loop in field-section decoding

– **ID:** BHTTP-LOOP-001
– **Severity:** High
– **CVSS v3.1:** 7.5 — `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H`
– **CWE:** CWE-835 (Loop with Unreachable Exit Condition) — secondary CWE-400 (U…

CVE-2026-63202
GitHub-GHSA

HIGH
netty-incubator-codec-ohttp: Binary HTTP parser infinite loop on known-length field section boundary
GHSA-8cfx-wx3q-mh5q
pkg: io.netty.incubator:netty-incubator-codec-bhttp
eco: maven
published: Aug 20, 2026
## Summary

`io.netty.incubator:netty-incubator-codec-bhttp` can enter a non-terminating parse loop when a known-length Binary HTTP field section ends exactly after a complete field line. A remote peer that can send Binary HTTP input to a Netty pipeline using `BinaryHttpParser` / `BinaryHttpDecoder`…

CVE-2026-63124
GitHub-GHSA

HIGH
node-opcua: Unbounded nonce cache enables unauthenticated heap exhaustion DoS
GHSA-6wvw-vrw4-363w
pkg: node-opcua
eco: npm
published: Aug 20, 2026
**Summary**
A process-global nonce cache with no eviction policy allows an unauthenticated remote attacker to exhaust server heap memory by repeatedly opening sessions, causing the node-opcua server process to crash.

**Affected versions:** <= 2.165.0
**Tested version:** 2.165.0
**CVSS Score:** 7.5 …

CVE-2026-54156
GitHub-GHSA

HIGH
vouch-proxy has an Unbounded Multipart Cookie Allocation DoS
GHSA-qqff-5854-px68
pkg: github.com/vouch/vouch-proxy
eco: go
published: Aug 20, 2026
## Unbounded Multipart Cookie Allocation DoS in vouch-proxy

### Summary

vouch-proxy v0.47.2 contains an unauthenticated remote denial-of-service vulnerability in its multipart cookie reassembly logic. The `/validate` endpoint parses the total cookie part count directly from the attacker-controlled…

CVE-2026-55149
NVD

HIGH
CVE-2026-62317
CVE-2026-62317
pkg: express

published: Aug 19, 2026

Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's email subaddressing blocklist in packages/core/src/libraries/sign-in-experience/email-blocklist-policy.ts used the attacker-controlled domain from email input to construct subaddressingRegex when bloc…
CWE: CWE-1333
NVD

HIGH
CVE-2026-16837
CVE-2026-16837
pkg: ssl

published: Aug 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to improper handling of a missing SSL client certificate.
CWE: CWE-400
GitHub-GHSA

HIGH
claude-faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools
GHSA-rr55-jp92-8wp2
pkg: claude-faf-mcp
eco: npm
published: Aug 19, 2026
### Summary
`claude-faf-mcp` MCP tools accept a caller-controlled `path` argument and resolve it (`~` expansion + `path.resolve()`) straight into a filesystem read/write **without confining it to a trusted project directory**. An absolute path or `../` traversal is resolved and used as-is, so the se…
GitHub-GHSA

HIGH
faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools
GHSA-j4r7-8ph4-43g3
pkg: faf-mcp
eco: npm
published: Aug 19, 2026
### Summary
`faf-mcp` MCP tools accept a caller-controlled `path` argument and resolve it (`~` expansion + `path.resolve()`) straight into a filesystem read/write **without confining it to a trusted project directory**. An absolute path or `../` traversal is resolved and used as-is, so the server pr…
GitHub-GHSA

HIGH
grok-faf-mcp has an arbitrary local file read via unconfined `path` argument in FAF tools
GHSA-cc2g-gq8c-r332
pkg: grok-faf-mcp
eco: npm
published: Aug 19, 2026
### Summary
Several `grok-faf-mcp` MCP tools accept a caller-controlled `path` argument and resolve it (`~` expansion + `path.resolve()`) straight into a filesystem read **without confining it to a trusted project directory**. An absolute path or `../` traversal is resolved and used as-is, so the se…
NVD

HIGH
CVE-2026-45798
CVE-2026-45798
pkg: tls

published: Aug 19, 2026

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.5.0 until 4.14.6 and 5.0.0-beta2, compare_wazuh_versions() in src/shared/version_op.c copies the attacker-controlled enrollment V: field into a 10-byte stack buffer with strncpy() but does not explic…
CWE: CWE-121, CWE-170
NVD

HIGH
CVE-2026-63408
CVE-2026-63408
pkg: jwt

published: Aug 19, 2026

Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.0-rc.16, the Grav API plugin JwtAuthenticator::extractBearerToken() accepts a JWT from the token URL query parameter on every /api/v1 route, including state-changing endpoints. Requ…
CWE: CWE-598
NVD

HIGH
CVE-2026-45742
CVE-2026-45742
pkg: docker

published: Aug 19, 2026

Gotenberg is a Docker-powered stateless API for PDF files. From 8.10.0 until 8.33.0, the newContext function in pkg/modules/api/context.go starts one errgroup.Go goroutine for each multipart downloadFrom entry and allows those goroutines to concurrently write to the shared ctx.files, ctx.diskToOrigi…
CWE: CWE-362
NVD

HIGH
CVE-2026-45741
CVE-2026-45741
pkg: docker

published: Aug 19, 2026

Gotenberg is a Docker-powered stateless API for PDF files. In 8.32.0 and earlier, the IsPublicIP function in pkg/gotenberg/outbound.go does not reject the 2002::/16 6to4 prefix, the 64:ff9b::/96 and 64:ff9b:1::/48 NAT64 prefixes, the fec0::/10 deprecated site-local prefix, Teredo, and other transiti…
CWE: CWE-184, CWE-918
NVD

HIGH
CVE-2026-76216
CVE-2026-76216
pkg: jwt

published: Aug 19, 2026

Vikunja through 2.4.0 contains a principal-type confusion vulnerability where LinkSharing principals with id N are treated as user principals with users.id == N at three permission checks lacking type guards. Attackers with a link-share JWT can remove victims from teams, enumerate and delete victim …
CWE: CWE-639
NVD

HIGH
CVE-2019-25766
CVE-2019-25766
pkg: go

published: Aug 19, 2026

Renovate versions >= 13.87.0 and <= 19.38.6 leak temporary repository tokens into pull request comments during certain Go Modules update failure scenarios. The issue is fixed in version 19.38.7. Anyone able to view the affected pull request comments could obtain the exposed tokens.
CWE: CWE-532
NVD

HIGH
CVE-2026-73394
CVE-2026-73394
pkg: express

published: Aug 19, 2026

Unauthenticated Broken Access Control in Stitch Express <= 1.9.0 versions.
CWE: CWE-862
NVD

HIGH
CVE-2026-52829
CVE-2026-52829
pkg: linux

published: Aug 18, 2026

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an unauthenticated IPv4 peer can deterministically terminate a synced Zebra node using the default Linux dual-stack listener configuration. The handshake path canonicalized an IPv4-mapped IPv6 PeerSocketAddr such as ::ffff:127.0.0.1 to …
CWE: CWE-617, CWE-843
NVD

HIGH
CVE-2026-47629
CVE-2026-47629
pkg: linux

published: Aug 18, 2026

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause improper input validation. A successful exploit might lead to denial of service.
CWE: CWE-20
NVD

HIGH
CVE-2026-47628
CVE-2026-47628
pkg: linux

published: Aug 18, 2026

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an allocation of resources without limits. A successful exploit might lead to denial of service.
CWE: CWE-770
NVD

HIGH
CVE-2026-24184
CVE-2026-24184
pkg: linux

published: Aug 18, 2026

NVIDIA Cumulus Linux contains a vulnerability in the Link Layer Discovery Protocol (LLDP) daemon component, where an unauthenticated attacker on an adjacent network could cause buffer overflow by sending crafted LLDP frames. A successful exploit of this vulnerability might lead to code execution.
CWE: CWE-120
GitHub-GHSA

HIGH
GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile data
GHSA-p23g-mvhj-jh3j
pkg: @geolens/sdk, geolens-cli, geolens
eco: npm
published: Aug 18, 2026
### Summary

Multiple GeoLens read/link endpoints authorized only the resource named in the
request URL (a map, a VRT, a source dataset, an AI request) and failed to
re-authorize a **second, caller-influenced dataset** that the request reached
through a relationship, layer reference, mosaic source, …

CVE-2026-55178
NVD

HIGH
CVE-2026-50578
CVE-2026-50578
pkg: tls

published: Aug 18, 2026

ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3.0, ePA 3.x Integration disables TLS certificate verification for both ePA connections in app/vau/VAUProtokoll.py and Konnektor connections in app/konn…
CWE: CWE-295
GitHub-GHSA

HIGH
@rhinostone/swig: arbitrary local file read via include/extends path traversal
GHSA-2mf3-mr2r-r4vf
pkg: @rhinostone/swig, @rhinostone/swig-core, @rhinostone/swig-twig
eco: npm
published: Aug 18, 2026
### Overview

`@rhinostone/swig` is a maintained fork of the abandoned `swig` template engine and inherited the directory-traversal vulnerability tracked upstream as CVE-2023-25345 / GHSA-2rq5-699j-x7p6. The `{% include %}`, `{% extends %}`, and `{% import %}` tags resolve their target path through …

NVD

HIGH
CVE-2026-75915
CVE-2026-75915
pkg: node

published: Aug 18, 2026

CodeWhale versions before 0.8.64 contain an environment variable exposure vulnerability in the js_execution tool that fails to scrub parent process environment variables before spawning Node.js. Attackers can craft malicious JavaScript code executed by the tool to read process.env and leak API keys,…
CWE: CWE-200
NVD

HIGH
CVE-2026-56684
CVE-2026-56684
pkg: tls

published: Aug 18, 2026

Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's tlsProcessPendingData function iterates pending_list while an authenticated client can trigger CLIENT KILL, causing connTLSClose to delete the iterator's cached next node and producing a use-after-…
CWE: CWE-416
NVD

HIGH
CVE-2026-75840
CVE-2026-75840
pkg: express

published: Aug 18, 2026

ArcadeDB before 26.8.1 contains an arbitrary file read vulnerability in the GraalVM JavaScript sandbox allowlist enforcement, which uses unescaped regular expressions to validate package names. Attackers with trigger creation privileges can use Java.type() to access java.util.zip.ZipFile or java.uti…
CWE: CWE-1025
GitHub-GHSA

HIGH
docx4j: Stack Overflow via Cyclic `w:basedOn` Style Chain leads to Denial of Service
GHSA-gc95-3vw8-vg43
pkg: org.docx4j:docx4j-core
eco: maven
published: Aug 17, 2026
### Summary
docx4j's `PropertyResolver` and several adjacent helpers recursively walk the OpenXML style inheritance chain (`w:basedOn`) without cycle detection.

A WordprocessingML document containing a cyclic style chain (for example, Style A based on B and Style B based on A) causes unbounded rec…

CVE-2026-53752
GitHub-GHSA

HIGH
http4k: Unbounded gzip decompression in `ServerFilters.GZip` / `RequestFilters.GunZip` allowed memory-exhaustion DoS
GHSA-g4w2-6h2r-3m3w
pkg: org.http4k:http4k-core, org.http4k:http4k-core, org.http4k:http4k-core
eco: maven
published: Aug 17, 2026
### Impact

`ServerFilters.GZip` and `RequestFilters.GunZip` (and the underlying `Gzip` functions used to decompress request bodies) did not impose any cap on the decompressed size. A small malicious gzip-encoded request body (on the order of kilobytes) could decompress to gigabytes, exhausting the …

CVE-2026-53659
NVD

HIGH
CVE-2026-74238
CVE-2026-74238
pkg: node

published: Aug 17, 2026

TIER IV Nebula through 1.2.0 contains an out-of-bounds read vulnerability in the Vlp32Decoder::unpack() function that allows unauthenticated remote attackers to cause the decoder to read past the end of a received UDP buffer into adjacent heap memory by sending a short UDP datagram. Attackers can se…
CWE: CWE-125
NVD

HIGH
CVE-2026-59893
CVE-2026-59893
pkg: python

published: Aug 17, 2026

sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, SQL_REGEX in sqlparse/keywords.py and the per-position loop in sqlparse/lexer.py repeatedly scan unmatched dollar-quoted literal and multiline-comment delimiters, causing quadratic CPU consumption through sqlparse.parse(), sq…
CWE: CWE-1333
GitHub-GHSA

HIGH
Netty: Memory Exhaustion in SctpMessageCompletionHandler
GHSA-2qj4-mmr9-4v2f
pkg: io.netty:netty-transport-sctp, io.netty:netty-transport-sctp
eco: maven
published: Aug 17, 2026
### Summary
SctpMessageCompletionHandler does not limit the total size of buffered fragments, allowing an unauthenticated attacker to cause an OutOfMemoryError by sending large SCTP fragments.

### Details
`io.netty.handler.codec.sctp.SctpMessageCompletionHandler` buffers fragments for incomplete SC…

CVE-2026-59902
GitHub-GHSA

HIGH
sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial of Service)
GHSA-prg7-hcfm-mfcr
pkg: sqlparse
eco: pip
published: Aug 17, 2026
### Summary

sqlparse contains a Regular Expression Denial of Service (ReDoS) vulnerability in its dollar-quoted SQL literal lexer. The regex pattern at `sqlparse/keywords.py:33` uses a backreference (`\1`) to match closing dollar-quote delimiters, causing O(n²) CPU complexity when processing input…

CVE-2026-59893
GitHub-GHSA

HIGH
vm2 has Memory Exhaustion DoS via bufferAllocLimit Bypass
GHSA-v836-6xw4-9cx3
pkg: vm2
eco: npm
published: Aug 17, 2026
### Summary:

The `bufferAllocLimit` defense (GHSA-6785-pvv7-mvg7) can be completely bypassed using `ArrayBuffer`, `SharedArrayBuffer`, or any `TypedArray` constructor. These allocate identical host-process RSS through the same V8/libuv C++ allocation path as `Buffer.alloc` but are not subject to th…

GitHub-GHSA

HIGH
New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging
GHSA-v828-m3pf-vq9q
pkg: github.com/QuantumNous/new-api
eco: go
published: Aug 17, 2026
## Summary

Unauthenticated payment webhook endpoints could read and log the entire request body before validating the webhook signature. When a payment webhook was enabled, an unauthenticated attacker could send oversized requests to public callback endpoints and force excessive memory use and log …

CVE-2026-64868
NVD

HIGH
CVE-2026-74892
CVE-2026-74892
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 contain a hardcoded default secret key in the standalone telemetry server configuration that is used for API key hashing. Attackers who know this default value can predict or forge API key hashes to compromise telemetry API authentication.
CWE: CWE-798
NVD

HIGH
CVE-2026-74888
CVE-2026-74888
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 use a non-standard PBKDF2 key derivation construction with iterations=1 per call in an outer loop, creating a KDF whose security properties have not been formally analyzed. Attackers can exploit this weakened key derivation to more efficiently crack passwords pr…
CWE: CWE-327
NVD

HIGH
CVE-2026-74884
CVE-2026-74884
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 contain a path traversal vulnerability in the _is_safe_path method where the plugin_id parameter is not sanitized before constructing the plugin config directory path. Attackers can declare a malicious plugin_id containing path traversal sequences like '../' to …
CWE: CWE-73
NVD

HIGH
CVE-2026-74882
CVE-2026-74882
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 contain an insecure default configuration that trusts the entire RFC 1918 private address space in IntegrityProxyConfig trusted_proxies. Attackers on private networks can forge client certificate headers to bypass mTLS authentication when ProxyAuth validation is…
CWE: CWE-345
NVD

HIGH
CVE-2026-74879
CVE-2026-74879
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in the /ready endpoint that returns full database exception strings to unauthenticated callers. Attackers can trigger database errors to extract sensitive information including hostnames, IP addresses, connection p…
CWE: CWE-209
NVD

HIGH
CVE-2026-74874
CVE-2026-74874
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 use Python's non-cryptographic random module for steganographic pixel selection in the generate_pseudorandom_sequence function. Attackers who know the password can recover the Mersenne Twister state from approximately 624 outputs and predict pixel locations cont…
CWE: CWE-338
NVD

HIGH
CVE-2026-78122
CVE-2026-78122
pkg: docker

published: Aug 22, 2026

docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace when the CONTAINERS environment variable is set. Attackers can use GET requests to /containers/{id}/archive, /containers/{id}/export, /containers/{id}/logs, and /containers/{id}/top to read arbitrary fi…
CWE: CWE-1220
NVD

HIGH
CVE-2026-62960
CVE-2026-62960
pkg: windows

published: Aug 21, 2026

Git for Windows is the Windows port of Git. Prior to 2.55.0.windows.4, a malicious remote Git server can advertise a bundle URI that reaches transport_get_remote_bundle_uri(), fetch_bundle_uri_internal(), and copy_uri_to_file() in bundle-uri.c during clone or fetch when transfer.bundleuri=true. Non-…
CWE: CWE-200, CWE-610
GitHub-GHSA

HIGH
Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs
GHSA-xpmj-wjcp-6pww
pkg: lemur
eco: pip
published: Aug 18, 2026
### Summary
The ACME client (used to issue certificates from Let's Encrypt / Google Public CA / private ACME CAs) connects to an `acme_url`, then issues requests to URLs that the **ACME server returns** in its directory/order/authorization/finalize responses – this is the classic ACME-client SSRF (R…
CVE-2026-70666
NVD

HIGH
CVE-2026-70666
CVE-2026-70666
pkg: tls

published: Aug 18, 2026

Lemur manages TLS certificate creation. Prior to 1.9.3, an authority-role member could update acme_url through PUT /api/1/authorities/ without revalidation and direct setup_acme_client_no_retry to an attacker-controlled ACME server. ACME directory and order responses contain newNonce, newOrder, auth…
CWE: CWE-918
NVD

HIGH
CVE-2026-59825
CVE-2026-59825
pkg: ssl

published: Aug 18, 2026

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.19 and from 4.5.0 until 4.5.12, Mastodon's app/models/concerns/user/ldap_authenticable.rb mutates OpenSSL::SSL::SSLContext::DEFAULT_PARAMS when LDAP authentication uses LDAP_TLS_NO_VERIFY=true, disabling SSL and…
CWE: CWE-295
NVD

HIGH
CVE-2026-78062
CVE-2026-78062
pkg: jwt

published: Aug 23, 2026

A vulnerability was identified in vas3k TaxHacker up to 0.8.2. The affected element is the function envSchema.parse of the file lib/config.ts of the component JWT Secret Handler. The manipulation of the argument BETTER_AUTH_SECRET leads to hard-coded credentials. The attack can be initiated remotely…
CWE: CWE-259, CWE-798
GitHub-GHSA

HIGH
Wagtail: Reflected XSS in dynamic image URL generator view
GHSA-23m2-mghx-vqmf
pkg: wagtail, wagtail
eco: pip
published: Aug 20, 2026
### Impact

A reflected cross-site scripting (XSS) vulnerability exists on the dynamic image URL generator view within the Wagtail admin interface. A user with a limited-permission editor account for the Wagtail admin could craft a URL that, when viewed by a user with higher privileges, could perfor…

CVE-2026-54263
GitHub-GHSA

HIGH
Lemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate record and revoking it
GHSA-pxmc-2ffp-8j67
pkg: lemur
eco: pip
published: Aug 18, 2026
## Summary

Repo under test: https://github.com/Netflix/lemur

`PUT /api/1/certificates/<id>/revoke` authorizes the caller against the *Lemur database row* (creator == current user, or `CertificatePermission` over the row's roles) rather than the underlying CA-side certificate identity. Separately, …

CVE-2026-71417
NVD

HIGH
CVE-2026-71417
CVE-2026-71417
pkg: tls

published: Aug 18, 2026

Lemur manages TLS certificate creation. Prior to 1.9.3, POST /api/1/certificates/upload allowed a non-read-only user to create a duplicate row using another certificate body, authority_id, serial, or external_id without requiring permission on the underlying authority. PUT /api/1/certificates//revok…
CWE: CWE-639
NVD

HIGH
CVE-2026-32657
CVE-2026-32657
pkg: node

published: Aug 18, 2026

Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Version 3.0.1, Dell VxRail Version 8.0.322, Dell PowerMax Version 10.3.0, Dell Unity Version 5.4, Dell PowerFlex Manager Version 4.5.4, Dell PowerFlex Intelligent Catalog Versions 46.377.00 and 46.382.00 and Dell PowerFlex Ra…
CWE: CWE-61
GitHub-GHSA

HIGH
GeoServer has a Server-Side Template Injection (SSTI) vulnerability in processing FreeMarker templates
GHSA-wf6j-gr27-g7ch
pkg: org.geoserver:gs-main, org.geoserver:gs-wms, org.geoserver.web:gs-web-app
eco: maven
published: Aug 19, 2026
### Summary
A server-side template injection (SSTI) vulnerability exist that allows an authenticated administrator to upload FreeMarker templates containing malicious content that can execute OS commands and read from or write to arbitrary files on the server. These FreeMarker templates are used in …
CVE-2024-45747
GitHub-GHSA

HIGH
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
GHSA-w47q-945m-q9pc
pkg: document-merge-service
eco: pip
published: Aug 19, 2026
### Impact
A remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. The vulnera…
CVE-2026-53964
NVD

HIGH
CVE-2026-15780
CVE-2026-15780
pkg: go

published: Aug 19, 2026

The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_campaign' parameter in all versions up to, and including, 14.16.8 due to insufficient input sanitization and output escaping. This makes it possi…
CWE: CWE-79
NVD

HIGH
CVE-2026-73367
CVE-2026-73367
pkg: go

published: Aug 18, 2026

Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions.
CWE: CWE-829
NVD

HIGH
CVE-2026-55013
CVE-2026-55013
pkg: windows

published: Aug 20, 2026

Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locally.
CWE: CWE-427
NVD

HIGH
CVE-2026-54616
CVE-2026-54616
pkg: windows

published: Aug 20, 2026

NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 1.0.88.0 until stable version 6.0.1698.0 and preview version 6.5.1742.0, the Lz4Decode function in NanaZip.Core/SevenZip/CPP/7zip/Archive/SquashfsHandler.cpp rejects only a zero return from LZ4_decompress_safe e…
CWE: CWE-125
NVD

HIGH
CVE-2026-17183
CVE-2026-17183
pkg: express

published: Aug 19, 2026

An authenticated user with permission to create or edit alert rules can bypass datasource query authorization by marking an alert rule query as a server-side expression while referencing a real datasource UID (incorrect authorization). This can expose data accessible through Grafana's configured dat…
CWE: CWE-863
NVD

HIGH
CVE-2026-28569
CVE-2026-28569
pkg: ssl

published: Aug 18, 2026

Unauthenticated Cross Site Scripting (XSS) in SSL Zen <= 4.7.43 versions.
CWE: CWE-79
GitHub-GHSA

HIGH
MLflow: CreateModelVersion source validation does not check READ permission on referenced run_id
GHSA-gqch-g4w5-7qcw
pkg: mlflow
eco: npm
published: Aug 17, 2026
### Summary

The `_validate_source_run` and `_validate_source_model` functions in `mlflow/server/handlers.py` verify that a model version source path is within the artifact directory of a specified run or logged model, but do not check whether the caller has READ permission on that run or model. An …

CVE-2026-69148
GitHub-GHSA

HIGH
Medplum: Improper Validation of Redirect URI in External Auth Callback allows Authorization Code Leakage
GHSA-m44r-7c5h-m6mj
pkg: @medplum/core
eco: npm
published: Aug 17, 2026
## Summary

The external identity provider callback at `GET /auth/external` accepts attacker-controlled redirect URIs that only need to start with a registered client redirect URI, rather than matching exactly. After a successful external IdP login, the server appends Medplum `login` and `code` valu…

CVE-2026-53728
NVD

HIGH
CVE-2026-62727
CVE-2026-62727
pkg: windows

published: Aug 19, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CWE: CWE-362
NVD

HIGH
CVE-2026-75857
CVE-2026-75857
pkg: python

published: Aug 18, 2026

CodeWhale versions >= 0.8.41 and < 0.8.64 contain a vulnerability in the exec_shell_interact (alias exec_interact) tool, whose approval_requirement returns ApprovalRequirement::Auto. This overrides the default Required approval for code-executing tools, so LLM-controlled stdin is written into an alr…
CWE: CWE-269
NVD

HIGH
CVE-2026-34789
CVE-2026-34789
pkg: python

published: Aug 17, 2026

FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, src/App/PropertyPythonObject.cpp in PropertyPythonObject::Restore() passes the attacker-controlled module attribute from serialized PropertyPythonObject XML directly to PyImport_ImportModule() while restoring a cr…
CWE: CWE-94
GitHub-GHSA

HIGH
kin-openapi has uncontrolled resource consumption in openapi3filter deepObject query parameter decoding
GHSA-xhj3-7xw9-vr34
pkg: github.com/getkin/kin-openapi
eco: go
published: Aug 21, 2026
### Summary

An uncontrolled resource consumption vulnerability in `openapi3filter` lets any unauthenticated client force multi-gigabyte heap allocation with a single, tiny HTTP request. When a spec declares a `deepObject`-style query parameter whose schema contains an array (a normal, documented pa…

CVE-2026-77354
GitHub-GHSA

HIGH
netty-incubator-codec-ohttp: BinaryHttpParser should enforce limits for variable lengths fields
GHSA-hmq9-67w8-j5pw
pkg: io.netty.incubator:netty-incubator-codec-bhttp
eco: maven
published: Aug 20, 2026
We don't enforce any limits for the encoded variable lengths that are used for fields. As the remote peer controls these it's easy for the remote peer to have us buffer data forever and so ultimately OOM.
CVE-2026-61827
GitHub-GHSA

HIGH
NocoBase: Arbitrary File Write chained with Local file Inclusion leads to Remote code execution
GHSA-ghvf-qf6h-g8x5
pkg: @nocobase/server
eco: npm
published: Aug 20, 2026
## Executive Summary

Two vulnerabilities were identified and chained to achieve authenticated remote code execution

The first vulnerability allows any authenticated admin to redirect the file upload storage root to an arbitrary path on disk including the application directory itself by supplying…

GitHub-GHSA

HIGH
netty-incubator-codec-ohttp: [OHttpServerCodec] Native Direct-Memory Leak on AEAD Decryption Failure Leads to Gateway Denial of Service
GHSA-vmr9-j6wf-pmh2
pkg: io.netty.incubator:netty-incubator-codec-ohttp
eco: maven
published: Aug 20, 2026
The **netty-incubator-codec-ohttp** library implements Oblivious HTTP (OHTTP) gateway and client functionality using Netty's `ByteBuf` memory management. When an OHTTP gateway processes encrypted client requests, it allocates a pooled direct (native off-heap) `ByteBuf` to hold the decrypted plaintex…
CVE-2026-54251
GitHub-GHSA

HIGH
Fleet: SQL injection in Okta conditional access endpoint allows host-controlled compromise of the Fleet database
GHSA-7q96-f8xw-jv5j
pkg: github.com/fleetdm/fleet
eco: go
published: Aug 20, 2026
### Summary

A SQL injection vulnerability in Fleet's Okta conditional access integration could allow an attacker who controls a single enrolled host to read or modify arbitrary data in the Fleet database, including stored session tokens. Disclosed session tokens may be replayed to act as a global a…

CVE-2026-54245
GitHub-GHSA

HIGH
logto-tunnel serves files outside –experience-path via path traversal
GHSA-rxjr-6c9q-h67x
pkg: @logto/tunnel
eco: npm
published: Aug 19, 2026
### Summary

`@logto/tunnel` serves custom sign-in experience files from the `–experience-path` directory. When the tunnel service is reachable, a requester can use `../` path segments in a static asset request to read files outside that directory that the CLI process can read.

### Details

The tu…

CVE-2026-63188
GitHub-GHSA

HIGH
GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)
GHSA-p77j-g7h5-r2vw
pkg: geolens
eco: pip
published: Aug 19, 2026
GeoLens 1.2.4 fixes a set of vulnerabilities, the most serious of which allow authenticated or anonymous users to obtain data and metadata for datasets they are not authorized to access.

### Impact

– **Private record metadata disclosure.** Record contact, keyword, and distribution sub-resource end…

GitHub-GHSA

HIGH
XWiki Platform Live Data Live Table Connector has privilege escalation from edit to script right through Live Data editing
GHSA-45ph-gxxr-gwgw
pkg: org.xwiki.platform:xwiki-platform-livedata-livetable, org.xwiki.platform:xwiki-platform-livedata-livetable, org.xwiki.platform:xwiki-platform-livedata-livetable
eco: maven
published: Aug 19, 2026
### Impact
Any user who can edit a page in XWiki can use Live Data's edit REST API in XWiki to change the rights on that page. This allows the user to obtain script right on the page. Script right allows the user to execute potentially dangerous Velocity scripts and send unfiltered HTML and JavaScri…
CVE-2026-53966
GitHub-GHSA

HIGH
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
GHSA-9gmc-jqmh-3rvm
pkg: copier
eco: pip
published: Aug 19, 2026
# Copier: trust-prefix bypass via path traversal runs tasks unprompted

### Summary

In copier `>= 9.5.0, <= 9.15.1`, the `trust` setting's prefix match
(`copier/_settings.py`) compares the template URL against a trusted prefix with
a raw `str.startswith` and **no path normalization**, while the URL…

CVE-2026-53951
GitHub-GHSA

HIGH
moby/go-archive: Crafted tar archive can write outside the extraction directory
GHSA-hfg8-hc9c-6c3h
pkg: github.com/moby/go-archive
eco: go
published: Aug 18, 2026
### Summary
The tar extraction routines in `moby/go-archive` (`Unpack`, `UnpackLayer`, `Untar`/`UntarUncompressed`, and the `ApplyLayer` helpers) do not confine filesystem operations to the destination directory. A crafted archive can create or overwrite files **outside** the intended destination.
CVE-2026-17106
GitHub-GHSA

HIGH
MONAI vulnerable to OS command injection
GHSA-rghg-q7wp-9767
pkg: MONAI
eco: pip
published: Aug 18, 2026
### Comment from JPCERT/CC
We are submitting the report again as we have yet to receive
any responses from you after submitting it on February 5 and March 11.

It would be greatly appreciated if you could send us a message
after confirming it so that we can follow up the case by email.

### Summary

GitHub-GHSA

HIGH
RabbitMQ Java client: Unvalidated Class.forName in JSON-RPC ProcedureDescription enables arbitrary class loading
GHSA-6g32-pxv4-2wfj
pkg: com.rabbitmq:amqp-client
eco: maven
published: Aug 18, 2026
The JSON-RPC tools in `com.rabbitmq.tools.jsonrpc` perform `Class.forName(javaReturnType)` with `initialize=true` on class names received from untrusted AMQP messages, without any validation or allowlist.

**Vulnerable code** (`ProcedureDescription.java:101-127`):
When a `JsonRpcClient` connects, it…

CVE-2026-63337
GitHub-GHSA

HIGH
RabbitMQ Java client ValueReader: Oversized LongString/bytes length triggers OOM via unchecked allocation
GHSA-68mj-5wr7-6fgg
pkg: com.rabbitmq:amqp-client
eco: maven
published: Aug 18, 2026
## Summary

`ValueReader.readBytes()` allocates a byte array sized by a wire-declared content length without validating it against actual frame data. A malicious AMQP peer triggers OOM by declaring a ~2GB string/bytes field.

## Vulnerable Code

`src/main/java/com/rabbitmq/client/impl/ValueReader.ja…

CVE-2026-69219
GitHub-GHSA

HIGH
RabbitMQ Java client ValueReader: Unbounded recursive table/array nesting causes StackOverflowError DoS
GHSA-93j5-89vc-pph4
pkg: com.rabbitmq:amqp-client
eco: maven
published: Aug 18, 2026
## Summary

`ValueReader.readTable()` and `readArray()` recursively call `readFieldValue()` with no depth limit. A malicious AMQP peer can crash the client JVM by sending a deeply nested table structure.

## Vulnerable Code

`src/main/java/com/rabbitmq/client/impl/ValueReader.java` lines 139-155 and…

CVE-2026-69220
GitHub-GHSA

HIGH
atomic-agents-stack: Parallel helper/delegate batch reserves $0 for models absent from the pricing table, bypassing the cost-cap fan-out guard
GHSA-j659-8xh6-5pq5
pkg: atomic-agents-stack
eco: pip
published: Aug 17, 2026
`_estimate_batch_cost` (`atomic_agents/agent.py`) looks up the per-model output price with `PRICING.get(model, {})`, returning 0.0 for any model not in the hardcoded pricing table. `_check_batch_reservation` then early-returns when the reservation is <= 0, skipping the batch reservation entirely. Th…
GitHub-GHSA

HIGH
atomic-agents-stack: HTTP MCP catalog accepts cleartext http and spawns catalog-supplied commands (MITM to RCE)
GHSA-xhcr-cqfr-m3hv
pkg: atomic-agents-stack
eco: pip
published: Aug 17, 2026
The HTTP MCP server-registry backend factory (`atomic_agents/mcp_registry/http.py`, `make_http_mcp_server_registry_backend_from_url`) accepts both `http` and `https` schemes. Catalog entries carry `command`/`args` that are type-validated but content-unrestricted, and are later spawned as local stdio…
GitHub-GHSA

HIGH
sqlparse: TokenList.__init__ materializes O(subtree) value per group, causing CPU DoS before depth/token caps trigger
GHSA-pwgv-4x5q-6m9f
pkg: sqlparse
eco: pip
published: Aug 17, 2026
### Summary

`sqlparse` ships hard limits (`MAX_GROUPING_DEPTH=100`, `MAX_GROUPING_TOKENS=10000`) intended to bound parsing work on attacker-supplied SQL, but the path that *reaches* those limits is itself `O(n*depth)` per token-group construction. A ~1-2 KB SQL payload (e.g. `SELECT (((((1))))) ……

CVE-2026-54284
GitHub-GHSA

HIGH
Etherpad has stored XSS in HTML export via unescaped attribute-pool values
GHSA-2jp7-wwpg-3p9w
pkg: ep_etherpad-lite
eco: npm
published: Aug 17, 2026
Fix: PR #7905 (ether/etherpad).

`getHTMLFromAtext` in `src/node/utils/ExportHtml.ts` interpolates values from the `exportHtmlAdditionalTagsWithData` plugin hook into `span data-<k>="<v>"` without HTML-attribute escaping. The value comes verbatim from the pad attribute pool, which a pad editor contr…

CVE-2026-55090
GitHub-GHSA

HIGH
vm2's bufferAllocLimit cap bypassed by Buffer.concat and Buffer.from arrayLike
GHSA-gmc2-2x9w-cgh9
pkg: vm2
eco: npm
published: Aug 17, 2026
## Summary

vm2 bufferAllocLimit cap bypassed by Buffer.concat and Buffer.from arrayLike

The `bufferAllocLimit` option introduced in 3.11.0 (GHSA-6785-pvv7-mvg7) caps host-side Buffer allocations driven by sandbox code, the way embedders opt into `timeout`. The cap wraps `Buffer.alloc`, `Buffer.all…

CVE-2026-47683
GitHub-GHSA

HIGH
sqlparse: Quadratic O(n²) DoS in group_comments
GHSA-f2ff-p2ww-7p4p
pkg: sqlparse
eco: pip
published: Aug 17, 2026
### Summary
A comment-only statement (`– c\n`*n) may cause a Denial of Service (DoS).

### Details
Location: [sqlparse/engine/grouping.py:331-341](https://github.com/andialbrecht/sqlparse/blob/f80af6a4007f11ada847218df8c29dc859238290/sqlparse/engine/grouping.py#L332) (`group_comments`), invoked fir…

CVE-2026-71491
GitHub-GHSA

HIGH
Glances: `–disable-config-exec` does not cover on-alert action commands (incomplete fix of CVE-2026-53925)
GHSA-59fj-m2j6-hcxh
pkg: glances
eco: pip
published: Aug 17, 2026
## Summary
In Glances 4.5.5 the `–disable-config-exec` flag was extended (GHSA-3vwc-qwhc-3mj7) to stop `secure_popen()` from
interpreting the shell operators `&&`, `|` and `>` in **AMP** command values taken from the configuration file. The
hardening was not applied to the **on-alert action** comma…
CVE-2026-68519
GitHub-GHSA

HIGH
Glances has a command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction
GHSA-qcpp-8×79-hhp3
pkg: glances
eco: pip
published: Aug 17, 2026
### Summary

The Glances action system lets an administrator configure shell commands that run
when a monitoring threshold is crossed. The command is a Mustache template whose
variables are filled with runtime stat fields such as a process name, a container
name or a filesystem mount point. Those fi…

CVE-2026-68518
GitHub-GHSA

HIGH
DeepmergeTS has stack exhaustion when merging recursive object graphs
GHSA-ggr8-5vv4-36mx
pkg: deepmerge-ts
eco: npm
published: Aug 17, 2026
### Summary

`deepmerge()` and `deepmergeInto()` can be crashed with a crafted recursive object graph. When both merged values contain self-references at the same property path, the library recurses until Node throws `RangeError: Maximum call stack size exceeded`.

### Details

Record merging is imp…

CVE-2026-40345
NVD

MEDIUM
CVE-2026-52873
CVE-2026-52873
pkg: windows

published: Aug 18, 2026

Streambert is a cross-platform Electron Desktop App to stream and download video content. From version 2.5.0 until version 2.6.0, the wyzie-open-redeem IPC handler in index.js creates the partition:wyzie-redeem Electron session and registers an onHeadersReceived hook that removes the Content-Securit…
CWE: CWE-79, CWE-693
GitHub-GHSA

MEDIUM
NocoBase backup restore schema name allows command injection
GHSA-p853-83gj-wjj3
pkg: @nocobase/plugin-backups
eco: npm
published: Aug 20, 2026
### Summary
NocoBase `@nocobase/plugin-backups` 2.0.57 restores PostgreSQL backups by interpolating the backup metadata schema name into shell command strings that are executed with Node.js `child_process.exec()`. A backup-management user who can restore an uploaded PostgreSQL backup with forced sch…
CVE-2026-55410
NVD

MEDIUM
CVE-2026-71477
CVE-2026-71477
pkg: node

published: Aug 18, 2026

mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.7.1, release tar archives record mise/bin/mise with user and group ID 1001 and packaging/standalone/install.envsubst extracts and moves it without normalizing ownership, allowing a local user with those IDs to replace a ro…
CWE: CWE-278
NVD

MEDIUM
CVE-2026-44845
CVE-2026-44845
pkg: express

published: Aug 17, 2026

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.10.17, an authenticated administrator with Applet Host management and deployment permissions can inject Jinja2 expressions into the IP/Host field or Core Service Address field, causing Ansibl…
CWE: CWE-1336
NVD

MEDIUM
CVE-2026-55586
CVE-2026-55586
pkg: windows

published: Aug 20, 2026

SumatraPDF is a multi-format reader for Windows. In 3.6.1 and earlier, a crafted CHM file can supply malformed LZX Huffman code lengths to make_decode_table in ext/CHMLib/lzx.c. In the long-code branch, the function writes new internal nodes through next_symbol before validating that the canonical H…
CWE: CWE-119, CWE-787
NVD

MEDIUM
CVE-2026-67448
CVE-2026-67448
pkg: go

published: Aug 20, 2026

Mailpit is an email testing tool and API for developers. From 1.29.0 until 1.30.6, Mailpit's server/server.go origin middleware checks the raw RequestURI for the /api/ prefix while Go's ServeMux routes using the percent-decoded URL path, and server/websockets/client.go configures websocket.Upgrader.…
CWE: CWE-177, CWE-200, CWE-346
GitHub-GHSA

MEDIUM
Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689)
GHSA-8r62-w5wh-fc5m
pkg: github.com/axllent/mailpit
eco: go
published: Aug 20, 2026
## Summary

The cross-site WebSocket hijacking fix was reimplemented as an origin check gated on a raw-URI prefix test, but Go's ServeMux routes on the percent-decoded path, so requesting /%61pi/events reaches the WebSocket handler while skipping the only origin control, and the upgrader itself acce…

CVE-2026-67448
NVD

MEDIUM
CVE-2026-77641
CVE-2026-77641
pkg: go

published: Aug 20, 2026

tor before 0.4.9.9 was prone to a NULL write after free when sending a CONFLUX_SWITCH cell fails. The return value of relay_send_command_from_edge() was ignored, so a send failure (which calls circuit_mark_for_close() and removes the leg via cfx_del_leg()) would go undetected, causing the caller…
CWE: CWE-252
NVD

MEDIUM
CVE-2026-53583
CVE-2026-53583
pkg: tls

published: Aug 20, 2026

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, verify_server_cert in src/libgit2/streams/openssl.c uses an inverted !!memcmp result in the GEN_IPADD b…
CWE: CWE-295, CWE-297
GitHub-GHSA

MEDIUM
Wagtail: Improper restriction handling on Page translation API endpoint
GHSA-jm5p-837g-rv8g
pkg: wagtail, wagtail, wagtail
eco: pip
published: Aug 20, 2026
### Impact
A CMS user with the "submit translations" permission, could use the Admin API's "copy for translation" endpoint to copy an existing page that they do not have edit access to, allowing them to view its contents.

### Patches
Patched versions have been released as Wagtail 7.0.9, 7.3.4, 7.4.…

GitHub-GHSA

MEDIUM
Wagtail: Improper permission handling when copying snippets
GHSA-x5cx-w6p2-mxf2
pkg: wagtail, wagtail, wagtail
eco: pip
published: Aug 20, 2026
### Impact
A CMS user with "add" permission over a snippet model, but not "change" or "view" permission, could copy an existing snippet that they do not have access to, allowing them to view its contents.

### Patches
Patched versions have been released as Wagtail 7.0.9, 7.3.4, 7.4.3 and 8.0rc2.

##…

GitHub-GHSA

MEDIUM
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
GHSA-6×92-6vx4-5fwr
pkg: django-cms
eco: pip
published: Aug 20, 2026
## Impact

The only authorization gate on the duplicate flow is `PageAdmin.has_add_permission`,
which checks `user_can_add_page(user, site)` / `user_can_add_subpage(…)` — i.e. *“may
this user create a page at all”*. Nothing checks the user’s relationship to the page being
copied:

– `cms/a…

CVE-2026-63003
GitHub-GHSA

MEDIUM
django CMS: Structure endpoint bypasses page-view permission
GHSA-vgxm-h9gx-h9w7
pkg: django-cms
eco: pip
published: Aug 20, 2026
### Summary
The structure-board endpoint (`render_object_structure`) renders a page's plugin structure without verifying that the requesting user is allowed to view the page. The edit and preview endpoints enforce this via `render_page()`, but the structure endpoint does not, allowing a low-privileg…
CVE-2026-54624
GitHub-GHSA

MEDIUM
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
GHSA-4xfr-4p46-gc6p
pkg: django-cms
eco: pip
published: Aug 20, 2026
### Summary
The clipboard copy paths of the `copy_plugins` admin endpoint validate only the target (the user's own clipboard) and skip source-side authorization. A staff user can copy plugins out of a placeholder they have no permission on into their clipboard, then read the (secret) content.
CVE-2026-54622
GitHub-GHSA

MEDIUM
Wagtail: Improper permission handling in image preview
GHSA-r6p4-grq7-xm4m
pkg: wagtail, wagtail, wagtail
eco: pip
published: Aug 20, 2026
### Impact
Due to a missing permission check on the image preview endpoint, a user with access to the Wagtail admin can preview any image. The existing data of the image object itself is not exposed. The vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin…
CVE-2026-54261
GitHub-GHSA

MEDIUM
Tekton Pipelines-as-Code: Unscoped GitHub App installation token allows unauthorized access to private repositories via remote task resolution
GHSA-6f2p-296r-cc28
pkg: github.com/openshift-pipelines/pipelines-as-code, github.com/openshift-pipelines/pipelines-as-code, github.com/openshift-pipelines/pipelines-as-code
eco: go
published: Aug 20, 2026
### Impact
When Pipelines-as-Code is configured with a GitHub App installed across multiple repositories, the installation token issued during webhook processing is not scoped to the triggering repository by default. The token retains access to all repositories in the GitHub App installation.

This …

CVE-2026-54168
NVD

MEDIUM
CVE-2026-63123
CVE-2026-63123
pkg: vite

published: Aug 19, 2026

Tina is a headless content management system. Prior to 2.5.2, the TinaCMS CLI package's Vite dev server packages/@tinacms/cli/src/next/vite/cors.ts origin callback returns false for a disallowed origin but does not reject the request, and packages/@tinacms/cli/src/next/vite/plugins.ts still routes P…
CWE: CWE-352
GitHub-GHSA

MEDIUM
Tina: Cross-origin `POST /media/upload/*` requests can write arbitrary files into the Tina dev server media root
GHSA-rgr9-r7mj-mf6x
pkg: @tinacms/cli
eco: npm
published: Aug 19, 2026
### Summary
A browser-based cross-origin request flaw in the Tina dev server allows an attacker-controlled website to cause arbitrary file creation inside the configured media upload directory on a developer machine running `tinacms dev`. No manual file upload is required. The attacker page builds t…
CVE-2026-63123
NVD

MEDIUM
CVE-2026-54738
CVE-2026-54738
pkg: docker

published: Aug 19, 2026

Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-beta.1, actix-web ConnectionInfo::realip_remote_addr reads the first value of X-Forwarded-For as the client address used by raw_ip_key in crates/utils/src/rate_limit/mod.rs. Lemmy's bundled docker/nginx.conf uses $pro…
CWE: CWE-799
NVD

MEDIUM
CVE-2026-68901
CVE-2026-68901
pkg: react

published: Aug 19, 2026

Wekan is open source kanban built with Meteor. Prior to 10.38, the /api/boards/:boardId/export, /api/boards/:boardId/attachments/:attachmentId/export, /api/boards/:boardId/export/csv, and /api/boards/:boardId/exportExcel handlers in models/export.js and models/exportExcel.js looked up a user from th…
CWE: CWE-476
GitHub-GHSA

MEDIUM
SearXNG MCP Server is Vulnerable to SSRF in web_url_read: the internal-address guard is disabled by default (MCP_HTTP_HARDEN off)
GHSA-q87f-qc2r-2gw4
pkg: mcp-searxng
eco: npm
published: Aug 19, 2026
Ref: https://github.com/ihor-sokoliuk/mcp-searxng/issues/87#issuecomment-4645453694

### Summary
The web_url_read tool fetches a caller-supplied URL server-side and converts it to markdown. An SSRF guard (assertUrlAllowed, which blocks private/loopback/metadata addresses) exists but runs only when …

CVE-2026-54688
NVD

MEDIUM
CVE-2026-50149
CVE-2026-50149
pkg: tls

published: Aug 19, 2026

Contour is a Kubernetes ingress controller using Envoy proxy. In versions 1.23.0 through 1.33.4, when an `HTTPProxy` is configured with incompatible combination of both `.spec.virtualhost.tls.enableFallbackCertificate: true` and `.spec.virtualhost.jwtProviders`, Contour does not reject the configura…
CWE: CWE-295
NVD

MEDIUM
CVE-2026-76039
CVE-2026-76039
pkg: google chrome, google android

published: Aug 18, 2026

Incorrect reference resolution in Core in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-706
NVD

MEDIUM
CVE-2026-62576
CVE-2026-62576
pkg: tls

published: Aug 18, 2026

Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromi…
NVD

MEDIUM
CVE-2026-12632
CVE-2026-12632
pkg: node

published: Aug 18, 2026

Zephyr's Precision Time Protocol receive handler ptp_msg_post_recv() in subsys/net/lib/ptp/msg.c takes the 4-bit message type straight off the wire via ptp_msg_type() (msg->header.type_major_sdo_id & 0xF, range 0-15) and uses it to index the msg_size[] table. That table only defines entries up to PT…
CWE: CWE-125
NVD

MEDIUM
CVE-2026-12631
CVE-2026-12631
pkg: express

published: Aug 18, 2026

The Zephyr kernel validates the k_thread_join() and k_thread_abort() system calls (declared __syscall in include/zephyr/kernel.h) through thread_obj_validate() in kernel/thread.c. Its default switch branch is the access-denied path, taken when k_object_validate() returns -EPERM (the calling user thr…
CWE: CWE-862
GitHub-GHSA

MEDIUM
Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent authority
GHSA-g7p5-89mh-248h
pkg: lemur
eco: pip
published: Aug 18, 2026
## Summary

Repo under test: https://github.com/Netflix/lemur

When `ADMIN_ONLY_AUTHORITY_CREATION=False` (an explicitly supported and documented configuration), `POST /api/1/authorities` with `type=subca` never verifies that the caller holds `AuthorityPermission` on the supplied `parent` authority.…

CVE-2026-71317
GitHub-GHSA

MEDIUM
devpi-server may leak database contents
GHSA-m5pq-69xg-vcq3
pkg: devpi-server
eco: pip
published: Aug 18, 2026
### Impact

If the replication protocol is enabled by using the “primary“ (or deprecated “master“) role for a server instance, then the “+changelog“ URL route can be used to read the complete database content including password hashes, and the ids and salts of tokens from “devpi-tokens“ by u…

CVE-2026-54723
NVD

MEDIUM
CVE-2026-71317
CVE-2026-71317
pkg: tls

published: Aug 18, 2026

Lemur manages TLS certificate creation. Prior to 1.9.3, POST /api/1/authorities with type=subca did not require AuthorityPermission on the parent authority when ADMIN_ONLY_AUTHORITY_CREATION was false. AssociatedAuthoritySchema resolved the caller-supplied parent and passed it through authority crea…
CWE: CWE-862
NVD

MEDIUM
CVE-2026-52733
CVE-2026-52733
pkg: node

published: Aug 18, 2026

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a natural or attacker-influenced chain fork can leave stale Sapling and Orchard note-commitment subtree roots in Zebra state. In zebra-state/src/service/non_finalized_state/chain.rs, Chain::pop_tip removed a reverted tip block but did n…
CWE: CWE-459, CWE-672
NVD

MEDIUM
CVE-2026-52731
CVE-2026-52731
pkg: node

published: Aug 18, 2026

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an attacker authenticated to an enabled Zebra RPC endpoint can terminate zebrad by supplying a getblocktemplate LongPollId containing multi-byte UTF-8 characters. In zebra-rpc/src/methods/types/long_poll.rs, LongPollId::from_str origina…
CWE: CWE-248
NVD

MEDIUM
CVE-2026-19671
CVE-2026-19671
pkg: docker

published: Aug 18, 2026

Malcolm's upload-processing pipeline (scripts/safe-extract.py) enforces entry-count, nesting-depth, and total-uncompressed-byte limits when extracting container archives (zip/tar/rar/7z via libarchive), but those limits are not applied when the uploaded file is a single-stream compressed format (.gz…
CWE: CWE-409
NVD

MEDIUM
CVE-2026-47606
CVE-2026-47606
pkg: linux

published: Aug 18, 2026

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal. A successful exploit might lead to code execution and information disclosure.
CWE: CWE-36
NVD

MEDIUM
CVE-2026-74044
CVE-2026-74044
pkg: node

published: Aug 18, 2026

Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows authenticated cluster peers to delete arbitrary directory contents by supplying a traversal-shaped node name in the cluster hello payload without validation. Attackers holding a valid cluster Fernet key can craft a malicio…
CWE: CWE-22
GitHub-GHSA

MEDIUM
MobSF's CSRF checks not enforced after Django migration
GHSA-3p54-567p-2wpr
pkg: mobsf
eco: pip
published: Aug 18, 2026
### Summary

Django's `CsrfViewMiddleware` exists only in the deprecated `MIDDLEWARE_CLASSES` (ignored since Django 2.0). The active `MIDDLEWARE` tuple does not include it. All authenticated web POST endpoints (delete scan, upload, download APK, change password, manage users) accept requests without…

CVE-2026-68923
NVD

MEDIUM
CVE-2026-66781
CVE-2026-66781
pkg: kubernetes

published: Aug 18, 2026

A flaw was found in the Submariner operator. The Submariner Custom Resource (CR), used for configuring network connectivity, stores the IPsec pre-shared key (PSK) in an unencrypted format. This key, which is critical for securing communication between Kubernetes clusters, can be accessed by unauthor…
CWE: CWE-312
GitHub-GHSA

MEDIUM
MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth
GHSA-3p64-6gvh-82v5
pkg: mlflow
eco: npm
published: Aug 17, 2026
### Summary

When MLflow is deployed with the built-in basic-auth plugin (`–app-name basic-auth`), any authenticated user can inject arbitrary dataset records into another user's run by calling `POST /api/2.0/mlflow/runs/log-inputs`. The `LogInputs` proto handler is absent from the `BEFORE_REQUEST_…

CVE-2026-69146
GitHub-GHSA

MEDIUM
http4k: `DigestAuthProvider.verify` ignored configured algorithm and did not bind to request URI
GHSA-vxxm-wwqh-mh47
pkg: org.http4k:http4k-security-digest, org.http4k:http4k-security-digest, org.http4k:http4k-security-digest
eco: maven
published: Aug 17, 2026
### Impact

An issue in `DigestAuthProvider.verify`:

**Algorithm silently forced to MD5.** The configured `algorithm` parameter was ignored — every verification used MD5 regardless of configuration. Deployments believing they were running SHA-256 Digest auth were silently inheriting MD5's collis…

CVE-2026-54147
NVD

MEDIUM
CVE-2026-63669
CVE-2026-63669
pkg: node

published: Aug 17, 2026

ApostropheCMS is an open-source Node.js content management system. Prior to 4.32.0, the page module's move() operation fails to enforce the destination parent's _create permission because its oldParent archive condition disables the check for ordinary moves, allowing an authenticated editor or contr…
CWE: CWE-639, CWE-862
NVD

MEDIUM
CVE-2026-63667
CVE-2026-63667
pkg: node

published: Aug 17, 2026

ApostropheCMS is an open-source Node.js content management system. Prior to 3.6.2, the import-export module in packages/import-export/lib/formats/gzip.js constructs an attachment source path from the attacker-controlled _id, name, and extension fields in aposAttachments.json without ensuring that th…
CWE: CWE-22
GitHub-GHSA

MEDIUM
Netty Vulnerable to Cache Poisoning and Information Disclosure via CORS Vary Header Overwrite
GHSA-8c42-7qj2-3j46
pkg: io.netty:netty-codec-http, io.netty:netty-codec-http
eco: maven
published: Aug 17, 2026
### Summary
Netty's `CorsHandler` silently overwrites existing `Vary` headers, enabling cache poisoning and sensitive information disclosure.

### Details
`io.netty.handler.codec.http.cors.CorsHandler#setVaryHeader` overwrites any existing Vary headers set by backend applications.

“`java
priv…

CVE-2026-59903
GitHub-GHSA

MEDIUM
Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing the Wildcard
GHSA-fp27-88fp-2phg
pkg: glances
eco: pip
published: Aug 17, 2026
### Summary
Glances's REST API server includes a documented safety check intended to guarantee that `cors_credentials=True` can never be combined with an unrestricted CORS origin allowlist. The check compares the configured origin list to the wildcard using exact list equality (`cors_origins == ["*"…
CVE-2026-68517
NVD

MEDIUM
CVE-2026-74881
CVE-2026-74881
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 configure CORS with allow_origins set to wildcard and allow_credentials enabled to true. Attackers can create malicious websites that make authenticated cross-origin requests to the API on behalf of any user who visits them.
CWE: CWE-942
NVD

MEDIUM
CVE-2026-44517
CVE-2026-44517
pkg: docker

published: Aug 21, 2026

Buildah is a tool that facilitates building OCI images. From 1.38.1 until 1.43.2 and 1.44.0, TempDirForURL in define/types.go does not securely confine Git repository subdirectories to the downloaded build context, and downloadToDirectory and stdinToDirectory can follow a Dockerfile symlink left by …
CWE: CWE-22
GitHub-GHSA

MEDIUM
stigmem-node has blind SSRF via unvalidated webhook subscription delivery_address
GHSA-5p3m-vhh6-9236
pkg: stigmem-node
eco: pip
published: Aug 20, 2026
### Summary

Stigmem allows an authenticated user to create a webhook subscription with a user-controlled `delivery_address`. That value is stored and later used directly by the subscription delivery worker as the destination of a server-side HTTP POST request.

The codebase already contains an outb…

NVD

MEDIUM
CVE-2026-72844
CVE-2026-72844
pkg: express

published: Aug 20, 2026

The Lean 4 kernel does not verify that the structure named in a projection expression matches the type of the value being projected, and environment::add_inductive in src/kernel/inductive.cpp did not type check the nested inductive applications that are replaced by auxiliary types, so their parametr…
CWE: CWE-843
GitHub-GHSA

MEDIUM
SearXNG MCP Server: Additional hardened-mode SSRF bypasses
GHSA-wppf-h75h-6pm6
pkg: mcp-searxng
eco: npm
published: Aug 19, 2026
## Summary

`mcp-searxng` has a hardened-mode URL-reading feature intended to prevent `web_url_read` from reaching private or internal network resources.

PR #79 appears to address one SSRF class: hostnames that resolve to private or internal addresses under hardened mode. I tested PR #79 locally an…

CVE-2026-54689
GitHub-GHSA

MEDIUM
Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete fix for GHSA-54vg-pfh7-jq95)
GHSA-f3qq-49m6-rw8f
pkg: lemur
eco: pip
published: Aug 18, 2026
## Summary
The SSRF mitigation added for GHSA-54vg-pfh7-jq95 (`_validate_revocation_url()` in `lemur
/certificates/verify.py`) can be bypassed. An operator-role user who uploads a certificate with attacker-controlled CRL/OCSP extensions can still make Lemur reach internal destinations (RFC1918, loop…
CVE-2026-70667
NVD

MEDIUM
CVE-2026-70667
CVE-2026-70667
pkg: tls

published: Aug 18, 2026

Lemur manages TLS certificate creation. Prior to 1.9.3, _validate_revocation_url in lemur/certificates/verify.py checked the original CRL or OCSP URL but the later request could reach a different destination. The CRL requests.get call followed HTTP redirects without validating each Location target, …
CWE: CWE-367, CWE-918
NVD

MEDIUM
CVE-2026-55163
CVE-2026-55163
pkg: tls

published: Aug 18, 2026

Lemur manages TLS certificate creation. Prior to 1.9.2, PUT /api/1/roles/ in lemur/roles/views.py:298 authorized updates with RoleMemberPermission(role_id), which allowed either an administrator or any existing member of the target role. The handler passed data["users"] and data["name"] to service.u…
CWE: CWE-863
NVD

MEDIUM
CVE-2026-55162
CVE-2026-55162
pkg: tls

published: Aug 18, 2026

Lemur manages TLS certificate creation. Prior to 1.9.2, lemur/certificates/verify.py accepted CRL Distribution Point and OCSP responder URLs from uploaded certificate extensions and used them in crl_verify and ocsp_verify without adequate destination validation. An authenticated operator could submi…
CWE: CWE-918
NVD

MEDIUM
CVE-2026-74871
CVE-2026-74871
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.6 contain a key derivation flaw in sequential XOR composition mode where the last stage cancels out during key generation. When configured with a single KDF and no prior hashing stage, attackers can bypass memory-hard key derivation and perform offline password cr…
CWE: CWE-916
NVD

MEDIUM
CVE-2026-54770
CVE-2026-54770
pkg: oauth

published: Aug 20, 2026

WebOb provides objects for HTTP requests and responses. Prior to 1.8.11, Response._make_location_absolute() in src/webob/response.py checks a Location value for a URI scheme or leading double slash before urllib.parse.urljoin() strips leading C0 control characters and spaces. An attacker-controlled …
CWE: CWE-601
NVD

MEDIUM
CVE-2026-16732
CVE-2026-16732
pkg: node

published: Aug 18, 2026

fastify is a fast and low overhead web framework for Node.js. Impact: the fix for CVE-2026-3635 added a guard on the forwarded-header reads used to derive the request host, protocol, hostname, ip, and ips values, checking the connecting address. That guard closes the IP, CIDR, and custom-function fo…
CWE: CWE-348
GitHub-GHSA

MEDIUM
chrome-devtools-mcp: validatePath() does not canonicalize symlinks before enforcing roots
GHSA-8qf9-62×2-82pp
pkg: chrome-devtools-mcp
eco: npm
published: Aug 17, 2026
### Summary

I originally reported this through Google Bug Hunters. The Google Bug Hunters team said this is in OSS VRP scope but not reward-eligible due to the project tier, and asked me to file an issue or PR directly with this repository. I am reporting it privately here first because it is an un…

CVE-2026-53766
NVD

MEDIUM
CVE-2026-63670
CVE-2026-63670
pkg: node

published: Aug 17, 2026

ApostropheCMS is an open-source Node.js content management system. Prior to 2.17.6, sanitizeHtml() can pass disallowed executable markup through packages/sanitize-html/index.js when textarea or xmp is included in allowedTags because a literal solidus after the raw-text end-tag name is treated as tex…
CWE: CWE-79
NVD

MEDIUM
CVE-2026-53572
CVE-2026-53572
pkg: ssl

published: Aug 21, 2026

KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to 2.20.0, pkg/scalers/postgresql_scaler.go constructs libpq-style connection strings from tenant-controlled host, port, userName, dbName, sslmode, and password values, while escapePostgreConnectionParameter() only quotes values co…
CWE: CWE-74, CWE-89
NVD

MEDIUM
CVE-2026-55558
CVE-2026-55558
pkg: tls

published: Aug 20, 2026

aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.2, SMTPProtocol.start_tls in src/aiosmtplib/protocol.py consumes the server's 220 response and starts the TLS handshake without clearing SMTPProtocol._buffer. An active network attacker can place attacker-chosen SMTP respon…
CWE: CWE-74
NVD

MEDIUM
CVE-2026-76401
CVE-2026-76401
pkg: express

published: Aug 19, 2026

In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API could configure timestamp extraction with a crafted regular expression and matching event data to block a Kafka Connect worker thread, stopping event d…
CWE: CWE-407
GitHub-GHSA

MEDIUM
langgraph-api: Incomplete assistant authorization in LangGraph Server run creation
GHSA-jfj5-wrj9-63×4
pkg: langgraph-api
eco: pip
published: Aug 19, 2026
## Summary

In affected versions of `langgraph-api` (the LangGraph Server runtime), the run-creation path authorized the assistant attached to a run using a different authorization event than the rest of the assistant-handling code paths. Direct assistant reads and cron creation dispatch the `assist…

CVE-2026-55236
GitHub-GHSA

MEDIUM
langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication
GHSA-2c9q-c2q9-qgqv
pkg: langgraph-api
eco: pip
published: Aug 19, 2026
## Summary

In affected versions of `langgraph-api` (the LangGraph Server runtime), a run or cron could be created with a relative webhook target. When the server later delivers such a webhook, it routes the request back into the same application through an in-process loopback transport that the aut…

CVE-2026-55235
NVD

MEDIUM
CVE-2026-52739
CVE-2026-52739
pkg: node

published: Aug 18, 2026

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a malicious block producer can terminate zebrad by placing the same shielded transaction in a non-finalized parent block and its child. In zebra-state/src/service/non_finalized_state/chain.rs, Chain::push originally inserted the transac…
CWE: CWE-248
NVD

MEDIUM
CVE-2026-50139
CVE-2026-50139
pkg: go

published: Aug 18, 2026

goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, `ShareHandler` reads the share token's `DownloadLimit` under `RLock`, releases the lock, serves the file, then re-acquires the lock to increment the counter. Concurrent requests all read the same `Downloaded`/`DownloadLimit` snapshot…
CWE: CWE-362
NVD

MEDIUM
CVE-2026-75145
CVE-2026-75145
pkg: windows

published: Aug 19, 2026

FFmpeg before commit b4c199c contains an incorrect integer narrowing conversion in the AV1 RTP packetizer (libavformat/rtpenc_av1.c). The OBU size is cast to long before comparison against the remaining frame size. On targets where long is 32 bits, including 64-bit Windows, sufficiently large OBU si…
CWE: CWE-681
NVD

MEDIUM
CVE-2026-45271
CVE-2026-45271
pkg: tls

published: Aug 21, 2026

Picotls is a TLS protocol library that allows users select different crypto backends based on their use case. Picotls implements its own ASN.1 validation helper, which is used by the minicrypto backend while parsing local PKCS#8 private keys. Prior to commit c14231d801407640bc42c2dcf92783409ea6a7c7,…
CWE: CWE-835
GitHub-GHSA

MEDIUM
Unleash: Addon webhook URL is dialed server-side with no internal-address filtering, enabling SSRF to internal services / cloud metadata and exfiltration of configured request headers
GHSA-5vf6-jrqr-78fj
pkg: unleash-server, unleash-server, unleash-server
eco: npm
published: Aug 21, 2026
## Summary

Unleash's addon/integration subsystem lets an operator configure a webhook (and the Slack, Microsoft Teams, Datadog, and New Relic integrations) with a target `url` parameter. Whenever a subscribed feature-flag event fires, the Unleash server itself issues an HTTP request to that configu…

CVE-2026-63004
NVD

MEDIUM
CVE-2026-55015
CVE-2026-55015
pkg: windows

published: Aug 20, 2026

Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny service locally.
CWE: CWE-427
GitHub-GHSA

MEDIUM
asteval Sandbox Escape: arbitrary native memory read/write via numpy ctypes in default asteval Interpreter
GHSA-9w56-46f6-3qhx
pkg: asteval
eco: pip
published: Aug 20, 2026
### Summary
With its default configuration (numpy enabled, `import` disabled), asteval's `Interpreter` lets an attacker-controlled expression obtain a raw **arbitrary process-memory read and write** primitive, without using `import`, any `__dunder__` attribute, or `eval`/`exec`/`getattr`. Arbitrary …
NVD

MEDIUM
CVE-2026-14978
CVE-2026-14978
pkg: go

published: Aug 19, 2026

HashiCorp go-slug 0.4.0 through 0.18.2 could allow a local attacker to bypass .terraformignore exclusions and cause sensitive files to be included in Terraform slug uploads due to improper handling of Unicode normalization during path matching.
CWE: CWE-176
GitHub-GHSA

MEDIUM
SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses
GHSA-hjwh-xvfw-qrwj
pkg: mcp-searxng
eco: npm
published: Aug 19, 2026
### Summary

mcp-searxng version 1.11.0 exposes SearXNG Basic Authentication credentials embedded in the `SEARXNG_URL` environment variable.

When the server starts in STDIO mode and an MCP client connects, the complete `SEARXNG_URL`, including its username and password, is sent to the client throug…

NVD

MEDIUM
CVE-2026-76227
CVE-2026-76227
pkg: docker

published: Aug 19, 2026

Renovate versions from 42.68.1 before 42.96.3 (and from 42.68.1 before 43.4.4), including corresponding Docker images (renovate/renovate, mend/renovate-ce, renovate-ee-server, renovate-ee-worker >=13.3.0 <13.6.0), fail to restrict environment variables to an allowlist when spawning child processes. …
CWE: CWE-526
NVD

MEDIUM
CVE-2026-73974
CVE-2026-73974
pkg: linux

published: Aug 18, 2026

linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses its shared testing helper across check plugins. Prior to linuxfabrik-lib 6.1.0 and Linuxfabrik Monitoring Plugins 7.0.0, lib.lftest.test() treated the …
CWE: CWE-22, CWE-269
NVD

MEDIUM
CVE-2026-73973
CVE-2026-73973
pkg: linux

published: Aug 18, 2026

Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems. Prior to version 7.0.0, check-plugins/logfile/logfile accepted a free-form –filename path and opened it as root when invoked through the shipped nagios or icinga sudoers allowlist, without confining …
CWE: CWE-22, CWE-269
GitHub-GHSA

MEDIUM
linuxfabrik-lib: Arbitrary root file read via live –test argument (lib.lftest) across sudoers-whitelisted plugins (LPE)
GHSA-rh9c-rqvg-f7pr
pkg: linuxfabrik-lib
eco: pip
published: Aug 18, 2026
## Summary
Every Linuxfabrik check plugin that supports the shared `–test` argument (routed through `lib.lftest.test()`) will, when `–test` is supplied, treat the first CSV element as a filesystem path and read its full contents as the plugin's simulated STDOUT — running as root when the plugin …
CVE-2026-73974
NVD

MEDIUM
CVE-2026-47630
CVE-2026-47630
pkg: linux

published: Aug 18, 2026

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal. A successful exploit might lead to code execution.
CWE: CWE-36
GitHub-GHSA

MEDIUM
MobSF Vulnerable to Arbitrary File Read via Path Traversal in ZIP Uploads
GHSA-8j49-mmcx-4mp5
pkg: mobsf
eco: pip
published: Aug 18, 2026
### Summary
The `find_icon_path_zip()` function in MobSF does not properly sanitize the `android:icon` attribute extracted from an Android manifest before resolving it as a filesystem path.

An attacker can supply a malicious `android:icon` value containing path traversal sequences, causing MobSF to…

CVE-2026-68922
NVD

MEDIUM
CVE-2026-75485
CVE-2026-75485
pkg: kubernetes

published: Aug 18, 2026

A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. The cluster Proxy object is dumped in raw form, bypassing the oc inspect redaction that would normally sanitize sensitive fields. This exposes proxy basic-auth credentials in the must-gather archive,…
CWE: CWE-532
NVD

MEDIUM
CVE-2026-73834
CVE-2026-73834
pkg: kubernetes

published: Aug 18, 2026

A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. Certain ACM wrapper Custom Resources that embed Secret data are collected without redaction. When an administrator runs must-gather, credentials and tokens are captured in cleartext in the resulting …
CWE: CWE-312
NVD

MEDIUM
CVE-2026-74890
CVE-2026-74890
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in CamelliaCipher that disables HMAC tag generation and verification when the PYTEST_CURRENT_TEST environment variable is set. Attackers with code execution can set this environment variable to produce unauthenticat…
CWE: CWE-345
NVD

MEDIUM
CVE-2026-74873
CVE-2026-74873
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 expose passwords passed via the –password CLI argument in process listings accessible to all system users. Attackers can read process arguments through ps aux or /proc/[pid]/cmdline to retrieve plaintext passwords and keystore passwords.
CWE: CWE-214
GitHub-GHSA

MEDIUM
Tina: Broken Access Control: arbitrary bucket-key write/delete in `next-tinacms-s3` (and sibling production media adapters)
GHSA-8mq9-5fw2-5rm4
pkg: next-tinacms-s3, next-tinacms-dos, next-tinacms-azure
eco: npm
published: Aug 19, 2026
## Summary

The production media handler shipped by `next-tinacms-s3` (`createMediaHandler` in `packages/next-tinacms-s3/src/handlers.ts`) accepts an attacker-chosen `?key=` query parameter and returns an AWS-signed `PutObject` URL whose `Key` is that value, with no check that the key falls under th…

CVE-2026-59992
NVD

MEDIUM
CVE-2026-18504
CVE-2026-18504
pkg: node

published: Aug 18, 2026

fastify is a fast and low overhead web framework for Node.js. Versions of fastify before 5.12.1 are affected by a schema validation bypass when a request body schema targets a root primitive value. When the schema validates a top-level primitive such as an integer, Ajv can coerce a JSON string into …
CWE: CWE-20
NVD

MEDIUM
CVE-2026-19670
CVE-2026-19670
pkg: nginx

published: Aug 18, 2026

Malcolm's nginx Lua role-based access control (RBAC) layer decides whether an authenticated user may reach a role-restricted path (e.g. /htadmin, /auth, /admin_login, /arkime/api/esadmin, NetBox, upload endpoints) by pattern-matching the raw, percent-encoded request URI. Nginx itself, however, selec…
CWE: CWE-863
GitHub-GHSA

MEDIUM
Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement
GHSA-r553-m4fv-5v97
pkg: github.com/axllent/mailpit
eco: go
published: Aug 20, 2026
## Summary

Mailpit's SMTP DATA reader enforces the configured `MaxMessageSize` only after `bufio.Reader.ReadBytes('\n')` has already buffered a complete DATA line. A remote unauthenticated SMTP client can send one line larger than the configured message-size cap and force memory allocation before M…

CVE-2026-67447
GitHub-GHSA

MEDIUM
Wagtail: Improper restriction handling on descendant collections in Documents and Images API
GHSA-c2xx-cjmh-9q8f
pkg: wagtail, wagtail, wagtail
eco: pip
published: Aug 20, 2026
### Impact

The Documents and Images [API V2](https://docs.wagtail.org/en/stable/advanced_topics/api/index.html) incorrectly listed items in descendants of private collections, which should inherit the view restrictions defined on their ancestors. A user with access to the API could see the filename…

GitHub-GHSA

MEDIUM
Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs
GHSA-q9c5-pp7m-fm2g
pkg: github.com/fleetdm/fleet/v4
eco: go
published: Aug 20, 2026
### Summary

Two endpoints serving in-house iOS application packages and manifests in Fleet's enterprise tier are reachable without a hard-to-guess token in the URL, allowing an unauthenticated attacker who can reach the Fleet server to download an in-house IPA by guessing sequential title identifie…

GitHub-GHSA

MEDIUM
netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash
GHSA-pgrf-4654-3gq8
pkg: io.netty.incubator:netty-incubator-codec-bhttp
eco: maven
published: Aug 20, 2026
## Summary

`io.netty.incubator:netty-incubator-codec-bhttp` uses attacker-controlled Binary HTTP variable-length integers as `long` values but accumulates them into `int` offsets. Large valid varint lengths wrap the internal offset negative, leading to unchecked `ArrayIndexOutOfBoundsException` / `…

CVE-2026-61799
NVD

MEDIUM
CVE-2026-68552
CVE-2026-68552
pkg: tls

published: Aug 19, 2026

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, an unauthenticated remote client can send a STUN message over TCP or TLS with a body-length field from 65520 through 65532, causing the uint16_t len variable in stun_get_message_len_str() in src/client/ns_turn_msg.…
CWE: CWE-190
NVD

MEDIUM
CVE-2026-49392
CVE-2026-49392
pkg: express

published: Aug 19, 2026

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.6.0 until 4.14.6 and 5.0.0-beta3, DB::getFile() and DB::searchFile() in src/syscheckd/src/db/src/file.cpp concatenate a monitored file path into SQLite row filters. On non-Windows systems, FIMDBCreat…
CWE: CWE-20, CWE-89
NVD

MEDIUM
CVE-2026-48796
CVE-2026-48796
pkg: windows

published: Aug 18, 2026

CefSharp provides .NET bindings for the Chromium Embedded Framework for Windows Forms and Windows Presentation Foundation applications. Prior to version 148.0.90, CefSharp/SchemeHandler/FolderSchemeHandlerFactory.cs used filePath.StartsWith(rootFolder, StringComparison.OrdinalIgnoreCase) to decide w…
CWE: CWE-22
NVD

MEDIUM
CVE-2026-70907
CVE-2026-70907
pkg: tls

published: Aug 18, 2026

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and 21.0.12; Oracle…
CWE: CWE-284
NVD

MEDIUM
CVE-2026-52737
CVE-2026-52737
pkg: node

published: Aug 18, 2026

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a malicious unauthenticated P2P peer can answer Zebra's outbound getblocks or FindBlocks request with a small two-hash inventory and then serve a syntactically valid block whose coinbase height is far above the local chain tip. In zebra…
CWE: CWE-345
NVD

MEDIUM
CVE-2026-52734
CVE-2026-52734
pkg: node

published: Aug 18, 2026

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an unauthenticated P2P peer can cause the mempool download pipeline to retain transactions after verification reaches the outer RATE_LIMIT_DELAY timeout. In zebrad/src/components/mempool/downloads.rs, Downloads::poll_next removed cancel…
CWE: CWE-401
NVD

MEDIUM
CVE-2026-52732
CVE-2026-52732
pkg: node

published: Aug 18, 2026

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, one unauthenticated P2P peer can monopolize all 25 MAX_INBOUND_CONCURRENCY slots in Zebra's inbound mempool download and verification pipeline. In zebrad/src/components/mempool/downloads.rs, the bounded queue was shared globally without…
CWE: CWE-770
NVD

MEDIUM
CVE-2026-65959
CVE-2026-65959
pkg: vite

published: Aug 18, 2026

Vitess is a database clustering system for horizontal scaling of MySQL. In 24.0.2 and earlier, the /debug/vrlog endpoint registered by addHttpEndpoint() in go/vt/vttablet/tabletmanager/vreplication/vrlog.go invokes vrlogStatsHandler() without acl.CheckAccessHTTP(r, acl.DEBUGGING), unlike comparable …
CWE: CWE-862
NVD

MEDIUM
CVE-2026-73502
CVE-2026-73502
pkg: go

published: Aug 18, 2026

kin-openapi is a Go project for handling OpenAPI files. From 0.2.0 until 0.144.0, openapi3filter.ValidateRequest can encounter a NULL-pointer-dereference denial of service when an operation declares a content parameter whose application/json media type has no schema. In openapi3filter/req_resp_decod…
CWE: CWE-476
NVD

MEDIUM
CVE-2026-46482
CVE-2026-46482
pkg: go

published: Aug 18, 2026

### Impact
The registration component does not validate the text-based _Security Question_ CAPTCHA correctly, allowing attackers to bypass the challenge via a specially crafted value.

[CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N](https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/U…

CWE: CWE-636
GitHub-GHSA

MEDIUM
Glances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/config
GHSA-4h34-v6r8-mmjc
pkg: glances
eco: pip
published: Aug 17, 2026
## Summary

Glances provides `as_dict_secure()` explicitly designed for unauthenticated API access, with a docstring stating it returns "a sanitised copy of the configuration dict" where "Sensitive keys in remaining sections are replaced by '********'". However, the implementation only checks KEY na…

CVE-2026-68520
GitHub-GHSA

MEDIUM
asteval has a Sandbox Escape via BaseException Subclasses
GHSA-89v8-rhwq-hf77
pkg: asteval
eco: pip
published: Aug 20, 2026
## Summary

An attacker who can supply expressions to `asteval.Interpreter.eval()` can raise `SystemExit`,
`KeyboardInterrupt`, `GeneratorExit`, or `BaseException` from inside the sandbox. These
exceptions are subclasses of `BaseException` but not `Exception`, so they bypass the
`except Exception:` …

CVE-2026-55244
NVD

MEDIUM
CVE-2026-77067
CVE-2026-77067
pkg: axios

published: Aug 20, 2026

The setWebhookResolver in packages/api/src/resolvers/webhooks/index.ts stores the caller-supplied url without any address validation, and the file imports no validation helper. When a subscribed event fires, callWebhook in packages/api/src/jobs/call_webhook.ts issues axios.request with that url, the…
CWE: CWE-918
NVD

MEDIUM
CVE-2026-77066
CVE-2026-77066
pkg: axios

published: Aug 20, 2026

The scanFeedsResolver in packages/api/src/resolvers/subscriptions/index.ts passes the caller-supplied url straight to axios.get(url, rssParserConfig()) with no address validation. The same file guards the subscribe path with validateUrl(), which rejects private and reserved ranges through the privat…
CWE: CWE-918
NVD

MEDIUM
CVE-2026-70656
CVE-2026-70656
pkg: express

published: Aug 21, 2026

Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. From 3.5.1 until 3.9.2, an authenticated admin or superadmin can set matchMethod to regex and place a malicious expression in…
CWE: CWE-1333
NVD

MEDIUM
CVE-2026-55164
CVE-2026-55164
pkg: tls

published: Aug 18, 2026

Lemur manages TLS certificate creation. Prior to 1.9.2, lemur.users.service.update assigned a replacement password directly to users.password, while lemur/users/models.py registered User.hash_password only for the before_insert event. Because no before_update listener ran, administrator-initiated pa…
CWE: CWE-256
NVD

MEDIUM
CVE-2026-74046
CVE-2026-74046
pkg: node

published: Aug 18, 2026

Wazuh 4.4.0 before 4.14.7 contains a denial of service vulnerability in the fdecompress_files() function within cluster.py that allows authenticated cluster peers to exhaust memory by supplying a malicious synchronization archive without decompressed size limits. Attackers holding a valid cluster Fe…
CWE: CWE-409
GitHub-GHSA

MEDIUM
MobSF Vulnerable to Zip Bomb Denial of Service via Per-File Size Limit Bypass in ZIP/APK Extraction
GHSA-x768-8642-mmq9
pkg: mobsf
eco: pip
published: Aug 18, 2026
### Summary

When extracting uploaded ZIP/APK files, MobSF checks if individual files exceed `ZIP_MAX_UNCOMPRESSED_FILE_SIZE` (400 MB) and logs "Skipping" — but the code lacks a `continue` statement, so extraction proceeds anyway. The log message is misleading; the file is still written to disk.

CVE-2026-68924
NVD

MEDIUM
CVE-2026-55165
CVE-2026-55165
pkg: tls

published: Aug 18, 2026

Lemur manages TLS certificate creation. Prior to 1.9.2, the JWT verifier in lemur/auth/service.py:130-137 used fetch_token_header to read header_data["alg"] from an unverified token and passed that attacker-controlled value to decode_with_multiple_secrets. PyJWT 2.x rejects alg=none with the configu…
CWE: CWE-347
GitHub-GHSA

MEDIUM
Ember has unneutralized terminal escape/control sequences from Caddy logs injected into the operator's TUI
GHSA-x3g7-qrwc-f6c5
pkg: github.com/alexandre-daubois/ember
eco: go
published: Aug 20, 2026
## Summary

Ember's interactive TUI renders fields taken from the monitored Caddy server's access logs — most notably the request URI — straight to the operator's terminal without neutralising terminal escape or control sequences (CWE-150). Those log fields are populated from arbitrary, unauthen…

CVE-2026-54162
GitHub-GHSA

MEDIUM
django CMS: Stored XSS in edit-mode plugin exception rendering
GHSA-hvq6-2r72-p2x7
pkg: django-cms
eco: pip
published: Aug 20, 2026
## Summary

When plugin rendering fails in edit mode, django CMS renders a `cms-rendering-exception` block so editors can see that a placeholder could not be rendered. Older code built that block's heading by interpolating the exception message, placeholder/source strings, and the failing plugin's s…

CVE-2026-75526
NVD

MEDIUM
CVE-2026-53487
CVE-2026-53487
pkg: kubernetes

published: Aug 21, 2026

Kite is a Kubernetes dashboard. Prior to version 0.12.3, authenticated Kite users with any role can request `/api/v1/overview` for a cluster that their roles do not permit by selecting that cluster with `x-cluster-name`. The overview route is registered before `middleware.RBACMiddleware()` and `GetO…
CWE: CWE-862
GitHub-GHSA

MEDIUM
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
GHSA-8qj2-c6q4-f399
pkg: django-cms
eco: pip
published: Aug 20, 2026
## Summary

The django-cms frontend-editing structure endpoint

“`
GET /<lang>/admin/cms/placeholder/object/<content_type_id>/structure/<object_id>/
“`

did not perform an object-level authorization check for **non-`PageContent`** objects. Any authenticated, active staff user could request the str…

CVE-2026-61663
GitHub-GHSA

MEDIUM
Wagtail: Improper restriction handling on Pages admin API
GHSA-3vrh-m9w7-v94f
pkg: wagtail, wagtail, wagtail
eco: pip
published: Aug 20, 2026
### Impact

The internal Pages admin [API](https://docs.wagtail.org/en/stable/advanced_topics/api/index.html) incorrectly returns page fields without access control when they are declared in `api_fields`. A user with access to the Wagtail admin can use this API to fetch draft and live page fields��…

CVE-2026-55468
GitHub-GHSA

MEDIUM
Wagtail: Pages translations can be created without page permissions when using simple_translation
GHSA-8634-mr4j-r72c
pkg: wagtail, wagtail, wagtail
eco: pip
published: Aug 20, 2026
### Impact
A low-level user with the "Can submit translation" permission can create translations for any page, including those they do not have permissions for.

### Patches
Patched versions have been released as Wagtail 7.0.8, 7.3.3, 7.4.2.

### Workarounds
N/A

### Acknowledgements

Many thanks to…

CVE-2026-54262
GitHub-GHSA

MEDIUM
Wagtail: Denial of service via unbounded filter specs in the image preview
GHSA-f2p5-j6fg-5cxf
pkg: wagtail, wagtail, wagtail
eco: pip
published: Aug 20, 2026
### Impact

An authenticated admin user can trigger expensive rendition processing with purposefully crafted filter specs resulting in potentially service degradation.

The vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin.

### Patches
Patched versions…

CVE-2026-54260
GitHub-GHSA

MEDIUM
Wagtail: Improper restriction handling on Documents and Images chosen endpoints
GHSA-h54r-xq46-qwqm
pkg: wagtail, wagtail, wagtail
eco: pip
published: Aug 20, 2026
### Impact
The Documents and Images chooser's chosen endpoint incorrectly listed items for which the user has not been granted choose permission. A user with access to the Wagtail admin could see the filename and name and URLs of documents and images in those collections.

The vulnerability is not e…

CVE-2026-54259
NVD

MEDIUM
CVE-2026-76380
CVE-2026-76380
pkg: oauth

published: Aug 19, 2026

In versions below 5.1.3 of the CrowdStrike OAuth API app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive document password by invoking either the detonate file or detonate url action, because the action's document_password parameter is not masked and …
CWE: CWE-312
NVD

MEDIUM
CVE-2026-54492
CVE-2026-54492
pkg: docker

published: Aug 19, 2026

Koel is a free, open-source music streaming solution. Prior to 9.7.0, the Subsonic-compatible createPodcastChannel.view route accepts an authenticated user's private URL because app/Http/Requests/Subsonic/CreatePodcastChannelRequest.php does not apply the SafeUrl validation used by the regular podca…
CWE: CWE-918
NVD

MEDIUM
CVE-2026-76166
CVE-2026-76166
pkg: node

published: Aug 19, 2026

A flaw was found in mod_cluster's AdvertiseListenerImpl (org.jboss.modcluster core module). A single crafted UDP multicast datagram with a valid HTTP status line and a "Server:" header but without the "Date:", "Digest:", and "Sequence:" headers triggers a NullPointerException in verifyDigest() that …
CWE: CWE-476
NVD

MEDIUM
CVE-2026-76041
CVE-2026-76041
pkg: google chrome

published: Aug 18, 2026

Information leak in Skia in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-200
GitHub-GHSA

MEDIUM
Lemur: Missing authorization check on POST /certificates/<id>/export for plugins with requires_key = False
GHSA-4h97-p9wq-chqj
pkg: lemur
eco: pip
published: Aug 18, 2026
## Summary

The `CertificateExport` handler in `lemur/certificates/views.py` nests its entire ownership / `CertificatePermission` check inside an `if plugin.requires_key:` branch. When the selected export plugin advertises `requires_key = False`, the authorization check is skipped entirely and any …

CVE-2026-71322
NVD

MEDIUM
CVE-2026-76032
CVE-2026-76032
pkg: node

published: Aug 18, 2026

Pydio Cells 5.0.0 through 5.0.2 returns share-link details to any authenticated user. The REST handler for GET /a/share/link/{Uuid} in idm/share/rest/handler.go reads the workspace UUID from the path, calls LinkById, and writes the result with no authorization step, whereas the sibling handler for G…
CWE: CWE-862
NVD

MEDIUM
CVE-2026-71322
CVE-2026-71322
pkg: tls

published: Aug 18, 2026

Lemur manages TLS certificate creation. Prior to 1.9.3, CertificateExport placed its CertificatePermission ownership check inside the plugin.requires_key branch for POST /api/1/certificates//export. A plugin declaring requires_key false bypassed that check, and the handler still passed cert.private_…
CWE: CWE-862
GitHub-GHSA

MEDIUM
MagicMirror socket payload secret placeholder expansion can disclose SECRET_* environment variables
GHSA-q4gh-4ffp-5cg8
pkg: magicmirror
eco: npm
published: Aug 18, 2026
### Summary
When `hideConfigSecrets: true` is enabled, MagicMirror redacts `SECRET_*` environment placeholders in the HTTP `/config` response, but the shared node-helper socket dispatcher expands `**SECRET_NAME**` placeholders in every inbound socket payload before passing it to module helpers. Any …
CVE-2026-63640
GitHub-GHSA

MEDIUM
Copyparty vulnerable to file/dirkey confusion
GHSA-x5pq-m9p8-f4vx
pkg: copyparty
eco: pip
published: Aug 18, 2026
A valid filekey could potentially be converted into a dirkey, granting read-access to the containing folder.

This issue only affected volumes which simultaneously enable both filekeys and dirkeys, with volflag `dk` or `dks` combined with `fk` or `fka`.

Both required features are default-disabled, …

CVE-2026-70657
NVD

MEDIUM
CVE-2026-75841
CVE-2026-75841
pkg: express

published: Aug 18, 2026

ArcadeDB before 26.8.1 contains a denial of service vulnerability in the Cypher range() function that allows authenticated users to exhaust server heap memory. Attackers can submit oversized range() expressions with large bounds to trigger OutOfMemoryError and cause temporary service degradation or …
CWE: CWE-770
NVD

MEDIUM
CVE-2026-16045
CVE-2026-16045
pkg: mattermost mattermost_server

published: Aug 17, 2026

Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 Mattermost failed to restrict OAuth deauthorization and personal access token management endpoints to direct user sessions, which allowed an OAuth app with a delegated user token to revoke the user's authorizations or tokens for other integra…
CWE: CWE-863
NVD

MEDIUM
CVE-2026-76033
CVE-2026-76033
pkg: google chrome

published: Aug 18, 2026

Inappropriate implementation in CORS in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-20
NVD

MEDIUM
CVE-2026-75833
CVE-2026-75833
pkg: oauth

published: Aug 18, 2026

The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0's admin-next/API stack) before version 1.0.14 contains an open redirect weakness in SsoController::sanitizeReturnTo(). The function rejects a literal '//' prefix but does not account for browsers normalizing backslashes to slashes i…
CWE: CWE-601
GitHub-GHSA

MEDIUM
Unleash: Global Mustache.escape override disables HTML escaping process-wide, enabling Slack/Teams link-injection via unrestricted username
GHSA-w4mq-xh27-6xpx
pkg: unleash-server
eco: npm
published: Aug 21, 2026
## Vulnerability Details

**File**: `src/lib/addons/feature-event-formatter-md.ts`
**Line**: 355 (in v8.0.1; `format()` method)

### Root Cause

`FeatureEventFormatterMd.format()` does:

“`ts
Mustache.escape = (text) => text;
const text = Mustache.render(action, context);
“`

`mustache` (pinned `^…

CVE-2026-63466
NVD

MEDIUM
CVE-2026-50126
CVE-2026-50126
pkg: node

published: Aug 18, 2026

Adaguc-server is an open source geographical information system to visualize, combine, compare and share real-time meteorological, climatological and remote sensing data via OGC standards. Versions prior to 7.2.2 crash with a memory-safety fault when it parses a GeoJSON document whose geometry conta…
CWE: CWE-125, CWE-476
GitHub-GHSA

MEDIUM
gettext-converter: Prototype pollution in js2i18next() via crafted translation keys
GHSA-f4jp-rw7w-ccwg
pkg: gettext-converter
eco: npm
published: Aug 20, 2026
### Impact

`js2i18next()` is vulnerable to prototype pollution. When converting translations, it splits nested keys on the key separator (default `##`) and uses each segment as a dynamic object key while building the output object. A key whose segment is `__proto__` (e.g. `__proto__##gcPolluted`) c…

CVE-2026-55451
GitHub-GHSA

MEDIUM
next-video: Unauthenticated arbitrary file read via /api/video request handler
GHSA-2p39-2jf3-fv2q
pkg: next-video
eco: npm
published: Aug 20, 2026
### Impact

The HTTP route handler exported by `next-video/request-handler` — which the README instructs consumers to mount at `/api/video` — allows an unauthenticated remote attacker to read arbitrary `.json` files from the production filesystem of any application following the documented setup…

CVE-2026-54150
GitHub-GHSA

MEDIUM
Zoo Design Studio: Memory-corruption in memory handling of lib-kcl
GHSA-mc9m-6fm9-pghc
pkg: zoo-kcl, kcl-lib
eco: pip
published: Aug 20, 2026
A race condition in kcl-lib can result in a use-after-free when accessing environments concurrently. During Vec reallocation, the previous buffer containing Box pointers is freed and replaced. A concurrent get_env operation that has already loaded a pointer to the old buffer may subsequently index i…
GitHub-GHSA

MEDIUM
Zoo Design Studio: Recursive KCL parsing is vulnerable to denial-of-service
GHSA-jgvr-6x5w-hx5w
pkg: zoo-kcl, kcl-lib
eco: pip
published: Aug 20, 2026
### Impact
Feeding a KCL program that wraps an expression in deep, unnecessary parentheses triggers the parser’s recursive `expression` -> `unnecessarily_bracketed` -> `expression` path. With enough nesting, the call stack grows until it exceeds the process stack limit, causing a stack overflow.
GitHub-GHSA

MEDIUM
OpenTelemetry-Go: Unsynchronized baggage map can panic under concurrent access
GHSA-42cj-99w8-cp2p
pkg: go.opentelemetry.io/otel/bridge/opentracing
eco: go
published: Aug 20, 2026
### Summary

`go.opentelemetry.io/otel/bridge/opentracing` introduced an unsynchronized `extraBaggageItems` map on `bridgeSpan`. One goroutine can write this map through `Span.SetBaggageItem` while another goroutine reads and iterates it during correlation baggage propagation, which can trigger Go's…

CVE-2026-45404
GitHub-GHSA

MEDIUM
Velero vulnerable to file path traversal when extracting from backup's tarball
GHSA-j2g6-362q-6qc6
pkg: github.com/vmware-tanzu/velero
eco: go
published: Aug 20, 2026
### Impact
_What kind of vulnerability is it? Who is impacted?_
If the attacker compromises the backup's object storage backend and uploads a malicious backup tarball including file names like the following:
* ../../../tmp/escape_1 -> file created at /tmp/escape_1
* ../../../../../../..…
CVE-2026-32637
GitHub-GHSA

MEDIUM
BuildKit: Custom frontend could bypass Seccomp/AppArmor
GHSA-7236-3392-c5c6
pkg: github.com/moby/buildkit
eco: go
published: Aug 19, 2026
### Impact
A custom frontend could send a crafted build request that disabled Seccomp and AppArmor protections for the build container, even if the user did not explicitly allow the `security.insecure` entitlement. Other security measures, like Linux capabilities were still applied to these containe…
CVE-2026-61711
GitHub-GHSA

MEDIUM
Uprobe gadgets: unprivileged container's ld.so.cache causes high CPU utilization and container startup DoS
GHSA-vjhx-2cqw-3q6q
pkg: github.com/inspektor-gadget/inspektor-gadget
eco: go
published: Aug 19, 2026
## Summary

An unprivileged container can block all other containers from starting on the
same host by placing a crafted `/etc/ld.so.cache` file in its filesystem. When
Inspektor Gadget attaches any uprobe-based gadget, it parses this file in the
container startup path. A malicious cache causes ~53 …

CVE-2026-53941
GitHub-GHSA

MEDIUM
block_buffer: panic corrupts inline buffer position
GHSA-qwgh-2vcv-g2f7
pkg: block_buffer
eco: rust
published: Aug 19, 2026
### Summary

A caught panic may leave the cursor position of `EagerBuffer` or `ReadBuffer` in a corrupted state; this in turn allows out-of-bounds reads/writes.

### Details & PoC

The following two tests fail miri:

“`rust
#[cfg(miri)]
#[test]
fn eager_digest_blocks_panic_corrupts_inline_position(…

GitHub-GHSA

MEDIUM
Triton VM Soundness Vulnerability due to Missing Constraint
GHSA-vjf8-9fx6-mv6x
pkg: triton-vm
eco: rust
published: Aug 18, 2026
The instruction `sponge_absorb_mem` Triton VM fails to verify that hashed values come from the claimed memory location. Malicious provers can substitute arbitrary data instead of actual memory contents.

Any application using instruction `sponge_absorb_mem` to hash memory data can be given a proof f…

GitHub-GHSA

MEDIUM
MagicMirror: ssrf calendar .js
GHSA-w6x9-28jw-hq7j
pkg: magicmirror
eco: npm
published: Aug 18, 2026
# Vulnerability — SSRF via `ADD_CALENDAR` (MagicMirror² calendar)

> Analysis of the PoC `exploit-ssrf-calendar.js`.
> Target: `calendar/node_helper.js` of MagicMirror², socket.io namespace `/calendar`.

## Identification

| Field | Value |
|——-|——-|
| **PoC file** | `exploit-ssrf-c…

CVE-2026-63643
GitHub-GHSA

MEDIUM
MagicMirror newsfeed Socket.IO notification allows blind server-side request forgery
GHSA-998g-7v5w-cr7g
pkg: magicmirror
eco: npm
published: Aug 18, 2026
# Vulnerability — Blind SSRF via `CHECK_ARTICLE_URL` (MagicMirror² newsfeed)

> Analysis of the PoC `exploit-ssrf-newsfeed.js`.
> Target: `newsfeed/node_helper.js` of MagicMirror², socket.io namespace `/newsfeed`.

## Identification

| Field | Value |
|——-|——-|
| **PoC file** | `exp…

CVE-2026-63642
GitHub-GHSA

MEDIUM
RabbitMQ Java client: TrustEverythingTrustManager used by default in useSslProtocol() enables MITM
GHSA-5m9f-rphj-c435
pkg: com.rabbitmq:amqp-client
eco: maven
published: Aug 18, 2026
## Vulnerability Summary

`com.rabbitmq.client.TrustEverythingTrustManager` accepts ANY TLS certificate (including null chains) and is used as the default trust manager when calling `ConnectionFactory.useSslProtocol()` without arguments. Combined with hostname verification being disabled by default,…

CVE-2026-63336
GitHub-GHSA

MEDIUM
RabbitMQ Java client malformed body frame triggers raw command assembler exception
GHSA-qx7j-jv8m-fppr
pkg: com.rabbitmq:amqp-client
eco: maven
published: Aug 18, 2026
### Summary
RabbitMQ Java Client's inbound AMQP command assembly accepts a content header declaring a small body and then processes a larger body frame by throwing a raw `UnsupportedOperationException` from `CommandAssembler`. A broker peer that the client has connected to can use this malformed fra…
CVE-2026-63335
GitHub-GHSA

MEDIUM
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write
GHSA-8rc5-4fr6-64pw
pkg: github.com/aquasecurity/trivy
eco: go
published: Aug 18, 2026
## Summary

Trivy's plugin manager does not fully validate metadata from a plugin's manifest before using it to construct filesystem paths under the plugin root (`~/.trivy/plugins`). A crafted plugin can cause Trivy to write its files (the manifest and the downloaded plugin binary) outside the plugi…

CVE-2026-63328
GitHub-GHSA

MEDIUM
package pkcs12: Authentication bypass in Decode functions
GHSA-mpwr-8vm7-h73f
pkg: software.sslmate.com/src/go-pkcs12
eco: go
published: Aug 17, 2026
`Decode`, `DecodeChain`, `DecodeTrustStore`, and `ToPEM` can incorrectly accept PKCS#12 files which were encoded with the wrong password, due to a failure to reject excessively-short PBMAC1 keys. Users who decode PKCS#12 files from untrusted sources and rely on the password for authentication can be…
GitHub-GHSA

MEDIUM
Etherpad addressed weak token RNG, login timing, plugin path handling, API request handling
GHSA-92hr-gmr6-h8cp
pkg: ep_etherpad-lite
eco: npm
published: Aug 17, 2026
Fix: PR #7906 (ether/etherpad). A set of medium/low hardening fixes:

– **Weak RNG for tokens (CWE-330):** author/session/readonly IDs were generated with `Math.random()` (client and server). Now use `crypto.getRandomValues`.
– **Login timing / no failure delay (CWE-208/CWE-307):** the OIDC interact…

GitHub-GHSA

MEDIUM
uniget CLI has Path Traversal in Hook Files – Directory Escape Vulnerability
GHSA-m6jg-wr9m-cg2f
pkg: gitlab.com/uniget-org/cli
eco: go
published: Aug 17, 2026
### Summary
Path Traversal vulnerability in hook filename handling allows attackers to access and manipulate arbitrary files outside the hooks directory via directory escape sequences like [passwd](vscode-file://vscode-app/app/extra/vscode/resources/app/out/vs/code/electron-browser/workbench/workben…
CVE-2026-55062
GitHub-GHSA

MEDIUM
uniget CLI has an EDITOR Command Injection
GHSA-qmcq-xw74-w667
pkg: gitlab.com/uniget-org/cli
eco: go
published: Aug 17, 2026
### Summary
The uniget CLI has a command injection vulnerability in [hooks.go](vscode-file://vscode-app/app/extra/vscode/resources/app/out/vs/code/electron-browser/workbench/workbench.html) line 199 where [strings.Split(editor, " ")](vscode-file://vscode-app/app/extra/vscode/resources/app/out/vs/cod…
CVE-2026-55061
GitHub-GHSA

MEDIUM
sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes
GHSA-3496-9g83-7v6x
pkg: sqlparse
eco: pip
published: Aug 17, 2026
### Summary

The documented Python and PHP output modes generate source-code snippets from caller-supplied SQL. Their output filters escape quote characters without first escaping existing backslashes. Crafted SQL can therefore neutralize the generated quote escape, terminate the intended language s…

CVE-2026-59894
GitHub-GHSA

MEDIUM
Terragrunt: Arbitrary File Deletion via Malicious Module Manifest
GHSA-8394-6f8r-whxg
pkg: github.com/gruntwork-io/terragrunt
eco: go
published: Aug 17, 2026
### Summary

Terragrunt is vulnerable to an arbitrary file deletion flaw when downloading external modules. If a remote module contains a maliciously crafted `.terragrunt-module-manifest` file, Terragrunt can be tricked into deleting files anywhere on the local filesystem that the Terragrunt process…

CVE-2026-45099
GitHub-GHSA

MEDIUM
New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass
GHSA-j6gc-4893-qwmp
pkg: github.com/QuantumNous/new-api
eco: go
published: Aug 17, 2026
### Summary
Authenticated users can repeatedly call PUT /api/user/self with language or sidebar_modules while relay requests are consuming quota. The settings path reads a full User snapshot and writes it back through User.Update(), which refreshes Redis with RedisHSetObj and overwrites the Quota fi…
CVE-2026-64865
GitHub-GHSA

MEDIUM
New API: Admin can reset passkeys for same-level or higher-privileged users
GHSA-p845-629j-rcj6
pkg: github.com/QuantumNous/new-api
eco: go
published: Aug 17, 2026
## Summary

The admin passkey reset endpoint lacked the role-level authorization check used by comparable privileged account-protection endpoints. A lower-privileged administrator could attempt passkey reset operations against same-level or higher-privileged users, including root-level accounts.

##…

CVE-2026-64866


Vulnerability Digest — August 17, 2026 · 54 Critical · 3 Exploited






Vulnerability Digest — Monday, August 17, 2026


Security Report

Monday, August 17, 2026  ·  Last 7 days  ·  Min severity: MEDIUM
Total Findings
289
Critical
54
High
153
Actively Exploited
3
CISA-KEV3
NVD244
GitHub-GHSA42
Findings sorted by severity
CISA-KEV

CRITICAL
Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
CVE-2026-68820
pkg: Microsoft Windows Ancillary Function Driver for WinSock

published: Aug 11, 2026

Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Metabase SQL Injection Vulnerability
CVE-2026-72898
pkg: Metabase Metabase

published: Aug 11, 2026

Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored c…
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability
CVE-2026-20349
pkg: Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)

published: Aug 11, 2026

Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
NVD

CRITICAL
CVE-2026-73678
CVE-2026-73678
pkg: python

published: Aug 14, 2026

MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by submitting crafted prompts to the unprotected POST /api/v1/responses/ endpoint, which reaches the Anton agent's …
CWE: CWE-94
NVD

CRITICAL
CVE-2026-73299
CVE-2026-73299
pkg: node

published: Aug 12, 2026

Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies with unrestricted JavaScript member access. An attacker-controlled template could traverse constructor and prototype properties…
CWE: CWE-94, CWE-1336
NVD

CRITICAL
CVE-2026-58115
CVE-2026-58115
pkg: node

published: Aug 11, 2026

A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to programming nodes that are c…
CWE: CWE-306
NVD

CRITICAL
CVE-2026-73269
CVE-2026-73269
pkg: node

published: Aug 12, 2026

A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, can trigger the creation of a cluster-scoped ClusterRoleBinding. This allows the user to escalate their privileges from namespace-local access to clust…
CWE: CWE-269
NVD

CRITICAL
CVE-2026-62420
CVE-2026-62420
pkg: node

published: Aug 12, 2026

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations. When moving an instance cross-project to a different cluster member via POST /1.0/instances/{name} with migration: true, project: <ta…
CWE: CWE-863
NVD

CRITICAL
CVE-2026-73263
CVE-2026-73263
pkg: kubernetes

published: Aug 12, 2026

Prowler is a cloud security platform. Prior to 5.36.0, the Kubernetes provider connection test accepted kubeconfig_content containing a legacy gcp auth-provider with config.cmd-path and config.cmd-args because kubeconfig_contains_exec_auth in api/src/backend/api/v1/serializers.py checked only exec b…
CWE: CWE-78
NVD

CRITICAL
CVE-2026-48765
CVE-2026-48765
pkg: oauth

published: Aug 11, 2026

TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege read collaborator to extract a workspace OAuth `credentialsId` from a readable bot configuration and then overwrite that credential through `handleUpdateOAuthCredentials()` by supplying an attacker-controlled writable …
CWE: CWE-639
NVD

CRITICAL
CVE-2026-72911
CVE-2026-72911
pkg: express

published: Aug 10, 2026

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.118.0 and 16.29.0, the validate_template and render_template calls in erpnext/accounts/doctype/process_statement_of_accounts/process_statement_of_accounts.py render subject, body, and pdf_name fields with unrestricted g…
CWE: CWE-1336
NVD

CRITICAL
CVE-2026-14450
CVE-2026-14450
pkg: kubernetes

published: Aug 10, 2026

A flaw was found in the MaaS API. This vulnerability allows any pod within the cluster to bypass the Kuadrant AuthPolicy gateway by forging HTTP headers, specifically `X-MaaS-Username` and `X-MaaS-Group`, which are trusted verbatim. This lack of first-party authentication enables an attacker to gain…
CWE: CWE-290
NVD

CRITICAL
CVE-2026-72901
CVE-2026-72901
pkg: docker

published: Aug 10, 2026

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated low-privilege member to execute arbitrary commands on the control-plane host because the volumeName field accepted by volumeBackup.create and volumeBackup.runManually is interpolated with…
CWE: CWE-78
NVD

CRITICAL
CVE-2026-72876
CVE-2026-72876
pkg: node

published: Aug 10, 2026

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, swarm.getNodes, swarm.getNodeInfo, swarm.getNodeApps, and swarm.getAppInfos in apps/dokploy/server/api/routers/swarm.ts accept another organization’s serverId without an activeOrganizationId ownership check, and getNo…
CWE: CWE-78, CWE-639, CWE-862
NVD

CRITICAL
CVE-2026-72869
CVE-2026-72869
pkg: docker

published: Aug 10, 2026

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC subscription passes the databaseName parameter to restore builders in packages/server/src/utils/restore/utils.ts, where PostgreSQL, MariaDB, MySQL, and MongoDB commands embed the va…
CWE: CWE-77, CWE-78
NVD

CRITICAL
CVE-2026-72868
CVE-2026-72868
pkg: docker

published: Aug 10, 2026

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, apps/dokploy/server/api/routers/destination.ts interpolates the accessKey, secretAccessKey, region, endpoint, provider, and bucket fields from destination.testConnection into an rclone ls command executed through child_…
CWE: CWE-78, CWE-862
NVD

CRITICAL
CVE-2026-72865
CVE-2026-72865
pkg: docker

published: Aug 10, 2026

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the compose.update operation stores an unvalidated composePath that packages/server/src/utils/builders/compose.ts and packages/server/src/services/compose.ts interpolate into docker compose -f, docker stack deploy -c, a…
CWE: CWE-78
NVD

CRITICAL
CVE-2026-72863
CVE-2026-72863
pkg: docker

published: Aug 10, 2026

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's WebSocket handlers (in-app terminals and log streamers) authenticate the session but never authorize it. They establish who the user is via validateRequest() and then proceed without consulting the role/permis…
CWE: CWE-269, CWE-639, CWE-862
NVD

CRITICAL
CVE-2026-72862
CVE-2026-72862
pkg: docker

published: Aug 10, 2026

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the mariadb.ts, mongo.ts, mysql.ts, postgres.ts, redis.ts, and libsql.ts Dokploy database service deployment functions pass user-controlled dockerImage fields unquoted into docker pull ${dockerImage} shell commands on t…
CWE: CWE-78
NVD

CRITICAL
CVE-2026-72736
CVE-2026-72736
pkg: docker

published: Aug 10, 2026

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy passes user-controlled values directly into shell commands via unquoted template literal interpolation in the registry credential testing and Docker Swarm cluster management endbpoints. Both endpoints have a saf…
CWE: CWE-77
NVD

CRITICAL
CVE-2026-74269
CVE-2026-74269
pkg: express

published: Aug 15, 2026

In the Linux kernel, the following vulnerability has been resolved:

bnxt: fix head underflow on XDP head-grow

The xdp.py test test_xdp_native_adjst_head_grow_data crashes when run on
a bnxt machine (and also crashes in NIPA).

It seems that the bug is an underflow in bnxt_rx_multi_page_skb, which

NVD

CRITICAL
CVE-2026-72317
CVE-2026-72317
pkg: tls

published: Aug 15, 2026

In the Linux kernel, the following vulnerability has been resolved:

SUNRPC: pin upper rpc_clnt across the TLS connect_worker

The TLS connect path has a use-after-free: nothing pins the
upper rpc_clnt across the delayed connect_worker. xs_connect()
stores task->tk_client in sock_xprt::clnt as a raw…

NVD

CRITICAL
CVE-2026-72222
CVE-2026-72222
pkg: tls

published: Aug 15, 2026

In the Linux kernel, the following vulnerability has been resolved:

sunrpc: pin svc_xprt across the asynchronous TLS handshake callback

svc_tcp_handshake() stores the raw svc_xprt pointer in
tls_handshake_args.ta_data and submits the request through
tls_server_hello_x509(). The handshake core take…

NVD

CRITICAL
CVE-2026-72221
CVE-2026-72221
pkg: tls

published: Aug 15, 2026

In the Linux kernel, the following vulnerability has been resolved:

sunrpc: wait for in-flight TLS handshake callback when cancel loses race

When wait_for_completion_interruptible_timeout() in
svc_tcp_handshake() returns 0 (timeout) or -ERESTARTSYS (signal) and
tls_handshake_cancel() then returns …

NVD

CRITICAL
CVE-2026-50027
CVE-2026-50027
pkg: oauth

published: Aug 14, 2026

mcp-memory-service is a semantic memory layer for AI applications. Prior to 10.67.1, all HTTP routes under /api/documents/* in mcp-memory-service are served without any authentication dependency, even when the server is configured with an API key (MCP_API_KEY) or OAuth. An unauthenticated remote att…
CWE: CWE-306
NVD

CRITICAL
CVE-2026-73649
CVE-2026-73649
pkg: express

published: Aug 13, 2026

Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for CVE-2026-44966 filtered constructor, __proto__, and prototype only in the #set assignment handler in src/compile/set.ts, while property-read expressions in src/compile/references.ts…
CWE: CWE-94
NVD

CRITICAL
CVE-2026-67614
CVE-2026-67614
pkg: jwt

published: Aug 13, 2026

CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote attackers to forge valid authentication tokens and obtain an interactive root shell via WebSocket on port 8888. Attackers can craft a forged JWT signed wit…
CWE: CWE-798
NVD

CRITICAL
CVE-2026-28185
CVE-2026-28185
pkg: go

published: Aug 13, 2026

Unauthenticated Broken Authentication in Log in with Google <= 1.4.2 versions.
CWE: CWE-345
NVD

CRITICAL
CVE-2026-28008
CVE-2026-28008
pkg: oauth

published: Aug 13, 2026

Unauthenticated Broken Authentication in OAuth Single Sign On – SSO (OAuth Client) <= 7.0.0 versions.
CWE: CWE-290
NVD

CRITICAL
CVE-2026-49819
CVE-2026-49819
pkg: jwt

published: Aug 13, 2026

UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerInitSuperuser` (`backend/pb/handlers.go:249`), reachable as `POST /api/upsnap/init-superuser`. The vulnerable code lacks any authentication, setup token…
CWE: CWE-78, CWE-269, CWE-306, CWE-862
NVD

CRITICAL
CVE-2026-73519
CVE-2026-73519
pkg: docker

published: Aug 12, 2026

WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs, allowing remote unauthenticated attackers to bypass authentication by supplying this value in the X-WolfStack-Secret header to the require_auth() gate…
CWE: CWE-798
NVD

CRITICAL
CVE-2026-73034
CVE-2026-73034
pkg: python

published: Aug 11, 2026

DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers to write arbitrary files to any location on the server by injecting directory traversal sequences into the user_id HTTP header of the Python file-upload endpoint. Attackers can send a crafted multipar…
CWE: CWE-22
NVD

CRITICAL
CVE-2026-73211
CVE-2026-73211
pkg: oauth

published: Aug 11, 2026

PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.1.6, ActorFollowModel.updateScore() interpolates the attacker-controlled ActivityPub actor inboxUrl into an SQL query, allowing an unauthenticated remote server to read and write PeerTube database tables, including oAuthToken.…
CWE: CWE-89
NVD

CRITICAL
CVE-2026-69102
CVE-2026-69102
pkg: jwt

published: Aug 11, 2026

MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in application-maxkey.properties that allows unauthenticated attackers to forge valid JWT tokens and authenticate as any user by exploiting the password-skipped login endpoint. Attackers can craft a JWT token…
CWE: CWE-798
NVD

CRITICAL
CVE-2026-72920
CVE-2026-72920
pkg: jwt

published: Aug 11, 2026

SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC service without mandatory authentication when jwt.filer_signing.key is unset, allowing any client that can reach the filer gRPC port to invoke CreateUser, CreateAccessKey, PutPolicy…
CWE: CWE-306
NVD

CRITICAL
CVE-2026-68160
CVE-2026-68160
pkg: go

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()

ceph_handle_caps() reads snap_trace_len from the wire-format
ceph_mds_caps header and uses it unconditionally to build a fake
end pointer (snaptrace + snaptr…

NVD

CRITICAL
CVE-2026-68127
CVE-2026-68127
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

ila: reload IPv6 header after pskb_may_pull in checksum adjust

ila_csum_adjust_transport() caches ip6h = ipv6_hdr(skb) before calling
pskb_may_pull(). On a non-linear skb whose transport header sits in a page
fragment, pskb_may_pu…

NVD

CRITICAL
CVE-2026-68123
CVE-2026-68123
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

openvswitch: fix GSO userspace truncation underflow

OVS_ACTION_ATTR_TRUNC currently stores a delta from the original skb
length in OVS_CB(skb)->cutlen. When a later userspace action segments a
GSO skb, queue_gso_packets() reuses t…

NVD

CRITICAL
CVE-2026-68117
CVE-2026-68117
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

tipc: clear sock->sk on the failed-insert path in tipc_sk_create()

When tipc_sk_create() fails to insert the new socket (tipc_sk_insert()
returns non-zero), its error path frees the sk with sk_free() but leaves
sock->sk pointing a…

NVD

CRITICAL
CVE-2026-73843
CVE-2026-73843
pkg: kubernetes

published: Aug 13, 2026

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, internal/cluster-gateway/server.go served caller-facing management APIs on the externally reachable agent listener without authentication, allowing network-reachable attackers to invoke /api/proxy/ and…
CWE: CWE-306, CWE-668, CWE-862
NVD

CRITICAL
CVE-2026-8715
CVE-2026-8715
pkg: kubernetes

published: Aug 13, 2026

Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissions to read files from the operator pod's filesystem and transmit their contents…
CWE: CWE-552
NVD

CRITICAL
CVE-2026-72877
CVE-2026-72877
pkg: docker

published: Aug 10, 2026

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the dockerImage field is interpolated without quoting into shell commands in buildRemoteDocker() in packages/server/src/utils/providers/docker.ts and is validated only as an optional string. An authenticated user with a…
CWE: CWE-78
NVD

CRITICAL
CVE-2026-68124
CVE-2026-68124
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

mctp: serial: handle zero-length frames to prevent rx buffer overflow

The MCTP serial receive state machine reads a frame length byte in
mctp_serial_push_header() case 2 and validates it upper-bound-only:

if (c > MCTP_SERIAL_FRA…

NVD

CRITICAL
CVE-2026-73653
CVE-2026-73653
pkg: vite

published: Aug 13, 2026

Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, takeScreenshot, screenshotMatcher, stopChunkTrace, deleteTracing, and annotateTraces accept browser-supplied file paths without enforcing the allowWrite …
CWE: CWE-22, CWE-552, CWE-862
NVD

CRITICAL
CVE-2026-50561
CVE-2026-50561
pkg: jwt

published: Aug 12, 2026

Yuxi is a large-model-based intelligent knowledge base and knowledge graph agent development platform. Prior to version 0.6.2, the project's authentication mechanism contains a flaw. In affected versions, the system does not sufficiently validate the identity token in the Authorization header — on…
CWE: CWE-287
NVD

CRITICAL
CVE-2026-50516
CVE-2026-50516
pkg: microsoft azure_kubernetes_service

published: Aug 11, 2026

Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
CWE: CWE-306
NVD

CRITICAL
CVE-2026-73080
CVE-2026-73080
pkg: jwt

published: Aug 11, 2026

SeaweedFS is a distributed storage system. Prior to 4.24, VolumeServer.FetchAndWriteNeedle in weed/server/volume_grpc_remote.go fetches a caller-supplied remote endpoint through weed/remote_storage/s3/s3_storage_client.go and writes the response into a needle. The RPC performs no authentication and …
CWE: CWE-918
GitHub-GHSA

CRITICAL
SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle
GHSA-87fv-vqqr-m4jr
pkg: github.com/seaweedfs/seaweedfs
eco: go
published: Aug 11, 2026
### Impact
`VolumeServer.FetchAndWriteNeedle` fetches a caller-supplied remote endpoint and writes the response into a needle. Before 4.24 this RPC performed no authentication and no validation of the target, so anyone able to reach a volume server's gRPC port could coerce the server into issuing re…
CVE-2026-73080
NVD

CRITICAL
CVE-2026-47754
CVE-2026-47754
pkg: node

published: Aug 10, 2026

Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.x through 2.19.1 and all 1.x versions contain an unauthenticated path traversal in the `archiveEntryName` parameter of the `action=read` endpoint that is part of the original 1.x Metacat API. `A…
CWE: CWE-22, CWE-862
NVD

CRITICAL
CVE-2026-49457
CVE-2026-49457
pkg: tls

published: Aug 14, 2026

erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and the hostname was not compared against the certificate,…
CWE: CWE-295, CWE-297
NVD

CRITICAL
CVE-2026-73501
CVE-2026-73501
pkg: oauth

published: Aug 12, 2026

kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces a nil AuthenticationFunc with NoopAuthenticationFunc, which returns nil without checking credentials. This substitution causes every OpenAPI se…
CWE: CWE-287
NVD

CRITICAL
CVE-2026-71290
CVE-2026-71290
pkg: tls

published: Aug 11, 2026

Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between the client and the server can impersonate…
CWE: CWE-295
NVD

CRITICAL
CVE-2026-68083
CVE-2026-68083
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix path resolution in ksmbd_vfs_kern_path_create

The SMB2 open lookup is rooted at the share with LOOKUP_BENEATH, but the
create/mkdir/hardlink sink is not: ksmbd_vfs_kern_path_create() builds an
absolute path with convert…

NVD

CRITICAL
CVE-2026-73842
CVE-2026-73842
pkg: kubernetes

published: Aug 13, 2026

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go exposed /api/proxy/, /api/exec/, and /api/wirelogs/ on an internal listener without requiring a client certificate or token, allowing any network-reachab…
CWE: CWE-269, CWE-306, CWE-862
NVD

HIGH
CVE-2026-72382
CVE-2026-72382
pkg: express

published: Aug 15, 2026

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: reject undersized DACLs before parsing ACEs

parse_dacl() limits the attacker-controlled ACE count by comparing it
with the number of minimal ACEs that fit in the DACL size. The DACL size
field is 16 bits, but the expression…

NVD

HIGH
CVE-2026-73841
CVE-2026-73841
pkg: kubernetes

published: Aug 13, 2026

OpenChoreo is a complete, open-source developer platform for Kubernetes. From 1.2.0-rc.1 until 1.2.0, internal/openchoreo-api/api/handlers/exec.go and internal/openchoreo-api/api/handlers/wirelogs.go authorize component:exec and wirelogs:view using the caller-supplied project query parameter instead…
CWE: CWE-639, CWE-863
NVD

HIGH
CVE-2026-73667
CVE-2026-73667
pkg: kubernetes

published: Aug 13, 2026

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.0-rc.2, OpenChoreo Workflow Plane templates under samples/getting-started/workflow-templates/ interpolated developer-controlled workflow parameters into shell program text executed through sh -c i…
CWE: CWE-78
NVD

HIGH
CVE-2026-15741
CVE-2026-15741
pkg: express

published: Aug 13, 2026

SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition. Attacks affect expression deparse consumers broadly, including pg_dump, psql commands like \sf, and any similar usage in non-core tools. Versions before Pos…
CWE: CWE-89
NVD

HIGH
CVE-2026-49473
CVE-2026-49473
pkg: express

published: Aug 13, 2026

@cedar-policy/authorization-for-expressjs is an open-source Express.js middleware that integrates Cedar authorization into Express applications by mapping HTTP requests to Cedar actions and evaluating authorization policies before allowing requests to proceed. Versions prior to 0.3.0 have an issue w…
CWE: CWE-436, CWE-863
NVD

HIGH
CVE-2026-13622
CVE-2026-13622
pkg: node

published: Aug 12, 2026

A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside the target virt-launcher pod via /proc/<pid>/root/ paths using net.Dial() without symlink protection. These socket paths reside in qemu-owned director…
CWE: CWE-22
NVD

HIGH
CVE-2026-49467
CVE-2026-49467
pkg: express

published: Aug 12, 2026

Pingvin Share X is a secure and easy self-hosted file sharing platform. A vulnerability in versions 1.5.0 through 1.18.0 allow an attacker to bypass password verification when managing Time-based One-Time Password (TOTP) settings. The root cause is a missing `await` keyword on calls to the asynchron…
CWE: CWE-303, CWE-304
NVD

HIGH
CVE-2026-44741
CVE-2026-44741
pkg: express

published: Aug 12, 2026

Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Versions prior to 2.3.6 and 1.7.18 have a SQL injection vulnerability in Pimcore's translation grid date filter — the user-supplied `property` field from the filter JSON is interpolated directly into a `UNIX_TIMESTAMP(DATE(FROM_UNIX…
CWE: CWE-89
NVD

HIGH
CVE-2026-65941
CVE-2026-65941
pkg: go

published: Aug 12, 2026

In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.
CWE: CWE-73, CWE-94, CWE-306, CWE-918
NVD

HIGH
CVE-2026-58076
CVE-2026-58076
pkg: apache airflow

published: Aug 12, 2026

Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and instantiating it with arguments from the same blob, with no restriction on what could be imported. An operator's `executor_config` reaches that branch, s…
CWE: CWE-502
NVD

HIGH
CVE-2026-19560
CVE-2026-19560
pkg: go

published: Aug 11, 2026

Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-19559
CVE-2026-19559
pkg: go

published: Aug 11, 2026

Use after free in HTML in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-19556
CVE-2026-19556
pkg: go

published: Aug 11, 2026

Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-55676
CVE-2026-55676
pkg: nginx

published: Aug 11, 2026

Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` and stores them in a directory served by the same nginx and php-fpm instance. The allow-list that should restrict accepted file types is an empty array …
CWE: CWE-434
NVD

HIGH
CVE-2026-73222
CVE-2026-73222
pkg: node

published: Aug 11, 2026

Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the –studio option in cli-tool/src/sandbox-server.js binds to all interfaces on port 3444, permits cross-origin requests, and requires no authentication. The PO…
CWE: CWE-78, CWE-306, CWE-352
NVD

HIGH
CVE-2026-18691
CVE-2026-18691
pkg: node

published: Aug 11, 2026

An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to influence which authentication mechanism is used when one replica set member connects to another. Under certain conditions, this could cause the cluster's shared internal credential to be …
CWE: CWE-757
NVD

HIGH
CVE-2026-49179
CVE-2026-49179
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.
CWE: CWE-77
NVD

HIGH
CVE-2026-72533
CVE-2026-72533
pkg: docker

published: Aug 11, 2026

An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privileged users to bypass Docker proxy authorization checks via non-canonical URL normalization, defeating all authorization middleware. The proxy endpoint fails to normalize request paths before applying…
CWE: CWE-287
NVD

HIGH
CVE-2026-15555
CVE-2026-15555
pkg: node

published: Aug 11, 2026

A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicated session data via the JBoss Marshalling River unmarshaller with no class filtering — enabling RCE via deserialization gadget chains on every cluster node.
CWE: CWE-502
NVD

HIGH
CVE-2026-18982
CVE-2026-18982
pkg: kubernetes

published: Aug 10, 2026

A flaw was found in the RHOAI training-operator. This vulnerability allows a user with standard edit or admin roles in any Kubernetes namespace to escalate their privileges. Through the creation of training jobs, an attacker can impersonate service accounts, access the host filesystem, and potential…
CWE: CWE-250
NVD

HIGH
CVE-2026-18951
CVE-2026-18951
pkg: kubernetes

published: Aug 10, 2026

A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly aggregates `trainjobs` management permissions into the native Kubernetes `edit ClusterRole`. This allows any user with `edit ClusterRole` permissions in a namespace to create, modify…
CWE: CWE-284
NVD

HIGH
CVE-2026-68341
CVE-2026-68341
pkg: express

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

ovpn: fix use after free in unlock_ovpn()

unlock_ovpn() iterates over the release_list using llist_for_each_entry()
and drops the peer reference inside the loop body via ovpn_peer_put().

If this drops the last reference, the peer…

NVD

HIGH
CVE-2026-68294
CVE-2026-68294
pkg: node

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

net: qrtr: restrict socket creation to the initial network namespace

QRTR keeps its entire port and node state in module-global variables
that are not partitioned per network namespace: qrtr_local_nid is a
single global node id (a…

NVD

HIGH
CVE-2026-68140
CVE-2026-68140
pkg: go

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

net/iucv: fix use-after-free of a severed iucv_path

af_iucv queues not-yet-received message notifications on iucv->message_q,
each holding a raw pointer to the connection's iucv_path. When the peer
severs the connection, iucv_sev…

NVD

HIGH
CVE-2026-68128
CVE-2026-68128
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

ice: reject out-of-range ptype in ice_parser_profile_init

set_bit(rslt->ptype, prof->ptypes) operates on a DECLARE_BITMAP of
ICE_FLOW_PTYPE_MAX (1024) bits. Nothing prevents a malicious VF from
providing ptype >= 1024 through VIRT…

NVD

HIGH
CVE-2026-68125
CVE-2026-68125
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

mac802154: llsec: reject frames shorter than the authentication tag

llsec_do_decrypt_auth() computes the associated-data length for the
AEAD request as

assoclen += datalen – authlen;

where datalen is the number of bytes after t…

NVD

HIGH
CVE-2026-68108
CVE-2026-68108
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu/vce: fix integer overflow in image size

Fix a security vulnerability where malicious VCE command streams
with oversized dimensions (e.g. 65536×65536) cause 32-bit integer
overflow, wrapping the calculated buffer size t…

NVD

HIGH
CVE-2026-68107
CVE-2026-68107
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu/vcn4: avoid rereading IB param length

Reuse the parameter length returned by
vcn_v4_0_enc_find_ib_param() instead of rereading it from
the IB.

This avoids a potential TOCTOU issue if the IB contents
change between read…

NVD

HIGH
CVE-2026-68098
CVE-2026-68098
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: bound DACL dedup walk to copied ACEs

set_ntacl_dacl() can stop copying ACEs before consuming the full input
DACL when size accounting overflows.

When that happens, num_aces reflects only the ACEs that were actually
copied …

NVD

HIGH
CVE-2026-68097
CVE-2026-68097
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: validate ACE size against SID sub-authorities

set_ntacl_dacl() validates sid.num_subauth before copying an ACE, but
does not verify that the declared ACE size contains all sub-authorities
described by that field. An undersi…

NVD

HIGH
CVE-2026-68091
CVE-2026-68091
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

HID: wacom: stop hardware after post-start probe failures

wacom_parse_and_register() starts HID hardware before registering inputs
and initializing pad LEDs/remotes. Those later steps can fail, but their
error paths currently rele…

NVD

HIGH
CVE-2026-49478
CVE-2026-49478
pkg: kubernetes

published: Aug 13, 2026

Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Versions through 1.8.5 improperly follow cross-host redirects and attach Kubernetes ServiceAccount tokens during OIDC discovery, allowing a malicious or compromised issuer to perform blind …
CWE: CWE-918
NVD

HIGH
CVE-2026-18608
CVE-2026-18608
pkg: kubernetes

published: Aug 10, 2026

A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which defines its permissions, includes extensive privileges beyond what is necessary for its operation. These excessive permissions, such as the ability to execute commands within pods and manage cluster-wid…
CWE: CWE-250
NVD

HIGH
CVE-2026-20349
CVE-2026-20349
pkg: cisco adaptive_security_appliance_software, cisco secure_firewall_threat_defense

published: Aug 11, 2026

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of servi…
CWE: CWE-244
GitHub-GHSA

HIGH
Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoS
GHSA-p28v-f755-9qrg
pkg: @trigger.dev/core
eco: npm
published: Aug 13, 2026
## Summary

The run-metadata update endpoint `PUT /api/v1/runs/:runId/metadata` applies client-supplied
"operations" by passing the **attacker-controlled `operation.key`** straight into
`new JSONHeroPath(operation.key).set(newMetadata, value)`
(`packages/core/src/v3/runMetadata/operations.ts:22-23`)…

CVE-2026-73654
NVD

HIGH
CVE-2026-73079
CVE-2026-73079
pkg: oauth

published: Aug 11, 2026

Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product subscriptions. From 0.1.135, to 0.1.168, platform API keys issued to tenants are exchanged for upstream requests made with shared provider accounts (ChatGPT/Codex OAuth, OpenAI platform keys, or an ope…
CWE: CWE-22, CWE-441
GitHub-GHSA

HIGH
Token Optimizer MCP: OS command injection in smart_user via username in get-user-info
GHSA-49mq-fc6q-3h46
pkg: @ooples/token-optimizer-mcp
eco: npm
published: Aug 14, 2026
### Summary

`token-optimizer-mcp` is vulnerable to OS command injection in the `smart_user` tool.

The `get-user-info` operation accepts a user-controlled `username` argument and later interpolates it into a shell command executed through `execAsync()`:

“`ts
getent passwd "${username}" || grep "^…

CVE-2026-55157
NVD

HIGH
CVE-2026-56865
CVE-2026-56865
pkg: go

published: Aug 13, 2026

A malicious GOPROXY was previously capable of forging up to two sumdb tiles that allow for a requested module to bypass the GOSUMDB check and persist attacker-controlled module content to a local Go module cache. This attack allows for a malicious GOPROXY to serve malicious module content that canno…
CWE: CWE-347
GitHub-GHSA

HIGH
MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`
GHSA-49m4-vp58-wgc9
pkg: stata-mcp
eco: pip
published: Aug 12, 2026
## Stata Command Injection via Unsanitized `package` in `ado_package_install`

### Summary

The `ado_package_install` MCP tool in `stata-mcp` concatenates user-controlled input directly into a Stata command string without any validation or sanitization. An attacker who can invoke the MCP tool or the…

CVE-2026-55071
NVD

HIGH
CVE-2026-67180
CVE-2026-67180
pkg: go

published: Aug 11, 2026

Google Turbinia allows arbitrary command execution via worker tasks. An attacker with privileges to submit a processing request or influence an evidence path/name obtains code execution on the worker fleet. Fixed on 2026-07-10.
CWE: CWE-78
NVD

HIGH
CVE-2026-8718
CVE-2026-8718
pkg: tls

published: Aug 10, 2026

tls_opt_dtls_peer_connection_id_value_get() in subsys/net/lib/sockets/sockets_tls.c, which handles getsockopt(SOL_TLS, TLS_DTLS_PEER_CID_VALUE), passed the caller-supplied optval directly to mbedtls_ssl_get_peer_cid() without verifying the buffer was at least MBEDTLS_SSL_CID_OUT_LEN_MAX (default 32)…
CWE: CWE-787
NVD

HIGH
CVE-2026-68371
CVE-2026-68371
pkg: node

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

usb: musb: omap2430: Do not put borrowed of_node in probe

omap2430_probe() stores pdev->dev.of_node in a local np variable. This is
a borrowed pointer and the probe function does not take a reference to
it.

The success and error …

NVD

HIGH
CVE-2026-19557
CVE-2026-19557
pkg: go

published: Aug 11, 2026

Use after free in TabStrip in Google Chrome on Mac prior to 151.0.7922.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-69119
CVE-2026-69119
pkg: oauth

published: Aug 11, 2026

Taubyte Tau v1.1.10 contains a missing authorization vulnerability in the services/auth HTTP service that allows any authenticated user to read or permanently delete another tenant's project by supplying an arbitrary project ID to the GET and DELETE /projects/{id} endpoints. The GitHubTokenHTTPAuth …
CWE: CWE-639
NVD

HIGH
CVE-2026-56179
CVE-2026-56179
pkg: microsoft windows_11_24h2, microsoft windows_11_25h2, microsoft windows_11_26h1

published: Aug 11, 2026

Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.
CWE: CWE-346
GitHub-GHSA

HIGH
Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket
GHSA-2j9v-p4xj-cjw2
pkg: github.com/lima-vm/lima/v2
eco: go
published: Aug 14, 2026
### Impact
On an instance of Lima running with `qemu` driver, an arbitrary user in the VM could access `/run/lima-guestagent.sock` when the guest agent is enabled.

This could result in running an arbitrary command with the root privileges in the VM (**not on the host**), as `lima-guestagent.sock` p…

CVE-2026-53657
NVD

HIGH
CVE-2026-73666
CVE-2026-73666
pkg: kubernetes

published: Aug 13, 2026

OpenChoreo is a developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.1, the OpenChoreo Backstage backend hardcoded backend.auth.dangerouslyDisableDefaultAuthPolicy and auth.providers.guest.dangerouslyAllowOutsideDevelopment to true, exposing /api/* without authentication and allowing un…
CWE: CWE-306
NVD

HIGH
CVE-2026-13048
CVE-2026-13048
pkg: express

published: Aug 13, 2026

Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the language attribute into the catalog filename.

load_lexicon builds the catalog path by appending `Messages/$lang.po` to the directory …

CWE: CWE-22, CWE-95
NVD

HIGH
CVE-2026-68118
CVE-2026-68118
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

tcp: challenge ACK for non-exact RST in SYN-RECEIVED

The SYN-RECEIVED request-socket path in tcp_check_req() accepts an
in-window RST without requiring SEG.SEQ to exactly match RCV.NXT. A
non-exact RST therefore removes the reque…

NVD

HIGH
CVE-2026-72665
CVE-2026-72665
pkg: go

published: Aug 13, 2026

Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who is able to author and evaluate Elastic Security detection rules can c…
CWE: CWE-862
NVD

HIGH
CVE-2026-55987
CVE-2026-55987
pkg: react

published: Aug 13, 2026

OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)
CWE: CWE-863
NVD

HIGH
CVE-2026-73289
CVE-2026-73289
pkg: jwt

published: Aug 12, 2026

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS evaluates the ForAllValues: and ForAnyValue: set qualifiers with the negated string operators StringNotEquals, StringNotEqualsIgnoreCase, StringNotLike, ArnNotEquals, and ArnNotLike using each other's semanti…
CWE: CWE-863
NVD

HIGH
CVE-2026-73286
CVE-2026-73286
pkg: jwt

published: Aug 12, 2026

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS get_condition_values folds attacker-controlled request headers from HeaderMap into server-derived userid, username, principaltype, groups, versionid, signatureversion, jwt:, and ldap: condition keys, allowing…
CWE: CWE-863
NVD

HIGH
CVE-2026-19594
CVE-2026-19594
pkg: python

published: Aug 12, 2026

Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-deputy privilege escalation through two related weaknesses: path traversal (CWE-22) via unencoded `..` identifier path segments, and HTTP parameter pollution (CWE-141) via unencoded `…
CWE: CWE-22, CWE-141
NVD

HIGH
CVE-2026-18961
CVE-2026-18961
pkg: oauth

published: Aug 12, 2026

The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnerable to Authentication Bypass via Unverified Provider Email in all versions up to, and including, 1.4.3. This is due to the plugin trusting the unverified email field returned by …
CWE: CWE-287
NVD

HIGH
CVE-2026-72921
CVE-2026-72921
pkg: jwt

published: Aug 11, 2026

SeaweedFS is a distributed storage system. Prior to 4.24, the weed/server/filer_server_handlers.go allowed_prefixes authorization check used strings.HasPrefix on raw path strings, so a filer JWT scoped to /tenant1 also authorized sibling paths such as /tenant1234, /tenant1-old, and /tenant1backup, e…
CWE: CWE-863
NVD

HIGH
CVE-2026-72903
CVE-2026-72903
pkg: windows

published: Aug 10, 2026

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.235, a malicious SFTP server can return a backslash traversal filename through entry.name. In tabby-ssh/src/session/sftp.ts, SFTPSession.readdir() and _makeFile() use POSIX path processing that preserves the backslash…
CWE: CWE-22
NVD

HIGH
CVE-2026-68100
CVE-2026-68100
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl

set_ntacl_dacl() copies each ACE from the attacker-controlled stored
security descriptor verbatim into the response DACL without checking
sid.num_subauth. The ACE byte…

NVD

HIGH
CVE-2026-70454
CVE-2026-70454
pkg: tls

published: Aug 13, 2026

rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation vulnerability that allows on-path attackers to intercept encrypted sessions by presenting self-signed or otherwise invalid certificates. Attackers can exploit the failure to valid…
CWE: CWE-295
NVD

HIGH
CVE-2026-65937
CVE-2026-65937
pkg: go

published: Aug 12, 2026

In WhatsUp Gold versions released before 2026.0.2, an authenticated attacker can bypass frontend controls and inject persistent script content.
CWE: CWE-79
NVD

HIGH
CVE-2026-68085
CVE-2026-68085
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled

HCI_UART_SENDING bit in tx_state means write_work is pending and blocks
queueing it again. Currently this bit is not cleared when canceling the
work in hci_u…

NVD

HIGH
CVE-2026-6726
CVE-2026-6726
pkg: tls

published: Aug 11, 2026

An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and falsify other TPM 2.…
CWE: CWE-704
NVD

HIGH
CVE-2026-68116
CVE-2026-68116
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

vxlan: mdb: Fix source list corruption on a failed replace

When replacing the source list of an MDB remote entry, all existing
sources are first marked for deletion and vxlan_mdb_remote_srcs_add()
is then called to add the new sou…

NVD

HIGH
CVE-2026-74270
CVE-2026-74270
pkg: tls

published: Aug 15, 2026

In the Linux kernel, the following vulnerability has been resolved:

handshake: Require admin permission for DONE command

ACCEPT and DONE are the two downcalls of the handshake genl
family, both intended for use by the trusted handshake agent
(tlshd). ACCEPT already requires GENL_ADMIN_PERM; DONE h…

NVD

HIGH
CVE-2026-73505
CVE-2026-73505
pkg: express

published: Aug 13, 2026

Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, the setStyle() function in src/segments/path.go passed pt.Path, which includes raw folder names, to template.Render, whose function map exposes cmd, so an attacker-controlled directory name co…
CWE: CWE-94, CWE-1336
NVD

HIGH
CVE-2026-73325
CVE-2026-73325
pkg: python

published: Aug 12, 2026

Fujitsu Research's OneCompression library 1.2.0 contains an unsafe deserialization vulnerability that allows attackers to execute arbitrary code by supplying a crafted model.pt checkpoint file, as QuantizedModelLoader.load_quantized_model_pt() unconditionally calls torch.load with weights_only=False…
CWE: CWE-502
NVD

HIGH
CVE-2026-73231
CVE-2026-73231
pkg: node

published: Aug 11, 2026

Faker generates massive amounts of fake data in the browser and Node.js. Prior to 10.5.0, the faker.helpers.fake method in src/modules/helpers/eval.ts allows attacker-controlled fake templates to access the Function constructor through fakeEval.resolveProperty when a function returns another functio…
CWE: CWE-95
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-62871 – .NET Elevation of Privilege Vulnerability
GHSA-vg44-h755-9hw7
pkg: Microsoft.WindowsDesktop.App.Runtime.win-arm64, Microsoft.WindowsDesktop.App.Runtime.win-x64, Microsoft.WindowsDesktop.App.Runtime.win-x86
eco: nuget
published: Aug 11, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in Windows Presentation Foundation. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

Out-of-bounds write in .NET …

CVE-2026-62871
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-70354 – .NET Core Remote Code Execution Vulnerability
GHSA-gg8c-3338-xw2f
pkg: Microsoft.WindowsDesktop.App.Runtime.win-arm64, Microsoft.WindowsDesktop.App.Runtime.win-x64, Microsoft.WindowsDesktop.App.Runtime.win-x86
eco: nuget
published: Aug 11, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in Windows Presentation Foundation. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

An out-of-bounds write in .N…

CVE-2026-70354
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-62886 – .NET Elevation of Privilege Vulnerability
GHSA-jqhp-238x-qhgf
pkg: Microsoft.WindowsDesktop.App.Runtime.win-arm64, Microsoft.WindowsDesktop.App.Runtime.win-x64, Microsoft.WindowsDesktop.App.Runtime.win-x86
eco: nuget
published: Aug 11, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in Windows Presentation Foundation. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

An integer overflow or wrapa…

CVE-2026-62886
NVD

HIGH
CVE-2026-61359
CVE-2026-61359
pkg: microsoft windows_11_23h2, microsoft windows_11_24h2, microsoft windows_11_25h2

published: Aug 11, 2026

Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.
CWE: CWE-122
NVD

HIGH
CVE-2026-61358
CVE-2026-61358
pkg: microsoft windows_10_1809, microsoft windows_10_21h2, microsoft windows_10_22h2

published: Aug 11, 2026

Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.
CWE: CWE-59
NVD

HIGH
CVE-2026-61356
CVE-2026-61356
pkg: microsoft windows_10_1809, microsoft windows_10_21h2, microsoft windows_10_22h2

published: Aug 11, 2026

Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
CWE: CWE-306
NVD

HIGH
CVE-2026-61355
CVE-2026-61355
pkg: microsoft windows_10_21h2, microsoft windows_10_22h2, microsoft windows_11_23h2

published: Aug 11, 2026

Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
CWE: CWE-122
NVD

HIGH
CVE-2026-61353
CVE-2026-61353
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CWE: CWE-122
NVD

HIGH
CVE-2026-61349
CVE-2026-61349
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.
CWE: CWE-362, CWE-416
NVD

HIGH
CVE-2026-59127
CVE-2026-59127
pkg: windows

published: Aug 11, 2026

Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally.
CWE: CWE-190
NVD

HIGH
CVE-2026-56174
CVE-2026-56174
pkg: microsoft windows_10_1809, microsoft windows_10_21h2, microsoft windows_10_22h2

published: Aug 11, 2026

Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.
CWE: CWE-426
NVD

HIGH
CVE-2026-54984
CVE-2026-54984
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.
CWE: CWE-122
NVD

HIGH
CVE-2026-54981
CVE-2026-54981
pkg: python

published: Aug 11, 2026

Inclusion of functionality from untrusted control sphere in Visual Studio Code – Python extension allows an unauthorized attacker to bypass a security feature locally.
CWE: CWE-693, CWE-829
NVD

HIGH
CVE-2026-42976
CVE-2026-42976
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally.
CWE: CWE-306
NVD

HIGH
CVE-2026-72693
CVE-2026-72693
pkg: node

published: Aug 11, 2026

`openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged context. In the documented `kbrequest`/init usage, the ownership test in `authenticate_user()` relies on `stat("/proc/<pid>/fd/0")`. `stat()` on `/proc/<pid>/fd/0` follows the syml…
CWE: CWE-284
NVD

HIGH
CVE-2026-68222
CVE-2026-68222
pkg: go

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

media: msi2500: Return queued buffers on start_streaming() failure

The vb2 framework hands buffers to the driver via buf_queue() before
calling start_streaming(). If start_streaming() returns an error
without first returning thos…

NVD

HIGH
CVE-2026-68121
CVE-2026-68121
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

pppoe: reload header pointer after dev_hard_header()

pppoe_sendmsg() saves a pointer to the PPPoE header before calling
dev_hard_header(). Device header callbacks are allowed to reallocate the
skb head, invalidating pointers into …

NVD

HIGH
CVE-2026-68106
CVE-2026-68106
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: fix division by zero with invalid uvd dimensions

When width or height is less than 16, width_in_mb or height_in_mb
becomes 0, leading to fs_in_mb being 0. This causes a division by
zero when calculating num_dpb_buffer …

NVD

HIGH
CVE-2026-68104
CVE-2026-68104
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: invoke pm_genpd_remove() before freeing genpd

Call pm_genpd_remove() to unregister from global list prior to releasing
acp_genpd memory, and clear the pointer after free.

(cherry picked from commit cd8650d7a91ee8b768e…

NVD

HIGH
CVE-2026-48767
CVE-2026-48767
pkg: oauth

published: Aug 11, 2026

TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege guest member of a workspace to obtain a live Google Sheets OAuth access token for that workspace by calling the Google Sheets helper `getAccessToken`. The vulnerable path checks only whether the caller has read access …
CWE: CWE-200
NVD

HIGH
CVE-2026-18621
CVE-2026-18621
pkg: node

published: Aug 10, 2026

A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security hardening by submitting a malicious Argo Workflow through the V1 API path. This allows the API server to create pods with elevated privileges, acting as a 'confused deputy' on behalf of…
CWE: CWE-266
NVD

HIGH
CVE-2026-74795
CVE-2026-74795
pkg: express

published: Aug 16, 2026

Scriban before 6.6.0 contains an uncontrolled recursion vulnerability in its recursive-descent parser. The parser does not enforce a default expression depth limit (the ExpressionDepthLimit property in ParserOptions defaults to null/disabled), so an attacker who controls template input can supply a …
CWE: CWE-674
NVD

HIGH
CVE-2026-74792
CVE-2026-74792
pkg: express

published: Aug 16, 2026

Scriban before 7.0.0 (affected versions <= 6.6.0) contains a stack overflow vulnerability in nested array initializer parsing. Deeply nested array initializers recurse through a path (ParseArrayInitializer → ParseExpression → ParseArrayInitializer) that is not covered by the ExpressionDepthLimit…
CWE: CWE-674
NVD

HIGH
CVE-2026-74789
CVE-2026-74789
pkg: express

published: Aug 16, 2026

Scriban before 7.0.0 (affected <= 6.6.0) applies its LoopLimit constraint only to script loop statements and not to expensive iteration performed inside built-in operators and functions. As a result, a single expression such as {{ 1..1000000 | array.size }} — or a memory-amplification expression s…
CWE: CWE-400
NVD

HIGH
CVE-2026-74783
CVE-2026-74783
pkg: express

published: Aug 16, 2026

Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimit guard that fails to stop recursive descent parsing of deeply nested expressions. Attackers can supply templates with deeply nested parentheses, array initializers, object initializers, or unary operators to trigger an …
CWE: CWE-674
NVD

HIGH
CVE-2026-72330
CVE-2026-72330
pkg: tls

published: Aug 15, 2026

In the Linux kernel, the following vulnerability has been resolved:

net/tls: Consume empty data records in tls_sw_read_sock()

A peer may send a zero-length TLS application_data record; TLS 1.3
explicitly permits these as a traffic-analysis countermeasure (RFC
8446, Section 5.1). After decryption s…

NVD

HIGH
CVE-2026-72254
CVE-2026-72254
pkg: express

published: Aug 15, 2026

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nft_fib: reject fib expression on the netdev egress hook

A fib expression in a netdev egress base chain dereferences nft_in(pkt),
NULL on the transmit path, causing a NULL pointer dereference at eval.
nft_fib_validate()…

NVD

HIGH
CVE-2026-56864
CVE-2026-56864
pkg: go

published: Aug 13, 2026

A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. This attack allows for a coordinating GOPROXY and GOSUMDB to serve a client malicious module content that cannot be detected by evaluating the transparency log. In order to determine if you…
CWE: CWE-347
GitHub-GHSA

HIGH
nltk: Arbitrary File Read via Path Traversal in nltk.data.load() through Percent-Encoded Sequences
GHSA-m42h-3232-vpv3
pkg: nltk
eco: pip
published: Aug 13, 2026
# Summary
nltk.data.load() and nltk.data.find() resolve user-supplied resource names to filesystem paths using url2pathname(), which decodes percent-encoded sequences (e.g. %2e%2e to ..). Path safety checks are performed on the raw, still-encoded string before decoding occurs. An attacker supplying …
CVE-2026-12243
NVD

HIGH
CVE-2026-73568
CVE-2026-73568
pkg: python

published: Aug 13, 2026

py-libp2p is the Python implementation of the libp2p networking stack. In 0.7.0 and earlier, the yamux handle_incoming() method in libp2p/stream_muxer/yamux/yamux.py reads an attacker-controlled 32-bit DATA frame length with read_exactly() before validating it against MAX_WINDOW_SIZE or checking whe…
CWE: CWE-400
NVD

HIGH
CVE-2024-58374
CVE-2024-58374
pkg: oauth

published: Aug 13, 2026

Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allows remote unauthenticated attackers to access protected resources by supplying a path traversal sequence in the request URI to bypass the oauthservlet authentication filter. Attackers …
CWE: CWE-89
NVD

HIGH
CVE-2026-14456
CVE-2026-14456
pkg: ssl

published: Aug 13, 2026

Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes
valid QUIC Initial packets for unknown destination connection IDs, it
can allocate and queue new incoming channels without enforcing any limit.

Impact summary: A remote peer that can make many Initial packets reach the
serve…

CWE: CWE-770
NVD

HIGH
CVE-2026-67991
CVE-2026-67991
pkg: express

published: Aug 13, 2026

crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in RubyLLM::Utils.underscore on Ruby 3.1.x. A very long crafted class, agent, or tool name can cause excessive CPU consumption and a denial of service.
CWE: CWE-1333
NVD

HIGH
CVE-2026-48702
CVE-2026-48702
pkg: go

published: Aug 13, 2026

Rekor is a software supply chain transparency log. Starting in version 0.3.0 and prior to version 1.5.2, the `Package.Unmarshal()` function in `pkg/types/alpine/apk.go` decompresses the signature and control gzip members of an APK file into in-memory buffers without bounding the total decompressed s…
CWE: CWE-770
NVD

HIGH
CVE-2026-19484
CVE-2026-19484
pkg: node

published: Aug 13, 2026

@fastify/busboy is a multipart form-data parser. In versions 3.1.0 through 3.2.0, a remote unauthenticated attacker can stall the Node.js event loop by sending a multipart request whose boundary is crafted to a specific length. The vendored streaming search stores its skip table in a fixed 256 entry…
CWE: CWE-835, CWE-1322
NVD

HIGH
CVE-2026-19481
CVE-2026-19481
pkg: node

published: Aug 13, 2026

@fastify/busboy is a multipart form-data parser. In versions 1.0.0 through 3.2.0, an attacker who can submit multipart form-data can crash the parser by sending a part header whose name is a prototype-inherited property such as __proto__ or constructor. The internal header parser stores headers in a…
CWE: CWE-754
GitHub-GHSA

HIGH
SIPSorcery: Malformed UDP datagram crashes TurnServer receive loop with no restart, disabling TURN UDP relay for all clients (DoS)
GHSA-pfvm-w89x-94jw
pkg: SIPSorcery
eco: nuget
published: Aug 12, 2026
## Summary
`TurnServer.ReceiveUdpAsync` places its generic `catch (Exception)` OUTSIDE the `while` receive loop, and `Start()` launches the loop fire-and-forget with no supervision or restart. A single pre-authentication UDP datagram whose STUN header first byte is in `0x80–0xFF` causes `STUNHeade…
GitHub-GHSA

HIGH
SIPSorcery vulnerable to Denial of Service via out-of-bounds read in SCTP SACK chunk parsing
GHSA-jwjp-4649-v8jp
pkg: SIPSorcery
eco: nuget
published: Aug 12, 2026
## Summary
`SctpSackChunk.ParseChunk` reads the `numGapAckBlocks` and `numDuplicateTSNs` fields (each up to 65535) directly from an attacker-controlled SCTP SACK chunk and loops that many times reading 4 bytes per iteration, with no validation of the counts against the chunk length or the receive bu…
GitHub-GHSA

HIGH
nimiq-blockchain: Validity store off by one error
GHSA-3763-qp59-59vf
pkg: nimiq-blockchain
eco: rust
published: Aug 12, 2026
### Impact
The validity store treats a transaction with stored `block_number = X` as "in window" only when `X > last_bn – transaction_validity_window_blocks` (strict inequality). However the protocol's `Transaction::is_valid_at` accepts a transaction for inclusion in any block in `[validity_start_he…
CVE-2026-46369
NVD

HIGH
CVE-2026-19558
CVE-2026-19558
pkg: go

published: Aug 11, 2026

Use after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-73232
CVE-2026-73232
pkg: go

published: Aug 11, 2026

ffuf is a fast web fuzzer written in Go. Prior to 2.2.0, ffuf allows a malicious target server to cause an out-of-memory denial of service because the response size guard in pkg/runner/simple.go checks only the compressed Content-Length while io.ReadAll reads gzip, brotli, deflate, transparently dec…
CWE: CWE-409
NVD

HIGH
CVE-2026-48804
CVE-2026-48804
pkg: python

published: Aug 11, 2026

python-socketio is a Python implementation of the Socket.IO realtime client and server. The python-socketio server stores binary `EVENT` and `ACK` messages in memory while it waits to receive their binary attachments. Once all the attachments are received, these messages are then processed. Prior to…
CWE: CWE-770
NVD

HIGH
CVE-2026-48809
CVE-2026-48809
pkg: python

published: Aug 11, 2026

python-engineio is a Python implementation of the Engine.IO realtime client and server. Versions prior to 4.13.2 have two specific configurations of the python-engineio server in which the size of incoming messages is not checked before the messages are loaded into memory. An attacker can take advan…
CWE: CWE-770
NVD

HIGH
CVE-2026-48802
CVE-2026-48802
pkg: python

published: Aug 11, 2026

python-engineio is a Python implementation of the Engine.IO realtime client and server. Prior to version 4.13.2, an attacker can cause the creation of unnecessary background threads in the python-engineio server by exploiting the heartbeat mechanism, which launches a thread when a new connection is …
CWE: CWE-770
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-62901 – .NET Denial of Service Vulnerability
GHSA-m93f-wj8c-rp8p
pkg: Microsoft.NETCore.App.Runtime.win-arm64, Microsoft.NETCore.App.Runtime.win-x64, Microsoft.NETCore.App.Runtime.win-x86
eco: nuget
published: Aug 11, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in System.Net.WebSockets. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

An unchecked input for loop condition …

CVE-2026-62901
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-62898 – .NET Information Disclosure Vulnerability
GHSA-c494-m2fq-59mx
pkg: Microsoft.NETCore.App.Runtime.win-arm64, Microsoft.NETCore.App.Runtime.win-x64, Microsoft.NETCore.App.Runtime.win-x86
eco: nuget
published: Aug 11, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in Microsoft QUIC. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A use after free in Microsoft QUIC allows an …

CVE-2026-62898
NVD

HIGH
CVE-2026-72713
CVE-2026-72713
pkg: docker

published: Aug 11, 2026

XAgent contains a path traversal vulnerability in the workspace file endpoint that allows self-registered or default-credential users to read arbitrary files on the host by supplying parent-directory segments in the `file_name` form field with no path containment check. Attackers can register an acc…
CWE: CWE-22
NVD

HIGH
CVE-2026-73089
CVE-2026-73089
pkg: node

published: Aug 11, 2026

Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, index.js retains every distinct `(queries, context)` result in cache and every parseQueries() AST in parseCache without a size cap, TTL, or eviction, allowing an attacker w…
CWE: CWE-770
NVD

HIGH
CVE-2026-73088
CVE-2026-73088
pkg: node

published: Aug 11, 2026

Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, normalizeStats() in node.js, reached unconditionally through getStat() and loadStat() on every browserslist() call, processes untrusted browserslist-stats.json, opts.stats,…
CWE: CWE-248, CWE-1321
NVD

HIGH
CVE-2026-59132
CVE-2026-59132
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.
CWE: CWE-476
NVD

HIGH
CVE-2026-54113
CVE-2026-54113
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network.
CWE: CWE-770
NVD

HIGH
CVE-2026-72605
CVE-2026-72605
pkg: jwt

published: Aug 11, 2026

A missing authentication vulnerability in Swing Music 3.0.0 allows unauthenticated remote attackers to create arbitrary user accounts via the POST /auth/profile/create endpoint. The endpoint is allowlisted from JWT verification, permitting unauthenticated account creation. An attacker can register a…
CWE: CWE-306
NVD

HIGH
CVE-2026-68131
CVE-2026-68131
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

rbd: Reset positive result codes to zero in object map update path

In a reply message to an RBD request, a positive result code indicates
a data payload, which is not allowed for writes. While
rbd_osd_req_callback() already resets…

NVD

HIGH
CVE-2026-68129
CVE-2026-68129
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

gve: fix Rx queue stall on alloc failure

When the system is under extreme memory pressure, page allocations can
fail during the Rx buffer refill loop. If the number of buffers posted
to hardware falls below a critical low threshol…

NVD

HIGH
CVE-2026-68120
CVE-2026-68120
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

rtase: Workaround for TX hang caused by hardware packet parsing

The hardware performs packet parsing before packet transmission.
Parsing incomplete IPv4, IPv6, TCP, or UDP headers may trigger a TX
hang because the hardware parser …

NVD

HIGH
CVE-2026-68119
CVE-2026-68119
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

tcp: initialize standalone TCP-AO response padding

tcp_v4_send_ack() and tcp_v6_send_response() construct standalone TCP
responses with TCP-AO options. The option length carries the actual MAC
length, but the TCP header length in…

NVD

HIGH
CVE-2026-68096
CVE-2026-68096
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

audit: fix recursive locking deadlock in audit_dupe_exe()

A deadlock occurs in the audit subsystem when duplicating
executable-related rules.

When a file is moved (e.g., via do_renameat2()), the VFS layer locks
the parent directo…

NVD

HIGH
CVE-2026-65942
CVE-2026-65942
pkg: tls

published: Aug 10, 2026

TLS hostname verification issue in Apache Ranger Client Code in versions <= 2.8.0.
Users are recommended to upgrade to version 2.9.0, which fixes this issue.
CWE: CWE-297
NVD

HIGH
CVE-2026-73655
CVE-2026-73655
pkg: go

published: Aug 13, 2026

Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.2, addGoogleStrategy() in apps/webapp/app/services/googleAuth.server.ts passes a Google profile email to findOrCreateGoogleUser() in apps/webapp/app/models/user.server.ts without requiring Google…
CWE: CWE-287
NVD

HIGH
CVE-2026-15554
CVE-2026-15554
pkg: ssl

published: Aug 11, 2026

the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authentication. This enables an unauthenticated attacker with direct TCP access to port 8009 to bypass CLIENT-CERT authentication by injecting a forged X.509 certificate via the AJP protoc…
CWE: CWE-295
NVD

HIGH
CVE-2026-18511
CVE-2026-18511
pkg: tls

published: Aug 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to generate a stack-based buffer overflow in the Native IBM i JSSE provider, caused by improper bounds checking during TLS session establishment. A local attacker could overflow a fixed-length buffer and execute arbitrary code o…
CWE: CWE-787
NVD

HIGH
CVE-2026-74564
CVE-2026-74564
pkg: express

published: Aug 15, 2026

In the Linux kernel, the following vulnerability has been resolved:

netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH

The XT_HASHLIMIT_RATE_MATCH flag mode changes the semantics of the
dsthash_ent structure which represents an entry in the hashtable. There
is a union ar…

GitHub-GHSA

HIGH
mchange-commons-java contains elements susceptible to abuse via JNDI injection and "deserialization gadgets"
GHSA-h84g-69h7-mw6v
pkg: com.mchange:mchange-commons-java
eco: maven
published: Aug 14, 2026
### Impact
Prior to version 0.6.0, mchange-commons-java includes a JNDI `ObjectFactory` implementation (`com.mchange.v2.naming.JavaBeanObjectFactory`) willing to construct objects of arbitrary classes and initialize "JavaBean"-style properties. There are classes for which this kind of initialization…
CVE-2026-55153
NVD

HIGH
CVE-2026-72632
CVE-2026-72632
pkg: express

published: Aug 13, 2026

Observable Discrepancy (CWE-203) in Kibana Fleet can lead to information disclosure via Excavation (CAPEC-116). Fleet removes the Elasticsearch API key value of an enrolled Elastic Agent from the responses of its agent listing capability, but that capability accepted caller-supplied filter expressio…
CWE: CWE-203
GitHub-GHSA

HIGH
SSH.NET: ScpClient Recursive Download Allows Arbitrary File Write via Server-Controlled SCP Filenames
GHSA-q939-rpr3-3284
pkg: SSH.NET
eco: nuget
published: Aug 12, 2026
## Summary

`ScpClient.Download(string directoryName, DirectoryInfo directoryInfo)` writes files and directories using names returned by the remote SCP server during recursive downloads, with no validation that the resulting path stays inside the requested local directory. A malicious, compromised, …

CVE-2026-48798
NVD

HIGH
CVE-2026-73291
CVE-2026-73291
pkg: node

published: Aug 12, 2026

Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.4.0, Seerr's ImageProxy in server/lib/imageproxy.ts uses the upstream ETag and Content-Type response headers to build a cache filename for the unauthenticated GET /avatarproxy/:jellyfinUserId…
CWE: CWE-22, CWE-94
NVD

HIGH
CVE-2026-63177
CVE-2026-63177
pkg: nginx

published: Aug 11, 2026

Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access control enforced in the Nginx OpenResty Lua layer evaluates the raw, unnormalized `ngx.var.request_uri`, while Nginx itself routes requests using the normalized path. An authenticated low-privilege user can…
CWE: CWE-863
NVD

HIGH
CVE-2026-48495
CVE-2026-48495
pkg: oauth

published: Aug 11, 2026

TypeBot is a chatbot builder tool. Prior to version 3.17.0, the Google Sheets OAuth callback decodes a base64-encoded JSON `state` parameter and trusts the embedded `workspaceId`, `typebotId`, `blockId`, and `redirectUrl` without cryptographic integrity protection or authorization checks. The callba…
CWE: CWE-862
NVD

HIGH
CVE-2026-42142
CVE-2026-42142
pkg: oauth

published: Aug 11, 2026

TypeBot is a chatbot builder tool. Prior to version 3.17.0, the `handleGetSheets` API handler (`POST /api/sheets/getSheets`) does not validate workspace membership, allowing any authenticated user to access and decrypt another workspace's Google Sheets OAuth credentials and retrieve spreadsheet data…
CWE: CWE-862
NVD

HIGH
CVE-2026-68103
CVE-2026-68103
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: reject mapping a reserved doorbell to a new queue

When creating an user-queue, the user space
provides a doorbell BO handle and an offset within
the bo to obtain a doorbell.

However current implementation using xa_sto…

NVD

HIGH
CVE-2026-53996
CVE-2026-53996
pkg: node

published: Aug 12, 2026

NetBSD's hdaudio(4) driver in sys/dev/hdaudio/hdaudio.c contains a missing access control vulnerability that allows unprivileged local attackers to invoke the HDAUDIO_FGRP_SETCONFIG ioctl without elevated permissions by exploiting the absence of an access check on /dev/hdaudioN device nodes. Attacke…
CWE: CWE-862
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-62897 – .NET Remote Code Execution Vulnerability
GHSA-fx4q-gjrx-2jw6
pkg: Microsoft.WindowsDesktop.App.Runtime.win-arm64, Microsoft.WindowsDesktop.App.Runtime.win-x64, Microsoft.WindowsDesktop.App.Runtime.win-x86
eco: nuget
published: Aug 11, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in Windows Presentation Foundation. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

An integer overflow or wrapa…

CVE-2026-62897
NVD

HIGH
CVE-2026-61361
CVE-2026-61361
pkg: microsoft windows_11_24h2, microsoft windows_11_25h2, microsoft windows_11_26h1

published: Aug 11, 2026

Use after free in Windows DHCP Client allows an authorized attacker to execute code locally.
CWE: CWE-416
NVD

HIGH
CVE-2026-61348
CVE-2026-61348
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CWE: CWE-416
NVD

HIGH
CVE-2026-61346
CVE-2026-61346
pkg: microsoft windows_10_1809, microsoft windows_10_21h2, microsoft windows_10_22h2

published: Aug 11, 2026

Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.
CWE: CWE-416
NVD

HIGH
CVE-2026-59126
CVE-2026-59126
pkg: microsoft windows_10_21h2, microsoft windows_10_22h2, microsoft windows_11_23h2

published: Aug 11, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.
CWE: CWE-362
NVD

HIGH
CVE-2026-59122
CVE-2026-59122
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CWE: CWE-362, CWE-416
NVD

HIGH
CVE-2026-50472
CVE-2026-50472
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.
CWE: CWE-122
GitHub-GHSA

HIGH
OpenAM Insecure SSO Cookie Initialization
GHSA-fpmh-vx4h-xc33
pkg: org.openidentityplatform.openam:openam-core
eco: maven
published: Aug 14, 2026
## Summary

**Description**
An Insecure Default Initialization of Resource (CWE-1188) issue in the OpenAM default configuration ships the `iPlanetDirectoryPro` SSO cookie with `HttpOnly=false`. Also, the `iPlanetDirectoryPro` SSO cookie is used as a CSRF token in OAuth/OIDC flows. This affects OpenA…

CVE-2026-53660
GitHub-GHSA

HIGH
Budibase: SSRF in Automation Steps – Webhook, Zapier, N8N, Slack, Discord Bypass IP Blacklist
GHSA-5fpj-28rv-84r7
pkg: @budibase/server
eco: npm
published: Aug 14, 2026
## Summary

Budibase automation steps (outgoing webhook, Zapier, n8n, Slack, Discord, Make.com) make server-side HTTP requests to user-provided URLs using `node-fetch` directly, completely bypassing the IP blacklist protection that exists in the REST API integration. Additionally, the REST API black…

CVE-2026-35219
GitHub-GHSA

HIGH
Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts
GHSA-29rf-f4vv-pvq6
pkg: github.com/authorizerdev/authorizer
eco: go
published: Aug 14, 2026
The OAuth callback handler links incoming OAuth identities (Google, GitHub, etc.) to existing accounts matched by email address without verifying that the existing account's email was verified by its original owner. An attacker who pre-registers with a victim's email address (without verifying it) g…
CVE-2026-35511
GitHub-GHSA

HIGH
atomic-agents-stack: Dashboard HTTP server path traversal allows arbitrary file read
GHSA-rm43-82j9-r4mj
pkg: atomic-agents-stack
eco: pip
published: Aug 13, 2026
The optional dashboard HTTP server (`atomic_agents/dashboard/serve.py`) builds filesystem paths directly from the request path and serves them without a containment check. It is the only per-request untrusted-path site in the codebase that does not route through `_io.safe_resolve_under`. Literal `..…
GitHub-GHSA

HIGH
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)
GHSA-48p8-g2fx-3wwm
pkg: github.com/argoproj/argo-workflows/v4, github.com/argoproj/argo-workflows/v3, github.com/argoproj/argo-workflows
eco: go
published: Aug 13, 2026
### Summary

The allow-list fix for CVE-2026-31892 (GHSA-3wf5-g532-rcrr), and its follow-up coverage of `hostNetwork`/`securityContext`/`serviceAccountName` in GHSA-3775-99mw-8rp4, is incomplete. `workflow/util/merge.go` `ValidateUserOverrides` / `SanitizeUserWorkflowSpec` walk only the top-level fi…

CVE-2026-54526
GitHub-GHSA

HIGH
Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv)
GHSA-cxgv-hp74-jj7r
pkg: ansible-jailexec
eco: pip
published: Aug 12, 2026
Through version 1.3.0, the jailexec connection plugin's put_file resolved a transfer's destination to a path on the jail host (<jail filesystem root> + <destination>) and ran mkdir -p and mv there as root on the host. Those commands follow symbolic links, and the path was operated on outside the jai…
CVE-2026-55074
GitHub-GHSA

HIGH
SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access
GHSA-w62w-66v9-vvgv
pkg: github.com/seaweedfs/seaweedfs
eco: go
published: Aug 12, 2026
## Summary

The S3 API gateway and the Iceberg REST catalog gateway construct their routers with `mux.NewRouter().SkipClean(true)`. With path cleaning disabled, a `..` segment inside the URL survives routing, so a request such as:

“`
GET /bucket-A/../evil-bucket/key
“`

is matched as `bucket=buck…

CVE-2026-54917
GitHub-GHSA

HIGH
compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0
GHSA-h47f-gmjp-m7rr
pkg: compliance-trestle
eco: pip
published: Aug 12, 2026
### Summary

`compliance-trestle` 4.0.3 (latest) ships an `URLSecurityValidator` in `trestle/core/remote/security.py` to block SSRF to loopback / link-local / cloud-metadata endpoints from the HTTPSFetcher and SFTPFetcher remote-fetch paths. The allowlist is incomplete and can be bypassed by four eq…

CVE-2026-52776
GitHub-GHSA

MEDIUM
Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials
GHSA-h7p7-w5gc-xj3w
pkg: pydantic-ai-slim, pydantic-ai-slim, pydantic-ai
eco: pip
published: Aug 13, 2026
### Summary

A client that can submit message history to a Pydantic AI UI adapter can reference arbitrary files in the application's model-provider or cloud-storage account. The server forwards the reference to the model provider, which fetches it using the server's own credentials, allowing the cli…

CVE-2026-54249
GitHub-GHSA

MEDIUM
ep_etherpad-lite: Device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author token
GHSA-vqfp-p66c-xrp9
pkg: ep_etherpad-lite
eco: npm
published: Aug 13, 2026
Etherpad's device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author token in the GET response body

## Description

Etherpad ships an endpoint pair under `/tokenTransfer` (`src/node/hooks/express/tokenTransfer.ts`) that lets a logged-in user move…

CVE-2026-55088
NVD

MEDIUM
CVE-2026-73611
CVE-2026-73611
pkg: jwt

published: Aug 13, 2026

File Browser versions from 2.50.0 through 2.63.21 fail to validate JWT expiration when proxy authentication is configured with a non-default logout page. Attackers with a previously valid token can access protected routes and administrative endpoints indefinitely, and exchange expired tokens for fre…
CWE: CWE-613
NVD

MEDIUM
CVE-2026-73419
CVE-2026-73419
pkg: oauth

published: Aug 12, 2026

NextAuth.js provides authentication for Next.js. Prior to@auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, Auth.js stores the OAuth/OIDC anti-CSRF checks state, nonce, and the PKCE verifier in global cookies that are not bound to the provider that created them. On callback, a check value mi…
CWE: CWE-345, CWE-346, CWE-940
NVD

MEDIUM
CVE-2026-65940
CVE-2026-65940
pkg: go

published: Aug 12, 2026

In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible location on the host server.
CWE: CWE-276, CWE-732
NVD

MEDIUM
CVE-2026-65939
CVE-2026-65939
pkg: go

published: Aug 12, 2026

In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root.
CWE: CWE-22, CWE-73, CWE-434
NVD

MEDIUM
CVE-2026-49349
CVE-2026-49349
pkg: docker

published: Aug 12, 2026

regclient is a Docker and OCI Registry Client in Go. Prior to version 0.11.5, credentials for a registry may be inadvertently leaked to external servers. A prerequisite for this attack is a malicious registry server, a malicious blob store, or a registry that does not restrict the external URLs for …
CWE: CWE-522
NVD

MEDIUM
CVE-2026-19278
CVE-2026-19278
pkg: express

published: Aug 10, 2026

A flaw was found in StackRox/RHACS Central's Auth Machine-to-Machine (M2M) token exchange. When an administrator configures M2M role mappings, the system uses unanchored regular expressions for matching claim values. This allows an attacker with a valid OpenID Connect (OIDC) token, whose claim value…
CWE: CWE-625
NVD

MEDIUM
CVE-2026-66016
CVE-2026-66016
pkg: tls

published: Aug 12, 2026

Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessible to highly privileged local users.
CWE: CWE-312
GitHub-GHSA

MEDIUM
Microsoft Security Advisory CVE-2026-62909 – .NET Elevation of Privilege Vulnerability
GHSA-9mr8-pwpw-3j2w
pkg: Microsoft.NETCore.App.Runtime.linux-arm, Microsoft.NETCore.App.Runtime.linux-arm64, Microsoft.NETCore.App.Runtime.linux-musl-arm
eco: nuget
published: Aug 11, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET diagnostics IPC. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A missing error check in .NET causes an…

CVE-2026-62909
NVD

MEDIUM
CVE-2026-71969
CVE-2026-71969
pkg: express

published: Aug 10, 2026

OP-TEE OS through 4.10.0, fixed in commit 7b8b494, contains a buffer underwrite vulnerability in the RSA NOPAD encrypt and decrypt operations within the mbedTLS software backend and SE050 hardware driver that allows a malicious Trusted Application to corrupt secure-world heap memory by supplying an …
CWE: CWE-124, CWE-787
NVD

MEDIUM
CVE-2026-71968
CVE-2026-71968
pkg: node

published: Aug 10, 2026

OP-TEE OS through 4.10.0, fixed in commit 8794043, contains a use-after-free vulnerability in the Trusted Application loader that allows attackers with the ability to load a signed Trusted Application to corrupt secure-world kernel memory by setting the TA_FLAG_CONCURRENT flag in a user TA signed he…
CWE: CWE-362, CWE-416
GitHub-GHSA

MEDIUM
ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)
GHSA-9hgc-g3w5-67cm
pkg: mcp-contextforge-gateway
eco: pip
published: Aug 14, 2026
## Summary

The `/admin/gateways/test` endpoint validates submitted URLs by resolving the hostname at validation time and blocking private address ranges. The HTTP client independently re-resolves DNS at connection time with no IP binding between the two operations, creating a TOCTOU window exploita…

CVE-2026-53708
NVD

MEDIUM
CVE-2026-73330
CVE-2026-73330
pkg: express

published: Aug 12, 2026

CamaleonCMS 2.9.1 contains a server-side template injection vulnerability that allows authenticated administrators to execute arbitrary commands by embedding ERB tags in the email parameter of the test_email settings action, which are evaluated when an SMTP rejection reflects the recipient address b…
CWE: CWE-1336
NVD

MEDIUM
CVE-2026-74785
CVE-2026-74785
pkg: express

published: Aug 16, 2026

Scriban before 7.0.0 contains three distinct denial-of-service vulnerabilities in expression evaluation that bypass existing safety controls through unbounded string multiplication, uncontrolled BigInteger shift operations, and LoopLimit bypass via range enumeration in builtin functions. Attackers w…
CWE: CWE-400
GitHub-GHSA

MEDIUM
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
GHSA-8rw6-p7m8-63jp
pkg: surrealdb
eco: rust
published: Aug 14, 2026
A `SELECT` permission defined on an array element (`DEFINE FIELD field.* … PERMISSIONS FOR select …`) is not enforced correctly for `RECORD` users. Instead of hiding the denied elements, the query leaks a subset of them: a deny-all returns the odd-indexed elements, and a per-element predicate ke…
NVD

MEDIUM
CVE-2026-72664
CVE-2026-72664
pkg: go

published: Aug 13, 2026

Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who holds only detection rule authoring privileges for the Elastic Security solution …
CWE: CWE-862
NVD

MEDIUM
CVE-2026-72663
CVE-2026-72663
pkg: express

published: Aug 13, 2026

Inefficient Algorithmic Complexity (CWE-407) in Kibana can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted, deeply nested expression submitted to a Kibana TSVB visualization is evaluated with a worst-case cost that grows disproportionately with the size of the …
CWE: CWE-407
NVD

MEDIUM
CVE-2026-72648
CVE-2026-72648
pkg: kubernetes

published: Aug 13, 2026

Cleartext Storage of Sensitive Information in an Environment Variable (CWE-526) in Elastic Cloud on Kubernetes (ECK) can lead to information disclosure via Retrieve Embedded Sensitive Data (CAPEC-37). When ECK reconciles a Fleet Server resource that authenticates to Elasticsearch with a service acco…
CWE: CWE-526
NVD

MEDIUM
CVE-2026-72640
CVE-2026-72640
pkg: kubernetes

published: Aug 13, 2026

The Elastic Cloud on Kubernetes (ECK) operator reads a list of secret references from an annotation on secrets it manages, and it accepts the namespace recorded in each reference without validating that the reference is authorized for the resource being reconciled. A user whose Kubernetes permission…
CWE: CWE-441
NVD

MEDIUM
CVE-2026-49089
CVE-2026-49089
pkg: express

published: Aug 13, 2026

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A query expression accepted by a connector reporting operation was processed without any limit on its size, and an oversized expression caused the Kibana proce…
CWE: CWE-770
GitHub-GHSA

MEDIUM
vLLM: Completion prompt lists fan out into unbounded engine requests
GHSA-87×5-vmc3-756j
pkg: vllm
eco: pip
published: Aug 13, 2026
## Summary

The `/v1/completions` request model accepts `prompt` as a list of text prompts or a list of token-id prompts without any outer prompt-count bound. The serving path turns each element into a separate engine input, creates one engine generator per element, merges all generators, and alloca…

CVE-2026-73559
NVD

MEDIUM
CVE-2026-14663
CVE-2026-14663
pkg: openssl

published: Aug 13, 2026

Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of the faulty ciphertext. The OpenSSL version and OpenSSL configuration determine the disabled ciphers. If the application accepts encrypted data as input, decryption will succeed e…
CWE: CWE-313, CWE-345
GitHub-GHSA

MEDIUM
Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint
GHSA-88p2-jj8w-j8qg
pkg: github.com/fleetdm/fleet/v4
eco: go
published: Aug 12, 2026
### Summary

The target search endpoint (`POST /api/latest/fleet/targets`) returned team enroll secrets and full team configuration, including credential-bearing agent options, to observer-class users. Other team-facing endpoints mask these fields for observers; the target search endpoint did not ap…

CVE-2026-48786
NVD

MEDIUM
CVE-2026-68868
CVE-2026-68868
pkg: go

published: Aug 12, 2026

The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections and Variables: the caller's `team_name` was accepted by the backend but dropped at the internal call boundary, so every lookup resolved against the team-agnosti…
CWE: CWE-1220
GitHub-GHSA

MEDIUM
Microsoft Security Advisory CVE-2026-62902 – .NET Information Disclosure Vulnerability
GHSA-9mrh-pw7c-9mqm
pkg: Microsoft.WindowsDesktop.App.Runtime.win-arm64, Microsoft.WindowsDesktop.App.Runtime.win-x64, Microsoft.WindowsDesktop.App.Runtime.win-x86
eco: nuget
published: Aug 11, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in Windows Presentation Foundation. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A specially crafted document…

CVE-2026-62902
NVD

MEDIUM
CVE-2026-69117
CVE-2026-69117
pkg: express

published: Aug 11, 2026

NetBox 4.5.8 contains an ORM injection vulnerability that allows authenticated attackers, including those with read-only API tokens, to inject arbitrary Django ORM lookup expressions into nested object references by supplying crafted JSON dictionary keys in POST, PUT, or PATCH requests to any REST A…
CWE: CWE-639
NVD

MEDIUM
CVE-2026-72739
CVE-2026-72739
pkg: docker

published: Aug 10, 2026

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the createCommand() function constructs shell commands by interpolating compose service names and configuration into bash command strings. When a compose with a maliciously crafted name or service definition is deployed…
CWE: CWE-78
NVD

MEDIUM
CVE-2026-65945
CVE-2026-65945
pkg: jwt

published: Aug 10, 2026

Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0
Users are recommended to upgrade to version 2.9.0, which fixes this issue.
CWE: CWE-532
NVD

MEDIUM
CVE-2026-19751
CVE-2026-19751
pkg: axios

published: Aug 13, 2026

A flaw has been found in EnzoVezzaro mcp-dominican-layer up to 39dd373786712650097ad31db27d5c477c8f9c82. The affected element is the function axios.get of the file src/index.ts of the component parse-csv tool. This manipulation of the argument csvUrl causes server-side request forgery. The attack is…
CWE: CWE-918
NVD

MEDIUM
CVE-2026-73576
CVE-2026-73576
pkg: jwt

published: Aug 13, 2026

In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability exists in the OnlyOffice integration. The zimbraDocumentEditingJwtSecret is generated using an insecure random number generator, resulting in insufficient entropy. An attacker who obtains a JWT signed with…
CWE: CWE-1241
GitHub-GHSA

MEDIUM
Duplicate Advisory: Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint
GHSA-4jjw-pwvw-q6w3
pkg: nuxt
eco: npm
published: Aug 11, 2026
## Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-7c4v-fwgw-9rf7. This link is maintained to preserve external references.

## Original Description
Nuxt versions >= 4.4.7 and < 4.5.1, and >= 3.21.7 and < 3.21.10, contain an information disclosure vulnerabilit…

NVD

MEDIUM
CVE-2026-73671
CVE-2026-73671
pkg: oauth

published: Aug 13, 2026

Saurus CMS Community Edition contains an unauthenticated open redirect vulnerability in the logout handling code in classes/port.inc.php, where the url parameter supplied via GET or POST is passed directly to the Location header without domain allowlist, scheme validation, or relative path enforceme…
CWE: CWE-601
GitHub-GHSA

MEDIUM
ep_etherpad-lite: Cache-poisoning Cross-site Scripting and Open Redirect via x-proxy-path Header
GHSA-fjgc-3mj7-8rg8
pkg: ep_etherpad-lite
eco: npm
published: Aug 13, 2026
# GHSA-03 — `x-proxy-path` header reflected into admin HTML/JS/CSS (cache-poisoning XSS) and concatenated into redirect (open-redirect)

**Severity:** Medium
**CVSS v3.1 vector:** `CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N`
**CVSS suggested base score:** ~6.1 — Medium
*(Re-validate in the f…

CVE-2026-55087
NVD

MEDIUM
CVE-2026-73084
CVE-2026-73084
pkg: oauth

published: Aug 11, 2026

Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /api/redirect OAuth callback endpoint embeds the user-supplied code query parameter directly into an inline script block without proper escaping. A crafted request to /api/redirect with a malicious code value can br…
CWE: CWE-79, CWE-94
NVD

MEDIUM
CVE-2026-69116
CVE-2026-69116
pkg: vue

published: Aug 10, 2026

FlyEnv before 4.18.0 fails to sanitize HTML from markdown rendering and AI chat content passed to Vue v-html directives. Attackers can inject malicious scripts through markdown sources or chat messages that execute in the Electron renderer process with access to Node.js APIs and the filesystem.
CWE: CWE-79
NVD

MEDIUM
CVE-2026-66455
CVE-2026-66455
pkg: react

published: Aug 13, 2026

Subscriber Broken Access Control in ReactPress <= 3.4.0 versions.
CWE: CWE-862
NVD

MEDIUM
CVE-2026-12233
CVE-2026-12233
pkg: tls

published: Aug 12, 2026

The PSA Protected Storage credential backend (subsys/net/lib/tls_credentials/tls_credentials_trusted.c) declared its credential-store mutex as a plain zero-filled static struct k_mutex credential_lock; and never called k_mutex_init() on it. A statically zero-filled k_mutex has an uninitialized wait …
CWE: CWE-665
GitHub-GHSA

MEDIUM
Microsoft Security Advisory CVE-2026-62899 – .NET Security Feature Bypass Vulnerability
GHSA-r6mh-95jw-g7qg
pkg: Microsoft.NETCore.App.Runtime.linux-arm, Microsoft.NETCore.App.Runtime.linux-arm64, Microsoft.NETCore.App.Runtime.linux-musl-arm
eco: nuget
published: Aug 11, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in System.Net.HttpListener. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

Inconsistent interpretation of http …

CVE-2026-62899
NVD

MEDIUM
CVE-2026-73068
CVE-2026-73068
pkg: jwt

published: Aug 11, 2026

ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.207, the ToolJet Database HTTP API in server/src/modules/tooljet-db/controller.ts authorizes operations against the :organizationId URL path value without ver…
CWE: CWE-639
NVD

MEDIUM
CVE-2026-72800
CVE-2026-72800
pkg: express

published: Aug 12, 2026

SiYuan versions before v3.7.4 fail to apply publish-access filtering to the getAttributeViewKeysByID endpoint, allowing authenticated readers to retrieve complete database column schemas including descriptions, select vocabularies, and template expressions. Additionally, getBlockDefIDsByRefText and …
CWE: CWE-862
NVD

MEDIUM
CVE-2026-73308
CVE-2026-73308
pkg: oauth

published: Aug 12, 2026

Budibase is an open-source low-code platform. Prior to 3.39.25, packages/server/src/api/controllers/automation.ts returned automation test results containing trigger.outputs.user.oauth2, broadcast BuilderSocketEvent.AutomationTestProgress to the app room, and stored progress in packages/server/src/a…
CWE: CWE-200
NVD

MEDIUM
CVE-2026-73647
CVE-2026-73647
pkg: vue

published: Aug 13, 2026

Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the public extend() utility in ui/src/utils/extend/extend.js recursively copied attacker-controlled object keys during extend(true, target, source) deep merges without rejecting an own __proto__ pr…
CWE: CWE-1321
NVD

MEDIUM
CVE-2026-19964
CVE-2026-19964
pkg: python

published: Aug 17, 2026

A vulnerability was found in Jij-Inc Jij-MCP-Server 0.1.0. This affects the function PythonREPL.run of the file jij_mcp/python_repr.py of the component jm_check. The manipulation of the argument code results in code injection. It is possible to launch the attack remotely. The exploit has been made p…
CWE: CWE-74, CWE-94
NVD

MEDIUM
CVE-2026-48790
CVE-2026-48790
pkg: jwt

published: Aug 11, 2026

Turso CLI is the command line interface (CLI) to the open-source database Turso. Versions prior to 1.0.26 persist the user's Turso platform JWT to `settings.json` using Viper's default `configPermissions` of `0o644`, leaving the credential file world-readable on standard Linux and macOS systems. Any…
CWE: CWE-276, CWE-732
NVD

MEDIUM
CVE-2026-61360
CVE-2026-61360
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally.
CWE: CWE-822
NVD

MEDIUM
CVE-2026-61347
CVE-2026-61347
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally.
CWE: CWE-126
NVD

MEDIUM
CVE-2026-59137
CVE-2026-59137
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally.
CWE: CWE-908
NVD

MEDIUM
CVE-2026-59136
CVE-2026-59136
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally.
CWE: CWE-908
NVD

MEDIUM
CVE-2026-59135
CVE-2026-59135
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.
CWE: CWE-1390
NVD

MEDIUM
CVE-2026-59128
CVE-2026-59128
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally.
CWE: CWE-125
NVD

MEDIUM
CVE-2026-18942
CVE-2026-18942
pkg: kubernetes

published: Aug 10, 2026

A flaw was found in the Feast operator. A malicious tenant could inject arbitrary code into their feature repository. This code would be executed by an automated process with elevated privileges, allowing the tenant to steal sensitive credentials. This could lead to a direct escalation of privileges…
CWE: CWE-94
NVD

MEDIUM
CVE-2026-74240
CVE-2026-74240
pkg: jwt

published: Aug 14, 2026

A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and single sign-on (SSO) authentication. Multiple issues related to audience verification and the enforcement of `azp` and `sub` claims were identified. These flaws could allow an attacker with a validly-…
CWE: CWE-287
NVD

MEDIUM
CVE-2026-19135
CVE-2026-19135
pkg: express

published: Aug 13, 2026

A JEXL expression sandbox bypass exists in multiple versions of OpenNMS Meridian and Horizon. A low-privileged authenticated user can submit a crafted expression to the Measurements REST API that escapes the sandbox and loads arbitrary Java classes on the server. This can potentially allow an attack…
CWE: CWE-470
GitHub-GHSA

MEDIUM
tablib: Stored XSS in the HTML export via unescaped dataset title
GHSA-gqgw-jghv-mxwx
pkg: tablib
eco: pip
published: Aug 12, 2026
tablib prior to 3.10.0 contains a stored cross-site scripting vulnerability in the HTML export functionality that allows attackers to execute arbitrary JavaScript by embedding malicious payloads in dataset titles, which are interpolated unsanitized into HTML output via the export_book method in the …
CVE-2026-9318
GitHub-GHSA

MEDIUM
s2n-quic has excessive memory allocation
GHSA-9q54-f358-3fqf
pkg: s2n-quic
eco: rust
published: Aug 14, 2026
s2n-quic is a Rust implementation of the QUIC protocol. An unauthenticated user can attempt to exhaust server memory on an s2n-quic endpoint by sending crafted CRYPTO frames with high offsets. The buffer used for processing CRYPTO frames does not enforce a maximum size. In the worst case, a single 1…
CVE-2026-10740
GitHub-GHSA

MEDIUM
Token Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API Endpoints
GHSA-76pc-mqxp-3rq5
pkg: @ooples/token-optimizer-mcp
eco: npm
published: Aug 14, 2026
# Unauthenticated Path Traversal in Dashboard Session Log API Endpoints

| Field | Value |
| —————- | —– |
| Repository | ooples/token-optimizer-mcp |
| Affected version | 5.0.1 (commit 8137147) |
| Vulnerability | CWE-22 — Improper Limitation of a Pathname to a Re…

CVE-2026-55156
NVD

MEDIUM
CVE-2026-73845
CVE-2026-73845
pkg: express

published: Aug 14, 2026

CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, the ckan_get_mqa_quality and ckan_get_mqa_quality_details tools in src/tools/quality.ts use isValidMqaServer to validate the server_url parameter with a prefix-only regular expression for dati.gov.it, allowing suffix-ho…
CWE: CWE-20, CWE-625, CWE-918
NVD

MEDIUM
CVE-2026-73840
CVE-2026-73840
pkg: kubernetes

published: Aug 13, 2026

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, the POST /api/v1alpha1/autobuild endpoint in internal/openchoreo-api/api/handlers/webhook_handler.go selected a webhook provider from caller-controlled X-Event-Key, accepted Bitbucket requ…
CWE: CWE-287, CWE-290, CWE-345
NVD

MEDIUM
CVE-2026-58507
CVE-2026-58507
pkg: go

published: Aug 13, 2026

Private Repository Existence Disclosure via go-get Meta Endpoint
CWE: CWE-284
NVD

MEDIUM
CVE-2026-19487
CVE-2026-19487
pkg: express

published: Aug 13, 2026

Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.

The prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one re…

CWE: CWE-670
NVD

MEDIUM
CVE-2026-73556
CVE-2026-73556
pkg: express

published: Aug 13, 2026

vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the structured_outputs.regex parameter in vllm/v1/structured_output/backend_lm_format_enforcer.py is passed to lmformatenforcer.RegexParser without compile_regex_with_timeout or validation in validate_structured_outp…
CWE: CWE-400, CWE-1333
NVD

MEDIUM
CVE-2026-73555
CVE-2026-73555
pkg: python

published: Aug 13, 2026

vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the validation_exception_handler in vllm/entrypoints/openai/server_utils.py converts FastAPI RequestValidationError objects with str(exc), and sanitize_message in vllm/entrypoints/utils.py does not remove traceback-s…
CWE: CWE-209
NVD

MEDIUM
CVE-2026-66384
CVE-2026-66384
pkg: docker

published: Aug 12, 2026

An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
CWE: CWE-22
NVD

MEDIUM
CVE-2026-33921
CVE-2026-33921
pkg: windows

published: Aug 11, 2026

The Windows installer deployed Npcap leaving its access restriction option at the insecure default value, so the driver was accessible to every local user of the host instead of being restricted to administrators only. A local user without administrative privileges could use the Npcap driver to capt…
CWE: CWE-1188
NVD

MEDIUM
CVE-2026-73304
CVE-2026-73304
pkg: oauth

published: Aug 13, 2026

Budibase is an open-source low-code platform. Prior to 3.39.25, GET /api/users/metadata and GET /api/users/metadata/:id returned user objects processed by packages/server/src/utilities/global.ts without removing oauth2.accessToken or oauth2.refreshToken. A user with the POWER role could retrieve the…
CWE: CWE-200
NVD

MEDIUM
CVE-2026-67613
CVE-2026-67613
pkg: ssl

published: Aug 13, 2026

CyberPanel before 3.0.0 contains a path traversal vulnerability that allows authenticated administrators to read arbitrary files from the server filesystem by supplying unsanitized file paths to the cloudAPI ReadReport endpoint. Attackers can manipulate the reportFile parameter in the JSON request b…
CWE: CWE-22
NVD

MEDIUM
CVE-2026-73282
CVE-2026-73282
pkg: openssh

published: Aug 11, 2026

In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.
CWE: CWE-416
NVD

MEDIUM
CVE-2026-73563
CVE-2026-73563
pkg: oauth

published: Aug 13, 2026

Backstage is an open framework for building developer portals. Prior to 0.29.2, the experimental dynamic client registration and client ID metadata document features in the @backstage/plugin-auth-backend use full-string matcher.isMatch glob matching for auth.experimentalDynamicClientRegistration.all…
CWE: CWE-601
NVD

MEDIUM
CVE-2026-49820
CVE-2026-49820
pkg: oauth

published: Aug 13, 2026

Probo is a self-hostable governance, risk, and compliance (GRC) platform built for engineering and security teams. Probo's `saferedirect` package validates redirect URLs used across authentication flows (OIDC, SAML, session transfer, OAuth connectors, and trust-center magic links). Prior to version …
CWE: CWE-601
NVD

MEDIUM
CVE-2026-61350
CVE-2026-61350
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.
CWE: CWE-126
NVD

MEDIUM
CVE-2026-73036
CVE-2026-73036
pkg: python

published: Aug 11, 2026

Bash-it 3.2.0 contains a terminal escape sequence injection vulnerability in the barbuk theme's Python virtualenv prompt segment that allows local attackers to inject arbitrary terminal control sequences by embedding escape sequences in the requires-python field of a pyproject.toml file. When a user…
CWE: CWE-150
NVD

MEDIUM
CVE-2026-58425
CVE-2026-58425
pkg: oauth

published: Aug 13, 2026

OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)
CWE: CWE-200, CWE-863
NVD

MEDIUM
CVE-2026-6470
CVE-2026-6470
pkg: express

published: Aug 13, 2026

Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations did check the privilege, but assigning a range subtype and referencing the type from an SQL expressio…
CWE: CWE-862
NVD

MEDIUM
CVE-2026-65938
CVE-2026-65938
pkg: go

published: Aug 12, 2026

In WhatsUp Gold versions released before 2026.0.2, an improper authorization vulnerability in the Scheduled Reports API allows any authenticated user to invoke restricted actions.
CWE: CWE-602, CWE-862
NVD

MEDIUM
CVE-2026-19078
CVE-2026-19078
pkg: oauth

published: Aug 11, 2026

A flaw was found in the oauth-server component. This open redirect vulnerability occurs when the 'then' parameter in the grant approval handler is not properly validated. A remote attacker can craft a malicious URL that, when approved or denied by an authenticated user, redirects them to an attacker…
CWE: CWE-601
NVD

MEDIUM
CVE-2026-72912
CVE-2026-72912
pkg: express

published: Aug 10, 2026

CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.3.0, CyberChef's pretty-recipe parser in src/core/Utils.mjs can exhaust client-side CPU when a malformed #recipe= URL fragment containing a large number of unmatched quote characters reaches Utils.parseRecip…
CWE: CWE-400, CWE-1333
NVD

MEDIUM
CVE-2026-18165
CVE-2026-18165
pkg: oauth

published: Aug 15, 2026

@fastify/oauth2 is an OAuth 2.0 plugin for Fastify. In versions from 7.2.0 up to but not including 8.3.0, the plugin validates the OAuth state, and with PKCE the code verifier, by comparing the callback query parameter against an unprefixed, predictable cookie, with no server-side binding to the bro…
CWE: CWE-352
GitHub-GHSA

MEDIUM
ep_etherpad-lite: Import/export uses Math.random() for temp file paths; predictable paths on shared /tmp enable symlink-based file overwrite
GHSA-2jwf-f4xq-f24h
pkg: ep_etherpad-lite
eco: npm
published: Aug 13, 2026
## Description

`src/node/handler/ImportHandler.ts` and `src/node/handler/ExportHandler.ts` both compute their temporary working-file paths as:

“`ts
const randNum = Math.floor(Math.random() * 0xFFFFFFFF);
const srcFile = `${os.tmpdir()}/etherpad_export_${randNum}.html`;
const destFile = `${os.tmpd…

CVE-2026-55086
NVD

MEDIUM
CVE-2026-14681
CVE-2026-14681
pkg: tls

published: Aug 13, 2026

Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules, via initial direct TLS connection. Despite a pg_hba.conf that appears to require GSSAPI, the connection may exchange data over TLS encryption alone. If the TLS se…
CWE: CWE-924
GitHub-GHSA

MEDIUM
Fabric CA Developer's Guide: LDAP Injection via Unescaped Username in GetUser Filter
GHSA-xghw-p77p-3r7x
pkg: github.com/hyperledger/fabric-ca
eco: go
published: Aug 14, 2026
When fabric-ca is configured with an LDAP backend, the username from HTTP Basic authentication is included in an LDAP uid search filter without proper escaping. An unauthenticated attacker with network access to the CA enrollment endpoint could exploit this to perform LDAP injection before password …
CVE-2026-53658
GitHub-GHSA

MEDIUM
hashi-vault-js: Vault token and secret values exposed in thrown errors
GHSA-5pq8-3ffp-7w5m
pkg: hashi-vault-js
eco: npm
published: Aug 13, 2026
## Summary

Vault token and secret values are exposed in thrown errors when using `hashi-vault-js`.

## Details

Every API method in `Vault.js` executes `throw parseAxiosError(err)`, which returns the raw `AxiosError` untouched. That error carries the full Axios configuration, including the `X-Vault…

CVE-2026-55102


Vulnerability Digest — August 10, 2026 · 52 Critical · 5 Exploited






Vulnerability Digest — Monday, August 10, 2026


Security Report

Monday, August 10, 2026  ·  Last 7 days  ·  Min severity: MEDIUM
Total Findings
381
Critical
52
High
171
Actively Exploited
5
CISA-KEV5
NVD216
GitHub-GHSA160
Findings sorted by severity
CISA-KEV

CRITICAL
Progress LoadMaster Command Injection Vulnerability
CVE-2026-8037
pkg: Progress LoadMaster

published: Aug 7, 2026

Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
JetBrains TeamCity Deserialization of Untrusted Data Vulnerability
CVE-2026-63077
pkg: JetBrains TeamCity

published: Aug 5, 2026

JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
CVE-2026-18556
pkg: N-able N-central

published: Aug 4, 2026

N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
CVE-2026-34486
pkg: Apache Tomcat

published: Aug 4, 2026

Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
IBM Langflow Code Injection Vulnerability
CVE-2026-9198
pkg: IBM Langflow

published: Aug 4, 2026

Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
NVD

CRITICAL
CVE-2026-5430
CVE-2026-5430
pkg: jwt

published: Aug 6, 2026

The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access.

Successful exploitation of this vuln…

CWE: CWE-347
NVD

CRITICAL
CVE-2026-48086
CVE-2026-48086
pkg: jwt

published: Aug 6, 2026

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN promotes themselves to platform-wide GLOBAL_ADMIN through a single PUT request. The role-update handler accepts the `GLOBAL_ADMIN` enum value from any te…
CWE: CWE-269
NVD

CRITICAL
CVE-2026-70615
CVE-2026-70615
pkg: tls

published: Aug 5, 2026

boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users with tunnel-creation permission to inject arbitrary lines into the server account's SSH authorized_keys file by supplying a percent-encoded newline character in the domain parameter o…
CWE: CWE-93
NVD

CRITICAL
CVE-2026-10090
CVE-2026-10090
pkg: kubernetes

published: Aug 5, 2026

A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with namespace-scoped "edit" privileges in an ACM hub namespace can create a Channel resource pointing to a Helm repository they contr…
CWE: CWE-267
NVD

CRITICAL
CVE-2026-19264
CVE-2026-19264
pkg: jwt

published: Aug 7, 2026

Postiz is an open-source social media scheduling tool. The route that serves locally stored media joins URL-supplied path segments onto the upload directory and streams the file without normalising the path or confining it to that directory, and the route requires no authentication. Raw dot-segments…
CWE: CWE-22
NVD

CRITICAL
CVE-2026-70558
CVE-2026-70558
pkg: docker

published: Aug 6, 2026

Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and file.transferTo(dest) with no path validation. The route is marked @SaIgnore and /download/** is excluded from the Sa-Token interceptor, so the only guard is a header equality …
CWE: CWE-434
NVD

CRITICAL
CVE-2026-53975
CVE-2026-53975
pkg: docker

published: Aug 6, 2026

OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by sending crafted POST requests to the /api/fs/exec endpoint, which passes commands verbatim to Node.js spawn() without any allowlist, blocklist, or ar…
CWE: CWE-78
NVD

CRITICAL
CVE-2026-67870
CVE-2026-67870
pkg: node

published: Aug 6, 2026

In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local ExpandedNodeId targets. A remote attacker can send a crafted AddReferencesRequest with an empty targetServerUri and a non-zero targetNodeId.serverIndex, causing the target node poin…
CWE: CWE-476
NVD

CRITICAL
CVE-2026-71289
CVE-2026-71289
pkg: docker

published: Aug 5, 2026

The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose.yml publishes the amp-manager service's REST API directly to the host network interface (port 8089, e.g. "${ION_MGR_PORT:-8089}:8089/tcp") with cap_add: NET_ADMIN, NET_RAW, SYS_NICE, bypass…
CWE: CWE-306
NVD

CRITICAL
CVE-2026-71214
CVE-2026-71214
pkg: jwt

published: Aug 5, 2026

The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-server/src/app.ts) derives the caller's Hasura session role via getHasuraSession(), which prefers a session_variables object taken directly from the client-supplied JSON request body over the Authorization header's JWT claims…
CWE: CWE-306
NVD

CRITICAL
CVE-2026-64566
CVE-2026-64566
pkg: linux

published: Aug 5, 2026

In the Linux kernel, the following vulnerability has been resolved:

xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags()

When iptfs_skb_add_frags() copies frag references from the source
frag walk into a new SKB, it increments the page reference count via
__skb_frag_ref() but does not…

NVD

CRITICAL
CVE-2026-66902
CVE-2026-66902
pkg: go

published: Aug 4, 2026

Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated system call.

The Pluggable subclass reads credential_source.executable.command from the credentials JSON and runs it as `system($command)`, a single argument call that passes the wh…

CWE: CWE-78, CWE-829
NVD

CRITICAL
CVE-2026-24254
CVE-2026-24254
pkg: nvidia dynamo, linux linux_kernel

published: Aug 4, 2026

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
CWE: CWE-288
NVD

CRITICAL
CVE-2025-29296
CVE-2025-29296
pkg: express

published: Aug 4, 2026

H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V100R017, H3C Magic R1510 V100R016, H3C NE36 Pro V100R002 and H3C MC102G HM1A0V200R010 contain multiple command injection vulnerabilities in the /api/esps request handler. The affec…
CWE: CWE-77
NVD

CRITICAL
CVE-2026-69098
CVE-2026-69098
pkg: python

published: Aug 4, 2026

kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON input with a __type__ field. Attackers can exploit this to override the __type__ fi…
CWE: CWE-502
NVD

CRITICAL
CVE-2026-64564
CVE-2026-64564
pkg: linux

published: Aug 4, 2026

In the Linux kernel, the following vulnerability has been resolved:

sctp: don't free the ASCONF's own transport in DEL-IP processing

sctp_process_asconf() caches the transport the ASCONF chunk is processed
against in asconf->transport (== chunk->transport, set once in sctp_rcv()).
For an ASCONF lo…

NVD

CRITICAL
CVE-2026-69240
CVE-2026-69240
pkg: express

published: Aug 3, 2026

Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with strings only if dialect is set to oracle. The escape function defined in sql-string.js does not escape quotes if the value starts with TO_TIMESTAMP or TO_DATE. In the Oracle dialect, when val is a string and starts with…
CWE: CWE-89
GitHub-GHSA

CRITICAL
Sequelize: SQL Injection (Oracle DB)
GHSA-v8fg-2rw7-q452
pkg: sequelize
eco: npm
published: Aug 3, 2026
### Summary
SQL Injection is possible with strings only **if dialect is set to `oracle`**.
The vulnerability was confirmed on Sequelize v6.37.3.

### Details
The `escape` function defined in `sql-string.js` does not escape quotes if the value starts with `TO_TIMESTAMP` or `TO_DATE`.

“`javascript

CVE-2026-69240
NVD

CRITICAL
CVE-2026-19171
CVE-2026-19171
pkg: google chrome, microsoft windows

published: Aug 6, 2026

Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

CRITICAL
CVE-2026-19157
CVE-2026-19157
pkg: google chrome, google android

published: Aug 6, 2026

Out of bounds write in ANGLE in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-787
NVD

CRITICAL
CVE-2026-19149
CVE-2026-19149
pkg: google chrome, linux linux_kernel

published: Aug 6, 2026

Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

CRITICAL
CVE-2026-71319
CVE-2026-71319
pkg: vue

published: Aug 5, 2026

Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite HMR WebSocket via the nuxt:devtools:rpc plugin. On affected versions the channel has no authentication: any client that can reach the V…
CWE: CWE-94, CWE-306
GitHub-GHSA

CRITICAL
Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host
GHSA-279x-mwfv-vcqv
pkg: @nuxt/devtools
eco: npm
published: Aug 5, 2026
### Impact

Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite HMR WebSocket via the `nuxt:devtools:rpc` plugin. On affected versions the channel has no authentication: any client that can reach the Vite HMR endpoint (`ws://<host>:<port>/`, subprotocol `vite-hmr`…

CVE-2026-71319
NVD

CRITICAL
CVE-2026-65520
CVE-2026-65520
pkg: oauth

published: Aug 6, 2026

Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions.
CWE: CWE-89
GitHub-GHSA

CRITICAL
Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware
GHSA-cxjq-mrr5-89rv
pkg: github.com/traefik/traefik/v2, github.com/traefik/traefik/v3, github.com/traefik/traefik/v3
eco: go
published: Aug 6, 2026
## Summary

There is a critical authentication-bypass vulnerability in Traefik's `ReplacePathRegex` middleware. When it is configured with a regular expression that captures user-controlled path segments without a mandatory separator (for example `regex: "^/api(.*)"`, `replacement: "/$1"`), a crafte…

CVE-2026-65600
NVD

CRITICAL
CVE-2026-53976
CVE-2026-53976
pkg: jwt

published: Aug 6, 2026

OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and /api/fs/raw that allows unauthenticated remote attackers to read arbitrary files by supplying the allowOutsideWorkspace=true query parameter alongside an absolute path, bypassing …
CWE: CWE-22
NVD

CRITICAL
CVE-2026-63687
CVE-2026-63687
pkg: apache cxf

published: Aug 6, 2026

Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without excluding security-sensitive parameters. A client that can produce a validly-signed request JWT (e.g., one whose client_secret is known or compromised) can thereby substitute th…
CWE: CWE-345
NVD

CRITICAL
CVE-2026-61466
CVE-2026-61466
pkg: apache cxf

published: Aug 6, 2026

In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration request verbatim, without validating it against an AS-defined allowlist. This could lead to a client self-assigning privileged scopes at regi…
CWE: CWE-304
NVD

CRITICAL
CVE-2026-71263
CVE-2026-71263
pkg: linux

published: Aug 5, 2026

The LINUXTCP port of FreeModbus contains an off-by-one bounds check in xMBPortTCPPool() (demo/LINUXTCP/port/porttcp.c). The check `if (usTCPFrameBytesLeft > MB_TCP_BUF_SIZE)` uses a strict greater-than comparison instead of greater-than-or-equal against the 263-byte MB_TCP_BUF_SIZE limit. An MBAP fr…
CWE: CWE-787
NVD

CRITICAL
CVE-2026-71238
CVE-2026-71238
pkg: oauth

published: Aug 5, 2026

DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. Since this key is used for session signing, CSRF token generation, and password reset tokens, anyone who reads the public repository can forge valid sessio…
CWE: CWE-798
NVD

CRITICAL
CVE-2026-10059
CVE-2026-10059
pkg: kubernetes

published: Aug 5, 2026

A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertently grants the tenant administrator the ability to mint a token …
CWE: CWE-266
NVD

CRITICAL
CVE-2026-18754
CVE-2026-18754
pkg: tls

published: Aug 4, 2026

The
product firmware contains an embedded, static RSA private key utilized by the
Lighttpd web server for TLS termination. Exposure of this private key allows
malicious actors to breach the confidentiality and integrity of HTTPS
communications, enabling traffic decryption and server spoofing.
CWE: CWE-321
NVD

CRITICAL
CVE-2026-18753
CVE-2026-18753
pkg: tls

published: Aug 4, 2026

The
product firmware contains an embedded, static RSA private key utilized by the
Lighttpd web server for TLS termination. Exposure of this private key allows
malicious actors to breach the confidentiality and integrity of HTTPS
communications, enabling traffic decryption and server spoofing.
CWE: CWE-321
NVD

CRITICAL
CVE-2026-48031
CVE-2026-48031
pkg: jwt

published: Aug 3, 2026

go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by PostgreSQL. In versions prior to 2026-05-18, the JWT signing secret is hardcoded to the known string "random", letting any attacker who reads the public repository forge tokens for arbitrary users, including admin ro…
CWE: CWE-798
NVD

CRITICAL
CVE-2026-9487
CVE-2026-9487
pkg: xml\ \

published: Aug 3, 2026

XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID.

_get_signed_xml() in lib/XML/Sig.pm, called from verify(), resolves the SignedInfo Reference/@URI to a node with the XPath expression "//*[@ID='$id']" and returns the first node of the resulting node set. A document i…

CWE: CWE-347
NVD

CRITICAL
CVE-2026-9390
CVE-2026-9390
pkg: xml\ \

published: Aug 3, 2026

XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup.

verify() and _get_signed_xml() in lib/XML/Sig.pm build XPath expressions by concatenating the SignedInfo/Reference/@URI value read from the document being verified. The value is neither escaped nor checked against the NCName…

CWE: CWE-643, CWE-1287
GitHub-GHSA

CRITICAL
crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain
GHSA-rg76-677x-56q9
pkg: crypto-js
eco: npm
published: Aug 7, 2026
### Summary

`CryptoJS.lib.WordArray.random()` in affected versions is not a cryptographically secure random number generator. Nominal requests for 128 or 256 bits of entropy produce effective search spaces of approximately 2^39 and 2^47 possibilities — small enough to enumerate on commodity hardw…

CVE-2026-71851
GitHub-GHSA

CRITICAL
Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables token theft for any connected service
GHSA-qgvm-j2hm-6m38
pkg: flowise
eco: npm
published: Aug 4, 2026
### Summary

The OAuth2 token refresh endpoint (`POST /api/v1/oauth2-credential/refresh/:credentialId`) is in `WHITELIST_URLS`, meaning it requires **no authentication**. It decrypts the stored credential (containing `clientId`, `clientSecret`, `refresh_token`), sends a refresh request to the config…

CVE-2026-70478
GitHub-GHSA

CRITICAL
Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
GHSA-5xvg-pmgg-3mxr
pkg: flowise, flowise-components
eco: npm
published: Aug 4, 2026
— ABSTRACT ————————————-

Trend Micro's Zero Day Initiative has identified a vulnerability affecting the following products:
Flowise – Flowise

— VULNERABILITY DETAILS ————————
* Version tested: 3.1.1
* Installer file: https://github.com/FlowiseAI/Flowise (n…

CVE-2026-70477
GitHub-GHSA

CRITICAL
Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation
GHSA-4j8x-x6v7-w9rq
pkg: flowise, flowise-components
eco: npm
published: Aug 4, 2026
### Summary
Flowise's `CSVAgent` interpolates an attacker-controlled segment of the
`csvFile` data URI directly into a Python source-code template that is then
executed by Pyodide. Because Pyodide is loaded with the default `js` bridge
to `globalThis` (which on Node.js exposes `eval` and dynamic `im…
CVE-2026-69264
GitHub-GHSA

CRITICAL
Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE
GHSA-52fh-8v99-63c2
pkg: flowise, flowise-components
eco: npm
published: Aug 4, 2026
### Summary
The validatePythonCodeForDataFrame blacklist in packages/components/src/pythonCodeValidator.ts can be bypassed with Unicode homoglyph identifiers, allowing arbitrary Python execution inside Pyodide and full OS command execution on the Flowise host via Pyodide's js module interop. This re…
CVE-2026-70470
GitHub-GHSA

CRITICAL
Flowise RCE via SQLite Record Manager Node
GHSA-x3hf-7cj6-3r4m
pkg: flowise, flowise-components
eco: npm
published: Aug 4, 2026
=============================================================================
Security Advisory
elttam

Topic: Flowise RCE via SQLite Record Manager Node

Modul…

CVE-2026-69259
GitHub-GHSA

CRITICAL
Flowise: Remote Code Execution Vulnerability in CSVAgent
GHSA-x6vm-w76m-8j7g
pkg: flowise-components, flowise
eco: npm
published: Aug 4, 2026
### Summary

The CSVAgent node was observed to allow users to write Python code which gets executed via `pyodide`. The original intent was to allow users to utilise the `pandas` library for CSV processing. Although there is a denylist that checks for dangerous Python constructs from being passed in,…

CVE-2026-69256
GitHub-GHSA

CRITICAL
Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified
GHSA-vmv7-4m6c-3cg5
pkg: flowise, flowise-components
eco: npm
published: Aug 4, 2026
## UPDATE 2026-05-20: Full RCE as root VERIFIED

**This is not theoretical — a Meterpreter reverse shell session as root has been established on Flowise 3.1.2.**

### Verified Exploit Chain

1. Python code injection via `base64_string = "${base64String}"` (CSVAgent.ts line 161)
2. Pyodide `js` bri…

CVE-2026-69255
GitHub-GHSA

CRITICAL
Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override
GHSA-3769-jgqc-cxm7
pkg: flowise, flowise-components
eco: npm
published: Aug 4, 2026
### Summary
A sandbox escape vulnerability in `executeJavaScriptCode()` allows any authenticated user to execute arbitrary system commands as root on the Flowise server. The function accepts caller-provided `nodeVMOptions` that override the
default sandbox security settings via JavaScript's spread…
CVE-2026-69254
GitHub-GHSA

CRITICAL
Flowise Sandbox Escape to RCE
GHSA-wg86-r78f-74mp
pkg: flowise, flowise-components
eco: npm
published: Aug 4, 2026
=============================================================================
Security Advisory
elttam

Topic: Flowise JavaScript Sandbox Escape

Module: …

CVE-2026-69253
GitHub-GHSA

CRITICAL
Flowise RCE via TypeORM DataSource
GHSA-g32j-mmxr-gfq5
pkg: flowise, flowise-components
eco: npm
published: Aug 4, 2026
=============================================================================
Security Advisory
elttam

Topic: Flowise RCE via TypeORM DataSource

Module: …

CVE-2026-69251
GitHub-GHSA

HIGH
GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution
GHSA-wvpp-8hx9-p66j
pkg: GitPython
eco: pip
published: Aug 7, 2026
## Summary
The `check_unsafe_options` guard can be bypassed on every guarded method (clone/clone_from, fetch/pull/push, ls_remote, iter_commits, blame, archive) by combining a single-character kwarg with `split_single_char_options=False`. The guard's candidate list omits the smuggled option, but `tr…
GitHub-GHSA

HIGH
GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE)
GHSA-jm78-9fvv-mhgr
pkg: GitPython
eco: pip
published: Aug 7, 2026
## Summary
GitPython's config-name validator only neutralizes CR/LF/NUL for the `"option"` label; it does not reject `=`, `#`, `;`, `[`, `]`, or whitespace in an **option name**. `write_section` writes the option name verbatim into the config file, so an option name such as `sshCommand = touch <cmd>…
NVD

HIGH
CVE-2026-9169
CVE-2026-9169
pkg: windows

published: Aug 7, 2026

DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows a local attacker to execute arbitrary code with the privileges of the application by placing a malicious DLL in a user-controlled directory listed in the PATH environment variable, which the SDK traverses when a re…
CWE: CWE-427
NVD

HIGH
CVE-2026-48054
CVE-2026-48054
pkg: node

published: Aug 6, 2026

OpenZeppelin Contracts Wizardis a web application to interactively build a contract out of components from OpenZeppelin Contracts. Versions prior to 0.10.9 generate a Hardhat test file (`test/test.ts`) by interpolating user-supplied `opts.name` (ERC20/ERC721) and `opts.uri` (ERC1155) directly into T…
CWE: CWE-94
NVD

HIGH
CVE-2026-19151
CVE-2026-19151
pkg: google chrome

published: Aug 6, 2026

Use after free in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-19150
CVE-2026-19150
pkg: google chrome

published: Aug 6, 2026

Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-693
NVD

HIGH
CVE-2026-19145
CVE-2026-19145
pkg: google chrome

published: Aug 6, 2026

Use after free in Translate in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-19144
CVE-2026-19144
pkg: go

published: Aug 6, 2026

Use after free in HTML in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-64586
CVE-2026-64586
pkg: linux

published: Aug 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

wifi: brcmfmac: drain bus_reset work on device removal

brcmf_fw_crashed() and the debugfs "reset" entry both schedule
drvr->bus_reset, whose callback recovers drvr through container_of()
and dereferences it. The removal path free…

GitHub-GHSA

HIGH
rclone `serve restic –private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories
GHSA-fqj9-69pf-6pjg
pkg: github.com/rclone/rclone
eco: go
published: Aug 5, 2026
## Summary

`rclone serve restic –private-repos` exists to let one rclone instance host many users' restic backup repositories behind HTTP Basic auth while keeping each user confined to a path prefix of `/<username>/`. The documentation states the flag "can be used to limit users to repositories st…

CVE-2026-59733
NVD

HIGH
CVE-2026-9201
CVE-2026-9201
pkg: langflow langflow

published: Aug 5, 2026

IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryptographic weakness in the custom component validation mechanism. When the optional hardening mode that restricts execution to trusted component templates is enabled, the application val…
CWE: CWE-326
NVD

HIGH
CVE-2026-17632
CVE-2026-17632
pkg: langflow langflow

published: Aug 5, 2026

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of Python code during AST-based security scanning.
CWE: CWE-94
NVD

HIGH
CVE-2026-17626
CVE-2026-17626
pkg: langflow langflow

published: Aug 5, 2026

IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expose sensitive host files via Docker-based MCP servers due to incomplete filtering of dangerous Docker volume-mount and device-mapping arguments.
CWE: CWE-266
NVD

HIGH
CVE-2026-71287
CVE-2026-71287
pkg: express

published: Aug 5, 2026

Cacti's sanitize_sql_column() (lib/functions.php) sanitizes user-supplied ORDER BY column names using the regex `preg_replace('/[^a-zA-Z0-9_().]/', '', $column)`. Because this allowlist retains letters, digits, underscore, parentheses, and dot (intended to support expressions like COUNT(id) and tabl…
CWE: CWE-89
NVD

HIGH
CVE-2026-71235
CVE-2026-71235
pkg: go

published: Aug 5, 2026

Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side when IoT messages arrive. The Go script engine (re/golang.go) runs scripts through the Yaegi interpreter with stdlib.Symbols, exposing the full Go standard library (including os …
CWE: CWE-94
NVD

HIGH
CVE-2026-55997
CVE-2026-55997
pkg: node

published: Aug 5, 2026

Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens were stored and exposed in plaintext with no expiration, so a malicious user could obtain one either through the Rancher API, etcd, stored automation, or direct file access on a …
CWE: CWE-312
NVD

HIGH
CVE-2026-70374
CVE-2026-70374
pkg: node

published: Aug 5, 2026

HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the media upload thumbnail generation routine. Media.generateThumbnail() in src/Server/Entity/Resource/Media.js builds a temporary file path as 'thumbnail' + Path.extname(filename) and passes it, unescaped, into a…
CWE: CWE-78
NVD

HIGH
CVE-2026-67195
CVE-2026-67195
pkg: express

published: Aug 4, 2026

Perspective 5.0.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary operating system commands by submitting crafted expression strings to the PolarsVirtualServer backend, which passes client-supplied input directly to Python's eval() with only …
CWE: CWE-95
NVD

HIGH
CVE-2026-64562
CVE-2026-64562
pkg: linux

published: Aug 4, 2026

In the Linux kernel, the following vulnerability has been resolved:

KVM: nVMX: Hide shadow VMCS right after VMCLEAR

free_nested() frees the shadow VMCS while vmcs01 still points to it. But
because it is asynchronous with respect to loaded_vmcs_clear(), the vCPU
might migrate before the pointer is …

NVD

HIGH
CVE-2026-64561
CVE-2026-64561
pkg: linux

published: Aug 4, 2026

In the Linux kernel, the following vulnerability has been resolved:

KVM: x86: Check for invalid/obsolete root *after* making MMU pages available

Check for a "stale" page fault, i.e. for an invalid and/or obsolete root,
after making MMU pages available for the shadow MMU. If reclaiming shadow
page…

NVD

HIGH
CVE-2026-69096
CVE-2026-69096
pkg: docker

published: Aug 3, 2026

OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.uc RPC backend after the JS/ucode conversion) contains an OS command injection vulnerability. The package's read ACL grants broad ubus access to docker.* / docker.container.*, which exposes the docker…
CWE: CWE-78
GitHub-GHSA

HIGH
Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages
GHSA-pwxh-7358-jq2x
pkg: open-webui
eco: pip
published: Aug 4, 2026
## Summary
Any authenticated user can store a chat message whose math block makes KaTeX fail with a stack overflow instead of a parse error. When that happens the renderer falls back to inserting the original math source into the page as HTML rather than as text, so script in the message runs in the…
CVE-2026-70492
NVD

HIGH
CVE-2026-64940
CVE-2026-64940
pkg: express

published: Aug 10, 2026

Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contains a vulnerability due to a permissive regular expression, which may allow an attacker who can access the affected product to log in to the management console. As a result, the attacker may perform any operations available from th…
CWE: CWE-625
NVD

HIGH
CVE-2026-63637
CVE-2026-63637
pkg: node

published: Aug 6, 2026

Dgraph is an open source distributed GraphQL database. Prior to 25.3.8, maybeQuoteArg in graphql/resolve/query_rewriter.go passes regexp filter strings into generated DQL without quoting or validating the /pattern/flags form, allowing crafted GraphQL query or mutation filters to inject DQL operators…
CWE: CWE-943
NVD

HIGH
CVE-2026-19143
CVE-2026-19143
pkg: google chrome, google android

published: Aug 6, 2026

Insufficient validation of untrusted input in WebAPKs in Google Chrome on Android prior to 151.0.7922.109 allowed a local attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
CWE: CWE-20
NVD

HIGH
CVE-2026-71259
CVE-2026-71259
pkg: python

published: Aug 5, 2026

ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url() validator in esphome/config_validation.py: `if parsed.scheme and parsed.netloc or parsed.scheme == "file": return parsed.geturl()`. Because `and` binds tighter than `or`, any file: URI passes validation regardless of ne…
CWE: CWE-184
NVD

HIGH
CVE-2026-45414
CVE-2026-45414
pkg: jwt

published: Aug 6, 2026

Decidim is a participatory democracy framework. Prior to 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, JWT-backed API authentication is not bound to the organization selected by the current host, allowing a JWT issued for one tenant to be replayed against another tenant’s API to read participantDeta…
CWE: CWE-639, CWE-863
NVD

HIGH
CVE-2026-71280
CVE-2026-71280
pkg: linux

published: Aug 5, 2026

go-shiori's DownloadBookmark() (internal/core/download.go) fetches a caller-supplied bookmark URL using a plain http.Client with no custom DialContext or destination-IP validation (no IsLoopback(), IsPrivate(), IsUnspecified(), or IsLinkLocalUnicast() checks). An authenticated user creating or updat…
CWE: CWE-918
NVD

HIGH
CVE-2026-71271
CVE-2026-71271
pkg: linux

published: Aug 5, 2026

Memos' webhook URL validation, isReservedIP() (internal/webhook/validate.go), checks a candidate IP against a reservedCIDRs list that omits 0.0.0.0/8 and never calls ip.IsUnspecified() — unlike the correctly implemented sibling function isInternalIP() in internal/httpgetter/html_meta.go, which doe…
CWE: CWE-918
NVD

HIGH
CVE-2026-19163
CVE-2026-19163
pkg: google chrome, microsoft windows

published: Aug 6, 2026

Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-19155
CVE-2026-19155
pkg: google chrome

published: Aug 6, 2026

Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-19154
CVE-2026-19154
pkg: google chrome, google android

published: Aug 6, 2026

Use after free in Skia in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-19152
CVE-2026-19152
pkg: google chrome

published: Aug 6, 2026

Insufficient policy enforcement in Navigation in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-693
NVD

HIGH
CVE-2026-19148
CVE-2026-19148
pkg: google chrome, linux linux_kernel

published: Aug 6, 2026

Out of bounds write in GPU in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-787
NVD

HIGH
CVE-2026-19147
CVE-2026-19147
pkg: go

published: Aug 6, 2026

Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-19141
CVE-2026-19141
pkg: google chrome, google android

published: Aug 6, 2026

Use after free in Resources in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-19140
CVE-2026-19140
pkg: google chrome

published: Aug 6, 2026

Use after free in GPU in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-19138
CVE-2026-19138
pkg: google chrome

published: Aug 6, 2026

Heap buffer overflow in CrashReporting in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-122
NVD

HIGH
CVE-2026-19137
CVE-2026-19137
pkg: google chrome, google android

published: Aug 6, 2026

Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-71206
CVE-2026-71206
pkg: jwt

published: Aug 5, 2026

Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature and returns the embedded claims.Account object unmodified, never re-fetching the account from the database. No session store or token-revocation mechanism exists in the codebase. Deleting an account or de…
CWE: CWE-613
GitHub-GHSA

HIGH
GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython
GHSA-hmq2-w58f-27jc
pkg: GitPython
eco: pip
published: Aug 7, 2026
### Summary
GitPython computes the on-disk location of a submodule's separate Git directory (`.git/modules/<name>`) from the submodule's `.gitmodules` section name with no validation. Because that name is fully attacker-controlled content of a cloned repository, a malicious repository can set a subm…
GitHub-GHSA

HIGH
Traefik: Gateway API route identity collision allows cross-namespace backend hijacking
GHSA-fgjj-px3w-67xx
pkg: github.com/traefik/traefik/v3, github.com/traefik/traefik/v3
eco: go
published: Aug 6, 2026
## Summary

There is a high severity vulnerability in Traefik's Kubernetes Gateway API provider. Router and service identities for `HTTPRoute`, `GRPCRoute`, `TCPRoute` and `TLSRoute` objects were built by hyphen-concatenating the route namespace, the route name, the Gateway identity, the entry point…

CVE-2026-71327
NVD

HIGH
CVE-2026-71315
CVE-2026-71315
pkg: vue

published: Aug 5, 2026

Nuxt is an open-source web development framework for Vue.js. From 3.21.7 until 3.21.10 and 4.5.1, mixed-case routeRules keys can fail to match case-folded lookups when router.options.sensitive is false and drop appMiddleware authorization gates. This is caused by an incomplete fix for CVE-2026-53721…
CWE: CWE-178, CWE-863
GitHub-GHSA

HIGH
Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)
GHSA-hxvh-4h3w-prp9
pkg: nuxt, nuxt
eco: npm
published: Aug 5, 2026
### Impact

Nuxt matches route rules case-insensitively by default (mirroring vue-router's default `sensitive: false` routing). The fix for GHSA-mm7m-92g8-7m47 / CVE-2026-53721 lowercased the *lookup* path before matching route rules, but the route-rule *keys* compiled into the matcher were left ver…

CVE-2026-71315
NVD

HIGH
CVE-2026-64578
CVE-2026-64578
pkg: linux

published: Aug 5, 2026

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: validate compound request size before reading StructureSize2

When ksmbd validates a compound (chained) SMB2 request,
ksmbd_smb2_check_message() reads pdu->StructureSize2 without first
checking that the compound element is l…

GitHub-GHSA

HIGH
Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin
GHSA-3xpf-xq7r-v8c5
pkg: open-webui
eco: pip
published: Aug 4, 2026
## Summary
Any authenticated user with access to a terminal server could get script of their choosing to run in the Open WebUI origin itself. The HTML file preview rendered terminal-served files in an iframe whose sandbox always granted `allow-same-origin` alongside `allow-scripts`, and the file is …
CVE-2026-70486
NVD

HIGH
CVE-2026-47623
CVE-2026-47623
pkg: nvidia dynamo, linux linux_kernel

published: Aug 4, 2026

NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to denial of service and data tampering.
CWE: CWE-502
NVD

HIGH
CVE-2026-24253
CVE-2026-24253
pkg: nvidia dynamo, linux linux_kernel

published: Aug 4, 2026

NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service and data tampering.
CWE: CWE-787
NVD

HIGH
CVE-2026-58080
CVE-2026-58080
pkg: eclipse milo

published: Aug 4, 2026

In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMapper`. On servers that rely on role permissions and construct the running configuration through `copy()`, sessions receive no role IDs and the default access controller skips role-permissio…
CWE: CWE-862
GitHub-GHSA

HIGH
GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite
GHSA-4gmw-gg2m-w46p
pkg: GitPython
eco: pip
published: Aug 7, 2026
## Summary
`IndexFile.from_tree`, `IndexFile.reset` (→ from_tree) and `IndexFile.merge_tree` append caller-influenced treeish strings positionally to `git read-tree` with no unsafe-option guard, no `allow_unsafe_options` parameter, and no `–` separator. `git read-tree –index-output=<file>` write…
NVD

HIGH
CVE-2026-64665
CVE-2026-64665
pkg: oauth

published: Aug 6, 2026

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker could sign in as an existing user, potentially including a super admin, withou…
CWE: CWE-287, CWE-290
NVD

HIGH
CVE-2026-5857
CVE-2026-5857
pkg: tls

published: Aug 6, 2026

Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_len_received=1 before checking topic_len against the 64-byte limit, so an over-length topic returns early but leaves the flag set. On the next TCP segment, tcp_input() re-invokes the parser with topic_received==…
CWE: CWE-787
NVD

HIGH
CVE-2026-19153
CVE-2026-19153
pkg: google chrome

published: Aug 6, 2026

Insufficient validation of untrusted input in Workers in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-20
NVD

HIGH
CVE-2026-71320
CVE-2026-71320
pkg: vue

published: Aug 5, 2026

Nuxt is an open-source web development framework for Vue.js. From 3.4.0 until 3.21.10 and 4.5.1, an attacker can inject a template key through /__nuxt_island/ props into a dynamic component when `vue.runtimeCompiler: true` is enabled, causing template execution in the Nitro process. This issue is fi…
CWE: CWE-74, CWE-94
GitHub-GHSA

HIGH
Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props
GHSA-9473-5f9j-94wq
pkg: nuxt, nuxt
eco: npm
published: Aug 5, 2026
## Impact

Nuxt server islands accept props via the `/__nuxt_island/` endpoint. When `vue.runtimeCompiler: true` is enabled (off by default) and the application has a server island component that forwards props into Vue's dynamic component resolution (`<component :is>`, `resolveDynamicComponent`, or…

CVE-2026-71320
NVD

HIGH
CVE-2026-9196
CVE-2026-9196
pkg: langflow langflow

published: Aug 5, 2026

IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agentic Assistant validation due to improper handling of LLM‑generated components. The application executes model‑generated Python code in the backend during validation prior to user app…
CWE: CWE-94
NVD

HIGH
CVE-2026-71285
CVE-2026-71285
pkg: express

published: Aug 5, 2026

Uptime Kuma's Matomo analytics integration (server/analytics/matomo-analytics.js) injects the admin-configurable Matomo `siteId` value as a bare, unquoted JavaScript expression inside a <script> block rendered on every public status page: `_paq.push(['setSiteId', ${escapedSiteIdHTMLAttribute}]);`. T…
CWE: CWE-79
GitHub-GHSA

HIGH
Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder
GHSA-3cg5-48j3-v4gv
pkg: open-webui
eco: pip
published: Aug 4, 2026
## Summary
A user granted write access to a shared chat folder could permanently delete chats and messages belonging to the folder's owner. Deleting a folder cascades into the owner's chats and the entire subfolder subtree, and the deletion handler required only write access on subfolders instead of…
CVE-2026-70494
NVD

HIGH
CVE-2026-70482
CVE-2026-70482
pkg: oauth

published: Aug 4, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.0, when ENABLE_OAUTH_TOKEN_EXCHANGE=True, /oauth/{provider}/token/exchange accepts a raw provider access token and validates it by calling the provider userinfo endpoint without confirming whi…
CWE: CWE-287
GitHub-GHSA

HIGH
Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client
GHSA-rq84-p6rr-vf89
pkg: open-webui
eco: pip
published: Aug 4, 2026
## Summary

The OAuth token exchange endpoint accepts a raw provider access token and validates it by calling the provider's userinfo endpoint. A userinfo endpoint reports only that a token is valid, never which OAuth client it was issued to, and the endpoint performed no audience or client check of…

CVE-2026-70482
GitHub-GHSA

HIGH
GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read
GHSA-3f7w-8rr8-f37f
pkg: GitPython
eco: pip
published: Aug 3, 2026
**Target:** gitpython-developers/GitPython
**Tested:** HEAD `07e80555` (2026-07-25), latest release 3.1.55, `git version 2.50.1`
**Reported instances:** 2 exploitable, from a sweep of 14 unguarded call sites

## Summary

GitPython blocks dangerous git options through `Git.check_unsafe_options()`, ga…

NVD

HIGH
CVE-2026-67611
CVE-2026-67611
pkg: oauth

published: Aug 3, 2026

OpenEMR through 8.2.0 contains an authentication bypass vulnerability that allows attackers with valid credentials to circumvent multi-factor authentication by exploiting the exposed OAuth2 password grant flow through an unauthenticated client registration endpoint. Attackers can register an OAuth2 …
CWE: CWE-308
NVD

HIGH
CVE-2026-67610
CVE-2026-67610
pkg: jwt

published: Aug 3, 2026

OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic client registration endpoint that allows unauthenticated attackers to register a malicious client with system-level FHIR scopes by supplying a self-generated RSA keypair via the jwks field. Once an administ…
CWE: CWE-306
GitHub-GHSA

HIGH
rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution
GHSA-2m8m-jhrm-w6j2
pkg: github.com/rclone/rclone
eco: go
published: Aug 5, 2026
## 1. Summary

rclone interpolates remote SFTP paths into PowerShell hash commands. Its quoting helper escapes only ASCII apostrophe, although PowerShell accepts four Unicode smart quotes as single-quote delimiters. An attacker-controlled filename can therefore terminate the intended path literal an…

CVE-2026-71312
NVD

HIGH
CVE-2026-71279
CVE-2026-71279
pkg: node

published: Aug 5, 2026

Zigbee2MQTT's ExternalJSExtension.getFilePath() (lib/extension/externalJS.ts) joins a `name` parameter received via an MQTT message (topic zigbee2mqtt/bridge/request/extension/save) into the extensions base path using path.join(basePath, name) with no sanitization. Because path.join() resolves `../`…
CWE: CWE-22
GitHub-GHSA

HIGH
jsii-diff: Command Injection via npm: package argument
GHSA-wcx4-wpfv-mc5c
pkg: jsii-diff
eco: npm
published: Aug 7, 2026
## Summary

jsii-diff is a command line tool to compare the API differences between two jsii assemblies, and report errors if there are backwards-incompatible changes to the API. An issue exists where specially formatted command line arguments can be used to execute shell commands via this tool.

##…

CVE-2026-15895
NVD

HIGH
CVE-2026-70628
CVE-2026-70628
pkg: express

published: Aug 6, 2026

FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsub_parser.c that allows attackers to trigger a heap buffer overflow by supplying a crafted WTV file. The overflow causes the bounds-check guard expressi…
CWE: CWE-190, CWE-787
NVD

HIGH
CVE-2026-64588
CVE-2026-64588
pkg: linux

published: Aug 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

fuse-uring: fix data races on ring->ready

On weakly-ordered architectures, the store to fiq->ops can be
reordered past the store to ring->ready, allowing a CPU that sees
ring->ready == true via fuse_uring_ready() to dispatch reque…

NVD

HIGH
CVE-2026-64585
CVE-2026-64585
pkg: linux

published: Aug 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

can: esd_usb: kill anchored URBs before freeing netdevs

esd_usb_disconnect() frees each CAN netdev with free_candev() inside
its per-netdev loop and only calls unlink_all_urbs(dev) afterwards.
The per-netdev private data (struct e…

NVD

HIGH
CVE-2026-64584
CVE-2026-64584
pkg: linux

published: Aug 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

usb: gadget: f_midi: cancel pending IN work before freeing the midi object

The f_midi driver embeds a work item (midi->work) whose handler,
f_midi_in_work(), dereferences the enclosing struct f_midi through
container_of(). This w…

NVD

HIGH
CVE-2026-64583
CVE-2026-64583
pkg: linux

published: Aug 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown

The Broadcom BDC UDC driver registers its IRQ handler with
devm_request_irq() in bdc_udc_init(), so the IRQ is released by devm
only after bdc_remove() ret…

NVD

HIGH
CVE-2026-55522
CVE-2026-55522
pkg: python

published: Aug 5, 2026

PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of praiseonaiagents, the workflow "include" feature is vulnerable to code execution. Workflow._execute_include() implicitly imports and runs an included recipe's tools.py via a raw imp…
CWE: CWE-94, CWE-426, CWE-829
NVD

HIGH
CVE-2026-18485
CVE-2026-18485
pkg: windows

published: Aug 5, 2026

There is a local privilege escalation vulnerability recently discovered in the NI-PAL kernel driver.  This may allow a local, authenticated user to escalate privileges and execute arbitrary code.  This vulnerability affects NI-PAL 26.3.1 and prior versions running on Microsoft Windows.
CWE: CWE-1285
NVD

HIGH
CVE-2026-12410
CVE-2026-12410
pkg: windows

published: Aug 5, 2026

Link following vulnerability in the Uninstaller component in CCleaner prior to 7.10.1464 on Windows allows a local, low-privileged attacker to escalate privileges to SYSTEM via a symlink/junction created during application uninstallation, which CCleaner follows when deleting the application's data f…
CWE: CWE-59
NVD

HIGH
CVE-2026-64582
CVE-2026-64582
pkg: linux

published: Aug 5, 2026

In the Linux kernel, the following vulnerability has been resolved:

RDMA/rxe: Fix a use-after-free problem in rxe_mmap

rxe_mmap() removes a rxe_mmap_info struct from the pending_mmaps list
and releases pending_lock while the struct's kref is still at 1:

list_del_init(&ip->pending_mmaps);
sp…

NVD

HIGH
CVE-2026-64581
CVE-2026-64581
pkg: linux

published: Aug 5, 2026

In the Linux kernel, the following vulnerability has been resolved:

xfrm: fix sk_dst_cache double-free in xfrm_user_policy()

xfrm_user_policy() clears the socket dst cache with __sk_dst_reset(),
i.e. the non-atomic __sk_dst_set(sk, NULL): it reads sk_dst_cache with
rcu_dereference_protected(), sto…

NVD

HIGH
CVE-2026-64580
CVE-2026-64580
pkg: linux

published: Aug 5, 2026

In the Linux kernel, the following vulnerability has been resolved:

xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst()

On the error path where in6_dev_get(dev) returns NULL, xfrm6_fill_dst()
releases the device reference with netdev_put() but leaves
xdst->u.dst.dev set. d…

NVD

HIGH
CVE-2026-64575
CVE-2026-64575
pkg: linux

published: Aug 5, 2026

In the Linux kernel, the following vulnerability has been resolved:

bpf: tcp: fix double sock release on batch realloc

bpf_iter_tcp_batch() releases the current batch via
bpf_iter_tcp_put_batch(), which drops the socket refs and rewrites
each slot with the socket cookie, then grows the batch. cur_…

NVD

HIGH
CVE-2026-64574
CVE-2026-64574
pkg: linux

published: Aug 5, 2026

In the Linux kernel, the following vulnerability has been resolved:

wifi: mac80211: tear down new links on vif update error path

When ieee80211_vif_update_links() adds new links it allocates a link
container for each and calls ieee80211_link_init() (which registers the
per-link debugfs files with …

NVD

HIGH
CVE-2026-64570
CVE-2026-64570
pkg: linux

published: Aug 5, 2026

In the Linux kernel, the following vulnerability has been resolved:

wifi: mac80211: fix fils_discovery double free on alloc failure

ieee80211_set_fils_discovery() calls kfree_rcu() on the old template
before allocating the replacement. If the kzalloc() then fails, it
returns -ENOMEM while link->u.…

NVD

HIGH
CVE-2026-64568
CVE-2026-64568
pkg: linux

published: Aug 5, 2026

In the Linux kernel, the following vulnerability has been resolved:

wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure

ieee80211_set_unsol_bcast_probe_resp() calls kfree_rcu() on the old
template before allocating the replacement. If the kzalloc() then fails,
it returns -ENOME…

NVD

HIGH
CVE-2026-64567
CVE-2026-64567
pkg: linux

published: Aug 5, 2026

In the Linux kernel, the following vulnerability has been resolved:

btrfs: reject free space cache with more entries than pages

When loading a v1 free space cache, __load_free_space_cache() takes
num_entries and num_bitmaps straight from the on-disk
btrfs_free_space_header. That header is stored i…

NVD

HIGH
CVE-2026-18657
CVE-2026-18657
pkg: windows

published: Aug 4, 2026

An uncontrolled search path element in Kiro CLI before version 2.10.0 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a maliciously crafted project directory containing an executable that bypasses workspace trust protections when a local user starts Kiro CLI in th…
CWE: CWE-427
NVD

HIGH
CVE-2026-18656
CVE-2026-18656
pkg: windows

published: Aug 4, 2026

An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a maliciously crafted project directory containing an executable that bypasses workspace trust protections when a local user opens the directory.…
CWE: CWE-427
NVD

HIGH
CVE-2026-64563
CVE-2026-64563
pkg: linux

published: Aug 4, 2026

In the Linux kernel, the following vulnerability has been resolved:

rhashtable: clear stale iter->p on table restart

rhashtable_walk_start_check() has two restart paths when resuming a walk.
When iter->walker.tbl is valid, it re-validates iter->p against the table
and sets iter->p = NULL if the ob…

NVD

HIGH
CVE-2026-41447
CVE-2026-41447
pkg: openssl

published: Aug 3, 2026

FirmaCheck for Windows before 1.3.16 contains a DLL hijacking vulnerability that allows local attackers to execute arbitrary code by placing a crafted openssl.cnf file in the unvalidated C:\Program Files (x86)\Common Files\SSL\ directory path. Attackers can write a malicious OpenSSL configuration fi…
CWE: CWE-426
NVD

HIGH
CVE-2026-64636
CVE-2026-64636
pkg: windows

published: Aug 7, 2026

An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to read arbitrary data from the panel database.
CWE: CWE-89
GitHub-GHSA

HIGH
Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader
GHSA-w2rx-84hp-gg95
pkg: open-webui
eco: pip
published: Aug 4, 2026
## Summary
With the Playwright web loader enabled, Open WebUI opens user-submitted URLs in a real browser and validates the destination address before allowing the request. That check only ran for the top-level page request. Every other request the page issued was passed through unvalidated, so a pa…
CVE-2026-70479
NVD

HIGH
CVE-2026-34966
CVE-2026-34966
pkg: oauth

published: Aug 5, 2026

Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiting HTTP fetch operations in migration and OAuth avatar code paths that use Go's default http.Get without a custom DialContext. Attackers can supply arb…
CWE: CWE-918
NVD

HIGH
CVE-2026-10595
CVE-2026-10595
pkg: python

published: Aug 9, 2026

A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specifically in the SPA catch-all route implemented in `backend/routers/ui.py`. The vulnerability arises from the improper handling of user-controlled path input, which is directly joined into a filesystem path without sanitizat…
CWE: CWE-23
NVD

HIGH
CVE-2026-52880
CVE-2026-52880
pkg: docker

published: Aug 7, 2026

Klever-Go is the Go implementation of the Klever blockchain protocol. Versions from 1.7.14 through 1.7.17 are vulnerable to a remotely triggerable denial of service. Both REST APIs are started with the Gin Engine.Run convenience method, which serves requests through Go's default HTTP server with no …
CWE: CWE-400, CWE-770
GitHub-GHSA

HIGH
pymdown-extensions: exponential-backtracking ReDoS in caret, tilde, betterem, and magiclink inline processors
GHSA-gm37-52c6-37mw
pkg: pymdown-extensions
eco: pip
published: Aug 7, 2026
### Summary

Four inline processors in pymdown-extensions contain regular expressions with
exponential backtracking. A single untrusted Markdown line under
50 bytes drives `markdown.markdown()` into unbounded CPU on the rendering thread
(seconds at ~45 bytes, growing exponentially with each added ch…

CVE-2026-67422
GitHub-GHSA

HIGH
GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via –template clone hooks
GHSA-9rj7-rf2p-w77r
pkg: GitPython
eco: pip
published: Aug 7, 2026
## Summary
`Repo.init()` forwards `**kwargs` verbatim to `git init` with no unsafe-option guard and no `allow_unsafe_options` parameter. `git init –template=<dir>` copies `<dir>/hooks/*` into the new repo's `.git/hooks`, so an attacker-controlled `template` kwarg plants a hook that executes on the …
NVD

HIGH
CVE-2026-16262
CVE-2026-16262
pkg: oauth

published: Aug 7, 2026

The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating user session, allowing an unauthenticated attacker to log a victim into an attacker-controlled account (login CSRF), so that the victim's subsequent activity is stored under and r…
CWE: CWE-352
NVD

HIGH
CVE-2026-70636
CVE-2026-70636
pkg: oauth

published: Aug 6, 2026

Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAuth2 credential refresh endpoint by exploiting prefix-based whitelist matching in the authentication middleware defined in packages/server/src/utils/constants.ts. Attackers can…
CWE: CWE-862
NVD

HIGH
CVE-2026-67422
CVE-2026-67422
pkg: express

published: Aug 6, 2026

pymdown-extensions is a collection of extensions for the Python Markdown library. In versions up to and including 11.0, four inline processors (caret, tilde, betterem, and magiclink) use regular expressions whose content groups can partition a run of delimiter characters in exponentially many ways, …
CWE: CWE-1333
NVD

HIGH
CVE-2026-19158
CVE-2026-19158
pkg: google chrome, microsoft windows

published: Aug 6, 2026

Use after free in Views in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-19156
CVE-2026-19156
pkg: google chrome

published: Aug 6, 2026

Heap buffer overflow in Base in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)
CWE: CWE-122
NVD

HIGH
CVE-2026-19142
CVE-2026-19142
pkg: go

published: Aug 6, 2026

Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
GitHub-GHSA

HIGH
JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported
GHSA-5p4m-2wfm-xmqj
pkg: js-yaml, js-yaml
eco: npm
published: Aug 6, 2026
# Quadratic CPU consumption in `!!omap` resolution (js-yaml 3.x and 4.x)

## Summary

`resolveYamlOmap()` enforces key uniqueness for `!!omap` sequences with a linear
scan (`objectKeys.indexOf(…)`) inside the per-element loop, making resolution
**O(n²)** in the number of entries. A modestly sized…

NVD

HIGH
CVE-2026-53985
CVE-2026-53985
pkg: docker

published: Aug 6, 2026

Ground Station prior to 0.6.0 contains an unauthenticated denial-of-service vulnerability in the Socket.IO server's service_control event handler that allows any unauthenticated network peer to forcibly terminate the ground-station process by sending a single restart_service command. Attackers can …
CWE: CWE-306
NVD

HIGH
CVE-2026-53977
CVE-2026-53977
pkg: express

published: Aug 6, 2026

OpenChamber 1.11.7 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to terminate the server process by sending a POST request to the /api/system/shutdown endpoint, which is registered before the authentication middleware in the Express route handler chain.…
CWE: CWE-306
NVD

HIGH
CVE-2026-71321
CVE-2026-71321
pkg: vue

published: Aug 5, 2026

Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, the internal island renderer endpoint `/__nuxt_island/…` decodes and hashes attacker-controlled JSON body input with destr and ohash before validating the URL-resident hash. An unauthenticated `POST /_…
CWE: CWE-407, CWE-770
NVD

HIGH
CVE-2026-71316
CVE-2026-71316
pkg: vue

published: Aug 5, 2026

Nuxt is an open-source web development framework for Vue.js. From 4.4.0 until 4.5.1, runtime cache:nuxt:payload entries for /<page>/_payload.json can be returned before route middleware and page guards because import.meta.prerender is not enforced, disclosing another user's SSR data. This issue is f…
CWE: CWE-524, CWE-862
NVD

HIGH
CVE-2026-67864
CVE-2026-67864
pkg: node

published: Aug 5, 2026

An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the NodeManagement type-instantiation logic component
CWE: CWE-400
GitHub-GHSA

HIGH
Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation
GHSA-9pgf-384g-p7mv
pkg: nuxt, nuxt
eco: npm
published: Aug 5, 2026
### Impact

The internal island renderer endpoint (`/__nuxt_island/…`) decodes and hashes attacker-controlled request input before it validates the URL-resident hash. An unauthenticated `POST /__nuxt_island/<name>_<anything>.json` with a large JSON body (for example ~4.6 MB / 150k keys) is fully r…

CVE-2026-71321
NVD

HIGH
CVE-2026-71314
CVE-2026-71314
pkg: vue

published: Aug 5, 2026

Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an unauthenticated attacker can use a server island v-for prop, including vforToArray and , to trigger unbounded SSR memory allocation until MAX_VFOR_LENGTH = 100000 and crash the Nuxt process. This issu…
CWE: CWE-400, CWE-770, CWE-789, CWE-1284
GitHub-GHSA

HIGH
Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients
GHSA-wm8w-6qjm-cv43
pkg: nuxt
eco: npm
published: Aug 5, 2026
### Impact

When a page is covered by `routeRules` `cache` / `swr` / `isr`, Nuxt enables runtime payload extraction and serves `/<page>/_payload.json`. On affected versions the renderer stored the SSR payload in the shared `cache:nuxt:payload` storage under a path-only key (no cookie, `authorization…

CVE-2026-71316
GitHub-GHSA

HIGH
Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering
GHSA-hxcr-hm88-mpq6
pkg: nuxt, nuxt
eco: npm
published: Aug 5, 2026
### Impact

An unauthenticated attacker can crash a Nuxt server that renders any island / server component containing a `v-for` over a prop (for example `v-for="n in count"` or a `<slot v-for>`). Because the island URL hash is a non-secret digest of the request, the attacker can compute a valid hash…

CVE-2026-71314
GitHub-GHSA

HIGH
rclone: Unvalidated symlink target in local `–links` — arbitrary file write from an untrusted remote
GHSA-cf44-9pgv-m4xc
pkg: github.com/rclone/rclone
eco: go
published: Aug 5, 2026
### Summary
With `-l/–links`, rclone serializes symlinks as `<name>.rclonelink` text objects whose body is the link target. When rclone writes such an object to a local destination, it recreates the symlink with `os.Symlink(<object body>, <dest path>)` and performs NO validation of the target. If t…
CVE-2026-54572
NVD

HIGH
CVE-2026-70601
CVE-2026-70601
pkg: windows

published: Aug 5, 2026

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.5, apps that expose Promise-returning functions to web content via contextBridge may be vulnerable to a context isolation bypass. Untrusted web con…
CWE: CWE-693
GitHub-GHSA

HIGH
Electron: Context isolation bypass via Function.prototype.bind hijack
GHSA-h7rp-cf8h-j98x
pkg: electron, electron, electron
eco: npm
published: Aug 5, 2026
### Impact
Apps that expose Promise-returning functions to web content via `contextBridge` may be vulnerable to a context isolation bypass. Untrusted web content could obtain access to the isolated preload world and, through it, every capability the preload script has. In renderers without a sandbox…
CVE-2026-70601
NVD

HIGH
CVE-2026-54876
CVE-2026-54876
pkg: tls

published: Aug 5, 2026

Issue summary: A malicious TLS server can cause a memory leak in a TLS
client that has enabled OCSP response checking by sending an OCSP
response that contains no single response entries.

Impact summary: An attacker can leak an attacker-tunable amount of memory
per TLS handshake in a victim client …

CWE: CWE-401
NVD

HIGH
CVE-2026-71215
CVE-2026-71215
pkg: node

published: Aug 5, 2026

art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by both the include() and extend() template directives, resolves the target file path via path.resolve(root, filename) with no check afterward that the result remains inside root. Because path.resolve() disc…
CWE: CWE-22
NVD

HIGH
CVE-2026-71209
CVE-2026-71209
pkg: express

published: Aug 5, 2026

audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated-allowed GET routes against req.path via a regex requiring a literal /items/:id/cover or /authors/:id/image shape, where req.path retains %2F sequences URL-encoded. Express's router decodes the :id route …
CWE: CWE-22
NVD

HIGH
CVE-2026-64577
CVE-2026-64577
pkg: linux

published: Aug 5, 2026

In the Linux kernel, the following vulnerability has been resolved:

gtp: check skb_pull_data() return in gtp1u_send_echo_resp()

gtp1u_send_echo_resp() ignores skb_pull_data()'s return value. Its
caller gtp1u_udp_encap_recv() only guarantees 16 bytes (udphdr +
gtp1_header), but the pull requests 20…

NVD

HIGH
CVE-2026-67592
CVE-2026-67592
pkg: apache qpid_protonj2

published: Aug 5, 2026

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.

This issue affects Apache Qpid ProtonJ2: through 1.1.0.

Users are recommended to upgrade to version 1.2.0…

CWE: CWE-770
GitHub-GHSA

HIGH
XSS in Ghost's ActivityPub client
GHSA-xpp7-93×6-v29m
pkg: @tryghost/activitypub
eco: npm
published: Aug 4, 2026
### Impact

The ActivityPub client in Ghost was vulnerable to JavaScript injection on posts shared by a maliciously customised ActivityPub server.

### Vulnerable Versions

This vulnerability is present in the @tryghost/activitypub package up to v3.0.8. All prior versions are also affected.

### Pa…

CVE-2026-53950
NVD

HIGH
CVE-2026-66901
CVE-2026-66901
pkg: jwt

published: Aug 4, 2026

Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated URLs taken from the credentials JSON.

The URLs the library requests are read from the credentials JSON, and their hosts were not checked against the universe domain before the re…

CWE: CWE-201, CWE-918
NVD

HIGH
CVE-2026-47618
CVE-2026-47618
pkg: nvidia dynamo, linux linux_kernel

published: Aug 4, 2026

NVIDIA Dynamo for Linux contains a vulnerability in the Rust multimodal media fetcher where an attacker could cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.
CWE: CWE-918
NVD

HIGH
CVE-2026-47617
CVE-2026-47617
pkg: nvidia dynamo, linux linux_kernel

published: Aug 4, 2026

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery via DNS rebinding. A successful exploit of this vulnerability might lead to information disclosure.
CWE: CWE-918
NVD

HIGH
CVE-2026-47616
CVE-2026-47616
pkg: nvidia dynamo, linux linux_kernel

published: Aug 4, 2026

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.
CWE: CWE-918
NVD

HIGH
CVE-2026-47615
CVE-2026-47615
pkg: nvidia dynamo, linux linux_kernel

published: Aug 4, 2026

NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery by supplying a crafted URL in a multimodal request. A successful exploit of this vulnerability might lead to information disclosure.
CWE: CWE-918
NVD

HIGH
CVE-2026-47614
CVE-2026-47614
pkg: nvidia dynamo, linux linux_kernel

published: Aug 4, 2026

NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.
CWE: CWE-918
NVD

HIGH
CVE-2026-47613
CVE-2026-47613
pkg: nvidia dynamo, linux linux_kernel

published: Aug 4, 2026

NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation of a pathname to a restricted directory by supplying a crafted local path in a multimodal request. A successful exploit of this vulnerability might lead to information disclosure.
CWE: CWE-918
NVD

HIGH
CVE-2026-47612
CVE-2026-47612
pkg: nvidia dynamo, linux linux_kernel

published: Aug 4, 2026

NVIDIA Dynamo for Linux contains a vulnerability in the image loading component where an attacker may cause improper limitation of a pathname to a restricted directory. A successful exploit of this vulnerability might lead to information disclosure.
CWE: CWE-22
NVD

HIGH
CVE-2026-24255
CVE-2026-24255
pkg: nvidia dynamo, linux linux_kernel

published: Aug 4, 2026

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a hash collision by submitting images that share an identical pixel byte sequence but have different dimensions. A successful exploit of this vulnerability might lead to data tampering.
CWE: CWE-1023
NVD

HIGH
CVE-2026-56848
CVE-2026-56848
pkg: node

published: Aug 4, 2026

A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free.

This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.

CWE: CWE-416
NVD

HIGH
CVE-2026-56846
CVE-2026-56846
pkg: node

published: Aug 4, 2026

A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion.

This vulnerability affects Node.js **24.x** and **22.x**.

CWE: CWE-400
GitHub-GHSA

HIGH
fast-uri vulnerable to host confusion via backslash authority introducer
GHSA-7p8r-x3mc-p8w7
pkg: fast-uri, fast-uri, fast-uri
eco: npm
published: Aug 3, 2026
### Impact

`fast-uri` v4.1.1 and earlier require a literal `//` to recognize a URI authority, so a reference that uses `\\`, `/\`, or `\/` as the authority introducer (in place of `//`, after an optional scheme) is parsed with no authority: the sequence and everything after it fold into the path. N…

CVE-2026-18446
GitHub-GHSA

HIGH
Socket.IO: Zero-attachment Memory Exhaustion
GHSA-2m8v-j782-fhvr
pkg: socket.io-parser, socket.io-parser, socket.io-parser
eco: npm
published: Aug 3, 2026
### Impact

A specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory.

### Patches

| Version range | Used by | Fixed version |
|———-…

CVE-2026-69185
GitHub-GHSA

HIGH
brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
GHSA-rgw5-rvv9-x895
pkg: brace-expansion, brace-expansion, brace-expansion
eco: npm
published: Aug 3, 2026
### Summary

The `maxLength` mitigation added in `5.0.8` for GHSA-mh99-v99m-4gvg / CVE-2026-14257 is incomplete. It bounds the accumulator where results are *combined*, but not the intermediate arrays that feed it. A ~25 KB input still crashes the Node process with an **uncatchable** out-of-memory e…

CVE-2026-69152
NVD

HIGH
CVE-2026-19139
CVE-2026-19139
pkg: google chrome, microsoft windows

published: Aug 6, 2026

Race in CredentialProvider in Google Chrome on Windows prior to 151.0.7922.109 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)
CWE: CWE-362, CWE-362
NVD

HIGH
CVE-2026-8470
CVE-2026-8470
pkg: langflow langflow

published: Aug 5, 2026

IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's non-cryptographic random module for generating Fernet encryption keys from user secrets under 32 characters. The deterministic Mersenne Twister PRNG produces identical keys for id…
CWE: CWE-327
GitHub-GHSA

HIGH
Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads
GHSA-v3j7-r9gq-3gjw
pkg: electron, electron, electron
eco: npm
published: Aug 5, 2026
### Impact
A custom scheme registered with `supportFetchAPI: true` but without `corsEnabled: true` was not subject to CORS enforcement. A page loaded from a remote origin could therefore `fetch()` or `XMLHttpRequest` that scheme cross-origin and read the full response body, rather than the read bein…
CVE-2026-70604
NVD

HIGH
CVE-2026-67598
CVE-2026-67598
pkg: tls

published: Aug 3, 2026

Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that allows network-adjacent attackers to intercept outbound HTTPS requests to configured LLM providers by presenting arbitrary TLS certificates, as CURLOPT_SSL_VERIFYPEER and CURLOPT_SSL_…
CWE: CWE-295
GitHub-GHSA

HIGH
undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives
GHSA-4cwx-7wf7-3272
pkg: undici, undici
eco: npm
published: Aug 3, 2026
### Summary

Two issues in undici's cache interceptor, both fixed by the same patch on `lib/util/cache.js`:

1. **Shared-cache disclosure:** Responses with malformed qualified `Cache-Control: private` directives such as `private=""` or `private=","` can be incorrectly stored in the default shared ca…

CVE-2026-13697
NVD

HIGH
CVE-2026-18770
CVE-2026-18770
pkg: python

published: Aug 4, 2026

A vulnerability has been found in vibesurf-ai VibeSurf up to cd6e519d507cdd4d63061300bf60fb176e1f57e0. Impacted is an unknown function of the file /code of the component Python Validation Handler. The manipulation leads to code injection. Remote exploitation of the attack is possible. This product f…
CWE: CWE-74, CWE-94
NVD

HIGH
CVE-2026-16636
CVE-2026-16636
pkg: go

published: Aug 6, 2026

The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Recipient Display Name (to.name) in Email Logs in all versions up to, and including, 2.2.95 due to insufficient input san…
CWE: CWE-79
GitHub-GHSA

HIGH
Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path
GHSA-9f4c-93c8-jc8g
pkg: electron, electron, electron
eco: npm
published: Aug 5, 2026
### Impact
A sandboxed iframe without the `allow-popups` keyword could still open a new window (or trigger `setWindowOpenHandler`) with no user interaction, because new-window navigations taking the OpenURL path did not apply the iframe sandbox popup restriction.

Apps that embed untrusted content i…

CVE-2026-70608
NVD

HIGH
CVE-2026-71269
CVE-2026-71269
pkg: node

published: Aug 5, 2026

Node-RED's local-filesystem library storage module (getLibraryEntry() and saveLibraryEntry() in packages/node_modules/@node-red/runtime/lib/storage/localfilesystem/library.js), reachable via GET/POST /library/:lib/:type/*path, joins the user-supplied path parameter directly into the filesystem path …
CWE: CWE-22
NVD

HIGH
CVE-2026-69246
CVE-2026-69246
pkg: tls

published: Aug 3, 2026

Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host header separately. The cURL handlers set CURLOPT_URL to the URI exactly as written and push that Host into CURLOPT_HTTPHEADER; StreamHandler does the same throug…
CWE: CWE-180, CWE-436, CWE-918, CWE-941
GitHub-GHSA

HIGH
go-git: Worktree operations may follow symlinks
GHSA-hc8v-wwc9-vgxm
pkg: github.com/go-git/go-git/v5, github.com/go-git/go-git/v6
eco: go
published: Aug 7, 2026
## Impact

A symlink traversal issue in `go-git` could allow worktree operations to modify files outside the intended worktree path.

The `worktreeFilesystem` wrapper rejected dangerous path strings, including paths containing `.git`, parent-directory components, or control characters. However, it d…

CVE-2026-71556
NVD

HIGH
CVE-2026-64576
CVE-2026-64576
pkg: linux

published: Aug 5, 2026

In the Linux kernel, the following vulnerability has been resolved:

nexthop: initialize extack in nh_res_bucket_migrate()

nh_res_bucket_migrate() passes an uninitialized netlink_ext_ack to
call_nexthop_res_bucket_notifiers(). When
nh_notifier_res_bucket_info_init() fails (e.g. the kzalloc returns

GitHub-GHSA

HIGH
Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs
GHSA-8x5v-cpv7-8jjp
pkg: open-webui
eco: pip
published: Aug 4, 2026
## Summary

Open WebUI fetches user-supplied URLs on the server for RAG URL ingestion, URL-to-markdown conversion and web-search content retrieval, and decides whether a destination is allowed by asking whether its IP address is globally routable. That test operates on the literal IPv6 address and d…

CVE-2026-70485
NVD

HIGH
CVE-2026-64587
CVE-2026-64587
pkg: linux

published: Aug 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

net: ethernet: arc: emac: quiesce interrupts before requesting IRQ

Normal RX/TX interrupts are enabled later, in arc_emac_open(), so probe
should not see interrupt delivery in the usual case. However, hardware may
still present st…

GitHub-GHSA

HIGH
ngx-extended-pdf-viewer bundles a version of pdf.js vulnerable to CVE-2026-16633
GHSA-w9hm-4m3m-fxmm
pkg: ngx-extended-pdf-viewer
eco: npm
published: Aug 6, 2026
ngx-extended-pdf-viewer embeds a fork of Mozilla's pdf.js rather than depending on pdfjs-dist, so this vulnerability is not visible to dependency scanners through package.json.

### Impact
Opening a malicious PDF can execute attacker-controlled JavaScript in the context of the hosting page. Upstream…

GitHub-GHSA

HIGH
PDF.js: Arbitrary JavaScript execution upon opening a malicious PDF
GHSA-hq66-cqwq-w95j
pkg: pdfjs-dist
eco: npm
published: Aug 6, 2026
### Impact

If PDF.js is used to load a malicious PDF, and PDF.js is configured with `enableScripting` set to true (which is the default value) and no CSP for disallowing script-src, unrestricted attacker-controlled JavaScript will be executed in the context of the hosting domain.

### Patches

### …

CVE-2026-16633
GitHub-GHSA

HIGH
Nx: Zip-Slip in the self-hosted remote cache
GHSA-vp3h-ghgh-jr7g
pkg: nx, @nx/s3-cache, @nx/gcs-cache
eco: npm
published: Aug 6, 2026
## Summary

The Nx **self-hosted HTTP remote cache** extracts downloaded cache artifacts without constraining where files are written. A malicious — or on-path (MITM) — remote cache server can return a crafted tar archive whose entries escape the cache directory and write to arbitrary locations …

CVE-2026-71476
GitHub-GHSA

HIGH
Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth
GHSA-x677-9fxg-v5c5
pkg: github.com/traefik/traefik/v2, github.com/traefik/traefik/v3, github.com/traefik/traefik/v3
eco: go
published: Aug 6, 2026
## Summary

There is a high severity vulnerability in Traefik's BasicAuth, DigestAuth, and ForwardAuth
middlewares. The fix for CVE-2026-33433 stripped canonical-cased spoofed identity headers
(e.g. `X-Auth-User`) before writing Traefik's own value, but did not account for
underscore-variant header …

CVE-2026-54763
GitHub-GHSA

HIGH
Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass
GHSA-8rxv-jg7p-wvg3
pkg: github.com/traefik/traefik/v3
eco: go
published: Aug 6, 2026
## Summary

There is a high severity vulnerability in Traefik's Kubernetes Ingress NGINX provider. When an Ingress uses the `nginx.ingress.kubernetes.io/rewrite-target` annotation with a regular expression that captures attacker-controlled text without requiring a path separator (for example path `/…

CVE-2026-67309
GitHub-GHSA

HIGH
Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool
GHSA-3ccp-42pg-hgv6
pkg: github.com/traefik/traefik/v2, github.com/traefik/traefik/v3, github.com/traefik/traefik/v3
eco: go
published: Aug 6, 2026
## Summary

There is a critical vulnerability in Traefik's default HTTP reverse proxy that leads to unauthenticated cross-user response poisoning. When a client opens an HTTP/2 or HTTP/3 `CONNECT` request, Traefik forwards it — body included — to an HTTP/1.1 upstream over a shared `net/http.Tran…

CVE-2026-71324
GitHub-GHSA

HIGH
rclone: Incomplete path validation allows backend root escape in serve restic
GHSA-45pq-889g-fcgh
pkg: github.com/rclone/rclone
eco: go
published: Aug 5, 2026
## Summary

`rclone serve restic` does not correctly reject URL paths beginning with `../`. On affected backends, an attacker who can access the REST endpoint can read, create, overwrite, or delete objects outside the path configured by the operator.

The issue affects `rclone v1.40` through `rclone…

CVE-2026-71309
GitHub-GHSA

HIGH
Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing Manipulation
GHSA-gmmw-qg98-6j6p
pkg: flowise
eco: npm
published: Aug 4, 2026
### Summary
Several organization billing endpoints accept attacker-controlled Stripe identifiers (subscriptionId) without verifying that the identifier belongs to the authenticated user's organization. This allows an authenticated attacker to perform unauthorized Stripe subscription operations on ot…
CVE-2026-70476
GitHub-GHSA

HIGH
Flowise: Missing Authorization on Execution Update Endpoint
GHSA-fm2f-4339-4p2f
pkg: flowise
eco: npm
published: Aug 4, 2026
# Flowise Security Audit Report
**Date**: 2026-03-17
**Researcher**: Dimpal Jadhav (jadhavdimpy@gmail.com)
**GitHub**: https://github.com/Dimpyj1604
**Target**: FlowiseAI/Flowise (latest main branch)
**Version**: flowise-components@3.1.0

### FINDING 1: Missing Authorization on Execution Update Endp…

CVE-2026-70475
GitHub-GHSA

HIGH
Flowise: Cross-Workspace OAuth2 Credential Metadata Leak
GHSA-wch5-xp77-fxg4
pkg: flowise
eco: npm
published: Aug 4, 2026
## Summary

Three OAuth2 credential endpoints look up credentials by `id` alone with no `workspaceId` filter. Two of these endpoints (`callback`, `refresh`) are whitelisted from all authentication. This allows:

1. **Cross-workspace credential access** — Any authenticated user can initiate OAuth2 …

CVE-2026-70474
GitHub-GHSA

HIGH
Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history
GHSA-fr6g-7cq8-fg82
pkg: flowise
eco: npm
published: Aug 4, 2026
### Summary
The **GET `/api/v1/upsert-history`** endpoint returns the **entire server-wide upsert history** (response size **>100MB**) instead of being scoped to the requesting user/tenant/workspace. The response includes **sensitive configuration data** (e.g., Vector Store settings such as **Qdrant…
CVE-2026-70473
GitHub-GHSA

HIGH
Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store
GHSA-chm3-vqcf-52rx
pkg: flowise
eco: npm
published: Aug 4, 2026
# Summary

These endpoints accept a client-controlled `credential` parameter. The server loads credentials by `id` and uses them directly, without checking whether that credential belongs to the caller’s workspace. If an attacker knows another workspace’s `credentialId`, they can use that works…

CVE-2026-70472
GitHub-GHSA

HIGH
Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys
GHSA-88pr-878c-24wf
pkg: flowise-components, flowise
eco: npm
published: Aug 4, 2026
## Summary

Flowise on current `main` allows an authenticated…

GitHub-GHSA

HIGH
Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure
GHSA-8r8h-6vcc-xhrv
pkg: flowise
eco: npm
published: Aug 4, 2026
## Finding — Unauthorized Workspace Variables disclosure via $vars injection (bypasses variables:view)

### What’s wrong (code locations)

– Variables for the active workspace are fetched without checking “variables:view” at this call site: flowise-src/
packages/components/src/utils.…

CVE-2026-70471
GitHub-GHSA

HIGH
Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)
GHSA-xc48-889x-5qmw
pkg: flowise, flowise-components
eco: npm
published: Aug 4, 2026
## Summary

The mitigation shipped for CVE-2025-8943 blocks the `-y` and `–yes` flags on `npx` to stop auto-installation of arbitrary packages. That flag filter works. The environment-variable check in the same patch denies only four variable names by exact string match, and `npm` reads its configu…

CVE-2026-69263
GitHub-GHSA

HIGH
Flowise: `DELETE /api/v1/chatflows/:id` does not validate resource type, allowing `agentflows:delete` and `chatflows:delete` to delete each other’s flow type
GHSA-p5w8-m249-4r4v
pkg: flowise
eco: npm
published: Aug 4, 2026
# summary:
In Flowise, `DELETE /api/v1/chatflows/:id` authorizes requests with `checkAnyPermission('chatflows:delete,agentflows:delete')`. Possession of either permission is sufficient to reach the delete path. The delete logic does not validate the target resource `type`, allowing a caller with onl…
CVE-2026-69262
GitHub-GHSA

HIGH
Flowise: Unauthenticated Property Injection into Flow Execution Context via Ungated `overrideConfig` Spread in Prediction API
GHSA-6vh2-wg4h-4vwj
pkg: flowise
eco: npm
published: Aug 4, 2026
#### Summary

The `POST /api/v1/prediction/:id` endpoint — which is unauthenticated (whitelisted in `WHITELIST_URLS`) — accepts an `overrideConfig` object in the request body. This object is unconditionally spread into the internal `flowConfig` and `flowData` objects at two locations in the code…

CVE-2026-69258
GitHub-GHSA

HIGH
Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses
GHSA-c6xh-wv4j-ppv5
pkg: flowise
eco: npm
published: Aug 4, 2026
## Summary

Flowise's HTTP security module (`httpSecurity.ts`) fails to normalize IPv4-mapped IPv6 addresses (e.g., `::ffff:127.0.0.1`, `::ffff:169.254.169.254`) before checking them against the deny list. Due to an `ipaddr.js` kind mismatch (`ipv6` vs `ipv4`), all IPv4 CIDR deny rules are silently …

CVE-2026-69257
GitHub-GHSA

HIGH
Flowise: Missing authorization on `/api/v1/files` allows low-privileged API keys to list and delete files across workspaces within the same organization
GHSA-wp74-f5hh-5f3r
pkg: flowise
eco: npm
published: Aug 4, 2026
# summary:
In Flowise, the `/api/v1/files` route is protected only by the `feat:files` feature gate and does not enforce `checkPermission(…)` on either `GET` or `DELETE`. As a result, any authenticated API key within the organization, even one with unrelated permissions, can list and delete files …
CVE-2026-69252
GitHub-GHSA

HIGH
Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret Exfiltration
GHSA-r745-8hwv-h473
pkg: flowise
eco: npm
published: Aug 4, 2026
### Summary

The OAuth2 token refresh endpoint (`POST /api/v1/oauth2-credential/refresh/:credentialId`) is unauthenticated by design (it is in the public whitelist) and performs a server-side HTTP request to a credential-controlled URL (`accessTokenUrl`) without SSRF protections. In runtime validati…

CVE-2026-69250
GitHub-GHSA

HIGH
python-cryptography: Duplicate self-signed intermediates can cause exponential path-building
GHSA-jwv3-5hgf-82ww
pkg: cryptography
eco: pip
published: Aug 3, 2026
### Summary
When resolving invalid certificate chains that include duplicate copies of self-signed certificates, the processing recursively invokes the same candidate, leading to an exponential blowup. Although the limitation that the chain depth cannot exceed a specified maximum depth prevents unbo…
CVE-2026-69249
GitHub-GHSA

HIGH
cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing
GHSA-g6cj-pr64-35w5
pkg: cryptography
eco: pip
published: Aug 3, 2026
### Summary

`pkcs7_decrypt_der`, `pkcs7_decrypt_pem`, and `pkcs7_decrypt_smime` reported the
outcome of decrypting a `RecipientInfo`'s `encryptedKey` in several
distinguishable ways, one of which disclosed the exact length recovered from the
RSA operation. The same distinction was also observable b…

CVE-2026-69247
GitHub-GHSA

HIGH
AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)
GHSA-cq5v-8q36-5273
pkg: aiohttp
eco: pip
published: Aug 3, 2026
### Summary

An out-of-bounds heap read could occur in the C response parser while building an error message for a malformed response.

### Impact

An attacker controlled server, or possibly an accidental response could trigger a DoS in the client.

### Workaround

If unable to upgrade, the Python p…

CVE-2026-69244
GitHub-GHSA

HIGH
ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass
GHSA-mwp4-54f8-5fhr
pkg: ip-address
eco: npm
published: Aug 3, 2026
### Summary

`Address4` accepts an octet written with a leading zero and decodes it as decimal, while the WHATWG URL host parser, `inet_aton`, and `getaddrinfo` all decode a leading zero as octal. The library and the network stack therefore disagree about which host a string names. `new Address4('01…

CVE-2026-69192
GitHub-GHSA

HIGH
Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes
GHSA-jj27-h5hq-8×99
pkg: @angular/compiler, @angular/compiler, @angular/compiler
eco: npm
published: Aug 3, 2026
A Cross-Site Scripting (XSS) vulnerability has been identified in the Angular compiler's internationalization (i18n) pipeline. Although Angular disallows binding to event-handler attributes such as `onclick` and `onerror` through standard attribute validation (`validateAttribute()` / `validateProper…
CVE-2026-69151
NVD

MEDIUM
CVE-2026-71313
CVE-2026-71313
pkg: windows

published: Aug 5, 2026

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From v1.51.0 until v1.75.0, the local backend in backend/local/local.go relies on the configurable filename encoder to prevent remote filename data from becoming operating-system path syntax…
CWE: CWE-22
GitHub-GHSA

MEDIUM
rclone: Local Encoding Path Traversal
GHSA-7p4m-qxvv-g567
pkg: github.com/rclone/rclone
eco: go
published: Aug 5, 2026
## Summary

The local backend relies on its configurable filename encoder to prevent remote filename data from becoming operating-system path syntax. If a local destination uses an encoding that omits `Dot`, such as `Slash`, `None`, or `Raw`, a remote object's standard-encoded `..` component is …

CVE-2026-71313
NVD

MEDIUM
CVE-2026-70611
CVE-2026-70611
pkg: windows

published: Aug 5, 2026

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.1, and 42.0.0-beta.3, the DevTools reveal in file manager action could launch the target file rather than reveal it. An attacker with a separate means of running scri…
CWE: CWE-78
GitHub-GHSA

MEDIUM
Electron: DevTools embedder handler executes arbitrary files via shell open
GHSA-f2r8-jv7c-xqmp
pkg: electron, electron, electron
eco: npm
published: Aug 5, 2026
### Impact
The DevTools "reveal in file manager" action could launch the target file rather than reveal it. An attacker with a separate means of running script inside the DevTools frontend (such as a malicious DevTools extension) could use this to execute native code outside the sandbox.

Apps are o…

CVE-2026-70611
NVD

MEDIUM
CVE-2026-19017
CVE-2026-19017
pkg: jwt

published: Aug 7, 2026

Consul Community Edition and Consul Enterprise 1.18.21 through 2.0.2 are vulnerable to a partial arbitrary file read when configured to use the Vault Connect CA provider with JWT or AppRole authentication. A privileged attacker with `operator:write` permission may direct Consul to read and forward c…
CWE: CWE-862
GitHub-GHSA

MEDIUM
AWS CLI: Disabled SSH host key verification in Amazon AWS CLI EMR helper commands
GHSA-hqvf-45jj-mccq
pkg: awscli
eco: pip
published: Aug 6, 2026
### Summary
The AWS Command Line Interface (AWS CLI) is a unified tool to manage AWS services from the command line. An issue exists where the EMR SSH helper commands (`aws emr ssh`, `aws emr socks`, `aws emr put`, `aws emr get`) passed `StrictHostKeyChecking=no` to the underlying SSH client, disabl…
CVE-2026-18654
NVD

MEDIUM
CVE-2026-70594
CVE-2026-70594
pkg: node

published: Aug 4, 2026

Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions on login which could have allowed for session fixation attacks. Successful exploitation would have required another vulnerability on the same domain where Ghost Admin was hosted. T…
CWE: CWE-384
GitHub-GHSA

MEDIUM
Ghost: Session Fixation in Ghost Admin
GHSA-7mpp-r37j-x5wh
pkg: ghost
eco: npm
published: Aug 4, 2026
### Impact

Ghost Admin did not invalidate existing sessions on login which could have allowed for session fixation attacks. Successful exploitation would have required another vulnerability on the same domain where Ghost Admin was hosted.

### Vulnerable versions

This vulnerability is present in G…

CVE-2026-70594
NVD

MEDIUM
CVE-2026-70602
CVE-2026-70602
pkg: windows

published: Aug 5, 2026

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, extension tab and scripting APIs were not scoped to the extension's own session. A malicious or compromised extension loaded into one session co…
CWE: CWE-284
GitHub-GHSA

MEDIUM
Electron: Extension tab APIs operate across session boundaries
GHSA-m55f-7gqj-fr98
pkg: electron, electron, electron
eco: npm
published: Aug 5, 2026
### Impact
Extension tab and scripting APIs were not scoped to the extension's own `session`. A malicious or compromised extension loaded into one session could navigate, script, and read from windows belonging to a different session.

Apps are only affected if they load Chrome extensions via `sessi…

CVE-2026-70602
NVD

MEDIUM
CVE-2026-70593
CVE-2026-70593
pkg: node

published: Aug 4, 2026

Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a vulnerability in custom themes allowed a staff user to write files outside of the uploads directory. This could be used to alter the behavior of the installation through custom theme upload path traversal in LocalStorageBase a…
CWE: CWE-22
GitHub-GHSA

MEDIUM
Ghost: Theme Upload Path Traversal
GHSA-cjc9-q5gf-327p
pkg: ghost
eco: npm
published: Aug 4, 2026
### Impact

A vulnerability in custom themes allowed a staff user to write files outside of the uploads directory. This could be used to alter the behavior of the installation.

### Vulnerable versions

This vulnerability is present in Ghost from v0.10.0 up to v6.54.0.

### Patches

v6.54.1 contains…

CVE-2026-70593
NVD

MEDIUM
CVE-2026-47619
CVE-2026-47619
pkg: nvidia dynamo, linux linux_kernel

published: Aug 4, 2026

NVIDIA Dynamo for Linux examples and recipes contain a vulnerability where an attacker could cause a system failure. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.
CWE: CWE-1357
GitHub-GHSA

MEDIUM
Netty: RedisArrayAggregator max-elements failure leaves retained partial aggregate state
GHSA-p9jm-q85p-7mcp
pkg: io.netty:netty-codec-redis, io.netty:netty-codec-redis
eco: maven
published: Aug 7, 2026
## Summary

`RedisArrayAggregator` clears retained partial aggregate state when the `maxNestedArrayDepth` limit is exceeded, but it does not clear the same state when the sibling `maxElements` limit is exceeded. A peer can start a valid RESP array, send a bulk-string child, then send a nested array …

CVE-2026-56818
GitHub-GHSA

MEDIUM
GitPython: Arbitrary file read via –pathspec-from-file in IndexFile.remove() and Head.checkout()
GHSA-hh9p-6wh2-4mfc
pkg: GitPython
eco: pip
published: Aug 7, 2026
## Summary

`IndexFile.remove()` and `Head.checkout()` forward `**kwargs` into `git rm` and `git checkout`
with no guard. Passing `–pathspec-from-file=<file>` **together with `–pathspec-file-nul`**
makes Git treat the whole file as a single NUL-delimited pathspec, and the unmatched-pathspec
error …

NVD

MEDIUM
CVE-2026-14204
CVE-2026-14204
pkg: go

published: Aug 6, 2026

The Google Authenticator WordPress plugin before 0.56 does not verify a CSRF nonce when saving its two-factor setup, allowing attackers to trick a logged-in user into overwriting their own 2FA secret with an attacker-controlled value, which enables two-factor authentication and locks the victim out …
CWE: CWE-352
GitHub-GHSA

MEDIUM
rclone: Path traversal in serve s3 allows reading and overwriting root-level files
GHSA-8v25-v8p6-qf7v
pkg: github.com/rclone/rclone
eco: go
published: Aug 5, 2026
### Summary

rclone serve s3 allows a client to read and write files at the root of the remote which would normally be inaccessible by using dot-dot path segments in the object key. It does not allow reading files outside of the root. A request such as GET /bucket/../root-secret.txt is handled as an…

NVD

MEDIUM
CVE-2026-70616
CVE-2026-70616
pkg: go

published: Aug 5, 2026

boringproxy through 0.10.0 contains a resource exhaustion vulnerability that allows any authenticated user to permanently exhaust server file descriptors, goroutines, and memory by sending requests to the GET /loading endpoint with attacker-supplied id query parameter values. Because the handler per…
CWE: CWE-833
NVD

MEDIUM
CVE-2026-7658
CVE-2026-7658
pkg: langflow langflow

published: Aug 5, 2026

IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate the username field, allowing attackers to inject path traversal sequences and bypass containment checks. This enables multiple severe impacts, including arbitrary directory deletion, cross-tenant data destruction, and JWT signing key d…
CWE: CWE-22
NVD

MEDIUM
CVE-2026-7646
CVE-2026-7646
pkg: langflow langflow

published: Aug 5, 2026

IBM Langflow OSS 1.0.0 through 1.10.3 allows users to read arbitrary files from the server filesystem, including other users' uploaded documents, the JWT signing secret, the SQLite database, and process environment variables, by sending a crafted MCP `resources/read` request with a URL-encoded path …
CWE: CWE-22
NVD

MEDIUM
CVE-2026-71244
CVE-2026-71244
pkg: oauth

published: Aug 5, 2026

Paperless-ngx's MailAccountViewSet.test() action, when called with an existing account's ID and a masked password field, reuses the stored password, account_type, refresh_token, and expiration from that existing account while allowing the caller to supply a different imap_server, imap_port, and imap…
CWE: CWE-918
NVD

MEDIUM
CVE-2026-71208
CVE-2026-71208
pkg: kubernetes

published: Aug 5, 2026

KubeSphere's cluster-controller reconciliation (pkg/utils/clusterclient/clusterclient.go, addCluster) processes every Cluster custom resource's connection configuration and immediately calls Discovery().ServerVersion() against the CRD-specified Kubernetes API endpoint, which is parsed only for URL s…
CWE: CWE-918
NVD

MEDIUM
CVE-2026-68080
CVE-2026-68080
pkg: apache qpid_broker-j

published: Aug 5, 2026

It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.

This issue affects Apache Qpid Broker-J: through 10.0.1.

Users are recommended to upgrade to version 10.1.…

CWE: CWE-406
NVD

MEDIUM
CVE-2026-68078
CVE-2026-68078
pkg: apache qpid_broker-j

published: Aug 5, 2026

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.

This issue affects Apache Qpid Broker-J: through 10.0.1.

Users are recommended to upgrade to version 10.1…

CWE: CWE-770
NVD

MEDIUM
CVE-2026-67555
CVE-2026-67555
pkg: apache qpid_proton-dotnet

published: Aug 5, 2026

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service

This issue affects Apache Qpid Proton-Dotnet: through 1.0.0.

Users are recommended to upgrade to version 1…

CWE: CWE-770
NVD

MEDIUM
CVE-2026-66277
CVE-2026-66277
pkg: apache qpid_proton-j

published: Aug 5, 2026

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.

This issue affects Apache Qpid Proton-J: through 0.34.1.

Users are recommended to upgrade to version 0.35…

CWE: CWE-770
NVD

MEDIUM
CVE-2026-70493
CVE-2026-70493
pkg: python

published: Aug 4, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the built-in knowledge search path in backend/open_webui/tools/knowledge_fs.py and backend/open_webui/tools/builtin.py let a chat participant choose a pattern used to grep knowledge files. …
CWE: CWE-1333
NVD

MEDIUM
CVE-2026-70491
CVE-2026-70491
pkg: python

published: Aug 4, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. In 0.10.2 and earlier, the GET /api/v1/tools/, GET /api/v1/tools/list, and GET /api/v1/tools/id/{id} endpoints in backend/open_webui/routers/tools.py returned full Python tool source to authenticated non-admin read…
CWE: CWE-200
GitHub-GHSA

MEDIUM
Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically
GHSA-2f54-p244-32q6
pkg: open-webui
eco: pip
published: Aug 4, 2026
## Summary
The built-in knowledge search tools let a chat participant choose the pattern used to grep knowledge files. Patterns containing regex metacharacters were compiled with Python's backtracking `re` engine and run against every line of every reachable file, with no time limit anywhere on that…
CVE-2026-70493
GitHub-GHSA

MEDIUM
Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints
GHSA-3r7g-q6cg-q2vx
pkg: open-webui
eco: pip
published: Aug 4, 2026
## Summary

A workspace tool shared with a read grant returned its full Python source to the recipient. Any authenticated non-admin who could use a shared tool could also read its source, including any user on the instance when a tool was shared publicly. Source is meant to be a writer-only tier: th…

CVE-2026-70491
GitHub-GHSA

MEDIUM
Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing
GHSA-73cq-mcgh-379c
pkg: open-webui
eco: pip
published: Aug 4, 2026
## Summary
In every affected release, automation recurrence parsing anchors minutely and hourly rules at a fixed date of 2000-01-01 and then walks forward one interval at a time to find the next run. A single `FREQ=MINUTELY` rule therefore enumerates roughly a quarter-century of occurrences, synchro…
CVE-2026-70489
NVD

MEDIUM
CVE-2026-47621
CVE-2026-47621
pkg: nvidia dynamo, linux linux_kernel

published: Aug 4, 2026

NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager singleton initialization. A successful exploit of this vulnerability might lead to denial of service and data tampering.
CWE: CWE-367
NVD

MEDIUM
CVE-2026-47620
CVE-2026-47620
pkg: nvidia dynamo, linux linux_kernel

published: Aug 4, 2026

NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager singleton initialization. A successful exploit of this vulnerability might lead to data tampering and denial of service.
CWE: CWE-362
GitHub-GHSA

MEDIUM
Flowise: Incomplete Credential Redaction Exposes Secrets via API
GHSA-rwrp-9823-p2xq
pkg: flowise
eco: npm
published: Aug 4, 2026
## Summary

The `GET /api/v1/credentials/:id` endpoint decrypts stored credential data and returns it in the `plainDataObj` field of the API response. While a `redactCredentialWithPasswordType()` function masks fields defined with `type: 'password'` in their component schema, many credential types s…

NVD

MEDIUM
CVE-2026-67199
CVE-2026-67199
pkg: express

published: Aug 4, 2026

Perspective 5.0.0 contains a denial of service vulnerability that allows remote attackers to block the server event loop indefinitely by submitting a crafted expression containing unbounded for or while loop constructs in a TableMakeViewReq message. Attackers can embed an arbitrarily large iteration…
CWE: CWE-770
NVD

MEDIUM
CVE-2026-63248
CVE-2026-63248
pkg: eclipse milo

published: Aug 4, 2026

In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An anonymous client can enable diagnostics over a None/None endpoint without a certificate; with a trusted client application certificate over SignAndEncrypt, it can read security diagn…
CWE: CWE-862
NVD

MEDIUM
CVE-2026-69245
CVE-2026-69245
pkg: go

published: Aug 3, 2026

Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of a cookie Domain that cookie unless SetCookie::matchesDomain() recognizes the Domain as an IP literal or a numeric host, and the decision comes from the domain's own text, so two sp…
CWE: CWE-180, CWE-346, CWE-384
NVD

MEDIUM
CVE-2026-18655
CVE-2026-18655
pkg: oauth

published: Aug 3, 2026

Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before 2.0.24 may allow a remote unauthenticated actor (via prompt injection) to obtain Amazon MQ for RabbitMQ broker credentials or OAuth access tokens sent …
CWE: CWE-923
GitHub-GHSA

MEDIUM
GitPython: Incomplete unsafe_git_archive_options denylist omits –add-file / –add-virtual-file, enabling arbitrary file read via Repo.archive()
GHSA-539m-9xh6-q6rr
pkg: GitPython
eco: pip
published: Aug 3, 2026
**Target:** gitpython-developers/GitPython
**Tested:** HEAD `07e80555` (2026-07-25), latest release 3.1.55, `git version 2.50.1`

## Summary

`Repo.archive()` does call the option guard, so this is not a missing-guard report. The guard is present and working; the **denylist it consults is incomplete…

GitHub-GHSA

MEDIUM
Russh: Channel-scoped server callbacks can be reached without an open channel
GHSA-m65r-rprj-r5rg
pkg: russh
eco: rust
published: Aug 3, 2026
There is a server-side channel state issue in `russh`.

After a client is authenticated, `russh` can dispatch channel-scoped handler callbacks for recipient channel IDs that were never opened or confirmed. In the strongest reproduced case, the client does not send `SSH_MSG_CHANNEL_OPEN` at all. It a…

CVE-2026-68930
NVD

MEDIUM
CVE-2026-69087
CVE-2026-69087
pkg: express

published: Aug 3, 2026

The Grav form plugin (getgrav/grav-plugin-form) before 9.1.13 contains an open redirect vulnerability. Since v9.1.11, the redirect process action evaluates user-supplied form data inside Twig expressions, and Grav::redirect() accepts external URLs without origin validation. When a form blueprint def…
CWE: CWE-601
GitHub-GHSA

MEDIUM
rclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Preserves Newlines
GHSA-8c48-q9wj-3w37
pkg: github.com/rclone/rclone
eco: go
published: Aug 5, 2026
## 1. Summary

A valid but nondefault FTP filename encoding can restore raw CR/LF immediately before an attacker-controlled path is interpolated into the line-oriented FTP control channel. The dependency does not reject CR or LF in command arguments, so a filename can inject an independent authentic…

CVE-2026-71311
NVD

MEDIUM
CVE-2026-19243
CVE-2026-19243
pkg: react

published: Aug 7, 2026

A security vulnerability has been detected in HKUDS nanobot up to 0.2.1. Impacted is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component Shell Allowlist Handler. Such manipulation leads to os command injection. The attack can be executed rem…
CWE: CWE-77, CWE-78
NVD

MEDIUM
CVE-2026-47363
CVE-2026-47363
pkg: oauth

published: Aug 7, 2026

In versions of the Datadog Android application prior to v541-5.9.2, the exported launcher activity AppActivity accepts an attacker-supplied session (including OAuth tokens) from Intent extras with no permission guard, and signs the app into that session without validating it against the backend.
Th…
CWE: CWE-926
GitHub-GHSA

MEDIUM
go-git: Malicious reference names may modify files outside the reference storage
GHSA-qgq7-7hm3-q39j
pkg: github.com/go-git/go-git/v5, github.com/go-git/go-git/v6
eco: go
published: Aug 7, 2026
### Impact
A path traversal issue in `go-git` could allow malicious reference names to access files outside the repository's intended reference storage.

Loose references are stored under `.git/<reference-name>`. The reference name was previously used as a path without verifying that the resolved pa…

CVE-2026-71557
NVD

MEDIUM
CVE-2026-19022
CVE-2026-19022
pkg: go

published: Aug 6, 2026

A vulnerability was determined in OpenHands up to 0.62.0. The affected element is the function initialize_repo of the file OpenHands/resolver/send_pull_request.py. This manipulation causes command injection. Remote exploitation of the attack is possible. The vendor deleted the original GitHub issue …
CWE: CWE-74, CWE-77
NVD

MEDIUM
CVE-2026-70597
CVE-2026-70597
pkg: node

published: Aug 5, 2026

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, the check Electron uses on macOS to confirm it was launched by a same-signed parent process could be bypassed by a local process. Apps that enab…
CWE: CWE-367
GitHub-GHSA

MEDIUM
Electron: Parent process code-sign check is spoofable
GHSA-jm7p-cc5g-qwxx
pkg: electron, electron, electron
eco: npm
published: Aug 5, 2026
### Impact
On macOS, the check Electron uses to confirm it was launched by a same-signed parent process could be bypassed by a local process. Apps that enable the fuse-based hardening restricting `ELECTRON_RUN_AS_NODE` and `NODE_OPTIONS` to same-signed parents rely on this check; a local attacker co…
CVE-2026-70597
NVD

MEDIUM
CVE-2026-70490
CVE-2026-70490
pkg: jwt

published: Aug 4, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, the terminal WebSocket route in backend/open_webui/routers/terminals.py authenticated its own first-message JWT and never applied the verified-user role gate that get_verified_user enforces…
CWE: CWE-863
NVD

MEDIUM
CVE-2026-54020
CVE-2026-54020
pkg: oauth

published: Aug 4, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.11.0, Open WebUI resolved a hostname during URL validation and rejected private, loopback, and link-local addresses, but the HTTP clients resolved the hostname again at connection time. An authenticated …
CWE: CWE-367, CWE-918
GitHub-GHSA

MEDIUM
Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check
GHSA-5gpj-vj23-vhhv
pkg: open-webui
eco: pip
published: Aug 4, 2026
## Summary
The terminal WebSocket route authenticates its own first-message JWT instead of going through the HTTP dependency chain, and never applies the role check that `get_verified_user` enforces on every HTTP terminal route. An account whose role is `pending`, meaning registered but not approved…
CVE-2026-70490
GitHub-GHSA

MEDIUM
Open WebUI: DNS Rebinding SSRF Bypass
GHSA-h6x2-583h-x99r
pkg: open-webui
eco: pip
published: Aug 4, 2026
## Summary
Open WebUI vetted user-supplied URLs by resolving the hostname once and rejecting private, loopback and link-local addresses, then let the HTTP client resolve that hostname again at connect time. An attacker who controls the authoritative DNS for a hostname they submit can answer with a p…
CVE-2026-54020
NVD

MEDIUM
CVE-2026-71430
CVE-2026-71430
pkg: express

published: Aug 6, 2026

node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.25.1, the WrappedRE2::Replace function built its replacement result and passed it to V8 using ToLocalChecked without checking for the empty MaybeLocal that V8 returns when the resulting string or buffer exceeds V8's ma…
CWE: CWE-617
GitHub-GHSA

MEDIUM
node-re2: String.prototype.replace(re2, template) aborts the Node process (uncatchable ToLocalChecked on empty MaybeLocal) when the result exceeds V8's max string length
GHSA-8hcv-x26h-mcgp
pkg: re2
eco: npm
published: Aug 6, 2026
## Description

`WrappedRE2::Replace` builds the replacement result and hands it to V8 with `.ToLocalChecked()` **without checking for the empty `MaybeLocal`** that V8 returns when the string/buffer exceeds its maximum length:

`lib/replace.cc` (v1.24.1):
“`cpp
// L553 — Buffer return path
info.G…

CVE-2026-71430
NVD

MEDIUM
CVE-2026-58045
CVE-2026-58045
pkg: node

published: Aug 4, 2026

A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion in the synchronous `node:zlib` APIs, causing the entire process to crash. All 11 synchronous zlib functions are affected.

Repeated exploitation of this condition can result in a denial of service.

Thi…

CWE: CWE-400
NVD

MEDIUM
CVE-2026-71286
CVE-2026-71286
pkg: express

published: Aug 5, 2026

The render-template component of ember-dynamic-render-template (addon/components/render-template.js) passes its `templateString` property directly into Ember/Glimmer's compileTemplate() (from @ember/template-compilation) with no sanitization, allow-listing, or validation of the input. Because compil…
CWE: CWE-1336
NVD

MEDIUM
CVE-2026-16792
CVE-2026-16792
pkg: tls

published: Aug 4, 2026

An improper certificate validation vulnerability was reported in multiple Lenovo XClarity Orchestrator (LXCO) 2.2.0 microservices that could allow an adjacent network attacker to intercept sensitive communications by performing a machine-in-the-middle attack against HTTPS connections during TLS cert…
CWE: CWE-295
GitHub-GHSA

MEDIUM
Electron: shell.openPath path validation bypass via embedded null byte
GHSA-5c9j-mhmv-5xgx
pkg: electron, electron, electron
eco: npm
published: Aug 5, 2026
### Impact
`shell.openPath()` did not reject paths containing embedded null bytes. Apps that perform string-only validation of file paths (for example, checking the file extension) before passing them to `shell.openPath()` could be bypassed, allowing an attacker-controlled path to open a different f…
CVE-2026-70603
GitHub-GHSA

MEDIUM
rclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone Memory
GHSA-xhf4-832v-7xcr
pkg: github.com/rclone/rclone
eco: go
published: Aug 5, 2026
## 1. Summary

The shared HTTP CONNECT helper parses a proxy response with `http.ReadResponse` over an unrestricted buffered reader. The production helper accepted a valid response containing a 2 MiB header in three consecutive runs. A malicious or compromised configured proxy, or an active on-path …

CVE-2026-71310
GitHub-GHSA

MEDIUM
Electron: ProtocolResponse.url reuses the default session cache instead of the registering session
GHSA-r4w5-6pfg-jxp5
pkg: electron, electron, electron
eco: npm
published: Aug 5, 2026
### Impact
When a custom protocol handler returned a `ProtocolResponse` with a `url` and no `session`, Electron made the upstream request through `defaultSession` instead of the session that handled the protocol. A cached response could then be reused across otherwise isolated session partitions.

A…

CVE-2026-70606
GitHub-GHSA

MEDIUM
Electron: HTTP redirect followed into local file loader
GHSA-v64r-4m7r-3mvq
pkg: electron, electron, electron
eco: npm
published: Aug 5, 2026
### Impact
When following HTTP redirects, `net.fetch()` and `net.request()` did not restrict which schemes a redirect could target. A remote server could redirect a request to a local resource, and if the app returns or forwards the response body, local file contents could be disclosed.

Apps are on…

CVE-2026-70605
GitHub-GHSA

MEDIUM
Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin
GHSA-9pf5-hg6p-4pwp
pkg: electron, electron, electron
eco: npm
published: Aug 5, 2026
### Impact
For serial-port and media (camera / microphone) permission checks made from an iframe, the `requestingOrigin` passed to `session.setPermissionCheckHandler` was the top-level frame's origin rather than the requesting frame's. Origin-based handler logic could therefore grant a cross-origin …
CVE-2026-70599
NVD

MEDIUM
CVE-2026-48154
CVE-2026-48154
pkg: go

published: Aug 4, 2026

GoRest is a Golang starter kit built with the Gin framework for prototyping and developing RESTful APIs. In versions prior to 1.12.2 nMemorySecret2FA contains a race condition due to an unsynchronized package-level map used to store 2FA secrets. Multiple HTTP handlers in handler/login.go and handler…
CWE: CWE-362
NVD

MEDIUM
CVE-2026-58042
CVE-2026-58042
pkg: node

published: Aug 4, 2026

A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process When a DNS Response Contains More Than 256 A Records.

Repeated triggering of this condition can lead to denial of service.

This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.

CWE: CWE-400
GitHub-GHSA

MEDIUM
undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives
GHSA-jr45-8vmc-qm54
pkg: undici, undici
eco: npm
published: Aug 3, 2026
## Impact

Undici's cache interceptor mishandles optional whitespace (OWS) placed around the `=` of a qualified `no-cache` or `private` Cache-Control directive, such as `no-cache ="authorization"` (OWS before `=`) or `no-cache= "authorization"` (OWS after `=`). The parser either drops the directive …

CVE-2026-14643
GitHub-GHSA

MEDIUM
Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false
GHSA-3q9r-p662-5j8m
pkg: github.com/traefik/traefik/v2, github.com/traefik/traefik/v3, github.com/traefik/traefik/v3
eco: go
published: Aug 6, 2026
## Summary

There is a medium severity vulnerability in Traefik's ForwardAuth middleware. Even when configured with `trustForwardHeader: false`, Traefik derives the `X-Forwarded-Port` header sent to the authentication service from the original incoming request instead of the sanitized forwarded requ…

CVE-2026-54764
GitHub-GHSA

MEDIUM
Ghost: Private IP filtering bypass to make server-side requests to internal services
GHSA-wvp2-4qqp-4h3r
pkg: ghost
eco: npm
published: Aug 4, 2026
### Impact

When making an external request, it is possible to bypass the IP filter that ensures the request isn't going to an internal service using an IPv6 literal which maps to a private IPv4 address.

### Vulnerable versions

This vulnerability is present in Ghost from v6.0.9 up to v6.21.0.

###…

CVE-2026-53944
NVD

MEDIUM
CVE-2026-70609
CVE-2026-70609
pkg: node

published: Aug 5, 2026

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1, the mode option of webContents.openDevTools() was not sanitized before use by the DevTools frontend. If an attacker can influence this value, sc…
CWE: CWE-94, CWE-116
GitHub-GHSA

MEDIUM
Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter
GHSA-4f78-qhmw-8j8m
pkg: electron, electron, electron
eco: npm
published: Aug 5, 2026
### Impact
The `mode` option of `webContents.openDevTools()` was not sanitized before use by the DevTools frontend. If an attacker can influence this value, script under their control may run in the DevTools context, which in unsandboxed configurations has access to Node.js.

Apps are only affected …

CVE-2026-70609
NVD

MEDIUM
CVE-2026-70592
CVE-2026-70592
pkg: node

published: Aug 4, 2026

Ghost is a Node.js content management system. From 1.20.1 until 6.54.1, an Administrator-level user could remotely overwrite certain files on the filesystem through the database backup filename, leading to integrity and availability issues. The database export endpoint failed to reject path separato…
CWE: CWE-22
GitHub-GHSA

MEDIUM
Ghost: Database Backup Path Traversal
GHSA-cj62-hvv2-2q5h
pkg: ghost
eco: npm
published: Aug 4, 2026
### Impact

An Administrator-level user could remotely overwrite certain files on the filesystem leading to integrity and availability issues.

### Vulnerable versions

This vulnerability is present in Ghost from 1.20.1 up to v6.54.0.

### Patches

v6.54.1 contains a fix for this issue.

### How to …

CVE-2026-70592
GitHub-GHSA

MEDIUM
Electron: Sandboxed iframes can launch external protocol handlers
GHSA-p2rr-rvmm-c5fp
pkg: electron, electron, electron
eco: npm
published: Aug 5, 2026
### Impact
Requests to open external protocol URLs from web content did not take iframe sandbox restrictions into account, so a sandboxed iframe could cause an OS-registered external application to be launched. The frame's sandbox state was also not made available to the app's permission handlers.

CVE-2026-70612
GitHub-GHSA

MEDIUM
Electron: contextBridge object copy honors prototype setters
GHSA-ff2p-hmqr-hxm4
pkg: electron, electron, electron
eco: npm
published: Aug 5, 2026
### Impact
Objects copied across the `contextBridge` boundary from untrusted content could carry an attacker-influenced prototype, enabling prototype-pollution-style attacks against preload code despite context isolation being enabled.

Apps are only affected if their preload code accepts object arg…

CVE-2026-70610
GitHub-GHSA

MEDIUM
Ghost: Mobiledoc image-size fetch SSRF
GHSA-g366-23fw-ggp6
pkg: ghost
eco: npm
published: Aug 4, 2026
### Impact

When re-rendering posts, Ghost would refetch missing image dimensions by issuing an outbound HTTP request to the URL stored on an image card — without restricting that URL to trusted image hosts. An authenticated staff user able to create or edit posts could therefore point an image ca…

CVE-2026-53946
GitHub-GHSA

MEDIUM
Ghost: File Upload Content-Type Spoofing
GHSA-944x-pm95-3jpr
pkg: ghost
eco: npm
published: Aug 4, 2026
### Impact

Insufficient validation of the client-supplied `Content-Type` on Ghost's Admin API file upload endpoint allowed uploaded files to be served from the site with an attacker-chosen content type on S3/GCS storage backends. On installations that serve uploaded files from the same origin as th…

CVE-2026-53948
GitHub-GHSA

MEDIUM
Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages
GHSA-mj5r-jf49-m3w7
pkg: open-webui
eco: pip
published: Aug 4, 2026
## Summary
On standard channels, the message update and delete handlers accepted any caller holding write access on the channel, without checking that the caller wrote the message. Write access is the same grant a member needs in order to post, so every ordinary participant in a shared channel could…
CVE-2026-70481
GitHub-GHSA

MEDIUM
GitPython: Arbitrary file truncation via git rev-list –output argument injection in unguarded Commit.count
GHSA-p538-c434-8v24
pkg: GitPython
eco: pip
published: Aug 3, 2026
## Summary
`Commit.count()` forwards `**kwargs` into `rev_list` with **no** `check_unsafe_options` guard (the guard exists only in the sibling `iter_items`, commit.py:341). `git rev-list –output=<path>` opens and truncates the target file to 0 bytes before revision parsing, so `count(output='/victi…
NVD

MEDIUM
CVE-2026-19369
CVE-2026-19369
pkg: axios

published: Aug 9, 2026

A vulnerability was found in KS-GEN-AI jira-mcp-server 0.2.0. This affects the function axios.get of the file src/index.ts of the component add_attachment_from_public_url. The manipulation of the argument imageUrl results in server-side request forgery. The attack requires a local approach. The proj…
CWE: CWE-918
NVD

MEDIUM
CVE-2026-19363
CVE-2026-19363
pkg: jwt

published: Aug 9, 2026

A vulnerability was found in lmammino oidc-authorizer up to 0.4.0. Impacted is the function unwrap of the file src/handler.rs of the component Fixed Message Handler. The manipulation of the argument jwtClaims results in deserialization. The attack can be executed remotely. The exploit has been made …
CWE: CWE-20, CWE-502
NVD

MEDIUM
CVE-2026-19323
CVE-2026-19323
pkg: react

published: Aug 9, 2026

A security flaw has been discovered in azer react-analyzer-mcp up to 335f2a3585f265e2e88352b59b10d3b478d678b0. Affected by this vulnerability is the function generateProjectDocs of the file src/index.ts of the component analyze-projec. The manipulation of the argument projectName results in path tra…
CWE: CWE-22
NVD

MEDIUM
CVE-2026-69207
CVE-2026-69207
pkg: express

published: Aug 7, 2026

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.34, the built-in CORS middleware, hono/cors, is vulnerable to a regular expression denial of service (ReDoS). During a preflight OPTIONS request, the middleware parses the attacker-controlled Access-C…
CWE: CWE-1333
GitHub-GHSA

MEDIUM
Hono: Algorithmic Complexity DoS in Language Middleware
GHSA-54fx-42gc-7vw4
pkg: hono
eco: npm
published: Aug 7, 2026
### Summary

The `languageDetector` middleware is vulnerable to algorithmic complexity denial of service when processing a crafted language tag containing a large number of hyphen-separated subtags.

### Details

To implement progressive language-tag truncation, `normalizeLanguage()` repeatedly call…

CVE-2026-71848
NVD

MEDIUM
CVE-2026-66062
CVE-2026-66062
pkg: express

published: Aug 7, 2026

SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.70.2, the content negotiation header parser used by SvelteKit's request handling (for headers such as Accept) uses a regular expression vulnerable to quadratic backtracking, so a maliciously …
CWE: CWE-1333
GitHub-GHSA

MEDIUM
SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept header
GHSA-29g2-3rmr-qm68
pkg: @sveltejs/kit
eco: npm
published: Aug 7, 2026
### Impact
SvelteKit is vulnerable to remote CPU-exhaustion DoS attacks via specifically-crafted `Accept` headers. The impact is mitigated by default header length limits on most platforms, but in the case of raised or absent limits a denial of service is possible.

### Patches
The vulnerability is …

CVE-2026-66062
NVD

MEDIUM
CVE-2026-49006
CVE-2026-49006
pkg: tls

published: Aug 7, 2026

By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to TLS transmission.
CWE: CWE-321
NVD

MEDIUM
CVE-2026-61632
CVE-2026-61632
pkg: python

published: Aug 6, 2026

PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. In versions up to and including 10.21.3, the b64 extension is vulnerable to a path traversal that discloses arbitrary files: it inlines images referenced by <img src="…"> by joining the src onto the configured base…
CWE: CWE-22
NVD

MEDIUM
CVE-2026-19146
CVE-2026-19146
pkg: google chrome, google android

published: Aug 6, 2026

Uninitialized Use in GPU in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-457
GitHub-GHSA

MEDIUM
h2: Duplicate Host header could facilitate request smuggling
GHSA-6hr6-w5qg-qmwg
pkg: h2
eco: pip
published: Aug 6, 2026
### Impact
h2 <=4.4.0 accepts request header blocks containing more than one Host header, and forwards every Host header to the consuming application. Where the consumer downgrades HTTP/2 to HTTP/1.1, the resulting request carries two Host header lines, which is a request smuggling primitive (CWE-44…
CVE-2026-71554
GitHub-GHSA

MEDIUM
LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores
GHSA-47pj-3jcm-6whg
pkg: langgraph-checkpoint-postgres, langgraph-checkpoint-sqlite
eco: pip
published: Aug 6, 2026
## Summary

The Postgres and SQLite stores persist hierarchical namespaces as a dot-joined string (`("memories", "alice")` becomes `memories.alice`) and scoped reads by matching that string with `LIKE '<path>%'`. Because `LIKE` has no notion of the `.` separator, a scoped `search` or `list_namespace…

CVE-2026-71433
NVD

MEDIUM
CVE-2026-19044
CVE-2026-19044
pkg: go

published: Aug 6, 2026

A flaw has been found in LeeSinLiang godot-mcp 0.1.0. Affected by this vulnerability is the function executeOperation of the file src/index.ts of the component create_scene/add_node. This manipulation of the argument projectPath causes command injection. The attack needs to be launched locally. The …
CWE: CWE-74, CWE-77
GitHub-GHSA

MEDIUM
rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect
GHSA-h4mf-4v27-hggj
pkg: github.com/rclone/rclone
eco: go
published: Aug 5, 2026
## 1. Summary

WebDAV's default redirect handling can replay Basic authorization and configured Cookie headers over plaintext HTTP after a same-host HTTPS-to-HTTP redirect. This was reproduced through the real backend. Unlike the low-impact STS token in rclone's published S3 redirect advisory, Basic…

GitHub-GHSA

MEDIUM
rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys
GHSA-8mxv-9xhp-86h4
pkg: github.com/rclone/rclone
eco: go
published: Aug 5, 2026
## 1. Summary

The S3 redirect callback strips `X-Amz-Security-Token` when a redirect changes scheme or host, but it does not strip IBM IAM bearer authorization or customer-provided encryption keys. Two independently validated paths remain:

– a same-host HTTPS-to-HTTP redirect preserves `Authorizat…

GitHub-GHSA

MEDIUM
rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic
GHSA-3x6r-wxxg-53vv
pkg: github.com/rclone/rclone
eco: go
published: Aug 5, 2026
## 1. Summary

A transport failure during the initial Infinite Scale TUS creation POST can return `(nil response, non-nil error)`. Rclone dereferences the nil response before processing the error and panics. The production `CreateUploader` path reproduced the crash against a closed endpoint.

The se…

GitHub-GHSA

MEDIUM
Electron: window.open features string controls some window options considered privileged
GHSA-v93f-fgjr-hjrj
pkg: electron, electron, electron
eco: npm
published: Aug 5, 2026
### Impact
Some window options supplied by web content in the `window.open()` features string were applied to the new `BrowserWindow` without an allowlist. Untrusted content could set window options it should not control, including options that cause the main process to access attacker-chosen file o…
CVE-2026-70607
GitHub-GHSA

MEDIUM
Ghost Content API filter bypass reveals private fields
GHSA-jx35-x7fj-vgpr
pkg: ghost
eco: npm
published: Aug 5, 2026
### Impact

The validation applied to filters on the public API endpoints could be partially bypassed, making it possible to reveal private fields via a brute force attack. If SQLite was used as the database password hashes were fully accessible. If MySQL was used as the database the password hashes…

CVE-2026-53949
GitHub-GHSA

MEDIUM
Ghost: Paid gift memberships obtainable at minimal cost via the donations feature
GHSA-xm43-3m56-w3wf
pkg: ghost
eco: npm
published: Aug 4, 2026
### Impact

A vulnerability in Ghost's public donation checkout flow allowed an unauthenticated attacker to obtain full paid gift memberships for a minimal payment. No customer or member data was exposed, and the issue could not be used to steal money from a site or its members.

### Vulnerable vers…

CVE-2026-59817
GitHub-GHSA

MEDIUM
Ghost: Member existence leak via magic link sign-in response
GHSA-chgm-3698-jm42
pkg: ghost
eco: npm
published: Aug 4, 2026
### Impact

A discrepancy in responses from the members signin endpoints made it possible for an unauthenticated attacker to determine whether a given email address belongs to a registered member of a Ghost site.

### Vulnerable versions

This vulnerability is present in Ghost from v5.18.0 up to v6.…

CVE-2026-53947
GitHub-GHSA

MEDIUM
Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadata
GHSA-6xhv-rxhv-pwm4
pkg: open-webui
eco: pip
published: Aug 4, 2026
## Summary
Open WebUI lets a client define a model inline on a chat request instead of selecting a saved workspace model. The knowledge attached to such an inline model was used as-is, without checking that the caller can read what it points at. Any authenticated user who knows another user's file i…
CVE-2026-70487
NVD

MEDIUM
CVE-2026-47622
CVE-2026-47622
pkg: nvidia dynamo, linux linux_kernel

published: Aug 4, 2026

NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause the generation of error messages that contain sensitive information. A successful exploit of this vulnerability might lead to information disclosure.
CWE: CWE-209
NVD

MEDIUM
CVE-2026-16536
CVE-2026-16536
pkg: go

published: Aug 4, 2026

The Simple Google Calendar Outlook Events Widget WordPress plugin before 3.1.0 does not validate a user-supplied URL before performing a server-side request, allowing unauthenticated attackers to perform Server-Side Request Forgery attacks and, in some cases, read the response of the internal reques…
CWE: CWE-918
NVD

MEDIUM
CVE-2026-58041
CVE-2026-58041
pkg: node

published: Aug 4, 2026

A flaw in Node.js node:sqlite allows a stale StatementSyncIterator created through DatabaseSync#createTagStore() to continue executing a cached prepared statement after it has been reset and rebound with new parameters. SQLTagStore resets cached statements using sqlite3_reset() directly, bypassing t…
CWE: CWE-367
NVD

MEDIUM
CVE-2026-18648
CVE-2026-18648
pkg: react

published: Aug 3, 2026

A vulnerability was detected in Blix Email Blue Mail Calendar App 2.2.305. Impacted is the function FileDirectory.getDataColumn/FileDirectory.getFileFromUri of the component react-native-receive-sharing-intent. The manipulation of the argument _display_name results in path traversal. The attack is o…
CWE: CWE-22
GitHub-GHSA

MEDIUM
Hono: ReDoS in CORS middleware via Access-Control-Request-Headers
GHSA-8j4g-w8fx-2239
pkg: hono
eco: npm
published: Aug 3, 2026
### Summary

The built-in CORS middleware (`hono/cors`) parses the attacker-controlled `Access-Control-Request-Headers` request header during a preflight (`OPTIONS`) request using a regular expression whose running time is quadratic in the input length. A single request carrying a long run of whites…

CVE-2026-69207
NVD

MEDIUM
CVE-2026-71498
CVE-2026-71498
pkg: express

published: Aug 6, 2026

node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.26.1, passing a Buffer whose final bytes form a truncated (incomplete) multi-byte UTF-8 sequence could cause the native binding to read past the end of the allocated buffer while attempting to decode the final, incompl…
CWE: CWE-125
GitHub-GHSA

MEDIUM
node-re2: Out-of-bounds heap read in `replace`/`split` via a `Buffer` ending in a truncated multi-byte UTF-8 character → adjacent heap memory disclosed to JavaScript
GHSA-j4r3-hg7j-8chg
pkg: re2
eco: npm
published: Aug 6, 2026
## Summary

`re2` infers a character's byte length from its UTF-8 lead byte alone, with no bound on the
bytes actually remaining in the input. `Buffer` arguments reach the native layer verbatim —
only strings are re-encoded into well-formed UTF-8 — so a `Buffer` whose last byte is a
multi-byte l…

CVE-2026-71498
GitHub-GHSA

MEDIUM
rclone archive extract allows S3 destination prefix escape via crafted archive paths
GHSA-4vr5-p2gc-h23p
pkg: github.com/rclone/rclone
eco: go
published: Aug 5, 2026
### Summary

`rclone archive extract` can write extracted files outside the user-selected destination prefix when extracting a crafted archive. A malicious archive entry containing parent path components such as `../` can escape the requested extraction prefix and create or overwrite sibling objects…

CVE-2026-59732
NVD

MEDIUM
CVE-2026-71201
CVE-2026-71201
pkg: node

published: Aug 5, 2026

In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assigned to Nodes owned or leased by another project.
CWE: CWE-863
NVD

MEDIUM
CVE-2026-70588
CVE-2026-70588
pkg: node

published: Aug 4, 2026

Ghost is a Node.js content management system. From 5.26.0 until 6.54.1, the Universal Import feature in Ghost Admin failed to properly sanitize imported content resulting in XSS in post content. This issue is fixed in version 6.54.1.
CWE: CWE-79
GitHub-GHSA

MEDIUM
Ghost: Cross-Site Scripting in Universal Import
GHSA-2gx6-7gx2-wwcf
pkg: ghost
eco: npm
published: Aug 4, 2026
### Impact

The Universal Import feature in Ghost Admin failed to properly sanitize imported content resulting in XSS in post content.

### Vulnerable versions

This vulnerability is present in Ghost from v5.26.0 up to v6.54.0.

### Patches

v6.54.1 contains a fix for this issue.

### How to update

CVE-2026-70588
GitHub-GHSA

MEDIUM
Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosure
GHSA-f23p-vx2j-j53r
pkg: hono
eco: npm
published: Aug 7, 2026
### Summary

`memo()` from `hono/jsx` retains the result of a server-side render and reuses it for later renders with comparator-equal props. Request-scoped values read inside the component take no part in that comparison, so a response can contain HTML rendered for another user's request.

### Deta…

CVE-2026-71850
NVD

MEDIUM
CVE-2026-71318
CVE-2026-71318
pkg: vue

published: Aug 5, 2026

Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an attacker can supply a top-level `as` prop to the /__nuxt_island/ endpoint and drive dynamic component resolution through <component :is>, resolveDynamicComponent, or h(). This issue is fixed in 3.21.1…
CWE: CWE-20
GitHub-GHSA

MEDIUM
Nuxt: Unauthorized Component Instantiation via Server Island Props
GHSA-48hr-524c-v5w3
pkg: nuxt, nuxt
eco: npm
published: Aug 5, 2026
## Impact

Nuxt server islands accept props via the `/__nuxt_island/` endpoint. When an application has a server island component that forwards props directly into Vue's dynamic component resolution (`<component :is>`, `resolveDynamicComponent`, or `h()`), an attacker can pass a plain string value (…

CVE-2026-71318
NVD

MEDIUM
CVE-2026-70590
CVE-2026-70590
pkg: node

published: Aug 4, 2026

Ghost is a Node.js content management system. Prior to 6.54.1, any staff-level user was able to leak the hashed passwords of other staff users through the Ghost Admin API. An offline password-guessing attack against the hashes could lead to account takeover if successful, but Device Verification sho…
CWE: CWE-200
NVD

MEDIUM
CVE-2026-70589
CVE-2026-70589
pkg: node

published: Aug 4, 2026

Ghost is a Node.js content management system. From 4.22.0 until 6.54.1, a missing validation check allowed users to redeem subscription offers that were no longer active. This issue is fixed in version 6.54.1.
CWE: CWE-20
GitHub-GHSA

MEDIUM
Ghost: Blind Password Hash Disclosure in Ghost Admin API
GHSA-jm22-3w23-5q7w
pkg: ghost
eco: npm
published: Aug 4, 2026
### Impact

Any staff-level user was able to leak the hashed passwords of other staff users. An offline password-guessing attack against the hashes could lead to account takeover if successful, but [Device Verification](https://docs.ghost.org/security#device-verification) should have prevented an at…

CVE-2026-70590
GitHub-GHSA

MEDIUM
Ghost: Archived Offers can be Redeemed
GHSA-4wx2-7gvj-qfq3
pkg: ghost
eco: npm
published: Aug 4, 2026
### Impact

A missing validation check allowed users to redeem subscription offers that were no longer active.

### Vulnerable versions

This vulnerability is present in Ghost from v4.22.0 up to v6.54.0.

### Patches

v6.54.1 contains a fix for this issue.

### How to update

For self-hosters using …

CVE-2026-70589
GitHub-GHSA

MEDIUM
undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields
GHSA-v3r7-h72x-cjcm
pkg: undici, undici, undici
eco: npm
published: Aug 3, 2026
## Impact

The `setCookie` function has two attribute injection paths. `validateCookieDomain` does not reject semicolons (`validateCookiePath` already does at 0x3B), so a `domain` value like `example.com; SameSite=None` lands verbatim as `Domain=example.com; SameSite=None`. The `unparsed` array's lo…

CVE-2026-16729
GitHub-GHSA

MEDIUM
undici vulnerable to downstream response desynchronization via retry interceptor
GHSA-8xcm-r25x-g524
pkg: undici, undici, undici
eco: npm
published: Aug 3, 2026
### Impact

Undici's `interceptors.retry()` can deliver a response whose body length does not match the `Content-Length` header exposed to the application after a retry or resume of a partial response. Applications that use `interceptors.retry()` and forward upstream response headers and bodies down…

CVE-2026-16728
NVD

MEDIUM
CVE-2026-56609
CVE-2026-56609
pkg: hcltech icontrol

published: Aug 3, 2026

HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using weak TLS versions such as TLS 1.0 and 1.1. These outdated protocols lack modern security features, making them vulnerable to known attacks and exposing sensitive information durin…
CWE: CWE-327
NVD

MEDIUM
CVE-2026-19244
CVE-2026-19244
pkg: react

published: Aug 7, 2026

A vulnerability was detected in HKUDS nanobot up to 0.2.1. The affected element is the function connect_mcp_servers of the file nanobot/agent/tools/mcp.py of the component MCP enabledTools Scope Handler. Performing a manipulation results in improper access controls. The attack is possible to be carr…
CWE: CWE-266, CWE-284
GitHub-GHSA

MEDIUM
jsoup: Cleaner may expose markup with custom raw-text elements
GHSA-pmhh-3w7g-xqp8
pkg: org.jsoup:jsoup
eco: maven
published: Aug 6, 2026
When a custom `Safelist` permits certain raw-text elements, jsoup may incorrectly sanitize malformed HTML containing a tag name that ends in a control character. The tag may acquire the parsing behavior of a different element, causing content that should remain text to be emitted as active markup af…
CVE-2026-71497
NVD

MEDIUM
CVE-2026-18909
CVE-2026-18909
pkg: windows

published: Aug 6, 2026

A stack-based buffer overflow vulnerability exists in ELAN Microelectronics Corp. ELAN Smart-Pad on Windows (ETD.sys and ETDSMBus.sys). During Intel SMBus recovery, ETDSMBus.sys does not enforce an upper-bound check on the hardware-derived report count, allowing an out-of-range value to be forwarded…
CWE: CWE-121
NVD

MEDIUM
CVE-2026-47487
CVE-2026-47487
pkg: linux

published: Aug 4, 2026

NVIDIA Triton Inference Server for Linux contains a vulnerability where a user could cause files outside the model repository to be read, written to, or modified by providing a path in the model name to the Triton MLflow plugin. A successful exploit of this vulnerability might lead to denial of serv…
CWE: CWE-22
NVD

MEDIUM
CVE-2026-70556
CVE-2026-70556
pkg: oauth

published: Aug 6, 2026

Hubzilla 11.2.1 contains a cross-site request forgery vulnerability in the OAuth2 /authorize endpoint handled by Zotlabs\Module\Authorize::post() that allows unauthenticated attackers to register arbitrary OAuth2 applications under an authenticated user's account by submitting a cross-origin POST re…
CWE: CWE-352
NVD

MEDIUM
CVE-2026-70442
CVE-2026-70442
pkg: go

published: Aug 5, 2026

Jenkins Google Chat Notification Plugin 166.ve6b_de280f2e8 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to use.
CWE: CWE-285
NVD

MEDIUM
CVE-2026-70596
CVE-2026-70596
pkg: node

published: Aug 5, 2026

Ghost is a Node.js content management system. From 4.9.0 until 6.54.1, an input validation issue allowed any staff user to create a post with content in feature_image_caption that could be used to hijack another staff user's Ghost Admin session, resulting in privilege escalation. This issue is fixed…
CWE: CWE-79
NVD

MEDIUM
CVE-2026-15656
CVE-2026-15656
pkg: go

published: Aug 5, 2026

IBM Maximo Application Suite 9.2, 9.1, and 9.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure…
CWE: CWE-614
GitHub-GHSA

MEDIUM
Ghost: Cross-Site Scripting in Feature Image Captions
GHSA-pr22-p9rp-2cqv
pkg: ghost
eco: npm
published: Aug 5, 2026
### Impact

An input validation issue allowed any staff user to create a post with content that could be used to hijack another staff user's Ghost Admin session resulting in privilege escalation.

### Vulnerable versions

This vulnerability is present in Ghost from v4.9.0 up to v6.54.0.

### Patches…

CVE-2026-70596
NVD

MEDIUM
CVE-2026-55996
CVE-2026-55996
pkg: tls

published: Aug 5, 2026

A denial-of-service vulnerability was identified in multiple TLS listeners in Rancher. Both the cattle-cluster-agent component running in downstream clusters and the Rancher server itself use the dynamiclistener library to serve TLS traffic. Without an effective CN filter configured, dynamiclistener…
CWE: CWE-770
GitHub-GHSA

MEDIUM
Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup
GHSA-jxc9-xmc4-gr23
pkg: open-webui
eco: pip
published: Aug 4, 2026
## Summary
A user with write access to one knowledge base could delete directories, and drop file embeddings, belonging to knowledge bases they do not control. The sync cleanup endpoint verified write access on the knowledge base named in the URL and then acted on the directory and file ids supplied…
CVE-2026-70488
GitHub-GHSA

MEDIUM
Open WebUI: Users denied the image-generation permission can still generate images via chat completions
GHSA-g423-grf7-98rv
pkg: open-webui
eco: pip
published: Aug 4, 2026
## Summary
An authenticated user whose `features.image_generation` permission has been revoked can still make the server generate images by sending the feature flag in a chat-completion request. The chat pipeline took the client-supplied `features` object at face value and never re-checked the permi…
CVE-2026-70484
GitHub-GHSA

MEDIUM
undici vulnerable to CRLF Injection via blob-like body 'type' property
GHSA-m8rv-5g2x-5cg5
pkg: undici, undici, undici
eco: npm
published: Aug 3, 2026
### Impact

When an application passes a duck-typed blob-like body to undici's HTTP/1.1 dispatcher (via `request()`, `stream()`, `pipeline()`, or `dispatch()`) with a `.type` derived from untrusted input, an attacker can inject CRLF sequences (`\r\n`) to append arbitrary HTTP headers and potentially…

CVE-2026-15157
NVD

MEDIUM
CVE-2026-70591
CVE-2026-70591
pkg: node

published: Aug 4, 2026

Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a Server-Side Request Forgery in Ghost Admin image fetching allowed any staff-level user to perform a blind HTTP GET request against internal hosts. No output was returned, but this could have been used to probe open ports on in…
CWE: CWE-918
GitHub-GHSA

MEDIUM
Ghost: Server-Side Request Forgery in Image Fetching
GHSA-gcvv-72q8-9v76
pkg: ghost
eco: npm
published: Aug 4, 2026
### Impact

A Server-Side Request Forgery (SSRF) in Ghost Admin allowed any staff-level user to perform a blind HTTP GET request against internal hosts. No output was returned, but this could have been used to probe open ports on internal hosts.

### Vulnerable versions

This vulnerability is presen…

CVE-2026-70591
GitHub-GHSA

MEDIUM
Open WebUI: Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart rendering
GHSA-rffm-9q57-q649
pkg: open-webui
eco: pip
published: Aug 4, 2026
## Summary
Open WebUI renders `vega` and `vega-lite` fenced code blocks in chat content by building a Vega view in the viewer's browser without a restricted resource loader. Any user who can place such a block where another user will see it can make that user's browser issue attacker-chosen outbound…
CVE-2026-70480
NVD

MEDIUM
CVE-2026-70595
CVE-2026-70595
pkg: node

published: Aug 5, 2026

Ghost is a Node.js content management system. From 6.26.0 until 6.54.1, a validation issue allowed some functionality, such as Webmentions, to be abused by an unauthenticated user to make limited HTTP requests to hosts in the Ghost server's internal network. A successful attack would not result in a…
CWE: CWE-918
GitHub-GHSA

MEDIUM
Ghost: Server-Side Request Forgery Mitigation Issue
GHSA-x5mm-wm4g-j5xv
pkg: ghost
eco: npm
published: Aug 5, 2026
### Impact

A validation issue allowed some functionality, such as Webmentions, to be abused by an unauthenticated user to make limited HTTP requests to hosts in the Ghost server's internal network. A successful attack would not result in any response data being returned.

### Vulnerable versions

T…

CVE-2026-70595
GitHub-GHSA

MEDIUM
Ghost: Server-side request forgery via DNS rebinding in external request handling
GHSA-ch52-px8q-f22j
pkg: ghost
eco: npm
published: Aug 4, 2026
### Impact

Ghost’s private-IP check for outbound HTTP requests could be bypassed via DNS rebinding, allowing an attacker to coerce the Ghost server into reaching hosts on internal networks through features that issue external fetches.

### Vulnerable versions

This vulnerability is present in Gho…

CVE-2026-53945
GitHub-GHSA

MEDIUM
pypdf: Possible large memory usage for large /ToUnicode streams
GHSA-fp3f-mc75-235c
pkg: pypdf
eco: pip
published: Aug 7, 2026
### Impact

An attacker who uses this vulnerability can craft a PDF which leads to large memory consumption. This requires parsing the `/ToUnicode` entry of a font with unusually large values, for example during text extraction.

### Patches

This has been fixed in [pypdf==6.15.0](https://github.com…

CVE-2026-71870
GitHub-GHSA

MEDIUM
pypdf: Possible long runtimes/large memory usage for large CID font width ranges
GHSA-fwg2-594c-jp42
pkg: pypdf
eco: pip
published: Aug 7, 2026
### Impact

An attacker who uses this vulnerability can craft a PDF which leads to long runtimes and large memory consumption. This requires parsing the font width entries of a font with unusually large values, for example during text extraction.

### Patches

This has been fixed in [pypdf==6.15.0](…

CVE-2026-71852
GitHub-GHSA

MEDIUM
Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint
GHSA-7c4v-fwgw-9rf7
pkg: nuxt, nuxt
eco: npm
published: Aug 7, 2026
### Impact

When a Nuxt dev server is bound to a network-reachable interface (for example `nuxt dev –host` for on-device testing), the default-enabled Chrome DevTools workspace endpoint `GET /.well-known/appspecific/com.chrome.devtools.json` returns the absolute project root (`workspace.root`, i.e.…

GitHub-GHSA

MEDIUM
DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS
GHSA-55q2-fjhq-7xh7
pkg: dompurify
eco: npm
published: Aug 7, 2026
### Summary

During `IN_PLACE` sanitization, a hook that removes an element can leave that element's detached descendants executable. A descendant image can retain its attacker-provided `onload` handler and fire after `sanitize()` returns, even though the returned root is clean and the image remains…

GitHub-GHSA

MEDIUM
Mermaid radar diagrams are vulnerable to DoS
GHSA-rhh3-jpg6-66xh
pkg: mermaid
eco: npm
published: Aug 6, 2026
### Impact

Mermaid radar diagrams allow arbitrary large values for `ticks`, which can cause high CPU usage, freezing the webpage/JavaScript process for long periods of time, until the process is eventually killed due to OOM/running out of memory.

#### Proof-of-concept

“`txt
radar-beta
axis a, …

CVE-2026-71439
GitHub-GHSA

MEDIUM
Mermaid allows CSS injection applying to sibling elements of the diagram
GHSA-6×64-9×62-f2gx
pkg: mermaid, mermaid
eco: npm
published: Aug 6, 2026
### Summary

Mermaid does not fully restrict CSS to the rendered SVG subtree. Although selectors are prefixed with `#mermaid-X`, sibling (`~` and `+`) combinators can still escape the Mermaid container and inject styles to DOM elements adjacent to the diagram `<svg>`.

**Most users of mermaid would …

CVE-2026-50159
GitHub-GHSA

MEDIUM
Mermaid Architecture diagrams are vulnerable to prototype pollution
GHSA-3rrr-jr9j-h3q3
pkg: mermaid
eco: npm
published: Aug 6, 2026
Rendering an untrusted `architecture-beta` diagram lets the diagram author write an arbitrary property with the value `horizontal` or `vertical` onto `Object.prototype`. A group id of `__proto__` is accepted as a valid parent.

### Impact

Any code in the same realm that reads a property of that nam…

CVE-2026-71437
GitHub-GHSA

MEDIUM
Mermaid XY Charts are vulnerable to an infinite loop DoS
GHSA-2v8p-3f2j-5mp7
pkg: mermaid, mermaid
eco: npm
published: Aug 6, 2026
### Impact

Mermaid XY Charts are vulnerable to an infinite loop DoS attack in the `setXAxisRangeData()`, when configuring an X-Axis with invalid parameters.

As each loop appends an element to an array, this would generally only cause an `RangeError: Invalid array length` to appear after a few seco…

CVE-2026-71436
GitHub-GHSA

MEDIUM
Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port
GHSA-6p8f-p8j2-rqmv
pkg: github.com/traefik/traefik/v3
eco: go
published: Aug 6, 2026
## Summary

There is a medium severity vulnerability in Traefik's Kubernetes Gateway API provider.
When two accepted HTTPRoutes target the same backend Service:port but configure different
`backendRef` filters, Traefik may resolve both routes to the same child service and apply
only one route's filt…

CVE-2026-54765
GitHub-GHSA

MEDIUM
Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef
GHSA-62fc-8686-hfmq
pkg: github.com/traefik/traefik/v2, github.com/traefik/traefik/v3, github.com/traefik/traefik/v3
eco: go
published: Aug 6, 2026
## Summary

There is a medium severity vulnerability in Traefik's Kubernetes CRD provider. When `providers.kubernetesCRD.allowCrossNamespace` is disabled — the default — cross-namespace `@kubernetescrd` references are rejected for middlewares, TLS options and HTTP/TCP ServersTransports, but the …

CVE-2026-71325
GitHub-GHSA

MEDIUM
Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass
GHSA-42cj-m3vj-89wv
pkg: github.com/traefik/traefik/v3, github.com/traefik/traefik/v3
eco: go
published: Aug 5, 2026
## Summary

There is a medium-severity cross-provider reference vulnerability in Traefik's Kubernetes CRD provider. The `crossProviderNamespaces` allowlist is enforced for HTTP `serversTransport` references but was not enforced for `IngressRouteTCP` service `serversTransport` references. A low-privi…

CVE-2026-65602
GitHub-GHSA

MEDIUM
Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion
GHSA-qq9q-x9w4-chhj
pkg: Traefik
eco: go
published: Aug 5, 2026
## Summary

There is a medium-severity namespace-confusion vulnerability in Traefik's Kubernetes Gateway API provider. When resolving `HTTPRoute.spec.rules[].backendRefs[].filters[].extensionRef`, Traefik used the backend Service namespace instead of the `HTTPRoute` namespace. A low-privileged route…

CVE-2026-65601
GitHub-GHSA

MEDIUM
Flowise: Unauthenticated Credential Abuse via Text-to-Speech Endpoint Allows Unauthorized Use of Private Chatflow TTS Credentials
GHSA-8gj2-2cvc-6xx7
pkg: flowise
eco: npm
published: Aug 4, 2026
## Summary

The `/api/v1/text-to-speech/generate` endpoint is whitelisted (requires no authentication) and accepts any `chatflowId` without checking whether the referenced chatflow is public. An unauthenticated attacker who knows a valid chatflow UUID can abuse that chatflow's TTS credential (OpenAI…

GitHub-GHSA

MEDIUM
Flowise: IDOR vulnerability exists at the GET /api/v1/organization/customer-default-source endpoint
GHSA-2364-jh4q-m9vm
pkg: flowise
eco: npm
published: Aug 4, 2026
### Summary
An Insecure Direct Object Reference (IDOR) vulnerability exists at the **GET /api/v1/organization/customer-default-source** endpoint. This flaw allows an authenticated attacker to bypass authorization checks and retrieve sensitive payment and profile information of other customers by man…
GitHub-GHSA

MEDIUM
python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees
GHSA-m2h6-j472-rp4c
pkg: cryptography
eco: pip
published: Aug 3, 2026
### Summary
If an intermediate constrained CA permits the DNS name `foo.example.com`, and the leaf certificate has a wildcard in its DNS SAN of `*.example.com`, python-cryptography's verifier accepts which allows escaping outside of the permitted names.

### PoC

“`
#!/usr/bin/env python3
"""Standa…

CVE-2026-69248
GitHub-GHSA

MEDIUM
AIOHTTP: HTTP request smuggling via WebSocket upgrade
GHSA-mfx4-hv73-q22v
pkg: aiohttp
eco: pip
published: Aug 3, 2026
### Summary

The HTTP parsers were vulnerable to a request smuggling attack relating to WebSocket upgrades.

### Impact

If using the server-side component, it may be possible for an attacker to execute a request smuggling vulnerability using an edge case in the WebSocket upgrade procedure. AIOHTT i…

CVE-2026-69243
GitHub-GHSA

MEDIUM
AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate
GHSA-mq44-7p77-q5h7
pkg: aiohttp
eco: pip
published: Aug 3, 2026
### Summary

The client accepts and decompresses frames with the RSV1 bit set even when the `permessage-deflate` extension was not negotiated.

### Impact

A client may unexpectedly decompress WebSocket frames when explicitly opted out. This could lead to additional CPU/memory consumption, but is un…

CVE-2026-59881
GitHub-GHSA

MEDIUM
ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks
GHSA-4xrf-jv44-h6hh
pkg: ip-address
eco: npm
published: Aug 3, 2026
### Summary

Every special-use classification method is built on `isInSubnet`, which short-circuits to `false` whenever the address's own subnet mask is *shorter* than the reference range's mask. That mask comes verbatim from the CIDR suffix on the parsed input, so appending a suffix such as `/0` su…

CVE-2026-69198
GitHub-GHSA

MEDIUM
ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks
GHSA-22jq-vg5j-6vgg
pkg: ip-address
eco: npm
published: Aug 3, 2026
### Summary

`Address6`'s special-property checks misclassify IPv4-mapped (`::ffff:0:0/96`) and NAT64 well-known (`64:ff9b::/96`) IPv6 addresses. These checks classify an address by its IPv6 wrapper rather than by the IPv4 address it embeds, so `isLoopback()`, `isLinkLocal()`, `isMulticast()`, and `…

CVE-2026-54272
GitHub-GHSA

MEDIUM
PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset
GHSA-fxqj-rqcc-2cmp
pkg: postcss
eco: npm
published: Aug 3, 2026
## Summary

The fix for GHSA-6g55-p6wh-862q added a guard in `lib/previous-map.js` `PreviousMap.loadFile()` that restricts an attacker-controlled `sourceMappingURL` (from a CSS comment) to a `.map` extension and, for untrusted maps, rejects `..` traversal and absolute paths. The traversal/absolute r…

CVE-2026-69153


Vulnerability Digest — August 3, 2026 · 43 Critical · 1 Exploited






Vulnerability Digest — Monday, August 3, 2026


Security Report

Monday, August 3, 2026  ·  Last 7 days  ·  Min severity: MEDIUM
Total Findings
337
Critical
43
High
177
Actively Exploited
1
CISA-KEV1
NVD200
GitHub-GHSA136
Findings sorted by severity
CISA-KEV

CRITICAL
Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
CVE-2026-20316
pkg: Cisco Secure Firewall Management Center (FMC)

published: Jul 29, 2026

Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impa…
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
GitHub-GHSA

CRITICAL
NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE
GHSA-p849-8hwh-84j9
pkg: @nocobase/plugin-notification-in-app-message
eco: npm
published: Jul 31, 2026
## Summary

`GET /api/myInAppChannels:list` accepts a structured `filter` query parameter. The handler for the `latestMsgReceiveTimestamp` field splices the `$lt` value directly into a `Sequelize.literal()` template string with no escape, type cast, or parameter binding. The action ACL is `loggedIn`…

CVE-2026-52887
GitHub-GHSA

CRITICAL
Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)
GHSA-2956-977x-2w3r
pkg: flyto-core
eco: pip
published: Jul 30, 2026
## Summary

`image.download` fetches a URL and writes the response to disk. It does not use the central path guard (`validate_path_with_env_config`, which confines writes to `FLYTO_SANDBOX_DIR`); instead it confines the output to `output_dir`, but `output_dir` is itself a caller parameter. Since the…

CVE-2026-67429
GitHub-GHSA

CRITICAL
prebid-server's request forgery vulnerability allows for possible host environment data extraction
GHSA-4p3g-4hcj-wpvx
pkg: github.com/prebid/prebid-server/v4, github.com/prebid/prebid-server/v3, github.com/prebid/prebid-server/v2
eco: go
published: Jul 29, 2026
### Impact
Certain bidder adapters accept user-supplied parameters that are interpolated into outbound request URLs. Without proper input validation, a malicious actor could craft bid request parameters that cause the server to send HTTP requests to unintended destinations, potentially exposing inte…
CVE-2026-54735
NVD

CRITICAL
CVE-2026-16812
CVE-2026-16812
pkg: arista velocloud_orchestrator

published: Jul 27, 2026

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by …
CWE: CWE-78
NVD

CRITICAL
CVE-2026-67330
CVE-2026-67330
pkg: oauth

published: Aug 1, 2026

@better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-beta.0 through <= 1.7.0-beta.9 contain an authorization bypass. SCIM token issuance did not reject provider IDs already used by existing SSO, SAML, OIDC, generic OAuth, or social account providers, and …
CWE: CWE-20
GitHub-GHSA

CRITICAL
Wings exposes node configuration secrets through egg configuration-file templating
GHSA-pfvc-3p5h-x7h6
pkg: github.com/pterodactyl/wings
eco: go
published: Jul 31, 2026
### Impact

**Type:** Exposure of sensitive information / insufficiently protected credentials
leading to privilege escalation and full node compromise.

Wings exposes its **entire** daemon configuration to the egg configuration-file
templating engine. When Wings renders a server's configuration fil…

CVE-2026-52855
NVD

CRITICAL
CVE-2026-13435
CVE-2026-13435
pkg: python

published: Jul 30, 2026

IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox implementation.
CWE: CWE-94
NVD

CRITICAL
CVE-2026-54680
CVE-2026-54680
pkg: kubernetes

published: Jul 29, 2026

Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior to 6.6.0, the Fluentd configuration renderer FluentRender in pkg/sdk/logging/model/render/fluent.go writes CRD strings such as Flow record_transformer.records values directly into fluent.conf without e…
CWE: CWE-74, CWE-77
GitHub-GHSA

CRITICAL
Logging operator has Fluentd configuration injection that allows remote code execution
GHSA-mjqf-28ph-426h
pkg: github.com/kube-logging/logging-operator
eco: go
published: Jul 29, 2026
### Summary

The Fluentd configuration renderer in Logging operator writes strings from CRDs such as `Flow` directly into `fluent.conf` without escaping them. As a result, a user who can create `Flow` resources can inject Fluentd configuration by providing values that contain newlines.

In the confi…

CVE-2026-54680
NVD

CRITICAL
CVE-2026-8457
CVE-2026-8457
pkg: jwt

published: Aug 2, 2026

The WooCommerce – Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple login handler accepting the Apple id_token and decoding only its base64 payload without verifying the JWT signature against Apple's …
CWE: CWE-289
NVD

CRITICAL
CVE-2026-66402
CVE-2026-66402
pkg: tls

published: Aug 1, 2026

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_verify_certificate(), tls_match_hostname(), and x509_utils_get_dns_names(). Because FreeRDP performs custom Common Name and DNS SAN string matching instead of using OpenSSL's l…
CWE: CWE-295
NVD

CRITICAL
CVE-2026-68771
CVE-2026-68771
pkg: node

published: Jul 31, 2026

ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and triggering its deserialization. Attackers can upload a malicious shard_*.pkl file via …
CWE: CWE-502
NVD

CRITICAL
CVE-2026-68770
CVE-2026-68770
pkg: python

published: Jul 31, 2026

sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code execution by exploiting a logic flaw in the import_module_class helper within sentence_transformers/util/misc.py, where the guard condition includes an 'or os.path.exists(model_name…
CWE: CWE-94
NVD

CRITICAL
CVE-2026-67208
CVE-2026-67208
pkg: docker

published: Jul 30, 2026

Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execute arbitrary OS commands by connecting to the exposed H2 database web console using default shipped credentials. Attackers can access the unprotected /h2-console endpoint, authent…
CWE: CWE-306, CWE-1188
NVD

CRITICAL
CVE-2026-41939
CVE-2026-41939
pkg: windows

published: Jul 29, 2026

Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final management interface that allows unauthenticated remote attackers to gain administrative access by using default credentials identical across all installations. Attackers can authentica…
CWE: CWE-1392
NVD

CRITICAL
CVE-2026-59243
CVE-2026-59243
pkg: oauth

published: Jul 29, 2026

The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or unsigned (`alg:none`) ID token to the OAuth callback could bypass authentication and log in as an arbitrary user, including one holding the Admin role…
CWE: CWE-347
GitHub-GHSA

CRITICAL
@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution
GHSA-6wcc-39rp-hh9p
pkg: @hypequery/clickhouse
eco: npm
published: Jul 28, 2026
### Impact
A SQL injection vulnerability exists in the `escapeValue()` function used for parameter substitution. Attackers who can control parameter values can inject arbitrary SQL by using a trailing backslash to escape the closing quote.

Who is impacted: All users of @hypequery/clickhouse versio…

CVE-2026-54658
NVD

CRITICAL
CVE-2026-64541
CVE-2026-64541
pkg: linux

published: Jul 27, 2026

In the Linux kernel, the following vulnerability has been resolved:

net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket

smc_cdc_rx_handler() looks up the connection by token under the link
group's conns_lock, drops the lock, and then dereferences conn and the
smc_sock derived from it, e…

NVD

CRITICAL
CVE-2026-68579
CVE-2026-68579
pkg: windows

published: Aug 2, 2026

FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_Read function (client/Windows/wf_cliprdr.c). When an OLE paste consumer (e.g. explorer.exe) calls IStream::Read with a fixed-size buffer of cb bytes, CliprdrStream_Read requests fi…
CWE: CWE-787
NVD

CRITICAL
CVE-2026-54725
CVE-2026-54725
pkg: kubernetes

published: Jul 31, 2026

vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in pkg/webhook/config.go accepts the vault.security.banzaicloud.io/vault-addr annotation, MutateConfigMap and MutateSecret call newVaultClient in pkg/webh…
CWE: CWE-918
GitHub-GHSA

CRITICAL
vault-addr annotation SSRF — webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API
GHSA-r2v3-8gwf-7ghm
pkg: github.com/bank-vaults/vault-secrets-webhook
eco: go
published: Jul 31, 2026
## Summary

The vault-secrets-webhook reads the `vault.security.banzaicloud.io/vault-addr` annotation from any ConfigMap or Secret being admitted and uses it as the Vault server address without any validation or allowlist. When a ConfigMap or Secret contains a value prefixed with `vault:`, the webho…

CVE-2026-54725
NVD

CRITICAL
CVE-2026-17692
CVE-2026-17692
pkg: windows

published: Jul 30, 2026

Use after free in DataTransfer in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

CRITICAL
CVE-2026-17691
CVE-2026-17691
pkg: windows

published: Jul 30, 2026

Out of bounds write in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-787
NVD

CRITICAL
CVE-2026-17656
CVE-2026-17656
pkg: go

published: Jul 30, 2026

Use after free in Ozone in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

CRITICAL
CVE-2026-17655
CVE-2026-17655
pkg: go

published: Jul 30, 2026

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-20
NVD

CRITICAL
CVE-2026-17652
CVE-2026-17652
pkg: go

published: Jul 30, 2026

Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

CRITICAL
CVE-2026-17651
CVE-2026-17651
pkg: go

published: Jul 30, 2026

Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-20
NVD

CRITICAL
CVE-2026-66395
CVE-2026-66395
pkg: node

published: Jul 27, 2026

SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler that allows attackers to execute arbitrary code by crafting a malicious siyuan:// deep link. Attackers can inject HTML payloads via the plugin name parameter that execute with ful…
CWE: CWE-79
GitHub-GHSA

CRITICAL
Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration
GHSA-jx74-cqjv-2c67
pkg: flyto-core
eco: pip
published: Jul 30, 2026
## Summary
The standalone `flyto-verification` service exposes `POST /run` with **no authentication**, on all interfaces (0.0.0.0:8344 per the shipped Dockerfile). The request body's `callback_url` is used verbatim for an outbound POST that **unconditionally attaches `X-Internal-Key: $FLYTO_RUNNER_S…
CVE-2026-67426
NVD

CRITICAL
CVE-2026-3141
CVE-2026-3141
pkg: linux

published: Aug 1, 2026

The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the /wp-json/formgent/responses/attachments REST API endpoint in all versions up to, and including, 1.9.2 This is due to the REST API route being registered without any authen…
CWE: CWE-862
GitHub-GHSA

CRITICAL
Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass
GHSA-6h5j-32cf-4253
pkg: apostrophe
eco: npm
published: Jul 31, 2026
<img width="1919" height="1046" alt="proto" src="https://github.com/user-attachments/assets/c5c69718-6448-448d-b64b-e3db41ab6ff6" />

## Summary

`apos.util.set()` traverses dot-notation paths without sanitizing `__proto__`, allowing an authenticated editor to write arbitrary values to `Object.proto…

CVE-2026-53609
NVD

CRITICAL
CVE-2026-52539
CVE-2026-52539
pkg: jwt

published: Jul 30, 2026

Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environment variable is not set, the application falls back to the default value which is publicly visible in the source code repository. An unauthenticated remote attacker can exploit this by forging JWT sessi…
CWE: CWE-798
NVD

CRITICAL
CVE-2026-63230
CVE-2026-63230
pkg: jwt

published: Jul 29, 2026

A pre-authentication error-based SQL injection
vulnerability in Koollab LMS allowed an unauthenticated attacker to read sensitive database
contents, including personally identifiable information, credentials, and valid
JWT tokens that may enable account takeover, via the SCORM report endpoint.
CWE: CWE-89
NVD

CRITICAL
CVE-2026-63229
CVE-2026-63229
pkg: jwt

published: Jul 29, 2026

A pre-authentication blind SQL injection
vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time-based SQL oracle via
the SSO OAuth endpoint to read sensitive database contents, including
personally identifiable information, credentials, and valid JWT tokens that may
enable ac…
CWE: CWE-89
NVD

CRITICAL
CVE-2026-64863
CVE-2026-64863
pkg: go

published: Jul 28, 2026

goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.4, the httpserver/server.go wdGuard handled WebDAV MOVE as a write-only method and did not enforce –no-delete, allowing WebDAV clients to delete or overwrite files via MOVE with Overwrite: T. This issue i…
CWE: CWE-284
NVD

CRITICAL
CVE-2026-62325
CVE-2026-62325
pkg: go

published: Jul 28, 2026

goshs is a feature-rich single-binary file server for red teamers and developers. From 2.1.3 until 2.1.4, the sftpserver/sftpserver.go password handler used Username != "" && Password != "", so running goshs with -b 'admin:' -sftp and no -fkf left both SFTP authentication handlers unset and allowed …
CWE: CWE-306
GitHub-GHSA

CRITICAL
goshs –no-delete WebDAV MOVE bypass allows file deletion/overwrite
GHSA-hq33-8jgp-8qq3
pkg: goshs.de/goshs/v2, github.com/patrickhener/goshs/v2, goshs.de/goshs
eco: go
published: Jul 28, 2026
## Summary

The WebDAV mode-flag guard added to fix GHSA-3whc-qvhv-xqjp still does not enforce `–no-delete` on the WebDAV `MOVE` verb. `MOVE` deletes the source file (rename removes it from its original path), and with `Overwrite: T` it additionally performs an explicit `RemoveAll` on the destinati…

CVE-2026-64863
GitHub-GHSA

CRITICAL
goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)
GHSA-rjrw-mjq6-hpmm
pkg: github.com/patrickhener/goshs/v2, goshs.de/goshs/v2
eco: go
published: Jul 28, 2026
## Summary

Start goshs v2.1.3 with `-b 'admin:' -sftp`. No `-fkf`. SFTP accepts connections without password. CVE-2026-40884 blocks the empty-username variant (`-b ':pass'`). The empty-password variant bypasses that fix.

## CVE-2026-40884

**CVE-2026-40884** (GHSA-c29w-qq4m-2gcv, Apr 13 2026) repo…

CVE-2026-62325
NVD

CRITICAL
CVE-2026-64551
CVE-2026-64551
pkg: linux

published: Jul 27, 2026

In the Linux kernel, the following vulnerability has been resolved:

sctp: validate STALE_COOKIE cause length before reading staleness

When an ERROR chunk with a STALE_COOKIE cause is received in the
COOKIE_ECHOED state, sctp_sf_do_5_2_6_stale() reads the 4-byte Measure
of Staleness that follows th…

GitHub-GHSA

CRITICAL
AWS Amplify Studio UI Component Properties Has an Input Validation Issue
GHSA-hf3j-86p7-mfw8
pkg: @aws-amplify/codegen-ui-react
eco: npm
published: Jul 30, 2026
### Summary
The AWS Amplify Studio [amplify-codegen-ui](https://github.com/aws-amplify/amplify-codegen-ui) is a package that generates front-end code from UI Builder entities (components, forms, views, and themes) primarily used in AWS Amplify Studio for component previews and in AWS Command Line In…
CVE-2025-4318
GitHub-GHSA

CRITICAL
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
GHSA-xr9x-r78c-5hrm
pkg: activestorage, activestorage, activestorage
eco: rubygems
published: Jul 30, 2026
### Impact
In its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds `secret_key_base` and often credentials for external systems, w…
CVE-2026-66066
GitHub-GHSA

CRITICAL
lettre has TLS hostname verification disabled when using Boring TLS backend
GHSA-4pj9-g833-qx53
pkg: lettre
eco: rust
published: Jul 28, 2026
### Summary
An inverted-boolean bug in lettre's `boring-tls` integration silently
disables TLS hostname verification for callers using the default (strict)
configuration. An on-path attacker presenting any chain-valid certificate
for any domain can intercept SMTP submission, including PLAIN/LOGIN
cr…
CVE-2026-46428
GitHub-GHSA

HIGH
AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping
GHSA-m4x6-gwgp-4pm7
pkg: @aws/agentcore, @aws/agentcore, @aws/agentcore
eco: npm
published: Jul 29, 2026
### Summary
The AgentCore CLI (@aws/agentcore) is a developer tool for managing agent infrastructure lifecycle on Amazon Bedrock AgentCore. An issue exists where, under certain circumstances, a crafted collaborationInstruction value stored in Bedrock Agent collaborator metadata can break out of a Py…
CVE-2026-11393
NVD

HIGH
CVE-2026-12562
CVE-2026-12562
pkg: linux

published: Jul 30, 2026

The RCU II+ and Multiload II+ are vulnerable to an unauthenticated
service that exposes a debug interface granting full root-level access
to the embedded system. This vulnerability stems from a
network-accessible port running a Target Communications Framework (TCF)
service that does not require …
CWE: CWE-306
NVD

HIGH
CVE-2026-67207
CVE-2026-67207
pkg: express

published: Jul 30, 2026

Wolf CMS through 0.8.3.1 contains an authorization bypass vulnerability in BackupRestoreController that allows authenticated non-administrative users to access restricted backup functionality due to a PHP operator precedence flaw in the permission check expression. Attackers can exploit the incorrec…
CWE: CWE-697
NVD

HIGH
CVE-2026-16526
CVE-2026-16526
pkg: linux

published: Jul 30, 2026

A flaw in the PCP linux_sockets module exposes an unsecured internal connection.
An attacker with initial code execution can exploit this to escalate privileges and execute arbitrary commands as root.
CWE: CWE-403
NVD

HIGH
CVE-2026-17894
CVE-2026-17894
pkg: linux

published: Jul 30, 2026

Use after free in Views in Google Chrome on Linux prior to 151.0.7922.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-416
NVD

HIGH
CVE-2026-17661
CVE-2026-17661
pkg: go

published: Jul 30, 2026

Use after free in Loader in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-17658
CVE-2026-17658
pkg: go

published: Jul 30, 2026

Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-64557
CVE-2026-64557
pkg: linux

published: Jul 29, 2026

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_new_connection_cb()

l2cap_sock_new_connection_cb() returned l2cap_pi(sk)->chan after
release_sock(parent). Once the parent lock is dropped the newly
enqueued child socket sk is re…

GitHub-GHSA

HIGH
Style Dictionary – Prototype Pollution in convertTokenData utility function
GHSA-vj5c-m527-mpff
pkg: style-dictionary
eco: npm
published: Jul 28, 2026
### Impact
Prototype pollution.
A malicious user can create a token array `[{ key: '{__proto__.foo}', value: 'malicious' }]`, when processed by `convertTokenData()` utility function, it will pollute the Object.prototype globally where `{}.foo` will equal `{ key: '{__proto__.foo}', value: 'malicious'…
CVE-2026-54639
NVD

HIGH
CVE-2026-54653
CVE-2026-54653
pkg: express

published: Jul 28, 2026

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. From 0.17.0 until 0.60.2, datamodel-code-generator preserves attacker-controlled default_factory values in src/datamodel_…
CWE: CWE-94, CWE-1336
GitHub-GHSA

HIGH
`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field
GHSA-386q-5hp3-95m9
pkg: datamodel-code-generator
eco: pip
published: Jul 28, 2026
### Summary

`datamodel-code-generator` is vulnerable to code injection when generating Python models from an attacker-controlled JSON Schema, OpenAPI, YAML, JSON, Avro, Protobuf, or XSD schema. When a property carries a `"default_factory"` key, its value is interpolated verbatim — as a raw Python…

CVE-2026-54653
NVD

HIGH
CVE-2026-66748
CVE-2026-66748
pkg: express

published: Jul 28, 2026

Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows users with custom_fields manage permission to execute arbitrary Ruby code by supplying a malicious expression through the select_eval custom field type. Attackers can store an attacker…
CWE: CWE-94
GitHub-GHSA

HIGH
Cedar-Java has policy injection, type confusion, and incorrect equality comparison vulnerabilities
GHSA-4r9r-4425-74p7
pkg: com.cedarpolicy:cedar-java, com.cedarpolicy:cedar-java, com.cedarpolicy:cedar-java
eco: maven
published: Jul 28, 2026
### Summary

CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisions. Under certain circumstances, it could lead to incorrect equality comparisons.

### Impact

**`EntityIdentifier.equals()` has inverted null/self branches**

The `E…

CVE-2026-55771
NVD

HIGH
CVE-2026-64555
CVE-2026-64555
pkg: linux

published: Jul 27, 2026

In the Linux kernel, the following vulnerability has been resolved:

KVM: arm64: nv: Fix SPSR_EL2 restore in kvm_hyp_handle_mops()

kvm_hyp_handle_mops() resets the single-step state machine as part of
rewinding state for a MOPS exception by modifying vcpu_cpsr() and
writing the result directly into…

NVD

HIGH
CVE-2026-64554
CVE-2026-64554
pkg: linux

published: Jul 27, 2026

In the Linux kernel, the following vulnerability has been resolved:

netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment()

br_ip6_fragment() gets prevhdr, a pointer into the skb head, from
ip6_find_1stfragopt(), then calls skb_checksum_help(). For a cloned skb
skb_checksum_help() reall…

GitHub-GHSA

HIGH
@apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script Tag
GHSA-wf43-fpp3-cf65
pkg: @apostrophecms/seo
eco: npm
published: Jul 31, 2026
<img width="1919" height="1046" alt="curl" src="https://github.com/user-attachments/assets/8aa19ff1-7f4b-44ee-83d5-d0dd1a0269f6" />
<img width="1919" height="775" alt="xss" src="https://github.com/user-attachments/assets/a65012e8-9b2f-416f-94df-c00493f2ca1d" />

### Summary

The `@apostrophecms/seo`…

CVE-2026-53608
GitHub-GHSA

HIGH
Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE mode
GHSA-qvv7-cg9c-w4x3
pkg: nltk
eco: pip
published: Jul 31, 2026
### Summary
`nltk.pathsec` provides an SSRF filter that NLTK documents as a security control, blocking loopback, private, link-local, and multicast ranges (including obfuscated forms) and recommending strict `ENFORCE` mode for security-sensitive environments. The filter is bypassable by DNS rebindin…
CVE-2026-12075
GitHub-GHSA

HIGH
Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url
GHSA-qq9q-xgm3-xv9g
pkg: flyto-core
eco: pip
published: Jul 30, 2026
## Summary

`llm.chat` reads the operator's provider key from the environment (`OPENAI_API_KEY`, `ANTHROPIC_API_KEY`, …) and sends it in the `Authorization: Bearer` header to `base_url`, a parameter the caller controls. `base_url` is only checked against the SSRF guard, and the guard allows any pu…

CVE-2026-67425
GitHub-GHSA

HIGH
Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted
GHSA-hr7p-wg7r-hg9m
pkg: flyto-core
eco: pip
published: Jul 30, 2026
## Summary

The capability policy denies the `env.get` and `env.load_dotenv` modules by default, with the stated reason that they read arbitrary host environment variables (API keys, DSNs) and are a secret-exfil risk. But the workflow engine's variable resolver expands `${env.VAR}` for any environme…

CVE-2026-67427
GitHub-GHSA

HIGH
openhole-server vulnerable to path traversal via URL-decoded request path
GHSA-fh2f-xfxc-q9cc
pkg: github.com/bablilayoub/openhole
eco: go
published: Jul 28, 2026
## Summary

openhole-server forwarded the URL-decoded request path (`r.URL.Path`) to tunnel clients instead of the original request-target. Percent-encoded dot-segments (`%2e`) and separators (`%2f`) were decoded to `../` and `/` before reaching the local service.

Go's ServeMux rejects literal `../…

CVE-2026-54650
NVD

HIGH
CVE-2026-54603
CVE-2026-54603
pkg: oauth

published: Jul 28, 2026

OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC). From 0.4.0 to 2.0.21, a protocol-relative redirect Location returned to OAuth2::Client#request overrides the request authority, so the bearer Authorization header is sent to an attacker-cont…
CWE: CWE-200, CWE-601
GitHub-GHSA

HIGH
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
GHSA-85rg-p3fr-xc2f
pkg: com.quietterminal:qti-neon, qti-neon, qti-neon
eco: npm
published: Jul 28, 2026
### Impact
The relay's reconnect handler forwards every `RECONNECT_REQUEST` to the host without deduplication or a size cap on the `pendingReconnects` map, unlike the connect flow which guards against this with `maxPendingConnections`. An unauthenticated attacker who knows a valid session ID can sen…
CVE-2026-54609
GitHub-GHSA

HIGH
OAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to attacker host
GHSA-pp92-crg2-gfv9
pkg: oauth2
eco: rubygems
published: Jul 28, 2026
## Summary

When an application uses `OAuth2::Client` (typically via an `OAuth2::AccessToken`) and the configured authorization server returns a redirect whose `Location` header is a protocol-relative URI of the form `//attacker.example/leak`, `OAuth2::Client#request` resolves the redirect with `res…

CVE-2026-54603
NVD

HIGH
CVE-2026-10079
CVE-2026-10079
pkg: kubernetes

published: Jul 31, 2026

A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, ACS replaces deployment identity metadata based on the openshift.io/encoded-deployment-config label. A user with permission to create Deployments can set this label to "null", causin…
CWE: CWE-345
NVD

HIGH
CVE-2026-62246
CVE-2026-62246
pkg: kubernetes

published: Jul 30, 2026

Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane datastore schema, database user, and etcd key prefix from a lossy namespace-and-name normalization in GetDefaultDatastoreSchema() and GetDefaultDatastoreUsername(), allowing distinct …
CWE: CWE-284, CWE-653
NVD

HIGH
CVE-2026-57862
CVE-2026-57862
pkg: curl

published: Jul 30, 2026

Kanboard 1.2.52 and prior contains a server-side request forgery vulnerability that allows authenticated users to bypass SSRF protections by supplying hexadecimal IP address notation in user-controlled URLs. Attackers can submit hexadecimal-encoded internal IP addresses through the web link creation…
CWE: CWE-918
GitHub-GHSA

HIGH
Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation
GHSA-c9hr-64h3-gxpc
pkg: flyto-core
eco: pip
published: Jul 30, 2026
## Summary
The HTTP modules that DO call the SSRF guard (`http.get`, `http.request`, `http.batch`) validate only the initial URL, then issue the request with aiohttp's default `allow_redirects=True` and perform no per-hop revalidation. An attacker hosts a public URL that 302-redirects to an internal…
CVE-2026-67424
GitHub-GHSA

HIGH
Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)
GHSA-pgwh-4jj4-qm8v
pkg: flyto-core
eco: pip
published: Jul 30, 2026
## Summary
Numerous HTTP-emitting modules (`core.api.http_get`, `core.api.http_post`, `graphql.query`/`graphql.mutation`, `monitor.http_check`, `communication.slack_send`, `notification.{discord,slack,teams}.send_message`, `ai.vision_analyze` [anthropic path], `verify.visual_diff`, `browser.proxy_ro…
CVE-2026-67428
GitHub-GHSA

HIGH
Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption
GHSA-qf5v-m7p4-95rp
pkg: github.com/fission/fission
eco: go
published: Jul 28, 2026
Fission v1.24.0 added PodSpec safety validation for tenant-facing Environment and Function CRDs (`ValidatePodSpecSafety` / `ValidateContainerSafety` admission webhook + `sanitizeContainerSecurityContext` executor merge layer), but the
capability check was implemented as a fixed **denylist of six Lin…
CVE-2026-50570
NVD

HIGH
CVE-2026-17877
CVE-2026-17877
pkg: linux

published: Jul 30, 2026

Inappropriate implementation in Chromoting in Google Chrome on Linux prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via malicious network traffic. (Chromium security severity: Medium)
CWE: CWE-269
NVD

HIGH
CVE-2026-64552
CVE-2026-64552
pkg: linux

published: Jul 27, 2026

In the Linux kernel, the following vulnerability has been resolved:

virtio-net: fix len check in receive_big()

receive_big() bounds the device-announced length by
(big_packets_num_skbfrags + 1) * PAGE_SIZE. That is still too loose:
add_recvbuf_big() sets sg[1] to start at offset
sizeof(struct pad…

NVD

HIGH
CVE-2026-64548
CVE-2026-64548
pkg: linux

published: Jul 27, 2026

In the Linux kernel, the following vulnerability has been resolved:

bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data()

When the scatterlist ring is full or nearly full, bpf_msg_push_data()
enters a copy fallback path and computes copy + len for the page
allocation size. Since len c…

NVD

HIGH
CVE-2026-66396
CVE-2026-66396
pkg: node

published: Jul 27, 2026

SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List value when rendering Gallery and Kanban cover images, allowing stored cross-site scripting via unescaped style attribute interpolation. Attackers with editor permissions can inject onload handlers that execute arbitrary cod…
CWE: CWE-79
NVD

HIGH
CVE-2026-47882
CVE-2026-47882
pkg: docker

published: Jul 30, 2026

When enabling Spring Boot DevTools support for a remote application target (for example a Docker container or Cloud Foundry app) from the Spring Tools Boot Dashboard, Spring Tools generates a shared secret that authenticates DevTools remote-restart uploads to the deployed application. This secret wa…
CWE: CWE-338
NVD

HIGH
CVE-2026-17723
CVE-2026-17723
pkg: windows

published: Jul 30, 2026

Use after free in Media in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-17660
CVE-2026-17660
pkg: go

published: Jul 30, 2026

Insufficient validation of untrusted input in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-20
NVD

HIGH
CVE-2026-17657
CVE-2026-17657
pkg: go

published: Jul 30, 2026

Use after free in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-17653
CVE-2026-17653
pkg: go

published: Jul 30, 2026

Use after free in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-17650
CVE-2026-17650
pkg: go

published: Jul 30, 2026

Use after free in Compositing in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-54666
CVE-2026-54666
pkg: axios

published: Jul 29, 2026

swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/schema-routes/schema-routes.ts passes OpenAPI path keys through parseRouteName to templates/default/procedure-call.ejs and templates/modular/procedure-call.ejs without escaping JavaSc…
CWE: CWE-74, CWE-94, CWE-1336
NVD

HIGH
CVE-2026-54664
CVE-2026-54664
pkg: axios

published: Jul 29, 2026

swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/schema-parser/base-schema-parsers/enum.ts passes components.schemas.*.enum[i] values to Ts.StringValue in src/configuration.ts without escaping before templates/base/enum-data-contrac…
CWE: CWE-74, CWE-94, CWE-1336
NVD

HIGH
CVE-2026-54662
CVE-2026-54662
pkg: axios

published: Jul 29, 2026

swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/code-gen-process.ts createApiConfig copies servers[0].url into apiConfig.baseUrl, and templates/base/http-clients/fetch-http-client.ejs interpolates apiConfig.baseUrl into the generated…
CWE: CWE-74, CWE-94, CWE-1336
NVD

HIGH
CVE-2026-54661
CVE-2026-54661
pkg: axios

published: Jul 29, 2026

swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, templates/base/http-clients/axios-http-client.ejs interpolates servers[0].url from src/code-gen-process.ts into the HttpClient constructor without escaping, allowing an attacker-controlle…
CWE: CWE-74, CWE-94, CWE-1336
GitHub-GHSA

HIGH
swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies
GHSA-w284-33mx-6g9v
pkg: swagger-typescript-api
eco: npm
published: Jul 29, 2026
### Summary

`swagger-typescript-api` interpolates OpenAPI path strings (the keys of the `paths` object, e.g. `/users/{id}`) directly into a JavaScript template literal inside the body of every generated API method, without escaping. A spec path containing `${ … }` survives `parseRouteName`'s `{x}…

CVE-2026-54666
GitHub-GHSA

HIGH
swagger-typescript-api vulnerable to code injection via unescaped enum string values
GHSA-5f94-x226-ccpm
pkg: swagger-typescript-api
eco: npm
published: Jul 29, 2026
### Summary

`swagger-typescript-api` interpolates `components.schemas.*.enum[i]` string values into the body of generated TypeScript `enum` declarations without escaping. A malicious enum value can close the enclosing string literal, terminate the enum body, and inject a bare-block IIFE that execut…

CVE-2026-54664
GitHub-GHSA

HIGH
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template
GHSA-38c3-wv3c-v3xj
pkg: swagger-typescript-api
eco: npm
published: Jul 29, 2026
### Summary

`swagger-typescript-api` interpolates `servers[0].url` directly into a TypeScript string literal inside the `HttpClient` constructor body of the generated **axios** client (`templates/base/http-clients/axios-http-client.ejs:71`), without any escaping. A malicious URL containing a `"` cl…

CVE-2026-54661
GitHub-GHSA

HIGH
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template
GHSA-hqj5-cw9f-rx67
pkg: swagger-typescript-api
eco: npm
published: Jul 29, 2026
### Summary

`swagger-typescript-api` interpolates `servers[0].url` directly into a TypeScript class-body field initializer of the generated **fetch** `HttpClient` (`templates/base/http-clients/fetch-http-client.ejs:75`), without any escaping. A malicious URL containing a `"` closes the string liter…

CVE-2026-54662
NVD

HIGH
CVE-2026-53501
CVE-2026-53501
pkg: python

published: Jul 31, 2026

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC validation can be bypassed due to the use of Python’s .replace() when removing the signature from the URL before validation. Since .replace() removes all occurrences of the substring, an attacker can i…
CWE: CWE-347
GitHub-GHSA

HIGH
Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature
GHSA-mw3h-qjxj-6xg9
pkg: thumbor
eco: pip
published: Jul 31, 2026
# HMAC validation bypass via multiple `.replace()` calls when removing URL signature

## Summary

Thumbor’s HMAC validation can be bypassed due to the use of Python’s `.replace()` when removing the signature from the URL before validation. Since `.replace()` removes **all occurrences** of the su…

CVE-2026-53501
GitHub-GHSA

HIGH
Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot
GHSA-6×26-6r6f-m537
pkg: thumbor
eco: pip
published: Jul 31, 2026
## Summary

The `ALLOWED_SOURCES` configuration is meant to restrict which hosts Thumbor's HTTP loader may fetch images from. Plain-string entries in that list (the overwhelming majority of real-world and documented configurations) are passed directly to `re.match()` without escaping. Because `.` is…

CVE-2026-53500
NVD

HIGH
CVE-2026-56672
CVE-2026-56672
pkg: node

published: Jul 31, 2026

ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, GET /userdata/{file} served user-controlled HTML and SVG files with extension-derived content types, allowing stored cross-site scripting in the ComfyUI origin and access to browser-stored API tokens, settings, workflows…
CWE: CWE-79
NVD

HIGH
CVE-2026-54574
CVE-2026-54574
pkg: docker

published: Jul 29, 2026

proot-distro is a utility for managing proot containers. Prior to version 5.1.5, proot-distro install extracted plain tarball root filesystems through _extract_plain_tar() in proot_distro/commands/install.py and Docker layers through _apply_layer() in proot_distro/helpers/docker.py without validatin…
CWE: CWE-61
GitHub-GHSA

HIGH
proot-distro has a Container Isolation Bypass via Crafted Restore Archive
GHSA-7h3g-4w2f-fj2f
pkg: proot-distro
eco: pip
published: Jul 29, 2026
## Affected Component

– **Package:** proot-distro
– **Affected command:** `restore`
– **Attack surface:** Host-side Termux CLI processing a user-supplied backup archive
– **Vulnerability type:** Container Isolation Bypass / Cross-Container Read and Write

## Affected Versions

| Component | Ve…

CVE-2026-54727
GitHub-GHSA

HIGH
`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive
GHSA-9xq3-3fqg-4vg7
pkg: proot-distro
eco: pip
published: Jul 29, 2026
**Repository:** `termux/proot-distro`
**Component:** `proot_distro/commands/install.py` → `_extract_plain_tar()`; also `helpers/docker.py` → `_apply_layer()`

## Affected Versions

| Component | Version |
|—————|——————————|
| proo…

CVE-2026-54574
NVD

HIGH
CVE-2026-22068
CVE-2026-22068
pkg: express

published: Jul 29, 2026

Regular Expression without Anchors vulnerability in Apache Traffic Server.

This issue affects Apache Traffic Server: from 10.0.X through 10.1.3, from 9.0.X through 9.2.14.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.

CWE: CWE-777
NVD

HIGH
CVE-2026-54691
CVE-2026-54691
pkg: python

published: Jul 28, 2026

datamodel-code-generator generates Python data models from schema definitions. From 0.9.1 until 0.61.0, src/datamodel_code_generator/http.py http.get_body accepts –url targets and redirect chain targets without host/IP validation, allowing server-side request forgery against loopback, private, link…
CWE: CWE-918
GitHub-GHSA

HIGH
datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)
GHSA-954p-556p-r752
pkg: datamodel-code-generator
eco: pip
published: Jul 28, 2026
### Summary

JSON-Schema `$ref` values pointing at HTTP or HTTPS URLs are silently dereferenced by `datamodel-code-generator` with no IP/host validation, no scheme allow-list, and redirects followed unconditionally. The `–allow-remote-refs` gate added in 0.56.0 defaults to `None`, which only emits …

CVE-2026-54690
GitHub-GHSA

HIGH
datamodel-code-generator vulnerable to SSRF via –url: no host/IP validation, follows redirects
GHSA-rfr2-mq9m-x2qx
pkg: datamodel-code-generator
eco: pip
published: Jul 28, 2026
### Summary

`datamodel-code-generator`'s built-in HTTP fetcher (`http.get_body`) issues an `httpx.GET` against any URL passed to `–url` (or reached via a redirect chain) with **no allow-list, no deny-list, no IP/host validation, and `follow_redirects=True`**. Loopback addresses, RFC1918 ranges, li…

CVE-2026-54691
GitHub-GHSA

HIGH
java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutor
GHSA-28f5-38xr-jh2w
pkg: io.appium:java-client
eco: maven
published: Jul 28, 2026
## Summary

When `directConnect(true)` is enabled, appium/java-client unconditionally
accepts `directConnectHost`, `directConnectPort`, and `directConnectPath`
from the server's NEW_SESSION response and silently redirects all subsequent
session traffic to the attacker-specified endpoint — with no …

CVE-2026-43910
NVD

HIGH
CVE-2026-64642
CVE-2026-64642
pkg: vercel next.js

published: Jul 27, 2026

Next.js is a React framework for building full-stack web applications. In versions 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router built with Turbopack and a single entry in config.i18n.locales can bypass middleware/proxy based authentication. This issue has …
CWE: CWE-285
NVD

HIGH
CVE-2026-68581
CVE-2026-68581
pkg: jwt

published: Aug 2, 2026

Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and link-share IDs are independent numeric sequences and both resolve through a generic web.Auth.GetID() interface, a link-share JWT whose numeric ID equals a target user's ID is treat…
CWE: CWE-863
GitHub-GHSA

HIGH
Savon::Model evaluates WSDL operation names as Ruby source
GHSA-mx5j-mp4f-g8jg
pkg: savon
eco: rubygems
published: Jul 31, 2026
### Impact

`Savon::Model` generated SOAP operation methods by interpolating operation names into Ruby source passed to `module_eval`. An attacker who can control the operation names of a WSDL, can inject Ruby code that executes in the application process. This affects only the `.all_operations` cla…

CVE-2026-53510
NVD

HIGH
CVE-2026-67345
CVE-2026-67345
pkg: oauth

published: Jul 30, 2026

MaxKey through 4.1.12, fixed in commit ddbb72f, contains an insufficient redirect URI validation vulnerability in DefaultRedirectResolver.hostMatches() that allows remote attackers to hijack OAuth 2.0 authorization codes by supplying a crafted redirect_uri whose hostname suffix matches a registered …
CWE: CWE-183
NVD

HIGH
CVE-2026-63231
CVE-2026-63231
pkg: jwt

published: Jul 29, 2026

A post-authentication SQL injection
vulnerability in Koollab LMS allowed an authenticated attacker to use an error-based SQL oracle via
the face-to-face runs update endpoint to read the entire application database
and obtain valid JWT tokens for account takeover.
CWE: CWE-89
NVD

HIGH
CVE-2026-14300
CVE-2026-14300
pkg: go

published: Jul 29, 2026

The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) WordPress plugin before 7.8.0 does not bind the one-time code used by its optional email-verification (Profile Completion) feature to the account it was issued for, allowing unauthenticated attackers to obtain a valid sess…
CWE: CWE-287
NVD

HIGH
CVE-2026-54593
CVE-2026-54593
pkg: jwt

published: Jul 28, 2026

Pterodactyl is a free, open-source game server management panel. Prior to Panel version 1.12.3 and Wings version 1.12.2, the Wings /upload/file endpoint accepted any valid panel-signed JWT that contained server_uuid, user_uuid, and unique_id claims without checking the token's intended purpose; beca…
CWE: CWE-1259, CWE-1270
GitHub-GHSA

HIGH
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions
GHSA-8r6w-3qq5-4p4r
pkg: pterodactyl/panel, github.com/pterodactyl/wings
eco: go
published: Jul 28, 2026
### Summary
A privilege escalation vulnerability exists in the Wings /upload/file endpoint due to insufficient validation of panel-signed JWTs. Wings accepts any valid panel-signed JWT containing `server_uuid`, `user_uuid`, and `unique_id`, regardless of the token’s intended purpose. Because the P…
CVE-2026-54593
NVD

HIGH
CVE-2026-64547
CVE-2026-64547
pkg: linux

published: Jul 27, 2026

In the Linux kernel, the following vulnerability has been resolved:

net: usb: net1080: validate packet_len before pad-byte access in rx_fixup

For an even packet_len, net1080_rx_fixup() reads the pad byte at
skb->data[packet_len] before the skb->len != packet_len check further
down, and packet_len …

NVD

HIGH
CVE-2026-64540
CVE-2026-64540
pkg: linux

published: Jul 27, 2026

In the Linux kernel, the following vulnerability has been resolved:

usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup()

genelink_rx_fixup() splits an aggregated RX frame into its individual
packets, using a per-packet length taken from device-supplied data. That
length is only bounded by…

NVD

HIGH
CVE-2026-47873
CVE-2026-47873
pkg: docker

published: Jul 30, 2026

The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of the host's network interfaces (0.0.0.0) rather than restricting them to loopback.
Affected Spring Products and Versions:
Spring Tools for Eclipse: 5.2.0 and earlier
CWE: CWE-1327
NVD

HIGH
CVE-2026-16524
CVE-2026-16524
pkg: linux

published: Jul 30, 2026

A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric.
This failed validation lets attackers execute arbitrary commands as the PMDA user when metrics refresh.
CWE: CWE-78
NVD

HIGH
CVE-2026-17863
CVE-2026-17863
pkg: windows

published: Jul 30, 2026

Inappropriate implementation in Browser in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Medium)
CWE: CWE-269
NVD

HIGH
CVE-2026-17862
CVE-2026-17862
pkg: windows

published: Jul 30, 2026

Use after free in Tracing in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium)
CWE: CWE-416
NVD

HIGH
CVE-2026-17654
CVE-2026-17654
pkg: go

published: Jul 30, 2026

Race in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Critical)
CWE: CWE-362
NVD

HIGH
CVE-2026-64560
CVE-2026-64560
pkg: linux

published: Jul 29, 2026

In the Linux kernel, the following vulnerability has been resolved:

posix-cpu-timers: Prevent UAF caused by non-leader exec() race

Wongi and Jungwoo decoded and reported a non-leader exec() related race
which can result in an UAF:

sys_timer_delete() exec()
posix_cpu_timer_del()
// Observ…

NVD

HIGH
CVE-2026-64559
CVE-2026-64559
pkg: linux

published: Jul 29, 2026

In the Linux kernel, the following vulnerability has been resolved:

s390/pkey: Check length in PKEY_VERIFYPROTK ioctl

Explicitly check the buffer length request structure provided by
user-space and fail, if it exceeds the buffer size.

NVD

HIGH
CVE-2026-64558
CVE-2026-64558
pkg: linux

published: Jul 29, 2026

In the Linux kernel, the following vulnerability has been resolved:

s390/pkey: Check length in pkey_pckmo handler implementation

Explicitly check the length of the target buffer in the pkey_pckmo
implementation of the key_to_protkey() handler function. The handler
function fails, if the generated …

NVD

HIGH
CVE-2026-64556
CVE-2026-64556
pkg: linux

published: Jul 29, 2026

In the Linux kernel, the following vulnerability has been resolved:

perf/core: Detach event groups during remove_on_exec

perf_event_remove_on_exec() removes events by calling
perf_event_exit_event(). For top-level events, this removes the event from
the context with DETACH_EXIT only.

This can lea…

NVD

HIGH
CVE-2026-54656
CVE-2026-54656
pkg: python

published: Jul 28, 2026

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. From 0.52.1 until 0.60.2, datamodel-code-generator interpolates validators from –extra-template-data in src/datamodel_cod…
CWE: CWE-94
NVD

HIGH
CVE-2026-54655
CVE-2026-54655
pkg: python

published: Jul 28, 2026

datamodel-code-generator generates Python data models from schema definitions. From 0.51.0 until 0.60.2, x-python-type values parsed by src/datamodel_code_generator/parser/jsonschema.py in _get_python_type_override are inserted into generated field annotations without sufficient validation, allowing…
CWE: CWE-94
NVD

HIGH
CVE-2026-54654
CVE-2026-54654
pkg: python

published: Jul 28, 2026

datamodel-code-generator generates Python data models from schema definitions. From 0.14.1 until 0.60.2, the –extra-template-data comment field is rendered into Python comments in src/datamodel_code_generator/model/template/TypeAliasAnnotation.jinja2, src/datamodel_code_generator/model/template/Typ…
CWE: CWE-94, CWE-1336
NVD

HIGH
CVE-2026-54621
CVE-2026-54621
pkg: python

published: Jul 28, 2026

datamodel-code-generator generates Python data models from schema definitions. Prior to 0.60.1, GraphQL Union description values in src/datamodel_code_generator/model/template/UnionTypeStatement.jinja2 and src/datamodel_code_generator/model/template/UnionTypeStatement.py312.jinja2 are rendered into …
CWE: CWE-94, CWE-1336
GitHub-GHSA

HIGH
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `–extra-template-data` `comment` field
GHSA-wjv6-jcfj-mf9r
pkg: datamodel-code-generator
eco: pip
published: Jul 28, 2026
### Summary

`datamodel-code-generator` is vulnerable to code injection when a developer passes an `–extra-template-data` file whose `comment` value contains a literal `\r` (carriage return). The `comment` variable is rendered into a Python `#` comment in six built-in templates with **no** line-ter…

CVE-2026-54654
GitHub-GHSA

HIGH
`datamodel-code-generator` vulnerable to code execution on import via unescaped `validators` entries in –extra-template-data
GHSA-8m8r-38jm-f355
pkg: datamodel-code-generator
eco: pip
published: Jul 28, 2026
### Summary

When the Pydantic v2 output mode is in use, `datamodel-code-generator` reads a `validators` array from each model entry in the `–extra-template-data` file and synthesises a Pydantic `@field_validator(…)` decorator from each entry. The field names and the validator mode are interpolat…

CVE-2026-54656
GitHub-GHSA

HIGH
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description
GHSA-j884-q54q-mmx3
pkg: datamodel-code-generator
eco: pip
published: Jul 28, 2026
### Summary

`datamodel-code-generator` is vulnerable to code injection when generating Python models from an attacker-controlled GraphQL schema. A description on a Union type, written in the regular-string form (`"…"`) with a literal `\r` escape, is rendered into a Python `#` comment by a Jinja2 …

CVE-2026-54621
GitHub-GHSA

HIGH
`datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON-Schema extension in datamodel-code-generator
GHSA-m34r-v34r-rf9q
pkg: datamodel-code-generator
eco: pip
published: Jul 28, 2026
### Summary
`datamodel-code-generator` honours a custom `x-python-type` JSON-Schema extension that lets a schema author override the generated Python type for a field. The value is forwarded verbatim into the generated Python source as the field annotation, with a single sanitisation pass that is tr…
CVE-2026-54655
NVD

HIGH
CVE-2026-64543
CVE-2026-64543
pkg: linux

published: Jul 27, 2026

In the Linux kernel, the following vulnerability has been resolved:

tipc: fix use-after-free of the discoverer in tipc_disc_rcv()

bearer_disable() frees b->disc with tipc_disc_delete()'s plain kfree(),
but tipc_disc_rcv() still dereferences b->disc in RX softirq under
rcu_read_lock() (tipc_udp_rec…

NVD

HIGH
CVE-2026-64539
CVE-2026-64539
pkg: linux

published: Jul 27, 2026

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: eir: Fix stack OOB write when prepending the Flags AD

eir_create_adv_data() builds the advertising data into a fixed-size
buffer ("size", 31 for the legacy path). It may prepend a 3-byte "Flags"
AD structure (LE_AD_NO_B…

NVD

HIGH
CVE-2026-24252
CVE-2026-24252
pkg: linux

published: Jul 27, 2026

NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A successful exploit of this vulnerability may lead to code execution, data tampering, escalation of privileges and information disclosure.
CWE: CWE-78
NVD

HIGH
CVE-2026-17523
CVE-2026-17523
pkg: linux

published: Jul 27, 2026

A flaw was found in the Linux kernel in net/can/bcm.c in can: bcm, where an unprivileged local user can exploit this vulnerability to execute arbitrary code within the kernel, which leads to a local privilege escalation (LPE). This allows the attacker to gain root privileges and take full control of…
CWE: CWE-825
GitHub-GHSA

HIGH
FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files
GHSA-vvp7-h4fj-m28w
pkg: github.com/gtsteffaniak/filebrowser/backend
eco: go
published: Jul 31, 2026
### Summary

The `subtitlesHandler` endpoint (`GET /api/media/subtitles`) accepts two user-controlled query parameters: `path` and `name`, both of which are used in filesystem operations without sanitization, creating two independent path traversal vectors.

The primary vector is the `path` paramete…

CVE-2026-54910
GitHub-GHSA

HIGH
Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory
GHSA-q6vm-xqc9-v3ff
pkg: github.com/fission/fission
eco: go
published: Jul 28, 2026
`Unarchive` in `pkg/utils/zip.go` joined each archive entry name with the destination directory via `filepath.Join` and wrote the result without checking whether the resolved path stayed under the destination. A zip entry named
`../../tmp/evil` therefore landed at `/tmp/evil`. An attacker who coul…
CVE-2026-50567
NVD

HIGH
CVE-2026-18381
CVE-2026-18381
pkg: kubernetes

published: Jul 30, 2026

A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary upload URL. The operator attaches its own Kubernetes service-account bearer token to queries sent to this user-con…
CWE: CWE-918
NVD

HIGH
CVE-2026-66427
CVE-2026-66427
pkg: go

published: Jul 27, 2026

Administrator SQL Injection in WP Google Review Slider <= 18.4 versions.
CWE: CWE-89
NVD

HIGH
CVE-2026-53504
CVE-2026-53504
pkg: express

published: Jul 31, 2026

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the convolution filter regular expression performs exponential backtracking on crafted repeated numeric input, allowing a URL request to exhaust processing time. This issue is fixed in 7.8.0.
CWE: CWE-400
GitHub-GHSA

HIGH
Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS
GHSA-phj3-59pf-cp83
pkg: thumbor
eco: pip
published: Jul 31, 2026
### Summary
Thumbor's `filters:proportion(<value>)` filter does not enforce an upper bound on `<value>` and runs in the post-transform phase. An attacker can trigger extremely large resizes (CPU/memory exhaustion) and cause denial of service.

### Details
– Filter implementation: `thumbor/filters/pr…

CVE-2026-53505
GitHub-GHSA

HIGH
Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter
GHSA-5vjc-7cxw-4w6j
pkg: thumbor
eco: pip
published: Jul 31, 2026
### Summary
The regular expression used to parse the `convolution` filter exhibits exponential-time backtracking for certain inputs, enabling a Regular Expression Denial of Service (ReDoS).

### Details
The RegExp for `convolution` is defined as `convolution\((?:\s*((?:[-]?[\d]+\.?[\d]*[;])*(?:[-]?[…

CVE-2026-53504
GitHub-GHSA

HIGH
Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoS
GHSA-cqjp-jf4r-h5q9
pkg: thumbor
eco: pip
published: Jul 31, 2026
### Summary
Thumbor's `filters:convolution(<matrix>, <columns>, <should_normalize>)` filter passes the user-controlled `<columns>` value to a C extension (`thumbor/ext/filters/_convolution.c`) where it is used as a divisor (for `%` and `/`) without validating `columns > 0`. When `columns=0`, the C c…
CVE-2026-53503
GitHub-GHSA

HIGH
Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)
GHSA-93wv-jw9v-4972
pkg: io.netty:netty-codec-http2, io.netty:netty-codec-http2
eco: maven
published: Jul 31, 2026
### Summary

A remote, unauthenticated peer can leak one direct `ByteBuf` per HTTP/2 `DATA` frame in
applications that enable HTTP/2 content decompression via `DelegatingDecompressorFrameListener`.
When a `DATA` frame is processed for a stream whose decompressor has already been closed,
`Http2Decomp…

CVE-2026-56819
GitHub-GHSA

HIGH
Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex
GHSA-fg7f-2386-8897
pkg: nltk
eco: pip
published: Jul 31, 2026
### Summary
`ReviewsCorpusReader` extracts feature annotations of the form *label* followed by a bracketed signed digit (e.g. a label then `[+2]`) from each review line, using the module-level `FEATURES` regex. The feature-label sub-pattern is unbounded — an optional greedy run of word-plus-whites…
CVE-2026-12061
GitHub-GHSA

HIGH
Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)
GHSA-6hm5-jgcp-p838
pkg: nltk
eco: pip
published: Jul 31, 2026
### Summary
A path-traversal vulnerability in `NKJPCorpusReader` allows an attacker who can
influence the `fileids` argument of its public read methods (`header`, `raw`,
`words`, `sents`, `tagged_words`) to read files outside the corpus root. The
reader builds the file path with no conta…
CVE-2026-12072
GitHub-GHSA

HIGH
Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)
GHSA-xh95-f55m-82fw
pkg: nltk
eco: pip
published: Jul 31, 2026
### Summary
`FramenetCorpusReader.frame(name)` interpolates a caller-supplied frame name into an XML file path that is read with the builtin `open()`, bypassing `CorpusReader.open()` and the `nltk.pathsec` sandbox — including strict `ENFORCE=True` mode. A `../` sequence in the name escapes the cor…
CVE-2026-12074
GitHub-GHSA

HIGH
Spring Data: Unbounded property-path cache keyed by externally-supplied path string
GHSA-88fw-v6x4-3f58
pkg: org.springframework.data:spring-data-commons, org.springframework.data:spring-data-commons, org.springframework.data:spring-data-commons
eco: maven
published: Jul 31, 2026
`src/main/java/org/springframework/data/mapping/context/PersistentPropertyPathFactory.java:175` · Unbounded Resource Allocation (Algorithmic DoS)

### Impact

When a consuming module routes user-supplied dot-paths (sort parameters, projection paths, PATCH paths) through `MappingContext.getPersisten…

CVE-2026-41695
GitHub-GHSA

HIGH
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service
GHSA-ghrq-5wpp-hxx5
pkg: github.com/pterodactyl/wings
eco: go
published: Jul 31, 2026
### Summary
A maliciously crafted packet received & parsed during the SFTP connection handshake will cause a Go panic.

### Impact
All wings users with an open SFTP port.

### Workarounds
Close SFTP port.

CVE-2026-52856
NVD

HIGH
CVE-2026-17347
CVE-2026-17347
pkg: windows

published: Jul 31, 2026

The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that returns a per-user encryption key, with %u in the configured string replaced by the current user's name. The previous implementation substituted the username directly into the comm…
CWE: CWE-78, CWE-88
GitHub-GHSA

HIGH
`@dynatrace-oss/dynatrace-mcp-server` has Unauthenticated HTTP MCP Tool Invocation
GHSA-p7w7-4929-vpj5
pkg: @dynatrace-oss/dynatrace-mcp-server
eco: npm
published: Jul 31, 2026
### Summary

`@dynatrace-oss/dynatrace-mcp-server` v1.8.5 exposes an HTTP transport mode (`–http` flag) that performs no authentication, session validation, or origin/host verification before dispatching MCP tool calls. Any network-reachable attacker can send a raw JSON-RPC `tools/call` request wit…

NVD

HIGH
CVE-2026-18446
CVE-2026-18446
pkg: node

published: Jul 31, 2026

fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a reference that uses a backslash based introducer in place of it (backslash backslash, forward slash backslash, or backslash forward slash) is parsed with no authority and folds into the…
CWE: CWE-436
NVD

HIGH
CVE-2026-18358
CVE-2026-18358
pkg: linux

published: Jul 31, 2026

A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the incoming connection handler bypasses the connection throttler, allowing an unauthenticated remote attacker to open many parallel pre-authentication connect…
CWE: CWE-400
NVD

HIGH
CVE-2026-56673
CVE-2026-56673
pkg: node

published: Jul 31, 2026

ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node interface. Prior to 0.28.0, folder_paths.get_annotated_filepath and exists_annotated_filepath join workflow-controlled annotated filenames to a base directory without a containment check, allowing an unauthenticated cra…
CWE: CWE-22
NVD

HIGH
CVE-2026-61536
CVE-2026-61536
pkg: python

published: Jul 30, 2026

Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.3, banks parses Tool JSON objects from the rendered body of {% completion %} blocks and later resolves their import_path field through importlib.import_module(…) + getattr(…) to obtain the callable …
CWE: CWE-94, CWE-470
NVD

HIGH
CVE-2026-15977
CVE-2026-15977
pkg: ssl

published: Jul 30, 2026

SGLang contains a credential leakage vulnerability in the /server_info endpoint, which will return API keys and SSL keyfile information when only the –admin-api-key is configured.
CWE: CWE-522
NVD

HIGH
CVE-2026-62663
CVE-2026-62663
pkg: python

published: Jul 30, 2026

Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.4, all four media filters (image, audio, video, document) in banks accept untrusted user input as file paths via Path(value) and pass them directly to open(file_path, "rb") without any path sanitization…
CWE: CWE-22
GitHub-GHSA

HIGH
MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport
GHSA-h669-8m4g-r2hc
pkg: mcp
eco: rubygems
published: Jul 30, 2026
## Summary

An unauthenticated remote attacker can force any MCP Ruby SDK server using `MCP::Server::Transports::StreamableHTTPTransport` to allocate gigabytes of memory by sending a single oversized JSON-RPC POST. The transport reads the entire HTTP body into a Ruby `String` and parses it with `JSO…

CVE-2026-67432
GitHub-GHSA

HIGH
OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)
GHSA-xpxj-f2fm-rqch
pkg: github.com/OliveTin/OliveTin
eco: go
published: Jul 30, 2026
## Summary

OliveTin's OAuth2 login handler stores per-login state in an in-memory map (`registeredStates`) that grows unboundedly. States are added on every `/oauth/login` request but are **never deleted or expired**. An unauthenticated attacker can send millions of requests to `/oauth/login` to fi…

CVE-2026-67437
NVD

HIGH
CVE-2026-54365
CVE-2026-54365
pkg: windows

published: Jul 30, 2026

CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthenticated attackers to create arbitrary local OS user accounts by supplying a crafted base64-encoded XML string to exposed API endpoints. Attackers can send a malicious StorageConfi…
CWE: CWE-306
NVD

HIGH
CVE-2026-58043
CVE-2026-58043
pkg: node

published: Jul 30, 2026

A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries.

Under `–permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist.

This vu…

CWE: CWE-284
NVD

HIGH
CVE-2026-67437
CVE-2026-67437
pkg: oauth

published: Jul 29, 2026

OliveTin gives access to predefined shell commands from a web interface. From 3000.0.0 until 3000.17.0, the service/internal/auth/otoauth2/restapi_auth_oauth2.go OAuth2 login handler stores per-login state in the registeredStates map on every /oauth/login request without expiring, deleting, or bound…
CWE: CWE-400, CWE-401, CWE-770
GitHub-GHSA

HIGH
Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities
GHSA-qcxp-gm7m-4j5v
pkg: io.quarkus:quarkus-vertx-http, io.quarkus:quarkus-vertx-http, io.quarkus:quarkus-vertx-http
eco: maven
published: Jul 29, 2026
Quarkus HTTP path-based authorization policies can be bypassed using encoded semicolons (%3B) to smuggle matrix
parameters past the security layer, and using encoded slashes (%2F) or backslashes (%5C) to access protected static
resources. This is a distinct issue from CVE-2026-39852, which addre…
CVE-2026-50559
NVD

HIGH
CVE-2026-58161
CVE-2026-58161
pkg: tls

published: Jul 29, 2026

Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handling.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix…

CWE: CWE-476
NVD

HIGH
CVE-2026-54719
CVE-2026-54719
pkg: go

published: Jul 28, 2026

goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.1, the httpserver/updown.go bulkDownload handler for ?bulk&file= ZIP downloads did not call findEffectiveACL or applyCustomAuth, allowing unauthenticated reads of files protected only by .goshs folder ACLs…
CWE: CWE-862, CWE-863
NVD

HIGH
CVE-2026-54638
CVE-2026-54638
pkg: go

published: Jul 28, 2026

gotd/td is a T Telegram MTProto API client in Go. Prior to 0.145.1, proto.UnencryptedMessage.Decode in proto/unencrypted_message.go read attacker controlled dataLen from an unauthenticated MTProto unencrypted packet and allocated make([]byte, dataLen) before checking the remaining buffer, allowing r…
CWE: CWE-770, CWE-789
NVD

HIGH
CVE-2026-47219
CVE-2026-47219
pkg: node

published: Jul 28, 2026

find-my-way is a framework-independent HTTP router that internally uses a Radix Tree and supports route parameters and wildcards. Versions prior to 9.7.0 are vulnerable to remotely triggerable DoS in find-my-way when it is used with Node's HTTP/2 server. The lookup() function passes req.method into …
CWE: CWE-20, CWE-248
NVD

HIGH
CVE-2026-55415
CVE-2026-55415
pkg: python

published: Jul 28, 2026

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. From 0.11.6 until 0.64.0, datamodel-code-generator allows attacker-controlled x-python-import or customTypePath schema ext…
CWE: CWE-94, CWE-95
NVD

HIGH
CVE-2026-55390
CVE-2026-55390
pkg: python

published: Jul 28, 2026

datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.62.0, XML Schema parsing in src/datamodel_code_generator/parser/xmlschema.py for –input-file-type xmlschema resolves xs:include, xs:import, xs:redefine, and xs:override schemaLocation values outside t…
CWE: CWE-22, CWE-200, CWE-610
GitHub-GHSA

HIGH
td has pre-auth denial of service via unbounded memory allocation in proto.UnencryptedMessage.Decode
GHSA-whmm-qj9r-wvr2
pkg: github.com/gotd/td
eco: go
published: Jul 28, 2026
### Impact

A remote, unauthenticated attacker can cause excessive memory allocation (and resulting CPU / GC pressure, potentially OOM termination) by sending a crafted unencrypted MTProto packet.

`(*proto.UnencryptedMessage).Decode` read an attacker-controlled 32-bit `dataLen` field and immediatel…

CVE-2026-54638
GitHub-GHSA

HIGH
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx)
GHSA-rmxw-pq4x-3fvh
pkg: github.com/patrickhener/goshs, github.com/patrickhener/goshs/v2, goshs.de/goshs
eco: go
published: Jul 28, 2026
GHSA-wvhv-qcqf-f3cx fixed the per-folder .goshs ACL bypass on the state-changing routes (PUT/POST upload/?mkdir/?delete) and added recursive ACL resolution, and its description states the read/list path correctly enforces .goshs. That premise does not hold for the ?bulk zip-download route. bulkDownl…
CVE-2026-54719
GitHub-GHSA

HIGH
datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `–no-allow-remote-refs`
GHSA-8359-h9fx-j6v9
pkg: datamodel-code-generator
eco: pip
published: Jul 28, 2026
### Summary

`datamodel-code-generator` resolves JSON-Schema `$ref` targets that point at the local filesystem without restricting them to the input/base directory and without honoring the remote-reference security control. In the default configuration, an attacker who controls an input schema (a "p…

CVE-2026-55389
GitHub-GHSA

HIGH
datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding
GHSA-vx7x-vcc2-c44g
pkg: datamodel-code-generator
eco: pip
published: Jul 28, 2026
### Summary

`datamodel-code-generator`'s anti-SSRF guard validates the resolved IP of a fetch target once and then lets `httpx` perform its own independent DNS resolution to connect, so the validated address is never pinned. A hostname that resolves to a public IP at validation time and a private I…

CVE-2026-55391
GitHub-GHSA

HIGH
datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements
GHSA-5578-w22f-pfx9
pkg: datamodel-code-generator
eco: pip
published: Jul 28, 2026
#### Summary

A malicious input schema (OpenAPI / JSON Schema) can execute arbitrary Python code on the machine that **imports** the generated model. The `x-python-import` and `customTypePath` schema extensions flow, unsanitized, into the `import` statements datamodel-code-generator emits. A newline…

CVE-2026-55415
GitHub-GHSA

HIGH
datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate
GHSA-442q-2j6p-642g
pkg: datamodel-code-generator
eco: pip
published: Jul 28, 2026
### Summary

When generating models from an XML Schema (`–input-file-type xmlschema`), `datamodel-code-generator` resolves `<xs:include>`, `<xs:import>`, `<xs:redefine>`, and `<xs:override>` `schemaLocation` attributes against the source directory and reads the target with no restriction to the inp…

CVE-2026-55390
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-32203 – .NET and Visual Studio Denial of Service Vulnerability
GHSA-6588-8gv4-xfgh
pkg: System.Security.Cryptography.Xml, System.Security.Cryptography.Xml, System.Security.Cryptography.Xml
eco: nuget
published: Jul 28, 2026
## Executive Summary:

Microsoft is releasing this security advisory to provide information about a vulnerability in System.Security.Cryptography.Xml. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A vulnerability exists in…

CVE-2026-32203
NVD

HIGH
CVE-2026-54635
CVE-2026-54635
pkg: python

published: Jul 28, 2026

pytonapi is a Python SDK for TONAPI that provides REST API, streaming, and webhook access to the TON blockchain. From 2.0.0 to 2.2.0, TonapiWebhookDispatcher fails to validate the Authorization header when a webhook handler is registered with the documented path argument, because setup() stores bear…
CWE: CWE-287
NVD

HIGH
CVE-2026-67183
CVE-2026-67183
pkg: express

published: Jul 28, 2026

TinyWeb through 0.0.8 contains a memory leak vulnerability that allows unauthenticated attackers to exhaust available memory by sending ordinary well-formed HTTP requests. Each request causes HttpParser::execute() to allocate Url objects, HttpHeaders objects, and HttpHeader instances via raw new exp…
CWE: CWE-401
NVD

HIGH
CVE-2026-67182
CVE-2026-67182
pkg: python

published: Jul 28, 2026

Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability that allows remote attackers to bypass access controls by injecting bare line feed characters (0x0A) into client-supplied request header values that are copied verbatim to upstream connections without validation. Attackers …
CWE: CWE-444
GitHub-GHSA

HIGH
pytonapi has a Webhook Custom Path Authentication Bypass
GHSA-3fcr-jvgp-7f58
pkg: pytonapi
eco: pip
published: Jul 28, 2026
## Webhook Custom Path Authentication Bypass in pytonapi

### Summary

`TonapiWebhookDispatcher` in pytonapi 2.2.0 fails to validate the `Authorization` header when a webhook handler is registered with the documented `path=` argument. During `setup()`, bearer tokens are stored only under the default…

CVE-2026-54635
GitHub-GHSA

HIGH
SIPSorcery: Malformed UDP packet on the RTP/ICE socket can remotely terminate a media session (DoS)
GHSA-28gm-jrmw-xx93
pkg: SIPSorcery
eco: nuget
published: Jul 28, 2026
### Impact

A single malformed inbound UDP packet on the RTP/ICE socket can remotely terminate an active RTP or WebRTC media session. The packet receive handler indexes packet (and STUN attribute) bytes without sufficient length checks and throws, and the UDP receive loop converted any such exceptio…

CVE-2026-54632
NVD

HIGH
CVE-2026-47427
CVE-2026-47427
pkg: go

published: Jul 28, 2026

GitHub MCP Server is GitHub's official MCP Server. Prior to 1.1.0, the CompletionsHandler function in pkg/github/server.go accesses params.Ref without first checking whether it is nil, so a completion/complete request with a missing or empty ref field triggers a nil pointer dereference and a Go runt…
CWE: CWE-476
GitHub-GHSA

HIGH
GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler
GHSA-w4q6-qw23-4rg7
pkg: github.com/github/github-mcp-server
eco: go
published: Jul 28, 2026
### Summary

A nil pointer dereference vulnerability in the GitHub MCP Server causes it to crash when receiving a malformed `completion/complete` request with missing or empty parameters. This allows any unauthenticated client to cause a complete denial of service.

### Details

The `CompletionsHand…

CVE-2026-47427
NVD

HIGH
CVE-2026-15025
CVE-2026-15025
pkg: go

published: Jul 28, 2026

The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.3.2 via the automator_google_contacts_fetch_labels, automator_mautic_segment_fetch, automator_mautic_tags_fetch, and aut…
CWE: CWE-862
NVD

HIGH
CVE-2026-64545
CVE-2026-64545
pkg: linux

published: Jul 27, 2026

In the Linux kernel, the following vulnerability has been resolved:

net, bpf: check master for NULL in xdp_master_redirect()

xdp_master_redirect() dereferences the result of
netdev_master_upper_dev_get_rcu() without a NULL check, but that helper
returns NULL when the receiving device has no upper-…

NVD

HIGH
CVE-2026-64641
CVE-2026-64641
pkg: vercel next.js

published: Jul 27, 2026

Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processing of further reques…
CWE: CWE-834
NVD

HIGH
CVE-2026-45623
CVE-2026-45623
pkg: node

published: Jul 27, 2026

PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. In versions 8.5.11 and prior, the PreviousMap parses the /*# sourceMappingURL=PATH */ comment from any CSS string passed to process() and dereferences PATH against the…
CWE: CWE-22, CWE-200
NVD

HIGH
CVE-2026-66050
CVE-2026-66050
pkg: windows

published: Jul 27, 2026

NitroShare Desktop through 0.3.4 contains a path traversal vulnerability in its LAN file transfer server that allows unauthenticated attackers on the same network to write arbitrary files by sending a crafted filename containing directory traversal sequences in the JSON item header name field. Attac…
CWE: CWE-22
NVD

HIGH
CVE-2026-55969
CVE-2026-55969
pkg: apache thrift

published: Jul 27, 2026

Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe bindings.

This issue affects Apache Thrift: before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.

CWE: CWE-190
NVD

HIGH
CVE-2026-55968
CVE-2026-55968
pkg: apache thrift

published: Jul 27, 2026

Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Node.js bindings.

This issue affects Apache Thrift: before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.

CWE: CWE-407, CWE-770
NVD

HIGH
CVE-2026-48586
CVE-2026-48586
pkg: apache thrift

published: Jul 27, 2026

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings.

This issue affects Apache Thrift: before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.

CWE: CWE-409
NVD

HIGH
CVE-2026-43871
CVE-2026-43871
pkg: apache thrift

published: Jul 27, 2026

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.

CWE: CWE-835
NVD

HIGH
CVE-2026-41608
CVE-2026-41608
pkg: apache thrift

published: Jul 27, 2026

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings.

This issue affects Apache Thrift: before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.

CWE: CWE-409
NVD

HIGH
CVE-2026-8497
CVE-2026-8497
pkg: tls

published: Jul 29, 2026

Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on Android, iOS, and macOS allows an adjacent-network attacker to intercept and modify sensitive information via a forged TLS certificate.
CWE: CWE-295
NVD

HIGH
CVE-2026-54660
CVE-2026-54660
pkg: axios

published: Jul 29, 2026

swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resolved-swagger-schema.ts getRemoteRequestHeaders forwards –authorizationToken to every URL fetched by fetchRemoteSchemaDocument while warmUpRemoteSchemasCache resolves external $ref …
CWE: CWE-200, CWE-201, CWE-522, CWE-918
GitHub-GHSA

HIGH
swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`
GHSA-h754-fxp7-88wx
pkg: swagger-typescript-api
eco: npm
published: Jul 29, 2026
### Summary

When the developer supplies an `–authorizationToken` (commonly required to fetch a private spec behind authentication), `swagger-typescript-api` attaches that token to the `Authorization` header of **every** subsequent HTTP request it makes while resolving external `$ref` URLs in the s…

CVE-2026-54660
NVD

HIGH
CVE-2026-56822
CVE-2026-56822
pkg: ssl

published: Jul 29, 2026

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator forwards the SslHandshakeCompletionEvent before the asynchronous OCSP validation completes. This allows the client's downstream handlers to send …
CWE: CWE-367
NVD

HIGH
CVE-2026-56821
CVE-2026-56821
pkg: go

published: Jul 29, 2026

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator flags an out-of-date OCSP response but does not stop processing it, so an expired GOOD response is still reported as VALID, letting an on-path at…
CWE: CWE-299
GitHub-GHSA

HIGH
@phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive Property Merging
GHSA-mj3g-7xcc-x4vh
pkg: @phun-ky/defaults-deep
eco: npm
published: Jul 31, 2026
### Impact

A prototype pollution vulnerability exists in @phun-ky/defaults-deep prior to version 2.0.5.

The library recursively merged user-supplied objects without filtering unsafe property names such as `__proto__`, `constructor`, and `prototype`. An attacker able to supply crafted input could c…

CVE-2026-54737
NVD

HIGH
CVE-2026-14893
CVE-2026-14893
pkg: node

published: Jul 28, 2026

IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320 IBM Instana Node.js tracer component @instana/core version 6.2.1 is vulnerable to prototype pollution through its configuration normalization API.
CWE: CWE-1321
NVD

HIGH
CVE-2026-64550
CVE-2026-64550
pkg: linux

published: Jul 27, 2026

In the Linux kernel, the following vulnerability has been resolved:

net: qualcomm: rmnet: validate MAP frame length before ingress parsing

When ingress deaggregation is disabled, rmnet_map_ingress_handler() passes
the skb straight to __rmnet_map_ingress_handler(), skipping the length
validation th…

NVD

HIGH
CVE-2026-67333
CVE-2026-67333
pkg: oauth

published: Aug 1, 2026

better-auth before 1.6.13 (and pre-release builds 1.7.0-beta.0 through 1.7.0-beta.3) fail to validate the scheme of redirect_uris registered via the deprecated oidc-provider plugin and the mcp plugin (which wraps the same provider). An attacker can register an OAuth client with a javascript: redirec…
CWE: CWE-79
GitHub-GHSA

HIGH
Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier
GHSA-rxcw-mc6f-6hr3
pkg: jodit
eco: npm
published: Jul 31, 2026
### Summary
jodit's built-in `clean-html` sanitizer can be bypassed by a MathML/`<style>` carrier that hides a dangerous element from the sanitizer's element walk, so a no-interaction event handler survives into the editor value. When an application supplies attacker-influenced HTML to the editor's …
CVE-2026-58263
NVD

HIGH
CVE-2026-16597
CVE-2026-16597
pkg: go

published: Jul 29, 2026

The GTM4WP – A Google Tag Manager (GTM) plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via WooCommerce Billing Fields in all versions up to, and including, 1.22.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthen…
CWE: CWE-79
NVD

HIGH
CVE-2026-54605
CVE-2026-54605
pkg: oauth

published: Jul 28, 2026

OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. From 0.5.5 to 1.1.5, OAuth::Consumer#token_request parses the raw Location header of a 300 to 399 redirect returned by the OAuth server and follows the redirect recursively, which can mutate the consumer's c…
CWE: CWE-200, CWE-346, CWE-918
GitHub-GHSA

HIGH
OAuth: Cross-origin token-request redirects can expose signed request metadata
GHSA-prq8-7wvh-44qh
pkg: oauth
eco: rubygems
published: Jul 28, 2026
# Cross-origin OAuth token-request redirects can expose signed request metadata

## Summary

When an application uses `OAuth::Consumer` to request OAuth 1.0 request tokens or
access tokens, the token request helper follows `300..399` redirects returned by
the OAuth server. In affected versions, `OAu…

CVE-2026-54605
NVD

HIGH
CVE-2026-55502
CVE-2026-55502
pkg: oauth

published: Jul 31, 2026

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, POST /api/v4/admin/policy/oauth/signin requires only Admin.Read even though GetOauthRedirectService persists caller-supplied OneDrive secret and app_id values, allowing an OAuth token without Admin.Write to modify storag…
CWE: CWE-863
NVD

HIGH
CVE-2026-17811
CVE-2026-17811
pkg: windows

published: Jul 30, 2026

Use after free in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-416
NVD

HIGH
CVE-2026-17744
CVE-2026-17744
pkg: linux

published: Jul 30, 2026

Inappropriate implementation in File Input in Google Chrome on Linux prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-269
GitHub-GHSA

HIGH
@wakaru/cli arbitrary file write during bundle unpack
GHSA-7wpj-vvmv-pgm8
pkg: @wakaru/cli
eco: npm
published: Jul 28, 2026
### Impact

`@wakaru/cli` is vulnerable to arbitrary file write when unpacking a crafted JavaScript bundle with `–unpack`.

Bundle-controlled module filenames were sanitized before writing extracted modules to the output directory. A crafted filename containing overlapping path traversal characters…

CVE-2026-54545
NVD

HIGH
CVE-2026-64546
CVE-2026-64546
pkg: linux

published: Jul 27, 2026

In the Linux kernel, the following vulnerability has been resolved:

drm/edid: fix OOB read in drm_parse_tiled_block()

drm_parse_tiled_block() casts the DisplayID block to a
struct displayid_tiled_block and reads the full fixed layout up to
tile->topology_id[7] without checking block->num_bytes. Th…

NVD

HIGH
CVE-2026-17993
CVE-2026-17993
pkg: google chrome

published: Jul 30, 2026

Race in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Low)
CWE: CWE-362
GitHub-GHSA

HIGH
Thumbor has path traversal via post-validation URL decoding bypass in file_loader
GHSA-cj54-hpcc-gj6h
pkg: thumbor
eco: pip
published: Jul 31, 2026
The file_loader performs `unquote()` on the file path AFTER the `abspath() + startswith()` security check. An attacker can use percent-encoded path traversal sequences (`%2e%2e` for `..`) that pass the security check as literal directory names, but are then decoded to actual `..` traversal sequences…
CVE-2026-53502
GitHub-GHSA

HIGH
hashi-vault-js has a path traversal and query parameter injection
GHSA-g956-2f74-rmv7
pkg: hashi-vault-js
eco: npm
published: Jul 31, 2026
## Summary

The `hashi-vault-js` library is vulnerable to path traversal and query string injection due to the lack of proper encoding of identifiers in path segments and query strings. This allows attackers to manipulate the request URL and potentially access unintended downstream endpoints or inje…

CVE-2026-55100
GitHub-GHSA

HIGH
dssrf: any users using 1.1.1.1 DNS is impacted by SSRF
GHSA-5846-7qm3-r52j
pkg: dssrf
eco: npm
published: Jul 31, 2026
## Summary

is_url_safe can treat localhost as safe when DNS resolver 1.1.1.1 returns NXDOMAIN because dns.resolve4 yields no address and no dns.lookup fallback occurs, allowing server-side request forgery.

## POC

Example to simulate 1.1.1.1 in version before 1.5.0 of dssrf:

“`js
import { is_url…

CVE-2026-54729
GitHub-GHSA

HIGH
dssrf has an SSRF bypass with remove_at_symbol_in_string
GHSA-cg4g-m8jx-vjv2
pkg: dssrf
eco: npm
published: Jul 30, 2026
## Summary

`is_url_safe` in v1.0.3 contains an SSRF bypass. `remove_at_symbol_in_string` is applied to the raw URL string **before** `new URL()` parses it. This strips the `@` that separates userinfo from host, corrupting the hostname so internal IPs are never checked.

## Vulnerability

In `helper…

CVE-2026-54722
GitHub-GHSA

HIGH
MCP Ruby SDK: Ruby SSE Session Poisoning
GHSA-5p9g-j988-pcwv
pkg: mcp
eco: rubygems
published: Jul 30, 2026
### Summary
**Vulnerability**: Missing Session Ownership Validation in the Ruby MCP SDK's Streamable and SSE HTTP transport implementation. Any attacker with a stolen session ID can execute tools with the victim's session. This is a silent attack – the victim's session is compromised and being used …
CVE-2026-67431
GitHub-GHSA

HIGH
netfoil: Incorrect block responses could lead to localhost traffic
GHSA-xvg2-cgv6-6h7v
pkg: github.com/tinfoil-factory/netfoil
eco: go
published: Jul 29, 2026
### Summary
`0.0.0.0` was used instead of NXDOMAIN for block responses. On Linux, which is the target platform for netfoil, the `0.0.0.0` is sent to localhost rather than just dropped.

### Impact
Unintended traffic could be sent to localhost. Impact depends on running services and firewall rules.

GitHub-GHSA

HIGH
ZITADEL Users Can Self-Verify Email/Phone via API
GHSA-jq8w-8q2f-ffm9
pkg: github.com/zitadel/zitadel, github.com/zitadel/zitadel, github.com/zitadel/zitadel
eco: go
published: Jul 29, 2026
### Summary

A vulnerability in Zitadel's self-management capability allowed users to mark their email and phone as verified without going through an actual verification process.

While [`GHSA-282g-fhmx-xf54`](https://github.com/zitadel/zitadel/security/advisories/GHSA-282g-fhmx-xf54) (CVE-2026-2794…

CVE-2026-54693
GitHub-GHSA

HIGH
veraPDF Validation XXE via Rich Text
GHSA-3jh7-wm29-q568
pkg: org.verapdf:validation-model, org.verapdf:validation-model, org.verapdf:validation-model-jakarta
eco: maven
published: Jul 29, 2026
## Summary

**Description**
An XML External Entity Injection (CWE-611) vulnerability in veraPDF allows a remote attacker to read arbitrary files on the server file system and perform Server-Side Request Forgery by submitting a crafted PDF containing a malicious rich-text (/RC or /RV) entry. This…

CVE-2026-54078
GitHub-GHSA

HIGH
veraPDF Validation XXE via XFA
GHSA-36mm-w85j-3q2j
pkg: org.verapdf:validation-model, org.verapdf:validation-model, org.verapdf:validation-model-jakarta
eco: maven
published: Jul 29, 2026
## Summary

**Description**
An XML External Entity Injection (CWE-611) vulnerability in veraPDF allows a remote attacker to read arbitrary files on the server file system and perform Server-Side Request Forgery by submitting a crafted PDF containing a malicious XFA stream. This affects all curre…

CVE-2026-54079
GitHub-GHSA

HIGH
Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions
GHSA-w6p7-2fxx-4f44
pkg: github.com/pocket-id/pocket-id/backend
eco: go
published: Jul 28, 2026
# OIDC Refresh Token Flow Bypasses Authorization Revocation, Account Disabling, and Group Restrictions

## Summary

The `createTokenFromRefreshToken` function (oidc_service.go:451) validates the refresh token's cryptographic integrity but does not re-validate the user's current authorization state b…

CVE-2026-43983
NVD

MEDIUM
CVE-2026-53668
CVE-2026-53668
pkg: react

published: Jul 27, 2026

React Router is a router for React. In versions 6.30.2 through 6.30.4 and 7.9.6 through 7.12.0, applications that allow open redirects are vulnerable to XSS. An attacker could craft a malicious link that redirects users to an unexpected external site or that exploits an XSS vector.This issue has bee…
CWE: CWE-79, CWE-601
NVD

MEDIUM
CVE-2026-53667
CVE-2026-53667
pkg: react

published: Jul 27, 2026

React Router is a router for React. In versions 7.11.0 through 7.17.0, the RSCErrorHandler is missing protocol validation, allowing for redirects from untrusted sources. This issue is a follow up to CVE-2026-53667, and only affects consuming applications if they are using the unstable RSC APIs. This…
CWE: CWE-79
GitHub-GHSA

MEDIUM
Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests
GHSA-68cj-mvg9-rgm2
pkg: github.com/projectcapsule/capsule
eco: go
published: Jul 31, 2026
### Summary

`CapsuleConfiguration.Spec.NodeMetadata.ForbiddenLabels.Regex` and `ForbiddenAnnotations.Regex` are never validated by any admission webhook. A Cluster Admin can persist a malformed regex to etcd without being blocked. Once stored, every Node `CREATE`, `UPDATE`, or `PATCH` request trigg…

CVE-2026-65834
NVD

MEDIUM
CVE-2026-65834
CVE-2026-65834
pkg: kubernetes

published: Jul 30, 2026

Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.8, CapsuleConfiguration.Spec.NodeMetadata.ForbiddenLabels.Regex and CapsuleConfiguration.Spec.NodeMetadata.ForbiddenAnnotations.Regex were not validated by the configuration admission webhook, allowing a Cluster Admi…
CWE: CWE-20, CWE-248
NVD

MEDIUM
CVE-2026-18382
CVE-2026-18382
pkg: oauth

published: Jul 30, 2026

A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary OAuth token endpoint. When authentication.type is set to service-account, the operator sends the tenant's Red Hat SSO client_id and client_s…
CWE: CWE-918
NVD

MEDIUM
CVE-2026-54249
CVE-2026-54249
pkg: python

published: Jul 29, 2026

Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.65.0 through 1.105.0, and 2.0.0b1 through 2.0.0b5, a client that submits message history to a Pydantic AI UI adapter (such as the Vercel AI adapter) can reference arbitrary files in the application's model…
CWE: CWE-918
NVD

MEDIUM
CVE-2026-46678
CVE-2026-46678
pkg: python

published: Jul 29, 2026

Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.56.0 through 1.98.0, when an application opts a URL into force_download='allow-local' (disabling the default block on private/internal IPs), the cloud-metadata blocklist could be bypassed by encoding the m…
CWE: CWE-918
GitHub-GHSA

MEDIUM
NocoBase: Sensitive Data Exposure via SQL Blacklist Bypass
GHSA-v8vm-cqh8-q87q
pkg: @nocobase/plugin-collection-sql, @nocobase/plugin-collection-sql, @nocobase/plugin-collection-sql
eco: npm
published: Jul 28, 2026
# Security Vulnerability Report: Sensitive Data Exposure via SQL Blacklist Bypass

## Summary

The `checkSQL()` function in `plugin-collection-sql` implements a **keyword-based blacklist** to prevent dangerous SQL queries from being executed through the SQL Collection feature. However, the blacklist…

CVE-2026-52888
GitHub-GHSA

MEDIUM
@novu/application-generic: `validateUrlSsrf` permits CGNAT (100.64.0.0/10) destinations — affects Workflow HTTP request step + Webhook filter condition
GHSA-vg6v-j97m-h5xq
pkg: @novu/application-generic
eco: npm
published: Jul 28, 2026
Hi Novu team,

Reporting an SSRF blocklist gap in the shared `validateUrlSsrf` guard. A complete self-contained reproduction is inlined below — copy the four files into a directory and run `docker compose up`, plus a single-file probe that runs against Node directly. Locally validated against HEAD…

GitHub-GHSA

MEDIUM
Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation)
GHSA-jr6p-8pjj-mfx6
pkg: github.com/projectcapsule/capsule
eco: go
published: Jul 31, 2026
### Summary
CVE-2026-22872 (GHSA-qjjm-7j9w-pw72) reported that a Tenant Owner could create cluster-scoped resources
(e.g. `ClusterRole`, `ValidatingWebhookConfiguration`) through a `TenantResource`, because the controller
applies them with its cluster-admin ServiceAccount and `SetNamespace` is ineff…
CVE-2026-65835
NVD

MEDIUM
CVE-2026-65835
CVE-2026-65835
pkg: kubernetes

published: Jul 30, 2026

Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.8, after the incomplete CVE-2026-22872 fix, TenantResource RawItems and Generators in internal/controllers/resources/collect.go, including handleRawItem and handleGeneratorItem, did not apply the ResourceRef…
CWE: CWE-269, CWE-863
GitHub-GHSA

MEDIUM
OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check
GHSA-xc5w-4v5w-7×65
pkg: github.com/OliveTin/OliveTin
eco: go
published: Jul 30, 2026
### Summary
OliveTin's checkShellArgumentSafety() function maintains a blocklist of argument types unsafe for Shell mode actions, but does not include regex:-prefixed types. Because regex: support was added independently via typeSafetyCheckRegex(), any Shell mode action using a regex:-typed argument…
CVE-2026-67438
GitHub-GHSA

MEDIUM
nono-cli'scregistry pack verification can fail open when provenance metadata is absent
GHSA-hc4m-q9jh-xw4j
pkg: nono-cli
eco: rust
published: Jul 28, 2026
## Summary

Registry-installed nono packs are expected to be verified from local provenance metadata before they are used. Two files are relevant:

– `~/.config/nono/packages/lockfile.json`
– `~/.config/nono/packages/<namespace>/<pack>/.nono-trust.bundle`

Testing shows that nono fails closed when a…

GitHub-GHSA

MEDIUM
ImageMagick: Heap Buffer Over-Read in XCF decoder due to integer conversion overflow
GHSA-pjxj-pchx-4c3m
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Jul 31, 2026
An integer overflow in the XCF decoder can result in an out of bounds read when a crafted image is read and that can result in a crash.
CVE-2026-53466
NVD

MEDIUM
CVE-2026-17348
CVE-2026-17348
pkg: node

published: Jul 31, 2026

In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; the application's before_request hook only handles desktop-mode auto-login and the Kerberos/Webserver-auth redirect, so any route shipped without the decorator is reachable without authentication (CWE-…
CWE: CWE-306
NVD

MEDIUM
CVE-2026-18208
CVE-2026-18208
pkg: jwt

published: Jul 31, 2026

A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source identity and access management solution used to secure modern applications and services. The issue occurs when a confidential client, configured to receive signed JWT introspectio…
CWE: CWE-862
NVD

MEDIUM
CVE-2026-64816
CVE-2026-64816
pkg: windows

published: Jul 30, 2026

RapidRAW before 1.6.0 does not validate the lutPath field in preset files before passing it to File::open() in lut_processing.rs. On Windows, a UNC path in lutPath causes an outbound SMB connection to an attacker-controlled host, leaking the victim's NTLMv2 credentials. The vulnerable code path is r…
CWE: CWE-73
NVD

MEDIUM
CVE-2026-17992
CVE-2026-17992
pkg: windows

published: Jul 30, 2026

Uninitialized Use in Skia in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
CWE: CWE-457
NVD

MEDIUM
CVE-2026-17846
CVE-2026-17846
pkg: windows

published: Jul 30, 2026

Inappropriate implementation in Media in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-346
NVD

MEDIUM
CVE-2026-17707
CVE-2026-17707
pkg: windows

published: Jul 30, 2026

Uninitialized Use in Media in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-457
NVD

MEDIUM
CVE-2026-65975
CVE-2026-65975
pkg: python

published: Jul 29, 2026

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.88.0 up to but not including 1.107.1 and 2.0.0b1 up to but not including 2.5.0, the UI adapters (AG-UI via Agent.to_ag_ui()/AGUIAdapter, and Vercel AI via VercelAIAdapter) use sanitize_m…
CWE: CWE-863
GitHub-GHSA

MEDIUM
OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords
GHSA-rwqx-fvqh-6wm4
pkg: io.opentelemetry.javaagent:opentelemetry-javaagent
eco: maven
published: Jul 29, 2026
OpenTelemetry Java Instrumentation JDBC auto-instrumentation may fail to sanitize passwords in SQL CONNECT statements when the password is double-quoted. As a result, clear-text database passwords can be added to trace span attributes and exported to observability backends.
CVE-2026-54704
GitHub-GHSA

MEDIUM
veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When Processing Untrusted PDFs
GHSA-cg9x-g3gm-h5h6
pkg: org.verapdf:validation-model, org.verapdf:validation-model, org.verapdf:validation-model-jakarta
eco: maven
published: Jul 29, 2026
### Summary

veraPDF-validation has an XML External Entity (XXE) vulnerability in two PDF parsing paths (validate and `GFPDAcroForm.getdynamicRender()`). A malicious/crafted PDF supplied to a veraPDF consumer can lead to the expansion of external entities while parsing rich-text annotation/form-fiel…

CVE-2026-54082
NVD

MEDIUM
CVE-2026-66063
CVE-2026-66063
pkg: go

published: Jul 28, 2026

goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/updown.go multipart upload handler split part.FileName() on / but did not reject .., allowing an unauthenticated upload with filename .. to create a file outside the served tree. This iss…
CWE: CWE-22
GitHub-GHSA

MEDIUM
skilo add follows symbolic links, allowing arbitrary local file disclosure from a malicious skill source
GHSA-6xx4-9wp6-65p7
pkg: skilo
eco: rust
published: Jul 28, 2026
### Impact

`skilo add` installs a skill by recursively copying the skill directory into the
target skills directory. The copy routine (`copy_dir_all`) classified each entry
with `std::fs::DirEntry::file_type()` — which does **not** follow symlinks — and
then copied non-directory entries with `s…

GitHub-GHSA

MEDIUM
goshs has a Path Traversal issue
GHSA-wg2q-39h6-66×9
pkg: goshs.de/goshs/v2, github.com/patrickhener/goshs/v2, goshs.de/goshs
eco: go
published: Jul 28, 2026
## Summary

The multipart upload filename fix splits on the path separator but never rejects dot-dot, allowing a write outside the served tree.

## Finding (Medium): upload filename escapes the served tree (residual of CVE-2026-35393)

The multipart filename fix (updown.go lines 135-136) splits on t…

CVE-2026-66063
NVD

MEDIUM
CVE-2026-66749
CVE-2026-66749
pkg: node

published: Jul 28, 2026

Let's Chat 0.4.0 through 0.4.8 contains a null dereference vulnerability that allows authenticated attackers to crash the server by supplying a valid 24-character hex string room parameter that matches no document in the database. Attackers can send a crafted GET /messages request causing an uncaugh…
CWE: CWE-476
NVD

MEDIUM
CVE-2026-62436
CVE-2026-62436
pkg: go

published: Jul 28, 2026

[This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE.]

With the introduction of Grant Table v2 came the requirement to be able to
switch between versions. Switching from v1 to v2 reduces the number of
valid grant references,…

CWE: CWE-362
NVD

MEDIUM
CVE-2026-62435
CVE-2026-62435
pkg: go

published: Jul 28, 2026

[This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE.]

With the introduction of Grant Table v2 came the requirement to be able to
switch between versions. Switching from v1 to v2 reduces the number of
valid grant references,…

CWE: CWE-362
NVD

MEDIUM
CVE-2026-64649
CVE-2026-64649
pkg: vercel next.js

published: Jul 27, 2026

Next.js is a React framework for building full-stack web applications. In versions 14.1.1 through 15.5.20 and 16.0.0 through 16.2.10, when a Server Action forwards or redirects a request, an attacker can cause the server to send that outbound request to a malicious host (Server-Side Request Forgery)…
CWE: CWE-918
GitHub-GHSA

MEDIUM
org.xwiki.contrib:discussions-server has Cross-Site Request Forgery (CSRF) issue that makes it possible to delete messages
GHSA-4j38-rw27-97gx
pkg: org.xwiki.contrib:discussions-server
eco: maven
published: Jul 27, 2026
### Impact
It's possible to forge a request to delete a message.

### Patches
The problem has been patched in version 2.0-rc-1 of Discussion Extension.

### Workarounds
There's no easy workaround except upgrading.

### References
https://jira.xwiki.org/browse/DISCUSSION-22

### For more information…

CVE-2023-37465
NVD

MEDIUM
CVE-2026-67332
CVE-2026-67332
pkg: oauth

published: Aug 1, 2026

@better-auth/oauth-provider before 1.7.0-beta.4 fails to bind access-token audience to the authorization grant, allowing clients to request tokens for unrelated resources. Attackers can complete an OAuth flow and obtain access tokens whose audience targets resource servers the authorization never co…
CWE: CWE-285
NVD

MEDIUM
CVE-2026-58040
CVE-2026-58040
pkg: tls

published: Jul 30, 2026

An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934).

This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.

CWE: CWE-297
GitHub-GHSA

MEDIUM
mathlive's Lack of Escaping of HTML allows for XSS
GHSA-fm7p-gw32-828p
pkg: mathlive
eco: npm
published: Jul 29, 2026
### Summary

Despite the 0.104.0 patch escaping attribute-bearing constructs (`\htmlData`, `\href`), text-content reflection was missed. The `\text{}`, `\mbox{}` commands accept arbitrary characters in their body and emit them raw and unescaped into both the HTML markup and the MathML output, leadin…

CVE-2026-54705
GitHub-GHSA

MEDIUM
gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with_files inline mode
GHSA-c5px-58j2-7fqp
pkg: gemini-bridge
eco: pip
published: Jul 31, 2026
### Summary
`consult_gemini_with_files` in **inline mode** read any file path supplied in
the `files` argument without confining it to the working `directory`, then
forwarded the contents to the Gemini CLI. Because the caller also controls
`query`, the file contents are echoed back through the Gemin…
CVE-2026-54785
GitHub-GHSA

MEDIUM
re2: Global `String.prototype.match` with an empty-matchable pattern never advances → infinite loop with unbounded native memory growth (DoS)
GHSA-6hxr-mr5r-9836
pkg: re2
eco: npm
published: Jul 31, 2026
## Summary

`String.prototype.match` with a **global** `RE2` collects all matches in a native loop that advances the cursor by the match length. A **zero-width (empty) match** has length 0, so the cursor never advances: the same empty match is found forever and appended to an ever-growing native vec…

CVE-2026-68499
NVD

MEDIUM
CVE-2026-68562
CVE-2026-68562
pkg: node

published: Jul 30, 2026

A flaw was found in ansible-collection-redhat-leapp. An attacker with privileged write access to a managed node's Leapp report content can manipulate it. When an operator runs a specific remediation task, this manipulated report can cause the Ansible controller to read its own local files and copy t…
CWE: CWE-610
NVD

MEDIUM
CVE-2026-68499
CVE-2026-68499
pkg: express

published: Jul 30, 2026

re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2's String.prototype.match implementation with a global RE2 pattern that can match the empty string fails to advance its native matching cursor in lib/match.cc, causing an infinite loop and unbounded native …
CWE: CWE-835
GitHub-GHSA

MEDIUM
MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)
GHSA-7683-3w9x-ch42
pkg: mcp
eco: rubygems
published: Jul 30, 2026
## Summary

The stdio transports in `MCP::Server::Transports::StdioTransport` and `MCP::Client::Stdio` read newline-delimited JSON-RPC frames using `IO#gets` with no `limit` argument. CRuby's `IO#gets` with no limit reads from the current position until the next separator (`\n`) with no upper bound …

CVE-2026-63119
NVD

MEDIUM
CVE-2026-54663
CVE-2026-54663
pkg: axios

published: Jul 29, 2026

swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resolved-swagger-schema.ts warmUpRemoteSchemasCache resolves external $ref URLs and fetchRemoteSchemaDocument uses isHttpUrl to fetch any http or https target without private IP, redire…
CWE: CWE-20, CWE-441, CWE-918
GitHub-GHSA

MEDIUM
swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`
GHSA-x36r-4347-pm5x
pkg: swagger-typescript-api
eco: npm
published: Jul 29, 2026
### Summary

`swagger-typescript-api` walks every `$ref` value in the input OpenAPI spec and, for any `$ref` whose target is an `http(s)://` URL, issues an HTTP GET to that URL during generation (`warmUpRemoteSchemasCache`). The only URL filter is a regex that matches `^https?://` — there is **no …

CVE-2026-54663
GitHub-GHSA

MEDIUM
Cosmos-Server has an authentication bypass via forward-auth header smuggling on Constellation tunnel
GHSA-2rx5-2g7j-2659
pkg: github.com/azukaar/cosmos-server
eco: go
published: Jul 28, 2026
### Summary

The Constellation-tunnel bypass branch in `tokenMiddleware` at `src/proxy/routerGen.go:53-66` returns to the upstream handler before the request's `x-cosmos-user`, `x-cosmos-role`, `x-cosmos-user-role`, and `x-cosmos-mfa` headers are stripped at lines 68-72, and before the `AdminOnlyWit…

CVE-2026-49446
NVD

MEDIUM
CVE-2026-65882
CVE-2026-65882
pkg: go

published: Jul 28, 2026

Joomla Extension – joomdle.com – Reflected XSS vulnerability in Joomdle < 3.1.1 – The goto url parameter of the moodle wrapper endpoint allowed a reflected XSS vector.
CWE: CWE-79
NVD

MEDIUM
CVE-2026-42494
CVE-2026-42494
pkg: go

published: Jul 28, 2026

[This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE.]

The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver
derives several lengths directly from attacker-controlled on-disk fields
without validating them:

CWE: CWE-125
NVD

MEDIUM
CVE-2026-53666
CVE-2026-53666
pkg: react

published: Jul 27, 2026

React Router is a router for React. In versions 6.4.0 through 7.17.0, if application code was written in a way that allows attacker-supplied input to overwrite certain aspects of errors caught by the SSR process, then it was possible for an attacker to trigger unexpected constructor execution on the…
CWE: CWE-470
NVD

MEDIUM
CVE-2026-64645
CVE-2026-64645
pkg: vercel next.js

published: Jul 27, 2026

Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a
rewrites() or redirects() rule that builds its external destination hostname from request-controlled input can be pointed at an arbitrary hostname, regardless of t…
CWE: CWE-601, CWE-918
NVD

MEDIUM
CVE-2026-67294
CVE-2026-67294
pkg: tls

published: Aug 1, 2026

FreeRDP before 3.29.0 improperly validates the Extended Key Usage (EKU) purpose of the peer certificate during client-side server TLS authentication. In x509_utils_verify(), when server-purpose (X509_PURPOSE_SSL_SERVER) verification fails, the code falls back to client-purpose and any-purpose verifi…
CWE: CWE-295
GitHub-GHSA

MEDIUM
`nx graph` dev server permissive CORS policy
GHSA-g2r8-wvmj-jf5w
pkg: nx, nx
eco: npm
published: Jul 31, 2026
## Summary

The local HTTP server started by `nx graph` sent `Access-Control-Allow-Origin: *` on every response, letting any website a developer visited read the server's responses cross-origin — including the full project graph and the output of the `/help` endpoint, which runs a target's configu…

CVE-2026-54753
GitHub-GHSA

MEDIUM
Penelope unsafe tar extraction allows arbitrary local file write via crafted session archive
GHSA-f42x-p2mx-hm8r
pkg: penelope-shell-handler
eco: pip
published: Jul 29, 2026
### Summary

Penelope versions prior to 0.19.3 extracted tar archives received from remote sessions without validating archive member paths. When using the affected Unix download path, a malicious or compromised remote session could return a crafted tar archive containing path traversal entries, suc…

CVE-2026-50558
NVD

MEDIUM
CVE-2026-16107
CVE-2026-16107
pkg: tls

published: Jul 28, 2026

IBM TS4500 CLI tool Versions:  0.1.31 through 1.12.0.0 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques.
CWE: CWE-295
NVD

MEDIUM
CVE-2026-66053
CVE-2026-66053
pkg: apache thrift

published: Jul 27, 2026

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings.

This issue affects Apache Thrift: before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.

This replaces CVE-2026-41603

CWE: CWE-297
NVD

MEDIUM
CVE-2026-17908
CVE-2026-17908
pkg: windows

published: Jul 30, 2026

Insufficient validation of untrusted input in Printing in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
CWE: CWE-20
GitHub-GHSA

MEDIUM
re2: Out-of-bounds heap read in `exec`/`test`/`match` via attacker-influenced `lastIndex` on a non-ASCII subject → uncatchable process crash (DoS)
GHSA-ff84-5f28-78qj
pkg: re2
eco: npm
published: Jul 31, 2026
## Summary

`re2` validates the user-settable `lastIndex` against the subject's **UTF-8 byte length** but then uses it as a **UTF-16 code-unit count** to walk the subject buffer, with no bounds check. For any non-ASCII subject, the byte length is larger than the true character count, so a `lastIndex…

CVE-2026-67550
NVD

MEDIUM
CVE-2026-67550
CVE-2026-67550
pkg: express

published: Jul 30, 2026

re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2 validates lastIndex against the UTF-8 byte length of a subject but uses it as a UTF-16 code-unit offset in exec, test, match, replace, and split, allowing an attacker-influenced lastIndex on a non-ASCII su…
CWE: CWE-125
NVD

MEDIUM
CVE-2026-45376
CVE-2026-45376
pkg: express

published: Jul 31, 2026

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the GET /admin/organization/users search interpolates params[:term] into raw Arel.sql ORDER BY similarity expressions before sanitization, allowing an authenticated organi…
CWE: CWE-89
GitHub-GHSA

MEDIUM
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM
GHSA-q6hh-gp44-4hcm
pkg: github.com/pterodactyl/wings
eco: go
published: Jul 31, 2026
### Summary
Config file parsers, `json`, `yaml`, `xml` etc in parser.go have no file size limit/checks, allowing for a giant config file to potentially OOM the wings process.

### Impact
All wings users who have an egg with a non-`file` parser configuration file setting.

CVE-2026-52857
NVD

MEDIUM
CVE-2026-68563
CVE-2026-68563
pkg: node

published: Jul 30, 2026

A flaw was found in ansible-collection-redhat-leapp. When a remediation task is executed with elevated privileges and the `leapp_old_postgresql_data` option is selected, a PostgreSQL data backup archive is created with insecure permissions. This allows a local non-root user on the managed node to re…
CWE: CWE-732
NVD

MEDIUM
CVE-2026-17932
CVE-2026-17932
pkg: windows

published: Jul 30, 2026

Use after free in DataTransfer in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
CWE: CWE-416
NVD

MEDIUM
CVE-2026-62425
CVE-2026-62425
pkg: go

published: Jul 28, 2026

[This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE.]

The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver
derives several lengths directly from attacker-controlled on-disk fields
without validating them:

CWE: CWE-20
NVD

MEDIUM
CVE-2026-62424
CVE-2026-62424
pkg: go

published: Jul 28, 2026

[This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE.]

The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver
derives several lengths directly from attacker-controlled on-disk fields
without validating them:

CWE: CWE-130
NVD

MEDIUM
CVE-2026-62423
CVE-2026-62423
pkg: go

published: Jul 28, 2026

[This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE.]

The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver
derives several lengths directly from attacker-controlled on-disk fields
without validating them:

CWE: CWE-130
NVD

MEDIUM
CVE-2026-42495
CVE-2026-42495
pkg: go

published: Jul 28, 2026

[This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE.]

The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver
derives several lengths directly from attacker-controlled on-disk fields
without validating them:

CWE: CWE-191
GitHub-GHSA

MEDIUM
sanitize-html has incomplete URI scheme validation in that allows javascript: URIs through action, formaction, data, poster, and background attributes
GHSA-vccv-cmxp-4j9h
pkg: sanitize-html
eco: npm
published: Jul 31, 2026
## Summary

sanitize-html uses `allowedSchemesAppliedToAttributes` (default: `['href', 'src', 'cite']`) to gate the `naughtyHref()` function that blocks dangerous URI schemes like `javascript:` and `vbscript:`. The HTML specification defines 10+ attributes that accept URIs (`action`, `formaction`, `…

CVE-2026-53606
GitHub-GHSA

MEDIUM
Jodit has incomplete javascript: scheme normalization in sanitizeHTMLElement href check that allows link XSS
GHSA-j839-gqq4-gf9j
pkg: jodit
eco: npm
published: Jul 31, 2026
### Summary

jodit's `sanitizeHTMLElement` neutralizes a `javascript:` `href` using a bare `href.trim().indexOf('javascript') === 0` check. This omits the normalization jodit applies to every other URL attribute: `isDangerousUrl` strips control bytes with `value.replace(/[\u0000-\u0020]+/g, '')` and…

CVE-2026-62324
GitHub-GHSA

MEDIUM
OnionShare Receive mode writes uploaded files even when file uploads are disabled
GHSA-v833-3823-cmhp
pkg: onionshare-cli
eco: pip
published: Jul 31, 2026
### Summary
OnionShare CLI/Desktop 2.6.3 does not enforce the Receive mode `disable_files` setting at the file upload sink. When a Receive service is configured as a text-message-only endpoint (`–disable-files` / "Disable uploading files"), a remote sender who can reach the OnionShare service can s…
CVE-2026-54707
NVD

MEDIUM
CVE-2026-18266
CVE-2026-18266
pkg: oauth

published: Jul 29, 2026

Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Dify. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicio…
CWE: CWE-601
NVD

MEDIUM
CVE-2026-64648
CVE-2026-64648
pkg: vercel next.js

published: Jul 27, 2026

Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a server-side fetch with a request body may return a cached response body from a different request to the same URL but different body. Confidential data in the POST'…
CWE: CWE-524
NVD

MEDIUM
CVE-2026-64647
CVE-2026-64647
pkg: vercel next.js

published: Jul 27, 2026

Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a server-side fetch with a request body may return a cached response body from a different request to the same URL but different body. Confidential data in the POST's…
CWE: CWE-116
NVD

MEDIUM
CVE-2026-67339
CVE-2026-67339
pkg: curl

published: Aug 1, 2026

guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL handlers. Attackers can capture proxy credentials through origin server access logs when requests are redirected, bypassed, or sent through SOCKS proxies that Guzzle misclassifie…
CWE: CWE-200
NVD

MEDIUM
CVE-2026-67335
CVE-2026-67335
pkg: oauth

published: Aug 1, 2026

better-auth versions before 1.6.2 fail to validate the OAuth state parameter against the stored nonce when using cookie-backed state storage without PKCE. Attackers can forge the state parameter and supply an attacker-controlled authorization code to create authenticated sessions bound to the attack…
CWE: CWE-287
GitHub-GHSA

MEDIUM
Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute
GHSA-34rh-wp3j-6cxc
pkg: github.com/pion/stun/v3, github.com/pion/stun/v2, github.com/pion/stun
eco: go
published: Jul 31, 2026
### Impact
Remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute

### Patches
Upgrade to v3.1.5 or later. This version includes this patch https://github.com/pion/stun/pull/278 which fixes the issue.

### Workarounds
No work around; please upgrade to v3.1.5 or a n…

CVE-2026-54909
GitHub-GHSA

MEDIUM
MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood
GHSA-52jp-gj8w-j6xh
pkg: mcp
eco: rubygems
published: Jul 30, 2026
## Summary

In its default configuration, `MCP::Server::Transports::StreamableHTTPTransport` never expires sessions. Every successful `initialize` request stores a new `ServerSession` and a session record under a fresh UUID, and the only path that removes them is an explicit client-issued HTTP `DELE…

CVE-2026-67430
GitHub-GHSA

MEDIUM
OpenTelemetry Javaagent RMI context propagation allows resource exhaustion
GHSA-fq3f-m5qm-99f5
pkg: io.opentelemetry.javaagent:opentelemetry-javaagent
eco: maven
published: Jul 29, 2026
The RMI context propagation payload reader limits the number of context entries but does not limit the aggregate size of the strings read from the stream.

An attacker who can reach an RMI endpoint on an instrumented JVM can send an oversized context propagation payload. This can cause excessive mem…

CVE-2026-54712
NVD

MEDIUM
CVE-2026-66064
CVE-2026-66064
pkg: go

published: Jul 28, 2026

goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/handler.go sendFile handler opened files using a cleaned path but derived the authorization filename from raw req.URL.Path, so a trailing slash could bypass .goshs ACL-file protection and…
CWE: CWE-41, CWE-863
GitHub-GHSA

MEDIUM
goshs has ACL Bypass & Path Traversal
GHSA-964w-f6gj-5236
pkg: github.com/patrickhener/goshs/v2, goshs.de/goshs/v2, github.com/patrickhener/goshs
eco: go
published: Jul 28, 2026
## Summary

`sendFile` derives the served filename from the raw request path while opening the file from the cleaned path, so appending a trailing slash empties the derived name and defeats both the never-serve rule for the ACL file and the block list.

## Finding (Medium): trailing-slash ACL and h…

CVE-2026-66064
GitHub-GHSA

MEDIUM
Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens
GHSA-5fqm-cc34-fcf5
pkg: github.com/azukaar/cosmos-server
eco: go
published: Jul 28, 2026
### Summary
`GET /cosmos/api/constellation/public-devices` discloses Constellation device metadata to a requester that supplies any non-empty `Authorization` header. The handler strips the string `Bearer ` from the header but never validates the resulting token and never uses it in the database quer…
CVE-2026-49447
NVD

MEDIUM
CVE-2026-64646
CVE-2026-64646
pkg: vercel next.js

published: Jul 27, 2026

Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive memory consumption if that Server Actions uses the Edge…
CWE: CWE-770
NVD

MEDIUM
CVE-2026-64644
CVE-2026-64644
pkg: vercel next.js

published: Jul 27, 2026

Next.js is a React framework for building full-stack web applications. In versions 15.5.0 through 15.5.20 and 16.0.0 through 16.2.10, when self-hosting Next.js with the default image loader, the Image Optimization API can optimize remotely hosted images if configured (not enabled by default). If tho…
CWE: CWE-407
NVD

MEDIUM
CVE-2026-64643
CVE-2026-64643
pkg: vercel next.js

published: Jul 27, 2026

Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, Next.js applications using App Router, Server Actions (use server) or use cache endpoints can be disclosed bypassing any authentication on the pages where these endpo…
CWE: CWE-201
NVD

MEDIUM
CVE-2026-17514
CVE-2026-17514
pkg: node

published: Jul 27, 2026

A vulnerability was determined in ZJONSSON node-unzipper up to 0.12.3. Affected by this vulnerability is the function Extract of the file lib/extract.js. This manipulation causes path traversal. The attack requires local access. The exploit has been publicly disclosed and may be utilized. The projec…
CWE: CWE-22
GitHub-GHSA

MEDIUM
OnionShare follows symlinks in shared directories, allowing unintended disclosure of local files
GHSA-22p9-r2f5-22mf
pkg: onionshare-cli
eco: pip
published: Jul 31, 2026
### Summary
OnionShare CLI/Desktop 2.6.3 can follow symbolic links inside a selected Share or Website directory and serve the symlink target rather than limiting access to files physically contained in the selected directory. If a user shares a directory that contains attacker-supplied or otherwise …
CVE-2026-54706
NVD

MEDIUM
CVE-2026-62845
CVE-2026-62845
pkg: kubernetes

published: Jul 30, 2026

Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, the PostgreSQL and MySQL datastore drivers build DDL statements by interpolating the user-supplied DataStoreUsername/DataStoreSchema directly into SQL via fmt.Sprintf, without escaping identifiers. These fields have no …
CWE: CWE-89
GitHub-GHSA

MEDIUM
@dynatrace-oss/dynatrace-mcp-server has a DQL injection via parameters not documented as DQL
GHSA-pqh8-p93p-2rx7
pkg: @dynatrace-oss/dynatrace-mcp-server
eco: npm
published: Jul 31, 2026
### Summary
A DQL injection vulnerability in several read tools lets a caller bypass the tools' documented field-scope, time-window, and display caps by injecting DQL pipeline stages through parameters typed as identifiers.

### Details
Several tools interpolate caller-supplied parameters directly i…

GitHub-GHSA

MEDIUM
OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output
GHSA-jm28-2wcr-qf3h
pkg: github.com/OliveTin/OliveTin
eco: go
published: Jul 30, 2026
## Summary

The synchronous execution RPCs `StartActionAndWait` and `StartActionByGetAndWait` return the full `LogEntry` for the just-executed action without checking whether the caller is allowed to read that action's logs.

OliveTin's ACL model separates `exec` from `logs`. A deployment can intent…

CVE-2026-67439
NVD

MEDIUM
CVE-2026-17900
CVE-2026-17900
pkg: windows

published: Jul 30, 2026

Inappropriate implementation in Enterprise in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a malicious file. (Chromium security severity: Low)
CWE: CWE-346
NVD

MEDIUM
CVE-2026-17858
CVE-2026-17858
pkg: windows

published: Jul 30, 2026

Uninitialized Use in WebNN in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-457
NVD

MEDIUM
CVE-2026-17790
CVE-2026-17790
pkg: windows

published: Jul 30, 2026

Uninitialized Use in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-457
NVD

MEDIUM
CVE-2026-17706
CVE-2026-17706
pkg: windows

published: Jul 30, 2026

Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-20
NVD

MEDIUM
CVE-2026-17662
CVE-2026-17662
pkg: go

published: Jul 30, 2026

Insufficient policy enforcement in Prefetch in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-346
NVD

MEDIUM
CVE-2026-15831
CVE-2026-15831
pkg: go

published: Jul 29, 2026

GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.3 and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to bypass administrator-configured tool governance policies due to improper authorization enforcement during token …
CWE: CWE-1270
NVD

MEDIUM
CVE-2026-17166
CVE-2026-17166
pkg: go

published: Jul 29, 2026

The Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.3.7. This is due to the plugin not properly verifying that a user is authorized to perform an actio…
CWE: CWE-862
GitHub-GHSA

MEDIUM
Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks
GHSA-vchh-r53j-8mpw
pkg: github.com/fission/fission
eco: go
published: Jul 28, 2026
`HTTPTriggerSpec.Validate()` validated `Methods`, `FunctionReference`, `Host`, `IngressConfig`, and `CorsConfig`, but silently skipped `RelativeURL` and `Prefix`. Those two fields were validated at the CLI level only
(`pkg/fission-cli/cmd/httptrigger/create.go:83`). The post-CRD-modernization webhoo…
CVE-2026-50569
NVD

MEDIUM
CVE-2026-18038
CVE-2026-18038
pkg: go

published: Jul 28, 2026

A flaw has been found in nextlevelbuilder GoClaw up to 3.13.2. Affected by this vulnerability is the function ExecTool.Execute of the file goclaw/internal/http/tools_invoke.go of the component jq Handler. Executing a manipulation can lead to information disclosure. The attack can be launched remotel…
CWE: CWE-200, CWE-284
NVD

MEDIUM
CVE-2026-16587
CVE-2026-16587
pkg: oauth

published: Jul 28, 2026

The Advanced Form Integration — Connect Forms to 200+ Apps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticat…
CWE: CWE-862
NVD

MEDIUM
CVE-2026-59728
CVE-2026-59728
pkg: node

published: Jul 27, 2026

Astro is a web framework for content-driven websites. In versions 1.0.0 through 4.0.18, the source.title and enclosure.type item fields in packages/astro-rss/src/index.ts are interpolated directly into XML template strings without XML-character escaping before being parsed by fast-xml-parser. Both f…
CWE: CWE-91
NVD

MEDIUM
CVE-2026-66428
CVE-2026-66428
pkg: go

published: Jul 27, 2026

Unauthenticated Cross Site Request Forgery (CSRF) in WP Google Review Slider <= 18.4 versions.
CWE: CWE-352
NVD

MEDIUM
CVE-2026-67293
CVE-2026-67293
pkg: tls

published: Aug 1, 2026

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains an improper certificate hostname validation vulnerability. The TLS hostname matcher (tls_match_hostname() in libfreerdp/crypto/tls.c) treats a wildcard pattern such as *.example.com as matching any hostname ending in .example.com, so it in…
CWE: CWE-295
GitHub-GHSA

MEDIUM
@dynatrace-oss/dynatrace-mcp-server has a workflow template injection via create_workflow_for_notification
GHSA-xrmj-5g4g-8987
pkg: @dynatrace-oss/dynatrace-mcp-server
eco: npm
published: Jul 31, 2026
### Summary
A template injection vulnerability in the `create_workflow_for_notification` tool lets a caller embed Jinja2 expressions that the Dynatrace workflow engine evaluates at runtime, exfiltrating event data to attacker-controlled destinations through a workflow that persists in the tenant aft…
NVD

MEDIUM
CVE-2026-17659
CVE-2026-17659
pkg: go

published: Jul 30, 2026

Inappropriate implementation in SiteIsolation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-693
NVD

MEDIUM
CVE-2026-56850
CVE-2026-56850
pkg: tls

published: Jul 30, 2026

A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates.

This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.

CWE: CWE-287
NVD

MEDIUM
CVE-2026-18018
CVE-2026-18018
pkg: windows

published: Jul 30, 2026

Inappropriate implementation in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform UI spoofing via a malicious file. (Chromium security severity: Low)
CWE: CWE-451
GitHub-GHSA

MEDIUM
guard-livereload has a directory traversal vulnerability
GHSA-g65v-27r3-5p6m
pkg: guard-livereload
eco: rubygems
published: Jul 31, 2026
The vulnerability allows remote attackers to read arbitrary files
on the server by exploiting improper path validation in the
livereload server functionality.

This vulnerability is related to the handling of file paths in the
livereload server component, which could allow an attacker to traverse
di…

CVE-2016-1000305
GitHub-GHSA

MEDIUM
core-geonetwork has an Open Redirect Bypass
GHSA-pjp7-q6wp-97qx
pkg: org.geonetwork-opensource:geonetwork, org.geonetwork-opensource:geonetwork, org.geonetwork-opensource:geonetwork
eco: maven
published: Jul 31, 2026
### Summary
GeoNetwork's post-login redirect handling can be bypassed to redirect users to an attacker-controlled external site, even though the code attempts to restrict redirect targets to relative, in-application URLs. This affects both supported SSO login methods: OAuth2/OIDC and Keycloak.

### …

CVE-2026-53573
GitHub-GHSA

MEDIUM
Pion DTLS vulnerable to denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message
GHSA-wg4g-wm44-ch5j
pkg: github.com/pion/dtls/v3
eco: go
published: Jul 31, 2026
### Impact
Remote denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message.

### Patches
Upgrade to v3.1.4 or later. This version includes this patch https://github.com/pion/dtls/pull/839 which fixes the issue.

### Workarounds
No work around; please upgrade to v3.1.4 …

CVE-2026-54908
GitHub-GHSA

MEDIUM
free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure
GHSA-qj55-47fp-p62j
pkg: github.com/free5gc/free5gc, github.com/free5gc/ausf
eco: go
published: Jul 31, 2026
### Summary

The free5GC AUSF (Authentication Server Function) does not validate the `supiOrSuci` field in UE authentication requests. Null bytes (`\x00`) and other control characters pass through JSON parsing unchanged and are forwarded to the UDM in an unescaped URL path. This causes Go's `net/url…

CVE-2026-53551
GitHub-GHSA

MEDIUM
zaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth Limit
GHSA-3whf-vgf2-9w6g
pkg: zaino-state
eco: rust
published: Jul 31, 2026
### Summary
`NonFinalizedState::handle_reorg` is a recursive, unbounded async function that traverses parent blocks until it finds a common ancestor on the main chain. It has **no recursion depth limit** and **no cycle detection**. A malicious or buggy validator can serve a block whose `previous_blo…
GitHub-GHSA

MEDIUM
Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses clean-html sanitization
GHSA-45qg-252v-3f7p
pkg: jodit
eco: npm
published: Jul 31, 2026
A `<script>` element placed directly inside an `<svg>` (or MathML) container was not removed by Jodit's clean-html sanitizer.

The deny/allow tag filter compared `node.nodeName` against an upper-cased tag hash, but foreign (SVG/MathML) elements preserve their original-case node names — an SVG scri…

CVE-2026-65841
GitHub-GHSA

MEDIUM
Jodit has prototype pollution via Jodit.configure() / ConfigMerge
GHSA-5957-5c94-3v7w
pkg: jodit
eco: npm
published: Jul 31, 2026
### Summary
`Jodit.configure(options)` — and the internal `ConfigMerge` / `ConfigProto` helpers — merged user-supplied options into the editor configuration without filtering prototype-mutating keys. A payload nested under an existing plain-object option such as `controls` could reach and mutate…
CVE-2026-54756
GitHub-GHSA

MEDIUM
linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect
GHSA-4jc5-g844-4×33
pkg: linuxfabrik-lib
eco: pip
published: Jul 30, 2026
### Summary
`lib.url.fetch()` follows HTTP redirects (`follow_redirects=True`). httpx strips only `Authorization` and `Cookie` when a redirect crosses the origin, so any other caller-supplied credential header (a session token such as Redfish's `X-Auth-Token`, an API key, …) was still sent to the …
CVE-2026-67435
GitHub-GHSA

MEDIUM
MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection
GHSA-rjr6-rcgv-9m7m
pkg: mcp
eco: rubygems
published: Jul 30, 2026
## Summary

`MCP::Server::Transports::StreamableHTTPTransport` (the Rack-mountable Streamable HTTP transport in the `mcp` gem) processes every incoming JSON-RPC request without ever inspecting the HTTP `Host` or `Origin` request headers. There is no `AllowedHosts`/`AllowedOrigins` allowlist and no D…

CVE-2026-63118
GitHub-GHSA

MEDIUM
olm dependency deprecation: CVE-2022-39255 and CVE-2024-45193
GHSA-wchh-9x6h-7f6p
pkg: matrix-commander
eco: pip
published: Jul 29, 2026
### Problem

Multiple vulnerabilities were disclosed in 2024 affecting libolm (Olm): AES timing / side‑channel, Ed25519 signature malleability, and timing leaks in base64 decoding; several CVEs were assigned. Patches and mitigations were published; maintainers recommend upgrading to fixed versions…

GitHub-GHSA

MEDIUM
veraPDF Parser DoS via PostScript Type 1 Font Programs
GHSA-7c26-995w-6f47
pkg: org.verapdf:parser, org.verapdf:parser
eco: maven
published: Jul 29, 2026
## Summary

**Description**

A PostScript-interpreter-driven Denial of Service (CWE-1325) vulnerability in veraPDF allows a remote attacker to exhaust validator memory or CPU by submitting a PDF whose Type 1 font `/FontFile` is a font program containing attacker-supplied PostScript. veraPDF's Type 1…

CVE-2026-54081
GitHub-GHSA

MEDIUM
veraPDF Parser DoS via PostScript CMap Streams
GHSA-jrmc-qg6p-94fp
pkg: org.verapdf:parser, org.verapdf:parser
eco: maven
published: Jul 29, 2026
## Summary

**Description**

A PostScript-interpreter-driven Denial of Service (CWE-1325) vulnerability in veraPDF allows a remote attacker to exhaust validator memory or CPU by submitting a PDF whose Type 0 font `/Encoding` (or any `/ToUnicode`) is a CMap stream containing attacker-supplied PostScr…

CVE-2026-54080
GitHub-GHSA

MEDIUM
Pagy I18n locale option is not validated before being used in a file path
GHSA-2xmw-f8j8-wfxc
pkg: pagy
eco: rubygems
published: Jul 28, 2026
### Summary

`Pagy::I18n.locale=` did not validate its argument before using it as a
path component to load the matching dictionary file (`<locale>.yml`). An
application that assigns untrusted input to the locale — e.g. the common
pattern `Pagy::I18n.locale = params[:locale]` — let that input in…

CVE-2026-54659
GitHub-GHSA

MEDIUM
GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS
GHSA-g6v3-7xmc-w563
pkg: github.com/gopacket/gopacket
eco: go
published: Jul 28, 2026
## Summary

The sFlow `ExtendedGatewayFlow` record decoder in `github.com/gopacket/gopacket` allocates a slice with `make([]uint32, n)` where `n` is an attacker-controlled 32-bit wire field that has no upper bound. Because the allocation happens *before* the read loop that would consume the correspo…

CVE-2026-54332
GitHub-GHSA

MEDIUM
GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS)
GHSA-6r28-9ppf-4hj5
pkg: github.com/gopacket/gopacket
eco: go
published: Jul 28, 2026
## Summary

The Diameter AVP decoder in `github.com/gopacket/gopacket` computes `dataLength := avp.Length – uint32(headerSize)` without first ensuring `avp.Length >= headerSize`. When the Vendor flag is set, `headerSize` is 12, but the only length guard upstream rejects `avp.Length < 8`. An AVP with…

CVE-2026-54345
GitHub-GHSA

MEDIUM
Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method
GHSA-hp74-gm6m-2qm5
pkg: github.com/pocket-id/pocket-id/backend
eco: go
published: Jul 28, 2026
# Reauthentication Bypass via One-Time Access Token Login

## Summary

A weaker authentication method (OTA token or signup token) is accepted as passkey step-up proof, yielding unauthorized renewable 30-day OIDC refresh tokens for clients explicitly configured with `RequiresReauthentication: true`. …