CISA-KEV
CRITICAL
Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV
CRITICAL
Metabase SQL Injection Vulnerability
Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored c…
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV
CRITICAL
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
NVD
CRITICAL
CVE-2026-73678
MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by submitting crafted prompts to the unprotected POST /api/v1/responses/ endpoint, which reaches the Anton agent's …
CWE: CWE-94
NVD
CRITICAL
CVE-2026-73299
Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies with unrestricted JavaScript member access. An attacker-controlled template could traverse constructor and prototype properties…
CWE: CWE-94, CWE-1336
NVD
CRITICAL
CVE-2026-58115
A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to programming nodes that are c…
CWE: CWE-306
NVD
CRITICAL
CVE-2026-73269
A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, can trigger the creation of a cluster-scoped ClusterRoleBinding. This allows the user to escalate their privileges from namespace-local access to clust…
CWE: CWE-269
NVD
CRITICAL
CVE-2026-62420
An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations. When moving an instance cross-project to a different cluster member via POST /1.0/instances/{name} with migration: true, project: <ta…
CWE: CWE-863
NVD
CRITICAL
CVE-2026-73263
Prowler is a cloud security platform. Prior to 5.36.0, the Kubernetes provider connection test accepted kubeconfig_content containing a legacy gcp auth-provider with config.cmd-path and config.cmd-args because kubeconfig_contains_exec_auth in api/src/backend/api/v1/serializers.py checked only exec b…
CWE: CWE-78
NVD
CRITICAL
CVE-2026-48765
TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege read collaborator to extract a workspace OAuth `credentialsId` from a readable bot configuration and then overwrite that credential through `handleUpdateOAuthCredentials()` by supplying an attacker-controlled writable …
CWE: CWE-639
NVD
CRITICAL
CVE-2026-72911
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.118.0 and 16.29.0, the validate_template and render_template calls in erpnext/accounts/doctype/process_statement_of_accounts/process_statement_of_accounts.py render subject, body, and pdf_name fields with unrestricted g…
CWE: CWE-1336
NVD
CRITICAL
CVE-2026-14450
A flaw was found in the MaaS API. This vulnerability allows any pod within the cluster to bypass the Kuadrant AuthPolicy gateway by forging HTTP headers, specifically `X-MaaS-Username` and `X-MaaS-Group`, which are trusted verbatim. This lack of first-party authentication enables an attacker to gain…
CWE: CWE-290
NVD
CRITICAL
CVE-2026-72901
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated low-privilege member to execute arbitrary commands on the control-plane host because the volumeName field accepted by volumeBackup.create and volumeBackup.runManually is interpolated with…
CWE: CWE-78
NVD
CRITICAL
CVE-2026-72876
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, swarm.getNodes, swarm.getNodeInfo, swarm.getNodeApps, and swarm.getAppInfos in apps/dokploy/server/api/routers/swarm.ts accept another organization’s serverId without an activeOrganizationId ownership check, and getNo…
CWE: CWE-78, CWE-639, CWE-862
NVD
CRITICAL
CVE-2026-72869
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC subscription passes the databaseName parameter to restore builders in packages/server/src/utils/restore/utils.ts, where PostgreSQL, MariaDB, MySQL, and MongoDB commands embed the va…
CWE: CWE-77, CWE-78
NVD
CRITICAL
CVE-2026-72868
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, apps/dokploy/server/api/routers/destination.ts interpolates the accessKey, secretAccessKey, region, endpoint, provider, and bucket fields from destination.testConnection into an rclone ls command executed through child_…
CWE: CWE-78, CWE-862
NVD
CRITICAL
CVE-2026-72865
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the compose.update operation stores an unvalidated composePath that packages/server/src/utils/builders/compose.ts and packages/server/src/services/compose.ts interpolate into docker compose -f, docker stack deploy -c, a…
CWE: CWE-78
NVD
CRITICAL
CVE-2026-72863
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's WebSocket handlers (in-app terminals and log streamers) authenticate the session but never authorize it. They establish who the user is via validateRequest() and then proceed without consulting the role/permis…
CWE: CWE-269, CWE-639, CWE-862
NVD
CRITICAL
CVE-2026-72862
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the mariadb.ts, mongo.ts, mysql.ts, postgres.ts, redis.ts, and libsql.ts Dokploy database service deployment functions pass user-controlled dockerImage fields unquoted into docker pull ${dockerImage} shell commands on t…
CWE: CWE-78
NVD
CRITICAL
CVE-2026-72736
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy passes user-controlled values directly into shell commands via unquoted template literal interpolation in the registry credential testing and Docker Swarm cluster management endbpoints. Both endpoints have a saf…
CWE: CWE-77
NVD
CRITICAL
CVE-2026-74269
In the Linux kernel, the following vulnerability has been resolved:
bnxt: fix head underflow on XDP head-grow
The xdp.py test test_xdp_native_adjst_head_grow_data crashes when run on
a bnxt machine (and also crashes in NIPA).
It seems that the bug is an underflow in bnxt_rx_multi_page_skb, which
…
NVD
CRITICAL
CVE-2026-72317
In the Linux kernel, the following vulnerability has been resolved:
SUNRPC: pin upper rpc_clnt across the TLS connect_worker
The TLS connect path has a use-after-free: nothing pins the
upper rpc_clnt across the delayed connect_worker. xs_connect()
stores task->tk_client in sock_xprt::clnt as a raw…
NVD
CRITICAL
CVE-2026-72222
In the Linux kernel, the following vulnerability has been resolved:
sunrpc: pin svc_xprt across the asynchronous TLS handshake callback
svc_tcp_handshake() stores the raw svc_xprt pointer in
tls_handshake_args.ta_data and submits the request through
tls_server_hello_x509(). The handshake core take…
NVD
CRITICAL
CVE-2026-72221
In the Linux kernel, the following vulnerability has been resolved:
sunrpc: wait for in-flight TLS handshake callback when cancel loses race
When wait_for_completion_interruptible_timeout() in
svc_tcp_handshake() returns 0 (timeout) or -ERESTARTSYS (signal) and
tls_handshake_cancel() then returns …
NVD
CRITICAL
CVE-2026-50027
mcp-memory-service is a semantic memory layer for AI applications. Prior to 10.67.1, all HTTP routes under /api/documents/* in mcp-memory-service are served without any authentication dependency, even when the server is configured with an API key (MCP_API_KEY) or OAuth. An unauthenticated remote att…
CWE: CWE-306
NVD
CRITICAL
CVE-2026-73649
Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for CVE-2026-44966 filtered constructor, __proto__, and prototype only in the #set assignment handler in src/compile/set.ts, while property-read expressions in src/compile/references.ts…
CWE: CWE-94
NVD
CRITICAL
CVE-2026-67614
CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote attackers to forge valid authentication tokens and obtain an interactive root shell via WebSocket on port 8888. Attackers can craft a forged JWT signed wit…
CWE: CWE-798
NVD
CRITICAL
CVE-2026-28185
Unauthenticated Broken Authentication in Log in with Google <= 1.4.2 versions.
CWE: CWE-345
NVD
CRITICAL
CVE-2026-28008
Unauthenticated Broken Authentication in OAuth Single Sign On – SSO (OAuth Client) <= 7.0.0 versions.
CWE: CWE-290
NVD
CRITICAL
CVE-2026-49819
UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerInitSuperuser` (`backend/pb/handlers.go:249`), reachable as `POST /api/upsnap/init-superuser`. The vulnerable code lacks any authentication, setup token…
CWE: CWE-78, CWE-269, CWE-306, CWE-862
NVD
CRITICAL
CVE-2026-73519
WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs, allowing remote unauthenticated attackers to bypass authentication by supplying this value in the X-WolfStack-Secret header to the require_auth() gate…
CWE: CWE-798
NVD
CRITICAL
CVE-2026-73034
DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers to write arbitrary files to any location on the server by injecting directory traversal sequences into the user_id HTTP header of the Python file-upload endpoint. Attackers can send a crafted multipar…
CWE: CWE-22
NVD
CRITICAL
CVE-2026-73211
PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.1.6, ActorFollowModel.updateScore() interpolates the attacker-controlled ActivityPub actor inboxUrl into an SQL query, allowing an unauthenticated remote server to read and write PeerTube database tables, including oAuthToken.…
CWE: CWE-89
NVD
CRITICAL
CVE-2026-69102
MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in application-maxkey.properties that allows unauthenticated attackers to forge valid JWT tokens and authenticate as any user by exploiting the password-skipped login endpoint. Attackers can craft a JWT token…
CWE: CWE-798
NVD
CRITICAL
CVE-2026-72920
SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC service without mandatory authentication when jwt.filer_signing.key is unset, allowing any client that can reach the filer gRPC port to invoke CreateUser, CreateAccessKey, PutPolicy…
CWE: CWE-306
NVD
CRITICAL
CVE-2026-68160
In the Linux kernel, the following vulnerability has been resolved:
ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()
ceph_handle_caps() reads snap_trace_len from the wire-format
ceph_mds_caps header and uses it unconditionally to build a fake
end pointer (snaptrace + snaptr…
NVD
CRITICAL
CVE-2026-68127
In the Linux kernel, the following vulnerability has been resolved:
ila: reload IPv6 header after pskb_may_pull in checksum adjust
ila_csum_adjust_transport() caches ip6h = ipv6_hdr(skb) before calling
pskb_may_pull(). On a non-linear skb whose transport header sits in a page
fragment, pskb_may_pu…
NVD
CRITICAL
CVE-2026-68123
In the Linux kernel, the following vulnerability has been resolved:
openvswitch: fix GSO userspace truncation underflow
OVS_ACTION_ATTR_TRUNC currently stores a delta from the original skb
length in OVS_CB(skb)->cutlen. When a later userspace action segments a
GSO skb, queue_gso_packets() reuses t…
NVD
CRITICAL
CVE-2026-68117
In the Linux kernel, the following vulnerability has been resolved:
tipc: clear sock->sk on the failed-insert path in tipc_sk_create()
When tipc_sk_create() fails to insert the new socket (tipc_sk_insert()
returns non-zero), its error path frees the sk with sk_free() but leaves
sock->sk pointing a…
NVD
CRITICAL
CVE-2026-73843
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, internal/cluster-gateway/server.go served caller-facing management APIs on the externally reachable agent listener without authentication, allowing network-reachable attackers to invoke /api/proxy/ and…
CWE: CWE-306, CWE-668, CWE-862
NVD
CRITICAL
CVE-2026-8715
Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissions to read files from the operator pod's filesystem and transmit their contents…
CWE: CWE-552
NVD
CRITICAL
CVE-2026-72877
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the dockerImage field is interpolated without quoting into shell commands in buildRemoteDocker() in packages/server/src/utils/providers/docker.ts and is validated only as an optional string. An authenticated user with a…
CWE: CWE-78
NVD
CRITICAL
CVE-2026-68124
In the Linux kernel, the following vulnerability has been resolved:
mctp: serial: handle zero-length frames to prevent rx buffer overflow
The MCTP serial receive state machine reads a frame length byte in
mctp_serial_push_header() case 2 and validates it upper-bound-only:
if (c > MCTP_SERIAL_FRA…
NVD
CRITICAL
CVE-2026-73653
Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, takeScreenshot, screenshotMatcher, stopChunkTrace, deleteTracing, and annotateTraces accept browser-supplied file paths without enforcing the allowWrite …
CWE: CWE-22, CWE-552, CWE-862
NVD
CRITICAL
CVE-2026-50561
Yuxi is a large-model-based intelligent knowledge base and knowledge graph agent development platform. Prior to version 0.6.2, the project's authentication mechanism contains a flaw. In affected versions, the system does not sufficiently validate the identity token in the Authorization header — on…
CWE: CWE-287
NVD
CRITICAL
CVE-2026-50516
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
CWE: CWE-306
NVD
CRITICAL
CVE-2026-73080
SeaweedFS is a distributed storage system. Prior to 4.24, VolumeServer.FetchAndWriteNeedle in weed/server/volume_grpc_remote.go fetches a caller-supplied remote endpoint through weed/remote_storage/s3/s3_storage_client.go and writes the response into a needle. The RPC performs no authentication and …
CWE: CWE-918
GitHub-GHSA
CRITICAL
SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle
GHSA-87fv-vqqr-m4jr
pkg: github.com/seaweedfs/seaweedfs
eco: go
published: Aug 11, 2026
### Impact
`VolumeServer.FetchAndWriteNeedle` fetches a caller-supplied remote endpoint and writes the response into a needle. Before 4.24 this RPC performed no authentication and no validation of the target, so anyone able to reach a volume server's gRPC port could coerce the server into issuing re…
CVE-2026-73080
NVD
CRITICAL
CVE-2026-47754
Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.x through 2.19.1 and all 1.x versions contain an unauthenticated path traversal in the `archiveEntryName` parameter of the `action=read` endpoint that is part of the original 1.x Metacat API. `A…
CWE: CWE-22, CWE-862
NVD
CRITICAL
CVE-2026-49457
erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and the hostname was not compared against the certificate,…
CWE: CWE-295, CWE-297
NVD
CRITICAL
CVE-2026-73501
kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces a nil AuthenticationFunc with NoopAuthenticationFunc, which returns nil without checking credentials. This substitution causes every OpenAPI se…
CWE: CWE-287
NVD
CRITICAL
CVE-2026-71290
Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between the client and the server can impersonate…
CWE: CWE-295
NVD
CRITICAL
CVE-2026-68083
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix path resolution in ksmbd_vfs_kern_path_create
The SMB2 open lookup is rooted at the share with LOOKUP_BENEATH, but the
create/mkdir/hardlink sink is not: ksmbd_vfs_kern_path_create() builds an
absolute path with convert…
NVD
CRITICAL
CVE-2026-73842
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go exposed /api/proxy/, /api/exec/, and /api/wirelogs/ on an internal listener without requiring a client certificate or token, allowing any network-reachab…
CWE: CWE-269, CWE-306, CWE-862
NVD
HIGH
CVE-2026-72382
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: reject undersized DACLs before parsing ACEs
parse_dacl() limits the attacker-controlled ACE count by comparing it
with the number of minimal ACEs that fit in the DACL size. The DACL size
field is 16 bits, but the expression…
NVD
HIGH
CVE-2026-73841
OpenChoreo is a complete, open-source developer platform for Kubernetes. From 1.2.0-rc.1 until 1.2.0, internal/openchoreo-api/api/handlers/exec.go and internal/openchoreo-api/api/handlers/wirelogs.go authorize component:exec and wirelogs:view using the caller-supplied project query parameter instead…
CWE: CWE-639, CWE-863
NVD
HIGH
CVE-2026-73667
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.0-rc.2, OpenChoreo Workflow Plane templates under samples/getting-started/workflow-templates/ interpolated developer-controlled workflow parameters into shell program text executed through sh -c i…
CWE: CWE-78
NVD
HIGH
CVE-2026-15741
SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition. Attacks affect expression deparse consumers broadly, including pg_dump, psql commands like \sf, and any similar usage in non-core tools. Versions before Pos…
CWE: CWE-89
NVD
HIGH
CVE-2026-49473
@cedar-policy/authorization-for-expressjs is an open-source Express.js middleware that integrates Cedar authorization into Express applications by mapping HTTP requests to Cedar actions and evaluating authorization policies before allowing requests to proceed. Versions prior to 0.3.0 have an issue w…
CWE: CWE-436, CWE-863
NVD
HIGH
CVE-2026-13622
A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside the target virt-launcher pod via /proc/<pid>/root/ paths using net.Dial() without symlink protection. These socket paths reside in qemu-owned director…
CWE: CWE-22
NVD
HIGH
CVE-2026-49467
Pingvin Share X is a secure and easy self-hosted file sharing platform. A vulnerability in versions 1.5.0 through 1.18.0 allow an attacker to bypass password verification when managing Time-based One-Time Password (TOTP) settings. The root cause is a missing `await` keyword on calls to the asynchron…
CWE: CWE-303, CWE-304
NVD
HIGH
CVE-2026-44741
Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Versions prior to 2.3.6 and 1.7.18 have a SQL injection vulnerability in Pimcore's translation grid date filter — the user-supplied `property` field from the filter JSON is interpolated directly into a `UNIX_TIMESTAMP(DATE(FROM_UNIX…
CWE: CWE-89
NVD
HIGH
CVE-2026-65941
In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.
CWE: CWE-73, CWE-94, CWE-306, CWE-918
NVD
HIGH
CVE-2026-58076
Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and instantiating it with arguments from the same blob, with no restriction on what could be imported. An operator's `executor_config` reaches that branch, s…
CWE: CWE-502
NVD
HIGH
CVE-2026-19560
Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD
HIGH
CVE-2026-19559
Use after free in HTML in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD
HIGH
CVE-2026-19556
Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD
HIGH
CVE-2026-55676
Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` and stores them in a directory served by the same nginx and php-fpm instance. The allow-list that should restrict accepted file types is an empty array …
CWE: CWE-434
NVD
HIGH
CVE-2026-73222
Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the –studio option in cli-tool/src/sandbox-server.js binds to all interfaces on port 3444, permits cross-origin requests, and requires no authentication. The PO…
CWE: CWE-78, CWE-306, CWE-352
NVD
HIGH
CVE-2026-18691
An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to influence which authentication mechanism is used when one replica set member connects to another. Under certain conditions, this could cause the cluster's shared internal credential to be …
CWE: CWE-757
NVD
HIGH
CVE-2026-49179
Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.
CWE: CWE-77
NVD
HIGH
CVE-2026-72533
An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privileged users to bypass Docker proxy authorization checks via non-canonical URL normalization, defeating all authorization middleware. The proxy endpoint fails to normalize request paths before applying…
CWE: CWE-287
NVD
HIGH
CVE-2026-15555
A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicated session data via the JBoss Marshalling River unmarshaller with no class filtering — enabling RCE via deserialization gadget chains on every cluster node.
CWE: CWE-502
NVD
HIGH
CVE-2026-18982
A flaw was found in the RHOAI training-operator. This vulnerability allows a user with standard edit or admin roles in any Kubernetes namespace to escalate their privileges. Through the creation of training jobs, an attacker can impersonate service accounts, access the host filesystem, and potential…
CWE: CWE-250
NVD
HIGH
CVE-2026-18951
A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly aggregates `trainjobs` management permissions into the native Kubernetes `edit ClusterRole`. This allows any user with `edit ClusterRole` permissions in a namespace to create, modify…
CWE: CWE-284
NVD
HIGH
CVE-2026-68341
In the Linux kernel, the following vulnerability has been resolved:
ovpn: fix use after free in unlock_ovpn()
unlock_ovpn() iterates over the release_list using llist_for_each_entry()
and drops the peer reference inside the loop body via ovpn_peer_put().
If this drops the last reference, the peer…
NVD
HIGH
CVE-2026-68294
In the Linux kernel, the following vulnerability has been resolved:
net: qrtr: restrict socket creation to the initial network namespace
QRTR keeps its entire port and node state in module-global variables
that are not partitioned per network namespace: qrtr_local_nid is a
single global node id (a…
NVD
HIGH
CVE-2026-68140
In the Linux kernel, the following vulnerability has been resolved:
net/iucv: fix use-after-free of a severed iucv_path
af_iucv queues not-yet-received message notifications on iucv->message_q,
each holding a raw pointer to the connection's iucv_path. When the peer
severs the connection, iucv_sev…
NVD
HIGH
CVE-2026-68128
In the Linux kernel, the following vulnerability has been resolved:
ice: reject out-of-range ptype in ice_parser_profile_init
set_bit(rslt->ptype, prof->ptypes) operates on a DECLARE_BITMAP of
ICE_FLOW_PTYPE_MAX (1024) bits. Nothing prevents a malicious VF from
providing ptype >= 1024 through VIRT…
NVD
HIGH
CVE-2026-68125
In the Linux kernel, the following vulnerability has been resolved:
mac802154: llsec: reject frames shorter than the authentication tag
llsec_do_decrypt_auth() computes the associated-data length for the
AEAD request as
assoclen += datalen – authlen;
where datalen is the number of bytes after t…
NVD
HIGH
CVE-2026-68108
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/vce: fix integer overflow in image size
Fix a security vulnerability where malicious VCE command streams
with oversized dimensions (e.g. 65536×65536) cause 32-bit integer
overflow, wrapping the calculated buffer size t…
NVD
HIGH
CVE-2026-68107
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu/vcn4: avoid rereading IB param length
Reuse the parameter length returned by
vcn_v4_0_enc_find_ib_param() instead of rereading it from
the IB.
This avoids a potential TOCTOU issue if the IB contents
change between read…
NVD
HIGH
CVE-2026-68098
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: bound DACL dedup walk to copied ACEs
set_ntacl_dacl() can stop copying ACEs before consuming the full input
DACL when size accounting overflows.
When that happens, num_aces reflects only the ACEs that were actually
copied …
NVD
HIGH
CVE-2026-68097
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: validate ACE size against SID sub-authorities
set_ntacl_dacl() validates sid.num_subauth before copying an ACE, but
does not verify that the declared ACE size contains all sub-authorities
described by that field. An undersi…
NVD
HIGH
CVE-2026-68091
In the Linux kernel, the following vulnerability has been resolved:
HID: wacom: stop hardware after post-start probe failures
wacom_parse_and_register() starts HID hardware before registering inputs
and initializing pad LEDs/remotes. Those later steps can fail, but their
error paths currently rele…
NVD
HIGH
CVE-2026-49478
Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Versions through 1.8.5 improperly follow cross-host redirects and attach Kubernetes ServiceAccount tokens during OIDC discovery, allowing a malicious or compromised issuer to perform blind …
CWE: CWE-918
NVD
HIGH
CVE-2026-18608
A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which defines its permissions, includes extensive privileges beyond what is necessary for its operation. These excessive permissions, such as the ability to execute commands within pods and manage cluster-wid…
CWE: CWE-250
NVD
HIGH
CVE-2026-20349
A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of servi…
CWE: CWE-244
GitHub-GHSA
HIGH
Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoS
GHSA-p28v-f755-9qrg
pkg: @trigger.dev/core
eco: npm
published: Aug 13, 2026
## Summary
The run-metadata update endpoint `PUT /api/v1/runs/:runId/metadata` applies client-supplied
"operations" by passing the **attacker-controlled `operation.key`** straight into
`new JSONHeroPath(operation.key).set(newMetadata, value)`
(`packages/core/src/v3/runMetadata/operations.ts:22-23`)…
CVE-2026-73654
NVD
HIGH
CVE-2026-73079
Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product subscriptions. From 0.1.135, to 0.1.168, platform API keys issued to tenants are exchanged for upstream requests made with shared provider accounts (ChatGPT/Codex OAuth, OpenAI platform keys, or an ope…
CWE: CWE-22, CWE-441
GitHub-GHSA
HIGH
Token Optimizer MCP: OS command injection in smart_user via username in get-user-info
GHSA-49mq-fc6q-3h46
pkg: @ooples/token-optimizer-mcp
eco: npm
published: Aug 14, 2026
### Summary
`token-optimizer-mcp` is vulnerable to OS command injection in the `smart_user` tool.
The `get-user-info` operation accepts a user-controlled `username` argument and later interpolates it into a shell command executed through `execAsync()`:
“`ts
getent passwd "${username}" || grep "^…
CVE-2026-55157
NVD
HIGH
CVE-2026-56865
A malicious GOPROXY was previously capable of forging up to two sumdb tiles that allow for a requested module to bypass the GOSUMDB check and persist attacker-controlled module content to a local Go module cache. This attack allows for a malicious GOPROXY to serve malicious module content that canno…
CWE: CWE-347
GitHub-GHSA
HIGH
MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`
GHSA-49m4-vp58-wgc9
pkg: stata-mcp
eco: pip
published: Aug 12, 2026
## Stata Command Injection via Unsanitized `package` in `ado_package_install`
### Summary
The `ado_package_install` MCP tool in `stata-mcp` concatenates user-controlled input directly into a Stata command string without any validation or sanitization. An attacker who can invoke the MCP tool or the…
CVE-2026-55071
NVD
HIGH
CVE-2026-67180
Google Turbinia allows arbitrary command execution via worker tasks. An attacker with privileges to submit a processing request or influence an evidence path/name obtains code execution on the worker fleet. Fixed on 2026-07-10.
CWE: CWE-78
NVD
HIGH
CVE-2026-8718
tls_opt_dtls_peer_connection_id_value_get() in subsys/net/lib/sockets/sockets_tls.c, which handles getsockopt(SOL_TLS, TLS_DTLS_PEER_CID_VALUE), passed the caller-supplied optval directly to mbedtls_ssl_get_peer_cid() without verifying the buffer was at least MBEDTLS_SSL_CID_OUT_LEN_MAX (default 32)…
CWE: CWE-787
NVD
HIGH
CVE-2026-68371
In the Linux kernel, the following vulnerability has been resolved:
usb: musb: omap2430: Do not put borrowed of_node in probe
omap2430_probe() stores pdev->dev.of_node in a local np variable. This is
a borrowed pointer and the probe function does not take a reference to
it.
The success and error …
NVD
HIGH
CVE-2026-19557
Use after free in TabStrip in Google Chrome on Mac prior to 151.0.7922.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD
HIGH
CVE-2026-69119
Taubyte Tau v1.1.10 contains a missing authorization vulnerability in the services/auth HTTP service that allows any authenticated user to read or permanently delete another tenant's project by supplying an arbitrary project ID to the GET and DELETE /projects/{id} endpoints. The GitHubTokenHTTPAuth …
CWE: CWE-639
NVD
HIGH
CVE-2026-56179
Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.
CWE: CWE-346
GitHub-GHSA
HIGH
Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket
GHSA-2j9v-p4xj-cjw2
pkg: github.com/lima-vm/lima/v2
eco: go
published: Aug 14, 2026
### Impact
On an instance of Lima running with `qemu` driver, an arbitrary user in the VM could access `/run/lima-guestagent.sock` when the guest agent is enabled.
This could result in running an arbitrary command with the root privileges in the VM (**not on the host**), as `lima-guestagent.sock` p…
CVE-2026-53657
NVD
HIGH
CVE-2026-73666
OpenChoreo is a developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.1, the OpenChoreo Backstage backend hardcoded backend.auth.dangerouslyDisableDefaultAuthPolicy and auth.providers.guest.dangerouslyAllowOutsideDevelopment to true, exposing /api/* without authentication and allowing un…
CWE: CWE-306
NVD
HIGH
CVE-2026-13048
Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the language attribute into the catalog filename.
load_lexicon builds the catalog path by appending `Messages/$lang.po` to the directory …
CWE: CWE-22, CWE-95
NVD
HIGH
CVE-2026-68118
In the Linux kernel, the following vulnerability has been resolved:
tcp: challenge ACK for non-exact RST in SYN-RECEIVED
The SYN-RECEIVED request-socket path in tcp_check_req() accepts an
in-window RST without requiring SEG.SEQ to exactly match RCV.NXT. A
non-exact RST therefore removes the reque…
NVD
HIGH
CVE-2026-72665
Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who is able to author and evaluate Elastic Security detection rules can c…
CWE: CWE-862
NVD
HIGH
CVE-2026-55987
OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)
CWE: CWE-863
NVD
HIGH
CVE-2026-73289
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS evaluates the ForAllValues: and ForAnyValue: set qualifiers with the negated string operators StringNotEquals, StringNotEqualsIgnoreCase, StringNotLike, ArnNotEquals, and ArnNotLike using each other's semanti…
CWE: CWE-863
NVD
HIGH
CVE-2026-73286
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS get_condition_values folds attacker-controlled request headers from HeaderMap into server-derived userid, username, principaltype, groups, versionid, signatureversion, jwt:, and ldap: condition keys, allowing…
CWE: CWE-863
NVD
HIGH
CVE-2026-19594
Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-deputy privilege escalation through two related weaknesses: path traversal (CWE-22) via unencoded `..` identifier path segments, and HTTP parameter pollution (CWE-141) via unencoded `…
CWE: CWE-22, CWE-141
NVD
HIGH
CVE-2026-18961
The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnerable to Authentication Bypass via Unverified Provider Email in all versions up to, and including, 1.4.3. This is due to the plugin trusting the unverified email field returned by …
CWE: CWE-287
NVD
HIGH
CVE-2026-72921
SeaweedFS is a distributed storage system. Prior to 4.24, the weed/server/filer_server_handlers.go allowed_prefixes authorization check used strings.HasPrefix on raw path strings, so a filer JWT scoped to /tenant1 also authorized sibling paths such as /tenant1234, /tenant1-old, and /tenant1backup, e…
CWE: CWE-863
NVD
HIGH
CVE-2026-72903
Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.235, a malicious SFTP server can return a backslash traversal filename through entry.name. In tabby-ssh/src/session/sftp.ts, SFTPSession.readdir() and _makeFile() use POSIX path processing that preserves the backslash…
CWE: CWE-22
NVD
HIGH
CVE-2026-68100
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl
set_ntacl_dacl() copies each ACE from the attacker-controlled stored
security descriptor verbatim into the response DACL without checking
sid.num_subauth. The ACE byte…
NVD
HIGH
CVE-2026-70454
rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation vulnerability that allows on-path attackers to intercept encrypted sessions by presenting self-signed or otherwise invalid certificates. Attackers can exploit the failure to valid…
CWE: CWE-295
NVD
HIGH
CVE-2026-65937
In WhatsUp Gold versions released before 2026.0.2, an authenticated attacker can bypass frontend controls and inject persistent script content.
CWE: CWE-79
NVD
HIGH
CVE-2026-68085
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled
HCI_UART_SENDING bit in tx_state means write_work is pending and blocks
queueing it again. Currently this bit is not cleared when canceling the
work in hci_u…
NVD
HIGH
CVE-2026-6726
An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and falsify other TPM 2.…
CWE: CWE-704
NVD
HIGH
CVE-2026-68116
In the Linux kernel, the following vulnerability has been resolved:
vxlan: mdb: Fix source list corruption on a failed replace
When replacing the source list of an MDB remote entry, all existing
sources are first marked for deletion and vxlan_mdb_remote_srcs_add()
is then called to add the new sou…
NVD
HIGH
CVE-2026-74270
In the Linux kernel, the following vulnerability has been resolved:
handshake: Require admin permission for DONE command
ACCEPT and DONE are the two downcalls of the handshake genl
family, both intended for use by the trusted handshake agent
(tlshd). ACCEPT already requires GENL_ADMIN_PERM; DONE h…
NVD
HIGH
CVE-2026-73505
Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, the setStyle() function in src/segments/path.go passed pt.Path, which includes raw folder names, to template.Render, whose function map exposes cmd, so an attacker-controlled directory name co…
CWE: CWE-94, CWE-1336
NVD
HIGH
CVE-2026-73325
Fujitsu Research's OneCompression library 1.2.0 contains an unsafe deserialization vulnerability that allows attackers to execute arbitrary code by supplying a crafted model.pt checkpoint file, as QuantizedModelLoader.load_quantized_model_pt() unconditionally calls torch.load with weights_only=False…
CWE: CWE-502
NVD
HIGH
CVE-2026-73231
Faker generates massive amounts of fake data in the browser and Node.js. Prior to 10.5.0, the faker.helpers.fake method in src/modules/helpers/eval.ts allows attacker-controlled fake templates to access the Function constructor through fakeEval.resolveProperty when a function returns another functio…
CWE: CWE-95
GitHub-GHSA
HIGH
Microsoft Security Advisory CVE-2026-62871 – .NET Elevation of Privilege Vulnerability
GHSA-vg44-h755-9hw7
pkg: Microsoft.WindowsDesktop.App.Runtime.win-arm64, Microsoft.WindowsDesktop.App.Runtime.win-x64, Microsoft.WindowsDesktop.App.Runtime.win-x86
eco: nuget
published: Aug 11, 2026
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in Windows Presentation Foundation. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
Out-of-bounds write in .NET …
CVE-2026-62871
GitHub-GHSA
HIGH
Microsoft Security Advisory CVE-2026-70354 – .NET Core Remote Code Execution Vulnerability
GHSA-gg8c-3338-xw2f
pkg: Microsoft.WindowsDesktop.App.Runtime.win-arm64, Microsoft.WindowsDesktop.App.Runtime.win-x64, Microsoft.WindowsDesktop.App.Runtime.win-x86
eco: nuget
published: Aug 11, 2026
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in Windows Presentation Foundation. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
An out-of-bounds write in .N…
CVE-2026-70354
GitHub-GHSA
HIGH
Microsoft Security Advisory CVE-2026-62886 – .NET Elevation of Privilege Vulnerability
GHSA-jqhp-238x-qhgf
pkg: Microsoft.WindowsDesktop.App.Runtime.win-arm64, Microsoft.WindowsDesktop.App.Runtime.win-x64, Microsoft.WindowsDesktop.App.Runtime.win-x86
eco: nuget
published: Aug 11, 2026
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in Windows Presentation Foundation. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
An integer overflow or wrapa…
CVE-2026-62886
NVD
HIGH
CVE-2026-61359
Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.
CWE: CWE-122
NVD
HIGH
CVE-2026-61358
Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.
CWE: CWE-59
NVD
HIGH
CVE-2026-61356
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
CWE: CWE-306
NVD
HIGH
CVE-2026-61355
Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
CWE: CWE-122
NVD
HIGH
CVE-2026-61353
Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CWE: CWE-122
NVD
HIGH
CVE-2026-61349
Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.
CWE: CWE-362, CWE-416
NVD
HIGH
CVE-2026-59127
Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally.
CWE: CWE-190
NVD
HIGH
CVE-2026-56174
Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.
CWE: CWE-426
NVD
HIGH
CVE-2026-54984
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.
CWE: CWE-122
NVD
HIGH
CVE-2026-54981
Inclusion of functionality from untrusted control sphere in Visual Studio Code – Python extension allows an unauthorized attacker to bypass a security feature locally.
CWE: CWE-693, CWE-829
NVD
HIGH
CVE-2026-42976
Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally.
CWE: CWE-306
NVD
HIGH
CVE-2026-72693
`openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged context. In the documented `kbrequest`/init usage, the ownership test in `authenticate_user()` relies on `stat("/proc/<pid>/fd/0")`. `stat()` on `/proc/<pid>/fd/0` follows the syml…
CWE: CWE-284
NVD
HIGH
CVE-2026-68222
In the Linux kernel, the following vulnerability has been resolved:
media: msi2500: Return queued buffers on start_streaming() failure
The vb2 framework hands buffers to the driver via buf_queue() before
calling start_streaming(). If start_streaming() returns an error
without first returning thos…
NVD
HIGH
CVE-2026-68121
In the Linux kernel, the following vulnerability has been resolved:
pppoe: reload header pointer after dev_hard_header()
pppoe_sendmsg() saves a pointer to the PPPoE header before calling
dev_hard_header(). Device header callbacks are allowed to reallocate the
skb head, invalidating pointers into …
NVD
HIGH
CVE-2026-68106
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: fix division by zero with invalid uvd dimensions
When width or height is less than 16, width_in_mb or height_in_mb
becomes 0, leading to fs_in_mb being 0. This causes a division by
zero when calculating num_dpb_buffer …
NVD
HIGH
CVE-2026-68104
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: invoke pm_genpd_remove() before freeing genpd
Call pm_genpd_remove() to unregister from global list prior to releasing
acp_genpd memory, and clear the pointer after free.
(cherry picked from commit cd8650d7a91ee8b768e…
NVD
HIGH
CVE-2026-48767
TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege guest member of a workspace to obtain a live Google Sheets OAuth access token for that workspace by calling the Google Sheets helper `getAccessToken`. The vulnerable path checks only whether the caller has read access …
CWE: CWE-200
NVD
HIGH
CVE-2026-18621
A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security hardening by submitting a malicious Argo Workflow through the V1 API path. This allows the API server to create pods with elevated privileges, acting as a 'confused deputy' on behalf of…
CWE: CWE-266
NVD
HIGH
CVE-2026-74795
Scriban before 6.6.0 contains an uncontrolled recursion vulnerability in its recursive-descent parser. The parser does not enforce a default expression depth limit (the ExpressionDepthLimit property in ParserOptions defaults to null/disabled), so an attacker who controls template input can supply a …
CWE: CWE-674
NVD
HIGH
CVE-2026-74792
Scriban before 7.0.0 (affected versions <= 6.6.0) contains a stack overflow vulnerability in nested array initializer parsing. Deeply nested array initializers recurse through a path (ParseArrayInitializer → ParseExpression → ParseArrayInitializer) that is not covered by the ExpressionDepthLimit…
CWE: CWE-674
NVD
HIGH
CVE-2026-74789
Scriban before 7.0.0 (affected <= 6.6.0) applies its LoopLimit constraint only to script loop statements and not to expensive iteration performed inside built-in operators and functions. As a result, a single expression such as {{ 1..1000000 | array.size }} — or a memory-amplification expression s…
CWE: CWE-400
NVD
HIGH
CVE-2026-74783
Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimit guard that fails to stop recursive descent parsing of deeply nested expressions. Attackers can supply templates with deeply nested parentheses, array initializers, object initializers, or unary operators to trigger an …
CWE: CWE-674
NVD
HIGH
CVE-2026-72330
In the Linux kernel, the following vulnerability has been resolved:
net/tls: Consume empty data records in tls_sw_read_sock()
A peer may send a zero-length TLS application_data record; TLS 1.3
explicitly permits these as a traffic-analysis countermeasure (RFC
8446, Section 5.1). After decryption s…
NVD
HIGH
CVE-2026-72254
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nft_fib: reject fib expression on the netdev egress hook
A fib expression in a netdev egress base chain dereferences nft_in(pkt),
NULL on the transmit path, causing a NULL pointer dereference at eval.
nft_fib_validate()…
NVD
HIGH
CVE-2026-56864
A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. This attack allows for a coordinating GOPROXY and GOSUMDB to serve a client malicious module content that cannot be detected by evaluating the transparency log. In order to determine if you…
CWE: CWE-347
GitHub-GHSA
HIGH
nltk: Arbitrary File Read via Path Traversal in nltk.data.load() through Percent-Encoded Sequences
GHSA-m42h-3232-vpv3
pkg: nltk
eco: pip
published: Aug 13, 2026
# Summary
nltk.data.load() and nltk.data.find() resolve user-supplied resource names to filesystem paths using url2pathname(), which decodes percent-encoded sequences (e.g. %2e%2e to ..). Path safety checks are performed on the raw, still-encoded string before decoding occurs. An attacker supplying …
CVE-2026-12243
NVD
HIGH
CVE-2026-73568
py-libp2p is the Python implementation of the libp2p networking stack. In 0.7.0 and earlier, the yamux handle_incoming() method in libp2p/stream_muxer/yamux/yamux.py reads an attacker-controlled 32-bit DATA frame length with read_exactly() before validating it against MAX_WINDOW_SIZE or checking whe…
CWE: CWE-400
NVD
HIGH
CVE-2024-58374
Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allows remote unauthenticated attackers to access protected resources by supplying a path traversal sequence in the request URI to bypass the oauthservlet authentication filter. Attackers …
CWE: CWE-89
NVD
HIGH
CVE-2026-14456
Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes
valid QUIC Initial packets for unknown destination connection IDs, it
can allocate and queue new incoming channels without enforcing any limit.
Impact summary: A remote peer that can make many Initial packets reach the
serve…
CWE: CWE-770
NVD
HIGH
CVE-2026-67991
crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in RubyLLM::Utils.underscore on Ruby 3.1.x. A very long crafted class, agent, or tool name can cause excessive CPU consumption and a denial of service.
CWE: CWE-1333
NVD
HIGH
CVE-2026-48702
Rekor is a software supply chain transparency log. Starting in version 0.3.0 and prior to version 1.5.2, the `Package.Unmarshal()` function in `pkg/types/alpine/apk.go` decompresses the signature and control gzip members of an APK file into in-memory buffers without bounding the total decompressed s…
CWE: CWE-770
NVD
HIGH
CVE-2026-19484
@fastify/busboy is a multipart form-data parser. In versions 3.1.0 through 3.2.0, a remote unauthenticated attacker can stall the Node.js event loop by sending a multipart request whose boundary is crafted to a specific length. The vendored streaming search stores its skip table in a fixed 256 entry…
CWE: CWE-835, CWE-1322
NVD
HIGH
CVE-2026-19481
@fastify/busboy is a multipart form-data parser. In versions 1.0.0 through 3.2.0, an attacker who can submit multipart form-data can crash the parser by sending a part header whose name is a prototype-inherited property such as __proto__ or constructor. The internal header parser stores headers in a…
CWE: CWE-754
GitHub-GHSA
HIGH
SIPSorcery: Malformed UDP datagram crashes TurnServer receive loop with no restart, disabling TURN UDP relay for all clients (DoS)
GHSA-pfvm-w89x-94jw
pkg: SIPSorcery
eco: nuget
published: Aug 12, 2026
## Summary
`TurnServer.ReceiveUdpAsync` places its generic `catch (Exception)` OUTSIDE the `while` receive loop, and `Start()` launches the loop fire-and-forget with no supervision or restart. A single pre-authentication UDP datagram whose STUN header first byte is in `0x80–0xFF` causes `STUNHeade…
GitHub-GHSA
HIGH
SIPSorcery vulnerable to Denial of Service via out-of-bounds read in SCTP SACK chunk parsing
GHSA-jwjp-4649-v8jp
pkg: SIPSorcery
eco: nuget
published: Aug 12, 2026
## Summary
`SctpSackChunk.ParseChunk` reads the `numGapAckBlocks` and `numDuplicateTSNs` fields (each up to 65535) directly from an attacker-controlled SCTP SACK chunk and loops that many times reading 4 bytes per iteration, with no validation of the counts against the chunk length or the receive bu…
GitHub-GHSA
HIGH
nimiq-blockchain: Validity store off by one error
GHSA-3763-qp59-59vf
pkg: nimiq-blockchain
eco: rust
published: Aug 12, 2026
### Impact
The validity store treats a transaction with stored `block_number = X` as "in window" only when `X > last_bn – transaction_validity_window_blocks` (strict inequality). However the protocol's `Transaction::is_valid_at` accepts a transaction for inclusion in any block in `[validity_start_he…
CVE-2026-46369
NVD
HIGH
CVE-2026-19558
Use after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: High)
CWE: CWE-416
NVD
HIGH
CVE-2026-73232
ffuf is a fast web fuzzer written in Go. Prior to 2.2.0, ffuf allows a malicious target server to cause an out-of-memory denial of service because the response size guard in pkg/runner/simple.go checks only the compressed Content-Length while io.ReadAll reads gzip, brotli, deflate, transparently dec…
CWE: CWE-409
NVD
HIGH
CVE-2026-48804
python-socketio is a Python implementation of the Socket.IO realtime client and server. The python-socketio server stores binary `EVENT` and `ACK` messages in memory while it waits to receive their binary attachments. Once all the attachments are received, these messages are then processed. Prior to…
CWE: CWE-770
NVD
HIGH
CVE-2026-48809
python-engineio is a Python implementation of the Engine.IO realtime client and server. Versions prior to 4.13.2 have two specific configurations of the python-engineio server in which the size of incoming messages is not checked before the messages are loaded into memory. An attacker can take advan…
CWE: CWE-770
NVD
HIGH
CVE-2026-48802
python-engineio is a Python implementation of the Engine.IO realtime client and server. Prior to version 4.13.2, an attacker can cause the creation of unnecessary background threads in the python-engineio server by exploiting the heartbeat mechanism, which launches a thread when a new connection is …
CWE: CWE-770
GitHub-GHSA
HIGH
Microsoft Security Advisory CVE-2026-62901 – .NET Denial of Service Vulnerability
GHSA-m93f-wj8c-rp8p
pkg: Microsoft.NETCore.App.Runtime.win-arm64, Microsoft.NETCore.App.Runtime.win-x64, Microsoft.NETCore.App.Runtime.win-x86
eco: nuget
published: Aug 11, 2026
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in System.Net.WebSockets. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
An unchecked input for loop condition …
CVE-2026-62901
GitHub-GHSA
HIGH
Microsoft Security Advisory CVE-2026-62898 – .NET Information Disclosure Vulnerability
GHSA-c494-m2fq-59mx
pkg: Microsoft.NETCore.App.Runtime.win-arm64, Microsoft.NETCore.App.Runtime.win-x64, Microsoft.NETCore.App.Runtime.win-x86
eco: nuget
published: Aug 11, 2026
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in Microsoft QUIC. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
A use after free in Microsoft QUIC allows an …
CVE-2026-62898
NVD
HIGH
CVE-2026-72713
XAgent contains a path traversal vulnerability in the workspace file endpoint that allows self-registered or default-credential users to read arbitrary files on the host by supplying parent-directory segments in the `file_name` form field with no path containment check. Attackers can register an acc…
CWE: CWE-22
NVD
HIGH
CVE-2026-73089
Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, index.js retains every distinct `(queries, context)` result in cache and every parseQueries() AST in parseCache without a size cap, TTL, or eviction, allowing an attacker w…
CWE: CWE-770
NVD
HIGH
CVE-2026-73088
Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, normalizeStats() in node.js, reached unconditionally through getStat() and loadStat() on every browserslist() call, processes untrusted browserslist-stats.json, opts.stats,…
CWE: CWE-248, CWE-1321
NVD
HIGH
CVE-2026-59132
Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.
CWE: CWE-476
NVD
HIGH
CVE-2026-54113
Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network.
CWE: CWE-770
NVD
HIGH
CVE-2026-72605
A missing authentication vulnerability in Swing Music 3.0.0 allows unauthenticated remote attackers to create arbitrary user accounts via the POST /auth/profile/create endpoint. The endpoint is allowlisted from JWT verification, permitting unauthenticated account creation. An attacker can register a…
CWE: CWE-306
NVD
HIGH
CVE-2026-68131
In the Linux kernel, the following vulnerability has been resolved:
rbd: Reset positive result codes to zero in object map update path
In a reply message to an RBD request, a positive result code indicates
a data payload, which is not allowed for writes. While
rbd_osd_req_callback() already resets…
NVD
HIGH
CVE-2026-68129
In the Linux kernel, the following vulnerability has been resolved:
gve: fix Rx queue stall on alloc failure
When the system is under extreme memory pressure, page allocations can
fail during the Rx buffer refill loop. If the number of buffers posted
to hardware falls below a critical low threshol…
NVD
HIGH
CVE-2026-68120
In the Linux kernel, the following vulnerability has been resolved:
rtase: Workaround for TX hang caused by hardware packet parsing
The hardware performs packet parsing before packet transmission.
Parsing incomplete IPv4, IPv6, TCP, or UDP headers may trigger a TX
hang because the hardware parser …
NVD
HIGH
CVE-2026-68119
In the Linux kernel, the following vulnerability has been resolved:
tcp: initialize standalone TCP-AO response padding
tcp_v4_send_ack() and tcp_v6_send_response() construct standalone TCP
responses with TCP-AO options. The option length carries the actual MAC
length, but the TCP header length in…
NVD
HIGH
CVE-2026-68096
In the Linux kernel, the following vulnerability has been resolved:
audit: fix recursive locking deadlock in audit_dupe_exe()
A deadlock occurs in the audit subsystem when duplicating
executable-related rules.
When a file is moved (e.g., via do_renameat2()), the VFS layer locks
the parent directo…
NVD
HIGH
CVE-2026-65942
TLS hostname verification issue in Apache Ranger Client Code in versions <= 2.8.0.
Users are recommended to upgrade to version 2.9.0, which fixes this issue.
CWE: CWE-297
NVD
HIGH
CVE-2026-73655
Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.2, addGoogleStrategy() in apps/webapp/app/services/googleAuth.server.ts passes a Google profile email to findOrCreateGoogleUser() in apps/webapp/app/models/user.server.ts without requiring Google…
CWE: CWE-287
NVD
HIGH
CVE-2026-15554
the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authentication. This enables an unauthenticated attacker with direct TCP access to port 8009 to bypass CLIENT-CERT authentication by injecting a forged X.509 certificate via the AJP protoc…
CWE: CWE-295
NVD
HIGH
CVE-2026-18511
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to generate a stack-based buffer overflow in the Native IBM i JSSE provider, caused by improper bounds checking during TLS session establishment. A local attacker could overflow a fixed-length buffer and execute arbitrary code o…
CWE: CWE-787
NVD
HIGH
CVE-2026-74564
In the Linux kernel, the following vulnerability has been resolved:
netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH
The XT_HASHLIMIT_RATE_MATCH flag mode changes the semantics of the
dsthash_ent structure which represents an entry in the hashtable. There
is a union ar…
GitHub-GHSA
HIGH
mchange-commons-java contains elements susceptible to abuse via JNDI injection and "deserialization gadgets"
GHSA-h84g-69h7-mw6v
pkg: com.mchange:mchange-commons-java
eco: maven
published: Aug 14, 2026
### Impact
Prior to version 0.6.0, mchange-commons-java includes a JNDI `ObjectFactory` implementation (`com.mchange.v2.naming.JavaBeanObjectFactory`) willing to construct objects of arbitrary classes and initialize "JavaBean"-style properties. There are classes for which this kind of initialization…
CVE-2026-55153
NVD
HIGH
CVE-2026-72632
Observable Discrepancy (CWE-203) in Kibana Fleet can lead to information disclosure via Excavation (CAPEC-116). Fleet removes the Elasticsearch API key value of an enrolled Elastic Agent from the responses of its agent listing capability, but that capability accepted caller-supplied filter expressio…
CWE: CWE-203
GitHub-GHSA
HIGH
SSH.NET: ScpClient Recursive Download Allows Arbitrary File Write via Server-Controlled SCP Filenames
GHSA-q939-rpr3-3284
pkg: SSH.NET
eco: nuget
published: Aug 12, 2026
## Summary
`ScpClient.Download(string directoryName, DirectoryInfo directoryInfo)` writes files and directories using names returned by the remote SCP server during recursive downloads, with no validation that the resulting path stays inside the requested local directory. A malicious, compromised, …
CVE-2026-48798
NVD
HIGH
CVE-2026-73291
Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.4.0, Seerr's ImageProxy in server/lib/imageproxy.ts uses the upstream ETag and Content-Type response headers to build a cache filename for the unauthenticated GET /avatarproxy/:jellyfinUserId…
CWE: CWE-22, CWE-94
NVD
HIGH
CVE-2026-63177
Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access control enforced in the Nginx OpenResty Lua layer evaluates the raw, unnormalized `ngx.var.request_uri`, while Nginx itself routes requests using the normalized path. An authenticated low-privilege user can…
CWE: CWE-863
NVD
HIGH
CVE-2026-48495
TypeBot is a chatbot builder tool. Prior to version 3.17.0, the Google Sheets OAuth callback decodes a base64-encoded JSON `state` parameter and trusts the embedded `workspaceId`, `typebotId`, `blockId`, and `redirectUrl` without cryptographic integrity protection or authorization checks. The callba…
CWE: CWE-862
NVD
HIGH
CVE-2026-42142
TypeBot is a chatbot builder tool. Prior to version 3.17.0, the `handleGetSheets` API handler (`POST /api/sheets/getSheets`) does not validate workspace membership, allowing any authenticated user to access and decrypt another workspace's Google Sheets OAuth credentials and retrieve spreadsheet data…
CWE: CWE-862
NVD
HIGH
CVE-2026-68103
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: reject mapping a reserved doorbell to a new queue
When creating an user-queue, the user space
provides a doorbell BO handle and an offset within
the bo to obtain a doorbell.
However current implementation using xa_sto…
NVD
HIGH
CVE-2026-53996
NetBSD's hdaudio(4) driver in sys/dev/hdaudio/hdaudio.c contains a missing access control vulnerability that allows unprivileged local attackers to invoke the HDAUDIO_FGRP_SETCONFIG ioctl without elevated permissions by exploiting the absence of an access check on /dev/hdaudioN device nodes. Attacke…
CWE: CWE-862
GitHub-GHSA
HIGH
Microsoft Security Advisory CVE-2026-62897 – .NET Remote Code Execution Vulnerability
GHSA-fx4q-gjrx-2jw6
pkg: Microsoft.WindowsDesktop.App.Runtime.win-arm64, Microsoft.WindowsDesktop.App.Runtime.win-x64, Microsoft.WindowsDesktop.App.Runtime.win-x86
eco: nuget
published: Aug 11, 2026
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in Windows Presentation Foundation. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
An integer overflow or wrapa…
CVE-2026-62897
NVD
HIGH
CVE-2026-61361
Use after free in Windows DHCP Client allows an authorized attacker to execute code locally.
CWE: CWE-416
NVD
HIGH
CVE-2026-61348
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CWE: CWE-416
NVD
HIGH
CVE-2026-61346
Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.
CWE: CWE-416
NVD
HIGH
CVE-2026-59126
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.
CWE: CWE-362
NVD
HIGH
CVE-2026-59122
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CWE: CWE-362, CWE-416
NVD
HIGH
CVE-2026-50472
Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.
CWE: CWE-122
GitHub-GHSA
HIGH
OpenAM Insecure SSO Cookie Initialization
GHSA-fpmh-vx4h-xc33
pkg: org.openidentityplatform.openam:openam-core
eco: maven
published: Aug 14, 2026
## Summary
**Description**
An Insecure Default Initialization of Resource (CWE-1188) issue in the OpenAM default configuration ships the `iPlanetDirectoryPro` SSO cookie with `HttpOnly=false`. Also, the `iPlanetDirectoryPro` SSO cookie is used as a CSRF token in OAuth/OIDC flows. This affects OpenA…
CVE-2026-53660
GitHub-GHSA
HIGH
Budibase: SSRF in Automation Steps – Webhook, Zapier, N8N, Slack, Discord Bypass IP Blacklist
GHSA-5fpj-28rv-84r7
pkg: @budibase/server
eco: npm
published: Aug 14, 2026
## Summary
Budibase automation steps (outgoing webhook, Zapier, n8n, Slack, Discord, Make.com) make server-side HTTP requests to user-provided URLs using `node-fetch` directly, completely bypassing the IP blacklist protection that exists in the REST API integration. Additionally, the REST API black…
CVE-2026-35219
GitHub-GHSA
HIGH
Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts
GHSA-29rf-f4vv-pvq6
pkg: github.com/authorizerdev/authorizer
eco: go
published: Aug 14, 2026
The OAuth callback handler links incoming OAuth identities (Google, GitHub, etc.) to existing accounts matched by email address without verifying that the existing account's email was verified by its original owner. An attacker who pre-registers with a victim's email address (without verifying it) g…
CVE-2026-35511
GitHub-GHSA
HIGH
atomic-agents-stack: Dashboard HTTP server path traversal allows arbitrary file read
GHSA-rm43-82j9-r4mj
pkg: atomic-agents-stack
eco: pip
published: Aug 13, 2026
The optional dashboard HTTP server (`atomic_agents/dashboard/serve.py`) builds filesystem paths directly from the request path and serves them without a containment check. It is the only per-request untrusted-path site in the codebase that does not route through `_io.safe_resolve_under`. Literal `..…
GitHub-GHSA
HIGH
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)
GHSA-48p8-g2fx-3wwm
pkg: github.com/argoproj/argo-workflows/v4, github.com/argoproj/argo-workflows/v3, github.com/argoproj/argo-workflows
eco: go
published: Aug 13, 2026
### Summary
The allow-list fix for CVE-2026-31892 (GHSA-3wf5-g532-rcrr), and its follow-up coverage of `hostNetwork`/`securityContext`/`serviceAccountName` in GHSA-3775-99mw-8rp4, is incomplete. `workflow/util/merge.go` `ValidateUserOverrides` / `SanitizeUserWorkflowSpec` walk only the top-level fi…
CVE-2026-54526
GitHub-GHSA
HIGH
Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv)
GHSA-cxgv-hp74-jj7r
pkg: ansible-jailexec
eco: pip
published: Aug 12, 2026
Through version 1.3.0, the jailexec connection plugin's put_file resolved a transfer's destination to a path on the jail host (<jail filesystem root> + <destination>) and ran mkdir -p and mv there as root on the host. Those commands follow symbolic links, and the path was operated on outside the jai…
CVE-2026-55074
GitHub-GHSA
HIGH
SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access
GHSA-w62w-66v9-vvgv
pkg: github.com/seaweedfs/seaweedfs
eco: go
published: Aug 12, 2026
## Summary
The S3 API gateway and the Iceberg REST catalog gateway construct their routers with `mux.NewRouter().SkipClean(true)`. With path cleaning disabled, a `..` segment inside the URL survives routing, so a request such as:
“`
GET /bucket-A/../evil-bucket/key
“`
is matched as `bucket=buck…
CVE-2026-54917
GitHub-GHSA
HIGH
compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0
GHSA-h47f-gmjp-m7rr
pkg: compliance-trestle
eco: pip
published: Aug 12, 2026
### Summary
`compliance-trestle` 4.0.3 (latest) ships an `URLSecurityValidator` in `trestle/core/remote/security.py` to block SSRF to loopback / link-local / cloud-metadata endpoints from the HTTPSFetcher and SFTPFetcher remote-fetch paths. The allowlist is incomplete and can be bypassed by four eq…
CVE-2026-52776
GitHub-GHSA
MEDIUM
Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials
GHSA-h7p7-w5gc-xj3w
pkg: pydantic-ai-slim, pydantic-ai-slim, pydantic-ai
eco: pip
published: Aug 13, 2026
### Summary
A client that can submit message history to a Pydantic AI UI adapter can reference arbitrary files in the application's model-provider or cloud-storage account. The server forwards the reference to the model provider, which fetches it using the server's own credentials, allowing the cli…
CVE-2026-54249
GitHub-GHSA
MEDIUM
ep_etherpad-lite: Device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author token
GHSA-vqfp-p66c-xrp9
pkg: ep_etherpad-lite
eco: npm
published: Aug 13, 2026
Etherpad's device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author token in the GET response body
## Description
Etherpad ships an endpoint pair under `/tokenTransfer` (`src/node/hooks/express/tokenTransfer.ts`) that lets a logged-in user move…
CVE-2026-55088
NVD
MEDIUM
CVE-2026-73611
File Browser versions from 2.50.0 through 2.63.21 fail to validate JWT expiration when proxy authentication is configured with a non-default logout page. Attackers with a previously valid token can access protected routes and administrative endpoints indefinitely, and exchange expired tokens for fre…
CWE: CWE-613
NVD
MEDIUM
CVE-2026-73419
NextAuth.js provides authentication for Next.js. Prior to@auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, Auth.js stores the OAuth/OIDC anti-CSRF checks state, nonce, and the PKCE verifier in global cookies that are not bound to the provider that created them. On callback, a check value mi…
CWE: CWE-345, CWE-346, CWE-940
NVD
MEDIUM
CVE-2026-65940
In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible location on the host server.
CWE: CWE-276, CWE-732
NVD
MEDIUM
CVE-2026-65939
In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root.
CWE: CWE-22, CWE-73, CWE-434
NVD
MEDIUM
CVE-2026-49349
regclient is a Docker and OCI Registry Client in Go. Prior to version 0.11.5, credentials for a registry may be inadvertently leaked to external servers. A prerequisite for this attack is a malicious registry server, a malicious blob store, or a registry that does not restrict the external URLs for …
CWE: CWE-522
NVD
MEDIUM
CVE-2026-19278
A flaw was found in StackRox/RHACS Central's Auth Machine-to-Machine (M2M) token exchange. When an administrator configures M2M role mappings, the system uses unanchored regular expressions for matching claim values. This allows an attacker with a valid OpenID Connect (OIDC) token, whose claim value…
CWE: CWE-625
NVD
MEDIUM
CVE-2026-66016
Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessible to highly privileged local users.
CWE: CWE-312
GitHub-GHSA
MEDIUM
Microsoft Security Advisory CVE-2026-62909 – .NET Elevation of Privilege Vulnerability
GHSA-9mr8-pwpw-3j2w
pkg: Microsoft.NETCore.App.Runtime.linux-arm, Microsoft.NETCore.App.Runtime.linux-arm64, Microsoft.NETCore.App.Runtime.linux-musl-arm
eco: nuget
published: Aug 11, 2026
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET diagnostics IPC. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
A missing error check in .NET causes an…
CVE-2026-62909
NVD
MEDIUM
CVE-2026-71969
OP-TEE OS through 4.10.0, fixed in commit 7b8b494, contains a buffer underwrite vulnerability in the RSA NOPAD encrypt and decrypt operations within the mbedTLS software backend and SE050 hardware driver that allows a malicious Trusted Application to corrupt secure-world heap memory by supplying an …
CWE: CWE-124, CWE-787
NVD
MEDIUM
CVE-2026-71968
OP-TEE OS through 4.10.0, fixed in commit 8794043, contains a use-after-free vulnerability in the Trusted Application loader that allows attackers with the ability to load a signed Trusted Application to corrupt secure-world kernel memory by setting the TA_FLAG_CONCURRENT flag in a user TA signed he…
CWE: CWE-362, CWE-416
GitHub-GHSA
MEDIUM
ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)
GHSA-9hgc-g3w5-67cm
pkg: mcp-contextforge-gateway
eco: pip
published: Aug 14, 2026
## Summary
The `/admin/gateways/test` endpoint validates submitted URLs by resolving the hostname at validation time and blocking private address ranges. The HTTP client independently re-resolves DNS at connection time with no IP binding between the two operations, creating a TOCTOU window exploita…
CVE-2026-53708
NVD
MEDIUM
CVE-2026-73330
CamaleonCMS 2.9.1 contains a server-side template injection vulnerability that allows authenticated administrators to execute arbitrary commands by embedding ERB tags in the email parameter of the test_email settings action, which are evaluated when an SMTP rejection reflects the recipient address b…
CWE: CWE-1336
NVD
MEDIUM
CVE-2026-74785
Scriban before 7.0.0 contains three distinct denial-of-service vulnerabilities in expression evaluation that bypass existing safety controls through unbounded string multiplication, uncontrolled BigInteger shift operations, and LoopLimit bypass via range enumeration in builtin functions. Attackers w…
CWE: CWE-400
GitHub-GHSA
MEDIUM
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
GHSA-8rw6-p7m8-63jp
pkg: surrealdb
eco: rust
published: Aug 14, 2026
A `SELECT` permission defined on an array element (`DEFINE FIELD field.* … PERMISSIONS FOR select …`) is not enforced correctly for `RECORD` users. Instead of hiding the denied elements, the query leaks a subset of them: a deny-all returns the odd-indexed elements, and a per-element predicate ke…
NVD
MEDIUM
CVE-2026-72664
Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who holds only detection rule authoring privileges for the Elastic Security solution …
CWE: CWE-862
NVD
MEDIUM
CVE-2026-72663
Inefficient Algorithmic Complexity (CWE-407) in Kibana can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted, deeply nested expression submitted to a Kibana TSVB visualization is evaluated with a worst-case cost that grows disproportionately with the size of the …
CWE: CWE-407
NVD
MEDIUM
CVE-2026-72648
Cleartext Storage of Sensitive Information in an Environment Variable (CWE-526) in Elastic Cloud on Kubernetes (ECK) can lead to information disclosure via Retrieve Embedded Sensitive Data (CAPEC-37). When ECK reconciles a Fleet Server resource that authenticates to Elasticsearch with a service acco…
CWE: CWE-526
NVD
MEDIUM
CVE-2026-72640
The Elastic Cloud on Kubernetes (ECK) operator reads a list of secret references from an annotation on secrets it manages, and it accepts the namespace recorded in each reference without validating that the reference is authorized for the resource being reconciled. A user whose Kubernetes permission…
CWE: CWE-441
NVD
MEDIUM
CVE-2026-49089
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A query expression accepted by a connector reporting operation was processed without any limit on its size, and an oversized expression caused the Kibana proce…
CWE: CWE-770
GitHub-GHSA
MEDIUM
vLLM: Completion prompt lists fan out into unbounded engine requests
GHSA-87×5-vmc3-756j
pkg: vllm
eco: pip
published: Aug 13, 2026
## Summary
The `/v1/completions` request model accepts `prompt` as a list of text prompts or a list of token-id prompts without any outer prompt-count bound. The serving path turns each element into a separate engine input, creates one engine generator per element, merges all generators, and alloca…
CVE-2026-73559
NVD
MEDIUM
CVE-2026-14663
Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of the faulty ciphertext. The OpenSSL version and OpenSSL configuration determine the disabled ciphers. If the application accepts encrypted data as input, decryption will succeed e…
CWE: CWE-313, CWE-345
GitHub-GHSA
MEDIUM
Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint
GHSA-88p2-jj8w-j8qg
pkg: github.com/fleetdm/fleet/v4
eco: go
published: Aug 12, 2026
### Summary
The target search endpoint (`POST /api/latest/fleet/targets`) returned team enroll secrets and full team configuration, including credential-bearing agent options, to observer-class users. Other team-facing endpoints mask these fields for observers; the target search endpoint did not ap…
CVE-2026-48786
NVD
MEDIUM
CVE-2026-68868
The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections and Variables: the caller's `team_name` was accepted by the backend but dropped at the internal call boundary, so every lookup resolved against the team-agnosti…
CWE: CWE-1220
GitHub-GHSA
MEDIUM
Microsoft Security Advisory CVE-2026-62902 – .NET Information Disclosure Vulnerability
GHSA-9mrh-pw7c-9mqm
pkg: Microsoft.WindowsDesktop.App.Runtime.win-arm64, Microsoft.WindowsDesktop.App.Runtime.win-x64, Microsoft.WindowsDesktop.App.Runtime.win-x86
eco: nuget
published: Aug 11, 2026
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in Windows Presentation Foundation. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
A specially crafted document…
CVE-2026-62902
NVD
MEDIUM
CVE-2026-69117
NetBox 4.5.8 contains an ORM injection vulnerability that allows authenticated attackers, including those with read-only API tokens, to inject arbitrary Django ORM lookup expressions into nested object references by supplying crafted JSON dictionary keys in POST, PUT, or PATCH requests to any REST A…
CWE: CWE-639
NVD
MEDIUM
CVE-2026-72739
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the createCommand() function constructs shell commands by interpolating compose service names and configuration into bash command strings. When a compose with a maliciously crafted name or service definition is deployed…
CWE: CWE-78
NVD
MEDIUM
CVE-2026-65945
Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0
Users are recommended to upgrade to version 2.9.0, which fixes this issue.
CWE: CWE-532
NVD
MEDIUM
CVE-2026-19751
A flaw has been found in EnzoVezzaro mcp-dominican-layer up to 39dd373786712650097ad31db27d5c477c8f9c82. The affected element is the function axios.get of the file src/index.ts of the component parse-csv tool. This manipulation of the argument csvUrl causes server-side request forgery. The attack is…
CWE: CWE-918
NVD
MEDIUM
CVE-2026-73576
In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability exists in the OnlyOffice integration. The zimbraDocumentEditingJwtSecret is generated using an insecure random number generator, resulting in insufficient entropy. An attacker who obtains a JWT signed with…
CWE: CWE-1241
GitHub-GHSA
MEDIUM
Duplicate Advisory: Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint
GHSA-4jjw-pwvw-q6w3
pkg: nuxt
eco: npm
published: Aug 11, 2026
## Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-7c4v-fwgw-9rf7. This link is maintained to preserve external references.
## Original Description
Nuxt versions >= 4.4.7 and < 4.5.1, and >= 3.21.7 and < 3.21.10, contain an information disclosure vulnerabilit…
NVD
MEDIUM
CVE-2026-73671
Saurus CMS Community Edition contains an unauthenticated open redirect vulnerability in the logout handling code in classes/port.inc.php, where the url parameter supplied via GET or POST is passed directly to the Location header without domain allowlist, scheme validation, or relative path enforceme…
CWE: CWE-601
GitHub-GHSA
MEDIUM
ep_etherpad-lite: Cache-poisoning Cross-site Scripting and Open Redirect via x-proxy-path Header
GHSA-fjgc-3mj7-8rg8
pkg: ep_etherpad-lite
eco: npm
published: Aug 13, 2026
# GHSA-03 — `x-proxy-path` header reflected into admin HTML/JS/CSS (cache-poisoning XSS) and concatenated into redirect (open-redirect)
**Severity:** Medium
**CVSS v3.1 vector:** `CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N`
**CVSS suggested base score:** ~6.1 — Medium
*(Re-validate in the f…
CVE-2026-55087
NVD
MEDIUM
CVE-2026-73084
Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /api/redirect OAuth callback endpoint embeds the user-supplied code query parameter directly into an inline script block without proper escaping. A crafted request to /api/redirect with a malicious code value can br…
CWE: CWE-79, CWE-94
NVD
MEDIUM
CVE-2026-69116
FlyEnv before 4.18.0 fails to sanitize HTML from markdown rendering and AI chat content passed to Vue v-html directives. Attackers can inject malicious scripts through markdown sources or chat messages that execute in the Electron renderer process with access to Node.js APIs and the filesystem.
CWE: CWE-79
NVD
MEDIUM
CVE-2026-66455
Subscriber Broken Access Control in ReactPress <= 3.4.0 versions.
CWE: CWE-862
NVD
MEDIUM
CVE-2026-12233
The PSA Protected Storage credential backend (subsys/net/lib/tls_credentials/tls_credentials_trusted.c) declared its credential-store mutex as a plain zero-filled static struct k_mutex credential_lock; and never called k_mutex_init() on it. A statically zero-filled k_mutex has an uninitialized wait …
CWE: CWE-665
GitHub-GHSA
MEDIUM
Microsoft Security Advisory CVE-2026-62899 – .NET Security Feature Bypass Vulnerability
GHSA-r6mh-95jw-g7qg
pkg: Microsoft.NETCore.App.Runtime.linux-arm, Microsoft.NETCore.App.Runtime.linux-arm64, Microsoft.NETCore.App.Runtime.linux-musl-arm
eco: nuget
published: Aug 11, 2026
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in System.Net.HttpListener. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
Inconsistent interpretation of http …
CVE-2026-62899
NVD
MEDIUM
CVE-2026-73068
ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.207, the ToolJet Database HTTP API in server/src/modules/tooljet-db/controller.ts authorizes operations against the :organizationId URL path value without ver…
CWE: CWE-639
NVD
MEDIUM
CVE-2026-72800
SiYuan versions before v3.7.4 fail to apply publish-access filtering to the getAttributeViewKeysByID endpoint, allowing authenticated readers to retrieve complete database column schemas including descriptions, select vocabularies, and template expressions. Additionally, getBlockDefIDsByRefText and …
CWE: CWE-862
NVD
MEDIUM
CVE-2026-73308
Budibase is an open-source low-code platform. Prior to 3.39.25, packages/server/src/api/controllers/automation.ts returned automation test results containing trigger.outputs.user.oauth2, broadcast BuilderSocketEvent.AutomationTestProgress to the app room, and stored progress in packages/server/src/a…
CWE: CWE-200
NVD
MEDIUM
CVE-2026-73647
Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the public extend() utility in ui/src/utils/extend/extend.js recursively copied attacker-controlled object keys during extend(true, target, source) deep merges without rejecting an own __proto__ pr…
CWE: CWE-1321
NVD
MEDIUM
CVE-2026-19964
A vulnerability was found in Jij-Inc Jij-MCP-Server 0.1.0. This affects the function PythonREPL.run of the file jij_mcp/python_repr.py of the component jm_check. The manipulation of the argument code results in code injection. It is possible to launch the attack remotely. The exploit has been made p…
CWE: CWE-74, CWE-94
NVD
MEDIUM
CVE-2026-48790
Turso CLI is the command line interface (CLI) to the open-source database Turso. Versions prior to 1.0.26 persist the user's Turso platform JWT to `settings.json` using Viper's default `configPermissions` of `0o644`, leaving the credential file world-readable on standard Linux and macOS systems. Any…
CWE: CWE-276, CWE-732
NVD
MEDIUM
CVE-2026-61360
Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally.
CWE: CWE-822
NVD
MEDIUM
CVE-2026-61347
Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally.
CWE: CWE-126
NVD
MEDIUM
CVE-2026-59137
Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally.
CWE: CWE-908
NVD
MEDIUM
CVE-2026-59136
Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally.
CWE: CWE-908
NVD
MEDIUM
CVE-2026-59135
Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.
CWE: CWE-1390
NVD
MEDIUM
CVE-2026-59128
Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally.
CWE: CWE-125
NVD
MEDIUM
CVE-2026-18942
A flaw was found in the Feast operator. A malicious tenant could inject arbitrary code into their feature repository. This code would be executed by an automated process with elevated privileges, allowing the tenant to steal sensitive credentials. This could lead to a direct escalation of privileges…
CWE: CWE-94
NVD
MEDIUM
CVE-2026-74240
A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and single sign-on (SSO) authentication. Multiple issues related to audience verification and the enforcement of `azp` and `sub` claims were identified. These flaws could allow an attacker with a validly-…
CWE: CWE-287
NVD
MEDIUM
CVE-2026-19135
A JEXL expression sandbox bypass exists in multiple versions of OpenNMS Meridian and Horizon. A low-privileged authenticated user can submit a crafted expression to the Measurements REST API that escapes the sandbox and loads arbitrary Java classes on the server. This can potentially allow an attack…
CWE: CWE-470
GitHub-GHSA
MEDIUM
tablib: Stored XSS in the HTML export via unescaped dataset title
GHSA-gqgw-jghv-mxwx
pkg: tablib
eco: pip
published: Aug 12, 2026
tablib prior to 3.10.0 contains a stored cross-site scripting vulnerability in the HTML export functionality that allows attackers to execute arbitrary JavaScript by embedding malicious payloads in dataset titles, which are interpolated unsanitized into HTML output via the export_book method in the …
CVE-2026-9318
GitHub-GHSA
MEDIUM
s2n-quic has excessive memory allocation
GHSA-9q54-f358-3fqf
pkg: s2n-quic
eco: rust
published: Aug 14, 2026
s2n-quic is a Rust implementation of the QUIC protocol. An unauthenticated user can attempt to exhaust server memory on an s2n-quic endpoint by sending crafted CRYPTO frames with high offsets. The buffer used for processing CRYPTO frames does not enforce a maximum size. In the worst case, a single 1…
CVE-2026-10740
GitHub-GHSA
MEDIUM
Token Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API Endpoints
GHSA-76pc-mqxp-3rq5
pkg: @ooples/token-optimizer-mcp
eco: npm
published: Aug 14, 2026
# Unauthenticated Path Traversal in Dashboard Session Log API Endpoints
| Field | Value |
| —————- | —– |
| Repository | ooples/token-optimizer-mcp |
| Affected version | 5.0.1 (commit 8137147) |
| Vulnerability | CWE-22 — Improper Limitation of a Pathname to a Re…
CVE-2026-55156
NVD
MEDIUM
CVE-2026-73845
CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, the ckan_get_mqa_quality and ckan_get_mqa_quality_details tools in src/tools/quality.ts use isValidMqaServer to validate the server_url parameter with a prefix-only regular expression for dati.gov.it, allowing suffix-ho…
CWE: CWE-20, CWE-625, CWE-918
NVD
MEDIUM
CVE-2026-73840
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, the POST /api/v1alpha1/autobuild endpoint in internal/openchoreo-api/api/handlers/webhook_handler.go selected a webhook provider from caller-controlled X-Event-Key, accepted Bitbucket requ…
CWE: CWE-287, CWE-290, CWE-345
NVD
MEDIUM
CVE-2026-58507
Private Repository Existence Disclosure via go-get Meta Endpoint
CWE: CWE-284
NVD
MEDIUM
CVE-2026-19487
Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.
The prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one re…
CWE: CWE-670
NVD
MEDIUM
CVE-2026-73556
vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the structured_outputs.regex parameter in vllm/v1/structured_output/backend_lm_format_enforcer.py is passed to lmformatenforcer.RegexParser without compile_regex_with_timeout or validation in validate_structured_outp…
CWE: CWE-400, CWE-1333
NVD
MEDIUM
CVE-2026-73555
vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the validation_exception_handler in vllm/entrypoints/openai/server_utils.py converts FastAPI RequestValidationError objects with str(exc), and sanitize_message in vllm/entrypoints/utils.py does not remove traceback-s…
CWE: CWE-209
NVD
MEDIUM
CVE-2026-66384
An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
CWE: CWE-22
NVD
MEDIUM
CVE-2026-33921
The Windows installer deployed Npcap leaving its access restriction option at the insecure default value, so the driver was accessible to every local user of the host instead of being restricted to administrators only. A local user without administrative privileges could use the Npcap driver to capt…
CWE: CWE-1188
NVD
MEDIUM
CVE-2026-73304
Budibase is an open-source low-code platform. Prior to 3.39.25, GET /api/users/metadata and GET /api/users/metadata/:id returned user objects processed by packages/server/src/utilities/global.ts without removing oauth2.accessToken or oauth2.refreshToken. A user with the POWER role could retrieve the…
CWE: CWE-200
NVD
MEDIUM
CVE-2026-67613
CyberPanel before 3.0.0 contains a path traversal vulnerability that allows authenticated administrators to read arbitrary files from the server filesystem by supplying unsanitized file paths to the cloudAPI ReadReport endpoint. Attackers can manipulate the reportFile parameter in the JSON request b…
CWE: CWE-22
NVD
MEDIUM
CVE-2026-73282
In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.
CWE: CWE-416
NVD
MEDIUM
CVE-2026-73563
Backstage is an open framework for building developer portals. Prior to 0.29.2, the experimental dynamic client registration and client ID metadata document features in the @backstage/plugin-auth-backend use full-string matcher.isMatch glob matching for auth.experimentalDynamicClientRegistration.all…
CWE: CWE-601
NVD
MEDIUM
CVE-2026-49820
Probo is a self-hostable governance, risk, and compliance (GRC) platform built for engineering and security teams. Probo's `saferedirect` package validates redirect URLs used across authentication flows (OIDC, SAML, session transfer, OAuth connectors, and trust-center magic links). Prior to version …
CWE: CWE-601
NVD
MEDIUM
CVE-2026-61350
Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.
CWE: CWE-126
NVD
MEDIUM
CVE-2026-73036
Bash-it 3.2.0 contains a terminal escape sequence injection vulnerability in the barbuk theme's Python virtualenv prompt segment that allows local attackers to inject arbitrary terminal control sequences by embedding escape sequences in the requires-python field of a pyproject.toml file. When a user…
CWE: CWE-150
NVD
MEDIUM
CVE-2026-58425
OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)
CWE: CWE-200, CWE-863
NVD
MEDIUM
CVE-2026-6470
Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations did check the privilege, but assigning a range subtype and referencing the type from an SQL expressio…
CWE: CWE-862
NVD
MEDIUM
CVE-2026-65938
In WhatsUp Gold versions released before 2026.0.2, an improper authorization vulnerability in the Scheduled Reports API allows any authenticated user to invoke restricted actions.
CWE: CWE-602, CWE-862
NVD
MEDIUM
CVE-2026-19078
A flaw was found in the oauth-server component. This open redirect vulnerability occurs when the 'then' parameter in the grant approval handler is not properly validated. A remote attacker can craft a malicious URL that, when approved or denied by an authenticated user, redirects them to an attacker…
CWE: CWE-601
NVD
MEDIUM
CVE-2026-72912
CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.3.0, CyberChef's pretty-recipe parser in src/core/Utils.mjs can exhaust client-side CPU when a malformed #recipe= URL fragment containing a large number of unmatched quote characters reaches Utils.parseRecip…
CWE: CWE-400, CWE-1333
NVD
MEDIUM
CVE-2026-18165
@fastify/oauth2 is an OAuth 2.0 plugin for Fastify. In versions from 7.2.0 up to but not including 8.3.0, the plugin validates the OAuth state, and with PKCE the code verifier, by comparing the callback query parameter against an unprefixed, predictable cookie, with no server-side binding to the bro…
CWE: CWE-352
GitHub-GHSA
MEDIUM
ep_etherpad-lite: Import/export uses Math.random() for temp file paths; predictable paths on shared /tmp enable symlink-based file overwrite
GHSA-2jwf-f4xq-f24h
pkg: ep_etherpad-lite
eco: npm
published: Aug 13, 2026
## Description
`src/node/handler/ImportHandler.ts` and `src/node/handler/ExportHandler.ts` both compute their temporary working-file paths as:
“`ts
const randNum = Math.floor(Math.random() * 0xFFFFFFFF);
const srcFile = `${os.tmpdir()}/etherpad_export_${randNum}.html`;
const destFile = `${os.tmpd…
CVE-2026-55086
NVD
MEDIUM
CVE-2026-14681
Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules, via initial direct TLS connection. Despite a pg_hba.conf that appears to require GSSAPI, the connection may exchange data over TLS encryption alone. If the TLS se…
CWE: CWE-924
GitHub-GHSA
MEDIUM
Fabric CA Developer's Guide: LDAP Injection via Unescaped Username in GetUser Filter
GHSA-xghw-p77p-3r7x
pkg: github.com/hyperledger/fabric-ca
eco: go
published: Aug 14, 2026
When fabric-ca is configured with an LDAP backend, the username from HTTP Basic authentication is included in an LDAP uid search filter without proper escaping. An unauthenticated attacker with network access to the CA enrollment endpoint could exploit this to perform LDAP injection before password …
CVE-2026-53658
GitHub-GHSA
MEDIUM
hashi-vault-js: Vault token and secret values exposed in thrown errors
GHSA-5pq8-3ffp-7w5m
pkg: hashi-vault-js
eco: npm
published: Aug 13, 2026
## Summary
Vault token and secret values are exposed in thrown errors when using `hashi-vault-js`.
## Details
Every API method in `Vault.js` executes `throw parseAxiosError(err)`, which returns the raw `AxiosError` untouched. That error carries the full Axios configuration, including the `X-Vault…
CVE-2026-55102