Vulnerability Digest — September 14, 2026 · 53 Critical · 14 Exploited






Vulnerability Digest — Monday, September 14, 2026


Security Report

Monday, September 14, 2026  ·  Last 7 days  ·  Min severity: MEDIUM
Total Findings
424
Critical
53
High
210
Actively Exploited
14
CISA-KEV14
NVD226
GitHub-GHSA184
Findings sorted by severity
CISA-KEV

CRITICAL
ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
CVE-2026-84869
pkg: ConnectWise ScreenConnect

published: Sep 11, 2026

ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to file transfer and execution through an active remote sessions without authorization or host confirmation.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
JFrog Artifactory Incorrect Authorization Vulnerability
CVE-2026-42016
pkg: JFrog Artifactory

published: Sep 11, 2026

JFrog Artifactory contains an incorrect authorization vulnerability that allows leads to privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
JFrog Artifactory Improper Authentication Vulnerability
CVE-2026-42018
pkg: JFrog Artifactory

published: Sep 11, 2026

JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
CVE-2026-85706
pkg: GitLab Community Edition and Enterprise Edition

published: Sep 11, 2026

GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository commits API.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
CVE-2026-67277
pkg: MikroTik RouterOS

published: Sep 10, 2026

MikroTik RouterOS contains a missing authenticaion for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
CVE-2026-86060
pkg: MikroTik RouterOS

published: Sep 10, 2026

MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacked to change the trusted RouterOS policy mask, leading to privilege escalation.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
CVE-2026-19490
pkg: Citrix NetScaler

published: Sep 9, 2026

Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may b…
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
CVE-2025-25249
pkg: Fortinet Multiple Products

published: Sep 9, 2026

Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Google Chromium V8 Out of Bounds Write Vulnerability
CVE-2026-87491
pkg: Google Chromium V8

published: Sep 9, 2026

Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Ed…
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability
CVE-2026-20079
pkg: Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management

published: Sep 9, 2026

Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files o…
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Microsoft Windows Heap-Based Buffer Overflow Vulnerability
CVE-2026-85880
pkg: Microsoft Windows

published: Sep 8, 2026

Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Microsoft Windows Link Following Vulnerability
CVE-2026-81963
pkg: Microsoft Windows

published: Sep 8, 2026

Microsoft Windows Update Stack contains a link following vulnerability that allows a local attacker to escalate privileges locally up to SYSTEM.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
N-able N-central Static Code Injection Vulnerability
CVE-2026-86218
pkg: N-able N-central

published: Sep 8, 2026

N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
CVE-2026-75650
pkg: Adobe Commerce and Magento

published: Sep 8, 2026

Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
GitHub-GHSA

CRITICAL
MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding / Direct Exposure)
GHSA-rqfv-2mw9-78g2
pkg: mysql-mcp-server
eco: pip
published: Sep 11, 2026
## Summary

In SSE/HTTP transport mode, `mysql_mcp_server` constructs `SseServerTransport` without passing `security_settings`. As a result, the MCP Python SDK's DNS-rebinding protection (Origin/Host header validation) is disabled; the Starlette application has no CORS or TrustedHost middleware; and…

CVE-2026-59971
GitHub-GHSA

CRITICAL
MapLibre GL JS: XSS Sanitizer Bypass in DOM.sanitize() via Live NamedNodeMap Removal Skip
GHSA-jrc7-96c5-q579
pkg: maplibre-gl
eco: npm
published: Sep 8, 2026
### Impact
`DOM.sanitize()` in `src/util/dom.ts` iterated `elem.attributes` (a live `NamedNodeMap`) while calling `elem.removeAttribute()` in the same loop. Removing an attribute shifts subsequent attributes down by one index, causing the iterator to skip the adjacent attribute.

An attacker can pro…

CVE-2026-85061
NVD

CRITICAL
CVE-2026-19583
CVE-2026-19583
pkg: linux

published: Sep 10, 2026

Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the Linux.Sys.BashShell artifact allows arbitrary command execution on endpoints, and so it requires the EXECVE permission to schedule. However, no such check was implemented for client monitoring artifa…
CWE: CWE-732
GitHub-GHSA

CRITICAL
Semaphore U: OS Command Injection
GHSA-xp7j-h7jc-4w8p
pkg: github.com/semaphoreui/semaphore
eco: go
published: Sep 8, 2026
# Summary
An OS command injection in repository git_url handling lets any user holding the Manager or Owner role on any project (the normal project-collaborator roles) achieve remote code execution on the Semaphore server host. Using git's –upload-pack=<cmd> option, an attacker runs arbitrary comma…
CVE-2026-73294
NVD

CRITICAL
CVE-2026-89536
CVE-2026-89536
pkg: tls

published: Sep 11, 2026

In the Linux kernel, the following vulnerability has been resolved:

SUNRPC: wait for in-flight client TLS handshake callback

xs_tls_handshake_sync() gives xs_tls_handshake_done() a reference to the
lower transport before submitting the handshake request. On timeout or
signal, the synchronous waite…

NVD

CRITICAL
CVE-2026-89495
CVE-2026-89495
pkg: node

published: Sep 11, 2026

In the Linux kernel, the following vulnerability has been resolved:

ocfs2: bound namelen in dlm_migrate_request_handler

Patch series "ocfs2/dlm: bound peer-controlled lengths in the o2dlm".

The o2dlm receive handlers trust u8 length and count fields from the wire
without bounding them, so a node …

NVD

CRITICAL
CVE-2026-89494
CVE-2026-89494
pkg: node

published: Sep 11, 2026

In the Linux kernel, the following vulnerability has been resolved:

ocfs2: validate lengths in dlm_mig_lockres_handler

A node receiving a DLM_MIG_LOCKRES message trusts several fields of the
peer-supplied dlm_migratable_lockres without validation. num_locks and
lockname_len are bounded only on th…

NVD

CRITICAL
CVE-2026-80926
CVE-2026-80926
pkg: linux

published: Sep 11, 2026

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix use-after-free in oplock break notification

smb2_oplock_break_noti() reads opinfo->conn without any lock and
dereferences it after two allocations which may sleep. When the
durable handle owning the oplock is disconnec…

NVD

CRITICAL
CVE-2026-89259
CVE-2026-89259
pkg: node

published: Sep 11, 2026

Hugo is a static site generator. From v0.161.0, Hugo executes Node tools under Node's permission model, but TailwindCSS — included in the default security.exec.allow list — requires a highly permissive configuration (–allow-addons, –allow-child-process, –allow-worker). As a result, the restri…
CWE: CWE-250
GitHub-GHSA

CRITICAL
rclone serve s3: –auth-proxy without –auth-key authenticates nobody – full SigV4 signature bypass
GHSA-xwwr-4h3p-r22c
pkg: github.com/rclone/rclone
eco: go
published: Sep 10, 2026
### Summary
`rclone serve s3`'s handler chain, when `–auth-proxy` is configured, is (outermost first): `authPairMiddleware` -> `proxyAuthMiddleware` -> gofakes3's own SigV4-verifying handler.

`authPairMiddleware` parses the accessKeyID straight out of the incoming request's own `Authorization` hea…

CVE-2026-88018
NVD

CRITICAL
CVE-2026-88877
CVE-2026-88877
pkg: kubernetes

published: Sep 10, 2026

Traefik is a HTTP reverse proxy and load balancer. In versions >= v3.7.0 and <= v3.7.11, the Kubernetes ingress-nginx provider mishandles Ingresses that carry both an authentication annotation and the nginx.ingress.kubernetes.io/from-to-www-redirect annotation. For such Ingresses the provider create…
CWE: CWE-639
NVD

CRITICAL
CVE-2026-80352
CVE-2026-80352
pkg: kubernetes

published: Sep 10, 2026

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Camel K.

A YAML injection vulnerability in custom resource configuration allows an authorized CR author to inject arbitrary Kubernetes objects, potentially enabling unauthorized resource creation with the privileges…

CWE: CWE-94
GitHub-GHSA

CRITICAL
Astro: Remote code execution through AVIF image optimization
GHSA-26w7-cxv4-gfx2
pkg: astro
eco: npm
published: Sep 8, 2026
A vulnerability in `libheif`, used by the default Sharp image service in Astro, can lead to remote code execution when a malicious AVIF image is optimized.

Projects are affected when an attacker can cause Astro to process an untrusted AVIF image.

The fix was released in Astro 7.2.8, which requires…

GitHub-GHSA

CRITICAL
Microsoft QUIC: Remote Code Execution Vulnerability
GHSA-92f5-vc22-8j33
pkg: Microsoft.Native.Quic.MsQuic.OpenSSL, Microsoft.Native.Quic.MsQuic.Schannel, Microsoft.Native.Quic.MsQuic.OpenSSL
eco: nuget
published: Sep 8, 2026
# Summary
Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.

# Details

New network path creations and removals triggered by incoming packets can lead to a pointer invalidation.

## Patches

– Guard path promotion [e0f55b5](https://github.com/microsoft/…

CVE-2026-62815
GitHub-GHSA

CRITICAL
GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE
GHSA-284h-m62q-gf8w
pkg: GitPython
eco: pip
published: Sep 8, 2026
– **CWE:** CWE-88 (Argument Injection) / CWE-94 (Code Injection) — via a read-then-corrupt-on-rewrite config round trip, not a direct setter argument
– **Affected component:** `git/config.py` — `GitConfigParser._read()` (multi-line value decoding, lines 444-541, esp. `string_decode()` at line 46…
CVE-2026-78676
NVD

CRITICAL
CVE-2026-68839
CVE-2026-68839
pkg: windows

published: Sep 8, 2026

Heap-based buffer overflow in Windows USB Mass Storage Class Driver allows an unauthorized attacker to execute code over a network.
CWE: CWE-20, CWE-122
GitHub-GHSA

CRITICAL
Gitea: Remote Code Execution via diffpatch Git Hook Installation
GHSA-rcr6-4jqh-j84m
pkg: gitea.dev
eco: go
published: Sep 8, 2026
### Summary

Gitea's `diffpatch` endpoint can be abused to install and execute a Git hook from repository-controlled content.

An attacker with ordinary write access to a repository can execute arbitrary shell commands as the Gitea OS user. With default open registration, an unauthenticated visitor …

CVE-2026-60004
GitHub-GHSA

CRITICAL
Prowler: SAML Domain Claiming Enables Cross-Tenant Account Takeover
GHSA-h8m9-jgf8-vwvp
pkg: prowler-cloud
eco: pip
published: Sep 11, 2026
## SAML Tenant Binding Enables Cross-Tenant Account Takeover

### Summary

Prowler's SAML authentication flow trusted the email domain asserted in a SAMLResponse when deciding which tenant should receive the final token. A malicious tenant with its own SAML configuration and a self-controlled IdP co…

CVE-2026-59151
NVD

CRITICAL
CVE-2026-54694
CVE-2026-54694
pkg: vue

published: Sep 9, 2026

SkillTree is a micro-learning gamification platform. Prior to version 4.4.2, two independent code flaws combine into a single exploitable attack chain, with three distinct exploitation paths of escalating impact. `StringHighlighter.js` builds an HTML string by interpolating raw `value` substrings di…
CWE: CWE-20, CWE-79, CWE-116, CWE-183, CWE-693
NVD

CRITICAL
CVE-2026-87634
CVE-2026-87634
pkg: google chrome

published: Sep 9, 2026

Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
CWE: CWE-416
NVD

CRITICAL
CVE-2026-87470
CVE-2026-87470
pkg: google chrome, apple macos

published: Sep 9, 2026

Improper quantity validation in Tint in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-1284
NVD

CRITICAL
CVE-2026-87464
CVE-2026-87464
pkg: google chrome

published: Sep 9, 2026

Use after free in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

CRITICAL
CVE-2026-87455
CVE-2026-87455
pkg: google chrome

published: Sep 9, 2026

Use after free in Aura in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-416
NVD

CRITICAL
CVE-2026-87448
CVE-2026-87448
pkg: google chrome

published: Sep 9, 2026

Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
CWE: CWE-416
NVD

CRITICAL
CVE-2026-87438
CVE-2026-87438
pkg: google chrome, google android

published: Sep 9, 2026

Out of bounds write in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-787
NVD

CRITICAL
CVE-2026-80238
CVE-2026-80238
pkg: dell secure_connect_gateway

published: Sep 7, 2026

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Execution with Unnecessary Privileges vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Protection mechanism …
CWE: CWE-250
GitHub-GHSA

CRITICAL
yayson: Prototype pollution in Store/LegacyStore deserialization
GHSA-325j-mg25-8q58
pkg: yayson
eco: npm
published: Sep 11, 2026
# Summary
`Store`/`LegacyStore` key internal lookup tables by the `type`, `id`, and relationship names from a JSON:API document. Because these were plain objects, a document with `type: "__proto__"` writes onto `Object.prototype`, polluting every object in the process.

# Severity
Suggested CVSS v3.…

CVE-2026-61534
NVD

CRITICAL
CVE-2026-89630
CVE-2026-89630
pkg: express

published: Sep 11, 2026

In the Linux kernel, the following vulnerability has been resolved:

smb: client: restore the data_offset bound in is_valid_oplock_break()

Commit 83bfbd0bb902 ("cifs: Remove the RFC1002 header from smb_hdr")
changed the quantity this bound is measured against. It used to be
srv->total_read minus t…

NVD

CRITICAL
CVE-2026-80945
CVE-2026-80945
pkg: linux

published: Sep 11, 2026

In the Linux kernel, the following vulnerability has been resolved:

crypto: iaa – unmap dst before software fallback on decompress

On a hardware analytics error, decompress retries through the software
fallback, which writes req->dst with the CPU while it is still mapped
DMA_FROM_DEVICE. With SWIO…

GitHub-GHSA

CRITICAL
rclone: RC per-server auth-proxy bypass
GHSA-p569-5gjg-9cmj
pkg: github.com/rclone/rclone
eco: go
published: Sep 10, 2026
## Summary

`serve/start` accepts protocol options in a per-server `proxyOpt` object. The FTP and S3 RC adapters parse that object and pass it to their server constructors, but the constructors decide whether proxy authentication is enabled by checking the process-global `proxy.Opt.AuthProxy` instea…

CVE-2026-88044
NVD

CRITICAL
CVE-2026-75156
CVE-2026-75156
pkg: oauth

published: Sep 8, 2026

Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `id_token`s during OAuth login. Deployments are affected only when the FAB auth manager is configured with Azure AD as an OAuth provider. Because the signing keys are fetched from Microsoft's …
CWE: CWE-346
GitHub-GHSA

CRITICAL
Next.js: Unauthenticated Remote Code Execution on windows-hosted servers
GHSA-p293-qw3h-jr36
pkg: next, next
eco: npm
published: Sep 8, 2026
## Impact

A vulnerability in applications using Pages and App router without Cache Component can lead to remote code execution when the server is hosted on machines using a Windows filesystem.

## Workaround

There is no known workaround for affected windows-hosted applications. You should upgrade …

CVE-2026-75604
GitHub-GHSA

CRITICAL
Central Dogma: Hard-coded ZooKeeper replication secret 'ch4n63m3' with silent fallback enables cluster takeover
GHSA-2j95-gqxf-v3vg
pkg: com.linecorp.centraldogma:centraldogma-server
eco: maven
published: Sep 11, 2026
## Vulnerability

`ZooKeeperReplicationConfig.secret()` silently substitutes the hard-coded constant `"ch4n63m3"` (leetspeak for "change me") whenever the operator omits `replication.secret`. The same secret is wired into both the **client-facing SASL context** and the **quorum/learner SASL contexts…

CVE-2026-11746
GitHub-GHSA

CRITICAL
Traefik HTTP/3 Backend NTLM Connection Reuse
GHSA-qqjf-53cj-pwvv
pkg: github.com/traefik/traefik/v3, github.com/traefik/traefik/v2
eco: go
published: Sep 10, 2026
## Summary

Traefik's HTTP/3 request path did not initialize the connection-scoped backend transport holder that isolates connection-bound NTLM and Negotiate (Kerberos) authentication on the HTTP/1.1 and HTTP/2 paths. The HTTP/3 entrypoint reuses the HTTPS handler chain and reaches the same backend …

CVE-2026-88007
GitHub-GHSA

CRITICAL
OmniRoute ACP Custom-Agent Remote Code Execution (RCE)
GHSA-hf57-cqmx-p4gr
pkg: omniroute
eco: npm
published: Sep 10, 2026
## 2. Summary

`POST /api/acp/agents` registers a custom ACP agent. The endpoint accepts user-controlled
`binary` and `versionCommand` values. After saving the custom agent, the same request calls
`refreshAgentCache()`, which triggers agent version detection. The version probe eventually runs:

“`t…

CVE-2026-88062
GitHub-GHSA

CRITICAL
Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used
GHSA-2xp9-vwfh-vxw4
pkg: next, next
eco: npm
published: Sep 8, 2026
A vulnerability in the underlying `libheif` library used by `sharp` which Next.js uses for image optimization can lead to remote code execution when AVIF files are optimized.

Until a fix has propagated, optimization of AVIF files is disabled.

GitHub-GHSA

CRITICAL
Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext
GHSA-c4c3-7fpv-j4q5
pkg: io.netty:netty-handler, io.netty:netty-handler
eco: maven
published: Sep 8, 2026
### Summary
A fragmented TLS ClientHello whose handshake header spans multiple records makes Netty silently fall back to the default SslContext; where per-SNI selection is the sole mTLS gate, an unauthenticated attacker can bypass the route's mTLS requirement.

### Details
In `io.netty.handler.ssl.S…

CVE-2026-75595
GitHub-GHSA

CRITICAL
NLTK: Allowlisted pickle loaders still permit code execution in current source
GHSA-x99w-6fgc-pmfw
pkg: nltk
eco: pip
published: Sep 8, 2026
### Summary

The current source tree still allows arbitrary code execution during supposedly safer allowlisted pickle loading. The allowlist trusts whole module namespaces instead of exact safe globals, so crafted pickles can invoke dangerous in-namespace callables through pickle REDUCE.

### Detail…

CVE-2026-79657
GitHub-GHSA

CRITICAL
NLTK: Unsafe Pickle Deserialization in TransitionParser Allows Remote Code Execution
GHSA-rhp5-r9x4-f5g2
pkg: nltk
eco: pip
published: Sep 8, 2026
## Summary

The NLTK library's `TransitionParser.parse()` method deserializes model files using `pickle_load()` with the default `restricted=False` parameter, allowing arbitrary Python code execution when loading a malicious model file. The library provides a `RestrictedUnpickler` class for safe des…

CVE-2026-78683
GitHub-GHSA

HIGH
@Mockoon/commons-server: Unauthenticated admin API + wildcard CORS allows mock-state hijack and secret theft
GHSA-rqx4-3f6q-3x2v
pkg: @mockoon/commons-server, @mockoon/cli
eco: npm
published: Sep 11, 2026
## Summary

Mockoon's admin API ([`commons-server/src/libs/server/admin-api.ts`](https://github.com/mockoon/mockoon/blob/4375a8f/packages/commons-server/src/libs/server/admin-api.ts)) is mounted on the same Express listener as the user-defined mock routes, **enabled by default** in every shipped run…

CVE-2026-59148
NVD

HIGH
CVE-2026-80937
CVE-2026-80937
pkg: linux

published: Sep 11, 2026

In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7915: bound the device EEPROM address before the EFUSE copy

mt7915_mcu_get_eeprom() copies a fixed EFUSE block into the driver's
dev->mt76.eeprom.data buffer at the offset reported by the MCU response
(res->addr, a d…

NVD

HIGH
CVE-2026-80935
CVE-2026-80935
pkg: linux

published: Sep 11, 2026

In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7996: bound the device EEPROM address before the EFUSE copy

mt7996_mcu_get_eeprom() derives the destination of the EFUSE/EXT block
copy from the address reported by the MCU response (event->addr, a
device-controlled …

NVD

HIGH
CVE-2026-81211
CVE-2026-81211
pkg: python

published: Sep 10, 2026

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary Python code due to improper authorization of custom components in stored flows.
CWE: CWE-862
GitHub-GHSA

HIGH
ESPHome Device Builder Dashboard: Unauthenticated dashboard access via the HA add-on ingress site bound to all interfaces
GHSA-vv4j-m4vr-f3g6
pkg: esphome-device-builder
eco: pip
published: Sep 9, 2026
## Summary

On the Home Assistant add-on, the dashboard serves a trusted ingress site that skips authentication because the supervisor authenticates the request upstream. That site was binding `0.0.0.0`. The add-on runs in host network mode for mDNS, so binding all interfaces also bound the host's L…

CVE-2026-59177
GitHub-GHSA

HIGH
Komari: Management Interface CSRF
GHSA-hxjg-93wc-h8p8
pkg: github.com/komari-monitor/komari
eco: go
published: Sep 9, 2026
# Vulnerability Overview

The `session_token` cookie is set **without** the `SameSite` or `Secure` attributes (`login.go:68`).

All `/api/admin/` management endpoints rely solely on this cookie for authentication, with **no CSRF token or Origin validation**.

**The server-side vulnerability is confi…

GitHub-GHSA

HIGH
@yeger/turbo-graph: Unauthenticated Network-Exposed Task Execution via /api/run
GHSA-2r5q-h53f-9rp3
pkg: @yeger/turbo-graph
eco: npm
published: Sep 9, 2026
## Unauthenticated Network-Exposed Turborepo Task Execution via /api/run

### Summary

`@yeger/turbo-graph` starts its embedded Next.js server without binding to the loopback interface, causing it to listen on all network interfaces (`0.0.0.0:29312` by default). The `/api/run` HTTP endpoint exposed …

CVE-2026-59160
NVD

HIGH
CVE-2026-80921
CVE-2026-80921
pkg: linux

published: Sep 9, 2026

In the Linux kernel, the following vulnerability has been resolved:

KVM: s390: vsie: zero stale crypto bits

When shadowing crypto access bits from a format0 apcb (crycb 0 or 1),
the bits 64..255 are unchanged from whatever is in the vsie page in the
crycb and thus in the apcb. This gives a nested …

NVD

HIGH
CVE-2026-80914
CVE-2026-80914
pkg: linux

published: Sep 9, 2026

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready

iso_conn_ready() looks up the BIS listener socket with iso_get_sock(),
which takes a reference, and then, without re-checking its state,
creates a child socke…

GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-69522 – .NET and Visual Studio Remote Code Execution Vulnerability
GHSA-2j8r-3c22-8565
pkg: Microsoft.DiaSymReader.Native
eco: nuget
published: Sep 9, 2026
# Microsoft Security Advisory CVE-2026-69522 – .NET and Visual Studio Remote Code Execution Vulnerability

## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in Microsoft.DiaSymReader.Native. This advisory also provides guidance on what…

CVE-2026-69522
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-69439 – .NET and Visual Studio Elevation of Privilege Vulnerability
GHSA-527h-q9f6-p7qx
pkg: Microsoft.DiaSymReader.Native
eco: nuget
published: Sep 9, 2026
# Microsoft Security Advisory CVE-2026-69439 – .NET and Visual Studio Elevation of Privilege Vulnerability

## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in Microsoft.DiaSymReader.Native. This advisory also provides guidance on wha…

CVE-2026-69439
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-71328 – .NET and Visual Studio Remote Code Execution Vulnerability
GHSA-63gh-g2x5-x69v
pkg: Microsoft.DiaSymReader.Native
eco: nuget
published: Sep 9, 2026
# Microsoft Security Advisory CVE-2026-71328 – .NET and Visual Studio Remote Code Execution Vulnerability

## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in Microsoft.DiaSymReader.Native. This advisory also provides guidance on what…

CVE-2026-71328
NVD

HIGH
CVE-2026-87460
CVE-2026-87460
pkg: google chrome

published: Sep 9, 2026

Use after free in Platform in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-87444
CVE-2026-87444
pkg: google chrome

published: Sep 9, 2026

Memory corruption in Codecs in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-119
NVD

HIGH
CVE-2026-87440
CVE-2026-87440
pkg: google chrome

published: Sep 9, 2026

Out of bounds read in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-125
NVD

HIGH
CVE-2026-87433
CVE-2026-87433
pkg: google chrome

published: Sep 9, 2026

Race condition in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-367
NVD

HIGH
CVE-2026-87430
CVE-2026-87430
pkg: google chrome

published: Sep 9, 2026

Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
CWE: CWE-122
NVD

HIGH
CVE-2026-86083
CVE-2026-86083
pkg: n8n n8n

published: Sep 8, 2026

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the legacy expression engine generated source text by calling the mutable global JSON.stringify while printing synthetic string literals and interpolating timezone data. An expression could replace JSON.string…
CWE: CWE-94
NVD

HIGH
CVE-2026-86076
CVE-2026-86076
pkg: n8n n8n

published: Sep 8, 2026

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the expression compiler sanitizer resolved through dynamically scoped this and did not reject reserved class member names. A class field named __sanitize could rebind the sanitizer and reach the Function const…
CWE: CWE-94
GitHub-GHSA

HIGH
Duplicate Advisory: Microsoft Security Advisory CVE-2026-71328 – .NET and Visual Studio Remote Code Execution Vulnerability
GHSA-4qhr-qf46-fcrx
pkg: Microsoft.DiaSymReader.Native
eco: nuget
published: Sep 8, 2026
### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-63gh-g2x5-x69v. This link is maintained to preserve external references.

### Original Description
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.

GitHub-GHSA

HIGH
Duplicate Advisory: Microsoft Security Advisory CVE-2026-69522 – .NET and Visual Studio Remote Code Execution Vulnerability
GHSA-q72m-f2r4-w4cw
pkg: Microsoft.DiaSymReader.Native
eco: nuget
published: Sep 8, 2026
### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-2j8r-3c22-8565. This link is maintained to preserve external references.

### Original Description
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.

GitHub-GHSA

HIGH
Duplicate Advisory: Microsoft Security Advisory CVE-2026-69439 – .NET and Visual Studio Elevation of Privilege Vulnerability
GHSA-mqvm-gmc4-6rv2
pkg: Microsoft.DiaSymReader.Native
eco: nuget
published: Sep 8, 2026
### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-527h-q9f6-p7qx. This link is maintained to preserve external references.

### Original Description
Heap-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to elevate privileges over…

NVD

HIGH
CVE-2026-62744
CVE-2026-62744
pkg: windows

published: Sep 8, 2026

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
CWE: CWE-122
NVD

HIGH
CVE-2026-62706
CVE-2026-62706
pkg: windows

published: Sep 8, 2026

Out-of-bounds read in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
CWE: CWE-121, CWE-125
NVD

HIGH
CVE-2026-86712
CVE-2026-86712
pkg: node

published: Sep 8, 2026

SiYuan before 3.8.2 trusts the attacker-writable text/siyuan clipboard MIME type and skips sanitization in the paste handler, allowing code execution in the Node-enabled desktop renderer. Attackers can craft malicious web pages that write to the clipboard, and when pasted into SiYuan, injected scrip…
CWE: CWE-79
GitHub-GHSA

HIGH
Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin
GHSA-jmc6-2wr8-h3wj
pkg: open-webui
eco: pip
published: Sep 10, 2026
## Summary
Any authenticated user with access to a shared terminal server could get script of their choosing to run in the Open WebUI origin itself. The in-app port preview rendered the content of a previewed port in an iframe whose sandbox always granted `allow-same-origin` alongside `allow-scripts…
CVE-2026-87995
NVD

HIGH
CVE-2026-84942
CVE-2026-84942
pkg: express

published: Sep 8, 2026

Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions by saving a crafted Vega visualization. The checkForF…
CWE: CWE-79
NVD

HIGH
CVE-2026-80219
CVE-2026-80219
pkg: oauth

published: Sep 8, 2026

A flaw was found in hawtio-operator. When deploying Hawtio in cluster mode, the operator creates a cluster-scoped OAuthClient with automatic grant approval (GrantMethod: auto) and no client secret (public client). The redirect URIs are derived from the operator-created Route, whose hostname is tenan…
CWE: CWE-1390
GitHub-GHSA

HIGH
SiYuan: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlocked
GHSA-v684-q882-jgmq
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: Sep 8, 2026
**CVE:** This vulnerability corresponds to [CVE-2026-72789](https://nvd.nist.gov/vuln/detail/CVE-2026-72789).

### Summary

`publishAccess.json` is an opt-out list. The publish gate returns *accessible* for anything not explicitly listed in it. Encrypted notebooks are never written into that file, b…

CVE-2026-72789
GitHub-GHSA

HIGH
FrontMCP and mcp-from-openapi have bypass of OpenAPI external $ref SSRF fix
GHSA-65h7-9wrw-629c
pkg: mcp-from-openapi, @frontmcp/adapters, frontmcp
eco: npm
published: Sep 11, 2026
## Summary

The published fix for GHSA-v6ph-xcq9-qxxj / CVE-2026-39885 added a direct hostname denylist for OpenAPI external `$ref` dereferencing, but the latest patched dependency `mcp-from-openapi` 2.3.0 still makes backend-origin requests to loopback when the target is reached through hostname re…

CVE-2026-59973
GitHub-GHSA

HIGH
Identrail Cross-tenant IDOR: Client-supplied GitHub App installation_id is bound to the caller's workspace without ownership verification
GHSA-cp3j-m783-3ph5
pkg: github.com/identrail/identrail
eco: go
published: Sep 9, 2026
## Summary

identrail's GitHub App connection-completion endpoint binds a fully client-supplied `installation_id` to the caller's workspace without verifying that the installation belongs to, or was installed by, the workspace that initiated the connect flow. identrail then mints a GitHub App instal…

CVE-2026-59185
NVD

HIGH
CVE-2026-86751
CVE-2026-86751
pkg: curl

published: Sep 9, 2026

Snipe-IT before 8.7.0 fails to properly sanitize markdown image syntax in note fields, allowing authenticated users to read arbitrary server files and issue server-side HTTP requests. Attackers can submit markdown image syntax in checkout acceptance notes that survive HTML escaping, are expanded by …
CWE: CWE-73
NVD

HIGH
CVE-2026-74860
CVE-2026-74860
pkg: python

published: Sep 8, 2026

A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback…
CWE: CWE-763
NVD

HIGH
CVE-2026-80953
CVE-2026-80953
pkg: linux

published: Sep 11, 2026

In the Linux kernel, the following vulnerability has been resolved:

i3c: master: adi: initialize the lock before enabling interrupts

adi_i3c_master_probe() requests the IRQ and unmasks REG_IRQ_PENDING_CMDR
before the controller's IBI state, transfer queue list and transfer
queue lock are initializ…

NVD

HIGH
CVE-2026-80932
CVE-2026-80932
pkg: linux

published: Sep 11, 2026

In the Linux kernel, the following vulnerability has been resolved:

vsock/virtio: flush works in dependency order

virtio_vsock_remove() stops the virtqueues and then flushes each work
item before freeing the enclosing virtio_vsock. The current order does
not account for dependencies between those…

NVD

HIGH
CVE-2026-87794
CVE-2026-87794
pkg: node

published: Sep 9, 2026

bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnerability in the nativeZip function that allows attackers to inject arbitrary arguments to the Info-ZIP backend. Attackers can supply a malicious destination path combined with crafted source entries to execute arbitrary commands wit…
CWE: CWE-88
GitHub-GHSA

HIGH
GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)
GHSA-7833-fr7j-v32q
pkg: GitPython
eco: pip
published: Sep 8, 2026
# [HIGH] Arbitrary local file content disclosure via `[include]` directive in untrusted `.gitmodules` (`SubmoduleConfigParser` never disables `merge_includes`)

– **CWE:** CWE-200 (Exposure of Sensitive Information) / CWE-73 (External Control of File Name or Path)
– **Affected component:** `git/obje…

CVE-2026-78675
NVD

HIGH
CVE-2026-86502
CVE-2026-86502
pkg: tls

published: Sep 7, 2026

In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts
CWE: CWE-306
NVD

HIGH
CVE-2026-87090
CVE-2026-87090
pkg: node

published: Sep 10, 2026

Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog node-write path that may allow an authenticated attacker to delete another node's catalog registration and take over its node identity. An attacker with a token granting node-write permission on any single node nam…
CWE: CWE-863
NVD

HIGH
CVE-2026-88029
CVE-2026-88029
pkg: python

published: Sep 10, 2026

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Python Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifi…
CWE: CWE-943
NVD

HIGH
CVE-2026-88861
CVE-2026-88861
pkg: jwt

published: Sep 10, 2026

Capgo (Cap-go/capgo.app) contains an authentication bypass affecting all versions (no patched version available at time of publication). The Edge authorization path allows a password-only Supabase aal1 session to exercise privileged RBAC permissions even when the account has a verified MFA factor th…
CWE: CWE-288
GitHub-GHSA

HIGH
@openhop/server: Path Traversal in Flow ID File Operations
GHSA-g72f-jw3w-mgh7
pkg: @openhop/server
eco: npm
published: Sep 9, 2026
## Path Traversal in Flow ID File Operations

### Summary

`@openhop/server` passes unsanitized HTTP route parameters directly to `path.join()` when constructing filesystem paths for flow YAML files. An unauthenticated attacker who can reach the server can read arbitrary `.yaml` files accessible to …

CVE-2026-59179
NVD

HIGH
CVE-2026-87639
CVE-2026-87639
pkg: google chrome

published: Sep 9, 2026

Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
GitHub-GHSA

HIGH
SVGO: removeScripts allows executable links through namespace and control-character bypasses
GHSA-w27v-7q3p-w38r
pkg: svgo, svgo, svgo
eco: npm
published: Sep 8, 2026
## Summary

SVGO's opt-in `removeScripts` plugin failed to remove some executable links. Namespace-prefixed SVG anchors and URL schemes containing ASCII tabs or newlines could bypass its checks. Applications that used this plugin as their only protection for untrusted SVG input could expose users to…

CVE-2026-84370
NVD

HIGH
CVE-2026-37008
CVE-2026-37008
pkg: python

published: Sep 13, 2026

CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275. Import-time blocking of module names does not address the availability of Python's complete object graph. For example, calling ctypes.CDLL(None) loa…
CWE: CWE-424
NVD

HIGH
CVE-2026-90651
CVE-2026-90651
pkg: tls

published: Sep 13, 2026

Socket Firewall (socketdev/socket-registry-firewall) in registry mode before 2.0.0 does not verify upstream TLS certificates by default. When the api_ssl_verify and upstream_ssl_verify configuration keys are omitted from socket.yml, the generated configuration sets SOCKET_API_SSL_VERIFY='false' and …
CWE: CWE-295
NVD

HIGH
CVE-2026-81003
CVE-2026-81003
pkg: tls

published: Sep 11, 2026

In the Linux kernel, the following vulnerability has been resolved:

net/iucv: filter frames in afiucv_hs_rcv() by ingress device

afiucv_hs_rcv() selects a socket from iucv_sk_list by matching four 8-byte
name fields in the transport header alone. No check is made against the
net_device the frame a…

GitHub-GHSA

HIGH
Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite
GHSA-wpmr-8h3q-fwj7
pkg: open-webui
eco: pip
published: Sep 10, 2026
## Summary

On SQLite deployments, the lookup that maps an external identity to a local account does a substring match instead of an exact match. A subject value containing SQL wildcard characters therefore matches accounts the value was never issued for, and the sign-in binds to whichever account t…

CVE-2026-87016
GitHub-GHSA

HIGH
@eigenpal/docx-editor-react: CSS injection and print-time XSS via unescaped embedded font-family name
GHSA-x7m8-jrm8-hpvx
pkg: @eigenpal/docx-editor-core, @eigenpal/docx-editor-react
eco: npm
published: Sep 10, 2026
## Summary
Embedded font-family names (`word/fontTable.xml`) were interpolated unescaped into an injected `@font-face` `<style>` and into the print window's `document.write()`. A crafted name injects page-wide CSS on open, and breaks out of `<style>`
into executable HTML on Print.

## Impact
Openi…

NVD

HIGH
CVE-2026-87016
CVE-2026-87016
pkg: oauth

published: Sep 9, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.41 until 0.11.1, get_user_by_oauth_sub and get_user_by_scim_external_id in backend/open_webui/models/users.py used JSON contains matching that compiled to SQL LIKE substring matching on SQLite. An OAuth su…
CWE: CWE-155, CWE-287
NVD

HIGH
CVE-2026-87874
CVE-2026-87874
pkg: python

published: Sep 9, 2026

A flaw was found in the memcached cache plugin of the community.general Ansible
collection. Although its documentation states that records are stored in JSON
format, the plugin performs no explicit serialization and relies on
python-memcached, which pickles values on write and unpickles them on read…
CWE: CWE-502
NVD

HIGH
CVE-2026-86770
CVE-2026-86770
pkg: oauth

published: Sep 9, 2026

Snipe-IT before 8.7.0 fails to validate username case sensitivity during SAML authentication, allowing attackers to authenticate as different users by registering IdP accounts with accent or case variants of victim usernames. Attackers can exploit the default utf8mb4_unicode_ci database collation to…
CWE: CWE-178
NVD

HIGH
CVE-2026-87471
CVE-2026-87471
pkg: google chrome

published: Sep 9, 2026

Incorrect authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-863
NVD

HIGH
CVE-2026-87467
CVE-2026-87467
pkg: google chrome, microsoft windows

published: Sep 9, 2026

Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
CWE: CWE-362
NVD

HIGH
CVE-2026-87457
CVE-2026-87457
pkg: google chrome, microsoft windows

published: Sep 9, 2026

Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)
CWE: CWE-367
GitHub-GHSA

HIGH
HTTPX2: Secure WebSocket traffic sent without TLS through SOCKS proxies
GHSA-7mj9-2mp8-4m2p
pkg: httpcore2, httpx2
eco: pip
published: Sep 8, 2026
### Summary

httpcore2 does not start TLS for `wss://` connections routed through a SOCKS5 proxy. The WebSocket opening handshake and all subsequent frames are sent in plaintext through the proxy path, despite the caller selecting the secure `wss` scheme.

The transport flaw affects httpcore2 releas…

CVE-2026-84381
NVD

HIGH
CVE-2026-78626
CVE-2026-78626
pkg: express

published: Sep 8, 2026

The Okta Access Gateway improperly handles input sanitization and regular expression evaluation within its Protected Rule authorization check, resulting in an authorization bypass when an administrator has explicitly configured a Protected Rule policy on one or more application resources.
CWE: CWE-863
NVD

HIGH
CVE-2026-75021
CVE-2026-75021
pkg: node

published: Sep 8, 2026

fastify-cli starts the Node.js Inspector when a debug flag is used, but it ignores the explicit bind address the user supplies and binds the Inspector to a broadly reachable address instead of the intended loopback. As a result the debugging interface can be exposed beyond the local machine, and bec…
CWE: CWE-1327
NVD

HIGH
CVE-2026-68894
CVE-2026-68894
pkg: windows

published: Sep 8, 2026

Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges over a network.
CWE: CWE-122
NVD

HIGH
CVE-2026-68880
CVE-2026-68880
pkg: windows

published: Sep 8, 2026

Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges over a network.
CWE: CWE-122, CWE-197
NVD

HIGH
CVE-2026-68878
CVE-2026-68878
pkg: windows

published: Sep 8, 2026

Stack-based buffer overflow in Windows Fast FAT Driver allows an authorized attacker to elevate privileges over a network.
CWE: CWE-121
NVD

HIGH
CVE-2026-68876
CVE-2026-68876
pkg: windows

published: Sep 8, 2026

Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges over a network.
CWE: CWE-122
NVD

HIGH
CVE-2026-68838
CVE-2026-68838
pkg: windows

published: Sep 8, 2026

Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.
CWE: CWE-121
NVD

HIGH
CVE-2026-68834
CVE-2026-68834
pkg: windows

published: Sep 8, 2026

Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.
CWE: CWE-121
NVD

HIGH
CVE-2026-68827
CVE-2026-68827
pkg: windows

published: Sep 8, 2026

Integer underflow (wrap or wraparound) in Windows GDI+ allows an authorized attacker to elevate privileges over a network.
CWE: CWE-122, CWE-191
NVD

HIGH
CVE-2026-89723
CVE-2026-89723
pkg: node

published: Sep 11, 2026

In the Linux kernel, the following vulnerability has been resolved:

nilfs2: fix slab-out-of-bounds in nilfs_direct_propagate after truncation

Shuangpeng Bai reported that KASAN detected a slab-out-of-bounds error
in nilfs_direct_propagate() during testing.

Analysis revealed that after truncating …

NVD

HIGH
CVE-2026-89617
CVE-2026-89617
pkg: express

published: Sep 11, 2026

In the Linux kernel, the following vulnerability has been resolved:

fs/ntfs3: validate dirty page table on log replay

Each DIR_PAGE_ENTRY ends in a page_lcns[] array whose length is the on-disk
lcns_follow field. check_rstbl() validates the table bookkeeping but never
checks that this array fits i…

NVD

HIGH
CVE-2026-89574
CVE-2026-89574
pkg: node

published: Sep 11, 2026

In the Linux kernel, the following vulnerability has been resolved:

dm array: validate array block headers on read

array_block_check() validates blocknr and csum and nothing else, while
node_check(), next to it, has bounded the structural fields since both
were written. dm_array_cursor_next() take…

NVD

HIGH
CVE-2026-81008
CVE-2026-81008
pkg: node

published: Sep 11, 2026

In the Linux kernel, the following vulnerability has been resolved:

interconnect: Fix use after free in icc_get() and of_icc_get_by_index()

In of_icc_get_by_index() and icc_get(), if the dynamic allocation for
path->name fails via kasprintf(), the error handling path directly
calls kfree(path) to …

NVD

HIGH
CVE-2026-80955
CVE-2026-80955
pkg: linux

published: Sep 11, 2026

In the Linux kernel, the following vulnerability has been resolved:

dm-pcache: fix use-after-free and invalid seg operations in kset_replay()

In kset_replay, when key->seg_gen is stale (key->seg_gen <
key->cache_pos.cache_seg->gen), cache_key_put(key) is called but then
key->cache_pos.cache_seg is…

NVD

HIGH
CVE-2026-80954
CVE-2026-80954
pkg: linux

published: Sep 11, 2026

In the Linux kernel, the following vulnerability has been resolved:

i3c: Fix unlocked dereference of dev->desc in i3c_device_get_supported_xfer_mode()

i3c_device_get_supported_xfer_mode() uses dev->desc to obtain the
master controller. However, dev->desc must not be dereferenced unless
bus->lock …

NVD

HIGH
CVE-2026-80952
CVE-2026-80952
pkg: linux

published: Sep 11, 2026

In the Linux kernel, the following vulnerability has been resolved:

i3c: master: Fix info leak and UAF in device unregister path

i3c_master_unregister_i3c_devs() clears i3cdev->dev->desc before
calling device_unregister(). During device_unregister(),
device_del() emits a KOBJ_REMOVE uevent and un…

NVD

HIGH
CVE-2026-80950
CVE-2026-80950
pkg: linux

published: Sep 11, 2026

In the Linux kernel, the following vulnerability has been resolved:

i3c: renesas: Check that the transfer is valid before accessing it

The Renesas I3C driver uses an asynchronous model to transfer data. It
prepares a struct renesas_i3c_xfer, enqueues it, and waits for completion.
The interrupt han…

NVD

HIGH
CVE-2026-80947
CVE-2026-80947
pkg: linux

published: Sep 11, 2026

In the Linux kernel, the following vulnerability has been resolved:

wifi: rtl8xxxu: fix use-after-free from rx_urb_wq on stop

rtl8xxxu arms rx_urb_wq from the RX completion path:
rtl8xxxu_rx_complete() hands the URB to rtl8xxxu_queue_rx_urb(), which
queues it on rx_urb_pending_list and, once the l…

NVD

HIGH
CVE-2026-80944
CVE-2026-80944
pkg: linux

published: Sep 11, 2026

In the Linux kernel, the following vulnerability has been resolved:

wifi: mwifiex: Detach sync cmd buffer on interrupted wait

mwifiex synchronous commands keep the caller-provided data buffer in
cmd_node->data_buf. Several callers pass stack-allocated objects there.

If wait_event_interruptible_ti…

NVD

HIGH
CVE-2026-80936
CVE-2026-80936
pkg: linux

published: Sep 11, 2026

In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7925: cancel mlo_pm_work on stop

mt7925 queues mlo_pm_work with a 5 second delay during multi-link
power-save setup and never cancels it on the stop path. If the device is
torn down inside that window, the work outli…

NVD

HIGH
CVE-2026-80933
CVE-2026-80933
pkg: linux

published: Sep 11, 2026

In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76: mt7996: validate default EEPROM firmware size

The default EEPROM firmware is parsed and copied as a full EEPROM
without checking its length. A truncated file can make the driver
read beyond the firmware buffer during v…

NVD

HIGH
CVE-2026-80931
CVE-2026-80931
pkg: linux

published: Sep 11, 2026

In the Linux kernel, the following vulnerability has been resolved:

w1: ds28e17: reject an oversize length on an I2C block read

w1_f19_i2c_master_transfer() is the master_xfer for the DS28E17 1-Wire
to I2C bridge. On an I2C_M_RECV_LEN read, it takes the length from the
device. The downstream slave…

NVD

HIGH
CVE-2026-80929
CVE-2026-80929
pkg: linux

published: Sep 11, 2026

In the Linux kernel, the following vulnerability has been resolved:

sysctl: move the "cad_pid" entry from pid_table[] to kern_reboot_table[]

cad_pid is global, and kill_cad_pid() is only used in the root namespace.

However, due to pid_table_root_permissions(), a non-root user can unshare
pid/user…

NVD

HIGH
CVE-2026-80928
CVE-2026-80928
pkg: linux

published: Sep 11, 2026

In the Linux kernel, the following vulnerability has been resolved:

smack: fix cred UAF in smack_file_send_sigiotask()

When inspecting the credentials of another task, objective credentials
(->real_cred, accessed with __task_cred()) must always be used.

Accessing ->cred on a non-current task is f…

GitHub-GHSA

HIGH
functype-mcp-server: MCP `set_functype_version` Package Alias RCE via Unsanitized pnpm install + Dynamic Import
GHSA-wcjj-9m6g-2fr2
pkg: functype-mcp-server
eco: npm
published: Sep 9, 2026
## MCP `set_functype_version` Package Alias RCE via Unsanitized pnpm install + Dynamic Import

### Summary

The `set_functype_version` MCP tool in `functype-mcp-server` accepts an unconstrained `version` string, interpolates it directly into an npm package specifier (`functype@<version>`), and insta…

CVE-2026-59176
GitHub-GHSA

HIGH
Joker linter executed project-local .jokerd/linter.* files during linting
GHSA-m835-3cm9-rggg
pkg: github.com/candid82/joker
eco: go
published: Sep 9, 2026
## Impact

In Joker versions before 1.8.2, `joker –lint <file>` located a `.jokerd/` directory by walking up from the linted file and executed matching `linter.*` files from that directory before linting. Because these files are executable Joker/Clojure code, linting a file inside an untrusted repo…

CVE-2026-59172
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-50646 – .NET Remote Code Execution Vulnerability
GHSA-gh2h-rhph-h37g
pkg: Microsoft.WindowsDesktop.App.Runtime.win-x64, Microsoft.WindowsDesktop.App.Runtime.win-x86, Microsoft.WindowsDesktop.App.Runtime.win-arm64
eco: nuget
published: Sep 8, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in Windows Presentation Foundation (WPF). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A remote code executio…

CVE-2026-50646
NVD

HIGH
CVE-2026-68896
CVE-2026-68896
pkg: windows

published: Sep 8, 2026

Absolute path traversal in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
CWE: CWE-36
NVD

HIGH
CVE-2026-68877
CVE-2026-68877
pkg: windows

published: Sep 8, 2026

Heap-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to execute code locally.
CWE: CWE-122
NVD

HIGH
CVE-2026-68875
CVE-2026-68875
pkg: windows

published: Sep 8, 2026

Buffer over-read in Windows NTFS allows an authorized attacker to execute code locally.
CWE: CWE-126
NVD

HIGH
CVE-2026-68848
CVE-2026-68848
pkg: windows

published: Sep 8, 2026

Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.
CWE: CWE-122
NVD

HIGH
CVE-2026-68845
CVE-2026-68845
pkg: windows

published: Sep 8, 2026

Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.
CWE: CWE-122
NVD

HIGH
CVE-2026-68844
CVE-2026-68844
pkg: windows

published: Sep 8, 2026

Heap-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to execute code locally.
CWE: CWE-122
NVD

HIGH
CVE-2026-68841
CVE-2026-68841
pkg: windows

published: Sep 8, 2026

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
CWE: CWE-122
NVD

HIGH
CVE-2026-68832
CVE-2026-68832
pkg: windows

published: Sep 8, 2026

Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.
CWE: CWE-190
NVD

HIGH
CVE-2026-62697
CVE-2026-62697
pkg: windows

published: Sep 8, 2026

Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
CWE: CWE-416
NVD

HIGH
CVE-2026-58600
CVE-2026-58600
pkg: windows

published: Sep 8, 2026

Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to elevate privileges locally.
CWE: CWE-122
NVD

HIGH
CVE-2026-58599
CVE-2026-58599
pkg: windows

published: Sep 8, 2026

Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally.
CWE: CWE-122
NVD

HIGH
CVE-2026-56177
CVE-2026-56177
pkg: windows

published: Sep 8, 2026

Use after free in Windows Server allows an authorized attacker to elevate privileges locally.
CWE: CWE-416
NVD

HIGH
CVE-2026-56172
CVE-2026-56172
pkg: windows

published: Sep 8, 2026

Use after free in Windows VHD miniport driver allows an authorized attacker to elevate privileges locally.
CWE: CWE-416
NVD

HIGH
CVE-2026-29811
CVE-2026-29811
pkg: python

published: Sep 13, 2026

CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same content as a primary domain; normally spelled "alias") via an ORM query filter rather than a Python "if" statement.
CWE: CWE-1025
NVD

HIGH
CVE-2026-89720
CVE-2026-89720
pkg: node

published: Sep 11, 2026

In the Linux kernel, the following vulnerability has been resolved:

ubifs: fix out-of-bounds read in signature length check

ubifs_sb_verify_signature() bounds the on-disk ubifs_sig_node->len field
before handing the signature payload to verify_pkcs7_signature(), but the
check has the wrong sign:

GitHub-GHSA

HIGH
Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader
GHSA-4v28-j6q3-5m4r
pkg: open-webui
eco: pip
published: Sep 10, 2026
## Summary
With the Playwright web loader enabled, Open WebUI checks the address behind a user-submitted URL before allowing the request, then handed the request to the browser to perform. The browser resolved the hostname a second time, on its own, and that answer was never checked. An attacker who…
CVE-2026-87996
NVD

HIGH
CVE-2026-88883
CVE-2026-88883
pkg: tls

published: Sep 10, 2026

Renovate is an automated dependency update tool. In versions before 44.14.4 (and Mend Renovate CE/EE images before 15.4.0 and the mend-renovate-enterprise-edition Helm chart before 10.4.0), log sanitisation for TLS private keys used for Mutual TLS was incomplete. While the value of hostRules[].https…
CWE: CWE-532
NVD

HIGH
CVE-2026-87996
CVE-2026-87996
pkg: python

published: Sep 9, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.1, SafePlaywrightURLLoader in backend/open_webui/retrieval/web/utils.py validated a user-controlled hostname in Python and then let the Playwright browser resolve it again in the sync and asyn…
CWE: CWE-367, CWE-918
NVD

HIGH
CVE-2026-80943
CVE-2026-80943
pkg: linux

published: Sep 11, 2026

In the Linux kernel, the following vulnerability has been resolved:

wifi: rtlwifi: rtl8192du: check QoS TID before indexing tids

rtl92du_tx_fill_desc() uses ieee80211_get_tid() to read the QoS TID
from the 802.11 header and then uses it as an index into
sta_entry->tids[]. ieee80211_get_tid() retur…

NVD

HIGH
CVE-2026-86073
CVE-2026-86073
pkg: n8n n8n

published: Sep 8, 2026

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.1, the OAuth token endpoint bound an authorization code's first access token to the consented resource but did not bind its refresh token. Refreshing checked only that the requested resource was registered, not that it matc…
CWE: CWE-863
NVD

HIGH
CVE-2026-15891
CVE-2026-15891
pkg: express

published: Sep 13, 2026

The MQTT-SN client keepalive handler process_ping() in subsys/net/lib/mqtt_sn/mqtt_sn.c removes the gateway record after PINGREQ retries are exhausted. It invoked SYS_SLIST_PEEK_HEAD_CONTAINER(&client->gateways, gw, next) but discarded the result. That macro is a pure expression that does not assign…
CWE: CWE-476
NVD

HIGH
CVE-2026-90776
CVE-2026-90776
pkg: node

published: Sep 13, 2026

Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser component when parsing email addresses with RFC 5322 comments. Attackers can craft malicious email headers with comment-separated atoms to consume excessive CPU and block the Node.js event…
CWE: CWE-407
NVD

HIGH
CVE-2026-89549
CVE-2026-89549
pkg: node

published: Sep 11, 2026

In the Linux kernel, the following vulnerability has been resolved:

sunrpc: route to a populated pool in svc_pool_for_cpu()

svc_set_num_threads() spreads the requested threads evenly across the
service's pools (base = nrservs / sv_nrpools). When a service runs
fewer threads than it has pools — e…

NVD

HIGH
CVE-2026-87776
CVE-2026-87776
pkg: express

published: Sep 11, 2026

compression is a Node.js and Express compression middleware. In versions before 1.8.2, when a client aborts the connection while a compressed response is still being sent, the zlib stream created to compress that response is never destroyed, so each aborted compressed response leaks its native zlib …
CWE: CWE-401, CWE-459
NVD

HIGH
CVE-2026-89146
CVE-2026-89146
pkg: node

published: Sep 11, 2026

libp2p-rendezvous through 0.17.1 fails to validate registration TTL values in discovery responses, allowing attackers to trigger timer arithmetic overflow. A malicious rendezvous server can send a discovery response with an unbounded TTL value that causes the client node process to panic when comput…
CWE: CWE-190, CWE-617
NVD

HIGH
CVE-2026-87908
CVE-2026-87908
pkg: node

published: Sep 11, 2026

multiparty is a Node.js library for parsing multipart/form-data request bodies. In versions from 2.1.0 up to but not including 4.3.1, the parser does not bound the amount of memory used while accumulating the headers of a single multipart part. An unauthenticated attacker can send a single request w…
CWE: CWE-400, CWE-770
GitHub-GHSA

HIGH
rclone: S3 multipart declared-length memory exhaustion
GHSA-2p48-j3qc-rx9f
pkg: github.com/rclone/rclone
eco: go
published: Sep 10, 2026
## Summary

In streamed multipart mode, `serve s3` passes the request's declared part length to `multipart.NewRW().Reserve(contentLength)` before reading any part data. `Reserve` immediately obtains enough 1 MiB pool pages for the entire declared length. The request handler therefore allocates attac…

CVE-2026-88045
GitHub-GHSA

HIGH
Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logout
GHSA-3g9q-v48f-hh9w
pkg: open-webui
eco: pip
published: Sep 10, 2026
## Summary

The OIDC back-channel logout endpoint is unauthenticated by design, because the identity provider calls it without a browser session. Before checking whether the submitted logout token was genuine, the handler fetched the provider's discovery document and its signing keys over the networ…

CVE-2026-87011
GitHub-GHSA

HIGH
@argos-ci/core: CI Branch Name OS Command Injection
GHSA-4×45-gxvp-6283
pkg: @argos-ci/core
eco: npm
published: Sep 10, 2026
## CI Branch Name OS Command Injection in @argos-ci/core

### Summary

`@argos-ci/core@6.2.0` passes attacker-controlled CI branch/ref strings directly into an `execSync()` template literal in `packages/core/src/ci-environment/git.ts:89`. When a CI project has `hasRemoteContentAccess: false`, the Ar…

CVE-2026-59960
GitHub-GHSA

HIGH
mistral.rs: Unbounded Remote Media Fetch and Video Frame Expansion DoS
GHSA-m3wp-48jr-vr4g
pkg: mistralrs-server-core
eco: rust
published: Sep 10, 2026
## Unbounded Remote Media Fetch and Video Frame Expansion DoS

### Summary
The `POST /v1/chat/completions` endpoint in mistral.rs fetches attacker-supplied media URLs (image, audio, video) into server memory with no byte limit, and extracts every frame of a supplied video when `num_frames` is `None`…

NVD

HIGH
CVE-2026-45747
CVE-2026-45747
pkg: tls

published: Sep 10, 2026

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.16, the Lua TLS certificate information helper could dereference NULL certificate fields when a Lua script requested certificate information for TLS traffic wher…
CWE: CWE-476
NVD

HIGH
CVE-2026-88874
CVE-2026-88874
pkg: nginx

published: Sep 10, 2026

AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) does not enforce the Live stream password check on the stats endpoint or on the HLS origin. Live::_getStats() (plugin/Live/Live.php) returns a password-protected transmission's RTMP stream key, its isPasswordProtec…
CWE: CWE-200
NVD

HIGH
CVE-2026-49363
CVE-2026-49363
pkg: node

published: Sep 10, 2026

An unauthenticated remote attacker connecting with the CORE protocol can discover cluster node details by sending a SUBSCRIBE_TOPOLOGY request prior to authentication.

This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0.

Users are r…

CWE: CWE-306
GitHub-GHSA

HIGH
Nuxt Ollama: Public Runtime Config Exposes Ollama API Key to Browser Clients
GHSA-fxg7-897c-57mp
pkg: nuxt-ollama
eco: npm
published: Sep 9, 2026
## Public Runtime Config Exposes Ollama API Key to Browser Clients

### Summary

`nuxt-ollama@1.2.26` unconditionally merges all module options — including `api_key` — into Nuxt's **public** runtime config (`runtimeConfig.public.ollama`). Nuxt serializes `runtimeConfig.public` into the SSR HTML …

CVE-2026-59158
NVD

HIGH
CVE-2026-80924
CVE-2026-80924
pkg: linux

published: Sep 9, 2026

In the Linux kernel, the following vulnerability has been resolved:

crypto: krb5 – use kfree_sensitive() for derived key buffers

crypto_krb5_prepare_encryption() and crypto_krb5_prepare_checksum()
free the buffer holding the freshly derived keys with plain kfree(),
leaving the key material behind …

NVD

HIGH
CVE-2026-22591
CVE-2026-22591
pkg: express

published: Sep 9, 2026

eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to versions 2.6.12, 2.14.6, 3.2.4, and 3.4.3, Fast DDS’s implementation of SQL‑based content filtering (DDSSQLFilter) allows any participant in a DDS domain to re…
CWE: CWE-400, CWE-674
NVD

HIGH
CVE-2026-86201
CVE-2026-86201
pkg: jwt

published: Sep 9, 2026

PocketMine-MP before 5.41.1 contains a denial of service vulnerability in LoginPacket processing where large or complex structures in unknown clientData JWT properties cause excessive logging without sanitization. Attackers can send crafted LoginPackets with deeply nested or massive object structure…
CWE: CWE-400
NVD

HIGH
CVE-2026-87819
CVE-2026-87819
pkg: express

published: Sep 9, 2026

GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit author and committer fields. Attackers can craft a commit object with a malformed author field containing an unterminated angle bracket to cause quadratic backtrackin…
CWE: CWE-1333
NVD

HIGH
CVE-2026-87450
CVE-2026-87450
pkg: google chrome

published: Sep 9, 2026

Incorrect authorization in Permissions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted Chrome extension. (Chromium security severity: Medium)
CWE: CWE-863
NVD

HIGH
CVE-2026-87431
CVE-2026-87431
pkg: google chrome

published: Sep 9, 2026

Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted Chrome extension. (Chromium security severity: Medium)
CWE: CWE-862
NVD

HIGH
CVE-2026-86075
CVE-2026-86075
pkg: n8n n8n

published: Sep 8, 2026

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the OAuth Dynamic Client Registration endpoint bounded redirect_uris but accepted arbitrarily large client_name and grant_types values. An unauthenticated remote caller could repeatedly persist oversized values in oauth_…
CWE: CWE-770
GitHub-GHSA

HIGH
Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list
GHSA-2x7j-588g-ccc2
pkg: nodemailer
eco: npm
published: Sep 8, 2026
### Summary

Nodemailer's address parser (`lib/addressparser/index.js`) parses a list of comma‑separated addresses in **quadratic time — O(n²)** in the number of addresses. A single crafted address string (e.g. a `To`, `Cc`, `Bcc`, `From`, or `Reply‑To` value, or any value passed to the expor…

GitHub-GHSA

HIGH
multer vulnerable to Denial of Service via crafted multipart field names
GHSA-wc9g-mqfw-jrwm
pkg: multer
eco: npm
published: Sep 8, 2026
### Impact

A vulnerability in multer allows a remote, unauthenticated attacker to crash the Node.js process with a single `multipart/form-data` request. Two specially crafted text field names cause an uncaught `RangeError: Invalid array length` inside multer's field parsing, which is not routed to …

CVE-2026-77078
GitHub-GHSA

HIGH
multer vulnerable to Denial of Service via file descriptor leak on aborted uploads
GHSA-qfvm-cv95-jqjf
pkg: multer
eco: npm
published: Sep 8, 2026
### Impact

A vulnerability in multer `2.2.0` allows an attacker to trigger a Denial of Service (DoS) by aborting or truncating multipart uploads. When using `diskStorage`, the destination write stream is not closed if the upload is aborted before it finishes, so each failed request leaks an open fi…

CVE-2026-77037
GitHub-GHSA

HIGH
multer vulnerable to Denial of Service via oversized array index in field names
GHSA-535w-7cp7-47q4
pkg: multer
eco: npm
published: Sep 8, 2026
### Impact

multer is vulnerable to a Denial of Service (DoS) via a crafted array index in multipart field names. The `append-field` dependency parses bracket notation in field names, and a large numeric index such as `items[4294967294]` forces allocation of a maximum-length sparse array. A followin…

CVE-2026-82333
GitHub-GHSA

HIGH
js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources
GHSA-2883-xcg3-v3hh
pkg: js-yaml, js-yaml
eco: npm
published: Sep 8, 2026
## Summary

`maxTotalMergeKeys` does not count empty mappings. An attacker can repeatedly merge a large sequence of them and consume significant CPU without reaching the configured limit.

## Example

“`yaml
arr: &arr [{}, {}, {}, …] # N empty mappings
targets:
– <<: *arr # repea…

CVE-2026-84375
GitHub-GHSA

HIGH
HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)
GHSA-8xx6-hgc6-gc2m
pkg: httpx2
eco: pip
published: Sep 8, 2026
### Summary

When decoding a compressed response body (`gzip`, `deflate`, `br`, or `zstd`), HTTPX2 fully decompressed each network read before yielding content to the application. A small compressed input could therefore cause a large intermediate memory allocation, even when the application streame…

CVE-2026-84382
GitHub-GHSA

HIGH
NLTK: ReDoS in nltk.text.Text.findall() via unvalidated user-supplied regular expressions
GHSA-rrv8-h7p8-rx55
pkg: nltk
eco: pip
published: Sep 8, 2026
### Summary
NLTK's `Text.findall()` and `TokenSearcher.findall()` methods accept user-supplied regular expressions and pass them to the Python `re` engine without timeout or validation, enabling catastrophic backtracking (ReDoS). This issue is isolated to the `nltk.text` module and was resolved in a…
CVE-2026-80205
GitHub-GHSA

HIGH
GitPython: clone_from()/clone() omit –separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination
GHSA-8mcc-hrx5-hvxc
pkg: GitPython
eco: pip
published: Sep 8, 2026
– **CWE:** CWE-73 (External Control of File Name or Path) / CWE-22 (Path Traversal, in the "escapes intended base directory" sense)
– **Affected component:** `git/repo/base.py`, `Repo.unsafe_git_clone_options` (class attribute, lines 153-165) and `Repo._clone()` (lines 1477-1520), reached via the pu…
CVE-2026-78677
NVD

HIGH
CVE-2026-72923
CVE-2026-72923
pkg: node

published: Sep 8, 2026

In Microsoft.OpenApi.YamlReader from 2.0.0-preview.11 until 2.12.0 and from 3.0.0 until 3.10.0, and in Microsoft.OpenApi.Readers prior to 1.6.30, a small YAML OpenAPI document containing nested anchors and aliases can cause uncontrolled resource consumption when parsed through the public YAML reader…
CWE: CWE-400
NVD

HIGH
CVE-2026-69397
CVE-2026-69397
pkg: openssh

published: Sep 8, 2026

Use after free in OpenSSH for Windows allows an unauthorized attacker to execute code over a network.
CWE: CWE-416
NVD

HIGH
CVE-2026-68887
CVE-2026-68887
pkg: windows

published: Sep 8, 2026

Out-of-bounds read in Windows Message Queuing Queue Manager allows an unauthorized attacker to deny service over a network.
CWE: CWE-125
NVD

HIGH
CVE-2026-62759
CVE-2026-62759
pkg: windows

published: Sep 8, 2026

Authentication bypass by spoofing in Windows Netlogon allows an unauthorized attacker to perform spoofing over an adjacent network.
CWE: CWE-290
NVD

HIGH
CVE-2026-57098
CVE-2026-57098
pkg: windows

published: Sep 8, 2026

Improper verification of cryptographic signature in Windows RDP Client allows an unauthorized attacker to disclose information over a network.
CWE: CWE-347
GitHub-GHSA

HIGH
LiquidJS: Uncontrolled Resource Consumption in `join` filter allows template authors to bypass `memoryLimit` and crash the process
GHSA-4r6h-5v86-94p3
pkg: liquidjs
eco: npm
published: Sep 8, 2026
### Summary

The `join` filter (`src/filters/array.ts:8-13`) charges `memoryLimit` by array element **count**, not by the string length it produces, letting a template bypass a configured `memoryLimit` and allocate strings far past budget — bounded only by V8/process limits, not by `memoryLimit`.

CVE-2026-69222
NVD

HIGH
CVE-2026-47625
CVE-2026-47625
pkg: linux

published: Sep 8, 2026

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could abuse missing authorization. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service.
CWE: CWE-862
NVD

HIGH
CVE-2026-16497
CVE-2026-16497
pkg: linux

published: Sep 8, 2026

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause excessive iteration. A successful exploit of this vulnerability might lead to denial of service.
CWE: CWE-834
GitHub-GHSA

HIGH
NLTK: Symlink-based sandbox bypass in FramenetCorpusReader (bypasses the fix for CVE-2026-54292)
GHSA-f833-7jw8-xwrv
pkg: nltk
eco: pip
published: Sep 8, 2026
This is a **new, distinct vulnerability**: a bypass of the fix already published as [GHSA-xh95-f55m-82fw](https://github.com/nltk/nltk/security/advisories/GHSA-xh95-f55m-82fw) ("Path traversal in NLTK FramenetCorpusReader.frame() allows arbitrary XML file read, bypassing the nltk.pathsec sandbox"), …
CVE-2026-62384
NVD

HIGH
CVE-2026-79575
CVE-2026-79575
pkg: jwt

published: Sep 8, 2026

The JWT signing secret in yfexam-exam v2.0 is derived from the username and the current month instead of a random server-side key, making the secret key easily obtainable via a bruteforce attack.
CWE: CWE-330
NVD

HIGH
CVE-2026-3174
CVE-2026-3174
pkg: oauth

published: Sep 8, 2026

The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Stripe OAuth return endpoint in all versions up to, and including, 5.27.4. This makes it possible for unauthenticated attackers to overwrite the site's …
CWE: CWE-862
NVD

HIGH
CVE-2026-90647
CVE-2026-90647
pkg: tls

published: Sep 12, 2026

ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation vulnerability in the IEC 60870-5-104 TLS client (Task Mode). This allows a network-positioned attacker to bypass certificate validation via a certificate with multiple simultaneou…
CWE: CWE-295
NVD

HIGH
CVE-2026-84003
CVE-2026-84003
pkg: node

published: Sep 8, 2026

Authentication bypass by capture-replay in Microsoft Authentication Library (MSAL) for Node.js allows an unauthorized attacker to perform spoofing over a network.
CWE: CWE-294
NVD

HIGH
CVE-2026-73311
CVE-2026-73311
pkg: xenforo xenforo

published: Sep 8, 2026

XenForo before 2.3.13 contains an OAuth2 authorization code reuse vulnerability that allows attackers to obtain unauthorized token pairs by submitting a previously used authorization code. Attackers can exploit the failure to invalidate or mark authorization codes as consumed after initial token iss…
CWE: CWE-294
NVD

HIGH
CVE-2026-73309
CVE-2026-73309
pkg: xenforo xenforo

published: Sep 8, 2026

XenForo before 2.3.13 contains an authentication bypass vulnerability in the OAuth2 token endpoint that allows unauthenticated attackers to obtain valid token pairs by submitting empty values for client_secret and code_verifier parameters. Attackers can exploit PHP truthy evaluation logic, which tre…
CWE: CWE-697
GitHub-GHSA

HIGH
rclone: FTP cross-session auth-proxy backend confusion
GHSA-c476-6w5q-jw77
pkg: github.com/rclone/rclone
eco: go
published: Sep 10, 2026
## Summary

The FTP auth-proxy driver stores one obscured password per username in a server-wide map. It does not bind the credential or returned VFS to the authenticated FTP session. If two accepted credentials use the same username but resolve to different proxy backends, the later login overwrite…

CVE-2026-88017
NVD

HIGH
CVE-2026-86754
CVE-2026-86754
pkg: oauth

published: Sep 9, 2026

Snipe-IT before 8.7.0 fails to properly gate Laravel Passport's OAuth client management routes, allowing any authenticated user to register OAuth clients with attacker-controlled redirect URIs. Attackers can trick administrators into approving consent screens, then exchange authorization codes for b…
CWE: CWE-863
NVD

HIGH
CVE-2026-78627
CVE-2026-78627
pkg: oauth

published: Sep 8, 2026

The Okta Hyperdrive Integration installer does not mask the OAuth client secret when passed as an MSI property. The credential is recorded in plaintext in the installer log, the Application Event Log, and the process command line, all of which are readable by an authenticated local user on the works…
CWE: CWE-532
GitHub-GHSA

HIGH
mistral.rs Media Loader: Unauthenticated SSRF and arbitrary local file read via image_url
GHSA-wfgq-w7cq-qj7j
pkg: mistralrs-server-core
eco: rust
published: Sep 10, 2026
### Summary
mistral.rs fetches any request-supplied image/audio URL with no host or IP validation, and opens arbitrary local files (a `file://` URL, or any existing relative/absolute path). A remote, unauthenticated client of any vision/audio deployment can cause the server to issue requests to inte…
NVD

HIGH
CVE-2026-74239
CVE-2026-74239
pkg: xenforo xenforo

published: Sep 8, 2026

XenForo before 2.3.13 contains a path traversal vulnerability in the style archive importer on Windows deployments that allows authenticated non-super administrators with style permissions to write arbitrary files outside the intended extraction directory by using backslash-based traversal sequences…
CWE: CWE-22
GitHub-GHSA

HIGH
@jhb.software/payload-alt-text-plugin: Alt Text Endpoint Authorization Bypass via Payload Local API `overrideAccess` Omission
GHSA-4qpv-39hg-f7fx
pkg: @jhb.software/payload-alt-text-plugin
eco: npm
published: Sep 10, 2026
## Alt Text Endpoint Authorization Bypass via Payload Local API `overrideAccess` Omission

### Summary

`@jhb.software/payload-alt-text-plugin` v0.7.0 exposes custom Payload CMS endpoints (`POST /api/alt-text-plugin/generate` and `/bulk`) that call the Payload Local API (`findByID` and `update`) wit…

CVE-2026-59965
GitHub-GHSA

HIGH
Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion
GHSA-2724-6cpj-gf3v
pkg: open-webui
eco: pip
published: Sep 10, 2026
## Summary
External knowledge connections are created and owned by administrators, and are shared by every external knowledge base bound to them. Deleting an external knowledge base also removed that connection from the instance configuration, with no check on the caller's role and no check for othe…
CVE-2026-87998
GitHub-GHSA

HIGH
Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch
GHSA-34r3-9m95-vq73
pkg: open-webui
eco: pip
published: Sep 10, 2026
## Summary

Open WebUI fetches user-supplied URLs on the server for RAG URL ingestion and web search, and screens the resolved addresses so internal destinations cannot be reached. That screen decided whether a destination was external by asking Python's standard library whether the address is globa…

CVE-2026-87999
NVD

HIGH
CVE-2026-87999
CVE-2026-87999
pkg: python

published: Sep 9, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.11.1, POST /api/v1/retrieval/process/web and POST /api/v1/retrieval/process/web/search in backend/open_webui/retrieval/web/utils.py treated Python's globally routable address classification as proof that…
CWE: CWE-918
GitHub-GHSA

HIGH
OpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output tree
GHSA-2q42-4q24-7rgv
pkg: @typespec/openapi3, @typespec/compiler
eco: npm
published: Sep 8, 2026
### Summary

The `@typespec/openapi3` emitter retains the value of a `@versioned` enum member and interpolates it into the output filename as `{version}` without sanitizing path separators or traversal components. The completed path reaches the compiler's `emitFile()`, which creates the parent direc…

NVD

HIGH
CVE-2026-86074
CVE-2026-86074
pkg: n8n n8n

published: Sep 8, 2026

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the Instance AI credential setup flow accepted a credential test or verification URL without checking that it matched the workflow node's origin. Attacker-controlled fetched content could influence that URL after a user …
CWE: CWE-918
NVD

HIGH
CVE-2026-68893
CVE-2026-68893
pkg: windows

published: Sep 8, 2026

Use after free in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges over a network.
CWE: CWE-416
NVD

HIGH
CVE-2026-68846
CVE-2026-68846
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Sep 8, 2026

Use after free in Windows Kernel allows an authorized attacker to elevate privileges over a network.
CWE: CWE-416
NVD

HIGH
CVE-2026-68835
CVE-2026-68835
pkg: windows

published: Sep 8, 2026

Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges over a network.
CWE: CWE-416
NVD

HIGH
CVE-2026-86725
CVE-2026-86725
pkg: oauth

published: Sep 8, 2026

AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in the SocialMediaPublisher plugin's add.json.php endpoint that allows authenticated users to modify other users' OAuth token records. Attackers can supply arbitrary row IDs to overwrite another us…
CWE: CWE-639
NVD

HIGH
CVE-2026-81192
CVE-2026-81192
pkg: linux

published: Sep 8, 2026

`OpenTelemetry.Resources.Host` NuGet package, which provides OpenTelemetry resource detectors for host, is affected by an untrusted search path vulnerability on macOS. Prior to version 1.16.0-beta.2, the `host.id` resource attribute detector launches the `sh` and `ioreg` executables by bare name rat…
CWE: CWE-426
NVD

HIGH
CVE-2026-68884
CVE-2026-68884
pkg: windows

published: Sep 8, 2026

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
CWE: CWE-122
NVD

HIGH
CVE-2026-68847
CVE-2026-68847
pkg: windows

published: Sep 8, 2026

Use after free in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.
CWE: CWE-416
NVD

HIGH
CVE-2026-68840
CVE-2026-68840
pkg: windows

published: Sep 8, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate privileges locally.
CWE: CWE-362, CWE-416
NVD

HIGH
CVE-2026-68837
CVE-2026-68837
pkg: windows

published: Sep 8, 2026

Use after free in Windows File History Service allows an authorized attacker to elevate privileges locally.
CWE: CWE-416
NVD

HIGH
CVE-2026-68825
CVE-2026-68825
pkg: windows

published: Sep 8, 2026

Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.
CWE: CWE-416
NVD

HIGH
CVE-2026-68824
CVE-2026-68824
pkg: windows

published: Sep 8, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.
CWE: CWE-362, CWE-416
NVD

HIGH
CVE-2026-62694
CVE-2026-62694
pkg: windows

published: Sep 8, 2026

Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.
CWE: CWE-416
NVD

HIGH
CVE-2026-50349
CVE-2026-50349
pkg: windows

published: Sep 8, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CWE: CWE-362, CWE-416
GitHub-GHSA

HIGH
NLTK: Symlink escape in CorpusReader allows arbitrary local file read outside the corpus root
GHSA-r6gq-whwq-mvg9
pkg: nltk
eco: pip
published: Sep 8, 2026
### Summary
`nltk.corpus.reader.api.CorpusReader.open()` can be used to read files outside the intended corpus root via a symlink placed inside that root. Although NLTK blocks absolute paths and `..` traversal, the current boundary check is only lexical and does not account for symlink resolution. T…
CVE-2026-70626
GitHub-GHSA

HIGH
NLTK: Stable FrameNet and NKJP readers parse outside-root XML
GHSA-568f-pv23-39p4
pkg: nltk
eco: pip
published: Sep 8, 2026
### Summary

Published `nltk==3.9.4` still contains several XML-reader entrypoints that build parser paths from caller-controlled selectors or trusted-looking index state without preserving the corpus-root boundary.

### Details

– **Vulnerability type:** Path traversal and trusted-root bypass
– **A…

CVE-2026-62385
GitHub-GHSA

HIGH
Central Dogma: SSH host-key verification permanently disabled in Git mirror (SshGitMirror)
GHSA-vjfw-cpmh-xwv3
pkg: com.linecorp.centraldogma:centraldogma-server-mirror-git
eco: maven
published: Sep 11, 2026
# Vulnerability

Central Dogma's Git mirror SSH client installs an Apache MINA SSHD `ServerKeyVerifier` lambda that returns `true` unconditionally for every outbound SSH connection used by `git+ssh://` mirrors. The accompanying lines disable the `known_hosts` and `~/.ssh/config` fallbacks, and a rep…

CVE-2026-11745
GitHub-GHSA

HIGH
Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization
GHSA-w4v4-9rw7-5326
pkg: github.com/traefik/traefik/v3, github.com/traefik/traefik/v2
eco: go
published: Sep 10, 2026
## Summary

There is a high-severity request-smuggling vulnerability in Traefik's handling of the HTTP/1.1 `Upgrade` mechanism. Since Traefik moved to unencrypted HTTP/2 with prior knowledge (Go 1.24), a client-initiated `Upgrade: h2c` request header and its connection-specific `HTTP2-Settings` head…

CVE-2026-88008
GitHub-GHSA

HIGH
Traefik entrypoint header-name sanitization bypassed via request trailers
GHSA-v67p-phpq-fc8x
pkg: github.com/traefik/traefik/v3
eco: go
published: Sep 10, 2026
## Summary

Traefik's entrypoint defenses against spoofed trusted header names — `aliasHeadersStrategy` / `underscoreHeadersStrategy` in `delete` or `reject` mode, and the default `forwardedHeaders` stripping of client-supplied `X-Forwarded-*` — scan `req.Header` only and never `req.Trailer`. An…

CVE-2026-88004
GitHub-GHSA

HIGH
Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing path-scoped routing, middleware guards and access logging
GHSA-f52w-8j3h-j724
pkg: github.com/traefik/traefik/v3, github.com/traefik/traefik/v2
eco: go
published: Sep 10, 2026
## Summary

Traefik accepts an HTTP/1.x request whose request-target is in rootless / opaque form (for example `GET http:http://internal-vhost/admin HTTP/1.1`). Go parses this into `URL.Opaque` with an empty `URL.Path`, so Traefik evaluates all routing, path-sanitization, middleware and access-log d…

CVE-2026-88009
GitHub-GHSA

HIGH
n8n: Expression Sandbox Escape via Shared Builtin Tampering and Code-Printer Injection Leads to Code Execution
GHSA-6xcw-7xm6-48c6
pkg: n8n, n8n, n8n
eco: npm
published: Sep 10, 2026
## Impact

Two stages of expression code generation built source text by calling the global `JSON.stringify` at generation time: the compiler when printing synthetic string literals, and the isolate bridge when interpolating a timezone value into its per-evaluation wrapper. An expression that replac…

CVE-2026-86083
GitHub-GHSA

HIGH
Angular: SSR XSS via Unescaped <template> Content Across DocumentFragment Boundaries in Fallback Raw-Content Elements
GHSA-v3p8-whq6-r5jg
pkg: @angular/platform-server, @angular/platform-server, @angular/platform-server
eco: npm
published: Sep 10, 2026
### Summary
An XSS vulnerability exists in `@angular/platform-server` during server-side rendering (SSR) HTML serialization when traversing ancestor tags across `<template>` element boundaries. When an application renders untrusted user input within raw-text tags (`<xmp>`, `<style>`, `<script>`), co…
CVE-2026-88060
GitHub-GHSA

HIGH
Angular: SSRF and Cross-Origin Credential Disclosure via URL Resolution Discrepancy in SSR
GHSA-f6mr-pjwc-34m4
pkg: @angular/platform-server, @angular/platform-server, @angular/platform-server
eco: npm
published: Sep 10, 2026
### Summary
A discrepancy between WHATWG URL parsing and Angular SSR's URL resolution allows attackers to bypass same-origin checks and cause Server-Side Request Forgery (SSRF), potentially leaking sensitive server-side credentials.

### Technical Description
When applications validate incoming URLs…

CVE-2026-88056
GitHub-GHSA

HIGH
n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Node
GHSA-34ff-336r-5q23
pkg: n8n, n8n, n8n
eco: npm
published: Sep 10, 2026
## Impact

The OpenAI Chat Model node checked a custom base URL against the credential's allowed-domains configuration before sending a request, but the model-search dropdown did not. A request setting `options.baseURL` on that path reached an arbitrary host with the credential attached, so the doma…

CVE-2026-86082
GitHub-GHSA

HIGH
n8n: Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a Git Node Clone Path
GHSA-j535-v25q-vx3q
pkg: n8n, n8n, n8n
eco: npm
published: Sep 10, 2026
## Impact

The Git node's clone operation matched the destination path against the default `N8N_BLOCK_FILE_PATTERNS` expression, which was written so that a crafted path caused catastrophic backtracking. Evaluation runs synchronously in the main n8n process, so an authenticated user could freeze the…

CVE-2026-86081
GitHub-GHSA

HIGH
n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint
GHSA-hh89-3r9w-qj3j
pkg: n8n, n8n
eco: npm
published: Sep 10, 2026
## Impact

The OAuth Dynamic Client Registration endpoints validated field sizes only for `redirect_uris`, leaving `client_name` and `grant_types` bounded by presence checks alone. An unauthenticated remote caller could submit arbitrarily large values in either field and have them persisted to the d…

CVE-2026-86075
GitHub-GHSA

HIGH
n8n: Expression Sandbox Escape via Class-Field Sanitizer Rebinding Can Lead to Code Execution
GHSA-hw8v-xxg5-vvvx
pkg: n8n, n8n, n8n
eco: npm
published: Sep 10, 2026
## Impact

The expression compiler's sanitizer resolved through a dynamically-scoped `this`, so a class field named `__sanitize` rebound it and reached the `Function` constructor. On the backend, any expression author could run code in the n8n process; in the editor preview, a member's expression co…

CVE-2026-86076
GitHub-GHSA

HIGH
Excelize: Streaming GetRows row-bound bypass causes attacker-controlled allocation
GHSA-q5j5-6p94-4gwc
pkg: github.com/xuri/excelize/v2, github.com/xuri/excelize
eco: go
published: Sep 10, 2026
# Streaming GetRows row-bound bypass causes attacker-controlled allocation

## Summary

Excelize's prior row-bound fix for GHSA-h69g / CVE-2026-54063 protects the checked worksheet parser, but the streaming worksheet reader used by `Rows` and `GetRows` does not enforce the same `TotalRows` bound on …

CVE-2026-59161
GitHub-GHSA

HIGH
GeoNetwork Web Module: Unauthenticaded Server-Side Request Forgery in SLD Tool
GHSA-5hx7-j24v-rffj
pkg: org.geonetwork-opensource:gn-web-app, org.geonetwork-opensource:gn-web-app
eco: maven
published: Sep 9, 2026
### Summary
An unauthenticated server-side request forgery vulnerability lets any anonymous user make the GeoNetwork server issue arbitrary outbound HTTP requests. This gives an external attacker a position inside the server's network, making it possible to make internal requests no matter if the re…
CVE-2026-55864
GitHub-GHSA

HIGH
smol-toml: Denial of Service via malformed TOML documents
GHSA-7w5x-hrqm-74c2
pkg: smol-toml
eco: npm
published: Sep 9, 2026
### Summary
`parse()` can be forced into an infinite loop when a value inside an array or inline table is followed by a comment that has no trailing newline (i.e. the comment "ends" the document).

The library fails to exit an internal loop when attempting to find the end of the structure, resetting…

CVE-2026-85730
GitHub-GHSA

HIGH
Windows ML CLI: CORS misconfig enables localhost RCE
GHSA-96p9-rh4f-92cf
pkg: winml-cli
eco: pip
published: Sep 8, 2026
Case Description:

MSRC Notes: Attachments: 1 file(s) attached (1 mp4) Summary: The vulnerability lies in the 'serve/cli_api.py' component of the 'winml-cli' project, which exposes all winml CLI commands over HTTP without authentication. Although it binds to localhost by default, it sets 'allow_orig…

CVE-2026-84452
GitHub-GHSA

HIGH
sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545
GHSA-rgj7-g3m4-5g8c
pkg: sharp
eco: npm
published: Sep 8, 2026
### Impact
A number of vulnerabilities, two rated as "Critical" severity using CVSSv3, have been discovered and fixed in the upstream libheif dependency. These can lead to possible remote code execution (RCE) on glibc-based Linux when run under certain conditions.

The attack vector for these claims…

GitHub-GHSA

HIGH
Tiptap: Quadratic ReDoS in block and inline Markdown attribute parsing
GHSA-j95f-988m-3j2f
pkg: @tiptap/core
eco: npm
published: Sep 8, 2026
## Summary

`@tiptap/core` contains two quadratic regular-expression denial-of-service paths in its default Markdown attribute parsers. Pandoc-style block attributes use two unanchored greedy expressions that rescan repeated `__QUOTED_0` prefixes. Inline shortcode attributes use another unanchored g…

GitHub-GHSA

HIGH
gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers
GHSA-2v4p-qf9q-27wj
pkg: google.golang.org/grpc, google.golang.org/grpc, google.golang.org/grpc
eco: go
published: Sep 8, 2026
A vulnerability exists in gRPC-Go servers configured with `xds.NewGRPCServer()` where a crafted request missing both `:authority` and `Host` headers can cause a server panic, resulting in a Denial of Service (DoS).

Servers built with `xds.NewGRPCServer` install an xDS routing interceptor on every R…

CVE-2026-84445
GitHub-GHSA

HIGH
xmldom: Processing Instruction Target Injection Bypasses requireWellFormed
GHSA-c7q8-3ch8-vqpv
pkg: @xmldom/xmldom, @xmldom/xmldom, xmldom
eco: npm
published: Sep 8, 2026
## Summary

`Document.createProcessingInstruction()` in `@xmldom/xmldom` performs no validation on the `target` parameter. The `requireWellFormed: true` serializer option validates only for `:` in the target and a case-insensitive `xml` prefix, but does not check for `>` characters. A `>` in the tar…

CVE-2026-83616
GitHub-GHSA

HIGH
xmldom: requireWellFormed element/attribute name validation is bypassable via an embedded line terminator
GHSA-jxjr-3g7g-3944
pkg: @xmldom/xmldom
eco: npm
published: Sep 8, 2026
## Summary

An embedded line terminator bypasses the `requireWellFormed` serializer check for element and
attribute names. The check was added to fix GHSA-w2rr-34g9-rvrj and GHSA-4w3w-2rp5-g8jm; a name whose
first line is well-formed slips past it and is serialized verbatim, so the characters after …

CVE-2026-83617
GitHub-GHSA

HIGH
xmldom: DocType `name` Injection Bypasses requireWellFormed
GHSA-27p8-2357-5qqv
pkg: @xmldom/xmldom, @xmldom/xmldom, xmldom
eco: npm
published: Sep 8, 2026
## Summary

The `@xmldom/xmldom` serializer emits `DocumentType.name` verbatim into the
`<!DOCTYPE …>` declaration with no well-formedness guard. GHSA-f6ww-3ggp-fr8h
(CVE-2026-41674) hardened the serializer's `requireWellFormed` path for a
DocumentType's sibling fields — `publicId`, `systemId`, …

CVE-2026-83608
GitHub-GHSA

HIGH
xmldom: Creation-time XML Name/QName validation is bypassable via an embedded line terminator, allowing injection on the default serialization path
GHSA-3px3-54cx-rmw9
pkg: @xmldom/xmldom
eco: npm
published: Sep 8, 2026
## Summary

An embedded line terminator bypasses xmldom's always-on, WHATWG-mandated creation-time name
validation. `createElementNS`, `createAttributeNS`, `createDocumentType`, and `createAttribute` should
reject a malformed qualified name with `InvalidCharacterError`, but a name whose first line i…

CVE-2026-83609
GitHub-GHSA

HIGH
xmldom: requireWellFormed DocType publicId/systemId validation is bypassable via an embedded line terminator
GHSA-vr34-hp96-76pp
pkg: @xmldom/xmldom
eco: npm
published: Sep 8, 2026
## Summary

An embedded line terminator bypasses the `requireWellFormed` serializer check for a `DocumentType`'s
publicId and systemId. The check was added to fix GHSA-f6ww-3ggp-fr8h; an id whose first line is a
valid literal slips past it and is emitted verbatim into the `<!DOCTYPE …>` declaratio…

CVE-2026-83618
GitHub-GHSA

HIGH
xmldom: Quadratic-time attribute deduplication
GHSA-8344-3jmq-59r6
pkg: @xmldom/xmldom, @xmldom/xmldom, xmldom
eco: npm
published: Sep 8, 2026
## Summary

xmldom builds the attribute collection of every parsed element by inserting attributes one at a
time into a DOM `NamedNodeMap`. Each insertion first performs a **linear scan of all
already-inserted attributes** to enforce the DOM uniqueness rule (no two attributes with the same
qualified…

CVE-2026-83613
GitHub-GHSA

HIGH
xmldom: End-tag Whitespace-Trim Regex ReDoS — quadratic backtracking in the 0.8.x end-tag parser
GHSA-x4fp-j954-r2f4
pkg: @xmldom/xmldom
eco: npm
published: Sep 8, 2026
## Summary

On the `@xmldom/xmldom` **`0.8.x`** line, parsing an XML end tag whose name is followed by a long run
of whitespace and then a non-whitespace character triggers quadratic-time regular-expression
backtracking (ReDoS), so a single small crafted end tag stalls the Node.js event loop. It is …

CVE-2026-83619
GitHub-GHSA

HIGH
xmldom: Quadratic-memory consumption
GHSA-965w-775f-mr7g
pkg: @xmldom/xmldom, @xmldom/xmldom, xmldom
eco: npm
published: Sep 8, 2026
## Summary

When an element declares a namespace prefix, xmldom copies the entire in-scope namespace map
into a fresh object and keeps that copy on the element while it is open on the parse stack. A
crafted document that nests N elements, each declaring one unique prefix, therefore drives the
parser…

CVE-2026-83615
GitHub-GHSA

HIGH
xmldom: Quadratic-time parsing via the malformed-input recovery path — `parseElementStartPart` re-scan and `normalize()` adjacent-text merge
GHSA-93r5-fhx6-vmg9
pkg: @xmldom/xmldom, @xmldom/xmldom, xmldom
eco: npm
published: Sep 8, 2026
## Summary

`xmldom`'s malformed-input **error-recovery path** has two quadratic-time (O(n²)) behaviors that a
single crafted input triggers together, so a tiny, highly compressible document (tens of KB) stalls
the Node.js event loop for multiple seconds. It is reachable from `DOMParser.parseFromSt…

CVE-2026-83614
GitHub-GHSA

HIGH
xmldom: HTML raw-text closing-tag case mismatch causes output amplification
GHSA-6mj3-qw4j-hgrw
pkg: @xmldom/xmldom
eco: npm
published: Sep 8, 2026
## Summary

In HTML mode (`text/html`), a raw-text element (`script`, `style`, `textarea`, `title`) whose closing
tag differs in case from its opening tag (e.g. `</ScRiPt>` for `<script>`) is mishandled by the
parser, producing quadratic (O(n²)) output growth — a small crafted document parses and…

CVE-2026-83612
GitHub-GHSA

HIGH
xmldom PI grammar regex ReDoS: quadratic backtracking on unterminated processing instructions
GHSA-g53g-w8rj-fmg7
pkg: @xmldom/xmldom
eco: npm
published: Sep 8, 2026
## Summary

`@xmldom/xmldom`'s processing-instruction (PI) grammar regex exhibits quadratic-time backtracking
(ReDoS) when parsing an **unterminated** processing instruction. A single small XML document
containing `<?` + a target + a long run of whitespace and no closing `?>` forces the regular
expr…

CVE-2026-83606
GitHub-GHSA

HIGH
xmldom: Element name injection via createElement() bypasses requireWellFormed
GHSA-w2rr-34g9-rvrj
pkg: @xmldom/xmldom, @xmldom/xmldom, xmldom
eco: npm
published: Sep 8, 2026
## Summary

`Document.createElement()` in `@xmldom/xmldom` accepts arbitrary strings as the `tagName` parameter with zero validation. The serializer emits the tag name verbatim into XML/HTML output. Critically, the `requireWellFormed: true` serializer option — the recommended mitigation from CVE-2…

CVE-2026-83607
GitHub-GHSA

HIGH
xmldom: Attribute name injection via setAttribute() bypasses requireWellFormed
GHSA-4w3w-2rp5-g8jm
pkg: @xmldom/xmldom, @xmldom/xmldom, xmldom
eco: npm
published: Sep 8, 2026
## Summary

`Element.setAttribute()` in `@xmldom/xmldom` bypasses attribute name validation by calling the private `_createAttribute(name)` method, which performs no validation. The public `createAttribute()` method correctly validates names against an anchored `QName` pattern, but `setAttribute()` …

CVE-2026-83605
GitHub-GHSA

HIGH
NLTK: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions
GHSA-w3v8-gmh9-3wv7
pkg: nltk
eco: pip
published: Sep 8, 2026
### Summary
The NLTK `tgrep` module accepts user-supplied regular expressions and passes them to the Python `re` engine without a timeout or validation, enabling catastrophic backtracking (ReDoS). Applications that expose the `tgrep` API to external input are vulnerable to a single-request denial of…
CVE-2026-80206
GitHub-GHSA

HIGH
NLTK: Corpus Reader Sandbox Bypass
GHSA-3gq4-3j92-5w49
pkg: nltk
eco: pip
published: Sep 8, 2026
## Summary

NLTK corpus-reader constructors can still reach outside-root file and database reads before the `nltk.pathsec` sandbox boundary is enforced.

The PoC shows the safe path blocked by `pathsec.open`, then `LinThesaurusCorpusReader` and `PanLexLiteCorpusReader` succeeding in the same process…

CVE-2026-79674
GitHub-GHSA

HIGH
NLTK: Corpus readers follow symlinks outside trusted roots despite pathsec enforcement
GHSA-p4rw-rvv2-7xwr
pkg: nltk
eco: pip
published: Sep 8, 2026
### Summary

Several corpus readers still step outside NLTK's symlink-aware trusted-root model. They derive in-root paths from trusted corpus state, convert those paths back into plain strings, and reopen them with built-in `open()` rather than `nltk.pathsec.open()`.

### Details

– **Vulnerability …

CVE-2026-79676
GitHub-GHSA

HIGH
NLTK: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parses
GHSA-97qj-x29f-37w7
pkg: nltk
eco: pip
published: Sep 8, 2026
Several XML parsing sites in NLTK still used `xml.etree.ElementTree` directly, which honours `<!ENTITY>` declarations in a document's internal DTD subset. A crafted document a few hundred bytes long can expand to megabytes in memory (each nesting level multiplies by ten), a denial-of-service.

Affec…

CVE-2026-78681
GitHub-GHSA

HIGH
NLTK: pathsec SSRF protection can be bypassed when a proxy is configured
GHSA-6ww7-3frv-cqxh
pkg: nltk
eco: pip
published: Sep 8, 2026
### Summary

Current NLTK source reopens SSRF in proxied environments. `pathsec.urlopen()` validates the requested hostname locally, but once proxy inheritance is enabled the real fetch is performed by the proxy rather than by the validated direct-connect socket path.

### Details

– **Vulnerability…

CVE-2026-78682
GitHub-GHSA

HIGH
NLTK: StreamBackedCorpusView Bypasses pathsec.ENFORCE – Arbitrary Local File Read
GHSA-x5ph-mj9p-rfr8
pkg: nltk
eco: pip
published: Sep 8, 2026
## Summary
Setting `nltk.pathsec.ENFORCE = True` is documented to sandbox all file access to allowed NLTK data directories and raise `PermissionError` on unauthorized access. However, `StreamBackedCorpusView` opens files via `builtins.open()` directly, bypassing `pathsec.validate_path()` entirely. A…
CVE-2026-63312
NVD

MEDIUM
CVE-2026-90474
CVE-2026-90474
pkg: oauth

published: Sep 12, 2026

MCPHub before 1.0.32 contains an authentication bypass vulnerability in its embedded OAuth 2.0 authorization server where client authentication is disabled by default and PKCE enforcement is optional. Attackers who obtain an authorization code through interception can redeem it for access tokens wit…
CWE: CWE-287
GitHub-GHSA

MEDIUM
Open WebUI: A user's session cookies are sent to tool servers configured for bearer authentication
GHSA-p78m-89r6-pgf7
pkg: open-webui
eco: pip
published: Sep 10, 2026
## Summary

When more than one external tool server is reachable in the same request, a tool call to a server configured for bearer authentication can arrive carrying the calling user's Open WebUI session cookies alongside that server's own key. The cookie jar is built per connection, but the callab…

CVE-2026-87015
NVD

MEDIUM
CVE-2026-87015
CVE-2026-87015
pkg: oauth

published: Sep 9, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.27 until 0.11.1, backend/open_webui/utils/tools.py captured a cookie jar from the enclosing connection loop instead of binding it to each external tool callable. When multiple tool servers were attached an…
CWE: CWE-201
NVD

MEDIUM
CVE-2026-87872
CVE-2026-87872
pkg: tls

published: Sep 9, 2026

A flaw was found in the OCAPI modules (ocapi_command, ocapi_info) of the
community.general Ansible collection. The shared OCAPI request helper disables
TLS certificate validation on every request and the modules expose no parameter
to re-enable it, while sending HTTP Basic-Auth credentials to an htt…
CWE: CWE-295
GitHub-GHSA

MEDIUM
gix-sec safe.directory protections absent for elevated administrators
GHSA-7rhf-42qf-vrvc
pkg: gix-sec
eco: rust
published: Sep 9, 2026
### Summary

In a process run with full administrative rights on Windows, `gix-sec` wrongly treats all locations as trusted, leading to the execution of commands configured in repositories controlled by limited user accounts.

### Details

In a similar way to Git, gitoxide tries to avoid operating i…

CVE-2025-24890
NVD

MEDIUM
CVE-2026-68833
CVE-2026-68833
pkg: windows

published: Sep 8, 2026

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.
CWE: CWE-122
NVD

MEDIUM
CVE-2026-78545
CVE-2026-78545
pkg: nginx

published: Sep 8, 2026

The Okta Access Gateway does not sanitize the application label field before including it in the generated nginx configuration file. The unsanitized value is interpolated into an nginx server block directive, resulting in execution of injected directives.
CWE: CWE-94
NVD

MEDIUM
CVE-2026-54248
CVE-2026-54248
pkg: docker

published: Sep 11, 2026

Doco-CD is a GitOps continuous delivery tool that automatically deploys and updates Docker Compose projects/services and Swarm stacks. Prior to version 0.90.1, a trust-boundary flaw in OCI artifact verification allowed artifact-provided deployment config to influence the policy used to verify that s…
CWE: CWE-347, CWE-501
GitHub-GHSA

MEDIUM
@Mockoon/commons-server: Path traversal in templated `filePath` lets a request escape the served directory (prefix-only base check)
GHSA-8wqc-v2q8-vff2
pkg: @mockoon/commons-server, @mockoon/cli
eco: npm
published: Sep 11, 2026
## Summary

A `FILE` response whose `filePath` embeds request data (e.g. `"/srv/public/{{queryParam 'name'}}"`, the documented way to let the client pick a file) is confined by `getSafeFilePath` with `resolvedPath.startsWith(staticBaseDir)`. That prefix test has no path-separator boundary, so a `../…

CVE-2026-59149
GitHub-GHSA

MEDIUM
Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange
GHSA-wvm9-9g5j-623f
pkg: open-webui
eco: pip
published: Sep 10, 2026
## Summary
Open WebUI's OAuth token exchange endpoint issues a session for a provider access token without running the OAuth role management that the normal OAuth login callback runs. A user whose provider roles the login callback would refuse, or would demote, could still obtain a working session a…
CVE-2026-88006
GitHub-GHSA

MEDIUM
rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local –links escapes the destination
GHSA-f8g7-2xjc-7mfh
pkg: github.com/rclone/rclone
eco: go
published: Sep 10, 2026
## Summary
With `-l/–links`, rclone's local backend recreates a source `.rclonelink` object as a real symlink at the destination **verbatim** (preserved by design for faithful backups). Directory-metadata application, however, does **not** go through the `os.Root` sandbox and does **not** use NOFOL…
CVE-2026-88016
GitHub-GHSA

MEDIUM
Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes
GHSA-wjwr-xfp9-r66p
pkg: open-webui
eco: pip
published: Sep 10, 2026
## Summary

A user who is demoted from admin by an identity provider keeps admin-level read and write access to every user's notes, over any Socket.IO connection that was already open when the demotion happened. Open WebUI caches the user's role on the socket at connection time, and the two SSO role…

CVE-2026-87014
NVD

MEDIUM
CVE-2026-88006
CVE-2026-88006
pkg: oauth

published: Sep 10, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.1, Open WebUI's OAuth token exchange endpoint issues a session for a provider access token without running the OAuth role management that the normal OAuth login callback runs. A user whose pro…
CWE: CWE-863
NVD

MEDIUM
CVE-2026-88005
CVE-2026-88005
pkg: oauth

published: Sep 10, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.9.0, Open WebUI's OAuth token exchange endpoint issues a session for a provider access token without applying the email domain allowlist that the normal OAuth login callback enforces. An account …
CWE: CWE-863
GitHub-GHSA

MEDIUM
Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange
GHSA-4qg5-cxx4-g927
pkg: open-webui
eco: pip
published: Sep 10, 2026
## Summary
Open WebUI's OAuth token exchange endpoint issues a session for a provider access token without applying the email domain allowlist that the normal OAuth login callback enforces. An account whose email domain the login callback would refuse could still obtain a working session through thi…
CVE-2026-88005
NVD

MEDIUM
CVE-2026-84828
CVE-2026-84828
pkg: node

published: Sep 10, 2026

A flaw was found in PCS (Pacemaker Configuration System). A local attacker with membership in the 'haclient' group can exploit the 'pcs host auth –token' command to read the contents of arbitrary files on the filesystem, provided the files are shorter than 256 bytes. The file contents are read with…
CWE: CWE-732
GitHub-GHSA

MEDIUM
Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree
GHSA-3cgp-3cqx-j8w2
pkg: open-webui
eco: pip
published: Sep 9, 2026
## Summary
Chat histories are stored as an unvalidated JSON object. After a message is deleted, the code that picks the chat's new current message walked down the `childrenIds` links without recording where it had already been. Any account with the default `user` role could store a chat whose messag…
CVE-2026-88000
GitHub-GHSA

MEDIUM
Open WebUI: Any authenticated user can hang the server via a cyclic chat message history
GHSA-jqhh-cjmq-vmv6
pkg: open-webui
eco: pip
published: Sep 9, 2026
## Summary
Chat histories are stored as an unvalidated JSON object. The walk that reconstructs a chat's message chain detected repeats using each message's own `id` field while moving through the history by map key, so a message that simply omitted `id` was never recorded as visited. A history whose…
CVE-2026-88002
GitHub-GHSA

MEDIUM
webhookd: Unrestricted HTTP Header to Shell Variable Injection
GHSA-v25g-mvwr-f5fp
pkg: github.com/ncarlier/webhookd
eco: go
published: Sep 9, 2026
## Description
Before 1.22, if the Basic Auth (`htpasswd`) middleware was not configured, all incoming HTTP headers were blindly forwarded to the webhook script execution environment as shell variables. While the Basic Auth middleware correctly strips the authentication header (`X-WebAuthn-User`) fr…
CVE-2026-59157
NVD

MEDIUM
CVE-2026-87014
CVE-2026-87014
pkg: oauth

published: Sep 9, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, role synchronization in backend/open_webui/routers/auths.py and backend/open_webui/utils/oauth.py updated an administrator's database role without invalidating the user record cached by bac…
CWE: CWE-613, CWE-863
NVD

MEDIUM
CVE-2026-87468
CVE-2026-87468
pkg: google chrome

published: Sep 9, 2026

Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-863
NVD

MEDIUM
CVE-2026-87459
CVE-2026-87459
pkg: google chrome

published: Sep 9, 2026

Observable discrepancy in Select in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
CWE: CWE-203
NVD

MEDIUM
CVE-2026-87454
CVE-2026-87454
pkg: google chrome, microsoft windows

published: Sep 9, 2026

Information leak in Enterprise in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-200
NVD

MEDIUM
CVE-2026-87447
CVE-2026-87447
pkg: google chrome

published: Sep 9, 2026

Incorrect authorization in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: High)
CWE: CWE-863
NVD

MEDIUM
CVE-2026-87446
CVE-2026-87446
pkg: google chrome

published: Sep 9, 2026

Incomplete cleanup in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium)
CWE: CWE-459
NVD

MEDIUM
CVE-2026-87443
CVE-2026-87443
pkg: google chrome

published: Sep 9, 2026

Missing authorization in Actor in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-862
NVD

MEDIUM
CVE-2026-87441
CVE-2026-87441
pkg: google chrome

published: Sep 9, 2026

Missing authorization in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium)
CWE: CWE-862
NVD

MEDIUM
CVE-2026-87437
CVE-2026-87437
pkg: google chrome

published: Sep 9, 2026

Information leak in Frames in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)
CWE: CWE-200
NVD

MEDIUM
CVE-2026-87436
CVE-2026-87436
pkg: google chrome

published: Sep 9, 2026

Incomplete cleanup in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Medium)
CWE: CWE-459
NVD

MEDIUM
CVE-2026-87429
CVE-2026-87429
pkg: google chrome

published: Sep 9, 2026

Missing authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
CWE: CWE-862
NVD

MEDIUM
CVE-2026-86082
CVE-2026-86082
pkg: n8n n8n

published: Sep 8, 2026

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the OpenAI Chat Model node enforced credential allowed-domain restrictions for normal calls but not for the model-search dropdown. A workflow editor could set options.baseURL to an arbitrary host and make the …
CWE: CWE-918
NVD

MEDIUM
CVE-2026-86079
CVE-2026-86079
pkg: n8n n8n

published: Sep 8, 2026

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Elasticsearch and ElasticSecurity nodes interpolated workflow-controlled index and document identifiers directly into REST request paths. An identifier containing path separators or dot segments could sele…
CWE: CWE-22
NVD

MEDIUM
CVE-2026-86078
CVE-2026-86078
pkg: n8n n8n

published: Sep 8, 2026

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the Instance AI workflow summary used node names and connection keys from stored workflows as ordinary object keys. A workflow submitted through the REST API could contain __proto__ or constructor, causing nested writes …
CWE: CWE-1321
NVD

MEDIUM
CVE-2026-86077
CVE-2026-86077
pkg: n8n n8n

published: Sep 8, 2026

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the /chat WebSocket route accepted a resumeToken and resumed a paused execution without checking that the target node supported chat messages. An anonymous form submitter who received that token could reuse it on the cha…
CWE: CWE-862
GitHub-GHSA

MEDIUM
Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain
GHSA-wmmp-3585-3rmp
pkg: nodemailer
eco: npm
published: Sep 8, 2026
### Summary

Nodemailer resolves an international (IDN / non-ASCII) recipient **domain** to a different Punycode `xn--` label than every UTS‑46‑conformant parser (web browsers, the WHATWG URL Standard, Node's `url.domainToASCII`, Python's `idna`). Its address normalizer (`_normalizeAddress` in `…

GitHub-GHSA

MEDIUM
Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-controlled domain
GHSA-cc9r-2j5m-2m83
pkg: nodemailer
eco: npm
published: Sep 8, 2026
### Summary

Nodemailer's email-address parser treats an **RFC 5322 comment** `( … )` inside the domain as a point to **concatenate** the surrounding text, rather than as folding whitespace (CFWS) that **terminates** the domain. Consequently a recipient address such as `user@good-corp.com(x)evil.c…

GitHub-GHSA

MEDIUM
Hono: Incomplete fix for CVE-2026-39408: `toSSG()` still writes files outside the output directory
GHSA-gqvv-2mrq-wpjv
pkg: hono
eco: npm
published: Sep 8, 2026
### Summary

The fix released for CVE-2026-39408 does not cover every traversal sequence. `toSSG()` can still write files outside the configured output directory when a route parameter contains consecutive parent-directory segments.

### Details

Static site generation builds each output path from t…

CVE-2026-84365
NVD

MEDIUM
CVE-2026-84685
CVE-2026-84685
pkg: react

published: Sep 8, 2026

The react-native-auth0 SDK's web platform implementation does not scope its in-memory token cache to individual user sessions when operating in a server-side rendering (SSR) environment where module state persists across HTTP requests. Under the listed preconditions, tokens cached in module memory c…
CWE: CWE-488
GitHub-GHSA

MEDIUM
vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections
GHSA-4hhp-h66f-j5j7
pkg: vllm
eco: pip
published: Sep 8, 2026
### Summary

`vllm/transformers_utils/processors/mimo_v2_omni.py` — the multimodal processor for `MiMoV2OmniForCausalLM` — issues `requests.get(…)` directly on user-supplied image and audio URL strings and `Image.open(…)` on user-supplied local paths, **without** the SSRF / `allowed_local_me…

CVE-2026-73560
GitHub-GHSA

MEDIUM
GitPython: TagReference.create positional reference bypasses kwargs-only –file guard, enabling arbitrary file read (incomplete fix of 3af0c251)
GHSA-3wxw-xv34-2frg
pkg: GitPython
eco: pip
published: Sep 8, 2026
## Summary
`TagReference.create()` forwards a caller-influenced positional `reference` value into `git tag` without it ever being inspected by the unsafe-option guard, allowing an arbitrary file read (the file's contents are returned in-band as the annotated tag message). This is an incomplete-fix b…
CVE-2026-78679
GitHub-GHSA

MEDIUM
GitPython: Incomplete unsafe_git_revision_options denylist omits –contents/-S, enabling arbitrary file read via Repo.blame()
GHSA-5xxx-qhh7-9287
pkg: GitPython
eco: pip
published: Sep 8, 2026
## Summary
`Repo.blame()` / `Repo.blame_incremental()` guard forwarded revision options against `unsafe_git_revision_options`, but that denylist only contains the file-WRITE options `–output`/`-o`. `git blame` also honors `–contents <file>` and `-S <file>`, which cause the file's lines to be echoe…
CVE-2026-78678
NVD

MEDIUM
CVE-2026-68898
CVE-2026-68898
pkg: windows

published: Sep 8, 2026

Out-of-bounds read in Windows iSCSI allows an unauthorized attacker to deny service over a network.
CWE: CWE-125
NVD

MEDIUM
CVE-2026-62801
CVE-2026-62801
pkg: windows

published: Sep 8, 2026

Improper limitation of a pathname to a restricted directory ('path traversal') in Windows PowerShell allows an unauthorized attacker to bypass a security feature over a network.
CWE: CWE-22
NVD

MEDIUM
CVE-2026-82076
CVE-2026-82076
pkg: node

published: Sep 8, 2026

An integer overflow in the query planning component of MongoDB Server can allow an authenticated user with ordinary database-level read/write privileges to bypass an internal resource limit. Submitting a specially crafted query causes the server to consume memory without bound during query planning,…
CWE: CWE-190
NVD

MEDIUM
CVE-2026-82068
CVE-2026-82068
pkg: node

published: Sep 8, 2026

A security issue in MongoDB Server allows an authenticated user with write privileges to trigger a persistent fatal assertion crash by sending specially crafted retryable write commands. The crash state is durably persisted, causing the server process to repeatedly crash on restart and potentially p…
CWE: CWE-617
NVD

MEDIUM
CVE-2026-82052
CVE-2026-82052
pkg: express

published: Sep 8, 2026

The $regexFindAll expression can be used by an authenticated user who can run aggregation pipeline stages to crash a MongoDB server (mongod). Under certain specific conditions the  regex match can start in the middle of a multi-code-unit character, triggering an assertion during query execution.
CWE: CWE-617
GitHub-GHSA

MEDIUM
NLTK: FileSystemPathPointer.open() sandbox check is dead code — arbitrary file read via file:// protocol
GHSA-72r2-7mfr-5xr9
pkg: nltk
eco: pip
published: Sep 8, 2026
### Summary

There's a logic bug in `FileSystemPathPointer.open()` inside `nltk/data.py`
that makes the sandbox check permanently inert. The guard condition is always
`False` — meaning any file the process can read is accessible by passing a
`file://` URL to `nltk.data.load()`.

### Details

CVE-2026-65915
NVD

MEDIUM
CVE-2026-86597
CVE-2026-86597
pkg: node

published: Sep 8, 2026

Insertion of sensitive information into log files in the Snowflake Python, Go, JDBC, Node.js, PHP PDO, and ODBC drivers allowed authentication tokens, query-result encryption keys, pre-signed cloud-storage URLs, and SAML assertions to be written to diagnostic logs in circumstances where the availabl…
CWE: CWE-532
NVD

MEDIUM
CVE-2026-86746
CVE-2026-86746
pkg: oauth

published: Sep 9, 2026

Snipe-IT before 8.7.0 contains an authorization bypass vulnerability in Livewire components that enforce authorization only at the route level, not within component lifecycle methods. Attackers with a valid authenticated session can replay signed component snapshots via POST /livewire/update to invo…
CWE: CWE-269
NVD

MEDIUM
CVE-2026-90581
CVE-2026-90581
pkg: nginx

published: Sep 13, 2026

A vulnerability was determined in cym1102 nginxWebUI up to 4.4.2. This issue affects the function MainController.autoUpdate of the file /adminPage/main/autoUpdate. This manipulation of the argument url causes code injection. Remote exploitation of the attack is possible. The exploit has been publicl…
CWE: CWE-74, CWE-94
NVD

MEDIUM
CVE-2026-90580
CVE-2026-90580
pkg: axios

published: Sep 13, 2026

A vulnerability was found in FlowiseAI Flowise up to 3.0.2. This vulnerability affects the function axios.post of the file packages/server/src/controllers/evaluations/index.ts of the component Evaluations Endpoint. The manipulation of the argument Host/X-Forwarded-Proto results in server-side reques…
CWE: CWE-918
GitHub-GHSA

MEDIUM
rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace
GHSA-66hp-wgxq-6f5q
pkg: github.com/rclone/rclone
eco: go
published: Sep 10, 2026
### Summary
`backend/archive` mounts a zip file as a browsable, syncable rclone `Fs` (e.g. `rclone lsf :zip:downloaded.zip` or `rclone copy :zip:downloaded.zip dest:`). Go's `archive/zip` package does not sanitize `file.Name` – it is taken verbatim from the untrusted zip's central directory. `readZi…
CVE-2026-88014
GitHub-GHSA

MEDIUM
weasyprint Has Server-Side Request Forgery (SSRF)
GHSA-jf6q-chmf-3h3v
pkg: weasyprint
eco: pip
published: Sep 9, 2026
## Summary

`url_fetcher` is WeasyPrint's documented mechanism for restricting resource loading – applications use it to block `file://`, internal hosts, etc. when rendering untrusted input.

Two `write_pdf()` channels ignore the document's `url_fetcher` and build a fresh default `URLFetcher()` inst…

CVE-2026-55073
NVD

MEDIUM
CVE-2026-89247
CVE-2026-89247
pkg: node

published: Sep 11, 2026

WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier contains an XML injection vulnerability in plugin/AD_Server/VMAP.php, which is reachable without authentication when the AD_Server plugin is enabled. The script emits Content-Type: application/xml and writes the timeOffset an…
CWE: CWE-91
GitHub-GHSA

MEDIUM
SVGO: removeScripts incompletely sanitizes executable HTML in SVG foreignObject elements
GHSA-4vpr-x523-8j87
pkg: svgo, svgo, svgo
eco: npm
published: Sep 8, 2026
## Summary

SVGO's opt-in `removeScripts` plugin did not inspect executable HTML content inside SVG `<foreignObject>` elements. Applications that used this plugin as their only protection for untrusted SVG input could produce SVGs containing active HTML and expose users to cross-site scripting (XSS)…

CVE-2026-84369
GitHub-GHSA

MEDIUM
SWC HTML minifier may allow script element breakout when minifying embedded JSON
GHSA-5qr2-v392-m9g8
pkg: @swc/html, swc_html_minifier
eco: npm
published: Sep 8, 2026
## Impact

`@swc/html` minifies JSON contained in `script` elements such as
`application/json` and `application/ld+json` by parsing and serializing the
JSON value.

Before the patched versions, JSON serialization could convert escaped
less-than signs such as `\u003C` into literal `<` characters. If …

CVE-2026-72925
NVD

MEDIUM
CVE-2022-51016
CVE-2022-51016
pkg: jwt

published: Sep 7, 2026

PocketMine-MP 3.x (before 3.27.0) does not implement Minecraft Bedrock protocol encryption, so the server cannot verify that a connecting client possesses the private key corresponding to its login token. An attacker who captures a valid login from another player's session (for example by tricking t…
CWE: CWE-294
NVD

MEDIUM
CVE-2026-78552
CVE-2026-78552
pkg: nginx

published: Sep 8, 2026

The Okta Access Gateway does not apply its Lua directive restriction to the application-level custom configuration field. The field is interpolated directly into the nginx server block without inspection, resulting in execution of injected directives.
CWE: CWE-693
NVD

MEDIUM
CVE-2026-87123
CVE-2026-87123
pkg: express

published: Sep 11, 2026

hbs is an Express view engine wrapper for Handlebars. Version 4.3.0 can crash the Node.js process during output escaping when an async helper, registered with registerAsyncHelper, resolves to an object whose toHTML property is truthy but not callable. Handlebars escapeExpression calls the toHTML met…
CWE: CWE-248
NVD

MEDIUM
CVE-2026-78123
CVE-2026-78123
pkg: openssl

published: Sep 11, 2026

strongSwan 5.0.2 through 6.0.7 has an Expired Pointer Dereference in PKCS#7 parsing in the openssl plugin.
CWE: CWE-825
NVD

MEDIUM
CVE-2026-88032
CVE-2026-88032
pkg: react

published: Sep 10, 2026

A use-after-free in the reactive client-side encryption component of the MongoDB Java Driver can cause native resources to be freed while an affected encrypted operation is still using them when the operation is cancelled. A party able to cause such an operation to be cancelled may cause the hosting…
CWE: CWE-416
GitHub-GHSA

MEDIUM
Microsoft Security Advisory CVE-2026-69304 – ASP.NET Core Denial of Service Vulnerability
GHSA-8cp2-47hg-mfgh
pkg: Microsoft.AspNetCore.Server.IISIntegration, Microsoft.AspNetCore.Server.IISIntegration, Microsoft.AspNetCore.Server.IISIntegration
eco: nuget
published: Sep 9, 2026
# Microsoft Security Advisory CVE-2026-69304 – ASP.NET Core Denial of Service Vulnerability

## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core IIS out-of-process hosting and request decompression. This advisory also pro…

CVE-2026-69304
GitHub-GHSA

MEDIUM
Hono: Query parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentials
GHSA-crvj-82cr-hjcx
pkg: hono
eco: npm
published: Sep 8, 2026
### Summary

Hono's query parsing does not stop at the URL fragment: a `?` appearing after a `#` is treated as the start of a query string. As a result, the application can read request parameters that no other component involved in handling the request can see.

### Details

A fragment is never par…

CVE-2026-84363
GitHub-GHSA

MEDIUM
Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the legacy signature
GHSA-8m3c-c648-2xjj
pkg: nodemailer
eco: npm
published: Sep 8, 2026
### Summary

Nodemailer's `disableFileAccess` / `disableUrlAccess` options are a security sandbox that lets an application forbid untrusted message content (`html`/`text`/attachment `path`/`href`) from reading local files or making outbound HTTP(S) requests. The fix for GHSA-wqvq-jvpq-h66f (commit `…

GitHub-GHSA

MEDIUM
Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock
GHSA-82fw-gwwq-j7x9
pkg: @vitest/mocker, vitest, vitest
eco: npm
published: Sep 8, 2026
## Summary
`@vitest/mocker` registers a redirect mock's target path without validating it
against the dev server's file-serving allowlist. An attacker who can reach the
dev server's WebSocket can register a redirect mock pointing outside the project
root; when the mocked module is requested, the plu…
CVE-2026-84373
GitHub-GHSA

MEDIUM
HTTPX2: Quadratic SSE line buffering can cause CPU denial of service
GHSA-f2fp-rgf2-35cp
pkg: httpx2
eco: pip
published: Sep 8, 2026
### Summary

HTTPX2's Server-Sent Events (SSE) parser repeatedly copied and rescanned buffered text when a server split one unterminated line across many response chunks. The total work grows quadratically with the length of the line. An attacker-controlled or compromised SSE endpoint can exploit th…

CVE-2026-84378
GitHub-GHSA

MEDIUM
Microsoft Security Advisory CVE-2026-62900 – .NET Information Disclosure Vulnerability
GHSA-23fw-v26w-5fgq
pkg: Microsoft.Build.Tasks.Git, Microsoft.Build.Tasks.Git, Microsoft.Build.Tasks.Git
eco: nuget
published: Sep 8, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in Microsoft.Build.Tasks.Git and Microsoft.SourceLink.AzureRepos.Git. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerabil…

CVE-2026-62900
GitHub-GHSA

MEDIUM
Duplicate Advisory: Microsoft Security Advisory CVE-2026-69304 – ASP.NET Core Denial of Service Vulnerability
GHSA-v3f6-m9j2-437p
pkg: Microsoft.AspNetCore.Server.IISIntegration, Microsoft.AspNetCore.Server.IISIntegration, Microsoft.AspNetCore.Server.IISIntegration
eco: nuget
published: Sep 8, 2026
### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-8cp2-47hg-mfgh. This link is maintained to preserve external references.

### Original Description
Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacke…

NVD

MEDIUM
CVE-2026-73310
CVE-2026-73310
pkg: xenforo xenforo

published: Sep 8, 2026

XenForo before 2.3.13 contains an authorization flaw in the OAuth2 token endpoint that allows attackers controlling any allowlisted redirect URI to bypass redirect URI binding by submitting a different allowlisted URI than the one recorded at authorization time. Attackers can exchange an intercepted…
CWE: CWE-863
NVD

MEDIUM
CVE-2026-86506
CVE-2026-86506
pkg: go

published: Sep 7, 2026

In JetBrains GoLand before 2026.2.2.1 missing authentication on the GoLand profiler's injected pprof server exposed profiling data
CWE: CWE-306
NVD

MEDIUM
CVE-2026-88884
CVE-2026-88884
pkg: docker

published: Sep 10, 2026

Renovate is a dependency update automation tool. In versions before 44.3.1 (and Mend Renovate CE/EE images before 15.4.0, mend-renovate-ce Helm chart before 15.4.0, mend-renovate-enterprise-edition Helm chart before 10.4.0), digest updates are not subject to the internal `minimumReleaseAge` (stabili…
CWE: CWE-863
GitHub-GHSA

MEDIUM
SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo
GHSA-74pj-6g7r-j55c
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: Sep 8, 2026
**CVE:** This vulnerability corresponds to [CVE-2026-72790](https://nvd.nist.gov/vuln/detail/CVE-2026-72790).

### Relationship to GHSA-8×84-r2ff-h8pq (please read first)

`getNotebookInfo` is named in the earlier advisory GHSA-8×84-r2ff-h8pq, in its remediation section, which asked for reader filte…

CVE-2026-72790
GitHub-GHSA

MEDIUM
SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAttributeViewFieldViews
GHSA-57v5-wqx3-cgj4
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: Sep 8, 2026
### Scope note (please read first)

This endpoint does not exist in v3.7.3 or on master. It was introduced on the development branch by commit `acfc02ee8` ("Improve database field visibility across views", #11020) and is live on `v3.7.4-alpha.1`, so it will ship in v3.7.4 unless gated first. No rele…

NVD

MEDIUM
CVE-2026-68874
CVE-2026-68874
pkg: windows

published: Sep 8, 2026

Out-of-bounds read in Windows Program Compatibility Assistant Service allows an authorized attacker to disclose information over a network.
CWE: CWE-125
GitHub-GHSA

MEDIUM
HTTPX2: Conflicting Content-Length and Transfer-Encoding headers can be auto-generated
GHSA-pf96-p4fj-6566
pkg: httpx2
eco: pip
published: Sep 8, 2026
### Summary

HTTPX2 can automatically add a `Content-Length` header to a request that already contains a caller-supplied `Transfer-Encoding` header. The resulting HTTP/1.1 request contains both framing headers, which can create an ambiguous message boundary and enable request smuggling or connection…

CVE-2026-84380
NVD

MEDIUM
CVE-2026-88055
CVE-2026-88055
pkg: jwt

published: Sep 10, 2026

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.16.1 and earlier, the manager role can store meta_page_title or meta_page_favicon through /api/admin/system-preferences, and MetaGenerator inserts those values into produc…
CWE: CWE-79
GitHub-GHSA

MEDIUM
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
GHSA-c23q-fw86-9h5x
pkg: github.com/lf-edge/ekuiper/v2
eco: go
published: Sep 9, 2026
### Summary
A path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system.

### Details
In `internal/plugin/native/manager.go`, the plugin installation en…

CVE-2025-58363
GitHub-GHSA

MEDIUM
LF Edge eKuiper: SSRF in External Service
GHSA-pqqc-8v73-9gg2
pkg: github.com/lf-edge/ekuiper/v2
eco: go
published: Sep 9, 2026
### Summary
Server-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or clou…
CVE-2025-24979
NVD

MEDIUM
CVE-2026-68886
CVE-2026-68886
pkg: windows

published: Sep 8, 2026

Use after free in Windows Network Connection Broker allows an authorized attacker to disclose information locally.
CWE: CWE-209, CWE-416
NVD

MEDIUM
CVE-2026-68873
CVE-2026-68873
pkg: windows

published: Sep 8, 2026

Insertion of sensitive information into log file in Windows Program Compatibility Assistant Service allows an authorized attacker to disclose information locally.
CWE: CWE-532, CWE-908
NVD

MEDIUM
CVE-2026-68851
CVE-2026-68851
pkg: windows

published: Sep 8, 2026

Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.
CWE: CWE-126
NVD

MEDIUM
CVE-2026-68842
CVE-2026-68842
pkg: windows

published: Sep 8, 2026

Exposure of sensitive system information to an unauthorized control sphere in Windows MIDI Service Module allows an authorized attacker to disclose information locally.
CWE: CWE-497
NVD

MEDIUM
CVE-2026-68831
CVE-2026-68831
pkg: windows

published: Sep 8, 2026

Files or directories accessible to external parties in Windows Defender Firewall Service allows an authorized attacker to disclose information locally.
CWE: CWE-552
NVD

MEDIUM
CVE-2026-68830
CVE-2026-68830
pkg: windows

published: Sep 8, 2026

Improper link resolution before file access ('link following') in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclose information locally.
CWE: CWE-59, CWE-269
GitHub-GHSA

MEDIUM
NLTK: Symlink-based arbitrary file read in IPIPANCorpusReader, bypasses nltk.pathsec entirely
GHSA-3hhw-38pf-pxj6
pkg: nltk
eco: pip
published: Sep 8, 2026
## Summary

`IPIPANCorpusReader` (`nltk/corpus/reader/ipipan.py`) exposes public methods, `channels()`, `domains()`, `categories()`, and `fileids(channels=…)`, that accept a caller supplied `fileids` list and read a file via a completely unprotected builtin `open()` call, with no `nltk.pathsec` in…

CVE-2026-62383
NVD

MEDIUM
CVE-2026-87107
CVE-2026-87107
pkg: node

published: Sep 10, 2026

Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog deregistration path that may allow a local ACL token to delete peer-imported catalog objects. A caller with {{service:write}} or {{node:write}} permission may exploit this issue to remove services, checks, or nodes…
CWE: CWE-863
NVD

MEDIUM
CVE-2026-87462
CVE-2026-87462
pkg: google chrome

published: Sep 9, 2026

UI misrepresentation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-451
NVD

MEDIUM
CVE-2026-87458
CVE-2026-87458
pkg: google chrome

published: Sep 9, 2026

UI misrepresentation in Geometry in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-451
NVD

MEDIUM
CVE-2026-87445
CVE-2026-87445
pkg: google chrome

published: Sep 9, 2026

UI misrepresentation in Session in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-451
NVD

MEDIUM
CVE-2026-86996
CVE-2026-86996
pkg: n8n n8n

published: Sep 8, 2026

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the workflow setting named This workflow can be called by was enforced by the Execute Workflow node but not when a workflow was attached to an Agent as a tool. A user able to build an Agent could invoke a restricted work…
CWE: CWE-862
GitHub-GHSA

MEDIUM
Prowler: Stored XSS in HTML reports through unescaped cloud resource tags
GHSA-c2jg-2778-ggm4
pkg: prowler, prowler-cloud
eco: pip
published: Sep 8, 2026
## Summary

Prowler's HTML output formatter inserts `finding.resource_tags` into the generated report without HTML escaping. A cloud principal who can create or edit a resource tag in an account that is later scanned can store HTML or JavaScript in that tag. When another user opens the generated Pro…

CVE-2026-73262
NVD

MEDIUM
CVE-2026-88932
CVE-2026-88932
pkg: node

published: Sep 14, 2026

multer is a Node.js middleware for handling multipart/form-data uploads. In versions 2.2.0 through 2.3.0, when a request using disk storage is aborted mid-upload, file writes that complete after multer has already run its abort cleanup are not removed, so each aborted upload can leave an orphaned fi…
CWE: CWE-400, CWE-459
NVD

MEDIUM
CVE-2026-90494
CVE-2026-90494
pkg: node

published: Sep 13, 2026

A flaw has been found in restify node-restify up to 12.0.0. This affects the function serveStatic in the library /lib/plugins/static.js. This manipulation causes path traversal. The attack can be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way.
CWE: CWE-22
NVD

MEDIUM
CVE-2026-87859
CVE-2026-87859
pkg: node

published: Sep 11, 2026

morgan is an HTTP request logger middleware for Node.js. In versions before 1.12.1, its escapeLogField() function does not escape the double quote character, which delimits the quoted fields of the Apache combined log format that morgan emits. An unauthenticated remote attacker who controls a value …
CWE: CWE-117
NVD

MEDIUM
CVE-2026-86781
CVE-2026-86781
pkg: ssl

published: Sep 11, 2026

The SSL Zen — SSL Certificate Installer & HTTPS Redirects WordPress plugin before 4.7.40 does not perform capability or nonce checks on a certificate-file download routine that runs early in the WordPress admin request lifecycle, allowing any authenticated user, including Subscribers, to download …
CWE: CWE-287
GitHub-GHSA

MEDIUM
rclone local: crafted Range request against a translated symlink panics (DoS)
GHSA-p6m2-r3w9-mpxw
pkg: github.com/rclone/rclone
eco: go
published: Sep 10, 2026
### Summary
When `backend/local` is used with `–links`/`-l` (or the `links=true` config option), each symlink is exposed as an rclone object whose content is the target path string, suffixed `.rclonelink`. `Object.Open()` decodes an incoming `fs.RangeOption` via `Decode(o.Size())`, then for a trans…
CVE-2026-88015
GitHub-GHSA

MEDIUM
rclone: source object names can escape the configured root on upload
GHSA-38xv-hf3p-h7mq
pkg: github.com/rclone/rclone
eco: go
published: Sep 10, 2026
### Summary

Multiple backends, when given a specially crafted object to copy, can escape the backend confinement.

| Backend | Keep/Close | Per-backend severity |
|—|—|—|
| sftp | Medium | Real filesystem escape, fires under default encoding. |
| smb | Low-Medium | Escapes to a different SMB …

CVE-2026-88046
GitHub-GHSA

MEDIUM
Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded
GHSA-7ghq-v6jf-g56c
pkg: github.com/traefik/traefik/v2, github.com/traefik/traefik/v3
eco: go
published: Sep 10, 2026
## Summary

There is a medium severity vulnerability in Traefik's HTTP/3 entry points: the `respondingTimeouts` settings were not applied to the HTTP/3 request path. `readTimeout` in particular is on by default at 60s and is documented as bounding the time to read the entire request including its bo…

CVE-2026-88012
NVD

MEDIUM
CVE-2026-88896
CVE-2026-88896
pkg: curl

published: Sep 10, 2026

EspoCRM before 10.0.4 is vulnerable to server-side request forgery. HostCheck::ipAddressIsNotInternal(), which validates outbound URLs to block requests to internal/private IP addresses, strips ::ffff: (IPv4-mapped IPv6) prefixes but does not recognize IPv6 transition addresses that embed private IP…
CWE: CWE-918
GitHub-GHSA

MEDIUM
SQLAdmin: Unvalidated sortBy parameter in `ModelView` bypasses `column_sortable_list`
GHSA-ccg5-9c8w-xh6v
pkg: sqladmin
eco: pip
published: Sep 9, 2026
## Summary

`ModelView.sort_query()` uses the attacker-controlled `sortBy` list-view query parameter without checking it against the configured `column_sortable_list` allow-list. The value is resolved with `getattr(model, …)` and fed into relationship joins and `order_by()`, so a request can sort …

CVE-2026-54529
GitHub-GHSA

MEDIUM
GitHacker: Path traversal in ref/hash parsing enables existence oracle and hex-fragment exfiltration via malicious .git server
GHSA-hr3m-4qwq-3mgc
pkg: githacker
eco: pip
published: Sep 9, 2026
## Summary

GitHacker through 1.1.7 did not validate path segments parsed from attacker-controlled `.git/HEAD` before joining them onto its output directory. A malicious server could coerce GitHacker into reading arbitrary local files. Contents do not stream back wholesale, but the recovery loop tur…

CVE-2026-50024
NVD

MEDIUM
CVE-2026-86200
CVE-2026-86200
pkg: jwt

published: Sep 9, 2026

PocketMine-MP versions before 5.42.1 contain a denial of service vulnerability in the LoginPacket handler that allows remote attackers to flood warning messages by injecting numerous junk properties into the clientData JWT. Attackers can craft malicious login packets with excessive unknown propertie…
CWE: CWE-779
NVD

MEDIUM
CVE-2025-71418
CVE-2025-71418
pkg: jwt

published: Sep 9, 2026

PocketMine-MP versions before 5.25.2 fail to limit the explode() function in packet parsing, allowing malicious clients to waste server resources. Attackers can send crafted packets with excessive delimiters to consume CPU and memory through sign editing, JWT parsing, and command parsing endpoints.
CWE: CWE-400
NVD

MEDIUM
CVE-2026-86777
CVE-2026-86777
pkg: node

published: Sep 9, 2026

AlchemyCMS versions before 7.4.16 and 8.x before 8.3.6 fail to authorize access to the GET /api/nodes endpoint, allowing unauthenticated attackers to retrieve all navigation nodes. Attackers can access the endpoint without authentication to disclose restricted page names, URL paths, and internal URL…
CWE: CWE-862
NVD

MEDIUM
CVE-2026-83537
CVE-2026-83537
pkg: express

published: Sep 9, 2026

The WP Express Checkout WordPress plugin before 2.5.0 does not verify server-side that a payment was actually completed before marking an order as paid, allowing unauthenticated users to forge a completed order without paying.
CWE: CWE-345
NVD

MEDIUM
CVE-2026-87453
CVE-2026-87453
pkg: google chrome

published: Sep 9, 2026

Confused deputy in BackgroundFetch in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-441
NVD

MEDIUM
CVE-2026-87439
CVE-2026-87439
pkg: google chrome

published: Sep 9, 2026

Information leak in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-200
NVD

MEDIUM
CVE-2026-87435
CVE-2026-87435
pkg: google chrome

published: Sep 9, 2026

Information leak in ControlledFrame in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-200
NVD

MEDIUM
CVE-2026-86080
CVE-2026-86080
pkg: n8n n8n

published: Sep 8, 2026

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the GitHub Trigger generated a webhook secret but discarded it when GitHub returned HTTP 422 and the node reused an existing webhook. Workflow static data then retained webhookId without webhookSecret, and X-H…
CWE: CWE-347
GitHub-GHSA

MEDIUM
morgan vulnerable to Log Forging via unescaped Unicode line separators
GHSA-jxfw-x594-9x9m
pkg: morgan
eco: npm
published: Sep 8, 2026
### Impact

Morgan writes attacker-controlled request data to the access log through its tokens. The 1.11.0 fix neutralizes C0 control characters, DEL, and backslash, but it does not escape the Unicode line separators `U+0085` (NEL), `U+2028` (LINE SEPARATOR), or `U+2029` (PARAGRAPH SEPARATOR). Thes…

CVE-2026-15603
GitHub-GHSA

MEDIUM
Hono: Unbounded dot-notation nesting in `parseBody()` can cause memory exhaustion
GHSA-g6gw-c38x-mqfc
pkg: hono
eco: npm
published: Sep 8, 2026
### Summary

When `parseBody()` expands dot-separated form field names into nested objects, it does not limit the nesting depth or the total number of objects created. A request body well within a normal size limit can therefore allocate an object graph far larger than the request itself, and concur…

CVE-2026-84364
GitHub-GHSA

MEDIUM
HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headers
GHSA-h4x7-gw46-3wm6
pkg: httpx2
eco: pip
published: Sep 8, 2026
### Summary

HTTPX2 serializes the per-file `Content-Type` and custom headers supplied through the `files=` tuple API directly into the `multipart/form-data` body without validating custom header names or values. An attacker who can influence upload metadata passed to HTTPX2 can use CR or LF charact…

CVE-2026-84379
GitHub-GHSA

MEDIUM
vLLM: Cross-User Data Leak Vulnerability
GHSA-7m6h-x95x-82q5
pkg: vllm
eco: pip
published: Sep 8, 2026
### Summary
An integer overflow in the act_and_mul_kernel kernel can cause the output of one user request to be incorporated into the response of another request within the same inference batch. Under certain conditions, the last request in a batch can receive a partial or complete copy of the first…
CVE-2026-73558
NVD

MEDIUM
CVE-2026-82059
CVE-2026-82059
pkg: express

published: Sep 8, 2026

An internal aggregation expression in MongoDB Server was incorrectly registered as accessible to any authenticated user rather than being restricted to internal cluster operations. By crafting a malformed index specification within this expression, an authenticated user with read-only privileges cou…
CWE: CWE-617
GitHub-GHSA

MEDIUM
NLTK: Missing Post-Download Integrity Verification Allows Malicious Package Injection
GHSA-5wp5-5229-5g6q
pkg: nltk
eco: pip
published: Sep 8, 2026
NLTK's package downloader in nltk/downloader.py does not verify file integrity after download and before extraction.

The download flow at lines 789-825:
1. File is downloaded to a temp path via HTTP
2. os.replace(tmp_filepath, filepath) moves it to the final location (line 799)
3. Extraction begins…

CVE-2026-12259
GitHub-GHSA

MEDIUM
Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets
GHSA-5x7x-4c3c-qf5w
pkg: open-webui
eco: pip
published: Sep 9, 2026
## Summary

Open WebUI protects server-side web fetches with two controls: the operator's list of excluded hosts, and a check that refuses private and internal addresses. Neither control was applied to the destination of an HTTP redirect. On a deployment where redirect following is enabled, any auth…

CVE-2026-88001
GitHub-GHSA

MEDIUM
ZITADEL: Auto-linking by email: IdP-side email verification is not checked
GHSA-992q-9gwp-7r79
pkg: github.com/zitadel/zitadel
eco: go
published: Sep 11, 2026
### Summary

A flaw in the external identity provider handler allows unauthorized account linking to occur under specific administrative configurations. When auto-linking by email is enabled, ZITADEL checks that the local user's email is verified, but does not explicitly cross-check whether the inco…

CVE-2026-56666
NVD

MEDIUM
CVE-2026-88038
CVE-2026-88038
pkg: node

published: Sep 10, 2026

cookies is a Node.js library for reading and writing HTTP cookies, used by Koa via ctx.cookies. In versions before 0.9.2 the library validates the cookie name and value against character sets that reject the semicolon separator, but the domain and path options are checked only against a permissive R…
CWE: CWE-74
GitHub-GHSA

MEDIUM
decidim-elections: Election question titles allow stored script execution
GHSA-9mvp-w4rr-5c6x
pkg: decidim-elections
eco: rubygems
published: Sep 9, 2026
## Description

A low-privilege process-scoped admin who can manage elections can store arbitrary HTML in the question statement/body without sanitization, and the public elections UI renders that value unsafely.

## Technical description

This stored XSS appears because election question titles ar…

CVE-2026-44282
NVD

MEDIUM
CVE-2026-87463
CVE-2026-87463
pkg: google chrome, google android

published: Sep 9, 2026

Incorrect authorization in Certificate in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to potentially spoof address bar via crafted network traffic. (Chromium security severity: Low)
CWE: CWE-863
NVD

MEDIUM
CVE-2026-68849
CVE-2026-68849
pkg: windows

published: Sep 8, 2026

Out-of-bounds read in Windows Bluetooth Port Driver allows an authorized attacker to disclose information locally.
CWE: CWE-125
GitHub-GHSA

MEDIUM
Open WebUI: Any authenticated user can suppress calendar alerts instance-wide via a non-numeric alert value
GHSA-v39v-59xw-j98g
pkg: open-webui
eco: pip
published: Sep 10, 2026
# Any authenticated user can suppress calendar alerts instance-wide via a non-numeric alert value

## Summary

Calendar events carry a free-form `meta` object that is stored exactly as submitted, with no validation of the values inside it. The scheduler reads the per-event alert offset out of that o…

CVE-2026-87012
GitHub-GHSA

MEDIUM
Open WebUI: Any authenticated user can start a non-terminating request via a folder parent cycle
GHSA-8r35-5x5r-hv74
pkg: open-webui
eco: pip
published: Sep 10, 2026
## Summary
Any authenticated user can move one of their own folders under itself, leaving a loop in their folder tree. The re-parent endpoint performed no check that the new parent was not the folder itself or one of its own subfolders, and the folder tree walks did not track which folders they had …
CVE-2026-87013
GitHub-GHSA

MEDIUM
Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends
GHSA-pcvc-8vrv-8q6w
pkg: open-webui
eco: pip
published: Sep 10, 2026
## Summary
The built-in knowledge search tool returns knowledge bases the calling user has no access to. The tool works out which knowledge bases the caller may read and hands that set to the vector store as a search filter, and that filter is the only access control on the path. Most of the shipped…
CVE-2026-87017
GitHub-GHSA

MEDIUM
Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint
GHSA-fmqh-xp37-5hr8
pkg: open-webui
eco: pip
published: Sep 10, 2026
## Summary
Any member of a channel who can post to it could also replace the text of a message written by a different member. The channel branch of the chat completions endpoint checked that the caller may write to the channel, and that the targeted message belongs to that channel, but never checked…
CVE-2026-87994
GitHub-GHSA

MEDIUM
Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions
GHSA-3pf7-q2g3-wj28
pkg: open-webui
eco: pip
published: Sep 10, 2026
## Summary
The chat-completions endpoint reads a folder id out of the request body and saves the newly created chat into that folder without checking that the caller is allowed to write there. Any authenticated user who knows a folder's id can put a chat of their own into another user's folder, incl…
CVE-2026-87997
NVD

MEDIUM
CVE-2026-87466
CVE-2026-87466
pkg: google chrome

published: Sep 9, 2026

Incorrect authorization in Workers in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-863
NVD

MEDIUM
CVE-2026-87461
CVE-2026-87461
pkg: google chrome

published: Sep 9, 2026

Information leak in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-origin data via a crafted Chrome extension. (Chromium security severity: Low)
CWE: CWE-200
NVD

MEDIUM
CVE-2026-87449
CVE-2026-87449
pkg: google chrome

published: Sep 9, 2026

Cross-site request forgery in DeviceBoundSessionCredentials in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-352
NVD

MEDIUM
CVE-2026-86995
CVE-2026-86995
pkg: n8n n8n

published: Sep 8, 2026

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Git node validated the repository parameter for fetch or pull, but setUpstream wrote a branch..remote value into repository configuration without validating it. A later fetch or pull resolved the remote fr…
CWE: CWE-22, CWE-73
GitHub-GHSA

MEDIUM
ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider
GHSA-v77h-2w3m-94hx
pkg: github.com/zitadel/zitadel, github.com/zitadel/zitadel
eco: go
published: Sep 11, 2026
### Summary

A token lifecycle validation vulnerability was discovered in ZITADEL's external JWT Identity Provider (IdP) implementation
Specifically, within the validation pipeline, if an incoming JWT omits the `exp` claim entirely, the expiration block is silently skipped rather than rejected. The …

CVE-2026-56665
NVD

MEDIUM
CVE-2026-87472
CVE-2026-87472
pkg: google chrome

published: Sep 9, 2026

Improper input validation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-20
NVD

MEDIUM
CVE-2026-87465
CVE-2026-87465
pkg: google chrome

published: Sep 9, 2026

Incorrect authorization in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-863
NVD

MEDIUM
CVE-2026-87432
CVE-2026-87432
pkg: google chrome

published: Sep 9, 2026

Incorrect authorization in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-863
GitHub-GHSA

MEDIUM
Angular: Information Leak via `HttpTransferCache` Bypass When Using `withRequestsMadeViaParent`
GHSA-p297-fm68-3q8c
pkg: @angular/common, @angular/common, @angular/common
eco: npm
published: Sep 10, 2026
A security bypass vulnerability was discovered in `@angular/common` when Server-Side Rendering (SSR) and hydration are enabled in applications using a hierarchical `HttpClient` configuration with `withRequestsMadeViaParent()`.

The `HttpTransferCache` utility optimizes hydration by caching outgoing …

CVE-2026-88059
GitHub-GHSA

MEDIUM
Central Dogma: LDAP injection in SearchFirstActiveDirectoryRealm enables authentication confusion and audit log evasion
GHSA-98q5-5qh2-7w75
pkg: com.linecorp.centraldogma:centraldogma-server-auth-shiro
eco: maven
published: Sep 11, 2026
# Vulnerability

`SearchFirstActiveDirectoryRealm.findUserDn()` substitutes the user-supplied username from the login form into an LDAP search filter template (default `cn={0}`) **without escaping RFC 4515 filter metacharacters** (`*`, `(`, `)`, `\`, NUL). Combined with `SearchControls.setCountLimit…

CVE-2026-11748
GitHub-GHSA

MEDIUM
n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution
GHSA-cw9w-vv67-hf73
pkg: n8n, n8n
eco: npm
published: Sep 10, 2026
## Impact

The OAuth token endpoint bound an authorization code's first access token to the consented resource, but not its refresh token. Refreshing only checked that the requested resource was registered, not that it matched the original grant. An OAuth client approved for one workflow could refre…

CVE-2026-86073
GitHub-GHSA

MEDIUM
n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content
GHSA-q5wm-mgqx-fv2f
pkg: n8n, n8n
eco: npm
published: Sep 10, 2026
## Impact

Instance AI credential setup accepted a credential test/verification URL without checking it matched the workflow node's origin. Exfiltration required the user to actively inject an attacker-controlled URL into the setup flow. The patch derives the credential destination from the node's o…

CVE-2026-86074
GitHub-GHSA

MEDIUM
n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Read
GHSA-qgpw-8g46-w95v
pkg: n8n, n8n, n8n
eco: npm
published: Sep 10, 2026
## Impact

The Git node validated the repository that a fetch or pull targeted, but `setUpstream` wrote a `branch.<name>.remote` value into the repository's own configuration without validating it. A subsequent fetch or pull resolved the remote from that configuration rather than from the checked pa…

CVE-2026-86995
GitHub-GHSA

MEDIUM
n8n: Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Role Assignment Endpoints
GHSA-cqr2-h44g-v75v
pkg: n8n, n8n
eco: npm
published: Sep 10, 2026
## Impact

The endpoints `/rest/roles/:slug/assignments` and `/rest/roles/:slug/assignments/:projectId/members` checked only that the caller could manage the role type, not that they could see the project named in the request. A user holding role-management permission could therefore name any projec…

CVE-2026-86085
GitHub-GHSA

MEDIUM
n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check
GHSA-pq6c-vh67-xpm3
pkg: n8n, n8n, n8n
eco: npm
published: Sep 10, 2026
## Impact

A log streaming event destination may reference a generic HTTP credential, and the destination resolved and decrypted whichever credential it named without checking that the caller had access to it. A user holding a custom global role scoped to Log Streaming operations could therefore nam…

CVE-2026-86993
GitHub-GHSA

MEDIUM
n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions
GHSA-pf83-w3f9-8m37
pkg: n8n, n8n, n8n
eco: npm
published: Sep 10, 2026
## Impact

The public OIDC login and callback endpoints ran the full flow whether or not OIDC was the instance's active, enabled authentication method, so turning OIDC off in Settings did not stop it issuing sessions. An administrator who disabled the provider still had a working login route. The pa…

CVE-2026-86084
GitHub-GHSA

MEDIUM
n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open
GHSA-5m98-cgcr-xx3q
pkg: n8n, n8n, n8n
eco: npm
published: Sep 10, 2026
## Impact

The GitHub Trigger generated a signing secret when it registered a webhook and verified `X-Hub-Signature-256` on each delivery. When GitHub answered the create request with a 422 because a webhook for the URL already existed, the node adopted the remote hook but kept only its id and event…

CVE-2026-86080
GitHub-GHSA

MEDIUM
n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiers
GHSA-f2cp-m7mv-8jpv
pkg: n8n, n8n, n8n
eco: npm
published: Sep 10, 2026
## Impact

The Elasticsearch and ElasticSecurity nodes built REST endpoints by interpolating user-provided identifiers straight into the request path. A value containing path separators or dot segments changed which endpoint the request actually reached, so an operation intended for one document cou…

CVE-2026-86079
GitHub-GHSA

MEDIUM
n8n: Prototype Pollution via Workflow Structure Summary Can Lead to Denial of Service
GHSA-679f-58pq-4v2c
pkg: n8n, n8n
eco: npm
published: Sep 10, 2026
## Impact

The Instance AI workflow summary built its result with get-or-create-then-nested-write idioms keyed by node names and connection keys taken from the stored workflow. Those are arbitrary strings: the restricted-name guard n8n shows in the editor is client-side and is bypassed by posting th…

CVE-2026-86078
GitHub-GHSA

MEDIUM
n8n: Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId Filter
GHSA-65xw-2v52-jhxc
pkg: n8n, n8n, n8n
eco: npm
published: Sep 10, 2026
## Impact

The endpoint `/rest/active-workflows` returned every active workflow ID on the instance to any member, regardless of sharing, and workflow activation, deactivation and publication push events were broadcast to every connected client, carrying workflow IDs, version IDs and activation-error…

CVE-2026-86994
GitHub-GHSA

MEDIUM
n8n: Anonymous Approval-Gate Bypass via Reused resumeToken over the Chat WebSocket
GHSA-35jj-42hp-8gmq
pkg: n8n, n8n
eco: npm
published: Sep 10, 2026
## Impact

The `/chat` WebSocket route resumed a paused execution from a resume token without checking that the node being resumed was a chat node. n8n hands that token to anonymous form submitters, so a party with no account could present it on the chat route and release an execution waiting at an …

CVE-2026-86077
GitHub-GHSA

MEDIUM
Traefik: ForwardAuth identity spoofing via dot-form header alias
GHSA-rf44-j88r-hh8c
pkg: github.com/traefik/traefik/v2, github.com/traefik/traefik/v3
eco: go
published: Sep 10, 2026
## Summary

There is a medium severity vulnerability in Traefik's handling of request headers whose name aliases another header name. Go canonicalizes header names on dashes only, so `X-Auth-User`, `X_Auth_User` and `X.Auth.User` are three distinct headers to Traefik, while backends that derive vari…

CVE-2026-88011
GitHub-GHSA

MEDIUM
Angular: Sanitization bypass via directive host bindings on concrete host elements in @angular/core and @angular/compiler
GHSA-hh8m-fm6v-7cvg
pkg: @angular/core, @angular/compiler, @angular/core
eco: npm
published: Sep 10, 2026
Angular automatically sanitizes untrusted values bound to security-sensitive DOM sinks (such as `href`, `src`, `action`, `xlink:href`, and `data`) to protect against Cross-Site Scripting (XSS).

Prior to the fix, the Angular compiler determined the `SecurityContext` for directive host bindings (`hos…

CVE-2026-88057
GitHub-GHSA

MEDIUM
Excelize: Negative shared-string index causes panic in GetCellValue and GetRows
GHSA-fx5j-qcqg-grpf
pkg: github.com/xuri/excelize/v2, github.com/xuri/excelize
eco: go
published: Sep 10, 2026
# Negative shared-string index causes panic in GetCellValue and GetRows

## Summary

Excelize parses shared-string cell values with `strconv.Atoi` and checks only the upper bound before indexing the shared string slice. If an XLSX file contains a shared-string cell with `<v>-1</v>`, the parsed index…

CVE-2026-59162
GitHub-GHSA

MEDIUM
containerd: CRI ExecSync Goroutine Leak Leads to Node-Level Denial of Service
GHSA-7jxh-36q5-gcqv
pkg: github.com/containerd/containerd/v2, github.com/containerd/containerd, github.com/containerd/containerd/v2
eco: go
published: Sep 9, 2026
### Impact

A bug in containerd's CRI ExecSync implementation allows exec probes and lifecycle hooks with background child processes to keep containerd's stdio-drain goroutines indefinitely blocked. Because the I/O drain phase lacks a default timeout or context cancellation handling, repeated ExecSy…

CVE-2026-53495
GitHub-GHSA

MEDIUM
n8n: Agent Workflow Tool Bypasses Sub-Workflow Caller Policy
GHSA-7hgx-277f-7vmg
pkg: n8n, n8n
eco: npm
published: Sep 8, 2026
## Impact

A workflow's "_This workflow can be called by_" setting was enforced by the Execute Workflow node but was not consulted when the same workflow was attached to an Agent as a tool. A user who could build an Agent could therefore call a workflow that its owner had restricted, and read back w…

CVE-2026-86996
GitHub-GHSA

MEDIUM
Astro: Authorization bypass from missing path-segment boundary check when stripping the configured base
GHSA-376h-93r7-7g6f
pkg: astro
eco: npm
published: Sep 8, 2026
## Summary

Astro stripped a configured `base` path from request pathnames using a string-prefix check that did not verify a path-segment boundary. With `base: "/app"`, a request to `/appX/admin` was treated as being under the base and resolved internally to the `/admin` route, while middleware stil…

CVE-2026-84376
GitHub-GHSA

MEDIUM
xmldom: Parser silently accepts a not-well-formed end tag whose name is followed by a line break and trailing content
GHSA-6h8r-xr42-gp59
pkg: @xmldom/xmldom, @xmldom/xmldom, xmldom
eco: npm
published: Sep 8, 2026
## Summary

xmldom's parser silently accepts a **not-well-formed end tag** whose valid name is followed by
trailing content — e.g. `</a⏎junk>`. The element is closed, the trailing content is discarded, and no
error is reported, even though the XML end-tag production allows only optional whitespa…

CVE-2026-83611
GitHub-GHSA

MEDIUM
Colord: Slow rejection of oversized malformed color strings
GHSA-2wm5-q62r-hmrv
pkg: colord
eco: npm
published: Sep 8, 2026
### Impact

`colord`'s CSS color string matchers described a number as `([+-]?\d*\.?\d+)`. In that form `\d*` and `\d+` can match the same digits, so a run of *n* digits can be divided between them in O(n²) ways, and rejecting an input retries every division. Parsing is synchronous and uninterrupti…

CVE-2026-85062
GitHub-GHSA

MEDIUM
gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion
GHSA-qc2q-p7wx-3px3
pkg: google.golang.org/grpc
eco: go
published: Sep 8, 2026
### Summary
A vulnerability in the xDS RBAC HTTP filter implementation in grpc-go allows remote attackers to bypass authorization policies (specifically DENY rules) by using mixed-case or canonical-case header matchers (e.g., X-Role instead of x-role). Additionally, the safety guards introduced by g…
CVE-2026-84303
GitHub-GHSA

MEDIUM
NLTK: Pl196xCorpusReader has quadratic ReDoS on malformed TEI blocks
GHSA-8mpw-7fpc-4gqj
pkg: nltk
eco: pip
published: Sep 8, 2026
### Summary

`Pl196xCorpusReader` still parses whole TEI blocks with multiple lazy regexes over attacker-controlled text. A malformed file with many opening tags and no matching closing tags forces repeated rescans and produces quadratic CPU growth in public reader APIs.

### Details

– **Vulnerabil…

CVE-2026-81725
GitHub-GHSA

MEDIUM
Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsing
GHSA-fccg-mwvh-qqg4
pkg: io.netty:netty-handler, io.netty:netty-handler
eco: maven
published: Sep 8, 2026
### Summary

Netty's default SNI entrypoint reparses and recopies previously received ClientHello fragments on every additional TLS handshake record. A remote peer can send a small first record that advertises a large ClientHello length and then drip the body in many tiny records, causing **superlin…

CVE-2026-75596
GitHub-GHSA

MEDIUM
Infracost: Terraform Cloud and registry token disclosure via unvalidated hostname
GHSA-6x6c-w9w9-hv4h
pkg: github.com/infracost/infracost
eco: go
published: Sep 8, 2026
### Impact

Sensitive information exposure in the Infracost Terraform Cloud/Enterprise integration. Several code paths attached a configured secret token to a request whose host was taken straight from the scanned Terraform, with no check that the host was the trusted endpoint.

The condition that …

CVE-2026-71494
GitHub-GHSA

MEDIUM
Infracost: Arbitrary file read via config-template readFile symlink traversal
GHSA-mmg6-4qmv-6pc8
pkg: github.com/infracost/infracost
eco: go
published: Sep 8, 2026
### Impact

Path traversal via link following in the Infracost config-template parser. The `readFile`, `pathExists`, `isDir`, and `matchPaths` template functions confined repo-supplied paths with a lexical `filepath.Rel` check plus a leaf-only `os.Lstat`:

“`
{{ readFile "evil/file" }}
“`

With an…

CVE-2026-71493
GitHub-GHSA

MEDIUM
node-csv: Prototype replacement still reachable via columns path
GHSA-8cw4-87c7-c6xx
pkg: csv-parse
eco: npm
published: Sep 8, 2026
### Impact
With columns: true and group_columns_by_name: true, a duplicated __proto__ header causes the duplicate-column branch to assign an array to obj['__proto__'], invoking the __proto__ setter and replacing the parsed record object's prototype with attacker-controlled data. Fixed in 7.0.2 (Obj…
CVE-2026-85063