Vulnerability Digest — May 25, 2026 · 29 Critical · 10 Exploited






Vulnerability Digest — Monday, May 25, 2026


Security Report

Monday, May 25, 2026  ·  Last 7 days  ·  Min severity: MEDIUM
Total Findings
216
Critical
29
High
90
Actively Exploited
10
CISA-KEV10
GitHub-GHSA206
Findings sorted by severity
CISA-KEV

CRITICAL
Drupal Core SQL Injection Vulnerability
CVE-2026-9082
pkg: Drupal Core

published: May 22, 2026

Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
Langflow Origin Validation Error Vulnerability
CVE-2025-34291
pkg: Langflow Langflow

published: May 21, 2026

Langflow contains an origin validation error vulnerability in which an overly permissive CORS configuration combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint…
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability
CVE-2026-34926
pkg: Trend Micro Apex One

published: May 21, 2026

Trend Micro Apex One (on-premise) contains a directory traversal vulnerability that could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
Microsoft Windows Buffer Overflow Vulnerability
CVE-2008-4250
pkg: Microsoft Windows

published: May 20, 2026

Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
Microsoft DirectX NULL Byte Overwrite Vulnerability
CVE-2009-1537
pkg: Microsoft DirectX

published: May 20, 2026

Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability
CVE-2009-3459
pkg: Adobe Acrobat and Reader

published: May 20, 2026

Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
Microsoft Internet Explorer Use-After-Free Vulnerability
CVE-2010-0249
pkg: Microsoft Internet Explorer

published: May 20, 2026

Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product util…
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
Microsoft Internet Explorer Use-After-Free Vulnerability
CVE-2010-0806
pkg: Microsoft Internet Explorer

published: May 20, 2026

Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users shou…
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
Microsoft Defender Link Following Vulnerability
CVE-2026-41091
pkg: Microsoft Defender

published: May 20, 2026

Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
Microsoft Defender Denial of Service Vulnerability
CVE-2026-45498
pkg: Microsoft Defender

published: May 20, 2026

Microsoft Defender contains an unspecified vulnerability that allows for denial of service.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
GitHub-GHSA

CRITICAL
BoxLite: Permission Bypass Allows Modification of Read-Only Files
GHSA-g6ww-w5j2-r7x3
pkg: boxlite, @boxlite-ai/boxlite, github.com/boxlite-ai/boxlite/sdks/go
eco: npm
published: May 21, 2026
#### Summary

Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code.

One of the core security features claimed by Boxlite is the ability to mount host directories in read-only mode (read_only=True) i…

CVE-2026-46695
GitHub-GHSA

CRITICAL
Malicious code in @beproduct/nestjs-auth (0.1.2 through 0.1.19) — Mini Shai-Hulud worm
GHSA-6xwp-cp5h-q856
pkg: @beproduct/nestjs-auth
eco: npm
published: May 19, 2026
## Summary

Between 2026-05-11 20:19 UTC and 22:56 UTC, an attacker used a compromised npm publish token to publish 18 malicious versions of `@beproduct/nestjs-auth` (0.1.2 through 0.1.19). The packages contained payloads from the **Mini Shai-Hulud** npm supply-chain worm campaign described by [Aiki…

CVE-2026-46412
GitHub-GHSA

CRITICAL
9router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes
GHSA-fhh6-4qxv-rpqj
pkg: 9router
eco: npm
published: May 19, 2026
## Summary

9router exposes two unauthenticated API endpoints that, when chained together, allow any network-adjacent attacker to execute arbitrary OS commands as the user running the 9router process — with **zero prerequisites** and **no credentials required**.

The vulnerability exists because t…

CVE-2026-46339
GitHub-GHSA

CRITICAL
Nezha Monitoring: RoleMember can run shell on every server (cross-tenant RCE) via POST /api/v1/cron
GHSA-99gv-2m7h-3hh9
pkg: github.com/nezhahq/nezha
eco: go
published: May 23, 2026
## Summary

`nezha`'s dashboard supports two user roles: `RoleAdmin` (Role==0) and `RoleMember` (Role==1). The cron routes `POST /api/v1/cron` and `PATCH /api/v1/cron/:id` are wired through `commonHandler` (any authenticated user) rather than `adminHandler`, and the per-server permission check on cr…

CVE-2026-46716
GitHub-GHSA

CRITICAL
Arcane Backend: Missing admin authorization on git repository endpoints allows non-admin users to exfiltrate stored Git credentials and tamper with GitOps configs
GHSA-7h26-hg47-p9hx
pkg: github.com/getarcaneapp/arcane/backend
eco: go
published: May 18, 2026
## Summary

Arcane's huma-based REST API exposes nine endpoints under `/api/customize/git-repositories` and `/api/git-repositories/sync` for managing GitOps source repositories and their stored credentials. Eight of those endpoints (`list`, `create`, `get`, `update`, `delete`, `test`, `listBranches`…

CVE-2026-45625
GitHub-GHSA

CRITICAL
Fission router exposes /fission-function/<ns>/<name> on its public listener, allowing invocation of any function without an HTTPTrigger
GHSA-3g33-6vg6-27m8
pkg: github.com/fission/fission
eco: go
published: May 21, 2026
### Summary

The Fission router registers an internal-style route — `/fission-function/<name>` and `/fission-function/<ns>/<name>` — for every `Function` object, independent of whether any `HTTPTrigger` exists for that function. The route was mounted on the same listener as user-defined `HTTPTri…

CVE-2026-46614
GitHub-GHSA

CRITICAL
Kopia: RCE via SSH ProxyCommand Injection
GHSA-2q4c-3mrw-63c3
pkg: github.com/kopia/kopia
eco: go
published: May 19, 2026
## Summary

Kopia's HTTP server, when started with `–without-password `, accepts unauthenticated requests to `/api/v1/repo/exists`. The handler forwards an attacker-supplied storage configuration to `blob.NewStorage`. For SFTP backends with `externalSSH: true`, that path constructs a process comman…

CVE-2026-45695
GitHub-GHSA

CRITICAL
Boxlite: Path Traversal Vulnerability Leads to Arbitrary File Write on the Host
GHSA-f396-4rp4-7v2j
pkg: boxlite, boxlite-cli, boxlite
eco: npm
published: May 21, 2026
#### Summary

Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and run OCI containers within them. Boxlite allows users to specify the OCI image used by containers in the sandbox. However, when processing tar entries in OCI images, Boxlite does not accoun…

CVE-2026-46703
GitHub-GHSA

CRITICAL
Malicious code in guardrails-ai 0.10.1 (supply chain compromise)
GHSA-xmpw-2vmm-p4p6
pkg: guardrails-ai
eco: pip
published: May 19, 2026
### Impact

On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of `guardrails-ai` (0.10.1) to PyPI.

**Affected:** any user who installed `guardrails-ai==0.10.1` from PyPI on May 11, 2026.

Security researchers identified the malicious package within approxim…

CVE-2026-45758
GitHub-GHSA

CRITICAL
Malware in @opensearch-project/opensearch
GHSA-27f5-xjrr-q9ff
pkg: @opensearch-project/opensearch, @opensearch-project/opensearch, @opensearch-project/opensearch
eco: npm
published: May 19, 2026
## Overview

The OpenSearch Project has sustained a security incident involving an external actor gaining force-push permissions within the project's CI infrastructure to embed malicious packages into four release versions of `@opensearch-project/opensearch`. Users are instructed to immediately take…

GitHub-GHSA

CRITICAL
Malicious dropper in mistralai 2.4.6 PyPI package
GHSA-wx9m-wx4f-4cmg
pkg: mistralai
eco: pip
published: May 18, 2026
The `mistralai` PyPI package version `2.4.6` contains a malicious dropper that executes on import on Linux. No `v2.4.6` tag, commit, or release workflow run exists in this repository, the legitimate latest version before the upload was `2.4.5`, and the upload bypassed this repository's normal releas…
GitHub-GHSA

CRITICAL
Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft
GHSA-6×44-w3xg-hqqf
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: May 19, 2026
## Summary

`azureidentity.Validate()` verifies that the PKCS#7 signer certificate chains to a trusted Azure CA but never verifies the PKCS#7 signature itself. An attacker can embed a legitimate Azure certificate alongside arbitrary content e.g. `{"vmId":"<target>"}` and the forged `vmId` will be ac…

CVE-2026-46354
GitHub-GHSA

CRITICAL
Algernon: handler.lua discovery walks parent directories above the server root
GHSA-xwcr-wm99-g9jc
pkg: github.com/xyproto/algernon
eco: go
published: May 19, 2026
### Summary

When Algernon is asked for any URL path that resolves to a directory *without* an index file, `DirPage` walks **upward through parent directories — past the configured server root** — looking for a file named `handler.lua` to execute as the request handler. The loop terminates only …

CVE-2026-45721
GitHub-GHSA

CRITICAL
FileBrowser Quantum: Path traversal in public share PATCH allows file ops outside shared directory
GHSA-qqqm-5547-774x
pkg: github.com/gtsteffaniak/filebrowser/backend
eco: go
published: May 22, 2026
## Summary

`publicPatchHandler` in `backend/http/public.go` joins user-controlled `fromPath` and `toPath` body fields with the trusted `d.share.Path` BEFORE the downstream sanitizer runs. Because `filepath.Join` collapses `..` segments during the join, the sanitizer in `resourcePatchHandler` never …

GitHub-GHSA

CRITICAL
@hulumi/policies: GitHub OIDC trust policy bypass via AWS set-qualified condition operators
GHSA-q2f7-m237-v562
pkg: @hulumi/policies
eco: npm
published: May 21, 2026
Impact: @hulumi/policies versions before 1.3.2 only checked exact AWS IAM StringLike/StringEquals condition operator keys in G_OIDC_1. Set-qualified operators such as ForAnyValue:StringLike could hide wildcard GitHub Actions OIDC sub conditions from the mandatory guardrail.

Patched in 1.3.2: the AW…

GitHub-GHSA

CRITICAL
Supply chain compromise via malicious package versions (@cap-js/sqlite, @cap-js/postgres, @cap-js/db-service)
GHSA-pvw4-cvr4-97p8
pkg: @cap-js/sqlite, @cap-js/postgres, @cap-js/db-service
eco: npm
published: May 20, 2026
## Impact

On April 29, 2026, compromised versions of `@cap-js/sqlite@2.2.2`, `@cap-js/postgres@2.2.2`, and `@cap-js/db-service@2.10.1` were published.
The malicious packages harvested credentials and attempted self-propagation.
If a compromised version was installed, all credentials accessible on t…

CVE-2026-46421
GitHub-GHSA

CRITICAL
MCP Gateway: Authority-injection and JWT/session bypass via the unauthenticated router hair-pin "router-key" / "mcp-init-host" path
GHSA-g53w-w6mj-hrpp
pkg: github.com/Kuadrant/mcp-gateway
eco: go
published: May 19, 2026
## Summary

The MCP router (ext_proc) exposes an `initialize`-method code path that, when a
request carries an `mcp-init-host` header, bypasses the gateway JWT session
validator and rewrites the upstream `:authority` header to whatever the caller
chooses, gated only by a single shared header value …

GitHub-GHSA

CRITICAL
rok Python ProxyShare can be used as an SSRF proxy through absolute URL paths
GHSA-jh67-hwqw-m5r7
pkg: zrok
eco: pip
published: May 19, 2026
## Summary

Alice exposes a Python SDK `ProxyShare` with a fixed target URL. Bob sends a request to the share with an absolute URL in the path. The Flask handler passes that path to `urllib.parse.urljoin`, which replaces Alice's configured target host with Bob's host and returns the server-side resp…

CVE-2026-45568
GitHub-GHSA

CRITICAL
HAXcms: Private Key Disclosure via Broken HMAC Implementation
GHSA-6c8g-9hfh-pq5h
pkg: @haxtheweb/haxcms-nodejs
eco: npm
published: May 19, 2026
### Summary
The `hmacBase64()` function in the HAXcms Node.js backend contains two critical cryptographic implementation errors that together allow any unauthenticated attacker to extract the system’s private signing key and forge arbitrary admin-level JSON Web Tokens (JWTs) allowing them to get f…
CVE-2026-46395
GitHub-GHSA

HIGH
Arcane: Missing admin authorization on global variables endpoint
GHSA-jpjh-jm2p-39hh
pkg: github.com/getarcaneapp/arcane/backend
eco: go
published: May 23, 2026
## Summary

The `PUT /api/environments/{id}/templates/variables` endpoint, which writes the system-wide `.env.global` file used for variable substitution in every project's compose file, is missing an admin authorization check. Any authenticated non-admin user can call this endpoint with their beare…

CVE-2026-47125
GitHub-GHSA

HIGH
MCP Server Kubernetes: Tool Access Control Bypass via Presentation-Layer Filtering Without Execution-Layer Enforcement
GHSA-cr22-wjx7-2w6m
pkg: mcp-server-kubernetes
eco: npm
published: May 21, 2026
## Summary

`mcp-server-kubernetes` exposes three environment variables (`ALLOW_ONLY_READONLY_TOOLS`, `ALLOW_ONLY_NON_DESTRUCTIVE_TOOLS`, `ALLOWED_TOOLS`) documented as access controls for restricting which Kubernetes operations are available. These controls are enforced at the tool discovery layer …

CVE-2026-46519
GitHub-GHSA

HIGH
Fission StorageSvc /v1/archive endpoint exposes unauthenticated CRUD over all function archives
GHSA-chf8-4hv6-8pg6
pkg: github.com/fission/fission
eco: go
published: May 21, 2026
### Summary

The Fission `storagesvc` component registers archive CRUD handlers (`/v1/archive` GET / POST / DELETE and `/v1/archives` list) directly on its HTTP router without performing any authentication or authorization. Any caller able to reach the `storagesvc` ClusterIP — including any other…

CVE-2026-46612
GitHub-GHSA

HIGH
PenPot MCP REPL server binds to 0.0.0.0 with unauthenticated /execute endpoint — RCE
GHSA-22qr-rp27-j9wm
pkg: @penpot/mcp
eco: npm
published: May 19, 2026
### Summary

The MCP module's `ReplServer` binds to all interfaces (`0.0.0.0:4403`) and exposes a `/execute` endpoint that runs arbitrary code with zero authentication. Anyone on the network can POST JavaScript and it runs on the server. The main `PenpotMcpServer` was partially fixed for a similar b…

CVE-2026-45805
GitHub-GHSA

HIGH
Budibase: Builder-to-Admin Privilege Escalation via onboardUsers Endpoint Without SMTP Configuration
GHSA-c54j-xp92-wh28
pkg: @budibase/worker
eco: npm
published: May 18, 2026
## Summary

The `POST /api/global/users/onboard` endpoint is protected by `workspaceBuilderOrAdmin` middleware, allowing any user with builder permissions to access it. When SMTP email is not configured (the default for self-hosted Budibase instances), this endpoint bypasses the admin-restricted inv…

CVE-2026-45716
GitHub-GHSA

HIGH
Dozzle: Pre-auth SSRF with response-body reflection via POST /api/notifications/test-webhook (default no-auth deploy)
GHSA-3v9w-6365-9w54
pkg: github.com/amir20/dozzle
eco: go
published: May 18, 2026
## Summary

In a default dozzle deploy (the documented quickstart, no `DOZZLE_AUTH_PROVIDER` set), `POST /api/notifications/test-webhook` is reachable without authentication and forwards an attacker-controlled URL into a `WebhookDispatcher` that:

– Sends an HTTP POST to the supplied URL with attack…

CVE-2026-45298
GitHub-GHSA

HIGH
Nezha Monitoring: RoleMember-reachable SSRF with full response-body reflection via POST /api/v1/notification
GHSA-w4g9-mxgg-j532
pkg: github.com/nezhahq/nezha
eco: go
published: May 23, 2026
## Summary

nezha's dashboard supports two user roles: `RoleAdmin` (Role==0) and `RoleMember` (Role==1). The notification routes `POST /api/v1/notification` and `PATCH /api/v1/notification/:id` are wired through `commonHandler` rather than `adminHandler` — so a `RoleMember` user can call them. The…

CVE-2026-46717
GitHub-GHSA

HIGH
wger: cross-tenant account deletion / deactivation / activation by gym.manage_gym + gym=None
GHSA-mw8f-w6p8-xrf4
pkg: wger
eco: pip
published: May 20, 2026
## Summary

GHSA-mhc8-p3jx-84mm (CVE-2026-43948) reported that wger's `reset_user_password` and `gym_permissions_user_edit` views in `wger/gym/views/user.py` performed a gym-scope authorization check using Django ORM object comparison (`if request.user.userprofile.gym != user.userprofile.gym`) which…

GitHub-GHSA

HIGH
SillyTavern: SSRF in SearXNG Search Proxy via Unvalidated baseUrl
GHSA-qg89-qwwh-5f3j
pkg: sillytavern
eco: npm
published: May 19, 2026
## Resolution

SillyTavern 1.18.0 added a generic server-side request filter (Private Request Whitelisting). Since we expect users to use the application in a trusted environment, the filter is disabled by default, however it is strongly advised to be enabled and properly configured when an instance…

CVE-2026-46372
GitHub-GHSA

HIGH
OpenMetadata: TEST_CONNECTION workflow leaks ingestion-bot JWT and database password to regular users
GHSA-9vmh-whc4-7phg
pkg: org.open-metadata:openmetadata-service
eco: maven
published: May 21, 2026
**This is not applicable if an application is configuring the Secrets Store to store credentials. Please make sure to follow the best practices when deploying in production**
In OpenMetadata 1.12.1, a non-admin SSO user can trigger a `TEST_CONNECTION` workflow for a Database Service and receive, in …
CVE-2026-46481
GitHub-GHSA

HIGH
Caddy Defender trusted proxy client IP bypass
GHSA-3h23-rrpc-3p87
pkg: pkg.jsn.cam/caddy-defender
eco: go
published: May 19, 2026
### Impact

Caddy Defender used `r.RemoteAddr` when evaluating whether a request should be blocked. `RemoteAddr` is the address of the immediate peer connected to Caddy.

In deployments where Caddy is behind a trusted proxy, CDN, or load balancer, the immediate peer is usually the proxy, not the ori…

CVE-2026-46415
GitHub-GHSA

HIGH
auth-fetch-mcp: SSRF and disk exfiltration via unvalidated auth_fetch and download_media URLs
GHSA-hv85-774v-26fg
pkg: auth-fetch-mcp
eco: npm
published: May 19, 2026
# SSRF + disk-exfil in `download_media` and `auth_fetch` tools — ymw0407/auth-fetch-mcp

## Severity
The `download_media` and `auth_fetch` MCP tools accept arbitrary URLs and reach them as the MCP server process, with `download_media` additionally persisting the fetched response body to a user-con…

GitHub-GHSA

HIGH
TinyIce: Missing authentication on WebRTC ingest endpoint allows unauthorized stream injection
GHSA-p7c4-8×34-8j8f
pkg: github.com/DatanoiseTV/tinyice
eco: go
published: May 18, 2026
## Title

Missing authentication on WebRTC ingest endpoint allows unauthenticated stream injection in TinyIce

## Ecosystem / Package

– **Ecosystem:** `Go` (or "Other" — TinyIce is shipped as a Go binary, not a Go module published to a registry)
– **Package name:** `github.com/DatanoiseTV/tinyice…

CVE-2026-45327
GitHub-GHSA

HIGH
@tmlmobilidade/utils has prototype pollution in its setValueAtPath
GHSA-cmxg-94mg-jq94
pkg: @tmlmobilidade/utils
eco: npm
published: May 18, 2026
### Impact
Prototype pollution vulnerability in @tmlmobilidade/utils for setValueAtPath().

### Patches
A fix is available in versions 20260509.0340.15 and up.

CVE-2026-45325
GitHub-GHSA

HIGH
parse-nested-form-data has Prototype Pollution via `__proto__` in FormData field names
GHSA-xp7r-j8r6-j9h3
pkg: parse-nested-form-data
eco: npm
published: May 18, 2026
## Summary

`parseFormData()` walks bracket and dot-notation FormData field names into nested objects without filtering reserved property keys. A single FormData field whose name begins with `__proto__`, or contains `.__proto__.` mid-path, causes the parser to traverse onto `Object.prototype` and as…

CVE-2026-45302
GitHub-GHSA

HIGH
Arcane Backend: Unauthenticated reflected XSS via SVG color parameter enables admin account takeover
GHSA-q2pj-8v84-9mh5
pkg: github.com/getarcaneapp/arcane/backend
eco: go
published: May 18, 2026
## Summary

The unauthenticated `GET /api/app-images/logo` endpoint reflects a user-supplied `color` query parameter into the body of an SVG document via `strings.ReplaceAll` with no escaping. The substitution lands inside a `<style>` element of the embedded `logo.svg`, allowing an attacker to close…

CVE-2026-45627
GitHub-GHSA

HIGH
form-data-objectizer: Prototype pollution in form-data-objectizer via bracket-notation form keys
GHSA-m2hg-wjq3-28wq
pkg: form-data-objectizer
eco: npm
published: May 18, 2026
## Summary

`form-data-objectizer` walks bracket-notation form keys (e.g. `name[sub]`) into nested objects without filtering `__proto__`, `constructor`, or `prototype`. A single HTTP form field whose name starts with `__proto__[…]` causes the library to mutate `Object.prototype`, which is a protot…

CVE-2026-46510
GitHub-GHSA

HIGH
ORAS Java: Path traversal in pullArtifact via attacker-controlled org.opencontainers.image.title annotation
GHSA-xm96-gfjx-jcrc
pkg: land.oras:oras-java-sdk
eco: maven
published: May 19, 2026
### Summary

The `pullArtifact` methods in `Registry` and `OCILayout` use the `org.opencontainers.image.title` annotation from a pulled manifest as a filename, resolving it against the caller supplied output directory without normalization or a containment check. A manifest publisher can set this an…

GitHub-GHSA

HIGH
n8n-MCP: Multi-tenant MCP requests fall back to process-level n8n credentials when tenant headers are absent or incomplete
GHSA-jxx9-px88-pj69
pkg: n8n-mcp
eco: npm
published: May 18, 2026
## Summary

When `ENABLE_MULTI_TENANT=true`, the HTTP transport documents that the target n8n instance is selected per-request from `x-n8n-url` / `x-n8n-key` headers. Requests that omitted those headers — or supplied only one of them — silently fell back to the process-level `N8N_API_URL` / `N8N…

CVE-2026-45707
GitHub-GHSA

HIGH
Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Files
GHSA-m675-2p33-xv9g
pkg: github.com/caddyserver/caddy/v2
eco: go
published: May 18, 2026
### Summary

The FastCGI transport's `splitPos()` in [`modules/caddyhttp/reverseproxy/fastcgi/fastcgi.go`](https://github.com/caddyserver/caddy/blob/master/modules/caddyhttp/reverseproxy/fastcgi/fastcgi.go) misuses `golang.org/x/text/search` with `search.IgnoreCase` when the request path contains a …

CVE-2026-45135
GitHub-GHSA

HIGH
lmdeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out
GHSA-9xq9-36w5-q796
pkg: lmdeploy
eco: pip
published: May 21, 2026
> ## 📋 Reframing (2026-05-02): implicit unsafe remote-code path, not "supply-chain"
>
> The accurate description of this vulnerability is:
> **"`get_model_arch` and related helpers hardcode `trust_remote_code=True`
> with no opt-out, creating an implicit unsafe remote-code load path
> on every mo…
CVE-2026-46517
GitHub-GHSA

HIGH
LMDeploy: Arbitrary code execution via hardcoded trust_remote_code=True in lmdeploy model initialization
GHSA-m549-qq94-fvhg
pkg: lmdeploy
eco: pip
published: May 21, 2026
## Summary

lmdeploy hardcodes `trust_remote_code=True` in multiple HuggingFace model-loading call sites.

The affected code paths are in:

“`text
lmdeploy/archs.py
lmdeploy/utils.py
““

The vulnerable call sites pass `trust_remote_code=True` into HuggingFace Transformers APIs such as `AutoConfig…

CVE-2026-46432
GitHub-GHSA

HIGH
Graphite Has a Pickle Deserialization Vulnerability
GHSA-qw48-84f6-28gv
pkg: graphitedb
eco: pip
published: May 18, 2026
### Impact
**Type of vulnerability:** Insecure Deserialization via Python's `pickle` module.

**Who is impacted:**
Users of *Graphite graph database engine* versions **before 0.2** who load database files from untrusted or third-party sources.
An attacker could craft a malicious database file th…

GitHub-GHSA

HIGH
Network-AI: Unauthenticated Cross-Origin MCP Tool Invocation via Empty Default Secret
GHSA-j3vx-cx2r-pvg8
pkg: network-ai
eco: npm
published: May 21, 2026
# Unauthenticated Cross-Origin MCP Tool Invocation via Empty Default Secret

| Field | Value |
| —————- | —– |
| Repository | Jovancoding/Network-AI |
| Affected version | v5.4.4 (commit c12686e181f231cf8d7bcf836a96d78f0f0877ac) |

## Summary

The MCP SSE server default…

CVE-2026-46701
GitHub-GHSA

HIGH
Budibase: Unrestricted Upload of File with Dangerous Type
GHSA-82rc-gxrg-v4gf
pkg: budibase
eco: npm
published: May 19, 2026
### Summary
The file upload endpoint `POST /api/attachments/process` does not enforce active-content restrictions for authenticated users. The checks for dangerous file extensions (`html`, `svg`, `js`, `php`, etc.) are conditionally wrapped inside `if (isPublicUser)` or `if (isPublicUser || !env.SEL…
CVE-2026-46426
GitHub-GHSA

HIGH
aiosend: Deserialization of request body before signature verification (Pre-auth DoS) in webhook handler
GHSA-7m8f-hgjq-8gc9
pkg: aiosend
eco: pip
published: May 22, 2026
# Vulnerability Description

In `aiosend/webhook/base.py`, the `WebhookHandler.feed_update()` method performs full deserialization of the incoming JSON via Pydantic **before** verifying the HMAC signature. Anyone can send a request with an arbitrary body — the server will parse it, spend CPU and m…

GitHub-GHSA

HIGH
js-libp2p: Memory DoS via subscription flood of unique topics
GHSA-4f8r-922h-2vgv
pkg: @libp2p/gossipsub
eco: npm
published: May 21, 2026
### Summary
Three cooperating omissions in `@libp2p/gossipsub` allow an unauthenticated single peer to exhaust the Node.js heap of any gossipsub node with default options.

1. **`defaultDecodeRpcLimits.maxSubscriptions = Infinity`** (`packages/gossipsub/src/message/decodeRpc.ts:11`): no decode-level…

CVE-2026-46679
GitHub-GHSA

HIGH
JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection
GHSA-qjx8-664m-686j
pkg: js-cookie
eco: npm
published: May 21, 2026
## Summary

`js-cookie`'s internal `assign()` helper copies properties with `for…in` + plain assignment. When the source object is produced by `JSON.parse`, the JSON object's `"__proto__"` member is an *own enumerable* property, so the `for…in` enumerates it and the `target[key] = source[key]` w…

CVE-2026-46625
GitHub-GHSA

HIGH
Russh: Unchecked CryptoVec allocation and growth handling is reachable
GHSA-g9f8-wqj9-fjw5
pkg: russh-cryptovec, russh
eco: rust
published: May 21, 2026
### Title
Unchecked `CryptoVec` allocation and growth handling was reachable from local agent inputs in current `russh` releases and from remote SSH traffic in historical pre-`0.58.0` releases

### Summary
`CryptoVec` used unchecked capacity growth, unchecked length arithmetic, and unsafe allocation…

CVE-2026-46673
GitHub-GHSA

HIGH
nimiq-primitives: Panic DoS in trie chunk processing via ROOT-keyed item
GHSA-mw3q-r9wh-h2ff
pkg: nimiq-primitives
eco: rust
published: May 21, 2026
### Impact

A remote, unauthenticated denial-of-service vulnerability in `MerkleRadixTrie::put_chunk` allows any state-sync peer to crash any node performing state synchronization (freshly joining nodes and recovering nodes).

A malicious peer can respond to a `RequestChunk` with a `ResponseChunk::C…

CVE-2026-46545
GitHub-GHSA

HIGH
Diffusers: TOCTOU Trust Remote Code Bypass
GHSA-7wx4-6vff-v64p
pkg: diffusers
eco: pip
published: May 20, 2026
## Background

This vulnerability is found in the `diffusers` package – the `transformers`-equivalent library for diffusion models.

It is found in the `DiffusionPipeline.from_pretrained` flow, which is used to load a pipeline from the HuggingFace Hub.

This function has a `trust_remote_code` guard:…

CVE-2026-45804
GitHub-GHSA

HIGH
SQLFluff: Uncontrolled Resource Consumption in SQLFluff Parser
GHSA-73jc-5mrq-prw7
pkg: sqlfluff
eco: pip
published: May 19, 2026
### Impact

In deployments where untrusted users can provide SQL queries to be linted, an untrusted user can submit a malicious long query to any application using the parser to trigger a Denial of Service through resource exhaustion.

### Patches

Versions 4.2.0 and up contain a configurable parse …

CVE-2026-46374
GitHub-GHSA

HIGH
SQLFluff: Recursive Stack Overflow in Parser
GHSA-wmhf-fqc8-vxhh
pkg: sqlfluff
eco: pip
published: May 19, 2026
### Impact

In deployments where untrusted users can provide SQL queries to be linted, an untrusted user can submit a malicious query with deliberate excessive nesting to any application using the parser to trigger a Denial of Service through resource exhaustion.

### Patches

Versions 4.1.0 and up …

CVE-2026-46373
GitHub-GHSA

HIGH
Dasel: Denial of service in dasel selector lexer due to infinite loop on unterminated regex literal
GHSA-m6xr-fvfg-5g64
pkg: github.com/tomwright/dasel/v3
eco: go
published: May 19, 2026
### Summary

`dasel`'s selector lexer enters a non-terminating loop when tokenizing an unterminated regex pattern such as `r/abc`. A 2-byte input (`r/`) is sufficient to cause the tokenizer to consume 100% CPU on one core indefinitely.

I confirmed the issue on `v3.3.1` (`fba653c7f248aff10f2b89fca93…

CVE-2026-46378
GitHub-GHSA

HIGH
Dasel: Index-out-of-range panic in dasel selector lexer on trailing backslash in quoted string
GHSA-m5j3-4634-c2vq
pkg: github.com/tomwright/dasel/v3
eco: go
published: May 19, 2026
### Summary

`dasel`'s selector lexer panics with an index-out-of-range error when tokenizing a quoted string that ends with a trailing backslash (e.g., `"\` or `'\`). A 2-byte input causes an immediate process crash via Go runtime panic.

I confirmed the issue on `v3.3.1` (`fba653c7f248aff10f2b89fc…

CVE-2026-46377
GitHub-GHSA

HIGH
@libp2p/kad-dht: Unvalidated PUT_VALUE records allow unbounded disk exhaustion on DHT server nodes
GHSA-32mq-hpph-xfvr
pkg: @libp2p/kad-dht
eco: npm
published: May 19, 2026
### Summary
An unauthenticated remote peer can exhaust the disk storage of any `@libp2p/kad-dht` node running in server mode by sending an unbounded stream of `PUT_VALUE` messages whose keys bypass all content validation. No credentials, no prior relationship, and no protocol deviation beyond a craf…
CVE-2026-45783
GitHub-GHSA

HIGH
Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service
GHSA-7xpr-hc2w-34m9
pkg: com.squareup.wire:wire-runtime-jvm, com.squareup.wire:wire-runtime, com.squareup.wire:wire-runtime
eco: maven
published: May 19, 2026
# CVE-2026-45799

## Maintainer summary

Wire's protobuf group-skipping logic did not reject negative lengths before skipping a
length-delimited field inside a group. A crafted protobuf payload could cause Wire to throw an
unchecked runtime exception during decoding instead of the documented `IOExce…

CVE-2026-45799
GitHub-GHSA

HIGH
Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes
GHSA-fpxj-m5q8-fphw
pkg: github.com/axllent/mailpit
eco: go
published: May 19, 2026
### Summary
The Mailpit SMTP server has a Server.MaxSize int field that controls the maximum allowed DATA payload size, but the field is never assigned anywhere outside test code, leaving it at Go's zero value (0 ⇒ "no limit"). The same applies to the HTTP /api/v1/send endpoint, whose request body…
CVE-2026-45713
GitHub-GHSA

HIGH
Algernon: Single-file mode unconditionally enables debug mode
GHSA-fwqx-8365-9983
pkg: github.com/xyproto/algernon
eco: go
published: May 19, 2026
### Summary

When Algernon is invoked with a single file path instead of a directory — the documented "quick demo" workflow (`algernon foo.lua`, `algernon page.po2`, `algernon index.html`, `algernon mywebsite.alg`) — `singleFileMode` is set to true and **`debugMode` is forcibly enabled** with no…

CVE-2026-45728
GitHub-GHSA

HIGH
ImageMagick: Infinite Loop in the MIFF decoder can lead to CPU exhaustion
GHSA-7gg8-qqx7-92g5
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 18, 2026
Due to a missing check in the MIFF decoder a crafted file could cause an infinite loop resulting in CPU exhaustion.
CVE-2026-46522
GitHub-GHSA

HIGH
ImageMagick: Heap Buffer Over-Write in IPL decoder when reading multiple images of different dimensions
GHSA-36wm-hprc-mcf5
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 18, 2026
When reading multiple images with different dimensions an out of bounds heap write can occur.
CVE-2026-46520
GitHub-GHSA

HIGH
HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint
GHSA-3653-68v6-rq57
pkg: ca.uhn.hapi.fhir:org.hl7.fhir.dstu2, ca.uhn.hapi.fhir:org.hl7.fhir.dstu2016may, ca.uhn.hapi.fhir:org.hl7.fhir.dstu3
eco: maven
published: May 18, 2026
## Summary

All implementations of FHIRPathEngine accept arbitrary FHIRPath expressions and evaluate them without input validation. The FHIRPath functions `matches()`, `matchesFull()`, and `replaceMatches()` pass user-controlled regular expressions directly to Java's `Pattern.compile()` and `String.…

CVE-2026-45367
GitHub-GHSA

HIGH
NiceGUI: Local file disclosure via Docutils file insertion in ui.restructured_text()
GHSA-jfrm-rx66-g536
pkg: nicegui
eco: pip
published: May 18, 2026
### Summary

`ui.restructured_text()` renders reStructuredText server-side with Docutils without disabling file insertion directives.

When a NiceGUI application passes attacker-controlled content to `ui.restructured_text()`, an attacker can use standard Docutils directives (`include`, `csv-table` w…

CVE-2026-45553
GitHub-GHSA

HIGH
OpenTelemetry eBPF Instrumentation: Memcached payload length overflow can crash OBI
GHSA-43g7-cwr8-q3jh
pkg: go.opentelemetry.io/obi
eco: go
published: May 18, 2026
### Summary

A remotely reachable integer overflow in OBI's memcached text protocol parser can crash the OBI process and cause denial of service. When parsing memcached storage commands such as `set`, `add`, `replace`, `append`, `prepend`, or `cas`, OBI accepts extremely large `<bytes>` values and a…

CVE-2026-45686
GitHub-GHSA

HIGH
OpenTelemetry eBPF Instrumentation: MongoDB parser panics on malformed wire messages
GHSA-j8p6-96vp-f3r9
pkg: go.opentelemetry.io/obi
eco: go
published: May 18, 2026
### Summary

Malformed MongoDB wire messages can trigger uncaught panics in the MongoDB TCP parser, allowing a remote unauthenticated attacker to crash the telemetry agent and cause a denial of service. The parser operates on raw attacker-controlled network payloads before the input is fully validat…

CVE-2026-45685
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-42899 – ASP.NET Core Denial of Service Vulnerability
GHSA-9v76-4qcc-frgh
pkg: Microsoft.AspNetCore.App.Runtime.win-arm, Microsoft.AspNetCore.App.Runtime.win-arm64, Microsoft.AspNetCore.App.Runtime.win-x64
eco: nuget
published: May 18, 2026
## Executive Summary:

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 8.0, .NET 9.0, and .NET 10.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

Loop with unreachable ex…

CVE-2026-42899
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-32175 – .NET Core Tampering Vulnerability
GHSA-rg75-q538-x34v
pkg: Microsoft.NetCore.App.Runtime.win-arm, Microsoft.NetCore.App.Runtime.win-arm, Microsoft.NetCore.App.Runtime.win-arm
eco: nuget
published: May 18, 2026
## Executive Summary:

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 8.0, .NET 9.0, and .NET 10.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A tampering vulnerabil…

CVE-2026-32175
GitHub-GHSA

HIGH
OpenTelemetry eBPF Instrumentation: Postgres BIND parsing can panic on malformed payloads
GHSA-pgvv-q3wf-mm9m
pkg: go.opentelemetry.io/obi
eco: go
published: May 18, 2026
### Summary

The Postgres protocol parser assumes `BIND` message payloads contain a valid NUL-terminated portal name. A crafted empty or unterminated payload can make OBI slice beyond the end of the captured buffer and panic.

### Details

The vulnerable logic is in [pkg/ebpf/common/sql_detect_postg…

CVE-2026-45678
GitHub-GHSA

HIGH
multiparty vulnerable to ReDoS via filename parsing
GHSA-65×3-rw7q-gx94
pkg: multiparty
eco: npm
published: May 18, 2026
### Impact

multiparty@4.2.3 and lower versions are vulnerable to denial of service via regular expression backtracking in the `Content-Disposition` filename parameter parser. A multipart upload with a long header value containing `!filename="1` repeated can cause regex matching to take seconds, blo…

CVE-2026-8159
GitHub-GHSA

HIGH
multiparty vulnerable to Denial of Service via Uncaught Exception in filename* parameter parsing
GHSA-xh3c-6gcq-g4rv
pkg: multiparty
eco: npm
published: May 18, 2026
### Impact

multiparty@4.2.3 and lower versions are vulnerable to denial of service via uncaught exception. By sending a `multipart/form-data` request with a `Content-Disposition: filename*=utf-8''` header containing a malformed percent-encoding (e.g., `%FF`, `%GG`), the parser invokes `decodeURI` o…

CVE-2026-8162
GitHub-GHSA

HIGH
multiparty: Denial of Service via Prototype Pollution leads to Uncaught Exception
GHSA-qxch-whhj-8956
pkg: multiparty
eco: npm
published: May 18, 2026
### Impact

multiparty@4.2.3 and lower versions are vulnerable to denial of service via uncaught exception. By sending a `multipart/form-data` request with a field name that collides with an inherited `Object.prototype` property (e.g., `__proto__`, `constructor`, `toString`), the parser invokes `.pu…

CVE-2026-8161
GitHub-GHSA

HIGH
dynoxide: DNS rebinding and cross-origin CSRF via MCP HTTP transport
GHSA-fvh2-gm75-j4j7
pkg: dynoxide-rs, dynoxide
eco: npm
published: May 18, 2026
## Summary

dynoxide's MCP HTTP transport was vulnerable to DNS rebinding via its transitive `rmcp` dependency, plus a related cross-origin CSRF gap. A malicious web page could make the user's browser send requests to a local `dynoxide mcp –http` or `dynoxide serve –mcp` server with a non-loopback…

GitHub-GHSA

HIGH
iskorotkov/avro: CPU Exhaustion in Decoder
GHSA-w8j3-pq8g-8m7w
pkg: github.com/iskorotkov/avro/v2
eco: go
published: May 18, 2026
# CPU Exhaustion in Avro Decoder via Unbounded Block-Count Iteration

## Summary

The Avro array and map decoders looped over an attacker-controlled block-count value without checking the underlying reader's error state inside the loop body. `Reader.ReadBlockHeader` returns the count as a Go `int`, …

CVE-2026-46385
GitHub-GHSA

HIGH
iskorotkov/avro: Integer Overflow in Decoder
GHSA-mc57-h6j3-3hmv
pkg: github.com/iskorotkov/avro/v2
eco: go
published: May 18, 2026
# Integer Overflow in Avro Decoder

## Summary

Several Avro decoder paths read attacker-controlled 64-bit values from the wire format and either narrowed them to platform-sized `int` before bounds-checking, or summed them with overflow-prone signed-`int` arithmetic. On 32-bit targets (`GOARCH=386`,…

CVE-2026-46384
GitHub-GHSA

HIGH
iskorotkov/avro: Denial-of-Service Vulnerability in Decoder
GHSA-mx64-mj3q-7prj
pkg: github.com/iskorotkov/avro/v2
eco: go
published: May 18, 2026
# Memory Exhaustion via Unbounded Map Allocations in Avro Decoder

## Summary

The Avro map decoder accepted attacker-controlled block-element counts from the wire format and grew the destination map without enforcing an upper bound. The slice decoder already had `Config.MaxSliceAllocSize` for the e…

GitHub-GHSA

HIGH
ruby-jwt: Empty-key HMAC bypass; cross-language sibling of CVE-2026-44351
GHSA-c32j-vqhx-rx3x
pkg: jwt
eco: rubygems
published: May 18, 2026
`JWT.decode(token, '', true, algorithm: 'HS256')` accepts an attacker-forged token.
`OpenSSL::HMAC.digest('SHA256', '', payload)` returns a valid digest under an empty key, and no `raise
InvalidKeyError if key.empty?` precondition exists in the HMAC algorithm.

“`
JWT.decode(token, "", true, algo…

CVE-2026-45363
GitHub-GHSA

HIGH
async-http-client: Cookie header not stripped on cross-origin redirect
GHSA-fmxf-pm6p-7xgm
pkg: org.asynchttpclient:async-http-client, org.asynchttpclient:async-http-client
eco: maven
published: May 18, 2026
## Summary

async-http-client leaks `Cookie` headers to cross-origin redirect targets. When following a redirect across a security boundary (different origin, or HTTPS→HTTP downgrade), the `propagatedHeaders()` method in `Redirect30xInterceptor.java` strips `Authorization` and `Proxy-Authorization…

CVE-2026-45300
GitHub-GHSA

HIGH
Microsoft APM: Symlinks under `.apm/prompts/` and `.apm/agents/` are dereferenced during `apm install`, copying host-local file contents into the project tree
GHSA-q5pp-gvjg-h7v4
pkg: apm
eco: pip
published: May 18, 2026
## Summary

Two primitive integrators in `apm-cli` enumerate package files with bare `Path.glob()` / `Path.rglob()` calls and read each match with `Path.read_text()`, transparently following symbolic links.

A symlink committed inside a remote APM dependency under `.apm/prompts/<x>.prompt.md` or `.a…

CVE-2026-45539
GitHub-GHSA

HIGH
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation
GHSA-h98r-wv3h-fr38
pkg: github.com/argoproj/argo-cd/v3, github.com/argoproj/argo-cd/v3, github.com/argoproj/argo-cd/v3
eco: go
published: May 19, 2026
### Summary

A user with **application write access (developer role)** can set `link.argocd.argoproj.io/*` annotations on any ArgoCD Application. These annotation values are rendered in the Summary tab's **URLs section** as `<a href>` elements without URL validation. Using the pipe-separator trick (…

CVE-2026-45738
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-35433 – .NET Elevation of Privilege Vulnerability
GHSA-8x9c-mqxv-q2pp
pkg: Microsoft.WindowsDesktop.App.Runtime.win-arm64, Microsoft.WindowsDesktop.App.Runtime.win-x64, Microsoft.WindowsDesktop.App.Runtime.win-x86
eco: nuget
published: May 18, 2026
## Executive Summary:

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 8.0, .NET 9.0, and .NET 10.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

Improper input validatio…

CVE-2026-35433
GitHub-GHSA

HIGH
md-fileserver: Stored/Reflected XSS when viewing Markdown (raw HTML allowed)
GHSA-32q2-hhr5-6qvv
pkg: md-fileserver
eco: npm
published: May 21, 2026
### Summary
A cross-site scripting (XSS) vulnerability exists in the application’s Markdown rendering logic. When user-supplied Markdown content is rendered, embedded raw HTML—including <script> tags—is processed and injected into the resulting page without sanitization, allowing arbitrary Jav…
CVE-2026-46492
GitHub-GHSA

HIGH
Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK ModelBuilder/Serve path
GHSA-7hh5-prp2-mfh5
pkg: sagemaker, sagemaker
eco: pip
published: May 21, 2026
## Summary
Amazon SageMaker Python SDK is an open-source library for training and deploying machine learning models on Amazon SageMaker. An issue exists where, under certain circumstances, the ModelBuilder/Serve component stores an HMAC signing key in cleartext as a container environment variable, w…
CVE-2026-8596
GitHub-GHSA

HIGH
Docker: Race condition in docker cp allows bind mount redirection to host path
GHSA-rg2x-37c3-w2rh
pkg: github.com/docker/docker, github.com/moby/moby/v2, github.com/moby/moby
eco: go
published: May 18, 2026
## Summary

A race condition during `docker cp` mount setup allows a malicious container to redirect a bind mount target to an arbitrary host path, potentially overwriting host files or causing denial of service.

## Details

When copying files into a container, the daemon sets up a temporary filesy…

CVE-2026-42306
GitHub-GHSA

HIGH
Docker: `PUT /containers/{id}/archive` executes container binary on the host
GHSA-x86f-5xw2-fm2r
pkg: github.com/moby/moby/v2, github.com/docker/docker, github.com/moby/moby
eco: go
published: May 18, 2026
## Summary

When a user uploads a compressed archive into a container, a malicious image can execute arbitrary code with daemon (host root) privileges.

## Details

When handling `PUT /containers/{id}/archive` requests with compressed archives, the daemon decompresses them using external system bina…

CVE-2026-41567
GitHub-GHSA

HIGH
Spring AI MCP Security: Unvalidated URL Fetching (SSRF)
GHSA-qjp4-4jvr-xqg3
pkg: org.springaicommunity:mcp-client-security
eco: maven
published: May 18, 2026
### Summary

The mcp-security framework fails to implement the mandatory SSRF mitigations outlined in the Model Context Protocol (MCP) [security specifications](https://modelcontextprotocol.io/docs/tutorials/security/security_best_practices#mitigation-3). Specifically, it processes untrusted URLs fo…

CVE-2026-45609
GitHub-GHSA

HIGH
Parse Server: Pre-authentication denial of service via client version header regex backtracking
GHSA-38m6-82c8-4xfm
pkg: parse-server, parse-server
eco: npm
published: May 23, 2026
### Impact

An unauthenticated attacker who knows a publicly-known Parse Application ID can submit a single HTTP request whose client SDK version field contains adversarial input that triggers polynomial backtracking in a request-header parser. The parsing runs before session authentication and befo…

CVE-2026-47138
GitHub-GHSA

HIGH
@nevware21/ts-utils: Prototype Pollution in objDeepCopy/objCopyProps via for…in without hasOwnProperty
GHSA-x7j8-49r8-mr43
pkg: @nevware21/ts-utils
eco: npm
published: May 21, 2026
## Summary

The _copyProps function in lib/src/object/copy.ts uses for…in to iterate over source object properties without an Object.hasOwnProperty check, and does not filter dangerous keys (__proto__, constructor, prototype). This allows an attacker to pollute the prototype chain of all objects i…

CVE-2026-46681
GitHub-GHSA

HIGH
containerd user ID handling bypass allows runAsNonRoot evasion
GHSA-fqw6-gf59-qr4w
pkg: github.com/containerd/containerd, github.com/containerd/containerd/v2, github.com/containerd/containerd/v2
eco: go
published: May 21, 2026
### Impact
A bug was found in containerd where containers launched with a numeric `User` directive that cannot be parsed as a 32-bit integer are incorrectly treated as a username. If a crafted image provides an `/etc/passwd` file mapping this large numeric string to root, the container ultimately ru…
CVE-2026-46680
GitHub-GHSA

HIGH
@hulumi/policies: Stack-wide evidence bypassed Cloudflare and deployment-governance guardrails
GHSA-59f3-7227-wmh4
pkg: @hulumi/policies
eco: npm
published: May 21, 2026
Impact: @hulumi/policies versions before 1.3.2 used stack-wide evidence shortcuts in several Cloudflare and deployment-governance validators. Unrelated compliant-looking evidence could suppress violations for different zones, hostnames, origins, or repositories in the same stack.

Patched in 1.3.2: …

GitHub-GHSA

HIGH
@hulumi/policies: CIS 1.16 admin policy bypass for inline and attached IAM policies
GHSA-4xrh-5m3m-328w
pkg: @hulumi/policies
eco: npm
published: May 21, 2026
Impact: @hulumi/policies versions before 1.3.2 did not fully inspect inline and attached IAM policy evidence for the administrator-policy guardrail, so some admin-equivalent policy paths could pass policy evaluation.

Patched in 1.3.2: the validator inspects the affected policy shapes and includes r…

GitHub-GHSA

HIGH
@hulumi/policies: HULUMI-H1 SecureBucket parent spoof bypass
GHSA-g43v-9x7q-83pq
pkg: @hulumi/policies
eco: npm
published: May 21, 2026
Impact: @hulumi/policies versions before 1.3.2 could accept spoofed SecureBucket parent evidence for HULUMI-H1, allowing policy evaluation to miss an unsafe bucket shape.

Patched in 1.3.2: the validator now correlates evidence to the expected component/resource relationship and includes regression …

GitHub-GHSA

HIGH
@hulumi/drift: Orphan reconciler accepted externally supplied execute plans
GHSA-2ffm-hxrq-qqmm
pkg: @hulumi/drift
eco: npm
published: May 21, 2026
Impact: @hulumi/drift versions before 1.3.2 could accept externally supplied execute plans without sufficient provenance checks, allowing unsafe reconciliation input to be treated as trusted.

Patched in 1.3.2: execute-plan handling now validates provenance and rejects untrusted plans, with regressi…

GitHub-GHSA

HIGH
Plonky3 MultiField32Challenger: transcript malleability and challenge entropy loss
GHSA-vj64-rjf3-w3v7
pkg: p3-challenger, p3-challenger
eco: rust
published: May 21, 2026
### Impact

– **Key**: `challenger/src/multi_field_challenger.rs` | `MultiField32Challenger::duplexing` | `transcript_malleability`
– **Affected files**: `challenger/src/multi_field_challenger.rs`, `field/src/helpers.rs`
– **Violated invariant**: The Fiat-Shamir sponge must bind challenges to the ex…

CVE-2026-46654
GitHub-GHSA

HIGH
Fission runtime pods automount the fission-fetcher service-account token into the user function container, granting function code namespace-wide secret / configmap read
GHSA-85g2-pmrx-r49q
pkg: github.com/fission/fission
eco: go
published: May 21, 2026
### Summary

Fission runtime pods were created with `ServiceAccountName: fission-fetcher`, and the `fission-fetcher` ServiceAccount was granted namespace-wide `get` on `secrets` and `configmaps` (it needs that to load function code, env vars, and config). The runtime pod's automounted token was reac…

CVE-2026-46617
GitHub-GHSA

HIGH
samlify: XML Injection in AttributeValue Allows Privilege Escalation in Signed SAML Assertions
GHSA-34r5-q4jw-r36m
pkg: samlify
eco: npm
published: May 21, 2026
## Summary

samlify’s template substitution only escapes attribute contexts. Values inserted into element text (e.g., `<saml:AttributeValue>`) are not escaped. A normal user can inject XML markup into an attribute value (e.g., email, name) and add new `<saml:Attribute>` elements inside the signed …

CVE-2026-46490
GitHub-GHSA

HIGH
Windows-MCP: HTTP transports expose unauthenticated PowerShell control with wildcard CORS
GHSA-vrxg-gm77-7q5g
pkg: windows-mcp
eco: pip
published: May 21, 2026
HTTP transports expose unauthenticated PowerShell control with wildcard CORS

There is an issue in the SSE and Streamable HTTP transport modes. The default stdio mode is not affected, but the documented HTTP modes expose the MCP control plane without authentication and add wildcard CORS handling aro…

GitHub-GHSA

HIGH
@angular/platform-server: SSRF via Hostname Hijacking
GHSA-rfh7-fxqc-q52v
pkg: @angular/platform-server, @angular/platform-server, @angular/platform-server
eco: npm
published: May 19, 2026
### Impact

A Server-Side Request Forgery (SSRF) vulnerability exists in `@angular/platform-server`. The issue stems from how the server-side rendering (SSR) engine processes the request URL provided to the rendering entry points.

When an absolute-form URL (e.g., `http://evil.com`) is passed to the…

CVE-2026-46417
GitHub-GHSA

HIGH
FileBrowser Quantum: unauthenticated user share share info
GHSA-3jmg-p96m-m328
pkg: github.com/gtsteffaniak/filebrowser/backend, github.com/gtsteffaniak/filebrowser
eco: go
published: May 19, 2026
### Impact
Some sensitive info — such as source and path can get exposed.

### Patches
Update to the latest version

### Workarounds
no

CVE-2026-46410
GitHub-GHSA

HIGH
CamoFox MCP: Unauthenticated HTTP MCP browser-control surface
GHSA-7hgr-7h44-33w2
pkg: camofox-mcp
eco: npm
published: May 19, 2026
# Unauthenticated HTTP MCP browser-control surface in `camofox-mcp`

## Summary

`camofox-mcp` exposed a Streamable HTTP MCP endpoint at `/mcp` with rate limiting but no inbound MCP-layer authentication. When HTTP mode was enabled, any client that could reach `/mcp` could list and invoke browser-con…

GitHub-GHSA

HIGH
libcrux-ml-dsa: Signature Verification on AVX2 Platforms Mishandles Edge Case
GHSA-fhvh-vw7h-9xf3
pkg: libcrux-ml-dsa
eco: rust
published: May 19, 2026
The AVX2 implementation of ML-DSA verification incorrectly implemented
the `use_hint` function, mishandling an edge case that should lead to
signature rejection.

## Impact
An attacker could make the ML-DSA verifier accept a crafted invalid
signature under a maliciously generated verification key, i…

GitHub-GHSA

HIGH
libcrux: Potential Panic on Overlong Ciphertext Buffer
GHSA-hc3c-63hc-2r9f
pkg: libcrux-chacha20poly1305
eco: rust
published: May 19, 2026
An application that passes in a ciphertext buffer of length greater
than `ptxt.len() + TAG_LEN` to `libcrux_chacha20poly1305::encrypt` or
`libcrux_chacha20poly1305::xchacha20_poly1305::encrypt` would
experience a panic.

## Impact
An application where the length of the ciphertext buffer is under
att…

GitHub-GHSA

HIGH
zrok copy writes attacker-controlled WebDAV paths outside the destination root
GHSA-c656-jcx2-7pqj
pkg: github.com/openziti/zrok/v2, github.com/openziti/zrok
eco: go
published: May 19, 2026
## Summary

Alice runs `zrok2 copy` from a WebDAV or zrok drive controlled by Bob into a local filesystem target. Bob returns a DAV `href` such as `/../outside.txt`. The sync pipeline stores that path in the source inventory and passes it to `FilesystemTarget.WriteStream`, which joins it with the ta…

CVE-2026-45576
GitHub-GHSA

HIGH
HAXcms: Mass Token Exfiltration and Cross-Tenant Hijack
GHSA-x3x5-7h4h-gwxg
pkg: @haxtheweb/haxcms-nodejs
eco: npm
published: May 19, 2026
### Summary
An attack chain utilizing **Stored XSS** alongside dynamic token exposure in the `/system/api/connectionSettings` endpoint allows an authenticated attacker to perform a complete cross-tenant account takeover. The API dynamically leaks the active session's authentication tokens (including…
CVE-2026-46511
GitHub-GHSA

HIGH
Stored XSS via <iframe> in HAX CMS allows access to sensitive client-side data and account takeover
GHSA-jh3h-rpxg-fr36
pkg: @haxtheweb/haxcms-nodejs, @haxtheweb/video-player, @haxtheweb/iframe-loader
eco: npm
published: May 19, 2026
### Summary
A stored cross-site scripting (XSS) vulnerability exists in HAX CMS due to improper sanitization of `<iframe>` elements.

The application allows `javascript:` URIs in the `src` attribute, which are executed when a malicious page is viewed. This enables attackers to execute arbitrary Java…

CVE-2026-46396
GitHub-GHSA

HIGH
HAX open-apis: Credential Theft via Server-Side Request Forgery (SSRF) in open-apis
GHSA-4fg7-f244-3j49
pkg: @haxtheweb/open-apis
eco: npm
published: May 19, 2026
### Summary
Multiple functions conduct substring-only matching to validate hostnames to which basic authorization should be sent. An attacker can append the matched substrings to an attacker-controlled endpoint and capture authentication.

### Details
[api/services/website/cacheAddress.js](https://g…

CVE-2026-46391
GitHub-GHSA

HIGH
HAXcms createSite SSRF Enables Arbitrary File Read
GHSA-q862-gcgq-5m6g
pkg: @haxtheweb/haxcms-nodejs
eco: npm
published: May 19, 2026
### Summary
An authenticated Server-Side Request Forgery (SSRF) vulnerability in HAXcms allows users to fetch arbitrary internal or local resources and write the responses to a web-accessible directory, enabling arbitrary file read and internal network access.

### Details
The `createSite` endpo…

CVE-2026-46393
GitHub-GHSA

HIGH
Scriban: array.insert_at index parameter DoS bypasses LoopLimit and LimitToString
GHSA-24c8-4792-22hx
pkg: scriban
eco: nuget
published: May 19, 2026
## Summary

`ArrayFunctions.InsertAt` in Scriban allocates `index – list.Count` null entries in a tight C# `for` loop with no bound on `index`. The function is exposed to template authors as `array.insert_at`, and the fill loop ignores every existing safety control: `LoopLimit`, `LimitToString`, `Ob…

GitHub-GHSA

HIGH
CloakBrowser: Unauthenticated path traversal via fingerprint parameter in cloakserve leads to arbitrary directory deletion
GHSA-mf33-gv72-w2h5
pkg: cloakbrowser
eco: pip
published: May 18, 2026
The `cloakserve` CDP multiplexer uses the user-supplied `fingerprint` query parameter directly as a filesystem path component when creating Chrome profile directories. An unauthenticated attacker who can reach the cloakserve port can supply a crafted `fingerprint` value containing path traversal seq…
CVE-2026-45727
GitHub-GHSA

HIGH
eduMFA Passkeys: missing expiration flag may allow replay attacks and reuse of old challenges
GHSA-j5rm-v3vh-vx94
pkg: edumfa
eco: pip
published: May 18, 2026
### Impact
In eduMFA < 2.9.1 userless Passkey/WebAuthn challenges might be replayed and do not expire

### Patches
Fixed in eduMFA >= 2.9.1 by adding validity information to the userless challenges.

### Workarounds
No known workarounds besides disabling userless login altogether.

GitHub-GHSA

HIGH
eduMFA: Incorrect InnoDB snapshot isolation possibly allows token reusage
GHSA-qq2p-4282-cfc5
pkg: edumfa
eco: pip
published: May 18, 2026
### Impact

For deployments using MySQL or MariaDB < 11.6.2 (or newer with innodb_snapshot_isolation=off) reusage of token values might be possible due to faulty transaction isolation inside the database. Exploiting this requires racing this transaction.
Affected are all tokentypes whose values are …

GitHub-GHSA

MEDIUM
n8n: Credential exfiltration via Allowed HTTP Request Domains Bypass
GHSA-3875-8gcx-7v46
pkg: n8n
eco: npm
published: May 19, 2026
## Impact
The `POST /rest/dynamic-node-parameters/options` endpoint allowed any authenticated user to cause the n8n server to issue HTTP requests including credentials bypassing the intended restrictions on which hosts could be contacted for that credential (Allowed HTTP Request Domains). The user n…
GitHub-GHSA

MEDIUM
Amazon SageMaker Python SDK is missing integrity verification in its Triton inference handler
GHSA-rq6v-x3j8-7qgf
pkg: sagemaker, sagemaker
eco: pip
published: May 21, 2026
## Summary
Amazon SageMaker Python SDK is an open-source library for training and deploying machine learning models on Amazon SageMaker. An issue exists where, under certain circumstances, the Triton inference handler deserializes model artifacts without performing integrity verification, allowing s…
CVE-2026-8597
GitHub-GHSA

MEDIUM
Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of CVE-2026-25580)
GHSA-cqp8-fcvh-x7r3
pkg: pydantic-ai, pydantic-ai-slim
eco: pip
published: May 21, 2026
## Summary

When an application using Pydantic AI opts a URL into `force_download='allow-local'` (which disables the default block on private/internal IPs), the cloud-metadata blocklist could be bypassed by encoding the metadata IP in an IPv6 transition form (IPv4-mapped IPv6, 6to4, or NAT64). Dual-…

CVE-2026-46678
GitHub-GHSA

MEDIUM
Nezha Monitoring: Nezha WebSocket server stream discloses cross-tenant server telemetry to authenticated members
GHSA-hvv7-hfrh-7gxj
pkg: github.com/nezhahq/nezha
eco: go
published: May 23, 2026
### Summary

Any authenticated non-admin member can connect to the server-status WebSocket and receive telemetry for all servers, including servers owned by other users. The normal server list API filters objects by `HasPermission`, but the WebSocket stream treats the presence of any authenticated u…

CVE-2026-47124
GitHub-GHSA

MEDIUM
instagrapi: Unsafe signup challenge path handling in instagrapi
GHSA-ggxf-37hm-9wqf
pkg: instagrapi
eco: pip
published: May 23, 2026
instagrapi versions before 2.6.9 accepted server-supplied signup challenge paths and used them to build request URLs before validating that the paths were relative Instagram API paths. A malicious or tampered challenge payload could cause challenge handling requests to be sent outside the intended I…
GitHub-GHSA

MEDIUM
aiograpi: Unsafe signup challenge path handling
GHSA-jh37-x3fv-4×72
pkg: aiograpi
eco: pip
published: May 23, 2026
aiograpi versions before 0.9.10 accepted server-supplied signup challenge paths and used them to build request URLs before validating that the paths were relative Instagram API paths. A malicious or tampered challenge payload could cause challenge handling requests to be sent outside the intended In…
CVE-2026-47157
GitHub-GHSA

MEDIUM
FlaskBB: SSRF in get_image_info() via unrestricted avatar URL
GHSA-xq32-9g7q-7297
pkg: flaskbb
eco: pip
published: May 21, 2026
###Summary
A Server-Side Request Forgery (SSRF) vulnerability in get_image_info() allows any authenticated user to force the server to send HTTP requests to arbitrary internal endpoints, including cloud metadata services (e.g., AWS 169.254.169.254). This is a blind SSRF with confirmed internal port …
CVE-2026-46556
GitHub-GHSA

MEDIUM
NocoDB: Missing File Size Enforcement in Upload-by-URL Allows Denial of Service via Disk Exhaustion
GHSA-99vc-2jx2-688p
pkg: nocodb
eco: npm
published: May 21, 2026
### Summary

The `uploadViaURL` path in the v1/v2 attachment API did not enforce `NC_ATTACHMENT_FIELD_SIZE` against the remote `content-length` or against the response stream. An authenticated user (Editor+) could direct the server to download arbitrarily large files, exhausting disk space and causi…

CVE-2026-46551
GitHub-GHSA

MEDIUM
Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint
GHSA-686c-7vgv-v3fx
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: May 19, 2026
## Summary

Unauthenticated semi-blind Server-Side Request Forgery (SSRF) via the Azure instance identity endpoint (`POST /api/v2/workspaceagents/azure-instance-identity`). An external attacker can force the Coder server to issue HTTP GET requests to arbitrary internal or external hosts by submittin…

CVE-2026-45796
GitHub-GHSA

MEDIUM
HAX CMS: Denial of Service using Malicious Import Request
GHSA-9r33-xhw8-4qqp
pkg: @haxtheweb/haxcms-nodejs
eco: npm
published: May 19, 2026
### Summary

The HAX CMS NodeJS application crashes when an authenticated attacker sends a specially crafted site creation request to the createSite endpoint. A single request is sufficient to take the entire application offline, requiring a manual server restart to restore service.

### Details

Th…

CVE-2026-46357
GitHub-GHSA

MEDIUM
OpenTelemetry eBPF Instrumentation: Redis error text is exported in span status messages
GHSA-8rrq-wcg8-cv5q
pkg: go.opentelemetry.io/obi
eco: go
published: May 18, 2026
### Summary

OBI exports raw Redis error text as the span status message. Because Redis error replies can contain attacker-controlled or sensitive values, this behavior can exfiltrate tokens, PII, or other confidential input into telemetry backends and inject untrusted text into downstream analysis …

CVE-2026-45679
GitHub-GHSA

MEDIUM
Budibase: CouchDB Reduce Injection via Unsanitized Calculation Parameter in V1 Views API
GHSA-363w-hvwh-w7m6
pkg: @budibase/server
eco: npm
published: May 18, 2026
# Security Advisory: CouchDB Reduce Injection via Unsanitized Calculation Parameter in V1 Views API

**Affected Software:** Budibase
**Affected Component:** `packages/server/src/api/controllers/view/viewBuilder.ts`, `packages/server/src/api/routes/view.ts`
**CWE:** CWE-94 (Improper Control of Genera…

CVE-2026-45719
GitHub-GHSA

MEDIUM
brace-expansion: Large numeric range defeats documented `max` DoS protection
GHSA-jxxr-4gwj-5jf2
pkg: brace-expansion
eco: npm
published: May 18, 2026
The `max` option was being applied too late:

When expanding a single large numeric range like `{1..10000000}`, the sequence generation loop generates all 10 million intermediate elements before the `max` limit is applied With `max=10`, the output is correctly limited to 10 items, but the process st…

CVE-2026-45149
GitHub-GHSA

MEDIUM
eduMFA: Unauthenticated Failcounter Increment on Resolver Tokens via /validate/check
GHSA-74r7-3mjm-jc5v
pkg: edumfa
eco: pip
published: May 18, 2026
### Impact
If the resolver parameter is passed, but the user does not exist, all failcounters of tokens in that resolver will be increased.

### Patches
This, along with other issues, was fixed in eduMFA v2.9.1.

### Workarounds
Limiting access to `/validate/check` to client applications (i.e. Shibb…

GitHub-GHSA

MEDIUM
n8n-MCP: Workflow telemetry sanitizer could retain partial values from URL-shaped node parameters
GHSA-f3rg-xqjj-cj9w
pkg: n8n-mcp
eco: npm
published: May 18, 2026
## Summary

In affected versions of n8n-mcp, the workflow telemetry sanitizer could retain partial fragments of URL-shaped node parameters before sending workflow data to the project's anonymous telemetry backend. Values placed in HTTP-Request-style node parameters — such as customer or tenant ide…

CVE-2026-45582
GitHub-GHSA

MEDIUM
n8n: Legacy ExecuteWorkflow Node Bypassed File Path Restrictions
GHSA-2vx9-7wpg-88jq
pkg: n8n
eco: npm
published: May 19, 2026
## Impact
The `ExecuteWorkflow` node's `localFile` source option read workflow files from disk without applying checks enforced by other file-reading nodes. An authenticated user with permission to create or modify workflows could supply an arbitrary file path via the REST API, bypassing the `N8N_RE…
GitHub-GHSA

MEDIUM
Klever-Go KVM read-only execution can commit contract delete and upgrade side effects
GHSA-jc6w-wmfc-fh33
pkg: github.com/klever-io/klever-go
eco: go
published: May 21, 2026
## Publisher note

**Fixed in `v1.7.17`.** Operators running `< v1.7.17` should upgrade. Contract delete and upgrade host-core paths now reject execution when `runtime.ReadOnly()` is true. The invariant is regression-tested for delete, upgrade, storage writes, value transfers, and any VM output fiel…

CVE-2026-46403
GitHub-GHSA

MEDIUM
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations
GHSA-rg3g-4rw9-gqrp
pkg: github.com/argoproj/argo-cd/v3, github.com/argoproj/argo-cd/v3, github.com/argoproj/argo-cd/v3
eco: go
published: May 19, 2026
### Summary
The original fix for [GHSA-3v3m-wc6v-x4x3](https://github.com/argoproj/argo-cd/security/advisories/GHSA-3v3m-wc6v-x4x3) is incomplete. argocd app diff –server-side-diff can still expose Kubernetes Secret values embedded in the kubectl.kubernetes.io/last-applied-configuration annotation.…
CVE-2026-45737
GitHub-GHSA

MEDIUM
Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameter
GHSA-9mvm-4gwg-v8mp
pkg: github.com/getarcaneapp/arcane/backend
eco: go
published: May 18, 2026
## Summary

`GET /environments/{id}/volumes/{volumeName}/browse` accepts a `path` query parameter that is passed to a shell command (`sh -c "find … | while …"`) inside an Arcane helper container. The path sanitiser blocks `../` traversal but does not strip Bourne-shell metacharacters such as `$(…

CVE-2026-45626
GitHub-GHSA

MEDIUM
ImageMagick: Heap Buffer Over-Write in json and yaml encoder of a single byte due to incorrect fix
GHSA-jqq5-8px3-9m6m
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 21, 2026
An incorrect fix that was applied in GHSA-5592-p365-24xh could result in a heap buffer over-write of a single byte.
GitHub-GHSA

MEDIUM
OpenMcdf: Uncatchable infinite loop in DirectoryTree.TryGetDirectoryEntry on crafted CFB directory cycle
GHSA-5qwm-7pvp-w988
pkg: OpenMcdf
eco: nuget
published: May 19, 2026
### Summary
The BST name-lookup loop in `DirectoryTree.TryGetDirectoryEntry` (`OpenMcdf/DirectoryTree.cs:35-46`) walks directory entries by repeatedly calling `directories.TryGetSibling(child, siblingType, validateColor)`. A crafted CFB file with cyclic Left/Right sibling links among directory entri…
CVE-2026-45785
GitHub-GHSA

MEDIUM
ImageMagick: Stack overflow in fx operation
GHSA-rcr6-g7jc-f57g
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 18, 2026
Due to a missing depth check a stack overflow can occur in the fx operation by passing a crafted argument.
CVE-2026-46557
GitHub-GHSA

MEDIUM
ImageMagick: Use-After-Free in MSL decoder.
GHSA-5r4x-w6p5-222q
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 18, 2026
A crafted MSL image can trigger a heap-use-after-free.
CVE-2026-46523
GitHub-GHSA

MEDIUM
NocoDB: Reflected Cross-Site Scripting via Page Leaving Redirect URL
GHSA-9qgr-6vpg-9gh9
pkg: nocodb
eco: npm
published: May 21, 2026
### Summary
A reflected XSS vulnerability exists in the Page Leaving Warning page. The `ncRedirectUrl` and `ncBackUrl` query parameters are used in `window.location.href` and `<a>` tag bindings without validation, allowing `javascript:` URI injection.

### Details
`PageLeavingWarning.vue` reads `ncR…

CVE-2026-46547
GitHub-GHSA

MEDIUM
Apify Model Context Protocol (MCP) server: Domain Allowlist Bypass in fetch-apify-docs via String Prefix Matching
GHSA-jwp7-wg77-3w9v
pkg: @apify/actors-mcp-server
eco: npm
published: May 19, 2026
### Summary
The `fetch-apify-docs` tool validates URLs against a domain allowlist using `String.startsWith()` instead of proper URL hostname comparison. This allows bypass via attacker-controlled subdomains (e.g., `https://docs.apify.com.evil.com/`), enabling the tool to fetch and return arbitrary w…
CVE-2026-46341
GitHub-GHSA

MEDIUM
Docker: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swap
GHSA-vp62-88p7-qqf5
pkg: github.com/docker/docker, github.com/moby/moby/v2, github.com/moby/moby
eco: go
published: May 18, 2026
## Summary

A race condition during `docker cp` mount setup allows a malicious container to create empty files or directories at arbitrary absolute paths on the host filesystem.

This advisory covers the race during mountpoint creation. The related race during the subsequent mount syscall is tracked…

CVE-2026-41568
GitHub-GHSA

MEDIUM
nimiq-primitives: BlockInclusionProof interlink issue when hops are empty
GHSA-799f-29jm-gr6c
pkg: nimiq-primitives
eco: rust
published: May 21, 2026
### Impact
A logic flaw in `BlockInclusionProof::is_block_proven` causes the function to return true without performing any cryptographic verification when `get_interlink_hops` yields an empty hop list. This occurs when the target block is at the election block position immediately preceding the ele…
CVE-2026-46539
GitHub-GHSA

MEDIUM
Mailpit: Concurrent map read & write in proxy CSS rewriter – remote unauth crash (fatal error: concurrent map read and map write)
GHSA-w4vj-r5pg-3722
pkg: github.com/axllent/mailpit
eco: go
published: May 19, 2026
### Summary
The screenshot/print proxy (/proxy?data=…) maintains a package-level assets map[string]MessageAssets cache, but reads the map without holding assetsMutex while a long-running cleanup goroutine and (re-entrant) CSS-rewriting code path concurrently write to it under the lock. When the un…
CVE-2026-45712
GitHub-GHSA

MEDIUM
Mailpit: Path traversal & arbitrary file write in mailpit dump –http via attacker-controlled message IDs
GHSA-qx5x-85p8-vg4j
pkg: github.com/axllent/mailpit
eco: go
published: May 19, 2026
### Summary
The mailpit dump –http <base-url> <out-dir> sub-command downloads every message from a remote Mailpit instance and writes each one as <id>.eml inside the user-supplied output directory. The message ID field is taken verbatim from the JSON response of the remote server and concatenated i…
CVE-2026-45711
GitHub-GHSA

MEDIUM
OpenTelemetry eBPF Instrumentation: CPU-mismatch fallback uses 256-byte buffer with 8KB size
GHSA-r6c9-g6q5-qrf9
pkg: go.opentelemetry.io/obi
eco: go
published: May 18, 2026
### Summary

The per-CPU message-buffer fallback path uses a 256-byte backup buffer but preserves the original payload size, which can be up to 8KB. If a CPU mismatch occurs, OBI can read beyond the fallback buffer and leak adjacent memory into telemetry.

### Details

https://github.com/open-teleme…

CVE-2026-45681
GitHub-GHSA

MEDIUM
OpenTelemetry eBPF Instrumentation: Unbounded BPF internal metrics replay can exhaust CPU
GHSA-89c6-vpcj-7vj4
pkg: go.opentelemetry.io/obi
eco: go
published: May 18, 2026
### Summary

OBI replays BPF probe hits into histogram observations by looping once per recorded run count. On busy systems, the run-count delta can become very large, causing the metrics exporter to spend excessive CPU time in a tight loop every collection interval.

### Details

The vulnerable loo…

CVE-2026-45680
GitHub-GHSA

MEDIUM
NocoDB: Shared-base link access can invite arbitrary users as persistent base members
GHSA-chqv-vrj7-qffp
pkg: nocodb
eco: npm
published: May 21, 2026
### Summary

Shared-base sessions were granted the same base-member capabilities as authenticated viewers. Using only the shared-base UUID (`xc-shared-base-id`), an attacker could enumerate base members and invite an arbitrary email into the base as a real member. The invited user could then redeem …

CVE-2026-46552
GitHub-GHSA

MEDIUM
Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer
GHSA-j3fj-qppj-fmmc
pkg: github.com/axllent/mailpit
eco: go
published: May 19, 2026
## Summary

The fix for GHSA-6jxm-fv7w-rw5j (CVE-2026-23845, "Server-Side Request Forgery (SSRF) via HTML Check API"), shipped in mailpit `v1.28.3`, hardened `internal/htmlcheck/css.go::downloadCSSToBytes` with a 5MB size cap, a `text/css` content-type check, login-info stripping in `isValidURL`, an…

CVE-2026-45709
GitHub-GHSA

MEDIUM
ImageMagick: Heap Buffer Over-Read in distributed pixel cache server
GHSA-6gxq-f64p-5w6f
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 22, 2026
An attacker who can connect to a magick -distribute-cache service can cause a heap buffer over-read in the server process.
CVE-2026-47166
GitHub-GHSA

MEDIUM
ImageMagick: Out-of-Bounds Read in connected components when the user supplies an invalid keep-top define
GHSA-vhrh-72hq-w8m7
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 18, 2026
An invalid `connected-components:keep-top` value could result in a heap buffer over-read when performing the connected components operation.
CVE-2026-45359
GitHub-GHSA

MEDIUM
fabric-chaincode-java: TLS Private Key Password Disclosed in INFO Startup Logs in Chaincode-as-a-Service Mode
GHSA-wg5x-3g47-v38r
pkg: org.hyperledger.fabric-chaincode-java:fabric-chaincode-shim
eco: maven
published: May 19, 2026
When chaincode is deployed in chaincode-as-a-service mode with TLS enabled, the chaincode server INFO level logging includes the TLS private key password in plaintext. An attacker with access to the chaincode server logs could recover the TLS private key password. If the attacker can also obtain the…
CVE-2026-45581
GitHub-GHSA

MEDIUM
ImageMagick: Heap Buffer Over-Write in MIFF encoder when using LZMA compression
GHSA-jcqp-6r6f-3mfx
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 18, 2026
When using LZMA compression in the MIFF encoder an out of bounds write can occur due to a missing check.
CVE-2026-46521
GitHub-GHSA

MEDIUM
OpenTelemetry eBPF Instrumentation: Unsafe fastelf parsing allows malformed ELF to crash agent
GHSA-wp73-mwgf-4jq9
pkg: go.opentelemetry.io/obi
eco: go
published: May 18, 2026
### Summary

OBI's replacement ELF parser trusts section offsets, counts, and string offsets from the executable file. A crafted local ELF can make OBI dereference invalid section pointers or slice past string tables, causing the agent to panic while determining the process language.

### Details

`…

CVE-2026-45676
GitHub-GHSA

MEDIUM
Nezha Monitoring: RoleMember can fire other users' cron tasks via AlertRule.FailTriggerTasks (no ownership check)
GHSA-rxf6-wjh4-jfj6
pkg: github.com/nezhahq/nezha
eco: go
published: May 23, 2026
## Summary

`createAlertRule` and `createService` (and their `update*` siblings) accept `FailTriggerTasks []uint64` and `RecoverTriggerTasks []uint64` — IDs of cron tasks to fire when the alert/service trips. The validation function only validates the alert's `Rules.Ignore` server map; it never ch…

CVE-2026-47120
GitHub-GHSA

MEDIUM
NocoDB: Refresh Token Cookie Set Without `secure` and `sameSite` Flags
GHSA-f74w-272x-mqcv
pkg: nocodb
eco: npm
published: May 21, 2026
### Summary

The refresh-token cookie was set with `httpOnly: true` but missing both the `secure` flag and the `sameSite` attribute. Over plain HTTP the cookie could be intercepted on the network; without `sameSite`, browsers attached it to cross-site POSTs, enabling CSRF against the token-refresh e…

CVE-2026-46550
GitHub-GHSA

MEDIUM
Umbraco.Cms: Open Redirect Vulnerability in Surface Controllers
GHSA-2qjj-h6wp-c7h7
pkg: Umbraco.Cms, Umbraco.Cms
eco: nuget
published: May 21, 2026
### Impact
Some of the Surface Controllers in the CMS provide to support member related operations fail to validate redirect URLs, making Razor templates that derive 'RedirectUrl' from user-controlled query parameters vulnerable to malicious redirect attacks.

### Patches
The issue is resolved in ve…

CVE-2026-46616
GitHub-GHSA

MEDIUM
Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalization
GHSA-x5w9-xh9r-mvfc
pkg: github.com/caddyserver/caddy/v2
eco: go
published: May 19, 2026
This report is not about a normal textual prefix-expansion case.

The issue here is that the authorization layer and the `/config` traversal layer do **not agree on what object the path refers to**.

In this case, a path authorized for one config object is accepted, but then resolves to a **diffe…

CVE-2026-45692
GitHub-GHSA

MEDIUM
go-git: Crafted repositories may modify main and submodule .git directories
GHSA-crhj-59gh-8×96
pkg: github.com/go-git/go-git/v5, github.com/go-git/go-git/v6, github.com/go-git/go-git
eco: go
published: May 19, 2026
### Impact
A path validation issue in `go-git` could allow crafted repository data to affect files outside the intended checkout target, including the repository's `.git` directory.

These validations were introduced in upstream Git years ago, so the vulnerability arose from go-git drifting from tho…

CVE-2026-45571
GitHub-GHSA

MEDIUM
Budibase: Row Action Trigger Bypasses View Row Filter Security Boundary Allowing Action on Out-of-Scope Rows
GHSA-3263-v5v9-xq8q
pkg: budibase
eco: npm
published: May 18, 2026
## Summary

The row action trigger endpoint (`POST /api/tables/:sourceId/actions/:actionId/trigger`) fails to validate that the user-supplied `rowId` is within the scope of the view's row filters. A user with access to a filtered view can trigger row actions on any row in the underlying table, inclu…

CVE-2026-45718
GitHub-GHSA

MEDIUM
qs has a remotely triggerable DoS: qs.stringify crashes with TypeError on null/undefined entries in comma-format arrays when encodeValuesOnly is set
GHSA-q8mj-m7cp-5q26
pkg: qs
eco: npm
published: May 22, 2026
### Summary

`qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is synchronous and not handled by any of qs's null-related options (`skipNulls`, `strictNullHandling`).

### Details

In the com…

CVE-2026-8723
GitHub-GHSA

MEDIUM
nimiq-blockchain: Genesis batch set request
GHSA-vghx-352f-93jm
pkg: nimiq-blockchain
eco: rust
published: May 21, 2026
### Impact
A remote peer can crash any full node by sending a RequestBatchSet message containing the genesis block's hash. The handler calls `get_epoch_chunks` which iterates backwards through macro blocks using `Policy::macro_block_before`. When it reaches the genesis block number, `macro_block_bef…
CVE-2026-46543
GitHub-GHSA

MEDIUM
protobufjs: Denial of Service via unbounded recursive JSON descriptor expansion
GHSA-jggg-4jg4-v7c6
pkg: protobufjs, protobufjs
eco: npm
published: May 19, 2026
## Summary

protobufjs could recurse without a depth limit while expanding nested JSON descriptors through `Root.fromJSON()` and `Namespace.addJSON()`.

A crafted JSON descriptor with deeply nested namespace definitions could cause the JavaScript call stack to be exhausted during descriptor loading.…

CVE-2026-45740
GitHub-GHSA

MEDIUM
Algernon: Auto-refresh SSE event server binds to all interfaces with Access-Control-Allow-Origin: * and no authentication
GHSA-9v4j-7g44-qcqw
pkg: github.com/xyproto/algernon
eco: go
published: May 19, 2026
### Summary

When auto-refresh is enabled, Algernon spins up an SSE handler that streams a `data:` line for every filesystem event under the watched directory. The handler performs **no authentication** of any kind — no shared token, no cookie check against the `permissions2` userstate, no IP allo…

GitHub-GHSA

MEDIUM
ImageMagick: Policy Bypass in MNG coder could
GHSA-g5mf-wqq5-vwg6
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 18, 2026
Because of a missing check in the MNG coder it would be possible to read more images than the list limit policy would allow resulting in excessive resource use.
CVE-2026-45664
GitHub-GHSA

MEDIUM
NiceGUI: Unauthenticated log-volume denial of service in dynamic resource routes
GHSA-pq7c-x8g4-rvp6
pkg: nicegui
eco: pip
published: May 18, 2026
### Summary

Two FastAPI routes that serve per-component static assets in NiceGUI accept a sub-path parameter that may resolve to a directory rather than a file. Requests that resolve to a directory raise an unhandled `RuntimeError` inside Starlette's `FileResponse`, which Uvicorn writes to the serv…

CVE-2026-45554
GitHub-GHSA

MEDIUM
ImageMagick: Policy Bypass in PSD decoder
GHSA-cwpj-h54c-xjpx
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 18, 2026
Due to a missing check in the PSD decoder it would be possible to bypass the `list-length` resource policy when decoding a PSD image. Other security limits would still apply.
CVE-2026-45031
GitHub-GHSA

MEDIUM
ImageMagick: Out-of-Bounds Read of a single byte in meta encoder
GHSA-cr6r-hmj8-pr7r
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 18, 2026
An of by one in the meta encoder could result in an out of bounds read of a single byte in the meta encoder.
CVE-2026-45358
GitHub-GHSA

MEDIUM
webpack-dev-server vulnerable to cross-origin source code exposure on non-HTTPS origins
GHSA-79cf-xcqc-c78w
pkg: webpack-dev-server
eco: npm
published: May 18, 2026
### Impact

When webpack-dev-server is running on a non-HTTPS origin (the default), cross-origin requests from malicious websites can load the dev server's JavaScript bundles via `<script>` tags. The fix introduced in v5.2.1 (CVE-2025-30359) relied on `Sec-Fetch-Mode` and `Sec-Fetch-Site` request he…

CVE-2026-6402
GitHub-GHSA

MEDIUM
ImageMagick: Heap Buffer Over-Read of a 4 bytes in distort operation.
GHSA-pfvh-m9xv-8966
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 18, 2026
When performing a polynomial distortion an out of bounds over-read of 24 bytes can occur when specifying specific arguments.
CVE-2026-45624
GitHub-GHSA

MEDIUM
OpenTelemetry eBPF Instrumentation: CappedConcurrentHashMap leaks keys after removals
GHSA-962q-hwm5-52×5
pkg: go.opentelemetry.io/obi
eco: go
published: May 18, 2026
### Summary

The custom `CappedConcurrentHashMap` introduced for Java TLS state tracking never removes keys from its insertion-order queue when entries are deleted. In long-running instrumented JVMs, repeated connection churn can therefore grow the queue without bound and exhaust heap memory.

### D…

CVE-2026-45682
GitHub-GHSA

MEDIUM
ImageMagick: Heap Buffer Over-Read in IPTC encoder
GHSA-7wff-wpr6-vmhm
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 18, 2026
When writing an IPTC output file a malicious input file could cause an out of bounds read of a single byte.
CVE-2026-42326
GitHub-GHSA

MEDIUM
pyload-ng: SSRF via HTTP Redirect Bypass in parse_urls API
GHSA-8rp3-xc6w-5qp5
pkg: pyload-ng
eco: pip
published: May 21, 2026
## Summary

The SSRF mitigation added in commit `33c55da` for GHSA-7gvf-3w72-p2pg is incomplete. The `PREREQFUNCTION`-based private IP check was correctly applied to `HTTPChunk` (download path) but not to `HTTPRequest` (used by the `parse_urls` API). An authenticated attacker can supply a URL pointi…

CVE-2026-46561
GitHub-GHSA

MEDIUM
OpenTelemetry eBPF Instrumentation: Log enricher writev path can overread and overwrite user buffers
GHSA-vvmg-8mjr-g6q3
pkg: go.opentelemetry.io/obi
eco: go
published: May 18, 2026
### Summary

OBI's log enricher mishandles `writev` buffers by reading only the first `iovec` entry but using the total `iov_iter.count` as the copy length. When log injection is enabled, a crafted multi-segment `writev` call can make OBI read and overwrite memory beyond the first segment.

### Deta…

CVE-2026-45684
GitHub-GHSA

MEDIUM
Umbraco.Cms: XSS/HTML Injection in Umbraco Backoffice confirmation dialog
GHSA-vr9v-27gg-qgx4
pkg: Umbraco.Cms
eco: nuget
published: May 21, 2026
### Impact
Authenticated users are able to inject HTML vulnerability into an input field, which is rendered in the confirmation dialog without proper output encoding.

### Patches
This issue has been patched in 17.4.0

CVE-2026-46609
GitHub-GHSA

MEDIUM
Rust OneNote File Parser: Path traversal in `Parser::parse_notebook` allows reading files outside the notebook directory
GHSA-4j5m-wc25-pvh7
pkg: onenote_parser
eco: rust
published: May 21, 2026
### Impact
A maliciously crafted `.onetoc2` table-of-contents file can cause `Parser::parse_notebook` to open arbitrary files on the host filesystem outside the notebook's directory. The parser reads entry names listed inside the `.onetoc2` and joins them against the notebook's base directory withou…
CVE-2026-46671
GitHub-GHSA

MEDIUM
ws: Uninitialized memory disclosure
GHSA-58qx-3vcg-4xpx
pkg: ws
eco: npm
published: May 18, 2026
### Impact

The `websocket.close()` implementation is vulnerable to uninitialized memory disclosure when a `TypedArray` is passed as the reason argument.

### Proof of concept

“`js
import { deepStrictEqual } from 'node:assert';
import { WebSocket, WebSocketServer } from 'ws';

const wss = new WebS…

CVE-2026-45736
GitHub-GHSA

MEDIUM
SQLAdmin: Authorization Bypass on `ajax_lookup`
GHSA-54mc-gghv-4cfj
pkg: sqladmin
eco: pip
published: May 21, 2026
### Impact

The `ajax_lookup` endpoint in `application.py` bypasses the `is_accessible()` access control check that all other endpoints enforce.

If a developer restricts model access by overriding `is_accessible()`, an authenticated user can still query that model's data through the `ajax_lookup` e…

CVE-2026-46645
GitHub-GHSA

MEDIUM
NocoDB: SSRF Protection Bypass in Notification Webhook Plugins (Slack, Discord, Mattermost, Teams)
GHSA-2c5x-4jgf-88mj
pkg: nocodb
eco: npm
published: May 21, 2026
### Summary

The `request-filtering-agent` SSRF protection was non-functional in the four notification webhook plugins (Slack, Discord, Mattermost, Teams) because `httpAgent` / `httpsAgent` were passed as part of the request **body** rather than the axios **config**. An authenticated user with hook-…

CVE-2026-46548
GitHub-GHSA

MEDIUM
nimiq-keys: Denial of service in Ed25519 multisig delinearization via invalid curve points
GHSA-h9cc-w26m-j342
pkg: nimiq-keys
eco: rust
published: May 21, 2026
### Impact

A denial-of-service vulnerability exists in the Ed25519 multisig delinearization code path. `Ed25519PublicKey::delinearize()` in `keys/src/multisig/mod.rs` called `.unwrap()` on curve point decompression, which panics when a public key is
constructed from 32 bytes that do not represent a…

CVE-2026-46542
GitHub-GHSA

MEDIUM
Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: *
GHSA-hw27-4v2q-5qff
pkg: github.com/xyproto/algernon
eco: go
published: May 20, 2026
### Summary

The SSE event server's `Access-Control-Allow-Origin` response header was hardcoded to the wildcard `*` regardless of the caller's `Origin`. Because `EventSource` does not preflight and does not send cookies, the wildcard is sufficient to let any third-party page the developer visits ope…

CVE-2026-46431
GitHub-GHSA

MEDIUM
Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS
GHSA-gj84-924c-48fx
pkg: github.com/xyproto/algernon
eco: go
published: May 20, 2026
### Summary

The SSE event server bound to `0.0.0.0:5553` on Linux/macOS by default because the platform-dependent host default in `engine/flags.go:39-46` set `host = ""` for non-Windows, and `utils.JoinHostPort("", ":5553")` resolves to `":5553"` — a Go `http.Server.Addr` of `":5553"` listens on …

CVE-2026-46430
GitHub-GHSA

MEDIUM
Regression in pymdownx.snippets reintroduces sibling-prefix path traversal bypass despite restrict_base_path
GHSA-62q4-447f-wv8h
pkg: pymdown-extensions
eco: pip
published: May 19, 2026
# Summary

`pymdownx.snippets` has a regression of the CVE-2023-32309 / GHSA-jh85-wwv9-24hv fix. With `restrict_base_path: True` (the default), the current `filename.startswith(base)` containment check does not enforce a directory boundary. As a result, a markdown snippet directive can read files fr…

CVE-2026-46338
GitHub-GHSA

MEDIUM
Caddy: Remote Admin Authorization Bypass on PKI Endpoints via Prefix-Based Path Matching
GHSA-gx7w-56w6-g48x
pkg: github.com/caddyserver/caddy/v2
eco: go
published: May 19, 2026
## AI Disclosure

I used an LLM to help review the source code, reason about attack surface, and help draft and refine this report.
I manually validated the finding by reproducing it locally, confirming the vulnerable code path, and verifying the HTTP behavior with `curl -v`.

## Summary

Ca…

GitHub-GHSA

MEDIUM
Budibase: Missing Cache Invalidation on Public API Role Unassignment Allows Revoked Users to Retain Privileges for Up to 1 Hour
GHSA-6vp2-6r7m-2jvx
pkg: @budibase/backend-core
eco: npm
published: May 19, 2026
## Summary

The public API role unassignment endpoint (`POST /api/public/v1/roles/unassign`) updates user documents in CouchDB but does not invalidate the corresponding Redis user cache entries. Because the authentication middleware resolves user identity and permissions from this cache (TTL: 3600 s…

CVE-2026-46424
GitHub-GHSA

MEDIUM
ImageMagick: Information Disclosure in distributed pixel cache server because it is not using a challenge–response authentication model
GHSA-2rgj-gx5x-f62w
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 22, 2026
The distributed pixel cache was originally designed to operate without a challenge–response authentication model. However, given today’s heightened security expectations, we have changed our implementation.
CVE-2026-47165
GitHub-GHSA

MEDIUM
ImageMagick: Race Condition in distributed pixel cache server can result in file descriptor hijacking
GHSA-4g75-9r48-jf92
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 22, 2026
An attacker who can connect to a magick -distribute-cache service can hijack a file descriptor in the server process when a race condition is met.
CVE-2026-46693
GitHub-GHSA

MEDIUM
ImageMagick: Heap Buffer Over-Write in distributed pixel cache server
GHSA-p93h-f2jc-477j
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 22, 2026
An attacker who can connect to a `magick -distribute-cache` service can cause a heap buffer over-write in the server process.
CVE-2026-46692
GitHub-GHSA

MEDIUM
ImageMagick: Heap Buffer Over-Write of a single byte in the JP2 encoder.
GHSA-533m-3wf6-c33v
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 18, 2026
An incorrect check in the JP2 will result in an heap buffer over-write of a single byte when specifying certain options.
CVE-2026-46559
GitHub-GHSA

MEDIUM
Flask-Security-Too OAuth reauthentication freshness bypass via cross- user OAuth identity acceptance
GHSA-97r5-pg8x-p63p
pkg: Flask-Security-Too
eco: pip
published: May 22, 2026
### Summary

Flask-Security-Too 5.8.0's OAuth reauthentication flow can mark a
session as fresh after verifying an OAuth account that belongs to a
different user.

If an attacker can operate an already-authenticated but stale victim
session, they can complete OAuth verification using their…

CVE-2026-46715
GitHub-GHSA

MEDIUM
@hulumi/baseline: CloudTrail selector tampering events were not fully detected
GHSA-gfp8-mp24-5vxg
pkg: @hulumi/baseline
eco: npm
published: May 21, 2026
Impact: @hulumi/baseline versions before 1.3.2 could miss some CloudTrail event-selector tampering evidence, reducing coverage for changes to audit logging configuration.

Patched in 1.3.2: detection coverage and regression tests were expanded.

Remediation: upgrade @hulumi/baseline to 1.3.2 or late…

GitHub-GHSA

MEDIUM
Fission builder accepts arbitrary buildcmd strings from Environment.spec.builder.command, allowing the builder pod to invoke arbitrary executables
GHSA-7pjr-qpvh-m339
pkg: github.com/fission/fission
eco: go
published: May 21, 2026
### Summary

Before the round-1 security sweep, `pkg/builder/builder.go` passed `Environment.spec.builder.command` directly into `exec.Command(…)` after a `strings.Fields` split, with no validation of the executable path or its arguments. A user who could create or update `Environment` CRDs in a n…

CVE-2026-46618
GitHub-GHSA

MEDIUM
@sveltejs/kit: `query.batch` cross-talk
GHSA-hgv7-v322-mmgr
pkg: @sveltejs/kit
eco: npm
published: May 21, 2026
`query.batch()` could, under very rare and specific timings, cause concurrent requests from different users to merge and resolve under single request context, enabling cross-user data disclosure.
GitHub-GHSA

MEDIUM
Mobile Verification Toolkit (MVT): Path Traversal via unsanitized File identifiers in iOS Backup processing
GHSA-5h3g-px23-w6vw
pkg: mvt
eco: pip
published: May 21, 2026
### Summary

The `fileID` field from `Manifest.db` (a SQLite database inside iOS backups, generated by the device) is used directly in filesystem path construction without validation. This affects two commands through a shared code path:

– **`mvt-ios decrypt-backup`** (`decrypt.py`): `file_id` is u…

CVE-2026-46486
GitHub-GHSA

MEDIUM
Flowise: Cross-Workspace Chatflow Disclosure via chatflows/apikey Endpoint Returns All Unprotected Chatflows
GHSA-c2c9-mfw7-p8hw
pkg: flowise
eco: npm
published: May 20, 2026
## Summary

The `/api/v1/chatflows/apikey/:apikey` endpoint (whitelisted, accessible with API key auth only) returns all chatflows bound to the provided API key AND all chatflows across the entire system that have no API key assigned. This crosses workspace boundaries, allowing a user in Workspace A…

GitHub-GHSA

MEDIUM
Flowise: Mass Assignment in PUT /api/v1/user Allows Authenticated Users to Override Password Hash and Bypass Password Change Verification
GHSA-59fh-9f3p-7m39
pkg: flowise
eco: npm
published: May 20, 2026
### Summary
A Mass Assignment vulnerability in the PUT /api/v1/user endpoint allows authenticated users to directly modify restricted user fields, including the credential (password hash), bypassing the intended password change workflow.

Because the endpoint forwards the entire request body to the …

GitHub-GHSA

MEDIUM
Flowise: Hardcoded CORS wildcard on TTS endpoint enables cross-origin credential abuse from any webpage
GHSA-m837-xvxr-vqwg
pkg: flowise
eco: npm
published: May 20, 2026
### Summary

The TTS generation endpoint sets `Access-Control-Allow-Origin: *` as a hardcoded response header, independent of the server's CORS configuration. This enables any webpage to make cross-origin requests to generate speech using stored credentials.

### Root Cause

“`typescript
// package…

GitHub-GHSA

MEDIUM
RTK improperly trusts project-local filter configuration, allowing silent tampering of command output shown to LLM
GHSA-fvvm-949w-qj4w
pkg: rtk
eco: rust
published: May 20, 2026
RTK (Rust Token Killer) improperly trusts project-local configuration files. In versions prior to 0.32.0, RTK automatically loads `.rtk/filters.toml` from the working directory with highest priority and without user notification. An attacker can place a malicious filter file in a repository to apply…
CVE-2026-45792
GitHub-GHSA

MEDIUM
rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
GHSA-phqj-4mhp-q6mq
pkg: openssl
eco: rust
published: May 19, 2026
`CipherCtxRef::cipher_update_inplace` incorrectly sized output buffers when used with AES key-wrap-with-padding ciphers (EVP_aes_{128,192,256}_wrap_pad). For a non-multiple-of-8 input, OpenSSL writes up to 7 bytes past the end of the caller's buffer or Vec, producing attacker-controllable heap corru…
CVE-2026-45784
GitHub-GHSA

MEDIUM
Trubo: Login callback CSRF/session fixation
GHSA-hcf7-66rw-9f5r
pkg: turbo
eco: npm
published: May 19, 2026
### Impact

Turborepo's self-hosted login and SSO browser flows did not validate a CSRF state value on the localhost callback. While the CLI was waiting for authentication, a malicious web page could send a request to the local callback server with an attacker-controlled token. If accepted before th…

CVE-2026-45773
GitHub-GHSA

MEDIUM
Diesel: Command injection in Diesel's implementation of `COPY FROM`/`COPY TO`
GHSA-m9p2-fxp5-v3fp
pkg: diesel
eco: rust
published: May 19, 2026
Diesel allows users to configure various options for PostgreSQL's `COPY FROM` and `COPY TO` statements. These configurations are partially provided as strings or characters.

Diesel did not check if any these user-provided options contain a quote character `'`, which can lead to the injection of ad…

GitHub-GHSA

MEDIUM
Diesel: Possible unaligned data access for implementations of `SqliteAggregate`
GHSA-q8x8-jrhj-fh9p
pkg: diesel
eco: rust
published: May 19, 2026
Diesel allows to register custom aggregate SQL functions for SQLite via the `SqliteAggregate` interface.

To store an instance of the custom aggregate processor Diesel relied on the `sqlite3_aggregate_context` function provided by sqlite. This function doesn't provide any guarantees about alignment …

GitHub-GHSA

MEDIUM
Caddy CVE-2026-30852 Fix Bypass
GHSA-wwhq-w58m-w29c
pkg: github.com/caddyserver/caddy/v2
eco: go
published: May 19, 2026
#

## TL;DR

CVE-2026-30852 fixed double expansion in `vars_regexp` when the variable key is a placeholder (e.g. `{http.vars.x}`). The fix does NOT protect literal key names (e.g. `tenant_id`). An attacker injects `{env.AWS_SECRET_ACCESS_KEY}` or `{file./etc/passwd}` via a request header → Caddy …

GitHub-GHSA

MEDIUM
Kong Ingress Controller for Kubernetes (KIC): Cross-namespace TLS Secret Exfiltration in Gateways with GatewayClass missing `konghq.com/gatewayclass-unmanaged: 'true'` annotation
GHSA-m23h-6mwm-39m8
pkg: github.com/kong/kubernetes-ingress-controller/v3, github.com/kong/kubernetes-ingress-controller/v3, github.com/kong/kubernetes-ingress-controller/v2
eco: go
published: May 19, 2026
## Summary

A vulnerability in the Kong Ingress Controller (KIC) allows for the unauthorized exfiltration of TLS certificates and private keys across Kubernetes namespace boundaries. In "managed" mode (where the `GatewayClass` lacks an unmanaged annotation), the Gateway TLS translator skips critical…

GitHub-GHSA

MEDIUM
Kong Ingress Controller for Kubernetes (KIC): Secret-backed plugin configurations leak through non-sensitive diagnostics endpoint
GHSA-3278-c88v-xrh4
pkg: github.com/kong/kubernetes-ingress-controller/v3, github.com/kong/kubernetes-ingress-controller/v2, github.com/kong/kubernetes-ingress-controller
eco: go
published: May 19, 2026
## Summary

A vulnerability in the Kong Ingress Controller (KIC) allows for the unauthorized exposure of sensitive plugin credentials through the diagnostics interface. Even when configured to redact sensitive information (using `–dump-sensitive-config=false`), KIC fails to sanitize the `Plugins` f…

GitHub-GHSA

MEDIUM
Envoy AI Proxy – MCP Message Smuggling Vulnerability
GHSA-4gph-2hhr-5mwg
pkg: github.com/envoyproxy/ai-gateway
eco: go
published: May 19, 2026
Envoy AI Gateway was found to be affected by a protocol parser differential vulnerability due to improper implementation of the JSON-RPC 2.0 specification. Such differential causes a MCP message alteration, potentially causing a bypass of security controls in a multi-layered architecture.

According…

GitHub-GHSA

MEDIUM
Nuxt: Dev server exposes built source over LAN to malicious sites (incomplete fix for GHSA-4gf7-ff8x-hq99)
GHSA-6m52-m754-pw2g
pkg: @nuxt/rspack-builder, @nuxt/rspack-builder, @nuxt/webpack-builder
eco: npm
published: May 19, 2026
### Summary
This is an incomplete fix for [GHSA-4gf7-ff8x-hq99](https://github.com/nuxt/nuxt/security/advisories/GHSA-4gf7-ff8x-hq99). Source code may be stolen during dev when using the webpack / rspack builder if the dev server is bound to a non-loopback address (e.g. `nuxt dev –host`) and the de…
CVE-2026-45670
GitHub-GHSA

MEDIUM
Nuxt: Reflected XSS in `navigateTo()` external redirect
GHSA-fx6j-w5w5-h468
pkg: nuxt, nuxt
eco: npm
published: May 19, 2026
### Summary
`navigateTo()` with `external: true` generates a server-side HTML redirect body containing a `<meta http-equiv="refresh">` tag. The destination URL is only sanitized by replacing `"` with `%22`, leaving `<`, `>`, `&`, and `'` unencoded. An attacker who can influence the URL passed to `na…
CVE-2026-45669
GitHub-GHSA

MEDIUM
HAX CMS: Stored XSS via '<video-player>' component allows arbitrary JavaScript execution and token theft
GHSA-2m6p-hm3w-6jm3
pkg: @haxtheweb/haxcms-nodejs, @haxtheweb/video-player
eco: npm
published: May 19, 2026
### Summary
A stored cross-site scripting (XSS) vulnerability exists in HAX CMS due to improper sanitization of the `<video-player>` component.

The component allows `javascript:` URIs in the `source` attribute, which are executed when the page is viewed. This enables attackers to execute arbitrary …

CVE-2026-46496
GitHub-GHSA

MEDIUM
Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix
GHSA-65pc-fj4g-8rjx
pkg: idna
eco: pip
published: May 19, 2026
This is the same issue as CVE-2024-3651, however the original remediation in 2024 was not a complete fix. Payloads such as `"\u0660" * N` or `"\u30fb" * N + "\u6f22"` utilize the `valid_contexto` function prior to length rejection, and for high values of `N` will take a long time to process.

### Im…

CVE-2026-45409
GitHub-GHSA

MEDIUM
Microsoft DirectX12: .spritefont multiply overflow only in 32-bit builds
GHSA-5r97-79vw-qvm4
pkg: directxtk12_desktop_win10, directxtk12_uwp
eco: nuget
published: May 18, 2026
### Impact
The spritefont reader can be induced to perform a 32-bit overflow multiply that could in theory result in a RCE.

This impacts the use of the *DirectX Tool Kit* **SpriteFont** class file loading ctor if given untrusted data files.

> Note this only applies to x86/ARM builds of the library…

GitHub-GHSA

MEDIUM
Microsoft DirectX: .spritefont multiply overflow only in 32-bit builds
GHSA-c55g-rp4x-fx84
pkg: directxtk_desktop_win10, directxtk_uwp
eco: nuget
published: May 18, 2026
### Impact
The spritefont reader can be induced to perform a 32-bit overflow multiply that could in theory result in a RCE.

This impacts the use of the *DirectX Tool Kit* **SpriteFont** class file loading ctor if given untrusted data files.

> Note this only applies to x86/ARM builds of the library…

GitHub-GHSA

MEDIUM
Neotoma: Unauthenticated Inspector/API access via reverse-proxy loopback auth bypass
GHSA-5cvp-p7p4-mcx9
pkg: neotoma
eco: npm
published: May 18, 2026
Neotoma versions starting at v0.6.0 can treat public reverse-proxied requests as local when the app receives them over a loopback socket and no Bearer token is present.

In affected deployments, the REST auth middleware can resolve unauthenticated requests as the local development user, making the h…

CVE-2026-45577


Vulnerability Digest — May 18, 2026 · 77 Critical · 2 Exploited






Vulnerability Digest — Monday, May 18, 2026


Security Report

Monday, May 18, 2026  ·  Last 7 days  ·  Min severity: MEDIUM
Total Findings
490
Critical
77
High
257
Actively Exploited
2
CISA-KEV2
NVD254
GitHub-GHSA234
Findings sorted by severity
CISA-KEV

CRITICAL
Microsoft Exchange Server Cross-Site Scripting Vulnerability
CVE-2026-42897
pkg: Microsoft Microsoft

published: May 15, 2026

Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
CVE-2026-20182
pkg: Cisco Catalyst SD-WAN

published: May 14, 2026

Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.
Required action: Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlined in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.
GitHub-GHSA

CRITICAL
utcp-cli Vulnerable to Command Injection via Unsanitized Argument Substitution in CLI Communication Protocol
GHSA-33p6-5jxp-p3x4
pkg: utcp-cli
eco: pip
published: May 14, 2026
## Summary

The `_substitute_utcp_args` method in `cli_communication_protocol.py` inserts user-controlled `tool_args` values directly into shell command strings without any sanitization or escaping. These commands are then executed via `/bin/bash -c` (Unix) or `powershell.exe -Command` (Windows), al…

CVE-2026-45369
NVD

CRITICAL
CVE-2026-44523
CVE-2026-44523
pkg: jwt

published: May 14, 2026

Note Mark is an open-source note-taking application. Prior to 0.19.4, no minimum length or entropy is enforced on the JWT_SECRET configuration value. The application accepts any base64-decodable secret regardless of size, including secrets as short as 1 byte. This vulnerability is fixed in 0.19.4.
CWE: CWE-326, CWE-345
NVD

CRITICAL
CVE-2026-44006
CVE-2026-44006
pkg: vm2_project vm2

published: May 13, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, It is possible to reach BaseHandler.getPrototypeOf, which can be used to get arbitrary prototypes. This vulnerability is fixed in 3.11.0.
CWE: CWE-94
NVD

CRITICAL
CVE-2026-44005
CVE-2026-44005
pkg: vm2_project vm2

published: May 13, 2026

vm2 is an open source vm/sandbox for Node.js. From 3.9.6 to 3.10.5, vm2's bridge exposes mutable proxies for real host-realm intrinsic prototypes and then forwards sandbox writes into the underlying host objects with otherReflectSet() and otherReflectDefineProperty(), which lets attacker-controlled …
CWE: CWE-94, CWE-1321
NVD

CRITICAL
CVE-2026-43997
CVE-2026-43997
pkg: vm2_project vm2

published: May 13, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, it is possible to obtain the host Object. There are various ways to use the host Object, to escape the sandbox, one example would be using HostObject.getOwnPropertySymbols to obtain Symbol(nodejs.util.inspect.custom). This vulnerability …
CWE: CWE-94
GitHub-GHSA

CRITICAL
Dalfox Server Mode Vulnerable to Unauthenticated Remote Code Execution via `found-action`
GHSA-v25v-m36w-jp4h
pkg: github.com/hahwul/dalfox/v2
eco: go
published: May 12, 2026
# GHSA: Unauthenticated Remote Code Execution via `found-action` in Dalfox Server Mode

## Summary

When dalfox is started in REST API server mode (`dalfox server`), the server binds to `0.0.0.0:6664` by default and requires no API key unless the operator explicitly passes `–api-key`. Because `mode…

CVE-2026-45087
NVD

CRITICAL
CVE-2026-42869
CVE-2026-42869
pkg: docker

published: May 11, 2026

SOCFortress CoPilot focuses on providing a single pane of glass for all your security operations needs. Prior to 0.1.57, SOCFortress CoPilot ships a hardcoded JWT signing secret as a fallback value in backend/app/auth/utils.py:28 and ships it verbatim in .env.example. Any deployment where JWT_SECRET…
CWE: CWE-287, CWE-522, CWE-798
GitHub-GHSA

CRITICAL
SandboxJS has a sandbox escape via Function.caller leakage of internal call op
GHSA-g8f2-4f4f-5jqw
pkg: @nyariv/sandboxjs
eco: npm
published: May 11, 2026
### Summary
Sandbox-defined functions expose `Function.caller`, allowing sandboxed code to recover the internal `LispType.Call` runtime callback. That callback can then be invoked with attacker-controlled fake context and obj values to extract blocked host statics, recover the real host Function con…
CVE-2026-43898
NVD

CRITICAL
CVE-2026-44643
CVE-2026-44643
pkg: peerigon angular-expressions

published: May 11, 2026

Angular Expressions provides expressions for the Angular.JS web framework as a standalone module. Prior to 1.5.2, an attacker can write a malicious expression using filters that escapes the sandbox to execute arbitrary code on the system. This vulnerability is fixed in 1.5.2.
CWE: CWE-95
NVD

CRITICAL
CVE-2026-43999
CVE-2026-43999
pkg: vm2_project vm2

published: May 13, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, NodeVM's builtin allowlist can be bypassed when the module builtin is allowed (including via the '*' wildcard). The module builtin exposes Node's Module._load(), which loads any module by name directly in the host context, completely byp…
CWE: CWE-863
NVD

CRITICAL
CVE-2026-43948
CVE-2026-43948
pkg: python

published: May 12, 2026

wger is a free, open-source workout and fitness manager. Prior to 2.6, the reset_user_password and gym_permissions_user_edit views in wger perform a gym-scope authorization check using Python object comparison (!=) that evaluates None != None as False, silently bypassing the guard when both the atta…
CWE: CWE-863
NVD

CRITICAL
CVE-2026-7813
CVE-2026-7813
pkg: ssl

published: May 11, 2026

Authorization vulnerability in pgAdmin 4 server mode affecting Server Groups, Servers, Shared Servers, Background Processes, and Debugger modules.

Multiple endpoints fetched user-owned objects without filtering by the requesting user's identity. An authenticated user could access another user's pri…

CWE: CWE-284
NVD

CRITICAL
CVE-2026-44717
CVE-2026-44717
pkg: express

published: May 15, 2026

MCP Calculate Server is a mathematical calculation service based on MCP protocol and SymPy library. Prior to 0.1.1, the use of eval() to evaluate mathematical expressions without proper input sanitization leads to remote code execution. This vulnerability is fixed in 0.1.1.
CWE: CWE-94
NVD

CRITICAL
CVE-2026-5229
CVE-2026-5229
pkg: oauth

published: May 15, 2026

The Form Notify plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.1.10. This is due to the plugin trusting user-controlled cookie data to determine which WordPress account to authenticate after a LINE OAuth login. When LINE doesn't provide an email address…
CWE: CWE-287
GitHub-GHSA

CRITICAL
vm2 Has a Sandbox Breakout Using Async Generator
GHSA-248r-7h7q-cr24
pkg: vm2
eco: npm
published: May 14, 2026
### Summary

VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system.

### Details

It is possible to catch a host exception using the `yield*` expression inside an async generator.…

CVE-2026-45411
GitHub-GHSA

CRITICAL
Marten has an injection vulnerability in its full-text search regConfig parameter
GHSA-vmw2-qwm8-x84c
pkg: Marten
eco: nuget
published: May 14, 2026
## Summary

Marten's full-text search APIs interpolated the user-supplied `regConfig` parameter directly into the generated SQL without parameterization or validation, making every code path that exposes `regConfig` to untrusted input a SQL injection sink.

## Affected APIs

– `IQuerySession.SearchA…

CVE-2026-45288
NVD

CRITICAL
CVE-2026-42589
CVE-2026-42589
pkg: express

published: May 14, 2026

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg's /forms/pdfengines/metadata/write HTTP endpoint accepts a JSON metadata object and passes its keys directly to ExifTool via the go-exiftool library. No validation is performed on key characters. A \n embedded in a…
CWE: CWE-78
NVD

CRITICAL
CVE-2026-45411
CVE-2026-45411
pkg: vm2_project vm2

published: May 13, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.3, it is possible to catch a host exception using the yield* expression inside an async generator. When the generator is closed using the return function, the value is awaited on and exceptions thrown in the then call will be caught by the …
CWE: CWE-668
NVD

CRITICAL
CVE-2026-44009
CVE-2026-44009
pkg: vm2_project vm2

published: May 13, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, This vulnerability is fixed in 3.11.2.
CWE: CWE-668
NVD

CRITICAL
CVE-2026-44008
CVE-2026-44008
pkg: vm2_project vm2

published: May 13, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, the new method neutralizeArraySpeciesBatch works with objects from the other side but can call into this side via getter on the array prototype exposing objects of the wrong side into the sandbox. This can be used to get host objects and…
CWE: CWE-668
GitHub-GHSA

CRITICAL
Goobi viewer – Core: Unauthenticated Solr Streaming Expression Proxy
GHSA-2rgp-f66f-4499
pkg: io.goobi.viewer:viewer-core
eco: maven
published: May 13, 2026
### Summary

The Goobi viewer REST endpoint `POST /api/v1/index/stream` accepted an arbitrary Solr streaming
expression from unauthenticated network clients and forwarded it to the backend Solr server without restriction.
An attacker could read the complete Solr index and, in default Solr deployment…

CVE-2026-45083
GitHub-GHSA

CRITICAL
SillyTavern has Authentication Bypass via SSO Header Injection
GHSA-gxx6-h3g6-vwjh
pkg: sillytavern
eco: npm
published: May 12, 2026
## Resolution

SillyTavern 1.18.0 now includes a configuration option to limit which IP addresses can authorize using SSO headers, limiting to just loopback addresses by default. A setting can be customized according to user's needs.

Documentation: https://docs.sillytavern.app/administration/sso/

CVE-2026-44649
NVD

CRITICAL
CVE-2026-45185
CVE-2026-45185
pkg: tls

published: May 12, 2026

Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CHUNKING transfer, followed by a final cleartext byte on the same TCP connection. This can lead to hea…
CWE: CWE-416
NVD

CRITICAL
CVE-2026-31239
CVE-2026-31239
pkg: python

published: May 12, 2026

The mamba language model framework thru 2.2.6 is vulnerable to insecure deserialization (CWE-502) when loading pre-trained models from HuggingFace Hub. The MambaLMHeadModel.from_pretrained() method uses torch.load() to load the pytorch_model.bin weight file without enabling the security-restrictive …
CWE: CWE-502
NVD

CRITICAL
CVE-2026-31238
CVE-2026-31238
pkg: python

published: May 12, 2026

The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) in its model serving component. When starting a model server with the ludwig serve command, the framework loads model weight files using torch.load() without enabling the security-restrictive weights_only=True param…
CWE: CWE-502
NVD

CRITICAL
CVE-2026-31237
CVE-2026-31237
pkg: python

published: May 12, 2026

The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) through its predict() method. When a user provides a dataset file path to the predict() method, the framework automatically determines the file format. If the file is a pickle (.pkl) file, it is loaded using pandas.…
CWE: CWE-502
NVD

CRITICAL
CVE-2026-31236
CVE-2026-31236
pkg: python

published: May 12, 2026

The llm CLI tool thru 0.27.1 contains a critical code injection vulnerability via its –functions command-line argument. This argument is intended to allow users to provide custom Python function definitions. However, the tool directly executes the provided code using the unsafe exec() function with…
CWE: CWE-94
NVD

CRITICAL
CVE-2026-31235
CVE-2026-31235
pkg: python

published: May 12, 2026

The imgaug library thru 0.4.0 contains an insecure deserialization vulnerability in its BackgroundAugmenter class within the multicore.py module. The class uses Python's pickle module to deserialize data received via a multiprocessing queue in the _augment_images_worker() method without any safety c…
CWE: CWE-502
NVD

CRITICAL
CVE-2026-31231
CVE-2026-31231
pkg: python

published: May 12, 2026

Cognee thru v0.4.0 contains a critical remote code execution vulnerability in its notebook cell execution API endpoint. The endpoint is designed to execute arbitrary Python code provided by the user, but it does so using the unsafe exec() function without any sandboxing, validation, or security cont…
CWE: CWE-94
NVD

CRITICAL
CVE-2026-31230
CVE-2026-31230
pkg: python

published: May 12, 2026

The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a command-line argument injection vulnerability in its Kubeflow component (robustness_evaluation_fgsm_pytorch.py). The script uses the unsafe eval() function to parse string values provided via the –clip_values and –input_shape command-…
CWE: CWE-88
NVD

CRITICAL
CVE-2026-31229
CVE-2026-31229
pkg: python

published: May 12, 2026

The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains an insecure deserialization vulnerability (CWE-502) in its Kubeflow component's model loading functionality. When loading model weights from a file (e.g., model.pt) during robustness evaluation, the code uses torch.load() without the secu…
CWE: CWE-502
NVD

CRITICAL
CVE-2026-31228
CVE-2026-31228
pkg: python

published: May 12, 2026

The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a remote code execution vulnerability in its Kubeflow component. The robustness evaluation function for PyTorch models uses the unsafe eval() function to dynamically evaluate user-supplied strings for the LossFn and Optimizer parameters w…
CWE: CWE-94
NVD

CRITICAL
CVE-2026-31220
CVE-2026-31220
pkg: python

published: May 12, 2026

PySyft (Syft Datasite/Server) versions 0.9.5 and earlier are vulnerable to remote code execution due to insufficient validation and sandboxing of user-submitted code. The system allows low-privileged users to submit Python functions (via @sy.syft_function()) for remote execution on the server. While…
CWE: CWE-94
NVD

CRITICAL
CVE-2026-31217
CVE-2026-31217
pkg: python

published: May 12, 2026

The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370811af6b11402f51d377f (2024-07-21) allows arbitrary code execution. When a user supplies a directory path via the –model command-line argument, the function reads a module.py file …
CWE: CWE-94
NVD

CRITICAL
CVE-2026-31214
CVE-2026-31214
pkg: python

published: May 12, 2026

The torch-checkpoint-shrink.py script in the ml-engineering project in commit 0099885db36a8f06556efe1faf552518852cb1e0 (2025-20-27) contains an insecure deserialization vulnerability (CWE-502). The script uses torch.load() to process PyTorch checkpoint files (.pt) without enabling the security-restr…
CWE: CWE-502
GitHub-GHSA

CRITICAL
WebdriverIO BrowserStack Service has a Command Injection issue
GHSA-5c46-x3qw-q7j7
pkg: @wdio/browserstack-service
eco: npm
published: May 11, 2026
### Summary
A command injection vulnerability exists in `@wdio/browserstack-service` that allows remote code execution (RCE) when processing git branch names in test orchestration. An attacker can exploit this by providing a malicious git repository with a branch name containing shell command inject…
CVE-2026-25244
GitHub-GHSA

CRITICAL
DeepSeek TUI: task_create Insecure Defaults Enable RCE via Prompt Injection in Project Files
GHSA-72w5-pf8h-xfp4
pkg: deepseek-tui
eco: rust
published: May 14, 2026
### Summary

The `task_create` tool spawns durable sub-agents that inherit two insecure defaults:

– `allow_shell` defaults to `true` (`config.rs:1499`: `self.allow_shell.unwrap_or(true)`)
– `auto_approve` defaults to `true` (`task_manager.rs:297`: `auto_approve: Some(true)`)

When a user approves a…

CVE-2026-45374
GitHub-GHSA

CRITICAL
DeepSeek TUI: run_tests Tool Enables RCE via Malicious Repository Without Approval
GHSA-wx44-2q6h-j6p8
pkg: deepseek-tui, deepseek-tui-cli, deepseek-tui
eco: npm
published: May 14, 2026
### Summary
The `run_tests` tool executes `cargo test` in the workspace with `ApprovalRequirement::Auto`, meaning it runs without any user approval prompt. The source code explicitly states this design choice:

“`rust
fn approval_requirement(&self) -> ApprovalRequirement {
// Tests are encoura…

CVE-2026-45311
NVD

CRITICAL
CVE-2026-8511
CVE-2026-8511
pkg: go

published: May 14, 2026

Use after free in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

CRITICAL
CVE-2026-44482
CVE-2026-44482
pkg: node

published: May 14, 2026

soundcloud-rpc is a SoundCloud Client with Discord Rich Presence, Dark Mode, Last.fm and AdBlock support. Prior to 0.1.8, a track title containing an HTML payload executed locally in the Electron app. This means attacker-controlled SoundCloud track metadata can lead to local command execution on the…
CWE: CWE-20, CWE-79, CWE-94, CWE-862
GitHub-GHSA

CRITICAL
Obot has an authorization bypass in /mcp-connect/{id} that allows any authenticated user to use any registered MCP server
GHSA-vw82-7fv8-r6gp
pkg: github.com/obot-platform/obot
eco: go
published: May 13, 2026
## Summary

If you have the MCP Server ID, you can connect to the MCP server even if you don't have permissions to the server.

The MCP gateway endpoint `/mcp-connect/{mcp_id}` does not enforce Access Control Rules (ACRs). Any authenticated Obot user who possesses an MCP Server ID can connect to tha…

GitHub-GHSA

CRITICAL
Malware in @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys
GHSA-g7cv-rxg3-hmpx
pkg: @tanstack/arktype-adapter, @tanstack/eslint-plugin-router, @tanstack/eslint-plugin-start
eco: npm
published: May 12, 2026
## Summary

On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 `@tanstack/*` packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for `TanStack/router`, but the publish wo…

CVE-2026-45321
GitHub-GHSA

CRITICAL
PraisonAI MCP `tools/call` path-traversal => RCE via Python `.pth` injection
GHSA-9mqq-jqxf-grvw
pkg: PraisonAI
eco: pip
published: May 11, 2026
## Summary

PraisonAI's MCP (Model Context Protocol) server (`praisonai mcp serve`) registers four file-handling tools by default — `praisonai.rules.create`, `praisonai.rules.show`, `praisonai.rules.delete`, and `praisonai.workflow.show`. Each accepts a path or filename string from MCP `tools/call…

CVE-2026-44336
NVD

CRITICAL
CVE-2026-42596
CVE-2026-42596
pkg: docker

published: May 14, 2026

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, the default deny-lists used by Gotenberg's downloadFrom feature and webhook feature are bypassable. Because the filter is regex-based and case-sensitive, an unauthenticated attacker can supply URLs such as http://[::ffff:127…
CWE: CWE-918
NVD

CRITICAL
CVE-2026-42882
CVE-2026-42882
pkg: go

published: May 11, 2026

oxyno-zeta/s3-proxy is an aws s3 proxy written in go. Prior to 5.0.0, s3-proxy contains an authentication bypass caused by inconsistent URL path interpretation between the authentication middleware and the bucket handler. The authentication middleware evaluates resource path patterns against the per…
CWE: CWE-22, CWE-863
GitHub-GHSA

CRITICAL
Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`
GHSA-rpr9-rxv7-x643
pkg: sanitize-html
eco: npm
published: May 14, 2026
### Summary
Under the default configuration, `sanitize-html` can turn attacker-controlled content inside a disallowed `xmp` element into live HTML or JavaScript. This is a sanitizer bypass in the default `disallowedTagsMode: 'discard'` path and can lead to stored XSS in applications that render sani…
CVE-2026-44990
NVD

CRITICAL
CVE-2026-43900
CVE-2026-43900
pkg: vue

published: May 11, 2026

DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to v1.0.4-beta.1, a Cross-Site Scripting (XSS) vulnerability exists due to a discrepancy between the backend validation layer and the frontend browser rendering engine. The SVGSanitizer (s…
CWE: CWE-79
NVD

CRITICAL
CVE-2026-41258
CVE-2026-41258
pkg: express

published: May 15, 2026

OpenMRS is an open source electronic medical record system platform. From 2.7.0 to before 2.7.9 and 2.8.6, the ConceptReferenceRangeUtility.evaluateCriteria() method in OpenMRS Core evaluates database-stored criteria strings as Apache Velocity templates without any sandbox configuration. The Velocit…
CWE: CWE-94
GitHub-GHSA

CRITICAL
@samanhappy/mcphub: SSE Endpoint Accepts Arbitrary Username from URL Path Without Authentication, Enabling User Impersonation
GHSA-wf8q-wvv8-p8jf
pkg: @samanhappy/mcphub
eco: npm
published: May 14, 2026
### Summary

A critical identity spoofing vulnerability in MCPHub allows any unauthenticated user to impersonate any other user — including administrators — on SSE (Server-Sent Events) and MCP transport endpoints. The server accepts a username from the URL path parameter and creates an internal …

NVD

CRITICAL
CVE-2026-42555
CVE-2026-42555
pkg: express

published: May 14, 2026

Valtimo is an open-source business process automation platform. com.ritense.valtimo:document from 12.0.0 to before 12.32.0, com.ritense.valtimo:case from 13.0.0 to before 13.23.0, and com.ritense.valtimo:contract from 13.4.0 to before 13.23.0 evaluate Spring Expression Language (SpEL) expressions fr…
CWE: CWE-94
NVD

CRITICAL
CVE-2026-44351
CVE-2026-44351
pkg: jwt

published: May 13, 2026

fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.2.4, a critical authentication-bypass vulnerability in fast-jwt's async key-resolver flow allows any unauthenticated attacker to forge arbitrary JWTs that are accepted as authentic. When the application's key resolver returns an …
CWE: CWE-287, CWE-326, CWE-1391
NVD

CRITICAL
CVE-2026-44007
CVE-2026-44007
pkg: vm2_project vm2

published: May 13, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.1, when a NodeVM is created with nesting: true, sandbox code can unconditionally require('vm2') regardless of the outer VM's require configuration — including require: false. With access to vm2, the sandbox constructs a new inner NodeVM w…
CWE: CWE-284
GitHub-GHSA

CRITICAL
SillyTavern has a Path Traversal issue
GHSA-886q-f44j-h6wh
pkg: sillytavern
eco: npm
published: May 12, 2026
## Summary

`POST /api/extensions/delete` endpoint accepts `extensionName: "."` which bypasses
`sanitize-filename` validation, causing the entire user extensions directory to be
recursively deleted. No authentication is required in the default configuration.

## Affected File

`src/endpoints/exten…

CVE-2026-44650
GitHub-GHSA

CRITICAL
sealed-env: TOTP secret embedded in unseal token payload (enterprise mode)
GHSA-x3r2-fj3r-g5mv
pkg: sealed-env, io.github.davidalmeidac:sealed-env-core
eco: npm
published: May 12, 2026
In sealed-env enterprise mode, versions 0.1.0-alpha.1 through 0.1.0-alpha.3 embedded the operator's literal TOTP secret in the JWS payload of every minted unseal token. JWS payload is base64-encoded JSON, NOT encrypted. Any party who could observe a minted token (CI build logs, container env dumps, …
CVE-2026-45091
NVD

CRITICAL
CVE-2026-45091
CVE-2026-45091
pkg: node

published: May 12, 2026

sealed-env is a cross-stack, zero-trust secret management library for Node.js and Java/Spring Boot. In sealed-env enterprise mode, versions 0.1.0-alpha.1 through 0.1.0-alpha.3 embedded the operator's literal TOTP secret in the JWS payload of every minted unseal token. JWS payload is base64-encoded J…
CWE: CWE-200, CWE-522
GitHub-GHSA

CRITICAL
Unity Catalog has a JWT Issuer Validation Bypass tht Allows Complete User Impersonation
GHSA-qqcj-rghw-829x
pkg: io.unitycatalog:unitycatalog-server
eco: maven
published: May 11, 2026
**Context:**
A critical authentication bypass vulnerability exists in the Unity Catalog token exchange endpoint (/api/1.0/unity-control/auth/tokens). The endpoint extracts the issuer (iss) claim from incoming JWTs and uses it to dynamically fetch the JWKS endpoint for signature validation without va…
CVE-2026-27478
NVD

CRITICAL
CVE-2026-42457
CVE-2026-42457
pkg: kubernetes

published: May 14, 2026

vCluster Platform provides a Kubernetes platform for managing virtual clusters, multi-tenancy, and cluster sharing. Prior to 4.4.3, 4.5.5, 4.6.2, 4.7.1, and 4.8.0, there is a Stored XSS attack vulnerability via the name field of a templateRef. This can lead to the execution of arbitrary external scr…
CWE: CWE-79
GitHub-GHSA

CRITICAL
SiYuan Bazaar marketplace renders unescaped package `name` and `version` metadata, allowing stored XSS and Electron code execution
GHSA-27qc-m5gf-jv5r
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: May 13, 2026
### Summary

SiYuan's Bazaar (community marketplace) renders the `name` and `version` fields of a package's `plugin.json` (and the equivalent `theme.json` / `template.json` / `widget.json` / `icon.json`) into the Settings → Marketplace UI without HTML escaping. The kernel-side helper `sanitizePack…

CVE-2026-45375
NVD

CRITICAL
CVE-2026-41901
CVE-2026-41901
pkg: express

published: May 12, 2026

Thymeleaf is a server-side Java template engine for web and standalone environments. Prior to 3.1.5.RELEASE, a security bypass vulnerability exists in the expression execution mechanisms of Thymeleaf. Although the library provides mechanisms to avoid the execution of potentially dangerous expression…
CWE: CWE-917, CWE-1336
GitHub-GHSA

CRITICAL
Amazon Redshift Vulnerable to Remote Code Execution via Unsafe Class Loading
GHSA-wmmv-vvg5-993q
pkg: com.amazon.redshift:redshift-jdbc42
eco: maven
published: May 14, 2026
### Summary
Amazon Redshift JDBC Driver is a Type 4 JDBC driver that provides database connectivity through the standard JDBC application program interfaces (APIs). An issue exists in versions prior to 2.2.2 where the driver could load arbitrary classes when processing certain connection URL paramet…
CVE-2026-8178
GitHub-GHSA

CRITICAL
Electerm Local code through electerm's single-instance socket
GHSA-7p5m-v798-f8vv
pkg: electerm
eco: npm
published: May 14, 2026
### Impact
_Local code execution without UI interaction: any same-user process can send a JSON payload to electerm's single-instance socket/pipe, causing the app to create tabs and potentially spawn attacker-controlled local processes. Affects electerm single-instance installs on the machine._

### …

CVE-2026-45353
GitHub-GHSA

CRITICAL
Electerm: Importing unsafe bookmark data could lead to unsafe operation when clicking local type bookmark
GHSA-jgg9-rw32-44pj
pkg: electerm
eco: npm
published: May 14, 2026
### Impact
_Persistent local-pty code execution via imported bookmarks or compromised sync targets. Affects users who import bookmark JSON files or who have electerm sync configured (gist/WebDAV). The attacker can inject `exec*` fields or global config to cause remote code to run when a bookmark is …
CVE-2026-45058
GitHub-GHSA

CRITICAL
Portainer has an endpoint security bypass via Swarm service create/update
GHSA-5fxq-qcf3-244w
pkg: github.com/portainer/portainer, github.com/portainer/portainer, github.com/portainer/portainer
eco: go
published: May 14, 2026
## Summary

Portainer enforces seven `EndpointSecuritySettings` restrictions that administrators configure to restrict the container configurations non-admin users can launch: **privileged mode**, **host PID namespace**, **device mapping**, **capabilities**, **sysctls**, **security-opt (Seccomp / Ap…

CVE-2026-44849
GitHub-GHSA

CRITICAL
Portainer missing authorization on Docker plugin endpoints, which allows host RCE
GHSA-rrmm-9v76-h3p4
pkg: github.com/portainer/portainer, github.com/portainer/portainer, github.com/portainer/portainer
eco: go
published: May 14, 2026
## Summary

Portainer enforces Role-Based Access Control (RBAC) on top of the Docker API. The proxy layer routes incoming Docker API requests to per-resource handlers (containers, images, services, volumes, etc.) that apply authorization checks.

The Docker plugin management endpoints (`/plugins/*`)…

CVE-2026-44848
GitHub-GHSA

CRITICAL
n8n Has an XML Node Prototype Pollution Patch Bypass
GHSA-wrwr-h859-xh2r
pkg: n8n, n8n, n8n
eco: npm
published: May 14, 2026
## Impact
An authenticated user with permission to create or modify workflows could bypass the patch for GHSA-hqr4-h3xv-9m3r in the XML node. When combined with other nodes, this could lead to RCE on the n8n host.

## Patches
The issue has been fixed in n8n versions 1.123.43, 2.20.7, and 2.22.1. Use…

CVE-2026-44791
GitHub-GHSA

CRITICAL
n8n Has an Arbitrary File Read via Git Node
GHSA-57g9-58c2-xjg3
pkg: n8n, n8n, n8n
eco: npm
published: May 14, 2026
## Impact
An authenticated user with permission to create or modify workflows could inject CLI flags on the Git node's Push operation allowing an attacker to read arbitrary files from the n8n server potentially leading to full compromise.

## Patches
The issue has been fixed in n8n versions 1.123.43…

CVE-2026-44790
GitHub-GHSA

CRITICAL
n8n: HTTP Request Node Pagination Prototype Pollution to RCE
GHSA-c8xv-5998-g76h
pkg: n8n, n8n, n8n
eco: npm
published: May 14, 2026
## Impact
An authenticated user with permission to create or modify workflows could achieve global prototype pollution via an unvalidated pagination parameter in the HTTP Request node. Combined with other techniques this could lead to RCE on the instance.

## Patches
The issue has been fixed in n8n …

CVE-2026-44789
GitHub-GHSA

CRITICAL
FlowiseAI: Authenticated Host RCE via POST /api/v1/node-custom-function and NodeVM Sandbox Escape
GHSA-9rvc-vf7m-pgm2
pkg: flowise
eco: npm
published: May 14, 2026
### Summary

`POST /api/v1/node-custom-function` lacks route-level authorization, allowing any authenticated user or API key to submit arbitrary JavaScript to the `Custom JS Function` node.

When `E2B_APIKEY` is not configured — the common deployment case — Flowise executes this code inside a `N…

CVE-2026-46442
GitHub-GHSA

CRITICAL
Strapi may leak sensitive data via relational filtering due to lack of query sanitization
GHSA-rjg2-95×7-8qmx
pkg: @strapi/strapi
eco: npm
published: May 14, 2026
### Summary of CVE-2026-27886 Vulnerability Details

– CVE: CVE-2026-27886
– CVSS v3.1 Vector: `CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N` (9.3 — Critical)
– Affected Versions: `@strapi/strapi` <=5.36.1
– How to Patch: Immediately update your Strapi to >=5.37.0

### Descripti…

CVE-2026-27886
GitHub-GHSA

CRITICAL
Strapi Vulnerable to SQL Injection in Content Type Builder
GHSA-3xcq-8mjw-h6mx
pkg: @strapi/content-type-builder, @strapi/plugin-content-type-builder
eco: npm
published: May 13, 2026
### Summary of CVE-2026-22599 Vulnerability Details

– CVE: CVE-2026-22599
– CVSS v3.1 Vector: `CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N` (9.3 — Critical)
– Affected Versions: `@strapi/content-type-builder` <=5.33.1 (v5), `@strapi/plugin-content-type-builder` <=4.26.0 (v4)
-…

CVE-2026-22599
GitHub-GHSA

CRITICAL
Mapfish Print: Remote Code Injection (RCE) in Dynamic table
GHSA-q7m6-wpvf-mvwx
pkg: org.mapfish.print:print-lib, org.mapfish.print:print-lib, org.mapfish.print:print-lib
eco: maven
published: May 13, 2026
### Impact

The attacker can execute arbitrary code without being authenticated

### Mitigation

Upgrade to a patched version (please check affected/patched version matrix)

### Credits

Bug Bounty of Canton du Jura

CVE-2026-44672
GitHub-GHSA

CRITICAL
esm.sh: Legacy Route Path Traversal Can Lead to RCE
GHSA-3636-h3vx-6465
pkg: github.com/esm-dev/esm.sh
eco: go
published: May 12, 2026
### Impact
– Arbitrary File Write – An attacker can cause the server to write data to any file path it has write permission for.
– Privilege Escalation / RCE – By overwriting critical binaries or scripts, the attacker can execute arbitrary code with the server’s privileges.

### Exploit

The l…

CVE-2026-44593
GitHub-GHSA

CRITICAL
OpenClaude Sandbox Bypass via Model-Controlled `dangerouslyDisableSandbox` Input
GHSA-m77w-p5jj-xmhg
pkg: openclaude
eco: npm
published: May 12, 2026
### Summary
The `dangerouslyDisableSandbox` parameter is exposed as part of the BashTool input schema, meaning the LLM (an untrusted principal per the project's own threat model) can set it to `true` in any `tool_use` response. Combined with the default `allowUnsandboxedCommands: true` setting, a pr…
CVE-2026-42074
GitHub-GHSA

CRITICAL
Angular Expressions – Remote Code Execution using filters
GHSA-pw8r-6689-xvf4
pkg: angular-expressions
eco: npm
published: May 11, 2026
## Impact

An attacker can write a malicious expression that escapes the sandbox to execute arbitrary code on the system.

Example of vulnerable code:

“`
const expressions = require("angular-expressions");
const result = expressions.compile("a | __proto__")({}, {});
“`

This should throw the erro…

CVE-2026-44643
GitHub-GHSA

CRITICAL
CloudNativePG's metrics exporter allows privilege escalation to PostgreSQL superuser and OS RCE
GHSA-423p-g724-fr39
pkg: github.com/cloudnative-pg/cloudnative-pg, github.com/cloudnative-pg/cloudnative-pg
eco: go
published: May 11, 2026
### Impact

The CloudNativePG metrics exporter opens its PostgreSQL connection as the `postgres` superuser via the pod-local Unix socket, then demotes the session with `SET ROLE pg_monitor`. `SET ROLE` changes only `current_user`; `session_user` remains `postgres`. That residual superuser identity i…

CVE-2026-44477
NVD

HIGH
CVE-2026-8719
CVE-2026-8719
pkg: oauth

published: May 17, 2026

The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Privilege Escalation in version 3.4.9. This is due to missing WordPress capability enforcement in the MCP OAuth bearer-token authorization path, where any valid OAuth token causes MCP access to be g…
CWE: CWE-269
GitHub-GHSA

HIGH
Budibase: `PUT /api/datasources/:datasourceId` is protected only by `TABLE/READ` permission instead of builder access, allowing any authenticated app user to overwrite datasource connection parameters including host, port, and URL
GHSA-44m2-crh7-f4q2
pkg: @budibase/server
eco: npm
published: May 15, 2026
## Summary

Budibase exposes a REST API for datasource management. The route `PUT /api/datasources/:datasourceId` is registered in the `authorizedRoutes` group with `TABLE/READ` permission. This is the same authorization level as the read endpoint (`GET /api/datasources/:datasourceId`). Every authen…

CVE-2026-45717
GitHub-GHSA

HIGH
Open WebUI: Jupyter code execution works despite `ENABLE_CODE_EXECUTION=false` — feature gate bypassed
GHSA-482j-2pq6-q5w4
pkg: open-webui
eco: pip
published: May 14, 2026
### Summary

The `/api/v1/utils/code/execute` endpoint executes arbitrary Python code via Jupyter for any verified user, even when the admin has set `ENABLE_CODE_EXECUTION=false`. The feature gate is not enforced on the API endpoint — the configuration says "disabled" but code still executes.

###…

CVE-2026-45672
NVD

HIGH
CVE-2026-8532
CVE-2026-8532
pkg: go

published: May 14, 2026

Integer overflow in XML in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-472
NVD

HIGH
CVE-2026-8531
CVE-2026-8531
pkg: go

published: May 14, 2026

Heap buffer overflow in WebML in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-122
NVD

HIGH
CVE-2026-8529
CVE-2026-8529
pkg: go

published: May 14, 2026

Heap buffer overflow in Codecs in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted video file. (Chromium security severity: High)
CWE: CWE-122
NVD

HIGH
CVE-2026-8527
CVE-2026-8527
pkg: go

published: May 14, 2026

Insufficient validation of untrusted input in Downloads in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-20
NVD

HIGH
CVE-2026-8526
CVE-2026-8526
pkg: go

published: May 14, 2026

Out of bounds write in WebRTC in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-787
NVD

HIGH
CVE-2026-8524
CVE-2026-8524
pkg: go

published: May 14, 2026

Out of bounds write in WebAudio in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-787
NVD

HIGH
CVE-2026-8522
CVE-2026-8522
pkg: go

published: May 14, 2026

Use after free in Downloads in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-8519
CVE-2026-8519
pkg: go

published: May 14, 2026

Integer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-472
NVD

HIGH
CVE-2026-8518
CVE-2026-8518
pkg: go

published: May 14, 2026

Use after free in Blink in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-8517
CVE-2026-8517
pkg: go

published: May 14, 2026

Object lifecycle issue in WebShare in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-664
NVD

HIGH
CVE-2026-8509
CVE-2026-8509
pkg: go

published: May 14, 2026

Heap buffer overflow in WebML in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-122
NVD

HIGH
CVE-2026-43909
CVE-2026-43909
pkg: openimageio openimageio

published: May 14, 2026

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, a signed 32-bit integer overflow in the loop index expression i * 4 inside SwapRGBABytes() causes the function to compute a large negative…
CWE: CWE-125, CWE-190, CWE-787
NVD

HIGH
CVE-2026-43908
CVE-2026-43908
pkg: openimageio openimageio

published: May 14, 2026

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, a signed 32-bit integer overflow in the pixel-loop index expression i * 3 inside ConvertCbYCrYToRGB() causes the function to compute a lar…
CWE: CWE-190, CWE-787
NVD

HIGH
CVE-2026-44827
CVE-2026-44827
pkg: python

published: May 14, 2026

Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, diffusers 0.37.0 allows remote code execution without the trust_remote_code=True safeguard when loading pipelines from Hugging Face Hub repositories. The _resolve_custom_pipeline_and_cls function in pipeline_loading_utils.…
CWE: CWE-94
NVD

HIGH
CVE-2026-44293
CVE-2026-44293
pkg: protobufjs_project protobufjs

published: May 13, 2026

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated JavaScript for toObject conversion could include an unsafe expression derived from a schema-controlled bytes field default value. A crafted descriptor with a non-string default val…
CWE: CWE-94
NVD

HIGH
CVE-2026-45227
CVE-2026-45227
pkg: python

published: May 12, 2026

Heym before 0.0.21 contains a sandbox escape vulnerability in the custom Python tool executor that allows authenticated workflow authors to bypass sandbox restrictions by using object-graph introspection primitives. Attackers can use Python introspection techniques to recover the unrestricted __impo…
CWE: CWE-693
NVD

HIGH
CVE-2026-44224
CVE-2026-44224
pkg: requarks wiki.js

published: May 12, 2026

Wiki.js is an open source wiki app built on Node.js. Prior to 2.5.313, the users.update GraphQL mutation accepts an arbitrary groups array and applies it directly to the database with no validation of the group IDs supplied. The resolver passes the caller's arguments straight to the model without an…
CWE: CWE-269
NVD

HIGH
CVE-2026-34329
CVE-2026-34329
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over an adjacent network.
CWE: CWE-122
NVD

HIGH
CVE-2026-31232
CVE-2026-31232
pkg: python

published: May 12, 2026

The CosyVoice project thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its model loading process. When loading model files (.pt) from a user-specified directory (via the –model_dir argument), the code uses torch.load()…
CWE: CWE-502
NVD

HIGH
CVE-2026-31225
CVE-2026-31225
pkg: python

published: May 12, 2026

The superduper project thru v0.10.0 contains a critical remote code execution vulnerability in its query parsing component. The _parse_op_part() function in query.py uses the unsafe eval() function to dynamically evaluate user-supplied query operands without proper sanitization or restriction. Altho…
CWE: CWE-94
NVD

HIGH
CVE-2026-31224
CVE-2026-31224
pkg: snorkel snorkel

published: May 12, 2026

The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the MultitaskClassifier.load() method of the MultitaskClassifier class. The method loads model weight files using torch.load() without enabling the security-restrictive weights_only=True parameter. This …
CWE: CWE-502
NVD

HIGH
CVE-2026-31223
CVE-2026-31223
pkg: snorkel snorkel

published: May 12, 2026

The snorkel library thru v0.10.0 contains a critical insecure deserialization vulnerability (CWE-502) in the BaseLabeler.load() method of the BaseLabeler class. The method loads serialized labeler models using the unsafe pickle.load() function on user-supplied file paths without any validation or se…
CWE: CWE-502, CWE-502
NVD

HIGH
CVE-2026-31222
CVE-2026-31222
pkg: snorkel snorkel

published: May 12, 2026

The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the Trainer.load() method of the Trainer class. The method loads model checkpoint files using torch.load() without enabling the security-restrictive weights_only=True parameter. This default behavior all…
CWE: CWE-502, CWE-502
NVD

HIGH
CVE-2026-31219
CVE-2026-31219
pkg: python

published: May 12, 2026

The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370811af6b11402f51d377f (2024-07-21) is vulnerable to insecure deserialization (CWE-502). When a user provides a single model file path (e.g., .pt or .pth) via the –model command-lin…
CWE: CWE-502
NVD

HIGH
CVE-2026-31218
CVE-2026-31218
pkg: python

published: May 12, 2026

The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370811af6b11402f51d377f (2024-07-21) is vulnerable to insecure deserialization (CWE-502). When loading a model state dictionary from a state_dict.pt file via torch.load(), the functio…
CWE: CWE-502
GitHub-GHSA

HIGH
LiteLLM has a sandbox escape in custom-code guardrail
GHSA-wxxx-gvqv-xp7p
pkg: litellm
eco: pip
published: May 11, 2026
### Impact

The `POST /guardrails/test_custom_code` endpoint runs user-supplied Python inside a hand-rolled sandbox. The sandbox can be escaped using bytecode-level techniques, allowing arbitrary code execution in the proxy process — which runs as root in the default Docker image.

**Reaching the …

CVE-2026-40217
GitHub-GHSA

HIGH
Dockerfile command injection via envs[*].name in bentofile.yaml (sibling fix-bypass of CVE-2026-33744 and CVE-2026-35043)
GHSA-w2pm-x38x-jp44
pkg: bentoml
eco: pip
published: May 11, 2026
# BentoML `envs[*].name` Dockerfile command injection — sibling of CVE-2026-33744 / CVE-2026-35043

A malicious `bentofile.yaml` containing a newline-injected value in `envs[*].name` produces unquoted `RUN` directives in the BentoML-generated Dockerfile. When the victim runs `bentoml containerize`…

CVE-2026-44346
GitHub-GHSA

HIGH
BentoML Dockerfile command injection via docker.base_image (sister of pending GHSA-w2pm-x38x-jp44 / CVE-2026-33744 / CVE-2026-35043)
GHSA-78f9-r8mh-4xm2
pkg: bentoml
eco: pip
published: May 11, 2026
The same Dockerfile template that mishandles `envs[*].name` (pending GHSA-w2pm-x38x-jp44) also interpolates `docker.base_image` raw with no escaping, newline filtering, or validation. A malicious bento.yaml with a multi-line `docker.base_image` value smuggles arbitrary Dockerfile directives into the…
CVE-2026-44345
GitHub-GHSA

HIGH
pyLoad is vulnerable to stored XSS in Downloads view via unsanitized link URL in packages.js template literal
GHSA-fcjq-435v-jx94
pkg: pyload-ng
eco: pip
published: May 14, 2026
## Summary

The `packages.js` template at `src/pyload/webui/app/themes/modern/templates/js/packages.js:172` interpolates a stored link URL into a template literal inside single-quoted HTML and then writes the result to the DOM via `$(div).html(html)`. No escaping runs between the API value and `inne…

CVE-2026-45348
GitHub-GHSA

HIGH
Open WebUI has stored XSS via attacker-controlled file extension in /api/v1/audio/transcriptions
GHSA-m8f9-9whg-f4xr
pkg: open-webui
eco: pip
published: May 14, 2026
## Summary

The audio transcription upload endpoint takes the file extension from the user-supplied filename and saves the file under CACHE_DIR/audio/tran…

CVE-2026-45315
GitHub-GHSA

HIGH
protobuf.js: Code injection in pbjs static output from crafted schema names
GHSA-6r35-46g8-jcw9
pkg: protobufjs-cli, protobufjs-cli
eco: npm
published: May 12, 2026
## Summary

`pbjs` static code generation could emit unsafe JavaScript identifiers derived from schema-controlled names. When generating static JavaScript from a crafted schema or JSON descriptor, certain namespace, enum, service, or derived full names could be written into the generated output with…

CVE-2026-44295
GitHub-GHSA

HIGH
Local Path Provisioner Vulnerable to HelperPod Template Injection
GHSA-7fxv-8wr2-mfc4
pkg: github.com/rancher/local-path-provisioner
eco: go
published: May 11, 2026
### Impact

A malicious user with permission to edit the `local-path-config` ConfigMap in the `local-path-storage` namespace can manipulate the `helperPod.yaml` template used by `rancher/local-path-provisioner`.

The `helperPod.yaml` template is loaded by the provisioner and used to create HelperPod…

CVE-2026-44543
NVD

HIGH
CVE-2026-42595
CVE-2026-42595
pkg: docker

published: May 14, 2026

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, Gotenberg's Chromium URL-to-PDF endpoint (/forms/chromium/convert/url) has no default protection against HTTP/HTTPS-based SSRF. The default deny-list regex only blocks file:// URIs. An unauthenticated attacker can point Chro…
CWE: CWE-918
NVD

HIGH
CVE-2026-44578
CVE-2026-44578
pkg: vercel next.js

published: May 13, 2026

Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket upgrade requests. An attacker can cause the server t…
CWE: CWE-918
NVD

HIGH
CVE-2026-44001
CVE-2026-44001
pkg: vm2_project vm2

published: May 13, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, a sandbox escape vulnerability in vm2 v3.10.5 allows any sandboxed code to crash the host Node.js process via a single Promise constructor that triggers an unhandled rejection propagating to the host. The fix for CVE-2026-22709 (v3.10.2)…
CWE: CWE-248
GitHub-GHSA

HIGH
Klever-Go MultiDataInterceptor has remote OOM via crafted compressed P2P payload
GHSA-87m7-qffr-542v
pkg: github.com/klever-io/klever-go
eco: go
published: May 13, 2026
## Summary

A remote, unauthenticated denial-of-service vulnerability in
`Batch.Decompress` (`data/batch/batch.go`) allows any peer that
participates in a topic served by `MultiDataInterceptor` to allocate
multi-gigabyte heaps on the receiving node from a sub-50 KiB gossip
payload. A single packet i…

CVE-2026-44697
GitHub-GHSA

HIGH
Next.js vulnerable to server-side request forgery in applications using WebSocket upgrades
GHSA-c4j6-fc7j-m34r
pkg: next, next
eco: npm
published: May 11, 2026
### Impact

Self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket upgrade requests. An attacker can cause the server to proxy requests to arbitrary internal or external destinations, which may expose internal services or…

CVE-2026-44578
GitHub-GHSA

HIGH
PraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables execute
GHSA-gmjg-hv98-qggq
pkg: praisonaiagents, PraisonAI
eco: pip
published: May 11, 2026
### Summary
`praisonaiagents` resolves unresolved tool names against module globals and `__main__` after it fails to match the declared tool list and the registry. With the default agent configuration, `_perm_allow` is `None`, so undeclared non-dangerous tool names are not rejected by the permission…
CVE-2026-44339
GitHub-GHSA

HIGH
Gotenberg: Server-Side Request Forgery via Chromium URL Endpoint with Redirect-Based Deny-List Bypass
GHSA-chwh-f6gm-r836
pkg: github.com/gotenberg/gotenberg/v8
eco: go
published: May 11, 2026
A review of 4 published Gotenberg security advisories exposed an SSRF issue. GHSA-pjrr-jgp4-v2fm covers SSRF via the `downloadFrom` endpoint. GHSA-pcrp-7g9h-7qhp covers SSRF via the `webhook` endpoint. Neither advisory addresses SSRF through the primary Chromium URL-to-PDF conversion endpoint (`/for…
CVE-2026-42595
GitHub-GHSA

HIGH
Open WebUI has a SSRF Bypass via HTTP Redirect Following in Web-Fetch and Image-Load Endpoints (not addressed by CVE-2025-65958)
GHSA-rh5x-h6pp-cjj6
pkg: open-webui
eco: pip
published: May 14, 2026
# Server-Side Request Forgery (SSRF) Bypass via HTTP Redirect Following in Web-Fetch, Image-Load, and Chat-Completion Endpoints

## Summary

The `validate_url()` function in `backend/open_webui/retrieval/web/utils.py` only validates the *initial* URL submitted by the caller. The HTTP clients used do…

CVE-2026-45401
GitHub-GHSA

HIGH
Open WebUI has a Server-Side Request Forgery (SSRF) bypass in `validate_url`
GHSA-8w7q-q5jp-jvgx
pkg: open-webui
eco: pip
published: May 14, 2026
### Summary
In the open-webui project, a parsing difference between the urlparse and requests libraries led to an SSRF bypass vulnerability.

### Details
In the current project, URL validation is performed using the function validate_url.

<img width="1323" height="1145" alt="QQ20260322-202854-22-1"…

CVE-2026-45400
GitHub-GHSA

HIGH
Open WebUI has a full SSRF Vulnerability in the RAG Web Search Feature
GHSA-4v7r-f4w8-8972
pkg: open-webui
eco: pip
published: May 14, 2026
# SSRF Bypass via IPv6/IPv4-mapped IPv6/IPv4-reserved-ranges in `validate_url()`

## Summary

`validate_url()` in `backend/open_webui/retrieval/web/utils.py` calls `validators.ipv6(ip, private=True)`, but the `validators` library does NOT implement the `private` keyword for IPv6 — the call raises …

CVE-2026-45331
GitHub-GHSA

HIGH
Portainer has a bind-mount restriction bypass via HostConfig.Mounts
GHSA-7fw3-x4r2-g7wc
pkg: github.com/portainer/portainer, github.com/portainer/portainer, github.com/portainer/portainer
eco: go
published: May 14, 2026
## Summary

Portainer offers an environment-level **Disable bind mounts for non-administrators** security setting that blocks regular users from binding host paths into containers they create through the Portainer-mediated Docker API. The check that enforces this setting only inspected the legacy `H…

CVE-2026-44850
NVD

HIGH
CVE-2026-43998
CVE-2026-43998
pkg: vm2_project vm2

published: May 13, 2026

vm2 is an open source vm/sandbox for Node.js. In 3.10.5, NodeVM's require.root path restriction can be bypassed using filesystem symlinks, allowing sandboxed code to load modules from outside the allowed root directory in host context. Because path validation uses path.resolve() (which does not dere…
CWE: CWE-59
GitHub-GHSA

HIGH
Nautobot: Webhook definitions could be used for server-side request forgery (SSRF)
GHSA-c35q-vxrp-ph26
pkg: nautobot, nautobot
eco: pip
published: May 13, 2026
### Impact

Nautobot's `Webhook` data model and associated feature set could be configured by users with sufficient access to perform requests to various hosts and IP addresses that should not be permitted, allowing for various behaviors similar to server-side request forgery (SSRF).

### Patches

F…

CVE-2026-44797
NVD

HIGH
CVE-2026-44015
CVE-2026-44015
pkg: nginxui nginx_ui

published: May 12, 2026

Nginx UI is a web user interface for the Nginx web server. In 2.3.4 and earlier, an authenticated user can perform Server-Side Request Forgery (SSRF) by creating a cluster node pointing to an arbitrary internal URL and then sending API requests with the X-Node-ID header. The Proxy middleware forward…
CWE: CWE-918
NVD

HIGH
CVE-2026-25705
CVE-2026-25705
pkg: node

published: May 13, 2026

A vulnerability has been identified in [Rancher's Extensions](https://ranchermanager.docs.rancher.com/integrations-in-rancher/rancher-extensions) where malicious code can be injected in Rancher through a path traversal in the `compressedEndpoint` field inside a `UIPlugin` deployment. A malicious UI …
CWE: CWE-35
NVD

HIGH
CVE-2026-45369
CVE-2026-45369
pkg: python

published: May 14, 2026

python-utcp is the python implementation of UTCP. Prior to 1.1.3, the _substitute_utcp_args method in cli_communication_protocol.py inserts user-controlled tool_args values directly into shell command strings without any sanitization or escaping. These commands are then executed via /bin/bash -c (Un…
CWE: CWE-78
NVD

HIGH
CVE-2026-8534
CVE-2026-8534
pkg: linux

published: May 14, 2026

Integer overflow in GPU in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-472
NVD

HIGH
CVE-2026-8533
CVE-2026-8533
pkg: go

published: May 14, 2026

Use after free in Accessibility in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-8530
CVE-2026-8530
pkg: go

published: May 14, 2026

Use after free in Network in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-8525
CVE-2026-8525
pkg: go

published: May 14, 2026

Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-122
NVD

HIGH
CVE-2026-8523
CVE-2026-8523
pkg: go

published: May 14, 2026

Use after free in Mojo in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-8520
CVE-2026-8520
pkg: go

published: May 14, 2026

Race in Payments in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-362
NVD

HIGH
CVE-2026-8515
CVE-2026-8515
pkg: go

published: May 14, 2026

Use after free in HID in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-8514
CVE-2026-8514
pkg: go

published: May 14, 2026

Use after free in Aura in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-8513
CVE-2026-8513
pkg: go

published: May 14, 2026

Use after free in Input in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-8512
CVE-2026-8512
pkg: go

published: May 14, 2026

Use after free in FileSystem in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-44586
CVE-2026-44586
pkg: node

published: May 14, 2026

SiYuan is an open-source personal knowledge management system. From 2.1.12 to before 3.7.0. SiYuan's Bazaar marketplace renders package author metadata from the public bazaar stage feed into HTML without escaping. In the desktop app this becomes stored XSS, and because SiYuan's Electron windows are …
CWE: CWE-79, CWE-94
NVD

HIGH
CVE-2026-42313
CVE-2026-42313
pkg: pyload-ng_project pyload-ng

published: May 11, 2026

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API method (@permission(Perms.SETTINGS)) in src/pyload/core/api/__init__.py gates security-sensitive options behind a hand-maintained allowlist ADMIN_ONLY_CORE_OPTIONS. The allowlist …
CWE: CWE-441, CWE-863, CWE-918
GitHub-GHSA

HIGH
Open WebUI has inconsistent authorization controls within memories API
GHSA-hmjq-crxp-7rjw
pkg: open-webui
eco: pip
published: May 11, 2026
### Summary

Authorization controls surrounding the memories API were inconsistent, resulting in the ability of a standard user to delete, restore, and view the contents of other users' memories.

### Details

Using a newly created non-admin user with no existing memories, it is possible to view ex…

CVE-2026-44570
GitHub-GHSA

HIGH
Open WebUI has a CORS misconfiguration and session validation issue
GHSA-6xcp-7mpr-m7wm
pkg: open-webui
eco: pip
published: May 11, 2026
# GitHub Security Lab (GHSL) Vulnerability Report, open-webui: `GHSL-2024-174`, `GHSL-2024-175`

The [GitHub Security Lab](https://securitylab.github.com) team has identified potential security vulnerabilities in [open-webui](https://github.com/open-webui/open-webui).

We are committed to working wi…

GitHub-GHSA

HIGH
@joplin/onenote-converter: Path traversal in OneNote importer allows overwriting arbitrary files
GHSA-gcmj-c9gg-9vh6
pkg: @joplin/onenote-converter
eco: npm
published: May 15, 2026
### Summary
A path traversal vulnerability in the OneNote importer allows overwriting arbitrary files on disk.

### Details
The OneNote converter does not sanitize the names of embedded files before writing them to disk. As a result, it's possible for an attacker to create a malicious `.one` file th…

CVE-2026-22810
GitHub-GHSA

HIGH
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in @ranfdev/deepobj
GHSA-x7q7-fchv-8h2j
pkg: @ranfdev/deepobj
eco: npm
published: May 14, 2026
### Impact
Prototype pollution is possible when property paths contain `__proto__`/`constructor`/`prototype`. The property path must not be exposed as user input.
CVE-2026-46509
NVD

HIGH
CVE-2026-42591
CVE-2026-42591
pkg: docker

published: May 14, 2026

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the LibreOffice conversion endpoint (/forms/libreoffice/convert) passes uploaded documents directly to LibreOffice without inspecting their content. LibreOffice then fetches any embedded external URLs on its own, completely …
CWE: CWE-918
NVD

HIGH
CVE-2026-42590
CVE-2026-42590
pkg: docker

published: May 14, 2026

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.30.0, The ExifTool metadata write blocklist in Gotenberg can be bypassed using ExifTool's group-prefix syntax, enabling arbitrary file rename, move, hardlink, and symlink creation on the server. ExifTool supports group-prefix synt…
CWE: CWE-184
NVD

HIGH
CVE-2026-40893
CVE-2026-40893
pkg: docker

published: May 14, 2026

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg only checks if the tag is exactly FileName, so System:FileName slips right through and ExifTool happily renames the file. This allows remote attackers to move, rename, and change permissions for arbitrary files. Th…
CWE: CWE-73, CWE-184
NVD

HIGH
CVE-2026-32992
CVE-2026-32992
pkg: ssl

published: May 13, 2026

SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and capture credentials.
CWE: CWE-295
GitHub-GHSA

HIGH
Anchor: Program<'info, System> is not properly validated
GHSA-c6rc-8jpp-2fgc
pkg: anchor-lang
eco: rust
published: May 13, 2026
### Summary
An logic error causes anchor programs to accept any program id when requiring the system program id, causing false assumptions resulting in potential arbitrary cpi in programs that invoke system program instructions.

### Details
In the TryFrom<&'a AccountInfo<'a>> implementation for Pro…

CVE-2026-45137
NVD

HIGH
CVE-2026-43929
CVE-2026-43929
pkg: node

published: May 12, 2026

ssrfcheck is a library that checks if a string contains a potential SSRF attack. In 1.3.0 and earlier, ssrfcheck fails to block Server-Side Request Forgery attacks when the target private IP address is encoded as an IPv4-mapped IPv6 address (e.g. http://[::ffff:127.0.0.1]/). The WHATWG URL parser bu…
CWE: CWE-184, CWE-918
GitHub-GHSA

HIGH
Dalfox Server Mode has an Unauthenticated Arbitrary File Create/Append via `output` Option
GHSA-8hf9-3q64-q2qf
pkg: github.com/hahwul/dalfox/v2
eco: go
published: May 12, 2026
## Summary

When dalfox is run in REST API server mode, the `output`, `output-all`, and `debug` fields in `model.Options` are JSON-tagged and deserialized directly from the attacker's request body, then propagated unchanged through `dalfox.Initialize` into the scan engine's logging path. The logger …

CVE-2026-45089
NVD

HIGH
CVE-2026-43893
CVE-2026-43893
pkg: node

published: May 11, 2026

exiftool-vendored provides cross-platform Node.js access to ExifTool. Prior to 35.19.0, exiftool-vendored starts ExifTool in -stay_open True -@ – mode, where arguments are read from stdin one per line. In affected versions, several caller-supplied strings were interpolated into ExifTool arguments wi…
CWE: CWE-88
NVD

HIGH
CVE-2026-43886
CVE-2026-43886
pkg: oauth

published: May 11, 2026

Outline is a service that allows for collaborative documentation. From 0.84.0 to 1.6.1, a logic error in OAuthInterface.validateScope() uses Array.some() to validate requested OAuth scopes, causing the function to accept the entire scope array if any single scope is valid. An attacker can smuggle th…
CWE: CWE-269
GitHub-GHSA

HIGH
@rvf/set-get has a prototype pollution issue that's reachable via @rvf/core preprocessFormData (HTTP form data)
GHSA-c567-44rc-m5hq
pkg: @rvf/set-get, @rvf/set-get
eco: npm
published: May 11, 2026
## Summary

`setPath` in `@rvf/set-get` (used by `@rvf/core` to flatten incoming form data into a nested object) does not block the keys `__proto__`, `constructor`, or `prototype` when walking a path. Because field names in submitted form data are passed directly to `setPath` via `preprocessFormData…

CVE-2026-44483
GitHub-GHSA

HIGH
GuardDog has a blind GitHub URL rewrite in remote project scanning causes SSRF and `GH_TOKEN` exfiltration
GHSA-587r-mc96-6f2p
pkg: guarddog
eco: pip
published: May 11, 2026
# Summary
The programmatic remote project scanning path rewrites attacker-controlled repository URLs using a blind string replacement and then sends the caller's GitHub credentials with the resulting request. This allows an attacker who can influence the scanned repository URL to trigger SSRF and ca…
CVE-2026-44971
NVD

HIGH
CVE-2026-45675
CVE-2026-45675
pkg: oauth

published: May 15, 2026

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, he LDAP and OAuth authentication flows use a TOCTOU (Time-of-Check-Time-of-Use) pattern for first-user admin role assignment. The regular signup handler (signup_handler in auths.py, lin…
CWE: CWE-269, CWE-362
GitHub-GHSA

HIGH
epa4all-client: TLS Certificate Validation Disabled in Production
GHSA-5hhf-xmfx-4vvr
pkg: com.oviva.telematik:epa4all-client
eco: maven
published: May 15, 2026
### Impact
An attacker on the network path between the ePA service and the Konnektor can present any TLS certificate (self-signed, expired, wrong CN) and intercept all SOAP traffic. This includes patient identifiers (KVNR), SMC-B card operations (authentication, signing),
document content, and crede…
CVE-2026-45574
GitHub-GHSA

HIGH
FrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP Files
GHSA-3g8v-8r37-cgjm
pkg: github.com/dunglas/frankenphp
eco: go
published: May 15, 2026
### Summary

The `splitPos()` function in [`cgi.go`](https://github.com/php/frankenphp/blob/main/cgi.go) misuses `golang.org/x/text/search` with `search.IgnoreCase` when the request path contains a non-ASCII byte. Two distinct flaws in that fallback let an attacker mislead FrankenPHP into treating a…

CVE-2026-45062
NVD

HIGH
CVE-2026-35194
CVE-2026-35194
pkg: express

published: May 15, 2026

Code injection in SQL code generation in Apache Flink 1.15.0 through 1.20.x and 2.0.0 through 2.x allows authenticated users with query submission privileges to execute arbitrary code on TaskManagers via maliciously crafted SQL queries. The vulnerability affects JSON functions (1.15.0+) and LIKE exp…
CWE: CWE-94
GitHub-GHSA

HIGH
Open WebUI: LDAP and OAuth First-User Race Condition Allows Multiple Admin Accounts
GHSA-h3ww-q6xx-w7x3
pkg: open-webui
eco: pip
published: May 14, 2026
## Summary

The LDAP and OAuth authentication flows use a TOCTOU (Time-of-Check-Time-of-Use) pattern for first-user admin role assignment. The regular signup handler (`signup_handler` in auths.py, line 663) was explicitly patched to prevent this race with the comment *"Insert with default role first…

CVE-2026-45675
GitHub-GHSA

HIGH
Open WebUI has Stored XSS in Banner Component via Improper Sanitization Order
GHSA-cqp4-qqvg-3787
pkg: open-webui
eco: npm
published: May 14, 2026
### Summary
A Stored Cross-Site Scripting (XSS) vulnerability exists in the Banner component due to an improper sanitization order (specifically, DOMPurify is executed before the marked library).

This vulnerability allows a compromised or malicious administrator to plant a malicious payload in the …

CVE-2026-45665
GitHub-GHSA

HIGH
Open WebUI: Cross-User File Access via Unchecked file_id in Folder Knowledge and Knowledge-Base Attach Endpoints
GHSA-r472-mw7m-967f
pkg: open-webui
eco: pip
published: May 14, 2026
# Cross-User File Access via Unchecked file_id in Folder Knowledge and Knowledge-Base Attach Endpoints

## Summary

Multiple endpoints accept a user-supplied `file_id` and attach the referenced file to a resource the caller controls (folder knowledge, knowledge-base contents) without verifying that …

CVE-2026-45402
GitHub-GHSA

HIGH
Open WebUI: Missing permission check in files API allows authenticated users to list, access and delete every uploaded file
GHSA-r8wh-8m7r-fh33
pkg: open-webui
eco: pip
published: May 14, 2026
### Summary
A missing permission check in all files related API endpoints allows any authenticated user to list, access and delete every file uploaded by every user to the platform.

### Details
All `files/` related endpoints lack permission checks.

#### Listing all files
For example, let's see how…

CVE-2026-45301
GitHub-GHSA

HIGH
Apostrophe has a Weak Password Recovery Mechanism for Forgotten Password and Improper Input Validation
GHSA-gf43-24g3-5hw2
pkg: apostrophe
eco: npm
published: May 14, 2026
## Summary

ApostropheCMS's password reset flow constructs the reset URL using `req.hostname`,
which is derived directly from the attacker-controlled HTTP `Host` header when
`apos.baseUrl` is not explicitly configured. An unauthenticated attacker who knows
a victim's email address can send a craf…

CVE-2026-45013
GitHub-GHSA

HIGH
go-billy has path traversal vulnerabilities
GHSA-qw64-3×98-g7q2
pkg: github.com/go-git/go-billy/v5, github.com/go-git/go-billy/v6
eco: go
published: May 14, 2026
### Impact
Multiple path traversal issues exist across different components of `go-billy`. Insufficient path sanitization and boundary enforcement may allow crafted paths (e.g., using `..`) to escape intended base directories.

While go-billy was not originally designed to provide a strong security …

CVE-2026-44973
GitHub-GHSA

HIGH
Portainer's Kubernetes middleware continues after token validation failure, bypassing endpoint authorization
GHSA-mgq6-4×29-88r3
pkg: github.com/portainer/portainer
eco: go
published: May 14, 2026
## Summary

Portainer proxies requests to Kubernetes clusters through a middleware layer (`kubeClientMiddleware`) that validates the requesting user's token before forwarding traffic to the cluster. When `security.RetrieveTokenData` returned an error, the middleware wrote an HTTP 403 response but wa…

CVE-2026-44882
GitHub-GHSA

HIGH
wger: Privilege escalation via trainer-login session chaining allows gym trainer to impersonate gym manager
GHSA-9qpr-vc49-hqg2
pkg: wger
eco: pip
published: May 14, 2026
### Summary
A gym trainer can escalate their session to any higher-privileged account (gym manager, general manager) by chaining two calls to the trainer-login endpoint. Once a trainer performs a legitimate switch into a low-privileged user, the session flag `trainer.identity`
is set and this flag a…
CVE-2026-43978
NVD

HIGH
CVE-2026-42602
CVE-2026-42602
pkg: jwt

published: May 13, 2026

azureauthextension is the Azure Authenticator Extension. From 0.124.0 to 0.150.0, a server-side authentication bypass in azureauthextension allows any party who holds a single valid Azure access token for any scope the collector's configured identity can mint for to authenticate to any OpenTelemetry…
CWE: CWE-208, CWE-287, CWE-290, CWE-294, CWE-347
NVD

HIGH
CVE-2026-44574
CVE-2026-44574
pkg: vercel next.js

published: May 13, 2026

Next.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applications that rely on middleware to protect dynamic routes can be vulnerable to authorization bypass. In affected deployments, specially crafted query parameters can alter the dynamic…
CWE: CWE-288
NVD

HIGH
CVE-2026-42945
CVE-2026-42945
pkg: express

published: May 13, 2026

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacemen…
CWE: CWE-122
NVD

HIGH
CVE-2026-44304
CVE-2026-44304
pkg: tls

published: May 12, 2026

Lemur manages TLS certificate creation. Prior to 1.9.0, Lemur's LDAP authentication module (lemur/auth/ldap.py) constructs LDAP search filters using unsanitized user input via Python string interpolation. An authenticated LDAP user can inject LDAP filter metacharacters through the username field to …
CWE: CWE-90
NVD

HIGH
CVE-2026-8430
CVE-2026-8430
pkg: nginx

published: May 12, 2026

SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the public space that is limited to certain nginx configurations, allowing attackers to execute arbitrary code in the context of the web server. Attackers can exploit this vulnerability through specific nginx configuratio…
CWE: CWE-94
GitHub-GHSA

HIGH
protobuf.js: Code generation gadget after prototype pollution
GHSA-75px-5xx7-5xc7
pkg: protobufjs, protobufjs
eco: npm
published: May 12, 2026
## Summary

protobufjs used plain objects with inherited prototypes for internal type lookup tables used by generated encode and decode functions. If `Object.prototype` had already been polluted, those lookup tables could resolve attacker-controlled inherited properties as valid protobuf type inform…

CVE-2026-44291
NVD

HIGH
CVE-2026-42315
CVE-2026-42315
pkg: pyload-ng_project pyload-ng

published: May 11, 2026

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, when passing a folder name in the set_package_data() API function call inside the data object with key "_folder", there is no sanitization at all, allowing a user with Perms.MODIFY to specify arbitrary dire…
CWE: CWE-22, CWE-36
GitHub-GHSA

HIGH
Open WebUI Arbitrary File Write, Delete via Path Traversal
GHSA-j3fw-wc48-29g3
pkg: open-webui
eco: pip
published: May 11, 2026
** CONFIDENTIAL **

Vulnerability Disclosure Analysis Documentation
———————————————–

Vulnerability Details
———————
1. Discoverer: Taylor Pennington of KoreLogic, Inc.
2. Date Submitted: June 11, 2024
3. Title: Open WebUI Arbitrary File Write, Delete via …

CVE-2026-44565
GitHub-GHSA

HIGH
Open WebUI: shared-chat branch ignores access_type, allowing unauthorized file deletion
GHSA-26g9-27vm-x3q8
pkg: open-webui
eco: pip
published: May 14, 2026
### Summary

Any authenticated user can permanently delete files owned by other users via `DELETE /api/v1/files/{id}` when the target file is referenced in any shared chat. The `has_access_to_file()` authorization gate unconditionally grants access through its shared-chat branch. It checks neither t…

CVE-2026-45671
NVD

HIGH
CVE-2026-34332
CVE-2026-34332
pkg: microsoft windows_server_2025

published: May 12, 2026

Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to execute code over a network.
CWE: CWE-416
GitHub-GHSA

HIGH
uniget is Vulnerable to Command Injection in tool.Check Leading to Arbitrary Code Execution
GHSA-qqq4-5773-pmw5
pkg: gitlab.com/uniget-org/cli
eco: go
published: May 13, 2026
I discovered a command injection vulnerability in uniget that allows arbitrary command execution through the metadata loading and version check mechanism.

### Summary

A command injection vulnerability exists in uniget due to unsafe execution of the `check` field from metadata files using `/bin/bas…

CVE-2026-45152
GitHub-GHSA

HIGH
Systeminformation vulnerable to Linux command injection in networkInterfaces() via unsanitized NetworkManager connection profile name
GHSA-hvx9-hwr7-wjj9
pkg: systeminformation
eco: npm
published: May 13, 2026
## Summary

On Linux, `systeminformation` is vulnerable to command injection in `networkInterfaces()` when an **active NetworkManager connection profile name** contains shell metacharacters.

This is not caused by a caller passing attacker-controlled arguments into `networkInterfaces()`. The vulnera…

CVE-2026-44724
NVD

HIGH
CVE-2026-35421
CVE-2026-35421
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Heap-based buffer overflow in Windows GDI allows an unauthorized attacker to execute code locally.
CWE: CWE-122
NVD

HIGH
CVE-2026-35420
CVE-2026-35420
pkg: microsoft windows_server_2012, microsoft windows_server_2016, microsoft windows_server_2019

published: May 12, 2026

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
CWE: CWE-122
NVD

HIGH
CVE-2026-35418
CVE-2026-35418
pkg: microsoft windows_10_1809, microsoft windows_10_21h2, microsoft windows_10_22h2

published: May 12, 2026

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
CWE: CWE-367, CWE-416
NVD

HIGH
CVE-2026-35417
CVE-2026-35417
pkg: microsoft windows_10_1809, microsoft windows_10_21h2, microsoft windows_10_22h2

published: May 12, 2026

Access of resource using incompatible type ('type confusion') in Windows Win32K – ICOMP allows an authorized attacker to elevate privileges locally.
CWE: CWE-843
NVD

HIGH
CVE-2026-35415
CVE-2026-35415
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Integer overflow or wraparound in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.
CWE: CWE-190
NVD

HIGH
CVE-2026-34351
CVE-2026-34351
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
CWE: CWE-362
NVD

HIGH
CVE-2026-34344
CVE-2026-34344
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CWE: CWE-843
NVD

HIGH
CVE-2026-34343
CVE-2026-34343
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Heap-based buffer overflow in Windows Application Identity (AppID) Subsystem allows an authorized attacker to elevate privileges locally.
CWE: CWE-122
NVD

HIGH
CVE-2026-34338
CVE-2026-34338
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CWE: CWE-416
NVD

HIGH
CVE-2026-34337
CVE-2026-34337
pkg: microsoft windows_10_1809, microsoft windows_10_21h2, microsoft windows_10_22h2

published: May 12, 2026

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
CWE: CWE-362, CWE-416
NVD

HIGH
CVE-2026-34336
CVE-2026-34336
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Buffer over-read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
CWE: CWE-126
NVD

HIGH
CVE-2026-34334
CVE-2026-34334
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
CWE: CWE-362
NVD

HIGH
CVE-2026-34333
CVE-2026-34333
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Use after free in Windows Win32K – GRFX allows an authorized attacker to elevate privileges locally.
CWE: CWE-190, CWE-416
NVD

HIGH
CVE-2026-34330
CVE-2026-34330
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Integer overflow or wraparound in Windows Win32K – GRFX allows an authorized attacker to elevate privileges locally.
CWE: CWE-190, CWE-416
NVD

HIGH
CVE-2026-33841
CVE-2026-33841
pkg: microsoft windows_10_21h2, microsoft windows_10_22h2, microsoft windows_11_23h2

published: May 12, 2026

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
CWE: CWE-122
NVD

HIGH
CVE-2026-33840
CVE-2026-33840
pkg: microsoft windows_11_24h2, microsoft windows_11_25h2, microsoft windows_11_26h1

published: May 12, 2026

Use after free in Windows Win32K – ICOMP allows an authorized attacker to elevate privileges locally.
CWE: CWE-416
NVD

HIGH
CVE-2026-33838
CVE-2026-33838
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Double free in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
CWE: CWE-415
NVD

HIGH
CVE-2026-33837
CVE-2026-33837
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Heap-based buffer overflow in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
CWE: CWE-122
NVD

HIGH
CVE-2026-33835
CVE-2026-33835
pkg: microsoft windows_10_1809, microsoft windows_10_21h2, microsoft windows_10_22h2

published: May 12, 2026

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
CWE: CWE-416
NVD

HIGH
CVE-2026-33834
CVE-2026-33834
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Improper access control in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.
CWE: CWE-284
NVD

HIGH
CVE-2026-20767
CVE-2026-20767
pkg: intel quickassist_technology

published: May 12, 2026

Improper input validation for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable escalation of privilege.…
CWE: CWE-20
NVD

HIGH
CVE-2026-20714
CVE-2026-20714
pkg: intel quickassist_technology

published: May 12, 2026

Out-of-bounds write for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable escalation of privilege. This r…
CWE: CWE-787
NVD

HIGH
CVE-2026-31221
CVE-2026-31221
pkg: lightningai pytorch_lightning

published: May 12, 2026

PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the securi…
CWE: CWE-502, CWE-502
GitHub-GHSA

HIGH
protobuf.js is Vulnerable to OS Command Injection in the CLI
GHSA-f84p-cvgm-xgjj
pkg: protobufjs-cli, protobufjs-cli
eco: npm
published: May 12, 2026
## Summary

`pbts` invoked JSDoc by building a shell command string from input file paths and executing it through `child_process.exec`. File paths containing shell metacharacters could therefore be interpreted by the shell instead of being passed to JSDoc as plain arguments.

## Impact

An attacker…

CVE-2026-42290
NVD

HIGH
CVE-2026-45338
CVE-2026-45338
pkg: oauth

published: May 15, 2026

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, a Server-Side Request Forgery (SSRF) vulnerability exists in _process_picture_url() in backend/open_webui/utils/oauth.py (line ~1338). The function fetches arbitrary URLs from OAuth pic…
CWE: CWE-918
GitHub-GHSA

HIGH
Budibase: SSRF Bypass via HTTP Redirect in REST Datasource Integration
GHSA-fgqv-jh4g-pvg2
pkg: @budibase/server
eco: npm
published: May 15, 2026
### Summary

The REST datasource integration follows HTTP redirects without re-checking the IP blacklist, allowing an authenticated Builder to access internal services (cloud metadata, databases) by redirecting through an attacker-controlled server. The same vulnerability class was already patched i…

CVE-2026-45715
GitHub-GHSA

HIGH
Budibase: SSRF in AI Extract File Automation Step via Missing IP Blacklist Validation
GHSA-rpj4-7x2v-wjrf
pkg: @budibase/server
eco: npm
published: May 15, 2026
## Vulnerability Details

**CWE-918**: Server-Side Request Forgery (SSRF)

The `processUrlFile` function in `packages/server/src/automations/steps/ai/extract.ts` uses `fetch(fileUrl)` directly **without the IP blacklist validation** that is consistently applied to all other automation steps. This al…

CVE-2026-45548
NVD

HIGH
CVE-2026-45370
CVE-2026-45370
pkg: python

published: May 14, 2026

python-utcp is the python implementation of UTCP. Prior to 1.1.3, _prepare_environment() in cli_communication_protocol.py passes a full copy of os.environ to every CLI subprocess. When combined with CVE-2026-45369, an attacker can exfiltrate all process-level secrets in a single tool call. This vuln…
CWE: CWE-526
GitHub-GHSA

HIGH
python-utcp: Full Process Environment Exposed to CLI Subprocess – Secrets Leakage via Command Injection
GHSA-5v57-8rxj-3p2r
pkg: utcp-cli
eco: pip
published: May 14, 2026
## Summary

`_prepare_environment()` in `cli_communication_protocol.py` passes a full copy of `os.environ` to every CLI subprocess. When combined with the Command Injection vulnerability (CWE-78) in `_substitute_utcp_args()` tracked as GHSA-33p6-5jxp-p3x4, an attacker can exfiltrate all process-leve…

CVE-2026-45370
GitHub-GHSA

HIGH
Open WebUI Vulnerable to SSRF via OAuth Profile Picture URL in _process_picture_url (oauth.py)
GHSA-24c9-2m8q-qhmh
pkg: open-webui
eco: pip
published: May 14, 2026
## Summary

A Server-Side Request Forgery (SSRF) vulnerability exists in `_process_picture_url()` in `backend/open_webui/utils/oauth.py` (line ~1338). The function fetches arbitrary URLs from OAuth `picture` claims without applying `validate_url()`, allowing an attacker to force the server to make H…

CVE-2026-45338
GitHub-GHSA

HIGH
Open WebUI has stored XSS via the HTML renedering view
GHSA-4vrc-m9ch-6m3r
pkg: open-webui
eco: pip
published: May 14, 2026
### Summary
Through the HTML rendering view, scripts can be injected and executed.
The finding resulted from a penetration test for a customer. It is suspected that the root cause of the issue lies within the core of Open WebUI, which is why it is being reported as a security issue here. Tested on …
CVE-2026-45303
NVD

HIGH
CVE-2026-42283
CVE-2026-42283
pkg: kubernetes

published: May 14, 2026

DevSpace is a client-only developer tool for cloud-native development with Kubernetes. Prior to 6.3.21, DevSpace's UI server WebSocket accepts connections from all origins by default, and therefore several endpoints are exposed via this WebSocket. When a developer runs the DevSpace UI and at the sam…
CWE: CWE-200, CWE-306
NVD

HIGH
CVE-2026-44738
CVE-2026-44738
pkg: getgrav grav

published: May 11, 2026

Grav is a file-based Web platform. Prior to 2.0.0-rc.2, the Twig sandbox allow-list permits any user with the admin.pages role to call config.toArray() from within a page body, dumping the entire merged site configuration — including all plugin secrets (SMTP passwords, AWS keys, OAuth client secre…
CWE: CWE-200
GitHub-GHSA

HIGH
Budibase vulnerable to SSRF via trivial `.tar.gz` substring bypass in Plugin URL upload (`/api/plugin`)
GHSA-xh5j-727m-w6gg
pkg: budibase
eco: npm
published: May 11, 2026
## 1. Summary

| Field | Value |
|——-|——-|
| **Title** | SSRF via trivial `.tar.gz` substring bypass in Plugin URL upload |
| **Product** | Budibase (Self-Hosted) |
| **Version** | ≤ 3.34.11 (latest stable as of 2026-03-30) |
| **Component** | `packages/server/src/api/controllers/plugin/ur…

CVE-2026-45061
GitHub-GHSA

HIGH
Apostrophe has authenticated SSRF in rich-text widget import via @apostrophecms/area/validate-widget
GHSA-pr28-mf3q-qpg6
pkg: apostrophe
eco: npm
published: May 14, 2026
### Summary
ApostropheCMS contains an authenticated server-side request forgery (SSRF) in the rich-text widget import flow. An authenticated user who can submit/edit rich-text widget content can cause the server to fetch attacker-controlled URLs during widget validation. For image-compatible respons…
CVE-2026-45012
GitHub-GHSA

HIGH
Valtimo has sensitive data exposure through HTTP request/response logging in LoggingRestClientCustomizer
GHSA-3jh5-rr2q-xfv7
pkg: com.ritense.valtimo:web, com.ritense.valtimo:web
eco: maven
published: May 11, 2026
### Summary

The `LoggingRestClientCustomizer` in the `web` module automatically intercepts all outgoing HTTP calls made via Spring's `RestClient` and logs the full request body, response body, and response headers. When an error response is received, this information is included in the thrown `Http…

CVE-2026-44516
NVD

HIGH
CVE-2021-47942
CVE-2021-47942
pkg: jwt

published: May 16, 2026

Home Assistant Community Store (HACS) 1.10.0 contains a path traversal vulnerability that allows unauthenticated attackers to read sensitive files by traversing directories via the /hacsfiles/ endpoint. Attackers can retrieve the .storage/auth file containing user credentials and refresh tokens, the…
CWE: CWE-22
NVD

HIGH
CVE-2026-46359
CVE-2026-46359
pkg: jwt

published: May 15, 2026

phpMyFAQ before 4.1.2 contains a sql injection vulnerability in CurrentUser::setTokenData that allows authenticated attackers to execute arbitrary SQL by injecting malicious OAuth token claims. Attackers with Azure AD accounts containing SQL metacharacters in display names or JWT claims can break ou…
CWE: CWE-89
GitHub-GHSA

HIGH
Pipecat: Path Traversal in Pipecat Runner `/files` Endpoint — Arbitrary File Read via `%2F`-Encoded Separator
GHSA-3363-2ph6-35wh
pkg: pipecat-ai
eco: pip
published: May 15, 2026
## Summary

A path traversal vulnerability exists in Pipecat's development runner (`src/pipecat/runner/run.py`). When the runner is started with the `–folder` flag, it exposes a `GET /files/{filename:path}` download endpoint. The `filename` path parameter is concatenated directly onto `args.folder`…

CVE-2026-44716
GitHub-GHSA

HIGH
nimiq-keys: Unchecked Ed25519 signature length in TaggedPublicKey::verify causes remote node panic via DHT
GHSA-27w2-87xv-37c6
pkg: nimiq-keys
eco: rust
published: May 15, 2026
### Impact
A malicious network peer can crash any Nimiq full node by publishing a crafted Kademlia DHT record containing a `TaggedSigned<ValidatorRecord, KeyPair>` with a signature field whose byte length is not exactly 64. When the victim node's DHT verifier calls `TaggedSigned::verify`, execution …
CVE-2026-40092
NVD

HIGH
CVE-2026-38728
CVE-2026-38728
pkg: node

published: May 15, 2026

An issue in Nodemailer smtp_server before v.3.18.3 allows a remote attacker to cause a denial of service via the SMTPStream._write, lib/smtp-stream.js components
CWE: CWE-400
GitHub-GHSA

HIGH
Open WebUI Vulnerable to IDOR: Retrieval API Bypasses Knowledge Base Access Controls
GHSA-4g37-7p2c-38r9
pkg: open-webui
eco: pip
published: May 14, 2026
# IDOR: Retrieval API Bypasses Knowledge Base Access Controls

**Author:** Andrew Orr <aorr@tenable.com>

## Summary

`_validate_collection_access()` ([PR #22109](https://github.com/open-webui/open-webui/pull/22109)) checks the `user-memory-*` and `file-*` collection name prefixes but does not check…

CVE-2026-45398
GitHub-GHSA

HIGH
Svelte devalue: DoS via sparse array deserialization
GHSA-77vg-94rm-hx3p
pkg: devalue
eco: npm
published: May 14, 2026
`devalue.parse` could, due to quirks in some JavaScript engines, be convinced to allocate much more memory than was needed when deserializing sparse arrays, leading to excessive memory consumption.
CVE-2026-42570
NVD

HIGH
CVE-2026-8521
CVE-2026-8521
pkg: go

published: May 14, 2026

Use after free in Tab Groups in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-8510
CVE-2026-8510
pkg: go

published: May 14, 2026

Integer overflow in Skia in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-472
NVD

HIGH
CVE-2026-23998
CVE-2026-23998
pkg: fleetdm fleet

published: May 14, 2026

Fleet is open source device management software. Prior to version 4.81.0, a vulnerability in Fleet’s Windows MDM management endpoint could allow requests to be processed without proper client certificate validation. In certain circumstances, this could allow an attacker to impersonate an enrolled …
CWE: CWE-295
NVD

HIGH
CVE-2026-42594
CVE-2026-42594
pkg: docker

published: May 14, 2026

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the webhook middleware spawns a goroutine that holds a reference to the request's echo.Context after the synchronous handler returns ErrAsyncProcess and Echo recycles the context back to its sync.Pool. When a concurrent requ…
CWE: CWE-362
GitHub-GHSA

HIGH
wger Vulnerable to IDOR: Authenticated Users Can Read Any User's Private Workout Session Data via Template Routine API
GHSA-cj9g-27ph-4cgv
pkg: wger
eco: pip
published: May 14, 2026
### Summary
Any authenticated user can read another user's private workout session notes, exercise history, and training statistics by calling the /logs/ and /stats/ actions on a routine they do not own.

The RoutinePermission class grants read access to any authenticated user when a routine has is…

CVE-2026-43977
GitHub-GHSA

HIGH
FlowiseAI Exposes Basic Auth Credentials via API
GHSA-php6-83fg-gw3g
pkg: flowise
eco: npm
published: May 14, 2026
**Detection Method:** Kolega.dev Deep Code Scan

| Attribute | Value |
|—|—|
| Severity | Medium |
| CWE | CWE-522 (Insufficiently Protected Credentials) |
| Location | packages/server/src/enterprise/controllers/account.controller.ts:128-135 |
| Practical Exploitability | Medium |
| Developer Ap…

CVE-2026-46440
NVD

HIGH
CVE-2026-6479
CVE-2026-6479
pkg: ssl

published: May 14, 2026

Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket. Versions before PostgreSQL 18.…
CWE: CWE-674
GitHub-GHSA

HIGH
Fleet has a Windows MDM management endpoint authentication bypass
GHSA-2rc4-7jc6-qffh
pkg: github.com/fleetdm/fleet/v4
eco: go
published: May 14, 2026
### Summary

A vulnerability in Fleet’s Windows MDM management endpoint could allow requests to be processed without proper client certificate validation. In certain circumstances, this could allow an attacker to impersonate an enrolled Windows device and retrieve sensitive configuration data.

##…

CVE-2026-23998
NVD

HIGH
CVE-2026-42561
CVE-2026-42561
pkg: python

published: May 13, 2026

Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.27, python-multipart has a denial of service vulnerability in multipart part header parsing. When parsing multipart/form-data, MultipartParser previously had no limit on the number of part headers or the size of an individual …
CWE: CWE-770
NVD

HIGH
CVE-2026-42304
CVE-2026-42304
pkg: react

published: May 13, 2026

Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 26.4.0rc2, the twisted.names module is vulnerable to a Denial of Service (DoS) attack via resource exhaustion during DNS name decompression. A remote, unauthenticated attacker can exploit this by sending …
CWE: CWE-400, CWE-407
NVD

HIGH
CVE-2026-42582
CVE-2026-42582
pkg: express

published: May 13, 2026

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final, when decoding header blocks, the non-Huffman branch of io.netty.handler.codec.http3.QpackDecoder#decodeHuffmanEncodedLiteral may execute new byte[length] for a string literal before verifying that length byt…
CWE: CWE-770, CWE-789
NVD

HIGH
CVE-2026-45109
CVE-2026-45109
pkg: vercel next.js

published: May 13, 2026

Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.18 and 16.2.6, it was found that the fix addressing CVE-2026-44575 did not apply to middleware.ts with Turbopack. This vulnerability is fixed in 15.5.18 and 16.2.6.
CWE: CWE-288
NVD

HIGH
CVE-2026-44579
CVE-2026-44579
pkg: vercel next.js

published: May 13, 2026

Next.js is a React framework for building full-stack web applications. From to before 15.5.16 and 16.2.5, applications using Partial Prerendering through the Cache Components feature can be vulnerable to connection exhaustion through crafted POST requests to a server action. In affected configurati…
CWE: CWE-770
NVD

HIGH
CVE-2026-44004
CVE-2026-44004
pkg: vm2_project vm2

published: May 13, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, sandboxed code can call Buffer.alloc() with an arbitrary size to allocate memory directly on the host heap. Because Buffer.alloc is a synchronous C++ native call, vm2's timeout option cannot interrupt it. A single request can exhaust hos…
CWE: CWE-770
NVD

HIGH
CVE-2026-44575
CVE-2026-44575
pkg: vercel next.js

published: May 13, 2026

Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Router applications that rely on middleware or proxy-based checks for authorization can allow unauthorized access through transport-specific route variants used for segment prefetchin…
CWE: CWE-288
NVD

HIGH
CVE-2026-44573
CVE-2026-44573
pkg: vercel next.js

published: May 13, 2026

Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authorization can allow unauthorized access to protected page data through locale-less /_next/data/<bui…
CWE: CWE-863
NVD

HIGH
CVE-2026-44432
CVE-2026-44432
pkg: python urllib3

published: May 13, 2026

urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the response was decompressed using the official Brotli library or (2) when HTTPResponse.dra…
CWE: CWE-409
NVD

HIGH
CVE-2026-42920
CVE-2026-42920
pkg: ssl

published: May 13, 2026

When a Client SSL profile is configured with Allow Dynamic Record Sizing on a UDP virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.
 Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CWE: CWE-835
NVD

HIGH
CVE-2026-40629
CVE-2026-40629
pkg: ssl

published: May 13, 2026

When SSL profiles are configured on a virtual server, undisclosed traffic can cause the virtual server to stop processing new client connections.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CWE: CWE-770
NVD

HIGH
CVE-2026-40618
CVE-2026-40618
pkg: ssl

published: May 13, 2026

When an SSL profile is configured on a virtual server on BIG-IP Virtual Edition (VE) without Intel QuickAssist Technology (QAT) or on BIG-IP hardware platforms with the database variable crypto.hwacceleration set to disabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to…
CWE: CWE-131
GitHub-GHSA

HIGH
SillyTavern: Existing sessions are not invalidated after password change, allowing session reuse and account takeover
GHSA-wmm3-h9qj-p5v6
pkg: sillytavern
eco: npm
published: May 12, 2026
### Summary
Changing a user’s password does not invalidate existing sessions, allowing an attacker with a stolen cookie to retain access even after the victim resets their password.

### Details
SillyTavern relies on cookie-session for authentication, storing all session data (user handle, permiss…

CVE-2026-44648
GitHub-GHSA

HIGH
esm.sh: Path Traversal via package.json browser field allows reading arbitrary server files
GHSA-rg65-45m7-hq57
pkg: github.com/esm-dev/esm.sh
eco: go
published: May 12, 2026
### Summary

A Local File Inclusion (LFI) vulnerability exists in the esbuild plugin's handling of the `browser` field in `package.json`. An attacker can publish an npm package that causes the server to read and return arbitrary files from the host filesystem during the build process.

### Details

CVE-2026-44594
NVD

HIGH
CVE-2026-44296
CVE-2026-44296
pkg: tls

published: May 12, 2026

Deskflow is a keyboard and mouse sharing app. Prior to 1.26.0.167, a remote, unauthenticated denial of service (DoS) vulnerability affects Deskflow servers running with TLS enabled (the default). When any TCP peer connects to the listening port and its first bytes do not parse as a valid TLS ClientH…
CWE: CWE-400, CWE-405
NVD

HIGH
CVE-2026-42544
CVE-2026-42544
pkg: python

published: May 12, 2026

Granian is a Rust HTTP server for Python applications. From 1.2.0 to 2.7.4, Granian aborts a worker process when an unauthenticated client sends a WebSocket upgrade request whose Sec-WebSocket-Protocol header contains non-ASCII bytes. The crash happens in Granian's WebSocket scope construction path,…
CWE: CWE-20, CWE-248, CWE-400
NVD

HIGH
CVE-2026-42268
CVE-2026-42268
pkg: owasp modsecurity

published: May 12, 2026

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 to before 3.0.15, there is an unhandled exception (std::out_of_range) caused by unsigned integer underflow in libmodsecurity3 if the user (administrator) uses a rule any of @veri…
CWE: CWE-191, CWE-248
NVD

HIGH
CVE-2026-44240
CVE-2026-44240
pkg: node

published: May 12, 2026

basic-ftp is an FTP client for Node.js. Prior to 5.3.1, basic-ftp is vulnerable to client-side denial of service when parsing FTP control-channel multiline responses. A malicious or compromised FTP server can send an unterminated multiline response during the initial FTP banner phase, before authent…
CWE: CWE-400, CWE-770
NVD

HIGH
CVE-2026-35424
CVE-2026-35424
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Missing release of memory after effective lifetime in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network.
CWE: CWE-401
NVD

HIGH
CVE-2026-32161
CVE-2026-32161
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Native WiFi Miniport Driver allows an unauthorized attacker to execute code over an adjacent network.
CWE: CWE-362, CWE-416
GitHub-GHSA

HIGH
Dalfox has an Unauthenticated Remote DoS via Closed-Channel Write in `ParameterAnalysis` (server mode)
GHSA-2g4x-fq3j-cgq4
pkg: github.com/hahwul/dalfox/v2
eco: go
published: May 12, 2026
## Summary

`ParameterAnalysis` in `pkg/scanning/parameterAnalysis.go` runs two sequential worker stages that both write to the same `results` channel. The channel is correctly closed after the first stage completes (`close(results)` at line 438), but the second stage — which processes POST-body p…

CVE-2026-45090
GitHub-GHSA

HIGH
Dalfox Server Mode has an Unauthenticated Arbitrary File Read with Out-of-Band Exfiltration via `custom-payload-file`
GHSA-35wr-x7v6-9fv2
pkg: github.com/hahwul/dalfox/v2
eco: go
published: May 12, 2026
## Summary

When dalfox is run in REST API server mode, the `custom-payload-file` field in `model.Options` is JSON-tagged and deserialized directly from the attacker's request body, then propagated unchanged through `dalfox.Initialize` into the scan engine. The engine passes the value to `voltFile.R…

CVE-2026-45088
GitHub-GHSA

HIGH
protobuf.js: Process-wide denial of service through unsafe option paths
GHSA-jvwf-75h9-cwgg
pkg: protobufjs, protobufjs
eco: npm
published: May 12, 2026
## Summary

protobufjs allowed certain schema option paths to traverse through inherited object properties while applying options. A crafted protobuf schema or JSON descriptor could cause option handling to write to properties on global JavaScript constructors, corrupting process-wide built-in funct…

CVE-2026-44290
GitHub-GHSA

HIGH
protobuf.js: Denial of service through unbounded protobuf recursion
GHSA-685m-2w69-288q
pkg: protobufjs, protobufjs
eco: npm
published: May 12, 2026
## Summary

protobufjs could recurse without a depth limit while decoding nested protobuf data. This affected both skipping unknown group fields and generated decoding of nested message fields.

A crafted protobuf binary payload could cause the JavaScript call stack to be exhausted during decoding.

CVE-2026-44289
NVD

HIGH
CVE-2026-8159
CVE-2026-8159
pkg: pillarjs multiparty

published: May 12, 2026

multiparty@4.2.3 and lower versions are vulnerable to denial of service via regular expression backtracking in the Content-Disposition filename parameter parser. A crafted multipart upload with a long header value can cause regex matching to take seconds, blocking the event loop. Impact: any service…
CWE: CWE-1333
GitHub-GHSA

HIGH
Kysely: JSON-path traversal injection via unsanitized path-leg metacharacters in `JSONPathBuilder.key()` / `.at()`
GHSA-pv5w-4p9q-p3v2
pkg: kysely
eco: npm
published: May 11, 2026
## Summary

Kysely 0.28.12 added a `sanitizeStringLiteral()` call inside `DefaultQueryCompiler.visitJSONPathLeg` (commit `0a602bf`, PR #1727) to fix CVE-2026-32763 (`GHSA-wmrf-hv6w-mr66`). The fix only doubles single quotes (`'` → `''`); it does **not** escape JSON-path metacharacters (`.`, `[`, `…

CVE-2026-44635
NVD

HIGH
CVE-2026-33359
CVE-2026-33359
pkg: windows

published: May 11, 2026

In Meari IoT Cloud alert image storage on Alibaba OSS (latest observed; storage service version not disclosed), motion snapshots are retrievable without authentication, signed URLs, or expiry enforcement. URLs function as direct object references and remain valid beyond expected operational windows.
CWE: CWE-862
GitHub-GHSA

HIGH
Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes – Incomplete Fix Follow-Up
GHSA-26hh-7cqf-hhc6
pkg: next, next
eco: npm
published: May 11, 2026
### Impact

It was found that the fix addressing [CVE-2026-44575](https://github.com/vercel/next.js/security/advisories/GHSA-267c-6grr-h53f) did not apply to `middleware.ts` with Turbopack. Refer to [CVE-2026-44575](https://github.com/vercel/next.js/security/advisories/GHSA-267c-6grr-h53f) for fur…

CVE-2026-45109
GitHub-GHSA

HIGH
Bird-lg-go has a Fatal Out-of-Memory (OOM) Denial of Service via Unbounded JSON Decoding
GHSA-39qr-rc93-vhqm
pkg: github.com/xddxdd/bird-lg-go
eco: go
published: May 11, 2026
### Summary
The `apiHandler` (and similarly `webHandlerTelegramBot`) processes user-provided JSON payloads by directly using `json.NewDecoder(r.Body).Decode(&request)` without restricting the maximum read size. An unauthenticated remote attacker can stream an extremely large, endless JSON payload (e…
CVE-2026-45047
GitHub-GHSA

HIGH
@theecryptochad/merge-guard has Prototype Pollution in its deepMerge() function
GHSA-mhwj-73qx-jqxm
pkg: @theecryptochad/merge-guard
eco: npm
published: May 11, 2026
## Summary

`@theecryptochad/merge-guard` versions prior to 1.0.1 are vulnerable to Prototype Pollution via the `deepMerge()` function. An attacker who controls the source object can inject `__proto__` keys that mutate `Object.prototype`, affecting all objects in the Node.js runtime.

## Details

Th…

GitHub-GHSA

HIGH
Next.js vulnerable to Denial of Service via connection exhaustion in applications using Cache Components
GHSA-mg66-mrh9-m8jx
pkg: next, next
eco: npm
published: May 11, 2026
### Impact

Applications using Partial Prerendering through the Cache Components feature can be vulnerable to connection exhaustion through crafted POST requests to a server action. In affected configurations, a malicious request can trigger a request-body handling deadlock that leaves connections o…

CVE-2026-44579
GitHub-GHSA

HIGH
Next.js has a Middleware / Proxy bypass in App Router applications via segment-prefetch routes
GHSA-267c-6grr-h53f
pkg: next, next
eco: npm
published: May 11, 2026
### Impact

App Router applications that rely on middleware or proxy-based checks for authorization can allow unauthorized access through transport-specific route variants used for segment prefetching. In affected configurations, specially crafted `.rsc` and segment-prefetch URLs can resolve to the …

CVE-2026-44575
GitHub-GHSA

HIGH
urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API
GHSA-mf9v-mfxr-j63j
pkg: urllib3
eco: pip
published: May 11, 2026
### Impact

urllib3's [streaming API](https://urllib3.readthedocs.io/en/2.7.0/advanced-usage.html#streaming-and-i-o) is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once.

urllib3 can perform…

CVE-2026-44432
GitHub-GHSA

HIGH
PraisonAI's symlink-extraction bypass of `_safe_extractall` writes outside `dest_dir`
GHSA-9q28-ghcr-c4x3
pkg: PraisonAI
eco: pip
published: May 11, 2026
### Summary
The `_safe_extractall` helper that all `recipe pull`, `recipe publish`, and `recipe unpack` flows route through validates each archive member's `name` for absolute paths, `..` segments, and resolved-path escape — but does **not** validate `member.linkname`, does not reject symlink/hard…
CVE-2026-44340
GitHub-GHSA

HIGH
Improper Verification of Cryptographic Signature in com.oviva.telematik:epa4all-client
GHSA-gqx7-6552-67hf
pkg: com.oviva.telematik:epa4all-client
eco: maven
published: May 15, 2026
### Impact
An attacker who can MITM the TLS connection between the client and the IDP (within the TI network) can substitute a forged discovery document. The forged document redirects u ri_puk_idp_enc and uri_puk_idp_sig to attacker-controlled URLs. The client then encrypts the SMC-B-signed challeng…
CVE-2026-45575
GitHub-GHSA

HIGH
goshs: SSH host key verification disabled, allowing transparent MITM of every tunnelled HTTP request
GHSA-mxg3-432p-mr72
pkg: goshs.de/goshs/v2
eco: go
published: May 15, 2026
### Summary

The `–tunnel` / `-t` flag opens an outbound SSH connection to `localhost.run:22` with `HostKeyCallback: ssh.InsecureIgnoreHostKey()`. The Go documentation for that function states verbatim: *"It should not be used for production code."* With the callback disabled the client accepts any…

GitHub-GHSA

HIGH
DeepSeek TUI has SSRF‌ IPV6 bypass
GHSA-88gh-2526-gfrr
pkg: deepseek-tui
eco: rust
published: May 14, 2026
### Summary
Although SSRF is validated against hostnames that resolve to private IPv6 addresses, when providing the IPV6 in‌‌ URL‌ as `http://[::1]`, the SSRF defenses do not work.

### Details
https://github.com/Hmbown/DeepSeek-TUI/blob/15f62e3e93d842f30b428877819ebc1c8cb96814/crates/tui/src/…

CVE-2026-45373
GitHub-GHSA

HIGH
DeepSeek TUI has SSRF via HTTP Redirect Bypass in fetch_url Tool
GHSA-96ff-gc8g-wpvg
pkg: deepseek-tui, deepseek-tui-cli, deepseek-tui
eco: npm
published: May 14, 2026
### Summary
The `fetch_url` tool validates the initial URL's resolved IP address against a restricted-IP blocklist (`is_restricted_ip()`) to prevent SSRF attacks against internal services (cloud metadata endpoints, localhost, private networks). However, the HTTP client (`reqwest`) is configured to a…
CVE-2026-45310
NVD

HIGH
CVE-2026-8759
CVE-2026-8759
pkg: express

published: May 17, 2026

A vulnerability was identified in xiandafu beetl up to 3.20.2. Affected is an unknown function of the file beetl-classic-integration/beetl-spring-classic/src/main/java/org/beetl/ext/spring/SpELFunction.java of the component SpELFunction. The manipulation leads to improper neutralization of special e…
CWE: CWE-20, CWE-917
GitHub-GHSA

HIGH
Better Auth: Rate limiter keys IPv6 addresses individually and is bypassable via prefix rotation
GHSA-p6v2-xcpg-h6xw
pkg: better-auth, better-auth
eco: npm
published: May 15, 2026
### Am I affected?

Users are affected if all of the following are true:

– Their app uses `better-auth` at a version `< 1.4.17`, or at a v1.5 prerelease tagged `<= 1.5.0-beta.8`.
– The apps authentication endpoints serve clients reachable over IPv6. Most managed hosts including Cloudflare, Vercel, …

CVE-2026-45364
GitHub-GHSA

HIGH
Open WebUI vulnerable to stored XSS via OAuth picture claim stored as SVG data URI in profile_image_url
GHSA-3wgj-c2hg-vm6q
pkg: open-webui
eco: pip
published: May 14, 2026
# Summary

When a user signs in via OAuth, Open WebUI fetches the `picture` claim URL, infers a MIME type from the URL extension via `mimetypes.guess_type`, and stores `data:<mime>;base64,…` as the user's profile image. The OAuth code path does not go through the `validate_profile_image_url` Pydan…

GitHub-GHSA

HIGH
Apostrophe has stored XSS via javascript: URL in Image Widget Link
GHSA-5f64-7vfc-rcx6
pkg: apostrophe
eco: npm
published: May 14, 2026
### Summary
A stored cross-site scripting vulnerability was identified in the image widget functionality. A user with the Editor role can configure an image widget link to use a javascript: URL payload.

Because editors have permission to publish pages, the malicious widget can be published to the l…

CVE-2026-45011
NVD

HIGH
CVE-2026-44995
CVE-2026-44995
pkg: openclaw openclaw

published: May 11, 2026

OpenClaw before 2026.4.20 contains an improper environment variable validation vulnerability in MCP stdio server configuration that allows attackers to execute arbitrary code. Malicious workspace configurations can pass dangerous startup variables like NODE_OPTIONS, LD_PRELOAD, or BASH_ENV to spawne…
CWE: CWE-829
NVD

HIGH
CVE-2026-31254
CVE-2026-31254
pkg: python

published: May 11, 2026

The flash-attention project thru commit e724e2588cbe754beb97cf7c011b5e7e34119e62 (2025-13-04) contains a code injection vulnerability (CWE-94) in its training script. The script registers the Python eval() function as a Hydra configuration resolver under the name eval. This allows configuration file…
CWE: CWE-95
NVD

HIGH
CVE-2026-31253
CVE-2026-31253
pkg: python

published: May 11, 2026

The flash-attention training framework thru commit e724e2588cbe754beb97cf7c011b5e7e34119e62 (2025-13-04) contains an insecure deserialization vulnerability (CWE-502) in its checkpoint loading mechanism. The load_checkpoint() function in checkpoint.py and the checkpoint loading code in eval.py use to…
CWE: CWE-94, CWE-502
NVD

HIGH
CVE-2026-31251
CVE-2026-31251
pkg: python

published: May 11, 2026

CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its gRPC server component. When the server starts, it loads the speech synthesis model from a user-specified directory using torch.load() without enabling the w…
CWE: CWE-20, CWE-94, CWE-915
NVD

HIGH
CVE-2026-31250
CVE-2026-31250
pkg: python

published: May 11, 2026

CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its average_model.py model averaging tool. The script loads PyTorch checkpoint files (epoch_*.pt) for model averaging using torch.load() without enabling the we…
CWE: CWE-502
NVD

HIGH
CVE-2026-31249
CVE-2026-31249
pkg: python

published: May 11, 2026

CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its make_parquet_list.py data processing tool. The script loads PyTorch .pt files (utterance embeddings, speaker embeddings, speech tokens) using torch.load() w…
CWE: CWE-502
GitHub-GHSA

HIGH
PraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow execution
GHSA-6rmh-7xcm-cpxj
pkg: PraisonAI
eco: pip
published: May 11, 2026
### Summary
PraisonAI ships a legacy Flask API server with authentication disabled by default. When that server is used, any caller that can reach it can access `/agents` and trigger the configured `agents.yaml` workflow through `/chat` without providing a token.

### Details
The vulnerable server i…

CVE-2026-44338
GitHub-GHSA

HIGH
Open WebUI: Missing `workspace.tools` Authorization Check on Tool Update Endpoint Allows Privilege Escalation to Code Execution
GHSA-p4fx-23fq-jfg6
pkg: open-webui
eco: npm
published: May 14, 2026
### Summary

The tool update endpoint (`POST /api/v1/tools/id/{id}/update`) is missing the `workspace.tools` permission check that is present on the tool create endpoint. This allows a user who has been explicitly **denied** tool management capabilities ( and who the administrator considers **untrus…

CVE-2026-45395
NVD

HIGH
CVE-2026-8597
CVE-2026-8597
pkg: python

published: May 14, 2026

Missing integrity verification in the Triton inference handler in Amazon SageMaker Python SDK v2 before v2.257.2 and v3 before v3.8.0 might allow a remote authenticated actor to achieve code execution in inference containers via replacement of model artifacts in S3 with a specially crafted pickle pa…
CWE: CWE-354
NVD

HIGH
CVE-2026-8596
CVE-2026-8596
pkg: python

published: May 14, 2026

Cleartext storage of sensitive information in the ModelBuilder/Serve component in Amazon SageMaker Python SDK before v2.257.2 and v3 before v3.8.0 might allow a remote authenticated actor to extract the HMAC signing key from SageMaker API responses and forge valid integrity signatures for specially …
CWE: CWE-312
GitHub-GHSA

HIGH
Open WebUI: Low-privilege authenticated users can enumerate and stop global background tasks, causing system-wide chat disruption
GHSA-8jjp-r2w2-4v22
pkg: open-webui
eco: pip
published: May 14, 2026
### Summary
Any authenticated user with low privileges can enumerate active background tasks across the system and stop tasks belonging to other users via the GET /api/tasks and POST /api/tasks/stop/{task_id} methods. This allows a casual user to disrupt system-wide chat usage by continuously cancel…
CVE-2026-45399
GitHub-GHSA

HIGH
Open WebUI's chat completion API allows tool restrictions to be bypassed
GHSA-4pcg-253r-rf9w
pkg: open-webui
eco: pip
published: May 14, 2026
### Summary
Open WebUI v0.6.43 contains a vulnerability in its chat completion API, which allows attackers to bypass tool restrictions, potentially enabling unauthorized actions or access.

### Details
In the [chat_completion](https://github.com/open-webui/open-webui/blob/a7271532f8a38da46785afcaa7…

CVE-2026-45350
GitHub-GHSA

HIGH
Open WebUI has Broken Access Control for Completions API
GHSA-gfm2-xm6c-37qc
pkg: open-webui
eco: pip
published: May 14, 2026
### Summary
Any user `X` can continue the conversation of any other user `Y`, as long as the Chat ID of `Y` is known. User `X` does not even need to be an admin to do so.

### Details
A user just needs to use the API endpoint: `/api/chat/completions` with their own API key (generated in OWUI) and t…

CVE-2026-45349
NVD

HIGH
CVE-2026-44637
CVE-2026-44637
pkg: saitoha libsixel

published: May 14, 2026

libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, a signed integer overflow in the SIXEL parser's image-buffer doubling loop can lead to an out-of-bounds heap write in sixel_decode_raw_impl. context->pos_x grows by repeat_count on every sixel character…
CWE: CWE-190, CWE-787, CWE-787
GitHub-GHSA

HIGH
Nautobot: GitRepository.current_head field should not be writable through REST API
GHSA-p3hx-pwf3-j8wr
pkg: nautobot, nautobot
eco: pip
published: May 13, 2026
### Impact

A user with access to add/change a GitRepository record could use the REST API to directly set the `current_head` field on the record, which was not intended to be user-editable. Doing so could cause Nautobot's local clone(s) of the relevant repository to checkout a commit other than the…

CVE-2026-44798
GitHub-GHSA

HIGH
LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning
GHSA-3644-q5cj-c5c7
pkg: langsmith, langsmith, langchain-classic
eco: npm
published: May 13, 2026
## Description

The LangSmith SDK's prompt pull methods (`pull_prompt` / `pull_prompt_commit` in Python, `pullPrompt` / `pullPromptCommit` in JS/TS) fetch and deserialize prompt manifests from the LangSmith Hub. These manifests may contain serialized LangChain objects and model configuration that af…

CVE-2026-45134
NVD

HIGH
CVE-2026-5371
CVE-2026-5371
pkg: oauth

published: May 12, 2026

The MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability checks on the get_ads_access_token() and reset_experience() functions in all versions up to, and i…
CWE: CWE-862
NVD

HIGH
CVE-2026-45226
CVE-2026-45226
pkg: node

published: May 12, 2026

Heym before 0.0.21 contains an authorization bypass vulnerability in workflow execution that allows authenticated users to execute arbitrary workflows by referencing victim workflow UUIDs without proper access validation. Attackers can create workflows with execute nodes or agent subWorkflowIds poin…
CWE: CWE-863
GitHub-GHSA

HIGH
Ella Core Vulnerable to UE Downlink Redirection via Forged PDUSessionResourceSetupResponse
GHSA-qfxw-v8qx-vj3v
pkg: github.com/ellanetworks/core
eco: go
published: May 11, 2026
## Summary

A radio with a valid NG Setup can send a forged PDUSessionResourceSetupResponse carrying any UE's AMF-UE-NGAP-ID. Ella Core does not verify the message arrived on the SCTP association bound to that UE's logical NG-connection, then creates a GTP tunnel towards that radio.

## Impact

Down…

CVE-2026-44473
GitHub-GHSA

HIGH
Open WebUI's Insecure Message Access Breaks Authorization
GHSA-jxwr-g6r6-j3fx
pkg: open-webui
eco: pip
published: May 11, 2026
### Description

There's an IDOR in the channels message management system that allows authenticated users to modify or delete any message within channels they have read access to. The vulnerability exists in the message update and delete endpoints, which implement channel-level authorization but co…

CVE-2026-44569
NVD

HIGH
CVE-2026-35416
CVE-2026-35416
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CWE: CWE-416
NVD

HIGH
CVE-2026-34347
CVE-2026-34347
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Use after free in Windows Win32K – GRFX allows an authorized attacker to elevate privileges locally.
CWE: CWE-416
NVD

HIGH
CVE-2026-34345
CVE-2026-34345
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CWE: CWE-362, CWE-416
NVD

HIGH
CVE-2026-34342
CVE-2026-34342
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.
CWE: CWE-362
NVD

HIGH
CVE-2026-34341
CVE-2026-34341
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Double free in Windows Link-Layer Discovery Protocol (LLDP) allows an authorized attacker to elevate privileges locally.
CWE: CWE-415
NVD

HIGH
CVE-2026-34340
CVE-2026-34340
pkg: microsoft windows_10_1809, microsoft windows_10_21h2, microsoft windows_10_22h2

published: May 12, 2026

Use after free in Windows Projected File System allows an authorized attacker to elevate privileges locally.
CWE: CWE-416
NVD

HIGH
CVE-2026-34331
CVE-2026-34331
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K – GRFX allows an authorized attacker to elevate privileges locally.
CWE: CWE-362, CWE-416
NVD

HIGH
CVE-2026-33839
CVE-2026-33839
pkg: microsoft windows_10_1809, microsoft windows_10_21h2, microsoft windows_10_22h2

published: May 12, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K – GRFX allows an authorized attacker to elevate privileges locally.
CWE: CWE-362
NVD

HIGH
CVE-2026-7818
CVE-2026-7818
pkg: python

published: May 11, 2026

Deserialization of untrusted data (CWE-502) in pgAdmin 4 FileBackedSessionManager.

The session manager performed unsafe deserialization of session-file contents (using Python's standard object-serialization module) before performing any HMAC integrity check. Any file dropped into the sessions direc…

CWE: CWE-502
GitHub-GHSA

HIGH
urllib3: Sensitive headers forwarded across origins in proxied low-level redirects
GHSA-qccp-gfcp-xxvc
pkg: urllib3
eco: pip
published: May 11, 2026
### Impact

When following cross-origin redirects for requests made using urllib3’s high-level APIs, such as `urllib3.request()`, `PoolManager.request()`, and `ProxyManager.request()`, sensitive headers — `Authorization`, `Cookie`, and `Proxy-Authorization` (defined in `Retry.DEFAULT_REMOVE_HEAD…

CVE-2026-44431
GitHub-GHSA

HIGH
Open WebUI has XSS via SVG in /api/v1/channels/webhooks/{webhook_id}/profile/image
GHSA-3856-3vxq-m6fc
pkg: open-webui
eco: pip
published: May 14, 2026
As part of our research on improving our [AI pentest](https://www.aikido.dev/attack/aipentest), we have uncovered the following issue in Open WebUI. We've manually verified and tided up the report, but you can also find the original agent finding at the bottom of this report.

### Summary

The chann…

CVE-2026-45314
GitHub-GHSA

HIGH
ethyca-fides has a DOM-based XSS vulnerability in fides.js via fides_description override
GHSA-5qrq-9645-g5g2
pkg: ethyca-fides
eco: pip
published: May 14, 2026
### Summary

`fides.js` is the script that renders Fides's consent banner on customer websites. It lets the embedding page override the banner's description text at runtime via a URL query parameter, a JavaScript global, or a cookie. On sites that have opted into HTML-formatted descriptions, the ove…

CVE-2026-44541
GitHub-GHSA

HIGH
Karakeep SDK has SSRF via metascraper-logo-favicon that bypasses validateUrl protections
GHSA-7rx4-c5vx-g8w3
pkg: @karakeep/sdk
eco: npm
published: May 14, 2026
## Summary

The `metascraper-logo-favicon` plugin makes HTTP requests to URLs extracted from attacker-controlled HTML without going through the application's `validateUrl()` SSRF protections. This allows any authenticated user to make the server fetch arbitrary internal URLs by bookmarking a page co…

GitHub-GHSA

HIGH
Portainer: JWT accepted in URL query leaks tokens to logs and referers
GHSA-jvp4-q659-95mj
pkg: github.com/portainer/portainer, github.com/portainer/portainer, github.com/portainer/portainer
eco: go
published: May 14, 2026
## Summary
Portainer's authentication middleware accepts JWT bearer tokens passed as the `?token=<JWT>` URL query parameter on any authenticated API endpoint, in addition to the standard `Authorization: Bearer` header. URLs are recorded in reverse-proxy access logs, browser history, and HTTP `Refere…
CVE-2026-44883
GitHub-GHSA

HIGH
Portainer Has an Arbitrary File Read via Git Symlink Injection in Stack Auto-Update
GHSA-rpgq-m5fp-32wr
pkg: github.com/portainer/portainer, github.com/portainer/portainer, github.com/portainer/portainer
eco: go
published: May 14, 2026
## Summary
Portainer supports deploying stacks from Git repositories. When a Git-backed stack is created or updated, Portainer clones the repository using `go-git` v5, which translates Git blob entries with mode `0o120000` (symlink) into real OS symlinks on the host filesystem via `os.Symlink`. The …
CVE-2026-44881
GitHub-GHSA

HIGH
FlowiseAI: Evaluator create+update mass-assignment allows cross-workspace evaluator takeover
GHSA-wxrr-jp8m-qq7f
pkg: flowise
eco: npm
published: May 14, 2026
## Summary

**Type:** Mass assignment via `Object.assign(entity, body)` -> client-controlled `workspaceId` (and on create, `id`) overwritten on the Evaluator entity -> cross-workspace data takeover and IDOR.
**File:** `packages/server/src/Interface.Evaluation.ts`
**Root cause:** The Evaluator contro…

CVE-2026-46480
GitHub-GHSA

HIGH
FlowiseAI: Evaluation create+update mass-assignment allows cross-workspace evaluation takeover
GHSA-mq53-pc65-wjc4
pkg: flowise
eco: npm
published: May 14, 2026
## Summary

**Type:** Mass assignment via `Object.assign(entity, body)` -> client-controlled `workspaceId` (and on create, `id`) overwritten on the Evaluation entity -> cross-workspace data takeover and IDOR.
**File:** `packages/server/src/services/evaluations/index.ts`
**Root cause:** The Evaluatio…

CVE-2026-46479
GitHub-GHSA

HIGH
FlowiseAI: DatasetRow create+update mass-assignment allows cross-workspace row takeover
GHSA-7j65-65cr-6644
pkg: flowise
eco: npm
published: May 14, 2026
## Summary

**Type:** Mass assignment via `Object.assign(entity, body)` -> client-controlled `workspaceId` (and on create, `id`) overwritten on the DatasetRow entity -> cross-workspace data takeover and IDOR.
**File:** `packages/server/src/services/dataset/index.ts`
**Root cause:** The DatasetRow co…

CVE-2026-46478
GitHub-GHSA

HIGH
FlowiseAI: Dataset create+update mass-assignment allows cross-workspace dataset takeover
GHSA-5h9v-837x-m97r
pkg: flowise
eco: npm
published: May 14, 2026
## Summary

**Type:** Mass assignment via `Object.assign(entity, body)` -> client-controlled `workspaceId` (and on create, `id`) overwritten on the Dataset entity -> cross-workspace data takeover and IDOR.
**File:** `packages/server/src/services/dataset/index.ts`
**Root cause:** The Dataset controll…

CVE-2026-46477
GitHub-GHSA

HIGH
FlowiseAI: CustomTemplate create+update mass-assignment allows cross-workspace template takeover
GHSA-728h-4mwj-f2p4
pkg: flowise
eco: npm
published: May 14, 2026
## Summary

**Type:** Mass assignment via `Object.assign(entity, body)` -> client-controlled `workspaceId` (and on create, `id`) overwritten on the CustomTemplate entity -> cross-workspace data takeover and IDOR.
**File:** `packages/server/src/services/marketplaces/index.ts`
**Root cause:** The Cust…

CVE-2026-46476
GitHub-GHSA

HIGH
FlowiseAI: Assistant create+update mass-assignment allows cross-workspace assistant takeover
GHSA-78pr-c5x5-jggc
pkg: flowise
eco: npm
published: May 14, 2026
## Summary

**Type:** Mass assignment via `Object.assign(entity, body)` -> client-controlled `workspaceId` (and on create, `id`) overwritten on the Assistant entity -> cross-workspace data takeover and IDOR.
**File:** `packages/server/src/services/assistants/index.ts`
**Root cause:** The Assistant c…

CVE-2026-46475
GitHub-GHSA

HIGH
FlowiseAI: Vector Store No Permission Checks
GHSA-hmg2-jjjx-jcp2
pkg: flowise
eco: npm
published: May 14, 2026
### FINDING 4: OpenAI Assistants Vector Store – No Auth on CRUD Operations
**Severity**: HIGH (CVSS ~8.1)
**Type**: CWE-306 (Missing Authentication for Critical Function)
**File**: `packages/server/src/routes/openai-assistants-vector-store/index.ts`

**Description**: ALL CRUD endpoints for OpenAI As…

CVE-2026-46444
GitHub-GHSA

HIGH
Synapse CPU starvation (Denial of Service)
GHSA-8q93-326v-3m7g
pkg: matrix-synapse
eco: pip
published: May 14, 2026
### Impact

Local authenticated users can cause Synapse to starve other requests of CPU and lead to other requests failing, causing other users to be denied service.

Homeservers that trust all their local users are not at risk.

### Patches

Update to Synapse 1.152.1 or later.

### Workarounds

If …

CVE-2026-45078
GitHub-GHSA

HIGH
n8n Has a Cross-user Authorization Bypass in Dynamic Credential OAuth Endpoints
GHSA-6h4j-wcr9-2vg7
pkg: n8n, n8n, n8n
eco: npm
published: May 14, 2026
## Impact
The OAuth1 and OAuth2 credential reconnect endpoints authorized access using `credential:read` rather than `credential:update`. An authenticated user with read-only access to a shared credential could initiate an OAuth reconnect flow and overwrite the stored token material for that credent…
CVE-2026-45732
GitHub-GHSA

HIGH
n8n Has a Source Control Pull SQL Injection
GHSA-mhrx-qhrj-673w
pkg: n8n, n8n, n8n
eco: npm
published: May 14, 2026
## Impact
An attacker with write access to the git repository connected to an n8n Source Control configuration could commit a malicious Data Table JSON file containing a crafted column name. When an administrator performed a Source Control Pull, n8n imported the file and could lead to SQL injection …
CVE-2026-44792
GitHub-GHSA

HIGH
FlowiseAI Vulnerable to Credential Data Leak
GHSA-7g73-99r4-m4mj
pkg: flowise
eco: npm
published: May 14, 2026
**Severity**: HIGH (CVSS ~7.5)
**Type**: CWE-200 (Exposure of Sensitive Information)
**File**: `packages/server/src/services/credentials/index.ts:62-71`

**Description**: When credentials are fetched with a `credentialName` filter parameter, the `encryptedData` field is NOT stripped from the respons…

CVE-2026-46443
GitHub-GHSA

HIGH
FlowiseAI has Mass Assignment in Assistant Update Endpoint that Allows Cross-Workspace Resource Reassignment
GHSA-hp26-q66v-q2w7
pkg: flowise
eco: npm
published: May 14, 2026
### Summary
A Mass Assignment vulnerability exists in the assistant update endpoint of FlowiseAI.

The endpoint allows authenticated users to modify server-controlled properties such as workspaceId, createdDate, and updatedDate when updating an assistant resource.

Due to missing server-side validat…

CVE-2026-46441
GitHub-GHSA

HIGH
Flowise has an MCP Security Bypass that Enables RCE
GHSA-m99r-2hxc-cp3q
pkg: flowise, flowise-components
eco: npm
published: May 14, 2026
## Summary
There are three bypass methods for the security limitations of the Flowise MCP feature, and attackers can execute arbitrary commands by combining these three methods

## Details

### 【Vulnerability one】The Docker build subcommand not being on the blocklist leads to remote code execu…

GitHub-GHSA

HIGH
FlowiseAI has Mass Assignment in Chatflow Update Endpoint that Allows Cross-Workspace AgentFlow Reassignment
GHSA-5wxp-qjgq-fx6m
pkg: flowise
eco: npm
published: May 14, 2026
### Summary
A Mass Assignment vulnerability exists in the chatflow update endpoint of FlowiseAI.

The endpoint allows clients to modify server-controlled properties such as deployed, isPublic, workspaceId, createdDate, and updatedDate when updating a chatflow object.

Due to missing server-side vali…

CVE-2026-42863
GitHub-GHSA

HIGH
FlowiseAI has Mass Assignment in Tool Update Endpoint that Allows Cross-Workspace Resource Reassignment
GHSA-x5v6-pj28-cwwm
pkg: flowise
eco: npm
published: May 14, 2026
### Summary
A Mass Assignment vulnerability exists in the tool update endpoint of FlowiseAI.

The endpoint allows authenticated users to modify server-controlled properties such as workspaceId, createdDate, and updatedDate when updating a tool resource.

Due to missing server-side validation and aut…

CVE-2026-42862
GitHub-GHSA

HIGH
FlowiseAI has Mass Assignment in Variable Update Endpoint that Allows Cross-Workspace Resource Reassignment
GHSA-6fw7-3q8r-m5vj
pkg: flowise
eco: npm
published: May 14, 2026
### Summary
A Mass Assignment vulnerability exists in the variable update endpoint of FlowiseAI.

The endpoint allows authenticated users to modify server-controlled properties such as workspaceId, createdDate, and updatedDate when updating a variable resource.

Due to missing server-side validation…

CVE-2026-42861
GitHub-GHSA

HIGH
Fleet server may terminate unexpectedly when handling certain gRPC requests
GHSA-x67p-9m2r-fxqv
pkg: github.com/fleetdm/fleet/v4
eco: go
published: May 14, 2026
### Summary

Fleet contained a denial-of-service (DoS) issue in the gRPC Launcher `PublishLogs` endpoint. In affected versions, certain unexpected input values were not handled gracefully, which could cause the Fleet server process to terminate while processing an authenticated request from an enrol…

CVE-2026-26062
GitHub-GHSA

HIGH
Fleet Windows MDM Azure AD JWT Authentication Bypass
GHSA-ffg9-j72f-j6xm
pkg: github.com/fleetdm/fleet/v4
eco: go
published: May 14, 2026
### Summary

A vulnerability in Fleet's Windows MDM enrollment flow allows authentication tokens from any Azure AD tenant to be accepted. Because Fleet validates JWT signatures using Microsoft's multi-tenant JWKS endpoint but does not enforce the `aud` (audience) or `iss` (issuer) claims, any Micros…

CVE-2026-24899
GitHub-GHSA

HIGH
SiYuan publish-mode Reader can mutate Conf and SQL index via 8 ungated APIs
GHSA-gmmv-4cc5-wr9r
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: May 13, 2026
### Summary

SiYuan publish-mode Reader can mutate Conf and SQL index via 8 ungated APIs

`POST /api/graph/getGraph`, `POST /api/graph/getLocalGraph`, `POST /api/sync/setSyncInterval`, `POST /api/storage/updateRecentDocViewTime`, `POST /api/storage/updateRecentDocCloseTime`, `POST /api/storage/updat…

CVE-2026-45371
GitHub-GHSA

HIGH
Anchor: `InterfaceAccount` allows account substitution between unexpected types
GHSA-429q-fhh4-r6hj
pkg: anchor-lang
eco: rust
published: May 13, 2026
### Impact
Any uses of `InterfaceAccount` allows another unexpected account type to be passed, after https://github.com/solana-foundation/anchor/pull/3837 disabled discriminator checking for this type.

The bug was originally reported and fixed in https://github.com/solana-foundation/anchor/pull/413…

GitHub-GHSA

HIGH
claude-code-cache-fix vulnerable to local code execution via Python triple-quote injection in tools/quota-statusline.sh
GHSA-g3xq-3gmv-qq8g
pkg: claude-code-cache-fix
eco: npm
published: May 13, 2026
## Summary

`tools/quota-statusline.sh` (introduced in v3.5.0) interpolates Claude Code's hook stdin payload directly into a Python triple-quoted string literal. A `'''` byte sequence in any user-controlled field of the payload closes the literal early and lets following bytes execute as Python in t…

CVE-2026-45136
GitHub-GHSA

HIGH
UltraJSON has a Memory Leak in ujson.dump() on Write Failure
GHSA-c38f-wx89-p2xg
pkg: ujson
eco: pip
published: May 12, 2026
### Summary

When `ujson.dump()` writes to a file-like object and the write operation raises an exception, the serialized JSON string object is not decremented, leaking memory. Each failed write operation leaks the full size of the serialized payload.

Code that uses `ujson.dumps()` rather than `ujs…

CVE-2026-44660
GitHub-GHSA

HIGH
protobuf.js: Code injection through bytes field defaults in generated toObject code
GHSA-66ff-xgx4-vchm
pkg: protobufjs, protobufjs
eco: npm
published: May 12, 2026
## Summary

protobufjs generated JavaScript for `toObject` conversion could include an unsafe expression derived from a schema-controlled `bytes` field default value. A crafted descriptor with a non-string default value for a `bytes` field could cause attacker-controlled code to be emitted into the …

CVE-2026-44293
GitHub-GHSA

HIGH
GitHub Copilot CLI: Nested Bare Repository Can Execute Arbitrary Commands via core.fsmonitor
GHSA-9ccr-r5hg-74gf
pkg: @github/copilot
eco: npm
published: May 11, 2026
## Summary

A security vulnerability has been identified in GitHub Copilot CLI where a malicious bare git repository nested inside a project directory can achieve arbitrary code execution when the agent performs git operations. By exploiting git's automatic bare repository discovery during directory…

CVE-2026-45033
GitHub-GHSA

HIGH
python-liquid: Absolute paths escape filesystem loader search path
GHSA-8p4x-wr7x-3788
pkg: python-liquid
eco: pip
published: May 11, 2026
### Impact
The built-in `FileSystemLoader` and `CachingFileSystemLoader` do not guard against reading files outside their search paths when given an absolute path to resolve. This allows malicious template authors to load and render arbitrary files via the `{% include %}` and `{% render %}` tags. Ta…
CVE-2026-45017
GitHub-GHSA

HIGH
go-git's improper parsing of specially crafted objects may lead to inconsistent interpretation compared to upstream Git
GHSA-389r-gv7p-r3rp
pkg: github.com/go-git/go-git/v6, github.com/go-git/go-git/v5
eco: go
published: May 11, 2026
### Impact
`go-git` may parse malformed Git objects in a way that differs from upstream Git. When `commit` or `tag` objects contain ambiguous or malformed headers, `go-git`’s decoded representation may expose values differently from how Git itself would interpret or reject the same object.

Additi…

CVE-2026-45022
GitHub-GHSA

HIGH
Dozzle's Cross-Site WebSocket Hijacking (CSWSH) on exec/attach endpointsbypasses authentication
GHSA-j643-x8pv-8m67
pkg: github.com/amir20/dozzle
eco: go
published: May 11, 2026
## Summary

The WebSocket upgrader for the `/exec` and `/attach` endpoints uses `CheckOrigin: func(r *http.Request) bool { return true }`, accepting upgrade requests from any origin. Combined with the JWT cookie using `SameSite: Lax`, this enables Cross-Site WebSocket Hijacking (CSWSH) — **even wh…

CVE-2026-44985
NVD

MEDIUM
CVE-2026-1322
CVE-2026-1322
pkg: gitlab gitlab

published: May 14, 2026

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.0 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with a read_api scoped OAuth application to create issues and add comments to issues in private projects due to …
CWE: CWE-840
NVD

MEDIUM
CVE-2026-44305
CVE-2026-44305
pkg: tls

published: May 12, 2026

Lemur manages TLS certificate creation. Prior to 1.9.0, when LDAP TLS is enabled (LDAP_USE_TLS = True), Lemur's LDAP authentication module unconditionally disables TLS certificate verification at the global ldap module level. This allows a man-in-the-middle attacker positioned between Lemur and the …
CWE: CWE-295
NVD

MEDIUM
CVE-2026-33603
CVE-2026-33603
pkg: tls

published: May 12, 2026

Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This requires that the attacker is able to position itself between Dovecot and the client connection. If successful, the attacker can eavesdrop communications between Dovecot and client…
CWE: CWE-99
NVD

MEDIUM
CVE-2026-43875
CVE-2026-43875
pkg: oauth

published: May 11, 2026

WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/MobileManager/oauth2.php completes an OAuth login by sending an HTTP 302 Location: oauth2Success.php?user=<email>&pass=<HASH> where <HASH> is the victim's stored password hash (md5(hash("whirlpool", sha1(passw…
CWE: CWE-598
NVD

MEDIUM
CVE-2026-42312
CVE-2026-42312
pkg: pyload-ng_project pyload-ng

published: May 11, 2026

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API method (@permission(Perms.SETTINGS)) in src/pyload/core/api/__init__.py gates security-sensitive options behind a hand-maintained allowlist ADMIN_ONLY_CORE_OPTIONS. The option ("g…
CWE: CWE-295, CWE-306, CWE-863
NVD

MEDIUM
CVE-2026-32170
CVE-2026-32170
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Double free in Windows Rich Text Edit Control allows an authorized attacker to elevate privileges locally.
CWE: CWE-415
NVD

MEDIUM
CVE-2026-21530
CVE-2026-21530
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.
CWE: CWE-415
NVD

MEDIUM
CVE-2026-20905
CVE-2026-20905
pkg: intel quickassist_technology

published: May 12, 2026

Improper input validation for some Intel(R) QAT software drivers for Windows before version 2.6 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result m…
CWE: CWE-20
NVD

MEDIUM
CVE-2026-20782
CVE-2026-20782
pkg: intel quickassist_technology

published: May 12, 2026

Buffer overflow for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potent…
CWE: CWE-120
NVD

MEDIUM
CVE-2026-20717
CVE-2026-20717
pkg: intel quickassist_technology

published: May 12, 2026

Improper input validation for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result …
CWE: CWE-20
NVD

MEDIUM
CVE-2026-39052
CVE-2026-39052
pkg: express

published: May 15, 2026

Oinone Pamirs 7.0.0 contains a code execution vulnerability via ScriptRunner. The method ScriptRunner.run(String expression, String type, Map<String, Object> context) evaluates attacker-controlled script expressions through the underlying script engine without sandboxing or allowlist restrictions.
CWE: CWE-94
GitHub-GHSA

MEDIUM
Open WebUI: Unauthenticated endpoint can trigger embedding generation (cost/DoS)
GHSA-m69w-p7m4-585j
pkg: open-webui
eco: pip
published: May 14, 2026
### Summary
GET `/api/v1/memories/ef` is accessible without authentication and executes `request.app.state.EMBEDDING_FUNCTION(…)`. This allows any unauthenticated caller to trigger embedding generation which can lead to direct cost exposure if a paid provider is used.
Code reference: `backend/open…
CVE-2026-45667
GitHub-GHSA

MEDIUM
Open WebUI has an Indirect Object Reference (IDOR) in user notes
GHSA-x3qm-p8hr-3c3h
pkg: open-webui
eco: pip
published: May 14, 2026
### Summary
The API /api/v1/notes/{note_id} endpoint lacks proper authorization checks, allowing authenticated users to retrieve notes belonging to other users by guessing or enumerating UUIDs. This results in unauthorized disclosure of potentially sensitive or private user data.

### Details
– if …

CVE-2026-45666
GitHub-GHSA

MEDIUM
Open WebUI Exposes System Prompt to Regular User [Non-Admin]
GHSA-jh9g-8jqw-m2qx
pkg: open-webui
eco: pip
published: May 14, 2026
### Summary
_A regular user [non-admin] can view the system prompt of the model which is set by an admin._

### Details
_When a regular user [non-admin] logs into the application, a http://IP:8080/api/models? web request is initiated by the application and in response, it reveals the system prompt o…

CVE-2026-45351
GitHub-GHSA

MEDIUM
Open WebUI missing authorization check at the model update function – models from other users can be updated
GHSA-gm54-m39w-grjp
pkg: open-webui
eco: pip
published: May 14, 2026
### Summary
A user can modify another user's model even if its visibility is set to `Private`.
The finding resulted from a penetration test for a customer. It is suspected that the root cause of the issue lies within the core of Open WebUI, which is why it is being reported as a security issue here.…
CVE-2026-45345
GitHub-GHSA

MEDIUM
Open WebUI's API key endpoint restrictions bypassed via `x-api-key` header — full message processing on restricted endpoints
GHSA-57q6-fvp4-pqmm
pkg: open-webu
eco: pip
published: May 14, 2026
### Summary

Open WebUI allows admins to restrict which API endpoints an API key can access. When an API key is restricted from `/api/v1/messages`, requests using the `Authorization: Bearer sk-…` header are correctly blocked with 403. However, the same key sent via the `x-api-key` header bypasses …

CVE-2026-45339
GitHub-GHSA

MEDIUM
pyLoad Has Incomplete Fix for CVE-2026-33509 -storage_folder Bypass via Session Directory in pyLoad
GHSA-w727-595x-pc3r
pkg: pyload-ng
eco: pip
published: May 14, 2026
## Summary
The fix for CVE-2026-33509 prevents setting `storage_folder` inside `PKGDIR` or `userdir`, but does NOT protect the Flask session directory (`/tmp/pyLoad/flask`). An authenticated attacker can set `storage_folder` to the session directory and download session files of other users via `/fi…
CVE-2026-45306
GitHub-GHSA

MEDIUM
Home Assistant MCP Server: YAML config backups written under www/ are served unauthenticated at /local/
GHSA-g39v-cvjh-8fpf
pkg: ha-mcp
eco: pip
published: May 14, 2026
### Summary

When `ENABLE_YAML_CONFIG_EDITING=true`, every `ha_config_set_yaml` call backs up the pre-edit file to `<config>/www/yaml_backups/`, which Home Assistant serves at `/local/` with **no authentication**. Anyone who can reach the HA web interface can download the most recent pre-edit `confi…

NVD

MEDIUM
CVE-2026-44514
CVE-2026-44514
pkg: kubernetes

published: May 14, 2026

Kubetail is a real-time logging dashboard for Kubernetes. Prior to 0.14.0, Kubetail's dashboard exposes WebSocket endpoints that did not adequately validate the Origin header on connection upgrade. A malicious web page visited by a user with an active Kubetail session could open a WebSocket to the u…
CWE: CWE-1385
GitHub-GHSA

MEDIUM
@apostrophecms/cli: Command Injection in apos create via Unsanitized Password Input
GHSA-hcwq-x9fw-8cfq
pkg: @apostrophecms/cli
eco: npm
published: May 14, 2026
Summary

The @apostrophecms/cli package contains a command injection vulnerability in the apos create command.
User-supplied input from the password prompt is embedded directly into a shell command without proper sanitization or escaping.
This allows execution of arbitrary commands on the host syste…

CVE-2026-42853
NVD

MEDIUM
CVE-2026-44000
CVE-2026-44000
pkg: vm2_project vm2

published: May 13, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, a sandbox boundary violation in vm2 allows host object identity to cross into the sandbox through host Promise resolution. When a host-side Promise that resolves to a host object is exposed to the sandbox, the value delivered to the sand…
CWE: CWE-693
NVD

MEDIUM
CVE-2026-42946
CVE-2026-42946
pkg: nginx

published: May 13, 2026

A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive memory allocation or an over-read of data. When scgi_pass or uwsgi_pass is configured, an unauthenticated attacker with man-in-the-middle (MITM) ability to control responses from an …
CWE: CWE-789, CWE-823
NVD

MEDIUM
CVE-2026-40460
CVE-2026-40460
pkg: nginx

published: May 13, 2026

When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluate…
CWE: CWE-290
GitHub-GHSA

MEDIUM
wger has an Uncontrolled Resource Consumption issue
GHSA-v25j-wqcw-fvhj
pkg: wger
eco: pip
published: May 13, 2026
### Summary

Any authenticated user can create a routine spanning an arbitrarily long date range (e.g. 100 years) and then trigger the `date_sequence` computation via any of the routine detail endpoints. The server iterates once per day in an unbounded `while` loop with no maximum duration validatio…

GitHub-GHSA

MEDIUM
Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS)
GHSA-qrpw-gjvh-x5gm
pkg: nautobot, nautobot
eco: pip
published: May 13, 2026
### Impact

Nautobot UI object-bulk-rename endpoints (for example, `/dcim/interfaces/rename/`) were vulnerable to application-wide denial of service via maliciously crafted regular expressions in the `find` field in combination with the `use_regex` flag.

### Patches

A general-purpose timeout has b…

CVE-2026-44796
GitHub-GHSA

MEDIUM
go-billy: Lack of depth and cycle detection in symlink resolution may lead to infinite loops and resource exhaustion
GHSA-m3xc-h892-ggx6
pkg: github.com/go-git/go-billy/v5, github.com/go-git/go-billy/v6
eco: go
published: May 13, 2026
### Impact
Multiple components may improperly handle crafted or malformed input, resulting in panics, infinite loops, uncontrolled recursion, or excessive resource consumption.

These issues arise from insufficient validation and missing safety mechanisms such as cycle detection, recursion limits, o…

CVE-2026-44740
NVD

MEDIUM
CVE-2026-8199
CVE-2026-8199
pkg: mongodb mongodb

published: May 13, 2026

An authenticated user can cause excess memory usage via bitwise match expression AST processing of $bitsAllSet, $bitsAnySet, $bitsAllClear, and $bitsAnyClear. This contributes to memory pressure and may lead to availability loss by OOM.

This issue impacts MongoDB Server v7.0 versions prior to 7.0.3…

CWE: CWE-1325
NVD

MEDIUM
CVE-2026-35422
CVE-2026-35422
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Authentication bypass using an alternate path or channel in Windows TCP/IP allows an authorized attacker to bypass a security feature over a network.
CWE: CWE-288
NVD

MEDIUM
CVE-2026-34350
CVE-2026-34350
pkg: microsoft windows_server_2025

published: May 12, 2026

Null pointer dereference in Windows Storport Miniport Driver allows an unauthorized attacker to deny service over a network.
CWE: CWE-476
GitHub-GHSA

MEDIUM
OpenClaude MCP OAuth Callback: State Check Bypass via error Param Leads to DoS
GHSA-c73c-x77g-854r
pkg: @gitlawb/openclaude
eco: npm
published: May 12, 2026
# OAuth State Validation Bypass via `error` Parameter Causes Local Server DoS in MCP Auth Callback

## Description

The OpenClaude MCP authentication flow starts a temporary local HTTP server to handle OAuth callbacks. To prevent CSRF attacks, the server validates a `state` parameter against an …

CVE-2026-42073
NVD

MEDIUM
CVE-2026-42314
CVE-2026-42314
pkg: pyload-ng_project pyload-ng

published: May 11, 2026

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, package folder names are sanitized using insufficient string replacement. The pattern ….// becomes .._ after replacement (partial removal), leaving .. which can be exploited when the path is later resolve…
CWE: CWE-22
NVD

MEDIUM
CVE-2026-7820
CVE-2026-7820
pkg: oauth

published: May 11, 2026

Improper restriction of excessive authentication attempts (CWE-307) in pgAdmin 4.

pgAdmin enforces MAX_LOGIN_ATTEMPTS only inside its custom /authenticate/login view. Flask-Security's default /login view, which is registered automatically by security.init_app() and is reachable on every server, nev…

CWE: CWE-307
GitHub-GHSA

MEDIUM
Streamlink has an arbitrary local file read via file:// URI in HLS and DASH
GHSA-hgqw-6m45-hw5f
pkg: streamlink
eco: pip
published: May 11, 2026
## Summary

Streamlink's HLS and DASH parsers do not validate the URI scheme of segment entries and other resources. A remote `.m3u8` HLS playlist or `.mpd` DASH manifest can list `file:///path/to/file` as a segment, and streamlink will read that local file and write its contents to the output strea…

CVE-2026-44353
GitHub-GHSA

MEDIUM
Open WebUI's Improper Authorization in Standard Channels Allows Message Updates with Read Permission
GHSA-jgj3-r8hr-9pjw
pkg: open-webui
eco: pip
published: May 11, 2026
## Vulnerability Description

In standard channels (i.e., channels whose `channel.type` is neither `group` nor `dm`), the endpoint

`POST /api/v1/channels/{channel_id}/messages/{message_id}/update` can be accessed with **read permission only**.

When `access_control` is set to `None`, the authorizat…

CVE-2026-44571
NVD

MEDIUM
CVE-2026-5361
CVE-2026-5361
pkg: express

published: May 14, 2026

The Envira Gallery Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST API in versions up to and including 1.12.4. This is due to insufficient input sanitization in the update_gallery_data() function and improper output escaping in the gallery_init() function. The san…
CWE: CWE-79
NVD

MEDIUM
CVE-2026-6962
CVE-2026-6962
pkg: go

published: May 13, 2026

The Cost of Goods: Product Cost & Profit Calculator for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'alg_wc_cog_product_cost' and 'alg_wc_cog_product_profit' shortcodes in all versions up to, and including, 4.1.0 due to insufficient input sanitizati…
CWE: CWE-79
GitHub-GHSA

MEDIUM
dbt MCP Server has an Argument Injection in dbt CLI Tool Wrappers via node_selection and resource_type Parameters
GHSA-xpww-f6pm-cfhq
pkg: dbt-mcp
eco: pip
published: May 14, 2026
*Discovered through manual source code review. Verified by PoC execution against a local dbt-mcp v1.15.1 installation.**

## Summary

`_run_dbt_command()` in `src/dbt_mcp/dbt_cli/tools.py` constructs the dbt subprocess argument list by appending user-supplied MCP tool parameters without sanitization…

CVE-2026-44968
NVD

MEDIUM
CVE-2026-33380
CVE-2026-33380
pkg: express

published: May 13, 2026

A vulnerability in SQL Expressions allows an authenticated attacker to read arbitrary files from the Grafana server's filesystem. Only instances with the sqlExpressions feature toggle enabled are vulnerable.
CWE: CWE-552
GitHub-GHSA

MEDIUM
Keylime has a hardcoded attestation challenge nonce that allows replay attacks
GHSA-q8w6-w55c-ccv5
pkg: keylime
eco: pip
published: May 11, 2026
## CVE-2026-6420: Hardcoded attestation challenge nonce allows replay attacks

### Impact

The `CertificationParameters.generate_challenge()` method in the push attestation protocol uses a hardcoded challenge nonce instead of generating a cryptographically random value. This removes the nonce-based …

CVE-2026-6420
GitHub-GHSA

MEDIUM
PraisonAI knowledge-store backends interpolate unvalidated collection names into SQL and CQL queries
GHSA-3643-7v76-5cj2
pkg: PraisonAI
eco: pip
published: May 11, 2026
### Summary
PraisonAI exposes optional SQL/CQL-backed knowledge-store implementations that build table and index identifiers from unvalidated `name` and `collection` arguments. Applications that pass untrusted collection names into these backends can trigger SQL or CQL injection.

### Details
This i…

CVE-2026-44337
GitHub-GHSA

MEDIUM
pyzipper has an encryption bypass for small files encrypted using it
GHSA-crqm-m339-7m2p
pkg: pyzipper
eco: pip
published: May 14, 2026
### Impact
A Python operator precedence bug in pyzipper/zipfile_aes.py caused the AE-2 format to never be automatically selected during encryption, regardless of file size or compression type. As a result, all encrypted entries are written in AE-1 format unless AE-2 is explicitly forced by the calle…
CVE-2026-44722
GitHub-GHSA

MEDIUM
Mistune TOC Anchor Injection XSS
GHSA-6269-cqxg-mhhv
pkg: mistune
eco: pip
published: May 14, 2026
## Summary
`render_toc_ul()` builds a `<ul>` table-of-contents tree from a list of `(level, id, text)` tuples. Both the `id` value (used as `href="#<id>"`) and the `text` value (used as the visible link label) are inserted into `<a>` tags via a plain Python format string — with no HTML escaping ap…
CVE-2026-44898
NVD

MEDIUM
CVE-2026-44580
CVE-2026-44580
pkg: vercel next.js

published: May 13, 2026

Next.js is a React framework for building full-stack web applications. From 13.0.0 to before 15.5.16 and 16.2.5, applications that use beforeInteractive scripts together with untrusted content can be vulnerable to cross-site scripting. In affected versions, serialized script content was not escaped …
CWE: CWE-79
GitHub-GHSA

MEDIUM
Authlib OIDC Implicit/Hybrid Authorization Vulnerable to Open Redirect
GHSA-r95x-qfjj-fjj2
pkg: authlib, authlib
eco: pip
published: May 13, 2026
### Summary

An unauthenticated open redirect in Authlib's `OpenIDImplicitGrant` and `OpenIDHybridGrant` authorization endpoint lets a remote attacker cause the authorization server to issue an HTTP 302 to an attacker-chosen URL by submitting an authorization request that omits the `openid` scope.

CVE-2026-44681
NVD

MEDIUM
CVE-2026-44245
CVE-2026-44245
pkg: vue

published: May 12, 2026

Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to 2.5.2, Vue 3's v-html directive is the framework-documented mechanism for injecting raw HTML, and it intentionally disables the auto-escaping that {{ }} interpolation provides. The PropertyCard.vue component us…
CWE: CWE-79
NVD

MEDIUM
CVE-2026-20771
CVE-2026-20771
pkg: intel quickassist_technology

published: May 12, 2026

Null pointer dereference for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result m…
CWE: CWE-476
NVD

MEDIUM
CVE-2026-7464
CVE-2026-7464
pkg: go

published: May 12, 2026

The WP Google Maps Integration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `page` parameter in all versions up to, and including, 1.2. This is due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject a…
CWE: CWE-79
GitHub-GHSA

MEDIUM
Next.js has cross-site scripting in beforeInteractive scripts with untrusted input
GHSA-gx5p-jg67-6x7h
pkg: next, next
eco: npm
published: May 11, 2026
### Impact

Applications that use `beforeInteractive` scripts together with untrusted content can be vulnerable to cross-site scripting. In affected versions, serialized script content was not escaped safely before being embedded into the document, which could allow attacker-controlled input to brea…

CVE-2026-44580
GitHub-GHSA

MEDIUM
Ella Core has a UE Security Capability bypass on NGAP PathSwitchRequest
GHSA-pwfh-mqp3-pqwj
pkg: github.com/ellanetworks/core
eco: go
published: May 11, 2026
## Summary

Ella Core does not verify the UE Security Capabilities received in NGAP PathSwitchRequest messages against its locally stored values. A malicious gNB can overwrite Ella Core's stored UE security capabilities for any UE with arbitrary values by sending a single crafted PathSwitchRequest.

CVE-2026-44475
NVD

MEDIUM
CVE-2026-42597
CVE-2026-42597
pkg: docker

published: May 14, 2026

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the /forms/chromium/convert/url and /forms/chromium/screenshot/url routes accept url=file:///tmp/… from anonymous callers. The default Chromium deny-list intentionally exempts file:///tmp/ so HTML/Markdown routes can load …
CWE: CWE-73, CWE-918
NVD

MEDIUM
CVE-2026-44577
CVE-2026-44577
pkg: vercel next.js

published: May 13, 2026

Next.js is a React framework for building full-stack web applications. From 10.0.0 to before 15.5.16 and 16.2.5, when self-hosting Next.js with the default image loader, the Image Optimization API fetches local images entirely into memory without enforcing a maximum size limit. An attacker could cau…
CWE: CWE-770
NVD

MEDIUM
CVE-2026-6253
CVE-2026-6253
pkg: haxx curl

published: May 13, 2026

curl might erroneously pass on credentials for a first proxy to a second
proxy.

This can happen when the following conditions are true:

1. curl is setup to use specific different proxies for different URL schemes
2. the first proxy needs credentials
3. the second proxy uses no credentials
4. while…

CWE: CWE-522
NVD

MEDIUM
CVE-2026-4873
CVE-2026-4873
pkg: haxx curl

published: May 13, 2026

A vulnerability exists where a connection requiring TLS incorrectly reuses an
existing unencrypted connection from the same connection pool. If an initial
transfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request
to that same host bypasses the TLS requirement and instead transmi…
CWE: CWE-295, CWE-319
NVD

MEDIUM
CVE-2026-42545
CVE-2026-42545
pkg: python

published: May 12, 2026

Granian is a Rust HTTP server for Python applications. From 0.2.0 to 2.7.4, Granian aborts a worker process if a WSGI application returns an invalid HTTP response header name or value. The WSGI response conversion path uses .unwrap() on both the header name and header value constructors, so malforme…
CWE: CWE-248, CWE-755
GitHub-GHSA

MEDIUM
Next.js has a Denial of Service in the Image Optimization API
GHSA-h64f-5h5j-jqjh
pkg: next, next
eco: npm
published: May 11, 2026
### Impact

When self-hosting Next.js with the default image loader, the Image Optimization API fetches local images entirely into memory without enforcing a maximum size limit. An attacker could cause out-of-memory conditions by requesting large local assets from the `/_next/image` endpoint that ma…

CVE-2026-44577
NVD

MEDIUM
CVE-2026-44312
CVE-2026-44312
pkg: openssl

published: May 14, 2026

css_parser is a Ruby CSS parser. Prior to 2.1.0 and 1.22.0, the CSS Parser gem does not validate HTTPS connections, allowing a Man-in-the-Middle (MITM) attacker to inject or modify CSS content when stylesheets are loaded via HTTPS. The connection is established with OpenSSL::SSL::VERIFY_NONE, meanin…
CWE: CWE-295, CWE-829
NVD

MEDIUM
CVE-2026-44002
CVE-2026-44002
pkg: vm2_project vm2

published: May 13, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, vm2's CallSite wrapper class (intended as a safe wrapper for V8's native CallSite) blocks getThis() and getFunction() to prevent host object leakage, but allows getFileName() to return unsanitized host absolute paths. Any sandboxed code …
CWE: CWE-209
NVD

MEDIUM
CVE-2026-42926
CVE-2026-42926
pkg: nginx

published: May 13, 2026

When NGINX Open Source is configured to proxy HTTP/2 traffic by setting proxy_http_version to 2, and also uses proxy_set_body, an attacker may be able to inject frame headers and payload bytes to the upstream peer.  Note: Software versions which have reached End of Technical Support (EoTS) are not…
CWE: CWE-172
NVD

MEDIUM
CVE-2026-44347
CVE-2026-44347
pkg: warpgate_project warpgate

published: May 12, 2026

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.23.3, the SSO flow does not validate the state parameter, which makes it possible for an attacker to trick a user into logging into the attacker's account, possibly convincing them to perform sensitive actions on the …
CWE: CWE-352
NVD

MEDIUM
CVE-2026-44695
CVE-2026-44695
pkg: getoutline outline

published: May 11, 2026

Outline is a service that allows for collaborative documentation. Prior to 1.7.1, the Slack integration callback for GET /auth/slack.post accepts an unsigned, session-independent OAuth state value. A third party who can obtain a Slack OAuth code for the same Outline Slack client can make a logged-in…
CWE: CWE-352
NVD

MEDIUM
CVE-2026-31252
CVE-2026-31252
pkg: python

published: May 11, 2026

CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its model loading component. The framework uses torch.load() to load model weight files (e.g., llm.pt, flow.pt, hift.pt) without enabling the security-restricti…
CWE: CWE-94, CWE-915
GitHub-GHSA

MEDIUM
Microsoft APM: Windows absolute-path tar member overwrite during legacy-bundle probing in `apm install`
GHSA-mq5j-pw29-jcv3
pkg: apm-cli
eco: pip
published: May 15, 2026
### Summary

Microsoft APM contains a Windows-specific archive extraction boundary failure in the legacy-bundle probe used by `apm install <bundle>` on supported Python 3.10 and 3.11 runtimes. When `apm install` is given a local `.tar.gz` that is not recognized as a plugin-format bundle, APM probes …

CVE-2026-46383
NVD

MEDIUM
CVE-2026-46383
CVE-2026-46383
pkg: python

published: May 15, 2026

Microsoft APM is an open-source, community-driven dependency manager for AI agents. Prior to 0.13.0, Microsoft APM contains a Windows-specific archive extraction boundary failure in the legacy-bundle probe used by apm install <bundle> on supported Python 3.10 and 3.11 runtimes. When apm install is g…
CWE: CWE-22, CWE-73
GitHub-GHSA

MEDIUM
Portainer has a path traversal in backup archive extraction that allows arbitrary file write
GHSA-m8fg-67j7-cx4v
pkg: github.com/portainer/portainer
eco: go
published: May 14, 2026
### Summary
Portainer's backup restore feature accepts a `.tar.gz` archive and extracts it to a target directory on the server. The extraction function (`ExtractTarGz` in `api/archive/targz.go`) constructed output paths using `filepath.Clean(filepath.Join(outputDirPath, header.Name))`. This combinat…
CVE-2026-44885
NVD

MEDIUM
CVE-2026-35419
CVE-2026-35419
pkg: microsoft windows_11_24h2, microsoft windows_11_25h2, microsoft windows_11_26h1

published: May 12, 2026

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
CWE: CWE-125
NVD

MEDIUM
CVE-2026-34339
CVE-2026-34339
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Null pointer dereference in Windows LDAP – Lightweight Directory Access Protocol allows an authorized attacker to deny service locally.
CWE: CWE-476
NVD

MEDIUM
CVE-2026-20914
CVE-2026-20914
pkg: intel quickassist_technology

published: May 12, 2026

Null pointer dereference for some Intel(R) QAT software drivers for Windows before version 2.6.0 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result …
CWE: CWE-476
NVD

MEDIUM
CVE-2026-20881
CVE-2026-20881
pkg: intel quickassist_technology

published: May 12, 2026

Divide by zero for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potenti…
CWE: CWE-369
GitHub-GHSA

MEDIUM
Gryph Agents Payload Filter Fails to Strip Tool Payload for Sensitive Content
GHSA-f3jg-756w-gm35
pkg: github.com/safedep/gryph
eco: go
published: May 11, 2026
Gryph implements logging levels that determine what content is logged to a local sqlite database. The README incorrectly mentions that the default log level is minimal while it is standard. Source code review shows sensitive `file-write` content remains in the stored `payload` as `ContentPreview`, …
CVE-2026-45046
NVD

MEDIUM
CVE-2026-23695
CVE-2026-23695
pkg: vue

published: May 15, 2026

Cockpit CMS through version 2.14.0, patched in commit 72a83fc, contains a stored cross-site scripting vulnerability in the Set field type's Display template option, where the template string is processed by the $interpolate function using new Function() and rendered via Vue's v-html directive withou…
CWE: CWE-79
NVD

MEDIUM
CVE-2026-44429
CVE-2026-44429
pkg: lfprojects mcp_registry

published: May 14, 2026

The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.7, the public catalogue UI served at GET / (file internal/api/handlers/v0/ui_index.html) is vulnerable to stored cross-site scripting via the server.websiteUrl field of any published ser…
CWE: CWE-79, CWE-116
GitHub-GHSA

MEDIUM
Open WebUI: Mass Assignment via FeedbackForm extra=allow Allows Feedback User ID Spoofing and Evaluation Data Manipulation
GHSA-rjmp-vjf2-qf4g
pkg: open-webui
eco: pip
published: May 14, 2026
# Mass Assignment in Feedback Creation Allows User ID Spoofing and Evaluation Data Manipulation

## Summary

The `POST /api/v1/evaluations/feedback` endpoint in Open WebUI v0.9.2 is vulnerable to mass assignment via `FeedbackForm`, which uses `model_config = ConfigDict(extra='allow')`. Due to an ins…

CVE-2026-45396
GitHub-GHSA

MEDIUM
Open WebUI: Authenticated users can bypass model access control via exposed query parameter [AI-ASSISTED]
GHSA-v6qf-75pr-p96m
pkg: open-webui
eco: pip
published: May 14, 2026
### Summary

An internal-only bypass_filter parameter is exposed on the /openai/chat/completions and /ollama/api/chat HTTP endpoints via FastAPI query string binding, allowing any authenticated user to append ?bypass_filter=true and bypass model access control checks to invoke admin-restricted model…

CVE-2026-45365
GitHub-GHSA

MEDIUM
Open WebUI has stored XSS via unsanitized Office/Excel/DOCX file preview rendering ({@html} without DOMPurify)
GHSA-hcwp-82g6-8wxc
pkg: open-webui
eco: pip
published: May 14, 2026
## Related advisory

This advisory tracks a regression of the original Excel-preview XSS that was
publicly disclosed and patched under [GHSA-jwf8-pv5p-vhmc](https://github.com/open-webui/open-webui/security/advisories/GHSA-jwf8-pv5p-vhmc)
(patched in v0.8.0). The same root cause — `XLSX.utils.sh…

CVE-2026-45318
GitHub-GHSA

MEDIUM
Open WebUI has Stored Cross-Site Scripting In Profile Picture
GHSA-6gh2-q7cp-9qf6
pkg: open-webui
eco: pip
published: May 14, 2026
## Summary

The `profile_image_url` field on the user profile update form accepted arbitrary `data:` URI values without MIME-type validation. Two distinct attack paths were independently demonstrated by separate reporters:

1. **`data:text/html;base64,…` in a new browser tab** (raresvis, 2025-04-1…

CVE-2026-45299
NVD

MEDIUM
CVE-2026-43644
CVE-2026-43644
pkg: go

published: May 14, 2026

podinfo through 6.11.2 contains a reflected cross-site scripting vulnerability in the /echo and /api/echo endpoints where the echoHandler writes request body content directly to the response without setting explicit Content-Type or X-Content-Type-Options headers. Attackers can craft cross-origin HTM…
CWE: CWE-79
NVD

MEDIUM
CVE-2026-3829
CVE-2026-3829
pkg: ssl

published: May 14, 2026

The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the 'wple_basic_get_requests' function in all versions up to, and including, 7.8.5.10. This mak…
CWE: CWE-862
NVD

MEDIUM
CVE-2026-45228
CVE-2026-45228
pkg: vue

published: May 13, 2026

Quark Drive before 0.8.5 contains a stored cross-site scripting vulnerability in the System Configuration page where the template renders push_config key names using Vue.js's v-html directive without escaping. Authenticated attackers can inject HTML or JavaScript payloads as key names through the PO…
CWE: CWE-79
NVD

MEDIUM
CVE-2026-44576
CVE-2026-44576
pkg: vercel next.js

published: May 13, 2026

Next.js is a React framework for building full-stack web applications. From 14.2.0 to before 15.5.16 and 16.2.5, applications using React Server Components can be vulnerable to cache poisoning when shared caches do not correctly partition response variants. Under affected conditions, an attacker can…
CWE: CWE-436
GitHub-GHSA

MEDIUM
Nautobot: REST API permits creation of GenericForeignKey references to objects that the user should not be able to reference
GHSA-wpxj-44w3-2j6x
pkg: nautobot, nautobot
eco: pip
published: May 13, 2026
### Impact

In the case of inter-object references via `GenericForeignKey` (a pattern allowing an object to reference another object that may belong to one of several different "content types" or database tables), when creating or updating an object containing a `GenericForeignKey`, Nautobot's REST …

CVE-2026-44794
NVD

MEDIUM
CVE-2026-43879
CVE-2026-43879
pkg: curl

published: May 11, 2026

WWBN AVideo is an open source video platform. In versions up to and including 29.0, an authenticated user can configure their own donation-notification webhook URL to point at internal/loopback/metadata hosts (e.g. http://127.0.0.1:8080/…, http://169.254.169.254/latest/…, RFC1918 addresses). Whe…
CWE: CWE-918
GitHub-GHSA

MEDIUM
Next.js vulnerable to cache poisoning in React Server Component responses
GHSA-wfc6-r584-vfw7
pkg: next, next
eco: npm
published: May 11, 2026
### Impact

Applications using React Server Components can be vulnerable to cache poisoning when shared caches do not correctly partition response variants. Under affected conditions, an attacker can cause an RSC response to be served from the original URL and poison shared cache entries so later vi…

CVE-2026-44576
NVD

MEDIUM
CVE-2026-8723
CVE-2026-8723
pkg: node

published: May 17, 2026

### Summary

`qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is synchronous and not handled by any of qs's null-related options (`skipNulls`, `strictNullHandling`).

### Details

In t…

CWE: CWE-476
GitHub-GHSA

MEDIUM
Better Auth: OAuth callback accepts mismatched `state` when cookie-backed state storage is used without PKCE
GHSA-wxw3-q3m9-c3jr
pkg: better-auth
eco: npm
published: May 15, 2026
### Am I affected?

Users are affected if all of the following are true:

– The application uses `better-auth` at a version below `1.6.2` (or `@better-auth/sso` paired with such a version).
– `betterAuth({ account: { storeStateStrategy } })` is set to `"cookie"`. The default `"database"` is not affe…

GitHub-GHSA

MEDIUM
Open WebUI Vulnerable to Unauthenticated RAG Configuration Disclosure
GHSA-65pg-qhhw-mxwg
pkg: open-webui
eco: pip
published: May 14, 2026
**Vulnerability Type:** Information Disclosure / Missing Authentication
**Severity:** Medium
**Component:** `backend/open_webui/routers/retrieval.py` — `get_status()` (`GET /`)
**Affected Endpoint:** `GET /api/v1/retrieval/`
**Affected Version:** Open WebUI `main` branch — confirmed unpa…
CVE-2026-45397
NVD

MEDIUM
CVE-2026-8535
CVE-2026-8535
pkg: linux

published: May 14, 2026

Out of bounds read in Media in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted JPEG file. (Chromium security severity: High)
CWE: CWE-125
NVD

MEDIUM
CVE-2026-8516
CVE-2026-8516
pkg: go

published: May 14, 2026

Insufficient validation of untrusted input in DataTransfer in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: C…
CWE: CWE-20
NVD

MEDIUM
CVE-2025-64526
CVE-2025-64526
pkg: strapi strapi

published: May 14, 2026

Strapi is an open source headless content management system. In Strapi versions prior to 5.45.0, the rate-limit middleware in the users-permissions plugin derived its rate-limit key in part from `ctx.request.body.email`, including on routes whose body schema does not contain an `email` field (`/auth…
CWE: CWE-307
GitHub-GHSA

MEDIUM
OpenTelemetry Java SDK has Unbounded Memory Allocation in W3C Baggage Propagation
GHSA-rcgg-9c38-7xpx
pkg: io.opentelemetry:opentelemetry-api, io.opentelemetry:opentelemetry-extension-trace-propagators
eco: maven
published: May 14, 2026
## Overview

A vulnerability affects the baggage propagation implementation in
`opentelemetry-api` and `opentelemetry-extension-trace-propagators`. Parsing oversized baggage
causes unbounded memory allocation and CPU consumption. Because baggage is automatically
re-injected into every outgoing reque…

CVE-2026-45292
NVD

MEDIUM
CVE-2026-42593
CVE-2026-42593
pkg: express

published: May 14, 2026

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, pdfengines/merge, pdfengines/split, libreoffice/convert, chromium/convert/url, chromium/convert/html, and chromium/convert/markdown accept stampSource=pdf + stampExpression=/path and watermarkSource=pdf + watermarkExpression…
CWE: CWE-22, CWE-73
NVD

MEDIUM
CVE-2026-42592
CVE-2026-42592
pkg: docker

published: May 14, 2026

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, FilterOutboundURL resolves the hostname, checks the resolved IPs against the private-address deny-list, and returns only the error. It discards the resolved addresses. Chromium later performs its own DNS resolution when it n…
CWE: CWE-367, CWE-918
GitHub-GHSA

MEDIUM
Fleet has a rate limiting bypass via untrusted client IP headers
GHSA-j8h8-75h3-jg53
pkg: github.com/fleetdm/fleet/v4
eco: go
published: May 14, 2026
### Impact

Fleet trusted client-supplied IP address headers when determining the source IP for incoming requests. This allowed authenticated and unauthenticated clients to spoof their apparent IP address and bypass per-IP rate limiting controls.

Fleet determines a client’s public IP address usin…

CVE-2026-24000
NVD

MEDIUM
CVE-2026-44003
CVE-2026-44003
pkg: vm2_project vm2

published: May 13, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, vm2's code transformer has a performance optimization that skips AST analysis when the code does not contain catch, import, or async keywords. This fast-path bypass allows sandboxed code to directly access the internal VM2_INTERNAL_STATE…
CWE: CWE-693
NVD

MEDIUM
CVE-2026-44431
CVE-2026-44431
pkg: python urllib3

published: May 13, 2026

urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(…, assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.
CWE: CWE-200
NVD

MEDIUM
CVE-2026-7009
CVE-2026-7009
pkg: haxx curl

published: May 13, 2026

When curl is told to use the Certificate Status Request TLS extension, often
referred to as *OCSP stapling*, to verify that the server certificate is
valid, it fails to detect OCSP problems and instead wrongly consider the
response as fine.
CWE: CWE-295
NVD

MEDIUM
CVE-2026-44341
CVE-2026-44341
pkg: go

published: May 12, 2026

GoJobs is a REST API for a Job Board platform. The application exposes a job retrieval endpoint that allows unauthenticated users to access job details by directly manipulating object identifiers. The endpoint lacks proper authentication and authorization checks, resulting in unauthorized access to …
CWE: CWE-284, CWE-639
NVD

MEDIUM
CVE-2026-42177
CVE-2026-42177
pkg: linux

published: May 12, 2026

linux-entra-sso is a browser plugin for Linux to SSO on Microsoft Entra ID. Prior to 1.8.1, platform/chrome/js/platform-chrome.js:69-88 registers a single declarativeNetRequest rule whose urlFilter is Platform.SSO_URL + "/*", i.e. "https://login.microsoftonline.com/*". Chrome's urlFilter without a |…
CWE: CWE-284, CWE-436
GitHub-GHSA

MEDIUM
protobuf.js: Denial of service from crafted field names in generated code
GHSA-2pr8-phx7-x9h3
pkg: protobufjs, protobufjs
eco: npm
published: May 12, 2026
## Summary

protobufjs generated JavaScript property accessors from schema-controlled field and oneof names. Certain control characters in field names were not escaped before being embedded into generated function bodies. A crafted schema or JSON descriptor could therefore cause generated encode, de…

CVE-2026-44294
GitHub-GHSA

MEDIUM
protobuf.js: Prototype injection in generated message constructors
GHSA-fx83-v9x8-x52w
pkg: protobufjs, protobufjs
eco: npm
published: May 12, 2026
## Summary

protobufjs generated message constructors copied enumerable properties from a provided properties object without filtering the `__proto__` key. If an application constructed a message from an attacker-controlled plain object, an own enumerable `__proto__` property could alter the prototy…

CVE-2026-44292
GitHub-GHSA

MEDIUM
protobufjs has overlong UTF-8 decoding
GHSA-q6x5-8v7m-xcrf
pkg: protobufjs, protobufjs, @protobufjs/utf8
eco: npm
published: May 12, 2026
## Summary

protobufjs includes a minimal UTF-8 decoder used in non-Node and fallback decoding paths. The affected decoder accepted overlong UTF-8 byte sequences and decoded them to their canonical characters instead of replacing them.

The issue concerns overlong encodings and code points outside t…

CVE-2026-44288
NVD

MEDIUM
CVE-2026-6402
CVE-2026-6402
pkg: webpack

published: May 12, 2026

webpack-dev-server versions up to and including 5.2.3 are vulnerable to cross-origin source code exposure when serving over a non-potentially trustworthy origin such as plain HTTP. The previous fix relied on the Sec-Fetch-Mode and Sec-Fetch-Site request headers, which browsers omit for non-trustwort…
CWE: CWE-749
NVD

MEDIUM
CVE-2026-44226
CVE-2026-44226
pkg: python

published: May 11, 2026

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, pyload-ng WebUI returns full Python traceback details to clients on unhandled exceptions. Because /web/<path:filename> is reachable without authentication and renders attacker-controlled template names, an …
CWE: CWE-209
GitHub-GHSA

MEDIUM
local-deep-research is Vulnerable to HTML Injection via Unescaped User Input in PDF Export (`pdf_service.py:_markdown_to_html`)
GHSA-fj2m-qvh9-jq4q
pkg: local-deep-research
eco: pip
published: May 11, 2026
## Summary

`PDFService._markdown_to_html()` constructs an HTML document by interpolating user-controlled values — specifically `title` (sourced from `research.title` or `research.query`) and `metadata` key-value pairs — directly into an f-string without any HTML escaping. An authenticated attac…

CVE-2026-43979
GitHub-GHSA

MEDIUM
GuardDog: Unsanitized human-readable scan output allows terminal escape injection from malicious package content
GHSA-m5p4-gvpx-4mvr
pkg: guarddog
eco: pip
published: May 11, 2026
# Summary
GuardDog includes attacker-controlled filenames, file locations, messages, and code snippets in its default human-readable output without escaping terminal control characters. A malicious package can therefore inject ANSI or OSC escape sequences into analyst terminals or CI logs.

# Descri…

CVE-2026-44972
NVD

MEDIUM
CVE-2026-42780
CVE-2026-42780
pkg: ssl

published: May 13, 2026

A directory traversal vulnerability exists in BIG-IP SSL Orchestrator that allows an authenticated attacker with high privilege to overwrite, delete or corrupt arbitrary local files.
 Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CWE: CWE-22
NVD

MEDIUM
CVE-2026-42876
CVE-2026-42876
pkg: kubernetes

published: May 11, 2026

External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Prior to 2.4.1, a user who only has permission to create ExternalSecret resources can cause the operator to create a Secret that Kubernetes will automatically populate w…
CWE: CWE-285
NVD

MEDIUM
CVE-2026-8367
CVE-2026-8367
pkg: tls

published: May 13, 2026

aria2c accepts a server certificate with incorrect Extended Key Usage (EKU). If the attackers compromise a certificate (with the associated private key) issued for a different purpose, they may be able to reuse it for TLS server authentication.
CWE: CWE-295
NVD

MEDIUM
CVE-2026-42934
CVE-2026-42934
pkg: nginx

published: May 13, 2026

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When charset, source_charset, and charset_map and proxy_pass with disabled buffering ("off") directives are configured, unauthenticated attackers can send requests that with conditions beyond the attackers…
CWE: CWE-125
NVD

MEDIUM
CVE-2026-40701
CVE-2026-40701
pkg: ssl

published: May 13, 2026

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured with a resolver. With this configuration, an unauthenticated …
CWE: CWE-416
NVD

MEDIUM
CVE-2026-44661
CVE-2026-44661
pkg: python

published: May 14, 2026

python-utcp is the python implementation of UTCP. Prior to 1.1.3, the utcp-http plugin is vulnerable to a blind Server-Side Request Forgery (SSRF) caused by a trust-boundary inconsistency between manual discovery and tool invocation. register_manual() validates the discovery URL against an HTTPS / l…
CWE: CWE-918
GitHub-GHSA

MEDIUM
@utcp/http: SSRF via attacker-controlled OpenAPI servers[0].url in HTTP communication protocol
GHSA-r8j5-8747-88cm
pkg: @utcp/http
eco: npm
published: May 14, 2026
## Summary

The `@utcp/http` package is vulnerable to a blind Server-Side Request Forgery (SSRF) caused by a trust-boundary inconsistency between manual discovery and tool invocation. `registerManual()` validates the discovery URL against an HTTPS / loopback allowlist, but `callTool()` reuses the re…

CVE-2026-45366
GitHub-GHSA

MEDIUM
Mistune Image Directive CSS Injection Vulnerability
GHSA-ccfx-mfmx-2fx9
pkg: mistune
eco: pip
published: May 14, 2026
## Summary
The Image directive plugin validates the `:width:` and `:height:` options with a regex compiled as `_num_re = re.compile(r"^\d+(?:\.\d*)?")`. This pattern is applied via `re.match()` (which anchors only at the **start** of the string, not the end). Any value that begins with one or more d…
CVE-2026-44899
NVD

MEDIUM
CVE-2026-44581
CVE-2026-44581
pkg: vercel next.js

published: May 13, 2026

Next.js is a React framework for building full-stack web applications. From 13.4.0 to before 15.5.16 and 16.2.5, App Router applications that rely on CSP nonces can be vulnerable to stored cross-site scripting when deployed behind shared caches. In affected versions, malformed nonce values derived f…
CWE: CWE-79
GitHub-GHSA

MEDIUM
Next.js vulnerable to cross-site scripting in App Router applications using CSP nonces
GHSA-ffhc-5mcf-pf4q
pkg: next, next
eco: npm
published: May 11, 2026
### Impact

App Router applications that rely on CSP nonces can be vulnerable to stored cross-site scripting when deployed behind shared caches. In affected versions, malformed nonce values derived from request headers could be reflected into rendered HTML in an unsafe way, allowing an attacker to p…

CVE-2026-44581
GitHub-GHSA

MEDIUM
Weblate: Stored HTML injection in editor search preview
GHSA-6wxc-8mgq-w26m
pkg: weblate
eco: pip
published: May 15, 2026
### Impact
Weblate's live search preview renders unit `source` and `context` as HTML without escaping. Any contributor whose content reaches those fields stores HTML and CSS that runs inside the authenticated editor of every user who runs a matching search.

### Patches
* https://github.com/WeblateO…

CVE-2026-45106
GitHub-GHSA

MEDIUM
Open WebUI Vulnerable to Cross-Site Request Forgery (CSRF) via Image URL Manipulation
GHSA-j6w6-986j-2m2m
pkg: open-webui
eco: pip
published: May 14, 2026
## Summary

An application-wide Cross-Site Request Forgery (CSRF) vulnerability was found Open-WebUl's image uploading functionality. An attacker can set an image URL to a malicious endpoint, allowing them to perform actions on behalf of a victim user. Any authenticated user can exploit this vulner…

CVE-2026-45317
NVD

MEDIUM
CVE-2026-45736
CVE-2026-45736
pkg: node

published: May 15, 2026

ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability is fixed in 8.20.1.
CWE: CWE-908
NVD

MEDIUM
CVE-2026-32209
CVE-2026-32209
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: May 12, 2026

Improper access control in Windows Filtering Platform (WFP) allows an authorized attacker to bypass a security feature locally.
CWE: CWE-284
GitHub-GHSA

MEDIUM
Open WebUI: Sharing models for others to use (read permission) also exposes model details (system prompt leakage)
GHSA-h2cw-7qw9-56xr
pkg: open-webui
eco: pip
published: May 14, 2026
### Summary
When setting model permissions so that a group has read access to it, intending for other users to use it, those users also can read the model's system prompt.

However users may consider their system prompt confidential, so we consider this a security issue.

Compare https://genai.owasp…

CVE-2026-45387
GitHub-GHSA

MEDIUM
Open WebUI has an IDOR vulnerability in the pin_channel_message API endpoint
GHSA-5gc6-xhv4-2wg6
pkg: open-webui
eco: pip
published: May 14, 2026
### Summary
`Pin/Unpin` is a write operation (modifies the message's `is_pinned `, `pinned_by`, `pinned_at` fields), but in standard channels it only checks `read` permission, allowing users with read-only access to pin/unpin any message.

### Details
https://github.com/open-webui/open-webui/blob/9b…

CVE-2026-45386
GitHub-GHSA

MEDIUM
Open WebUI has an IDOR vulnerability in the update_message_by_id API endpoint
GHSA-wwhq-cx22-f7vv
pkg: open-webui
eco: pip
published: May 14, 2026
### Summary
An IDOR vulnerability exists in the Channels feature of `Open WebUI`, allowing any channel member to modify messages sent by other members (including administrators) within the same channel. This vulnerability affects the latest version (`v0.8.12`) of `Open WebUI`.

### Details
In the `u…

CVE-2026-45385
GitHub-GHSA

MEDIUM
Open WebUI vulnerable to blind server side request forgery (SSRF) via the PDF generate function
GHSA-f776-fp4w-266c
pkg: open-webui
eco: pip
published: May 14, 2026
### Summary
Blind server side request forgery (SSRF) via the PDF generate function.
The finding resulted from a penetration test for a customer. It is suspected that the root cause of the issue lies within the core of Open WebUI, which is why it is being reported as a security issue here. Tested on…
CVE-2026-45347
NVD

MEDIUM
CVE-2026-8576
CVE-2026-8576
pkg: linux

published: May 14, 2026

Inappropriate implementation in CORS in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-942
NVD

MEDIUM
CVE-2026-8537
CVE-2026-8537
pkg: go

published: May 14, 2026

Insufficient policy enforcement in ViewTransitions in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-942
NVD

MEDIUM
CVE-2026-8528
CVE-2026-8528
pkg: go

published: May 14, 2026

Insufficient validation of untrusted input in SiteIsolation in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to bypass Site Isolation via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-20, CWE-20
GitHub-GHSA

MEDIUM
SiYuan has broken access control in `/api/search/{searchAsset,searchTag,searchWidget,searchTemplate}` publish-mode
GHSA-fmh9-gpqh-g53g
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: May 13, 2026
### Summary

The advisory `GHSA-c77m-r996-jr3q` patched `getBookmark` so that, when invoked by a publish-mode `RoleReader`, results are filtered through `FilterBlocksByPublishAccess` to remove entries from password-protected / publish-ignored notebooks. Four sibling search handlers in the same file …

CVE-2026-45148
GitHub-GHSA

MEDIUM
SiYuan: Broken access control in `/api/tag/getTag` — Reader role can mutate `Conf.Tag.Sort` and persist to disk
GHSA-6r88-8v7q-q4p2
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: May 13, 2026
### Summary

`POST /api/tag/getTag` is registered with `model.CheckAuth` only, omitting both `model.CheckAdminRole` and `model.CheckReadonly`, despite the handler performing a configuration write that is normally guarded by both. Any authenticated user — including publish-service `RoleReader` acco…

CVE-2026-45147
NVD

MEDIUM
CVE-2026-42541
CVE-2026-42541
pkg: kubernetes

published: May 12, 2026

Kubewarden is a policy engine for Kubernetes. Prior to , An attacker with privileged AdmissionPolicy or AdmissionPolicyGroup create permissions (which isn't the default) can craft a policy that makes use of the can_i host callback. The callback issues a SubjectAccessReview (SAR) requests to enumerat…
CWE: CWE-862
NVD

MEDIUM
CVE-2026-42565
CVE-2026-42565
pkg: oauth

published: May 11, 2026

@workos/authkit-session is a toolkit for building WorkOS AuthKit framework integrations. Prior to 0.5.1, an open redirect vulnerability exists in AuthService.handleCallback due to insufficient validation of the returnPathname value derived from the OAuth state parameter. The state parameter is round…
CWE: CWE-601
GitHub-GHSA

MEDIUM
oxidize-pdf: NaN/inf bypass in colour content-stream emission causes PDF rejection (DoS)
GHSA-88q9-cmp2-c2vq
pkg: oxidize-pdf, OxidizePdf.NET, oxidize-pdf
eco: pip
published: May 11, 2026
### Impact

`oxidize-pdf` defines `Color` as a `pub enum` with public tuple-struct variants `Rgb(f64, f64, f64)`, `Gray(f64)`, and `Cmyk(f64, f64, f64, f64)`. The constructors `Color::rgb`, `Color::gray`, and `Color::cmyk` clamp incoming
components to `[0.0, 1.0]`, but because the variants are `…

GitHub-GHSA

MEDIUM
arnika is affected by medium-severity issues in UDP rotation, PQC handling, and KMS TLS
GHSA-rc6v-5rmx-w5mv
pkg: github.com/arnika-project/arnika
eco: go
published: May 15, 2026
### Summary
Three medium-severity issues in arnika affecting the UDP key-rotation protocol, PQC key file handling, and KMS TLS client. All require specific preconditions to exploit and do not allow direct code execution or immediate key extraction. A self-contained PoC is attached.

### Details
1) A…

GitHub-GHSA

MEDIUM
rkyv: Panic safety bugs in `InlineVec::clear` and `SerVec::clear` enable arbitrary code execution
GHSA-vfvv-c25p-m7mm
pkg: rkyv
eco: rust
published: May 15, 2026
`InlineVec::clear()` and `SerVec::clear()` in `rkyv` were not panic-safe. Both functions iterate over their elements and call `drop_in_place` on each, updating `self.len` only *after* the loop. If an element's `Drop` implementation panics during the loop, `self.len` is left at its original value.

A…

GitHub-GHSA

MEDIUM
slack-go `SecretsVerifier` accepts empty signing secret without precondition
GHSA-gxhx-2686-5h9g
pkg: github.com/slack-go/slack
eco: go
published: May 14, 2026
“`go
func NewSecretsVerifier(header http.Header, secret string) (SecretsVerifier, error) {
hash := hmac.New(sha256.New, []byte(secret)) // raw secret, no precondition
}
“`
GitHub-GHSA

MEDIUM
Svelte: SSR XSS via Insecure Promise Serialization in hydratable
GHSA-f3cj-j4f6-wq85
pkg: svelte
eco: npm
published: May 14, 2026
Contents of `hydratable` promises were not properly stringified, potentially leading to an XSS exploit. You are vulnerable if all of the following is true:
– you are using `hydratable` (an experimental feature at the time of this report)
– you are passing attacker-controlled input such that a synchr…
GitHub-GHSA

MEDIUM
electerm's encrypt method not safe enough
GHSA-g29v-q6h7-76wh
pkg: electerm
eco: npm
published: May 14, 2026
### Impact
_Insecure sync encryption: deterministic AES-192-CBC with a fixed zero IV, constant KDF salt, and no MAC leads to confidentiality and integrity failures for synced bookmark/profile data. Attackers can crack common passwords across installs and perform undetected ciphertext bit-flips to al…
CVE-2026-45787
GitHub-GHSA

MEDIUM
Svelte Vulnerable to XSS via DOM Clobbering of Internal Framework State
GHSA-rcqx-6q8c-2c42
pkg: svelte
eco: npm
published: May 14, 2026
Svelte was vulnerable to DOM clobbering of its internal framework state on elements, potentially leading to XSS attacks.

You are vulnerable if all of the following is true:
– you are using attribute spreading on a form element
– you are using attribute spreading or allow a dynamic value for the `na…

CVE-2026-42573
GitHub-GHSA

MEDIUM
Svelte: ReDoS in `<svelte:element>` Tag Validation
GHSA-9rmh-mm8f-r9h6
pkg: svelte
eco: npm
published: May 14, 2026
An internal regex in the Svelte runtime can take exponential time to test in `<svelte:element this={tag}></svelte:element>`. You are only vulnerable to this if you allow tags of unconstrained length. If your application only allows a predetermined list of tags or trims their length before passing th…
CVE-2026-42567
GitHub-GHSA

MEDIUM
Open WebUI Has Stored Cross-Site Scripting in SVG Renderer
GHSA-r29h-37fj-x2w6
pkg: open-webui
eco: npm
published: May 14, 2026
### Summary
There is a Cross-Site Scripting vulnerability in Open WebUI SVG renderer implementation.

### Details

It is possible permanently save any HTML/JavaScript code in the application, which can be then executed in the context of the application domain. This behaviour can be used to extract …

CVE-2026-45346
GitHub-GHSA

MEDIUM
Svelte SSR vulnerable to cross-site scripting via spread attributes
GHSA-pr6f-5x2q-rwfp
pkg: svelte
eco: npm
published: May 14, 2026
When using spread syntax to render attributes from untrusted data, event handler properties are included in the rendered HTML output. If an application spreads user-controlled or external data as element attributes, an attacker can inject malicious event handlers that execute in victims' browsers. N…
CVE-2026-42599
GitHub-GHSA

MEDIUM
Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin
GHSA-3vcp-chfh-f6r2
pkg: github.com/kumahq/kuma, github.com/kumahq/kuma, github.com/kumahq/kuma
eco: go
published: May 14, 2026
## Summary

Default `kuma-cp` config leaks the admin bootstrap token and signing keys to any webpage the operator visits while the control plane is reachable from their browser. `CorsAllowedDomains: [".*"]` reflects any `Origin`, and `LocalhostIsAdmin: true` promotes requests from `127.0.0.1` to `me…

CVE-2026-45021
GitHub-GHSA

MEDIUM
TanStack Start – Server Core: Inbound server-function request deserialization could invoke a sibling client-referenced server function
GHSA-9m65-766c-r333
pkg: @tanstack/start-server-core
eco: npm
published: May 14, 2026
### Summary
A type-confusion bug in seroval ≤ 1.5.2 ([upstream advisory](https://github.com/lxsmnsyc/seroval/security/advisories)) allowed a crafted JSON body sent to one TanStack Start server function to trigger invocation of a different client-referenced server function as a side effect of deser…
GitHub-GHSA

MEDIUM
Portainer missing authorization on custom template file endpoint, which exposes template content
GHSA-cqpq-2fgr-8mvc
pkg: github.com/portainer/portainer, github.com/portainer/portainer
eco: go
published: May 14, 2026
## Summary
A missing authorization vulnerability in the Custom Template file endpoint (`GET /api/custom_templates/{id}/file`) allows any authenticated user to read the file content of any custom template by enumerating sequential integer IDs, bypassing Resource Control access restrictions. Template …
CVE-2026-44884
GitHub-GHSA

MEDIUM
Synapse pagination Denial of Service
GHSA-6qf2-7×63-mm6v
pkg: matrix-synapse
eco: pip
published: May 14, 2026
### Impact

In federated rooms, malicious homeservers can craft room events in such a way that prevents Synapse from providing full history to paginating clients.

Clients could therefore fail to display room history.

### Patches

Update to Synapse 1.152.1 or later.

### Workarounds

There are no k…

CVE-2026-45076
GitHub-GHSA

MEDIUM
Fleet: IP spoofing allows bypassing API rate limiting
GHSA-mxmp-wr3w-rvqx
pkg: github.com/fleetdm/fleet/v4
eco: go
published: May 14, 2026
### Summary
A vulnerability in Fleet's IP extraction logic allows unauthenticated attackers to bypass API rate limiting by spoofing client IP headers. This may allow brute-force login attempts or other abuse against Fleet instances exposed to the public internet.

### Impact
Fleet extracted client I…

CVE-2026-46356
GitHub-GHSA

MEDIUM
Fleet vulnerable to OS command injection in software packages
GHSA-9vcr-g537-3w5v
pkg: github.com/fleetdm/fleet/v4
eco: go
published: May 14, 2026
### Summary

A vulnerability in Fleet's software installer pipeline could allow a crafted software package to execute arbitrary commands as root (macOS/Linux) or SYSTEM (Windows) on managed endpoints when an uninstall is triggered.

### Impact

When a software package (.pkg, .deb, .rpm, .exe, or .ms…

CVE-2026-26191
GitHub-GHSA

MEDIUM
Strapi Upload Plugin MIME Validation Bypass via Content API
GHSA-pcw7-5633-82vv
pkg: @strapi/upload
eco: npm
published: May 14, 2026
### Summary of CVE-2026-22707 Vulnerability Details

– CVE: CVE-2026-22707
– CVSS v3.1 Vector: `CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N` (5.3 — Medium)
– Affected Versions: `@strapi/upload` <=5.33.2
– How to Patch: Immediately update your Strapi to >=5.33.3

### Description…

CVE-2026-22707
GitHub-GHSA

MEDIUM
Strapi has a rate limit bypass on users-permissions plugin via attacker-controlled email keying
GHSA-7mqx-wwh4-f9fw
pkg: @strapi/plugin-users-permissions
eco: npm
published: May 13, 2026
### Summary of CVE-2025-64526 Vulnerability Details

– CVE: CVE-2025-64526
– CVSS v3.1 Vector: `CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N` (6.9 — Medium)
– Affected Versions: `@strapi/plugin-users-permissions` <=5.44.0
– How to Patch: Immediately update your Strapi to >=5.45.…

CVE-2025-64526
GitHub-GHSA

MEDIUM
Traefik: Gateway API TraefikService backend accepts rest@internal, allowing unauthorized exposure of the REST provider despite providers.rest.insecure=false
GHSA-96qj-4jj5-wcjc
pkg: github.com/traefik/traefik/v3, github.com/traefik/traefik/v3, github.com/traefik/traefik/v2
eco: go
published: May 13, 2026
## Summary

There is a medium severity vulnerability in Traefik's Kubernetes Gateway API provider that allows a tenant with `HTTPRoute` creation permissions to expose the REST provider handler, bypassing the `providers.rest.insecure=false` setting. The Gateway provider accepts any `TraefikService` b…

CVE-2026-44774
GitHub-GHSA

MEDIUM
OpenLearnX: Critical Authentication Bypass via JWT Signature Verification Disabled Leading to Account Takeover
GHSA-223g-f5mq-gw33
pkg: openlearnx
eco: npm
published: May 13, 2026
### Overview

A critical authentication vulnerability was identified in OpenLearnX that could allow unauthorized access to user accounts under specific conditions. The issue has been fixed.

**Advisory**: https://github.com/th30d4y/OpenLearnX/security/advisories/GHSA-223g-f5mq-gw33

CVE-2026-44720
GitHub-GHSA

MEDIUM
SillyTavern has a SSRF vulnerability in the CORS proxy middleware
GHSA-ccfq-2454-f5xw
pkg: sillytavern
eco: npm
published: May 12, 2026
## Resolution

SillyTavern 1.18.0 added a generic server-side request filter (Private Request Whitelisting). Since we expect users to use the application in a trusted environment, the filter is disabled by default, however it is strongly advised to be enabled and properly configured when an instance…

CVE-2026-44652
GitHub-GHSA

MEDIUM
SillyTavern has a reflected XSS vulnerability in the CORS proxy middleware
GHSA-xc4x-2452-5gc9
pkg: sillytavern
eco: npm
published: May 12, 2026
## Resolution

Fixed in SillyTavern 1.18.0: a user-provided URL is no longer reflected in the HTTP response body.

## Overview
– Vulnerability Type: XSS
– Affected Location: `src/middleware/corsProxy.js:40`
– Trigger Scenario: reflected XSS in CORS proxy error response

## Root Cause
When `fetch(url…

CVE-2026-44651
GitHub-GHSA

MEDIUM
Mermaid: Improper sanitization of configuration leads to CSS injection
GHSA-87f9-hvmw-gh4p
pkg: mermaid, mermaid
eco: npm
published: May 11, 2026
### Impact

Mermaid's default configuration allows injecting CSS that applies outside of the Mermaid diagram via the `fontFamily`, `themeCSS`, and `altFontFamily` configuration options.

Live demo: [mermaid.live](https://mermaid.live/edit#pako:eNpNjktLxDAUhf9KvFBR6JS-60QQfODKlUvJ5k6TtsEmKTHFGUP-u-mI…

CVE-2026-41159
GitHub-GHSA

MEDIUM
Mermaid Gantt Charts are vulnerable to an Infinite Loop DoS
GHSA-6m6c-36f7-fhxh
pkg: mermaid, mermaid
eco: npm
published: May 11, 2026
### Impact

Mermaid v11.14.0 and earlier are vulnerable to a denial-of-service attack when rendering gantt charts, if they use the [`excludes` attribute](https://mermaid.js.org/syntax/gantt.html?#excludes) to exclude all dates.

Example:

“`
gantt
excludes monday,tuesday,wednesday,thursday,friday…

CVE-2026-41150
GitHub-GHSA

MEDIUM
Mermaid: Improper sanitization of `classDef` in state diagrams leads to HTML injection
GHSA-ghcm-xqfw-q4vr
pkg: mermaid, mermaid
eco: npm
published: May 11, 2026
### Impact

Under the default configuration, Mermaid state diagram's `classDef` allow DOM injection that escapes the SVG, although `<script>` tags are removed, preventing XSS.

#### Proof-of-concept

“`
stateDiagram-v2
classDef xss fill:red</style></svg><style>*{x:x;y:y;overflow:visible!important…

CVE-2026-41149
GitHub-GHSA

MEDIUM
Mermaid: Improper sanitization of `classDefs` in diagrams leads to CSS injection
GHSA-xcj9-5m2h-648r
pkg: mermaid, mermaid
eco: npm
published: May 11, 2026
### Details

The state diagram and any other diagram type that routes user-controlled style strings through createCssStyles parser for Mermaid v11.14.0 and earlier captures `classDef` values with an unrestricted regex:

“`jison
// packages/mermaid/src/diagrams/state/parser/stateDiagram.jison:83
<CL…

CVE-2026-41148
GitHub-GHSA

MEDIUM
Steamworks game clients/servers using P2P authentication vulnerable to denial of service
GHSA-g588-cjg3-6g78
pkg: steamworks
eco: rust
published: May 11, 2026
Processing the raw `ValidateAuthTicketResponse_t` callback data panics when the `m_eAuthSessionResponse` field is `k_EAuthSessionResponseAuthTicketNetworkIdentityFailure`. This can lead to denial of service in game clients and servers using the `begin_authentication_session` API to authenticate play…


Vulnerability Digest — May 11, 2026 · 99 Critical · 3 Exploited






Vulnerability Digest — Monday, May 11, 2026


Security Report

Monday, May 11, 2026  ·  Last 7 days  ·  Min severity: MEDIUM
Total Findings
557
Critical
99
High
259
Actively Exploited
3
CISA-KEV3
NVD179
GitHub-GHSA375
Findings sorted by severity
CISA-KEV

CRITICAL
BerriAI LiteLLM SQL Injection Vulnerability
CVE-2026-42208
pkg: BerriAI LiteLLM

published: May 8, 2026

BerriAI LiteLLM contains a SQL injection vulnerability that allows an attacker to read data from the proxy's database and potentially modify it, leading to unauthorised access to the proxy and the credentials it manages.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability
CVE-2026-6973
pkg: Ivanti Endpoint Manager Mobile (EPMM)

published: May 7, 2026

Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with administrative access to achieve remote code execution.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability
CVE-2026-0300
pkg: Palo Alto Networks PAN-OS

published: May 6, 2026

Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted pa…
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Until the vendor releases an official fix, the following workaround should be implemented: – Restrict User-ID Authentication Portal access to only trusted zones. – Disable User-ID Authentication Portal if not required.
NVD

CRITICAL
CVE-2026-42298
CVE-2026-42298
pkg: docker

published: May 8, 2026

Postiz is an AI social media scheduling tool. Prior to commit da44801, a "Pwn Request" vulnerability in the Build and Publish PR Docker Image workflow (.github/workflows/pr-docker-build.yml) allows any unauthenticated user to execute arbitrary code during the Docker build process and exfiltrate a hi…
CWE: CWE-94
GitHub-GHSA

CRITICAL
free5GC's NEF nnef-pfdmanagement API is unauthenticated; forged bearer tokens can read PFD data and create/delete PFD subscriptions
GHSA-rwww-x45w-p52w
pkg: github.com/free5gc/nef
eco: go
published: May 8, 2026
### Summary
free5GC's NEF mounts the `nnef-pfdmanagement` route group without inbound OAuth2/bearer-token authorization. A network attacker who can reach NEF on the SBI can use a forged or arbitrary bearer token (e.g. `Authorization: Bearer not-a-real-token`) to read PFD application data via `GET /a…
CVE-2026-44330
GitHub-GHSA

CRITICAL
free5GC's SMF UPI management interface lacks auth middleware; unauthenticated topology read/write requests reach handlers
GHSA-3258-qmv8-frp3
pkg: github.com/free5gc/smf
eco: go
published: May 8, 2026
### Summary
free5GC's SMF mounts the `UPI` management route group without OAuth2/bearer-token authorization middleware. A network attacker who can reach SMF on the SBI can hit `UPI` endpoints with no `Authorization` header at all, and the requests reach the SMF business handlers. In the running Dock…
CVE-2026-44329
GitHub-GHSA

CRITICAL
free5GC's NEF nnef-oam route group is unauthenticated; no-token requests reach the OAM handler
GHSA-cmpj-2x3g-m7g3
pkg: github.com/free5gc/nef
eco: go
published: May 8, 2026
### Summary
free5GC's NEF mounts the `nnef-oam` route group without inbound OAuth2/bearer-token authorization. A network attacker who can reach NEF on the SBI can hit the OAM route with no `Authorization` header at all and the handler returns `200 OK`. The current OAM handler is a stub that returns …
CVE-2026-44327
GitHub-GHSA

CRITICAL
Note Mark has a JWT Secret Weakness that allows Full Account Takeover via Token Forgery
GHSA-q6mh-rqwh-g786
pkg: github.com/enchant97/note-mark/backend
eco: go
published: May 7, 2026
#### Summary

No minimum length or entropy is enforced on the `JWT_SECRET` configuration value. The application accepts any base64-decodable secret regardless of size, including secrets as short as 1 byte.

HS256 secrets below 32 bytes are brute-forceable offline, allowing attackers to recover the s…

CVE-2026-44523
NVD

CRITICAL
CVE-2026-33587
CVE-2026-33587
pkg: lfnovo open-notebook

published: May 7, 2026

Lack of user input sanitisation in Open Notebook v1.8.3 allows the application user to execute Python code (and subsequently OS commands) on the docker container via Server-Side Template Injection (SSTI) for user-created transformations.
CWE: CWE-20
GitHub-GHSA

CRITICAL
vm2: Mutable Proxies for Host Intrinsic Prototypes Allows Sandbox Escape
GHSA-vwrp-x96c-mhwq
pkg: vm2
eco: npm
published: May 7, 2026
### Summary
vm2's bridge exposes mutable proxies for real host-realm intrinsic prototypes and then forwards sandbox writes into the underlying host objects with otherReflectSet() and otherReflectDefineProperty(), which lets attacker-controlled JavaScript running in a default VM or inherited NodeVM m…
CVE-2026-44005
GitHub-GHSA

CRITICAL
vm2 Access to Host Object Enables Sandbox Escape
GHSA-47×8-96vw-5wg6
pkg: vm2
eco: npm
published: May 7, 2026
### Summary

It is possible to obtain the host `Object`, https://github.com/patriksimek/vm2/commit/ebcfe94ad2f864f0bc35e78cff1d921107cfd160 added some protections, but the implementation is incomplete.

### Details

There are various ways to use the host `Object`, to escape the sandbox, one example …

CVE-2026-43997
GitHub-GHSA

CRITICAL
vm2 has a Sandbox Escape Vulnerability
GHSA-qcp4-v2jj-fjx8
pkg: vm2
eco: npm
published: May 7, 2026
### Summary

It is possible to reach `BaseHandler.getPrototypeOf`, which can be used to get arbitrary prototypes

### Details

https://github.com/patriksimek/vm2/blob/408fc855f1cc1bbc2985b029465ee0e732ada433/lib/bridge.js#L655-L658

`BaseHandler` can be reached via `util.inspect` (same as https://gi…

CVE-2026-44006
NVD

CRITICAL
CVE-2026-40281
CVE-2026-40281
pkg: docker

published: May 6, 2026

Gotenberg is a Docker-powered stateless API for PDF files. In versions 8.30.1 and earlier, the metadata write endpoint validates metadata keys for control characters but leaves metadata values unsanitized. A newline character in a metadata value splits the ExifTool stdin line into two separate argum…
CWE: CWE-88
NVD

CRITICAL
CVE-2026-42454
CVE-2026-42454
pkg: docker

published: May 8, 2026

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.1.0, all Docker container management endpoints in Termix interpolate the containerId URL path parameter and WebSocket message field directly into shell commands executed v…
CWE: CWE-78
GitHub-GHSA

CRITICAL
vm2 has a NodeVM builtin allowlist bypass via `module` builtin's `Module._load` that allows sandbox escape
GHSA-947f-4v7f-x2v8
pkg: vm2
eco: npm
published: May 7, 2026
## Summary
NodeVM's `builtin` allowlist can be bypassed when the `module` builtin is allowed (including via the `'*'` wildcard). The `module` builtin exposes Node's `Module._load()`, which loads any module by name directly in the host context, completely bypassing vm2's builtin restriction. This all…
CVE-2026-43999
GitHub-GHSA

CRITICAL
Fleet: Helm impersonation bypass of `RESTClientGetter` retains `cluster-admin` during template rendering
GHSA-765j-qfrp-hm3j
pkg: github.com/rancher/fleet, github.com/rancher/fleet, github.com/rancher/fleet
eco: go
published: May 7, 2026
### Impact

Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git push access to a Fleet-monitored repository to read secrets from any namespace on every downstream cluster targeted by their `GitRepo`.

**Helm `lookup` bypass:** The Helm…

CVE-2026-41050
GitHub-GHSA

CRITICAL
wger: cross-tenant password reset and plaintext disclosure via gym=None bypass
GHSA-mhc8-p3jx-84mm
pkg: wger
eco: pip
published: May 6, 2026
### Summary

The `reset_user_password` and `gym_permissions_user_edit` views in wger perform a gym-scope authorization check using Python object comparison (`!=`) that evaluates `None != None` as `False`, silently bypassing the guard when both the attacker and victim have no gym assignment (`gym=Non…

CVE-2026-43948
GitHub-GHSA

CRITICAL
Rucio has SQL Injection in FilterEngine PostgreSQL Query Builder via DID Search API
GHSA-6j7p-qjhg-9947
pkg: rucio, rucio, rucio
eco: pip
published: May 6, 2026
### Summary

A SQL injection vulnerability in `FilterEngine.create_postgres_query` allows any authenticated Rucio user to execute arbitrary SQL against the configured PostgreSQL metadata database through the DID search endpoint (`GET /dids/<scope>/dids/search`). When the external metadata plugin `po…

CVE-2026-29090
GitHub-GHSA

CRITICAL
Rucio has SQL Injection in FilterEngine Oracle JSON Path via DID Search API
GHSA-vjr5-c9qv-hgm3
pkg: rucio, rucio, rucio
eco: pip
published: May 6, 2026
### Summary

A SQL injection vulnerability in the Oracle path of `FilterEngine.create_sqla_query` allows any authenticated Rucio user to execute arbitrary SQL against the backend database through the DID search endpoint (`GET /dids/<scope>/dids/search`). Attacker-controlled filter keys and values ar…

CVE-2026-29080
GitHub-GHSA

CRITICAL
Apache Polaris has an Improper Input Validation Issue
GHSA-vxgg-mqx2-3w59
pkg: org.apache.polaris:polaris-core
eco: maven
published: May 4, 2026
Apache Polaris accepts literal `*` characters in namespace and table names. When it later builds temporary S3 access policies for delegated table access, those same characters appear to be reused unescaped in S3 IAM resource patterns and `s3:prefix` conditions.

In S3 IAM policy matching, `*` is tre…

CVE-2026-42810
GitHub-GHSA

CRITICAL
Apache Polaris has an Improper Input Validation Issue
GHSA-8ggj-j522-h5qf
pkg: org.apache.polaris:polaris-runtime-service
eco: maven
published: May 4, 2026
Apache Polaris can issue broad temporary ("vended") storage credentials during staged table creation before the effective table location has been validated or durably reserved. Those temporary credentials are meant to limit the scope of accessible table data and metadata, but this scope limitation b…
CVE-2026-42809
GitHub-GHSA

CRITICAL
Apache Polaris has an Improper Input Validation issue
GHSA-w76p-3cgp-qfcm
pkg: org.apache.polaris:polaris-runtime-service
eco: maven
published: May 4, 2026
In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table and which table version to read.

`write.metadata.path` is an optional table property that tells Polaris where to write those metadata files. For a table already registered in a Po…

CVE-2026-42812
GitHub-GHSA

CRITICAL
Apache Polaris has an Improper Input Validation issue
GHSA-fc3h-c6h7-r83j
pkg: org.apache.polaris:polaris-core
eco: maven
published: May 4, 2026
In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, but a crafted namespace or table name can cause those credentials to work across the configured bucket instead.

Apache Polaris builds Google Cloud Storage downscoped credentials by …

CVE-2026-42811
NVD

CRITICAL
CVE-2026-42811
CVE-2026-42811
pkg: express

published: May 4, 2026

In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials
that
only work for one table's files, but a crafted namespace or table name can
cause those credentials to work across the configured bucket instead.

Apache Polaris builds Google Cloud Storage downscoped credentials by…

CWE: CWE-20, CWE-917
GitHub-GHSA

CRITICAL
@profullstack/mcp-server vulnerable to OS Command Injection in domain_lookup Module
GHSA-v6wj-c83f-v46x
pkg: @profullstack/mcp-server
eco: npm
published: May 9, 2026
<html>
<body>
<!–StartFragment–><html><head></head><body><h1>Security Advisory: OS Command Injection in <code>profullstack/mcp-server</code> <code>domain_lookup</code> Module</h1>

Field | Value
— | —
Project | profullstack/mcp-server
Repository | https://github.com/profullstack/mcp-server
Affec…

GitHub-GHSA

CRITICAL
Electerm runWidget has a path traversal that leads to arbitrary code execution
GHSA-f77v-9vpc-6pjm
pkg: electerm
eco: npm
published: May 8, 2026
### Impact
The `runWidget` function in `src/app/widgets/load-widget.js` constructs a file path by directly concatenating user‑supplied widget identifiers without any sanitisation:

“`javascript
const file = `widget-${widgetId}.js`
const widget = require(path.join(__dirname, file))
“`

Because `r…

CVE-2026-43940
GitHub-GHSA

CRITICAL
vm2 has Sandbox Breakout Through Null Proto Exception
GHSA-9vg3-4rfj-wgcm
pkg: vm2
eco: npm
published: May 8, 2026
### Summary

VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system.

### Details

In `handleException` due to “// SECURITY (post-GHSA-mpf8 hardening): use `from` (not `ensureThis…

CVE-2026-44009
GitHub-GHSA

CRITICAL
vm2 has sandbox breakout via `neutralizeArraySpeciesBatch`
GHSA-9qj6-qjgg-37qq
pkg: vm2
eco: npm
published: May 8, 2026
### Summary

VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system.

### Details

The new method `neutralizeArraySpeciesBatch` works with objects from the other side but can call …

CVE-2026-44008
NVD

CRITICAL
CVE-2026-43402
CVE-2026-43402
pkg: node

published: May 8, 2026

In the Linux kernel, the following vulnerability has been resolved:

kthread: consolidate kthread exit paths to prevent use-after-free

Guillaume reported crashes via corrupted RCU callback function pointers
during KUnit testing. The crash was traced back to the pidfs rhashtable
conversion which rep…

NVD

CRITICAL
CVE-2026-41507
CVE-2026-41507
pkg: express

published: May 8, 2026

math-codegen generates code from mathematical expressions. Prior to version 0.4.3, string literal content passed to cg.parse() is injected verbatim into a new Function() body without sanitization. This allows an attacker to execute arbitrary system commands when user-controlled input reaches the par…
CWE: CWE-94
NVD

CRITICAL
CVE-2026-41497
CVE-2026-41497
pkg: praison praisonai

published: May 8, 2026

PraisonAI is a multi-agent teams system. Prior to version 4.6.9, the fix for PraisonAI's MCP command handling does not add a command allowlist or argument validation to parse_mcp_command(), allowing arbitrary executables like bash, python, or /bin/sh with inline code execution flags to pass through …
CWE: CWE-77, CWE-78
NVD

CRITICAL
CVE-2023-46453
CVE-2023-46453
pkg: express

published: May 8, 2026

Certain GL.iNet devices with 4.x firmware allow authentication bypass (resulting in administrative control of the device) via a username that is both a valid SQL statement and a valid regular expression. For example, this affects version 4.3.7 on GL-MT3000 GL-AR300M GL-B1300 GL-AX1800 GL-AR750S GL-M…
CWE: CWE-89
GitHub-GHSA

CRITICAL
Gotenberg has Unauthenticated RCE via ExifTool Metadata Key Injection
GHSA-rqgh-gxv4-6657
pkg: github.com/gotenberg/gotenberg/v8
eco: go
published: May 7, 2026
# Unauthenticated RCE in Gotenberg via Metadata Key Newline Injection

## Summary

Gotenberg's `/forms/pdfengines/metadata/write` HTTP endpoint accepts a JSON metadata object and passes its keys directly to ExifTool via the go-exiftool library. No validation is performed on key characters. A `\n` em…

CVE-2026-42589
NVD

CRITICAL
CVE-2026-41930
CVE-2026-41930
pkg: docker

published: May 6, 2026

Vvveb before version 1.0.8.2 contains a hard-coded credentials vulnerability in its docker-compose-apache.yaml configuration that allows unauthenticated attackers to access the bundled phpMyAdmin container with pre-configured database credentials. Attackers can connect to the phpMyAdmin port to gain…
CWE: CWE-306
GitHub-GHSA

CRITICAL
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore
GHSA-4pvg-prr3-9cxr
pkg: github.com/0xJacky/nginx-ui
eco: go
published: May 6, 2026
**Product:** nginx-ui
**Repository:** `0xJacky/nginx-ui` (branch: `dev`)
**Vulnerability Class:** Authentication Bypass → Arbitrary File Write → OS Command Injection
**Affected Component:** `POST /api/restore`

## 1. Vulnerability Summary

nginx-ui exposes a backup restore endpoint (`POST /…

CVE-2026-42238
NVD

CRITICAL
CVE-2026-43186
CVE-2026-43186
pkg: node

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

ipv6: ioam: fix heap buffer overflow in __ioam6_fill_trace_data()

On the receive path, __ioam6_fill_trace_data() uses trace->nodelen
to decide how much data to write for each node. It trusts this field
as-is from the incoming pack…

NVD

CRITICAL
CVE-2026-35579
CVE-2026-35579
pkg: coredns.io coredns

published: May 5, 2026

CoreDNS is a DNS server written in Go. In versions prior to 1.14.3, the gRPC, QUIC, DoH, and DoH3 transport implementations incorrectly handle TSIG authentication. For gRPC and QUIC, the server checks whether the TSIG key name exists in the configuration but never calls dns.TsigVerify() to validate …
CWE: CWE-287
NVD

CRITICAL
CVE-2026-38428
CVE-2026-38428
pkg: kestra kestra

published: May 5, 2026

Kestra v1.3.3 and before is vulnerable to SQL Injection. The vulnerability occurs because user-controlled input from a GET parameter is directly concatenated into an SQL query without proper sanitization or parameterization. As a result, attackers can inject arbitrary SQL expressions into the databa…
CWE: CWE-89
NVD

CRITICAL
CVE-2026-38431
CVE-2026-38431
pkg: frappe erpnext

published: May 5, 2026

ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or edit email templates can inject template expressions that are executed on the server when the template is rendered.
CWE: CWE-94
GitHub-GHSA

CRITICAL
VM2 Has a WASM Sandbox Escape (Node 25 only)
GHSA-ffh4-j6h5-pg66
pkg: vm2
eco: npm
published: May 5, 2026
## Summary

Full sandbox escape with arbitrary code execution. Attacker code inside `VM.run()` obtains host process object and runs host commands with zero host cooperation.

## Details

**Confirmed on:** vm2 3.10.4, Node.js v25.6.1 (x64 Linux)
**Trigger:** Attacker-controlled code passed to `VM.run…

CVE-2026-26956
GitHub-GHSA

CRITICAL
VM2 Has a Sandbox Escape Issue via SuppressedError
GHSA-55hx-c926-fr95
pkg: vm2
eco: npm
published: May 5, 2026
In vm2 v3.10.4 on Node.js v24.13.0, `SuppressedError` allows attackers to escape the sandbox and run arbitrary code.

### PoC
“`js
const { VM } = require("vm2");

const vm = new VM();

vm.run(`
const ds = new DisposableStack();
ds.defer(() => { throw null; });
ds.defer(() => {
const e = Error();

CVE-2026-26332
GitHub-GHSA

CRITICAL
VM2 Has Sandbox Breakout Through Inspect Function
GHSA-v37h-5mfm-c47c
pkg: vm2
eco: npm
published: May 5, 2026
### Summary

VM2 suffers from a sandbox breakout vulnerability through the `inspect` function. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system.

### Details

The node `inspect` method allows to log details of objects. To get…

CVE-2026-24781
GitHub-GHSA

CRITICAL
VM2 Has Sandbox Breakout Through Promise Species
GHSA-qvjj-29qf-hp7p
pkg: vm2
eco: npm
published: May 5, 2026
### Summary

The fix for https://github.com/patriksimek/vm2/security/advisories/GHSA-cchq-frgv-rjh5 is insufficient and can be circumvented allowing attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system.

### Details

The fix for https://gith…

CVE-2026-24120
NVD

CRITICAL
CVE-2026-43067
CVE-2026-43067
pkg: linux

published: May 5, 2026

In the Linux kernel, the following vulnerability has been resolved:

ext4: handle wraparound when searching for blocks for indirect mapped blocks

Commit 4865c768b563 ("ext4: always allocate blocks only from groups
inode can use") restricts what blocks will be allocated for indirect
block based file…

NVD

CRITICAL
CVE-2026-42238
CVE-2026-42238
pkg: nginxui nginx_ui

published: May 4, 2026

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, nginx-ui exposes a backup restore endpoint (POST /api/restore) that is completely unauthenticated during the first 10 minutes after process startup on any fresh installation. An unauthenticated remote attacker can upl…
CWE: CWE-94
NVD

CRITICAL
CVE-2026-42233
CVE-2026-42233
pkg: n8n n8n

published: May 4, 2026

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the Oracle Database node's select operation allowed user-controlled input passed into the Limit field via expressions to be interpolated directly into the SQL query without sanitization or p…
CWE: CWE-89
GitHub-GHSA

CRITICAL
Apache OpenNLP ExtensionLoader Vulnerable to Arbitrary Class Instantiation via Model Manifest
GHSA-cx4m-2p55-rw7j
pkg: org.apache.opennlp:opennlp-tools, org.apache.opennlp:opennlp-tools
eco: maven
published: May 4, 2026
Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader

Versions Affected: before 2.5.9, before 3.0.0-M3

Description: 

The ExtensionLoader.instantiateExtension(Class, String) method loads a class by its fully-qualified name via Class.forName() and invokes its…

CVE-2026-42027
NVD

CRITICAL
CVE-2026-42796
CVE-2026-42796
pkg: python

published: May 4, 2026

Arelle before 2.39.10 contains an unauthenticated remote code execution vulnerability in the /rest/configure REST endpoint that accepts a plugins query parameter and forwards it to the plugin manager without authentication or authorization. Attackers can supply a URL to a malicious Python file throu…
CWE: CWE-306
NVD

CRITICAL
CVE-2026-42076
CVE-2026-42076
pkg: curl

published: May 4, 2026

Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a command injection vulnerability in the _extractLLM() function allows attackers to execute arbitrary shell commands on the server. The function constructs a curl command using string concatenation and passes it to…
CWE: CWE-78
NVD

CRITICAL
CVE-2026-26956
CVE-2026-26956
pkg: vm2_project vm2

published: May 4, 2026

vm2 is an open source vm/sandbox for Node.js. In version 3.10.4, vm2 is vulnerable to full sandbox escape with arbitrary code execution. Attacker code inside VM.run() obtains host process object and runs host commands with zero host cooperation. This issue has been patched in version 3.10.5.
CWE: CWE-693
NVD

CRITICAL
CVE-2026-26332
CVE-2026-26332
pkg: vm2_project vm2

published: May 4, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, SuppressedError allows attackers to escape the sandbox and run arbitrary code. This issue has been patched in version 3.11.0.
CWE: CWE-94, CWE-693
NVD

CRITICAL
CVE-2026-24781
CVE-2026-24781
pkg: vm2_project vm2

published: May 4, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability through the inspect function. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system. This issue has been patc…
CWE: CWE-94, CWE-693
NVD

CRITICAL
CVE-2026-24120
CVE-2026-24120
pkg: vm2_project vm2

published: May 4, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.10.5, the fix for CVE-2023-37466 is insufficient and can be circumvented allowing attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system. This issue has been patched in version 3…
CWE: CWE-94, CWE-693
NVD

CRITICAL
CVE-2026-24118
CVE-2026-24118
pkg: vm2_project vm2

published: May 4, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system. This issue has been patched in version 3.11.0.
CWE: CWE-94, CWE-693
GitHub-GHSA

CRITICAL
Cline Kanban Server has a Cross-Origin WebSocket Hijacking Vulnerability
GHSA-5c57-rqjx-35g2
pkg: cline
eco: npm
published: May 8, 2026
## Summary

The `kanban` npm package (used by the `cline` CLI) starts a WebSocket server on `127.0.0.1:3484` with no Origin header validation. Any website a developer visits can silently connect to the kanban server via WebSocket and:

1. Leak sensitive data in real-time: workspace filesystem paths,…

CVE-2026-44211
NVD

CRITICAL
CVE-2026-44336
CVE-2026-44336
pkg: praison praisonai

published: May 8, 2026

PraisonAI is a multi-agent teams system. Prior to version 4.6.34, PraisonAI's MCP (Model Context Protocol) server (praisonai mcp serve) registers four file-handling tools by default — praisonai.rules.create, praisonai.rules.show, praisonai.rules.delete, and praisonai.workflow.show. Each accepts a …
CWE: CWE-20, CWE-22, CWE-94, CWE-829, CWE-913
NVD

CRITICAL
CVE-2026-42880
CVE-2026-42880
pkg: kubernetes

published: May 7, 2026

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.0 to before 3.3.9, there is a missing authorization and data-masking gap in Argo CD's ServerSideDiff endpoint that allows an attacker with read-only access to extract plaintext Kube…
CWE: CWE-200, CWE-212
GitHub-GHSA

CRITICAL
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction
GHSA-3v3m-wc6v-x4x3
pkg: github.com/argoproj/argo-cd/v3, github.com/argoproj/argo-cd/v3
eco: go
published: May 7, 2026
### Summary
There is a missing authorization and data-masking gap in Argo CD's ServerSideDiff endpoint that allows an attacker with read-only access to extract plaintext Kubernetes Secret data from etcd via the Kubernetes API server's Server-Side Apply dry-run mechanism.

### Details
Argo CD masks S…

CVE-2026-42880
NVD

CRITICAL
CVE-2026-7910
CVE-2026-7910
pkg: google chrome, apple macos, linux linux_kernel

published: May 6, 2026

Use after free in Views in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

CRITICAL
CVE-2026-7908
CVE-2026-7908
pkg: google chrome, apple macos, linux linux_kernel

published: May 6, 2026

Use after free in Fullscreen in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

CRITICAL
CVE-2026-42235
CVE-2026-42235
pkg: n8n n8n

published: May 4, 2026

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an unauthenticated attacker could register a malicious MCP OAuth client with a crafted client_name. If a victim user authorized the OAuth consent dialog and a second user subsequently revoked that acc…
CWE: CWE-79, CWE-87
NVD

CRITICAL
CVE-2026-42088
CVE-2026-42088
pkg: docker

published: May 4, 2026

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the do…
CWE: CWE-250
NVD

CRITICAL
CVE-2026-42090
CVE-2026-42090
pkg: node

published: May 4, 2026

Notesnook is a note-taking app focused on user privacy & ease of use. Prior to Notesnook Web/Desktop version 3.3.15 and prior to Notesnook iOS/Android version 3.3.20, a stored XSS vulnerability in the note export flow can be escalated to remote code execution in the desktop app. The root cause is th…
CWE: CWE-79, CWE-94
GitHub-GHSA

CRITICAL
free5GC's NEF 3gpp-traffic-influence API is unauthenticated; missing or forged bearer tokens can create, read, patch, and delete subscriptions
GHSA-3p28-73q7-45xp
pkg: github.com/free5gc/nef
eco: go
published: May 8, 2026
### Summary
free5GC's NEF mounts the `3gpp-traffic-influence` API without inbound OAuth2/bearer-token authorization. A network attacker who can reach NEF on the SBI can create, read, patch, and delete traffic-influence subscriptions either with no `Authorization` header at all, or with a forged bear…
CVE-2026-44326
GitHub-GHSA

CRITICAL
free5GC's NEF 3gpp-pfd-management API is unauthenticated; forged bearer tokens can create, read, and delete PFD transactions
GHSA-5f62-53r8-qrqf
pkg: github.com/free5gc/nef
eco: go
published: May 8, 2026
### Summary
free5GC's NEF mounts the `3gpp-pfd-management` API without inbound OAuth2/bearer-token authorization. A network attacker who can reach NEF on the SBI can create, read, and delete PFD-management transaction state with a forged or arbitrary bearer token (e.g. `Authorization: Bearer not-a-r…
CVE-2026-44315
GitHub-GHSA

CRITICAL
Gotenberg vulnerable to unauthenticated SSRF via default deny-list bypass in downloadFrom and webhook
GHSA-4vmc-gm8v-m35h
pkg: github.com/gotenberg/gotenberg/v8
eco: go
published: May 7, 2026
### Summary
The default deny-lists used by Gotenberg's `downloadFrom` feature and `webhook` feature are bypassable. Because the filter is regex-based and case-sensitive, an unauthenticated attacker can supply URLs such as `http://[::ffff:127.0.0.1]:…` and reach loopback or private HTTP services th…
CVE-2026-42596
GitHub-GHSA

CRITICAL
S3-Proxy has Security Issues in its Resource Path Matching Implementation
GHSA-rfgq-wgg8-662p
pkg: github.com/oxyno-zeta/s3-proxy
eco: go
published: May 5, 2026
## Background

The original concern is functional: a resource pattern should treat a percent-encoded segment like some%2Fvalue as a single opaque token rather than splitting it into two path segments at the decoded /. Investigation into why %2F was being decoded and how routes matched against the re…

CVE-2026-42882
GitHub-GHSA

CRITICAL
Compromised version of intercom-client published to npm
GHSA-54pg-9963-v8vg
pkg: intercom-client
eco: npm
published: May 7, 2026
### Impact

On April 30, 2026, version 7.0.4 of intercom-client was published to npm using credentials obtained from a compromised developer account. This version was not produced by Intercom's build pipeline.

The malicious version contained an obfuscated JavaScript payload that executed during pac…

NVD

CRITICAL
CVE-2026-42560
CVE-2026-42560
pkg: oauth

published: May 9, 2026

auth provides authentication via oauth2, direct and email. From versions 1.18.0 to before 1.25.2 and 2.0.0 to before 2.1.2, the Patreon OAuth provider maps every authenticated Patreon account to the same local user.ID, instead of deriving a unique ID from the Patreon account returned by Patreon. In …
CWE: CWE-287
GitHub-GHSA

CRITICAL
Open WebUI has an LDAP Empty Password Authentication Bypass
GHSA-2r4p-jpmg-48f4
pkg: open-webui
eco: pip
published: May 8, 2026
# LDAP Empty Password Authentication Bypass

## Affected Component

LDAP authentication endpoint:
– `backend/open_webui/routers/auths.py` (lines 468-477, user bind with empty password)
– `backend/open_webui/models/auths.py` (lines 58-60, `LdapForm` model)

## Affected Versions

Current main branch (…

CVE-2026-44551
NVD

CRITICAL
CVE-2026-44497
CVE-2026-44497
pkg: zfnd zebra-script, zfnd zebrad

published: May 8, 2026

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.4.0 and prior to zebra-script version 6.0.0, the fix for CVE-2026-41583 introduced a separate issue due to insufficient error handling of the case where the sighash type is invalid, during sighash computation. Instead of retur…
CWE: CWE-347
NVD

CRITICAL
CVE-2026-41583
CVE-2026-41583
pkg: zfnd zebra-script, zfnd zebrad

published: May 8, 2026

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and prior to zebra-script version 5.0.2, after a refactoring, Zebra failed to validate a consensus rule that restricted the possible values of sighash hash types for V5 transactions which were enabled in the NU5 network up…
CWE: CWE-573
GitHub-GHSA

CRITICAL
vm2 NodeVM `nesting: true` bypasses `require: false` allowing sandbox escape and arbitrary OS command execution
GHSA-8hg8-63c5-gwmx
pkg: vm2
eco: npm
published: May 7, 2026
### Summary

When a `NodeVM` is created with `nesting: true`, sandbox code can unconditionally `require('vm2')` regardless of the outer VM's `require` configuration — including `require: false`. With access to `vm2`, the sandbox constructs a new inner `NodeVM` with its own unrestricted `require` s…

CVE-2026-44007
GitHub-GHSA

CRITICAL
FileBrowser Public Share DELETE API Path Traversal Allows Unauthenticated Arbitrary File Deletion
GHSA-fwj3-42wh-8673
pkg: github.com/gtsteffaniak/filebrowser
eco: go
published: May 7, 2026
### **Summary**

Attacker-controlled path input is joined with a trusted base path prior to sanitization, allowing traversal sequences (e.g., ../) to escape the intended shared directory. As a result, an unauthenticated attacker possessing a valid public share hash with delete permissions enabled ca…

CVE-2026-44542
GitHub-GHSA

CRITICAL
Axonflow fixed bugs by implementing multi-tenant isolation and access-control hardening
GHSA-9h64-2846-7x7f
pkg: github.com/getaxonflow/axonflow
eco: go
published: May 6, 2026
## Summary

Eight independently-filed bug fixes in the v7.1.3 → v7.5.0 release window collectively close a set of multi-tenant isolation, access-control, and policy-enforcement defects in the AxonFlow platform. They are filed as a single consolidated advisory because the recommended remediation is…

GitHub-GHSA

CRITICAL
fast-jwt: JWT auth bypass due to empty HMAC secret accepted by async key resolver
GHSA-gmvf-9v4p-v8jc
pkg: fast-jwt
eco: npm
published: May 6, 2026
### Summary

A critical authentication-bypass vulnerability in `fast-jwt`'s async key-resolver flow allows any unauthenticated attacker to forge arbitrary JWTs that are accepted as authentic. When the application's key resolver returns an empty string (`''`), for example via the common `keys[decoded…

CVE-2026-44351
GitHub-GHSA

CRITICAL
Valtimo has SpEL injection via StandardEvaluationContext that allows Remote Code Execution by admin users
GHSA-j7j9-5253-f7vh
pkg: com.ritense.valtimo:document, com.ritense.valtimo:case, com.ritense.valtimo:contract
eco: maven
published: May 6, 2026
### Summary

Multiple classes evaluate Spring Expression Language (SpEL) expressions from user-supplied input using `StandardEvaluationContext`, which provides unrestricted access to Java types and methods. An authenticated user with the ADMIN role can achieve Remote Code Execution and credential ex…

CVE-2026-42555
NVD

CRITICAL
CVE-2026-43083
CVE-2026-43083
pkg: linux

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

net: ioam6: fix OOB and missing lock

When trace->type.bit6 is set:

if (trace->type.bit6) {

queue = skb_get_tx_queue(dev, skb);
qdisc = rcu_dereference(queue->qdisc);

This code can lead to an out-o…

NVD

CRITICAL
CVE-2026-43071
CVE-2026-43071
pkg: linux

published: May 5, 2026

In the Linux kernel, the following vulnerability has been resolved:

dcache: Limit the minimal number of bucket to two

There is an OOB read problem on dentry_hashtable when user sets
'dhash_entries=1':
BUG: unable to handle page fault for address: ffff888b30b774b0
#PF: supervisor read access in…

NVD

CRITICAL
CVE-2026-36356
CVE-2026-36356
pkg: go

published: May 5, 2026

The GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthenticated OS command injection via the /action/SetRemoteAccessCfg endpoint.
CWE: CWE-78, CWE-306
GitHub-GHSA

CRITICAL
OpenMRS has Stored Velocity SSTI to RCE via ConceptReferenceRange
GHSA-xj4f-8jjg-vx4q
pkg: org.openmrs.api:openmrs-api, org.openmrs.api:openmrs-api
eco: maven
published: May 4, 2026
### Impact

The `ConceptReferenceRangeUtility.evaluateCriteria()` method in OpenMRS Core
evaluates database-stored criteria strings as Apache Velocity templates without any sandbox configuration. The `VelocityEngine` is initialized with only logging properties and no`SecureUberspector`, leaving the …

CVE-2026-41258
GitHub-GHSA

CRITICAL
Apache OpenNLP DictionaryEntryPersistor Vulnerable to XML External Entity (XXE) via Unsanitized Dictionary Parsing
GHSA-4v8g-86×5-3vrc
pkg: org.apache.opennlp:opennlp-tools, org.apache.opennlp:opennlp-tools
eco: maven
published: May 4, 2026
XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor

Versions Affected: before 2.5.9, before 3.0.0-M3

Description: The DictionaryEntryPersistor class initializes a static SAXParserFactory at class-load time without enabling FEATURE_SECURE_PROCES…

CVE-2026-40682
GitHub-GHSA

CRITICAL
ArcadeDB vulnerable to cross-database authorization bypass and unsecured newly-created databases
GHSA-fxc7-fm93-6q77
pkg: com.arcadedb:arcadedb-server
eco: maven
published: May 5, 2026
### Impact
Authenticated users and API tokens scoped to a specific database could read, write, and mutate schema on any other database on the same server. Two distinct defects contributed: (1) ServerSecurityUser.getDatabaseUser() returned a DB user with an uninitialized fileAccessMap, which requestA…
CVE-2026-44221
GitHub-GHSA

CRITICAL
Sandboxed Thymeleaf expressions vulnerable to improper recognition of unauthorized syntax patterns
GHSA-c9ph-gxww-7744
pkg: org.thymeleaf:thymeleaf, org.thymeleaf:thymeleaf-spring5, org.thymeleaf:thymeleaf-spring6
eco: maven
published: May 4, 2026
### Impact

A security bypass vulnerability exists in the expression execution mechanisms of Thymeleaf up to and including 3.1.4.RELEASE. Although the library provides mechanisms to avoid the execution of potentially dangerous expressions in some specific sandboxed (restricted) contexts, it fails to…

CVE-2026-41901
GitHub-GHSA

CRITICAL
OpenMRS Module Upload Vulnerable to Path Traversal (Zip Slip)
GHSA-78fc-9688-w8xw
pkg: org.openmrs.web:openmrs-web, org.openmrs.web:openmrs-web
eco: maven
published: May 4, 2026
## Affected Versions

version ≤ 2.7.8 (latest version at time of disclosure)

https://github.com/openmrs/openmrs-core

## Impact

The endpoint `POST /openmrs/ws/rest/v1/module` is vulnerable to a path traversal (Zip Slip) attack. An authenticated attacker can upload a crafted `.omod` archive conta…

CVE-2026-40076
GitHub-GHSA

CRITICAL
SiYuan: Electron Renderer RCE via decodeURIComponent-driven tooltip XSS in aria-label sink (incomplete fix for CVE-2026-34585)
GHSA-25rp-h46x-2hjm
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: May 8, 2026
## Summary

The tooltip mouseover handler in `app/src/block/popover.ts` reads `aria-label` via `getAttribute` and passes it through `decodeURIComponent` before assigning to `messageElement.innerHTML` in `app/src/dialog/tooltip.ts:41`. The encoder used at the producer side, `escapeAriaLabel` in `app/…

CVE-2026-44588
GitHub-GHSA

CRITICAL
Electerm users can run dangrous code through link or command line
GHSA-mpm8-cx2p-626q
pkg: electerm
eco: npm
published: May 8, 2026
### Impact
_Arbitrary local code execution via deep links, CLI `–opts`, or crafted shortcuts. Affected users: electerm installs that accept protocol URLs or CLI options (affected versions listed in the original report). Exploit requires clicking a crafted `electerm://…` link or opening a crafted …
CVE-2026-43944
GitHub-GHSA

CRITICAL
Zebra v4.4.0 still accepts V5 SIGHASH_SINGLE without a corresponding output
GHSA-pvmv-cwg8-v6c8
pkg: zebrad, zebra-script
eco: rust
published: May 8, 2026
# Consensus Divergence in V5 Transparent SIGHASH_SINGLE With No Corresponding Output

## Summary

Zebra failed to enforce a ZIP-244 consensus rule for V5 transparent transactions: when an input is signed with `SIGHASH_SINGLE` and there is no transparent output at the same index as that input, valida…

GitHub-GHSA

CRITICAL
SiYuan Affected by Stored XSS via Attribute View Name to Electron Renderer RCE
GHSA-2h64-c999-c9r6
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: May 8, 2026
## Summary

The kernel stores Attribute View (AV / database) names without any HTML escape, then a render template uses raw `strings.ReplaceAll(tpl, "${avName}", nodeAvName)` to embed the name in HTML before pushing to all clients via WebSocket. Three independent client paths (`render.ts:120` → `o…

CVE-2026-44670
GitHub-GHSA

CRITICAL
Zebra's Transparent SIGHASH_SINGLE Handling Diverges from zcashd for Corresponding Outputs
GHSA-cwfq-rfcr-8hmp
pkg: zebrad
eco: rust
published: May 7, 2026
# `Zebra` Transparent `SIGHASH_SINGLE` Corresponding-Output Handling Diverges From `zcashd`

### Summary
For V5+ transparent spends, `Zebra` and `zcashd` disagree on the same consensus rule: `SIGHASH_SINGLE` must fail when the input index has no corresponding output. `zcashd` treats this as consensu…

GitHub-GHSA

CRITICAL
Zebra has Consensus Divergence in Transparent Sighash Hash-Type Handling due to Stale Buffer
GHSA-gq4h-3grw-2rhv
pkg: zebra-script, zebrad
eco: rust
published: May 7, 2026
# CVE-2026-44497: Consensus Divergence in Transparent Sighash Hash-Type Handling due to Stale Buffer

## Summary

The fix for https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-8m29-fpq5-89jj introduced a separate issue due to insuficient error handling of the case where the sighash t…

CVE-2026-44497
GitHub-GHSA

CRITICAL
Zebra's Block Validator Undercounts Coinbase and P2SH Sigops
GHSA-jv4h-j224-23cc
pkg: zebrad
eco: rust
published: May 7, 2026
Zebra's block validator undercounts transparent signature operations against the 20000-sigop block limit (`MAX_BLOCK_SIGOPS`), allowing it to accept blocks that `zcashd` rejects with `bad-blk-sigops`. A miner who produces such a block can split the network: Zebra nodes follow the offending chain whi…
CVE-2026-44498
GitHub-GHSA

CRITICAL
Compromise of PyTorch Lightning PyPi Package Versions
GHSA-w37p-236h-pfx3
pkg: pytorch-lightning, pytorch-lightning
eco: pip
published: May 7, 2026
# Security Advisory: Compromise of PyTorch Lightning PyPI Package Versions

**Published:** 2026-04-30
**Last Updated:** 2026-04-30

Lightning AI has identified a security incident affecting certain versions of a PyPI package.

## What happened

Lightning AI has determined that one or more releas…

CVE-2026-44484
GitHub-GHSA

CRITICAL
misp-modules website – Missing CSRF protection in the website home blueprint
GHSA-j4rh-7jcr-qm69
pkg: misp-modules
eco: pip
published: May 6, 2026
A Cross-Site Request Forgery vulnerability in the MISP Modules website allowed an attacker to cause an authenticated user to submit unintended requests to the home endpoint. The vulnerability was due to the home blueprint being exempted from CSRF protection. This could allow modification of session …
CVE-2026-44364
GitHub-GHSA

CRITICAL
DevGuard has an unauthenticated identity assertion via `X-Admin-Token` header
GHSA-2g9v-7mr5-fgjg
pkg: github.com/l3montree-dev/devguard
eco: go
published: May 5, 2026
### Impact
The `SessionMiddleware` accepts a client-supplied `X-Admin-Token` HTTP request header and uses its raw string value as the authenticated `userID` when no Kratos session cookie is present. An unauthenticated attacker who knows or can guess a target user's Kratos identity UUID can issue req…
CVE-2026-42300
GitHub-GHSA

CRITICAL
MagicMirror vulnerable to unauthenticated SSRF via /cors endpoint
GHSA-ph6f-2cvq-79hq
pkg: magicmirror
eco: npm
published: May 5, 2026
### Summary

An unauthenticated Server-Side Request Forgery (SSRF) vulnerability in the `/cors` endpoint allows any remote attacker to force the MagicMirror² server to perform arbitrary HTTP requests to internal networks, cloud metadata services, and localhost services. The endpoint also expands en…

CVE-2026-42281
GitHub-GHSA

CRITICAL
django-s3file is vulnerable to relative path traversal
GHSA-67qg-7284-2277
pkg: django-s3file
eco: pip
published: May 5, 2026
### Impact
`S3FileMiddleware` is vulnerable to relative path traversal attacks, where an attacker can use a modified request to escape pre-signed upload locations and have the Django application load files from random locations into `request.FILES`

Depending on how files are handled, this may lead …

CVE-2026-42196
GitHub-GHSA

CRITICAL
`mysten-metrics` was removed from crates.io for malicious code
GHSA-g38r-8gmr-ghrf
pkg: mysten-metrics
eco: rust
published: May 4, 2026
`mysten-metrics` included a build script that attempted to exfiltrate data from the build machine.

The malicious crate had 1 version published on 2026-04-20 and had no evidence of actual usage. This crate had no dependencies on crates.io.

GitHub-GHSA

CRITICAL
`sui-execution-cut` was removed from crates.io for malicious code
GHSA-qprh-m6p3-hwxc
pkg: sui-execution-cut
eco: rust
published: May 4, 2026
`sui-execution-cut` included a build script that attempted to exfiltrate data from the build machine.

The malicious crate had 1 version published on 2026-04-20 and had no evidence of actual usage. This crate had no dependencies on crates.io.

GitHub-GHSA

HIGH
Electerm Security Vulnerability: RCE via malicious SSH server filename in openFileWithEditor
GHSA-q4p8-8j9m-8hxj
pkg: electerm
eco: npm
published: May 8, 2026
### Impact

A code execution (RCE) vulnerability exists in electerm's SFTP open with system editor or "Edit with custom editor" feature. When a user opts to edit a file using open with system editor or open with a custom editor, the filename is passed directly into a command line without sanitizatio…

CVE-2026-43943
GitHub-GHSA

HIGH
Electerm has an unvalidated shell.openExternal that allows arbitrary protocol execution via terminal link click
GHSA-fwf6-j56g-m97c
pkg: electerm
eco: npm
published: May 8, 2026
### Impact

Electerm's terminal hyperlink handler passes any URL clicked in the terminal directly to `shell.openExternal` without any protocol validation.

When a user connects to a malicious SSH server, the attacker can print a crafted URI in the terminal output. If the victim clicks the link, `she…

CVE-2026-43941
NVD

HIGH
CVE-2026-42215
CVE-2026-42215
pkg: python

published: May 7, 2026

GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as –upload-pack and –receive-pack by default, but the equivalent Python kwargs upload_pack and receive_pack bypass that check. If an appli…
CWE: CWE-78
NVD

HIGH
CVE-2025-63705
CVE-2025-63705
pkg: node

published: May 7, 2026

NPM package node-ts-ocr 1.0.15 is vulnerable to OS Command Injection via the invokeImageOcr function in src/index.js.
CWE: CWE-78
NVD

HIGH
CVE-2026-41139
CVE-2026-41139
pkg: mathjs mathjs

published: May 7, 2026

Math.js is an extensive math library for JavaScript and Node.js. From version 13.1.0 to before version 15.2.0, arbitrary JavaScript can be executed via the expression parser of mathjs. This issue has been patched in version 15.2.0.
CWE: CWE-915
GitHub-GHSA

HIGH
Diffusers has a `trust_remote_code` bypass via `custom_pipeline` and local custom components
GHSA-98h9-4798-4q5v
pkg: diffusers
eco: pip
published: May 7, 2026
### Impact

A `trust_remote_code` bypass in `DiffusionPipeline.from_pretrained` allows arbitrary remote code execution despite the user passing `trust_remote_code=False` (or omitting it, which is the default). The vulnerability has three variants, all sharing the same root cause — the `trust_remot…

CVE-2026-44513
GitHub-GHSA

HIGH
Diffusers has a `trust_remote_code` bypass via `custom_pipeline` and local custom components
GHSA-j7w6-vpvq-j3gm
pkg: diffusers
eco: pip
published: May 7, 2026
## Background

This vulnerability is found in the `DiffusionPipeline.from_pretrained` flow, which is used to load a pipeline from the HuggingFace Hub.

This function accepts an optional `custom_pipeline` keyword argument: the name of a Python file in the repo that contains a custom class inheriting …

CVE-2026-44827
GitHub-GHSA

HIGH
rmcp Streamable HTTP server transport has a DNS rebinding vulnerability
GHSA-89vp-x53w-74fx
pkg: rmcp
eco: rust
published: May 6, 2026
## Summary

Prior to version 1.4.0, the `rmcp` crate's Streamable HTTP server transport (`crates/rmcp/src/transport/streamable_http_server/`) did not validate the incoming `Host` header. This allowed a malicious public website, via a DNS rebinding attack, to send authenticated requests to an MCP ser…

CVE-2026-42559
NVD

HIGH
CVE-2026-8000
CVE-2026-8000
pkg: google chrome, apple macos, linux linux_kernel

published: May 6, 2026

Insufficient validation of untrusted input in ChromeDriver in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)
CWE: CWE-20
NVD

HIGH
CVE-2026-7973
CVE-2026-7973
pkg: google chrome, microsoft windows

published: May 6, 2026

Integer overflow in Dawn in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-472
NVD

HIGH
CVE-2026-7928
CVE-2026-7928
pkg: google chrome, microsoft windows

published: May 6, 2026

Use after free in WebRTC in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-7907
CVE-2026-7907
pkg: google chrome, apple macos, linux linux_kernel

published: May 6, 2026

Use after free in DOM in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-7906
CVE-2026-7906
pkg: google chrome, apple macos, linux linux_kernel

published: May 6, 2026

Use after free in SVG in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-7903
CVE-2026-7903
pkg: google chrome, apple macos, microsoft windows

published: May 6, 2026

Integer overflow in ANGLE in Google Chrome on Mac,Windows prior to 148.0.7778.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-472
NVD

HIGH
CVE-2026-7902
CVE-2026-7902
pkg: google chrome, apple macos, linux linux_kernel

published: May 6, 2026

Out of bounds memory access in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-787, CWE-125
NVD

HIGH
CVE-2026-7901
CVE-2026-7901
pkg: google chrome, apple macos

published: May 6, 2026

Use after free in ANGLE in Google Chrome on Mac prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-7899
CVE-2026-7899
pkg: google chrome, apple macos, linux linux_kernel

published: May 6, 2026

Out of bounds read and write in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-125, CWE-787
NVD

HIGH
CVE-2026-7898
CVE-2026-7898
pkg: google chrome, linux linux_kernel

published: May 6, 2026

Use after free in Chromoting in Google Chrome on Linux prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-7896
CVE-2026-7896
pkg: google chrome, apple macos, linux linux_kernel

published: May 6, 2026

Integer overflow in Blink in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-472
NVD

HIGH
CVE-2026-42503
CVE-2026-42503
pkg: go

published: May 6, 2026

gopls by default communicates via pipe. However, -port and -listen flags are supported as means of debugging.
If -listen is given a value without an explicit host (e.g. :8080), or -port is used, gopls will listen on 0.0.0.0. 
As a result, users might inadvertently cause gopls to bind 0.0.0.0.
This…
CWE: CWE-1327
NVD

HIGH
CVE-2026-43158
CVE-2026-43158
pkg: go

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

xfs: fix freemap adjustments when adding xattrs to leaf blocks

xfs/592 and xfs/794 both trip this assertion in the leaf block freemap
adjustment code after ~20 minutes of running on my test VMs:

ASSERT(ichdr->firstused >= ichdr-…

GitHub-GHSA

HIGH
@evomap/evolver: Path Traversal in `evolver fetch` default-branch `safeId` allows Hub-controlled overwrite of project files (RCE)
GHSA-cfcj-hqpf-hccf
pkg: @evomap/evolver
eco: npm
published: May 5, 2026
## Summary

The `evolver fetch` subcommand in `index.js` writes Hub-supplied `bundled_files[]` into a directory derived from a Hub-supplied `skill_id`. When `–out` is not used, the path-sanitizing regex permits `.` characters, allowing a `skill_id` of `..` to escape the `skills/` subdirectory and r…

GitHub-GHSA

HIGH
Hysteria: A specially constructed quic package can crash the server OOM when the sniff is enabled
GHSA-9fw6-xgg2-mq9q
pkg: github.com/apernet/hysteria/core/v2
eco: go
published: May 5, 2026
### Summary

A specially constructed quic package can crash the server OOM when the sniff is enabled.

### Details

When the server has sniff enabled, a valid connection can request the server to forward UDP traffic and construct a huge crypto length. The server will allocate memory according to thi…

GitHub-GHSA

HIGH
JupyterHub has an Extension Manager API/GUI Policy Discrepancy, allowing 3rd party (malicious) extensions install via POST request
GHSA-37w4-hwhx-4rc4
pkg: jupyterlab
eco: pip
published: May 5, 2026
The allow-list of extensions that can be installed from PyPI Extension Manager (`allowed_extensions_uris`) is not correctly enforced by JupyterLab prior to 4.5.X. The PyPI Extension Manager was not contained to packages listed on the default PyPI index.

This has security implications for deployment…

CVE-2026-42266
GitHub-GHSA

HIGH
YAFNET: Pre-Handler Authorization Bypass on Admin Pages Enables Blind SQL Execution via `/Admin/RunSql`
GHSA-xhw7-j96h-c3g5
pkg: YAFNET.Core
eco: nuget
published: May 5, 2026
**Issue Details:**
YAFNET's only admin authorization gate is `PageSecurityCheckAttribute`, implemented as a `ResultFilterAttribute` that runs *after* the page handler completes rather than before it. No other gate exists. Any admin `OnPost…` handler therefore executes its side effects before the f…
CVE-2026-43937
NVD

HIGH
CVE-2026-34464
CVE-2026-34464
pkg: sandboxie-plus sandboxie

published: May 5, 2026

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, NamedPipeServer::OpenHandler copies the server field from NAMED_PIPE_OPEN_REQ into a fixed WCHAR pipename[160] stack buffer using wcscat without verifying null termination. The handler only…
CWE: CWE-121, CWE-170
NVD

HIGH
CVE-2026-34459
CVE-2026-34459
pkg: sandboxie-plus sandboxie

published: May 5, 2026

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, the SbieSvc proxy service's GetRawInputDeviceInfoSlave handler contains two vulnerabilities that can be chained for sandbox escape. First, when a sandboxed process sends an IPC request with…
CWE: CWE-121
NVD

HIGH
CVE-2026-34458
CVE-2026-34458
pkg: sandboxie-plus sandboxie

published: May 5, 2026

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, an INI injection vulnerability allows any standard local user to bypass configuration restrictions (EditAdminOnly and ConfigPassword) and inject arbitrary directives into the global Sandbox…
CWE: CWE-93
GitHub-GHSA

HIGH
OpenClaw's gateway config mutation guard allowed unsafe model-driven config writes
GHSA-cwj3-vqpp-pmxr
pkg: openclaw
eco: npm
published: May 5, 2026
## Summary

The agent-facing `gateway` tool protects `config.apply` and `config.patch` with a model-to-operator trust boundary. That guard used a hand-maintained denylist of protected config paths. The config schema outgrew that denylist, leaving sensitive subtrees writable through model-driven gate…

NVD

HIGH
CVE-2026-42434
CVE-2026-42434
pkg: node

published: May 5, 2026

OpenClaw versions 2026.4.5 before 2026.4.10 contain a sandbox escape vulnerability allowing sandboxed agents to override exec routing by specifying host=node. Attackers can bypass sandbox boundaries and route execution to remote nodes instead of intended sandbox paths.
CWE: CWE-863
NVD

HIGH
CVE-2026-42237
CVE-2026-42237
pkg: n8n n8n

published: May 4, 2026

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the fix for GHSA-f3f2-mcxc-pwjx did not cover the Snowflake node or the legacy MySQL v1 node. Both nodes construct SQL queries by directly interpolating user-controlled table names, column names, and …
CWE: CWE-89
NVD

HIGH
CVE-2026-42234
CVE-2026-42234
pkg: n8n n8n

published: May 4, 2026

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated user with permission to create or modify workflows containing a Python Code Node could escape the sandbox and achieve arbitrary code execution on the task runner container. This issue…
CWE: CWE-94
NVD

HIGH
CVE-2026-42232
CVE-2026-42232
pkg: n8n n8n

published: May 4, 2026

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated user with permission to create or modify workflows could achieve global prototype pollution via the XML Node leading to RCE when combined with other nodes exploiting the prototype pol…
CWE: CWE-1321
NVD

HIGH
CVE-2026-42231
CVE-2026-42231
pkg: n8n n8n

published: May 4, 2026

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the xml2js library used to parse XML request bodies in n8n's webhook handler allowed prototype pollution via a crafted XML payload. An authenticated user with permission to create or modify …
CWE: CWE-1321
NVD

HIGH
CVE-2026-42229
CVE-2026-42229
pkg: n8n n8n

published: May 4, 2026

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the SeaTable node's row:search and row:get operations allowed user-controlled input to be concatenated directly into SQL query strings without escaping or parameterization. In workflows wher…
CWE: CWE-89
NVD

HIGH
CVE-2026-29514
CVE-2026-29514
pkg: express

published: May 4, 2026

NetBox versions 4.3.5 through 4.5.4 contain a remote code execution vulnerability in the RenderTemplateMixin.get_environment_params() method that allows authenticated users with exporttemplate or configtemplate permissions to execute arbitrary code by specifying malicious Python callables in the env…
CWE: CWE-183
GitHub-GHSA

HIGH
Open WebUI: Redis Cache Keys tool_servers and terminal_servers Missing Instance Prefix Enable Cross-Instance Cache Poisoning
GHSA-3x8w-4f7p-xxc2
pkg: open-webui
eco: pip
published: May 8, 2026
# Redis Cache Keys tool_servers and terminal_servers Missing Instance Prefix Enable Cross-Instance Cache Poisoning

## Affected Component

Tool server and terminal server Redis cache:
– `backend/open_webui/utils/tools.py` (line 841, tool_servers SET)
– `backend/open_webui/utils/tools.py` (line 850, …

CVE-2026-44552
GitHub-GHSA

HIGH
netbox-data-flows has stored XSS in ObjectAlias names rendered inside DataFlow tables
GHSA-v7qw-hx66-4w9x
pkg: netbox-data-flows
eco: pip
published: May 7, 2026
### Summary
An authenticated user who can create or edit `ObjectAlias` objects can store arbitrary HTML/JavaScript in an alias name. That payload is later rendered unescaped in `DataFlow` table views, causing a stored XSS when another user views the affected page.

### Details
The issue is caused by…

NVD

HIGH
CVE-2026-42352
CVE-2026-42352
pkg: python

published: May 8, 2026

pygeoapi is a Python server implementation of the OGC API suite of standards. From version 0.23.0 to before version 0.23.3, OGC API process execution requests can use the subscriber object to requests to internal HTTP services. This issue has been patched in version 0.23.3.
CWE: CWE-918
NVD

HIGH
CVE-2026-41690
CVE-2026-41690
pkg: express

published: May 8, 2026

18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. Versions prior to 3.9.3 allow an unauthenticated HTTP client to pollute Object.prototype in the Node.js process hosting the middleware, via two unvalidated entry points that reach…
CWE: CWE-22, CWE-1321
NVD

HIGH
CVE-2026-41683
CVE-2026-41683
pkg: express

published: May 8, 2026

i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. Prior to version 3.9.3, i18next-http-middleware wrote user-controlled language values into the Content-Language response header after passing them through utils.escape(), which i…
CWE: CWE-79, CWE-113
NVD

HIGH
CVE-2026-42047
CVE-2026-42047
pkg: express

published: May 7, 2026

Inngest is a platform for running event-driven and scheduled background functions with queueing, retries, and step orchestration. Versions 3.22.0 through 3.53.1 contain a vulnerability that allows unauthenticated remote attackers to exfiltrate environment variables from the host process via the serv…
CWE: CWE-200, CWE-497
GitHub-GHSA

HIGH
vm2 has a Sandbox Escape via Promise Constructor Unhandled Rejection (Process Crash DoS)
GHSA-hw58-p9xv-2mjh
pkg: vm2
eco: npm
published: May 7, 2026
### Summary
A sandbox escape vulnerability in vm2 v3.10.5 allows any sandboxed code to crash the host Node.js process via a single Promise constructor that triggers an unhandled rejection propagating to the host. The fix for CVE-2026-22709 (v3.10.2) only sanitized the `onRejected` callback in `.then…
CVE-2026-44001
GitHub-GHSA

HIGH
Harvester's SUSE Virtualization Registration Client Vulnerable to MITM and DOS
GHSA-pgh9-mpwc-8jjf
pkg: github.com/harvester/harvester
eco: go
published: May 6, 2026
### Impact

A vulnerability has been identified in the [SUSE Virtualization (Harvester) Rancher integration mechanism](https://docs.harvesterhci.io/v1.7/rancher/rancher-integration) where by default the registration client uses an insecure TLS option that fails to verify the remote server’s certi…

CVE-2025-71261
GitHub-GHSA

HIGH
PPTAgent: Arbitrary Code Execution via Python eval() of LLM-Generated Code with Builtins in Scope
GHSA-89g2-xw5c-v95p
pkg: pptagent
eco: pip
published: May 5, 2026
## Summary

> This vulnerability has been fixed in https://github.com/icip-cas/PPTAgent/commit/418491a9a1c02d9d93194b5973bb58df35cf9d00.

`CodeExecutor.execute_actions` (pptagent/apis.py:126-205) processes LLM-generated slide editing actions using Python's `eval()`:

“`python
# pptagent/apis.py:18…

CVE-2026-42079
GitHub-GHSA

HIGH
Inngest TypeScript SDK exposes environment variables via serve() handler on unhandled HTTP methods
GHSA-2jf5-6wwv-vhxx
pkg: inngest
eco: npm
published: May 5, 2026
# Summary

A vulnerability in the Inngest TypeScript SDK versions `3.22.0` through `3.53.1` allows unauthenticated remote attackers to exfiltrate environment variables from the host process via the `serve()` HTTP handler.

The `serve()` handler implements `GET`, `POST`, and `PUT` methods. Requests u…

CVE-2026-42047
NVD

HIGH
CVE-2026-42079
CVE-2026-42079
pkg: python

published: May 4, 2026

PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, PPTAgent is vulnerable to arbitrary code execution via Python eval() of LLM-generated code with builtins in scope. This issue has been patched via commit 418491a.
CWE: CWE-95
NVD

HIGH
CVE-2026-42449
CVE-2026-42449
pkg: node

published: May 7, 2026

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. In versions 2.47.4 through 2.47.13, the SDK embedder path (N8NDocumentationMCPServer constructor, getN8nApiClient(), and validateInstanceContext()), the synchronous URL validator in SSR…
CWE: CWE-918
GitHub-GHSA

HIGH
vm2 has a NodeVM require.root bypass via symlink traversal that allows sandbox escape
GHSA-cp6g-6699-wx9c
pkg: vm2
eco: npm
published: May 7, 2026
## Summary
NodeVM's `require.root` path restriction can be bypassed using filesystem symlinks, allowing sandboxed code to load modules from outside the allowed root directory in host context. Because path validation uses `path.resolve()` (which does not dereference symlinks) but module loading uses …
CVE-2026-43998
GitHub-GHSA

HIGH
Rancher Extensions have arbitrary file access via path traversal
GHSA-5v3h-x4wf-5c35
pkg: github.com/rancher/rancher, github.com/rancher/rancher, github.com/rancher/rancher
eco: go
published: May 7, 2026
### Impact

A vulnerability has been identified in [Rancher's Extensions](https://ranchermanager.docs.rancher.com/integrations-in-rancher/rancher-extensions) where malicious code can be injected in Rancher through a path traversal in the `compressedEndpoint` field inside a `UIPlugin` deployment. A m…

CVE-2026-25705
GitHub-GHSA

HIGH
PraisonAI has unauthenticated RCE via `tool_override.py` (CVE-2026-40287 patch bypass)
GHSA-xcmw-grxf-wjhj
pkg: praisonai
eco: pip
published: May 6, 2026
## TL;DR

CVE-2026-40287's fix gated `tools.py` auto-import behind `PRAISONAI_ALLOW_LOCAL_TOOLS=true` in **two** files (`tool_resolver.py`, `api/call.py`). A **third** import sink in `praisonai/templates/tool_override.py` was missed and remains unguarded. It is reached by the recipe runner on every …

CVE-2026-44334
GitHub-GHSA

HIGH
Velocity.js has a Prototype Pollution vulnerability through #set path assignment
GHSA-j658-c2gf-x6pq
pkg: velocityjs
eco: npm
published: May 9, 2026
### Summary
A prototype pollution vulnerability was discovered in Velocity.js <= 2.1.5. This issue occurs during the processing of #set directives in Velocity templates. If an application renders a template controlled by an attacker, it is possible to modify Object.prototype, potentially leading to …
CVE-2026-44966
GitHub-GHSA

HIGH
n8n-mcp affected by path traversal, redirect-following SSRF, and telemetry payload exposure
GHSA-8g7g-hmwm-6rv2
pkg: n8n-mcp
eco: npm
published: May 8, 2026
## Impact

`n8n-mcp` versions before 2.50.1 contained three independently-reported issues affecting deployments that run the n8n API integration:

1. **Caller-supplied identifiers were not validated before being used as URL path segments** by the n8n API client. An authenticated MCP caller passing a…

NVD

HIGH
CVE-2026-41422
CVE-2026-41422
pkg: express

published: May 7, 2026

Daptin is a GraphQL/JSON-API headless CMS. Prior to version 0.11.4, the /aggregate/:typename endpoint accepted column and group query parameters that were passed verbatim to goqu.L() — a raw SQL literal expression builder — without any validation. This bypassed all parameterization and allowed a…
CWE: CWE-89
NVD

HIGH
CVE-2026-7917
CVE-2026-7917
pkg: google chrome, microsoft windows

published: May 6, 2026

Use after free in Fullscreen in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-7914
CVE-2026-7914
pkg: google chrome, microsoft windows

published: May 6, 2026

Type Confusion in Accessibility in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-843
NVD

HIGH
CVE-2026-7911
CVE-2026-7911
pkg: google chrome, microsoft windows

published: May 6, 2026

Use after free in Aura in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-7905
CVE-2026-7905
pkg: google chrome, google android

published: May 6, 2026

Insufficient validation of untrusted input in Media in Google Chrome on Android prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-20
NVD

HIGH
CVE-2026-7900
CVE-2026-7900
pkg: google chrome, apple macos, linux linux_kernel

published: May 6, 2026

Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-122
GitHub-GHSA

HIGH
LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists
GHSA-pjwx-r37v-7724
pkg: langchain-core, langchain-core
eco: pip
published: May 8, 2026
LangChain contains older runtime code paths that deserialize run inputs, run outputs, or other application-controlled payloads using overly broad object allowlists. These paths may call `load()` with `allowed_objects="all"`. This does not enable arbitrary Python object deserialization, but it does a…
CVE-2026-44843
GitHub-GHSA

HIGH
free5GC's SMF UPI DELETE /upi/v1/upNodesLinks/{ref} panics on AN-node deletion via nil UPF dereference; unauthenticated, state-mutating
GHSA-p9mg-74mg-cwwr
pkg: github.com/free5gc/smf
eco: go
published: May 8, 2026
### Summary
free5GC's SMF mounts the `UPI` management route group without inbound OAuth2 middleware (same root cause as the broader UPI auth gap reported in free5gc/free5gc#887). On top of that, the `DELETE /upi/v1/upNodesLinks/{upNodeRef}` handler unconditionally dereferences `upNode.UPF` after the…
CVE-2026-44328
GitHub-GHSA

HIGH
@babel/plugin-transform-modules-systemjs generates arbitrary code when compiling malicious input
GHSA-fv7c-fp4j-7gwp
pkg: @babel/plugin-transform-modules-systemjs, @babel/plugin-transform-modules-systemjs
eco: npm
published: May 8, 2026
### Impact

Using Babel to compile code that was specifically crafted by an attacker can cause Babel to generate output code that executes arbitrary code.

Known affected plugins are:
– `@babel/plugin-transform-modules-systemjs`
– `@babel/preset-env` when using the [`modules: "systemjs"` option](htt…

CVE-2026-44728
NVD

HIGH
CVE-2026-42353
CVE-2026-42353
pkg: express

published: May 8, 2026

i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. Prior to version 3.9.3, i18next-http-middleware passes the user-controlled lng and ns values from getResourcesHandler directly into i18next.services.backendConnector.load(languag…
CWE: CWE-22, CWE-918
GitHub-GHSA

HIGH
Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosure of subscriber SUPI
GHSA-6rgm-gr97-x3j5
pkg: github.com/free5gc/pcf
eco: go
published: May 7, 2026
### Summary
PCF Npcf_SMPolicyControl missing authentication middleware allows unauthenticated access to SM policy handlers and disclosure of subscriber SUPI
### Details
In `NewServer()`, the `smPolicyGroup` route group is created and routes are applied without attaching the router authorization midd…
CVE-2026-42083
GitHub-GHSA

HIGH
Gotenberg has a Server-Side Request Forgery (SSRF) Issue
GHSA-rm4c-xj6x-49mw
pkg: github.com/gotenberg/gotenberg/v8
eco: go
published: May 7, 2026
### Summary

The SSRF hardening shipped in v8.31.0 only covers outbound URLs that Gotenberg's Go code handles — Chromium asset fetches, webhook delivery, and download-from. The LibreOffice conversion endpoint (`/forms/libreoffice/convert`) passes uploaded documents directly to LibreOffice without …

CVE-2026-42591
GitHub-GHSA

HIGH
Gotenberg's ExifTool group-prefix syntax bypasses dangerous-tag blocklist
GHSA-7v3r-m9c8-r855
pkg: github.com/gotenberg/gotenberg/v8
eco: go
published: May 7, 2026
**Summary**

The ExifTool metadata write blocklist in Gotenberg v8 can be bypassed using ExifTool's group-prefix syntax, enabling arbitrary file rename, move, hardlink, and symlink creation on the server. This is a bypass of the fix for GHSA-qmwh-9m9c-h36m.

**Details**

The blocklist in `pkg/module…

CVE-2026-42590
NVD

HIGH
CVE-2026-39852
CVE-2026-39852
pkg: quarkus quarkus

published: May 5, 2026

Quarkus is a Java framework for building cloud-native applications. In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3.35.1.1, 3.34.7, and 3.35.2, a path normalization inconsistency between the security layer and the routing layer allows unauthenticated or lower-privileged users to bypass HTTP pat…
CWE: CWE-863
GitHub-GHSA

HIGH
open-websearch has SSRF in `fetchWebContent` MCP tool: bracketed IPv6 literals and non-resolving hostname check bypass `isPrivateOrLocalHostname`
GHSA-v228-72c7-fx8j
pkg: open-websearch
eco: npm
published: May 5, 2026
### Summary
`src/utils/urlSafety.ts` exposes `isPublicHttpUrl` / `assertPublicHttpUrl`, used to gate the MCP `fetchWebContent` tool against private-network targets. The check has two defects that together allow **non-blind SSRF with the response body returned to the caller**:

1. **Bracketed IPv6 li…

CVE-2026-42260
GitHub-GHSA

HIGH
ssrfcheck Vulnerable to Server-Side Request Forgery (SSRF) and Incomplete List of Disallowed Inputs
GHSA-j4rj-2jr5-m439
pkg: ssrfcheck
eco: npm
published: May 5, 2026
### Summary

`ssrfcheck` v1.3.0 (latest) fails to block Server-Side Request Forgery attacks when the target private IP address is encoded as an IPv4-mapped IPv6 address (e.g. `http://[::ffff:127.0.0.1]/`). The WHATWG URL parser built into Node.js silently normalizes the IPv4 notation inside the brac…

CVE-2026-43929
GitHub-GHSA

HIGH
exiftool-vendored vulnerable to argument injection via newline characters in tag names
GHSA-cw26-7653-2rp5
pkg: exiftool-vendored
eco: npm
published: May 5, 2026
### Impact

`exiftool-vendored` starts ExifTool in `-stay_open True -@ -` mode, where arguments are read from stdin one per line. In affected versions, several caller-supplied strings were interpolated into ExifTool arguments without rejecting line delimiters. A newline or carriage return inside one…

CVE-2026-43893
GitHub-GHSA

HIGH
Quarkus has Authentication/Authorization bypasses
GHSA-rc95-pcm8-65v9
pkg: io.quarkus:quarkus-vertx-http, io.quarkus:quarkus-vertx-http, io.quarkus:quarkus-vertx-http
eco: maven
published: May 4, 2026
Quarkus version 3.32.4 is vulnerable to an authorization bypass issue (GHSL-2026-099), in which semicolons (matrix parameters) in HTTP requests can be used to bypass security constraints, potentially allowing unauthorized access to protected resources.

Unauthenticated or lower-privileged users can …

CVE-2026-39852
NVD

HIGH
CVE-2026-42296
CVE-2026-42296
pkg: kubernetes

published: May 9, 2026

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to versions 3.7.14 and 4.0.5, a user with create Workflow permission can bypass templateReferencing: Strict to get host network access, switch service accounts, override pod securit…
CWE: CWE-863
GitHub-GHSA

HIGH
epa4all-client has a VAU Signature bypass
GHSA-g8r3-5hwf-qp96
pkg: com.oviva.telematik:epa4all-client
eco: maven
published: May 8, 2026
### Impact
In SignedPublicKeysTrustValidatorImpl.isTrusted(), the ECDSA signature verification at line 45 discards the boolean return value of Signature.verify(). The method performs certificate chain validation, OCSP check, and signature algorithm setup, but never checks whether the signature actua…
CVE-2026-44900
NVD

HIGH
CVE-2026-42452
CVE-2026-42452
pkg: jwt

published: May 8, 2026

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.1.0, /users/login issues a temporary JWT (temp_token) for TOTP-enabled accounts. That token carries a pendingTOTP state and should only be valid for the second-factor flow…
CWE: CWE-304
GitHub-GHSA

HIGH
Open WebUI has Knowledge Base Destruction and RAG Poisoning via Unauthorized Collection Overwrite
GHSA-7r82-qhg4-6wvj
pkg: open-webui
eco: pip
published: May 8, 2026
# Knowledge Base Destruction and RAG Poisoning via Unauthorized Collection Overwrite

## Affected Component

Retrieval web/YouTube processing endpoints:
– `backend/open_webui/routers/retrieval.py` (lines 1810-1837, `process_web`)
– `backend/open_webui/routers/retrieval.py` (the parallel `process_you…

CVE-2026-44554
GitHub-GHSA

HIGH
Open WebUI: Stale Admin Role in Socket.IO Session Pool Enables Post-Demotion Cross-User Note Access
GHSA-45m8-cpm2-3v65
pkg: open-webui
eco: pip
published: May 8, 2026
# Stale Admin Role in Socket.IO Session Pool Enables Post-Demotion Cross-User Note Access

## Affected Component

Socket.IO session state and role-check callsites:
– `backend/open_webui/socket/main.py` (lines 330-351, `connect` handler — role snapshotted into SESSION_POOL)
– `backend/open_webui/so…

CVE-2026-44553
NVD

HIGH
CVE-2026-41883
CVE-2026-41883
pkg: express

published: May 8, 2026

OmniFaces is a utility library for Faces. Prior to versions 1.14.2, 2.7.32, 3.14.16, 4.7.5, and 5.2.3, there is a server-side EL injection leading to Remote Code Execution (RCE). This affects applications that use CDNResourceHandler with a wildcard CDN mapping (e.g. libraryName:*=https://cdn.example…
CWE: CWE-917
NVD

HIGH
CVE-2026-42239
CVE-2026-42239
pkg: jwt

published: May 7, 2026

Budibase is an open-source low-code platform. Prior to version 3.35.10, the budibase:auth cookie containing the JWT session token is set with httpOnly: false at packages/backend-core/src/utils/utils.ts:218. JavaScript can read this cookie via document.cookie. This means every XSS becomes a full acco…
CWE: CWE-1004
NVD

HIGH
CVE-2026-42284
CVE-2026-42284
pkg: gitpython_project gitpython

published: May 7, 2026

GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_options as the original list, then executes shlex.split(" ".join(multi_options)). A string like "–branch main –config core.hooksPath=/x" passes validation (starts with –branch),…
CWE: CWE-88
NVD

HIGH
CVE-2026-33588
CVE-2026-33588
pkg: lfnovo open-notebook

published: May 7, 2026

Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to create or modify files on the docker container via path traversal.
CWE: CWE-20
GitHub-GHSA

HIGH
opentelemetry-collector-contrib's azureauthextension Authenticate method does not validate bearer tokens, allowing auth bypass via replay
GHSA-pjv4-3c63-699f
pkg: github.com/open-telemetry/opentelemetry-collector-contrib/extension/azureauthextension
eco: go
published: May 6, 2026
### Summary

A server-side authentication bypass in `azureauthextension` allows any party who holds a single valid Azure access token for *any scope the collector's configured identity can mint for* to authenticate to any OpenTelemetry receiver that uses `auth: azure_auth`. The extension's `Authenti…

CVE-2026-42602
GitHub-GHSA

HIGH
Lemur: LDAP Filter Injection enables post-authentication privilege escalation
GHSA-3r34-vq8m-39gh
pkg: lemur
eco: pip
published: May 6, 2026
## Description

### Overview

Lemur's LDAP authentication module (`lemur/auth/ldap.py`) constructs LDAP search filters using unsanitized user input via Python string interpolation. An authenticated LDAP user can inject LDAP filter metacharacters through the username field to manipulate group members…

CVE-2026-44304
GitHub-GHSA

HIGH
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover
GHSA-mxqh-q9h6-v8pq
pkg: github.com/0xJacky/nginx-ui
eco: go
published: May 6, 2026
## Summary

An unauthenticated bootstrap takeover exists in `nginx-ui` during the initial installation window exposed by `POST /api/install`.

When the instance is still uninitialized, `POST /api/install` is reachable without authentication and accepts attacker-controlled bootstrap data. The handler…

CVE-2026-42222
GitHub-GHSA

HIGH
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim
GHSA-h27v-ph7w-m9fp
pkg: github.com/0xJacky/Nginx-UI
eco: go
published: May 6, 2026
### Summary
An unauthenticated network attacker can claim the initial administrator account on a fresh `nginx-ui` instance during the first-run setup window. The public `/api/install` endpoint is reachable without authentication, and the request-encryption flow only protects payload confidentiality …
CVE-2026-42221
GitHub-GHSA

HIGH
PyLoad vulnerable to Path Traversal via Package Folder Name in set_package_data
GHSA-838g-gr43-qqg9
pkg: pyload-ng
eco: pip
published: May 5, 2026
### Summary
No sanitization of package folder name allows writing files anywhere outside the intended download directory.

#### Affected Component
– `src/pyload/core/api/__init__.py`
– Function: `set_package_data()`

### Details
When passing a folder name in the `set_package_data()` API function cal…

CVE-2026-42315
GitHub-GHSA

HIGH
@evomap/evolver's validator sandbox allowlist permits `npm`/`npx`, yielding RCE from Hub-delivered validation tasks via lifecycle scripts
GHSA-jxh8-jh77-xh6g
pkg: @evomap/evolver
eco: npm
published: May 5, 2026
## Summary

The validator-mode sandbox executor (`src/gep/validator/sandboxExecutor.js`) places `npm` and `npx` in its hard executable allowlist. Because `npm install <pkg>` and `npx -y -p <pkg> <bin>` execute arbitrary code by design (preinstall/install/postinstall lifecycle scripts and remote-pack…

GitHub-GHSA

HIGH
YAFNET has Unauthenticated Stored Second-Order XSS in Admin Event Log via Reflected `User-Agent` Header
GHSA-33gv-fc78-qgf5
pkg: YAFNET.Core, YAFNET.Core
eco: nuget
published: May 5, 2026
**Description:**
Stored (second-order) Cross-Site Scripting (XSS) occurs when attacker-controlled input is persisted through one component of an application and later rendered, without proper sanitization or contextual output encoding, by a completely different component — often one that implicitl…
CVE-2026-43938
GitHub-GHSA

HIGH
@tdurieux/anonymous_github Vulnerable to XSS via Unsanitized GitHub Repository Content Rendering in Anonymous GitHub Origin
GHSA-g485-8j3v-p6x8
pkg: @tdurieux/anonymous_github
eco: npm
published: May 5, 2026
### Summary

Anonymous GitHub fetches repository content (e.g., markdown files) from GitHub's API and renders it without sanitization. On the client side, markdown is parsed with `marked` (with `sanitize: false`) and injected into the DOM via `$sce.trustAsHtml()` + `ng-bind-html`, bypassing AngularJ…

NVD

HIGH
CVE-2026-42222
CVE-2026-42222
pkg: nginxui nginx_ui

published: May 4, 2026

Nginx UI is a web user interface for the Nginx web server. In version 2.3.5, an unauthenticated bootstrap takeover exists in nginx-ui during the initial installation window exposed by POST /api/install. At time of publication no public patches are available.
CWE: CWE-284, CWE-306
NVD

HIGH
CVE-2026-42221
CVE-2026-42221
pkg: nginxui nginx_ui

published: May 4, 2026

Nginx UI is a web user interface for the Nginx web server. From version 2.0.0 to before version 2.3.8, an unauthenticated network attacker can claim the initial administrator account on a fresh nginx-ui instance during the first-run setup window. The public /api/install endpoint is reachable without…
CWE: CWE-306
GitHub-GHSA

HIGH
Ech0's OAuth redirect URI validation ignores path component, enables exchange-code theft
GHSA-p64j-f4x9-wq66
pkg: github.com/lin-snow/Ech0
eco: go
published: May 7, 2026
## Summary

`parseAndValidateClientRedirect` at `internal/service/auth/auth.go:448` validates OAuth client-redirect URIs by comparing only scheme and host against the admin-configured allowlist. Path, query, and fragment are ignored. The initiator at `/oauth/:provider/login` embeds the caller-suppli…

NVD

HIGH
CVE-2026-42301
CVE-2026-42301
pkg: python

published: May 9, 2026

pyp2spec generates working Fedora RPM spec file for Python projects. Prior to version 0.14.1, pyp2spec was writing PyPI package metadata (e.g. the summary field) into the generated spec file without escaping RPM macro directives. When a packager then runs rpmbuild, those directives get evaluated, so…
CWE: CWE-20, CWE-94
NVD

HIGH
CVE-2026-8148
CVE-2026-8148
pkg: windows

published: May 8, 2026

NAVER MYBOX Explorer for Windows before 3.0.11.160 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM via registry manipulation due to improper privilege checks.
CWE: CWE-266
NVD

HIGH
CVE-2022-26522
CVE-2022-26522
pkg: windows

published: May 8, 2026

The socket connection handler in aswArPot.sys in the Avast and AVG Windows Anti Rootkit driver before 22.1 allows local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) due to a double fetch vulnerability at aswArPot+0xc4a3.
CWE: CWE-367
NVD

HIGH
CVE-2026-44244
CVE-2026-44244
pkg: python

published: May 7, 2026

GitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value() passes values to Python's configparser without validating for newlines. GitPython's own _write() converts embedded newlines into indented continuation lines (e.g. \n becomes \n\…
CWE: CWE-94
GitHub-GHSA

HIGH
gix-fs: Symlink prefix-reuse allows worktree escape during checkout
GHSA-f89h-2fjh-2r9q
pkg: gix-fs
eco: rust
published: May 7, 2026
### Summary

A malicious tree can be constructed that will, when checked out with gitoxide, permit writing an attacker-controlled symlink into any existing directory the user has write access to.

### Details

During checkout, all symlink index entries are deferred and created after regular files us…

CVE-2026-44471
GitHub-GHSA

HIGH
GitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPath
GHSA-v87r-6q3f-2j67
pkg: GitPython
eco: pip
published: May 6, 2026
`GitConfigParser.set_value()` passes values to Python's `configparser` without validating for newlines. GitPython's own `_write()` converts embedded newlines into indented continuation lines (e.g. `\n` becomes `\n\t`), but Git still accepts an indented `[core]` stanza as a section header — so the …
CVE-2026-44244
NVD

HIGH
CVE-2026-7994
CVE-2026-7994
pkg: google chrome, microsoft windows

published: May 6, 2026

Inappropriate implementation in Chromoting in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium)
CWE: CWE-269
NVD

HIGH
CVE-2026-7990
CVE-2026-7990
pkg: google chrome, microsoft windows

published: May 6, 2026

Insufficient validation of untrusted input in Updater in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium)
CWE: CWE-20
NVD

HIGH
CVE-2026-7925
CVE-2026-7925
pkg: google chrome, microsoft windows

published: May 6, 2026

Use after free in Chromoting in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-7913
CVE-2026-7913
pkg: google chrome, google android

published: May 6, 2026

Insufficient policy enforcement in DevTools in Google Chrome on Android prior to 148.0.7778.96 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: High)
CWE: CWE-693
NVD

HIGH
CVE-2026-43236
CVE-2026-43236
pkg: node

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

drm/atmel-hlcdc: fix use-after-free of drm_crtc_commit after release

The atmel_hlcdc_plane_atomic_duplicate_state() callback was copying
the atmel_hlcdc_plane state structure without properly duplicating the
drm_plane_state. In pa…

NVD

HIGH
CVE-2026-43211
CVE-2026-43211
pkg: go

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

PCI: Fix pci_slot_trylock() error handling

Commit a4e772898f8b ("PCI: Add missing bridge lock to pci_bus_lock()")
delegates the bridge device's pci_dev_trylock() to pci_bus_trylock() in
pci_slot_trylock(), but it forgets to remove…

NVD

HIGH
CVE-2026-43178
CVE-2026-43178
pkg: go

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

procfs: fix possible double mmput() in do_procmap_query()

When user provides incorrectly sized buffer for build ID for PROCMAP_QUERY
we return with -ENAMETOOLONG error. After recent changes this condition
happens later, after we …

NVD

HIGH
CVE-2026-43150
CVE-2026-43150
pkg: node

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

perf/arm-cmn: Reject unsupported hardware configurations

So far we've been fairly lax about accepting both unknown CMN models
(at least with a warning), and unknown revisions of those which we
do know, as although things do freque…

NVD

HIGH
CVE-2026-43116
CVE-2026-43116
pkg: linux linux_kernel

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

netfilter: ctnetlink: ensure safe access to master conntrack

Holding reference on the expectation is not sufficient, the master
conntrack object can just go away, making exp->master invalid.

To access exp->master safely:

– Grab …

CWE: CWE-362
NVD

HIGH
CVE-2026-43106
CVE-2026-43106
pkg: linux

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

cachefiles: fix incorrect dentry refcount in cachefiles_cull()

The patch mentioned below changed cachefiles_bury_object() to expect 2
references to the 'rep' dentry. Three of the callers were changed to
use start_removing_dentry(…

NVD

HIGH
CVE-2026-43093
CVE-2026-43093
pkg: linux

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

xsk: tighten UMEM headroom validation to account for tailroom and min frame

The current headroom validation in xdp_umem_reg() could leave us with
insufficient space dedicated to even receive minimum-sized ethernet
frame. Furthermo…

NVD

HIGH
CVE-2026-43091
CVE-2026-43091
pkg: linux

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

xfrm: Wait for RCU readers during policy netns exit

xfrm_policy_fini() frees the policy_bydst hash tables after flushing the
policy work items and deleting all policies, but it does not wait for
concurrent RCU readers to leave the…

NVD

HIGH
CVE-2026-43084
CVE-2026-43084
pkg: linux

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nfnetlink_queue: make hash table per queue

Sharing a global hash table among all queues is tempting, but
it can cause crash:

BUG: KASAN: slab-use-after-free in nfqnl_recv_verdict+0x11ac/0x15e0 [nfnetlink_queue]
[..]
n…

NVD

HIGH
CVE-2026-43078
CVE-2026-43078
pkg: linux

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

crypto: af_alg – Fix page reassignment overflow in af_alg_pull_tsgl

When page reassignment was added to af_alg_pull_tsgl the original
loop wasn't updated so it may try to reassign one more page than
necessary.

Add the check to th…

NVD

HIGH
CVE-2026-43076
CVE-2026-43076
pkg: linux

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

ocfs2: validate inline data i_size during inode read

When reading an inode from disk, ocfs2_validate_inode_block() performs
various sanity checks but does not validate the size of inline data. If
the filesystem is corrupted, an i…

NVD

HIGH
CVE-2026-43075
CVE-2026-43075
pkg: linux

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

ocfs2: fix out-of-bounds write in ocfs2_write_end_inline

KASAN reports a use-after-free write of 4086 bytes in
ocfs2_write_end_inline, called from ocfs2_write_end_nolock during a
copy_file_range splice fallback on a corrupted ocfs…

NVD

HIGH
CVE-2026-43074
CVE-2026-43074
pkg: linux

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

eventpoll: defer struct eventpoll free to RCU grace period

In certain situations, ep_free() in eventpoll.c will kfree the epi->ep
eventpoll struct while it still being used by another concurrent thread.
Defer the kfree() to an RCU…

NVD

HIGH
CVE-2026-34462
CVE-2026-34462
pkg: sandboxie-plus sandboxie

published: May 5, 2026

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, several ProcessServer handlers (KillAllHandler, SuspendAllHandler, and RunSandboxedHandler) copy a WCHAR boxname[34] field from request structures into WCHAR[40] stack buffers using wcscpy …
CWE: CWE-121, CWE-170
NVD

HIGH
CVE-2026-34461
CVE-2026-34461
pkg: sandboxie-plus sandboxie

published: May 5, 2026

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, the SbieIniServer RunSbieCtrl handler contains a stack buffer overflow. The MSGID_SBIE_INI_RUN_SBIE_CTRL message is handled before normal sandbox and impersonation checks, and for non-sandb…
CWE: CWE-121
GitHub-GHSA

HIGH
gitoxide: CommandForbiddenInModulesConfiguration Bypass in gix_submodule::File::update() Enables Arbitrary Command Execution via .gitmodules
GHSA-f26g-jm89-4g65
pkg: gix
eco: rust
published: May 5, 2026
### Summary

[`gix_submodule::File::update()`](https://github.com/GitoxideLabs/gitoxide/blob/main/gix-submodule/src/access.rs#L168) is the API that gates whether an attacker-supplied `.gitmodules` file may set `update = !<shell command>`. The function is designed to return `Err(CommandForbiddenInMod…

GitHub-GHSA

HIGH
OpenClaw vulnerable to arbitrary code execution via attacker-controlled setup-api.js loaded from cwd during env-key resolution
GHSA-r39h-4c2p-3jxp
pkg: openclaw
eco: npm
published: May 5, 2026
## Summary

OpenClaw's bundled plugin setup resolver could fall back to `process.cwd()` while resolving provider setup metadata. If a user ran an OpenClaw command from an attacker-controlled repository containing `extensions/<plugin>/setup-api.js`, OpenClaw could load and execute that JavaScript dur…

NVD

HIGH
CVE-2026-43070
CVE-2026-43070
pkg: linux

published: May 5, 2026

In the Linux kernel, the following vulnerability has been resolved:

bpf: Reset register ID for BPF_END value tracking

When a register undergoes a BPF_END (byte swap) operation, its scalar
value is mutated in-place. If this register previously shared a scalar ID
with another register (e.g., after a…

NVD

HIGH
CVE-2026-43063
CVE-2026-43063
pkg: linux

published: May 5, 2026

In the Linux kernel, the following vulnerability has been resolved:

xfs: don't irele after failing to iget in xfs_attri_recover_work

xlog_recovery_iget* never set @ip to a valid pointer if they return
an error, so this irele will walk off a dangling pointer. Fix that.

NVD

HIGH
CVE-2026-43060
CVE-2026-43060
pkg: linux

published: May 5, 2026

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nft_ct: drop pending enqueued packets on removal

Packets sitting in nfqueue might hold a reference to:

– templates that specify the conntrack zone, because a percpu area is
used and module removal is possible.
– conn…

NVD

HIGH
CVE-2026-7791
CVE-2026-7791
pkg: windows

published: May 4, 2026

Improper privilege management in the log rotation mechanism of the Skylight Workspace Config Service in Amazon WorkSpaces for Windows before 2.6.2034.0 allows a local non-admin authenticated user to place arbitrary files into arbitrary locations bypassing file system permission protections, leading …
CWE: CWE-367
GitHub-GHSA

HIGH
Ech0 has Server-Side Request Forgery (SSRF) via Connect Handler fetchPeerConnectInfo
GHSA-8mc6-xjpr-h98x
pkg: github.com/lin-snow/ech0
eco: go
published: May 7, 2026
## Summary
The `fetchPeerConnectInfo` function in `internal/service/connect/connect.go:214-239` uses `httpUtil.SendRequest` (no SSRF protection) instead of `SendSafeRequest` (which has `ValidatePublicHTTPURL` with private IP blocking). This allows authenticated users to make the server request arbit…
NVD

HIGH
CVE-2026-41905
CVE-2026-41905
pkg: curl

published: May 7, 2026

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, Helper::sanitizeRemoteUrl() in app/Misc/Helper.php follows HTTP redirects via curlGetLastRedirectedUrl() but then re-validates the original URL instead of the final redirect destination. An a…
CWE: CWE-918
NVD

HIGH
CVE-2026-41688
CVE-2026-41688
pkg: curl

published: May 7, 2026

Wallos is an open-source, self-hostable personal subscription tracker. In versions 4.8.4 and prior, the incomplete SSRF fix in Wallos validates webhook URLs via gethostbyname() but passes the original hostname to cURL without CURLOPT_RESOLVE pinning on 10 of 11 outbound HTTP endpoints, leaving a DNS…
CWE: CWE-918
GitHub-GHSA

HIGH
DevSpace UI Server WebSocket CheckOrigin does not validate source
GHSA-hqwm-7x7x-8379
pkg: github.com/loft-sh/devspace
eco: go
published: May 6, 2026
### Description

DevSpace's UI server WebSocket accepts connections from all origins by default, and therefore several endpoints are exposed via this WebSocket. When a developer runs the DevSpace UI and at the same time uses a browser to access the internet, a malicious website they visit can use th…

CVE-2026-42283
GitHub-GHSA

HIGH
OpenStack Ironic has an Incorrect Resource Transfer Between Spheres
GHSA-54w4-233h-x86g
pkg: ironic-python-agent, ironic-python-agent, ironic-python-agent
eco: pip
published: May 5, 2026
An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a remote endpoint. The credential forwarded is a time-limited Keystone token (which provides access to all OpenStack services Ironic is authorized for); or…
CVE-2026-42997
GitHub-GHSA

HIGH
Open WebUI's Base Model Routing Bypasses Access Control via Model Chaining
GHSA-9vvh-qmjx-p4q8
pkg: open-webui
eco: pip
published: May 8, 2026
# Base Model Routing Bypasses Access Control via Model Chaining

## Affected Component

Model chaining via `base_model_id`:
– `backend/open_webui/routers/models.py` (lines 170-214, `create_new_model`)
– `backend/open_webui/routers/models.py` (lines 254-308, `import_models`)
– `backend/open_webui/mai…

CVE-2026-44555
GitHub-GHSA

HIGH
MikroORM has SQL injection via runtime-controlled identifiers and JSON-path keys
GHSA-cfw5-68c4-ffqp
pkg: @mikro-orm/sql, @mikro-orm/knex
eco: npm
published: May 8, 2026
## Summary

MikroORM's identifier-quoting helper (`Platform.quoteIdentifier` and the postgres/mssql overrides) and its JSON-path emitters (`Platform.getSearchJsonPropertyKey`, `quoteJsonKey`) did not properly escape characters that delimit the SQL identifier or string-literal context they emit into.…

CVE-2026-44680
NVD

HIGH
CVE-2026-42351
CVE-2026-42351
pkg: python

published: May 8, 2026

pygeoapi is a Python server implementation of the OGC API suite of standards. From version 0.23.0 to before version 0.23.3, a raw string path concatenation vulnerability in pygeoapi's STAC FileSystemProvider plugin can allow for requests to STAC collection based collections to expose directories wit…
CWE: CWE-22
GitHub-GHSA

HIGH
free5GC NRF: type-confusion panic in POST /oauth2/token structured-form parser via Reflect.Set on incompatible types
GHSA-f8qv-7x5w-qr48
pkg: github.com/free5gc/nrf
eco: go
published: May 8, 2026
### Summary
free5GC's NRF root SBI endpoint `POST /oauth2/token` contains a parser-level type-confusion bug family. The handler in `NFs/nrf/internal/sbi/api_accesstoken.go` reflects over `models.NrfAccessTokenAccessTokenReq`, special-cases only plain `string` and `NrfNfManagementNfType` fields, and …
CVE-2026-44325
GitHub-GHSA

HIGH
free5GC's NEF 3gpp-pfd-management PATCH applications/{appId} panics on UDR access failure due to nil ProblemDetails dereference
GHSA-j59f-x285-69jx
pkg: github.com/free5gc/nef
eco: go
published: May 8, 2026
### Summary
free5GC's NEF `PATCH /3gpp-pfd-management/v1/{afId}/transactions/{transId}/applications/{appId}` handler panics with a nil-pointer dereference when the upstream UDR call fails AND the consumer wrapper returns `err != nil` together with a nil `*ProblemDetails`. The handler's `errPfdData !…
CVE-2026-44322
GitHub-GHSA

HIGH
free5GC's SMF UPI POST /upi/v1/upNodesLinks exits the SMF process on overlapping UE pools (unauthenticated, reachable Fatalf)
GHSA-44qj-cghf-9p97
pkg: github.com/free5gc/smf
eco: go
published: May 8, 2026
### Summary
free5GC's SMF mounts the `UPI` management route group without inbound OAuth2 middleware (same root cause as free5gc/free5gc#887). The `POST /upi/v1/upNodesLinks` create-or-update handler accepts attacker-controlled JSON and passes it directly into `UpNodesFromConfiguration()`, which call…
CVE-2026-44321
GitHub-GHSA

HIGH
free5GC's NEF crashes via logger.Fatal on PFD notification delivery failure (attacker-controlled notifyUri)
GHSA-rxrq-fv76-26pr
pkg: github.com/free5gc/nef
eco: go
published: May 8, 2026
### Summary
free5GC's NEF terminates the entire process when a stored PFD-subscription `notifyUri` cannot be reached. In `PfdChangeNotifier.FlushNotifications()`, the notifier calls `NnefPFDmanagementNotify(…)` and on any delivery error invokes `logger.PFDManageLog.Fatal(err)`, which is `os.Exit(1…
CVE-2026-44319
GitHub-GHSA

HIGH
free5GC's PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 via nil pointer dereference
GHSA-wr8j-6chw-gm6p
pkg: github.com/free5gc/pcf
eco: go
published: May 8, 2026
### Summary
free5GC's PCF `POST /npcf-smpolicycontrol/v1/sm-policies` handler (`HandleCreateSmPolicyRequest`) panics with a nil-pointer dereference when a downstream OpenAPI consumer call (UDR lookup) returns `404 Not Found` and the consumer wrapper returns `err != nil` together with a nil response …
CVE-2026-44316
GitHub-GHSA

HIGH
banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI
GHSA-gphh-9q3h-jgpp
pkg: banks
eco: pip
published: May 8, 2026
## Summary

`banks <= 2.4.1` uses `jinja2.Environment()` (unsandboxed) to render prompt templates. Applications that pass user-supplied strings as the template argument to `Prompt()` are vulnerable to Server-Side Template Injection (SSTI), which can lead to Remote Code Execution (RCE) on the host sy…

CVE-2026-44209
GitHub-GHSA

HIGH
fast-uri vulnerable to host confusion via percent-encoded authority delimiters
GHSA-v39h-62p7-jpjc
pkg: fast-uri
eco: npm
published: May 8, 2026
### Impact

`fast-uri` v3.1.1 and earlier decodes percent-encoded authority delimiters (`%40` as `@`, `%3A` as `:`) inside the host component and serializes them back as raw characters. This changes the URI structure, turning a hostname into userinfo plus a different host.

For example, `http://trus…

CVE-2026-6322
GitHub-GHSA

HIGH
bitcoinj has a ScriptExecution P2PKH/P2WPKH Verification Bypass
GHSA-hfcf-v2f8-x9pc
pkg: org.bitcoinj:bitcoinj-core
eco: maven
published: May 8, 2026
### Summary
`ScriptExecution.correctlySpends()` contains two fast-path verification bugs for standard `P2PKH` and native `P2WPKH` spends in `core/src/main/java/org/bitcoinj/script/ScriptExecution.java`.

In both branches, bitcoinj verifies an attacker-controlled signature/public-key pair but fails t…

CVE-2026-44714
GitHub-GHSA

HIGH
fast-uri vulnerable to path traversal via percent-encoded dot segments
GHSA-q3j6-qgpj-74h6
pkg: fast-uri
eco: npm
published: May 8, 2026
### Impact

`fast-uri` v3.1.0 and earlier decodes percent-encoded path separators (`%2F`) and dot segments (`%2E`) before applying dot-segment removal in `normalize()` and `equal()`. This makes encoded path data behave like real `/` and `..`, so distinct URIs collapse onto the same normalized path.

CVE-2026-6321
GitHub-GHSA

HIGH
@fastify/accepts-serializer Vulnerable to Denial of Service via Unbounded Accept Header Cache Growth
GHSA-qxhc-wx3p-2wmg
pkg: @fastify/accepts-serializer
eco: npm
published: May 8, 2026
### Impact

`@fastify/accepts-serializer` cached serializer-selection results keyed by the request `Accept` header without a size limit or eviction policy. A remote unauthenticated client could send many distinct but matching `Accept` header variants to make the cache grow unbounded. Under sustained…

CVE-2026-7768
GitHub-GHSA

HIGH
ZITADEL has LDAP Filter Injection in Login Flow
GHSA-rxvx-hhpj-q6px
pkg: github.com/zitadel/zitadel, github.com/zitadel/zitadel, github.com/zitadel/zitadel
eco: go
published: May 8, 2026
## Summary

A vulnerability was discovered in Zitadel's LDAP identity provider implementation, which fails to properly escape user-provided usernames before incorporating them into LDAP search filters. This allows unauthenticated attackers to perform LDAP Filter Injection during the login process.

CVE-2026-44671
NVD

HIGH
CVE-2026-44498
CVE-2026-44498
pkg: zfnd zebrad

published: May 8, 2026

ZEBRA is a Zcash node written entirely in Rust. Prior to version 4.4.0, Zebra's block validator undercounts transparent signature operations against the 20000-sigop block limit (MAX_BLOCK_SIGOPS), allowing it to accept blocks that zcashd rejects with bad-blk-sigops. A miner who produces such a block…
CWE: CWE-682
NVD

HIGH
CVE-2026-41584
CVE-2026-41584
pkg: zfnd zebra-chain, zfnd zebrad

published: May 8, 2026

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and prior to zebra-chain version 6.0.2, Orchard transactions contain a rk field which is a randomized validating key and also an elliptic curve point. The Zcash specification allows the field to be the identity (a "zero" v…
CWE: CWE-617
NVD

HIGH
CVE-2024-46508
CVE-2024-46508
pkg: yeti-platform yeti

published: May 8, 2026

yeti-platform yeti before 2.1.12 allows attackers to generate valid JWT tokens is the secret is not changed (by setting YETI_AUTH_SECRET_KEY to a value other than SECRET).
CWE: CWE-798
NVD

HIGH
CVE-2026-39836
CVE-2026-39836
pkg: windows

published: May 7, 2026

The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).
GitHub-GHSA

HIGH
vm2 Sandbox Access to Host Buffer.alloc Allows timeout Bypass Resulting in Memory Exhaustion
GHSA-6785-pvv7-mvg7
pkg: vm2
eco: npm
published: May 7, 2026
### Summary
Sandboxed code can call `Buffer.alloc()` with an arbitrary size to allocate memory directly on the host heap. Because `Buffer.alloc` is a synchronous C++ native call, vm2's `timeout` option cannot interrupt it. A single request can exhaust host memory and crash the process with a `FATAL …
CVE-2026-44004
NVD

HIGH
CVE-2026-41640
CVE-2026-41640
pkg: node

published: May 7, 2026

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.39, the queryParentSQL() function in the core database package constructs a recursive CTE query by joining nodeIds with string concatenation instead of using paramete…
CWE: CWE-89
GitHub-GHSA

HIGH
Talos Linux has a local privilege escalation from untrusted workloads
GHSA-m38g-vww2-mvgx
pkg: github.com/siderolabs/talos
eco: go
published: May 7, 2026
### Summary

A vulnerability in the Linux kernel's algif_aead subsystem (CVE-2026-31431, "copy.fail") allows an unprivileged container workload to corrupt arbitrary file page-cache pages via the AF_ALG crypto interface and splice(). On Talos Linux, this vulnerability can be chained into a complete n…

GitHub-GHSA

HIGH
rust-zserio has Unbounded Memory Allocation
GHSA-fpf5-4jw8-67×8
pkg: rust-zserio
eco: rust
published: May 7, 2026
### Impact

When deserializing arrays, strings or bytes (blob) types zserio first reads the size of the variable, and then allocates sufficient memory to load data. Since the size is always trusted this can be abused by creating a data file with a large size value, causing the zserio runtime to allo…

GitHub-GHSA

HIGH
Gotenberg has an unauthenticated denial of service via echo.Context pool reuse in webhook async goroutine
GHSA-r33j-c622-r6qp
pkg: github.com/gotenberg/gotenberg/v8
eco: go
published: May 7, 2026
## Summary

The webhook middleware spawns a goroutine that holds a reference to the request's `echo.Context` after the synchronous handler returns `ErrAsyncProcess` and Echo recycles the context back to its `sync.Pool`. When a concurrent request claims the recycled context, `c.Reset()` clears the st…

CVE-2026-42594
GitHub-GHSA

HIGH
Netty: HttpContentDecompressor maxAllocation bypass when Content-Encoding set to br/zstd/snappy leads to decompression bomb DoS
GHSA-f6hv-jmp6-3vwv
pkg: io.netty:netty-codec-http, io.netty:netty-codec-http2, io.netty:netty-codec-http
eco: maven
published: May 7, 2026
## Summary

`HttpContentDecompressor` accepts a `maxAllocation` parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via `ZlibDecoder`, but is silently ignored when the content encoding is `br` (Brotli), …

CVE-2026-42587
GitHub-GHSA

HIGH
Netty Lz4FrameDecoder is vulnerable to resource exhaustion
GHSA-mj4r-2hfc-f8p6
pkg: io.netty:netty-codec-compression, io.netty:netty-codec
eco: maven
published: May 7, 2026
### Summary
Lz4FrameDecoder allocates a ByteBuf of size `decompressedLength` (up to 32 MB per block) before LZ4 runs. A peer only needs a 21-byte header plus `compressedLength` payload bytes – 22 bytes if `compressedLength == 1` – to force that allocation.

### Details
io.netty.handler.codec.compres…

CVE-2026-42583
GitHub-GHSA

HIGH
Netty HTTP/3 QPACK literal unbounded allocation
GHSA-2c5c-chwr-9hqw
pkg: io.netty:netty-codec-http3
eco: maven
published: May 7, 2026
### Summary
When Netty decodes HTTP/3 headers, it sometimes runs `new byte[length]` using a length from the wire before checking that many bytes are really there. A small malicious header can claim a huge length (on the order of a gigabyte).

### Details
When decoding header blocks, the non-Huffman …

CVE-2026-42582
GitHub-GHSA

HIGH
Netty has a DNS Codec Input Validation Bypass (Encoder + Decoder)
GHSA-cm33-6792-r9fm
pkg: io.netty:netty-codec-dns, io.netty:netty-codec-dns
eco: maven
published: May 7, 2026
# Security Vulnerability Report: DNS Codec Input Validation Bypass in Netty (Encoder + Decoder)

## 1. Vulnerability Summary

| Field | Value |
|——-|——-|
| **Product** | Netty |
| **Version** | 4.2.12.Final (and all prior versions with codec-dns) |
| **Component** | `io.netty.handler.codec.d…

CVE-2026-42579
GitHub-GHSA

HIGH
Netty epoll transport denial of service via RST on half-closed TCP connection
GHSA-rwm7-x88c-3g2p
pkg: io.netty:netty-transport-native-epoll
eco: maven
published: May 6, 2026
## Summary

Netty's epoll transport fails to detect and close TCP connections that receive a RST after being half-closed, leading to stale channels that are never cleaned up and, in some code paths, a 100% CPU busy-loop in the event loop thread.

## Affected versions

All versions of 4.2.x `netty-tr…

CVE-2026-42577
GitHub-GHSA

HIGH
Nerdbank.MessagePack: Attacker-controlled stackalloc in DateTime decoding causes process-terminating StackOverflowException
GHSA-2cwq-pwfr-wcw3
pkg: Nerdbank.MessagePack
eco: nuget
published: May 6, 2026
### Summary

Nerdbank.MessagePack contains an uncontrolled stack allocation vulnerability in DateTime decoding. A malicious MessagePack payload can declare an oversized timestamp extension length, causing the reader to allocate an attacker-controlled number of bytes on the stack. This can trigger a …

CVE-2026-44375
GitHub-GHSA

HIGH
python-multipart has Denial of Service via unbounded multipart part headers
GHSA-pp6c-gr5w-3c5g
pkg: python-multipart
eco: pip
published: May 6, 2026
### Summary

`python-multipart` has a denial of service vulnerability in multipart part header parsing. When parsing `multipart/form-data`, `MultipartParser` previously had no limit on the number of part headers or the size of an individual part header. An attacker could send a request with either m…

CVE-2026-42561
GitHub-GHSA

HIGH
Granian vulnerable to unauthenticated DoS via WebSocket subprotocol header panic
GHSA-vrg7-482j-p6f6
pkg: granian
eco: pip
published: May 6, 2026
### Summary

Granian aborts a worker process when an unauthenticated client sends a WebSocket upgrade request whose `Sec-WebSocket-Protocol` header contains non-ASCII bytes.

The crash happens in Granian's WebSocket scope construction path, before the ASGI application is invoked.

This is a single-r…

CVE-2026-42544
GitHub-GHSA

HIGH
Snappier has an infinite loop during SnappyStream decompression with malformed framed input
GHSA-pggp-6c3x-2xmx
pkg: Snappier
eco: nuget
published: May 6, 2026
### Summary
`Snappier.SnappyStream` enters an uncatchable infinite loop when decompressing a malformed framed-format Snappy stream as small as 15 bytes.

### Details
The hang manifests as a userspace busy loop with SnappyStreamDecompressor.Decompress repeatedly calling Crc32CAlgorithm.Append. The ex…

CVE-2026-44302
GitHub-GHSA

HIGH
Micronaut has unbounded `formattersCache` in `TimeConverterRegistrar` that Allows Memory Exhaustion via `Accept-Language` Header
GHSA-8hjv-92q9-g4xj
pkg: io.micronaut:micronaut-context
eco: maven
published: May 6, 2026
## Summary

`TimeConverterRegistrar` caches `DateTimeFormatter` instances in an unbounded `ConcurrentHashMap<String, DateTimeFormatter>` whose key is derived from the `@Format` annotation pattern concatenated with the locale from the HTTP `Accept-Language` header. Because `Locale.forLanguageTag()` a…

CVE-2026-44241
GitHub-GHSA

HIGH
basic-ftp allows a malicious FTP server to cause client-side denial of service via unbounded multiline control response buffering
GHSA-rpmf-866q-6p89
pkg: basic-ftp
eco: npm
published: May 6, 2026
## Summary

`basic-ftp` is vulnerable to client-side denial of service when parsing FTP control-channel multiline responses.

A malicious or compromised FTP server can send an unterminated multiline response during the initial FTP banner phase, before authentication. The client keeps appending attac…

CVE-2026-44240
NVD

HIGH
CVE-2026-7948
CVE-2026-7948
pkg: google chrome, microsoft windows

published: May 6, 2026

Race in Chromoting in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Medium)
CWE: CWE-362
NVD

HIGH
CVE-2026-7897
CVE-2026-7897
pkg: google chrome, apple iphone_os

published: May 6, 2026

Use after free in Mobile in Google Chrome on iOS prior to 148.0.7778.96 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
GitHub-GHSA

HIGH
Nokogiri CSS selector tokenizer has regular expression backtracking
GHSA-c4rq-3m3g-8wgx
pkg: nokogiri
eco: rubygems
published: May 6, 2026
## Summary

Nokogiri's CSS selector tokenizer contains regular expressions whose construction may result in exponential regex backtracking on adversarial selectors. Three ReDoS vectors are addressed in this release:

1. String-literal tokenization on certain unterminated quoted-string input.
2. Stri…

NVD

HIGH
CVE-2026-23870
CVE-2026-23870
pkg: react

published: May 6, 2026

A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to server crashes, out-of-memory exceptions or excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel, react…
NVD

HIGH
CVE-2026-43226
CVE-2026-43226
pkg: linux linux_kernel

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

net/rds: No shortcut out of RDS_CONN_ERROR

RDS connections carry a state "rds_conn_path::cp_state"
and transitions from one state to another and are conditional
upon an expected state: "rds_conn_path_transition."

There is one exc…

NVD

HIGH
CVE-2026-43164
CVE-2026-43164
pkg: go

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

udplite: Fix null-ptr-deref in __udp_enqueue_schedule_skb().

syzbot reported null-ptr-deref of udp_sk(sk)->udp_prod_queue. [0]

Since the cited commit, udp_lib_init_sock() can fail, as can
udp_init_sock() and udpv6_init_sock().

L…

NVD

HIGH
CVE-2026-43101
CVE-2026-43101
pkg: linux

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data()

We need to check __in6_dev_get() for possible NULL value, as
suggested by Yiming Qian.

Also add skb_dst_dev_rcu() instead of skb_dst_dev(),
and two missing …

NVD

HIGH
CVE-2026-43099
CVE-2026-43099
pkg: linux

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

ipv4: icmp: fix null-ptr-deref in icmp_build_probe()

ipv6_stub->ipv6_dev_find() may return ERR_PTR(-EAFNOSUPPORT) when the
IPv6 stack is not active (CONFIG_IPV6=m and not loaded), and passing
this error pointer to dev_hold() will …

GitHub-GHSA

HIGH
Mongoose's Improper Sanitization of $nor in sanitizeFilter May Allow NoSQL Injection
GHSA-wpg9-53fq-2r8h
pkg: mongoose, mongoose, mongoose
eco: npm
published: May 5, 2026
### Impact

This vulnerability allows bypassing Mongoose’s sanitizeFilter query sanitization mechanism via the `$nor` operator.

When sanitizeFilter is enabled, Mongoose wraps query operators in `$eq` to neutralize them. However, prior to the fix, `$nor` was not included in the set of logical oper…

CVE-2026-42334
GitHub-GHSA

HIGH
changedetection.io has an Arbitrary Local File Read via a crafted backup restore
GHSA-8757-69j2-hx56
pkg: changedetection.io
eco: pip
published: May 5, 2026
### Details
The vulnerability is caused by trusting attacker-controlled snapshot paths restored from backup files.

The vulnerable flow starts in the backup restore logic. When a backup ZIP is restored, the application extracts the archive and copies each restored watch UUID directory directly into …

CVE-2026-43891
GitHub-GHSA

HIGH
Twisted has a Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chains
GHSA-grgv-6hw6-v9g4
pkg: Twisted
eco: pip
published: May 5, 2026
### Details

The twisted.names module is vulnerable to a Denial of Service (DoS) attack via resource exhaustion during DNS name decompression. A remote, unauthenticated attacker can exploit this by sending a crafted TCP DNS packet containing deeply chained compression pointers. This flaw bypasses pr…

CVE-2026-42304
GitHub-GHSA

HIGH
GoBGP has a panic in AdjRib.Update via malformed BGP Update message (Nil Pointer Dereference)
GHSA-p3w2-64xm-833j
pkg: github.com/osrg/gobgp/v4
eco: go
published: May 5, 2026
### Summary
Remote Denial of Service (DoS) via Nil Pointer Dereference in BGP Update Processing
An unauthenticated remote BGP peer can trigger a fatal panic in GoBGP by sending a specially crafted BGP UPDATE message. When the server receives a message with inconsistent attribute lengths, it improper…
CVE-2026-42285
GitHub-GHSA

HIGH
ssrfcheck: SSRF Bypass Caused by Failure to Classify Reserved IP Address Space as Invalid
GHSA-p4hc-9pjh-55c8
pkg: ssrfcheck
eco: npm
published: May 5, 2026
# SSRF Bypass in `ssrfcheck` – fails to classify reserved IP address space as invalid

`ssrfcheck` is an npm package that serves to provide protection from SSRF by validating URLs or hostname inputs.

Resources:
* Project's GitHub code repository: https://github.com/felippe-regazio/ssrfcheck
* Pr…

CVE-2025-8267
NVD

HIGH
CVE-2026-40280
CVE-2026-40280
pkg: thecodingmachine gotenberg

published: May 5, 2026

Gotenberg is an API-based document conversion tool. In versions 8.30.1 and earlier, the default private-IP deny-lists for the –webhook-deny-list and –api-download-from-deny-list flags use a case-sensitive regular expression (^https?://) to match URL schemes. Because Go's net/url.Parse() normalizes…
CWE: CWE-918
NVD

HIGH
CVE-2026-32934
CVE-2026-32934
pkg: coredns.io coredns

published: May 5, 2026

CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-QUIC (DoQ) server can be driven into unbounded goroutine and memory growth by a remote client that opens many QUIC streams and sends only 1 byte per stream. When the worker pool is full, CoreDNS still spawns a gor…
CWE: CWE-770
GitHub-GHSA

HIGH
pgjdbc: Unbounded PBKDF2 iterations in SCRAM authentication allows CPU exhaustion DoS
GHSA-98qh-xjc8-98pq
pkg: org.postgresql:postgresql
eco: maven
published: May 5, 2026
## Summary
pgjdbc is vulnerable to a client-side denial of service during SCRAM-SHA-256 authentication.

### Impact
A malicious server can instruct the driver to perform SCRAM authentication with a very large iteration count.
With a large enough value, the client spends an unbounded amount of CPU ti…

CVE-2026-42198
GitHub-GHSA

HIGH
Prometheus: Remote read endpoint allows denial of service via crafted snappy payload
GHSA-8rm2-7qqf-34qm
pkg: github.com/prometheus/prometheus
eco: go
published: May 5, 2026
### Impact

The remote read endpoint (`/api/v1/read`) does not validate the declared decoded length in a snappy-compressed request body before allocating memory.
An unauthenticated attacker can send a small payload that causes a huge heap allocation per request. Under concurrent load this can exhaus…

CVE-2026-42154
GitHub-GHSA

HIGH
Prometheus Azure AD remote write OAuth client secret exposed via config API
GHSA-wg65-39gg-5wfj
pkg: github.com/prometheus/prometheus
eco: go
published: May 5, 2026
### Impact

Users who use Azure AD remote write with OAuth authentication are impacted.

The `client_secret` field in the Azure AD remote write OAuth configuration (`storage/remote/azuread`) was typed as `string` instead of `Secret`. Prometheus redacts fields of type `Secret` when serving the config…

CVE-2026-42151
NVD

HIGH
CVE-2026-30923
CVE-2026-30923
pkg: owasp modsecurity

published: May 5, 2026

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Libmodsecurity is one component of the ModSecurity v3 project. A segmentation fault occurs when a rule using the t:hexDecode transformation inspects a query string parameter containing a si…
CWE: CWE-125
NVD

HIGH
CVE-2026-7776
CVE-2026-7776
pkg: tls

published: May 4, 2026

Boundary Community Edition and Boundary Enterprise (“Boundary”) workers are vulnerable to a denial-of-service condition during node enrollment TLS handshakes. An attacker with network access to the worker authentication listener may open a connection and delay or withhold the client certificate …
CWE: CWE-770
NVD

HIGH
CVE-2026-7768
CVE-2026-7768
pkg: node

published: May 4, 2026

@fastify/accepts-serializer cached serializer-selection results keyed by the request Accept header without a size limit or eviction policy. A remote unauthenticated client could send many distinct but matching Accept header variants to make the cache grow unbounded, eventually exhausting the Node.js…
CWE: CWE-770
NVD

HIGH
CVE-2026-42236
CVE-2026-42236
pkg: n8n n8n

published: May 4, 2026

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the MCP OAuth client registration endpoint accepted unauthenticated requests and stored client data without adequate resource controls. An unauthenticated remote attacker could exhaust server memory r…
CWE: CWE-770
NVD

HIGH
CVE-2026-42226
CVE-2026-42226
pkg: n8n n8n

published: May 4, 2026

n8n is an open source workflow automation platform. Prior to versions 1.123.33 and 2.17.5, the dynamic-node-parameters endpoints did not verify whether the authenticated caller was authorized to use a supplied credential reference. An authenticated user with access to a shared workflow could supply …
CWE: CWE-862
NVD

HIGH
CVE-2026-42151
CVE-2026-42151
pkg: oauth

published: May 4, 2026

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of Secret. Prometheus redacts fields of type Secret when serving …
CWE: CWE-200, CWE-312
GitHub-GHSA

HIGH
Apache OpenNLP AbstractModelReader has an OOM Denial of Service via Unbounded Array Allocation
GHSA-659w-93r5-9j6m
pkg: org.apache.opennlp:opennlp-tools, org.apache.opennlp:opennlp-tools
eco: maven
published: May 4, 2026
OOM Denial of Service via Unbounded Array Allocation in Apache OpenNLP AbstractModelReader 

Versions Affected: 

Before 2.5.9

Before 3.0.0-M3 

Description:

The AbstractModelReader methods getOutcomes(), getOutcomePatterns(), and getPredicates() each read a 32-bit signed integer count field f…

CVE-2026-42440
GitHub-GHSA

HIGH
OpenMRS ModuleResourcesServlet has Path Traversal that Leads to Arbitrary File Read
GHSA-jjgj-cx3q-pw4w
pkg: org.openmrs.web:openmrs-web, org.openmrs.web:openmrs-web
eco: maven
published: May 4, 2026
## Affected Versions

version ≤ 2.7.8 (latest version at time of disclosure)

https://github.com/openmrs/openmrs-core

## Impact

The `/openmrs/moduleResources/{moduleid}` endpoint in OpenMRS Core is vulnerable to a path traversal attack. The `ModuleResourcesServlet` does not properly validate use…

CVE-2026-40075
NVD

HIGH
CVE-2026-37461
CVE-2026-37461
pkg: go

published: May 4, 2026

An out-of-bounds read in the ParseIP6Extended function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.
CWE: CWE-125
NVD

HIGH
CVE-2026-34354
CVE-2026-34354
pkg: windows

published: May 8, 2026

Akamai Guardicore Platform Agent (GPA) and Zero Trust Client on Linux and macOS allow TOCTOU-based local privilege escalation. The GPA service creates an IPC socket in the world-writable /tmp directory. It accepts unauthenticated IPC control messages. This enables a TOCTOU vulnerability in the Handl…
CWE: CWE-367
NVD

HIGH
CVE-2026-42264
CVE-2026-42264
pkg: axios

published: May 8, 2026

Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPath, beforeRedirect, and insecureHTTPParser) in the HTTP adapter are read via direct property access without hasOwnProperty guards, making the…
CWE: CWE-1321
NVD

HIGH
CVE-2026-40213
CVE-2026-40213
pkg: node

published: May 7, 2026

OpenStack Cyborg before 16.0.1 uses rule:allow (check_str='@') as the default policy for multiple API endpoints. This unconditionally authorizes any request carrying a valid Keystone token regardless of roles, project membership, or scope. An authenticated user with zero role assignments can complet…
CWE: CWE-863
GitHub-GHSA

HIGH
ech0's acess tokens with expiry=never cannot be revoked: logout panics, delete does not blacklist JTI
GHSA-fpw6-hrg5-q5x5
pkg: github.com/lin-snow/Ech0
eco: go
published: May 7, 2026
## Summary

Access tokens created with the "never expire" option have no `exp` JWT claim. Three independent revocation mechanisms fail for this token type. Logout at `internal/handler/auth/auth.go:154` and `:163` dereferences `claims.ExpiresAt.Time`, panicking on the nil field so the token never hit…

GitHub-GHSA

HIGH
katalyst-koi: Session cookies can be replayed after user logout
GHSA-4cx3-3c38-j9vv
pkg: katalyst-koi, katalyst-koi
eco: rubygems
published: May 7, 2026
### Impact

Admin session cookies were not invalidated when an admin user logged out. An attacker with access to a valid admin session cookie could continue to access admin functionality after logout, until the cookie expired or session secrets were rotated.

This affects applications using Koi admi…

CVE-2026-44511
GitHub-GHSA

HIGH
wger: CSV/TSV formula injection in gym member export (first_name/last_name)
GHSA-xq9m-hmp9-fw87
pkg: wger
eco: pip
published: May 6, 2026
### Summary

The gym member TSV export endpoint in wger writes `first_name` and `last_name` profile fields verbatim to TSV cells with no formula-prefix sanitization. Any gym member (including newly self-registered users) can pre-load a spreadsheet formula into their own profile. When a gym admin lat…

GitHub-GHSA

HIGH
Axios: Prototype Pollution Gadgets – Response Tampering, Data Exfiltration, and Request Hijacking
GHSA-pf86-5×62-jrwf
pkg: axios, axios
eco: npm
published: May 5, 2026
## Summary

When `Object.prototype` has been polluted by any co-dependency with keys that axios reads without a `hasOwnProperty` guard, an attacker can (a) silently intercept and modify every JSON response before the application sees it, or (b) fully hijack the underlying HTTP transport, gaining acc…

CVE-2026-42033
GitHub-GHSA

HIGH
Axios: Header Injection via Prototype Pollution
GHSA-6chq-wfr3-2hj9
pkg: axios, axios
eco: npm
published: May 5, 2026
### Summary

A prototype pollution gadget exists in the Axios HTTP adapter (lib/adapters/http.js) that allows an attacker to inject arbitrary HTTP headers into outgoing requests. The vulnerability exploits duck-type checking of the data payload, where if Object.prototype is polluted with getHeaders,…

CVE-2026-42035
GitHub-GHSA

HIGH
Axios has prototype pollution read-side gadgets in HTTP adapter that allow credential injection and request hijacking
GHSA-q8qp-cvcw-x6jj
pkg: axios
eco: npm
published: May 5, 2026
## Summary

Five config properties in the HTTP adapter are read via direct property access without `hasOwnProperty` guards, making them exploitable as prototype pollution gadgets. When `Object.prototype` is polluted by another dependency in the same process, axios silently picks up these polluted va…

CVE-2026-42264
GitHub-GHSA

HIGH
smallbitvec: Integer overflow in safe API leads to heap buffer overflow
GHSA-97wc-2hqc-cjgr
pkg: smallbitvec
eco: rust
published: May 9, 2026
### Summary
An integer overflow in the internal capacity calculation of `smallbitvec` can lead to an undersized heap allocation, resulting in a heap buffer overflow through safe APIs only. This allows memory corruption without requiring `unsafe` code from the caller.

### Details
The issue originate…

CVE-2026-44983
GitHub-GHSA

HIGH
free5GC's NEF nnef-callback route group is unauthenticated; forged callback requests are accepted into the processing path
GHSA-wqfh-gq79-j8mf
pkg: github.com/free5gc/nef
eco: go
published: May 8, 2026
### Summary
free5GC's NEF mounts the `nnef-callback` route group without inbound OAuth2/bearer-token authorization. A forged or arbitrary bearer token (e.g. `Authorization: Bearer not-a-real-token`) is enough to reach the SMF-callback handler — the callback body is parsed and dispatched into NEF bu…
CVE-2026-44320
GitHub-GHSA

HIGH
Open WebUI Vulnerable to Arbitrary File Upload and Path Traversal
GHSA-9pgh-j74g-qj6m
pkg: open-webui
eco: pip
published: May 8, 2026
# **CONFIDENTIAL**

# KL-CAN-2024-002

## Vulnerability Details

| # | Field | Value |
|—|——-|——-|
| 1 | **Discoverer** | Jaggar Henry & Sean Segreti of KoreLogic, Inc. |
| 2 | **Date Submitted** | 2024.03.12 |
| 3 | **Title** | Open WebUI Arbitrary File Upload + Path Traversal |
| 5 | **A…

CVE-2026-44566
GitHub-GHSA

HIGH
Open WebUI has Improper Authorization Control
GHSA-4vg5-rp28-gvjf
pkg: open-webui
eco: pip
published: May 8, 2026
# **CONFIDENTIAL**

# Vulnerability Disclosure Analysis Documentation

## Vulnerability Details

| # | Field | Value |
|—|——-|——-|
| 1 | **Discoverer** | Taylor Pennington of KoreLogic, Inc. |
| 2 | **Date Submitted** | June 11, 2024 |
| 3 | **Title** | Open WebUI Improper Authorizati…

CVE-2026-44567
GitHub-GHSA

HIGH
Open WebUI has stored XSS in Excel file preview
GHSA-jwf8-pv5p-vhmc
pkg: open-webui
eco: pip
published: May 8, 2026
### Summary
Excel file attachments are previewed in an unsafe way. A crafted XLSX file payload can be used to cause the [sheetjs](https://git.sheetjs.com/sheetjs/sheetjs) function [sheet_to_html](https://git.sheetjs.com/sheetjs/sheetjs/src/commit/66cf8d2117d271f89e4f47b5fed35a3e1ea93f67/bits/79_html…
CVE-2026-44549
GitHub-GHSA

HIGH
open-webui Vulnerable to Stored XSS via Model Description
GHSA-gf5m-wcrh-7928
pkg: open-webui, open-webui
eco: npm
published: May 8, 2026
> [!IMPORTANT]
> Relationship to CVE-2024-7990

> CVE-2024-7990 (issued by huntr.dev, March 2025) describes a stored XSS in the same field — the model description — but exploits a different bypass mechanism: a second-order injection through the sanitizeResponseContent function's video-tag place…

CVE-2026-44721
NVD

HIGH
CVE-2025-55449
CVE-2025-55449
pkg: jwt

published: May 8, 2026

AstrBotDevs AstrBot 3.5.15 has Advanced_System_for_Text_Response_and_Bot_Operations_Tool as the hardcoded private key used to sign a JWT.
CWE: CWE-321
GitHub-GHSA

HIGH
Netty has HttpClientCodec response desynchronization
GHSA-57rv-r2g8-2cj3
pkg: io.netty:netty-codec-http, io.netty:netty-codec-http
eco: maven
published: May 7, 2026
### Summary
If HttpClientCodec is configured, there are use cases when a response body from one request, can be parsed as another's.

### Details
HttpClientCodec pairs each inbound response with an outbound request by `queue.poll()` once per response, including for `1xx`. If the client pipelines GE…

CVE-2026-42584
GitHub-GHSA

HIGH
YAFNET has Stored XSS in Forum Thread Posts/Replies that Allows Arbitrary JavaScript Execution for All Thread Viewers
GHSA-8rq5-wwpp-fmj2
pkg: YAFNET.Core, YAFNET.Core
eco: nuget
published: May 5, 2026
**Description:**
Stored Cross-Site Scripting (XSS) occurs when user-supplied input is persisted by the application and later rendered in another user's browser without proper sanitization or contextual output encoding. When the vulnerable sink is a high-traffic surface such as a public forum thread,…
CVE-2026-43939
GitHub-GHSA

HIGH
Apache Thrift vulnerable to Path Traversal, HTTP Request/Response Splitting, Uncontrolled Resource Consumption
GHSA-526f-jxpj-jmg2
pkg: thrift
eco: npm
published: May 5, 2026
Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting'), Uncontrolled Resource Consumption vulnerability in Apache Thrift.

This issue affects Apache Thrift:…

CVE-2026-43870
GitHub-GHSA

HIGH
Apache Thrift has an Improper Validation of Certificate with Host Mismatch Vulnerability
GHSA-7pwc-h2j2-rjgj
pkg: org.apache.thrift:libthrift
eco: maven
published: May 5, 2026
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift.

This issue affects Apache Thrift: before 0.23.0.

Users are recommended to upgrade to version [0.23.0](https://github.com/apache/thrift/releases/tag/v0.23.0), which fixes the issue.

CVE-2026-43869
NVD

HIGH
CVE-2026-7810
CVE-2026-7810
pkg: python

published: May 5, 2026

A flaw has been found in UsamaK98 python-notebook-mcp up to a05a232815809a7e425b5fa7be26e0d4369894c2. Impacted is the function create_notebook/read_notebook/edit_cell/add_cell of the file server.py. This manipulation causes path traversal. It is possible to initiate the attack remotely. The exploit …
CWE: CWE-22
GitHub-GHSA

HIGH
Amazon ECS Container Agent (Windows) is vulnerable to Information Disclosure
GHSA-fc67-c4hg-q653
pkg: github.com/aws/amazon-ecs-agent
eco: go
published: May 7, 2026
### Summary
[Amazon Elastic Container Service (Amazon ECS)](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/Welcome.html) is a fully managed container orchestration service that enables customers to deploy, manage, and scale containerized applications. An issue exists where, under certai…
NVD

HIGH
CVE-2026-39383
CVE-2026-39383
pkg: thecodingmachine gotenberg

published: May 5, 2026

Gotenberg is an API-based document conversion tool. In version 8.29.1, an unauthenticated attacker with network access can force the server to make outbound HTTP POST requests to arbitrary internal or external destinations by supplying a crafted URL in the Gotenberg-Webhook-Url request header. The F…
CWE: CWE-918
GitHub-GHSA

HIGH
Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0
GHSA-pmwg-cvhr-8vh7
pkg: axios, axios
eco: npm
published: May 5, 2026
**1. Executive Summary**
This report documents an **incomplete security patch** for the previously disclosed vulnerability **GHSA-3p68-rc4w-qgx5 (CVE-2025-62718)**, which affects the `NO_PROXY` hostname resolution logic in the Axios HTTP library.

**Background — The Original Vulnerability**
The or…

CVE-2026-42043
GitHub-GHSA

HIGH
Open WebUI's responses passthrough endpoint lacks access control authorization
GHSA-hp5m-24vp-vq2q
pkg: open-webui
eco: pip
published: May 8, 2026
## Summary

The /responses endpoint in the OpenAI router accepts any authenticated user and forwards requests directly to upstream LLM providers without enforcing per-model access control. While the primary chat completion endpoint (generate_chat_completion) checks model ownership, group membership,…

CVE-2026-44556
GitHub-GHSA

HIGH
Microsoft APM CLI's plugin.json component paths escape plugin root and copy arbitrary host files during install
GHSA-xhrw-5qxx-jpwr
pkg: apm-cli
eco: pip
published: May 7, 2026
### Summary
Microsoft APM normalizes marketplace plugins by copying plugin components referenced in `plugin.json` into `.apm/`. The manifest fields `agents`, `skills`, `commands`, and `hooks` are attacker-controlled, but the implementation does not enforce that those paths remain inside the plugin d…
CVE-2026-44641
NVD

HIGH
CVE-2026-44243
CVE-2026-44243
pkg: gitpython_project gitpython

published: May 7, 2026

GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython allows attackers who can supply a crafted reference path to an application using GitPython to write, overwrite, move, or delete files outside the repository’s .git directory …
CWE: CWE-22
GitHub-GHSA

HIGH
GitPython reference APIs has a path traversal vulnerability that allows arbitrary file write and delete outside the repository
GHSA-7545-fcxq-7j24
pkg: GitPython
eco: pip
published: May 6, 2026
## 🧾 Summary

A vulnerability in **GitPython** allows **attackers who can supply a crafted reference path to an application using GitPython** to **write, overwrite, move, or delete files outside the repository’s `.git` directory** via **insufficient validation of reference paths in reference cr…

CVE-2026-44243
GitHub-GHSA

HIGH
Auth.js SDK has Improper Permission Checking
GHSA-8qjv-jj2q-x832
pkg: auth0-js
eco: npm
published: May 6, 2026
### Description
Under specific preconditions, the Auth0.js SDK may improperly return user profile information using a valid access token when a specifically crafted invalid ID token is provided.

### Am I Affected?
Users are affected if they meet each of the following preconditions:
– Applications b…

CVE-2026-42280
NVD

HIGH
CVE-2026-43062
CVE-2026-43062
pkg: linux

published: May 5, 2026

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: L2CAP: Fix type confusion in l2cap_ecred_reconf_rsp()

l2cap_ecred_reconf_rsp() casts the incoming data to struct
l2cap_ecred_conn_rsp (the ECRED *connection* response, 8 bytes with
result at offset 6) instead of struct …

GitHub-GHSA

HIGH
Apache Atlas has a Code Injection Vulnerability
GHSA-35xx-9xrg-gwhf
pkg: org.apache.atlas:apache-atlas
eco: maven
published: May 4, 2026
### Description:
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Atlas.

Apache Atlas exposes a DSL search endpoint that accepts user-supplied query strings. Attacker can alter Gremlin traversal logic within grammar-allowed characters to access unintended data.

##…

CVE-2026-40563
GitHub-GHSA

HIGH
GitPython: Newline injection in config_writer() section parameter bypasses CVE-2026-42215 patch, enabling RCE via core.hooksPath
GHSA-mv93-w799-cj2w
pkg: GitPython
eco: pip
published: May 8, 2026
Summary

The patch for CVE-2026-42215 (GitPython 3.1.49) validates newlines only in the value parameter of set_value(). The section and option parameters are passed to configparser without any newline validation. An attacker who controls the section argument can inject \n to write arbitrary section …

NVD

HIGH
CVE-2026-34596
CVE-2026-34596
pkg: sandboxie-plus sandboxie

published: May 5, 2026

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, a Time-of-Check-to-Time-of-Use (TOCTOU) race condition exists during addon installation. When a user installs an addon through the SandMan interface, UpdUtil.exe is spawned as SYSTEM by Sbi…
CWE: CWE-367
GitHub-GHSA

HIGH
awslabs/tough is Missing Delegated Metadata Validation
GHSA-4v58-8p28-2rq3
pkg: tough, tuftool
eco: rust
published: May 5, 2026
### Summary
Missing expiration, hash, and length enforcement in delegated metadata validation in awslabs/tough before tough-v0.22.0 allows remote authenticated users with delegated signing authority to bypass TUF specification integrity checks for delegated targets metadata and poison the local meta…
CVE-2026-6967
GitHub-GHSA

HIGH
awslabs/tough Delegated Roles have a Signature Threshold Bypass
GHSA-8m7c-8m39-rv4x
pkg: tough, tuftool
eco: rust
published: May 5, 2026
### Summary
Improper verification of cryptographic signature uniqueness in delegated role validation in awslabs/tough before tough-v0.22.0 allows remote authenticated users to bypass the TUF signature threshold requirement by duplicating a valid signature, causing the client to accept forged delegat…
CVE-2026-6966
GitHub-GHSA

HIGH
@yoda.digital/gitlab-mcp-server's SSE transport has no authentication and wildcard CORS, exposing all 86 GitLab tools
GHSA-8jr5-6gvj-rfpf
pkg: @yoda.digital/gitlab-mcp-server
eco: npm
published: May 9, 2026
## SSE Transport Has No Authentication and Wildcard CORS, Exposing All 86 GitLab Tools Including Destructive Operations

A review of `mcp-gitlab-server` at commit `80a7b4cf3fba6b55389c0ef491a48190f7c8996a` uncovered that the SSE HTTP transport — advertised in the README and comparison table as a d…

CVE-2026-44895
GitHub-GHSA

HIGH
Zebra has Permanent Block Discovery Halt via Gossip Queue Saturation and Syncer Poisoning
GHSA-h9hm-m2xj-4rq9
pkg: zebrad
eco: rust
published: May 8, 2026
## Summary

A composite denial-of-service vulnerability in Zebra's block discovery pipeline allows an unauthenticated remote attacker to permanently halt all new block discovery on a targeted node. The attack exploits three independent weaknesses in the gossip, syncer, and download subsystems — al…

CVE-2026-44499
GitHub-GHSA

HIGH
n8n-mcp webhook and API client paths has an authenticated SSRF
GHSA-cmrh-wvq6-wm9r
pkg: n8n-mcp
eco: npm
published: May 8, 2026
### Summary

Authenticated Server-Side Request Forgery affecting the webhook trigger tools, the n8n API client (`N8N_API_URL`), and per-request URLs supplied via the `x-n8n-url` header in multi-tenant HTTP mode.

### Impact

A caller with access to the MCP session can drive HTTP requests from the n8…

CVE-2026-44694
GitHub-GHSA

HIGH
gmaps-mcp's unauthenticated HTTP transport allows unlimited Google Maps API calls at operator expense
GHSA-52cq-7v8r-62c6
pkg: gmaps-mcp
eco: pip
published: May 8, 2026
## Unauthenticated HTTP Transport Allows Unlimited Google Maps API Calls at Operator Expense

The `gmaps-mcp` codebase was reviewed at commit `e671db68c804c9e67d51582d3280839ffa65f127` and three issues worth flagging were discovered — one high-severity, one medium, one structural. There were no pr…

GitHub-GHSA

HIGH
fast-xml-builder allows attribute values with unwanted quotes to bypass malicious or unwanted attributes
GHSA-5wm8-gmm8-39j9
pkg: fast-xml-builder
eco: npm
published: May 8, 2026
# Summary
When an input data has quotes in attribute values but process entities is not enabled, it breaks the attribute value into multiple attributes. This gives the room for an attacker to insert unwanted attributes to the XML/HTML.

## Detail

Malicious Input
“`
{
a: {
"@_attr": '…

CVE-2026-44665
GitHub-GHSA

HIGH
mcp-ssh-tool has file transfer path policy bypass and bearer token comparison hardening
GHSA-j7h9-2jh7-g967
pkg: mcp-ssh-tool
eco: npm
published: May 7, 2026
## Summary

`mcp-ssh-tool` has released version `2.1.1` with security hardening for transfer path authorization and HTTP bearer authentication.

The release addresses:

– insufficient local path policy enforcement in transfer-related filesystem handling
– incomplete canonicalization and segment-boun…

GitHub-GHSA

HIGH
Note Mark: Arbitrary File Write via Path Traversal in Asset Names Leads to Remote Code Execution
GHSA-g49p-4qxj-88v3
pkg: github.com/enchant97/note-mark/backend
eco: go
published: May 7, 2026
### Description

The Note Mark application allows authenticated users to upload assets to notes via `POST /api/notes/{noteID}/assets`, where the asset filename is provided through the `X-Name` HTTP request header. This value is stored directly in the database without any sanitization or validation -…

CVE-2026-44522
GitHub-GHSA

HIGH
Cinny vulnerable to access token disclosure via invalidated emoji pack avatar URL in service worker
GHSA-j944-w549-3453
pkg: cinny
eco: npm
published: May 7, 2026
### Impact
A remote authenticated attacker who shares a room with a victim and has permissions to create room emotes (for example in a DM) can cause the victim's client to send their Matrix access token to an attacker-controlled server. This occurs when the victim opens the emoji or sticker picker f…
CVE-2026-42553
GitHub-GHSA

HIGH
hickory-proto: NSEC3 closest-encloser proof validation enters unbounded loop on cross-zone responses
GHSA-3v94-mw7p-v465
pkg: hickory-proto, hickory-net
eco: rust
published: May 7, 2026
The NSEC3 closest-encloser proof validation in `hickory-proto`'s (0.25.0-alpha.3 … 0.25.2) and `hickory-net`'s (0.26.0-alpha.1 .. 0.26.0) `DnssecDnsHandle` walks from the QNAME up to the SOA owner name, building a list of candidate encloser names. The iterator used assumes the QNAME is a descenda…
GitHub-GHSA

HIGH
Free5GC UDM has Improper Input Validation and Generation of Error Messages Containing Sensitive Information
GHSA-585v-hcgf-jhfr
pkg: github.com/free5gc/udm
eco: go
published: May 7, 2026
## Summary

The free5GC UDM component fails to validate the `supi` path parameter in six GET handlers of the `nudm-sdm` (Subscriber Data Management) service. An unauthenticated attacker can inject control characters into the SUPI parameter, causing UDM to forward a malformed request to UDR and retur…

CVE-2026-42459
GitHub-GHSA

HIGH
Aegra has cross-user run injection in /threads/{thread_id}/runs (IDOR)
GHSA-m98r-6667-4wq7
pkg: aegra-api
eco: pip
published: May 7, 2026
## Impact

Aegra deployments running 0.9.0 through 0.9.6 with multiple authenticated users on a shared instance are vulnerable to a cross-tenant IDOR. Any authenticated user (User A), given another user's `thread_id` (User B), can:

– Execute graph runs against User B's thread via `POST /threads/{th…

CVE-2026-44504
GitHub-GHSA

HIGH
Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host redirect
GHSA-7j59-v9qr-6fq9
pkg: com.microsoft.kiota:microsoft-kiota-abstractions, Microsoft.Kiota.Abstractions, microsoft-kiota-http
eco: npm
published: May 7, 2026
### Summary
The RedirectHandler middleware in microsoft/kiota-java (com.microsoft.kiota:microsoft-kiota-http-okHttp v1.9.0) and other Kiota libraries fails to strip sensitive HTTP headers when following 3xx redirects to a different host or scheme.

This vulnerability is present in the RedirectHandl…

CVE-2026-44503
GitHub-GHSA

HIGH
ldap3_proto has LDAP Filter stack exhaustion
GHSA-qcxq-75wr-5cm8
pkg: ldap3_proto
eco: rust
published: May 6, 2026
### Impact
LDAP queries are not validated for depth, which can cause the parser (both PEG and ASN) to exhaust the stack. This *may* cause a denial of service in applications that process queries.

### Workarounds
N/A

### Resources
Related to GHSA-r5fr-9gmv-jggh

GitHub-GHSA

HIGH
scim_proton and kanidm_proto have an authenticated process abort via SCIM filter stack exhaustion
GHSA-r5fr-9gmv-jggh
pkg: scim_proto, kanidm_proto
eco: rust
published: May 6, 2026
### Summary

A single unauthenticated `GET` to any `/scim/v1/…` endpoint with a `?filter=` query string of a few thousand nested parentheses (≈ 4–12 KB) drives the recursive-descent PEG parser past the worker thread's stack guard page. Rust responds to stack overflow with `std::process::abort(…

GitHub-GHSA

HIGH
Keras vulnerable to DoS via Malicious .keras Model (HDF5 Shape Bomb Causes Petabyte Allocation in KerasFileEditor)
GHSA-mgx6-5cf9-rr43
pkg: keras, keras
eco: pip
published: May 6, 2026
### Summary
Keras’s model loader (KerasFileEditor) unsafely loads user-supplied .keras model files containing HDF5-based weight files without performing any validation on HDF5 dataset metadata. An attacker can craft a .keras archive containing a valid model.weights.h5 file whose dataset declares a…
CVE-2026-0897
GitHub-GHSA

HIGH
Daptin fuzzy search injects unvalidated column name into raw SQL
GHSA-pwqg-q8pg-pp6r
pkg: github.com/daptin/daptin
eco: go
published: May 6, 2026
## Summary

`processFuzzySearch` in `server/resource/resource_findallpaginated.go:1484` splits the user-supplied `column` parameter by comma and interpolates each segment directly into `goqu.L(fmt.Sprintf("LOWER(%s) LIKE ?", prefix+col))` raw SQL with no column whitelist check. The entry point is `G…

CVE-2026-44349
GitHub-GHSA

HIGH
PraisonAI has an SSRF bypass
GHSA-q9pw-vmhh-384g
pkg: praisonaiagents
eco: pip
published: May 6, 2026
### Summary
The URL checking logic in PraisonAI has a logical flaw that could be bypassed by attackers, leading to SSRF attacks.

### Details
The current PraisonAI project uses _validate_url to validate the input URL. The main logic is to perform security checks on the host portion of the URL extrac…

CVE-2026-44335
GitHub-GHSA

HIGH
Mako vulnerable to path traversal via backslash URI on Windows in TemplateLookup
GHSA-2h4p-vjrc-8xpq
pkg: Mako
eco: pip
published: May 6, 2026
## Summary

On Windows, a URI using backslash traversal (e.g. `\..\..\ secret.txt`) bypasses the directory traversal check in `Template.__init__` and the `posixpath`-based normalization in `TemplateLookup.get_template()`, allowing reads of files outside the configured template directory.

## Detail…

CVE-2026-44307
GitHub-GHSA

HIGH
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
GHSA-mqcg-5×36-vfcg
pkg: jupyterlab, notebook
eco: pip
published: May 6, 2026
JupyterLab's HTML sanitizer allowlists `data-commandlinker-command` and `data-commandlinker-args` on `button` elements, while `CommandLinker` listens for all click events on `document.body` and executes the named command without checking whether the element came from trusted JupyterLab UI. A noteboo…
CVE-2026-42557
GitHub-GHSA

HIGH
Mezo: ERC-20 bridgeOut burn can be erased by a stale StateDB overwrite leading to full L1 bridge drain
GHSA-6447-269v-g68m
pkg: github.com/mezo-org/mezod
eco: go
published: May 6, 2026
**Note: the fixed version of the validator client has been deployed for some time.**

### Impact

Potential full drain of L1 bridge without changing bridged balance on Mezo.

## Brief/Intro

A malicious user can steal all ERC-20 tokens locked in the L1 bridge by repeatedly calling the `bridgeOut` pr…

GitHub-GHSA

HIGH
dssrf: every IPv6 category bypasses is_url_safe
GHSA-8p33-q827-ghj5
pkg: dssrf
eco: npm
published: May 6, 2026
A vulnerability in dssrf allows an attacker to bypass its SSRF protections by supplying one of the following IPv6 addresses, resulting in a successful SSRF. This contradicts dssrf documentation, which incorrectly claims that IPv6 is disabled entirely. See below:

“`rust
Input Category
http://[::1]/…

CVE-2026-44232
GitHub-GHSA

HIGH
QuantumNous/new-api has an SSRF Filter Bypass via 0.0.0.0
GHSA-v5c3-6wvc-pc2q
pkg: github.com/QuantumNous/new-api
eco: go
published: May 6, 2026
# SSRF Filter Bypass via `0.0.0.0`

### Summary

The SSRF protection introduced in v0.9.0.5 (CVE-2025-59146) and hardened in v0.9.6 (CVE-2025-62155) does not block the unspecified address `0.0.0.0`. A regular (non-admin) user holding any valid API token can send a multimodal request to `/v1/chat/co…

CVE-2026-42339
GitHub-GHSA

HIGH
Duplicate Advisory: Mistune has a ReDoS in LINK_TITLE_RE that allows denial of service via crafted Markdown input
GHSA-hjph-f4mc-wx4c
pkg: mistune
eco: pip
published: May 6, 2026
### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-8mp2-v27r-99xp. This link is maintained to preserve external references.

### Original Description

### Summary
**Denial-of-Service (DoS)** vulnerability in the Mistune Markdown parser. The issue occurs when pr…

GitHub-GHSA

HIGH
Mistune has a ReDoS in LINK_TITLE_RE that allows denial of service via crafted Markdown input
GHSA-8mp2-v27r-99xp
pkg: mistune
eco: pip
published: May 6, 2026
### Summary

A ReDoS (Regular Expression Denial of Service) vulnerability in `LINK_TITLE_RE` allows an attacker who can supply Markdown for parsing to cause denial of service. A crafted 58-byte Markdown document blocks the parser for approximately 6 seconds (measured on Apple M2, Python 3.14.3), wit…

CVE-2026-33079
GitHub-GHSA

HIGH
jdbi3-freemarker Vulnerable to Improper Neutralization of Special Elements Used in FreeMarker Template Engine
GHSA-mggx-p7jf-jgw4
pkg: org.jdbi:jdbi3-freemarker
eco: maven
published: May 5, 2026
# Summary

**Description**

An Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) vulnerability in Jdbi allows arbitrary command execution when an application using `jdbi3-freemarker` permits attacker-influenced text to reach `FreemarkerEngine.parse()` as template sourc…

GitHub-GHSA

HIGH
authd: Primary group ID is incorrectly set to value of UID
GHSA-fg3j-5w9g-hmg7
pkg: github.com/canonical/authd
eco: go
published: May 5, 2026
authd 0.6.0 contains [a bug](https://github.com/canonical/authd/issues/1482) which can lead to an incorrect primary group ID.

It affects users whose primary group ID (i.e. the GID in the user record) differs from their UID. There are two ways which can lead to this:

1. The user was created with au…

CVE-2026-6970
GitHub-GHSA

HIGH
rust-openssl has undefined behavior in X509Ref::ocsp_responders for certificates with non-UTF-8 OCSP URLs
GHSA-xp3w-r5p5-63rr
pkg: openssl
eco: rust
published: May 5, 2026
`X509Ref::ocsp_responders` returns OCSP responder URLs from a certificate's AIA extension as `OpensslString`, whose `Deref<Target = str>` wraps the raw bytes with `str::from_utf8_unchecked`. OpenSSL does not enforce that the underlying IA5String is ASCII, so a certificate with non-UTF-8 bytes in its…
CVE-2026-42327
GitHub-GHSA

HIGH
RustFS: ListServiceAccount authorizes against wrong admin action, enabling cross-user enumeration and root service account takeover
GHSA-mm2q-qcmx-gw4w
pkg: rustfs
eco: rust
published: May 5, 2026
## Summary

`ListServiceAccount` (`GET /rustfs/admin/v3/list-service-accounts?user=<other>`) authorizes cross-user requests against `UpdateServiceAccountAdminAction` instead of `ListServiceAccountsAdminAction` at `rustfs/src/admin/handlers/service_account.rs:936`. The handler accepts the **wrong** a…

GitHub-GHSA

HIGH
link-preview-js vulnerable to IPv6 and internal loopback attacks
GHSA-4gp8-rjrq-ch6q
pkg: link-preview-js
eco: npm
published: May 5, 2026
### Impact
The library did not check for IPv6 loopback attacks. There was also a DNS attack, where an address could be resolved into an internal IP. This could cause internal data leaks.

### Patches
Problem has been patched in version 4.0.1. However, it cannot be completely solved by the package al…

CVE-2026-43897
GitHub-GHSA

HIGH
gix and gitoxide: unvalidated submodule name traverses out of .git/modules and redirects state() / open() to another repository
GHSA-fr8x-3vfx-f45h
pkg: gitoxide, gix
eco: rust
published: May 5, 2026
## **Summary**
attachments:
[pocs.zip](https://github.com/user-attachments/files/26431422/pocs.zip)

Submodule names coming from `.gitmodules` are exposed as unvalidated names and are later reused to derive the submodule git directory as:

“`
<superproject common_dir>/modules/<submodule name>
“`

GitHub-GHSA

HIGH
gix and gitoxide's symlinked .gitmodules are followed and parsed from outside of the repository
GHSA-pg4w-g64p-qwhj
pkg: gitoxide, gix
eco: rust
published: May 5, 2026
## Summary
attachments:
[pocs.zip](https://github.com/user-attachments/files/26431422/pocs.zip)

When `Repository::submodules()` loads submodule metadata, it prefers the worktree `.gitmodules` file if that path exists. In the current implementation, the path is read with `std::fs::read()`, which fo…

GitHub-GHSA

HIGH
gix-pack has multiple DoS vectors: unchecked indexing panics and uncapped OOM allocations from crafted pack data
GHSA-x494-mj8g-cj27
pkg: gix-pack
eco: rust
published: May 5, 2026
### Summary

Multiple denial-of-service vectors in `gix-pack`: unchecked array indexing causes panics on crafted delta data, and uncapped attacker-controlled size headers enable OOM process kills. Both are triggered by malicious pack data received during clone/fetch.

### Details

**Bug 1: Unchecked…

GitHub-GHSA

HIGH
gix's submodule name validation bypass + trust inheritance flaw enables path traversal and credential disclosure
GHSA-p3hw-mv63-rf9w
pkg: gix, gix-validate
eco: rust
published: May 5, 2026
### Summary

Submodule name validation bypass plus missing validation in production code paths allows path traversal via crafted `.gitmodules`. Combined with a trust inheritance flaw in `Submodule::open()`, this enables reading arbitrary git repository configs (including credentials) from traversed …

GitHub-GHSA

HIGH
Diesel's SQLite backend has possible UTF-8 corruption
GHSA-h5x4-m2qf-r4f2
pkg: diesel
eco: rust
published: May 5, 2026
Diesel uses the `sqlite3_value_text` function to receive strings from SQLite while deserializing query results. We misinterpreted the corresponding [SQLite](https://sqlite.org/c3ref/value_blob.html) documentation that this function always returns a UTF-8 encoded string values as `*const c_char`. Bas…
GitHub-GHSA

HIGH
Network-AI missing authentication on MCP HTTP endpoint, which allows unauthenticated privileged tool calls
GHSA-fj4g-2p96-q6m3
pkg: network-ai
eco: npm
published: May 5, 2026
# Security Advisory: Missing Authentication for Critical Function in `Jovancoding/Network-AI`

| Field | Value |
|—|—|
| Project | `Jovancoding/Network-AI` |
| Repository | https://github.com/Jovancoding/Network-AI |
| Affected commit | `c344f2053eb0d49395988f803bf92f2a86b2a0d0` |
| Affected tes…

CVE-2026-42856
GitHub-GHSA

HIGH
net-imap vulnerable to STARTTLS stripping via invalid response timing
GHSA-vcgp-9326-pqcp
pkg: net-imap, net-imap, net-imap
eco: rubygems
published: May 4, 2026
### Summary

A man-in-the-middle attacker can cause `Net::IMAP#starttls` to return "successfully", without starting TLS.

### Details

When using `Net::IMAP#starttls` to upgrade a plaintext connection to use TLS, a man-in-the-middle attacker can inject a tagged `OK` response with an easily predictab…

CVE-2026-42246
GitHub-GHSA

MEDIUM
Axios: unbounded recursion in toFormData causes DoS via deeply nested request data
GHSA-62hf-57xw-28j9
pkg: axios, axios
eco: npm
published: May 5, 2026
### Summary
toFormData recursively walks nested objects with no depth limit, so a deeply nested value passed as request data crashes the Node.js process with a RangeError.

### Details
lib/helpers/toFormData.js:210 defines an inner `build(value, path)` that recurses into every object/array child (li…

CVE-2026-42039
GitHub-GHSA

MEDIUM
Volcano's webhook server vulnerable to OOM due to unbounded HTTP request body size
GHSA-8wxp-xxp2-rcgx
pkg: volcano.sh/volcano, volcano.sh/volcano, volcano.sh/volcano
eco: go
published: May 8, 2026
### Impact
The Volcano webhook server does not enforce a size limit on incoming HTTP request bodies. Any in-cluster pod that can reach the webhook endpoint may send an arbitrarily large request body, potentially causing the webhook server to be killed by OOM. All Volcano deployments with the webhook…
CVE-2026-44247
NVD

MEDIUM
CVE-2026-42194
CVE-2026-42194
pkg: curl

published: May 7, 2026

Admidio is an open-source user management solution. Prior to version 5.0.9, the incomplete SSRF fix in Admidio's fetch_metadata.php validates the resolved IP address but passes the original hostname-based URL to curl_init(), leaving a DNS rebinding TOCTOU window that allows redirecting requests to i…
CWE: CWE-918
GitHub-GHSA

MEDIUM
Netty Redis Codec Encoder has a CRLF Injection Issue
GHSA-rgrr-p7gp-5xj7
pkg: io.netty:netty-codec-redis, io.netty:netty-codec-redis
eco: maven
published: May 7, 2026
# Security Vulnerability Report: CRLF Injection in Netty Redis Codec Encoder

## 1. Vulnerability Summary

| Field | Value |
|——-|——-|
| **Product** | Netty |
| **Version** | 4.2.12.Final (and all prior versions with codec-redis) |
| **Component** | `io.netty.handler.codec.redis.RedisEncoder…

CVE-2026-42586
GitHub-GHSA

MEDIUM
Lemur: LDAP Authentication Globally Disables TLS Certificate Verification When LDAP_USE_TLS Is Enabled
GHSA-vr7c-r5gj-j3w5
pkg: lemur
eco: pip
published: May 6, 2026
## Description

### Overview

When LDAP TLS is enabled (`LDAP_USE_TLS = True`), Lemur's LDAP authentication module unconditionally disables TLS certificate verification at the **global** `ldap` module level. This allows a man-in-the-middle attacker positioned between Lemur and the LDAP server to int…

CVE-2026-44305
GitHub-GHSA

MEDIUM
wireshark-mcp vulnerable to arbitrary file write via export_objects when WIRESHARK_MCP_ALLOWED_DIRS is not configured
GHSA-3r68-x3xc-rxpg
pkg: wireshark-mcp
eco: pip
published: May 5, 2026
## Description

### Impact

`wireshark-mcp` exposes a `wireshark_export_objects` MCP tool that accepts an attacker-controlled `dest_dir` parameter and passes it to tshark's `–export-objects` flag with **no mandatory path restriction**.

The path sandbox (`_allowed_dirs`) is `None` by default and on…

CVE-2026-43901
GitHub-GHSA

MEDIUM
gix-transport: HTTP credentials leaked to redirected host in curl backend
GHSA-9857-6mw7-fq2m
pkg: gix-transport
eco: rust
published: May 5, 2026
## Summary

The curl-based HTTP transport in `gix-transport` sends user credentials (passwords, tokens) to an attacker-controlled server after an HTTP redirect. When a server responds with a 302 redirect during the initial `GET /info/refs`, gitoxide records the redirected base URL and rewrites all s…

GitHub-GHSA

MEDIUM
Axios: no_proxy bypass via IP alias allows SSRF
GHSA-m7pr-hjqh-92cm
pkg: axios, axios
eco: npm
published: May 5, 2026
The fix for no_proxy hostname normalization bypass (#10661) is incomplete.When no_proxy=localhost is set, requests to 127.0.0.1 and [::1] still route through the proxy instead of bypassing it.

The shouldBypassProxy() function does pure string matching — it does not
resolve IP aliases or loopback…

CVE-2026-42038
GitHub-GHSA

MEDIUM
view_component: Preview Route Can Dispatch Inherited Helper Methods
GHSA-7f3r-gwc9-2995
pkg: view_component
eco: rubygems
published: May 8, 2026
### Summary

The preview route derives an example name from the URL and calls it with `public_send`. The code does not verify that the requested method is one of the preview examples explicitly defined by the preview class.

As a result, inherited public methods on `ViewComponent::Preview` are route…

CVE-2026-44836
GitHub-GHSA

MEDIUM
free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface type assertion (single authenticated request)
GHSA-jqfc-gwj5-3w63
pkg: github.com/free5gc/udr
eco: go
published: May 8, 2026
### Summary
free5GC's UDR `nudr-dr` `DELETE /subscription-data/{ueId}/{servingPlmnId}/ee-subscriptions/{subsId}/amf-subscriptions` handler panics on a single authenticated request against a fresh UDR instance when the supplied `ueId` does not exist in `UESubsCollection`. The processor checks `value,…
CVE-2026-44324
GitHub-GHSA

MEDIUM
free5GC's BSF concurrent PUT /nbsf-management/v1/subscriptions/{subId} crashes the BSF process via concurrent map read/write on Subscriptions
GHSA-27ph-8q4f-h7m7
pkg: github.com/free5gc/bsf
eco: go
published: May 8, 2026
### Summary
free5GC's BSF `PUT /nbsf-management/v1/subscriptions/{subId}` handler has an unsynchronized write on the global `Subscriptions` map. The handler first reads the map under `RLock()` via `BSFContext.GetSubscription(subId)`, but if the subscription does not exist, `ReplaceIndividualSubcript…
CVE-2026-44318
GitHub-GHSA

MEDIUM
free5GC's PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing AfRoutReq via nil pointer dereference
GHSA-wwqh-7jm5-gj7w
pkg: github.com/free5gc/pcf
eco: go
published: May 8, 2026
### Summary
free5GC's PCF `POST /npcf-policyauthorization/v1/app-sessions` handler panics on a single authenticated request whose `ascReqData.suppFeat == "1"` (enabling traffic-routing feature negotiation) and whose `medComponents` entries supply an `afAppId` but NO `AfRoutReq`. The create path then…
CVE-2026-44317
GitHub-GHSA

MEDIUM
OpenTelemetry.Exporter.Instana bypasses TLS certificate validation when a proxy is configured
GHSA-wfr5-454p-mjc2
pkg: OpenTelemetry.Exporter.Instana
eco: nuget
published: May 8, 2026
### Summary

The `OpenTelemetry.Exporter.Instana` NuGet package does not validate HTTPS/TLS certificates are valid when sending telemetry to a configured Instana back-end when a proxy is configured using the `INSTANA_ENDPOINT_PROXY` environment variable.

If a network attacker can Man-in-the-Middle …

CVE-2026-44213
GitHub-GHSA

MEDIUM
Wagtail has improper permission handling when copying pages
GHSA-67rv-mg8q-5pf3
pkg: wagtail, wagtail
eco: pip
published: May 8, 2026
### Impact

A CMS user with limited access to pages could copy a page they don't have access to to an area of the site they do. Once copied, they'd be able to view its contents, and potentially publish it. Permissions were correctly checked for the copy destination, but not for the source page.

###…

CVE-2026-44200
GitHub-GHSA

MEDIUM
Wagtail has improper permission handling when deleting form submissions
GHSA-pwm3-7fv4-g6xx
pkg: wagtail, wagtail
eco: pip
published: May 8, 2026
### Impact

A CMS user with limited access to form pages could delete submissions to form pages they don't have access to by crafting a form submission to delete submissions on a page they do have access to for submissions they don't.

The vulnerability is not exploitable by an ordinary site visito…

CVE-2026-44199
GitHub-GHSA

MEDIUM
Wagtail has improper permission handling when comparing revisions
GHSA-c6wj-9vcj-75pj
pkg: wagtail, wagtail
eco: pip
published: May 8, 2026
### Impact

A CMS user without the ability to edit a page could access revisions of the page through the revision compare view if they knew the primary key of two revisions. This could potentially result in disclosure of sensitive information.

### Patches

Patched versions have been released as Wag…

CVE-2026-44197
GitHub-GHSA

MEDIUM
Open WebUI has Unauthorized File and Knowledge Base Content Access via RAG Vector Search
GHSA-h36f-rqpx-j5wx
pkg: open-webui
eco: pip
published: May 8, 2026
# Unauthorized File and Knowledge Base Content Access via RAG Vector Search

## Affected Component

RAG source resolution in chat completion pipeline:
– `backend/open_webui/retrieval/utils.py` (lines 963-965, 1063-1068, 1126-1131 in `get_sources_from_items`)

## Affected Versions

Current main branc…

CVE-2026-44560
GitHub-GHSA

MEDIUM
Open WebUI's Model Import Overwrites Any Model Without Ownership Check
GHSA-mqq6-cqcx-38vg
pkg: open-webui
eco: pip
published: May 8, 2026
# Model Import Overwrites Any Model Without Ownership Check

## Affected Component

Model import endpoint:
– `backend/open_webui/routers/models.py` (lines 254-308, `import_models`)

## Affected Versions

Current main branch (commit `6fdd19bf1`) and likely all versions with model import functionality…

CVE-2026-44562
GitHub-GHSA

MEDIUM
Electerm's full process.env exposed to renderer via window.pre.env
GHSA-37j4-88rp-2f6h
pkg: electerm
eco: npm
published: May 8, 2026
### Impact

The `getConstants()` IPC handler in `src/app/lib/ipc-sync.js` serialises the entire `process.env` object and sends it to the renderer. The data is stored as `window.pre.env` and is accessible from any JavaScript running in the renderer (e.g., via the DevTools console or a compromised web…

CVE-2026-43942
NVD

MEDIUM
CVE-2026-41585
CVE-2026-41585
pkg: zfnd zebra-rpc, zfnd zebrad

published: May 8, 2026

ZEBRA is a Zcash node written entirely in Rust. From zebrad versions 2.2.0 to before 4.3.1 and from zebra-rpc versions 1.0.0-beta.45 to before 6.0.2, a vulnerability in Zebra's JSON-RPC HTTP middleware allows an authenticated RPC client to cause a Zebra node to crash by disconnecting before the requ…
CWE: CWE-248, CWE-617
GitHub-GHSA

MEDIUM
Ech0 allows PUT /api/echo/like/:id unauthenticated: anonymous callers to modify any echo's fav_count
GHSA-pj6q-4vq4-r8cg
pkg: github.com/lin-snow/Ech0
eco: go
published: May 7, 2026
## Summary

`PUT /api/echo/like/:id` at `internal/router/echo.go:12` is registered on `PublicRouterGroup` with no authentication and no rate limit. Anonymous callers increment the `fav_count` counter on any echo (including private echoes) by UUID, repeat the request without deduplication, and trigge…

NVD

MEDIUM
CVE-2026-33589
CVE-2026-33589
pkg: lfnovo open-notebook

published: May 7, 2026

Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to access local files content from the docker container via path traversal.
CWE: CWE-20
GitHub-GHSA

MEDIUM
vm2 Host Promise Resolution Preserves Object Identity Across Sandbox Boundary
GHSA-mpf8-4hx2-7cjg
pkg: vm2
eco: npm
published: May 7, 2026
### Summary

A sandbox boundary violation in **vm2** allows host object identity to cross into the sandbox through host Promise resolution.

When a host-side Promise that resolves to a host object is exposed to the sandbox, the value delivered to the sandbox `.then()` callback preserves host identit…

CVE-2026-44000
GitHub-GHSA

MEDIUM
ShellHub has cross-tenant IDOR in `GET /api/namespaces/:tenant` via API Key bypasses membership check
GHSA-vwx9-7qcf-gg7f
pkg: github.com/shellhub-io/shellhub
eco: go
published: May 7, 2026
## Summary
`GET /api/namespaces/:tenant` returns the full namespace object — including the members list (user IDs, e-mails, roles), settings, and device counts — to any caller authenticated by an **API Key**, for any tenant, regardless of the API Key's own tenant scope.

The handler conditionall…

CVE-2026-44426
GitHub-GHSA

MEDIUM
Daptin's Session Management Vulnerability Leads to Insufficient Session Expiration After Password Change
GHSA-258c-965c-p3hc
pkg: github.com/daptin/daptin
eco: go
published: May 7, 2026
### Summary

A session invalidation vulnerability exists in daptin's authentication system where JSON Web Tokens (JWTs) remain fully valid after a user changes their password. The JWT validation middleware (`CheckJWT`) only verifies token signature, expiry, issuer, and signing algorithm — it does …

GitHub-GHSA

MEDIUM
Kubetail has a Cross-Site WebSocket Hijacking issue that allows attacker to read Kubernetes logs from authenticated users
GHSA-v8j7-hp7c-738f
pkg: github.com/kubetail-org/kubetail/modules/dashboard, github.com/kubetail-org/kubetail/modules/cli
eco: go
published: May 7, 2026
### Summary

Kubetail's dashboard exposes WebSocket endpoints that did not adequately validate the Origin header on connection upgrade. A malicious web page visited by a user with an active Kubetail session could open a WebSocket to the user's dashboard and read their Kubernetes logs in real time. T…

CVE-2026-44514
GitHub-GHSA

MEDIUM
Netty vulnerable to HTTP Request Smuggling due to malformed Transfer-Encoding
GHSA-38f8-5428-x5cv
pkg: io.netty:netty-codec-http, io.netty:netty-codec-http
eco: maven
published: May 7, 2026
### Summary
Netty incorrectly parses malformed Transfer-Encoding, enabling request smuggling attacks.

### Details
Netty incorrectly marks a request as chunked when malformed "Transfer-Encoding: chunked, identity" is present.
According to RFC https://datatracker.ietf.org/doc/html/rfc9112#name-messag…

CVE-2026-42585
GitHub-GHSA

MEDIUM
Netty vulnerable to HTTP Request Smuggling due to incorrect chunk size parsing
GHSA-m4cv-j2px-7723
pkg: io.netty:netty-codec-http, io.netty:netty-codec-http
eco: maven
published: May 7, 2026
### Summary
Netty's chunk size parser silently overflows int, enabling request smuggling attacks.

### Details
io.netty.handler.codec.http.HttpObjectDecoder#getChunkSize silently overflows int.

The size is accumulated as follows:

result *= 16;
result += digit;

The result is checked only for negat…

CVE-2026-42580
GitHub-GHSA

MEDIUM
Hono: bodyLimit() can be bypassed for chunked / unknown-length requests
GHSA-9vqf-7f2p-gf9v
pkg: hono
eco: npm
published: May 6, 2026
## Summary

`bodyLimit()` does not reliably enforce `maxSize` for requests without a usable `Content-Length` (e.g. `Transfer-Encoding: chunked`). Oversized requests can reach handlers and return `200` instead of `413`.

## Details

For chunked / unknown-length requests, `bodyLimit()` wraps the body …

CVE-2026-44456
GitHub-GHSA

MEDIUM
ShellHub has cross-tenant IDOR in `GET /api/sessions/:uid` that discloses SSH session data
GHSA-9w9c-9w8m-w89q
pkg: github.com/shellhub-io/shellhub
eco: go
published: May 6, 2026
## Summary
`GET /api/sessions/:uid` returns the full session object for any authenticated caller, without scoping by the caller's tenant. An authenticated user can read session records (SSH username, device UID, remote IP, terminal type, authenticated flag, timestamps) belonging to any other namespa…
CVE-2026-44423
GitHub-GHSA

MEDIUM
ShellHub has cross-tenant IDOR in `GET /api/devices/:uid` that discloses device data of any namespace
GHSA-j72x-xfwg-783f
pkg: github.com/shellhub-io/shellhub
eco: go
published: May 6, 2026
## Summary
`GET /api/devices/:uid` returns the full device object whenever the caller is authenticated, without verifying that the device belongs to the caller's namespace (tenant). Any authenticated user (JWT or API Key) who knows or can guess a device UID can read device metadata from any other na…
CVE-2026-44424
GitHub-GHSA

MEDIUM
vLLM: extract_hidden_states speculative decoding crashes server on any request with penalty parameters
GHSA-83vm-p52w-f9pw
pkg: vllm
eco: pip
published: May 6, 2026
### Summary

The `extract_hidden_states` speculative decoding proposer in vLLM returns a tensor with an incorrect shape after the first decode step, causing a `RuntimeError` that crashes the EngineCore process. The crash is triggered when any request in the batch uses sampling penalty parameters (`r…

CVE-2026-44223
NVD

MEDIUM
CVE-2026-40197
CVE-2026-40197
pkg: linuxcontainers incus

published: May 6, 2026

Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage volume import logic allows an authenticated user with access to the storage volume feature to cause the Incus daemon to crash. The custom volume backup import subsystem contains…
CWE: CWE-476
GitHub-GHSA

MEDIUM
Nginx-UI Settings API Exposes Protected Secrets
GHSA-q4w7-56hr-83rm
pkg: github.com/0xJacky/nginx-ui
eco: go
published: May 6, 2026
### Summary
The `GetSettings` API handler (`api/settings/settings.go:24-65`) serializes all settings structs to JSON and returns them to authenticated users. Many sensitive fields are tagged with `protected:"true"` – however, this tag is only enforced during writes (via `ProtectedFill` in `SaveSetti…
CVE-2026-42223
GitHub-GHSA

MEDIUM
vLLM Vulnerable to Remote DoS via Special-Token Placeholders
GHSA-hpv8-x276-m59f
pkg: vllm
eco: pip
published: May 5, 2026
## Summary
This report explains a Token Injection vulnerability in vLLM’s multimodal processing. Unauthenticated, text-only prompts that spell special tokens are interpreted as control. Image and video placeholder sequences supplied without matching data cause vLLM to index into empty grids during…
CVE-2026-44222
GitHub-GHSA

MEDIUM
PyLoad Vulnerable to Path Traversal via Package Folder Name
GHSA-97r3-5w84-r4q8
pkg: pyload-ng
eco: pip
published: May 5, 2026
Insufficient sanitization of package folder names allows writing files outside the intended download directory.

## Affected Component
– `src/pyload/core/api/__init__.py`
– Function: `add_package()`

## Description
Package folder names are sanitized using insufficient string replacement:

“`python

CVE-2026-42314
GitHub-GHSA

MEDIUM
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback
GHSA-7jrr-xw9c-mj39
pkg: github.com/0xJacky/Nginx-UI
eco: go
published: May 5, 2026
## Summary
An authenticated user can call `GET /api/settings` and retrieve sensitive configuration values, including `node.secret`. The same `node.secret` is accepted by `AuthRequired()` through the `X-Node-Secret` header (or `node_secret` query parameter), causing the request to be treated as authe…
CVE-2026-42220
NVD

MEDIUM
CVE-2026-32603
CVE-2026-32603
pkg: sandboxie-plus sandboxie

published: May 5, 2026

Sandboxie is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, a local denial of service vulnerability exists in the Sandboxie kernel driver. An unprivileged process running inside a Standard Sandbox can send a malformed IOCTL to the \Device\SandboxieDriver…
CWE: CWE-20
GitHub-GHSA

MEDIUM
requests-hardened is Vulnerable to Server-Side Request Forgery
GHSA-vh75-fwv3-pqrh
pkg: requests-hardened
eco: pip
published: May 5, 2026
The SSRF protection in `requests-hardened` prior to version 1.2.1 fails to block IP addresses within the RFC 6598 Shared Address Space (`100.64.0.0/10`). An attacker who can supply arbitrary URLs to `requests-hardened` could exploit this gap to access internal services hosted within `100.64.0.0/10`.…
CVE-2026-42175
NVD

MEDIUM
CVE-2026-30246
CVE-2026-30246
pkg: go

published: May 5, 2026

Fiber is a web framework for Go. In github.com/gofiber/fiber/v3 versions through 3.1.0, the default key generator in the cache middleware uses only the request path and does not include the query string. As a result, requests for the same path with different query parameters can share a cache key an…
CWE: CWE-436
GitHub-GHSA

MEDIUM
OpenClaw contains a symlink traversal vulnerability
GHSA-35mw-5vvr-vrxc
pkg: openclaw
eco: npm
published: May 5, 2026
OpenClaw versions 2026.3.22 before 2026.4.5 contain a symlink traversal vulnerability in remote marketplace repository path handling that allows attackers to escape the expected repository root. Attackers can exploit this by providing crafted symlink paths to access files outside the intended reposi…
CVE-2026-43570
GitHub-GHSA

MEDIUM
Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`
GHSA-3w6x-2g7m-8v23
pkg: axios
eco: npm
published: May 5, 2026
# Vulnerability Disclosure: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`

## Summary

The Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any `Object.prototype` pollution in the application's dependency tree to be escalated into …

CVE-2026-42044
NVD

MEDIUM
CVE-2026-42223
CVE-2026-42223
pkg: nginxui nginx_ui

published: May 4, 2026

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, the GetSettings API handler (api/settings/settings.go:24-65) serializes all settings structs to JSON and returns them to authenticated users. Many sensitive fields are tagged with protected:"true" – however, this tag …
CWE: CWE-200
NVD

MEDIUM
CVE-2026-42220
CVE-2026-42220
pkg: nginxui nginx_ui

published: May 4, 2026

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, an authenticated user can call GET /api/settings and retrieve sensitive configuration values, including node.secret. The same node.secret is accepted by AuthRequired() through the X-Node-Secret header (or node_secret …
CWE: CWE-200, CWE-863
NVD

MEDIUM
CVE-2026-42228
CVE-2026-42228
pkg: n8n n8n

published: May 4, 2026

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the /chat WebSocket endpoint used by the Chat Trigger node's Hosted Chat feature did not verify that an incoming connection was authorized to interact with the target execution. An unauthenticated rem…
CWE: CWE-862
NVD

MEDIUM
CVE-2026-42092
CVE-2026-42092
pkg: go

published: May 4, 2026

titra is an open source time tracking project. In version 0.99.52, the globalsettings Meteor publication returns all global settings without any admin or role check. Any authenticated user can subscribe via DDP and receive sensitive configuration fields such as google_secret, openai_apikey, and goog…
CWE: CWE-200
NVD

MEDIUM
CVE-2026-42091
CVE-2026-42091
pkg: go

published: May 4, 2026

goshs is a SimpleHTTPServer written in Go. Prior to version 2.0.2, the PUT upload handler (httpserver/updown.go) lacks the CSRF token validation that was added to the POST upload handler during the CVE-2026-40883 fix. Combined with the unconditional Access-Control-Allow-Origin: * on the OPTIONS pref…
CWE: CWE-352
GitHub-GHSA

MEDIUM
kube-router: GoBGP gRPC Admin Port Exposed on Node Primary IP Without Authentication, Allowing Cluster-Wide BGP Route Injection
GHSA-v5mh-h5hx-7v92
pkg: github.com/cloudnativelabs/kube-router
eco: go
published: May 6, 2026
## Summary

When the kube-router routing controller starts (`–run-router`), it binds the GoBGP gRPC management server to the node's primary IP (e.g., `192.168.1.10:50051`) in addition to `127.0.0.1:50051`. The default admin port is `50051` and the server is enabled by default with no TLS and no aut…

GitHub-GHSA

MEDIUM
go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth
GHSA-w239-58×2-q8p5
pkg: github.com/ipld/go-ipld-prime
eco: go
published: May 7, 2026
The DAG-CBOR and DAG-JSON decoders recurse on each nested map or list without a depth limit. A payload containing deeply nested collections causes the decoder to recurse once per level, growing the goroutine stack until the Go runtime terminates the process with a fatal stack overflow (distinct from…
CVE-2026-42328
GitHub-GHSA

MEDIUM
@evomap/evolver has an unbounded request body in proxy /asset/submit that causes persistent disk-exhaustion DoS
GHSA-7xp7-m392-h92c
pkg: @evomap/evolver
eco: npm
published: May 5, 2026
## Summary

The EvoMap proxy daemon's HTTP body parser accepts requests of any size, and the `POST /asset/submit` route persists the full request body — verbatim and uncapped — as a JSONL line in `<dataDir>/messages.jsonl`. An unauthenticated local attacker (other local user, container neighbor,…

GitHub-GHSA

MEDIUM
LobeHub has a Cross-Site Scripting issue that escalates to Remote Code Execution
GHSA-xq4x-622m-q8fq
pkg: @lobehub/lobehub
eco: npm
published: May 5, 2026
### Summary
The vulnerability was automatically discovered by an ai agent and then manually verified.

LobeChat's message rendering mechanism has a stored cross-site scripting (XSS) vulnerability. Combined with the Electron main process's exposed insecure IPC interface, attackers can construct malic…

CVE-2026-42045
GitHub-GHSA

MEDIUM
Mistune Heading ID Attribute has Injection XSS
GHSA-v87v-83h2-53w7
pkg: mistune
eco: pip
published: May 9, 2026
## Summary
`HTMLRenderer.heading()` builds the opening `<hN>` tag by string-concatenating the `id` attribute value directly into the HTML — with no call to `escape()`, `safe_entity()`, or any other sanitisation function. A double-quote character `"` in the `id` value terminates the attribute, allo…
CVE-2026-44897
GitHub-GHSA

MEDIUM
Mistune Math Plugin has an XSS Escape Bypass
GHSA-8g87-j6q8-g93x
pkg: mistune
eco: pip
published: May 8, 2026
## Summary
The mistune math plugin renders inline math (`$…$`) and block math (`$$…$$`) by concatenating the raw user-supplied content directly into the HTML output **without any HTML escaping**. This occurs even when the parser is explicitly created with `escape=True`, which is supposed to guar…
CVE-2026-44708
GitHub-GHSA

MEDIUM
fast-xml-builder Comment Value regex can be bypassed
GHSA-45c6-75p6-83cc
pkg: fast-xml-builder
eco: npm
published: May 8, 2026
# Summary
The fix for https://github.com/advisories/GHSA-gh4j-gqv2-49f6 in fast-xml-parser sanitizes `–` sequences in XML comment content using .replace(/–/g, '- -'). This skip the values containing three consecutive dashes (e.g., —>…), allowing an attacker to break out of an XML comment and i…
CVE-2026-44664
GitHub-GHSA

MEDIUM
Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler
GHSA-jp94-3292-c3xv
pkg: devise
eco: rubygems
published: May 8, 2026
## Summary

When the `Timeoutable` module is enabled in Devise, the `FailureApp#redirect_url` method returns `request.referrer` — the HTTP `Referer` header, which is attacker-controllable — without validation for any non-GET request that results in a session timeout. An attacker who hosts a page…

CVE-2026-40295
GitHub-GHSA

MEDIUM
Free5GC AMF Bypasses UE Security Capabilities on NGAP PathSwitchRequest
GHSA-77×9-rf64-92gv
pkg: github.com/free5gc/amf
eco: go
published: May 7, 2026
### Summary
The AMF in Free5GC v4.2.1 does not verify the UE Security Capabilities received in NGAP PathSwitchRequest messages against its locally stored values, as mandated by 3GPP TS 33.501 §6.7.3.1. A malicious gNB can overwrite the AMF's stored UE security capabilities with arbitrary values, wh…
CVE-2026-42081
GitHub-GHSA

MEDIUM
Kanidm: Stored HTML injection in "passkey-enrolment" partial via displayname → htmx-driven authenticated request forgery
GHSA-gpxg-fx2g-qxj2
pkg: kanidm
eco: rust
published: May 6, 2026
### Summary

The kanidmd web UI renders the WebAuthn passkey-registration challenge as raw JSON inside an inline `<script id="data">` element using the Askama `|safe` filter. The challenge embeds the account's `displayname`, which `serde_json` serialises without escaping `<`/`>`. A `displayname` con…

GitHub-GHSA

MEDIUM
Kyverno policy-reporter-ui has XSS via Stored Property Values in PropertyCard Component
GHSA-q98m-7w8c-w388
pkg: github.com/kyverno/policy-reporter-ui
eco: go
published: May 6, 2026
### Summary
Vue 3's v-html directive is the framework-documented mechanism for injecting raw HTML, and it intentionally disables the auto-escaping that {{ }} interpolation provides. The PropertyCard.vue component uses v-html for the else branch of the URL check, meaning any non-URL string value flow…
CVE-2026-44245
NVD

MEDIUM
CVE-2026-42230
CVE-2026-42230
pkg: n8n n8n

published: May 4, 2026

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the /mcp-oauth/register endpoint accepted OAuth client registrations without authentication, allowing arbitrary redirect_uri values to be registered. When a user denies the MCP OAuth consent dialog, t…
CWE: CWE-601
GitHub-GHSA

MEDIUM
OpenClaw's Webhooks SecretRef route secret remains valid after rotation/reload
GHSA-q8ff-7ffm-m3r9
pkg: openclaw
eco: npm
published: May 5, 2026
## Summary

OpenClaw webhooks allowed route secrets to be backed by `SecretRef` values, but cached the resolved secret for a route. After an operator rotated the underlying secret and ran `openclaw secrets reload`, the previous resolved webhook secret could remain valid until the plugin or gateway r…

GitHub-GHSA

MEDIUM
SharpCompress has directory traversal via directory entries in WriteToDirectory (zip slip variant)
GHSA-6c8g-7p36-r338
pkg: SharpCompress
eco: nuget
published: May 8, 2026
### Summary

A path traversal vulnerability in `IArchive.WriteToDirectory()` allows a malicious archive to create directories outside the intended extraction root. For TAR archives, this can be escalated to arbitrary file writes by chaining with a symlink entry, giving a full write primitive on the …

CVE-2026-44788
GitHub-GHSA

MEDIUM
view_component: System Test Entry Point Path Check Allows Sibling Directory Escape
GHSA-hg3h-g7xc-f7vp
pkg: view_component
eco: rubygems
published: May 8, 2026
### Summary

The system test entrypoint canonicalizes a user-controlled file path with `File.realpath`, then checks whether the resolved path starts with the temp directory path. This is not a safe containment check because sibling directories can share the same string prefix.

Severity: Medium; tes…

CVE-2026-44837
GitHub-GHSA

MEDIUM
Gotenberg allows Chromium URL conversion routes to read arbitrary files under /tmp via file:// scheme
GHSA-g924-cjx7-2rjw
pkg: github.com/gotenberg/gotenberg/v8
eco: go
published: May 7, 2026
## Summary

The `/forms/chromium/convert/url` and `/forms/chromium/screenshot/url` routes accept `url=file:///tmp/…` from anonymous callers. The default Chromium deny-list intentionally exempts `file:///tmp/` so HTML/Markdown routes can load their own request-local assets, and those routes apply a…

CVE-2026-42597
GitHub-GHSA

MEDIUM
axonflow-sdk-java: Webhook signing-key (HMAC-SHA256) not exposed by SDK type, preventing signature verification
GHSA-248h-974q-xrc2
pkg: com.getaxonflow:axonflow-sdk
eco: maven
published: May 6, 2026
## Summary

The AxonFlow SDK's `WebhookSubscription` (or equivalent) type did not expose the HMAC-SHA256 signing key returned by the platform's `CreateWebhook` endpoint. Without access to the secret through the typed SDK API, callers had no path to verify the `X-AxonFlow-Signature` header on incomin…

GitHub-GHSA

MEDIUM
axonflow-sdk-typescript: Webhook signing-key (HMAC-SHA256) not exposed by SDK type, preventing signature verification
GHSA-mph8-9v29-pm42
pkg: @axonflow/sdk
eco: npm
published: May 6, 2026
## Summary

The AxonFlow SDK's `WebhookSubscription` (or equivalent) type did not expose the HMAC-SHA256 signing key returned by the platform's `CreateWebhook` endpoint. Without access to the secret through the typed SDK API, callers had no path to verify the `X-AxonFlow-Signature` header on incomin…

GitHub-GHSA

MEDIUM
axonflow-sdk-go: Webhook signing-key (HMAC-SHA256) not exposed by SDK type, preventing signature verification
GHSA-mhc4-qq83-fmrr
pkg: github.com/getaxonflow/axonflow-sdk-go/v5
eco: go
published: May 6, 2026
## Summary

The AxonFlow SDK's `WebhookSubscription` (or equivalent) type did not expose the HMAC-SHA256 signing key returned by the platform's `CreateWebhook` endpoint. Without access to the secret through the typed SDK API, callers had no path to verify the `X-AxonFlow-Signature` header on incomin…

GitHub-GHSA

MEDIUM
axonflow-sdk-python: Webhook signing-key (HMAC-SHA256) not exposed by SDK type, preventing signature verification
GHSA-7f4h-6264-89fr
pkg: axonflow
eco: pip
published: May 6, 2026
## Summary

The AxonFlow SDK's `WebhookSubscription` (or equivalent) type did not expose the HMAC-SHA256 signing key returned by the platform's `CreateWebhook` endpoint. Without access to the secret through the typed SDK API, callers had no path to verify the `X-AxonFlow-Signature` header on incomin…

GitHub-GHSA

MEDIUM
Granian vulnerable to DoS via WSGI response header panic
GHSA-f5p7-9fr5-8jmj
pkg: granian
eco: pip
published: May 6, 2026
### Summary

Granian aborts a worker process if a WSGI application returns an invalid HTTP response header name or value. The WSGI response conversion path uses `.unwrap()` on both the header name and header value constructors, so malformed output from the application becomes a process abort instead…

CVE-2026-42545
GitHub-GHSA

MEDIUM
OpAMP client reads unbounded HTTP response bodies
GHSA-w2jh-77fq-7gp8
pkg: OpenTelemetry.OpAmp.Client
eco: nuget
published: May 5, 2026
### Summary

When receiving responses from the OpAMP server over HTTP, the OpAMP client allocates an unbounded buffer to read all bytes from the server, with no upper-bound on the number of bytes consumed.

This could cause memory exhaustion in the consuming application if the configured OpAMP serve…

CVE-2026-42348
GitHub-GHSA

MEDIUM
eventsource-encoder vulnerable to SSE event injection via unsanitized `event` and `id` fields
GHSA-m9g3-3g99-mhpx
pkg: eventsource-encoder
eco: npm
published: May 8, 2026
### Summary

`eventsource-encoder` does not sanitize the `event` or `id` fields of an `EventSourceMessage` before serializing them. An attacker who controls either field can inject arbitrary Server-Sent Events line terminators (`\n`, `\r`, or `\r\n`) and thereby forge additional SSE fields or entire…

CVE-2026-44214
GitHub-GHSA

MEDIUM
vm2 is Vulnerable to Host File Path Disclosure via Stack Trace Information Leak
GHSA-v27g-jcqj-v8rw
pkg: vm2
eco: npm
published: May 7, 2026
### Summary
vm2's `CallSite` wrapper class (intended as a safe wrapper for V8's native CallSite) blocks `getThis()` and `getFunction()` to prevent host object leakage, but allows `getFileName()` to return unsanitized host absolute paths. Any sandboxed code can extract the full directory structure, l…
CVE-2026-44002
GitHub-GHSA

MEDIUM
CSS Parser: Improper Certificate Validation allows MITM injection of remote CSS content
GHSA-ff6c-w6qf-7xqc
pkg: css_parser, css_parser
eco: rubygems
published: May 7, 2026
### Summary

The CSS Parser gem does not validate HTTPS connections, allowing a Man-in-the-Middle (MITM) attacker to inject or modify CSS content when stylesheets are loaded via HTTPS. The connection is established with `OpenSSL::SSL::VERIFY_NONE`, meaning any HTTPS certificate—even entirely untru…

CVE-2026-44312
GitHub-GHSA

MEDIUM
Netty HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitization
GHSA-xxqh-mfjm-7mv9
pkg: io.netty:netty-codec-http, io.netty:netty-codec-http
eco: maven
published: May 7, 2026
# NETTY HTTP/1.0 TE+CL Coexistence Bypasses Smuggling Sanitization

| Field | Value |
|———–|——-|
| Library | `io.netty:netty-codec-http` |
| Component | `codec-http` — `HttpObjectDecoder` |
| Severity | **HIGH** |
| Affects | HEAD, commit `4f3533ae` confirmed |

## Summary…

CVE-2026-42581
GitHub-GHSA

MEDIUM
docling-graph has SSRF via Missing Internal IP Validation in URLInputHandler
GHSA-fqph-j6v6-jvgx
pkg: docling-graph
eco: pip
published: May 7, 2026
### Impact

The `URLInputHandler` class in `docling_graph/core/input/handlers.py` makes HTTP requests to user-supplied URLs without validating whether the target resolves to a private, loopback, or link-local IP address. The `URLValidator` only checks for a valid scheme and non-empty `netloc`, perfo…

CVE-2026-44520
GitHub-GHSA

MEDIUM
BentoML has Information Disclosure in `bentoml build` via symlink traversal in the build context
GHSA-mcfx-4vc6-qgxv
pkg: bentoml
eco: pip
published: May 7, 2026
### Summary
BentoML's `bentoml build` packaging workflow follows attacker-controlled symlinks inside the build context and copies the referenced file contents into the generated Bento artifact.

If a victim builds an untrusted repository or other attacker-supplied build context, the attacker can pla…

CVE-2026-40610
NVD

MEDIUM
CVE-2026-40004
CVE-2026-40004
pkg: openssl

published: May 7, 2026

There exists an openssl.cnf privilege escalation vulnerability in ZTE Cloud PC client uSmartview. An attacker can execute arbitrary code locally and escalate privileges.
CWE: CWE-427
GitHub-GHSA

MEDIUM
Vercel: Non-interactive mode includes CLI arguments in suggested command output
GHSA-pgf8-2hgj-grqg
pkg: vercel
eco: npm
published: May 7, 2026
# Summary

When the Vercel CLI runs in non-interactive mode (`–non-interactive` or auto-detected AI agent), commands that cannot complete autonomously emit JSON payloads with suggested follow-up commands. If the user authenticated via `–token` or `-t` on the command line, the token value is includ…

CVE-2026-44479
GitHub-GHSA

MEDIUM
@axonflow/openclaw fix introduces plugin cache and credential-file permission hardening
GHSA-cqmh-pcgr-q42f
pkg: @axonflow/openclaw
eco: npm
published: May 6, 2026
## Summary

Two related permission defects in this AxonFlow plugin allowed registration credentials and cache state to be readable by other local users on hosts where the calling user's home directory was at the conventional `0755` mode.

## Affected versions

Versions 1.3.2 and below.

## Impact

1…

NVD

MEDIUM
CVE-2026-43277
CVE-2026-43277
pkg: linux linux_kernel

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

APEI/GHES: ensure that won't go past CPER allocated record

The logic at ghes_new() prevents allocating too large records, by
checking if they're bigger than GHES_ESTATUS_MAX_SIZE (currently, 64KB).
Yet, the allocation is done with…

NVD

MEDIUM
CVE-2026-43271
CVE-2026-43271
pkg: linux linux_kernel

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

md-cluster: fix NULL pointer dereference in process_metadata_update

The function process_metadata_update() blindly dereferences the 'thread'
pointer (acquired via rcu_dereference_protected) within the wait_event()
macro.

While th…

CWE: CWE-476
NVD

MEDIUM
CVE-2026-43266
CVE-2026-43266
pkg: linux linux_kernel

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

EFI/CPER: don't go past the ARM processor CPER record buffer

There's a logic inside GHES/CPER to detect if the section_length
is too small, but it doesn't detect if it is too big.

Currently, if the firmware receives an ARM proces…

NVD

MEDIUM
CVE-2026-43265
CVE-2026-43265
pkg: linux linux_kernel

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

KVM: x86: Ignore -EBUSY when checking nested events from vcpu_block()

Ignore -EBUSY when checking nested events after exiting a blocking state
while L2 is active, as exiting to userspace will generate a spurious
userspace exit, us…

NVD

MEDIUM
CVE-2026-43264
CVE-2026-43264
pkg: linux linux_kernel

published: May 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

fbdev: of: display_timing: fix refcount leak in of_get_display_timings()

of_parse_phandle() returns a device_node with refcount incremented,
which is stored in 'entry' and then copied to 'native_mode'. When the
error paths at line…

NVD

MEDIUM
CVE-2026-42192
CVE-2026-42192
pkg: react

published: May 8, 2026

Plunk is an open-source email platform built on top of AWS SES. Prior to version 0.9.0, a stored cross-site scripting (XSS) vulnerability exists in the campaign management feature, where the email body content created by authenticated project members is stored and later rendered in the admin dashboa…
CWE: CWE-79
GitHub-GHSA

MEDIUM
Open WebUI: Deactivated Channel Members Retain Full Access to Group/DM Channels
GHSA-hmgr-67hw-j2cq
pkg: open-webui
eco: pip
published: May 8, 2026
# Deactivated Channel Members Retain Full Access to Group/DM Channels

## Affected Component

Channel membership authorization check:
– `backend/open_webui/models/channels.py` (lines 663-673, `is_user_channel_member`)
– Used at 15 locations in `backend/open_webui/routers/channels.py`

## Affected Ve…

CVE-2026-44561
GitHub-GHSA

MEDIUM
Read-Only Open WebUI Users Can Modify Collaborative Documents via Socket.IO
GHSA-vrfh-rj4q-rmhr
pkg: open-webui
eco: pip
published: May 8, 2026
# Read-Only Users Can Modify Collaborative Documents via Socket.IO

## Affected Component

Socket.IO collaborative document editing handler:
– `backend/open_webui/socket/main.py` (lines 667-721, `ydoc:document:update` handler)

## Affected Versions

Current main branch and likely all versions with c…

CVE-2026-44564
GitHub-GHSA

MEDIUM
Open WebUI's Ollama Model Access Control Bypass via /api/generate, /api/embed, /api/embeddings, and /api/show
GHSA-rcvp-6fgw-c7fh
pkg: open-webui
eco: pip
published: May 8, 2026
# Ollama Model Access Control Bypass via /api/generate, /api/embed, /api/embeddings, and /api/show

## Affected Component

Ollama proxy endpoints missing model access control:
– `backend/open_webui/routers/ollama.py` (lines 955-995, `generate_completion`)
– `backend/open_webui/routers/ollama.py` (li…

CVE-2026-44563
GitHub-GHSA

MEDIUM
Open WebUI's Channel Access Grants Bypass filter_allowed_access_grants
GHSA-7rjh-px4v-5w55
pkg: open-webui
eco: pip
published: May 8, 2026
# Channel Access Grants Bypass filter_allowed_access_grants

## Affected Component

Channel creation and update endpoints:
– `backend/open_webui/routers/channels.py` (lines 291-340, `create_new_channel`)
– `backend/open_webui/routers/channels.py` (lines 617-638, `update_channel_by_id`)
– `backend/op…

CVE-2026-44558
GitHub-GHSA

MEDIUM
gitsign –verify panics on empty-certificate PKCS7 and exits 0, bypassing exit-code callers
GHSA-7c37-gx6w-8vc5
pkg: github.com/sigstore/gitsign
eco: go
published: May 8, 2026
## Summary

`CertVerifier.Verify()` in `pkg/git/verifier.go` unconditionally dereferences `certs[0]` after `sd.GetCertificates()` without checking the slice length. A CMS/PKCS7 signed message with an empty certificate set is a structurally valid DER payload; `GetCertificates()` returns an empty slic…

CVE-2026-44310
GitHub-GHSA

MEDIUM
FileBrowser Vulnerable to Stored XSS via SVG File in Public Share (Missing CSP Header)
GHSA-mmpx-jh39-wrv6
pkg: github.com/gtsteffaniak/filebrowser
eco: go
published: May 7, 2026
## Summary

FileBrowser Quantum serves inline SVG files without a `Content-Security-Policy` header, allowing embedded JavaScript in SVG files to execute when accessed via public share links.

Verified on v1.3.0-stable.

## Affected product

– **Product:** FileBrowser Quantum (`gtsteffaniak/filebrows…

GitHub-GHSA

MEDIUM
ShellHub has crash-DoS via field injection in filter and sort-by parameters
GHSA-47r2-v3x6-wff9
pkg: github.com/shellhub-io/shellhub
eco: go
published: May 6, 2026
## Summary
The device list endpoint accepts user-controlled identifiers in two places that are passed directly as BSON/SQL keys in the database layer without validation:

1. The `name` field of each filter property in the base64-encoded `filter`
query parameter.
2. The `sort_by` query param…

CVE-2026-44425
GitHub-GHSA

MEDIUM
wger: trainer_login open redirect – ?next= parameter not validated against host
GHSA-vqv8-j3mj-wjxj
pkg: wger
eco: pip
published: May 6, 2026
### Summary

The `trainer_login` view in wger redirects to `request.GET['next']` directly via `HttpResponseRedirect()` without calling `url_has_allowed_host_and_scheme()`. After the trainer successfully enters impersonation mode, their browser is redirected to any attacker-controlled URL supplied in…

GitHub-GHSA

MEDIUM
Axios: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `withXSRFToken` Boolean Coercion
GHSA-xx6v-rp6x-q39c
pkg: axios, axios
eco: npm
published: May 5, 2026
# Vulnerability Disclosure: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `withXSRFToken` Boolean Coercion

## Summary

The Axios library's XSRF token protection logic uses JavaScript truthy/falsy semantics instead of strict boolean comparison for the `withXSRFToken` config prope…

CVE-2026-42042
NVD

MEDIUM
CVE-2026-1677
CVE-2026-1677
pkg: tls

published: May 11, 2026

Zephyr sockets created with `IPPROTO_TLS_1_3` can still negotiate a TLS 1.2 connection when both TLS versions are enabled in Kconfig, because the socket-level protocol selection is not propagated to mbedTLS (e.g. via `mbedtls_ssl_conf_min_tls_version`). The ClientHello advertises both versions and t…
CWE: CWE-757
GitHub-GHSA

MEDIUM
Vert.x has a DoS via unbounded server-side SNI SslContext cache growth
GHSA-3g76-f9xq-8vp6
pkg: io.vertx:vertx-core, io.vertx:vertx-core, io.vertx:vertx-core
eco: maven
published: May 9, 2026
Potential unbounded server-side SNI `SslContext` cache growth in Vert.x TLS handling, with possible resource-exhaustion / DoS impact.

On affected versions, matching server-side SNI names are cached via `computeIfAbsent(serverName, …)` in a serverName-keyed `SslContext` cache, and I could not find…

CVE-2026-6860
GitHub-GHSA

MEDIUM
Hono's Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakage
GHSA-p77w-8qqv-26rm
pkg: hono
eco: npm
published: May 9, 2026
### Summary

Cache Middleware does not skip caching for responses that declare per-user variance via `Vary: Authorization` or `Vary: Cookie`. As a result, a response cached for one authenticated user may be served to subsequent requests from different users.

### Details

The Cache Middleware skips …

CVE-2026-44457
GitHub-GHSA

MEDIUM
gitsign verify accepts signatures over go-git-normalized bytes, enabling trust confusion on malformed commits
GHSA-7rmh-48mx-2vwc
pkg: github.com/sigstore/gitsign
eco: go
published: May 8, 2026
## Summary

`gitsign verify` and `gitsign verify-tag` re-encode commit/tag objects through go-git's `EncodeWithoutSignature` before checking the signature, instead of verifying against the raw git object bytes. For malformed objects with duplicate `tree` headers, git-core and go-git parse different …

CVE-2026-44309
GitHub-GHSA

MEDIUM
Wagtail has improper restriction handling on Documents and Images API
GHSA-p5gm-92h4-6pv6
pkg: wagtail, wagtail
eco: pip
published: May 8, 2026
### Impact

The Documents and Images [API](https://docs.wagtail.org/en/stable/advanced_topics/api/index.html) incorrectly listed items in private collections. A user with access to the API could see the filename and name of documents and images in private collections.

### Patches

Patched versions …

CVE-2026-44201
NVD

MEDIUM
CVE-2026-42190
CVE-2026-42190
pkg: react

published: May 8, 2026

RedwoodSDK is a server-first React framework. From version 1.0.0-beta.50 to before version 1.2.3, server actions in rwsdk apply HTTP method enforcement but no origin validation. A request originating from a different origin that the browser treats as same-site can invoke a server action with the vic…
CWE: CWE-352
GitHub-GHSA

MEDIUM
vm2 has access to `VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL`
GHSA-2cm2-m3w5-gp2f
pkg: vm2
eco: npm
published: May 8, 2026
### Summary

https://github.com/patriksimek/vm2/security/advisories/GHSA-wp5r-2gw5-m7q7 is not fully patched.

### Details

It is still possible to get access to `VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL`.

### PoC

“`js
const {VM} = require("vm2");
const vm = new VM();
console.log(vm.run…

NVD

MEDIUM
CVE-2026-44500
CVE-2026-44500
pkg: zfnd zebra-chain, zfnd zebra-network, zfnd zebrad

published: May 8, 2026

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.4.0, prior to zebra-chain version 7.0.0, and prior to zebra-network version 6.0.0, several inbound deserialization paths in Zebra allocated buffers sized against generic transport or block-size ceilings before the tighter prot…
CWE: CWE-770
NVD

MEDIUM
CVE-2022-26523
CVE-2022-26523
pkg: windows

published: May 8, 2026

The socket connection handler in aswArPot.sys in the Avast and AVG Windows Anti Rootkit driver before 22.1 allows local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) due to a double fetch vulnerability at aswArPot+0xbb94.
CWE: CWE-400
NVD

MEDIUM
CVE-2026-41645
CVE-2026-41645
pkg: projectdiscovery nuclei

published: May 8, 2026

Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From version 3.0.0 to before version 3.8.0, a vulnerability in Nuclei's expression evaluation engine makes it possible for a malicious target server to inject and execute supported DSL expressions. This happens when HTTP response da…
CWE: CWE-94
GitHub-GHSA

MEDIUM
Ech0's Unauthenticated Like Endpoint Enables Arbitrary Engagement Metric Inflation
GHSA-rgj7-vg8v-j4wr
pkg: github.com/lin-snow/ech0
eco: go
published: May 7, 2026
### Summary

**No authentication** is required to invoke **`PUT /api/echo/like/:id`**. The handler is registered on the **public** router group. The service increments **`fav_count`** for the given echo **without** checking identity, **without** a per-user limit, and **without** CSRF tokens. A remot…

GitHub-GHSA

MEDIUM
Ech0 comment model's Email field returned on public /api/comments endpoints
GHSA-rj4g-rqgh-rx9h
pkg: github.com/lin-snow/Ech0
eco: go
published: May 7, 2026
## Summary

The `Comment` model serializes its `Email` field through the public comment-listing API. `internal/model/comment/comment.go:33` uses `json:"email"`, while adjacent PII fields (`IPHash`, `UserAgent`) correctly use `json:"-"`. The public endpoints `GET /api/comments?echo_id=X` and `GET /ap…

GitHub-GHSA

MEDIUM
Zebra Vulnerable to Allocation Amplification in Inbound Network Deserializers
GHSA-438q-jx8f-cccv
pkg: zebra-network, zebrad, zebra-chain
eco: rust
published: May 7, 2026
# CVE-2026-44500: Allocation Amplification in Inbound Network Deserializers

## Summary

Several inbound deserialization paths in Zebra allocated buffers sized against generic transport or block-size ceilings before the tighter protocol or consensus limits were enforced. An unauthenticated or post-h…

CVE-2026-44500
GitHub-GHSA

MEDIUM
Netty MQTT: Resource exhaustion in MqttDecoder
GHSA-jfg9-48mv-9qgx
pkg: io.netty:netty-codec-mqtt, io.netty:netty-codec-mqtt
eco: maven
published: May 7, 2026
### Impact
The MQTT 5 header Properties section is parsed and buffered _before_ any message size limit is applied.

Specifically, in `MqttDecoder`, the `decodeVariableHeader()` method is called before the `bytesRemainingBeforeVariableHeader > maxBytesInMessage` check. The `decodeVariableHeader()` ca…

CVE-2026-44248
GitHub-GHSA

MEDIUM
vm2's Transformer Fast-Path Bypass Exposes Internal State Variable
GHSA-wp5r-2gw5-m7q7
pkg: vm2
eco: npm
published: May 7, 2026
### Summary
vm2's code transformer has a performance optimization that skips AST analysis when the code does not contain `catch`, `import`, or `async` keywords. This fast-path bypass allows sandboxed code to directly access the internal `VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL` variable, …
CVE-2026-44003
GitHub-GHSA

MEDIUM
Goteberg has arbitrary PDF read via stampExpression and watermarkExpression in merge, split, and convert routes
GHSA-3cv5-q585-h563
pkg: github.com/gotenberg/gotenberg/v8
eco: go
published: May 7, 2026
## Summary

Six conversion routes (`pdfengines/merge`, `pdfengines/split`, `libreoffice/convert`, `chromium/convert/url`, `chromium/convert/html`, `chromium/convert/markdown`) accept `stampSource=pdf` + `stampExpression=/path` and `watermarkSource=pdf` + `watermarkExpression=/path` from anonymous ca…

CVE-2026-42593
GitHub-GHSA

MEDIUM
Gotenberg's DNS rebinding bypasses SSRF validation on Chromium URL conversion routes
GHSA-2pmr-289p-44r3
pkg: github.com/gotenberg/gotenberg/v8
eco: go
published: May 7, 2026
## Summary

`FilterOutboundURL` resolves the hostname, checks the resolved IPs against the private-address deny-list, and returns only the error. It discards the resolved addresses. Chromium later performs its own DNS resolution when it navigates to the URL. An attacker who controls DNS for a hostna…

CVE-2026-42592
GitHub-GHSA

MEDIUM
OpenSearch Security plugin: DLS not applied on documents linked by has_child or has_parent relation
GHSA-x83w-23jp-g6pw
pkg: org.opensearch.plugin:opensearch-security, org.opensearch.plugin:opensearch-security
eco: maven
published: May 7, 2026
### Description

A flaw was identified in the OpenSearch Security plugin's document-level security (DLS) implementation. DLS restrictions were not correctly applied to search queries that use has_parent or has_child join relations. This could allow an authenticated user to access document contents t…

GitHub-GHSA

MEDIUM
Nitro has a proxy scope bypass via percent-encoded path traversal in `routeRules`
GHSA-5w89-w975-hf9q
pkg: nitro, nitropack
eco: npm
published: May 6, 2026
A proxy route rule like:

“`ts
routeRules: {
"/api/orders/**": { proxy: { to: "http://upstream/orders/**" } }
}
“`

is intended to limit the proxy to URLs under `/api/orders/`. Before the patch, an attacker could bypass that scope by sending percent-encoded path traversal (`..%2f`) in the URL, c…

CVE-2026-44373
GitHub-GHSA

MEDIUM
Lemmy may expose private community data through community, saved, liked, and modlog API views
GHSA-95q8-x6r6-672m
pkg: lemmy_api
eco: rust
published: May 6, 2026
## Summary

Lemmy applies private-community checks in `PostView` and `CommentView`, but several adjacent API views skip the accepted-follower filter. Bob, a registered user who is not an accepted follower, can read private community `sidebar` and `summary` fields. Alice, a former accepted follower, …

GitHub-GHSA

MEDIUM
Private Lemmy instances expose multi-community metadata without authentication
GHSA-jmxc-hhwx-gvv3
pkg: lemmy_api
eco: rust
published: May 6, 2026
## Summary

`read_multi_community()` does not enforce the private-instance setting. On a private instance, an unauthenticated visitor can read multi-community names, titles, summaries, sidebars, owner identities, and member community lists.

## Details

Other read handlers load `local_site` and call…

GitHub-GHSA

MEDIUM
Hatchet affected by cross-tenant information disclosure in `listTasksByDAGIds`
GHSA-55gc-6fmc-fpx9
pkg: github.com/hatchet-dev/hatchet
eco: go
published: May 6, 2026
## Summary

A missing authorization directive on the `GET /api/v1/stable/dags/tasks` endpoint caused Hatchet's tenant-membership check to be skipped for this route. A user authenticated to any tenant on the same Hatchet instance could query the endpoint with another tenant's UUID and a DAG UUID belo…

CVE-2026-42572
GitHub-GHSA

MEDIUM
Nokogiri XSLT transform has a memory leak
GHSA-v2fc-qm4h-8hqv
pkg: nokogiri
eco: rubygems
published: May 6, 2026
## Summary

Nokogiri's `Nokogiri::XSLT::Stylesheet#transform` leaks a small heap allocation when passed a Ruby string parameter containing a null byte.

For applications that pass attacker-controlled input through `XSLT.transform` parameters, this may be a vector for a denial of service attack again…

GitHub-GHSA

MEDIUM
PyLoad vulnerable to unauthenticated traceback disclosure via global exception handler in WebUI
GHSA-c3gc-9pf2-84gg
pkg: pyload-ng
eco: pip
published: May 6, 2026
### Summary
`pyload-ng` WebUI returns full Python traceback details to clients on unhandled exceptions.

Because `/web/<path:filename>` is reachable without authentication and renders attacker-controlled template names, an unauthenticated user can reliably trigger a server exception (for example by …

CVE-2026-44226
GitHub-GHSA

MEDIUM
GraphQL-Ruby's Ruby lexer does not count comment tokens for the purposes of max_query_string_tokens
GHSA-3h96-34p3-xm76
pkg: graphql, graphql, graphql
eco: rubygems
published: May 5, 2026
GraphQL-Ruby's `max_query_string_tokens` configuration didn't count comment tokens against the limit, allowing strings to be processed even after the configured maximum had actually been reached.

In patched versions, the Ruby lexer does count these tokens.

GraphQL-CParser is not affected by this…

NVD

MEDIUM
CVE-2026-34527
CVE-2026-34527
pkg: sandboxie-plus sandboxie

published: May 5, 2026

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, SbieIniServer::HashPassword converts a SHA-1 digest to hexadecimal incorrectly. The high nibble of each byte is shifted right by 8 instead of 4, which always produces zero for an 8-bit valu…
CWE: CWE-328
GitHub-GHSA

MEDIUM
OpenStack Horizon has Incorrect Behavior Order
GHSA-vxvf-xvm3-p8j5
pkg: horizon
eco: pip
published: May 5, 2026
An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauthenticated requests. This is a regression of the CVE-2014-8124 fix.
CVE-2026-43002
GitHub-GHSA

MEDIUM
Django has an Improper Handling of Length Parameter Inconsistency
GHSA-w26r-rmm8-9c29
pkg: Django, Django
eco: pip
published: May 5, 2026
An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. ASGI requests with a missing or understated `Content-Length` header can bypass the `FILE_UPLOAD_MAX_MEMORY_SIZE` limit, potentially loading large files into memory and causing service degradation.

As a reminder, Django expects a li…

CVE-2026-5766
GitHub-GHSA

MEDIUM
Netty: Start-Line Injection in DefaultHttpRequest.setUri() Allows HTTP Request Smuggling and RTSP Request Injection
GHSA-v8h7-rr48-vmmv
pkg: io.netty:netty-codec-http, io.netty:netty-codec-http
eco: maven
published: May 5, 2026
### Summary
Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created first and its URI is later changed via `setUri()`.

The constructors reject CRLF and whitespace characters that would break the start-line, but `setUri()` does not apply…

CVE-2026-41417
GitHub-GHSA

MEDIUM
ots has a negative expire override that can bypass its secret retention policy
GHSA-h5fq-653g-gxrm
pkg: github.com/Luzifer/ots
eco: go
published: May 5, 2026
## Summary

The `/api/create` endpoint accepted negative `expire` query values. For the memory storage backend, negative values were passed to secret creation as a negative duration and treated as no expiry, allowing callers to create secrets that persisted longer than intended.

## Impact

Unauthen…

GitHub-GHSA

MEDIUM
Apache Thrift has a Memory Allocation with Excessive Size Value Vulnerability
GHSA-2f9f-gq7v-9h6m
pkg: thrift
eco: rust
published: May 5, 2026
Memory Allocation with Excessive Size Value vulnerability in Apache Thrift.

This issue affects Apache Thrift: before 0.23.0.

Users are recommended to upgrade to version [0.23.0](https://github.com/apache/thrift/releases/tag/v0.23.0), which fixes the issue.

CVE-2026-43868
GitHub-GHSA

MEDIUM
Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStream
GHSA-445q-vr5w-6q77
pkg: axios
eco: npm
published: May 5, 2026
### Summary
The `FormDataPart` constructor in `lib/helpers/formDataToStream.js` interpolates `value.type` directly into the `Content-Type` header of each multipart part without sanitizing CRLF (`\r\n`) sequences. An attacker who controls the `.type` property of a Blob/File-like object (e.g., via a u…
CVE-2026-42037
GitHub-GHSA

MEDIUM
Axios' HTTP adapter-streamed uploads bypass maxBodyLength when maxRedirects: 0
GHSA-5c9x-8gcm-mpgx
pkg: axios, axios
eco: npm
published: May 5, 2026
### Summary

For stream request bodies, maxBodyLength is bypassed when maxRedirects is set to 0 (native http/https transport path). Oversized streamed uploads are sent fully even when the caller sets strict body limits.

### Details

Relevant flow in lib/adapters/http.js:
– 556-564: maxBodyLength …

CVE-2026-42034
GitHub-GHSA

MEDIUM
Axios: HTTP adapter streamed responses bypass maxContentLength
GHSA-vf2m-468p-8v99
pkg: axios, axios
eco: npm
published: May 5, 2026
### Summary

When responseType: 'stream' is used, Axios returns the response stream without enforcing maxContentLength. This bypasses configured response-size limits and allows unbounded downstream consumption.

### Details
In lib/adapters/http.js:
– 786-789: for responseType === 'stream', Axios i…

CVE-2026-42036
NVD

MEDIUM
CVE-2026-41572
CVE-2026-41572
pkg: go

published: May 4, 2026

Note Mark is an open-source note-taking application. Prior to version 0.19.3, after a note-mark owner soft-deletes a public book, its notes and uploaded assets stay readable at /api/notes/{id}, /api/notes/{id}/content, the slug URL, and the asset endpoints. Unauthenticated callers who hold the note …
CWE: CWE-285
GitHub-GHSA

MEDIUM
`potato-annotation` has a Project-Boundary Bypass
GHSA-q9m2-fhv9-3jcf
pkg: potato-annotation
eco: pip
published: May 8, 2026
## Summary
`validate_path_security` uses string-prefix containment (`startswith`) for boundary checks. This allows paths that are **outside** the intended project directory but share its prefix string (e.g., `/tmp/potato_proj_demo_evil/…` vs `/tmp/potato_proj_demo`) to be accepted.

## Details
###…

GitHub-GHSA

MEDIUM
Open WebUI's Mass Assignment via Pydantic extra='allow' Allows Creating Folders in Other Users' Accounts
GHSA-hr43-rjmr-7wmm
pkg: open-webui
eco: pip
published: May 8, 2026
# Mass Assignment via Pydantic extra='allow' Allows Creating Folders in Other Users' Accounts

## Affected Component

Folder creation endpoint and form model:
– `backend/open_webui/models/folders.py` (lines 72-77, `FolderForm` with `extra='allow'`)
– `backend/open_webui/models/folders.py` (lines 95-…

CVE-2026-44550
GitHub-GHSA

MEDIUM
ExternalSecrets vulnerable to privilege escalation with secret overwriting
GHSA-fq7h-9×26-6j22
pkg: github.com/external-secrets/external-secrets/apis
eco: go
published: May 8, 2026
ExternalSecrets allows users to craft Service Account tokens for misconfigured Service Accounts in namespaces the users have access to.

### Impact

A user who only has permission to create ExternalSecret resources can cause the operator to create a Secret that Kubernetes will automatically populate…

CVE-2026-42876
GitHub-GHSA

MEDIUM
Open WebUI has Stored XSS in Pending User Overlay via Incorrect DOMPurify Application Order
GHSA-fq3v-xjjx-95rc
pkg: open-webui
eco: pip
published: May 8, 2026
## Vulnerability Details

**CWE-79**: Cross-site Scripting (XSS)

The `AccountPending.svelte` component renders the admin-configured "Pending User Overlay Content" using `marked.parse()` inside `{@html}` with an incorrect DOMPurify application order:

### Vulnerable Code

**`src/lib/components/layou…

CVE-2026-44568
GitHub-GHSA

MEDIUM
Ech0's RSS feed renders unescaped tag names and raw-HTML markdown, stored XSS against subscribers
GHSA-3v85-fqvh-7rxf
pkg: github.com/lin-snow/Ech0
eco: go
published: May 7, 2026
## Summary

The public RSS/Atom feed at `/rss` renders two attacker-controlled surfaces without HTML escaping. Tag names flow through `fmt.Appendf(renderedContent, "<br /><span class=\"tag\">#%s</span>", tag.Name)` at `internal/service/common/common.go:120`, and the Markdown renderer at `internal/ut…

NVD

MEDIUM
CVE-2026-40243
CVE-2026-40243
pkg: linuxcontainers incus

published: May 6, 2026

Incus is a system container and virtual machine manager. In versions before 7.0.0, broken TLS validation logic in the OVN database connection logic can allow connections to an attacker's OVN database. The OVN client implementations disable Go standard TLS server verification and replace it with cust…
CWE: CWE-295
GitHub-GHSA

MEDIUM
Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy
GHSA-w9j2-pvgh-6h63
pkg: axios, axios
eco: npm
published: May 5, 2026
# Vulnerability Disclosure: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy

## Summary

The Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any `Object.prototype` pollution to **silently suppress all HTTP error responses** (40…

CVE-2026-42041
GitHub-GHSA

MEDIUM
utcp-http vulnerable to SSRF via attacker-controlled OpenAPI servers[0].url in HTTP communication protocol
GHSA-39j6-4867-gg4w
pkg: utcp-http
eco: pip
published: May 7, 2026
## Summary

The `utcp-http` plugin is vulnerable to a blind Server-Side Request Forgery (SSRF) caused by a trust-boundary inconsistency between manual discovery and tool invocation. `register_manual()` validates the discovery URL against an HTTPS / loopback allowlist, but `call_tool()` and `call_too…

CVE-2026-44661
GitHub-GHSA

MEDIUM
hono/jsx has Unvalidated JSX Tag Names that May Allow HTML Injection
GHSA-69xw-7hcm-h432
pkg: hono
eco: npm
published: May 6, 2026
## Summary

Improper handling of JSX element tag names in hono/jsx allowed unvalidated tag names to be directly inserted into the generated HTML output.

When untrusted input is used as a tag name via the programmatic `jsx()` or `createElement()` APIs during server-side rendering, specially crafted …

CVE-2026-44455
GitHub-GHSA

MEDIUM
PPTAgent: Arbitrary File Write via `save_generated_slides`
GHSA-pxhg-7xr2-w7xg
pkg: pptagent
eco: pip
published: May 5, 2026
## Summary

> This vulnerability has been fixed in https://github.com/icip-cas/PPTAgent/commit/418491a9a1c02d9d93194b5973bb58df35cf9d00.

The `save_generated_slides` MCP tool accepts a pptx_path argument and writes the generated PPTX file to that path without any workspace restriction or path valida…

CVE-2026-42080
GitHub-GHSA

MEDIUM
PPTAgent: Arbitrary File Write + Directory Creation via markdown_table_to_image
GHSA-hrcw-xc63-g29m
pkg: pptagent
eco: pip
published: May 5, 2026
### Summary

The `markdown_table_to_image` tool accepts a caller-controlled path parameter and passes it directly to `get_html_table_image`:

“`python
# pptagent/mcp_server.py:127-143
def markdown_table_to_image(markdown_table: str, path: str, css: str) -> str:
"""
Args:
path (str):…

CVE-2026-42078
NVD

MEDIUM
CVE-2026-7572
CVE-2026-7572
pkg: linux

published: May 6, 2026

An off-by-one error (CWE-193) in the ConsumeUnit16Array and ConsumeUnit64Array functions in Velocidex Velociraptor before version 0.76.5 on Windows and Linux allows a local attacker to cause a Denial of Service (DoS) via a process crash by providing a specially crafted .evtx file to the parse_evtx V…
CWE: CWE-193
GitHub-GHSA

MEDIUM
XWiki PlantUML Macro Vulnerable to Server-Side Request Forgery (SSRF) via 'server' parameter
GHSA-42fc-7w97-8vrc
pkg: org.xwiki.contrib.plantuml:macro-plantuml-macro
eco: maven
published: May 5, 2026
### Impact

The [PlantUML Macro](https://extensions.xwiki.org/xwiki/bin/view/Extension/PlantUML+Macro) is vulnerable to Server-Side Request Forgery (SSRF). The macro allows users to specify an alternative PlantUML server via the `server` parameter. However, the application does not validate the supp…

CVE-2026-42140
NVD

MEDIUM
CVE-2026-8194
CVE-2026-8194
pkg: react

published: May 9, 2026

A security vulnerability has been detected in osTicket up to 1.18.3. Impacted is an unknown function of the file include/class.dispatcher.php of the component Dispatcher. The manipulation of the argument _method leads to cross-site request forgery. Remote exploitation of the attack is possible. The …
CWE: CWE-352, CWE-862
GitHub-GHSA

MEDIUM
Hono has CSS Declaration Injection via Style Object Values in JSX SSR
GHSA-qp7p-654g-cw7p
pkg: hono
eco: npm
published: May 9, 2026
### Summary

The JSX renderer escapes `style` attribute object values for HTML but not for CSS. Untrusted input in a `style` object value or property name can therefore inject additional CSS declarations into the rendered `style` attribute. The impact is limited to CSS and does not allow JavaScript …

CVE-2026-44458
GitHub-GHSA

MEDIUM
free5GC's UDR nudr-dr DELETE amf-subscriptions panics on missing subsId when UE state exists (nil pointer dereference)
GHSA-4rqf-grm6-vf75
pkg: github.com/free5gc/udr
eco: go
published: May 8, 2026
### Summary
free5GC's UDR `nudr-dr` `DELETE /subscription-data/{ueId}/{servingPlmnId}/ee-subscriptions/{subsId}/amf-subscriptions` handler contains a nil-pointer dereference reachable from a single authenticated request, after one preparatory authenticated EE-subscription create. The handler checks …
CVE-2026-44323
GitHub-GHSA

MEDIUM
Wagtail has improper permission handling when viewing page history
GHSA-c4mr-889m-vgf6
pkg: wagtail, wagtail
eco: pip
published: May 8, 2026
### Impact

A CMS user without the ability to edit a page could still access the history report for the page, potentially resulting in disclosure of sensitive information.

### Patches
Patched versions have been released as Wagtail 7.0.7 and 7.3.2. The new 7.4 LTS feature release also incorporates t…

CVE-2026-44198
NVD

MEDIUM
CVE-2026-42282
CVE-2026-42282
pkg: oauth

published: May 8, 2026

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to version 2.47.13, when n8n-mcp runs in HTTP transport mode, authenticated MCP tools/call requests had their full arguments and JSON-RPC params written to server logs by the requ…
CWE: CWE-532
GitHub-GHSA

MEDIUM
Open WebUI Missing Access Check on Channel Members Endpoint for Standard Channels
GHSA-c7wp-3qh5-55pv
pkg: open-webui
eco: pip
published: May 8, 2026
# Missing Access Check on Channel Members Endpoint for Standard Channels

## Affected Component

Channel members listing endpoint:
– `backend/open_webui/routers/channels.py` (lines 445-507, `get_channel_members_by_id`)

## Affected Versions

Current main branch and likely all versions with the chann…

CVE-2026-44559
GitHub-GHSA

MEDIUM
Open WebUI vulnerable to Global Knowledge Base Enumeration via knowledge-bases Meta-Collection
GHSA-6c2x-gcp3-gp73
pkg: open-webui
eco: pip
published: May 8, 2026
# Global Knowledge Base Enumeration via knowledge-bases Meta-Collection

## Affected Component

Retrieval collection access validation:
– `backend/open_webui/routers/retrieval.py` (lines 2330-2355, `_validate_collection_access`)
– `backend/open_webui/routers/retrieval.py` (query endpoints, e.g. `POS…

CVE-2026-44557
GitHub-GHSA

MEDIUM
Bunsink has an SSRF bypass in `validate_webhook_url`
GHSA-fp53-qcf8-2xx2
pkg: bugsink
eco: pip
published: May 8, 2026
## Summary

Bugsink’s webhook URL validation in versions 2.1.2 and earlier could be (partially) bypassed because of a mismatch in URL parsing.

In some malformed URLs, Python’s standard URL parser (urllib) and the HTTP client stack (requests / urllib3) do not agree on which host is actually bei…

CVE-2026-44502
GitHub-GHSA

MEDIUM
Weblate vulnerable to XSS via crafted Markdown
GHSA-5cmv-3rc4-7279
pkg: weblate
eco: pip
published: May 7, 2026
### Impact
The Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes.

### Patches
* https://github.com/WeblateOrg/weblate/pull/19259

### Workarounds
Even though the attacker might be able to inject code into the HTML, the Weblate's strict …

CVE-2026-44264
GitHub-GHSA

MEDIUM
Weblate Vulnerable to Private Translation Enumeration via Screenshot API
GHSA-gcg5-86jr-f7jg
pkg: weblate
eco: pip
published: May 7, 2026
### Impact

The screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user.

### Patches
* https://github.com/WeblateOrg/weblate/pull/19258

### Acknowledgement
Weblate thanks Luay for reporting this vulnerability according to the org…

CVE-2026-44263
GitHub-GHSA

MEDIUM
Backstage: Catalog unprocessed read endpoints allow authenticated cross-owner data access without permission checks
GHSA-p7g9-rp3g-mgfg
pkg: @backstage/plugin-catalog-unprocessed-entities-common, @backstage/plugin-catalog-unprocessed-entities, @backstage/plugin-catalog-backend-module-unprocessed
eco: npm
published: May 6, 2026
### Impact

The unprocessed entities read endpoints in `@backstage/plugin-catalog-backend-module-unprocessed` do not enforce permission authorization checks. Any authenticated user can access unprocessed entity records regardless of ownership. This is
an information disclosure vulnerability …

CVE-2026-44374
NVD

MEDIUM
CVE-2026-7946
CVE-2026-7946
pkg: google chrome, apple macos, google chrome_os

published: May 6, 2026

Insufficient policy enforcement in WebUI in Google Chrome on Linux, Mac, Windows, ChromeOS prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-693
NVD

MEDIUM
CVE-2026-7904
CVE-2026-7904
pkg: google chrome, apple macos, linux linux_kernel

published: May 6, 2026

Out of bounds read in Fonts in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-125
GitHub-GHSA

MEDIUM
Kubewarden vulnerable to RBAC Reconnaissance via unchecked can_i host capability call
GHSA-wqcw-g35j-j578
pkg: github.com/kubewarden/kubewarden-controller
eco: go
published: May 5, 2026
### Impact
Kubewarden is a policy engine for Kubernetes. Kubewarden cluster operators can grant permissions to users to deploy namespaced AdmissionPolicies and AdmissionPolicyGroups in their Namespaces. One of Kubewarden promises is that configured users can deploy namespaced policies in a safe mann…
CVE-2026-42541
GitHub-GHSA

MEDIUM
@workos/authkit-session has an Open Redirect via state-derived redirect target
GHSA-vvvv-983w-r7pv
pkg: @workos/authkit-session
eco: npm
published: May 5, 2026
An open redirect vulnerability exists in `AuthService.handleCallback` due to insufficient validation of the `returnPathname` value derived from the OAuth `state` parameter.

The `state` parameter is round-tripped through the identity provider (IdP) and can be influenced by an attacker. The handleCal…

CVE-2026-42565
NVD

MEDIUM
CVE-2026-7996
CVE-2026-7996
pkg: google chrome, apple macos, linux linux_kernel

published: May 6, 2026

Insufficient validation of untrusted input in SSL in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
CWE: CWE-20
NVD

MEDIUM
CVE-2026-7912
CVE-2026-7912
pkg: google chrome, google android

published: May 6, 2026

Integer overflow in GPU in Google Chrome on Android prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-472
GitHub-GHSA

MEDIUM
next-intl has prototype pollution with `experimental.messages.precompile` via attacker-controlled translation catalog keys
GHSA-4c35-wcg5-mm9h
pkg: next-intl
eco: npm
published: May 6, 2026
## Summary

`setNestedProperty` in `packages/next-intl/src/extractor/utils.tsx` walks a dotted key path and assigns the final value without blocking the reserved keys `__proto__`, `constructor`, or `prototype`. When the next-intl Next.js plugin is configured with `experimental.messages` and `message…

GitHub-GHSA

MEDIUM
in-toto-golang and in-toto-python have inconsistent negation behavior
GHSA-pmwq-pjrm-6p5r
pkg: github.com/in-toto/in-toto-golang
eco: go
published: May 8, 2026
### Impact
_What kind of vulnerability is it? Who is impacted?_

in-toto-golang and in-toto-python both support glob patterns in artifact rules to indicate the artifacts that a rule applies to. Both support negations in character classes to indicate what should *not* be matched, but they used differ…

GitHub-GHSA

MEDIUM
ciguard: SCA HTTP client reads response body without size cap
GHSA-xw8c-rrvx-f7xq
pkg: ciguard
eco: pip
published: May 5, 2026
## Summary

Both SCA HTTP clients (`src/ciguard/analyzer/sca/osv.py` and `src/ciguard/analyzer/sca/endoflife.py`) call `payload = json.loads(resp.read().decode('utf-8'))` without a maximum-bytes cap. A hostile or compromised endoflife.date / OSV.dev (or a successful TLS MITM) could return a multi-GB…

CVE-2026-44219
GitHub-GHSA

MEDIUM
Mistune has XSS via unescaped figclass/figwidth in Figure directive
GHSA-58cw-g322-p94v
pkg: mistune
eco: pip
published: May 8, 2026
In `src/mistune/directives/image.py`, the `render_figure()` function concatenates `figclass` and `figwidth` options directly into HTML attributes without escaping (lines 152-168).

This allows attribute injection and XSS even when `HTMLRenderer(escape=True)` is used, because these values bypass the …

CVE-2026-44896
GitHub-GHSA

MEDIUM
eml_parser has recursion DoS via nested message/rfc822 attachments
GHSA-g47v-rwmh-r9f8
pkg: eml_parser
eco: pip
published: May 8, 2026
### Summary

`EmlParser.get_raw_body_text()` recurses unconditionally for every nested `message/rfc822` attachment without any depth limit. An attacker who can supply a badly crafted EML file with approximately 120 nested `message/rfc822` parts triggers an unhandled `RecursionError` and aborts parsi…

CVE-2026-44844
GitHub-GHSA

MEDIUM
@cyclonedx/cdxgen: Docker registry auth substring match forwards credentials to a different registry
GHSA-qhh4-458h-xwh2
pkg: @cyclonedx/cdxgen
eco: npm
published: May 8, 2026
# Docker registry auth substring match forwards credentials to a different registry

## Repository

`cdxgen/cdxgen`

## Affected product/package

– Ecosystem: npm
– Package: `@cyclonedx/cdxgen`
– Reviewed tree version: `12.3.3`
– Reviewed commit: `b1e179869fd7c6032c3d483c3f7bd4d7154ec22b`
– Affected…

GitHub-GHSA

MEDIUM
MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist
GHSA-r48c-v28r-pf6v
pkg: github.com/modelcontextprotocol/registry
eco: go
published: May 8, 2026
### Summary

The Registry's HTTP-based namespace verification (`POST /v0/auth/http`, `POST /v0.1/auth/http`) uses `safeDialContext` (`internal/api/handlers/v0/auth/http.go:67-110`) to refuse dialling private/internal addresses when fetching the well-known public-key file from a publisher-supplied do…

CVE-2026-44430
GitHub-GHSA

MEDIUM
MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl`
GHSA-rqv2-m695-f8j4
pkg: github.com/modelcontextprotocol/registry
eco: go
published: May 8, 2026
## Summary

The public catalogue UI served at `GET /` (file `internal/api/handlers/v0/ui_index.html`) is vulnerable to stored cross-site scripting via the `server.websiteUrl` field of any published `server.json`. Server-side validation in `internal/validators/validators.go` (`validateWebsiteURL`) on…

CVE-2026-44429
GitHub-GHSA

MEDIUM
MCP Registry has open redirect via protocol-relative path in trailing-slash middleware
GHSA-v8vw-gw5j-w7m6
pkg: github.com/modelcontextprotocol/registry
eco: go
published: May 8, 2026
### Summary
The TrailingSlashMiddleware in internal/api/server.go is vulnerable to an open redirect attack. An attacker can craft a URL with a protocol-relative path (e.g., //evil.com/) that, after trailing slash removal, results in a Location header of //evil.com — which browsers interpret as an …
CVE-2026-44427
GitHub-GHSA

MEDIUM
rust-openssl vulnerable to heap buffer overflow when encrypting with AES key-wrap-with-padding
GHSA-xv59-967r-8726
pkg: openssl
eco: rust
published: May 7, 2026
`CipherCtxRef::cipher_update`, `CipherCtxRef::cipher_update_vec`, and `symm::Crypter::update` incorrectly sized output buffers when used with AES key-wrap-with-padding ciphers (`EVP_aes_{128,192,256}_wrap_pad`). For a non-multiple-of-8 input, OpenSSL writes up to 7 bytes past the end of the caller's…
CVE-2026-44662
GitHub-GHSA

MEDIUM
gittuf's policy can be rolled back to prior valid versions
GHSA-vxvc-cg7j-rwqj
pkg: github.com/gittuf/gittuf
eco: go
published: May 7, 2026
## Summary

An attacker with push access to gittuf's Reference State Log (RSL) can roll back the current policy to any previous policy trusted by the current set of root keys.

## Impact

gittuf determines the policy to load by inspecting the RSL. Except for the very first policy (which is automatic…

CVE-2026-44544
GitHub-GHSA

MEDIUM
imageproc: integer overflow in kernel size check leads to out-of-bounds read
GHSA-w5p8-4jcx-2j6r
pkg: imageproc, imageproc, imageproc
eco: rust
published: May 7, 2026
A bounds verification of a slice storage of a 2-dimensional matrix's coefficients (a kernel) would compare the total size against the product of individual dimensions. This would erroneously cast *after* the multiplication and consequently fail to detect possible violations when overflow occurs.

Af…

GitHub-GHSA

MEDIUM
imageproc: Out-of-bounds read via NaN coordinates in bilinear/bicubic sampling
GHSA-qg8r-f7x3-25f7
pkg: imageproc, imageproc, imageproc
eco: rust
published: May 7, 2026
A bounds check was performed in floating points before a cast to the index passed to an unchecked access function. This checked considered `NaN` cases improperly, causing them to succeed the check instead of failing it. The floating point coordinate is under caller control by passing a selected proj…
GitHub-GHSA

MEDIUM
imageproc has fragile bounds check when sampling from image
GHSA-5qv7-j6w5-fr4m
pkg: imageproc, imageproc, imageproc
eco: rust
published: May 7, 2026
A read of pixels was coded as modifying coordinates to lie within the image bounds. It would calculate a coordinate by adding a constant to an input and taking the minimum of the resulting coordinate and 'dimension – 1'. This would not protect against malicious inputs that could overflow the additio…
GitHub-GHSA

MEDIUM
hickory-proto vulnerable to CPU exhaustion during message encoding due to O(n²) name compression
GHSA-q2qq-hmj6-3wpp
pkg: hickory-proto
eco: rust
published: May 7, 2026
During message encoding, `hickory-proto`'s `BinEncoder` stores pointers to labels that are candidates for name compression in a `Vec<(usize, Vec<u8>)>`. The name compression logic then searches for matches with a linear scan.

A malicious message with many records can both introduce many candidate l…

GitHub-GHSA

MEDIUM
wasmtime has a panic when allocating a table exceeding the size of the host's address space
GHSA-p8xm-42r7-89xg
pkg: wasmtime, wasmtime
eco: rust
published: May 7, 2026
### Impact

Wasmtime's allocation logic for a WebAssembly table contained checked arithmetic which panicked on overflow. This overflow is possible to trigger, and thus panic, when a table with an extremely large size is allocated. This is possible with the WebAssembly memory64 proposal where tables …

CVE-2026-44216
GitHub-GHSA

MEDIUM
Spring Cloud AWS missing SNS message signature verification allows spoofing of HTTP/HTTPS endpoint notifications
GHSA-r4w4-wv68-qv85
pkg: io.awspring.cloud:spring-cloud-aws-sns, io.awspring.cloud:spring-cloud-aws-sns
eco: maven
published: May 7, 2026
### Impact

Applications using Spring Cloud AWS SNS HTTP/HTTPS endpoint support (@NotificationMessageMapping, @NotificationSubscriptionMapping, @NotificationUnsubscribeConfirmationMapping) did not verify the signature of incoming SNS messages.

An unauthenticated attacker who knows the endpoint …

CVE-2026-44308
GitHub-GHSA

MEDIUM
Lemmy resend-verification endpoint exposes registered email addresses to unauthenticated users
GHSA-qxrw-f6fh-34r7
pkg: lemmy_api
eco: rust
published: May 6, 2026
## Summary

The unauthenticated resend-verification endpoint returns different responses for registered and unregistered email addresses. A malicious third party can submit candidate addresses to `/api/v4/account/auth/resend_verification_email` and distinguish accounts from misses.

## Details

`res…

GitHub-GHSA

MEDIUM
Playwright Capture permits access to local files and internal network resources during page capture
GHSA-687h-xw6f-q2qw
pkg: PlaywrightCapture
eco: pip
published: May 6, 2026
Playwright Capture did not sufficiently restrict navigations and resource requests initiated by rendered pages. An attacker-controlled page could abuse browser-side redirection mechanisms, such as window.location.href, to make the capture process open file:// URLs or request resources hosted on priv…
CVE-2026-44439
GitHub-GHSA

MEDIUM
Angular SSR has Open Redirect and Request Steering via Encoded X-Forwarded-Prefix
GHSA-69xr-m8h6-h664
pkg: @angular/ssr, @angular/ssr, @angular/ssr
eco: npm
published: May 6, 2026
### Description
A vulnerability exists in the `X-Forwarded-Prefix` header processing logic within Angular SSR. The internal validation mechanism fails to properly account for URL-encoded characters, specifically dots (`%2e%2e`). This allows an attacker to bypass security filters by injecting encoded…
CVE-2026-44437
GitHub-GHSA

MEDIUM
kanidmd_lib: Image upload validators run before authorization; PNG validator panics on malformed input
GHSA-84jc-3hj2-hwc7
pkg: kanidmd_lib
eco: rust
published: May 6, 2026
### Summary
The `POST /v1/domain/_image` and `POST /v1/oauth2/{rs_name}/_image` handlers call `validate_image()` on the uploaded body **before** the ACL check that restricts image upload to admins. Any bug in an image validator is therefore reachable by an unauthenticated remote client rather than b…
GitHub-GHSA

MEDIUM
Nitro has an Open Redirect via Protocol-Relative URL Bypass in Wildcard Route Rules
GHSA-9phm-9p8f-hw5m
pkg: nitro, nitropack
eco: npm
published: May 6, 2026
A redirect route rule like:

“`ts
routeRules: {
"/legacy/**": { redirect: "/**" }
}
“`

is intended to rewrite paths within the same host. Before the patch, an attacker could turn the rewrite into a cross-host redirect by sliding an extra slash in after the rule prefix. Example exploit:

“`
GET…

CVE-2026-44372
GitHub-GHSA

MEDIUM
pyquorum: Timing side‑channel in mul_mod
GHSA-7r92-3jgr-r65q
pkg: pyquorum
eco: pip
published: May 6, 2026
### Impact
The `mul_mod` function implements multiplication via a binary expansion loop whose execution time depends on the Hamming weight of the second operand (the exponent). An attacker who can measure the time of secret‑sharing operations (e.g., via a remote service) could progressively recove…
CVE-2026-44368
GitHub-GHSA

MEDIUM
misp-modules has nsafe remote resource fetching in expansion
GHSA-fhq3-2gf3-8f3j
pkg: misp-modules
eco: pip
published: May 6, 2026
An unsafe remote resource fetching vulnerability existed in MISP Modules expansion modules. The html_to_markdown module accepted arbitrary HTTP(S) URLs without sufficient validation, which could allow Server-Side Request Forgery against loopback, private, or link-local network resources. Additionall…
CVE-2026-44363
GitHub-GHSA

MEDIUM
Hugo's Node tool execution allows file system access outside the project directory
GHSA-x597-9fr4-5857
pkg: github.com/gohugoio/hugo
eco: go
published: May 6, 2026
## Impact
When building a Hugo site that uses Node-based asset pipelines (PostCSS, Babel, TailwindCSS), Hugo invoked the configured Node tools without restrictions on file system access. As a result, executing hugo against an untrusted site could allow code running through these tools to read or wr…
CVE-2026-44301
GitHub-GHSA

MEDIUM
astral-tokio-tar is Vulnerable to PAX Header Desynchronization
GHSA-fp55-jw48-c537
pkg: astral-tokio-tar
eco: rust
published: May 6, 2026
### Impact

Versions of astral-tokio-tar prior to 0.6.1 contain a PAX header interpretation bug that allows manipulated entries to be made selectively visible or invisible during extraction with astral-tokio-tar versus other tar implementations. An attacker could use this differential to smuggle une…

GitHub-GHSA

MEDIUM
Tauri has an Origin Confusion Issue that Allows Remote Pages to Invoke Local-Only IPC Commands
GHSA-7gmj-67g7-phm9
pkg: tauri
eco: rust
published: May 6, 2026
### Summary
A flaw in Tauri's `is_local_url()` function causes it to incorrectly classify remote URLs as trusted local origins on Windows and Android. On these systems, Tauri maps custom URI scheme protocols to `http://<scheme>.localhost/` because those platforms' WebView implementations cannot serv…
CVE-2026-42184
GitHub-GHSA

MEDIUM
sse-channel: SSE Injection via unsanitized event fields
GHSA-84hm-wfh8-c5pg
pkg: sse-channel
eco: npm
published: May 5, 2026
### Impact

Implementations that allows user-provided values to be passed to `event`, `retry` or `id` fields would be susceptible to event spoofing, where an attacker could inject arbitrary messages into the stream.

– **Event Spoofing:** Attacker can inject arbitrary SSE events into the stream
– **…

CVE-2026-44217
GitHub-GHSA

MEDIUM
Prometheus vulnerable to stored XSS via crafted histogram bucket label values in the old web UI heatmap display
GHSA-fw8g-cg8f-9j28
pkg: github.com/prometheus/prometheus
eco: go
published: May 5, 2026
### Impact

In the Prometheus server's legacy web UI (enabled via the command-line flag `–enable-feature=old-ui`), the histogram heatmap chart view does not escape `le` label values when inserting them into the HTML for use as axis tick mark labels.

An attacker who can inject crafted metrics (e.g.…

GitHub-GHSA

MEDIUM
ip-address has XSS in Address6 HTML-emitting methods
GHSA-v2v4-37r5-5v8g
pkg: ip-address
eco: npm
published: May 5, 2026
### Summary

`Address6.group()` and `Address6.link()` do not HTML-escape attacker-controlled content before embedding it in the HTML strings they return, and `AddressError.parseMessage` (emitted by the `Address6` constructor for invalid input) can contain unescaped attacker-controlled content in one…

CVE-2026-42338
GitHub-GHSA

MEDIUM
PocketBase vulnerable to account pre-hijacking via OAuth2 unverfied->verified autolinking upgrade
GHSA-pq7p-mc74-g65w
pkg: github.com/pocketbase/pocketbase, github.com/pocketbase/pocketbase
eco: go
published: May 5, 2026
A pre-hijacking issue was discovered with the OAuth2 autolinking by [Alardiians](https://github.com/Alardiians).

In some situations, if an attacker knows the email address of the victim they can create and link an **unverified** PocketBase user in advance by authenticating with one of the OAuth2 ap…

CVE-2026-44166
GitHub-GHSA

MEDIUM
Ethyca Fides has a Privacy Request Identity Verification Bypass Vulnerability via Duplicate Detection
GHSA-qx5f-ghc2-7g5c
pkg: ethyca-fides
eco: pip
published: May 5, 2026
### Summary

Fides deployments that enable both subject identity verification and duplicate privacy request detection are affected by a vulnerability in which an administrator can approve a privacy request whose identity was never verified. For erasure policies, this can result in unauthorized delet…

CVE-2026-42303
GitHub-GHSA

MEDIUM
Fiber vulnerable to XSS in AutoFormat Content Negotiation
GHSA-qjv7-627w-8qjv
pkg: github.com/gofiber/fiber/v3, github.com/gofiber/fiber/v2
eco: go
published: May 5, 2026
## Summary

**Description**

A Cross-Site Scripting (CWE-79) vulnerability in Go Fiber allows a remote attacker to inject arbitrary HTML/JavaScript by supplying `Accept: text/html` on any request whose handler passes attacker-influenced data to the AutoFormat() feature. This affects `github.com/gofi…

CVE-2026-42554
GitHub-GHSA

MEDIUM
MinIO vulnerable to Path Traversal via msgpack Body in `ReadMultiple` Storage-REST Endpoint
GHSA-xh8f-g2qw-gcm7
pkg: github.com/minio/minio
eco: go
published: May 5, 2026
### Impact

_What kind of vulnerability is it? Who is impacted?_

A path traversal vulnerability in MinIO's `ReadMultiple` internode storage-REST
endpoint allows a caller holding the cluster root JWT to read files from
outside the configured drive roots, bounded only by the MinIO process UID.

Distr…

CVE-2026-42600
GitHub-GHSA

MEDIUM
net-imap vulnerable to command Injection via "raw" arguments to multiple commands
GHSA-hm49-wcqc-g2xg
pkg: net-imap, net-imap, net-imap
eco: rubygems
published: May 4, 2026
### Summary
Several `Net::IMAP` commands accept a raw string argument that is sent to the server without validation or escaping. If this string is derived from user-controlled input, it may contain contain `CRLF` sequences, which an attacker can use to inject arbitrary IMAP commands.

### Details

CVE-2026-42257
GitHub-GHSA

MEDIUM
net-imap vulnerable to command Injection via unvalidated Symbol inputs
GHSA-75xq-5h9v-w6px
pkg: net-imap, net-imap, net-imap
eco: rubygems
published: May 4, 2026
### Summary

Symbol arguments to commands are vulnerable to a CRLF Injection / IMAP Command injection via Symbol arguments passed to IMAP commands.

### Details

Symbol arguments represent IMAP "system flags", which are formatted as "atoms" (with no quoting) with a `"\"` prefix. Vulnerable versions…

CVE-2026-42258
GitHub-GHSA

MEDIUM
net-imap vulnerable to denial of service via high iteration count for `SCRAM-*` authentication
GHSA-87pf-fpwv-p7m7
pkg: net-imap, net-imap, net-imap
eco: rubygems
published: May 4, 2026
### Summary

When authenticating a connection with `SCRAM-SHA1` or `SCRAM-SHA256`, a hostile server can perform a computational denial-of-service attack on the client process by sending a big iteration count value.

### Details

A hostile IMAP server can send an arbitrarily large PBKDF2 iteration co…

CVE-2026-42256
GitHub-GHSA

MEDIUM
quarkus-openapi-generator has overly broad path-parameter matching that sends authentication headers to unintended operations
GHSA-fr8f-rwjx-f32v
pkg: io.quarkiverse.openapi.generator:quarkus-openapi-generator, io.quarkiverse.openapi.generator:quarkus-openapi-generator
eco: maven
published: May 4, 2026
### Summary

The generated authentication filter matches OpenAPI path templates too broadly when deciding whether to attach credentials. A security scheme configured for one operation can therefore be applied to a different same-method operation whose path only partially resembles the protected temp…

CVE-2026-42333
GitHub-GHSA

MEDIUM
OpenClaw's Gateway Control UI bootstrap config required Gateway auth
GHSA-93rg-2xm5-2p9v
pkg: openclaw
eco: npm
published: May 4, 2026
## Summary
Gateway Control UI bootstrap config required Gateway auth.

## Affected Packages / Versions
– Package: openclaw (npm)
– Affected versions: <= 2026.4.21
– Fixed version: 2026.4.22

## Impact
When Gateway authentication was enabled, the Control UI bootstrap config endpoint could still be re…

GitHub-GHSA

MEDIUM
OpenClaw: OpenShell FS bridge reads pin and verify the opened file before returning bytes
GHSA-5h3g-6xhh-rg6p
pkg: openclaw
eco: npm
published: May 4, 2026
## Summary
OpenShell FS bridge reads pin and verify the opened file before returning bytes

## Affected Packages / Versions
– Package: openclaw (npm)
– Affected versions: <= 2026.4.21
– Fixed version: 2026.4.22

## Impact
A time-of-check/time-of-use race around OpenShell sandbox filesystem reads cou…

GitHub-GHSA

MEDIUM
jOpenDocument has an improper restriction of XML external entity reference vulnerability
GHSA-j9rh-p96m-mhhp
pkg: org.jopendocument:jOpenDocument
eco: maven
published: May 4, 2026
Improper restriction of XML external entity reference vulnerability in ILM Informatique jOpenDocument allows Data Serialization External Entities Blowup.

This issue affects jOpenDocument: 1.5.

CVE-2026-6501


Vulnerability Digest — May 4, 2026 · 20 Critical · 4 Exploited






Vulnerability Digest — Monday, May 4, 2026


Security Report

Monday, May 4, 2026  ·  Last 7 days  ·  Min severity: MEDIUM
Total Findings
175
Critical
20
High
99
Actively Exploited
4
CISA-KEV4
NVD117
GitHub-GHSA54
Findings sorted by severity
CISA-KEV

CRITICAL
Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability
CVE-2026-31431
pkg: Linux Kernel

published: May 1, 2026

Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation.
Required action: "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability
CVE-2026-41940
pkg: WebPros cPanel & WHM and WP2 (WordPress Squared)

published: Apr 30, 2026

WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
ConnectWise ScreenConnect Path Traversal Vulnerability
CVE-2024-1708
pkg: ConnectWise ScreenConnect

published: Apr 28, 2026

ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
Microsoft Windows Protection Mechanism Failure Vulnerability
CVE-2026-32202
pkg: Microsoft Windows

published: Apr 28, 2026

Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
GitHub-GHSA

CRITICAL
Gotenberg has ExifTool stdin argument injection via metadata value newlines (bypass of key sanitization fix)
GHSA-q7r4-hc83-hf2q
pkg: github.com/gotenberg/gotenberg/v8
eco: go
published: Apr 30, 2026
## Vulnerability Details

**CWE**: CWE-20 – Improper Input Validation

The metadata value sanitization introduced in v8.30.1 (commit 405f106) only validates metadata KEYS via safeKeyPattern regex. Metadata VALUES are passed unsanitized to go-exiftool SetString(), which writes them as fmt.Fprintln(e.…

CVE-2026-40281
GitHub-GHSA

CRITICAL
n8n has Prototype Pollution in XML Webhook Body Parser that Leads to RCE
GHSA-q5f4-99jv-pgg5
pkg: n8n, n8n, n8n
eco: npm
published: Apr 29, 2026
## Impact
A flaw in the `xml2js` library used to parse XML request bodies in n8n's webhook handler allowed prototype pollution via a crafted XML payload. An authenticated user with permission to create or modify workflows could exploit this to pollute the JavaScript object prototype and, by chaining…
CVE-2026-42231
GitHub-GHSA

CRITICAL
n8n has XML Node Prototype Pollution that to RCE
GHSA-hqr4-h3xv-9m3r
pkg: n8n, n8n, n8n
eco: npm
published: Apr 29, 2026
## Impact
An authenticated user with permission to create or modify workflows could achieve global prototype pollution via the XML Node leading to RCE when combined with other nodes exploiting the prototype pollution.

## Patches
The issue has been fixed in n8n versions 1.123.32, 2.17.4, and 2.18.1.…

CVE-2026-42232
NVD

CRITICAL
CVE-2026-31718
CVE-2026-31718
pkg: linux

published: May 1, 2026

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix use-after-free in __ksmbd_close_fd() via durable scavenger

When a durable file handle survives session disconnect (TCP close without
SMB2_LOGOFF), session_fd_check() sets fp->conn = NULL to preserve the
handle for later…

NVD

CRITICAL
CVE-2026-31705
CVE-2026-31705
pkg: linux

published: May 1, 2026

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix out-of-bounds write in smb2_get_ea() EA alignment

smb2_get_ea() applies 4-byte alignment padding via memset() after
writing each EA entry. The bounds check on buf_free_len is performed
before the value memcpy, but the a…

NVD

CRITICAL
CVE-2018-25316
CVE-2018-25316
pkg: go

published: Apr 29, 2026

Tenda W308R v2 V5.07.48 contains a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient session validation. Attackers can send GET requests to the goform/AdvSetDns endpoint with a crafted admin language cookie to change DNS ser…
CWE: CWE-290
NVD

CRITICAL
CVE-2026-41873
CVE-2026-41873
pkg: apache pony_mail

published: Apr 28, 2026

** UNSUPPORTED WHEN ASSIGNED ** Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Pony Mail leading to admin account takeover.

This issue affects all versions of the Lua implementation of Pony Mail. There is a Python implementation under development u…

CWE: CWE-444
NVD

CRITICAL
CVE-2026-32644
CVE-2026-32644
pkg: ssl

published: Apr 28, 2026

Specific firmware versions of Milesight AIOT cameras use SSL certificates with default private keys.
CWE: CWE-321
NVD

CRITICAL
CVE-2026-41462
CVE-2026-41462
pkg: express

published: Apr 27, 2026

ProjeQtor versions 7.0 through 12.4.3 contain an unauthenticated SQL injection vulnerability in the login functionality where the login variable is directly concatenated into a SQL query without parameterization or sanitization. Attackers can inject arbitrary SQL expressions through the username fie…
CWE: CWE-89
NVD

CRITICAL
CVE-2026-7333
CVE-2026-7333
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Use after free in GPU in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
GitHub-GHSA

CRITICAL
Gotenberg has case-insensitive URL scheme that bypasses webhook and downloadFrom deny-list SSRF protection
GHSA-5q7p-7jgv-ww56
pkg: github.com/gotenberg/gotenberg/v8
eco: go
published: Apr 30, 2026
## Vulnerability Details

**CWE**: CWE-918 – Server-Side Request Forgery (SSRF)

The default private-IP deny-lists for –webhook-deny-list and –api-download-from-deny-list use a case-sensitive regex (^https?://). Any uppercase URL scheme variant (HTTP://, HTTPS://, Http://) bypasses the pattern. Go…

CVE-2026-40280
GitHub-GHSA

CRITICAL
auth: Patreon provider assigns the same local user ID to every authenticated Patreon account, enabling cross‑user impersonation
GHSA-f6qq-3m3h-4g42
pkg: github.com/go-pkgz/auth, github.com/go-pkgz/auth/v2
eco: go
published: Apr 30, 2026
### Summary
The Patreon OAuth provider maps every authenticated Patreon account to the same local `user.ID`, instead of deriving a unique ID from the Patreon account returned by Patreon.

In practice, this means all Patreon-authenticated users of an application using this library are collapsed into …

CVE-2026-42560
GitHub-GHSA

CRITICAL
Sentry's improper authentication on SAML SSO process allows user identity linking
GHSA-rcmw-7mc7-3rj7
pkg: sentry
eco: pip
published: Apr 30, 2026
### Impact
A critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via Sentry's private bug bounty program.

The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the …

CVE-2026-42354
NVD

CRITICAL
CVE-2026-7381
CVE-2026-7381
pkg: express

published: Apr 29, 2026

Plack::Middleware::XSendfile versions through 1.0053 for Perl can allow client-controlled path rewriting.

Plack::Middleware::XSendfile allows the variation setting (sendfile type) to be set by the client via the X-Sendfile-Type header, if it is not considered in the middleware constructor or the Pl…

CWE: CWE-200, CWE-441, CWE-913
NVD

CRITICAL
CVE-2026-30893
CVE-2026-30893
pkg: wazuh wazuh

published: Apr 29, 2026

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.4.0 to before version 4.14.4, a path traversal vulnerability in Wazuh's cluster synchronization extraction routine allows an authenticated cluster peer to write arbitrary files outside the in…
CWE: CWE-22, CWE-73
GitHub-GHSA

CRITICAL
fabric-sdk-java has ObjectInputStream.readObject() without ObjectInputFilter, which allows Java deserialization RCE
GHSA-prf8-cf2x-rhx7
pkg: org.hyperledger.fabric-sdk-java:fabric-sdk-java
eco: maven
published: Apr 29, 2026
## Summary

This advisory covers the deprecated `fabric-sdk-java` client SDK. `Channel.java` implements `readObject()` and exposes `deSerializeChannel()` which call `ObjectInputStream.readObject()` on untrusted byte arrays without configuring an `ObjectInputFilter`. This is the classic Java deserial…

CVE-2026-41586
NVD

HIGH
CVE-2026-2052
CVE-2026-2052
pkg: express

published: May 2, 2026

The Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.2.2 via the Display Logic feature. This is due to the plugin using eval() on user-supplied Display Logic e…
CWE: CWE-94
NVD

HIGH
CVE-2026-43048
CVE-2026-43048
pkg: go

published: May 1, 2026

In the Linux kernel, the following vulnerability has been resolved:

HID: core: Mitigate potential OOB by removing bogus memset()

The memset() in hid_report_raw_event() has the good intention of
clearing out bogus data by zeroing the area from the end of the incoming
data string to the assumed end …

NVD

HIGH
CVE-2026-31735
CVE-2026-31735
pkg: go

published: May 1, 2026

In the Linux kernel, the following vulnerability has been resolved:

iommupt: Fix short gather if the unmap goes into a large mapping

unmap has the odd behavior that it can unmap more than requested if the
ending point lands within the middle of a large or contiguous IOPTE.

In this case the gather…

NVD

HIGH
CVE-2026-31717
CVE-2026-31717
pkg: linux

published: May 1, 2026

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: validate owner of durable handle on reconnect

Currently, ksmbd does not verify if the user attempting to reconnect
to a durable handle is the same user who originally opened the file.
This allows any authenticated user to h…

NVD

HIGH
CVE-2026-31709
CVE-2026-31709
pkg: linux

published: May 1, 2026

In the Linux kernel, the following vulnerability has been resolved:

smb: client: validate the whole DACL before rewriting it in cifsacl

build_sec_desc() and id_mode_to_cifs_acl() derive a DACL pointer from a
server-supplied dacloffset and then use the incoming ACL to rebuild the
chmod/chown securi…

NVD

HIGH
CVE-2026-31706
CVE-2026-31706
pkg: linux

published: May 1, 2026

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: validate num_aces and harden ACE walk in smb_inherit_dacl()

smb_inherit_dacl() trusts the on-disk num_aces value from the parent
directory's DACL xattr and uses it to size a heap allocation:

aces_base = kmalloc(sizeof(st…

NVD

HIGH
CVE-2026-5402
CVE-2026-5402
pkg: wireshark wireshark

published: Apr 30, 2026

TLS protocol dissector heap overflow in Wireshark 4.6.0 to 4.6.4 allows denial of service and possible code execution
CWE: CWE-122
NVD

HIGH
CVE-2026-7466
CVE-2026-7466
pkg: python

published: Apr 29, 2026

AgentFlow contains an arbitrary code execution vulnerability that allows attackers to execute local Python pipeline files by supplying a user-controlled pipeline_path parameter to the POST /api/runs and POST /api/runs/validate endpoints. Attackers can induce requests to the local AgentFlow API to lo…
CWE: CWE-94
NVD

HIGH
CVE-2026-7363
CVE-2026-7363
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Use after free in Canvas in Google Chrome on Linux, ChromeOS prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-7361
CVE-2026-7361
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Use after free in iOS in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-7359
CVE-2026-7359
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Use after free in ANGLE in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416, CWE-416
NVD

HIGH
CVE-2026-7358
CVE-2026-7358
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Use after free in Animation in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-7356
CVE-2026-7356
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Use after free in Navigation in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-7355
CVE-2026-7355
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Use after free in Media in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-416
NVD

HIGH
CVE-2026-7354
CVE-2026-7354
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Out of bounds read and write in Angle in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-125, CWE-787
NVD

HIGH
CVE-2026-7348
CVE-2026-7348
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Use after free in Codecs in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-7344
CVE-2026-7344
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Use after free in Accessibility in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-7342
CVE-2026-7342
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Use after free in WebView in Google Chrome on Android prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-7341
CVE-2026-7341
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Use after free in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-7339
CVE-2026-7339
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Heap buffer overflow in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-122
NVD

HIGH
CVE-2026-7337
CVE-2026-7337
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Type Confusion in V8 in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-843
NVD

HIGH
CVE-2026-7336
CVE-2026-7336
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Use after free in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-7335
CVE-2026-7335
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Use after free in media in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-7334
CVE-2026-7334
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Use after free in Views in Google Chrome on Mac prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-42426
CVE-2026-42426
pkg: openclaw openclaw

published: Apr 28, 2026

OpenClaw before 2026.4.8 contains an improper authorization vulnerability where the node.pair.approve method accepts operator.write scope instead of the narrower operator.pairing scope, allowing unprivileged users to approve node pairing. Attackers with operator.write permissions can bypass pairing …
CWE: CWE-863
NVD

HIGH
CVE-2026-41378
CVE-2026-41378
pkg: openclaw openclaw

published: Apr 28, 2026

OpenClaw before 2026.3.31 contains a privilege escalation vulnerability allowing paired nodes with role=node to dispatch node.event agent requests with unrestricted gateway-side tool access. Attackers with trusted paired node credentials can escalate privileges by leveraging unrestricted agent.reque…
CWE: CWE-862
GitHub-GHSA

HIGH
Gotenberg Vulnerable to Unauthenticated SSRF via Unfiltered Webhook URL
GHSA-5vh4-rgv7-p9g4
pkg: github.com/gotenberg/gotenberg/v8
eco: go
published: Apr 30, 2026
# CVE Report — Unauthenticated SSRF via Unfiltered Webhook URL in Gotenberg

## Severity

| Field | Value |
|———–|—————————————-|
| CVSS v3.1 | **8.6 High** |
| Vector | `AV:N/AC:L/PR:N/UI:N/S:C/C:H/…

CVE-2026-39383
GitHub-GHSA

HIGH
pygeoapi 0.23.x: Unauthenticated SSRF via OGC API – Processes Subscriber
GHSA-jgvc-94c8-3chc
pkg: pygeoapi
eco: pip
published: Apr 29, 2026
### Impact
OGC API – Process execution requests can use the `subscriber` object to requests to internal HTTP services.

### Patches
The issue has been patched in master branch and made available as part of the 0.23.3 release. The patch disables any HTTP requests made to internal resources by defaul…

CVE-2026-42352
NVD

HIGH
CVE-2026-40967
CVE-2026-40967
pkg: vmware spring_ai

published: Apr 28, 2026

In Spring AI, various FilterExpressionConverter implementations accept a filter expression object and translate them to specific vector store query languages. In several cases, keys and values are not properly escaped, leading to the ability to alter the query.

Affected versions:
Spring AI: 1.0.0 -…

CWE: CWE-94
GitHub-GHSA

HIGH
n8n-mcp's IPv4-mapped IPv6 addresses bypass SSRF protection in validateUrlSync(), enabling full SSRF for SDK embedders
GHSA-56c3-vfp2-5qqj
pkg: n8n-mcp
eco: npm
published: Apr 30, 2026
### Impact

In the SDK embedder path (`N8NDocumentationMCPServer` constructor, `getN8nApiClient()`, and `validateInstanceContext()`), the synchronous URL validator in `SSRFProtection.validateUrlSync()` had no IPv6 checks. IPv4-mapped IPv6 addresses such as `http://[::ffff:169.254.169.254]` bypassed …

CVE-2026-42449
GitHub-GHSA

HIGH
n8n's Credential Authorization Bypass in dynamic-node-parameters Allows Foreign API Key Replay
GHSA-r4v6-9fqc-w5jr
pkg: n8n, n8n
eco: npm
published: Apr 29, 2026
## Impact
The `dynamic-node-parameters` endpoints did not verify whether the authenticated caller was authorized to use a supplied credential reference. An authenticated user with access to a shared workflow could supply a foreign credential ID in the request body, causing the backend to decrypt and…
CVE-2026-42226
GitHub-GHSA

HIGH
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services
GHSA-wr32-99hh-6f35
pkg: github.com/0xJacky/Nginx-UI
eco: go
published: Apr 29, 2026
### Summary

An authenticated user can perform Server-Side Request Forgery (SSRF) by creating a cluster node pointing to an arbitrary internal URL and then sending API requests with the `X-Node-ID` header. The Proxy middleware forwards these requests to the attacker-specified internal address, bypas…

NVD

HIGH
CVE-2026-31712
CVE-2026-31712
pkg: linux

published: May 1, 2026

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: require minimum ACE size in smb_check_perm_dacl()

Both ACE-walk loops in smb_check_perm_dacl() only guard against an
under-sized remaining buffer, not against an ACE whose declared
`ace->size` is smaller than the struct it …

NVD

HIGH
CVE-2026-7353
CVE-2026-7353
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Heap buffer overflow in Skia in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-122
NVD

HIGH
CVE-2026-7352
CVE-2026-7352
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Use after free in Media in Google Chrome on Android prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-7350
CVE-2026-7350
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Use after free in WebMIDI in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-7345
CVE-2026-7345
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Insufficient validation of untrusted input in Feedback in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-20
GitHub-GHSA

HIGH
i18next-http-middleware has path traversal / SSRF via user-controlled language and namespace parameters
GHSA-jfgf-83c5-2c4m
pkg: i18next-http-middleware
eco: npm
published: Apr 29, 2026
### Summary

Versions of `i18next-http-middleware` prior to 3.9.3 pass the user-controlled `lng` and `ns` values from `getResourcesHandler` directly into `i18next.services.backendConnector.load(languages, namespaces, …)` without any sanitisation. Depending on which backend is configured, the unval…

CVE-2026-42353
GitHub-GHSA

HIGH
n8n Vulnerable to XSS via MCP OAuth client
GHSA-537j-gqpc-p7fq
pkg: n8n, n8n, n8n
eco: npm
published: Apr 29, 2026
## Impact
An unauthenticated attacker could register a malicious MCP OAuth client with a crafted `client_name`. If a victim user authorized the OAuth consent dialog and a second user subsequently revoked that access, a toast notification would render the injected script. Clicking the link would exec…
CVE-2026-42235
NVD

HIGH
CVE-2026-38651
CVE-2026-38651
pkg: jwt

published: Apr 28, 2026

Authentication Bypass vulnerability exists in Netmaker versions prior to 1.5.0. The VerifyHostToken function in logic/jwts.go fails to validate the JWT signature when verifying host tokens. An attacker can forge a JWT signed with any arbitrary key and use it to impersonate any host in the network, g…
CWE: CWE-347
NVD

HIGH
CVE-2026-40022
CVE-2026-40022
pkg: apache camel

published: Apr 27, 2026

When authentication is enabled on the Apache Camel embedded HTTP server or embedded management server (camel-platform-http-main) and a non-root context path such as /api or /admin is configured via camel.server.path or camel.management.path, the BasicAuthenticationConfigurer and JWTAuthenticationCon…
CWE: CWE-288
NVD

HIGH
CVE-2026-31708
CVE-2026-31708
pkg: linux

published: May 1, 2026

In the Linux kernel, the following vulnerability has been resolved:

smb: client: fix OOB read in smb2_ioctl_query_info QUERY_INFO path

smb2_ioctl_query_info() has two response-copy branches: PASSTHRU_FSCTL
and the default QUERY_INFO path. The QUERY_INFO branch clamps
qi.input_buffer_length to the…

GitHub-GHSA

HIGH
Contras Affected by CopyFile Policy Subversion via Symlinks
GHSA-rh99-wc69-c255
pkg: github.com/edgelesssys/contrast
eco: go
published: Apr 30, 2026
### Impact

The [Kata agent policies](https://docs.edgeless.systems/contrast/architecture/components/policies) generated by the Contrast CLI had an issue in the `CopyFile` verification, which allowed arbitrary writes to the guest root filesytem. A malicious process on the host with the capability to…

NVD

HIGH
CVE-2026-7347
CVE-2026-7347
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Use after free in Chromoting in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-7346
CVE-2026-7346
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Inappropriate implementation in Tint in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-119
NVD

HIGH
CVE-2026-42431
CVE-2026-42431
pkg: openclaw openclaw

published: Apr 28, 2026

OpenClaw before 2026.4.8 contains a security bypass vulnerability in node.invoke(browser.proxy) that allows mutation of persistent browser profiles. Attackers can exploit this path to circumvent the browser.request persistent profile-mutation guard and modify browser configurations.
CWE: CWE-863
NVD

HIGH
CVE-2026-43003
CVE-2026-43003
pkg: python

published: May 1, 2026

An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install from within a chroot of the deployed partition image, leading to code execution in the case of a malicious image.
CWE: CWE-829
NVD

HIGH
CVE-2026-43016
CVE-2026-43016
pkg: go

published: May 1, 2026

In the Linux kernel, the following vulnerability has been resolved:

bpf: sockmap: Fix use-after-free of sk->sk_socket in sk_psock_verdict_data_ready().

syzbot reported use-after-free of AF_UNIX socket's sk->sk_socket
in sk_psock_verdict_data_ready(). [0]

In unix_stream_sendmsg(), the peer socket'…

NVD

HIGH
CVE-2026-31716
CVE-2026-31716
pkg: linux

published: May 1, 2026

In the Linux kernel, the following vulnerability has been resolved:

fs/ntfs3: validate rec->used in journal-replay file record check

check_file_record() validates rec->total against the record size but
never validates rec->used. The do_action() journal-replay handlers read
rec->used from disk and…

NVD

HIGH
CVE-2026-31703
CVE-2026-31703
pkg: linux

published: May 1, 2026

In the Linux kernel, the following vulnerability has been resolved:

writeback: Fix use after free in inode_switch_wbs_work_fn()

inode_switch_wbs_work_fn() has a loop like:

wb_get(new_wb);
while (1) {
list = llist_del_all(&new_wb->switch_wbs_ctxs);
/* Nothing to do? */
if (!list)

NVD

HIGH
CVE-2026-31700
CVE-2026-31700
pkg: linux

published: May 1, 2026

In the Linux kernel, the following vulnerability has been resolved:

net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd()

In tpacket_snd(), when PACKET_VNET_HDR is enabled, vnet_hdr points
directly into the mmap'd TX ring buffer shared with userspace. The
kernel validates the header via …

NVD

HIGH
CVE-2026-31695
CVE-2026-31695
pkg: linux

published: May 1, 2026

In the Linux kernel, the following vulnerability has been resolved:

wifi: virt_wifi: remove SET_NETDEV_DEV to avoid use-after-free

Currently we execute `SET_NETDEV_DEV(dev, &priv->lowerdev->dev)` for
the virt_wifi net devices. However, unregistering a virt_wifi device in
netdev_run_todo() can happ…

NVD

HIGH
CVE-2026-31694
CVE-2026-31694
pkg: linux

published: May 1, 2026

In the Linux kernel, the following vulnerability has been resolved:

fuse: reject oversized dirents in page cache

fuse_add_dirent_to_cache() computes a serialized dirent size from the
server-controlled namelen field and copies the dirent into a single
page-cache page. The existing logic only checks…

NVD

HIGH
CVE-2026-7584
CVE-2026-7584
pkg: python

published: May 1, 2026

The LabOne Q serialization framework uses a class-loading mechanism (import_cls) to dynamically import and instantiate Python classes during deserialization. Prior to the fix, this mechanism accepted arbitrary fully-qualified class names from the serialized data without any validation of the target …
CWE: CWE-502
NVD

HIGH
CVE-2026-31693
CVE-2026-31693
pkg: linux

published: Apr 30, 2026

In the Linux kernel, the following vulnerability has been resolved:

cifs: some missing initializations on replay

In several places in the code, we have a label to signify
the start of the code where a request can be replayed if
necessary. However, some of these places were missing the
necessary re…

NVD

HIGH
CVE-2026-31786
CVE-2026-31786
pkg: linux

published: Apr 30, 2026

In the Linux kernel, the following vulnerability has been resolved:

Buffer overflow in drivers/xen/sys-hypervisor.c

The build id returned by HYPERVISOR_xen_version(XENVER_build_id) is
neither NUL terminated nor a string.

The first causes a buffer overflow as sprintf in buildid_show will
read and …

NVD

HIGH
CVE-2026-42432
CVE-2026-42432
pkg: openclaw openclaw

published: Apr 28, 2026

OpenClaw before 2026.4.8 contains a privilege escalation vulnerability allowing previously paired nodes to reconnect with exec-capable commands without operator.admin scope requirement. Attackers can bypass re-pairing authentication to execute privileged commands on the local assistant system.
CWE: CWE-863
NVD

HIGH
CVE-2026-43824
CVE-2026-43824
pkg: kubernetes

published: May 2, 2026

In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data.
CWE: CWE-212
NVD

HIGH
CVE-2026-37554
CVE-2026-37554
pkg: openssl

published: May 1, 2026

An issue was discovered in Vanetza V2X v26.02 allowing remote unauthorized attackers to cause a denial of service. The vulnerability exists in the GeoNetworking packet processing pipeline where OpenSSL exceptions from ECC point validation (invalid compressed point, point not on curve) are not proper…
CWE: CWE-248
NVD

HIGH
CVE-2026-31719
CVE-2026-31719
pkg: linux

published: May 1, 2026

In the Linux kernel, the following vulnerability has been resolved:

crypto: krb5enc – fix async decrypt skipping hash verification

krb5enc_dispatch_decrypt() sets req->base.complete as the skcipher
callback, which is the caller's own completion handler. When the
skcipher completes asynchronously, …

NVD

HIGH
CVE-2026-31711
CVE-2026-31711
pkg: linux

published: May 1, 2026

In the Linux kernel, the following vulnerability has been resolved:

smb: server: fix active_num_conn leak on transport allocation failure

Commit 77ffbcac4e56 ("smb: server: fix leak of active_num_conn in
ksmbd_tcp_new_connection()") addressed the kthread_run() failure
path. The earlier alloc_tran…

NVD

HIGH
CVE-2026-40595
CVE-2026-40595
pkg: go

published: Apr 30, 2026

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Chartbrew exposes public chart retrieval and export routes that only verify project-level public access and, for exports, a team-level export toggle. The r…
CWE: CWE-284
GitHub-GHSA

HIGH
pygeoapi 0.23.x: Path Traversal in STAC FileSystemProvider
GHSA-f6pr-83pg-ghh6
pkg: pygeoapi
eco: pip
published: Apr 29, 2026
### Impact
A raw string path concatenation vulnerability in pygeoapi's STAC FileSystemProvider plugin can allow for requests to STAC collection based collections to expose directories without authentication. The issue manifests when pygeoapi is deployed without a proxy or web front end that would n…
CVE-2026-42351
GitHub-GHSA

HIGH
Marked Vulnerable to OOM Denial of Service via Infinite Recursion in marked Tokenizer
GHSA-6v9c-7cg6-27q7
pkg: marked
eco: npm
published: Apr 29, 2026
### Summary
A critical Denial of Service (DoS) vulnerability exists in `marked@18.0.0`. By providing a specific 3-byte input sequence a tab, a vertical tab, and a newline (`\x09\x0b\n`)—an unauthenticated attacker can trigger an infinite recursion loop during parsing. This leads to unbounded memor…
CVE-2026-41680
GitHub-GHSA

HIGH
n8n has a Python Task Runner Sandbox Escape Vulnerability
GHSA-44v6-jhgm-p3m4
pkg: n8n, n8n, n8n
eco: npm
published: Apr 29, 2026
## Impact
An authenticated user with permission to create or modify workflows containing a Python Code Node could escape the sandbox and achieve arbitrary code execution on the task runner container.

– This issue only affects instances where the Python Task Runner is enabled.

## Patches
The issue …

CVE-2026-42234
GitHub-GHSA

HIGH
GoBGP has Remote Denial of Service (Panic) in UpdatePathAttrs4ByteAs via Malformed BGP UPDATE
GHSA-8rxh-r2p6-7f2q
pkg: github.com/osrg/gobgp/v4
eco: go
published: Apr 29, 2026
### Summary
A remote Denial of Service (DoS) vulnerability exists in GoBGP where a malformed BGP UPDATE message can trigger a runtime error: index out of range panic. This occurs during the processing of 4-byte AS attributes when the message structure causes an internal slice index shift that is not…
CVE-2026-41643
GitHub-GHSA

HIGH
GoBGP has Remote Denial of Service (Panic) via Malformed Well-known Path Attribute
GHSA-7235-89m6-f4px
pkg: github.com/osrg/gobgp/v4
eco: go
published: Apr 29, 2026
### Summary
A remote Denial of Service (DoS) vulnerability exists in GoBGP due to a nil pointer dereference. When a malformed BGP UPDATE message contains an unrecognized Path Attribute marked as "Well-known," the daemon fails to interrupt the message handling flow. This results in an illegal memory …
CVE-2026-41642
NVD

HIGH
CVE-2026-42520
CVE-2026-42520
pkg: node

published: Apr 29, 2026

Jenkins Credentials Binding Plugin 719.v80e905ef14eb_ and earlier does not sanitize file names for file and zip file credentials, allowing attackers able to provide credentials to a job to write files to arbitrary locations on the node filesystem, which can lead to remote code execution if Jenkins i…
CWE: CWE-22
NVD

HIGH
CVE-2026-7357
CVE-2026-7357
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Use after free in GPU in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-7349
CVE-2026-7349
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Use after free in Cast in Google Chrome prior to 147.0.7727.138 allowed an attacker on the local network segment to execute arbitrary code inside a sandbox via malicious network traffic. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-7343
CVE-2026-7343
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Use after free in Views in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-7338
CVE-2026-7338
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Use after free in Cast in Google Chrome prior to 147.0.7727.138 allowed an attacker on the local network segment to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: High)
CWE: CWE-416
GitHub-GHSA

HIGH
CoreDNS has TSIG authentication bypass on gRPC and QUIC transports
GHSA-vp29-5652-4fw9
pkg: github.com/coredns/coredns
eco: go
published: Apr 28, 2026
### Summary

The gRPC, QUIC, DoH, and DoH3 transports in CoreDNS incorrectly handle TSIG authentication.

For gRPC and QUIC, CoreDNS checks whether the TSIG key name exists in the config, but does not actually verify the TSIG HMAC. If the key name matches, `tsigStatus` remains nil and the tsig plugi…

CVE-2026-35579
GitHub-GHSA

HIGH
CoreDNS has TSIG authentication bypass on DoT, DoH, DoH3, DoQ, and gRPC
GHSA-qhmp-q7xh-99rh
pkg: github.com/coredns/coredns
eco: go
published: Apr 28, 2026
### Summary
CoreDNS' tsig plugin can be bypassed on non-plain-DNS transports because it trusts the transport writer's TsigStatus() instead of performing verification itself. In the attached PoC, plain DNS/TCP correctly rejects an invalid TSIG (NOTAUTH), while the same invalid-TSIG request is accepte…
CVE-2026-33190
GitHub-GHSA

HIGH
CoreDNS' transfer stanza selection uses lexicographic compare (subzone ACL bypass)
GHSA-h8mm-c463-wjq3
pkg: github.com/coredns/coredns
eco: go
published: Apr 28, 2026
### Summary
CoreDNS' transfer plugin can select the wrong ACL stanza when both a parent zone and a more-specific subzone are configured. A permissive parent-zone transfer rule can override a restrictive subzone rule (name-dependent), allowing an unauthorized client to perform AXFR/IXFR for the subzo…
CVE-2026-33489
GitHub-GHSA

HIGH
CoreDNS DoH GET oversized dns= query parameter causes pre-validation CPU and memory amplification
GHSA-63cw-r7xf-jmwr
pkg: github.com/coredns/coredns
eco: go
published: Apr 28, 2026
### Summary

CoreDNS's DNS-over-HTTPS (DoH) GET path accepts oversized `dns=` query values and performs substantial request parsing, query unescaping, base64 decoding, and message unpacking work before returning `400 Bad Request`.

A remote, unauthenticated attacker can repeatedly send oversized DoH…

CVE-2026-32936
GitHub-GHSA

HIGH
CoreDNS' DoQ worker pool does not bound stream backlog
GHSA-2wpx-qpw2-g5h5
pkg: github.com/coredns/coredns
eco: go
published: Apr 28, 2026
### Summary
CoreDNS' DNS-over-QUIC (DoQ) server can be driven into large goroutine and memory growth by a remote client that opens many QUIC streams and stalls after sending only 1 byte. Even with a small configured quic { worker_pool_size … }, CoreDNS still spawns a goroutine per accepted stream …
CVE-2026-32934
NVD

HIGH
CVE-2026-42423
CVE-2026-42423
pkg: openclaw openclaw

published: Apr 28, 2026

OpenClaw before 2026.4.8 contains an approval-timeout fallback mechanism that bypasses strictInlineEval explicit-approval requirements on gateway and node exec hosts. Attackers can exploit this timeout fallback to execute inline eval commands that should require explicit user approval, circumventing…
CWE: CWE-636
NVD

HIGH
CVE-2026-41405
CVE-2026-41405
pkg: openclaw openclaw

published: Apr 28, 2026

OpenClaw before 2026.3.31 parses MS Teams webhook request bodies before performing JWT validation, allowing unauthenticated attackers to trigger resource exhaustion. Remote attackers can send malicious Teams webhook payloads to exhaust server resources by bypassing authentication checks.
CWE: CWE-408
NVD

HIGH
CVE-2026-41636
CVE-2026-41636
pkg: apache thrift

published: Apr 28, 2026

Uncontrolled Recursion vulnerability in Apache Thrift Node.js bindings

This issue affects Apache Thrift: before 0.23.0.

Users are recommended to upgrade to version 0.23.0, which fixes the issue.

CWE: CWE-674
NVD

HIGH
CVE-2026-41602
CVE-2026-41602
pkg: apache thrift

published: Apr 28, 2026

Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation

This issue affects Apache Thrift: before 0.23.0.

Users are recommended to upgrade to version 0.23.0, which fixes the issue.

CWE: CWE-190
NVD

HIGH
CVE-2026-42800
CVE-2026-42800
pkg: linux

published: Apr 30, 2026

NULL pointer dereference vulnerability in ASR1903 in ASR Lapwing_Linux on Linux (ims_client modules) allows Pointer Manipulation.

This vulnerability is associated with program files sip/utils/src/sipuri.c.

CWE: CWE-476
NVD

HIGH
CVE-2026-7710
CVE-2026-7710
pkg: jwt

published: May 4, 2026

A security flaw has been discovered in YunaiV yudao-cloud up to 3.8.0. This affects the function doFilterInternal of the file JwtAuthenticationTokenFilter.java of the component Ruoyi-Vue-Pro. Performing a manipulation of the argument mock-token results in improper authentication. Remote exploitation…
CWE: CWE-287
NVD

HIGH
CVE-2026-7505
CVE-2026-7505
pkg: go

published: Apr 30, 2026

A flaw has been found in nextlevelbuilder GoClaw and GoClaw Lite up to 3.8.5. This affects an unknown function of the component RPC Handler. This manipulation causes improper authorization. The attack may be initiated remotely. The exploit has been published and may be used. Upgrading to version 3.9…
CWE: CWE-266, CWE-285
NVD

HIGH
CVE-2025-50328
CVE-2025-50328
pkg: windows

published: Apr 29, 2026

A vulnerability in B1 Free Archiver v1.5.86 allows files extracted from downloaded archives to bypass Windows Mark of the Web (MotW) protections. When an archive is downloaded from the internet and extracted using B1 Free Archiver, the software fails to propagate the 'Zone.Identifier' alternate data…
CWE: CWE-290
NVD

HIGH
CVE-2026-7146
CVE-2026-7146
pkg: axios

published: Apr 27, 2026

A security vulnerability has been detected in AlejandroArciniegas mcp-data-vis up to de5a51525a69822290eaee569a1ab447b490746d. Affected by this vulnerability is the function axios of the file src/servers/web-scraper/server.js of the component HTTP Request Handler. Such manipulation leads to server-s…
CWE: CWE-918
NVD

HIGH
CVE-2026-7461
CVE-2026-7461
pkg: windows

published: Apr 30, 2026

Improper neutralization of inputs used in an OS command in the FSx Windows File Server volume mounting component in Amazon ECS Agent on Windows before version 1.103.0 might allow a remote authenticated threat actor to execute shell commands with SYSTEM privileges on the underlying host via a special…
CWE: CWE-78
GitHub-GHSA

HIGH
appsmith has SQL Injection in FilterDataService via Unsafe DROP TABLE Execution
GHSA-h8cj-hpmg-636v
pkg: com.appsmith:interfaces
eco: maven
published: Apr 29, 2026
### Summary
A SQL injection vulnerability exists in `FilterDataServiceCE.java` where the `dropTable` method constructs a SQL `DROP TABLE` statement using string concatenation with the table name. If the table name is derived from user input, this allows for arbitrary SQL command execution.

### Deta…

NVD

HIGH
CVE-2026-7191
CVE-2026-7191
pkg: express

published: Apr 27, 2026

Improper use of the static-eval npm package in the open source solution qnabot-on-aws versions 7.2.4 and earlier may allow an authenticated administrator to execute arbitrary code within the fulfillment Lambda execution context by injecting a crafted conditional chaining expression via the Content D…
CWE: CWE-94
NVD

HIGH
CVE-2026-31707
CVE-2026-31707
pkg: linux

published: May 1, 2026

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: validate response sizes in ipc_validate_msg()

ipc_validate_msg() computes the expected message size for each
response type by adding (or multiplying) attacker-controlled fields
from the daemon response to a fixed struct siz…

NVD

HIGH
CVE-2026-31699
CVE-2026-31699
pkg: linux

published: May 1, 2026

In the Linux kernel, the following vulnerability has been resolved:

crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed

When retrieving the PEK CSR, don't attempt to copy the blob to userspace
if the firmware command failed. If the failure was due to an invalid
length, i.e. …

NVD

HIGH
CVE-2026-31698
CVE-2026-31698
pkg: linux

published: May 1, 2026

In the Linux kernel, the following vulnerability has been resolved:

crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed

When retrieving the PDH cert, don't attempt to copy the blobs to userspace
if the firmware command failed. If the failure was due to an invalid
length…

NVD

HIGH
CVE-2026-31697
CVE-2026-31697
pkg: linux

published: May 1, 2026

In the Linux kernel, the following vulnerability has been resolved:

crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed

When retrieving the ID for the CPU, don't attempt to copy the ID blob to
userspace if the firmware command failed. If the failure was due to an
invalid leng…

GitHub-GHSA

HIGH
Arcane Vulnerable to Unauthenticated Disclosure of Custom Compose Template Content (incl. `.env` secrets)
GHSA-cxx3-hr75-4q96
pkg: github.com/getarcaneapp/arcane/backend
eco: go
published: Apr 30, 2026
### Summary
Four `GET` endpoints under `/api/templates*` in Arcane's Huma backend are registered without any `Security` requirement, allowing any unauthenticated network client to list and read the full Compose YAML and `.env` content of every custom template stored in the instance. Because Arcane's…
CVE-2026-42461
GitHub-GHSA

HIGH
Clerk has an authorization bypass when combining organization, billing, or reverification checks
GHSA-w24r-5266-9c3c
pkg: @clerk/shared, @clerk/shared, @clerk/backend
eco: npm
published: Apr 30, 2026
### Summary

`has()`, `auth.protect()`, and related authorization predicates in `@clerk/shared`, `@clerk/nextjs`, `@clerk/backend`, and other framework SDKs can return true for certain combined authorization checks when the result should be false, allowing a gated action to proceed for a user who do…

CVE-2026-42349
GitHub-GHSA

HIGH
Hickory DNS's Record Cache Accepts AUTHORITY-Section NS from Sibling Zone via Parent-Pool Zone-Context Elevation
GHSA-83hf-93m4-rgwq
pkg: hickory-recursor, hickory-recursor
eco: rust
published: Apr 30, 2026
# Summary

The Hickory DNS project's experimental `hickory-recursor` crate's record cache (`DnsLru`) stores records from DNS responses keyed by each record's own (name, type), not by the query that triggered the response. `cache_response()` in `crates/recursor/src/lib.rs` chains `ANSWER`, `AUTHORITY…

GitHub-GHSA

HIGH
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
GHSA-rch3-82jr-f9w9
pkg: @jupyter-notebook/help-extension, notebook, jupyterlab
eco: npm
published: Apr 30, 2026
### Impact

A stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interacti…

CVE-2026-40171
GitHub-GHSA

HIGH
CKAN has Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`
GHSA-h7j7-3rx6-xvcg
pkg: ckan, ckan
eco: pip
published: Apr 29, 2026
### Impact

A vulnerability in `datastore_search_sql` allowed attackers to inject SQL in order to gain access to private resources and PostgreSQL system information.

### Patches
The issue has been patched in CKAN 2.10.10 and CKAN 2.11.5

### Workarounds
Disable the DataStore SQL search (`ckan.datas…

CVE-2026-42031
GitHub-GHSA

HIGH
n8n Vulnerable to Unauthenticated Denial of Service via MCP Client Registration
GHSA-49m9-pgww-9vq6
pkg: n8n, n8n, n8n
eco: npm
published: Apr 29, 2026
## Impact
The MCP OAuth client registration endpoint accepted unauthenticated requests and stored client data without adequate resource controls. An unauthenticated remote attacker could exhaust server memory resources by sending large registration payloads, rendering the n8n instance unavailable. T…
CVE-2026-42236
GitHub-GHSA

MEDIUM
n8n has SQL Injection in Snowflake and MySQL Nodes
GHSA-hp3c-vfpm-q4f7
pkg: n8n, n8n, n8n
eco: npm
published: Apr 29, 2026
## Impact
The fix for [GHSA-f3f2-mcxc-pwjx](https://github.com/advisories/GHSA-f3f2-mcxc-pwjx) did not cover the Snowflake node or the legacy MySQL v1 node. Both nodes construct SQL queries by directly interpolating user-controlled table names, column names, and update keys into query strings withou…
CVE-2026-42237
GitHub-GHSA

MEDIUM
n8n has Public API Variables IDOR that Allows Cross-Project Secret Disclosure
GHSA-756q-gq9h-fp22
pkg: n8n, n8n, n8n
eco: npm
published: Apr 29, 2026
## Impact
An authenticated user with a valid API key scoped to `variable:list` could read variables from projects they are not a member of by supplying an arbitrary `projectId` query parameter to the public API variables endpoint. The handler queried the variables repository directly without enforci…
CVE-2026-42227
GitHub-GHSA

MEDIUM
n8n has SQL Injection in SeaTable Node
GHSA-mp4j-h6gh-f6mp
pkg: n8n, n8n, n8n
eco: npm
published: Apr 29, 2026
## Impact
A flaw in the SeaTable node's `row:search` and `row:get` operations allowed user-controlled input to be concatenated directly into SQL query strings without escaping or parameterization. In workflows where external user input is passed via expressions into the SeaTable node's search or row…
CVE-2026-42229
NVD

MEDIUM
CVE-2026-7714
CVE-2026-7714
pkg: react

published: May 4, 2026

A flaw has been found in crocodilestick Calibre-Web-Automated up to 4.0.6. Affected by this issue is some unknown functionality of the file cps/cwa_functions.py of the component Admin Endpoint. This manipulation causes missing authentication. It is possible to initiate the attack remotely. The explo…
CWE: CWE-287, CWE-306
NVD

MEDIUM
CVE-2026-23863
CVE-2026-23863
pkg: windows

published: May 1, 2026

An attachment spoofing issue in WhatsApp for Windows prior to v2.3000.1032164386.258709 could have allowed maliciously formatted documents with embedded NUL bytes in the filename to be shown in the application as one type of file but run as an executable when opened. We have not seen evidence of exp…
CWE: CWE-158
NVD

MEDIUM
CVE-2026-1577
CVE-2026-1577
pkg: ibm db2

published: Apr 30, 2026

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic.
CWE: CWE-1284
NVD

MEDIUM
CVE-2025-36122
CVE-2025-36122
pkg: ibm db2

published: Apr 30, 2026

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of service using a specially crafted SQL query due to improper allocation of system resources.
CWE: CWE-770
NVD

MEDIUM
CVE-2026-35514
CVE-2026-35514
pkg: jwt

published: Apr 30, 2026

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, the endpoint POST /user/invited does not validate any invite token, authentication header, or session. Any unauthenticated attacker can call this endpoint …
CWE: CWE-306
GitHub-GHSA

MEDIUM
OpenTelemetry's disk retry default temp path enables local blob injection via OTLP Exporter
GHSA-4625-4j76-fww9
pkg: OpenTelemetry.Exporter.OpenTelemetryProtocol
eco: nuget
published: Apr 30, 2026
### Summary

The OTLP disk retry feature in `OpenTelemetry.Exporter.OpenTelemetryProtocol` silently fell back to `Path.GetTempPath()` when `OTEL_DOTNET_EXPERIMENTAL_OTLP_RETRY=disk` was set but `OTEL_DOTNET_EXPERIMENTAL_OTLP_DISK_RETRY_DIRECTORY_PATH` was not configured.

The exporter stored and loa…

CVE-2026-42191
GitHub-GHSA

MEDIUM
Fiber's cache middleware default key generator ignores query string, causing response mix-up across distinct query parameters
GHSA-35hp-hqmv-8qg8
pkg: github.com/gofiber/fiber/v3
eco: go
published: Apr 28, 2026
### Summary
Fiber cache middleware's default key generator uses only `c.Path()` and does not include the query string.
As a result, requests like `/?id=1` and `/?id=2` can map to the same cache key and share the same cached response.

This can cause response mix-up (cache poisoning-like behavior) fo…

CVE-2026-30246
NVD

MEDIUM
CVE-2026-41369
CVE-2026-41369
pkg: openclaw openclaw

published: Apr 28, 2026

OpenClaw before 2026.3.31 contains insufficient environment variable sanitization in host exec operations, failing to filter package, registry, Docker, compiler, and TLS override variables. Attackers can exploit this by injecting malicious environment variables to override critical system configurat…
CWE: CWE-668
NVD

MEDIUM
CVE-2026-41081
CVE-2026-41081
pkg: apache storm

published: Apr 27, 2026

Improper Handling of TLS Client Authentication Failure Leading to Anonymous Principal Assignment in Apache Storm

Versions Affected: up to 2.8.7

Description: When TLS transport is enabled in Apache Storm without requiring client certificate authentication (the default configuration), the TlsTranspo…

CWE: CWE-287
NVD

MEDIUM
CVE-2026-41174
CVE-2026-41174
pkg: traefik traefik

published: Apr 30, 2026

Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a potential vulnerability in Traefik's Kubernetes CRD provider cross-namespace isolation enforcement. When providers.kubernetesCRD.allowCrossNamespace=false, Traefik correctly rejects dire…
CWE: CWE-653, CWE-863
NVD

MEDIUM
CVE-2026-7716
CVE-2026-7716
pkg: windows

published: May 4, 2026

A vulnerability was found in code-projects Gym Management System In PHP and Windows NT 1.0. This vulnerability affects unknown code of the file /index.php. Performing a manipulation of the argument day results in sql injection. The attack can be initiated remotely. The exploit has been made public a…
CWE: CWE-74, CWE-89
NVD

MEDIUM
CVE-2026-7629
CVE-2026-7629
pkg: react

published: May 2, 2026

A flaw has been found in kleneway awesome-cursor-mpc-server up to 2.0.1. Impacted is the function runCodeReviewTool of the file src/tools/codeReview.ts of the component Ccode-Review Tool. Executing a manipulation can lead to command injection. The attack may be launched remotely. The exploit has bee…
CWE: CWE-74, CWE-77
NVD

MEDIUM
CVE-2026-7628
CVE-2026-7628
pkg: react

published: May 2, 2026

A vulnerability was detected in crazyrabbitLTC mcp-code-review-server up to 0.1.0. This issue affects the function executeRepomix of the file src/repomix.ts of the component RepoMix Command Handler. Performing a manipulation results in command injection. The attack may be initiated remotely. The exp…
CWE: CWE-74, CWE-77
NVD

MEDIUM
CVE-2026-7595
CVE-2026-7595
pkg: react

published: May 1, 2026

A flaw has been found in nextlevelbuilder ui-ux-pro-max-skill up to 2.5.0. Affected by this vulnerability is the function _format_plugins of the file .claude/skills/ui-styling/scripts/tailwind_config_gen.py of the component Tailwind Config Generator. This manipulation causes code injection. The atta…
CWE: CWE-74, CWE-94
NVD

MEDIUM
CVE-2026-7305
CVE-2026-7305
pkg: go

published: Apr 28, 2026

A weakness has been identified in Xuxueli xxl-job up to 3.3.2. The affected element is the function triggerJob of the file xxl-job-admin/src/main/java/com/xxl/job/admin/service/impl/XxlJobServiceImpl.java of the component trigger Endpoint. This manipulation of the argument addressList causes server-…
CWE: CWE-918
NVD

MEDIUM
CVE-2026-7163
CVE-2026-7163
pkg: jwt

published: Apr 30, 2026

A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multicluster Engine (MCE), allows an authenticated user with minimal namespace-scoped privileges to obtain administrative credentials for arbitrary clusters provisioned through the hu…
CWE: CWE-312
GitHub-GHSA

MEDIUM
CKAN has CSRF exemption primed by anonymous requests
GHSA-mcvf-jxcw-vj73
pkg: ckan, ckan
eco: pip
published: Apr 29, 2026
Views can be marked as exempt from CSRF protection

Access to the views via tokens or unauthenticated requests marked the endpoint as not requiring CSRF protection.

The marking was a member variable in flask-wtf.csrf.CSRFProtect(), which was stored as a module level variable in the flask_app midd…

CVE-2026-41255
NVD

MEDIUM
CVE-2026-41016
CVE-2026-41016
pkg: apache airflow

published: Apr 30, 2026

Apache Airflow's SMTP provider `SmtpHook` called Python's `smtplib.SMTP.starttls()` without an SSL context, so no certificate validation was performed on the TLS upgrade. A man-in-the-middle between the Airflow worker and the SMTP server could present a self-signed certificate, complete the STARTTLS…
CWE: CWE-295
GitHub-GHSA

MEDIUM
OpenTelemetry.Resources.Azure has an unbounded HTTP response body read
GHSA-vc24-j8c5-2vw4
pkg: OpenTelemetry.Resources.Azure
eco: nuget
published: Apr 29, 2026
### Summary

`OpenTelemetry.Resources.Azure` reads unbounded HTTP response bodies from the Azure VM remote instance metadata service endpoint into memory.

This would allow an attacker-controlled endpoint or one acting as a Man-in-the-Middle (MitM) to cause excessive memory allocation and possible p…

CVE-2026-41483
NVD

MEDIUM
CVE-2026-7669
CVE-2026-7669
pkg: python

published: May 2, 2026

A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation of the argument trust_remote_code with the input False as part of Boo…
CWE: CWE-74, CWE-94
NVD

MEDIUM
CVE-2026-7292
CVE-2026-7292
pkg: node

published: Apr 28, 2026

A security vulnerability has been detected in o2oa up to 10.0. This impacts the function syncFile of the file NodeAgent.java of the component NodeAgent. The manipulation leads to improper authorization. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitabil…
CWE: CWE-266, CWE-285
NVD

MEDIUM
CVE-2026-7113
CVE-2026-7113
pkg: react

published: Apr 27, 2026

A vulnerability was found in NousResearch hermes-agent 0.8.0. Affected by this issue is some unknown functionality of the file gateway/platforms/webhook.py of the component Webhooks Endpoint. The manipulation of the argument _INSECURE_NO_AUTH results in missing authentication. The attack can be laun…
CWE: CWE-287, CWE-306
NVD

MEDIUM
CVE-2026-7112
CVE-2026-7112
pkg: react

published: Apr 27, 2026

A vulnerability has been found in NousResearch hermes-agent 0.8.0. Affected by this vulnerability is the function _check_auth of the file gateway/platforms/api_server.py of the component API_SERVER_KEY Handler. The manipulation leads to improper authentication. The attack can be initiated remotely. …
CWE: CWE-287
NVD

MEDIUM
CVE-2026-6528
CVE-2026-6528
pkg: wireshark wireshark

published: Apr 30, 2026

TLS protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 allows denial of service
CWE: CWE-835
NVD

MEDIUM
CVE-2026-6446
CVE-2026-6446
pkg: oauth

published: May 2, 2026

The My Social Feeds – Social Feeds Embedder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to and including 1.0.4 via the 'ttp_get_accounts' AJAX action. This is due to the complete absence of authorization checks (no capability verification) and nonce veri…
CWE: CWE-522
GitHub-GHSA

MEDIUM
n8n Vulnerable to Hijacking of Unauthenticated Chat Execution
GHSA-f77h-j2v7-g6mw
pkg: n8n, n8n, n8n
eco: npm
published: Apr 29, 2026
## Impact
The `/chat` WebSocket endpoint used by the Chat Trigger node's Hosted Chat feature did not verify that an incoming connection was authorized to interact with the target execution. An unauthenticated remote attacker who could identify a valid execution ID for a workflow in a waiting state c…
CVE-2026-42228
NVD

MEDIUM
CVE-2026-37504
CVE-2026-37504
pkg: node

published: May 1, 2026

Sensitive server_token exposed via GET parameter in V2Board thru 1.7.4. In app/Http/Controllers/Server/UniProxyController.php, the server authentication token is accepted via GET parameter transmission. The token appears in URLs such as /api/v1/server/UniProxy/user?token=SECRET, causing it to be rec…
CWE: CWE-598
NVD

MEDIUM
CVE-2025-14688
CVE-2025-14688
pkg: ibm db2

published: Apr 30, 2026

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic when certain configurations exist.
CWE: CWE-1284
GitHub-GHSA

MEDIUM
OneCollector exporter reads unbounded HTTP response bodies
GHSA-55m9-299j-53c7
pkg: OpenTelemetry.Exporter.OneCollector
eco: nuget
published: Apr 29, 2026
### Summary

When exporting telemetry to a back-end/collector over HTTP using the OpenTelemetry.Exporter.OneCollector exporter, if the request results in a unsuccessful request (i.e. HTTP 4xx or 5xx), the response is read into memory with no upper-bound on the number of bytes consumed.

This could c…

CVE-2026-41484
NVD

MEDIUM
CVE-2026-22745
CVE-2026-22745
pkg: windows

published: Apr 29, 2026

Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources.

More precisely, an application can be vulnerable when all the following are true:

* the application is using Spring MVC or Spring WebFlux
* the application is serving static reso…

CWE: CWE-400
GitHub-GHSA

MEDIUM
OpenTelemetry's Zipkin remote endpoint cache could grow without bounds and increase memory pressure
GHSA-88hf-wf7h-7w4m
pkg: OpenTelemetry.Exporter.Zipkin
eco: nuget
published: Apr 28, 2026
### Summary

The Zipkin exporter remote endpoint cache accepted unbounded key growth derived from span attributes. In high-cardinality scenarios, this could increase process memory usage over time and degrade availability.

### Details

– Introduce a bounded, thread-safe LRU cache for remote endpoin…

CVE-2026-41310
NVD

MEDIUM
CVE-2026-41391
CVE-2026-41391
pkg: openclaw openclaw

published: Apr 28, 2026

OpenClaw before 2026.3.31 fails to properly sanitize PIP_INDEX_URL and UV_INDEX_URL environment variables in host execution contexts, allowing attackers to redirect Python package-index traffic. Attackers can exploit this bypass to intercept or manipulate package management operations by injecting m…
CWE: CWE-184
NVD

MEDIUM
CVE-2026-22726
CVE-2026-22726
pkg: go

published: May 1, 2026

Route Services can be leveraged to send app traffic to network destinations outside of an app's configured egress rules. As a result, a malicious developer with access to Cloudfoundry could configure a route-service that would allow it to send requests to HTTP services on internal networks reachable…
CWE: CWE-923
NVD

MEDIUM
CVE-2026-40974
CVE-2026-40974
pkg: ssl

published: Apr 28, 2026

Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to Cassandra.

Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); Ca…

CWE: CWE-295
NVD

MEDIUM
CVE-2026-40971
CVE-2026-40971
pkg: ssl

published: Apr 27, 2026

When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification when connecting to the RabbitMQ broker.

Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14) per vendor advisory.

CWE: CWE-295
NVD

MEDIUM
CVE-2026-40970
CVE-2026-40970
pkg: ssl

published: Apr 27, 2026

When configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perform hostname verification when connecting to the Elasticsearch server.

Affected: Spring Boot 4.0.0–4.0.5; upgrade to 4.0.6 or later per vendor advisory.

CWE: CWE-295
NVD

MEDIUM
CVE-2026-1858
CVE-2026-1858
pkg: tls

published: Apr 29, 2026

wget2 accepts a server certificate with incorrect Key Usage (KU) or Extended Key Usage (EKU). If the attackers compromise a certificate (with the associated private key) issued for a different purpose, they may be able to reuse it for TLS server authentication.
CWE: CWE-20
NVD

MEDIUM
CVE-2025-10539
CVE-2025-10539
pkg: tls

published: Apr 28, 2026

Due to improper TLS certificate validation in the DeskTime Time Tracking App before version 1.3.674, attackers who can position themselves in the network path between the client and the DeskTime update servers can return a malicious executable in response to an update request. This allows the attack…
CWE: CWE-295, CWE-296, CWE-494
NVD

MEDIUM
CVE-2026-40557
CVE-2026-40557
pkg: ssl

published: Apr 27, 2026

Improper Certificate Validation via Global SSL Context Downgrade in Apache Storm Prometheus Reporter

Versions Affected: from 2.6.3 to 2.8.6

Description: 

In production deployments where an administrator enables storm.daemon.metrics.reporter.plugin.prometheus.skip_tls_validation (by default it…

CWE: CWE-295
GitHub-GHSA

MEDIUM
n8n has Open Redirect in MCP OAuth Consent Flow
GHSA-f6x8-65q6-j9m9
pkg: n8n, n8n, n8n
eco: npm
published: Apr 29, 2026
## Impact
The `/mcp-oauth/register` endpoint accepted OAuth client registrations without authentication, allowing arbitrary `redirect_uri` values to be registered. When a user denies the MCP OAuth consent dialog, the `handleDeny` handler redirects the user to the registered `redirect_uri` without va…
CVE-2026-42230
NVD

MEDIUM
CVE-2026-7596
CVE-2026-7596
pkg: react

published: May 1, 2026

A vulnerability has been found in nextlevelbuilder ui-ux-pro-max-skill up to 2.5.0. Affected by this issue is the function data.get of the file .claude/skills/design-system/scripts/generate-slide.py of the component Slide Generator. Such manipulation leads to cross site scripting. The attack may be …
CWE: CWE-79, CWE-94
NVD

MEDIUM
CVE-2026-7340
CVE-2026-7340
pkg: google chrome, apple macos, linux linux_kernel

published: Apr 28, 2026

Integer overflow in ANGLE in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-472
GitHub-GHSA

MEDIUM
Weblate Doesn't Invalidate API Token on Password Change
GHSA-6j8j-4qp3-36p2
pkg: weblate
eco: pip
published: Apr 30, 2026
### Impact
When a user changes their password, browser sessions are correctly invalidated via `cycle_session_keys()`, but DRF API tokens (`wlu_*` prefix) stored in `authtoken_token` are not revoked.

### Patches
* https://github.com/WeblateOrg/weblate/pull/19057

### Resources
Weblate thanks Sang Yu…

CVE-2026-41519
GitHub-GHSA

MEDIUM
CKAN has Unauthenticated Authorization Bypass in `datastore_search_sql`
GHSA-cg4x-64p3-x59h
pkg: ckan, ckan
eco: pip
published: Apr 30, 2026
### Impact

A vulnerability in `datastore_search_sql` allowed attackers to bypass authorization in order to gain access to private resources and PostgreSQL system information

### Patches
The issue has been patched in CKAN 2.10.10 and CKAN 2.11.5

### Workarounds
Disable the DataStore SQL search (`c…

CVE-2026-42032
GitHub-GHSA

MEDIUM
Weblate Vulnerable to Authenticated SSRF via Project Backup Import bypassing validate_repo_url
GHSA-cwcx-382v-8m9g
pkg: weblate
eco: pip
published: Apr 30, 2026
### Impact
An authenticated user with `project.add` permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose `components/<name>.json` contains an attacker-chosen `repo` URL pointing at a **private address** (e.g. …
CVE-2026-41654
GitHub-GHSA

MEDIUM
Claude SDK for TypeScript has Insecure Default File Permissions in Local Filesystem Memory Tool
GHSA-p7fg-763f-g4gf
pkg: @anthropic-ai/sdk
eco: npm
published: Apr 29, 2026
The `BetaLocalFilesystemMemoryTool` in the Anthropic TypeScript SDK created memory files and directories using the Node.js default modes (`0o666` for files, `0o777` for directories), leaving them world-readable on systems with a standard umask and world-writable in environments with a permissive uma…
CVE-2026-41686
GitHub-GHSA

MEDIUM
netfoil's optional seccomp sandboxing was not applied
GHSA-vjgj-42f6-7997
pkg: github.com/tinfoil-factory/netfoil
eco: go
published: Apr 29, 2026
### Summary
The optional flag `–filter-system-calls` was not applied even if specified.

### Details
This is a defense in depth feature to apply additional seccomp filters after the binary has started. The example config also sandboxes the binary with systemd.

### Impact
Reduced sandboxing of the …

GitHub-GHSA

MEDIUM
Netfoil has incorrect allowlist enforcement
GHSA-84g5-x8j3-7235
pkg: github.com/tinfoil-factory/netfoil
eco: go
published: Apr 29, 2026
### Summary
Rules could be bypassed by changing the first character: `example.com` could be be bypassed by e.g. `fxample.com`.

### Details
Off-by-one error in the suffixtrie implementation.

### Impact
The domain filter could be bypassed. Please note that DNS filtering alone is not enough to block …

GitHub-GHSA

MEDIUM
OpenClaw: Webchat audio embedding could read local files without local-root containment
GHSA-gfg9-5357-hv4c
pkg: openclaw
eco: npm
published: Apr 29, 2026
## Impact

OpenClaw deployments before `2026.4.15` could embed host-local audio files into webchat responses without applying the local media root containment check used by other media-serving paths.

If an attacker could influence an agent or tool-produced `ReplyPayload.mediaUrl`, the webchat audio…

GitHub-GHSA

MEDIUM
OpenClaw: Owner-enforced commands could accept wildcard channel senders as command owners
GHSA-c28g-vh7m-fm7v
pkg: openclaw
eco: npm
published: Apr 29, 2026
## Impact

OpenClaw deployments before `2026.4.21` could treat a non-owner sender as authorized for owner-enforced slash commands when all of the following were true:

– a channel plugin declared `commands.enforceOwnerForCommands: true`;
– the channel accepted wildcard inbound senders with `allowFro…

GitHub-GHSA

MEDIUM
n8n has SQL Injection in Oracle Database Node via Limit Field
GHSA-r6jc-mpqw-m755
pkg: n8n, n8n, n8n
eco: npm
published: Apr 29, 2026
## Impact
A flaw in the Oracle Database node's select operation allowed user-controlled input passed into the `Limit` field via expressions to be interpolated directly into the SQL query without sanitization or parameterization. In workflows where external input is passed into the `Limit` field (e.g…
CVE-2026-42233
GitHub-GHSA

MEDIUM
CKAN has no certificate validation on STMP connection
GHSA-mpfm-fpgx-647q
pkg: ckan, ckan
eco: pip
published: Apr 29, 2026
### Impact
Configured SMTP server may be spoofed with any certificate (e.g. self-signed), leaving credentials and all emails sent open to MITM attacks.

### Patches
The vulnerability has been patched in CKAN 2.10.10 and CKAN 2.11.5

CVE-2026-41132
GitHub-GHSA

MEDIUM
beets has a Cross-site Scripting vulnerability
GHSA-3gxm-wfjx-m847
pkg: beets
eco: pip
published: Apr 29, 2026
During code logic analyis, an area that may lead to unintended behavior under specific conditions was discovered.

## Overview
– Verified Version: `80cd21554124da07d17a4f962c7d770a4f70d0f2`
– Vulnerability Type: Stored XSS
– Affected Location: `beetsplug/web/templates/index.html:42`
– Trigger Scena…

CVE-2026-42052


Vulnerability Digest — April 27, 2026 · 50 Critical · 6 Exploited






Vulnerability Digest — Monday, April 27, 2026


Security Report

Monday, April 27, 2026  ·  Last 7 days  ·  Min severity: MEDIUM
Total Findings
292
Critical
50
High
113
Actively Exploited
6
CISA-KEV6
NVD124
GitHub-GHSA162
Findings sorted by severity
CISA-KEV

CRITICAL
D-Link DIR-823X Command Injection Vulnerability
CVE-2025-29635
pkg: D-Link DIR-823X

published: Apr 24, 2026

D-Link DIR-823X contains a command injection vulnerability that allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function. The impacted product could be end-of-life (EoL) and/or end-of-service (Eo…
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
Samsung MagicINFO 9 Server Path Traversal Vulnerability
CVE-2024-7399
pkg: Samsung MagicINFO 9 Server

published: Apr 24, 2026

Samsung MagicINFO 9 Server contains a path traversal vulnerability that could allow an attacker to write arbitrary files as system authority.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
SimpleHelp Path Traversal Vulnerability
CVE-2024-57728
pkg: SimpleHelp SimpleHelp

published: Apr 24, 2026

SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
SimpleHelp Missing Authorization Vulnerability
CVE-2024-57726
pkg: SimpleHelp SimpleHelp

published: Apr 24, 2026

SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
Marimo Remote Code Execution Vulnerability
CVE-2026-39987
pkg: Marimo Marimo

published: Apr 23, 2026

Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system commands.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
Microsoft Defender Insufficient Granularity of Access Control Vulnerability
CVE-2026-33825
pkg: Microsoft Defender

published: Apr 22, 2026

Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
GitHub-GHSA

CRITICAL
Gemini CLI: Remote Code Execution via workspace trust and tool allowlisting bypasses
GHSA-wpqr-6v78-jr5g
pkg: @google/gemini-cli, @google/gemini-cli, google-github-actions/run-gemini-cli
eco: npm
published: Apr 24, 2026
# Summary

Gemini CLI (`@google/gemini-cli`) and the `run-gemini-cli` GitHub Action are being updated to harden workspace trust and tool allowlisting, in particular when used in untrusted environments like GitHub Actions. This update introduces a breaking change to how non-interactive (headless) env…

NVD

CRITICAL
CVE-2026-41679
CVE-2026-41679
pkg: react

published: Apr 23, 2026

Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 2026.416.0, an unauthenticated attacker can achieve full remote code execution on any network-accessible Paperclip instance running in `authenticated` mode with default configuration.…
CWE: CWE-287, CWE-862, CWE-1188
GitHub-GHSA

CRITICAL
openvpn-auth-oauth2 returns FUNC_SUCCESS on client-deny, allowing unauthenticated VPN access
GHSA-246w-jgmq-88fg
pkg: github.com/jkroepke/openvpn-auth-oauth2
eco: go
published: Apr 22, 2026
# Summary

When `openvpn-auth-oauth2` is deployed in the **experimental plugin mode** (shared library loaded by OpenVPN via the `plugin` directive), clients that do not support WebAuth/SSO (e.g., the `openvpn` CLI on Linux) are incorrectly admitted to the VPN despite being denied by the authenticati…

CVE-2026-41070
GitHub-GHSA

CRITICAL
Spinnaker: RCE via expression parsing due to unrestricted context handling
GHSA-69rw-45wj-g4v6
pkg: io.spinnaker.echo:echo-pipelinetriggers, io.spinnaker.echo:echo-pipelinetriggers, io.spinnaker.echo:echo-pipelinetriggers
eco: maven
published: Apr 21, 2026
### Impact
Echo like some other services, uses SPeL (Spring Expression Language) to process information – specifically around expected artifacts. Unlike orca, it was NOT restricting that context to a set of trusted classes, but allowing FULL JVM access. This enables a user to use arbitrary java cl…
CVE-2026-32613
GitHub-GHSA

CRITICAL
Spinnaker: RCE when using gitrepo artifact types due to improper sanitization of user input on branch and paths
GHSA-x3j7-7pgj-h87r
pkg: io.spinnaker.clouddriver:clouddriver-artifacts-gitrepo
eco: maven
published: Apr 21, 2026
### Impact
A bad actor can execute arbitrary commands very simply on the clouddriver pods. This can expose credentials, remove files, or inject resources easily.

### Workarounds
Disable the gitrepo artifact types.

CVE-2026-32604
NVD

CRITICAL
CVE-2026-40906
CVE-2026-40906
pkg: express

published: Apr 21, 2026

Electric is a Postgres sync engine. From 1.1.12 to before 1.5.0, the order_by parameter in the ElectricSQL /v1/shape API is vulnerable to error-based SQL injection, allowing any authenticated user to read, write, and destroy the full contents of the underlying PostgreSQL database through crafted ORD…
CWE: CWE-89
NVD

CRITICAL
CVE-2026-32613
CVE-2026-32613
pkg: linuxfoundation spinnaker

published: Apr 20, 2026

Spinnaker is an open source, multi-cloud continuous delivery platform. Echo like some other services, uses SPeL (Spring Expression Language) to process information – specifically around expected artifacts. In versions prior to 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2, unlike orca, it was NOT restr…
CWE: CWE-94
GitHub-GHSA

CRITICAL
electurm has Command Injection via runLinux funtion
GHSA-8×35-hph8-37hq
pkg: electerm
eco: npm
published: Apr 24, 2026
### Impact
_What kind of vulnerability is it? Who is impacted?_

**Command Injection vulnerabilities in electerm:**

A command injection vulnerability exists in `github.com/elcterm/electerm/npm/install.js:130`. The `runLinux()` function appends attacker-controlled remote version strings directly int…

CVE-2026-41501
NVD

CRITICAL
CVE-2026-6911
CVE-2026-6911
pkg: jwt

published: Apr 24, 2026

Missing JWT signature verification in AWS Ops Wheel allows unauthenticated attackers to forge JWT tokens and gain unintended administrative access to the application, including the ability to read, modify, and delete all application data across tenants and manage Cognito user accounts within the dep…
CWE: CWE-347
GitHub-GHSA

CRITICAL
go-zserio has Unbounded Memory Allocation for All Platforms
GHSA-xhj4-g6w8-2xjw
pkg: github.com/woven-planet/go-zserio
eco: go
published: Apr 24, 2026
### Impact

When deserializing arrays, strings or bytes (blob) types zserio first reads the size of the variable, and then allocates sufficient memory to load data. Since the size is always trusted this can be abused by creating a data file with a large size value, causing the zserio runtime to allo…

GitHub-GHSA

CRITICAL
Dgraph: Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars
GHSA-vvf7-6rmr-m29q
pkg: github.com/dgraph-io/dgraph/v25, github.com/dgraph-io/dgraph/v24, github.com/dgraph-io/dgraph
eco: go
published: Apr 24, 2026
### Summary
Dgraph `v25.3.2` still exposes the process command line through the unauthenticated `/debug/vars` endpoint on Alpha. Because the admin token is commonly supplied via the `–security "token=…"` startup flag, an unauthenticated attacker can retrieve that token and replay it in the `X-Dgr…
CVE-2026-41492
GitHub-GHSA

CRITICAL
Pipecat: Remote Code Execution by Pickle Deserialization Through LivekitFrameSerializer
GHSA-c2jg-5cp7-6wc7
pkg: pipecat-ai
eco: pip
published: Apr 23, 2026
Remote Code Execution via Unsafe Deserialization in Pipecat's LivekitFrameSerializer

### Summary

A critical vulnerability exists in Pipecat's `LivekitFrameSerializer` – an **optional, non-default, undocumented** frame serializer class (now deprecated) intended for LiveKit integration. The class'…

CVE-2025-62373
NVD

CRITICAL
CVE-2026-41268
CVE-2026-41268
pkg: flowiseai flowise

published: Apr 23, 2026

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise is vulnerable to a critical unauthenticated remote command execution (RCE) vulnerability. It can be exploited via a parameter override bypass using the FILE-STORAGE:: keyword combined wit…
CWE: CWE-20
NVD

CRITICAL
CVE-2026-41265
CVE-2026-41265
pkg: flowiseai flowise

published: Apr 23, 2026

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific flaw exists within the run method of the Airtable_Agents class. The issue results from the lack of proper sandboxing when evaluating an LLM generated python script. Using prompt inje…
CWE: CWE-77
NVD

CRITICAL
CVE-2026-41264
CVE-2026-41264
pkg: flowiseai flowise

published: Apr 23, 2026

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific flaw exists within the run method of the CSV_Agents class. The issue results from the lack of proper sandboxing when evaluating an LLM generated python script. An attacker can levera…
CWE: CWE-184
NVD

CRITICAL
CVE-2025-62373
CVE-2025-62373
pkg: python

published: Apr 23, 2026

Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. Versions 0.0.41 through 0.0.93 have a vulnerability in `LivekitFrameSerializer` – an optional, non-default, undocumented frame serializer class (now deprecated) intended for LiveKit integr…
CWE: CWE-502
NVD

CRITICAL
CVE-2026-29198
CVE-2026-29198
pkg: oauth

published: Apr 23, 2026

In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability can lead to account takeover of the first user with a generated token when an OAuth app is configured.
CWE: CWE-89
GitHub-GHSA

CRITICAL
Evolver: Command Injection via `execSync` in `_extractLLM()` function allows Remote Code Execution
GHSA-j5w5-568x-rq53
pkg: @evomap/evolver
eco: npm
published: Apr 22, 2026
### Summary
A command injection vulnerability in the `_extractLLM()` function allows attackers to execute arbitrary shell commands on the server. The function constructs a curl command using string concatenation and passes it to `execSync()` without proper sanitization, enabling remote code executio…
GitHub-GHSA

CRITICAL
NornicDB has Improper Network Binding in its Bolt Server, allowing unauthorized remote access
GHSA-2hp7-65r3-wv54
pkg: github.com/orneryd/nornicdb
eco: go
published: Apr 22, 2026
## Summary

The `–address` CLI flag (and `NORNICDB_ADDRESS` / `server.host` config key) is plumbed through to the HTTP server correctly but **never reaches the Bolt server config**. The Bolt listener therefore always binds to the wildcard address (all interfaces), regardless of what the user config…

NVD

CRITICAL
CVE-2026-33519
CVE-2026-33519
pkg: kubernetes

published: Apr 21, 2026

An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentials.
CWE: CWE-266
NVD

CRITICAL
CVE-2026-33518
CVE-2026-33518
pkg: linux

published: Apr 21, 2026

An incorrect privilege assignment vulnerability exists in Esri Portal for ArcGIS 11.5 in Windows and Linux that allows highly privileged users to create developer credentials that may grant more privileges than expected.
CWE: CWE-266
NVD

CRITICAL
CVE-2026-40884
CVE-2026-40884
pkg: go

published: Apr 21, 2026

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs contains an SFTP authentication bypass when the documented empty-username basic-auth syntax is used. If the server is started with -b ':pass' together with -sftp, goshs accepts that configuration but does not install any SFTP pa…
CWE: CWE-306
NVD

CRITICAL
CVE-2026-32311
CVE-2026-32311
pkg: reconurge flowsint

published: Apr 20, 2026

Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Flowsint allows a user to create investigations, which are used to manage sketches and analyses. Sketches have controllable graphs, which are comprised of nodes and relat…
CWE: CWE-78
NVD

CRITICAL
CVE-2026-6920
CVE-2026-6920
pkg: google chrome, google android, linux linux_kernel

published: Apr 23, 2026

Out of bounds read in GPU in Google Chrome on Android prior to 147.0.7727.117 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-125
NVD

CRITICAL
CVE-2026-6919
CVE-2026-6919
pkg: google chrome, google android, linux linux_kernel

published: Apr 23, 2026

Use after free in DevTools in Google Chrome prior to 147.0.7727.117 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
GitHub-GHSA

CRITICAL
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
GHSA-2wvh-87g2-89hr
pkg: openc3
eco: rubygems
published: Apr 23, 2026
**Vulnerability Type: Execution with Unnecessary Privileges
Attack type: Authenticated remote
Impact: Data disclosure/manipulation, privilege escalation
Affected components: The following docker images:
• Openc3inc/openc3-COSMOS-script-runner-api**

The Script Runner widget allows users to execute…

GitHub-GHSA

CRITICAL
OpenC3 COSMOS has SQL Injection in QuestDB Time-Series Database
GHSA-v529-vhwc-wfc5
pkg: openc3
eco: rubygems
published: Apr 23, 2026
**Vulnerability Type: CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Attack type: Authenticated remote
Impact: Telemetry data disclosure and deletion
Affected components: openc3-tsdb (QuestDB)**

A SQL injection vulnerability exists in the Time-Series Da…

GitHub-GHSA

CRITICAL
nimiq-block has skip block quorum bypass via out-of-range BitSet indices & u16 truncation
GHSA-6973-8887-87ff
pkg: nimiq-block
eco: rust
published: Apr 22, 2026
### Impact
`SkipBlockProof::verify` computes its quorum check using `BitSet.len()`, then iterates `BitSet` indices and casts each `usize` index to `u16` (`slot as u16`) for slot lookup. If an attacker can get a `SkipBlockProof` verified where `MultiSignature.signers` contains out-of-range indices sp…
CVE-2026-33471
GitHub-GHSA

CRITICAL
Note Mark: OIDC-registered users authenticated by submitting password "null"
GHSA-pxf8-6wqm-r6hh
pkg: github.com/enchant97/note-mark/backend
eco: go
published: Apr 25, 2026
## Summary

`IsPasswordMatch` in `backend/db/models.go` falls back to a hard-coded `bcrypt("null")` placeholder whenever a user has no stored password. OIDC-registered users are created with an empty password, so anyone who submits `password: "null"` to the internal login endpoint receives a valid s…

CVE-2026-41571
NVD

CRITICAL
CVE-2026-41428
CVE-2026-41428
pkg: express

published: Apr 24, 2026

Budibase is an open-source low-code platform. Prior to 3.35.4, the authenticated middleware uses unanchored regular expressions to match public (no-auth) endpoint patterns against ctx.request.url. Since ctx.request.url in Koa includes the query string, an attacker can access any protected endpoint b…
CWE: CWE-287
GitHub-GHSA

CRITICAL
Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in NQuad Lang Field
GHSA-x92x-px7w-4gx4
pkg: github.com/dgraph-io/dgraph/v25, github.com/dgraph-io/dgraph/v24, github.com/dgraph-io/dgraph
eco: go
published: Apr 24, 2026
## 1. Executive Summary

A vulnerability has been found in Dgraph that gives an unauthenticated attacker full read access to every piece of data in the database. This affects Dgraph's default configuration where ACL is not enabled.

The attack requires two HTTP POSTs to port 8080. The first sets up …

CVE-2026-41328
GitHub-GHSA

CRITICAL
Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in Upsert Condition Field
GHSA-mrxx-39g5-ph77
pkg: github.com/dgraph-io/dgraph/v25, github.com/dgraph-io/dgraph/v24, github.com/dgraph-io/dgraph
eco: go
published: Apr 24, 2026
## 1. Executive Summary

A vulnerability has been found in Dgraph that gives an unauthenticated attacker full read access to every piece of data in the database. This affects Dgraph's default configuration where ACL is not enabled.

The attack is a single HTTP POST to `/mutate?commitNow=true` contai…

CVE-2026-41327
GitHub-GHSA

CRITICAL
Microsoft Security Advisory CVE-2026-40372 – ASP.NET Core Elevation of Privilege
GHSA-9mv3-2cwr-p262
pkg: Microsoft.AspNetCore.DataProtection
eco: nuget
published: Apr 23, 2026
## Executive Summary:

A bug in `Microsoft.AspNetCore.DataProtection` 10.0.0-10.0.6 NuGet packages can give an attacker the opportunity to execute an Elevation of Privilege attack by forging authentication cookies, and also allows some protected payloads to be decrypted.

If an attacker used forged…

CVE-2026-40372
NVD

CRITICAL
CVE-2026-40575
CVE-2026-40575
pkg: nginx

published: Apr 22, 2026

OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 may trust a client-supplied `X-Forwarded-Uri` header when `–reverse-proxy` is enabled and `–skip-auth-regex` or `–skip-auth-route` is configured. An attacker can spoof this header so…
CWE: CWE-290
NVD

CRITICAL
CVE-2026-40903
CVE-2026-40903
pkg: go

published: Apr 21, 2026

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs has an ArtiPACKED vulnerability. ArtiPACKED can lead to leakage of the GITHUB_TOKEN through workflow artifacts, even though the token is not present in the repository source code. This vulnerability is fixed in 2.0.0-beta.6.
CWE: CWE-829
NVD

CRITICAL
CVE-2026-40887
CVE-2026-40887
pkg: express

published: Apr 21, 2026

Vendure is an open-source headless commerce platform. Starting in version 1.7.4 and prior to versions 2.3.4, 3.5.7, and 3.6.2, an unauthenticated SQL injection vulnerability exists in the Vendure Shop API. A user-controlled query string parameter is interpolated directly into a raw SQL expression wi…
CWE: CWE-89
NVD

CRITICAL
CVE-2026-33432
CVE-2026-33432
pkg: roxy-wi roxy-wi

published: Apr 20, 2026

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions up to and including 8.2.8.2, when LDAP authentication is enabled, Roxy-WI constructs an LDAP search filter by directly concatenating the user-supplied login username into the filter string without esca…
CWE: CWE-287
GitHub-GHSA

CRITICAL
Apache Kafka does not validate JWT tokens in its OAUTHBEARER authentication implementation
GHSA-28jg-cgg7-j4wc
pkg: org.apache.kafka:kafka-clients
eco: maven
published: Apr 20, 2026
A security vulnerability has been identified in Apache Kafka. By default, the broker property `sasl.oauthbearer.jwt.validator.class` is set to `org.apache.kafka.common.security.oauthbearer.DefaultJwtValidator`. It accepts any JWT token without validating its signature, issuer, or audience. An atta…
CVE-2026-33557
NVD

CRITICAL
CVE-2026-33557
CVE-2026-33557
pkg: apache kafka

published: Apr 20, 2026

A possible security vulnerability has been identified in Apache Kafka.

By default, the broker property `sasl.oauthbearer.jwt.validator.class` is set to `org.apache.kafka.common.security.oauthbearer.DefaultJwtValidator`. It accepts any JWT token without validating its signature, issuer, or audienc…

CWE: CWE-1285
GitHub-GHSA

CRITICAL
LiteLLM has SQL Injection in Proxy API key verification
GHSA-r75f-5x8p-qvmc
pkg: litellm
eco: pip
published: Apr 24, 2026
### Impact

A database query used during proxy API key checks mixed the caller-supplied key value into the query text instead of passing it as a separate parameter. An unauthenticated attacker could send a specially crafted `Authorization` header to any LLM API route (for example `POST /chat/complet…

GitHub-GHSA

CRITICAL
RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution
GHSA-jfwf-28xr-xw6q
pkg: github.com/rclone/rclone
eco: go
published: Apr 22, 2026
### Summary
The RC endpoint `operations/fsinfo` is exposed without `AuthRequired: true` and accepts attacker-controlled `fs` input. Because `rc.GetFs(…)` supports inline backend definitions, an unauthenticated attacker can instantiate an attacker-controlled backend on demand. For the WebDAV backen…
CVE-2026-41179
GitHub-GHSA

CRITICAL
Rclone: Unauthenticated options/set allows runtime auth bypass, leading to sensitive operations and command execution
GHSA-25qr-6mpr-f7qx
pkg: github.com/rclone/rclone
eco: go
published: Apr 22, 2026
### Summary
The RC endpoint `options/set` is exposed without `AuthRequired: true`, but it can mutate global runtime configuration, including the RC option block itself. An unauthenticated attacker can set `rc.NoAuth=true`, which disables the authorization gate for many RC methods registered with `Au…
CVE-2026-41176
GitHub-GHSA

CRITICAL
Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
GHSA-3hjv-c53m-58jj
pkg: flowise, flowise-components
eco: npm
published: Apr 21, 2026
## Abstract

Trend Micro's Zero Day Initiative has identified a vulnerability affecting FlowiseAI Flowise.

## Vulnerability Details

– **Version tested:** 3.0.13
– **Installer file:** https://github.com/FlowiseAI/Flowise
– **Platform tested:** Ubuntu 25.10

## Analysis

This vulnerability allows re…

CVE-2026-41264
GitHub-GHSA

CRITICAL
Brillig: Heap corruption in foreign call results with nested tuple arrays
GHSA-jj7c-x25r-r8r3
pkg: brillig
eco: rust
published: Apr 21, 2026
## Description

Noir programs can invoke external functions through foreign calls. When compiling to Brillig bytecode, the SSA instructions are processed block-by-block in `BrilligBlock::compile_block()`. When the compiler encounters an `Instruction::Call` with a `Value::ForeignFunction` target, it …

CVE-2026-41197
NVD

HIGH
CVE-2026-7082
CVE-2026-7082
pkg: go

published: Apr 27, 2026

A flaw has been found in Tenda F456 1.0.0.5. Affected by this vulnerability is the function formWrlExtraSet of the file /goform/WrlExtraSet of the component httpd. Executing a manipulation of the argument Go can lead to buffer overflow. The attack can be executed remotely. The exploit has been publi…
CWE: CWE-119, CWE-120
NVD

HIGH
CVE-2026-7035
CVE-2026-7035
pkg: go

published: Apr 26, 2026

A vulnerability was determined in Tenda FH1202 1.2.0.14. This affects the function fromWrlclientSet of the file /goform/WrlclientSet of the component httpd. Executing a manipulation of the argument Go can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been …
CWE: CWE-119, CWE-121
NVD

HIGH
CVE-2026-7034
CVE-2026-7034
pkg: go

published: Apr 26, 2026

A vulnerability was found in Tenda FH1202 1.2.0.14(408). Affected by this issue is the function WrlExtraSet of the file /goform/WrlExtraSet of the component httpd. Performing a manipulation of the argument Go results in stack-based buffer overflow. The attack may be initiated remotely. The exploit h…
CWE: CWE-119, CWE-121
GitHub-GHSA

HIGH
GitPython has Command Injection via Git options bypass
GHSA-rpm5-65cw-6hj4
pkg: GitPython
eco: pip
published: Apr 25, 2026
### Summary
GitPython blocks dangerous Git options such as `–upload-pack` and `–receive-pack` by default, but the equivalent Python kwargs `upload_pack` and `receive_pack` bypass that check. If an application passes attacker-controlled kwargs into `Repo.clone_from()`, `Remote.fetch()`, `Remote.pul…
NVD

HIGH
CVE-2026-41421
CVE-2026-41421
pkg: windows

published: Apr 24, 2026

SiYuan is an open-source personal knowledge management system. Prior to 3.6.5, SiYuan desktop renders notification messages as raw HTML inside an Electron renderer. The notification route POST /api/notification/pushMsg accepts a user-controlled msg value, forwards it through the backend broadcast la…
CWE: CWE-78, CWE-79
NVD

HIGH
CVE-2026-40897
CVE-2026-40897
pkg: express

published: Apr 24, 2026

Math.js is an extensive math library for JavaScript and Node.js. From 13.1.1 to before 15.2.0, a vulnerability allowed executing arbitrary JavaScript via the expression parser of mathjs. You can be affected when you have an application where users can evaluate arbitrary expressions using the mathjs …
CWE: CWE-915
GitHub-GHSA

HIGH
Avo: Broken Access Control Through Unauthorized Execution of Arbitrary Action Classes Across Resources
GHSA-qc5p-3mg5-9fh8
pkg: avo
eco: rubygems
published: Apr 24, 2026
### Summary

A critical Broken Access Control vulnerability was identified in the `ActionsController` of the Avo framework (v3.x). Due to insecure action lookup logic, an authenticated user can execute any Action class (descendants of `Avo::BaseAction`) on any resource, even if the action is not reg…

NVD

HIGH
CVE-2026-41352
CVE-2026-41352
pkg: node

published: Apr 23, 2026

OpenClaw before 2026.3.31 contains a remote code execution vulnerability where a device-paired node can bypass the node scope gate authentication mechanism. Attackers with device pairing credentials can execute arbitrary node commands on the host system without proper node pairing validation.
CWE: CWE-862
GitHub-GHSA

HIGH
OpenLearnX has Critical Remote Code Execution Through Python Sandbox Escape via Code Execution Environment
GHSA-8h25-q488-4hxw
pkg: openlearnx
eco: npm
published: Apr 23, 2026
## Overview

A critical Remote Code Execution (RCE) vulnerability was identified in the OpenLearnX code execution environment, allowing sandbox escape and arbitrary command execution. The issue has been fixed.

CVE-2026-41900
GitHub-GHSA

HIGH
Actual has Privilege Escalation via 'change-password' Endpoint on OpenID-Migrated Servers
GHSA-prp4-2f49-fcgp
pkg: @actual-app/sync-server
eco: npm
published: Apr 23, 2026
### Summary

Any authenticated user (including `BASIC` role) can escalate to `ADMIN` on servers migrated from password authentication to OpenID Connect. Three weaknesses combine: `POST /account/change-password` has no authorization check, allowing any session to overwrite the password hash; the inac…

CVE-2026-33318
NVD

HIGH
CVE-2026-41138
CVE-2026-41138
pkg: flowiseai flowise

published: Apr 23, 2026

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, there is a remote code execution vulnerability in AirtableAgent.ts caused by lack of input verification when using Pandas. The user’s input is directly applied to the question parameter within …
CWE: CWE-94
NVD

HIGH
CVE-2026-41208
CVE-2026-41208
pkg: react

published: Apr 23, 2026

Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Versions of @paperclipai/server prior to 2026.416.0 contain a privilege escalation vulnerability that allows an attacker with an Agent API key to execute arbitrary OS commands on the Paperclip server …
CWE: CWE-78
NVD

HIGH
CVE-2026-6859
CVE-2026-6859
pkg: python

published: Apr 22, 2026

A flaw was found in InstructLab. The `linux_train.py` script hardcodes `trust_remote_code=True` when loading models from HuggingFace. This allows a remote attacker to achieve arbitrary Python code execution by convincing a user to run `ilab train/download/generate` with a specially crafted malicious…
CWE: CWE-829
NVD

HIGH
CVE-2026-41133
CVE-2026-41133
pkg: python

published: Apr 22, 2026

pyLoad is a free and open-source download manager written in Python. Versions up to and including 0.5.0b3.dev97 cache `role` and `permission` in the session at login and continues to authorize requests using these cached values, even after an admin changes the user's role/permissions in the database…
CWE: CWE-613
NVD

HIGH
CVE-2026-40876
CVE-2026-40876
pkg: goshs goshs

published: Apr 21, 2026

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs contains an SFTP root escape caused by prefix-based path validation. An authenticated SFTP user can read from and write to filesystem paths outside the configured SFTP root, which breaks the intended jail boundary and can expose…
CWE: CWE-22
NVD

HIGH
CVE-2026-40611
CVE-2026-40611
pkg: go

published: Apr 21, 2026

Let's Encrypt client and ACME library written in Go (Lego). Prior to 4.34.0, the webroot HTTP-01 challenge provider in lego is vulnerable to arbitrary file write and deletion via path traversal. A malicious ACME server can supply a crafted challenge token containing ../ sequences, causing lego to wr…
CWE: CWE-22
GitHub-GHSA

HIGH
Neko has a Self-service Privilege Escalation for Authenticated Users
GHSA-2gw9-c2r2-f5qf
pkg: github.com/m1k1o/neko/server, github.com/m1k1o/neko/server
eco: go
published: Apr 21, 2026
### Impact

Any authenticated user can immediately obtain full administrative control of the entire Neko instance (member management, room settings, broadcast control, session termination, etc.). This results in a complete compromise of the instance.

### Patches

The vulnerability has been patched …

CVE-2026-39386
NVD

HIGH
CVE-2026-39386
CVE-2026-39386
pkg: m1k1o neko

published: Apr 21, 2026

Neko is a a self-hosted virtual browser that runs in Docker and uses WebRTC In versions 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1, any authenticated user can immediately obtain full administrative control of the entire Neko instance (member management, room settings, broadcast control, session te…
CWE: CWE-20, CWE-269, CWE-284, CWE-639, CWE-862
GitHub-GHSA

HIGH
zrok: WebDAV drive backend follows symlinks outside DriveRoot, enabling host filesystem read/write
GHSA-74m3-9qvm-rp9h
pkg: github.com/openziti/zrok, github.com/openziti/zrok/v2
eco: go
published: Apr 25, 2026
**Summary**
The zrok WebDAV drive backend (davServer.Dir) restricts path traversal through lexical normalization but does not prevent symlink following. When a symbolic link inside the shared DriveRoot points to a location outside that root, remote WebDAV consumers can read files and—on shares wit…
GitHub-GHSA

HIGH
i18next-http-middleware: HTTP response splitting and DoS via unsanitised Content-Language header
GHSA-c3h8-g69v-pjrg
pkg: i18next-http-middleware
eco: npm
published: Apr 22, 2026
### Summary

Versions of `i18next-http-middleware` prior to 3.9.3 wrote user-controlled language values into the `Content-Language` response header after passing them through `utils.escape()`, which is an HTML-entity encoder that does not strip carriage return, line feed, or other control characters…

CVE-2026-41683
GitHub-GHSA

HIGH
i18next-http-middleware: Prototype pollution and path traversal via user-controlled language and namespace parameters
GHSA-5fgg-jcpf-8jjw
pkg: i18next-http-middleware
eco: npm
published: Apr 22, 2026
### Summary

Versions of `i18next-http-middleware` prior to 3.9.3 pass user-controlled `lng` and `ns` parameters to two internal paths that use them in ways that enable prototype pollution and, depending on the configured backend, path traversal or SSRF.

The vulnerable entry points are unauthentica…

NVD

HIGH
CVE-2026-40931
CVE-2026-40931
pkg: node-modules compressing

published: Apr 21, 2026

Compressing is a compressing and uncompressing lib for node. Prior to 2.1.1 and 1.10.5, the patch for CVE-2026-24884 relies on a purely logical string validation within the isPathWithinParent utility. This check verifies if a resolved path string starts with the destination directory string but fail…
CWE: CWE-59
GitHub-GHSA

HIGH
OpenClaude: Sandbox Bypass via Early-Exit Logic Flaw Allows Path Traversal
GHSA-m6rx-7pvw-2f73
pkg: @gitlawb/openclaude
eco: npm
published: Apr 21, 2026
A logic flaw exists in `bashToolHasPermission()` inside `src/tools/BashTool/bashPermissions.ts`. When the sandbox auto-allow feature is active and no explicit deny rule is configured, the function returns an `allow` result immediately — before the path constraint filter (`checkPathConstraints`) is…
CVE-2026-35570
NVD

HIGH
CVE-2026-6921
CVE-2026-6921
pkg: google chrome, google android, linux linux_kernel

published: Apr 23, 2026

Race in GPU in Google Chrome on Windows prior to 147.0.7727.117 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Medium)
CWE: CWE-362
GitHub-GHSA

HIGH
RustFS: Missing admin authorization on notification target endpoints allows unauthenticated configuration of event webhooks
GHSA-pfcq-4gjr-6gjm
pkg: rustfs
eco: rust
published: Apr 22, 2026
# Missing Admin Auth on Notification Target Endpoints in RustFS

### Finding Summary

All four notification target admin API endpoints in `rustfs/src/admin/handlers/event.rs` use a `check_permissions` helper that validates authentication only (access key + session token), without performing any adm…

CVE-2026-40937
GitHub-GHSA

HIGH
Daptin: SQL injection via unvalidated goqu.L() calls in aggregate API
GHSA-rw2c-8rfq-gwfv
pkg: github.com/daptin/daptin
eco: go
published: Apr 22, 2026
## Summary

The `/aggregate/:typename` endpoint accepted `column` and `group` query parameters that were passed verbatim to `goqu.L()` — a raw SQL literal expression builder — without any validation. This bypassed all parameterization and allowed authenticated users with any valid session to inj…

CVE-2026-41422
NVD

HIGH
CVE-2026-41273
CVE-2026-41273
pkg: flowiseai flowise

published: Apr 23, 2026

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise contains an authentication bypass vulnerability that allows an unauthenticated attacker to obtain OAuth 2.0 access tokens associated with a public chatflow. By accessing a public chatflow…
CWE: CWE-306
GitHub-GHSA

HIGH
i18next-fs-backend: Path traversal via unsanitised lng/ns allows arbitrary file read/overwrite
GHSA-8847-338w-5hcj
pkg: i18next-fs-backend
eco: npm
published: Apr 22, 2026
### Summary

Versions of `i18next-fs-backend` prior to 2.6.4 interpolate the caller-supplied `lng` and `ns` values directly into the configured `loadPath` and `addPath` templates with no path-component validation and no sanitisation. When an application exposes the resolved language code to user-con…

NVD

HIGH
CVE-2026-41059
CVE-2026-41059
pkg: oauth

published: Apr 22, 2026

OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 have a configuration-dependent authentication bypass. Deployments are affected when all of the following are true: Use of `skip_auth_routes` or the legacy `skip_auth_regex`; use of patt…
CWE: CWE-288
GitHub-GHSA

HIGH
GitPython: Unsafe option check validates multi_options before shlex.split transformation
GHSA-x2qx-6953-8485
pkg: GitPython
eco: pip
published: Apr 25, 2026
### Summary

`_clone()` validates `multi_options` as the original list, then executes `shlex.split(" ".join(multi_options))`. A string like `"–branch main –config core.hooksPath=/x"` passes validation (starts with `–branch`), but after split becomes `["–branch", "main", "–config", "core.hooksPa…

GitHub-GHSA

HIGH
Budibase auth session cookies are set with httpOnly:false — any XSS can lead to full account takeover
GHSA-4f9j-vr4p-642r
pkg: @budibase/backend-core
eco: npm
published: Apr 24, 2026
### Summary

The `budibase:auth` cookie containing the JWT session token is set with `httpOnly: false` at `packages/backend-core/src/utils/utils.ts:218`. JavaScript can read this cookie via `document.cookie`. Given that Budibase has had XSS vulnerabilities (GHSA-gp5x-2v54-v2q5 — stored XSS via uns…

GitHub-GHSA

HIGH
ERB has an @_init deserialization guard bypass via def_module / def_method / def_class
GHSA-q339-8rmv-2mhv
pkg: erb, erb, erb
eco: rubygems
published: Apr 24, 2026
## Summary

Ruby 2.7.0 (before ERB 2.2.0 was published on rubygems.org) introduced an `@_init` instance variable guard in `ERB#result` and `ERB#run` to prevent code execution when an ERB object is reconstructed via `Marshal.load` (deserialization). However, three other public methods that also evalu…

CVE-2026-41316
GitHub-GHSA

HIGH
Contour has Lua code injection via Cookie Path Rewrite Policy
GHSA-x4mj-7f9g-29h4
pkg: github.com/projectcontour/contour, github.com/projectcontour/contour, github.com/projectcontour/contour
eco: go
published: Apr 24, 2026
### Impact

Contour's [Cookie Rewriting](https://projectcontour.io/docs/1.33/config/cookie-rewriting/) feature is vulnerable to Lua code injection. An attacker with RBAC permissions to create or modify `HTTPProxy` resources can craft a malicious value in the following fields that results in arbitrar…

CVE-2026-41246
NVD

HIGH
CVE-2026-41246
CVE-2026-41246
pkg: kubernetes

published: Apr 23, 2026

Contour is a Kubernetes ingress controller using Envoy proxy. From v1.19.0 to before v1.33.4, v1.32.5, and v1.31.6, Contour's Cookie Rewriting feature is vulnerable to Lua code injection. An attacker with RBAC permissions to create or modify HTTPProxy resources can craft a malicious value in spec.ro…
CWE: CWE-94
GitHub-GHSA

HIGH
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
GHSA-wgx6-g857-jjf7
pkg: openc3, openc3
eco: rubygems
published: Apr 22, 2026
### Summary
The OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to g…
GitHub-GHSA

HIGH
Evolver: Path Traversal via `–out` flag in `fetch` command allows Arbitrary File Write
GHSA-r466-rxw4-3j9j
pkg: @evomap/evolver
eco: npm
published: Apr 22, 2026
### Summary
A path traversal vulnerability in the skill download (`fetch`) command allows attackers to write files to arbitrary locations on the filesystem. The `–out=` flag accepts user-provided paths without validation, enabling directory traversal attacks that can overwrite critical system files…
NVD

HIGH
CVE-2026-34403
CVE-2026-34403
pkg: nginxui nginx_ui

published: Apr 20, 2026

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.5, all WebSocket endpoints in nginx-ui use a gorilla/websocket Upgrader with CheckOrigin unconditionally returning true, allowing Cross-Site WebSocket Hijacking (CSWSH). Combined with the fact that authentication tokens …
CWE: CWE-1385
NVD

HIGH
CVE-2026-33031
CVE-2026-33031
pkg: nginxui nginx_ui

published: Apr 20, 2026

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, a user who was disabled by an administrator can use previously issued API tokens for up to the token lifetime. In practice, disabling a compromised account does not actually terminate that user’s access, so an attac…
CWE: CWE-284, CWE-863
GitHub-GHSA

HIGH
Cillium exposes sensitive information included in the cilium-bugtool debug archive
GHSA-gj49-89wh-h4gj
pkg: github.com/cilium/cilium, github.com/cilium/cilium, github.com/cilium/cilium
eco: go
published: Apr 25, 2026
### Impact
The output of `cilium-bugtool` can contain sensitive data when the tool is run against Cilium deployments with WireGuard encryption enabled.

Users of [WireGuard Transparent Encryption](https://docs.cilium.io/en/stable/security/network/encryption-wireguard/) are affected.
The sensitive da…

CVE-2026-41520
NVD

HIGH
CVE-2026-32679
CVE-2026-32679
pkg: windows

published: Apr 23, 2026

The installers of LiveOn Meet Client for Windows (Downloader5Installer.exe and Downloader5InstallerForAdmin.exe) and the installers of Canon Network Camera Plugin (CanonNWCamPlugin.exe and CanonNWCamPluginForAdmin.exe) insecurely load Dynamic Link Libraries (DLLs). If a malicious DLL is placed at th…
CWE: CWE-427
GitHub-GHSA

HIGH
Kyverno Controller Denial of Service via forEach Mutation Panic
GHSA-fpjq-c37h-cqcv
pkg: github.com/kyverno/kyverno, github.com/kyverno/kyverno
eco: go
published: Apr 24, 2026
### Summary

An unchecked type assertion in the `forEach` mutation handler allows any user with permission to create a `Policy` or `ClusterPolicy` to crash the cluster-wide background controller into a persistent CrashLoopBackOff. The same bug also causes the admission controller to drop connections…

CVE-2026-41485
NVD

HIGH
CVE-2026-41068
CVE-2026-41068
pkg: kubernetes

published: Apr 24, 2026

Kyverno is a policy engine designed for cloud native platform engineering teams. The patch for CVE-2026-22039 fixed cross-namespace privilege escalation in Kyverno's `apiCall` context by validating the `URLPath` field. However, the ConfigMap context loader has the identical vulnerability — the `co…
CWE: CWE-863
GitHub-GHSA

HIGH
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller
GHSA-5jv8-h7qh-rf5p
pkg: github.com/argoproj/argo-workflows/v4, github.com/argoproj/argo-workflows/v3, github.com/argoproj/argo-workflows/v3
eco: go
published: Apr 23, 2026
### Summary

An unchecked array index in the pod informer's `podGCFromPod()` function causes a controller-wide panic when a workflow pod carries a malformed `workflows.argoproj.io/pod-gc-strategy` annotation. Because the panic occurs inside an informer goroutine (outside the controller's `recover()`…

CVE-2026-40886
NVD

HIGH
CVE-2026-40886
CVE-2026-40886
pkg: kubernetes

published: Apr 23, 2026

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 3.6.5 to 4.0.4, an unchecked array index in the pod informer's podGCFromPod() function causes a controller-wide panic when a workflow pod carries a malformed workflows.argoproj.io/po…
CWE: CWE-129
GitHub-GHSA

HIGH
Tekton Pipelines: Git resolver API mode leaks system-configured API token to user-controlled serverURL
GHSA-wjxp-xrpv-xpff
pkg: github.com/tektoncd/pipeline
eco: go
published: Apr 21, 2026
### Summary

The Tekton Pipelines git resolver in API mode sends the system-configured Git API token to a user-controlled `serverURL` when the user omits the `token` parameter. A tenant with TaskRun or PipelineRun create permission can exfiltrate the shared API token (GitHub PAT, GitLab token, etc.)…

CVE-2026-40161
NVD

HIGH
CVE-2026-34428
CVE-2026-34428
pkg: curl

published: Apr 20, 2026

Vvveb prior to 1.0.8.1 contains a server-side request forgery vulnerability in the oEmbedProxy action of the editor/editor module where the url parameter is passed directly to getUrl() via curl without scheme or destination validation. Authenticated backend users can supply file:// URLs to read arb…
CWE: CWE-918
NVD

HIGH
CVE-2026-31952
CVE-2026-31952
pkg: windows

published: Apr 24, 2026

Xibo is an open source digital signage platform with a web content management system and Windows display player software. Versions 1.7 through 4.4.0 have an SQL injection vulnerability in the API routes inside the CMS responsible for Filtering DataSets. This allows an authenticated user to to obtain…
CWE: CWE-89, CWE-184
NVD

HIGH
CVE-2026-41066
CVE-2026-41066
pkg: python

published: Apr 24, 2026

lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.0, using either of the two parsers in the default configuration (with resolve_entities=True) allows untrusted XML input to read local files. Setting the resolve_entities option explicitly to resolve_entities='internal…
CWE: CWE-611
GitHub-GHSA

HIGH
Zserio Runtime: Integer Overflow in BitStreamReader and Unbounded Memory Allocation in Deserialization
GHSA-cwq5-8pvq-j65j
pkg: io.github.ndsev:zserio-runtime
eco: maven
published: Apr 24, 2026
## Summary

### Unbounded Memory Allocation (all platforms)

A crafted payload as small as 4-5 bytes can force memory allocations of up to 16 GB, crashing any process with an OOM error (Denial of Service).

**Affected code (C++):**
– `cpp/runtime/src/zserio/Array.h` (line 1029) — `m_rawArray.reser…

CVE-2026-33524
GitHub-GHSA

HIGH
rustls-webpki: Denial of service via panic on malformed CRL BIT STRING
GHSA-82j2-j2ch-gfr8
pkg: rustls-webpki, rustls-webpki
eco: rust
published: Apr 24, 2026
### Summary

`bit_string_flags()` in `src/der.rs` panics with an index-out-of-bounds when given a BIT STRING whose content is exactly `[0x00]` (one byte: zero padding bits, zero data bytes). This is reachable through the public API `BorrowedCertRevocationList::from_der()` via the `issuingDistributio…

GitHub-GHSA

HIGH
russh has pre-auth DoS via unbounded allocation in its keyboard-interactive auth handler
GHSA-f5v4-2wr6-hqmg
pkg: russh
eco: rust
published: Apr 24, 2026
## Summary

A pre-authentication denial-of-service vulnerability exists in the server's keyboard-interactive authentication handler. A malicious client can crash any russh-based server that implements keyboard-interactive auth (e.g., for 2FA/TOTP) with a single malformed packet, requiring no credent…

GitHub-GHSA

HIGH
liquidjs has a Denial of Service via circular block reference in layout
GHSA-4rc3-7j7w-m548
pkg: liquidjs
eco: npm
published: Apr 24, 2026
### Summary

A circular block reference in `{% layout %}` / `{% block %}` causes an infinite recursive loop, consuming all available memory (~4GB) and crashing the Node.js process with `FATAL ERROR: JavaScript heap out of memory`. This allows any user who can submit a Liquid template to perform a De…

CVE-2026-41311
NVD

HIGH
CVE-2026-41324
CVE-2026-41324
pkg: node

published: Apr 24, 2026

basic-ftp is an FTP client for Node.js. Versions prior to 5.3.0 are vulnerable to denial of service through unbounded memory growth while processing directory listings from a remote FTP server. A malicious or compromised server can send an extremely large or never-ending listing response to `Client.…
CWE: CWE-400, CWE-770
NVD

HIGH
CVE-2026-41278
CVE-2026-41278
pkg: flowiseai flowise

published: Apr 23, 2026

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GET /api/v1/public-chatflows/:id endpoint returns the full chatflow object without sanitization for public chatflows. Docker validation revealed this is worse than initially assessed: the san…
CWE: CWE-200
NVD

HIGH
CVE-2026-41040
CVE-2026-41040
pkg: express

published: Apr 23, 2026

GROWI provided by GROWI, Inc. is vulnerable to a regular expression denial of service (ReDoS) via a crafted input string.
CWE: CWE-1333
GitHub-GHSA

HIGH
locize Client SDK: Cross-origin DOM XSS & Handler Hijack Through Missing e.origin Validation in InContext Editor
GHSA-w937-fg2h-xhq2
pkg: locize
eco: npm
published: Apr 22, 2026
### Summary

Versions of the `locize` client SDK (the browser module that wires up the locize InContext translation editor) prior to 4.0.21 register a `window.addEventListener("message", …)` handler that dispatches to registered internal handlers (`editKey`, `commitKey`, `commitKeys`, `isLocizeEna…

NVD

HIGH
CVE-2026-34065
CVE-2026-34065
pkg: nimiq nimiq_proof-of-stake

published: Apr 22, 2026

nimiq-primitives contains primitives (e.g., block, account, transaction) to be used in Nimiq's Rust implementation. Prior to version 1.3.0, an untrusted p2p peer can cause a node to panic by announcing an election macro block whose `validators` set contains an invalid compressed BLS voting key. Hash…
CWE: CWE-252, CWE-755
NVD

HIGH
CVE-2026-34063
CVE-2026-34063
pkg: nimiq nimiq_proof-of-stake

published: Apr 22, 2026

Nimiq's network-libp2p is a Nimiq network implementation based on libp2p. Prior to version 1.3.0, `network-libp2p` discovery uses a libp2p `ConnectionHandler` state machine. the handler assumes there is at most one inbound and one outbound discovery substream per connection. if a remote peer opens/n…
CWE: CWE-617
GitHub-GHSA

HIGH
@nocobase/database has SQL Injection via String Concatenation through Recursive Eager Loading
GHSA-4948-f92q-f432
pkg: @nocobase/database
eco: npm
published: Apr 22, 2026
## Summary

The `queryParentSQL()` function in the core database package constructs a recursive CTE query by joining `nodeIds` with string concatenation instead of using parameterized queries. The `nodeIds` array contains primary key values read from database rows. An attacker who can create a recor…

CVE-2026-41640
GitHub-GHSA

HIGH
free5GC PCF: Memory Leak via CORS Middleware Registration in HTTP Handler Leads to Denial of Service
GHSA-98cp-84m9-q3qp
pkg: github.com/free5gc/pcf
eco: go
published: Apr 22, 2026
## Summary

A memory leak vulnerability in the free5GC PCF (Policy Control Function) allows any unauthenticated attacker with network access to the PCF SBI interface to cause uncontrolled memory growth by sending repeated HTTP requests to the OAM endpoint. The root cause is a `router.Use()` call ins…

CVE-2026-41135
GitHub-GHSA

HIGH
nimiq-primitives: Node crash due to missing interlink validation in election macro block proposals
GHSA-7c4j-2m43-2mgh
pkg: nimiq-primitives
eco: rust
published: Apr 22, 2026
### Impact
An untrusted p2p peer can cause a node to panic by announcing an election macro block whose `validators` set contains an invalid compressed BLS voting key.

Hashing an election macro header hashes `validators` and reaches `Validators::voting_keys()`, which calls `validator.voting_key.unco…

CVE-2026-34065
NVD

HIGH
CVE-2026-40895
CVE-2026-40895
pkg: follow-redirects_project follow-redirects

published: Apr 21, 2026

follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. Prior to 1.16.0, when an HTTP request follows a cross-domain redirect (301/302/307/308), follow-redirects only strips authorization, proxy-authorization, and cookie hea…
CWE: CWE-200
GitHub-GHSA

HIGH
lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files
GHSA-vfmq-68hx-4jfw
pkg: lxml
eco: pip
published: Apr 21, 2026
### Impact
Using either of the two parsers in the default configuration (with `resolve_entities=True`) allows untrusted XML input to read local files.

### Patches
lxml 6.1.0 changes the default to `resolve_entities='internal'`, thus disallowing local file access by default.

### Workarounds
Setting…

CVE-2026-41066
GitHub-GHSA

HIGH
Tekton Pipeline: Git Resolver Unsanitized Revision Parameter Enables git Argument Injection Leading to RCE
GHSA-94jr-7pqp-xhcq
pkg: github.com/tektoncd/pipeline
eco: go
published: Apr 21, 2026
## Summary

The git resolver's `revision` parameter is passed directly as a positional argument to `git fetch` without any validation that it does not begin with a `-` character. Because git parses flags from mixed positional arguments, an attacker can inject arbitrary `git fetch` flags such as `–u…

CVE-2026-40938
NVD

HIGH
CVE-2026-40890
CVE-2026-40890
pkg: go

published: Apr 21, 2026

The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Processing a malformed input containing a < character that is not followed by a > character anywhere in the remaining text with a SmartypantsRenderer will lead to Out of Bounds read or a pan…
CWE: CWE-125
NVD

HIGH
CVE-2026-40879
CVE-2026-40879
pkg: nestjs nest

published: Apr 21, 2026

Nest is a framework for building scalable Node.js server-side applications. Prior to 11.1.19, when an attacker sends many small, valid JSON messages in one TCP frame, handleData() recurses once per message; the buffer shrinks each call. maxBufferSize is never reached; call stack overflows instead. A…
CWE: CWE-674
NVD

HIGH
CVE-2026-40869
CVE-2026-40869
pkg: decidim decidim

published: Apr 21, 2026

Decidim is a participatory democracy framework. Starting in version 0.19.0 and prior to versions 0.30.5 and 0.31.1, a vulnerability allows any registered and authenticated user to accept or reject any amendments. The impact is on any users who have created proposals where the amendments feature is e…
CWE: CWE-266
GitHub-GHSA

HIGH
Signal K Server has an Unauthenticated Regular Expression Denial of Service (ReDoS) via WebSocket Subscription Paths
GHSA-7gcj-phff-2884
pkg: signalk-server
eco: npm
published: Apr 21, 2026
## Summary
The SignalK server is vulnerable to an unauthenticated Regular Expression Denial of Service (ReDoS) attack within its WebSocket subscription handling logic. By injecting unescaped regex metacharacters into the `context` parameter of a stream subscription, an attacker can force the server'…
CVE-2026-39320
GitHub-GHSA

HIGH
LMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading
GHSA-6w67-hwm5-92mq
pkg: lmdeploy
eco: pip
published: Apr 21, 2026
## Summary

A Server-Side Request Forgery (SSRF) vulnerability exists in LMDeploy's vision-language module. The `load_image()` function in `lmdeploy/vl/utils.py` fetches arbitrary URLs without validating internal/private IP addresses, allowing attackers to access cloud metadata services, internal ne…

CVE-2026-33626
NVD

HIGH
CVE-2026-39320
CVE-2026-39320
pkg: signalk signal_k_server

published: Apr 21, 2026

Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.25.0 are vulnerable to an unauthenticated Regular Expression Denial of Service (ReDoS) attack within the WebSocket subscription handling logic. By injecting unescaped regex metacharacters into the `cont…
CWE: CWE-400, CWE-1333
NVD

HIGH
CVE-2026-42035
CVE-2026-42035
pkg: axios

published: Apr 24, 2026

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, a prototype pollution gadget exists in the Axios HTTP adapter (lib/adapters/http.js) that allows an attacker to inject arbitrary HTTP headers into outgoing requests. The vulnerability exploits duck-type che…
CWE: CWE-113, CWE-1321
NVD

HIGH
CVE-2026-42033
CVE-2026-42033
pkg: axios

published: Apr 24, 2026

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when Object.prototype has been polluted by any co-dependency with keys that axios reads without a hasOwnProperty guard, an attacker can (a) silently intercept and modify every JSON response before the appli…
CWE: CWE-1321
NVD

HIGH
CVE-2026-7060
CVE-2026-7060
pkg: react

published: Apr 26, 2026

A vulnerability was determined in liyupi yu-picture up to a053632c41340152bf75b66b3c543d129123d8ec. This impacts the function PageRequest of the file yu-picture-backend/src/main/java/com/yupi/yupicturebackend/service/impl/PictureServiceImpl.java of the component MyBatis-Plus. Executing a manipulatio…
CWE: CWE-74, CWE-89
NVD

HIGH
CVE-2025-14362
CVE-2025-14362
pkg: fortra goanywhere_managed_file_transfer

published: Apr 21, 2026

The login limit is not enforced on the SFTP service of Fortra's GoAnywhere MFT prior to 7.10.0 if the Web User attempting to be logged in to is configured to log in with an SSH Key, making the SSH key vulnerable to being guessed via Brute Force.
CWE: CWE-307
NVD

HIGH
CVE-2026-42043
CVE-2026-42043
pkg: axios

published: Apr 24, 2026

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axios request can use any address in the 127.0.0.0/8 range (other than 127.0.0.1) to completely bypass the NO_PROXY protection. This vulnerability is due t…
CWE: CWE-183, CWE-441, CWE-918
NVD

HIGH
CVE-2026-5464
CVE-2026-5464
pkg: go

published: Apr 23, 2026

The ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation and activation in all versions up to, and including, 9.1.2. This is due to the reports page exposing the 'onboarding_key' transient to…
CWE: CWE-862
GitHub-GHSA

HIGH
@nocobase/plugin-collection-sql: SQL Validation Bypass Through Missing `checkSQL` Call
GHSA-wrwh-c28m-9jjh
pkg: @nocobase/plugin-collection-sql
eco: npm
published: Apr 22, 2026
## Summary

The `checkSQL()` validation function that blocks dangerous SQL keywords (e.g., `pg_read_file`, `LOAD_FILE`, `dblink`) is applied on the `collections:create` and `sqlCollection:execute` endpoints but is entirely missing on the `sqlCollection:update` endpoint. An attacker with collection m…

CVE-2026-41641
NVD

HIGH
CVE-2026-40871
CVE-2026-40871
pkg: docker

published: Apr 21, 2026

mailcow: dockerized is an open source groupware/email suite based on docker. Versions prior to 2026-03b have a second-order SQL injection vulnerability in the quarantine_category field via the Mailcow API. The /api/v1/add/mailbox endpoint stores quarantine_category without validation or sanitization…
CWE: CWE-20, CWE-89, CWE-116, CWE-564
GitHub-GHSA

HIGH
New API: Stripe Webhook Signature Bypass via Empty Secret Enables Unlimited Quota Fraud
GHSA-xff3-5c9p-2mr4
pkg: github.com/QuantumNous/new-api
eco: go
published: Apr 24, 2026
## Summary

A critical vulnerability exists in the Stripe webhook handler that allows an **unauthenticated attacker to forge webhook events** and credit arbitrary quota to their account without making any payment. The vulnerability stems from three compounding flaws:

1. The Stripe webhook endpoint …

CVE-2026-41432
GitHub-GHSA

HIGH
Apktool: Path Traversal to Arbitrary File Write
GHSA-m8mh-x359-vm8m
pkg: org.apktool:apktool-lib
eco: maven
published: Apr 23, 2026
A path traversal vulnerability in `brut/androlib/res/decoder/ResFileDecoder.java` allows a maliciously crafted APK to write arbitrary files to the filesystem during standard decoding (`apktool d`). This is a security regression introduced in commit [e10a045](https://github.com/iBotPeaches/Apktool/co…
CVE-2026-39973
NVD

HIGH
CVE-2026-41270
CVE-2026-41270
pkg: flowiseai flowise

published: Apr 23, 2026

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Server-Side Request Forgery (SSRF) protection bypass vulnerability exists in the Custom Function feature. While the application implements SSRF protection via HTTP_DENY_LIST for axios and node-…
CWE: CWE-284, CWE-918
NVD

HIGH
CVE-2026-41269
CVE-2026-41269
pkg: flowiseai flowise

published: Apr 23, 2026

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the Chatflow configuration file upload settings can be modified to allow the application/javascript MIME type. This lets an attacker upload .js files even though the frontend doesn’t normally a…
CWE: CWE-434
NVD

HIGH
CVE-2026-39973
CVE-2026-39973
pkg: apktool apktool

published: Apr 21, 2026

Apktool is a tool for reverse engineering Android APK files. In versions 3.0.0 and 3.0.1, a path traversal vulnerability in `brut/androlib/res/decoder/ResFileDecoder.java` allows a maliciously crafted APK to write arbitrary files to the filesystem during standard decoding (`apktool d`). This is a se…
CWE: CWE-22
GitHub-GHSA

HIGH
OpenRemote has Improper Access Control via updateUserRealmRoles function
GHSA-49vv-25qx-mg44
pkg: io.openremote:openremote-manager
eco: maven
published: Apr 22, 2026
### Summary
A user who has `write:admin` in one Keycloak realm can call the Manager API to update **Keycloak realm roles** for users in **another** realm, including **`master`**. The handler uses the `{realm}` path segment when talking to the identity provider but does not check that the caller may …
CVE-2026-41166
GitHub-GHSA

HIGH
Heimdall has an authorization bypass via path normalization mismatch
GHSA-3q34-rx83-r6mq
pkg: github.com/dadrus/heimdall
eco: go
published: Apr 25, 2026
### Summary

Heimdall performs rule matching on the raw (non-normalized) request path, while downstream components may normalize dot-segments according to [RFC 3986, Section 6.2.2.3](https://www.rfc-editor.org/rfc/rfc3986#section-6.2.2.3). This discrepancy can result in heimdall authorizing a reques…

GitHub-GHSA

HIGH
Heimdall: Case-sensitive host matching may lead to policy bypass
GHSA-72h4-mxfc-jx37
pkg: github.com/dadrus/heimdall
eco: go
published: Apr 25, 2026
### Summary

Heimdall performs host matching in a case-sensitive manner, while HTTP hostnames are case-insensitive. This discrepancy can result in heimdall failing to match a rule for a request host that differs only in letter casing, potentially causing the request to be classified differently than…

GitHub-GHSA

HIGH
Heimdall: Case-sensitive handling of URL-encoded slashes may lead to inconsistent path interpretation
GHSA-43jv-5j4x-qv67
pkg: github.com/dadrus/heimdall
eco: go
published: Apr 25, 2026
### Summary

Heimdall handles URL-encoded slashes (`%2F`) in a case-sensitive manner, while percent-encoding is defined to be case-insensitive. As a result, the lowercase equivalent (`%2f`) is not recognized and therefore not processed as expected when `allow_encoded_slashes` is set to `off` (the de…

GitHub-GHSA

HIGH
LiteLLM: Authenticated command execution via MCP stdio test endpoints
GHSA-v4p8-mg3p-g94g
pkg: litellm
eco: pip
published: Apr 25, 2026
### Impact

Two endpoints used to preview an MCP server before saving it — `POST /mcp-rest/test/connection` and `POST /mcp-rest/test/tools/list` — accepted a full server configuration in the request body, including the `command`, `args`, and `env` fields used by the stdio transport. When called …

GitHub-GHSA

HIGH
Traefik has an StripPrefixRegex Middleware Authorization Bypass via Path/RawPath Desync
GHSA-6jwx-7vp4-9847
pkg: github.com/traefik/traefik/v3, github.com/traefik/traefik/v3, github.com/traefik/traefik/v2
eco: go
published: Apr 24, 2026
## Summary

There is a high severity authentication bypass vulnerability in Traefik's `StripPrefixRegex` middleware when used in combination with `ForwardAuth`, `BasicAuth`, or `DigestAuth`.

The middleware matches the regex against the decoded URL path but uses the resulting byte length to slice th…

CVE-2026-40912
GitHub-GHSA

HIGH
k8sGPT has Prompt Injection through its k8sGPT-Operator
GHSA-rp7v-4384-hfrp
pkg: github.com/k8sgpt-ai/k8sgpt
eco: go
published: Apr 24, 2026
### Summary
In the auto-remediation pipeline, `object_to_execution.go` was deserializing the AI-generated YAML directly into a Deployment object, but there was lack of validation from the original Deployment object.

### Details
This issue was fixed after coordination with Alex Jones.

### PoC
To mi…

GitHub-GHSA

HIGH
Claude Code: Trust Dialog Bypass via Git Worktree Spoofing Allows Arbitrary Code Execution
GHSA-q5hj-mxqh-vv77
pkg: @anthropic-ai/claude-code
eco: npm
published: Apr 24, 2026
Claude Code used the git worktree `commondir` file when determining folder trust but did not validate its contents. By crafting a repository with a `commondir` file pointing to a path the victim had previously trusted, an attacker could bypass the trust dialog and immediately execute malicious hooks…
CVE-2026-40068
GitHub-GHSA

HIGH
Traefik: Pre-authentication decision bypass due to forwarded alias spoofing
GHSA-5m6w-wvh7-57vm
pkg: github.com/traefik/traefik/v3, github.com/traefik/traefik/v3, github.com/traefik/traefik/v2
eco: go
published: Apr 24, 2026
## Summary

There is a high severity authentication bypass vulnerability in Traefik's `ForwardAuth` and snippet-based authentication middleware. Traefik's forwarded-header sanitization logic targets only canonical header names (e.g., `X-Forwarded-Proto`) and does not strip or normalize alias variant…

CVE-2026-39858
GitHub-GHSA

HIGH
Traefik's ForwardAuth trustForwardHeader=false allows spoofed X-Forwarded-Prefix to bypass authentication
GHSA-6384-m2mw-rf54
pkg: github.com/traefik/traefik/v3, github.com/traefik/traefik/v3, github.com/traefik/traefik/v2
eco: go
published: Apr 24, 2026
## Summary

There is a high-severity authentication bypass vulnerability in Traefik's `ForwardAuth` middleware when `trustForwardHeader=false` is configured and Traefik is deployed behind a trusted upstream proxy.

While `X-Forwarded-*` headers (such as `X-Forwarded-For`, `X-Forwarded-Host`, and `X-…

CVE-2026-35051
GitHub-GHSA

HIGH
Ray: Remote Code Execution via Parquet Arrow Extension Type Deserialization
GHSA-mw35-8rx3-xf9r
pkg: ray
eco: pip
published: Apr 24, 2026
# Remote Code Execution via Parquet Arrow Extension Type Deserialization

## Summary

Ray Data registers custom Arrow extension types (`ray.data.arrow_tensor`, `ray.data.arrow_tensor_v2`, `ray.data.arrow_variable_shaped_tensor`) globally in PyArrow. When PyArrow reads a Parquet file containing one o…

CVE-2026-41486
GitHub-GHSA

HIGH
LiteLLM: Server-Side Template Injection in /prompts/test endpoint
GHSA-xqmj-j6mv-4862
pkg: litellm
eco: pip
published: Apr 24, 2026
### Impact
The `POST /prompts/test` endpoint accepted user-supplied prompt templates and rendered them without sandboxing. A crafted template could run arbitrary code inside the LiteLLM Proxy process.

The endpoint only checks that the caller presents a valid proxy API key, so any authenticated user…

GitHub-GHSA

HIGH
rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
GHSA-pqf5-4pqq-29f5
pkg: openssl
eco: rust
published: Apr 22, 2026
`Deriver::derive` (and `PkeyCtxRef::derive`) sets `len = buf.len()` and passes it as the in/out length to `EVP_PKEY_derive`, relying on OpenSSL to honor it. On OpenSSL 1.1.x, X25519, X448, DH and HKDF-extract ignore the incoming `*keylen`, unconditionally writing the full shared secret (32/56/prime…
CVE-2026-41676
GitHub-GHSA

HIGH
rust-openssl has incorrect bounds assertion in aes key wrap
GHSA-8c75-8mhr-p7r9
pkg: openssl
eco: rust
published: Apr 22, 2026
### Summary
“aes::unwrap_key()“ has an incorrect bounds assertion on the out buffer size, which can lead to out-of-bounds write.

### Details
“aes::unwrap_key()“ contains an incorrect assertion: it checks that `out.len() + 8 <= in_.len()`, but this condition is reversed. The intended invariant i…

CVE-2026-41678
GitHub-GHSA

HIGH
rust-openssl: rustMdCtxRef::digest_final() writes past caller buffer with no length check
GHSA-ghm9-cr32-g9qj
pkg: openssl
eco: rust
published: Apr 22, 2026
`EVP_DigestFinal()` always writes `EVP_MD_CTX_size(ctx)` to the `out` buffer. If `out` is smaller than that, `MdCtxRef::digest_final()` writes past its end, usually corrupting the stack. This is reachable from safe Rust.
CVE-2026-41681
GitHub-GHSA

HIGH
rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer
GHSA-hppc-g8h3-xhp3
pkg: openssl
eco: rust
published: Apr 22, 2026
The FFI trampolines behind `SslContextBuilder::set_psk_client_callback`, `set_psk_server_callback`, `set_cookie_generate_cb`, and `set_stateless_cookie_generate_cb` forwarded the user closure's returned usize directly to OpenSSL without checking it against the `&mut [u8]` that was handed to the clo…
GitHub-GHSA

HIGH
SiYuan: Path Traversal via Double URL Encoding in `/export/` Endpoint (Incomplete Fix Bypass for CVE-2026-30869)
GHSA-hjh7-r5w8-5872
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: Apr 22, 2026
### Summary
The fix for CVE-2026-30869 in SiYuan v3.5.10 only added a denylist check (`IsSensitivePath`) but did not address the root cause — a redundant `url.PathUnescape()` call in `serveExport()`. An authenticated attacker can use double URL encoding (`%252e%252e`) to traverse directories and r…
GitHub-GHSA

HIGH
MCPHub has Path Traversal via Malicious MCPB Manifest Name
GHSA-p3h2-2j4p-p83g
pkg: @samanhappy/mcphub
eco: npm
published: Apr 22, 2026
The MCPB file upload handler extracts a ZIP file and reads `manifest.json` from it. The `name` field from the manifest is concatenated directly into the file path (line 107) without any sanitization or path traversal character validation. An attacker can craft a malicious MCPB file with `manifest.na…
GitHub-GHSA

HIGH
xmldom: Uncontrolled recursion in XML serialization leads to DoS
GHSA-2v35-w6hq-6mfw
pkg: @xmldom/xmldom, @xmldom/xmldom, xmldom
eco: npm
published: Apr 22, 2026
## Summary

Seven recursive traversals in `lib/dom.js` operate without a depth limit. A sufficiently deeply
nested DOM tree causes a `RangeError: Maximum call stack size exceeded`, crashing the application.

**Reported operations:**
– `Node.prototype.normalize()` — reported by @praveen-kv (email 2…

CVE-2026-41673
GitHub-GHSA

HIGH
xmldom has XML injection through unvalidated DocumentType serialization
GHSA-f6ww-3ggp-fr8h
pkg: @xmldom/xmldom, @xmldom/xmldom, xmldom
eco: npm
published: Apr 22, 2026
## Summary

The package serializes `DocumentType` node fields (`internalSubset`, `publicId`, `systemId`) verbatim
without any escaping or validation. When these fields are set programmatically to attacker-controlled
strings, `XMLSerializer.serializeToString` can produce output where the DOCTYPE decl…

CVE-2026-41674
GitHub-GHSA

HIGH
xmldom has XML node injection through unvalidated processing instruction serialization
GHSA-x6wf-f3px-wcqx
pkg: @xmldom/xmldom, @xmldom/xmldom, xmldom
eco: npm
published: Apr 22, 2026
## Summary

The package allows attacker-controlled processing instruction data to be serialized into XML without validating or neutralizing the PI-closing sequence `?>`. As a result, an attacker can terminate the processing instruction early and inject arbitrary XML nodes into the serialized output.…

CVE-2026-41675
GitHub-GHSA

HIGH
xmldom has XML node injection through unvalidated comment serialization
GHSA-j759-j44w-7fr8
pkg: @xmldom/xmldom, @xmldom/xmldom, xmldom
eco: npm
published: Apr 22, 2026
## Summary

The package allows attacker-controlled comment content to be serialized into XML without validating or neutralizing comment breaking sequences. As a result, an attacker can terminate the comment early and inject arbitrary XML nodes into the serialized output.

## Details

The issue …

CVE-2026-41672
GitHub-GHSA

HIGH
monetr: Server-side request forgery in Lunch Flow link creation and refresh
GHSA-29v9-frvh-c426
pkg: github.com/monetr/monetr
eco: go
published: Apr 22, 2026
### Impact

A server-side request forgery (SSRF) vulnerability in monetr's Lunch Flow integration allowed any authenticated user on
a self-hosted instance to cause the monetr server to issue HTTP GET requests to arbitrary URLs supplied by the caller,
with the response body from non-200 upstream resp…

CVE-2026-41644
GitHub-GHSA

HIGH
engram: HTTP server CORS wildcard + auth-off-by-default enables CSRF graph exfiltration and persistent indirect prompt injection
GHSA-2r2p-4cgf-hv7h
pkg: engramx
eco: npm
published: Apr 22, 2026
### Summary

The local HTTP server started by `engram server` (binding `127.0.0.1:7337` by default) was exposed to any browser origin with no authentication unless `ENGRAM_API_TOKEN` was explicitly set. Combined with `Access-Control-Allow-Origin: *` on every response and a body parser that did not r…

GitHub-GHSA

HIGH
@saltcorn/data: Tenant user role is used for tenant creation role check
GHSA-9237-rg5p-rhfw
pkg: @saltcorn/data, @saltcorn/data, @saltcorn/data
eco: npm
published: Apr 22, 2026
## Summary

When a tenant admin is logged out of the root domain (e.g., saltcorn.com) but logged in to their own tenant space as admin, they can simply append `/tenant/create` to their tenant URL. The system reads the role from the tenant context (admin), and a new tenant is created on the **root do…

GitHub-GHSA

HIGH
Claude Code: Sandbox Escape via Symlink Following Allows Arbitrary File Write Outside Workspace
GHSA-vp62-r36r-9xqp
pkg: @anthropic-ai/claude-code
eco: npm
published: Apr 21, 2026
Claude Code's sandbox did not prevent sandboxed processes from creating symlinks pointing to locations outside the workspace. When Claude Code subsequently wrote to a path within such a symlink, its unsandboxed process followed the symlink and wrote to the target location outside the workspace witho…
CVE-2026-39861
GitHub-GHSA

HIGH
Glances has SSRF in IP Plugin via public_api leading to credential leakage
GHSA-g5pq-48mj-jvw8
pkg: glances
eco: pip
published: Apr 21, 2026
### Summary
A Server-Side Request Forgery (SSRF) vulnerability exists in the Glances IP plugin due to improper validation of the public_api configuration parameter. The value of public_api is used directly in outbound HTTP requests without any scheme restriction or hostname/IP validation.

An attack…

CVE-2026-35587
GitHub-GHSA

HIGH
Glances: Cross-Origin Information Disclosure via Unauthenticated REST API (/api/4) due to Permissive CORS
GHSA-gfc2-9qmw-w7vh
pkg: Glances
eco: pip
published: Apr 21, 2026
### Summary
The Glances web server exposes a REST API (`/api/4/*`) that is accessible without authentication and allows cross-origin requests from any origin due to a permissive CORS policy (`Access-Control-Allow-Origin: *`).

This allows a malicious website to read sensitive system information from…

CVE-2026-34839
GitHub-GHSA

HIGH
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints
GHSA-78mf-482w-62qj
pkg: github.com/0xJacky/Nginx-UI
eco: go
published: Apr 21, 2026
## Summary

All WebSocket endpoints in nginx-ui use a gorilla/websocket Upgrader with CheckOrigin unconditionally returning true, allowing Cross-Site WebSocket Hijacking (CSWSH). Combined with the fact that authentication tokens are stored in browser cookies (set via JavaScript without HttpOnly or e…

CVE-2026-34403
GitHub-GHSA

HIGH
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens
GHSA-x234-x5vq-cc2v
pkg: github.com/0xJacky/Nginx-UI
eco: go
published: Apr 21, 2026
### Summary

A user who was disabled by an administrator can use previously issued API tokens for up to the token lifetime. In practice, disabling a compromised account does not actually terminate that user’s access, so an attacker who already stole a JWT can continue reading and modifying protect…

CVE-2026-33031
GitHub-GHSA

MEDIUM
DOMPurify: Prototype Pollution to XSS Bypass via CUSTOM_ELEMENT_HANDLING Fallback
GHSA-v9jr-rg53-9pgp
pkg: dompurify
eco: npm
published: Apr 22, 2026
## Summary

DOMPurify versions 3.0.1 through 3.3.3 (latest) are vulnerable to a prototype pollution-based XSS bypass. When an application uses `DOMPurify.sanitize()` with the default configuration (no `CUSTOM_ELEMENT_HANDLING` option), a prior prototype pollution gadget can inject permissive `tagNam…

CVE-2026-41238
NVD

MEDIUM
CVE-2026-41527
CVE-2026-41527
pkg: windows

published: Apr 21, 2026

KDE Kleopatra before 26.08.0 on Windows allows local users to obtain the privileges of a Kleopatra user, because there is an error in the mechanism (KUniqueService) for ensuring that only one instance is running.
CWE: CWE-670
NVD

MEDIUM
CVE-2026-42038
CVE-2026-42038
pkg: axios

published: Apr 24, 2026

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, he fix for no_proxy hostname normalization bypass is incomplete. When no_proxy=localhost is set, requests to 127.0.0.1 and [::1] still route through the proxy instead of bypassing it. The shouldBypassProxy(…
CWE: CWE-918
NVD

MEDIUM
CVE-2026-41239
CVE-2026-41239
pkg: vue

published: Apr 23, 2026

DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Starting in version 1.0.10 and prior to version 3.4.0, `SAFE_FOR_TEMPLATES` strips `{{…}}` expressions from untrusted HTML. This works in string mode but not with `RETURN_DOM` or `RETURN_DOM_FRAGMENT`, allowing XSS v…
CWE: CWE-79, CWE-1289
GitHub-GHSA

MEDIUM
nimiq-transaction: UpdateValidator transactions allows voting key change without proof-of-knowledge
GHSA-pf4j-pf3w-95f9
pkg: nimiq-transaction
eco: rust
published: Apr 22, 2026
### Impact
The staking contract accepts `UpdateValidator` transactions that set `new_voting_key=Some(…)` while omitting `new_proof_of_knowledge`. this skips the proof-of-knowledge requirement that is needed to prevent BLS rogue-key attacks when public keys are aggregated.

Because tendermint macro…

CVE-2026-34068
GitHub-GHSA

MEDIUM
DOMPurify has a SAFE_FOR_TEMPLATES bypass in RETURN_DOM mode
GHSA-crv5-9vww-q3g8
pkg: dompurify
eco: npm
published: Apr 22, 2026
## Summary

| Field | Value |
|:——|:——|
| **Severity** | Medium |
| **Affected** | DOMPurify `main` at [`883ac15`](https://github.com/cure53/DOMPurify/tree/883ac15d47f907cb1a3b5a152fe90c4d8c10f9e6), introduced in v1.0.10 ([`7fc196db`](https://github.com/cure53/DOMPurify/commit/7fc196db0b42a0…

CVE-2026-41239
NVD

MEDIUM
CVE-2026-40574
CVE-2026-40574
pkg: oauth

published: Apr 21, 2026

OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Prior to 7.15.2, an authorization bypass exists in OAuth2 Proxy as part of the email_domain enforcement option. An attacker may be able to authenticate with an email claim such as attacker@evil.com@company.com and s…
CWE: CWE-863
NVD

MEDIUM
CVE-2026-41667
CVE-2026-41667
pkg: node

published: Apr 22, 2026

Integer overflow in constant tensor data size calculation in Samsung Open Source ONE could cause incorrect buffer sizing for large constant nodes.
Affected version is prior to commit 1.30.0.
CWE: CWE-190
GitHub-GHSA

MEDIUM
python-dotenv: Symlink following in set_key allows arbitrary file overwrite via cross-device rename fallback
GHSA-mf9w-mj56-hr94
pkg: python-dotenv
eco: pip
published: Apr 21, 2026
### Summary

`set_key()` and `unset_key()` in python-dotenv follow symbolic links when rewriting `.env` files, allowing a local attacker to overwrite arbitrary files via a crafted symlink when a cross-device rename fallback is triggered.

### Details

The `rewrite()` context manager in `dotenv/main…

CVE-2026-28684
NVD

MEDIUM
CVE-2026-28684
CVE-2026-28684
pkg: python

published: Apr 20, 2026

python-dotenv reads key-value pairs from a .env file and can set them as environment variables. Prior to version 1.2.2, `set_key()` and `unset_key()` in python-dotenv follow symbolic links when rewriting `.env` files, allowing a local attacker to overwrite arbitrary files via a crafted symlink when …
CWE: CWE-59, CWE-61
NVD

MEDIUM
CVE-2026-42044
CVE-2026-42044
pkg: axios

published: Apr 24, 2026

Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.2, he Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's dependency tree to be escalated into surgical, invisible modification…
CWE: CWE-915, CWE-1321
GitHub-GHSA

MEDIUM
Lemmy has SSRF and internal image disclosure in post link metadata via unvalidated og:image
GHSA-h6hf-9846-xwrq
pkg: lemmy_api_common
eco: rust
published: Apr 24, 2026
### Summary
Lemmy fetches metadata for user-supplied post URLs and, under the default `StoreLinkPreviews` image mode, downloads the preview image through local pict-rs. While the top-level page URL is checked against internal IP ranges, the extracted `og:image` URL is not subject to the same restric…
GitHub-GHSA

MEDIUM
goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS
GHSA-rhf7-wvw3-vjvm
pkg: github.com/patrickhener/goshs/v2, github.com/patrickhener/goshs
eco: go
published: Apr 23, 2026
### Summary
The PUT upload handler (`httpserver/updown.go`) lacks the CSRF token validation that was added to the POST upload handler during the GHSA-jrq5-hg6x-j6g3 fix. Combined with the unconditional `Access-Control-Allow-Origin: *` on the OPTIONS preflight handler (`httpserver/server.go`), any we…
NVD

MEDIUM
CVE-2026-1352
CVE-2026-1352
pkg: windows

published: Apr 23, 2026

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in data query logic.
CWE: CWE-1284
GitHub-GHSA

MEDIUM
i18next-locize-backend has URL Injection via Unsanitized Path Parameters
GHSA-mgcp-mfp8-3q45
pkg: i18next-locize-backend
eco: npm
published: Apr 22, 2026
### Summary

Versions of `i18next-locize-backend` prior to 9.0.2 interpolate `lng`, `ns`, `projectId`, and `version` directly into the configured `loadPath` / `privatePath` / `addPath` / `updatePath` / `getLanguagesPath` URL templates with no path-component validation and no encoding. When an applic…

GitHub-GHSA

MEDIUM
DDEV has ZipSlip path traversal in tar and zip archive extraction
GHSA-x2xq-qhjf-5mvg
pkg: github.com/ddev/ddev
eco: go
published: Apr 22, 2026
## Summary

The DDEV local dev tool has unsanitized extraction in both `Untar()` and `Unzip()` functions in `pkg/archive/archive.go`. This flaw allows users to download and extract archives from remote sources without path validation.

## Vulnerable Code

`pkg/archive/archive.go:235` (Untar):
“`go

CVE-2026-32885
GitHub-GHSA

MEDIUM
i18next-http-backend has Path Traversal & URL Injection via Unsanitised lng/ns
GHSA-q89c-q3h5-w34g
pkg: i18next-http-backend
eco: npm
published: Apr 22, 2026
### Summary

Versions of `i18next-http-backend` prior to 3.0.5 interpolate the `lng` and `ns` values directly into the configured `loadPath` / `addPath` URL template without any encoding, validation, or path sanitisation. When an application exposes the language-code selection to user-controlled inp…

NVD

MEDIUM
CVE-2026-32885
CVE-2026-32885
pkg: node

published: Apr 22, 2026

DDEV is an open-source tool for running local web development environments for PHP and Node.js. Versions prior to 1.25.2 have unsanitized extraction in both `Untar()` and `Unzip()` functions in `pkg/archive/archive.go`. Downloads and extracts archives from remote sources without path validation. Ver…
CWE: CWE-22
NVD

MEDIUM
CVE-2026-40924
CVE-2026-40924
pkg: kubernetes

published: Apr 21, 2026

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Prior to 1.11.1, the HTTP resolver's FetchHttpResource function calls io.ReadAll(resp.Body) with no response body size limit. Any tenant with permission to create TaskRuns or PipelineRuns that reference the HT…
CWE: CWE-400
GitHub-GHSA

MEDIUM
Tekton Pipelines: HTTP Resolver Unbounded Response Body Read Enables Denial of Service via Memory Exhaustion
GHSA-m2cx-gpqf-qf74
pkg: github.com/tektoncd/pipeline
eco: go
published: Apr 21, 2026
## Summary

The HTTP resolver's `FetchHttpResource` function calls `io.ReadAll(resp.Body)` with no response body size limit. Any tenant with permission to create TaskRuns or PipelineRuns that reference the HTTP resolver can point it at an attacker-controlled HTTP server that returns a very large res…

CVE-2026-40924
NVD

MEDIUM
CVE-2026-40907
CVE-2026-40907
pkg: wwbn avideo

published: Apr 21, 2026

WWBN AVideo is an open source video platform. In versions 29.0 and prior, the endpoint `plugin/Live/view/Live_restreams/list.json.php` contains an Insecure Direct Object Reference (IDOR) vulnerability that allows any authenticated user with streaming permission to retrieve other users' live restream…
CWE: CWE-639
GitHub-GHSA

MEDIUM
nbconvert has an Arbitrary File Read via Path Traversal in HTMLExporter Image Embedding
GHSA-7jqv-fw35-gmx9
pkg: nbconvert
eco: pip
published: Apr 21, 2026
## Summary

When `HTMLExporter.embed_images=True`, nbconvert's markdown renderer allows arbitrary file read via path traversal in image references. A malicious notebook can exfiltrate sensitive files from the conversion host by embedding them as base64 data URIs in the output HTML.

## Patches

Upgr…

CVE-2026-39378
GitHub-GHSA

MEDIUM
nbconvert has an Arbitrary File Write via Path Traversal in Cell Attachment Filenames
GHSA-4c99-qj7h-p3vg
pkg: nbconvert
eco: pip
published: Apr 21, 2026
# Arbitrary File Write via Path Traversal in Cell Attachment Filenames

## Summary

nbconvert allows arbitrary file writes to locations outside the intended output directory when processing notebooks containing crafted cell attachment filenames. The `ExtractAttachmentsPreprocessor` passes attachment…

CVE-2026-39377
NVD

MEDIUM
CVE-2026-25542
CVE-2026-25542
pkg: go

published: Apr 21, 2026

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. From 0.43.0 to 1.11.0, trusted resources verification policies match a resource source string (refSource.URI) against spec.resources[].pattern using regexp.MatchString. In Go, regexp.MatchString reports a matc…
CWE: CWE-185
GitHub-GHSA

MEDIUM
Tekton Pipelines has VerificationPolicy regex pattern bypass via substring matching
GHSA-rmx9-2pp3-xhcr
pkg: github.com/tektoncd/pipeline
eco: go
published: Apr 21, 2026
## Summary

The Trusted Resources verification system matches a resource source string (`refSource.URI`) against `spec.resources[].pattern` using Go's `regexp.MatchString`. In Go, `regexp.MatchString` reports a match if the pattern matches **anywhere** in the input string. As a result, common unanch…

CVE-2026-25542
NVD

MEDIUM
CVE-2026-1089
CVE-2026-1089
pkg: fortra goanywhere_managed_file_transfer

published: Apr 21, 2026

User‑Controlled HTTP Header in Fortra's GoAnywhere MFT prior to version 7.10.0 allows attackers to trigger a DNS lookup, as well as DNS Rebinding and Information Disclosure.
CWE: CWE-74
NVD

MEDIUM
CVE-2026-33431
CVE-2026-33431
pkg: roxy-wi roxy-wi

published: Apr 20, 2026

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the POST /config/<service>/show API endpoint accepts a configver parameter that is directly appended to a base directory path to construct a local file path, which is subsequently opened …
CWE: CWE-24
NVD

MEDIUM
CVE-2026-31953
CVE-2026-31953
pkg: windows

published: Apr 24, 2026

Xibo is an open source digital signage platform with a web content management system and Windows display player software. A stored Cross-Site Scripting (XSS) vulnerability in versions prior to 4.4.1 allows an authenticated user with notification creation permissions to inject arbitrary JavaScript in…
CWE: CWE-79
GitHub-GHSA

MEDIUM
Marko: XSS via case-insensitive script/style closing tag bypass in runtime HTML escaping
GHSA-x9fj-57fh-c8wq
pkg: marko, @marko/runtime-tags
eco: npm
published: Apr 22, 2026
### Summary

When dynamic text is interpolated into a `<script>` or `<style>` tag the Marko runtime failed to prevent tag breakout when the closing tag used non-lowercase casing.
An attacker able to place input inside a `<script>` or `<style>` block could break out of the tag with `</SCRIPT>`, `</St…

CVE-2026-41591
NVD

MEDIUM
CVE-2026-35252
CVE-2026-35252
pkg: ssl

published: Apr 21, 2026

Vulnerability in the Oracle Security Service product of Oracle Fusion Middleware (component: C Oracle SSL API). Supported versions that are affected are 12.2.1.4.0 and 12.1.3.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle S…
CWE: CWE-284
GitHub-GHSA

MEDIUM
Lemmy has SSRF in /api/v3/post via Webmention dispatch
GHSA-3jvj-v6w2-h948
pkg: lemmy_api_common
eco: rust
published: Apr 24, 2026
### Summary
Lemmy allows an authenticated low-privileged user to create a link post through `POST /api/v3/post`. When a post is created in a public community, the backend asynchronously sends a Webmention to the attacker-controlled link target.

The submitted URL is checked for syntax and scheme, bu…

NVD

MEDIUM
CVE-2025-62233
CVE-2025-62233
pkg: node

published: Apr 24, 2026

Deserialization of Untrusted Data vulnerability in Apache DolphinScheduler RPC module.

This issue affects Apache DolphinScheduler: 

Version >= 3.2.0 and < 3.3.1.

Attackers who can access the Master or Worker nodes can compromise the system by creating a StandardRpcRequest, injecting a malicious …

CWE: CWE-502
GitHub-GHSA

MEDIUM
Glances has CQL Injection in its Cassandra Export Module via Unsanitized Config Values
GHSA-grp3-h8m8-45p7
pkg: glances
eco: pip
published: Apr 21, 2026
## Summary

The Cassandra export module (`glances/exports/glances_cassandra/__init__.py`) interpolates `keyspace`, `table`, and `replication_factor` configuration values directly into CQL statements without validation. A user with write access to `glances.conf` can redirect all monitoring data to an…

CVE-2026-35588
GitHub-GHSA

MEDIUM
Grid: Integer Overflow in Grid::expand_rows Leads to Safe-API Undefined Behavior
GHSA-38c5-483c-4qqp
pkg: grid
eco: rust
published: Apr 24, 2026
### Summary
An integer overflow in `Grid::expand_rows()` can corrupt the relationship between the grid’s logical dimensions and its backing storage. After the internal invariant is broken, the safe API get() may invoke get_unchecked() with an invalid index, resulting in Undefined Behavior.

### De…

GitHub-GHSA

MEDIUM
OpenMcdf has an Infinite loop DoS via crafted CFB directory cycle
GHSA-jxpf-xq2m-q525
pkg: OpenMcdf
eco: nuget
published: Apr 22, 2026
### Summary
OpenMcdf does not detect cycles in the directory entry red-black tree of a Compound File Binary (CFB) document. A crafted CFB file with a cycle in the `LeftSiblingID` / `RightSiblingID` chain causes `Storage.EnumerateEntries()` and `Storage.OpenStream()` to loop indefinitely, consuming t…
CVE-2026-41511
NVD

MEDIUM
CVE-2026-40608
CVE-2026-40608
pkg: node

published: Apr 21, 2026

Next AI Draw.io is a next.js web application that integrates AI capabilities with draw.io diagrams. Prior to 0.4.15, the embedded HTTP sidecar contains three POST handlers (/api/state, /api/restore, and /api/history-svg) that process incoming requests by accumulating the entire request body into a J…
CWE: CWE-770
GitHub-GHSA

MEDIUM
PostCSS has XSS via Unescaped </style> in its CSS Stringify Output
GHSA-qx2v-qp2m-jg93
pkg: postcss
eco: npm
published: Apr 24, 2026
# PostCSS: XSS via Unescaped `</style>` in CSS Stringify Output

## Summary

PostCSS v8.5.5 (latest) does not escape `</style>` sequences when stringifying CSS ASTs. When user-submitted CSS is parsed and re-stringified for embedding in HTML `<style>` tags, `</style>` in CSS values breaks out of the …

CVE-2026-41305
GitHub-GHSA

MEDIUM
melange has Path Traversal When Resolving External Pipelines via Unvalidated pipeline[].uses
GHSA-98f2-w9h9-7fp9
pkg: chainguard.dev/melange
eco: go
published: Apr 23, 2026
### Impact

An attacker who can influence a melange configuration file — for example through pull-request-driven CI or build-as-a-service scenarios — could set `pipeline[].uses` to a value containing `../` sequences or an absolute path. The `(*Compiled).compilePipeline` function in `pkg/build/co…

CVE-2026-29050
GitHub-GHSA

MEDIUM
fast-xml-parser XMLBuilder: XML Comment and CDATA Injection via Unescaped Delimiters
GHSA-gh4j-gqv2-49f6
pkg: fast-xml-parser
eco: npm
published: Apr 22, 2026
# fast-xml-parser XMLBuilder: Comment and CDATA Injection via Unescaped Delimiters

## Summary

fast-xml-parser XMLBuilder does not escape the `–>` sequence in comment content or the `]]>` sequence in CDATA sections when building XML from JavaScript objects. This allows XML injection when user-cont…

CVE-2026-41650
GitHub-GHSA

MEDIUM
Astro: XSS in define:vars via incomplete </script> tag sanitization
GHSA-j687-52p2-xcff
pkg: astro
eco: npm
published: Apr 21, 2026
## Summary

The `defineScriptVars` function in Astro's server-side rendering pipeline uses a case-sensitive regex `/<\/script>/g` to sanitize values injected into inline `<script>` tags via the `define:vars` directive. HTML parsers close `<script>` elements case-insensitively and also accept whitesp…

CVE-2026-41067
NVD

MEDIUM
CVE-2026-40565
CVE-2026-40565
pkg: freescout freescout

published: Apr 21, 2026

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, FreeScout's linkify() function in app/Misc/Helper.php converts plain-text URLs in email bodies into HTML anchor tags without escaping double-quote characters (") in the URL. HTMLPurifier (called first via getClea…
CWE: CWE-79
GitHub-GHSA

MEDIUM
OpenTelemetry.Sampler.AWS & OpenTelemetry.Resources.AWS have unbounded HTTP response body reads
GHSA-28xm-prxc-5866
pkg: OpenTelemetry.Sampler.AWS, OpenTelemetry.Resources.AWS
eco: nuget
published: Apr 23, 2026
### Summary

`OpenTelemetry.Sampler.AWS` reads unbounded HTTP response bodies from a configured AWS X-Ray remote sampling endpoint into memory.

`OpenTelemetry.Resources.AWS` reads unbounded HTTP response bodies from a configured AWS EC2/ECS/EKS remote instance metadata service endpoint into memory.…

CVE-2026-41173
NVD

MEDIUM
CVE-2026-41213
CVE-2026-41213
pkg: oauth

published: Apr 23, 2026

@node-oauth/oauth2-server is a module for implementing an OAuth2 server in Node.js. The token exchange path accepts RFC7636-invalid code_verifier values (including one-character strings) for S256 PKCE flows. Because short/weak verifiers are accepted and failed verifier attempts do not consume the au…
CWE: CWE-307, CWE-1289
GitHub-GHSA

MEDIUM
free5GC UDR: Fail-open handling in PolicyDataSubsToNotifyPost allows unintended subscription creation
GHSA-jwch-w7wh-gqjm
pkg: github.com/free5gc/udr
eco: go
published: Apr 21, 2026
### Summary
A fail-open request handling flaw in the UDR service causes the `/nudr-dr/v2/policy-data/subs-to-notify` POST handler to continue processing requests even after request body retrieval or deserialization errors.

This may allow unintended creation of Policy Data notification subscriptions…

CVE-2026-40343
NVD

MEDIUM
CVE-2025-1241
CVE-2025-1241
pkg: fortra goanywhere_agents, fortra goanywhere_managed_file_transfer, apple macos

published: Apr 21, 2026

Encrypted values in Fortra's GoAnywhere MFT prior to version 7.10.0 and GoAnywhere Agents prior to version 2.2.0 utilize a static IV which allows admin users to brute-force decryption of data.
CWE: CWE-326
NVD

MEDIUM
CVE-2026-41389
CVE-2026-41389
pkg: windows

published: Apr 20, 2026

OpenClaw versions 2026.4.7 before 2026.4.15 fail to enforce local-root containment on tool-result media paths, allowing arbitrary local and UNC file access. Attackers can craft malicious tool-result media references to trigger host-side file reads or Windows network path access, potentially disclosi…
CWE: CWE-73
NVD

MEDIUM
CVE-2026-7018
CVE-2026-7018
pkg: react

published: Apr 26, 2026

A vulnerability was determined in Datavane Datavines up to 13607645e14a4982468cfdbcf75c85cde63bae71. The affected element is an unknown function of the file datavines-core/src/main/java/io/datavines/core/utils/TokenManager.java of the component JWT Token Handler. Executing a manipulation of the argu…
CWE: CWE-320, CWE-321
NVD

MEDIUM
CVE-2026-40602
CVE-2026-40602
pkg: python

published: Apr 21, 2026

The Home Assistant Command-line interface (hass-cli) is a command-line tool for Home Assistant. Up to 1.0.0 of home-assitant-cli an unrestricted environment was used to handle Jninja2 templates instead of a sandboxed one. The user-supplied input within Jinja2 templates was rendered locally with no r…
CWE: CWE-94, CWE-1336
GitHub-GHSA

MEDIUM
Nuclei: Local File Read via require() Module Loader Bypass
GHSA-29rg-wmcw-hpf4
pkg: github.com/projectdiscovery/nuclei/v3
eco: go
published: Apr 22, 2026
A vulnerability in Nuclei's JavaScript protocol runtime allows JavaScript templates to read local `.js` and `.json` files through the `require()` function, bypassing the default local file access restriction.

**Affected Component**

The issue is in the JavaScript runtime's module loading system. Th…

CVE-2026-41646
NVD

MEDIUM
CVE-2026-6862
CVE-2026-6862
pkg: node

published: Apr 22, 2026

A flaw was found in libefiboot, a component of efivar. The device path node parser in libefiboot fails to validate that each node's Length field is at least 4 bytes, which is the minimum size for an EFI (Extensible Firmware Interface) device path node header. A local user could exploit this vulnerab…
CWE: CWE-674
NVD

MEDIUM
CVE-2026-41425
CVE-2026-41425
pkg: oauth

published: Apr 24, 2026

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.11, there is no CSRF protection on the cache feature in authlib.integrations.starlette_client.OAuth. This vulnerability is fixed in 1.6.11.
CWE: CWE-352
NVD

MEDIUM
CVE-2026-42042
CVE-2026-42042
pkg: axios

published: Apr 24, 2026

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library's XSRF token protection logic uses JavaScript truthy/falsy semantics instead of strict boolean comparison for the withXSRFToken config property. When this property is set to any truthy non…
CWE: CWE-183, CWE-201
GitHub-GHSA

MEDIUM
Tekton Pipelines: VolumeMount path restriction bypass via missing filepath.Clean in /tekton/ check
GHSA-rx35-6rhx-7858
pkg: github.com/tektoncd/pipeline
eco: go
published: Apr 21, 2026
## Summary

A validation bypass in the VolumeMount path restriction allows mounting volumes under restricted `/tekton/` internal paths by using `..` path traversal components. The restriction check uses `strings.HasPrefix` without `filepath.Clean`, so a path like `/tekton/home/../results` passes val…

CVE-2026-40923
NVD

MEDIUM
CVE-2026-41194
CVE-2026-41194
pkg: oauth

published: Apr 21, 2026

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, the mailbox OAuth disconnect action is implemented as `GET /mailbox/oauth-disconnect/{id}/{in_out}/{provider}`. It removes stored OAuth metadata from the mailbox and then redirects. Because it is a GET route, no …
CWE: CWE-352
GitHub-GHSA

MEDIUM
Auth0 Next.js SDK has Improper Proxy Cache Lookup
GHSA-xq8m-7c5p-c2r6
pkg: @auth0/nextjs-auth0
eco: npm
published: Apr 21, 2026
### Description
In affected versions of the Next.js SDK, simultaneous requests that trigger a nonce retry may cause the proxy cache fetcher to perform improper lookups for the token request results.

### Which Projects are Affected?
Users are affected if they meet all of the following preconditions:…

CVE-2026-40155
NVD

MEDIUM
CVE-2026-0972
CVE-2026-0972
pkg: fortra goanywhere_managed_file_transfer

published: Apr 21, 2026

HTML injection is possible in system generated emails in Fortra's GoAnywhere MFT prior to 7.10.0.

Note: The title, details, and description of this CVE were corrected post-publishing.

CWE: CWE-74
GitHub-GHSA

MEDIUM
Note Mark: Unauthenticated read of notes and assets in soft-deleted public books
GHSA-3gr9-485j-v4xf
pkg: github.com/enchant97/note-mark/backend
eco: go
published: Apr 25, 2026
## Summary

After a note-mark owner soft-deletes a public book, its notes and uploaded assets stay readable at `/api/notes/{id}`, `/api/notes/{id}/content`, the slug URL, and the asset endpoints. Unauthenticated callers who hold the note ID or the slug path retain access. GORM's soft-delete scope do…

CVE-2026-41572
NVD

MEDIUM
CVE-2026-6993
CVE-2026-6993
pkg: go

published: Apr 25, 2026

A security flaw has been discovered in go-kratos kratos up to 2.9.2. This impacts the function NewServer of the file transport/http/server.go of the component http.DefaultServeMux Fallback Handler. The manipulation results in unintended intermediary. The attack may be launched remotely. The exploit …
CWE: CWE-441
NVD

MEDIUM
CVE-2026-6985
CVE-2026-6985
pkg: go

published: Apr 25, 2026

A weakness has been identified in Cesanta Mongoose up to 7.20. This vulnerability affects the function handle_opt of the file /src/net_builtin.c of the component TCP Option Handler. This manipulation of the argument optlen causes infinite loop. The attack is possible to be carried out remotely. The …
CWE: CWE-404, CWE-835
NVD

MEDIUM
CVE-2026-42037
CVE-2026-42037
pkg: axios

published: Apr 24, 2026

Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.1, the FormDataPart constructor in lib/helpers/formDataToStream.js interpolates value.type directly into the Content-Type header of each multipart part without sanitizing CRLF (\r\n) sequences. An attacker wh…
CWE: CWE-93
NVD

MEDIUM
CVE-2026-42036
CVE-2026-42036
pkg: axios

published: Apr 24, 2026

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when responseType: 'stream' is used, Axios returns the response stream without enforcing maxContentLength. This bypasses configured response-size limits and allows unbounded downstream consumption. This vul…
CWE: CWE-770
NVD

MEDIUM
CVE-2026-42034
CVE-2026-42034
pkg: axios

published: Apr 24, 2026

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, for stream request bodies, maxBodyLength is bypassed when maxRedirects is set to 0 (native http/https transport path). Oversized streamed uploads are sent fully even when the caller sets strict body limits.…
CWE: CWE-770
NVD

MEDIUM
CVE-2026-41322
CVE-2026-41322
pkg: node

published: Apr 24, 2026

@astrojs/node allows Astro to deploy your SSR site to Node targets. Prior to 10.0.5, requesting a static js/css resources from _astro path with an incorrect/malformed if-match header returns a 500 error with a one year cache lifetime instead of 412 in some cases. This has the effect that all subsequ…
CWE: CWE-525
GitHub-GHSA

MEDIUM
ParquetSharp: Possible Stack Overflow When Reading a ParquetFile with Large Decimal Type Width
GHSA-rrjr-v56m-ww88
pkg: ParquetSharp
eco: nuget
published: Apr 24, 2026
`DecimalConverter.ReadDecimal` makes a stackalloc using what might be an attacker-supplied value. If an attacker declares a decimal column with some unreasonable width, this could lead to a stack overflow. In a service environment, this would potentially take down a service.

This affects applicatio…

GitHub-GHSA

MEDIUM
RedwoodSDK has Same-site CSRF through lack of origin validation in its server actions
GHSA-m2m6-cff5-3w7c
pkg: rwsdk
eco: npm
published: Apr 24, 2026
### Summary

Server actions in `rwsdk` apply HTTP method enforcement but no origin validation. A request originating from a different origin that the browser treats as same-site can invoke a server action with the victim's session cookie attached.

### Impact

An attacker who controls any origin the…

NVD

MEDIUM
CVE-2026-5488
CVE-2026-5488
pkg: go

published: Apr 24, 2026

The ExactMetrics – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 9.1.2. This is due to missing capability checks in the get_ads_access_token() and reset_experience() AJAX handlers. While the mi-admin-nonce is lo…
CWE: CWE-862
NVD

MEDIUM
CVE-2026-32952
CVE-2026-32952
pkg: go

published: Apr 24, 2026

go-ntlmssp is a Go package that provides NTLM/Negotiate authentication over HTTP. Prior to version 0.1.1, a malicious NTLM challenge message can causes an slice out of bounds panic, which can crash any Go process using `ntlmssp.Negotiator` as an HTTP transport. Version 0.1.1 patches the issue.
CWE: CWE-190
GitHub-GHSA

MEDIUM
OpenTelemetry dotnet: Excessive memory allocation when parsing OpenTelemetry propagation headers
GHSA-g94r-2vxg-569j
pkg: OpenTelemetry.Api, OpenTelemetry.Extensions.Propagators
eco: nuget
published: Apr 23, 2026
### Summary

The implementation details of the baggage, B3 and Jaeger processing code in the `OpenTelemetry.Api` and `OpenTelemetry.Extensions.Propagators` NuGet packages can allocate excessive memory when parsing which could create a potential denial of service (DoS) in the consuming application.

CVE-2026-40894
GitHub-GHSA

MEDIUM
OpenTelemetry dotnet: Unbounded `grpc-status-details-bin` parsing in OTLP/gRPC retry handling
GHSA-mr8r-92fq-pj8p
pkg: OpenTelemetry.Exporter.OpenTelemetryProtocol
eco: nuget
published: Apr 23, 2026
### Summary

When exporting telemetry over gRPC using the OpenTelemetry Protocol (OTLP), the exporter may parse a server-provided `grpc-status-details-bin` trailer during retry handling. Prior to the fix, a malformed trailer could encode an extremely large length-delimited protobuf field which was u…

CVE-2026-40891
GitHub-GHSA

MEDIUM
OpenTelemetry dotnet: OTLP exporter reads unbounded HTTP response bodies
GHSA-q834-8qmm-v933
pkg: OpenTelemetry.Exporter.OpenTelemetryProtocol
eco: nuget
published: Apr 23, 2026
### Summary

When exporting telemetry to a back-end/collector over gRPC or HTTP using OpenTelemetry Protocol format (OTLP), if the request results in a unsuccessful request (i.e. HTTP 4xx or 5xx), the response is read into memory with no upper-bound on the number of bytes consumed.

This could cause…

CVE-2026-40182
GitHub-GHSA

MEDIUM
go-ntlmssp NTLM challenges can panic on malformed payloads
GHSA-pjcq-xvwq-hhpj
pkg: github.com/Azure/go-ntlmssp
eco: go
published: Apr 23, 2026
A malicious NTLM challenge message can causes an slice out of bounds panic, which can crash any Go process using `ntlmssp.Negotiator` as an HTTP transport.
CVE-2026-32952
GitHub-GHSA

MEDIUM
Astro: Cache Poisoning due to incorrect error handling when if-match header is malformed
GHSA-c57f-mm3j-27q9
pkg: @astrojs/node
eco: npm
published: Apr 23, 2026
### Summary
Requesting a static JS/CSS resource from the `_astro` path with an incorrect or malformed `if-match` header returns a `500` error with a one-year cache lifetime instead of `412` in some cases. As a result, all subsequent requests to that file — regardless of the `if-match` header — w…
CVE-2026-41322
GitHub-GHSA

MEDIUM
n8n-MCP Logs Sensitive Request Data on Unauthorized /mcp Requests
GHSA-pfm2-2mhg-8wpx
pkg: n8n-mcp
eco: npm
published: Apr 23, 2026
### Impact

When `n8n-mcp` runs in HTTP transport mode, incoming requests to the `POST /mcp` endpoint had their request metadata written to server logs regardless of the authentication outcome. In deployments where logs are collected, forwarded to external systems, or viewable outside the request tr…

CVE-2026-41495
NVD

MEDIUM
CVE-2026-41182
CVE-2026-41182
pkg: python

published: Apr 23, 2026

LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to version 0.5.19 of the JavaScript SDK and version 0.7.31 of the Python SDK, the LangSmith SDK's output redaction controls (hideOutputs in JS, hide_outputs in Python) do not apply to streaming token events. When …
CWE: CWE-200, CWE-359, CWE-532
NVD

MEDIUM
CVE-2026-34064
CVE-2026-34064
pkg: nimiq nimiq_proof-of-stake

published: Apr 22, 2026

nimiq-account contains account primitives to be used in Nimiq's Rust implementation. Prior to version 1.3.0, `VestingContract::can_change_balance` returns `AccountError::InsufficientFunds` when `new_balance < min_cap`, but it constructs the error using `balance: self.balance – min_cap`. `Coin::sub` …
CWE: CWE-191
NVD

MEDIUM
CVE-2026-34062
CVE-2026-34062
pkg: nimiq nimiq_proof-of-stake

published: Apr 22, 2026

nimiq-libp2p is a Nimiq network implementation based on libp2p. Prior to version 1.3.0, `MessageCodec::read_request` and `read_response` call `read_to_end()` on inbound substreams, so a remote peer can send only a partial frame and keep the substream open. because `Behaviour::new` also sets `with_ma…
CWE: CWE-770
GitHub-GHSA

MEDIUM
Nuclei: Environment variable disclosure via Response-Derived DSL Expressions
GHSA-jm34-66cf-qpvr
pkg: github.com/projectdiscovery/nuclei/v3
eco: go
published: Apr 22, 2026
A vulnerability in Nuclei's expression evaluation engine makes it possible for a malicious target server to inject and execute supported DSL expressions. This happens when HTTP response data containing helper/function syntax gets reused by multi-step templates. If the `-env-vars` / `-ev` option is e…
CVE-2026-41645
GitHub-GHSA

MEDIUM
nimiq-blockchain: Peer-triggerable panic during history sync
GHSA-j99g-7rqw-q9jg
pkg: nimiq-blockchain
eco: rust
published: Apr 22, 2026
### Impact
`HistoryStore::put_historic_txns` uses an `assert!` to enforce invariants about `HistoricTransaction.block_number` (must be within the macro block being pushed and within the same epoch). During history sync, a peer can influence the `history: &[HistoricTransaction]` input passed into `Bl…
CVE-2026-34066
GitHub-GHSA

MEDIUM
nimiq-account: Vesting insufficient funds error can panic
GHSA-vc34-39q2-m6q3
pkg: nimiq-account
eco: rust
published: Apr 22, 2026
### Impact
`VestingContract::can_change_balance` returns `AccountError::InsufficientFunds` when `new_balance < min_cap`, but it constructs the error using `balance: self.balance – min_cap`. `Coin::sub` panics on underflow, so if an attacker can reach a state where `min_cap > balance`, the node crash…
CVE-2026-34064
NVD

MEDIUM
CVE-2026-22748
CVE-2026-22748
pkg: vmware spring_security

published: Apr 22, 2026

Vulnerability in Spring Spring Security. When an application configures JWT decoding with NimbusJwtDecoder  or NimbusReactiveJwtDecoder, it must configure an OAuth2TokenValidator<Jwt> separately, for example by calling setJwtValidator.This issue affects Spring Security: from 6.3.0 through 6.3.…
CWE: CWE-20
NVD

MEDIUM
CVE-2026-34273
CVE-2026-34273
pkg: go

published: Apr 21, 2026

Vulnerability in Oracle GoldenGate (component: Libraries). Supported versions that are affected are 23.4-23.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GoldenGate. Successful attacks of this vulnerability can result in una…
CWE: CWE-200
GitHub-GHSA

MEDIUM
Apache Kafka exposes sensitive information in its DEBUG logs
GHSA-wf66-mphr-4c4r
pkg: org.apache.kafka:kafka-clients, org.apache.kafka:kafka-clients
eco: maven
published: Apr 20, 2026
Information exposure vulnerability has been identified in Apache Kafka.

The NetworkClient component will output entire requests and responses information in the DEBUG log level in the logs. By default, the log level is set to INFO level. If the DEBUG level is enabled, the sensitive information will…

CVE-2026-33558
GitHub-GHSA

MEDIUM
Apache Doris MCP Server vulnerable to SQL Injection via improper query context neutralization
GHSA-qhfq-gvvc-5q6q
pkg: doris-mcp-server
eco: pip
published: Apr 20, 2026
Apache Doris MCP Server versions prior to 0.6.1 are affected by an improper neutralization flaw in query context handling that may allow execution of unintended SQL statements and bypass of intended query validation and access restrictions through the MCP query execution interface. Versions 0.6.1 an…
CVE-2025-66335
GitHub-GHSA

MEDIUM
Evolver has Prototype Pollution via `Object.assign()` in its mailbox store operations
GHSA-2cjr-5v3h-v2w4
pkg: @evomap/evolver
eco: npm
published: Apr 22, 2026
### Summary
A prototype pollution vulnerability in the mailbox store module allows attackers to modify the behavior of all JavaScript objects by injecting malicious properties into `Object.prototype`. The vulnerability exists in the `_applyUpdate()` and `_updateRecord()` functions which use `Object.…
GitHub-GHSA

MEDIUM
wlc: print_html outputs API data without HTML escaping
GHSA-gx2m-mcc2-r4p3
pkg: wlc
eco: pip
published: Apr 24, 2026
### Impact
The HTML output format in wlc embeds API response data into HTML without escaping, allowing cross-site scripting when the output is rendered in a browser.

### Patches
* https://github.com/WeblateOrg/wlc/pull/1327

### Workarounds
The only vulnerable code path is HTML output which is opt…

GitHub-GHSA

MEDIUM
OpenFGA has Improper Policy Enforcement
GHSA-57j5-qwp2-vqp6
pkg: github.com/openfga/openfga
eco: go
published: Apr 22, 2026
### Description
In OpenFGA, in specific scenarios, models using conditions with caching enabled can result in two different check requests producing the same cache key. This could result in OpenFGA reusing an earlier cached result for a subsequent request.

### Am I Affected?
Users are affected if t…

CVE-2026-41131
NVD

MEDIUM
CVE-2026-31955
CVE-2026-31955
pkg: windows

published: Apr 24, 2026

Xibo is an open source digital signage platform with a web content management system and Windows display player software. An authenticated Server-Side Request Forgery (SSRF) vulnerability in versions prior to 4.4.1 allows users with DataSet permissions to make arbitrary HTTP requests from the CMS se…
CWE: CWE-918
NVD

MEDIUM
CVE-2026-42041
CVE-2026-42041
pkg: axios

published: Apr 24, 2026

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution to silently suppress all HTTP error responses (401, 403, 500, etc.), causing them to be tr…
CWE: CWE-287, CWE-1321
GitHub-GHSA

MEDIUM
Spring Security Core has a TOCTOU race condition when One-Time Token login with JdbcOneTimeTokenService is configured
GHSA-x2wq-9x2f-fhj7
pkg: org.springframework.security:spring-security-core, org.springframework.security:spring-security-core, org.springframework.security:spring-security-core
eco: maven
published: Apr 21, 2026
Vulnerability in Spring Spring Security. Applications that explicitly configure One-Time Token login with JdbcOneTimeTokenService are vulnerable to a Time-of-check Time-of-use (TOCTOU) race condition. This issue affects Spring Security: from 6.4.0 through 6.4.15, from 6.5.0 through 6.5.9, from 7.…
CVE-2026-22751
NVD

MEDIUM
CVE-2026-40606
CVE-2026-40606
pkg: mitmproxy mitmproxy

published: Apr 21, 2026

mitmproxy is a interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers and mitmweb is a web-based interface for mitmproxy. In mitmproxy 12.2.1 and below, the builtin LDAP proxy authentication does not correctly sanitize the username when querying the LDAP serv…
CWE: CWE-90
NVD

MEDIUM
CVE-2026-40594
CVE-2026-40594
pkg: tls

published: Apr 21, 2026

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev98, the set_session_cookie_secure before_request handler in src/pyload/webui/app/__init__.py reads the X-Forwarded-Proto header from any HTTP request without validating that the request originates from a trusted…
CWE: CWE-346
GitHub-GHSA

MEDIUM
AWS Encryption SDK for Python: Key commitment policy bypass via shared key cache
GHSA-v638-38fc-rhfv
pkg: aws-encryption-sdk, aws-encryption-sdk
eco: pip
published: Apr 24, 2026
## Summary
AWS Encryption SDK (ESDK) for Python is a client-side encryption library. An issue exists where, under certain circumstances, a specific cryptographic algorithm downgrade in the caching layer might allow an authenticated local threat actor to bypass key commitment policy enforcement via a…
CVE-2026-6550
GitHub-GHSA

MEDIUM
i18nextify has DOM XSS via javascript:/data: URL schemes in translated href/src attributes
GHSA-6457-mxpq-4fqq
pkg: i18nextify
eco: npm
published: Apr 22, 2026
### Summary

Versions of `i18nextify` prior to 4.0.8 substitute `{{key}}` interpolation tokens inside `src` and `href` attribute values with the raw string returned by `i18next.t()`. The substitution logic in `src/localize.js` (`replaceInside` handler around line 122) only guards against a duplicate…

NVD

MEDIUM
CVE-2026-6550
CVE-2026-6550
pkg: python

published: Apr 20, 2026

Cryptographic algorithm downgrade in the caching layer of Amazon AWS Encryption SDK for Python before version 3.3.1 and before version 4.0.5 might allow an authenticated local threat actor to bypass key commitment policy enforcement via a shared key cache, resulting in ciphertext that can be decryp…
CWE: CWE-757
GitHub-GHSA

MEDIUM
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
GHSA-ffq5-qpvf-xq7x
pkg: openc3
eco: rubygems
published: Apr 22, 2026
### Summary
The Command Sender UI uses an unsafe `eval()` function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command. This creates a self-XSS risk because an attacker can trigger their own script execution in the victim’s sessio…
GitHub-GHSA

MEDIUM
melange has Path Traversal via .PKGINFO in –persist-lint-results
GHSA-q2pw-xx38-p64j
pkg: chainguard.dev/melange
eco: go
published: Apr 23, 2026
### Impact

`melange lint –persist-lint-results` (opt-in flag, also usable via `melange build –persist-lint-results`) constructs output file paths by joining `–out-dir` with the `arch` and `pkgname` values read from the `.PKGINFO` control file of the APK being linted. In affected versions these v…

CVE-2026-29051
NVD

MEDIUM
CVE-2026-35366
CVE-2026-35366
pkg: go

published: Apr 22, 2026

The printenv utility in uutils coreutils fails to display environment variables containing invalid UTF-8 byte sequences. While POSIX permits arbitrary bytes in environment strings, the uutils implementation silently skips these entries rather than printing the raw bytes. This vulnerability allows ma…
CWE: CWE-754
NVD

MEDIUM
CVE-2026-35358
CVE-2026-35358
pkg: node

published: Apr 22, 2026

The cp utility in uutils coreutils, when performing recursive copies (-R), incorrectly treats character and block device nodes as stream sources rather than preserving them. Because the implementation reads bytes into regular files at the destination instead of using mknod, device semantics are dest…
CWE: CWE-706
NVD

MEDIUM
CVE-2026-41330
CVE-2026-41330
pkg: tls

published: Apr 21, 2026

OpenClaw before 2026.3.31 contains an environment variable override vulnerability in host exec policy that fails to properly enforce proxy, TLS, Docker, and Git TLS controls. Attackers can bypass security controls by overriding environment variables to circumvent proxy settings, TLS verification, Do…
CWE: CWE-453
NVD

MEDIUM
CVE-2026-7086
CVE-2026-7086
pkg: docker

published: Apr 27, 2026

A vulnerability was identified in HBAI-Ltd Toonflow-app up to 1.1.1. This issue affects the function updateStoryboardUrl of the file replaceUrl.ts of the component Storyboard Export. Such manipulation of the argument url leads to path traversal. It is possible to launch the attack remotely. The expl…
CWE: CWE-22
NVD

MEDIUM
CVE-2026-33566
CVE-2026-33566
pkg: windows

published: Apr 27, 2026

There is a cypher injection issue in LogonTracer prior to v2.0.0. If specially crafted Windows event log data is loaded, the contents of the database may be altered.
CWE: CWE-943
GitHub-GHSA

MEDIUM
n8n-MCP: Sensitive MCP tool-call arguments logged on authenticated requests in HTTP mode
GHSA-wg4g-395p-mqv3
pkg: n8n-mcp
eco: npm
published: Apr 25, 2026
### Impact

When `n8n-mcp` runs in HTTP transport mode, authenticated MCP `tools/call` requests had their full arguments and JSON-RPC params written to server logs by the request dispatcher and several sibling code paths before any redaction. When a tool call carries credential material — most not…

NVD

MEDIUM
CVE-2026-40690
CVE-2026-40690
pkg: node

published: Apr 24, 2026

The asset dependency graph did not restrict nodes by the viewer's DAG read permissions: a user with read access to at least one DAG could browse the asset graph for any other asset in the deployment and learn the existence and names of DAGs and assets outside their authorized scope.

Users are recom…

CWE: CWE-1220
NVD

MEDIUM
CVE-2026-31956
CVE-2026-31956
pkg: windows

published: Apr 24, 2026

Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to version 4.4.1, any authenticated user can manually construct a URL to preview campaigns/regions, and export saved reports belonging to other users. Exploitation of the v…
CWE: CWE-639
GitHub-GHSA

MEDIUM
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
GHSA-4jvx-93h3-f45h
pkg: openc3, openc3
eco: rubygems
published: Apr 22, 2026
### Summary
OpenC3 COSMOS contains a design flaw in the `save_tool_config()` function that allows saving tool configuration files at arbitrary locations inside the shared `/plugins` directory tree by supplying crafted configuration filenames. Although the implementation sufficiently mitigates standa…
NVD

MEDIUM
CVE-2026-6294
CVE-2026-6294
pkg: go

published: Apr 22, 2026

The Google PageRank Display plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.4. This is due to missing nonce validation in the gpdisplay_option() function, which handles the plugin settings page. The settings form does not include a wp_nonce_field(),…
CWE: CWE-352
NVD

MEDIUM
CVE-2026-0971
CVE-2026-0971
pkg: fortra goanywhere_managed_file_transfer

published: Apr 21, 2026

An improper session timeout issue in Fortra's GoAnywhere MFT prior to version 7.10.0 results in SAML configured Web Users being redirected to the regular login page instead of the SAML login page.
CWE: CWE-613
NVD

MEDIUM
CVE-2026-41285
CVE-2026-41285
pkg: openbsd openbsd

published: Apr 21, 2026

In OpenBSD through 7.8, the slaacd and rad daemons have an infinite loop when they receive a crafted ICMPv6 Neighbor Discovery (ND) option (over a local network) with length zero, because of an "nd_opt_len * 8 – 2" expression with no preceding check for whether nd_opt_len is zero.
CWE: CWE-1284, CWE-835
GitHub-GHSA

MEDIUM
OpenClaw: Agent gateway config mutations could change protected operator settings
GHSA-7jm2-g593-4qrc
pkg: openclaw
eco: npm
published: Apr 25, 2026
## Affected Packages / Versions

– Package: `openclaw` (npm)
– Affected versions: `< 2026.4.20`
– Patched version: `2026.4.20`

## Impact

The agent-facing `gateway config.patch` / `config.apply` guard did not cover several operator-trusted settings, including sandbox policy, plugin enablement, gate…

GitHub-GHSA

MEDIUM
OpenClaw: Bundled MCP/LSP tools could bypass configured tool policy
GHSA-qrp5-gfw2-gxv4
pkg: openclaw
eco: npm
published: Apr 25, 2026
## Affected Packages / Versions

– Package: `openclaw` (npm)
– Affected versions: `< 2026.4.20`
– Patched version: `2026.4.20`

## Impact

Bundled MCP and LSP tools could be appended to the agent's effective tool set after the normal tool-policy pipeline had already filtered core tools. If an operat…

GitHub-GHSA

MEDIUM
OpenClaw: Workspace dotenv MiniMax host override could redirect credentialed requests
GHSA-h2vw-ph2c-jvwf
pkg: openclaw
eco: npm
published: Apr 25, 2026
## Affected Packages / Versions

– Package: `openclaw` (npm)
– Affected versions: `>= 2026.4.5, < 2026.4.20`
– Patched version: `2026.4.20`

## Impact

A malicious workspace `.env` could set `MINIMAX_API_HOST` and redirect credentialed MiniMax requests to an attacker-controlled origin, exposing the …

GitHub-GHSA

MEDIUM
OpenClaw: MCP stdio server env could load dangerous startup variables from workspace config
GHSA-mj59-h3q9-ghfh
pkg: openclaw
eco: npm
published: Apr 25, 2026
## Affected Packages / Versions

– Package: `openclaw` (npm)
– Affected versions: `< 2026.4.20`
– Patched version: `2026.4.20`

## Impact

Workspace MCP stdio configuration could pass dangerous process-startup environment variables such as `NODE_OPTIONS`, `LD_PRELOAD`, or `BASH_ENV` to the spawned M…

GitHub-GHSA

MEDIUM
OpenClaw: Workspace dotenv could override runtime-control environment variables
GHSA-hxvm-xjvf-93f3
pkg: openclaw
eco: npm
published: Apr 25, 2026
## Affected Packages / Versions

– Package: `openclaw` (npm)
– Affected versions: `< 2026.4.20`
– Patched version: `2026.4.20`

## Impact

Workspace `.env` loading did not reserve the `OPENCLAW_` runtime-control namespace broadly enough. A malicious workspace could set variables such as `OPENCLAW_GI…

GitHub-GHSA

MEDIUM
OpenClaw: Feishu card actions could misclassify DMs and skip dmPolicy
GHSA-72q8-jcmc-97wx
pkg: openclaw
eco: npm
published: Apr 25, 2026
## Affected Packages / Versions

– Package: `openclaw` (npm)
– Affected versions: `< 2026.4.20`
– Patched version: `2026.4.20`

## Impact

Feishu card-action callbacks could synthesize a message event with DM conversations classified as group conversations. That skipped `dmPolicy` enforcement for ca…

GitHub-GHSA

MEDIUM
OpenClaw: Hook mapping templates could bypass hook session-key opt-in
GHSA-2xcp-x87w-q377
pkg: openclaw
eco: npm
published: Apr 25, 2026
## Affected Packages / Versions

– Package: `openclaw` (npm)
– Affected versions: `< 2026.4.20`
– Patched version: `2026.4.20`

## Impact

Templated hook mapping `sessionKey` values were treated differently from request-supplied session keys. A hook mapping could render an externally influenced sess…

GitHub-GHSA

MEDIUM
gitverify has improper tag signature verification
GHSA-h829-5cg7-6hff
pkg: github.com/supply-chain-tools/gitverify
eco: go
published: Apr 24, 2026
gitverify is still a prototype.

### Impact
The bug is related to `requireSignedTags` which is on by default: an unsigned annotated tag would pass the verification. The commit pointed to by the tag would still have to be signed by a maintainer or a contributor.

### Patches
Since the initial commit,…

GitHub-GHSA

MEDIUM
Excalidraw vulnerable to XSS via Mermaid sequence diagram labels (KaTeX rendering)
GHSA-39h7-pwv7-rc3x
pkg: @excalidraw/excalidraw, @excalidraw/mermaid-to-excalidraw
eco: npm
published: Apr 24, 2026
### Impact

`@excalidraw/excalidraw@0.18.0` depends on a Mermaid conversion package version that resolves to a Mermaid release affected by CVE-2025-54881 / GHSA-7rqq-prvp-x9jh. User-supplied Mermaid sequence diagram labels could trigger XSS through Mermaid’s KaTeX label rendering path.

This is pa…

GitHub-GHSA

MEDIUM
Traefik: A timing side-channel vulnerability allows for valid username enumeration via BasicAuth middleware
GHSA-6x2q-h3cr-8j2h
pkg: github.com/traefik/traefik/v3, github.com/traefik/traefik/v3, github.com/traefik/traefik/v2
eco: go
published: Apr 24, 2026
## Summary

There is a timing side-channel vulnerability in Traefik's BasicAuth middleware that allows an attacker to enumerate valid usernames through response-time differences.

The variable intended to hold a constant-time fallback secret always resolves to an empty string, causing the constant-t…

CVE-2026-41263
GitHub-GHSA

MEDIUM
Traefik Kubernetes CRD allows unauthorized cross-namespace middleware binding
GHSA-xhjw-95fp-8vgq
pkg: github.com/traefik/traefik/v3, github.com/traefik/traefik/v3, github.com/traefik/traefik/v2
eco: go
published: Apr 24, 2026
## Summary

There is a vulnerability in Traefik's Kubernetes CRD provider cross-namespace isolation enforcement.

When `providers.kubernetesCRD.allowCrossNamespace=false`, Traefik correctly rejects direct cross-namespace middleware references from `IngressRoute` objects, but fails to apply the same …

CVE-2026-41174
GitHub-GHSA

MEDIUM
justhtml has sanitization bypass in custom policies and programmatic DOM
GHSA-vrx2-77f2-ww34
pkg: justhtml
eco: pip
published: Apr 22, 2026
## Summary

`justhtml` `1.17.0` fixes multiple security issues in sanitization, serialization, and programmatic DOM handling.

Most of these issues affected advanced or custom configurations rather than the default safe path.

## Affected versions

– `justhtml` `<= 1.16.0`

## Fixed version

– `just…

GitHub-GHSA

MEDIUM
uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided
GHSA-w5hq-g745-h8pq
pkg: uuid
eco: npm
published: Apr 22, 2026
### Summary

`v3`, `v5`, and `v6` accept external output buffers but do not reject out-of-range writes (small `buf` or large `offset`).
By contrast, `v4`, `v1`, and `v7` explicitly throw `RangeError` on invalid bounds.

This inconsistency allows **silent partial writes** into caller-provided buffe…

GitHub-GHSA

MEDIUM
Gitea has insecure default SSH settings
GHSA-3m6q-h5gj-7mrw
pkg: code.gitea.io/gitea
eco: go
published: Apr 22, 2026
## Summary

The built-in SSH server currently advertises a number of key exchange, MAC, and host key algorithms that are considered weak or broken. The defaults should be tightened so a fresh installation passes a baseline SSH security audit out of the box.

## Details

Running `ssh-audit` against a…

GitHub-GHSA

MEDIUM
free5GC AMF: Missing default case in Content-Type switch in HTTPUEContextTransfer
GHSA-r99v-75p9-xqm5
pkg: github.com/free5gc/amf
eco: go
published: Apr 22, 2026
## Summary

The `HTTPUEContextTransfer` handler in `internal/sbi/api_communication.go` does not include a `default` case in the `Content-Type` switch statement. When a request arrives with an unsupported `Content-Type`, the deserialization step is silently skipped, `err` remains `nil`, and the proce…

CVE-2026-41136
GitHub-GHSA

MEDIUM
Inspektor Gadget uses unsanitized ANSI Escape Sequences In `columns` Output Mode
GHSA-34r5-6j7w-235f
pkg: github.com/inspektor-gadget/inspektor-gadget
eco: go
published: Apr 22, 2026
### Description
String fields from eBPF events in `columns` output mode are rendered to the terminal without any sanitization of control characters or ANSI escape sequences.

Therefore, a maliciously forged – partially or completely – event payload, coming from an observed container, might inj…

CVE-2026-25996
GitHub-GHSA

MEDIUM
Inspektor Gadget: Command Injection via malicious buildOptions manipulation
GHSA-79qw-g77v-2vfh
pkg: github.com/inspektor-gadget/inspektor-gadget
eco: go
published: Apr 22, 2026
### Impacted Resources

`inspektor-gadget/cmd/common/image/build.go`
`inspektor-gadget/cmd/common/image/helpers/Makefile.build`

### Description

The `ig` binary provides a subcommand for image building, used to generate custom gadget OCI images.

A part of this functionality is implemented in the f…

CVE-2026-24905
GitHub-GHSA

MEDIUM
DOMPurify: FORBID_TAGS bypassed by function-based ADD_TAGS predicate (asymmetry with FORBID_ATTR fix)
GHSA-h7mw-gpvr-xq4m
pkg: dompurify
eco: npm
published: Apr 22, 2026
There is an inconsistency between FORBID_TAGS and FORBID_ATTR handling when function-based ADD_TAGS is used.

Commit [c361baa](https://github.com/cure53/DOMPurify/commit/c361baa18dbdcb3344a41110f4c48ad85bf48f80) added an early exit for FORBID_ATTR at line 1214:

/* FORBID_ATTR must always win, e…

CVE-2026-41240
GitHub-GHSA

MEDIUM
actix-http has HTTP/1.1 CL.TE Request Smuggling
GHSA-xhj4-vrgc-hr34
pkg: actix-http
eco: rust
published: Apr 22, 2026
A vulnerability in `actix-http`'s HTTP/1.1 request parser allows an unauthenticated remote client to smuggle requests in deployments where a front-end HTTP intermediary and the Actix backend disagree about whether `Content-Length` or `Transfer-Encoding: chunked` defines the request body length.

## …

GitHub-GHSA

MEDIUM
OpenBao's SQL Injection in PostgreSQL database secrets engine
GHSA-6vgr-cp5c-ffx3
pkg: github.com/openbao/openbao
eco: go
published: Apr 21, 2026
### Impact

When OpenBao revoked privileges on a role in the PostgreSQL database secrets engine, OpenBao failed to use proper database quoting on schema names provided by PostgreSQL. This could lead to role revocation failures, or more rarely, SQL injection as the management user.

This vulnerabilit…

CVE-2026-39946
GitHub-GHSA

MEDIUM
pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
GHSA-58qw-9mgm-455v
pkg: pip
eco: pip
published: Apr 20, 2026
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP file. This behavior could result in confusing installation behavior, such as installing "incorrect" files according to the filename of the archive. New behavior only proceeds with i…
CVE-2026-3219


Vulnerability Digest — April 20, 2026 · 39 Critical · 3 Exploited






Vulnerability Digest — Monday, April 20, 2026


Security Report

Monday, April 20, 2026  ·  Last 7 days  ·  Min severity: MEDIUM
Total Findings
268
Critical
39
High
111
Actively Exploited
3
CISA-KEV3
GitHub-GHSA265
Findings sorted by severity
CISA-KEV

CRITICAL
Apache ActiveMQ Improper Input Validation Vulnerability
CVE-2026-34197
pkg: Apache ActiveMQ

published: Apr 16, 2026

Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
Microsoft Office Remote Code Execution
CVE-2009-0238
pkg: Microsoft Office

published: Apr 14, 2026

Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that includes a malformed object.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
Microsoft SharePoint Server Improper Input Validation Vulnerability
CVE-2026-32201
pkg: Microsoft SharePoint Server

published: Apr 14, 2026

Microsoft SharePoint Server contains an improper input validation vulnerability that allows an unauthorized attacker to perform spoofing over a network.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
GitHub-GHSA

CRITICAL
Saltcorn: SQL Injection via Unparameterized Sync Endpoints (maxLoadedId)
GHSA-jp74-mfrx-3qvh
pkg: @saltcorn/server, @saltcorn/server, @saltcorn/server
eco: npm
published: Apr 16, 2026
## Summary
Saltcorn's mobile-sync routes (`POST /sync/load_changes` and `POST /sync/deletes`) interpolate user-controlled values directly into SQL template literals without parameterization, type-casting, or sanitization. Any authenticated user (role_id ≥ 80, the default "user" role) who has read …
GitHub-GHSA

CRITICAL
Paperclip: Cross-tenant agent API key IDOR in `/agents/:id/keys` routes allows full victim-company compromise
GHSA-3xx2-mqjm-hg9x
pkg: @paperclipai/server
eco: npm
published: Apr 16, 2026
## Summary

The `GET`, `POST`, and `DELETE` handlers under `/agents/:id/keys` in the Paperclip control-plane API only call `assertBoard(req)`, which verifies that the caller has a board-type session but does not verify that the caller has access to the company owning the target agent. A board user w…

GitHub-GHSA

CRITICAL
Paperclip: Cross-tenant agent API token minting via missing assertCompanyAccess on /api/agents/:id/keys
GHSA-47wq-cj9q-wpmp
pkg: @paperclipai/server
eco: npm
published: Apr 16, 2026
<img width="7007" height="950" alt="01-setup" src="https://github.com/user-attachments/assets/1596b8d1-8de5-4c21-b1d2-2db41b568d7e" />

> Isolated paperclip instance running in authenticated mode (default config)
> on a clean Docker image matching commit b649bd4 (2026.411.0-canary.8, post
> the 2026…

GitHub-GHSA

CRITICAL
Flowise: Authenticated RCE Via MCP Adapters
GHSA-c9gw-hvqq-f33r
pkg: flowise, flowise-components
eco: npm
published: Apr 16, 2026
### Summary
Due to unsafe serialization of stdio commands in the MCP adapter, an authenticated attacker can add an MCP stdio server with an arbitrary command, achieving command execution.

### Details
The vulnerability lies in a bug in the input sanitization from the “Custom MCP” configuration i…

CVE-2026-40933
GitHub-GHSA

CRITICAL
Expression Injection in OpenRemote
GHSA-7mqr-33rv-p3mp
pkg: io.openremote:openremote-manager
eco: maven
published: Apr 14, 2026
### Summary
The OpenRemote IoT platform's rules engine contains two interrelated critical expression injection vulnerabilities that allow an attacker to execute arbitrary code on the server, ultimately achieving full server compromise.

– Unsandboxed Nashorn JavaScript Engine: JavaScript rules are e…

CVE-2026-39842
GitHub-GHSA

CRITICAL
Remote Code Execution (RCE) via String Literal Injection into math-codegen
GHSA-p6x5-p4xf-cc4r
pkg: math-codegen
eco: npm
published: Apr 17, 2026
### Impact

String literal content passed to `cg.parse()` is injected verbatim into a `new Function()` body without sanitization. This allows an attacker to execute arbitrary system commands when user-controlled input reaches the parser. Any application exposing a math evaluation endpoint where user…

GitHub-GHSA

CRITICAL
Incomplete fix for CVE-2026-34935: Command Injection in MervinPraison/PraisonAI
GHSA-9qhq-v63v-fv3j
pkg: praisonai
eco: pip
published: Apr 17, 2026
### Summary

The fix for PraisonAI's MCP command handling does not add a command allowlist or argument validation to `parse_mcp_command()`, allowing arbitrary executables like `bash`, `python`, or `/bin/sh` with inline code execution flags to pass through to subprocess execution.

### Affected Packa…

GitHub-GHSA

CRITICAL
Paperclip: OS Command Injection via Execution Workspace cleanupCommand
GHSA-vr7g-88fq-vhq3
pkg: @paperclipai/server
eco: npm
published: Apr 16, 2026
| Field | Value |
|——-|——-|
| **Affected Software** | Paperclip AI v2026.403.0 |
| **Affected Component** | Execution Workspace lifecycle (`workspace-runtime.ts`) |
| **Affected Endpoint** | `PATCH /api/execution-workspaces/:id` |
| **Deployment Modes** | All — `local_trusted` (zero auth),…
GitHub-GHSA

CRITICAL
electerm: electerm_install_script_CommandInjection Vulnerability Report
GHSA-wxw2-rwmh-vr8f
pkg: electerm
eco: npm
published: Apr 16, 2026
### Impact
_What kind of vulnerability is it? Who is impacted?_

**Two Command Injection vulnerabilities in electerm:**

1. **macOS Installer** (`electerm_CommandInjection_02`): A command injection vulnerability exists in `github.com/elcterm/electerm/npm/install.js:150`. The `runMac()` function appe…

GitHub-GHSA

CRITICAL
UEFI Firmware Parser has a heap out-of-bounds write in tiano decompressor ReadCLen
GHSA-hm2w-vr2p-hq7w
pkg: uefi-firmware
eco: pip
published: Apr 16, 2026
`uefi-firmware` contains a heap out-of-bounds write vulnerability in the native tiano/EFI decompressor. in `uefi_firmware/compression/Tiano/Decompress.c`, `ReadCLen()` reads `Number = GetBits(Sd, CBIT)` with `CBIT = 9`, so `Number` can be as large as `511`, while the destination array `Sd->mCLen` ha…
GitHub-GHSA

CRITICAL
UEFI Firmware Parser has a stack out-of-bounds write in tiano decompressor MakeTable
GHSA-2689-5p89-6j3j
pkg: uefi-firmware
eco: pip
published: Apr 16, 2026
`uefi-firmware` contains a stack out-of-bounds write vulnerability in the native tiano/EFI decompressor. in `uefi_firmware/compression/Tiano/Decompress.c`, `MakeTable()` does not validate that bit-length values read from the compressed bitstream are within the expected range (`0..16`). a crafted fir…
GitHub-GHSA

CRITICAL
MsQuic has a Remote Elevation of Privilege Vulnerability
GHSA-gvvw-8j96-8g5r
pkg: Microsoft.Native.Quic.MsQuic.OpenSSL, Microsoft.Native.Quic.MsQuic.Schannel, Microsoft.Native.Quic.MsQuic.Schannel
eco: nuget
published: Apr 16, 2026
### Summary
Improper input validation in Microsoft QUIC allows an unauthorized attacker to elevate privileges over a network.

### Details
Improper Input Validation Integer Underflow (Wrap or Wraparound) when decoding ACK frame.

#### Patches
– Fix underflow in ACK frame parsing – 1e6e999b

### Imp…

CVE-2026-32179
GitHub-GHSA

CRITICAL
Upsonic: remote code execution vulnerability in its MCP server/task creation functionality
GHSA-cw73-5f7h-m4gv
pkg: upsonic
eco: pip
published: Apr 15, 2026
Upsonic 0.71.6 contains a remote code execution vulnerability in its MCP server/task creation functionality. The application allows users to define MCP tasks with arbitrary command and args values. Although an allowlist exists, certain allowed commands (npm, npx) accept argument flags that enable ex…
CVE-2026-30625
GitHub-GHSA

CRITICAL
goshs has an empty-username SFTP password authentication bypass
GHSA-c29w-qq4m-2gcv
pkg: github.com/patrickhener/goshs, github.com/patrickhener/goshs/v2
eco: go
published: Apr 14, 2026
### Summary
goshs contains an SFTP authentication bypass when the documented empty-username basic-auth syntax is used. If the server is started with `-b ':pass'` together with `-sftp`, goshs accepts that configuration but does not install any SFTP password handler. As a result, an unauthenticated ne…
CVE-2026-40884
GitHub-GHSA

CRITICAL
Wish has SCP Path Traversal that allows arbitrary file read/write
GHSA-xjvp-7243-rg9h
pkg: charm.land/wish/v2, github.com/charmbracelet/wish
eco: go
published: Apr 18, 2026
## Summary

The SCP middleware in `charm.land/wish/v2` is vulnerable to path traversal attacks. A malicious SCP client can read arbitrary files from the server, write arbitrary files to the server, and create directories outside the configured root directory by sending crafted filenames containing `…

GitHub-GHSA

CRITICAL
Dgraph: Unauthenticated /debug/pprof/cmdline discloses admin auth token, enabling unauthorized access to protected Alpha admin endpoints
GHSA-95mq-xwj4-r47p
pkg: github.com/dgraph-io/dgraph/v25, github.com/dgraph-io/dgraph/v24, github.com/dgraph-io/dgraph
eco: go
published: Apr 16, 2026
### Summary
An unauthenticated debug endpoint in Dgraph Alpha exposes the full process command line, including the configured admin token from `–security "token=…"`.

This does not break token validation logic directly; instead, it discloses the credential and enables unauthorized admin-level acc…

CVE-2026-40173
GitHub-GHSA

CRITICAL
excel-mcp-server has a Path Traversal issue
GHSA-j98m-w3xp-9f56
pkg: excel-mcp-server
eco: pip
published: Apr 14, 2026
## Summary

A path traversal vulnerability exists in [`excel-mcp-server`](https://github.com/haris-musa/excel-mcp-server) versions up to and including `0.1.7`. When running in SSE or Streamable-HTTP transport mode (the documented way to use this server remotely), an unauthenticated attacker on the n…

CVE-2026-40576
GitHub-GHSA

CRITICAL
Sentry: Improper authentication on SAML SSO process allows user identity linking
GHSA-ggmg-cqg6-j45g
pkg: sentry
eco: pip
published: Apr 17, 2026
### Impact
A critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program.

The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same …

CVE-2026-27197
GitHub-GHSA

CRITICAL
Budibase: Authentication Bypass via Unanchored Regex in Public Endpoint Matcher — Unauthenticated Access to Protected Endpoints
GHSA-8783-3wgf-jggf
pkg: @budibase/backend-core
eco: npm
published: Apr 16, 2026
### Summary

The `authenticated` middleware uses unanchored regular expressions to match public (no-auth) endpoint patterns against `ctx.request.url`. Since `ctx.request.url` in Koa includes the query string, an attacker can access any protected endpoint by appending a public endpoint path as a quer…

GitHub-GHSA

CRITICAL
@fastify/middie vulnerable to middleware authentication bypass in child plugin scopes
GHSA-72c6-fx6q-fr5w
pkg: @fastify/middie
eco: npm
published: Apr 16, 2026
### Impact

`@fastify/middie` v9.3.1 and earlier incorrectly re-prefixes middleware paths when propagating them to child plugin scopes. When a child plugin is registered with a prefix that overlaps with a parent-scoped middleware path, the middleware path is modified during inheritance and silently …

CVE-2026-6270
GitHub-GHSA

CRITICAL
Official Clerk JavaScript SDKs: Middleware-based route protection bypass
GHSA-vqx2-fgx2-5wq9
pkg: @clerk/nextjs, @clerk/nuxt, @clerk/astro
eco: npm
published: Apr 16, 2026
## Summary

`createRouteMatcher` in `@clerk/nextjs`, `@clerk/nuxt`, and `@clerk/astro` can be bypassed by certain crafted requests, allowing them to skip middleware gating and reach downstream handlers.

Sessions are not compromised and no existing user can be impersonated – the bypass only affects …

GitHub-GHSA

CRITICAL
ChilliCream GraphQL Platform: Utf8GraphQLParser Stack Overflow via Deeply Nested GraphQL Documents
GHSA-qr3m-xw4c-jqw3
pkg: HotChocolate.Language, HotChocolate.Language, HotChocolate.Language
eco: nuget
published: Apr 16, 2026
### Impact

Hot Chocolate's `Utf8GraphQLParser` is a recursive descent parser with no recursion depth limit. A crafted GraphQL document with deeply nested selection sets, object values, list values, or list types can trigger a `StackOverflowException` on payloads as small as **40 KB**.

Because `Sta…

CVE-2026-40324
GitHub-GHSA

CRITICAL
Exposure of Storage Secret in Pyroscope
GHSA-m9hq-h476-h2g8
pkg: github.com/grafana/pyroscope, github.com/grafana/pyroscope
eco: go
published: Apr 15, 2026
Pyroscope is an open-source continuous profiling database. The database supports various storage backends, including Tencent Cloud Object Storage (COS).

If the database is configured to use Tencent COS as the storage backend, an attacker could extract the secret_key configuration value from the Pyr…

CVE-2025-41118
GitHub-GHSA

CRITICAL
Improper neutralization of specific syntax patterns for unauthorized expressions in Thymeleaf
GHSA-xjw8-8c5c-9r79
pkg: org.thymeleaf:thymeleaf, org.thymeleaf:thymeleaf-spring5, org.thymeleaf:thymeleaf-spring6
eco: maven
published: Apr 15, 2026
### Impact
A security bypass vulnerability exists in the expression execution mechanisms of Thymeleaf up to and including 3.1.3.RELEASE. Although the library provides mechanisms to prevent expression injection, it fails to properly neutralize specific syntax patterns that allow for the execution of …
CVE-2026-40478
GitHub-GHSA

CRITICAL
Improper restriction of the scope of accessible objects in Thymeleaf expressions
GHSA-r4v4-5mwr-2fwr
pkg: org.thymeleaf:thymeleaf, org.thymeleaf:thymeleaf-spring5, org.thymeleaf:thymeleaf-spring6
eco: maven
published: Apr 15, 2026
### Impact
A security bypass vulnerability exists in the expression execution mechanisms of Thymeleaf up to and including 3.1.3.RELEASE. Although the library provides mechanisms to prevent expression injection, it fails to properly restrict the scope of accessible objects, allowing specific potentia…
CVE-2026-40477
GitHub-GHSA

CRITICAL
OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing
GHSA-7×63-xv5r-3p2x
pkg: github.com/oauth2-proxy/oauth2-proxy/v7
eco: go
published: Apr 15, 2026
### Impact

A configuration-dependent authentication bypass exists in OAuth2 Proxy.

Deployments are affected when all of the following are true:

* OAuth2 Proxy is configured with `–reverse-proxy`
* and at least one rule is defined with `–skip_auth_routes` or the legacy `–skip-auth-regex`

OAuth…

CVE-2026-40575
GitHub-GHSA

CRITICAL
OAuth2 Proxy's Health Check User-Agent Matching Bypasses Authentication in auth_request Mode
GHSA-5hvv-m4w4-gf6v
pkg: github.com/oauth2-proxy/oauth2-proxy/v7, github.com/oauth2-proxy/oauth2-proxy
eco: go
published: Apr 14, 2026
### Impact
A configuration-dependent authentication bypass exists in OAuth2 Proxy.

Deployments are affected when all of the following are true:

– OAuth2 Proxy is used with an `auth_request`-style integration (for example, nginx `auth_request`)
– `–ping-user-agent` is set or `–gcp-healthchecks`…

CVE-2026-34457
GitHub-GHSA

CRITICAL
Zebra Vulnerable to Consensus Divergence in Transparent Sighash Hash-Type Handling
GHSA-8m29-fpq5-89jj
pkg: zebrad, zebra-script
eco: rust
published: Apr 18, 2026
# Consensus Divergence in Transparent Sighash Hash-Type Handling

## Summary

After a refactoring, Zebra failed to validate a consensus rule that restricted the possible values of sighash hash types for V5 transactions which were enabled in the NU5 network upgrade. Zebra nodes could thus accept and …

GitHub-GHSA

CRITICAL
Zebra has rk Identity Point Panic in Transaction Verification
GHSA-452v-w3gx-72wg
pkg: zebrad, zebra-chain
eco: rust
published: Apr 18, 2026
# rk Identity Point Panic in Transaction Verification

## Summary

Orchard transactions contain a `rk` field which is a randomized validating key and also an elliptic curve point. The Zcash specification allows the field to be the identity (a "zero" value), however, the `orchard` crate which is used…

GitHub-GHSA

CRITICAL
Nhost Vulnerable to Account Takeover via OAuth Email Verification Bypass
GHSA-6g38-8j4p-j3pr
pkg: github.com/nhost/nhost
eco: go
published: Apr 18, 2026
## Summary

Nhost automatically links an incoming OAuth identity to an existing Nhost account when the email addresses match. This is only safe when the email has been **verified by the OAuth provider**. Nhost's controller trusts a `profile.EmailVerified` boolean that is set by each provider adapter…

GitHub-GHSA

CRITICAL
Flowise: Airtable_Agent Code Injection Remote Code Execution Vulnerability
GHSA-v38x-c887-992f
pkg: flowise, flowise-components
eco: npm
published: Apr 18, 2026
ZDI-CAN-29412: FlowiseAI Flowise Airtable_Agent Code Injection Remote Code Execution Vulnerability

— ABSTRACT ————————————-

Trend Micro's Zero Day Initiative has identified a vulnerability affecting the following products:
Flowise – Flowise

— VULNERABILITY DETAILS ——…

GitHub-GHSA

CRITICAL
OpenClaw: Feishu webhook and card-action validation now fail closed
GHSA-xh72-v6v9-mwhc
pkg: openclaw
eco: npm
published: Apr 17, 2026
## Summary

Feishu webhook mode accepted missing `encryptKey` configuration as valid and blank card-action callback tokens as usable lifecycle tokens. Together, those fail-open paths could allow unauthenticated webhook or card-action traffic to reach command dispatch in affected deployments.

## Imp…

GitHub-GHSA

CRITICAL
Arbitrary code execution in protobufjs
GHSA-xq3m-2v4x-88gg
pkg: protobufjs, protobufjs
eco: npm
published: Apr 16, 2026
### Summary
protobufjs compiles protobuf definitions into JS functions. Attackers can manipulate these definitions to execute arbitrary JS code.

### Details
Attackers can inject arbitrary code in the "type" fields of protobuf definitions, which will then execute during object decoding using that de…

CVE-2026-41242
GitHub-GHSA

CRITICAL
Flowise: Code Injection in CSVAgent leads to Authenticated RCE
GHSA-9wc7-mj3f-74xv
pkg: flowise, flowise-components
eco: npm
published: Apr 16, 2026
### Summary
The CSVAgent allows providing a custom Pandas CSV read code. Due to lack of sanitization, an attacker can provide the following payload: `DataFrame({'foo': ['bar!']});import os;os.system('whoami')` that will get interpolated and executed by the server.

### Details
The code in question t…

GitHub-GHSA

CRITICAL
Oxia has an OIDC token audience validation bypass via SkipClientIDCheck
GHSA-fhvp-9hcj-6m33
pkg: github.com/oxia-db/oxia
eco: go
published: Apr 14, 2026
### Summary
The OIDC authentication provider unconditionally sets `SkipClientIDCheck: true` in the `go-oidc` verifier configuration, disabling the standard audience (`aud`) claim validation at the library level. This allows tokens issued for unrelated services by the same OIDC issuer to be accepted …
GitHub-GHSA

CRITICAL
Decidim has a cross-site scripting (XSS) in user name
GHSA-fc46-r95f-hq7g
pkg: decidim-core, decidim-core
eco: rubygems
published: Apr 13, 2026
### Impact
A stored code execution vulnerability in the user name field allows a low-privileged attacker to execute arbitrary code in the context of any user who passively visits a comment page, resulting in high confidentiality and integrity impact across security boundaries.

### Patches
N/A

### …

CVE-2026-23891
GitHub-GHSA

HIGH
Paperclip: Privilege Escalation via Agent-Controlled workspaceStrategy.provisionCommand Leading to OS Command Execution
GHSA-265w-rf2w-cjh4
pkg: @paperclipai/server
eco: npm
published: Apr 16, 2026
### Summary
Paperclip contains a privilege escalation vulnerability that allows an attacker with an Agent API key to execute arbitrary OS commands on the Paperclip server host.
An attacker with an agent credential can escalate privileges from the agent runtime to the Paperclip server host.
The vulne…
GitHub-GHSA

HIGH
Unsafe object property setter in mathjs
GHSA-29qv-4j9f-fjw5
pkg: mathjs
eco: npm
published: Apr 16, 2026
### Impact
This security vulnerability allowed executing arbitrary JavaScript via the expression parser of mathjs. You can be affected when you have an application where users can evaluate arbitrary expressions using the mathjs expression parser.

### Patches
The issue was introduced in mathjs `v13.…

CVE-2026-40897
GitHub-GHSA

HIGH
ACME Lego: Arbitrary File Write via Path Traversal in Webroot HTTP-01 Provider
GHSA-qqx8-2xmm-jrv8
pkg: github.com/go-acme/lego/v4, github.com/go-acme/lego/v3, github.com/go-acme/lego
eco: go
published: Apr 16, 2026
### Summary

The webroot HTTP-01 challenge provider in lego is vulnerable to arbitrary file write and deletion via path traversal. A malicious ACME server can supply a crafted challenge token containing `../` sequences, causing lego to write attacker-influenced content to any path writable by the le…

CVE-2026-40611
GitHub-GHSA

HIGH
Weblate: Privilege escalation in the user API endpoint
GHSA-3382-gw9x-477v
pkg: weblate
eco: pip
published: Apr 16, 2026
### Impact

The user patching API endpoint didn't properly limit the scope of edits.

### Patches
* https://github.com/WeblateOrg/weblate/pull/18687

### References
Thanks to @tikket1 and @DavidCarliez for reporting this via GitHub. We received two individual reports for this.

CVE-2026-34393
GitHub-GHSA

HIGH
pyLoad has Stale Session Privilege After Role/Permission Change (Privilege Revocation Bypass)
GHSA-66hx-chf7-3332
pkg: pyload-ng
eco: pip
published: Apr 14, 2026
### Summary
pyLoad caches `role` and `permission` in the session at login and continues to authorize requests using these cached values, even after an admin changes the user's role/permissions in the database.

As a result, an already logged-in user can keep old (revoked) privileges until logout/ses…

GitHub-GHSA

HIGH
Emissary has an OS Command Injection via Unvalidated IN_FILE_ENDING / OUT_FILE_ENDING in Executrix
GHSA-3p24-9x7v-7789
pkg: gov.nsa.emissary:emissary
eco: maven
published: Apr 13, 2026
### Summary

`Executrix.getCommand()` constructs shell commands by substituting temporary file paths directly into a `/bin/sh -c` string with no escaping. The `IN_FILE_ENDING` and `OUT_FILE_ENDING` configuration keys flow into those paths unmodified. A place author who sets either key to a shell met…

CVE-2026-35582
GitHub-GHSA

HIGH
Apache Airflow: Unsafe Deserialization via Legacy Serialization Keys (__type/__var) Bypass in XCom API
GHSA-mc4f-r875-v87w
pkg: apache-airflow
eco: pip
published: Apr 13, 2026
Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low.

Users are recommended to upgrade to Apache Airflow 3.2.0, whi…

CVE-2026-33858
GitHub-GHSA

HIGH
Keras has an untrusted deserialization vulnerability
GHSA-4f3f-g24h-fr8m
pkg: keras
eco: pip
published: Apr 13, 2026
A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during deserialization of `.keras` models, even when `safe_mode=True`. This bypasses the security guarantees of `safe_mode` and enables arbitrary attacker-c…
CVE-2026-1462
GitHub-GHSA

HIGH
Apache Storm: Deserialization of Untrusted Data vulnerability
GHSA-jf89-3q6q-vcgr
pkg: org.apache.storm:storm-client
eco: maven
published: Apr 13, 2026
Deserialization of Untrusted Data vulnerability in Apache Storm.

Versions Affected:
before 2.8.6.

Description:
When processing topology credentials submitted via the Nimbus Thrift API, Storm deserializes the base64-encoded TGT blob using ObjectInputStream.readObject() without any class filtering …

CVE-2026-35337
GitHub-GHSA

HIGH
pretalx vulnerable to stored cross-site scripting in organizer search typeahead
GHSA-cjcx-jfp2-f7m2
pkg: pretalx
eco: pip
published: Apr 18, 2026
The organiser search in the pretalx backend rendered submission titles, speaker display names, and user names/emails into the result dropdown using `innerHTML` string interpolation. Any user who controls one of those fields (which includes any registered user whose display name is looked up by an ad…
GitHub-GHSA

HIGH
Paperclip: codex_local inherited ChatGPT/OpenAI-connected Gmail and was able to send real email
GHSA-gqqj-85qm-8qhf
pkg: paperclipai
eco: npm
published: Apr 16, 2026
### Summary

A Paperclip-managed `codex_local` runtime was able to access and use a Gmail connector that I had connected in the ChatGPT/OpenAI apps UI, even though I had not explicitly connected Gmail inside Paperclip or separately inside Codex.

In my environment this enabled mailbox access and a r…

GitHub-GHSA

HIGH
Stored XSS in SEO Fields Leads to Authenticated API Data Exposure in ApostropheCMS
GHSA-855c-r2vq-c292
pkg: apostrophe
eco: npm
published: Apr 16, 2026
## Summary

A stored cross-site scripting (XSS) vulnerability exists in SEO-related fields (SEO Title and Meta Description) in ApostropheCMS.

Improper neutralization of user-controlled input in SEO-related fields allows injection of arbitrary JavaScript into HTML contexts, resulting in stored cross…

CVE-2026-35569
GitHub-GHSA

HIGH
Note Mark has Stored XSS via Unrestricted Asset Upload
GHSA-9pr4-rf97-79qh
pkg: github.com/enchant97/note-mark/backend
eco: go
published: Apr 13, 2026
### Summary
A stored same-origin XSS vulnerability allows any authenticated user to upload an HTML, SVG, or XHTML file as a note asset and have it executed in a victim’s browser under the application’s origin. Because the application serves these files inline without a safe content type and with…
CVE-2026-40262
GitHub-GHSA

HIGH
Kyverno has SSRF via CEL http.Get/http.Post in NamespacedValidatingPolicy allows cross-namespace data access
GHSA-rggm-jjmc-3394
pkg: github.com/kyverno/kyverno
eco: go
published: Apr 14, 2026
## Summary

A Server-Side Request Forgery (SSRF) vulnerability in Kyverno's CEL HTTP library (`pkg/cel/libs/http/`) allows users with namespace-scoped policy creation permissions to make arbitrary HTTP requests from the Kyverno admission controller. This enables unauthorized access to internal servi…

CVE-2026-4789
GitHub-GHSA

HIGH
OpenTelemetry eBPF Instrumentation: Privileged Java agent injection allows arbitrary host file overwrite via untrusted TMPDIR
GHSA-8gmg-3w2q-65f4
pkg: go.opentelemetry.io/obi
eco: go
published: Apr 17, 2026
### Summary

A flaw in the Java agent injection path allows a local attacker controlling a Java workload to overwrite arbitrary host files when Java injection is enabled and OBI is running with elevated privileges. The injector trusted `TMPDIR` from the target process and used unsafe file creation s…

GitHub-GHSA

HIGH
Complete Bypass of CVE-2026-24884 Patch via Git-Delivered Symlink Poisoning in compressing
GHSA-4c3q-x735-j3r5
pkg: compressing, compressing
eco: npm
published: Apr 17, 2026
**1. Executive Summary**
This report documents a critical security research finding in the `compressing` npm package (specifically tested on the latest **v2.1.0**). The core vulnerability is a **Partial Fix Bypass** of **CVE-2026-24884**.

The current patch relies on a purely logical string validati…

CVE-2026-40931
GitHub-GHSA

HIGH
NietThijmen ShoppingCart: Command injection in the connect function
GHSA-ggmw-mjhv-75rm
pkg: github.com/NietThijmen/ShoppingCart
eco: go
published: Apr 15, 2026
Command injection in the connect function in NietThijmen ShoppingCart 0.0.2 allows an attacker to execute arbitrary shell commands and achieve remote code execution via injection of malicious payloads into the Port field
CVE-2024-53412
GitHub-GHSA

HIGH
Dagster Vulnerable to SQL Injection via Dynamic Partition Keys in Database I/O Manager Integrations
GHSA-mjw2-v2hm-wj34
pkg: dagster-duckdb, dagster-snowflake, dagster-gcp
eco: pip
published: Apr 18, 2026
### Summary

The DuckDB, Snowflake, BigQuery, and DeltaLake I/O managers constructed SQL WHERE clauses by interpolating dynamic partition key values into queries without escaping. A user with the `Add Dynamic Partitions` permission could create a partition key that injects arbitrary SQL, which would…

GitHub-GHSA

HIGH
Paperclip: Unauthenticated Access to Multiple API Endpoints in Authenticated Mode
GHSA-xfqj-r5qw-8g4j
pkg: @paperclipai/server
eco: npm
published: Apr 16, 2026
## Summary

Several API endpoints in `authenticated` mode have no authentication at all. They respond to completely unauthenticated requests with sensitive data or allow state-changing operations. No account, no session, no API key needed.

Verified against the latest version.

Discord: sagi03581

#…

GitHub-GHSA

HIGH
Flowise: Remote code execution vulnerability in AirtableAgent.ts caused by lack of input verification when using `Pandas`.
GHSA-f228-chmx-v6j6
pkg: flowise, flowise-components
eco: npm
published: Apr 16, 2026
## Description

### Summary

“AirtableAgent” is an agent function provided by FlowiseAI that retrieves search results by accessing private datasets from airtable.com. “AirtableAgent” uses Python, along with `Pyodide` and `Pandas`, to get and return results.

The user’s input is directly ap…

GitHub-GHSA

HIGH
OAuth2 Proxy has an Authentication Bypass via Fragment Confusion in skip_auth_routes and skip_auth_regex
GHSA-pxq7-h93f-9jrg
pkg: github.com/oauth2-proxy/oauth2-proxy/v7
eco: go
published: Apr 15, 2026
### Impact

A configuration-dependent authentication bypass exists in OAuth2 Proxy.

Deployments are affected when all of the following are true:

* Use of `skip_auth_routes` or the legacy `skip_auth_regex` * Use of patterns that can be widened by attacker-controlled suffixes, such as `^/foo/.*/b…

GitHub-GHSA

HIGH
Maddy Mail Server has an LDAP Filter Injection via Unsanitized Username
GHSA-5835-4gvc-32pc
pkg: github.com/foxcpp/maddy
eco: go
published: Apr 13, 2026
### Summary

The `auth.ldap` module constructs LDAP search filters and DN strings by directly interpolating user-supplied usernames via `strings.ReplaceAll()` without any LDAP filter escaping. An attacker who can reach the SMTP submission (AUTH PLAIN) or IMAP LOGIN interface can inject arbitrary LDA…

CVE-2026-40193
GitHub-GHSA

HIGH
PraisonAI: SQL Injection via unvalidated `table_prefix` in 9 conversation store backends (incomplete fix for CVE-2026-40315)
GHSA-rg3h-x3jw-7jm5
pkg: praisonai, praisonaiagents
eco: pip
published: Apr 17, 2026
The fix for [CVE-2026-40315](https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-x783-xp3g-mqhp) added input validation to `SQLiteConversationStore` only. Nine sibling backends — MySQL, PostgreSQL, async SQLite/MySQL/PostgreSQL, Turso, SingleStore, Supabase, SurrealDB — pass `tab…
GitHub-GHSA

HIGH
Dapr: Service Invocation path traversal ACL bypass
GHSA-85gx-3qv6-4463
pkg: github.com/dapr/dapr, github.com/dapr/dapr, github.com/dapr/dapr
eco: go
published: Apr 17, 2026
### Summary

A vulnerability has been found in Dapr that allows bypassing access control policies for service invocation using reserved URL characters and path traversal sequences in method paths. The ACL normalized the method path independently from the dispatch layer, so the ACL evaluated one path…

GitHub-GHSA

HIGH
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service
GHSA-m2w4-8ggf-rj47
pkg: github.com/hashicorp/vault
eco: go
published: Apr 17, 2026
An authenticated user with access to a kvv2 path through a policy containing a glob may be able to delete secrets they were not authorized to read or write, resulting in denial-of-service. This vulnerability did not allow a malicious user to delete secrets across namespaces, nor read any secret data…
CVE-2026-3605
GitHub-GHSA

HIGH
Flowise: Improper Mass Assignment in Account Registration Enables Unauthorized Organization Association
GHSA-48m6-ch88-55mj
pkg: flowise
eco: npm
published: Apr 16, 2026
### Summary

An improper mass assignment (JSON injection) vulnerability in the account registration endpoint of Flowise Cloud allows unauthenticated attackers to inject server-managed fields and nested objects during account creation. This enables client-controlled manipulation of ownership metadata…

GitHub-GHSA

HIGH
Kyverno: ServiceAccount token leaked to external servers via apiCall service URL
GHSA-f9g8-6ppc-pqq4
pkg: github.com/kyverno/kyverno
eco: go
published: Apr 16, 2026
## Summary

Kyverno's apiCall feature in ClusterPolicy automatically attaches the admission controller's ServiceAccount token to outgoing HTTP requests. The service URL has no validation — it can point anywhere, including attacker-controlled servers. Since the admission controller SA has permissio…

GitHub-GHSA

HIGH
OmniFaces: EL injection via crafted resource name in wildcard CDN mapping
GHSA-vp6r-9m58-5xv8
pkg: org.omnifaces:omnifaces, org.omnifaces:omnifaces, org.omnifaces:omnifaces
eco: maven
published: Apr 16, 2026
### Impact

Server-side EL injection leading to Remote Code Execution (RCE). Affects applications that use `CDNResourceHandler` with a wildcard CDN mapping (e.g. `libraryName:*=https://cdn.example.com/*`). An attacker can craft a resource request
URL containing an EL expression in the resource name,…

GitHub-GHSA

HIGH
Weblate: Remote code execution during backup restoration
GHSA-558g-h753-6m33
pkg: weblate
eco: pip
published: Apr 16, 2026
### Impact
The project backup didn't filter Git and Mercurial configuration files and this could lead to remote code execution under certain circumstances.

### Patches
* https://github.com/WeblateOrg/weblate/pull/18549

### Workarounds
The project backup is only accessible to users who can create p…

CVE-2026-33435
GitHub-GHSA

HIGH
Apache Airflow: RCE by race condition in example_xcom dag
GHSA-q2hg-643c-gw8h
pkg: apache-airflow
eco: pip
published: Apr 16, 2026
The example example_xcom that was included in airflow documentation implemented unsafe pattern of reading value
from xcom in the way that could be exploited to allow UI user who had access to modify XComs to perform arbitrary
execution of code on the worker. Since the UI users are already highly tr…
CVE-2025-54550
GitHub-GHSA

HIGH
Velociraptor vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token
GHSA-hv5g-26jg-pc45
pkg: www.velocidex.com/golang/velociraptor
eco: go
published: Apr 15, 2026
Velociraptor versions prior to 0.76.3 contain a vulnerability in the query() plugin which allows access to all orgs with the user's current ACL token. This allows an authenticated GUI user with access in one org, to use the query() plugin, in a notebook cell, to run VQL queries on other orgs which t…
CVE-2026-6290
GitHub-GHSA

HIGH
kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token
GHSA-q93q-v844-jrqp
pkg: github.com/kyverno/kyverno
eco: go
published: Apr 14, 2026
kyverno’s apiCall servicecall helper implicitly injects `Authorization: Bearer …` using the kyverno controller serviceaccount token when a policy does not explicitly set an Authorization header. because `context.apiCall.service.url` is policy-controlled, this can send the kyverno serviceaccount …
CVE-2026-40868
GitHub-GHSA

HIGH
Flowise: Parameter Override Bypass Remote Command Execution
GHSA-cvrr-qhgw-2mm6
pkg: flowise, flowise-components
eco: npm
published: Apr 16, 2026
### Summary

Flowise is vulnerable to a critical unauthenticated remote command execution (RCE) vulnerability. It can be exploited via a parameter override bypass using the `FILE-STORAGE::` keyword combined with a `NODE_OPTIONS` environment variable injection. This allows for the execution of arbitr…

GitHub-GHSA

HIGH
Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak)
GHSA-8wfp-579w-6r25
pkg: github.com/kyverno/kyverno
eco: go
published: Apr 16, 2026
### Summary
Kyverno's apiCall service mode automatically attaches the admission controller's ServiceAccount (SA) token to outbound HTTP requests. This results in unintended credential exposure when requests are sent to external or attacker-controlled endpoints.

The behavior is insecure-by-default a…

GitHub-GHSA

HIGH
Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix)
GHSA-cvq5-hhx3-f99p
pkg: github.com/kyverno/kyverno
eco: go
published: Apr 16, 2026
### Summary

CVE-2026-22039 fixed cross-namespace privilege escalation in Kyverno's `apiCall` context by validating the `URLPath` field. However, the **ConfigMap context loader has the identical vulnerability** — the `configMap.namespace` field accepts any namespace with zero validation, allowing …

GitHub-GHSA

HIGH
Weblate: Arbitrary File Read via Symlink
GHSA-hv99-mxm5-q397
pkg: weblate
eco: pip
published: Apr 16, 2026
### Impact

The ZIP download feature didn't verify downloaded file and it could follow symlinks outside the repository.

### Patches

* https://github.com/WeblateOrg/weblate/pull/18683

### References

Thanks to @DavidCarliez for reporting this vulnerability via GitHub.

CVE-2026-34242
GitHub-GHSA

HIGH
OpenStack Keystone: LDAP identity backend does not convert enabled attribute to boolean
GHSA-pfx2-9x9m-7ghx
pkg: keystone
eco: pip
published: Apr 14, 2026
In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean conversion when user_e…
CVE-2026-40683
GitHub-GHSA

HIGH
Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach
GHSA-fmqp-4wfc-w3v7
pkg: github.com/kyverno/kyverno
eco: go
published: Apr 14, 2026
### Summary

Kyverno's APICall feature contains a Server-Side Request Forgery (SSRF) vulnerability that allows users with Policy creation permissions to access arbitrary internal resources through Kyverno's high-privilege ServiceAccount. In multi-tenant Kubernetes environments, this constitutes a cl…

GitHub-GHSA

HIGH
Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF
GHSA-qr4g-8hrp-c4rw
pkg: github.com/kyverno/kyverno
eco: go
published: Apr 14, 2026
### Summary
A Server-Side Request Forgery (SSRF) vulnerability in Kyverno allows authenticated users to induce the admission controller to send arbitrary HTTP requests to attacker-controlled endpoints.

When a `ClusterPolicy` uses `apiCall.service.url` with variable substitution (e.g. `{{request.obj…

GitHub-GHSA

HIGH
wger has Broken Access Control in Global Gym Configuration Update Endpoint
GHSA-xppv-4jrx-qf8m
pkg: wger
eco: pip
published: Apr 16, 2026
## Summary

wger exposes a global configuration edit endpoint at `/config/gym-config/edit` implemented by `GymConfigUpdateView`. The view declares `permission_required = 'config.change_gymconfig'` but does not enforce it because it inherits `WgerFormMixin` (ownership-only checks) instead of the proj…

CVE-2026-40474
GitHub-GHSA

HIGH
OpenRemote has XXE in Velbus Asset Import
GHSA-g24f-mgc3-jwwc
pkg: io.openremote:openremote-manager
eco: maven
published: Apr 15, 2026
### Summary
The Velbus asset import path parses attacker-controlled XML without explicit XXE hardening. An authenticated user who can call the import endpoint may trigger XML external entity processing, which can lead to server-side file disclosure and SSRF. The target file must be less than 1023 ch…
CVE-2026-40882
GitHub-GHSA

HIGH
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations
GHSA-88v5-9hxc-f85r
pkg: github.com/hashicorp/vault
eco: go
published: Apr 17, 2026
Vault is vulnerable to a denial-of-service condition where an unauthenticated attacker can repeatedly initiate or cancel root token generation or rekey operations, occupying the single in-progress operation slot. This prevents legitimate operators from completing these workflows. This vulnerability,…
CVE-2026-5807
GitHub-GHSA

HIGH
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization
GHSA-72gw-fmmr-c4r4
pkg: github.com/hashicorp/vault
eco: go
published: Apr 17, 2026
If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vault forwarded the Vault token to the auth plugin backend. Fixed in 2.0.0, 1.21.5, 1.20.10, and 1.19.16.
CVE-2026-4525
GitHub-GHSA

HIGH
Meridian: Multiple defense-in-depth gaps (collection/depth caps, telemetry, retry, fan-out)
GHSA-f5v8-v6q3-q4h6
pkg: Meridian.Mapping, Meridian.Mediator
eco: nuget
published: Apr 16, 2026
## Summary

Meridian v2.1.0 (`Meridian.Mapping` and `Meridian.Mediator`) shipped with nine defense-in-depth gaps reachable through its public APIs. Two are HIGH severity — the advertised `DefaultMaxCollectionItems` and `DefaultMaxDepth` safety caps are silently bypassed on the `IMapper.Map(source,…

GitHub-GHSA

HIGH
basic-ftp vulnerable to denial of service via unbounded memory consumption in Client.list()
GHSA-rp42-5vxx-qpwr
pkg: basic-ftp
eco: npm
published: Apr 16, 2026
### Summary
`basic-ftp@5.2.2` is vulnerable to denial of service through unbounded memory growth while processing directory listings from a remote FTP server. A malicious or compromised server can send an extremely large or never-ending listing response to `Client.list()`, causing the client process…
GitHub-GHSA

HIGH
PsiTransfer: Upload PATCH path traversal can create `config.<NODE_ENV>.js` and lead to code execution on restart
GHSA-533q-w4g6-5586
pkg: psitransfer
eco: npm
published: Apr 16, 2026
### Summary

The upload PATCH flow under `/files/:uploadId` validates the mounted request path using the still-encoded `req.path`, but the downstream tus handler later writes using the decoded `req.params.uploadId`. In deployments that use a supported custom `PSITRANSFER_UPLOAD_DIR` whose basename p…

GitHub-GHSA

HIGH
zrok: Unauthenticated DoS via unbounded memory allocation in striped session cookie parsing
GHSA-cpf9-ph2j-ccr9
pkg: github.com/openziti/zrok, github.com/openziti/zrok/v2
eco: go
published: Apr 16, 2026
**Summary**
endpoints.GetSessionCookie parses an attacker-supplied cookie chunk count and calls make([]string, count) with no upper bound before any token validation occurs. The function is reached on every request to an OAuth-protected proxy share, allowing an unauthenticated remote attacker to tri…
CVE-2026-40303
GitHub-GHSA

HIGH
SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information
GHSA-27h3-crw2-q36w
pkg: org.apache.skywalking:server-core
eco: maven
published: Apr 16, 2026
The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of MySQL/PostgreSQL.

This issue affects Apache SkyWalking: from 9.7.0 through 10.3.0.

Users are recommended to upgrade to version 10.4.0, which fixes the issue.

CVE-2026-30778
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-26171 – .NET Denial of Service Vulnerability
GHSA-w3x6-4m5h-cxqf
pkg: System.Security.Cryptography.Xml, System.Security.Cryptography.Xml, System.Security.Cryptography.Xml
eco: nuget
published: Apr 14, 2026
## Executive Summary:

Microsoft is releasing this security advisory to provide information about a vulnerability in System.Security.Cryptography.Xml. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A vulnerability exists in…

CVE-2026-26171
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-33116 – .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
GHSA-37gx-xxp4-5rgx
pkg: System.Security.Cryptography.Xml, System.Security.Cryptography.Xml, System.Security.Cryptography.Xml
eco: nuget
published: Apr 14, 2026
## Executive Summary:

Microsoft is releasing this security advisory to provide information about a vulnerability in System.Security.Cryptography.Xml. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A vulnerability exists in…

CVE-2026-33116
GitHub-GHSA

HIGH
Go Markdown has an Out-of-bounds Read in SmartypantsRenderer
GHSA-77fj-vx54-gvh7
pkg: github.com/gomarkdown/markdown
eco: go
published: Apr 14, 2026
### Summary

Processing a malformed input containing a `<` character that is not followed by a `>` character anywhere in the remaining text with a SmartypantsRenderer will lead to Out of Bounds read or a panic.

### Details

The `smartLeftAngle()` function in `html/smartypants.go:367-376` performs a…

CVE-2026-40890
GitHub-GHSA

HIGH
Decidim's comments API allows access to all commentable resources
GHSA-ghmh-q25g-gxxx
pkg: decidim-comments, decidim-api, decidim-comments
eco: rubygems
published: Apr 14, 2026
### Impact
The root level `commentable` field in the API allows access to all commentable resources within the platform, without any permission checks. All Decidim instances are impacted that have not secured the `/api` endpoint. The `/api` endpoint is publicly available with the default configurati…
CVE-2026-40870
GitHub-GHSA

HIGH
Decidim amendments can be accepted or rejected by anyone
GHSA-w5xj-99cg-rccm
pkg: decidim-core, decidim-core
eco: rubygems
published: Apr 14, 2026
### Impact
The vulnerability allows any registered and authenticated user to accept or reject any amendments. The impact is on any users who have created proposals where the amendments feature is enabled. This also elevates the user accepting the amendment as the author of the original proposal as p…
CVE-2026-40869
GitHub-GHSA

HIGH
free5gc UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authentication
GHSA-wrwh-rpq4-87hf
pkg: github.com/free5gc/udr
eco: go
published: Apr 14, 2026
### Summary
An information disclosure vulnerability in the UDR service allows any unauthenticated attacker with access to the 5G Service Based Interface (SBI) to retrieve stored subscriber identifiers (SUPI/IMSI) with a single HTTP GET request requiring no parameters or credentials.

### Details
Th…

CVE-2026-40245
GitHub-GHSA

HIGH
ImageMagick has a heap Buffer Overflow in ImageMagick MVG decoder
GHSA-x9h5-r9v2-vcww
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Apr 14, 2026
A heap buffer overflow occurs in the MVG decoder that could result in an out of bounds write when processing a crafted image.
CVE-2026-33901
GitHub-GHSA

HIGH
ImageMagick has a Stack Overflow in DestroyXMLTree()
GHSA-fwvm-ggf6-2p4x
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Apr 14, 2026
Magick frees the memory of the XML tree via the `DestroyXMLTree` function; however, this process is executed recursively with no depth limit imposed. When magick processes an XML file with deeply nested structures, it will exhaust the stack memory, resulting in a Denial of Service (DoS) attack.
CVE-2026-33908
GitHub-GHSA

HIGH
@fastify/middie vulnerable to middleware bypass via deprecated ignoreDuplicateSlashes option
GHSA-v9ww-2j6r-98q6
pkg: @fastify/middie
eco: npm
published: Apr 16, 2026
### Impact

`@fastify/middie` v9.3.1 and earlier does not read the deprecated (but still functional) top-level `ignoreDuplicateSlashes` option, only reading from `routerOptions`. This creates a normalization gap: Fastify's router normalizes duplicate slashes but middie does not, allowing middleware …

CVE-2026-33804
GitHub-GHSA

HIGH
Jetty has HTTP Request Smuggling via Chunked Extension Quoted-String Parsing
GHSA-355h-qmc2-wpwf
pkg: org.eclipse.jetty:jetty-http, org.eclipse.jetty:jetty-http, org.eclipse.jetty:jetty-http
eco: maven
published: Apr 14, 2026
### Description (as reported)

Jetty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks.

### Background

This vulnerability is a new variant discovered while researching the "Funky Chunks" HTTP request smuggling techniques:
-…

CVE-2026-2332
GitHub-GHSA

HIGH
Eclipse Jetty: Early return from the JASPIAuthenticator code can potentially no clear ThreadLocal variables
GHSA-r7p8-xq5m-436c
pkg: org.eclipse.jetty.ee11:jetty-ee11-jaspi, org.eclipse.jetty.ee10:jetty-ee10-jaspi, org.eclipse.jetty.ee9:jetty-ee9-jaspi
eco: maven
published: Apr 14, 2026
### Description (as reported)

A security vulnerability has been identified in Jetty's `JaspiAuthenticator.java`.

The root cause is a failure to consistently clear authentication metadata stored in `ThreadLocal` during certain error or incomplete authentication flows.
Specifically, after a `Gr…

CVE-2026-5795
GitHub-GHSA

HIGH
Paperclip: Malicious skills able to exfiltrate and destroy all user data
GHSA-w8hx-hqjv-vjcq
pkg: @paperclipai/server
eco: npm
published: Apr 16, 2026
### Summary
An arbitrary code execution vulnerability in the workspace runtime service allows any agent to execute shell commands on the server, exposing all environment variables including API keys, JWT secrets, and database credentials.

### Details
A malicious skill can instruct the agent to expl…

GitHub-GHSA

HIGH
thin-vec: Use-After-Free and Double Free in IntoIter::drop When Element Drop Panics
GHSA-xphw-cqx3-667j
pkg: thin-vec
eco: rust
published: Apr 15, 2026
### Summary

A **Double Free / Use-After-Free (UAF)** vulnerability has been identified in the `IntoIter::drop` and `ThinVec::clear` implementations of the `thin_vec` crate.
Both vulnerabilities share the same root cause and can trigger memory corruption using only safe Rust code — no `unsafe` blo…

GitHub-GHSA

HIGH
Flowise: APIChain Prompt Injection SSRF in GET/POST API Chains
GHSA-6r77-hqx7-7vw8
pkg: flowise, flowise-components
eco: npm
published: Apr 16, 2026
### Summary
A Server-Side Request Forgery (SSRF) vulnerability exists in FlowiseAI's POST/GET API Chain components that allows unauthenticated attackers to force the server to make arbitrary HTTP requests to internal and external systems. By injecting malicious prompt templates, attackers can bypass…
GitHub-GHSA

HIGH
Flowise: SSRF Protection Bypass (TOCTOU & Default Insecure)
GHSA-2x8m-83vc-6wv4
pkg: flowise, flowise-components
eco: npm
published: Apr 16, 2026
### Summary
The core security wrappers (secureAxiosRequest and secureFetch) intended to prevent Server-Side Request Forgery (SSRF) contain multiple logic flaws. These flaws allow attackers to bypass the allow/deny lists via DNS Rebinding (Time-of-Check Time-of-Use) or by exploiting the default confi…
GitHub-GHSA

HIGH
Flowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function Sandbox
GHSA-xhmj-rg95-44hv
pkg: flowise, flowise-components
eco: npm
published: Apr 16, 2026
### Summary
A Server-Side Request Forgery (SSRF) protection bypass vulnerability exists in the Custom Function feature. While the application implements SSRF protection via HTTP_DENY_LIST for axios and node-fetch libraries, the built-in Node.js `http`, `https`, and `net` modules are allowed in the N…
GitHub-GHSA

HIGH
Flowise: File Upload Validation Bypass in createAttachment
GHSA-rh7v-6w34-w2rr
pkg: flowise
eco: npm
published: Apr 16, 2026
### Summary
In FlowiseAI, the Chatflow configuration file upload settings can be modified to allow the application/javascript MIME type. This lets an attacker upload .js files even though the frontend doesn’t normally allow JavaScript uploads. This enables attackers to persistently store malicious…
GitHub-GHSA

HIGH
Zarf has a Path Traversal via Malicious Package Metadata.Name — Arbitrary File Write
GHSA-pj97-4p9w-gx3q
pkg: github.com/zarf-dev/zarf
eco: go
published: Apr 14, 2026
### Impact
This vulnerability impacts users of `zarf package inspect sbom` or `zarf package inspect documentation` on untrusted packages.

### Patches
#4793, now fixed in version v0.74.2

### Workarounds
Avoid inspecting unsigned packages

## Description

The `package inspect sbom` and `package insp…

CVE-2026-40090
GitHub-GHSA

HIGH
Apache SkyWalking MCP: Server-Side Request Forgery via SW-URL Header in MCP Server
GHSA-c4hg-6933-x62x
pkg: github.com/apache/skywalking-mcp
eco: go
published: Apr 13, 2026
Server-Side Request Forgery via SW-URL Header vulnerability in Apache SkyWalking MCP.

This issue affects Apache SkyWalking MCP: 0.1.0.

Users are recommended to upgrade to version 0.2.0, which fixes this issue.

CVE-2026-34476
GitHub-GHSA

HIGH
Zebra: Cached Mempool Verification Bypasses Consensus Rules for Ahead-of-Tip Blocks
GHSA-xvj8-ph7x-65gf
pkg: zebra-consensus, zebrad
eco: rust
published: Apr 18, 2026
# CVE-2026-40880: Cached Mempool Verification Bypasses Consensus Rules for Ahead-of-Tip Blocks

## Summary

A logic error in Zebra's transaction verification cache could allow a malicious miner to induce a consensus split. By carefully submitting a transaction that is valid for height `H+1` but inva…

CVE-2026-40880
GitHub-GHSA

HIGH
OpenClaw: Webchat media embedding enforces local-root containment for tool-result files
GHSA-mr34-9552-qr95
pkg: openclaw
eco: npm
published: Apr 17, 2026
## Summary

Webchat tool-result media normalization could pass local and UNC-style file paths into the host-side media embedding path without applying the configured local-root containment policy.

## Impact

A crafted tool-result media reference could cause the host to attempt local file reads or W…

GitHub-GHSA

HIGH
OpenClaw: Matrix room control-command authorization no longer trusts DM pairing-store entries
GHSA-2gvc-4f3c-2855
pkg: openclaw
eco: npm
published: Apr 17, 2026
## Summary

Matrix room control-command authorization used the effective allowlist for room traffic, which included sender IDs learned from the Matrix DM pairing store. A sender who was allowed only for a Matrix DM could therefore authorize room control commands when they also posted in a bot room.

GitHub-GHSA

HIGH
OpenClaw: Gateway HTTP endpoints re-resolve bearer auth after SecretRef rotation
GHSA-xmxx-7p24-h892
pkg: openclaw
eco: npm
published: Apr 17, 2026
## Summary

Gateway HTTP and WebSocket handlers captured the resolved bearer-auth configuration when the server started. After a SecretRef rotation, the already-running gateway could continue accepting the old bearer token until restart.

## Impact

A bearer token that should have been revoked by Se…

GitHub-GHSA

HIGH
OpenClaw: QQBot media tags could read arbitrary local files through reply text
GHSA-66r7-m7xm-v49h
pkg: openclaw
eco: npm
published: Apr 17, 2026
## Summary

QQBot media tags could read arbitrary local files through reply text.

## Affected Packages / Versions

– Package: `openclaw`
– Ecosystem: npm
– Affected versions: `< 2026.4.10`
– Patched versions: `>= 2026.4.10`

## Impact

QQBot outbound media tags in AI reply text could reference host…

GitHub-GHSA

HIGH
OpenClaw: busybox and toybox applet execution weakened exec approval binding
GHSA-2cq5-mf3v-mx44
pkg: openclaw
eco: npm
published: Apr 17, 2026
## Summary

busybox and toybox applet execution weakened exec approval binding.

## Affected Packages / Versions

– Package: `openclaw`
– Ecosystem: npm
– Affected versions: `>= 2026.2.23 < 2026.4.12`
– Patched versions: `>= 2026.4.12`

## Impact

Opaque multi-call binaries such as `busybox` and `to…

GitHub-GHSA

HIGH
OpenClaw: Matrix profile config persistence was reachable from operator.write message tools
GHSA-7jp6-r74r-995q
pkg: openclaw
eco: npm
published: Apr 17, 2026
## Summary

Matrix profile config persistence was reachable from operator.write message tools.

## Affected Packages / Versions

– Package: `openclaw`
– Ecosystem: npm
– Affected versions: `< 2026.4.10`
– Patched versions: `>= 2026.4.10`

## Impact

Gateway `operator.write` message-tool paths could …

GitHub-GHSA

HIGH
OpenClaw: Sandboxed agents could escape exec routing via host=node override
GHSA-736r-jwj6-4w23
pkg: openclaw
eco: npm
published: Apr 17, 2026
## Summary

Sandboxed agents could escape exec routing via host=node override.

## Affected Packages / Versions

– Package: `openclaw`
– Ecosystem: npm
– Affected versions: `>= 2026.4.5 < 2026.4.10`
– Patched versions: `>= 2026.4.10`

## Impact

A sandboxed agent could request `host: "node"` and rou…

GitHub-GHSA

HIGH
OpenClaw: Workspace provider auth choices could auto-enable untrusted provider plugins
GHSA-939r-rj45-g2rj
pkg: openclaw
eco: npm
published: Apr 17, 2026
## Summary

Workspace provider auth choices could auto-enable untrusted provider plugins.

## Affected Packages / Versions

– Package: `openclaw`
– Ecosystem: npm
– Affected versions: `< 2026.4.9`
– Patched versions: `>= 2026.4.9`

## Impact

Non-interactive onboarding could select a provider auth c…

GitHub-GHSA

HIGH
OpenClaw: Sandbox browser CDP relay could expose DevTools protocol on 0.0.0.0
GHSA-525j-hqq2-66r4
pkg: openclaw
eco: npm
published: Apr 17, 2026
## Summary

Sandbox browser CDP relay could expose DevTools protocol on 0.0.0.0.

## Affected Packages / Versions

– Package: `openclaw`
– Ecosystem: npm
– Affected versions: `< 2026.4.10`
– Patched versions: `>= 2026.4.10`

## Impact

The sandbox browser CDP relay could bind too broadly, exposing C…

GitHub-GHSA

HIGH
OpenClaw: Channel setup catalog lookups could include untrusted workspace plugin shadows
GHSA-82qx-6vj7-p8m2
pkg: openclaw
eco: npm
published: Apr 17, 2026
## Summary

Channel setup catalog lookups could include untrusted workspace plugin shadows.

## Affected Packages / Versions

– Package: `openclaw`
– Ecosystem: npm
– Affected versions: `< 2026.4.10`
– Patched versions: `>= 2026.4.10`

## Impact

Channel setup could resolve a workspace plugin shadow…

GitHub-GHSA

HIGH
OpenClaw: Exec environment denylist missed high-risk interpreter startup variables
GHSA-vfp4-8×56-j7c5
pkg: openclaw
eco: npm
published: Apr 17, 2026
## Summary

Exec environment denylist missed high-risk interpreter startup variables.

## Affected Packages / Versions

– Package: `openclaw`
– Ecosystem: npm
– Affected versions: `< 2026.4.10`
– Patched versions: `>= 2026.4.10`

## Impact

The exec environment policy missed interpreter startup vari…

GitHub-GHSA

HIGH
OpenClaw: Voice-call realtime WebSocket accepted oversized frames
GHSA-vw3h-q6xq-jjm5
pkg: openclaw
eco: npm
published: Apr 17, 2026
## Summary

Voice-call realtime WebSocket accepted oversized frames.

## Affected Packages / Versions

– Package: `openclaw`
– Ecosystem: npm
– Affected versions: `>= 2026.4.9 < 2026.4.10`
– Patched versions: `>= 2026.4.10`

## Impact

The voice-call realtime WebSocket path could accept oversized fr…

GitHub-GHSA

HIGH
OpenClaw: config.get redaction bypass through sourceConfig and runtimeConfig aliases
GHSA-8372-7vhw-cm6q
pkg: openclaw
eco: npm
published: Apr 17, 2026
## Summary

config.get redaction bypass through sourceConfig and runtimeConfig aliases.

## Affected Packages / Versions

– Package: `openclaw`
– Ecosystem: npm
– Affected versions: `< 2026.4.14`
– Patched versions: `>= 2026.4.14`

## Impact

An authenticated gateway client with config read access c…

GitHub-GHSA

HIGH
Flowise: Unauthenticated TTS endpoint accepts arbitrary credential IDs — enables API credit abuse via stored credentials
GHSA-5fw2-mwhh-9947
pkg: flowise
eco: npm
published: Apr 17, 2026
### Summary

The text-to-speech generation endpoint (`POST /api/v1/text-to-speech/generate`) is whitelisted (no auth) and accepts a `credentialId` directly in the request body. When called without a `chatflowId`, the endpoint uses the provided `credentialId` to decrypt the stored credential (e.g., O…

GitHub-GHSA

HIGH
Flowise: Public chatflow endpoints return unsanitized flowData including plaintext API keys, passwords, and credential IDs
GHSA-w47f-j8rh-wx87
pkg: flowise
eco: npm
published: Apr 17, 2026
### Summary

The `GET /api/v1/public-chatflows/:id` endpoint returns the full chatflow object **without sanitization** for public chatflows. Docker validation revealed this is worse than initially assessed: the `sanitizeFlowDataForPublicEndpoint` function does NOT exist in the released v3.0.13 Docke…

GitHub-GHSA

HIGH
Flowise: Mass Assignment in DocumentStore Create Endpoint Leads to Cross-Workspace Object Takeover (IDOR)
GHSA-3prp-9gf7-4rxx
pkg: flowise
eco: npm
published: Apr 17, 2026
### Summary
A Mass Assignment vulnerability in the DocumentStore creation endpoint allows authenticated users to control the primary key (id) and internal state fields of DocumentStore entities.

Because the service uses repository.save() with a client-supplied primary key, the POST create endpoint …

GitHub-GHSA

HIGH
Bouncy Castle Uncontrolled Resource Consumption vulnerability
GHSA-cj8j-37rh-8475
pkg: org.bouncycastle:bcpg-jdk12, org.bouncycastle:bcpg-jdk14, org.bouncycastle:bcpg-jdk15
eco: maven
published: Apr 17, 2026
Allocation of resources without limits or throttling vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpg on all (pg modules). This issue affects BC-JAVA before 1.84.

Unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion.

CVE-2026-3505
GitHub-GHSA

HIGH
PAC4J has a Cross-Site Request Forgery (CSRF) Vulnerability
GHSA-xw5c-jc7x-gf75
pkg: org.pac4j:pac4j-core, org.pac4j:pac4j-core
eco: maven
published: Apr 17, 2026
PAC4J is vulnerable to Cross-Site Request Forgery (CSRF). A malicious attacker can craft a specially designed website which, when visited by a user, will automatically submit a forged cross-site request with a token whose hash collides with the victim's legitimate CSRF token. Importantly, the attack…
CVE-2026-40458
GitHub-GHSA

HIGH
OAuth 2.1 Provider: Unprivileged users can register OAuth clients
GHSA-xr8f-h2gw-9xh6
pkg: @better-auth/oauth-provider, @better-auth/oauth-provider
eco: npm
published: Apr 16, 2026
### Summary
An authorization bypass in the OAuth provider allows any authenticated low-privilege user to create OAuth clients even when the deployment configures clientPrivileges to restrict client creation. The option contract explicitly includes a create action, but the create paths never invoke t…
GitHub-GHSA

HIGH
Angular: SSRF via protocol-relative and backslash URLs in Angular Platform-Server
GHSA-45q2-gjvg-7973
pkg: @angular/platform-server, @angular/platform-server, @angular/platform-server
eco: npm
published: Apr 16, 2026
### Impact

A [Server-Side Request Forgery (SSRF)](https://developer.mozilla.org/en-US/docs/Web/Security/Attacks/SSRF) vulnerability exists in `@angular/platform-server` due to improper handling of URLs during Server-Side Rendering (SSR).

When an attacker sends a request such as `GET /\evil.com/ HT…

GitHub-GHSA

HIGH
Flowise: resetPassword Authentication Bypass Vulnerability
GHSA-f6hc-c5jr-878p
pkg: flowise
eco: npm
published: Apr 16, 2026
ZDI-CAN-28762: Flowise AccountService resetPassword Authentication Bypass Vulnerability

— ABSTRACT ————————————-

Trend Micro's Zero Day Initiative has identified a vulnerability affecting the following products:
Flowise – Flowise

— VULNERABILITY DETAILS —————–…

GitHub-GHSA

HIGH
Flowise: Cypher Injection in GraphCypherQAChain
GHSA-28g4-38q8-3cwc
pkg: flowise, flowise-components
eco: npm
published: Apr 16, 2026
## Summary

The GraphCypherQAChain node forwards user-provided input directly into the Cypher query execution pipeline without proper sanitization. An attacker can inject arbitrary Cypher commands that are executed on the underlying Neo4j database, enabling data exfiltration, modification, or deleti…

GitHub-GHSA

HIGH
Flowise: Password Reset Link Sent Over Unsecured HTTP
GHSA-x5w6-38gp-mrqh
pkg: flowise
eco: npm
published: Apr 16, 2026
**Summary:**
The password reset functionality on [cloud.flowiseai.com](http://cloud.flowiseai.com/) sends a reset password link over the unsecured HTTP protocol instead of HTTPS. This behavior introduces the risk of a man-in-the-middle (MITM) attack, where an attacker on the same network as the user…
GitHub-GHSA

HIGH
Flowise: Unauthenticated OAuth 2.0 Access Token Disclosure via Public Chatflow in Flowise
GHSA-6f7g-v4pp-r667
pkg: flowise
eco: npm
published: Apr 16, 2026
### Summary
Flowise contains an authentication bypass vulnerability that allows an unauthenticated attacker to obtain OAuth 2.0 access tokens associated with a public chatflow.

By accessing a public chatflow configuration endpoint, an attacker can retrieve internal workflow data, including OAuth cr…

GitHub-GHSA

HIGH
Flowise: Sensitive Data Leak in public-chatbotConfig
GHSA-4jpm-cgx2-8h37
pkg: flowise
eco: npm
published: Apr 16, 2026
### Summary

`/api/v1/public-chatbotConfig/:id `ep exposes sensitive data including API keys, HTTP authorization headers and internal configuration without any authentication. An attacker with knowledge just of a chatflow UUID can retrieve credentials stored in password type fields and HTTP headers,…

GitHub-GHSA

HIGH
MCP-Framework: Unbounded memory allocation in readRequestBody allows denial of service via HTTP transport
GHSA-353c-v8x9-v7c3
pkg: mcp-framework
eco: npm
published: Apr 16, 2026
### Summary

The `readRequestBody()` function in `src/transports/http/server.ts` concatenates HTTP request body chunks into a string with no size limit, allowing a remote unauthenticated attacker to crash the server via memory exhaustion with a single large HTTP POST request.

### Details

**File:**…

CVE-2026-39313
GitHub-GHSA

HIGH
SpdyStream: DOS on CRI
GHSA-pc3f-x583-g7j2
pkg: github.com/moby/spdystream
eco: go
published: Apr 16, 2026
The SPDY/3 frame parser in spdystream does not validate
attacker-controlled counts and lengths before allocating memory. A
remote peer that can send SPDY frames to a service using spdystream can
cause the process to allocate gigabytes of memory with a small number of
malformed control frames, leadin…
CVE-2026-35469
GitHub-GHSA

HIGH
Uncontrolled resource consumption and loop with unreachable exit condition in facil.io and downstream iodine ruby gem
GHSA-2×79-gwq3-vxxm
pkg: iodine
eco: rubygems
published: Apr 14, 2026
### Summary
`fio_json_parse` can enter an infinite loop when it encounters a nested JSON value starting with `i` or `I`. The process spins in user space and pegs one CPU core at ~100% instead of returning a parse error. Because `iodine` vendors the same parser code, the issue also affects `iodine` w…
GitHub-GHSA

HIGH
MinIO has an Unauthenticated Object Write via Query-String Credential Signature Bypass in Unsigned-Trailer Uploads
GHSA-hv4r-mvr4-25vw
pkg: github.com/minio/minio
eco: go
published: Apr 14, 2026
### Impact

_What kind of vulnerability is it? Who is impacted?_

An authentication bypass vulnerability in MinIO's `STREAMING-UNSIGNED-PAYLOAD-TRAILER` code path
allows any user who knows a valid access key to write arbitrary objects to any bucket without knowing
the secret key or providing a valid…

GitHub-GHSA

HIGH
Kiota: Code Generation Literal Injection
GHSA-2hx3-vp6r-mg3f
pkg: kiota
eco: nuget
published: Apr 14, 2026
# Code Generation Literal Injection in Kiota

## Summary

Kiota versions **prior to 1.31.1** are affected by a code-generation literal injection vulnerability in multiple writer sinks (for example: serialization/deserialization keys, path/query parameter mappings, URL template metadata, enum/propert…

GitHub-GHSA

HIGH
Oxia's TLS CA certificate chain validation fails with multi-certificate PEM bundles
GHSA-7jrq-q4pq-rhm6
pkg: github.com/oxia-db/oxia
eco: go
published: Apr 14, 2026
### Summary
The `trustedCertPool()` function in the TLS configuration only parses the first PEM block from CA certificate files. When a CA bundle contains multiple certificates (e.g., intermediate + root CA), only the first certificate is loaded. This silently breaks certificate chain validation for…
GitHub-GHSA

HIGH
Oxia affected by server crash via race condition in session heartbeat handling
GHSA-5gqc-qhrj-9xw8
pkg: github.com/oxia-db/oxia
eco: go
published: Apr 14, 2026
### Summary
A race condition between session heartbeat processing and session closure can cause the server to panic with `send on closed channel`. The `heartbeat()` method uses a blocking channel send while holding a mutex, and under specific timing with concurrent `close()` calls, this can lead to …
GitHub-GHSA

HIGH
Oxia exposes bearer token in debug log messages on authentication failure
GHSA-pm7q-rjjx-979p
pkg: github.com/oxia-db/oxia
eco: go
published: Apr 14, 2026
### Summary
When OIDC authentication fails, the full bearer token is logged at DEBUG level in plaintext. If debug logging is enabled in production, JWT tokens are exposed in application logs and any connected log aggregation system.

### Impact
An attacker with access to application logs (e.g., via …

GitHub-GHSA

HIGH
goshs's public collaborator feed leaks .goshs ACL credentials and enables unauthorized access
GHSA-7h3j-592v-jcrp
pkg: github.com/patrickhener/goshs/v2
eco: go
published: Apr 14, 2026
### Summary
goshs leaks file-based ACL credentials through its public collaborator feed when the server is deployed without global basic auth. Requests to `.goshs`-protected folders are logged before authorization is enforced, and the collaborator websocket broadcasts raw request headers, including …
CVE-2026-40885
GitHub-GHSA

HIGH
SFTP root escape via prefix-based path validation in goshs
GHSA-5h6h-7rc9-3824
pkg: github.com/patrickhener/goshs, github.com/patrickhener/goshs/v2
eco: go
published: Apr 14, 2026
### Summary
goshs contains an SFTP root escape caused by prefix-based path validation. An authenticated SFTP user can read from and write to filesystem paths outside the configured SFTP root, which breaks the intended jail boundary and can expose or modify unrelated server files.

### Details
The SF…

CVE-2026-40876
GitHub-GHSA

HIGH
free5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence Subscriptions
GHSA-jgq2-qv8v-5cmj
pkg: github.com/free5gc/udr
eco: go
published: Apr 14, 2026
### Summary
An improper path validation vulnerability in the UDR service allows any unauthenticated attacker with access to the 5G Service Based Interface (SBI) to create or overwrite Traffic Influence Subscriptions by supplying an arbitrary value in place of the expected `subs-to-notify` path segme…
CVE-2026-40248
GitHub-GHSA

HIGH
free5gc UDR improper path validation allows unauthenticated access to Traffic Influence Subscriptions
GHSA-x5r2-r74c-3w28
pkg: github.com/free5gc/udr
eco: go
published: Apr 14, 2026
### Summary
An improper path validation vulnerability in the UDR service allows any unauthenticated attacker with access to the 5G Service Based Interface (SBI) to read Traffic Influence Subscriptions by supplying an arbitrary value in place of the expected `subs-to-notify` path segment.

### Detail…

CVE-2026-40247
GitHub-GHSA

HIGH
free5gc UDR improper path validation allows unauthenticated deletion of Traffic Influence Subscriptions
GHSA-g9cw-qwhf-24jp
pkg: github.com/free5gc/udr
eco: go
published: Apr 14, 2026
### Summary
An improper path validation vulnerability in the UDR service allows any unauthenticated attacker with access to the 5G Service Based Interface (SBI) to delete Traffic Influence Subscriptions by supplying an arbitrary value in place of the expected `subs-to-notify` path segment.

### Deta…

CVE-2026-40246
GitHub-GHSA

HIGH
SP1 V6 Recursion Circuit Row-Count Binding Gap
GHSA-63×8-x938-vx33
pkg: sp1_sdk, sp1_recursion_circuit, sp1_prover
eco: rust
published: Apr 14, 2026
## Summary

A soundness vulnerability in the SP1 V6 recursive shard verifier allows a malicious prover to construct a recursive proof from a shard proof that the native verifier would reject.

– **Affected versions:** `>= 6.0.0, <= 6.0.2`
– **Not affected:** SP1 V5 (all versions)
– **Severity:** Hig…

CVE-2026-40323
GitHub-GHSA

HIGH
MinIO has an Unauthenticated Object Write via Missing Signature Verification in Unsigned-Trailer Uploads
GHSA-9c4q-hq6p-c237
pkg: github.com/minio/minio
eco: go
published: Apr 14, 2026
### Impact

_What kind of vulnerability is it? Who is impacted?_

Two authentication bypass vulnerabilities in MinIO's `STREAMING-UNSIGNED-PAYLOAD-TRAILER` code path
allow any user who knows a valid access key to write arbitrary objects to any bucket without knowing
the secret key or providing a val…

GitHub-GHSA

HIGH
In monetr, unauthenticated Stripe webhook reads attacker-sized request bodies before signature validation
GHSA-v7xq-3wx6-fqc2
pkg: github.com/monetr/monetr
eco: go
published: Apr 14, 2026
### Summary

The public Stripe webhook endpoint fully reads the request body into memory before validating the Stripe signature. A remote unauthenticated attacker can send oversized POST bodies and cause substantial memory growth, leading to denial of service.

### Details

When Stripe webhooks are …

CVE-2026-40481
GitHub-GHSA

HIGH
FITS GZIP decompression bomb in Pillow
GHSA-whj4-6x5x-4v2j
pkg: pillow
eco: pip
published: Apr 13, 2026
### Impact
Pillow did not limit the amount of GZIP-compressed data read when decoding a FITS image, making it vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation).
CVE-2026-40192
GitHub-GHSA

HIGH
External Secrets Operator has DNS-based secret exfiltration via getHostByName in External Secrets v2 template engine
GHSA-r2pg-r6h7-crf3
pkg: github.com/external-secrets/external-secrets, github.com/external-secrets/external-secrets
eco: go
published: Apr 13, 2026
## Summary

The v2 template engine in `runtime/template/v2/template.go` imports Sprig’s `TxtFuncMap()` and removes `env` and `expandenv`, but leaves `getHostByName` available to user-controlled templates. Because ESO executes templates inside the controller process, an attacker who can create or …

CVE-2026-34984
GitHub-GHSA

MEDIUM
ImageMagick has has a stack-buffer-overflow in MNG encoder with oversized pallete
GHSA-98cp-rj9f-6v5g
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Apr 14, 2026
The patch for GHSA-7h7q-j33q-hvpf was incomplete and still allows a stack buffer overflow for the multi frame images.
GitHub-GHSA

MEDIUM
Keycloak: Arbitrary code execution via Stored Cross-Site Scripting (XSS) in organization selection login page
GHSA-m32f-8vh9-2hh3
pkg: org.keycloak:keycloak-services
eco: maven
published: Apr 14, 2026
A flaw was found in Keycloak, specifically in the organization selection login page. A remote attacker with `manage-realm` or `manage-organizations` administrative privileges can exploit a Stored Cross-Site Scripting (XSS) vulnerability. This flaw occurs because the `organization.alias` is placed in…
CVE-2026-37980
GitHub-GHSA

MEDIUM
Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository
GHSA-mqph-7h49-hqfm
pkg: weblate
eco: pip
published: Apr 16, 2026
### Impact
The translation memory API exposed unintended endpoints, which in turn didn't do proper access control.

### Patches
* https://github.com/WeblateOrg/weblate/pull/18516

### Workarounds
The CDN add-on is not enabled by default.

### References
Thanks to @spbavarva for reporting this respon…

CVE-2026-33220
GitHub-GHSA

MEDIUM
OAuth2 Proxy has an Authorization Bypass in Email Domain Validation via Malformed Multi-@ Email Claims
GHSA-c5c4-8r6x-56w3
pkg: github.com/oauth2-proxy/oauth2-proxy/v7
eco: go
published: Apr 15, 2026
### Impact

An authorization bypass exists in OAuth2 Proxy as part of the `email_domain` enforcement option. An attacker may be able to authenticate with an email claim such as `attacker@evil.com@company.com` and satisfy an allowed domain check for `company.com`, even though the claim is not a valid…

CVE-2026-40574
GitHub-GHSA

MEDIUM
AsyncHttpClient leaks authorization credentialsto untrusted domains on cross-origin redirects
GHSA-cmxv-58fp-fm3g
pkg: org.asynchttpclient:async-http-client
eco: maven
published: Apr 14, 2026
### Impact
When redirect following is enabled (followRedirect(true)), AsyncHttpClient forwards Authorization and Proxy-Authorization headers along with Realm credentials to arbitrary redirect targets regardless of domain, scheme, or port changes. This leaks credentials on cross-domain redirects and …
CVE-2026-40490
GitHub-GHSA

MEDIUM
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
GHSA-9j88-vvj5-vhgr
pkg: MailKit
eco: nuget
published: Apr 18, 2026
### Summary

A STARTTLS Response Injection vulnerability in MailKit allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal rea…

GitHub-GHSA

MEDIUM
Amazon EFS CSI Driver has mount option injection via unsanitized volumeHandle and mounttargetip fields
GHSA-mph4-q2vm-w2pw
pkg: github.com/kubernetes-sigs/aws-efs-csi-driver
eco: go
published: Apr 18, 2026
### Summary
The Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. An issue exists where, under certain circumstances, unsanitized values in the volumeHandle and mounttargetip fields are passed directly to the mount comman…
CVE-2026-6437
GitHub-GHSA

MEDIUM
LangChain Text Splitters: HTMLHeaderTextSplitter.split_text_from_url SSRF Redirect Bypass
GHSA-fv5p-p927-qmxr
pkg: langchain-text-splitters
eco: pip
published: Apr 16, 2026
## Summary

`HTMLHeaderTextSplitter.split_text_from_url()` validated the initial URL using `validate_safe_url()` but then performed the fetch with `requests.get()` with redirects enabled (the default). Because redirect targets were not revalidated, a URL pointing to an attacker-controlled server cou…

GitHub-GHSA

MEDIUM
Paperclip: Arbitrary File Read via Agent-Controlled adapterConfig.instructionsFilePath
GHSA-3pw3-v88x-xj24
pkg: @paperclipai/shared
eco: npm
published: Apr 16, 2026
### Summary
Paperclip contains an arbitrary file read vulnerability that allows an attacker with an Agent API key to read files from the Paperclip server host filesystem.
The vulnerability occurs because agents are allowed to modify their own adapterConfig through the /agents/:id API endpoint.
The c…
GitHub-GHSA

MEDIUM
Apache Airlfow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view access
GHSA-4g48-54q2-fg7q
pkg: apache-airflow
eco: pip
published: Apr 15, 2026
The `access_key` and `connection_string` connection properties were not marked as sensitive names in secrets masker. This means that user with read permission could see the values in Connection UI, as well as when Connection was accidently logged to logs, those values could be seen in the logs. Azur…
CVE-2026-25219
GitHub-GHSA

MEDIUM
frp has an authentication bypass in HTTP vhost routing when routeByHTTPUser is used for access control
GHSA-pq96-pwvg-vrr9
pkg: github.com/fatedier/frp
eco: go
published: Apr 14, 2026
### Summary
frp contains an authentication bypass in the HTTP vhost routing path when `routeByHTTPUser` is used as part of access control. In proxy-style requests, the routing logic uses the username from `Proxy-Authorization` to select the `routeByHTTPUser` backend, while the access control check u…
GitHub-GHSA

MEDIUM
gdown Affected by Arbitrary File Write via Path Traversal in gdown.extractall
GHSA-76hw-p97h-883f
pkg: gdown
eco: pip
published: Apr 14, 2026
### Summary
The gdown library (tested on v5.2.1) is vulnerable to a Path Traversal attack within its extractall functionality. When extracting a maliciously crafted ZIP or TAR archive, the library fails to sanitize or validate the filenames of the archive members. This allow files to be written outs…
CVE-2026-40491
GitHub-GHSA

MEDIUM
ImageMagick has an off-by-one error in MSL decoder could result in crash
GHSA-5xg3-585r-9jh5
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Apr 14, 2026
An off by one error in de MSL decoder could result in a crash when a malicous msl file is read.
CVE-2026-40312
GitHub-GHSA

MEDIUM
ImageMagick has a heap buffer overflow (WRITE) in the YAML and JSON encoders.
GHSA-5592-p365-24xh
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Apr 14, 2026
A crafted image could result in an out of bounds heap write when writing a yaml or json output and that could result in a crash.
CVE-2026-40169
GitHub-GHSA

MEDIUM
pretalx mail templates vulnerable to email injection via unescaped user-controlled placeholders
GHSA-jm8c-9f3j-4378
pkg: pretalx
eco: pip
published: Apr 18, 2026
An unauthenticated attacker can send arbitrary HTML-rendered emails from a pretalx instance's configured sender address by embedding malformed HTML or markdown link syntax in a user-controlled template placeholder such as the account display name. The most direct vector is the password-reset flow: t…
GitHub-GHSA

MEDIUM
goldmark vulnerable to Cross-site Scripting (XSS)
GHSA-c97m-vxhj-p7j6
pkg: github.com/yuin/goldmark/renderer/html
eco: go
published: Apr 17, 2026
Versions of the package github.com/yuin/goldmark/renderer/html before 1.7.17 are vulnerable to Cross-site Scripting (XSS) due to improper ordering of URL validation and normalization. The renderer validates link destinations using a prefix-based check (IsDangerousURL) before resolving HTML entities.…
CVE-2026-5160
GitHub-GHSA

MEDIUM
zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering
GHSA-4fxq-2x3x-6xqx
pkg: github.com/openziti/zrok, github.com/openziti/zrok/v2
eco: go
published: Apr 16, 2026
**Summary**
The proxyUi template engine uses Go's text/template (which performs no HTML escaping) instead of html/template. The GitHub OAuth callback handlers in both publicProxy and dynamicProxy embed the attacker-controlled refreshInterval query parameter verbatim into an error message when time.P…
CVE-2026-40302
GitHub-GHSA

MEDIUM
sanitize-html allowedTags Bypass via Entity-Decoded Text in nonTextTags Elements
GHSA-9mrh-v2v3-xpfm
pkg: sanitize-html
eco: npm
published: Apr 16, 2026
## Summary

Commit 49d0bb7 introduced a regression in sanitize-html that bypasses `allowedTags` enforcement for text inside `nonTextTagsArray` elements (`textarea` and `option`). Entity-encoded HTML inside these elements passes through the sanitizer as decoded, unescaped HTML, allowing injection of …

CVE-2026-40186
GitHub-GHSA

MEDIUM
SpiceDB's SPICEDB_DATASTORE_CONN_URI is leaked on startup logs
GHSA-jf4f-rr2c-9m58
pkg: github.com/authzed/spicedb
eco: go
published: Apr 14, 2026
### Impact
When SpiceDB starts with log level `info`, the startup `"configuration"` log will include the full datastore DSN, including the plaintext password, inside `DatastoreConfig.URI`.

### Patches
v1.51.1

### Workarounds
Change the log level to `warn` or `error`.

CVE-2026-40091
GitHub-GHSA

MEDIUM
OpenTelemetry .NET has potential memory exhaustion via unbounded pooled-list sizing in Jaeger exporter conversion path
GHSA-38h3-2333-qx47
pkg: OpenTelemetry.Exporter.Jaeger
eco: nuget
published: Apr 18, 2026
### Summary

> [!IMPORTANT]
> There is no plan to fix this issue as `OpenTelemetry.Exporter.Jaeger` was deprecated in 2023. It is for informational purposes only.

`OpenTelemetry.Exporter.Jaeger` may allow sustained memory pressure when the internal pooled-list sizing grows based on a large observ…

CVE-2026-41078
GitHub-GHSA

MEDIUM
@fastify/static vulnerable to route guard bypass via encoded path separators
GHSA-x428-ghpx-8j92
pkg: @fastify/static
eco: npm
published: Apr 16, 2026
### Impact

`@fastify/static` v9.1.0 and earlier decodes percent-encoded path separators (`%2F`) before filesystem resolution, but Fastify's router treats them as literal characters. This creates a routing mismatch: route guards on `/admin/*` do not match `/admin%2Fsecret.html`, but @fastify/static …

CVE-2026-6414
GitHub-GHSA

MEDIUM
Junrar: Path Traversal (Zip-Slip) via Sibling Directory Name Prefix
GHSA-hf5p-q87m-crj7
pkg: com.github.junrar:junrar
eco: maven
published: Apr 16, 2026
### Summary

A path traversal vulnerability in `LocalFolderExtractor` allows an attacker to write arbitrary files with attacker-controlled content into sibling directories when a crafted RAR archive is extracted.

### Example

Given an extraction directory set to `/tmp/extract`, a crafted archive wi…

GitHub-GHSA

MEDIUM
@node-oauth/oauth2-server: PKCE code_verifier ABNF not enforced in token exchange allows brute-force redemption of intercepted authorization codes
GHSA-jhm7-29pj-4xvf
pkg: @node-oauth/oauth2-server
eco: npm
published: Apr 16, 2026
## Summary

The token exchange path accepts RFC7636-invalid `code_verifier` values (including one-character strings) for `S256` PKCE flows.
Because short/weak verifiers are accepted and failed verifier attempts do not consume the authorization code, an attacker who intercepts an authorization code…

GitHub-GHSA

MEDIUM
Note Mark has Broken Access Control on Asset Download
GHSA-p5w6-75f9-cc2p
pkg: github.com/enchant97/note-mark/backend
eco: go
published: Apr 13, 2026
### Summary
A broken access control vulnerability allows unauthenticated users to retrieve note assets directly from the asset download endpoint when they know both the note UUID and asset UUID. This exposes the full contents of private note assets without authentication, even when the associated bo…
CVE-2026-40265
GitHub-GHSA

MEDIUM
ImageMagick has a heap overflow caused by integer overflow/wraparound in viff encoder on 32-bit builds
GHSA-v67w-737x-v2c9
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-x86
eco: nuget
published: Apr 13, 2026
In viff encoder contains an integer truncation/wraparound issue on 32-bit builds that could trigger an out of bounds heap write that can result in a crash.
CVE-2026-33900
GitHub-GHSA

MEDIUM
Home Assistant Command-line Interface: Handling of user-supplied Jinja2 templates
GHSA-33qf-q99x-wpm8
pkg: homeassistant-cli
eco: pip
published: Apr 16, 2026
### Impact

Up to 1.0.0 of `home-assitant-cli` (or `hass-cli` for short) an unrestricted environment was used to handle Jninja2 templates instead of a sandboxed one. The user-supplied input within Jinja2 templates was rendered locally with no restrictions. This gave users access to Python's internal…

CVE-2026-40602
GitHub-GHSA

MEDIUM
Flowise: Weak Default Token Hash Secret
GHSA-m7mq-85xj-9×33
pkg: flowise
eco: npm
published: Apr 16, 2026
**Detection Method:** Kolega.dev Deep Code Scan

| Attribute | Value |
|—|—|
| Location | packages/server/src/enterprise/utils/tempTokenUtils.ts:31-34 |
| Practical Exploitability | Medium |
| Developer Approver | faizan@kolega.ai |

### Description
The encryption key for token encryption has a …

GitHub-GHSA

MEDIUM
Flowise: Weak Default Express Session Secret
GHSA-2qqc-p94c-hxwh
pkg: flowise
eco: npm
published: Apr 16, 2026
**Detection Method:** Kolega.dev Deep Code Scan

| Attribute | Value |
|—|—|
| Location | packages/server/src/enterprise/middleware/passport/index.ts:55 |
| Practical Exploitability | High |
| Developer Approver | faizan@kolega.ai |

### Description
Express session secret has a weak default valu…

GitHub-GHSA

MEDIUM
Flowise: Weak Default JWT Secrets
GHSA-cc4f-hjpj-g9p8
pkg: flowise
eco: npm
published: Apr 16, 2026
**Detection Method:** Kolega.dev Deep Code Scan

| Attribute | Value |
|—|—|
| Severity | Critical |
| Location | packages/server/src/enterprise/middleware/passport/index.ts:29-34 |
| Practical Exploitability | High |
| Developer Approver | faizan@kolega.ai |

### Description
JWT secrets have we…

GitHub-GHSA

MEDIUM
ImageMagick has a heap-use-after-free via XMP profile could result in a crash when printing the values.
GHSA-r83h-crwp-3vm7
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Apr 14, 2026
An heap use after free when reading an invalid XMP profile could result in a crash due to an heap use after free when printing the values.
CVE-2026-40311
GitHub-GHSA

MEDIUM
ImageMagick has a heap out-of-bounds write in JP2 encoder
GHSA-pwg5-6jfc-crvh
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Apr 14, 2026
Heap out-of-bounds write in the JP2 encoder with when a user specifies an invalid sampling index.
CVE-2026-40310
GitHub-GHSA

MEDIUM
ImageMagick has a heap buffer overflow when encoding JXL image with a 16-bit float
GHSA-jvgr-9ph5-m8v4
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Apr 14, 2026
The JXL encoder has an heap write overflow when a user specifies that the image should be encoded as 16 bit floats.
CVE-2026-40183
GitHub-GHSA

MEDIUM
ImageMagick has an out-of-bounds read in sample operation
GHSA-pcvx-ph33-r5vv
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Apr 14, 2026
The -sample operation has an out of bounds read when an specific offset is set through the `sample:offset` define that could lead to an out of bounds read.
CVE-2026-33905
GitHub-GHSA

MEDIUM
ImageMagick has a Stack Overflow via Recursive FX Expression Parsing
GHSA-f4qm-vj5j-9xpw
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Apr 14, 2026
A stack overflow vulnerability in ImageMagick's FX expression parser allows an attacker to crash the process by providing a deeply nested expression.
CVE-2026-33902
GitHub-GHSA

MEDIUM
Sigstore Timestamp Authority has Improper Certificate Validation in verifier
GHSA-xm5m-wgh2-rrg3
pkg: github.com/sigstore/timestamp-authority/v2
eco: go
published: Apr 14, 2026
### Authorization bypass via certificate bag manipulation in sigstore/timestamp-authority verifier

An authorization bypass vulnerability exists in sigstore/timestamp-authority verifier (timestamp-authority/v2/pkg/verification): `VerifyTimestampResponse` function correctly verifies the certificate c…

CVE-2026-39984
GitHub-GHSA

MEDIUM
Paperclip: Stored XSS via javascript: URLs in MarkdownBody — urlTransform override disables react-markdown sanitization
GHSA-fpw4-p57j-hqmq
pkg: @paperclipai/ui
eco: npm
published: Apr 16, 2026
## Summary

`MarkdownBody`, the shared component used to render every Markdown surface in the Paperclip UI (issue documents, issue comments, chat threads, approvals, agent details, export previews, etc.), passes `urlTransform={(url) => url}` to `react-markdown`. That override replaces `react-markdow…

GitHub-GHSA

MEDIUM
Authlib: Cross-site request forging when using cache
GHSA-jj8c-mmj3-mmgv
pkg: authlib
eco: pip
published: Apr 16, 2026
### Summary

There is no CSRF protection on the cache feature on most integrations clients.

### Details
In `authlib.integrations.starlette_client.OAuth`, no CSRF protection is set up when using the cache parameter. When _not_ using the cache parameter, the use of SessionMiddleware ties the client t…

GitHub-GHSA

MEDIUM
Istio: AuthorizationPolicy serviceAccounts regex injection via unescaped dots
GHSA-9gcg-w975-3rjh
pkg: istio.io/istio
eco: go
published: Apr 16, 2026
### Impact
The `serviceAccounts` and `notServiceAccounts` fields in AuthorizationPolicy incorrectly interpret dots (`.`) as a regular expression matcher. Because `.` is a valid character in a service account name, an `AuthorizationPolicy` ALLOW rule targeting SA e.g. `cert-manager.io` also matches `…
CVE-2026-39350
GitHub-GHSA

MEDIUM
ApostropheCMS: Stored XSS via CSS Custom Property Injection in @apostrophecms/color-field Escaping Style Tag Context
GHSA-97v6-998m-fp4g
pkg: apostrophe
eco: npm
published: Apr 16, 2026
## Summary

The `@apostrophecms/color-field` module bypasses color validation for values prefixed with `–` (intended for CSS custom properties), but performs no HTML sanitization on these values. When styles containing attacker-controlled color values are rendered into `<style>` tags — both in th…

CVE-2026-33889
GitHub-GHSA

MEDIUM
KubeVirt's authorization mechanism improperly truncates subresource names
GHSA-j6cv-3w8p-vrg8
pkg: kubevirt.io/kubevirt
eco: go
published: Apr 15, 2026
A flaw was found in KubeVirt's Role-Based Access Control (RBAC) evaluation logic. The authorization mechanism improperly truncates subresource names, leading to incorrect permission evaluations. This allows authenticated users with specific custom roles to gain unauthorized access to subresources, p…
CVE-2026-6383
GitHub-GHSA

MEDIUM
Apache Storm UI: Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata
GHSA-f2hp-qw27-8wfq
pkg: org.apache.storm:storm-webapp
eco: maven
published: Apr 13, 2026
Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata in Apache Storm UI

Versions Affected: before 2.8.6

Description: The Storm UI visualization component interpolates topology metadata including component IDs, stream names, and grouping values directly into HTML via innerHTML in p…

CVE-2026-35565
GitHub-GHSA

MEDIUM
HashiCorp Vault has Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS
GHSA-8r5m-3f66-qpr3
pkg: github.com/hashicorp/vault
eco: go
published: Apr 17, 2026
Vault’s PKI engine’s ACME validation did not reject local targets when issuing http-01 and tls-alpn-01 challenges. This may lead to these requests being sent to local network targets, potentially leading to information disclosure. Fixed in Vault Community Edition 2.0.0 and Vault Enterprise 2.0.0…
CVE-2026-5052
GitHub-GHSA

MEDIUM
@fastify/static vulnerable to path traversal in directory listing
GHSA-pr96-94w5-mx2h
pkg: @fastify/static
eco: npm
published: Apr 16, 2026
### Impact

`@fastify/static` v9.1.0 and earlier serves directory listings outside the configured static root when the `list` option is enabled. A request such as `/public/../outside/` causes `dirList.path()` to resolve a directory outside the root via `path.join()` without a containment check.

A r…

CVE-2026-6410
GitHub-GHSA

MEDIUM
Flowise: Unauthenticated Information Disclosure of OAuth Secrets (Cleartext) via GET Request
GHSA-6pcv-j4jx-m4vx
pkg: flowise
eco: npm
published: Apr 16, 2026
### Summary
I have discovered a critical Missing Authentication vulnerability on the /api/v1/loginmethod endpoint. The API allows unauthenticated users (guests) to retrieve the full SSO configuration of any organization by simply providing an organizationId. The response includes sensitive OAuth cre…
GitHub-GHSA

MEDIUM
zrok: Broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records
GHSA-3jpj-v3xr-5h6g
pkg: github.com/openziti/zrok, github.com/openziti/zrok/v2
eco: go
published: Apr 16, 2026
Summary
The unaccess handler (controller/unaccess.go) contains a logical error in its ownership guard: when a frontend record has environment_id = NULL (the marker for admin-created global frontends), the condition short-circuits to false and allows the deletion to proceed without any ownership veri…
CVE-2026-40304
GitHub-GHSA

MEDIUM
ApostropheCMS: Information Disclosure via choices/counts Query Parameters Bypassing publicApiProjection Field Restrictions
GHSA-c276-fj82-f2pq
pkg: apostrophe
eco: npm
published: Apr 16, 2026
## Summary

The `choices` and `counts` query parameters in the Apostrophe CMS REST API allow unauthenticated users to extract distinct field values for any schema field that has a registered query builder, completely bypassing `publicApiProjection` restrictions that are intended to limit which field…

CVE-2026-39857
GitHub-GHSA

MEDIUM
LangSmith SDK: Streaming token events bypass output redaction
GHSA-rr7j-v2q5-chgv
pkg: langsmith, langsmith
eco: pip
published: Apr 16, 2026
## Summary

The LangSmith SDK's output redaction controls (hideOutputs in JS, hide_outputs in Python) do not apply to streaming token events. When an LLM run produces streaming output, each chunk is recorded as a new_token event containing the raw token value. These events bypass the redaction pipel…

GitHub-GHSA

MEDIUM
Grafana Loki Path Traversal – CVE-2021-36156 Bypass
GHSA-497x-rrr9-68jp
pkg: github.com/grafana/loki/v3
eco: go
published: Apr 15, 2026
The CVE-2021-36156 fix validates the namespace parameter for path traversal sequences after a single URL decode, by double encoding, an attacker can read files at the Ruler API endpoint /loki/api/v1/rules/{namespace}

Thanks to Prasanth Sundararajan for reporting this vulnerability.

CVE-2026-21726
GitHub-GHSA

MEDIUM
python-multipart affected by Denial of Service via large multipart preamble or epilogue data
GHSA-mj87-hwqh-73pj
pkg: python-multipart
eco: pip
published: Apr 15, 2026
### Summary

A denial of service vulnerability exists when parsing crafted `multipart/form-data` requests with large preamble or epilogue sections.

### Details

Two inefficient multipart parsing paths could be abused with attacker-controlled input.

Before the first multipart boundary, the parser h…

CVE-2026-40347
GitHub-GHSA

MEDIUM
ImageMagick has a heap-Buffer-Overflow write of a single zero byte when parsing xml.
GHSA-cr67-pvmx-2pp2
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Apr 13, 2026
When `Magick` parses an XML file it is possible that a single zero byte is written out of the bounds.
CVE-2026-33899
GitHub-GHSA

MEDIUM
nimiq-consensus panics via RequestMacroChain micro-block locator
GHSA-48m6-486p-9j8p
pkg: nimiq-consensus
eco: rust
published: Apr 13, 2026
### Impact
An unauthenticated p2p peer can cause the `RequestMacroChain` message handler task to panic by sending a `RequestMacroChain` message where the first locator hash that is on the victim’s main chain is a micro block hash (not a macro block hash).

In `RequestMacroChain::handle`, the hand…

CVE-2026-34069
GitHub-GHSA

MEDIUM
ImageMagick has an integer overflow in despeckle operation causing a heap buffer overflow on 32-bit builds
GHSA-26qp-ffjh-2x4v
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-x86
eco: nuget
published: Apr 13, 2026
An integer overflow in the despeckle operation causes a heap buffer overflow on 32-bit builds that will result in an out of bounds write.

“`
==1551685==ERROR: AddressSanitizer: heap-buffer-overflow on address 0xea2fb818 at pc 0x56cbc42a bp 0xffc4ce48 sp 0xffc4ce38
WRITE of size 8 at 0xea2fb818 thr…

CVE-2026-34238
GitHub-GHSA

MEDIUM
Istio: SSRF via RequestAuthentication jwksUri
GHSA-fgw5-hp8f-xfhc
pkg: istio.io/istio
eco: go
published: Apr 16, 2026
### Impact

When a RequestAuthentication resource is created with a jwksUri pointing to an internal service, istiod makes an unauthenticated HTTP GET request to that URL without filtering out localhost or link local ips. This can result in sensitive data being distributed to Envoy proxies via xDS co…

GitHub-GHSA

MEDIUM
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
GHSA-ffgh-3jrf-8wvh
pkg: weblate
eco: pip
published: Apr 16, 2026
### Impact
Weblate repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and can be bypassed when the external path shares the same string prefix as …
CVE-2026-40256
GitHub-GHSA

MEDIUM
Weblate: SSRF via Project-Level Machinery Configuration
GHSA-xrwr-fcw6-fmq8
pkg: weblate
eco: pip
published: Apr 16, 2026
### Impact
A user with the `project.edit` permission (granted by the per-project "Administration" role) can configure machine translation service URLs pointing to arbitrary internal network addresses. During configuration validation, Weblate makes an HTTP request to the attacker-controlled URL and r…
CVE-2026-34244
GitHub-GHSA

MEDIUM
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
GHSA-5fhx-9jwj-867m
pkg: weblate
eco: pip
published: Apr 16, 2026
### Impact
The ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects.

### Patches
* https://github.com/WeblateOrg/weblate/pull/18550

### References
This issue was reported by @spbavarva via GitHub.

CVE-2026-33440
GitHub-GHSA

MEDIUM
Valtimo: Sensitive data exposure through inbox message logging in InboxHandlingService
GHSA-hfrg-mcvw-8mch
pkg: com.ritense.valtimo:inbox
eco: maven
published: Apr 16, 2026
### Summary

The `InboxHandlingService` logs the full content of every incoming inbox message at INFO level (`logger.info("Received message: {}", message)`). Inbox messages are wrappers around outbox message data, which can contain highly sensitive information such as personal data (PII), citizen id…

CVE-2026-34164
GitHub-GHSA

MEDIUM
pyLoad has a Session Cookie Security Downgrade via Untrusted X-Forwarded-Proto Header Spoofing (Global State Race Condition)
GHSA-mp82-fmj6-f22v
pkg: pyload-ng
eco: pip
published: Apr 16, 2026
## Summary

The `set_session_cookie_secure` `before_request` handler in `src/pyload/webui/app/__init__.py` reads the `X-Forwarded-Proto` header from any HTTP request without validating that the request originates from a trusted proxy, then mutates the **global** Flask configuration `SESSION_COOKIE_S…

CVE-2026-40594
GitHub-GHSA

MEDIUM
mitmproxy has an LDAP Injection
GHSA-527g-3w9m-29hv
pkg: mitmproxy
eco: pip
published: Apr 14, 2026
### Impact
In mitmproxy 12.2.1 and below, the builtin LDAP proxy authentication does not correctly sanitize the username when querying the LDAP server. This allows a malicious client to bypass authentication.

Only mitmproxy instances using the `proxyauth` option with LDAP are affected. This option …

CVE-2026-40606
GitHub-GHSA

MEDIUM
go-git: Credential leak via cross-host redirect in smart HTTP transport
GHSA-3xc5-wrhm-f963
pkg: github.com/go-git/go-git/v5, github.com/go-git/go-git/v6
eco: go
published: Apr 17, 2026
### Impact
`go-git` may leak HTTP authentication credentials when following redirects during smart-HTTP clone and fetch operations.

If a remote repository responds to the initial `/info/refs` request with a redirect to a different host, go-git updates the session endpoint to the redirected location…

GitHub-GHSA

MEDIUM
Mojic: Observable Timing Discrepancy in HMAC Verification
GHSA-wqq3-wfmp-v85g
pkg: mojic
eco: npm
published: Apr 16, 2026
### Summary
The `CipherEngine` in Mojic v2.1.3 uses a standard equality operator (`!==`) to verify the HMAC-SHA256 integrity seal during the decryption phase. This creates an Observable Timing Discrepancy (CWE-208), allowing a potential attacker to bypass the file integrity check via a timing attack…
GitHub-GHSA

MEDIUM
Paperclip: Approval decision attribution spoofing via client-controlled `decidedByUserId` in paperclip server
GHSA-p7mm-r948-4q3q
pkg: @paperclipai/server
eco: npm
published: Apr 16, 2026
## Summary

The approval-resolution endpoints (`POST /approvals/:id/approve`, `/reject`, `/request-revision`) accept a client-supplied `decidedByUserId` field in the request body and write it verbatim into the authoritative `approvals.decidedByUserId` column — without cross-checking it against the…

GitHub-GHSA

MEDIUM
Weblate: Improper access control for the translation memory in API
GHSA-mpf5-3vph-q75r
pkg: weblate
eco: pip
published: Apr 16, 2026
### Impact
The translation memory API exposed unintended endpoints, which in turn didn't do proper access control.

### Patches
* https://github.com/WeblateOrg/weblate/pull/18513

### Workarounds
Blocking access to `/api/memory/` in the HTTP server removes access to this feature.

### References
Thi…

CVE-2026-33214
GitHub-GHSA

MEDIUM
Apache PDFBox Examples: Path Traversal in PDFBox ExtractEmbeddedFiles Example Code
GHSA-gcj8-76p4-g2fq
pkg: org.apache.pdfbox:pdfbox-examples, org.apache.pdfbox:pdfbox-examples
eco: maven
published: Apr 14, 2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache PDFBox Examples.

This issue affects the
ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.36, from 3.0.0 through 3.0.7.

Users are recommended to update to version 2.0.37 or…

CVE-2026-33929
GitHub-GHSA

MEDIUM
Weblate: SSRF via the webhook add-on using unprotected fetch_url()
GHSA-f8hv-g549-hwg2
pkg: weblate
eco: pip
published: Apr 16, 2026
### Impact
The webhook add-on did not utilize existing SSRF protection.

### Patches
* https://github.com/WeblateOrg/weblate/pull/18815

### Workarounds
Disabling the add-on would avoid misusing this.

### References
Thanks to @Lihfdgjr for reporting this via GitHub.

CVE-2026-39845
GitHub-GHSA

MEDIUM
Zebra Vulnerable to Denial of Service via Interrupted JSON-RPC Requests from Authenticated Clients
GHSA-29×4-r6jv-ff4w
pkg: zebra-rpc, zebrad
eco: rust
published: Apr 18, 2026
A vulnerability in Zebra's JSON-RPC HTTP middleware allows an authenticated RPC client to cause a Zebra node to crash by disconnecting before the request body is fully received. The node treats the failure to read the HTTP request body as an unrecoverable error and aborts the process instead of retu…
GitHub-GHSA

MEDIUM
Zebra: addr/addrv2 Deserialization Resource Exhaustion
GHSA-xr93-pcq3-pxf8
pkg: zebrad, zebra-network
eco: rust
published: Apr 18, 2026
# CVE-2026-40881: addr/addrv2 Deserialization Resource Exhaustion

## Summary

When deserializing `addr` or `addrv2` messages, which contain vectors of addresses, Zebra would fully deserialize them up to a maximum length (over 233,000) that was derived from the 2 MiB message size limit. This is much…

CVE-2026-40881
GitHub-GHSA

MEDIUM
OpenClaw: QMD memory_get restricts reads to canonical or indexed memory paths
GHSA-f934-5rqf-xx47
pkg: openclaw
eco: npm
published: Apr 17, 2026
## Summary

The QMD backend `memory_get` read path accepted arbitrary workspace Markdown paths that were inside the workspace but outside the canonical memory locations or indexed QMD result set.

## Impact

When the QMD backend was enabled, a caller with access to `memory_get` could read arbitrary …

GitHub-GHSA

MEDIUM
yard: Possible arbitrary path traversal and file access via yard server
GHSA-3jfp-46×4-xgfj
pkg: yard
eco: rubygems
published: Apr 17, 2026
### Impact

A path traversal vulnerability was discovered in YARD <= 0.9.41 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions.

The original patch in [GHSA-xfhh-rx56-rx…

GitHub-GHSA

MEDIUM
Claude Code: Insecure System-Wide Configuration Loading Enables Local Privilege Escalation on Windows
GHSA-5cwg-9f6j-9jvx
pkg: @anthropic-ai/claude-code
eco: npm
published: Apr 17, 2026
On Windows, Claude Code loaded system-wide default configuration from `C:\ProgramData\ClaudeCode\managed-settings.json` without validating directory ownership or access permissions. Because the `ProgramData` directory is writable by non-administrative users by default and the `ClaudeCode` subdirecto…
CVE-2026-35603
GitHub-GHSA

MEDIUM
OpenClaw: CDP /json/version WebSocket URL could pivot to untrusted second-hop targets
GHSA-f7fh-qg34-x2xh
pkg: openclaw
eco: npm
published: Apr 17, 2026
## Summary

CDP /json/version WebSocket URL could pivot to untrusted second-hop targets.

## Affected Packages / Versions

– Package: `openclaw`
– Ecosystem: npm
– Affected versions: `< 2026.4.5`
– Patched versions: `>= 2026.4.5`

## Impact

A browser profile could trust a CDP `/json/version` respon…

GitHub-GHSA

MEDIUM
OpenClaw: Sender policy bypass in host media attachment reads allows unauthorized local file disclosure
GHSA-jhpv-5j76-m56h
pkg: openclaw
eco: npm
published: Apr 17, 2026
## Summary

OpenClaw's outbound host-media attachment read helper could enable host-local file reads based on global or agent-level read access without also honoring sender and group-scoped tool policy. In channel deployments that used `toolsBySender` or group policy to deny `read` for less-trusted …

GitHub-GHSA

MEDIUM
OpenClaw: Browser press/type interaction routes missed complete navigation guard coverage
GHSA-536q-mj95-h29h
pkg: openclaw
eco: npm
published: Apr 17, 2026
## Summary

Browser press/type interaction routes missed complete navigation guard coverage.

## Affected Packages / Versions

– Package: `openclaw`
– Ecosystem: npm
– Affected versions: `< 2026.4.10`
– Patched versions: `>= 2026.4.10`

## Impact

Some browser press/type style interactions could tri…

GitHub-GHSA

MEDIUM
OpenClaw: Browser interaction routes could pivot into local CDP and regain file reads
GHSA-qmwg-qprg-3j38
pkg: openclaw
eco: npm
published: Apr 17, 2026
## Summary

Browser interaction routes could pivot into local CDP and regain file reads.

## Affected Packages / Versions

– Package: `openclaw`
– Ecosystem: npm
– Affected versions: `< 2026.4.9`
– Patched versions: `>= 2026.4.9`

## Impact

Browser act/evaluate interactions could trigger navigation…

GitHub-GHSA

MEDIUM
OpenClaw: Existing-session browser interaction routes bypassed SSRF policy enforcement
GHSA-527m-976r-jf79
pkg: openclaw
eco: npm
published: Apr 17, 2026
## Summary

Existing-session browser interaction routes bypassed SSRF policy enforcement.

## Affected Packages / Versions

– Package: `openclaw`
– Ecosystem: npm
– Affected versions: `< 2026.4.10`
– Patched versions: `>= 2026.4.10`

## Impact

Existing-session browser interaction routes could conti…

GitHub-GHSA

MEDIUM
OpenClaw: Browser tabs action select and close routes bypassed SSRF policy
GHSA-rj2p-j66c-mgqh
pkg: openclaw
eco: npm
published: Apr 17, 2026
## Summary

Browser tabs action select and close routes bypassed SSRF policy.

## Affected Packages / Versions

– Package: `openclaw`
– Ecosystem: npm
– Affected versions: `< 2026.4.10`
– Patched versions: `>= 2026.4.10`

## Impact

The browser `/tabs/action` select and close branches could operate …

GitHub-GHSA

MEDIUM
OpenClaw: Nostr profile mutation routes allowed operator.write config persistence
GHSA-f3h5-h452-vp3j
pkg: openclaw
eco: npm
published: Apr 17, 2026
## Summary

Nostr profile mutation routes allowed operator.write config persistence.

## Affected Packages / Versions

– Package: `openclaw`
– Ecosystem: npm
– Affected versions: `< 2026.4.10`
– Patched versions: `>= 2026.4.10`

## Impact

Nostr plugin HTTP profile routes could persist profile confi…

GitHub-GHSA

MEDIUM
OpenClaw: screen_record outPath bypassed workspace-only filesystem guard
GHSA-jf25-7968-h2h5
pkg: openclaw
eco: npm
published: Apr 17, 2026
## Summary

screen_record outPath bypassed workspace-only filesystem guard.

## Affected Packages / Versions

– Package: `openclaw`
– Ecosystem: npm
– Affected versions: `< 2026.4.10`
– Patched versions: `>= 2026.4.10`

## Impact

The node-host screen recording tool could honor an `outPath` outside …

GitHub-GHSA

MEDIUM
OpenClaw: Browser SSRF policy default allowed private-network navigation
GHSA-53vx-pmqw-863c
pkg: openclaw
eco: npm
published: Apr 17, 2026
## Summary

Browser SSRF policy default allowed private-network navigation.

## Affected Packages / Versions

– Package: `openclaw`
– Ecosystem: npm
– Affected versions: `< 2026.4.14`
– Patched versions: `>= 2026.4.14`

## Impact

Browser SSRF protection could allow private-network navigation by def…

GitHub-GHSA

MEDIUM
OpenClaw: Browser SSRF hostname validation could be bypassed by DNS rebinding
GHSA-xq94-r468-qwgj
pkg: openclaw
eco: npm
published: Apr 17, 2026
## Summary

Browser SSRF hostname validation could be bypassed by DNS rebinding.

## Affected Packages / Versions

– Package: `openclaw`
– Ecosystem: npm
– Affected versions: `< 2026.4.10`
– Patched versions: `>= 2026.4.10`

## Impact

Browser navigation policy could validate a hostname/IP resolutio…

GitHub-GHSA

MEDIUM
OpenClaw: QQBot reply media URL handling could trigger SSRF and re-upload fetched bytes
GHSA-2767-2q9v-9326
pkg: openclaw
eco: npm
published: Apr 17, 2026
## Summary

QQBot reply media URL handling could trigger SSRF and re-upload fetched bytes.

## Affected Packages / Versions

– Package: `openclaw`
– Ecosystem: npm
– Affected versions: `< 2026.4.12`
– Patched versions: `>= 2026.4.12`

## Impact

QQBot reply media URLs could be treated as trusted med…

GitHub-GHSA

MEDIUM
OpenClaw: Workspace .env could inject OpenClaw runtime-control variables
GHSA-7wv4-cc7p-jhxc
pkg: openclaw
eco: npm
published: Apr 17, 2026
## Summary

Workspace .env could inject OpenClaw runtime-control variables.

## Affected Packages / Versions

– Package: `openclaw`
– Ecosystem: npm
– Affected versions: `< 2026.4.9`
– Patched versions: `>= 2026.4.9`

## Impact

A malicious workspace `.env` file could set OpenClaw runtime-control va…

GitHub-GHSA

MEDIUM
OpenClaw: Discord event cover images bypassed sandbox media normalization
GHSA-c9h3-5p7r-mrjh
pkg: openclaw
eco: npm
published: Apr 17, 2026
## Summary

Discord event cover images bypassed sandbox media normalization.

## Affected Packages / Versions

– Package: `openclaw`
– Ecosystem: npm
– Affected versions: `>= 2026.4.7 < 2026.4.10`
– Patched versions: `>= 2026.4.10`

## Impact

Discord event cover image parameters could bypass the sa…

GitHub-GHSA

MEDIUM
OpenClaw: Empty approver lists could grant explicit approval authorization
GHSA-49cg-279w-m73x
pkg: openclaw
eco: npm
published: Apr 17, 2026
## Summary

Empty approver lists could grant explicit approval authorization.

## Affected Packages / Versions

– Package: `openclaw`
– Ecosystem: npm
– Affected versions: `< 2026.4.12`
– Patched versions: `>= 2026.4.12`

## Impact

For helper-backed channels, an empty resolved approver list could b…

GitHub-GHSA

MEDIUM
OpenClaw: Agent hook events could enqueue trusted system events from unsanitized external input
GHSA-7g8c-cfr3-vqqr
pkg: openclaw
eco: npm
published: Apr 17, 2026
## Summary

Agent hook events could enqueue trusted system events from unsanitized external input.

## Affected Packages / Versions

– Package: `openclaw`
– Ecosystem: npm
– Affected versions: `< 2026.4.10`
– Patched versions: `>= 2026.4.10`

## Impact

Agent hook dispatch could turn externally supp…

GitHub-GHSA

MEDIUM
OpenClaw: Shell-wrapper detection missed env-argv assignment injection forms
GHSA-j6c7-3h5x-99g9
pkg: openclaw
eco: npm
published: Apr 17, 2026
## Summary

Shell-wrapper detection missed env-argv assignment injection forms.

## Affected Packages / Versions

– Package: `openclaw`
– Ecosystem: npm
– Affected versions: `>= 2026.2.22 < 2026.4.12`
– Patched versions: `>= 2026.4.12`

## Impact

Exec preflight handling missed shell-wrapper and arg…

GitHub-GHSA

MEDIUM
OpenClaw: Memory dreaming config persistence was reachable from operator.write commands
GHSA-5gjc-grvm-m88j
pkg: openclaw
eco: npm
published: Apr 17, 2026
## Summary

Memory dreaming config persistence was reachable from operator.write commands.

## Affected Packages / Versions

– Package: `openclaw`
– Ecosystem: npm
– Affected versions: `>= 2026.4.5 < 2026.4.10`
– Patched versions: `>= 2026.4.10`

## Impact

A write-scoped gateway path could toggle p…

GitHub-GHSA

MEDIUM
OpenClaw: Heartbeat owner downgrade missed local async exec completion events
GHSA-g375-h3v6-4873
pkg: openclaw
eco: npm
published: Apr 17, 2026
## Summary

Heartbeat owner downgrade missed local async exec completion events.

## Affected Packages / Versions

– Package: `openclaw`
– Ecosystem: npm
– Affected versions: `>= 2026.3.31 < 2026.4.10`
– Patched versions: `>= 2026.4.10`

## Impact

Local background exec completion text could be miss…

GitHub-GHSA

MEDIUM
OpenClaw: Heartbeat owner downgrade missed untrusted webhook wake events
GHSA-g2hm-779g-vm32
pkg: openclaw
eco: npm
published: Apr 17, 2026
## Summary

Heartbeat owner downgrade missed untrusted webhook wake events.

## Affected Packages / Versions

– Package: `openclaw`
– Ecosystem: npm
– Affected versions: `>= 2026.4.7 < 2026.4.14`
– Patched versions: `>= 2026.4.14`

## Impact

Heartbeat owner downgrade logic could skip webhook wake e…

GitHub-GHSA

MEDIUM
OpenClaw: Browser snapshot and screenshot routes could expose internal page content after navigation
GHSA-c4qm-58hj-j6pj
pkg: openclaw
eco: npm
published: Apr 17, 2026
## Summary

Browser snapshot and screenshot routes could expose internal page content after navigation.

## Affected Packages / Versions

– Package: `openclaw`
– Ecosystem: npm
– Affected versions: `< 2026.4.14`
– Patched versions: `>= 2026.4.14`

## Impact

Authenticated browser tool callers could …

GitHub-GHSA

MEDIUM
OpenClaw: Collect-mode queue batches could reuse the last sender authorization context
GHSA-jwrq-8g5x-5fhm
pkg: openclaw
eco: npm
published: Apr 17, 2026
## Summary

Collect-mode queue batches could reuse the last sender authorization context.

## Affected Packages / Versions

– Package: `openclaw`
– Ecosystem: npm
– Affected versions: `< 2026.4.14`
– Patched versions: `>= 2026.4.14`

## Impact

Collect-mode queued messages from different senders cou…

GitHub-GHSA

MEDIUM
OpenClaw: Sandbox noVNC helper route exposed interactive browser session credentials
GHSA-92jp-89mq-4374
pkg: openclaw
eco: npm
published: Apr 17, 2026
## Summary

Sandbox noVNC helper route exposed interactive browser session credentials.

## Affected Packages / Versions

– Package: `openclaw`
– Ecosystem: npm
– Affected versions: `>= 2026.2.21 < 2026.4.10`
– Patched versions: `>= 2026.4.10`

## Impact

The sandbox noVNC helper route could be reac…

GitHub-GHSA

MEDIUM
Bouncy Castle has an LDAP injection
GHSA-c3fc-8qff-9hwx
pkg: org.bouncycastle:bcprov-jdk14, org.bouncycastle:bcprov-jdk15to18, org.bouncycastle:bcprov-jdk18on
eco: maven
published: Apr 17, 2026
Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (prov modules). This vulnerability is associated with program files LDAPStoreHelper.

This issue affects BC-JAVA: from 1.74 before 1.84.

CVE-2026-0636
GitHub-GHSA

MEDIUM
Saltcorn: Open Redirect in `POST /auth/login` due to incomplete `is_relative_url` validation (backslash bypass)
GHSA-f3g8-9xv5-77gv
pkg: @saltcorn/server, @saltcorn/server, @saltcorn/server
eco: npm
published: Apr 16, 2026
### Summary
Saltcorn validates the post-login `dest` parameter with a string check that only blocks `:/` and `//`. Because all WHATWG-compliant browsers normalise backslashes (`\`) to forward slashes (`/`) for special schemes, a payload such as `/\evil.com/path` slips through `is_relative_url()`, is…
GitHub-GHSA

MEDIUM
pypdf: Manipulated FlateDecode image dimensions can exhaust RAM
GHSA-x284-j5p8-9c5p
pkg: pypdf
eco: pip
published: Apr 16, 2026
### Impact
An attacker who uses this vulnerability can craft a PDF which leads to the RAM being exhausted. This requires accessing an image using `/FlateDecode` with large size values.

### Patches
This has been fixed in [pypdf==6.10.2](https://github.com/py-pdf/pypdf/releases/tag/6.10.2).

### Work…

GitHub-GHSA

MEDIUM
pypdf: Possible long runtimes for wrong size values in incremental mode
GHSA-4pxv-j86v-mhcw
pkg: pypdf
eco: pip
published: Apr 16, 2026
### Impact
An attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires loading a PDF with a large trailer `/Size` value in incremental mode.

### Patches
This has been fixed in [pypdf==6.10.2](https://github.com/py-pdf/pypdf/releases/tag/6.10.2).

### Workarou…

GitHub-GHSA

MEDIUM
pypdf: Manipulated FlateDecode predictor parameters can exhaust RAM
GHSA-7gw9-cf7v-778f
pkg: pypdf
eco: pip
published: Apr 16, 2026
### Impact
An attacker who uses this vulnerability can craft a PDF which leads to the RAM being exhausted. This requires accessing a stream compressed using `/FlateDecode` with a `/Predictor` unequal 1 and large predictor parameters.

### Patches
This has been fixed in [pypdf==6.10.2](https://github…

GitHub-GHSA

MEDIUM
Flowise Execute Flow function has an SSRF vulnerability
GHSA-9hrv-gvrv-6gf2
pkg: flowise, flowise-components
eco: npm
published: Apr 16, 2026
### Summary

The attacker provides an intranet address through the base url field configured in the Execute Flow node
→ Bypass checkDenyList / resolveAndValidate in httpSecurity.ts (not called)
→ Causes the server to initiate an HTTP request to any internal network address, read cloud metadata,…

GitHub-GHSA

MEDIUM
Flowise: SSRF Protection Bypass via Direct node-fetch / axios Usage (Patch Enforcement Failure)
GHSA-qqvm-66q4-vf5c
pkg: flowise, flowise-components
eco: npm
published: Apr 16, 2026
### Summary

Flowise introduced SSRF protections through a centralized HTTP security wrapper (`httpSecurity.ts`) that implements deny-list validation and IP pinning logic.

However, multiple tool implementations directly import and invoke raw HTTP clients (`node-fetch`, `axios`Instead of using the s…

GitHub-GHSA

MEDIUM
Flowise: Path Traversal in Vector Store basePath
GHSA-w6v6-49gh-mc9w
pkg: flowise, flowise-components
eco: npm
published: Apr 16, 2026
## Summary

The Faiss and SimpleStore (LlamaIndex) vector store implementations accept a `basePath` parameter from user-controlled input and pass it directly to filesystem write operations without any sanitization. An authenticated attacker can exploit this to write vector store data to arbitrary lo…

GitHub-GHSA

MEDIUM
Mako: Path traversal via double-slash URI prefix in TemplateLookup
GHSA-v92g-xgxw-vvmm
pkg: Mako
eco: pip
published: Apr 16, 2026
### Summary

`TemplateLookup.get_template()` is vulnerable to path traversal when a URI starts with `//` (e.g., `//../../../secret.txt`). The root cause is an inconsistency between two slash-stripping implementations:

– `Template.__init__` strips **one** leading `/` using `if`/slice
– `TemplateLook…

GitHub-GHSA

MEDIUM
Buffer Overflow in Zlib::GzipReader ungetc via large input leads to memory corruption
GHSA-g857-hhfv-j68w
pkg: zlib, zlib, zlib
eco: rubygems
published: Apr 16, 2026
### Details

A buffer overflow vulnerability exists in `Zlib::GzipReader`.

The `zstream_buffer_ungets` function prepends caller-provided bytes ahead of previously produced output but fails to guarantee the backing Ruby string has enough capacity before the memmove shifts the existing data. This can…

CVE-2026-27820
GitHub-GHSA

MEDIUM
Apache Airflow: JWT token appearing in logs
GHSA-phv5-vq5p-qhp7
pkg: apache-airflow
eco: pip
published: Apr 16, 2026
JWT Tokens used by tasks were exposed in logs. This could allow UI users to act as Dag Authors.
Users are advised to upgrade to Airflow version that contains fix.

Users are recommended to upgrade to version 3.2.0, which fixes this issue.

CVE-2026-31987
GitHub-GHSA

MEDIUM
wger has Stored XSS via Unescaped License Attribution Fields
GHSA-6f54-qjvm-wwq3
pkg: wger
eco: pip
published: Apr 16, 2026
# Stored XSS via Unescaped License Attribution Fields

## Summary

The `AbstractLicenseModel.attribution_link` property in `wger/utils/models.py` constructs HTML strings by directly interpolating user-controlled fields (`license_author`, `license_title`, `license_object_url`, `license_author_url`, `…

CVE-2026-40353
GitHub-GHSA

MEDIUM
PySpector has a Plugin Code Execution Bypass via Incomplete Static Analysis in PluginSecurity.validate_plugin_code
GHSA-vp22-38m5-r39r
pkg: pyspector
eco: pip
published: Apr 16, 2026
### Summary

The plugin security validator in PySpector uses AST-based static analysis to prevent dangerous code from being loaded as plugins. The blocklist implemented in `PluginSecurity.validate_plugin_code` is incomplete and can be bypassed using several Python constructs that are not checked. An…

GitHub-GHSA

MEDIUM
pypdf has long runtimes for wrong size values in cross-reference and object streams
GHSA-jj6c-8h6c-hppx
pkg: pypdf
eco: pip
published: Apr 15, 2026
### Impact

An attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires cross-reference streams with wrong large `/Size` values or object streams with wrong large `/N` values.

### Patches

This has been fixed in [pypdf==6.10.1](https://github.com/py-pdf/pypdf…

GitHub-GHSA

MEDIUM
Data Sharing Framework has an Inverted Time Comparison in OIDC JWKS and Token Cache
GHSA-xmj9-7625-f634
pkg: dev.dsf:dsf-bpe-process-api-v2, dev.dsf:dsf-bpe-server
eco: maven
published: Apr 15, 2026
### Affected Components
– DSF FHIR Server with enabled [bearer-token authentication](https://dsf.dev/operations/v2.1.0/fhir/oidc.html) or [back-channel logout](https://dsf.dev/operations/v2.1.0/fhir/oidc.html).
– DSF BPE Server with enabled [bearer-token authentication](https://dsf.dev/operations/v2…
GitHub-GHSA

MEDIUM
Data Sharing Framework is Missing Session Timeout for OIDC Sessions
GHSA-gj7p-595x-qwf5
pkg: dev.dsf:dsf-common-jetty, dev.dsf:dsf-fhir-server, dev.dsf:dsf-bpe-server
eco: maven
published: Apr 15, 2026
### Affected Components
DSF FHIR Server with enabled [OIDC authentication](https://dsf.dev/operations/v2.1.0/fhir/oidc.html).
DSF BPE Server with enabled [OIDC authentication](https://dsf.dev/operations/v2.1.0/bpe/oidc.html).

### Summary
OIDC-authenticated sessions had no configured maximum inactiv…

CVE-2026-40939
GitHub-GHSA

MEDIUM
Bouncy Castle Crypto Package For Java: Use of a Broken or Risky Cryptographic Algorithm vulnerability in bcpkix modules
GHSA-wg6q-6289-32hp
pkg: org.bouncycastle:bcpkix-jdk18on, org.bouncycastle:bcpkix-jdk15to18, org.bouncycastle:bcpkix-jdk15on
eco: maven
published: Apr 15, 2026
: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all (pkix modules).

PKIX draft CompositeVerifier accepts empty signature sequence as valid.

This issue affects BC-JAVA: from 1.49 before 1.84.

CVE-2026-5588
GitHub-GHSA

MEDIUM
Giskard has Unsandboxed Jinja2 Template Rendering in ConformityCheck
GHSA-7xjm-g8f4-rp26
pkg: giskard-checks
eco: pip
published: Apr 14, 2026
## Summary

The `ConformityCheck` class in `giskard-checks` rendered the `rule` parameter through Jinja2's default `Template()` constructor. Because the `rule` string is silently interpreted as a Jinja2 template, a developer may not realize that template expressions embedded in rule definitions are…

CVE-2026-40320
GitHub-GHSA

MEDIUM
SiYuan has incomplete fix for CVE-2026-33066: XSS
GHSA-8q5w-mmxf-48jg
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: Apr 14, 2026
### Summary

The incomplete fix for SiYuan's bazaar README rendering enables the Lute HTML sanitizer but fails to block `<iframe>` tags, allowing stored XSS via `srcdoc` attributes containing embedded scripts that execute in the Electron context.

### Affected Package

– **Ecosystem:** Go
– **Packag…

GitHub-GHSA

MEDIUM
XWiki's REST APIs can list all pages/spaces, leading to unavailability
GHSA-mrqg-xmgm-rc5g
pkg: org.xwiki.platform:xwiki-platform-oldcore, org.xwiki.platform:xwiki-platform-oldcore, org.xwiki.platform:xwiki-platform-oldcore
eco: maven
published: Apr 14, 2026
### Impact
REST API endpoints like `/xwiki/rest/wikis/xwiki/spaces/AnnotationCode/pages/AnnotationConfig/objects/AnnotationCode.AnnotationConfig/0/properties` list all available pages as part of the metadata for database list properties, which can exhaust available resources on large wikis.

### Pat…

CVE-2026-40104
GitHub-GHSA

MEDIUM
XWiki has Reflected Cross-Site Scripting (XSS) in page history compare
GHSA-w4fj-87j5-f25c
pkg: org.xwiki.platform:xwiki-platform-web-templates, org.xwiki.platform:xwiki-platform-web-templates, org.xwiki.platform:xwiki-platform-web-templates
eco: maven
published: Apr 14, 2026
### Impact
A reflected cross-site scripting vulnerability (XSS) in the compare view between revisions of a page allows executing JavaScript code in the user's browser. If the current user is an admin, this can not only affect the current user but also the confidentiality, integrity and availability …
CVE-2026-40105
GitHub-GHSA

MEDIUM
PowerShell Command Injection in Podman HyperV Machine
GHSA-hc8w-h2mf-hp59
pkg: github.com/containers/podman/v4, github.com/containers/podman/v5
eco: go
published: Apr 14, 2026
## Summary

A command injection vulnerability exists in Podman's HyperV machine backend. The VM image path is inserted into a PowerShell double-quoted string without sanitization, allowing `$()` subexpression injection.

## Affected Code

**File**: `pkg/machine/hyperv/stubber.go:647`

“`go
resize :…

CVE-2026-33414
GitHub-GHSA

MEDIUM
goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation
GHSA-jrq5-hg6x-j6g3
pkg: github.com/patrickhener/goshs/v2
eco: go
published: Apr 14, 2026
### Summary
goshs contains a cross-site request forgery issue in its state-changing HTTP GET routes. An external attacker can cause an already authenticated browser to trigger destructive actions such as `?delete` and `?mkdir` because goshs relies on HTTP basic auth alone and performs no CSRF, `Orig…
CVE-2026-40883
GitHub-GHSA

MEDIUM
free5gc UDR fail-open request handling in PolicyDataSubsToNotifySubsIdPut may allow unintended subscription updates after input errors
GHSA-gx38-8h33-pmxr
pkg: github.com/free5gc/udr
eco: go
published: Apr 14, 2026
### Summary
A fail-open request handling flaw in the UDR service causes the `/nudr-dr/v2/policy-data/subs-to-notify/{subsId}` PUT handler to continue processing requests even after request body retrieval or deserialization errors.

This may allow unintended modification of existing Policy Data notif…

CVE-2026-40249
GitHub-GHSA

MEDIUM
Prometheus has Stored XSS via metric names and label values in Prometheus web UI tooltips and metrics explorer
GHSA-vffh-x6r8-xx99
pkg: github.com/prometheus/prometheus, github.com/prometheus/prometheus, github.com/prometheus/prometheus
eco: go
published: Apr 13, 2026
### Impact

Stored cross-site scripting (XSS) via crafted metric names in the Prometheus web UI:

* **Old React UI + New Mantine UI:** When a user hovers over a chart tooltip on the Graph page, metric names containing HTML/JavaScript are injected into `innerHTML` without escaping, causing arbitrary …

CVE-2026-40179
GitHub-GHSA

MEDIUM
Apache Airflow: Secrets from Airflow config file logged in plain text in DAG run logs UI
GHSA-j86x-fwp2-qh7v
pkg: apache-airflow
eco: pip
published: Apr 13, 2026
Before Airflow 3.2.0, it was unclear that secure Airflow deployments require the Deployment Manager to take appropriate actions and pay attention to security details and security model of Airflow. Some assumptions the Deployment Manager could make were not clear or explicit enough, even though Airfl…
CVE-2025-66236


Vulnerability Digest — April 13, 2026 · 61 Critical · 1 Exploited






Vulnerability Digest — Monday, April 13, 2026


Security Report

Monday, April 13, 2026  ·  Last 7 days  ·  Min severity: MEDIUM
Total Findings
434
Critical
61
High
163
Actively Exploited
1
CISA-KEV1
NVD134
GitHub-GHSA299
Findings sorted by severity
CISA-KEV

CRITICAL
Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
CVE-2026-1340
pkg: Ivanti Endpoint Manager Mobile (EPMM)

published: Apr 8, 2026

Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
GitHub-GHSA

CRITICAL
Daptin has Unauthenticated Path Traversal and Zip Slip
GHSA-9cp7-j3f8-p5jx
pkg: github.com/daptin/daptin
eco: go
published: Apr 10, 2026
### Impact
The `cloudstore.file.upload` action in `server/actions/action_cloudstore_file_upload.go` writes user-supplied filenames directly to disk without proper validation.

This allows unauthenticated attackers to perform path traversal and zip slip attacks, leading to arbitrary file write and p…

GitHub-GHSA

CRITICAL
paperclip Vulnerable to Unauthenticated Remote Code Execution via Import Authorization Bypass
GHSA-68qg-g8mg-6pr7
pkg: paperclipai, @paperclipai/server
eco: npm
published: Apr 10, 2026
## Summary

An unauthenticated attacker can achieve full remote code execution on any network-accessible Paperclip instance running in `authenticated` mode with default configuration. No user interaction, no credentials, just the target's address. The entire chain is six API calls.

## Steps to Repr…

GitHub-GHSA

CRITICAL
Juju: CloudSpec method leaking cloud credentials
GHSA-w5fq-8965-c969
pkg: github.com/juju/juju
eco: go
published: Apr 10, 2026
### Impact

If a user has login permission to a controller and knows the controller model UUID, they can call the CloudSpec method on the Controller facade and get cloud credentials used to bootstrap the controller.

The CloudSpec API is called by workers running in the controller to maintain connec…

CVE-2026-5412
NVD

CRITICAL
CVE-2026-40175
CVE-2026-40175
pkg: axios

published: Apr 10, 2026

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0, the Axios library is vulnerable to a specific "Gadget" attack chain that allows Prototype Pollution in any third-party dependency to be escalated into Remote Code Execution (RCE) or Full Cloud Compromise (via AWS IMDS…
CWE: CWE-113, CWE-444, CWE-918
GitHub-GHSA

CRITICAL
Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
GHSA-fvcv-3m26-pcqx
pkg: axios
eco: npm
published: Apr 10, 2026
# Vulnerability Disclosure: Unrestricted Cloud Metadata Exfiltration via Header Injection Chain

## Summary
The Axios library is vulnerable to a specific "Gadget" attack chain that allows **Prototype Pollution** in any third-party dependency to be escalated into **Remote Code Execution (RCE)** or **…

CVE-2026-40175
GitHub-GHSA

CRITICAL
PraisonAI has sandbox escape via exception frame traversal in `execute_code` (subprocess mode)
GHSA-qf73-2hrx-xprp
pkg: praisonaiagents
eco: pip
published: Apr 8, 2026
## Summary

`execute_code()` in `praisonaiagents.tools.python_tools` defaults to
`sandbox_mode="sandbox"`, which runs user code in a subprocess wrapped with a
restricted `__builtins__` dict and an AST-based blocklist. The AST blocklist
embedded inside the subprocess wrapper (`blocked_attrs`, line 14…

CVE-2026-39888
NVD

CRITICAL
CVE-2026-40089
CVE-2026-40089
pkg: docker

published: Apr 9, 2026

Sonicverse is a Self-hosted Docker Compose stack for live radio streaming. The Sonicverse Radio Audio Streaming Stack dashboard contains a Server-Side Request Forgery (SSRF) vulnerability in its API client (apps/dashboard/lib/api.ts). Installations created using the provided install.sh script (inclu…
CWE: CWE-918
NVD

CRITICAL
CVE-2026-39888
CVE-2026-39888
pkg: python

published: Apr 8, 2026

PraisonAI is a multi-agent teams system. Prior to 1.5.115, execute_code() in praisonaiagents.tools.python_tools defaults to sandbox_mode="sandbox", which runs user code in a subprocess wrapped with a restricted __builtins__ dict and an AST-based blocklist. The AST blocklist embedded inside the subpr…
CWE: CWE-657, CWE-693
NVD

CRITICAL
CVE-2026-23696
CVE-2026-23696
pkg: jwt

published: Apr 7, 2026

Windmill CE and EE versions 1.276.0 through 1.603.2 contain an SQL injection vulnerability in the folder ownership management functionality that allows authenticated attackers to inject SQL through the owner parameter. An attacker can use the injection to read sensitive data such as the JWT signing …
CWE: CWE-89
GitHub-GHSA

CRITICAL
PraisonAI has critical RCE via `type: job` workflow YAML
GHSA-vc46-vw85-3wvm
pkg: praisonaiagents, PraisonAI
eco: pip
published: Apr 10, 2026
`praisonai workflow run <file.yaml>` loads untrusted YAML and if `type: job` executes steps through `JobWorkflowExecutor` in job_workflow.py.

This supports:
– `run:` → shell command execution via `subprocess.run()`
– `script:` → inline Python execution via `exec()`
– `python:` → arbitrary Pyt…

GitHub-GHSA

CRITICAL
PraisonAI Vulnerable to Remote Code Execution via YAML Deserialization in Agent Definition Loading
GHSA-32vr-5gcf-3pw2
pkg: praisonai
eco: pip
published: Apr 8, 2026
## Summary
The `AgentService.loadAgentFromFile` method uses the `js-yaml` library to parse YAML files without disabling dangerous tags (such as `!!js/function` and `!!js/undefined`). This allows an attacker to craft a malicious YAML file that, when parsed, executes arbitrary JavaScript code. An atta…
CVE-2026-39890
NVD

CRITICAL
CVE-2026-33229
CVE-2026-33229
pkg: python

published: Apr 8, 2026

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.4.8 and 17.10.1, an improperly protected scripting API allows any user with script right to bypass the sandboxing of the Velocity scripting API and execute, e.g., arbitrary Python scr…
CWE: CWE-862
NVD

CRITICAL
CVE-2026-3535
CVE-2026-3535
pkg: go

published: Apr 8, 2026

The DSGVO Google Web Fonts GDPR plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the `DSGVOGWPdownloadGoogleFonts()` function in all versions up to, and including, 1.1. The function is exposed via a `wp_ajax_nopriv_` hook, requiring no authentication…
CWE: CWE-434
GitHub-GHSA

CRITICAL
pgx contains memory-safety vulnerability
GHSA-xgrm-4fwx-7qm8
pkg: github.com/jackc/pgx/v5/pgproto3
eco: go
published: Apr 7, 2026
[pgx](github.com/jackc/pgx/v5) is a pure Go driver and toolkit for PostgreSQL. pgx v5.9.1 and earlier contain a memory-safety vulnerability.
CVE-2026-33815
NVD

CRITICAL
CVE-2026-35458
CVE-2026-35458
pkg: go

published: Apr 7, 2026

Gotenberg is an API for converting document formats. In 8.29.1 and earlier, Gotenberg uses dlclark/regexp2 to compile user-supplied scope patterns without setting a proper timeout. Users with access to features using this logic can hang workers indefinitely.
CWE: CWE-1333
NVD

CRITICAL
CVE-2026-1114
CVE-2026-1114
pkg: jwt

published: Apr 7, 2026

In parisneo/lollms version 2.1.0, the application's session management is vulnerable to improper access control due to the use of a weak secret key for signing JSON Web Tokens (JWT). This vulnerability allows an attacker to perform an offline brute-force attack to recover the secret key. Once the se…
CWE: CWE-284
NVD

CRITICAL
CVE-2026-35471
CVE-2026-35471
pkg: goshs goshs

published: Apr 6, 2026

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, tdeleteFile() missing return after path traversal check. This vulnerability is fixed in 2.0.0-beta.3.
CWE: CWE-22
NVD

CRITICAL
CVE-2026-35393
CVE-2026-35393
pkg: goshs goshs

published: Apr 6, 2026

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, the POST multipart upload directory not sanitized. This vulnerability is fixed in 2.0.0-beta.3.
CWE: CWE-22
NVD

CRITICAL
CVE-2026-35392
CVE-2026-35392
pkg: goshs goshs

published: Apr 6, 2026

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, PUT upload in httpserver/updown.go has no path sanitization. This vulnerability is fixed in 2.0.0-beta.3.
CWE: CWE-22
GitHub-GHSA

CRITICAL
changedetection.io Vulnerable to Authentication Bypass via Decorator Ordering
GHSA-jmrh-xmgh-x9j4
pkg: changedetection.io
eco: pip
published: Apr 6, 2026
### Summary

On 13 routes across 5 blueprint files, the `@login_optionally_required` decorator is placed **before** (outer to) `@blueprint.route()` instead of after it. In Flask, `@route()` must be the outermost decorator because it registers the function it receives. When the order is reversed, `@r…

CVE-2026-35490
NVD

CRITICAL
CVE-2026-34841
CVE-2026-34841
pkg: axios

published: Apr 6, 2026

Bruno is an open source IDE for exploring and testing APIs. Prior to 3.2.1, Bruno was affected by a supply chain attack involving compromised versions of the axios npm package, which introduced a hidden dependency deploying a cross-platform Remote Access Trojan (RAT). Users of @usebruno/cli who ran …
CWE: CWE-494, CWE-506
GitHub-GHSA

CRITICAL
PraisonAI Vulnerable to OS Command Injection
GHSA-2763-cj5r-c79m
pkg: PraisonAI
eco: pip
published: Apr 8, 2026
The `execute_command` function and workflow shell execution are exposed to user-controlled input via agent workflows, YAML definitions, and LLM-generated tool calls, allowing attackers to inject arbitrary shell commands through shell metacharacters.

## Description

PraisonAI's workflow system …

CVE-2026-40088
GitHub-GHSA

CRITICAL
parisneo/lollms vulnerable to stored XSS in the social feature
GHSA-8wrq-fv5f-pfp2
pkg: lollms
eco: pip
published: Apr 10, 2026
A Stored Cross-Site Scripting (XSS) vulnerability was identified in the social feature of parisneo/lollms, affecting the latest version prior to 2.2.0. The vulnerability exists in the `create_post` function within `backend/routers/social/__init__.py`, where user-provided content is directly assigned…
CVE-2026-1115
NVD

CRITICAL
CVE-2026-5874
CVE-2026-5874
pkg: go

published: Apr 8, 2026

Use after free in PrivateAI in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-416, CWE-416
GitHub-GHSA

CRITICAL
@delmaredigital/payload-puc is missing authorization on /api/puck/* CRUD endpoints allows unauthenticated access to Puck-registered collections
GHSA-65w6-pf7x-5g85
pkg: @delmaredigital/payload-puck
eco: npm
published: Apr 8, 2026
### Impact

All `/api/puck/*` CRUD endpoint handlers registered by `createPuckPlugin()` called Payload's local API with the default `overrideAccess: true`, bypassing all collection-level access control. The `access` option passed to `createPuckPlugin()` and any `access` rules defined on Puck-registe…

CVE-2026-39397
GitHub-GHSA

CRITICAL
PraisonAI Vulnerable Untrusted Remote Template Code Execution
GHSA-pv9q-275h-rh7x
pkg: PraisonAI
eco: pip
published: Apr 10, 2026
PraisonAI treats remotely fetched template files as trusted executable code without integrity verification, origin validation, or user confirmation, enabling supply chain attacks through malicious templates.

## Description

When a user installs a template from a remote source (e.g., GitHub), P…

CVE-2026-40154
GitHub-GHSA

CRITICAL
gramps-webapi: Zip Slip Path Traversal in Media Archive Import
GHSA-m5gr-86j6-99jp
pkg: gramps-webapi
eco: pip
published: Apr 10, 2026
## Summary

A path traversal vulnerability (Zip Slip) exists in the media archive import feature. An authenticated user with owner-level privileges can craft a malicious ZIP file with directory-traversal filenames to write arbitrary files outside the intended temporary extraction directory on the se…

CVE-2026-40258
GitHub-GHSA

CRITICAL
nimiq-blockchain is missing a wall-clock upper bound on block timestamps
GHSA-49xc-52mp-cc9j
pkg: nimiq-blockchain
eco: rust
published: Apr 10, 2026
### Impact

Block timestamp validation enforces that `timestamp >= parent.timestamp` for non-skip blocks and `timestamp == parent.timestamp + MIN_PRODUCER_TIMEOUT` for skip blocks, but there is no visible upper bound check against the wall clock. A malicious block-producing validator can set block t…

CVE-2026-40093
GitHub-GHSA

CRITICAL
PraisonAI Browser Server allows unauthenticated WebSocket clients to hijack connected extension sessions
GHSA-8x8f-54wf-vv92
pkg: praisonaiagents, PraisonAI
eco: pip
published: Apr 10, 2026
### Summary
`praisonai browser start` exposes the browser bridge on `0.0.0.0` by default, and its `/ws` endpoint accepts websocket clients that omit the `Origin` header entirely. An unauthenticated network client can connect as a fake controller, send `start_session`, cause the server to forward `st…
GitHub-GHSA

CRITICAL
LXD: VM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf
GHSA-fm2x-c5qw-4h6f
pkg: github.com/canonical/lxd
eco: go
published: Apr 10, 2026
## Summary

The `isVMLowLevelOptionForbidden` function in `lxd/project/limits/permissions.go` is missing `raw.apparmor` and `raw.qemu.conf` from its hardcoded forbidden list. A user with `can_edit` permission on a VM instance in a restricted project can combine these two omissions to bridge the LXD …

CVE-2026-34177
GitHub-GHSA

CRITICAL
LXD: Importing a crafted backup leads to project restriction bypass
GHSA-q96j-3fmm-7fv4
pkg: github.com/canonical/lxd
eco: go
published: Apr 10, 2026
## Summary

LXD instance backup import validates project restrictions against `backup/index.yaml` embedded in the tar archive, but creates the actual instance from `backup/container/backup.yaml` extracted to the storage volume. Because these are separate, independently attacker-controlled files with…

CVE-2026-34178
GitHub-GHSA

CRITICAL
LXD: Update of type field in restricted TLS certificate allows privilege escalation to cluster admin
GHSA-c3h3-89qf-jqm5
pkg: github.com/canonical/lxd
eco: go
published: Apr 10, 2026
### Summary

A restricted TLS certificate user can escalate to cluster admin by changing their certificate type from `client` to `server` via PUT/PATCH to `/1.0/certificates/{fingerprint}`. The non-admin guard and reset block in `doCertificateUpdate` fail to validate or reset the `Type` field, allow…

CVE-2026-34179
GitHub-GHSA

CRITICAL
Apache Tomcat: CLIENT_CERT authentication does not fail as expected
GHSA-95jq-rwvf-vjx4
pkg: org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat-catalina
eco: maven
published: Apr 9, 2026
CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52, from 9.0.83 through 9.0.115; Apache Tomcat Nativ…

CVE-2026-29145
GitHub-GHSA

CRITICAL
Apache Airflow: JWT token still valid after logout
GHSA-c92r-g8j5-vhcx
pkg: apache-airflow
eco: pip
published: Apr 9, 2026
When user logged out, the JWT token the user had authtenticated with was not invalidated, which could lead to reuse of that token in case it was intercepted. In Airflow 3.2 we implemented the mechanism that implements token invalidation at logout. Users who are concerned about the logout scenario an…
CVE-2025-57735
NVD

CRITICAL
CVE-2025-57735
CVE-2025-57735
pkg: jwt

published: Apr 9, 2026

When user logged out, the JWT token the user had authtenticated with was not invalidated, which could lead to reuse of that token in case it was intercepted. In Airflow 3.2 we implemented the mechanism that implements token invalidation at logout. Users who are concerned about the logout scenario an…
CWE: CWE-613
NVD

CRITICAL
CVE-2026-34179
CVE-2026-34179
pkg: tls

published: Apr 9, 2026

In Canonical LXD versions 4.12 through 6.7, the doCertificateUpdate function in lxd/certificates.go does not validate the Type field when handling PUT/PATCH requests to /1.0/certificates/{fingerprint} for restricted TLS certificate users, allowing a remote authenticated attacker to escalate privileg…
CWE: CWE-915
GitHub-GHSA

CRITICAL
SiYuan: Remote Code Execution in the Electron desktop client via stored XSS in synced table captions
GHSA-phhp-9rm9-6gr2
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: Apr 8, 2026
### Summary
A malicious note synced to another user can trigger remote code execution in the SiYuan Electron desktop client. The root cause is that table caption content is stored without safe escaping and later unescaped into rendered HTML, creating a stored XSS sink. Because the desktop renderer r…
CVE-2026-39846
GitHub-GHSA

CRITICAL
Emmett has a path traversal in internal assets handler
GHSA-pr46-2v3c-5356
pkg: emmett
eco: pip
published: Apr 8, 2026
The RSGI static handler for Emmett's internal assets (`/__emmett__` paths) is vulnerable to path traversal attacks.

An attacker can use `../` sequences (eg `/__emmett__/../rsgi/handlers.py`) to read arbitrary files outside the assets directory.

CVE-2026-39847
GitHub-GHSA

CRITICAL
Emissary has GitHub Actions Shell Injection via Workflow Inputs
GHSA-3g6g-gq4r-xjm9
pkg: gov.nsa.emissary:emissary
eco: maven
published: Apr 8, 2026
## Summary

Three GitHub Actions workflow files contained **10 shell injection points** where
user-controlled `workflow_dispatch` inputs were interpolated directly into shell
commands via `${{ }}` expression syntax. An attacker with repository write access
could inject arbitrary shell commands, lead…

CVE-2026-35580
NVD

CRITICAL
CVE-2026-39847
CVE-2026-39847
pkg: python

published: Apr 7, 2026

Emmett is a full-stack Python web framework designed with simplicity. From 2.5.0 to before 2.8.1, the RSGI static handler for Emmett's internal assets (/__emmett__ paths) is vulnerable to path traversal attacks. An attacker can use ../ sequences (eg /__emmett__/../rsgi/handlers.py) to read arbitrary…
CWE: CWE-22
NVD

CRITICAL
CVE-2026-28386
CVE-2026-28386
pkg: tls

published: Apr 7, 2026

Issue summary: Applications using AES-CFB128 encryption or decryption on
systems with AVX-512 and VAES support can trigger an out-of-bounds read
of up to 15 bytes when processing partial cipher blocks.

Impact summary: This out-of-bounds read may trigger a crash which leads to
Denial of Service for …

CWE: CWE-125
NVD

CRITICAL
CVE-2026-35580
CVE-2026-35580
pkg: express

published: Apr 7, 2026

Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, GitHub Actions workflow files contained shell injection points where user-controlled workflow_dispatch inputs were interpolated directly into shell commands via ${{ }} expression syntax. An attacker with repository write access co…
CWE: CWE-77
NVD

CRITICAL
CVE-2026-35459
CVE-2026-35459
pkg: python

published: Apr 6, 2026

pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, pyLoad has a server-side request forgery (SSRF) vulnerability. The fix for CVE-2026-33992 added IP validation to BaseDownloader.download() that checks the hostname of the initial download URL. However,…
CWE: CWE-918
NVD

CRITICAL
CVE-2026-35050
CVE-2026-35050
pkg: python

published: Apr 6, 2026

text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.1.1, users can save extention settings in "py" format and in the app root directory. This allows to overwrite python files, for instance the "download-model.py" file could be overwritten. Then, this p…
CWE: CWE-22
NVD

CRITICAL
CVE-2026-35030
CVE-2026-35030
pkg: litellm litellm

published: Apr 6, 2026

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, when JWT authentication is enabled (enable_jwt_auth: true), the OIDC userinfo cache uses token[:20] as the cache key. JWT headers produced by the same signing algorithm generate identical first 20 …
CWE: CWE-287
NVD

CRITICAL
CVE-2026-34950
CVE-2026-34950
pkg: jwt

published: Apr 6, 2026

fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.1.0 and earlier, the publicKeyPemMatcher regex in fast-jwt/src/crypto.js uses a ^ anchor that is defeated by any leading whitespace in the key string, re-enabling the exact same JWT algorithm confusion attack that CVE-2023-48223 patche…
CWE: CWE-327
NVD

CRITICAL
CVE-2026-39860
CVE-2026-39860
pkg: linux

published: Apr 8, 2026

Nix is a package manager for Linux and other Unix systems. A bug in the fix for CVE-2024-27297 allowed for arbitrary overwrites of files writable by the Nix process orchestrating the builds (typically the Nix daemon running as root in multi-user installations) by following symlinks during fixed-outp…
CWE: CWE-61
NVD

CRITICAL
CVE-2026-39846
CVE-2026-39846
pkg: node

published: Apr 7, 2026

SiYuan is a personal knowledge management system. Prior to 3.6.4, a malicious note synced to another user can trigger remote code execution in the SiYuan Electron desktop client. The root cause is that table caption content is stored without safe escaping and later unescaped into rendered HTML, crea…
CWE: CWE-79, CWE-94
GitHub-GHSA

CRITICAL
PraisonAI Vulnerable to Arbitrary File Write / Path Traversal in Action Orchestrator
GHSA-jfxc-v5g9-38xr
pkg: PraisonAI
eco: pip
published: Apr 6, 2026
The Action Orchestrator feature contains a Path Traversal vulnerability that allows an attacker (or compromised agent) to write to arbitrary files outside of the configured workspace directory. By supplying relative path segments (`../`) in the target path, malicious actions can overwrite sensitive …
CVE-2026-39305
GitHub-GHSA

CRITICAL
goshs has a file-based ACL authorization bypass in goshs state-changing routes
GHSA-wvhv-qcqf-f3cx
pkg: github.com/patrickhener/goshs
eco: go
published: Apr 10, 2026
### Summary
goshs enforces the documented per-folder `.goshs` ACL/basic-auth mechanism for directory listings and file reads, but it does not enforce the same authorization checks for state-changing routes. An unauthenticated attacker can upload files with `PUT`, upload files with multipart `POST /u…
CVE-2026-40189
GitHub-GHSA

CRITICAL
ajenti.plugin.core has password bypass when 2FA is activated
GHSA-3mcx-6wxm-qr8v
pkg: ajenti.plugin.core
eco: pip
published: Apr 10, 2026
### Impact

If the 2FA was activated, it was possible to bypass the password authentication

### Patches

This is fixed in the version 0.112. Users should upgrade to this version as soon as possible.

CVE-2026-40177
GitHub-GHSA

CRITICAL
PraisonAI vulnerable to arbitrary file write via path traversal in `praisonai recipe unpack`
GHSA-99g3-w8gr-x37c
pkg: PraisonAI
eco: pip
published: Apr 10, 2026
| Field | Value |
|—|—|
| Severity | Critical |
| Type | Path traversal — arbitrary file write via `tar.extract()` without member validation |
| Affected | `src/praisonai/praisonai/cli/features/recipe.py:1170-1172` |

## Summary

`cmd_unpack` in the recipe CLI extracts `.praison` tar archives u…

CVE-2026-40157
GitHub-GHSA

CRITICAL
PraisonAIAgents has an OS Command Injection via shell=True in Memory Hooks Executor (memory/hooks.py)
GHSA-v7px-3835-7gjx
pkg: praisonaiagents
eco: pip
published: Apr 10, 2026
Summary

The memory hooks executor in praisonaiagents passes a user-controlled command string
directly to subprocess.run() with shell=True at
src/praisonai-agents/praisonaiagents/memory/hooks.py lines 303 to 305.
No sanitization, no shlex.quote(), no character filter, and no allowlist check
exists a…

CVE-2026-40111
GitHub-GHSA

CRITICAL
Wasmtime with Winch compiler backend on aarch64 may allow a sandbox-escaping memory access
GHSA-xx5w-cvp6-jv83
pkg: wasmtime, wasmtime, wasmtime
eco: rust
published: Apr 10, 2026
### Impact

Wasmtime with its Winch (baseline) non-default compiler backend may allow properly constructed guest Wasm to access host memory outside of its linear-memory sandbox.

This vulnerability requires use of the Winch compiler (`-Ccompiler=winch`). By default, Wasmtime uses its Cranelift backe…

CVE-2026-34987
GitHub-GHSA

CRITICAL
Wasmtime: Miscompiled guest heap access enables sandbox escape on aarch64 Cranelift
GHSA-jhxm-h53p-jm7w
pkg: wasmtime, wasmtime, wasmtime
eco: rust
published: Apr 9, 2026
### Impact

Wasmtime's Cranelift compilation backend contains a bug on aarch64 when performing a certain shape of heap accesses which means that the wrong address is accessed. When combined with explicit bounds checks a guest WebAssembly module this can create a situation where there are two divergi…

CVE-2026-34971
GitHub-GHSA

CRITICAL
Axios has a NO_PROXY Hostname Normalization Bypass Leads to SSRF
GHSA-3p68-rc4w-qgx5
pkg: axios
eco: npm
published: Apr 9, 2026
Axios does not correctly handle hostname normalization when checking `NO_PROXY` rules.
Requests to loopback addresses like `localhost.` (with a trailing dot) or `[::1]` (IPv6 literal) skip `NO_PROXY` matching and go through the configured proxy.

This goes against what developers expect and lets att…

CVE-2025-62718
GitHub-GHSA

CRITICAL
Marimo: Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
GHSA-2679-6mx9-h9xc
pkg: marimo
eco: pip
published: Apr 8, 2026
## Summary

Marimo (19.6k stars) has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint `/terminal/ws` lacks authentication validation, allowing an unauthenticated attacker to obtain a full PTY shell and execute arbitrary system commands.

Unlike other WebSocket endpoints (e.g., `/ws`) th…

CVE-2026-39987
GitHub-GHSA

CRITICAL
Rack::Session::Cookie secrets: decrypt failure fallback enables secretless session forgery and Marshal deserialization
GHSA-33qg-7wpp-89cq
pkg: rack-session
eco: rubygems
published: Apr 8, 2026
`Rack::Session::Cookie` incorrectly handles decryption failures when configured with `secrets:`. If cookie decryption fails, the implementation falls back to a default decoder instead of rejecting the cookie. This allows an unauthenticated attacker to supply a crafted session cookie that is accepted…
CVE-2026-39324
GitHub-GHSA

CRITICAL
OpenIdentityPlatform OpenAM: Pre-Authentication Remote Code Execution via `jato.clientSession` Deserialization in OpenAM
GHSA-2cqq-rpvq-g5qj
pkg: org.openidentityplatform.openam:openam
eco: maven
published: Apr 7, 2026
## Summary

OpenIdentityPlatform OpenAM 16.0.5 (and likely earlier versions) is vulnerable to pre-authentication Remote Code Execution (RCE) via unsafe Java deserialization of the `jato.clientSession` HTTP parameter. This bypasses the `WhitelistObjectInputStream` mitigation that was applied to the `…

CVE-2026-33439
GitHub-GHSA

CRITICAL
PraisonAI Has Path Traversal in FileTools
GHSA-693f-pf34-72c5
pkg: PraisonAI
eco: pip
published: Apr 6, 2026
### Executive Summary:
The path validation has a critical logic bug: it checks for `..` AFTER `normpath()` has already collapsed all `..` sequences. This makes the check completely useless and allows trivial path traversal to any file on the system.
The path validation function also does not resolve…
CVE-2026-35615
GitHub-GHSA

HIGH
mathjs Allows Improperly Controlled Modification of Dynamically-Determined Object Attributes
GHSA-jvff-x2qm-6286
pkg: mathjs
eco: npm
published: Apr 10, 2026
### Impact
Two security vulnerabilities where detected that allowed executing arbitrary JavaScript via the expression parser of mathjs. You can be affected when you have an application where users can evaluate arbitrary expressions using the mathjs expression parser.

### Patches
The problem is patc…

GitHub-GHSA

HIGH
PraisonAI: Hardcoded `approval_mode="auto"` in Chainlit UI Overrides Administrator Configuration, Enabling Unapproved Shell Command Execution
GHSA-qwgj-rrpj-75xm
pkg: PraisonAI
eco: pip
published: Apr 10, 2026
## Summary

The Chainlit UI modules (`chat.py` and `code.py`) hardcode `config.approval_mode = "auto"` after loading administrator configuration from the `PRAISON_APPROVAL_MODE` environment variable, silently overriding any "manual" or "scoped" approval setting. This defeats the human-in-the-loop ap…

GitHub-GHSA

HIGH
Duplicate Advisory: OpenClaw Gateway: RCE and Privilege Escalation from operator.pairing to operator.admin via device.pair.approve
GHSA-r3v5-2grc-429h
pkg: openclaw
eco: npm
published: Apr 10, 2026
### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-hf68-49fm-59cq. This link is maintained to preserve external references.

### Original Description
OpenClaw before 2026.3.22 contains a privilege escalation vulnerability in the device.pair.approve method that …

NVD

HIGH
CVE-2026-35639
CVE-2026-35639
pkg: node

published: Apr 9, 2026

OpenClaw before 2026.3.22 contains a privilege escalation vulnerability in the device.pair.approve method that allows an operator.pairing approver to approve pending device requests with broader operator scopes than the approver actually holds. Attackers can exploit insufficient scope validation to …
CWE: CWE-648
NVD

HIGH
CVE-2026-39911
CVE-2026-39911
pkg: express

published: Apr 9, 2026

Hashgraph Guardian through version 3.5.0 contains an unsandboxed JavaScript execution vulnerability in the Custom Logic policy block worker that allows authenticated Standard Registry users to execute arbitrary code by passing user-supplied JavaScript expressions directly to the Node.js Function() c…
CWE: CWE-668
NVD

HIGH
CVE-2026-30478
CVE-2026-30478
pkg: windows

published: Apr 9, 2026

A Dynamic-link Library Injection vulnerability in GatewayGeo MapServer for Windows version 5 allows attackers to escalate privileges via a crafted executable.
CWE: CWE-427
NVD

HIGH
CVE-2026-5866
CVE-2026-5866
pkg: go

published: Apr 8, 2026

Use after free in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416, CWE-416
NVD

HIGH
CVE-2026-39891
CVE-2026-39891
pkg: express

published: Apr 8, 2026

PraisonAI is a multi-agent teams system. Prior to 4.5.115, the create_agent_centric_tools() function returns tools (like acp_create_file) that process file content using template rendering. When user input from agent.start() is passed directly into these tools without escaping, template expressions …
CWE: CWE-94
GitHub-GHSA

HIGH
AGiXT Vulnerable to Path Traversal in safe_join()
GHSA-5gfj-64gh-mgmw
pkg: agixt
eco: pip
published: Apr 8, 2026
### Summary
The safe_join() function in the essential_abilities extension fails to validate that resolved file paths remain within the designated agent workspace. An authenticated attacker can use directory traversal sequences to read, write, or delete arbitrary files on the server hosting the AGiXT…
CVE-2026-39981
GitHub-GHSA

HIGH
PraisonAI has Template Injection in Agent Tool Definitions
GHSA-hwg5-x759-7wjg
pkg: praisonai
eco: pip
published: Apr 8, 2026
## Summary
Direct insertion of unescaped user input into template-rendering tools allows arbitrary code execution via specially crafted agent instructions.
## Details
The `create_agent_centric_tools()` function returns tools (like `acp_create_file`) that process file content using template rendering…
CVE-2026-39891
GitHub-GHSA

HIGH
Apache Cassandra is vulnerable to privilege escalation in an mTLS environment using MutualTlsAuthenticator
GHSA-qxpc-96fq-wwmg
pkg: org.apache.cassandra:cassandra-all
eco: maven
published: Apr 7, 2026
Privilege escalation in Apache Cassandra 5.0 on an mTLS environment using MutualTlsAuthenticator allows a user with only CREATE permission to associate their own certificate identity with an arbitrary role, including a superuser role, and authenticate as that role via ADD IDENTITY.

Users are re…

CVE-2026-27314
NVD

HIGH
CVE-2026-35463
CVE-2026-35463
pkg: ssl

published: Apr 7, 2026

pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, the ADMIN_ONLY_OPTIONS protection mechanism restricts security-critical configuration values (reconnect scripts, SSL certs, proxy credentials) to admin-only access. However, this protection is only app…
CWE: CWE-78
NVD

HIGH
CVE-2025-65115
CVE-2025-65115
pkg: windows

published: Apr 7, 2026

Remote Code Execution Vulnerability in JP1/IT Desktop Management 2 – Manager on Windows, JP1/IT Desktop Management 2 – Operations Director on Windows, Job Management Partner 1/IT Desktop Management 2 – Manager on Windows, JP1/IT Desktop Management – Manager on Windows, Job Management Partner 1/IT D…
CWE: CWE-73
NVD

HIGH
CVE-2026-35044
CVE-2026-35044
pkg: bentoml bentoml

published: Apr 6, 2026

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.38, the Dockerfile generation function generate_containerfile() in src/bentoml/_internal/container/generate.py uses an unsandboxed jinja2.Environment with the jinja2.ext.do extensi…
CWE: CWE-1336
NVD

HIGH
CVE-2026-35029
CVE-2026-35029
pkg: litellm litellm

published: Apr 6, 2026

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, the /config/update endpoint does not enforce admin role authorization. A user who is already authenticated into the platform can then use this endpoint to modify proxy configuration and environment…
CWE: CWE-863
NVD

HIGH
CVE-2026-35408
CVE-2026-35408
pkg: oauth

published: Apr 6, 2026

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus's Single Sign-On (SSO) login pages lacked a Cross-Origin-Opener-Policy (COOP) HTTP response header. Without this header, a malicious cross-origin window that opens the Directus login page reta…
CWE: CWE-346, CWE-693
GitHub-GHSA

HIGH
PraisonAI Vulnerable to Code Injection and Protection Mechanism Failure
GHSA-3c4r-6p77-xwr7
pkg: PraisonAI
eco: pip
published: Apr 10, 2026
PraisonAI's AST-based Python sandbox can be bypassed using `type.__getattribute__` trampoline, allowing arbitrary code execution when running untrusted agent code.

## Description

The `_execute_code_direct` function in `praisonaiagents/tools/python_tools.py` uses AST filtering to block dangerous Py…

CVE-2026-40158
NVD

HIGH
CVE-2026-40158
CVE-2026-40158
pkg: node

published: Apr 10, 2026

PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI's AST-based Python sandbox can be bypassed using type.__getattribute__ trampoline, allowing arbitrary code execution when running untrusted agent code. The _execute_code_direct function in praisonaiagents/tools/python_tools.py uses…
CWE: CWE-94, CWE-693
NVD

HIGH
CVE-2026-39983
CVE-2026-39983
pkg: node

published: Apr 9, 2026

basic-ftp is an FTP client for Node.js. Prior to 5.2.1, basic-ftp allows FTP command injection via CRLF sequences (\r\n) in file path parameters passed to high-level path APIs such as cd(), remove(), rename(), uploadFrom(), downloadTo(), list(), and removeDir(). The library's protectWhitespace() hel…
CWE: CWE-93
GitHub-GHSA

HIGH
basic-ftp has FTP Command Injection via CRLF
GHSA-chqc-8p9q-pq6q
pkg: basic-ftp
eco: npm
published: Apr 8, 2026
## Summary

`basic-ftp` version `5.2.0` allows FTP command injection via CRLF sequences (`\r\n`) in file path parameters passed to high-level path APIs such as `cd()`, `remove()`, `rename()`, `uploadFrom()`, `downloadTo()`, `list()`, and `removeDir()`. The library's `protectWhitespace()` helper only…

CVE-2026-39983
NVD

HIGH
CVE-2026-33752
CVE-2026-33752
pkg: lexiforest curl_cffi

published: Apr 6, 2026

curl_cffi is the a Python binding for curl. Prior to 0.15.0, curl_cffi does not restrict requests to internal IP ranges, and follows redirects automatically via the underlying libcurl. Because of this, an attacker-controlled URL can redirect requests to internal services such as cloud metadata endpo…
CWE: CWE-918
GitHub-GHSA

HIGH
SiYuan: Publish Reader Path Traversal Delete via `removeUnusedAttributeView`
GHSA-vw86-c94w-v3x4
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: Apr 10, 2026
SiYuan's publish/read-only boundary can be broken through `/api/av/removeUnusedAttributeView`.

A publish-service Reader context can call this endpoint because it is protected only by `CheckAuth`, and publish requests are forwarded upstream with a valid `RoleReader` JWT. The handler accepts attacker…

NVD

HIGH
CVE-2026-5483
CVE-2026-5483
pkg: kubernetes

published: Apr 10, 2026

A flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in the `odh-dashboard` component of Red Hat OpenShift AI (RHOAI) allows for the disclosure of Kubernetes Service Account tokens through a NodeJS endpoint. This could enable an attacker to gain unauthorized access to Kubern…
CWE: CWE-201
NVD

HIGH
CVE-2026-5329
CVE-2026-5329
pkg: linux

published: Apr 9, 2026

Rapid7 Velociraptor versions prior to 0.76.2 contain an improper input validation vulnerability in the client monitoring message handler on the Velociraptor server (primarily Linux) that allows an authenticated remote attacker to write to arbitrary internal server queues via a crafted monitoring m…
CWE: CWE-20
NVD

HIGH
CVE-2026-39974
CVE-2026-39974
pkg: node

published: Apr 9, 2026

n8n-MCP is a Model Context Protocol (MCP) server that provides AI assistants with comprehensive access to n8n node documentation, properties, and operations. Prior to 2.47.4, an authenticated Server-Side Request Forgery in n8n-mcp allows a caller holding a valid AUTH_TOKEN to cause the server to iss…
CWE: CWE-918
GitHub-GHSA

HIGH
n8n-mcp has authenticated SSRF via instance-URL header in multi-tenant HTTP mode
GHSA-4ggg-h7ph-26qr
pkg: n8n-mcp
eco: npm
published: Apr 8, 2026
## Impact
An authenticated Server-Side Request Forgery in `n8n-mcp` allows a caller holding a valid `AUTH_TOKEN` to cause the server to issue HTTP requests to arbitrary URLs supplied through multi-tenant HTTP headers. Response bodies are reflected back through JSON-RPC, so an attacker can read the c…
CVE-2026-39974
GitHub-GHSA

HIGH
PraisonAI Vulnerable to RCE via Automatic tools.py Import
GHSA-g985-wjh9-qxxc
pkg: praisonaiagents, PraisonAI
eco: pip
published: Apr 10, 2026
PraisonAI automatically imports `./tools.py` from the current working directory when launching certain components. This includes call.py, tool_resolver.py, and CLI tool-loading paths.

A malicious tools.py placed in the process working directory is executed immediately, allowing arbitrary Python cod…

GitHub-GHSA

HIGH
PraisonAI Vulnerable to Argument Injection into Cloud Run Environment Variables via Unsanitized Comma in gcloud –set-env-vars
GHSA-fvxx-ggmx-3cjg
pkg: PraisonAI
eco: pip
published: Apr 10, 2026
**Summary**

deploy.py constructs a single comma-delimited string for the gcloud run
deploy –set-env-vars argument by directly interpolating openai_model,
openai_key, and openai_base without validating that these values do not
contain commas. gcloud uses a comma as the key-value pair separator for

CVE-2026-40113
GitHub-GHSA

HIGH
Vikunja vulnerable to Privilege Escalation via Project Reparenting
GHSA-2vq4-854f-5c72
pkg: code.vikunja.io/api
eco: go
published: Apr 10, 2026
## Summary

A user with Write-level access to a project can escalate their permissions to Admin by moving the project under a project they own. After reparenting, the recursive permission CTE resolves ownership of the new parent as Admin on the moved project. The attacker can then delete the project…

CVE-2026-35595
GitHub-GHSA

HIGH
Open Cluster Management (OCM): Cross-cluster privilege escalation via improper Kubernetes client certificate renewal validation
GHSA-q4gv-pjmh-c735
pkg: open-cluster-management.io/ocm
eco: go
published: Apr 7, 2026
A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). Improper validation of Kubernetes client certificate renewal allows a managed cluster administrator to forge a client certificate that can be approved by the OCM controller. This e…
CVE-2026-4740
GitHub-GHSA

HIGH
n8n-mcp has unauthenticated session termination and information disclosure in HTTP transport
GHSA-75hx-xj24-mqrw
pkg: n8n-mcp
eco: npm
published: Apr 10, 2026
### Summary

Several HTTP transport endpoints in n8n-mcp lacked proper authentication, and the health check endpoint exposed sensitive operational metadata without credentials.

### Impact

An unauthenticated attacker with network access to the n8n-mcp HTTP server could disrupt active MCP sessions a…

GitHub-GHSA

HIGH
basic-ftp: Incomplete CRLF Injection Protection Allows Arbitrary FTP Command Execution via Credentials and MKD Commands
GHSA-6v7q-wjvx-w8wg
pkg: basic-ftp
eco: npm
published: Apr 10, 2026
## Summary

basic-ftp's CRLF injection protection (added in commit 2ecc8e2 for GHSA-chqc-8p9q-pq6q) is incomplete. Two code paths bypass the `protectWhitespace()` control character check: (1) the `login()` method directly concatenates user-supplied credentials into USER/PASS FTP commands without any…

GitHub-GHSA

HIGH
Saltcorn has an Unauthenticated Path Traversal in sync endpoints, allowing arbitrary file write and directory read
GHSA-32pv-mpqg-h292
pkg: @saltcorn/server, @saltcorn/server, @saltcorn/server
eco: npm
published: Apr 10, 2026
### Summary

Two unauthenticated path traversal vulnerabilities exist in Saltcorn's mobile sync endpoints. The `POST /sync/offline_changes` endpoint allows an unauthenticated attacker to create arbitrary directories and write a `changes.json` file with attacker-controlled JSON content anywhere on th…

CVE-2026-40163
NVD

HIGH
CVE-2026-39429
CVE-2026-39429
pkg: kubernetes

published: Apr 8, 2026

kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.30.3 and 0.29.3, the cache server is directly exposed by the root shard and has no authentication or authorization in place. This allows anyone who can access the root shard to…
CWE: CWE-302, CWE-862
GitHub-GHSA

HIGH
kcp's cache server is accessible without authentication or authorization checks
GHSA-3j3q-wp9x-585p
pkg: github.com/kcp-dev/kcp, github.com/kcp-dev/kcp
eco: go
published: Apr 8, 2026
### Summary

The cache server is directly exposed by the root shard and has no authentication or authorization in place.
This allows anyone who can access the root shard to read and write to the cache server.

### Details

The cache server is routed in the pre-mux chain in the shard code.
The preHa…

CVE-2026-39429
NVD

HIGH
CVE-2026-34045
CVE-2026-34045
pkg: kubernetes

published: Apr 7, 2026

Podman Desktop is a graphical tool for developing on containers and Kubernetes. Prior to 1.26.2, an unauthenticated HTTP server exposed by Podman Desktop allows any network attacker to remotely trigger denial-of-service conditions and extract sensitive information. By abusing missing connection limi…
CWE: CWE-209, CWE-284, CWE-400
NVD

HIGH
CVE-2026-4740
CVE-2026-4740
pkg: kubernetes

published: Apr 7, 2026

A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). Improper validation of Kubernetes client certificate renewal allows a managed cluster administrator to forge a client certificate that can be approved by the OCM controller. This e…
CWE: CWE-295
NVD

HIGH
CVE-2026-34982
CVE-2026-34982
pkg: express

published: Apr 6, 2026

Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The `complete`, `guitabtooltip` and `printheader` options are missing the `P_MLE` flag, allowing a modeline to be execu…
CWE: CWE-78
GitHub-GHSA

HIGH
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
GHSA-ffq7-898w-9jc4
pkg: DotNetNuke.Core
eco: nuget
published: Apr 10, 2026
A user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user.
GitHub-GHSA

HIGH
SiYuan: Publish Reader Can Arbitrarily Delete Attribute View Files via `/api/av/removeUnusedAttributeView`
GHSA-7m5h-w69j-qggg
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: Apr 10, 2026
## Summary

An authenticated publish-service reader can invoke `/api/av/removeUnusedAttributeView` and cause persistent deletion of arbitrary attribute view (`AV`) definition files from the workspace.

The route is protected only by generic `CheckAuth`, which accepts publish `RoleReader` requests. T…

CVE-2026-40259
GitHub-GHSA

HIGH
PraisonAI: Cross-Origin Agent Execution via Hardcoded Wildcard CORS and Missing Authentication on AGUI Endpoint
GHSA-x462-jjpc-q4q4
pkg: praisonaiagents
eco: pip
published: Apr 10, 2026
## Summary

The AGUI endpoint (`POST /agui`) has no authentication and hardcodes `Access-Control-Allow-Origin: *` on all responses. Combined with Starlette/FastAPI's Content-Type-agnostic JSON parsing, any website a victim visits can silently trigger arbitrary agent execution against a locally-runni…

NVD

HIGH
CVE-2021-47961
CVE-2021-47961
pkg: ssl

published: Apr 10, 2026

A plaintext storage of a password vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access or influence the user's PIN code due to insecure storage. This may lead to unauthorized VPN configuration and potential interception of subsequent VPN traffic when combined …
CWE: CWE-256
GitHub-GHSA

HIGH
bsv-sdk and bsv-wallet persist unverified certifier signatures in acquire_certificate (direct and issuance paths)
GHSA-hc36-c89j-5f4j
pkg: bsv-sdk, bsv-wallet
eco: rubygems
published: Apr 9, 2026
# Unverified certifier signatures persisted by `acquire_certificate`

## Affected packages

Both `bsv-sdk` and `bsv-wallet` are published from the [sgbett/bsv-ruby-sdk](https://github.com/sgbett/bsv-ruby-sdk) repository. The vulnerable code lives in `lib/bsv/wallet_interface/wallet_client.rb`, which…

CVE-2026-40070
GitHub-GHSA

HIGH
RedwoodSDK has a CSRF vulnerability in server function dispatch via GET requests
GHSA-x8rx-789c-2pxq
pkg: rwsdk
eco: npm
published: Apr 8, 2026
**Summary**

Server functions exported from `"use server"` files could be invoked via GET requests, bypassing their intended HTTP method. In cookie-authenticated applications, this allowed cross-site GET navigations to trigger state-changing functions, because browsers send `SameSite=Lax` cookies on…

CVE-2026-39371
GitHub-GHSA

HIGH
File Browser: Proxy auth auto-provisioned users inherit Execute permission and Commands
GHSA-7526-j432-6ppp
pkg: github.com/filebrowser/filebrowser/v2
eco: go
published: Apr 8, 2026
## Summary

The fix in commit `b6a4fb1` ("self-registered users don't get execute perms") stripped `Execute` permission and `Commands` from users created via the signup handler. The same fix was not applied to the proxy auth handler. Users auto-created on first successful proxy-auth login are grante…

CVE-2026-35607
NVD

HIGH
CVE-2026-39371
CVE-2026-39371
pkg: react

published: Apr 7, 2026

RedwoodSDK is a server-first React framework. From 1.0.0-beta.50 to 1.0.5, erver functions exported from "use server" files could be invoked via GET requests, bypassing their intended HTTP method. In cookie-authenticated applications, this allowed cross-site GET navigations to trigger state-changing…
CWE: CWE-352
NVD

HIGH
CVE-2026-39307
CVE-2026-39307
pkg: python

published: Apr 7, 2026

PraisonAI is a multi-agent teams system. Prior to 1.5.113, The PraisonAI templates installation feature is vulnerable to a "Zip Slip" Arbitrary File Write attack. When downloading and extracting template archives from external sources (e.g., GitHub), the application uses Python's zipfile.extractall(…
CWE: CWE-22
GitHub-GHSA

HIGH
PraisonAI Has Arbitrary File Write (Zip Slip) in Templates Extraction
GHSA-4ph2-f6pf-79wv
pkg: PraisonAI
eco: pip
published: Apr 6, 2026
The PraisonAI templates installation feature is vulnerable to a "Zip Slip" Arbitrary File Write attack. When downloading and extracting template archives from external sources (e.g., GitHub), the application uses Python's `zipfile.extractall()` without verifying if the files within the archive resol…
CVE-2026-39307
GitHub-GHSA

HIGH
PraisonAI: Unauthenticated Allow-List Manipulation Bypasses Agent Tool Approval Safety Controls
GHSA-4wr3-f4p3-5wjh
pkg: PraisonAI
eco: pip
published: Apr 10, 2026
## Summary

The gateway's `/api/approval/allow-list` endpoint permits unauthenticated modification of the tool approval allowlist when no `auth_token` is configured (the default). By adding dangerous tool names (e.g., `shell_exec`, `file_write`) to the allowlist, an attacker can cause the `ExecAppro…

CVE-2026-40149
GitHub-GHSA

HIGH
PraisonAI Vulnerable to Implicit Execution of Arbitrary Code via Automatic `tools.py` Loading
GHSA-2g3w-cpc4-chr4
pkg: praisonai
eco: pip
published: Apr 10, 2026
PraisonAI automatically loads a file named `tools.py` from the current working directory to discover and register custom agent tools. This loading process uses `importlib.util.spec_from_file_location` and immediately executes module-level code via `spec.loader.exec_module()` **without explicit user …
CVE-2026-40156
NVD

HIGH
CVE-2026-35625
CVE-2026-35625
pkg: node

published: Apr 9, 2026

OpenClaw before 2026.3.25 contains a privilege escalation vulnerability where silent local shared-auth reconnects auto-approve scope-upgrade requests, widening paired device permissions from operator.read to operator.admin. Attackers can exploit this by triggering local reconnection to silently esca…
CWE: CWE-648
NVD

HIGH
CVE-2026-33793
CVE-2026-33793
pkg: python

published: Apr 9, 2026

An Execution with Unnecessary Privileges vulnerability in the User Interface (UI) of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privileged attacker to gain root privileges, thus compromising the system.

When a configuration that allows unsigned Python op scripts is present…

CWE: CWE-250
GitHub-GHSA

HIGH
Fleet Affected by Local Privilege Escalation via Tcl Command Injection in Orbit
GHSA-rphv-h674-5hp2
pkg: github.com/fleetdm/fleet/v4
eco: go
published: Apr 8, 2026
## Summary

The Orbit agent's FileVault disk encryption key rotation flow on collects a local user's password via a GUI dialog and interpolates it directly into a Tcl/expect script executed via `exec.Command("expect", "-c", script)`. Because the password is inserted into Tcl brace-quoted `send {%s}`…

CVE-2026-27806
GitHub-GHSA

HIGH
OpenEXR has a signed 32-bit Overflow in PIZ Decoder Leads to OOB Read/Write
GHSA-588r-cr5c-w6hf
pkg: OpenEXR, OpenEXR, OpenEXR
eco: pip
published: Apr 8, 2026
## Summary

`internal_exr_undo_piz()` advances the working wavelet pointer with signed 32-bit arithmetic:

“`c
wavbuf += nx * ny * wcount;
“`

Because `nx`, `ny`, and `wcount` are `int`, a crafted EXR file can make this product overflow and wrap. The next channel then decodes from an incorrect add…

CVE-2026-34588
GitHub-GHSA

HIGH
Local settings bypass config trust checks
GHSA-436v-8fw5-4mj8
pkg: mise
eco: rust
published: Apr 7, 2026
### Summary

`mise` loads trust-control settings from a local project `.mise.toml` before the trust check runs. An attacker who can place a malicious `.mise.toml` in a repository can make that same file appear trusted and then reach dangerous directives such as `[env] _.source`, templates, hooks, or…

CVE-2026-35533
NVD

HIGH
CVE-2025-14821
CVE-2025-14821
pkg: windows

published: Apr 7, 2026

A flaw was found in libssh. This vulnerability allows local man-in-the-middle attacks, security downgrades of SSH (Secure Shell) connections, and manipulation of trusted host information, posing a significant risk to the confidentiality, integrity, and availability of SSH communications via an insec…
CWE: CWE-427
NVD

HIGH
CVE-2026-35021
CVE-2026-35021
pkg: express

published: Apr 6, 2026

Anthropic Claude Code CLI and Claude Agent SDK contain an OS command injection vulnerability in the prompt editor invocation utility that allows attackers to execute arbitrary commands by crafting malicious file paths. Attackers can inject shell metacharacters such as $() or backtick expressions int…
CWE: CWE-78
NVD

HIGH
CVE-2026-35043
CVE-2026-35043
pkg: bentoml bentoml

published: Apr 6, 2026

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.38, the cloud deployment path in src/bentoml/_internal/cloud/deployment.py was not included in the fix for CVE-2026-33744. Line 1648 interpolates system_packages directly into a sh…
CWE: CWE-78
GitHub-GHSA

HIGH
goshs is Missing Write Protection for Parametric Data Values
GHSA-2943-crp8-38xx
pkg: github.com/patrickhener/goshs
eco: go
published: Apr 10, 2026
### Summary
The SFTP command rename sanitizes only the source path and not the destination, so it is possible to write outside of the root directory of the SFTP.

### Details

Here is the issue:
“`go
// helper.go:155-215
func cmdFile(root string, r *sftp.Request, ip string, sftpServer *SFTPServer)…

CVE-2026-40188
GitHub-GHSA

HIGH
PraisonAIAgents has SSRF and Local File Read via Unvalidated URLs in web_crawl Tool
GHSA-8f4v-xfm9-3244
pkg: praisonaiagents
eco: pip
published: Apr 10, 2026
## Summary

The `web_crawl()` function in `praisonaiagents/tools/web_crawl_tools.py` accepts arbitrary URLs from AI agents with zero validation. No scheme allowlisting, hostname/IP blocklisting, or private network checks are applied before fetching. This allows an attacker (or prompt injection in cr…

CVE-2026-40150
NVD

HIGH
CVE-2026-35533
CVE-2026-35533
pkg: node

published: Apr 7, 2026

mise manages dev tools like node, python, cmake, and terraform. From 2026.2.18 through 2026.4.5, mise loads trust-control settings from a local project .mise.toml before the trust check runs. An attacker who can place a malicious .mise.toml in a repository can make that same file appear trusted and …
CWE: CWE-284
GitHub-GHSA

HIGH
MONAI: Unsafe functions lead to pickle deserialization rce
GHSA-89gg-p5r5-q6r4
pkg: monai
eco: pip
published: Apr 7, 2026
### Summary
The `algo_from_pickle` function in `monai/auto3dseg/utils.py` causes `pickle.loads(data_bytes)` to be executed, and it does not perform any validation on the input parameters. This ultimately leads to insecure deserialization and can result in code execution vulnerabilities.

### Details…

NVD

HIGH
CVE-2026-35187
CVE-2026-35187
pkg: python

published: Apr 6, 2026

pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, the parse_urls API function in src/pyload/core/api/__init__.py fetches arbitrary URLs server-side via get_url(url) (pycurl) without any URL validation, protocol restriction, or IP blacklist. An authent…
CWE: CWE-918
GitHub-GHSA

HIGH
Ech0: Scoped admin access tokens can bypass least-privilege controls on privileged endpoints, including backup export
GHSA-4h9q-p5j4-xvvh
pkg: github.com/lin-snow/ech0
eco: go
published: Apr 10, 2026
## Summary

Ech0 scoped access tokens do not reliably enforce least privilege: multiple privileged admin routes omit scope checks, and the backup export handler strips token scope metadata entirely, allowing a low-scope admin access token to reach broader admin functionality than intended.

## Impac…

GitHub-GHSA

HIGH
PraisonAI: Unauthenticated WebSocket Endpoint Proxies to Paid OpenAI Realtime API Without Rate Limits
GHSA-q5r4-47m9-5mc7
pkg: PraisonAI
eco: pip
published: Apr 10, 2026
## Summary

The `/media-stream` WebSocket endpoint in PraisonAI's call module accepts connections from any client without authentication or Twilio signature validation. Each connection opens an authenticated session to OpenAI's Realtime API using the server's API key. There are no limits on concurre…

CVE-2026-40116
GitHub-GHSA

HIGH
@vitejs/plugin-rsc has a Denial of Service with React Server Components
GHSA-v457-wxvj-p9w9
pkg: @vitejs/plugin-rsc
eco: npm
published: Apr 10, 2026
### Impact

`@vitejs/plugin-rsc` vendors `react-server-dom-webpack`, which contained a vulnerability in versions prior to 19.2.4. See details in React repository's advisory https://github.com/facebook/react/security/advisories/GHSA-479c-33wc-g2pg

### Patches

Upgrade immediately to `@vitejs/plugin-…

GitHub-GHSA

HIGH
Next.js has a Denial of Service with Server Components
GHSA-q4gf-8mx6-v5v3
pkg: next, next
eco: npm
published: Apr 10, 2026
A vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23869](https://github.com/facebook/react/security/advisories…
GitHub-GHSA

HIGH
React Server Components have a Denial of Service Vulnerability
GHSA-479c-33wc-g2pg
pkg: react-server-dom-parcel, react-server-dom-parcel, react-server-dom-parcel
eco: npm
published: Apr 10, 2026
## Impact

A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack versions 19.0.0, 19.1.0 and 19.2.0. The vulnerability is triggered by sending specially crafted HTTP request…

CVE-2026-23869
GitHub-GHSA

HIGH
Apache ActiveMQ: Denial of Service via Out of Memory vulnerability
GHSA-5568-6qcg-g7fx
pkg: org.apache.activemq:activemq-client, org.apache.activemq:activemq-client, org.apache.activemq:activemq-broker
eco: maven
published: Apr 10, 2026
Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ.

ActiveMQ NIO SSL transports do not correctly handle TLSv1.3 handshake KeyUpdates triggered by clients. This makes it possible for a client to rapidly trigger updates which causes th…

CVE-2026-39304
NVD

HIGH
CVE-2026-39304
CVE-2026-39304
pkg: ssl

published: Apr 10, 2026

Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ.

ActiveMQ NIO SSL transports do not correctly handle TLSv1.3 handshake KeyUpdates triggered by clients. This makes it possible for a client to rapidly trigger updates which causes th…

CWE: CWE-400
GitHub-GHSA

HIGH
Spring Cloud Gateway's SSL bundle configuration silently bypassed
GHSA-hwqh-2684-54fc
pkg: org.springframework.cloud:spring-cloud-gateway
eco: maven
published: Apr 10, 2026
When configuring SSL bundles in Spring Cloud Gateway by using the configuration property spring.ssl.bundle, the configuration was silently ignored and the default SSL configuration was used instead.
Note: The 4.2.x branch is no longer under open source support. If you are using Spring Cloud Gatew…
CVE-2026-22750
NVD

HIGH
CVE-2026-22750
CVE-2026-22750
pkg: ssl

published: Apr 10, 2026

When configuring SSL bundles in Spring Cloud Gateway by using the configuration property spring.ssl.bundle, the configuration was silently ignored and the default SSL configuration was used instead.
Note: The 4.2.x branch is no longer under open source support. If you are using Spring Cloud Gatew…
CWE: CWE-15
GitHub-GHSA

HIGH
Apache Tomcat Missing Encryption of Sensitive Data vulnerability
GHSA-69r9-qgr7-g2wj
pkg: org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat-catalina
eco: maven
published: Apr 9, 2026
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.

This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116.

Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the …

CVE-2026-34486
GitHub-GHSA

HIGH
Apache Tomcat has an Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve
GHSA-rv64-5gf8-9qq8
pkg: org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat-catalina
eco: maven
published: Apr 9, 2026
Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.40 through 9.0.116.

Users are recommended to upgrade to version 11.0.21, 10.1.54 or…

CVE-2026-34483
GitHub-GHSA

HIGH
Apache Tomcat vulnerable to Insertion of Sensitive Information into Log File
GHSA-x4m4-345f-5h5g
pkg: org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat-catalina
eco: maven
published: Apr 9, 2026
Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.13 through 9.0.116.

Users…

CVE-2026-34487
GitHub-GHSA

HIGH
Apache Tomcat has an HTTP Request/Response Smuggling vulnerability
GHSA-563x-q5rq-57qp
pkg: org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat-catalina
eco: maven
published: Apr 9, 2026
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M1 through 9.0.115, from 8.5.0 through 8.5.100, f…

CVE-2026-24880
GitHub-GHSA

HIGH
Apache Tomcat: Configured cipher preference order not preserved
GHSA-69cc-cv78-qc8g
pkg: org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat-catalina
eco: maven
published: Apr 9, 2026
Configured cipher preference order not preserved vulnerability in Apache Tomcat.

This issue affects Apache Tomcat: from 11.0.16 through 11.0.18, from 10.1.51 through 10.1.52, from 9.0.114 through 9.0.115.

Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.

CVE-2026-29129
GitHub-GHSA

HIGH
Apache Tomcat: Padding Oracle vulnerability in EncryptInterceptor
GHSA-h468-7pvh-8vr8
pkg: org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat-catalina
eco: maven
published: Apr 9, 2026
Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109.

Users are recommen…

CVE-2026-29146
GitHub-GHSA

HIGH
bsv-sdk ARC broadcaster treats INVALID/MALFORMED/ORPHAN responses as successful broadcasts
GHSA-9hfr-gw99-8rhx
pkg: bsv-sdk
eco: rubygems
published: Apr 9, 2026
# ARC broadcaster treats failure statuses as successful broadcasts

## Summary

`BSV::Network::ARC`'s failure detection only recognises `REJECTED` and `DOUBLE_SPEND_ATTEMPTED`. ARC responses with `txStatus` values of `INVALID`, `MALFORMED`, `MINED_IN_STALE_BLOCK`, or any `ORPHAN`-containing `extraIn…

CVE-2026-40069
NVD

HIGH
CVE-2026-34487
CVE-2026-34487
pkg: kubernetes

published: Apr 9, 2026

Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.13 through 9.0.116.

Users…

CWE: CWE-532
GitHub-GHSA

HIGH
Apache OpenMeetings Uses GET Request Method With Sensitive Query Strings
GHSA-gcvm-c75m-h4p4
pkg: org.apache.openmeetings:openmeetings-parent
eco: maven
published: Apr 9, 2026
Use of GET Request Method With Sensitive Query Strings vulnerability in Apache OpenMeetings.

The REST login endpoint uses HTTP GET method with username and password passed as query parameters. Please check references regarding possible impact

This issue affects Apache OpenMeetings: from 3.1.3 be…

CVE-2026-34020
GitHub-GHSA

HIGH
Apache OpenMeetings Uses Hard-coded Cryptographic Key
GHSA-wqxq-w68r-wg85
pkg: org.apache.openmeetings:openmeetings-parent
eco: maven
published: Apr 9, 2026
Use of Hard-coded Cryptographic Key vulnerability in Apache OpenMeetings.

The remember-me cookie encryption key is set to default value in openmeetings.properties and not being auto-rotated. In case OM admin hasn't changed the default encryption key, an attacker who has stolen a cookie from a logge…

CVE-2026-33266
NVD

HIGH
CVE-2026-1584
CVE-2026-1584
pkg: tls

published: Apr 9, 2026

A flaw was found in gnutls. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted ClientHello message with an invalid Pre-Shared Key (PSK) binder value during the TLS handshake. This can lead to a NULL pointer dereference, causing the server to crash and re…
CWE: CWE-476
GitHub-GHSA

HIGH
HashiCorp's go-getter library may allow arbitrary file reads
GHSA-92mm-2pjq-r785
pkg: github.com/hashicorp/go-getter
eco: go
published: Apr 9, 2026
HashiCorp's go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously crafted URL. This is fixed in go-getter v1.8.6. This vulnerability does not affect the go-getter/v2 branch and package.
CVE-2026-4660
GitHub-GHSA

HIGH
Apache DolphinScheduler vulnerable to sensitive information disclosure
GHSA-3cjc-vhfm-ffp2
pkg: org.apache.dolphinscheduler:dolphinscheduler
eco: maven
published: Apr 9, 2026
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Apache DolphinScheduler.

This vulnerability may allow unauthorized actors to access sensitive information, including database credentials.

This issue affects Apache DolphinScheduler versions 3.1.*.

Users are r…

CVE-2025-62188
GitHub-GHSA

HIGH
Duplicate Advisory: Unfurl's unbounded zlib decompression allows decompression bomb DoS
GHSA-c3f2-qg8v-25q2
pkg: dfir-unfurl
eco: pip
published: Apr 9, 2026
### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-h5qv-qjv4-pc5m. This link is maintained to preserve external references.

### Original Description
Unfurl before 2026.04 contains an unbounded zlib decompression vulnerability in parse_compressed.py that allow…

NVD

HIGH
CVE-2026-5886
CVE-2026-5886
pkg: go

published: Apr 8, 2026

Out of bounds read in WebAudio in Google Chrome on Mac prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-125, CWE-125
NVD

HIGH
CVE-2026-39863
CVE-2026-39863
pkg: tls

published: Apr 8, 2026

Kamailio is an open source implementation of a SIP Signaling Server. Prior to 6.1.1, 6.0.6, and 5.8.8, an out-of-bounds access in the core of Kamailio (formerly OpenSER and SER) allows remote attackers to cause a denial of service (process crash) via a specially crafted data packet sent over TCP. Th…
CWE: CWE-119
NVD

HIGH
CVE-2026-23869
CVE-2026-23869
pkg: react

published: Apr 8, 2026

A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack and react-server-dom-webpack (versions 19.0.0 through 19.0.4, 19.1.0 through 19.1.5, and 19.2.0 through 19.2.4). The vulnerability is triggered b…
CWE: CWE-400, CWE-502
GitHub-GHSA

HIGH
mcp-from-openapi is Vulnerable to SSRF via $ref Dereferencing in Untrusted OpenAPI Specifications
GHSA-v6ph-xcq9-qxxj
pkg: mcp-from-openapi, @frontmcp/sdk, @frontmcp/adapters
eco: npm
published: Apr 8, 2026
## Summary

The `mcp-from-openapi` library uses `@apidevtools/json-schema-ref-parser` to dereference `$ref` pointers in OpenAPI specifications without configuring any URL restrictions or custom resolvers. A malicious OpenAPI specification containing `$ref` values pointing to internal network address…

CVE-2026-39885
GitHub-GHSA

HIGH
PraisonAI Has Unauthenticated SSE Event Stream that Exposes All Agent Activity in A2U Server
GHSA-f292-66h9-fpmf
pkg: praisonai
eco: pip
published: Apr 8, 2026
The A2U (Agent-to-User) event stream server in PraisonAI exposes all agent activity without authentication. This is a separate component from the gateway server fixed in CVE-2026-34952.

The create_a2u_routes() function registers the following endpoints with NO authentication checks:
– GET /a2u/inf…

CVE-2026-39889
GitHub-GHSA

HIGH
LiquidJS: Root restriction bypass for partial and layout loading through symlinked templates
GHSA-56p5-8mhr-2fph
pkg: liquidjs
eco: npm
published: Apr 8, 2026
### Summary

LiquidJS enforces partial and layout root restrictions using the resolved pathname string, but it does not resolve the canonical filesystem path before opening the file. A symlink placed inside an allowed partials or layouts directory can therefore point to a file outside that directory…

CVE-2026-35525
GitHub-GHSA

HIGH
Drizzle ORM has SQL injection via improperly escaped SQL identifiers
GHSA-gpj5-g38j-94v9
pkg: drizzle-orm, drizzle-orm
eco: npm
published: Apr 8, 2026
### Summary

Drizzle ORM improperly escaped quoted SQL identifiers in its dialect-specific `escapeName()` implementations. In affected versions, embedded identifier delimiters were not escaped before the identifier was wrapped in quotes or backticks.

As a result, applications that pass attacker-con…

CVE-2026-39356
GitHub-GHSA

HIGH
FastFeedParser has an infinite redirect loop DoS via meta-refresh chain
GHSA-4gx2-pc4f-wq37
pkg: fastfeedparser
eco: pip
published: Apr 8, 2026
### Summary
When `parse()` fetches a URL that returns an HTML page containing a `<meta http-equiv="refresh">` tag, it recursively calls itself with the redirect URL — with no depth limit, no visited-URL deduplication, and no redirect count cap. An attacker-controlled server that returns an infinit…
CVE-2026-39376
GitHub-GHSA

HIGH
Addressable has a Regular Expression Denial of Service in Addressable templates
GHSA-h27x-rffw-24p4
pkg: addressable
eco: rubygems
published: Apr 8, 2026
### Impact

Within the URI template implementation in Addressable, two classes of URI template generate regular expressions vulnerable to catastrophic backtracking:

1. Templates using the `*` (explode) modifier with any expansion operator (e.g., `{foo*}`, `{+var*}`, `{#var*}`, `{/var*}`, `{.var*}`,…

CVE-2026-35611
NVD

HIGH
CVE-2026-34079
CVE-2026-34079
pkg: linux

published: Apr 7, 2026

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the caching for ld.so removes outdated cache files without properly checking that the app controlled path to the outdated cache is in the cache directory. This allows Flatpak apps to delete arbitrary files on the…
CWE: CWE-22
NVD

HIGH
CVE-2026-28390
CVE-2026-28390
pkg: openssl

published: Apr 7, 2026

Issue summary: During processing of a crafted CMS EnvelopedData message
with KeyTransportRecipientInfo a NULL pointer dereference can happen.

Impact summary: Applications that process attacker-controlled CMS data may
crash before authentication or cryptographic operations occur resulting in
Denial …

CWE: CWE-476
NVD

HIGH
CVE-2026-28389
CVE-2026-28389
pkg: openssl

published: Apr 7, 2026

Issue summary: During processing of a crafted CMS EnvelopedData message
with KeyAgreeRecipientInfo a NULL pointer dereference can happen.

Impact summary: Applications that process attacker-controlled CMS data may
crash before authentication or cryptographic operations occur resulting in
Denial of S…

CWE: CWE-476
NVD

HIGH
CVE-2026-28388
CVE-2026-28388
pkg: openssl

published: Apr 7, 2026

Issue summary: When a delta CRL that contains a Delta CRL Indicator extension
is processed a NULL pointer dereference might happen if the required CRL
Number extension is missing.

Impact summary: A NULL pointer dereference can trigger a crash which
leads to a Denial of Service for an application.

CWE: CWE-476
GitHub-GHSA

HIGH
GenieACS has an unauthenticated access vulnerability via the NBI API endpoint
GHSA-2h6j-mhcp-9j9h
pkg: genieacs
eco: npm
published: Apr 7, 2026
In GenieACS 1.2.13, an unauthenticated access vulnerability exists in the NBI API endpoint.
CVE-2025-56015
NVD

HIGH
CVE-2026-29181
CVE-2026-29181
pkg: go

published: Apr 7, 2026

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregates members across values. This allows an attacker to amplify cpu and allocations by sending many baggage: header lines, e…
CWE: CWE-770
NVD

HIGH
CVE-2026-39376
CVE-2026-39376
pkg: python

published: Apr 7, 2026

FastFeedParser is a high performance RSS, Atom and RDF parser. Prior to 0.5.10, when parse() fetches a URL that returns an HTML page containing a <meta http-equiv="refresh"> tag, it recursively calls itself with the redirect URL — with no depth limit, no visited-URL deduplication, and no redirect …
CWE: CWE-674
GitHub-GHSA

HIGH
OpenTelemetry-Go: multi-value `baggage` header extraction causes excessive allocations (remote dos amplification)
GHSA-mh2q-q3fh-2475
pkg: go.opentelemetry.io/otel/baggage, go.opentelemetry.io/otel/propagation
eco: go
published: Apr 7, 2026
multi-value `baggage:` header extraction parses each header field-value independently and aggregates members across values. this allows an attacker to amplify cpu and allocations by sending many `baggage:` header lines, even when each individual value is within the 8192-byte per-value parse limit.

CVE-2026-29181
NVD

HIGH
CVE-2026-35611
CVE-2026-35611
pkg: express

published: Apr 7, 2026

Addressable is an alternative implementation to the URI implementation that is part of Ruby's standard library. From 2.3.0 to before 2.9.0, within the URI template implementation in Addressable, two classes of URI template generate regular expressions vulnerable to catastrophic backtracking. Templat…
CWE: CWE-1333
GitHub-GHSA

HIGH
Django vulnerable to ASGI header spoofing via underscore/hyphen conflation
GHSA-mvfq-ggxm-9mc5
pkg: Django, Django, Django
eco: pip
published: Apr 7, 2026
An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `ASGIRequest` allows a remote attacker to spoof headers by exploiting an ambiguous mapping of two header variants (with hyphens or with underscores) to a single version with underscores.

Earlier, unsupported Djan…

CVE-2026-3902
GitHub-GHSA

HIGH
Django: SGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit
GHSA-933h-hp56-hf7m
pkg: Django, Django, Django
eco: pip
published: Apr 7, 2026
An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. ASGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit when reading `HttpRequest.body`, allowing remote attackers to load an unbounded request body…
CVE-2026-33034
NVD

HIGH
CVE-2026-35464
CVE-2026-35464
pkg: python

published: Apr 7, 2026

pyLoad is a free and open-source download manager written in Python. The fix for CVE-2026-33509 added an ADMIN_ONLY_OPTIONS set to block non-admin users from modifying security-critical config options. The storage_folder option is not in this set and passes the existing path restriction because the …
CWE: CWE-502, CWE-863
NVD

HIGH
CVE-2026-31842
CVE-2026-31842
pkg: nginx

published: Apr 7, 2026

Tinyproxy through 1.11.3 is vulnerable to HTTP request parsing desynchronization due to a case-sensitive comparison of the Transfer-Encoding header in src/reqs.c. The is_chunked_transfer() function uses strcmp() to compare the header value against "chunked", even though RFC 7230 specifies that trans…
CWE: CWE-444
GitHub-GHSA

HIGH
strawberry-graphql: Denial of Service via unbounded WebSocket subscriptions
GHSA-hv3w-m4g2-5×77
pkg: strawberry-graphql
eco: pip
published: Apr 6, 2026
Strawberry GraphQL's WebSocket subscription handlers for both the `graphql-transport-ws` and legacy `graphql-ws` protocols allocate an `asyncio.Task` and associated `Operation` object for every incoming subscribe message without enforcing any limit on the number of active subscriptions per connectio…
CVE-2026-35526
GitHub-GHSA

HIGH
strawberry-graphql: Authentication bypass via legacy graphql-ws WebSocket subprotocol
GHSA-vpwc-v33q-mq89
pkg: strawberry-graphql
eco: pip
published: Apr 6, 2026
Strawberry up until version `0.312.3` is vulnerable to an authentication bypass on WebSocket subscription endpoints. The legacy graphql-ws subprotocol handler does not verify that a `connection_init` handshake has been completed before processing start (subscription) messages. This allows a remote a…
CVE-2026-35523
GitHub-GHSA

HIGH
Distribution: stale blob access resurrection via repo-scoped redis descriptor cache invalidation
GHSA-f2g3-hh2r-cwgc
pkg: github.com/distribution/distribution/v3, github.com/distribution/distribution
eco: go
published: Apr 6, 2026
## summary:
distribution can restore read access in `repo a` after an explicit delete when `storage.cache.blobdescriptor: redis` and `storage.delete.enabled: true` are both enabled. the delete path clears the shared digest descriptor but leaves stale repo-scoped membership behind, so a later `Stat` …
CVE-2026-35172
GitHub-GHSA

HIGH
Distribution affected by pull-through cache credential exfiltration via www-authenticate bearer realm
GHSA-3p65-76g6-3w7r
pkg: github.com/distribution/distribution/v3, github.com/distribution/distribution
eco: go
published: Apr 6, 2026
hi guys,

commit: 40594bd98e6d6ed993b5c6021c93fdf96d2e5851 (as-of 2026-01-31)
contact: GitHub Security Advisory (https://github.com/distribution/distribution/security/advisories/new)

## summary

in pull-through cache mode, distribution discovers token auth endpoints by parsing `WWW-Authenticate` ch…

CVE-2026-33540
NVD

HIGH
CVE-2026-34986
CVE-2026-34986
pkg: go

published: Apr 6, 2026

Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and 3.0.5, decrypting a JSON Web Encryption (JWE) object will panic…
CWE: CWE-248
NVD

HIGH
CVE-2026-34211
CVE-2026-34211
pkg: nyariv sandboxjs

published: Apr 6, 2026

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, the @nyariv/sandboxjs parser contains unbounded recursion in the restOfExp function and the lispify/lispifyExpr call chain. An attacker can crash any Node.js process that parses untrusted input by supplying deeply nested expressions (e.g…
CWE: CWE-674
GitHub-GHSA

HIGH
PraisonAIAgents: Environment Variable Secret Exfiltration via os.path.expandvars() Bypassing shell=False in Shell Tool
GHSA-v8g7-9q6v-p3x8
pkg: praisonaiagents
eco: pip
published: Apr 10, 2026
## Summary

The `execute_command` function in `shell_tools.py` calls `os.path.expandvars()` on every command argument at line 64, manually re-implementing shell-level environment variable expansion despite using `shell=False` (line 88) for security. This allows exfiltration of secrets stored in envi…

CVE-2026-40153
NVD

HIGH
CVE-2026-34727
CVE-2026-34727
pkg: jwt

published: Apr 10, 2026

Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the OIDC callback handler issues a full JWT token without checking whether the matched user has TOTP two-factor authentication enabled. When a local user with TOTP enrolled is matched via the OIDC email fallback mechanis…
CWE: CWE-287
GitHub-GHSA

HIGH
Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path
GHSA-8jvc-mcx6-r4cg
pkg: code.vikunja.io/api
eco: go
published: Apr 10, 2026
## Summary

The OIDC callback handler issues a full JWT token without checking whether the matched user has TOTP two-factor authentication enabled. When a local user with TOTP enrolled is matched via the OIDC email fallback mechanism, the second factor is completely skipped.

## Details

The OIDC ca…

CVE-2026-34727
GitHub-GHSA

HIGH
Eclipse Jetty: Early return from the JASPIAuthenticator code can potentially no clear ThreadLocal variables
GHSA-gc59-r5jq-98qw
pkg: org.eclipse.jetty.ee10:jetty-ee10, org.eclipse.jetty.ee10:jetty-ee10, org.eclipse.jetty.ee10:jetty-ee10
eco: maven
published: Apr 8, 2026
In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable.

Upon returning from the initial checks, there are conditions that cause an early return from the JASPIAuthenticator code without clearing those ThreadLocals.

A subsequent reque…

CVE-2026-5795
NVD

HIGH
CVE-2026-4158
CVE-2026-4158
pkg: openssl

published: Apr 11, 2026

KeePassXC OpenSSL Configuration Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of KeePassXC. An attacker must first obtain the ability to execute low-privileged code on the target s…
CWE: CWE-427
NVD

HIGH
CVE-2026-5974
CVE-2026-5974
pkg: react

published: Apr 9, 2026

A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the probl…
CWE: CWE-77, CWE-78
NVD

HIGH
CVE-2026-5973
CVE-2026-5973
pkg: react

published: Apr 9, 2026

A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file metagpt/utils/common.py. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. The project was in…
CWE: CWE-77, CWE-78
NVD

HIGH
CVE-2026-5971
CVE-2026-5971
pkg: react

published: Apr 9, 2026

A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fill of the file metagpt/actions/action_node.py of the component XML Handler. Executing a manipulation can lead to improper neutralization of directives in dynamically evaluated code…
CWE: CWE-94, CWE-95
NVD

HIGH
CVE-2026-5970
CVE-2026-5970
pkg: react

published: Apr 9, 2026

A vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the component HumanEvalBenchmark/MBPPBenchmark. Performing a manipulation results in code injection. The attack may be initiated remotely. The exploit is now public and may be used. The …
CWE: CWE-74, CWE-94
NVD

HIGH
CVE-2026-5741
CVE-2026-5741
pkg: docker

published: Apr 7, 2026

A weakness has been identified in suvarchal docker-mcp-server up to 0.1.0. The impacted element is the function stop_container/remove_container/pull_image of the file src/index.ts of the component HTTP Interface. This manipulation causes os command injection. The attack is possible to be carried out…
CWE: CWE-77, CWE-78
NVD

HIGH
CVE-2026-5739
CVE-2026-5739
pkg: node

published: Apr 7, 2026

A security flaw has been discovered in PowerJob 5.1.0/5.1.1/5.1.2. The affected element is the function GroovyEvaluator.evaluate of the file /openApi/addWorkflowNode of the component OpenAPI Endpoint. The manipulation of the argument nodeParams results in code injection. The attack can be executed r…
CWE: CWE-74, CWE-94
GitHub-GHSA

HIGH
PraisonAI recipe registry pull path traversal writes files outside the chosen output directory
GHSA-4rx4-4r3x-6534
pkg: PraisonAI
eco: pip
published: Apr 6, 2026
### Summary

PraisonAI's recipe registry pull flow extracts attacker-controlled `.praison` tar archives with `tar.extractall()` and does not validate archive member paths before extraction. A malicious publisher can upload a recipe bundle that contains `../` traversal entries and any user who later …

CVE-2026-39306
GitHub-GHSA

HIGH
Authorizer: CQL/N1QL Injection in Cassandra and Couchbase Backends via fmt.Sprintf String Interpolation
GHSA-jfwg-rxf3-p7r9
pkg: github.com/authorizerdev/authorizer
eco: go
published: Apr 6, 2026
## Vulnerability Details

**CWE:** CWE-943 – Improper Neutralization of Special Elements in Data Query Logic

All 66+ CQL queries in `internal/storage/db/cassandradb/` use `fmt.Sprintf` to interpolate user-controlled values directly into CQL query strings without parameterization.

Unauthenticated e…

NVD

HIGH
CVE-2026-40242
CVE-2026-40242
pkg: docker

published: Apr 10, 2026

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.17.3, the /api/templates/fetch endpoint accepts a caller-supplied url parameter and performs a server-side HTTP GET request to that URL without authentication and without URL scheme or host validation. T…
CWE: CWE-918
GitHub-GHSA

HIGH
Arcane has Unauthenticated SSRF with Conditional Response Reflection in Template Fetch Endpoint
GHSA-ff24-4prj-gpmj
pkg: github.com/getarcaneapp/arcane/backend
eco: go
published: Apr 10, 2026
### Summary
The /api/templates/fetch endpoint accepts a caller-supplied url parameter and performs a server-side HTTP GET request to that URL without authentication and without URL scheme or host validation. The server's response is returned directly to the caller. type. This constitutes an unauthen…
CVE-2026-40242
GitHub-GHSA

HIGH
PraisonAI Vulnerable to Server-Side Request Forgery via Unvalidated webhook_url in Jobs API
GHSA-8frj-8q3m-xhgm
pkg: PraisonAI
eco: pip
published: Apr 10, 2026
## Summary

The `/api/v1/runs` endpoint accepts an arbitrary `webhook_url` in the request body with no URL validation. When a submitted job completes (success or failure), the server makes an HTTP POST request to this URL using `httpx.AsyncClient`. An unauthenticated attacker can use this to make th…

CVE-2026-40114
GitHub-GHSA

HIGH
Emissary has a Command Injection via PLACE_NAME Configuration in Executrix
GHSA-6c37-7w4p-jg9v
pkg: gov.nsa.emissary:emissary
eco: maven
published: Apr 8, 2026
## Summary

The `Executrix` utility class constructed shell commands by concatenating
configuration-derived values — including the `PLACE_NAME` parameter — with
insufficient sanitization. Only spaces were replaced with underscores, allowing
shell metacharacters (`;`, `|`, `$`, “ ` “, `(`, `)`,…

CVE-2026-35581
GitHub-GHSA

HIGH
Bugsink affected by authenticated arbitrary file write in artifactbundle/assemble
GHSA-8hw4-fhww-273g
pkg: bugsink
eco: pip
published: Apr 10, 2026
# Authenticated arbitrary file write in artifact bundle assembly

## Summary

An authenticated file write vulnerability was identified in Bugsink **2.1.0** in the artifact bundle assembly flow.

A user with a valid authentication token could cause the application to write attacker-controlled content…

CVE-2026-40162
NVD

HIGH
CVE-2026-39976
CVE-2026-39976
pkg: jwt

published: Apr 9, 2026

Laravel Passport provides OAuth2 server support to Laravel. From 13.0.0 to before 13.7.1, there is an Authentication Bypass for client_credentials tokens. the league/oauth2-server library sets the JWT sub claim to the client identifier (since there's no user). The token guard then passes this value …
CWE: CWE-287
GitHub-GHSA

HIGH
Tmds.DBus: malicious D-Bus peers can spoof signals, exhaust file descriptor resources, and cause denial of service
GHSA-xrw6-gwf8-vvr9
pkg: Tmds.DBus, Tmds.DBus.Protocol, Tmds.DBus.Protocol
eco: nuget
published: Apr 8, 2026
Tmds.DBus and Tmds.DBus.Protocol are vulnerable to malicious D-Bus peers. A peer on the same bus can spoof signals by impersonating the owner of a well-known name, exhaust system resources or cause file descriptor spillover by sending messages with an excessive number of Unix file descriptors, and c…
CVE-2026-39959
GitHub-GHSA

HIGH
PraisonAI recipe registry publish path traversal allows out-of-root file write
GHSA-r9x3-wx45-2v7f
pkg: PraisonAI
eco: pip
published: Apr 6, 2026
### Summary

PraisonAI's recipe registry publish endpoint writes uploaded recipe bundles to a filesystem path derived from the bundle's internal `manifest.json` before it verifies that the manifest `name` and `version` match the HTTP route. A malicious publisher can place `../` traversal sequences i…

CVE-2026-39308
NVD

HIGH
CVE-2026-39883
CVE-2026-39883
pkg: opentelemetry opentelemetry

published: Apr 8, 2026

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg command to use an absolute path but left the BSD kenv command using a bare name, allowing the same PATH hijacking attack on BSD and Solaris platforms. This vulnerabi…
CWE: CWE-426
GitHub-GHSA

HIGH
Duplicate Advisory: OpenClaw: Plivo V2 verified replay identity drifts on query-only variants
GHSA-j56c-wpqm-h24x
pkg: openclaw
eco: npm
published: Apr 10, 2026
### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-cg6c-q2hx-69h7. This link is maintained to preserve external references.

### Original Description
OpenClaw before 2026.3.23 contains a replay identity vulnerability in Plivo V2 signature verification that allo…

GitHub-GHSA

HIGH
Duplicate Advisory: OpenClaw: `fetchWithSsrFGuard` replays unsafe request bodies across cross-origin redirects
GHSA-pg8g-f2hf-x82m
pkg: openclaw
eco: npm
published: Apr 9, 2026
### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-qx8j-g322-qj6m. This link is maintained to preserve external references.

### Original Description
OpenClaw before 2026.3.31 (patched in 2026.4.8) contains a request body replay vulnerability in fetchWithSsrFGu…

GitHub-GHSA

HIGH
OpenEXR: DWA Lossy Decoder Heap Out-of-Bounds Write
GHSA-p8xc-w3q4-h64x
pkg: OpenEXR, OpenEXR, OpenEXR
eco: pip
published: Apr 8, 2026
## Summary

The DWA lossy decoder constructs temporary per-component block pointers using signed 32-bit arithmetic. For a large enough width, the calculation overflows and later decoder stores operate on a wrapped pointer outside the allocated `rowBlock` backing store.

This bug is reachable from th…

CVE-2026-34589
GitHub-GHSA

HIGH
PraisonAIAgents: SSRF via unvalidated URL in `web_crawl` httpx fallback
GHSA-qq9r-63f6-v542
pkg: praisonaiagents
eco: pip
published: Apr 10, 2026
| Field | Value |
|—|—|
| Severity | High |
| Type | SSRF — unvalidated URL in `web_crawl` httpx fallback allows internal network access |
| Affected | `src/praisonai-agents/praisonaiagents/tools/web_crawl_tools.py:133-180` |

## Summary

`web_crawl`'s httpx fallback path passes user-supplied U…

CVE-2026-40160
GitHub-GHSA

HIGH
SiYuan Affected by Zero-Click NTLM Hash Theft and Blind SSRF via Mermaid Diagram Rendering
GHSA-w95v-4h65-j455
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: Apr 10, 2026
SiYuan configures Mermaid.js with `securityLevel: "loose"` and `htmlLabels: true`. In this mode, `<img>` tags with `src` attributes survive Mermaid's internal DOMPurify and land in SVG `<foreignObject>` blocks. The SVG is injected via `innerHTML` with no secondary sanitization. When a victim opens a…
CVE-2026-40107
GitHub-GHSA

HIGH
@sveltejs/adapter-node has a BODY_SIZE_LIMIT bypass
GHSA-2crg-3p73-43xp
pkg: @sveltejs/kit
eco: npm
published: Apr 10, 2026
Under certain circumstances, requests could bypass the `BODY_SIZE_LIMIT` on SvelteKit applications running with `adapter-node`. This bypass does not affect body size limits at other layers of the application stack, so limits enforced in the WAF, gateway, or at the platform level are unaffected.
CVE-2026-40073
GitHub-GHSA

HIGH
Helm's plugin verification fails open when .prov is missing, allowing unsigned plugin install
GHSA-q5jf-9vfq-h4h7
pkg: helm.sh/helm/v4
eco: go
published: Apr 10, 2026
Helm is a package manager for Charts for Kubernetes. In Helm versions >=4.0.0 and <=4.1.3, Helm will install plugins missing provenance (`.prov` file) when signature verification is required.

### Impact

The bug allows plugin authors to omit provenance (signing) data from plugins, bypassing plugin …

CVE-2026-35205
GitHub-GHSA

HIGH
Helm has a path traversal in plugin metadata version enables arbitrary file write outside Helm plugin directory
GHSA-vmx8-mqv2-9gmg
pkg: helm.sh/helm/v4
eco: go
published: Apr 10, 2026
Helm is a package manager for Charts for Kubernetes. In Helm versions >=4.0.0 and <=4.1.3, a specially crafted Helm plugin, when installed or updated, will cause Helm to write the contents of the plugin to an arbitrary filesystem location.

### Impact

A Helm user who installs or updates a plugin th…

CVE-2026-35204
GitHub-GHSA

HIGH
OpenClaw: `fetchWithSsrFGuard` replays unsafe request bodies across cross-origin redirects
GHSA-qx8j-g322-qj6m
pkg: openclaw
eco: npm
published: Apr 9, 2026
## Impact

`fetchWithSsrFGuard` replays unsafe request bodies across cross-origin redirects.

A guarded fetch could resend unsafe request bodies or headers when following cross-origin redirects.

OpenClaw is a user-controlled local assistant. This advisory is scoped to the OpenClaw trust model and d…

CVE-2026-40037
GitHub-GHSA

HIGH
OpenClaw: Node Pairing Reconnect Command Escalation Bypasses operator.admin Scope Requirement
GHSA-5wj5-87vq-39xm
pkg: openclaw
eco: npm
published: Apr 9, 2026
## Impact

Node Pairing Reconnect Command Escalation Bypasses operator.admin Scope Requirement.

A previously paired node could reconnect with a broader command set, including exec-capable commands, without forcing the operator/admin re-pairing path.

OpenClaw is a user-controlled local assistant. T…

GitHub-GHSA

HIGH
MinIO affected a DoS via Unbounded Memory Allocation in S3 Select CSV Parsing
GHSA-h749-fxx7-pwpg
pkg: github.com/minio/minio
eco: go
published: Apr 9, 2026
### Impact

_What kind of vulnerability is it? Who is impacted?_

MinIO's S3 Select feature is vulnerable to memory exhaustion when processing CSV
files containing lines longer than available memory. The CSV reader's `nextSplit()`
function calls `bufio.Reader.ReadBytes('\n')` with no size limit, b…

CVE-2026-39414
GitHub-GHSA

HIGH
OpenClaw: HGRCPATH, CARGO_BUILD_RUSTC_WRAPPER, RUSTC_WRAPPER, and MAKEFLAGS missing from exec env denylist — RCE via build tool env injection (GHSA-cm8v-2vh9-cxf3 class)
GHSA-7437-7hg8-frrw
pkg: openclaw
eco: npm
published: Apr 9, 2026
## Impact

HGRCPATH, CARGO_BUILD_RUSTC_WRAPPER, RUSTC_WRAPPER, and MAKEFLAGS missing from exec env denylist — RCE via build tool env injection (GHSA-cm8v-2vh9-cxf3 class).

Missing denylist entries allowed hostile build-tool environment variables to influence host exec commands.

OpenClaw is a use…

GitHub-GHSA

HIGH
OpenClaw: Authenticated `/hooks/wake` and mapped `wake` payloads are promoted into the trusted `System:` prompt channel
GHSA-jf56-mccx-5f3f
pkg: openclaw
eco: npm
published: Apr 9, 2026
## Impact

Authenticated `/hooks/wake` and mapped `wake` payloads are promoted into the trusted `System:` prompt channel.

An authenticated wake hook or mapped wake payload could be promoted into the trusted System prompt channel instead of an untrusted event.

OpenClaw is a user-controlled local as…

GitHub-GHSA

HIGH
OpenClaw: Lower-trust background runtime output is injected into trusted `System:` events, and local async exec completion misses the intended `exec-event` downgrade
GHSA-gfmx-pph7-g46x
pkg: openclaw
eco: npm
published: Apr 9, 2026
## Impact

Lower-trust background runtime output is injected into trusted `System:` events, and local async exec completion misses the intended `exec-event` downgrade.

Lower-trust runtime/background output could be promoted into trusted System events, allowing prompt-injection into later agent turn…

GitHub-GHSA

HIGH
Pretext: Algorithmic Complexity (DoS) in the text analysis phase
GHSA-5478-66c3-rhxr
pkg: @chenglou/pretext
eco: npm
published: Apr 8, 2026
`isRepeatedSingleCharRun()` in `src/analysis.ts` (line 285) re-scans the entire accumulated segment on every merge iteration during text analysis, producing O(n²) total work for input consisting of repeated identical punctuation characters. An attacker who controls text passed to `prepare()` can bl…
GitHub-GHSA

HIGH
mercure has Topic Selector Cache Key Collision
GHSA-hwr4-mq23-wcv5
pkg: github.com/dunglas/mercure
eco: go
published: Apr 8, 2026
### Impact

A cache key collision vulnerability in `TopicSelectorStore` allows an attacker to poison the match result cache, potentially causing private updates to be delivered to unauthorized subscribers or blocking delivery to authorized ones.

The cache key was constructed by concatenating the to…

CVE-2026-39972
GitHub-GHSA

HIGH
opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking
GHSA-hfvc-g4fc-pqhx
pkg: go.opentelemetry.io/otel/sdk
eco: go
published: Apr 8, 2026
## Summary

The fix for GHSA-9h8m-3fm2-qjrq (CVE-2026-24051) changed the Darwin `ioreg` command to use an absolute path but left the BSD `kenv` command using a bare name, allowing the same PATH hijacking attack on BSD and Solaris platforms.

## Root Cause

`sdk/resource/host_id.go` line 42:

if …

CVE-2026-39883
GitHub-GHSA

HIGH
stata-mcp has insufficient validation of user-supplied Stata do-file content that can lead to command execution
GHSA-jpcj-7wfg-mqxv
pkg: stata-mcp
eco: pip
published: Apr 8, 2026
A vulnerability was identified in stata-mcp prior to v1.13.0 where insufficient validation of user-supplied Stata do-file content can lead to command execution.
CVE-2026-31040
GitHub-GHSA

HIGH
XWiki vulnerable to remote code execution with script right through unprotected Velocity scripting API
GHSA-h259-74h5-4rh9
pkg: org.xwiki.platform:xwiki-platform-oldcore, org.xwiki.platform:xwiki-platform-oldcore, org.xwiki.platform:xwiki-platform-legacy-oldcore
eco: maven
published: Apr 8, 2026
### Impact
An improperly protected scripting API allows any user with script right to bypass the sandboxing of the Velocity scripting API and execute, e.g., arbitrary Python scripts, allowing full access to the XWiki instance and thereby compromising the confidentiality, integrity and availability o…
CVE-2026-33229
GitHub-GHSA

HIGH
File Browser share links remain accessible after Share/Download permissions are revoked
GHSA-v9w4-gm2x-6rvf
pkg: github.com/filebrowser/filebrowser/v2
eco: go
published: Apr 8, 2026
When an admin revokes a user's Share and Download permissions, existing share links created by that user remain fully accessible to unauthenticated users. The public share download handler does not re-check the share owner's current permissions. Verified with a running PoC against v2.62.2 (commit 86…
CVE-2026-35604
GitHub-GHSA

HIGH
File Browser has a Command Injection via Hook Runner
GHSA-jvpw-637p-h3pw
pkg: github.com/filebrowser/filebrowser/v2
eco: go
published: Apr 8, 2026
> [!NOTE]
> **This feature has been disabled by default for all installations from v2.33.8 onwards, including for existent installations**. To exploit this vulnerability, the instance administrator must turn on a feature and ignore all the warnings about known vulnerabilities. We're publishing this …
CVE-2026-35585
GitHub-GHSA

HIGH
LiteLLM: Password hash exposure and pass-the-hash authentication bypass
GHSA-69×8-hrgq-fjj8
pkg: litellm
eco: pip
published: Apr 8, 2026
### Impact

Three issues combine into a full authentication bypass chain:

1. Weak hashing: User passwords are stored as unsalted SHA-256 hashes, making them vulnerable to rainbow table attacks and trivially identifying users with identical passwords.
2. Hash exposure: Multiple API endpoints (/user/…

GitHub-GHSA

HIGH
Java-SDK has a DNS Rebinding Vulnerability
GHSA-8jxr-pr72-r468
pkg: io.modelcontextprotocol.sdk:mcp-core
eco: maven
published: Apr 7, 2026
### Summary

The java-sdk contains a DNS rebinding vulnerability. This vulnerability allows an attacker to access a locally or network-private java-sdk MCP server via a victims browser that is either local, or network adjacent.

This allows an attacker to make any tool call to the server as if they …

CVE-2026-35568
GitHub-GHSA

HIGH
Gotenberg has incomplete fix for ExifTool arbitrary file write: case-insensitive bypass and missing HardLink/SymLink tags
GHSA-qmwh-9m9c-h36m
pkg: github.com/gotenberg/gotenberg/v8
eco: go
published: Apr 7, 2026
## Summary

The fix for ExifTool arbitrary file write (commit `043b158`, released in v8.29.0) uses a case-sensitive blocklist to filter dangerous pseudo-tags. ExifTool processes tag names case-insensitively, so alternate casings bypass the filter. The blocklist also omits the `HardLink` and `SymLink…

GitHub-GHSA

HIGH
Gotenberg Vulnerable to ReDoS via extraHttpHeaders scope feature
GHSA-fmwg-qcqh-m992
pkg: github.com/gotenberg/gotenberg/v8
eco: go
published: Apr 7, 2026
### Summary
Gotenberg uses `dlclark/regexp2` to compile user-supplied scope patterns without setting a proper timeout. Users with access to features using this logic can hang workers indefinitely.

### Details
Gotenberg uses `dlclark/regexp2` to compile user-supplied scope patterns (gotenberg/pkg/m…

CVE-2026-35458
GitHub-GHSA

HIGH
Lupa has a Sandbox escape and RCE due to incomplete attribute_filter enforcement in getattr / setattr
GHSA-69v7-xpr6-6gjm
pkg: lupa
eco: pip
published: Apr 7, 2026
### Summary
The `attribute_filter` in the Lupa library is intended to restrict access to sensitive Python attributes when exposing objects to Lua.

However, the filter is not consistently applied when attributes are accessed through built-in functions like getattr and setattr. This allows an attacke…

CVE-2026-34444
GitHub-GHSA

HIGH
Authorizer: Password reset token theft and full auth token redirect via unvalidated redirect_uri
GHSA-x3f4-v83f-7wp2
pkg: github.com/authorizerdev/authorizer
eco: go
published: Apr 6, 2026
Hi,

I found that 6 endpoints in Authorizer accept a user-controlled `redirect_uri` and append sensitive tokens to it without validating the URL against `AllowedOrigins`. The OAuth `/app` handler validates redirect_uri at `http_handlers/app.go:46`, but the GraphQL mutations and verify_email handler …

GitHub-GHSA

MEDIUM
OpenEXR has buffer overflow in PyOpenEXR_old's channels() and channel()
GHSA-vh63-9mqx-wmjr
pkg: OpenEXR, OpenEXR, OpenEXR
eco: pip
published: Apr 6, 2026
### Summary

A memory safety bug in the legacy OpenEXR Python adapter (the deprecated OpenEXR.InputFile wrapper) allow crashes and likely code execution when opening attacker-controlled EXR files or when passing crafted Python objects.

Integer overflow and unchecked allocation in InputFile.channel(…

CVE-2025-64182
GitHub-GHSA

MEDIUM
OpenEXR has use after free in PyObject_StealAttrString
GHSA-57cw-j6vp-2p9m
pkg: OpenEXR, OpenEXR, OpenEXR
eco: pip
published: Apr 6, 2026
### Summary
There is a use-after-free in PyObject_StealAttrString of pyOpenEXR_old.cpp.

This bug was found with [ZeroPath](https://zeropath.com/?utm_source=joshua.hu).

### Details

The legacy adapter defines PyObject_StealAttrString that calls PyObject_GetAttrString to obtain a new reference, imme…

CVE-2025-64183
GitHub-GHSA

MEDIUM
Duplicate Advisory: OpenClaw: SSRF via Unguarded Configured Base URLs in Multiple Channel Extensions (Incomplete Fix for CVE-2026-28476)
GHSA-8j7f-g9gv-7jhc
pkg: openclaw
eco: npm
published: Apr 10, 2026
### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-rhfg-j8jq-7v2h. This link is maintained to preserve external references.

### Original Description
OpenClaw before 2026.3.25 contains a server-side request forgery vulnerability in multiple channel extensions t…

GitHub-GHSA

MEDIUM
Duplicate Advisory: OpenClaw: Tlon cite expansion happens before channel and DM authorization is complete
GHSA-p6j4-wvmc-vx2h
pkg: openclaw
eco: npm
published: Apr 10, 2026
### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-vfg3-pqpq-93m4. This link is maintained to preserve external references.

### Original Description
OpenClaw before 2026.3.22 performs cite expansion before completing channel and DM authorization checks, allowi…

GitHub-GHSA

MEDIUM
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py
GHSA-fcc8-4q7h-wvwc
pkg: metagpt
eco: pip
published: Apr 9, 2026
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the probl…
CVE-2026-5974
GitHub-GHSA

MEDIUM
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/utils/common.py
GHSA-qw5f-qpq5-ppfg
pkg: metagpt
eco: pip
published: Apr 9, 2026
A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file metagpt/utils/common.py. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. The project was in…
CVE-2026-5973
GitHub-GHSA

MEDIUM
FoundationAgents MetaGPT vulnerable to os command injection via the Terminal.run_command
GHSA-wp29-qmvj-frvp
pkg: metagpt
eco: pip
published: Apr 9, 2026
A vulnerability has been found in FoundationAgents MetaGPT up to 0.8.1. This issue affects the function Terminal.run_command in the library metagpt/tools/libs/terminal.py. The manipulation leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to…
CVE-2026-5972
GitHub-GHSA

MEDIUM
FoundationAgents MetaGPT vulnerable to eval injection
GHSA-3ghp-8r47-4gj4
pkg: metagpt
eco: pip
published: Apr 9, 2026
A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fill of the file metagpt/actions/action_node.py of the component XML Handler. Executing a manipulation can lead to improper neutralization of directives in dynamically evaluated code…
CVE-2026-5971
GitHub-GHSA

MEDIUM
decolua 9router vulnerable to authorization bypass
GHSA-xrrh-p7f2-27vm
pkg: 9router
eco: npm
published: Apr 9, 2026
A security vulnerability has been detected in decolua 9router up to 0.3.47. The impacted element is an unknown function of the file /api of the component Administrative API Endpoint. The manipulation leads to authorization bypass. The attack is possible to be carried out remotely. The exploit has be…
CVE-2026-5842
GitHub-GHSA

MEDIUM
api-lab-mcp vulnerable to SSRF
GHSA-crh9-3gjh-m6gc
pkg: api-lab-mcp
eco: npm
published: Apr 9, 2026
A weakness has been identified in atototo api-lab-mcp up to 0.2.1. This affects the function analyze_api_spec/generate_test_scenarios/test_http_endpoint of the file src/mcp/http-server.ts of the component HTTP Interface. This manipulation of the argument source/url causes server-side request forgery…
CVE-2026-5832
GitHub-GHSA

MEDIUM
PowerJob's GroovyEvaluator.evaluate endpoint vulnerable to code injection
GHSA-wpwf-v25w-54g3
pkg: tech.powerjob:powerjob-server-starter
eco: maven
published: Apr 7, 2026
A security flaw has been discovered in PowerJob 5.1.0/5.1.1/5.1.2. The affected element is the function GroovyEvaluator.evaluate of the file /openApi/addWorkflowNode of the component OpenAPI Endpoint. The manipulation of the argument nodeParams results in code injection. The attack can be executed r…
CVE-2026-5739
GitHub-GHSA

MEDIUM
PowerJob vulnerable to SQL injection
GHSA-4fp2-3xgg-jg4w
pkg: tech.powerjob:powerjob-server-starter
eco: maven
published: Apr 7, 2026
A vulnerability was identified in PowerJob 5.1.0/5.1.1/5.1.2. Impacted is an unknown function of the file powerjob-server/powerjob-server-starter/src/main/java/tech/powerjob/server/web/controller/InstanceController.java of the component detailPlus Endpoint. The manipulation of the argument customQue…
CVE-2026-5736
GitHub-GHSA

MEDIUM
Aiven Operator has cross-namespace secret exfiltration via ClickhouseUser connInfoSecretSource
GHSA-99j8-wv67-4c72
pkg: github.com/aiven/aiven-operator
eco: go
published: Apr 10, 2026
### Impact
A developer with create permission on ClickhouseUser CRDs in their own namespace can exfiltrate secrets from any other namespace — production database credentials, API keys, service tokens — with a single kubectl apply. The operator reads the victim's secret using its ClusterRole and …
CVE-2026-39961
NVD

MEDIUM
CVE-2026-39961
CVE-2026-39961
pkg: kubernetes

published: Apr 9, 2026

Aiven Operator allows you to provision and manage Aiven Services from your Kubernetes cluster. From 0.31.0 to before 0.37.0, a developer with create permission on ClickhouseUser CRDs in their own namespace can exfiltrate secrets from any other namespace — production database credentials, API keys,…
CWE: CWE-269, CWE-441
GitHub-GHSA

MEDIUM
pyload-ng: Authorization Bypass for SSL Certificate/Key Configuration Due to Option Name Mismatch in pyload-ng
GHSA-ppvx-rwh9-7rj7
pkg: pyload-ng
eco: pip
published: Apr 8, 2026
## Summary

The `ADMIN_ONLY_CORE_OPTIONS` authorization set in `set_config_value()` uses incorrect option names `ssl_cert` and `ssl_key`, while the actual configuration option names are `ssl_certfile` and `ssl_keyfile`. This name mismatch causes the admin-only check to always evaluate to False, allo…

CVE-2026-35586
NVD

MEDIUM
CVE-2026-35586
CVE-2026-35586
pkg: ssl

published: Apr 7, 2026

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the ADMIN_ONLY_CORE_OPTIONS authorization set in set_config_value() uses incorrect option names ssl_cert and ssl_key, while the actual configuration option names are ssl_certfile and ssl_keyfile. This name m…
CWE: CWE-863
NVD

MEDIUM
CVE-2025-30650
CVE-2025-30650
pkg: linux

published: Apr 8, 2026

A Missing Authentication for Critical Function vulnerability in command processing of Juniper Networks Junos OS allows a privileged local attacker to gain access to line cards running Junos OS Evolved

as root.

This issue affects systems running Junos OS using Linux-based line cards. Affected lin…

CWE: CWE-306
NVD

MEDIUM
CVE-2026-4837
CVE-2026-4837
pkg: tls

published: Apr 8, 2026

An eval() injection vulnerability in the Rapid7 Insight Agent beaconing logic for Linux versions could theoretically allow an attacker to achieve remote code execution as root via a crafted beacon response. Because the Agent uses mutual TLS (mTLS) to verify commands from the Rapid7 Platform, it is u…
CWE: CWE-95
NVD

MEDIUM
CVE-2026-35197
CVE-2026-35197
pkg: express

published: Apr 6, 2026

dye is a portable and respectful color library for shell scripts. Prior to 1.1.1, certain dye template expressions would result in execution of arbitrary code. This issue was discovered and fixed by dye's author, and is not known to be exploited. This vulnerability is fixed in 1.1.1.
CWE: CWE-94
GitHub-GHSA

MEDIUM
Ech0 Scope Bypass: profile:read Access Token Can Change Admin Password and Escalate to Unrestricted Session
GHSA-hm2h-wwwh-g49x
pkg: github.com/lin-snow/ech0
eco: go
published: Apr 10, 2026
## Summary

The `PUT /user` endpoint is protected by `RequireScopes("profile:read")`, which is a read-only scope. However, the endpoint performs write operations including password changes. An attacker who obtains an admin's restricted `profile:read` access token can change the admin's password, the…

GitHub-GHSA

MEDIUM
Ech0: Missing authorization on dashboard log endpoints allows low-privilege users to access sensitive system logs
GHSA-cp79-9mwr-wr49
pkg: github.com/lin-snow/ech0
eco: go
published: Apr 10, 2026
## Summary

Ech0 allows any authenticated user to read historical system logs and subscribe to live log streams because the dashboard log endpoints validate only that a JWT is present and valid, but do not require an administrator role or privileged scope.

## Impact

Any valid user session can acce…

GitHub-GHSA

MEDIUM
PraisonAI Vulnerable to Decompression Bomb DoS via Recipe Bundle Extraction Without Size Limits
GHSA-f2h6-7xfr-xm8w
pkg: PraisonAI
eco: pip
published: Apr 10, 2026
## Summary

The `_safe_extractall()` function in PraisonAI's recipe registry validates archive members against path traversal attacks but performs no checks on individual member sizes, cumulative extracted size, or member count before calling `tar.extractall()`. An attacker can publish a malicious r…

CVE-2026-40148
NVD

MEDIUM
CVE-2026-35594
CVE-2026-35594
pkg: jwt

published: Apr 10, 2026

Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, Vikunja's link share authentication (GetLinkShareFromClaims in pkg/models/link_sharing.go) constructs authorization objects entirely from JWT claims without any server-side database validation. When a project owner delet…
CWE: CWE-613
GitHub-GHSA

MEDIUM
Vikunja has Algorithmic Complexity DoS in Repeating Task Handler
GHSA-r4fg-73rc-hhh7
pkg: code.vikunja.io/api
eco: go
published: Apr 10, 2026
## Summary

The `addRepeatIntervalToTime` function uses an O(n) loop that advances a date by the task's `RepeatAfter` duration until it exceeds the current time. By creating a repeating task with a 1-second interval and a due date far in the past, an attacker triggers billions of loop iterations, co…

CVE-2026-35599
GitHub-GHSA

MEDIUM
Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade
GHSA-96q5-xm3p-7m84
pkg: code.vikunja.io/api
eco: go
published: Apr 10, 2026
## Title
Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade

## Description

Vikunja's link share authentication constructs authorization objects entirely from JWT claims without any server-side database validation. When a project owner deletes a link share …

CVE-2026-35594
NVD

MEDIUM
CVE-2021-47960
CVE-2021-47960
pkg: ssl

published: Apr 10, 2026

A files or directories accessible to external parties vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access files within the installation directory via a local HTTP server bound to the loopback interface. By leveraging user interaction with a crafted web page, …
CWE: CWE-552
GitHub-GHSA

MEDIUM
Duplicate Advisory: OpenClaw: Nostr inbound DMs could trigger unauthenticated crypto work before sender policy enforcement
GHSA-2j53-2c28-g9v2
pkg: openclaw
eco: npm
published: Apr 10, 2026
### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-65h8-27jh-q8wv. This link is maintained to preserve external references.

### Original Description
OpenClaw before 2026.3.22 performs cryptographic and dispatch operations on inbound Nostr direct messages befor…

NVD

MEDIUM
CVE-2026-39848
CVE-2026-39848
pkg: docker

published: Apr 9, 2026

Dockyard is a Docker container management app. Prior to 1.1.0, Docker container start and stop operations are performed through GET requests without CSRF protection. A remote attacker can cause a logged-in administrator's browser to request /apps/action.php?action=stop&name=<container> or /apps/acti…
CWE: CWE-306
GitHub-GHSA

MEDIUM
Apache Tomcat: CLIENT_CERT authentication does not fail as expected
GHSA-24j9-x2wg-9qv6
pkg: org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat-catalina
eco: maven
published: Apr 9, 2026
CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat.

This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.20, from 10.1.22 through 10.1.53, from 9.0.92 through 9.0.116.

Users are recommended to upgrade to ver…

CVE-2026-34500
GitHub-GHSA

MEDIUM
Apache Airflow has an authorization bypass in DagRun wait endpoint
GHSA-r7vr-m4jw-r794
pkg: apache-airflow
eco: pip
published: Apr 9, 2026
Apache Airflow versions 3.0.0 through 3.1.8 DagRun wait endpoint returns XCom result values even to users who only have DAG Run read permissions, such as the Viewer role.This behavior conflicts with the FAB RBAC model, which treats XCom as a separate protected resource, and with the security model d…
CVE-2026-34538
NVD

MEDIUM
CVE-2026-5905
CVE-2026-5905
pkg: windows

published: Apr 8, 2026

Incorrect security UI in Permissions in Google Chrome on Windows prior to 147.0.7727.55 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)
CWE: CWE-451
NVD

MEDIUM
CVE-2026-5876
CVE-2026-5876
pkg: go

published: Apr 8, 2026

Side-channel information leakage in Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-1300, CWE-1300
NVD

MEDIUM
CVE-2026-5869
CVE-2026-5869
pkg: go

published: Apr 8, 2026

Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-122, CWE-122
NVD

MEDIUM
CVE-2026-5867
CVE-2026-5867
pkg: go

published: Apr 8, 2026

Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-122, CWE-122
NVD

MEDIUM
CVE-2026-5864
CVE-2026-5864
pkg: go

published: Apr 8, 2026

Heap buffer overflow in WebAudio in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-122, CWE-122
GitHub-GHSA

MEDIUM
OpenFGA: Unauthenticated playground endpoint discloses preshared API key in HTML response
GHSA-68m9-983m-f3v5
pkg: github.com/openfga/openfga
eco: go
published: Apr 8, 2026
### Description
When OpenFGA is configured to use preshared-key authentication with the built-in playground enabled, the local server includes the preshared API key in the HTML response of the /playground endpoint. The /playground endpoint is enabled by default and does not require authentication. I…
GitHub-GHSA

MEDIUM
PraisonAI has Memory State Leakage and Path Traversal in MultiAgent Context Handling
GHSA-766v-q9x3-g744
pkg: praisonaiagents
eco: pip
published: Apr 8, 2026
## Summary
The `MultiAgentLedger` and `MultiAgentMonitor` components in the provided code exhibit vulnerabilities that can lead to context leakage and arbitrary file operations. Specifically:
1. **Memory State Leakage via Agent ID Collision**: The `MultiAgentLedger` uses a dictionary to store ledger…
GitHub-GHSA

MEDIUM
kubernetes-graphql-gateway: GraphQL Endpoint Vulnerable to Authenticated Denial-of-Service via Unrestricted Query Execution
GHSA-h9mw-h4qc-f5jf
pkg: github.com/platform-mesh/kubernetes-graphql-gateway
eco: go
published: Apr 8, 2026
**CVSS 6.5 Medium** — The GraphQL API served by kubernetes-graphql-gateway is vulnerable to Denial-of-Service (DoS) attacks due to a complete absence of query resource controls (depth limiting, complexity analysis, response size capping, and rate limiting). An authenticated attacker can craft quer…
NVD

MEDIUM
CVE-2026-39674
CVE-2026-39674
pkg: go

published: Apr 8, 2026

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Manoj Kumar MK Google Directions google-distance-calculator allows DOM-Based XSS.This issue affects MK Google Directions: from n/a through <= 3.1.1.
CWE: CWE-79
GitHub-GHSA

MEDIUM
Django has potential DoS via MultiPartParser through crafted multipart uploads
GHSA-5mf9-h53q-7mhq
pkg: Django, Django, Django
eco: pip
published: Apr 7, 2026
An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `MultiPartParser` allows remote attackers to degrade performance by submitting multipart uploads with `Content-Transfer-Encoding: base64` including excessive whitespace.

Earlier, unsupported Django series (such a…

CVE-2026-33033
GitHub-GHSA

MEDIUM
HuggingFace Transformers allows for arbitrary code execution in the `Trainer` class
GHSA-69w3-r845-3855
pkg: transformers
eco: pip
published: Apr 7, 2026
A vulnerability in the HuggingFace Transformers library, specifically in the `Trainer` class, allows for arbitrary code execution. The `_load_rng_state()` method in `src/transformers/trainer.py` at line 3059 calls `torch.load()` without the `weights_only=True` parameter. This issue affects all versi…
CVE-2026-1839
GitHub-GHSA

MEDIUM
kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write
GHSA-cjg8-h5qc-hrjv
pkg: kedro-datasets
eco: pip
published: Apr 6, 2026
### Impact

PartitionedDataset in kedro-datasets was vulnerable to path traversal. Partition IDs were concatenated directly with the dataset base path without validation. An attacker or malicious input containing .. components in a partition ID could cause files to be written outside the configured …

CVE-2026-35492
GitHub-GHSA

MEDIUM
OpenEXR has heap-buffer-overflow via signed integer underflow in ImfContextInit.cpp
GHSA-q6vj-wxvf-5m8c
pkg: OpenEXR, OpenEXR
eco: pip
published: Apr 6, 2026
## Summary

A heap-buffer-overflow (OOB read) occurs in the `istream_nonparallel_read` function in `ImfContextInit.cpp` when parsing a malformed EXR file through a memory-mapped `IStream`. A signed integer subtraction produces a negative value that is implicitly converted to `size_t`, resulting in a…

CVE-2026-26981
NVD

MEDIUM
CVE-2026-34756
CVE-2026-34756
pkg: python

published: Apr 6, 2026

vLLM is an inference and serving engine for large language models (LLMs). From 0.1.0 to before 0.19.0, a Denial of Service vulnerability exists in the vLLM OpenAI-compatible API server. Due to the lack of an upper bound validation on the n parameter in the ChatCompletionRequest and CompletionRequest…
CWE: CWE-770
NVD

MEDIUM
CVE-2025-57851
CVE-2025-57851
pkg: kubernetes

published: Apr 8, 2026

A container privilege escalation flaw was found in certain Multicluster Engine for Kubernetes images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container, …
CWE: CWE-276
NVD

MEDIUM
CVE-2026-33727
CVE-2026-33727
pkg: pi-hole pi-hole

published: Apr 6, 2026

Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. Version 6.4 has a local privilege-escalation vulnerability allows code execution as root from the low-privilege pihole account. Important context: the pihole account uses nologin, so this is not a direct intera…
CWE: CWE-269
NVD

MEDIUM
CVE-2026-6108
CVE-2026-6108
pkg: node

published: Apr 12, 2026

A vulnerability was found in 1Panel-dev MaxKB up to 2.6.1. The affected element is the function execute of the file apps/application/flow/step_node/mcp_node/impl/base_mcp_node.py of the component Model Context Protocol Node. Performing a manipulation results in os command injection. The attack is po…
CWE: CWE-77, CWE-78
GitHub-GHSA

MEDIUM
Agions taskflow-ai vulnerable to os command injection in src/mcp/server/handlers.ts
GHSA-3xp3-pr8x-f755
pkg: taskflow-ai
eco: npm
published: Apr 9, 2026
A security flaw has been discovered in Agions taskflow-ai up to 2.1.8. This impacts an unknown function of the file src/mcp/server/handlers.ts of the component terminal_execute. Performing a manipulation results in os command injection. The attack is possible to be carried out remotely. Upgrading to…
CVE-2026-5831
GitHub-GHSA

MEDIUM
PraisonAIAgents: Arbitrary File Read via read_skill_file Missing Workspace Boundary and Approval Gate
GHSA-grrg-5cg9-58pf
pkg: praisonaiagents
eco: pip
published: Apr 10, 2026
## Summary

`read_skill_file()` in `skill_tools.py` allows reading arbitrary files from the filesystem by accepting an unrestricted `skill_path` parameter. Unlike `file_tools.read_file` which enforces workspace boundary confinement, and unlike `run_skill_script` which requires critical-level approva…

CVE-2026-40117
GitHub-GHSA

MEDIUM
PraisonAI has Unrestricted Upload Size in WSGI Recipe Registry Server that Enables Memory Exhaustion DoS
GHSA-2xgv-5cv2-47vv
pkg: PraisonAI
eco: pip
published: Apr 10, 2026
## Summary

The WSGI-based recipe registry server (`server.py`) reads the entire HTTP request body into memory based on the client-supplied `Content-Length` header with no upper bound. Combined with authentication being disabled by default (no token configured), any local process can send arbitraril…

CVE-2026-40115
NVD

MEDIUM
CVE-2026-33753
CVE-2026-33753
pkg: python

published: Apr 8, 2026

rfc3161-client is a Python library implementing the Time-Stamp Protocol (TSP) described in RFC 3161. Prior to 1.0.6, an Authorization Bypass vulnerability in rfc3161-client's signature verification allows any attacker to impersonate a trusted TimeStamping Authority (TSA). By exploiting a logic flaw …
CWE: CWE-295
GitHub-GHSA

MEDIUM
rfc3161-client Has Improper Certificate Validation
GHSA-3xxc-pwj6-jgrj
pkg: rfc3161-client
eco: pip
published: Apr 8, 2026
### Summary

An Authorization Bypass vulnerability in `rfc3161-client`'s signature verification allows any attacker to impersonate a trusted TimeStamping Authority (TSA). By exploiting a logic flaw in how the library extracts the leaf certificate from an unordered PKCS#7 bag of certificates, an atta…

CVE-2026-33753
GitHub-GHSA

MEDIUM
netavark has incorrect error handling for malformed tcp packets
GHSA-hfpq-x728-986j
pkg: netavark
eco: rust
published: Apr 7, 2026
### Impact

A truncated TCP DNS query followed by a connection reset causes aardvark-dns to enter an unrecoverable infinite error loop at 100% CPU.

### Patches
https://github.com/containers/aardvark-dns/commit/3b49ea7b38bdea134b7f03256f2e13f44ce73bb1

### Workarounds
None

### Credits

Thanks to @d…

CVE-2026-35406
NVD

MEDIUM
CVE-2026-35480
CVE-2026-35480
pkg: go

published: Apr 7, 2026

go-ipld-prime is an implementation of the InterPlanetary Linked Data (IPLD) spec interfaces, a batteries-included codec implementations of IPLD for CBOR and JSON, and tooling for basic operations on IPLD objects. Prior to 0.22.0, the DAG-CBOR decoder uses collection sizes declared in CBOR headers as…
CWE: CWE-770
GitHub-GHSA

MEDIUM
go-ipld-prime: DAG-CBOR decoder unbounded memory allocation from CBOR headers
GHSA-378j-3jfj-8r9f
pkg: github.com/ipld/go-ipld-prime
eco: go
published: Apr 6, 2026
The DAG-CBOR decoder uses collection sizes declared in CBOR headers as Go preallocation hints for maps and lists. The decoder does not cap these size hints or account for their cost in its allocation budget, allowing small payloads to cause excessive memory allocation.

A CBOR map or list header can…

CVE-2026-35480
GitHub-GHSA

MEDIUM
go.etcd.io/bbolt affected by index out-of-range vulnerability
GHSA-6jwv-w5xf-7j27
pkg: go.etcd.io/bbolt
eco: go
published: Apr 6, 2026
Index out-of-range when encountering a branch page with zero elements in go.etcd.io/bbolt
CVE-2026-33817
GitHub-GHSA

MEDIUM
Apache Tomcat has an Open Redirect vulnerability
GHSA-9m3c-qcxr-9×87
pkg: org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat
eco: maven
published: Apr 9, 2026
Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDrainingValve.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M23 through 9.0.115, from 8.5.30 through 8.5.100.
Other, unsu…

CVE-2026-25854
GitHub-GHSA

MEDIUM
Unhead has a hasDangerousProtocol() bypass via leading-zero padded HTML entities in useHeadSafe()
GHSA-95h2-gj7x-gx9w
pkg: unhead
eco: npm
published: Apr 9, 2026
##EVIDENCE

<img width="1900" height="855" alt="Screenshot_2026-03-25_090729" src="https://github.com/user-attachments/assets/3da93464-1caf-46ca-818f-46f8fe32ab50" />
<img width="1919" height="947" alt="Screenshot_2026-03-25_090715" src="https://github.com/user-attachments/assets/b27b1fc3-fa89-4864-…

CVE-2026-39315
NVD

MEDIUM
CVE-2026-39315
CVE-2026-39315
pkg: express

published: Apr 9, 2026

Unhead is a document head and template manager. Prior to 2.1.13, useHeadSafe() is the composable that Nuxt's own documentation explicitly recommends for rendering user-supplied content in <head> safely. Internally, the hasDangerousProtocol() function in packages/unhead/src/plugins/safe.ts decodes HT…
CWE: CWE-184
NVD

MEDIUM
CVE-2026-35199
CVE-2026-35199
pkg: windows

published: Apr 6, 2026

SymCrypt is the core cryptographic function library currently used by Windows. From 103.5.0 to before 103.11.0, The SymCryptXmssSign function passes a 64-bit leaf count value to a helper function that accepts a 32-bit parameter. For XMSS^MT parameter sets with total tree height >= 32 (which includes…
CWE: CWE-122
NVD

MEDIUM
CVE-2026-34765
CVE-2026-34765
pkg: windows

published: Apr 7, 2026

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5, when a renderer calls window.open() with a target name, Electron did not correctly scope the named-window lookup to the opener's browsing conte…
CWE: CWE-668
GitHub-GHSA

MEDIUM
Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout
GHSA-fgfv-pv97-6cmj
pkg: code.vikunja.io/api
eco: go
published: Apr 10, 2026
## Summary

The TOTP failed-attempt lockout mechanism is non-functional due to a database transaction handling bug. The account lock is written to the same database session that the login handler always rolls back on TOTP failure, so the lockout is triggered but never persisted. This allows unlimite…

CVE-2026-35597
NVD

MEDIUM
CVE-2026-39844
CVE-2026-39844
pkg: windows

published: Apr 8, 2026

NiceGUI is a Python-based UI framework. Prior to 3.10.0, Since PurePosixPath only recognizes forward slashes (/) as path separators, an attacker can bypass this sanitization on Windows by using backslashes (\) in the upload filename. Applications that construct file paths using file.name (a pattern …
CWE: CWE-22
GitHub-GHSA

MEDIUM
Axios HTTP/2 Session Cleanup State Corruption Vulnerability
GHSA-qj83-cq47-w5f8
pkg: axios
eco: npm
published: Apr 8, 2026
### Summary

Axios HTTP/2 session cleanup logic contains a state corruption bug that allows a malicious server to crash the client process through concurrent session closures. This denial-of-service vulnerability affects axios versions prior to 1.13.2 when HTTP/2 is enabled.

### Details

The vulner…

CVE-2026-39865
NVD

MEDIUM
CVE-2026-39865
CVE-2026-39865
pkg: axios

published: Apr 8, 2026

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.13.2, Axios HTTP/2 session cleanup logic contains a state corruption bug that allows a malicious server to crash the client process through concurrent session closures. The vulnerability exists in the Http2Sessions.getSessi…
CWE: CWE-400, CWE-662
GitHub-GHSA

MEDIUM
NiceGUI: Upload filename sanitization bypass via backslashes allows path traversal on Windows
GHSA-w8wv-vfpc-hw2w
pkg: nicegui
eco: pip
published: Apr 8, 2026
### Summary

The upload filename sanitization introduced in GHSA-9ffm-fxg3-xrhh uses `PurePosixPath(filename).name` to strip path components. Since `PurePosixPath` only recognizes forward slashes (`/`) as path separators, an attacker can bypass this sanitization on Windows by using backslashes (`\`)…

CVE-2026-39844
GitHub-GHSA

MEDIUM
Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder
GHSA-xmrv-pmrh-hhx2
pkg: github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream, github.com/aws/aws-sdk-go-v2/service/bedrockagentcore, github.com/aws/aws-sdk-go-v2/service/bedrockagentruntime
eco: go
published: Apr 8, 2026
**CVSSv3.1 Rating**: [Medium]
**CVSSv3.1 Score**: [5.9]
**CVSSv3.1 Vector String**: [CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H]

## Summary and Impact
An issue exists in the the EventStream header decoder in AWS SDK for Go v2 in versions predating [2026-03-23](https://github.com/aws/aws-sdk-go-v2…

GitHub-GHSA

MEDIUM
rdiscount has an Out-of-bounds Read
GHSA-6r34-94wq-jhrc
pkg: rdiscount
eco: rubygems
published: Apr 6, 2026
### Summary

A signed length truncation bug causes an out-of-bounds read in the default Markdown parse path. Inputs larger than `INT_MAX` are truncated to a signed `int` before entering the native parser, allowing the parser to read past the end of the supplied buffer and crash the process

### Deta…

CVE-2026-35201
NVD

MEDIUM
CVE-2026-34380
CVE-2026-34380
pkg: openexr openexr

published: Apr 6, 2026

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.2.0 to before 3.2.7, 3.3.9, and 3.4.9, a signed integer overflow exists in undo_pxr24_impl() in src/lib/OpenEXRCore/internal_pxr24.c at line 377. Th…
CWE: CWE-190, CWE-787
GitHub-GHSA

MEDIUM
monetr: Protected Transactions Deletable via PUT
GHSA-hqxq-hwqf-wg83
pkg: github.com/monetr/monetr
eco: go
published: Apr 8, 2026
### Summary
A transaction integrity flaw allows an authenticated tenant user to soft-delete synced non-manual transactions through the transaction update endpoint, despite the application explicitly blocking deletion of those transactions via the normal `DELETE` path. This bypass undermines the inte…
CVE-2026-39901
GitHub-GHSA

MEDIUM
LangSmith Client SDKs has Prototype Pollution in langsmith-sdk via Incomplete `__proto__` Guard in Internal lodash `set()`
GHSA-fw9q-39r9-c252
pkg: langsmith
eco: npm
published: Apr 10, 2026
# GHSA-fw9q-39r9-c252: Prototype Pollution via Incomplete Lodash `set()` Guard in `langsmith-sdk`

**Severity:** Medium (CVSS ~5.6)
**Status:** Fixed in 0.5.18

## Summary

The LangSmith JavaScript/TypeScript SDK (`langsmith`) contains an incomplete prototype pollution fix in its internally ven…

CVE-2026-40190
NVD

MEDIUM
CVE-2026-40190
CVE-2026-40190
pkg: node

published: Apr 10, 2026

LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.5.18, the LangSmith JavaScript/TypeScript SDK (langsmith) contains an incomplete prototype pollution fix in its internally vendored lodash set() utility. The baseAssignValue() function only guards against the…
CWE: CWE-1321
GitHub-GHSA

MEDIUM
Ech0 has SSRF via DNS Resolution Bypass in Webhook URL Validation
GHSA-r2x7-427f-rq69
pkg: github.com/lin-snow/ech0
eco: go
published: Apr 10, 2026
## Summary

The `validateWebhookURL` function in `webhook_setting_service.go` attempts to block webhooks targeting private/internal IP addresses, but only checks literal IP strings via `net.ParseIP()`. Hostnames that DNS-resolve to private IPs (e.g., `169.254.169.254.nip.io`, `10.0.0.1.nip.io`) bypa…

GitHub-GHSA

MEDIUM
Ech0 Comment Panel Endpoints Missing RequireScopes Middleware — Scoped Access Token Bypass
GHSA-fwg7-53p4-g33c
pkg: github.com/lin-snow/ech0
eco: go
published: Apr 10, 2026
## Summary

All 9 comment panel admin endpoints (`/api/panel/comments/*`) are missing `RequireScopes()` middleware, while every other admin endpoint in the application enforces scope-based authorization on access tokens. An admin-issued access token scoped to minimal permissions (e.g., `echo:read` o…

GitHub-GHSA

MEDIUM
PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands
GHSA-ffp3-3562-8cv3
pkg: praisonaiagents
eco: pip
published: Apr 10, 2026
## Summary

The approval system in PraisonAI Agents caches tool approval decisions by tool name only, not by invocation arguments. Once a user approves `execute_command` for any command (e.g., `ls -la`), all subsequent `execute_command` calls in that execution context bypass the approval prompt enti…

GitHub-GHSA

MEDIUM
PraisonAI Vulnerable to Sensitive Environment Variable Exposure via Untrusted MCP Subprocess Execution
GHSA-pj2r-f9mw-vrcq
pkg: PraisonAI
eco: pip
published: Apr 10, 2026
PraisonAI’s MCP (Model Context Protocol) integration allows spawning background servers via stdio using user-supplied command strings (e.g., `MCP("npx -y @smithery/cli …")`). These commands are executed through Python’s `subprocess` module. By default, the implementation **forwards the entire …
CVE-2026-40159
NVD

MEDIUM
CVE-2026-40159
CVE-2026-40159
pkg: python

published: Apr 10, 2026

PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI’s MCP (Model Context Protocol) integration allows spawning background servers via stdio using user-supplied command strings (e.g., MCP("npx -y @smithery/cli …")). These commands are executed through Python’s subprocess module…
CWE: CWE-200, CWE-214
NVD

MEDIUM
CVE-2026-35477
CVE-2026-35477
pkg: express

published: Apr 8, 2026

InvenTree is an Open Source Inventory Management System. From 1.2.3 to 1.2.6, the fix for CVE-2026-27629 upgraded the PART_NAME_FORMAT validator to use jinja2.sandbox.SandboxedEnvironment. However, the actual renderer in part/helpers.py was not updated and still uses the non-sandboxed jinja2.Environ…
CWE: CWE-1336
NVD

MEDIUM
CVE-2026-39390
CVE-2026-39390
pkg: go

published: Apr 8, 2026

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.4.0, the Google Maps iframe setting (cMap field) in compInfosPost() sanitizes input using strip_tags() with an <iframe> allowlist and regex-base…
CWE: CWE-79
NVD

MEDIUM
CVE-2025-65116
CVE-2025-65116
pkg: windows

published: Apr 7, 2026

Buffer Overflow Vulnerability in JP1/IT Desktop Management 2 – Manager on Windows, JP1/IT Desktop Management 2 – Operations Director on Windows, Job Management Partner 1/IT Desktop Management 2 – Manager on Windows, JP1/IT Desktop Management – Manager on Windows, Job Management Partner 1/IT Desktop …
CWE: CWE-763
GitHub-GHSA

MEDIUM
PraisonAI Vulnerable to Stored XSS via Unsanitized Agent Output in HTML Rendering (nh3 Not a Required Dependency)
GHSA-cfg2-mxfj-j6pw
pkg: PraisonAI
eco: pip
published: Apr 10, 2026
## Summary

The Flask API endpoint in `src/praisonai/api.py` renders agent output as HTML without effective sanitization. The `_sanitize_html` function relies on the `nh3` library, which is not listed as a required or optional dependency in `pyproject.toml`. When `nh3` is absent (the default install…

CVE-2026-40112
GitHub-GHSA

MEDIUM
Vikunja has File Size Limit Bypass via Vikunja Import
GHSA-qh78-rvg3-cv54
pkg: code.vikunja.io/api
eco: go
published: Apr 10, 2026
## Summary

The Vikunja file import endpoint uses the attacker-controlled `Size` field from the JSON metadata inside the import zip instead of the actual decompressed file content length for the file size enforcement check. By setting `Size` to 0 in the JSON while including large compressed file ent…

CVE-2026-35602
GitHub-GHSA

MEDIUM
Vikunja has HTML Injection via Task Titles in Overdue Email Notifications
GHSA-45q4-x4r9-8fqj
pkg: code.vikunja.io/api
eco: go
published: Apr 10, 2026
## Summary

Task titles are embedded directly into Markdown link syntax in overdue email notifications without escaping Markdown special characters. When rendered by goldmark and sanitized by bluemonday (which allows `<a>` and `<img>` tags), injected Markdown constructs produce phishing links and tr…

CVE-2026-35600
GitHub-GHSA

MEDIUM
Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT vulnerable to Integer Overflow or Wraparound
GHSA-xvqc-pp94-fmpx
pkg: org.apache.activemq:apache-activemq, org.apache.activemq:activemq-all, org.apache.activemq:activemq-mqtt
eco: maven
published: Apr 9, 2026
Integer Overflow or Wraparound vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT.

The fix for "CVE-2025-66168: MQTT control packet remaining length field is not properly validated" was only applied to 5.19.2 (and future 5.19.x) releases but was missed for all 6.0.0+ versio…

CVE-2026-40046
NVD

MEDIUM
CVE-2026-40071
CVE-2026-40071
pkg: python

published: Apr 9, 2026

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the /json/package_order, /json/link_order, and /json/abort_link WebUI JSON endpoints enforce weaker permissions than the core API methods they invoke. This allows authenticated low-privileged users to execut…
CWE: CWE-863
NVD

MEDIUM
CVE-2026-35207
CVE-2026-35207
pkg: tls

published: Apr 9, 2026

dde-control-center is the control panel of DDE, the Deepin Desktop Environment. plugin-deepinid is a plugin in dde-control-center, which provides the deepinid cloud service. Prior to 6.1.80, plugin-deepinid is configured to skip TLS certificate verification when fetching the user's avatar from opena…
CWE: CWE-295
GitHub-GHSA

MEDIUM
pyload-ng has a WebUI JSON permission mismatch that lets ADD/DELETE users invoke MODIFY-only actions
GHSA-rfgh-63mg-8pwm
pkg: pyload-ng
eco: pip
published: Apr 8, 2026
### Summary
Several WebUI JSON endpoints enforce weaker permissions than the core API methods they invoke. This allows authenticated low-privileged users to execute `MODIFY` operations that should be denied by pyLoad's own permission model.

Confirmed mismatches:
– `ADD` user can reorder packages/fi…

NVD

MEDIUM
CVE-2026-35200
CVE-2026-35200
pkg: parseplatform parse-server

published: Apr 6, 2026

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.73 and 9.7.1-alpha.4, a file can be uploaded with a filename extension that passes the file extension allowlist (e.g., .txt) but with a Content-Type header that differs from the exten…
CWE: CWE-436
NVD

MEDIUM
CVE-2026-3691
CVE-2026-3691
pkg: oauth

published: Apr 11, 2026

OpenClaw Client PKCE Verifier Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose stored credentials on affected installations of OpenClaw. User interaction is required to exploit this vulnerability in that the target must initiate an OAuth authorization flow…
CWE: CWE-200
GitHub-GHSA

MEDIUM
Rembg has a Path Traversal via Custom Model Loading
GHSA-3wqj-33cg-xc48
pkg: rembg
eco: pip
published: Apr 10, 2026
## Summary

A **path traversal vulnerability** in the rembg HTTP server allows unauthenticated remote attackers to read arbitrary files from the server's filesystem. By sending a crafted request with a malicious `model_path` parameter, an attacker can force the server to attempt loading any file as …

CVE-2026-40086
GitHub-GHSA

MEDIUM
xrootd has path traversal in directory listing that allows access to the parent directory via trailing ".." pattern
GHSA-vj8v-p5vw-m6v5
pkg: xrootd
eco: pip
published: Apr 10, 2026
## Summary

A path traversal vulnerability in XRootD allows users to escape the exported directory scope and enumerate the contents of the parent directory by appending `/..` (specifically without trailing slash) to an exported path in `xrdfs ls` or `HTTP PROPFIND` requests.

This bypass ignores the…

GitHub-GHSA

MEDIUM
PraisonAIAgents: Path Traversal via Unvalidated Glob Pattern in list_files Bypasses Workspace Boundary
GHSA-7j2f-xc8p-fjmq
pkg: praisonaiagents
eco: pip
published: Apr 10, 2026
## Summary

The `list_files()` tool in `FileTools` validates the `directory` parameter against workspace boundaries via `_validate_path()`, but passes the `pattern` parameter directly to `Path.glob()` without any validation. Since Python's `Path.glob()` supports `..` path segments, an attacker can u…

CVE-2026-40152
GitHub-GHSA

MEDIUM
PraisonAI: Unauthenticated Information Disclosure of Agent Instructions via /api/agents in AgentOS
GHSA-pm96-6xpr-978x
pkg: PraisonAI
eco: pip
published: Apr 10, 2026
## Summary

The AgentOS deployment platform exposes a `GET /api/agents` endpoint that returns agent names, roles, and the first 100 characters of agent system instructions to any unauthenticated caller. The AgentOS FastAPI application has no authentication middleware, no API key validation, and defa…

CVE-2026-40151
GitHub-GHSA

MEDIUM
Zod jsVideoUrlParser vulnerable to ReDoS in util.js
GHSA-8fgx-wgvr-pcx8
pkg: js-video-url-parser
eco: npm
published: Apr 10, 2026
A weakness has been identified in Zod jsVideoUrlParser up to 0.5.1. The impacted element is the function getTime in the library lib/util.js. This manipulation of the argument timestamp causes inefficient regular expression complexity. It is possible to initiate the attack remotely. The exploit has b…
CVE-2026-5986
GitHub-GHSA

MEDIUM
Duplicate Advisory: OpenClaw is vulnerable to unauthenticated resource exhaustion through its voice call webhook handling
GHSA-36cp-mh65-x882
pkg: openclaw
eco: npm
published: Apr 10, 2026
### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-rm59-992w-x2mv. This link is maintained to preserve external references.

### Original Description
OpenClaw before 2026.3.22 contains an unauthenticated resource exhaustion vulnerability in voice call webhook h…

GitHub-GHSA

MEDIUM
Duplicate Advisory: OpenClaw: Feishu webhook reads and parses unauthenticated request bodies before signature validation
GHSA-8f9r-gr6r-x63q
pkg: openclaw
eco: npm
published: Apr 10, 2026
### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-3h52-cx59-c456. This link is maintained to preserve external references.

### Original Description
OpenClaw before 2026.3.25 parses JSON request bodies before validating webhook signatures, allowing unauthentic…

GitHub-GHSA

MEDIUM
Duplicate Advisory: OpenClaw: Remote media error responses could trigger unbounded memory allocation before failure
GHSA-hm63-vwj4-mj2q
pkg: openclaw
eco: npm
published: Apr 10, 2026
### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-4qwc-c7g9-4xcw. This link is maintained to preserve external references.

### Original Description
OpenClaw before 2026.3.22 contains an unbounded memory allocation vulnerability in remote media HTTP error hand…

NVD

MEDIUM
CVE-2026-5986
CVE-2026-5986
pkg: express

published: Apr 9, 2026

A weakness has been identified in Zod jsVideoUrlParser up to 0.5.1. The impacted element is the function getTime in the library lib/util.js. This manipulation of the argument timestamp causes inefficient regular expression complexity. It is possible to initiate the attack remotely. The exploit has b…
CWE: CWE-400, CWE-1333
NVD

MEDIUM
CVE-2026-40152
CVE-2026-40152
pkg: python

published: Apr 9, 2026

PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, he list_files() tool in FileTools validates the directory parameter against workspace boundaries via _validate_path(), but passes the pattern parameter directly to Path.glob() without any validation. Since Python's Path.glob() supports…
CWE: CWE-22
GitHub-GHSA

MEDIUM
Apache Tomcat has an Improper Input Validation vulnerability
GHSA-8mc5-53m5-3qj2
pkg: org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat-catalina
eco: maven
published: Apr 9, 2026
Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614.

This issue affects Apache Tomcat: from 11.0.15 through 11.0.19, from 10.1.50 through 10.1.52, from 9.0.113 through 9.0.115.

Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, …

CVE-2026-32990
NVD

MEDIUM
CVE-2026-40087
CVE-2026-40087
pkg: express

published: Apr 9, 2026

LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.84 and 1.2.28, LangChain's f-string prompt-template validation was incomplete in two respects. First, some prompt template classes accepted f-string templates and formatted them without enforcing the same attribu…
CWE: CWE-1336
GitHub-GHSA

MEDIUM
fast-jwt: Stateful RegExp (/g or /y) causes non-deterministic allowed-claim validation (logical DoS)
GHSA-3j8v-cgw4-2g6q
pkg: fast-jwt
eco: npm
published: Apr 9, 2026
## Impact

Using certain modifiers on RegExp objects in the allowedAud, allowedIss, allowedSub, allowedJti, or allowedNonce options in verify functions can cause certain unintended behaviours. This is because some modifiers are stateful and will cause failures in every second verification attempt re…

CVE-2026-35040
GitHub-GHSA

MEDIUM
LangChain has incomplete f-string validation in prompt templates
GHSA-926x-3r5x-gfhw
pkg: langchain-core, langchain-core
eco: pip
published: Apr 8, 2026
LangChain's f-string prompt-template validation was incomplete in two respects.

First, some prompt template classes accepted f-string templates and formatted them without enforcing the same attribute-access validation as `PromptTemplate`. In particular, `DictPromptTemplate` and `ImagePromptTemplate…

CVE-2026-40087
NVD

MEDIUM
CVE-2026-39882
CVE-2026-39882
pkg: opentelemetry opentelemetry

published: Apr 8, 2026

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to 1.43.0, the otlp HTTP exporters (traces/metrics/logs) read the full HTTP response body into an in-memory bytes.Buffer without a size cap. This is exploitable for memory exhaustion when the configured collector endpoint is attacker-…
CWE: CWE-789
GitHub-GHSA

MEDIUM
opentelemetry-go: OTLP HTTP exporters read unbounded HTTP response bodies
GHSA-w8rr-5gcm-pp58
pkg: go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp, go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp, go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp
eco: go
published: Apr 8, 2026
overview:
this report shows that the otlp HTTP exporters (traces/metrics/logs) read the full HTTP response body into an in-memory `bytes.Buffer` without a size cap.

this is exploitable for memory exhaustion when the configured collector endpoint is attacker-controlled (or a network attacker can mit…

CVE-2026-39882
NVD

MEDIUM
CVE-2026-39406
CVE-2026-39406
pkg: node

published: Apr 8, 2026

@hono/node-server allows running the Hono application on Node.js. Prior to 1.19.13, a path handling inconsistency in serveStatic allows protected static files to be accessed by using repeated slashes (//) in the request path. When route-based middleware (e.g., /admin/*) is used for authorization, th…
CWE: CWE-22
GitHub-GHSA

MEDIUM
LiquidJS: ownPropertyOnly bypass via sort_natural filter — prototype property information disclosure through sorting side-channel
GHSA-rv5g-f82m-qrvv
pkg: liquidjs
eco: npm
published: Apr 8, 2026
### Summary

The `sort_natural` filter bypasses the `ownPropertyOnly` security option, allowing template authors to extract values of prototype-inherited properties through a sorting side-channel attack. Applications relying on `ownPropertyOnly: true` as a security boundary (e.g., multi-tenant templ…

CVE-2026-39412
GitHub-GHSA

MEDIUM
Hono missing validation of cookie name on write path in setCookie()
GHSA-26pp-8wgv-hjvm
pkg: hono
eco: npm
published: Apr 8, 2026
## Summary

Cookie names are not validated on the write path when using `setCookie()`, `serialize()`, or `serializeSigned()` to generate Set-Cookie headers.

While certain cookie attributes such as domain and path are validated, the cookie name itself may contain invalid characters.

This results in…

GitHub-GHSA

MEDIUM
Hono: Middleware bypass via repeated slashes in serveStatic
GHSA-wmmm-f939-6g9c
pkg: hono
eco: npm
published: Apr 8, 2026
## Summary

A path handling inconsistency in `serveStatic` allows protected static files to be accessed by using repeated slashes (`//`) in the request path.

When route-based middleware (e.g., `/admin/*`) is used for authorization, the router may not match paths containing repeated slashes, while s…

CVE-2026-39407
GitHub-GHSA

MEDIUM
@hono/node-server: Middleware bypass via repeated slashes in serveStatic
GHSA-92pp-h63x-v22m
pkg: @hono/node-server
eco: npm
published: Apr 8, 2026
## Summary

A path handling inconsistency in `serveStatic` allows protected static files to be accessed by using repeated slashes (`//`) in the request path.

When route-based middleware (e.g., `/admin/*`) is used for authorization, the router may not match paths containing repeated slashes, while `…

CVE-2026-39406
GitHub-GHSA

MEDIUM
JWCrypto: JWE ZIP decompression bomb
GHSA-fjrm-76×2-c4q4
pkg: jwcrypto
eco: pip
published: Apr 8, 2026
### Summary
The fix for GHSA-j857-7rvv-vj97 in v1.5.6 is weak in that it does not allow to fully control the amount of plaintext the receiver is willing to deal with and provides just a weak upper bound. The patch limits input token size to 250KB but does not validate the decompressed output size. A…
CVE-2026-39373
GitHub-GHSA

MEDIUM
Emissary has a Path Traversal via Blacklist Bypass in Configuration API
GHSA-hxf2-gm22-7vcm
pkg: gov.nsa.emissary:emissary
eco: maven
published: Apr 8, 2026
## Summary

The configuration API endpoint (`/api/configuration/{name}`) validated
configuration names using a blacklist approach that checked for `\`, `/`, `..`,
and trailing `.`. This could potentially be bypassed using URL-encoded variants,
double-encoding, or Unicode normalization to achieve pat…

CVE-2026-35583
GitHub-GHSA

MEDIUM
pyload-ng: Incomplete Tar Path Traversal Fix in UnTar._safe_extractall via os.path.commonprefix Bypass
GHSA-mvwx-582f-56r7
pkg: pyload-ng
eco: pip
published: Apr 8, 2026
## Summary

The `_safe_extractall()` function in `src/pyload/plugins/extractors/UnTar.py` uses `os.path.commonprefix()` for its path traversal check, which performs character-level string comparison rather than path-level comparison. This allows a specially crafted tar archive to write files outside…

CVE-2026-35592
NVD

MEDIUM
CVE-2026-39373
CVE-2026-39373
pkg: python

published: Apr 7, 2026

JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attacker can exhaust server memory by sending crafted JWE tokens with ZIP compression. The existing patch for CVE-2024-28102 limits input token size to 250KB but does not validate the …
CWE: CWE-409
GitHub-GHSA

MEDIUM
OpenViking contains a missing authorization vulnerability in the task polling endpoints
GHSA-h336-2wxm-pr6q
pkg: OpenViking
eco: pip
published: Apr 7, 2026
OpenViking versions prior to 0.3.3 contain a missing authorization vulnerability in the task polling endpoints that allows unauthorized attackers to enumerate or retrieve background task metadata created by other users. Attackers can access the /api/v1/tasks and /api/v1/tasks/{task_id} routes withou…
CVE-2026-22680
NVD

MEDIUM
CVE-2026-35592
CVE-2026-35592
pkg: python

published: Apr 7, 2026

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the _safe_extractall() function in src/pyload/plugins/extractors/UnTar.py uses os.path.commonprefix() for its path traversal check, which performs character-level string comparison rather than path-level com…
CWE: CWE-22
NVD

MEDIUM
CVE-2026-34899
CVE-2026-34899
pkg: express

published: Apr 7, 2026

Missing Authorization vulnerability in Eniture technology LTL Freight Quotes – Worldwide Express Edition allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LTL Freight Quotes – Worldwide Express Edition: from n/a through 5.2.1.
CWE: CWE-862
GitHub-GHSA

MEDIUM
Duplicate Advisory: OpenClaw: Gateway Canvas local-direct requests bypass Canvas HTTP and WebSocket authentication
GHSA-9gvx-vj57-vqqx
pkg: openclaw
eco: npm
published: Apr 10, 2026
### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-6mqc-jqh6-x8fc. This link is maintained to preserve external references.

### Original Description
OpenClaw before 2026.3.23 contains an authentication bypass vulnerability in the Canvas gateway where authorize…

GitHub-GHSA

MEDIUM
coursevault-preview has a path traversal due to improper base-directory boundary validation
GHSA-9h9m-rr67-9jpg
pkg: coursevault-preview
eco: npm
published: Apr 8, 2026
## Summary

`coursevault-preview` versions prior to `0.1.1` contain a path traversal vulnerability in the `resolveSafe` utility. The boundary check used `String.prototype.startsWith(baseDir)` on a normalized path, which does not enforce a directory boundary. An attacker who controls the `relativePat…

CVE-2026-35613
GitHub-GHSA

MEDIUM
LobeHub: Unauthenticated authentication bypass on `webapi` routes via forgeable `X-lobe-chat-auth` header
GHSA-5mwj-v5jw-5c97
pkg: @lobehub/lobehub
eco: npm
published: Apr 8, 2026
# Summary

The `webapi` authentication layer trusts a client-controlled `X-lobe-chat-auth` header that is only XOR-obfuscated, not signed or otherwise authenticated. Because the XOR key is hardcoded in the repository, an attacker can forge arbitrary auth payloads and bypass authentication on protect…

CVE-2026-39411
GitHub-GHSA

MEDIUM
OpenFGA's BatchCheck within-request deduplication produces incorrect authorization decisions via list-value cache-key collision
GHSA-jwvj-g8pc-cx45
pkg: github.com/openfga/openfga
eco: go
published: Apr 7, 2026
### Description

In OpenFGA, under specific conditions, BatchCheck calls with multiple checks sent for the same object, relation, and user combination can result in improper policy enforcement.

### Am I affected?

You are affected if you meet the following preconditions:
1. You execute **BatchCheck…

CVE-2026-34972
NVD

MEDIUM
CVE-2026-34972
CVE-2026-34972
pkg: go

published: Apr 6, 2026

OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Zanzibar. From 1.8.0 to 1.13.1, under specific conditions, BatchCheck calls with multiple checks sent for the same object, relation, and user combination can result in improper poli…
CWE: CWE-863
GitHub-GHSA

MEDIUM
Nodemailer Vulnerable to SMTP Command Injection via CRLF in Transport name Option (EHLO/HELO)
GHSA-vvjj-xcjg-gr5g
pkg: nodemailer
eco: npm
published: Apr 8, 2026
### Summary

Nodemailer versions up to and including 8.0.4 are vulnerable to SMTP command injection via CRLF sequences in the transport `name` configuration option. The `name` value is used directly in the EHLO/HELO SMTP command without any sanitization for carriage return and line feed characters (…

GitHub-GHSA

MEDIUM
Ech0 has Stored XSS via SVG Upload and Content-Type Validation Bypass in File Upload
GHSA-69hx-63pv-f8f4
pkg: github.com/lin-snow/ech0
eco: go
published: Apr 10, 2026
## Summary

The file upload endpoint validates Content-Type using only the client-supplied multipart header, with no server-side content inspection or file extension validation. Combined with an unauthenticated static file server that determines Content-Type from file extension, this allows an admin…

GitHub-GHSA

MEDIUM
Duplicate Advisory: OpenClaw: Synology Chat Webhook Pre-Auth Rate-Limit Bypass Enables Brute-Force Guessing of Webhook Token
GHSA-59xc-5v89-r7pr
pkg: openclaw
eco: npm
published: Apr 10, 2026
### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-mf5g-6r6f-ghhm. This link is maintained to preserve external references.

### Original Description
OpenClaw before 2026.3.25 contains a pre-authentication rate-limit bypass vulnerability in webhook token valida…

GitHub-GHSA

MEDIUM
Duplicate Advisory: OpenClaw Bypasses DM Policy Separation via Synology Chat Webhook Path Collision
GHSA-g8mc-c5f2-mqg7
pkg: openclaw
eco: npm
published: Apr 10, 2026
### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-rqp8-q22p-5j9q This link is maintained to preserve external references.

### Original Description
OpenClaw before 2026.3.22 contains a webhook path route replacement vulnerability in the Synology Chat extension…

GitHub-GHSA

MEDIUM
Hono: Non-breaking space prefix bypass in cookie name handling in getCookie()
GHSA-r5rp-j6wh-rvv4
pkg: hono
eco: npm
published: Apr 8, 2026
## Summary

A discrepancy between browser cookie parsing and `parse()` handling allows cookie prefix protections to be bypassed.

Cookie names that are treated as distinct by the browser may be normalized to the same key by `parse()`, allowing attacker-controlled cookies to override legitimate ones.…

CVE-2026-39410
GitHub-GHSA

MEDIUM
Emissary has Stored XSS via Navigation Template Link Injection
GHSA-cpm7-cfpx-3hvp
pkg: gov.nsa.emissary:emissary
eco: maven
published: Apr 7, 2026
## Summary

Mustache navigation templates interpolated configuration-controlled link values
directly into `href` attributes without URL scheme validation. An administrator
who could modify the `navItems` configuration could inject `javascript:` URIs,
enabling stored cross-site scripting (XSS) agains…

CVE-2026-35571
NVD

MEDIUM
CVE-2026-30613
CVE-2026-30613
pkg: node

published: Apr 6, 2026

An information disclosure vulnerability exists in AZIOT 1 Node Smart Switch (16amp)- WiFi/Bluetooth Enabled Software Version: 1.1.9 due to improper access control on the UART debug interface. An attacker with physical access can connect to the UART interface and obtain sensitive information from the…
CWE: CWE-200
GitHub-GHSA

MEDIUM
rembg server is vulnerable to Server-Side Request Forgery (SSRF) and a weak default CORS configuration
GHSA-55v6-g8pm-pw4c
pkg: rembg
eco: pip
published: Apr 10, 2026
# GitHub Security Lab (GHSL) Vulnerability Report, rembg: `GHSL-2024-161`, `GHSL-2024-162`

The [GitHub Security Lab](https://securitylab.github.com) team has identified potential security vulnerabilities in [rembg](https://github.com/danielgatis/rembg).

We are committed to working with you to help…

GitHub-GHSA

MEDIUM
DNN: Force Friend Request Acceptance
GHSA-fpj4-9qhx-5m6m
pkg: DotNetNuke.Core
eco: nuget
published: Apr 10, 2026
In the friends feature, a user could craft a request that would force the acceptance of a friend request on another user.
GitHub-GHSA

MEDIUM
Ech0's Missing Authorization on System Logs Allows Non-Admin Information Disclosure
GHSA-w8jj-cwmc-wgq2
pkg: github.com/lin-snow/ech0
eco: go
published: Apr 10, 2026
## Summary

The system log endpoints (`GET /api/system/logs`, `GET /api/system/logs/stream`, `WS /ws/system/logs`) lack authorization checks, allowing any authenticated non-admin user to read and stream all server logs. These logs contain error stack traces, internal file paths, module names, and ar…

GitHub-GHSA

MEDIUM
Vikunja: Scoped API tokens with projects.background permission can delete project backgrounds
GHSA-v479-vf79-mg83
pkg: code.vikunja.io/api
eco: go
published: Apr 10, 2026
### Summary

Vikunja's scoped API token enforcement for custom project background routes is method-confused. A token with only `projects.background` can successfully delete a project background, while a token with only `projects.background_delete` is rejected.

This is a scoped-token authorization b…

CVE-2026-40103
GitHub-GHSA

MEDIUM
Vikunja Missing Authorization on CalDAV Task Read
GHSA-48ch-p4gq-x46x
pkg: code.vikunja.io/api
eco: go
published: Apr 10, 2026
## Summary

The CalDAV `GetResource` and `GetResourcesByList` methods fetch tasks by UID from the database without verifying that the authenticated user has access to the task's project. Any authenticated CalDAV user who knows (or guesses) a task UID can read the full task data from any project on t…

CVE-2026-35598
GitHub-GHSA

MEDIUM
Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug
GHSA-hj5c-mhh2-g7jq
pkg: code.vikunja.io/api
eco: go
published: Apr 10, 2026
## Summary

The `hasAccessToLabel` function contains a SQL operator precedence bug that allows any authenticated user to read any label that has at least one task association, regardless of project access. Label titles, descriptions, colors, and creator information are exposed.

## Details

The acce…

CVE-2026-35596
NVD

MEDIUM
CVE-2026-35642
CVE-2026-35642
pkg: react

published: Apr 9, 2026

OpenClaw before 2026.3.25 contains an authorization bypass vulnerability where group reaction events bypass the requireMention access control mechanism. Attackers can trigger reactions in mention-gated groups to enqueue agent-visible system events that should remain restricted.
CWE: CWE-288
GitHub-GHSA

MEDIUM
Apache OpenMeetings has an Improper Handling of Insufficient Privileges vulnerability
GHSA-78cg-fc6c-w44w
pkg: org.apache.openmeetings:openmeetings-parent
eco: maven
published: Apr 9, 2026
Sny registered user can query web service with their credentials and get files/sub-folders of any folder by ID (metadata only NOT contents). Metadata includes id, type, name and some other field. Full list of fields get be checked at FileItemDTO object.

This issue affects Apache OpenMeetings: fro…

CVE-2026-33005
NVD

MEDIUM
CVE-2026-5875
CVE-2026-5875
pkg: go

published: Apr 8, 2026

Policy bypass in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-639
GitHub-GHSA

MEDIUM
RustFS has an authorization bypass in multipart UploadPartCopy enables cross-bucket object exfiltration
GHSA-mx42-j6wv-px98
pkg: rustfs
eco: rust
published: Apr 8, 2026
RustFS contains a missing authorization check in the multipart copy path (`UploadPartCopy`). A low-privileged user who cannot read objects from a victim bucket can still exfiltrate victim objects by copying them into an attacker-controlled multipart upload and completing the upload.

This breaks ten…

CVE-2026-39360
GitHub-GHSA

MEDIUM
Cosign's verify-blob-attestation reports false positive when payload parsing fails
GHSA-w6c6-c85g-mmv6
pkg: github.com/sigstore/cosign, github.com/sigstore/cosign
eco: go
published: Apr 8, 2026
## Description

`cosign verify-blob-attestation` may erroneously report a "Verified OK" result for attestations with malformed payloads or mismatched predicate types. For old-format bundles and detached signatures, this was due to a logic flaw in the error handling of the predicate type validation. …

CVE-2026-39395
GitHub-GHSA

MEDIUM
Apache ActiveMQ: Improper validation and restriction of a classpath path name
GHSA-h2h4-5m64-m273
pkg: org.apache.activemq:activemq-client, org.apache.activemq:activemq-client, org.apache.activemq:activemq-broker
eco: maven
published: Apr 7, 2026
Improper validation and restriction of a classpath path name vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ Web, Apache ActiveMQ.

In two instances (when creating a Stomp consumer and also browsing messages in the Web console) an authenticated u…

CVE-2026-33227
GitHub-GHSA

MEDIUM
fast-jwt has a ReDoS when using RegExp in allowed* leading to CPU exhaustion during token verification
GHSA-cjw9-ghj4-fwxf
pkg: fast-jwt
eco: npm
published: Apr 9, 2026
## ⚠️ IMPORTANT CLARIFICATIONS

### Affected Configurations
This vulnerability ONLY affects applications that:
– Use RegExp objects (not strings) in the allowedAud, allowedIss, allowedSub, allowedJti, or allowedNonce options
– Configure patterns susceptible to catastrophic backtracking

CVE-2026-35041
NVD

MEDIUM
CVE-2026-35041
CVE-2026-35041
pkg: express

published: Apr 9, 2026

fast-jwt provides fast JSON Web Token (JWT) implementation. From 5.0.0 to 6.2.0, a denial-of-service condition exists in fast-jwt when the allowedAud verification option is configured using a regular expression. Because the aud claim is attacker-controlled and the library evaluates it against the su…
CWE: CWE-1333
NVD

MEDIUM
CVE-2026-39413
CVE-2026-39413
pkg: jwt

published: Apr 8, 2026

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.4.14, the LightRAG API is vulnerable to a JWT algorithm confusion attack where an attacker can forge tokens by specifying 'alg': 'none' in the JWT header. Since the jwt.decode() call does not explicitly deny the 'none' algo…
CWE: CWE-347
GitHub-GHSA

MEDIUM
lightrag-hku: JWT Algorithm Confusion Vulnerability
GHSA-8ffj-4hx4-9pgf
pkg: lightrag-hku
eco: pip
published: Apr 8, 2026
## Summary
The LightRAG API is vulnerable to a JWT algorithm confusion attack where an attacker can forge tokens by specifying 'alg': 'none' in the JWT header. Since the `jwt.decode()` call does not explicitly deny the 'none' algorithm, a crafted token without a signature will be accepted as valid, …
CVE-2026-39413
GitHub-GHSA

MEDIUM
Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output
GHSA-2g7h-7rqr-9p4r
pkg: code.vikunja.io/api
eco: go
published: Apr 10, 2026
## Summary

The CalDAV output generator builds iCalendar VTODO entries via raw string concatenation without applying RFC 5545 TEXT value escaping. User-controlled task titles containing CRLF characters break the iCalendar property boundary, allowing injection of arbitrary iCalendar properties such a…

CVE-2026-35601
GitHub-GHSA

MEDIUM
parisneo/lollms has an insufficient session expiration vulnerability
GHSA-8jg2-726g-xh43
pkg: lollms
eco: pip
published: Apr 8, 2026
An insufficient session expiration vulnerability exists in the latest version of parisneo/lollms. The application fails to invalidate active sessions after a password reset, allowing an attacker to continue using an old session token. This issue arises due to the absence of logic to reject requests …
CVE-2026-1163
GitHub-GHSA

MEDIUM
kube-router: BGP Peer Passwords Exposed in Logs at Verbose Logging Level
GHSA-fcmh-qfxc-w685
pkg: github.com/cloudnativelabs/kube-router/v2
eco: go
published: Apr 8, 2026
## Summary

When kube-router is configured with per-node BGP peer passwords using the `kube-router.io/peer.passwords` node annotation, and verbose logging is enabled (`–v=2` or higher), the raw Kubernetes node annotation map is logged verbatim — including the base64-encoded BGP MD5 passwords. Any…

NVD

MEDIUM
CVE-2026-39316
CVE-2026-39316
pkg: linux

published: Apr 7, 2026

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, a use-after-free vulnerability exists in the CUPS scheduler (cupsd) when temporary printers are automatically deleted. cupsdDeleteTemporaryPrinters() in scheduler/printe…
CWE: CWE-416
NVD

MEDIUM
CVE-2026-39314
CVE-2026-39314
pkg: linux

published: Apr 7, 2026

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, an integer underflow vulnerability in _ppdCreateFromIPP() (cups/ppd-cache.c) allows any unprivileged local user to crash the cupsd root process by supplying a negative j…
CWE: CWE-191
GitHub-GHSA

MEDIUM
next-intl has an open redirect vulnerability
GHSA-8f24-v5vv-gm5j
pkg: next-intl
eco: npm
published: Apr 10, 2026
### Impact

Applications using the `next-intl` middleware with `localePrefix: 'as-needed'` could construct URLs where path handling and the WHATWG URL parser resolved a relative redirect target to another host (e.g. scheme-relative `//` or control characters stripped by the URL parser), so the middl…

GitHub-GHSA

MEDIUM
Juju: In-Memory Token Store for Discharge Tokens Lacks Concurrency Safety and Persistence
GHSA-7m55-2hr4-pw78
pkg: github.com/juju/juju
eco: go
published: Apr 10, 2026
### Summary

The localLoginHandlers struct in the Juju API server maintains an in-memory map to store discharge tokens following successful local authentication. This map is accessed concurrently from multiple HTTP handler goroutines without any synchronization primitive protecting it. The absence o…

CVE-2026-5774
GitHub-GHSA

MEDIUM
pypdf: Manipulated XMP metadata entity declarations can exhaust RAM
GHSA-3crg-w4f6-42mx
pkg: pypdf
eco: pip
published: Apr 10, 2026
### Impact

An attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires parsing the XMP metadata.

### Patches
This has been fixed in [pypdf==6.10.0](https://github.com/py-pdf/pypdf/releases/tag/6.10.0).

### Workarounds
If you cannot upgrade yet, conside…

CVE-2026-40260
GitHub-GHSA

MEDIUM
ajenti.plugin.core has race conditions in 2FA
GHSA-8647-755q-fw9p
pkg: ajenti.plugin.core
eco: pip
published: Apr 10, 2026
### Impact

If the 2FA was activated, it was possible during a short moment after the authentication of an user to bypass its authentication.

### Patches

This is fixed in the version 0.112. Users should upgrade to this version as soon as possible.

CVE-2026-40178
GitHub-GHSA

MEDIUM
PraisonAI: SQLiteConversationStore didn't validate table_prefix when constructing SQL queries
GHSA-x783-xp3g-mqhp
pkg: PraisonAI
eco: pip
published: Apr 10, 2026
### Summary

The `table_prefix` configuration value is directly used to construct SQL table identifiers without validation.

If an attacker controls this value, they can manipulate SQL query structure, leading to unauthorized data access (e.g., reading internal SQLite tables such as `sqlite_master`)…

GitHub-GHSA

MEDIUM
justhtml includes multiple security fixes
GHSA-c9vm-hv86-f23r
pkg: justhtml
eco: pip
published: Apr 10, 2026
## Summary

`justhtml` `1.15.0` includes multiple security fixes affecting URL sanitization helpers, HTML serialization, Markdown passthrough, and several custom sanitization-policy edge cases.

These issues have different impact levels and do not all affect the default configuration in the same way…

GitHub-GHSA

MEDIUM
Apache Log4j's JsonTemplateLayout produces invalid JSON output when log events contain non-finite floating-point values
GHSA-w35j-pv5h-q9q9
pkg: org.apache.logging.log4j:log4j-layout-template-json, org.apache.logging.log4j:log4j-layout-template-json
eco: maven
published: Apr 10, 2026
Apache Log4j's JsonTemplateLayout https://logging.apache.org/log4j/2.x/manual/json-template-layout.html , in versions up to and including 2.25.3, produces invalid JSON output when log events contain non-finite floating-point values (NaN, Infinity, or -Infinity), which are prohibited by RFC 8259. Thi…
CVE-2026-34481
GitHub-GHSA

MEDIUM
Apache Log4j Core's XmlLayout fails to sanitize characters
GHSA-3pxv-7cmr-fjr4
pkg: org.apache.logging.log4j:log4j-core, org.apache.logging.log4j:log4j-core
eco: maven
published: Apr 10, 2026
Apache Log4j Core's XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , in versions up to and including 2.25.3, fails to sanitize characters forbidden by the XML 1.0 specification https://www.w3.org/TR/xml/#charsets producing invalid XML output whenever a log message or …
CVE-2026-34480
GitHub-GHSA

MEDIUM
@sveltejs/kit: Unvalidated redirect in handle hook causes Denial-of-Service
GHSA-3f6h-2hrp-w5wx
pkg: @sveltejs/kit
eco: npm
published: Apr 10, 2026
`redirect`, when called from inside the `handle` server hook with a location parameter containing characters that are invalid in a HTTP header, will cause an unhandled `TypeError`. This could result in DoS on some platforms, especially if the location passed to `redirect` contains unsanitized user i…
CVE-2026-40074
GitHub-GHSA

MEDIUM
Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segment
GHSA-hr2v-4r36-88hr
pkg: helm.sh/helm/v4, helm.sh/helm/v3
eco: go
published: Apr 10, 2026
Helm is a package manager for Charts for Kubernetes. In Helm versions <=3.20.1 and <=4.1.3, a specially crafted Chart will cause `helm pull –untar [chart URL | repo/chartname]` to write the Chart's contents to the immediate output directory (as defaulted to the current working directory; or as giv…
CVE-2026-35206
GitHub-GHSA

MEDIUM
Wasmtime has improperly masked return value from `table.grow` with Winch compiler backend
GHSA-f984-pcp8-v2p7
pkg: wasmtime, wasmtime, wasmtime
eco: rust
published: Apr 10, 2026
### Impact

Wasmtime's Winch compiler backend contains a bug where translating the `table.grow` operator causes the result to be incorrectly typed. For 32-bit tables this means that the result of the operator, internally in Winch, is tagged as a 64-bit value instead of a 32-bit value. This invalid i…

CVE-2026-35186
GitHub-GHSA

MEDIUM
Gramps Web API: Private Sub-Object Data in Non-Private Objects Exposed to Guest Users
GHSA-9gjv-jvm7-vv2v
pkg: gramps-webapi
eco: pip
published: Apr 9, 2026
## Summary

Users with the **Guest** role could receive private sub-object data (e.g. private alternate names, private addresses, private note/citation/media handles) through list API endpoints such as `GET /api/people/`, `GET /api/places/`, `GET /api/events/`, and all other object list endpoints.

GitHub-GHSA

MEDIUM
Wasmtime has out-of-bounds write or crash when transcoding component model strings
GHSA-394w-hwhg-8vgm
pkg: wasmtime, wasmtime, wasmtime
eco: rust
published: Apr 9, 2026
### Impact

Wasmtime's implementation of transcoding strings between components contains a bug where the return value of a guest component's `realloc` is not validated before the host attempts to write through the pointer. This enables a guest to cause the host to write arbitrary transcoded string b…

CVE-2026-35195
GitHub-GHSA

MEDIUM
Wasmtime has host panic when Winch compiler executes `table.fill`
GHSA-q49f-xg75-m9xw
pkg: wasmtime, wasmtime, wasmtime
eco: rust
published: Apr 9, 2026
### Impact

Wasmtime's Winch compiler contains a vulnerability where the compilation of the `table.fill` instruction can result in a host panic. This means that a valid guest can be compiled with Winch, on any architecture, and cause the host to panic. This represents a denial-of-service vulnerabili…

CVE-2026-34946
GitHub-GHSA

MEDIUM
Wasmtime segfault or unused out-of-sandbox load with `f64x2.splat` operator on x86-64
GHSA-qqfj-4vcm-26hv
pkg: wasmtime, wasmtime, wasmtime
eco: rust
published: Apr 9, 2026
On x86-64 platforms with SSE3 disabled Wasmtime's compilation of the `f64x2.splat` WebAssembly instruction with Cranelift may load 8 more bytes than is necessary. When [signals-based-traps](https://docs.rs/wasmtime/latest/wasmtime/struct.Config.html#method.signals_based_traps) are disabled this can …
CVE-2026-34944
GitHub-GHSA

MEDIUM
Wasmtime has a possible panic when lifting `flags` component value
GHSA-m758-wjhj-p3jq
pkg: wasmtime, wasmtime, wasmtime
eco: rust
published: Apr 9, 2026
### Impact

Wasmtime contains a possible panic which can happen when a `flags`-typed component model value is lifted with the `Val` type. If bits are set outside of the set of flags the component model specifies that these bits should be ignored but Wasmtime will panic when this value is lifted. Thi…

CVE-2026-34943
GitHub-GHSA

MEDIUM
Wasmtime: Panic when transcoding misaligned utf-16 strings
GHSA-jxhv-7h78-9775
pkg: wasmtime, wasmtime, wasmtime
eco: rust
published: Apr 9, 2026
### Impact

Wasmtime's implementation of transcoding strings into the Component Model's `utf16` or `latin1+utf16` encodings improperly verified the alignment of reallocated strings. This meant that unaligned pointers could be passed to the host for transcoding which would trigger a host panic. This …

CVE-2026-34942
GitHub-GHSA

MEDIUM
Wasmtime: Heap OOB read in component model UTF-16 to latin1+utf16 string transcoding
GHSA-hx6p-xpx3-jvvv
pkg: wasmtime, wasmtime, wasmtime
eco: rust
published: Apr 9, 2026
### Summary

Wasmtime contains a vulnerability where when transcoding a UTF-16 string to the latin1+utf16 component-model encoding it would incorrectly validate the byte length of the input string when performing a bounds check. Specifically the number of code units were checked instead of the byte …

CVE-2026-34941
GitHub-GHSA

MEDIUM
OpenClaw: Multiple Code Paths Missing Base64 Pre-Allocation Size Checks
GHSA-ccx3-fw7q-rr2r
pkg: openclaw
eco: npm
published: Apr 9, 2026
## Impact

Multiple Code Paths Missing Base64 Pre-Allocation Size Checks.

Several base64 decode paths could allocate before enforcing decoded-size limits.

OpenClaw is a user-controlled local assistant. This advisory is scoped to the OpenClaw trust model and does not assume a multi-tenant service b…

GitHub-GHSA

MEDIUM
OpenClaw B-M3: ClawHub package downloads are not enforced with integrity verification
GHSA-3vvq-q2qc-7rmp
pkg: openclaw
eco: npm
published: Apr 9, 2026
## Impact

B-M3: ClawHub package downloads are not enforced with integrity verification.

ClawHub downloads could install plugin archives without enforcing archive or per-file integrity metadata.

OpenClaw is a user-controlled local assistant. This advisory is scoped to the OpenClaw trust model and …

GitHub-GHSA

MEDIUM
OpenClaw Host-Exec Environment Variable Injection
GHSA-w9j9-w4cp-6wgr
pkg: openclaw
eco: npm
published: Apr 9, 2026
## Impact

OpenClaw Host-Exec Environment Variable Injection.

Host exec could inherit environment variables that influence interpreters, shells, or build tools.

OpenClaw is a user-controlled local assistant. This advisory is scoped to the OpenClaw trust model and does not assume a multi-tenant ser…

GitHub-GHSA

MEDIUM
OpenClaw: Strict browser SSRF bypass in Playwright redirect handling leaves private targets reachable
GHSA-w8g9-x8gx-crmm
pkg: openclaw
eco: npm
published: Apr 9, 2026
## Impact

Strict browser SSRF bypass in Playwright redirect handling leaves private targets reachable.

Strict browser SSRF checks could miss Playwright request-time navigation to private targets.

OpenClaw is a user-controlled local assistant. This advisory is scoped to the OpenClaw trust model an…

GitHub-GHSA

MEDIUM
OpenClaw has Browser SSRF Policy Bypass via Interaction-Triggered Navigation
GHSA-vr5g-mmx7-h897
pkg: openclaw
eco: npm
published: Apr 9, 2026
## Impact

Browser SSRF Policy Bypass via Interaction-Triggered Navigation.

Browser interactions could trigger navigations that bypassed the normal SSRF navigation checks.

OpenClaw is a user-controlled local assistant. This advisory is scoped to the OpenClaw trust model and does not assume a multi…

GitHub-GHSA

MEDIUM
OpenClaw `node.pair.approve` placed in `operator.write` scope instead of `operator.pairing` allows unprivileged pairing approval
GHSA-67mf-f936-ppxf
pkg: openclaw
eco: npm
published: Apr 9, 2026
## Impact

OpenClaw `node.pair.approve` placed in `operator.write` scope instead of `operator.pairing` allows unprivileged pairing approval.

The pairing approval method accepted operator.write instead of the narrower pairing scope and admin requirement for exec-capable nodes.

OpenClaw is a user-co…

GitHub-GHSA

MEDIUM
OpenClaw QQ Bot Extension missing SSRF Protection on All Media Fetch Paths
GHSA-3fv3-6p2v-gxwj
pkg: openclaw
eco: npm
published: Apr 9, 2026
## Impact

QQ Bot Extension: Missing SSRF Protection on All Media Fetch Paths.

QQ Bot media download paths were not consistently routed through the SSRF guard and allowlist policy.

OpenClaw is a user-controlled local assistant. This advisory is scoped to the OpenClaw trust model and does not assum…

GitHub-GHSA

MEDIUM
OpenClaw: Existing WS sessions survive shared gateway token rotation
GHSA-5h3f-885m-v22w
pkg: openclaw
eco: npm
published: Apr 9, 2026
## Impact

Existing WS sessions survive shared gateway token rotation.

Rotating the shared gateway token did not disconnect existing shared-token WebSocket sessions.

OpenClaw is a user-controlled local assistant. This advisory is scoped to the OpenClaw trust model and does not assume a multi-tenan…

GitHub-GHSA

MEDIUM
OpenClaw: /allowlist omits owner-only enforcement for cross-channel allowlist writes
GHSA-vc32-h5mq-453v
pkg: openclaw
eco: npm
published: Apr 9, 2026
## Impact

/allowlist omits owner-only enforcement for cross-channel allowlist writes.

An authorized non-owner sender could attempt allowlist writes against a different channel.

OpenClaw is a user-controlled local assistant. This advisory is scoped to the OpenClaw trust model and does not assume a…

GitHub-GHSA

MEDIUM
OpenClaw: resolvedAuth closure becomes stale after config reload
GHSA-68×5-xx89-w9mm
pkg: openclaw
eco: npm
published: Apr 9, 2026
## Impact

resolvedAuth closure becomes stale after config reload.

After a config reload, newly accepted gateway connections could continue using stale resolved auth state.

OpenClaw is a user-controlled local assistant. This advisory is scoped to the OpenClaw trust model and does not assume a mult…

GitHub-GHSA

MEDIUM
OpenClaw `node.invoke(browser.proxy)` bypasses `browser.request` persistent profile-mutation guard
GHSA-cmfr-9m2r-xwhq
pkg: openclaw
eco: npm
published: Apr 9, 2026
## Impact

OpenClaw `node.invoke(browser.proxy)` bypasses `browser.request` persistent profile-mutation guard.

node.invoke(browser.proxy) could mutate persistent browser profiles through a path that bypassed the browser.request guard.

OpenClaw is a user-controlled local assistant. This advisory is…

GitHub-GHSA

MEDIUM
OpenClaw `device.token.rotate` mints tokens for unapproved roles, bypassing device role-upgrade pairing
GHSA-whf9-3hcx-gq54
pkg: openclaw
eco: npm
published: Apr 9, 2026
## Impact

OpenClaw `device.token.rotate` mints tokens for unapproved roles, bypassing device role-upgrade pairing.

Device token rotation could mint or preserve roles/scopes that had not gone through the intended pairing approval.

OpenClaw is a user-controlled local assistant. This advisory is sco…

GitHub-GHSA

MEDIUM
OpenClaw: Shared reply MEDIA – paths are treated as trusted and can trigger cross-channel local file exfiltration
GHSA-qqq7-4hxc-x63c
pkg: openclaw
eco: npm
published: Apr 9, 2026
## Impact

Shared reply MEDIA: paths are treated as trusted and can trigger cross-channel local file exfiltration.

A crafted shared reply MEDIA reference could cause another channel to read a local file path as trusted generated media.

OpenClaw is a user-controlled local assistant. This advisory i…

GitHub-GHSA

MEDIUM
OpenClaw: strictInlineEval explicit-approval boundary bypassed by approval-timeout fallback on gateway and node exec hosts
GHSA-q2gc-xjqw-qp89
pkg: openclaw
eco: npm
published: Apr 9, 2026
## Impact

strictInlineEval explicit-approval boundary bypassed by approval-timeout fallback on gateway and node exec hosts.

The approval-timeout fallback could allow inline eval commands that strictInlineEval was meant to require explicit approval for.

OpenClaw is a user-controlled local assistan…

GitHub-GHSA

MEDIUM
Cryptography vulnerable to buffer overflow if non-contiguous buffers were passed to APIs
GHSA-p423-j2cm-9vmq
pkg: cryptography
eco: pip
published: Apr 8, 2026
If a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. `Hash.update()`), this could lead to buffer overflows. For example:

“`python
h = Hash(SHA256())
b.update(buf[::-1])
“`

would read past the end of the buffer on Python >3.11

CVE-2026-39892
GitHub-GHSA

MEDIUM
quarkus-openapi-generator extension has Zip Slip Path Traversal in ApicurioCodegenWrapper class
GHSA-jx2w-vp7f-456q
pkg: io.quarkiverse.openapi.generator:quarkus-openapi-generator
eco: maven
published: Apr 8, 2026
### Summary
A path traversal vulnerability was discovered in the quarkus-openapi-generator extension

### Details
The `unzip()` method in `ApicurioCodegenWrapper.java` extracts ZIP entries without validating that the resolved file path stays within the intended output directory. At line 101, the des…

CVE-2026-40180
GitHub-GHSA

MEDIUM
pretix: API leaks check-in data between events of the same organizer
GHSA-wr8q-c73g-m7gp
pkg: pretix, pretix, pretix
eco: pip
published: Apr 8, 2026
A new API endpoint introduced in pretix 2025 that is supposed to return all check-in events of a specific event in fact returns all check-in events belonging to the respective organizer. This allows an API consumer to access information for all other events under the same organizer, even those they …
CVE-2026-5600
GitHub-GHSA

MEDIUM
LiquidJS: `renderFile()` / `parseFile()` bypass configured `root` and allow arbitrary file read
GHSA-v273-448j-v4qj
pkg: liquidjs
eco: npm
published: Apr 8, 2026
`liquidjs` 10.25.0 documents `root` as constraining filenames passed to `renderFile()` and `parseFile()`, but top-level file loads do not enforce that boundary.

The published npm package `liquidjs@10.25.0` on Linux 6.17.0 with Node v22.22.1. A `Liquid` instance configured with an empty temporary di…

CVE-2026-39859
GitHub-GHSA

MEDIUM
Hono has incorrect IP matching in ipRestriction() for IPv4-mapped IPv6 addresses
GHSA-xpcf-pg52-r92g
pkg: hono
eco: npm
published: Apr 8, 2026
## Summary

`ipRestriction()` does not canonicalize IPv4-mapped IPv6 client addresses (e.g. `::ffff:127.0.0.1`) before applying IPv4 allow or deny rules. In environments such as Node.js dual-stack, this can cause IPv4 rules to fail to match, leading to unintended authorization behavior.

## Details

CVE-2026-39409
GitHub-GHSA

MEDIUM
Hono: Path traversal in toSSG() allows writing files outside the output directory
GHSA-xf4j-xp2r-rqqx
pkg: hono
eco: npm
published: Apr 8, 2026
## Summary

A path traversal issue in `toSSG()` allows files to be written outside the configured output directory during static site generation. When using dynamic route parameters via `ssgParams`, specially crafted values can cause generated file paths to escape the intended output directory.

## …

CVE-2026-39408
GitHub-GHSA

MEDIUM
openclaw-claude-bridge: sandbox is not effective – `–allowed-tools ""` does not restrict available tools
GHSA-7853-gqqm-vcwx
pkg: openclaw-claude-bridge
eco: npm
published: Apr 8, 2026
## Affected

openclaw-claude-bridge v1.1.0

## Issue

v1.1.0 spawns the Claude Code CLI subprocess with `–allowed-tools ""` and the release notes + README claim this **"disables all CLI tools"** for sandboxing. This claim is incorrect.

Per the Claude Code CLI documentation, `–allowed-tools` (alia…

CVE-2026-39398
GitHub-GHSA

MEDIUM
Parse Server's Endpoint `/sessions/me` bypasses `_Session` `protectedFields`
GHSA-g4v2-qx3q-4p64
pkg: parse-server, parse-server
eco: npm
published: Apr 8, 2026
### Impact

The `GET /sessions/me` endpoint returns `_Session` fields that the server operator explicitly configured as protected via the `protectedFields` server option. Any authenticated user can retrieve their own session's protected fields with a single request. The equivalent `GET /sessions` an…

CVE-2026-39381
GitHub-GHSA

MEDIUM
skilleton has improper input handling in repository/path processing
GHSA-5g3j-89fr-r2vp
pkg: skilleton
eco: npm
published: Apr 8, 2026
## Summary

`skilleton` versions prior to `0.3.1` include security-related weaknesses in repository normalization and path handling logic.
Version `0.3.1` contains fixes and additional test coverage for these issues.

## Affected Versions

`<0.3.1`

## Patched Versions

`>=0.3.1`

## Impact

In af…

GitHub-GHSA

MEDIUM
Parse Server has a login timing side-channel reveals user existence
GHSA-mmpq-5hcv-hf2v
pkg: parse-server, parse-server
eco: npm
published: Apr 8, 2026
### Impact

The login endpoint response time differs measurably depending on whether the submitted username or email exists in the database. When a user is not found, the server responds immediately. When a user exists but the password is wrong, a bcrypt comparison runs first, adding significant lat…

CVE-2026-39321
GitHub-GHSA

MEDIUM
File Browser discloses text file content via /api/resources endpoint bypassing Perm.Download check
GHSA-67cg-cpj7-qgc9
pkg: github.com/filebrowser/filebrowser/v2
eco: go
published: Apr 8, 2026
## Summary

The `resourceGetHandler` in `http/resource.go` returns full text file content without checking the `Perm.Download` permission flag. All three other content-serving endpoints (`/api/raw`, `/api/preview`, `/api/subtitle`) correctly verify this permission before serving content. A user with…

CVE-2026-35606
GitHub-GHSA

MEDIUM
File Browser has an access rule bypass via HasPrefix without trailing separator in path matching
GHSA-5q48-q4fm-g3m6
pkg: github.com/filebrowser/filebrowser/v2
eco: go
published: Apr 8, 2026
Hi,

The `Matches()` function in `rules/rules.go` uses `strings.HasPrefix()` without a trailing directory separator when matching paths against access rules. A rule for `/uploads` also matches `/uploads_backup/`, granting or denying access to unintended directories. Verified against v2.62.2 (commit …

CVE-2026-35605
GitHub-GHSA

MEDIUM
Apache Cassandra has sensitive Information Leak in cqlsh
GHSA-fh34-c629-p8xj
pkg: org.apache.cassandra:cassandra-all
eco: maven
published: Apr 7, 2026
Sensitive Information Leak in cqlsh in Apache Cassandra 4.0 allows access to sensitive information, like passwords, from previously executed cqlsh command via  ~/.cassandra/cqlsh_history local file access.

Users are recommended to upgrade to version 4.0.20, which fixes this issue.


Description…

CVE-2026-27315
GitHub-GHSA

MEDIUM
OpenClaw: Android accepted cleartext remote gateway endpoints and sent stored credentials over ws://
GHSA-83f3-hh45-vfw9
pkg: openclaw
eco: npm
published: Apr 7, 2026
## Summary

Before OpenClaw 2026.4.2, Android accepted non-loopback cleartext `ws://` gateway endpoints and would send stored gateway credentials over that connection. Discovery beacons or setup codes could therefore steer the client onto a cleartext remote endpoint.

## Impact

A user who followed …

GitHub-GHSA

MEDIUM
OpenClaw: Shared-secret comparison call sites leaked length information through timing
GHSA-jj6q-rrrf-h66h
pkg: openclaw
eco: npm
published: Apr 7, 2026
## Summary

Before OpenClaw 2026.4.2, several shared-secret comparison call sites still used early length-mismatch checks instead of the shared fixed-length comparison helper. Those paths could leak secret-length information through measurable timing differences.

## Impact

The affected paths expos…

GitHub-GHSA

MEDIUM
OpenClaw: Zalo replay dedupe keys could suppress messages across chats or senders
GHSA-rxmx-g7hr-8mx4
pkg: openclaw
eco: npm
published: Apr 7, 2026
## Summary

Before OpenClaw 2026.4.2, Zalo webhook replay dedupe keys were not scoped strongly enough across chat and sender dimensions. Legitimate events from different conversations or senders could collide and be dropped as duplicates.

## Impact

Cross-conversation or cross-sender collisions cou…

GitHub-GHSA

MEDIUM
OpenClaw: Trailing-dot localhost CDP hosts could bypass remote loopback protections
GHSA-fh32-73r9-rgh5
pkg: openclaw
eco: npm
published: Apr 7, 2026
## Summary

Before OpenClaw 2026.4.2, remote CDP discovery could return a trailing-dot localhost host such as `localhost.` and bypass OpenClaw's loopback-host normalization. That let a non-loopback remote CDP profile pivot the follow-up connection back onto localhost.

## Impact

A hostile discovery…

GitHub-GHSA

MEDIUM
OpenClaw: pnpm dlx approvals did not bind local script operands
GHSA-w6wx-jq6j-6mcj
pkg: openclaw
eco: npm
published: Apr 7, 2026
## Summary

Before OpenClaw 2026.4.2, `pnpm dlx` approval planning did not bind local script operands the same way as related `pnpm exec` flows. A local script approved through a `pnpm dlx` path could be replaced before execution without invalidating the approval.

## Impact

An operator could appro…

GitHub-GHSA

MEDIUM
OpenClaw: Windows-compatible env override keys could bypass system.run approval binding
GHSA-98ch-45wp-ch47
pkg: openclaw
eco: npm
published: Apr 7, 2026
## Summary

Before OpenClaw 2026.4.2, system-run approval binding normalized environment override keys differently from host execution. Windows-compatible keys could be omitted from the approval binding while still being injected at execution time.

## Impact

An approved command could run with atta…

GitHub-GHSA

MEDIUM
OpenClaw: Gateway hello snapshots exposed host config and state paths to non-admin clients
GHSA-2f7j-rp58-mr42
pkg: openclaw
eco: npm
published: Apr 7, 2026
## Summary

Before OpenClaw 2026.4.2, the Gateway `connect` success snapshot exposed local `configPath` and `stateDir` metadata to non-admin clients. Low-privilege authenticated clients could learn host filesystem layout and deployment details that were not needed for their role.

## Impact

A non-a…

GitHub-GHSA

MEDIUM
OpenClaw: Untrusted workspace channel shadows could execute during built-in channel setup
GHSA-2qrv-rc5x-2g2h
pkg: openclaw
eco: npm
published: Apr 7, 2026
## Summary

Before OpenClaw 2026.4.2, built-in channel setup and login could resolve an untrusted workspace channel shadow before the plugin was explicitly trusted. A malicious workspace plugin that claimed a bundled channel id could execute during channel setup even while still disabled.

## Impact…

GitHub-GHSA

MEDIUM
OpenClaw: Read-scoped identity-bearing HTTP clients could kill sessions via /sessions/:sessionKey/kill
GHSA-5hff-46vh-rxmw
pkg: openclaw
eco: npm
published: Apr 7, 2026
## Summary

Before OpenClaw 2026.4.2, `POST /sessions/:sessionKey/kill` did not enforce write scopes in identity-bearing HTTP modes. A caller limited to read-only operator scopes could still terminate a running subagent session.

## Impact

A read-scoped caller could perform a write-class control-pl…

GitHub-GHSA

MEDIUM
OpenClaw: iOS A2UI bridge trusted generic local-network pages for agent.request dispatch
GHSA-4p4f-fc8q-84m3
pkg: openclaw
eco: npm
published: Apr 7, 2026
## Summary
Before OpenClaw 2026.4.2, the iOS A2UI bridge treated generic local-network pages as trusted bridge origins. A page loaded from a local-network or tailnet host could trigger agent.request dispatch without the stricter trusted-canvas origin check.

## Impact
A loaded attacker-controlled pa…

GitHub-GHSA

MEDIUM
OpenClaw: QQ Bot structured payloads could read arbitrary local files
GHSA-846p-hgpv-vphc
pkg: openclaw
eco: npm
published: Apr 7, 2026
## Summary

Before OpenClaw 2026.4.2, QQ Bot structured media payloads could read local files from attacker-chosen paths. A crafted structured payload could escape QQ Bot-owned media roots and cause arbitrary file reads on the host.

## Impact

Prompt-influenced structured payload output could exfil…

GitHub-GHSA

MEDIUM
OpenClaw: OpenShell mirror mode could delete arbitrary remote directories when roots were mis-scoped
GHSA-m34q-h93w-vg5x
pkg: openclaw
eco: npm
published: Apr 7, 2026
## Summary

Before OpenClaw 2026.4.2, the OpenShell mirror backend accepted arbitrary absolute `remoteWorkspaceDir` and `remoteAgentWorkspaceDir` values. In mirror mode, those paths were then used as the target of remote cleanup and overwrite operations.

## Impact

If an attacker could influence th…

GitHub-GHSA

MEDIUM
OpenClaw: Pairing pending-request caps were enforced per channel instead of per account
GHSA-wwfp-w96m-c6x8
pkg: openclaw
eco: npm
published: Apr 7, 2026
## Summary

Before OpenClaw 2026.3.31, pending pairing-request caps were enforced per channel file instead of per account. On multi-account channel setups, requests from other accounts could fill the shared pending window and block new pairing challenges on an unaffected account.

## Impact

This is…

GitHub-GHSA

MEDIUM
MLflow is vulnerable to Stored Cross-Site Scripting (XSS) caused by unsafe parsing of YAML-based MLmodel artifacts in its web interface
GHSA-fh64-r2vc-xvhr
pkg: mlflow
eco: pip
published: Apr 7, 2026
MLflow is vulnerable to Stored Cross-Site Scripting (XSS) caused by unsafe parsing of YAML-based MLmodel artifacts in its web interface. An authenticated attacker can upload a malicious MLmodel file containing a payload that executes when another user views the artifact in the UI. This allows action…
CVE-2026-33865
GitHub-GHSA

MEDIUM
MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint
GHSA-46r5-x6jq-v8g6
pkg: mlflow
eco: pip
published: Apr 7, 2026
MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint used to download saved model artifacts. Due to missing access‑control validation, a user without permissions to a given experiment can directly query this endpoint and retrieve model artifacts they are not authorized to ac…
CVE-2026-33866


Vulnerability Digest — April 11, 2026 · 54 Critical · 2 Exploited






Vulnerability Digest — Saturday, April 11, 2026


Security Report

Saturday, April 11, 2026  ·  Last 7 days  ·  Min severity: MEDIUM
Total Findings
401
Critical
54
High
157
Actively Exploited
2
CISA-KEV2
NVD100
GitHub-GHSA299
Findings sorted by severity
CISA-KEV

CRITICAL
Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
CVE-2026-1340
pkg: Ivanti Endpoint Manager Mobile (EPMM)

published: Apr 8, 2026

Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
Fortinet FortiClient EMS Improper Access Control Vulnerability
CVE-2026-35616
pkg: Fortinet FortiClient EMS

published: Apr 6, 2026

Fortinet FortiClient EMS contains an improper access control vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
GitHub-GHSA

CRITICAL
Daptin has Unauthenticated Path Traversal and Zip Slip
GHSA-9cp7-j3f8-p5jx
pkg: github.com/daptin/daptin
eco: go
published: Apr 10, 2026
### Impact
The `cloudstore.file.upload` action in `server/actions/action_cloudstore_file_upload.go` writes user-supplied filenames directly to disk without proper validation.

This allows unauthenticated attackers to perform path traversal and zip slip attacks, leading to arbitrary file write and p…

GitHub-GHSA

CRITICAL
paperclip Vulnerable to Unauthenticated Remote Code Execution via Import Authorization Bypass
GHSA-68qg-g8mg-6pr7
pkg: paperclipai, @paperclipai/server
eco: npm
published: Apr 10, 2026
## Summary

An unauthenticated attacker can achieve full remote code execution on any network-accessible Paperclip instance running in `authenticated` mode with default configuration. No user interaction, no credentials, just the target's address. The entire chain is six API calls.

## Steps to Repr…

GitHub-GHSA

CRITICAL
Juju: CloudSpec method leaking cloud credentials
GHSA-w5fq-8965-c969
pkg: github.com/juju/juju
eco: go
published: Apr 10, 2026
### Impact

If a user has login permission to a controller and knows the controller model UUID, they can call the CloudSpec method on the Controller facade and get cloud credentials used to bootstrap the controller.

The CloudSpec API is called by workers running in the controller to maintain connec…

CVE-2026-5412
NVD

CRITICAL
CVE-2026-40175
CVE-2026-40175
pkg: axios

published: Apr 10, 2026

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0, the Axios library is vulnerable to a specific "Gadget" attack chain that allows Prototype Pollution in any third-party dependency to be escalated into Remote Code Execution (RCE) or Full Cloud Compromise (via AWS IMDS…
CWE: CWE-113, CWE-444, CWE-918
GitHub-GHSA

CRITICAL
Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
GHSA-fvcv-3m26-pcqx
pkg: axios
eco: npm
published: Apr 10, 2026
# Vulnerability Disclosure: Unrestricted Cloud Metadata Exfiltration via Header Injection Chain

## Summary
The Axios library is vulnerable to a specific "Gadget" attack chain that allows **Prototype Pollution** in any third-party dependency to be escalated into **Remote Code Execution (RCE)** or **…

CVE-2026-40175
GitHub-GHSA

CRITICAL
PraisonAI has sandbox escape via exception frame traversal in `execute_code` (subprocess mode)
GHSA-qf73-2hrx-xprp
pkg: praisonaiagents
eco: pip
published: Apr 8, 2026
## Summary

`execute_code()` in `praisonaiagents.tools.python_tools` defaults to
`sandbox_mode="sandbox"`, which runs user code in a subprocess wrapped with a
restricted `__builtins__` dict and an AST-based blocklist. The AST blocklist
embedded inside the subprocess wrapper (`blocked_attrs`, line 14…

CVE-2026-39888
NVD

CRITICAL
CVE-2026-40089
CVE-2026-40089
pkg: docker

published: Apr 9, 2026

Sonicverse is a Self-hosted Docker Compose stack for live radio streaming. The Sonicverse Radio Audio Streaming Stack dashboard contains a Server-Side Request Forgery (SSRF) vulnerability in its API client (apps/dashboard/lib/api.ts). Installations created using the provided install.sh script (inclu…
CWE: CWE-918
NVD

CRITICAL
CVE-2026-23696
CVE-2026-23696
pkg: jwt

published: Apr 7, 2026

Windmill CE and EE versions 1.276.0 through 1.603.2 contain an SQL injection vulnerability in the folder ownership management functionality that allows authenticated attackers to inject SQL through the owner parameter. An attacker can use the injection to read sensitive data such as the JWT signing …
CWE: CWE-89
GitHub-GHSA

CRITICAL
PraisonAI has critical RCE via `type: job` workflow YAML
GHSA-vc46-vw85-3wvm
pkg: praisonaiagents, PraisonAI
eco: pip
published: Apr 10, 2026
`praisonai workflow run <file.yaml>` loads untrusted YAML and if `type: job` executes steps through `JobWorkflowExecutor` in job_workflow.py.

This supports:
– `run:` → shell command execution via `subprocess.run()`
– `script:` → inline Python execution via `exec()`
– `python:` → arbitrary Pyt…

GitHub-GHSA

CRITICAL
PraisonAI Vulnerable to Remote Code Execution via YAML Deserialization in Agent Definition Loading
GHSA-32vr-5gcf-3pw2
pkg: praisonai
eco: pip
published: Apr 8, 2026
## Summary
The `AgentService.loadAgentFromFile` method uses the `js-yaml` library to parse YAML files without disabling dangerous tags (such as `!!js/function` and `!!js/undefined`). This allows an attacker to craft a malicious YAML file that, when parsed, executes arbitrary JavaScript code. An atta…
CVE-2026-39890
GitHub-GHSA

CRITICAL
pgx contains memory-safety vulnerability
GHSA-xgrm-4fwx-7qm8
pkg: github.com/jackc/pgx/v5/pgproto3
eco: go
published: Apr 7, 2026
[pgx](github.com/jackc/pgx/v5) is a pure Go driver and toolkit for PostgreSQL. pgx v5.9.1 and earlier contain a memory-safety vulnerability.
CVE-2026-33815
NVD

CRITICAL
CVE-2026-35490
CVE-2026-35490
pkg: flask

published: Apr 7, 2026

changedetection.io is a free open source web page change detection tool. Prior to 0.54.8, the @login_optionally_required decorator is placed before (outer to) @blueprint.route() instead of after it. In Flask, @route() must be the outermost decorator because it registers the function it receives. Whe…
CWE: CWE-863
NVD

CRITICAL
CVE-2026-4277
CVE-2026-4277
pkg: django

published: Apr 7, 2026

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30.
Add permissions on inline model instances were not validated on submission of
forged `POST` data in `GenericInlineModelAdmin`.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluat…
CWE: CWE-862
NVD

CRITICAL
CVE-2026-1114
CVE-2026-1114
pkg: jwt

published: Apr 7, 2026

In parisneo/lollms version 2.1.0, the application's session management is vulnerable to improper access control due to the use of a weak secret key for signing JSON Web Tokens (JWT). This vulnerability allows an attacker to perform an offline brute-force attack to recover the secret key. Once the se…
CWE: CWE-284
GitHub-GHSA

CRITICAL
changedetection.io Vulnerable to Authentication Bypass via Decorator Ordering
GHSA-jmrh-xmgh-x9j4
pkg: changedetection.io
eco: pip
published: Apr 6, 2026
### Summary

On 13 routes across 5 blueprint files, the `@login_optionally_required` decorator is placed **before** (outer to) `@blueprint.route()` instead of after it. In Flask, `@route()` must be the outermost decorator because it registers the function it receives. When the order is reversed, `@r…

CVE-2026-35490
NVD

CRITICAL
CVE-2026-34841
CVE-2026-34841
pkg: axios

published: Apr 6, 2026

Bruno is an open source IDE for exploring and testing APIs. Prior to 3.2.1, Bruno was affected by a supply chain attack involving compromised versions of the axios npm package, which introduced a hidden dependency deploying a cross-platform Remote Access Trojan (RAT). Users of @usebruno/cli who ran …
CWE: CWE-494, CWE-506
GitHub-GHSA

CRITICAL
PraisonAI Vulnerable to OS Command Injection
GHSA-2763-cj5r-c79m
pkg: PraisonAI
eco: pip
published: Apr 8, 2026
The `execute_command` function and workflow shell execution are exposed to user-controlled input via agent workflows, YAML definitions, and LLM-generated tool calls, allowing attackers to inject arbitrary shell commands through shell metacharacters.

## Description

PraisonAI's workflow system …

CVE-2026-40088
GitHub-GHSA

CRITICAL
parisneo/lollms vulnerable to stored XSS in the social feature
GHSA-8wrq-fv5f-pfp2
pkg: lollms
eco: pip
published: Apr 10, 2026
A Stored Cross-Site Scripting (XSS) vulnerability was identified in the social feature of parisneo/lollms, affecting the latest version prior to 2.2.0. The vulnerability exists in the `create_post` function within `backend/routers/social/__init__.py`, where user-provided content is directly assigned…
CVE-2026-1115
GitHub-GHSA

CRITICAL
@delmaredigital/payload-puc is missing authorization on /api/puck/* CRUD endpoints allows unauthenticated access to Puck-registered collections
GHSA-65w6-pf7x-5g85
pkg: @delmaredigital/payload-puck
eco: npm
published: Apr 8, 2026
### Impact

All `/api/puck/*` CRUD endpoint handlers registered by `createPuckPlugin()` called Payload's local API with the default `overrideAccess: true`, bypassing all collection-level access control. The `access` option passed to `createPuckPlugin()` and any `access` rules defined on Puck-registe…

CVE-2026-39397
GitHub-GHSA

CRITICAL
PraisonAI Vulnerable Untrusted Remote Template Code Execution
GHSA-pv9q-275h-rh7x
pkg: PraisonAI
eco: pip
published: Apr 10, 2026
PraisonAI treats remotely fetched template files as trusted executable code without integrity verification, origin validation, or user confirmation, enabling supply chain attacks through malicious templates.

## Description

When a user installs a template from a remote source (e.g., GitHub), P…

CVE-2026-40154
GitHub-GHSA

CRITICAL
gramps-webapi: Zip Slip Path Traversal in Media Archive Import
GHSA-m5gr-86j6-99jp
pkg: gramps-webapi
eco: pip
published: Apr 10, 2026
## Summary

A path traversal vulnerability (Zip Slip) exists in the media archive import feature. An authenticated user with owner-level privileges can craft a malicious ZIP file with directory-traversal filenames to write arbitrary files outside the intended temporary extraction directory on the se…

CVE-2026-40258
GitHub-GHSA

CRITICAL
nimiq-blockchain is missing a wall-clock upper bound on block timestamps
GHSA-49xc-52mp-cc9j
pkg: nimiq-blockchain
eco: rust
published: Apr 10, 2026
### Impact

Block timestamp validation enforces that `timestamp >= parent.timestamp` for non-skip blocks and `timestamp == parent.timestamp + MIN_PRODUCER_TIMEOUT` for skip blocks, but there is no visible upper bound check against the wall clock. A malicious block-producing validator can set block t…

CVE-2026-40093
GitHub-GHSA

CRITICAL
PraisonAI Browser Server allows unauthenticated WebSocket clients to hijack connected extension sessions
GHSA-8x8f-54wf-vv92
pkg: praisonaiagents, PraisonAI
eco: pip
published: Apr 10, 2026
### Summary
`praisonai browser start` exposes the browser bridge on `0.0.0.0` by default, and its `/ws` endpoint accepts websocket clients that omit the `Origin` header entirely. An unauthenticated network client can connect as a fake controller, send `start_session`, cause the server to forward `st…
GitHub-GHSA

CRITICAL
LXD: VM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf
GHSA-fm2x-c5qw-4h6f
pkg: github.com/canonical/lxd
eco: go
published: Apr 10, 2026
## Summary

The `isVMLowLevelOptionForbidden` function in `lxd/project/limits/permissions.go` is missing `raw.apparmor` and `raw.qemu.conf` from its hardcoded forbidden list. A user with `can_edit` permission on a VM instance in a restricted project can combine these two omissions to bridge the LXD …

CVE-2026-34177
GitHub-GHSA

CRITICAL
LXD: Importing a crafted backup leads to project restriction bypass
GHSA-q96j-3fmm-7fv4
pkg: github.com/canonical/lxd
eco: go
published: Apr 10, 2026
## Summary

LXD instance backup import validates project restrictions against `backup/index.yaml` embedded in the tar archive, but creates the actual instance from `backup/container/backup.yaml` extracted to the storage volume. Because these are separate, independently attacker-controlled files with…

CVE-2026-34178
GitHub-GHSA

CRITICAL
LXD: Update of type field in restricted TLS certificate allows privilege escalation to cluster admin
GHSA-c3h3-89qf-jqm5
pkg: github.com/canonical/lxd
eco: go
published: Apr 10, 2026
### Summary

A restricted TLS certificate user can escalate to cluster admin by changing their certificate type from `client` to `server` via PUT/PATCH to `/1.0/certificates/{fingerprint}`. The non-admin guard and reset block in `doCertificateUpdate` fail to validate or reset the `Type` field, allow…

CVE-2026-34179
GitHub-GHSA

CRITICAL
Apache Tomcat: CLIENT_CERT authentication does not fail as expected
GHSA-95jq-rwvf-vjx4
pkg: org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat-catalina
eco: maven
published: Apr 9, 2026
CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52, from 9.0.83 through 9.0.115; Apache Tomcat Nativ…

CVE-2026-29145
NVD

CRITICAL
CVE-2026-29145
CVE-2026-29145
pkg: apache

published: Apr 9, 2026

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52, from 9.0.83 through 9.0.115; Apache Tomcat Nativ…

CWE: CWE-287
GitHub-GHSA

CRITICAL
Apache Airflow: JWT token still valid after logout
GHSA-c92r-g8j5-vhcx
pkg: apache-airflow
eco: pip
published: Apr 9, 2026
When user logged out, the JWT token the user had authtenticated with was not invalidated, which could lead to reuse of that token in case it was intercepted. In Airflow 3.2 we implemented the mechanism that implements token invalidation at logout. Users who are concerned about the logout scenario an…
CVE-2025-57735
NVD

CRITICAL
CVE-2025-57735
CVE-2025-57735
pkg: jwt

published: Apr 9, 2026

When user logged out, the JWT token the user had authtenticated with was not invalidated, which could lead to reuse of that token in case it was intercepted. In Airflow 3.2 we implemented the mechanism that implements token invalidation at logout. Users who are concerned about the logout scenario an…
CWE: CWE-613
NVD

CRITICAL
CVE-2026-34179
CVE-2026-34179
pkg: tls

published: Apr 9, 2026

In Canonical LXD versions 4.12 through 6.7, the doCertificateUpdate function in lxd/certificates.go does not validate the Type field when handling PUT/PATCH requests to /1.0/certificates/{fingerprint} for restricted TLS certificate users, allowing a remote authenticated attacker to escalate privileg…
CWE: CWE-915
NVD

CRITICAL
CVE-2026-40035
CVE-2026-40035
pkg: flask

published: Apr 8, 2026

Unfurl through 2025.08 contains an improper input validation vulnerability in config parsing that enables Flask debug mode by default. The debug configuration value is read as a string and passed directly to app.run(), causing any non-empty string to evaluate truthy, allowing attackers to access the…
CWE: CWE-489
GitHub-GHSA

CRITICAL
SiYuan: Remote Code Execution in the Electron desktop client via stored XSS in synced table captions
GHSA-phhp-9rm9-6gr2
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: Apr 8, 2026
### Summary
A malicious note synced to another user can trigger remote code execution in the SiYuan Electron desktop client. The root cause is that table caption content is stored without safe escaping and later unescaped into rendered HTML, creating a stored XSS sink. Because the desktop renderer r…
CVE-2026-39846
GitHub-GHSA

CRITICAL
Emmett has a path traversal in internal assets handler
GHSA-pr46-2v3c-5356
pkg: emmett
eco: pip
published: Apr 8, 2026
The RSGI static handler for Emmett's internal assets (`/__emmett__` paths) is vulnerable to path traversal attacks.

An attacker can use `../` sequences (eg `/__emmett__/../rsgi/handlers.py`) to read arbitrary files outside the assets directory.

CVE-2026-39847
GitHub-GHSA

CRITICAL
Emissary has GitHub Actions Shell Injection via Workflow Inputs
GHSA-3g6g-gq4r-xjm9
pkg: gov.nsa.emissary:emissary
eco: maven
published: Apr 8, 2026
## Summary

Three GitHub Actions workflow files contained **10 shell injection points** where
user-controlled `workflow_dispatch` inputs were interpolated directly into shell
commands via `${{ }}` expression syntax. An attacker with repository write access
could inject arbitrary shell commands, lead…

CVE-2026-35580
NVD

CRITICAL
CVE-2026-28386
CVE-2026-28386
pkg: tls

published: Apr 7, 2026

Issue summary: Applications using AES-CFB128 encryption or decryption on
systems with AVX-512 and VAES support can trigger an out-of-bounds read
of up to 15 bytes when processing partial cipher blocks.

Impact summary: This out-of-bounds read may trigger a crash which leads to
Denial of Service for …

CWE: CWE-125
NVD

CRITICAL
CVE-2026-35573
CVE-2026-35573
pkg: churchcrm churchcrm

published: Apr 7, 2026

ChurchCRM is an open-source church management system. Prior to 6.5.3, a path traversal vulnerability in ChurchCRM's backup restore functionality allows authenticated administrators to upload arbitrary files and achieve remote code execution by overwriting Apache .htaccess configuration files. The vu…
CWE: CWE-22, CWE-434
NVD

CRITICAL
CVE-2026-35580
CVE-2026-35580
pkg: express

published: Apr 7, 2026

Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, GitHub Actions workflow files contained shell injection points where user-controlled workflow_dispatch inputs were interpolated directly into shell commands via ${{ }} expression syntax. An attacker with repository write access co…
CWE: CWE-77
NVD

CRITICAL
CVE-2026-35030
CVE-2026-35030
pkg: litellm litellm

published: Apr 6, 2026

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, when JWT authentication is enabled (enable_jwt_auth: true), the OIDC userinfo cache uses token[:20] as the cache key. JWT headers produced by the same signing algorithm generate identical first 20 …
CWE: CWE-287
NVD

CRITICAL
CVE-2026-34950
CVE-2026-34950
pkg: jwt

published: Apr 6, 2026

fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.1.0 and earlier, the publicKeyPemMatcher regex in fast-jwt/src/crypto.js uses a ^ anchor that is defeated by any leading whitespace in the key string, re-enabling the exact same JWT algorithm confusion attack that CVE-2023-48223 patche…
CWE: CWE-327
GitHub-GHSA

CRITICAL
PraisonAI Vulnerable to Arbitrary File Write / Path Traversal in Action Orchestrator
GHSA-jfxc-v5g9-38xr
pkg: PraisonAI
eco: pip
published: Apr 6, 2026
The Action Orchestrator feature contains a Path Traversal vulnerability that allows an attacker (or compromised agent) to write to arbitrary files outside of the configured workspace directory. By supplying relative path segments (`../`) in the target path, malicious actions can overwrite sensitive …
CVE-2026-39305
GitHub-GHSA

CRITICAL
goshs has a file-based ACL authorization bypass in goshs state-changing routes
GHSA-wvhv-qcqf-f3cx
pkg: github.com/patrickhener/goshs
eco: go
published: Apr 10, 2026
### Summary
goshs enforces the documented per-folder `.goshs` ACL/basic-auth mechanism for directory listings and file reads, but it does not enforce the same authorization checks for state-changing routes. An unauthenticated attacker can upload files with `PUT`, upload files with multipart `POST /u…
CVE-2026-40189
GitHub-GHSA

CRITICAL
ajenti.plugin.core has password bypass when 2FA is activated
GHSA-3mcx-6wxm-qr8v
pkg: ajenti.plugin.core
eco: pip
published: Apr 10, 2026
### Impact

If the 2FA was activated, it was possible to bypass the password authentication

### Patches

This is fixed in the version 0.112. Users should upgrade to this version as soon as possible.

CVE-2026-40177
GitHub-GHSA

CRITICAL
PraisonAI vulnerable to arbitrary file write via path traversal in `praisonai recipe unpack`
GHSA-99g3-w8gr-x37c
pkg: PraisonAI
eco: pip
published: Apr 10, 2026
| Field | Value |
|—|—|
| Severity | Critical |
| Type | Path traversal — arbitrary file write via `tar.extract()` without member validation |
| Affected | `src/praisonai/praisonai/cli/features/recipe.py:1170-1172` |

## Summary

`cmd_unpack` in the recipe CLI extracts `.praison` tar archives u…

CVE-2026-40157
GitHub-GHSA

CRITICAL
PraisonAIAgents has an OS Command Injection via shell=True in Memory Hooks Executor (memory/hooks.py)
GHSA-v7px-3835-7gjx
pkg: praisonaiagents
eco: pip
published: Apr 10, 2026
Summary

The memory hooks executor in praisonaiagents passes a user-controlled command string
directly to subprocess.run() with shell=True at
src/praisonai-agents/praisonaiagents/memory/hooks.py lines 303 to 305.
No sanitization, no shlex.quote(), no character filter, and no allowlist check
exists a…

CVE-2026-40111
GitHub-GHSA

CRITICAL
Wasmtime with Winch compiler backend on aarch64 may allow a sandbox-escaping memory access
GHSA-xx5w-cvp6-jv83
pkg: wasmtime, wasmtime, wasmtime
eco: rust
published: Apr 10, 2026
### Impact

Wasmtime with its Winch (baseline) non-default compiler backend may allow properly constructed guest Wasm to access host memory outside of its linear-memory sandbox.

This vulnerability requires use of the Winch compiler (`-Ccompiler=winch`). By default, Wasmtime uses its Cranelift backe…

CVE-2026-34987
GitHub-GHSA

CRITICAL
Wasmtime: Miscompiled guest heap access enables sandbox escape on aarch64 Cranelift
GHSA-jhxm-h53p-jm7w
pkg: wasmtime, wasmtime, wasmtime
eco: rust
published: Apr 9, 2026
### Impact

Wasmtime's Cranelift compilation backend contains a bug on aarch64 when performing a certain shape of heap accesses which means that the wrong address is accessed. When combined with explicit bounds checks a guest WebAssembly module this can create a situation where there are two divergi…

CVE-2026-34971
GitHub-GHSA

CRITICAL
Axios has a NO_PROXY Hostname Normalization Bypass Leads to SSRF
GHSA-3p68-rc4w-qgx5
pkg: axios
eco: npm
published: Apr 9, 2026
Axios does not correctly handle hostname normalization when checking `NO_PROXY` rules.
Requests to loopback addresses like `localhost.` (with a trailing dot) or `[::1]` (IPv6 literal) skip `NO_PROXY` matching and go through the configured proxy.

This goes against what developers expect and lets att…

CVE-2025-62718
GitHub-GHSA

CRITICAL
Marimo: Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
GHSA-2679-6mx9-h9xc
pkg: marimo
eco: pip
published: Apr 8, 2026
## Summary

Marimo (19.6k stars) has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint `/terminal/ws` lacks authentication validation, allowing an unauthenticated attacker to obtain a full PTY shell and execute arbitrary system commands.

Unlike other WebSocket endpoints (e.g., `/ws`) th…

CVE-2026-39987
GitHub-GHSA

CRITICAL
Rack::Session::Cookie secrets: decrypt failure fallback enables secretless session forgery and Marshal deserialization
GHSA-33qg-7wpp-89cq
pkg: rack-session
eco: rubygems
published: Apr 8, 2026
`Rack::Session::Cookie` incorrectly handles decryption failures when configured with `secrets:`. If cookie decryption fails, the implementation falls back to a default decoder instead of rejecting the cookie. This allows an unauthenticated attacker to supply a crafted session cookie that is accepted…
CVE-2026-39324
GitHub-GHSA

CRITICAL
OpenIdentityPlatform OpenAM: Pre-Authentication Remote Code Execution via `jato.clientSession` Deserialization in OpenAM
GHSA-2cqq-rpvq-g5qj
pkg: org.openidentityplatform.openam:openam
eco: maven
published: Apr 7, 2026
## Summary

OpenIdentityPlatform OpenAM 16.0.5 (and likely earlier versions) is vulnerable to pre-authentication Remote Code Execution (RCE) via unsafe Java deserialization of the `jato.clientSession` HTTP parameter. This bypasses the `WhitelistObjectInputStream` mitigation that was applied to the `…

CVE-2026-33439
GitHub-GHSA

CRITICAL
PraisonAI Has Path Traversal in FileTools
GHSA-693f-pf34-72c5
pkg: PraisonAI
eco: pip
published: Apr 6, 2026
### Executive Summary:
The path validation has a critical logic bug: it checks for `..` AFTER `normpath()` has already collapsed all `..` sequences. This makes the check completely useless and allows trivial path traversal to any file on the system.
The path validation function also does not resolve…
CVE-2026-35615
GitHub-GHSA

HIGH
mathjs Allows Improperly Controlled Modification of Dynamically-Determined Object Attributes
GHSA-jvff-x2qm-6286
pkg: mathjs
eco: npm
published: Apr 10, 2026
### Impact
Two security vulnerabilities where detected that allowed executing arbitrary JavaScript via the expression parser of mathjs. You can be affected when you have an application where users can evaluate arbitrary expressions using the mathjs expression parser.

### Patches
The problem is patc…

GitHub-GHSA

HIGH
PraisonAI: Hardcoded `approval_mode="auto"` in Chainlit UI Overrides Administrator Configuration, Enabling Unapproved Shell Command Execution
GHSA-qwgj-rrpj-75xm
pkg: PraisonAI
eco: pip
published: Apr 10, 2026
## Summary

The Chainlit UI modules (`chat.py` and `code.py`) hardcode `config.approval_mode = "auto"` after loading administrator configuration from the `PRAISON_APPROVAL_MODE` environment variable, silently overriding any "manual" or "scoped" approval setting. This defeats the human-in-the-loop ap…

GitHub-GHSA

HIGH
Duplicate Advisory: OpenClaw Gateway: RCE and Privilege Escalation from operator.pairing to operator.admin via device.pair.approve
GHSA-r3v5-2grc-429h
pkg: openclaw
eco: npm
published: Apr 10, 2026
### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-hf68-49fm-59cq. This link is maintained to preserve external references.

### Original Description
OpenClaw before 2026.3.22 contains a privilege escalation vulnerability in the device.pair.approve method that …

NVD

HIGH
CVE-2026-39911
CVE-2026-39911
pkg: express

published: Apr 9, 2026

Hashgraph Guardian through version 3.5.0 contains an unsandboxed JavaScript execution vulnerability in the Custom Logic policy block worker that allows authenticated Standard Registry users to execute arbitrary code by passing user-supplied JavaScript expressions directly to the Node.js Function() c…
CWE: CWE-668
NVD

HIGH
CVE-2026-39891
CVE-2026-39891
pkg: express

published: Apr 8, 2026

PraisonAI is a multi-agent teams system. Prior to 4.5.115, the create_agent_centric_tools() function returns tools (like acp_create_file) that process file content using template rendering. When user input from agent.start() is passed directly into these tools without escaping, template expressions …
CWE: CWE-94
GitHub-GHSA

HIGH
AGiXT Vulnerable to Path Traversal in safe_join()
GHSA-5gfj-64gh-mgmw
pkg: agixt
eco: pip
published: Apr 8, 2026
### Summary
The safe_join() function in the essential_abilities extension fails to validate that resolved file paths remain within the designated agent workspace. An authenticated attacker can use directory traversal sequences to read, write, or delete arbitrary files on the server hosting the AGiXT…
CVE-2026-39981
GitHub-GHSA

HIGH
PraisonAI has Template Injection in Agent Tool Definitions
GHSA-hwg5-x759-7wjg
pkg: praisonai
eco: pip
published: Apr 8, 2026
## Summary
Direct insertion of unescaped user input into template-rendering tools allows arbitrary code execution via specially crafted agent instructions.
## Details
The `create_agent_centric_tools()` function returns tools (like `acp_create_file`) that process file content using template rendering…
CVE-2026-39891
GitHub-GHSA

HIGH
Apache Cassandra is vulnerable to privilege escalation in an mTLS environment using MutualTlsAuthenticator
GHSA-qxpc-96fq-wwmg
pkg: org.apache.cassandra:cassandra-all
eco: maven
published: Apr 7, 2026
Privilege escalation in Apache Cassandra 5.0 on an mTLS environment using MutualTlsAuthenticator allows a user with only CREATE permission to associate their own certificate identity with an arbitrary role, including a superuser role, and authenticate as that role via ADD IDENTITY.

Users are re…

CVE-2026-27314
NVD

HIGH
CVE-2026-27314
CVE-2026-27314
pkg: apache

published: Apr 7, 2026

Privilege escalation in Apache Cassandra 5.0 on an mTLS environment using MutualTlsAuthenticator allows a user with only CREATE permission to associate their own certificate identity with an arbitrary role,
including a superuser role, and authenticate as that role via ADD IDENTITY.

Users are re…

CWE: CWE-267
NVD

HIGH
CVE-2026-35463
CVE-2026-35463
pkg: ssl

published: Apr 7, 2026

pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, the ADMIN_ONLY_OPTIONS protection mechanism restricts security-critical configuration values (reconnect scripts, SSL certs, proxy credentials) to admin-only access. However, this protection is only app…
CWE: CWE-78
NVD

HIGH
CVE-2026-34197
CVE-2026-34197
pkg: apache

published: Apr 7, 2026

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ.

Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations o…

CWE: CWE-20, CWE-94
NVD

HIGH
CVE-2026-35044
CVE-2026-35044
pkg: bentoml bentoml

published: Apr 6, 2026

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.38, the Dockerfile generation function generate_containerfile() in src/bentoml/_internal/container/generate.py uses an unsandboxed jinja2.Environment with the jinja2.ext.do extensi…
CWE: CWE-1336
NVD

HIGH
CVE-2019-25671
CVE-2019-25671
pkg: apache

published: Apr 5, 2026

VA MAX 8.3.4 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary commands by injecting shell metacharacters into the mtu_eth0 parameter. Attackers can send POST requests to the changeip.php endpoint with malicious payload in the mtu_eth0 field to e…
CWE: CWE-22
NVD

HIGH
CVE-2026-35554
CVE-2026-35554
pkg: apache

published: Apr 7, 2026

A race condition in the Apache Kafka Java producer client’s buffer pool management can cause messages to be silently delivered to incorrect topics.

When a produce batch expires due to delivery.timeout.ms while a network request containing that batch is still in flight, the batch’s ByteBuffer is…

CWE: CWE-362, CWE-416
NVD

HIGH
CVE-2026-35408
CVE-2026-35408
pkg: oauth

published: Apr 6, 2026

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus's Single Sign-On (SSO) login pages lacked a Cross-Origin-Opener-Policy (COOP) HTTP response header. Without this header, a malicious cross-origin window that opens the Directus login page reta…
CWE: CWE-346, CWE-693
GitHub-GHSA

HIGH
PraisonAI Vulnerable to Code Injection and Protection Mechanism Failure
GHSA-3c4r-6p77-xwr7
pkg: PraisonAI
eco: pip
published: Apr 10, 2026
PraisonAI's AST-based Python sandbox can be bypassed using `type.__getattribute__` trampoline, allowing arbitrary code execution when running untrusted agent code.

## Description

The `_execute_code_direct` function in `praisonaiagents/tools/python_tools.py` uses AST filtering to block dangerous Py…

CVE-2026-40158
GitHub-GHSA

HIGH
basic-ftp has FTP Command Injection via CRLF
GHSA-chqc-8p9q-pq6q
pkg: basic-ftp
eco: npm
published: Apr 8, 2026
## Summary

`basic-ftp` version `5.2.0` allows FTP command injection via CRLF sequences (`\r\n`) in file path parameters passed to high-level path APIs such as `cd()`, `remove()`, `rename()`, `uploadFrom()`, `downloadTo()`, `list()`, and `removeDir()`. The library's `protectWhitespace()` helper only…

CVE-2026-39983
NVD

HIGH
CVE-2026-33752
CVE-2026-33752
pkg: lexiforest curl_cffi

published: Apr 6, 2026

curl_cffi is the a Python binding for curl. Prior to 0.15.0, curl_cffi does not restrict requests to internal IP ranges, and follows redirects automatically via the underlying libcurl. Because of this, an attacker-controlled URL can redirect requests to internal services such as cloud metadata endpo…
CWE: CWE-918
GitHub-GHSA

HIGH
SiYuan: Publish Reader Path Traversal Delete via `removeUnusedAttributeView`
GHSA-vw86-c94w-v3x4
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: Apr 10, 2026
SiYuan's publish/read-only boundary can be broken through `/api/av/removeUnusedAttributeView`.

A publish-service Reader context can call this endpoint because it is protected only by `CheckAuth`, and publish requests are forwarded upstream with a valid `RoleReader` JWT. The handler accepts attacker…

NVD

HIGH
CVE-2026-5483
CVE-2026-5483
pkg: kubernetes

published: Apr 10, 2026

A flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in the `odh-dashboard` component of Red Hat OpenShift AI (RHOAI) allows for the disclosure of Kubernetes Service Account tokens through a NodeJS endpoint. This could enable an attacker to gain unauthorized access to Kubern…
CWE: CWE-201
GitHub-GHSA

HIGH
n8n-mcp has authenticated SSRF via instance-URL header in multi-tenant HTTP mode
GHSA-4ggg-h7ph-26qr
pkg: n8n-mcp
eco: npm
published: Apr 8, 2026
## Impact
An authenticated Server-Side Request Forgery in `n8n-mcp` allows a caller holding a valid `AUTH_TOKEN` to cause the server to issue HTTP requests to arbitrary URLs supplied through multi-tenant HTTP headers. Response bodies are reflected back through JSON-RPC, so an attacker can read the c…
CVE-2026-39974
GitHub-GHSA

HIGH
PraisonAI Vulnerable to RCE via Automatic tools.py Import
GHSA-g985-wjh9-qxxc
pkg: praisonaiagents, PraisonAI
eco: pip
published: Apr 10, 2026
PraisonAI automatically imports `./tools.py` from the current working directory when launching certain components. This includes call.py, tool_resolver.py, and CLI tool-loading paths.

A malicious tools.py placed in the process working directory is executed immediately, allowing arbitrary Python cod…

GitHub-GHSA

HIGH
PraisonAI Vulnerable to Argument Injection into Cloud Run Environment Variables via Unsanitized Comma in gcloud –set-env-vars
GHSA-fvxx-ggmx-3cjg
pkg: PraisonAI
eco: pip
published: Apr 10, 2026
**Summary**

deploy.py constructs a single comma-delimited string for the gcloud run
deploy –set-env-vars argument by directly interpolating openai_model,
openai_key, and openai_base without validating that these values do not
contain commas. gcloud uses a comma as the key-value pair separator for

CVE-2026-40113
GitHub-GHSA

HIGH
Vikunja vulnerable to Privilege Escalation via Project Reparenting
GHSA-2vq4-854f-5c72
pkg: code.vikunja.io/api
eco: go
published: Apr 10, 2026
## Summary

A user with Write-level access to a project can escalate their permissions to Admin by moving the project under a project they own. After reparenting, the recursive permission CTE resolves ownership of the new parent as Admin on the moved project. The attacker can then delete the project…

CVE-2026-35595
GitHub-GHSA

HIGH
Open Cluster Management (OCM): Cross-cluster privilege escalation via improper Kubernetes client certificate renewal validation
GHSA-q4gv-pjmh-c735
pkg: open-cluster-management.io/ocm
eco: go
published: Apr 7, 2026
A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). Improper validation of Kubernetes client certificate renewal allows a managed cluster administrator to forge a client certificate that can be approved by the OCM controller. This e…
CVE-2026-4740
GitHub-GHSA

HIGH
n8n-mcp has unauthenticated session termination and information disclosure in HTTP transport
GHSA-75hx-xj24-mqrw
pkg: n8n-mcp
eco: npm
published: Apr 10, 2026
### Summary

Several HTTP transport endpoints in n8n-mcp lacked proper authentication, and the health check endpoint exposed sensitive operational metadata without credentials.

### Impact

An unauthenticated attacker with network access to the n8n-mcp HTTP server could disrupt active MCP sessions a…

GitHub-GHSA

HIGH
basic-ftp: Incomplete CRLF Injection Protection Allows Arbitrary FTP Command Execution via Credentials and MKD Commands
GHSA-6v7q-wjvx-w8wg
pkg: basic-ftp
eco: npm
published: Apr 10, 2026
## Summary

basic-ftp's CRLF injection protection (added in commit 2ecc8e2 for GHSA-chqc-8p9q-pq6q) is incomplete. Two code paths bypass the `protectWhitespace()` control character check: (1) the `login()` method directly concatenates user-supplied credentials into USER/PASS FTP commands without any…

GitHub-GHSA

HIGH
Saltcorn has an Unauthenticated Path Traversal in sync endpoints, allowing arbitrary file write and directory read
GHSA-32pv-mpqg-h292
pkg: @saltcorn/server, @saltcorn/server, @saltcorn/server
eco: npm
published: Apr 10, 2026
### Summary

Two unauthenticated path traversal vulnerabilities exist in Saltcorn's mobile sync endpoints. The `POST /sync/offline_changes` endpoint allows an unauthenticated attacker to create arbitrary directories and write a `changes.json` file with attacker-controlled JSON content anywhere on th…

CVE-2026-40163
NVD

HIGH
CVE-2026-39429
CVE-2026-39429
pkg: kubernetes

published: Apr 8, 2026

kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.30.3 and 0.29.3, the cache server is directly exposed by the root shard and has no authentication or authorization in place. This allows anyone who can access the root shard to…
CWE: CWE-302, CWE-862
GitHub-GHSA

HIGH
kcp's cache server is accessible without authentication or authorization checks
GHSA-3j3q-wp9x-585p
pkg: github.com/kcp-dev/kcp, github.com/kcp-dev/kcp
eco: go
published: Apr 8, 2026
### Summary

The cache server is directly exposed by the root shard and has no authentication or authorization in place.
This allows anyone who can access the root shard to read and write to the cache server.

### Details

The cache server is routed in the pre-mux chain in the shard code.
The preHa…

CVE-2026-39429
NVD

HIGH
CVE-2026-34045
CVE-2026-34045
pkg: kubernetes

published: Apr 7, 2026

Podman Desktop is a graphical tool for developing on containers and Kubernetes. Prior to 1.26.2, an unauthenticated HTTP server exposed by Podman Desktop allows any network attacker to remotely trigger denial-of-service conditions and extract sensitive information. By abusing missing connection limi…
CWE: CWE-209, CWE-284, CWE-400
NVD

HIGH
CVE-2026-4740
CVE-2026-4740
pkg: kubernetes

published: Apr 7, 2026

A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). Improper validation of Kubernetes client certificate renewal allows a managed cluster administrator to forge a client certificate that can be approved by the OCM controller. This e…
CWE: CWE-295
NVD

HIGH
CVE-2026-34982
CVE-2026-34982
pkg: express

published: Apr 6, 2026

Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The `complete`, `guitabtooltip` and `printheader` options are missing the `P_MLE` flag, allowing a modeline to be execu…
CWE: CWE-78
GitHub-GHSA

HIGH
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
GHSA-ffq7-898w-9jc4
pkg: DotNetNuke.Core
eco: nuget
published: Apr 10, 2026
A user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user.
GitHub-GHSA

HIGH
SiYuan: Publish Reader Can Arbitrarily Delete Attribute View Files via `/api/av/removeUnusedAttributeView`
GHSA-7m5h-w69j-qggg
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: Apr 10, 2026
## Summary

An authenticated publish-service reader can invoke `/api/av/removeUnusedAttributeView` and cause persistent deletion of arbitrary attribute view (`AV`) definition files from the workspace.

The route is protected only by generic `CheckAuth`, which accepts publish `RoleReader` requests. T…

CVE-2026-40259
GitHub-GHSA

HIGH
PraisonAI: Cross-Origin Agent Execution via Hardcoded Wildcard CORS and Missing Authentication on AGUI Endpoint
GHSA-x462-jjpc-q4q4
pkg: praisonaiagents
eco: pip
published: Apr 10, 2026
## Summary

The AGUI endpoint (`POST /agui`) has no authentication and hardcodes `Access-Control-Allow-Origin: *` on all responses. Combined with Starlette/FastAPI's Content-Type-agnostic JSON parsing, any website a victim visits can silently trigger arbitrary agent execution against a locally-runni…

NVD

HIGH
CVE-2021-47961
CVE-2021-47961
pkg: ssl

published: Apr 10, 2026

A plaintext storage of a password vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access or influence the user's PIN code due to insecure storage. This may lead to unauthorized VPN configuration and potential interception of subsequent VPN traffic when combined …
CWE: CWE-256
GitHub-GHSA

HIGH
bsv-sdk and bsv-wallet persist unverified certifier signatures in acquire_certificate (direct and issuance paths)
GHSA-hc36-c89j-5f4j
pkg: bsv-sdk, bsv-wallet
eco: rubygems
published: Apr 9, 2026
# Unverified certifier signatures persisted by `acquire_certificate`

## Affected packages

Both `bsv-sdk` and `bsv-wallet` are published from the [sgbett/bsv-ruby-sdk](https://github.com/sgbett/bsv-ruby-sdk) repository. The vulnerable code lives in `lib/bsv/wallet_interface/wallet_client.rb`, which…

CVE-2026-40070
GitHub-GHSA

HIGH
RedwoodSDK has a CSRF vulnerability in server function dispatch via GET requests
GHSA-x8rx-789c-2pxq
pkg: rwsdk
eco: npm
published: Apr 8, 2026
**Summary**

Server functions exported from `"use server"` files could be invoked via GET requests, bypassing their intended HTTP method. In cookie-authenticated applications, this allowed cross-site GET navigations to trigger state-changing functions, because browsers send `SameSite=Lax` cookies on…

CVE-2026-39371
GitHub-GHSA

HIGH
File Browser: Proxy auth auto-provisioned users inherit Execute permission and Commands
GHSA-7526-j432-6ppp
pkg: github.com/filebrowser/filebrowser/v2
eco: go
published: Apr 8, 2026
## Summary

The fix in commit `b6a4fb1` ("self-registered users don't get execute perms") stripped `Execute` permission and `Commands` from users created via the signup handler. The same fix was not applied to the proxy auth handler. Users auto-created on first successful proxy-auth login are grante…

CVE-2026-35607
NVD

HIGH
CVE-2026-39371
CVE-2026-39371
pkg: react

published: Apr 7, 2026

RedwoodSDK is a server-first React framework. From 1.0.0-beta.50 to 1.0.5, erver functions exported from "use server" files could be invoked via GET requests, bypassing their intended HTTP method. In cookie-authenticated applications, this allowed cross-site GET navigations to trigger state-changing…
CWE: CWE-352
GitHub-GHSA

HIGH
PraisonAI Has Arbitrary File Write (Zip Slip) in Templates Extraction
GHSA-4ph2-f6pf-79wv
pkg: PraisonAI
eco: pip
published: Apr 6, 2026
The PraisonAI templates installation feature is vulnerable to a "Zip Slip" Arbitrary File Write attack. When downloading and extracting template archives from external sources (e.g., GitHub), the application uses Python's `zipfile.extractall()` without verifying if the files within the archive resol…
CVE-2026-39307
GitHub-GHSA

HIGH
PraisonAI: Unauthenticated Allow-List Manipulation Bypasses Agent Tool Approval Safety Controls
GHSA-4wr3-f4p3-5wjh
pkg: PraisonAI
eco: pip
published: Apr 10, 2026
## Summary

The gateway's `/api/approval/allow-list` endpoint permits unauthenticated modification of the tool approval allowlist when no `auth_token` is configured (the default). By adding dangerous tool names (e.g., `shell_exec`, `file_write`) to the allowlist, an attacker can cause the `ExecAppro…

CVE-2026-40149
GitHub-GHSA

HIGH
PraisonAI Vulnerable to Implicit Execution of Arbitrary Code via Automatic `tools.py` Loading
GHSA-2g3w-cpc4-chr4
pkg: praisonai
eco: pip
published: Apr 10, 2026
PraisonAI automatically loads a file named `tools.py` from the current working directory to discover and register custom agent tools. This loading process uses `importlib.util.spec_from_file_location` and immediately executes module-level code via `spec.loader.exec_module()` **without explicit user …
CVE-2026-40156
GitHub-GHSA

HIGH
Fleet Affected by Local Privilege Escalation via Tcl Command Injection in Orbit
GHSA-rphv-h674-5hp2
pkg: github.com/fleetdm/fleet/v4
eco: go
published: Apr 8, 2026
## Summary

The Orbit agent's FileVault disk encryption key rotation flow on collects a local user's password via a GUI dialog and interpolates it directly into a Tcl/expect script executed via `exec.Command("expect", "-c", script)`. Because the password is inserted into Tcl brace-quoted `send {%s}`…

CVE-2026-27806
GitHub-GHSA

HIGH
OpenEXR has a signed 32-bit Overflow in PIZ Decoder Leads to OOB Read/Write
GHSA-588r-cr5c-w6hf
pkg: OpenEXR, OpenEXR, OpenEXR
eco: pip
published: Apr 8, 2026
## Summary

`internal_exr_undo_piz()` advances the working wavelet pointer with signed 32-bit arithmetic:

“`c
wavbuf += nx * ny * wcount;
“`

Because `nx`, `ny`, and `wcount` are `int`, a crafted EXR file can make this product overflow and wrap. The next channel then decodes from an incorrect add…

CVE-2026-34588
GitHub-GHSA

HIGH
Local settings bypass config trust checks
GHSA-436v-8fw5-4mj8
pkg: mise
eco: rust
published: Apr 7, 2026
### Summary

`mise` loads trust-control settings from a local project `.mise.toml` before the trust check runs. An attacker who can place a malicious `.mise.toml` in a repository can make that same file appear trusted and then reach dangerous directives such as `[env] _.source`, templates, hooks, or…

CVE-2026-35533
NVD

HIGH
CVE-2026-35021
CVE-2026-35021
pkg: express

published: Apr 6, 2026

Anthropic Claude Code CLI and Claude Agent SDK contain an OS command injection vulnerability in the prompt editor invocation utility that allows attackers to execute arbitrary commands by crafting malicious file paths. Attackers can inject shell metacharacters such as $() or backtick expressions int…
CWE: CWE-78
GitHub-GHSA

HIGH
goshs is Missing Write Protection for Parametric Data Values
GHSA-2943-crp8-38xx
pkg: github.com/patrickhener/goshs
eco: go
published: Apr 10, 2026
### Summary
The SFTP command rename sanitizes only the source path and not the destination, so it is possible to write outside of the root directory of the SFTP.

### Details

Here is the issue:
“`go
// helper.go:155-215
func cmdFile(root string, r *sftp.Request, ip string, sftpServer *SFTPServer)…

CVE-2026-40188
GitHub-GHSA

HIGH
PraisonAIAgents has SSRF and Local File Read via Unvalidated URLs in web_crawl Tool
GHSA-8f4v-xfm9-3244
pkg: praisonaiagents
eco: pip
published: Apr 10, 2026
## Summary

The `web_crawl()` function in `praisonaiagents/tools/web_crawl_tools.py` accepts arbitrary URLs from AI agents with zero validation. No scheme allowlisting, hostname/IP blocklisting, or private network checks are applied before fetching. This allows an attacker (or prompt injection in cr…

CVE-2026-40150
GitHub-GHSA

HIGH
MONAI: Unsafe functions lead to pickle deserialization rce
GHSA-89gg-p5r5-q6r4
pkg: monai
eco: pip
published: Apr 7, 2026
### Summary
The `algo_from_pickle` function in `monai/auto3dseg/utils.py` causes `pickle.loads(data_bytes)` to be executed, and it does not perform any validation on the input parameters. This ultimately leads to insecure deserialization and can result in code execution vulnerabilities.

### Details…

GitHub-GHSA

HIGH
Ech0: Scoped admin access tokens can bypass least-privilege controls on privileged endpoints, including backup export
GHSA-4h9q-p5j4-xvvh
pkg: github.com/lin-snow/ech0
eco: go
published: Apr 10, 2026
## Summary

Ech0 scoped access tokens do not reliably enforce least privilege: multiple privileged admin routes omit scope checks, and the backup export handler strips token scope metadata entirely, allowing a low-scope admin access token to reach broader admin functionality than intended.

## Impac…

GitHub-GHSA

HIGH
PraisonAI: Unauthenticated WebSocket Endpoint Proxies to Paid OpenAI Realtime API Without Rate Limits
GHSA-q5r4-47m9-5mc7
pkg: PraisonAI
eco: pip
published: Apr 10, 2026
## Summary

The `/media-stream` WebSocket endpoint in PraisonAI's call module accepts connections from any client without authentication or Twilio signature validation. Each connection opens an authenticated session to OpenAI's Realtime API using the server's API key. There are no limits on concurre…

CVE-2026-40116
GitHub-GHSA

HIGH
@vitejs/plugin-rsc has a Denial of Service with React Server Components
GHSA-v457-wxvj-p9w9
pkg: @vitejs/plugin-rsc
eco: npm
published: Apr 10, 2026
### Impact

`@vitejs/plugin-rsc` vendors `react-server-dom-webpack`, which contained a vulnerability in versions prior to 19.2.4. See details in React repository's advisory https://github.com/facebook/react/security/advisories/GHSA-479c-33wc-g2pg

### Patches

Upgrade immediately to `@vitejs/plugin-…

GitHub-GHSA

HIGH
Next.js has a Denial of Service with Server Components
GHSA-q4gf-8mx6-v5v3
pkg: next, next
eco: npm
published: Apr 10, 2026
A vulnerability affects certain React Server Components packages for versions 19.x and frameworks that use the affected packages, including Next.js 13.x, 14.x, 15.x, and 16.x using the App Router. The issue is tracked upstream as [CVE-2026-23869](https://github.com/facebook/react/security/advisories…
GitHub-GHSA

HIGH
React Server Components have a Denial of Service Vulnerability
GHSA-479c-33wc-g2pg
pkg: react-server-dom-parcel, react-server-dom-parcel, react-server-dom-parcel
eco: npm
published: Apr 10, 2026
## Impact

A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack versions 19.0.0, 19.1.0 and 19.2.0. The vulnerability is triggered by sending specially crafted HTTP request…

CVE-2026-23869
GitHub-GHSA

HIGH
Apache ActiveMQ: Denial of Service via Out of Memory vulnerability
GHSA-5568-6qcg-g7fx
pkg: org.apache.activemq:activemq-client, org.apache.activemq:activemq-client, org.apache.activemq:activemq-broker
eco: maven
published: Apr 10, 2026
Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ.

ActiveMQ NIO SSL transports do not correctly handle TLSv1.3 handshake KeyUpdates triggered by clients. This makes it possible for a client to rapidly trigger updates which causes th…

CVE-2026-39304
NVD

HIGH
CVE-2026-39304
CVE-2026-39304
pkg: ssl

published: Apr 10, 2026

Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ.

ActiveMQ NIO SSL transports do not correctly handle TLSv1.3 handshake KeyUpdates triggered by clients. This makes it possible for a client to rapidly trigger updates which causes th…

CWE: CWE-400
GitHub-GHSA

HIGH
Spring Cloud Gateway's SSL bundle configuration silently bypassed
GHSA-hwqh-2684-54fc
pkg: org.springframework.cloud:spring-cloud-gateway
eco: maven
published: Apr 10, 2026
When configuring SSL bundles in Spring Cloud Gateway by using the configuration property spring.ssl.bundle, the configuration was silently ignored and the default SSL configuration was used instead.
Note: The 4.2.x branch is no longer under open source support. If you are using Spring Cloud Gatew…
CVE-2026-22750
NVD

HIGH
CVE-2026-22750
CVE-2026-22750
pkg: ssl

published: Apr 10, 2026

When configuring SSL bundles in Spring Cloud Gateway by using the configuration property spring.ssl.bundle, the configuration was silently ignored and the default SSL configuration was used instead.
Note: The 4.2.x branch is no longer under open source support. If you are using Spring Cloud Gatew…
CWE: CWE-15
GitHub-GHSA

HIGH
Apache Tomcat Missing Encryption of Sensitive Data vulnerability
GHSA-69r9-qgr7-g2wj
pkg: org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat-catalina
eco: maven
published: Apr 9, 2026
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.

This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116.

Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the …

CVE-2026-34486
GitHub-GHSA

HIGH
Apache Tomcat has an Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve
GHSA-rv64-5gf8-9qq8
pkg: org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat-catalina
eco: maven
published: Apr 9, 2026
Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.40 through 9.0.116.

Users are recommended to upgrade to version 11.0.21, 10.1.54 or…

CVE-2026-34483
GitHub-GHSA

HIGH
Apache Tomcat vulnerable to Insertion of Sensitive Information into Log File
GHSA-x4m4-345f-5h5g
pkg: org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat-catalina
eco: maven
published: Apr 9, 2026
Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.13 through 9.0.116.

Users…

CVE-2026-34487
GitHub-GHSA

HIGH
Apache Tomcat: Configured cipher preference order not preserved
GHSA-69cc-cv78-qc8g
pkg: org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat-catalina
eco: maven
published: Apr 9, 2026
Configured cipher preference order not preserved vulnerability in Apache Tomcat.

This issue affects Apache Tomcat: from 11.0.16 through 11.0.18, from 10.1.51 through 10.1.52, from 9.0.114 through 9.0.115.

Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.

CVE-2026-29129
GitHub-GHSA

HIGH
Apache Tomcat: Padding Oracle vulnerability in EncryptInterceptor
GHSA-h468-7pvh-8vr8
pkg: org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat-catalina
eco: maven
published: Apr 9, 2026
Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109.

Users are recommen…

CVE-2026-29146
GitHub-GHSA

HIGH
Apache Tomcat has an HTTP Request/Response Smuggling vulnerability
GHSA-563x-q5rq-57qp
pkg: org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat-catalina
eco: maven
published: Apr 9, 2026
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M1 through 9.0.115, from 8.5.0 through 8.5.100, f…

CVE-2026-24880
GitHub-GHSA

HIGH
bsv-sdk ARC broadcaster treats INVALID/MALFORMED/ORPHAN responses as successful broadcasts
GHSA-9hfr-gw99-8rhx
pkg: bsv-sdk
eco: rubygems
published: Apr 9, 2026
# ARC broadcaster treats failure statuses as successful broadcasts

## Summary

`BSV::Network::ARC`'s failure detection only recognises `REJECTED` and `DOUBLE_SPEND_ATTEMPTED`. ARC responses with `txStatus` values of `INVALID`, `MALFORMED`, `MINED_IN_STALE_BLOCK`, or any `ORPHAN`-containing `extraIn…

CVE-2026-40069
NVD

HIGH
CVE-2026-34487
CVE-2026-34487
pkg: kubernetes

published: Apr 9, 2026

Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.13 through 9.0.116.

Users…

CWE: CWE-532
NVD

HIGH
CVE-2026-34486
CVE-2026-34486
pkg: apache

published: Apr 9, 2026

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.

This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116.

Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the …

CWE: CWE-311
NVD

HIGH
CVE-2026-34483
CVE-2026-34483
pkg: apache

published: Apr 9, 2026

Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.40 through 9.0.116.

Users are recommended to upgrade to version 11.0.21, 10.1.54 or…

CWE: CWE-116
NVD

HIGH
CVE-2026-29146
CVE-2026-29146
pkg: apache

published: Apr 9, 2026

Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109.

Users are recommen…

CWE: CWE-209, CWE-642
NVD

HIGH
CVE-2026-29129
CVE-2026-29129
pkg: apache

published: Apr 9, 2026

Configured cipher preference order not preserved vulnerability in Apache Tomcat.

This issue affects Apache Tomcat: from 11.0.16 through 11.0.18, from 10.1.51 through 10.1.52, from 9.0.114 through 9.0.115.

Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.

CWE: CWE-327
NVD

HIGH
CVE-2026-24880
CVE-2026-24880
pkg: apache

published: Apr 9, 2026

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M1 through 9.0.115, from 8.5.0 through 8.5.100, f…

CWE: CWE-444
GitHub-GHSA

HIGH
Apache OpenMeetings Uses GET Request Method With Sensitive Query Strings
GHSA-gcvm-c75m-h4p4
pkg: org.apache.openmeetings:openmeetings-parent
eco: maven
published: Apr 9, 2026
Use of GET Request Method With Sensitive Query Strings vulnerability in Apache OpenMeetings.

The REST login endpoint uses HTTP GET method with username and password passed as query parameters. Please check references regarding possible impact

This issue affects Apache OpenMeetings: from 3.1.3 be…

CVE-2026-34020
GitHub-GHSA

HIGH
Apache OpenMeetings Uses Hard-coded Cryptographic Key
GHSA-wqxq-w68r-wg85
pkg: org.apache.openmeetings:openmeetings-parent
eco: maven
published: Apr 9, 2026
Use of Hard-coded Cryptographic Key vulnerability in Apache OpenMeetings.

The remember-me cookie encryption key is set to default value in openmeetings.properties and not being auto-rotated. In case OM admin hasn't changed the default encryption key, an attacker who has stolen a cookie from a logge…

CVE-2026-33266
NVD

HIGH
CVE-2026-1584
CVE-2026-1584
pkg: tls

published: Apr 9, 2026

A flaw was found in gnutls. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted ClientHello message with an invalid Pre-Shared Key (PSK) binder value during the TLS handshake. This can lead to a NULL pointer dereference, causing the server to crash and re…
CWE: CWE-476
NVD

HIGH
CVE-2026-40046
CVE-2026-40046
pkg: apache

published: Apr 9, 2026

Integer Overflow or Wraparound vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT.

The fix for "CVE-2025-66168: MQTT control packet remaining length field is not properly validated" was only applied to 5.19.2 (and future 5.19.x) releases but was missed for all 6.0.0+ versio…

CWE: CWE-190
NVD

HIGH
CVE-2026-34020
CVE-2026-34020
pkg: apache

published: Apr 9, 2026

Use of GET Request Method With Sensitive Query Strings vulnerability in Apache OpenMeetings.

The REST login endpoint uses HTTP GET method with username and password passed as query parameters. Please check references regarding possible impact

This issue affects Apache OpenMeetings: from 3.1.3 be…

CWE: CWE-598
NVD

HIGH
CVE-2026-33266
CVE-2026-33266
pkg: apache

published: Apr 9, 2026

Use of Hard-coded Cryptographic Key vulnerability in Apache OpenMeetings.

The remember-me cookie encryption key is set to default value in openmeetings.properties and not being auto-rotated. In case OM admin hasn't changed the default encryption key, an attacker who has stolen a cookie from a logge…

CWE: CWE-321
GitHub-GHSA

HIGH
HashiCorp's go-getter library may allow arbitrary file reads
GHSA-92mm-2pjq-r785
pkg: github.com/hashicorp/go-getter
eco: go
published: Apr 9, 2026
HashiCorp's go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously crafted URL. This is fixed in go-getter v1.8.6. This vulnerability does not affect the go-getter/v2 branch and package.
CVE-2026-4660
GitHub-GHSA

HIGH
Apache DolphinScheduler vulnerable to sensitive information disclosure
GHSA-3cjc-vhfm-ffp2
pkg: org.apache.dolphinscheduler:dolphinscheduler
eco: maven
published: Apr 9, 2026
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Apache DolphinScheduler.

This vulnerability may allow unauthorized actors to access sensitive information, including database credentials.

This issue affects Apache DolphinScheduler versions 3.1.*.

Users are r…

CVE-2025-62188
NVD

HIGH
CVE-2025-62188
CVE-2025-62188
pkg: apache

published: Apr 9, 2026

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Apache DolphinScheduler.

This vulnerability may allow unauthorized actors to access sensitive information, including database credentials.

This issue affects Apache DolphinScheduler versions 3.1.*.

Users are r…

CWE: CWE-200
GitHub-GHSA

HIGH
Duplicate Advisory: Unfurl's unbounded zlib decompression allows decompression bomb DoS
GHSA-c3f2-qg8v-25q2
pkg: dfir-unfurl
eco: pip
published: Apr 9, 2026
### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-h5qv-qjv4-pc5m. This link is maintained to preserve external references.

### Original Description
Unfurl before 2026.04 contains an unbounded zlib decompression vulnerability in parse_compressed.py that allow…

NVD

HIGH
CVE-2026-39863
CVE-2026-39863
pkg: tls

published: Apr 8, 2026

Kamailio is an open source implementation of a SIP Signaling Server. Prior to 6.1.1, 6.0.6, and 5.8.8, an out-of-bounds access in the core of Kamailio (formerly OpenSER and SER) allows remote attackers to cause a denial of service (process crash) via a specially crafted data packet sent over TCP. Th…
CWE: CWE-119
NVD

HIGH
CVE-2026-23869
CVE-2026-23869
pkg: react

published: Apr 8, 2026

A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack and react-server-dom-webpack (versions 19.0.0 through 19.0.4, 19.1.0 through 19.1.5, and 19.2.0 through 19.2.4). The vulnerability is triggered b…
CWE: CWE-400, CWE-502
GitHub-GHSA

HIGH
mcp-from-openapi is Vulnerable to SSRF via $ref Dereferencing in Untrusted OpenAPI Specifications
GHSA-v6ph-xcq9-qxxj
pkg: mcp-from-openapi, @frontmcp/sdk, @frontmcp/adapters
eco: npm
published: Apr 8, 2026
## Summary

The `mcp-from-openapi` library uses `@apidevtools/json-schema-ref-parser` to dereference `$ref` pointers in OpenAPI specifications without configuring any URL restrictions or custom resolvers. A malicious OpenAPI specification containing `$ref` values pointing to internal network address…

CVE-2026-39885
GitHub-GHSA

HIGH
PraisonAI Has Unauthenticated SSE Event Stream that Exposes All Agent Activity in A2U Server
GHSA-f292-66h9-fpmf
pkg: praisonai
eco: pip
published: Apr 8, 2026
The A2U (Agent-to-User) event stream server in PraisonAI exposes all agent activity without authentication. This is a separate component from the gateway server fixed in CVE-2026-34952.

The create_a2u_routes() function registers the following endpoints with NO authentication checks:
– GET /a2u/inf…

CVE-2026-39889
GitHub-GHSA

HIGH
LiquidJS: Root restriction bypass for partial and layout loading through symlinked templates
GHSA-56p5-8mhr-2fph
pkg: liquidjs
eco: npm
published: Apr 8, 2026
### Summary

LiquidJS enforces partial and layout root restrictions using the resolved pathname string, but it does not resolve the canonical filesystem path before opening the file. A symlink placed inside an allowed partials or layouts directory can therefore point to a file outside that directory…

CVE-2026-35525
GitHub-GHSA

HIGH
Drizzle ORM has SQL injection via improperly escaped SQL identifiers
GHSA-gpj5-g38j-94v9
pkg: drizzle-orm, drizzle-orm
eco: npm
published: Apr 8, 2026
### Summary

Drizzle ORM improperly escaped quoted SQL identifiers in its dialect-specific `escapeName()` implementations. In affected versions, embedded identifier delimiters were not escaped before the identifier was wrapped in quotes or backticks.

As a result, applications that pass attacker-con…

CVE-2026-39356
GitHub-GHSA

HIGH
FastFeedParser has an infinite redirect loop DoS via meta-refresh chain
GHSA-4gx2-pc4f-wq37
pkg: fastfeedparser
eco: pip
published: Apr 8, 2026
### Summary
When `parse()` fetches a URL that returns an HTML page containing a `<meta http-equiv="refresh">` tag, it recursively calls itself with the redirect URL — with no depth limit, no visited-URL deduplication, and no redirect count cap. An attacker-controlled server that returns an infinit…
CVE-2026-39376
GitHub-GHSA

HIGH
Addressable has a Regular Expression Denial of Service in Addressable templates
GHSA-h27x-rffw-24p4
pkg: addressable
eco: rubygems
published: Apr 8, 2026
### Impact

Within the URI template implementation in Addressable, two classes of URI template generate regular expressions vulnerable to catastrophic backtracking:

1. Templates using the `*` (explode) modifier with any expansion operator (e.g., `{foo*}`, `{+var*}`, `{#var*}`, `{/var*}`, `{.var*}`,…

CVE-2026-35611
NVD

HIGH
CVE-2026-28390
CVE-2026-28390
pkg: openssl

published: Apr 7, 2026

Issue summary: During processing of a crafted CMS EnvelopedData message
with KeyTransportRecipientInfo a NULL pointer dereference can happen.

Impact summary: Applications that process attacker-controlled CMS data may
crash before authentication or cryptographic operations occur resulting in
Denial …

CWE: CWE-476
NVD

HIGH
CVE-2026-28389
CVE-2026-28389
pkg: openssl

published: Apr 7, 2026

Issue summary: During processing of a crafted CMS EnvelopedData message
with KeyAgreeRecipientInfo a NULL pointer dereference can happen.

Impact summary: Applications that process attacker-controlled CMS data may
crash before authentication or cryptographic operations occur resulting in
Denial of S…

CWE: CWE-476
NVD

HIGH
CVE-2026-28388
CVE-2026-28388
pkg: openssl

published: Apr 7, 2026

Issue summary: When a delta CRL that contains a Delta CRL Indicator extension
is processed a NULL pointer dereference might happen if the required CRL
Number extension is missing.

Impact summary: A NULL pointer dereference can trigger a crash which
leads to a Denial of Service for an application.

CWE: CWE-476
GitHub-GHSA

HIGH
GenieACS has an unauthenticated access vulnerability via the NBI API endpoint
GHSA-2h6j-mhcp-9j9h
pkg: genieacs
eco: npm
published: Apr 7, 2026
In GenieACS 1.2.13, an unauthenticated access vulnerability exists in the NBI API endpoint.
CVE-2025-56015
GitHub-GHSA

HIGH
OpenTelemetry-Go: multi-value `baggage` header extraction causes excessive allocations (remote dos amplification)
GHSA-mh2q-q3fh-2475
pkg: go.opentelemetry.io/otel/baggage, go.opentelemetry.io/otel/propagation
eco: go
published: Apr 7, 2026
multi-value `baggage:` header extraction parses each header field-value independently and aggregates members across values. this allows an attacker to amplify cpu and allocations by sending many `baggage:` header lines, even when each individual value is within the 8192-byte per-value parse limit.

CVE-2026-29181
NVD

HIGH
CVE-2026-35611
CVE-2026-35611
pkg: express

published: Apr 7, 2026

Addressable is an alternative implementation to the URI implementation that is part of Ruby's standard library. From 2.3.0 to before 2.9.0, within the URI template implementation in Addressable, two classes of URI template generate regular expressions vulnerable to catastrophic backtracking. Templat…
CWE: CWE-1333
GitHub-GHSA

HIGH
Django vulnerable to ASGI header spoofing via underscore/hyphen conflation
GHSA-mvfq-ggxm-9mc5
pkg: Django, Django, Django
eco: pip
published: Apr 7, 2026
An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `ASGIRequest` allows a remote attacker to spoof headers by exploiting an ambiguous mapping of two header variants (with hyphens or with underscores) to a single version with underscores.

Earlier, unsupported Djan…

CVE-2026-3902
GitHub-GHSA

HIGH
Django: SGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit
GHSA-933h-hp56-hf7m
pkg: Django, Django, Django
eco: pip
published: Apr 7, 2026
An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. ASGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit when reading `HttpRequest.body`, allowing remote attackers to load an unbounded request body…
CVE-2026-33034
NVD

HIGH
CVE-2026-3902
CVE-2026-3902
pkg: django

published: Apr 7, 2026

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30.
`ASGIRequest` allows a remote attacker to spoof headers by exploiting an ambiguous mapping of two header variants (with hyphens or with underscores) to a single version with underscores.
Earlier, unsupported Djang…
CWE: CWE-290
NVD

HIGH
CVE-2026-35464
CVE-2026-35464
pkg: flask

published: Apr 7, 2026

pyLoad is a free and open-source download manager written in Python. The fix for CVE-2026-33509 added an ADMIN_ONLY_OPTIONS set to block non-admin users from modifying security-critical config options. The storage_folder option is not in this set and passes the existing path restriction because the …
CWE: CWE-502, CWE-863
NVD

HIGH
CVE-2026-33034
CVE-2026-33034
pkg: django

published: Apr 7, 2026

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30.
ASGI requests with a missing or understated `Content-Length` header could
bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit when reading
`HttpRequest.body`, allowing remote attackers to load an unbounded request bo…
CWE: CWE-770
NVD

HIGH
CVE-2026-31842
CVE-2026-31842
pkg: nginx

published: Apr 7, 2026

Tinyproxy through 1.11.3 is vulnerable to HTTP request parsing desynchronization due to a case-sensitive comparison of the Transfer-Encoding header in src/reqs.c. The is_chunked_transfer() function uses strcmp() to compare the header value against "chunked", even though RFC 7230 specifies that trans…
CWE: CWE-444
GitHub-GHSA

HIGH
strawberry-graphql: Denial of Service via unbounded WebSocket subscriptions
GHSA-hv3w-m4g2-5×77
pkg: strawberry-graphql
eco: pip
published: Apr 6, 2026
Strawberry GraphQL's WebSocket subscription handlers for both the `graphql-transport-ws` and legacy `graphql-ws` protocols allocate an `asyncio.Task` and associated `Operation` object for every incoming subscribe message without enforcing any limit on the number of active subscriptions per connectio…
CVE-2026-35526
GitHub-GHSA

HIGH
strawberry-graphql: Authentication bypass via legacy graphql-ws WebSocket subprotocol
GHSA-vpwc-v33q-mq89
pkg: strawberry-graphql
eco: pip
published: Apr 6, 2026
Strawberry up until version `0.312.3` is vulnerable to an authentication bypass on WebSocket subscription endpoints. The legacy graphql-ws subprotocol handler does not verify that a `connection_init` handshake has been completed before processing start (subscription) messages. This allows a remote a…
CVE-2026-35523
GitHub-GHSA

HIGH
Distribution: stale blob access resurrection via repo-scoped redis descriptor cache invalidation
GHSA-f2g3-hh2r-cwgc
pkg: github.com/distribution/distribution/v3, github.com/distribution/distribution
eco: go
published: Apr 6, 2026
## summary:
distribution can restore read access in `repo a` after an explicit delete when `storage.cache.blobdescriptor: redis` and `storage.delete.enabled: true` are both enabled. the delete path clears the shared digest descriptor but leaves stale repo-scoped membership behind, so a later `Stat` …
CVE-2026-35172
GitHub-GHSA

HIGH
Distribution affected by pull-through cache credential exfiltration via www-authenticate bearer realm
GHSA-3p65-76g6-3w7r
pkg: github.com/distribution/distribution/v3, github.com/distribution/distribution
eco: go
published: Apr 6, 2026
hi guys,

commit: 40594bd98e6d6ed993b5c6021c93fdf96d2e5851 (as-of 2026-01-31)
contact: GitHub Security Advisory (https://github.com/distribution/distribution/security/advisories/new)

## summary

in pull-through cache mode, distribution discovers token auth endpoints by parsing `WWW-Authenticate` ch…

CVE-2026-33540
NVD

HIGH
CVE-2026-34211
CVE-2026-34211
pkg: nyariv sandboxjs

published: Apr 6, 2026

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, the @nyariv/sandboxjs parser contains unbounded recursion in the restOfExp function and the lispify/lispifyExpr call chain. An attacker can crash any Node.js process that parses untrusted input by supplying deeply nested expressions (e.g…
CWE: CWE-674
GitHub-GHSA

HIGH
PraisonAIAgents: Environment Variable Secret Exfiltration via os.path.expandvars() Bypassing shell=False in Shell Tool
GHSA-v8g7-9q6v-p3x8
pkg: praisonaiagents
eco: pip
published: Apr 10, 2026
## Summary

The `execute_command` function in `shell_tools.py` calls `os.path.expandvars()` on every command argument at line 64, manually re-implementing shell-level environment variable expansion despite using `shell=False` (line 88) for security. This allows exfiltration of secrets stored in envi…

CVE-2026-40153
NVD

HIGH
CVE-2026-34727
CVE-2026-34727
pkg: jwt

published: Apr 10, 2026

Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the OIDC callback handler issues a full JWT token without checking whether the matched user has TOTP two-factor authentication enabled. When a local user with TOTP enrolled is matched via the OIDC email fallback mechanis…
CWE: CWE-287
GitHub-GHSA

HIGH
Vikunja has TOTP Two-Factor Authentication Bypass via OIDC Login Path
GHSA-8jvc-mcx6-r4cg
pkg: code.vikunja.io/api
eco: go
published: Apr 10, 2026
## Summary

The OIDC callback handler issues a full JWT token without checking whether the matched user has TOTP two-factor authentication enabled. When a local user with TOTP enrolled is matched via the OIDC email fallback mechanism, the second factor is completely skipped.

## Details

The OIDC ca…

CVE-2026-34727
GitHub-GHSA

HIGH
Eclipse Jetty: Early return from the JASPIAuthenticator code can potentially no clear ThreadLocal variables
GHSA-gc59-r5jq-98qw
pkg: org.eclipse.jetty.ee10:jetty-ee10, org.eclipse.jetty.ee10:jetty-ee10, org.eclipse.jetty.ee10:jetty-ee10
eco: maven
published: Apr 8, 2026
In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable.

Upon returning from the initial checks, there are conditions that cause an early return from the JASPIAuthenticator code without clearing those ThreadLocals.

A subsequent reque…

CVE-2026-5795
NVD

HIGH
CVE-2026-4158
CVE-2026-4158
pkg: openssl

published: Apr 11, 2026

KeePassXC OpenSSL Configuration Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of KeePassXC. An attacker must first obtain the ability to execute low-privileged code on the target s…
CWE: CWE-427
NVD

HIGH
CVE-2026-5974
CVE-2026-5974
pkg: react

published: Apr 9, 2026

A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the probl…
CWE: CWE-77, CWE-78
NVD

HIGH
CVE-2026-5973
CVE-2026-5973
pkg: react

published: Apr 9, 2026

A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file metagpt/utils/common.py. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. The project was in…
CWE: CWE-77, CWE-78
NVD

HIGH
CVE-2026-5971
CVE-2026-5971
pkg: react

published: Apr 9, 2026

A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fill of the file metagpt/actions/action_node.py of the component XML Handler. Executing a manipulation can lead to improper neutralization of directives in dynamically evaluated code…
CWE: CWE-94, CWE-95
NVD

HIGH
CVE-2026-5970
CVE-2026-5970
pkg: react

published: Apr 9, 2026

A vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the component HumanEvalBenchmark/MBPPBenchmark. Performing a manipulation results in code injection. The attack may be initiated remotely. The exploit is now public and may be used. The …
CWE: CWE-74, CWE-94
NVD

HIGH
CVE-2026-5741
CVE-2026-5741
pkg: docker

published: Apr 7, 2026

A weakness has been identified in suvarchal docker-mcp-server up to 0.1.0. The impacted element is the function stop_container/remove_container/pull_image of the file src/index.ts of the component HTTP Interface. This manipulation causes os command injection. The attack is possible to be carried out…
CWE: CWE-77, CWE-78
GitHub-GHSA

HIGH
PraisonAI recipe registry pull path traversal writes files outside the chosen output directory
GHSA-4rx4-4r3x-6534
pkg: PraisonAI
eco: pip
published: Apr 6, 2026
### Summary

PraisonAI's recipe registry pull flow extracts attacker-controlled `.praison` tar archives with `tar.extractall()` and does not validate archive member paths before extraction. A malicious publisher can upload a recipe bundle that contains `../` traversal entries and any user who later …

CVE-2026-39306
GitHub-GHSA

HIGH
Authorizer: CQL/N1QL Injection in Cassandra and Couchbase Backends via fmt.Sprintf String Interpolation
GHSA-jfwg-rxf3-p7r9
pkg: github.com/authorizerdev/authorizer
eco: go
published: Apr 6, 2026
## Vulnerability Details

**CWE:** CWE-943 – Improper Neutralization of Special Elements in Data Query Logic

All 66+ CQL queries in `internal/storage/db/cassandradb/` use `fmt.Sprintf` to interpolate user-controlled values directly into CQL query strings without parameterization.

Unauthenticated e…

NVD

HIGH
CVE-2026-5577
CVE-2026-5577
pkg: flask

published: Apr 5, 2026

A vulnerability has been found in Song-Li cross_browser up to ca690f0fe6954fd9bcda36d071b68ed8682a786a. This affects an unknown part of the file flask/uniquemachine_app.py of the component details Endpoint. Such manipulation of the argument ID leads to sql injection. The attack can be executed remot…
CWE: CWE-74, CWE-89
NVD

HIGH
CVE-2026-40242
CVE-2026-40242
pkg: docker

published: Apr 10, 2026

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.17.3, the /api/templates/fetch endpoint accepts a caller-supplied url parameter and performs a server-side HTTP GET request to that URL without authentication and without URL scheme or host validation. T…
CWE: CWE-918
GitHub-GHSA

HIGH
Arcane has Unauthenticated SSRF with Conditional Response Reflection in Template Fetch Endpoint
GHSA-ff24-4prj-gpmj
pkg: github.com/getarcaneapp/arcane/backend
eco: go
published: Apr 10, 2026
### Summary
The /api/templates/fetch endpoint accepts a caller-supplied url parameter and performs a server-side HTTP GET request to that URL without authentication and without URL scheme or host validation. The server's response is returned directly to the caller. type. This constitutes an unauthen…
CVE-2026-40242
GitHub-GHSA

HIGH
PraisonAI Vulnerable to Server-Side Request Forgery via Unvalidated webhook_url in Jobs API
GHSA-8frj-8q3m-xhgm
pkg: PraisonAI
eco: pip
published: Apr 10, 2026
## Summary

The `/api/v1/runs` endpoint accepts an arbitrary `webhook_url` in the request body with no URL validation. When a submitted job completes (success or failure), the server makes an HTTP POST request to this URL using `httpx.AsyncClient`. An unauthenticated attacker can use this to make th…

CVE-2026-40114
GitHub-GHSA

HIGH
Emissary has a Command Injection via PLACE_NAME Configuration in Executrix
GHSA-6c37-7w4p-jg9v
pkg: gov.nsa.emissary:emissary
eco: maven
published: Apr 8, 2026
## Summary

The `Executrix` utility class constructed shell commands by concatenating
configuration-derived values — including the `PLACE_NAME` parameter — with
insufficient sanitization. Only spaces were replaced with underscores, allowing
shell metacharacters (`;`, `|`, `$`, “ ` “, `(`, `)`,…

CVE-2026-35581
GitHub-GHSA

HIGH
Bugsink affected by authenticated arbitrary file write in artifactbundle/assemble
GHSA-8hw4-fhww-273g
pkg: bugsink
eco: pip
published: Apr 10, 2026
# Authenticated arbitrary file write in artifact bundle assembly

## Summary

An authenticated file write vulnerability was identified in Bugsink **2.1.0** in the artifact bundle assembly flow.

A user with a valid authentication token could cause the application to write attacker-controlled content…

CVE-2026-40162
NVD

HIGH
CVE-2026-33704
CVE-2026-33704
pkg: apache

published: Apr 10, 2026

Chamilo LMS is a learning management system. Prior to 1.11.38, any authenticated user (including students) can write arbitrary content to files on the server via the BigUpload endpoint. The key parameter controls the filename and the raw POST body becomes the file content. While .php extensions are …
CWE: CWE-434
NVD

HIGH
CVE-2026-39976
CVE-2026-39976
pkg: jwt

published: Apr 9, 2026

Laravel Passport provides OAuth2 server support to Laravel. From 13.0.0 to before 13.7.1, there is an Authentication Bypass for client_credentials tokens. the league/oauth2-server library sets the JWT sub claim to the client identifier (since there's no user). The token guard then passes this value …
CWE: CWE-287
GitHub-GHSA

HIGH
Tmds.DBus: malicious D-Bus peers can spoof signals, exhaust file descriptor resources, and cause denial of service
GHSA-xrw6-gwf8-vvr9
pkg: Tmds.DBus, Tmds.DBus.Protocol, Tmds.DBus.Protocol
eco: nuget
published: Apr 8, 2026
Tmds.DBus and Tmds.DBus.Protocol are vulnerable to malicious D-Bus peers. A peer on the same bus can spoof signals by impersonating the owner of a well-known name, exhaust system resources or cause file descriptor spillover by sending messages with an excessive number of Unix file descriptors, and c…
CVE-2026-39959
GitHub-GHSA

HIGH
PraisonAI recipe registry publish path traversal allows out-of-root file write
GHSA-r9x3-wx45-2v7f
pkg: PraisonAI
eco: pip
published: Apr 6, 2026
### Summary

PraisonAI's recipe registry publish endpoint writes uploaded recipe bundles to a filesystem path derived from the bundle's internal `manifest.json` before it verifies that the manifest `name` and `version` match the HTTP route. A malicious publisher can place `../` traversal sequences i…

CVE-2026-39308
GitHub-GHSA

HIGH
Duplicate Advisory: OpenClaw: Plivo V2 verified replay identity drifts on query-only variants
GHSA-j56c-wpqm-h24x
pkg: openclaw
eco: npm
published: Apr 10, 2026
### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-cg6c-q2hx-69h7. This link is maintained to preserve external references.

### Original Description
OpenClaw before 2026.3.23 contains a replay identity vulnerability in Plivo V2 signature verification that allo…

GitHub-GHSA

HIGH
Duplicate Advisory: OpenClaw: `fetchWithSsrFGuard` replays unsafe request bodies across cross-origin redirects
GHSA-pg8g-f2hf-x82m
pkg: openclaw
eco: npm
published: Apr 9, 2026
### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-qx8j-g322-qj6m. This link is maintained to preserve external references.

### Original Description
OpenClaw before 2026.3.31 (patched in 2026.4.8) contains a request body replay vulnerability in fetchWithSsrFGu…

GitHub-GHSA

HIGH
OpenEXR: DWA Lossy Decoder Heap Out-of-Bounds Write
GHSA-p8xc-w3q4-h64x
pkg: OpenEXR, OpenEXR, OpenEXR
eco: pip
published: Apr 8, 2026
## Summary

The DWA lossy decoder constructs temporary per-component block pointers using signed 32-bit arithmetic. For a large enough width, the calculation overflows and later decoder stores operate on a wrapped pointer outside the allocated `rowBlock` backing store.

This bug is reachable from th…

CVE-2026-34589
GitHub-GHSA

HIGH
PraisonAIAgents: SSRF via unvalidated URL in `web_crawl` httpx fallback
GHSA-qq9r-63f6-v542
pkg: praisonaiagents
eco: pip
published: Apr 10, 2026
| Field | Value |
|—|—|
| Severity | High |
| Type | SSRF — unvalidated URL in `web_crawl` httpx fallback allows internal network access |
| Affected | `src/praisonai-agents/praisonaiagents/tools/web_crawl_tools.py:133-180` |

## Summary

`web_crawl`'s httpx fallback path passes user-supplied U…

CVE-2026-40160
GitHub-GHSA

HIGH
SiYuan Affected by Zero-Click NTLM Hash Theft and Blind SSRF via Mermaid Diagram Rendering
GHSA-w95v-4h65-j455
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: Apr 10, 2026
SiYuan configures Mermaid.js with `securityLevel: "loose"` and `htmlLabels: true`. In this mode, `<img>` tags with `src` attributes survive Mermaid's internal DOMPurify and land in SVG `<foreignObject>` blocks. The SVG is injected via `innerHTML` with no secondary sanitization. When a victim opens a…
CVE-2026-40107
GitHub-GHSA

HIGH
@sveltejs/adapter-node has a BODY_SIZE_LIMIT bypass
GHSA-2crg-3p73-43xp
pkg: @sveltejs/kit
eco: npm
published: Apr 10, 2026
Under certain circumstances, requests could bypass the `BODY_SIZE_LIMIT` on SvelteKit applications running with `adapter-node`. This bypass does not affect body size limits at other layers of the application stack, so limits enforced in the WAF, gateway, or at the platform level are unaffected.
CVE-2026-40073
GitHub-GHSA

HIGH
Helm's plugin verification fails open when .prov is missing, allowing unsigned plugin install
GHSA-q5jf-9vfq-h4h7
pkg: helm.sh/helm/v4
eco: go
published: Apr 10, 2026
Helm is a package manager for Charts for Kubernetes. In Helm versions >=4.0.0 and <=4.1.3, Helm will install plugins missing provenance (`.prov` file) when signature verification is required.

### Impact

The bug allows plugin authors to omit provenance (signing) data from plugins, bypassing plugin …

CVE-2026-35205
GitHub-GHSA

HIGH
Helm has a path traversal in plugin metadata version enables arbitrary file write outside Helm plugin directory
GHSA-vmx8-mqv2-9gmg
pkg: helm.sh/helm/v4
eco: go
published: Apr 10, 2026
Helm is a package manager for Charts for Kubernetes. In Helm versions >=4.0.0 and <=4.1.3, a specially crafted Helm plugin, when installed or updated, will cause Helm to write the contents of the plugin to an arbitrary filesystem location.

### Impact

A Helm user who installs or updates a plugin th…

CVE-2026-35204
GitHub-GHSA

HIGH
OpenClaw: `fetchWithSsrFGuard` replays unsafe request bodies across cross-origin redirects
GHSA-qx8j-g322-qj6m
pkg: openclaw
eco: npm
published: Apr 9, 2026
## Impact

`fetchWithSsrFGuard` replays unsafe request bodies across cross-origin redirects.

A guarded fetch could resend unsafe request bodies or headers when following cross-origin redirects.

OpenClaw is a user-controlled local assistant. This advisory is scoped to the OpenClaw trust model and d…

CVE-2026-40037
GitHub-GHSA

HIGH
OpenClaw: Node Pairing Reconnect Command Escalation Bypasses operator.admin Scope Requirement
GHSA-5wj5-87vq-39xm
pkg: openclaw
eco: npm
published: Apr 9, 2026
## Impact

Node Pairing Reconnect Command Escalation Bypasses operator.admin Scope Requirement.

A previously paired node could reconnect with a broader command set, including exec-capable commands, without forcing the operator/admin re-pairing path.

OpenClaw is a user-controlled local assistant. T…

GitHub-GHSA

HIGH
MinIO affected a DoS via Unbounded Memory Allocation in S3 Select CSV Parsing
GHSA-h749-fxx7-pwpg
pkg: github.com/minio/minio
eco: go
published: Apr 9, 2026
### Impact

_What kind of vulnerability is it? Who is impacted?_

MinIO's S3 Select feature is vulnerable to memory exhaustion when processing CSV
files containing lines longer than available memory. The CSV reader's `nextSplit()`
function calls `bufio.Reader.ReadBytes('\n')` with no size limit, b…

CVE-2026-39414
GitHub-GHSA

HIGH
OpenClaw: HGRCPATH, CARGO_BUILD_RUSTC_WRAPPER, RUSTC_WRAPPER, and MAKEFLAGS missing from exec env denylist — RCE via build tool env injection (GHSA-cm8v-2vh9-cxf3 class)
GHSA-7437-7hg8-frrw
pkg: openclaw
eco: npm
published: Apr 9, 2026
## Impact

HGRCPATH, CARGO_BUILD_RUSTC_WRAPPER, RUSTC_WRAPPER, and MAKEFLAGS missing from exec env denylist — RCE via build tool env injection (GHSA-cm8v-2vh9-cxf3 class).

Missing denylist entries allowed hostile build-tool environment variables to influence host exec commands.

OpenClaw is a use…

GitHub-GHSA

HIGH
OpenClaw: Authenticated `/hooks/wake` and mapped `wake` payloads are promoted into the trusted `System:` prompt channel
GHSA-jf56-mccx-5f3f
pkg: openclaw
eco: npm
published: Apr 9, 2026
## Impact

Authenticated `/hooks/wake` and mapped `wake` payloads are promoted into the trusted `System:` prompt channel.

An authenticated wake hook or mapped wake payload could be promoted into the trusted System prompt channel instead of an untrusted event.

OpenClaw is a user-controlled local as…

GitHub-GHSA

HIGH
OpenClaw: Lower-trust background runtime output is injected into trusted `System:` events, and local async exec completion misses the intended `exec-event` downgrade
GHSA-gfmx-pph7-g46x
pkg: openclaw
eco: npm
published: Apr 9, 2026
## Impact

Lower-trust background runtime output is injected into trusted `System:` events, and local async exec completion misses the intended `exec-event` downgrade.

Lower-trust runtime/background output could be promoted into trusted System events, allowing prompt-injection into later agent turn…

GitHub-GHSA

HIGH
Pretext: Algorithmic Complexity (DoS) in the text analysis phase
GHSA-5478-66c3-rhxr
pkg: @chenglou/pretext
eco: npm
published: Apr 8, 2026
`isRepeatedSingleCharRun()` in `src/analysis.ts` (line 285) re-scans the entire accumulated segment on every merge iteration during text analysis, producing O(n²) total work for input consisting of repeated identical punctuation characters. An attacker who controls text passed to `prepare()` can bl…
GitHub-GHSA

HIGH
mercure has Topic Selector Cache Key Collision
GHSA-hwr4-mq23-wcv5
pkg: github.com/dunglas/mercure
eco: go
published: Apr 8, 2026
### Impact

A cache key collision vulnerability in `TopicSelectorStore` allows an attacker to poison the match result cache, potentially causing private updates to be delivered to unauthorized subscribers or blocking delivery to authorized ones.

The cache key was constructed by concatenating the to…

CVE-2026-39972
GitHub-GHSA

HIGH
opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking
GHSA-hfvc-g4fc-pqhx
pkg: go.opentelemetry.io/otel/sdk
eco: go
published: Apr 8, 2026
## Summary

The fix for GHSA-9h8m-3fm2-qjrq (CVE-2026-24051) changed the Darwin `ioreg` command to use an absolute path but left the BSD `kenv` command using a bare name, allowing the same PATH hijacking attack on BSD and Solaris platforms.

## Root Cause

`sdk/resource/host_id.go` line 42:

if …

CVE-2026-39883
GitHub-GHSA

HIGH
stata-mcp has insufficient validation of user-supplied Stata do-file content that can lead to command execution
GHSA-jpcj-7wfg-mqxv
pkg: stata-mcp
eco: pip
published: Apr 8, 2026
A vulnerability was identified in stata-mcp prior to v1.13.0 where insufficient validation of user-supplied Stata do-file content can lead to command execution.
CVE-2026-31040
GitHub-GHSA

HIGH
XWiki vulnerable to remote code execution with script right through unprotected Velocity scripting API
GHSA-h259-74h5-4rh9
pkg: org.xwiki.platform:xwiki-platform-oldcore, org.xwiki.platform:xwiki-platform-oldcore, org.xwiki.platform:xwiki-platform-legacy-oldcore
eco: maven
published: Apr 8, 2026
### Impact
An improperly protected scripting API allows any user with script right to bypass the sandboxing of the Velocity scripting API and execute, e.g., arbitrary Python scripts, allowing full access to the XWiki instance and thereby compromising the confidentiality, integrity and availability o…
CVE-2026-33229
GitHub-GHSA

HIGH
File Browser share links remain accessible after Share/Download permissions are revoked
GHSA-v9w4-gm2x-6rvf
pkg: github.com/filebrowser/filebrowser/v2
eco: go
published: Apr 8, 2026
When an admin revokes a user's Share and Download permissions, existing share links created by that user remain fully accessible to unauthenticated users. The public share download handler does not re-check the share owner's current permissions. Verified with a running PoC against v2.62.2 (commit 86…
CVE-2026-35604
GitHub-GHSA

HIGH
File Browser has a Command Injection via Hook Runner
GHSA-jvpw-637p-h3pw
pkg: github.com/filebrowser/filebrowser/v2
eco: go
published: Apr 8, 2026
> [!NOTE]
> **This feature has been disabled by default for all installations from v2.33.8 onwards, including for existent installations**. To exploit this vulnerability, the instance administrator must turn on a feature and ignore all the warnings about known vulnerabilities. We're publishing this …
CVE-2026-35585
GitHub-GHSA

HIGH
LiteLLM: Password hash exposure and pass-the-hash authentication bypass
GHSA-69×8-hrgq-fjj8
pkg: litellm
eco: pip
published: Apr 8, 2026
### Impact

Three issues combine into a full authentication bypass chain:

1. Weak hashing: User passwords are stored as unsalted SHA-256 hashes, making them vulnerable to rainbow table attacks and trivially identifying users with identical passwords.
2. Hash exposure: Multiple API endpoints (/user/…

GitHub-GHSA

HIGH
Java-SDK has a DNS Rebinding Vulnerability
GHSA-8jxr-pr72-r468
pkg: io.modelcontextprotocol.sdk:mcp-core
eco: maven
published: Apr 7, 2026
### Summary

The java-sdk contains a DNS rebinding vulnerability. This vulnerability allows an attacker to access a locally or network-private java-sdk MCP server via a victims browser that is either local, or network adjacent.

This allows an attacker to make any tool call to the server as if they …

CVE-2026-35568
GitHub-GHSA

HIGH
Gotenberg has incomplete fix for ExifTool arbitrary file write: case-insensitive bypass and missing HardLink/SymLink tags
GHSA-qmwh-9m9c-h36m
pkg: github.com/gotenberg/gotenberg/v8
eco: go
published: Apr 7, 2026
## Summary

The fix for ExifTool arbitrary file write (commit `043b158`, released in v8.29.0) uses a case-sensitive blocklist to filter dangerous pseudo-tags. ExifTool processes tag names case-insensitively, so alternate casings bypass the filter. The blocklist also omits the `HardLink` and `SymLink…

GitHub-GHSA

HIGH
Gotenberg Vulnerable to ReDoS via extraHttpHeaders scope feature
GHSA-fmwg-qcqh-m992
pkg: github.com/gotenberg/gotenberg/v8
eco: go
published: Apr 7, 2026
### Summary
Gotenberg uses `dlclark/regexp2` to compile user-supplied scope patterns without setting a proper timeout. Users with access to features using this logic can hang workers indefinitely.

### Details
Gotenberg uses `dlclark/regexp2` to compile user-supplied scope patterns (gotenberg/pkg/m…

CVE-2026-35458
GitHub-GHSA

HIGH
Lupa has a Sandbox escape and RCE due to incomplete attribute_filter enforcement in getattr / setattr
GHSA-69v7-xpr6-6gjm
pkg: lupa
eco: pip
published: Apr 7, 2026
### Summary
The `attribute_filter` in the Lupa library is intended to restrict access to sensitive Python attributes when exposing objects to Lua.

However, the filter is not consistently applied when attributes are accessed through built-in functions like getattr and setattr. This allows an attacke…

CVE-2026-34444
GitHub-GHSA

HIGH
Authorizer: Password reset token theft and full auth token redirect via unvalidated redirect_uri
GHSA-x3f4-v83f-7wp2
pkg: github.com/authorizerdev/authorizer
eco: go
published: Apr 6, 2026
Hi,

I found that 6 endpoints in Authorizer accept a user-controlled `redirect_uri` and append sensitive tokens to it without validating the URL against `AllowedOrigins`. The OAuth `/app` handler validates redirect_uri at `http_handlers/app.go:46`, but the GraphQL mutations and verify_email handler …

GitHub-GHSA

MEDIUM
OpenEXR has buffer overflow in PyOpenEXR_old's channels() and channel()
GHSA-vh63-9mqx-wmjr
pkg: OpenEXR, OpenEXR, OpenEXR
eco: pip
published: Apr 6, 2026
### Summary

A memory safety bug in the legacy OpenEXR Python adapter (the deprecated OpenEXR.InputFile wrapper) allow crashes and likely code execution when opening attacker-controlled EXR files or when passing crafted Python objects.

Integer overflow and unchecked allocation in InputFile.channel(…

CVE-2025-64182
GitHub-GHSA

MEDIUM
OpenEXR has use after free in PyObject_StealAttrString
GHSA-57cw-j6vp-2p9m
pkg: OpenEXR, OpenEXR, OpenEXR
eco: pip
published: Apr 6, 2026
### Summary
There is a use-after-free in PyObject_StealAttrString of pyOpenEXR_old.cpp.

This bug was found with [ZeroPath](https://zeropath.com/?utm_source=joshua.hu).

### Details

The legacy adapter defines PyObject_StealAttrString that calls PyObject_GetAttrString to obtain a new reference, imme…

CVE-2025-64183
GitHub-GHSA

MEDIUM
Duplicate Advisory: OpenClaw: SSRF via Unguarded Configured Base URLs in Multiple Channel Extensions (Incomplete Fix for CVE-2026-28476)
GHSA-8j7f-g9gv-7jhc
pkg: openclaw
eco: npm
published: Apr 10, 2026
### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-rhfg-j8jq-7v2h. This link is maintained to preserve external references.

### Original Description
OpenClaw before 2026.3.25 contains a server-side request forgery vulnerability in multiple channel extensions t…

GitHub-GHSA

MEDIUM
Duplicate Advisory: OpenClaw: Tlon cite expansion happens before channel and DM authorization is complete
GHSA-p6j4-wvmc-vx2h
pkg: openclaw
eco: npm
published: Apr 10, 2026
### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-vfg3-pqpq-93m4. This link is maintained to preserve external references.

### Original Description
OpenClaw before 2026.3.22 performs cite expansion before completing channel and DM authorization checks, allowi…

GitHub-GHSA

MEDIUM
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/utils/common.py
GHSA-qw5f-qpq5-ppfg
pkg: metagpt
eco: pip
published: Apr 9, 2026
A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file metagpt/utils/common.py. The manipulation results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used. The project was in…
CVE-2026-5973
GitHub-GHSA

MEDIUM
FoundationAgents MetaGPT vulnerable to os command injection via the Terminal.run_command
GHSA-wp29-qmvj-frvp
pkg: metagpt
eco: pip
published: Apr 9, 2026
A vulnerability has been found in FoundationAgents MetaGPT up to 0.8.1. This issue affects the function Terminal.run_command in the library metagpt/tools/libs/terminal.py. The manipulation leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to…
CVE-2026-5972
GitHub-GHSA

MEDIUM
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py
GHSA-fcc8-4q7h-wvwc
pkg: metagpt
eco: pip
published: Apr 9, 2026
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in the library metagpt/tools/libs/terminal.py. This manipulation causes os command injection. The attack is possible to be carried out remotely. The project was informed of the probl…
CVE-2026-5974
GitHub-GHSA

MEDIUM
FoundationAgents MetaGPT vulnerable to eval injection
GHSA-3ghp-8r47-4gj4
pkg: metagpt
eco: pip
published: Apr 9, 2026
A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fill of the file metagpt/actions/action_node.py of the component XML Handler. Executing a manipulation can lead to improper neutralization of directives in dynamically evaluated code…
CVE-2026-5971
GitHub-GHSA

MEDIUM
decolua 9router vulnerable to authorization bypass
GHSA-xrrh-p7f2-27vm
pkg: 9router
eco: npm
published: Apr 9, 2026
A security vulnerability has been detected in decolua 9router up to 0.3.47. The impacted element is an unknown function of the file /api of the component Administrative API Endpoint. The manipulation leads to authorization bypass. The attack is possible to be carried out remotely. The exploit has be…
CVE-2026-5842
GitHub-GHSA

MEDIUM
api-lab-mcp vulnerable to SSRF
GHSA-crh9-3gjh-m6gc
pkg: api-lab-mcp
eco: npm
published: Apr 9, 2026
A weakness has been identified in atototo api-lab-mcp up to 0.2.1. This affects the function analyze_api_spec/generate_test_scenarios/test_http_endpoint of the file src/mcp/http-server.ts of the component HTTP Interface. This manipulation of the argument source/url causes server-side request forgery…
CVE-2026-5832
GitHub-GHSA

MEDIUM
PowerJob's GroovyEvaluator.evaluate endpoint vulnerable to code injection
GHSA-wpwf-v25w-54g3
pkg: tech.powerjob:powerjob-server-starter
eco: maven
published: Apr 7, 2026
A security flaw has been discovered in PowerJob 5.1.0/5.1.1/5.1.2. The affected element is the function GroovyEvaluator.evaluate of the file /openApi/addWorkflowNode of the component OpenAPI Endpoint. The manipulation of the argument nodeParams results in code injection. The attack can be executed r…
CVE-2026-5739
GitHub-GHSA

MEDIUM
PowerJob vulnerable to SQL injection
GHSA-4fp2-3xgg-jg4w
pkg: tech.powerjob:powerjob-server-starter
eco: maven
published: Apr 7, 2026
A vulnerability was identified in PowerJob 5.1.0/5.1.1/5.1.2. Impacted is an unknown function of the file powerjob-server/powerjob-server-starter/src/main/java/tech/powerjob/server/web/controller/InstanceController.java of the component detailPlus Endpoint. The manipulation of the argument customQue…
CVE-2026-5736
GitHub-GHSA

MEDIUM
Aiven Operator has cross-namespace secret exfiltration via ClickhouseUser connInfoSecretSource
GHSA-99j8-wv67-4c72
pkg: github.com/aiven/aiven-operator
eco: go
published: Apr 10, 2026
### Impact
A developer with create permission on ClickhouseUser CRDs in their own namespace can exfiltrate secrets from any other namespace — production database credentials, API keys, service tokens — with a single kubectl apply. The operator reads the victim's secret using its ClusterRole and …
CVE-2026-39961
NVD

MEDIUM
CVE-2026-39961
CVE-2026-39961
pkg: kubernetes

published: Apr 9, 2026

Aiven Operator allows you to provision and manage Aiven Services from your Kubernetes cluster. From 0.31.0 to before 0.37.0, a developer with create permission on ClickhouseUser CRDs in their own namespace can exfiltrate secrets from any other namespace — production database credentials, API keys,…
CWE: CWE-269, CWE-441
GitHub-GHSA

MEDIUM
pyload-ng: Authorization Bypass for SSL Certificate/Key Configuration Due to Option Name Mismatch in pyload-ng
GHSA-ppvx-rwh9-7rj7
pkg: pyload-ng
eco: pip
published: Apr 8, 2026
## Summary

The `ADMIN_ONLY_CORE_OPTIONS` authorization set in `set_config_value()` uses incorrect option names `ssl_cert` and `ssl_key`, while the actual configuration option names are `ssl_certfile` and `ssl_keyfile`. This name mismatch causes the admin-only check to always evaluate to False, allo…

CVE-2026-35586
NVD

MEDIUM
CVE-2026-35586
CVE-2026-35586
pkg: ssl

published: Apr 7, 2026

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the ADMIN_ONLY_CORE_OPTIONS authorization set in set_config_value() uses incorrect option names ssl_cert and ssl_key, while the actual configuration option names are ssl_certfile and ssl_keyfile. This name m…
CWE: CWE-863
NVD

MEDIUM
CVE-2026-4837
CVE-2026-4837
pkg: tls

published: Apr 8, 2026

An eval() injection vulnerability in the Rapid7 Insight Agent beaconing logic for Linux versions could theoretically allow an attacker to achieve remote code execution as root via a crafted beacon response. Because the Agent uses mutual TLS (mTLS) to verify commands from the Rapid7 Platform, it is u…
CWE: CWE-95
NVD

MEDIUM
CVE-2026-35197
CVE-2026-35197
pkg: express

published: Apr 6, 2026

dye is a portable and respectful color library for shell scripts. Prior to 1.1.1, certain dye template expressions would result in execution of arbitrary code. This issue was discovered and fixed by dye's author, and is not known to be exploited. This vulnerability is fixed in 1.1.1.
CWE: CWE-94
GitHub-GHSA

MEDIUM
Ech0 Scope Bypass: profile:read Access Token Can Change Admin Password and Escalate to Unrestricted Session
GHSA-hm2h-wwwh-g49x
pkg: github.com/lin-snow/ech0
eco: go
published: Apr 10, 2026
## Summary

The `PUT /user` endpoint is protected by `RequireScopes("profile:read")`, which is a read-only scope. However, the endpoint performs write operations including password changes. An attacker who obtains an admin's restricted `profile:read` access token can change the admin's password, the…

GitHub-GHSA

MEDIUM
Ech0: Missing authorization on dashboard log endpoints allows low-privilege users to access sensitive system logs
GHSA-cp79-9mwr-wr49
pkg: github.com/lin-snow/ech0
eco: go
published: Apr 10, 2026
## Summary

Ech0 allows any authenticated user to read historical system logs and subscribe to live log streams because the dashboard log endpoints validate only that a JWT is present and valid, but do not require an administrator role or privileged scope.

## Impact

Any valid user session can acce…

GitHub-GHSA

MEDIUM
PraisonAI Vulnerable to Decompression Bomb DoS via Recipe Bundle Extraction Without Size Limits
GHSA-f2h6-7xfr-xm8w
pkg: PraisonAI
eco: pip
published: Apr 10, 2026
## Summary

The `_safe_extractall()` function in PraisonAI's recipe registry validates archive members against path traversal attacks but performs no checks on individual member sizes, cumulative extracted size, or member count before calling `tar.extractall()`. An attacker can publish a malicious r…

CVE-2026-40148
NVD

MEDIUM
CVE-2026-35594
CVE-2026-35594
pkg: jwt

published: Apr 10, 2026

Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, Vikunja's link share authentication (GetLinkShareFromClaims in pkg/models/link_sharing.go) constructs authorization objects entirely from JWT claims without any server-side database validation. When a project owner delet…
CWE: CWE-613
GitHub-GHSA

MEDIUM
Vikunja has Algorithmic Complexity DoS in Repeating Task Handler
GHSA-r4fg-73rc-hhh7
pkg: code.vikunja.io/api
eco: go
published: Apr 10, 2026
## Summary

The `addRepeatIntervalToTime` function uses an O(n) loop that advances a date by the task's `RepeatAfter` duration until it exceeds the current time. By creating a repeating task with a 1-second interval and a due date far in the past, an attacker triggers billions of loop iterations, co…

CVE-2026-35599
GitHub-GHSA

MEDIUM
Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade
GHSA-96q5-xm3p-7m84
pkg: code.vikunja.io/api
eco: go
published: Apr 10, 2026
## Title
Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrade

## Description

Vikunja's link share authentication constructs authorization objects entirely from JWT claims without any server-side database validation. When a project owner deletes a link share …

CVE-2026-35594
NVD

MEDIUM
CVE-2021-47960
CVE-2021-47960
pkg: ssl

published: Apr 10, 2026

A files or directories accessible to external parties vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access files within the installation directory via a local HTTP server bound to the loopback interface. By leveraging user interaction with a crafted web page, …
CWE: CWE-552
GitHub-GHSA

MEDIUM
Duplicate Advisory: OpenClaw: Nostr inbound DMs could trigger unauthenticated crypto work before sender policy enforcement
GHSA-2j53-2c28-g9v2
pkg: openclaw
eco: npm
published: Apr 10, 2026
### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-65h8-27jh-q8wv. This link is maintained to preserve external references.

### Original Description
OpenClaw before 2026.3.22 performs cryptographic and dispatch operations on inbound Nostr direct messages befor…

NVD

MEDIUM
CVE-2026-39848
CVE-2026-39848
pkg: docker

published: Apr 9, 2026

Dockyard is a Docker container management app. Prior to 1.1.0, Docker container start and stop operations are performed through GET requests without CSRF protection. A remote attacker can cause a logged-in administrator's browser to request /apps/action.php?action=stop&name=<container> or /apps/acti…
CWE: CWE-306
GitHub-GHSA

MEDIUM
Apache Tomcat: CLIENT_CERT authentication does not fail as expected
GHSA-24j9-x2wg-9qv6
pkg: org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat-catalina
eco: maven
published: Apr 9, 2026
CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat.

This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.20, from 10.1.22 through 10.1.53, from 9.0.92 through 9.0.116.

Users are recommended to upgrade to ver…

CVE-2026-34500
NVD

MEDIUM
CVE-2026-34500
CVE-2026-34500
pkg: apache

published: Apr 9, 2026

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat.

This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.20, from 10.1.22 through 10.1.53, from 9.0.92 through 9.0.116.

Users are recommended to upgrade to ver…

CWE: CWE-287
GitHub-GHSA

MEDIUM
Apache Airflow has an authorization bypass in DagRun wait endpoint
GHSA-r7vr-m4jw-r794
pkg: apache-airflow
eco: pip
published: Apr 9, 2026
Apache Airflow versions 3.0.0 through 3.1.8 DagRun wait endpoint returns XCom result values even to users who only have DAG Run read permissions, such as the Viewer role.This behavior conflicts with the FAB RBAC model, which treats XCom as a separate protected resource, and with the security model d…
CVE-2026-34538
NVD

MEDIUM
CVE-2026-34538
CVE-2026-34538
pkg: apache

published: Apr 9, 2026

Apache Airflow versions 3.0.0 through 3.1.8 DagRun wait endpoint returns XCom result values even to users who only have DAG Run read permissions, such as the Viewer role.This behavior conflicts with the FAB RBAC model, which treats XCom as a separate protected resource, and with the security model d…
CWE: CWE-668
GitHub-GHSA

MEDIUM
OpenFGA: Unauthenticated playground endpoint discloses preshared API key in HTML response
GHSA-68m9-983m-f3v5
pkg: github.com/openfga/openfga
eco: go
published: Apr 8, 2026
### Description
When OpenFGA is configured to use preshared-key authentication with the built-in playground enabled, the local server includes the preshared API key in the HTML response of the /playground endpoint. The /playground endpoint is enabled by default and does not require authentication. I…
GitHub-GHSA

MEDIUM
PraisonAI has Memory State Leakage and Path Traversal in MultiAgent Context Handling
GHSA-766v-q9x3-g744
pkg: praisonaiagents
eco: pip
published: Apr 8, 2026
## Summary
The `MultiAgentLedger` and `MultiAgentMonitor` components in the provided code exhibit vulnerabilities that can lead to context leakage and arbitrary file operations. Specifically:
1. **Memory State Leakage via Agent ID Collision**: The `MultiAgentLedger` uses a dictionary to store ledger…
GitHub-GHSA

MEDIUM
kubernetes-graphql-gateway: GraphQL Endpoint Vulnerable to Authenticated Denial-of-Service via Unrestricted Query Execution
GHSA-h9mw-h4qc-f5jf
pkg: github.com/platform-mesh/kubernetes-graphql-gateway
eco: go
published: Apr 8, 2026
**CVSS 6.5 Medium** — The GraphQL API served by kubernetes-graphql-gateway is vulnerable to Denial-of-Service (DoS) attacks due to a complete absence of query resource controls (depth limiting, complexity analysis, response size capping, and rate limiting). An authenticated attacker can craft quer…
NVD

MEDIUM
CVE-2026-32588
CVE-2026-32588
pkg: apache

published: Apr 7, 2026

Authenticated DoS over CQL in Apache Cassandra 4.0, 4.1, 5.0 allows authenticated user to raise query latencies via repeated password changes.
Users are recommended to upgrade to version 4.0.20, 4.1.11, 5.0.7, which fixes this issue.
CWE: CWE-400
GitHub-GHSA

MEDIUM
Django has potential DoS via MultiPartParser through crafted multipart uploads
GHSA-5mf9-h53q-7mhq
pkg: Django, Django, Django
eco: pip
published: Apr 7, 2026
An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `MultiPartParser` allows remote attackers to degrade performance by submitting multipart uploads with `Content-Transfer-Encoding: base64` including excessive whitespace.

Earlier, unsupported Django series (such a…

CVE-2026-33033
NVD

MEDIUM
CVE-2026-33033
CVE-2026-33033
pkg: django

published: Apr 7, 2026

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30.
`MultiPartParser` allows remote attackers to degrade performance by submitting multipart uploads with `Content-Transfer-Encoding: base64` including excessive whitespace.
Earlier, unsupported Django series (such as…
CWE: CWE-407
GitHub-GHSA

MEDIUM
HuggingFace Transformers allows for arbitrary code execution in the `Trainer` class
GHSA-69w3-r845-3855
pkg: transformers
eco: pip
published: Apr 7, 2026
A vulnerability in the HuggingFace Transformers library, specifically in the `Trainer` class, allows for arbitrary code execution. The `_load_rng_state()` method in `src/transformers/trainer.py` at line 3059 calls `torch.load()` without the `weights_only=True` parameter. This issue affects all versi…
CVE-2026-1839
GitHub-GHSA

MEDIUM
kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write
GHSA-cjg8-h5qc-hrjv
pkg: kedro-datasets
eco: pip
published: Apr 6, 2026
### Impact

PartitionedDataset in kedro-datasets was vulnerable to path traversal. Partition IDs were concatenated directly with the dataset base path without validation. An attacker or malicious input containing .. components in a partition ID could cause files to be written outside the configured …

CVE-2026-35492
GitHub-GHSA

MEDIUM
OpenEXR has heap-buffer-overflow via signed integer underflow in ImfContextInit.cpp
GHSA-q6vj-wxvf-5m8c
pkg: OpenEXR, OpenEXR
eco: pip
published: Apr 6, 2026
## Summary

A heap-buffer-overflow (OOB read) occurs in the `istream_nonparallel_read` function in `ImfContextInit.cpp` when parsing a malformed EXR file through a memory-mapped `IStream`. A signed integer subtraction produces a negative value that is implicitly converted to `size_t`, resulting in a…

CVE-2026-26981
NVD

MEDIUM
CVE-2025-57851
CVE-2025-57851
pkg: kubernetes

published: Apr 8, 2026

A container privilege escalation flaw was found in certain Multicluster Engine for Kubernetes images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container, …
CWE: CWE-276
GitHub-GHSA

MEDIUM
Agions taskflow-ai vulnerable to os command injection in src/mcp/server/handlers.ts
GHSA-3xp3-pr8x-f755
pkg: taskflow-ai
eco: npm
published: Apr 9, 2026
A security flaw has been discovered in Agions taskflow-ai up to 2.1.8. This impacts an unknown function of the file src/mcp/server/handlers.ts of the component terminal_execute. Performing a manipulation results in os command injection. The attack is possible to be carried out remotely. Upgrading to…
CVE-2026-5831
GitHub-GHSA

MEDIUM
PraisonAIAgents: Arbitrary File Read via read_skill_file Missing Workspace Boundary and Approval Gate
GHSA-grrg-5cg9-58pf
pkg: praisonaiagents
eco: pip
published: Apr 10, 2026
## Summary

`read_skill_file()` in `skill_tools.py` allows reading arbitrary files from the filesystem by accepting an unrestricted `skill_path` parameter. Unlike `file_tools.read_file` which enforces workspace boundary confinement, and unlike `run_skill_script` which requires critical-level approva…

CVE-2026-40117
GitHub-GHSA

MEDIUM
PraisonAI has Unrestricted Upload Size in WSGI Recipe Registry Server that Enables Memory Exhaustion DoS
GHSA-2xgv-5cv2-47vv
pkg: PraisonAI
eco: pip
published: Apr 10, 2026
## Summary

The WSGI-based recipe registry server (`server.py`) reads the entire HTTP request body into memory based on the client-supplied `Content-Length` header with no upper bound. Combined with authentication being disabled by default (no token configured), any local process can send arbitraril…

CVE-2026-40115
GitHub-GHSA

MEDIUM
rfc3161-client Has Improper Certificate Validation
GHSA-3xxc-pwj6-jgrj
pkg: rfc3161-client
eco: pip
published: Apr 8, 2026
### Summary

An Authorization Bypass vulnerability in `rfc3161-client`'s signature verification allows any attacker to impersonate a trusted TimeStamping Authority (TSA). By exploiting a logic flaw in how the library extracts the leaf certificate from an unordered PKCS#7 bag of certificates, an atta…

CVE-2026-33753
GitHub-GHSA

MEDIUM
netavark has incorrect error handling for malformed tcp packets
GHSA-hfpq-x728-986j
pkg: netavark
eco: rust
published: Apr 7, 2026
### Impact

A truncated TCP DNS query followed by a connection reset causes aardvark-dns to enter an unrecoverable infinite error loop at 100% CPU.

### Patches
https://github.com/containers/aardvark-dns/commit/3b49ea7b38bdea134b7f03256f2e13f44ce73bb1

### Workarounds
None

### Credits

Thanks to @d…

CVE-2026-35406
GitHub-GHSA

MEDIUM
go-ipld-prime: DAG-CBOR decoder unbounded memory allocation from CBOR headers
GHSA-378j-3jfj-8r9f
pkg: github.com/ipld/go-ipld-prime
eco: go
published: Apr 6, 2026
The DAG-CBOR decoder uses collection sizes declared in CBOR headers as Go preallocation hints for maps and lists. The decoder does not cap these size hints or account for their cost in its allocation budget, allowing small payloads to cause excessive memory allocation.

A CBOR map or list header can…

CVE-2026-35480
GitHub-GHSA

MEDIUM
go.etcd.io/bbolt affected by index out-of-range vulnerability
GHSA-6jwv-w5xf-7j27
pkg: go.etcd.io/bbolt
eco: go
published: Apr 6, 2026
Index out-of-range when encountering a branch page with zero elements in go.etcd.io/bbolt
CVE-2026-33817
GitHub-GHSA

MEDIUM
Apache Tomcat has an Open Redirect vulnerability
GHSA-9m3c-qcxr-9×87
pkg: org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat
eco: maven
published: Apr 9, 2026
Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDrainingValve.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M23 through 9.0.115, from 8.5.30 through 8.5.100.
Other, unsu…

CVE-2026-25854
GitHub-GHSA

MEDIUM
Unhead has a hasDangerousProtocol() bypass via leading-zero padded HTML entities in useHeadSafe()
GHSA-95h2-gj7x-gx9w
pkg: unhead
eco: npm
published: Apr 9, 2026
##EVIDENCE

<img width="1900" height="855" alt="Screenshot_2026-03-25_090729" src="https://github.com/user-attachments/assets/3da93464-1caf-46ca-818f-46f8fe32ab50" />
<img width="1919" height="947" alt="Screenshot_2026-03-25_090715" src="https://github.com/user-attachments/assets/b27b1fc3-fa89-4864-…

CVE-2026-39315
NVD

MEDIUM
CVE-2026-25854
CVE-2026-25854
pkg: apache

published: Apr 9, 2026

Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDrainingValve.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M23 through 9.0.115, from 8.5.30 through 8.5.100.
Other, unsu…

CWE: CWE-601
NVD

MEDIUM
CVE-2026-39315
CVE-2026-39315
pkg: express

published: Apr 9, 2026

Unhead is a document head and template manager. Prior to 2.1.13, useHeadSafe() is the composable that Nuxt's own documentation explicitly recommends for rendering user-supplied content in <head> safely. Internally, the hasDangerousProtocol() function in packages/unhead/src/plugins/safe.ts decodes HT…
CWE: CWE-184
GitHub-GHSA

MEDIUM
Vikunja Vulnerable to TOTP Brute-Force Due to Non-Functional Account Lockout
GHSA-fgfv-pv97-6cmj
pkg: code.vikunja.io/api
eco: go
published: Apr 10, 2026
## Summary

The TOTP failed-attempt lockout mechanism is non-functional due to a database transaction handling bug. The account lock is written to the same database session that the login handler always rolls back on TOTP failure, so the lockout is triggered but never persisted. This allows unlimite…

CVE-2026-35597
GitHub-GHSA

MEDIUM
Axios HTTP/2 Session Cleanup State Corruption Vulnerability
GHSA-qj83-cq47-w5f8
pkg: axios
eco: npm
published: Apr 8, 2026
### Summary

Axios HTTP/2 session cleanup logic contains a state corruption bug that allows a malicious server to crash the client process through concurrent session closures. This denial-of-service vulnerability affects axios versions prior to 1.13.2 when HTTP/2 is enabled.

### Details

The vulner…

CVE-2026-39865
NVD

MEDIUM
CVE-2026-39865
CVE-2026-39865
pkg: axios

published: Apr 8, 2026

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.13.2, Axios HTTP/2 session cleanup logic contains a state corruption bug that allows a malicious server to crash the client process through concurrent session closures. The vulnerability exists in the Http2Sessions.getSessi…
CWE: CWE-400, CWE-662
GitHub-GHSA

MEDIUM
NiceGUI: Upload filename sanitization bypass via backslashes allows path traversal on Windows
GHSA-w8wv-vfpc-hw2w
pkg: nicegui
eco: pip
published: Apr 8, 2026
### Summary

The upload filename sanitization introduced in GHSA-9ffm-fxg3-xrhh uses `PurePosixPath(filename).name` to strip path components. Since `PurePosixPath` only recognizes forward slashes (`/`) as path separators, an attacker can bypass this sanitization on Windows by using backslashes (`\`)…

CVE-2026-39844
GitHub-GHSA

MEDIUM
Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder
GHSA-xmrv-pmrh-hhx2
pkg: github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream, github.com/aws/aws-sdk-go-v2/service/bedrockagentcore, github.com/aws/aws-sdk-go-v2/service/bedrockagentruntime
eco: go
published: Apr 8, 2026
**CVSSv3.1 Rating**: [Medium]
**CVSSv3.1 Score**: [5.9]
**CVSSv3.1 Vector String**: [CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H]

## Summary and Impact
An issue exists in the the EventStream header decoder in AWS SDK for Go v2 in versions predating [2026-03-23](https://github.com/aws/aws-sdk-go-v2…

GitHub-GHSA

MEDIUM
rdiscount has an Out-of-bounds Read
GHSA-6r34-94wq-jhrc
pkg: rdiscount
eco: rubygems
published: Apr 6, 2026
### Summary

A signed length truncation bug causes an out-of-bounds read in the default Markdown parse path. Inputs larger than `INT_MAX` are truncated to a signed `int` before entering the native parser, allowing the parser to read past the end of the supplied buffer and crash the process

### Deta…

CVE-2026-35201
NVD

MEDIUM
CVE-2026-34380
CVE-2026-34380
pkg: openexr openexr

published: Apr 6, 2026

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.2.0 to before 3.2.7, 3.3.9, and 3.4.9, a signed integer overflow exists in undo_pxr24_impl() in src/lib/OpenEXRCore/internal_pxr24.c at line 377. Th…
CWE: CWE-190, CWE-787
GitHub-GHSA

MEDIUM
monetr: Protected Transactions Deletable via PUT
GHSA-hqxq-hwqf-wg83
pkg: github.com/monetr/monetr
eco: go
published: Apr 8, 2026
### Summary
A transaction integrity flaw allows an authenticated tenant user to soft-delete synced non-manual transactions through the transaction update endpoint, despite the application explicitly blocking deletion of those transactions via the normal `DELETE` path. This bypass undermines the inte…
CVE-2026-39901
GitHub-GHSA

MEDIUM
LangSmith Client SDKs has Prototype Pollution in langsmith-sdk via Incomplete `__proto__` Guard in Internal lodash `set()`
GHSA-fw9q-39r9-c252
pkg: langsmith
eco: npm
published: Apr 10, 2026
# GHSA-fw9q-39r9-c252: Prototype Pollution via Incomplete Lodash `set()` Guard in `langsmith-sdk`

**Severity:** Medium (CVSS ~5.6)
**Status:** Fixed in 0.5.18

## Summary

The LangSmith JavaScript/TypeScript SDK (`langsmith`) contains an incomplete prototype pollution fix in its internally ven…

CVE-2026-40190
NVD

MEDIUM
CVE-2026-40190
CVE-2026-40190
pkg: lodash

published: Apr 10, 2026

LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.5.18, the LangSmith JavaScript/TypeScript SDK (langsmith) contains an incomplete prototype pollution fix in its internally vendored lodash set() utility. The baseAssignValue() function only guards against the…
CWE: CWE-1321
GitHub-GHSA

MEDIUM
Ech0 has SSRF via DNS Resolution Bypass in Webhook URL Validation
GHSA-r2x7-427f-rq69
pkg: github.com/lin-snow/ech0
eco: go
published: Apr 10, 2026
## Summary

The `validateWebhookURL` function in `webhook_setting_service.go` attempts to block webhooks targeting private/internal IP addresses, but only checks literal IP strings via `net.ParseIP()`. Hostnames that DNS-resolve to private IPs (e.g., `169.254.169.254.nip.io`, `10.0.0.1.nip.io`) bypa…

GitHub-GHSA

MEDIUM
Ech0 Comment Panel Endpoints Missing RequireScopes Middleware — Scoped Access Token Bypass
GHSA-fwg7-53p4-g33c
pkg: github.com/lin-snow/ech0
eco: go
published: Apr 10, 2026
## Summary

All 9 comment panel admin endpoints (`/api/panel/comments/*`) are missing `RequireScopes()` middleware, while every other admin endpoint in the application enforces scope-based authorization on access tokens. An admin-issued access token scoped to minimal permissions (e.g., `echo:read` o…

GitHub-GHSA

MEDIUM
PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands
GHSA-ffp3-3562-8cv3
pkg: praisonaiagents
eco: pip
published: Apr 10, 2026
## Summary

The approval system in PraisonAI Agents caches tool approval decisions by tool name only, not by invocation arguments. Once a user approves `execute_command` for any command (e.g., `ls -la`), all subsequent `execute_command` calls in that execution context bypass the approval prompt enti…

GitHub-GHSA

MEDIUM
PraisonAI Vulnerable to Sensitive Environment Variable Exposure via Untrusted MCP Subprocess Execution
GHSA-pj2r-f9mw-vrcq
pkg: PraisonAI
eco: pip
published: Apr 10, 2026
PraisonAI’s MCP (Model Context Protocol) integration allows spawning background servers via stdio using user-supplied command strings (e.g., `MCP("npx -y @smithery/cli …")`). These commands are executed through Python’s `subprocess` module. By default, the implementation **forwards the entire …
CVE-2026-40159
NVD

MEDIUM
CVE-2026-35477
CVE-2026-35477
pkg: express

published: Apr 8, 2026

InvenTree is an Open Source Inventory Management System. From 1.2.3 to 1.2.6, the fix for CVE-2026-27629 upgraded the PART_NAME_FORMAT validator to use jinja2.sandbox.SandboxedEnvironment. However, the actual renderer in part/helpers.py was not updated and still uses the non-sandboxed jinja2.Environ…
CWE: CWE-1336
NVD

MEDIUM
CVE-2026-27315
CVE-2026-27315
pkg: apache

published: Apr 7, 2026

Sensitive Information Leak in cqlsh in Apache Cassandra 4.0 allows access to sensitive information, like passwords, from previously executed cqlsh command via  ~/.cassandra/cqlsh_history local file access.

Users are recommended to upgrade to version 4.0.20, which fixes this issue.


Description…

CWE: CWE-532
GitHub-GHSA

MEDIUM
PraisonAI Vulnerable to Stored XSS via Unsanitized Agent Output in HTML Rendering (nh3 Not a Required Dependency)
GHSA-cfg2-mxfj-j6pw
pkg: PraisonAI
eco: pip
published: Apr 10, 2026
## Summary

The Flask API endpoint in `src/praisonai/api.py` renders agent output as HTML without effective sanitization. The `_sanitize_html` function relies on the `nh3` library, which is not listed as a required or optional dependency in `pyproject.toml`. When `nh3` is absent (the default install…

CVE-2026-40112
GitHub-GHSA

MEDIUM
Vikunja has File Size Limit Bypass via Vikunja Import
GHSA-qh78-rvg3-cv54
pkg: code.vikunja.io/api
eco: go
published: Apr 10, 2026
## Summary

The Vikunja file import endpoint uses the attacker-controlled `Size` field from the JSON metadata inside the import zip instead of the actual decompressed file content length for the file size enforcement check. By setting `Size` to 0 in the JSON while including large compressed file ent…

CVE-2026-35602
GitHub-GHSA

MEDIUM
Vikunja has HTML Injection via Task Titles in Overdue Email Notifications
GHSA-45q4-x4r9-8fqj
pkg: code.vikunja.io/api
eco: go
published: Apr 10, 2026
## Summary

Task titles are embedded directly into Markdown link syntax in overdue email notifications without escaping Markdown special characters. When rendered by goldmark and sanitized by bluemonday (which allows `<a>` and `<img>` tags), injected Markdown constructs produce phishing links and tr…

CVE-2026-35600
NVD

MEDIUM
CVE-2026-40112
CVE-2026-40112
pkg: flask

published: Apr 9, 2026

PraisonAI is a multi-agent teams system. Prior to 4.5.128, the Flask API endpoint in src/praisonai/api.py renders agent output as HTML without effective sanitization. The _sanitize_html function relies on the nh3 library, which is not listed as a required or optional dependency in pyproject.toml. Wh…
CWE: CWE-79
GitHub-GHSA

MEDIUM
Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT vulnerable to Integer Overflow or Wraparound
GHSA-xvqc-pp94-fmpx
pkg: org.apache.activemq:apache-activemq, org.apache.activemq:activemq-all, org.apache.activemq:activemq-mqtt
eco: maven
published: Apr 9, 2026
Integer Overflow or Wraparound vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT.

The fix for "CVE-2025-66168: MQTT control packet remaining length field is not properly validated" was only applied to 5.19.2 (and future 5.19.x) releases but was missed for all 6.0.0+ versio…

CVE-2026-40046
NVD

MEDIUM
CVE-2026-35207
CVE-2026-35207
pkg: tls

published: Apr 9, 2026

dde-control-center is the control panel of DDE, the Deepin Desktop Environment. plugin-deepinid is a plugin in dde-control-center, which provides the deepinid cloud service. Prior to 6.1.80, plugin-deepinid is configured to skip TLS certificate verification when fetching the user's avatar from opena…
CWE: CWE-295
GitHub-GHSA

MEDIUM
pyload-ng has a WebUI JSON permission mismatch that lets ADD/DELETE users invoke MODIFY-only actions
GHSA-rfgh-63mg-8pwm
pkg: pyload-ng
eco: pip
published: Apr 8, 2026
### Summary
Several WebUI JSON endpoints enforce weaker permissions than the core API methods they invoke. This allows authenticated low-privileged users to execute `MODIFY` operations that should be denied by pyLoad's own permission model.

Confirmed mismatches:
– `ADD` user can reorder packages/fi…

NVD

MEDIUM
CVE-2026-3691
CVE-2026-3691
pkg: oauth

published: Apr 11, 2026

OpenClaw Client PKCE Verifier Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose stored credentials on affected installations of OpenClaw. User interaction is required to exploit this vulnerability in that the target must initiate an OAuth authorization flow…
CWE: CWE-200
GitHub-GHSA

MEDIUM
Rembg has a Path Traversal via Custom Model Loading
GHSA-3wqj-33cg-xc48
pkg: rembg
eco: pip
published: Apr 10, 2026
## Summary

A **path traversal vulnerability** in the rembg HTTP server allows unauthenticated remote attackers to read arbitrary files from the server's filesystem. By sending a crafted request with a malicious `model_path` parameter, an attacker can force the server to attempt loading any file as …

CVE-2026-40086
GitHub-GHSA

MEDIUM
xrootd has path traversal in directory listing that allows access to the parent directory via trailing ".." pattern
GHSA-vj8v-p5vw-m6v5
pkg: xrootd
eco: pip
published: Apr 10, 2026
## Summary

A path traversal vulnerability in XRootD allows users to escape the exported directory scope and enumerate the contents of the parent directory by appending `/..` (specifically without trailing slash) to an exported path in `xrdfs ls` or `HTTP PROPFIND` requests.

This bypass ignores the…

GitHub-GHSA

MEDIUM
PraisonAIAgents: Path Traversal via Unvalidated Glob Pattern in list_files Bypasses Workspace Boundary
GHSA-7j2f-xc8p-fjmq
pkg: praisonaiagents
eco: pip
published: Apr 10, 2026
## Summary

The `list_files()` tool in `FileTools` validates the `directory` parameter against workspace boundaries via `_validate_path()`, but passes the `pattern` parameter directly to `Path.glob()` without any validation. Since Python's `Path.glob()` supports `..` path segments, an attacker can u…

CVE-2026-40152
GitHub-GHSA

MEDIUM
PraisonAI: Unauthenticated Information Disclosure of Agent Instructions via /api/agents in AgentOS
GHSA-pm96-6xpr-978x
pkg: PraisonAI
eco: pip
published: Apr 10, 2026
## Summary

The AgentOS deployment platform exposes a `GET /api/agents` endpoint that returns agent names, roles, and the first 100 characters of agent system instructions to any unauthenticated caller. The AgentOS FastAPI application has no authentication middleware, no API key validation, and defa…

CVE-2026-40151
GitHub-GHSA

MEDIUM
Zod jsVideoUrlParser vulnerable to ReDoS in util.js
GHSA-8fgx-wgvr-pcx8
pkg: js-video-url-parser
eco: npm
published: Apr 10, 2026
A weakness has been identified in Zod jsVideoUrlParser up to 0.5.1. The impacted element is the function getTime in the library lib/util.js. This manipulation of the argument timestamp causes inefficient regular expression complexity. It is possible to initiate the attack remotely. The exploit has b…
CVE-2026-5986
GitHub-GHSA

MEDIUM
Duplicate Advisory: OpenClaw: Remote media error responses could trigger unbounded memory allocation before failure
GHSA-hm63-vwj4-mj2q
pkg: openclaw
eco: npm
published: Apr 10, 2026
### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-4qwc-c7g9-4xcw. This link is maintained to preserve external references.

### Original Description
OpenClaw before 2026.3.22 contains an unbounded memory allocation vulnerability in remote media HTTP error hand…

GitHub-GHSA

MEDIUM
Duplicate Advisory: OpenClaw: Feishu webhook reads and parses unauthenticated request bodies before signature validation
GHSA-8f9r-gr6r-x63q
pkg: openclaw
eco: npm
published: Apr 10, 2026
### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-3h52-cx59-c456. This link is maintained to preserve external references.

### Original Description
OpenClaw before 2026.3.25 parses JSON request bodies before validating webhook signatures, allowing unauthentic…

GitHub-GHSA

MEDIUM
Duplicate Advisory: OpenClaw is vulnerable to unauthenticated resource exhaustion through its voice call webhook handling
GHSA-36cp-mh65-x882
pkg: openclaw
eco: npm
published: Apr 10, 2026
### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-rm59-992w-x2mv. This link is maintained to preserve external references.

### Original Description
OpenClaw before 2026.3.22 contains an unauthenticated resource exhaustion vulnerability in voice call webhook h…

NVD

MEDIUM
CVE-2026-5986
CVE-2026-5986
pkg: express

published: Apr 9, 2026

A weakness has been identified in Zod jsVideoUrlParser up to 0.5.1. The impacted element is the function getTime in the library lib/util.js. This manipulation of the argument timestamp causes inefficient regular expression complexity. It is possible to initiate the attack remotely. The exploit has b…
CWE: CWE-400, CWE-1333
GitHub-GHSA

MEDIUM
Apache Tomcat has an Improper Input Validation vulnerability
GHSA-8mc5-53m5-3qj2
pkg: org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat-catalina, org.apache.tomcat:tomcat-catalina
eco: maven
published: Apr 9, 2026
Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614.

This issue affects Apache Tomcat: from 11.0.15 through 11.0.19, from 10.1.50 through 10.1.52, from 9.0.113 through 9.0.115.

Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, …

CVE-2026-32990
NVD

MEDIUM
CVE-2026-40087
CVE-2026-40087
pkg: express

published: Apr 9, 2026

LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.84 and 1.2.28, LangChain's f-string prompt-template validation was incomplete in two respects. First, some prompt template classes accepted f-string templates and formatted them without enforcing the same attribu…
CWE: CWE-1336
NVD

MEDIUM
CVE-2026-32990
CVE-2026-32990
pkg: apache

published: Apr 9, 2026

Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614.

This issue affects Apache Tomcat: from 11.0.15 through 11.0.19, from 10.1.50 through 10.1.52, from 9.0.113 through 9.0.115.

Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, …

CWE: CWE-20
GitHub-GHSA

MEDIUM
fast-jwt: Stateful RegExp (/g or /y) causes non-deterministic allowed-claim validation (logical DoS)
GHSA-3j8v-cgw4-2g6q
pkg: fast-jwt
eco: npm
published: Apr 9, 2026
## Impact

Using certain modifiers on RegExp objects in the allowedAud, allowedIss, allowedSub, allowedJti, or allowedNonce options in verify functions can cause certain unintended behaviours. This is because some modifiers are stateful and will cause failures in every second verification attempt re…

CVE-2026-35040
GitHub-GHSA

MEDIUM
LangChain has incomplete f-string validation in prompt templates
GHSA-926x-3r5x-gfhw
pkg: langchain-core, langchain-core
eco: pip
published: Apr 8, 2026
LangChain's f-string prompt-template validation was incomplete in two respects.

First, some prompt template classes accepted f-string templates and formatted them without enforcing the same attribute-access validation as `PromptTemplate`. In particular, `DictPromptTemplate` and `ImagePromptTemplate…

CVE-2026-40087
GitHub-GHSA

MEDIUM
opentelemetry-go: OTLP HTTP exporters read unbounded HTTP response bodies
GHSA-w8rr-5gcm-pp58
pkg: go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp, go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetrichttp, go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp
eco: go
published: Apr 8, 2026
overview:
this report shows that the otlp HTTP exporters (traces/metrics/logs) read the full HTTP response body into an in-memory `bytes.Buffer` without a size cap.

this is exploitable for memory exhaustion when the configured collector endpoint is attacker-controlled (or a network attacker can mit…

CVE-2026-39882
GitHub-GHSA

MEDIUM
LiquidJS: ownPropertyOnly bypass via sort_natural filter — prototype property information disclosure through sorting side-channel
GHSA-rv5g-f82m-qrvv
pkg: liquidjs
eco: npm
published: Apr 8, 2026
### Summary

The `sort_natural` filter bypasses the `ownPropertyOnly` security option, allowing template authors to extract values of prototype-inherited properties through a sorting side-channel attack. Applications relying on `ownPropertyOnly: true` as a security boundary (e.g., multi-tenant templ…

CVE-2026-39412
GitHub-GHSA

MEDIUM
Hono missing validation of cookie name on write path in setCookie()
GHSA-26pp-8wgv-hjvm
pkg: hono
eco: npm
published: Apr 8, 2026
## Summary

Cookie names are not validated on the write path when using `setCookie()`, `serialize()`, or `serializeSigned()` to generate Set-Cookie headers.

While certain cookie attributes such as domain and path are validated, the cookie name itself may contain invalid characters.

This results in…

GitHub-GHSA

MEDIUM
Hono: Middleware bypass via repeated slashes in serveStatic
GHSA-wmmm-f939-6g9c
pkg: hono
eco: npm
published: Apr 8, 2026
## Summary

A path handling inconsistency in `serveStatic` allows protected static files to be accessed by using repeated slashes (`//`) in the request path.

When route-based middleware (e.g., `/admin/*`) is used for authorization, the router may not match paths containing repeated slashes, while s…

CVE-2026-39407
GitHub-GHSA

MEDIUM
@hono/node-server: Middleware bypass via repeated slashes in serveStatic
GHSA-92pp-h63x-v22m
pkg: @hono/node-server
eco: npm
published: Apr 8, 2026
## Summary

A path handling inconsistency in `serveStatic` allows protected static files to be accessed by using repeated slashes (`//`) in the request path.

When route-based middleware (e.g., `/admin/*`) is used for authorization, the router may not match paths containing repeated slashes, while `…

CVE-2026-39406
GitHub-GHSA

MEDIUM
JWCrypto: JWE ZIP decompression bomb
GHSA-fjrm-76×2-c4q4
pkg: jwcrypto
eco: pip
published: Apr 8, 2026
### Summary
The fix for GHSA-j857-7rvv-vj97 in v1.5.6 is weak in that it does not allow to fully control the amount of plaintext the receiver is willing to deal with and provides just a weak upper bound. The patch limits input token size to 250KB but does not validate the decompressed output size. A…
CVE-2026-39373
GitHub-GHSA

MEDIUM
Emissary has a Path Traversal via Blacklist Bypass in Configuration API
GHSA-hxf2-gm22-7vcm
pkg: gov.nsa.emissary:emissary
eco: maven
published: Apr 8, 2026
## Summary

The configuration API endpoint (`/api/configuration/{name}`) validated
configuration names using a blacklist approach that checked for `\`, `/`, `..`,
and trailing `.`. This could potentially be bypassed using URL-encoded variants,
double-encoding, or Unicode normalization to achieve pat…

CVE-2026-35583
GitHub-GHSA

MEDIUM
pyload-ng: Incomplete Tar Path Traversal Fix in UnTar._safe_extractall via os.path.commonprefix Bypass
GHSA-mvwx-582f-56r7
pkg: pyload-ng
eco: pip
published: Apr 8, 2026
## Summary

The `_safe_extractall()` function in `src/pyload/plugins/extractors/UnTar.py` uses `os.path.commonprefix()` for its path traversal check, which performs character-level string comparison rather than path-level comparison. This allows a specially crafted tar archive to write files outside…

CVE-2026-35592
GitHub-GHSA

MEDIUM
OpenViking contains a missing authorization vulnerability in the task polling endpoints
GHSA-h336-2wxm-pr6q
pkg: OpenViking
eco: pip
published: Apr 7, 2026
OpenViking versions prior to 0.3.3 contain a missing authorization vulnerability in the task polling endpoints that allows unauthorized attackers to enumerate or retrieve background task metadata created by other users. Attackers can access the /api/v1/tasks and /api/v1/tasks/{task_id} routes withou…
CVE-2026-22680
NVD

MEDIUM
CVE-2026-34899
CVE-2026-34899
pkg: express

published: Apr 7, 2026

Missing Authorization vulnerability in Eniture technology LTL Freight Quotes – Worldwide Express Edition allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LTL Freight Quotes – Worldwide Express Edition: from n/a through 5.2.1.
CWE: CWE-862
GitHub-GHSA

MEDIUM
Duplicate Advisory: OpenClaw: Gateway Canvas local-direct requests bypass Canvas HTTP and WebSocket authentication
GHSA-9gvx-vj57-vqqx
pkg: openclaw
eco: npm
published: Apr 10, 2026
### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-6mqc-jqh6-x8fc. This link is maintained to preserve external references.

### Original Description
OpenClaw before 2026.3.23 contains an authentication bypass vulnerability in the Canvas gateway where authorize…

GitHub-GHSA

MEDIUM
coursevault-preview has a path traversal due to improper base-directory boundary validation
GHSA-9h9m-rr67-9jpg
pkg: coursevault-preview
eco: npm
published: Apr 8, 2026
## Summary

`coursevault-preview` versions prior to `0.1.1` contain a path traversal vulnerability in the `resolveSafe` utility. The boundary check used `String.prototype.startsWith(baseDir)` on a normalized path, which does not enforce a directory boundary. An attacker who controls the `relativePat…

CVE-2026-35613
GitHub-GHSA

MEDIUM
LobeHub: Unauthenticated authentication bypass on `webapi` routes via forgeable `X-lobe-chat-auth` header
GHSA-5mwj-v5jw-5c97
pkg: @lobehub/lobehub
eco: npm
published: Apr 8, 2026
# Summary

The `webapi` authentication layer trusts a client-controlled `X-lobe-chat-auth` header that is only XOR-obfuscated, not signed or otherwise authenticated. Because the XOR key is hardcoded in the repository, an attacker can forge arbitrary auth payloads and bypass authentication on protect…

CVE-2026-39411
GitHub-GHSA

MEDIUM
OpenFGA's BatchCheck within-request deduplication produces incorrect authorization decisions via list-value cache-key collision
GHSA-jwvj-g8pc-cx45
pkg: github.com/openfga/openfga
eco: go
published: Apr 7, 2026
### Description

In OpenFGA, under specific conditions, BatchCheck calls with multiple checks sent for the same object, relation, and user combination can result in improper policy enforcement.

### Am I affected?

You are affected if you meet the following preconditions:
1. You execute **BatchCheck…

CVE-2026-34972
GitHub-GHSA

MEDIUM
Nodemailer Vulnerable to SMTP Command Injection via CRLF in Transport name Option (EHLO/HELO)
GHSA-vvjj-xcjg-gr5g
pkg: nodemailer
eco: npm
published: Apr 8, 2026
### Summary

Nodemailer versions up to and including 8.0.4 are vulnerable to SMTP command injection via CRLF sequences in the transport `name` configuration option. The `name` value is used directly in the EHLO/HELO SMTP command without any sanitization for carriage return and line feed characters (…

GitHub-GHSA

MEDIUM
Ech0 has Stored XSS via SVG Upload and Content-Type Validation Bypass in File Upload
GHSA-69hx-63pv-f8f4
pkg: github.com/lin-snow/ech0
eco: go
published: Apr 10, 2026
## Summary

The file upload endpoint validates Content-Type using only the client-supplied multipart header, with no server-side content inspection or file extension validation. Combined with an unauthenticated static file server that determines Content-Type from file extension, this allows an admin…

GitHub-GHSA

MEDIUM
Duplicate Advisory: OpenClaw: Synology Chat Webhook Pre-Auth Rate-Limit Bypass Enables Brute-Force Guessing of Webhook Token
GHSA-59xc-5v89-r7pr
pkg: openclaw
eco: npm
published: Apr 10, 2026
### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-mf5g-6r6f-ghhm. This link is maintained to preserve external references.

### Original Description
OpenClaw before 2026.3.25 contains a pre-authentication rate-limit bypass vulnerability in webhook token valida…

GitHub-GHSA

MEDIUM
Duplicate Advisory: OpenClaw Bypasses DM Policy Separation via Synology Chat Webhook Path Collision
GHSA-g8mc-c5f2-mqg7
pkg: openclaw
eco: npm
published: Apr 10, 2026
### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-rqp8-q22p-5j9q This link is maintained to preserve external references.

### Original Description
OpenClaw before 2026.3.22 contains a webhook path route replacement vulnerability in the Synology Chat extension…

GitHub-GHSA

MEDIUM
Hono: Non-breaking space prefix bypass in cookie name handling in getCookie()
GHSA-r5rp-j6wh-rvv4
pkg: hono
eco: npm
published: Apr 8, 2026
## Summary

A discrepancy between browser cookie parsing and `parse()` handling allows cookie prefix protections to be bypassed.

Cookie names that are treated as distinct by the browser may be normalized to the same key by `parse()`, allowing attacker-controlled cookies to override legitimate ones.…

CVE-2026-39410
GitHub-GHSA

MEDIUM
Emissary has Stored XSS via Navigation Template Link Injection
GHSA-cpm7-cfpx-3hvp
pkg: gov.nsa.emissary:emissary
eco: maven
published: Apr 7, 2026
## Summary

Mustache navigation templates interpolated configuration-controlled link values
directly into `href` attributes without URL scheme validation. An administrator
who could modify the `navItems` configuration could inject `javascript:` URIs,
enabling stored cross-site scripting (XSS) agains…

CVE-2026-35571
GitHub-GHSA

MEDIUM
rembg server is vulnerable to Server-Side Request Forgery (SSRF) and a weak default CORS configuration
GHSA-55v6-g8pm-pw4c
pkg: rembg
eco: pip
published: Apr 10, 2026
# GitHub Security Lab (GHSL) Vulnerability Report, rembg: `GHSL-2024-161`, `GHSL-2024-162`

The [GitHub Security Lab](https://securitylab.github.com) team has identified potential security vulnerabilities in [rembg](https://github.com/danielgatis/rembg).

We are committed to working with you to help…

GitHub-GHSA

MEDIUM
DNN: Force Friend Request Acceptance
GHSA-fpj4-9qhx-5m6m
pkg: DotNetNuke.Core
eco: nuget
published: Apr 10, 2026
In the friends feature, a user could craft a request that would force the acceptance of a friend request on another user.
GitHub-GHSA

MEDIUM
Ech0's Missing Authorization on System Logs Allows Non-Admin Information Disclosure
GHSA-w8jj-cwmc-wgq2
pkg: github.com/lin-snow/ech0
eco: go
published: Apr 10, 2026
## Summary

The system log endpoints (`GET /api/system/logs`, `GET /api/system/logs/stream`, `WS /ws/system/logs`) lack authorization checks, allowing any authenticated non-admin user to read and stream all server logs. These logs contain error stack traces, internal file paths, module names, and ar…

GitHub-GHSA

MEDIUM
Vikunja: Scoped API tokens with projects.background permission can delete project backgrounds
GHSA-v479-vf79-mg83
pkg: code.vikunja.io/api
eco: go
published: Apr 10, 2026
### Summary

Vikunja's scoped API token enforcement for custom project background routes is method-confused. A token with only `projects.background` can successfully delete a project background, while a token with only `projects.background_delete` is rejected.

This is a scoped-token authorization b…

CVE-2026-40103
GitHub-GHSA

MEDIUM
Vikunja Missing Authorization on CalDAV Task Read
GHSA-48ch-p4gq-x46x
pkg: code.vikunja.io/api
eco: go
published: Apr 10, 2026
## Summary

The CalDAV `GetResource` and `GetResourcesByList` methods fetch tasks by UID from the database without verifying that the authenticated user has access to the task's project. Any authenticated CalDAV user who knows (or guesses) a task UID can read the full task data from any project on t…

CVE-2026-35598
GitHub-GHSA

MEDIUM
Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug
GHSA-hj5c-mhh2-g7jq
pkg: code.vikunja.io/api
eco: go
published: Apr 10, 2026
## Summary

The `hasAccessToLabel` function contains a SQL operator precedence bug that allows any authenticated user to read any label that has at least one task association, regardless of project access. Label titles, descriptions, colors, and creator information are exposed.

## Details

The acce…

CVE-2026-35596
NVD

MEDIUM
CVE-2026-35642
CVE-2026-35642
pkg: react

published: Apr 9, 2026

OpenClaw before 2026.3.25 contains an authorization bypass vulnerability where group reaction events bypass the requireMention access control mechanism. Attackers can trigger reactions in mention-gated groups to enqueue agent-visible system events that should remain restricted.
CWE: CWE-288
GitHub-GHSA

MEDIUM
Apache OpenMeetings has an Improper Handling of Insufficient Privileges vulnerability
GHSA-78cg-fc6c-w44w
pkg: org.apache.openmeetings:openmeetings-parent
eco: maven
published: Apr 9, 2026
Sny registered user can query web service with their credentials and get files/sub-folders of any folder by ID (metadata only NOT contents). Metadata includes id, type, name and some other field. Full list of fields get be checked at FileItemDTO object.

This issue affects Apache OpenMeetings: fro…

CVE-2026-33005
NVD

MEDIUM
CVE-2026-33005
CVE-2026-33005
pkg: apache

published: Apr 9, 2026

Improper Handling of Insufficient Privileges vulnerability in Apache OpenMeetings.

Any registered user can query web service with their credentials and get files/sub-folders of any folder by ID (metadata only NOT contents). Metadata includes id, type, name and some other field. Full list of fields …

CWE: CWE-274
GitHub-GHSA

MEDIUM
RustFS has an authorization bypass in multipart UploadPartCopy enables cross-bucket object exfiltration
GHSA-mx42-j6wv-px98
pkg: rustfs
eco: rust
published: Apr 8, 2026
RustFS contains a missing authorization check in the multipart copy path (`UploadPartCopy`). A low-privileged user who cannot read objects from a victim bucket can still exfiltrate victim objects by copying them into an attacker-controlled multipart upload and completing the upload.

This breaks ten…

CVE-2026-39360
GitHub-GHSA

MEDIUM
Cosign's verify-blob-attestation reports false positive when payload parsing fails
GHSA-w6c6-c85g-mmv6
pkg: github.com/sigstore/cosign, github.com/sigstore/cosign
eco: go
published: Apr 8, 2026
## Description

`cosign verify-blob-attestation` may erroneously report a "Verified OK" result for attestations with malformed payloads or mismatched predicate types. For old-format bundles and detached signatures, this was due to a logic flaw in the error handling of the predicate type validation. …

CVE-2026-39395
GitHub-GHSA

MEDIUM
Apache ActiveMQ: Improper validation and restriction of a classpath path name
GHSA-h2h4-5m64-m273
pkg: org.apache.activemq:activemq-client, org.apache.activemq:activemq-client, org.apache.activemq:activemq-broker
eco: maven
published: Apr 7, 2026
Improper validation and restriction of a classpath path name vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ Web, Apache ActiveMQ.

In two instances (when creating a Stomp consumer and also browsing messages in the Web console) an authenticated u…

CVE-2026-33227
NVD

MEDIUM
CVE-2026-33227
CVE-2026-33227
pkg: apache

published: Apr 7, 2026

Improper validation and restriction of a classpath path name vulnerability in

Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ Web, Apache ActiveMQ.

In two instances (when creating a Stomp consumer and also browsing messages in the Web console) an authentica…

CWE: CWE-22
GitHub-GHSA

MEDIUM
fast-jwt has a ReDoS when using RegExp in allowed* leading to CPU exhaustion during token verification
GHSA-cjw9-ghj4-fwxf
pkg: fast-jwt
eco: npm
published: Apr 9, 2026
## ⚠️ IMPORTANT CLARIFICATIONS

### Affected Configurations
This vulnerability ONLY affects applications that:
– Use RegExp objects (not strings) in the allowedAud, allowedIss, allowedSub, allowedJti, or allowedNonce options
– Configure patterns susceptible to catastrophic backtracking

CVE-2026-35041
NVD

MEDIUM
CVE-2026-35041
CVE-2026-35041
pkg: express

published: Apr 9, 2026

fast-jwt provides fast JSON Web Token (JWT) implementation. From 5.0.0 to 6.2.0, a denial-of-service condition exists in fast-jwt when the allowedAud verification option is configured using a regular expression. Because the aud claim is attacker-controlled and the library evaluates it against the su…
CWE: CWE-1333
NVD

MEDIUM
CVE-2026-39413
CVE-2026-39413
pkg: jwt

published: Apr 8, 2026

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.4.14, the LightRAG API is vulnerable to a JWT algorithm confusion attack where an attacker can forge tokens by specifying 'alg': 'none' in the JWT header. Since the jwt.decode() call does not explicitly deny the 'none' algo…
CWE: CWE-347
GitHub-GHSA

MEDIUM
lightrag-hku: JWT Algorithm Confusion Vulnerability
GHSA-8ffj-4hx4-9pgf
pkg: lightrag-hku
eco: pip
published: Apr 8, 2026
## Summary
The LightRAG API is vulnerable to a JWT algorithm confusion attack where an attacker can forge tokens by specifying 'alg': 'none' in the JWT header. Since the `jwt.decode()` call does not explicitly deny the 'none' algorithm, a crafted token without a signature will be accepted as valid, …
CVE-2026-39413
GitHub-GHSA

MEDIUM
Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output
GHSA-2g7h-7rqr-9p4r
pkg: code.vikunja.io/api
eco: go
published: Apr 10, 2026
## Summary

The CalDAV output generator builds iCalendar VTODO entries via raw string concatenation without applying RFC 5545 TEXT value escaping. User-controlled task titles containing CRLF characters break the iCalendar property boundary, allowing injection of arbitrary iCalendar properties such a…

CVE-2026-35601
GitHub-GHSA

MEDIUM
parisneo/lollms has an insufficient session expiration vulnerability
GHSA-8jg2-726g-xh43
pkg: lollms
eco: pip
published: Apr 8, 2026
An insufficient session expiration vulnerability exists in the latest version of parisneo/lollms. The application fails to invalidate active sessions after a password reset, allowing an attacker to continue using an old session token. This issue arises due to the absence of logic to reject requests …
CVE-2026-1163
GitHub-GHSA

MEDIUM
kube-router: BGP Peer Passwords Exposed in Logs at Verbose Logging Level
GHSA-fcmh-qfxc-w685
pkg: github.com/cloudnativelabs/kube-router/v2
eco: go
published: Apr 8, 2026
## Summary

When kube-router is configured with per-node BGP peer passwords using the `kube-router.io/peer.passwords` node annotation, and verbose logging is enabled (`–v=2` or higher), the raw Kubernetes node annotation map is logged verbatim — including the base64-encoded BGP MD5 passwords. Any…

GitHub-GHSA

MEDIUM
next-intl has an open redirect vulnerability
GHSA-8f24-v5vv-gm5j
pkg: next-intl
eco: npm
published: Apr 10, 2026
### Impact

Applications using the `next-intl` middleware with `localePrefix: 'as-needed'` could construct URLs where path handling and the WHATWG URL parser resolved a relative redirect target to another host (e.g. scheme-relative `//` or control characters stripped by the URL parser), so the middl…

GitHub-GHSA

MEDIUM
Juju: In-Memory Token Store for Discharge Tokens Lacks Concurrency Safety and Persistence
GHSA-7m55-2hr4-pw78
pkg: github.com/juju/juju
eco: go
published: Apr 10, 2026
### Summary

The localLoginHandlers struct in the Juju API server maintains an in-memory map to store discharge tokens following successful local authentication. This map is accessed concurrently from multiple HTTP handler goroutines without any synchronization primitive protecting it. The absence o…

CVE-2026-5774
GitHub-GHSA

MEDIUM
pypdf: Manipulated XMP metadata entity declarations can exhaust RAM
GHSA-3crg-w4f6-42mx
pkg: pypdf
eco: pip
published: Apr 10, 2026
### Impact

An attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires parsing the XMP metadata.

### Patches
This has been fixed in [pypdf==6.10.0](https://github.com/py-pdf/pypdf/releases/tag/6.10.0).

### Workarounds
If you cannot upgrade yet, conside…

CVE-2026-40260
GitHub-GHSA

MEDIUM
ajenti.plugin.core has race conditions in 2FA
GHSA-8647-755q-fw9p
pkg: ajenti.plugin.core
eco: pip
published: Apr 10, 2026
### Impact

If the 2FA was activated, it was possible during a short moment after the authentication of an user to bypass its authentication.

### Patches

This is fixed in the version 0.112. Users should upgrade to this version as soon as possible.

CVE-2026-40178
GitHub-GHSA

MEDIUM
PraisonAI: SQLiteConversationStore didn't validate table_prefix when constructing SQL queries
GHSA-x783-xp3g-mqhp
pkg: PraisonAI
eco: pip
published: Apr 10, 2026
### Summary

The `table_prefix` configuration value is directly used to construct SQL table identifiers without validation.

If an attacker controls this value, they can manipulate SQL query structure, leading to unauthorized data access (e.g., reading internal SQLite tables such as `sqlite_master`)…

GitHub-GHSA

MEDIUM
justhtml includes multiple security fixes
GHSA-c9vm-hv86-f23r
pkg: justhtml
eco: pip
published: Apr 10, 2026
## Summary

`justhtml` `1.15.0` includes multiple security fixes affecting URL sanitization helpers, HTML serialization, Markdown passthrough, and several custom sanitization-policy edge cases.

These issues have different impact levels and do not all affect the default configuration in the same way…

GitHub-GHSA

MEDIUM
Apache Log4j's JsonTemplateLayout produces invalid JSON output when log events contain non-finite floating-point values
GHSA-w35j-pv5h-q9q9
pkg: org.apache.logging.log4j:log4j-layout-template-json, org.apache.logging.log4j:log4j-layout-template-json
eco: maven
published: Apr 10, 2026
Apache Log4j's JsonTemplateLayout https://logging.apache.org/log4j/2.x/manual/json-template-layout.html , in versions up to and including 2.25.3, produces invalid JSON output when log events contain non-finite floating-point values (NaN, Infinity, or -Infinity), which are prohibited by RFC 8259. Thi…
CVE-2026-34481
GitHub-GHSA

MEDIUM
Apache Log4j Core's XmlLayout fails to sanitize characters
GHSA-3pxv-7cmr-fjr4
pkg: org.apache.logging.log4j:log4j-core, org.apache.logging.log4j:log4j-core
eco: maven
published: Apr 10, 2026
Apache Log4j Core's XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , in versions up to and including 2.25.3, fails to sanitize characters forbidden by the XML 1.0 specification https://www.w3.org/TR/xml/#charsets producing invalid XML output whenever a log message or …
CVE-2026-34480
GitHub-GHSA

MEDIUM
@sveltejs/kit: Unvalidated redirect in handle hook causes Denial-of-Service
GHSA-3f6h-2hrp-w5wx
pkg: @sveltejs/kit
eco: npm
published: Apr 10, 2026
`redirect`, when called from inside the `handle` server hook with a location parameter containing characters that are invalid in a HTTP header, will cause an unhandled `TypeError`. This could result in DoS on some platforms, especially if the location passed to `redirect` contains unsanitized user i…
CVE-2026-40074
GitHub-GHSA

MEDIUM
Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segment
GHSA-hr2v-4r36-88hr
pkg: helm.sh/helm/v4, helm.sh/helm/v3
eco: go
published: Apr 10, 2026
Helm is a package manager for Charts for Kubernetes. In Helm versions <=3.20.1 and <=4.1.3, a specially crafted Chart will cause `helm pull –untar [chart URL | repo/chartname]` to write the Chart's contents to the immediate output directory (as defaulted to the current working directory; or as giv…
CVE-2026-35206
GitHub-GHSA

MEDIUM
Wasmtime has improperly masked return value from `table.grow` with Winch compiler backend
GHSA-f984-pcp8-v2p7
pkg: wasmtime, wasmtime, wasmtime
eco: rust
published: Apr 10, 2026
### Impact

Wasmtime's Winch compiler backend contains a bug where translating the `table.grow` operator causes the result to be incorrectly typed. For 32-bit tables this means that the result of the operator, internally in Winch, is tagged as a 64-bit value instead of a 32-bit value. This invalid i…

CVE-2026-35186
GitHub-GHSA

MEDIUM
Gramps Web API: Private Sub-Object Data in Non-Private Objects Exposed to Guest Users
GHSA-9gjv-jvm7-vv2v
pkg: gramps-webapi
eco: pip
published: Apr 9, 2026
## Summary

Users with the **Guest** role could receive private sub-object data (e.g. private alternate names, private addresses, private note/citation/media handles) through list API endpoints such as `GET /api/people/`, `GET /api/places/`, `GET /api/events/`, and all other object list endpoints.

GitHub-GHSA

MEDIUM
Wasmtime has out-of-bounds write or crash when transcoding component model strings
GHSA-394w-hwhg-8vgm
pkg: wasmtime, wasmtime, wasmtime
eco: rust
published: Apr 9, 2026
### Impact

Wasmtime's implementation of transcoding strings between components contains a bug where the return value of a guest component's `realloc` is not validated before the host attempts to write through the pointer. This enables a guest to cause the host to write arbitrary transcoded string b…

CVE-2026-35195
GitHub-GHSA

MEDIUM
Wasmtime has host panic when Winch compiler executes `table.fill`
GHSA-q49f-xg75-m9xw
pkg: wasmtime, wasmtime, wasmtime
eco: rust
published: Apr 9, 2026
### Impact

Wasmtime's Winch compiler contains a vulnerability where the compilation of the `table.fill` instruction can result in a host panic. This means that a valid guest can be compiled with Winch, on any architecture, and cause the host to panic. This represents a denial-of-service vulnerabili…

CVE-2026-34946
GitHub-GHSA

MEDIUM
Wasmtime segfault or unused out-of-sandbox load with `f64x2.splat` operator on x86-64
GHSA-qqfj-4vcm-26hv
pkg: wasmtime, wasmtime, wasmtime
eco: rust
published: Apr 9, 2026
On x86-64 platforms with SSE3 disabled Wasmtime's compilation of the `f64x2.splat` WebAssembly instruction with Cranelift may load 8 more bytes than is necessary. When [signals-based-traps](https://docs.rs/wasmtime/latest/wasmtime/struct.Config.html#method.signals_based_traps) are disabled this can …
CVE-2026-34944
GitHub-GHSA

MEDIUM
Wasmtime has a possible panic when lifting `flags` component value
GHSA-m758-wjhj-p3jq
pkg: wasmtime, wasmtime, wasmtime
eco: rust
published: Apr 9, 2026
### Impact

Wasmtime contains a possible panic which can happen when a `flags`-typed component model value is lifted with the `Val` type. If bits are set outside of the set of flags the component model specifies that these bits should be ignored but Wasmtime will panic when this value is lifted. Thi…

CVE-2026-34943
GitHub-GHSA

MEDIUM
Wasmtime: Panic when transcoding misaligned utf-16 strings
GHSA-jxhv-7h78-9775
pkg: wasmtime, wasmtime, wasmtime
eco: rust
published: Apr 9, 2026
### Impact

Wasmtime's implementation of transcoding strings into the Component Model's `utf16` or `latin1+utf16` encodings improperly verified the alignment of reallocated strings. This meant that unaligned pointers could be passed to the host for transcoding which would trigger a host panic. This …

CVE-2026-34942
GitHub-GHSA

MEDIUM
Wasmtime: Heap OOB read in component model UTF-16 to latin1+utf16 string transcoding
GHSA-hx6p-xpx3-jvvv
pkg: wasmtime, wasmtime, wasmtime
eco: rust
published: Apr 9, 2026
### Summary

Wasmtime contains a vulnerability where when transcoding a UTF-16 string to the latin1+utf16 component-model encoding it would incorrectly validate the byte length of the input string when performing a bounds check. Specifically the number of code units were checked instead of the byte …

CVE-2026-34941
GitHub-GHSA

MEDIUM
OpenClaw: Multiple Code Paths Missing Base64 Pre-Allocation Size Checks
GHSA-ccx3-fw7q-rr2r
pkg: openclaw
eco: npm
published: Apr 9, 2026
## Impact

Multiple Code Paths Missing Base64 Pre-Allocation Size Checks.

Several base64 decode paths could allocate before enforcing decoded-size limits.

OpenClaw is a user-controlled local assistant. This advisory is scoped to the OpenClaw trust model and does not assume a multi-tenant service b…

GitHub-GHSA

MEDIUM
OpenClaw B-M3: ClawHub package downloads are not enforced with integrity verification
GHSA-3vvq-q2qc-7rmp
pkg: openclaw
eco: npm
published: Apr 9, 2026
## Impact

B-M3: ClawHub package downloads are not enforced with integrity verification.

ClawHub downloads could install plugin archives without enforcing archive or per-file integrity metadata.

OpenClaw is a user-controlled local assistant. This advisory is scoped to the OpenClaw trust model and …

GitHub-GHSA

MEDIUM
OpenClaw Host-Exec Environment Variable Injection
GHSA-w9j9-w4cp-6wgr
pkg: openclaw
eco: npm
published: Apr 9, 2026
## Impact

OpenClaw Host-Exec Environment Variable Injection.

Host exec could inherit environment variables that influence interpreters, shells, or build tools.

OpenClaw is a user-controlled local assistant. This advisory is scoped to the OpenClaw trust model and does not assume a multi-tenant ser…

GitHub-GHSA

MEDIUM
OpenClaw: Strict browser SSRF bypass in Playwright redirect handling leaves private targets reachable
GHSA-w8g9-x8gx-crmm
pkg: openclaw
eco: npm
published: Apr 9, 2026
## Impact

Strict browser SSRF bypass in Playwright redirect handling leaves private targets reachable.

Strict browser SSRF checks could miss Playwright request-time navigation to private targets.

OpenClaw is a user-controlled local assistant. This advisory is scoped to the OpenClaw trust model an…

GitHub-GHSA

MEDIUM
OpenClaw has Browser SSRF Policy Bypass via Interaction-Triggered Navigation
GHSA-vr5g-mmx7-h897
pkg: openclaw
eco: npm
published: Apr 9, 2026
## Impact

Browser SSRF Policy Bypass via Interaction-Triggered Navigation.

Browser interactions could trigger navigations that bypassed the normal SSRF navigation checks.

OpenClaw is a user-controlled local assistant. This advisory is scoped to the OpenClaw trust model and does not assume a multi…

GitHub-GHSA

MEDIUM
OpenClaw `node.pair.approve` placed in `operator.write` scope instead of `operator.pairing` allows unprivileged pairing approval
GHSA-67mf-f936-ppxf
pkg: openclaw
eco: npm
published: Apr 9, 2026
## Impact

OpenClaw `node.pair.approve` placed in `operator.write` scope instead of `operator.pairing` allows unprivileged pairing approval.

The pairing approval method accepted operator.write instead of the narrower pairing scope and admin requirement for exec-capable nodes.

OpenClaw is a user-co…

GitHub-GHSA

MEDIUM
OpenClaw QQ Bot Extension missing SSRF Protection on All Media Fetch Paths
GHSA-3fv3-6p2v-gxwj
pkg: openclaw
eco: npm
published: Apr 9, 2026
## Impact

QQ Bot Extension: Missing SSRF Protection on All Media Fetch Paths.

QQ Bot media download paths were not consistently routed through the SSRF guard and allowlist policy.

OpenClaw is a user-controlled local assistant. This advisory is scoped to the OpenClaw trust model and does not assum…

GitHub-GHSA

MEDIUM
OpenClaw: Existing WS sessions survive shared gateway token rotation
GHSA-5h3f-885m-v22w
pkg: openclaw
eco: npm
published: Apr 9, 2026
## Impact

Existing WS sessions survive shared gateway token rotation.

Rotating the shared gateway token did not disconnect existing shared-token WebSocket sessions.

OpenClaw is a user-controlled local assistant. This advisory is scoped to the OpenClaw trust model and does not assume a multi-tenan…

GitHub-GHSA

MEDIUM
OpenClaw: /allowlist omits owner-only enforcement for cross-channel allowlist writes
GHSA-vc32-h5mq-453v
pkg: openclaw
eco: npm
published: Apr 9, 2026
## Impact

/allowlist omits owner-only enforcement for cross-channel allowlist writes.

An authorized non-owner sender could attempt allowlist writes against a different channel.

OpenClaw is a user-controlled local assistant. This advisory is scoped to the OpenClaw trust model and does not assume a…

GitHub-GHSA

MEDIUM
OpenClaw: resolvedAuth closure becomes stale after config reload
GHSA-68×5-xx89-w9mm
pkg: openclaw
eco: npm
published: Apr 9, 2026
## Impact

resolvedAuth closure becomes stale after config reload.

After a config reload, newly accepted gateway connections could continue using stale resolved auth state.

OpenClaw is a user-controlled local assistant. This advisory is scoped to the OpenClaw trust model and does not assume a mult…

GitHub-GHSA

MEDIUM
OpenClaw `node.invoke(browser.proxy)` bypasses `browser.request` persistent profile-mutation guard
GHSA-cmfr-9m2r-xwhq
pkg: openclaw
eco: npm
published: Apr 9, 2026
## Impact

OpenClaw `node.invoke(browser.proxy)` bypasses `browser.request` persistent profile-mutation guard.

node.invoke(browser.proxy) could mutate persistent browser profiles through a path that bypassed the browser.request guard.

OpenClaw is a user-controlled local assistant. This advisory is…

GitHub-GHSA

MEDIUM
OpenClaw `device.token.rotate` mints tokens for unapproved roles, bypassing device role-upgrade pairing
GHSA-whf9-3hcx-gq54
pkg: openclaw
eco: npm
published: Apr 9, 2026
## Impact

OpenClaw `device.token.rotate` mints tokens for unapproved roles, bypassing device role-upgrade pairing.

Device token rotation could mint or preserve roles/scopes that had not gone through the intended pairing approval.

OpenClaw is a user-controlled local assistant. This advisory is sco…

GitHub-GHSA

MEDIUM
OpenClaw: Shared reply MEDIA – paths are treated as trusted and can trigger cross-channel local file exfiltration
GHSA-qqq7-4hxc-x63c
pkg: openclaw
eco: npm
published: Apr 9, 2026
## Impact

Shared reply MEDIA: paths are treated as trusted and can trigger cross-channel local file exfiltration.

A crafted shared reply MEDIA reference could cause another channel to read a local file path as trusted generated media.

OpenClaw is a user-controlled local assistant. This advisory i…

GitHub-GHSA

MEDIUM
OpenClaw: strictInlineEval explicit-approval boundary bypassed by approval-timeout fallback on gateway and node exec hosts
GHSA-q2gc-xjqw-qp89
pkg: openclaw
eco: npm
published: Apr 9, 2026
## Impact

strictInlineEval explicit-approval boundary bypassed by approval-timeout fallback on gateway and node exec hosts.

The approval-timeout fallback could allow inline eval commands that strictInlineEval was meant to require explicit approval for.

OpenClaw is a user-controlled local assistan…

GitHub-GHSA

MEDIUM
Cryptography vulnerable to buffer overflow if non-contiguous buffers were passed to APIs
GHSA-p423-j2cm-9vmq
pkg: cryptography
eco: pip
published: Apr 8, 2026
If a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. `Hash.update()`), this could lead to buffer overflows. For example:

“`python
h = Hash(SHA256())
b.update(buf[::-1])
“`

would read past the end of the buffer on Python >3.11

CVE-2026-39892
GitHub-GHSA

MEDIUM
quarkus-openapi-generator extension has Zip Slip Path Traversal in ApicurioCodegenWrapper class
GHSA-jx2w-vp7f-456q
pkg: io.quarkiverse.openapi.generator:quarkus-openapi-generator
eco: maven
published: Apr 8, 2026
### Summary
A path traversal vulnerability was discovered in the quarkus-openapi-generator extension

### Details
The `unzip()` method in `ApicurioCodegenWrapper.java` extracts ZIP entries without validating that the resolved file path stays within the intended output directory. At line 101, the des…

CVE-2026-40180
GitHub-GHSA

MEDIUM
pretix: API leaks check-in data between events of the same organizer
GHSA-wr8q-c73g-m7gp
pkg: pretix, pretix, pretix
eco: pip
published: Apr 8, 2026
A new API endpoint introduced in pretix 2025 that is supposed to return all check-in events of a specific event in fact returns all check-in events belonging to the respective organizer. This allows an API consumer to access information for all other events under the same organizer, even those they …
CVE-2026-5600
GitHub-GHSA

MEDIUM
LiquidJS: `renderFile()` / `parseFile()` bypass configured `root` and allow arbitrary file read
GHSA-v273-448j-v4qj
pkg: liquidjs
eco: npm
published: Apr 8, 2026
`liquidjs` 10.25.0 documents `root` as constraining filenames passed to `renderFile()` and `parseFile()`, but top-level file loads do not enforce that boundary.

The published npm package `liquidjs@10.25.0` on Linux 6.17.0 with Node v22.22.1. A `Liquid` instance configured with an empty temporary di…

CVE-2026-39859
GitHub-GHSA

MEDIUM
Hono has incorrect IP matching in ipRestriction() for IPv4-mapped IPv6 addresses
GHSA-xpcf-pg52-r92g
pkg: hono
eco: npm
published: Apr 8, 2026
## Summary

`ipRestriction()` does not canonicalize IPv4-mapped IPv6 client addresses (e.g. `::ffff:127.0.0.1`) before applying IPv4 allow or deny rules. In environments such as Node.js dual-stack, this can cause IPv4 rules to fail to match, leading to unintended authorization behavior.

## Details

CVE-2026-39409
GitHub-GHSA

MEDIUM
Hono: Path traversal in toSSG() allows writing files outside the output directory
GHSA-xf4j-xp2r-rqqx
pkg: hono
eco: npm
published: Apr 8, 2026
## Summary

A path traversal issue in `toSSG()` allows files to be written outside the configured output directory during static site generation. When using dynamic route parameters via `ssgParams`, specially crafted values can cause generated file paths to escape the intended output directory.

## …

CVE-2026-39408
GitHub-GHSA

MEDIUM
openclaw-claude-bridge: sandbox is not effective – `–allowed-tools ""` does not restrict available tools
GHSA-7853-gqqm-vcwx
pkg: openclaw-claude-bridge
eco: npm
published: Apr 8, 2026
## Affected

openclaw-claude-bridge v1.1.0

## Issue

v1.1.0 spawns the Claude Code CLI subprocess with `–allowed-tools ""` and the release notes + README claim this **"disables all CLI tools"** for sandboxing. This claim is incorrect.

Per the Claude Code CLI documentation, `–allowed-tools` (alia…

CVE-2026-39398
GitHub-GHSA

MEDIUM
Parse Server's Endpoint `/sessions/me` bypasses `_Session` `protectedFields`
GHSA-g4v2-qx3q-4p64
pkg: parse-server, parse-server
eco: npm
published: Apr 8, 2026
### Impact

The `GET /sessions/me` endpoint returns `_Session` fields that the server operator explicitly configured as protected via the `protectedFields` server option. Any authenticated user can retrieve their own session's protected fields with a single request. The equivalent `GET /sessions` an…

CVE-2026-39381
GitHub-GHSA

MEDIUM
skilleton has improper input handling in repository/path processing
GHSA-5g3j-89fr-r2vp
pkg: skilleton
eco: npm
published: Apr 8, 2026
## Summary

`skilleton` versions prior to `0.3.1` include security-related weaknesses in repository normalization and path handling logic.
Version `0.3.1` contains fixes and additional test coverage for these issues.

## Affected Versions

`<0.3.1`

## Patched Versions

`>=0.3.1`

## Impact

In af…

GitHub-GHSA

MEDIUM
Parse Server has a login timing side-channel reveals user existence
GHSA-mmpq-5hcv-hf2v
pkg: parse-server, parse-server
eco: npm
published: Apr 8, 2026
### Impact

The login endpoint response time differs measurably depending on whether the submitted username or email exists in the database. When a user is not found, the server responds immediately. When a user exists but the password is wrong, a bcrypt comparison runs first, adding significant lat…

CVE-2026-39321
GitHub-GHSA

MEDIUM
File Browser discloses text file content via /api/resources endpoint bypassing Perm.Download check
GHSA-67cg-cpj7-qgc9
pkg: github.com/filebrowser/filebrowser/v2
eco: go
published: Apr 8, 2026
## Summary

The `resourceGetHandler` in `http/resource.go` returns full text file content without checking the `Perm.Download` permission flag. All three other content-serving endpoints (`/api/raw`, `/api/preview`, `/api/subtitle`) correctly verify this permission before serving content. A user with…

CVE-2026-35606
GitHub-GHSA

MEDIUM
File Browser has an access rule bypass via HasPrefix without trailing separator in path matching
GHSA-5q48-q4fm-g3m6
pkg: github.com/filebrowser/filebrowser/v2
eco: go
published: Apr 8, 2026
Hi,

The `Matches()` function in `rules/rules.go` uses `strings.HasPrefix()` without a trailing directory separator when matching paths against access rules. A rule for `/uploads` also matches `/uploads_backup/`, granting or denying access to unintended directories. Verified against v2.62.2 (commit …

CVE-2026-35605
GitHub-GHSA

MEDIUM
Apache Cassandra has sensitive Information Leak in cqlsh
GHSA-fh34-c629-p8xj
pkg: org.apache.cassandra:cassandra-all
eco: maven
published: Apr 7, 2026
Sensitive Information Leak in cqlsh in Apache Cassandra 4.0 allows access to sensitive information, like passwords, from previously executed cqlsh command via  ~/.cassandra/cqlsh_history local file access.

Users are recommended to upgrade to version 4.0.20, which fixes this issue.


Description…

CVE-2026-27315
GitHub-GHSA

MEDIUM
OpenClaw: Android accepted cleartext remote gateway endpoints and sent stored credentials over ws://
GHSA-83f3-hh45-vfw9
pkg: openclaw
eco: npm
published: Apr 7, 2026
## Summary

Before OpenClaw 2026.4.2, Android accepted non-loopback cleartext `ws://` gateway endpoints and would send stored gateway credentials over that connection. Discovery beacons or setup codes could therefore steer the client onto a cleartext remote endpoint.

## Impact

A user who followed …

GitHub-GHSA

MEDIUM
OpenClaw: Shared-secret comparison call sites leaked length information through timing
GHSA-jj6q-rrrf-h66h
pkg: openclaw
eco: npm
published: Apr 7, 2026
## Summary

Before OpenClaw 2026.4.2, several shared-secret comparison call sites still used early length-mismatch checks instead of the shared fixed-length comparison helper. Those paths could leak secret-length information through measurable timing differences.

## Impact

The affected paths expos…

GitHub-GHSA

MEDIUM
OpenClaw: Zalo replay dedupe keys could suppress messages across chats or senders
GHSA-rxmx-g7hr-8mx4
pkg: openclaw
eco: npm
published: Apr 7, 2026
## Summary

Before OpenClaw 2026.4.2, Zalo webhook replay dedupe keys were not scoped strongly enough across chat and sender dimensions. Legitimate events from different conversations or senders could collide and be dropped as duplicates.

## Impact

Cross-conversation or cross-sender collisions cou…

GitHub-GHSA

MEDIUM
OpenClaw: Trailing-dot localhost CDP hosts could bypass remote loopback protections
GHSA-fh32-73r9-rgh5
pkg: openclaw
eco: npm
published: Apr 7, 2026
## Summary

Before OpenClaw 2026.4.2, remote CDP discovery could return a trailing-dot localhost host such as `localhost.` and bypass OpenClaw's loopback-host normalization. That let a non-loopback remote CDP profile pivot the follow-up connection back onto localhost.

## Impact

A hostile discovery…

GitHub-GHSA

MEDIUM
OpenClaw: pnpm dlx approvals did not bind local script operands
GHSA-w6wx-jq6j-6mcj
pkg: openclaw
eco: npm
published: Apr 7, 2026
## Summary

Before OpenClaw 2026.4.2, `pnpm dlx` approval planning did not bind local script operands the same way as related `pnpm exec` flows. A local script approved through a `pnpm dlx` path could be replaced before execution without invalidating the approval.

## Impact

An operator could appro…

GitHub-GHSA

MEDIUM
OpenClaw: Windows-compatible env override keys could bypass system.run approval binding
GHSA-98ch-45wp-ch47
pkg: openclaw
eco: npm
published: Apr 7, 2026
## Summary

Before OpenClaw 2026.4.2, system-run approval binding normalized environment override keys differently from host execution. Windows-compatible keys could be omitted from the approval binding while still being injected at execution time.

## Impact

An approved command could run with atta…

GitHub-GHSA

MEDIUM
OpenClaw: Gateway hello snapshots exposed host config and state paths to non-admin clients
GHSA-2f7j-rp58-mr42
pkg: openclaw
eco: npm
published: Apr 7, 2026
## Summary

Before OpenClaw 2026.4.2, the Gateway `connect` success snapshot exposed local `configPath` and `stateDir` metadata to non-admin clients. Low-privilege authenticated clients could learn host filesystem layout and deployment details that were not needed for their role.

## Impact

A non-a…

GitHub-GHSA

MEDIUM
OpenClaw: Untrusted workspace channel shadows could execute during built-in channel setup
GHSA-2qrv-rc5x-2g2h
pkg: openclaw
eco: npm
published: Apr 7, 2026
## Summary

Before OpenClaw 2026.4.2, built-in channel setup and login could resolve an untrusted workspace channel shadow before the plugin was explicitly trusted. A malicious workspace plugin that claimed a bundled channel id could execute during channel setup even while still disabled.

## Impact…

GitHub-GHSA

MEDIUM
OpenClaw: Read-scoped identity-bearing HTTP clients could kill sessions via /sessions/:sessionKey/kill
GHSA-5hff-46vh-rxmw
pkg: openclaw
eco: npm
published: Apr 7, 2026
## Summary

Before OpenClaw 2026.4.2, `POST /sessions/:sessionKey/kill` did not enforce write scopes in identity-bearing HTTP modes. A caller limited to read-only operator scopes could still terminate a running subagent session.

## Impact

A read-scoped caller could perform a write-class control-pl…

GitHub-GHSA

MEDIUM
OpenClaw: iOS A2UI bridge trusted generic local-network pages for agent.request dispatch
GHSA-4p4f-fc8q-84m3
pkg: openclaw
eco: npm
published: Apr 7, 2026
## Summary
Before OpenClaw 2026.4.2, the iOS A2UI bridge treated generic local-network pages as trusted bridge origins. A page loaded from a local-network or tailnet host could trigger agent.request dispatch without the stricter trusted-canvas origin check.

## Impact
A loaded attacker-controlled pa…

GitHub-GHSA

MEDIUM
OpenClaw: QQ Bot structured payloads could read arbitrary local files
GHSA-846p-hgpv-vphc
pkg: openclaw
eco: npm
published: Apr 7, 2026
## Summary

Before OpenClaw 2026.4.2, QQ Bot structured media payloads could read local files from attacker-chosen paths. A crafted structured payload could escape QQ Bot-owned media roots and cause arbitrary file reads on the host.

## Impact

Prompt-influenced structured payload output could exfil…

GitHub-GHSA

MEDIUM
OpenClaw: OpenShell mirror mode could delete arbitrary remote directories when roots were mis-scoped
GHSA-m34q-h93w-vg5x
pkg: openclaw
eco: npm
published: Apr 7, 2026
## Summary

Before OpenClaw 2026.4.2, the OpenShell mirror backend accepted arbitrary absolute `remoteWorkspaceDir` and `remoteAgentWorkspaceDir` values. In mirror mode, those paths were then used as the target of remote cleanup and overwrite operations.

## Impact

If an attacker could influence th…

GitHub-GHSA

MEDIUM
OpenClaw: Pairing pending-request caps were enforced per channel instead of per account
GHSA-wwfp-w96m-c6x8
pkg: openclaw
eco: npm
published: Apr 7, 2026
## Summary

Before OpenClaw 2026.3.31, pending pairing-request caps were enforced per channel file instead of per account. On multi-account channel setups, requests from other accounts could fill the shared pending window and block new pairing challenges on an unaffected account.

## Impact

This is…

GitHub-GHSA

MEDIUM
MLflow is vulnerable to Stored Cross-Site Scripting (XSS) caused by unsafe parsing of YAML-based MLmodel artifacts in its web interface
GHSA-fh64-r2vc-xvhr
pkg: mlflow
eco: pip
published: Apr 7, 2026
MLflow is vulnerable to Stored Cross-Site Scripting (XSS) caused by unsafe parsing of YAML-based MLmodel artifacts in its web interface. An authenticated attacker can upload a malicious MLmodel file containing a payload that executes when another user views the artifact in the UI. This allows action…
CVE-2026-33865
GitHub-GHSA

MEDIUM
MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint
GHSA-46r5-x6jq-v8g6
pkg: mlflow
eco: pip
published: Apr 7, 2026
MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint used to download saved model artifacts. Due to missing access‑control validation, a user without permissions to a given experiment can directly query this endpoint and retrieve model artifacts they are not authorized to ac…
CVE-2026-33866