CISA-KEV
CRITICAL
Progress LoadMaster Command Injection Vulnerability
Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV
CRITICAL
JetBrains TeamCity Deserialization of Untrusted Data Vulnerability
JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV
CRITICAL
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV
CRITICAL
Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV
CRITICAL
IBM Langflow Code Injection Vulnerability
Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
NVD
CRITICAL
CVE-2026-5430
The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access.
Successful exploitation of this vuln…
CWE: CWE-347
NVD
CRITICAL
CVE-2026-48086
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN promotes themselves to platform-wide GLOBAL_ADMIN through a single PUT request. The role-update handler accepts the `GLOBAL_ADMIN` enum value from any te…
CWE: CWE-269
NVD
CRITICAL
CVE-2026-70615
boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users with tunnel-creation permission to inject arbitrary lines into the server account's SSH authorized_keys file by supplying a percent-encoded newline character in the domain parameter o…
CWE: CWE-93
NVD
CRITICAL
CVE-2026-10090
A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with namespace-scoped "edit" privileges in an ACM hub namespace can create a Channel resource pointing to a Helm repository they contr…
CWE: CWE-267
NVD
CRITICAL
CVE-2026-19264
Postiz is an open-source social media scheduling tool. The route that serves locally stored media joins URL-supplied path segments onto the upload directory and streams the file without normalising the path or confining it to that directory, and the route requires no authentication. Raw dot-segments…
CWE: CWE-22
NVD
CRITICAL
CVE-2026-70558
Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and file.transferTo(dest) with no path validation. The route is marked @SaIgnore and /download/** is excluded from the Sa-Token interceptor, so the only guard is a header equality …
CWE: CWE-434
NVD
CRITICAL
CVE-2026-53975
OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by sending crafted POST requests to the /api/fs/exec endpoint, which passes commands verbatim to Node.js spawn() without any allowlist, blocklist, or ar…
CWE: CWE-78
NVD
CRITICAL
CVE-2026-67870
In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local ExpandedNodeId targets. A remote attacker can send a crafted AddReferencesRequest with an empty targetServerUri and a non-zero targetNodeId.serverIndex, causing the target node poin…
CWE: CWE-476
NVD
CRITICAL
CVE-2026-71289
The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose.yml publishes the amp-manager service's REST API directly to the host network interface (port 8089, e.g. "${ION_MGR_PORT:-8089}:8089/tcp") with cap_add: NET_ADMIN, NET_RAW, SYS_NICE, bypass…
CWE: CWE-306
NVD
CRITICAL
CVE-2026-71214
The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-server/src/app.ts) derives the caller's Hasura session role via getHasuraSession(), which prefers a session_variables object taken directly from the client-supplied JSON request body over the Authorization header's JWT claims…
CWE: CWE-306
NVD
CRITICAL
CVE-2026-64566
In the Linux kernel, the following vulnerability has been resolved:
xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags()
When iptfs_skb_add_frags() copies frag references from the source
frag walk into a new SKB, it increments the page reference count via
__skb_frag_ref() but does not…
NVD
CRITICAL
CVE-2026-66902
Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated system call.
The Pluggable subclass reads credential_source.executable.command from the credentials JSON and runs it as `system($command)`, a single argument call that passes the wh…
CWE: CWE-78, CWE-829
NVD
CRITICAL
CVE-2026-24254
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
CWE: CWE-288
NVD
CRITICAL
CVE-2025-29296
H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V100R017, H3C Magic R1510 V100R016, H3C NE36 Pro V100R002 and H3C MC102G HM1A0V200R010 contain multiple command injection vulnerabilities in the /api/esps request handler. The affec…
CWE: CWE-77
NVD
CRITICAL
CVE-2026-69098
kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON input with a __type__ field. Attackers can exploit this to override the __type__ fi…
CWE: CWE-502
NVD
CRITICAL
CVE-2026-64564
In the Linux kernel, the following vulnerability has been resolved:
sctp: don't free the ASCONF's own transport in DEL-IP processing
sctp_process_asconf() caches the transport the ASCONF chunk is processed
against in asconf->transport (== chunk->transport, set once in sctp_rcv()).
For an ASCONF lo…
NVD
CRITICAL
CVE-2026-69240
Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with strings only if dialect is set to oracle. The escape function defined in sql-string.js does not escape quotes if the value starts with TO_TIMESTAMP or TO_DATE. In the Oracle dialect, when val is a string and starts with…
CWE: CWE-89
GitHub-GHSA
CRITICAL
Sequelize: SQL Injection (Oracle DB)
GHSA-v8fg-2rw7-q452
pkg: sequelize
eco: npm
published: Aug 3, 2026
### Summary
SQL Injection is possible with strings only **if dialect is set to `oracle`**.
The vulnerability was confirmed on Sequelize v6.37.3.
### Details
The `escape` function defined in `sql-string.js` does not escape quotes if the value starts with `TO_TIMESTAMP` or `TO_DATE`.
“`javascript
…
CVE-2026-69240
NVD
CRITICAL
CVE-2026-19171
Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD
CRITICAL
CVE-2026-19157
Out of bounds write in ANGLE in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-787
NVD
CRITICAL
CVE-2026-19149
Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD
CRITICAL
CVE-2026-71319
Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite HMR WebSocket via the nuxt:devtools:rpc plugin. On affected versions the channel has no authentication: any client that can reach the V…
CWE: CWE-94, CWE-306
GitHub-GHSA
CRITICAL
Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host
GHSA-279x-mwfv-vcqv
pkg: @nuxt/devtools
eco: npm
published: Aug 5, 2026
### Impact
Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite HMR WebSocket via the `nuxt:devtools:rpc` plugin. On affected versions the channel has no authentication: any client that can reach the Vite HMR endpoint (`ws://<host>:<port>/`, subprotocol `vite-hmr`…
CVE-2026-71319
NVD
CRITICAL
CVE-2026-65520
Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions.
CWE: CWE-89
GitHub-GHSA
CRITICAL
Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware
GHSA-cxjq-mrr5-89rv
pkg: github.com/traefik/traefik/v2, github.com/traefik/traefik/v3, github.com/traefik/traefik/v3
eco: go
published: Aug 6, 2026
## Summary
There is a critical authentication-bypass vulnerability in Traefik's `ReplacePathRegex` middleware. When it is configured with a regular expression that captures user-controlled path segments without a mandatory separator (for example `regex: "^/api(.*)"`, `replacement: "/$1"`), a crafte…
CVE-2026-65600
NVD
CRITICAL
CVE-2026-53976
OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and /api/fs/raw that allows unauthenticated remote attackers to read arbitrary files by supplying the allowOutsideWorkspace=true query parameter alongside an absolute path, bypassing …
CWE: CWE-22
NVD
CRITICAL
CVE-2026-63687
Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without excluding security-sensitive parameters. A client that can produce a validly-signed request JWT (e.g., one whose client_secret is known or compromised) can thereby substitute th…
CWE: CWE-345
NVD
CRITICAL
CVE-2026-61466
In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration request verbatim, without validating it against an AS-defined allowlist. This could lead to a client self-assigning privileged scopes at regi…
CWE: CWE-304
NVD
CRITICAL
CVE-2026-71263
The LINUXTCP port of FreeModbus contains an off-by-one bounds check in xMBPortTCPPool() (demo/LINUXTCP/port/porttcp.c). The check `if (usTCPFrameBytesLeft > MB_TCP_BUF_SIZE)` uses a strict greater-than comparison instead of greater-than-or-equal against the 263-byte MB_TCP_BUF_SIZE limit. An MBAP fr…
CWE: CWE-787
NVD
CRITICAL
CVE-2026-71238
DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. Since this key is used for session signing, CSRF token generation, and password reset tokens, anyone who reads the public repository can forge valid sessio…
CWE: CWE-798
NVD
CRITICAL
CVE-2026-10059
A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertently grants the tenant administrator the ability to mint a token …
CWE: CWE-266
NVD
CRITICAL
CVE-2026-18754
The
product firmware contains an embedded, static RSA private key utilized by the
Lighttpd web server for TLS termination. Exposure of this private key allows
malicious actors to breach the confidentiality and integrity of HTTPS
communications, enabling traffic decryption and server spoofing.
CWE: CWE-321
NVD
CRITICAL
CVE-2026-18753
The
product firmware contains an embedded, static RSA private key utilized by the
Lighttpd web server for TLS termination. Exposure of this private key allows
malicious actors to breach the confidentiality and integrity of HTTPS
communications, enabling traffic decryption and server spoofing.
CWE: CWE-321
NVD
CRITICAL
CVE-2026-48031
go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by PostgreSQL. In versions prior to 2026-05-18, the JWT signing secret is hardcoded to the known string "random", letting any attacker who reads the public repository forge tokens for arbitrary users, including admin ro…
CWE: CWE-798
NVD
CRITICAL
CVE-2026-9487
XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID.
_get_signed_xml() in lib/XML/Sig.pm, called from verify(), resolves the SignedInfo Reference/@URI to a node with the XPath expression "//*[@ID='$id']" and returns the first node of the resulting node set. A document i…
CWE: CWE-347
NVD
CRITICAL
CVE-2026-9390
XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup.
verify() and _get_signed_xml() in lib/XML/Sig.pm build XPath expressions by concatenating the SignedInfo/Reference/@URI value read from the document being verified. The value is neither escaped nor checked against the NCName…
CWE: CWE-643, CWE-1287
GitHub-GHSA
CRITICAL
crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain
GHSA-rg76-677x-56q9
pkg: crypto-js
eco: npm
published: Aug 7, 2026
### Summary
`CryptoJS.lib.WordArray.random()` in affected versions is not a cryptographically secure random number generator. Nominal requests for 128 or 256 bits of entropy produce effective search spaces of approximately 2^39 and 2^47 possibilities — small enough to enumerate on commodity hardw…
CVE-2026-71851
GitHub-GHSA
CRITICAL
Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables token theft for any connected service
GHSA-qgvm-j2hm-6m38
pkg: flowise
eco: npm
published: Aug 4, 2026
### Summary
The OAuth2 token refresh endpoint (`POST /api/v1/oauth2-credential/refresh/:credentialId`) is in `WHITELIST_URLS`, meaning it requires **no authentication**. It decrypts the stored credential (containing `clientId`, `clientSecret`, `refresh_token`), sends a refresh request to the config…
CVE-2026-70478
GitHub-GHSA
CRITICAL
Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
GHSA-5xvg-pmgg-3mxr
pkg: flowise, flowise-components
eco: npm
published: Aug 4, 2026
— ABSTRACT ————————————-
Trend Micro's Zero Day Initiative has identified a vulnerability affecting the following products:
Flowise – Flowise
— VULNERABILITY DETAILS ————————
* Version tested: 3.1.1
* Installer file: https://github.com/FlowiseAI/Flowise (n…
CVE-2026-70477
GitHub-GHSA
CRITICAL
Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation
GHSA-4j8x-x6v7-w9rq
pkg: flowise, flowise-components
eco: npm
published: Aug 4, 2026
### Summary
Flowise's `CSVAgent` interpolates an attacker-controlled segment of the
`csvFile` data URI directly into a Python source-code template that is then
executed by Pyodide. Because Pyodide is loaded with the default `js` bridge
to `globalThis` (which on Node.js exposes `eval` and dynamic `im…
CVE-2026-69264
GitHub-GHSA
CRITICAL
Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE
GHSA-52fh-8v99-63c2
pkg: flowise, flowise-components
eco: npm
published: Aug 4, 2026
### Summary
The validatePythonCodeForDataFrame blacklist in packages/components/src/pythonCodeValidator.ts can be bypassed with Unicode homoglyph identifiers, allowing arbitrary Python execution inside Pyodide and full OS command execution on the Flowise host via Pyodide's js module interop. This re…
CVE-2026-70470
GitHub-GHSA
CRITICAL
Flowise RCE via SQLite Record Manager Node
GHSA-x3hf-7cj6-3r4m
pkg: flowise, flowise-components
eco: npm
published: Aug 4, 2026
=============================================================================
Security Advisory
elttam
Topic: Flowise RCE via SQLite Record Manager Node
Modul…
CVE-2026-69259
GitHub-GHSA
CRITICAL
Flowise: Remote Code Execution Vulnerability in CSVAgent
GHSA-x6vm-w76m-8j7g
pkg: flowise-components, flowise
eco: npm
published: Aug 4, 2026
### Summary
The CSVAgent node was observed to allow users to write Python code which gets executed via `pyodide`. The original intent was to allow users to utilise the `pandas` library for CSV processing. Although there is a denylist that checks for dangerous Python constructs from being passed in,…
CVE-2026-69256
GitHub-GHSA
CRITICAL
Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified
GHSA-vmv7-4m6c-3cg5
pkg: flowise, flowise-components
eco: npm
published: Aug 4, 2026
## UPDATE 2026-05-20: Full RCE as root VERIFIED
**This is not theoretical — a Meterpreter reverse shell session as root has been established on Flowise 3.1.2.**
### Verified Exploit Chain
1. Python code injection via `base64_string = "${base64String}"` (CSVAgent.ts line 161)
2. Pyodide `js` bri…
CVE-2026-69255
GitHub-GHSA
CRITICAL
Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override
GHSA-3769-jgqc-cxm7
pkg: flowise, flowise-components
eco: npm
published: Aug 4, 2026
### Summary
A sandbox escape vulnerability in `executeJavaScriptCode()` allows any authenticated user to execute arbitrary system commands as root on the Flowise server. The function accepts caller-provided `nodeVMOptions` that override the
default sandbox security settings via JavaScript's spread…
CVE-2026-69254
GitHub-GHSA
CRITICAL
Flowise Sandbox Escape to RCE
GHSA-wg86-r78f-74mp
pkg: flowise, flowise-components
eco: npm
published: Aug 4, 2026
=============================================================================
Security Advisory
elttam
Topic: Flowise JavaScript Sandbox Escape
Module: …
CVE-2026-69253
GitHub-GHSA
CRITICAL
Flowise RCE via TypeORM DataSource
GHSA-g32j-mmxr-gfq5
pkg: flowise, flowise-components
eco: npm
published: Aug 4, 2026
=============================================================================
Security Advisory
elttam
Topic: Flowise RCE via TypeORM DataSource
Module: …
CVE-2026-69251
GitHub-GHSA
HIGH
GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution
GHSA-wvpp-8hx9-p66j
pkg: GitPython
eco: pip
published: Aug 7, 2026
## Summary
The `check_unsafe_options` guard can be bypassed on every guarded method (clone/clone_from, fetch/pull/push, ls_remote, iter_commits, blame, archive) by combining a single-character kwarg with `split_single_char_options=False`. The guard's candidate list omits the smuggled option, but `tr…
GitHub-GHSA
HIGH
GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE)
GHSA-jm78-9fvv-mhgr
pkg: GitPython
eco: pip
published: Aug 7, 2026
## Summary
GitPython's config-name validator only neutralizes CR/LF/NUL for the `"option"` label; it does not reject `=`, `#`, `;`, `[`, `]`, or whitespace in an **option name**. `write_section` writes the option name verbatim into the config file, so an option name such as `sshCommand = touch <cmd>…
NVD
HIGH
CVE-2026-9169
DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows a local attacker to execute arbitrary code with the privileges of the application by placing a malicious DLL in a user-controlled directory listed in the PATH environment variable, which the SDK traverses when a re…
CWE: CWE-427
NVD
HIGH
CVE-2026-48054
OpenZeppelin Contracts Wizardis a web application to interactively build a contract out of components from OpenZeppelin Contracts. Versions prior to 0.10.9 generate a Hardhat test file (`test/test.ts`) by interpolating user-supplied `opts.name` (ERC20/ERC721) and `opts.uri` (ERC1155) directly into T…
CWE: CWE-94
NVD
HIGH
CVE-2026-19151
Use after free in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD
HIGH
CVE-2026-19150
Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-693
NVD
HIGH
CVE-2026-19145
Use after free in Translate in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD
HIGH
CVE-2026-19144
Use after free in HTML in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD
HIGH
CVE-2026-64586
In the Linux kernel, the following vulnerability has been resolved:
wifi: brcmfmac: drain bus_reset work on device removal
brcmf_fw_crashed() and the debugfs "reset" entry both schedule
drvr->bus_reset, whose callback recovers drvr through container_of()
and dereferences it. The removal path free…
GitHub-GHSA
HIGH
rclone `serve restic –private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories
GHSA-fqj9-69pf-6pjg
pkg: github.com/rclone/rclone
eco: go
published: Aug 5, 2026
## Summary
`rclone serve restic –private-repos` exists to let one rclone instance host many users' restic backup repositories behind HTTP Basic auth while keeping each user confined to a path prefix of `/<username>/`. The documentation states the flag "can be used to limit users to repositories st…
CVE-2026-59733
NVD
HIGH
CVE-2026-9201
IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryptographic weakness in the custom component validation mechanism. When the optional hardening mode that restricts execution to trusted component templates is enabled, the application val…
CWE: CWE-326
NVD
HIGH
CVE-2026-17632
IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of Python code during AST-based security scanning.
CWE: CWE-94
NVD
HIGH
CVE-2026-17626
IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expose sensitive host files via Docker-based MCP servers due to incomplete filtering of dangerous Docker volume-mount and device-mapping arguments.
CWE: CWE-266
NVD
HIGH
CVE-2026-71287
Cacti's sanitize_sql_column() (lib/functions.php) sanitizes user-supplied ORDER BY column names using the regex `preg_replace('/[^a-zA-Z0-9_().]/', '', $column)`. Because this allowlist retains letters, digits, underscore, parentheses, and dot (intended to support expressions like COUNT(id) and tabl…
CWE: CWE-89
NVD
HIGH
CVE-2026-71235
Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side when IoT messages arrive. The Go script engine (re/golang.go) runs scripts through the Yaegi interpreter with stdlib.Symbols, exposing the full Go standard library (including os …
CWE: CWE-94
NVD
HIGH
CVE-2026-55997
Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens were stored and exposed in plaintext with no expiration, so a malicious user could obtain one either through the Rancher API, etcd, stored automation, or direct file access on a …
CWE: CWE-312
NVD
HIGH
CVE-2026-70374
HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the media upload thumbnail generation routine. Media.generateThumbnail() in src/Server/Entity/Resource/Media.js builds a temporary file path as 'thumbnail' + Path.extname(filename) and passes it, unescaped, into a…
CWE: CWE-78
NVD
HIGH
CVE-2026-67195
Perspective 5.0.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary operating system commands by submitting crafted expression strings to the PolarsVirtualServer backend, which passes client-supplied input directly to Python's eval() with only …
CWE: CWE-95
NVD
HIGH
CVE-2026-64562
In the Linux kernel, the following vulnerability has been resolved:
KVM: nVMX: Hide shadow VMCS right after VMCLEAR
free_nested() frees the shadow VMCS while vmcs01 still points to it. But
because it is asynchronous with respect to loaded_vmcs_clear(), the vCPU
might migrate before the pointer is …
NVD
HIGH
CVE-2026-64561
In the Linux kernel, the following vulnerability has been resolved:
KVM: x86: Check for invalid/obsolete root *after* making MMU pages available
Check for a "stale" page fault, i.e. for an invalid and/or obsolete root,
after making MMU pages available for the shadow MMU. If reclaiming shadow
page…
NVD
HIGH
CVE-2026-69096
OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.uc RPC backend after the JS/ucode conversion) contains an OS command injection vulnerability. The package's read ACL grants broad ubus access to docker.* / docker.container.*, which exposes the docker…
CWE: CWE-78
GitHub-GHSA
HIGH
Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages
GHSA-pwxh-7358-jq2x
pkg: open-webui
eco: pip
published: Aug 4, 2026
## Summary
Any authenticated user can store a chat message whose math block makes KaTeX fail with a stack overflow instead of a parse error. When that happens the renderer falls back to inserting the original math source into the page as HTML rather than as text, so script in the message runs in the…
CVE-2026-70492
NVD
HIGH
CVE-2026-64940
Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contains a vulnerability due to a permissive regular expression, which may allow an attacker who can access the affected product to log in to the management console. As a result, the attacker may perform any operations available from th…
CWE: CWE-625
NVD
HIGH
CVE-2026-63637
Dgraph is an open source distributed GraphQL database. Prior to 25.3.8, maybeQuoteArg in graphql/resolve/query_rewriter.go passes regexp filter strings into generated DQL without quoting or validating the /pattern/flags form, allowing crafted GraphQL query or mutation filters to inject DQL operators…
CWE: CWE-943
NVD
HIGH
CVE-2026-19143
Insufficient validation of untrusted input in WebAPKs in Google Chrome on Android prior to 151.0.7922.109 allowed a local attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
CWE: CWE-20
NVD
HIGH
CVE-2026-71259
ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url() validator in esphome/config_validation.py: `if parsed.scheme and parsed.netloc or parsed.scheme == "file": return parsed.geturl()`. Because `and` binds tighter than `or`, any file: URI passes validation regardless of ne…
CWE: CWE-184
NVD
HIGH
CVE-2026-45414
Decidim is a participatory democracy framework. Prior to 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, JWT-backed API authentication is not bound to the organization selected by the current host, allowing a JWT issued for one tenant to be replayed against another tenant’s API to read participantDeta…
CWE: CWE-639, CWE-863
NVD
HIGH
CVE-2026-71280
go-shiori's DownloadBookmark() (internal/core/download.go) fetches a caller-supplied bookmark URL using a plain http.Client with no custom DialContext or destination-IP validation (no IsLoopback(), IsPrivate(), IsUnspecified(), or IsLinkLocalUnicast() checks). An authenticated user creating or updat…
CWE: CWE-918
NVD
HIGH
CVE-2026-71271
Memos' webhook URL validation, isReservedIP() (internal/webhook/validate.go), checks a candidate IP against a reservedCIDRs list that omits 0.0.0.0/8 and never calls ip.IsUnspecified() — unlike the correctly implemented sibling function isInternalIP() in internal/httpgetter/html_meta.go, which doe…
CWE: CWE-918
NVD
HIGH
CVE-2026-19163
Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD
HIGH
CVE-2026-19155
Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD
HIGH
CVE-2026-19154
Use after free in Skia in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD
HIGH
CVE-2026-19152
Insufficient policy enforcement in Navigation in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-693
NVD
HIGH
CVE-2026-19148
Out of bounds write in GPU in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-787
NVD
HIGH
CVE-2026-19147
Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD
HIGH
CVE-2026-19141
Use after free in Resources in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD
HIGH
CVE-2026-19140
Use after free in GPU in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD
HIGH
CVE-2026-19138
Heap buffer overflow in CrashReporting in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-122
NVD
HIGH
CVE-2026-19137
Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD
HIGH
CVE-2026-71206
Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature and returns the embedded claims.Account object unmodified, never re-fetching the account from the database. No session store or token-revocation mechanism exists in the codebase. Deleting an account or de…
CWE: CWE-613
GitHub-GHSA
HIGH
GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython
GHSA-hmq2-w58f-27jc
pkg: GitPython
eco: pip
published: Aug 7, 2026
### Summary
GitPython computes the on-disk location of a submodule's separate Git directory (`.git/modules/<name>`) from the submodule's `.gitmodules` section name with no validation. Because that name is fully attacker-controlled content of a cloned repository, a malicious repository can set a subm…
GitHub-GHSA
HIGH
Traefik: Gateway API route identity collision allows cross-namespace backend hijacking
GHSA-fgjj-px3w-67xx
pkg: github.com/traefik/traefik/v3, github.com/traefik/traefik/v3
eco: go
published: Aug 6, 2026
## Summary
There is a high severity vulnerability in Traefik's Kubernetes Gateway API provider. Router and service identities for `HTTPRoute`, `GRPCRoute`, `TCPRoute` and `TLSRoute` objects were built by hyphen-concatenating the route namespace, the route name, the Gateway identity, the entry point…
CVE-2026-71327
NVD
HIGH
CVE-2026-71315
Nuxt is an open-source web development framework for Vue.js. From 3.21.7 until 3.21.10 and 4.5.1, mixed-case routeRules keys can fail to match case-folded lookups when router.options.sensitive is false and drop appMiddleware authorization gates. This is caused by an incomplete fix for CVE-2026-53721…
CWE: CWE-178, CWE-863
GitHub-GHSA
HIGH
Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)
GHSA-hxvh-4h3w-prp9
pkg: nuxt, nuxt
eco: npm
published: Aug 5, 2026
### Impact
Nuxt matches route rules case-insensitively by default (mirroring vue-router's default `sensitive: false` routing). The fix for GHSA-mm7m-92g8-7m47 / CVE-2026-53721 lowercased the *lookup* path before matching route rules, but the route-rule *keys* compiled into the matcher were left ver…
CVE-2026-71315
NVD
HIGH
CVE-2026-64578
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: validate compound request size before reading StructureSize2
When ksmbd validates a compound (chained) SMB2 request,
ksmbd_smb2_check_message() reads pdu->StructureSize2 without first
checking that the compound element is l…
GitHub-GHSA
HIGH
Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin
GHSA-3xpf-xq7r-v8c5
pkg: open-webui
eco: pip
published: Aug 4, 2026
## Summary
Any authenticated user with access to a terminal server could get script of their choosing to run in the Open WebUI origin itself. The HTML file preview rendered terminal-served files in an iframe whose sandbox always granted `allow-same-origin` alongside `allow-scripts`, and the file is …
CVE-2026-70486
NVD
HIGH
CVE-2026-47623
NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to denial of service and data tampering.
CWE: CWE-502
NVD
HIGH
CVE-2026-24253
NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service and data tampering.
CWE: CWE-787
NVD
HIGH
CVE-2026-58080
In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMapper`. On servers that rely on role permissions and construct the running configuration through `copy()`, sessions receive no role IDs and the default access controller skips role-permissio…
CWE: CWE-862
GitHub-GHSA
HIGH
GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite
GHSA-4gmw-gg2m-w46p
pkg: GitPython
eco: pip
published: Aug 7, 2026
## Summary
`IndexFile.from_tree`, `IndexFile.reset` (→ from_tree) and `IndexFile.merge_tree` append caller-influenced treeish strings positionally to `git read-tree` with no unsafe-option guard, no `allow_unsafe_options` parameter, and no `–` separator. `git read-tree –index-output=<file>` write…
NVD
HIGH
CVE-2026-64665
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker could sign in as an existing user, potentially including a super admin, withou…
CWE: CWE-287, CWE-290
NVD
HIGH
CVE-2026-5857
Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_len_received=1 before checking topic_len against the 64-byte limit, so an over-length topic returns early but leaves the flag set. On the next TCP segment, tcp_input() re-invokes the parser with topic_received==…
CWE: CWE-787
NVD
HIGH
CVE-2026-19153
Insufficient validation of untrusted input in Workers in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-20
NVD
HIGH
CVE-2026-71320
Nuxt is an open-source web development framework for Vue.js. From 3.4.0 until 3.21.10 and 4.5.1, an attacker can inject a template key through /__nuxt_island/ props into a dynamic component when `vue.runtimeCompiler: true` is enabled, causing template execution in the Nitro process. This issue is fi…
CWE: CWE-74, CWE-94
GitHub-GHSA
HIGH
Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props
GHSA-9473-5f9j-94wq
pkg: nuxt, nuxt
eco: npm
published: Aug 5, 2026
## Impact
Nuxt server islands accept props via the `/__nuxt_island/` endpoint. When `vue.runtimeCompiler: true` is enabled (off by default) and the application has a server island component that forwards props into Vue's dynamic component resolution (`<component :is>`, `resolveDynamicComponent`, or…
CVE-2026-71320
NVD
HIGH
CVE-2026-9196
IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agentic Assistant validation due to improper handling of LLM‑generated components. The application executes model‑generated Python code in the backend during validation prior to user app…
CWE: CWE-94
NVD
HIGH
CVE-2026-71285
Uptime Kuma's Matomo analytics integration (server/analytics/matomo-analytics.js) injects the admin-configurable Matomo `siteId` value as a bare, unquoted JavaScript expression inside a <script> block rendered on every public status page: `_paq.push(['setSiteId', ${escapedSiteIdHTMLAttribute}]);`. T…
CWE: CWE-79
GitHub-GHSA
HIGH
Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder
GHSA-3cg5-48j3-v4gv
pkg: open-webui
eco: pip
published: Aug 4, 2026
## Summary
A user granted write access to a shared chat folder could permanently delete chats and messages belonging to the folder's owner. Deleting a folder cascades into the owner's chats and the entire subfolder subtree, and the deletion handler required only write access on subfolders instead of…
CVE-2026-70494
NVD
HIGH
CVE-2026-70482
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.0, when ENABLE_OAUTH_TOKEN_EXCHANGE=True, /oauth/{provider}/token/exchange accepts a raw provider access token and validates it by calling the provider userinfo endpoint without confirming whi…
CWE: CWE-287
GitHub-GHSA
HIGH
Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client
GHSA-rq84-p6rr-vf89
pkg: open-webui
eco: pip
published: Aug 4, 2026
## Summary
The OAuth token exchange endpoint accepts a raw provider access token and validates it by calling the provider's userinfo endpoint. A userinfo endpoint reports only that a token is valid, never which OAuth client it was issued to, and the endpoint performed no audience or client check of…
CVE-2026-70482
GitHub-GHSA
HIGH
GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read
GHSA-3f7w-8rr8-f37f
pkg: GitPython
eco: pip
published: Aug 3, 2026
**Target:** gitpython-developers/GitPython
**Tested:** HEAD `07e80555` (2026-07-25), latest release 3.1.55, `git version 2.50.1`
**Reported instances:** 2 exploitable, from a sweep of 14 unguarded call sites
## Summary
GitPython blocks dangerous git options through `Git.check_unsafe_options()`, ga…
NVD
HIGH
CVE-2026-67611
OpenEMR through 8.2.0 contains an authentication bypass vulnerability that allows attackers with valid credentials to circumvent multi-factor authentication by exploiting the exposed OAuth2 password grant flow through an unauthenticated client registration endpoint. Attackers can register an OAuth2 …
CWE: CWE-308
NVD
HIGH
CVE-2026-67610
OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic client registration endpoint that allows unauthenticated attackers to register a malicious client with system-level FHIR scopes by supplying a self-generated RSA keypair via the jwks field. Once an administ…
CWE: CWE-306
GitHub-GHSA
HIGH
rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution
GHSA-2m8m-jhrm-w6j2
pkg: github.com/rclone/rclone
eco: go
published: Aug 5, 2026
## 1. Summary
rclone interpolates remote SFTP paths into PowerShell hash commands. Its quoting helper escapes only ASCII apostrophe, although PowerShell accepts four Unicode smart quotes as single-quote delimiters. An attacker-controlled filename can therefore terminate the intended path literal an…
CVE-2026-71312
NVD
HIGH
CVE-2026-71279
Zigbee2MQTT's ExternalJSExtension.getFilePath() (lib/extension/externalJS.ts) joins a `name` parameter received via an MQTT message (topic zigbee2mqtt/bridge/request/extension/save) into the extensions base path using path.join(basePath, name) with no sanitization. Because path.join() resolves `../`…
CWE: CWE-22
GitHub-GHSA
HIGH
jsii-diff: Command Injection via npm: package argument
GHSA-wcx4-wpfv-mc5c
pkg: jsii-diff
eco: npm
published: Aug 7, 2026
## Summary
jsii-diff is a command line tool to compare the API differences between two jsii assemblies, and report errors if there are backwards-incompatible changes to the API. An issue exists where specially formatted command line arguments can be used to execute shell commands via this tool.
##…
CVE-2026-15895
NVD
HIGH
CVE-2026-70628
FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsub_parser.c that allows attackers to trigger a heap buffer overflow by supplying a crafted WTV file. The overflow causes the bounds-check guard expressi…
CWE: CWE-190, CWE-787
NVD
HIGH
CVE-2026-64588
In the Linux kernel, the following vulnerability has been resolved:
fuse-uring: fix data races on ring->ready
On weakly-ordered architectures, the store to fiq->ops can be
reordered past the store to ring->ready, allowing a CPU that sees
ring->ready == true via fuse_uring_ready() to dispatch reque…
NVD
HIGH
CVE-2026-64585
In the Linux kernel, the following vulnerability has been resolved:
can: esd_usb: kill anchored URBs before freeing netdevs
esd_usb_disconnect() frees each CAN netdev with free_candev() inside
its per-netdev loop and only calls unlink_all_urbs(dev) afterwards.
The per-netdev private data (struct e…
NVD
HIGH
CVE-2026-64584
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: f_midi: cancel pending IN work before freeing the midi object
The f_midi driver embeds a work item (midi->work) whose handler,
f_midi_in_work(), dereferences the enclosing struct f_midi through
container_of(). This w…
NVD
HIGH
CVE-2026-64583
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown
The Broadcom BDC UDC driver registers its IRQ handler with
devm_request_irq() in bdc_udc_init(), so the IRQ is released by devm
only after bdc_remove() ret…
NVD
HIGH
CVE-2026-55522
PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of praiseonaiagents, the workflow "include" feature is vulnerable to code execution. Workflow._execute_include() implicitly imports and runs an included recipe's tools.py via a raw imp…
CWE: CWE-94, CWE-426, CWE-829
NVD
HIGH
CVE-2026-18485
There is a local privilege escalation vulnerability recently discovered in the NI-PAL kernel driver. This may allow a local, authenticated user to escalate privileges and execute arbitrary code. This vulnerability affects NI-PAL 26.3.1 and prior versions running on Microsoft Windows.
CWE: CWE-1285
NVD
HIGH
CVE-2026-12410
Link following vulnerability in the Uninstaller component in CCleaner prior to 7.10.1464 on Windows allows a local, low-privileged attacker to escalate privileges to SYSTEM via a symlink/junction created during application uninstallation, which CCleaner follows when deleting the application's data f…
CWE: CWE-59
NVD
HIGH
CVE-2026-64582
In the Linux kernel, the following vulnerability has been resolved:
RDMA/rxe: Fix a use-after-free problem in rxe_mmap
rxe_mmap() removes a rxe_mmap_info struct from the pending_mmaps list
and releases pending_lock while the struct's kref is still at 1:
list_del_init(&ip->pending_mmaps);
sp…
NVD
HIGH
CVE-2026-64581
In the Linux kernel, the following vulnerability has been resolved:
xfrm: fix sk_dst_cache double-free in xfrm_user_policy()
xfrm_user_policy() clears the socket dst cache with __sk_dst_reset(),
i.e. the non-atomic __sk_dst_set(sk, NULL): it reads sk_dst_cache with
rcu_dereference_protected(), sto…
NVD
HIGH
CVE-2026-64580
In the Linux kernel, the following vulnerability has been resolved:
xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst()
On the error path where in6_dev_get(dev) returns NULL, xfrm6_fill_dst()
releases the device reference with netdev_put() but leaves
xdst->u.dst.dev set. d…
NVD
HIGH
CVE-2026-64575
In the Linux kernel, the following vulnerability has been resolved:
bpf: tcp: fix double sock release on batch realloc
bpf_iter_tcp_batch() releases the current batch via
bpf_iter_tcp_put_batch(), which drops the socket refs and rewrites
each slot with the socket cookie, then grows the batch. cur_…
NVD
HIGH
CVE-2026-64574
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: tear down new links on vif update error path
When ieee80211_vif_update_links() adds new links it allocates a link
container for each and calls ieee80211_link_init() (which registers the
per-link debugfs files with …
NVD
HIGH
CVE-2026-64570
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: fix fils_discovery double free on alloc failure
ieee80211_set_fils_discovery() calls kfree_rcu() on the old template
before allocating the replacement. If the kzalloc() then fails, it
returns -ENOMEM while link->u.…
NVD
HIGH
CVE-2026-64568
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure
ieee80211_set_unsol_bcast_probe_resp() calls kfree_rcu() on the old
template before allocating the replacement. If the kzalloc() then fails,
it returns -ENOME…
NVD
HIGH
CVE-2026-64567
In the Linux kernel, the following vulnerability has been resolved:
btrfs: reject free space cache with more entries than pages
When loading a v1 free space cache, __load_free_space_cache() takes
num_entries and num_bitmaps straight from the on-disk
btrfs_free_space_header. That header is stored i…
NVD
HIGH
CVE-2026-18657
An uncontrolled search path element in Kiro CLI before version 2.10.0 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a maliciously crafted project directory containing an executable that bypasses workspace trust protections when a local user starts Kiro CLI in th…
CWE: CWE-427
NVD
HIGH
CVE-2026-18656
An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a maliciously crafted project directory containing an executable that bypasses workspace trust protections when a local user opens the directory.…
CWE: CWE-427
NVD
HIGH
CVE-2026-64563
In the Linux kernel, the following vulnerability has been resolved:
rhashtable: clear stale iter->p on table restart
rhashtable_walk_start_check() has two restart paths when resuming a walk.
When iter->walker.tbl is valid, it re-validates iter->p against the table
and sets iter->p = NULL if the ob…
NVD
HIGH
CVE-2026-41447
FirmaCheck for Windows before 1.3.16 contains a DLL hijacking vulnerability that allows local attackers to execute arbitrary code by placing a crafted openssl.cnf file in the unvalidated C:\Program Files (x86)\Common Files\SSL\ directory path. Attackers can write a malicious OpenSSL configuration fi…
CWE: CWE-426
NVD
HIGH
CVE-2026-64636
An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to read arbitrary data from the panel database.
CWE: CWE-89
GitHub-GHSA
HIGH
Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader
GHSA-w2rx-84hp-gg95
pkg: open-webui
eco: pip
published: Aug 4, 2026
## Summary
With the Playwright web loader enabled, Open WebUI opens user-submitted URLs in a real browser and validates the destination address before allowing the request. That check only ran for the top-level page request. Every other request the page issued was passed through unvalidated, so a pa…
CVE-2026-70479
NVD
HIGH
CVE-2026-34966
Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiting HTTP fetch operations in migration and OAuth avatar code paths that use Go's default http.Get without a custom DialContext. Attackers can supply arb…
CWE: CWE-918
NVD
HIGH
CVE-2026-10595
A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specifically in the SPA catch-all route implemented in `backend/routers/ui.py`. The vulnerability arises from the improper handling of user-controlled path input, which is directly joined into a filesystem path without sanitizat…
CWE: CWE-23
NVD
HIGH
CVE-2026-52880
Klever-Go is the Go implementation of the Klever blockchain protocol. Versions from 1.7.14 through 1.7.17 are vulnerable to a remotely triggerable denial of service. Both REST APIs are started with the Gin Engine.Run convenience method, which serves requests through Go's default HTTP server with no …
CWE: CWE-400, CWE-770
GitHub-GHSA
HIGH
pymdown-extensions: exponential-backtracking ReDoS in caret, tilde, betterem, and magiclink inline processors
GHSA-gm37-52c6-37mw
pkg: pymdown-extensions
eco: pip
published: Aug 7, 2026
### Summary
Four inline processors in pymdown-extensions contain regular expressions with
exponential backtracking. A single untrusted Markdown line under
50 bytes drives `markdown.markdown()` into unbounded CPU on the rendering thread
(seconds at ~45 bytes, growing exponentially with each added ch…
CVE-2026-67422
GitHub-GHSA
HIGH
GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via –template clone hooks
GHSA-9rj7-rf2p-w77r
pkg: GitPython
eco: pip
published: Aug 7, 2026
## Summary
`Repo.init()` forwards `**kwargs` verbatim to `git init` with no unsafe-option guard and no `allow_unsafe_options` parameter. `git init –template=<dir>` copies `<dir>/hooks/*` into the new repo's `.git/hooks`, so an attacker-controlled `template` kwarg plants a hook that executes on the …
NVD
HIGH
CVE-2026-16262
The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating user session, allowing an unauthenticated attacker to log a victim into an attacker-controlled account (login CSRF), so that the victim's subsequent activity is stored under and r…
CWE: CWE-352
NVD
HIGH
CVE-2026-70636
Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAuth2 credential refresh endpoint by exploiting prefix-based whitelist matching in the authentication middleware defined in packages/server/src/utils/constants.ts. Attackers can…
CWE: CWE-862
NVD
HIGH
CVE-2026-67422
pymdown-extensions is a collection of extensions for the Python Markdown library. In versions up to and including 11.0, four inline processors (caret, tilde, betterem, and magiclink) use regular expressions whose content groups can partition a run of delimiter characters in exponentially many ways, …
CWE: CWE-1333
NVD
HIGH
CVE-2026-19158
Use after free in Views in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD
HIGH
CVE-2026-19156
Heap buffer overflow in Base in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)
CWE: CWE-122
NVD
HIGH
CVE-2026-19142
Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
GitHub-GHSA
HIGH
JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported
GHSA-5p4m-2wfm-xmqj
pkg: js-yaml, js-yaml
eco: npm
published: Aug 6, 2026
# Quadratic CPU consumption in `!!omap` resolution (js-yaml 3.x and 4.x)
## Summary
`resolveYamlOmap()` enforces key uniqueness for `!!omap` sequences with a linear
scan (`objectKeys.indexOf(…)`) inside the per-element loop, making resolution
**O(n²)** in the number of entries. A modestly sized…
NVD
HIGH
CVE-2026-53985
Ground Station prior to 0.6.0 contains an unauthenticated denial-of-service vulnerability in the Socket.IO server's service_control event handler that allows any unauthenticated network peer to forcibly terminate the ground-station process by sending a single restart_service command. Attackers can …
CWE: CWE-306
NVD
HIGH
CVE-2026-53977
OpenChamber 1.11.7 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to terminate the server process by sending a POST request to the /api/system/shutdown endpoint, which is registered before the authentication middleware in the Express route handler chain.…
CWE: CWE-306
NVD
HIGH
CVE-2026-71321
Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, the internal island renderer endpoint `/__nuxt_island/…` decodes and hashes attacker-controlled JSON body input with destr and ohash before validating the URL-resident hash. An unauthenticated `POST /_…
CWE: CWE-407, CWE-770
NVD
HIGH
CVE-2026-71316
Nuxt is an open-source web development framework for Vue.js. From 4.4.0 until 4.5.1, runtime cache:nuxt:payload entries for /<page>/_payload.json can be returned before route middleware and page guards because import.meta.prerender is not enforced, disclosing another user's SSR data. This issue is f…
CWE: CWE-524, CWE-862
NVD
HIGH
CVE-2026-67864
An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the NodeManagement type-instantiation logic component
CWE: CWE-400
GitHub-GHSA
HIGH
Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation
GHSA-9pgf-384g-p7mv
pkg: nuxt, nuxt
eco: npm
published: Aug 5, 2026
### Impact
The internal island renderer endpoint (`/__nuxt_island/…`) decodes and hashes attacker-controlled request input before it validates the URL-resident hash. An unauthenticated `POST /__nuxt_island/<name>_<anything>.json` with a large JSON body (for example ~4.6 MB / 150k keys) is fully r…
CVE-2026-71321
NVD
HIGH
CVE-2026-71314
Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an unauthenticated attacker can use a server island v-for prop, including vforToArray and , to trigger unbounded SSR memory allocation until MAX_VFOR_LENGTH = 100000 and crash the Nuxt process. This issu…
CWE: CWE-400, CWE-770, CWE-789, CWE-1284
GitHub-GHSA
HIGH
Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients
GHSA-wm8w-6qjm-cv43
pkg: nuxt
eco: npm
published: Aug 5, 2026
### Impact
When a page is covered by `routeRules` `cache` / `swr` / `isr`, Nuxt enables runtime payload extraction and serves `/<page>/_payload.json`. On affected versions the renderer stored the SSR payload in the shared `cache:nuxt:payload` storage under a path-only key (no cookie, `authorization…
CVE-2026-71316
GitHub-GHSA
HIGH
Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering
GHSA-hxcr-hm88-mpq6
pkg: nuxt, nuxt
eco: npm
published: Aug 5, 2026
### Impact
An unauthenticated attacker can crash a Nuxt server that renders any island / server component containing a `v-for` over a prop (for example `v-for="n in count"` or a `<slot v-for>`). Because the island URL hash is a non-secret digest of the request, the attacker can compute a valid hash…
CVE-2026-71314
GitHub-GHSA
HIGH
rclone: Unvalidated symlink target in local `–links` — arbitrary file write from an untrusted remote
GHSA-cf44-9pgv-m4xc
pkg: github.com/rclone/rclone
eco: go
published: Aug 5, 2026
### Summary
With `-l/–links`, rclone serializes symlinks as `<name>.rclonelink` text objects whose body is the link target. When rclone writes such an object to a local destination, it recreates the symlink with `os.Symlink(<object body>, <dest path>)` and performs NO validation of the target. If t…
CVE-2026-54572
NVD
HIGH
CVE-2026-70601
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.5, apps that expose Promise-returning functions to web content via contextBridge may be vulnerable to a context isolation bypass. Untrusted web con…
CWE: CWE-693
GitHub-GHSA
HIGH
Electron: Context isolation bypass via Function.prototype.bind hijack
GHSA-h7rp-cf8h-j98x
pkg: electron, electron, electron
eco: npm
published: Aug 5, 2026
### Impact
Apps that expose Promise-returning functions to web content via `contextBridge` may be vulnerable to a context isolation bypass. Untrusted web content could obtain access to the isolated preload world and, through it, every capability the preload script has. In renderers without a sandbox…
CVE-2026-70601
NVD
HIGH
CVE-2026-54876
Issue summary: A malicious TLS server can cause a memory leak in a TLS
client that has enabled OCSP response checking by sending an OCSP
response that contains no single response entries.
Impact summary: An attacker can leak an attacker-tunable amount of memory
per TLS handshake in a victim client …
CWE: CWE-401
NVD
HIGH
CVE-2026-71215
art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by both the include() and extend() template directives, resolves the target file path via path.resolve(root, filename) with no check afterward that the result remains inside root. Because path.resolve() disc…
CWE: CWE-22
NVD
HIGH
CVE-2026-71209
audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated-allowed GET routes against req.path via a regex requiring a literal /items/:id/cover or /authors/:id/image shape, where req.path retains %2F sequences URL-encoded. Express's router decodes the :id route …
CWE: CWE-22
NVD
HIGH
CVE-2026-64577
In the Linux kernel, the following vulnerability has been resolved:
gtp: check skb_pull_data() return in gtp1u_send_echo_resp()
gtp1u_send_echo_resp() ignores skb_pull_data()'s return value. Its
caller gtp1u_udp_encap_recv() only guarantees 16 bytes (udphdr +
gtp1_header), but the pull requests 20…
NVD
HIGH
CVE-2026-67592
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.
This issue affects Apache Qpid ProtonJ2: through 1.1.0.
Users are recommended to upgrade to version 1.2.0…
CWE: CWE-770
GitHub-GHSA
HIGH
XSS in Ghost's ActivityPub client
GHSA-xpp7-93×6-v29m
pkg: @tryghost/activitypub
eco: npm
published: Aug 4, 2026
### Impact
The ActivityPub client in Ghost was vulnerable to JavaScript injection on posts shared by a maliciously customised ActivityPub server.
### Vulnerable Versions
This vulnerability is present in the @tryghost/activitypub package up to v3.0.8. All prior versions are also affected.
### Pa…
CVE-2026-53950
NVD
HIGH
CVE-2026-66901
Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated URLs taken from the credentials JSON.
The URLs the library requests are read from the credentials JSON, and their hosts were not checked against the universe domain before the re…
CWE: CWE-201, CWE-918
NVD
HIGH
CVE-2026-47618
NVIDIA Dynamo for Linux contains a vulnerability in the Rust multimodal media fetcher where an attacker could cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.
CWE: CWE-918
NVD
HIGH
CVE-2026-47617
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery via DNS rebinding. A successful exploit of this vulnerability might lead to information disclosure.
CWE: CWE-918
NVD
HIGH
CVE-2026-47616
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.
CWE: CWE-918
NVD
HIGH
CVE-2026-47615
NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery by supplying a crafted URL in a multimodal request. A successful exploit of this vulnerability might lead to information disclosure.
CWE: CWE-918
NVD
HIGH
CVE-2026-47614
NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.
CWE: CWE-918
NVD
HIGH
CVE-2026-47613
NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation of a pathname to a restricted directory by supplying a crafted local path in a multimodal request. A successful exploit of this vulnerability might lead to information disclosure.
CWE: CWE-918
NVD
HIGH
CVE-2026-47612
NVIDIA Dynamo for Linux contains a vulnerability in the image loading component where an attacker may cause improper limitation of a pathname to a restricted directory. A successful exploit of this vulnerability might lead to information disclosure.
CWE: CWE-22
NVD
HIGH
CVE-2026-24255
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a hash collision by submitting images that share an identical pixel byte sequence but have different dimensions. A successful exploit of this vulnerability might lead to data tampering.
CWE: CWE-1023
NVD
HIGH
CVE-2026-56848
A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free.
This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.
CWE: CWE-416
NVD
HIGH
CVE-2026-56846
A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion.
This vulnerability affects Node.js **24.x** and **22.x**.
CWE: CWE-400
GitHub-GHSA
HIGH
fast-uri vulnerable to host confusion via backslash authority introducer
GHSA-7p8r-x3mc-p8w7
pkg: fast-uri, fast-uri, fast-uri
eco: npm
published: Aug 3, 2026
### Impact
`fast-uri` v4.1.1 and earlier require a literal `//` to recognize a URI authority, so a reference that uses `\\`, `/\`, or `\/` as the authority introducer (in place of `//`, after an optional scheme) is parsed with no authority: the sequence and everything after it fold into the path. N…
CVE-2026-18446
GitHub-GHSA
HIGH
Socket.IO: Zero-attachment Memory Exhaustion
GHSA-2m8v-j782-fhvr
pkg: socket.io-parser, socket.io-parser, socket.io-parser
eco: npm
published: Aug 3, 2026
### Impact
A specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory.
### Patches
| Version range | Used by | Fixed version |
|———-…
CVE-2026-69185
GitHub-GHSA
HIGH
brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
GHSA-rgw5-rvv9-x895
pkg: brace-expansion, brace-expansion, brace-expansion
eco: npm
published: Aug 3, 2026
### Summary
The `maxLength` mitigation added in `5.0.8` for GHSA-mh99-v99m-4gvg / CVE-2026-14257 is incomplete. It bounds the accumulator where results are *combined*, but not the intermediate arrays that feed it. A ~25 KB input still crashes the Node process with an **uncatchable** out-of-memory e…
CVE-2026-69152
NVD
HIGH
CVE-2026-19139
Race in CredentialProvider in Google Chrome on Windows prior to 151.0.7922.109 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)
CWE: CWE-362, CWE-362
NVD
HIGH
CVE-2026-8470
IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's non-cryptographic random module for generating Fernet encryption keys from user secrets under 32 characters. The deterministic Mersenne Twister PRNG produces identical keys for id…
CWE: CWE-327
GitHub-GHSA
HIGH
Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads
GHSA-v3j7-r9gq-3gjw
pkg: electron, electron, electron
eco: npm
published: Aug 5, 2026
### Impact
A custom scheme registered with `supportFetchAPI: true` but without `corsEnabled: true` was not subject to CORS enforcement. A page loaded from a remote origin could therefore `fetch()` or `XMLHttpRequest` that scheme cross-origin and read the full response body, rather than the read bein…
CVE-2026-70604
NVD
HIGH
CVE-2026-67598
Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that allows network-adjacent attackers to intercept outbound HTTPS requests to configured LLM providers by presenting arbitrary TLS certificates, as CURLOPT_SSL_VERIFYPEER and CURLOPT_SSL_…
CWE: CWE-295
GitHub-GHSA
HIGH
undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives
GHSA-4cwx-7wf7-3272
pkg: undici, undici
eco: npm
published: Aug 3, 2026
### Summary
Two issues in undici's cache interceptor, both fixed by the same patch on `lib/util/cache.js`:
1. **Shared-cache disclosure:** Responses with malformed qualified `Cache-Control: private` directives such as `private=""` or `private=","` can be incorrectly stored in the default shared ca…
CVE-2026-13697
NVD
HIGH
CVE-2026-18770
A vulnerability has been found in vibesurf-ai VibeSurf up to cd6e519d507cdd4d63061300bf60fb176e1f57e0. Impacted is an unknown function of the file /code of the component Python Validation Handler. The manipulation leads to code injection. Remote exploitation of the attack is possible. This product f…
CWE: CWE-74, CWE-94
NVD
HIGH
CVE-2026-16636
The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Recipient Display Name (to.name) in Email Logs in all versions up to, and including, 2.2.95 due to insufficient input san…
CWE: CWE-79
GitHub-GHSA
HIGH
Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path
GHSA-9f4c-93c8-jc8g
pkg: electron, electron, electron
eco: npm
published: Aug 5, 2026
### Impact
A sandboxed iframe without the `allow-popups` keyword could still open a new window (or trigger `setWindowOpenHandler`) with no user interaction, because new-window navigations taking the OpenURL path did not apply the iframe sandbox popup restriction.
Apps that embed untrusted content i…
CVE-2026-70608
NVD
HIGH
CVE-2026-71269
Node-RED's local-filesystem library storage module (getLibraryEntry() and saveLibraryEntry() in packages/node_modules/@node-red/runtime/lib/storage/localfilesystem/library.js), reachable via GET/POST /library/:lib/:type/*path, joins the user-supplied path parameter directly into the filesystem path …
CWE: CWE-22
NVD
HIGH
CVE-2026-69246
Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host header separately. The cURL handlers set CURLOPT_URL to the URI exactly as written and push that Host into CURLOPT_HTTPHEADER; StreamHandler does the same throug…
CWE: CWE-180, CWE-436, CWE-918, CWE-941
GitHub-GHSA
HIGH
go-git: Worktree operations may follow symlinks
GHSA-hc8v-wwc9-vgxm
pkg: github.com/go-git/go-git/v5, github.com/go-git/go-git/v6
eco: go
published: Aug 7, 2026
## Impact
A symlink traversal issue in `go-git` could allow worktree operations to modify files outside the intended worktree path.
The `worktreeFilesystem` wrapper rejected dangerous path strings, including paths containing `.git`, parent-directory components, or control characters. However, it d…
CVE-2026-71556
NVD
HIGH
CVE-2026-64576
In the Linux kernel, the following vulnerability has been resolved:
nexthop: initialize extack in nh_res_bucket_migrate()
nh_res_bucket_migrate() passes an uninitialized netlink_ext_ack to
call_nexthop_res_bucket_notifiers(). When
nh_notifier_res_bucket_info_init() fails (e.g. the kzalloc returns
…
GitHub-GHSA
HIGH
Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs
GHSA-8x5v-cpv7-8jjp
pkg: open-webui
eco: pip
published: Aug 4, 2026
## Summary
Open WebUI fetches user-supplied URLs on the server for RAG URL ingestion, URL-to-markdown conversion and web-search content retrieval, and decides whether a destination is allowed by asking whether its IP address is globally routable. That test operates on the literal IPv6 address and d…
CVE-2026-70485
NVD
HIGH
CVE-2026-64587
In the Linux kernel, the following vulnerability has been resolved:
net: ethernet: arc: emac: quiesce interrupts before requesting IRQ
Normal RX/TX interrupts are enabled later, in arc_emac_open(), so probe
should not see interrupt delivery in the usual case. However, hardware may
still present st…
GitHub-GHSA
HIGH
ngx-extended-pdf-viewer bundles a version of pdf.js vulnerable to CVE-2026-16633
GHSA-w9hm-4m3m-fxmm
pkg: ngx-extended-pdf-viewer
eco: npm
published: Aug 6, 2026
ngx-extended-pdf-viewer embeds a fork of Mozilla's pdf.js rather than depending on pdfjs-dist, so this vulnerability is not visible to dependency scanners through package.json.
### Impact
Opening a malicious PDF can execute attacker-controlled JavaScript in the context of the hosting page. Upstream…
GitHub-GHSA
HIGH
PDF.js: Arbitrary JavaScript execution upon opening a malicious PDF
GHSA-hq66-cqwq-w95j
pkg: pdfjs-dist
eco: npm
published: Aug 6, 2026
### Impact
If PDF.js is used to load a malicious PDF, and PDF.js is configured with `enableScripting` set to true (which is the default value) and no CSP for disallowing script-src, unrestricted attacker-controlled JavaScript will be executed in the context of the hosting domain.
### Patches
### …
CVE-2026-16633
GitHub-GHSA
HIGH
Nx: Zip-Slip in the self-hosted remote cache
GHSA-vp3h-ghgh-jr7g
pkg: nx, @nx/s3-cache, @nx/gcs-cache
eco: npm
published: Aug 6, 2026
## Summary
The Nx **self-hosted HTTP remote cache** extracts downloaded cache artifacts without constraining where files are written. A malicious — or on-path (MITM) — remote cache server can return a crafted tar archive whose entries escape the cache directory and write to arbitrary locations …
CVE-2026-71476
GitHub-GHSA
HIGH
Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth
GHSA-x677-9fxg-v5c5
pkg: github.com/traefik/traefik/v2, github.com/traefik/traefik/v3, github.com/traefik/traefik/v3
eco: go
published: Aug 6, 2026
## Summary
There is a high severity vulnerability in Traefik's BasicAuth, DigestAuth, and ForwardAuth
middlewares. The fix for CVE-2026-33433 stripped canonical-cased spoofed identity headers
(e.g. `X-Auth-User`) before writing Traefik's own value, but did not account for
underscore-variant header …
CVE-2026-54763
GitHub-GHSA
HIGH
Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass
GHSA-8rxv-jg7p-wvg3
pkg: github.com/traefik/traefik/v3
eco: go
published: Aug 6, 2026
## Summary
There is a high severity vulnerability in Traefik's Kubernetes Ingress NGINX provider. When an Ingress uses the `nginx.ingress.kubernetes.io/rewrite-target` annotation with a regular expression that captures attacker-controlled text without requiring a path separator (for example path `/…
CVE-2026-67309
GitHub-GHSA
HIGH
Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool
GHSA-3ccp-42pg-hgv6
pkg: github.com/traefik/traefik/v2, github.com/traefik/traefik/v3, github.com/traefik/traefik/v3
eco: go
published: Aug 6, 2026
## Summary
There is a critical vulnerability in Traefik's default HTTP reverse proxy that leads to unauthenticated cross-user response poisoning. When a client opens an HTTP/2 or HTTP/3 `CONNECT` request, Traefik forwards it — body included — to an HTTP/1.1 upstream over a shared `net/http.Tran…
CVE-2026-71324
GitHub-GHSA
HIGH
rclone: Incomplete path validation allows backend root escape in serve restic
GHSA-45pq-889g-fcgh
pkg: github.com/rclone/rclone
eco: go
published: Aug 5, 2026
## Summary
`rclone serve restic` does not correctly reject URL paths beginning with `../`. On affected backends, an attacker who can access the REST endpoint can read, create, overwrite, or delete objects outside the path configured by the operator.
The issue affects `rclone v1.40` through `rclone…
CVE-2026-71309
GitHub-GHSA
HIGH
Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing Manipulation
GHSA-gmmw-qg98-6j6p
pkg: flowise
eco: npm
published: Aug 4, 2026
### Summary
Several organization billing endpoints accept attacker-controlled Stripe identifiers (subscriptionId) without verifying that the identifier belongs to the authenticated user's organization. This allows an authenticated attacker to perform unauthorized Stripe subscription operations on ot…
CVE-2026-70476
GitHub-GHSA
HIGH
Flowise: Missing Authorization on Execution Update Endpoint
GHSA-fm2f-4339-4p2f
pkg: flowise
eco: npm
published: Aug 4, 2026
# Flowise Security Audit Report
**Date**: 2026-03-17
**Researcher**: Dimpal Jadhav (jadhavdimpy@gmail.com)
**GitHub**: https://github.com/Dimpyj1604
**Target**: FlowiseAI/Flowise (latest main branch)
**Version**: flowise-components@3.1.0
### FINDING 1: Missing Authorization on Execution Update Endp…
CVE-2026-70475
GitHub-GHSA
HIGH
Flowise: Cross-Workspace OAuth2 Credential Metadata Leak
GHSA-wch5-xp77-fxg4
pkg: flowise
eco: npm
published: Aug 4, 2026
## Summary
Three OAuth2 credential endpoints look up credentials by `id` alone with no `workspaceId` filter. Two of these endpoints (`callback`, `refresh`) are whitelisted from all authentication. This allows:
1. **Cross-workspace credential access** — Any authenticated user can initiate OAuth2 …
CVE-2026-70474
GitHub-GHSA
HIGH
Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history
GHSA-fr6g-7cq8-fg82
pkg: flowise
eco: npm
published: Aug 4, 2026
### Summary
The **GET `/api/v1/upsert-history`** endpoint returns the **entire server-wide upsert history** (response size **>100MB**) instead of being scoped to the requesting user/tenant/workspace. The response includes **sensitive configuration data** (e.g., Vector Store settings such as **Qdrant…
CVE-2026-70473
GitHub-GHSA
HIGH
Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store
GHSA-chm3-vqcf-52rx
pkg: flowise
eco: npm
published: Aug 4, 2026
# Summary
These endpoints accept a client-controlled `credential` parameter. The server loads credentials by `id` and uses them directly, without checking whether that credential belongs to the caller’s workspace. If an attacker knows another workspace’s `credentialId`, they can use that works…
CVE-2026-70472
GitHub-GHSA
HIGH
Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys
GHSA-88pr-878c-24wf
pkg: flowise-components, flowise
eco: npm
published: Aug 4, 2026
## Summary
Flowise on current `main` allows an authenticated…
GitHub-GHSA
HIGH
Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure
GHSA-8r8h-6vcc-xhrv
pkg: flowise
eco: npm
published: Aug 4, 2026
## Finding — Unauthorized Workspace Variables disclosure via $vars injection (bypasses variables:view)
### What’s wrong (code locations)
– Variables for the active workspace are fetched without checking “variables:view” at this call site: flowise-src/
packages/components/src/utils.…
CVE-2026-70471
GitHub-GHSA
HIGH
Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)
GHSA-xc48-889x-5qmw
pkg: flowise, flowise-components
eco: npm
published: Aug 4, 2026
## Summary
The mitigation shipped for CVE-2025-8943 blocks the `-y` and `–yes` flags on `npx` to stop auto-installation of arbitrary packages. That flag filter works. The environment-variable check in the same patch denies only four variable names by exact string match, and `npm` reads its configu…
CVE-2026-69263
GitHub-GHSA
HIGH
Flowise: `DELETE /api/v1/chatflows/:id` does not validate resource type, allowing `agentflows:delete` and `chatflows:delete` to delete each other’s flow type
GHSA-p5w8-m249-4r4v
pkg: flowise
eco: npm
published: Aug 4, 2026
# summary:
In Flowise, `DELETE /api/v1/chatflows/:id` authorizes requests with `checkAnyPermission('chatflows:delete,agentflows:delete')`. Possession of either permission is sufficient to reach the delete path. The delete logic does not validate the target resource `type`, allowing a caller with onl…
CVE-2026-69262
GitHub-GHSA
HIGH
Flowise: Unauthenticated Property Injection into Flow Execution Context via Ungated `overrideConfig` Spread in Prediction API
GHSA-6vh2-wg4h-4vwj
pkg: flowise
eco: npm
published: Aug 4, 2026
#### Summary
The `POST /api/v1/prediction/:id` endpoint — which is unauthenticated (whitelisted in `WHITELIST_URLS`) — accepts an `overrideConfig` object in the request body. This object is unconditionally spread into the internal `flowConfig` and `flowData` objects at two locations in the code…
CVE-2026-69258
GitHub-GHSA
HIGH
Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses
GHSA-c6xh-wv4j-ppv5
pkg: flowise
eco: npm
published: Aug 4, 2026
## Summary
Flowise's HTTP security module (`httpSecurity.ts`) fails to normalize IPv4-mapped IPv6 addresses (e.g., `::ffff:127.0.0.1`, `::ffff:169.254.169.254`) before checking them against the deny list. Due to an `ipaddr.js` kind mismatch (`ipv6` vs `ipv4`), all IPv4 CIDR deny rules are silently …
CVE-2026-69257
GitHub-GHSA
HIGH
Flowise: Missing authorization on `/api/v1/files` allows low-privileged API keys to list and delete files across workspaces within the same organization
GHSA-wp74-f5hh-5f3r
pkg: flowise
eco: npm
published: Aug 4, 2026
# summary:
In Flowise, the `/api/v1/files` route is protected only by the `feat:files` feature gate and does not enforce `checkPermission(…)` on either `GET` or `DELETE`. As a result, any authenticated API key within the organization, even one with unrelated permissions, can list and delete files …
CVE-2026-69252
GitHub-GHSA
HIGH
Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret Exfiltration
GHSA-r745-8hwv-h473
pkg: flowise
eco: npm
published: Aug 4, 2026
### Summary
The OAuth2 token refresh endpoint (`POST /api/v1/oauth2-credential/refresh/:credentialId`) is unauthenticated by design (it is in the public whitelist) and performs a server-side HTTP request to a credential-controlled URL (`accessTokenUrl`) without SSRF protections. In runtime validati…
CVE-2026-69250
GitHub-GHSA
HIGH
python-cryptography: Duplicate self-signed intermediates can cause exponential path-building
GHSA-jwv3-5hgf-82ww
pkg: cryptography
eco: pip
published: Aug 3, 2026
### Summary
When resolving invalid certificate chains that include duplicate copies of self-signed certificates, the processing recursively invokes the same candidate, leading to an exponential blowup. Although the limitation that the chain depth cannot exceed a specified maximum depth prevents unbo…
CVE-2026-69249
GitHub-GHSA
HIGH
cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing
GHSA-g6cj-pr64-35w5
pkg: cryptography
eco: pip
published: Aug 3, 2026
### Summary
`pkcs7_decrypt_der`, `pkcs7_decrypt_pem`, and `pkcs7_decrypt_smime` reported the
outcome of decrypting a `RecipientInfo`'s `encryptedKey` in several
distinguishable ways, one of which disclosed the exact length recovered from the
RSA operation. The same distinction was also observable b…
CVE-2026-69247
GitHub-GHSA
HIGH
AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)
GHSA-cq5v-8q36-5273
pkg: aiohttp
eco: pip
published: Aug 3, 2026
### Summary
An out-of-bounds heap read could occur in the C response parser while building an error message for a malformed response.
### Impact
An attacker controlled server, or possibly an accidental response could trigger a DoS in the client.
### Workaround
If unable to upgrade, the Python p…
CVE-2026-69244
GitHub-GHSA
HIGH
ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass
GHSA-mwp4-54f8-5fhr
pkg: ip-address
eco: npm
published: Aug 3, 2026
### Summary
`Address4` accepts an octet written with a leading zero and decodes it as decimal, while the WHATWG URL host parser, `inet_aton`, and `getaddrinfo` all decode a leading zero as octal. The library and the network stack therefore disagree about which host a string names. `new Address4('01…
CVE-2026-69192
GitHub-GHSA
HIGH
Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes
GHSA-jj27-h5hq-8×99
pkg: @angular/compiler, @angular/compiler, @angular/compiler
eco: npm
published: Aug 3, 2026
A Cross-Site Scripting (XSS) vulnerability has been identified in the Angular compiler's internationalization (i18n) pipeline. Although Angular disallows binding to event-handler attributes such as `onclick` and `onerror` through standard attribute validation (`validateAttribute()` / `validateProper…
CVE-2026-69151
NVD
MEDIUM
CVE-2026-71313
rclone is a command-line program to sync files and directories to and from different cloud storage providers. From v1.51.0 until v1.75.0, the local backend in backend/local/local.go relies on the configurable filename encoder to prevent remote filename data from becoming operating-system path syntax…
CWE: CWE-22
GitHub-GHSA
MEDIUM
rclone: Local Encoding Path Traversal
GHSA-7p4m-qxvv-g567
pkg: github.com/rclone/rclone
eco: go
published: Aug 5, 2026
## Summary
The local backend relies on its configurable filename encoder to prevent remote filename data from becoming operating-system path syntax. If a local destination uses an encoding that omits `Dot`, such as `Slash`, `None`, or `Raw`, a remote object's standard-encoded `..` component is …
CVE-2026-71313
NVD
MEDIUM
CVE-2026-70611
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.1, and 42.0.0-beta.3, the DevTools reveal in file manager action could launch the target file rather than reveal it. An attacker with a separate means of running scri…
CWE: CWE-78
GitHub-GHSA
MEDIUM
Electron: DevTools embedder handler executes arbitrary files via shell open
GHSA-f2r8-jv7c-xqmp
pkg: electron, electron, electron
eco: npm
published: Aug 5, 2026
### Impact
The DevTools "reveal in file manager" action could launch the target file rather than reveal it. An attacker with a separate means of running script inside the DevTools frontend (such as a malicious DevTools extension) could use this to execute native code outside the sandbox.
Apps are o…
CVE-2026-70611
NVD
MEDIUM
CVE-2026-19017
Consul Community Edition and Consul Enterprise 1.18.21 through 2.0.2 are vulnerable to a partial arbitrary file read when configured to use the Vault Connect CA provider with JWT or AppRole authentication. A privileged attacker with `operator:write` permission may direct Consul to read and forward c…
CWE: CWE-862
GitHub-GHSA
MEDIUM
AWS CLI: Disabled SSH host key verification in Amazon AWS CLI EMR helper commands
GHSA-hqvf-45jj-mccq
pkg: awscli
eco: pip
published: Aug 6, 2026
### Summary
The AWS Command Line Interface (AWS CLI) is a unified tool to manage AWS services from the command line. An issue exists where the EMR SSH helper commands (`aws emr ssh`, `aws emr socks`, `aws emr put`, `aws emr get`) passed `StrictHostKeyChecking=no` to the underlying SSH client, disabl…
CVE-2026-18654
NVD
MEDIUM
CVE-2026-70594
Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions on login which could have allowed for session fixation attacks. Successful exploitation would have required another vulnerability on the same domain where Ghost Admin was hosted. T…
CWE: CWE-384
GitHub-GHSA
MEDIUM
Ghost: Session Fixation in Ghost Admin
GHSA-7mpp-r37j-x5wh
pkg: ghost
eco: npm
published: Aug 4, 2026
### Impact
Ghost Admin did not invalidate existing sessions on login which could have allowed for session fixation attacks. Successful exploitation would have required another vulnerability on the same domain where Ghost Admin was hosted.
### Vulnerable versions
This vulnerability is present in G…
CVE-2026-70594
NVD
MEDIUM
CVE-2026-70602
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, extension tab and scripting APIs were not scoped to the extension's own session. A malicious or compromised extension loaded into one session co…
CWE: CWE-284
GitHub-GHSA
MEDIUM
Electron: Extension tab APIs operate across session boundaries
GHSA-m55f-7gqj-fr98
pkg: electron, electron, electron
eco: npm
published: Aug 5, 2026
### Impact
Extension tab and scripting APIs were not scoped to the extension's own `session`. A malicious or compromised extension loaded into one session could navigate, script, and read from windows belonging to a different session.
Apps are only affected if they load Chrome extensions via `sessi…
CVE-2026-70602
NVD
MEDIUM
CVE-2026-70593
Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a vulnerability in custom themes allowed a staff user to write files outside of the uploads directory. This could be used to alter the behavior of the installation through custom theme upload path traversal in LocalStorageBase a…
CWE: CWE-22
GitHub-GHSA
MEDIUM
Ghost: Theme Upload Path Traversal
GHSA-cjc9-q5gf-327p
pkg: ghost
eco: npm
published: Aug 4, 2026
### Impact
A vulnerability in custom themes allowed a staff user to write files outside of the uploads directory. This could be used to alter the behavior of the installation.
### Vulnerable versions
This vulnerability is present in Ghost from v0.10.0 up to v6.54.0.
### Patches
v6.54.1 contains…
CVE-2026-70593
NVD
MEDIUM
CVE-2026-47619
NVIDIA Dynamo for Linux examples and recipes contain a vulnerability where an attacker could cause a system failure. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.
CWE: CWE-1357
GitHub-GHSA
MEDIUM
Netty: RedisArrayAggregator max-elements failure leaves retained partial aggregate state
GHSA-p9jm-q85p-7mcp
pkg: io.netty:netty-codec-redis, io.netty:netty-codec-redis
eco: maven
published: Aug 7, 2026
## Summary
`RedisArrayAggregator` clears retained partial aggregate state when the `maxNestedArrayDepth` limit is exceeded, but it does not clear the same state when the sibling `maxElements` limit is exceeded. A peer can start a valid RESP array, send a bulk-string child, then send a nested array …
CVE-2026-56818
GitHub-GHSA
MEDIUM
GitPython: Arbitrary file read via –pathspec-from-file in IndexFile.remove() and Head.checkout()
GHSA-hh9p-6wh2-4mfc
pkg: GitPython
eco: pip
published: Aug 7, 2026
## Summary
`IndexFile.remove()` and `Head.checkout()` forward `**kwargs` into `git rm` and `git checkout`
with no guard. Passing `–pathspec-from-file=<file>` **together with `–pathspec-file-nul`**
makes Git treat the whole file as a single NUL-delimited pathspec, and the unmatched-pathspec
error …
NVD
MEDIUM
CVE-2026-14204
The Google Authenticator WordPress plugin before 0.56 does not verify a CSRF nonce when saving its two-factor setup, allowing attackers to trick a logged-in user into overwriting their own 2FA secret with an attacker-controlled value, which enables two-factor authentication and locks the victim out …
CWE: CWE-352
GitHub-GHSA
MEDIUM
rclone: Path traversal in serve s3 allows reading and overwriting root-level files
GHSA-8v25-v8p6-qf7v
pkg: github.com/rclone/rclone
eco: go
published: Aug 5, 2026
### Summary
rclone serve s3 allows a client to read and write files at the root of the remote which would normally be inaccessible by using dot-dot path segments in the object key. It does not allow reading files outside of the root. A request such as GET /bucket/../root-secret.txt is handled as an…
NVD
MEDIUM
CVE-2026-70616
boringproxy through 0.10.0 contains a resource exhaustion vulnerability that allows any authenticated user to permanently exhaust server file descriptors, goroutines, and memory by sending requests to the GET /loading endpoint with attacker-supplied id query parameter values. Because the handler per…
CWE: CWE-833
NVD
MEDIUM
CVE-2026-7658
IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate the username field, allowing attackers to inject path traversal sequences and bypass containment checks. This enables multiple severe impacts, including arbitrary directory deletion, cross-tenant data destruction, and JWT signing key d…
CWE: CWE-22
NVD
MEDIUM
CVE-2026-7646
IBM Langflow OSS 1.0.0 through 1.10.3 allows users to read arbitrary files from the server filesystem, including other users' uploaded documents, the JWT signing secret, the SQLite database, and process environment variables, by sending a crafted MCP `resources/read` request with a URL-encoded path …
CWE: CWE-22
NVD
MEDIUM
CVE-2026-71244
Paperless-ngx's MailAccountViewSet.test() action, when called with an existing account's ID and a masked password field, reuses the stored password, account_type, refresh_token, and expiration from that existing account while allowing the caller to supply a different imap_server, imap_port, and imap…
CWE: CWE-918
NVD
MEDIUM
CVE-2026-71208
KubeSphere's cluster-controller reconciliation (pkg/utils/clusterclient/clusterclient.go, addCluster) processes every Cluster custom resource's connection configuration and immediately calls Discovery().ServerVersion() against the CRD-specified Kubernetes API endpoint, which is parsed only for URL s…
CWE: CWE-918
NVD
MEDIUM
CVE-2026-68080
It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.
This issue affects Apache Qpid Broker-J: through 10.0.1.
Users are recommended to upgrade to version 10.1.…
CWE: CWE-406
NVD
MEDIUM
CVE-2026-68078
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.
This issue affects Apache Qpid Broker-J: through 10.0.1.
Users are recommended to upgrade to version 10.1…
CWE: CWE-770
NVD
MEDIUM
CVE-2026-67555
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service
This issue affects Apache Qpid Proton-Dotnet: through 1.0.0.
Users are recommended to upgrade to version 1…
CWE: CWE-770
NVD
MEDIUM
CVE-2026-66277
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.
This issue affects Apache Qpid Proton-J: through 0.34.1.
Users are recommended to upgrade to version 0.35…
CWE: CWE-770
NVD
MEDIUM
CVE-2026-70493
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the built-in knowledge search path in backend/open_webui/tools/knowledge_fs.py and backend/open_webui/tools/builtin.py let a chat participant choose a pattern used to grep knowledge files. …
CWE: CWE-1333
NVD
MEDIUM
CVE-2026-70491
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. In 0.10.2 and earlier, the GET /api/v1/tools/, GET /api/v1/tools/list, and GET /api/v1/tools/id/{id} endpoints in backend/open_webui/routers/tools.py returned full Python tool source to authenticated non-admin read…
CWE: CWE-200
GitHub-GHSA
MEDIUM
Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically
GHSA-2f54-p244-32q6
pkg: open-webui
eco: pip
published: Aug 4, 2026
## Summary
The built-in knowledge search tools let a chat participant choose the pattern used to grep knowledge files. Patterns containing regex metacharacters were compiled with Python's backtracking `re` engine and run against every line of every reachable file, with no time limit anywhere on that…
CVE-2026-70493
GitHub-GHSA
MEDIUM
Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints
GHSA-3r7g-q6cg-q2vx
pkg: open-webui
eco: pip
published: Aug 4, 2026
## Summary
A workspace tool shared with a read grant returned its full Python source to the recipient. Any authenticated non-admin who could use a shared tool could also read its source, including any user on the instance when a tool was shared publicly. Source is meant to be a writer-only tier: th…
CVE-2026-70491
GitHub-GHSA
MEDIUM
Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing
GHSA-73cq-mcgh-379c
pkg: open-webui
eco: pip
published: Aug 4, 2026
## Summary
In every affected release, automation recurrence parsing anchors minutely and hourly rules at a fixed date of 2000-01-01 and then walks forward one interval at a time to find the next run. A single `FREQ=MINUTELY` rule therefore enumerates roughly a quarter-century of occurrences, synchro…
CVE-2026-70489
NVD
MEDIUM
CVE-2026-47621
NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager singleton initialization. A successful exploit of this vulnerability might lead to denial of service and data tampering.
CWE: CWE-367
NVD
MEDIUM
CVE-2026-47620
NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager singleton initialization. A successful exploit of this vulnerability might lead to data tampering and denial of service.
CWE: CWE-362
GitHub-GHSA
MEDIUM
Flowise: Incomplete Credential Redaction Exposes Secrets via API
GHSA-rwrp-9823-p2xq
pkg: flowise
eco: npm
published: Aug 4, 2026
## Summary
The `GET /api/v1/credentials/:id` endpoint decrypts stored credential data and returns it in the `plainDataObj` field of the API response. While a `redactCredentialWithPasswordType()` function masks fields defined with `type: 'password'` in their component schema, many credential types s…
NVD
MEDIUM
CVE-2026-67199
Perspective 5.0.0 contains a denial of service vulnerability that allows remote attackers to block the server event loop indefinitely by submitting a crafted expression containing unbounded for or while loop constructs in a TableMakeViewReq message. Attackers can embed an arbitrarily large iteration…
CWE: CWE-770
NVD
MEDIUM
CVE-2026-63248
In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An anonymous client can enable diagnostics over a None/None endpoint without a certificate; with a trusted client application certificate over SignAndEncrypt, it can read security diagn…
CWE: CWE-862
NVD
MEDIUM
CVE-2026-69245
Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of a cookie Domain that cookie unless SetCookie::matchesDomain() recognizes the Domain as an IP literal or a numeric host, and the decision comes from the domain's own text, so two sp…
CWE: CWE-180, CWE-346, CWE-384
NVD
MEDIUM
CVE-2026-18655
Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before 2.0.24 may allow a remote unauthenticated actor (via prompt injection) to obtain Amazon MQ for RabbitMQ broker credentials or OAuth access tokens sent …
CWE: CWE-923
GitHub-GHSA
MEDIUM
GitPython: Incomplete unsafe_git_archive_options denylist omits –add-file / –add-virtual-file, enabling arbitrary file read via Repo.archive()
GHSA-539m-9xh6-q6rr
pkg: GitPython
eco: pip
published: Aug 3, 2026
**Target:** gitpython-developers/GitPython
**Tested:** HEAD `07e80555` (2026-07-25), latest release 3.1.55, `git version 2.50.1`
## Summary
`Repo.archive()` does call the option guard, so this is not a missing-guard report. The guard is present and working; the **denylist it consults is incomplete…
GitHub-GHSA
MEDIUM
Russh: Channel-scoped server callbacks can be reached without an open channel
GHSA-m65r-rprj-r5rg
pkg: russh
eco: rust
published: Aug 3, 2026
There is a server-side channel state issue in `russh`.
After a client is authenticated, `russh` can dispatch channel-scoped handler callbacks for recipient channel IDs that were never opened or confirmed. In the strongest reproduced case, the client does not send `SSH_MSG_CHANNEL_OPEN` at all. It a…
CVE-2026-68930
NVD
MEDIUM
CVE-2026-69087
The Grav form plugin (getgrav/grav-plugin-form) before 9.1.13 contains an open redirect vulnerability. Since v9.1.11, the redirect process action evaluates user-supplied form data inside Twig expressions, and Grav::redirect() accepts external URLs without origin validation. When a form blueprint def…
CWE: CWE-601
GitHub-GHSA
MEDIUM
rclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Preserves Newlines
GHSA-8c48-q9wj-3w37
pkg: github.com/rclone/rclone
eco: go
published: Aug 5, 2026
## 1. Summary
A valid but nondefault FTP filename encoding can restore raw CR/LF immediately before an attacker-controlled path is interpolated into the line-oriented FTP control channel. The dependency does not reject CR or LF in command arguments, so a filename can inject an independent authentic…
CVE-2026-71311
NVD
MEDIUM
CVE-2026-19243
A security vulnerability has been detected in HKUDS nanobot up to 0.2.1. Impacted is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component Shell Allowlist Handler. Such manipulation leads to os command injection. The attack can be executed rem…
CWE: CWE-77, CWE-78
NVD
MEDIUM
CVE-2026-47363
In versions of the Datadog Android application prior to v541-5.9.2, the exported launcher activity AppActivity accepts an attacker-supplied session (including OAuth tokens) from Intent extras with no permission guard, and signs the app into that session without validating it against the backend.
Th…
CWE: CWE-926
GitHub-GHSA
MEDIUM
go-git: Malicious reference names may modify files outside the reference storage
GHSA-qgq7-7hm3-q39j
pkg: github.com/go-git/go-git/v5, github.com/go-git/go-git/v6
eco: go
published: Aug 7, 2026
### Impact
A path traversal issue in `go-git` could allow malicious reference names to access files outside the repository's intended reference storage.
Loose references are stored under `.git/<reference-name>`. The reference name was previously used as a path without verifying that the resolved pa…
CVE-2026-71557
NVD
MEDIUM
CVE-2026-19022
A vulnerability was determined in OpenHands up to 0.62.0. The affected element is the function initialize_repo of the file OpenHands/resolver/send_pull_request.py. This manipulation causes command injection. Remote exploitation of the attack is possible. The vendor deleted the original GitHub issue …
CWE: CWE-74, CWE-77
NVD
MEDIUM
CVE-2026-70597
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, the check Electron uses on macOS to confirm it was launched by a same-signed parent process could be bypassed by a local process. Apps that enab…
CWE: CWE-367
GitHub-GHSA
MEDIUM
Electron: Parent process code-sign check is spoofable
GHSA-jm7p-cc5g-qwxx
pkg: electron, electron, electron
eco: npm
published: Aug 5, 2026
### Impact
On macOS, the check Electron uses to confirm it was launched by a same-signed parent process could be bypassed by a local process. Apps that enable the fuse-based hardening restricting `ELECTRON_RUN_AS_NODE` and `NODE_OPTIONS` to same-signed parents rely on this check; a local attacker co…
CVE-2026-70597
NVD
MEDIUM
CVE-2026-70490
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, the terminal WebSocket route in backend/open_webui/routers/terminals.py authenticated its own first-message JWT and never applied the verified-user role gate that get_verified_user enforces…
CWE: CWE-863
NVD
MEDIUM
CVE-2026-54020
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.11.0, Open WebUI resolved a hostname during URL validation and rejected private, loopback, and link-local addresses, but the HTTP clients resolved the hostname again at connection time. An authenticated …
CWE: CWE-367, CWE-918
GitHub-GHSA
MEDIUM
Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check
GHSA-5gpj-vj23-vhhv
pkg: open-webui
eco: pip
published: Aug 4, 2026
## Summary
The terminal WebSocket route authenticates its own first-message JWT instead of going through the HTTP dependency chain, and never applies the role check that `get_verified_user` enforces on every HTTP terminal route. An account whose role is `pending`, meaning registered but not approved…
CVE-2026-70490
GitHub-GHSA
MEDIUM
Open WebUI: DNS Rebinding SSRF Bypass
GHSA-h6x2-583h-x99r
pkg: open-webui
eco: pip
published: Aug 4, 2026
## Summary
Open WebUI vetted user-supplied URLs by resolving the hostname once and rejecting private, loopback and link-local addresses, then let the HTTP client resolve that hostname again at connect time. An attacker who controls the authoritative DNS for a hostname they submit can answer with a p…
CVE-2026-54020
NVD
MEDIUM
CVE-2026-71430
node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.25.1, the WrappedRE2::Replace function built its replacement result and passed it to V8 using ToLocalChecked without checking for the empty MaybeLocal that V8 returns when the resulting string or buffer exceeds V8's ma…
CWE: CWE-617
GitHub-GHSA
MEDIUM
node-re2: String.prototype.replace(re2, template) aborts the Node process (uncatchable ToLocalChecked on empty MaybeLocal) when the result exceeds V8's max string length
GHSA-8hcv-x26h-mcgp
pkg: re2
eco: npm
published: Aug 6, 2026
## Description
`WrappedRE2::Replace` builds the replacement result and hands it to V8 with `.ToLocalChecked()` **without checking for the empty `MaybeLocal`** that V8 returns when the string/buffer exceeds its maximum length:
`lib/replace.cc` (v1.24.1):
“`cpp
// L553 — Buffer return path
info.G…
CVE-2026-71430
NVD
MEDIUM
CVE-2026-58045
A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion in the synchronous `node:zlib` APIs, causing the entire process to crash. All 11 synchronous zlib functions are affected.
Repeated exploitation of this condition can result in a denial of service.
Thi…
CWE: CWE-400
NVD
MEDIUM
CVE-2026-71286
The render-template component of ember-dynamic-render-template (addon/components/render-template.js) passes its `templateString` property directly into Ember/Glimmer's compileTemplate() (from @ember/template-compilation) with no sanitization, allow-listing, or validation of the input. Because compil…
CWE: CWE-1336
NVD
MEDIUM
CVE-2026-16792
An improper certificate validation vulnerability was reported in multiple Lenovo XClarity Orchestrator (LXCO) 2.2.0 microservices that could allow an adjacent network attacker to intercept sensitive communications by performing a machine-in-the-middle attack against HTTPS connections during TLS cert…
CWE: CWE-295
GitHub-GHSA
MEDIUM
Electron: shell.openPath path validation bypass via embedded null byte
GHSA-5c9j-mhmv-5xgx
pkg: electron, electron, electron
eco: npm
published: Aug 5, 2026
### Impact
`shell.openPath()` did not reject paths containing embedded null bytes. Apps that perform string-only validation of file paths (for example, checking the file extension) before passing them to `shell.openPath()` could be bypassed, allowing an attacker-controlled path to open a different f…
CVE-2026-70603
GitHub-GHSA
MEDIUM
rclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone Memory
GHSA-xhf4-832v-7xcr
pkg: github.com/rclone/rclone
eco: go
published: Aug 5, 2026
## 1. Summary
The shared HTTP CONNECT helper parses a proxy response with `http.ReadResponse` over an unrestricted buffered reader. The production helper accepted a valid response containing a 2 MiB header in three consecutive runs. A malicious or compromised configured proxy, or an active on-path …
CVE-2026-71310
GitHub-GHSA
MEDIUM
Electron: ProtocolResponse.url reuses the default session cache instead of the registering session
GHSA-r4w5-6pfg-jxp5
pkg: electron, electron, electron
eco: npm
published: Aug 5, 2026
### Impact
When a custom protocol handler returned a `ProtocolResponse` with a `url` and no `session`, Electron made the upstream request through `defaultSession` instead of the session that handled the protocol. A cached response could then be reused across otherwise isolated session partitions.
A…
CVE-2026-70606
GitHub-GHSA
MEDIUM
Electron: HTTP redirect followed into local file loader
GHSA-v64r-4m7r-3mvq
pkg: electron, electron, electron
eco: npm
published: Aug 5, 2026
### Impact
When following HTTP redirects, `net.fetch()` and `net.request()` did not restrict which schemes a redirect could target. A remote server could redirect a request to a local resource, and if the app returns or forwards the response body, local file contents could be disclosed.
Apps are on…
CVE-2026-70605
GitHub-GHSA
MEDIUM
Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin
GHSA-9pf5-hg6p-4pwp
pkg: electron, electron, electron
eco: npm
published: Aug 5, 2026
### Impact
For serial-port and media (camera / microphone) permission checks made from an iframe, the `requestingOrigin` passed to `session.setPermissionCheckHandler` was the top-level frame's origin rather than the requesting frame's. Origin-based handler logic could therefore grant a cross-origin …
CVE-2026-70599
NVD
MEDIUM
CVE-2026-48154
GoRest is a Golang starter kit built with the Gin framework for prototyping and developing RESTful APIs. In versions prior to 1.12.2 nMemorySecret2FA contains a race condition due to an unsynchronized package-level map used to store 2FA secrets. Multiple HTTP handlers in handler/login.go and handler…
CWE: CWE-362
NVD
MEDIUM
CVE-2026-58042
A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process When a DNS Response Contains More Than 256 A Records.
Repeated triggering of this condition can lead to denial of service.
This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.
CWE: CWE-400
GitHub-GHSA
MEDIUM
undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives
GHSA-jr45-8vmc-qm54
pkg: undici, undici
eco: npm
published: Aug 3, 2026
## Impact
Undici's cache interceptor mishandles optional whitespace (OWS) placed around the `=` of a qualified `no-cache` or `private` Cache-Control directive, such as `no-cache ="authorization"` (OWS before `=`) or `no-cache= "authorization"` (OWS after `=`). The parser either drops the directive …
CVE-2026-14643
GitHub-GHSA
MEDIUM
Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false
GHSA-3q9r-p662-5j8m
pkg: github.com/traefik/traefik/v2, github.com/traefik/traefik/v3, github.com/traefik/traefik/v3
eco: go
published: Aug 6, 2026
## Summary
There is a medium severity vulnerability in Traefik's ForwardAuth middleware. Even when configured with `trustForwardHeader: false`, Traefik derives the `X-Forwarded-Port` header sent to the authentication service from the original incoming request instead of the sanitized forwarded requ…
CVE-2026-54764
GitHub-GHSA
MEDIUM
Ghost: Private IP filtering bypass to make server-side requests to internal services
GHSA-wvp2-4qqp-4h3r
pkg: ghost
eco: npm
published: Aug 4, 2026
### Impact
When making an external request, it is possible to bypass the IP filter that ensures the request isn't going to an internal service using an IPv6 literal which maps to a private IPv4 address.
### Vulnerable versions
This vulnerability is present in Ghost from v6.0.9 up to v6.21.0.
###…
CVE-2026-53944
NVD
MEDIUM
CVE-2026-70609
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1, the mode option of webContents.openDevTools() was not sanitized before use by the DevTools frontend. If an attacker can influence this value, sc…
CWE: CWE-94, CWE-116
GitHub-GHSA
MEDIUM
Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter
GHSA-4f78-qhmw-8j8m
pkg: electron, electron, electron
eco: npm
published: Aug 5, 2026
### Impact
The `mode` option of `webContents.openDevTools()` was not sanitized before use by the DevTools frontend. If an attacker can influence this value, script under their control may run in the DevTools context, which in unsandboxed configurations has access to Node.js.
Apps are only affected …
CVE-2026-70609
NVD
MEDIUM
CVE-2026-70592
Ghost is a Node.js content management system. From 1.20.1 until 6.54.1, an Administrator-level user could remotely overwrite certain files on the filesystem through the database backup filename, leading to integrity and availability issues. The database export endpoint failed to reject path separato…
CWE: CWE-22
GitHub-GHSA
MEDIUM
Ghost: Database Backup Path Traversal
GHSA-cj62-hvv2-2q5h
pkg: ghost
eco: npm
published: Aug 4, 2026
### Impact
An Administrator-level user could remotely overwrite certain files on the filesystem leading to integrity and availability issues.
### Vulnerable versions
This vulnerability is present in Ghost from 1.20.1 up to v6.54.0.
### Patches
v6.54.1 contains a fix for this issue.
### How to …
CVE-2026-70592
GitHub-GHSA
MEDIUM
Electron: Sandboxed iframes can launch external protocol handlers
GHSA-p2rr-rvmm-c5fp
pkg: electron, electron, electron
eco: npm
published: Aug 5, 2026
### Impact
Requests to open external protocol URLs from web content did not take iframe sandbox restrictions into account, so a sandboxed iframe could cause an OS-registered external application to be launched. The frame's sandbox state was also not made available to the app's permission handlers.
…
CVE-2026-70612
GitHub-GHSA
MEDIUM
Electron: contextBridge object copy honors prototype setters
GHSA-ff2p-hmqr-hxm4
pkg: electron, electron, electron
eco: npm
published: Aug 5, 2026
### Impact
Objects copied across the `contextBridge` boundary from untrusted content could carry an attacker-influenced prototype, enabling prototype-pollution-style attacks against preload code despite context isolation being enabled.
Apps are only affected if their preload code accepts object arg…
CVE-2026-70610
GitHub-GHSA
MEDIUM
Ghost: Mobiledoc image-size fetch SSRF
GHSA-g366-23fw-ggp6
pkg: ghost
eco: npm
published: Aug 4, 2026
### Impact
When re-rendering posts, Ghost would refetch missing image dimensions by issuing an outbound HTTP request to the URL stored on an image card — without restricting that URL to trusted image hosts. An authenticated staff user able to create or edit posts could therefore point an image ca…
CVE-2026-53946
GitHub-GHSA
MEDIUM
Ghost: File Upload Content-Type Spoofing
GHSA-944x-pm95-3jpr
pkg: ghost
eco: npm
published: Aug 4, 2026
### Impact
Insufficient validation of the client-supplied `Content-Type` on Ghost's Admin API file upload endpoint allowed uploaded files to be served from the site with an attacker-chosen content type on S3/GCS storage backends. On installations that serve uploaded files from the same origin as th…
CVE-2026-53948
GitHub-GHSA
MEDIUM
Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages
GHSA-mj5r-jf49-m3w7
pkg: open-webui
eco: pip
published: Aug 4, 2026
## Summary
On standard channels, the message update and delete handlers accepted any caller holding write access on the channel, without checking that the caller wrote the message. Write access is the same grant a member needs in order to post, so every ordinary participant in a shared channel could…
CVE-2026-70481
GitHub-GHSA
MEDIUM
GitPython: Arbitrary file truncation via git rev-list –output argument injection in unguarded Commit.count
GHSA-p538-c434-8v24
pkg: GitPython
eco: pip
published: Aug 3, 2026
## Summary
`Commit.count()` forwards `**kwargs` into `rev_list` with **no** `check_unsafe_options` guard (the guard exists only in the sibling `iter_items`, commit.py:341). `git rev-list –output=<path>` opens and truncates the target file to 0 bytes before revision parsing, so `count(output='/victi…
NVD
MEDIUM
CVE-2026-19369
A vulnerability was found in KS-GEN-AI jira-mcp-server 0.2.0. This affects the function axios.get of the file src/index.ts of the component add_attachment_from_public_url. The manipulation of the argument imageUrl results in server-side request forgery. The attack requires a local approach. The proj…
CWE: CWE-918
NVD
MEDIUM
CVE-2026-19363
A vulnerability was found in lmammino oidc-authorizer up to 0.4.0. Impacted is the function unwrap of the file src/handler.rs of the component Fixed Message Handler. The manipulation of the argument jwtClaims results in deserialization. The attack can be executed remotely. The exploit has been made …
CWE: CWE-20, CWE-502
NVD
MEDIUM
CVE-2026-19323
A security flaw has been discovered in azer react-analyzer-mcp up to 335f2a3585f265e2e88352b59b10d3b478d678b0. Affected by this vulnerability is the function generateProjectDocs of the file src/index.ts of the component analyze-projec. The manipulation of the argument projectName results in path tra…
CWE: CWE-22
NVD
MEDIUM
CVE-2026-69207
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.34, the built-in CORS middleware, hono/cors, is vulnerable to a regular expression denial of service (ReDoS). During a preflight OPTIONS request, the middleware parses the attacker-controlled Access-C…
CWE: CWE-1333
GitHub-GHSA
MEDIUM
Hono: Algorithmic Complexity DoS in Language Middleware
GHSA-54fx-42gc-7vw4
pkg: hono
eco: npm
published: Aug 7, 2026
### Summary
The `languageDetector` middleware is vulnerable to algorithmic complexity denial of service when processing a crafted language tag containing a large number of hyphen-separated subtags.
### Details
To implement progressive language-tag truncation, `normalizeLanguage()` repeatedly call…
CVE-2026-71848
NVD
MEDIUM
CVE-2026-66062
SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.70.2, the content negotiation header parser used by SvelteKit's request handling (for headers such as Accept) uses a regular expression vulnerable to quadratic backtracking, so a maliciously …
CWE: CWE-1333
GitHub-GHSA
MEDIUM
SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept header
GHSA-29g2-3rmr-qm68
pkg: @sveltejs/kit
eco: npm
published: Aug 7, 2026
### Impact
SvelteKit is vulnerable to remote CPU-exhaustion DoS attacks via specifically-crafted `Accept` headers. The impact is mitigated by default header length limits on most platforms, but in the case of raised or absent limits a denial of service is possible.
### Patches
The vulnerability is …
CVE-2026-66062
NVD
MEDIUM
CVE-2026-49006
By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to TLS transmission.
CWE: CWE-321
NVD
MEDIUM
CVE-2026-61632
PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. In versions up to and including 10.21.3, the b64 extension is vulnerable to a path traversal that discloses arbitrary files: it inlines images referenced by <img src="…"> by joining the src onto the configured base…
CWE: CWE-22
NVD
MEDIUM
CVE-2026-19146
Uninitialized Use in GPU in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-457
GitHub-GHSA
MEDIUM
h2: Duplicate Host header could facilitate request smuggling
GHSA-6hr6-w5qg-qmwg
pkg: h2
eco: pip
published: Aug 6, 2026
### Impact
h2 <=4.4.0 accepts request header blocks containing more than one Host header, and forwards every Host header to the consuming application. Where the consumer downgrades HTTP/2 to HTTP/1.1, the resulting request carries two Host header lines, which is a request smuggling primitive (CWE-44…
CVE-2026-71554
GitHub-GHSA
MEDIUM
LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores
GHSA-47pj-3jcm-6whg
pkg: langgraph-checkpoint-postgres, langgraph-checkpoint-sqlite
eco: pip
published: Aug 6, 2026
## Summary
The Postgres and SQLite stores persist hierarchical namespaces as a dot-joined string (`("memories", "alice")` becomes `memories.alice`) and scoped reads by matching that string with `LIKE '<path>%'`. Because `LIKE` has no notion of the `.` separator, a scoped `search` or `list_namespace…
CVE-2026-71433
NVD
MEDIUM
CVE-2026-19044
A flaw has been found in LeeSinLiang godot-mcp 0.1.0. Affected by this vulnerability is the function executeOperation of the file src/index.ts of the component create_scene/add_node. This manipulation of the argument projectPath causes command injection. The attack needs to be launched locally. The …
CWE: CWE-74, CWE-77
GitHub-GHSA
MEDIUM
rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect
GHSA-h4mf-4v27-hggj
pkg: github.com/rclone/rclone
eco: go
published: Aug 5, 2026
## 1. Summary
WebDAV's default redirect handling can replay Basic authorization and configured Cookie headers over plaintext HTTP after a same-host HTTPS-to-HTTP redirect. This was reproduced through the real backend. Unlike the low-impact STS token in rclone's published S3 redirect advisory, Basic…
GitHub-GHSA
MEDIUM
rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys
GHSA-8mxv-9xhp-86h4
pkg: github.com/rclone/rclone
eco: go
published: Aug 5, 2026
## 1. Summary
The S3 redirect callback strips `X-Amz-Security-Token` when a redirect changes scheme or host, but it does not strip IBM IAM bearer authorization or customer-provided encryption keys. Two independently validated paths remain:
– a same-host HTTPS-to-HTTP redirect preserves `Authorizat…
GitHub-GHSA
MEDIUM
rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic
GHSA-3x6r-wxxg-53vv
pkg: github.com/rclone/rclone
eco: go
published: Aug 5, 2026
## 1. Summary
A transport failure during the initial Infinite Scale TUS creation POST can return `(nil response, non-nil error)`. Rclone dereferences the nil response before processing the error and panics. The production `CreateUploader` path reproduced the crash against a closed endpoint.
The se…
GitHub-GHSA
MEDIUM
Electron: window.open features string controls some window options considered privileged
GHSA-v93f-fgjr-hjrj
pkg: electron, electron, electron
eco: npm
published: Aug 5, 2026
### Impact
Some window options supplied by web content in the `window.open()` features string were applied to the new `BrowserWindow` without an allowlist. Untrusted content could set window options it should not control, including options that cause the main process to access attacker-chosen file o…
CVE-2026-70607
GitHub-GHSA
MEDIUM
Ghost Content API filter bypass reveals private fields
GHSA-jx35-x7fj-vgpr
pkg: ghost
eco: npm
published: Aug 5, 2026
### Impact
The validation applied to filters on the public API endpoints could be partially bypassed, making it possible to reveal private fields via a brute force attack. If SQLite was used as the database password hashes were fully accessible. If MySQL was used as the database the password hashes…
CVE-2026-53949
GitHub-GHSA
MEDIUM
Ghost: Paid gift memberships obtainable at minimal cost via the donations feature
GHSA-xm43-3m56-w3wf
pkg: ghost
eco: npm
published: Aug 4, 2026
### Impact
A vulnerability in Ghost's public donation checkout flow allowed an unauthenticated attacker to obtain full paid gift memberships for a minimal payment. No customer or member data was exposed, and the issue could not be used to steal money from a site or its members.
### Vulnerable vers…
CVE-2026-59817
GitHub-GHSA
MEDIUM
Ghost: Member existence leak via magic link sign-in response
GHSA-chgm-3698-jm42
pkg: ghost
eco: npm
published: Aug 4, 2026
### Impact
A discrepancy in responses from the members signin endpoints made it possible for an unauthenticated attacker to determine whether a given email address belongs to a registered member of a Ghost site.
### Vulnerable versions
This vulnerability is present in Ghost from v5.18.0 up to v6.…
CVE-2026-53947
GitHub-GHSA
MEDIUM
Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadata
GHSA-6xhv-rxhv-pwm4
pkg: open-webui
eco: pip
published: Aug 4, 2026
## Summary
Open WebUI lets a client define a model inline on a chat request instead of selecting a saved workspace model. The knowledge attached to such an inline model was used as-is, without checking that the caller can read what it points at. Any authenticated user who knows another user's file i…
CVE-2026-70487
NVD
MEDIUM
CVE-2026-47622
NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause the generation of error messages that contain sensitive information. A successful exploit of this vulnerability might lead to information disclosure.
CWE: CWE-209
NVD
MEDIUM
CVE-2026-16536
The Simple Google Calendar Outlook Events Widget WordPress plugin before 3.1.0 does not validate a user-supplied URL before performing a server-side request, allowing unauthenticated attackers to perform Server-Side Request Forgery attacks and, in some cases, read the response of the internal reques…
CWE: CWE-918
NVD
MEDIUM
CVE-2026-58041
A flaw in Node.js node:sqlite allows a stale StatementSyncIterator created through DatabaseSync#createTagStore() to continue executing a cached prepared statement after it has been reset and rebound with new parameters. SQLTagStore resets cached statements using sqlite3_reset() directly, bypassing t…
CWE: CWE-367
NVD
MEDIUM
CVE-2026-18648
A vulnerability was detected in Blix Email Blue Mail Calendar App 2.2.305. Impacted is the function FileDirectory.getDataColumn/FileDirectory.getFileFromUri of the component react-native-receive-sharing-intent. The manipulation of the argument _display_name results in path traversal. The attack is o…
CWE: CWE-22
GitHub-GHSA
MEDIUM
Hono: ReDoS in CORS middleware via Access-Control-Request-Headers
GHSA-8j4g-w8fx-2239
pkg: hono
eco: npm
published: Aug 3, 2026
### Summary
The built-in CORS middleware (`hono/cors`) parses the attacker-controlled `Access-Control-Request-Headers` request header during a preflight (`OPTIONS`) request using a regular expression whose running time is quadratic in the input length. A single request carrying a long run of whites…
CVE-2026-69207
NVD
MEDIUM
CVE-2026-71498
node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.26.1, passing a Buffer whose final bytes form a truncated (incomplete) multi-byte UTF-8 sequence could cause the native binding to read past the end of the allocated buffer while attempting to decode the final, incompl…
CWE: CWE-125
GitHub-GHSA
MEDIUM
node-re2: Out-of-bounds heap read in `replace`/`split` via a `Buffer` ending in a truncated multi-byte UTF-8 character → adjacent heap memory disclosed to JavaScript
GHSA-j4r3-hg7j-8chg
pkg: re2
eco: npm
published: Aug 6, 2026
## Summary
`re2` infers a character's byte length from its UTF-8 lead byte alone, with no bound on the
bytes actually remaining in the input. `Buffer` arguments reach the native layer verbatim —
only strings are re-encoded into well-formed UTF-8 — so a `Buffer` whose last byte is a
multi-byte l…
CVE-2026-71498
GitHub-GHSA
MEDIUM
rclone archive extract allows S3 destination prefix escape via crafted archive paths
GHSA-4vr5-p2gc-h23p
pkg: github.com/rclone/rclone
eco: go
published: Aug 5, 2026
### Summary
`rclone archive extract` can write extracted files outside the user-selected destination prefix when extracting a crafted archive. A malicious archive entry containing parent path components such as `../` can escape the requested extraction prefix and create or overwrite sibling objects…
CVE-2026-59732
NVD
MEDIUM
CVE-2026-71201
In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assigned to Nodes owned or leased by another project.
CWE: CWE-863
NVD
MEDIUM
CVE-2026-70588
Ghost is a Node.js content management system. From 5.26.0 until 6.54.1, the Universal Import feature in Ghost Admin failed to properly sanitize imported content resulting in XSS in post content. This issue is fixed in version 6.54.1.
CWE: CWE-79
GitHub-GHSA
MEDIUM
Ghost: Cross-Site Scripting in Universal Import
GHSA-2gx6-7gx2-wwcf
pkg: ghost
eco: npm
published: Aug 4, 2026
### Impact
The Universal Import feature in Ghost Admin failed to properly sanitize imported content resulting in XSS in post content.
### Vulnerable versions
This vulnerability is present in Ghost from v5.26.0 up to v6.54.0.
### Patches
v6.54.1 contains a fix for this issue.
### How to update
…
CVE-2026-70588
GitHub-GHSA
MEDIUM
Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosure
GHSA-f23p-vx2j-j53r
pkg: hono
eco: npm
published: Aug 7, 2026
### Summary
`memo()` from `hono/jsx` retains the result of a server-side render and reuses it for later renders with comparator-equal props. Request-scoped values read inside the component take no part in that comparison, so a response can contain HTML rendered for another user's request.
### Deta…
CVE-2026-71850
NVD
MEDIUM
CVE-2026-71318
Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an attacker can supply a top-level `as` prop to the /__nuxt_island/ endpoint and drive dynamic component resolution through <component :is>, resolveDynamicComponent, or h(). This issue is fixed in 3.21.1…
CWE: CWE-20
GitHub-GHSA
MEDIUM
Nuxt: Unauthorized Component Instantiation via Server Island Props
GHSA-48hr-524c-v5w3
pkg: nuxt, nuxt
eco: npm
published: Aug 5, 2026
## Impact
Nuxt server islands accept props via the `/__nuxt_island/` endpoint. When an application has a server island component that forwards props directly into Vue's dynamic component resolution (`<component :is>`, `resolveDynamicComponent`, or `h()`), an attacker can pass a plain string value (…
CVE-2026-71318
NVD
MEDIUM
CVE-2026-70590
Ghost is a Node.js content management system. Prior to 6.54.1, any staff-level user was able to leak the hashed passwords of other staff users through the Ghost Admin API. An offline password-guessing attack against the hashes could lead to account takeover if successful, but Device Verification sho…
CWE: CWE-200
NVD
MEDIUM
CVE-2026-70589
Ghost is a Node.js content management system. From 4.22.0 until 6.54.1, a missing validation check allowed users to redeem subscription offers that were no longer active. This issue is fixed in version 6.54.1.
CWE: CWE-20
GitHub-GHSA
MEDIUM
Ghost: Blind Password Hash Disclosure in Ghost Admin API
GHSA-jm22-3w23-5q7w
pkg: ghost
eco: npm
published: Aug 4, 2026
### Impact
Any staff-level user was able to leak the hashed passwords of other staff users. An offline password-guessing attack against the hashes could lead to account takeover if successful, but [Device Verification](https://docs.ghost.org/security#device-verification) should have prevented an at…
CVE-2026-70590
GitHub-GHSA
MEDIUM
Ghost: Archived Offers can be Redeemed
GHSA-4wx2-7gvj-qfq3
pkg: ghost
eco: npm
published: Aug 4, 2026
### Impact
A missing validation check allowed users to redeem subscription offers that were no longer active.
### Vulnerable versions
This vulnerability is present in Ghost from v4.22.0 up to v6.54.0.
### Patches
v6.54.1 contains a fix for this issue.
### How to update
For self-hosters using …
CVE-2026-70589
GitHub-GHSA
MEDIUM
undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields
GHSA-v3r7-h72x-cjcm
pkg: undici, undici, undici
eco: npm
published: Aug 3, 2026
## Impact
The `setCookie` function has two attribute injection paths. `validateCookieDomain` does not reject semicolons (`validateCookiePath` already does at 0x3B), so a `domain` value like `example.com; SameSite=None` lands verbatim as `Domain=example.com; SameSite=None`. The `unparsed` array's lo…
CVE-2026-16729
GitHub-GHSA
MEDIUM
undici vulnerable to downstream response desynchronization via retry interceptor
GHSA-8xcm-r25x-g524
pkg: undici, undici, undici
eco: npm
published: Aug 3, 2026
### Impact
Undici's `interceptors.retry()` can deliver a response whose body length does not match the `Content-Length` header exposed to the application after a retry or resume of a partial response. Applications that use `interceptors.retry()` and forward upstream response headers and bodies down…
CVE-2026-16728
NVD
MEDIUM
CVE-2026-56609
HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using weak TLS versions such as TLS 1.0 and 1.1. These outdated protocols lack modern security features, making them vulnerable to known attacks and exposing sensitive information durin…
CWE: CWE-327
NVD
MEDIUM
CVE-2026-19244
A vulnerability was detected in HKUDS nanobot up to 0.2.1. The affected element is the function connect_mcp_servers of the file nanobot/agent/tools/mcp.py of the component MCP enabledTools Scope Handler. Performing a manipulation results in improper access controls. The attack is possible to be carr…
CWE: CWE-266, CWE-284
GitHub-GHSA
MEDIUM
jsoup: Cleaner may expose markup with custom raw-text elements
GHSA-pmhh-3w7g-xqp8
pkg: org.jsoup:jsoup
eco: maven
published: Aug 6, 2026
When a custom `Safelist` permits certain raw-text elements, jsoup may incorrectly sanitize malformed HTML containing a tag name that ends in a control character. The tag may acquire the parsing behavior of a different element, causing content that should remain text to be emitted as active markup af…
CVE-2026-71497
NVD
MEDIUM
CVE-2026-18909
A stack-based buffer overflow vulnerability exists in ELAN Microelectronics Corp. ELAN Smart-Pad on Windows (ETD.sys and ETDSMBus.sys). During Intel SMBus recovery, ETDSMBus.sys does not enforce an upper-bound check on the hardware-derived report count, allowing an out-of-range value to be forwarded…
CWE: CWE-121
NVD
MEDIUM
CVE-2026-47487
NVIDIA Triton Inference Server for Linux contains a vulnerability where a user could cause files outside the model repository to be read, written to, or modified by providing a path in the model name to the Triton MLflow plugin. A successful exploit of this vulnerability might lead to denial of serv…
CWE: CWE-22
NVD
MEDIUM
CVE-2026-70556
Hubzilla 11.2.1 contains a cross-site request forgery vulnerability in the OAuth2 /authorize endpoint handled by Zotlabs\Module\Authorize::post() that allows unauthenticated attackers to register arbitrary OAuth2 applications under an authenticated user's account by submitting a cross-origin POST re…
CWE: CWE-352
NVD
MEDIUM
CVE-2026-70442
Jenkins Google Chat Notification Plugin 166.ve6b_de280f2e8 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to use.
CWE: CWE-285
NVD
MEDIUM
CVE-2026-70596
Ghost is a Node.js content management system. From 4.9.0 until 6.54.1, an input validation issue allowed any staff user to create a post with content in feature_image_caption that could be used to hijack another staff user's Ghost Admin session, resulting in privilege escalation. This issue is fixed…
CWE: CWE-79
NVD
MEDIUM
CVE-2026-15656
IBM Maximo Application Suite 9.2, 9.1, and 9.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure…
CWE: CWE-614
GitHub-GHSA
MEDIUM
Ghost: Cross-Site Scripting in Feature Image Captions
GHSA-pr22-p9rp-2cqv
pkg: ghost
eco: npm
published: Aug 5, 2026
### Impact
An input validation issue allowed any staff user to create a post with content that could be used to hijack another staff user's Ghost Admin session resulting in privilege escalation.
### Vulnerable versions
This vulnerability is present in Ghost from v4.9.0 up to v6.54.0.
### Patches…
CVE-2026-70596
NVD
MEDIUM
CVE-2026-55996
A denial-of-service vulnerability was identified in multiple TLS listeners in Rancher. Both the cattle-cluster-agent component running in downstream clusters and the Rancher server itself use the dynamiclistener library to serve TLS traffic. Without an effective CN filter configured, dynamiclistener…
CWE: CWE-770
GitHub-GHSA
MEDIUM
Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup
GHSA-jxc9-xmc4-gr23
pkg: open-webui
eco: pip
published: Aug 4, 2026
## Summary
A user with write access to one knowledge base could delete directories, and drop file embeddings, belonging to knowledge bases they do not control. The sync cleanup endpoint verified write access on the knowledge base named in the URL and then acted on the directory and file ids supplied…
CVE-2026-70488
GitHub-GHSA
MEDIUM
Open WebUI: Users denied the image-generation permission can still generate images via chat completions
GHSA-g423-grf7-98rv
pkg: open-webui
eco: pip
published: Aug 4, 2026
## Summary
An authenticated user whose `features.image_generation` permission has been revoked can still make the server generate images by sending the feature flag in a chat-completion request. The chat pipeline took the client-supplied `features` object at face value and never re-checked the permi…
CVE-2026-70484
GitHub-GHSA
MEDIUM
undici vulnerable to CRLF Injection via blob-like body 'type' property
GHSA-m8rv-5g2x-5cg5
pkg: undici, undici, undici
eco: npm
published: Aug 3, 2026
### Impact
When an application passes a duck-typed blob-like body to undici's HTTP/1.1 dispatcher (via `request()`, `stream()`, `pipeline()`, or `dispatch()`) with a `.type` derived from untrusted input, an attacker can inject CRLF sequences (`\r\n`) to append arbitrary HTTP headers and potentially…
CVE-2026-15157
NVD
MEDIUM
CVE-2026-70591
Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a Server-Side Request Forgery in Ghost Admin image fetching allowed any staff-level user to perform a blind HTTP GET request against internal hosts. No output was returned, but this could have been used to probe open ports on in…
CWE: CWE-918
GitHub-GHSA
MEDIUM
Ghost: Server-Side Request Forgery in Image Fetching
GHSA-gcvv-72q8-9v76
pkg: ghost
eco: npm
published: Aug 4, 2026
### Impact
A Server-Side Request Forgery (SSRF) in Ghost Admin allowed any staff-level user to perform a blind HTTP GET request against internal hosts. No output was returned, but this could have been used to probe open ports on internal hosts.
### Vulnerable versions
This vulnerability is presen…
CVE-2026-70591
GitHub-GHSA
MEDIUM
Open WebUI: Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart rendering
GHSA-rffm-9q57-q649
pkg: open-webui
eco: pip
published: Aug 4, 2026
## Summary
Open WebUI renders `vega` and `vega-lite` fenced code blocks in chat content by building a Vega view in the viewer's browser without a restricted resource loader. Any user who can place such a block where another user will see it can make that user's browser issue attacker-chosen outbound…
CVE-2026-70480
NVD
MEDIUM
CVE-2026-70595
Ghost is a Node.js content management system. From 6.26.0 until 6.54.1, a validation issue allowed some functionality, such as Webmentions, to be abused by an unauthenticated user to make limited HTTP requests to hosts in the Ghost server's internal network. A successful attack would not result in a…
CWE: CWE-918
GitHub-GHSA
MEDIUM
Ghost: Server-Side Request Forgery Mitigation Issue
GHSA-x5mm-wm4g-j5xv
pkg: ghost
eco: npm
published: Aug 5, 2026
### Impact
A validation issue allowed some functionality, such as Webmentions, to be abused by an unauthenticated user to make limited HTTP requests to hosts in the Ghost server's internal network. A successful attack would not result in any response data being returned.
### Vulnerable versions
T…
CVE-2026-70595
GitHub-GHSA
MEDIUM
Ghost: Server-side request forgery via DNS rebinding in external request handling
GHSA-ch52-px8q-f22j
pkg: ghost
eco: npm
published: Aug 4, 2026
### Impact
Ghost’s private-IP check for outbound HTTP requests could be bypassed via DNS rebinding, allowing an attacker to coerce the Ghost server into reaching hosts on internal networks through features that issue external fetches.
### Vulnerable versions
This vulnerability is present in Gho…
CVE-2026-53945
GitHub-GHSA
MEDIUM
pypdf: Possible large memory usage for large /ToUnicode streams
GHSA-fp3f-mc75-235c
pkg: pypdf
eco: pip
published: Aug 7, 2026
### Impact
An attacker who uses this vulnerability can craft a PDF which leads to large memory consumption. This requires parsing the `/ToUnicode` entry of a font with unusually large values, for example during text extraction.
### Patches
This has been fixed in [pypdf==6.15.0](https://github.com…
CVE-2026-71870
GitHub-GHSA
MEDIUM
pypdf: Possible long runtimes/large memory usage for large CID font width ranges
GHSA-fwg2-594c-jp42
pkg: pypdf
eco: pip
published: Aug 7, 2026
### Impact
An attacker who uses this vulnerability can craft a PDF which leads to long runtimes and large memory consumption. This requires parsing the font width entries of a font with unusually large values, for example during text extraction.
### Patches
This has been fixed in [pypdf==6.15.0](…
CVE-2026-71852
GitHub-GHSA
MEDIUM
Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint
GHSA-7c4v-fwgw-9rf7
pkg: nuxt, nuxt
eco: npm
published: Aug 7, 2026
### Impact
When a Nuxt dev server is bound to a network-reachable interface (for example `nuxt dev –host` for on-device testing), the default-enabled Chrome DevTools workspace endpoint `GET /.well-known/appspecific/com.chrome.devtools.json` returns the absolute project root (`workspace.root`, i.e.…
GitHub-GHSA
MEDIUM
DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS
GHSA-55q2-fjhq-7xh7
pkg: dompurify
eco: npm
published: Aug 7, 2026
### Summary
During `IN_PLACE` sanitization, a hook that removes an element can leave that element's detached descendants executable. A descendant image can retain its attacker-provided `onload` handler and fire after `sanitize()` returns, even though the returned root is clean and the image remains…
GitHub-GHSA
MEDIUM
Mermaid radar diagrams are vulnerable to DoS
GHSA-rhh3-jpg6-66xh
pkg: mermaid
eco: npm
published: Aug 6, 2026
### Impact
Mermaid radar diagrams allow arbitrary large values for `ticks`, which can cause high CPU usage, freezing the webpage/JavaScript process for long periods of time, until the process is eventually killed due to OOM/running out of memory.
#### Proof-of-concept
“`txt
radar-beta
axis a, …
CVE-2026-71439
GitHub-GHSA
MEDIUM
Mermaid allows CSS injection applying to sibling elements of the diagram
GHSA-6×64-9×62-f2gx
pkg: mermaid, mermaid
eco: npm
published: Aug 6, 2026
### Summary
Mermaid does not fully restrict CSS to the rendered SVG subtree. Although selectors are prefixed with `#mermaid-X`, sibling (`~` and `+`) combinators can still escape the Mermaid container and inject styles to DOM elements adjacent to the diagram `<svg>`.
**Most users of mermaid would …
CVE-2026-50159
GitHub-GHSA
MEDIUM
Mermaid Architecture diagrams are vulnerable to prototype pollution
GHSA-3rrr-jr9j-h3q3
pkg: mermaid
eco: npm
published: Aug 6, 2026
Rendering an untrusted `architecture-beta` diagram lets the diagram author write an arbitrary property with the value `horizontal` or `vertical` onto `Object.prototype`. A group id of `__proto__` is accepted as a valid parent.
### Impact
Any code in the same realm that reads a property of that nam…
CVE-2026-71437
GitHub-GHSA
MEDIUM
Mermaid XY Charts are vulnerable to an infinite loop DoS
GHSA-2v8p-3f2j-5mp7
pkg: mermaid, mermaid
eco: npm
published: Aug 6, 2026
### Impact
Mermaid XY Charts are vulnerable to an infinite loop DoS attack in the `setXAxisRangeData()`, when configuring an X-Axis with invalid parameters.
As each loop appends an element to an array, this would generally only cause an `RangeError: Invalid array length` to appear after a few seco…
CVE-2026-71436
GitHub-GHSA
MEDIUM
Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port
GHSA-6p8f-p8j2-rqmv
pkg: github.com/traefik/traefik/v3
eco: go
published: Aug 6, 2026
## Summary
There is a medium severity vulnerability in Traefik's Kubernetes Gateway API provider.
When two accepted HTTPRoutes target the same backend Service:port but configure different
`backendRef` filters, Traefik may resolve both routes to the same child service and apply
only one route's filt…
CVE-2026-54765
GitHub-GHSA
MEDIUM
Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef
GHSA-62fc-8686-hfmq
pkg: github.com/traefik/traefik/v2, github.com/traefik/traefik/v3, github.com/traefik/traefik/v3
eco: go
published: Aug 6, 2026
## Summary
There is a medium severity vulnerability in Traefik's Kubernetes CRD provider. When `providers.kubernetesCRD.allowCrossNamespace` is disabled — the default — cross-namespace `@kubernetescrd` references are rejected for middlewares, TLS options and HTTP/TCP ServersTransports, but the …
CVE-2026-71325
GitHub-GHSA
MEDIUM
Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass
GHSA-42cj-m3vj-89wv
pkg: github.com/traefik/traefik/v3, github.com/traefik/traefik/v3
eco: go
published: Aug 5, 2026
## Summary
There is a medium-severity cross-provider reference vulnerability in Traefik's Kubernetes CRD provider. The `crossProviderNamespaces` allowlist is enforced for HTTP `serversTransport` references but was not enforced for `IngressRouteTCP` service `serversTransport` references. A low-privi…
CVE-2026-65602
GitHub-GHSA
MEDIUM
Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion
GHSA-qq9q-x9w4-chhj
pkg: Traefik
eco: go
published: Aug 5, 2026
## Summary
There is a medium-severity namespace-confusion vulnerability in Traefik's Kubernetes Gateway API provider. When resolving `HTTPRoute.spec.rules[].backendRefs[].filters[].extensionRef`, Traefik used the backend Service namespace instead of the `HTTPRoute` namespace. A low-privileged route…
CVE-2026-65601
GitHub-GHSA
MEDIUM
Flowise: Unauthenticated Credential Abuse via Text-to-Speech Endpoint Allows Unauthorized Use of Private Chatflow TTS Credentials
GHSA-8gj2-2cvc-6xx7
pkg: flowise
eco: npm
published: Aug 4, 2026
## Summary
The `/api/v1/text-to-speech/generate` endpoint is whitelisted (requires no authentication) and accepts any `chatflowId` without checking whether the referenced chatflow is public. An unauthenticated attacker who knows a valid chatflow UUID can abuse that chatflow's TTS credential (OpenAI…
GitHub-GHSA
MEDIUM
Flowise: IDOR vulnerability exists at the GET /api/v1/organization/customer-default-source endpoint
GHSA-2364-jh4q-m9vm
pkg: flowise
eco: npm
published: Aug 4, 2026
### Summary
An Insecure Direct Object Reference (IDOR) vulnerability exists at the **GET /api/v1/organization/customer-default-source** endpoint. This flaw allows an authenticated attacker to bypass authorization checks and retrieve sensitive payment and profile information of other customers by man…
GitHub-GHSA
MEDIUM
python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees
GHSA-m2h6-j472-rp4c
pkg: cryptography
eco: pip
published: Aug 3, 2026
### Summary
If an intermediate constrained CA permits the DNS name `foo.example.com`, and the leaf certificate has a wildcard in its DNS SAN of `*.example.com`, python-cryptography's verifier accepts which allows escaping outside of the permitted names.
### PoC
“`
#!/usr/bin/env python3
"""Standa…
CVE-2026-69248
GitHub-GHSA
MEDIUM
AIOHTTP: HTTP request smuggling via WebSocket upgrade
GHSA-mfx4-hv73-q22v
pkg: aiohttp
eco: pip
published: Aug 3, 2026
### Summary
The HTTP parsers were vulnerable to a request smuggling attack relating to WebSocket upgrades.
### Impact
If using the server-side component, it may be possible for an attacker to execute a request smuggling vulnerability using an edge case in the WebSocket upgrade procedure. AIOHTT i…
CVE-2026-69243
GitHub-GHSA
MEDIUM
AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate
GHSA-mq44-7p77-q5h7
pkg: aiohttp
eco: pip
published: Aug 3, 2026
### Summary
The client accepts and decompresses frames with the RSV1 bit set even when the `permessage-deflate` extension was not negotiated.
### Impact
A client may unexpectedly decompress WebSocket frames when explicitly opted out. This could lead to additional CPU/memory consumption, but is un…
CVE-2026-59881
GitHub-GHSA
MEDIUM
ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks
GHSA-4xrf-jv44-h6hh
pkg: ip-address
eco: npm
published: Aug 3, 2026
### Summary
Every special-use classification method is built on `isInSubnet`, which short-circuits to `false` whenever the address's own subnet mask is *shorter* than the reference range's mask. That mask comes verbatim from the CIDR suffix on the parsed input, so appending a suffix such as `/0` su…
CVE-2026-69198
GitHub-GHSA
MEDIUM
ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks
GHSA-22jq-vg5j-6vgg
pkg: ip-address
eco: npm
published: Aug 3, 2026
### Summary
`Address6`'s special-property checks misclassify IPv4-mapped (`::ffff:0:0/96`) and NAT64 well-known (`64:ff9b::/96`) IPv6 addresses. These checks classify an address by its IPv6 wrapper rather than by the IPv4 address it embeds, so `isLoopback()`, `isLinkLocal()`, `isMulticast()`, and `…
CVE-2026-54272
GitHub-GHSA
MEDIUM
PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset
GHSA-fxqj-rqcc-2cmp
pkg: postcss
eco: npm
published: Aug 3, 2026
## Summary
The fix for GHSA-6g55-p6wh-862q added a guard in `lib/previous-map.js` `PreviousMap.loadFile()` that restricts an attacker-controlled `sourceMappingURL` (from a CSS comment) to a `.map` extension and, for untrusted maps, rejects `..` traversal and absolute paths. The traversal/absolute r…
CVE-2026-69153