Vulnerability Digest — October 5, 2026 · 56 Critical · 6 Exploited






Vulnerability Digest — Monday, October 5, 2026


Security Report

Monday, October 5, 2026  ·  Last 7 days  ·  Min severity: MEDIUM
Total Findings
430
Critical
56
High
211
Actively Exploited
6
CISA-KEV6
NVD247
GitHub-GHSA177
Findings sorted by severity
CISA-KEV

CRITICAL
Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
CVE-2026-88779
pkg: Citrix NetScaler

published: Oct 4, 2026

Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for a denial of service.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Zammad GmbH Zammad Improper Privilege Management Vulnerability
CVE-2026-102490
pkg: Zammad GmbH Zammad

published: Oct 2, 2026

Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Zammad GmbH Zammad Session Fixation Vulnerability
CVE-2026-102489
pkg: Zammad GmbH Zammad

published: Oct 2, 2026

Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with CVE-2026-102490.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Fortinet FortiMail Path Traversal Vulnerability
CVE-2026-104286
pkg: Fortinet FortiMail

published: Oct 1, 2026

Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability
CVE-2026-76504
pkg: Cisco Catalyst SD-WAN Manager

published: Sep 30, 2026

Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Apple Multiple Products Out-of-Bounds Write Vulnerability
CVE-2026-86950
pkg: Apple Multiple Products

published: Sep 29, 2026

Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
GitHub-GHSA

CRITICAL
Vibe-Trading FastAPI endpoints permit unauthenticated access, file upload, and an RCE chain
GHSA-v2f8-6655-7grj
pkg: vibe-trading-ai
eco: pip
published: Oct 2, 2026
### Summary:
5 findings — unauthenticated full-API exposure (F1, lead Critical), read-side authorization gap that persists even with `API_AUTH_KEY` set (F2), unauthenticated file write of `.py`/`.sh`/`.yaml` to a server-returned path (F3), default-permissive CORS that combines with a loopback-onl…
GitHub-GHSA

CRITICAL
Vibe-Trading LLM-callable tools permit command execution, code injection, and SSRF
GHSA-jqmf-mx4f-hfr6
pkg: vibe-trading-ai
eco: pip
published: Oct 2, 2026
### Summary:
5 findings — `BashTool` shell-injection sink (F6, the canonical RCE primitive), `BackgroundRunTool` async shell-injection sink (F7), backtest `exec_module()` runs top-level statements before the `SignalEngine` class check (F8 — independent RCE path that does not match BashTool sign…
GitHub-GHSA

CRITICAL
vm2 exposes host HTTPS credentials and TLS traffic through globalAgent
GHSA-h85j-hv3c-qfgq
pkg: vm2
eco: npm
published: Oct 1, 2026
Summary

vm2 3.11.6 exposes the host process's real `https.globalAgent` when a `NodeVM` is explicitly allowed to require `https`. The module is wrapped as read-only, but calls to methods on the shared agent still mutate the host object. Sandbox code can register a `free` listener and receive host re…

CVE-2026-92940
GitHub-GHSA

CRITICAL
vm2: GHSA-m283-3h24-438v fix bypass leads to host RCE via call/apply indirection
GHSA-647f-g98j-qq25
pkg: vm2
eco: npm
published: Oct 1, 2026
## Summary

Untrusted JavaScript run by vm2 can escape the sandbox and execute arbitrary commands in the host Node.js process when an embedder-exposed host Promise rejects. This is an incomplete fix for GHSA-m283-3h24-438v: the advisory's capability-bearing rejection rebuild runs only through this d…

CVE-2026-92937
GitHub-GHSA

CRITICAL
vm2 NodeVM can replace the host process TLS trust store
GHSA-98xx-8mx4-x7cm
pkg: vm2
eco: npm
published: Oct 1, 2026
Summary

vm2 3.11.6 exposes the host `tls` module to a `NodeVM` when that builtin is explicitly allowed. Although the module object is wrapped as read-only, its functions still execute against process-wide host state. On Node.js versions that provide `tls.setDefaultCACertificates()`, sandbox code ca…

CVE-2026-92941
GitHub-GHSA

CRITICAL
SiYuan: Unauthenticated SQL injection in searchDocs via unescaped keyword (publish mode): cross-notebook read/write with statement stacking
GHSA-33jq-p8c2-q3q4
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: Oct 1, 2026
### Summary

The `/api/filetree/searchDocs` endpoint concatenates the caller-supplied search keyword directly into a SQL statement with no escaping and no parameter binding. The endpoint is gated by `CheckAuth` only reachable by the publish RoleReader token, and by the anonymous account when `Publis…

CVE-2026-69085
NVD

CRITICAL
CVE-2026-53988
CVE-2026-53988
pkg: docker

published: Sep 29, 2026

Dockhand before 1.0.40 contains an authentication bypass vulnerability in its git webhook endpoints that allows unauthenticated remote attackers to trigger arbitrary stack redeployments by exploiting a null webhook secret guard condition. Attackers can enumerate sequential stack IDs and send unsigne…
CWE: CWE-306
GitHub-GHSA

CRITICAL
gitea-runner: workflow container.options passes host namespaces and capability flags to job container when privileged mode is disabled
GHSA-x4q3-gcj3-m6cf
pkg: gitea.com/gitea/runner
eco: go
published: Oct 2, 2026
### Summary
act_runner appends workflow-controlled `jobs.<job>.container.options` directly
to the Docker HostConfig for the job container. When runner privileged mode is
disabled, only `Privileged` is forced false. Host namespace flags, capability
expansion, and security profile overrides from wo…
CVE-2026-73802
GitHub-GHSA

CRITICAL
vm2: NodeVM builtin allowlist bypass via node:test.run() execArgv allows sandbox escape
GHSA-qhwx-74w5-xhxq
pkg: vm2
eco: npm
published: Oct 1, 2026
## Summary

On Node.js 24 and newer, `vm2` can expose the host `node:test` module to sandboxed `NodeVM` code when the embedder explicitly allows the `node:test` builtin. Sandbox code can reach that module through `require('node:node:test')` and call `run()` with attacker-controlled `execArgv`.

`nod…

CVE-2026-92948
GitHub-GHSA

CRITICAL
vm2 Custom Module Resolver Can Bypass the External Package Allowlist by Loading a Colliding Host Package
GHSA-c48m-32m9-vx93
pkg: vm2
eco: npm
published: Oct 1, 2026
### Summary

vm2 is a sandbox library for isolating and executing untrusted JavaScript code inside a Node.js process. It can restrict access to built-in modules and external packages.

When `NodeVM` enables an `external` allowlist together with a custom `resolve` callback, vm2 checks the requested p…

CVE-2026-92951
GitHub-GHSA

CRITICAL
vm2: NodeVM node:-prefixed negative builtin deny bypass exposes child_process
GHSA-8686-vhfx-7r3j
pkg: vm2
eco: npm
published: Oct 1, 2026
## Summary

NodeVM normalizes `node:`-prefixed builtin specifiers during `require()` resolution, but it does not normalize user-provided negative builtin entries in wildcard policy.

As a result, this configuration:

“`js
new NodeVM({
require: {
builtin: ['*', '-node:child_process']
}
});
`…

CVE-2026-92957
GitHub-GHSA

CRITICAL
vm2 allows a sandboxed plugin to execute native code through `node:sqlite`
GHSA-6w8r-xxw2-g3hx
pkg: vm2
eco: npm
published: Oct 1, 2026
### Summary

vm2 3.11.6 exposes Node.js's host `node:sqlite` module to `NodeVM` code when that builtin is allowed explicitly or through `builtin: ['*']`. The module is wrapped as read-only, but callable methods retain host-process authority. A sandboxed plugin can construct an in-memory database wit…

CVE-2026-92938
GitHub-GHSA

CRITICAL
vm2 crypto builtin loads attacker native code through setEngine
GHSA-46pr-c5wc-xffx
pkg: vm2
eco: npm
published: Oct 1, 2026
Summary

vm2 3.11.6 exposes the host `crypto` module to a `NodeVM` when that single builtin is allowed. The module is presented through a read-only bridge, but its functions still execute with host-process authority. `crypto.setEngine()` accepts a filesystem path and asks OpenSSL to dynamically load…

CVE-2026-92939
NVD

CRITICAL
CVE-2026-87799
CVE-2026-87799
pkg: linux

published: Sep 28, 2026

Improper link resolution in the migration receive path in Canonical LXD versions 4.0 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client that can create instances or custom storage volumes in a project, or a malicious migration source server, to write attacke…
CWE: CWE-59
NVD

CRITICAL
CVE-2026-85526
CVE-2026-85526
pkg: linux

published: Sep 28, 2026

Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated user with instance creation privileges to delete or replace arbitrary files and directories on the host filesystem as root via a crafted subvolumes[].path entry in backup/optimized_header.yaml…
CWE: CWE-22
NVD

CRITICAL
CVE-2026-82042
CVE-2026-82042
pkg: jwt

published: Oct 2, 2026

UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote attackers to gain full administrative API access by presenting a valid Utm-Internal-Key header matching the INTERNAL_KEY environment variable value, which the InternalApiKeyFilter accepts for any endpoint with…
CWE: CWE-306
NVD

CRITICAL
CVE-2026-59797
CVE-2026-59797
pkg: ssl

published: Oct 1, 2026

Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions.

This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

CWE: CWE-269
GitHub-GHSA

CRITICAL
vm2 sandbox escape on Node.js 26 through a stale PromiseThenLookupChain protector
GHSA-27g9-p43v-cw3v
pkg: vm2
eco: npm
published: Oct 1, 2026
## Reporter

– Name or handle: `[YMsora]`
– Report date: 2026-08-14

## Summary

The latest published vm2 release, **3.11.5**, and the current `main` branch are vulnerable to a sandbox escape when used on Node.js 26. An ordinary fulfilled Promise created by an async function can retain an attacker-c…

CVE-2026-92944
NVD

CRITICAL
CVE-2026-82827
CVE-2026-82827
pkg: jwt

published: Oct 1, 2026

Hitachi Coding Software Suite contains a vulnerability related to Use of Hard-coded Cryptographic Key. The Hardcoding of JWT signing secret key allows an attacker to generate unauthorized Bearer tokens and exploit administrative functions.

This issue affects Hitachi Coding Software Suite: through …

CWE: CWE-321
NVD

CRITICAL
CVE-2026-51857
CVE-2026-51857
pkg: python

published: Sep 30, 2026

In camel-ai camel 0.2.91a1, v0.2.91a2 and v0.2.91a3, CodeExecutionToolkit can run model-produced Python code through SubprocessInterpreter without an approval boundary.
CWE: CWE-94
NVD

CRITICAL
CVE-2026-51856
CVE-2026-51856
pkg: python

published: Sep 30, 2026

In agentscope 1.0.18, 1.0.19, and 1.0.19 when the RealtimeAgent session exposes execute_python_code as an available tool, a remote WebSocket user can prompt the agent to call that tool and run Python code in the service environment. In the validated path, RealtimeAgent._acting forwards the model-pro…
CWE: CWE-94
NVD

CRITICAL
CVE-2026-55494
CVE-2026-55494
pkg: docker

published: Sep 30, 2026

Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.4, Tugtainer Agent allows unauthenticated access to Docker management APIs when AGENT_SECRET is not configured. The Agent uses request signatures to protect its API routes. However, in agent/auth.py, th…
CWE: CWE-284
NVD

CRITICAL
CVE-2026-97274
CVE-2026-97274
pkg: oauth

published: Sep 30, 2026

Unauthenticated Bypass Vulnerability in OAuth Single Sign On – SSO (OAuth Client) <= 7.1.2 versions.
CWE: CWE-290
NVD

CRITICAL
CVE-2026-103110
CVE-2026-103110
pkg: node

published: Sep 30, 2026

Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation that allows a remote attacker to execute code remotely as an unprivileged user on a Pexip Infinity Conferencing Node.
CWE: CWE-787
NVD

CRITICAL
CVE-2026-77177
CVE-2026-77177
pkg: express

published: Sep 29, 2026

Open GenAI Stack (aka ogx-ai) 2026-06-11, as used in the Meta AI backend for WhatsApp and other products, allows code execution because prompt injection (with Jinja2 template syntax) can be used to achieve server-side expression evaluation without sanitization.
CWE: CWE-94
NVD

CRITICAL
CVE-2026-95313
CVE-2026-95313
pkg: google chrome

published: Sep 29, 2026

Use after free in Fullscreen in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

CRITICAL
CVE-2026-95311
CVE-2026-95311
pkg: google chrome

published: Sep 29, 2026

Free of non-heap memory in Fonts in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-590
NVD

CRITICAL
CVE-2026-95310
CVE-2026-95310
pkg: google chrome

published: Sep 29, 2026

Use after free in AdFilter in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

CRITICAL
CVE-2026-95299
CVE-2026-95299
pkg: google chrome

published: Sep 29, 2026

Use after free in GPU in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

CRITICAL
CVE-2026-95284
CVE-2026-95284
pkg: google chrome, google android

published: Sep 29, 2026

Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-122
NVD

CRITICAL
CVE-2026-95283
CVE-2026-95283
pkg: google chrome, google android

published: Sep 29, 2026

Buffer overflow in Tint in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-122
NVD

CRITICAL
CVE-2026-95281
CVE-2026-95281
pkg: google chrome, google android

published: Sep 29, 2026

Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-122
NVD

CRITICAL
CVE-2026-95277
CVE-2026-95277
pkg: google chrome

published: Sep 29, 2026

Use after free in Views in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

CRITICAL
CVE-2026-85185
CVE-2026-85185
pkg: linux

published: Sep 28, 2026

Path traversal in the btrfs storage driver in Canonical LXD versions 4.0.2 and later (fixed in 4.0.14, 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create instances in a project to delete arbitrary files on the host as root. On hosts whose root filesystem is bt…
CWE: CWE-22
NVD

CRITICAL
CVE-2026-55181
CVE-2026-55181
pkg: docker

published: Sep 30, 2026

Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.3, Tugtainer's OIDC authentication can still be initiated even when OIDC_ENABLED=false. The /auth/oidc/enabled endpoint correctly reports that OIDC is disabled. However, a direct request to /auth/oidc/l…
CWE: CWE-284
GitHub-GHSA

CRITICAL
@a2ui/web_core: `openUrl` permits `javascript:` URI execution via agent-supplied button actions
GHSA-72qq-p3r5-f7wq
pkg: @a2ui/web_core
eco: npm
published: Oct 2, 2026
### Summary

The `openUrl` function in `@a2ui/web_core` passes an agent-controlled URL directly to `window.open()` without validating the URI scheme. A malicious agent can supply a `javascript:` URI as the `url` argument of a `Button` component's `functionCall` action. When the user clicks the rende…

CVE-2026-10032
NVD

CRITICAL
CVE-2026-51864
CVE-2026-51864
pkg: python

published: Sep 30, 2026

DB-GPT v0.7.5 and v0.8.0 contains directory traversal in python_file_upload (packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/python_upload_api.py:42). A remote attacker can use the validated exploitation path to write files outside the intended workspace or storage boundary.
CWE: CWE-22
NVD

CRITICAL
CVE-2026-62308
CVE-2026-62308
pkg: docker

published: Sep 30, 2026

Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.6, Tugtainer allows an authenticated user to make the backend server send outbound HTTP requests to arbitrary user-supplied URLs through the notification test endpoint. The /settings/test_notification e…
CWE: CWE-918
NVD

CRITICAL
CVE-2026-87830
CVE-2026-87830
pkg: express

published: Sep 30, 2026

In the StAX streaming WS-SecurityPolicy validator, certain relative or unsupported XPath expressions can be converted into paths that never match the actual XML element path. A remote SOAP peer may therefore send a required element without the expected signature or encryption.
Users are recommended …
CWE: CWE-917
GitHub-GHSA

CRITICAL
@xhmikosr/decompress: Path traversal via symlink chain
GHSA-hrh2-vp3x-79xf
pkg: @xhmikosr/decompress, @xhmikosr/decompress, decompress
eco: npm
published: Sep 29, 2026
### Impact

When extracting an untrusted archive with the default `decompress(input, output)` API, a crafted archive containing a chain of symlink entries can make a later entry resolve **outside** the output directory. The lexical containment checks pass, but the kernel follows the planted symlinks…

CVE-2026-101894
GitHub-GHSA

CRITICAL
PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip the HS/asymmetric confusion guard
GHSA-ffc3-869f-jxw9
pkg: PyJWT
eco: pip
published: Sep 29, 2026
**Prerequisites** (both conditions must hold; both are deployment properties, not attacker-controlled at request time):

– The `jwt.decode` allow-list mixes an HMAC algorithm with an asymmetric one, e.g. `algorithms=["ES256", "HS256"]` (the RFC 8725 footgun the guard exists to backstop).
– The verif…

CVE-2026-102268
NVD

CRITICAL
CVE-2026-102268
CVE-2026-102268
pkg: jwt

published: Sep 28, 2026

PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, is_pem_format in jwt/utils.py is affected because is_pem_format does not recognize every PEM representation accepted by the cryptography loader. This occurs when an application mixes HMAC and asymmetric algorithms and sup…
CWE: CWE-347
NVD

CRITICAL
CVE-2026-101894
CVE-2026-101894
pkg: node

published: Sep 28, 2026

The decompress package for Node.js extracts archives. Prior to 10.2.2 and 11.1.4, the default decompress(input, output) API relies on lexical containment checks that do not account for the kernel following a planted symlink chain. An attacker can supply a crafted archive containing chained symlink e…
CWE: CWE-22, CWE-59
NVD

CRITICAL
CVE-2026-93029
CVE-2026-93029
pkg: ssl

published: Oct 2, 2026

There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Manage SSL Hosts interface.
CWE: CWE-79
NVD

CRITICAL
CVE-2026-86345
CVE-2026-86345
pkg: tls

published: Oct 2, 2026

A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP message that is processed after the TLS upgrade and whose response is delivered to the client in pla…
CWE: CWE-923
GitHub-GHSA

CRITICAL
vm2: NodeVM nesting guard accepts array-shaped require and permits host RCE
GHSA-8hr7-r645-pc6w
pkg: vm2
eco: npm
published: Oct 1, 2026
## Summary

The `NodeVM` constructor computes `hasRealRequireConfig` using `typeof requireOpts === 'object' && requireOpts !== null`, so `require: []` bypasses the guard intended to reject `nesting` without an explicit require configuration. `makeResolverFromLegacyOptions()` then destructures the ar…

CVE-2026-92935
NVD

CRITICAL
CVE-2026-103248
CVE-2026-103248
pkg: express

published: Oct 1, 2026

n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a filter injection vulnerability in the Supabase node's Filters (String) mode that fails to escape field values. Attackers can inject filter expressions from untrusted input to read all table rows, update a…
CWE: CWE-89
GitHub-GHSA

CRITICAL
Trigger.dev: V1 coordinator default-secret unauth Socket.IO
GHSA-gg6r-gp4c-89hp
pkg: trigger.dev
eco: npm
published: Oct 2, 2026
## TL;DR

The /coordinator Socket.IO namespace mounts on every webapp boot and authenticates with a default secret ("coordinator-secret") baked into source. The override variable isn't documented in the self-host docs, .env.example, or helm values, so any operator who didn't read source ships with t…

GitHub-GHSA

CRITICAL
piscina: Prototype-pollution gadget in ThreadPool.options allows RCE via execArgv / loadBalancer / env
GHSA-67c8-pqhq-4rmx
pkg: piscina, piscina, piscina
eco: npm
published: Oct 1, 2026
### Summary

A prototype-pollution gadget in `ThreadPool.options` allows an attacker who can pollute `Object.prototype` to execute arbitrary code in Piscina worker threads, invoke arbitrary functions during task scheduling, or inject environment variables into workers. The root cause is that `Thread…

CVE-2026-102992
GitHub-GHSA

CRITICAL
Next.js: Remote Code Execution in next/og ImageResponse
GHSA-vcvr-r3jv-pc5j
pkg: next
eco: npm
published: Sep 30, 2026
## Impact

The Node.js `ImageResponse` implementation from `next/og` is affected by an upstream vulnerability. This can lead to remote code execution.

Affected applications pass attacker-controlled values into SVG content, attributes, or styles during image generation:

“`tsx
import { ImageRespons…

GitHub-GHSA

HIGH
Headroom vulnerable to Cross-Site WebSocket Hijacking (CSWSH)
GHSA-h46j-26q3-rggf
pkg: headroom-ai
eco: pip
published: Oct 2, 2026
### Summary
The Headroom WebSocket server does not validate the `Origin` header of incoming client WebSocket requests before forwarding the request to the upstream server, allowing malicious WebSocket clients to perform arbitrary LLM requests without authentication. This can be exploited by a malici…
CVE-2026-71416
GitHub-GHSA

HIGH
Dulwich: Arbitrary File Write (RCE) on Windows via Unvalidated Drive Letters in Tree Paths
GHSA-8mcx-5rqc-vhmf
pkg: dulwich
eco: pip
published: Oct 2, 2026
### Affected files
* `dulwich/index.py` (Methods: `validate_path_element_ntfs`, `_tree_to_fs_path`)
* `dulwich/porcelain/__init__.py` (Method: `_checked_worktree_path`)

### Description / Summary
A High-severity Path Traversal vulnerability exists in Dulwich's checkout logic when running on Windows.…

NVD

HIGH
CVE-2026-104851
CVE-2026-104851
pkg: express

published: Oct 2, 2026

fsspec is a specification and Python implementation framework for filesystem interfaces. From 0.9.0 until 2026.6.0, fsspec.implementations.reference.ReferenceFileSystem evaluates fields from Kerchunk reference JSON documents through unrestricted jinja2.Template(…).render(…) calls in _process_ref…
CWE: CWE-94, CWE-1336
NVD

HIGH
CVE-2026-103268
CVE-2026-103268
pkg: react

published: Oct 1, 2026

Ghost versions before 6.62.0 contain an authentication bypass vulnerability that allows suspended staff users to reactivate their accounts through self-service password reset. Attackers with suspended staff credentials can perform password reset operations to regain active account access and restore…
CWE: CWE-862
GitHub-GHSA

HIGH
GitPython: Repository content can impersonate the git directory, leading to arbitrary code execution
GHSA-239g-whfq-7xj9
pkg: gitpython
eco: pip
published: Sep 30, 2026
### Summary

`Repo.__init__` decides which directory is the git directory by testing candidate paths in an order that
considers the real `.git` **last**. Two earlier tests can be satisfied by ordinary tracked files. Git
reserves only the literal name `.git`, so `HEAD`, `objects/`, `refs/`, `config`,…

CVE-2026-87817
NVD

HIGH
CVE-2026-102120
CVE-2026-102120
pkg: node

published: Sep 30, 2026

A privilege escalation vulnerability in Kiteworks could have allowed an attacker who had already obtained code execution on one node of a clustered Kiteworks deployment to run operating system commands with elevated privileges on another node of the same cluster. Insufficient input validation in an …
CWE: CWE-78, CWE-269
NVD

HIGH
CVE-2026-101882
CVE-2026-101882
pkg: node

published: Sep 30, 2026

OpenClaw Windows Node before 2026.7.1 contains an incomplete validation vulnerability in system.execApprovals.set that accepts wildcard-executable rules and abusable system binaries like mshta, rundll32, and certutil. Remote callers can add broad allow rules to execute arbitrary commands on the Wind…
CWE: CWE-184
NVD

HIGH
CVE-2026-101880
CVE-2026-101880
pkg: node

published: Sep 30, 2026

OpenClaw Windows Node before 2026.7.1 contains an incorrect authorization vulnerability in the system.run exec-approval policy where ExecShellWrapperParser fails to split commands on pipe operators or extract command substitutions. Connected gateways or agents can bypass approval rules by placing de…
CWE: CWE-863
NVD

HIGH
CVE-2026-100254
CVE-2026-100254
pkg: windows

published: Sep 30, 2026

In JetBrains TeamCity before 2026.2,
2026.1.4,
2025.11.8 authenticated users could execute commands on Windows servers via CRLF injection in Pipeline Git connection settings
CWE: CWE-78
NVD

HIGH
CVE-2026-103105
CVE-2026-103105
pkg: node

published: Sep 30, 2026

Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper access control on a product-internal API which allows an attacker with local access to a node within a Pexip Infinity installation to execute arbitrary code as an unprivileged user on another Pexip Infinity node.
CWE: CWE-863
NVD

HIGH
CVE-2026-95306
CVE-2026-95306
pkg: google chrome

published: Sep 29, 2026

Type confusion in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-843
NVD

HIGH
CVE-2026-95304
CVE-2026-95304
pkg: google chrome

published: Sep 29, 2026

Out of bounds write in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-787
NVD

HIGH
CVE-2026-95286
CVE-2026-95286
pkg: google chrome

published: Sep 29, 2026

Type confusion in Bindings in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-843
NVD

HIGH
CVE-2026-95282
CVE-2026-95282
pkg: google chrome

published: Sep 29, 2026

Use after free in Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-92370
CVE-2026-92370
pkg: linux

published: Sep 29, 2026

An improper access control vulnerability in TeamViewer Full Client, Host, and related affected modules on Windows, Linux, and macOS allows an authenticated remote attacker to bypass user-configured permission settings during session establishment. By modifying access control parameters for restricte…
CWE: CWE-284
NVD

HIGH
CVE-2026-92142
CVE-2026-92142
pkg: go

published: Sep 29, 2026

Apache Karaf exposes a JMX MBeanServer guarded by KarafMBeanServerGuard, which enforces role-based access control (RBAC) on MBean operations invoked over the remote JMX connector (RMI registry/server, enabled by default on ports 1099 and 44444). The guard is implemented as a java.lang.reflect.Proxy…
CWE: CWE-862
NVD

HIGH
CVE-2026-78424
CVE-2026-78424
pkg: node

published: Sep 28, 2026

Improper parameter handling in NeuVector allows any authenticated user who holds the namespaced Runtime Policies (write) permission or anyone with access to NeuVector’s internal gRPC certificate key pair the ability to inject OS commands in the privileged enforcer container, which can lead to the …
CWE: CWE-78
NVD

HIGH
CVE-2026-12268
CVE-2026-12268
pkg: windows

published: Sep 28, 2026

ManageEngine DDI Central versions below 6201 are vulnerable to PowerShell command injection in Windows DNS SPF/TXT record push leading to remote code execution.
CWE: CWE-20
GitHub-GHSA

HIGH
Dulwich: Symlink write-through in checkout(paths=[]) via raw os.open bypasses all symlink protections
GHSA-8w8g-wq8h-fq33
pkg: dulwich
eco: pip
published: Oct 2, 2026
## Summary

Dulwich's `porcelain.checkout(paths=[…])` code path writes files using raw `os.open(file_path, O_WRONLY|O_CREAT|O_TRUNC, mode)` followed by `f.write(obj.data)`. This code path does NOT call `build_file_from_blob()` at all, completely bypassing any symlink protections (including the unr…

GitHub-GHSA

HIGH
Dulwich: Symlink directory traversal in filter-branch index_filter via cross-commit state persistence
GHSA-5fqc-mrg8-w798
pkg: dulwich
eco: pip
published: Oct 2, 2026
## Summary

Dulwich's `filter_branch.py` `CommitFilter._apply_index_filter()` is vulnerable to symlink directory traversal. When processing commit history, materialized tree entries (including symlinks) persist in the working directory between commits, allowing a symlink from an ancestor commit to r…

GitHub-GHSA

HIGH
Dulwich: Symlink directory traversal in stash pop allows arbitrary file write via intermediate directory symlinks
GHSA-cm62-gvxx-vmxx
pkg: dulwich
eco: pip
published: Oct 2, 2026
## Summary

Dulwich's `stash.py:pop()` function is vulnerable to symlink directory traversal, allowing an attacker to write arbitrary files outside the repository worktree when a victim pops a stash in a malicious repository.

## Root Cause

The `pop()` function at `dulwich/stash.py:236` uses `os.pa…

GitHub-GHSA

HIGH
SiYuan: getAttributeViewSearchTarget returns database row content to anonymous readers with no publish-access check, reopening the class closed one day earlier at the adjacent route
GHSA-9cqf-hhrq-7v45
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: Oct 1, 2026
### Scope note

This endpoint does not exist in v3.7.3 or on master. It was introduced on the development branch by commit `9b8e8956f` on 2026-07-27 and is present on the current development head. No released stable version is affected.

### Summary

`/api/av/getAttributeViewSearchTarget` is registe…

GitHub-GHSA

HIGH
vm2 CLI provides no sandbox isolation – host-realm require() is reachable from sandboxed scripts
GHSA-jxxv-8r27-vm4p
pkg: vm2
eco: npm
published: Oct 1, 2026
### Summary
The `vm2` command-line tool installed by `npm install -g vm2` and documented in the README's "CLI" section runs the supplied script under `NodeVM` with `require:{external:true}` and no `root` / `context` / `builtin` configured. With these defaults the resolver loads every relative or abs…
CVE-2026-92950
NVD

HIGH
CVE-2026-103101
CVE-2026-103101
pkg: node

published: Sep 30, 2026

Pexip Infinity 30.0 through 40.x before 41.0 is affected by improper input validation in the web server that allows a malicious attacker to render a Pexip Infinity node inaccessible.
CWE: CWE-770
NVD

HIGH
CVE-2026-102317
CVE-2026-102317
pkg: google chrome, microsoft windows

published: Sep 29, 2026

Improper privilege management in Mojo in Google Chrome on on Windows prior to 154.0.8037.92 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
CWE: CWE-269
GitHub-GHSA

HIGH
vm2: NodeVM builtin denylist bypass via fs/promises despite -fs, allowing host filesystem writes
GHSA-6rh5-qq4q-97xh
pkg: vm2
eco: npm
published: Oct 1, 2026
## Summary

NodeVM's builtin wildcard policy can allow sandboxed code to access `fs/promises` even when the embedder denies `fs`.

With the following configuration:

“`js
require: {
builtin: ['*', '-fs', '-child_process']
}
“`

`require('fs')` and `require('child_process')` are blocked, but `req…

CVE-2026-92958
NVD

HIGH
CVE-2026-19184
CVE-2026-19184
pkg: express

published: Oct 5, 2026

The NXP GAU ADC driver (drivers/adc/adc_mcux_gau_adc.c) validated the caller-supplied sequence->buffer_size, which is expressed in bytes, against the number of active channels, which is a sample count. It then stored that byte count directly in data->results_length and used it in mcux_gau_adc_read_s…
CWE: CWE-787
NVD

HIGH
CVE-2026-95285
CVE-2026-95285
pkg: google chrome, google android

published: Sep 29, 2026

Missing authorization in WebView in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
CWE: CWE-862
NVD

HIGH
CVE-2026-95278
CVE-2026-95278
pkg: google chrome

published: Sep 29, 2026

Missing authorization in WakeLock in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
CWE: CWE-862
NVD

HIGH
CVE-2024-42002
CVE-2024-42002
pkg: express

published: Sep 28, 2026

A code injection vulnerability has been discovered in the Robot Operating System 2 (ROS 2) 'ros2topic' command-line tool, affecting all ROS 2 distributions from Crystal Clemmys up to and including Lyrical Luth and Rolling Ridley. The vulnerability lies in the 'hz' verb, which reports the publishing …
CWE: CWE-94, CWE-95
NVD

HIGH
CVE-2026-95276
CVE-2026-95276
pkg: google chrome

published: Sep 29, 2026

Improper input validation in Themes in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code inside the sandbox via crafted network traffic. (Chromium security severity: Medium)
CWE: CWE-20
NVD

HIGH
CVE-2026-95274
CVE-2026-95274
pkg: google chrome

published: Sep 29, 2026

Improper output encoding in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-116
NVD

HIGH
CVE-2026-102676
CVE-2026-102676
pkg: node

published: Sep 29, 2026

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, an Electron <webview> guest could enable nodeIntegrationInWorker for its Web Workers even when the unsandboxed embedder had Node.js integration…
CWE: CWE-269, CWE-1188
GitHub-GHSA

HIGH
SiYuan Agent Tools SSRF via DNS-Rebinding TOCTOU (Bypass of CheckHostSSRF)
GHSA-x8gv-g2g3-65fj
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: Oct 2, 2026
# Security Advisory — SiYuan Agent Tools SSRF via DNS-Rebinding TOCTOU (Bypass of `CheckHostSSRF`)

| Field | Value |
|—|—|
| **Disclosed by** | joysinleung (`joysinleung@gmail.com`) |
| **Report date** | 2026-08-13 |
| **Product** | SiYuan (思源笔记) — `siyuan-note/siyuan` |
| **Go modu…

GitHub-GHSA

HIGH
Electron drops inherited HTML sandbox restrictions for popups opened through OpenURLFromTab
GHSA-hq2x-r82h-9wj4
pkg: electron, electron, electron
eco: npm
published: Sep 29, 2026
### Impact

Popups opened from a sandboxed iframe through a link (for example `target="_blank"` or a middle-click) did not inherit the iframe's HTML `sandbox` restrictions. Content that was meant to run sandboxed could open a popup with the embedding app's full origin, gaining access to that origin'…

CVE-2026-102673
GitHub-GHSA

HIGH
Electron: Windows opened from a sandboxed top-level document do not inherit its sandbox restrictions
GHSA-gr2m-v5gq-v685
pkg: electron, electron, electron
eco: npm
published: Sep 29, 2026
### Impact

Windows opened from a sandboxed top-level document did not inherit that document's HTML `sandbox` restrictions, so content that was meant to run sandboxed could open a window with the app's full origin. GHSA-hq2x-r82h-9wj4 covers the same issue for sandboxed iframes.

Apps are only affec…

CVE-2026-102674
NVD

HIGH
CVE-2026-102674
CVE-2026-102674
pkg: windows

published: Sep 29, 2026

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, windows opened from a sandboxed top-level document did not inherit that document's active HTML sandbox restrictions. Untrusted content in a san…
CWE: CWE-266, CWE-693
NVD

HIGH
CVE-2026-84782
CVE-2026-84782
pkg: ssl

published: Sep 29, 2026

Issue summary: The DTLS retransmission logic does not correctly handle
a handshake message write that is suspended part-way through.
The retransmitted message can be read past the message buffer and
the retransmission overwrites the internal state the suspended write
needs to resume correctly.

Impa…

CWE: CWE-125
NVD

HIGH
CVE-2026-104988
CVE-2026-104988
pkg: ssl

published: Oct 2, 2026

A flaw was found in Dogtag PKI (pki-core). The CMCAuthForEST authentication plugin fails open when an EST fullcmc enrollment request is submitted via BasicAuth without an end-user TLS client certificate. The SSL_CLIENT_CERT session attribute retains the EST subsystem's agent certificate, which cause…
CWE: CWE-290
GitHub-GHSA

HIGH
JupyterLab: Cross-site scripting (XSS) in JupyterLab via notebook cells pasted from the system clipboard
GHSA-6966-vjj6-99xv
pkg: jupyterlab, jupyterlab, notebook
eco: pip
published: Oct 1, 2026
## Description

JupyterLab 4.5.0 enabled copying and pasing cells through the system clipboard. The paste path parses clipboard text as cell JSON and inserts the cells without clearing `metadata.trusted`, so a payload can declare its own output as trusted. JupyterLab does not sanitize a trusted outp…

CVE-2026-102831
GitHub-GHSA

HIGH
fastify vulnerable to request body replacement via an async validation result collision
GHSA-667r-xxjv-c9mm
pkg: fastify
eco: npm
published: Sep 30, 2026
### Impact

Fastify runs a route's validator and, for a result shaped like `{ value, error }`, unwraps it: an `error` becomes a validation failure and `value` replaces the request part. This convention is intended for synchronous custom compilers (for example Joi). A JSON Schema `$async` validator, …

CVE-2026-84504
NVD

HIGH
CVE-2026-87004
CVE-2026-87004
pkg: docker

published: Sep 30, 2026

Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.31.3, when the OIDC login flow completes, backend/modules/auth/providers/auth_oidc_provider.py decodes the id_token returned by the identity provider's token endpoint using jose.jwt.get_unverified_claims()…
CWE: CWE-347
NVD

HIGH
CVE-2026-103473
CVE-2026-103473
pkg: node

published: Sep 30, 2026

Deno versions 2.7.0 through 2.9.7 on Windows contain a command injection vulnerability in node:child_process where shell arguments are escaped for the wrong shell type. Attackers can inject OS commands by passing untrusted arguments with the shell option, allowing arbitrary command execution with De…
CWE: CWE-78
NVD

HIGH
CVE-2026-93994
CVE-2026-93994
pkg: openssh

published: Sep 30, 2026

Apache MINA SSHD is a Java library for client-side and server-side SSH. SSH servers can be configured to require multi-authentication schemes, for instance two different public keys, not just one. In OpenSSH, this would be done by setting in sshd_config AuthenticationMethods "publickey,publickey". A…
CWE: CWE-304
NVD

HIGH
CVE-2026-102827
CVE-2026-102827
pkg: node

published: Sep 29, 2026

simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 4.0.0, the default blockUnsafeOperationsPlugin compares parsed option names with literal dangerous option spellings while Git accepts unambiguous lon…
CWE: CWE-77, CWE-88
NVD

HIGH
CVE-2026-102826
CVE-2026-102826
pkg: node

published: Sep 29, 2026

simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 4.0.0, the default blockUnsafeOperationsPlugin does not completely reject configuration includes supplied through customArgs to git.clone(). The miss…
CWE: CWE-77, CWE-78
NVD

HIGH
CVE-2026-95301
CVE-2026-95301
pkg: google chrome

published: Sep 29, 2026

Missing authorization in Extensions in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-862
NVD

HIGH
CVE-2026-93355
CVE-2026-93355
pkg: jwt

published: Sep 28, 2026

LiteLLM contains a weak authentication vulnerability that allows an attacker holding a valid JWT from the configured identity provider to authenticate as any existing user by exploiting an email-based fallback lookup in the JWT authentication flow without verifying the email_verified claim. Attacker…
CWE: CWE-1390
NVD

HIGH
CVE-2026-93348
CVE-2026-93348
pkg: python

published: Sep 28, 2026

Unsloth Zoo versions 2025.9.9 before 2026.8.14, as implemented in Unsloth 2025.9.9 through 2026.8.19, contains a code injection vulnerability in the model-loading compile path where the get_transformers_model_type() function in hf_utils.py collects model_type values from nested model configurations …
CWE: CWE-94
GitHub-GHSA

HIGH
virtualenv bash and fish activation scripts execute commands embedded in paths
GHSA-p58f-9548-mpm2
pkg: virtualenv
eco: pip
published: Oct 1, 2026
### Impact

The generated `activate` (bash/zsh) and `activate.fish` scripts interpolate a `shlex.quote`-ed value into a position that quotes it a second time. The extra quotes terminate the quoted run early and leave part of the value parsed as shell code, so a path containing shell metacharacters r…

CVE-2026-102925
NVD

HIGH
CVE-2026-47530
CVE-2026-47530
pkg: linux

published: Sep 30, 2026

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and da…
CWE: CWE-787
NVD

HIGH
CVE-2026-47528
CVE-2026-47528
pkg: linux

published: Sep 30, 2026

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the firmware where an attacker could cause an access of an uninitialized pointer. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, …
CWE: CWE-824
NVD

HIGH
CVE-2026-47523
CVE-2026-47523
pkg: linux

published: Sep 30, 2026

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and da…
CWE: CWE-787
NVD

HIGH
CVE-2026-47521
CVE-2026-47521
pkg: linux

published: Sep 30, 2026

NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tamp…
CWE: CWE-125
NVD

HIGH
CVE-2026-47520
CVE-2026-47520
pkg: linux

published: Sep 30, 2026

NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tamp…
CWE: CWE-125
NVD

HIGH
CVE-2026-47519
CVE-2026-47519
pkg: linux

published: Sep 30, 2026

NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tamp…
CWE: CWE-125
NVD

HIGH
CVE-2026-47516
CVE-2026-47516
pkg: linux

published: Sep 30, 2026

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where an unprivileged user could cause a use-after-free. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
CWE: CWE-416
NVD

HIGH
CVE-2026-47514
CVE-2026-47514
pkg: linux

published: Sep 30, 2026

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause exposure of kernel stack contents including return addresses and pointers. A successful exploit of this vulnerability might lead to code execution, denial of service, escalatio…
CWE: CWE-200
NVD

HIGH
CVE-2026-47513
CVE-2026-47513
pkg: linux

published: Sep 30, 2026

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an out-of-bounds read from kernel heap memory. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information…
CWE: CWE-125
NVD

HIGH
CVE-2026-47512
CVE-2026-47512
pkg: linux

published: Sep 30, 2026

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an out-of-bounds read leading to kernel information disclosure. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privil…
CWE: CWE-125
NVD

HIGH
CVE-2026-47511
CVE-2026-47511
pkg: linux

published: Sep 30, 2026

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data t…
CWE: CWE-787
NVD

HIGH
CVE-2026-47510
CVE-2026-47510
pkg: linux

published: Sep 30, 2026

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an integer overflow leading to an out-of-bounds write to GPU memory. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of p…
CWE: CWE-190
NVD

HIGH
CVE-2026-47508
CVE-2026-47508
pkg: linux

published: Sep 30, 2026

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an incorrect conversion between numeric types. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information…
CWE: CWE-681
NVD

HIGH
CVE-2026-47507
CVE-2026-47507
pkg: linux

published: Sep 30, 2026

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an out-of-bounds array access. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and…
CWE: CWE-129
NVD

HIGH
CVE-2026-47505
CVE-2026-47505
pkg: windows

published: Sep 30, 2026

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer where an attacker could cause a use-after-free. A successful exploit of this vulnerability might lead to code execution, denial of service, or escalation of privileges, information disclosure, and data tampering.
CWE: CWE-416
NVD

HIGH
CVE-2026-47504
CVE-2026-47504
pkg: linux

published: Sep 30, 2026

NVIDIA Linux GPU Display Driver contains a vulnerability in the NGX updater where an outdated embedded cryptographic library is susceptible to type confusion. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, or data tampering.
CWE: CWE-843
NVD

HIGH
CVE-2026-47503
CVE-2026-47503
pkg: linux

published: Sep 30, 2026

NVIDIA GPU Display Driver for Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a guest VM user may cause an out-of-bounds write by sending a crafted RPC message with invalid performance state list size parameters. A successful exploit of this vulnerability might lead to…
CWE: CWE-787
NVD

HIGH
CVE-2026-47502
CVE-2026-47502
pkg: linux

published: Sep 30, 2026

NVIDIA vGPU Virtual GPU Manager for Windows and Linux contains a vulnerability in the kernel mode layer, where a guest user could cause an integer overflow leading to memory corruption. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileg…
CWE: CWE-190
NVD

HIGH
CVE-2026-47501
CVE-2026-47501
pkg: linux

published: Sep 30, 2026

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a user could cause an out-of-bounds write by supplying mismatched memory buffers during event buffer setup. A successful exploit of this vulnerability might lead to code execution, denial of service, escalati…
CWE: CWE-787
NVD

HIGH
CVE-2026-47500
CVE-2026-47500
pkg: linux

published: Sep 30, 2026

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where improper cleanup of reference counts during error paths could lead to a use-after-free condition. A successful exploit of this vulnerability might lead to code execution, denial of service, escala…
CWE: CWE-416
NVD

HIGH
CVE-2026-47499
CVE-2026-47499
pkg: linux

published: Sep 30, 2026

NVIDIA vGPU Virtual GPU Manager for Windows and Linux contains a vulnerability in the kernel mode layer where a guest could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and d…
CWE: CWE-125
NVD

HIGH
CVE-2026-47495
CVE-2026-47495
pkg: linux

published: Sep 30, 2026

NVIDIA vGPU Virtual GPU Manager for Windows and Linux contains a vulnerability in the kernel mode layer where a user could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and d…
CWE: CWE-787
NVD

HIGH
CVE-2026-47494
CVE-2026-47494
pkg: linux

published: Sep 30, 2026

NVIDIA GPU Display Driver for Linux contains a vulnerability where a user might be able to cause a format string issue. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
CWE: CWE-134
NVD

HIGH
CVE-2026-47493
CVE-2026-47493
pkg: linux

published: Sep 30, 2026

NVIDIA vGPU software for Windows and Linux contains a vulnerability in the GPU kernel driver where a guest may access privileged host GPU resources for which it is not authorized. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denia…
CWE: CWE-862
NVD

HIGH
CVE-2026-47491
CVE-2026-47491
pkg: linux

published: Sep 30, 2026

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user can cause improper release of memory resources, leaving a mapping accessible after the underlying memory is reused. A successful exploit of this vulnerability might lead to code execution…
CWE: CWE-404
NVD

HIGH
CVE-2026-47489
CVE-2026-47489
pkg: linux

published: Sep 30, 2026

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where permissions on read-only memory might not be preserved. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data t…
CWE: CWE-281
NVD

HIGH
CVE-2026-103106
CVE-2026-103106
pkg: node

published: Sep 30, 2026

Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation within an internal Pexip Infinity service that allows an attacker with local access to escalate privileges to root. Exploitation requires an attacker to be able to run arbitrary code on a node by either a…
CWE: CWE-669
NVD

HIGH
CVE-2026-102925
CVE-2026-102925
pkg: python

published: Sep 29, 2026

virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.13, the generated activate (bash and zsh) and activate.fish scripts place values already escaped by shlex.quote inside an additional quoted context. In the bash and zsh script, a crafted virtual environment path re…
CWE: CWE-78
NVD

HIGH
CVE-2026-95298
CVE-2026-95298
pkg: google chrome

published: Sep 29, 2026

Use after free in Browser in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-92368
CVE-2026-92368
pkg: linux

published: Sep 29, 2026

TeamViewer Full Client and Host for Linux and macOS prior version 15.82 contain a heap-based buffer overflow vulnerability in the processing of .tvs session recording files. A size mismatch during decompression of recorded session data can result in out-of-bounds heap writes. By convincing a user to…
CWE: CWE-122
NVD

HIGH
CVE-2026-19743
CVE-2026-19743
pkg: linux

published: Sep 29, 2026

Improper path validation in the local IPC service of TeamViewer Full Client and Host on Windows, Linux, and macOS prior to version 15.82 allows a local authenticated user with low privileges to perform arbitrary file writes with elevated privileges (NT AUTHORITY/SYSTEM \ root). By sending crafted IP…
CWE: CWE-22
GitHub-GHSA

HIGH
Trigger.dev: Cross-tenant SQL injection in the TSQL query compiler (POST /api/v1/query) via unsanitized window-function name
GHSA-9q4r-4842-93vw
pkg: trigger.dev
eco: npm
published: Oct 2, 2026
### Summary

A cross-tenant SQL injection in the TSQL query compiler lets **any authenticated trigger.dev customer read every other tenant's analytics data**. The customer-facing query endpoint `POST /api/v1/query` accepts a TSQL/TRQL query that is compiled to ClickHouse SQL by `internal-packages/ts…

GitHub-GHSA

HIGH
Trigger.dev: Server-side request forgery via unvalidated webhook alert-channel URL
GHSA-xxv7-2vv3-h682
pkg: trigger.dev
eco: npm
published: Oct 2, 2026
### Summary
A project member can create a webhook alert channel whose delivery URL points at an internal address, and trigger.dev's control plane will send the alert there with no SSRF protection. The webhook URL is stored as an unvalidated string and is fetched directly from the webapp server, so a…
NVD

HIGH
CVE-2026-86158
CVE-2026-86158
pkg: oauth

published: Sep 29, 2026

Missing authentication in the local .NET backend (Fiddler.WebUi) of Progress Software Fiddler Everywhere 8.0.2 allows a local unauthenticated attacker to mint OAuth tokens and read the machine-in-the-middle root certificate through an unauthenticated localhost HTTP and SignalR RPC channel.
CWE: CWE-306
NVD

HIGH
CVE-2026-97335
CVE-2026-97335
pkg: linux

published: Sep 28, 2026

Incorrect authorization in the custom storage volume creation endpoint in Canonical LXD versions 5.0.0 and later (fixed in 5.0.10, 5.21.8 and 6.10) on Linux allows an authenticated client with permission to create custom volumes in a project to copy, and so read, any custom storage volume from any o…
CWE: CWE-863
NVD

HIGH
CVE-2026-103111
CVE-2026-103111
pkg: express

published: Sep 30, 2026

PCRE2 before 10.49, when there is an attacker-controlled regular expression and certain JIT API usage, allows an out-of-bounds write with arbitrary data.
CWE: CWE-787
NVD

HIGH
CVE-2026-105314
CVE-2026-105314
pkg: python

published: Oct 5, 2026

Papermerge 3.5.3 allows remote code execution by a standard user via directory traversal in a /api/documents/upload call. A Python .pth file can be written to site-packages, and its code is executed upon the next start of the Python interpreter.
CWE: CWE-24
NVD

HIGH
CVE-2026-105295
CVE-2026-105295
pkg: ssl

published: Oct 5, 2026

GitAhead 2.5.0 through 2.7.1 contains an insecure update mechanism that installs downloaded updates without integrity or signature verification and permanently ignores TLS errors after one SSL error dialog. Network attackers presenting an invalid certificate once can intercept later automatic update…
CWE: CWE-494
NVD

HIGH
CVE-2026-105219
CVE-2026-105219
pkg: express

published: Oct 4, 2026

Mammoth.js 1.3.0 before 1.12.3 contains a regular expression denial of service vulnerability in the style map tokeniser in lib/styles/parser/tokeniser.js due to overlapping regex alternatives. Attackers can supply a crafted .docx with an unterminated quoted string of repeated backslash escapes in ma…
CWE: CWE-1333
GitHub-GHSA

HIGH
probe-image-size: Quadratic-time Denial of Service in the SVG Parser
GHSA-gjj5-9665-rwrc
pkg: probe-image-size
eco: npm
published: Oct 2, 2026
## Overview

`probe-image-size` scans the SVG header with a searching regular expression, `/<[-_.:a-zA-Z0-9][^>]*>/`. On input that contains many `<` characters but no `>`, the engine restarts the `[^>]*` scan at every `<` position and runs to end of input each time, giving quadratic time complexity…

CVE-2026-104861
GitHub-GHSA

HIGH
@fastify/busboy vulnerable to Denial of Service via prototype-named multipart part header
GHSA-x8mw-p69m-v3mx
pkg: @fastify/busboy
eco: npm
published: Oct 2, 2026
### Impact

Versions of `@fastify/busboy` from 1.0.0 and prior to 3.2.1 are vulnerable to a Denial of Service. The multipart header parser stores part-header names on a plain JavaScript object, so a part header named `__proto__` or `constructor` resolves to an inherited value that is not an array, a…

CVE-2026-19481
GitHub-GHSA

HIGH
@fastify/busboy vulnerable to Denial of Service via oversized multipart boundary
GHSA-xjh9-v7x6-24jw
pkg: @fastify/busboy
eco: npm
published: Oct 2, 2026
### Impact

Versions of `@fastify/busboy` from 3.1.0 and prior to 3.2.1 are vulnerable to a Denial of Service. The vendored streaming multipart search stores its default skip distance in a `Uint8Array(256)`. A multipart boundary of exactly 252 bytes makes the search needle 256 bytes, and the table e…

CVE-2026-19484
GitHub-GHSA

HIGH
Praxis affected by HTTP/2 Bomb
GHSA-cjcg-cxmh-9wcr
pkg: praxis-proxy
eco: rust
published: Oct 2, 2026
### Summary

Multiple denial-of-service vulnerabilities have been discovered in HTTP/2 server implementations. All have been rated with a severity impact of [Important](https://access.redhat.com/security/updates/classification). The vulnerabilities target HPACK, the header compression scheme in HTTP…

GitHub-GHSA

HIGH
SiYuan: 17 block metadata/content endpoints in kernel/api/block.go have zero publish-access filtering, reachable by anonymous publish-mode readers
GHSA-4vpg-gwqq-w44c
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: Oct 2, 2026
Same CWE-862 family, found via an automated bulk sweep of every
`/api/block/*` handler in `kernel/api/block.go` for the presence of any
access-check reference (`IsReadOnlyRoleContext`, `checkBlockPublishAccess`,
`GetPublishAccess`) anywhere in the function body. 17 of 28 candidate
endpoints have non…
CVE-2026-74904
GitHub-GHSA

HIGH
aws-smithy-json: Uncontrolled recursion in the aws-smithy-json unknown-key skip path allows unauthenticated remote denial of service in smithy-rs generated servers
GHSA-8ffr-xgwf-xj56
pkg: aws-smithy-json
eco: rust
published: Oct 2, 2026
### Summary
Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists which allows uncontrolled recursion in the unknown-key skip path of the A…
CVE-2026-18140
GitHub-GHSA

HIGH
Vibe-Trading file-read tools expose arbitrary server-readable files
GHSA-5rmq-chc7-m22f
pkg: vibe-trading-ai
eco: pip
published: Oct 2, 2026
### Summary:
2 findings — `safe_user_path()` accepts any path under `Path.home()` or `Path.cwd()`, which inside the shipped root container resolves to `/root` and `/app` (so all of root's home, including `/root/.ssh/id_rsa`, `/root/.aws/credentials`, `/root/.kube/config`, and `/app/agent/.env`, p…
NVD

HIGH
CVE-2026-104861
CVE-2026-104861
pkg: express

published: Oct 2, 2026

probe-image-size gets image dimensions without downloading the entire file. Prior to 7.4.0, lib/parse_sync/svg.js and lib/parse_stream/svg.js use the searching regular expression /<[-_.:a-zA-Z0-9][^>]*>/, which repeatedly scans to the end of input when attacker-controlled data contains many less-tha…
CWE: CWE-400, CWE-1333
NVD

HIGH
CVE-2026-67989
CVE-2026-67989
pkg: express

published: Oct 2, 2026

crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in Mistral model capability matching on Ruby 3.1.x
CWE: CWE-1333
NVD

HIGH
CVE-2026-86344
CVE-2026-86344
pkg: tls

published: Oct 1, 2026

A flaw was found in 389-ds-base. An unauthenticated remote attacker can send a complete LDAP operation followed by the first bytes of an incomplete LDAPMessage on the same connection, causing the server to hand that connection to a second worker thread before the first worker's result is flushed. Th…
CWE: CWE-400
NVD

HIGH
CVE-2026-104020
CVE-2026-104020
pkg: python

published: Oct 1, 2026

Uncontrolled recursion in the Ion reader in Amazon Ion Python before 0.15.0 might allow a remote unauthenticated actor to crash the application using the library, resulting in a denial of service, via a crafted, deeply nested Ion value.

To remediate this issue, users should upgrade to version 0.1…

CWE: CWE-674
NVD

HIGH
CVE-2026-79896
CVE-2026-79896
pkg: tls

published: Oct 1, 2026

Fortra BoKS Manager contains an out-of-bounds read vulnerability in the custom TLS ClientHello parser used by boks_portmux. A remote unauthenticated attacker can submit a malformed ClientHello and terminate boks_portmux. Although the daemon is normally restarted automatically, repeated requests can …
CWE: CWE-125
GitHub-GHSA

HIGH
jackson-core: UTF8DataInputJsonParser._reportInvalidToken() missing maxErrorTokenLength limit -> unbounded StringBuilder growth (DoS)
GHSA-7hhh-6rmp-j9qf
pkg: com.fasterxml.jackson.core:jackson-core, com.fasterxml.jackson.core:jackson-core, tools.jackson.core:jackson-core
eco: maven
published: Oct 1, 2026
## Status

**FULLY REPRODUCED.** A malformed token fed through `createParser(DataInput)` produced a
20,000,109-character exception message from a 20-million-character attacker payload, while the
identical payload fed through `createParser(InputStream)` produced a correctly bounded
367-character mess…

CVE-2026-89425
GitHub-GHSA

HIGH
jackson-core: ReDoS: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber()
GHSA-p6pp-m3f8-5c89
pkg: com.fasterxml.jackson.core:jackson-core, com.fasterxml.jackson.core:jackson-core, com.fasterxml.jackson.core:jackson-core
eco: maven
published: Oct 1, 2026
## Status

**FULLY REPRODUCED** with a clean, textbook empirical signature: measured runtime grew almost
exactly 4x for every doubling of input size across five consecutive doublings (5,000 → 160,000
characters), confirming O(n²) behavior. A single 160,000-character string (smaller than a typical…

CVE-2026-89407
GitHub-GHSA

HIGH
devalue: `stringify`/`uneval` serialize shared memory
GHSA-j22f-vq7h-c4qm
pkg: devalue
eco: npm
published: Oct 1, 2026
### Impact

`stringify` and `uneval` serialize a typed array by emitting its backing `ArrayBuffer`, not just the view. In the case of a Node `Buffer` object, the backing buffer is a process-wide shared pool, meaning unrelated memory can be serialized into a response that is then sent to the client. …

CVE-2026-92708
NVD

HIGH
CVE-2026-103262
CVE-2026-103262
pkg: curl

published: Oct 1, 2026

Tornado versions before 6.5.9 contain an unbounded memory accumulation vulnerability in CurlAsyncHTTPClient that allows remote attackers to cause denial of service by sending a compressed response. Attackers can send a gzip-encoded decompression bomb that accumulates in memory without size limits, c…
CWE: CWE-409
GitHub-GHSA

HIGH
tornado: CurlAsyncHTTPClient enforces no response-size limit — decompression bomb drives unbounded memory accumulation to OOM
GHSA-chx6-46f5-w4vp
pkg: tornado
eco: pip
published: Sep 30, 2026
An unbounded memory accumulation (decompression bomb) in `tornado.curl_httpclient.CurlAsyncHTTPClient` — the client-side sibling gap of CVE-2026-49855 — verified end-to-end on the 2026-08-15 master snapshot (`6.6.dev1`) and present unchanged in the latest release tag `v6.5.8` and on master (chec…
GitHub-GHSA

HIGH
fastify vulnerable to authentication bypass via malformed URLs reaching encapsulated not-found handlers
GHSA-p68q-wchp-6fh7
pkg: fastify
eco: npm
published: Sep 30, 2026
### Impact

Fastify routes a malformed URL under one plugin prefix to the custom not-found handler of a different sibling plugin, invoking the handler registered last and skipping the `preHandler` declared in its `setNotFoundHandler()`. When the request method has no route in the main router, a malf…

CVE-2026-76169
GitHub-GHSA

HIGH
fastify vulnerable to request validation bypass via skipped boolean false schemas
GHSA-hwr6-493r-vm6h
pkg: fastify
eco: npm
published: Sep 30, 2026
### Impact

Fastify decided whether to validate a request part by checking its schema for JavaScript truthiness. JSON Schema Draft 7 defines the boolean `false` as a valid schema that rejects every instance, but because `false` is falsy, a route that set `body`, `querystring`, `params`, or `headers`…

CVE-2026-84469
GitHub-GHSA

HIGH
fastify vulnerable to header validation bypass via incomplete schema case normalization
GHSA-9q9j-q6p8-xq58
pkg: fastify
eco: npm
published: Sep 30, 2026
### Impact

Fastify lowercases header-schema property names before compiling the schema, because Node.js stores request header names in lowercase. That normalization was incomplete: it lowercased only top-level `properties` keys and the root `required` array, and did not lowercase the JSON Schema Dr…

CVE-2026-84428
GitHub-GHSA

HIGH
GitPython: Denial of Service via catastrophic backtracking (ReDoS) in Actor.name_email_regex — commit author/committer field parsing
GHSA-g5vv-9gxw-82hx
pkg: GitPython
eco: pip
published: Sep 30, 2026
### Summary

GitPython's `Actor.name_email_regex` regular expression (`git/util.py`, line 863)
is vulnerable to catastrophic backtracking (ReDoS — Regular Expression Denial of
Service). When GitPython parses the `author` or `committer` header of a git commit
object that contains a long string with…

CVE-2026-87819
GitHub-GHSA

HIGH
russh: Client-side channel-scoped Handler callbacks fire for channel IDs the client never opened
GHSA-47hw-gvq5-r2gm
pkg: russh
eco: rust
published: Sep 30, 2026
### Summary
CVE-2026-68930 was fixed by adding `Session::is_established_channel()` in `russh/src/server/encrypted.rs`, which gates every channel-scoped SERVER-side message (CHANNEL_REQUEST, CHANNEL_DATA, CHANNEL_EOF, CHANNEL_CLOSE, CHANNEL_WINDOW_ADJUST, CHANNEL_EXTENDED_DATA) on `enc.channels.get(&…
CVE-2026-102823
NVD

HIGH
CVE-2026-51853
CVE-2026-51853
pkg: python

published: Sep 30, 2026

agent-zero 1.7, 1.8, 1.9, and 1.10 is vulnerable to Directory Traversal in python/helpers/file_browser.py:FileBrowser.__init__. The FileBrowser class initializes with the host root directory as the workspace, allowing the agent to access any file on the system without restriction.
CWE: CWE-22
NVD

HIGH
CVE-2026-101884
CVE-2026-101884
pkg: node

published: Sep 30, 2026

OpenClaw Windows Node before 2026.7.1 contains an incomplete environment-variable sanitizer in system.run that fails to block GIT_CONFIG_*, DOTNET_STARTUP_HOOKS, and JAVA_TOOL_OPTIONS variables. Attackers with gateway or agent access can supply these variables to allowlisted tools like git, dotnet, …
CWE: CWE-184
GitHub-GHSA

HIGH
jackson-databind quadratic forward-reference completion
GHSA-cxp5-3px4-pw24
pkg: com.fasterxml.jackson.core:jackson-databind, tools.jackson.core:jackson-databind, tools.jackson.core:jackson-databind
eco: maven
published: Sep 30, 2026
### Summary

When an `@JsonIdentityInfo` collection or map first creates N unresolved
object-ID references and later resolves the same IDs in reverse order,
jackson-databind scans the remaining pending-reference accumulator for each
resolution. A shallow JSON document whose size grows linearly can t…

CVE-2026-91777
GitHub-GHSA

HIGH
jackson-databind retains every unknown raw type ID
GHSA-wv8q-qhhj-9h54
pkg: com.fasterxml.jackson.core:jackson-databind, com.fasterxml.jackson.core:jackson-databind, com.fasterxml.jackson.core:jackson-databind
eco: maven
published: Sep 30, 2026
### Summary

With `@JsonTypeInfo(use = Id.NAME, defaultImpl = …)`, every distinct unknown
raw type ID selects the same fallback deserializer but is retained as a
separate key in `TypeDeserializerBase._deserializers`. An attacker who can
repeatedly supply new unknown type IDs can grow this process-…

CVE-2026-91776
GitHub-GHSA

HIGH
Nodemailer addressparser: O(n^2) on comment-joined addresses enables a remote DoS (reachable via mailparser)
GHSA-prgh-xp8r-p3m5
pkg: nodemailer
eco: npm
published: Sep 30, 2026
### Summary

`nodemailer/lib/addressparser` parses one shape of address in O(n^2) time. A single ~640 KB address value blocks the Node.js event loop for roughly 7 seconds. And it is reachable without auth: mailparser feeds inbound email headers straight into this parser, so one crafted email is enou…

NVD

HIGH
CVE-2026-96818
CVE-2026-96818
pkg: express

published: Sep 30, 2026

Unauthenticated Broken Access Control in WP Express Checkout (Accept PayPal Payments) <= 2.4.9 versions.
CWE: CWE-862
NVD

HIGH
CVE-2026-103055
CVE-2026-103055
pkg: jwt

published: Sep 30, 2026

AiSOC versions 7.5.0 before 12.0.0 use a hard-coded constant for JWT verification in the realtime WebSocket and SSE service when the AISOC_REALTIME_JWT_SECRET environment variable is not set. Unauthenticated attackers can forge subscription tickets with arbitrary tenant identifiers to access cross-t…
CWE: CWE-321
GitHub-GHSA

HIGH
Nest: Remote process termination via a deeply nested microservice message pattern
GHSA-m8vh-jmq9-5rjg
pkg: @nestjs/microservices, @nestjs/microservices
eco: npm
published: Sep 29, 2026
| Field | Value |
| — | — |
| Ecosystem | npm |
| Package | `@nestjs/microservices` |
| Affected versions | `>= 12.0.0, < 12.0.2` and `< 11.2.4` |
| Patched versions | `12.0.2` and `11.2.4` (upgrade to `12.0.3` / `11.2.5`) |

### Summary

A single message whose `pattern` is a deeply nested objec…

CVE-2026-102281
GitHub-GHSA

HIGH
brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion
GHSA-qhr7-859c-m2p7
pkg: brace-expansion, brace-expansion, brace-expansion
eco: npm
published: Sep 29, 2026
### Summary

`expand_()` recurses once per level of brace *nesting*. Deeply nested input exhausts the native stack and crashes the process.

This is distinct from CVE-2026-14257 / GHSA-mh99-v99m-4gvg, which made the *tail* iterative (recursion on `m.post`, driven by how many groups are chained). Nes…

CVE-2026-102278
GitHub-GHSA

HIGH
brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion
GHSA-6j4f-fj2g-mc7p
pkg: brace-expansion, brace-expansion, brace-expansion
eco: npm
published: Sep 29, 2026
### Summary

`parseCommaParts()` can exhaust the native stack and crash the process. There are two distinct ways to trigger it, both reachable from a single untrusted pattern string.

This is the parsing-side counterpart to CVE-2026-14257 / GHSA-mh99-v99m-4gvg. That fix made `expand_()` iterative an…

CVE-2026-102276
GitHub-GHSA

HIGH
Socket.IO: Engine.IO Protocol Revision Mismatch DoS
GHSA-2gc4-cqfq-p2gv
pkg: engine.io
eco: npm
published: Sep 29, 2026
### Impact

A denial-of-service vulnerability exists in Engine.IO / Socket.IO servers that allow transport upgrades.

The Engine.IO protocol revision is negotiated during the initial handshake and stored on the session, but a newly-created transport, including a WebSocket upgrade transport, could in…

CVE-2026-102599
GitHub-GHSA

HIGH
Nodemailer: Quadratic backtracking in the addressparser free-text fallback allows remote denial of service
GHSA-v53p-9fqp-m79j
pkg: nodemailer
eco: npm
published: Sep 29, 2026
### Summary

When `addressparser` finds no address by its strict reading, it falls back to pulling one out of the free text with `/\s*\b[^@\s]+@[^\s]+\b\s*/`. That pattern backtracks quadratically: `[^@\s]+` is retried from every offset and rescans the run to the next `@` each time. A single header …

NVD

HIGH
CVE-2026-103043
CVE-2026-103043
pkg: express

published: Sep 29, 2026

anchorme through 3.0.8 contains a regular expression denial of service vulnerability in the IPv6 host extraction regex due to catastrophic backtracking. Attackers can supply specially crafted input strings with repeated patterns to cause exponential regex engine backtracking, blocking the Node.js ev…
CWE: CWE-1333
NVD

HIGH
CVE-2026-103042
CVE-2026-103042
pkg: node

published: Sep 29, 2026

LightLLM through 1.2.0 contains a memory exhaustion vulnerability in the NCCL control channel when started with –pd_trans_mode nccl, allowing unauthenticated attackers to exhaust KV-transfer worker memory. Attackers can call the exposed_set_value method to store unbounded key-value pairs without si…
CWE: CWE-770
GitHub-GHSA

HIGH
adm-zip: Unhandled error event in async DEFLATE decompression crashes Node.js process (DoS)
GHSA-8238-w5pm-2374
pkg: adm-zip
eco: npm
published: Sep 29, 2026
## Summary

Denial of Service in `adm-zip`'s async decompression API allows an unauthenticated attacker to crash the entire Node.js host process by supplying a single malformed ZIP file.

## Details

**Affected package**: adm-zip
**Affected versions**: at least 0.6.0 (current latest); likely all ver…

NVD

HIGH
CVE-2026-67987
CVE-2026-67987
pkg: express

published: Sep 29, 2026

crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains polynomial-time regular expression denial-of-service conditions in think-tag response parsing on Ruby 3.1.x. A malicious or anomalous model response containing many unterminated <think> tags can cause excessive CPU consumptio…
CWE: CWE-1333
GitHub-GHSA

HIGH
adm-zip: Decompression-bomb protection (fix for CVE-2026-39244) can be bypassed by declaring uncompressed size as 0
GHSA-rcw4-f5rp-g42v
pkg: adm-zip
eco: npm
published: Sep 29, 2026
**Affected package:** adm-zip (npm)
**Affected version:** 0.6.0

## Summary

The fix shipped for CVE-2026-39244 (`methods/inflater.js`) caps zlib's decompression output via `maxOutputLength: expectedLength`, where `expectedLength` is read directly from the ZIP entry's attacker-controlled "uncompress…

GitHub-GHSA

HIGH
undici vulnerable to Denial of Service via unrequested WebSocket subprotocol
GHSA-rfgv-xxqx-mfg5
pkg: undici, undici, undici
eco: npm
published: Sep 29, 2026
### Impact

The undici WebSocket client throws an uncaught `TypeError` during the opening handshake when a server's `101` response includes a `Sec-WebSocket-Protocol` header that the client never requested. The throw occurs in a `queueMicrotask` callback with no surrounding `try`/`catch`, so it prop…

CVE-2026-19534
NVD

HIGH
CVE-2026-95280
CVE-2026-95280
pkg: google chrome

published: Sep 29, 2026

Race condition in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-362
NVD

HIGH
CVE-2026-102758
CVE-2026-102758
pkg: tls

published: Sep 29, 2026

The `_nx_secure_x509_asn1_tlv_block_parse()` function parses ASN.1 TLV (tag-length-value) blocks out of DER-encoded data. It is the primitive underneath all X.509 certificate parsing in NetX Secure, and therefore runs on certificates supplied by a remote peer during the TLS handshake.

The functio…

CWE: CWE-126
NVD

HIGH
CVE-2026-102728
CVE-2026-102728
pkg: tls

published: Sep 29, 2026

Two client-side TLS/DTLS handshake parsers in NetX Secure read fields from a server-supplied message before validating that the message is long enough to contain them. Both are bounded out-of-bounds reads on a remotely reachable path, both are reached from a TLS or DTLS client connecting to a malici…
CWE: CWE-126
GitHub-GHSA

HIGH
joi: Quadratic regular-expression backtracking in `Joi.string().isoDate()`
GHSA-6h2x-m376-mqjq
pkg: joi, joi
eco: npm
published: Sep 29, 2026
### Impact
Any application that validates a user-supplied string with `Joi.string().isoDate()` can be stalled by a single request. One of the regular expressions the rule runs over the input was unanchored, so a valid ISO date followed by a long run of fractional-second digits made the regex engine …
NVD

HIGH
CVE-2026-84784
CVE-2026-84784
pkg: openssl

published: Sep 29, 2026

Issue summary: A malicious remote peer may flood the local QUIC
stack with NEW_CONNECTION_ID frames by avoiding a limit check on
how many connection IDs the remote QUIC stack can use.

Impact summary: The local QUIC stack sends a RETIRE_CONN_ID frame
for every NEW_CONNECTION_ID frame it receives. Th…

CWE: CWE-770
NVD

HIGH
CVE-2026-84783
CVE-2026-84783
pkg: tls

published: Sep 29, 2026

Issue summary: The first concurrent use of the same X.509 certificate by
several threads may cause its cached extension data to be freed while
another thread is still using it.

Impact summary: A remote, unauthenticated peer could crash a multi-threaded
TLS client, or a multi-threaded TLS server tha…

CWE: CWE-416
NVD

HIGH
CVE-2026-72897
CVE-2026-72897
pkg: ssl

published: Sep 29, 2026

Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a
connection to a different SSL_CTX part way through a handshake may access
memory beyond the end of an internal array if the replacement context knows
about more provider signature algorithms than the context the connection was
crea…
CWE: CWE-787
NVD

HIGH
CVE-2026-54873
CVE-2026-54873
pkg: openssl

published: Sep 29, 2026

Issue summary: QUIC process may keep memory for QUIC packet
buffer for much longer period than necessary.

Impact summary: Remote peer can exploit this vulnerability
by sending maliciously crafted packets, making the local
QUIC stack to keep the memory for packet buffers allocated.
The time for whic…

CWE: CWE-770
NVD

HIGH
CVE-2026-102600
CVE-2026-102600
pkg: node

published: Sep 29, 2026

Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 0.1.1, @socket.io/cluster-engine uses inherited object properties when looking up attacker-controlled session IDs in clustered deployments. Special property names such as __proto__ or constructor can resolve t…
CWE: CWE-20, CWE-1321
NVD

HIGH
CVE-2026-102281
CVE-2026-102281
pkg: node

published: Sep 28, 2026

Nest is a framework for building scalable Node.js server-side applications. Prior to 11.2.4 and 12.0.2, a single message with a deeply nested object in its pattern can terminate a NestJS microservice using the TCP or RabbitMQ transport. ServerTCP#handleMessage and ServerRMQ#handleMessage pass a clie…
CWE: CWE-248, CWE-674
NVD

HIGH
CVE-2026-102278
CVE-2026-102278
pkg: node

published: Sep 28, 2026

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.20, 2.1.6, 3.0.8, and 5.0.11, deeply nested brace groups cause expand_() to recurse once per nesting level at comma-member and single-set expansion sites, exhausting the native stack before ou…
CWE: CWE-400, CWE-674
NVD

HIGH
CVE-2026-102276
CVE-2026-102276
pkg: node

published: Sep 28, 2026

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.19, 2.1.5, 3.0.7, and 5.0.10, crafted brace patterns can exhaust the native stack in parseCommaParts because parseCommaParts recursively processes the remainder once per brace group and uses p…
CWE: CWE-400, CWE-674
GitHub-GHSA

HIGH
jackson-databind: Duration XMLGregorianCalendar Unbounded Number Parse DoS
GHSA-q4xh-88c3-wmh7
pkg: tools.jackson.core:jackson-databind, tools.jackson.core:jackson-databind, com.fasterxml.jackson.core:jackson-databind
eco: maven
published: Sep 28, 2026
### Summary
`jackson-databind` 3.2.1 deserializes a JSON **string** bound to a `javax.xml.datatype.Duration` or `javax.xml.datatype.XMLGregorianCalendar` field by passing the raw string verbatim to `DatatypeFactory.newDuration(value)` / `newXMLGregorianCalendar(value)`. Per the XML-Schema lexical gr…
CVE-2026-68497
NVD

HIGH
CVE-2026-105223
CVE-2026-105223
pkg: tls

published: Oct 5, 2026

maclof kubernetes-client 0.17.0 before 0.32.0 disables TLS certificate verification in parseKubeconfig() and parseKubeconfigFile() when a kubeconfig lacks certificate-authority-data, ignoring insecure-skip-tls-verify. On-path attackers can impersonate the Kubernetes API server to capture Bearer toke…
CWE: CWE-295
NVD

HIGH
CVE-2026-105222
CVE-2026-105222
pkg: ssl

published: Oct 4, 2026

The alexpechkarev/google-maps Laravel package through 12.16 disables TLS certificate verification by default because the bundled config sets ssl_verify_peer to FALSE, which is passed to CURLOPT_SSL_VERIFYPEER. On-path attackers can present any certificate to intercept Google Maps web-service request…
CWE: CWE-295
NVD

HIGH
CVE-2026-105221
CVE-2026-105221
pkg: oauth

published: Oct 4, 2026

The gist RubyGem before 6.1.0 contains an improper certificate validation vulnerability that allows on-path attackers to intercept HTTPS traffic because http_connection in lib/gist.rb sets VERIFY_NONE. Attackers can present any certificate to read or modify GitHub API traffic, stealing OAuth tokens …
CWE: CWE-295
NVD

HIGH
CVE-2026-105218
CVE-2026-105218
pkg: tls

published: Oct 4, 2026

gopay before 1.5.119 disables TLS certificate verification in defaultClient() in pkg/xhttp/client.go, allowing man-in-the-middle attackers to impersonate payment provider APIs. Attackers can present any certificate to read merchant credentials, signatures and transaction data, and modify payment, re…
CWE: CWE-295
NVD

HIGH
CVE-2026-105216
CVE-2026-105216
pkg: tls

published: Oct 4, 2026

go-micro before 6.0.0 contains an improper certificate validation vulnerability that allows network attackers to impersonate services because the shared TLS helper sets InsecureSkipVerify to true by default. Man-in-the-middle attackers can present any certificate to intercept or modify gRPC transpor…
CWE: CWE-295
NVD

HIGH
CVE-2026-15911
CVE-2026-15911
pkg: tls

published: Oct 1, 2026

Confluent Kafka Python client's HashiCorp Vault KMS integration could allow a remote attacker to obtain sensitive information due to improper TLS certificate validation.
CWE: CWE-295
NVD

HIGH
CVE-2026-103921
CVE-2026-103921
pkg: tls

published: Oct 1, 2026

GraphQL Tools provides utilities for building, stitching, and mocking GraphQL schemas. Prior to 1.1.35, the executor-legacy-ws buildWSLegacyExecutor() function hardcodes TLS certificate rejection off for Node.js connections to wss:// endpoints. Applications using the executor directly, or url-loader…
CWE: CWE-295
GitHub-GHSA

HIGH
@grpc/grpc-js: In certain configurations, getAuthContext can return unauthorized certificates as though they were authorized
GHSA-m9gg-hp2v-232j
pkg: @grpc/grpc-js, @grpc/grpc-js
eco: npm
published: Sep 30, 2026
### Impact
When server credentials are created with the `requireClientCertificate` option set to `false`, `getAuthContext` does not distinguish between authorized and unauthorized certificates in its return value. This can create improper authentication vulnerabilities for `@grpc/grpc-js` users who …
CVE-2026-101916
GitHub-GHSA

HIGH
@nestjs/platform-fastify: Path-scoped middleware bypass via absolute-form request targets
GHSA-9c5c-9qcx-q35q
pkg: @nestjs/platform-fastify, @nestjs/platform-fastify
eco: npm
published: Sep 30, 2026
| Field | Value |
| — | — |
| Ecosystem | npm |
| Package | `@nestjs/platform-fastify` |
| Affected versions | `>= 12.0.0, < 12.0.2` and `< 11.2.4` |
| Patched versions | `12.0.2` and `11.2.4` (upgrade to `12.0.3` / `11.2.5`) |

### Summary

On the Fastify adapter, an HTTP request that uses an *…

GitHub-GHSA

HIGH
PyJWT: PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation
GHSA-9j54-fg26-wv3r
pkg: PyJWT
eco: pip
published: Sep 29, 2026
### Summary

A service that verifies HS256 tokens using an empty oct JWK through PyJWK, including a PyJWK obtained from PyJWKSet, can therefore accept attacker-generated tokens as authenticated.

PyJWT 2.13.0 rejects an empty HMAC key when it is supplied through the raw `str`/`bytes` key path, but a…

CVE-2026-102266
GitHub-GHSA

HIGH
PyJWT accepts public JWK containers as HMAC secrets
GHSA-w2cx-738m-mc7w
pkg: PyJWT
eco: pip
published: Sep 29, 2026
### Summary

PyJWT 2.13.0 contains an incomplete defense against algorithm confusion when
an application mixes symmetric and asymmetric algorithms in one verification
path. A public RSA, EC, or OKP JWK can be accepted as an HMAC secret when it
is wrapped in a JWKS object, nested in an array, or repr…

CVE-2026-102273
GitHub-GHSA

HIGH
PyJWT: PyJWKClient follows redirects when fetching JWKS
GHSA-9v7f-9g4p-ffgj
pkg: PyJWT
eco: pip
published: Sep 29, 2026
### Summary

PyJWT 2.13.0 `PyJWKClient` followed HTTP redirects while fetching a JWKS,
without validating the redirect destination. A configured trusted endpoint
could therefore redirect the client to a different host.

### Impact

When an application uses `PyJWKClient` with caller-supplied request …

CVE-2026-102267
GitHub-GHSA

HIGH
PyJWT: Public keys in DER form are accepted as HMAC secrets, bypassing the CVE-2022-29217 guard
GHSA-p4g4-x82p-q773
pkg: pyjwt
eco: pip
published: Sep 29, 2026
### Summary

`HMACAlgorithm.prepare_key` blocks asymmetric keys from being used as HMAC secrets by searching for text markers only. It looks for `—–BEGIN` and for an `ssh-` prefix. The same key in DER form is binary ASN.1 and has neither marker, so it passes the check and is used as an HMAC secre…

CVE-2026-102271
GitHub-GHSA

HIGH
PyJWT BOM Bypass
GHSA-r6x4-923q-g947
pkg: PyJWT
eco: pip
published: Sep 29, 2026
## Affected Package

– **Package**: PyJWT (`pyjwt` on PyPI)
– **Repository**: https://www.google.com/url?q=https://github.com/jpadilla/pyjwt&source=gmail&ust=1781794518474000&sa=E
– **Affected version**: 2.13.0
– **Vulnerability class**: Algorithm confusion / patch bypass

—

## Root Cause

PyJWT …

CVE-2026-102272
GitHub-GHSA

HIGH
undici vulnerable to TLS certificate validation bypass via dropped connect options in BalancedPool
GHSA-w293-vg96-wgc3
pkg: undici, undici
eco: npm
published: Sep 29, 2026
### Impact

undici's `BalancedPool` passes its constructor options through a JSON-based deep clone (`JSON.parse(JSON.stringify(…))`) before forwarding them to each per-upstream `Pool`. JSON cannot represent functions, so a caller-supplied `connect` or `tls` option containing a `checkServerIdentity…

CVE-2026-84961
GitHub-GHSA

HIGH
undici vulnerable to cross-origin cache poisoning via missing origin isolation in interceptors
GHSA-vp8m-p9jh-q5pm
pkg: undici
eco: npm
published: Sep 29, 2026
## Impact

When `interceptors.cache()` or `interceptors.deduplicate()` is used with a dispatcher that does not carry a single authoritative origin, or when a request supplies its own `origin`, undici builds the cache and deduplication keys without the actual destination origin. If a cache store or i…

CVE-2026-85152
NVD

HIGH
CVE-2026-102334
CVE-2026-102334
pkg: nginx

published: Sep 28, 2026

Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers to make unlimited password guesses against any account. Attackers can brute-force login credentials via POST /api/tokens and subsequently guess TOTP codes via POST /api/tokens/2fa t…
CWE: CWE-307
NVD

HIGH
CVE-2026-102273
CVE-2026-102273
pkg: python

published: Sep 28, 2026

PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, PyJWT HMACAlgorithm.prepare_key is affected because HMAC key guard only recognizes top-level public JWK forms and misses container representations. This occurs when an application allows HMAC and asymmetric algor…
CWE: CWE-347
NVD

HIGH
CVE-2026-102272
CVE-2026-102272
pkg: jwt

published: Sep 28, 2026

PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, HMACAlgorithm.prepare_key in jwt/algorithms.py is affected because raw-JWK detector does not normalize accepted Unicode byte-order marks before checking for JSON. This occurs when a public JWK is prefixed with a …
CWE: CWE-347
NVD

HIGH
CVE-2026-102271
CVE-2026-102271
pkg: python

published: Sep 28, 2026

PyJWT is a Python implementation of JSON Web Token standards. From 2.4.0 until 2.14.0, PyJWT HMACAlgorithm.prepare_key is affected because asymmetric-key guard relies on textual markers that are absent from DER encoding. This occurs when an application mixes HMAC and asymmetric algorithms and suppli…
CWE: CWE-347
NVD

HIGH
CVE-2026-102267
CVE-2026-102267
pkg: python

published: Sep 28, 2026

PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT PyJWKClient is affected because redirect destinations are not revalidated against the JWKS trust boundary. This occurs when a configured trusted JWKS endpoint returns an attacker-influenced redirect. As a result, Py…
CWE: CWE-200, CWE-345, CWE-918
NVD

HIGH
CVE-2026-102266
CVE-2026-102266
pkg: python

published: Sep 28, 2026

PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, HMACAlgorithm.from_jwk is affected because PyJWK verification path used the decoded key without applying prepare_key validation. This occurs when a trusted JWK Set contains an oct entry with an empty k value. As …
CWE: CWE-347
NVD

HIGH
CVE-2026-105147
CVE-2026-105147
pkg: jwt

published: Oct 4, 2026

A vulnerability was determined in SciPhi-AI R2R up to 3.6.6. This affects an unknown part of the component JWT Secret Handler. This manipulation of the argument DEFAULT_BCRYPT_SECRET_KEY/DEFAULT_NACL_SECRET_KEY causes hard-coded credentials. The attack can be initiated remotely. The exploit has been…
CWE: CWE-259, CWE-798
NVD

HIGH
CVE-2026-47496
CVE-2026-47496
pkg: linux

published: Sep 30, 2026

NVIDIA GPU Display Driver for Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin) where a guest VM user may cause an out-of-bounds write by sending a specially crafted RPC call to the host. A successful exploit of this vulnerability might lead to escalation of privileges, data ta…
CWE: CWE-787
NVD

HIGH
CVE-2026-92873
CVE-2026-92873
pkg: node

published: Sep 30, 2026

Pgpool-II contains an incorrect implementation of an authentication algorithm, which may allow an unauthenticated attacker to promote an arbitrary watchdog node to the leader node.
CWE: CWE-303
NVD

HIGH
CVE-2026-102616
CVE-2026-102616
pkg: oauth

published: Sep 29, 2026

A vulnerability was detected in risesoft-y9 WorkFlow-Engine up to 9.6.10. Impacted is the function getByIdAndYear of the file CustomHistoricProcessServiceImpl.java of the component OAuth2 Resource Filter. Performing a manipulation of the argument year/processInstanceId results in sql injection. Remo…
CWE: CWE-74, CWE-89
NVD

HIGH
CVE-2026-92369
CVE-2026-92369
pkg: windows

published: Sep 29, 2026

TeamViewer Full Client and Host prior to version 15.82 on Windows contain a TOCTOU race condition in the installer rollback mechanism. A local low-privileged attacker can replace rollback backup files stored in a user-writable temporary directory before they are restored by an elevated installer, re…
CWE: CWE-367
NVD

HIGH
CVE-2026-101052
CVE-2026-101052
pkg: jwt

published: Sep 28, 2026

A security vulnerability has been detected in refly-ai refly up to 1.1.0. This issue affects some unknown processing of the file apps/api/src/modules/config/app.config.ts of the component JWT Token Handler. The manipulation with the input test leads to hard-coded credentials. It is possible to initi…
CWE: CWE-259, CWE-798
NVD

HIGH
CVE-2026-96566
CVE-2026-96566
pkg: curl

published: Oct 2, 2026

The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'np1' Custom Field Parameter in all versions up to, and including, 9.4.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated …
CWE: CWE-79
NVD

HIGH
CVE-2026-102142
CVE-2026-102142
pkg: express

published: Sep 30, 2026

A system notification template on the Kiteworks appliance was rendered by a template engine that evaluated expressions contained in the stored template body. An authenticated System Administrator could potentially store a crafted template that executed operating-system commands on the appliance when…
CWE: CWE-1336
NVD

HIGH
CVE-2026-102117
CVE-2026-102117
pkg: node

published: Sep 30, 2026

On deployments where the remote-support capability is licensed and enabled, an authenticated System Administrator who also possessed the key protecting the submitted data could redirect the underlying system's outbound support connection to a destination of their choosing. That destination could the…
CWE: CWE-807, CWE-940
NVD

HIGH
CVE-2026-102114
CVE-2026-102114
pkg: node

published: Sep 30, 2026

A command injection vulnerability in Kiteworks could allow a high-privileged authenticated administrator to execute arbitrary operating-system commands as root on the affected appliance node. Successful exploitation requires an administrative account with elevated privileges.
CWE: CWE-78
NVD

HIGH
CVE-2026-96815
CVE-2026-96815
pkg: vite

published: Sep 30, 2026

Custom role Privilege Escalation in Vitepos <= 3.5.0 versions.
CWE: CWE-266
NVD

HIGH
CVE-2026-12267
CVE-2026-12267
pkg: windows

published: Sep 28, 2026

ManageEngine DDI Central versions below 6201 are vulnerable to Command injection in Windows DNS Query Resolution Policy name field leading to remote code execution.
CWE: CWE-20
GitHub-GHSA

HIGH
Trigger.dev: Missing Authentication in Run Replay Action Allows Cross-Organization Task Execution (IDOR)
GHSA-pp95-gc86-jq6q
pkg: trigger.dev
eco: npm
published: Oct 2, 2026
### Summary

The run replay `action` function at `apps/webapp/app/routes/resources.taskruns.$runParam.replay.ts` has no authentication or authorization check. While the `loader` (GET) in the same file properly calls `requireUser(request)` and scopes queries to the user's organizations, the `action` …

GitHub-GHSA

HIGH
Trigger.dev: Run replay injects a task run into an attacker-chosen environment (cross-tenant write)
GHSA-qxpp-qjg8-x4jv
pkg: trigger.dev
eco: npm
published: Oct 2, 2026
### Summary
The dashboard replay action authorizes the source run (it must belong to the caller's org), but the target environment for the replayed run is taken verbatim from the request body and is never checked for org or project membership. The environment lookup used by the replay path filters b…
GitHub-GHSA

HIGH
adm-zip extraction preserves SUID/SGID bits from untrusted ZIPs -> local privilege escalation
GHSA-j5f4-cc29-5×44
pkg: adm-zip
eco: npm
published: Sep 29, 2026
## Summary

adm-zip applies the Unix permission bits stored in a zip entry directly to the extracted file via `fs.chmodSync()` when `keepOriginalPermission=true` is passed to `extractAllTo()`/`extractEntryTo()` — and it never filters the setuid/setgid/sticky bits out of those bits. A zip crafted b…

CVE-2026-102282
NVD

HIGH
CVE-2026-102335
CVE-2026-102335
pkg: nginx

published: Sep 28, 2026

Nginx Proxy Manager through 2.16.0 fails to restrict the advanced_config field to administrators, allowing non-admin users with manage permissions to inject arbitrary nginx directives. Attackers can inject malicious nginx configuration such as alias directives to serve arbitrary files or control rou…
CWE: CWE-863
NVD

HIGH
CVE-2026-87114
CVE-2026-87114
pkg: docker

published: Sep 28, 2026

A flaw was found in kube-compare. When processing a 'container://' reference path, the tool incorrectly executes an untrusted container image's entrypoint instead of merely extracting data from a stopped container. This allows a remote attacker to achieve arbitrary code execution on the operator's w…
CWE: CWE-829
NVD

HIGH
CVE-2026-92371
CVE-2026-92371
pkg: linux

published: Sep 29, 2026

TeamViewer Full Client and Host for Linux prior version 15.82 contains an improper path validation vulnerability in the Cloud Session Recording (CSR) functionality. By exploiting a race condition during path validation and subsequent file access, a local authenticated attacker may cause privileged f…
CWE: CWE-59
GitHub-GHSA

HIGH
Trigger.dev Self-Hosted Deployment: Default Secrets allow Unauthenticated Infrastructure Compromise
GHSA-pqxw-g93w-hj9x
pkg: trigger.dev
eco: npm
published: Oct 2, 2026
## Summary

Self-hosted trigger.dev v4 instances deployed using the provided Docker Compose configuration with default secrets from `hosting/docker/.env.example` are vulnerable to a multi-stage unauthenticated attack chain leading to complete infrastructure compromise.

## Vulnerability Details

The…

GitHub-GHSA

HIGH
figlet is vulnerable to denial of service via unbounded loop when whitespaceBreak is used with a small width
GHSA-62ch-8vmq-8xm7
pkg: figlet
eco: npm
published: Oct 2, 2026
### Impact
A denial-of-service (infinite loop) can occur in `text()` / `textSync()` when
**both**:
– `whitespaceBreak: true` is set, **and**
– `width` is set smaller than the rendered width of a single FIGlet character.
Under these conditions `breakWord()` could never find a valid break point, so th…
CVE-2026-96780
GitHub-GHSA

HIGH
Xray-core: Pinning a CA certificate via pinnedPeerCertSha256 can lead to the success of MITM attacks
GHSA-5wf9-h793-w73c
pkg: github.com/xtls/xray-core
eco: go
published: Oct 2, 2026
### Summary

Pinning a CA certificate via `pinnedPeerCertSha256` can lead to the success of MITM attacks in some cases.

### Details

https://github.com/XTLS/Xray-core/blob/45cf2898ab12e97a55dd8f1f3d78d903340bdc9e/transport/internet/tls/config.go#L333-L347

If `r.Config.ServerName` is empty, `DNSNam…

GitHub-GHSA

HIGH
Copernik XML Factory (stock JDK provider) has Improper restriction of XInclude resource resolution
GHSA-xm28-xvqc-gxxg
pkg: eu.copernik:copernik-xml-factory
eco: maven
published: Oct 2, 2026
Copernik XML Factory through `0.1.1`, when running on its stock JDK provider, does not block XInclude resource resolution after an application enables XInclude on a factory returned by `XmlFactories.newDocumentBuilderFactory()` or `XmlFactories.newSAXParserFactory()`, or on an `XMLReader` passed thr…
CVE-2026-61586
GitHub-GHSA

HIGH
devalue: Repeated primitive strings cause quadratic expansion in uneval
GHSA-mcm9-63f2-9j32
pkg: devalue
eco: npm
published: Oct 1, 2026
Under very constrained circumstances, data that was `parse`d and then passed to `uneval` could turn a small payload into a very large serialized string.
GitHub-GHSA

HIGH
devalue: stringifyAsync can cause an unhandled rejection despite a caught returned promise
GHSA-x5rw-q4pp-hg5g
pkg: devalue
eco: npm
published: Oct 1, 2026
When serializing multiple promises, a later promise can reject before an earlier one settles. An internal rejected promise remains unhandled even if the caller catches the returned `stringifyAsync` promise. Under Node's default unhandled-rejection behavior this can terminate the process. Application…
GitHub-GHSA

HIGH
virtualenv: Command injection via –prompt in activate.bat (batch activator)
GHSA-x78j-v8h9-3j2q
pkg: virtualenv
eco: pip
published: Oct 1, 2026
`BatchActivator.quote()` returned its input unchanged, the only activator with no escaping at all. `–prompt`, the `VIRTUALENV_PROMPT` environment variable, and the config file all set the prompt, and `activate.bat` writes it straight into `@set "VAR=value"`. A prompt containing a double quote close…
CVE-2026-102937
GitHub-GHSA

HIGH
pypdf: Possible long runtimes with large amount of embedded files
GHSA-v247-6f48-mgcj
pkg: pypdf
eco: pip
published: Oct 1, 2026
### Impact

An attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires accessing the embedded files through the dictionary-based API.

### Patches

This has been fixed in [pypdf==6.19.0](https://github.com/py-pdf/pypdf/releases/tag/6.19.0).

### Workarounds

…

CVE-2026-102999
GitHub-GHSA

HIGH
pypdf: Possible long runtimes when generating appearance streams
GHSA-php9-fj8v-98fj
pkg: pypdf
eco: pip
published: Oct 1, 2026
### Impact

An attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires updating form field values with flattening enabled, which triggers appearance stream generation.

### Patches

This has been fixed in [pypdf==6.19.0](https://github.com/py-pdf/pypdf/releas…

CVE-2026-102998
GitHub-GHSA

HIGH
pypdf: Possible large memory usage when retrieving alphabetical page labels
GHSA-w23x-9jrw-r45c
pkg: pypdf
eco: pip
published: Oct 1, 2026
### Impact

An attacker who uses this vulnerability can craft a PDF which leads to large memory consumption. This requires accessing the page labels of a document with large alphabetical labels.

### Patches

This has been fixed in [pypdf==6.19.0](https://github.com/py-pdf/pypdf/releases/tag/6.19.0)…

CVE-2026-103000
GitHub-GHSA

HIGH
pypdf: Possible long runtimes for partially malformed FlateDecode streams (Follow-up)
GHSA-jw7q-gvrg-4vj3
pkg: pypdf
eco: pip
published: Oct 1, 2026
### Impact

An attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires a partially malformed `/FlateDecode` stream, where the byte-by-byte decompression is used.

### Patches

This has been fixed in [pypdf==6.18.1](https://github.com/py-pdf/pypdf/releases/tag…

CVE-2026-102997
GitHub-GHSA

HIGH
pypdf: Possible large memory usage when parsing font data
GHSA-g9cg-prrw-2r8q
pkg: pypdf
eco: pip
published: Oct 1, 2026
### Impact

An attacker who uses this vulnerability can craft a PDF which leads to large memory consumption. This requires parsing the `/Widths` entry of a TrueType or Type1 fonts with unusually large values, for example during text extraction.

### Patches

This has been fixed in [pypdf==6.18.1](ht…

CVE-2026-102996
GitHub-GHSA

HIGH
pypdf: Possible large memory usage for large /ToUnicode streams (Follow-up 2)
GHSA-fp3h-c4fm-7vvf
pkg: pypdf
eco: pip
published: Oct 1, 2026
### Impact

An attacker who uses this vulnerability can craft a PDF which leads to large memory consumption. This requires parsing the `/ToUnicode` entry of a font with unusually large values, for example during text extraction.

### Patches

This has been fixed in [pypdf==6.18.1](https://github.com…

CVE-2026-102995
GitHub-GHSA

HIGH
pypdf: Possible long runtimes/large memory usage when parsing indirect objects
GHSA-5jq2-8×83-x246
pkg: pypdf
eco: pip
published: Oct 1, 2026
### Impact

An attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires reading a PDF document with long indirect object headers, not terminated by whitespace.

### Patches

This has been fixed in [pypdf==6.18.0](https://github.com/py-pdf/pypdf/releases/tag/6.…

CVE-2026-102994
GitHub-GHSA

HIGH
pypdf: Possible large memory usage when retrieving Roman page labels
GHSA-qv6h-rv94-w285
pkg: pypdf
eco: pip
published: Oct 1, 2026
### Impact

An attacker who uses this vulnerability can craft a PDF which leads to large memory consumption. This requires accessing the page labels of a document with large Roman numerals.

### Patches

This has been fixed in [pypdf==6.17.0](https://github.com/py-pdf/pypdf/releases/tag/6.17.0).

##…

CVE-2026-102993
GitHub-GHSA

HIGH
basic-ftp: Quadratic-time CPU denial of service in Client.list() Unix directory-listing parser (RE_LINE backtracking)
GHSA-c475-qrg2-pj4r
pkg: basic-ftp
eco: npm
published: Oct 1, 2026
## Summary

`Client.list()` parses the server's directory listing with the Unix-style parser in `parseListUnix.js`. Its `RE_LINE` regex has two adjacent `(\S+(?:\s\S+)*)` groups (owner name, then group name) followed by a required numeric size group. When a line starts with a valid listing prefix bu…

CVE-2026-102990
GitHub-GHSA

HIGH
virtualenv: Downloaded seed wheels (pip/setuptools) are not integrity-checked before use
GHSA-94p9-xgh2-xp45
pkg: virtualenv
eco: pip
published: Sep 30, 2026
`download_wheel()` runs `pip download` and hands the result straight to the seeder, with nothing checking the bytes it gets back. The embedded pip and setuptools wheels carry a `BUNDLE_SHA256` that virtualenv checks on every load, but a wheel fetched over the network for the periodic-update feature …
CVE-2026-102930
GitHub-GHSA

HIGH
Tornado: StaticFileHandler follows symlinks outside static root (path traversal)
GHSA-c2m8-h5v5-343r
pkg: tornado
eco: pip
published: Sep 30, 2026
### Summary
StaticFileHandler allows an unauthenticated attacker to read arbitrary files from the server's filesystem by requesting a path that resolves to a symbolic link placed inside the static root directory. Any application that serves user-uploadable content, or whose static directory is popul…
GitHub-GHSA

HIGH
Astro: Malformed port in the Host header can crash the Node adapter
GHSA-qh8j-hqjv-7m4x
pkg: @astrojs/node
eco: npm
published: Sep 30, 2026
## Summary

In the Astro Node adapter, a request whose `Host` header contains a malformed port (for example `example.com:65536` or `example.com:8080:8080`) produced an invalid request URL. The fallback intended to recover from an unparseable URL reused the same malformed host, so it failed again and…

CVE-2026-102984
GitHub-GHSA

HIGH
Angular Server-Side Rendering (SSR): Denial of Service via Numeric URL Matrix Parameters
GHSA-ff3f-86qr-9cv3
pkg: @angular/router, @angular/router, @angular/router
eco: npm
published: Sep 30, 2026
A denial of service (DoS) vulnerability was identified in `@angular/router` when Server-Side Rendering (SSR) is enabled on Node.js (V8).

When `@angular/router` parses incoming request URLs, it extracts path segments, matrix parameters, and child outlets into plain JavaScript objects (`Record<string…

CVE-2026-101896
GitHub-GHSA

HIGH
Axios: Node HTTP adapter prototype-pollution gadget allows request socket hijack via inherited createConnection
GHSA-m8m8-qj5v-23w3
pkg: axios
eco: npm
published: Sep 30, 2026
## Summary

Axios' Node HTTP adapter can act as a read-side prototype-pollution gadget for Node's sensitive `createConnection` request option. The adapter creates a null-prototype options object, but Node's HTTP client can copy or normalize request options into ordinary objects before connection cre…

CVE-2026-101905
GitHub-GHSA

HIGH
Axios: maxRedirects: 0 is not enforced by the fetch adapter, allowing redirect-based SSRF
GHSA-r4gj-5m52-g5wh
pkg: axios
eco: npm
published: Sep 30, 2026
## Summary

Axios exposes `maxRedirects` to limit redirect following, and `maxRedirects: 0` is used by applications as a redirect-based SSRF guard. The Node HTTP adapter enforces this option. The fetch adapter does not read it and does not set a Fetch API `redirect` mode, so the runtime default of `…

CVE-2026-101907
GitHub-GHSA

HIGH
Axios: ReDoS in fromDataURI data: URL parser freezes the Node event loop (DoS)
GHSA-c29m-xwm3-cm6r
pkg: axios
eco: npm
published: Sep 30, 2026
## Summary

Axios for Node.js parses `data:` URLs in `lib/helpers/fromDataURI.js`. The current RFC-2397 parser uses a regular expression whose media type groups allow `/` inside both sides of the `type/subtype` match. A malformed `data:` URL containing many slashes and no comma forces the JavaScript…

CVE-2026-101903
GitHub-GHSA

HIGH
Axios: ReDoS (O(N²)) in shouldBypassProxy host normalization, reachable via untrusted redirect Location
GHSA-mghh-pgcx-3jjj
pkg: axios
eco: npm
published: Sep 30, 2026
## Summary

Axios `shouldBypassProxy()` normalizes hostnames with `hostname.replace(/\.+$/, '')`. For a hostname shaped as many dots followed by a non-dot, the anchored regex can perform quadratic backtracking. Because axios re-evaluates proxy bypass rules for redirected requests, a malicious server…

CVE-2026-101906
GitHub-GHSA

HIGH
Axios: Prototype Pollution Gadget in axios toFormData Options
GHSA-x97p-jq2g-jp4f
pkg: axios, axios
eco: npm
published: Sep 30, 2026
## Summary

Axios form serialization reads `visitor`, `maxDepth`, `dots`, `indexes`, `metaTokens`, and `Blob` from an internal options object without own-property guards. When `Object.prototype` has been polluted elsewhere in the same process, those inherited values can change how axios serializes m…

CVE-2026-101909
GitHub-GHSA

HIGH
Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls
GHSA-3pq3-5fj3-cg6v
pkg: axios
eco: npm
published: Sep 30, 2026
## Summary

Axios for Node.js does not apply configured DNS lookup or proxy controls when a request uses `httpVersion: 2`. The HTTP/1 adapter path wraps and forwards `config.lookup`, builds normal request options, and applies proxy routing through `setProxy()`. The HTTP/2 path builds a session with …

CVE-2026-101898
GitHub-GHSA

HIGH
Axios: Denial of Service via Unhandled 'error' Event in HTTP/2 ClientHttp2Session Initialization
GHSA-542g-h47m-68v8
pkg: axios
eco: npm
published: Sep 30, 2026
## Summary

Axios versions with Node.js HTTP/2 support can terminate the caller’s process when a ClientHttp2Session emits an error event that is not handled by axios.

This affects applications that use the Node HTTP adapter with httpVersion: 2. A malicious, unavailable, or non-HTTP/2 endpoint can…

CVE-2026-101901
GitHub-GHSA

HIGH
urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory
GHSA-vxq7-64xx-v4gw
pkg: urllib3
eco: pip
published: Sep 30, 2026
## Impact

urllib3's [streaming API](https://urllib3.readthedocs.io/en/2.7.0/advanced-usage.html#streaming-and-i-o) is designed for efficiently handling large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. When decoding a [chunked-t…

CVE-2026-97689
GitHub-GHSA

HIGH
urllib3: HTTPS proxy TLS configuration may be ignored or overridden
GHSA-8988-9cw3-xx77
pkg: urllib3
eco: pip
published: Sep 30, 2026
## Impact

urllib3 supports configuring TLS independently for an HTTPS proxy and the target server.

`proxy_ssl_context`, `proxy_assert_hostname`, and `proxy_assert_fingerprint` configure the TLS connection to the proxy. `ssl_context` and the other target-specific TLS parameters configure the connec…

CVE-2026-97687
NVD

MEDIUM
CVE-2026-105119
CVE-2026-105119
pkg: oauth

published: Oct 3, 2026

OpenAM before 16.1.3 applies its OAuth2 Provider PKCE enforcement only to authorization requests whose response_type is exactly code, so codes issued through OpenID Connect hybrid flows (code token, code id_token, code token id_token) carry no bound challenge. An attacker who intercepts such a code …
CWE: CWE-285
GitHub-GHSA

MEDIUM
vm2: Incomplete nodejs.* symbol filtering lets sandbox override host WebStream state checks
GHSA-jf8q-945g-9q4c
pkg: vm2
eco: npm
published: Oct 1, 2026
## Summary

vm2 current head (`v3.11.5`, commit `7a1f5100b96f48d34e0fe104ab37c0acc5944f92`) still exposes registered Node.js internal symbols from host WebStream prototypes to sandbox code.

The prior `nodejs.*` symbol hardening blocks `Symbol.for('nodejs.<name>')` at the source, but the extraction …

CVE-2026-92952
GitHub-GHSA

MEDIUM
JupyterLab: Cross-site scripting (XSS) in JupyterLab via crafted language package (jupyterlab.json)
GHSA-3jqq-pw4j-pqcj
pkg: jupyterlab, jupyterlab, jupyterlite-core
eco: pip
published: Oct 1, 2026
## Description

A language pack ships a `Plural-Forms` header saying how the language counts, for example `nplurals=2; plural=(n != 1);`. JupyterLab turns that string into a function with `new Function`, so the header gets executed. The check that meant to keep it safe was a regular expression. The …

CVE-2026-102830
NVD

MEDIUM
CVE-2026-102830
CVE-2026-102830
pkg: express

published: Sep 29, 2026

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 3.0.0 until 4.5.11 and 4.6.4, and in JupyterLite Core 0.8.3 and earlier, the Plural-Forms header in a selected third-party language pack can append JavaScri…
CWE: CWE-79, CWE-94
GitHub-GHSA

MEDIUM
Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)
GHSA-xpv3-w29h-x7cv
pkg: oauthlib
eco: pip
published: Sep 29, 2026
## Summary

A timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation
of the Authorization Code Grant flow. The `code_challenge_method_plain` function
uses Python's standard `==` operator for string comparison instead of a
constant-time comparison function, potentially allo…

CVE-2026-49265
NVD

MEDIUM
CVE-2026-47538
CVE-2026-47538
pkg: windows

published: Sep 30, 2026

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the firmware where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tamper…
CWE: CWE-787
NVD

MEDIUM
CVE-2026-47533
CVE-2026-47533
pkg: windows

published: Sep 30, 2026

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an improper validation of an array index. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information …
CWE: CWE-129
NVD

MEDIUM
CVE-2026-47532
CVE-2026-47532
pkg: windows

published: Sep 30, 2026

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and da…
CWE: CWE-787
NVD

MEDIUM
CVE-2026-47529
CVE-2026-47529
pkg: linux

published: Sep 30, 2026

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering…
CWE: CWE-787
NVD

MEDIUM
CVE-2026-47527
CVE-2026-47527
pkg: linux

published: Sep 30, 2026

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the firmware where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tamperi…
CWE: CWE-125
NVD

MEDIUM
CVE-2026-47525
CVE-2026-47525
pkg: linux

published: Sep 30, 2026

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an improper validation of an array index. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information …
CWE: CWE-129
NVD

MEDIUM
CVE-2026-47524
CVE-2026-47524
pkg: linux

published: Sep 30, 2026

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and dat…
CWE: CWE-125
NVD

MEDIUM
CVE-2026-47522
CVE-2026-47522
pkg: linux

published: Sep 30, 2026

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause improper input validation. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and…
CWE: CWE-20
NVD

MEDIUM
CVE-2026-47515
CVE-2026-47515
pkg: linux

published: Sep 30, 2026

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an out-of-bounds read via an unbounded string operation. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, i…
CWE: CWE-125
NVD

MEDIUM
CVE-2026-47509
CVE-2026-47509
pkg: linux

published: Sep 30, 2026

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data t…
CWE: CWE-787
NVD

MEDIUM
CVE-2026-78229
CVE-2026-78229
pkg: linux

published: Sep 30, 2026

Image Scanner Driver for Linux contains an OS command injection vulnerability. An attacker who can log in to a Linux system where the affected product is installed may execute an arbitrary OS command by making certain preparations.
CWE: CWE-78
GitHub-GHSA

MEDIUM
Electron: Local race condition in Squirrel.Mac update installation on macOS
GHSA-vv43-5jgx-7qv8
pkg: electron, electron, electron
eco: npm
published: Sep 29, 2026
### Impact

On macOS, Electron bundles the Squirrel.Mac auto-update framework, whose privileged `ShipIt` helper performs the final step of an update as root. A local attacker could cause that helper to overwrite a different application's files, as root, instead of the app that started the update. Ex…

CVE-2026-102672
NVD

MEDIUM
CVE-2026-81310
CVE-2026-81310
pkg: linux

published: Sep 30, 2026

Image Scanner Driver for Linux contains a link following vulnerability. An attacker who can log in to a Linux system where the product is installed may overwrite arbitrary files by using a special method in advance.
CWE: CWE-59
GitHub-GHSA

MEDIUM
Dulwich: Infinite Loop Denial of Service (DoS) in Packfile Object Resolution
GHSA-35mr-4567-66vg
pkg: dulwich
eco: pip
published: Oct 2, 2026
### Affected file
* `dulwich/pack.py` (Method: `Pack.resolve_object`)

### Description / Summary
A High-severity Denial of Service (DoS) vulnerability exists in the `Pack.resolve_object` method. When resolving an `OFS_DELTA` object, the resolver calculates the base offset using `base_offset = obj_of…

NVD

MEDIUM
CVE-2026-79900
CVE-2026-79900
pkg: openssl

published: Oct 1, 2026

boks_ksllogsd accepts a checksum algorithm name in the MD field of an authenticated KSL start message. Affected releases verify that OpenSSL recognizes the digest name but do not verify that the value fits in a fixed 16-byte checksum context field before copying it. An authenticated KSL client can s…
CWE: CWE-787
GitHub-GHSA

MEDIUM
PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse
GHSA-gvp8-978c-rx2q
pkg: PyJWT
eco: pip
published: Sep 30, 2026
### Summary

`PyJWT.decode()`/`decode_complete()` mutates a caller-supplied `options` dict in place whenever `verify_signature` is falsy, adding `verify_exp`/`verify_nbf`/`verify_iat`/`verify_aud`/`verify_iss`/`verify_sub`/`verify_jti` keys directly onto that object. If application code reuses the s…

CVE-2026-103001
GitHub-GHSA

MEDIUM
Russh: Unbounded memory exhaustion via CHANNEL_OPEN flood during a client-stalled rekey
GHSA-35g8-35p8-c8fw
pkg: russh
eco: rust
published: Sep 30, 2026
## Summary

A russh **server** can be driven to unbounded heap growth (process OOM / kill) by
a peer that speaks only standard SSH messages, in the **default configuration**.

The peer starts a key re-exchange (sends `SSH_MSG_KEXINIT`) but never sends the
follow-up `SSH_MSG_KEX_ECDH_INIT`, leaving t…

CVE-2026-102821
GitHub-GHSA

MEDIUM
GitPython: –no-index bypasses diff unsafe-option protections and enables a blind local-file content oracle
GHSA-whh4-5q6c-9v3x
pkg: gitpython
eco: pip
published: Sep 30, 2026
### Summary

GitPython 3.1.59 blocks a previously available local-file read path through unsafe git diff options such as -O/–orderfile.

However, the high-level diff API still permits –no-index with the default allow_unsafe_options=False.

–no-index changes the semantics of the paths arguments: i…

NVD

MEDIUM
CVE-2026-103001
CVE-2026-103001
pkg: jwt

published: Sep 30, 2026

PyJWT is a Python implementation of JSON Web Token standards. From 2.11.0 through 2.13.0, PyJWT's PyJWT._merge_options() method can modify a caller-supplied mutable options mapping when verify_signature is false. If an application reuses that same mapping for a later decode() or decode_complete() ca…
CWE: CWE-471
GitHub-GHSA

MEDIUM
LiteLLM: Authenticated SSRF and provider-credential exfiltration via unvalidated request-body routing parameters
GHSA-3cv6-jpf6-8222
pkg: litellm, litellm, litellm
eco: pip
published: Sep 30, 2026
### Impact

Any authenticated LiteLLM proxy user could redirect an outbound provider call to a destination they control and cause the proxy to send its own configured provider credentials to that destination. The proxy's request-body validation was a denylist that did not cover every sensitive param…

CVE-2026-84377
NVD

MEDIUM
CVE-2026-102991
CVE-2026-102991
pkg: express

published: Sep 30, 2026

Mako is a template library written in Python. Prior to 1.4.2, on Windows, TemplateLookup.get_template() in mako/lookup.py resolves template URIs with posixpath, while Template.__init__() in mako/template.py validates them with os.path, which uses ntpath. A URI beginning with a drive designator cause…
CWE: CWE-22
NVD

MEDIUM
CVE-2026-101881
CVE-2026-101881
pkg: node

published: Sep 30, 2026

OpenClaw Windows Node before 2026.7.1 contains an allocation of resources without limits vulnerability in the gateway WebSocket transport that allows connected gateways to exhaust node memory. Attackers can send an unending sequence of WebSocket continuation frames without EndOfMessage to cause unbo…
CWE: CWE-770
NVD

MEDIUM
CVE-2026-101879
CVE-2026-101879
pkg: node

published: Sep 30, 2026

OpenClaw Windows Node before 2026.7.1-3 contains a missing authorization vulnerability in NodeService capture handlers that allows connected gateways or agents to perform screen snapshots, camera snaps, and location captures without consent prompts. Attackers can invoke screen.snapshot, camera.snap,…
CWE: CWE-862
GitHub-GHSA

MEDIUM
Nest: Unbounded memory growth in the NestJS TCP microservice transport
GHSA-96h4-vgxj-gvm2
pkg: @nestjs/microservices, @nestjs/microservices
eco: npm
published: Sep 30, 2026
## Summary

A peer that can open a TCP connection to a NestJS microservice using the built-in TCP
transport can make the server process allocate memory without limit, on either side of the
connection, until the process is killed by the OS or by its container memory limit. No
authentication, no crede…

NVD

MEDIUM
CVE-2026-97288
CVE-2026-97288
pkg: oauth

published: Sep 30, 2026

Contributor Cross Site Scripting (XSS) in OAuth Server <= 4.5.1 versions.
CWE: CWE-79
NVD

MEDIUM
CVE-2026-94029
CVE-2026-94029
pkg: openssh

published: Sep 30, 2026

Server-side memory exhaustion in Apache MINA SSHD 1.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5, component sshd-sftp, in the SFTP v6 check-file-name/check-file-handle extension. Apache MINA SSHD is a Java library for client-side and server-side SSH.

Using a very small "block size" (for instance 256,…

CWE: CWE-770
GitHub-GHSA

MEDIUM
undici vulnerable to cross-user cookie disclosure via Set-Cookie caching in shared caches
GHSA-2jfj-6hjv-fm6j
pkg: undici, undici
eco: npm
published: Sep 29, 2026
### Impact

undici's `interceptors.cache()` does not handle `Set-Cookie` in the cache path. In shared-cache mode (`type: 'shared'`, the default), a cacheable response (for example `Cache-Control: public, max-age=…`) carrying a `Set-Cookie` header is stored, and the stored `Set-Cookie` is re-served…

CVE-2026-84933
NVD

MEDIUM
CVE-2026-95385
CVE-2026-95385
pkg: google chrome, microsoft windows

published: Sep 29, 2026

Inappropriate implementation in PlatformIntegration in Google Chrome on on Windows prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
CWE: CWE-841
NVD

MEDIUM
CVE-2026-95303
CVE-2026-95303
pkg: google chrome

published: Sep 29, 2026

Incomplete cleanup in SmartCard in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-459
NVD

MEDIUM
CVE-2026-95297
CVE-2026-95297
pkg: google chrome

published: Sep 29, 2026

Missing authorization in Contextual Tasks in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-862
NVD

MEDIUM
CVE-2026-95275
CVE-2026-95275
pkg: google chrome

published: Sep 29, 2026

Incorrect reference resolution in MediaStream in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-706
NVD

MEDIUM
CVE-2026-18417
CVE-2026-18417
pkg: go

published: Sep 29, 2026

The native BSD-socket layer recorded a pending asynchronous socket error by type-punning it into struct net_context's void user_data field (ctx->user_data = INT_TO_POINTER(-status) in zsock_accepted_cb(), zsock_received_cb(), zsock_connected_cb() and zsock_close_ctx() in subsys/net/lib/sockets/socke…
CWE: CWE-843
NVD

MEDIUM
CVE-2026-102275
CVE-2026-102275
pkg: jwt

published: Sep 28, 2026

PyJWT is a Python implementation of JSON Web Token standards. From 2.1.0 until 2.15.0, PyJWT OKPAlgorithm.from_jwk in jwt/algorithms.py is affected because private-JWK import path does not compare the public key derived from d with x. This occurs when an OKP private JWK supplies non-corresponding x…
CWE: CWE-345, CWE-348
NVD

MEDIUM
CVE-2026-93537
CVE-2026-93537
pkg: kubernetes

published: Sep 28, 2026

A user who can supply bundle content to a repository referenced by a GitRepo resource, for example through Git push access, or through permission to create or modify a GitRepo, can cause SUSE Rancher Fleet to read files from the filesystem of the environment that processes the bundle and include the…
CWE: CWE-23
NVD

MEDIUM
CVE-2026-19444
CVE-2026-19444
pkg: kubernetes

published: Sep 28, 2026

A path traversal vulnerability was discovered in the Kubernetes kubectl client's kubectl cp command on Windows. When copying files from a container, kubectl runs tar inside the container to build a tar archive, transfers it over the network, and unpacks it on the local machine. If the tar bina…
CWE: CWE-22
NVD

MEDIUM
CVE-2026-101925
CVE-2026-101925
pkg: curl

published: Oct 1, 2026

The bbp style pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'display_name (via /wp-admin/profile.php) + bbp_reply_content (via bbPress reply form)' parameter in all versions up to, and including, 6.4.8 due to insufficient input sanitization and output escaping. This …
CWE: CWE-79
NVD

MEDIUM
CVE-2026-92712
CVE-2026-92712
pkg: react

published: Sep 30, 2026

The ReactPress – Create React App for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'permalink' parameter in all versions up to, and including, 3.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers…
CWE: CWE-79
NVD

MEDIUM
CVE-2026-105141
CVE-2026-105141
pkg: jwt

published: Oct 4, 2026

A security flaw has been discovered in topoteretes cognee up to 1.5.4. The affected element is the function get_user_id_by_email of the file cognee/modules/users/authentication/get_api_auth_backend.py of the component JWT Signing Key Handler. The manipulation of the argument FASTAPI_USERS_JWT_SECRET…
CWE: CWE-259, CWE-798
NVD

MEDIUM
CVE-2026-102136
CVE-2026-102136
pkg: node

published: Sep 30, 2026

In multi-node deployments, an attacker who had already obtained code execution on one appliance node could submit a value through an internal cluster interface that was written into monitoring configuration on another node without sufficient validation, potentially allowing OS commands to be execute…
CWE: CWE-93
NVD

MEDIUM
CVE-2026-81930
CVE-2026-81930
pkg: jwt

published: Sep 29, 2026

Apache Airflow's Snowflake provider did not validate the connection's `account` and `region` fields before interpolating them into request URLs. The SQL API endpoint is built as `https://{account}.snowflakecomputing.com/api/v2/statements`, so an `account` value containing `/`, `?` or `#` demotes the…
CWE: CWE-522
NVD

MEDIUM
CVE-2026-86335
CVE-2026-86335
pkg: linux

published: Sep 28, 2026

Missing Authorization in imageDownload in Canonical LXD before 5.0.10, 5.21.8, and 6.10 on Linux allows a project-restricted client to access private images from other projects via local fingerprint reuse during image or instance import requests.
CWE: CWE-862
NVD

MEDIUM
CVE-2026-103957
CVE-2026-103957
pkg: oauth

published: Oct 2, 2026

Server-side request forgery in the OAuth2 discovery handling in Loom for AWS before 1.7.0 might allow an authenticated remote user to obtain the access token of another user of the deployment and to cause the application to issue requests to arbitrary internal network locations, via a crafted discov…
CWE: CWE-201, CWE-918
GitHub-GHSA

MEDIUM
pageant: Out-of-bounds read / oversized allocation in `pageant` MemoryMap::read via a malicious Pageant agent (Windows)
GHSA-g4mp-vgx3-xrvm
pkg: pageant
eco: rust
published: Sep 30, 2026
## Summary

`MemoryMap::read` in the `pageant` crate (part of the russh workspace, used by
russh's SSH-agent client on Windows via `AgentClient::connect_pageant`) copies a
**peer-controlled** number of bytes out of an 8192-byte shared-memory view with
**no bounds check** — unlike the sibling `Memo…

CVE-2026-102820
NVD

MEDIUM
CVE-2026-102820
CVE-2026-102820
pkg: windows

published: Sep 29, 2026

pageant provides a [PageantStream] type that implements [AsyncRead] and [AsyncWrite] traits and can be used to talk to a running Pageant instance. Prior to pageant 0.2.3, the Windows pageant crate's pageant/src/wmmessage.rs MemoryMap::read function trusts a peer-controlled u32 response length suppli…
CWE: CWE-125, CWE-789
NVD

MEDIUM
CVE-2026-105114
CVE-2026-105114
pkg: oauth

published: Oct 3, 2026

OpenAM before 16.1.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject script by supplying crafted parameters rendered unencoded on the OAuth2 authorization error page. Attackers can lure victims to a crafted /oauth2/authorize link with repeated …
CWE: CWE-79
NVD

MEDIUM
CVE-2026-83589
CVE-2026-83589
pkg: oauth

published: Oct 1, 2026

A flaw was found in oauth-proxy. The application fails to properly validate the destination redirect parameter (`rd`) during post-login redirection. A remote attacker can exploit this vulnerability by enticing a user to follow a specially crafted link, resulting in the user being redirected to an ar…
CWE: CWE-601
GitHub-GHSA

MEDIUM
Oauthlib : Unsafe JSONP callback injection in RevocationEndpoint allows arbitrary JavaScript response generation
GHSA-hj66-6f7g-4r5v
pkg: oauthlib
eco: pip
published: Sep 29, 2026
### Summary

When `enable_jsonp=True`, oauthlib's `RevocationEndpoint` reflects the user-supplied `callback` parameter directly into JavaScript response bodies on both success and error paths without validating that it is a legal JSONP callback name. This allows arbitrary JavaScript response generat…

CVE-2026-49264
NVD

MEDIUM
CVE-2026-102374
CVE-2026-102374
pkg: oauth

published: Sep 29, 2026

GestSup versions before 3.2.62 contain a stored cross-site scripting vulnerability in the IMAP OAuth connector that double-decodes MIME-encoded email subjects after HTML escaping. Unauthenticated attackers can send crafted emails to monitored mailboxes with nested MIME encoded-words to inject JavaSc…
CWE: CWE-79
NVD

MEDIUM
CVE-2026-47518
CVE-2026-47518
pkg: linux

published: Sep 30, 2026

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in a secure microcontroller component, where incorrect permission assignment for a critical resource allows an attacker with privileged local access to modify protected memory that should be restricted. A successful exploit of …
CWE: CWE-732
NVD

MEDIUM
CVE-2026-105292
CVE-2026-105292
pkg: oauth

published: Oct 5, 2026

Chaterm before 0.12.1 contains a login cross-site request forgery vulnerability that allows remote attackers to inject login state by sending chaterm:// callbacks without OAuth state validation. Attackers can trigger a crafted callback with attacker-controlled userInfo from a web page, signing the v…
CWE: CWE-352
GitHub-GHSA

MEDIUM
fastify vulnerable to Denial of Service via unhandled exception on HTTP/2 trailer responses
GHSA-4mh8-r7rc-xpvc
pkg: fastify
eco: npm
published: Sep 30, 2026
### Impact

`fastify` crashes with an uncaught `ERR_HTTP2_INVALID_CONNECTION_HEADERS` exception when a route that registers a response trailer via `reply.trailer()` is served over HTTP/2. Fastify unconditionally adds the `Transfer-Encoding: chunked` header when a trailer is set, which is forbidden o…

CVE-2026-92081
GitHub-GHSA

MEDIUM
moment vulnerable to Path Traversal via crafted non-string locale name
GHSA-4p3w-j4w9-5jqw
pkg: moment
eco: npm
published: Sep 29, 2026
### Impact

moment before 2.31.0 is vulnerable to path traversal in `moment.locale()`. When an application passes a non-string, attacker-influenced value to `moment.locale()`, a specially crafted object can bypass the locale name validation and cause moment to load a file from an attacker-controlled…

CVE-2026-17495
GitHub-GHSA

MEDIUM
adm-zip: Duplicate ZIP entry names: getEntry() and extractAllTo() resolve to different content
GHSA-p634-w6r4-rjp2
pkg: adm-zip
eco: npm
published: Sep 29, 2026
### Summary

A ZIP file can contain two entries with the identical name. adm-zip keeps both in its internal entry list, but its name-lookup table only retains the last one written. `getEntry(name)` and `extractAllTo()` walk these two different internal structures, so they can each resolve a duplicat…

GitHub-GHSA

MEDIUM
Nodemailer: Nested structured recipient arrays bypass the parser depth limit and cause stack exhaustion DoS
GHSA-8vvx-rff5-p5rq
pkg: nodemailer
eco: npm
published: Sep 29, 2026
## Submission metadata

| Field | Value |
|—|—|
| Ecosystem | npm |
| Package | `nodemailer` |
| Repository | https://github.com/nodemailer/nodemailer |
| Tested commit | `40d52215aac65b811d7e131bc916f68605efd9d2` |
| Current tested version | `10.0.1` |
| Confirmed vulnerable versions | `2.7.2`,…

GitHub-GHSA

MEDIUM
PyJWT: Malformed RSA JWK aborts parsing of an entire JWK Set
GHSA-w6j9-cwv2-h6wq
pkg: PyJWT
eco: pip
published: Sep 29, 2026
## Summary

A malformed RSA JWK inside a JWK Set aborts parsing of the entire set instead of being skipped, because `RSAAlgorithm.from_jwk` can raise a plain `ValueError` that isn't caught by `PyJWKSet`'s per-key error-skipping logic.

## Affected component / version

– Package: `PyJWT` (PyPI, ecosy…

CVE-2026-102274
GitHub-GHSA

MEDIUM
undici vulnerable to Denial of Service via orphaned RetryHandler response body
GHSA-pmjh-fq2x-6v4x
pkg: undici, undici
eco: npm
published: Sep 29, 2026
### Impact

undici's `RetryHandler` can leave a response body pending indefinitely. When a retried request receives a non-retryable response after a truncated one, the original `response.body` held by the application is never settled, so reads such as `response.body.text()` hang and `bodyTimeout` do…

CVE-2026-18149
GitHub-GHSA

MEDIUM
undici vulnerable to Denial of Service via unbounded decompression of compressed responses
GHSA-3xpg-4rpp-hhhm
pkg: undici, undici
eco: npm
published: Sep 29, 2026
### Impact

The `interceptors.decompress()` interceptor decompresses HTTP response bodies according to the untrusted `Content-Encoding` header. The number of decompression layers is capped at 5, but the total decompressed output size is not bounded and there is no option to limit it. A malicious or …

CVE-2026-84890
GitHub-GHSA

MEDIUM
undici vulnerable to Denial of Service via WebSocketStream unclean close
GHSA-rx4f-c7p8-82vq
pkg: undici, undici
eco: npm
published: Sep 29, 2026
## Impact

undici's `WebSocketStream` crashes the client process when a WebSocket connection is closed abruptly without a close handshake. On such an unclean close, the internal socket-close handler calls `abort()` on the writable stream even when the application holds a writer lock. Per the WHATWG …

CVE-2026-85014
NVD

MEDIUM
CVE-2026-102274
CVE-2026-102274
pkg: jwt

published: Sep 28, 2026

PyJWT is a Python implementation of JSON Web Token standards. From 2.9.0 until 2.14.0, PyJWKSet does not catch the plain ValueError raised for malformed RSA JWK components by RSAAlgorithm.from_jwk in jwt/api_jwk.py. This occurs when a JWK Set contains a malformed RSA key alongside otherwise usable …
CWE: CWE-755
GitHub-GHSA

MEDIUM
Anubis: Policy bypass via client controlled X-Original-URI header
GHSA-6wcg-mqvh-fcvg
pkg: github.com/TecharoHQ/anubis
eco: go
published: Oct 2, 2026
Any HTTP client can bypass Anubis bot protection on the default configuration by adding a single request header. No challenge needs to be solved.
Affected versions: v1.22.0 through v1.25.0 (introduced in commit d1d631a, PR #1015)

The root cause is in `lib/policy/checker.go`, `PathChecker.Check()`:
…

CVE-2026-62314
GitHub-GHSA

MEDIUM
SiYuan: The reference filter for getRefIDs checks visibility but not the password tier, disclosing that password-protected documents reference a given block
GHSA-vg99-7gj7-2fr5
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: Oct 1, 2026
### Summary

`/api/block/getRefIDs` filters its results for reader roles through a helper that checks only the visibility tiers. The password tier is not checked, because the helper does not receive the request context and therefore cannot evaluate the publish auth cookie. A reader who has not enter…

CVE-2026-73606
GitHub-GHSA

MEDIUM
SiYuan: getBookmarkLabels returns every bookmark label in the workspace to anonymous readers, with no publish-access filtering
GHSA-j4ph-9xwf-wcj4
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: Oct 1, 2026
### Summary

`/api/attr/getBookmarkLabels` is registered with `CheckAuth` only and applies no filtering of any kind. It runs a scan of the entire `blocks` table and returns the distinct set of every bookmark label in the workspace. An anonymous reader in publish mode receives the author's complete b…

CVE-2026-73609
GitHub-GHSA

MEDIUM
SiYuan: getUniqueFilename passes an unvalidated client-supplied path to the filesystem, giving anonymous readers an existence oracle over the entire host filesystem
GHSA-hf8h-97gm-4x2p
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: Oct 1, 2026
### Summary

`/api/file/getUniqueFilename` takes a path from the request body and passes it to a filesystem existence check with no validation, confinement or authorization. The response distinguishes paths that exist from paths that do not, so an anonymous reader in publish mode can probe arbitrary…

CVE-2026-73605
GitHub-GHSA

MEDIUM
SiYuan: Outline state for any document, including documents forbidden to readers, is returned by /api/storage/getOutlineStorage with no access check
GHSA-53fp-9jmv-227g
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: Oct 1, 2026
### Summary

`/api/storage/getOutlineStorage` is registered with `CheckAuth` only and performs no authorization of any kind. Given a document identifier it returns that document's stored outline state, regardless of the document's publish tier.

The two write endpoints for the same data, `setOutline…

CVE-2026-73607
GitHub-GHSA

MEDIUM
SiYuan discloses an administrator's open documents and search terms to anonymous readers
GHSA-hgfg-j9pg-43xw
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: Oct 1, 2026
### Summary

`/api/system/getConf` serves `Conf.UILayout` to publish readers after passing it through `FilterConfByPublishIgnore`, whose only function is to filter that layout. The layout is written exclusively by `setUILayout`, which is administrator-gated, so what readers receive is the administra…

CVE-2026-72788
NVD

MEDIUM
CVE-2026-87798
CVE-2026-87798
pkg: linux

published: Sep 28, 2026

Improper link resolution in the recursive file pull feature of the LXD CLI client in Canonical LXD versions 4.0.2 up to 6.9 (fixed in 4.0.14, 5.0.10 and 5.21.8) on Linux allows an attacker with root access inside a virtual machine to write attacker-controlled files or directory trees to arbitrary pa…
CWE: CWE-59
GitHub-GHSA

MEDIUM
SiYuan MCP asset.upload Reads Arbitrary Absolute File Paths (Workspace Boundary Bypass)
GHSA-p23f-cm6q-2qp8
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: Oct 2, 2026
# Security Advisory — SiYuan MCP `asset.upload` Reads Arbitrary Absolute File Paths (Workspace Boundary Bypass)

| Field | Value |
|—|—|
| **Disclosed by** | joysinleung (`joysinleung@gmail.com`) |
| **Report date** | 2026-08-13 |
| **Product** | SiYuan (思源笔记) — `siyuan-note/siyuan` …

NVD

MEDIUM
CVE-2026-86157
CVE-2026-86157
pkg: oauth

published: Sep 29, 2026

Exposure of privileged IPC functionality in Progress Telerik Fiddler Everywhere before version 8.2.0 allows a local, low-privileged attacker who can modify application launch parameters and persuade a user to start the application to replace the application UI or settings with attacker-controlled co…
CWE: CWE-749
GitHub-GHSA

MEDIUM
jackson-databind: Comparable missing from DefaultBaseTypeLimitingValidator's unsafe base types (incomplete PolymorphicTypeValidator denylist)
GHSA-gx83-3vf8-gh7j
pkg: tools.jackson.core:jackson-databind, tools.jackson.core:jackson-databind, com.fasterxml.jackson.core:jackson-databind
eco: maven
published: Sep 28, 2026
### Summary
`DefaultBaseTypeLimitingValidator` — the `PolymorphicTypeValidator` used automatically whenever `@JsonTypeInfo` is applied without an explicitly configured custom validator — denies polymorphic resolution only for nine specific "unsafe base types" (`Object`, `Serializable`, `Closeabl…
CVE-2026-83557
GitHub-GHSA

MEDIUM
Trigger.dev: Trigger CLI debug deployment logs expose resolved environment secret values
GHSA-fj2x-mqqp-3v2w
pkg: trigger.dev
eco: npm
published: Oct 2, 2026
Affected version: trigger.dev 4.5.3 (4.5.6 was advertised by the CLI but was not tested).

A staging dry-run executed with `trigger.dev deploy –env staging –dry-run –log-level debug`. The debug output logged the complete build-worker options object. Its `envVars` property contained unredacted val…

NVD

MEDIUM
CVE-2026-47534
CVE-2026-47534
pkg: windows

published: Sep 30, 2026

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause a divide by zero. A successful exploit of this vulnerability might lead to denial of service.
CWE: CWE-369
NVD

MEDIUM
CVE-2026-47517
CVE-2026-47517
pkg: linux

published: Sep 30, 2026

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode driver where a local user may cause a null pointer dereference by submitting a crafted ioctl. A successful exploit of this vulnerability might lead to denial of service.
CWE: CWE-476
NVD

MEDIUM
CVE-2026-47506
CVE-2026-47506
pkg: windows

published: Sep 30, 2026

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel-mode color transform path where excessive kernel stack use occurs when evaluating YCbCr420 display emulation. A successful exploit of this vulnerability might lead to denial of service.
CWE: CWE-121
NVD

MEDIUM
CVE-2026-47492
CVE-2026-47492
pkg: linux

published: Sep 30, 2026

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an attacker can cause improper access control. A successful exploit of this vulnerability might lead to denial of service.
CWE: CWE-862
NVD

MEDIUM
CVE-2026-98164
CVE-2026-98164
pkg: linux linux_kernel

published: Sep 29, 2026

In the Linux kernel, the following vulnerability has been resolved:

KVM: x86/mmu: Check write tracking in all address spaces

kvm_gfn_is_write_tracked() checks only the supplied memslot, but page
tracking is per-address-space and shadow pages are shared across all
address spaces. With SMM, a GFN c…

CWE: CWE-670
NVD

MEDIUM
CVE-2026-105122
CVE-2026-105122
pkg: oauth

published: Oct 3, 2026

OpenAM before 16.1.3 contains a server-side request forgery vulnerability that allows attackers able to register or modify OAuth 2.0 clients to make OpenAM fetch internal resources via an unvalidated jwks_uri. Attackers can trigger unauthenticated fetches through client-authentication and ID-token v…
CWE: CWE-918
GitHub-GHSA

MEDIUM
Trigger.dev: Cross-environment deployment cancel
GHSA-4672-hwv6-gq62
pkg: trigger.dev
eco: npm
published: Oct 2, 2026
### Summary

Trigger.dev isolates each project into multiple **environments** (`dev`, `staging`, `prod`, and per-PR `preview` branches), each with its **own secret API key** — the environment is a trust boundary (a `dev`/preview/CI key is lower-trust than a `prod` key). Most API routes enforce thi…

GitHub-GHSA

MEDIUM
Trigger.dev: Blind SSRF via alert-channel webhook
GHSA-q567-cr4x-96w4
pkg: trigger.dev
eco: npm
published: Oct 2, 2026
### Summary

A WEBHOOK alert channel stores a user-supplied `url`. When an alert fires (deployment/run failure, error groups), the webapp server (`alertsWorker` -> `DeliverAlertService`) POSTs the HMAC-signed alert payload to that URL via `fetch(webhook.url, …)`. The URL is never validated against…

GitHub-GHSA

MEDIUM
JupyterLab: Argument injection in JupyterLab extension uninstall exposes server-readable files and internal URLs
GHSA-3325-v43h-43rv
pkg: jupyterlab, jupyterlab
eco: pip
published: Oct 1, 2026
JupyterLab's PyPI extension manager runs `python -m pip uninstall` with the extension name taken from the request body. `ExtensionHandler.post` validates the name for `cmd=install` but not for `cmd=uninstall`, so a name that begins with `-` reaches the command line and pip reads it as an option rath…
CVE-2026-102904
NVD

MEDIUM
CVE-2026-101883
CVE-2026-101883
pkg: node

published: Sep 30, 2026

OpenClaw Windows Node through 2026.9.4 contains a server-side request forgery vulnerability in the canvas.present capability that bypasses URL risk evaluation enforced by canvas.navigate. Attackers with gateway or agent access can issue canvas.present to make the node's WebView send requests to loca…
CWE: CWE-918
NVD

MEDIUM
CVE-2026-103053
CVE-2026-103053
pkg: docker

published: Sep 30, 2026

AiSOC versions 9.0.0 before 12.0.0 fail to enforce authentication on the response-action API endpoints when AISOC_DEV_MODE is enabled and AISOC_ACTIONS_SERVICE_TOKEN is empty in the default Docker Compose deployment. Unauthenticated attackers can list response-action integrations, submit and approve…
CWE: CWE-306
GitHub-GHSA

MEDIUM
Ammonia: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
GHSA-m6mh-2hw2-555x
pkg: ammonia, ammonia, ammonia
eco: rust
published: Sep 29, 2026
The following SVG will produce a link with a `javascript` scheme. If the user clicks this link, they will run it.

“`svg
<svg xmlns="http://www.w3.org/2000/svg">
<a>
<set attributeName="href" to="javascript:alert('SET_XSS')"></set>
<text y="30">Click set</text>
</a>
</svg>
“`

### Impa…

CVE-2026-102342
NVD

MEDIUM
CVE-2026-102904
CVE-2026-102904
pkg: python

published: Sep 29, 2026

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 4.0.0 until 4.5.11 and 4.6.4, the PyPI Extension Manager uninstall request reaches ExtensionHandler.post, which validates extension names for installation b…
CWE: CWE-88, CWE-209, CWE-918
NVD

MEDIUM
CVE-2026-95309
CVE-2026-95309
pkg: google chrome, apple iphone_os

published: Sep 29, 2026

UI misrepresentation in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
CWE: CWE-451
NVD

MEDIUM
CVE-2026-95307
CVE-2026-95307
pkg: google chrome

published: Sep 29, 2026

UI misrepresentation in ExtensionsMenu in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
CWE: CWE-451
NVD

MEDIUM
CVE-2026-95294
CVE-2026-95294
pkg: google chrome

published: Sep 29, 2026

UI misrepresentation in Browser in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-451
NVD

MEDIUM
CVE-2026-95291
CVE-2026-95291
pkg: google chrome, apple iphone_os

published: Sep 29, 2026

UI misrepresentation in SecurityIndicators in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-451
NVD

MEDIUM
CVE-2026-95290
CVE-2026-95290
pkg: google chrome

published: Sep 29, 2026

Missing authorization in NFC in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-862
NVD

MEDIUM
CVE-2026-95288
CVE-2026-95288
pkg: google chrome, apple iphone_os

published: Sep 29, 2026

UI misrepresentation in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
CWE: CWE-451
NVD

MEDIUM
CVE-2026-95287
CVE-2026-95287
pkg: google chrome

published: Sep 29, 2026

Missing authorization in Navigation in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-862
NVD

MEDIUM
CVE-2026-95279
CVE-2026-95279
pkg: google chrome, google android

published: Sep 29, 2026

UI misrepresentation in Omnibox in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)
CWE: CWE-451
NVD

MEDIUM
CVE-2026-93539
CVE-2026-93539
pkg: kubernetes

published: Sep 28, 2026

A vulnerability was discovered in Fleet's Git webhook receiver (the gitjob webhook service). When a webhook secret is not configured, incoming webhook requests are accepted without verification, and processing a request can change the spec.pollingInterval field of a matching GitRepo resource in any …
CWE: CWE-306
GitHub-GHSA

MEDIUM
Trigger.dev: Unauthenticated Realtime Stream Data Injection via Run FriendlyId
GHSA-59h8-w5q6-mfmp
pkg: trigger.dev
eco: npm
published: Oct 2, 2026
## Summary

The POST handler for `/realtime/v1/streams/:runId/:streamId` has no authentication. Any entity that knows or guesses a run friendlyId can inject arbitrary data into its realtime stream.

## Vulnerability Details

**File:** `apps/webapp/app/routes/realtime.v1.streams.$runId.$streamId.ts`
…

NVD

MEDIUM
CVE-2026-104440
CVE-2026-104440
pkg: curl

published: Oct 2, 2026

YesWiki before 4.6.7 contains a blind server-side request forgery vulnerability that allows unauthenticated attackers to make arbitrary server-side requests via the idtypeannonce parameter of /api/entries/bazarlist. Because isValidURL() always returns true, attackers can supply internal URLs fetched…
CWE: CWE-918
NVD

MEDIUM
CVE-2026-102671
CVE-2026-102671
pkg: ssl

published: Oct 1, 2026

The Joyland AI app accepts invalid SSL certificates in the invisible advertisement WebView by default.
CWE: CWE-295
NVD

MEDIUM
CVE-2026-102668
CVE-2026-102668
pkg: tls

published: Oct 1, 2026

The Joyland AI app accepts any TLS certificates from any server without validation.
CWE: CWE-295
GitHub-GHSA

MEDIUM
Tornado: Unbounded query-string argument count allows event-loop-stalling DoS
GHSA-3hv7-mjh2-fv65
pkg: tornado
eco: pip
published: Sep 30, 2026
## Summary

`HTTPServerRequest.__init__` in `tornado/httputil.py` parses the URL query string via
`parse_qs_bytes()` with no field-count limit — while the sibling POST-body parsing path
(`parse_body_arguments`) received a `max_num_fields=1000` cap added earlier in this exact
same release (v6.5.8, …

GitHub-GHSA

MEDIUM
PyJWT: Unauthenticated RecursionError DoS in pre-verification payload parse (PyJWKClient.get_signing_key_from_jwt / verify_signature=False)
GHSA-42vr-xj54-vc7v
pkg: PyJWT
eco: pip
published: Sep 30, 2026
## Summary

`PyJWKClient.get_signing_key_from_jwt(token)` — the first step of the JWKS
verification flow documented in `docs/usage.rst` — must decode a token's
payload before its signature can be checked, via
`jwt.api_jwt.decode_complete(token, options={"verify_signature": False})`.
That call pa…

CVE-2026-101918
GitHub-GHSA

MEDIUM
brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of service
GHSA-q2hr-2g5m-vwhr
pkg: brace-expansion, brace-expansion, brace-expansion
eco: npm
published: Sep 29, 2026
### Summary

Expanding `{a},b}`-shaped input takes time quadratic in the number of literal `}` characters, blocking the event loop.

Bash preserves a quirk where a brace group followed by a comma set still expands (`{a},b}`). The parser implements this by rewriting the string and restarting the scan…

CVE-2026-102277
GitHub-GHSA

MEDIUM
Nodemailer: Quoted local-part can produce malformed envelope recipient through RFC 5322 comment parsing
GHSA-g57g-f23g-4646
pkg: nodemailer
eco: npm
published: Sep 29, 2026
## Summary

Nodemailer's address parser can produce an unexpected recipient address when an RFC 5322 comment follows the domain of an address whose local-part is a quoted string.

For example:

“`text
"user"@example.com(x)evil.com
“`

is parsed as:

“`text
{
address: "user@example.com evil.com"…

GitHub-GHSA

MEDIUM
PyJWT: Uncaught RecursionError in jwt.decode() on deeply nested token header
GHSA-8wjv-2p76-3863
pkg: pyJWT
eco: pip
published: Sep 29, 2026
## Package

pyjwt (PyPI)

## Affected versions

tested & verified on: 2.13.0. Every version whose `PyJWS._load()` translates only `ValueError` is affected

## Description

`PyJWS._looad()` (`jwt/api_jws.py:337`) splits the compact token, base64url decodes the header segment and hands it to `json.loa…

CVE-2026-102265
GitHub-GHSA

MEDIUM
PyJWT: PyJWKClient still amplifies unauthenticated JWKS fetches on unknown kid values (incomplete fix of CVE-2026-48524)
GHSA-2gx3-rcp4-g85q
pkg: pyjwt
eco: pip
published: Sep 29, 2026
Summary
CVE-2026-48524 (GHSA-fhv5-28vv-h8m8, "PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)") was fixed in 2.13.0 by stopping fetch_data() from clearing the cache on a fetch error. That closed one amplification path but did not add the mitigation the advisory'…
CVE-2026-101917
GitHub-GHSA

MEDIUM
adm-zip: getDataAsync() bypasses the maxOutputLength size guard enforced by the synchronous getData() path
GHSA-c6fg-446q-cg94
pkg: adm-zip
eco: npm
published: Sep 29, 2026
### Summary
adm-zip enforces a `maxOutputLength` guard against decompression bombs on its synchronous `getData()` path, but the equivalent asynchronous `getDataAsync()` path does not enforce it — it accumulates and returns the entire decompressed output regardless of the entry's declared size. An …
NVD

MEDIUM
CVE-2026-75806
CVE-2026-75806
pkg: tls

published: Sep 29, 2026

Issue summary: An established DTLS 1.2 association using an AEAD cipher suite
can be terminated by a single unauthenticated datagram whose encrypted
fragment is shorter than the mandatory explicit IV and authentication tag
overhead.

Impact summary: An attacker who can send a datagram that is routed…

CWE: CWE-1284
NVD

MEDIUM
CVE-2026-75805
CVE-2026-75805
pkg: openssl

published: Sep 29, 2026

Issue summary: A CMP client that requests certificate revocation on the basis
of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when
processing a crafted revocation response.

Impact summary: The NULL pointer dereference happens on a read which
leads to a crash and a Denial …

CWE: CWE-476
NVD

MEDIUM
CVE-2026-75804
CVE-2026-75804
pkg: openssl

published: Sep 29, 2026

Issue summary: OpenSSL QUIC stack does not enforce connection
level flow control for streams. Remote peers may send more bytes
as long as they fit within the stream flow control limits.

Impact summary: A malicious remote peer may exploit the lack of connection
flow control for streams to make the Q…

CWE: CWE-770
NVD

MEDIUM
CVE-2026-42772
CVE-2026-42772
pkg: openssl

published: Sep 29, 2026

Issue summary: The QUIC stream reassembly algorithm performance deteriorates
progressively as packets are arriving out of order. The worst case has
a quadratic complexity proportional to the number of stream frames kept in
the buffer for the received stream data.

Impact summary: A remote QUIC peer …

CWE: CWE-407
NVD

MEDIUM
CVE-2026-35189
CVE-2026-35189
pkg: tls

published: Sep 29, 2026

Issue summary: A certificate with many nameRelativeToCRLIssuer CRL
distribution points causes disproportionate heap growth when OpenSSL caches
X.509 extensions.

Impact summary: Receiving a crafted certificate from a malicious peer can lead
to significant memory pressure and possible Denial of Servi…

CWE: CWE-770
NVD

MEDIUM
CVE-2026-102277
CVE-2026-102277
pkg: node

published: Sep 28, 2026

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.21, 2.1.7, 3.0.9, and 5.0.12, the expand function handles untrusted {a},b}-shaped patterns with many trailing closing braces by restarting its scan once for each trailing closing brace. The su…
CWE: CWE-400, CWE-407
NVD

MEDIUM
CVE-2026-102265
CVE-2026-102265
pkg: jwt

published: Sep 28, 2026

PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, PyJWS._load in jwt/api_jws.py is affected because parser catches ValueError but not RecursionError. This occurs when a deeply nested token header reaches json.loads. As a result, RecursionError escapes the docume…
CWE: CWE-674
NVD

MEDIUM
CVE-2026-101918
CVE-2026-101918
pkg: jwt

published: Sep 28, 2026

PyJWT is a Python implementation of JSON Web Token standards. From 2.0.0a1 until 2.15.0, PyJWT PyJWKClient.get_signing_key_from_jwt is affected because payload parser catches ValueError but not RecursionError. This occurs when an attacker-controlled recursively nested payload reaches json.loads. As …
CWE: CWE-248
NVD

MEDIUM
CVE-2026-101917
CVE-2026-101917
pkg: python

published: Sep 28, 2026

PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT get_signing_key_from_jwt is affected because unknown kid misses force refreshes without a negative cache or minimum refresh interval. This occurs when unauthenticated tokens repeatedly use the same unknown kid or va…
CWE: CWE-770
GitHub-GHSA

MEDIUM
jackson-databind: Path Deserialization Missing Scheme Allowlist for FileSystemProvider Resolution
GHSA-wjgm-6hv5-3cvf
pkg: tools.jackson.core:jackson-databind, tools.jackson.core:jackson-databind, com.fasterxml.jackson.core:jackson-databind
eco: maven
published: Sep 28, 2026
### Summary

A `java.nio.file.Path` field bound from untrusted JSON reaches `JDKFromStringDeserializer.NioPathHelper.deserialize`. The attacker string flows through `new URI(value)` → `Path.of(uri)`, then on `FileSystemNotFoundException` into a `ServiceLoader<FileSystemProvider>` enumeration that …

CVE-2026-19032
GitHub-GHSA

MEDIUM
jackson-databind: Incomplete fix for CVE-2026-54514: eager DNS resolution (SSRF) still present in InetAddress deserialization
GHSA-vvgp-rfg2-7rr6
pkg: com.fasterxml.jackson.core:jackson-databind, com.fasterxml.jackson.core:jackson-databind, com.fasterxml.jackson.core:jackson-databind
eco: maven
published: Sep 28, 2026
### Summary
CVE-2026-54514 (GHSA-hgj6-7826-r7m5) fixed an eager-DNS-resolution / SSRF issue in jackson-databind's deserialization of `java.net.InetSocketAddress` by switching to `InetSocketAddress.createUnresolved(…)` (PR #5951, commit 1f5a1037, released in 2.18.8 / 2.21.4 / 3.1.4). That fix did n…
CVE-2026-77310
NVD

MEDIUM
CVE-2026-55156
CVE-2026-55156
pkg: node

published: Sep 28, 2026

Token Optimizer MCP measures token savings per AI coding agent, optimizes context, and shares a live local knowledge graph across 16 CLI clients. Prior to version 5.1.0, the dashboard HTTP server in token-optimizer-mcp exposes /api/session-summary and /api/session-events with no authentication middl…
CWE: CWE-22
GitHub-GHSA

MEDIUM
fast-uri vulnerable to inconsistent host case normalization via percent-encoded octets
GHSA-hrr3-gc8f-f4qj
pkg: fast-uri, fast-uri, fast-uri
eco: npm
published: Sep 29, 2026
### Impact

`fast-uri` folds the host to lowercase before it percent-decodes the host, so a percent-encoded uppercase unreserved octet such as `%41` decodes to a literal `A` that is never folded. For a scheme-relative reference (`//host`) there is no scheme, so the host canonicalization that repairs…

CVE-2026-86472
GitHub-GHSA

MEDIUM
fast-uri vulnerable to mailto header injection via percent-encoded field-name desynchronization
GHSA-jvvf-x445-j334
pkg: fast-uri
eco: npm
published: Sep 29, 2026
### Impact

`fast-uri`'s `mailto` scheme parser compares each query field name to the reserved names (`to`, `subject`, `body`) while the name is still percent-encoded, and only percent-decodes it when storing it as a generic header. On serialize, the decoded name is re-emitted, so a field name such …

CVE-2026-86818
GitHub-GHSA

MEDIUM
PyJWT: Non-canonical signature segments enable raw-token revocation bypass
GHSA-hxm8-2xgr-2p9m
pkg: PyJWT
eco: pip
published: Sep 29, 2026
## Summary

PyJWT 2.13.0 accepts compact JWS signature segments containing characters that
are not in the Base64URL alphabet. Appending `!!!!` to a valid signature does
not change the decoded signature bytes or authenticated claims, but it changes
the serialized token and its SHA-256 hash. An applic…

CVE-2026-102269
NVD

MEDIUM
CVE-2026-95305
CVE-2026-95305
pkg: google chrome

published: Sep 29, 2026

UI misrepresentation in Chromoting in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI elements via crafted network traffic. (Chromium security severity: Low)
CWE: CWE-451
NVD

MEDIUM
CVE-2026-95300
CVE-2026-95300
pkg: google chrome

published: Sep 29, 2026

Missing authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)
CWE: CWE-862
NVD

MEDIUM
CVE-2026-95292
CVE-2026-95292
pkg: google chrome

published: Sep 29, 2026

Incorrect authorization in Safebrowsing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: Low)
CWE: CWE-863
NVD

MEDIUM
CVE-2026-102269
CVE-2026-102269
pkg: python

published: Sep 28, 2026

PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT signature segment is affected because signature segment decoding accepts characters outside the canonical Base64URL representation. This occurs when non-Base64URL characters are appended to a valid compact JWS signa…
CWE: CWE-180
GitHub-GHSA

MEDIUM
hono/jsx renders plain strings unescaped in boundary components, leading to XSS
GHSA-hxh3-vqpv-xpqv
pkg: hono
eco: npm
published: Sep 30, 2026
### Summary

`hono/jsx` does not HTML-escape a plain string placed directly as a child or `fallback` of `Suspense` or `ErrorBoundary`, as the only child of a `Context.Provider`, or as the root value of `renderToString()` / `renderToReadableStream()` from `hono/jsx/dom/server`. Such a string is emitt…

CVE-2026-93981
NVD

MEDIUM
CVE-2026-102313
CVE-2026-102313
pkg: google chrome, microsoft windows

published: Sep 29, 2026

Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 154.0.8037.92 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-908
NVD

MEDIUM
CVE-2026-95293
CVE-2026-95293
pkg: google chrome

published: Sep 29, 2026

Uninitialized resource in GPU in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-908
NVD

MEDIUM
CVE-2026-95295
CVE-2026-95295
pkg: google chrome, apple iphone_os

published: Sep 29, 2026

Information leak in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 allowed a local attacker to leak sensitive information via physical access. (Chromium security severity: Medium)
CWE: CWE-200
NVD

MEDIUM
CVE-2026-47531
CVE-2026-47531
pkg: windows

published: Sep 30, 2026

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause a null pointer dereference. A successful exploit of this vulnerability might lead to denial of service.
CWE: CWE-476
NVD

MEDIUM
CVE-2026-47526
CVE-2026-47526
pkg: linux

published: Sep 30, 2026

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the firmware where an attacker could cause a null pointer dereference. A successful exploit of this vulnerability might lead to denial of service.
CWE: CWE-476
GitHub-GHSA

MEDIUM
PyJWT: ReDoS vulnerability when calling the `is_pem_format` function.
GHSA-jwrc-g2q2-pq5p
pkg: pyjwt
eco: pip
published: Sep 30, 2026
### Summary
There is a Re-DoS vulnerability in the `is_pem_format` function which results in a intesive CPU usage if an attacker is been able to provide a custom certificate.

### Details
The problem is that the lazy quantifier `.+?` will always first try to match as little as possible until it fin…

CVE-2026-102270
NVD

MEDIUM
CVE-2026-102877
CVE-2026-102877
pkg: oauth

published: Sep 29, 2026

Fider before 0.38.0 contains a server-side request forgery vulnerability due to a time-of-check time-of-use gap in URL validation for webhooks and custom OAuth provider endpoints. Administrators controlling DNS can perform DNS rebinding attacks to make the Fider server send requests to internal serv…
CWE: CWE-918
NVD

MEDIUM
CVE-2026-102270
CVE-2026-102270
pkg: express

published: Sep 28, 2026

PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT is_pem_format is affected because lazy PEM regular expression backtracks extensively. This occurs when a certificate-like input contains repeated BEGIN markers without a matching END marker. As a result, is_pem_form…
CWE: CWE-1333
GitHub-GHSA

MEDIUM
Russh: Missing X25519 zero-point validation in hybrid ML-KEM key exchange
GHSA-w3jg-pjxf-73p4
pkg: russh
eco: rust
published: Sep 30, 2026
## Vulnerability

The hybrid ML-KEM 768 + X25519 key exchange implementation in `russh/src/kex/hybrid_mlkem.rs` does not validate that the remote peer's X25519 public key is not the zero point (all-zero 32-byte value). This allows a remote peer to force the X25519 contribution to the combined shared…

CVE-2026-102824
NVD

MEDIUM
CVE-2026-95296
CVE-2026-95296
pkg: google chrome, apple macos

published: Sep 29, 2026

Missing authorization in Core in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Low)
CWE: CWE-862
NVD

MEDIUM
CVE-2026-95289
CVE-2026-95289
pkg: google chrome

published: Sep 29, 2026

Incorrect authorization in Scroll in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-863
NVD

MEDIUM
CVE-2026-81914
CVE-2026-81914
pkg: express

published: Sep 29, 2026

Apache Airflow's Google provider built Google Drive search expressions by interpolating file and folder names directly into single-quoted string literals, without escaping the quote character that delimits them. A name containing an apostrophe therefore terminated the literal early and appended clau…
CWE: CWE-943
NVD

MEDIUM
CVE-2026-13018
CVE-2026-13018
pkg: google chrome

published: Sep 28, 2026

Insufficient validation of untrusted input in Codecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially perform out of bounds memory access via a crafted video file. (Chromium security severity: Low)
CWE: CWE-20
GitHub-GHSA

MEDIUM
vm2: External module allowlist uses a raw prefix test, so a prefix-sharing sibling package is treated as allowlisted
GHSA-7q3f-wx44-378m
pkg: vm2
eco: npm
published: Oct 1, 2026
## Summary

`isPathAllowedForModule` decides whether a resolved path belongs to an allowlisted external module using a raw string prefix test. `node_modules/foo2` starts with `node_modules/foo`, so a package whose name merely shares a prefix with an allowlisted one is treated as being inside it, and…

CVE-2026-92945
NVD

MEDIUM
CVE-2026-101861
CVE-2026-101861
pkg: python

published: Sep 28, 2026

Langflow 1.0.16 before 1.12.0 and 0.0.94 before 1.12.0 contain an unsafe eval() vulnerability in schema.py that allows authenticated attackers to achieve code execution by placing a Python object with a malicious __repr__ method into component input options lists. The eval() sink is triggered when a…
CWE: CWE-94, CWE-95
GitHub-GHSA

MEDIUM
geopy: Regular Expression Denial of Service (ReDoS) in geopy.Point
GHSA-mhvh-fq92-pfmr
pkg: geopy
eco: pip
published: Oct 2, 2026
### Impact

`geopy.Point` and `Point.from_string()` may take excessive CPU time when parsing long, malformed coordinate strings due to inefficient regular-expression behavior. The numeric Point constructor is not affected.

Geocoders' `reverse` methods called with string inputs exercise the vulnerab…

CVE-2026-77387
NVD

MEDIUM
CVE-2026-77387
CVE-2026-77387
pkg: python

published: Oct 1, 2026

geopy is a geocoding library for Python. Prior to 2.5.0, geopy.Point and Point.from_string() can spend excessive CPU time due to inefficient regular-expression behavior when an application passes a long malformed coordinate string without the 256-character input limit used by the fix. Geocoder rever…
CWE: CWE-1333
GitHub-GHSA

MEDIUM
vm2: vm.freeze()/vm.readonly() bypass via accessor descriptor
GHSA-633r-hq9m-c4ff
pkg: vm2
eco: npm
published: Oct 1, 2026
### Summary
Untrusted JavaScript running inside `new VM().run()` / `new NodeVM().run()` can bypass `vm.freeze()` / `vm.readonly()` and mutate a host object the embedder explicitly marked read-only – the documented contract is "prevent sandboxed scripts from adding, changing, or deleting properties".…
CVE-2026-92949
GitHub-GHSA

MEDIUM
sqlite3-ruby: Use-After-Free in SQLite Aggregate Arguments in Heap-Allocated Argument Array
GHSA-mwm8-39rw-8826
pkg: sqlite3
eco: rubygems
published: Oct 2, 2026
## Summary

Using `Database#create_aggregate`, `#create_aggregate_handler`, or `Database#define_aggregator` to define an aggregate function that takes two or more arguments, and then evaluating it over TEXT or BLOB column values, can free the Ruby objects holding those arguments while a later argume…

GitHub-GHSA

MEDIUM
rmcp OAuth client fetches server-controlled resource_metadata URLs
GHSA-c9xm-49cp-xcr9
pkg: rmcp
eco: rust
published: Oct 2, 2026
## Summary

The `rmcp` OAuth client accepts a server-controlled `resource_metadata=` URL from the `WWW-Authenticate` header and fetches it without same-origin or private-network validation.

An attacker-controlled MCP server can return a `401 WWW-Authenticate: Bearer resource_metadata="…"` header …

GitHub-GHSA

MEDIUM
devalue: Residual sparse-array CPU amplification in uneval
GHSA-hx4r-w6wj-j8fg
pkg: devalue
eco: npm
published: Oct 1, 2026
`uneval` performs synchronous work proportional to a sparse array's declared length. An application that passes attacker-influenced sparse values to `uneval` can suffer event-loop blocking. Since attacker-controlled creation of sparse arrays is so difficult, this vulnerability is very difficult to e…
GitHub-GHSA

MEDIUM
devalue: Malformed null-prototype object keys bypass __proto__ rejection via property-key coercion
GHSA-4q55-j62x-fr9h
pkg: devalue
eco: npm
published: Oct 1, 2026
This is another instance of https://github.com/sveltejs/devalue/security/advisories/GHSA-mwv9-gp5h-frr4, where some payloads could cause `parse` to create objects with a `__proto__` own property. This on its own is not enough to cause prototype pollution, and indeed this is actually how `JSON.parse`…
GitHub-GHSA

MEDIUM
virtualenv writes prompt values into pyvenv.cfg without sanitizing line boundaries, allowing configuration injection
GHSA-9h9j-4vrj-gf7g
pkg: virtualenv
eco: pip
published: Sep 30, 2026
### Summary

`pyvenv.cfg` is a line-based format with no escape syntax. `PyEnvCfg.write()` wrote values verbatim, while `PyEnvCfg._read_values()` parses the file with `str.splitlines()`. A value containing a line boundary therefore became additional configuration lines, and because reading is last-w…

CVE-2026-102938
GitHub-GHSA

MEDIUM
GitPython submodule update path traversal can write outside the repository
GHSA-59cr-6r3x-644w
pkg: GitPython
eco: pip
published: Sep 30, 2026
**Affected:** `GitPython` **3.1.61** (latest release) and `main` — `git/objects/submodule/base.py`. `git diff 3.1.61 origin/main — git/objects/submodule/` is empty, so both are identical here.

—

## The gap

The fix for `GHSA-hmq2-w58f-27jc` added `Submodule._validated_name()` and wired it int…

GitHub-GHSA

MEDIUM
Astro: Netlify Image CDN allowlist bypass enables SSRF
GHSA-4233-jc72-56c5
pkg: @astrojs/netlify
eco: npm
published: Sep 30, 2026
## Summary

The `@astrojs/netlify` adapter generated regular expressions for Netlify Image CDN remote-image allowlists without anchoring them to the beginning of the URL. Netlify evaluates these expressions with `RegExp.test()`, so an allowed image origin appearing anywhere in a URL, including its p…

CVE-2026-102983
GitHub-GHSA

MEDIUM
Axios: Header Injection via Inherited headers After Minimal Interceptor
GHSA-j8rh-479h-cp32
pkg: axios
eco: npm
published: Sep 30, 2026
## Summary

Axios request interceptors may return a replacement config object. If an interceptor returns a plain object without an own `headers` property, `dispatchRequest()` later evaluates `config.headers` and can resolve an inherited `Object.prototype.headers` value. In a process where another vu…

CVE-2026-101904
GitHub-GHSA

MEDIUM
Axios: Fetch Adapter Header Injection via Inherited FormData getHeaders
GHSA-4hqw-qxg8-jxx2
pkg: axios
eco: npm
published: Sep 30, 2026
## Summary

Axios contains a guard in the Node HTTP adapter to avoid using an inherited `Object.prototype.getHeaders` as a FormData header source. The fetch adapter calls the shared `resolveConfig()` helper before dispatch, and that helper lacks the same guard. If another vulnerability pollutes `Obj…

CVE-2026-101900
GitHub-GHSA

MEDIUM
Axios: CIDR-form NO_PROXY entries are ignored, causing proxy exclusion bypass for internal IP ranges
GHSA-44g4-m2mj-wpvx
pkg: axios
eco: npm
published: Sep 30, 2026
## Summary

Axios supports proxy environment variables and evaluates `NO_PROXY` exclusions in the Node.js adapter. CIDR-form `NO_PROXY` entries such as `127.0.0.0/8`, `10.0.0.0/8`, or `169.254.169.254/32` are not interpreted as IP ranges. As a result, a request to an IP address inside a configured C…

CVE-2026-101899
GitHub-GHSA

MEDIUM
Axios: Prototype pollution gadget in fetch adapter can alter outbound requests
GHSA-vh66-26gq-q6x8
pkg: axios
eco: npm
published: Sep 30, 2026
## Summary

Axios fetch adapter requests can be altered by inherited properties on `fetchOptions`. The adapter resolves method, headers, body, signal, and credentials into `resolvedOptions`, creates a `Request`, and then calls `fetch(request, fetchOptions)` instead of `fetch(request, resolvedOptions…

CVE-2026-101908
GitHub-GHSA

MEDIUM
Axios: Prototype-Pollution Gadget in the Default Instance Allows Inherited Object.prototype.method to Override HTTP Method
GHSA-9fr6-4gfg-395g
pkg: axios, axios
eco: npm
published: Sep 30, 2026
## Summary

Axios default-instance requests that omit an explicit method can read an inherited `method` value from `Object.prototype`. If another vulnerability in the same process pollutes `Object.prototype.method`, calls such as `axios.request({ url })` and `axios({ url })` can send a state-changin…

CVE-2026-101902
GitHub-GHSA

MEDIUM
urllib3: Chunked Deflate streaming can enter an infinite loop
GHSA-gh4c-6fx4-qh6g
pkg: urllib3
eco: pip
published: Sep 30, 2026
### Impact

urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading content in chunks instead of loading the entire response body into memory at once.

urllib3 can decompress response bodies according to the HTTP `Content-Encoding` header. When streaming a c…

CVE-2026-97688
GitHub-GHSA

MEDIUM
ip-address: isInSubnet() and isHostInSubnet() compare addresses of different families as if they shared an address space, allowing an allowlist check to admit an address outside its range
GHSA-j6r3-76f7-8jcv
pkg: ip-address
eco: npm
published: Sep 29, 2026
### Summary

`isInSubnet()` and `isHostInSubnet()` accept an address of either family and compare masked binary strings without checking that both operands are the same family. `Address4` pads to 32 bits and `Address6` to 128, so whenever the leading bits agree the strings are equal: `new Address6('…

CVE-2026-101912
GitHub-GHSA

MEDIUM
ip-address: Address6 builds a parse diagnostic proportional to the input with no length bound, allowing a single long string to stall or crash the process
GHSA-h3mg-xc3c-68pw
pkg: ip-address
eco: npm
published: Sep 29, 2026
### Summary

`new Address6()` and `Address6.isValid()` place no bound on the length of the string they parse. When the string contains a character that cannot appear in an IPv6 address, the parser builds a diagnostic that wraps every such character in a 34-byte `<span class="parse-error">`, so the w…

CVE-2026-101911
GitHub-GHSA

MEDIUM
OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full
GHSA-hjf4-fphr-2h65
pkg: go.opentelemetry.io/otel/sdk/log
eco: go
published: Sep 29, 2026
### Summary

A `BatchingProcessor` in `go.opentelemetry.io/otel/sdk/log` can enter a tight CPU loop when the asynchronous export buffer is full. Under exporter backpressure, attacker-driven high-volume log emission can keep the queue at or above the batch size, causing repeated immediate export retr…

CVE-2026-81872
GitHub-GHSA

MEDIUM
OpenTelemetry-Go: UTF-8 replacement rune bypasses attribute length truncation
GHSA-p9f8-wvj8-2fg8
pkg: go.opentelemetry.io/otel/sdk
eco: go
published: Sep 29, 2026
### Summary

The OpenTelemetry Go SDK trace package can fail to enforce `AttributeValueLengthLimit` for string attributes containing the valid Unicode replacement character U+FFFD. An oversized attacker-controlled attribute value that includes U+FFFD is returned untruncated, bypassing the configured…

CVE-2026-81869