Vulnerability Digest — September 21, 2026 · 66 Critical · 6 Exploited






Vulnerability Digest — Monday, September 21, 2026


Security Report

Monday, September 21, 2026  ·  Last 7 days  ·  Min severity: MEDIUM
Total Findings
450
Critical
66
High
220
Actively Exploited
6
CISA-KEV6
NVD311
GitHub-GHSA133
Findings sorted by severity
CISA-KEV

CRITICAL
Linux Kernel Race Condition Vulnerability
CVE-2025-39964
pkg: Linux Kernel

published: Sep 18, 2026

Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Linux Kernel Out-of-Bounds Write Vulnerability
CVE-2026-53266
pkg: Linux Kernel

published: Sep 18, 2026

Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of…
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability
CVE-2025-39682
pkg: Linux Kernel

published: Sep 18, 2026

Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causing subsequent TLS records to be processed using inc…
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Google Pixel Improper Authorization Vulnerability
CVE-2026-58704
pkg: Google Pixel

published: Sep 16, 2026

Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
CVE-2026-76460
pkg: Cisco Identity Services Engine

published: Sep 16, 2026

Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Acronis Backup Incorrect Default Permissions Vulnerability
CVE-2026-87886
pkg: Acronis Backup

published: Sep 16, 2026

Acronis Backup plugin for cPanel & WHM and extension for Plesk contains an incorrect default permissions vulnerability that could allow for privilege escalation.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
NVD

CRITICAL
CVE-2026-92941
CVE-2026-92941
pkg: tls

published: Sep 17, 2026

vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call tls.setDefaultCACertificates() and replace process-wide certificate authorities. Attackers with access to allowed tls and url builtins can use URLSearchParams to create host-realm arr…
CWE: CWE-732
NVD

CRITICAL
CVE-2026-92940
CVE-2026-92940
pkg: tls

published: Sep 17, 2026

vm2 versions 3.11.3 through 3.11.6 expose the host process's real https.globalAgent to sandboxed code when a NodeVM is explicitly configured to allow require('https'). The builtin loader wraps host modules in a read-only proxy, but method calls such as Agent.prototype.on() are forwarded to the under…
CWE: CWE-668
NVD

CRITICAL
CVE-2026-53710
CVE-2026-53710
pkg: python

published: Sep 15, 2026

MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs. Prior to 1.0.2, the python_sandbox_server in mcp-servers/python/python_sandbox_server/src/python_sandbox_server/server_fastmcp.py exposes raw getattr through safe_builtins, omits a required _getattr_ guard, an…
CWE: CWE-94, CWE-693
GitHub-GHSA

CRITICAL
kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace
GHSA-c8w2-fgvx-vhv4
pkg: github.com/kcp-dev/kcp, github.com/kcp-dev/kcp
eco: go
published: Sep 18, 2026
# Summary

The kcp front-proxy fails to strip client-supplied identity headers before forwarding requests to shards. Any authenticated tenant can inject their own `X-Remote-Group` and `X-Remote-Extra-*` headers, which the shard trusts as a verified identity assertion — allowing a low-privilege use…

CVE-2026-61682
NVD

CRITICAL
CVE-2026-61682
CVE-2026-61682
pkg: kubernetes

published: Sep 18, 2026

kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.31.4 and 0.32.2, the kcp front-proxy does not remove inbound X-Remote-User, X-Remote-Group, or X-Remote-Extra-* identity headers before forwarding requests to shards. Any authe…
CWE: CWE-290, CWE-302, CWE-348
NVD

CRITICAL
CVE-2025-53837
CVE-2025-53837
pkg: python

published: Sep 18, 2026

XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Prior to versions 14.10.2 and 15.0 RC1, any user who can edit their own user profile or any other document can execute arbitrary script macros includ…
CWE: CWE-95
GitHub-GHSA

CRITICAL
org.xwiki.rendering:xwiki-rendering-xml has an Eval Injection issue
GHSA-26vp-8gxg-v4pg
pkg: org.xwiki.rendering:xwiki-rendering-xml
eco: maven
published: Sep 18, 2026
### Impact
Any user who can edit their own user profile or any other document can execute arbitrary script macros including Groovy and Python macros that allow remote code execution including unrestricted read and write access to all wiki contents. The reason is that rendering output is included as …
CVE-2025-53837
NVD

CRITICAL
CVE-2026-92939
CVE-2026-92939
pkg: openssl

published: Sep 17, 2026

vm2 3.11.3 through 3.11.6 exposes the host Node.js crypto module to a NodeVM sandbox when the crypto builtin is allowed. The module is presented via a recursive read-only proxy, but its callable exports still execute with host-process authority. Sandboxed JavaScript can therefore call crypto.setEngi…
CWE: CWE-114
NVD

CRITICAL
CVE-2026-20307
CVE-2026-20307
pkg: node

published: Sep 16, 2026

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have at least low-privileged administrative creden…
CWE: CWE-502
NVD

CRITICAL
CVE-2026-61667
CVE-2026-61667
pkg: python

published: Sep 15, 2026

DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1.10, DataManagementSystem/Service/FileCatalogHandler.py checkDataset forwards an authenticated caller-controlled datasets value to DatasetManager.py __checkDataset, where datasetNa…
CWE: CWE-89, CWE-95
NVD

CRITICAL
CVE-2026-45579
CVE-2026-45579
pkg: express

published: Sep 15, 2026

DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1.10, the RequestManagementSystem/Service/ReqManagerHandler.py export_getRequestCountersWeb function passes an authenticated caller-controlled groupingAttribute to RequestManagement…
CWE: CWE-95
NVD

CRITICAL
CVE-2026-90937
CVE-2026-90937
pkg: nginx

published: Sep 14, 2026

froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated customers to inject arbitrary nginx or Apache configuration directives. Attackers can supply URLs containing literal newlines that are written verbatim into vhost config files during …
CWE: CWE-93
NVD

CRITICAL
CVE-2025-66455
CVE-2025-66455
pkg: python

published: Sep 18, 2026

LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.2 and prior to version 0.16.0, LMDeploy's PyTorch DistServe/PD-disaggregation control plane used `recv_pyobj()` to deserialize messages received through a ZeroMQ PULL socket. PyZMQ implements…
CWE: CWE-502
GitHub-GHSA

CRITICAL
LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.py
GHSA-2vh9-42vm-xmv2
pkg: lmdeploy
eco: pip
published: Sep 18, 2026
## Summary

LMDeploy's PyTorch DistServe/PD-disaggregation control plane used
`recv_pyobj()` to deserialize messages received through a ZeroMQ PULL
socket. PyZMQ implements `recv_pyobj()` using Python pickle
deserialization, which can execute arbitrary code while reconstructing
an object.

The peer …

CVE-2025-66455
NVD

CRITICAL
CVE-2026-92787
CVE-2026-92787
pkg: jwt

published: Sep 16, 2026

Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypass all role-based access control by presenting an unverified token with a hardcoded claim value. Attackers can obtain trusted internal identity and gain unchecked read and write acc…
CWE: CWE-798
NVD

CRITICAL
CVE-2025-56563
CVE-2025-56563
pkg: curl

published: Sep 16, 2026

A Server-Side Request Forgery vulnerability exists in sat_proxy.php in Zenith Satellite Tracker 1.0. The script accepts an attacker-controlled address URL parameter and passes it to curl_setopt(CURLOPT_URL) without host or scheme validation. An unauthenticated remote attacker can leverage this to ma…
CWE: CWE-918
GitHub-GHSA

CRITICAL
LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy
GHSA-5h8j-6crg-7rmw
pkg: lmdeploy
eco: pip
published: Sep 16, 2026
### Description

The LMdeploy implements an rpc server (AsyncRPCServer in zmq_rpc.py) for supporting the RPC communications. In its core functionality call_and_response(), I found it will directly use the pickles.loads() to deserialize the received messages without any sanitization, hence resu…

CVE-2025-59953
GitHub-GHSA

CRITICAL
@zereight/mcp-gitlab: Unauthenticated arbitrary file read via `upload_markdown` enables PAT exfiltration and full account takeover
GHSA-cv3r-c5h8-f4g5
pkg: @zereight/mcp-gitlab
eco: npm
published: Sep 16, 2026
### Summary

The SSE transport mode (`SSE=true`) exposes all MCP tools without any authentication. The `upload_markdown` tool reads arbitrary files from the server's local filesystem via an unsanitized `file_path` parameter and uploads them to a GitLab project. Combined, any unauthenticated network-…

CVE-2026-61560
NVD

CRITICAL
CVE-2026-89788
CVE-2026-89788
pkg: linux

published: Sep 16, 2026

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix tree connection use-after-free in smb2_tree_connect()

ksmbd_tree_conn_connect() publishes a new tree connection in
sess->tree_conns with a single reference and returns its pointer to
smb2_tree_connect(). The handler con…

NVD

CRITICAL
CVE-2026-89783
CVE-2026-89783
pkg: linux

published: Sep 16, 2026

In the Linux kernel, the following vulnerability has been resolved:

xfrm6: fix out-of-bounds write in xfrm6_input_addr() when secpath is full

The depth check in xfrm6_input_addr() is off by one:

if (1 + sp->len == XFRM_MAX_DEPTH)
goto drop;

sp->xvec[sp->len++] = x;

xfrm_input…

NVD

CRITICAL
CVE-2026-89778
CVE-2026-89778
pkg: linux

published: Sep 16, 2026

In the Linux kernel, the following vulnerability has been resolved:

isofs: fix out-of-bounds page array access on empty zisofs block

zisofs_uncompress_block()'s empty-block fast path returns
pcount << PAGE_SHIFT, ignoring the incoming poffset, unlike the
decompression path which returns bytes prod…

NVD

CRITICAL
CVE-2026-61560
CVE-2026-61560
pkg: docker

published: Sep 15, 2026

`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Prior to version 2.1.27, the SSE transport mode (`SSE=true`) exposes all MCP tools without any authentication. The `upload_markdown` tool reads arbitrary files from the server's local filesystem via an unsanitized `file_path` para…
CWE: CWE-22
NVD

CRITICAL
CVE-2026-89026
CVE-2026-89026
pkg: jwt

published: Sep 15, 2026

The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote attackers to forge valid bearer tokens. Attackers can …
CWE: CWE-321
NVD

CRITICAL
CVE-2026-57148
CVE-2026-57148
pkg: jwt

published: Sep 15, 2026

PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py falls back to the public dev-secret-change-me HS256 signing key when PLATFORM_JWT_SECRET is unset, while the startup and token-issuance guards are disabled because PLATFORM_ENV also defaults to dev. …
CWE: CWE-287, CWE-798, CWE-1188
NVD

CRITICAL
CVE-2026-57147
CVE-2026-57147
pkg: jwt

published: Sep 15, 2026

PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py assigns the public dev-secret-change-me value to JWT_SECRET when PLATFORM_JWT_SECRET is unset, and its production guard does not run when PLATFORM_ENV is also unset because that setting defaults to d…
CWE: CWE-798, CWE-1188
NVD

CRITICAL
CVE-2026-90945
CVE-2026-90945
pkg: jwt

published: Sep 14, 2026

Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables. Unauthenticated attackers can forge valid administrator tokens to access administrative APIs and execute code on worker nodes.
CWE: CWE-321
GitHub-GHSA

CRITICAL
ESPHome Device Builder: Renamed auth env vars silently disable dashboard authentication on upgrade
GHSA-rrxg-g2pf-6hh4
pkg: esphome-device-builder
eco: pip
published: Sep 14, 2026
## Summary

The dashboard reads its authentication credentials from `$ESPHOME_USERNAME` and `$ESPHOME_PASSWORD`. Earlier versions, and the legacy `esphome` dashboard, read the bare `$USERNAME` and `$PASSWORD` instead. When the env vars were renamed the bare names were dropped with no fallback, so an…

CVE-2026-59178
NVD

CRITICAL
CVE-2026-57127
CVE-2026-57127
pkg: jwt

published: Sep 14, 2026

PraisonAI is a multi-agent teams system. Prior to 4.6.58, recipe serve installs APIKeyAuthMiddleware or JWTAuthMiddleware when an operator selects api-key or JWT authentication, but each middleware forwards requests when PRAISONAI_API_KEY or PRAISONAI_JWT_SECRET and the corresponding recipe value ar…
CWE: CWE-306, CWE-1188
NVD

CRITICAL
CVE-2026-78330
CVE-2026-78330
pkg: jwt

published: Sep 14, 2026

Incorrect privilege assignment vulnerability in Apache Syncope.

When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can obtain admin privileges after completing a successful authentication and obtaining a valid low-privileges JWT.…

CWE: CWE-266
NVD

CRITICAL
CVE-2026-90898
CVE-2026-90898
pkg: go

published: Sep 14, 2026

Bifrost registers MCP clients through its management API. A stdio client is a command plus args. Bifrost starts that program in the gateway the moment the client is added. No MCP handshake required.

The default is governance.auth_config.is_enabled=false. Auth off means every caller is a local adm…

CWE: CWE-284, CWE-306
GitHub-GHSA

CRITICAL
@zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery
GHSA-2h44-8472-frjj
pkg: @zereight/mcp-gitlab
eco: npm
published: Sep 15, 2026
# Server-Side Request Forgery via X-GitLab-API-URL Header Allows Credential Theft

## Affected

– **Repository:** `zereight/gitlab-mcp`
– **Affected versions:** All versions through commit `74a8c83`
– **Patched versions:** None at time of report

## Severity

High. CVSS v3.1 8.5 (`AV:N/AC:L/PR:L/UI:…

CVE-2026-61559
GitHub-GHSA

CRITICAL
@zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transport
GHSA-vmp7-252j-cwp7
pkg: @zereight/mcp-gitlab
eco: npm
published: Sep 15, 2026
`@zereight/mcp-gitlab` exposes its Streamable HTTP MCP endpoint without an effective Host or Origin allowlist. A malicious web page can use DNS rebinding to route browser requests to a victim's local MCP listener while preserving an attacker-controlled `Host` and `Origin`. The server accepts those h…
CVE-2026-61568
NVD

CRITICAL
CVE-2026-12944
CVE-2026-12944
pkg: docker

published: Sep 14, 2026

IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by submitting components containing socket or urllib imports. This enables: (1) AWS credential theft via IMDSv1 SSRF with full IAM role permissions, (2) arbi…
CWE: CWE-918
NVD

CRITICAL
CVE-2026-90942
CVE-2026-90942
pkg: jwt

published: Sep 14, 2026

Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /api/get-cert endpoints, allowing organization administrators to retrieve it. Attackers can use the exposed private key to forge JWT tokens for any user in any organization, includin…
CWE: CWE-863
NVD

CRITICAL
CVE-2026-89918
CVE-2026-89918
pkg: express

published: Sep 16, 2026

In the Linux kernel, the following vulnerability has been resolved:

KVM: arm64: Correctly handle end of VA space TLBI invalidation

Our TLB invalidation by VA code is based on comparing two ranges,
one defined by the TLB, and one defined by the TLBI instruction.

Each range is defined by a start an…

NVD

CRITICAL
CVE-2026-89775
CVE-2026-89775
pkg: linux

published: Sep 16, 2026

In the Linux kernel, the following vulnerability has been resolved:

KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation

Computing the effects of a TLB invalidation involves looking at
the size of the mapping cached by the TLB. For S1 mappings such as
VNCR, this is deducted from …

NVD

CRITICAL
CVE-2026-91949
CVE-2026-91949
pkg: tls

published: Sep 15, 2026

FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated attackers to establish RDSTLS connections despite server policy disabling them. Attackers can send incompatible protocol requests, receive negotiation failures, then complete TLS han…
CWE: CWE-693
NVD

CRITICAL
CVE-2026-92701
CVE-2026-92701
pkg: tls

published: Sep 18, 2026

trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) Intel TDX verification path does not copy the expected current-session freshness value into the TDX quote-body policy before quote validation, so structurally valid TDX QuoteV4 Evidence is …
CWE: CWE-346, CWE-354
NVD

CRITICAL
CVE-2026-59163
CVE-2026-59163
pkg: jwt

published: Sep 18, 2026

Mnemosyne is a memory layer for artificial intelligence agents. Prior to v3.10.1, the auth check in mnemosyne/core/sync_server.py parsed the JWT's header and payload using base64 decoding, then passed the token to a jwt library call with options that effectively disabled signature verification. The …
CWE: CWE-347
GitHub-GHSA

CRITICAL
Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass
GHSA-xcw4-53cc-hv32
pkg: mnemosyne-memory
eco: pip
published: Sep 18, 2026
### Summary

The Mnemosyne sync server's authentication check decoded JWT bearer tokens but never verified their HMAC-SHA256 signatures. Any well-formed token was accepted, allowing an unauthenticated attacker to impersonate any user and read or modify their sync data.

**Severity: Critical**

CVSS …

CVE-2026-59163
GitHub-GHSA

CRITICAL
Marten's LINQ provider has SQL injection via unescaped string literals
GHSA-rfx3-98h7-v3xp
pkg: Marten
eco: nuget
published: Sep 17, 2026
Several code paths in Marten's LINQ provider and tenant-management internals interpolated a runtime, potentially attacker-influenced value into generated SQL as a single-quoted string literal without escaping or parameterization. A value containing a single quote (`'`) could break out of the literal…
CVE-2026-75513
GitHub-GHSA

CRITICAL
Vendure affected by external-authentication account takeover: external login linked to a pre-existing account by email without verification
GHSA-6j36-r6pr-59×4
pkg: @vendure/core
eco: npm
published: Sep 17, 2026
# External-authentication account takeover: external login linked to a pre-existing account by email without requiring verification

**Package:** @vendure/core (vendure-ecommerce/vendure, latest master) ·

> [!IMPORTANT]
> This vulnerability **only affects deployments that use external / social au…

CVE-2026-63472
NVD

CRITICAL
CVE-2026-61594
CVE-2026-61594
pkg: react

published: Sep 16, 2026

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the live (WebSocket) transport authorizes a mount via `check_view_auth`, not Django's `View.dispatch()` chain. As a result, standard Django authorization — `LoginR…
CWE: CWE-306, CWE-862
GitHub-GHSA

CRITICAL
djust has an authorization bypass on the WebSocket/SSE mount path
GHSA-xhhm-f6hp-2qwj
pkg: djust
eco: pip
published: Sep 16, 2026
### Impact
The live (WebSocket) transport authorizes a mount via `check_view_auth`, not Django's `View.dispatch()` chain. As a result, standard Django authorization — `LoginRequiredMixin`, `PermissionRequiredMixin`, `UserPassesTestMixin`, `@method_decorator(login_required, name="dispatch")`, and c…
CVE-2026-61594
NVD

CRITICAL
CVE-2026-92717
CVE-2026-92717
pkg: jwt

published: Sep 16, 2026

Covenant through 0.6 registers the CovenantHub SignalR hub without an Authorize attribute, allowing unauthenticated callers to invoke CreateHttpListener and receive a signed JWT token. Attackers can use the obtained token to authenticate against the entire operator API and access grunts, credentials…
CWE: CWE-306
NVD

CRITICAL
CVE-2026-20306
CVE-2026-20306
pkg: node

published: Sep 16, 2026

A vulnerability in the REST API of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, the attacker must have valid administrative credentials.

Th…

CWE: CWE-78
NVD

CRITICAL
CVE-2026-20305
CVE-2026-20305
pkg: node

published: Sep 16, 2026

A vulnerability in the diagnostic tools of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying operating system and elevate privileges to&nbsp;root. To exploit this vulnerability, the attacker must have valid administrative crede…
CWE: CWE-78
NVD

CRITICAL
CVE-2026-92395
CVE-2026-92395
pkg: express

published: Sep 16, 2026

@fastify/proxy-addr is a Fastify plugin that determines a request's client address behind trusted reverse proxies, and it backs Fastify request.ip and request.ips. In versions 3.0.0 through 5.1.0, a trust subnet written in IPv4-mapped IPv6 notation with an IPv4-sized prefix, such as ::ffff:10.0.0.0/…
CWE: CWE-290, CWE-348, CWE-697
NVD

CRITICAL
CVE-2026-89786
CVE-2026-89786
pkg: linux

published: Sep 16, 2026

In the Linux kernel, the following vulnerability has been resolved:

ext4: fix out-of-bounds read in ext4_read_inline_dir()

ext4_read_inline_dir() can read a dirent header past the end of its inline
buffer, triggering a slab-out-of-bounds read during getdents64():

BUG: KASAN: slab-out-of-bounds …

NVD

CRITICAL
CVE-2026-89779
CVE-2026-89779
pkg: linux

published: Sep 16, 2026

In the Linux kernel, the following vulnerability has been resolved:

fs/ntfs3: validate ef->size covers the record's name and value

When an EA record has a non-zero ef->size, ntfs_read_ea() only checks
that the record fits in the remaining buffer (ea_size > bytes), not that
ef->size is large enough…

NVD

CRITICAL
CVE-2026-90711
CVE-2026-90711
pkg: express

published: Sep 15, 2026

proxy-addr is a Node.js module that determines a request's client address behind trusted reverse proxies, and it backs Express req.ip and req.ips. In versions 1.1.0 through 2.0.7, a trust subnet written in IPv4-mapped IPv6 notation with an IPv4-sized prefix, such as ::ffff:10.0.0.0/8 instead of the …
CWE: CWE-290, CWE-348, CWE-697
NVD

CRITICAL
CVE-2026-53713
CVE-2026-53713
pkg: tls

published: Sep 14, 2026

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, to_absolute_normalized_path in internal/gatewayapi/luavalidator/security.lua does not collapse redundant separators before is_critical_path evaluates Lu…
CWE: CWE-20
NVD

CRITICAL
CVE-2026-43790
CVE-2026-43790
pkg: apple macos

published: Sep 14, 2026

The issue was addressed with improved memory handling. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.
CWE: CWE-787, CWE-787
NVD

CRITICAL
CVE-2026-87802
CVE-2026-87802
pkg: jwt

published: Sep 14, 2026

Improper verification of cryptographic signature vulnerability in Apache Syncope.

When SRA is configured for OAuth 2.0 without JWKS set URI assigned, an attacker can forge arbitrary JWTs to impersonate any user identity and permissions, gaining full access to services proxied by SRA.

This issue …

CWE: CWE-347
NVD

CRITICAL
CVE-2026-87785
CVE-2026-87785
pkg: jwt

published: Sep 14, 2026

Authentication bypass by spoofing vulnerability in Apache Syncope.

When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can spoof another user's privileges after completing a successful authentication and obtaining a valid JWT.

CWE: CWE-290
GitHub-GHSA

CRITICAL
AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing
GHSA-82r6-8w77-94w6
pkg: anyio
eco: pip
published: Sep 18, 2026
### Impact
Services using internationalized (non-ASCII) domain names are potentially vulnerable to TLS connections made from AnyIO's `connect_tcp()` or directly via `TLSStream.wrap()` where the connection has (through other means) been hijacked and redirected to a malicious server. The attacker woul…
CVE-2026-63374
GitHub-GHSA

CRITICAL
RabbitMQ amqp091-go: Protocol Desynchronization and Frame Injection via Integer Overflow in readLongstr
GHSA-c5pq-fr2g-9jpf
pkg: github.com/rabbitmq/amqp091-go
eco: go
published: Sep 17, 2026
**Summary**

A critical stream desynchronization vulnerability has been identified in the AMQP wire-protocol parser. When parsing a long string (`readLongstr`) within a table field, providing a length that exceeds the maximum signed 32-bit integer (`2^31 – 1`, or roughly `2.1` GiB) triggers an impro…

CVE-2026-77411
GitHub-GHSA

CRITICAL
RabbitMQ amqp091-go: Silent Data Truncation and State Corruption via Shortstr Integer Overflow
GHSA-j497-x9hr-x34x
pkg: github.com/rabbitmq/amqp091-go
eco: go
published: Sep 17, 2026
## Summary
A data integrity and protocol corruption vulnerability exists in the AMQP client's property serialization logic. When encoding AMQP short string (`shortstr`) fields—such as identifiers, routing strings, and content metadata—the length of the string is explicitly cast to a fixed-size 8…
CVE-2026-77408
GitHub-GHSA

CRITICAL
RabbitMQ amqp091-go: Missing Explicit TLS Minimum Version Configuration In URI Parser
GHSA-33mj-cw25-m34h
pkg: github.com/rabbitmq/amqp091-go
eco: go
published: Sep 17, 2026
## Summary
A structural security weakness exists in the AMQP client's TLS configuration generator (`tlsConfigFromURI`). When constructing a `*tls.Config` object from an `amqps://` connection URI, the library initializes the structure without explicitly defining the `MinVersion` field.

While modern…

CVE-2026-77405
GitHub-GHSA

CRITICAL
Http4s Ember accepts Transfer-Encoding combined with Content-Length (CL.TE request smuggling)
GHSA-8h4c-x2wg-6xp8
pkg: org.http4s:http4s-ember-core_2.12, org.http4s:http4s-ember-core_2.13, org.http4s:http4s-ember-core_3
eco: maven
published: Sep 15, 2026
## Summary

Ember's HTTP/1.1 request parser does not reject a message that carries both a
`Transfer-Encoding` and a `Content-Length` header. RFC 9112 §6.1 requires a
server to treat such a message as a framing error and close the connection.
An intermediary that follows the RFC's CL-strip-and-forwa…

CVE-2026-69204
NVD

HIGH
CVE-2026-81180
CVE-2026-81180
pkg: python

published: Sep 18, 2026

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.61, authenticated users of SysReptor Professional can upload image files whose formats cause image processing to invoke Ghostscript, allowing embedded PostScript to operate in the shared temporary directory. An attacker can …
CWE: CWE-20
NVD

HIGH
CVE-2026-33625
CVE-2026-33625
pkg: python

published: Sep 18, 2026

LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions 012.1 through 0.12.2 contain a code injection vulnerability in `lmdeploy/pytorch/config.py` line 620 that allows an attacker to execute arbitrary Python code by publishing a malicious HuggingFace model with…
CWE: CWE-400
GitHub-GHSA

HIGH
Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion
GHSA-xwmw-prc4-v3cr
pkg: github.com/obot-platform/obot
eco: go
published: Sep 18, 2026
## Summary

In affected versions, an unauthenticated attacker could register an OAuth client with an arbitrary external redirect URI, and the authorization flow would auto-complete without a consent screen. If a logged-in victim visited a crafted authorization URL, an authorization code was delivere…

NVD

HIGH
CVE-2026-58197
CVE-2026-58197
pkg: docker

published: Sep 18, 2026

ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol servers. Prior to ToolHive CLI 0.30.1 and ToolHive Studio 0.38.0, locally run MCP server containers use the default network permission profile without network isolation, permitting access to host.docke…
CWE: CWE-284, CWE-306
GitHub-GHSA

HIGH
ToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movement
GHSA-qg2g-g9w3-m5h8
pkg: github.com/stacklok/toolhive
eco: go
published: Sep 18, 2026
## Summary

A containerized MCP server running with the default `network` permission profile (`insecure_allow_all: true`) can reach host-local services via `host.docker.internal`. This includes the ToolHive API itself, other ToolHive-managed MCP server proxies, and any other service listening on the…

CVE-2026-58197
GitHub-GHSA

HIGH
LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loading
GHSA-3hmm-rh5q-gwwr
pkg: lmdeploy
eco: pip
published: Sep 18, 2026
### Summary

lmdeploy <= latest contains a code injection vulnerability in `lmdeploy/pytorch/config.py` line 620 that allows an attacker to execute arbitrary Python code by publishing a malicious HuggingFace model with a crafted `quantization_config.quant_dtype` value. When a user loads the model wi…

CVE-2026-33625
NVD

HIGH
CVE-2026-93381
CVE-2026-93381
pkg: windows

published: Sep 17, 2026

Buffer overflow in PDFium in Google Chrome on on Windows prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High)
CWE: CWE-122
NVD

HIGH
CVE-2026-54916
CVE-2026-54916
pkg: python

published: Sep 17, 2026

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The absence of tests/init.py and the lack of –import-mode=importlib cause pytest prepend import mode to place the tests directory at the front of sys.path during collection. An unauthenti…
CWE: CWE-427, CWE-829
GitHub-GHSA

HIGH
oras-go: Arbitrary file write outside file.Store root via symlink-chain bypass in tar extraction (pushDir)
GHSA-m37j-52j7-pjw7
pkg: oras.land/oras-go/v2
eco: go
published: Sep 17, 2026
### Summary
The `content/file.Store` in oras-go v2 unpacks OCI layer tarballs when a descriptor carries `io.deis.oras.content.unpack=true`. The extraction routine validates symlink targets purely lexically (`filepath.Join`) and, for regular files placed directly at the extraction root, skips the par…
CVE-2026-85731
GitHub-GHSA

HIGH
Tina: [Broken Access Control] letting any TinaCloud user authorize against any self-hosted site
GHSA-g74q-6g2f-874x
pkg: @tinacms/auth, next-tinacms-azure
eco: npm
published: Sep 17, 2026
## Summary

`@tinacms/auth`'s `isAuthorized(req)` decides authorization by validating the caller's bearer token against `https://identity.tinajs.io/v2/apps/${req.query.clientID}/currentUser`, where the `clientID` comes from the request and is never compared to the site's own configured TinaCloud ap…

CVE-2026-63506
NVD

HIGH
CVE-2026-92580
CVE-2026-92580
pkg: tls

published: Sep 16, 2026

In AVideo through 29.0, the CloneSite plugin is vulnerable to stored OS command injection. In plugin/CloneSite/cloneClient.json.php (line ~270) the stored SSH password is substituted into the command string `sshpass -p '{password}' rsync …` with a plain str_replace and no escaping, so a single quo…
CWE: CWE-78
NVD

HIGH
CVE-2026-92762
CVE-2026-92762
pkg: docker

published: Sep 16, 2026

Pelican Panel versions before 1.0.0-beta35 enforce startup write permissions only through disabled form controls rather than server-side authorization checks. Attackers with startup.read permission can craft Livewire state updates to invoke afterStateUpdated callbacks and modify startup commands, do…
CWE: CWE-862
NVD

HIGH
CVE-2026-88064
CVE-2026-88064
pkg: python

published: Sep 16, 2026

Backstage is an open framework for building developer portals. Prior to 1.14.6 and from 1.15.0 until 1.15.4, the @backstage/plugin-techdocs-node package insufficiently validates mkdocs.yml supplied by an authenticated user who can register or modify a TechDocs source. Unsafe Python YAML tags, markdo…
CWE: CWE-20, CWE-1336
NVD

HIGH
CVE-2026-82964
CVE-2026-82964
pkg: windows

published: Sep 16, 2026

Improper preservation of permissions in the Avast sandbox minifilter driver (aswSnx.sys) on Windows allows a local, low-privileged attacker executing inside the sandbox to escape file isolation and escalate to SYSTEM.

When the sandbox virtualizes a file it copies the original security descriptor,…

CWE: CWE-281, CWE-653, CWE-862
NVD

HIGH
CVE-2026-90041
CVE-2026-90041
pkg: node

published: Sep 16, 2026

In the Linux kernel, the following vulnerability has been resolved:

HID: sony: clean up device list on probe failure

sony_input_configured() adds some controllers to sony_device_list before
HID core registers their input devices. input_register_device() can fail
after the callback returns successf…

NVD

HIGH
CVE-2026-89811
CVE-2026-89811
pkg: linux

published: Sep 16, 2026

In the Linux kernel, the following vulnerability has been resolved:

drm/amdkfd: Add TLB flush after MES queue eviction/suspension

MES (Micro Engine Scheduler) does not perform heavy-weight TLB
invalidation after unmapping queues, unlike HWS which does this
automatically. This causes a race conditi…

NVD

HIGH
CVE-2026-89804
CVE-2026-89804
pkg: linux

published: Sep 16, 2026

In the Linux kernel, the following vulnerability has been resolved:

drm/nouveau/dmem: fix mismatched DMA unmap size for large folios

Device-private THP migration maps migration buffers with page_size()
and records that length in dma_info->size. For a compound folio
page_size() is PAGE_SIZE << ord…

NVD

HIGH
CVE-2026-86792
CVE-2026-86792
pkg: apache apache-airflow-providers-apache-kafka

published: Sep 16, 2026

Apache Airflow Apache Kafka provider versions 1.15.0 before 2.0.0 resolve dotted-path strings found in a Kafka connection's `extra` field into Python callables via `import_string`, with no allowlist, and hand them to the confluent-kafka client which invokes them. Deployments that have enabled the Ka…
CWE: CWE-470
NVD

HIGH
CVE-2026-89777
CVE-2026-89777
pkg: linux

published: Sep 16, 2026

In the Linux kernel, the following vulnerability has been resolved:

vfio/pci: clear vdev->msi_perm after freeing it on init failure

vfio_msi_cap_len() lazily allocates the per-device MSI permission table:

vdev->msi_perm = kmalloc_obj(struct perm_bits, GFP_KERNEL_ACCOUNT);
if (!vdev->msi_perm)

NVD

HIGH
CVE-2026-89774
CVE-2026-89774
pkg: linux

published: Sep 16, 2026

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: SCO: hold sk properly in sco_conn_ready

sk deref in sco_conn_ready must be done either under conn->lock, or
holding a refcount, to avoid concurrent close. conn->sk and parent sk is
currently accessed without either, and…

NVD

HIGH
CVE-2026-84408
CVE-2026-84408
pkg: windows

published: Sep 16, 2026

QND contains an improper access control vulnerability in a named pipe, which may allow a local attacker who is logged in to a Windows PC where the affected product's client is installed to execute arbitrary commands with SYSTEM privileges.
CWE: CWE-782
NVD

HIGH
CVE-2026-40058
CVE-2026-40058
pkg: linux

published: Sep 15, 2026

CrowdStrike released a security update to address a vulnerability in the Falcon sensor for Windows. The vulnerability only exists when the Microsoft Office File Malicious Macro Removal Windows policy setting is enabled and customers remain protected through the Cloud Anti-malware for Microsoft Offic…
CWE: CWE-367
NVD

HIGH
CVE-2026-91934
CVE-2026-91934
pkg: node

published: Sep 15, 2026

Flowise versions before 3.1.4 fail to validate file paths in the SQL Database Chain node when connecting to SQLite databases, allowing authenticated attackers to write arbitrary files. Attackers can write malicious SQLite databases to system directories or inject files into the web root to execute c…
CWE: CWE-22
NVD

HIGH
CVE-2026-91771
CVE-2026-91771
pkg: python

published: Sep 15, 2026

Weights & Biases wandb before 0.29.0 fails to validate the file name from server responses in the File.download function, allowing path traversal attacks. Attackers controlling the backend can supply file names with directory traversal sequences to write files outside the intended download directory…
CWE: CWE-22
NVD

HIGH
CVE-2026-43692
CVE-2026-43692
pkg: apple macos

published: Sep 14, 2026

A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A remote user may cause an unexpected app termination or arbitrary code execution.
CWE: CWE-20
NVD

HIGH
CVE-2026-43686
CVE-2026-43686
pkg: apple ipados, apple iphone_os, apple macos

published: Sep 14, 2026

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Connecting to a malicious NFS server may lead to kernel memory co…
CWE: CWE-416
GitHub-GHSA

HIGH
Opencast: Stored XSS in Paella player via WebVTT/DFXP caption cue text
GHSA-m6c8-jcw2-5r25
pkg: org.opencastproject:opencast-engage-paella-player-7, org.opencastproject:opencast-engage-paella-player-7, paella-core
eco: npm
published: Sep 18, 2026
## Summary

The Opencast Paella player renders caption cue text into `innerHTML` without escaping. The captions canvas clears `_captionsContainer.innerHTML` and then appends each active cue with `_captionsContainer.innerHTML += cue`, so HTML inside a WebVTT or DFXP cue becomes live DOM and executes …

CVE-2026-77615
GitHub-GHSA

HIGH
Vendure has stored XSS in the Admin Dashboard via unsafe HTML-stripping (innerHTML) of entity descriptions
GHSA-xhq9-whgq-49j5
pkg: @vendure/dashboard
eco: npm
published: Sep 17, 2026
# Stored XSS in the Admin Dashboard via unsafe HTML-stripping (`innerHTML`) of entity descriptions

**Package:** @vendure/dashboard (vendure-ecommerce/vendure, latest master) ·

## Summary
The dashboard's `RichTextDescriptionCell` "strips HTML" from an entity's `description` by assigning it to a l…

CVE-2026-63459
GitHub-GHSA

HIGH
Http4s Ember Transfer-Encoding value parsing (TE.CL / TE.0 request smuggling)
GHSA-9998-894r-fwvr
pkg: org.http4s:http4s-ember-core_3, org.http4s:http4s-ember-core_2.13, org.http4s:http4s-ember-core_2.12
eco: maven
published: Sep 15, 2026
## Summary

Ember's HTTP/1.1 header parser matches the `Transfer-Encoding` header value
with a case-sensitive substring test (`hValue.contains("chunked")`). RFC
9112 §7 requires transfer-coding names to be compared case-insensitively. A
request carrying `Transfer-Encoding: Chunked` (capital C) is t…

CVE-2026-69205
NVD

HIGH
CVE-2026-93759
CVE-2026-93759
pkg: express

published: Sep 18, 2026

Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side JavaScript expression. An unauthenticated party able to influence the value an application supplies as a query argument may cause code of their choosing to…
CWE: CWE-94
GitHub-GHSA

HIGH
Kestra: SSRF via Pebble http() function allows unauthenticated access to internal services & cloud metadata
GHSA-r56g-q4p6-m3p6
pkg: io.kestra:core, io.kestra:kestra-core
eco: maven
published: Sep 17, 2026
### Summary
The Pebble template engine's `http()` function in Kestra OSS accepts user-controlled URLs without any validation, allowing Server-Side Request Forgery (SSRF) attacks. An unauthenticated attacker can import a malicious Flow YAML and execute it to access internal services, cloud metadata e…
CVE-2026-73247
NVD

HIGH
CVE-2026-20295
CVE-2026-20295
pkg: tls

published: Sep 16, 2026

A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software and Cisco Secure FTD Software could allow an unauthenticated, remote attacker to exhaust the available memory of an affected device.

This vulnerability is due to improper management of memory resource…

CWE: CWE-789
NVD

HIGH
CVE-2026-20250
CVE-2026-20250
pkg: tls

published: Sep 16, 2026

A vulnerability in Datagram TLS (DTLS) message handling of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software for Cisco Secure Firewall 3100 Series and 4200 Series devices could allow an unauthenticated, remote attacker to cause a…
CWE: CWE-772
NVD

HIGH
CVE-2026-20135
CVE-2026-20135
pkg: tls

published: Sep 16, 2026

A vulnerability in the TLS 1.3 implementation in Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition.

This vulnerability is due to improper buffer m…

CWE: CWE-415
NVD

HIGH
CVE-2026-54628
CVE-2026-54628
pkg: go

published: Sep 14, 2026

Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes URL-capable SQLite virtual table modules such as json_reader and log_reader through its unauthenticated MySQL-compatible server port without restricting outbound destinations. A remote attacker can provid…
CWE: CWE-284, CWE-441, CWE-862, CWE-918
NVD

HIGH
CVE-2026-90938
CVE-2026-90938
pkg: docker

published: Sep 14, 2026

LangBot's plugin runtime (pip package langbot_plugin) through 0.4.17 starts a debug WebSocket server on 0.0.0.0:5401 (/plugin/ws) whose authentication is gated on plugin_debug_key, which defaults to an empty string and is never set by the upstream repository, Docker image, or docker-compose (which a…
CWE: CWE-306
NVD

HIGH
CVE-2026-91931
CVE-2026-91931
pkg: node

published: Sep 15, 2026

Flowise before 3.1.4 contains a remote code execution vulnerability in the Custom MCP node that allows authenticated attackers to execute arbitrary code by supplying npx package names in the mcpServerConfig parameter. Attackers can invoke npx with attacker-controlled npm packages to execute code on …
CWE: CWE-78
NVD

HIGH
CVE-2026-55072
CVE-2026-55072
pkg: express

published: Sep 14, 2026

Pimcore is an Open Source Data & Experience Management Platform. Prior to 2026.1.5, an authenticated user with the objects permission can submit a malicious ClassDefinition UID because the name and ID validation expressions in models/DataObject/ClassDefinition.php validate only the beginning of each…
CWE: CWE-20, CWE-89
GitHub-GHSA

HIGH
RestrictedPython vulnerable to sandbox escape via string.Formatter field resolution
GHSA-hp3v-5vw7-fx9w
pkg: RestrictedPython
eco: pip
published: Sep 17, 2026
### Impact
RestrictedPython could allow a sandbox escape when a policy exposes the standard library `string` module, or otherwise exposes `string.Formatter`, to restricted code.

`string.Formatter` field resolution methods such as `get_field` can perform attribute and item traversal internally and r…

CVE-2026-76825
NVD

HIGH
CVE-2026-76825
CVE-2026-76825
pkg: python

published: Sep 16, 2026

RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a trusted environment. Prior to 8.4, RestrictedPython could allow a sandbox escape when a custom import policy or globals exposed the standard library string module, the string.Formatter class…
CWE: CWE-200, CWE-470, CWE-680, CWE-693
NVD

HIGH
CVE-2026-89992
CVE-2026-89992
pkg: node

published: Sep 16, 2026

In the Linux kernel, the following vulnerability has been resolved:

cpuidle: dt_idle_genpd: kfree() the original name allocation

dt_idle_pd_alloc() kasprintf()s the full node path, then points
pd->name at kbasename() of that string. dt_idle_pd_free() kfree()s
pd->name, which is no longer the start…

NVD

HIGH
CVE-2026-89806
CVE-2026-89806
pkg: linux

published: Sep 16, 2026

In the Linux kernel, the following vulnerability has been resolved:

drm/sysfb: ofdrm: Fix integer overflow in fb_size calculation

The framebuffer size calculation `fb_size = linebytes * height` can
overflow when both values are large (e.g., 46341 * 46341 > INT_MAX).
Since linebytes and height are …

NVD

HIGH
CVE-2026-89795
CVE-2026-89795
pkg: linux

published: Sep 16, 2026

In the Linux kernel, the following vulnerability has been resolved:

PCI: Allow per function PCI slots to fix slot reset on s390

On s390 systems, which use a machine level hypervisor, PCI devices are
always accessed through a form of PCI pass-through which fundamentally
operates on a per PCI functi…

NVD

HIGH
CVE-2026-89782
CVE-2026-89782
pkg: linux

published: Sep 16, 2026

In the Linux kernel, the following vulnerability has been resolved:

fs/ntfs3: reject restart table growth beyond U16_MAX entries

During $LogFile replay, log_replay() indexes the transaction table by the
transact_id taken from the log record header. check_log_rec() only
verifies that transact_id i…

NVD

HIGH
CVE-2026-89781
CVE-2026-89781
pkg: linux

published: Sep 16, 2026

In the Linux kernel, the following vulnerability has been resolved:

fs/ntfs3: fix out-of-bounds read in read_log_rec_buf()

read_log_rec_buf() copies a log record into a caller buffer starting at

u32 off = lsn_to_page_off(log, lsn) + log->record_header_len;

log->record_header_len (and log->data_…

NVD

HIGH
CVE-2026-54447
CVE-2026-54447
pkg: oauth

published: Sep 14, 2026

garminconnect is a Python 3 API wrapper for Garmin Connect that retrieves statistics and manages activities. Prior to 0.3.5, garminconnect/client.py Client.dump creates the OAuth token directory and garmin_tokens.json without explicit owner-only modes, so a permissive umask such as 022 can leave the…
CWE: CWE-732
NVD

HIGH
CVE-2026-54597
CVE-2026-54597
pkg: express

published: Sep 17, 2026

ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.07, an authenticated user with module_support write permission and access to a credential record can perform time-based blind SQL injection through the expires parameter of t…
CWE: CWE-89
NVD

HIGH
CVE-2026-20323
CVE-2026-20323
pkg: tls

published: Sep 16, 2026

A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software and Cisco Secure FTD Software could allow an unauthenticated, adjacent attacker to impersonate the peer device and obtain access at the level of the&nbsp;manager role, which is equivalent to root.

Thi…

CWE: CWE-295
NVD

HIGH
CVE-2026-91935
CVE-2026-91935
pkg: node

published: Sep 15, 2026

Flowise before 3.1.4 fails to validate baseURL parameters in chat-model nodes, allowing authenticated users to redirect requests to arbitrary hosts. Attackers with chatflows:create or chatflows:update permissions can exfiltrate LLM provider API keys by redirecting requests to cloud metadata services…
CWE: CWE-918
GitHub-GHSA

HIGH
File Viewer: DOM XSS via unsafe hyperlink schemes in the legacy DOC renderer
GHSA-3753-m2x2-q623
pkg: @file-viewer/doc, msdoc-viewer
eco: npm
published: Sep 18, 2026
### Summary

Before 2.3.1, the legacy `.doc` renderer emitted document hyperlink targets after HTML escaping but without a URL-scheme allowlist. A crafted `.doc` could therefore render a live `javascript:`, `vbscript:`, `data:`, or similarly unsafe link. Script could execute in the embedding origin …

CVE-2026-91127
NVD

HIGH
CVE-2026-54253
CVE-2026-54253
pkg: jwt

published: Sep 17, 2026

TS3 Manager is modern web interface for maintaining Teamspeak3 servers. Prior to 2.2.6, the /api/download handler in packages/server/routes/api.js passes the attacker-controlled port query parameter to socket.connect(port, host) and returns the resulting error.message through res.status(400).send(er…
CWE: CWE-79
GitHub-GHSA

HIGH
libp2p: PeerStore accepts attacker-signed PeerRecords for a victim peer ID and stores certified attacker addresses
GHSA-vrf4-mx87-p53w
pkg: @libp2p/peer-store
eco: npm
published: Sep 17, 2026
### Summary
`@libp2p/peer-store` accepts a signed `PeerRecord` whose envelope is signed by one peer but whose payload claims a different peer ID. The vulnerable `consumePeerRecord` path verifies the envelope signature, but does not verify that the envelope signer is the same peer as the wrapped `Pee…
CVE-2026-86039
NVD

HIGH
CVE-2026-85077
CVE-2026-85077
pkg: python

published: Sep 17, 2026

Sanic is an opensource python web server/framework. Prior to version 24.12.1, and in version 25.12.0, the HTTP/1.1 response pipeline in sanic/response/types.py serializes response header names and values without rejecting carriage-return or line-feed characters. Applications that place attacker-cont…
CWE: CWE-113
GitHub-GHSA

HIGH
RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata Discovery
GHSA-33f5-2c5q-wgwj
pkg: rmcp
eco: rust
published: Sep 16, 2026
### Summary
The `rmcp` library does not validate the `resource` parameter in OAuth Protected Resource metadata (RFC 9728), allowing a malicious MCP server to redirect OAuth flows to a legitimate authorization server and steal the resulting access tokens.

### Details
RFC 9728 specifies two MUST requ…

CVE-2026-63127
NVD

HIGH
CVE-2026-63127
CVE-2026-63127
pkg: oauth

published: Sep 16, 2026

RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's OAuth implementation in crates/rmcp/src/transport/auth.rs omits the RFC 9728 resource field from ResourceServerMetadata and allows discover_oauth_server_via_resource_metadata to use protected-resource metad…
CWE: CWE-345
NVD

HIGH
CVE-2026-54167
CVE-2026-54167
pkg: jwt

published: Sep 15, 2026

Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, the GitHub App provider accepts X-GitHub-Enterprise-Host as the API host while processing webhook events containing an installation.id, before webhook…
CWE: CWE-345
NVD

HIGH
CVE-2026-57134
CVE-2026-57134
pkg: oauth

published: Sep 15, 2026

PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, MCPSecurity.evaluatePolicy() in src/praisonai-ts/src/mcp/security.ts invokes the configured credential validator only when AuthMethod is api-key or bearer. Basic and OAuth policies accept any non-empty Authorization header without call…
CWE: CWE-287, CWE-288, CWE-863
NVD

HIGH
CVE-2026-85921
CVE-2026-85921
pkg: windows

published: Sep 14, 2026

Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
CWE: CWE-415
GitHub-GHSA

HIGH
zot: Bearer authentication maps DELETE to push scope, allowing unauthorized deletion
GHSA-qg67-7m6v-qg25
pkg: zotregistry.dev/zot/v2
eco: go
published: Sep 18, 2026
### Summary

A bearer token with only `pull` and `push` scopes can successfully delete manifests and blobs from a zot registry. The bearer authentication handler maps all non-GET/HEAD HTTP methods, including DELETE, to the `"push"` action, and the `DistSpecAuthzHandler` middleware is bypassed entire…

CVE-2026-61833
NVD

HIGH
CVE-2026-93393
CVE-2026-93393
pkg: tls

published: Sep 17, 2026

A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. A remote endpoint that the client connects to can cause the driver to write uncontrolled data outside the bounds of a heap allocation while processing incoming enc…
CWE: CWE-787
NVD

HIGH
CVE-2026-93375
CVE-2026-93375
pkg: windows

published: Sep 17, 2026

Incorrect reference resolution in Tracing in Google Chrome on on Windows prior to 153.0.8010.52 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
CWE: CWE-706
NVD

HIGH
CVE-2026-54596
CVE-2026-54596
pkg: express

published: Sep 17, 2026

ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.07, an authenticated Technician or higher with access to at least one client invoice can inject SQL through the frequency parameter handled by agent/post/recurring_invoice.ph…
CWE: CWE-89
NVD

HIGH
CVE-2026-92943
CVE-2026-92943
pkg: tls

published: Sep 17, 2026

Improper validation of certificate with host mismatch in the MQTT client TLS connection layer in AWS IoT Device SDK for Python 1.5.3 through 1.6.0 on Python 3.7 and later might allow an adversary-in-the-middle actor to impersonate the AWS IoT Core endpoint, read device telemetry, and inject arbitrar…
CWE: CWE-297
NVD

HIGH
CVE-2026-92919
CVE-2026-92919
pkg: windows

published: Sep 17, 2026

admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to write files outside the storage root on Windows deployments. Attackers can use dot-dot path segments in filenames to escape the configured storage directory and overwrite arbitrary…
CWE: CWE-22
NVD

HIGH
CVE-2026-87935
CVE-2026-87935
pkg: nginx

published: Sep 17, 2026

The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.15 via the admin_request_handler function. This is due to missing authorization and file type validation in the admin_request_handler function, which is reachable unauthenticated vi…
CWE: CWE-434
NVD

HIGH
CVE-2026-61591
CVE-2026-61591
pkg: react

published: Sep 16, 2026

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, for views that opt into state snapshots, the snapshot `state_json` embedded in the client page was restored on reconnect as trusted view state with no integrity chec…
CWE: CWE-345, CWE-915
GitHub-GHSA

HIGH
@nuxtjs/mdc's URL sanitizer misses SVG xlink:href and data:text/html, allowing XSS from untrusted markdown at the default configuration
GHSA-mxm6-v9r6-r94c
pkg: @nuxtjs/mdc
eco: npm
published: Sep 16, 2026
## Summary

`@nuxtjs/mdc` renders untrusted markdown (including raw HTML) to a Vue component tree. Across two prior advisories it added a URL/attribute sanitizer to block dangerous links in that HTML: `validateProps` / `validateProp` and an `unsafeLinkPrefix` deny-list (`dist/runtime/parser/utils/pr…

CVE-2026-63671
GitHub-GHSA

HIGH
djust: Unsigned client state snapshot is restored as trusted view state (privilege escalation / state injection)
GHSA-c67v-vqrp-m5wj
pkg: djust
eco: pip
published: Sep 16, 2026
### Impact
For views that opt into state snapshots, the snapshot `state_json` embedded in the client page was restored on reconnect as **trusted** view state with no integrity check. A client could edit the unsigned `state_json` in their page and return it in the reconnect mount frame to **inject ar…
CVE-2026-61591
NVD

HIGH
CVE-2026-61593
CVE-2026-61593
pkg: react

published: Sep 16, 2026

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the SSE client→server POST endpoints are `@csrf_exempt` and the SSE GET stream endpoint had no Origin check, so a cross-origin page could drive a victim-cookie-aut…
CWE: CWE-352
GitHub-GHSA

HIGH
djust has Cross-Site Request Forgery on the Server-Sent-Events transport: a cross-origin page can drive a victim-authenticated SSE session
GHSA-pg97-jvmf-qfvc
pkg: djust
eco: pip
published: Sep 16, 2026
### Impact
The SSE client→server POST endpoints are `@csrf_exempt` and the SSE GET stream endpoint had no Origin check, so a cross-origin page could drive a victim-cookie-authenticated SSE session: force the victim's browser to GET the stream URL (which **creates and mounts** a LiveView as the vic…
CVE-2026-61593
NVD

HIGH
CVE-2026-63671
CVE-2026-63671
pkg: vue

published: Sep 16, 2026

MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. Prior to 0.22.1, @nuxtjs/mdc uses parseMarkdown with allowDangerousHtml enabled by default and relies on validateProps, validateProp, and unsafeLinkPrefix to remove executable URLs from untrusted Mark…
CWE: CWE-79, CWE-184
NVD

HIGH
CVE-2026-89999
CVE-2026-89999
pkg: node

published: Sep 16, 2026

In the Linux kernel, the following vulnerability has been resolved:

HID: wacom: validate report length in wacom_intuos_pro2_bt_irq

wacom_intuos_pro2_bt_irq() receives the wire report length in `len`
but never consults it before parsing. After the report-id gate it
unconditionally calls wacom_intuo…

NVD

HIGH
CVE-2026-86466
CVE-2026-86466
pkg: apache apache-airflow-providers-fab

published: Sep 16, 2026

Apache Airflow FAB provider: the Authentik OAuth path in the FAB auth manager does not validate the issuer or audience claims of the id_token it accepts. An attacker holding a token that the same Authentik identity provider minted for a different client application can present it to Airflow and be a…
CWE: CWE-346
GitHub-GHSA

HIGH
@zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticated transports, session-exhaustion DoS
GHSA-5648-rgj9-v224
pkg: @zereight/mcp-gitlab
eco: npm
published: Sep 15, 2026
### Summary
@zereight/mcp-gitlab exposes GitLab to an LLM agent while relying on read-only mode, a project allow-list, and transport auth as its safety controls. Five defects defeat those controls. Under the MCP threat model, tool-call arguments/content can be shaped by untrusted input (prompt injec…
NVD

HIGH
CVE-2026-61668
CVE-2026-61668
pkg: ssl

published: Sep 15, 2026

DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1.10, WorkloadManagementSystem/Utilities/PilotWrapper.py pilotWrapperScript uses ssl._create_unverified_context to download the second-stage pilot.tar archive without TLS certificat…
CWE: CWE-295
GitHub-GHSA

HIGH
ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange
GHSA-vrh8-c9cm-wh8v
pkg: github.com/zitadel/zitadel
eco: go
published: Sep 14, 2026
### Summary

A vulnerability in ZITADEL’s OAuth2 Token Exchange endpoint allows an authenticated user or client to exchange a low-privilege access token for a token with elevated permissions at a completely different application. This bypasses the intended authorization and separation policies con…

CVE-2026-56668
NVD

HIGH
CVE-2026-54182
CVE-2026-54182
pkg: curl

published: Sep 14, 2026

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to 4.1.70, 5.6.2, 6.8.13, and 7.0.36, Backpack\CRUD\Stats::makeCurlRequest in src/Stats.php is reached from BackpackServicePr…
CWE: CWE-20, CWE-78, CWE-116
NVD

HIGH
CVE-2026-82438
CVE-2026-82438
pkg: go

published: Sep 14, 2026

Description

Three separate mechanisms allowed a web page on an unrelated origin to read responses that Storm's HTTP
components served to an authenticated user.

The Logviewer reflected the request's `Origin` header back in `Access-Control-Allow-Origin` while also
sending `Access-Control-Allow-Crede…

CWE: CWE-346, CWE-942
NVD

HIGH
CVE-2026-55225
CVE-2026-55225
pkg: kubernetes

published: Sep 15, 2026

Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In Strimzi 1.0.0 and earlier, an attacker who can create a Kafka custom resource can set Kafka.spec.entityOperator watchedNamespace to a target namespace, causing the Cluster Operat…
CWE: CWE-269, CWE-441, CWE-250
NVD

HIGH
CVE-2026-46655
CVE-2026-46655
pkg: windows

published: Sep 18, 2026

virtio-win provides Windows paravirtualized drivers for QEMU and KVM. From mm210 until mm320, the Viosock driver permits a low-privilege local process to submit an IOCTL_SELECT request with attacker-controlled VIRTIO_VSOCK_SELECT.Fdss[*].fd_count values that overflow the 32-bit sum used by VIOSockSe…
CWE: CWE-122, CWE-190
NVD

HIGH
CVE-2026-90321
CVE-2026-90321
pkg: python

published: Sep 17, 2026

In the Linux kernel, the following vulnerability has been resolved:

ocfs2: validate inline xattrs during inode block validation

Patch series "ocfs2: validate xattr entry bounds", v7.

This series validates OCFS2 xattr entry name/value bounds when xattr
metadata is read and validated, before getxat…

NVD

HIGH
CVE-2026-90199
CVE-2026-90199
pkg: express

published: Sep 17, 2026

In the Linux kernel, the following vulnerability has been resolved:

fs/ntfs3: reject out-of-range evcn in mi_enum_attr()

In mi_enum_attr(), the start/end VCN validation for non-resident
attributes is:

if (svcn > evcn + 1) goto out;

When evcn is U64_MAX the "evcn + 1" expression wraps to 0 and a…

NVD

HIGH
CVE-2026-63325
CVE-2026-63325
pkg: express

published: Sep 16, 2026

Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to version 2.33.0 of @redocly/respect-core and @redocly/cli, the respect command dynamically evaluates $faker runtime expressions in Arazzo descriptions. A crafted expression can traverse constructor, prototype,…
CWE: CWE-94, CWE-95
NVD

HIGH
CVE-2026-59974
CVE-2026-59974
pkg: python

published: Sep 16, 2026

Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human languages. Prior to 1.14.0, stanza.resources.common.unzip in stanza/resources/common.py passes downloaded model and resource archives to zipfile.ZipFile.extractall without validating membe…
CWE: CWE-22
NVD

HIGH
CVE-2026-90047
CVE-2026-90047
pkg: node

published: Sep 16, 2026

In the Linux kernel, the following vulnerability has been resolved:

drm/xe: Don't hand out the flat CCS storage as usable VRAM

get_flat_ccs_offset() reads the base of the flat CCS storage from the
hardware, scales it by the number of enabled L3 nodes, and rounds the
result up to 128K. Everything …

NVD

HIGH
CVE-2026-89985
CVE-2026-89985
pkg: node

published: Sep 16, 2026

In the Linux kernel, the following vulnerability has been resolved:

memcg: keep folio's objcg same as its node

memcg_reparent_objcgs() has an inherent assumption that a folio's objcg is
the objcg of the folio's node. Folio migration across nodes breaks that
assumption: the new folio simply inheri…

NVD

HIGH
CVE-2026-89894
CVE-2026-89894
pkg: node

published: Sep 16, 2026

In the Linux kernel, the following vulnerability has been resolved:

media: cx231xx: reject geometry changes while the VBI queue is busy

vidioc_s_fmt_vid_cap() and vidioc_s_std() change the device-wide
dev->width / dev->norm but only refuse the change when the *video* queue
(dev->vidq) is busy. The…

NVD

HIGH
CVE-2026-89832
CVE-2026-89832
pkg: node

published: Sep 16, 2026

In the Linux kernel, the following vulnerability has been resolved:

f2fs: fix to clear dirty flag on folio in error path

If node block is corrupted due to chksum mismatch or inconsistent
footer info, it needs to drop clear flag of node folio, in order
to persist inconsistent node data to storage.

NVD

HIGH
CVE-2026-89814
CVE-2026-89814
pkg: linux

published: Sep 16, 2026

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: clamp the isolation index for rings outside a partition

adev->isolation[] has one slot per partition, but a ring that is not
assigned to one keeps AMDGPU_XCP_NO_PARTITION, which is ~0, so indexing
the array with it is …

NVD

HIGH
CVE-2026-89810
CVE-2026-89810
pkg: linux

published: Sep 16, 2026

In the Linux kernel, the following vulnerability has been resolved:

drm/amdkfd: Fix error path at svm_migrate_copy_to_ram

If page migration from device to sys ram fails for some reasons driver needs
release and unlock allocated system pages. To do that driver should use page
physical address, or p…

NVD

HIGH
CVE-2026-89808
CVE-2026-89808
pkg: linux

published: Sep 16, 2026

In the Linux kernel, the following vulnerability has been resolved:

drm/amdkfd: Fix the case that vm range is hole at svm_migrate_copy_to_vram

When migration vm range is hole at cpu side(MIGRATE_PFN_MIGRATE set +
MIGRATE_PFN_VALID unset) driver still allocates device pages. There is no
dma map of …

NVD

HIGH
CVE-2026-89805
CVE-2026-89805
pkg: linux

published: Sep 16, 2026

In the Linux kernel, the following vulnerability has been resolved:

drm/pagemap: Fix folio allocation fallback and use-after-put

drm_pagemap_migrate_populate_ram_pfn() had two issues when populating
RAM PFNs with higher-order folios:

1. The higher-order vma_alloc_folio()/folio_alloc() calls did n…

NVD

HIGH
CVE-2026-89803
CVE-2026-89803
pkg: linux

published: Sep 16, 2026

In the Linux kernel, the following vulnerability has been resolved:

drm/nouveau: unsubscribe the channel-kill event before the fence context

nouveau_channel_del() tears the fence context down first and only drops
the channel-kill subscription later, in the middle of the nvif object
teardown:

if …

NVD

HIGH
CVE-2026-89801
CVE-2026-89801
pkg: linux

published: Sep 16, 2026

In the Linux kernel, the following vulnerability has been resolved:

drm/nouveau/uvmm: fix premature region free on failed OP_UNMAP_SPARSE

In nouveau_uvmm_bind_job_submit()'s OP_UNMAP_SPARSE arm, op->reg is set
from nouveau_uvma_region_find(), which only looks the region up and takes
no reference; …

NVD

HIGH
CVE-2026-89799
CVE-2026-89799
pkg: linux

published: Sep 16, 2026

In the Linux kernel, the following vulnerability has been resolved:

bpf: Disable preemption in bpf_get_stackid

The get_perf_callchain call needs disabled preemption plus we need
it disabled as long as we access its returned trace entries buffer.

Note the bpf_get_stackid_pe function is executed al…

NVD

HIGH
CVE-2026-89793
CVE-2026-89793
pkg: linux

published: Sep 16, 2026

In the Linux kernel, the following vulnerability has been resolved:

ublk: clear VM_MAYWRITE on read-only ublk char device mmap

ublk_ch_mmap() rejects mmap requests with VM_WRITE set, but never
clears VM_MAYWRITE on the resulting read-only mapping. This allows
a userspace daemon to mmap the per-que…

NVD

HIGH
CVE-2026-89791
CVE-2026-89791
pkg: linux

published: Sep 16, 2026

In the Linux kernel, the following vulnerability has been resolved:

perf: Fix use-after-free when perf mmap() revival races with the last munmap()

perf_mmap_close() drops rb->mmap_count *without* holding
event->mmap_mutex (the refcount_dec_and_test() right before the
refcount_dec_and_mutex_lock() …

NVD

HIGH
CVE-2026-89789
CVE-2026-89789
pkg: linux

published: Sep 16, 2026

In the Linux kernel, the following vulnerability has been resolved:

gtp: add synchronize_net() in gtp_newlink() error path to prevent use-after-free

gtp_newlink()'s error path frees tid_hash and addr_hash without
waiting for an RCU grace period after clearing sk_user_data. A
concurrent gtp_encap_r…

NVD

HIGH
CVE-2026-87271
CVE-2026-87271
pkg: windows

published: Sep 15, 2026

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle …
CWE: CWE-269
NVD

HIGH
CVE-2026-87270
CVE-2026-87270
pkg: windows

published: Sep 15, 2026

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle …
CWE: CWE-269
NVD

HIGH
CVE-2026-87269
CVE-2026-87269
pkg: windows

published: Sep 15, 2026

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle …
CWE: CWE-269
NVD

HIGH
CVE-2026-87268
CVE-2026-87268
pkg: windows

published: Sep 15, 2026

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle …
CWE: CWE-269
NVD

HIGH
CVE-2026-65344
CVE-2026-65344
pkg: apple ipados, apple iphone_os, apple macos

published: Sep 14, 2026

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27. Processing a maliciously crafted video file may lead to unexpected app te…
CWE: CWE-787
NVD

HIGH
CVE-2026-64790
CVE-2026-64790
pkg: apple macos

published: Sep 14, 2026

A path handling issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain elevated privileges.
CWE: CWE-22
NVD

HIGH
CVE-2026-64712
CVE-2026-64712
pkg: apple macos

published: Sep 14, 2026

This issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges.
CWE: CWE-284
NVD

HIGH
CVE-2026-43786
CVE-2026-43786
pkg: apple macos

published: Sep 14, 2026

This issue was addressed with additional entitlement checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges.
CWE: CWE-280
NVD

HIGH
CVE-2026-43691
CVE-2026-43691
pkg: apple macos

published: Sep 14, 2026

A path handling issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges.
CWE: CWE-22
NVD

HIGH
CVE-2026-43689
CVE-2026-43689
pkg: apple ipados, apple iphone_os, apple macos

published: Sep 14, 2026

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. A malicious app may be able to gain root privileges.
CWE: CWE-862
NVD

HIGH
CVE-2026-43688
CVE-2026-43688
pkg: apple ipados, apple iphone_os, apple macos

published: Sep 14, 2026

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27. Processing a maliciously crafted file may lead to unexpected app termination.
CWE: CWE-1021
NVD

HIGH
CVE-2026-43684
CVE-2026-43684
pkg: apple ipados, apple iphone_os, apple macos

published: Sep 14, 2026

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, macOS Golden Gate 27, macOS Sequoia 15.8. An app may be able to cause unexpected system termination or corrupt kernel memory.
CWE: CWE-416
NVD

HIGH
CVE-2026-82430
CVE-2026-82430
pkg: docker

published: Sep 14, 2026

Description

When launching a Docker or OCI worker, the setuid-root `worker-launcher` first changes ownership of the
entire worker directory to the untrusted topology user, and only afterwards reads and acts on the command
file that the supervisor wrote into that same directory. The file is opened w…

CWE: CWE-367
NVD

HIGH
CVE-2026-82429
CVE-2026-82429
pkg: node

published: Sep 14, 2026

Description

The setuid-root `worker-launcher` binary adjusts ownership and permissions of worker directories by walking
the tree with FTS and calling `lchown` and `chmod` on each entry's full pathname while running with an
effective uid of 0. Both syscalls re-resolve the path at the time of the cal…

CWE: CWE-367
NVD

HIGH
CVE-2026-82427
CVE-2026-82427
pkg: node

published: Sep 14, 2026

Description

A topology's `topology.blobstore.map` lets the submitter choose a local name for each blob that the
supervisor localises. That name was used to build a path under the topology's working directory without
normalisation, in both `AsyncLocalizer` and `Container.createBlobstoreLinks`, and t…

CWE: CWE-22
NVD

HIGH
CVE-2026-61595
CVE-2026-61595
pkg: react

published: Sep 16, 2026

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, `djust.tenants` isolation was enforced only on the HTTP path. The current tenant was stored in `threading.local()` and set exclusively by the HTTP-only `TenantMiddle…
CWE: CWE-636, CWE-862
GitHub-GHSA

HIGH
djust: Multi-tenant isolation fails open on the WebSocket/SSE path, disclosing other tenants' data
GHSA-3492-cvg7-9mr2
pkg: djust
eco: pip
published: Sep 16, 2026
### Impact
`djust.tenants` isolation was enforced only on the HTTP path. The current tenant was stored in `threading.local()` and set exclusively by the HTTP-only `TenantMiddleware`, so on the live (WebSocket/SSE) path `get_current_tenant()` was always `None` during mount and every event handler —…
CVE-2026-61595
NVD

HIGH
CVE-2026-91943
CVE-2026-91943
pkg: python

published: Sep 15, 2026

Crawl4AI before 0.9.3 contains a server-side request forgery vulnerability in PDFContentScrapingStrategy where _get_pdf_path() re-downloads targets with Python requests without egress validation. Authenticated attackers can supply URLs that redirect to internal addresses or use DNS rebinding to acce…
CWE: CWE-918
NVD

HIGH
CVE-2026-54155
CVE-2026-54155
pkg: node

published: Sep 14, 2026

node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the UserNameIdentityToken authentication handler in packages/node-opcua-server/source/opcua_server.ts decrypts an RSA-OAEP password blob but does not verify that the trailing bytes match the current session serverNo…
CWE: CWE-347
NVD

HIGH
CVE-2026-47701
CVE-2026-47701
pkg: kubernetes

published: Sep 14, 2026

The OpenTelemetry Operator is a Kubernetes Operator for the OpenTelemetry Collector. Prior to 0.152.0, cmd/otel-allocator TargetAllocator instances with targetAllocator.prometheusCR.enabled set to true preserve a selected ServiceMonitor endpoint's bearerTokenFile value as HTTPClientConfig.Authorizat…
CWE: CWE-200
GitHub-GHSA

HIGH
Obot: Server-Side Request Forgery via remote MCP server URL
GHSA-jgh3-fggc-mcpm
pkg: github.com/obot-platform/obot
eco: go
published: Sep 18, 2026
## Summary

In affected versions, the URL of a remote MCP server is attacker-controlled at registration and is fetched server-side with no validation of the destination. There is no guard against loopback, link-local, RFC1918 private ranges, or the cloud metadata endpoint (`169.254.169.254`), so a u…

NVD

HIGH
CVE-2026-54506
CVE-2026-54506
pkg: express

published: Sep 17, 2026

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5, app/controller/user/profile.php accepts the user[bio] field and passes stored content through sanitizeHTML() in system/functions.php, whose on* event-handler regular expression o…
CWE: CWE-79, CWE-116, CWE-185
NVD

HIGH
CVE-2026-45726
CVE-2026-45726
pkg: kubernetes

published: Sep 17, 2026

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. From 1.3.0 until 1.6.6 and 1.7.3, importing a standalone Talos cluster creates an ImportedClusterSecrets resource containing the cluster's complete CA secrets bundle. The access rules in internal/backend/runtime/omni/state_acces…
CWE: CWE-200, CWE-522, CWE-732
NVD

HIGH
CVE-2026-93761
CVE-2026-93761
pkg: express

published: Sep 18, 2026

An inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library may allow an unauthenticated party to cause excessive processing within an embedding application process. Applications that place user-supplied text into a pattern-matching query con…
CWE: CWE-1333
GitHub-GHSA

HIGH
io.moquette:moquette-broker has a Missing Authorization issue
GHSA-9jjc-fw8x-fmwx
pkg: io.moquette:moquette-broker
eco: maven
published: Sep 18, 2026
## Summary

Moquette MQTT Broker fails to enforce ACL write permission checks when publishing Will (Last Will and Testament) messages on behalf of disconnected clients. All normal PUBLISH paths (`receivedPublishQos0`, `receivedPublishQos1`, `receivedPublishQos2`) correctly invoke `authorizator.canWr…

CVE-2026-85058
GitHub-GHSA

HIGH
adm-zip: Uncontrolled memory allocation via the declared uncompressed size (DoS)
GHSA-7q85-xj36-vmfc
pkg: adm-zip
eco: npm
published: Sep 18, 2026
### Summary
adm-zip allocates an entry's output buffer from the declared uncompressed size (central-directory `size` field) before validating it against the actual data. A tiny crafted ZIP that declares a huge uncompressed size forces a multi-gigabyte allocation from a few bytes.

### Impact
On adm-…

CVE-2026-77301
GitHub-GHSA

HIGH
LMDeploy has an SSRF bypass
GHSA-39wr-7q6h-cf68
pkg: lmdeploy
eco: pip
published: Sep 18, 2026
### Summary
The URL checking logic in lmdeploy has a logical flaw that could be bypassed by attackers, leading to SSRF attacks.

### Details
The current lmdeploy project uses `_is_safe_url` to validate the input URL. The main logic is to perform security checks on the host portion of the URL extract…

GitHub-GHSA

HIGH
CoreDNS DoH/DoQ/gRPC bypass UPDATE rejection enforced on UDP/TCP
GHSA-9gm5-9rfh-m6vx
pkg: github.com/coredns/coredns
eco: go
published: Sep 17, 2026
### Summary

CoreDNS accepted [RFC 2136](https://datatracker.ietf.org/doc/html/rfc2136) UPDATE messages over DoH, DoH3, DoQ, and DNS-over-gRPC, then allowed the `proxy`/`forward` plugin to send them unchanged to an upstream DNS server. UDP, TCP, and DoT rejected the same opcode before plugin dispatc…

CVE-2026-86003
GitHub-GHSA

HIGH
CoreDNS: Unauthenticated memory exhaustion in custom transports
GHSA-mrg3-qvqr-jw29
pkg: github.com/coredns/coredns
eco: go
published: Sep 17, 2026
### Summary

CoreDNS parses attacker-controlled DNS section counts before validating them on DNS-over-HTTPS (DoH and DoH3), DNS-over-QUIC (DoQ), and DNS-over-gRPC listeners. An unauthenticated client can use DNS name compression to make one
65,533-byte request allocate more than 10 MiB while it is u…

CVE-2026-82399
GitHub-GHSA

HIGH
HAPI FHIR: SHCParser DEFLATE infinite loop causes denial of service
GHSA-gq9c-wmrm-5hvr
pkg: ca.uhn.hapi.fhir:org.hl7.fhir.r5, ca.uhn.hapi.fhir:org.hl7.fhir.validation, ca.uhn.hapi.fhir:org.hl7.fhir.validation.cli
eco: maven
published: Sep 17, 2026
### Summary
A malformed Smart Health Card (SHC) JWT with `zip: "DEF"` and an empty or truncated DEFLATE payload causes `SHCParser.inflate()` to loop forever. This allows an attacker who can submit SHC content for validation to pin a JVM worker thread indefinitely, causing denial of service.

### Det…

CVE-2026-81876
GitHub-GHSA

HIGH
HAPI FHIR: SHCParser unbounded DEFLATE decompression causes denial of service
GHSA-3w98-rrpr-fprr
pkg: ca.uhn.hapi.fhir:org.hl7.fhir.r5, ca.uhn.hapi.fhir:org.hl7.fhir.validation, ca.uhn.hapi.fhir:org.hl7.fhir.validation.cli
eco: maven
published: Sep 17, 2026
### Summary
`SHCParser` inflates compressed Smart Health Card JWT payloads into memory without a decompressed-size limit. An attacker who can submit SHC content for validation can craft a small compressed JWT payload that expands to a very large byte array, causing memory exhaustion or severe garbag…
CVE-2026-81875
GitHub-GHSA

HIGH
Steeltoe.Discovery.Consul: malformed 'secure' metadata aborts service instance lookup (DoS)
GHSA-67c9-f6v2-qv86
pkg: Steeltoe.Discovery.Consul
eco: nuget
published: Sep 17, 2026
## Summary

Steeltoe's Consul discovery client parses the `secure` metadata field on each registered service instance using `bool.Parse`, which throws on any value other than `true` or `false`. A single service instance registered with a malformed `secure` value (for example `yes` or `1`) aborts con…

CVE-2026-81516
GitHub-GHSA

HIGH
Steeltoe.Discovery.Eureka: malformed enum/bool/timestamp field aborts entire registry fetch (DoS)
GHSA-hr73-3gpv-hh6q
pkg: Steeltoe.Discovery.Eureka
eco: nuget
published: Sep 17, 2026
## Summary

Steeltoe's Eureka discovery client deserializes the registry response as a single unit. If any registered instance contains a field value that cannot be parsed (for example, an unrecognized `actionType`, a non-boolean value for `isCoordinatingDiscoveryServer`, or a non-numeric timestamp)…

CVE-2026-81515
NVD

HIGH
CVE-2026-50125
CVE-2026-50125
pkg: kubernetes

published: Sep 17, 2026

MKP is a Model Context Protocol server for Kubernetes. Prior to 0.4.1, cmd/server/main.go exposes the default HTTP endpoint and pkg/mcp/server.go registers the unauthenticated get_resource tool, which accepts attacker-controlled limitBytes and tailLines values for the pods logs subresource. buildPod…
CWE: CWE-400
GitHub-GHSA

HIGH
Fulgur: Non-painting replaced elements amplify to thousands of blank PDF pages (denial of service)
GHSA-4rf6-qx84-q9fv
pkg: fulgur
eco: rust
published: Sep 17, 2026
`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that
processes input supplied by many tenants. In versions prior to 0.26.0, a
childless box that resolves to a pathologically tall height was amplified into
thousands of blank PDF pages, even when it produces no visible output.

The…

CVE-2026-68537
GitHub-GHSA

HIGH
Fulgur: Unbounded page slicing from attacker-controlled CSS height causes denial of service
GHSA-j5cx-ph8g-95v3
pkg: fulgur
eco: rust
published: Sep 17, 2026
`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that
processes input supplied by many tenants. In versions prior to 0.19.0, a
body-direct child whose CSS-resolved height greatly exceeds the page height was
sliced into one fragment per page with **no upper bound**.

The height is …

CVE-2026-68523
GitHub-GHSA

HIGH
libp2p: Gossipsub StrictSign accepts attacker-signed messages as a victim RSA peer ID
GHSA-c3gv-825q-fvmp
pkg: @libp2p/gossipsub
eco: npm
published: Sep 17, 2026
### Summary
`@libp2p/gossipsub` `StrictSign` validation does not bind a supplied message public key to the claimed `from` peer ID when `from` is an RSA-style peer ID that does not inline its public key. An attacker can set `from` to a victim RSA peer ID, sign the message with the attacker's own priv…
CVE-2026-86038
GitHub-GHSA

HIGH
AsyncHttpClient's unbounded HTTP/1.1 response decompression enables a decompression-bomb denial of service
GHSA-7grg-jcf7-rpmx
pkg: org.asynchttpclient:async-http-client, org.asynchttpclient:async-http-client
eco: maven
published: Sep 17, 2026
### Impact
With automatic response decompression enabled (the default), the HTTP/1.1 path decompresses response bodies with no limit on the total output size. A hostile or compromised server, or an attacker who can change a response in transit, can send a small compressed body that inflates without …
CVE-2026-85721
GitHub-GHSA

HIGH
SSH.NET: ScpClient allows server-side RCE via default SCP path handling
GHSA-mggc-4xg6-vcxf
pkg: SSH.NET
eco: nuget
published: Sep 17, 2026
## Summary

Default SCP remote-path handling places caller-supplied paths into the command that runs scp on the server. On a shell-based server that command is interpreted by a shell, so an attacker-influenced path that is not quoted to suit that shell can execute as a command as the authenticated S…

CVE-2026-85756
GitHub-GHSA

HIGH
Skipper has OPA body-authz bypass: truncated_body mitigation fails open on chunked/HTTP-2 (incomplete fix GHSA-8qqm-fp2q-v734)
GHSA-5gpm-rgj3-9q76
pkg: github.com/zalando/skipper
eco: go
published: Sep 17, 2026
– **Affected component:** `filters/openpolicyagent/openpolicyagent.go` → `ExtractHttpBodyOptionally`; combined with `github.com/open-policy-agent/opa-envoy-plugin` `envoyauth/request.go` → `getParsedBody` / `checkIfHTTPBodyTruncated`. Filter: `opaAuthorizeRequestWithBody`.
– **Affected versions:…
CVE-2026-86043
GitHub-GHSA

HIGH
ExifReader: DoS via Crafted HEIC/AVIF iloc Box – Memory Exhaustion
GHSA-pj96-35fp-cfcc
pkg: exifreader
eco: npm
published: Sep 17, 2026
## Summary
ExifReader 4.41.0 is vulnerable to denial of service through a crafted HEIC or AVIF file with a malicious `iloc` box. When `offsetSize`, `lengthSize`, and `baseOffsetSize` are set to zero in the iloc header, the extent-parsing loop allocates an unbounded number of JavaScript objects – up …
CVE-2026-85715
NVD

HIGH
CVE-2026-63460
CVE-2026-63460
pkg: express

published: Sep 17, 2026

Vendure is an open-source headless commerce platform. Prior to 3.6.5, the public Shop GraphQL API allows an unauthenticated caller to supply a catastrophically backtracking pattern through StringOperators.regex. packages/core/src/service/helpers/list-query-builder/parse-filter-params.ts passes the r…
CWE: CWE-1333
GitHub-GHSA

HIGH
Wire: Unauthenticated decoder crash via 32-bit length integer overflow in ByteArrayProtoReader32 (incomplete fix of CVE-2026-45799)
GHSA-9rm7-3qhh-h2mc
pkg: com.squareup.wire:wire-runtime, com.squareup.wire:wire-runtime
eco: maven
published: Sep 17, 2026
Wire's protobuf decoders did not consistently validate attacker-controlled length-delimited sizes against the current reader bounds before computing cursor, limit, or pointer positions.

In the Kotlin runtime, `ProtoAdapter.decode(ByteArray)` and `ProtoAdapter.decode(ByteString)` use the `ProtoReade…

CVE-2026-63126
GitHub-GHSA

HIGH
Vendure: Unauthenticated ReDoS via `regex` filter on SQLite backends
GHSA-jgm3-qmp2-c4p7
pkg: vendure/core
eco: npm
published: Sep 17, 2026
### Summary

> [!IMPORTANT]
> Only instances running on the SQLite driver (better-sqlite3) are affected; SQLite is usually used in development/testing backend, so production deployments on PostgreSQL or MySQL/MariaDB are unaffected.

The `StringOperators.regex` filter exposed on the public Shop Gra…

CVE-2026-63460
NVD

HIGH
CVE-2026-92599
CVE-2026-92599
pkg: express

published: Sep 16, 2026

joi (npm package `joi`, hapi.js) versions >=17.2.0 <17.13.7 and >=18.0.0 <18.2.6 are vulnerable to regular expression denial of service in the `Joi.string().isoDate()` validation rule. One of the regular expressions the rule applies to the input is unanchored, so a valid ISO date followed by a long …
CWE: CWE-1333
GitHub-GHSA

HIGH
RMCP: Unauthenticated permanent session-table leak in rmcp Streamable HTTP server transport leads to remote denial-of-service
GHSA-9pj6-vhgr-3mwh
pkg: rmcp
eco: rust
published: Sep 16, 2026
### Summary

An unauthenticated remote attacker can leak one entry per HTTP request out of the in-memory session table of `LocalSessionManager` by sending a well-formed JSON-RPC `POST` that is *not* an `InitializeRequest`. The Streamable HTTP server's `handle_post` allocates the session **before** i…

CVE-2026-63128
NVD

HIGH
CVE-2026-81876
CVE-2026-81876
pkg: jwt

published: Sep 16, 2026

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.12, SHCParser in org.hl7.fhir.r5/src/main/java/org/hl7/fhir/r5/elementmodel/SHCParser.java can enter an infinite loop while processing attacker-controlled Smart Health Card J…
CWE: CWE-20, CWE-400, CWE-835
NVD

HIGH
CVE-2026-81875
CVE-2026-81875
pkg: jwt

published: Sep 16, 2026

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.12, SHCParser in org.hl7.fhir.r5/src/main/java/org/hl7/fhir/r5/elementmodel/SHCParser.java can consume attacker-controlled Smart Health Card JWT content whose header contains…
CWE: CWE-20, CWE-400, CWE-409
NVD

HIGH
CVE-2026-84997
CVE-2026-84997
pkg: react

published: Sep 16, 2026

react/http is an event-driven, streaming HTTP client and server implementation for ReactPHP. From 0.6.0 until 1.11.1, React\Http\Io\ChunkedDecoder could enter an infinite loop while processing a malformed Transfer-Encoding: chunked body because handleData required its buffer to shrink on every itera…
CWE: CWE-835
NVD

HIGH
CVE-2026-89968
CVE-2026-89968
pkg: node

published: Sep 16, 2026

In the Linux kernel, the following vulnerability has been resolved:

nvmet-tcp: reject unsolicited H2CData PDUs

nvmet_tcp_handle_h2c_data_pdu() accepts an H2CData PDU after only checking
that its TTAG is a valid in-range command index and that the command's
data buffers are mapped. It never checks …

NVD

HIGH
CVE-2026-79993
CVE-2026-79993
pkg: apache zookeeper

published: Sep 16, 2026

The `deleteContainer` opcode (0x14/20) is processed without verifying the caller's ACL permissions, allowing any authenticated client to delete specific znodes in the data tree regardless of the ACL restrictions on the znode or its parent. This opcode is considered internal-only and the official cli…
CWE: CWE-862
NVD

HIGH
CVE-2026-59969
CVE-2026-59969
pkg: apache zookeeper

published: Sep 16, 2026

Apache ZooKeeper quorum TLS fails to enforce peer hostname verification in FIPS-mode deployments. When sslQuorum=true, zookeeper.fips-mode=true, ssl.quorum.hostnameVerification=true, and ssl.quorum.clientHostnameVerification=true are enabled, the Java SSLSocket quorum path accepts a CA-trusted pee…
CWE: CWE-297
NVD

HIGH
CVE-2026-61554
CVE-2026-61554
pkg: linux

published: Sep 15, 2026

emp3r0r is a C2 designed by Linux users for Linux environments. Prior to version 4.2.5, the `http_poll` C2 transport accepts attacker-controlled HTTP polling sessions before CBOR `MsgAuth` authentication is completed. A remote unauthenticated attacker can create arbitrary polling sessions and send r…
CWE: CWE-400
GitHub-GHSA

HIGH
emp3r0r has an unauthenticated HTTP Polling DoS
GHSA-4595-rvpx-4q34
pkg: github.com/jm33-m0/emp3r0r/core
eco: go
published: Sep 15, 2026
### Summary
The `http_poll` C2 transport accepts attacker-controlled HTTP polling sessions before CBOR `MsgAuth` authentication is completed. A remote unauthenticated attacker can create arbitrary polling sessions and send request bodies that are forwarded into the C2 dispatch path. This can consume…
CVE-2026-61554
GitHub-GHSA

HIGH
Http4s: Ember HTTP/2 buffers a frame's declared payload before checking SETTINGS_MAX_FRAME_SIZE
GHSA-gq9p-f254-h286
pkg: org.http4s:http4s-ember-core_2.13, org.http4s:http4s-ember-core_2.12, org.http4s:http4s-ember-core_3
eco: maven
published: Sep 15, 2026
### Summary
An unauthenticated peer can make Ember's HTTP/2 read loop hold 16 MiB of a single frame in memory on a connection where Ember advertised a 16 KiB limit. The declared length is readable from the frame's first 9 bytes, but it is not compared against SETTINGS_MAX_FRAME_SIZE until the whole …
CVE-2026-88975
GitHub-GHSA

HIGH
Http4s Ember HTTP/2: unbounded continuation frame accumulation
GHSA-cp4q-fqw9-4hf6
pkg: org.http4s:http4s-ember-core_2.12, org.http4s:http4s-ember-core_2.13, org.http4s:http4s-ember-core_3
eco: maven
published: Sep 15, 2026
When Ember receives an HTTP/2 `HEADERS` or `PUSH_PROMISE` frame without the `END_HEADERS` flag, it buffers the header block fragment and waits for subsequent `CONTINUATION` frames. These accumulate unbounded until the connection closes.

### Impact

A remote, unauthenticated peer can exhaust the h…

CVE-2026-69218
GitHub-GHSA

HIGH
Http4s Ember HTTP/2 has an unbounded outbound frame queue
GHSA-8f3q-3jmv-7prw
pkg: org.http4s:http4s-ember-core_2.12, org.http4s:http4s-ember-core_2.13, org.http4s:http4s-ember-core_3
eco: maven
published: Sep 15, 2026
Ember's HTTP/2 connection serializes all outgoing frames through a single unbounded queue drained by one writer fiber (`writeLoop`). When the write side stalls, any frames the connection keeps producing accumulate in that queue without limit. The peer can drive this cheaply because the connection …
CVE-2026-69213
GitHub-GHSA

HIGH
Http4s: DigestAuth nonce map grows unbounded
GHSA-fm4g-76c9-7w69
pkg: org.http4s:http4s-ember-server_2.12, org.http4s:http4s-ember-server_2.13, org.http4s:http4s-ember-server_3
eco: maven
published: Sep 15, 2026
The `DigestAuth` server middleware's stale-nonce cleanup uses an inverted comparison: it removes *fresh* nonces and stops at the first *stale* one. Because a new nonce is created for every unauthenticated challenge, an attacker can drive the nonce map to grow without bound until the JVM runs out of…
CVE-2026-69208
GitHub-GHSA

HIGH
Http4s Ember HTTP/2 does not enforce SETTINGS_MAX_CONCURRENT_STREAMS
GHSA-9vwc-pc8p-253q
pkg: org.http4s:http4s-ember-core_2.12, org.http4s:http4s-ember-core_2.13, org.http4s:http4s-ember-core_3
eco: maven
published: Sep 15, 2026
An ember server with HTTP/2 enabled (`.withHttp2`) does not enforce `SETTINGS_MAX_CONCURRENT_STREAMS` on streams opened by the peer. A single unauthenticated connection can open an unbounded number of concurrent streams, each of which allocates per-stream server state that is never released, exhaus…
CVE-2026-69203
GitHub-GHSA

HIGH
Http4s Ember HTTP/2: unbounded inbound body buffering
GHSA-6m4x-pp6q-5jmm
pkg: org.http4s:http4s-ember-core_2.12, org.http4s:http4s-ember-core_2.13, org.http4s:http4s-ember-core_3
eco: maven
published: Sep 15, 2026
Ember's HTTP/2 stack replenishes the inbound flow-control window based on bytes
received off the wire, not bytes consumed by the application. Received DATA is buffered in an unbounded per-stream channel. Flow control therefore
provides no backpressure: a peer can stream a large or unbounded body f…
CVE-2026-69202
NVD

HIGH
CVE-2026-58483
CVE-2026-58483
pkg: node

published: Sep 15, 2026

mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.7.1, web_url_read in src/index.ts passes a caller-supplied URL to readUrlContent() in src/url-reader.ts, where checkContentLength() treats a missing Content-Len…
CWE: CWE-400
NVD

HIGH
CVE-2026-55149
CVE-2026-55149
pkg: nginx

published: Sep 15, 2026

Vouch Proxy is an SSO and OAuth/OIDC login solution for Nginx using the auth_request module. Prior to 0.48.0, Cookie in pkg/cookie/cookie.go parses the total part count from an attacker-controlled multipart cookie name and passes the value to make([]string, numParts) without checking that the value …
CWE: CWE-789
NVD

HIGH
CVE-2026-91985
CVE-2026-91985
pkg: jwt

published: Sep 15, 2026

Vikunja before 2.6.0 fails to properly restrict access to the link-share hash field in single-share read endpoints, allowing read-only members to obtain the share's secret credential. Attackers can exchange the disclosed hash for a link-share JWT at the share's permission level to escalate privilege…
CWE: CWE-200
NVD

HIGH
CVE-2026-91972
CVE-2026-91972
pkg: oauth

published: Sep 15, 2026

Vikunja versions before 2.6.0 fail to apply rate limiting to /api/v2 public authentication endpoints including login, register, password-reset, and OAuth token routes. Remote unauthenticated attackers can perform unbounded credential guessing, account enumeration, and password-reset flooding attacks…
CWE: CWE-307
NVD

HIGH
CVE-2026-91937
CVE-2026-91937
pkg: node

published: Sep 15, 2026

Flowise before 3.1.4 fails to sanitize the overrideConfig.sessionId parameter before using it in MongoDB queries within the MongoDBMemory node. Unauthenticated attackers can submit MongoDB operator objects through the prediction API to read chat history records belonging to other users from the shar…
CWE: CWE-943
NVD

HIGH
CVE-2026-65342
CVE-2026-65342
pkg: apple macos

published: Sep 14, 2026

A permissions issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access sensitive user data.
CWE: CWE-862, CWE-862
NVD

HIGH
CVE-2026-43789
CVE-2026-43789
pkg: apple macos

published: Sep 14, 2026

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access user-sensitive data.
CWE: CWE-862, CWE-862
NVD

HIGH
CVE-2026-90946
CVE-2026-90946
pkg: python

published: Sep 14, 2026

DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerability in the unauthenticated /ws/chat WebSocket endpoint that accepts repo_url as a filesystem path with no containment. Attackers can supply arbitrary directory paths to read all files with supported extensions including P…
CWE: CWE-73
NVD

HIGH
CVE-2026-54156
CVE-2026-54156
pkg: node

published: Sep 14, 2026

node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the process-global g_alreadyUsedNonce cache used by nonceAlreadyBeenUsed in packages/node-opcua-secure-channel/source/server/server_secure_channel_layer.ts records nonces from OpenSecureChannelRequest and CreateSess…
CWE: CWE-770
NVD

HIGH
CVE-2026-73178
CVE-2026-73178
pkg: jwt

published: Sep 14, 2026

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Syncope.

An administrator with adequate entitlements can get access via REST to the list of existing Access Tokens, including their signed JWT body.
These values can be then used to perform further REST requests, imp…

CWE: CWE-200
NVD

HIGH
CVE-2026-84975
CVE-2026-84975
pkg: tls

published: Sep 18, 2026

PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the OpenSSL and GnuTLS backends in pjlib/src/pj/ssl_sock_ossl.c and pjlib/src/pj/ssl_sock_gtls.c copy DNS SubjectAltName values with string functions that recalculate their length and truncate an embe…
CWE: CWE-295, CWE-297
NVD

HIGH
CVE-2026-90997
CVE-2026-90997
pkg: jwt

published: Sep 17, 2026

A flaw was found in Keycloak. When deployed in stateless mode with MySQL or MariaDB, a mismatch in row-count semantics between the database driver and Keycloak's application logic allows an attacker to bypass replay protection. This vulnerability enables an attacker who intercepts single-use securit…
CWE: CWE-294
NVD

HIGH
CVE-2026-61592
CVE-2026-61592
pkg: react

published: Sep 16, 2026

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, SSE sessions were keyed solely by a client-chosen `session_id` with no binding to the authenticated user — a control the WebSocket transport has but that was dropp…
CWE: CWE-384, CWE-639, CWE-862
GitHub-GHSA

HIGH
djust: SSE sessions are not bound to the authenticated user; the client-chosen session_id is the sole authorization capability (session hijack)
GHSA-f795-p5jw-j6g2
pkg: djust
eco: pip
published: Sep 16, 2026
### Impact
SSE sessions were keyed solely by a **client-chosen** `session_id` with no binding to the authenticated user — a control the WebSocket transport has but that was dropped on SSE. An attacker who learns (or a victim who leaks) a `session_id` could connect to the message endpoint and dispa…
CVE-2026-61592
NVD

HIGH
CVE-2026-61590
CVE-2026-61590
pkg: react

published: Sep 16, 2026

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, djust's observability endpoints expose live view/session state and a remote method-invocation surface (`eval_handler`). The localhost restriction was an opt-in middl…
CWE: CWE-306, CWE-668
GitHub-GHSA

HIGH
djust's observability endpoints are network-exposed: the localhost gate is an opt-in middleware the docs omit, and the views enforce only DEBUG
GHSA-8g2f-g3gq-5rjv
pkg: djust
eco: pip
published: Sep 16, 2026
### Impact
djust's observability endpoints expose live view/session state and a remote method-invocation surface (`eval_handler`). The localhost restriction was an **opt-in middleware that the documented setup omits**; the views themselves enforced only `DEBUG`. In the misconfigured-but-documented s…
CVE-2026-61590
NVD

HIGH
CVE-2026-92299
CVE-2026-92299
pkg: windows

published: Sep 16, 2026

@jitsi/electron-sdk before 10.0.5 exposes getDesktopSources() via contextBridge without requiring an active getDisplayMedia() picker, allowing any script in the meeting page to enumerate screens and windows. Attackers can call the jitsi-screen-sharing-get-sources IPC route to retrieve desktop thumbn…
CWE: CWE-862
NVD

HIGH
CVE-2026-91734
CVE-2026-91734
pkg: google chrome, microsoft windows

published: Sep 15, 2026

Incorrect authorization in Core in Google Chrome on on Windows prior to 153.0.8010.47 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
CWE: CWE-863
NVD

HIGH
CVE-2026-87242
CVE-2026-87242
pkg: tls

published: Sep 15, 2026

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Hyperion Financia…
CWE: CWE-284
NVD

HIGH
CVE-2026-87195
CVE-2026-87195
pkg: tls

published: Sep 15, 2026

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Hyperion Financia…
CWE: CWE-306
NVD

HIGH
CVE-2026-53714
CVE-2026-53714
pkg: tls

published: Sep 14, 2026

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, the xDS gRPC server in GatewayNamespaceMode, configured through provider.kubernetes.deploy.type=GatewayNamespace, installs a JWT StreamInterceptor but n…
CWE: CWE-306
NVD

HIGH
CVE-2026-7006
CVE-2026-7006
pkg: windows

published: Sep 18, 2026

Sublime Text for Windows through Build 4192 (Sublime Text 4) and Build 3207 (Sublime Text 3) contains a local privilege escalation vulnerability that allows unprivileged local attackers to execute arbitrary code with elevated privileges by abusing the update staging mechanism. Attackers can place a …
CWE: CWE-494
NVD

HIGH
CVE-2026-64752
CVE-2026-64752
pkg: apple ipados, apple iphone_os, apple macos

published: Sep 14, 2026

A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. Processing a maliciously crafted image may lead to arbitrary code execution.
CWE: CWE-787
NVD

HIGH
CVE-2026-81895
CVE-2026-81895
pkg: concretecms concrete_cms

published: Sep 15, 2026

In Concrete CMS before 9.5.3, the Document Library block stored the file-set identifiers submitted through fsID[] without validating them as integers, and when the block was configured with setMode set to any it concatenated each stored identifier directly into the file-set filter query instead of c…
CWE: CWE-89
NVD

HIGH
CVE-2026-61672
CVE-2026-61672
pkg: kubernetes

published: Sep 18, 2026

Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.7, ForbiddenListSpec.ExactMatch in pkg/api/forbidden_list.go sorts denied metadata keys case-insensitively and then uses sort.SearchStrings, which assumes byte-order sorting. When an administrator's forbidden list mi…
CWE: CWE-697, CWE-863
GitHub-GHSA

HIGH
Capsule: Tenant owner bypasses Capsule's forbidden namespace/service/node label and annotation enforcement
GHSA-gjw4-3v3v-rqxg
pkg: github.com/projectcapsule/capsule
eco: go
published: Sep 18, 2026
## Summary

Capsule lets a cluster administrator forbid specific metadata keys that tenant owners must not place on their own resources: `Tenant.spec.namespaceOptions.forbiddenLabels` / `forbiddenAnnotations` (namespaces), `Tenant.spec.serviceOptions.forbiddenLabels` / `forbiddenAnnotations` (Servic…

CVE-2026-61672
GitHub-GHSA

HIGH
Jupyter Server: 5xx request logging leaks token-bearing Referer header values
GHSA-c3mw-737p-c7g2
pkg: jupyter_server
eco: pip
published: Sep 17, 2026
### Summary

When a request returns a 500, `jupyter_server/log.py` logs a small JSON block of request headers.

The Referer header was copied into it as-is, so a token in the Referer URL ended up in the logs in plain text.

### Impact

Anyone who can read the server logs can pick tokens out of thes…

CVE-2026-86049
NVD

HIGH
CVE-2026-61596
CVE-2026-61596
pkg: react

published: Sep 16, 2026

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, djust's per-object authorization (`get_object` + `has_object_permission`, ADR-017) was enforced on the WebSocket mount and event paths but not on three other render …
CWE: CWE-639, CWE-862
GitHub-GHSA

HIGH
djust has broken object-level access control (IDOR)
GHSA-c7c5-5j6r-q957
pkg: djust
eco: pip
published: Sep 16, 2026
### Impact
djust's per-object authorization (`get_object` + `has_object_permission`, ADR-017) was enforced on the WebSocket **mount** and **event** paths but **not** on three other render entry points: (a) the initial **HTTP GET** render, (b) **SPA `url_change`** navigation, and (c) `{% live_render …
CVE-2026-61596
NVD

HIGH
CVE-2026-89927
CVE-2026-89927
pkg: express

published: Sep 16, 2026

In the Linux kernel, the following vulnerability has been resolved:

KVM: x86: hyper-v: Clamp stimer deadline to avoid livelock

Fix an issue where userspace or the guest can program an Hyper-V
synthetic timer to have a deadline in the past via integer overflow,
preventing the CPU from making progre…

NVD

HIGH
CVE-2026-89818
CVE-2026-89818
pkg: express

published: Sep 16, 2026

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu/vcn: fix integer overflow in dec_msg buffer count check

If the supplied msg[2] (num_buffers) is 0x3FFFFFFF, the expression
6 + num_buffers * 4 wraps to 2 and the bounds check passes, letting
the parser loop far past the…

NVD

HIGH
CVE-2026-89792
CVE-2026-89792
pkg: linux

published: Sep 16, 2026

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: prevent out-of-bounds reads in share config responses

Validate IPC share configuration payload sizes before consuming
variable-length fields. Bound veto list parsing and account for
the separator byte when deriving the path…

NVD

HIGH
CVE-2026-91938
CVE-2026-91938
pkg: node

published: Sep 15, 2026

Flowise versions before 3.1.4 contain a server-side request forgery vulnerability in Cheerio, Playwright, and Puppeteer document loader nodes that bypass SSRF protection. Attackers can provide arbitrary URLs to fetch cloud metadata, internal services, and private network resources with response cont…
CWE: CWE-918
NVD

HIGH
CVE-2026-91145
CVE-2026-91145
pkg: express

published: Sep 14, 2026

Activiti through 7.1.0.M6 fails to validate hash-brace deferred expressions in process variables, allowing attackers to bypass expression filtering. Attackers can inject expressions beginning with #{ that are stored and later evaluated in the full Spring context when a mail task uses variable-backed…
CWE: CWE-917
NVD

HIGH
CVE-2026-43697
CVE-2026-43697
pkg: apple macos

published: Sep 14, 2026

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Processing a maliciously crafted 3D file may lead to an out-of-bounds read.
CWE: CWE-125, CWE-125
NVD

HIGH
CVE-2026-43683
CVE-2026-43683
pkg: apple macos

published: Sep 14, 2026

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause unexpected process termination or disclose process memory.
CWE: CWE-125
NVD

HIGH
CVE-2026-20683
CVE-2026-20683
pkg: apple ipados, apple iphone_os, apple macos

published: Sep 14, 2026

An authentication issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27. An app may be able to use the Sign In With Apple authentication flow to access the user's Apple Account.
CWE: CWE-287
NVD

HIGH
CVE-2026-57223
CVE-2026-57223
pkg: windows

published: Sep 18, 2026

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, the Windows service installation and parameter-update logic in src/win32-service.c can pass an unquoted service ImagePath to CreateServiceA. When Suricata …
CWE: CWE-428
NVD

HIGH
CVE-2026-45720
CVE-2026-45720
pkg: kubernetes

published: Sep 17, 2026

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and from 1.7.0 until 1.7.3, SAML.getSession in internal/pkg/auth/interceptor/saml.go checks SAMLAssertion.Used and marks it used in separate state operations. Concurrent requests carrying the same captured saml-se…
CWE: CWE-294, CWE-367
GitHub-GHSA

HIGH
node-opcua: TCP Socket Leak (FIN-WAIT-2) via keepalive reconnection cycle – Resource Exhaustion
GHSA-r2pf-9cw4-5j65
pkg: node-opcua-transport, node-opcua-client, node-opcua
eco: npm
published: Sep 16, 2026
SUMMARY
——-
A combination of bugs in node-opcua causes unlimited TCP socket accumulation (FIN-WAIT-2 state) during automatic reconnection, leading to memory exhaustion and eventual container/process crash (OOM kill). The issue is triggered by the default configuration (keepSessionAlive: true) wh…
CVE-2026-68904
GitHub-GHSA

HIGH
OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS
GHSA-v8pv-4842-x354
pkg: OpenTelemetry.Resources.Host
eco: nuget
published: Sep 16, 2026
### Summary

The `OpenTelemetry.Resources.Host` NuGet package is affected by an untrusted search path vulnerability on macOS. The `host.id` resource attribute detector launches the `sh` and `ioreg` executables by bare name rather than by absolute path, so both are resolved
through the `PATH` environ…

CVE-2026-81192
NVD

HIGH
CVE-2026-12150
CVE-2026-12150
pkg: tls

published: Sep 15, 2026

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow a remote attacker with a trusted TLS client certificate to cause a denial of service and pot…
CWE: CWE-121
GitHub-GHSA

HIGH
Perses's unvalidated project parameter enables filesystem path traversal
GHSA-vr5f-w35q-98jp
pkg: github.com/perses/perses
eco: go
published: Sep 18, 2026
### Impact
When Perses is using the file system database, on the list endpoints, the project value is bound from the request into the resource `Query` struct and is never validated against directory-traversal characters (validation/Flatten only runs for Create/Update bodies, not list queries).

Th…

CVE-2026-63445
GitHub-GHSA

HIGH
Perses's missing authorization in datasource proxy allows cross-scope secret disclosure
GHSA-4227-9989-jrhx
pkg: github.com/perses/perses
eco: go
published: Sep 18, 2026
### Impact

The datasource proxy authorizes the caller on the Datasource scope, then resolves and decrypts any Secret named in the request body with no Secret-scope check.

Datasource and Secret are distinct, independently grantable role scopes, so an operator can grant datasource access without sec…

CVE-2026-63199
GitHub-GHSA

HIGH
Perses's project query parameter authorization bypass exposes cross-project resources
GHSA-cjgj-2fwf-4c2w
pkg: github.com/perses/perses
eco: go
published: Sep 18, 2026
### Impact
_What kind of vulnerability is it?_

An authenticated user who is only a viewer on project team-a requests GET /api/v1/projects/team-a/dashboards?project=finance-secret (or simply GET /api/v1/datasources?project=finance-secret) and receives the full list of the finance-secret project's da…

CVE-2026-63458
GitHub-GHSA

HIGH
Convoy: Cross-Tenant Source IDOR Leaks Plaintext Message Broker Credentials
GHSA-p5vg-v7mj-f6q4
pkg: github.com/frain-dev/convoy
eco: go
published: Sep 18, 2026
## Summary
frain-dev/convoy (all versions up to and including v26.6.2, no patch
available) lets any authenticated caller who is authorized on at least one
project read ANY OTHER project's "Source" record by ID via
GET /api/v1/projects/{projectID}/sources/{sourceID} — regardless of whether
that Sour…
CVE-2026-81505
GitHub-GHSA

HIGH
AnyIO run_process/open_process ignores extra_groups and can retain parent supplementary groups
GHSA-3w57-8xmc-8v26
pkg: anyio
eco: pip
published: Sep 18, 2026
AnyIO 4.14.0 accepts the POSIX extra_groups argument on anyio.run_process() and anyio.open_process(), but open_process() forwards the wrong variable to the backend: when extra_groups is not None, it assigns kwargs["extra_groups"] = group instead of extra_groups. As a result, callers cannot reliably …
CVE-2026-63349
GitHub-GHSA

HIGH
djust: A template binding inherits a context safety grant it never earned (XSS)
GHSA-xjw9-38cr-6372
pkg: djust
eco: pip
published: Sep 17, 2026
A context safety grant was inherited by a template **binding** that never earned it, so rebinding a name the view had marked safe left the mark attached to the new, attacker-controlled value.

djust's context safety channel is keyed by **name**, not by value. Every bind copied the value and left the…

GitHub-GHSA

HIGH
djust: Six template-layer defects emit attacker-controlled markup unescaped (XSS)
GHSA-9395-2g46-rj3f
pkg: djust
eco: pip
published: Sep 17, 2026
Five independent defects in djust's template auto-escaping cause attacker-controlled input to be rendered as live markup where Django escapes it. All four are present in shipped 1.1.0 and are fixed in 1.1.1.

They share one shape: **a filter or grant that escapes nothing itself and relies on the ren…

GitHub-GHSA

HIGH
RabbitMQ amqp091-go: Denial of Service via Malicious Field Length in AMQP Client
GHSA-4v58-74mf-rjx3
pkg: github.com/rabbitmq/amqp091-go
eco: go
published: Sep 17, 2026
**Summary**
A vulnerability in the readField function allows a malicious or compromised AMQP server to trigger an unhandled runtime panic in the client application, leading to an immediate crash of the entire process.

**Details**
When parsing incoming AMQP frames, the `readField` function processes…

CVE-2026-77412
GitHub-GHSA

HIGH
RabbitMQ amqp091-go: Resource Exhaustion (OOM) via Unbounded Body Buffer Allocation
GHSA-r9c8-gcjp-xfwh
pkg: github.com/rabbitmq/amqp091-go
eco: go
published: Sep 17, 2026
**Summary**
A flaw in the `recvContent` function allows a malicious AMQP server to trigger an Out-of-Memory (OOM) error, forcing the host operating system or container runtime to immediately terminate the client process.

**Vulnerability Details**
When receiving message content payloads, the client …

CVE-2026-77410
GitHub-GHSA

HIGH
RabbitMQ amqp091-go: Plaintext Credential Exposure via Exported PLAIN Authentication Struct Fields
GHSA-27gv-rfvv-22mv
pkg: github.com/rabbitmq/amqp091-go
eco: go
published: Sep 17, 2026
## Summary
An information disclosure vulnerability exists in the AMQP client implementation's authentication handling configuration. Following a successful connection handshake, the `Connection.Config.SASL` field stores the `Authentication` implementation state used to establish the session.

For s…

CVE-2026-77407
GitHub-GHSA

HIGH
RabbitMQ amqp091-go: Consumer Message Flooding via Signed-to-Unsigned Integer Casting in Qos Configuration
GHSA-rm6m-hrcw-jw33
pkg: github.com/rabbitmq/amqp091-go
eco: go
published: Sep 17, 2026
## Summary
A logic and resource exhaustion vulnerability exists in the AMQP client's Quality of Service (`Qos`) configuration method. The `Qos` function accepts signed integers (`int`) for the `prefetchCount` and `prefetchSize` parameters but casts them directly to unsigned integers (`uint16` and `u…
CVE-2026-77406
GitHub-GHSA

HIGH
RabbitMQ amqp091-go: Connection Configuration Overwrite via Unsanitized TLS Path Parameter Injection
GHSA-465g-fh3v-9jw4
pkg: github.com/rabbitmq/amqp091-go
eco: go
published: Sep 17, 2026
## Summary
A query parameter injection vulnerability exists in the AMQP client's connection URI formatting logic. When generating or parsing connection URIs, TLS-related filesystem paths (such as certificates or keys) are appended directly to the URI's query string using string concatenation rather …
CVE-2026-77404
GitHub-GHSA

HIGH
RabbitMQ amqp091-go: Denial of Service via Sub-Spec Frame Size Negotiation
GHSA-xwwf-m8fg-p9q2
pkg: github.com/rabbitmq/amqp091-go
eco: go
published: Sep 17, 2026
## Summary
A Denial of Service (DoS) vulnerability exists in the AMQP client's connection negotiation logic. The AMQP specification explicitly mandates a strict minimum frame size of 4096 bytes to prevent pathological packet fragmentation. While the library defines a `frameMinSize = 4096` constant, …
CVE-2026-77403
GitHub-GHSA

HIGH
Umbraco: Delivery API leaks protected (Public Access) content through Content Picker / Multi-Node Tree Picker expansion
GHSA-wr57-hqmp-fgvh
pkg: Umbraco.Cms, Umbraco.Cms, Umbraco.Cms
eco: nuget
published: Sep 17, 2026
The Content Delivery API enforces member / Public Access protection only at the controller layer, against the node that is directly requested. When a public (unprotected) node references a protected node through a Content Picker or Multi-Node Tree Picker (including those nested inside Block List, Bl…
CVE-2026-69197
GitHub-GHSA

HIGH
Pocketbase: Unhandled panic in worker goroutines
GHSA-84vh-m24q-wjjx
pkg: github.com/pocketbase/pocketbase, github.com/pocketbase/pocketbase
eco: go
published: Sep 17, 2026
PocketBase already has builtin panic-recover middleware for the regular requests handling but it doesn't cover panics in internal child/worker goroutines which in some situations could cause termination of the server process.

To prevent this from hapenning all existing internal worker functions wer…

CVE-2026-82410
GitHub-GHSA

HIGH
RabbitMQ Java client has frame-level OOM: Math.min(maxInboundMessageBodySize, 0) defeats frame size enforcement
GHSA-jh4v-gfqj-7rhx
pkg: com.rabbitmq:amqp-client
eco: maven
published: Sep 17, 2026
## Vulnerability

In `AMQConnection.java` (line 435-436), after `Connection.Tune` negotiation, the frame-max limit is set via:

“`java
_frameHandler.setFrameMax(
Math.min(this.maxInboundMessageBodySize, frameMax));
“`

When `frameMax = 0` (meaning "unlimited" per AMQP spec), `Math.min(67108864…

CVE-2026-75516
GitHub-GHSA

HIGH
@cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized –workspace Argument on Windows
GHSA-q69g-4hcv-6jg4
pkg: @cyclonedx/cyclonedx-npm
eco: npm
published: Sep 17, 2026
## Summary

A **Windows-specific** command injection vulnerability exists in `@cyclonedx/cyclonedx-npm` when the CLI is invoked with the `–workspace <value>` option.
User-supplied `–workspace` values can be passed to a shell command without proper neutralization on the Windows fallback execution…

CVE-2026-71538
GitHub-GHSA

HIGH
djust has an unauthenticated arbitrary module import via the WebSocket/SSE view-mount path
GHSA-7prp-2623-8g45
pkg: djust
eco: pip
published: Sep 16, 2026
### Impact
The djust live transport resolves the LiveView to mount from a **client-supplied dotted path** by calling `__import__(module_path, …)`. The module is imported — running its **top-level code (import side effects)** — *before* the framework checks that the resolved object is a `LiveVi…
CVE-2026-61599
GitHub-GHSA

HIGH
djust: Client mass-assignment of arbitrary view attributes via the default dj-model update_model handler
GHSA-cc7c-9jff-58wj
pkg: djust
eco: pip
published: Sep 16, 2026
### Impact
`djust.mixins.model_binding.ModelBindingMixin` provides a default `update_model` event handler and is part of the **LiveView base MRO**, so every LiveView exposes it. It `setattr`s a view attribute whose **name is client-supplied** (`field`), gated only by: reject `_`-prefixed names; reje…
CVE-2026-61598
GitHub-GHSA

HIGH
libp2p-quic: Remote panic via certificate expiry race during QUIC handshake
GHSA-5hq8-qhww-jm7q
pkg: libp2p-quic
eco: rust
published: Sep 15, 2026
### Summary

`libp2p-quic` can panic on an inbound QUIC handshake if a malicious peer presents a valid, short lived libp2p TLS certificate and delays the final TLS 1.3 handshake fragment until the certificate expires.

This is remotely reachable by a network peer and can crash applications exposing …

CVE-2026-61544
NVD

MEDIUM
CVE-2026-61722
CVE-2026-61722
pkg: express

published: Sep 18, 2026

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS parser validates articulation chunks using the unsigned expression cbsize + connblocks * 12 without first ensuring that the multiplication and addition fit in 32 bits. A crafted DLS f…
CWE: CWE-190
NVD

MEDIUM
CVE-2026-61795
CVE-2026-61795
pkg: kubernetes

published: Sep 18, 2026

Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.7, hostnameRegexHandler.OnUpdate in internal/webhook/tenant/validation/hostname_regex.go reverses the new and old Tenant parameters and validates the previous AllowedHostnames.Regex instead of the submitted …
CWE: CWE-697
NVD

MEDIUM
CVE-2026-61794
CVE-2026-61794
pkg: express

published: Sep 18, 2026

Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.7, the Tenant update validation in internal/webhook/tenant/validation/forbidden_annotations_regex.go compiles ForbiddenLabels.Regex for both the labels and annotations checks instead of validating ForbiddenA…
CWE: CWE-20
GitHub-GHSA

MEDIUM
Capsule: hostnameRegexHandler.OnUpdate validates stale (old) Tenant regex, allowing invalid AllowedHostnames regex to bypass webhook validation
GHSA-f94q-w3w8-cj67
pkg: github.com/projectcapsule/capsule
eco: go
published: Sep 18, 2026
### Summary

A parameter order bug in `internal/webhook/tenant/validation/hostname_regex.go` causes the `hostnameRegexHandler.OnUpdate` webhook to validate the **old** Tenant object's `AllowedHostnames.Regex` instead of the **new** one being submitted. This allows an invalid (malformed) regex to byp…

CVE-2026-61795
NVD

MEDIUM
CVE-2026-75883
CVE-2026-75883
pkg: tls

published: Sep 18, 2026

The code in pppd that formats a response to a PEAP Request packet in peap_response() copies an entire TLS record of up to 16384 bytes into the fixed global buffer outpacket_buf
without checking the available space and without implementing outgoing
PEAP fragmentation. Thus a pppd process connecting…
CWE: CWE-122
GitHub-GHSA

MEDIUM
AsyncHttpClient re-sends client-wide realm credentials to a cross-origin redirect target
GHSA-f8m2-889x-vw4x
pkg: org.asynchttpclient:async-http-client, org.asynchttpclient:async-http-client
eco: maven
published: Sep 17, 2026
### Impact
A client configured with a client-wide realm (a Realm set on the config builder rather than on an individual request) and following redirects could re-send those credentials to a redirect target on a different origin. The redirect code strips the per-exchange realm, but when the target an…
CVE-2026-85717
GitHub-GHSA

MEDIUM
Zope AccessControl vulnerable to information disclosure through Python string `format` and `format_map` functions
GHSA-pq59-9fq7-m886
pkg: AccessControl
eco: pip
published: Sep 17, 2026
### Impact
Python's string `format` functionality allows someone controlling the format string to "read" objects accessible (recursively) via attribute access and subscription from accessible objects. Those attribute accesses and subscriptions use Python's full blown `getattr` and `getitem`, not the…
CVE-2026-77401
GitHub-GHSA

MEDIUM
RMCP: Custom HTTP headers leak to cross-origin redirect targets
GHSA-9g45-5xwm-f3wc
pkg: rmcp
eco: rust
published: Sep 17, 2026
## Summary

The `rmcp` crate's `StreamableHttpClientTransport` forwards caller-supplied custom HTTP headers (such as `X-API-Key`, `X-Auth-Token`, `Api-Key`) to cross-origin redirect targets. The `default_http_client()` function builds a `reqwest::Client` without a redirect policy override, so the de…

CVE-2026-64684
NVD

MEDIUM
CVE-2026-77401
CVE-2026-77401
pkg: python

published: Sep 16, 2026

Zope AccessControl provides a general security framework for use in Zope. Prior to 7.4, applications that allow untrusted users to create and execute AccessControl-controlled Python code do not safely guard str.format and str.format_map when those methods are reached through a str subclass. In both …
CWE: CWE-693
GitHub-GHSA

MEDIUM
Http4s: CookieJar middleware matches by substring, leaking cookies cross-origin
GHSA-grh8-3p95-f9rr
pkg: org.http4s:http4s-client_2.12, org.http4s:http4s-client_2.13, org.http4s:http4s-client_3
eco: maven
published: Sep 15, 2026
The `CookieJar` client middleware decides whether to attach a cookie to an outgoing request using an unanchored substring test on the host and path, instead of the domain match specified by RFC6265 5.1.3. A cookie stored for `example.com` is therefore sent to any host whose name merely contains `ex…
CVE-2026-69215
GitHub-GHSA

MEDIUM
Http4s: CookieJar middleware accepts arbitrary Set-Cookie domain
GHSA-wv64-j4fq-5f9x
pkg: org.http4s:http4s-client_2.12, org.http4s:http4s-client_2.13, org.http4s:http4s-client_2.13
eco: maven
published: Sep 15, 2026
When processing a `Set-Cookie` from a response, the `CookieJar` client middleware trusts the server-supplied `Domain` attribute verbatim, with no check that it domain-matches the host that sent the cookie (RFC6265 §5.3 step 6) and no public suffix check. A malicious or compromised server can there…
CVE-2026-69214
NVD

MEDIUM
CVE-2026-91936
CVE-2026-91936
pkg: docker

published: Sep 15, 2026

Flowise versions before 3.1.4 contain a script injection vulnerability in Docker image build workflows where workflow_dispatch inputs are directly interpolated into shell run blocks. Attackers with repository write access can inject shell metacharacters through inputs like tag_version and node_versi…
CWE: CWE-78
NVD

MEDIUM
CVE-2026-55837
CVE-2026-55837
pkg: oauth

published: Sep 14, 2026

dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.20.0, the local OAuth helper in src/dbt_mcp/oauth/fastapi_app.py exposes GET /dbt_platform_context without authentication or Host validation after a user completes the dbt Platform OAuth flow. The endpoint returns the fu…
CWE: CWE-200, CWE-306, CWE-346
NVD

MEDIUM
CVE-2025-24890
CVE-2025-24890
pkg: windows

published: Sep 14, 2026

gitoxide is an implementation of git written in Rust. Prior to 0.13.3, the gix-sec crate on Windows incorrectly treats repositories controlled by another user as trusted when an administrator runs a dependent program with an unfiltered elevated token. In gix-sec/src/identity.rs, gix_sec::identity::i…
CWE: CWE-283
NVD

MEDIUM
CVE-2026-12985
CVE-2026-12985
pkg: oauth

published: Sep 14, 2026

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 Mattermost failed to validate Dynamic Client Registration redirect URIs by URL component (matching glob patterns against the raw URI string instead) which allows a remote unauthenticated attacker to register an OAuth client wit…
CWE: CWE-601
NVD

MEDIUM
CVE-2026-92615
CVE-2026-92615
pkg: tls

published: Sep 16, 2026

A flaw was found in flightctl. The configureRepoHTTPSClient() function in the device-render worker builds a per-repository tls.Config (which may include InsecureSkipVerify, a custom CA bundle, or tenant-supplied mTLS client certificates) and installs it into go-git's process-global client.Protocols …
CWE: CWE-413
NVD

MEDIUM
CVE-2026-43788
CVE-2026-43788
pkg: apple macos

published: Sep 14, 2026

An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27. Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents.
CWE: CWE-190
NVD

MEDIUM
CVE-2026-93737
CVE-2026-93737
pkg: express

published: Sep 18, 2026

Azkaban through 4.0.0 omits project permission checks in the ScheduleServlet fetchSchedule action, allowing authenticated users to read any project's schedule configuration. Attackers can supply arbitrary project and flow identifiers to retrieve sensitive schedule details including execution times, …
CWE: CWE-862
GitHub-GHSA

MEDIUM
Caddy: rewrite placeholder re-expansion, unbounded body buffer DoS, and fileHidden case-sensitivity bypass
GHSA-j8px-rmrx-76h9
pkg: github.com/caddyserver/caddy/v2
eco: go
published: Sep 18, 2026
# Caddy v2.11.3 — Three vulnerabilities in handler/placeholder layer

**Tested against:** `caddy:2.11.3` (official Docker image, SHA verified at runtime)
**Reproduction environment:** Docker Desktop 4.73.1 / Engine 29.4.3 on Windows 10 host, isolated containers, no network egress required for any …

CVE-2026-77281
NVD

MEDIUM
CVE-2026-77281
CVE-2026-77281
pkg: tls

published: Sep 17, 2026

Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, three configuration-dependent weaknesses affect the handler and placeholder layer. In modules/caddyhttp/rewrite/rewrite.go, Rewrite.Rewrite() can pass attacker-controlled replacement bytes through buildQu…
CWE: CWE-94, CWE-178, CWE-770
GitHub-GHSA

MEDIUM
Steeltoe: Header-forwarded client cert lacks proof of private-key possession
GHSA-5mq7-rwhj-4fh9
pkg: Steeltoe.Security.Authorization.Certificate
eco: nuget
published: Sep 17, 2026
### Summary

When Steeltoe's certificate-based authorization (`UseCertificateAuthorization`) is configured, the default configuration of the middleware relies on the `X-Client-Cert` HTTP header to identify the client certificate, without verifying private-key possession. This header is not stripped …

CVE-2026-81868
NVD

MEDIUM
CVE-2026-44235
CVE-2026-44235
pkg: tls

published: Sep 17, 2026

rabbitmq-c is a C-language AMQP client library for RabbitMQ. Prior to 0.16.0, a malicious AMQP server can send an undersized HEADER or METHOD frame during client login and cause unsigned size_t underflow in amqp_handle_input() in librabbitmq/amqp_connection.c. The parser subtracts HEADER_SIZE, fixed…
CWE: CWE-125, CWE-191
GitHub-GHSA

MEDIUM
Kestra: Unauthenticated management/actuator endpoints exposed on port 8081 (/env, /loggers) bypass API basic-auth
GHSA-hpj9-grjp-7vc7
pkg: io.kestra:kestra
eco: maven
published: Sep 17, 2026
## Summary
Kestra's Micronaut **management endpoints are served on port 8081 with no authentication**, even when the main API (port 8080) has basic-auth enabled. Anyone who can reach `:8081` can read `GET /env` (full resolved environment/configuration) and mutate runtime state via `POST /loggers/{na…
CVE-2026-73245
GitHub-GHSA

MEDIUM
vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation
GHSA-8pw2-6jv3-mj5j
pkg: vllm
eco: pip
published: Sep 17, 2026
## Summary

Current vLLM `main` lets an inference request choose the PyNvVideoCodec GPU video decoder through `media_io_kwargs.video.video_backend`, but engine GPU memory reservation is computed only from static startup configuration and `VLLM_VIDEO_LOADER_BACKEND`. If the server starts with the def…

CVE-2026-69147
NVD

MEDIUM
CVE-2026-85078
CVE-2026-85078
pkg: python

published: Sep 17, 2026

Sanic is an opensource python web server/framework. In version 25.12.0, Sanic's core HTTP/1.1 chunked-body handling does not fully consume the trailer-part after the terminating zero chunk before reusing the keep-alive connection buffer. A remote unauthenticated client can place attacker-controlled …
CWE: CWE-444
GitHub-GHSA

MEDIUM
sanic chunked trailer request smuggling allows hidden second request execution
GHSA-wmj6-g64g-j7q5
pkg: sanic, sanic
eco: pip
published: Sep 17, 2026
## Description

Sanic's HTTP/1.1 chunked-body handling does not fully consume the `trailer-part` after the terminating `0\r\n` chunk. Because of that, attacker-controlled bytes left in the connection buffer after the first chunked request can be interpreted as the start of a new HTTP request on the …

CVE-2026-85078
GitHub-GHSA

MEDIUM
AsyncSSH: asyncio event-loop freeze via SSH maximum packet size = 0 in SSH_MSG_CHANNEL_OPEN / OPEN_CONFIRMATION
GHSA-rw4j-r22c-9gc3
pkg: asyncssh
eco: pip
published: Sep 17, 2026
## Summary

A malicious SSH server can wedge an AsyncSSH **client**, and an authenticated
client can wedge an AsyncSSH **server**, by sending a channel `maximum packet
size` of `0` in `SSH_MSG_CHANNEL_OPEN_CONFIRMATION` (server→client) or
`SSH_MSG_CHANNEL_OPEN` (client→server). AsyncSSH stores t…

CVE-2026-62949
NVD

MEDIUM
CVE-2026-61588
CVE-2026-61588
pkg: react

published: Sep 16, 2026

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, when a Django `Model` instance is assigned to a public view attribute, djust serialized it to the client with no sensitive-field denylist — sending fields such as …
CWE: CWE-200, CWE-359
GitHub-GHSA

MEDIUM
vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions
GHSA-hcwq-8wjf-3gcr
pkg: vllm
eco: pip
published: Sep 16, 2026
### Summary
The audio decode-duration guard (`max_duration_s`, env `VLLM_MAX_AUDIO_DECODE_DURATION_S`, default 600s) that protects against audio decompression-bomb DoS is wired into **only** the speech-to-text path (`/v1/audio/transcriptions`). The **chat** audio path (`/v1/chat/completions`, `input…
CVE-2026-57173
GitHub-GHSA

MEDIUM
djust's Django model serialization has no sensitive-field denylist: password hashes, privilege flags, and PII on a public view attribute are sent to the client
GHSA-pvg3-6q9j-mj3x
pkg: djust
eco: pip
published: Sep 16, 2026
### Impact
When a Django `Model` instance is assigned to a **public** view attribute, djust serialized it to the client with **no sensitive-field denylist** — sending fields such as `password` (the hash), privilege flags (e.g. `is_staff` / `is_superuser`), tokens, and other PII to the browser. Bec…
CVE-2026-61588
NVD

MEDIUM
CVE-2026-92750
CVE-2026-92750
pkg: tls

published: Sep 16, 2026

Harness through 3.3.0 omits access control validation in the infrastructure provider read endpoint, allowing authenticated users to retrieve provider configurations from spaces they do not belong to. Attackers can query the GET /api/v1/infraproviders endpoint with arbitrary space identifiers to expo…
CWE: CWE-862
NVD

MEDIUM
CVE-2026-62949
CVE-2026-62949
pkg: python

published: Sep 16, 2026

AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Prior to 2.24.0, _process_channel_open and _process_channel_open_confirmation in asyncssh/connection.py accept a peer-supplied send_pktsize value…
CWE: CWE-835
NVD

MEDIUM
CVE-2026-89027
CVE-2026-89027
pkg: jwt

published: Sep 15, 2026

miniOrange JWT Authentication for WP REST APIs plugin for WordPress before 4.8.0 contains an authentication method downgrade vulnerability that allows unauthenticated attackers to bypass administrator-configured authentication by supplying a specific GET parameter without any capability check or non…
CWE: CWE-306
NVD

MEDIUM
CVE-2026-83251
CVE-2026-83251
pkg: tls

published: Sep 15, 2026

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Orac…
NVD

MEDIUM
CVE-2026-91968
CVE-2026-91968
pkg: express

published: Sep 15, 2026

vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the task-filter endpoint that accepts deeply nested filter expressions without recursion depth limits. Authenticated attackers can supply thousands of nested parentheses in the filter query parameter to exhaust memory and t…
CWE: CWE-674
NVD

MEDIUM
CVE-2026-55776
CVE-2026-55776
pkg: express

published: Sep 15, 2026

OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an authenticated OpenBao caller with write access to transit/keys/* could terminate the server process by setting derived to true while the type parameter selected rsa-, ecdsa-, or ed25519. The Transit policy creatio…
CWE: CWE-617
NVD

MEDIUM
CVE-2026-90439
CVE-2026-90439
pkg: tls

published: Sep 15, 2026

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module module. When using HTTP/3 with OpenSSL versions <= OpenSSL 3.5.0 under certain configurations, a limited heap buffer overflow could happen while processing a TLS handshake. This can happen in a non-deterministic manner t…
CWE: CWE-122
NVD

MEDIUM
CVE-2026-48987
CVE-2026-48987
pkg: python

published: Sep 15, 2026

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, EventManager in src/pyload/core/managers/event_manager.py appends a Client object to the clients list for each unique uuid submitted to the authenticated getEvents API endpoint, but get_events does not invo…
CWE: CWE-400, CWE-401, CWE-770
NVD

MEDIUM
CVE-2026-64753
CVE-2026-64753
pkg: apple safari, apple ipados, apple iphone_os

published: Sep 14, 2026

A permissions issue was addressed by removing the vulnerable code. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may disclose sensitive user information.
CWE: CWE-269
NVD

MEDIUM
CVE-2026-53719
CVE-2026-53719
pkg: kubernetes

published: Sep 14, 2026

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, translateSecurityPolicyForRoute in internal/gatewayapi/securitypolicy.go dereferences a nil authorization value when a namespace-scoped tenant creates a…
CWE: CWE-476
NVD

MEDIUM
CVE-2026-53716
CVE-2026-53716
pkg: kubernetes

published: Sep 14, 2026

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, getFileFromGZ in internal/wasm/httpfetcher.go calls io.ReadAll on a gzip.Reader without limiting decompressed output when a tenant-controlled EnvoyExten…
CWE: CWE-789
NVD

MEDIUM
CVE-2026-43791
CVE-2026-43791
pkg: apple macos

published: Sep 14, 2026

A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to read arbitrary files.
CWE: CWE-22, CWE-22
NVD

MEDIUM
CVE-2026-43719
CVE-2026-43719
pkg: apple macos

published: Sep 14, 2026

A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Mounting a maliciously crafted SMB network share may lead to system termination.
CWE: CWE-416
NVD

MEDIUM
CVE-2026-43687
CVE-2026-43687
pkg: apple ipados, apple iphone_os, apple macos

published: Sep 14, 2026

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Connecting to a malicious NFS server may disclose kernel memory.
CWE: CWE-200
NVD

MEDIUM
CVE-2026-43677
CVE-2026-43677
pkg: apple macos

published: Sep 14, 2026

An out-of-bounds write issue was addressed by removing the vulnerable code. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious WebDAV server may lead to unexpected app termination.
CWE: CWE-787
NVD

MEDIUM
CVE-2026-28934
CVE-2026-28934
pkg: apple macos

published: Sep 14, 2026

A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Mounting a malicious disk image may cause unexpected system termination.
CWE: CWE-120
NVD

MEDIUM
CVE-2026-53717
CVE-2026-53717
pkg: kubernetes

published: Sep 14, 2026

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, internal/wasm/imagefetcher.go follows tenant-controlled EnvoyExtensionPolicy spec.wasm[].code.image.url values to Docker or OCI Wasm layers, and extract…
CWE: CWE-789
NVD

MEDIUM
CVE-2026-17463
CVE-2026-17463
pkg: linux

published: Sep 14, 2026

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a remote authenticated attacker to cause a denial of service due to uncontrolled resource consumption.
CWE: CWE-400
NVD

MEDIUM
CVE-2026-16702
CVE-2026-16702
pkg: linux

published: Sep 14, 2026

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a remote authenticated attacker to cause a denial of service due to a null pointer dereference.
CWE: CWE-476
NVD

MEDIUM
CVE-2026-54723
CVE-2026-54723
pkg: nginx

published: Sep 14, 2026

devpi is a Python package index staging server and packaging, testing, and release tool. Prior to 6.20.2 and 7.0.0b3, a server configured with the primary or deprecated master role allows an unauthenticated, modified GET request to the +changelog route because verify_primary does not reject a missin…
CWE: CWE-304
NVD

MEDIUM
CVE-2026-50157
CVE-2026-50157
pkg: oauth

published: Sep 14, 2026

Auth0 Symfony is a Symfony SDK for Auth0 Authentication and Management APIs. From 5.0.0-BETA0 until 5.9.0, the Authorizer::authenticate() and Authorizer::supports() paths in the Authorizer security authenticator may accept OAuth 2.0 bearer access tokens from the token URL query parameter as well as …
CWE: CWE-598
NVD

MEDIUM
CVE-2026-82433
CVE-2026-82433
pkg: tls

published: Sep 14, 2026

Description

`getNimbusConf` returned the complete daemon configuration without redaction after only a user-level
authorization check. Where the cluster is configured with them, that response includes
`storm.zookeeper.auth.payload` and the keystore and truststore passwords for the Thrift, Netty and

CWE: CWE-522, CWE-862
NVD

MEDIUM
CVE-2026-82426
CVE-2026-82426
pkg: tls

published: Sep 14, 2026

Description

Nimbus accepted the `uploadedJarLocation` argument of `submitTopology` / `submitTopologyWithOpts` as a
server-side path and opened it directly, without checking that it referred to a file the caller had
actually uploaded. The intended flow is that a client first calls `beginFileUpload`,…

CWE: CWE-22
NVD

MEDIUM
CVE-2026-84179
CVE-2026-84179
pkg: tls

published: Sep 14, 2026

Description

getTopologyPageInfo merged the Nimbus daemon configuration with the topology's own configuration and returned the result without redaction in the topology_conf field of TopologyPageInfo. The Storm UI copied that value verbatim into the configuration field of GET /api/v1/topology/{id} …

CWE: CWE-200, CWE-522
NVD

MEDIUM
CVE-2026-53718
CVE-2026-53718
pkg: kubernetes

published: Sep 14, 2026

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, an HTTPRoute can use an extension-managed custom backendRef to reference a backend resource in another namespace without a matching Gateway API Referenc…
CWE: CWE-862
NVD

MEDIUM
CVE-2026-92992
CVE-2026-92992
pkg: curl

published: Sep 17, 2026

A security vulnerability has been detected in Dromara mayfly-go up to 1.11.5. The affected element is an unknown function of the file server/internal/ai/api/ai.go of the component AI Assistant. The manipulation leads to missing authorization. Remote exploitation of the attack is possible. The exploi…
CWE: CWE-862, CWE-863
NVD

MEDIUM
CVE-2026-61589
CVE-2026-61589
pkg: tls

published: Sep 16, 2026

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the WebSocket `handle_mount` and `ViewRuntime._build_request` rebuild an `HttpRequest` via `RequestFactory().get(…)` with no `HTTP_HOST`, so `request.get_host()` d…
CWE: CWE-348, CWE-639
GitHub-GHSA

MEDIUM
djust: WebSocket/runtime reconstructed request omits the client Host, causing host/subdomain TenantResolvers to misresolve the tenant on the live path
GHSA-v9rj-xjfv-xj9r
pkg: djust
eco: pip
published: Sep 16, 2026
### Impact
The WebSocket `handle_mount` and `ViewRuntime._build_request` rebuild an `HttpRequest` via `RequestFactory().get(…)` with no `HTTP_HOST`, so `request.get_host()` defaulted to `"testserver"` on the live path. Host/subdomain/domain `TenantResolver`s then misresolved the tenant — `None` …
CVE-2026-61589
NVD

MEDIUM
CVE-2026-92527
CVE-2026-92527
pkg: oauth

published: Sep 16, 2026

A vulnerability has been found in chatwoot up to 4.17.1. This impacts an unknown function of the file callbacks_controller.rb of the component Shopify OAuth. The manipulation leads to server-side request forgery. Remote exploitation of the attack is possible. The exploit has been disclosed to the pu…
CWE: CWE-918
NVD

MEDIUM
CVE-2026-81303
CVE-2026-81303
pkg: oauth

published: Sep 15, 2026

A flaw was found in hawtio-operator. The operator holds routes/custom-host:create permission cluster-wide and writes the tenant-supplied spec.routeHostName value from the Hawtio custom resource directly into the Route spec without validation or authorization checks. A namespace edit user, who normal…
CWE: CWE-441
NVD

MEDIUM
CVE-2026-15463
CVE-2026-15463
pkg: ssl

published: Sep 19, 2026

The SSL Zen — SSL Certificate Installer & HTTPS Redirects plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'host' parameter in all versions up to, and including, 4.7.42 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticate…
CWE: CWE-79
NVD

MEDIUM
CVE-2026-84992
CVE-2026-84992
pkg: vue

published: Sep 18, 2026

md-editor-v3 is a Markdown editor for Vue 3 developed in JSX and TypeScript. Prior to 6.5.4, MdPreview's useMarkdownIt() highlight callback in packages/MdEditor/layouts/Content/composition/useMarkdownIt.ts inserts a fenced-code language value into class and language HTML attributes without escaping …
CWE: CWE-79
GitHub-GHSA

MEDIUM
md-editor-v3: XSS via fenced-code language rendering bypass
GHSA-3rm2-h79c-8qw6
pkg: md-editor-v3
eco: npm
published: Sep 18, 2026
### Summary
`MdPreview` interpolates a fenced-code language into HTML attributes without escaping it. A crafted info string therefore executes JavaScript even when the shipped `XSSPlugin` is enabled.

### Details
`useMarkdownIt()` (`packages/MdEditor/layouts/Content/composition/useMarkdownIt.ts:206`…

CVE-2026-84992
GitHub-GHSA

MEDIUM
@platejs/core HTML deserialization can trigger browser behavior during parsing
GHSA-qrfj-mgw8-j9c6
pkg: @platejs/core, @platejs/core
eco: npm
published: Sep 17, 2026
### Summary

HTML strings passed to Plate's core deserialization APIs were parsed in the active document. Certain HTML attributes could therefore trigger browser behavior during parsing, before the content was converted into editor nodes.

Applications that deserialize HTML from untrusted or cross-u…

CVE-2026-88976
NVD

MEDIUM
CVE-2026-88976
CVE-2026-88976
pkg: node

published: Sep 16, 2026

Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.11, and in the discontinued 54.0.0-beta.0 through 54.0.0-beta.1 builds, Plate core HTML deserialization APIs parse supplied HTML strings in the active document. When an application passes untrusted or cross-user HTML to these APIs, cer…
CWE: CWE-79
NVD

MEDIUM
CVE-2026-49446
CVE-2026-49446
pkg: jwt

published: Sep 15, 2026

Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager. Prior to 0.22.19, tokenMiddleware in src/proxy/routerGen.go can return through the Constellation tunnel bypass before removing x-cosmos-user, x-cosmos-role, x-cos…
CWE: CWE-285, CWE-290
NVD

MEDIUM
CVE-2026-62280
CVE-2026-62280
pkg: oauth

published: Sep 15, 2026

Open Access Management (OpenAM) is an access management solution. From 13.0.0 until 16.1.2, the OAuth2 authorize endpoint's display=wap consent page reflects request-derived values through ConsentRequiredResource and wap/authorize.ftl without HTML escaping. An attacker can induce a user with an acti…
CWE: CWE-79
GitHub-GHSA

MEDIUM
AnyCable: Telemetry Subsystem Contains Hardcoded Authentication Token and Transmits CLI Arguments Including Secrets
GHSA-w72w-9qmj-c9qm
pkg: github.com/anycable/anycable
eco: go
published: Sep 18, 2026
### Summary
The telemetry subsystem embeds a hardcoded auth token (`"secret"`) in the public source and transmits raw CLI arguments—including `–secret`, `–jwt_secret`, and `–http_rpc_secret` values—to a third-party telemetry endpoint.

### Details
In `telemetry/config.go` line 12, `var authTo…

CVE-2026-63406
GitHub-GHSA

MEDIUM
AnyCable: Pusher REST API Does Not Verify Request Body MD5 Enabling Signed-Request Replay with Arbitrary Body
GHSA-5p54-whvp-x327
pkg: github.com/anycable/anycable
eco: go
published: Sep 18, 2026
### Summary
The Pusher-compatible REST API includes `body_md5` in the HMAC signature string but never computes or verifies the MD5 of the received HTTP body, allowing anyone who observes a signed request to replay it with an entirely different body.

### Details
In `pusher/http.go`, the `Handler` fu…

CVE-2026-63405
GitHub-GHSA

MEDIUM
Steeltoe.Management.Endpoint: HttpExchanges URI masking leaks query-string secrets
GHSA-8phw-xrj9-cpqp
pkg: Steeltoe.Management.Endpoint
eco: nuget
published: Sep 17, 2026
## Summary

Steeltoe's `/actuator/httpexchanges` endpoint records and displays request URIs after passing them through `MaskedUri`. The masking only covers the `UserInfo` portion of the URI (inline `user:password@host` credentials) and does not inspect the query string. With `IncludeQueryString` ena…

CVE-2026-75523
GitHub-GHSA

MEDIUM
AsyncHttpClient sends origin credentials to the proxy on the plaintext CONNECT request
GHSA-xr57-gcx8-52hf
pkg: org.asynchttpclient:async-http-client, org.asynchttpclient:async-http-client
eco: maven
published: Sep 17, 2026
### Impact
When a request uses an HTTP proxy to reach an HTTPS origin, the client opens the tunnel with a plaintext CONNECT sent to the proxy before any TLS exists. On affected versions the origin's preemptive credentials were added to that CONNECT. A Basic realm sent `Authorization: Basic base64(us…
CVE-2026-85720
NVD

MEDIUM
CVE-2026-85720
CVE-2026-85720
pkg: tls

published: Sep 17, 2026

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 2.16.1 and 3.0.12, a request using an HTTP proxy to reach an HTTPS origin can expose preemptive origin credentials because NettyRequestFactory and Ne…
CWE: CWE-319, CWE-522
NVD

MEDIUM
CVE-2026-85718
CVE-2026-85718
pkg: tls

published: Sep 17, 2026

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 3.0.8 until 3.0.12, a client with maxConnections or maxConnectionsPerHost set above zero leaks one connection permit whenever TLS connection establishment fails …
CWE: CWE-400, CWE-772
NVD

MEDIUM
CVE-2026-75523
CVE-2026-75523
pkg: oauth

published: Sep 17, 2026

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. Prior to 4.3.0, the Steeltoe.Management.Endpoint /actuator/httpexchanges endpoint passes recorded request URIs through MaskedUri, which masks URI user information but does not…
CWE: CWE-200
NVD

MEDIUM
CVE-2026-92591
CVE-2026-92591
pkg: express

published: Sep 16, 2026

Craft CMS 5.0.0 through 5.10.12 treats a database connection failure as meaning that Craft is not installed, which makes anonymous installer actions — including install/validate-site — reachable on an installed production site whenever PHP remains available but the configured MySQL endpoint does…
CWE: CWE-636
NVD

MEDIUM
CVE-2026-92081
CVE-2026-92081
pkg: node

published: Sep 16, 2026

fastify is a fast and low-overhead web framework for Node.js. In versions before 5.12.5, when a route registers a response trailer via reply.trailer() and is served over HTTP/2, fastify unconditionally sets the Transfer-Encoding: chunked header, which is forbidden on HTTP/2, so Node.js throws while …
CWE: CWE-248
GitHub-GHSA

MEDIUM
Http4s: ResourceService and Webjar Service path escape via percent-encoded separators
GHSA-crq5-92j2-j7wv
pkg: org.http4s:http4s-server_2.12, org.http4s:http4s-server_2.13, org.http4s:http4s-server_3
eco: maven
published: Sep 15, 2026
The static content handlers `ResourceService` and `WebjarService` URL decode each path segment and then reject only segments that are exactly `""`, `"."`, or `".."`. A percent-encoded separator (`%2F`) lets an attacker smuggle a `../` segment past that filter and escape the configured base, reading…
CVE-2026-69201
GitHub-GHSA

MEDIUM
Http4s: DigestAuth allows replay of captured requests
GHSA-9xww-74xv-gjfp
pkg: org.http4s:http4s-ember-core_2.12, org.http4s:http4s-ember-core_2.13, org.http4s:http4s-ember-core_3
eco: maven
published: Sep 15, 2026
The `DigestAuth` replay defence stores `lastNc + 1` rather than the nonce-count (`nc`) value it just accepted. When a legitimate client sends non-contiguous `nc` values (parallel or retried requests, as browsers do), the server's counter lags behind the highest `nc` seen, and a captured `Authorizati…
CVE-2026-69206
NVD

MEDIUM
CVE-2026-91992
CVE-2026-91992
pkg: tls

published: Sep 15, 2026

Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing. Attackers can obtain sensitive credentials by issuing requests through the same client instance, allowing TLS certificates or proxy auth…
CWE: CWE-200
NVD

MEDIUM
CVE-2026-43787
CVE-2026-43787
pkg: apple macos

published: Sep 14, 2026

A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An attacker in a privileged network position may be able to leak sensitive user information.
CWE: CWE-693
NVD

MEDIUM
CVE-2026-15924
CVE-2026-15924
pkg: tls

published: Sep 14, 2026

Zephyr's TLS socket layer in subsys/net/lib/sockets/sockets_tls.c keeps a single process-global array, client_cache, of cached client sessions that is shared by every TLS socket context. The functions that mutate and read it — tls_session_save(), tls_session_get(), tls_session_cache_reset(), and t…
CWE: CWE-416
NVD

MEDIUM
CVE-2026-20290
CVE-2026-20290
pkg: ssl

published: Sep 16, 2026

A vulnerability in SSL/TLS certificate parsing in the Snort 2 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 2 Detection Engine to restart.

This vulnerability is due to incomplete validation of the SSL cer…

CWE: CWE-805
NVD

MEDIUM
CVE-2026-78301
CVE-2026-78301
pkg: node

published: Sep 16, 2026

A malformed zone may contain an NS or DNAME node above its origin, which `named` treats as a zone cut. If an attacker inserts a malformed zone into a BIND authoritative server (e.g., via zone transfer), queries for names inside the configured zone then lose authoritative status and return an out-of-…
CWE: CWE-349
NVD

MEDIUM
CVE-2026-55636
CVE-2026-55636
pkg: kubernetes

published: Sep 15, 2026

Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.6, charts/capsule/templates/configuration.yaml configures the validating webhook with namespace/finalize instead of the Kubernetes resource name namespaces/finalize. A user with namespaces/finalize RBAC can …
CWE: CWE-863
NVD

MEDIUM
CVE-2026-54246
CVE-2026-54246
pkg: kubernetes

published: Sep 14, 2026

Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.13, the routesrv component serves cluster-wide control-plane data without application-layer authentication through /routes, /routes/{zone}, /swarm/redis/shards, and /swarm/valkey/shards. The handlers registered in rou…
CWE: CWE-306
NVD

MEDIUM
CVE-2026-19542
CVE-2026-19542
pkg: node

published: Sep 14, 2026

Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.

The tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as n…

CWE: CWE-121
NVD

MEDIUM
CVE-2026-92756
CVE-2026-92756
pkg: tls

published: Sep 17, 2026

Applications built on MongoDB Entity Framework Core Provider which combine independent encryption settings and this provider's encryption settings may silently lose TLS and schema-map settings leading to protected fields being stored unencrypted in the database.
CWE: CWE-311
NVD

MEDIUM
CVE-2026-81326
CVE-2026-81326
pkg: windows

published: Sep 16, 2026

QND uses a hard-coded cryptographic key, which may allow a local attacker who is logged in to a Windows PC where the affected product's client is installed to obtain administrator credentials, including an ID and password.
CWE: CWE-321
NVD

MEDIUM
CVE-2026-81320
CVE-2026-81320
pkg: tls

published: Sep 15, 2026

A flaw was found in hawtio-operator. When a custom Route TLS secret is configured and the operator runs at debug log level 1 or higher, the entire Route object — including the TLS private key in PEM format — is serialized to JSON and written to the operator's standard output. Operator logs are t…
CWE: CWE-532
GitHub-GHSA

MEDIUM
ZITADEL: Improper Role Revocation on Granted Projects during Multiple Role Deletions
GHSA-v859-c572-qh5p
pkg: github.com/zitadel/zitadel
eco: go
published: Sep 14, 2026
### Summary

A bug in how ZITADEL updates permissions when multiple project roles are deleted at the same time can cause some user permissions to be missed. This issue specifically affects **User Grants on Granted Projects** (projects shared between different organizations), **potentially** allowing…

CVE-2026-76081
NVD

MEDIUM
CVE-2026-65348
CVE-2026-65348
pkg: apple ipados, apple iphone_os, apple macos

published: Sep 14, 2026

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to modify protected parts of the file system.
CWE: CWE-732
NVD

MEDIUM
CVE-2026-65345
CVE-2026-65345
pkg: apple ipados, apple iphone_os, apple macos

published: Sep 14, 2026

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access user-sensitive data.
CWE: CWE-284
NVD

MEDIUM
CVE-2026-64756
CVE-2026-64756
pkg: apple ipados, apple iphone_os, apple macos

published: Sep 14, 2026

A path handling issue was addressed with improved validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access user-sensitive data.
CWE: CWE-22
NVD

MEDIUM
CVE-2026-64714
CVE-2026-64714
pkg: apple ipados, apple iphone_os, apple macos

published: Sep 14, 2026

A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Golden Gate 27, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. Processing a maliciously crafted image may lead to a denial-of-service.
CWE: CWE-119
NVD

MEDIUM
CVE-2026-43785
CVE-2026-43785
pkg: apple ipados, apple iphone_os, apple macos

published: Sep 14, 2026

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27. An app may be able to modify a file it only had permission to read.
CWE: CWE-863, CWE-863
NVD

MEDIUM
CVE-2026-43741
CVE-2026-43741
pkg: apple macos

published: Sep 14, 2026

A logic issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access protected user data.
CWE: CWE-284
NVD

MEDIUM
CVE-2026-43737
CVE-2026-43737
pkg: apple ipados, apple iphone_os, apple macos

published: Sep 14, 2026

An authorization issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, watchOS 27. An app may be able to access motion data from headphones without user consent.
CWE: CWE-863
NVD

MEDIUM
CVE-2026-43695
CVE-2026-43695
pkg: apple ipados, apple iphone_os, apple macos

published: Sep 14, 2026

An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to access sensitive user data.
CWE: CWE-863, CWE-285
NVD

MEDIUM
CVE-2026-43664
CVE-2026-43664
pkg: apple ipados, apple iphone_os, apple macos

published: Sep 14, 2026

This issue was addressed with improved data protection. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, watchOS 27. An app may be able to access sensitive user data.
CWE: CWE-200
NVD

MEDIUM
CVE-2026-28968
CVE-2026-28968
pkg: apple ipados, apple iphone_os, apple macos

published: Sep 14, 2026

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination or …
CWE: CWE-125
NVD

MEDIUM
CVE-2026-28937
CVE-2026-28937
pkg: apple macos

published: Sep 14, 2026

This issue was addressed through improved state management. This issue is fixed in macOS Golden Gate 27. An app may be able to access sensitive user data.
CWE: CWE-284
NVD

MEDIUM
CVE-2026-28899
CVE-2026-28899
pkg: apple macos

published: Sep 14, 2026

A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.6, macOS Tahoe 26.7. An app may bypass Gatekeeper checks.
CWE: CWE-693
NVD

MEDIUM
CVE-2026-92568
CVE-2026-92568
pkg: kubernetes

published: Sep 16, 2026

MLRun through 1.11.0 contains a server-side request forgery vulnerability in the WebhookNotification handler that allows authenticated users to make the API server send arbitrary HTTP requests to internal addresses. Attackers can update a run with a malicious webhook notification that executes when …
CWE: CWE-918
GitHub-GHSA

MEDIUM
Http4s: Ember chunk parser lenience (TE.TE request smuggling)
GHSA-jrpm-956j-96jg
pkg: org.http4s:http4s-ember-core_2.12, org.http4s:http4s-ember-core_2.13, org.http4s:http4s-ember-core_3
eco: maven
published: Sep 15, 2026
## Summary

Ember's chunk decoder parses the size token leniently: it strips leading and trailing whitespace and accepts a leading `+` or `-` sign. RFC9112 §7.1 defines `chunk-size = 1*HEXDIG`. An intermediary that parses the chunk boundary differently (or rejects it) will disagree with Ember on …

CVE-2026-69216
NVD

MEDIUM
CVE-2026-81921
CVE-2026-81921
pkg: concretecms concrete_cms

published: Sep 15, 2026

Concrete CMS 8.5.3 through 9.5.2 enabled the OAuth 2.0 refresh-token grant using the unmodified upstream League grant, which issued new access tokens from a valid refresh token without re-checking the associated account's active status. A user who obtained a refresh token while active could therefor…
CWE: CWE-862
NVD

MEDIUM
CVE-2026-55226
CVE-2026-55226
pkg: kubernetes

published: Sep 15, 2026

Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In Strimzi 1.0.0 and earlier, deploying only the Topic Operator or only the User Operator through the Kafka custom resource leaves the Entity Operator ServiceAccount with RBAC permi…
CWE: CWE-269, CWE-272
NVD

MEDIUM
CVE-2026-81897
CVE-2026-81897
pkg: concretecms concrete_cms

published: Sep 15, 2026

In Concrete CMS below CMS 9.5.3, the save_control action in the Express entities forms dashboard controller did not validate the anti-CSRF token. By causing an authenticated administrator to submit a forged cross-site request, a remote attacker without credentials could write attacker-controlled hea…
CWE: CWE-79, CWE-352
NVD

MEDIUM
CVE-2026-91942
CVE-2026-91942
pkg: docker

published: Sep 15, 2026

crawl4ai before 0.9.3 contains a DOM-based cross-site scripting vulnerability in the Docker Playground UI that assigns untrusted crawl results to element.innerHTML. Attackers can craft malicious PDFs with event-handler markup to execute JavaScript in the Playground origin and steal API tokens from s…
CWE: CWE-79
NVD

MEDIUM
CVE-2024-58384
CVE-2024-58384
pkg: curl

published: Sep 15, 2026

Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request headers. Attackers can inject CRLF sequences into header values to inject arbitrary headers or construct entirely new HTTP requests.
CWE: CWE-113
NVD

MEDIUM
CVE-2026-91201
CVE-2026-91201
pkg: oauth

published: Sep 14, 2026

DocsGPT through 0.20.0 posts OAuth connector session tokens to a wildcard target origin in the callback-status endpoint without validating sender origin. Attackers can obtain session tokens and provider account emails by acting as window.opener during OAuth authorization, then use tokens to disconne…
CWE: CWE-346
NVD

MEDIUM
CVE-2026-93964
CVE-2026-93964
pkg: openssl

published: Sep 20, 2026

A vulnerability was detected in NginxProxyManager nginx-proxy-manager up to 2.15.1. This impacts the function internalCertificate.validate of the file backend/internal/certificate.js of the component Validate Route. The manipulation results in missing authentication. The attack can be launched remot…
CWE: CWE-287, CWE-306
NVD

MEDIUM
CVE-2026-18346
CVE-2026-18346
pkg: oauth

published: Sep 19, 2026

The TikTok plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to overwrite the merchant's stored …
CWE: CWE-862
NVD

MEDIUM
CVE-2026-77528
CVE-2026-77528
pkg: python

published: Sep 18, 2026

Autobahn Python is a WebSocket and WAMP implementation for Python that supports Twisted and asyncio. Prior to 26.7.1, WebSocket endpoints that accept permessage-deflate and rely on maxMessagePayloadSize enforce that limit against the compressed frame length before inflation but do not recheck the de…
CWE: CWE-409, CWE-770
NVD

MEDIUM
CVE-2026-52745
CVE-2026-52745
pkg: express

published: Sep 18, 2026

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.0, the POST /account-pool/page endpoint allows an authenticated caller with MODULE_SETTING:UPDATE to place a crafted sort.name value into a dynamic SQL ORDER BY expression wi…
CWE: CWE-89
GitHub-GHSA

MEDIUM
Obot: MCP Registry API readable without authentication
GHSA-pr6h-vr44-xq8j
pkg: github.com/obot-platform/obot
eco: go
published: Sep 18, 2026
## Summary

In affected versions, enabling registry authentication (`OBOT_SERVER_ENABLE_REGISTRY_AUTH=true`) does not actually protect the MCP Registry endpoints under `/v0.1/*` — they remain readable by unauthenticated callers.

## Am I affected?

You are affected if you run Obot `<= v0.22.1` wit…

NVD

MEDIUM
CVE-2026-93395
CVE-2026-93395
pkg: express

published: Sep 17, 2026

A missing lower-bound validation in the bson_new_from_buffer() function of libbson allows an integer underflow when processing BSON data with a zero-length prefix. The function reads a 32-bit document length from the input buffer but does not verify that the value is at least 5 (the minimum valid BS…
CWE: CWE-191
GitHub-GHSA

MEDIUM
Soup Sieve: Polynomial-time ReDoS (O(n²)) in the `IDENTIFIER` / `VALUE` selector sub-patterns
GHSA-gjv8-xp57-g29c
pkg: soupsieve
eco: pip
published: Sep 17, 2026
## Summary

soupsieve compiles CSS selector strings with a set of hand-written regular expressions. The shared `IDENTIFIER` sub-pattern (also embedded in `VALUE`, and therefore in attribute selectors) places two adjacent quantified groups over overlapping character classes: `(?:[classA]|ESC)+(?:[cla…

CVE-2026-86000
GitHub-GHSA

MEDIUM
Soup Sieve: Polynomial-time ReDoS (O(n²)) in the whitespace/comment trimming regex `RE_WS_END` (triggers on VALID selectors)
GHSA-j934-xhv5-fg8f
pkg: soupsieve
eco: pip
published: Sep 17, 2026
## Summary

Before tokenizing, `selector_iter` trims leading/trailing whitespace and comments by running two regexes over the whole raw selector with `.search()`. The trailing one, `RE_WS_END = re.compile(r'{WSC}*$')`, is anchored only at the end (`$`), not the start. Because `.search()` retries the…

CVE-2026-85999
GitHub-GHSA

MEDIUM
Svelte devalue: DoS via malformed input
GHSA-9rgm-9g3h-6×36
pkg: devalue
eco: npm
published: Sep 17, 2026
### Impact

`devalue.parse` prior to version 5.9.2 fails to reject out-of-bounds indices. Specially-crafted payloads can exploit this to cause devalue to alternate between different array representations, resulting in work that is quadratic with payload size.

Applications are potentially affected i…

CVE-2026-81176
NVD

MEDIUM
CVE-2026-86000
CVE-2026-86000
pkg: express

published: Sep 17, 2026

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, the selector parser in src/soupsieve/css_parser.py defines IDENTIFIER with adjacent quantified groups over overlapping character classes, and VALUE embeds IDENTIFIER for attribute selectors. When an attacke…
CWE: CWE-400, CWE-1333
NVD

MEDIUM
CVE-2026-85999
CVE-2026-85999
pkg: express

published: Sep 17, 2026

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, selector_iter in src/soupsieve/css_parser.py trims the raw selector with RE_WS_END, an end-anchored WSC whitespace-and-comment expression used with search(), so the regular expression engine retries a greed…
CWE: CWE-400, CWE-1333
GitHub-GHSA

MEDIUM
Vendure: Shop API list queries can return non-public entities when filterOperator is OR
GHSA-xf65-r35x-wmmv
pkg: @vendure/core
eco: npm
published: Sep 17, 2026
The Shop API `products`, `collections` and `facets` queries inject a mandatory filter to restrict results to publicly-visible entities (`Product.enabled = true`, `Collection.isPrivate = false`, `Facet.isPrivate = false`). This injected guard was combined with the caller-supplied filter using the cal…
CVE-2026-63461
NVD

MEDIUM
CVE-2026-81829
CVE-2026-81829
pkg: jwt

published: Sep 17, 2026

A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by AWS Application Load Balancers. When the AWS_ALB key provider is configured, the resolver constructs the key-fetch URL by directly concatenating the attacker-controlled kid header …
CWE: CWE-22
NVD

MEDIUM
CVE-2026-71568
CVE-2026-71568
pkg: tls

published: Sep 17, 2026

In BMCtest, Ironic is started without authentication and TLS for the duration of the test. Exploiting the problem requires winning the race with bmctest itself, which reduces the attack window and significantly increases its complexity.
CWE: CWE-306
NVD

MEDIUM
CVE-2026-90982
CVE-2026-90982
pkg: windows

published: Sep 17, 2026

@fastify/static is a Fastify plugin that serves static files from a configured root directory. In versions before 10.1.4, on a case-insensitive filesystem such as Windows or the default macOS volume, a route guard or allowedPath restriction can be bypassed by altering the letter case of a path segme…
CWE: CWE-178, CWE-284
GitHub-GHSA

MEDIUM
OpenFGA: ListUsers returns a deliberately-excluded user when a `but not` exclusion under a type-bound wildcard is intersected (`and`) with another relation that also grants that user
GHSA-g3pg-frfm-pr2m
pkg: github.com/openfga/openfga
eco: go
published: Sep 16, 2026
### Description

In OpenFGA, the ListUsers API could incorrectly return a user who should have been excluded.

### Preconditions

This applies if all of the following are present:

– The authorization model contains a relation defined as an intersection (and) where at least one operand is an exclus…

CVE-2026-61709
NVD

MEDIUM
CVE-2026-92220
CVE-2026-92220
pkg: react

published: Sep 16, 2026

A vulnerability was found in vllm-project vLLM 0.26.0/0.27.0. Affected is the function MoRIIOConnectorScheduler.request_finished/MoRIIOConnectorWorker.get_finished/MoRIIOWrapper._handle_release_message of the file vllm/distributed/kv_transfer/kv_connector/v1/moriio/moriio_connector.py of the compone…
CWE: CWE-400, CWE-404
NVD

MEDIUM
CVE-2026-92114
CVE-2026-92114
pkg: express

published: Sep 15, 2026

A vulnerability was identified in a2ui-project a2ui up to 0.10.6. Affected is an unknown function of the file renderers/web_core/src/v0_9/basic_catalog/functions/safe_regex.ts of the component Basic Catalog. Such manipulation leads to inefficient regular expression complexity. The attack can be laun…
CWE: CWE-400, CWE-1333
NVD

MEDIUM
CVE-2026-55375
CVE-2026-55375
pkg: oauth

published: Sep 15, 2026

canto-saas-api is a PHP library for interacting with the Canto SaaS API. Prior to version 3.0.0, OAuth2Request::getQueryParams() places app_id, app_secret, refresh_token, and code in the URL query string of token POST requests, allowing access logs, proxy logs, and APM traces to persist the credenti…
CWE: CWE-209, CWE-598
NVD

MEDIUM
CVE-2026-44163
CVE-2026-44163
pkg: node

published: Sep 15, 2026

fluent-plugin-opentelemetry is a Fluentd input and output plugin for forwarding OpenTelemetry Protocol data. Prior to 0.5.3, the in_opentelemetry HTTP input read the entire incoming request body and decompressed payloads into memory without enforcing maximum size thresholds. When an OpenTelemetry in…
CWE: CWE-409
NVD

MEDIUM
CVE-2026-53715
CVE-2026-53715
pkg: kubernetes

published: Sep 14, 2026

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, HTTPServer.ServeHTTP in internal/wasm/httpserver.go reads the plain mappingPath2Cache map without synchronization while HTTPServer.Get writes the same m…
CWE: CWE-362
NVD

MEDIUM
CVE-2026-43696
CVE-2026-43696
pkg: apple macos

published: Sep 14, 2026

An authorization issue was addressed with improved entitlement checks. This issue is fixed in macOS Golden Gate 27. An app may be able to capture Touch Bar content without authorization.
CWE: CWE-862, CWE-862
NVD

MEDIUM
CVE-2026-55244
CVE-2026-55244
pkg: express

published: Sep 14, 2026

ASTEVAL is an evaluator of Python expressions and statements. Prior to 1.0.9, FROM_PY in asteval/astutils.py exposes BaseException, SystemExit, KeyboardInterrupt, and GeneratorExit to expressions evaluated by asteval.Interpreter.eval(), while run() and eval() in asteval/asteval.py catch Exception ra…
CWE: CWE-248
GitHub-GHSA

MEDIUM
Capsule: Malformed ForbiddenAnnotations.Regex can bypass Tenant validation and trigger namespace admission panic
GHSA-gxjc-74v5-3vx3
pkg: github.com/projectcapsule/capsule
eco: go
published: Sep 18, 2026
### Summary
A validation bug in `internal/webhook/tenant/validation/forbidden_annotations_regex.go` allows an invalid `ForbiddenAnnotations.Regex` value to bypass Tenant admission on update. The webhook compiles `ForbiddenLabels.Regex` for both labels and annotations, so a malformed annotations rege…
CVE-2026-61794
NVD

MEDIUM
CVE-2026-48737
CVE-2026-48737
pkg: curl

published: Sep 15, 2026

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, is_global_address in src/pyload/core/utils/web/check.py relies on Python's global-address classification without examining IPv4 destinations embedded in 6to4 or NAT64 IPv6 addresses. A low-privileged user c…
CWE: CWE-918
NVD

MEDIUM
CVE-2026-77883
CVE-2026-77883
pkg: express

published: Sep 14, 2026

Exposure of sensitive information through data queries vulnerability in Apache Syncope.

An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficient entitlements for User read to access LinkedAccount's (if pres…

CWE: CWE-202
NVD

MEDIUM
CVE-2026-84850
CVE-2026-84850
pkg: tls

published: Sep 15, 2026

Improper certificate validation in the shared HTTP client used by synchronization and integration features in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to intercept and tamper with outbound TLS connections via a spoofed or self-signed certificate.
CWE: CWE-295
NVD

MEDIUM
CVE-2026-86818
CVE-2026-86818
pkg: node

published: Sep 15, 2026

fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv, that added a mailto scheme parser in version 4.1.3. In versions 4.1.3 and 4.1.4, the mailto parser compares each query field name to the reserved names to, subject, and body while the name is still percent-encode…
CWE: CWE-172, CWE-436
NVD

MEDIUM
CVE-2026-86472
CVE-2026-86472
pkg: node

published: Sep 15, 2026

fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv. In versions before 2.4.7, from 3.0.0 through 3.1.7, and from 4.0.0 through 4.1.4, fast-uri folds the host to lowercase before it percent-decodes the host, so a percent-encoded uppercase octet such as %41 decodes …
CWE: CWE-178
GitHub-GHSA

MEDIUM
oras-go: Blind SSRF via unvalidated Link header URL in pagination allows internal network probing
GHSA-h7vf-4x9w-h99v
pkg: oras.land/oras-go/v2
eco: go
published: Sep 17, 2026
## Summary

oras-go's pagination helper `parseLink()` in `registry/remote/utils.go` follows the `Link` response header from a registry without validating the URL's host or scheme. When a malicious registry returns a `Link` header containing an absolute URL pointing to an arbitrary host (e.g., a clou…

CVE-2026-85732
NVD

MEDIUM
CVE-2026-43690
CVE-2026-43690
pkg: apple macos

published: Sep 14, 2026

A race condition was addressed with improved locking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A local user may be able to read kernel memory.
CWE: CWE-362
NVD

MEDIUM
CVE-2026-16148
CVE-2026-16148
pkg: node

published: Sep 14, 2026

The ITE it82xx2 USB device-controller driver initialized its bus-suspend detection work with k_work_init_delayable(&priv->suspended_work, suspended_handler) inside it82xx2_enable() (the driver's .enable op) in drivers/usb/udc/udc_it82xx2.c. This work item is scheduled essentially continuously while …
CWE: CWE-666
NVD

MEDIUM
CVE-2025-13533
CVE-2025-13533
pkg: express

published: Sep 18, 2026

The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 12.0.6 via the Assignment Engine fields. This is due to insufficient input sanitization and output escaping on assignment data fields including Expressions, URLs, and …
CWE: CWE-79
GitHub-GHSA

MEDIUM
Redocly CLI: Path traversal when using `split` command
GHSA-657c-g7qc-r9j2
pkg: @redocly/cli, @redocly/cli
eco: npm
published: Sep 17, 2026
### Impact

An OpenAPI or AsyncAPI description could make the `split` command write
files outside the chosen output directory, on the machine of anyone who runs
`split` against it. The write is constrained rather than a free file-write
primitive: component data is emitted only as YAML/JSON, and code…

CVE-2026-63225
NVD

MEDIUM
CVE-2026-93960
CVE-2026-93960
pkg: oauth

published: Sep 20, 2026

A vulnerability was identified in Pixelfed up to 0.12.11. Impacted is the function instancePeers of the file app/Http/Controllers/Api/ApiV1Controller.php of the component OAuth Scope Handler. Such manipulation of the argument ID leads to missing authentication. The attack may be performed from remot…
CWE: CWE-287, CWE-306
NVD

MEDIUM
CVE-2026-91983
CVE-2026-91983
pkg: react

published: Sep 15, 2026

Vikunja before 2.6.0 contains an API token scope bypass vulnerability in task read endpoints where authorization fails to inspect query string parameters. Attackers with limited token scopes can use the expand parameter to access restricted data like comments, reactions, and time entries without pro…
CWE: CWE-863
NVD

MEDIUM
CVE-2026-91091
CVE-2026-91091
pkg: node

published: Sep 15, 2026

A vulnerability was identified in GPAC up to f1219cde. The impacted element is the function gf_node_list_insert_child of the file scenegraph/base_scenegraph.c of the component Node Insertion. Such manipulation leads to memory corruption. The attack can be launched remotely. The exploit is publicly a…
CWE: CWE-119
NVD

MEDIUM
CVE-2026-28966
CVE-2026-28966
pkg: apple ipados, apple iphone_os, apple macos

published: Sep 14, 2026

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27. Processing a maliciously crafted file may lead to unexpected app terminat…
CWE: CWE-787
NVD

MEDIUM
CVE-2026-54247
CVE-2026-54247
pkg: kubernetes

published: Sep 14, 2026

Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.26.22, Handler in dataclients/kubernetes/admission/admission.go passes the body of requests to the Kubernetes admission endpoint at :9443/admission directly to io.ReadAll(r.Body) without a size limit. An attacker with in…
CWE: CWE-770
NVD

MEDIUM
CVE-2026-82437
CVE-2026-82437
pkg: node

published: Sep 14, 2026

Description

The Logviewer offers `logs.users` and `logs.groups` so operators can control who may read log content. For
daemon logs those settings were not applied: the access decision combined the "this is a daemon log" flag
with the authorizer result in a way that discarded the authorizer's answer…

CWE: CWE-862
NVD

MEDIUM
CVE-2026-90712
CVE-2026-90712
pkg: oauth

published: Sep 14, 2026

A vulnerability was identified in Gitlawb openclaude up to 0.30.0. Impacted is the function waitForCallback of the file src/services/api/xaiOAuthCallback.ts of the component xAI OAuth Callback Handler. The manipulation of the argument Error leads to denial of service. Remote exploitation of the atta…
CWE: CWE-404
NVD

MEDIUM
CVE-2026-11993
CVE-2026-11993
pkg: go

published: Sep 14, 2026

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to properly enforce the limit of concurrent files being processed and handled failed files, which allows a user with permission to upload files to spawn more goroutines than intended and block the inde…
CWE: CWE-770
NVD

MEDIUM
CVE-2026-93999
CVE-2026-93999
pkg: jwt

published: Sep 19, 2026

A flaw was found in the OIDC protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs during the token refresh process when the server restores requested audiences from stored client IDs. Keycloak fails to verify if the target audience client is s…
CWE: CWE-862
NVD

MEDIUM
CVE-2026-85511
CVE-2026-85511
pkg: oauth

published: Sep 18, 2026

A flaw was found in EAP's Elytron. An EAP application whose security domain is backed by an Elytron token-realm with oauth2-introspection would allow parameter substitution due to missing URL encoding.
CWE: CWE-290
NVD

MEDIUM
CVE-2026-92138
CVE-2026-92138
pkg: oauth

published: Sep 16, 2026

The OAuth authorization endpoint in Jenkins Bitbucket Server Integration Plugin 6.0.1 and earlier reads the `oauth_callback` URL from the submitted form rather than from the server-side stored request token, allowing attackers to hijack the OAuth flow and obtain an access token on behalf of the vict…
CWE: CWE-345
NVD

MEDIUM
CVE-2026-59341
CVE-2026-59341
pkg: kubernetes

published: Sep 15, 2026

A security vulnerability exists in the Sealed Secrets controller's unauthenticated POST endpoints. By submitting a modified payload containing custom Go template logic in spec.template.data, an attacker with internal network access can abuse the handler as a decryption oracle to recover the full pla…
CWE: CWE-203
GitHub-GHSA

MEDIUM
Process Compose: Browser DNS rebinding lets websites control local process-compose MCP tools
GHSA-5gm3-9crp-6g3v
pkg: github.com/f1bonacc1/process-compose
eco: go
published: Sep 18, 2026
## Summary

A malicious website can use DNS rebinding to control a developer's local process-compose MCP SSE listener when MCP SSE is enabled. The vulnerable path accepts browser-origin requests before any Host validation, Origin validation, or caller-secret check, then dispatches the requests into …

CVE-2026-77339
GitHub-GHSA

MEDIUM
AnyIO process-pool workers can block indefinitely on undrained stderr
GHSA-5p39-cfhj-2xmp
pkg: anyio
eco: pip
published: Sep 18, 2026
### Impact
AnyIO starts process-pool workers with stderr connected to a pipe but never drains that pipe. The worker redirects stdin and stdout to /dev/null to protect its protocol, but does not redirect stderr even though the documentation says all three standard streams are redirected. Worker code …
CVE-2026-64847
GitHub-GHSA

MEDIUM
OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning
GHSA-w34q-cm8f-9c5x
pkg: go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc
eco: go
published: Sep 17, 2026
### Summary

The OTLP log gRPC exporter loads TLS settings from environment variables but does not apply them when creating gRPC transport credentials. Operators who rely on `OTEL_EXPORTER_OTLP_LOGS_CERTIFICATE`, `OTEL_EXPORTER_OTLP_CERTIFICATE`, or related client certificate variables for CA pinnin…

CVE-2026-81871
GitHub-GHSA

MEDIUM
oRPC: Vary Header Injection in CORS Plugin leading to potential Cache/CORS Bypass
GHSA-j9v4-rhgr-4m5f
pkg: @orpc/server
eco: npm
published: Sep 17, 2026
### Summary
A flaw in the CORS plugin allowed the incoming request's `Vary` header to be reflected into the response, letting a client influence a header that should be controlled solely by the server.

### Details
The CORS plugin previously copied the request's `Vary` header directly onto the respo…

CVE-2026-77360
GitHub-GHSA

MEDIUM
LiteLLM Proxy has server-side request forgery via the `user_config` request parameter
GHSA-hx8v-g79f-8w5f
pkg: litellm
eco: pip
published: Sep 17, 2026
### Summary
A server-side request forgery in LiteLLM Proxy lets an authenticated caller redirect the
proxy's outbound request to a host of their choosing by smuggling an `api_base` inside the
`user_config` request body, bypassing the existing parameter guard.

### Details
LiteLLM Proxy validates req…

CVE-2026-59823
GitHub-GHSA

MEDIUM
Nuxt OG Image has unauthenticated SSRF via `fonts[].path` URL parameter
GHSA-q8hw-4fvp-9rwv
pkg: nuxt-og-image
eco: npm
published: Sep 17, 2026
### Summary
`nuxt-og-image` exposes an **unauthenticated HTTP endpoint** at `/_og/d/**` that base64url-decodes and `JSON.parse`s a `fonts` URL segment, then passes each `fonts[i].path` value directly into `fetch()` server-side **without any URL validation** (no scheme allowlist, no loopback/RFC1918 …
CVE-2026-61793
GitHub-GHSA

MEDIUM
djust is vulnerable to stored/reflected XSS via javascript: URLs in built-in component template tags
GHSA-4mf4-73j6-mvrw
pkg: djust
eco: pip
published: Sep 16, 2026
### Impact
Many djust built-in component template tags (`djust.components.templatetags.*`) render a developer/user-supplied URL into an `href` / `action` attribute, HTML-escaping it with `conditional_escape` but **never validating the URL scheme**. HTML escaping prevents attribute breakout but does …
CVE-2026-61597
GitHub-GHSA

MEDIUM
Netmaker has a boolean‑based SQL Injection
GHSA-r8cr-4f9w-7r75
pkg: github.com/gravitl/netmaker
eco: go
published: Sep 15, 2026
# SQL Injection in Netmaker SQLite Database Backend

## Summary

The `sqliteDeleteRecord` function in Netmaker's database layer constructs SQL `DELETE` statements using direct string concatenation of user-supplied input. This allows an authenticated attacker to perform **boolean-based SQL injection*…

CVE-2026-32599