Vulnerability Digest — August 24, 2026 · 63 Critical · 8 Exploited






Vulnerability Digest — Monday, August 24, 2026


Security Report

Monday, August 24, 2026  ·  Last 7 days  ·  Min severity: MEDIUM
Total Findings
398
Critical
63
High
183
Actively Exploited
8
CISA-KEV8
NVD236
GitHub-GHSA154
Findings sorted by severity
CISA-KEV

CRITICAL
Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
CVE-2026-73570
pkg: Synacor Zimbra Collaboration Suite (ZCS)

published: Aug 21, 2026

Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
TrueConf Server Code Injection Vulnerability
CVE-2026-72530
pkg: TrueConf Server

published: Aug 20, 2026

TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
TrueConf Server Missing Authentication for Critical Function Vulnerability
CVE-2026-72529
pkg: TrueConf Server

published: Aug 20, 2026

TrueConf Server contains a missing authentication for critical function vulnerability which could allow a remote unauthorized attacker with network access via port 4307/TCP to execute an arbitrary script.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
MLflow Server-Side Request Forgery Vulnerability
CVE-2026-64849
pkg: MLflow MLflow

published: Aug 19, 2026

MLflow contains a server-side request forgery vulnerability that can allow attackers to reach internal or cloud metadata services and receive response_status and response_body.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability
CVE-2026-33824
pkg: Microsoft Internet Key Exchange (IKE) Service Extensions

published: Aug 18, 2026

Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Microsoft SharePoint Weak Authentication Vulnerability
CVE-2026-55040
pkg: Microsoft SharePoint

published: Aug 18, 2026

Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Apple macOS Improper Authentication Vulnerability
CVE-2026-65400
pkg: Apple macOS

published: Aug 18, 2026

Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Broadcom VMware vCenter Path Traversal Vulnerability
CVE-2026-59310
pkg: Broadcom VMware vCenter

published: Aug 18, 2026

Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
NVD

CRITICAL
CVE-2026-61539
CVE-2026-61539
pkg: express

published: Aug 21, 2026

Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and earlier, Xinference passes attacker-influenced Llama3 tool-call output to eval() in xinference/model/llm/tool_parsers/llama3_tool_parser.py and xinference/model/llm/utils.py. Requests to /v1/chat/comp…
CWE: CWE-95
GitHub-GHSA

CRITICAL
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
GHSA-x2rj-828p-hx9m
pkg: xinference
eco: pip
published: Aug 21, 2026
### Summary

Xinference used Python's unsafe `eval()` function when parsing Llama3 tool-call output generated by a large language model. Because the model output can be influenced by attacker-controlled prompts sent to the chat completion API, a remote attacker can craft prompts that cause the model…

CVE-2026-61539
NVD

CRITICAL
CVE-2026-22306
CVE-2026-22306
pkg: windows

published: Aug 19, 2026

Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext
transmission of sensitive information vulnerability in Ozols Grupa OZOLS
on Windows caused by an abandoned auto-update domain. Affected
component: the automatic update channel – Ozo…
CWE: CWE-319, CWE-494, CWE-829
NVD

CRITICAL
CVE-2026-70921
CVE-2026-70921
pkg: tls

published: Aug 18, 2026

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Hyperion Financial …
CWE: CWE-284
GitHub-GHSA

CRITICAL
kobako Sandbox Escape: guest eval reaches host RCE via method_missing → public_send (any bound Service)
GHSA-7pwq-q9jf-539h
pkg: kobako
eco: rubygems
published: Aug 18, 2026
### Summary
A guest mruby script running inside the Kobako sandbox can execute arbitrary
Ruby in the host process, fully escaping the sandbox.

### Details
A host embeds bound "Service" objects that guest scripts call across the wasm
boundary through the transport dispatcher. The dispatcher passed t…

CVE-2026-55107
GitHub-GHSA

CRITICAL
vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)
GHSA-m5w8-4gq2-6f8x
pkg: vm2
eco: npm
published: Aug 17, 2026
# NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)

**CWE**: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) chained with CWE-732 (Incorrect Permission Assignment for Critic…

NVD

CRITICAL
CVE-2026-63125
CVE-2026-63125
pkg: tls

published: Aug 21, 2026

Incus is a system container and virtual machine manager. Prior to version 7.3.0, an unprivileged, project-confined Incus user (a non-admin TLS/RBAC identity with `can_create_images` and `can_create_instances`) can execute arbitrary code as root on the host. A crafted image ships `backup.yaml` as a s…
CWE: CWE-59, CWE-61
NVD

CRITICAL
CVE-2026-55089
CVE-2026-55089
pkg: oauth

published: Aug 19, 2026

Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad's src/node/handler/APIHandler.ts authorizes requests to /api/2/* in the authorization_code OAuth path by using requiredClaims with the admin claim. This check requires only that the claim exists, while src/node/security/O…
CWE: CWE-863
NVD

CRITICAL
CVE-2026-60995
CVE-2026-60995
pkg: tls

published: Aug 18, 2026

Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via TLS to compromise Oracle Identit…
CWE: CWE-284
NVD

CRITICAL
CVE-2026-60990
CVE-2026-60990
pkg: oracle identity_manager_connector

published: Aug 18, 2026

Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via TLS to compromise Oracle Identit…
CWE: CWE-284
NVD

CRITICAL
CVE-2026-55166
CVE-2026-55166
pkg: tls

published: Aug 18, 2026

Lemur manages TLS certificate creation. Prior to 1.9.2, authenticated users could influence an ACME authority acme_url without an effective server-side destination restriction and trigger AcmeHandler.setup_acme_client to make backend requests. An attacker could target cloud instance metadata or inte…
CWE: CWE-285, CWE-639, CWE-918
NVD

CRITICAL
CVE-2026-47686
CVE-2026-47686
pkg: node

published: Aug 17, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, handleException() in lib/setup-sandbox.js sanitizes SuppressedError.error, SuppressedError.suppressed, and AggregateError.errors but does not sanitize Error.cause, allowing sandbox code to obtain a powerful host object such as process fr…
CWE: CWE-693
GitHub-GHSA

CRITICAL
VM2 has Missing Error.cause Sanitization that Enables Sandbox Escape to RCE
GHSA-m283-3h24-438v
pkg: vm2
eco: npm
published: Aug 17, 2026
**Affected:** vm2 <= 3.11.3
**CVSS 3.1:** 9.9 HIGH (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
**CWE:** CWE-693 (Protection Mechanism Failure)
**Prerequisite:** Embedder exposes a host function that throws an Error with `.cause` referencing a powerful host object (e.g., `process`)

## Summary

I …

CVE-2026-47686
GitHub-GHSA

CRITICAL
GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers
GHSA-mqjf-5f49-2fjh
pkg: org.geotools.jdbc:gt-jdbc-postgis, org.geotools.jdbc:gt-jdbc-postgis, org.geotools.jdbc:gt-jdbc-postgis
eco: maven
published: Aug 21, 2026
### Summary

An SQL Injection Vulnerability has been found when executing OGC Filters with PostGIS DataStore implementation:

* `jsonArrayContains` function
Requires PostGIS 12 or greater with a String or JSON field

For PostGIS 12 and greater `jsonArrayContains(<column>, <pointer>, <value>)` …

CVE-2026-76904
GitHub-GHSA

CRITICAL
surfio has an out-of-bounds read
GHSA-rcr2-hggw-43wm
pkg: surfio
eco: pip
published: Aug 18, 2026
### Impact
Prior to version 0.0.19, surfio would not correctly validate size fields in irap files, leading to a buffer overflow . The severity rating assumes that surfio is used to parse untrused files in a networking context such as a web service.

### Patches
The bug has been patched in version 0…

CVE-2026-55211
GitHub-GHSA

CRITICAL
resdata has Classic Buffer Overflow, Improper Validation of Array Index, NULL Pointer Dereference and Out-of-bounds Read
GHSA-pr85-w493-9w3x
pkg: resdata
eco: pip
published: Aug 18, 2026
### Impact
Prior to version 6.2.9 resdata would not correctly validate input in GRDECL files. The severity rating assumes that resdata is used to parse untrused files in a networking context such as a webservice.

### Patches
The bug has been patched starting with version 6.2.9.

CVE-2026-55209
NVD

CRITICAL
CVE-2026-47627
CVE-2026-47627
pkg: linux

published: Aug 18, 2026

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause path traversal. A successful exploit might lead to denial of service.
CWE: CWE-22
NVD

CRITICAL
CVE-2026-73366
CVE-2026-73366
pkg: go

published: Aug 18, 2026

Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions.
CWE: CWE-502
NVD

CRITICAL
CVE-2026-59940
CVE-2026-59940
pkg: node

published: Aug 18, 2026

Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() allows attacker-controlled JSON Promise control nodes to operate on values from the general deserialization reference table without verifying genuine inte…
CWE: CWE-502, CWE-843
NVD

CRITICAL
CVE-2026-34884
CVE-2026-34884
pkg: express

published: Aug 18, 2026

SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP.

This issue affects Apache SkyWalking MCP: 0.1.0.

Users are recommended to upgrade to version 0.2.0, which fixes this issue.

CWE: CWE-918
NVD

CRITICAL
CVE-2026-38165
CVE-2026-38165
pkg: express

published: Aug 17, 2026

A Server-Side Template Injection (SSTI) vulnerability in the Velocity template engine configuration of xdocreport v0.9.2 to v2.2.0 allows attackers to execute arbitrary code via a crafted expression.
CWE: CWE-94
NVD

CRITICAL
CVE-2026-47698
CVE-2026-47698
pkg: node

published: Aug 17, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, lib/bridge.js and lib/setup-sandbox.js fail to block stacked indirection through Function.prototype.call around dangerous host prototype getter and setter mutators, allowing sandbox code to sever a host intrinsic's prototype chain and re…
CWE: CWE-913
GitHub-GHSA

CRITICAL
vm2: Sandbox Breakout Using Dangerous Host Proto Mutators
GHSA-cfcw-xp6x-25gj
pkg: vm2
eco: npm
published: Aug 17, 2026
### Summary

VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system.

### Details

The fix for https://github.com/patriksimek/vm2/security/advisories/GHSA-v6mx-mf47-r5wg is insuffi…

CVE-2026-47698
NVD

CRITICAL
CVE-2026-74901
CVE-2026-74901
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM decryption failures trigger fallback to unauthenticated AES-CTR mode. Attackers can modify ciphertext in transit to bypass integrity verification and perform bit-flipping attacks without dete…
CWE: CWE-347
NVD

CRITICAL
CVE-2026-74900
CVE-2026-74900
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 contain a critical vulnerability in pqc.py where KEM decapsulation failures silently fall back to simulation mode, generating a deterministic shared secret from only 16 bytes of the private key and publicly available encapsulated key data. Attackers who obtain 1…
CWE: CWE-391
NVD

CRITICAL
CVE-2026-74899
CVE-2026-74899
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecutor that exposes Python type objects in restricted exec() builtins. Attackers can traverse the Python class hierarchy via __class__.__mro__.__subclasses__() to access system functions and execute arbit…
CWE: CWE-95
NVD

CRITICAL
CVE-2026-74896
CVE-2026-74896
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in the DangerousPatternVisitor AST analyzer that fails to detect dunder attribute traversal techniques. Attackers can use __class__, __bases__, __subclasses__(), and __globals__ chains to access restricted functions and exe…
CWE: CWE-693
NVD

CRITICAL
CVE-2026-74895
CVE-2026-74895
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default process isolation mode for plugin execution. Attackers can execute malicious plugins with unrestricted access to the filesystem, network, subprocess execution, and all Python modules.
CWE: CWE-693
NVD

CRITICAL
CVE-2026-74894
CVE-2026-74894
pkg: openssl

published: Aug 17, 2026

openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token function that accepts any non-empty Bearer token string without validation. Attackers can upload arbitrary public keys, enumerate all keys, and revoke keys belonging to any user by providing any Bear…
CWE: CWE-287
NVD

CRITICAL
CVE-2026-74891
CVE-2026-74891
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server configuration files. Attackers on the same network can access PostgreSQL databases using well-known default credentials to retrieve sensitive data.
CWE: CWE-798
NVD

CRITICAL
CVE-2026-74889
CVE-2026-74889
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, reducing entropy extraction and determinism. Attackers can exploit predictable key derivation with identical inputs to weaken cryptographic security against multi-target attacks.
CWE: CWE-326
NVD

CRITICAL
CVE-2026-74886
CVE-2026-74886
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the PluginImportGuard blocks a different set of modules than the AST analyzer's DANGEROUS_MODULES set. Attackers can bypass AST analysis through string obfuscation or encoding to import unblocked dangerous modu…
CWE: CWE-184
NVD

CRITICAL
CVE-2026-74880
CVE-2026-74880
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and telemetry server routes. Attackers can extract tokens from server logs, proxy logs, browser history, and HTTP Referer headers to gain unauthorized access.
CWE: CWE-598
NVD

CRITICAL
CVE-2026-74878
CVE-2026-74878
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection that is not shared across workers and is lost on server restart. Attackers can distribute authentication attempts across multiple server instances or retry immediately after a restart to bypass rate l…
CWE: CWE-770
NVD

CRITICAL
CVE-2026-74876
CVE-2026-74876
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict() that creates key bundles from untrusted data without verifying signatures. Attackers can call from_dict() followed by to_identity() without signature verification to encrypt data using attacker-controlled pu…
CWE: CWE-347
NVD

CRITICAL
CVE-2026-74875
CVE-2026-74875
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema library is not installed, allowing malformed metadata to be accepted. Attackers can remove the jsonschema package or supply unknown metadata format versions to bypass all schema checks and process maliciou…
CWE: CWE-345
NVD

CRITICAL
CVE-2026-74872
CVE-2026-74872
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementation that uses broad glob patterns to load .so modules without integrity verification. Attackers can place malicious .so files matching the whirlpool*py313*.so pattern in site-pack…
CWE: CWE-426
NVD

CRITICAL
CVE-2026-53548
CVE-2026-53548
pkg: jwt

published: Aug 19, 2026

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.6.1, the GET /host/db/host/:id/password endpoint in src/backend/database/routes/host.ts accepts an authenticated user's numeric host ID and the field=password or field=sudoPasswor…
CWE: CWE-285, CWE-639
NVD

CRITICAL
CVE-2026-76036
CVE-2026-76036
pkg: google chrome, google android

published: Aug 18, 2026

Buffer overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-122
NVD

CRITICAL
CVE-2026-76035
CVE-2026-76035
pkg: go

published: Aug 18, 2026

Inappropriate implementation in Media in Google Chrome on on Mac prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-20
NVD

CRITICAL
CVE-2026-12564
CVE-2026-12564
pkg: kubernetes

published: Aug 18, 2026

A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service account token and sends it to an attacker-controlled URL when a HashiCorp Vault Secret Lookup credential w…
CWE: CWE-918
NVD

CRITICAL
CVE-2026-71424
CVE-2026-71424
pkg: oauth

published: Aug 17, 2026

Onyx is an open-source AI platform. Prior to 3.1.10, 3.2.14, and 4.0.0, Onyx's GET /api/mcp/servers and GET /api/mcp/servers/persona/{persona_id} endpoints expose another user's OAuth Authorization header because OnyxTokenStorage.set_tokens and OnyxTokenStorage.set_client_info in backend/onyx/server…
CWE: CWE-200, CWE-863
NVD

CRITICAL
CVE-2026-66794
CVE-2026-66794
pkg: kubernetes

published: Aug 19, 2026

A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker, who can access the user-facing route, to bypass authentication and authorization checks. By manipulating URL path segments, the attacker can proxy req…
CWE: CWE-918
GitHub-GHSA

CRITICAL
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
GHSA-7gwp-5pfp-969j
pkg: mlflow
eco: pip
published: Aug 17, 2026
### Summary
The default MLflow Tracking Server (`mlflow server`, no authentication, default SQLite backend) exposes the model-registry webhooks API unauthenticated, including a synchronous `POST /api/2.0/mlflow/webhooks/{id}/test` endpoint that returns the upstream response status and body to the ca…
CVE-2026-64849
NVD

CRITICAL
CVE-2026-74799
CVE-2026-74799
pkg: go

published: Aug 17, 2026

SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints including heap and goroutine dumps without authentication when –mode flag is not set to exactly prod. Attackers can access /debug/pprof/heap and related endpoints to extract in-memory secrets including AccessAuthCode and AI provider AP…
CWE: CWE-215
NVD

CRITICAL
CVE-2026-77776
CVE-2026-77776
pkg: docker

published: Aug 21, 2026

Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The header is read directly at several points in headroom/proxy/handlers/openai.py, including the chat completion and websocket paths, and nothing binds the value to the caller. A client can therefore name anot…
CWE: CWE-639
GitHub-GHSA

CRITICAL
Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import
GHSA-rrwh-6jrq-wp5v
pkg: github.com/dgraph-io/dgraph/v25
eco: go
published: Aug 20, 2026
## Summary

Dgraph Alpha exposes the RPCs used for external snapshot import on the public gRPC port `:9080` without authentication or authorization. As a result, an unauthenticated network client can open `StreamExtSnapshot` and send Badger stream data to the target group’s store. In addition, the…

CVE-2026-54061
NVD

CRITICAL
CVE-2026-71960
CVE-2026-71960
pkg: jwt

published: Aug 19, 2026

Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnerability in the Mosquitto MQTT broker's authentication plugin that allows unauthenticated attackers to forge valid JWT tokens by extracting the secret from the firmware image. Attackers can use the extr…
CWE: CWE-798
NVD

CRITICAL
CVE-2026-52723
CVE-2026-52723
pkg: tls

published: Aug 18, 2026

ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3.0, ePA 3.x Integration performs VAU server certificate validation in app/vau/VAUProtokoll.py without anchoring the signed_vau_server_pub_keys and AUT_…
CWE: CWE-295
GitHub-GHSA

CRITICAL
New API: Integer overflow in quota billing yields negative charges (self-crediting)
GHSA-8r8v-xf7q-rcpr
pkg: github.com/QuantumNous/new-api
eco: go
published: Aug 17, 2026
## Summary

Multiple billing paths multiplied **user-controlled quantity parameters** into the quota calculation without an upper bound or overflow-safe integer conversion. A crafted extreme value (e.g. image `n = 18446744073686646784`, a wrapped-negative accepted by a `*uint` field) makes conversio…

CVE-2026-71479
GitHub-GHSA

CRITICAL
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation
GHSA-6x2c-phff-wx57
pkg: github.com/QuantumNous/new-api
eco: go
published: Aug 17, 2026
## Vulnerability Information

– **Product**: new-api
– **Affected versions**: versions before `v1.0.0-rc.7` that serialize `User.AccessToken` as `access_token`; the issue was confirmed in `v0.12.14`
– **Patched version**: `v1.0.0-rc.7`
– **Fixed commit**: `0936e2504655a5cbf7bc3c388f6d3e2bb24916d3`
-…

CVE-2026-64859
GitHub-GHSA

CRITICAL
JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions
GHSA-66mm-25pp-rfff
pkg: jsonata, jsonata
eco: npm
published: Aug 21, 2026
Before JSONata `2.2.1` and `1.8.8` it was possible to execute arbitrary code with
crafted expressions, due to:
– overwriting `$clone` allowing mutation of objects via transforms (see
[`evaluateTransformExpression`](https://github.com/jsonata-js/jsonata/blob/8ee4476f8a228bfc7a62979ae0a9c13a4043cd03/s…
CVE-2026-77415
GitHub-GHSA

CRITICAL
JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions
GHSA-2943-5xfg-gq5f
pkg: jsonata, jsonata
eco: npm
published: Aug 21, 2026
Before JSONata `2.2.1` and `1.8.8` it was possible to execute arbitrary code with
crafted expressions, due to a bypassable `hasOwnProperty` check in
`environment.lookup`
https://github.com/jsonata-js/jsonata/blob/8ee4476f8a228bfc7a62979ae0a9c13a4043cd03/src/jsonata.js#L1863-L1871

This was fixed in …

CVE-2026-77414
GitHub-GHSA

CRITICAL
JSONata: Arbitrary Code Execution via crafted JSONata expressions
GHSA-8gq3-vp5j-2grp
pkg: jsonata, jsonata
eco: npm
published: Aug 21, 2026
## Impact

Before JSONata `2.2.0` and `1.8.8` it was possible to execute arbitrary code with crafted expressions, due to a missing `hasOwnProperty` check in the `lookup` function:
https://github.com/jsonata-js/jsonata/blob/f9632e01e6e67d4f9f00593f9795420cb4b57f48/src/functions.js#L1686-L1705

This w…

CVE-2026-77413
GitHub-GHSA

CRITICAL
Qinglong has an incomplete fix for CVE-2026-3965: Improper Authentication
GHSA-v667-gc2r-2xm7
pkg: @whyour/qinglong
eco: npm
published: Aug 20, 2026
### Summary

The init guard middleware in Qinglong only checks `/api/user/init` paths but not `/open/user/init`, which is whitelisted from JWT authentication and rewritten to `/api/user/init` after the guard has already passed, allowing unauthenticated admin credential reset on initialized instances…

CVE-2026-55445
NVD

HIGH
CVE-2026-62675
CVE-2026-62675
pkg: python

published: Aug 21, 2026

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, multipart POST /v1/sessions accepts an authenticated user's agent bundle and omnigent/server/bundles.py validate_agent_bundle does not reject a tools..callable dotted Python path. omnigent…
CWE: CWE-94
NVD

HIGH
CVE-2026-76023
CVE-2026-76023
pkg: linux

published: Aug 20, 2026

Improper resource control in Linux Toolkit Theming in Google Chrome prior to 151.0.7922.173 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-913
NVD

HIGH
CVE-2026-76022
CVE-2026-76022
pkg: go

published: Aug 20, 2026

Buffer overflow in Network in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-122
NVD

HIGH
CVE-2026-76021
CVE-2026-76021
pkg: go

published: Aug 20, 2026

Use after free in DOM in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-76018
CVE-2026-76018
pkg: go

published: Aug 20, 2026

Privilege elevation in Import in Google Chrome prior to 151.0.7922.173 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted file. (Chromium security severity: High)
CWE: CWE-250
NVD

HIGH
CVE-2026-76017
CVE-2026-76017
pkg: go

published: Aug 20, 2026

Use after free in Chromoting in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-73040
CVE-2026-73040
pkg: docker

published: Aug 20, 2026

Dockge validates a stack name only on the write path. In backend/stack.ts the allow-list check in validate(), which requires the name to match ^[a-z0-9_-]+$, is reached from save() alone, while the path getter returns path.join(this.server.stacksDir, this.name) and Stack.getStack builds path.join(se…
CWE: CWE-22
NVD

HIGH
CVE-2026-76832
CVE-2026-76832
pkg: python

published: Aug 19, 2026

Agno's PythonTools in libs/agno/agno/tools/python.py contains a path traversal vulnerability that allows attackers to read, write, or execute arbitrary files by supplying parent-directory traversal sequences in the file_name argument passed to read_file, save_to_file, or run_python_file tool actions…
CWE: CWE-22
NVD

HIGH
CVE-2026-76314
CVE-2026-76314
pkg: splunk splunk

published: Aug 19, 2026

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could perform Remote Code Execution (RCE) by submitting crafted Splunk Web Manager Configuration content. The user could then access all relevant data and affect syste…
CWE: CWE-94
NVD

HIGH
CVE-2026-76259
CVE-2026-76259
pkg: splunk splunk, microsoft windows

published: Aug 19, 2026

In Splunk Enterprise for Windows versions below 10.4.2, 10.2.6, 10.0.9, 9.4.13, and 9.3.14, a local user with access to the Windows host could bind to the management port before Splunk Enterprise starts, intercept authentication tokens from child processes, and use those tokens to compromise all rel…
CWE: CWE-269
NVD

HIGH
CVE-2026-49255
CVE-2026-49255
pkg: windows

published: Aug 19, 2026

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.11.11, electerm constructs operating system commands in src/app/lib/fs.js by interpolating untrusted file paths into the rmrf(), mv(), and cp() functions. A malicious SSH or SFTP server can provide a…
CWE: CWE-78
NVD

HIGH
CVE-2026-44829
CVE-2026-44829
pkg: docker

published: Aug 19, 2026

Gotenberg is a Docker-powered stateless API for PDF files. In 8.32.0 and earlier, filename handling in pkg/modules/api/context.go uses filepath.Base on Linux, which does not treat backslashes as path separators, so a multipart filename containing Windows-style parent directory components survives sa…
CWE: CWE-22
NVD

HIGH
CVE-2026-50191
CVE-2026-50191
pkg: go

published: Aug 18, 2026

4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards is vulnerable to pre-account takeover when registrationEnabled, localRegistrationEnabled, and ssoRegistrationEnabled are enabled and Google, GitHub, Microsoft, or OIDC SSO is configured. The POST /api/register en…
CWE: CWE-287, CWE-288
NVD

HIGH
CVE-2026-76047
CVE-2026-76047
pkg: google chrome

published: Aug 18, 2026

Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-843
NVD

HIGH
CVE-2026-76045
CVE-2026-76045
pkg: google chrome

published: Aug 18, 2026

Use after free in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-76043
CVE-2026-76043
pkg: google chrome

published: Aug 18, 2026

Incorrect calculation in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-682
NVD

HIGH
CVE-2026-76040
CVE-2026-76040
pkg: google chrome, apple macos

published: Aug 18, 2026

Use after free in Browser in Google Chrome on on Mac prior to 151.0.7922.169 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-76038
CVE-2026-76038
pkg: google chrome

published: Aug 18, 2026

Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-843
NVD

HIGH
CVE-2026-76034
CVE-2026-76034
pkg: google chrome

published: Aug 18, 2026

Buffer overflow in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-122
NVD

HIGH
CVE-2026-48508
CVE-2026-48508
pkg: tls

published: Aug 18, 2026

Lemur manages TLS certificate creation. Prior to 1.9.1, StrictRolePermission and AuthorityCreatorPermission in lemur/auth/permissions.py call flask_principal.Permission.__init__() with zero Need objects when ADMIN_ONLY_AUTHORITY_CREATION and LEMUR_STRICT_ROLE_ENFORCEMENT are unset because both flags…
CWE: CWE-863
NVD

HIGH
CVE-2026-61574
CVE-2026-61574
pkg: go

published: Aug 18, 2026

authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the Remote Access Control endpoint list returns every configured endpoint to any authenticated user regardless of which applications the user may access, and the response includes connection settings that can contain stor…
CWE: CWE-639, CWE-863
NVD

HIGH
CVE-2026-66793
CVE-2026-66793
pkg: kubernetes

published: Aug 18, 2026

A flaw was found in the governance-policy-addon-controller component of Red Hat Advanced Cluster Management for Kubernetes. A user with permissions to annotate the namespaced ManagedClusterAddOn resource can override the governance-policy container image. This allows an attacker to run a controlled …
CWE: CWE-20
GitHub-GHSA

HIGH
Glances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command injection
GHSA-73wf-9vmv-5pv9
pkg: glances
eco: pip
published: Aug 17, 2026
## Summary
CVE-2026-32608 ("Command Injection via Process Names in Action Command Templates") was fixed (commit `5680a5d`) by adding `_sanitize_mustache_dict`, which replaces the shell operators `&&`, `|`, `>>`, `>` with spaces in the values rendered into action command templates.

The sanitizer onl…

CVE-2026-62982
NVD

HIGH
CVE-2026-74893
CVE-2026-74893
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 contain hardcoded default JWT signing secrets in config.py that pass validation checks. Attackers with access to source code can forge valid JWT tokens for any client_id to gain authenticated access to keyserver and telemetry APIs.
CWE: CWE-798
NVD

HIGH
CVE-2026-74883
CVE-2026-74883
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability where the plugin sandbox fails to restrict alternative file access methods like pathlib.Path and io.open. Attackers can import pathlib or io modules to read and write arbitrary files, completely bypassing the restricted_ope…
CWE: CWE-693
NVD

HIGH
CVE-2026-74877
CVE-2026-74877
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerability in the revoke_key method that allows authenticated clients to revoke any other client's key. Attackers can revoke arbitrary keys by providing a valid ML-DSA signature, bypassing the intended ownership restri…
CWE: CWE-639
NVD

HIGH
CVE-2026-66787
CVE-2026-66787
pkg: kubernetes

published: Aug 20, 2026

A flaw was found in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability stems from insufficient validation of advertised IP addresses within EndpointSlice objects. A compromised spoke cluster can exploit this by creating EndpointSlices with attacker-con…
CWE: CWE-345
NVD

HIGH
CVE-2026-49283
CVE-2026-49283
pkg: tls

published: Aug 19, 2026

The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.19.3, 4.20.2, 5.0.6, and 6.2.1, the HTTPArtifact::receive() flow can treat an unsigned embedded SAML Response as cryptographically valid for the wrong identity provider. SOAPClient::addSSLValidator(…
CWE: CWE-295
GitHub-GHSA

HIGH
Kestra vulnerable to stored XSS via custom Markdown [[link]] attribute injection
GHSA-34pm-923j-7wf8
pkg: io.kestra:kestra
eco: maven
published: Aug 18, 2026
## Summary

Kestra’s Markdown renderer supports a custom `[[link …]]` syntax that is converted into a custom HTML element. The custom Markdown parser allows attacker-controlled attributes to be rendered into the generated element without proper allowlisting or sanitization.

As a result, a user …

CVE-2026-55839
NVD

HIGH
CVE-2026-74798
CVE-2026-74798
pkg: node

published: Aug 17, 2026

SiYuan kernel before v3.7.4 contains a path traversal vulnerability in the database_clean MCP tool. The tool performs only an empty-string check on the id parameter before passing it to RemoveUnusedAttributeView (kernel/model/attribute_view.go), which builds a filesystem path via filepath.Join witho…
CWE: CWE-22
NVD

HIGH
CVE-2026-75932
CVE-2026-75932
pkg: oauth

published: Aug 21, 2026

Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom domain, edit the authentication configuration, and reroute traffic to the attacker-controlled app. Once connected to the target domain, the attacker's workspace is populated with the victim's OAuth Client…
CWE: CWE-862
NVD

HIGH
CVE-2026-77775
CVE-2026-77775
pkg: docker

published: Aug 21, 2026

Headroom's LLM proxy lets a client choose the upstream destination with the x-headroom-base-url request header. _resolve_openai_upstream_base in headroom/proxy/handlers/openai.py accepts the header value, requires only that it parse with an http or https scheme and a hostname, and returns it for use…
CWE: CWE-918
NVD

HIGH
CVE-2026-75916
CVE-2026-75916
pkg: windows

published: Aug 19, 2026

SiYuan through 3.7.3 contains a cross-site scripting vulnerability in the '((' block-reference autocomplete hint popup. In genHintItemHTML() (app/src/protyle/hint/extend.ts), a candidate block's name, alias, and memo fields are concatenated into the popup's HTML without escaping. An attacker who can…
CWE: CWE-79
NVD

HIGH
CVE-2026-75926
CVE-2026-75926
pkg: node

published: Aug 18, 2026

Hugo 0.161.0 placed the Node asset pipelines behind the Node.js permission model so that code running through PostCSS, Babel, or TailwindCSS could not reach the file system outside the project directory. Hugo 0.162.0 added tailwindcss to the AllowChildProcess default in config/security/securityConfi…
CWE: CWE-1188
GitHub-GHSA

HIGH
9Router: Authenticated Server-Side Request Forgery (SSRF) via OIDC Provider Test Endpoint
GHSA-8g4w-4ffg-8vgx
pkg: 9router
eco: npm
published: Aug 17, 2026
### Summary

A Server-Side Request Forgery (SSRF) vulnerability exists in the 9Router dashboard via the `/api/auth/oidc/test` endpoint. The application accepts a user-controlled URL string through the `issuerUrl` parameter and performs an outbound HTTP request without validating if the destination I…

CVE-2026-56677
NVD

HIGH
CVE-2026-55765
CVE-2026-55765
pkg: kubernetes

published: Aug 20, 2026

CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG embedded cleartext role passwords in `ALTER ROLE` and `CREATE ROLE` statements generated by SetUserPassword in pkg/management/postgres/utils/roles.go and appe…
CWE: CWE-256, CWE-522
NVD

HIGH
CVE-2026-68558
CVE-2026-68558
pkg: express

published: Aug 19, 2026

Wekan is open source kanban built with Meteor. From 8.36 until 9.74, the outgoing webhook Integration URL validator in models/integrations.js checked only the literal URL.hostname against regular expressions, so DNS names such as 169-254-169-254.nip.io passed that first-line check. The delivery path…
CWE: CWE-918
NVD

HIGH
CVE-2026-73410
CVE-2026-73410
pkg: node

published: Aug 17, 2026

Budibase is an open-source low-code platform. Prior to 3.40.0, packages/backend-core/src/utils/outboundFetch.ts pinned a validated address through a Node agent, but the REST integration used getDispatcher from packages/backend-core/src/utils/fetch.ts, causing undici to ignore that agent and resolve …
CWE: CWE-367, CWE-918
NVD

HIGH
CVE-2026-44901
CVE-2026-44901
pkg: python

published: Aug 19, 2026

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta2, AffectedItemsWazuhResult.merge() in framework/wazuh/core/results.py trusts the sort_casting field in a cluster worker's JSON response. During a distributed API merge…
CWE: CWE-502
NVD

HIGH
CVE-2026-76037
CVE-2026-76037
pkg: google chrome, microsoft windows

published: Aug 18, 2026

Link following in CredentialProvider in Google Chrome on on Windows prior to 151.0.7922.169 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
CWE: CWE-59
NVD

HIGH
CVE-2026-76046
CVE-2026-76046
pkg: google chrome, google android

published: Aug 18, 2026

Buffer overflow in ANGLE in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-122
NVD

HIGH
CVE-2026-76044
CVE-2026-76044
pkg: google chrome

published: Aug 18, 2026

Race condition in USB in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-367
GitHub-GHSA

HIGH
MeshCentral has unsanitized data fields
GHSA-c7hr-448w-65px
pkg: meshcentral
eco: npm
published: Aug 18, 2026
### Description

A rogue or compromised MeshAgent can inject arbitrary HTML/JavaScript via the osdesc (OS description) field in its coreinfo message. The server stores this value with zero HTML sanitization (meshagent.js:1903 only checks typeof == 'string'). When an admin views the
device details pa…

NVD

HIGH
CVE-2026-45733
CVE-2026-45733
pkg: node

published: Aug 18, 2026

Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.103.0, the #iconClass label value is returned raw by getNoteIcon() and inserted without HTML attribute encoding into class attributes in apps/client/src/widgets/quic…
CWE: CWE-79, CWE-83, CWE-693
GitHub-GHSA

HIGH
Defuddle vulnerable to XSS via unescaped attribute interpolation in site extractors
GHSA-jg4p-g6xj-4qmf
pkg: defuddle
eco: npm
published: Aug 21, 2026
## Summary

An Improper Neutralization of Input During Web Page Generation issue in the site extractor component allows an attacker-controlled attribute value to be injected into output HTML without escaping. An attacker who crafts a malicious HTML page or controls content on a matching domain can e…

CVE-2026-61824
GitHub-GHSA

HIGH
Pipelines-as-Code GitHub App token request can be redirected via untrusted Enterprise Host header
GHSA-f5f4-3hh4-f54m
pkg: github.com/openshift-pipelines/pipelines-as-code, github.com/openshift-pipelines/pipelines-as-code, github.com/openshift-pipelines/pipelines-as-code
eco: go
published: Aug 20, 2026
## Impact

Pipelines-as-Code installations using the GitHub App provider are vulnerable to GitHub App credential exfiltration through the webhook endpoint.

Affected versions accepted the `X-GitHub-Enterprise-Host` request header as the GitHub Enterprise API host during GitHub App token generation. …

CVE-2026-54167
NVD

HIGH
CVE-2026-49825
CVE-2026-49825
pkg: python

published: Aug 20, 2026

lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in “lxml.html.defs.link_attrs“ were missing “xlink:href“, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_c…
CWE: CWE-79, CWE-184
NVD

HIGH
CVE-2026-63407
CVE-2026-63407
pkg: jwt

published: Aug 19, 2026

Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.0-rc.16, the Grav API plugin CorsMiddleware returns Access-Control-Allow-Origin: * and permissive OPTIONS responses for authenticated /api/v1 endpoints. JavaScript from any origin ca…
CWE: CWE-942
NVD

HIGH
CVE-2026-47719
CVE-2026-47719
pkg: axios

published: Aug 18, 2026

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the DEVICE_WEBAPI_REQUEST and DEVICE_PROPERTY Socket.IO handlers in server/runtime/index.js omit isSocketWriteAuthorized and accept attacker-controlled property.address or endpoint connection data. A remote una…
CWE: CWE-918
NVD

HIGH
CVE-2026-66783
CVE-2026-66783
pkg: kubernetes

published: Aug 18, 2026

A flaw was found in the `submariner-operator` component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability allows a cluster administrator, or any user with permissions to modify the Submariner Custom Resource (CR), to specify an unvalidated image path. This lack of validation …
CWE: CWE-20
NVD

HIGH
CVE-2026-64679
CVE-2026-64679
pkg: go

published: Aug 21, 2026

Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. From 0.19.8 until 0.45.0, Atlantis does not consistently validate user-controlled workspace values supplied through accepted repository-level atlantis.yaml configuration or authenticated /api/pl…
CWE: CWE-22, CWE-73
GitHub-GHSA

HIGH
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation
GHSA-26w5-6g95-gj28
pkg: github.com/runatlantis/atlantis
eco: go
published: Aug 21, 2026
### Summary
Atlantis versions `>= 0.19.8` and `< 0.45.0` did not consistently validate user-controlled `workspace` values before using them to construct local workspace paths.

A crafted workspace value containing path traversal segments could cause Atlantis to resolve workspace paths outside the in…

CVE-2026-64679
NVD

HIGH
CVE-2026-76019
CVE-2026-76019
pkg: go

published: Aug 20, 2026

Incorrect authorization in Workers in Google Chrome prior to 151.0.7922.173 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-863
GitHub-GHSA

HIGH
netty-incubator-codec-ohttp: BoringSSL HPKE private key bytes exposed through toString() and exception messages
GHSA-2mc4-j865-9q4r
pkg: io.netty.incubator:netty-incubator-codec-ohttp-hpke-classes-boringssl
eco: maven
published: Aug 20, 2026
## Summary

`io.netty.incubator:netty-incubator-codec-ohttp-hpke-classes-boringssl` exposes raw HPKE private key bytes in string representations and error messages. `BoringSSLAsymmetricCipherKeyPair.toString()` includes the private-key parameter object, and `BoringSSLAsymmetricKeyParameter.toString(…

CVE-2026-61798
NVD

HIGH
CVE-2026-28150
CVE-2026-28150
pkg: go

published: Aug 20, 2026

Unauthenticated Local File Inclusion in Golo Framework < 1.7.5 versions.
CWE: CWE-98
NVD

HIGH
CVE-2026-15078
CVE-2026-15078
pkg: ibm vios, ibm aix

published: Aug 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to gain unauthorized access to AIX systems due to improper validation of TLS certificates.
CWE: CWE-295
NVD

HIGH
CVE-2026-61265
CVE-2026-61265
pkg: tls

published: Aug 18, 2026

Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component: E1 IOT Orchestrator Security). Supported versions that are affected are 9.2.0.0-9.2.26.4. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise …
CWE: CWE-284
NVD

HIGH
CVE-2026-60992
CVE-2026-60992
pkg: oracle identity_manager_connector

published: Aug 18, 2026

Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Iden…
CWE: CWE-284
GitHub-GHSA

HIGH
Lemur: Unchecked `replaces[]` lets any user silence notifications and hijack auto-rotation for arbitrary certificates
GHSA-cfh6-pv5c-38jv
pkg: lemur
eco: pip
published: Aug 18, 2026
## Summary

Repo under test: https://github.com/Netflix/lemur

The certificate create and upload endpoints accept a `replaces[]` (alias `replacements`) array that is resolved to live `Certificate` ORM objects with no ownership or `CertificatePermission` check on the referenced certificates. The SQLA…

CVE-2026-71308
NVD

HIGH
CVE-2026-71308
CVE-2026-71308
pkg: tls

published: Aug 18, 2026

Lemur manages TLS certificate creation. From 0.5.0 until 1.9.3, certificate create, upload, and edit requests accepted replaces[] or replacements identifiers that AssociatedCertificateSchema resolved with fetch_objects without a CertificatePermission check. Assigning those objects to Certificate.rep…
CWE: CWE-639, CWE-862
NVD

HIGH
CVE-2025-9210
CVE-2025-9210
pkg: jwt

published: Aug 18, 2026

Missing signature validation in JSON Web Tokens in Otalio Ship Property Management System versions before 2.22.0 allows authenticated attackers to escalate privileges via tampering with JWTs
CWE: CWE-347
NVD

HIGH
CVE-2026-50138
CVE-2026-50138
pkg: go

published: Aug 18, 2026

goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, when `goshs` is launched with WebDAV enabled (`-w`), the mode-restriction flags `–read-only`, `–upload-only`, and `–no-delete` are enforced only on the primary HTTP port. The WebDAV port is wired straight to `golang.org/x/net/webd…
CWE: CWE-284
GitHub-GHSA

HIGH
http4k: `DigestAuthProvider.verify` did not bind to request URI
GHSA-p28p-j94q-pg32
pkg: org.http4k:http4k-security-digest, org.http4k:http4k-security-digest, org.http4k:http4k-security-digest
eco: maven
published: Aug 17, 2026
### Impact

An issue in `DigestAuthProvider.verify`:

The `uri` parameter in the client's `Authorization: Digest …` response was not checked against the actual request URL. A captured Digest authentication response could be replayed against any other URL served by the same realm, breaking the per-…

CVE-2026-54148
NVD

HIGH
CVE-2026-54552
CVE-2026-54552
pkg: docker

published: Aug 18, 2026

sh provides Python process launching. Prior to 2.2.4, the _uid option in sh.py performs an incomplete privilege drop on Linux and Unix-like systems. When sh runs from an elevated process and launches a command with _uid set to an unprivileged user, the child changes its UID but can retain the parent…
CWE: CWE-273
NVD

HIGH
CVE-2026-68508
CVE-2026-68508
pkg: python

published: Aug 21, 2026

Hydra is a framework for elegantly configuring complex applications. Prior to 1.3.4, hydra.utils.instantiate() resolves and calls Python objects selected by configuration through _resolve_target() in hydra/_internal/instantiate/_instantiate2.py, allowing attacker-controlled target values and argumen…
CWE: CWE-94, CWE-470
GitHub-GHSA

HIGH
Hydra: hydra.utils.instantiate with untrusted config can lead to code execution
GHSA-2cp2-2r3c-7p7r
pkg: hydra-core
eco: pip
published: Aug 21, 2026
## Summary

`hydra.utils.instantiate()` resolves and calls Python objects from config. If an
application passes untrusted config to `instantiate()`, an attacker who controls
`_target_` and its arguments can cause arbitrary code execution in the consuming
process.

Hydra is not a network service. Exp…

CVE-2026-68508
NVD

HIGH
CVE-2026-54071
CVE-2026-54071
pkg: python

published: Aug 21, 2026

BabelDOC is a document translation tool. Prior to 0.6.3, BabelDOC's vendored PDF parser in babeldoc/pdfminer/cmapdb.py deserializes untrusted pickle data when CMapDB._load_data() loads CMap files. PDF-controlled Encoding or CMapName values and embedded PostScript usecmap operators can reach this sin…
CWE: CWE-502
NVD

HIGH
CVE-2026-18287
CVE-2026-18287
pkg: python

published: Aug 20, 2026

Aeon load_time_series_segmentation_benchmark Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of aeon. User interaction is required to exploit this vulnerability in that the target must visit a maliciou…
CWE: CWE-94
NVD

HIGH
CVE-2026-18286
CVE-2026-18286
pkg: python

published: Aug 20, 2026

Aeon load_human_activity_segmentation_datasets Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of aeon. User interaction is required to exploit this vulnerability in that the target must visit a malici…
CWE: CWE-94
NVD

HIGH
CVE-2026-61898
CVE-2026-61898
pkg: express

published: Aug 20, 2026

The Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accountsservice before 23.13.9-8ubuntu7 treat the user-controlled LANGUAGE entry in ~/.pam_environment as trusted input. The value is interpolated unescaped into a GNU sed replacement expression, allowing an …
CWE: CWE-78
NVD

HIGH
CVE-2026-43961
CVE-2026-43961
pkg: express

published: Aug 19, 2026

A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context during mark/unmark operations, allowing arbitrary Vimscript execution. This can be leveraged to run shell commands with the privileges of the user runni…
CWE: CWE-94
NVD

HIGH
CVE-2026-55426
CVE-2026-55426
pkg: linux

published: Aug 18, 2026

linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses those modules to run external monitoring commands. From the earliest affected releases until linuxfabrik-lib 5.0.0 and Linuxfabrik Monitoring Plugins 6…
CWE: CWE-78
GitHub-GHSA

HIGH
MONAI: Unsafe deserialization in NumpyReader allows arbitrary code execution via malicious .npy files
GHSA-wg9g-w2j2-8pgr
pkg: monai
eco: pip
published: Aug 18, 2026
### Summary

The `NumpyReader` class in `monai/data/image_reader.py` unconditionally uses `np.load(name, allow_pickle=True)` (line 1276), enabling arbitrary code execution when loading a crafted `.npy` or `.npz` file. This affects all MONAI versions up to and including the latest commit (5b71547). T…

GitHub-GHSA

HIGH
Incomplete Fix in MONAI: algo_from_pickle() pickle.loads() RCE still present in v1.5.2 despite GHSA-89gg-p5r5-q6r4 claiming patch
GHSA-qxq5-qhx6-94qw
pkg: monai
eco: pip
published: Aug 18, 2026
## Summary

GHSA-89gg-p5r5-q6r4 claims the pickle deserialization vulnerability in
`algo_from_pickle()` was fixed in v1.5.2. However, `monai/auto3dseg/utils.py`
has not been modified since 2024-07-12 — 18 months before v1.5.2 was released
(2026-01-29). All three `pickle.loads()` calls rema…

NVD

HIGH
CVE-2026-24183
CVE-2026-24183
pkg: linux

published: Aug 18, 2026

NVIDIA Cumulus Linux contains a vulnerability in the user management component, where an unprivileged user could use improper privilege management on the system. A successful exploit of this vulnerability might lead to escalation of privileges.
CWE: CWE-250
NVD

HIGH
CVE-2026-71551
CVE-2026-71551
pkg: node

published: Aug 18, 2026

Super Productivity is an advanced todo list app with integrated timeboxing and time tracking capabilities. Prior to 18.13.0, the EXEC IPC handler in electron/ipc-handlers/exec.ts accepts a command string from the renderer through the IPC.EXEC channel and executes it with child_process.exec(). The el…
CWE: CWE-78
NVD

HIGH
CVE-2026-75858
CVE-2026-75858
pkg: python

published: Aug 18, 2026

CodeWhale (packages codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain a remote code execution vulnerability in the rlm_eval tool. The tool's approval_requirement() returns ApprovalRequirement::Auto, which the engine treats as 'never prompt,' causing arbitrary model-supplied Python c…
CWE: CWE-94
NVD

HIGH
CVE-2026-34399
CVE-2026-34399
pkg: python

published: Aug 17, 2026

FreeCAD is a free and open-source multiplatform 3D parametric modeler. From 0.19 until 1.1.1, FreeCAD's BIM Workbench contains an eval() call on untrusted data from SVG template files. When a user creates a TechDraw page from a malicious SVG template, arbitrary Python code executes. The vulnerable c…
CWE: CWE-95
NVD

HIGH
CVE-2026-34398
CVE-2026-34398
pkg: python

published: Aug 17, 2026

FreeCAD is a free and open-source multiplatform 3D parametric modeler. From 0.19 until 1.1.1, src/Mod/BIM/bimcommands/BimProjectManager.py in the BIM Project Manager Load Template flow passes attacker-controlled FCStd Meta property values for wpposition, wpu, wpv, and wpaxis directly to eval(), allo…
CWE: CWE-95
GitHub-GHSA

HIGH
uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set
GHSA-fhgh-wq4q-r37x
pkg: gitlab.com/uniget-org/cli
eco: go
published: Aug 17, 2026
## Summary

The sigstore check on `metadata.json` is gated on the wrong side of the condition. `LoadMetadata` in `internal/config/update.go:81` verifies the bundle only when `UNIGET_IGNORE_METADATA_SIGNATURE` is non-empty, so in a normal run, where nobody sets that variable, the signature is never c…

GitHub-GHSA

HIGH
node-opcua missing nonce verification in UserNameIdentityToken authentication
GHSA-mq36-523m-x7vv
pkg: node-opcua
eco: npm
published: Aug 20, 2026
**Summary**
A missing nonce verification in the UserNameIdentityToken authentication handler allows an unauthenticated remote attacker to forge a password token that extracts as an empty string, and to replay captured authentication tokens across sessions.

**Affected versions:** <= 2.165.0
**Tested…

CVE-2026-54155
GitHub-GHSA

HIGH
LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure
GHSA-533j-2v4q-mw5h
pkg: langgraph-checkpoint-mongodb, langgraph-store-mongodb
eco: pip
published: Aug 20, 2026
# Executive Summary

A NoSQL injection issue exists in the langgraph-checkpoint-mongodb and
langgraph-store-mongodb libraries. MongoDBSaver.list() and MongoDBStore.search() methods
accept a filter parameter that is incorporated into MongoDB queries without sufficient validation.
Because MongoDB quer…

CVE-2026-55253
NVD

HIGH
CVE-2026-54493
CVE-2026-54493
pkg: docker

published: Aug 19, 2026

Koel is a free, open-source music streaming solution. Prior to 9.7.0, the Subsonic-compatible createInternetRadioStation.view and updateInternetRadioStation.view routes accept an authenticated user's streamUrl without the SafeUrl and HasAudioContentType checks used by the regular radio API. app/Http…
CWE: CWE-918
GitHub-GHSA

HIGH
Contentful MCP Server: export_space/import_space tools pass LLM-controlled `host`/`proxy` args to CMA client, redirecting server PAT to attacker-controlled endpoint
GHSA-2xhg-73j7-rrgx
pkg: @contentful/mcp-server, @contentful/mcp-tools
eco: npm
published: Aug 19, 2026
### Summary

`export_space` and `import_space` tools in `@contentful/mcp-tools` accept LLM-controlled `host` and `proxy` parameters that are spread directly into the options object passed to `contentful-export` / `contentful-import`. These libraries pass the merged options — including the attacker…

CVE-2026-53957
GitHub-GHSA

HIGH
Lemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP password / private-key passphrase) via the destinations API
GHSA-6c8m-q6g9-vrw3
pkg: lemur
eco: pip
published: Aug 18, 2026
### Summary
Lemur's destination read endpoints — `GET /api/1/destinations` and `GET /api/1/destinations/<id>` — return the full set of stored plugin option values to any authenticated user, with no authorization check and no redaction of secret-bearing options. The sibling write endpoints (`POST`/…
CVE-2026-71307
GitHub-GHSA

HIGH
Lemur: Incomplete fix for GHSA-v2wp-frmc-5q3v — ACME authority update endpoint allows non-admin to replace `acme_url` with internal IP, bypassing allowlist
GHSA-v5rc-cpwc-cfpr
pkg: lemur
eco: pip
published: Aug 18, 2026
### Summary

The fix for GHSA-v2wp-frmc-5q3v added `_validate_acme_url()` to reject `acme_url` values not in `ACME_DIRECTORY_HOST_ALLOWLIST`, but the validation is only called at **authority creation time** (POST). The authority **update** endpoint (`PUT /api/1/authorities/<id>`) accepts and stores …

CVE-2026-71303
NVD

HIGH
CVE-2026-71307
CVE-2026-71307
pkg: tls

published: Aug 18, 2026

Lemur manages TLS certificate creation. Prior to 1.9.3, GET /api/1/destinations and GET /api/1/destinations/ relied only on authentication while sibling write handlers required admin_permission. DestinationOutputSchema returned raw options and copied them into pluginOptions without redacting sensiti…
CWE: CWE-862
NVD

HIGH
CVE-2026-71303
CVE-2026-71303
pkg: tls

published: Aug 18, 2026

Lemur manages TLS certificate creation. Prior to 1.9.3, _validate_acme_url enforced ACME_DIRECTORY_HOST_ALLOWLIST when an authority was created, but PUT /api/1/authorities/ passed options to lemur/authorities/service.py without applying the same check. A user holding an authority role could replace …
CWE: CWE-918
NVD

HIGH
CVE-2026-66393
CVE-2026-66393
pkg: python

published: Aug 22, 2026

NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONTaggedDecoder.decode_obj() that allows attackers to cause denial of service by supplying deeply nested JSON structures. Attackers can craft JSON payloads exceeding the recursion limit to trigger an unhandled RecursionErro…
CWE: CWE-674
NVD

HIGH
CVE-2026-62243
CVE-2026-62243
pkg: ssl

published: Aug 22, 2026

Netty (io.netty:netty-handler) versions from 4.2.0.Final through 4.2.16.Final and versions through 4.1.136.Final disable TLS hostname verification on the SslProvider.OPENSSL client path when a plain (non-extended) X509TrustManager is used and Unsafe-based trust-manager wrapping is unavailable (Java …
CWE: CWE-297
GitHub-GHSA

HIGH
kin-openapi openai3filter: nil-pointer panic in ConvertErrors on malformed multipart/form-data body enables unauthenticated DoS
GHSA-mmfr-pmjx-hw9w
pkg: github.com/getkin/kin-openapi
eco: go
published: Aug 21, 2026
### Summary

A nil-pointer dereference in `openapi3filter.ConvertErrors` lets any unauthenticated client crash a server with a single HTTP request. When an application validates a `multipart/form-data` request body and renders the resulting validation error through the library-provided `ValidationEr…

CVE-2026-76905
GitHub-GHSA

HIGH
Keystone vulnerable to `graphql.maxTake` bypass with negative `take`
GHSA-cqmq-8755-7xvh
pkg: @keystone-6/core
eco: npm
published: Aug 21, 2026
# Summary
The value of `graphql.maxTake` can be bypassed by providing a negative input.
This can be used to exceed the developer's intended `graphql.maxTake` value, allowing queries to return results in excess of the `graphql.maxTake` value set.

# Impact
This affects any project relying on `graphql…

CVE-2026-63421
GitHub-GHSA

HIGH
Unleash: Unauthenticated single-request DoS via OpenAPI validation error formatter
GHSA-r5pq-6chh-j3xp
pkg: unleash-server, unleash-server, unleash-server
eco: npm
published: Aug 21, 2026
## Summary

An unauthenticated `POST` to any OpenAPI-validated endpoint, including the anonymous `POST /edge/validate` and `POST /edge/issue-token`, crashes the entire Unleash server with one request body of deeply-nested JSON.

When request-body validation fails, Unleash builds the error message by…

CVE-2026-63462
NVD

HIGH
CVE-2026-47827
CVE-2026-47827
pkg: windows

published: Aug 21, 2026

Command Injection in BOSH CLI tool on windows in Cloud Foundry allows a remote attacker to execute arbitrary shell commands via command injection vulnerabilities
CWE: CWE-77
NVD

HIGH
CVE-2026-72818
CVE-2026-72818
pkg: express

published: Aug 20, 2026

The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and applied by TweetTokenizer.tokenize, contains a naked-domain branch whose domain-label prefix [a-z0-9]+(?:[.\-][a-z0-9]+)* is unbounded. Input consisting of many alternating label separators can be partit…
CWE: CWE-1333
NVD

HIGH
CVE-2026-49217
CVE-2026-49217
pkg: docker

published: Aug 20, 2026

Mailu is a mail server as a set of Docker images. Prior to version 2024.06.52, a missing authorization check in the Mailu admin REST API allows any unauthenticated attacker to remove any potential IP restriction or update the comment field from any existing user token provided the REST API is enable…
CWE: CWE-306
NVD

HIGH
CVE-2026-76020
CVE-2026-76020
pkg: go

published: Aug 20, 2026

Race condition in V8 in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-367
GitHub-GHSA

HIGH
netty-incubator-codec-ohttp BinaryHttpParser: Unauthenticated CPU-exhaustion DoS via infinite loop in field-section decoding
GHSA-4899-mpch-38p3
pkg: io.netty.incubator:netty-incubator-codec-bhttp
eco: maven
published: Aug 20, 2026
# BinaryHttpParser: Unauthenticated CPU-exhaustion DoS via infinite loop in field-section decoding

– **ID:** BHTTP-LOOP-001
– **Severity:** High
– **CVSS v3.1:** 7.5 — `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H`
– **CWE:** CWE-835 (Loop with Unreachable Exit Condition) — secondary CWE-400 (U…

CVE-2026-63202
GitHub-GHSA

HIGH
netty-incubator-codec-ohttp: Binary HTTP parser infinite loop on known-length field section boundary
GHSA-8cfx-wx3q-mh5q
pkg: io.netty.incubator:netty-incubator-codec-bhttp
eco: maven
published: Aug 20, 2026
## Summary

`io.netty.incubator:netty-incubator-codec-bhttp` can enter a non-terminating parse loop when a known-length Binary HTTP field section ends exactly after a complete field line. A remote peer that can send Binary HTTP input to a Netty pipeline using `BinaryHttpParser` / `BinaryHttpDecoder`…

CVE-2026-63124
GitHub-GHSA

HIGH
node-opcua: Unbounded nonce cache enables unauthenticated heap exhaustion DoS
GHSA-6wvw-vrw4-363w
pkg: node-opcua
eco: npm
published: Aug 20, 2026
**Summary**
A process-global nonce cache with no eviction policy allows an unauthenticated remote attacker to exhaust server heap memory by repeatedly opening sessions, causing the node-opcua server process to crash.

**Affected versions:** <= 2.165.0
**Tested version:** 2.165.0
**CVSS Score:** 7.5 …

CVE-2026-54156
GitHub-GHSA

HIGH
vouch-proxy has an Unbounded Multipart Cookie Allocation DoS
GHSA-qqff-5854-px68
pkg: github.com/vouch/vouch-proxy
eco: go
published: Aug 20, 2026
## Unbounded Multipart Cookie Allocation DoS in vouch-proxy

### Summary

vouch-proxy v0.47.2 contains an unauthenticated remote denial-of-service vulnerability in its multipart cookie reassembly logic. The `/validate` endpoint parses the total cookie part count directly from the attacker-controlled…

CVE-2026-55149
NVD

HIGH
CVE-2026-62317
CVE-2026-62317
pkg: express

published: Aug 19, 2026

Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's email subaddressing blocklist in packages/core/src/libraries/sign-in-experience/email-blocklist-policy.ts used the attacker-controlled domain from email input to construct subaddressingRegex when bloc…
CWE: CWE-1333
NVD

HIGH
CVE-2026-16837
CVE-2026-16837
pkg: ssl

published: Aug 19, 2026

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to improper handling of a missing SSL client certificate.
CWE: CWE-400
GitHub-GHSA

HIGH
claude-faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools
GHSA-rr55-jp92-8wp2
pkg: claude-faf-mcp
eco: npm
published: Aug 19, 2026
### Summary
`claude-faf-mcp` MCP tools accept a caller-controlled `path` argument and resolve it (`~` expansion + `path.resolve()`) straight into a filesystem read/write **without confining it to a trusted project directory**. An absolute path or `../` traversal is resolved and used as-is, so the se…
GitHub-GHSA

HIGH
faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools
GHSA-j4r7-8ph4-43g3
pkg: faf-mcp
eco: npm
published: Aug 19, 2026
### Summary
`faf-mcp` MCP tools accept a caller-controlled `path` argument and resolve it (`~` expansion + `path.resolve()`) straight into a filesystem read/write **without confining it to a trusted project directory**. An absolute path or `../` traversal is resolved and used as-is, so the server pr…
GitHub-GHSA

HIGH
grok-faf-mcp has an arbitrary local file read via unconfined `path` argument in FAF tools
GHSA-cc2g-gq8c-r332
pkg: grok-faf-mcp
eco: npm
published: Aug 19, 2026
### Summary
Several `grok-faf-mcp` MCP tools accept a caller-controlled `path` argument and resolve it (`~` expansion + `path.resolve()`) straight into a filesystem read **without confining it to a trusted project directory**. An absolute path or `../` traversal is resolved and used as-is, so the se…
NVD

HIGH
CVE-2026-45798
CVE-2026-45798
pkg: tls

published: Aug 19, 2026

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.5.0 until 4.14.6 and 5.0.0-beta2, compare_wazuh_versions() in src/shared/version_op.c copies the attacker-controlled enrollment V: field into a 10-byte stack buffer with strncpy() but does not explic…
CWE: CWE-121, CWE-170
NVD

HIGH
CVE-2026-63408
CVE-2026-63408
pkg: jwt

published: Aug 19, 2026

Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.0-rc.16, the Grav API plugin JwtAuthenticator::extractBearerToken() accepts a JWT from the token URL query parameter on every /api/v1 route, including state-changing endpoints. Requ…
CWE: CWE-598
NVD

HIGH
CVE-2026-45742
CVE-2026-45742
pkg: docker

published: Aug 19, 2026

Gotenberg is a Docker-powered stateless API for PDF files. From 8.10.0 until 8.33.0, the newContext function in pkg/modules/api/context.go starts one errgroup.Go goroutine for each multipart downloadFrom entry and allows those goroutines to concurrently write to the shared ctx.files, ctx.diskToOrigi…
CWE: CWE-362
NVD

HIGH
CVE-2026-45741
CVE-2026-45741
pkg: docker

published: Aug 19, 2026

Gotenberg is a Docker-powered stateless API for PDF files. In 8.32.0 and earlier, the IsPublicIP function in pkg/gotenberg/outbound.go does not reject the 2002::/16 6to4 prefix, the 64:ff9b::/96 and 64:ff9b:1::/48 NAT64 prefixes, the fec0::/10 deprecated site-local prefix, Teredo, and other transiti…
CWE: CWE-184, CWE-918
NVD

HIGH
CVE-2026-76216
CVE-2026-76216
pkg: jwt

published: Aug 19, 2026

Vikunja through 2.4.0 contains a principal-type confusion vulnerability where LinkSharing principals with id N are treated as user principals with users.id == N at three permission checks lacking type guards. Attackers with a link-share JWT can remove victims from teams, enumerate and delete victim …
CWE: CWE-639
NVD

HIGH
CVE-2019-25766
CVE-2019-25766
pkg: go

published: Aug 19, 2026

Renovate versions >= 13.87.0 and <= 19.38.6 leak temporary repository tokens into pull request comments during certain Go Modules update failure scenarios. The issue is fixed in version 19.38.7. Anyone able to view the affected pull request comments could obtain the exposed tokens.
CWE: CWE-532
NVD

HIGH
CVE-2026-73394
CVE-2026-73394
pkg: express

published: Aug 19, 2026

Unauthenticated Broken Access Control in Stitch Express <= 1.9.0 versions.
CWE: CWE-862
NVD

HIGH
CVE-2026-52829
CVE-2026-52829
pkg: linux

published: Aug 18, 2026

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an unauthenticated IPv4 peer can deterministically terminate a synced Zebra node using the default Linux dual-stack listener configuration. The handshake path canonicalized an IPv4-mapped IPv6 PeerSocketAddr such as ::ffff:127.0.0.1 to …
CWE: CWE-617, CWE-843
NVD

HIGH
CVE-2026-47629
CVE-2026-47629
pkg: linux

published: Aug 18, 2026

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause improper input validation. A successful exploit might lead to denial of service.
CWE: CWE-20
NVD

HIGH
CVE-2026-47628
CVE-2026-47628
pkg: linux

published: Aug 18, 2026

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an allocation of resources without limits. A successful exploit might lead to denial of service.
CWE: CWE-770
NVD

HIGH
CVE-2026-24184
CVE-2026-24184
pkg: linux

published: Aug 18, 2026

NVIDIA Cumulus Linux contains a vulnerability in the Link Layer Discovery Protocol (LLDP) daemon component, where an unauthenticated attacker on an adjacent network could cause buffer overflow by sending crafted LLDP frames. A successful exploit of this vulnerability might lead to code execution.
CWE: CWE-120
GitHub-GHSA

HIGH
GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile data
GHSA-p23g-mvhj-jh3j
pkg: @geolens/sdk, geolens-cli, geolens
eco: npm
published: Aug 18, 2026
### Summary

Multiple GeoLens read/link endpoints authorized only the resource named in the
request URL (a map, a VRT, a source dataset, an AI request) and failed to
re-authorize a **second, caller-influenced dataset** that the request reached
through a relationship, layer reference, mosaic source, …

CVE-2026-55178
NVD

HIGH
CVE-2026-50578
CVE-2026-50578
pkg: tls

published: Aug 18, 2026

ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3.0, ePA 3.x Integration disables TLS certificate verification for both ePA connections in app/vau/VAUProtokoll.py and Konnektor connections in app/konn…
CWE: CWE-295
GitHub-GHSA

HIGH
@rhinostone/swig: arbitrary local file read via include/extends path traversal
GHSA-2mf3-mr2r-r4vf
pkg: @rhinostone/swig, @rhinostone/swig-core, @rhinostone/swig-twig
eco: npm
published: Aug 18, 2026
### Overview

`@rhinostone/swig` is a maintained fork of the abandoned `swig` template engine and inherited the directory-traversal vulnerability tracked upstream as CVE-2023-25345 / GHSA-2rq5-699j-x7p6. The `{% include %}`, `{% extends %}`, and `{% import %}` tags resolve their target path through …

NVD

HIGH
CVE-2026-75915
CVE-2026-75915
pkg: node

published: Aug 18, 2026

CodeWhale versions before 0.8.64 contain an environment variable exposure vulnerability in the js_execution tool that fails to scrub parent process environment variables before spawning Node.js. Attackers can craft malicious JavaScript code executed by the tool to read process.env and leak API keys,…
CWE: CWE-200
NVD

HIGH
CVE-2026-56684
CVE-2026-56684
pkg: tls

published: Aug 18, 2026

Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's tlsProcessPendingData function iterates pending_list while an authenticated client can trigger CLIENT KILL, causing connTLSClose to delete the iterator's cached next node and producing a use-after-…
CWE: CWE-416
NVD

HIGH
CVE-2026-75840
CVE-2026-75840
pkg: express

published: Aug 18, 2026

ArcadeDB before 26.8.1 contains an arbitrary file read vulnerability in the GraalVM JavaScript sandbox allowlist enforcement, which uses unescaped regular expressions to validate package names. Attackers with trigger creation privileges can use Java.type() to access java.util.zip.ZipFile or java.uti…
CWE: CWE-1025
GitHub-GHSA

HIGH
docx4j: Stack Overflow via Cyclic `w:basedOn` Style Chain leads to Denial of Service
GHSA-gc95-3vw8-vg43
pkg: org.docx4j:docx4j-core
eco: maven
published: Aug 17, 2026
### Summary
docx4j's `PropertyResolver` and several adjacent helpers recursively walk the OpenXML style inheritance chain (`w:basedOn`) without cycle detection.

A WordprocessingML document containing a cyclic style chain (for example, Style A based on B and Style B based on A) causes unbounded rec…

CVE-2026-53752
GitHub-GHSA

HIGH
http4k: Unbounded gzip decompression in `ServerFilters.GZip` / `RequestFilters.GunZip` allowed memory-exhaustion DoS
GHSA-g4w2-6h2r-3m3w
pkg: org.http4k:http4k-core, org.http4k:http4k-core, org.http4k:http4k-core
eco: maven
published: Aug 17, 2026
### Impact

`ServerFilters.GZip` and `RequestFilters.GunZip` (and the underlying `Gzip` functions used to decompress request bodies) did not impose any cap on the decompressed size. A small malicious gzip-encoded request body (on the order of kilobytes) could decompress to gigabytes, exhausting the …

CVE-2026-53659
NVD

HIGH
CVE-2026-74238
CVE-2026-74238
pkg: node

published: Aug 17, 2026

TIER IV Nebula through 1.2.0 contains an out-of-bounds read vulnerability in the Vlp32Decoder::unpack() function that allows unauthenticated remote attackers to cause the decoder to read past the end of a received UDP buffer into adjacent heap memory by sending a short UDP datagram. Attackers can se…
CWE: CWE-125
NVD

HIGH
CVE-2026-59893
CVE-2026-59893
pkg: python

published: Aug 17, 2026

sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, SQL_REGEX in sqlparse/keywords.py and the per-position loop in sqlparse/lexer.py repeatedly scan unmatched dollar-quoted literal and multiline-comment delimiters, causing quadratic CPU consumption through sqlparse.parse(), sq…
CWE: CWE-1333
GitHub-GHSA

HIGH
Netty: Memory Exhaustion in SctpMessageCompletionHandler
GHSA-2qj4-mmr9-4v2f
pkg: io.netty:netty-transport-sctp, io.netty:netty-transport-sctp
eco: maven
published: Aug 17, 2026
### Summary
SctpMessageCompletionHandler does not limit the total size of buffered fragments, allowing an unauthenticated attacker to cause an OutOfMemoryError by sending large SCTP fragments.

### Details
`io.netty.handler.codec.sctp.SctpMessageCompletionHandler` buffers fragments for incomplete SC…

CVE-2026-59902
GitHub-GHSA

HIGH
sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial of Service)
GHSA-prg7-hcfm-mfcr
pkg: sqlparse
eco: pip
published: Aug 17, 2026
### Summary

sqlparse contains a Regular Expression Denial of Service (ReDoS) vulnerability in its dollar-quoted SQL literal lexer. The regex pattern at `sqlparse/keywords.py:33` uses a backreference (`\1`) to match closing dollar-quote delimiters, causing O(n²) CPU complexity when processing input…

CVE-2026-59893
GitHub-GHSA

HIGH
vm2 has Memory Exhaustion DoS via bufferAllocLimit Bypass
GHSA-v836-6xw4-9cx3
pkg: vm2
eco: npm
published: Aug 17, 2026
### Summary:

The `bufferAllocLimit` defense (GHSA-6785-pvv7-mvg7) can be completely bypassed using `ArrayBuffer`, `SharedArrayBuffer`, or any `TypedArray` constructor. These allocate identical host-process RSS through the same V8/libuv C++ allocation path as `Buffer.alloc` but are not subject to th…

GitHub-GHSA

HIGH
New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging
GHSA-v828-m3pf-vq9q
pkg: github.com/QuantumNous/new-api
eco: go
published: Aug 17, 2026
## Summary

Unauthenticated payment webhook endpoints could read and log the entire request body before validating the webhook signature. When a payment webhook was enabled, an unauthenticated attacker could send oversized requests to public callback endpoints and force excessive memory use and log …

CVE-2026-64868
NVD

HIGH
CVE-2026-74892
CVE-2026-74892
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 contain a hardcoded default secret key in the standalone telemetry server configuration that is used for API key hashing. Attackers who know this default value can predict or forge API key hashes to compromise telemetry API authentication.
CWE: CWE-798
NVD

HIGH
CVE-2026-74888
CVE-2026-74888
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 use a non-standard PBKDF2 key derivation construction with iterations=1 per call in an outer loop, creating a KDF whose security properties have not been formally analyzed. Attackers can exploit this weakened key derivation to more efficiently crack passwords pr…
CWE: CWE-327
NVD

HIGH
CVE-2026-74884
CVE-2026-74884
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 contain a path traversal vulnerability in the _is_safe_path method where the plugin_id parameter is not sanitized before constructing the plugin config directory path. Attackers can declare a malicious plugin_id containing path traversal sequences like '../' to …
CWE: CWE-73
NVD

HIGH
CVE-2026-74882
CVE-2026-74882
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 contain an insecure default configuration that trusts the entire RFC 1918 private address space in IntegrityProxyConfig trusted_proxies. Attackers on private networks can forge client certificate headers to bypass mTLS authentication when ProxyAuth validation is…
CWE: CWE-345
NVD

HIGH
CVE-2026-74879
CVE-2026-74879
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in the /ready endpoint that returns full database exception strings to unauthenticated callers. Attackers can trigger database errors to extract sensitive information including hostnames, IP addresses, connection p…
CWE: CWE-209
NVD

HIGH
CVE-2026-74874
CVE-2026-74874
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 use Python's non-cryptographic random module for steganographic pixel selection in the generate_pseudorandom_sequence function. Attackers who know the password can recover the Mersenne Twister state from approximately 624 outputs and predict pixel locations cont…
CWE: CWE-338
NVD

HIGH
CVE-2026-78122
CVE-2026-78122
pkg: docker

published: Aug 22, 2026

docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace when the CONTAINERS environment variable is set. Attackers can use GET requests to /containers/{id}/archive, /containers/{id}/export, /containers/{id}/logs, and /containers/{id}/top to read arbitrary fi…
CWE: CWE-1220
NVD

HIGH
CVE-2026-62960
CVE-2026-62960
pkg: windows

published: Aug 21, 2026

Git for Windows is the Windows port of Git. Prior to 2.55.0.windows.4, a malicious remote Git server can advertise a bundle URI that reaches transport_get_remote_bundle_uri(), fetch_bundle_uri_internal(), and copy_uri_to_file() in bundle-uri.c during clone or fetch when transfer.bundleuri=true. Non-…
CWE: CWE-200, CWE-610
GitHub-GHSA

HIGH
Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs
GHSA-xpmj-wjcp-6pww
pkg: lemur
eco: pip
published: Aug 18, 2026
### Summary
The ACME client (used to issue certificates from Let's Encrypt / Google Public CA / private ACME CAs) connects to an `acme_url`, then issues requests to URLs that the **ACME server returns** in its directory/order/authorization/finalize responses – this is the classic ACME-client SSRF (R…
CVE-2026-70666
NVD

HIGH
CVE-2026-70666
CVE-2026-70666
pkg: tls

published: Aug 18, 2026

Lemur manages TLS certificate creation. Prior to 1.9.3, an authority-role member could update acme_url through PUT /api/1/authorities/ without revalidation and direct setup_acme_client_no_retry to an attacker-controlled ACME server. ACME directory and order responses contain newNonce, newOrder, auth…
CWE: CWE-918
NVD

HIGH
CVE-2026-59825
CVE-2026-59825
pkg: ssl

published: Aug 18, 2026

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.19 and from 4.5.0 until 4.5.12, Mastodon's app/models/concerns/user/ldap_authenticable.rb mutates OpenSSL::SSL::SSLContext::DEFAULT_PARAMS when LDAP authentication uses LDAP_TLS_NO_VERIFY=true, disabling SSL and…
CWE: CWE-295
NVD

HIGH
CVE-2026-78062
CVE-2026-78062
pkg: jwt

published: Aug 23, 2026

A vulnerability was identified in vas3k TaxHacker up to 0.8.2. The affected element is the function envSchema.parse of the file lib/config.ts of the component JWT Secret Handler. The manipulation of the argument BETTER_AUTH_SECRET leads to hard-coded credentials. The attack can be initiated remotely…
CWE: CWE-259, CWE-798
GitHub-GHSA

HIGH
Wagtail: Reflected XSS in dynamic image URL generator view
GHSA-23m2-mghx-vqmf
pkg: wagtail, wagtail
eco: pip
published: Aug 20, 2026
### Impact

A reflected cross-site scripting (XSS) vulnerability exists on the dynamic image URL generator view within the Wagtail admin interface. A user with a limited-permission editor account for the Wagtail admin could craft a URL that, when viewed by a user with higher privileges, could perfor…

CVE-2026-54263
GitHub-GHSA

HIGH
Lemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate record and revoking it
GHSA-pxmc-2ffp-8j67
pkg: lemur
eco: pip
published: Aug 18, 2026
## Summary

Repo under test: https://github.com/Netflix/lemur

`PUT /api/1/certificates/<id>/revoke` authorizes the caller against the *Lemur database row* (creator == current user, or `CertificatePermission` over the row's roles) rather than the underlying CA-side certificate identity. Separately, …

CVE-2026-71417
NVD

HIGH
CVE-2026-71417
CVE-2026-71417
pkg: tls

published: Aug 18, 2026

Lemur manages TLS certificate creation. Prior to 1.9.3, POST /api/1/certificates/upload allowed a non-read-only user to create a duplicate row using another certificate body, authority_id, serial, or external_id without requiring permission on the underlying authority. PUT /api/1/certificates//revok…
CWE: CWE-639
NVD

HIGH
CVE-2026-32657
CVE-2026-32657
pkg: node

published: Aug 18, 2026

Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Version 3.0.1, Dell VxRail Version 8.0.322, Dell PowerMax Version 10.3.0, Dell Unity Version 5.4, Dell PowerFlex Manager Version 4.5.4, Dell PowerFlex Intelligent Catalog Versions 46.377.00 and 46.382.00 and Dell PowerFlex Ra…
CWE: CWE-61
GitHub-GHSA

HIGH
GeoServer has a Server-Side Template Injection (SSTI) vulnerability in processing FreeMarker templates
GHSA-wf6j-gr27-g7ch
pkg: org.geoserver:gs-main, org.geoserver:gs-wms, org.geoserver.web:gs-web-app
eco: maven
published: Aug 19, 2026
### Summary
A server-side template injection (SSTI) vulnerability exist that allows an authenticated administrator to upload FreeMarker templates containing malicious content that can execute OS commands and read from or write to arbitrary files on the server. These FreeMarker templates are used in …
CVE-2024-45747
GitHub-GHSA

HIGH
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
GHSA-w47q-945m-q9pc
pkg: document-merge-service
eco: pip
published: Aug 19, 2026
### Impact
A remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server's context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container. The vulnera…
CVE-2026-53964
NVD

HIGH
CVE-2026-15780
CVE-2026-15780
pkg: go

published: Aug 19, 2026

The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_campaign' parameter in all versions up to, and including, 14.16.8 due to insufficient input sanitization and output escaping. This makes it possi…
CWE: CWE-79
NVD

HIGH
CVE-2026-73367
CVE-2026-73367
pkg: go

published: Aug 18, 2026

Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions.
CWE: CWE-829
NVD

HIGH
CVE-2026-55013
CVE-2026-55013
pkg: windows

published: Aug 20, 2026

Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locally.
CWE: CWE-427
NVD

HIGH
CVE-2026-54616
CVE-2026-54616
pkg: windows

published: Aug 20, 2026

NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 1.0.88.0 until stable version 6.0.1698.0 and preview version 6.5.1742.0, the Lz4Decode function in NanaZip.Core/SevenZip/CPP/7zip/Archive/SquashfsHandler.cpp rejects only a zero return from LZ4_decompress_safe e…
CWE: CWE-125
NVD

HIGH
CVE-2026-17183
CVE-2026-17183
pkg: express

published: Aug 19, 2026

An authenticated user with permission to create or edit alert rules can bypass datasource query authorization by marking an alert rule query as a server-side expression while referencing a real datasource UID (incorrect authorization). This can expose data accessible through Grafana's configured dat…
CWE: CWE-863
NVD

HIGH
CVE-2026-28569
CVE-2026-28569
pkg: ssl

published: Aug 18, 2026

Unauthenticated Cross Site Scripting (XSS) in SSL Zen <= 4.7.43 versions.
CWE: CWE-79
GitHub-GHSA

HIGH
MLflow: CreateModelVersion source validation does not check READ permission on referenced run_id
GHSA-gqch-g4w5-7qcw
pkg: mlflow
eco: npm
published: Aug 17, 2026
### Summary

The `_validate_source_run` and `_validate_source_model` functions in `mlflow/server/handlers.py` verify that a model version source path is within the artifact directory of a specified run or logged model, but do not check whether the caller has READ permission on that run or model. An …

CVE-2026-69148
GitHub-GHSA

HIGH
Medplum: Improper Validation of Redirect URI in External Auth Callback allows Authorization Code Leakage
GHSA-m44r-7c5h-m6mj
pkg: @medplum/core
eco: npm
published: Aug 17, 2026
## Summary

The external identity provider callback at `GET /auth/external` accepts attacker-controlled redirect URIs that only need to start with a registered client redirect URI, rather than matching exactly. After a successful external IdP login, the server appends Medplum `login` and `code` valu…

CVE-2026-53728
NVD

HIGH
CVE-2026-62727
CVE-2026-62727
pkg: windows

published: Aug 19, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CWE: CWE-362
NVD

HIGH
CVE-2026-75857
CVE-2026-75857
pkg: python

published: Aug 18, 2026

CodeWhale versions >= 0.8.41 and < 0.8.64 contain a vulnerability in the exec_shell_interact (alias exec_interact) tool, whose approval_requirement returns ApprovalRequirement::Auto. This overrides the default Required approval for code-executing tools, so LLM-controlled stdin is written into an alr…
CWE: CWE-269
NVD

HIGH
CVE-2026-34789
CVE-2026-34789
pkg: python

published: Aug 17, 2026

FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, src/App/PropertyPythonObject.cpp in PropertyPythonObject::Restore() passes the attacker-controlled module attribute from serialized PropertyPythonObject XML directly to PyImport_ImportModule() while restoring a cr…
CWE: CWE-94
GitHub-GHSA

HIGH
kin-openapi has uncontrolled resource consumption in openapi3filter deepObject query parameter decoding
GHSA-xhj3-7xw9-vr34
pkg: github.com/getkin/kin-openapi
eco: go
published: Aug 21, 2026
### Summary

An uncontrolled resource consumption vulnerability in `openapi3filter` lets any unauthenticated client force multi-gigabyte heap allocation with a single, tiny HTTP request. When a spec declares a `deepObject`-style query parameter whose schema contains an array (a normal, documented pa…

CVE-2026-77354
GitHub-GHSA

HIGH
netty-incubator-codec-ohttp: BinaryHttpParser should enforce limits for variable lengths fields
GHSA-hmq9-67w8-j5pw
pkg: io.netty.incubator:netty-incubator-codec-bhttp
eco: maven
published: Aug 20, 2026
We don't enforce any limits for the encoded variable lengths that are used for fields. As the remote peer controls these it's easy for the remote peer to have us buffer data forever and so ultimately OOM.
CVE-2026-61827
GitHub-GHSA

HIGH
NocoBase: Arbitrary File Write chained with Local file Inclusion leads to Remote code execution
GHSA-ghvf-qf6h-g8x5
pkg: @nocobase/server
eco: npm
published: Aug 20, 2026
## Executive Summary

Two vulnerabilities were identified and chained to achieve authenticated remote code execution

The first vulnerability allows any authenticated admin to redirect the file upload storage root to an arbitrary path on disk including the application directory itself by supplying…

GitHub-GHSA

HIGH
netty-incubator-codec-ohttp: [OHttpServerCodec] Native Direct-Memory Leak on AEAD Decryption Failure Leads to Gateway Denial of Service
GHSA-vmr9-j6wf-pmh2
pkg: io.netty.incubator:netty-incubator-codec-ohttp
eco: maven
published: Aug 20, 2026
The **netty-incubator-codec-ohttp** library implements Oblivious HTTP (OHTTP) gateway and client functionality using Netty's `ByteBuf` memory management. When an OHTTP gateway processes encrypted client requests, it allocates a pooled direct (native off-heap) `ByteBuf` to hold the decrypted plaintex…
CVE-2026-54251
GitHub-GHSA

HIGH
Fleet: SQL injection in Okta conditional access endpoint allows host-controlled compromise of the Fleet database
GHSA-7q96-f8xw-jv5j
pkg: github.com/fleetdm/fleet
eco: go
published: Aug 20, 2026
### Summary

A SQL injection vulnerability in Fleet's Okta conditional access integration could allow an attacker who controls a single enrolled host to read or modify arbitrary data in the Fleet database, including stored session tokens. Disclosed session tokens may be replayed to act as a global a…

CVE-2026-54245
GitHub-GHSA

HIGH
logto-tunnel serves files outside –experience-path via path traversal
GHSA-rxjr-6c9q-h67x
pkg: @logto/tunnel
eco: npm
published: Aug 19, 2026
### Summary

`@logto/tunnel` serves custom sign-in experience files from the `–experience-path` directory. When the tunnel service is reachable, a requester can use `../` path segments in a static asset request to read files outside that directory that the CLI process can read.

### Details

The tu…

CVE-2026-63188
GitHub-GHSA

HIGH
GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)
GHSA-p77j-g7h5-r2vw
pkg: geolens
eco: pip
published: Aug 19, 2026
GeoLens 1.2.4 fixes a set of vulnerabilities, the most serious of which allow authenticated or anonymous users to obtain data and metadata for datasets they are not authorized to access.

### Impact

– **Private record metadata disclosure.** Record contact, keyword, and distribution sub-resource end…

GitHub-GHSA

HIGH
XWiki Platform Live Data Live Table Connector has privilege escalation from edit to script right through Live Data editing
GHSA-45ph-gxxr-gwgw
pkg: org.xwiki.platform:xwiki-platform-livedata-livetable, org.xwiki.platform:xwiki-platform-livedata-livetable, org.xwiki.platform:xwiki-platform-livedata-livetable
eco: maven
published: Aug 19, 2026
### Impact
Any user who can edit a page in XWiki can use Live Data's edit REST API in XWiki to change the rights on that page. This allows the user to obtain script right on the page. Script right allows the user to execute potentially dangerous Velocity scripts and send unfiltered HTML and JavaScri…
CVE-2026-53966
GitHub-GHSA

HIGH
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
GHSA-9gmc-jqmh-3rvm
pkg: copier
eco: pip
published: Aug 19, 2026
# Copier: trust-prefix bypass via path traversal runs tasks unprompted

### Summary

In copier `>= 9.5.0, <= 9.15.1`, the `trust` setting's prefix match
(`copier/_settings.py`) compares the template URL against a trusted prefix with
a raw `str.startswith` and **no path normalization**, while the URL…

CVE-2026-53951
GitHub-GHSA

HIGH
moby/go-archive: Crafted tar archive can write outside the extraction directory
GHSA-hfg8-hc9c-6c3h
pkg: github.com/moby/go-archive
eco: go
published: Aug 18, 2026
### Summary
The tar extraction routines in `moby/go-archive` (`Unpack`, `UnpackLayer`, `Untar`/`UntarUncompressed`, and the `ApplyLayer` helpers) do not confine filesystem operations to the destination directory. A crafted archive can create or overwrite files **outside** the intended destination.
CVE-2026-17106
GitHub-GHSA

HIGH
MONAI vulnerable to OS command injection
GHSA-rghg-q7wp-9767
pkg: MONAI
eco: pip
published: Aug 18, 2026
### Comment from JPCERT/CC
We are submitting the report again as we have yet to receive
any responses from you after submitting it on February 5 and March 11.

It would be greatly appreciated if you could send us a message
after confirming it so that we can follow up the case by email.

### Summary

GitHub-GHSA

HIGH
RabbitMQ Java client: Unvalidated Class.forName in JSON-RPC ProcedureDescription enables arbitrary class loading
GHSA-6g32-pxv4-2wfj
pkg: com.rabbitmq:amqp-client
eco: maven
published: Aug 18, 2026
The JSON-RPC tools in `com.rabbitmq.tools.jsonrpc` perform `Class.forName(javaReturnType)` with `initialize=true` on class names received from untrusted AMQP messages, without any validation or allowlist.

**Vulnerable code** (`ProcedureDescription.java:101-127`):
When a `JsonRpcClient` connects, it…

CVE-2026-63337
GitHub-GHSA

HIGH
RabbitMQ Java client ValueReader: Oversized LongString/bytes length triggers OOM via unchecked allocation
GHSA-68mj-5wr7-6fgg
pkg: com.rabbitmq:amqp-client
eco: maven
published: Aug 18, 2026
## Summary

`ValueReader.readBytes()` allocates a byte array sized by a wire-declared content length without validating it against actual frame data. A malicious AMQP peer triggers OOM by declaring a ~2GB string/bytes field.

## Vulnerable Code

`src/main/java/com/rabbitmq/client/impl/ValueReader.ja…

CVE-2026-69219
GitHub-GHSA

HIGH
RabbitMQ Java client ValueReader: Unbounded recursive table/array nesting causes StackOverflowError DoS
GHSA-93j5-89vc-pph4
pkg: com.rabbitmq:amqp-client
eco: maven
published: Aug 18, 2026
## Summary

`ValueReader.readTable()` and `readArray()` recursively call `readFieldValue()` with no depth limit. A malicious AMQP peer can crash the client JVM by sending a deeply nested table structure.

## Vulnerable Code

`src/main/java/com/rabbitmq/client/impl/ValueReader.java` lines 139-155 and…

CVE-2026-69220
GitHub-GHSA

HIGH
atomic-agents-stack: Parallel helper/delegate batch reserves $0 for models absent from the pricing table, bypassing the cost-cap fan-out guard
GHSA-j659-8xh6-5pq5
pkg: atomic-agents-stack
eco: pip
published: Aug 17, 2026
`_estimate_batch_cost` (`atomic_agents/agent.py`) looks up the per-model output price with `PRICING.get(model, {})`, returning 0.0 for any model not in the hardcoded pricing table. `_check_batch_reservation` then early-returns when the reservation is <= 0, skipping the batch reservation entirely. Th…
GitHub-GHSA

HIGH
atomic-agents-stack: HTTP MCP catalog accepts cleartext http and spawns catalog-supplied commands (MITM to RCE)
GHSA-xhcr-cqfr-m3hv
pkg: atomic-agents-stack
eco: pip
published: Aug 17, 2026
The HTTP MCP server-registry backend factory (`atomic_agents/mcp_registry/http.py`, `make_http_mcp_server_registry_backend_from_url`) accepts both `http` and `https` schemes. Catalog entries carry `command`/`args` that are type-validated but content-unrestricted, and are later spawned as local stdio…
GitHub-GHSA

HIGH
sqlparse: TokenList.__init__ materializes O(subtree) value per group, causing CPU DoS before depth/token caps trigger
GHSA-pwgv-4x5q-6m9f
pkg: sqlparse
eco: pip
published: Aug 17, 2026
### Summary

`sqlparse` ships hard limits (`MAX_GROUPING_DEPTH=100`, `MAX_GROUPING_TOKENS=10000`) intended to bound parsing work on attacker-supplied SQL, but the path that *reaches* those limits is itself `O(n*depth)` per token-group construction. A ~1-2 KB SQL payload (e.g. `SELECT (((((1))))) ……

CVE-2026-54284
GitHub-GHSA

HIGH
Etherpad has stored XSS in HTML export via unescaped attribute-pool values
GHSA-2jp7-wwpg-3p9w
pkg: ep_etherpad-lite
eco: npm
published: Aug 17, 2026
Fix: PR #7905 (ether/etherpad).

`getHTMLFromAtext` in `src/node/utils/ExportHtml.ts` interpolates values from the `exportHtmlAdditionalTagsWithData` plugin hook into `span data-<k>="<v>"` without HTML-attribute escaping. The value comes verbatim from the pad attribute pool, which a pad editor contr…

CVE-2026-55090
GitHub-GHSA

HIGH
vm2's bufferAllocLimit cap bypassed by Buffer.concat and Buffer.from arrayLike
GHSA-gmc2-2x9w-cgh9
pkg: vm2
eco: npm
published: Aug 17, 2026
## Summary

vm2 bufferAllocLimit cap bypassed by Buffer.concat and Buffer.from arrayLike

The `bufferAllocLimit` option introduced in 3.11.0 (GHSA-6785-pvv7-mvg7) caps host-side Buffer allocations driven by sandbox code, the way embedders opt into `timeout`. The cap wraps `Buffer.alloc`, `Buffer.all…

CVE-2026-47683
GitHub-GHSA

HIGH
sqlparse: Quadratic O(n²) DoS in group_comments
GHSA-f2ff-p2ww-7p4p
pkg: sqlparse
eco: pip
published: Aug 17, 2026
### Summary
A comment-only statement (`– c\n`*n) may cause a Denial of Service (DoS).

### Details
Location: [sqlparse/engine/grouping.py:331-341](https://github.com/andialbrecht/sqlparse/blob/f80af6a4007f11ada847218df8c29dc859238290/sqlparse/engine/grouping.py#L332) (`group_comments`), invoked fir…

CVE-2026-71491
GitHub-GHSA

HIGH
Glances: `–disable-config-exec` does not cover on-alert action commands (incomplete fix of CVE-2026-53925)
GHSA-59fj-m2j6-hcxh
pkg: glances
eco: pip
published: Aug 17, 2026
## Summary
In Glances 4.5.5 the `–disable-config-exec` flag was extended (GHSA-3vwc-qwhc-3mj7) to stop `secure_popen()` from
interpreting the shell operators `&&`, `|` and `>` in **AMP** command values taken from the configuration file. The
hardening was not applied to the **on-alert action** comma…
CVE-2026-68519
GitHub-GHSA

HIGH
Glances has a command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction
GHSA-qcpp-8×79-hhp3
pkg: glances
eco: pip
published: Aug 17, 2026
### Summary

The Glances action system lets an administrator configure shell commands that run
when a monitoring threshold is crossed. The command is a Mustache template whose
variables are filled with runtime stat fields such as a process name, a container
name or a filesystem mount point. Those fi…

CVE-2026-68518
GitHub-GHSA

HIGH
DeepmergeTS has stack exhaustion when merging recursive object graphs
GHSA-ggr8-5vv4-36mx
pkg: deepmerge-ts
eco: npm
published: Aug 17, 2026
### Summary

`deepmerge()` and `deepmergeInto()` can be crashed with a crafted recursive object graph. When both merged values contain self-references at the same property path, the library recurses until Node throws `RangeError: Maximum call stack size exceeded`.

### Details

Record merging is imp…

CVE-2026-40345
NVD

MEDIUM
CVE-2026-52873
CVE-2026-52873
pkg: windows

published: Aug 18, 2026

Streambert is a cross-platform Electron Desktop App to stream and download video content. From version 2.5.0 until version 2.6.0, the wyzie-open-redeem IPC handler in index.js creates the partition:wyzie-redeem Electron session and registers an onHeadersReceived hook that removes the Content-Securit…
CWE: CWE-79, CWE-693
GitHub-GHSA

MEDIUM
NocoBase backup restore schema name allows command injection
GHSA-p853-83gj-wjj3
pkg: @nocobase/plugin-backups
eco: npm
published: Aug 20, 2026
### Summary
NocoBase `@nocobase/plugin-backups` 2.0.57 restores PostgreSQL backups by interpolating the backup metadata schema name into shell command strings that are executed with Node.js `child_process.exec()`. A backup-management user who can restore an uploaded PostgreSQL backup with forced sch…
CVE-2026-55410
NVD

MEDIUM
CVE-2026-71477
CVE-2026-71477
pkg: node

published: Aug 18, 2026

mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.7.1, release tar archives record mise/bin/mise with user and group ID 1001 and packaging/standalone/install.envsubst extracts and moves it without normalizing ownership, allowing a local user with those IDs to replace a ro…
CWE: CWE-278
NVD

MEDIUM
CVE-2026-44845
CVE-2026-44845
pkg: express

published: Aug 17, 2026

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.10.17, an authenticated administrator with Applet Host management and deployment permissions can inject Jinja2 expressions into the IP/Host field or Core Service Address field, causing Ansibl…
CWE: CWE-1336
NVD

MEDIUM
CVE-2026-55586
CVE-2026-55586
pkg: windows

published: Aug 20, 2026

SumatraPDF is a multi-format reader for Windows. In 3.6.1 and earlier, a crafted CHM file can supply malformed LZX Huffman code lengths to make_decode_table in ext/CHMLib/lzx.c. In the long-code branch, the function writes new internal nodes through next_symbol before validating that the canonical H…
CWE: CWE-119, CWE-787
NVD

MEDIUM
CVE-2026-67448
CVE-2026-67448
pkg: go

published: Aug 20, 2026

Mailpit is an email testing tool and API for developers. From 1.29.0 until 1.30.6, Mailpit's server/server.go origin middleware checks the raw RequestURI for the /api/ prefix while Go's ServeMux routes using the percent-decoded URL path, and server/websockets/client.go configures websocket.Upgrader.…
CWE: CWE-177, CWE-200, CWE-346
GitHub-GHSA

MEDIUM
Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689)
GHSA-8r62-w5wh-fc5m
pkg: github.com/axllent/mailpit
eco: go
published: Aug 20, 2026
## Summary

The cross-site WebSocket hijacking fix was reimplemented as an origin check gated on a raw-URI prefix test, but Go's ServeMux routes on the percent-decoded path, so requesting /%61pi/events reaches the WebSocket handler while skipping the only origin control, and the upgrader itself acce…

CVE-2026-67448
NVD

MEDIUM
CVE-2026-77641
CVE-2026-77641
pkg: go

published: Aug 20, 2026

tor before 0.4.9.9 was prone to a NULL write after free when sending a CONFLUX_SWITCH cell fails. The return value of relay_send_command_from_edge() was ignored, so a send failure (which calls circuit_mark_for_close() and removes the leg via cfx_del_leg()) would go undetected, causing the caller…
CWE: CWE-252
NVD

MEDIUM
CVE-2026-53583
CVE-2026-53583
pkg: tls

published: Aug 20, 2026

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, verify_server_cert in src/libgit2/streams/openssl.c uses an inverted !!memcmp result in the GEN_IPADD b…
CWE: CWE-295, CWE-297
GitHub-GHSA

MEDIUM
Wagtail: Improper restriction handling on Page translation API endpoint
GHSA-jm5p-837g-rv8g
pkg: wagtail, wagtail, wagtail
eco: pip
published: Aug 20, 2026
### Impact
A CMS user with the "submit translations" permission, could use the Admin API's "copy for translation" endpoint to copy an existing page that they do not have edit access to, allowing them to view its contents.

### Patches
Patched versions have been released as Wagtail 7.0.9, 7.3.4, 7.4.…

GitHub-GHSA

MEDIUM
Wagtail: Improper permission handling when copying snippets
GHSA-x5cx-w6p2-mxf2
pkg: wagtail, wagtail, wagtail
eco: pip
published: Aug 20, 2026
### Impact
A CMS user with "add" permission over a snippet model, but not "change" or "view" permission, could copy an existing snippet that they do not have access to, allowing them to view its contents.

### Patches
Patched versions have been released as Wagtail 7.0.9, 7.3.4, 7.4.3 and 8.0rc2.

##…

GitHub-GHSA

MEDIUM
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
GHSA-6×92-6vx4-5fwr
pkg: django-cms
eco: pip
published: Aug 20, 2026
## Impact

The only authorization gate on the duplicate flow is `PageAdmin.has_add_permission`,
which checks `user_can_add_page(user, site)` / `user_can_add_subpage(…)` — i.e. *“may
this user create a page at all”*. Nothing checks the user’s relationship to the page being
copied:

– `cms/a…

CVE-2026-63003
GitHub-GHSA

MEDIUM
django CMS: Structure endpoint bypasses page-view permission
GHSA-vgxm-h9gx-h9w7
pkg: django-cms
eco: pip
published: Aug 20, 2026
### Summary
The structure-board endpoint (`render_object_structure`) renders a page's plugin structure without verifying that the requesting user is allowed to view the page. The edit and preview endpoints enforce this via `render_page()`, but the structure endpoint does not, allowing a low-privileg…
CVE-2026-54624
GitHub-GHSA

MEDIUM
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
GHSA-4xfr-4p46-gc6p
pkg: django-cms
eco: pip
published: Aug 20, 2026
### Summary
The clipboard copy paths of the `copy_plugins` admin endpoint validate only the target (the user's own clipboard) and skip source-side authorization. A staff user can copy plugins out of a placeholder they have no permission on into their clipboard, then read the (secret) content.
CVE-2026-54622
GitHub-GHSA

MEDIUM
Wagtail: Improper permission handling in image preview
GHSA-r6p4-grq7-xm4m
pkg: wagtail, wagtail, wagtail
eco: pip
published: Aug 20, 2026
### Impact
Due to a missing permission check on the image preview endpoint, a user with access to the Wagtail admin can preview any image. The existing data of the image object itself is not exposed. The vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin…
CVE-2026-54261
GitHub-GHSA

MEDIUM
Tekton Pipelines-as-Code: Unscoped GitHub App installation token allows unauthorized access to private repositories via remote task resolution
GHSA-6f2p-296r-cc28
pkg: github.com/openshift-pipelines/pipelines-as-code, github.com/openshift-pipelines/pipelines-as-code, github.com/openshift-pipelines/pipelines-as-code
eco: go
published: Aug 20, 2026
### Impact
When Pipelines-as-Code is configured with a GitHub App installed across multiple repositories, the installation token issued during webhook processing is not scoped to the triggering repository by default. The token retains access to all repositories in the GitHub App installation.

This …

CVE-2026-54168
NVD

MEDIUM
CVE-2026-63123
CVE-2026-63123
pkg: vite

published: Aug 19, 2026

Tina is a headless content management system. Prior to 2.5.2, the TinaCMS CLI package's Vite dev server packages/@tinacms/cli/src/next/vite/cors.ts origin callback returns false for a disallowed origin but does not reject the request, and packages/@tinacms/cli/src/next/vite/plugins.ts still routes P…
CWE: CWE-352
GitHub-GHSA

MEDIUM
Tina: Cross-origin `POST /media/upload/*` requests can write arbitrary files into the Tina dev server media root
GHSA-rgr9-r7mj-mf6x
pkg: @tinacms/cli
eco: npm
published: Aug 19, 2026
### Summary
A browser-based cross-origin request flaw in the Tina dev server allows an attacker-controlled website to cause arbitrary file creation inside the configured media upload directory on a developer machine running `tinacms dev`. No manual file upload is required. The attacker page builds t…
CVE-2026-63123
NVD

MEDIUM
CVE-2026-54738
CVE-2026-54738
pkg: docker

published: Aug 19, 2026

Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-beta.1, actix-web ConnectionInfo::realip_remote_addr reads the first value of X-Forwarded-For as the client address used by raw_ip_key in crates/utils/src/rate_limit/mod.rs. Lemmy's bundled docker/nginx.conf uses $pro…
CWE: CWE-799
NVD

MEDIUM
CVE-2026-68901
CVE-2026-68901
pkg: react

published: Aug 19, 2026

Wekan is open source kanban built with Meteor. Prior to 10.38, the /api/boards/:boardId/export, /api/boards/:boardId/attachments/:attachmentId/export, /api/boards/:boardId/export/csv, and /api/boards/:boardId/exportExcel handlers in models/export.js and models/exportExcel.js looked up a user from th…
CWE: CWE-476
GitHub-GHSA

MEDIUM
SearXNG MCP Server is Vulnerable to SSRF in web_url_read: the internal-address guard is disabled by default (MCP_HTTP_HARDEN off)
GHSA-q87f-qc2r-2gw4
pkg: mcp-searxng
eco: npm
published: Aug 19, 2026
Ref: https://github.com/ihor-sokoliuk/mcp-searxng/issues/87#issuecomment-4645453694

### Summary
The web_url_read tool fetches a caller-supplied URL server-side and converts it to markdown. An SSRF guard (assertUrlAllowed, which blocks private/loopback/metadata addresses) exists but runs only when …

CVE-2026-54688
NVD

MEDIUM
CVE-2026-50149
CVE-2026-50149
pkg: tls

published: Aug 19, 2026

Contour is a Kubernetes ingress controller using Envoy proxy. In versions 1.23.0 through 1.33.4, when an `HTTPProxy` is configured with incompatible combination of both `.spec.virtualhost.tls.enableFallbackCertificate: true` and `.spec.virtualhost.jwtProviders`, Contour does not reject the configura…
CWE: CWE-295
NVD

MEDIUM
CVE-2026-76039
CVE-2026-76039
pkg: google chrome, google android

published: Aug 18, 2026

Incorrect reference resolution in Core in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-706
NVD

MEDIUM
CVE-2026-62576
CVE-2026-62576
pkg: tls

published: Aug 18, 2026

Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromi…
NVD

MEDIUM
CVE-2026-12632
CVE-2026-12632
pkg: node

published: Aug 18, 2026

Zephyr's Precision Time Protocol receive handler ptp_msg_post_recv() in subsys/net/lib/ptp/msg.c takes the 4-bit message type straight off the wire via ptp_msg_type() (msg->header.type_major_sdo_id & 0xF, range 0-15) and uses it to index the msg_size[] table. That table only defines entries up to PT…
CWE: CWE-125
NVD

MEDIUM
CVE-2026-12631
CVE-2026-12631
pkg: express

published: Aug 18, 2026

The Zephyr kernel validates the k_thread_join() and k_thread_abort() system calls (declared __syscall in include/zephyr/kernel.h) through thread_obj_validate() in kernel/thread.c. Its default switch branch is the access-denied path, taken when k_object_validate() returns -EPERM (the calling user thr…
CWE: CWE-862
GitHub-GHSA

MEDIUM
Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent authority
GHSA-g7p5-89mh-248h
pkg: lemur
eco: pip
published: Aug 18, 2026
## Summary

Repo under test: https://github.com/Netflix/lemur

When `ADMIN_ONLY_AUTHORITY_CREATION=False` (an explicitly supported and documented configuration), `POST /api/1/authorities` with `type=subca` never verifies that the caller holds `AuthorityPermission` on the supplied `parent` authority.…

CVE-2026-71317
GitHub-GHSA

MEDIUM
devpi-server may leak database contents
GHSA-m5pq-69xg-vcq3
pkg: devpi-server
eco: pip
published: Aug 18, 2026
### Impact

If the replication protocol is enabled by using the “primary“ (or deprecated “master“) role for a server instance, then the “+changelog“ URL route can be used to read the complete database content including password hashes, and the ids and salts of tokens from “devpi-tokens“ by u…

CVE-2026-54723
NVD

MEDIUM
CVE-2026-71317
CVE-2026-71317
pkg: tls

published: Aug 18, 2026

Lemur manages TLS certificate creation. Prior to 1.9.3, POST /api/1/authorities with type=subca did not require AuthorityPermission on the parent authority when ADMIN_ONLY_AUTHORITY_CREATION was false. AssociatedAuthoritySchema resolved the caller-supplied parent and passed it through authority crea…
CWE: CWE-862
NVD

MEDIUM
CVE-2026-52733
CVE-2026-52733
pkg: node

published: Aug 18, 2026

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a natural or attacker-influenced chain fork can leave stale Sapling and Orchard note-commitment subtree roots in Zebra state. In zebra-state/src/service/non_finalized_state/chain.rs, Chain::pop_tip removed a reverted tip block but did n…
CWE: CWE-459, CWE-672
NVD

MEDIUM
CVE-2026-52731
CVE-2026-52731
pkg: node

published: Aug 18, 2026

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an attacker authenticated to an enabled Zebra RPC endpoint can terminate zebrad by supplying a getblocktemplate LongPollId containing multi-byte UTF-8 characters. In zebra-rpc/src/methods/types/long_poll.rs, LongPollId::from_str origina…
CWE: CWE-248
NVD

MEDIUM
CVE-2026-19671
CVE-2026-19671
pkg: docker

published: Aug 18, 2026

Malcolm's upload-processing pipeline (scripts/safe-extract.py) enforces entry-count, nesting-depth, and total-uncompressed-byte limits when extracting container archives (zip/tar/rar/7z via libarchive), but those limits are not applied when the uploaded file is a single-stream compressed format (.gz…
CWE: CWE-409
NVD

MEDIUM
CVE-2026-47606
CVE-2026-47606
pkg: linux

published: Aug 18, 2026

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal. A successful exploit might lead to code execution and information disclosure.
CWE: CWE-36
NVD

MEDIUM
CVE-2026-74044
CVE-2026-74044
pkg: node

published: Aug 18, 2026

Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows authenticated cluster peers to delete arbitrary directory contents by supplying a traversal-shaped node name in the cluster hello payload without validation. Attackers holding a valid cluster Fernet key can craft a malicio…
CWE: CWE-22
GitHub-GHSA

MEDIUM
MobSF's CSRF checks not enforced after Django migration
GHSA-3p54-567p-2wpr
pkg: mobsf
eco: pip
published: Aug 18, 2026
### Summary

Django's `CsrfViewMiddleware` exists only in the deprecated `MIDDLEWARE_CLASSES` (ignored since Django 2.0). The active `MIDDLEWARE` tuple does not include it. All authenticated web POST endpoints (delete scan, upload, download APK, change password, manage users) accept requests without…

CVE-2026-68923
NVD

MEDIUM
CVE-2026-66781
CVE-2026-66781
pkg: kubernetes

published: Aug 18, 2026

A flaw was found in the Submariner operator. The Submariner Custom Resource (CR), used for configuring network connectivity, stores the IPsec pre-shared key (PSK) in an unencrypted format. This key, which is critical for securing communication between Kubernetes clusters, can be accessed by unauthor…
CWE: CWE-312
GitHub-GHSA

MEDIUM
MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth
GHSA-3p64-6gvh-82v5
pkg: mlflow
eco: npm
published: Aug 17, 2026
### Summary

When MLflow is deployed with the built-in basic-auth plugin (`–app-name basic-auth`), any authenticated user can inject arbitrary dataset records into another user's run by calling `POST /api/2.0/mlflow/runs/log-inputs`. The `LogInputs` proto handler is absent from the `BEFORE_REQUEST_…

CVE-2026-69146
GitHub-GHSA

MEDIUM
http4k: `DigestAuthProvider.verify` ignored configured algorithm and did not bind to request URI
GHSA-vxxm-wwqh-mh47
pkg: org.http4k:http4k-security-digest, org.http4k:http4k-security-digest, org.http4k:http4k-security-digest
eco: maven
published: Aug 17, 2026
### Impact

An issue in `DigestAuthProvider.verify`:

**Algorithm silently forced to MD5.** The configured `algorithm` parameter was ignored — every verification used MD5 regardless of configuration. Deployments believing they were running SHA-256 Digest auth were silently inheriting MD5's collis…

CVE-2026-54147
NVD

MEDIUM
CVE-2026-63669
CVE-2026-63669
pkg: node

published: Aug 17, 2026

ApostropheCMS is an open-source Node.js content management system. Prior to 4.32.0, the page module's move() operation fails to enforce the destination parent's _create permission because its oldParent archive condition disables the check for ordinary moves, allowing an authenticated editor or contr…
CWE: CWE-639, CWE-862
NVD

MEDIUM
CVE-2026-63667
CVE-2026-63667
pkg: node

published: Aug 17, 2026

ApostropheCMS is an open-source Node.js content management system. Prior to 3.6.2, the import-export module in packages/import-export/lib/formats/gzip.js constructs an attachment source path from the attacker-controlled _id, name, and extension fields in aposAttachments.json without ensuring that th…
CWE: CWE-22
GitHub-GHSA

MEDIUM
Netty Vulnerable to Cache Poisoning and Information Disclosure via CORS Vary Header Overwrite
GHSA-8c42-7qj2-3j46
pkg: io.netty:netty-codec-http, io.netty:netty-codec-http
eco: maven
published: Aug 17, 2026
### Summary
Netty's `CorsHandler` silently overwrites existing `Vary` headers, enabling cache poisoning and sensitive information disclosure.

### Details
`io.netty.handler.codec.http.cors.CorsHandler#setVaryHeader` overwrites any existing Vary headers set by backend applications.

“`java
priv…

CVE-2026-59903
GitHub-GHSA

MEDIUM
Glances: REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test — Bypassed by Any Multi-Origin Allowlist Containing the Wildcard
GHSA-fp27-88fp-2phg
pkg: glances
eco: pip
published: Aug 17, 2026
### Summary
Glances's REST API server includes a documented safety check intended to guarantee that `cors_credentials=True` can never be combined with an unrestricted CORS origin allowlist. The check compares the configured origin list to the wildcard using exact list equality (`cors_origins == ["*"…
CVE-2026-68517
NVD

MEDIUM
CVE-2026-74881
CVE-2026-74881
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 configure CORS with allow_origins set to wildcard and allow_credentials enabled to true. Attackers can create malicious websites that make authenticated cross-origin requests to the API on behalf of any user who visits them.
CWE: CWE-942
NVD

MEDIUM
CVE-2026-44517
CVE-2026-44517
pkg: docker

published: Aug 21, 2026

Buildah is a tool that facilitates building OCI images. From 1.38.1 until 1.43.2 and 1.44.0, TempDirForURL in define/types.go does not securely confine Git repository subdirectories to the downloaded build context, and downloadToDirectory and stdinToDirectory can follow a Dockerfile symlink left by …
CWE: CWE-22
GitHub-GHSA

MEDIUM
stigmem-node has blind SSRF via unvalidated webhook subscription delivery_address
GHSA-5p3m-vhh6-9236
pkg: stigmem-node
eco: pip
published: Aug 20, 2026
### Summary

Stigmem allows an authenticated user to create a webhook subscription with a user-controlled `delivery_address`. That value is stored and later used directly by the subscription delivery worker as the destination of a server-side HTTP POST request.

The codebase already contains an outb…

NVD

MEDIUM
CVE-2026-72844
CVE-2026-72844
pkg: express

published: Aug 20, 2026

The Lean 4 kernel does not verify that the structure named in a projection expression matches the type of the value being projected, and environment::add_inductive in src/kernel/inductive.cpp did not type check the nested inductive applications that are replaced by auxiliary types, so their parametr…
CWE: CWE-843
GitHub-GHSA

MEDIUM
SearXNG MCP Server: Additional hardened-mode SSRF bypasses
GHSA-wppf-h75h-6pm6
pkg: mcp-searxng
eco: npm
published: Aug 19, 2026
## Summary

`mcp-searxng` has a hardened-mode URL-reading feature intended to prevent `web_url_read` from reaching private or internal network resources.

PR #79 appears to address one SSRF class: hostnames that resolve to private or internal addresses under hardened mode. I tested PR #79 locally an…

CVE-2026-54689
GitHub-GHSA

MEDIUM
Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete fix for GHSA-54vg-pfh7-jq95)
GHSA-f3qq-49m6-rw8f
pkg: lemur
eco: pip
published: Aug 18, 2026
## Summary
The SSRF mitigation added for GHSA-54vg-pfh7-jq95 (`_validate_revocation_url()` in `lemur
/certificates/verify.py`) can be bypassed. An operator-role user who uploads a certificate with attacker-controlled CRL/OCSP extensions can still make Lemur reach internal destinations (RFC1918, loop…
CVE-2026-70667
NVD

MEDIUM
CVE-2026-70667
CVE-2026-70667
pkg: tls

published: Aug 18, 2026

Lemur manages TLS certificate creation. Prior to 1.9.3, _validate_revocation_url in lemur/certificates/verify.py checked the original CRL or OCSP URL but the later request could reach a different destination. The CRL requests.get call followed HTTP redirects without validating each Location target, …
CWE: CWE-367, CWE-918
NVD

MEDIUM
CVE-2026-55163
CVE-2026-55163
pkg: tls

published: Aug 18, 2026

Lemur manages TLS certificate creation. Prior to 1.9.2, PUT /api/1/roles/ in lemur/roles/views.py:298 authorized updates with RoleMemberPermission(role_id), which allowed either an administrator or any existing member of the target role. The handler passed data["users"] and data["name"] to service.u…
CWE: CWE-863
NVD

MEDIUM
CVE-2026-55162
CVE-2026-55162
pkg: tls

published: Aug 18, 2026

Lemur manages TLS certificate creation. Prior to 1.9.2, lemur/certificates/verify.py accepted CRL Distribution Point and OCSP responder URLs from uploaded certificate extensions and used them in crl_verify and ocsp_verify without adequate destination validation. An authenticated operator could submi…
CWE: CWE-918
NVD

MEDIUM
CVE-2026-74871
CVE-2026-74871
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.6 contain a key derivation flaw in sequential XOR composition mode where the last stage cancels out during key generation. When configured with a single KDF and no prior hashing stage, attackers can bypass memory-hard key derivation and perform offline password cr…
CWE: CWE-916
NVD

MEDIUM
CVE-2026-54770
CVE-2026-54770
pkg: oauth

published: Aug 20, 2026

WebOb provides objects for HTTP requests and responses. Prior to 1.8.11, Response._make_location_absolute() in src/webob/response.py checks a Location value for a URI scheme or leading double slash before urllib.parse.urljoin() strips leading C0 control characters and spaces. An attacker-controlled …
CWE: CWE-601
NVD

MEDIUM
CVE-2026-16732
CVE-2026-16732
pkg: node

published: Aug 18, 2026

fastify is a fast and low overhead web framework for Node.js. Impact: the fix for CVE-2026-3635 added a guard on the forwarded-header reads used to derive the request host, protocol, hostname, ip, and ips values, checking the connecting address. That guard closes the IP, CIDR, and custom-function fo…
CWE: CWE-348
GitHub-GHSA

MEDIUM
chrome-devtools-mcp: validatePath() does not canonicalize symlinks before enforcing roots
GHSA-8qf9-62×2-82pp
pkg: chrome-devtools-mcp
eco: npm
published: Aug 17, 2026
### Summary

I originally reported this through Google Bug Hunters. The Google Bug Hunters team said this is in OSS VRP scope but not reward-eligible due to the project tier, and asked me to file an issue or PR directly with this repository. I am reporting it privately here first because it is an un…

CVE-2026-53766
NVD

MEDIUM
CVE-2026-63670
CVE-2026-63670
pkg: node

published: Aug 17, 2026

ApostropheCMS is an open-source Node.js content management system. Prior to 2.17.6, sanitizeHtml() can pass disallowed executable markup through packages/sanitize-html/index.js when textarea or xmp is included in allowedTags because a literal solidus after the raw-text end-tag name is treated as tex…
CWE: CWE-79
NVD

MEDIUM
CVE-2026-53572
CVE-2026-53572
pkg: ssl

published: Aug 21, 2026

KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to 2.20.0, pkg/scalers/postgresql_scaler.go constructs libpq-style connection strings from tenant-controlled host, port, userName, dbName, sslmode, and password values, while escapePostgreConnectionParameter() only quotes values co…
CWE: CWE-74, CWE-89
NVD

MEDIUM
CVE-2026-55558
CVE-2026-55558
pkg: tls

published: Aug 20, 2026

aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.2, SMTPProtocol.start_tls in src/aiosmtplib/protocol.py consumes the server's 220 response and starts the TLS handshake without clearing SMTPProtocol._buffer. An active network attacker can place attacker-chosen SMTP respon…
CWE: CWE-74
NVD

MEDIUM
CVE-2026-76401
CVE-2026-76401
pkg: express

published: Aug 19, 2026

In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API could configure timestamp extraction with a crafted regular expression and matching event data to block a Kafka Connect worker thread, stopping event d…
CWE: CWE-407
GitHub-GHSA

MEDIUM
langgraph-api: Incomplete assistant authorization in LangGraph Server run creation
GHSA-jfj5-wrj9-63×4
pkg: langgraph-api
eco: pip
published: Aug 19, 2026
## Summary

In affected versions of `langgraph-api` (the LangGraph Server runtime), the run-creation path authorized the assistant attached to a run using a different authorization event than the rest of the assistant-handling code paths. Direct assistant reads and cron creation dispatch the `assist…

CVE-2026-55236
GitHub-GHSA

MEDIUM
langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication
GHSA-2c9q-c2q9-qgqv
pkg: langgraph-api
eco: pip
published: Aug 19, 2026
## Summary

In affected versions of `langgraph-api` (the LangGraph Server runtime), a run or cron could be created with a relative webhook target. When the server later delivers such a webhook, it routes the request back into the same application through an in-process loopback transport that the aut…

CVE-2026-55235
NVD

MEDIUM
CVE-2026-52739
CVE-2026-52739
pkg: node

published: Aug 18, 2026

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a malicious block producer can terminate zebrad by placing the same shielded transaction in a non-finalized parent block and its child. In zebra-state/src/service/non_finalized_state/chain.rs, Chain::push originally inserted the transac…
CWE: CWE-248
NVD

MEDIUM
CVE-2026-50139
CVE-2026-50139
pkg: go

published: Aug 18, 2026

goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, `ShareHandler` reads the share token's `DownloadLimit` under `RLock`, releases the lock, serves the file, then re-acquires the lock to increment the counter. Concurrent requests all read the same `Downloaded`/`DownloadLimit` snapshot…
CWE: CWE-362
NVD

MEDIUM
CVE-2026-75145
CVE-2026-75145
pkg: windows

published: Aug 19, 2026

FFmpeg before commit b4c199c contains an incorrect integer narrowing conversion in the AV1 RTP packetizer (libavformat/rtpenc_av1.c). The OBU size is cast to long before comparison against the remaining frame size. On targets where long is 32 bits, including 64-bit Windows, sufficiently large OBU si…
CWE: CWE-681
NVD

MEDIUM
CVE-2026-45271
CVE-2026-45271
pkg: tls

published: Aug 21, 2026

Picotls is a TLS protocol library that allows users select different crypto backends based on their use case. Picotls implements its own ASN.1 validation helper, which is used by the minicrypto backend while parsing local PKCS#8 private keys. Prior to commit c14231d801407640bc42c2dcf92783409ea6a7c7,…
CWE: CWE-835
GitHub-GHSA

MEDIUM
Unleash: Addon webhook URL is dialed server-side with no internal-address filtering, enabling SSRF to internal services / cloud metadata and exfiltration of configured request headers
GHSA-5vf6-jrqr-78fj
pkg: unleash-server, unleash-server, unleash-server
eco: npm
published: Aug 21, 2026
## Summary

Unleash's addon/integration subsystem lets an operator configure a webhook (and the Slack, Microsoft Teams, Datadog, and New Relic integrations) with a target `url` parameter. Whenever a subscribed feature-flag event fires, the Unleash server itself issues an HTTP request to that configu…

CVE-2026-63004
NVD

MEDIUM
CVE-2026-55015
CVE-2026-55015
pkg: windows

published: Aug 20, 2026

Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny service locally.
CWE: CWE-427
GitHub-GHSA

MEDIUM
asteval Sandbox Escape: arbitrary native memory read/write via numpy ctypes in default asteval Interpreter
GHSA-9w56-46f6-3qhx
pkg: asteval
eco: pip
published: Aug 20, 2026
### Summary
With its default configuration (numpy enabled, `import` disabled), asteval's `Interpreter` lets an attacker-controlled expression obtain a raw **arbitrary process-memory read and write** primitive, without using `import`, any `__dunder__` attribute, or `eval`/`exec`/`getattr`. Arbitrary …
NVD

MEDIUM
CVE-2026-14978
CVE-2026-14978
pkg: go

published: Aug 19, 2026

HashiCorp go-slug 0.4.0 through 0.18.2 could allow a local attacker to bypass .terraformignore exclusions and cause sensitive files to be included in Terraform slug uploads due to improper handling of Unicode normalization during path matching.
CWE: CWE-176
GitHub-GHSA

MEDIUM
SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses
GHSA-hjwh-xvfw-qrwj
pkg: mcp-searxng
eco: npm
published: Aug 19, 2026
### Summary

mcp-searxng version 1.11.0 exposes SearXNG Basic Authentication credentials embedded in the `SEARXNG_URL` environment variable.

When the server starts in STDIO mode and an MCP client connects, the complete `SEARXNG_URL`, including its username and password, is sent to the client throug…

NVD

MEDIUM
CVE-2026-76227
CVE-2026-76227
pkg: docker

published: Aug 19, 2026

Renovate versions from 42.68.1 before 42.96.3 (and from 42.68.1 before 43.4.4), including corresponding Docker images (renovate/renovate, mend/renovate-ce, renovate-ee-server, renovate-ee-worker >=13.3.0 <13.6.0), fail to restrict environment variables to an allowlist when spawning child processes. …
CWE: CWE-526
NVD

MEDIUM
CVE-2026-73974
CVE-2026-73974
pkg: linux

published: Aug 18, 2026

linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses its shared testing helper across check plugins. Prior to linuxfabrik-lib 6.1.0 and Linuxfabrik Monitoring Plugins 7.0.0, lib.lftest.test() treated the …
CWE: CWE-22, CWE-269
NVD

MEDIUM
CVE-2026-73973
CVE-2026-73973
pkg: linux

published: Aug 18, 2026

Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems. Prior to version 7.0.0, check-plugins/logfile/logfile accepted a free-form –filename path and opened it as root when invoked through the shipped nagios or icinga sudoers allowlist, without confining …
CWE: CWE-22, CWE-269
GitHub-GHSA

MEDIUM
linuxfabrik-lib: Arbitrary root file read via live –test argument (lib.lftest) across sudoers-whitelisted plugins (LPE)
GHSA-rh9c-rqvg-f7pr
pkg: linuxfabrik-lib
eco: pip
published: Aug 18, 2026
## Summary
Every Linuxfabrik check plugin that supports the shared `–test` argument (routed through `lib.lftest.test()`) will, when `–test` is supplied, treat the first CSV element as a filesystem path and read its full contents as the plugin's simulated STDOUT — running as root when the plugin …
CVE-2026-73974
NVD

MEDIUM
CVE-2026-47630
CVE-2026-47630
pkg: linux

published: Aug 18, 2026

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal. A successful exploit might lead to code execution.
CWE: CWE-36
GitHub-GHSA

MEDIUM
MobSF Vulnerable to Arbitrary File Read via Path Traversal in ZIP Uploads
GHSA-8j49-mmcx-4mp5
pkg: mobsf
eco: pip
published: Aug 18, 2026
### Summary
The `find_icon_path_zip()` function in MobSF does not properly sanitize the `android:icon` attribute extracted from an Android manifest before resolving it as a filesystem path.

An attacker can supply a malicious `android:icon` value containing path traversal sequences, causing MobSF to…

CVE-2026-68922
NVD

MEDIUM
CVE-2026-75485
CVE-2026-75485
pkg: kubernetes

published: Aug 18, 2026

A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. The cluster Proxy object is dumped in raw form, bypassing the oc inspect redaction that would normally sanitize sensitive fields. This exposes proxy basic-auth credentials in the must-gather archive,…
CWE: CWE-532
NVD

MEDIUM
CVE-2026-73834
CVE-2026-73834
pkg: kubernetes

published: Aug 18, 2026

A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. Certain ACM wrapper Custom Resources that embed Secret data are collected without redaction. When an administrator runs must-gather, credentials and tokens are captured in cleartext in the resulting …
CWE: CWE-312
NVD

MEDIUM
CVE-2026-74890
CVE-2026-74890
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in CamelliaCipher that disables HMAC tag generation and verification when the PYTEST_CURRENT_TEST environment variable is set. Attackers with code execution can set this environment variable to produce unauthenticat…
CWE: CWE-345
NVD

MEDIUM
CVE-2026-74873
CVE-2026-74873
pkg: openssl

published: Aug 17, 2026

openssl_encrypt versions before 1.4.0 expose passwords passed via the –password CLI argument in process listings accessible to all system users. Attackers can read process arguments through ps aux or /proc/[pid]/cmdline to retrieve plaintext passwords and keystore passwords.
CWE: CWE-214
GitHub-GHSA

MEDIUM
Tina: Broken Access Control: arbitrary bucket-key write/delete in `next-tinacms-s3` (and sibling production media adapters)
GHSA-8mq9-5fw2-5rm4
pkg: next-tinacms-s3, next-tinacms-dos, next-tinacms-azure
eco: npm
published: Aug 19, 2026
## Summary

The production media handler shipped by `next-tinacms-s3` (`createMediaHandler` in `packages/next-tinacms-s3/src/handlers.ts`) accepts an attacker-chosen `?key=` query parameter and returns an AWS-signed `PutObject` URL whose `Key` is that value, with no check that the key falls under th…

CVE-2026-59992
NVD

MEDIUM
CVE-2026-18504
CVE-2026-18504
pkg: node

published: Aug 18, 2026

fastify is a fast and low overhead web framework for Node.js. Versions of fastify before 5.12.1 are affected by a schema validation bypass when a request body schema targets a root primitive value. When the schema validates a top-level primitive such as an integer, Ajv can coerce a JSON string into …
CWE: CWE-20
NVD

MEDIUM
CVE-2026-19670
CVE-2026-19670
pkg: nginx

published: Aug 18, 2026

Malcolm's nginx Lua role-based access control (RBAC) layer decides whether an authenticated user may reach a role-restricted path (e.g. /htadmin, /auth, /admin_login, /arkime/api/esadmin, NetBox, upload endpoints) by pattern-matching the raw, percent-encoded request URI. Nginx itself, however, selec…
CWE: CWE-863
GitHub-GHSA

MEDIUM
Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement
GHSA-r553-m4fv-5v97
pkg: github.com/axllent/mailpit
eco: go
published: Aug 20, 2026
## Summary

Mailpit's SMTP DATA reader enforces the configured `MaxMessageSize` only after `bufio.Reader.ReadBytes('\n')` has already buffered a complete DATA line. A remote unauthenticated SMTP client can send one line larger than the configured message-size cap and force memory allocation before M…

CVE-2026-67447
GitHub-GHSA

MEDIUM
Wagtail: Improper restriction handling on descendant collections in Documents and Images API
GHSA-c2xx-cjmh-9q8f
pkg: wagtail, wagtail, wagtail
eco: pip
published: Aug 20, 2026
### Impact

The Documents and Images [API V2](https://docs.wagtail.org/en/stable/advanced_topics/api/index.html) incorrectly listed items in descendants of private collections, which should inherit the view restrictions defined on their ancestors. A user with access to the API could see the filename…

GitHub-GHSA

MEDIUM
Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs
GHSA-q9c5-pp7m-fm2g
pkg: github.com/fleetdm/fleet/v4
eco: go
published: Aug 20, 2026
### Summary

Two endpoints serving in-house iOS application packages and manifests in Fleet's enterprise tier are reachable without a hard-to-guess token in the URL, allowing an unauthenticated attacker who can reach the Fleet server to download an in-house IPA by guessing sequential title identifie…

GitHub-GHSA

MEDIUM
netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash
GHSA-pgrf-4654-3gq8
pkg: io.netty.incubator:netty-incubator-codec-bhttp
eco: maven
published: Aug 20, 2026
## Summary

`io.netty.incubator:netty-incubator-codec-bhttp` uses attacker-controlled Binary HTTP variable-length integers as `long` values but accumulates them into `int` offsets. Large valid varint lengths wrap the internal offset negative, leading to unchecked `ArrayIndexOutOfBoundsException` / `…

CVE-2026-61799
NVD

MEDIUM
CVE-2026-68552
CVE-2026-68552
pkg: tls

published: Aug 19, 2026

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, an unauthenticated remote client can send a STUN message over TCP or TLS with a body-length field from 65520 through 65532, causing the uint16_t len variable in stun_get_message_len_str() in src/client/ns_turn_msg.…
CWE: CWE-190
NVD

MEDIUM
CVE-2026-49392
CVE-2026-49392
pkg: express

published: Aug 19, 2026

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.6.0 until 4.14.6 and 5.0.0-beta3, DB::getFile() and DB::searchFile() in src/syscheckd/src/db/src/file.cpp concatenate a monitored file path into SQLite row filters. On non-Windows systems, FIMDBCreat…
CWE: CWE-20, CWE-89
NVD

MEDIUM
CVE-2026-48796
CVE-2026-48796
pkg: windows

published: Aug 18, 2026

CefSharp provides .NET bindings for the Chromium Embedded Framework for Windows Forms and Windows Presentation Foundation applications. Prior to version 148.0.90, CefSharp/SchemeHandler/FolderSchemeHandlerFactory.cs used filePath.StartsWith(rootFolder, StringComparison.OrdinalIgnoreCase) to decide w…
CWE: CWE-22
NVD

MEDIUM
CVE-2026-70907
CVE-2026-70907
pkg: tls

published: Aug 18, 2026

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and 21.0.12; Oracle…
CWE: CWE-284
NVD

MEDIUM
CVE-2026-52737
CVE-2026-52737
pkg: node

published: Aug 18, 2026

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a malicious unauthenticated P2P peer can answer Zebra's outbound getblocks or FindBlocks request with a small two-hash inventory and then serve a syntactically valid block whose coinbase height is far above the local chain tip. In zebra…
CWE: CWE-345
NVD

MEDIUM
CVE-2026-52734
CVE-2026-52734
pkg: node

published: Aug 18, 2026

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an unauthenticated P2P peer can cause the mempool download pipeline to retain transactions after verification reaches the outer RATE_LIMIT_DELAY timeout. In zebrad/src/components/mempool/downloads.rs, Downloads::poll_next removed cancel…
CWE: CWE-401
NVD

MEDIUM
CVE-2026-52732
CVE-2026-52732
pkg: node

published: Aug 18, 2026

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, one unauthenticated P2P peer can monopolize all 25 MAX_INBOUND_CONCURRENCY slots in Zebra's inbound mempool download and verification pipeline. In zebrad/src/components/mempool/downloads.rs, the bounded queue was shared globally without…
CWE: CWE-770
NVD

MEDIUM
CVE-2026-65959
CVE-2026-65959
pkg: vite

published: Aug 18, 2026

Vitess is a database clustering system for horizontal scaling of MySQL. In 24.0.2 and earlier, the /debug/vrlog endpoint registered by addHttpEndpoint() in go/vt/vttablet/tabletmanager/vreplication/vrlog.go invokes vrlogStatsHandler() without acl.CheckAccessHTTP(r, acl.DEBUGGING), unlike comparable …
CWE: CWE-862
NVD

MEDIUM
CVE-2026-73502
CVE-2026-73502
pkg: go

published: Aug 18, 2026

kin-openapi is a Go project for handling OpenAPI files. From 0.2.0 until 0.144.0, openapi3filter.ValidateRequest can encounter a NULL-pointer-dereference denial of service when an operation declares a content parameter whose application/json media type has no schema. In openapi3filter/req_resp_decod…
CWE: CWE-476
NVD

MEDIUM
CVE-2026-46482
CVE-2026-46482
pkg: go

published: Aug 18, 2026

### Impact
The registration component does not validate the text-based _Security Question_ CAPTCHA correctly, allowing attackers to bypass the challenge via a specially crafted value.

[CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N](https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/U…

CWE: CWE-636
GitHub-GHSA

MEDIUM
Glances: as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/config
GHSA-4h34-v6r8-mmjc
pkg: glances
eco: pip
published: Aug 17, 2026
## Summary

Glances provides `as_dict_secure()` explicitly designed for unauthenticated API access, with a docstring stating it returns "a sanitised copy of the configuration dict" where "Sensitive keys in remaining sections are replaced by '********'". However, the implementation only checks KEY na…

CVE-2026-68520
GitHub-GHSA

MEDIUM
asteval has a Sandbox Escape via BaseException Subclasses
GHSA-89v8-rhwq-hf77
pkg: asteval
eco: pip
published: Aug 20, 2026
## Summary

An attacker who can supply expressions to `asteval.Interpreter.eval()` can raise `SystemExit`,
`KeyboardInterrupt`, `GeneratorExit`, or `BaseException` from inside the sandbox. These
exceptions are subclasses of `BaseException` but not `Exception`, so they bypass the
`except Exception:` …

CVE-2026-55244
NVD

MEDIUM
CVE-2026-77067
CVE-2026-77067
pkg: axios

published: Aug 20, 2026

The setWebhookResolver in packages/api/src/resolvers/webhooks/index.ts stores the caller-supplied url without any address validation, and the file imports no validation helper. When a subscribed event fires, callWebhook in packages/api/src/jobs/call_webhook.ts issues axios.request with that url, the…
CWE: CWE-918
NVD

MEDIUM
CVE-2026-77066
CVE-2026-77066
pkg: axios

published: Aug 20, 2026

The scanFeedsResolver in packages/api/src/resolvers/subscriptions/index.ts passes the caller-supplied url straight to axios.get(url, rssParserConfig()) with no address validation. The same file guards the subscribe path with validateUrl(), which rejects private and reserved ranges through the privat…
CWE: CWE-918
NVD

MEDIUM
CVE-2026-70656
CVE-2026-70656
pkg: express

published: Aug 21, 2026

Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. From 3.5.1 until 3.9.2, an authenticated admin or superadmin can set matchMethod to regex and place a malicious expression in…
CWE: CWE-1333
NVD

MEDIUM
CVE-2026-55164
CVE-2026-55164
pkg: tls

published: Aug 18, 2026

Lemur manages TLS certificate creation. Prior to 1.9.2, lemur.users.service.update assigned a replacement password directly to users.password, while lemur/users/models.py registered User.hash_password only for the before_insert event. Because no before_update listener ran, administrator-initiated pa…
CWE: CWE-256
NVD

MEDIUM
CVE-2026-74046
CVE-2026-74046
pkg: node

published: Aug 18, 2026

Wazuh 4.4.0 before 4.14.7 contains a denial of service vulnerability in the fdecompress_files() function within cluster.py that allows authenticated cluster peers to exhaust memory by supplying a malicious synchronization archive without decompressed size limits. Attackers holding a valid cluster Fe…
CWE: CWE-409
GitHub-GHSA

MEDIUM
MobSF Vulnerable to Zip Bomb Denial of Service via Per-File Size Limit Bypass in ZIP/APK Extraction
GHSA-x768-8642-mmq9
pkg: mobsf
eco: pip
published: Aug 18, 2026
### Summary

When extracting uploaded ZIP/APK files, MobSF checks if individual files exceed `ZIP_MAX_UNCOMPRESSED_FILE_SIZE` (400 MB) and logs "Skipping" — but the code lacks a `continue` statement, so extraction proceeds anyway. The log message is misleading; the file is still written to disk.

CVE-2026-68924
NVD

MEDIUM
CVE-2026-55165
CVE-2026-55165
pkg: tls

published: Aug 18, 2026

Lemur manages TLS certificate creation. Prior to 1.9.2, the JWT verifier in lemur/auth/service.py:130-137 used fetch_token_header to read header_data["alg"] from an unverified token and passed that attacker-controlled value to decode_with_multiple_secrets. PyJWT 2.x rejects alg=none with the configu…
CWE: CWE-347
GitHub-GHSA

MEDIUM
Ember has unneutralized terminal escape/control sequences from Caddy logs injected into the operator's TUI
GHSA-x3g7-qrwc-f6c5
pkg: github.com/alexandre-daubois/ember
eco: go
published: Aug 20, 2026
## Summary

Ember's interactive TUI renders fields taken from the monitored Caddy server's access logs — most notably the request URI — straight to the operator's terminal without neutralising terminal escape or control sequences (CWE-150). Those log fields are populated from arbitrary, unauthen…

CVE-2026-54162
GitHub-GHSA

MEDIUM
django CMS: Stored XSS in edit-mode plugin exception rendering
GHSA-hvq6-2r72-p2x7
pkg: django-cms
eco: pip
published: Aug 20, 2026
## Summary

When plugin rendering fails in edit mode, django CMS renders a `cms-rendering-exception` block so editors can see that a placeholder could not be rendered. Older code built that block's heading by interpolating the exception message, placeholder/source strings, and the failing plugin's s…

CVE-2026-75526
NVD

MEDIUM
CVE-2026-53487
CVE-2026-53487
pkg: kubernetes

published: Aug 21, 2026

Kite is a Kubernetes dashboard. Prior to version 0.12.3, authenticated Kite users with any role can request `/api/v1/overview` for a cluster that their roles do not permit by selecting that cluster with `x-cluster-name`. The overview route is registered before `middleware.RBACMiddleware()` and `GetO…
CWE: CWE-862
GitHub-GHSA

MEDIUM
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
GHSA-8qj2-c6q4-f399
pkg: django-cms
eco: pip
published: Aug 20, 2026
## Summary

The django-cms frontend-editing structure endpoint

“`
GET /<lang>/admin/cms/placeholder/object/<content_type_id>/structure/<object_id>/
“`

did not perform an object-level authorization check for **non-`PageContent`** objects. Any authenticated, active staff user could request the str…

CVE-2026-61663
GitHub-GHSA

MEDIUM
Wagtail: Improper restriction handling on Pages admin API
GHSA-3vrh-m9w7-v94f
pkg: wagtail, wagtail, wagtail
eco: pip
published: Aug 20, 2026
### Impact

The internal Pages admin [API](https://docs.wagtail.org/en/stable/advanced_topics/api/index.html) incorrectly returns page fields without access control when they are declared in `api_fields`. A user with access to the Wagtail admin can use this API to fetch draft and live page fields��…

CVE-2026-55468
GitHub-GHSA

MEDIUM
Wagtail: Pages translations can be created without page permissions when using simple_translation
GHSA-8634-mr4j-r72c
pkg: wagtail, wagtail, wagtail
eco: pip
published: Aug 20, 2026
### Impact
A low-level user with the "Can submit translation" permission can create translations for any page, including those they do not have permissions for.

### Patches
Patched versions have been released as Wagtail 7.0.8, 7.3.3, 7.4.2.

### Workarounds
N/A

### Acknowledgements

Many thanks to…

CVE-2026-54262
GitHub-GHSA

MEDIUM
Wagtail: Denial of service via unbounded filter specs in the image preview
GHSA-f2p5-j6fg-5cxf
pkg: wagtail, wagtail, wagtail
eco: pip
published: Aug 20, 2026
### Impact

An authenticated admin user can trigger expensive rendition processing with purposefully crafted filter specs resulting in potentially service degradation.

The vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin.

### Patches
Patched versions…

CVE-2026-54260
GitHub-GHSA

MEDIUM
Wagtail: Improper restriction handling on Documents and Images chosen endpoints
GHSA-h54r-xq46-qwqm
pkg: wagtail, wagtail, wagtail
eco: pip
published: Aug 20, 2026
### Impact
The Documents and Images chooser's chosen endpoint incorrectly listed items for which the user has not been granted choose permission. A user with access to the Wagtail admin could see the filename and name and URLs of documents and images in those collections.

The vulnerability is not e…

CVE-2026-54259
NVD

MEDIUM
CVE-2026-76380
CVE-2026-76380
pkg: oauth

published: Aug 19, 2026

In versions below 5.1.3 of the CrowdStrike OAuth API app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive document password by invoking either the detonate file or detonate url action, because the action's document_password parameter is not masked and …
CWE: CWE-312
NVD

MEDIUM
CVE-2026-54492
CVE-2026-54492
pkg: docker

published: Aug 19, 2026

Koel is a free, open-source music streaming solution. Prior to 9.7.0, the Subsonic-compatible createPodcastChannel.view route accepts an authenticated user's private URL because app/Http/Requests/Subsonic/CreatePodcastChannelRequest.php does not apply the SafeUrl validation used by the regular podca…
CWE: CWE-918
NVD

MEDIUM
CVE-2026-76166
CVE-2026-76166
pkg: node

published: Aug 19, 2026

A flaw was found in mod_cluster's AdvertiseListenerImpl (org.jboss.modcluster core module). A single crafted UDP multicast datagram with a valid HTTP status line and a "Server:" header but without the "Date:", "Digest:", and "Sequence:" headers triggers a NullPointerException in verifyDigest() that …
CWE: CWE-476
NVD

MEDIUM
CVE-2026-76041
CVE-2026-76041
pkg: google chrome

published: Aug 18, 2026

Information leak in Skia in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-200
GitHub-GHSA

MEDIUM
Lemur: Missing authorization check on POST /certificates/<id>/export for plugins with requires_key = False
GHSA-4h97-p9wq-chqj
pkg: lemur
eco: pip
published: Aug 18, 2026
## Summary

The `CertificateExport` handler in `lemur/certificates/views.py` nests its entire ownership / `CertificatePermission` check inside an `if plugin.requires_key:` branch. When the selected export plugin advertises `requires_key = False`, the authorization check is skipped entirely and any …

CVE-2026-71322
NVD

MEDIUM
CVE-2026-76032
CVE-2026-76032
pkg: node

published: Aug 18, 2026

Pydio Cells 5.0.0 through 5.0.2 returns share-link details to any authenticated user. The REST handler for GET /a/share/link/{Uuid} in idm/share/rest/handler.go reads the workspace UUID from the path, calls LinkById, and writes the result with no authorization step, whereas the sibling handler for G…
CWE: CWE-862
NVD

MEDIUM
CVE-2026-71322
CVE-2026-71322
pkg: tls

published: Aug 18, 2026

Lemur manages TLS certificate creation. Prior to 1.9.3, CertificateExport placed its CertificatePermission ownership check inside the plugin.requires_key branch for POST /api/1/certificates//export. A plugin declaring requires_key false bypassed that check, and the handler still passed cert.private_…
CWE: CWE-862
GitHub-GHSA

MEDIUM
MagicMirror socket payload secret placeholder expansion can disclose SECRET_* environment variables
GHSA-q4gh-4ffp-5cg8
pkg: magicmirror
eco: npm
published: Aug 18, 2026
### Summary
When `hideConfigSecrets: true` is enabled, MagicMirror redacts `SECRET_*` environment placeholders in the HTTP `/config` response, but the shared node-helper socket dispatcher expands `**SECRET_NAME**` placeholders in every inbound socket payload before passing it to module helpers. Any …
CVE-2026-63640
GitHub-GHSA

MEDIUM
Copyparty vulnerable to file/dirkey confusion
GHSA-x5pq-m9p8-f4vx
pkg: copyparty
eco: pip
published: Aug 18, 2026
A valid filekey could potentially be converted into a dirkey, granting read-access to the containing folder.

This issue only affected volumes which simultaneously enable both filekeys and dirkeys, with volflag `dk` or `dks` combined with `fk` or `fka`.

Both required features are default-disabled, …

CVE-2026-70657
NVD

MEDIUM
CVE-2026-75841
CVE-2026-75841
pkg: express

published: Aug 18, 2026

ArcadeDB before 26.8.1 contains a denial of service vulnerability in the Cypher range() function that allows authenticated users to exhaust server heap memory. Attackers can submit oversized range() expressions with large bounds to trigger OutOfMemoryError and cause temporary service degradation or …
CWE: CWE-770
NVD

MEDIUM
CVE-2026-16045
CVE-2026-16045
pkg: mattermost mattermost_server

published: Aug 17, 2026

Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 Mattermost failed to restrict OAuth deauthorization and personal access token management endpoints to direct user sessions, which allowed an OAuth app with a delegated user token to revoke the user's authorizations or tokens for other integra…
CWE: CWE-863
NVD

MEDIUM
CVE-2026-76033
CVE-2026-76033
pkg: google chrome

published: Aug 18, 2026

Inappropriate implementation in CORS in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-20
NVD

MEDIUM
CVE-2026-75833
CVE-2026-75833
pkg: oauth

published: Aug 18, 2026

The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0's admin-next/API stack) before version 1.0.14 contains an open redirect weakness in SsoController::sanitizeReturnTo(). The function rejects a literal '//' prefix but does not account for browsers normalizing backslashes to slashes i…
CWE: CWE-601
GitHub-GHSA

MEDIUM
Unleash: Global Mustache.escape override disables HTML escaping process-wide, enabling Slack/Teams link-injection via unrestricted username
GHSA-w4mq-xh27-6xpx
pkg: unleash-server
eco: npm
published: Aug 21, 2026
## Vulnerability Details

**File**: `src/lib/addons/feature-event-formatter-md.ts`
**Line**: 355 (in v8.0.1; `format()` method)

### Root Cause

`FeatureEventFormatterMd.format()` does:

“`ts
Mustache.escape = (text) => text;
const text = Mustache.render(action, context);
“`

`mustache` (pinned `^…

CVE-2026-63466
NVD

MEDIUM
CVE-2026-50126
CVE-2026-50126
pkg: node

published: Aug 18, 2026

Adaguc-server is an open source geographical information system to visualize, combine, compare and share real-time meteorological, climatological and remote sensing data via OGC standards. Versions prior to 7.2.2 crash with a memory-safety fault when it parses a GeoJSON document whose geometry conta…
CWE: CWE-125, CWE-476
GitHub-GHSA

MEDIUM
gettext-converter: Prototype pollution in js2i18next() via crafted translation keys
GHSA-f4jp-rw7w-ccwg
pkg: gettext-converter
eco: npm
published: Aug 20, 2026
### Impact

`js2i18next()` is vulnerable to prototype pollution. When converting translations, it splits nested keys on the key separator (default `##`) and uses each segment as a dynamic object key while building the output object. A key whose segment is `__proto__` (e.g. `__proto__##gcPolluted`) c…

CVE-2026-55451
GitHub-GHSA

MEDIUM
next-video: Unauthenticated arbitrary file read via /api/video request handler
GHSA-2p39-2jf3-fv2q
pkg: next-video
eco: npm
published: Aug 20, 2026
### Impact

The HTTP route handler exported by `next-video/request-handler` — which the README instructs consumers to mount at `/api/video` — allows an unauthenticated remote attacker to read arbitrary `.json` files from the production filesystem of any application following the documented setup…

CVE-2026-54150
GitHub-GHSA

MEDIUM
Zoo Design Studio: Memory-corruption in memory handling of lib-kcl
GHSA-mc9m-6fm9-pghc
pkg: zoo-kcl, kcl-lib
eco: pip
published: Aug 20, 2026
A race condition in kcl-lib can result in a use-after-free when accessing environments concurrently. During Vec reallocation, the previous buffer containing Box pointers is freed and replaced. A concurrent get_env operation that has already loaded a pointer to the old buffer may subsequently index i…
GitHub-GHSA

MEDIUM
Zoo Design Studio: Recursive KCL parsing is vulnerable to denial-of-service
GHSA-jgvr-6x5w-hx5w
pkg: zoo-kcl, kcl-lib
eco: pip
published: Aug 20, 2026
### Impact
Feeding a KCL program that wraps an expression in deep, unnecessary parentheses triggers the parser’s recursive `expression` -> `unnecessarily_bracketed` -> `expression` path. With enough nesting, the call stack grows until it exceeds the process stack limit, causing a stack overflow.
GitHub-GHSA

MEDIUM
OpenTelemetry-Go: Unsynchronized baggage map can panic under concurrent access
GHSA-42cj-99w8-cp2p
pkg: go.opentelemetry.io/otel/bridge/opentracing
eco: go
published: Aug 20, 2026
### Summary

`go.opentelemetry.io/otel/bridge/opentracing` introduced an unsynchronized `extraBaggageItems` map on `bridgeSpan`. One goroutine can write this map through `Span.SetBaggageItem` while another goroutine reads and iterates it during correlation baggage propagation, which can trigger Go's…

CVE-2026-45404
GitHub-GHSA

MEDIUM
Velero vulnerable to file path traversal when extracting from backup's tarball
GHSA-j2g6-362q-6qc6
pkg: github.com/vmware-tanzu/velero
eco: go
published: Aug 20, 2026
### Impact
_What kind of vulnerability is it? Who is impacted?_
If the attacker compromises the backup's object storage backend and uploads a malicious backup tarball including file names like the following:
* ../../../tmp/escape_1 -> file created at /tmp/escape_1
* ../../../../../../..…
CVE-2026-32637
GitHub-GHSA

MEDIUM
BuildKit: Custom frontend could bypass Seccomp/AppArmor
GHSA-7236-3392-c5c6
pkg: github.com/moby/buildkit
eco: go
published: Aug 19, 2026
### Impact
A custom frontend could send a crafted build request that disabled Seccomp and AppArmor protections for the build container, even if the user did not explicitly allow the `security.insecure` entitlement. Other security measures, like Linux capabilities were still applied to these containe…
CVE-2026-61711
GitHub-GHSA

MEDIUM
Uprobe gadgets: unprivileged container's ld.so.cache causes high CPU utilization and container startup DoS
GHSA-vjhx-2cqw-3q6q
pkg: github.com/inspektor-gadget/inspektor-gadget
eco: go
published: Aug 19, 2026
## Summary

An unprivileged container can block all other containers from starting on the
same host by placing a crafted `/etc/ld.so.cache` file in its filesystem. When
Inspektor Gadget attaches any uprobe-based gadget, it parses this file in the
container startup path. A malicious cache causes ~53 …

CVE-2026-53941
GitHub-GHSA

MEDIUM
block_buffer: panic corrupts inline buffer position
GHSA-qwgh-2vcv-g2f7
pkg: block_buffer
eco: rust
published: Aug 19, 2026
### Summary

A caught panic may leave the cursor position of `EagerBuffer` or `ReadBuffer` in a corrupted state; this in turn allows out-of-bounds reads/writes.

### Details & PoC

The following two tests fail miri:

“`rust
#[cfg(miri)]
#[test]
fn eager_digest_blocks_panic_corrupts_inline_position(…

GitHub-GHSA

MEDIUM
Triton VM Soundness Vulnerability due to Missing Constraint
GHSA-vjf8-9fx6-mv6x
pkg: triton-vm
eco: rust
published: Aug 18, 2026
The instruction `sponge_absorb_mem` Triton VM fails to verify that hashed values come from the claimed memory location. Malicious provers can substitute arbitrary data instead of actual memory contents.

Any application using instruction `sponge_absorb_mem` to hash memory data can be given a proof f…

GitHub-GHSA

MEDIUM
MagicMirror: ssrf calendar .js
GHSA-w6x9-28jw-hq7j
pkg: magicmirror
eco: npm
published: Aug 18, 2026
# Vulnerability — SSRF via `ADD_CALENDAR` (MagicMirror² calendar)

> Analysis of the PoC `exploit-ssrf-calendar.js`.
> Target: `calendar/node_helper.js` of MagicMirror², socket.io namespace `/calendar`.

## Identification

| Field | Value |
|——-|——-|
| **PoC file** | `exploit-ssrf-c…

CVE-2026-63643
GitHub-GHSA

MEDIUM
MagicMirror newsfeed Socket.IO notification allows blind server-side request forgery
GHSA-998g-7v5w-cr7g
pkg: magicmirror
eco: npm
published: Aug 18, 2026
# Vulnerability — Blind SSRF via `CHECK_ARTICLE_URL` (MagicMirror² newsfeed)

> Analysis of the PoC `exploit-ssrf-newsfeed.js`.
> Target: `newsfeed/node_helper.js` of MagicMirror², socket.io namespace `/newsfeed`.

## Identification

| Field | Value |
|——-|——-|
| **PoC file** | `exp…

CVE-2026-63642
GitHub-GHSA

MEDIUM
RabbitMQ Java client: TrustEverythingTrustManager used by default in useSslProtocol() enables MITM
GHSA-5m9f-rphj-c435
pkg: com.rabbitmq:amqp-client
eco: maven
published: Aug 18, 2026
## Vulnerability Summary

`com.rabbitmq.client.TrustEverythingTrustManager` accepts ANY TLS certificate (including null chains) and is used as the default trust manager when calling `ConnectionFactory.useSslProtocol()` without arguments. Combined with hostname verification being disabled by default,…

CVE-2026-63336
GitHub-GHSA

MEDIUM
RabbitMQ Java client malformed body frame triggers raw command assembler exception
GHSA-qx7j-jv8m-fppr
pkg: com.rabbitmq:amqp-client
eco: maven
published: Aug 18, 2026
### Summary
RabbitMQ Java Client's inbound AMQP command assembly accepts a content header declaring a small body and then processes a larger body frame by throwing a raw `UnsupportedOperationException` from `CommandAssembler`. A broker peer that the client has connected to can use this malformed fra…
CVE-2026-63335
GitHub-GHSA

MEDIUM
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write
GHSA-8rc5-4fr6-64pw
pkg: github.com/aquasecurity/trivy
eco: go
published: Aug 18, 2026
## Summary

Trivy's plugin manager does not fully validate metadata from a plugin's manifest before using it to construct filesystem paths under the plugin root (`~/.trivy/plugins`). A crafted plugin can cause Trivy to write its files (the manifest and the downloaded plugin binary) outside the plugi…

CVE-2026-63328
GitHub-GHSA

MEDIUM
package pkcs12: Authentication bypass in Decode functions
GHSA-mpwr-8vm7-h73f
pkg: software.sslmate.com/src/go-pkcs12
eco: go
published: Aug 17, 2026
`Decode`, `DecodeChain`, `DecodeTrustStore`, and `ToPEM` can incorrectly accept PKCS#12 files which were encoded with the wrong password, due to a failure to reject excessively-short PBMAC1 keys. Users who decode PKCS#12 files from untrusted sources and rely on the password for authentication can be…
GitHub-GHSA

MEDIUM
Etherpad addressed weak token RNG, login timing, plugin path handling, API request handling
GHSA-92hr-gmr6-h8cp
pkg: ep_etherpad-lite
eco: npm
published: Aug 17, 2026
Fix: PR #7906 (ether/etherpad). A set of medium/low hardening fixes:

– **Weak RNG for tokens (CWE-330):** author/session/readonly IDs were generated with `Math.random()` (client and server). Now use `crypto.getRandomValues`.
– **Login timing / no failure delay (CWE-208/CWE-307):** the OIDC interact…

GitHub-GHSA

MEDIUM
uniget CLI has Path Traversal in Hook Files – Directory Escape Vulnerability
GHSA-m6jg-wr9m-cg2f
pkg: gitlab.com/uniget-org/cli
eco: go
published: Aug 17, 2026
### Summary
Path Traversal vulnerability in hook filename handling allows attackers to access and manipulate arbitrary files outside the hooks directory via directory escape sequences like [passwd](vscode-file://vscode-app/app/extra/vscode/resources/app/out/vs/code/electron-browser/workbench/workben…
CVE-2026-55062
GitHub-GHSA

MEDIUM
uniget CLI has an EDITOR Command Injection
GHSA-qmcq-xw74-w667
pkg: gitlab.com/uniget-org/cli
eco: go
published: Aug 17, 2026
### Summary
The uniget CLI has a command injection vulnerability in [hooks.go](vscode-file://vscode-app/app/extra/vscode/resources/app/out/vs/code/electron-browser/workbench/workbench.html) line 199 where [strings.Split(editor, " ")](vscode-file://vscode-app/app/extra/vscode/resources/app/out/vs/cod…
CVE-2026-55061
GitHub-GHSA

MEDIUM
sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes
GHSA-3496-9g83-7v6x
pkg: sqlparse
eco: pip
published: Aug 17, 2026
### Summary

The documented Python and PHP output modes generate source-code snippets from caller-supplied SQL. Their output filters escape quote characters without first escaping existing backslashes. Crafted SQL can therefore neutralize the generated quote escape, terminate the intended language s…

CVE-2026-59894
GitHub-GHSA

MEDIUM
Terragrunt: Arbitrary File Deletion via Malicious Module Manifest
GHSA-8394-6f8r-whxg
pkg: github.com/gruntwork-io/terragrunt
eco: go
published: Aug 17, 2026
### Summary

Terragrunt is vulnerable to an arbitrary file deletion flaw when downloading external modules. If a remote module contains a maliciously crafted `.terragrunt-module-manifest` file, Terragrunt can be tricked into deleting files anywhere on the local filesystem that the Terragrunt process…

CVE-2026-45099
GitHub-GHSA

MEDIUM
New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass
GHSA-j6gc-4893-qwmp
pkg: github.com/QuantumNous/new-api
eco: go
published: Aug 17, 2026
### Summary
Authenticated users can repeatedly call PUT /api/user/self with language or sidebar_modules while relay requests are consuming quota. The settings path reads a full User snapshot and writes it back through User.Update(), which refreshes Redis with RedisHSetObj and overwrites the Quota fi…
CVE-2026-64865
GitHub-GHSA

MEDIUM
New API: Admin can reset passkeys for same-level or higher-privileged users
GHSA-p845-629j-rcj6
pkg: github.com/QuantumNous/new-api
eco: go
published: Aug 17, 2026
## Summary

The admin passkey reset endpoint lacked the role-level authorization check used by comparable privileged account-protection endpoints. A lower-privileged administrator could attempt passkey reset operations against same-level or higher-privileged users, including root-level accounts.

##…

CVE-2026-64866


Vulnerability Digest — August 17, 2026 · 54 Critical · 3 Exploited






Vulnerability Digest — Monday, August 17, 2026


Security Report

Monday, August 17, 2026  ·  Last 7 days  ·  Min severity: MEDIUM
Total Findings
289
Critical
54
High
153
Actively Exploited
3
CISA-KEV3
NVD244
GitHub-GHSA42
Findings sorted by severity
CISA-KEV

CRITICAL
Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
CVE-2026-68820
pkg: Microsoft Windows Ancillary Function Driver for WinSock

published: Aug 11, 2026

Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Metabase SQL Injection Vulnerability
CVE-2026-72898
pkg: Metabase Metabase

published: Aug 11, 2026

Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored c…
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability
CVE-2026-20349
pkg: Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)

published: Aug 11, 2026

Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
NVD

CRITICAL
CVE-2026-73678
CVE-2026-73678
pkg: python

published: Aug 14, 2026

MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by submitting crafted prompts to the unprotected POST /api/v1/responses/ endpoint, which reaches the Anton agent's …
CWE: CWE-94
NVD

CRITICAL
CVE-2026-73299
CVE-2026-73299
pkg: node

published: Aug 12, 2026

Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies with unrestricted JavaScript member access. An attacker-controlled template could traverse constructor and prototype properties…
CWE: CWE-94, CWE-1336
NVD

CRITICAL
CVE-2026-58115
CVE-2026-58115
pkg: node

published: Aug 11, 2026

A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to programming nodes that are c…
CWE: CWE-306
NVD

CRITICAL
CVE-2026-73269
CVE-2026-73269
pkg: node

published: Aug 12, 2026

A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, can trigger the creation of a cluster-scoped ClusterRoleBinding. This allows the user to escalate their privileges from namespace-local access to clust…
CWE: CWE-269
NVD

CRITICAL
CVE-2026-62420
CVE-2026-62420
pkg: node

published: Aug 12, 2026

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations. When moving an instance cross-project to a different cluster member via POST /1.0/instances/{name} with migration: true, project: <ta…
CWE: CWE-863
NVD

CRITICAL
CVE-2026-73263
CVE-2026-73263
pkg: kubernetes

published: Aug 12, 2026

Prowler is a cloud security platform. Prior to 5.36.0, the Kubernetes provider connection test accepted kubeconfig_content containing a legacy gcp auth-provider with config.cmd-path and config.cmd-args because kubeconfig_contains_exec_auth in api/src/backend/api/v1/serializers.py checked only exec b…
CWE: CWE-78
NVD

CRITICAL
CVE-2026-48765
CVE-2026-48765
pkg: oauth

published: Aug 11, 2026

TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege read collaborator to extract a workspace OAuth `credentialsId` from a readable bot configuration and then overwrite that credential through `handleUpdateOAuthCredentials()` by supplying an attacker-controlled writable …
CWE: CWE-639
NVD

CRITICAL
CVE-2026-72911
CVE-2026-72911
pkg: express

published: Aug 10, 2026

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.118.0 and 16.29.0, the validate_template and render_template calls in erpnext/accounts/doctype/process_statement_of_accounts/process_statement_of_accounts.py render subject, body, and pdf_name fields with unrestricted g…
CWE: CWE-1336
NVD

CRITICAL
CVE-2026-14450
CVE-2026-14450
pkg: kubernetes

published: Aug 10, 2026

A flaw was found in the MaaS API. This vulnerability allows any pod within the cluster to bypass the Kuadrant AuthPolicy gateway by forging HTTP headers, specifically `X-MaaS-Username` and `X-MaaS-Group`, which are trusted verbatim. This lack of first-party authentication enables an attacker to gain…
CWE: CWE-290
NVD

CRITICAL
CVE-2026-72901
CVE-2026-72901
pkg: docker

published: Aug 10, 2026

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated low-privilege member to execute arbitrary commands on the control-plane host because the volumeName field accepted by volumeBackup.create and volumeBackup.runManually is interpolated with…
CWE: CWE-78
NVD

CRITICAL
CVE-2026-72876
CVE-2026-72876
pkg: node

published: Aug 10, 2026

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, swarm.getNodes, swarm.getNodeInfo, swarm.getNodeApps, and swarm.getAppInfos in apps/dokploy/server/api/routers/swarm.ts accept another organization’s serverId without an activeOrganizationId ownership check, and getNo…
CWE: CWE-78, CWE-639, CWE-862
NVD

CRITICAL
CVE-2026-72869
CVE-2026-72869
pkg: docker

published: Aug 10, 2026

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC subscription passes the databaseName parameter to restore builders in packages/server/src/utils/restore/utils.ts, where PostgreSQL, MariaDB, MySQL, and MongoDB commands embed the va…
CWE: CWE-77, CWE-78
NVD

CRITICAL
CVE-2026-72868
CVE-2026-72868
pkg: docker

published: Aug 10, 2026

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, apps/dokploy/server/api/routers/destination.ts interpolates the accessKey, secretAccessKey, region, endpoint, provider, and bucket fields from destination.testConnection into an rclone ls command executed through child_…
CWE: CWE-78, CWE-862
NVD

CRITICAL
CVE-2026-72865
CVE-2026-72865
pkg: docker

published: Aug 10, 2026

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the compose.update operation stores an unvalidated composePath that packages/server/src/utils/builders/compose.ts and packages/server/src/services/compose.ts interpolate into docker compose -f, docker stack deploy -c, a…
CWE: CWE-78
NVD

CRITICAL
CVE-2026-72863
CVE-2026-72863
pkg: docker

published: Aug 10, 2026

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's WebSocket handlers (in-app terminals and log streamers) authenticate the session but never authorize it. They establish who the user is via validateRequest() and then proceed without consulting the role/permis…
CWE: CWE-269, CWE-639, CWE-862
NVD

CRITICAL
CVE-2026-72862
CVE-2026-72862
pkg: docker

published: Aug 10, 2026

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the mariadb.ts, mongo.ts, mysql.ts, postgres.ts, redis.ts, and libsql.ts Dokploy database service deployment functions pass user-controlled dockerImage fields unquoted into docker pull ${dockerImage} shell commands on t…
CWE: CWE-78
NVD

CRITICAL
CVE-2026-72736
CVE-2026-72736
pkg: docker

published: Aug 10, 2026

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy passes user-controlled values directly into shell commands via unquoted template literal interpolation in the registry credential testing and Docker Swarm cluster management endbpoints. Both endpoints have a saf…
CWE: CWE-77
NVD

CRITICAL
CVE-2026-74269
CVE-2026-74269
pkg: express

published: Aug 15, 2026

In the Linux kernel, the following vulnerability has been resolved:

bnxt: fix head underflow on XDP head-grow

The xdp.py test test_xdp_native_adjst_head_grow_data crashes when run on
a bnxt machine (and also crashes in NIPA).

It seems that the bug is an underflow in bnxt_rx_multi_page_skb, which

NVD

CRITICAL
CVE-2026-72317
CVE-2026-72317
pkg: tls

published: Aug 15, 2026

In the Linux kernel, the following vulnerability has been resolved:

SUNRPC: pin upper rpc_clnt across the TLS connect_worker

The TLS connect path has a use-after-free: nothing pins the
upper rpc_clnt across the delayed connect_worker. xs_connect()
stores task->tk_client in sock_xprt::clnt as a raw…

NVD

CRITICAL
CVE-2026-72222
CVE-2026-72222
pkg: tls

published: Aug 15, 2026

In the Linux kernel, the following vulnerability has been resolved:

sunrpc: pin svc_xprt across the asynchronous TLS handshake callback

svc_tcp_handshake() stores the raw svc_xprt pointer in
tls_handshake_args.ta_data and submits the request through
tls_server_hello_x509(). The handshake core take…

NVD

CRITICAL
CVE-2026-72221
CVE-2026-72221
pkg: tls

published: Aug 15, 2026

In the Linux kernel, the following vulnerability has been resolved:

sunrpc: wait for in-flight TLS handshake callback when cancel loses race

When wait_for_completion_interruptible_timeout() in
svc_tcp_handshake() returns 0 (timeout) or -ERESTARTSYS (signal) and
tls_handshake_cancel() then returns …

NVD

CRITICAL
CVE-2026-50027
CVE-2026-50027
pkg: oauth

published: Aug 14, 2026

mcp-memory-service is a semantic memory layer for AI applications. Prior to 10.67.1, all HTTP routes under /api/documents/* in mcp-memory-service are served without any authentication dependency, even when the server is configured with an API key (MCP_API_KEY) or OAuth. An unauthenticated remote att…
CWE: CWE-306
NVD

CRITICAL
CVE-2026-73649
CVE-2026-73649
pkg: express

published: Aug 13, 2026

Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for CVE-2026-44966 filtered constructor, __proto__, and prototype only in the #set assignment handler in src/compile/set.ts, while property-read expressions in src/compile/references.ts…
CWE: CWE-94
NVD

CRITICAL
CVE-2026-67614
CVE-2026-67614
pkg: jwt

published: Aug 13, 2026

CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote attackers to forge valid authentication tokens and obtain an interactive root shell via WebSocket on port 8888. Attackers can craft a forged JWT signed wit…
CWE: CWE-798
NVD

CRITICAL
CVE-2026-28185
CVE-2026-28185
pkg: go

published: Aug 13, 2026

Unauthenticated Broken Authentication in Log in with Google <= 1.4.2 versions.
CWE: CWE-345
NVD

CRITICAL
CVE-2026-28008
CVE-2026-28008
pkg: oauth

published: Aug 13, 2026

Unauthenticated Broken Authentication in OAuth Single Sign On – SSO (OAuth Client) <= 7.0.0 versions.
CWE: CWE-290
NVD

CRITICAL
CVE-2026-49819
CVE-2026-49819
pkg: jwt

published: Aug 13, 2026

UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerInitSuperuser` (`backend/pb/handlers.go:249`), reachable as `POST /api/upsnap/init-superuser`. The vulnerable code lacks any authentication, setup token…
CWE: CWE-78, CWE-269, CWE-306, CWE-862
NVD

CRITICAL
CVE-2026-73519
CVE-2026-73519
pkg: docker

published: Aug 12, 2026

WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs, allowing remote unauthenticated attackers to bypass authentication by supplying this value in the X-WolfStack-Secret header to the require_auth() gate…
CWE: CWE-798
NVD

CRITICAL
CVE-2026-73034
CVE-2026-73034
pkg: python

published: Aug 11, 2026

DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers to write arbitrary files to any location on the server by injecting directory traversal sequences into the user_id HTTP header of the Python file-upload endpoint. Attackers can send a crafted multipar…
CWE: CWE-22
NVD

CRITICAL
CVE-2026-73211
CVE-2026-73211
pkg: oauth

published: Aug 11, 2026

PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.1.6, ActorFollowModel.updateScore() interpolates the attacker-controlled ActivityPub actor inboxUrl into an SQL query, allowing an unauthenticated remote server to read and write PeerTube database tables, including oAuthToken.…
CWE: CWE-89
NVD

CRITICAL
CVE-2026-69102
CVE-2026-69102
pkg: jwt

published: Aug 11, 2026

MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in application-maxkey.properties that allows unauthenticated attackers to forge valid JWT tokens and authenticate as any user by exploiting the password-skipped login endpoint. Attackers can craft a JWT token…
CWE: CWE-798
NVD

CRITICAL
CVE-2026-72920
CVE-2026-72920
pkg: jwt

published: Aug 11, 2026

SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC service without mandatory authentication when jwt.filer_signing.key is unset, allowing any client that can reach the filer gRPC port to invoke CreateUser, CreateAccessKey, PutPolicy…
CWE: CWE-306
NVD

CRITICAL
CVE-2026-68160
CVE-2026-68160
pkg: go

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()

ceph_handle_caps() reads snap_trace_len from the wire-format
ceph_mds_caps header and uses it unconditionally to build a fake
end pointer (snaptrace + snaptr…

NVD

CRITICAL
CVE-2026-68127
CVE-2026-68127
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

ila: reload IPv6 header after pskb_may_pull in checksum adjust

ila_csum_adjust_transport() caches ip6h = ipv6_hdr(skb) before calling
pskb_may_pull(). On a non-linear skb whose transport header sits in a page
fragment, pskb_may_pu…

NVD

CRITICAL
CVE-2026-68123
CVE-2026-68123
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

openvswitch: fix GSO userspace truncation underflow

OVS_ACTION_ATTR_TRUNC currently stores a delta from the original skb
length in OVS_CB(skb)->cutlen. When a later userspace action segments a
GSO skb, queue_gso_packets() reuses t…

NVD

CRITICAL
CVE-2026-68117
CVE-2026-68117
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

tipc: clear sock->sk on the failed-insert path in tipc_sk_create()

When tipc_sk_create() fails to insert the new socket (tipc_sk_insert()
returns non-zero), its error path frees the sk with sk_free() but leaves
sock->sk pointing a…

NVD

CRITICAL
CVE-2026-73843
CVE-2026-73843
pkg: kubernetes

published: Aug 13, 2026

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, internal/cluster-gateway/server.go served caller-facing management APIs on the externally reachable agent listener without authentication, allowing network-reachable attackers to invoke /api/proxy/ and…
CWE: CWE-306, CWE-668, CWE-862
NVD

CRITICAL
CVE-2026-8715
CVE-2026-8715
pkg: kubernetes

published: Aug 13, 2026

Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissions to read files from the operator pod's filesystem and transmit their contents…
CWE: CWE-552
NVD

CRITICAL
CVE-2026-72877
CVE-2026-72877
pkg: docker

published: Aug 10, 2026

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the dockerImage field is interpolated without quoting into shell commands in buildRemoteDocker() in packages/server/src/utils/providers/docker.ts and is validated only as an optional string. An authenticated user with a…
CWE: CWE-78
NVD

CRITICAL
CVE-2026-68124
CVE-2026-68124
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

mctp: serial: handle zero-length frames to prevent rx buffer overflow

The MCTP serial receive state machine reads a frame length byte in
mctp_serial_push_header() case 2 and validates it upper-bound-only:

if (c > MCTP_SERIAL_FRA…

NVD

CRITICAL
CVE-2026-73653
CVE-2026-73653
pkg: vite

published: Aug 13, 2026

Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, takeScreenshot, screenshotMatcher, stopChunkTrace, deleteTracing, and annotateTraces accept browser-supplied file paths without enforcing the allowWrite …
CWE: CWE-22, CWE-552, CWE-862
NVD

CRITICAL
CVE-2026-50561
CVE-2026-50561
pkg: jwt

published: Aug 12, 2026

Yuxi is a large-model-based intelligent knowledge base and knowledge graph agent development platform. Prior to version 0.6.2, the project's authentication mechanism contains a flaw. In affected versions, the system does not sufficiently validate the identity token in the Authorization header — on…
CWE: CWE-287
NVD

CRITICAL
CVE-2026-50516
CVE-2026-50516
pkg: microsoft azure_kubernetes_service

published: Aug 11, 2026

Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
CWE: CWE-306
NVD

CRITICAL
CVE-2026-73080
CVE-2026-73080
pkg: jwt

published: Aug 11, 2026

SeaweedFS is a distributed storage system. Prior to 4.24, VolumeServer.FetchAndWriteNeedle in weed/server/volume_grpc_remote.go fetches a caller-supplied remote endpoint through weed/remote_storage/s3/s3_storage_client.go and writes the response into a needle. The RPC performs no authentication and …
CWE: CWE-918
GitHub-GHSA

CRITICAL
SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle
GHSA-87fv-vqqr-m4jr
pkg: github.com/seaweedfs/seaweedfs
eco: go
published: Aug 11, 2026
### Impact
`VolumeServer.FetchAndWriteNeedle` fetches a caller-supplied remote endpoint and writes the response into a needle. Before 4.24 this RPC performed no authentication and no validation of the target, so anyone able to reach a volume server's gRPC port could coerce the server into issuing re…
CVE-2026-73080
NVD

CRITICAL
CVE-2026-47754
CVE-2026-47754
pkg: node

published: Aug 10, 2026

Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.x through 2.19.1 and all 1.x versions contain an unauthenticated path traversal in the `archiveEntryName` parameter of the `action=read` endpoint that is part of the original 1.x Metacat API. `A…
CWE: CWE-22, CWE-862
NVD

CRITICAL
CVE-2026-49457
CVE-2026-49457
pkg: tls

published: Aug 14, 2026

erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and the hostname was not compared against the certificate,…
CWE: CWE-295, CWE-297
NVD

CRITICAL
CVE-2026-73501
CVE-2026-73501
pkg: oauth

published: Aug 12, 2026

kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces a nil AuthenticationFunc with NoopAuthenticationFunc, which returns nil without checking credentials. This substitution causes every OpenAPI se…
CWE: CWE-287
NVD

CRITICAL
CVE-2026-71290
CVE-2026-71290
pkg: tls

published: Aug 11, 2026

Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between the client and the server can impersonate…
CWE: CWE-295
NVD

CRITICAL
CVE-2026-68083
CVE-2026-68083
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix path resolution in ksmbd_vfs_kern_path_create

The SMB2 open lookup is rooted at the share with LOOKUP_BENEATH, but the
create/mkdir/hardlink sink is not: ksmbd_vfs_kern_path_create() builds an
absolute path with convert…

NVD

CRITICAL
CVE-2026-73842
CVE-2026-73842
pkg: kubernetes

published: Aug 13, 2026

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go exposed /api/proxy/, /api/exec/, and /api/wirelogs/ on an internal listener without requiring a client certificate or token, allowing any network-reachab…
CWE: CWE-269, CWE-306, CWE-862
NVD

HIGH
CVE-2026-72382
CVE-2026-72382
pkg: express

published: Aug 15, 2026

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: reject undersized DACLs before parsing ACEs

parse_dacl() limits the attacker-controlled ACE count by comparing it
with the number of minimal ACEs that fit in the DACL size. The DACL size
field is 16 bits, but the expression…

NVD

HIGH
CVE-2026-73841
CVE-2026-73841
pkg: kubernetes

published: Aug 13, 2026

OpenChoreo is a complete, open-source developer platform for Kubernetes. From 1.2.0-rc.1 until 1.2.0, internal/openchoreo-api/api/handlers/exec.go and internal/openchoreo-api/api/handlers/wirelogs.go authorize component:exec and wirelogs:view using the caller-supplied project query parameter instead…
CWE: CWE-639, CWE-863
NVD

HIGH
CVE-2026-73667
CVE-2026-73667
pkg: kubernetes

published: Aug 13, 2026

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.0-rc.2, OpenChoreo Workflow Plane templates under samples/getting-started/workflow-templates/ interpolated developer-controlled workflow parameters into shell program text executed through sh -c i…
CWE: CWE-78
NVD

HIGH
CVE-2026-15741
CVE-2026-15741
pkg: express

published: Aug 13, 2026

SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition. Attacks affect expression deparse consumers broadly, including pg_dump, psql commands like \sf, and any similar usage in non-core tools. Versions before Pos…
CWE: CWE-89
NVD

HIGH
CVE-2026-49473
CVE-2026-49473
pkg: express

published: Aug 13, 2026

@cedar-policy/authorization-for-expressjs is an open-source Express.js middleware that integrates Cedar authorization into Express applications by mapping HTTP requests to Cedar actions and evaluating authorization policies before allowing requests to proceed. Versions prior to 0.3.0 have an issue w…
CWE: CWE-436, CWE-863
NVD

HIGH
CVE-2026-13622
CVE-2026-13622
pkg: node

published: Aug 12, 2026

A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside the target virt-launcher pod via /proc/<pid>/root/ paths using net.Dial() without symlink protection. These socket paths reside in qemu-owned director…
CWE: CWE-22
NVD

HIGH
CVE-2026-49467
CVE-2026-49467
pkg: express

published: Aug 12, 2026

Pingvin Share X is a secure and easy self-hosted file sharing platform. A vulnerability in versions 1.5.0 through 1.18.0 allow an attacker to bypass password verification when managing Time-based One-Time Password (TOTP) settings. The root cause is a missing `await` keyword on calls to the asynchron…
CWE: CWE-303, CWE-304
NVD

HIGH
CVE-2026-44741
CVE-2026-44741
pkg: express

published: Aug 12, 2026

Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Versions prior to 2.3.6 and 1.7.18 have a SQL injection vulnerability in Pimcore's translation grid date filter — the user-supplied `property` field from the filter JSON is interpolated directly into a `UNIX_TIMESTAMP(DATE(FROM_UNIX…
CWE: CWE-89
NVD

HIGH
CVE-2026-65941
CVE-2026-65941
pkg: go

published: Aug 12, 2026

In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.
CWE: CWE-73, CWE-94, CWE-306, CWE-918
NVD

HIGH
CVE-2026-58076
CVE-2026-58076
pkg: apache airflow

published: Aug 12, 2026

Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and instantiating it with arguments from the same blob, with no restriction on what could be imported. An operator's `executor_config` reaches that branch, s…
CWE: CWE-502
NVD

HIGH
CVE-2026-19560
CVE-2026-19560
pkg: go

published: Aug 11, 2026

Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-19559
CVE-2026-19559
pkg: go

published: Aug 11, 2026

Use after free in HTML in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-19556
CVE-2026-19556
pkg: go

published: Aug 11, 2026

Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-55676
CVE-2026-55676
pkg: nginx

published: Aug 11, 2026

Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` and stores them in a directory served by the same nginx and php-fpm instance. The allow-list that should restrict accepted file types is an empty array …
CWE: CWE-434
NVD

HIGH
CVE-2026-73222
CVE-2026-73222
pkg: node

published: Aug 11, 2026

Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the –studio option in cli-tool/src/sandbox-server.js binds to all interfaces on port 3444, permits cross-origin requests, and requires no authentication. The PO…
CWE: CWE-78, CWE-306, CWE-352
NVD

HIGH
CVE-2026-18691
CVE-2026-18691
pkg: node

published: Aug 11, 2026

An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to influence which authentication mechanism is used when one replica set member connects to another. Under certain conditions, this could cause the cluster's shared internal credential to be …
CWE: CWE-757
NVD

HIGH
CVE-2026-49179
CVE-2026-49179
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.
CWE: CWE-77
NVD

HIGH
CVE-2026-72533
CVE-2026-72533
pkg: docker

published: Aug 11, 2026

An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privileged users to bypass Docker proxy authorization checks via non-canonical URL normalization, defeating all authorization middleware. The proxy endpoint fails to normalize request paths before applying…
CWE: CWE-287
NVD

HIGH
CVE-2026-15555
CVE-2026-15555
pkg: node

published: Aug 11, 2026

A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicated session data via the JBoss Marshalling River unmarshaller with no class filtering — enabling RCE via deserialization gadget chains on every cluster node.
CWE: CWE-502
NVD

HIGH
CVE-2026-18982
CVE-2026-18982
pkg: kubernetes

published: Aug 10, 2026

A flaw was found in the RHOAI training-operator. This vulnerability allows a user with standard edit or admin roles in any Kubernetes namespace to escalate their privileges. Through the creation of training jobs, an attacker can impersonate service accounts, access the host filesystem, and potential…
CWE: CWE-250
NVD

HIGH
CVE-2026-18951
CVE-2026-18951
pkg: kubernetes

published: Aug 10, 2026

A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly aggregates `trainjobs` management permissions into the native Kubernetes `edit ClusterRole`. This allows any user with `edit ClusterRole` permissions in a namespace to create, modify…
CWE: CWE-284
NVD

HIGH
CVE-2026-68341
CVE-2026-68341
pkg: express

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

ovpn: fix use after free in unlock_ovpn()

unlock_ovpn() iterates over the release_list using llist_for_each_entry()
and drops the peer reference inside the loop body via ovpn_peer_put().

If this drops the last reference, the peer…

NVD

HIGH
CVE-2026-68294
CVE-2026-68294
pkg: node

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

net: qrtr: restrict socket creation to the initial network namespace

QRTR keeps its entire port and node state in module-global variables
that are not partitioned per network namespace: qrtr_local_nid is a
single global node id (a…

NVD

HIGH
CVE-2026-68140
CVE-2026-68140
pkg: go

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

net/iucv: fix use-after-free of a severed iucv_path

af_iucv queues not-yet-received message notifications on iucv->message_q,
each holding a raw pointer to the connection's iucv_path. When the peer
severs the connection, iucv_sev…

NVD

HIGH
CVE-2026-68128
CVE-2026-68128
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

ice: reject out-of-range ptype in ice_parser_profile_init

set_bit(rslt->ptype, prof->ptypes) operates on a DECLARE_BITMAP of
ICE_FLOW_PTYPE_MAX (1024) bits. Nothing prevents a malicious VF from
providing ptype >= 1024 through VIRT…

NVD

HIGH
CVE-2026-68125
CVE-2026-68125
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

mac802154: llsec: reject frames shorter than the authentication tag

llsec_do_decrypt_auth() computes the associated-data length for the
AEAD request as

assoclen += datalen – authlen;

where datalen is the number of bytes after t…

NVD

HIGH
CVE-2026-68108
CVE-2026-68108
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu/vce: fix integer overflow in image size

Fix a security vulnerability where malicious VCE command streams
with oversized dimensions (e.g. 65536×65536) cause 32-bit integer
overflow, wrapping the calculated buffer size t…

NVD

HIGH
CVE-2026-68107
CVE-2026-68107
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu/vcn4: avoid rereading IB param length

Reuse the parameter length returned by
vcn_v4_0_enc_find_ib_param() instead of rereading it from
the IB.

This avoids a potential TOCTOU issue if the IB contents
change between read…

NVD

HIGH
CVE-2026-68098
CVE-2026-68098
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: bound DACL dedup walk to copied ACEs

set_ntacl_dacl() can stop copying ACEs before consuming the full input
DACL when size accounting overflows.

When that happens, num_aces reflects only the ACEs that were actually
copied …

NVD

HIGH
CVE-2026-68097
CVE-2026-68097
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: validate ACE size against SID sub-authorities

set_ntacl_dacl() validates sid.num_subauth before copying an ACE, but
does not verify that the declared ACE size contains all sub-authorities
described by that field. An undersi…

NVD

HIGH
CVE-2026-68091
CVE-2026-68091
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

HID: wacom: stop hardware after post-start probe failures

wacom_parse_and_register() starts HID hardware before registering inputs
and initializing pad LEDs/remotes. Those later steps can fail, but their
error paths currently rele…

NVD

HIGH
CVE-2026-49478
CVE-2026-49478
pkg: kubernetes

published: Aug 13, 2026

Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Versions through 1.8.5 improperly follow cross-host redirects and attach Kubernetes ServiceAccount tokens during OIDC discovery, allowing a malicious or compromised issuer to perform blind …
CWE: CWE-918
NVD

HIGH
CVE-2026-18608
CVE-2026-18608
pkg: kubernetes

published: Aug 10, 2026

A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which defines its permissions, includes extensive privileges beyond what is necessary for its operation. These excessive permissions, such as the ability to execute commands within pods and manage cluster-wid…
CWE: CWE-250
NVD

HIGH
CVE-2026-20349
CVE-2026-20349
pkg: cisco adaptive_security_appliance_software, cisco secure_firewall_threat_defense

published: Aug 11, 2026

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of servi…
CWE: CWE-244
GitHub-GHSA

HIGH
Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoS
GHSA-p28v-f755-9qrg
pkg: @trigger.dev/core
eco: npm
published: Aug 13, 2026
## Summary

The run-metadata update endpoint `PUT /api/v1/runs/:runId/metadata` applies client-supplied
"operations" by passing the **attacker-controlled `operation.key`** straight into
`new JSONHeroPath(operation.key).set(newMetadata, value)`
(`packages/core/src/v3/runMetadata/operations.ts:22-23`)…

CVE-2026-73654
NVD

HIGH
CVE-2026-73079
CVE-2026-73079
pkg: oauth

published: Aug 11, 2026

Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product subscriptions. From 0.1.135, to 0.1.168, platform API keys issued to tenants are exchanged for upstream requests made with shared provider accounts (ChatGPT/Codex OAuth, OpenAI platform keys, or an ope…
CWE: CWE-22, CWE-441
GitHub-GHSA

HIGH
Token Optimizer MCP: OS command injection in smart_user via username in get-user-info
GHSA-49mq-fc6q-3h46
pkg: @ooples/token-optimizer-mcp
eco: npm
published: Aug 14, 2026
### Summary

`token-optimizer-mcp` is vulnerable to OS command injection in the `smart_user` tool.

The `get-user-info` operation accepts a user-controlled `username` argument and later interpolates it into a shell command executed through `execAsync()`:

“`ts
getent passwd "${username}" || grep "^…

CVE-2026-55157
NVD

HIGH
CVE-2026-56865
CVE-2026-56865
pkg: go

published: Aug 13, 2026

A malicious GOPROXY was previously capable of forging up to two sumdb tiles that allow for a requested module to bypass the GOSUMDB check and persist attacker-controlled module content to a local Go module cache. This attack allows for a malicious GOPROXY to serve malicious module content that canno…
CWE: CWE-347
GitHub-GHSA

HIGH
MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`
GHSA-49m4-vp58-wgc9
pkg: stata-mcp
eco: pip
published: Aug 12, 2026
## Stata Command Injection via Unsanitized `package` in `ado_package_install`

### Summary

The `ado_package_install` MCP tool in `stata-mcp` concatenates user-controlled input directly into a Stata command string without any validation or sanitization. An attacker who can invoke the MCP tool or the…

CVE-2026-55071
NVD

HIGH
CVE-2026-67180
CVE-2026-67180
pkg: go

published: Aug 11, 2026

Google Turbinia allows arbitrary command execution via worker tasks. An attacker with privileges to submit a processing request or influence an evidence path/name obtains code execution on the worker fleet. Fixed on 2026-07-10.
CWE: CWE-78
NVD

HIGH
CVE-2026-8718
CVE-2026-8718
pkg: tls

published: Aug 10, 2026

tls_opt_dtls_peer_connection_id_value_get() in subsys/net/lib/sockets/sockets_tls.c, which handles getsockopt(SOL_TLS, TLS_DTLS_PEER_CID_VALUE), passed the caller-supplied optval directly to mbedtls_ssl_get_peer_cid() without verifying the buffer was at least MBEDTLS_SSL_CID_OUT_LEN_MAX (default 32)…
CWE: CWE-787
NVD

HIGH
CVE-2026-68371
CVE-2026-68371
pkg: node

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

usb: musb: omap2430: Do not put borrowed of_node in probe

omap2430_probe() stores pdev->dev.of_node in a local np variable. This is
a borrowed pointer and the probe function does not take a reference to
it.

The success and error …

NVD

HIGH
CVE-2026-19557
CVE-2026-19557
pkg: go

published: Aug 11, 2026

Use after free in TabStrip in Google Chrome on Mac prior to 151.0.7922.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-69119
CVE-2026-69119
pkg: oauth

published: Aug 11, 2026

Taubyte Tau v1.1.10 contains a missing authorization vulnerability in the services/auth HTTP service that allows any authenticated user to read or permanently delete another tenant's project by supplying an arbitrary project ID to the GET and DELETE /projects/{id} endpoints. The GitHubTokenHTTPAuth …
CWE: CWE-639
NVD

HIGH
CVE-2026-56179
CVE-2026-56179
pkg: microsoft windows_11_24h2, microsoft windows_11_25h2, microsoft windows_11_26h1

published: Aug 11, 2026

Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.
CWE: CWE-346
GitHub-GHSA

HIGH
Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket
GHSA-2j9v-p4xj-cjw2
pkg: github.com/lima-vm/lima/v2
eco: go
published: Aug 14, 2026
### Impact
On an instance of Lima running with `qemu` driver, an arbitrary user in the VM could access `/run/lima-guestagent.sock` when the guest agent is enabled.

This could result in running an arbitrary command with the root privileges in the VM (**not on the host**), as `lima-guestagent.sock` p…

CVE-2026-53657
NVD

HIGH
CVE-2026-73666
CVE-2026-73666
pkg: kubernetes

published: Aug 13, 2026

OpenChoreo is a developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.1, the OpenChoreo Backstage backend hardcoded backend.auth.dangerouslyDisableDefaultAuthPolicy and auth.providers.guest.dangerouslyAllowOutsideDevelopment to true, exposing /api/* without authentication and allowing un…
CWE: CWE-306
NVD

HIGH
CVE-2026-13048
CVE-2026-13048
pkg: express

published: Aug 13, 2026

Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the language attribute into the catalog filename.

load_lexicon builds the catalog path by appending `Messages/$lang.po` to the directory …

CWE: CWE-22, CWE-95
NVD

HIGH
CVE-2026-68118
CVE-2026-68118
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

tcp: challenge ACK for non-exact RST in SYN-RECEIVED

The SYN-RECEIVED request-socket path in tcp_check_req() accepts an
in-window RST without requiring SEG.SEQ to exactly match RCV.NXT. A
non-exact RST therefore removes the reque…

NVD

HIGH
CVE-2026-72665
CVE-2026-72665
pkg: go

published: Aug 13, 2026

Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who is able to author and evaluate Elastic Security detection rules can c…
CWE: CWE-862
NVD

HIGH
CVE-2026-55987
CVE-2026-55987
pkg: react

published: Aug 13, 2026

OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)
CWE: CWE-863
NVD

HIGH
CVE-2026-73289
CVE-2026-73289
pkg: jwt

published: Aug 12, 2026

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS evaluates the ForAllValues: and ForAnyValue: set qualifiers with the negated string operators StringNotEquals, StringNotEqualsIgnoreCase, StringNotLike, ArnNotEquals, and ArnNotLike using each other's semanti…
CWE: CWE-863
NVD

HIGH
CVE-2026-73286
CVE-2026-73286
pkg: jwt

published: Aug 12, 2026

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS get_condition_values folds attacker-controlled request headers from HeaderMap into server-derived userid, username, principaltype, groups, versionid, signatureversion, jwt:, and ldap: condition keys, allowing…
CWE: CWE-863
NVD

HIGH
CVE-2026-19594
CVE-2026-19594
pkg: python

published: Aug 12, 2026

Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-deputy privilege escalation through two related weaknesses: path traversal (CWE-22) via unencoded `..` identifier path segments, and HTTP parameter pollution (CWE-141) via unencoded `…
CWE: CWE-22, CWE-141
NVD

HIGH
CVE-2026-18961
CVE-2026-18961
pkg: oauth

published: Aug 12, 2026

The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnerable to Authentication Bypass via Unverified Provider Email in all versions up to, and including, 1.4.3. This is due to the plugin trusting the unverified email field returned by …
CWE: CWE-287
NVD

HIGH
CVE-2026-72921
CVE-2026-72921
pkg: jwt

published: Aug 11, 2026

SeaweedFS is a distributed storage system. Prior to 4.24, the weed/server/filer_server_handlers.go allowed_prefixes authorization check used strings.HasPrefix on raw path strings, so a filer JWT scoped to /tenant1 also authorized sibling paths such as /tenant1234, /tenant1-old, and /tenant1backup, e…
CWE: CWE-863
NVD

HIGH
CVE-2026-72903
CVE-2026-72903
pkg: windows

published: Aug 10, 2026

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.235, a malicious SFTP server can return a backslash traversal filename through entry.name. In tabby-ssh/src/session/sftp.ts, SFTPSession.readdir() and _makeFile() use POSIX path processing that preserves the backslash…
CWE: CWE-22
NVD

HIGH
CVE-2026-68100
CVE-2026-68100
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl

set_ntacl_dacl() copies each ACE from the attacker-controlled stored
security descriptor verbatim into the response DACL without checking
sid.num_subauth. The ACE byte…

NVD

HIGH
CVE-2026-70454
CVE-2026-70454
pkg: tls

published: Aug 13, 2026

rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation vulnerability that allows on-path attackers to intercept encrypted sessions by presenting self-signed or otherwise invalid certificates. Attackers can exploit the failure to valid…
CWE: CWE-295
NVD

HIGH
CVE-2026-65937
CVE-2026-65937
pkg: go

published: Aug 12, 2026

In WhatsUp Gold versions released before 2026.0.2, an authenticated attacker can bypass frontend controls and inject persistent script content.
CWE: CWE-79
NVD

HIGH
CVE-2026-68085
CVE-2026-68085
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled

HCI_UART_SENDING bit in tx_state means write_work is pending and blocks
queueing it again. Currently this bit is not cleared when canceling the
work in hci_u…

NVD

HIGH
CVE-2026-6726
CVE-2026-6726
pkg: tls

published: Aug 11, 2026

An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and falsify other TPM 2.…
CWE: CWE-704
NVD

HIGH
CVE-2026-68116
CVE-2026-68116
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

vxlan: mdb: Fix source list corruption on a failed replace

When replacing the source list of an MDB remote entry, all existing
sources are first marked for deletion and vxlan_mdb_remote_srcs_add()
is then called to add the new sou…

NVD

HIGH
CVE-2026-74270
CVE-2026-74270
pkg: tls

published: Aug 15, 2026

In the Linux kernel, the following vulnerability has been resolved:

handshake: Require admin permission for DONE command

ACCEPT and DONE are the two downcalls of the handshake genl
family, both intended for use by the trusted handshake agent
(tlshd). ACCEPT already requires GENL_ADMIN_PERM; DONE h…

NVD

HIGH
CVE-2026-73505
CVE-2026-73505
pkg: express

published: Aug 13, 2026

Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, the setStyle() function in src/segments/path.go passed pt.Path, which includes raw folder names, to template.Render, whose function map exposes cmd, so an attacker-controlled directory name co…
CWE: CWE-94, CWE-1336
NVD

HIGH
CVE-2026-73325
CVE-2026-73325
pkg: python

published: Aug 12, 2026

Fujitsu Research's OneCompression library 1.2.0 contains an unsafe deserialization vulnerability that allows attackers to execute arbitrary code by supplying a crafted model.pt checkpoint file, as QuantizedModelLoader.load_quantized_model_pt() unconditionally calls torch.load with weights_only=False…
CWE: CWE-502
NVD

HIGH
CVE-2026-73231
CVE-2026-73231
pkg: node

published: Aug 11, 2026

Faker generates massive amounts of fake data in the browser and Node.js. Prior to 10.5.0, the faker.helpers.fake method in src/modules/helpers/eval.ts allows attacker-controlled fake templates to access the Function constructor through fakeEval.resolveProperty when a function returns another functio…
CWE: CWE-95
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-62871 – .NET Elevation of Privilege Vulnerability
GHSA-vg44-h755-9hw7
pkg: Microsoft.WindowsDesktop.App.Runtime.win-arm64, Microsoft.WindowsDesktop.App.Runtime.win-x64, Microsoft.WindowsDesktop.App.Runtime.win-x86
eco: nuget
published: Aug 11, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in Windows Presentation Foundation. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

Out-of-bounds write in .NET …

CVE-2026-62871
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-70354 – .NET Core Remote Code Execution Vulnerability
GHSA-gg8c-3338-xw2f
pkg: Microsoft.WindowsDesktop.App.Runtime.win-arm64, Microsoft.WindowsDesktop.App.Runtime.win-x64, Microsoft.WindowsDesktop.App.Runtime.win-x86
eco: nuget
published: Aug 11, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in Windows Presentation Foundation. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

An out-of-bounds write in .N…

CVE-2026-70354
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-62886 – .NET Elevation of Privilege Vulnerability
GHSA-jqhp-238x-qhgf
pkg: Microsoft.WindowsDesktop.App.Runtime.win-arm64, Microsoft.WindowsDesktop.App.Runtime.win-x64, Microsoft.WindowsDesktop.App.Runtime.win-x86
eco: nuget
published: Aug 11, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in Windows Presentation Foundation. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

An integer overflow or wrapa…

CVE-2026-62886
NVD

HIGH
CVE-2026-61359
CVE-2026-61359
pkg: microsoft windows_11_23h2, microsoft windows_11_24h2, microsoft windows_11_25h2

published: Aug 11, 2026

Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.
CWE: CWE-122
NVD

HIGH
CVE-2026-61358
CVE-2026-61358
pkg: microsoft windows_10_1809, microsoft windows_10_21h2, microsoft windows_10_22h2

published: Aug 11, 2026

Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.
CWE: CWE-59
NVD

HIGH
CVE-2026-61356
CVE-2026-61356
pkg: microsoft windows_10_1809, microsoft windows_10_21h2, microsoft windows_10_22h2

published: Aug 11, 2026

Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
CWE: CWE-306
NVD

HIGH
CVE-2026-61355
CVE-2026-61355
pkg: microsoft windows_10_21h2, microsoft windows_10_22h2, microsoft windows_11_23h2

published: Aug 11, 2026

Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
CWE: CWE-122
NVD

HIGH
CVE-2026-61353
CVE-2026-61353
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CWE: CWE-122
NVD

HIGH
CVE-2026-61349
CVE-2026-61349
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.
CWE: CWE-362, CWE-416
NVD

HIGH
CVE-2026-59127
CVE-2026-59127
pkg: windows

published: Aug 11, 2026

Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally.
CWE: CWE-190
NVD

HIGH
CVE-2026-56174
CVE-2026-56174
pkg: microsoft windows_10_1809, microsoft windows_10_21h2, microsoft windows_10_22h2

published: Aug 11, 2026

Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.
CWE: CWE-426
NVD

HIGH
CVE-2026-54984
CVE-2026-54984
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.
CWE: CWE-122
NVD

HIGH
CVE-2026-54981
CVE-2026-54981
pkg: python

published: Aug 11, 2026

Inclusion of functionality from untrusted control sphere in Visual Studio Code – Python extension allows an unauthorized attacker to bypass a security feature locally.
CWE: CWE-693, CWE-829
NVD

HIGH
CVE-2026-42976
CVE-2026-42976
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally.
CWE: CWE-306
NVD

HIGH
CVE-2026-72693
CVE-2026-72693
pkg: node

published: Aug 11, 2026

`openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged context. In the documented `kbrequest`/init usage, the ownership test in `authenticate_user()` relies on `stat("/proc/<pid>/fd/0")`. `stat()` on `/proc/<pid>/fd/0` follows the syml…
CWE: CWE-284
NVD

HIGH
CVE-2026-68222
CVE-2026-68222
pkg: go

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

media: msi2500: Return queued buffers on start_streaming() failure

The vb2 framework hands buffers to the driver via buf_queue() before
calling start_streaming(). If start_streaming() returns an error
without first returning thos…

NVD

HIGH
CVE-2026-68121
CVE-2026-68121
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

pppoe: reload header pointer after dev_hard_header()

pppoe_sendmsg() saves a pointer to the PPPoE header before calling
dev_hard_header(). Device header callbacks are allowed to reallocate the
skb head, invalidating pointers into …

NVD

HIGH
CVE-2026-68106
CVE-2026-68106
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: fix division by zero with invalid uvd dimensions

When width or height is less than 16, width_in_mb or height_in_mb
becomes 0, leading to fs_in_mb being 0. This causes a division by
zero when calculating num_dpb_buffer …

NVD

HIGH
CVE-2026-68104
CVE-2026-68104
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: invoke pm_genpd_remove() before freeing genpd

Call pm_genpd_remove() to unregister from global list prior to releasing
acp_genpd memory, and clear the pointer after free.

(cherry picked from commit cd8650d7a91ee8b768e…

NVD

HIGH
CVE-2026-48767
CVE-2026-48767
pkg: oauth

published: Aug 11, 2026

TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege guest member of a workspace to obtain a live Google Sheets OAuth access token for that workspace by calling the Google Sheets helper `getAccessToken`. The vulnerable path checks only whether the caller has read access …
CWE: CWE-200
NVD

HIGH
CVE-2026-18621
CVE-2026-18621
pkg: node

published: Aug 10, 2026

A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security hardening by submitting a malicious Argo Workflow through the V1 API path. This allows the API server to create pods with elevated privileges, acting as a 'confused deputy' on behalf of…
CWE: CWE-266
NVD

HIGH
CVE-2026-74795
CVE-2026-74795
pkg: express

published: Aug 16, 2026

Scriban before 6.6.0 contains an uncontrolled recursion vulnerability in its recursive-descent parser. The parser does not enforce a default expression depth limit (the ExpressionDepthLimit property in ParserOptions defaults to null/disabled), so an attacker who controls template input can supply a …
CWE: CWE-674
NVD

HIGH
CVE-2026-74792
CVE-2026-74792
pkg: express

published: Aug 16, 2026

Scriban before 7.0.0 (affected versions <= 6.6.0) contains a stack overflow vulnerability in nested array initializer parsing. Deeply nested array initializers recurse through a path (ParseArrayInitializer → ParseExpression → ParseArrayInitializer) that is not covered by the ExpressionDepthLimit…
CWE: CWE-674
NVD

HIGH
CVE-2026-74789
CVE-2026-74789
pkg: express

published: Aug 16, 2026

Scriban before 7.0.0 (affected <= 6.6.0) applies its LoopLimit constraint only to script loop statements and not to expensive iteration performed inside built-in operators and functions. As a result, a single expression such as {{ 1..1000000 | array.size }} — or a memory-amplification expression s…
CWE: CWE-400
NVD

HIGH
CVE-2026-74783
CVE-2026-74783
pkg: express

published: Aug 16, 2026

Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimit guard that fails to stop recursive descent parsing of deeply nested expressions. Attackers can supply templates with deeply nested parentheses, array initializers, object initializers, or unary operators to trigger an …
CWE: CWE-674
NVD

HIGH
CVE-2026-72330
CVE-2026-72330
pkg: tls

published: Aug 15, 2026

In the Linux kernel, the following vulnerability has been resolved:

net/tls: Consume empty data records in tls_sw_read_sock()

A peer may send a zero-length TLS application_data record; TLS 1.3
explicitly permits these as a traffic-analysis countermeasure (RFC
8446, Section 5.1). After decryption s…

NVD

HIGH
CVE-2026-72254
CVE-2026-72254
pkg: express

published: Aug 15, 2026

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nft_fib: reject fib expression on the netdev egress hook

A fib expression in a netdev egress base chain dereferences nft_in(pkt),
NULL on the transmit path, causing a NULL pointer dereference at eval.
nft_fib_validate()…

NVD

HIGH
CVE-2026-56864
CVE-2026-56864
pkg: go

published: Aug 13, 2026

A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. This attack allows for a coordinating GOPROXY and GOSUMDB to serve a client malicious module content that cannot be detected by evaluating the transparency log. In order to determine if you…
CWE: CWE-347
GitHub-GHSA

HIGH
nltk: Arbitrary File Read via Path Traversal in nltk.data.load() through Percent-Encoded Sequences
GHSA-m42h-3232-vpv3
pkg: nltk
eco: pip
published: Aug 13, 2026
# Summary
nltk.data.load() and nltk.data.find() resolve user-supplied resource names to filesystem paths using url2pathname(), which decodes percent-encoded sequences (e.g. %2e%2e to ..). Path safety checks are performed on the raw, still-encoded string before decoding occurs. An attacker supplying …
CVE-2026-12243
NVD

HIGH
CVE-2026-73568
CVE-2026-73568
pkg: python

published: Aug 13, 2026

py-libp2p is the Python implementation of the libp2p networking stack. In 0.7.0 and earlier, the yamux handle_incoming() method in libp2p/stream_muxer/yamux/yamux.py reads an attacker-controlled 32-bit DATA frame length with read_exactly() before validating it against MAX_WINDOW_SIZE or checking whe…
CWE: CWE-400
NVD

HIGH
CVE-2024-58374
CVE-2024-58374
pkg: oauth

published: Aug 13, 2026

Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allows remote unauthenticated attackers to access protected resources by supplying a path traversal sequence in the request URI to bypass the oauthservlet authentication filter. Attackers …
CWE: CWE-89
NVD

HIGH
CVE-2026-14456
CVE-2026-14456
pkg: ssl

published: Aug 13, 2026

Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes
valid QUIC Initial packets for unknown destination connection IDs, it
can allocate and queue new incoming channels without enforcing any limit.

Impact summary: A remote peer that can make many Initial packets reach the
serve…

CWE: CWE-770
NVD

HIGH
CVE-2026-67991
CVE-2026-67991
pkg: express

published: Aug 13, 2026

crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in RubyLLM::Utils.underscore on Ruby 3.1.x. A very long crafted class, agent, or tool name can cause excessive CPU consumption and a denial of service.
CWE: CWE-1333
NVD

HIGH
CVE-2026-48702
CVE-2026-48702
pkg: go

published: Aug 13, 2026

Rekor is a software supply chain transparency log. Starting in version 0.3.0 and prior to version 1.5.2, the `Package.Unmarshal()` function in `pkg/types/alpine/apk.go` decompresses the signature and control gzip members of an APK file into in-memory buffers without bounding the total decompressed s…
CWE: CWE-770
NVD

HIGH
CVE-2026-19484
CVE-2026-19484
pkg: node

published: Aug 13, 2026

@fastify/busboy is a multipart form-data parser. In versions 3.1.0 through 3.2.0, a remote unauthenticated attacker can stall the Node.js event loop by sending a multipart request whose boundary is crafted to a specific length. The vendored streaming search stores its skip table in a fixed 256 entry…
CWE: CWE-835, CWE-1322
NVD

HIGH
CVE-2026-19481
CVE-2026-19481
pkg: node

published: Aug 13, 2026

@fastify/busboy is a multipart form-data parser. In versions 1.0.0 through 3.2.0, an attacker who can submit multipart form-data can crash the parser by sending a part header whose name is a prototype-inherited property such as __proto__ or constructor. The internal header parser stores headers in a…
CWE: CWE-754
GitHub-GHSA

HIGH
SIPSorcery: Malformed UDP datagram crashes TurnServer receive loop with no restart, disabling TURN UDP relay for all clients (DoS)
GHSA-pfvm-w89x-94jw
pkg: SIPSorcery
eco: nuget
published: Aug 12, 2026
## Summary
`TurnServer.ReceiveUdpAsync` places its generic `catch (Exception)` OUTSIDE the `while` receive loop, and `Start()` launches the loop fire-and-forget with no supervision or restart. A single pre-authentication UDP datagram whose STUN header first byte is in `0x80–0xFF` causes `STUNHeade…
GitHub-GHSA

HIGH
SIPSorcery vulnerable to Denial of Service via out-of-bounds read in SCTP SACK chunk parsing
GHSA-jwjp-4649-v8jp
pkg: SIPSorcery
eco: nuget
published: Aug 12, 2026
## Summary
`SctpSackChunk.ParseChunk` reads the `numGapAckBlocks` and `numDuplicateTSNs` fields (each up to 65535) directly from an attacker-controlled SCTP SACK chunk and loops that many times reading 4 bytes per iteration, with no validation of the counts against the chunk length or the receive bu…
GitHub-GHSA

HIGH
nimiq-blockchain: Validity store off by one error
GHSA-3763-qp59-59vf
pkg: nimiq-blockchain
eco: rust
published: Aug 12, 2026
### Impact
The validity store treats a transaction with stored `block_number = X` as "in window" only when `X > last_bn – transaction_validity_window_blocks` (strict inequality). However the protocol's `Transaction::is_valid_at` accepts a transaction for inclusion in any block in `[validity_start_he…
CVE-2026-46369
NVD

HIGH
CVE-2026-19558
CVE-2026-19558
pkg: go

published: Aug 11, 2026

Use after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-73232
CVE-2026-73232
pkg: go

published: Aug 11, 2026

ffuf is a fast web fuzzer written in Go. Prior to 2.2.0, ffuf allows a malicious target server to cause an out-of-memory denial of service because the response size guard in pkg/runner/simple.go checks only the compressed Content-Length while io.ReadAll reads gzip, brotli, deflate, transparently dec…
CWE: CWE-409
NVD

HIGH
CVE-2026-48804
CVE-2026-48804
pkg: python

published: Aug 11, 2026

python-socketio is a Python implementation of the Socket.IO realtime client and server. The python-socketio server stores binary `EVENT` and `ACK` messages in memory while it waits to receive their binary attachments. Once all the attachments are received, these messages are then processed. Prior to…
CWE: CWE-770
NVD

HIGH
CVE-2026-48809
CVE-2026-48809
pkg: python

published: Aug 11, 2026

python-engineio is a Python implementation of the Engine.IO realtime client and server. Versions prior to 4.13.2 have two specific configurations of the python-engineio server in which the size of incoming messages is not checked before the messages are loaded into memory. An attacker can take advan…
CWE: CWE-770
NVD

HIGH
CVE-2026-48802
CVE-2026-48802
pkg: python

published: Aug 11, 2026

python-engineio is a Python implementation of the Engine.IO realtime client and server. Prior to version 4.13.2, an attacker can cause the creation of unnecessary background threads in the python-engineio server by exploiting the heartbeat mechanism, which launches a thread when a new connection is …
CWE: CWE-770
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-62901 – .NET Denial of Service Vulnerability
GHSA-m93f-wj8c-rp8p
pkg: Microsoft.NETCore.App.Runtime.win-arm64, Microsoft.NETCore.App.Runtime.win-x64, Microsoft.NETCore.App.Runtime.win-x86
eco: nuget
published: Aug 11, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in System.Net.WebSockets. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

An unchecked input for loop condition …

CVE-2026-62901
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-62898 – .NET Information Disclosure Vulnerability
GHSA-c494-m2fq-59mx
pkg: Microsoft.NETCore.App.Runtime.win-arm64, Microsoft.NETCore.App.Runtime.win-x64, Microsoft.NETCore.App.Runtime.win-x86
eco: nuget
published: Aug 11, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in Microsoft QUIC. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A use after free in Microsoft QUIC allows an …

CVE-2026-62898
NVD

HIGH
CVE-2026-72713
CVE-2026-72713
pkg: docker

published: Aug 11, 2026

XAgent contains a path traversal vulnerability in the workspace file endpoint that allows self-registered or default-credential users to read arbitrary files on the host by supplying parent-directory segments in the `file_name` form field with no path containment check. Attackers can register an acc…
CWE: CWE-22
NVD

HIGH
CVE-2026-73089
CVE-2026-73089
pkg: node

published: Aug 11, 2026

Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, index.js retains every distinct `(queries, context)` result in cache and every parseQueries() AST in parseCache without a size cap, TTL, or eviction, allowing an attacker w…
CWE: CWE-770
NVD

HIGH
CVE-2026-73088
CVE-2026-73088
pkg: node

published: Aug 11, 2026

Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, normalizeStats() in node.js, reached unconditionally through getStat() and loadStat() on every browserslist() call, processes untrusted browserslist-stats.json, opts.stats,…
CWE: CWE-248, CWE-1321
NVD

HIGH
CVE-2026-59132
CVE-2026-59132
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.
CWE: CWE-476
NVD

HIGH
CVE-2026-54113
CVE-2026-54113
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network.
CWE: CWE-770
NVD

HIGH
CVE-2026-72605
CVE-2026-72605
pkg: jwt

published: Aug 11, 2026

A missing authentication vulnerability in Swing Music 3.0.0 allows unauthenticated remote attackers to create arbitrary user accounts via the POST /auth/profile/create endpoint. The endpoint is allowlisted from JWT verification, permitting unauthenticated account creation. An attacker can register a…
CWE: CWE-306
NVD

HIGH
CVE-2026-68131
CVE-2026-68131
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

rbd: Reset positive result codes to zero in object map update path

In a reply message to an RBD request, a positive result code indicates
a data payload, which is not allowed for writes. While
rbd_osd_req_callback() already resets…

NVD

HIGH
CVE-2026-68129
CVE-2026-68129
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

gve: fix Rx queue stall on alloc failure

When the system is under extreme memory pressure, page allocations can
fail during the Rx buffer refill loop. If the number of buffers posted
to hardware falls below a critical low threshol…

NVD

HIGH
CVE-2026-68120
CVE-2026-68120
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

rtase: Workaround for TX hang caused by hardware packet parsing

The hardware performs packet parsing before packet transmission.
Parsing incomplete IPv4, IPv6, TCP, or UDP headers may trigger a TX
hang because the hardware parser …

NVD

HIGH
CVE-2026-68119
CVE-2026-68119
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

tcp: initialize standalone TCP-AO response padding

tcp_v4_send_ack() and tcp_v6_send_response() construct standalone TCP
responses with TCP-AO options. The option length carries the actual MAC
length, but the TCP header length in…

NVD

HIGH
CVE-2026-68096
CVE-2026-68096
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

audit: fix recursive locking deadlock in audit_dupe_exe()

A deadlock occurs in the audit subsystem when duplicating
executable-related rules.

When a file is moved (e.g., via do_renameat2()), the VFS layer locks
the parent directo…

NVD

HIGH
CVE-2026-65942
CVE-2026-65942
pkg: tls

published: Aug 10, 2026

TLS hostname verification issue in Apache Ranger Client Code in versions <= 2.8.0.
Users are recommended to upgrade to version 2.9.0, which fixes this issue.
CWE: CWE-297
NVD

HIGH
CVE-2026-73655
CVE-2026-73655
pkg: go

published: Aug 13, 2026

Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.2, addGoogleStrategy() in apps/webapp/app/services/googleAuth.server.ts passes a Google profile email to findOrCreateGoogleUser() in apps/webapp/app/models/user.server.ts without requiring Google…
CWE: CWE-287
NVD

HIGH
CVE-2026-15554
CVE-2026-15554
pkg: ssl

published: Aug 11, 2026

the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authentication. This enables an unauthenticated attacker with direct TCP access to port 8009 to bypass CLIENT-CERT authentication by injecting a forged X.509 certificate via the AJP protoc…
CWE: CWE-295
NVD

HIGH
CVE-2026-18511
CVE-2026-18511
pkg: tls

published: Aug 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to generate a stack-based buffer overflow in the Native IBM i JSSE provider, caused by improper bounds checking during TLS session establishment. A local attacker could overflow a fixed-length buffer and execute arbitrary code o…
CWE: CWE-787
NVD

HIGH
CVE-2026-74564
CVE-2026-74564
pkg: express

published: Aug 15, 2026

In the Linux kernel, the following vulnerability has been resolved:

netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH

The XT_HASHLIMIT_RATE_MATCH flag mode changes the semantics of the
dsthash_ent structure which represents an entry in the hashtable. There
is a union ar…

GitHub-GHSA

HIGH
mchange-commons-java contains elements susceptible to abuse via JNDI injection and "deserialization gadgets"
GHSA-h84g-69h7-mw6v
pkg: com.mchange:mchange-commons-java
eco: maven
published: Aug 14, 2026
### Impact
Prior to version 0.6.0, mchange-commons-java includes a JNDI `ObjectFactory` implementation (`com.mchange.v2.naming.JavaBeanObjectFactory`) willing to construct objects of arbitrary classes and initialize "JavaBean"-style properties. There are classes for which this kind of initialization…
CVE-2026-55153
NVD

HIGH
CVE-2026-72632
CVE-2026-72632
pkg: express

published: Aug 13, 2026

Observable Discrepancy (CWE-203) in Kibana Fleet can lead to information disclosure via Excavation (CAPEC-116). Fleet removes the Elasticsearch API key value of an enrolled Elastic Agent from the responses of its agent listing capability, but that capability accepted caller-supplied filter expressio…
CWE: CWE-203
GitHub-GHSA

HIGH
SSH.NET: ScpClient Recursive Download Allows Arbitrary File Write via Server-Controlled SCP Filenames
GHSA-q939-rpr3-3284
pkg: SSH.NET
eco: nuget
published: Aug 12, 2026
## Summary

`ScpClient.Download(string directoryName, DirectoryInfo directoryInfo)` writes files and directories using names returned by the remote SCP server during recursive downloads, with no validation that the resulting path stays inside the requested local directory. A malicious, compromised, …

CVE-2026-48798
NVD

HIGH
CVE-2026-73291
CVE-2026-73291
pkg: node

published: Aug 12, 2026

Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.4.0, Seerr's ImageProxy in server/lib/imageproxy.ts uses the upstream ETag and Content-Type response headers to build a cache filename for the unauthenticated GET /avatarproxy/:jellyfinUserId…
CWE: CWE-22, CWE-94
NVD

HIGH
CVE-2026-63177
CVE-2026-63177
pkg: nginx

published: Aug 11, 2026

Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access control enforced in the Nginx OpenResty Lua layer evaluates the raw, unnormalized `ngx.var.request_uri`, while Nginx itself routes requests using the normalized path. An authenticated low-privilege user can…
CWE: CWE-863
NVD

HIGH
CVE-2026-48495
CVE-2026-48495
pkg: oauth

published: Aug 11, 2026

TypeBot is a chatbot builder tool. Prior to version 3.17.0, the Google Sheets OAuth callback decodes a base64-encoded JSON `state` parameter and trusts the embedded `workspaceId`, `typebotId`, `blockId`, and `redirectUrl` without cryptographic integrity protection or authorization checks. The callba…
CWE: CWE-862
NVD

HIGH
CVE-2026-42142
CVE-2026-42142
pkg: oauth

published: Aug 11, 2026

TypeBot is a chatbot builder tool. Prior to version 3.17.0, the `handleGetSheets` API handler (`POST /api/sheets/getSheets`) does not validate workspace membership, allowing any authenticated user to access and decrypt another workspace's Google Sheets OAuth credentials and retrieve spreadsheet data…
CWE: CWE-862
NVD

HIGH
CVE-2026-68103
CVE-2026-68103
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: reject mapping a reserved doorbell to a new queue

When creating an user-queue, the user space
provides a doorbell BO handle and an offset within
the bo to obtain a doorbell.

However current implementation using xa_sto…

NVD

HIGH
CVE-2026-53996
CVE-2026-53996
pkg: node

published: Aug 12, 2026

NetBSD's hdaudio(4) driver in sys/dev/hdaudio/hdaudio.c contains a missing access control vulnerability that allows unprivileged local attackers to invoke the HDAUDIO_FGRP_SETCONFIG ioctl without elevated permissions by exploiting the absence of an access check on /dev/hdaudioN device nodes. Attacke…
CWE: CWE-862
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-62897 – .NET Remote Code Execution Vulnerability
GHSA-fx4q-gjrx-2jw6
pkg: Microsoft.WindowsDesktop.App.Runtime.win-arm64, Microsoft.WindowsDesktop.App.Runtime.win-x64, Microsoft.WindowsDesktop.App.Runtime.win-x86
eco: nuget
published: Aug 11, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in Windows Presentation Foundation. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

An integer overflow or wrapa…

CVE-2026-62897
NVD

HIGH
CVE-2026-61361
CVE-2026-61361
pkg: microsoft windows_11_24h2, microsoft windows_11_25h2, microsoft windows_11_26h1

published: Aug 11, 2026

Use after free in Windows DHCP Client allows an authorized attacker to execute code locally.
CWE: CWE-416
NVD

HIGH
CVE-2026-61348
CVE-2026-61348
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CWE: CWE-416
NVD

HIGH
CVE-2026-61346
CVE-2026-61346
pkg: microsoft windows_10_1809, microsoft windows_10_21h2, microsoft windows_10_22h2

published: Aug 11, 2026

Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.
CWE: CWE-416
NVD

HIGH
CVE-2026-59126
CVE-2026-59126
pkg: microsoft windows_10_21h2, microsoft windows_10_22h2, microsoft windows_11_23h2

published: Aug 11, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.
CWE: CWE-362
NVD

HIGH
CVE-2026-59122
CVE-2026-59122
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CWE: CWE-362, CWE-416
NVD

HIGH
CVE-2026-50472
CVE-2026-50472
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.
CWE: CWE-122
GitHub-GHSA

HIGH
OpenAM Insecure SSO Cookie Initialization
GHSA-fpmh-vx4h-xc33
pkg: org.openidentityplatform.openam:openam-core
eco: maven
published: Aug 14, 2026
## Summary

**Description**
An Insecure Default Initialization of Resource (CWE-1188) issue in the OpenAM default configuration ships the `iPlanetDirectoryPro` SSO cookie with `HttpOnly=false`. Also, the `iPlanetDirectoryPro` SSO cookie is used as a CSRF token in OAuth/OIDC flows. This affects OpenA…

CVE-2026-53660
GitHub-GHSA

HIGH
Budibase: SSRF in Automation Steps – Webhook, Zapier, N8N, Slack, Discord Bypass IP Blacklist
GHSA-5fpj-28rv-84r7
pkg: @budibase/server
eco: npm
published: Aug 14, 2026
## Summary

Budibase automation steps (outgoing webhook, Zapier, n8n, Slack, Discord, Make.com) make server-side HTTP requests to user-provided URLs using `node-fetch` directly, completely bypassing the IP blacklist protection that exists in the REST API integration. Additionally, the REST API black…

CVE-2026-35219
GitHub-GHSA

HIGH
Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts
GHSA-29rf-f4vv-pvq6
pkg: github.com/authorizerdev/authorizer
eco: go
published: Aug 14, 2026
The OAuth callback handler links incoming OAuth identities (Google, GitHub, etc.) to existing accounts matched by email address without verifying that the existing account's email was verified by its original owner. An attacker who pre-registers with a victim's email address (without verifying it) g…
CVE-2026-35511
GitHub-GHSA

HIGH
atomic-agents-stack: Dashboard HTTP server path traversal allows arbitrary file read
GHSA-rm43-82j9-r4mj
pkg: atomic-agents-stack
eco: pip
published: Aug 13, 2026
The optional dashboard HTTP server (`atomic_agents/dashboard/serve.py`) builds filesystem paths directly from the request path and serves them without a containment check. It is the only per-request untrusted-path site in the codebase that does not route through `_io.safe_resolve_under`. Literal `..…
GitHub-GHSA

HIGH
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)
GHSA-48p8-g2fx-3wwm
pkg: github.com/argoproj/argo-workflows/v4, github.com/argoproj/argo-workflows/v3, github.com/argoproj/argo-workflows
eco: go
published: Aug 13, 2026
### Summary

The allow-list fix for CVE-2026-31892 (GHSA-3wf5-g532-rcrr), and its follow-up coverage of `hostNetwork`/`securityContext`/`serviceAccountName` in GHSA-3775-99mw-8rp4, is incomplete. `workflow/util/merge.go` `ValidateUserOverrides` / `SanitizeUserWorkflowSpec` walk only the top-level fi…

CVE-2026-54526
GitHub-GHSA

HIGH
Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv)
GHSA-cxgv-hp74-jj7r
pkg: ansible-jailexec
eco: pip
published: Aug 12, 2026
Through version 1.3.0, the jailexec connection plugin's put_file resolved a transfer's destination to a path on the jail host (<jail filesystem root> + <destination>) and ran mkdir -p and mv there as root on the host. Those commands follow symbolic links, and the path was operated on outside the jai…
CVE-2026-55074
GitHub-GHSA

HIGH
SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access
GHSA-w62w-66v9-vvgv
pkg: github.com/seaweedfs/seaweedfs
eco: go
published: Aug 12, 2026
## Summary

The S3 API gateway and the Iceberg REST catalog gateway construct their routers with `mux.NewRouter().SkipClean(true)`. With path cleaning disabled, a `..` segment inside the URL survives routing, so a request such as:

“`
GET /bucket-A/../evil-bucket/key
“`

is matched as `bucket=buck…

CVE-2026-54917
GitHub-GHSA

HIGH
compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0
GHSA-h47f-gmjp-m7rr
pkg: compliance-trestle
eco: pip
published: Aug 12, 2026
### Summary

`compliance-trestle` 4.0.3 (latest) ships an `URLSecurityValidator` in `trestle/core/remote/security.py` to block SSRF to loopback / link-local / cloud-metadata endpoints from the HTTPSFetcher and SFTPFetcher remote-fetch paths. The allowlist is incomplete and can be bypassed by four eq…

CVE-2026-52776
GitHub-GHSA

MEDIUM
Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials
GHSA-h7p7-w5gc-xj3w
pkg: pydantic-ai-slim, pydantic-ai-slim, pydantic-ai
eco: pip
published: Aug 13, 2026
### Summary

A client that can submit message history to a Pydantic AI UI adapter can reference arbitrary files in the application's model-provider or cloud-storage account. The server forwards the reference to the model provider, which fetches it using the server's own credentials, allowing the cli…

CVE-2026-54249
GitHub-GHSA

MEDIUM
ep_etherpad-lite: Device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author token
GHSA-vqfp-p66c-xrp9
pkg: ep_etherpad-lite
eco: npm
published: Aug 13, 2026
Etherpad's device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author token in the GET response body

## Description

Etherpad ships an endpoint pair under `/tokenTransfer` (`src/node/hooks/express/tokenTransfer.ts`) that lets a logged-in user move…

CVE-2026-55088
NVD

MEDIUM
CVE-2026-73611
CVE-2026-73611
pkg: jwt

published: Aug 13, 2026

File Browser versions from 2.50.0 through 2.63.21 fail to validate JWT expiration when proxy authentication is configured with a non-default logout page. Attackers with a previously valid token can access protected routes and administrative endpoints indefinitely, and exchange expired tokens for fre…
CWE: CWE-613
NVD

MEDIUM
CVE-2026-73419
CVE-2026-73419
pkg: oauth

published: Aug 12, 2026

NextAuth.js provides authentication for Next.js. Prior to@auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, Auth.js stores the OAuth/OIDC anti-CSRF checks state, nonce, and the PKCE verifier in global cookies that are not bound to the provider that created them. On callback, a check value mi…
CWE: CWE-345, CWE-346, CWE-940
NVD

MEDIUM
CVE-2026-65940
CVE-2026-65940
pkg: go

published: Aug 12, 2026

In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible location on the host server.
CWE: CWE-276, CWE-732
NVD

MEDIUM
CVE-2026-65939
CVE-2026-65939
pkg: go

published: Aug 12, 2026

In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root.
CWE: CWE-22, CWE-73, CWE-434
NVD

MEDIUM
CVE-2026-49349
CVE-2026-49349
pkg: docker

published: Aug 12, 2026

regclient is a Docker and OCI Registry Client in Go. Prior to version 0.11.5, credentials for a registry may be inadvertently leaked to external servers. A prerequisite for this attack is a malicious registry server, a malicious blob store, or a registry that does not restrict the external URLs for …
CWE: CWE-522
NVD

MEDIUM
CVE-2026-19278
CVE-2026-19278
pkg: express

published: Aug 10, 2026

A flaw was found in StackRox/RHACS Central's Auth Machine-to-Machine (M2M) token exchange. When an administrator configures M2M role mappings, the system uses unanchored regular expressions for matching claim values. This allows an attacker with a valid OpenID Connect (OIDC) token, whose claim value…
CWE: CWE-625
NVD

MEDIUM
CVE-2026-66016
CVE-2026-66016
pkg: tls

published: Aug 12, 2026

Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessible to highly privileged local users.
CWE: CWE-312
GitHub-GHSA

MEDIUM
Microsoft Security Advisory CVE-2026-62909 – .NET Elevation of Privilege Vulnerability
GHSA-9mr8-pwpw-3j2w
pkg: Microsoft.NETCore.App.Runtime.linux-arm, Microsoft.NETCore.App.Runtime.linux-arm64, Microsoft.NETCore.App.Runtime.linux-musl-arm
eco: nuget
published: Aug 11, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET diagnostics IPC. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A missing error check in .NET causes an…

CVE-2026-62909
NVD

MEDIUM
CVE-2026-71969
CVE-2026-71969
pkg: express

published: Aug 10, 2026

OP-TEE OS through 4.10.0, fixed in commit 7b8b494, contains a buffer underwrite vulnerability in the RSA NOPAD encrypt and decrypt operations within the mbedTLS software backend and SE050 hardware driver that allows a malicious Trusted Application to corrupt secure-world heap memory by supplying an …
CWE: CWE-124, CWE-787
NVD

MEDIUM
CVE-2026-71968
CVE-2026-71968
pkg: node

published: Aug 10, 2026

OP-TEE OS through 4.10.0, fixed in commit 8794043, contains a use-after-free vulnerability in the Trusted Application loader that allows attackers with the ability to load a signed Trusted Application to corrupt secure-world kernel memory by setting the TA_FLAG_CONCURRENT flag in a user TA signed he…
CWE: CWE-362, CWE-416
GitHub-GHSA

MEDIUM
ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)
GHSA-9hgc-g3w5-67cm
pkg: mcp-contextforge-gateway
eco: pip
published: Aug 14, 2026
## Summary

The `/admin/gateways/test` endpoint validates submitted URLs by resolving the hostname at validation time and blocking private address ranges. The HTTP client independently re-resolves DNS at connection time with no IP binding between the two operations, creating a TOCTOU window exploita…

CVE-2026-53708
NVD

MEDIUM
CVE-2026-73330
CVE-2026-73330
pkg: express

published: Aug 12, 2026

CamaleonCMS 2.9.1 contains a server-side template injection vulnerability that allows authenticated administrators to execute arbitrary commands by embedding ERB tags in the email parameter of the test_email settings action, which are evaluated when an SMTP rejection reflects the recipient address b…
CWE: CWE-1336
NVD

MEDIUM
CVE-2026-74785
CVE-2026-74785
pkg: express

published: Aug 16, 2026

Scriban before 7.0.0 contains three distinct denial-of-service vulnerabilities in expression evaluation that bypass existing safety controls through unbounded string multiplication, uncontrolled BigInteger shift operations, and LoopLimit bypass via range enumeration in builtin functions. Attackers w…
CWE: CWE-400
GitHub-GHSA

MEDIUM
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
GHSA-8rw6-p7m8-63jp
pkg: surrealdb
eco: rust
published: Aug 14, 2026
A `SELECT` permission defined on an array element (`DEFINE FIELD field.* … PERMISSIONS FOR select …`) is not enforced correctly for `RECORD` users. Instead of hiding the denied elements, the query leaks a subset of them: a deny-all returns the odd-indexed elements, and a per-element predicate ke…
NVD

MEDIUM
CVE-2026-72664
CVE-2026-72664
pkg: go

published: Aug 13, 2026

Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who holds only detection rule authoring privileges for the Elastic Security solution …
CWE: CWE-862
NVD

MEDIUM
CVE-2026-72663
CVE-2026-72663
pkg: express

published: Aug 13, 2026

Inefficient Algorithmic Complexity (CWE-407) in Kibana can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted, deeply nested expression submitted to a Kibana TSVB visualization is evaluated with a worst-case cost that grows disproportionately with the size of the …
CWE: CWE-407
NVD

MEDIUM
CVE-2026-72648
CVE-2026-72648
pkg: kubernetes

published: Aug 13, 2026

Cleartext Storage of Sensitive Information in an Environment Variable (CWE-526) in Elastic Cloud on Kubernetes (ECK) can lead to information disclosure via Retrieve Embedded Sensitive Data (CAPEC-37). When ECK reconciles a Fleet Server resource that authenticates to Elasticsearch with a service acco…
CWE: CWE-526
NVD

MEDIUM
CVE-2026-72640
CVE-2026-72640
pkg: kubernetes

published: Aug 13, 2026

The Elastic Cloud on Kubernetes (ECK) operator reads a list of secret references from an annotation on secrets it manages, and it accepts the namespace recorded in each reference without validating that the reference is authorized for the resource being reconciled. A user whose Kubernetes permission…
CWE: CWE-441
NVD

MEDIUM
CVE-2026-49089
CVE-2026-49089
pkg: express

published: Aug 13, 2026

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A query expression accepted by a connector reporting operation was processed without any limit on its size, and an oversized expression caused the Kibana proce…
CWE: CWE-770
GitHub-GHSA

MEDIUM
vLLM: Completion prompt lists fan out into unbounded engine requests
GHSA-87×5-vmc3-756j
pkg: vllm
eco: pip
published: Aug 13, 2026
## Summary

The `/v1/completions` request model accepts `prompt` as a list of text prompts or a list of token-id prompts without any outer prompt-count bound. The serving path turns each element into a separate engine input, creates one engine generator per element, merges all generators, and alloca…

CVE-2026-73559
NVD

MEDIUM
CVE-2026-14663
CVE-2026-14663
pkg: openssl

published: Aug 13, 2026

Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of the faulty ciphertext. The OpenSSL version and OpenSSL configuration determine the disabled ciphers. If the application accepts encrypted data as input, decryption will succeed e…
CWE: CWE-313, CWE-345
GitHub-GHSA

MEDIUM
Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint
GHSA-88p2-jj8w-j8qg
pkg: github.com/fleetdm/fleet/v4
eco: go
published: Aug 12, 2026
### Summary

The target search endpoint (`POST /api/latest/fleet/targets`) returned team enroll secrets and full team configuration, including credential-bearing agent options, to observer-class users. Other team-facing endpoints mask these fields for observers; the target search endpoint did not ap…

CVE-2026-48786
NVD

MEDIUM
CVE-2026-68868
CVE-2026-68868
pkg: go

published: Aug 12, 2026

The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections and Variables: the caller's `team_name` was accepted by the backend but dropped at the internal call boundary, so every lookup resolved against the team-agnosti…
CWE: CWE-1220
GitHub-GHSA

MEDIUM
Microsoft Security Advisory CVE-2026-62902 – .NET Information Disclosure Vulnerability
GHSA-9mrh-pw7c-9mqm
pkg: Microsoft.WindowsDesktop.App.Runtime.win-arm64, Microsoft.WindowsDesktop.App.Runtime.win-x64, Microsoft.WindowsDesktop.App.Runtime.win-x86
eco: nuget
published: Aug 11, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in Windows Presentation Foundation. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A specially crafted document…

CVE-2026-62902
NVD

MEDIUM
CVE-2026-69117
CVE-2026-69117
pkg: express

published: Aug 11, 2026

NetBox 4.5.8 contains an ORM injection vulnerability that allows authenticated attackers, including those with read-only API tokens, to inject arbitrary Django ORM lookup expressions into nested object references by supplying crafted JSON dictionary keys in POST, PUT, or PATCH requests to any REST A…
CWE: CWE-639
NVD

MEDIUM
CVE-2026-72739
CVE-2026-72739
pkg: docker

published: Aug 10, 2026

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the createCommand() function constructs shell commands by interpolating compose service names and configuration into bash command strings. When a compose with a maliciously crafted name or service definition is deployed…
CWE: CWE-78
NVD

MEDIUM
CVE-2026-65945
CVE-2026-65945
pkg: jwt

published: Aug 10, 2026

Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0
Users are recommended to upgrade to version 2.9.0, which fixes this issue.
CWE: CWE-532
NVD

MEDIUM
CVE-2026-19751
CVE-2026-19751
pkg: axios

published: Aug 13, 2026

A flaw has been found in EnzoVezzaro mcp-dominican-layer up to 39dd373786712650097ad31db27d5c477c8f9c82. The affected element is the function axios.get of the file src/index.ts of the component parse-csv tool. This manipulation of the argument csvUrl causes server-side request forgery. The attack is…
CWE: CWE-918
NVD

MEDIUM
CVE-2026-73576
CVE-2026-73576
pkg: jwt

published: Aug 13, 2026

In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability exists in the OnlyOffice integration. The zimbraDocumentEditingJwtSecret is generated using an insecure random number generator, resulting in insufficient entropy. An attacker who obtains a JWT signed with…
CWE: CWE-1241
GitHub-GHSA

MEDIUM
Duplicate Advisory: Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint
GHSA-4jjw-pwvw-q6w3
pkg: nuxt
eco: npm
published: Aug 11, 2026
## Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-7c4v-fwgw-9rf7. This link is maintained to preserve external references.

## Original Description
Nuxt versions >= 4.4.7 and < 4.5.1, and >= 3.21.7 and < 3.21.10, contain an information disclosure vulnerabilit…

NVD

MEDIUM
CVE-2026-73671
CVE-2026-73671
pkg: oauth

published: Aug 13, 2026

Saurus CMS Community Edition contains an unauthenticated open redirect vulnerability in the logout handling code in classes/port.inc.php, where the url parameter supplied via GET or POST is passed directly to the Location header without domain allowlist, scheme validation, or relative path enforceme…
CWE: CWE-601
GitHub-GHSA

MEDIUM
ep_etherpad-lite: Cache-poisoning Cross-site Scripting and Open Redirect via x-proxy-path Header
GHSA-fjgc-3mj7-8rg8
pkg: ep_etherpad-lite
eco: npm
published: Aug 13, 2026
# GHSA-03 — `x-proxy-path` header reflected into admin HTML/JS/CSS (cache-poisoning XSS) and concatenated into redirect (open-redirect)

**Severity:** Medium
**CVSS v3.1 vector:** `CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N`
**CVSS suggested base score:** ~6.1 — Medium
*(Re-validate in the f…

CVE-2026-55087
NVD

MEDIUM
CVE-2026-73084
CVE-2026-73084
pkg: oauth

published: Aug 11, 2026

Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /api/redirect OAuth callback endpoint embeds the user-supplied code query parameter directly into an inline script block without proper escaping. A crafted request to /api/redirect with a malicious code value can br…
CWE: CWE-79, CWE-94
NVD

MEDIUM
CVE-2026-69116
CVE-2026-69116
pkg: vue

published: Aug 10, 2026

FlyEnv before 4.18.0 fails to sanitize HTML from markdown rendering and AI chat content passed to Vue v-html directives. Attackers can inject malicious scripts through markdown sources or chat messages that execute in the Electron renderer process with access to Node.js APIs and the filesystem.
CWE: CWE-79
NVD

MEDIUM
CVE-2026-66455
CVE-2026-66455
pkg: react

published: Aug 13, 2026

Subscriber Broken Access Control in ReactPress <= 3.4.0 versions.
CWE: CWE-862
NVD

MEDIUM
CVE-2026-12233
CVE-2026-12233
pkg: tls

published: Aug 12, 2026

The PSA Protected Storage credential backend (subsys/net/lib/tls_credentials/tls_credentials_trusted.c) declared its credential-store mutex as a plain zero-filled static struct k_mutex credential_lock; and never called k_mutex_init() on it. A statically zero-filled k_mutex has an uninitialized wait …
CWE: CWE-665
GitHub-GHSA

MEDIUM
Microsoft Security Advisory CVE-2026-62899 – .NET Security Feature Bypass Vulnerability
GHSA-r6mh-95jw-g7qg
pkg: Microsoft.NETCore.App.Runtime.linux-arm, Microsoft.NETCore.App.Runtime.linux-arm64, Microsoft.NETCore.App.Runtime.linux-musl-arm
eco: nuget
published: Aug 11, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in System.Net.HttpListener. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

Inconsistent interpretation of http …

CVE-2026-62899
NVD

MEDIUM
CVE-2026-73068
CVE-2026-73068
pkg: jwt

published: Aug 11, 2026

ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.207, the ToolJet Database HTTP API in server/src/modules/tooljet-db/controller.ts authorizes operations against the :organizationId URL path value without ver…
CWE: CWE-639
NVD

MEDIUM
CVE-2026-72800
CVE-2026-72800
pkg: express

published: Aug 12, 2026

SiYuan versions before v3.7.4 fail to apply publish-access filtering to the getAttributeViewKeysByID endpoint, allowing authenticated readers to retrieve complete database column schemas including descriptions, select vocabularies, and template expressions. Additionally, getBlockDefIDsByRefText and …
CWE: CWE-862
NVD

MEDIUM
CVE-2026-73308
CVE-2026-73308
pkg: oauth

published: Aug 12, 2026

Budibase is an open-source low-code platform. Prior to 3.39.25, packages/server/src/api/controllers/automation.ts returned automation test results containing trigger.outputs.user.oauth2, broadcast BuilderSocketEvent.AutomationTestProgress to the app room, and stored progress in packages/server/src/a…
CWE: CWE-200
NVD

MEDIUM
CVE-2026-73647
CVE-2026-73647
pkg: vue

published: Aug 13, 2026

Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the public extend() utility in ui/src/utils/extend/extend.js recursively copied attacker-controlled object keys during extend(true, target, source) deep merges without rejecting an own __proto__ pr…
CWE: CWE-1321
NVD

MEDIUM
CVE-2026-19964
CVE-2026-19964
pkg: python

published: Aug 17, 2026

A vulnerability was found in Jij-Inc Jij-MCP-Server 0.1.0. This affects the function PythonREPL.run of the file jij_mcp/python_repr.py of the component jm_check. The manipulation of the argument code results in code injection. It is possible to launch the attack remotely. The exploit has been made p…
CWE: CWE-74, CWE-94
NVD

MEDIUM
CVE-2026-48790
CVE-2026-48790
pkg: jwt

published: Aug 11, 2026

Turso CLI is the command line interface (CLI) to the open-source database Turso. Versions prior to 1.0.26 persist the user's Turso platform JWT to `settings.json` using Viper's default `configPermissions` of `0o644`, leaving the credential file world-readable on standard Linux and macOS systems. Any…
CWE: CWE-276, CWE-732
NVD

MEDIUM
CVE-2026-61360
CVE-2026-61360
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally.
CWE: CWE-822
NVD

MEDIUM
CVE-2026-61347
CVE-2026-61347
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally.
CWE: CWE-126
NVD

MEDIUM
CVE-2026-59137
CVE-2026-59137
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally.
CWE: CWE-908
NVD

MEDIUM
CVE-2026-59136
CVE-2026-59136
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally.
CWE: CWE-908
NVD

MEDIUM
CVE-2026-59135
CVE-2026-59135
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.
CWE: CWE-1390
NVD

MEDIUM
CVE-2026-59128
CVE-2026-59128
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally.
CWE: CWE-125
NVD

MEDIUM
CVE-2026-18942
CVE-2026-18942
pkg: kubernetes

published: Aug 10, 2026

A flaw was found in the Feast operator. A malicious tenant could inject arbitrary code into their feature repository. This code would be executed by an automated process with elevated privileges, allowing the tenant to steal sensitive credentials. This could lead to a direct escalation of privileges…
CWE: CWE-94
NVD

MEDIUM
CVE-2026-74240
CVE-2026-74240
pkg: jwt

published: Aug 14, 2026

A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and single sign-on (SSO) authentication. Multiple issues related to audience verification and the enforcement of `azp` and `sub` claims were identified. These flaws could allow an attacker with a validly-…
CWE: CWE-287
NVD

MEDIUM
CVE-2026-19135
CVE-2026-19135
pkg: express

published: Aug 13, 2026

A JEXL expression sandbox bypass exists in multiple versions of OpenNMS Meridian and Horizon. A low-privileged authenticated user can submit a crafted expression to the Measurements REST API that escapes the sandbox and loads arbitrary Java classes on the server. This can potentially allow an attack…
CWE: CWE-470
GitHub-GHSA

MEDIUM
tablib: Stored XSS in the HTML export via unescaped dataset title
GHSA-gqgw-jghv-mxwx
pkg: tablib
eco: pip
published: Aug 12, 2026
tablib prior to 3.10.0 contains a stored cross-site scripting vulnerability in the HTML export functionality that allows attackers to execute arbitrary JavaScript by embedding malicious payloads in dataset titles, which are interpolated unsanitized into HTML output via the export_book method in the …
CVE-2026-9318
GitHub-GHSA

MEDIUM
s2n-quic has excessive memory allocation
GHSA-9q54-f358-3fqf
pkg: s2n-quic
eco: rust
published: Aug 14, 2026
s2n-quic is a Rust implementation of the QUIC protocol. An unauthenticated user can attempt to exhaust server memory on an s2n-quic endpoint by sending crafted CRYPTO frames with high offsets. The buffer used for processing CRYPTO frames does not enforce a maximum size. In the worst case, a single 1…
CVE-2026-10740
GitHub-GHSA

MEDIUM
Token Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API Endpoints
GHSA-76pc-mqxp-3rq5
pkg: @ooples/token-optimizer-mcp
eco: npm
published: Aug 14, 2026
# Unauthenticated Path Traversal in Dashboard Session Log API Endpoints

| Field | Value |
| —————- | —– |
| Repository | ooples/token-optimizer-mcp |
| Affected version | 5.0.1 (commit 8137147) |
| Vulnerability | CWE-22 — Improper Limitation of a Pathname to a Re…

CVE-2026-55156
NVD

MEDIUM
CVE-2026-73845
CVE-2026-73845
pkg: express

published: Aug 14, 2026

CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, the ckan_get_mqa_quality and ckan_get_mqa_quality_details tools in src/tools/quality.ts use isValidMqaServer to validate the server_url parameter with a prefix-only regular expression for dati.gov.it, allowing suffix-ho…
CWE: CWE-20, CWE-625, CWE-918
NVD

MEDIUM
CVE-2026-73840
CVE-2026-73840
pkg: kubernetes

published: Aug 13, 2026

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, the POST /api/v1alpha1/autobuild endpoint in internal/openchoreo-api/api/handlers/webhook_handler.go selected a webhook provider from caller-controlled X-Event-Key, accepted Bitbucket requ…
CWE: CWE-287, CWE-290, CWE-345
NVD

MEDIUM
CVE-2026-58507
CVE-2026-58507
pkg: go

published: Aug 13, 2026

Private Repository Existence Disclosure via go-get Meta Endpoint
CWE: CWE-284
NVD

MEDIUM
CVE-2026-19487
CVE-2026-19487
pkg: express

published: Aug 13, 2026

Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.

The prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one re…

CWE: CWE-670
NVD

MEDIUM
CVE-2026-73556
CVE-2026-73556
pkg: express

published: Aug 13, 2026

vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the structured_outputs.regex parameter in vllm/v1/structured_output/backend_lm_format_enforcer.py is passed to lmformatenforcer.RegexParser without compile_regex_with_timeout or validation in validate_structured_outp…
CWE: CWE-400, CWE-1333
NVD

MEDIUM
CVE-2026-73555
CVE-2026-73555
pkg: python

published: Aug 13, 2026

vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the validation_exception_handler in vllm/entrypoints/openai/server_utils.py converts FastAPI RequestValidationError objects with str(exc), and sanitize_message in vllm/entrypoints/utils.py does not remove traceback-s…
CWE: CWE-209
NVD

MEDIUM
CVE-2026-66384
CVE-2026-66384
pkg: docker

published: Aug 12, 2026

An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
CWE: CWE-22
NVD

MEDIUM
CVE-2026-33921
CVE-2026-33921
pkg: windows

published: Aug 11, 2026

The Windows installer deployed Npcap leaving its access restriction option at the insecure default value, so the driver was accessible to every local user of the host instead of being restricted to administrators only. A local user without administrative privileges could use the Npcap driver to capt…
CWE: CWE-1188
NVD

MEDIUM
CVE-2026-73304
CVE-2026-73304
pkg: oauth

published: Aug 13, 2026

Budibase is an open-source low-code platform. Prior to 3.39.25, GET /api/users/metadata and GET /api/users/metadata/:id returned user objects processed by packages/server/src/utilities/global.ts without removing oauth2.accessToken or oauth2.refreshToken. A user with the POWER role could retrieve the…
CWE: CWE-200
NVD

MEDIUM
CVE-2026-67613
CVE-2026-67613
pkg: ssl

published: Aug 13, 2026

CyberPanel before 3.0.0 contains a path traversal vulnerability that allows authenticated administrators to read arbitrary files from the server filesystem by supplying unsanitized file paths to the cloudAPI ReadReport endpoint. Attackers can manipulate the reportFile parameter in the JSON request b…
CWE: CWE-22
NVD

MEDIUM
CVE-2026-73282
CVE-2026-73282
pkg: openssh

published: Aug 11, 2026

In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.
CWE: CWE-416
NVD

MEDIUM
CVE-2026-73563
CVE-2026-73563
pkg: oauth

published: Aug 13, 2026

Backstage is an open framework for building developer portals. Prior to 0.29.2, the experimental dynamic client registration and client ID metadata document features in the @backstage/plugin-auth-backend use full-string matcher.isMatch glob matching for auth.experimentalDynamicClientRegistration.all…
CWE: CWE-601
NVD

MEDIUM
CVE-2026-49820
CVE-2026-49820
pkg: oauth

published: Aug 13, 2026

Probo is a self-hostable governance, risk, and compliance (GRC) platform built for engineering and security teams. Probo's `saferedirect` package validates redirect URLs used across authentication flows (OIDC, SAML, session transfer, OAuth connectors, and trust-center magic links). Prior to version …
CWE: CWE-601
NVD

MEDIUM
CVE-2026-61350
CVE-2026-61350
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.
CWE: CWE-126
NVD

MEDIUM
CVE-2026-73036
CVE-2026-73036
pkg: python

published: Aug 11, 2026

Bash-it 3.2.0 contains a terminal escape sequence injection vulnerability in the barbuk theme's Python virtualenv prompt segment that allows local attackers to inject arbitrary terminal control sequences by embedding escape sequences in the requires-python field of a pyproject.toml file. When a user…
CWE: CWE-150
NVD

MEDIUM
CVE-2026-58425
CVE-2026-58425
pkg: oauth

published: Aug 13, 2026

OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)
CWE: CWE-200, CWE-863
NVD

MEDIUM
CVE-2026-6470
CVE-2026-6470
pkg: express

published: Aug 13, 2026

Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations did check the privilege, but assigning a range subtype and referencing the type from an SQL expressio…
CWE: CWE-862
NVD

MEDIUM
CVE-2026-65938
CVE-2026-65938
pkg: go

published: Aug 12, 2026

In WhatsUp Gold versions released before 2026.0.2, an improper authorization vulnerability in the Scheduled Reports API allows any authenticated user to invoke restricted actions.
CWE: CWE-602, CWE-862
NVD

MEDIUM
CVE-2026-19078
CVE-2026-19078
pkg: oauth

published: Aug 11, 2026

A flaw was found in the oauth-server component. This open redirect vulnerability occurs when the 'then' parameter in the grant approval handler is not properly validated. A remote attacker can craft a malicious URL that, when approved or denied by an authenticated user, redirects them to an attacker…
CWE: CWE-601
NVD

MEDIUM
CVE-2026-72912
CVE-2026-72912
pkg: express

published: Aug 10, 2026

CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.3.0, CyberChef's pretty-recipe parser in src/core/Utils.mjs can exhaust client-side CPU when a malformed #recipe= URL fragment containing a large number of unmatched quote characters reaches Utils.parseRecip…
CWE: CWE-400, CWE-1333
NVD

MEDIUM
CVE-2026-18165
CVE-2026-18165
pkg: oauth

published: Aug 15, 2026

@fastify/oauth2 is an OAuth 2.0 plugin for Fastify. In versions from 7.2.0 up to but not including 8.3.0, the plugin validates the OAuth state, and with PKCE the code verifier, by comparing the callback query parameter against an unprefixed, predictable cookie, with no server-side binding to the bro…
CWE: CWE-352
GitHub-GHSA

MEDIUM
ep_etherpad-lite: Import/export uses Math.random() for temp file paths; predictable paths on shared /tmp enable symlink-based file overwrite
GHSA-2jwf-f4xq-f24h
pkg: ep_etherpad-lite
eco: npm
published: Aug 13, 2026
## Description

`src/node/handler/ImportHandler.ts` and `src/node/handler/ExportHandler.ts` both compute their temporary working-file paths as:

“`ts
const randNum = Math.floor(Math.random() * 0xFFFFFFFF);
const srcFile = `${os.tmpdir()}/etherpad_export_${randNum}.html`;
const destFile = `${os.tmpd…

CVE-2026-55086
NVD

MEDIUM
CVE-2026-14681
CVE-2026-14681
pkg: tls

published: Aug 13, 2026

Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules, via initial direct TLS connection. Despite a pg_hba.conf that appears to require GSSAPI, the connection may exchange data over TLS encryption alone. If the TLS se…
CWE: CWE-924
GitHub-GHSA

MEDIUM
Fabric CA Developer's Guide: LDAP Injection via Unescaped Username in GetUser Filter
GHSA-xghw-p77p-3r7x
pkg: github.com/hyperledger/fabric-ca
eco: go
published: Aug 14, 2026
When fabric-ca is configured with an LDAP backend, the username from HTTP Basic authentication is included in an LDAP uid search filter without proper escaping. An unauthenticated attacker with network access to the CA enrollment endpoint could exploit this to perform LDAP injection before password …
CVE-2026-53658
GitHub-GHSA

MEDIUM
hashi-vault-js: Vault token and secret values exposed in thrown errors
GHSA-5pq8-3ffp-7w5m
pkg: hashi-vault-js
eco: npm
published: Aug 13, 2026
## Summary

Vault token and secret values are exposed in thrown errors when using `hashi-vault-js`.

## Details

Every API method in `Vault.js` executes `throw parseAxiosError(err)`, which returns the raw `AxiosError` untouched. That error carries the full Axios configuration, including the `X-Vault…

CVE-2026-55102


Vulnerability Digest — August 10, 2026 · 52 Critical · 5 Exploited






Vulnerability Digest — Monday, August 10, 2026


Security Report

Monday, August 10, 2026  ·  Last 7 days  ·  Min severity: MEDIUM
Total Findings
381
Critical
52
High
171
Actively Exploited
5
CISA-KEV5
NVD216
GitHub-GHSA160
Findings sorted by severity
CISA-KEV

CRITICAL
Progress LoadMaster Command Injection Vulnerability
CVE-2026-8037
pkg: Progress LoadMaster

published: Aug 7, 2026

Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
JetBrains TeamCity Deserialization of Untrusted Data Vulnerability
CVE-2026-63077
pkg: JetBrains TeamCity

published: Aug 5, 2026

JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
CVE-2026-18556
pkg: N-able N-central

published: Aug 4, 2026

N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
CVE-2026-34486
pkg: Apache Tomcat

published: Aug 4, 2026

Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
IBM Langflow Code Injection Vulnerability
CVE-2026-9198
pkg: IBM Langflow

published: Aug 4, 2026

Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
NVD

CRITICAL
CVE-2026-5430
CVE-2026-5430
pkg: jwt

published: Aug 6, 2026

The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access.

Successful exploitation of this vuln…

CWE: CWE-347
NVD

CRITICAL
CVE-2026-48086
CVE-2026-48086
pkg: jwt

published: Aug 6, 2026

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN promotes themselves to platform-wide GLOBAL_ADMIN through a single PUT request. The role-update handler accepts the `GLOBAL_ADMIN` enum value from any te…
CWE: CWE-269
NVD

CRITICAL
CVE-2026-70615
CVE-2026-70615
pkg: tls

published: Aug 5, 2026

boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users with tunnel-creation permission to inject arbitrary lines into the server account's SSH authorized_keys file by supplying a percent-encoded newline character in the domain parameter o…
CWE: CWE-93
NVD

CRITICAL
CVE-2026-10090
CVE-2026-10090
pkg: kubernetes

published: Aug 5, 2026

A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with namespace-scoped "edit" privileges in an ACM hub namespace can create a Channel resource pointing to a Helm repository they contr…
CWE: CWE-267
NVD

CRITICAL
CVE-2026-19264
CVE-2026-19264
pkg: jwt

published: Aug 7, 2026

Postiz is an open-source social media scheduling tool. The route that serves locally stored media joins URL-supplied path segments onto the upload directory and streams the file without normalising the path or confining it to that directory, and the route requires no authentication. Raw dot-segments…
CWE: CWE-22
NVD

CRITICAL
CVE-2026-70558
CVE-2026-70558
pkg: docker

published: Aug 6, 2026

Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and file.transferTo(dest) with no path validation. The route is marked @SaIgnore and /download/** is excluded from the Sa-Token interceptor, so the only guard is a header equality …
CWE: CWE-434
NVD

CRITICAL
CVE-2026-53975
CVE-2026-53975
pkg: docker

published: Aug 6, 2026

OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by sending crafted POST requests to the /api/fs/exec endpoint, which passes commands verbatim to Node.js spawn() without any allowlist, blocklist, or ar…
CWE: CWE-78
NVD

CRITICAL
CVE-2026-67870
CVE-2026-67870
pkg: node

published: Aug 6, 2026

In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local ExpandedNodeId targets. A remote attacker can send a crafted AddReferencesRequest with an empty targetServerUri and a non-zero targetNodeId.serverIndex, causing the target node poin…
CWE: CWE-476
NVD

CRITICAL
CVE-2026-71289
CVE-2026-71289
pkg: docker

published: Aug 5, 2026

The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose.yml publishes the amp-manager service's REST API directly to the host network interface (port 8089, e.g. "${ION_MGR_PORT:-8089}:8089/tcp") with cap_add: NET_ADMIN, NET_RAW, SYS_NICE, bypass…
CWE: CWE-306
NVD

CRITICAL
CVE-2026-71214
CVE-2026-71214
pkg: jwt

published: Aug 5, 2026

The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-server/src/app.ts) derives the caller's Hasura session role via getHasuraSession(), which prefers a session_variables object taken directly from the client-supplied JSON request body over the Authorization header's JWT claims…
CWE: CWE-306
NVD

CRITICAL
CVE-2026-64566
CVE-2026-64566
pkg: linux

published: Aug 5, 2026

In the Linux kernel, the following vulnerability has been resolved:

xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags()

When iptfs_skb_add_frags() copies frag references from the source
frag walk into a new SKB, it increments the page reference count via
__skb_frag_ref() but does not…

NVD

CRITICAL
CVE-2026-66902
CVE-2026-66902
pkg: go

published: Aug 4, 2026

Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated system call.

The Pluggable subclass reads credential_source.executable.command from the credentials JSON and runs it as `system($command)`, a single argument call that passes the wh…

CWE: CWE-78, CWE-829
NVD

CRITICAL
CVE-2026-24254
CVE-2026-24254
pkg: nvidia dynamo, linux linux_kernel

published: Aug 4, 2026

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
CWE: CWE-288
NVD

CRITICAL
CVE-2025-29296
CVE-2025-29296
pkg: express

published: Aug 4, 2026

H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V100R017, H3C Magic R1510 V100R016, H3C NE36 Pro V100R002 and H3C MC102G HM1A0V200R010 contain multiple command injection vulnerabilities in the /api/esps request handler. The affec…
CWE: CWE-77
NVD

CRITICAL
CVE-2026-69098
CVE-2026-69098
pkg: python

published: Aug 4, 2026

kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON input with a __type__ field. Attackers can exploit this to override the __type__ fi…
CWE: CWE-502
NVD

CRITICAL
CVE-2026-64564
CVE-2026-64564
pkg: linux

published: Aug 4, 2026

In the Linux kernel, the following vulnerability has been resolved:

sctp: don't free the ASCONF's own transport in DEL-IP processing

sctp_process_asconf() caches the transport the ASCONF chunk is processed
against in asconf->transport (== chunk->transport, set once in sctp_rcv()).
For an ASCONF lo…

NVD

CRITICAL
CVE-2026-69240
CVE-2026-69240
pkg: express

published: Aug 3, 2026

Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with strings only if dialect is set to oracle. The escape function defined in sql-string.js does not escape quotes if the value starts with TO_TIMESTAMP or TO_DATE. In the Oracle dialect, when val is a string and starts with…
CWE: CWE-89
GitHub-GHSA

CRITICAL
Sequelize: SQL Injection (Oracle DB)
GHSA-v8fg-2rw7-q452
pkg: sequelize
eco: npm
published: Aug 3, 2026
### Summary
SQL Injection is possible with strings only **if dialect is set to `oracle`**.
The vulnerability was confirmed on Sequelize v6.37.3.

### Details
The `escape` function defined in `sql-string.js` does not escape quotes if the value starts with `TO_TIMESTAMP` or `TO_DATE`.

“`javascript

CVE-2026-69240
NVD

CRITICAL
CVE-2026-19171
CVE-2026-19171
pkg: google chrome, microsoft windows

published: Aug 6, 2026

Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

CRITICAL
CVE-2026-19157
CVE-2026-19157
pkg: google chrome, google android

published: Aug 6, 2026

Out of bounds write in ANGLE in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-787
NVD

CRITICAL
CVE-2026-19149
CVE-2026-19149
pkg: google chrome, linux linux_kernel

published: Aug 6, 2026

Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

CRITICAL
CVE-2026-71319
CVE-2026-71319
pkg: vue

published: Aug 5, 2026

Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite HMR WebSocket via the nuxt:devtools:rpc plugin. On affected versions the channel has no authentication: any client that can reach the V…
CWE: CWE-94, CWE-306
GitHub-GHSA

CRITICAL
Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host
GHSA-279x-mwfv-vcqv
pkg: @nuxt/devtools
eco: npm
published: Aug 5, 2026
### Impact

Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite HMR WebSocket via the `nuxt:devtools:rpc` plugin. On affected versions the channel has no authentication: any client that can reach the Vite HMR endpoint (`ws://<host>:<port>/`, subprotocol `vite-hmr`…

CVE-2026-71319
NVD

CRITICAL
CVE-2026-65520
CVE-2026-65520
pkg: oauth

published: Aug 6, 2026

Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions.
CWE: CWE-89
GitHub-GHSA

CRITICAL
Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware
GHSA-cxjq-mrr5-89rv
pkg: github.com/traefik/traefik/v2, github.com/traefik/traefik/v3, github.com/traefik/traefik/v3
eco: go
published: Aug 6, 2026
## Summary

There is a critical authentication-bypass vulnerability in Traefik's `ReplacePathRegex` middleware. When it is configured with a regular expression that captures user-controlled path segments without a mandatory separator (for example `regex: "^/api(.*)"`, `replacement: "/$1"`), a crafte…

CVE-2026-65600
NVD

CRITICAL
CVE-2026-53976
CVE-2026-53976
pkg: jwt

published: Aug 6, 2026

OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and /api/fs/raw that allows unauthenticated remote attackers to read arbitrary files by supplying the allowOutsideWorkspace=true query parameter alongside an absolute path, bypassing …
CWE: CWE-22
NVD

CRITICAL
CVE-2026-63687
CVE-2026-63687
pkg: apache cxf

published: Aug 6, 2026

Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without excluding security-sensitive parameters. A client that can produce a validly-signed request JWT (e.g., one whose client_secret is known or compromised) can thereby substitute th…
CWE: CWE-345
NVD

CRITICAL
CVE-2026-61466
CVE-2026-61466
pkg: apache cxf

published: Aug 6, 2026

In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration request verbatim, without validating it against an AS-defined allowlist. This could lead to a client self-assigning privileged scopes at regi…
CWE: CWE-304
NVD

CRITICAL
CVE-2026-71263
CVE-2026-71263
pkg: linux

published: Aug 5, 2026

The LINUXTCP port of FreeModbus contains an off-by-one bounds check in xMBPortTCPPool() (demo/LINUXTCP/port/porttcp.c). The check `if (usTCPFrameBytesLeft > MB_TCP_BUF_SIZE)` uses a strict greater-than comparison instead of greater-than-or-equal against the 263-byte MB_TCP_BUF_SIZE limit. An MBAP fr…
CWE: CWE-787
NVD

CRITICAL
CVE-2026-71238
CVE-2026-71238
pkg: oauth

published: Aug 5, 2026

DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. Since this key is used for session signing, CSRF token generation, and password reset tokens, anyone who reads the public repository can forge valid sessio…
CWE: CWE-798
NVD

CRITICAL
CVE-2026-10059
CVE-2026-10059
pkg: kubernetes

published: Aug 5, 2026

A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertently grants the tenant administrator the ability to mint a token …
CWE: CWE-266
NVD

CRITICAL
CVE-2026-18754
CVE-2026-18754
pkg: tls

published: Aug 4, 2026

The
product firmware contains an embedded, static RSA private key utilized by the
Lighttpd web server for TLS termination. Exposure of this private key allows
malicious actors to breach the confidentiality and integrity of HTTPS
communications, enabling traffic decryption and server spoofing.
CWE: CWE-321
NVD

CRITICAL
CVE-2026-18753
CVE-2026-18753
pkg: tls

published: Aug 4, 2026

The
product firmware contains an embedded, static RSA private key utilized by the
Lighttpd web server for TLS termination. Exposure of this private key allows
malicious actors to breach the confidentiality and integrity of HTTPS
communications, enabling traffic decryption and server spoofing.
CWE: CWE-321
NVD

CRITICAL
CVE-2026-48031
CVE-2026-48031
pkg: jwt

published: Aug 3, 2026

go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by PostgreSQL. In versions prior to 2026-05-18, the JWT signing secret is hardcoded to the known string "random", letting any attacker who reads the public repository forge tokens for arbitrary users, including admin ro…
CWE: CWE-798
NVD

CRITICAL
CVE-2026-9487
CVE-2026-9487
pkg: xml\ \

published: Aug 3, 2026

XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID.

_get_signed_xml() in lib/XML/Sig.pm, called from verify(), resolves the SignedInfo Reference/@URI to a node with the XPath expression "//*[@ID='$id']" and returns the first node of the resulting node set. A document i…

CWE: CWE-347
NVD

CRITICAL
CVE-2026-9390
CVE-2026-9390
pkg: xml\ \

published: Aug 3, 2026

XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup.

verify() and _get_signed_xml() in lib/XML/Sig.pm build XPath expressions by concatenating the SignedInfo/Reference/@URI value read from the document being verified. The value is neither escaped nor checked against the NCName…

CWE: CWE-643, CWE-1287
GitHub-GHSA

CRITICAL
crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain
GHSA-rg76-677x-56q9
pkg: crypto-js
eco: npm
published: Aug 7, 2026
### Summary

`CryptoJS.lib.WordArray.random()` in affected versions is not a cryptographically secure random number generator. Nominal requests for 128 or 256 bits of entropy produce effective search spaces of approximately 2^39 and 2^47 possibilities — small enough to enumerate on commodity hardw…

CVE-2026-71851
GitHub-GHSA

CRITICAL
Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables token theft for any connected service
GHSA-qgvm-j2hm-6m38
pkg: flowise
eco: npm
published: Aug 4, 2026
### Summary

The OAuth2 token refresh endpoint (`POST /api/v1/oauth2-credential/refresh/:credentialId`) is in `WHITELIST_URLS`, meaning it requires **no authentication**. It decrypts the stored credential (containing `clientId`, `clientSecret`, `refresh_token`), sends a refresh request to the config…

CVE-2026-70478
GitHub-GHSA

CRITICAL
Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
GHSA-5xvg-pmgg-3mxr
pkg: flowise, flowise-components
eco: npm
published: Aug 4, 2026
— ABSTRACT ————————————-

Trend Micro's Zero Day Initiative has identified a vulnerability affecting the following products:
Flowise – Flowise

— VULNERABILITY DETAILS ————————
* Version tested: 3.1.1
* Installer file: https://github.com/FlowiseAI/Flowise (n…

CVE-2026-70477
GitHub-GHSA

CRITICAL
Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation
GHSA-4j8x-x6v7-w9rq
pkg: flowise, flowise-components
eco: npm
published: Aug 4, 2026
### Summary
Flowise's `CSVAgent` interpolates an attacker-controlled segment of the
`csvFile` data URI directly into a Python source-code template that is then
executed by Pyodide. Because Pyodide is loaded with the default `js` bridge
to `globalThis` (which on Node.js exposes `eval` and dynamic `im…
CVE-2026-69264
GitHub-GHSA

CRITICAL
Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE
GHSA-52fh-8v99-63c2
pkg: flowise, flowise-components
eco: npm
published: Aug 4, 2026
### Summary
The validatePythonCodeForDataFrame blacklist in packages/components/src/pythonCodeValidator.ts can be bypassed with Unicode homoglyph identifiers, allowing arbitrary Python execution inside Pyodide and full OS command execution on the Flowise host via Pyodide's js module interop. This re…
CVE-2026-70470
GitHub-GHSA

CRITICAL
Flowise RCE via SQLite Record Manager Node
GHSA-x3hf-7cj6-3r4m
pkg: flowise, flowise-components
eco: npm
published: Aug 4, 2026
=============================================================================
Security Advisory
elttam

Topic: Flowise RCE via SQLite Record Manager Node

Modul…

CVE-2026-69259
GitHub-GHSA

CRITICAL
Flowise: Remote Code Execution Vulnerability in CSVAgent
GHSA-x6vm-w76m-8j7g
pkg: flowise-components, flowise
eco: npm
published: Aug 4, 2026
### Summary

The CSVAgent node was observed to allow users to write Python code which gets executed via `pyodide`. The original intent was to allow users to utilise the `pandas` library for CSV processing. Although there is a denylist that checks for dangerous Python constructs from being passed in,…

CVE-2026-69256
GitHub-GHSA

CRITICAL
Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified
GHSA-vmv7-4m6c-3cg5
pkg: flowise, flowise-components
eco: npm
published: Aug 4, 2026
## UPDATE 2026-05-20: Full RCE as root VERIFIED

**This is not theoretical — a Meterpreter reverse shell session as root has been established on Flowise 3.1.2.**

### Verified Exploit Chain

1. Python code injection via `base64_string = "${base64String}"` (CSVAgent.ts line 161)
2. Pyodide `js` bri…

CVE-2026-69255
GitHub-GHSA

CRITICAL
Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override
GHSA-3769-jgqc-cxm7
pkg: flowise, flowise-components
eco: npm
published: Aug 4, 2026
### Summary
A sandbox escape vulnerability in `executeJavaScriptCode()` allows any authenticated user to execute arbitrary system commands as root on the Flowise server. The function accepts caller-provided `nodeVMOptions` that override the
default sandbox security settings via JavaScript's spread…
CVE-2026-69254
GitHub-GHSA

CRITICAL
Flowise Sandbox Escape to RCE
GHSA-wg86-r78f-74mp
pkg: flowise, flowise-components
eco: npm
published: Aug 4, 2026
=============================================================================
Security Advisory
elttam

Topic: Flowise JavaScript Sandbox Escape

Module: …

CVE-2026-69253
GitHub-GHSA

CRITICAL
Flowise RCE via TypeORM DataSource
GHSA-g32j-mmxr-gfq5
pkg: flowise, flowise-components
eco: npm
published: Aug 4, 2026
=============================================================================
Security Advisory
elttam

Topic: Flowise RCE via TypeORM DataSource

Module: …

CVE-2026-69251
GitHub-GHSA

HIGH
GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution
GHSA-wvpp-8hx9-p66j
pkg: GitPython
eco: pip
published: Aug 7, 2026
## Summary
The `check_unsafe_options` guard can be bypassed on every guarded method (clone/clone_from, fetch/pull/push, ls_remote, iter_commits, blame, archive) by combining a single-character kwarg with `split_single_char_options=False`. The guard's candidate list omits the smuggled option, but `tr…
GitHub-GHSA

HIGH
GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE)
GHSA-jm78-9fvv-mhgr
pkg: GitPython
eco: pip
published: Aug 7, 2026
## Summary
GitPython's config-name validator only neutralizes CR/LF/NUL for the `"option"` label; it does not reject `=`, `#`, `;`, `[`, `]`, or whitespace in an **option name**. `write_section` writes the option name verbatim into the config file, so an option name such as `sshCommand = touch <cmd>…
NVD

HIGH
CVE-2026-9169
CVE-2026-9169
pkg: windows

published: Aug 7, 2026

DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows a local attacker to execute arbitrary code with the privileges of the application by placing a malicious DLL in a user-controlled directory listed in the PATH environment variable, which the SDK traverses when a re…
CWE: CWE-427
NVD

HIGH
CVE-2026-48054
CVE-2026-48054
pkg: node

published: Aug 6, 2026

OpenZeppelin Contracts Wizardis a web application to interactively build a contract out of components from OpenZeppelin Contracts. Versions prior to 0.10.9 generate a Hardhat test file (`test/test.ts`) by interpolating user-supplied `opts.name` (ERC20/ERC721) and `opts.uri` (ERC1155) directly into T…
CWE: CWE-94
NVD

HIGH
CVE-2026-19151
CVE-2026-19151
pkg: google chrome

published: Aug 6, 2026

Use after free in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-19150
CVE-2026-19150
pkg: google chrome

published: Aug 6, 2026

Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-693
NVD

HIGH
CVE-2026-19145
CVE-2026-19145
pkg: google chrome

published: Aug 6, 2026

Use after free in Translate in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-19144
CVE-2026-19144
pkg: go

published: Aug 6, 2026

Use after free in HTML in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-64586
CVE-2026-64586
pkg: linux

published: Aug 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

wifi: brcmfmac: drain bus_reset work on device removal

brcmf_fw_crashed() and the debugfs "reset" entry both schedule
drvr->bus_reset, whose callback recovers drvr through container_of()
and dereferences it. The removal path free…

GitHub-GHSA

HIGH
rclone `serve restic –private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories
GHSA-fqj9-69pf-6pjg
pkg: github.com/rclone/rclone
eco: go
published: Aug 5, 2026
## Summary

`rclone serve restic –private-repos` exists to let one rclone instance host many users' restic backup repositories behind HTTP Basic auth while keeping each user confined to a path prefix of `/<username>/`. The documentation states the flag "can be used to limit users to repositories st…

CVE-2026-59733
NVD

HIGH
CVE-2026-9201
CVE-2026-9201
pkg: langflow langflow

published: Aug 5, 2026

IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryptographic weakness in the custom component validation mechanism. When the optional hardening mode that restricts execution to trusted component templates is enabled, the application val…
CWE: CWE-326
NVD

HIGH
CVE-2026-17632
CVE-2026-17632
pkg: langflow langflow

published: Aug 5, 2026

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of Python code during AST-based security scanning.
CWE: CWE-94
NVD

HIGH
CVE-2026-17626
CVE-2026-17626
pkg: langflow langflow

published: Aug 5, 2026

IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expose sensitive host files via Docker-based MCP servers due to incomplete filtering of dangerous Docker volume-mount and device-mapping arguments.
CWE: CWE-266
NVD

HIGH
CVE-2026-71287
CVE-2026-71287
pkg: express

published: Aug 5, 2026

Cacti's sanitize_sql_column() (lib/functions.php) sanitizes user-supplied ORDER BY column names using the regex `preg_replace('/[^a-zA-Z0-9_().]/', '', $column)`. Because this allowlist retains letters, digits, underscore, parentheses, and dot (intended to support expressions like COUNT(id) and tabl…
CWE: CWE-89
NVD

HIGH
CVE-2026-71235
CVE-2026-71235
pkg: go

published: Aug 5, 2026

Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side when IoT messages arrive. The Go script engine (re/golang.go) runs scripts through the Yaegi interpreter with stdlib.Symbols, exposing the full Go standard library (including os …
CWE: CWE-94
NVD

HIGH
CVE-2026-55997
CVE-2026-55997
pkg: node

published: Aug 5, 2026

Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens were stored and exposed in plaintext with no expiration, so a malicious user could obtain one either through the Rancher API, etcd, stored automation, or direct file access on a …
CWE: CWE-312
NVD

HIGH
CVE-2026-70374
CVE-2026-70374
pkg: node

published: Aug 5, 2026

HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the media upload thumbnail generation routine. Media.generateThumbnail() in src/Server/Entity/Resource/Media.js builds a temporary file path as 'thumbnail' + Path.extname(filename) and passes it, unescaped, into a…
CWE: CWE-78
NVD

HIGH
CVE-2026-67195
CVE-2026-67195
pkg: express

published: Aug 4, 2026

Perspective 5.0.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary operating system commands by submitting crafted expression strings to the PolarsVirtualServer backend, which passes client-supplied input directly to Python's eval() with only …
CWE: CWE-95
NVD

HIGH
CVE-2026-64562
CVE-2026-64562
pkg: linux

published: Aug 4, 2026

In the Linux kernel, the following vulnerability has been resolved:

KVM: nVMX: Hide shadow VMCS right after VMCLEAR

free_nested() frees the shadow VMCS while vmcs01 still points to it. But
because it is asynchronous with respect to loaded_vmcs_clear(), the vCPU
might migrate before the pointer is …

NVD

HIGH
CVE-2026-64561
CVE-2026-64561
pkg: linux

published: Aug 4, 2026

In the Linux kernel, the following vulnerability has been resolved:

KVM: x86: Check for invalid/obsolete root *after* making MMU pages available

Check for a "stale" page fault, i.e. for an invalid and/or obsolete root,
after making MMU pages available for the shadow MMU. If reclaiming shadow
page…

NVD

HIGH
CVE-2026-69096
CVE-2026-69096
pkg: docker

published: Aug 3, 2026

OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.uc RPC backend after the JS/ucode conversion) contains an OS command injection vulnerability. The package's read ACL grants broad ubus access to docker.* / docker.container.*, which exposes the docker…
CWE: CWE-78
GitHub-GHSA

HIGH
Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages
GHSA-pwxh-7358-jq2x
pkg: open-webui
eco: pip
published: Aug 4, 2026
## Summary
Any authenticated user can store a chat message whose math block makes KaTeX fail with a stack overflow instead of a parse error. When that happens the renderer falls back to inserting the original math source into the page as HTML rather than as text, so script in the message runs in the…
CVE-2026-70492
NVD

HIGH
CVE-2026-64940
CVE-2026-64940
pkg: express

published: Aug 10, 2026

Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contains a vulnerability due to a permissive regular expression, which may allow an attacker who can access the affected product to log in to the management console. As a result, the attacker may perform any operations available from th…
CWE: CWE-625
NVD

HIGH
CVE-2026-63637
CVE-2026-63637
pkg: node

published: Aug 6, 2026

Dgraph is an open source distributed GraphQL database. Prior to 25.3.8, maybeQuoteArg in graphql/resolve/query_rewriter.go passes regexp filter strings into generated DQL without quoting or validating the /pattern/flags form, allowing crafted GraphQL query or mutation filters to inject DQL operators…
CWE: CWE-943
NVD

HIGH
CVE-2026-19143
CVE-2026-19143
pkg: google chrome, google android

published: Aug 6, 2026

Insufficient validation of untrusted input in WebAPKs in Google Chrome on Android prior to 151.0.7922.109 allowed a local attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
CWE: CWE-20
NVD

HIGH
CVE-2026-71259
CVE-2026-71259
pkg: python

published: Aug 5, 2026

ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url() validator in esphome/config_validation.py: `if parsed.scheme and parsed.netloc or parsed.scheme == "file": return parsed.geturl()`. Because `and` binds tighter than `or`, any file: URI passes validation regardless of ne…
CWE: CWE-184
NVD

HIGH
CVE-2026-45414
CVE-2026-45414
pkg: jwt

published: Aug 6, 2026

Decidim is a participatory democracy framework. Prior to 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, JWT-backed API authentication is not bound to the organization selected by the current host, allowing a JWT issued for one tenant to be replayed against another tenant’s API to read participantDeta…
CWE: CWE-639, CWE-863
NVD

HIGH
CVE-2026-71280
CVE-2026-71280
pkg: linux

published: Aug 5, 2026

go-shiori's DownloadBookmark() (internal/core/download.go) fetches a caller-supplied bookmark URL using a plain http.Client with no custom DialContext or destination-IP validation (no IsLoopback(), IsPrivate(), IsUnspecified(), or IsLinkLocalUnicast() checks). An authenticated user creating or updat…
CWE: CWE-918
NVD

HIGH
CVE-2026-71271
CVE-2026-71271
pkg: linux

published: Aug 5, 2026

Memos' webhook URL validation, isReservedIP() (internal/webhook/validate.go), checks a candidate IP against a reservedCIDRs list that omits 0.0.0.0/8 and never calls ip.IsUnspecified() — unlike the correctly implemented sibling function isInternalIP() in internal/httpgetter/html_meta.go, which doe…
CWE: CWE-918
NVD

HIGH
CVE-2026-19163
CVE-2026-19163
pkg: google chrome, microsoft windows

published: Aug 6, 2026

Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-19155
CVE-2026-19155
pkg: google chrome

published: Aug 6, 2026

Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-19154
CVE-2026-19154
pkg: google chrome, google android

published: Aug 6, 2026

Use after free in Skia in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-19152
CVE-2026-19152
pkg: google chrome

published: Aug 6, 2026

Insufficient policy enforcement in Navigation in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-693
NVD

HIGH
CVE-2026-19148
CVE-2026-19148
pkg: google chrome, linux linux_kernel

published: Aug 6, 2026

Out of bounds write in GPU in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-787
NVD

HIGH
CVE-2026-19147
CVE-2026-19147
pkg: go

published: Aug 6, 2026

Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-19141
CVE-2026-19141
pkg: google chrome, google android

published: Aug 6, 2026

Use after free in Resources in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-19140
CVE-2026-19140
pkg: google chrome

published: Aug 6, 2026

Use after free in GPU in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-19138
CVE-2026-19138
pkg: google chrome

published: Aug 6, 2026

Heap buffer overflow in CrashReporting in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-122
NVD

HIGH
CVE-2026-19137
CVE-2026-19137
pkg: google chrome, google android

published: Aug 6, 2026

Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-71206
CVE-2026-71206
pkg: jwt

published: Aug 5, 2026

Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature and returns the embedded claims.Account object unmodified, never re-fetching the account from the database. No session store or token-revocation mechanism exists in the codebase. Deleting an account or de…
CWE: CWE-613
GitHub-GHSA

HIGH
GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython
GHSA-hmq2-w58f-27jc
pkg: GitPython
eco: pip
published: Aug 7, 2026
### Summary
GitPython computes the on-disk location of a submodule's separate Git directory (`.git/modules/<name>`) from the submodule's `.gitmodules` section name with no validation. Because that name is fully attacker-controlled content of a cloned repository, a malicious repository can set a subm…
GitHub-GHSA

HIGH
Traefik: Gateway API route identity collision allows cross-namespace backend hijacking
GHSA-fgjj-px3w-67xx
pkg: github.com/traefik/traefik/v3, github.com/traefik/traefik/v3
eco: go
published: Aug 6, 2026
## Summary

There is a high severity vulnerability in Traefik's Kubernetes Gateway API provider. Router and service identities for `HTTPRoute`, `GRPCRoute`, `TCPRoute` and `TLSRoute` objects were built by hyphen-concatenating the route namespace, the route name, the Gateway identity, the entry point…

CVE-2026-71327
NVD

HIGH
CVE-2026-71315
CVE-2026-71315
pkg: vue

published: Aug 5, 2026

Nuxt is an open-source web development framework for Vue.js. From 3.21.7 until 3.21.10 and 4.5.1, mixed-case routeRules keys can fail to match case-folded lookups when router.options.sensitive is false and drop appMiddleware authorization gates. This is caused by an incomplete fix for CVE-2026-53721…
CWE: CWE-178, CWE-863
GitHub-GHSA

HIGH
Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)
GHSA-hxvh-4h3w-prp9
pkg: nuxt, nuxt
eco: npm
published: Aug 5, 2026
### Impact

Nuxt matches route rules case-insensitively by default (mirroring vue-router's default `sensitive: false` routing). The fix for GHSA-mm7m-92g8-7m47 / CVE-2026-53721 lowercased the *lookup* path before matching route rules, but the route-rule *keys* compiled into the matcher were left ver…

CVE-2026-71315
NVD

HIGH
CVE-2026-64578
CVE-2026-64578
pkg: linux

published: Aug 5, 2026

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: validate compound request size before reading StructureSize2

When ksmbd validates a compound (chained) SMB2 request,
ksmbd_smb2_check_message() reads pdu->StructureSize2 without first
checking that the compound element is l…

GitHub-GHSA

HIGH
Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin
GHSA-3xpf-xq7r-v8c5
pkg: open-webui
eco: pip
published: Aug 4, 2026
## Summary
Any authenticated user with access to a terminal server could get script of their choosing to run in the Open WebUI origin itself. The HTML file preview rendered terminal-served files in an iframe whose sandbox always granted `allow-same-origin` alongside `allow-scripts`, and the file is …
CVE-2026-70486
NVD

HIGH
CVE-2026-47623
CVE-2026-47623
pkg: nvidia dynamo, linux linux_kernel

published: Aug 4, 2026

NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to denial of service and data tampering.
CWE: CWE-502
NVD

HIGH
CVE-2026-24253
CVE-2026-24253
pkg: nvidia dynamo, linux linux_kernel

published: Aug 4, 2026

NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service and data tampering.
CWE: CWE-787
NVD

HIGH
CVE-2026-58080
CVE-2026-58080
pkg: eclipse milo

published: Aug 4, 2026

In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMapper`. On servers that rely on role permissions and construct the running configuration through `copy()`, sessions receive no role IDs and the default access controller skips role-permissio…
CWE: CWE-862
GitHub-GHSA

HIGH
GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite
GHSA-4gmw-gg2m-w46p
pkg: GitPython
eco: pip
published: Aug 7, 2026
## Summary
`IndexFile.from_tree`, `IndexFile.reset` (→ from_tree) and `IndexFile.merge_tree` append caller-influenced treeish strings positionally to `git read-tree` with no unsafe-option guard, no `allow_unsafe_options` parameter, and no `–` separator. `git read-tree –index-output=<file>` write…
NVD

HIGH
CVE-2026-64665
CVE-2026-64665
pkg: oauth

published: Aug 6, 2026

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker could sign in as an existing user, potentially including a super admin, withou…
CWE: CWE-287, CWE-290
NVD

HIGH
CVE-2026-5857
CVE-2026-5857
pkg: tls

published: Aug 6, 2026

Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_len_received=1 before checking topic_len against the 64-byte limit, so an over-length topic returns early but leaves the flag set. On the next TCP segment, tcp_input() re-invokes the parser with topic_received==…
CWE: CWE-787
NVD

HIGH
CVE-2026-19153
CVE-2026-19153
pkg: google chrome

published: Aug 6, 2026

Insufficient validation of untrusted input in Workers in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-20
NVD

HIGH
CVE-2026-71320
CVE-2026-71320
pkg: vue

published: Aug 5, 2026

Nuxt is an open-source web development framework for Vue.js. From 3.4.0 until 3.21.10 and 4.5.1, an attacker can inject a template key through /__nuxt_island/ props into a dynamic component when `vue.runtimeCompiler: true` is enabled, causing template execution in the Nitro process. This issue is fi…
CWE: CWE-74, CWE-94
GitHub-GHSA

HIGH
Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props
GHSA-9473-5f9j-94wq
pkg: nuxt, nuxt
eco: npm
published: Aug 5, 2026
## Impact

Nuxt server islands accept props via the `/__nuxt_island/` endpoint. When `vue.runtimeCompiler: true` is enabled (off by default) and the application has a server island component that forwards props into Vue's dynamic component resolution (`<component :is>`, `resolveDynamicComponent`, or…

CVE-2026-71320
NVD

HIGH
CVE-2026-9196
CVE-2026-9196
pkg: langflow langflow

published: Aug 5, 2026

IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agentic Assistant validation due to improper handling of LLM‑generated components. The application executes model‑generated Python code in the backend during validation prior to user app…
CWE: CWE-94
NVD

HIGH
CVE-2026-71285
CVE-2026-71285
pkg: express

published: Aug 5, 2026

Uptime Kuma's Matomo analytics integration (server/analytics/matomo-analytics.js) injects the admin-configurable Matomo `siteId` value as a bare, unquoted JavaScript expression inside a <script> block rendered on every public status page: `_paq.push(['setSiteId', ${escapedSiteIdHTMLAttribute}]);`. T…
CWE: CWE-79
GitHub-GHSA

HIGH
Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder
GHSA-3cg5-48j3-v4gv
pkg: open-webui
eco: pip
published: Aug 4, 2026
## Summary
A user granted write access to a shared chat folder could permanently delete chats and messages belonging to the folder's owner. Deleting a folder cascades into the owner's chats and the entire subfolder subtree, and the deletion handler required only write access on subfolders instead of…
CVE-2026-70494
NVD

HIGH
CVE-2026-70482
CVE-2026-70482
pkg: oauth

published: Aug 4, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.0, when ENABLE_OAUTH_TOKEN_EXCHANGE=True, /oauth/{provider}/token/exchange accepts a raw provider access token and validates it by calling the provider userinfo endpoint without confirming whi…
CWE: CWE-287
GitHub-GHSA

HIGH
Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client
GHSA-rq84-p6rr-vf89
pkg: open-webui
eco: pip
published: Aug 4, 2026
## Summary

The OAuth token exchange endpoint accepts a raw provider access token and validates it by calling the provider's userinfo endpoint. A userinfo endpoint reports only that a token is valid, never which OAuth client it was issued to, and the endpoint performed no audience or client check of…

CVE-2026-70482
GitHub-GHSA

HIGH
GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read
GHSA-3f7w-8rr8-f37f
pkg: GitPython
eco: pip
published: Aug 3, 2026
**Target:** gitpython-developers/GitPython
**Tested:** HEAD `07e80555` (2026-07-25), latest release 3.1.55, `git version 2.50.1`
**Reported instances:** 2 exploitable, from a sweep of 14 unguarded call sites

## Summary

GitPython blocks dangerous git options through `Git.check_unsafe_options()`, ga…

NVD

HIGH
CVE-2026-67611
CVE-2026-67611
pkg: oauth

published: Aug 3, 2026

OpenEMR through 8.2.0 contains an authentication bypass vulnerability that allows attackers with valid credentials to circumvent multi-factor authentication by exploiting the exposed OAuth2 password grant flow through an unauthenticated client registration endpoint. Attackers can register an OAuth2 …
CWE: CWE-308
NVD

HIGH
CVE-2026-67610
CVE-2026-67610
pkg: jwt

published: Aug 3, 2026

OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic client registration endpoint that allows unauthenticated attackers to register a malicious client with system-level FHIR scopes by supplying a self-generated RSA keypair via the jwks field. Once an administ…
CWE: CWE-306
GitHub-GHSA

HIGH
rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution
GHSA-2m8m-jhrm-w6j2
pkg: github.com/rclone/rclone
eco: go
published: Aug 5, 2026
## 1. Summary

rclone interpolates remote SFTP paths into PowerShell hash commands. Its quoting helper escapes only ASCII apostrophe, although PowerShell accepts four Unicode smart quotes as single-quote delimiters. An attacker-controlled filename can therefore terminate the intended path literal an…

CVE-2026-71312
NVD

HIGH
CVE-2026-71279
CVE-2026-71279
pkg: node

published: Aug 5, 2026

Zigbee2MQTT's ExternalJSExtension.getFilePath() (lib/extension/externalJS.ts) joins a `name` parameter received via an MQTT message (topic zigbee2mqtt/bridge/request/extension/save) into the extensions base path using path.join(basePath, name) with no sanitization. Because path.join() resolves `../`…
CWE: CWE-22
GitHub-GHSA

HIGH
jsii-diff: Command Injection via npm: package argument
GHSA-wcx4-wpfv-mc5c
pkg: jsii-diff
eco: npm
published: Aug 7, 2026
## Summary

jsii-diff is a command line tool to compare the API differences between two jsii assemblies, and report errors if there are backwards-incompatible changes to the API. An issue exists where specially formatted command line arguments can be used to execute shell commands via this tool.

##…

CVE-2026-15895
NVD

HIGH
CVE-2026-70628
CVE-2026-70628
pkg: express

published: Aug 6, 2026

FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsub_parser.c that allows attackers to trigger a heap buffer overflow by supplying a crafted WTV file. The overflow causes the bounds-check guard expressi…
CWE: CWE-190, CWE-787
NVD

HIGH
CVE-2026-64588
CVE-2026-64588
pkg: linux

published: Aug 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

fuse-uring: fix data races on ring->ready

On weakly-ordered architectures, the store to fiq->ops can be
reordered past the store to ring->ready, allowing a CPU that sees
ring->ready == true via fuse_uring_ready() to dispatch reque…

NVD

HIGH
CVE-2026-64585
CVE-2026-64585
pkg: linux

published: Aug 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

can: esd_usb: kill anchored URBs before freeing netdevs

esd_usb_disconnect() frees each CAN netdev with free_candev() inside
its per-netdev loop and only calls unlink_all_urbs(dev) afterwards.
The per-netdev private data (struct e…

NVD

HIGH
CVE-2026-64584
CVE-2026-64584
pkg: linux

published: Aug 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

usb: gadget: f_midi: cancel pending IN work before freeing the midi object

The f_midi driver embeds a work item (midi->work) whose handler,
f_midi_in_work(), dereferences the enclosing struct f_midi through
container_of(). This w…

NVD

HIGH
CVE-2026-64583
CVE-2026-64583
pkg: linux

published: Aug 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown

The Broadcom BDC UDC driver registers its IRQ handler with
devm_request_irq() in bdc_udc_init(), so the IRQ is released by devm
only after bdc_remove() ret…

NVD

HIGH
CVE-2026-55522
CVE-2026-55522
pkg: python

published: Aug 5, 2026

PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of praiseonaiagents, the workflow "include" feature is vulnerable to code execution. Workflow._execute_include() implicitly imports and runs an included recipe's tools.py via a raw imp…
CWE: CWE-94, CWE-426, CWE-829
NVD

HIGH
CVE-2026-18485
CVE-2026-18485
pkg: windows

published: Aug 5, 2026

There is a local privilege escalation vulnerability recently discovered in the NI-PAL kernel driver.  This may allow a local, authenticated user to escalate privileges and execute arbitrary code.  This vulnerability affects NI-PAL 26.3.1 and prior versions running on Microsoft Windows.
CWE: CWE-1285
NVD

HIGH
CVE-2026-12410
CVE-2026-12410
pkg: windows

published: Aug 5, 2026

Link following vulnerability in the Uninstaller component in CCleaner prior to 7.10.1464 on Windows allows a local, low-privileged attacker to escalate privileges to SYSTEM via a symlink/junction created during application uninstallation, which CCleaner follows when deleting the application's data f…
CWE: CWE-59
NVD

HIGH
CVE-2026-64582
CVE-2026-64582
pkg: linux

published: Aug 5, 2026

In the Linux kernel, the following vulnerability has been resolved:

RDMA/rxe: Fix a use-after-free problem in rxe_mmap

rxe_mmap() removes a rxe_mmap_info struct from the pending_mmaps list
and releases pending_lock while the struct's kref is still at 1:

list_del_init(&ip->pending_mmaps);
sp…

NVD

HIGH
CVE-2026-64581
CVE-2026-64581
pkg: linux

published: Aug 5, 2026

In the Linux kernel, the following vulnerability has been resolved:

xfrm: fix sk_dst_cache double-free in xfrm_user_policy()

xfrm_user_policy() clears the socket dst cache with __sk_dst_reset(),
i.e. the non-atomic __sk_dst_set(sk, NULL): it reads sk_dst_cache with
rcu_dereference_protected(), sto…

NVD

HIGH
CVE-2026-64580
CVE-2026-64580
pkg: linux

published: Aug 5, 2026

In the Linux kernel, the following vulnerability has been resolved:

xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst()

On the error path where in6_dev_get(dev) returns NULL, xfrm6_fill_dst()
releases the device reference with netdev_put() but leaves
xdst->u.dst.dev set. d…

NVD

HIGH
CVE-2026-64575
CVE-2026-64575
pkg: linux

published: Aug 5, 2026

In the Linux kernel, the following vulnerability has been resolved:

bpf: tcp: fix double sock release on batch realloc

bpf_iter_tcp_batch() releases the current batch via
bpf_iter_tcp_put_batch(), which drops the socket refs and rewrites
each slot with the socket cookie, then grows the batch. cur_…

NVD

HIGH
CVE-2026-64574
CVE-2026-64574
pkg: linux

published: Aug 5, 2026

In the Linux kernel, the following vulnerability has been resolved:

wifi: mac80211: tear down new links on vif update error path

When ieee80211_vif_update_links() adds new links it allocates a link
container for each and calls ieee80211_link_init() (which registers the
per-link debugfs files with …

NVD

HIGH
CVE-2026-64570
CVE-2026-64570
pkg: linux

published: Aug 5, 2026

In the Linux kernel, the following vulnerability has been resolved:

wifi: mac80211: fix fils_discovery double free on alloc failure

ieee80211_set_fils_discovery() calls kfree_rcu() on the old template
before allocating the replacement. If the kzalloc() then fails, it
returns -ENOMEM while link->u.…

NVD

HIGH
CVE-2026-64568
CVE-2026-64568
pkg: linux

published: Aug 5, 2026

In the Linux kernel, the following vulnerability has been resolved:

wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure

ieee80211_set_unsol_bcast_probe_resp() calls kfree_rcu() on the old
template before allocating the replacement. If the kzalloc() then fails,
it returns -ENOME…

NVD

HIGH
CVE-2026-64567
CVE-2026-64567
pkg: linux

published: Aug 5, 2026

In the Linux kernel, the following vulnerability has been resolved:

btrfs: reject free space cache with more entries than pages

When loading a v1 free space cache, __load_free_space_cache() takes
num_entries and num_bitmaps straight from the on-disk
btrfs_free_space_header. That header is stored i…

NVD

HIGH
CVE-2026-18657
CVE-2026-18657
pkg: windows

published: Aug 4, 2026

An uncontrolled search path element in Kiro CLI before version 2.10.0 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a maliciously crafted project directory containing an executable that bypasses workspace trust protections when a local user starts Kiro CLI in th…
CWE: CWE-427
NVD

HIGH
CVE-2026-18656
CVE-2026-18656
pkg: windows

published: Aug 4, 2026

An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a maliciously crafted project directory containing an executable that bypasses workspace trust protections when a local user opens the directory.…
CWE: CWE-427
NVD

HIGH
CVE-2026-64563
CVE-2026-64563
pkg: linux

published: Aug 4, 2026

In the Linux kernel, the following vulnerability has been resolved:

rhashtable: clear stale iter->p on table restart

rhashtable_walk_start_check() has two restart paths when resuming a walk.
When iter->walker.tbl is valid, it re-validates iter->p against the table
and sets iter->p = NULL if the ob…

NVD

HIGH
CVE-2026-41447
CVE-2026-41447
pkg: openssl

published: Aug 3, 2026

FirmaCheck for Windows before 1.3.16 contains a DLL hijacking vulnerability that allows local attackers to execute arbitrary code by placing a crafted openssl.cnf file in the unvalidated C:\Program Files (x86)\Common Files\SSL\ directory path. Attackers can write a malicious OpenSSL configuration fi…
CWE: CWE-426
NVD

HIGH
CVE-2026-64636
CVE-2026-64636
pkg: windows

published: Aug 7, 2026

An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to read arbitrary data from the panel database.
CWE: CWE-89
GitHub-GHSA

HIGH
Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader
GHSA-w2rx-84hp-gg95
pkg: open-webui
eco: pip
published: Aug 4, 2026
## Summary
With the Playwright web loader enabled, Open WebUI opens user-submitted URLs in a real browser and validates the destination address before allowing the request. That check only ran for the top-level page request. Every other request the page issued was passed through unvalidated, so a pa…
CVE-2026-70479
NVD

HIGH
CVE-2026-34966
CVE-2026-34966
pkg: oauth

published: Aug 5, 2026

Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiting HTTP fetch operations in migration and OAuth avatar code paths that use Go's default http.Get without a custom DialContext. Attackers can supply arb…
CWE: CWE-918
NVD

HIGH
CVE-2026-10595
CVE-2026-10595
pkg: python

published: Aug 9, 2026

A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specifically in the SPA catch-all route implemented in `backend/routers/ui.py`. The vulnerability arises from the improper handling of user-controlled path input, which is directly joined into a filesystem path without sanitizat…
CWE: CWE-23
NVD

HIGH
CVE-2026-52880
CVE-2026-52880
pkg: docker

published: Aug 7, 2026

Klever-Go is the Go implementation of the Klever blockchain protocol. Versions from 1.7.14 through 1.7.17 are vulnerable to a remotely triggerable denial of service. Both REST APIs are started with the Gin Engine.Run convenience method, which serves requests through Go's default HTTP server with no …
CWE: CWE-400, CWE-770
GitHub-GHSA

HIGH
pymdown-extensions: exponential-backtracking ReDoS in caret, tilde, betterem, and magiclink inline processors
GHSA-gm37-52c6-37mw
pkg: pymdown-extensions
eco: pip
published: Aug 7, 2026
### Summary

Four inline processors in pymdown-extensions contain regular expressions with
exponential backtracking. A single untrusted Markdown line under
50 bytes drives `markdown.markdown()` into unbounded CPU on the rendering thread
(seconds at ~45 bytes, growing exponentially with each added ch…

CVE-2026-67422
GitHub-GHSA

HIGH
GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via –template clone hooks
GHSA-9rj7-rf2p-w77r
pkg: GitPython
eco: pip
published: Aug 7, 2026
## Summary
`Repo.init()` forwards `**kwargs` verbatim to `git init` with no unsafe-option guard and no `allow_unsafe_options` parameter. `git init –template=<dir>` copies `<dir>/hooks/*` into the new repo's `.git/hooks`, so an attacker-controlled `template` kwarg plants a hook that executes on the …
NVD

HIGH
CVE-2026-16262
CVE-2026-16262
pkg: oauth

published: Aug 7, 2026

The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating user session, allowing an unauthenticated attacker to log a victim into an attacker-controlled account (login CSRF), so that the victim's subsequent activity is stored under and r…
CWE: CWE-352
NVD

HIGH
CVE-2026-70636
CVE-2026-70636
pkg: oauth

published: Aug 6, 2026

Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAuth2 credential refresh endpoint by exploiting prefix-based whitelist matching in the authentication middleware defined in packages/server/src/utils/constants.ts. Attackers can…
CWE: CWE-862
NVD

HIGH
CVE-2026-67422
CVE-2026-67422
pkg: express

published: Aug 6, 2026

pymdown-extensions is a collection of extensions for the Python Markdown library. In versions up to and including 11.0, four inline processors (caret, tilde, betterem, and magiclink) use regular expressions whose content groups can partition a run of delimiter characters in exponentially many ways, …
CWE: CWE-1333
NVD

HIGH
CVE-2026-19158
CVE-2026-19158
pkg: google chrome, microsoft windows

published: Aug 6, 2026

Use after free in Views in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-19156
CVE-2026-19156
pkg: google chrome

published: Aug 6, 2026

Heap buffer overflow in Base in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)
CWE: CWE-122
NVD

HIGH
CVE-2026-19142
CVE-2026-19142
pkg: go

published: Aug 6, 2026

Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
GitHub-GHSA

HIGH
JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported
GHSA-5p4m-2wfm-xmqj
pkg: js-yaml, js-yaml
eco: npm
published: Aug 6, 2026
# Quadratic CPU consumption in `!!omap` resolution (js-yaml 3.x and 4.x)

## Summary

`resolveYamlOmap()` enforces key uniqueness for `!!omap` sequences with a linear
scan (`objectKeys.indexOf(…)`) inside the per-element loop, making resolution
**O(n²)** in the number of entries. A modestly sized…

NVD

HIGH
CVE-2026-53985
CVE-2026-53985
pkg: docker

published: Aug 6, 2026

Ground Station prior to 0.6.0 contains an unauthenticated denial-of-service vulnerability in the Socket.IO server's service_control event handler that allows any unauthenticated network peer to forcibly terminate the ground-station process by sending a single restart_service command. Attackers can …
CWE: CWE-306
NVD

HIGH
CVE-2026-53977
CVE-2026-53977
pkg: express

published: Aug 6, 2026

OpenChamber 1.11.7 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to terminate the server process by sending a POST request to the /api/system/shutdown endpoint, which is registered before the authentication middleware in the Express route handler chain.…
CWE: CWE-306
NVD

HIGH
CVE-2026-71321
CVE-2026-71321
pkg: vue

published: Aug 5, 2026

Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, the internal island renderer endpoint `/__nuxt_island/…` decodes and hashes attacker-controlled JSON body input with destr and ohash before validating the URL-resident hash. An unauthenticated `POST /_…
CWE: CWE-407, CWE-770
NVD

HIGH
CVE-2026-71316
CVE-2026-71316
pkg: vue

published: Aug 5, 2026

Nuxt is an open-source web development framework for Vue.js. From 4.4.0 until 4.5.1, runtime cache:nuxt:payload entries for /<page>/_payload.json can be returned before route middleware and page guards because import.meta.prerender is not enforced, disclosing another user's SSR data. This issue is f…
CWE: CWE-524, CWE-862
NVD

HIGH
CVE-2026-67864
CVE-2026-67864
pkg: node

published: Aug 5, 2026

An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the NodeManagement type-instantiation logic component
CWE: CWE-400
GitHub-GHSA

HIGH
Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation
GHSA-9pgf-384g-p7mv
pkg: nuxt, nuxt
eco: npm
published: Aug 5, 2026
### Impact

The internal island renderer endpoint (`/__nuxt_island/…`) decodes and hashes attacker-controlled request input before it validates the URL-resident hash. An unauthenticated `POST /__nuxt_island/<name>_<anything>.json` with a large JSON body (for example ~4.6 MB / 150k keys) is fully r…

CVE-2026-71321
NVD

HIGH
CVE-2026-71314
CVE-2026-71314
pkg: vue

published: Aug 5, 2026

Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an unauthenticated attacker can use a server island v-for prop, including vforToArray and , to trigger unbounded SSR memory allocation until MAX_VFOR_LENGTH = 100000 and crash the Nuxt process. This issu…
CWE: CWE-400, CWE-770, CWE-789, CWE-1284
GitHub-GHSA

HIGH
Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients
GHSA-wm8w-6qjm-cv43
pkg: nuxt
eco: npm
published: Aug 5, 2026
### Impact

When a page is covered by `routeRules` `cache` / `swr` / `isr`, Nuxt enables runtime payload extraction and serves `/<page>/_payload.json`. On affected versions the renderer stored the SSR payload in the shared `cache:nuxt:payload` storage under a path-only key (no cookie, `authorization…

CVE-2026-71316
GitHub-GHSA

HIGH
Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering
GHSA-hxcr-hm88-mpq6
pkg: nuxt, nuxt
eco: npm
published: Aug 5, 2026
### Impact

An unauthenticated attacker can crash a Nuxt server that renders any island / server component containing a `v-for` over a prop (for example `v-for="n in count"` or a `<slot v-for>`). Because the island URL hash is a non-secret digest of the request, the attacker can compute a valid hash…

CVE-2026-71314
GitHub-GHSA

HIGH
rclone: Unvalidated symlink target in local `–links` — arbitrary file write from an untrusted remote
GHSA-cf44-9pgv-m4xc
pkg: github.com/rclone/rclone
eco: go
published: Aug 5, 2026
### Summary
With `-l/–links`, rclone serializes symlinks as `<name>.rclonelink` text objects whose body is the link target. When rclone writes such an object to a local destination, it recreates the symlink with `os.Symlink(<object body>, <dest path>)` and performs NO validation of the target. If t…
CVE-2026-54572
NVD

HIGH
CVE-2026-70601
CVE-2026-70601
pkg: windows

published: Aug 5, 2026

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.5, apps that expose Promise-returning functions to web content via contextBridge may be vulnerable to a context isolation bypass. Untrusted web con…
CWE: CWE-693
GitHub-GHSA

HIGH
Electron: Context isolation bypass via Function.prototype.bind hijack
GHSA-h7rp-cf8h-j98x
pkg: electron, electron, electron
eco: npm
published: Aug 5, 2026
### Impact
Apps that expose Promise-returning functions to web content via `contextBridge` may be vulnerable to a context isolation bypass. Untrusted web content could obtain access to the isolated preload world and, through it, every capability the preload script has. In renderers without a sandbox…
CVE-2026-70601
NVD

HIGH
CVE-2026-54876
CVE-2026-54876
pkg: tls

published: Aug 5, 2026

Issue summary: A malicious TLS server can cause a memory leak in a TLS
client that has enabled OCSP response checking by sending an OCSP
response that contains no single response entries.

Impact summary: An attacker can leak an attacker-tunable amount of memory
per TLS handshake in a victim client …

CWE: CWE-401
NVD

HIGH
CVE-2026-71215
CVE-2026-71215
pkg: node

published: Aug 5, 2026

art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by both the include() and extend() template directives, resolves the target file path via path.resolve(root, filename) with no check afterward that the result remains inside root. Because path.resolve() disc…
CWE: CWE-22
NVD

HIGH
CVE-2026-71209
CVE-2026-71209
pkg: express

published: Aug 5, 2026

audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated-allowed GET routes against req.path via a regex requiring a literal /items/:id/cover or /authors/:id/image shape, where req.path retains %2F sequences URL-encoded. Express's router decodes the :id route …
CWE: CWE-22
NVD

HIGH
CVE-2026-64577
CVE-2026-64577
pkg: linux

published: Aug 5, 2026

In the Linux kernel, the following vulnerability has been resolved:

gtp: check skb_pull_data() return in gtp1u_send_echo_resp()

gtp1u_send_echo_resp() ignores skb_pull_data()'s return value. Its
caller gtp1u_udp_encap_recv() only guarantees 16 bytes (udphdr +
gtp1_header), but the pull requests 20…

NVD

HIGH
CVE-2026-67592
CVE-2026-67592
pkg: apache qpid_protonj2

published: Aug 5, 2026

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.

This issue affects Apache Qpid ProtonJ2: through 1.1.0.

Users are recommended to upgrade to version 1.2.0…

CWE: CWE-770
GitHub-GHSA

HIGH
XSS in Ghost's ActivityPub client
GHSA-xpp7-93×6-v29m
pkg: @tryghost/activitypub
eco: npm
published: Aug 4, 2026
### Impact

The ActivityPub client in Ghost was vulnerable to JavaScript injection on posts shared by a maliciously customised ActivityPub server.

### Vulnerable Versions

This vulnerability is present in the @tryghost/activitypub package up to v3.0.8. All prior versions are also affected.

### Pa…

CVE-2026-53950
NVD

HIGH
CVE-2026-66901
CVE-2026-66901
pkg: jwt

published: Aug 4, 2026

Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated URLs taken from the credentials JSON.

The URLs the library requests are read from the credentials JSON, and their hosts were not checked against the universe domain before the re…

CWE: CWE-201, CWE-918
NVD

HIGH
CVE-2026-47618
CVE-2026-47618
pkg: nvidia dynamo, linux linux_kernel

published: Aug 4, 2026

NVIDIA Dynamo for Linux contains a vulnerability in the Rust multimodal media fetcher where an attacker could cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.
CWE: CWE-918
NVD

HIGH
CVE-2026-47617
CVE-2026-47617
pkg: nvidia dynamo, linux linux_kernel

published: Aug 4, 2026

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery via DNS rebinding. A successful exploit of this vulnerability might lead to information disclosure.
CWE: CWE-918
NVD

HIGH
CVE-2026-47616
CVE-2026-47616
pkg: nvidia dynamo, linux linux_kernel

published: Aug 4, 2026

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.
CWE: CWE-918
NVD

HIGH
CVE-2026-47615
CVE-2026-47615
pkg: nvidia dynamo, linux linux_kernel

published: Aug 4, 2026

NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery by supplying a crafted URL in a multimodal request. A successful exploit of this vulnerability might lead to information disclosure.
CWE: CWE-918
NVD

HIGH
CVE-2026-47614
CVE-2026-47614
pkg: nvidia dynamo, linux linux_kernel

published: Aug 4, 2026

NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.
CWE: CWE-918
NVD

HIGH
CVE-2026-47613
CVE-2026-47613
pkg: nvidia dynamo, linux linux_kernel

published: Aug 4, 2026

NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation of a pathname to a restricted directory by supplying a crafted local path in a multimodal request. A successful exploit of this vulnerability might lead to information disclosure.
CWE: CWE-918
NVD

HIGH
CVE-2026-47612
CVE-2026-47612
pkg: nvidia dynamo, linux linux_kernel

published: Aug 4, 2026

NVIDIA Dynamo for Linux contains a vulnerability in the image loading component where an attacker may cause improper limitation of a pathname to a restricted directory. A successful exploit of this vulnerability might lead to information disclosure.
CWE: CWE-22
NVD

HIGH
CVE-2026-24255
CVE-2026-24255
pkg: nvidia dynamo, linux linux_kernel

published: Aug 4, 2026

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a hash collision by submitting images that share an identical pixel byte sequence but have different dimensions. A successful exploit of this vulnerability might lead to data tampering.
CWE: CWE-1023
NVD

HIGH
CVE-2026-56848
CVE-2026-56848
pkg: node

published: Aug 4, 2026

A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free.

This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.

CWE: CWE-416
NVD

HIGH
CVE-2026-56846
CVE-2026-56846
pkg: node

published: Aug 4, 2026

A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion.

This vulnerability affects Node.js **24.x** and **22.x**.

CWE: CWE-400
GitHub-GHSA

HIGH
fast-uri vulnerable to host confusion via backslash authority introducer
GHSA-7p8r-x3mc-p8w7
pkg: fast-uri, fast-uri, fast-uri
eco: npm
published: Aug 3, 2026
### Impact

`fast-uri` v4.1.1 and earlier require a literal `//` to recognize a URI authority, so a reference that uses `\\`, `/\`, or `\/` as the authority introducer (in place of `//`, after an optional scheme) is parsed with no authority: the sequence and everything after it fold into the path. N…

CVE-2026-18446
GitHub-GHSA

HIGH
Socket.IO: Zero-attachment Memory Exhaustion
GHSA-2m8v-j782-fhvr
pkg: socket.io-parser, socket.io-parser, socket.io-parser
eco: npm
published: Aug 3, 2026
### Impact

A specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory.

### Patches

| Version range | Used by | Fixed version |
|———-…

CVE-2026-69185
GitHub-GHSA

HIGH
brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
GHSA-rgw5-rvv9-x895
pkg: brace-expansion, brace-expansion, brace-expansion
eco: npm
published: Aug 3, 2026
### Summary

The `maxLength` mitigation added in `5.0.8` for GHSA-mh99-v99m-4gvg / CVE-2026-14257 is incomplete. It bounds the accumulator where results are *combined*, but not the intermediate arrays that feed it. A ~25 KB input still crashes the Node process with an **uncatchable** out-of-memory e…

CVE-2026-69152
NVD

HIGH
CVE-2026-19139
CVE-2026-19139
pkg: google chrome, microsoft windows

published: Aug 6, 2026

Race in CredentialProvider in Google Chrome on Windows prior to 151.0.7922.109 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)
CWE: CWE-362, CWE-362
NVD

HIGH
CVE-2026-8470
CVE-2026-8470
pkg: langflow langflow

published: Aug 5, 2026

IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's non-cryptographic random module for generating Fernet encryption keys from user secrets under 32 characters. The deterministic Mersenne Twister PRNG produces identical keys for id…
CWE: CWE-327
GitHub-GHSA

HIGH
Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads
GHSA-v3j7-r9gq-3gjw
pkg: electron, electron, electron
eco: npm
published: Aug 5, 2026
### Impact
A custom scheme registered with `supportFetchAPI: true` but without `corsEnabled: true` was not subject to CORS enforcement. A page loaded from a remote origin could therefore `fetch()` or `XMLHttpRequest` that scheme cross-origin and read the full response body, rather than the read bein…
CVE-2026-70604
NVD

HIGH
CVE-2026-67598
CVE-2026-67598
pkg: tls

published: Aug 3, 2026

Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that allows network-adjacent attackers to intercept outbound HTTPS requests to configured LLM providers by presenting arbitrary TLS certificates, as CURLOPT_SSL_VERIFYPEER and CURLOPT_SSL_…
CWE: CWE-295
GitHub-GHSA

HIGH
undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives
GHSA-4cwx-7wf7-3272
pkg: undici, undici
eco: npm
published: Aug 3, 2026
### Summary

Two issues in undici's cache interceptor, both fixed by the same patch on `lib/util/cache.js`:

1. **Shared-cache disclosure:** Responses with malformed qualified `Cache-Control: private` directives such as `private=""` or `private=","` can be incorrectly stored in the default shared ca…

CVE-2026-13697
NVD

HIGH
CVE-2026-18770
CVE-2026-18770
pkg: python

published: Aug 4, 2026

A vulnerability has been found in vibesurf-ai VibeSurf up to cd6e519d507cdd4d63061300bf60fb176e1f57e0. Impacted is an unknown function of the file /code of the component Python Validation Handler. The manipulation leads to code injection. Remote exploitation of the attack is possible. This product f…
CWE: CWE-74, CWE-94
NVD

HIGH
CVE-2026-16636
CVE-2026-16636
pkg: go

published: Aug 6, 2026

The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Recipient Display Name (to.name) in Email Logs in all versions up to, and including, 2.2.95 due to insufficient input san…
CWE: CWE-79
GitHub-GHSA

HIGH
Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path
GHSA-9f4c-93c8-jc8g
pkg: electron, electron, electron
eco: npm
published: Aug 5, 2026
### Impact
A sandboxed iframe without the `allow-popups` keyword could still open a new window (or trigger `setWindowOpenHandler`) with no user interaction, because new-window navigations taking the OpenURL path did not apply the iframe sandbox popup restriction.

Apps that embed untrusted content i…

CVE-2026-70608
NVD

HIGH
CVE-2026-71269
CVE-2026-71269
pkg: node

published: Aug 5, 2026

Node-RED's local-filesystem library storage module (getLibraryEntry() and saveLibraryEntry() in packages/node_modules/@node-red/runtime/lib/storage/localfilesystem/library.js), reachable via GET/POST /library/:lib/:type/*path, joins the user-supplied path parameter directly into the filesystem path …
CWE: CWE-22
NVD

HIGH
CVE-2026-69246
CVE-2026-69246
pkg: tls

published: Aug 3, 2026

Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host header separately. The cURL handlers set CURLOPT_URL to the URI exactly as written and push that Host into CURLOPT_HTTPHEADER; StreamHandler does the same throug…
CWE: CWE-180, CWE-436, CWE-918, CWE-941
GitHub-GHSA

HIGH
go-git: Worktree operations may follow symlinks
GHSA-hc8v-wwc9-vgxm
pkg: github.com/go-git/go-git/v5, github.com/go-git/go-git/v6
eco: go
published: Aug 7, 2026
## Impact

A symlink traversal issue in `go-git` could allow worktree operations to modify files outside the intended worktree path.

The `worktreeFilesystem` wrapper rejected dangerous path strings, including paths containing `.git`, parent-directory components, or control characters. However, it d…

CVE-2026-71556
NVD

HIGH
CVE-2026-64576
CVE-2026-64576
pkg: linux

published: Aug 5, 2026

In the Linux kernel, the following vulnerability has been resolved:

nexthop: initialize extack in nh_res_bucket_migrate()

nh_res_bucket_migrate() passes an uninitialized netlink_ext_ack to
call_nexthop_res_bucket_notifiers(). When
nh_notifier_res_bucket_info_init() fails (e.g. the kzalloc returns

GitHub-GHSA

HIGH
Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs
GHSA-8x5v-cpv7-8jjp
pkg: open-webui
eco: pip
published: Aug 4, 2026
## Summary

Open WebUI fetches user-supplied URLs on the server for RAG URL ingestion, URL-to-markdown conversion and web-search content retrieval, and decides whether a destination is allowed by asking whether its IP address is globally routable. That test operates on the literal IPv6 address and d…

CVE-2026-70485
NVD

HIGH
CVE-2026-64587
CVE-2026-64587
pkg: linux

published: Aug 6, 2026

In the Linux kernel, the following vulnerability has been resolved:

net: ethernet: arc: emac: quiesce interrupts before requesting IRQ

Normal RX/TX interrupts are enabled later, in arc_emac_open(), so probe
should not see interrupt delivery in the usual case. However, hardware may
still present st…

GitHub-GHSA

HIGH
ngx-extended-pdf-viewer bundles a version of pdf.js vulnerable to CVE-2026-16633
GHSA-w9hm-4m3m-fxmm
pkg: ngx-extended-pdf-viewer
eco: npm
published: Aug 6, 2026
ngx-extended-pdf-viewer embeds a fork of Mozilla's pdf.js rather than depending on pdfjs-dist, so this vulnerability is not visible to dependency scanners through package.json.

### Impact
Opening a malicious PDF can execute attacker-controlled JavaScript in the context of the hosting page. Upstream…

GitHub-GHSA

HIGH
PDF.js: Arbitrary JavaScript execution upon opening a malicious PDF
GHSA-hq66-cqwq-w95j
pkg: pdfjs-dist
eco: npm
published: Aug 6, 2026
### Impact

If PDF.js is used to load a malicious PDF, and PDF.js is configured with `enableScripting` set to true (which is the default value) and no CSP for disallowing script-src, unrestricted attacker-controlled JavaScript will be executed in the context of the hosting domain.

### Patches

### …

CVE-2026-16633
GitHub-GHSA

HIGH
Nx: Zip-Slip in the self-hosted remote cache
GHSA-vp3h-ghgh-jr7g
pkg: nx, @nx/s3-cache, @nx/gcs-cache
eco: npm
published: Aug 6, 2026
## Summary

The Nx **self-hosted HTTP remote cache** extracts downloaded cache artifacts without constraining where files are written. A malicious — or on-path (MITM) — remote cache server can return a crafted tar archive whose entries escape the cache directory and write to arbitrary locations …

CVE-2026-71476
GitHub-GHSA

HIGH
Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth
GHSA-x677-9fxg-v5c5
pkg: github.com/traefik/traefik/v2, github.com/traefik/traefik/v3, github.com/traefik/traefik/v3
eco: go
published: Aug 6, 2026
## Summary

There is a high severity vulnerability in Traefik's BasicAuth, DigestAuth, and ForwardAuth
middlewares. The fix for CVE-2026-33433 stripped canonical-cased spoofed identity headers
(e.g. `X-Auth-User`) before writing Traefik's own value, but did not account for
underscore-variant header …

CVE-2026-54763
GitHub-GHSA

HIGH
Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass
GHSA-8rxv-jg7p-wvg3
pkg: github.com/traefik/traefik/v3
eco: go
published: Aug 6, 2026
## Summary

There is a high severity vulnerability in Traefik's Kubernetes Ingress NGINX provider. When an Ingress uses the `nginx.ingress.kubernetes.io/rewrite-target` annotation with a regular expression that captures attacker-controlled text without requiring a path separator (for example path `/…

CVE-2026-67309
GitHub-GHSA

HIGH
Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool
GHSA-3ccp-42pg-hgv6
pkg: github.com/traefik/traefik/v2, github.com/traefik/traefik/v3, github.com/traefik/traefik/v3
eco: go
published: Aug 6, 2026
## Summary

There is a critical vulnerability in Traefik's default HTTP reverse proxy that leads to unauthenticated cross-user response poisoning. When a client opens an HTTP/2 or HTTP/3 `CONNECT` request, Traefik forwards it — body included — to an HTTP/1.1 upstream over a shared `net/http.Tran…

CVE-2026-71324
GitHub-GHSA

HIGH
rclone: Incomplete path validation allows backend root escape in serve restic
GHSA-45pq-889g-fcgh
pkg: github.com/rclone/rclone
eco: go
published: Aug 5, 2026
## Summary

`rclone serve restic` does not correctly reject URL paths beginning with `../`. On affected backends, an attacker who can access the REST endpoint can read, create, overwrite, or delete objects outside the path configured by the operator.

The issue affects `rclone v1.40` through `rclone…

CVE-2026-71309
GitHub-GHSA

HIGH
Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing Manipulation
GHSA-gmmw-qg98-6j6p
pkg: flowise
eco: npm
published: Aug 4, 2026
### Summary
Several organization billing endpoints accept attacker-controlled Stripe identifiers (subscriptionId) without verifying that the identifier belongs to the authenticated user's organization. This allows an authenticated attacker to perform unauthorized Stripe subscription operations on ot…
CVE-2026-70476
GitHub-GHSA

HIGH
Flowise: Missing Authorization on Execution Update Endpoint
GHSA-fm2f-4339-4p2f
pkg: flowise
eco: npm
published: Aug 4, 2026
# Flowise Security Audit Report
**Date**: 2026-03-17
**Researcher**: Dimpal Jadhav (jadhavdimpy@gmail.com)
**GitHub**: https://github.com/Dimpyj1604
**Target**: FlowiseAI/Flowise (latest main branch)
**Version**: flowise-components@3.1.0

### FINDING 1: Missing Authorization on Execution Update Endp…

CVE-2026-70475
GitHub-GHSA

HIGH
Flowise: Cross-Workspace OAuth2 Credential Metadata Leak
GHSA-wch5-xp77-fxg4
pkg: flowise
eco: npm
published: Aug 4, 2026
## Summary

Three OAuth2 credential endpoints look up credentials by `id` alone with no `workspaceId` filter. Two of these endpoints (`callback`, `refresh`) are whitelisted from all authentication. This allows:

1. **Cross-workspace credential access** — Any authenticated user can initiate OAuth2 …

CVE-2026-70474
GitHub-GHSA

HIGH
Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history
GHSA-fr6g-7cq8-fg82
pkg: flowise
eco: npm
published: Aug 4, 2026
### Summary
The **GET `/api/v1/upsert-history`** endpoint returns the **entire server-wide upsert history** (response size **>100MB**) instead of being scoped to the requesting user/tenant/workspace. The response includes **sensitive configuration data** (e.g., Vector Store settings such as **Qdrant…
CVE-2026-70473
GitHub-GHSA

HIGH
Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store
GHSA-chm3-vqcf-52rx
pkg: flowise
eco: npm
published: Aug 4, 2026
# Summary

These endpoints accept a client-controlled `credential` parameter. The server loads credentials by `id` and uses them directly, without checking whether that credential belongs to the caller’s workspace. If an attacker knows another workspace’s `credentialId`, they can use that works…

CVE-2026-70472
GitHub-GHSA

HIGH
Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys
GHSA-88pr-878c-24wf
pkg: flowise-components, flowise
eco: npm
published: Aug 4, 2026
## Summary

Flowise on current `main` allows an authenticated…

GitHub-GHSA

HIGH
Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure
GHSA-8r8h-6vcc-xhrv
pkg: flowise
eco: npm
published: Aug 4, 2026
## Finding — Unauthorized Workspace Variables disclosure via $vars injection (bypasses variables:view)

### What’s wrong (code locations)

– Variables for the active workspace are fetched without checking “variables:view” at this call site: flowise-src/
packages/components/src/utils.…

CVE-2026-70471
GitHub-GHSA

HIGH
Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)
GHSA-xc48-889x-5qmw
pkg: flowise, flowise-components
eco: npm
published: Aug 4, 2026
## Summary

The mitigation shipped for CVE-2025-8943 blocks the `-y` and `–yes` flags on `npx` to stop auto-installation of arbitrary packages. That flag filter works. The environment-variable check in the same patch denies only four variable names by exact string match, and `npm` reads its configu…

CVE-2026-69263
GitHub-GHSA

HIGH
Flowise: `DELETE /api/v1/chatflows/:id` does not validate resource type, allowing `agentflows:delete` and `chatflows:delete` to delete each other’s flow type
GHSA-p5w8-m249-4r4v
pkg: flowise
eco: npm
published: Aug 4, 2026
# summary:
In Flowise, `DELETE /api/v1/chatflows/:id` authorizes requests with `checkAnyPermission('chatflows:delete,agentflows:delete')`. Possession of either permission is sufficient to reach the delete path. The delete logic does not validate the target resource `type`, allowing a caller with onl…
CVE-2026-69262
GitHub-GHSA

HIGH
Flowise: Unauthenticated Property Injection into Flow Execution Context via Ungated `overrideConfig` Spread in Prediction API
GHSA-6vh2-wg4h-4vwj
pkg: flowise
eco: npm
published: Aug 4, 2026
#### Summary

The `POST /api/v1/prediction/:id` endpoint — which is unauthenticated (whitelisted in `WHITELIST_URLS`) — accepts an `overrideConfig` object in the request body. This object is unconditionally spread into the internal `flowConfig` and `flowData` objects at two locations in the code…

CVE-2026-69258
GitHub-GHSA

HIGH
Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses
GHSA-c6xh-wv4j-ppv5
pkg: flowise
eco: npm
published: Aug 4, 2026
## Summary

Flowise's HTTP security module (`httpSecurity.ts`) fails to normalize IPv4-mapped IPv6 addresses (e.g., `::ffff:127.0.0.1`, `::ffff:169.254.169.254`) before checking them against the deny list. Due to an `ipaddr.js` kind mismatch (`ipv6` vs `ipv4`), all IPv4 CIDR deny rules are silently …

CVE-2026-69257
GitHub-GHSA

HIGH
Flowise: Missing authorization on `/api/v1/files` allows low-privileged API keys to list and delete files across workspaces within the same organization
GHSA-wp74-f5hh-5f3r
pkg: flowise
eco: npm
published: Aug 4, 2026
# summary:
In Flowise, the `/api/v1/files` route is protected only by the `feat:files` feature gate and does not enforce `checkPermission(…)` on either `GET` or `DELETE`. As a result, any authenticated API key within the organization, even one with unrelated permissions, can list and delete files …
CVE-2026-69252
GitHub-GHSA

HIGH
Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret Exfiltration
GHSA-r745-8hwv-h473
pkg: flowise
eco: npm
published: Aug 4, 2026
### Summary

The OAuth2 token refresh endpoint (`POST /api/v1/oauth2-credential/refresh/:credentialId`) is unauthenticated by design (it is in the public whitelist) and performs a server-side HTTP request to a credential-controlled URL (`accessTokenUrl`) without SSRF protections. In runtime validati…

CVE-2026-69250
GitHub-GHSA

HIGH
python-cryptography: Duplicate self-signed intermediates can cause exponential path-building
GHSA-jwv3-5hgf-82ww
pkg: cryptography
eco: pip
published: Aug 3, 2026
### Summary
When resolving invalid certificate chains that include duplicate copies of self-signed certificates, the processing recursively invokes the same candidate, leading to an exponential blowup. Although the limitation that the chain depth cannot exceed a specified maximum depth prevents unbo…
CVE-2026-69249
GitHub-GHSA

HIGH
cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing
GHSA-g6cj-pr64-35w5
pkg: cryptography
eco: pip
published: Aug 3, 2026
### Summary

`pkcs7_decrypt_der`, `pkcs7_decrypt_pem`, and `pkcs7_decrypt_smime` reported the
outcome of decrypting a `RecipientInfo`'s `encryptedKey` in several
distinguishable ways, one of which disclosed the exact length recovered from the
RSA operation. The same distinction was also observable b…

CVE-2026-69247
GitHub-GHSA

HIGH
AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)
GHSA-cq5v-8q36-5273
pkg: aiohttp
eco: pip
published: Aug 3, 2026
### Summary

An out-of-bounds heap read could occur in the C response parser while building an error message for a malformed response.

### Impact

An attacker controlled server, or possibly an accidental response could trigger a DoS in the client.

### Workaround

If unable to upgrade, the Python p…

CVE-2026-69244
GitHub-GHSA

HIGH
ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass
GHSA-mwp4-54f8-5fhr
pkg: ip-address
eco: npm
published: Aug 3, 2026
### Summary

`Address4` accepts an octet written with a leading zero and decodes it as decimal, while the WHATWG URL host parser, `inet_aton`, and `getaddrinfo` all decode a leading zero as octal. The library and the network stack therefore disagree about which host a string names. `new Address4('01…

CVE-2026-69192
GitHub-GHSA

HIGH
Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes
GHSA-jj27-h5hq-8×99
pkg: @angular/compiler, @angular/compiler, @angular/compiler
eco: npm
published: Aug 3, 2026
A Cross-Site Scripting (XSS) vulnerability has been identified in the Angular compiler's internationalization (i18n) pipeline. Although Angular disallows binding to event-handler attributes such as `onclick` and `onerror` through standard attribute validation (`validateAttribute()` / `validateProper…
CVE-2026-69151
NVD

MEDIUM
CVE-2026-71313
CVE-2026-71313
pkg: windows

published: Aug 5, 2026

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From v1.51.0 until v1.75.0, the local backend in backend/local/local.go relies on the configurable filename encoder to prevent remote filename data from becoming operating-system path syntax…
CWE: CWE-22
GitHub-GHSA

MEDIUM
rclone: Local Encoding Path Traversal
GHSA-7p4m-qxvv-g567
pkg: github.com/rclone/rclone
eco: go
published: Aug 5, 2026
## Summary

The local backend relies on its configurable filename encoder to prevent remote filename data from becoming operating-system path syntax. If a local destination uses an encoding that omits `Dot`, such as `Slash`, `None`, or `Raw`, a remote object's standard-encoded `..` component is …

CVE-2026-71313
NVD

MEDIUM
CVE-2026-70611
CVE-2026-70611
pkg: windows

published: Aug 5, 2026

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.1, and 42.0.0-beta.3, the DevTools reveal in file manager action could launch the target file rather than reveal it. An attacker with a separate means of running scri…
CWE: CWE-78
GitHub-GHSA

MEDIUM
Electron: DevTools embedder handler executes arbitrary files via shell open
GHSA-f2r8-jv7c-xqmp
pkg: electron, electron, electron
eco: npm
published: Aug 5, 2026
### Impact
The DevTools "reveal in file manager" action could launch the target file rather than reveal it. An attacker with a separate means of running script inside the DevTools frontend (such as a malicious DevTools extension) could use this to execute native code outside the sandbox.

Apps are o…

CVE-2026-70611
NVD

MEDIUM
CVE-2026-19017
CVE-2026-19017
pkg: jwt

published: Aug 7, 2026

Consul Community Edition and Consul Enterprise 1.18.21 through 2.0.2 are vulnerable to a partial arbitrary file read when configured to use the Vault Connect CA provider with JWT or AppRole authentication. A privileged attacker with `operator:write` permission may direct Consul to read and forward c…
CWE: CWE-862
GitHub-GHSA

MEDIUM
AWS CLI: Disabled SSH host key verification in Amazon AWS CLI EMR helper commands
GHSA-hqvf-45jj-mccq
pkg: awscli
eco: pip
published: Aug 6, 2026
### Summary
The AWS Command Line Interface (AWS CLI) is a unified tool to manage AWS services from the command line. An issue exists where the EMR SSH helper commands (`aws emr ssh`, `aws emr socks`, `aws emr put`, `aws emr get`) passed `StrictHostKeyChecking=no` to the underlying SSH client, disabl…
CVE-2026-18654
NVD

MEDIUM
CVE-2026-70594
CVE-2026-70594
pkg: node

published: Aug 4, 2026

Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions on login which could have allowed for session fixation attacks. Successful exploitation would have required another vulnerability on the same domain where Ghost Admin was hosted. T…
CWE: CWE-384
GitHub-GHSA

MEDIUM
Ghost: Session Fixation in Ghost Admin
GHSA-7mpp-r37j-x5wh
pkg: ghost
eco: npm
published: Aug 4, 2026
### Impact

Ghost Admin did not invalidate existing sessions on login which could have allowed for session fixation attacks. Successful exploitation would have required another vulnerability on the same domain where Ghost Admin was hosted.

### Vulnerable versions

This vulnerability is present in G…

CVE-2026-70594
NVD

MEDIUM
CVE-2026-70602
CVE-2026-70602
pkg: windows

published: Aug 5, 2026

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, extension tab and scripting APIs were not scoped to the extension's own session. A malicious or compromised extension loaded into one session co…
CWE: CWE-284
GitHub-GHSA

MEDIUM
Electron: Extension tab APIs operate across session boundaries
GHSA-m55f-7gqj-fr98
pkg: electron, electron, electron
eco: npm
published: Aug 5, 2026
### Impact
Extension tab and scripting APIs were not scoped to the extension's own `session`. A malicious or compromised extension loaded into one session could navigate, script, and read from windows belonging to a different session.

Apps are only affected if they load Chrome extensions via `sessi…

CVE-2026-70602
NVD

MEDIUM
CVE-2026-70593
CVE-2026-70593
pkg: node

published: Aug 4, 2026

Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a vulnerability in custom themes allowed a staff user to write files outside of the uploads directory. This could be used to alter the behavior of the installation through custom theme upload path traversal in LocalStorageBase a…
CWE: CWE-22
GitHub-GHSA

MEDIUM
Ghost: Theme Upload Path Traversal
GHSA-cjc9-q5gf-327p
pkg: ghost
eco: npm
published: Aug 4, 2026
### Impact

A vulnerability in custom themes allowed a staff user to write files outside of the uploads directory. This could be used to alter the behavior of the installation.

### Vulnerable versions

This vulnerability is present in Ghost from v0.10.0 up to v6.54.0.

### Patches

v6.54.1 contains…

CVE-2026-70593
NVD

MEDIUM
CVE-2026-47619
CVE-2026-47619
pkg: nvidia dynamo, linux linux_kernel

published: Aug 4, 2026

NVIDIA Dynamo for Linux examples and recipes contain a vulnerability where an attacker could cause a system failure. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.
CWE: CWE-1357
GitHub-GHSA

MEDIUM
Netty: RedisArrayAggregator max-elements failure leaves retained partial aggregate state
GHSA-p9jm-q85p-7mcp
pkg: io.netty:netty-codec-redis, io.netty:netty-codec-redis
eco: maven
published: Aug 7, 2026
## Summary

`RedisArrayAggregator` clears retained partial aggregate state when the `maxNestedArrayDepth` limit is exceeded, but it does not clear the same state when the sibling `maxElements` limit is exceeded. A peer can start a valid RESP array, send a bulk-string child, then send a nested array …

CVE-2026-56818
GitHub-GHSA

MEDIUM
GitPython: Arbitrary file read via –pathspec-from-file in IndexFile.remove() and Head.checkout()
GHSA-hh9p-6wh2-4mfc
pkg: GitPython
eco: pip
published: Aug 7, 2026
## Summary

`IndexFile.remove()` and `Head.checkout()` forward `**kwargs` into `git rm` and `git checkout`
with no guard. Passing `–pathspec-from-file=<file>` **together with `–pathspec-file-nul`**
makes Git treat the whole file as a single NUL-delimited pathspec, and the unmatched-pathspec
error …

NVD

MEDIUM
CVE-2026-14204
CVE-2026-14204
pkg: go

published: Aug 6, 2026

The Google Authenticator WordPress plugin before 0.56 does not verify a CSRF nonce when saving its two-factor setup, allowing attackers to trick a logged-in user into overwriting their own 2FA secret with an attacker-controlled value, which enables two-factor authentication and locks the victim out …
CWE: CWE-352
GitHub-GHSA

MEDIUM
rclone: Path traversal in serve s3 allows reading and overwriting root-level files
GHSA-8v25-v8p6-qf7v
pkg: github.com/rclone/rclone
eco: go
published: Aug 5, 2026
### Summary

rclone serve s3 allows a client to read and write files at the root of the remote which would normally be inaccessible by using dot-dot path segments in the object key. It does not allow reading files outside of the root. A request such as GET /bucket/../root-secret.txt is handled as an…

NVD

MEDIUM
CVE-2026-70616
CVE-2026-70616
pkg: go

published: Aug 5, 2026

boringproxy through 0.10.0 contains a resource exhaustion vulnerability that allows any authenticated user to permanently exhaust server file descriptors, goroutines, and memory by sending requests to the GET /loading endpoint with attacker-supplied id query parameter values. Because the handler per…
CWE: CWE-833
NVD

MEDIUM
CVE-2026-7658
CVE-2026-7658
pkg: langflow langflow

published: Aug 5, 2026

IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate the username field, allowing attackers to inject path traversal sequences and bypass containment checks. This enables multiple severe impacts, including arbitrary directory deletion, cross-tenant data destruction, and JWT signing key d…
CWE: CWE-22
NVD

MEDIUM
CVE-2026-7646
CVE-2026-7646
pkg: langflow langflow

published: Aug 5, 2026

IBM Langflow OSS 1.0.0 through 1.10.3 allows users to read arbitrary files from the server filesystem, including other users' uploaded documents, the JWT signing secret, the SQLite database, and process environment variables, by sending a crafted MCP `resources/read` request with a URL-encoded path …
CWE: CWE-22
NVD

MEDIUM
CVE-2026-71244
CVE-2026-71244
pkg: oauth

published: Aug 5, 2026

Paperless-ngx's MailAccountViewSet.test() action, when called with an existing account's ID and a masked password field, reuses the stored password, account_type, refresh_token, and expiration from that existing account while allowing the caller to supply a different imap_server, imap_port, and imap…
CWE: CWE-918
NVD

MEDIUM
CVE-2026-71208
CVE-2026-71208
pkg: kubernetes

published: Aug 5, 2026

KubeSphere's cluster-controller reconciliation (pkg/utils/clusterclient/clusterclient.go, addCluster) processes every Cluster custom resource's connection configuration and immediately calls Discovery().ServerVersion() against the CRD-specified Kubernetes API endpoint, which is parsed only for URL s…
CWE: CWE-918
NVD

MEDIUM
CVE-2026-68080
CVE-2026-68080
pkg: apache qpid_broker-j

published: Aug 5, 2026

It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.

This issue affects Apache Qpid Broker-J: through 10.0.1.

Users are recommended to upgrade to version 10.1.…

CWE: CWE-406
NVD

MEDIUM
CVE-2026-68078
CVE-2026-68078
pkg: apache qpid_broker-j

published: Aug 5, 2026

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.

This issue affects Apache Qpid Broker-J: through 10.0.1.

Users are recommended to upgrade to version 10.1…

CWE: CWE-770
NVD

MEDIUM
CVE-2026-67555
CVE-2026-67555
pkg: apache qpid_proton-dotnet

published: Aug 5, 2026

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service

This issue affects Apache Qpid Proton-Dotnet: through 1.0.0.

Users are recommended to upgrade to version 1…

CWE: CWE-770
NVD

MEDIUM
CVE-2026-66277
CVE-2026-66277
pkg: apache qpid_proton-j

published: Aug 5, 2026

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.

This issue affects Apache Qpid Proton-J: through 0.34.1.

Users are recommended to upgrade to version 0.35…

CWE: CWE-770
NVD

MEDIUM
CVE-2026-70493
CVE-2026-70493
pkg: python

published: Aug 4, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the built-in knowledge search path in backend/open_webui/tools/knowledge_fs.py and backend/open_webui/tools/builtin.py let a chat participant choose a pattern used to grep knowledge files. …
CWE: CWE-1333
NVD

MEDIUM
CVE-2026-70491
CVE-2026-70491
pkg: python

published: Aug 4, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. In 0.10.2 and earlier, the GET /api/v1/tools/, GET /api/v1/tools/list, and GET /api/v1/tools/id/{id} endpoints in backend/open_webui/routers/tools.py returned full Python tool source to authenticated non-admin read…
CWE: CWE-200
GitHub-GHSA

MEDIUM
Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically
GHSA-2f54-p244-32q6
pkg: open-webui
eco: pip
published: Aug 4, 2026
## Summary
The built-in knowledge search tools let a chat participant choose the pattern used to grep knowledge files. Patterns containing regex metacharacters were compiled with Python's backtracking `re` engine and run against every line of every reachable file, with no time limit anywhere on that…
CVE-2026-70493
GitHub-GHSA

MEDIUM
Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints
GHSA-3r7g-q6cg-q2vx
pkg: open-webui
eco: pip
published: Aug 4, 2026
## Summary

A workspace tool shared with a read grant returned its full Python source to the recipient. Any authenticated non-admin who could use a shared tool could also read its source, including any user on the instance when a tool was shared publicly. Source is meant to be a writer-only tier: th…

CVE-2026-70491
GitHub-GHSA

MEDIUM
Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing
GHSA-73cq-mcgh-379c
pkg: open-webui
eco: pip
published: Aug 4, 2026
## Summary
In every affected release, automation recurrence parsing anchors minutely and hourly rules at a fixed date of 2000-01-01 and then walks forward one interval at a time to find the next run. A single `FREQ=MINUTELY` rule therefore enumerates roughly a quarter-century of occurrences, synchro…
CVE-2026-70489
NVD

MEDIUM
CVE-2026-47621
CVE-2026-47621
pkg: nvidia dynamo, linux linux_kernel

published: Aug 4, 2026

NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager singleton initialization. A successful exploit of this vulnerability might lead to denial of service and data tampering.
CWE: CWE-367
NVD

MEDIUM
CVE-2026-47620
CVE-2026-47620
pkg: nvidia dynamo, linux linux_kernel

published: Aug 4, 2026

NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager singleton initialization. A successful exploit of this vulnerability might lead to data tampering and denial of service.
CWE: CWE-362
GitHub-GHSA

MEDIUM
Flowise: Incomplete Credential Redaction Exposes Secrets via API
GHSA-rwrp-9823-p2xq
pkg: flowise
eco: npm
published: Aug 4, 2026
## Summary

The `GET /api/v1/credentials/:id` endpoint decrypts stored credential data and returns it in the `plainDataObj` field of the API response. While a `redactCredentialWithPasswordType()` function masks fields defined with `type: 'password'` in their component schema, many credential types s…

NVD

MEDIUM
CVE-2026-67199
CVE-2026-67199
pkg: express

published: Aug 4, 2026

Perspective 5.0.0 contains a denial of service vulnerability that allows remote attackers to block the server event loop indefinitely by submitting a crafted expression containing unbounded for or while loop constructs in a TableMakeViewReq message. Attackers can embed an arbitrarily large iteration…
CWE: CWE-770
NVD

MEDIUM
CVE-2026-63248
CVE-2026-63248
pkg: eclipse milo

published: Aug 4, 2026

In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An anonymous client can enable diagnostics over a None/None endpoint without a certificate; with a trusted client application certificate over SignAndEncrypt, it can read security diagn…
CWE: CWE-862
NVD

MEDIUM
CVE-2026-69245
CVE-2026-69245
pkg: go

published: Aug 3, 2026

Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of a cookie Domain that cookie unless SetCookie::matchesDomain() recognizes the Domain as an IP literal or a numeric host, and the decision comes from the domain's own text, so two sp…
CWE: CWE-180, CWE-346, CWE-384
NVD

MEDIUM
CVE-2026-18655
CVE-2026-18655
pkg: oauth

published: Aug 3, 2026

Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before 2.0.24 may allow a remote unauthenticated actor (via prompt injection) to obtain Amazon MQ for RabbitMQ broker credentials or OAuth access tokens sent …
CWE: CWE-923
GitHub-GHSA

MEDIUM
GitPython: Incomplete unsafe_git_archive_options denylist omits –add-file / –add-virtual-file, enabling arbitrary file read via Repo.archive()
GHSA-539m-9xh6-q6rr
pkg: GitPython
eco: pip
published: Aug 3, 2026
**Target:** gitpython-developers/GitPython
**Tested:** HEAD `07e80555` (2026-07-25), latest release 3.1.55, `git version 2.50.1`

## Summary

`Repo.archive()` does call the option guard, so this is not a missing-guard report. The guard is present and working; the **denylist it consults is incomplete…

GitHub-GHSA

MEDIUM
Russh: Channel-scoped server callbacks can be reached without an open channel
GHSA-m65r-rprj-r5rg
pkg: russh
eco: rust
published: Aug 3, 2026
There is a server-side channel state issue in `russh`.

After a client is authenticated, `russh` can dispatch channel-scoped handler callbacks for recipient channel IDs that were never opened or confirmed. In the strongest reproduced case, the client does not send `SSH_MSG_CHANNEL_OPEN` at all. It a…

CVE-2026-68930
NVD

MEDIUM
CVE-2026-69087
CVE-2026-69087
pkg: express

published: Aug 3, 2026

The Grav form plugin (getgrav/grav-plugin-form) before 9.1.13 contains an open redirect vulnerability. Since v9.1.11, the redirect process action evaluates user-supplied form data inside Twig expressions, and Grav::redirect() accepts external URLs without origin validation. When a form blueprint def…
CWE: CWE-601
GitHub-GHSA

MEDIUM
rclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Preserves Newlines
GHSA-8c48-q9wj-3w37
pkg: github.com/rclone/rclone
eco: go
published: Aug 5, 2026
## 1. Summary

A valid but nondefault FTP filename encoding can restore raw CR/LF immediately before an attacker-controlled path is interpolated into the line-oriented FTP control channel. The dependency does not reject CR or LF in command arguments, so a filename can inject an independent authentic…

CVE-2026-71311
NVD

MEDIUM
CVE-2026-19243
CVE-2026-19243
pkg: react

published: Aug 7, 2026

A security vulnerability has been detected in HKUDS nanobot up to 0.2.1. Impacted is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component Shell Allowlist Handler. Such manipulation leads to os command injection. The attack can be executed rem…
CWE: CWE-77, CWE-78
NVD

MEDIUM
CVE-2026-47363
CVE-2026-47363
pkg: oauth

published: Aug 7, 2026

In versions of the Datadog Android application prior to v541-5.9.2, the exported launcher activity AppActivity accepts an attacker-supplied session (including OAuth tokens) from Intent extras with no permission guard, and signs the app into that session without validating it against the backend.
Th…
CWE: CWE-926
GitHub-GHSA

MEDIUM
go-git: Malicious reference names may modify files outside the reference storage
GHSA-qgq7-7hm3-q39j
pkg: github.com/go-git/go-git/v5, github.com/go-git/go-git/v6
eco: go
published: Aug 7, 2026
### Impact
A path traversal issue in `go-git` could allow malicious reference names to access files outside the repository's intended reference storage.

Loose references are stored under `.git/<reference-name>`. The reference name was previously used as a path without verifying that the resolved pa…

CVE-2026-71557
NVD

MEDIUM
CVE-2026-19022
CVE-2026-19022
pkg: go

published: Aug 6, 2026

A vulnerability was determined in OpenHands up to 0.62.0. The affected element is the function initialize_repo of the file OpenHands/resolver/send_pull_request.py. This manipulation causes command injection. Remote exploitation of the attack is possible. The vendor deleted the original GitHub issue …
CWE: CWE-74, CWE-77
NVD

MEDIUM
CVE-2026-70597
CVE-2026-70597
pkg: node

published: Aug 5, 2026

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, the check Electron uses on macOS to confirm it was launched by a same-signed parent process could be bypassed by a local process. Apps that enab…
CWE: CWE-367
GitHub-GHSA

MEDIUM
Electron: Parent process code-sign check is spoofable
GHSA-jm7p-cc5g-qwxx
pkg: electron, electron, electron
eco: npm
published: Aug 5, 2026
### Impact
On macOS, the check Electron uses to confirm it was launched by a same-signed parent process could be bypassed by a local process. Apps that enable the fuse-based hardening restricting `ELECTRON_RUN_AS_NODE` and `NODE_OPTIONS` to same-signed parents rely on this check; a local attacker co…
CVE-2026-70597
NVD

MEDIUM
CVE-2026-70490
CVE-2026-70490
pkg: jwt

published: Aug 4, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, the terminal WebSocket route in backend/open_webui/routers/terminals.py authenticated its own first-message JWT and never applied the verified-user role gate that get_verified_user enforces…
CWE: CWE-863
NVD

MEDIUM
CVE-2026-54020
CVE-2026-54020
pkg: oauth

published: Aug 4, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.11.0, Open WebUI resolved a hostname during URL validation and rejected private, loopback, and link-local addresses, but the HTTP clients resolved the hostname again at connection time. An authenticated …
CWE: CWE-367, CWE-918
GitHub-GHSA

MEDIUM
Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check
GHSA-5gpj-vj23-vhhv
pkg: open-webui
eco: pip
published: Aug 4, 2026
## Summary
The terminal WebSocket route authenticates its own first-message JWT instead of going through the HTTP dependency chain, and never applies the role check that `get_verified_user` enforces on every HTTP terminal route. An account whose role is `pending`, meaning registered but not approved…
CVE-2026-70490
GitHub-GHSA

MEDIUM
Open WebUI: DNS Rebinding SSRF Bypass
GHSA-h6x2-583h-x99r
pkg: open-webui
eco: pip
published: Aug 4, 2026
## Summary
Open WebUI vetted user-supplied URLs by resolving the hostname once and rejecting private, loopback and link-local addresses, then let the HTTP client resolve that hostname again at connect time. An attacker who controls the authoritative DNS for a hostname they submit can answer with a p…
CVE-2026-54020
NVD

MEDIUM
CVE-2026-71430
CVE-2026-71430
pkg: express

published: Aug 6, 2026

node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.25.1, the WrappedRE2::Replace function built its replacement result and passed it to V8 using ToLocalChecked without checking for the empty MaybeLocal that V8 returns when the resulting string or buffer exceeds V8's ma…
CWE: CWE-617
GitHub-GHSA

MEDIUM
node-re2: String.prototype.replace(re2, template) aborts the Node process (uncatchable ToLocalChecked on empty MaybeLocal) when the result exceeds V8's max string length
GHSA-8hcv-x26h-mcgp
pkg: re2
eco: npm
published: Aug 6, 2026
## Description

`WrappedRE2::Replace` builds the replacement result and hands it to V8 with `.ToLocalChecked()` **without checking for the empty `MaybeLocal`** that V8 returns when the string/buffer exceeds its maximum length:

`lib/replace.cc` (v1.24.1):
“`cpp
// L553 — Buffer return path
info.G…

CVE-2026-71430
NVD

MEDIUM
CVE-2026-58045
CVE-2026-58045
pkg: node

published: Aug 4, 2026

A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion in the synchronous `node:zlib` APIs, causing the entire process to crash. All 11 synchronous zlib functions are affected.

Repeated exploitation of this condition can result in a denial of service.

Thi…

CWE: CWE-400
NVD

MEDIUM
CVE-2026-71286
CVE-2026-71286
pkg: express

published: Aug 5, 2026

The render-template component of ember-dynamic-render-template (addon/components/render-template.js) passes its `templateString` property directly into Ember/Glimmer's compileTemplate() (from @ember/template-compilation) with no sanitization, allow-listing, or validation of the input. Because compil…
CWE: CWE-1336
NVD

MEDIUM
CVE-2026-16792
CVE-2026-16792
pkg: tls

published: Aug 4, 2026

An improper certificate validation vulnerability was reported in multiple Lenovo XClarity Orchestrator (LXCO) 2.2.0 microservices that could allow an adjacent network attacker to intercept sensitive communications by performing a machine-in-the-middle attack against HTTPS connections during TLS cert…
CWE: CWE-295
GitHub-GHSA

MEDIUM
Electron: shell.openPath path validation bypass via embedded null byte
GHSA-5c9j-mhmv-5xgx
pkg: electron, electron, electron
eco: npm
published: Aug 5, 2026
### Impact
`shell.openPath()` did not reject paths containing embedded null bytes. Apps that perform string-only validation of file paths (for example, checking the file extension) before passing them to `shell.openPath()` could be bypassed, allowing an attacker-controlled path to open a different f…
CVE-2026-70603
GitHub-GHSA

MEDIUM
rclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone Memory
GHSA-xhf4-832v-7xcr
pkg: github.com/rclone/rclone
eco: go
published: Aug 5, 2026
## 1. Summary

The shared HTTP CONNECT helper parses a proxy response with `http.ReadResponse` over an unrestricted buffered reader. The production helper accepted a valid response containing a 2 MiB header in three consecutive runs. A malicious or compromised configured proxy, or an active on-path …

CVE-2026-71310
GitHub-GHSA

MEDIUM
Electron: ProtocolResponse.url reuses the default session cache instead of the registering session
GHSA-r4w5-6pfg-jxp5
pkg: electron, electron, electron
eco: npm
published: Aug 5, 2026
### Impact
When a custom protocol handler returned a `ProtocolResponse` with a `url` and no `session`, Electron made the upstream request through `defaultSession` instead of the session that handled the protocol. A cached response could then be reused across otherwise isolated session partitions.

A…

CVE-2026-70606
GitHub-GHSA

MEDIUM
Electron: HTTP redirect followed into local file loader
GHSA-v64r-4m7r-3mvq
pkg: electron, electron, electron
eco: npm
published: Aug 5, 2026
### Impact
When following HTTP redirects, `net.fetch()` and `net.request()` did not restrict which schemes a redirect could target. A remote server could redirect a request to a local resource, and if the app returns or forwards the response body, local file contents could be disclosed.

Apps are on…

CVE-2026-70605
GitHub-GHSA

MEDIUM
Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin
GHSA-9pf5-hg6p-4pwp
pkg: electron, electron, electron
eco: npm
published: Aug 5, 2026
### Impact
For serial-port and media (camera / microphone) permission checks made from an iframe, the `requestingOrigin` passed to `session.setPermissionCheckHandler` was the top-level frame's origin rather than the requesting frame's. Origin-based handler logic could therefore grant a cross-origin …
CVE-2026-70599
NVD

MEDIUM
CVE-2026-48154
CVE-2026-48154
pkg: go

published: Aug 4, 2026

GoRest is a Golang starter kit built with the Gin framework for prototyping and developing RESTful APIs. In versions prior to 1.12.2 nMemorySecret2FA contains a race condition due to an unsynchronized package-level map used to store 2FA secrets. Multiple HTTP handlers in handler/login.go and handler…
CWE: CWE-362
NVD

MEDIUM
CVE-2026-58042
CVE-2026-58042
pkg: node

published: Aug 4, 2026

A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process When a DNS Response Contains More Than 256 A Records.

Repeated triggering of this condition can lead to denial of service.

This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.

CWE: CWE-400
GitHub-GHSA

MEDIUM
undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives
GHSA-jr45-8vmc-qm54
pkg: undici, undici
eco: npm
published: Aug 3, 2026
## Impact

Undici's cache interceptor mishandles optional whitespace (OWS) placed around the `=` of a qualified `no-cache` or `private` Cache-Control directive, such as `no-cache ="authorization"` (OWS before `=`) or `no-cache= "authorization"` (OWS after `=`). The parser either drops the directive …

CVE-2026-14643
GitHub-GHSA

MEDIUM
Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false
GHSA-3q9r-p662-5j8m
pkg: github.com/traefik/traefik/v2, github.com/traefik/traefik/v3, github.com/traefik/traefik/v3
eco: go
published: Aug 6, 2026
## Summary

There is a medium severity vulnerability in Traefik's ForwardAuth middleware. Even when configured with `trustForwardHeader: false`, Traefik derives the `X-Forwarded-Port` header sent to the authentication service from the original incoming request instead of the sanitized forwarded requ…

CVE-2026-54764
GitHub-GHSA

MEDIUM
Ghost: Private IP filtering bypass to make server-side requests to internal services
GHSA-wvp2-4qqp-4h3r
pkg: ghost
eco: npm
published: Aug 4, 2026
### Impact

When making an external request, it is possible to bypass the IP filter that ensures the request isn't going to an internal service using an IPv6 literal which maps to a private IPv4 address.

### Vulnerable versions

This vulnerability is present in Ghost from v6.0.9 up to v6.21.0.

###…

CVE-2026-53944
NVD

MEDIUM
CVE-2026-70609
CVE-2026-70609
pkg: node

published: Aug 5, 2026

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1, the mode option of webContents.openDevTools() was not sanitized before use by the DevTools frontend. If an attacker can influence this value, sc…
CWE: CWE-94, CWE-116
GitHub-GHSA

MEDIUM
Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter
GHSA-4f78-qhmw-8j8m
pkg: electron, electron, electron
eco: npm
published: Aug 5, 2026
### Impact
The `mode` option of `webContents.openDevTools()` was not sanitized before use by the DevTools frontend. If an attacker can influence this value, script under their control may run in the DevTools context, which in unsandboxed configurations has access to Node.js.

Apps are only affected …

CVE-2026-70609
NVD

MEDIUM
CVE-2026-70592
CVE-2026-70592
pkg: node

published: Aug 4, 2026

Ghost is a Node.js content management system. From 1.20.1 until 6.54.1, an Administrator-level user could remotely overwrite certain files on the filesystem through the database backup filename, leading to integrity and availability issues. The database export endpoint failed to reject path separato…
CWE: CWE-22
GitHub-GHSA

MEDIUM
Ghost: Database Backup Path Traversal
GHSA-cj62-hvv2-2q5h
pkg: ghost
eco: npm
published: Aug 4, 2026
### Impact

An Administrator-level user could remotely overwrite certain files on the filesystem leading to integrity and availability issues.

### Vulnerable versions

This vulnerability is present in Ghost from 1.20.1 up to v6.54.0.

### Patches

v6.54.1 contains a fix for this issue.

### How to …

CVE-2026-70592
GitHub-GHSA

MEDIUM
Electron: Sandboxed iframes can launch external protocol handlers
GHSA-p2rr-rvmm-c5fp
pkg: electron, electron, electron
eco: npm
published: Aug 5, 2026
### Impact
Requests to open external protocol URLs from web content did not take iframe sandbox restrictions into account, so a sandboxed iframe could cause an OS-registered external application to be launched. The frame's sandbox state was also not made available to the app's permission handlers.

CVE-2026-70612
GitHub-GHSA

MEDIUM
Electron: contextBridge object copy honors prototype setters
GHSA-ff2p-hmqr-hxm4
pkg: electron, electron, electron
eco: npm
published: Aug 5, 2026
### Impact
Objects copied across the `contextBridge` boundary from untrusted content could carry an attacker-influenced prototype, enabling prototype-pollution-style attacks against preload code despite context isolation being enabled.

Apps are only affected if their preload code accepts object arg…

CVE-2026-70610
GitHub-GHSA

MEDIUM
Ghost: Mobiledoc image-size fetch SSRF
GHSA-g366-23fw-ggp6
pkg: ghost
eco: npm
published: Aug 4, 2026
### Impact

When re-rendering posts, Ghost would refetch missing image dimensions by issuing an outbound HTTP request to the URL stored on an image card — without restricting that URL to trusted image hosts. An authenticated staff user able to create or edit posts could therefore point an image ca…

CVE-2026-53946
GitHub-GHSA

MEDIUM
Ghost: File Upload Content-Type Spoofing
GHSA-944x-pm95-3jpr
pkg: ghost
eco: npm
published: Aug 4, 2026
### Impact

Insufficient validation of the client-supplied `Content-Type` on Ghost's Admin API file upload endpoint allowed uploaded files to be served from the site with an attacker-chosen content type on S3/GCS storage backends. On installations that serve uploaded files from the same origin as th…

CVE-2026-53948
GitHub-GHSA

MEDIUM
Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages
GHSA-mj5r-jf49-m3w7
pkg: open-webui
eco: pip
published: Aug 4, 2026
## Summary
On standard channels, the message update and delete handlers accepted any caller holding write access on the channel, without checking that the caller wrote the message. Write access is the same grant a member needs in order to post, so every ordinary participant in a shared channel could…
CVE-2026-70481
GitHub-GHSA

MEDIUM
GitPython: Arbitrary file truncation via git rev-list –output argument injection in unguarded Commit.count
GHSA-p538-c434-8v24
pkg: GitPython
eco: pip
published: Aug 3, 2026
## Summary
`Commit.count()` forwards `**kwargs` into `rev_list` with **no** `check_unsafe_options` guard (the guard exists only in the sibling `iter_items`, commit.py:341). `git rev-list –output=<path>` opens and truncates the target file to 0 bytes before revision parsing, so `count(output='/victi…
NVD

MEDIUM
CVE-2026-19369
CVE-2026-19369
pkg: axios

published: Aug 9, 2026

A vulnerability was found in KS-GEN-AI jira-mcp-server 0.2.0. This affects the function axios.get of the file src/index.ts of the component add_attachment_from_public_url. The manipulation of the argument imageUrl results in server-side request forgery. The attack requires a local approach. The proj…
CWE: CWE-918
NVD

MEDIUM
CVE-2026-19363
CVE-2026-19363
pkg: jwt

published: Aug 9, 2026

A vulnerability was found in lmammino oidc-authorizer up to 0.4.0. Impacted is the function unwrap of the file src/handler.rs of the component Fixed Message Handler. The manipulation of the argument jwtClaims results in deserialization. The attack can be executed remotely. The exploit has been made …
CWE: CWE-20, CWE-502
NVD

MEDIUM
CVE-2026-19323
CVE-2026-19323
pkg: react

published: Aug 9, 2026

A security flaw has been discovered in azer react-analyzer-mcp up to 335f2a3585f265e2e88352b59b10d3b478d678b0. Affected by this vulnerability is the function generateProjectDocs of the file src/index.ts of the component analyze-projec. The manipulation of the argument projectName results in path tra…
CWE: CWE-22
NVD

MEDIUM
CVE-2026-69207
CVE-2026-69207
pkg: express

published: Aug 7, 2026

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.34, the built-in CORS middleware, hono/cors, is vulnerable to a regular expression denial of service (ReDoS). During a preflight OPTIONS request, the middleware parses the attacker-controlled Access-C…
CWE: CWE-1333
GitHub-GHSA

MEDIUM
Hono: Algorithmic Complexity DoS in Language Middleware
GHSA-54fx-42gc-7vw4
pkg: hono
eco: npm
published: Aug 7, 2026
### Summary

The `languageDetector` middleware is vulnerable to algorithmic complexity denial of service when processing a crafted language tag containing a large number of hyphen-separated subtags.

### Details

To implement progressive language-tag truncation, `normalizeLanguage()` repeatedly call…

CVE-2026-71848
NVD

MEDIUM
CVE-2026-66062
CVE-2026-66062
pkg: express

published: Aug 7, 2026

SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.70.2, the content negotiation header parser used by SvelteKit's request handling (for headers such as Accept) uses a regular expression vulnerable to quadratic backtracking, so a maliciously …
CWE: CWE-1333
GitHub-GHSA

MEDIUM
SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept header
GHSA-29g2-3rmr-qm68
pkg: @sveltejs/kit
eco: npm
published: Aug 7, 2026
### Impact
SvelteKit is vulnerable to remote CPU-exhaustion DoS attacks via specifically-crafted `Accept` headers. The impact is mitigated by default header length limits on most platforms, but in the case of raised or absent limits a denial of service is possible.

### Patches
The vulnerability is …

CVE-2026-66062
NVD

MEDIUM
CVE-2026-49006
CVE-2026-49006
pkg: tls

published: Aug 7, 2026

By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to TLS transmission.
CWE: CWE-321
NVD

MEDIUM
CVE-2026-61632
CVE-2026-61632
pkg: python

published: Aug 6, 2026

PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. In versions up to and including 10.21.3, the b64 extension is vulnerable to a path traversal that discloses arbitrary files: it inlines images referenced by <img src="…"> by joining the src onto the configured base…
CWE: CWE-22
NVD

MEDIUM
CVE-2026-19146
CVE-2026-19146
pkg: google chrome, google android

published: Aug 6, 2026

Uninitialized Use in GPU in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-457
GitHub-GHSA

MEDIUM
h2: Duplicate Host header could facilitate request smuggling
GHSA-6hr6-w5qg-qmwg
pkg: h2
eco: pip
published: Aug 6, 2026
### Impact
h2 <=4.4.0 accepts request header blocks containing more than one Host header, and forwards every Host header to the consuming application. Where the consumer downgrades HTTP/2 to HTTP/1.1, the resulting request carries two Host header lines, which is a request smuggling primitive (CWE-44…
CVE-2026-71554
GitHub-GHSA

MEDIUM
LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores
GHSA-47pj-3jcm-6whg
pkg: langgraph-checkpoint-postgres, langgraph-checkpoint-sqlite
eco: pip
published: Aug 6, 2026
## Summary

The Postgres and SQLite stores persist hierarchical namespaces as a dot-joined string (`("memories", "alice")` becomes `memories.alice`) and scoped reads by matching that string with `LIKE '<path>%'`. Because `LIKE` has no notion of the `.` separator, a scoped `search` or `list_namespace…

CVE-2026-71433
NVD

MEDIUM
CVE-2026-19044
CVE-2026-19044
pkg: go

published: Aug 6, 2026

A flaw has been found in LeeSinLiang godot-mcp 0.1.0. Affected by this vulnerability is the function executeOperation of the file src/index.ts of the component create_scene/add_node. This manipulation of the argument projectPath causes command injection. The attack needs to be launched locally. The …
CWE: CWE-74, CWE-77
GitHub-GHSA

MEDIUM
rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect
GHSA-h4mf-4v27-hggj
pkg: github.com/rclone/rclone
eco: go
published: Aug 5, 2026
## 1. Summary

WebDAV's default redirect handling can replay Basic authorization and configured Cookie headers over plaintext HTTP after a same-host HTTPS-to-HTTP redirect. This was reproduced through the real backend. Unlike the low-impact STS token in rclone's published S3 redirect advisory, Basic…

GitHub-GHSA

MEDIUM
rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys
GHSA-8mxv-9xhp-86h4
pkg: github.com/rclone/rclone
eco: go
published: Aug 5, 2026
## 1. Summary

The S3 redirect callback strips `X-Amz-Security-Token` when a redirect changes scheme or host, but it does not strip IBM IAM bearer authorization or customer-provided encryption keys. Two independently validated paths remain:

– a same-host HTTPS-to-HTTP redirect preserves `Authorizat…

GitHub-GHSA

MEDIUM
rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic
GHSA-3x6r-wxxg-53vv
pkg: github.com/rclone/rclone
eco: go
published: Aug 5, 2026
## 1. Summary

A transport failure during the initial Infinite Scale TUS creation POST can return `(nil response, non-nil error)`. Rclone dereferences the nil response before processing the error and panics. The production `CreateUploader` path reproduced the crash against a closed endpoint.

The se…

GitHub-GHSA

MEDIUM
Electron: window.open features string controls some window options considered privileged
GHSA-v93f-fgjr-hjrj
pkg: electron, electron, electron
eco: npm
published: Aug 5, 2026
### Impact
Some window options supplied by web content in the `window.open()` features string were applied to the new `BrowserWindow` without an allowlist. Untrusted content could set window options it should not control, including options that cause the main process to access attacker-chosen file o…
CVE-2026-70607
GitHub-GHSA

MEDIUM
Ghost Content API filter bypass reveals private fields
GHSA-jx35-x7fj-vgpr
pkg: ghost
eco: npm
published: Aug 5, 2026
### Impact

The validation applied to filters on the public API endpoints could be partially bypassed, making it possible to reveal private fields via a brute force attack. If SQLite was used as the database password hashes were fully accessible. If MySQL was used as the database the password hashes…

CVE-2026-53949
GitHub-GHSA

MEDIUM
Ghost: Paid gift memberships obtainable at minimal cost via the donations feature
GHSA-xm43-3m56-w3wf
pkg: ghost
eco: npm
published: Aug 4, 2026
### Impact

A vulnerability in Ghost's public donation checkout flow allowed an unauthenticated attacker to obtain full paid gift memberships for a minimal payment. No customer or member data was exposed, and the issue could not be used to steal money from a site or its members.

### Vulnerable vers…

CVE-2026-59817
GitHub-GHSA

MEDIUM
Ghost: Member existence leak via magic link sign-in response
GHSA-chgm-3698-jm42
pkg: ghost
eco: npm
published: Aug 4, 2026
### Impact

A discrepancy in responses from the members signin endpoints made it possible for an unauthenticated attacker to determine whether a given email address belongs to a registered member of a Ghost site.

### Vulnerable versions

This vulnerability is present in Ghost from v5.18.0 up to v6.…

CVE-2026-53947
GitHub-GHSA

MEDIUM
Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadata
GHSA-6xhv-rxhv-pwm4
pkg: open-webui
eco: pip
published: Aug 4, 2026
## Summary
Open WebUI lets a client define a model inline on a chat request instead of selecting a saved workspace model. The knowledge attached to such an inline model was used as-is, without checking that the caller can read what it points at. Any authenticated user who knows another user's file i…
CVE-2026-70487
NVD

MEDIUM
CVE-2026-47622
CVE-2026-47622
pkg: nvidia dynamo, linux linux_kernel

published: Aug 4, 2026

NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause the generation of error messages that contain sensitive information. A successful exploit of this vulnerability might lead to information disclosure.
CWE: CWE-209
NVD

MEDIUM
CVE-2026-16536
CVE-2026-16536
pkg: go

published: Aug 4, 2026

The Simple Google Calendar Outlook Events Widget WordPress plugin before 3.1.0 does not validate a user-supplied URL before performing a server-side request, allowing unauthenticated attackers to perform Server-Side Request Forgery attacks and, in some cases, read the response of the internal reques…
CWE: CWE-918
NVD

MEDIUM
CVE-2026-58041
CVE-2026-58041
pkg: node

published: Aug 4, 2026

A flaw in Node.js node:sqlite allows a stale StatementSyncIterator created through DatabaseSync#createTagStore() to continue executing a cached prepared statement after it has been reset and rebound with new parameters. SQLTagStore resets cached statements using sqlite3_reset() directly, bypassing t…
CWE: CWE-367
NVD

MEDIUM
CVE-2026-18648
CVE-2026-18648
pkg: react

published: Aug 3, 2026

A vulnerability was detected in Blix Email Blue Mail Calendar App 2.2.305. Impacted is the function FileDirectory.getDataColumn/FileDirectory.getFileFromUri of the component react-native-receive-sharing-intent. The manipulation of the argument _display_name results in path traversal. The attack is o…
CWE: CWE-22
GitHub-GHSA

MEDIUM
Hono: ReDoS in CORS middleware via Access-Control-Request-Headers
GHSA-8j4g-w8fx-2239
pkg: hono
eco: npm
published: Aug 3, 2026
### Summary

The built-in CORS middleware (`hono/cors`) parses the attacker-controlled `Access-Control-Request-Headers` request header during a preflight (`OPTIONS`) request using a regular expression whose running time is quadratic in the input length. A single request carrying a long run of whites…

CVE-2026-69207
NVD

MEDIUM
CVE-2026-71498
CVE-2026-71498
pkg: express

published: Aug 6, 2026

node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.26.1, passing a Buffer whose final bytes form a truncated (incomplete) multi-byte UTF-8 sequence could cause the native binding to read past the end of the allocated buffer while attempting to decode the final, incompl…
CWE: CWE-125
GitHub-GHSA

MEDIUM
node-re2: Out-of-bounds heap read in `replace`/`split` via a `Buffer` ending in a truncated multi-byte UTF-8 character → adjacent heap memory disclosed to JavaScript
GHSA-j4r3-hg7j-8chg
pkg: re2
eco: npm
published: Aug 6, 2026
## Summary

`re2` infers a character's byte length from its UTF-8 lead byte alone, with no bound on the
bytes actually remaining in the input. `Buffer` arguments reach the native layer verbatim —
only strings are re-encoded into well-formed UTF-8 — so a `Buffer` whose last byte is a
multi-byte l…

CVE-2026-71498
GitHub-GHSA

MEDIUM
rclone archive extract allows S3 destination prefix escape via crafted archive paths
GHSA-4vr5-p2gc-h23p
pkg: github.com/rclone/rclone
eco: go
published: Aug 5, 2026
### Summary

`rclone archive extract` can write extracted files outside the user-selected destination prefix when extracting a crafted archive. A malicious archive entry containing parent path components such as `../` can escape the requested extraction prefix and create or overwrite sibling objects…

CVE-2026-59732
NVD

MEDIUM
CVE-2026-71201
CVE-2026-71201
pkg: node

published: Aug 5, 2026

In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assigned to Nodes owned or leased by another project.
CWE: CWE-863
NVD

MEDIUM
CVE-2026-70588
CVE-2026-70588
pkg: node

published: Aug 4, 2026

Ghost is a Node.js content management system. From 5.26.0 until 6.54.1, the Universal Import feature in Ghost Admin failed to properly sanitize imported content resulting in XSS in post content. This issue is fixed in version 6.54.1.
CWE: CWE-79
GitHub-GHSA

MEDIUM
Ghost: Cross-Site Scripting in Universal Import
GHSA-2gx6-7gx2-wwcf
pkg: ghost
eco: npm
published: Aug 4, 2026
### Impact

The Universal Import feature in Ghost Admin failed to properly sanitize imported content resulting in XSS in post content.

### Vulnerable versions

This vulnerability is present in Ghost from v5.26.0 up to v6.54.0.

### Patches

v6.54.1 contains a fix for this issue.

### How to update

CVE-2026-70588
GitHub-GHSA

MEDIUM
Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosure
GHSA-f23p-vx2j-j53r
pkg: hono
eco: npm
published: Aug 7, 2026
### Summary

`memo()` from `hono/jsx` retains the result of a server-side render and reuses it for later renders with comparator-equal props. Request-scoped values read inside the component take no part in that comparison, so a response can contain HTML rendered for another user's request.

### Deta…

CVE-2026-71850
NVD

MEDIUM
CVE-2026-71318
CVE-2026-71318
pkg: vue

published: Aug 5, 2026

Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an attacker can supply a top-level `as` prop to the /__nuxt_island/ endpoint and drive dynamic component resolution through <component :is>, resolveDynamicComponent, or h(). This issue is fixed in 3.21.1…
CWE: CWE-20
GitHub-GHSA

MEDIUM
Nuxt: Unauthorized Component Instantiation via Server Island Props
GHSA-48hr-524c-v5w3
pkg: nuxt, nuxt
eco: npm
published: Aug 5, 2026
## Impact

Nuxt server islands accept props via the `/__nuxt_island/` endpoint. When an application has a server island component that forwards props directly into Vue's dynamic component resolution (`<component :is>`, `resolveDynamicComponent`, or `h()`), an attacker can pass a plain string value (…

CVE-2026-71318
NVD

MEDIUM
CVE-2026-70590
CVE-2026-70590
pkg: node

published: Aug 4, 2026

Ghost is a Node.js content management system. Prior to 6.54.1, any staff-level user was able to leak the hashed passwords of other staff users through the Ghost Admin API. An offline password-guessing attack against the hashes could lead to account takeover if successful, but Device Verification sho…
CWE: CWE-200
NVD

MEDIUM
CVE-2026-70589
CVE-2026-70589
pkg: node

published: Aug 4, 2026

Ghost is a Node.js content management system. From 4.22.0 until 6.54.1, a missing validation check allowed users to redeem subscription offers that were no longer active. This issue is fixed in version 6.54.1.
CWE: CWE-20
GitHub-GHSA

MEDIUM
Ghost: Blind Password Hash Disclosure in Ghost Admin API
GHSA-jm22-3w23-5q7w
pkg: ghost
eco: npm
published: Aug 4, 2026
### Impact

Any staff-level user was able to leak the hashed passwords of other staff users. An offline password-guessing attack against the hashes could lead to account takeover if successful, but [Device Verification](https://docs.ghost.org/security#device-verification) should have prevented an at…

CVE-2026-70590
GitHub-GHSA

MEDIUM
Ghost: Archived Offers can be Redeemed
GHSA-4wx2-7gvj-qfq3
pkg: ghost
eco: npm
published: Aug 4, 2026
### Impact

A missing validation check allowed users to redeem subscription offers that were no longer active.

### Vulnerable versions

This vulnerability is present in Ghost from v4.22.0 up to v6.54.0.

### Patches

v6.54.1 contains a fix for this issue.

### How to update

For self-hosters using …

CVE-2026-70589
GitHub-GHSA

MEDIUM
undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields
GHSA-v3r7-h72x-cjcm
pkg: undici, undici, undici
eco: npm
published: Aug 3, 2026
## Impact

The `setCookie` function has two attribute injection paths. `validateCookieDomain` does not reject semicolons (`validateCookiePath` already does at 0x3B), so a `domain` value like `example.com; SameSite=None` lands verbatim as `Domain=example.com; SameSite=None`. The `unparsed` array's lo…

CVE-2026-16729
GitHub-GHSA

MEDIUM
undici vulnerable to downstream response desynchronization via retry interceptor
GHSA-8xcm-r25x-g524
pkg: undici, undici, undici
eco: npm
published: Aug 3, 2026
### Impact

Undici's `interceptors.retry()` can deliver a response whose body length does not match the `Content-Length` header exposed to the application after a retry or resume of a partial response. Applications that use `interceptors.retry()` and forward upstream response headers and bodies down…

CVE-2026-16728
NVD

MEDIUM
CVE-2026-56609
CVE-2026-56609
pkg: hcltech icontrol

published: Aug 3, 2026

HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using weak TLS versions such as TLS 1.0 and 1.1. These outdated protocols lack modern security features, making them vulnerable to known attacks and exposing sensitive information durin…
CWE: CWE-327
NVD

MEDIUM
CVE-2026-19244
CVE-2026-19244
pkg: react

published: Aug 7, 2026

A vulnerability was detected in HKUDS nanobot up to 0.2.1. The affected element is the function connect_mcp_servers of the file nanobot/agent/tools/mcp.py of the component MCP enabledTools Scope Handler. Performing a manipulation results in improper access controls. The attack is possible to be carr…
CWE: CWE-266, CWE-284
GitHub-GHSA

MEDIUM
jsoup: Cleaner may expose markup with custom raw-text elements
GHSA-pmhh-3w7g-xqp8
pkg: org.jsoup:jsoup
eco: maven
published: Aug 6, 2026
When a custom `Safelist` permits certain raw-text elements, jsoup may incorrectly sanitize malformed HTML containing a tag name that ends in a control character. The tag may acquire the parsing behavior of a different element, causing content that should remain text to be emitted as active markup af…
CVE-2026-71497
NVD

MEDIUM
CVE-2026-18909
CVE-2026-18909
pkg: windows

published: Aug 6, 2026

A stack-based buffer overflow vulnerability exists in ELAN Microelectronics Corp. ELAN Smart-Pad on Windows (ETD.sys and ETDSMBus.sys). During Intel SMBus recovery, ETDSMBus.sys does not enforce an upper-bound check on the hardware-derived report count, allowing an out-of-range value to be forwarded…
CWE: CWE-121
NVD

MEDIUM
CVE-2026-47487
CVE-2026-47487
pkg: linux

published: Aug 4, 2026

NVIDIA Triton Inference Server for Linux contains a vulnerability where a user could cause files outside the model repository to be read, written to, or modified by providing a path in the model name to the Triton MLflow plugin. A successful exploit of this vulnerability might lead to denial of serv…
CWE: CWE-22
NVD

MEDIUM
CVE-2026-70556
CVE-2026-70556
pkg: oauth

published: Aug 6, 2026

Hubzilla 11.2.1 contains a cross-site request forgery vulnerability in the OAuth2 /authorize endpoint handled by Zotlabs\Module\Authorize::post() that allows unauthenticated attackers to register arbitrary OAuth2 applications under an authenticated user's account by submitting a cross-origin POST re…
CWE: CWE-352
NVD

MEDIUM
CVE-2026-70442
CVE-2026-70442
pkg: go

published: Aug 5, 2026

Jenkins Google Chat Notification Plugin 166.ve6b_de280f2e8 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to use.
CWE: CWE-285
NVD

MEDIUM
CVE-2026-70596
CVE-2026-70596
pkg: node

published: Aug 5, 2026

Ghost is a Node.js content management system. From 4.9.0 until 6.54.1, an input validation issue allowed any staff user to create a post with content in feature_image_caption that could be used to hijack another staff user's Ghost Admin session, resulting in privilege escalation. This issue is fixed…
CWE: CWE-79
NVD

MEDIUM
CVE-2026-15656
CVE-2026-15656
pkg: go

published: Aug 5, 2026

IBM Maximo Application Suite 9.2, 9.1, and 9.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure…
CWE: CWE-614
GitHub-GHSA

MEDIUM
Ghost: Cross-Site Scripting in Feature Image Captions
GHSA-pr22-p9rp-2cqv
pkg: ghost
eco: npm
published: Aug 5, 2026
### Impact

An input validation issue allowed any staff user to create a post with content that could be used to hijack another staff user's Ghost Admin session resulting in privilege escalation.

### Vulnerable versions

This vulnerability is present in Ghost from v4.9.0 up to v6.54.0.

### Patches…

CVE-2026-70596
NVD

MEDIUM
CVE-2026-55996
CVE-2026-55996
pkg: tls

published: Aug 5, 2026

A denial-of-service vulnerability was identified in multiple TLS listeners in Rancher. Both the cattle-cluster-agent component running in downstream clusters and the Rancher server itself use the dynamiclistener library to serve TLS traffic. Without an effective CN filter configured, dynamiclistener…
CWE: CWE-770
GitHub-GHSA

MEDIUM
Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup
GHSA-jxc9-xmc4-gr23
pkg: open-webui
eco: pip
published: Aug 4, 2026
## Summary
A user with write access to one knowledge base could delete directories, and drop file embeddings, belonging to knowledge bases they do not control. The sync cleanup endpoint verified write access on the knowledge base named in the URL and then acted on the directory and file ids supplied…
CVE-2026-70488
GitHub-GHSA

MEDIUM
Open WebUI: Users denied the image-generation permission can still generate images via chat completions
GHSA-g423-grf7-98rv
pkg: open-webui
eco: pip
published: Aug 4, 2026
## Summary
An authenticated user whose `features.image_generation` permission has been revoked can still make the server generate images by sending the feature flag in a chat-completion request. The chat pipeline took the client-supplied `features` object at face value and never re-checked the permi…
CVE-2026-70484
GitHub-GHSA

MEDIUM
undici vulnerable to CRLF Injection via blob-like body 'type' property
GHSA-m8rv-5g2x-5cg5
pkg: undici, undici, undici
eco: npm
published: Aug 3, 2026
### Impact

When an application passes a duck-typed blob-like body to undici's HTTP/1.1 dispatcher (via `request()`, `stream()`, `pipeline()`, or `dispatch()`) with a `.type` derived from untrusted input, an attacker can inject CRLF sequences (`\r\n`) to append arbitrary HTTP headers and potentially…

CVE-2026-15157
NVD

MEDIUM
CVE-2026-70591
CVE-2026-70591
pkg: node

published: Aug 4, 2026

Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a Server-Side Request Forgery in Ghost Admin image fetching allowed any staff-level user to perform a blind HTTP GET request against internal hosts. No output was returned, but this could have been used to probe open ports on in…
CWE: CWE-918
GitHub-GHSA

MEDIUM
Ghost: Server-Side Request Forgery in Image Fetching
GHSA-gcvv-72q8-9v76
pkg: ghost
eco: npm
published: Aug 4, 2026
### Impact

A Server-Side Request Forgery (SSRF) in Ghost Admin allowed any staff-level user to perform a blind HTTP GET request against internal hosts. No output was returned, but this could have been used to probe open ports on internal hosts.

### Vulnerable versions

This vulnerability is presen…

CVE-2026-70591
GitHub-GHSA

MEDIUM
Open WebUI: Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart rendering
GHSA-rffm-9q57-q649
pkg: open-webui
eco: pip
published: Aug 4, 2026
## Summary
Open WebUI renders `vega` and `vega-lite` fenced code blocks in chat content by building a Vega view in the viewer's browser without a restricted resource loader. Any user who can place such a block where another user will see it can make that user's browser issue attacker-chosen outbound…
CVE-2026-70480
NVD

MEDIUM
CVE-2026-70595
CVE-2026-70595
pkg: node

published: Aug 5, 2026

Ghost is a Node.js content management system. From 6.26.0 until 6.54.1, a validation issue allowed some functionality, such as Webmentions, to be abused by an unauthenticated user to make limited HTTP requests to hosts in the Ghost server's internal network. A successful attack would not result in a…
CWE: CWE-918
GitHub-GHSA

MEDIUM
Ghost: Server-Side Request Forgery Mitigation Issue
GHSA-x5mm-wm4g-j5xv
pkg: ghost
eco: npm
published: Aug 5, 2026
### Impact

A validation issue allowed some functionality, such as Webmentions, to be abused by an unauthenticated user to make limited HTTP requests to hosts in the Ghost server's internal network. A successful attack would not result in any response data being returned.

### Vulnerable versions

T…

CVE-2026-70595
GitHub-GHSA

MEDIUM
Ghost: Server-side request forgery via DNS rebinding in external request handling
GHSA-ch52-px8q-f22j
pkg: ghost
eco: npm
published: Aug 4, 2026
### Impact

Ghost’s private-IP check for outbound HTTP requests could be bypassed via DNS rebinding, allowing an attacker to coerce the Ghost server into reaching hosts on internal networks through features that issue external fetches.

### Vulnerable versions

This vulnerability is present in Gho…

CVE-2026-53945
GitHub-GHSA

MEDIUM
pypdf: Possible large memory usage for large /ToUnicode streams
GHSA-fp3f-mc75-235c
pkg: pypdf
eco: pip
published: Aug 7, 2026
### Impact

An attacker who uses this vulnerability can craft a PDF which leads to large memory consumption. This requires parsing the `/ToUnicode` entry of a font with unusually large values, for example during text extraction.

### Patches

This has been fixed in [pypdf==6.15.0](https://github.com…

CVE-2026-71870
GitHub-GHSA

MEDIUM
pypdf: Possible long runtimes/large memory usage for large CID font width ranges
GHSA-fwg2-594c-jp42
pkg: pypdf
eco: pip
published: Aug 7, 2026
### Impact

An attacker who uses this vulnerability can craft a PDF which leads to long runtimes and large memory consumption. This requires parsing the font width entries of a font with unusually large values, for example during text extraction.

### Patches

This has been fixed in [pypdf==6.15.0](…

CVE-2026-71852
GitHub-GHSA

MEDIUM
Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint
GHSA-7c4v-fwgw-9rf7
pkg: nuxt, nuxt
eco: npm
published: Aug 7, 2026
### Impact

When a Nuxt dev server is bound to a network-reachable interface (for example `nuxt dev –host` for on-device testing), the default-enabled Chrome DevTools workspace endpoint `GET /.well-known/appspecific/com.chrome.devtools.json` returns the absolute project root (`workspace.root`, i.e.…

GitHub-GHSA

MEDIUM
DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS
GHSA-55q2-fjhq-7xh7
pkg: dompurify
eco: npm
published: Aug 7, 2026
### Summary

During `IN_PLACE` sanitization, a hook that removes an element can leave that element's detached descendants executable. A descendant image can retain its attacker-provided `onload` handler and fire after `sanitize()` returns, even though the returned root is clean and the image remains…

GitHub-GHSA

MEDIUM
Mermaid radar diagrams are vulnerable to DoS
GHSA-rhh3-jpg6-66xh
pkg: mermaid
eco: npm
published: Aug 6, 2026
### Impact

Mermaid radar diagrams allow arbitrary large values for `ticks`, which can cause high CPU usage, freezing the webpage/JavaScript process for long periods of time, until the process is eventually killed due to OOM/running out of memory.

#### Proof-of-concept

“`txt
radar-beta
axis a, …

CVE-2026-71439
GitHub-GHSA

MEDIUM
Mermaid allows CSS injection applying to sibling elements of the diagram
GHSA-6×64-9×62-f2gx
pkg: mermaid, mermaid
eco: npm
published: Aug 6, 2026
### Summary

Mermaid does not fully restrict CSS to the rendered SVG subtree. Although selectors are prefixed with `#mermaid-X`, sibling (`~` and `+`) combinators can still escape the Mermaid container and inject styles to DOM elements adjacent to the diagram `<svg>`.

**Most users of mermaid would …

CVE-2026-50159
GitHub-GHSA

MEDIUM
Mermaid Architecture diagrams are vulnerable to prototype pollution
GHSA-3rrr-jr9j-h3q3
pkg: mermaid
eco: npm
published: Aug 6, 2026
Rendering an untrusted `architecture-beta` diagram lets the diagram author write an arbitrary property with the value `horizontal` or `vertical` onto `Object.prototype`. A group id of `__proto__` is accepted as a valid parent.

### Impact

Any code in the same realm that reads a property of that nam…

CVE-2026-71437
GitHub-GHSA

MEDIUM
Mermaid XY Charts are vulnerable to an infinite loop DoS
GHSA-2v8p-3f2j-5mp7
pkg: mermaid, mermaid
eco: npm
published: Aug 6, 2026
### Impact

Mermaid XY Charts are vulnerable to an infinite loop DoS attack in the `setXAxisRangeData()`, when configuring an X-Axis with invalid parameters.

As each loop appends an element to an array, this would generally only cause an `RangeError: Invalid array length` to appear after a few seco…

CVE-2026-71436
GitHub-GHSA

MEDIUM
Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port
GHSA-6p8f-p8j2-rqmv
pkg: github.com/traefik/traefik/v3
eco: go
published: Aug 6, 2026
## Summary

There is a medium severity vulnerability in Traefik's Kubernetes Gateway API provider.
When two accepted HTTPRoutes target the same backend Service:port but configure different
`backendRef` filters, Traefik may resolve both routes to the same child service and apply
only one route's filt…

CVE-2026-54765
GitHub-GHSA

MEDIUM
Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef
GHSA-62fc-8686-hfmq
pkg: github.com/traefik/traefik/v2, github.com/traefik/traefik/v3, github.com/traefik/traefik/v3
eco: go
published: Aug 6, 2026
## Summary

There is a medium severity vulnerability in Traefik's Kubernetes CRD provider. When `providers.kubernetesCRD.allowCrossNamespace` is disabled — the default — cross-namespace `@kubernetescrd` references are rejected for middlewares, TLS options and HTTP/TCP ServersTransports, but the …

CVE-2026-71325
GitHub-GHSA

MEDIUM
Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass
GHSA-42cj-m3vj-89wv
pkg: github.com/traefik/traefik/v3, github.com/traefik/traefik/v3
eco: go
published: Aug 5, 2026
## Summary

There is a medium-severity cross-provider reference vulnerability in Traefik's Kubernetes CRD provider. The `crossProviderNamespaces` allowlist is enforced for HTTP `serversTransport` references but was not enforced for `IngressRouteTCP` service `serversTransport` references. A low-privi…

CVE-2026-65602
GitHub-GHSA

MEDIUM
Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion
GHSA-qq9q-x9w4-chhj
pkg: Traefik
eco: go
published: Aug 5, 2026
## Summary

There is a medium-severity namespace-confusion vulnerability in Traefik's Kubernetes Gateway API provider. When resolving `HTTPRoute.spec.rules[].backendRefs[].filters[].extensionRef`, Traefik used the backend Service namespace instead of the `HTTPRoute` namespace. A low-privileged route…

CVE-2026-65601
GitHub-GHSA

MEDIUM
Flowise: Unauthenticated Credential Abuse via Text-to-Speech Endpoint Allows Unauthorized Use of Private Chatflow TTS Credentials
GHSA-8gj2-2cvc-6xx7
pkg: flowise
eco: npm
published: Aug 4, 2026
## Summary

The `/api/v1/text-to-speech/generate` endpoint is whitelisted (requires no authentication) and accepts any `chatflowId` without checking whether the referenced chatflow is public. An unauthenticated attacker who knows a valid chatflow UUID can abuse that chatflow's TTS credential (OpenAI…

GitHub-GHSA

MEDIUM
Flowise: IDOR vulnerability exists at the GET /api/v1/organization/customer-default-source endpoint
GHSA-2364-jh4q-m9vm
pkg: flowise
eco: npm
published: Aug 4, 2026
### Summary
An Insecure Direct Object Reference (IDOR) vulnerability exists at the **GET /api/v1/organization/customer-default-source** endpoint. This flaw allows an authenticated attacker to bypass authorization checks and retrieve sensitive payment and profile information of other customers by man…
GitHub-GHSA

MEDIUM
python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees
GHSA-m2h6-j472-rp4c
pkg: cryptography
eco: pip
published: Aug 3, 2026
### Summary
If an intermediate constrained CA permits the DNS name `foo.example.com`, and the leaf certificate has a wildcard in its DNS SAN of `*.example.com`, python-cryptography's verifier accepts which allows escaping outside of the permitted names.

### PoC

“`
#!/usr/bin/env python3
"""Standa…

CVE-2026-69248
GitHub-GHSA

MEDIUM
AIOHTTP: HTTP request smuggling via WebSocket upgrade
GHSA-mfx4-hv73-q22v
pkg: aiohttp
eco: pip
published: Aug 3, 2026
### Summary

The HTTP parsers were vulnerable to a request smuggling attack relating to WebSocket upgrades.

### Impact

If using the server-side component, it may be possible for an attacker to execute a request smuggling vulnerability using an edge case in the WebSocket upgrade procedure. AIOHTT i…

CVE-2026-69243
GitHub-GHSA

MEDIUM
AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate
GHSA-mq44-7p77-q5h7
pkg: aiohttp
eco: pip
published: Aug 3, 2026
### Summary

The client accepts and decompresses frames with the RSV1 bit set even when the `permessage-deflate` extension was not negotiated.

### Impact

A client may unexpectedly decompress WebSocket frames when explicitly opted out. This could lead to additional CPU/memory consumption, but is un…

CVE-2026-59881
GitHub-GHSA

MEDIUM
ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks
GHSA-4xrf-jv44-h6hh
pkg: ip-address
eco: npm
published: Aug 3, 2026
### Summary

Every special-use classification method is built on `isInSubnet`, which short-circuits to `false` whenever the address's own subnet mask is *shorter* than the reference range's mask. That mask comes verbatim from the CIDR suffix on the parsed input, so appending a suffix such as `/0` su…

CVE-2026-69198
GitHub-GHSA

MEDIUM
ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks
GHSA-22jq-vg5j-6vgg
pkg: ip-address
eco: npm
published: Aug 3, 2026
### Summary

`Address6`'s special-property checks misclassify IPv4-mapped (`::ffff:0:0/96`) and NAT64 well-known (`64:ff9b::/96`) IPv6 addresses. These checks classify an address by its IPv6 wrapper rather than by the IPv4 address it embeds, so `isLoopback()`, `isLinkLocal()`, `isMulticast()`, and `…

CVE-2026-54272
GitHub-GHSA

MEDIUM
PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset
GHSA-fxqj-rqcc-2cmp
pkg: postcss
eco: npm
published: Aug 3, 2026
## Summary

The fix for GHSA-6g55-p6wh-862q added a guard in `lib/previous-map.js` `PreviousMap.loadFile()` that restricts an attacker-controlled `sourceMappingURL` (from a CSS comment) to a `.map` extension and, for untrusted maps, rejects `..` traversal and absolute paths. The traversal/absolute r…

CVE-2026-69153


Vulnerability Digest — August 3, 2026 · 43 Critical · 1 Exploited






Vulnerability Digest — Monday, August 3, 2026


Security Report

Monday, August 3, 2026  ·  Last 7 days  ·  Min severity: MEDIUM
Total Findings
337
Critical
43
High
177
Actively Exploited
1
CISA-KEV1
NVD200
GitHub-GHSA136
Findings sorted by severity
CISA-KEV

CRITICAL
Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
CVE-2026-20316
pkg: Cisco Secure Firewall Management Center (FMC)

published: Jul 29, 2026

Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impa…
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
GitHub-GHSA

CRITICAL
NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE
GHSA-p849-8hwh-84j9
pkg: @nocobase/plugin-notification-in-app-message
eco: npm
published: Jul 31, 2026
## Summary

`GET /api/myInAppChannels:list` accepts a structured `filter` query parameter. The handler for the `latestMsgReceiveTimestamp` field splices the `$lt` value directly into a `Sequelize.literal()` template string with no escape, type cast, or parameter binding. The action ACL is `loggedIn`…

CVE-2026-52887
GitHub-GHSA

CRITICAL
Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)
GHSA-2956-977x-2w3r
pkg: flyto-core
eco: pip
published: Jul 30, 2026
## Summary

`image.download` fetches a URL and writes the response to disk. It does not use the central path guard (`validate_path_with_env_config`, which confines writes to `FLYTO_SANDBOX_DIR`); instead it confines the output to `output_dir`, but `output_dir` is itself a caller parameter. Since the…

CVE-2026-67429
GitHub-GHSA

CRITICAL
prebid-server's request forgery vulnerability allows for possible host environment data extraction
GHSA-4p3g-4hcj-wpvx
pkg: github.com/prebid/prebid-server/v4, github.com/prebid/prebid-server/v3, github.com/prebid/prebid-server/v2
eco: go
published: Jul 29, 2026
### Impact
Certain bidder adapters accept user-supplied parameters that are interpolated into outbound request URLs. Without proper input validation, a malicious actor could craft bid request parameters that cause the server to send HTTP requests to unintended destinations, potentially exposing inte…
CVE-2026-54735
NVD

CRITICAL
CVE-2026-16812
CVE-2026-16812
pkg: arista velocloud_orchestrator

published: Jul 27, 2026

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by …
CWE: CWE-78
NVD

CRITICAL
CVE-2026-67330
CVE-2026-67330
pkg: oauth

published: Aug 1, 2026

@better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-beta.0 through <= 1.7.0-beta.9 contain an authorization bypass. SCIM token issuance did not reject provider IDs already used by existing SSO, SAML, OIDC, generic OAuth, or social account providers, and …
CWE: CWE-20
GitHub-GHSA

CRITICAL
Wings exposes node configuration secrets through egg configuration-file templating
GHSA-pfvc-3p5h-x7h6
pkg: github.com/pterodactyl/wings
eco: go
published: Jul 31, 2026
### Impact

**Type:** Exposure of sensitive information / insufficiently protected credentials
leading to privilege escalation and full node compromise.

Wings exposes its **entire** daemon configuration to the egg configuration-file
templating engine. When Wings renders a server's configuration fil…

CVE-2026-52855
NVD

CRITICAL
CVE-2026-13435
CVE-2026-13435
pkg: python

published: Jul 30, 2026

IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox implementation.
CWE: CWE-94
NVD

CRITICAL
CVE-2026-54680
CVE-2026-54680
pkg: kubernetes

published: Jul 29, 2026

Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior to 6.6.0, the Fluentd configuration renderer FluentRender in pkg/sdk/logging/model/render/fluent.go writes CRD strings such as Flow record_transformer.records values directly into fluent.conf without e…
CWE: CWE-74, CWE-77
GitHub-GHSA

CRITICAL
Logging operator has Fluentd configuration injection that allows remote code execution
GHSA-mjqf-28ph-426h
pkg: github.com/kube-logging/logging-operator
eco: go
published: Jul 29, 2026
### Summary

The Fluentd configuration renderer in Logging operator writes strings from CRDs such as `Flow` directly into `fluent.conf` without escaping them. As a result, a user who can create `Flow` resources can inject Fluentd configuration by providing values that contain newlines.

In the confi…

CVE-2026-54680
NVD

CRITICAL
CVE-2026-8457
CVE-2026-8457
pkg: jwt

published: Aug 2, 2026

The WooCommerce – Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple login handler accepting the Apple id_token and decoding only its base64 payload without verifying the JWT signature against Apple's …
CWE: CWE-289
NVD

CRITICAL
CVE-2026-66402
CVE-2026-66402
pkg: tls

published: Aug 1, 2026

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_verify_certificate(), tls_match_hostname(), and x509_utils_get_dns_names(). Because FreeRDP performs custom Common Name and DNS SAN string matching instead of using OpenSSL's l…
CWE: CWE-295
NVD

CRITICAL
CVE-2026-68771
CVE-2026-68771
pkg: node

published: Jul 31, 2026

ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and triggering its deserialization. Attackers can upload a malicious shard_*.pkl file via …
CWE: CWE-502
NVD

CRITICAL
CVE-2026-68770
CVE-2026-68770
pkg: python

published: Jul 31, 2026

sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code execution by exploiting a logic flaw in the import_module_class helper within sentence_transformers/util/misc.py, where the guard condition includes an 'or os.path.exists(model_name…
CWE: CWE-94
NVD

CRITICAL
CVE-2026-67208
CVE-2026-67208
pkg: docker

published: Jul 30, 2026

Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execute arbitrary OS commands by connecting to the exposed H2 database web console using default shipped credentials. Attackers can access the unprotected /h2-console endpoint, authent…
CWE: CWE-306, CWE-1188
NVD

CRITICAL
CVE-2026-41939
CVE-2026-41939
pkg: windows

published: Jul 29, 2026

Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final management interface that allows unauthenticated remote attackers to gain administrative access by using default credentials identical across all installations. Attackers can authentica…
CWE: CWE-1392
NVD

CRITICAL
CVE-2026-59243
CVE-2026-59243
pkg: oauth

published: Jul 29, 2026

The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or unsigned (`alg:none`) ID token to the OAuth callback could bypass authentication and log in as an arbitrary user, including one holding the Admin role…
CWE: CWE-347
GitHub-GHSA

CRITICAL
@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution
GHSA-6wcc-39rp-hh9p
pkg: @hypequery/clickhouse
eco: npm
published: Jul 28, 2026
### Impact
A SQL injection vulnerability exists in the `escapeValue()` function used for parameter substitution. Attackers who can control parameter values can inject arbitrary SQL by using a trailing backslash to escape the closing quote.

Who is impacted: All users of @hypequery/clickhouse versio…

CVE-2026-54658
NVD

CRITICAL
CVE-2026-64541
CVE-2026-64541
pkg: linux

published: Jul 27, 2026

In the Linux kernel, the following vulnerability has been resolved:

net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket

smc_cdc_rx_handler() looks up the connection by token under the link
group's conns_lock, drops the lock, and then dereferences conn and the
smc_sock derived from it, e…

NVD

CRITICAL
CVE-2026-68579
CVE-2026-68579
pkg: windows

published: Aug 2, 2026

FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_Read function (client/Windows/wf_cliprdr.c). When an OLE paste consumer (e.g. explorer.exe) calls IStream::Read with a fixed-size buffer of cb bytes, CliprdrStream_Read requests fi…
CWE: CWE-787
NVD

CRITICAL
CVE-2026-54725
CVE-2026-54725
pkg: kubernetes

published: Jul 31, 2026

vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in pkg/webhook/config.go accepts the vault.security.banzaicloud.io/vault-addr annotation, MutateConfigMap and MutateSecret call newVaultClient in pkg/webh…
CWE: CWE-918
GitHub-GHSA

CRITICAL
vault-addr annotation SSRF — webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API
GHSA-r2v3-8gwf-7ghm
pkg: github.com/bank-vaults/vault-secrets-webhook
eco: go
published: Jul 31, 2026
## Summary

The vault-secrets-webhook reads the `vault.security.banzaicloud.io/vault-addr` annotation from any ConfigMap or Secret being admitted and uses it as the Vault server address without any validation or allowlist. When a ConfigMap or Secret contains a value prefixed with `vault:`, the webho…

CVE-2026-54725
NVD

CRITICAL
CVE-2026-17692
CVE-2026-17692
pkg: windows

published: Jul 30, 2026

Use after free in DataTransfer in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

CRITICAL
CVE-2026-17691
CVE-2026-17691
pkg: windows

published: Jul 30, 2026

Out of bounds write in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-787
NVD

CRITICAL
CVE-2026-17656
CVE-2026-17656
pkg: go

published: Jul 30, 2026

Use after free in Ozone in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

CRITICAL
CVE-2026-17655
CVE-2026-17655
pkg: go

published: Jul 30, 2026

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-20
NVD

CRITICAL
CVE-2026-17652
CVE-2026-17652
pkg: go

published: Jul 30, 2026

Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

CRITICAL
CVE-2026-17651
CVE-2026-17651
pkg: go

published: Jul 30, 2026

Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-20
NVD

CRITICAL
CVE-2026-66395
CVE-2026-66395
pkg: node

published: Jul 27, 2026

SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler that allows attackers to execute arbitrary code by crafting a malicious siyuan:// deep link. Attackers can inject HTML payloads via the plugin name parameter that execute with ful…
CWE: CWE-79
GitHub-GHSA

CRITICAL
Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration
GHSA-jx74-cqjv-2c67
pkg: flyto-core
eco: pip
published: Jul 30, 2026
## Summary
The standalone `flyto-verification` service exposes `POST /run` with **no authentication**, on all interfaces (0.0.0.0:8344 per the shipped Dockerfile). The request body's `callback_url` is used verbatim for an outbound POST that **unconditionally attaches `X-Internal-Key: $FLYTO_RUNNER_S…
CVE-2026-67426
NVD

CRITICAL
CVE-2026-3141
CVE-2026-3141
pkg: linux

published: Aug 1, 2026

The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the /wp-json/formgent/responses/attachments REST API endpoint in all versions up to, and including, 1.9.2 This is due to the REST API route being registered without any authen…
CWE: CWE-862
GitHub-GHSA

CRITICAL
Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass
GHSA-6h5j-32cf-4253
pkg: apostrophe
eco: npm
published: Jul 31, 2026
<img width="1919" height="1046" alt="proto" src="https://github.com/user-attachments/assets/c5c69718-6448-448d-b64b-e3db41ab6ff6" />

## Summary

`apos.util.set()` traverses dot-notation paths without sanitizing `__proto__`, allowing an authenticated editor to write arbitrary values to `Object.proto…

CVE-2026-53609
NVD

CRITICAL
CVE-2026-52539
CVE-2026-52539
pkg: jwt

published: Jul 30, 2026

Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environment variable is not set, the application falls back to the default value which is publicly visible in the source code repository. An unauthenticated remote attacker can exploit this by forging JWT sessi…
CWE: CWE-798
NVD

CRITICAL
CVE-2026-63230
CVE-2026-63230
pkg: jwt

published: Jul 29, 2026

A pre-authentication error-based SQL injection
vulnerability in Koollab LMS allowed an unauthenticated attacker to read sensitive database
contents, including personally identifiable information, credentials, and valid
JWT tokens that may enable account takeover, via the SCORM report endpoint.
CWE: CWE-89
NVD

CRITICAL
CVE-2026-63229
CVE-2026-63229
pkg: jwt

published: Jul 29, 2026

A pre-authentication blind SQL injection
vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time-based SQL oracle via
the SSO OAuth endpoint to read sensitive database contents, including
personally identifiable information, credentials, and valid JWT tokens that may
enable ac…
CWE: CWE-89
NVD

CRITICAL
CVE-2026-64863
CVE-2026-64863
pkg: go

published: Jul 28, 2026

goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.4, the httpserver/server.go wdGuard handled WebDAV MOVE as a write-only method and did not enforce –no-delete, allowing WebDAV clients to delete or overwrite files via MOVE with Overwrite: T. This issue i…
CWE: CWE-284
NVD

CRITICAL
CVE-2026-62325
CVE-2026-62325
pkg: go

published: Jul 28, 2026

goshs is a feature-rich single-binary file server for red teamers and developers. From 2.1.3 until 2.1.4, the sftpserver/sftpserver.go password handler used Username != "" && Password != "", so running goshs with -b 'admin:' -sftp and no -fkf left both SFTP authentication handlers unset and allowed …
CWE: CWE-306
GitHub-GHSA

CRITICAL
goshs –no-delete WebDAV MOVE bypass allows file deletion/overwrite
GHSA-hq33-8jgp-8qq3
pkg: goshs.de/goshs/v2, github.com/patrickhener/goshs/v2, goshs.de/goshs
eco: go
published: Jul 28, 2026
## Summary

The WebDAV mode-flag guard added to fix GHSA-3whc-qvhv-xqjp still does not enforce `–no-delete` on the WebDAV `MOVE` verb. `MOVE` deletes the source file (rename removes it from its original path), and with `Overwrite: T` it additionally performs an explicit `RemoveAll` on the destinati…

CVE-2026-64863
GitHub-GHSA

CRITICAL
goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)
GHSA-rjrw-mjq6-hpmm
pkg: github.com/patrickhener/goshs/v2, goshs.de/goshs/v2
eco: go
published: Jul 28, 2026
## Summary

Start goshs v2.1.3 with `-b 'admin:' -sftp`. No `-fkf`. SFTP accepts connections without password. CVE-2026-40884 blocks the empty-username variant (`-b ':pass'`). The empty-password variant bypasses that fix.

## CVE-2026-40884

**CVE-2026-40884** (GHSA-c29w-qq4m-2gcv, Apr 13 2026) repo…

CVE-2026-62325
NVD

CRITICAL
CVE-2026-64551
CVE-2026-64551
pkg: linux

published: Jul 27, 2026

In the Linux kernel, the following vulnerability has been resolved:

sctp: validate STALE_COOKIE cause length before reading staleness

When an ERROR chunk with a STALE_COOKIE cause is received in the
COOKIE_ECHOED state, sctp_sf_do_5_2_6_stale() reads the 4-byte Measure
of Staleness that follows th…

GitHub-GHSA

CRITICAL
AWS Amplify Studio UI Component Properties Has an Input Validation Issue
GHSA-hf3j-86p7-mfw8
pkg: @aws-amplify/codegen-ui-react
eco: npm
published: Jul 30, 2026
### Summary
The AWS Amplify Studio [amplify-codegen-ui](https://github.com/aws-amplify/amplify-codegen-ui) is a package that generates front-end code from UI Builder entities (components, forms, views, and themes) primarily used in AWS Amplify Studio for component previews and in AWS Command Line In…
CVE-2025-4318
GitHub-GHSA

CRITICAL
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
GHSA-xr9x-r78c-5hrm
pkg: activestorage, activestorage, activestorage
eco: rubygems
published: Jul 30, 2026
### Impact
In its default configuration, a Rails application that displays image variants may allow an
unauthenticated attacker to read arbitrary files from the server, including the process environment.
That environment typically holds `secret_key_base` and often credentials for external systems, w…
CVE-2026-66066
GitHub-GHSA

CRITICAL
lettre has TLS hostname verification disabled when using Boring TLS backend
GHSA-4pj9-g833-qx53
pkg: lettre
eco: rust
published: Jul 28, 2026
### Summary
An inverted-boolean bug in lettre's `boring-tls` integration silently
disables TLS hostname verification for callers using the default (strict)
configuration. An on-path attacker presenting any chain-valid certificate
for any domain can intercept SMTP submission, including PLAIN/LOGIN
cr…
CVE-2026-46428
GitHub-GHSA

HIGH
AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping
GHSA-m4x6-gwgp-4pm7
pkg: @aws/agentcore, @aws/agentcore, @aws/agentcore
eco: npm
published: Jul 29, 2026
### Summary
The AgentCore CLI (@aws/agentcore) is a developer tool for managing agent infrastructure lifecycle on Amazon Bedrock AgentCore. An issue exists where, under certain circumstances, a crafted collaborationInstruction value stored in Bedrock Agent collaborator metadata can break out of a Py…
CVE-2026-11393
NVD

HIGH
CVE-2026-12562
CVE-2026-12562
pkg: linux

published: Jul 30, 2026

The RCU II+ and Multiload II+ are vulnerable to an unauthenticated
service that exposes a debug interface granting full root-level access
to the embedded system. This vulnerability stems from a
network-accessible port running a Target Communications Framework (TCF)
service that does not require …
CWE: CWE-306
NVD

HIGH
CVE-2026-67207
CVE-2026-67207
pkg: express

published: Jul 30, 2026

Wolf CMS through 0.8.3.1 contains an authorization bypass vulnerability in BackupRestoreController that allows authenticated non-administrative users to access restricted backup functionality due to a PHP operator precedence flaw in the permission check expression. Attackers can exploit the incorrec…
CWE: CWE-697
NVD

HIGH
CVE-2026-16526
CVE-2026-16526
pkg: linux

published: Jul 30, 2026

A flaw in the PCP linux_sockets module exposes an unsecured internal connection.
An attacker with initial code execution can exploit this to escalate privileges and execute arbitrary commands as root.
CWE: CWE-403
NVD

HIGH
CVE-2026-17894
CVE-2026-17894
pkg: linux

published: Jul 30, 2026

Use after free in Views in Google Chrome on Linux prior to 151.0.7922.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-416
NVD

HIGH
CVE-2026-17661
CVE-2026-17661
pkg: go

published: Jul 30, 2026

Use after free in Loader in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-17658
CVE-2026-17658
pkg: go

published: Jul 30, 2026

Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-64557
CVE-2026-64557
pkg: linux

published: Jul 29, 2026

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_new_connection_cb()

l2cap_sock_new_connection_cb() returned l2cap_pi(sk)->chan after
release_sock(parent). Once the parent lock is dropped the newly
enqueued child socket sk is re…

GitHub-GHSA

HIGH
Style Dictionary – Prototype Pollution in convertTokenData utility function
GHSA-vj5c-m527-mpff
pkg: style-dictionary
eco: npm
published: Jul 28, 2026
### Impact
Prototype pollution.
A malicious user can create a token array `[{ key: '{__proto__.foo}', value: 'malicious' }]`, when processed by `convertTokenData()` utility function, it will pollute the Object.prototype globally where `{}.foo` will equal `{ key: '{__proto__.foo}', value: 'malicious'…
CVE-2026-54639
NVD

HIGH
CVE-2026-54653
CVE-2026-54653
pkg: express

published: Jul 28, 2026

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. From 0.17.0 until 0.60.2, datamodel-code-generator preserves attacker-controlled default_factory values in src/datamodel_…
CWE: CWE-94, CWE-1336
GitHub-GHSA

HIGH
`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field
GHSA-386q-5hp3-95m9
pkg: datamodel-code-generator
eco: pip
published: Jul 28, 2026
### Summary

`datamodel-code-generator` is vulnerable to code injection when generating Python models from an attacker-controlled JSON Schema, OpenAPI, YAML, JSON, Avro, Protobuf, or XSD schema. When a property carries a `"default_factory"` key, its value is interpolated verbatim — as a raw Python…

CVE-2026-54653
NVD

HIGH
CVE-2026-66748
CVE-2026-66748
pkg: express

published: Jul 28, 2026

Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows users with custom_fields manage permission to execute arbitrary Ruby code by supplying a malicious expression through the select_eval custom field type. Attackers can store an attacker…
CWE: CWE-94
GitHub-GHSA

HIGH
Cedar-Java has policy injection, type confusion, and incorrect equality comparison vulnerabilities
GHSA-4r9r-4425-74p7
pkg: com.cedarpolicy:cedar-java, com.cedarpolicy:cedar-java, com.cedarpolicy:cedar-java
eco: maven
published: Jul 28, 2026
### Summary

CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisions. Under certain circumstances, it could lead to incorrect equality comparisons.

### Impact

**`EntityIdentifier.equals()` has inverted null/self branches**

The `E…

CVE-2026-55771
NVD

HIGH
CVE-2026-64555
CVE-2026-64555
pkg: linux

published: Jul 27, 2026

In the Linux kernel, the following vulnerability has been resolved:

KVM: arm64: nv: Fix SPSR_EL2 restore in kvm_hyp_handle_mops()

kvm_hyp_handle_mops() resets the single-step state machine as part of
rewinding state for a MOPS exception by modifying vcpu_cpsr() and
writing the result directly into…

NVD

HIGH
CVE-2026-64554
CVE-2026-64554
pkg: linux

published: Jul 27, 2026

In the Linux kernel, the following vulnerability has been resolved:

netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment()

br_ip6_fragment() gets prevhdr, a pointer into the skb head, from
ip6_find_1stfragopt(), then calls skb_checksum_help(). For a cloned skb
skb_checksum_help() reall…

GitHub-GHSA

HIGH
@apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script Tag
GHSA-wf43-fpp3-cf65
pkg: @apostrophecms/seo
eco: npm
published: Jul 31, 2026
<img width="1919" height="1046" alt="curl" src="https://github.com/user-attachments/assets/8aa19ff1-7f4b-44ee-83d5-d0dd1a0269f6" />
<img width="1919" height="775" alt="xss" src="https://github.com/user-attachments/assets/a65012e8-9b2f-416f-94df-c00493f2ca1d" />

### Summary

The `@apostrophecms/seo`…

CVE-2026-53608
GitHub-GHSA

HIGH
Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE mode
GHSA-qvv7-cg9c-w4x3
pkg: nltk
eco: pip
published: Jul 31, 2026
### Summary
`nltk.pathsec` provides an SSRF filter that NLTK documents as a security control, blocking loopback, private, link-local, and multicast ranges (including obfuscated forms) and recommending strict `ENFORCE` mode for security-sensitive environments. The filter is bypassable by DNS rebindin…
CVE-2026-12075
GitHub-GHSA

HIGH
Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url
GHSA-qq9q-xgm3-xv9g
pkg: flyto-core
eco: pip
published: Jul 30, 2026
## Summary

`llm.chat` reads the operator's provider key from the environment (`OPENAI_API_KEY`, `ANTHROPIC_API_KEY`, …) and sends it in the `Authorization: Bearer` header to `base_url`, a parameter the caller controls. `base_url` is only checked against the SSRF guard, and the guard allows any pu…

CVE-2026-67425
GitHub-GHSA

HIGH
Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted
GHSA-hr7p-wg7r-hg9m
pkg: flyto-core
eco: pip
published: Jul 30, 2026
## Summary

The capability policy denies the `env.get` and `env.load_dotenv` modules by default, with the stated reason that they read arbitrary host environment variables (API keys, DSNs) and are a secret-exfil risk. But the workflow engine's variable resolver expands `${env.VAR}` for any environme…

CVE-2026-67427
GitHub-GHSA

HIGH
openhole-server vulnerable to path traversal via URL-decoded request path
GHSA-fh2f-xfxc-q9cc
pkg: github.com/bablilayoub/openhole
eco: go
published: Jul 28, 2026
## Summary

openhole-server forwarded the URL-decoded request path (`r.URL.Path`) to tunnel clients instead of the original request-target. Percent-encoded dot-segments (`%2e`) and separators (`%2f`) were decoded to `../` and `/` before reaching the local service.

Go's ServeMux rejects literal `../…

CVE-2026-54650
NVD

HIGH
CVE-2026-54603
CVE-2026-54603
pkg: oauth

published: Jul 28, 2026

OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC). From 0.4.0 to 2.0.21, a protocol-relative redirect Location returned to OAuth2::Client#request overrides the request authority, so the bearer Authorization header is sent to an attacker-cont…
CWE: CWE-200, CWE-601
GitHub-GHSA

HIGH
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
GHSA-85rg-p3fr-xc2f
pkg: com.quietterminal:qti-neon, qti-neon, qti-neon
eco: npm
published: Jul 28, 2026
### Impact
The relay's reconnect handler forwards every `RECONNECT_REQUEST` to the host without deduplication or a size cap on the `pendingReconnects` map, unlike the connect flow which guards against this with `maxPendingConnections`. An unauthenticated attacker who knows a valid session ID can sen…
CVE-2026-54609
GitHub-GHSA

HIGH
OAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to attacker host
GHSA-pp92-crg2-gfv9
pkg: oauth2
eco: rubygems
published: Jul 28, 2026
## Summary

When an application uses `OAuth2::Client` (typically via an `OAuth2::AccessToken`) and the configured authorization server returns a redirect whose `Location` header is a protocol-relative URI of the form `//attacker.example/leak`, `OAuth2::Client#request` resolves the redirect with `res…

CVE-2026-54603
NVD

HIGH
CVE-2026-10079
CVE-2026-10079
pkg: kubernetes

published: Jul 31, 2026

A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, ACS replaces deployment identity metadata based on the openshift.io/encoded-deployment-config label. A user with permission to create Deployments can set this label to "null", causin…
CWE: CWE-345
NVD

HIGH
CVE-2026-62246
CVE-2026-62246
pkg: kubernetes

published: Jul 30, 2026

Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane datastore schema, database user, and etcd key prefix from a lossy namespace-and-name normalization in GetDefaultDatastoreSchema() and GetDefaultDatastoreUsername(), allowing distinct …
CWE: CWE-284, CWE-653
NVD

HIGH
CVE-2026-57862
CVE-2026-57862
pkg: curl

published: Jul 30, 2026

Kanboard 1.2.52 and prior contains a server-side request forgery vulnerability that allows authenticated users to bypass SSRF protections by supplying hexadecimal IP address notation in user-controlled URLs. Attackers can submit hexadecimal-encoded internal IP addresses through the web link creation…
CWE: CWE-918
GitHub-GHSA

HIGH
Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation
GHSA-c9hr-64h3-gxpc
pkg: flyto-core
eco: pip
published: Jul 30, 2026
## Summary
The HTTP modules that DO call the SSRF guard (`http.get`, `http.request`, `http.batch`) validate only the initial URL, then issue the request with aiohttp's default `allow_redirects=True` and perform no per-hop revalidation. An attacker hosts a public URL that 302-redirects to an internal…
CVE-2026-67424
GitHub-GHSA

HIGH
Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)
GHSA-pgwh-4jj4-qm8v
pkg: flyto-core
eco: pip
published: Jul 30, 2026
## Summary
Numerous HTTP-emitting modules (`core.api.http_get`, `core.api.http_post`, `graphql.query`/`graphql.mutation`, `monitor.http_check`, `communication.slack_send`, `notification.{discord,slack,teams}.send_message`, `ai.vision_analyze` [anthropic path], `verify.visual_diff`, `browser.proxy_ro…
CVE-2026-67428
GitHub-GHSA

HIGH
Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption
GHSA-qf5v-m7p4-95rp
pkg: github.com/fission/fission
eco: go
published: Jul 28, 2026
Fission v1.24.0 added PodSpec safety validation for tenant-facing Environment and Function CRDs (`ValidatePodSpecSafety` / `ValidateContainerSafety` admission webhook + `sanitizeContainerSecurityContext` executor merge layer), but the
capability check was implemented as a fixed **denylist of six Lin…
CVE-2026-50570
NVD

HIGH
CVE-2026-17877
CVE-2026-17877
pkg: linux

published: Jul 30, 2026

Inappropriate implementation in Chromoting in Google Chrome on Linux prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via malicious network traffic. (Chromium security severity: Medium)
CWE: CWE-269
NVD

HIGH
CVE-2026-64552
CVE-2026-64552
pkg: linux

published: Jul 27, 2026

In the Linux kernel, the following vulnerability has been resolved:

virtio-net: fix len check in receive_big()

receive_big() bounds the device-announced length by
(big_packets_num_skbfrags + 1) * PAGE_SIZE. That is still too loose:
add_recvbuf_big() sets sg[1] to start at offset
sizeof(struct pad…

NVD

HIGH
CVE-2026-64548
CVE-2026-64548
pkg: linux

published: Jul 27, 2026

In the Linux kernel, the following vulnerability has been resolved:

bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data()

When the scatterlist ring is full or nearly full, bpf_msg_push_data()
enters a copy fallback path and computes copy + len for the page
allocation size. Since len c…

NVD

HIGH
CVE-2026-66396
CVE-2026-66396
pkg: node

published: Jul 27, 2026

SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List value when rendering Gallery and Kanban cover images, allowing stored cross-site scripting via unescaped style attribute interpolation. Attackers with editor permissions can inject onload handlers that execute arbitrary cod…
CWE: CWE-79
NVD

HIGH
CVE-2026-47882
CVE-2026-47882
pkg: docker

published: Jul 30, 2026

When enabling Spring Boot DevTools support for a remote application target (for example a Docker container or Cloud Foundry app) from the Spring Tools Boot Dashboard, Spring Tools generates a shared secret that authenticates DevTools remote-restart uploads to the deployed application. This secret wa…
CWE: CWE-338
NVD

HIGH
CVE-2026-17723
CVE-2026-17723
pkg: windows

published: Jul 30, 2026

Use after free in Media in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-17660
CVE-2026-17660
pkg: go

published: Jul 30, 2026

Insufficient validation of untrusted input in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-20
NVD

HIGH
CVE-2026-17657
CVE-2026-17657
pkg: go

published: Jul 30, 2026

Use after free in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-17653
CVE-2026-17653
pkg: go

published: Jul 30, 2026

Use after free in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-17650
CVE-2026-17650
pkg: go

published: Jul 30, 2026

Use after free in Compositing in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-54666
CVE-2026-54666
pkg: axios

published: Jul 29, 2026

swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/schema-routes/schema-routes.ts passes OpenAPI path keys through parseRouteName to templates/default/procedure-call.ejs and templates/modular/procedure-call.ejs without escaping JavaSc…
CWE: CWE-74, CWE-94, CWE-1336
NVD

HIGH
CVE-2026-54664
CVE-2026-54664
pkg: axios

published: Jul 29, 2026

swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/schema-parser/base-schema-parsers/enum.ts passes components.schemas.*.enum[i] values to Ts.StringValue in src/configuration.ts without escaping before templates/base/enum-data-contrac…
CWE: CWE-74, CWE-94, CWE-1336
NVD

HIGH
CVE-2026-54662
CVE-2026-54662
pkg: axios

published: Jul 29, 2026

swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/code-gen-process.ts createApiConfig copies servers[0].url into apiConfig.baseUrl, and templates/base/http-clients/fetch-http-client.ejs interpolates apiConfig.baseUrl into the generated…
CWE: CWE-74, CWE-94, CWE-1336
NVD

HIGH
CVE-2026-54661
CVE-2026-54661
pkg: axios

published: Jul 29, 2026

swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, templates/base/http-clients/axios-http-client.ejs interpolates servers[0].url from src/code-gen-process.ts into the HttpClient constructor without escaping, allowing an attacker-controlle…
CWE: CWE-74, CWE-94, CWE-1336
GitHub-GHSA

HIGH
swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies
GHSA-w284-33mx-6g9v
pkg: swagger-typescript-api
eco: npm
published: Jul 29, 2026
### Summary

`swagger-typescript-api` interpolates OpenAPI path strings (the keys of the `paths` object, e.g. `/users/{id}`) directly into a JavaScript template literal inside the body of every generated API method, without escaping. A spec path containing `${ … }` survives `parseRouteName`'s `{x}…

CVE-2026-54666
GitHub-GHSA

HIGH
swagger-typescript-api vulnerable to code injection via unescaped enum string values
GHSA-5f94-x226-ccpm
pkg: swagger-typescript-api
eco: npm
published: Jul 29, 2026
### Summary

`swagger-typescript-api` interpolates `components.schemas.*.enum[i]` string values into the body of generated TypeScript `enum` declarations without escaping. A malicious enum value can close the enclosing string literal, terminate the enum body, and inject a bare-block IIFE that execut…

CVE-2026-54664
GitHub-GHSA

HIGH
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template
GHSA-38c3-wv3c-v3xj
pkg: swagger-typescript-api
eco: npm
published: Jul 29, 2026
### Summary

`swagger-typescript-api` interpolates `servers[0].url` directly into a TypeScript string literal inside the `HttpClient` constructor body of the generated **axios** client (`templates/base/http-clients/axios-http-client.ejs:71`), without any escaping. A malicious URL containing a `"` cl…

CVE-2026-54661
GitHub-GHSA

HIGH
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template
GHSA-hqj5-cw9f-rx67
pkg: swagger-typescript-api
eco: npm
published: Jul 29, 2026
### Summary

`swagger-typescript-api` interpolates `servers[0].url` directly into a TypeScript class-body field initializer of the generated **fetch** `HttpClient` (`templates/base/http-clients/fetch-http-client.ejs:75`), without any escaping. A malicious URL containing a `"` closes the string liter…

CVE-2026-54662
NVD

HIGH
CVE-2026-53501
CVE-2026-53501
pkg: python

published: Jul 31, 2026

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC validation can be bypassed due to the use of Python’s .replace() when removing the signature from the URL before validation. Since .replace() removes all occurrences of the substring, an attacker can i…
CWE: CWE-347
GitHub-GHSA

HIGH
Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature
GHSA-mw3h-qjxj-6xg9
pkg: thumbor
eco: pip
published: Jul 31, 2026
# HMAC validation bypass via multiple `.replace()` calls when removing URL signature

## Summary

Thumbor’s HMAC validation can be bypassed due to the use of Python’s `.replace()` when removing the signature from the URL before validation. Since `.replace()` removes **all occurrences** of the su…

CVE-2026-53501
GitHub-GHSA

HIGH
Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot
GHSA-6×26-6r6f-m537
pkg: thumbor
eco: pip
published: Jul 31, 2026
## Summary

The `ALLOWED_SOURCES` configuration is meant to restrict which hosts Thumbor's HTTP loader may fetch images from. Plain-string entries in that list (the overwhelming majority of real-world and documented configurations) are passed directly to `re.match()` without escaping. Because `.` is…

CVE-2026-53500
NVD

HIGH
CVE-2026-56672
CVE-2026-56672
pkg: node

published: Jul 31, 2026

ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, GET /userdata/{file} served user-controlled HTML and SVG files with extension-derived content types, allowing stored cross-site scripting in the ComfyUI origin and access to browser-stored API tokens, settings, workflows…
CWE: CWE-79
NVD

HIGH
CVE-2026-54574
CVE-2026-54574
pkg: docker

published: Jul 29, 2026

proot-distro is a utility for managing proot containers. Prior to version 5.1.5, proot-distro install extracted plain tarball root filesystems through _extract_plain_tar() in proot_distro/commands/install.py and Docker layers through _apply_layer() in proot_distro/helpers/docker.py without validatin…
CWE: CWE-61
GitHub-GHSA

HIGH
proot-distro has a Container Isolation Bypass via Crafted Restore Archive
GHSA-7h3g-4w2f-fj2f
pkg: proot-distro
eco: pip
published: Jul 29, 2026
## Affected Component

– **Package:** proot-distro
– **Affected command:** `restore`
– **Attack surface:** Host-side Termux CLI processing a user-supplied backup archive
– **Vulnerability type:** Container Isolation Bypass / Cross-Container Read and Write

## Affected Versions

| Component | Ve…

CVE-2026-54727
GitHub-GHSA

HIGH
`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive
GHSA-9xq3-3fqg-4vg7
pkg: proot-distro
eco: pip
published: Jul 29, 2026
**Repository:** `termux/proot-distro`
**Component:** `proot_distro/commands/install.py` → `_extract_plain_tar()`; also `helpers/docker.py` → `_apply_layer()`

## Affected Versions

| Component | Version |
|—————|——————————|
| proo…

CVE-2026-54574
NVD

HIGH
CVE-2026-22068
CVE-2026-22068
pkg: express

published: Jul 29, 2026

Regular Expression without Anchors vulnerability in Apache Traffic Server.

This issue affects Apache Traffic Server: from 10.0.X through 10.1.3, from 9.0.X through 9.2.14.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.

CWE: CWE-777
NVD

HIGH
CVE-2026-54691
CVE-2026-54691
pkg: python

published: Jul 28, 2026

datamodel-code-generator generates Python data models from schema definitions. From 0.9.1 until 0.61.0, src/datamodel_code_generator/http.py http.get_body accepts –url targets and redirect chain targets without host/IP validation, allowing server-side request forgery against loopback, private, link…
CWE: CWE-918
GitHub-GHSA

HIGH
datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)
GHSA-954p-556p-r752
pkg: datamodel-code-generator
eco: pip
published: Jul 28, 2026
### Summary

JSON-Schema `$ref` values pointing at HTTP or HTTPS URLs are silently dereferenced by `datamodel-code-generator` with no IP/host validation, no scheme allow-list, and redirects followed unconditionally. The `–allow-remote-refs` gate added in 0.56.0 defaults to `None`, which only emits …

CVE-2026-54690
GitHub-GHSA

HIGH
datamodel-code-generator vulnerable to SSRF via –url: no host/IP validation, follows redirects
GHSA-rfr2-mq9m-x2qx
pkg: datamodel-code-generator
eco: pip
published: Jul 28, 2026
### Summary

`datamodel-code-generator`'s built-in HTTP fetcher (`http.get_body`) issues an `httpx.GET` against any URL passed to `–url` (or reached via a redirect chain) with **no allow-list, no deny-list, no IP/host validation, and `follow_redirects=True`**. Loopback addresses, RFC1918 ranges, li…

CVE-2026-54691
GitHub-GHSA

HIGH
java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutor
GHSA-28f5-38xr-jh2w
pkg: io.appium:java-client
eco: maven
published: Jul 28, 2026
## Summary

When `directConnect(true)` is enabled, appium/java-client unconditionally
accepts `directConnectHost`, `directConnectPort`, and `directConnectPath`
from the server's NEW_SESSION response and silently redirects all subsequent
session traffic to the attacker-specified endpoint — with no …

CVE-2026-43910
NVD

HIGH
CVE-2026-64642
CVE-2026-64642
pkg: vercel next.js

published: Jul 27, 2026

Next.js is a React framework for building full-stack web applications. In versions 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router built with Turbopack and a single entry in config.i18n.locales can bypass middleware/proxy based authentication. This issue has …
CWE: CWE-285
NVD

HIGH
CVE-2026-68581
CVE-2026-68581
pkg: jwt

published: Aug 2, 2026

Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and link-share IDs are independent numeric sequences and both resolve through a generic web.Auth.GetID() interface, a link-share JWT whose numeric ID equals a target user's ID is treat…
CWE: CWE-863
GitHub-GHSA

HIGH
Savon::Model evaluates WSDL operation names as Ruby source
GHSA-mx5j-mp4f-g8jg
pkg: savon
eco: rubygems
published: Jul 31, 2026
### Impact

`Savon::Model` generated SOAP operation methods by interpolating operation names into Ruby source passed to `module_eval`. An attacker who can control the operation names of a WSDL, can inject Ruby code that executes in the application process. This affects only the `.all_operations` cla…

CVE-2026-53510
NVD

HIGH
CVE-2026-67345
CVE-2026-67345
pkg: oauth

published: Jul 30, 2026

MaxKey through 4.1.12, fixed in commit ddbb72f, contains an insufficient redirect URI validation vulnerability in DefaultRedirectResolver.hostMatches() that allows remote attackers to hijack OAuth 2.0 authorization codes by supplying a crafted redirect_uri whose hostname suffix matches a registered …
CWE: CWE-183
NVD

HIGH
CVE-2026-63231
CVE-2026-63231
pkg: jwt

published: Jul 29, 2026

A post-authentication SQL injection
vulnerability in Koollab LMS allowed an authenticated attacker to use an error-based SQL oracle via
the face-to-face runs update endpoint to read the entire application database
and obtain valid JWT tokens for account takeover.
CWE: CWE-89
NVD

HIGH
CVE-2026-14300
CVE-2026-14300
pkg: go

published: Jul 29, 2026

The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) WordPress plugin before 7.8.0 does not bind the one-time code used by its optional email-verification (Profile Completion) feature to the account it was issued for, allowing unauthenticated attackers to obtain a valid sess…
CWE: CWE-287
NVD

HIGH
CVE-2026-54593
CVE-2026-54593
pkg: jwt

published: Jul 28, 2026

Pterodactyl is a free, open-source game server management panel. Prior to Panel version 1.12.3 and Wings version 1.12.2, the Wings /upload/file endpoint accepted any valid panel-signed JWT that contained server_uuid, user_uuid, and unique_id claims without checking the token's intended purpose; beca…
CWE: CWE-1259, CWE-1270
GitHub-GHSA

HIGH
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions
GHSA-8r6w-3qq5-4p4r
pkg: pterodactyl/panel, github.com/pterodactyl/wings
eco: go
published: Jul 28, 2026
### Summary
A privilege escalation vulnerability exists in the Wings /upload/file endpoint due to insufficient validation of panel-signed JWTs. Wings accepts any valid panel-signed JWT containing `server_uuid`, `user_uuid`, and `unique_id`, regardless of the token’s intended purpose. Because the P…
CVE-2026-54593
NVD

HIGH
CVE-2026-64547
CVE-2026-64547
pkg: linux

published: Jul 27, 2026

In the Linux kernel, the following vulnerability has been resolved:

net: usb: net1080: validate packet_len before pad-byte access in rx_fixup

For an even packet_len, net1080_rx_fixup() reads the pad byte at
skb->data[packet_len] before the skb->len != packet_len check further
down, and packet_len …

NVD

HIGH
CVE-2026-64540
CVE-2026-64540
pkg: linux

published: Jul 27, 2026

In the Linux kernel, the following vulnerability has been resolved:

usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup()

genelink_rx_fixup() splits an aggregated RX frame into its individual
packets, using a per-packet length taken from device-supplied data. That
length is only bounded by…

NVD

HIGH
CVE-2026-47873
CVE-2026-47873
pkg: docker

published: Jul 30, 2026

The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of the host's network interfaces (0.0.0.0) rather than restricting them to loopback.
Affected Spring Products and Versions:
Spring Tools for Eclipse: 5.2.0 and earlier
CWE: CWE-1327
NVD

HIGH
CVE-2026-16524
CVE-2026-16524
pkg: linux

published: Jul 30, 2026

A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric.
This failed validation lets attackers execute arbitrary commands as the PMDA user when metrics refresh.
CWE: CWE-78
NVD

HIGH
CVE-2026-17863
CVE-2026-17863
pkg: windows

published: Jul 30, 2026

Inappropriate implementation in Browser in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Medium)
CWE: CWE-269
NVD

HIGH
CVE-2026-17862
CVE-2026-17862
pkg: windows

published: Jul 30, 2026

Use after free in Tracing in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium)
CWE: CWE-416
NVD

HIGH
CVE-2026-17654
CVE-2026-17654
pkg: go

published: Jul 30, 2026

Race in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Critical)
CWE: CWE-362
NVD

HIGH
CVE-2026-64560
CVE-2026-64560
pkg: linux

published: Jul 29, 2026

In the Linux kernel, the following vulnerability has been resolved:

posix-cpu-timers: Prevent UAF caused by non-leader exec() race

Wongi and Jungwoo decoded and reported a non-leader exec() related race
which can result in an UAF:

sys_timer_delete() exec()
posix_cpu_timer_del()
// Observ…

NVD

HIGH
CVE-2026-64559
CVE-2026-64559
pkg: linux

published: Jul 29, 2026

In the Linux kernel, the following vulnerability has been resolved:

s390/pkey: Check length in PKEY_VERIFYPROTK ioctl

Explicitly check the buffer length request structure provided by
user-space and fail, if it exceeds the buffer size.

NVD

HIGH
CVE-2026-64558
CVE-2026-64558
pkg: linux

published: Jul 29, 2026

In the Linux kernel, the following vulnerability has been resolved:

s390/pkey: Check length in pkey_pckmo handler implementation

Explicitly check the length of the target buffer in the pkey_pckmo
implementation of the key_to_protkey() handler function. The handler
function fails, if the generated …

NVD

HIGH
CVE-2026-64556
CVE-2026-64556
pkg: linux

published: Jul 29, 2026

In the Linux kernel, the following vulnerability has been resolved:

perf/core: Detach event groups during remove_on_exec

perf_event_remove_on_exec() removes events by calling
perf_event_exit_event(). For top-level events, this removes the event from
the context with DETACH_EXIT only.

This can lea…

NVD

HIGH
CVE-2026-54656
CVE-2026-54656
pkg: python

published: Jul 28, 2026

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. From 0.52.1 until 0.60.2, datamodel-code-generator interpolates validators from –extra-template-data in src/datamodel_cod…
CWE: CWE-94
NVD

HIGH
CVE-2026-54655
CVE-2026-54655
pkg: python

published: Jul 28, 2026

datamodel-code-generator generates Python data models from schema definitions. From 0.51.0 until 0.60.2, x-python-type values parsed by src/datamodel_code_generator/parser/jsonschema.py in _get_python_type_override are inserted into generated field annotations without sufficient validation, allowing…
CWE: CWE-94
NVD

HIGH
CVE-2026-54654
CVE-2026-54654
pkg: python

published: Jul 28, 2026

datamodel-code-generator generates Python data models from schema definitions. From 0.14.1 until 0.60.2, the –extra-template-data comment field is rendered into Python comments in src/datamodel_code_generator/model/template/TypeAliasAnnotation.jinja2, src/datamodel_code_generator/model/template/Typ…
CWE: CWE-94, CWE-1336
NVD

HIGH
CVE-2026-54621
CVE-2026-54621
pkg: python

published: Jul 28, 2026

datamodel-code-generator generates Python data models from schema definitions. Prior to 0.60.1, GraphQL Union description values in src/datamodel_code_generator/model/template/UnionTypeStatement.jinja2 and src/datamodel_code_generator/model/template/UnionTypeStatement.py312.jinja2 are rendered into …
CWE: CWE-94, CWE-1336
GitHub-GHSA

HIGH
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `–extra-template-data` `comment` field
GHSA-wjv6-jcfj-mf9r
pkg: datamodel-code-generator
eco: pip
published: Jul 28, 2026
### Summary

`datamodel-code-generator` is vulnerable to code injection when a developer passes an `–extra-template-data` file whose `comment` value contains a literal `\r` (carriage return). The `comment` variable is rendered into a Python `#` comment in six built-in templates with **no** line-ter…

CVE-2026-54654
GitHub-GHSA

HIGH
`datamodel-code-generator` vulnerable to code execution on import via unescaped `validators` entries in –extra-template-data
GHSA-8m8r-38jm-f355
pkg: datamodel-code-generator
eco: pip
published: Jul 28, 2026
### Summary

When the Pydantic v2 output mode is in use, `datamodel-code-generator` reads a `validators` array from each model entry in the `–extra-template-data` file and synthesises a Pydantic `@field_validator(…)` decorator from each entry. The field names and the validator mode are interpolat…

CVE-2026-54656
GitHub-GHSA

HIGH
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description
GHSA-j884-q54q-mmx3
pkg: datamodel-code-generator
eco: pip
published: Jul 28, 2026
### Summary

`datamodel-code-generator` is vulnerable to code injection when generating Python models from an attacker-controlled GraphQL schema. A description on a Union type, written in the regular-string form (`"…"`) with a literal `\r` escape, is rendered into a Python `#` comment by a Jinja2 …

CVE-2026-54621
GitHub-GHSA

HIGH
`datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON-Schema extension in datamodel-code-generator
GHSA-m34r-v34r-rf9q
pkg: datamodel-code-generator
eco: pip
published: Jul 28, 2026
### Summary
`datamodel-code-generator` honours a custom `x-python-type` JSON-Schema extension that lets a schema author override the generated Python type for a field. The value is forwarded verbatim into the generated Python source as the field annotation, with a single sanitisation pass that is tr…
CVE-2026-54655
NVD

HIGH
CVE-2026-64543
CVE-2026-64543
pkg: linux

published: Jul 27, 2026

In the Linux kernel, the following vulnerability has been resolved:

tipc: fix use-after-free of the discoverer in tipc_disc_rcv()

bearer_disable() frees b->disc with tipc_disc_delete()'s plain kfree(),
but tipc_disc_rcv() still dereferences b->disc in RX softirq under
rcu_read_lock() (tipc_udp_rec…

NVD

HIGH
CVE-2026-64539
CVE-2026-64539
pkg: linux

published: Jul 27, 2026

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: eir: Fix stack OOB write when prepending the Flags AD

eir_create_adv_data() builds the advertising data into a fixed-size
buffer ("size", 31 for the legacy path). It may prepend a 3-byte "Flags"
AD structure (LE_AD_NO_B…

NVD

HIGH
CVE-2026-24252
CVE-2026-24252
pkg: linux

published: Jul 27, 2026

NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A successful exploit of this vulnerability may lead to code execution, data tampering, escalation of privileges and information disclosure.
CWE: CWE-78
NVD

HIGH
CVE-2026-17523
CVE-2026-17523
pkg: linux

published: Jul 27, 2026

A flaw was found in the Linux kernel in net/can/bcm.c in can: bcm, where an unprivileged local user can exploit this vulnerability to execute arbitrary code within the kernel, which leads to a local privilege escalation (LPE). This allows the attacker to gain root privileges and take full control of…
CWE: CWE-825
GitHub-GHSA

HIGH
FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files
GHSA-vvp7-h4fj-m28w
pkg: github.com/gtsteffaniak/filebrowser/backend
eco: go
published: Jul 31, 2026
### Summary

The `subtitlesHandler` endpoint (`GET /api/media/subtitles`) accepts two user-controlled query parameters: `path` and `name`, both of which are used in filesystem operations without sanitization, creating two independent path traversal vectors.

The primary vector is the `path` paramete…

CVE-2026-54910
GitHub-GHSA

HIGH
Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory
GHSA-q6vm-xqc9-v3ff
pkg: github.com/fission/fission
eco: go
published: Jul 28, 2026
`Unarchive` in `pkg/utils/zip.go` joined each archive entry name with the destination directory via `filepath.Join` and wrote the result without checking whether the resolved path stayed under the destination. A zip entry named
`../../tmp/evil` therefore landed at `/tmp/evil`. An attacker who coul…
CVE-2026-50567
NVD

HIGH
CVE-2026-18381
CVE-2026-18381
pkg: kubernetes

published: Jul 30, 2026

A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary upload URL. The operator attaches its own Kubernetes service-account bearer token to queries sent to this user-con…
CWE: CWE-918
NVD

HIGH
CVE-2026-66427
CVE-2026-66427
pkg: go

published: Jul 27, 2026

Administrator SQL Injection in WP Google Review Slider <= 18.4 versions.
CWE: CWE-89
NVD

HIGH
CVE-2026-53504
CVE-2026-53504
pkg: express

published: Jul 31, 2026

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the convolution filter regular expression performs exponential backtracking on crafted repeated numeric input, allowing a URL request to exhaust processing time. This issue is fixed in 7.8.0.
CWE: CWE-400
GitHub-GHSA

HIGH
Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS
GHSA-phj3-59pf-cp83
pkg: thumbor
eco: pip
published: Jul 31, 2026
### Summary
Thumbor's `filters:proportion(<value>)` filter does not enforce an upper bound on `<value>` and runs in the post-transform phase. An attacker can trigger extremely large resizes (CPU/memory exhaustion) and cause denial of service.

### Details
– Filter implementation: `thumbor/filters/pr…

CVE-2026-53505
GitHub-GHSA

HIGH
Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter
GHSA-5vjc-7cxw-4w6j
pkg: thumbor
eco: pip
published: Jul 31, 2026
### Summary
The regular expression used to parse the `convolution` filter exhibits exponential-time backtracking for certain inputs, enabling a Regular Expression Denial of Service (ReDoS).

### Details
The RegExp for `convolution` is defined as `convolution\((?:\s*((?:[-]?[\d]+\.?[\d]*[;])*(?:[-]?[…

CVE-2026-53504
GitHub-GHSA

HIGH
Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoS
GHSA-cqjp-jf4r-h5q9
pkg: thumbor
eco: pip
published: Jul 31, 2026
### Summary
Thumbor's `filters:convolution(<matrix>, <columns>, <should_normalize>)` filter passes the user-controlled `<columns>` value to a C extension (`thumbor/ext/filters/_convolution.c`) where it is used as a divisor (for `%` and `/`) without validating `columns > 0`. When `columns=0`, the C c…
CVE-2026-53503
GitHub-GHSA

HIGH
Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)
GHSA-93wv-jw9v-4972
pkg: io.netty:netty-codec-http2, io.netty:netty-codec-http2
eco: maven
published: Jul 31, 2026
### Summary

A remote, unauthenticated peer can leak one direct `ByteBuf` per HTTP/2 `DATA` frame in
applications that enable HTTP/2 content decompression via `DelegatingDecompressorFrameListener`.
When a `DATA` frame is processed for a stream whose decompressor has already been closed,
`Http2Decomp…

CVE-2026-56819
GitHub-GHSA

HIGH
Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex
GHSA-fg7f-2386-8897
pkg: nltk
eco: pip
published: Jul 31, 2026
### Summary
`ReviewsCorpusReader` extracts feature annotations of the form *label* followed by a bracketed signed digit (e.g. a label then `[+2]`) from each review line, using the module-level `FEATURES` regex. The feature-label sub-pattern is unbounded — an optional greedy run of word-plus-whites…
CVE-2026-12061
GitHub-GHSA

HIGH
Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)
GHSA-6hm5-jgcp-p838
pkg: nltk
eco: pip
published: Jul 31, 2026
### Summary
A path-traversal vulnerability in `NKJPCorpusReader` allows an attacker who can
influence the `fileids` argument of its public read methods (`header`, `raw`,
`words`, `sents`, `tagged_words`) to read files outside the corpus root. The
reader builds the file path with no conta…
CVE-2026-12072
GitHub-GHSA

HIGH
Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)
GHSA-xh95-f55m-82fw
pkg: nltk
eco: pip
published: Jul 31, 2026
### Summary
`FramenetCorpusReader.frame(name)` interpolates a caller-supplied frame name into an XML file path that is read with the builtin `open()`, bypassing `CorpusReader.open()` and the `nltk.pathsec` sandbox — including strict `ENFORCE=True` mode. A `../` sequence in the name escapes the cor…
CVE-2026-12074
GitHub-GHSA

HIGH
Spring Data: Unbounded property-path cache keyed by externally-supplied path string
GHSA-88fw-v6x4-3f58
pkg: org.springframework.data:spring-data-commons, org.springframework.data:spring-data-commons, org.springframework.data:spring-data-commons
eco: maven
published: Jul 31, 2026
`src/main/java/org/springframework/data/mapping/context/PersistentPropertyPathFactory.java:175` · Unbounded Resource Allocation (Algorithmic DoS)

### Impact

When a consuming module routes user-supplied dot-paths (sort parameters, projection paths, PATCH paths) through `MappingContext.getPersisten…

CVE-2026-41695
GitHub-GHSA

HIGH
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service
GHSA-ghrq-5wpp-hxx5
pkg: github.com/pterodactyl/wings
eco: go
published: Jul 31, 2026
### Summary
A maliciously crafted packet received & parsed during the SFTP connection handshake will cause a Go panic.

### Impact
All wings users with an open SFTP port.

### Workarounds
Close SFTP port.

CVE-2026-52856
NVD

HIGH
CVE-2026-17347
CVE-2026-17347
pkg: windows

published: Jul 31, 2026

The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that returns a per-user encryption key, with %u in the configured string replaced by the current user's name. The previous implementation substituted the username directly into the comm…
CWE: CWE-78, CWE-88
GitHub-GHSA

HIGH
`@dynatrace-oss/dynatrace-mcp-server` has Unauthenticated HTTP MCP Tool Invocation
GHSA-p7w7-4929-vpj5
pkg: @dynatrace-oss/dynatrace-mcp-server
eco: npm
published: Jul 31, 2026
### Summary

`@dynatrace-oss/dynatrace-mcp-server` v1.8.5 exposes an HTTP transport mode (`–http` flag) that performs no authentication, session validation, or origin/host verification before dispatching MCP tool calls. Any network-reachable attacker can send a raw JSON-RPC `tools/call` request wit…

NVD

HIGH
CVE-2026-18446
CVE-2026-18446
pkg: node

published: Jul 31, 2026

fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a reference that uses a backslash based introducer in place of it (backslash backslash, forward slash backslash, or backslash forward slash) is parsed with no authority and folds into the…
CWE: CWE-436
NVD

HIGH
CVE-2026-18358
CVE-2026-18358
pkg: linux

published: Jul 31, 2026

A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the incoming connection handler bypasses the connection throttler, allowing an unauthenticated remote attacker to open many parallel pre-authentication connect…
CWE: CWE-400
NVD

HIGH
CVE-2026-56673
CVE-2026-56673
pkg: node

published: Jul 31, 2026

ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node interface. Prior to 0.28.0, folder_paths.get_annotated_filepath and exists_annotated_filepath join workflow-controlled annotated filenames to a base directory without a containment check, allowing an unauthenticated cra…
CWE: CWE-22
NVD

HIGH
CVE-2026-61536
CVE-2026-61536
pkg: python

published: Jul 30, 2026

Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.3, banks parses Tool JSON objects from the rendered body of {% completion %} blocks and later resolves their import_path field through importlib.import_module(…) + getattr(…) to obtain the callable …
CWE: CWE-94, CWE-470
NVD

HIGH
CVE-2026-15977
CVE-2026-15977
pkg: ssl

published: Jul 30, 2026

SGLang contains a credential leakage vulnerability in the /server_info endpoint, which will return API keys and SSL keyfile information when only the –admin-api-key is configured.
CWE: CWE-522
NVD

HIGH
CVE-2026-62663
CVE-2026-62663
pkg: python

published: Jul 30, 2026

Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.4, all four media filters (image, audio, video, document) in banks accept untrusted user input as file paths via Path(value) and pass them directly to open(file_path, "rb") without any path sanitization…
CWE: CWE-22
GitHub-GHSA

HIGH
MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport
GHSA-h669-8m4g-r2hc
pkg: mcp
eco: rubygems
published: Jul 30, 2026
## Summary

An unauthenticated remote attacker can force any MCP Ruby SDK server using `MCP::Server::Transports::StreamableHTTPTransport` to allocate gigabytes of memory by sending a single oversized JSON-RPC POST. The transport reads the entire HTTP body into a Ruby `String` and parses it with `JSO…

CVE-2026-67432
GitHub-GHSA

HIGH
OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)
GHSA-xpxj-f2fm-rqch
pkg: github.com/OliveTin/OliveTin
eco: go
published: Jul 30, 2026
## Summary

OliveTin's OAuth2 login handler stores per-login state in an in-memory map (`registeredStates`) that grows unboundedly. States are added on every `/oauth/login` request but are **never deleted or expired**. An unauthenticated attacker can send millions of requests to `/oauth/login` to fi…

CVE-2026-67437
NVD

HIGH
CVE-2026-54365
CVE-2026-54365
pkg: windows

published: Jul 30, 2026

CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthenticated attackers to create arbitrary local OS user accounts by supplying a crafted base64-encoded XML string to exposed API endpoints. Attackers can send a malicious StorageConfi…
CWE: CWE-306
NVD

HIGH
CVE-2026-58043
CVE-2026-58043
pkg: node

published: Jul 30, 2026

A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries.

Under `–permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist.

This vu…

CWE: CWE-284
NVD

HIGH
CVE-2026-67437
CVE-2026-67437
pkg: oauth

published: Jul 29, 2026

OliveTin gives access to predefined shell commands from a web interface. From 3000.0.0 until 3000.17.0, the service/internal/auth/otoauth2/restapi_auth_oauth2.go OAuth2 login handler stores per-login state in the registeredStates map on every /oauth/login request without expiring, deleting, or bound…
CWE: CWE-400, CWE-401, CWE-770
GitHub-GHSA

HIGH
Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities
GHSA-qcxp-gm7m-4j5v
pkg: io.quarkus:quarkus-vertx-http, io.quarkus:quarkus-vertx-http, io.quarkus:quarkus-vertx-http
eco: maven
published: Jul 29, 2026
Quarkus HTTP path-based authorization policies can be bypassed using encoded semicolons (%3B) to smuggle matrix
parameters past the security layer, and using encoded slashes (%2F) or backslashes (%5C) to access protected static
resources. This is a distinct issue from CVE-2026-39852, which addre…
CVE-2026-50559
NVD

HIGH
CVE-2026-58161
CVE-2026-58161
pkg: tls

published: Jul 29, 2026

Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handling.

This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix…

CWE: CWE-476
NVD

HIGH
CVE-2026-54719
CVE-2026-54719
pkg: go

published: Jul 28, 2026

goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.1, the httpserver/updown.go bulkDownload handler for ?bulk&file= ZIP downloads did not call findEffectiveACL or applyCustomAuth, allowing unauthenticated reads of files protected only by .goshs folder ACLs…
CWE: CWE-862, CWE-863
NVD

HIGH
CVE-2026-54638
CVE-2026-54638
pkg: go

published: Jul 28, 2026

gotd/td is a T Telegram MTProto API client in Go. Prior to 0.145.1, proto.UnencryptedMessage.Decode in proto/unencrypted_message.go read attacker controlled dataLen from an unauthenticated MTProto unencrypted packet and allocated make([]byte, dataLen) before checking the remaining buffer, allowing r…
CWE: CWE-770, CWE-789
NVD

HIGH
CVE-2026-47219
CVE-2026-47219
pkg: node

published: Jul 28, 2026

find-my-way is a framework-independent HTTP router that internally uses a Radix Tree and supports route parameters and wildcards. Versions prior to 9.7.0 are vulnerable to remotely triggerable DoS in find-my-way when it is used with Node's HTTP/2 server. The lookup() function passes req.method into …
CWE: CWE-20, CWE-248
NVD

HIGH
CVE-2026-55415
CVE-2026-55415
pkg: python

published: Jul 28, 2026

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. From 0.11.6 until 0.64.0, datamodel-code-generator allows attacker-controlled x-python-import or customTypePath schema ext…
CWE: CWE-94, CWE-95
NVD

HIGH
CVE-2026-55390
CVE-2026-55390
pkg: python

published: Jul 28, 2026

datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.62.0, XML Schema parsing in src/datamodel_code_generator/parser/xmlschema.py for –input-file-type xmlschema resolves xs:include, xs:import, xs:redefine, and xs:override schemaLocation values outside t…
CWE: CWE-22, CWE-200, CWE-610
GitHub-GHSA

HIGH
td has pre-auth denial of service via unbounded memory allocation in proto.UnencryptedMessage.Decode
GHSA-whmm-qj9r-wvr2
pkg: github.com/gotd/td
eco: go
published: Jul 28, 2026
### Impact

A remote, unauthenticated attacker can cause excessive memory allocation (and resulting CPU / GC pressure, potentially OOM termination) by sending a crafted unencrypted MTProto packet.

`(*proto.UnencryptedMessage).Decode` read an attacker-controlled 32-bit `dataLen` field and immediatel…

CVE-2026-54638
GitHub-GHSA

HIGH
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx)
GHSA-rmxw-pq4x-3fvh
pkg: github.com/patrickhener/goshs, github.com/patrickhener/goshs/v2, goshs.de/goshs
eco: go
published: Jul 28, 2026
GHSA-wvhv-qcqf-f3cx fixed the per-folder .goshs ACL bypass on the state-changing routes (PUT/POST upload/?mkdir/?delete) and added recursive ACL resolution, and its description states the read/list path correctly enforces .goshs. That premise does not hold for the ?bulk zip-download route. bulkDownl…
CVE-2026-54719
GitHub-GHSA

HIGH
datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `–no-allow-remote-refs`
GHSA-8359-h9fx-j6v9
pkg: datamodel-code-generator
eco: pip
published: Jul 28, 2026
### Summary

`datamodel-code-generator` resolves JSON-Schema `$ref` targets that point at the local filesystem without restricting them to the input/base directory and without honoring the remote-reference security control. In the default configuration, an attacker who controls an input schema (a "p…

CVE-2026-55389
GitHub-GHSA

HIGH
datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding
GHSA-vx7x-vcc2-c44g
pkg: datamodel-code-generator
eco: pip
published: Jul 28, 2026
### Summary

`datamodel-code-generator`'s anti-SSRF guard validates the resolved IP of a fetch target once and then lets `httpx` perform its own independent DNS resolution to connect, so the validated address is never pinned. A hostname that resolves to a public IP at validation time and a private I…

CVE-2026-55391
GitHub-GHSA

HIGH
datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements
GHSA-5578-w22f-pfx9
pkg: datamodel-code-generator
eco: pip
published: Jul 28, 2026
#### Summary

A malicious input schema (OpenAPI / JSON Schema) can execute arbitrary Python code on the machine that **imports** the generated model. The `x-python-import` and `customTypePath` schema extensions flow, unsanitized, into the `import` statements datamodel-code-generator emits. A newline…

CVE-2026-55415
GitHub-GHSA

HIGH
datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate
GHSA-442q-2j6p-642g
pkg: datamodel-code-generator
eco: pip
published: Jul 28, 2026
### Summary

When generating models from an XML Schema (`–input-file-type xmlschema`), `datamodel-code-generator` resolves `<xs:include>`, `<xs:import>`, `<xs:redefine>`, and `<xs:override>` `schemaLocation` attributes against the source directory and reads the target with no restriction to the inp…

CVE-2026-55390
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-32203 – .NET and Visual Studio Denial of Service Vulnerability
GHSA-6588-8gv4-xfgh
pkg: System.Security.Cryptography.Xml, System.Security.Cryptography.Xml, System.Security.Cryptography.Xml
eco: nuget
published: Jul 28, 2026
## Executive Summary:

Microsoft is releasing this security advisory to provide information about a vulnerability in System.Security.Cryptography.Xml. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A vulnerability exists in…

CVE-2026-32203
NVD

HIGH
CVE-2026-54635
CVE-2026-54635
pkg: python

published: Jul 28, 2026

pytonapi is a Python SDK for TONAPI that provides REST API, streaming, and webhook access to the TON blockchain. From 2.0.0 to 2.2.0, TonapiWebhookDispatcher fails to validate the Authorization header when a webhook handler is registered with the documented path argument, because setup() stores bear…
CWE: CWE-287
NVD

HIGH
CVE-2026-67183
CVE-2026-67183
pkg: express

published: Jul 28, 2026

TinyWeb through 0.0.8 contains a memory leak vulnerability that allows unauthenticated attackers to exhaust available memory by sending ordinary well-formed HTTP requests. Each request causes HttpParser::execute() to allocate Url objects, HttpHeaders objects, and HttpHeader instances via raw new exp…
CWE: CWE-401
NVD

HIGH
CVE-2026-67182
CVE-2026-67182
pkg: python

published: Jul 28, 2026

Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability that allows remote attackers to bypass access controls by injecting bare line feed characters (0x0A) into client-supplied request header values that are copied verbatim to upstream connections without validation. Attackers …
CWE: CWE-444
GitHub-GHSA

HIGH
pytonapi has a Webhook Custom Path Authentication Bypass
GHSA-3fcr-jvgp-7f58
pkg: pytonapi
eco: pip
published: Jul 28, 2026
## Webhook Custom Path Authentication Bypass in pytonapi

### Summary

`TonapiWebhookDispatcher` in pytonapi 2.2.0 fails to validate the `Authorization` header when a webhook handler is registered with the documented `path=` argument. During `setup()`, bearer tokens are stored only under the default…

CVE-2026-54635
GitHub-GHSA

HIGH
SIPSorcery: Malformed UDP packet on the RTP/ICE socket can remotely terminate a media session (DoS)
GHSA-28gm-jrmw-xx93
pkg: SIPSorcery
eco: nuget
published: Jul 28, 2026
### Impact

A single malformed inbound UDP packet on the RTP/ICE socket can remotely terminate an active RTP or WebRTC media session. The packet receive handler indexes packet (and STUN attribute) bytes without sufficient length checks and throws, and the UDP receive loop converted any such exceptio…

CVE-2026-54632
NVD

HIGH
CVE-2026-47427
CVE-2026-47427
pkg: go

published: Jul 28, 2026

GitHub MCP Server is GitHub's official MCP Server. Prior to 1.1.0, the CompletionsHandler function in pkg/github/server.go accesses params.Ref without first checking whether it is nil, so a completion/complete request with a missing or empty ref field triggers a nil pointer dereference and a Go runt…
CWE: CWE-476
GitHub-GHSA

HIGH
GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler
GHSA-w4q6-qw23-4rg7
pkg: github.com/github/github-mcp-server
eco: go
published: Jul 28, 2026
### Summary

A nil pointer dereference vulnerability in the GitHub MCP Server causes it to crash when receiving a malformed `completion/complete` request with missing or empty parameters. This allows any unauthenticated client to cause a complete denial of service.

### Details

The `CompletionsHand…

CVE-2026-47427
NVD

HIGH
CVE-2026-15025
CVE-2026-15025
pkg: go

published: Jul 28, 2026

The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.3.2 via the automator_google_contacts_fetch_labels, automator_mautic_segment_fetch, automator_mautic_tags_fetch, and aut…
CWE: CWE-862
NVD

HIGH
CVE-2026-64545
CVE-2026-64545
pkg: linux

published: Jul 27, 2026

In the Linux kernel, the following vulnerability has been resolved:

net, bpf: check master for NULL in xdp_master_redirect()

xdp_master_redirect() dereferences the result of
netdev_master_upper_dev_get_rcu() without a NULL check, but that helper
returns NULL when the receiving device has no upper-…

NVD

HIGH
CVE-2026-64641
CVE-2026-64641
pkg: vercel next.js

published: Jul 27, 2026

Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processing of further reques…
CWE: CWE-834
NVD

HIGH
CVE-2026-45623
CVE-2026-45623
pkg: node

published: Jul 27, 2026

PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. In versions 8.5.11 and prior, the PreviousMap parses the /*# sourceMappingURL=PATH */ comment from any CSS string passed to process() and dereferences PATH against the…
CWE: CWE-22, CWE-200
NVD

HIGH
CVE-2026-66050
CVE-2026-66050
pkg: windows

published: Jul 27, 2026

NitroShare Desktop through 0.3.4 contains a path traversal vulnerability in its LAN file transfer server that allows unauthenticated attackers on the same network to write arbitrary files by sending a crafted filename containing directory traversal sequences in the JSON item header name field. Attac…
CWE: CWE-22
NVD

HIGH
CVE-2026-55969
CVE-2026-55969
pkg: apache thrift

published: Jul 27, 2026

Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe bindings.

This issue affects Apache Thrift: before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.

CWE: CWE-190
NVD

HIGH
CVE-2026-55968
CVE-2026-55968
pkg: apache thrift

published: Jul 27, 2026

Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Node.js bindings.

This issue affects Apache Thrift: before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.

CWE: CWE-407, CWE-770
NVD

HIGH
CVE-2026-48586
CVE-2026-48586
pkg: apache thrift

published: Jul 27, 2026

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings.

This issue affects Apache Thrift: before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.

CWE: CWE-409
NVD

HIGH
CVE-2026-43871
CVE-2026-43871
pkg: apache thrift

published: Jul 27, 2026

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.This issue affects Apache Thrift: before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.

CWE: CWE-835
NVD

HIGH
CVE-2026-41608
CVE-2026-41608
pkg: apache thrift

published: Jul 27, 2026

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings.

This issue affects Apache Thrift: before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.

CWE: CWE-409
NVD

HIGH
CVE-2026-8497
CVE-2026-8497
pkg: tls

published: Jul 29, 2026

Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on Android, iOS, and macOS allows an adjacent-network attacker to intercept and modify sensitive information via a forged TLS certificate.
CWE: CWE-295
NVD

HIGH
CVE-2026-54660
CVE-2026-54660
pkg: axios

published: Jul 29, 2026

swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resolved-swagger-schema.ts getRemoteRequestHeaders forwards –authorizationToken to every URL fetched by fetchRemoteSchemaDocument while warmUpRemoteSchemasCache resolves external $ref …
CWE: CWE-200, CWE-201, CWE-522, CWE-918
GitHub-GHSA

HIGH
swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`
GHSA-h754-fxp7-88wx
pkg: swagger-typescript-api
eco: npm
published: Jul 29, 2026
### Summary

When the developer supplies an `–authorizationToken` (commonly required to fetch a private spec behind authentication), `swagger-typescript-api` attaches that token to the `Authorization` header of **every** subsequent HTTP request it makes while resolving external `$ref` URLs in the s…

CVE-2026-54660
NVD

HIGH
CVE-2026-56822
CVE-2026-56822
pkg: ssl

published: Jul 29, 2026

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator forwards the SslHandshakeCompletionEvent before the asynchronous OCSP validation completes. This allows the client's downstream handlers to send …
CWE: CWE-367
NVD

HIGH
CVE-2026-56821
CVE-2026-56821
pkg: go

published: Jul 29, 2026

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator flags an out-of-date OCSP response but does not stop processing it, so an expired GOOD response is still reported as VALID, letting an on-path at…
CWE: CWE-299
GitHub-GHSA

HIGH
@phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive Property Merging
GHSA-mj3g-7xcc-x4vh
pkg: @phun-ky/defaults-deep
eco: npm
published: Jul 31, 2026
### Impact

A prototype pollution vulnerability exists in @phun-ky/defaults-deep prior to version 2.0.5.

The library recursively merged user-supplied objects without filtering unsafe property names such as `__proto__`, `constructor`, and `prototype`. An attacker able to supply crafted input could c…

CVE-2026-54737
NVD

HIGH
CVE-2026-14893
CVE-2026-14893
pkg: node

published: Jul 28, 2026

IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320 IBM Instana Node.js tracer component @instana/core version 6.2.1 is vulnerable to prototype pollution through its configuration normalization API.
CWE: CWE-1321
NVD

HIGH
CVE-2026-64550
CVE-2026-64550
pkg: linux

published: Jul 27, 2026

In the Linux kernel, the following vulnerability has been resolved:

net: qualcomm: rmnet: validate MAP frame length before ingress parsing

When ingress deaggregation is disabled, rmnet_map_ingress_handler() passes
the skb straight to __rmnet_map_ingress_handler(), skipping the length
validation th…

NVD

HIGH
CVE-2026-67333
CVE-2026-67333
pkg: oauth

published: Aug 1, 2026

better-auth before 1.6.13 (and pre-release builds 1.7.0-beta.0 through 1.7.0-beta.3) fail to validate the scheme of redirect_uris registered via the deprecated oidc-provider plugin and the mcp plugin (which wraps the same provider). An attacker can register an OAuth client with a javascript: redirec…
CWE: CWE-79
GitHub-GHSA

HIGH
Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier
GHSA-rxcw-mc6f-6hr3
pkg: jodit
eco: npm
published: Jul 31, 2026
### Summary
jodit's built-in `clean-html` sanitizer can be bypassed by a MathML/`<style>` carrier that hides a dangerous element from the sanitizer's element walk, so a no-interaction event handler survives into the editor value. When an application supplies attacker-influenced HTML to the editor's …
CVE-2026-58263
NVD

HIGH
CVE-2026-16597
CVE-2026-16597
pkg: go

published: Jul 29, 2026

The GTM4WP – A Google Tag Manager (GTM) plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via WooCommerce Billing Fields in all versions up to, and including, 1.22.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthen…
CWE: CWE-79
NVD

HIGH
CVE-2026-54605
CVE-2026-54605
pkg: oauth

published: Jul 28, 2026

OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. From 0.5.5 to 1.1.5, OAuth::Consumer#token_request parses the raw Location header of a 300 to 399 redirect returned by the OAuth server and follows the redirect recursively, which can mutate the consumer's c…
CWE: CWE-200, CWE-346, CWE-918
GitHub-GHSA

HIGH
OAuth: Cross-origin token-request redirects can expose signed request metadata
GHSA-prq8-7wvh-44qh
pkg: oauth
eco: rubygems
published: Jul 28, 2026
# Cross-origin OAuth token-request redirects can expose signed request metadata

## Summary

When an application uses `OAuth::Consumer` to request OAuth 1.0 request tokens or
access tokens, the token request helper follows `300..399` redirects returned by
the OAuth server. In affected versions, `OAu…

CVE-2026-54605
NVD

HIGH
CVE-2026-55502
CVE-2026-55502
pkg: oauth

published: Jul 31, 2026

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, POST /api/v4/admin/policy/oauth/signin requires only Admin.Read even though GetOauthRedirectService persists caller-supplied OneDrive secret and app_id values, allowing an OAuth token without Admin.Write to modify storag…
CWE: CWE-863
NVD

HIGH
CVE-2026-17811
CVE-2026-17811
pkg: windows

published: Jul 30, 2026

Use after free in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-416
NVD

HIGH
CVE-2026-17744
CVE-2026-17744
pkg: linux

published: Jul 30, 2026

Inappropriate implementation in File Input in Google Chrome on Linux prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-269
GitHub-GHSA

HIGH
@wakaru/cli arbitrary file write during bundle unpack
GHSA-7wpj-vvmv-pgm8
pkg: @wakaru/cli
eco: npm
published: Jul 28, 2026
### Impact

`@wakaru/cli` is vulnerable to arbitrary file write when unpacking a crafted JavaScript bundle with `–unpack`.

Bundle-controlled module filenames were sanitized before writing extracted modules to the output directory. A crafted filename containing overlapping path traversal characters…

CVE-2026-54545
NVD

HIGH
CVE-2026-64546
CVE-2026-64546
pkg: linux

published: Jul 27, 2026

In the Linux kernel, the following vulnerability has been resolved:

drm/edid: fix OOB read in drm_parse_tiled_block()

drm_parse_tiled_block() casts the DisplayID block to a
struct displayid_tiled_block and reads the full fixed layout up to
tile->topology_id[7] without checking block->num_bytes. Th…

NVD

HIGH
CVE-2026-17993
CVE-2026-17993
pkg: google chrome

published: Jul 30, 2026

Race in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Low)
CWE: CWE-362
GitHub-GHSA

HIGH
Thumbor has path traversal via post-validation URL decoding bypass in file_loader
GHSA-cj54-hpcc-gj6h
pkg: thumbor
eco: pip
published: Jul 31, 2026
The file_loader performs `unquote()` on the file path AFTER the `abspath() + startswith()` security check. An attacker can use percent-encoded path traversal sequences (`%2e%2e` for `..`) that pass the security check as literal directory names, but are then decoded to actual `..` traversal sequences…
CVE-2026-53502
GitHub-GHSA

HIGH
hashi-vault-js has a path traversal and query parameter injection
GHSA-g956-2f74-rmv7
pkg: hashi-vault-js
eco: npm
published: Jul 31, 2026
## Summary

The `hashi-vault-js` library is vulnerable to path traversal and query string injection due to the lack of proper encoding of identifiers in path segments and query strings. This allows attackers to manipulate the request URL and potentially access unintended downstream endpoints or inje…

CVE-2026-55100
GitHub-GHSA

HIGH
dssrf: any users using 1.1.1.1 DNS is impacted by SSRF
GHSA-5846-7qm3-r52j
pkg: dssrf
eco: npm
published: Jul 31, 2026
## Summary

is_url_safe can treat localhost as safe when DNS resolver 1.1.1.1 returns NXDOMAIN because dns.resolve4 yields no address and no dns.lookup fallback occurs, allowing server-side request forgery.

## POC

Example to simulate 1.1.1.1 in version before 1.5.0 of dssrf:

“`js
import { is_url…

CVE-2026-54729
GitHub-GHSA

HIGH
dssrf has an SSRF bypass with remove_at_symbol_in_string
GHSA-cg4g-m8jx-vjv2
pkg: dssrf
eco: npm
published: Jul 30, 2026
## Summary

`is_url_safe` in v1.0.3 contains an SSRF bypass. `remove_at_symbol_in_string` is applied to the raw URL string **before** `new URL()` parses it. This strips the `@` that separates userinfo from host, corrupting the hostname so internal IPs are never checked.

## Vulnerability

In `helper…

CVE-2026-54722
GitHub-GHSA

HIGH
MCP Ruby SDK: Ruby SSE Session Poisoning
GHSA-5p9g-j988-pcwv
pkg: mcp
eco: rubygems
published: Jul 30, 2026
### Summary
**Vulnerability**: Missing Session Ownership Validation in the Ruby MCP SDK's Streamable and SSE HTTP transport implementation. Any attacker with a stolen session ID can execute tools with the victim's session. This is a silent attack – the victim's session is compromised and being used …
CVE-2026-67431
GitHub-GHSA

HIGH
netfoil: Incorrect block responses could lead to localhost traffic
GHSA-xvg2-cgv6-6h7v
pkg: github.com/tinfoil-factory/netfoil
eco: go
published: Jul 29, 2026
### Summary
`0.0.0.0` was used instead of NXDOMAIN for block responses. On Linux, which is the target platform for netfoil, the `0.0.0.0` is sent to localhost rather than just dropped.

### Impact
Unintended traffic could be sent to localhost. Impact depends on running services and firewall rules.

GitHub-GHSA

HIGH
ZITADEL Users Can Self-Verify Email/Phone via API
GHSA-jq8w-8q2f-ffm9
pkg: github.com/zitadel/zitadel, github.com/zitadel/zitadel, github.com/zitadel/zitadel
eco: go
published: Jul 29, 2026
### Summary

A vulnerability in Zitadel's self-management capability allowed users to mark their email and phone as verified without going through an actual verification process.

While [`GHSA-282g-fhmx-xf54`](https://github.com/zitadel/zitadel/security/advisories/GHSA-282g-fhmx-xf54) (CVE-2026-2794…

CVE-2026-54693
GitHub-GHSA

HIGH
veraPDF Validation XXE via Rich Text
GHSA-3jh7-wm29-q568
pkg: org.verapdf:validation-model, org.verapdf:validation-model, org.verapdf:validation-model-jakarta
eco: maven
published: Jul 29, 2026
## Summary

**Description**
An XML External Entity Injection (CWE-611) vulnerability in veraPDF allows a remote attacker to read arbitrary files on the server file system and perform Server-Side Request Forgery by submitting a crafted PDF containing a malicious rich-text (/RC or /RV) entry. This…

CVE-2026-54078
GitHub-GHSA

HIGH
veraPDF Validation XXE via XFA
GHSA-36mm-w85j-3q2j
pkg: org.verapdf:validation-model, org.verapdf:validation-model, org.verapdf:validation-model-jakarta
eco: maven
published: Jul 29, 2026
## Summary

**Description**
An XML External Entity Injection (CWE-611) vulnerability in veraPDF allows a remote attacker to read arbitrary files on the server file system and perform Server-Side Request Forgery by submitting a crafted PDF containing a malicious XFA stream. This affects all curre…

CVE-2026-54079
GitHub-GHSA

HIGH
Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions
GHSA-w6p7-2fxx-4f44
pkg: github.com/pocket-id/pocket-id/backend
eco: go
published: Jul 28, 2026
# OIDC Refresh Token Flow Bypasses Authorization Revocation, Account Disabling, and Group Restrictions

## Summary

The `createTokenFromRefreshToken` function (oidc_service.go:451) validates the refresh token's cryptographic integrity but does not re-validate the user's current authorization state b…

CVE-2026-43983
NVD

MEDIUM
CVE-2026-53668
CVE-2026-53668
pkg: react

published: Jul 27, 2026

React Router is a router for React. In versions 6.30.2 through 6.30.4 and 7.9.6 through 7.12.0, applications that allow open redirects are vulnerable to XSS. An attacker could craft a malicious link that redirects users to an unexpected external site or that exploits an XSS vector.This issue has bee…
CWE: CWE-79, CWE-601
NVD

MEDIUM
CVE-2026-53667
CVE-2026-53667
pkg: react

published: Jul 27, 2026

React Router is a router for React. In versions 7.11.0 through 7.17.0, the RSCErrorHandler is missing protocol validation, allowing for redirects from untrusted sources. This issue is a follow up to CVE-2026-53667, and only affects consuming applications if they are using the unstable RSC APIs. This…
CWE: CWE-79
GitHub-GHSA

MEDIUM
Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests
GHSA-68cj-mvg9-rgm2
pkg: github.com/projectcapsule/capsule
eco: go
published: Jul 31, 2026
### Summary

`CapsuleConfiguration.Spec.NodeMetadata.ForbiddenLabels.Regex` and `ForbiddenAnnotations.Regex` are never validated by any admission webhook. A Cluster Admin can persist a malformed regex to etcd without being blocked. Once stored, every Node `CREATE`, `UPDATE`, or `PATCH` request trigg…

CVE-2026-65834
NVD

MEDIUM
CVE-2026-65834
CVE-2026-65834
pkg: kubernetes

published: Jul 30, 2026

Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.8, CapsuleConfiguration.Spec.NodeMetadata.ForbiddenLabels.Regex and CapsuleConfiguration.Spec.NodeMetadata.ForbiddenAnnotations.Regex were not validated by the configuration admission webhook, allowing a Cluster Admi…
CWE: CWE-20, CWE-248
NVD

MEDIUM
CVE-2026-18382
CVE-2026-18382
pkg: oauth

published: Jul 30, 2026

A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary OAuth token endpoint. When authentication.type is set to service-account, the operator sends the tenant's Red Hat SSO client_id and client_s…
CWE: CWE-918
NVD

MEDIUM
CVE-2026-54249
CVE-2026-54249
pkg: python

published: Jul 29, 2026

Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.65.0 through 1.105.0, and 2.0.0b1 through 2.0.0b5, a client that submits message history to a Pydantic AI UI adapter (such as the Vercel AI adapter) can reference arbitrary files in the application's model…
CWE: CWE-918
NVD

MEDIUM
CVE-2026-46678
CVE-2026-46678
pkg: python

published: Jul 29, 2026

Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.56.0 through 1.98.0, when an application opts a URL into force_download='allow-local' (disabling the default block on private/internal IPs), the cloud-metadata blocklist could be bypassed by encoding the m…
CWE: CWE-918
GitHub-GHSA

MEDIUM
NocoBase: Sensitive Data Exposure via SQL Blacklist Bypass
GHSA-v8vm-cqh8-q87q
pkg: @nocobase/plugin-collection-sql, @nocobase/plugin-collection-sql, @nocobase/plugin-collection-sql
eco: npm
published: Jul 28, 2026
# Security Vulnerability Report: Sensitive Data Exposure via SQL Blacklist Bypass

## Summary

The `checkSQL()` function in `plugin-collection-sql` implements a **keyword-based blacklist** to prevent dangerous SQL queries from being executed through the SQL Collection feature. However, the blacklist…

CVE-2026-52888
GitHub-GHSA

MEDIUM
@novu/application-generic: `validateUrlSsrf` permits CGNAT (100.64.0.0/10) destinations — affects Workflow HTTP request step + Webhook filter condition
GHSA-vg6v-j97m-h5xq
pkg: @novu/application-generic
eco: npm
published: Jul 28, 2026
Hi Novu team,

Reporting an SSRF blocklist gap in the shared `validateUrlSsrf` guard. A complete self-contained reproduction is inlined below — copy the four files into a directory and run `docker compose up`, plus a single-file probe that runs against Node directly. Locally validated against HEAD…

GitHub-GHSA

MEDIUM
Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation)
GHSA-jr6p-8pjj-mfx6
pkg: github.com/projectcapsule/capsule
eco: go
published: Jul 31, 2026
### Summary
CVE-2026-22872 (GHSA-qjjm-7j9w-pw72) reported that a Tenant Owner could create cluster-scoped resources
(e.g. `ClusterRole`, `ValidatingWebhookConfiguration`) through a `TenantResource`, because the controller
applies them with its cluster-admin ServiceAccount and `SetNamespace` is ineff…
CVE-2026-65835
NVD

MEDIUM
CVE-2026-65835
CVE-2026-65835
pkg: kubernetes

published: Jul 30, 2026

Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.8, after the incomplete CVE-2026-22872 fix, TenantResource RawItems and Generators in internal/controllers/resources/collect.go, including handleRawItem and handleGeneratorItem, did not apply the ResourceRef…
CWE: CWE-269, CWE-863
GitHub-GHSA

MEDIUM
OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check
GHSA-xc5w-4v5w-7×65
pkg: github.com/OliveTin/OliveTin
eco: go
published: Jul 30, 2026
### Summary
OliveTin's checkShellArgumentSafety() function maintains a blocklist of argument types unsafe for Shell mode actions, but does not include regex:-prefixed types. Because regex: support was added independently via typeSafetyCheckRegex(), any Shell mode action using a regex:-typed argument…
CVE-2026-67438
GitHub-GHSA

MEDIUM
nono-cli'scregistry pack verification can fail open when provenance metadata is absent
GHSA-hc4m-q9jh-xw4j
pkg: nono-cli
eco: rust
published: Jul 28, 2026
## Summary

Registry-installed nono packs are expected to be verified from local provenance metadata before they are used. Two files are relevant:

– `~/.config/nono/packages/lockfile.json`
– `~/.config/nono/packages/<namespace>/<pack>/.nono-trust.bundle`

Testing shows that nono fails closed when a…

GitHub-GHSA

MEDIUM
ImageMagick: Heap Buffer Over-Read in XCF decoder due to integer conversion overflow
GHSA-pjxj-pchx-4c3m
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Jul 31, 2026
An integer overflow in the XCF decoder can result in an out of bounds read when a crafted image is read and that can result in a crash.
CVE-2026-53466
NVD

MEDIUM
CVE-2026-17348
CVE-2026-17348
pkg: node

published: Jul 31, 2026

In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; the application's before_request hook only handles desktop-mode auto-login and the Kerberos/Webserver-auth redirect, so any route shipped without the decorator is reachable without authentication (CWE-…
CWE: CWE-306
NVD

MEDIUM
CVE-2026-18208
CVE-2026-18208
pkg: jwt

published: Jul 31, 2026

A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source identity and access management solution used to secure modern applications and services. The issue occurs when a confidential client, configured to receive signed JWT introspectio…
CWE: CWE-862
NVD

MEDIUM
CVE-2026-64816
CVE-2026-64816
pkg: windows

published: Jul 30, 2026

RapidRAW before 1.6.0 does not validate the lutPath field in preset files before passing it to File::open() in lut_processing.rs. On Windows, a UNC path in lutPath causes an outbound SMB connection to an attacker-controlled host, leaking the victim's NTLMv2 credentials. The vulnerable code path is r…
CWE: CWE-73
NVD

MEDIUM
CVE-2026-17992
CVE-2026-17992
pkg: windows

published: Jul 30, 2026

Uninitialized Use in Skia in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
CWE: CWE-457
NVD

MEDIUM
CVE-2026-17846
CVE-2026-17846
pkg: windows

published: Jul 30, 2026

Inappropriate implementation in Media in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-346
NVD

MEDIUM
CVE-2026-17707
CVE-2026-17707
pkg: windows

published: Jul 30, 2026

Uninitialized Use in Media in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-457
NVD

MEDIUM
CVE-2026-65975
CVE-2026-65975
pkg: python

published: Jul 29, 2026

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.88.0 up to but not including 1.107.1 and 2.0.0b1 up to but not including 2.5.0, the UI adapters (AG-UI via Agent.to_ag_ui()/AGUIAdapter, and Vercel AI via VercelAIAdapter) use sanitize_m…
CWE: CWE-863
GitHub-GHSA

MEDIUM
OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords
GHSA-rwqx-fvqh-6wm4
pkg: io.opentelemetry.javaagent:opentelemetry-javaagent
eco: maven
published: Jul 29, 2026
OpenTelemetry Java Instrumentation JDBC auto-instrumentation may fail to sanitize passwords in SQL CONNECT statements when the password is double-quoted. As a result, clear-text database passwords can be added to trace span attributes and exported to observability backends.
CVE-2026-54704
GitHub-GHSA

MEDIUM
veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When Processing Untrusted PDFs
GHSA-cg9x-g3gm-h5h6
pkg: org.verapdf:validation-model, org.verapdf:validation-model, org.verapdf:validation-model-jakarta
eco: maven
published: Jul 29, 2026
### Summary

veraPDF-validation has an XML External Entity (XXE) vulnerability in two PDF parsing paths (validate and `GFPDAcroForm.getdynamicRender()`). A malicious/crafted PDF supplied to a veraPDF consumer can lead to the expansion of external entities while parsing rich-text annotation/form-fiel…

CVE-2026-54082
NVD

MEDIUM
CVE-2026-66063
CVE-2026-66063
pkg: go

published: Jul 28, 2026

goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/updown.go multipart upload handler split part.FileName() on / but did not reject .., allowing an unauthenticated upload with filename .. to create a file outside the served tree. This iss…
CWE: CWE-22
GitHub-GHSA

MEDIUM
skilo add follows symbolic links, allowing arbitrary local file disclosure from a malicious skill source
GHSA-6xx4-9wp6-65p7
pkg: skilo
eco: rust
published: Jul 28, 2026
### Impact

`skilo add` installs a skill by recursively copying the skill directory into the
target skills directory. The copy routine (`copy_dir_all`) classified each entry
with `std::fs::DirEntry::file_type()` — which does **not** follow symlinks — and
then copied non-directory entries with `s…

GitHub-GHSA

MEDIUM
goshs has a Path Traversal issue
GHSA-wg2q-39h6-66×9
pkg: goshs.de/goshs/v2, github.com/patrickhener/goshs/v2, goshs.de/goshs
eco: go
published: Jul 28, 2026
## Summary

The multipart upload filename fix splits on the path separator but never rejects dot-dot, allowing a write outside the served tree.

## Finding (Medium): upload filename escapes the served tree (residual of CVE-2026-35393)

The multipart filename fix (updown.go lines 135-136) splits on t…

CVE-2026-66063
NVD

MEDIUM
CVE-2026-66749
CVE-2026-66749
pkg: node

published: Jul 28, 2026

Let's Chat 0.4.0 through 0.4.8 contains a null dereference vulnerability that allows authenticated attackers to crash the server by supplying a valid 24-character hex string room parameter that matches no document in the database. Attackers can send a crafted GET /messages request causing an uncaugh…
CWE: CWE-476
NVD

MEDIUM
CVE-2026-62436
CVE-2026-62436
pkg: go

published: Jul 28, 2026

[This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE.]

With the introduction of Grant Table v2 came the requirement to be able to
switch between versions. Switching from v1 to v2 reduces the number of
valid grant references,…

CWE: CWE-362
NVD

MEDIUM
CVE-2026-62435
CVE-2026-62435
pkg: go

published: Jul 28, 2026

[This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE.]

With the introduction of Grant Table v2 came the requirement to be able to
switch between versions. Switching from v1 to v2 reduces the number of
valid grant references,…

CWE: CWE-362
NVD

MEDIUM
CVE-2026-64649
CVE-2026-64649
pkg: vercel next.js

published: Jul 27, 2026

Next.js is a React framework for building full-stack web applications. In versions 14.1.1 through 15.5.20 and 16.0.0 through 16.2.10, when a Server Action forwards or redirects a request, an attacker can cause the server to send that outbound request to a malicious host (Server-Side Request Forgery)…
CWE: CWE-918
GitHub-GHSA

MEDIUM
org.xwiki.contrib:discussions-server has Cross-Site Request Forgery (CSRF) issue that makes it possible to delete messages
GHSA-4j38-rw27-97gx
pkg: org.xwiki.contrib:discussions-server
eco: maven
published: Jul 27, 2026
### Impact
It's possible to forge a request to delete a message.

### Patches
The problem has been patched in version 2.0-rc-1 of Discussion Extension.

### Workarounds
There's no easy workaround except upgrading.

### References
https://jira.xwiki.org/browse/DISCUSSION-22

### For more information…

CVE-2023-37465
NVD

MEDIUM
CVE-2026-67332
CVE-2026-67332
pkg: oauth

published: Aug 1, 2026

@better-auth/oauth-provider before 1.7.0-beta.4 fails to bind access-token audience to the authorization grant, allowing clients to request tokens for unrelated resources. Attackers can complete an OAuth flow and obtain access tokens whose audience targets resource servers the authorization never co…
CWE: CWE-285
NVD

MEDIUM
CVE-2026-58040
CVE-2026-58040
pkg: tls

published: Jul 30, 2026

An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934).

This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.

CWE: CWE-297
GitHub-GHSA

MEDIUM
mathlive's Lack of Escaping of HTML allows for XSS
GHSA-fm7p-gw32-828p
pkg: mathlive
eco: npm
published: Jul 29, 2026
### Summary

Despite the 0.104.0 patch escaping attribute-bearing constructs (`\htmlData`, `\href`), text-content reflection was missed. The `\text{}`, `\mbox{}` commands accept arbitrary characters in their body and emit them raw and unescaped into both the HTML markup and the MathML output, leadin…

CVE-2026-54705
GitHub-GHSA

MEDIUM
gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with_files inline mode
GHSA-c5px-58j2-7fqp
pkg: gemini-bridge
eco: pip
published: Jul 31, 2026
### Summary
`consult_gemini_with_files` in **inline mode** read any file path supplied in
the `files` argument without confining it to the working `directory`, then
forwarded the contents to the Gemini CLI. Because the caller also controls
`query`, the file contents are echoed back through the Gemin…
CVE-2026-54785
GitHub-GHSA

MEDIUM
re2: Global `String.prototype.match` with an empty-matchable pattern never advances → infinite loop with unbounded native memory growth (DoS)
GHSA-6hxr-mr5r-9836
pkg: re2
eco: npm
published: Jul 31, 2026
## Summary

`String.prototype.match` with a **global** `RE2` collects all matches in a native loop that advances the cursor by the match length. A **zero-width (empty) match** has length 0, so the cursor never advances: the same empty match is found forever and appended to an ever-growing native vec…

CVE-2026-68499
NVD

MEDIUM
CVE-2026-68562
CVE-2026-68562
pkg: node

published: Jul 30, 2026

A flaw was found in ansible-collection-redhat-leapp. An attacker with privileged write access to a managed node's Leapp report content can manipulate it. When an operator runs a specific remediation task, this manipulated report can cause the Ansible controller to read its own local files and copy t…
CWE: CWE-610
NVD

MEDIUM
CVE-2026-68499
CVE-2026-68499
pkg: express

published: Jul 30, 2026

re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2's String.prototype.match implementation with a global RE2 pattern that can match the empty string fails to advance its native matching cursor in lib/match.cc, causing an infinite loop and unbounded native …
CWE: CWE-835
GitHub-GHSA

MEDIUM
MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)
GHSA-7683-3w9x-ch42
pkg: mcp
eco: rubygems
published: Jul 30, 2026
## Summary

The stdio transports in `MCP::Server::Transports::StdioTransport` and `MCP::Client::Stdio` read newline-delimited JSON-RPC frames using `IO#gets` with no `limit` argument. CRuby's `IO#gets` with no limit reads from the current position until the next separator (`\n`) with no upper bound …

CVE-2026-63119
NVD

MEDIUM
CVE-2026-54663
CVE-2026-54663
pkg: axios

published: Jul 29, 2026

swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resolved-swagger-schema.ts warmUpRemoteSchemasCache resolves external $ref URLs and fetchRemoteSchemaDocument uses isHttpUrl to fetch any http or https target without private IP, redire…
CWE: CWE-20, CWE-441, CWE-918
GitHub-GHSA

MEDIUM
swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`
GHSA-x36r-4347-pm5x
pkg: swagger-typescript-api
eco: npm
published: Jul 29, 2026
### Summary

`swagger-typescript-api` walks every `$ref` value in the input OpenAPI spec and, for any `$ref` whose target is an `http(s)://` URL, issues an HTTP GET to that URL during generation (`warmUpRemoteSchemasCache`). The only URL filter is a regex that matches `^https?://` — there is **no …

CVE-2026-54663
GitHub-GHSA

MEDIUM
Cosmos-Server has an authentication bypass via forward-auth header smuggling on Constellation tunnel
GHSA-2rx5-2g7j-2659
pkg: github.com/azukaar/cosmos-server
eco: go
published: Jul 28, 2026
### Summary

The Constellation-tunnel bypass branch in `tokenMiddleware` at `src/proxy/routerGen.go:53-66` returns to the upstream handler before the request's `x-cosmos-user`, `x-cosmos-role`, `x-cosmos-user-role`, and `x-cosmos-mfa` headers are stripped at lines 68-72, and before the `AdminOnlyWit…

CVE-2026-49446
NVD

MEDIUM
CVE-2026-65882
CVE-2026-65882
pkg: go

published: Jul 28, 2026

Joomla Extension – joomdle.com – Reflected XSS vulnerability in Joomdle < 3.1.1 – The goto url parameter of the moodle wrapper endpoint allowed a reflected XSS vector.
CWE: CWE-79
NVD

MEDIUM
CVE-2026-42494
CVE-2026-42494
pkg: go

published: Jul 28, 2026

[This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE.]

The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver
derives several lengths directly from attacker-controlled on-disk fields
without validating them:

CWE: CWE-125
NVD

MEDIUM
CVE-2026-53666
CVE-2026-53666
pkg: react

published: Jul 27, 2026

React Router is a router for React. In versions 6.4.0 through 7.17.0, if application code was written in a way that allows attacker-supplied input to overwrite certain aspects of errors caught by the SSR process, then it was possible for an attacker to trigger unexpected constructor execution on the…
CWE: CWE-470
NVD

MEDIUM
CVE-2026-64645
CVE-2026-64645
pkg: vercel next.js

published: Jul 27, 2026

Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a
rewrites() or redirects() rule that builds its external destination hostname from request-controlled input can be pointed at an arbitrary hostname, regardless of t…
CWE: CWE-601, CWE-918
NVD

MEDIUM
CVE-2026-67294
CVE-2026-67294
pkg: tls

published: Aug 1, 2026

FreeRDP before 3.29.0 improperly validates the Extended Key Usage (EKU) purpose of the peer certificate during client-side server TLS authentication. In x509_utils_verify(), when server-purpose (X509_PURPOSE_SSL_SERVER) verification fails, the code falls back to client-purpose and any-purpose verifi…
CWE: CWE-295
GitHub-GHSA

MEDIUM
`nx graph` dev server permissive CORS policy
GHSA-g2r8-wvmj-jf5w
pkg: nx, nx
eco: npm
published: Jul 31, 2026
## Summary

The local HTTP server started by `nx graph` sent `Access-Control-Allow-Origin: *` on every response, letting any website a developer visited read the server's responses cross-origin — including the full project graph and the output of the `/help` endpoint, which runs a target's configu…

CVE-2026-54753
GitHub-GHSA

MEDIUM
Penelope unsafe tar extraction allows arbitrary local file write via crafted session archive
GHSA-f42x-p2mx-hm8r
pkg: penelope-shell-handler
eco: pip
published: Jul 29, 2026
### Summary

Penelope versions prior to 0.19.3 extracted tar archives received from remote sessions without validating archive member paths. When using the affected Unix download path, a malicious or compromised remote session could return a crafted tar archive containing path traversal entries, suc…

CVE-2026-50558
NVD

MEDIUM
CVE-2026-16107
CVE-2026-16107
pkg: tls

published: Jul 28, 2026

IBM TS4500 CLI tool Versions:  0.1.31 through 1.12.0.0 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques.
CWE: CWE-295
NVD

MEDIUM
CVE-2026-66053
CVE-2026-66053
pkg: apache thrift

published: Jul 27, 2026

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings.

This issue affects Apache Thrift: before 0.24.0.

Users are recommended to upgrade to version 0.24.0, which fixes the issue.

This replaces CVE-2026-41603

CWE: CWE-297
NVD

MEDIUM
CVE-2026-17908
CVE-2026-17908
pkg: windows

published: Jul 30, 2026

Insufficient validation of untrusted input in Printing in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
CWE: CWE-20
GitHub-GHSA

MEDIUM
re2: Out-of-bounds heap read in `exec`/`test`/`match` via attacker-influenced `lastIndex` on a non-ASCII subject → uncatchable process crash (DoS)
GHSA-ff84-5f28-78qj
pkg: re2
eco: npm
published: Jul 31, 2026
## Summary

`re2` validates the user-settable `lastIndex` against the subject's **UTF-8 byte length** but then uses it as a **UTF-16 code-unit count** to walk the subject buffer, with no bounds check. For any non-ASCII subject, the byte length is larger than the true character count, so a `lastIndex…

CVE-2026-67550
NVD

MEDIUM
CVE-2026-67550
CVE-2026-67550
pkg: express

published: Jul 30, 2026

re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2 validates lastIndex against the UTF-8 byte length of a subject but uses it as a UTF-16 code-unit offset in exec, test, match, replace, and split, allowing an attacker-influenced lastIndex on a non-ASCII su…
CWE: CWE-125
NVD

MEDIUM
CVE-2026-45376
CVE-2026-45376
pkg: express

published: Jul 31, 2026

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the GET /admin/organization/users search interpolates params[:term] into raw Arel.sql ORDER BY similarity expressions before sanitization, allowing an authenticated organi…
CWE: CWE-89
GitHub-GHSA

MEDIUM
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM
GHSA-q6hh-gp44-4hcm
pkg: github.com/pterodactyl/wings
eco: go
published: Jul 31, 2026
### Summary
Config file parsers, `json`, `yaml`, `xml` etc in parser.go have no file size limit/checks, allowing for a giant config file to potentially OOM the wings process.

### Impact
All wings users who have an egg with a non-`file` parser configuration file setting.

CVE-2026-52857
NVD

MEDIUM
CVE-2026-68563
CVE-2026-68563
pkg: node

published: Jul 30, 2026

A flaw was found in ansible-collection-redhat-leapp. When a remediation task is executed with elevated privileges and the `leapp_old_postgresql_data` option is selected, a PostgreSQL data backup archive is created with insecure permissions. This allows a local non-root user on the managed node to re…
CWE: CWE-732
NVD

MEDIUM
CVE-2026-17932
CVE-2026-17932
pkg: windows

published: Jul 30, 2026

Use after free in DataTransfer in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
CWE: CWE-416
NVD

MEDIUM
CVE-2026-62425
CVE-2026-62425
pkg: go

published: Jul 28, 2026

[This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE.]

The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver
derives several lengths directly from attacker-controlled on-disk fields
without validating them:

CWE: CWE-20
NVD

MEDIUM
CVE-2026-62424
CVE-2026-62424
pkg: go

published: Jul 28, 2026

[This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE.]

The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver
derives several lengths directly from attacker-controlled on-disk fields
without validating them:

CWE: CWE-130
NVD

MEDIUM
CVE-2026-62423
CVE-2026-62423
pkg: go

published: Jul 28, 2026

[This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE.]

The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver
derives several lengths directly from attacker-controlled on-disk fields
without validating them:

CWE: CWE-130
NVD

MEDIUM
CVE-2026-42495
CVE-2026-42495
pkg: go

published: Jul 28, 2026

[This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE.]

The directory and Rock Ridge / SUSP walk in libfsimage's iso9660 driver
derives several lengths directly from attacker-controlled on-disk fields
without validating them:

CWE: CWE-191
GitHub-GHSA

MEDIUM
sanitize-html has incomplete URI scheme validation in that allows javascript: URIs through action, formaction, data, poster, and background attributes
GHSA-vccv-cmxp-4j9h
pkg: sanitize-html
eco: npm
published: Jul 31, 2026
## Summary

sanitize-html uses `allowedSchemesAppliedToAttributes` (default: `['href', 'src', 'cite']`) to gate the `naughtyHref()` function that blocks dangerous URI schemes like `javascript:` and `vbscript:`. The HTML specification defines 10+ attributes that accept URIs (`action`, `formaction`, `…

CVE-2026-53606
GitHub-GHSA

MEDIUM
Jodit has incomplete javascript: scheme normalization in sanitizeHTMLElement href check that allows link XSS
GHSA-j839-gqq4-gf9j
pkg: jodit
eco: npm
published: Jul 31, 2026
### Summary

jodit's `sanitizeHTMLElement` neutralizes a `javascript:` `href` using a bare `href.trim().indexOf('javascript') === 0` check. This omits the normalization jodit applies to every other URL attribute: `isDangerousUrl` strips control bytes with `value.replace(/[\u0000-\u0020]+/g, '')` and…

CVE-2026-62324
GitHub-GHSA

MEDIUM
OnionShare Receive mode writes uploaded files even when file uploads are disabled
GHSA-v833-3823-cmhp
pkg: onionshare-cli
eco: pip
published: Jul 31, 2026
### Summary
OnionShare CLI/Desktop 2.6.3 does not enforce the Receive mode `disable_files` setting at the file upload sink. When a Receive service is configured as a text-message-only endpoint (`–disable-files` / "Disable uploading files"), a remote sender who can reach the OnionShare service can s…
CVE-2026-54707
NVD

MEDIUM
CVE-2026-18266
CVE-2026-18266
pkg: oauth

published: Jul 29, 2026

Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Dify. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicio…
CWE: CWE-601
NVD

MEDIUM
CVE-2026-64648
CVE-2026-64648
pkg: vercel next.js

published: Jul 27, 2026

Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a server-side fetch with a request body may return a cached response body from a different request to the same URL but different body. Confidential data in the POST'…
CWE: CWE-524
NVD

MEDIUM
CVE-2026-64647
CVE-2026-64647
pkg: vercel next.js

published: Jul 27, 2026

Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a server-side fetch with a request body may return a cached response body from a different request to the same URL but different body. Confidential data in the POST's…
CWE: CWE-116
NVD

MEDIUM
CVE-2026-67339
CVE-2026-67339
pkg: curl

published: Aug 1, 2026

guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL handlers. Attackers can capture proxy credentials through origin server access logs when requests are redirected, bypassed, or sent through SOCKS proxies that Guzzle misclassifie…
CWE: CWE-200
NVD

MEDIUM
CVE-2026-67335
CVE-2026-67335
pkg: oauth

published: Aug 1, 2026

better-auth versions before 1.6.2 fail to validate the OAuth state parameter against the stored nonce when using cookie-backed state storage without PKCE. Attackers can forge the state parameter and supply an attacker-controlled authorization code to create authenticated sessions bound to the attack…
CWE: CWE-287
GitHub-GHSA

MEDIUM
Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute
GHSA-34rh-wp3j-6cxc
pkg: github.com/pion/stun/v3, github.com/pion/stun/v2, github.com/pion/stun
eco: go
published: Jul 31, 2026
### Impact
Remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute

### Patches
Upgrade to v3.1.5 or later. This version includes this patch https://github.com/pion/stun/pull/278 which fixes the issue.

### Workarounds
No work around; please upgrade to v3.1.5 or a n…

CVE-2026-54909
GitHub-GHSA

MEDIUM
MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood
GHSA-52jp-gj8w-j6xh
pkg: mcp
eco: rubygems
published: Jul 30, 2026
## Summary

In its default configuration, `MCP::Server::Transports::StreamableHTTPTransport` never expires sessions. Every successful `initialize` request stores a new `ServerSession` and a session record under a fresh UUID, and the only path that removes them is an explicit client-issued HTTP `DELE…

CVE-2026-67430
GitHub-GHSA

MEDIUM
OpenTelemetry Javaagent RMI context propagation allows resource exhaustion
GHSA-fq3f-m5qm-99f5
pkg: io.opentelemetry.javaagent:opentelemetry-javaagent
eco: maven
published: Jul 29, 2026
The RMI context propagation payload reader limits the number of context entries but does not limit the aggregate size of the strings read from the stream.

An attacker who can reach an RMI endpoint on an instrumented JVM can send an oversized context propagation payload. This can cause excessive mem…

CVE-2026-54712
NVD

MEDIUM
CVE-2026-66064
CVE-2026-66064
pkg: go

published: Jul 28, 2026

goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/handler.go sendFile handler opened files using a cleaned path but derived the authorization filename from raw req.URL.Path, so a trailing slash could bypass .goshs ACL-file protection and…
CWE: CWE-41, CWE-863
GitHub-GHSA

MEDIUM
goshs has ACL Bypass & Path Traversal
GHSA-964w-f6gj-5236
pkg: github.com/patrickhener/goshs/v2, goshs.de/goshs/v2, github.com/patrickhener/goshs
eco: go
published: Jul 28, 2026
## Summary

`sendFile` derives the served filename from the raw request path while opening the file from the cleaned path, so appending a trailing slash empties the derived name and defeats both the never-serve rule for the ACL file and the block list.

## Finding (Medium): trailing-slash ACL and h…

CVE-2026-66064
GitHub-GHSA

MEDIUM
Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens
GHSA-5fqm-cc34-fcf5
pkg: github.com/azukaar/cosmos-server
eco: go
published: Jul 28, 2026
### Summary
`GET /cosmos/api/constellation/public-devices` discloses Constellation device metadata to a requester that supplies any non-empty `Authorization` header. The handler strips the string `Bearer ` from the header but never validates the resulting token and never uses it in the database quer…
CVE-2026-49447
NVD

MEDIUM
CVE-2026-64646
CVE-2026-64646
pkg: vercel next.js

published: Jul 27, 2026

Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive memory consumption if that Server Actions uses the Edge…
CWE: CWE-770
NVD

MEDIUM
CVE-2026-64644
CVE-2026-64644
pkg: vercel next.js

published: Jul 27, 2026

Next.js is a React framework for building full-stack web applications. In versions 15.5.0 through 15.5.20 and 16.0.0 through 16.2.10, when self-hosting Next.js with the default image loader, the Image Optimization API can optimize remotely hosted images if configured (not enabled by default). If tho…
CWE: CWE-407
NVD

MEDIUM
CVE-2026-64643
CVE-2026-64643
pkg: vercel next.js

published: Jul 27, 2026

Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, Next.js applications using App Router, Server Actions (use server) or use cache endpoints can be disclosed bypassing any authentication on the pages where these endpo…
CWE: CWE-201
NVD

MEDIUM
CVE-2026-17514
CVE-2026-17514
pkg: node

published: Jul 27, 2026

A vulnerability was determined in ZJONSSON node-unzipper up to 0.12.3. Affected by this vulnerability is the function Extract of the file lib/extract.js. This manipulation causes path traversal. The attack requires local access. The exploit has been publicly disclosed and may be utilized. The projec…
CWE: CWE-22
GitHub-GHSA

MEDIUM
OnionShare follows symlinks in shared directories, allowing unintended disclosure of local files
GHSA-22p9-r2f5-22mf
pkg: onionshare-cli
eco: pip
published: Jul 31, 2026
### Summary
OnionShare CLI/Desktop 2.6.3 can follow symbolic links inside a selected Share or Website directory and serve the symlink target rather than limiting access to files physically contained in the selected directory. If a user shares a directory that contains attacker-supplied or otherwise …
CVE-2026-54706
NVD

MEDIUM
CVE-2026-62845
CVE-2026-62845
pkg: kubernetes

published: Jul 30, 2026

Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, the PostgreSQL and MySQL datastore drivers build DDL statements by interpolating the user-supplied DataStoreUsername/DataStoreSchema directly into SQL via fmt.Sprintf, without escaping identifiers. These fields have no …
CWE: CWE-89
GitHub-GHSA

MEDIUM
@dynatrace-oss/dynatrace-mcp-server has a DQL injection via parameters not documented as DQL
GHSA-pqh8-p93p-2rx7
pkg: @dynatrace-oss/dynatrace-mcp-server
eco: npm
published: Jul 31, 2026
### Summary
A DQL injection vulnerability in several read tools lets a caller bypass the tools' documented field-scope, time-window, and display caps by injecting DQL pipeline stages through parameters typed as identifiers.

### Details
Several tools interpolate caller-supplied parameters directly i…

GitHub-GHSA

MEDIUM
OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output
GHSA-jm28-2wcr-qf3h
pkg: github.com/OliveTin/OliveTin
eco: go
published: Jul 30, 2026
## Summary

The synchronous execution RPCs `StartActionAndWait` and `StartActionByGetAndWait` return the full `LogEntry` for the just-executed action without checking whether the caller is allowed to read that action's logs.

OliveTin's ACL model separates `exec` from `logs`. A deployment can intent…

CVE-2026-67439
NVD

MEDIUM
CVE-2026-17900
CVE-2026-17900
pkg: windows

published: Jul 30, 2026

Inappropriate implementation in Enterprise in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a malicious file. (Chromium security severity: Low)
CWE: CWE-346
NVD

MEDIUM
CVE-2026-17858
CVE-2026-17858
pkg: windows

published: Jul 30, 2026

Uninitialized Use in WebNN in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-457
NVD

MEDIUM
CVE-2026-17790
CVE-2026-17790
pkg: windows

published: Jul 30, 2026

Uninitialized Use in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-457
NVD

MEDIUM
CVE-2026-17706
CVE-2026-17706
pkg: windows

published: Jul 30, 2026

Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-20
NVD

MEDIUM
CVE-2026-17662
CVE-2026-17662
pkg: go

published: Jul 30, 2026

Insufficient policy enforcement in Prefetch in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-346
NVD

MEDIUM
CVE-2026-15831
CVE-2026-15831
pkg: go

published: Jul 29, 2026

GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.3 and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to bypass administrator-configured tool governance policies due to improper authorization enforcement during token …
CWE: CWE-1270
NVD

MEDIUM
CVE-2026-17166
CVE-2026-17166
pkg: go

published: Jul 29, 2026

The Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.3.7. This is due to the plugin not properly verifying that a user is authorized to perform an actio…
CWE: CWE-862
GitHub-GHSA

MEDIUM
Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks
GHSA-vchh-r53j-8mpw
pkg: github.com/fission/fission
eco: go
published: Jul 28, 2026
`HTTPTriggerSpec.Validate()` validated `Methods`, `FunctionReference`, `Host`, `IngressConfig`, and `CorsConfig`, but silently skipped `RelativeURL` and `Prefix`. Those two fields were validated at the CLI level only
(`pkg/fission-cli/cmd/httptrigger/create.go:83`). The post-CRD-modernization webhoo…
CVE-2026-50569
NVD

MEDIUM
CVE-2026-18038
CVE-2026-18038
pkg: go

published: Jul 28, 2026

A flaw has been found in nextlevelbuilder GoClaw up to 3.13.2. Affected by this vulnerability is the function ExecTool.Execute of the file goclaw/internal/http/tools_invoke.go of the component jq Handler. Executing a manipulation can lead to information disclosure. The attack can be launched remotel…
CWE: CWE-200, CWE-284
NVD

MEDIUM
CVE-2026-16587
CVE-2026-16587
pkg: oauth

published: Jul 28, 2026

The Advanced Form Integration — Connect Forms to 200+ Apps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticat…
CWE: CWE-862
NVD

MEDIUM
CVE-2026-59728
CVE-2026-59728
pkg: node

published: Jul 27, 2026

Astro is a web framework for content-driven websites. In versions 1.0.0 through 4.0.18, the source.title and enclosure.type item fields in packages/astro-rss/src/index.ts are interpolated directly into XML template strings without XML-character escaping before being parsed by fast-xml-parser. Both f…
CWE: CWE-91
NVD

MEDIUM
CVE-2026-66428
CVE-2026-66428
pkg: go

published: Jul 27, 2026

Unauthenticated Cross Site Request Forgery (CSRF) in WP Google Review Slider <= 18.4 versions.
CWE: CWE-352
NVD

MEDIUM
CVE-2026-67293
CVE-2026-67293
pkg: tls

published: Aug 1, 2026

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains an improper certificate hostname validation vulnerability. The TLS hostname matcher (tls_match_hostname() in libfreerdp/crypto/tls.c) treats a wildcard pattern such as *.example.com as matching any hostname ending in .example.com, so it in…
CWE: CWE-295
GitHub-GHSA

MEDIUM
@dynatrace-oss/dynatrace-mcp-server has a workflow template injection via create_workflow_for_notification
GHSA-xrmj-5g4g-8987
pkg: @dynatrace-oss/dynatrace-mcp-server
eco: npm
published: Jul 31, 2026
### Summary
A template injection vulnerability in the `create_workflow_for_notification` tool lets a caller embed Jinja2 expressions that the Dynatrace workflow engine evaluates at runtime, exfiltrating event data to attacker-controlled destinations through a workflow that persists in the tenant aft…
NVD

MEDIUM
CVE-2026-17659
CVE-2026-17659
pkg: go

published: Jul 30, 2026

Inappropriate implementation in SiteIsolation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-693
NVD

MEDIUM
CVE-2026-56850
CVE-2026-56850
pkg: tls

published: Jul 30, 2026

A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates.

This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.

CWE: CWE-287
NVD

MEDIUM
CVE-2026-18018
CVE-2026-18018
pkg: windows

published: Jul 30, 2026

Inappropriate implementation in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform UI spoofing via a malicious file. (Chromium security severity: Low)
CWE: CWE-451
GitHub-GHSA

MEDIUM
guard-livereload has a directory traversal vulnerability
GHSA-g65v-27r3-5p6m
pkg: guard-livereload
eco: rubygems
published: Jul 31, 2026
The vulnerability allows remote attackers to read arbitrary files
on the server by exploiting improper path validation in the
livereload server functionality.

This vulnerability is related to the handling of file paths in the
livereload server component, which could allow an attacker to traverse
di…

CVE-2016-1000305
GitHub-GHSA

MEDIUM
core-geonetwork has an Open Redirect Bypass
GHSA-pjp7-q6wp-97qx
pkg: org.geonetwork-opensource:geonetwork, org.geonetwork-opensource:geonetwork, org.geonetwork-opensource:geonetwork
eco: maven
published: Jul 31, 2026
### Summary
GeoNetwork's post-login redirect handling can be bypassed to redirect users to an attacker-controlled external site, even though the code attempts to restrict redirect targets to relative, in-application URLs. This affects both supported SSO login methods: OAuth2/OIDC and Keycloak.

### …

CVE-2026-53573
GitHub-GHSA

MEDIUM
Pion DTLS vulnerable to denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message
GHSA-wg4g-wm44-ch5j
pkg: github.com/pion/dtls/v3
eco: go
published: Jul 31, 2026
### Impact
Remote denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message.

### Patches
Upgrade to v3.1.4 or later. This version includes this patch https://github.com/pion/dtls/pull/839 which fixes the issue.

### Workarounds
No work around; please upgrade to v3.1.4 …

CVE-2026-54908
GitHub-GHSA

MEDIUM
free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure
GHSA-qj55-47fp-p62j
pkg: github.com/free5gc/free5gc, github.com/free5gc/ausf
eco: go
published: Jul 31, 2026
### Summary

The free5GC AUSF (Authentication Server Function) does not validate the `supiOrSuci` field in UE authentication requests. Null bytes (`\x00`) and other control characters pass through JSON parsing unchanged and are forwarded to the UDM in an unescaped URL path. This causes Go's `net/url…

CVE-2026-53551
GitHub-GHSA

MEDIUM
zaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth Limit
GHSA-3whf-vgf2-9w6g
pkg: zaino-state
eco: rust
published: Jul 31, 2026
### Summary
`NonFinalizedState::handle_reorg` is a recursive, unbounded async function that traverses parent blocks until it finds a common ancestor on the main chain. It has **no recursion depth limit** and **no cycle detection**. A malicious or buggy validator can serve a block whose `previous_blo…
GitHub-GHSA

MEDIUM
Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses clean-html sanitization
GHSA-45qg-252v-3f7p
pkg: jodit
eco: npm
published: Jul 31, 2026
A `<script>` element placed directly inside an `<svg>` (or MathML) container was not removed by Jodit's clean-html sanitizer.

The deny/allow tag filter compared `node.nodeName` against an upper-cased tag hash, but foreign (SVG/MathML) elements preserve their original-case node names — an SVG scri…

CVE-2026-65841
GitHub-GHSA

MEDIUM
Jodit has prototype pollution via Jodit.configure() / ConfigMerge
GHSA-5957-5c94-3v7w
pkg: jodit
eco: npm
published: Jul 31, 2026
### Summary
`Jodit.configure(options)` — and the internal `ConfigMerge` / `ConfigProto` helpers — merged user-supplied options into the editor configuration without filtering prototype-mutating keys. A payload nested under an existing plain-object option such as `controls` could reach and mutate…
CVE-2026-54756
GitHub-GHSA

MEDIUM
linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect
GHSA-4jc5-g844-4×33
pkg: linuxfabrik-lib
eco: pip
published: Jul 30, 2026
### Summary
`lib.url.fetch()` follows HTTP redirects (`follow_redirects=True`). httpx strips only `Authorization` and `Cookie` when a redirect crosses the origin, so any other caller-supplied credential header (a session token such as Redfish's `X-Auth-Token`, an API key, …) was still sent to the …
CVE-2026-67435
GitHub-GHSA

MEDIUM
MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection
GHSA-rjr6-rcgv-9m7m
pkg: mcp
eco: rubygems
published: Jul 30, 2026
## Summary

`MCP::Server::Transports::StreamableHTTPTransport` (the Rack-mountable Streamable HTTP transport in the `mcp` gem) processes every incoming JSON-RPC request without ever inspecting the HTTP `Host` or `Origin` request headers. There is no `AllowedHosts`/`AllowedOrigins` allowlist and no D…

CVE-2026-63118
GitHub-GHSA

MEDIUM
olm dependency deprecation: CVE-2022-39255 and CVE-2024-45193
GHSA-wchh-9x6h-7f6p
pkg: matrix-commander
eco: pip
published: Jul 29, 2026
### Problem

Multiple vulnerabilities were disclosed in 2024 affecting libolm (Olm): AES timing / side‑channel, Ed25519 signature malleability, and timing leaks in base64 decoding; several CVEs were assigned. Patches and mitigations were published; maintainers recommend upgrading to fixed versions…

GitHub-GHSA

MEDIUM
veraPDF Parser DoS via PostScript Type 1 Font Programs
GHSA-7c26-995w-6f47
pkg: org.verapdf:parser, org.verapdf:parser
eco: maven
published: Jul 29, 2026
## Summary

**Description**

A PostScript-interpreter-driven Denial of Service (CWE-1325) vulnerability in veraPDF allows a remote attacker to exhaust validator memory or CPU by submitting a PDF whose Type 1 font `/FontFile` is a font program containing attacker-supplied PostScript. veraPDF's Type 1…

CVE-2026-54081
GitHub-GHSA

MEDIUM
veraPDF Parser DoS via PostScript CMap Streams
GHSA-jrmc-qg6p-94fp
pkg: org.verapdf:parser, org.verapdf:parser
eco: maven
published: Jul 29, 2026
## Summary

**Description**

A PostScript-interpreter-driven Denial of Service (CWE-1325) vulnerability in veraPDF allows a remote attacker to exhaust validator memory or CPU by submitting a PDF whose Type 0 font `/Encoding` (or any `/ToUnicode`) is a CMap stream containing attacker-supplied PostScr…

CVE-2026-54080
GitHub-GHSA

MEDIUM
Pagy I18n locale option is not validated before being used in a file path
GHSA-2xmw-f8j8-wfxc
pkg: pagy
eco: rubygems
published: Jul 28, 2026
### Summary

`Pagy::I18n.locale=` did not validate its argument before using it as a
path component to load the matching dictionary file (`<locale>.yml`). An
application that assigns untrusted input to the locale — e.g. the common
pattern `Pagy::I18n.locale = params[:locale]` — let that input in…

CVE-2026-54659
GitHub-GHSA

MEDIUM
GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS
GHSA-g6v3-7xmc-w563
pkg: github.com/gopacket/gopacket
eco: go
published: Jul 28, 2026
## Summary

The sFlow `ExtendedGatewayFlow` record decoder in `github.com/gopacket/gopacket` allocates a slice with `make([]uint32, n)` where `n` is an attacker-controlled 32-bit wire field that has no upper bound. Because the allocation happens *before* the read loop that would consume the correspo…

CVE-2026-54332
GitHub-GHSA

MEDIUM
GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS)
GHSA-6r28-9ppf-4hj5
pkg: github.com/gopacket/gopacket
eco: go
published: Jul 28, 2026
## Summary

The Diameter AVP decoder in `github.com/gopacket/gopacket` computes `dataLength := avp.Length – uint32(headerSize)` without first ensuring `avp.Length >= headerSize`. When the Vendor flag is set, `headerSize` is 12, but the only length guard upstream rejects `avp.Length < 8`. An AVP with…

CVE-2026-54345
GitHub-GHSA

MEDIUM
Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method
GHSA-hp74-gm6m-2qm5
pkg: github.com/pocket-id/pocket-id/backend
eco: go
published: Jul 28, 2026
# Reauthentication Bypass via One-Time Access Token Login

## Summary

A weaker authentication method (OTA token or signup token) is accepted as passkey step-up proof, yielding unauthorized renewable 30-day OIDC refresh tokens for clients explicitly configured with `RequiresReauthentication: true`. …


Vulnerability Digest — July 27, 2026 · 76 Critical · 6 Exploited






Vulnerability Digest — Monday, July 27, 2026


Security Report

Monday, July 27, 2026  ·  Last 7 days  ·  Min severity: MEDIUM
Total Findings
534
Critical
76
High
242
Actively Exploited
6
CISA-KEV6
NVD187
GitHub-GHSA341
Findings sorted by severity
CISA-KEV

CRITICAL
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
CVE-2026-50522
pkg: Microsoft SharePoint

published: Jul 22, 2026

Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Check Point SmartConsole Improper Authentication Vulnerability
CVE-2026-16232
pkg: Check Point SmartConsole

published: Jul 22, 2026

Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
WordPress Core SQL Injection Vulnerability
CVE-2026-60137
pkg: WordPress Core

published: Jul 21, 2026

WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
WordPress Core Interpretation Conflict Vulnerability
CVE-2026-63030
pkg: WordPress Core

published: Jul 21, 2026

WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
CVE-2026-0770
pkg: Langflow Langflow

published: Jul 21, 2026

Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
DD-WRT Stack-Based Buffer Overflow Vulnerability
CVE-2021-27137
pkg: DD-WRT DD-WRT

published: Jul 21, 2026

DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
NVD

CRITICAL
CVE-2026-66012
CVE-2026-66012
pkg: jwt

published: Jul 25, 2026

SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This exposes 31 MCP tools, including a file tool with list/read/write/delete/rename/copy ac…
CWE: CWE-862
GitHub-GHSA

CRITICAL
Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer
GHSA-w28w-gp39-m4p6
pkg: @prompty/core, @prompty/core
eco: npm
published: Jul 24, 2026
## Summary
The TypeScript Nunjucks renderer evaluated untrusted `.prompty` template bodies with unrestricted JavaScript member access. An attacker-controlled template could traverse constructor and prototype properties to execute JavaScript in the host Node.js process.

## Affected packages
– npm `@…

NVD

CRITICAL
CVE-2026-56163
CVE-2026-56163
pkg: kubernetes

published: Jul 24, 2026

Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
CWE: CWE-306
NVD

CRITICAL
CVE-2025-71389
CVE-2025-71389
pkg: react

published: Jul 23, 2026

Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) request handling deserializes attacker-controlled input. A remote attacker can send a crafted RSC request to the server and cause a…
CWE: CWE-94
NVD

CRITICAL
CVE-2026-47668
CVE-2026-47668
pkg: node

published: Jul 23, 2026

DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection in the `functionName` parameter of JSON script `assign` commands. The `functionName` value is interpolated directly into dynamic…
CWE: CWE-20, CWE-94, CWE-1188
NVD

CRITICAL
CVE-2026-46412
CVE-2026-46412
pkg: oauth

published: Jul 20, 2026

@beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support. Between 2026-05-11 20:19 UTC and 22:56 UTC, an attacker used a compromised npm publish token to publish 18 malicious versions of `@beproduct/nestjs-auth` (0.1.2 through 0.1.19). …
CWE: CWE-506
GitHub-GHSA

CRITICAL
@better-auth/scim: account takeover and stale access via SCIM provider-id collision
GHSA-rjg6-39jm-rgg4
pkg: @better-auth/scim, @better-auth/scim
eco: npm
published: Jul 24, 2026
### Am I affected?

You are affected if your application registers the `@better-auth/scim` plugin and lets authenticated users generate SCIM tokens. The default `canGenerateToken` policy was affected, and custom policies were affected when they did not reject provider IDs already used by other accou…

NVD

CRITICAL
CVE-2026-63732
CVE-2026-63732
pkg: node

published: Jul 23, 2026

9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default password (123456) that authenticates any fresh installation, a bypass of the LOCAL_ONLY network gate via a spoofed Host header, and unvalidated arguments passed to child_process.spawn() when registering MCP plu…
CWE: CWE-78
NVD

CRITICAL
CVE-2026-47752
CVE-2026-47752
pkg: docker

published: Jul 23, 2026

Tugtainer is a self-hosted app for automating updates of Docker containers. Versions prior to 1.30.2 are vulnerable to Server-Side Template Injection (SSTI) in the notification template feature. The `title_template` and `body_template` fields are rendered using an unsandboxed `jinja2.Environment`, a…
CWE: CWE-1336
NVD

CRITICAL
CVE-2026-60402
CVE-2026-60402
pkg: kubernetes

published: Jul 21, 2026

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTe…
CWE: CWE-284
NVD

CRITICAL
CVE-2026-47392
CVE-2026-47392
pkg: python

published: Jul 21, 2026

PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praisonaiagents, `execute_code()` in `praisonaiagents/tools/python_tools.py` (v1.6.37, subprocess sandbox mode) can be fully bypassed using `print.__self__` to retrieve the real Python `…
CWE: CWE-184, CWE-693
NVD

CRITICAL
CVE-2026-64459
CVE-2026-64459
pkg: node

published: Jul 25, 2026

In the Linux kernel, the following vulnerability has been resolved:

tcp: restore RCU grace period in tcp_ao_destroy_sock

Commit 51e547e8c89c ("tcp: Free TCP-AO/TCP-MD5 info/keys without RCU")
removed the call_rcu() callback from tcp_ao_destroy_sock(), arguing that
"the destruction of info/keys is …

GitHub-GHSA

CRITICAL
OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback
GHSA-wg5r-wc3x-39vc
pkg: org.openidentityplatform.openam:openam-core
eco: maven
published: Jul 24, 2026
## Summary
A pre-authentication remote code execution vulnerability affects OpenAM. The
remote authentication endpoint (`/authservice`, PLL) accepts an XML element
that names an arbitrary Java class, which the server then loads and
instantiates without validation. On a default configuration this is …
CVE-2026-62379
GitHub-GHSA

CRITICAL
Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix)
GHSA-7gfh-x38p-prh3
pkg: velocityjs
eco: npm
published: Jul 24, 2026
### Summary

Remote Code Execution (RCE) in velocityjs v2.1.6 via property-read to the Function constructor. This bypasses the fix for GHSA-j658-c2gf-x6pq ("Prototype Pollution in #set path assignment") — that advisory blocked constructor/__proto__/prototype only in the #set assignment handler (se…

NVD

CRITICAL
CVE-2026-64232
CVE-2026-64232
pkg: linux

published: Jul 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

block: recompute nr_integrity_segments in blk_insert_cloned_request

blk_insert_cloned_request() already recomputes nr_phys_segments
against the bottom queue, because "the queue settings related to
segment counting may differ from …

NVD

CRITICAL
CVE-2026-64216
CVE-2026-64216
pkg: linux

published: Jul 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

netfs: Fix potential UAF in netfs_unlock_abandoned_read_pages()

netfs_unlock_abandoned_read_pages(rreq) accesses the index of the folios it
is wanting to unlock and compares that to rreq->no_unlock_folio so that it
doesn't unlock …

GitHub-GHSA

CRITICAL
seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization
GHSA-mv8w-475r-vwqw
pkg: seroval
eco: npm
published: Jul 24, 2026
## Summary

A type confusion issue in `seroval.fromJSON()` allowed attacker-controlled JSON input to cause Promise control nodes to operate on values from the general deserialization reference table without first verifying that those values were genuine internal promise resolver records.

In applica…

CVE-2026-59940
NVD

CRITICAL
CVE-2026-15981
CVE-2026-15981
pkg: openssl

published: Jul 23, 2026

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.4. This is due to the mo_saml_validate_signature() function performing a loose boolean check on the raw tri-state integer returned by PHP's openssl_verify(), ca…
CWE: CWE-287
NVD

CRITICAL
CVE-2026-15015
CVE-2026-15015
pkg: oauth

published: Jul 23, 2026

The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to…
CWE: CWE-862
NVD

CRITICAL
CVE-2026-14282
CVE-2026-14282
pkg: go

published: Jul 23, 2026

The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 1.12.2. This is due to insufficient file type validation in the save_video_file() function hoo…
CWE: CWE-434
NVD

CRITICAL
CVE-2026-16606
CVE-2026-16606
pkg: linux

published: Jul 22, 2026

A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for unauthenticated remote code execution (pre-auth RCE) on GNU/Linux or Oracle Solaris. The Fsas Technologies PSIRT obtained that intelligence internally and covers the CVE b…
CWE: CWE-94
GitHub-GHSA

CRITICAL
Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER`
GHSA-f75j-4cw6-rmx4
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
# Summary

The Gitea Docker images ship an `app.ini` template that hard-codes:

“`
REVERSE_PROXY_TRUSTED_PROXIES = *
“`

The documented default for this setting, in `custom/conf/app.example.ini`, is `127.0.0.0/8,::1/128`, i.e. only loopback is trusted.

When an admin enables `ENABLE_REVERSE_PROXY_…

CVE-2026-20896
NVD

CRITICAL
CVE-2026-59147
CVE-2026-59147
pkg: node

published: Jul 21, 2026

Data::DisjointSet::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via an unvalidated parent index in dsu_find.

The attach-time validator dsu_validate_header checks the header scalars and region layout against the file size, but does not validate the array contents it then…

CWE: CWE-125, CWE-787
NVD

CRITICAL
CVE-2026-47410
CVE-2026-47410
pkg: jwt

published: Jul 21, 2026

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an insecure default cryptographic key. The JWT signing secret defaults to the hardcoded literal `"dev-secret-change-me"` when `PLATFORM_JWT_SECRET` is unset. A safety check exists but on…
CWE: CWE-321, CWE-798
NVD

CRITICAL
CVE-2026-47391
CVE-2026-47391
pkg: python

published: Jul 21, 2026

PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's first-party A2A server example exposes an unauthenticated A2A JSON-RPC endpoint and registers a `calculate(expression)` tool implemented with Python `eval()`. The example also binds to `0.0.0.0`. A remote unauthenticated a…
CWE: CWE-95, CWE-306
GitHub-GHSA

CRITICAL
OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check
GHSA-p279-2cqp-84jg
pkg: org.openidentityplatform.opendj:opendj-server-legacy
eco: maven
published: Jul 24, 2026
### Summary
When a SASL PLAIN bind supplies an authorization identity (authzid) that resolves to a **different** user, PlainSASLMechanismHandler verified only the PROXIED_AUTH privilege and never evaluated the "proxy" access-control right (the mayProxy ACI scope check). As a result, any account hold…
GitHub-GHSA

CRITICAL
Budibase: SQL Injection via `multipleStatements: true`
GHSA-q6x4-v3qx-85qw
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
## Summary
A critical SQL injection vulnerability was discovered in Budibase's MySQL integration that allows remote attackers to execute arbitrary SQL commands.

## Details
### Vulnerability Type
SQL Injection

### Description
The MySQL integration component in Budibase is configured with `multipleS…

NVD

CRITICAL
CVE-2026-65606
CVE-2026-65606
pkg: node

published: Jul 23, 2026

SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler. When a siyuan://plugins/<name> link references a name that is not an installed plugin, the application opens a custom tab and inserts the link's icon parameter into the tab header via innerHTML with…
CWE: CWE-79
NVD

CRITICAL
CVE-2026-65605
CVE-2026-65605
pkg: node

published: Jul 23, 2026

SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell rendering. A Template column value is rendered as HTML via text/template without auto-escaping, and EscapeHTML is only applied when HasUnclosedHtmlTag returns true; because balanced self-closi…
CWE: CWE-79
NVD

CRITICAL
CVE-2026-16424
CVE-2026-16424
pkg: google chrome, google android

published: Jul 21, 2026

Use after free in GPU in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

CRITICAL
CVE-2026-16419
CVE-2026-16419
pkg: google chrome, google android

published: Jul 21, 2026

Out of bounds read and write in ANGLE in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-125, CWE-787
GitHub-GHSA

CRITICAL
Gitea: Public-only repository tokens can update private PR head branches
GHSA-xxjv-752h-3vp2
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary
Gitea allows a `public-only,write:repository` token to update a private pull request head branch through a public base repository route.

The vulnerable endpoint is:

“`text
POST /api/v1/repos/{public-owner}/{public-repo}/pulls/{index}/update
“`

Gitea checks the token's public-only re…

CVE-2026-58443
GitHub-GHSA

CRITICAL
Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write
GHSA-hg5r-vq93-9fv6
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary

Gitea Actions Artifacts V4 signed upload/download URLs can be rewritten to access a different running task and repository context while preserving the original HMAC signature. An attacker with permission to run a Gitea Actions job can turn a signed URL for an attacker-controlled artifac…

CVE-2026-58426
GitHub-GHSA

CRITICAL
Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter
GHSA-2r5c-gw76-rh3w
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
## Summary

Gitea's default SSRF allow-list ([`MatchBuiltinExternal`](https://github.com/go-gitea/gitea/blob/4c37f4dacbac022f7beca75272439331f0368830/modules/hostmatcher/hostmatcher.go#L26-L27), used by both webhook delivery and repository migrations) relies on Go's standard library [`net.IP.IsPriva…

CVE-2026-22874
NVD

CRITICAL
CVE-2026-15901
CVE-2026-15901
pkg: google chrome

published: Jul 20, 2026

Use after free in Network in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

CRITICAL
CVE-2026-15900
CVE-2026-15900
pkg: google chrome, google android

published: Jul 20, 2026

Use after free in GPU in Google Chrome on Android prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

CRITICAL
CVE-2026-15899
CVE-2026-15899
pkg: go

published: Jul 20, 2026

Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
GitHub-GHSA

CRITICAL
OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway
GHSA-68r5-9hpg-7qw9
pkg: org.openidentityplatform.opendj:opendj-dsml-servlet
eco: maven
published: Jul 24, 2026
The DSMLv2 SOAP gateway (opendj-dsml-servlet) in OpenIdentityPlatform OpenDJ through 5.1.1 dereferences attacker-supplied xsd:anyURI values server-side without a scheme allowlist, egress filtering, or a size cap, and is reachable without authentication by default. A remote unauthenticated attacker c…
GitHub-GHSA

CRITICAL
LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests
GHSA-6x6h-qqr7-855w
pkg: lightrag-hku
eco: pip
published: Jul 20, 2026
### Summary
The server defaults to CORS_ORIGINS=* combined with allow_credentials=True. Starlette's CORSMiddleware echoes the requesting origin in preflight responses when credentials are enabled, meaning every origin is effectively whitelisted for credentialed cross-origin requests. Any malicious w…
CVE-2026-61736
GitHub-GHSA

CRITICAL
sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock
GHSA-vh45-f885-3848
pkg: sm-crypto
eco: npm
published: Jul 24, 2026
## Summary

`sm-crypto` (npm package **0.4.0**, the latest release, published 2026-01-20)
generates SM2 private keys and signing ephemeral scalars from a single
module-wide RNG instance (`src/sm2/utils.js`: `const rng = new SecureRandom()`).
`SecureRandom` is jsbn's PRNG, which seeds an **ARC4** str…

NVD

CRITICAL
CVE-2026-48021
CVE-2026-48021
pkg: tls

published: Jul 24, 2026

In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU handshake with attacker-controlled keys and obtain the session encryption keys. All inner HTTP traffic (patient consent decisions, medication data, docum…
CWE: CWE-295, CWE-347
GitHub-GHSA

CRITICAL
kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default
GHSA-r277-6w6q-xmqw
pkg: github.com/getkin/kin-openapi
eco: go
published: Jul 24, 2026
### Summary
`ValidationHandler.Load()` in `getkin/kin-openapi` silently replaces a nil `AuthenticationFunc` with `NoopAuthenticationFunc`, which always returns `nil` without performing any credential check. Because this substitution happens unconditionally when the caller omits the field, every Open…
NVD

CRITICAL
CVE-2026-60267
CVE-2026-60267
pkg: tls

published: Jul 21, 2026

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle…
CWE: CWE-284
NVD

CRITICAL
CVE-2026-47731
CVE-2026-47731
pkg: python

published: Jul 21, 2026

The AMMOS Instrument Toolkit (Formerly the Bespoke Links to Instruments for Surface and Space (BLISS)) is a Python-based software suite developed to handle Ground Data System (GDS), Electronic Ground Support Equipment (EGSE), commanding, telemetry uplink/downlink, and sequencing for instrument and C…
CWE: CWE-22
NVD

CRITICAL
CVE-2026-59141
CVE-2026-59141
pkg: node

published: Jul 21, 2026

Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated node and arena indices in rdx_find_locked.

The attach-time validator rdx_validate_header checks the header scalars and region layout against the file size, but does not validate the node records it the…

CWE: CWE-125
NVD

CRITICAL
CVE-2026-59140
CVE-2026-59140
pkg: node

published: Jul 21, 2026

Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds read via unvalidated node indices in the rank and min/max query paths.

The attach-time validator ss_validate_header bounds only the root index against the node pool (node_capacity). The order-statistics and min/max queries…

CWE: CWE-125
NVD

CRITICAL
CVE-2026-28321
CVE-2026-28321
pkg: solarwinds serv-u

published: Jul 21, 2026

SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate privileges and execute code as root. A domain administrator access is required, and the impact is lower in Windows installations.
CWE: CWE-284
NVD

CRITICAL
CVE-2026-28317
CVE-2026-28317
pkg: solarwinds serv-u

published: Jul 21, 2026

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires domain administrator access. The impact is lower in Windows deployments.
CWE: CWE-639
NVD

CRITICAL
CVE-2026-28316
CVE-2026-28316
pkg: solarwinds serv-u

published: Jul 21, 2026

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability to execute commands as the root user. This issue requires a domain account with administrator access. The impact is lower in Wind…
CWE: CWE-639
NVD

CRITICAL
CVE-2026-28314
CVE-2026-28314
pkg: solarwinds serv-u

published: Jul 21, 2026

SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. User authentication is required. The impact is lower in Windows deployments.
CWE: CWE-639
NVD

CRITICAL
CVE-2026-28313
CVE-2026-28313
pkg: solarwinds serv-u

published: Jul 21, 2026

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary account takeover. The impact is lower in Windows deployments.
CWE: CWE-639
NVD

CRITICAL
CVE-2026-28312
CVE-2026-28312
pkg: solarwinds serv-u

published: Jul 21, 2026

SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system administrator and allow code execution as root. The impact is lower in Windows deployments.
CWE: CWE-285
NVD

CRITICAL
CVE-2026-28310
CVE-2026-28310
pkg: solarwinds serv-u

published: Jul 21, 2026

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate their user type to that of a system administrator. The impact is lower in Windows deployments.
CWE: CWE-862
NVD

CRITICAL
CVE-2026-28309
CVE-2026-28309
pkg: solarwinds serv-u

published: Jul 21, 2026

SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts. The impact is lower in Windows deployments.
CWE: CWE-862
NVD

CRITICAL
CVE-2026-28308
CVE-2026-28308
pkg: solarwinds serv-u

published: Jul 21, 2026

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrator access is required. The impact is lower in Windows deployments.
CWE: CWE-639
NVD

CRITICAL
CVE-2026-28307
CVE-2026-28307
pkg: solarwinds serv-u

published: Jul 21, 2026

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an administrator group. The impact is lower in Windows deployments.
CWE: CWE-284
NVD

CRITICAL
CVE-2026-28306
CVE-2026-28306
pkg: solarwinds serv-u

published: Jul 21, 2026

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a system administrator. The impact is lower in Windows deployments.
CWE: CWE-284
NVD

CRITICAL
CVE-2026-28305
CVE-2026-28305
pkg: solarwinds serv-u

published: Jul 21, 2026

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution as root. A domain account with admin privileges and read and write access to the home directory is required. The impact is lower in Windows deployments.
CWE: CWE-639
NVD

CRITICAL
CVE-2026-28304
CVE-2026-28304
pkg: solarwinds serv-u

published: Jul 21, 2026

SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary execution of code remotely as root. The impact is lower in Windows deployments.
CWE: CWE-284
NVD

CRITICAL
CVE-2026-28302
CVE-2026-28302
pkg: solarwinds serv-u

published: Jul 21, 2026

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root. This issue requires group administrator access. The impact is lower in Windows deployments.
CWE: CWE-639
GitHub-GHSA

CRITICAL
Shescape: Shell injection via unescaped parentheses on Windows with CMD
GHSA-w4hw-qcx7-56pr
pkg: shescape, shescape
eco: npm
published: Jul 24, 2026
### Impact

This impacts users of Shescape on Windows that explicitly configure `shell` to CMD, or `true` with the default shell being CMD, using the `escape` and `escapeAll` APIs.

An attacker may be able to achieve shell injection depending on the original command.

“`javascript
import * as cp fr…

GitHub-GHSA

CRITICAL
Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak
GHSA-mqhr-6j6h-74p5
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
## Summary
Budibase attaches a REST datasource's stored credentials (Bearer/Basic tokens and static headers) to an outgoing request before it decides which host the request goes to, and never checks that the destination host matches the datasource. A query's request path can be pointed at any host (…
GitHub-GHSA

CRITICAL
Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified
GHSA-hp6v-6jw7-gv2f
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
### Summary
Budibase's OIDC SSO login links an incoming SSO identity to an existing Budibase account **by email address alone**, without ever checking the `email_verified` claim of the OIDC ID token. Budibase first tries to match the IdP `sub`; when that misses (any fresh attacker IdP account) it si…
GitHub-GHSA

CRITICAL
OpenAM: WebAuthn Java deserialization RCE via ObjectInputFilter depth>1 bypass
GHSA-gf8h-gq53-288j
pkg: org.openidentityplatform.openam:openam-auth-webauthn
eco: maven
published: Jul 24, 2026
### Summary
The GHSA-6c99-87fr-6q7r fix wrapped WebAuthn authenticator deserialization in an `ObjectInputFilter` meant to allow only `AuthenticatorImpl`, but it short-circuits to `ALLOWED` for any object at stream `depth > 1`. Because the Java serialization filter is consulted for every class in the…
CVE-2026-62263
GitHub-GHSA

CRITICAL
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
GHSA-hq9q-27g5-qwpj
pkg: Microsoft.OpenApi.Kiota, Microsoft.OpenApi.Kiota.Builder
eco: nuget
published: Jul 24, 2026
### Summary

`kiota info` — the command developers run to learn which packages to install after generating a client —
read the `x-ms-kiota-info` extension from the OpenAPI description and presented the spec-supplied
`dependencyInstallCommand` (and dependency `name`/`version`) **as the tool's own…

CVE-2026-59865
GitHub-GHSA

CRITICAL
Microsoft Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions
GHSA-4jwf-m4wg-8p66
pkg: Microsoft.OpenApi.Kiota, Microsoft.OpenApi.Kiota.Builder
eco: nuget
published: Jul 24, 2026
### Summary

`kiota plugin add` / `kiota plugin generate` (with `-t APIPlugin`) emits an attacker-controlled `static_template.file` path from the AI-plugin extensions (`x-ai-adaptive-card`, `x-ai-capabilities`) **verbatim**, with no path validation, into the generated Microsoft 365 Copilot / Teams p…

CVE-2026-59864
GitHub-GHSA

CRITICAL
Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)
GHSA-8fpg-xm3f-6cx3
pkg: next-auth
eco: npm
published: Jul 23, 2026
### Impact

`next-auth` (Auth.js) v5 applications that gate access by checking only for the **existence** of the `auth` object — the pattern shown in the official [session management / protecting resources guide](https://authjs.dev/getting-started/session-management/protecting) — are affected.

GitHub-GHSA

CRITICAL
Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
GHSA-7rqj-j65f-68wh
pkg: @auth/core, next-auth, next-auth
eco: npm
published: Jul 23, 2026
## Summary

The default email-address normalizer used by the email/magic-link sign-in flow validates the address **before** applying Unicode normalization. An address can contain a Unicode character that is not an ASCII `@` (U+0040) but canonicalizes to one under NFKC/NFKD normalization (the normali…

GitHub-GHSA

CRITICAL
Gitea Remember-Me Token Theft Not Invalidating Attacker Session
GHSA-rgv6-xp99-6mgj
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
The vulnerability is in the Remember-Me (gitea_incredible) token validation logic, specifically when handling a compromised token (hash mismatch).

The vulnerable function is this one:

https://github.com/go-gitea/gitea/blob/689ace1ce28fd74244b8aa335d9928cdbf6b22f9/services/auth/auth_token.go#L33-L6…

CVE-2026-56750
GitHub-GHSA

CRITICAL
LightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection
GHSA-f4vv-55c2-5789
pkg: lightrag-hku
eco: pip
published: Jul 20, 2026
## Summary

When LightRAG is deployed with `LIGHTRAG_API_KEY` set but `AUTH_ACCOUNTS` unset (an officially documented "API-Key authentication" mode), the `X-API-Key` protection can be bypassed by any remote unauthenticated attacker. The bypass does not require network contact with the victim server …

CVE-2026-61740
NVD

HIGH
CVE-2024-58355
CVE-2024-58355
pkg: react

published: Jul 23, 2026

Cal.com (calcom/cal.diy) versions through 4.7.15 contain a stored cross-site scripting vulnerability. The single booking view (e.g., https://app.cal.com/booking/<id>) renders booking-question field labels via React's dangerouslySetInnerHTML without sanitizing or escaping user input. An attacker who …
CWE: CWE-80
NVD

HIGH
CVE-2024-58353
CVE-2024-58353
pkg: react

published: Jul 23, 2026

Cal.com (repository calcom/cal.diy) in versions <= 4.7.15 is vulnerable to cross-site scripting (XSS) on the publicly accessible single booking view (e.g., /booking/<id>). Booking question (form field) labels are rendered via React's dangerouslySetInnerHTML without proper input sanitization or CSP, …
CWE: CWE-80
GitHub-GHSA

HIGH
Gitea: Permanent Fork PR Workflow Approval Gate Bypass
GHSA-777r-4v59-6486
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
| Field | Value |
|——-|——-|
| **Identifier (researcher-assigned)** | GITEA-2026-004 |
| **Product** | Gitea (self-hosted Git service) |
| **Component** | Gitea Actions — fork pull request approval gate |
| **Affected versions** | All Gitea releases **`v1.20.0` and later**, including the la…
CVE-2026-58424
NVD

HIGH
CVE-2026-64467
CVE-2026-64467
pkg: node

published: Jul 25, 2026

In the Linux kernel, the following vulnerability has been resolved:

rust_binder: use a u64 stride when cleaning up the offsets array

Allocation's Drop walks the offsets array (binder_size_t = u64 entries),
cleaning up the objects, but it used usize instead of u64 for both the
stride and the per-en…

NVD

HIGH
CVE-2026-64394
CVE-2026-64394
pkg: windows

published: Jul 25, 2026

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: add a WRITE_DAC/WRITE_OWNER check to SMB2 SET_INFO SECURITY

commit cc57232cae23 ("ksmbd: fix FSCTL permission bypass by adding a
permission check for FSCTL_SET_SPARSE") added a fp->daccess gate to
fsctl_set_sparse and noted…

GitHub-GHSA

HIGH
Budibase: Privilege escalation via public role assignment API missing app-level authorization
GHSA-j9fc-w3mr-x6mv
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
### Summary

Budibase `3.39.19` (commit `03fbabae4`) is affected by a privilege-escalation / missing-authorization flaw in the public role-assignment API. An **app-scoped builder** (a user who builds only specific apps — `user.builder.apps = [appA]`, not a global builder or admin) can grant **them…

GitHub-GHSA

HIGH
GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution
GHSA-r9mr-m37c-5fr3
pkg: GitPython
eco: pip
published: Jul 24, 2026
## Summary
GitPython's `check_unsafe_options` guard (the control introduced by CVE-2026-42215 / GHSA-2f96 and hardened since) can be bypassed for **every** guarded method (`clone`/`clone_from`, `fetch`/`pull`/`push`, `ls_remote`, `iter_commits`, `blame`, `archive`) by smuggling an option token insid…
GitHub-GHSA

HIGH
Ray: Arbitrary code execution via ray.data.read_webdataset default decoder: pickle.loads(value) and torch.load(weights_only=False)
GHSA-hhrp-gw25-jr43
pkg: ray
eco: pip
published: Jul 24, 2026
## Summary

`ray.data.read_webdataset(paths=…)` is a `@PublicAPI(stability="alpha")`
reader for WebDataset-format TAR files. Its default `decoder=True` invokes
`_default_decoder` on every sample's keys, which routes file extension to a
decoder by extension. Two of those branches deserialize attack…

CVE-2026-57516
NVD

HIGH
CVE-2026-16745
CVE-2026-16745
pkg: kubernetes

published: Jul 23, 2026

A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized…
CWE: CWE-346
NVD

HIGH
CVE-2025-44089
CVE-2025-44089
pkg: express

published: Jul 22, 2026

An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.
CWE: CWE-693
NVD

HIGH
CVE-2026-16423
CVE-2026-16423
pkg: google chrome

published: Jul 21, 2026

Use after free in UI in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-16421
CVE-2026-16421
pkg: google chrome

published: Jul 21, 2026

Inappropriate implementation in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-20
NVD

HIGH
CVE-2026-16420
CVE-2026-16420
pkg: google chrome

published: Jul 21, 2026

Type Confusion in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-843
NVD

HIGH
CVE-2026-16418
CVE-2026-16418
pkg: google chrome

published: Jul 21, 2026

Stack buffer overflow in V8 in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-121
NVD

HIGH
CVE-2026-60400
CVE-2026-60400
pkg: go

published: Jul 21, 2026

Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle GoldenGate. Succe…
CWE: CWE-284
NVD

HIGH
CVE-2026-60398
CVE-2026-60398
pkg: go

published: Jul 21, 2026

Vulnerability in Oracle GoldenGate (component: Oracle GoldenGate Microservices). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle GoldenGate.…
CWE: CWE-306
NVD

HIGH
CVE-2026-60157
CVE-2026-60157
pkg: go

published: Jul 21, 2026

Vulnerability in Oracle GoldenGate (component: Service Manager). Supported versions that are affected are 19.1.0.0.0-19.29.0.0, 21.3-21.21 and 23.4-23.26.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle GoldenGate. Successful…
CWE: CWE-284
GitHub-GHSA

HIGH
Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write
GHSA-649p-mmhf-85c7
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
## Vulnerability Header

| Field | Value |
| ——————- | ———————————————————————————– |
| Vulnerability Title | Cached Per-Branch Permission Ch…

CVE-2026-27775
GitHub-GHSA

HIGH
GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
GHSA-2f96-g7mh-g2hx
pkg: GitPython
eco: pip
published: Jul 21, 2026
## Command injection via long-option prefix abbreviation bypassing `check_unsafe_options` (incomplete fix of CVE-2026-42215 / GHSA-rpm5-65cw-6hj4)

**Component:** gitpython-developers/GitPython (PyPI: GitPython)
**Affected:** all versions carrying the 3.1.47 blocklist fix, through current `main` (ve…

NVD

HIGH
CVE-2026-55084
CVE-2026-55084
pkg: express

published: Jul 21, 2026

DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. A SQL injection vulnerability was identified in the SqlView API endpoint of the DHIS2 application in the `filter` parameter used by the
`/api/sqlViews/{viewId}/data.json` endpoint. An authen…
CWE: CWE-89
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-47300 – .NET Elevation of Privilege Vulnerability
GHSA-8prm-248r-h957
pkg: Microsoft.AspNetCore.Authentication.Negotiate, Microsoft.AspNetCore.Authentication.Negotiate, Microsoft.AspNetCore.Authentication.Negotiate
eco: nuget
published: Jul 21, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core Negotiate Authentication (Microsoft.AspNetCore.Authentication.Negotiate). This advisory also provides guidance on what developers can do to update their applications to re…

CVE-2026-47300
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-47303 – .NET Elevation of Privilege Vulnerability
GHSA-2p3q-h3hg-jcqq
pkg: Microsoft.AspNetCore.Authentication.Negotiate, Microsoft.AspNetCore.Authentication.Negotiate, Microsoft.AspNetCore.Authentication.Negotiate
eco: nuget
published: Jul 21, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core Negotiate Authentication (Microsoft.AspNetCore.Authentication.Negotiate). This advisory also provides guidance on what developers can do to update their applications to re…

CVE-2026-47303
NVD

HIGH
CVE-2026-15904
CVE-2026-15904
pkg: google chrome, linux linux_kernel

published: Jul 20, 2026

Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.128 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-15903
CVE-2026-15903
pkg: google chrome

published: Jul 20, 2026

Out of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-125, CWE-787, CWE-125, CWE-787
NVD

HIGH
CVE-2026-15902
CVE-2026-15902
pkg: google chrome

published: Jul 20, 2026

Use after free in Cast in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-12341
CVE-2026-12341
pkg: oauth

published: Jul 20, 2026

This vulnerability
impacts all versions of IdentityIQ and allows an unauthenticated attacker
unauthorized access to protected APIs and data due to improper validation of
OAuth bearer tokens.
CWE: CWE-287
NVD

HIGH
CVE-2026-64206
CVE-2026-64206
pkg: linux

published: Jul 20, 2026

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock

l2cap_conn_del() takes conn->lock and then calls cancel_work_sync() for
pending_rx_work. process_pending_rx() takes the same mutex, so teardown
can deadlock agains…

NVD

HIGH
CVE-2026-25039
CVE-2026-25039
pkg: windows

published: Jul 20, 2026

Parsec is a cloud-based application for simple and cryptographically secure file sharing. The application does not sanitize the workspace name, creating a vulnerability if that workspace name is a UNC path. When creating mountpoint in the windows filesystem to mount the workspace of an organization,…
CWE: CWE-40
NVD

HIGH
CVE-2026-65908
CVE-2026-65908
pkg: python

published: Jul 23, 2026

In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open
CWE: CWE-829
GitHub-GHSA

HIGH
Budibase: SSRF via DNS rebinding in the REST datasource integration
GHSA-v42f-v8xc-j435
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
### Summary
Budibase's central outbound-fetch guard (`fetchWithBlacklist`) prevents SSRF/DNS-rebinding by resolving the target hostname, checking every resolved IP against the blacklist, and **pinning** the connection to the validated IP. The pin is implemented as a Node `http(s).Agent` (`makePinned…
GitHub-GHSA

HIGH
Budibase: DNS rebinding SSRF bypasses remain in OpenAPI import and REST query execution
GHSA-xg5g-26×8-cvf4
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
## Impact

A builder-level user can make Budibase issue server-side HTTP requests to loopback or private-network targets by using DNS rebinding against two outbound fetch paths that are still not pinned to the validated DNS answer.

The first path is OpenAPI query import. It validates the supplied h…

NVD

HIGH
CVE-2026-17107
CVE-2026-17107
pkg: kubernetes

published: Jul 24, 2026

A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first removing caller-supplied values, and the spoke Servi…
CWE: CWE-441
GitHub-GHSA

HIGH
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration
GHSA-82f7-87hm-852x
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
# Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration

## Summary

Gitea validates the user-supplied repository migration URL, but the actual clone and later mirror fetch operations are performed by the Git command-line clie…

CVE-2026-57894
NVD

HIGH
CVE-2026-64806
CVE-2026-64806
pkg: node

published: Jul 23, 2026

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter
CWE: CWE-829
GitHub-GHSA

HIGH
GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`
GHSA-956x-8gvw-wg5v
pkg: GitPython
eco: pip
published: Jul 21, 2026
## Summary

GitPython spawns the real `git` binary with an argument vector built from caller-supplied values. To prevent argument injection, GitPython maintains denylists of "unsafe" Git options (`–upload-pack`, `–receive-pack`, `–exec`, `-c`, `–config`, …) that can be abused to run arbitrary …

NVD

HIGH
CVE-2026-64824
CVE-2026-64824
pkg: docker

published: Jul 21, 2026

Home Assistant Core before 2026.7.0 contains a path traversal vulnerability in the backup-restore function that allows attackers to write files to arbitrary absolute filesystem paths by supplying a crafted tar archive with a SYMTYPE entry containing a benign member name paired with an absolute linkn…
CWE: CWE-22
NVD

HIGH
CVE-2026-28220
CVE-2026-28220
pkg: node

published: Jul 20, 2026

Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.14.5, issues in the Cluster Distributed API (DAPI) handling allow a cluster peer, or any actor able to authenticate to the cluster channel using the shared cluster key, to make the master…
CWE: CWE-502
NVD

HIGH
CVE-2026-17497
CVE-2026-17497
pkg: python

published: Jul 26, 2026

NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore invoke plugin:shell|execute to run attacker-controlled operating …
CWE: CWE-78, CWE-276, CWE-1249
GitHub-GHSA

HIGH
Budibase: NoSQL Injection via JSON Parameter Interpolation in MongoDB Query Execution
GHSA-qw6m-8fw2-2v64
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
## Summary

Budibase's MongoDB query execution endpoint (`POST /api/v2/queries/:queryId`) is vulnerable to NoSQL injection through user-supplied query parameters. The `enrichContext()` function interpolates parameter values into JSON query templates using Handlebars with `noEscaping: true`, then par…

GitHub-GHSA

HIGH
Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in
GHSA-qq9h-g4jm-xgf3
pkg: better-auth, better-auth
eco: npm
published: Jul 24, 2026
### Am I affected

You are affected if all of the following hold:

– You run a `better-auth` version below 1.6.22, or a `1.7.0-beta` below `1.7.0-beta.10`.
– You enable the magic-link plugin or the email-OTP plugin.
– You also enable email and password sign-up with open registration.
– An account ca…

NVD

HIGH
CVE-2026-16416
CVE-2026-16416
pkg: google chrome

published: Jul 21, 2026

Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High)
CWE: CWE-190
NVD

HIGH
CVE-2026-16413
CVE-2026-16413
pkg: google chrome

published: Jul 21, 2026

Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-787
NVD

HIGH
CVE-2026-47688
CVE-2026-47688
pkg: node

published: Jul 21, 2026

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `clearAES` and `clearPMTasks` methods in `FOGPage` can be invoked by an unauthenticated attacker via a single HTTP GET request through the public `client` node e…
CWE: CWE-862
GitHub-GHSA

HIGH
Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`
GHSA-xj96-63gp-2gmr
pkg: Pillow
eco: pip
published: Jul 20, 2026
### Summary

Pillow's public rank-filter API can trigger a native heap out-of-bounds write
when given a very large odd filter size.

Minimal public API trigger:

“`python
from PIL import Image, ImageFilter

im = Image.new("L", (3, 3), 128)
im.filter(ImageFilter.MedianFilter(4294967295))
“`

`Image…

CVE-2026-59197
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-50528 – .NET Security Feature Bypass Vulnerability
GHSA-qvw7-jm5c-6hqw
pkg: Microsoft.NetCore.App.Runtime.linux-arm, Microsoft.NetCore.App.Runtime.linux-arm64, Microsoft.NetCore.App.Runtime.linux-musl-arm
eco: nuget
published: Jul 20, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET TLS/SSL (System.Net.Security). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A security feature bypass…

CVE-2026-50528
NVD

HIGH
CVE-2026-47255
CVE-2026-47255
pkg: tls

published: Jul 20, 2026

AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0.9.10 had weakness related to validation and and binding of inactive-agent hour filtering; storage SQL identifier validation; metadata-backed ownership…
CWE: CWE-20, CWE-89, CWE-284, CWE-319, CWE-798
GitHub-GHSA

HIGH
File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup
GHSA-fmm7-x4gx-8jhr
pkg: github.com/filebrowser/filebrowser/v2
eco: go
published: Jul 20, 2026
## Summary

A scoped, non-admin File Browser user holding only the **Create** permission can delete arbitrary files outside their scope (other tenants' data, and the application's own database) via the upload failure-cleanup path. This is an incomplete fix of CVE-2026-54094: the v2.63.14 `ScopedFs` …

CVE-2026-55667
NVD

HIGH
CVE-2026-54342
CVE-2026-54342
pkg: tls

published: Jul 24, 2026

In epa4all, prior to version 2026-05-20, an attacker on the network path between epa4all and any backend (ePA Aktensystem, Konnektor, IDP, TSS) can present a self-signed TLS certificate and intercept the connection. For non-VAU connections (Konnektor, IDP), this allows direct read and modification o…
CWE: CWE-295
GitHub-GHSA

HIGH
GitPython: Arbitrary file overwrite via git diff –output argument injection in Diffable.diff (key- and value-controlled)
GHSA-fjr4-x663-mwxc
pkg: GitPython
eco: pip
published: Jul 24, 2026
## Summary
`Diffable.diff()` forwards `**kwargs` straight into `diff`/`diff_tree` with **no** `check_unsafe_options` guard. `Diffable` is mixed into `Commit`, `Tree`, `IndexFile`, and `Submodule`, giving a broad surface. `git diff –output=<path>` writes real patch content to an attacker-chosen path…
NVD

HIGH
CVE-2026-64235
CVE-2026-64235
pkg: linux

published: Jul 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

x86/ftrace: Relocate %rip-relative percpu refs in dynamic trampolines

With CONFIG_CALL_DEPTH_TRACKING enabled on an x86 retbleed-affected platform
(eg: Skylake), with retbleed=stuff, registering a dynamic ftrace trampoline
crashes…

NVD

HIGH
CVE-2026-64223
CVE-2026-64223
pkg: linux

published: Jul 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

wifi: mac80211: consume only present negotiated TTLM maps

ieee80211_tid_to_link_map_size_ok() validates negotiated TTLM elements
against the number of link-map entries indicated by link_map_presence.
ieee80211_parse_neg_ttlm() mus…

NVD

HIGH
CVE-2026-61106
CVE-2026-61106
pkg: go

published: Jul 21, 2026

Vulnerability in Oracle GoldenGate (component: Config Service Executable). Supported versions that are affected are 23.4-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GoldenGate. Successful attacks of this vulnerabilit…
CWE: CWE-284, CWE-306
GitHub-GHSA

HIGH
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)
GHSA-vrhc-jjfc-m3m3
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
## Description

Gitea's OAuth2 sign-in callback reactivates a deactivated user account (`IsActive=false`) when the user signs in through an authentication source that does not issue refresh tokens (notably GitHub, and any OIDC/OAuth2 source configured without `offline_access`). PR #38009 added a gat…

CVE-2026-55987
GitHub-GHSA

HIGH
Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
GHSA-w5pg-649r-p6gg
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
## Summary

Gitea does not re-evaluate the `official` flag on existing pull request reviews when a PR's target branch is changed. An attacker with write access to a repository can obtain an `official: true` approval on a PR targeting an unprotected branch, then retarget the PR to a protected branch …

CVE-2026-58439
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-47304 – .NET Security Feature Bypass Vulnerability
GHSA-g8r8-53c2-pm3f
pkg: System.Security.Cryptography.Xml, System.Security.Cryptography.Xml, System.Security.Cryptography.Xml
eco: nuget
published: Jul 20, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET XML Encryption (System.Security.Cryptography.Xml). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A sec…

CVE-2026-47304
GitHub-GHSA

HIGH
File Browser: Colliding username normalization gives two users the same home directory
GHSA-7rc3-g7h6-22m7
pkg: github.com/filebrowser/filebrowser/v2
eco: go
published: Jul 20, 2026
## Summary

FileBrowser confines each user to a *scope*: a home directory that acts as the boundary for everything they can read or write. When self-registration and automatic home-directory creation are both enabled (`Signup=true` and `CreateUserDir=true`), a new user's scope is built from their us…

CVE-2026-62685
GitHub-GHSA

HIGH
Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)
GHSA-j657-m4c4-24jq
pkg: open-webui
eco: pip
published: Jul 24, 2026
## Summary

The terminal proxy in `backend/open_webui/routers/terminals.py` forwards the Open WebUI user's identity to the upstream terminal server / backend coordinator as an authorization claim, with no cryptographic binding to the session that produced it. The forwarded identity is attacker-influ…

CVE-2026-59224
NVD

HIGH
CVE-2026-61224
CVE-2026-61224
pkg: tls

published: Jul 21, 2026

Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Security). The supported version that is affected is 8.3. Difficult to exploit vulnerability allows high privileged attacker with network access via TLS to compromise Oracle Communi…
CWE: CWE-284
NVD

HIGH
CVE-2026-47237
CVE-2026-47237
pkg: kubernetes

published: Jul 21, 2026

Kubeflow Community Distribution helps users to install Kubeflow Platform in popular Kubernetes clusters. Prior to version 26.03-rc.1, a Kubeflow setup based on the official manifests or most other packaged Kubeflow distributions is vulnerable to authorization token stealing from any user of the Kube…
CWE: CWE-266
NVD

HIGH
CVE-2026-64418
CVE-2026-64418
pkg: node

published: Jul 25, 2026

In the Linux kernel, the following vulnerability has been resolved:

mm: shrinker: fix shrinker_info teardown race with expansion

expand_shrinker_info() iterates all visible memcgs under shrinker_mutex,
including memcgs that have not finished ->css_online() yet.

Once pn->shrinker_info has been pub…

NVD

HIGH
CVE-2026-64361
CVE-2026-64361
pkg: node

published: Jul 25, 2026

In the Linux kernel, the following vulnerability has been resolved:

hfs/hfsplus: fix u32 overflow in check_and_correct_requested_length

check_and_correct_requested_length() compares (off + len) against
node_size using u32 arithmetic. When the caller passes a large len
value (e.g. from an underflo…

NVD

HIGH
CVE-2026-64293
CVE-2026-64293
pkg: express

published: Jul 25, 2026

In the Linux kernel, the following vulnerability has been resolved:

iommufd: Use sizeof(*hdr) instead of sizeof(hdr) in veventq read

The bound-check in iommufd_veventq_fops_read() for the normal vEVENT
path uses sizeof(hdr) where the surrounding code uses sizeof(*hdr):

if (!vevent_for_lost_event…

NVD

HIGH
CVE-2026-64277
CVE-2026-64277
pkg: node

published: Jul 25, 2026

In the Linux kernel, the following vulnerability has been resolved:

Input: synaptics-rmi4 – bound the F3A keymap to the GPIO count

rmi_f3a_initialize() takes the GPIO count from the device query register
(f3a->gpio_count = buf & RMI_F3A_GPIO_COUNT, range 0..127).
rmi_f3a_map_gpios() then allocates…

GitHub-GHSA

HIGH
Oh My Posh: Arbitrary command execution via template injection in the path segment
GHSA-6xj8-qv9j-xcjq
pkg: github.com/jandedobbeleer/oh-my-posh
eco: go
published: Jul 24, 2026
### Summary
Oh My Posh re-renders the resolved path string, which contains the raw folder names taken from the filesystem, through the Go `text/template` engine. That engine's function map exposes a `cmd` function that runs arbitrary OS commands. A directory whose name contains a Go template express…
NVD

HIGH
CVE-2025-71408
CVE-2025-71408
pkg: express

published: Jul 24, 2026

NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls command-line arguments to execute arbitrary Python code. When collocations.py is invoked directly, the __main__ block passes command-line…
CWE: CWE-95
NVD

HIGH
CVE-2026-64226
CVE-2026-64226
pkg: linux

published: Jul 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

sched_ext: Avoid UAF in scx_root_enable_workfn() init failure path

In scx_root_enable_workfn(), put_task_struct(p) is called before scx_error()
dereferences p->comm and p->pid. If the iterator's reference is the last
drop, the tas…

NVD

HIGH
CVE-2026-64221
CVE-2026-64221
pkg: linux

published: Jul 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

spi: ti-qspi: fix use-after-free after DMA setup failure

The driver falls back to PIO mode if DMA setup fails during probe.

Make sure to clear the DMA channel pointer also if buffer allocation
fails to avoid passing a pointer to …

NVD

HIGH
CVE-2026-64218
CVE-2026-64218
pkg: linux

published: Jul 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

batman-adv: bla: fix report_work leak on backbone_gw purge

batadv_bla_purge_backbone_gw() removes stale backbone gateway entries,
but fails to properly handle their associated report_work:

– If report_work is running, the purge m…

NVD

HIGH
CVE-2026-64217
CVE-2026-64217
pkg: linux

published: Jul 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

netfs: Fix overrun check in netfs_extract_user_iter()

Fix netfs_extract_user_iter() so that if iov_iter_extract_pages() overfills
pages[], then those pages don't get included in the iterator constructed at
the end of the function.…

GitHub-GHSA

HIGH
electron-updater: Uncontrolled search path elements within `AppImage` built by `app-builder-lib`
GHSA-7g7r-gx96-252g
pkg: app-builder-lib
eco: npm
published: Jul 24, 2026
### Summary

`AppImage` targets built by `app-builder-lib` could use an empty path component when setting the `LD_LIBRARY_PATH` environment variable at runtime. This causes the current working directory to be added to the dynamic linker search path, which may allow an attacker to execute arbitrary c…

CVE-2026-54672
NVD

HIGH
CVE-2026-64802
CVE-2026-64802
pkg: go

published: Jul 23, 2026

In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration
CWE: CWE-94
NVD

HIGH
CVE-2026-64600
CVE-2026-64600
pkg: linux

published: Jul 23, 2026

In the Linux kernel, the following vulnerability has been resolved:

xfs: resample the data fork mapping after cycling ILOCK

xfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode,
a data fork mapping, and a cow fork mapping. Unfortunately, these two
helpers cycle the ILOCK to grab …

NVD

HIGH
CVE-2026-16607
CVE-2026-16607
pkg: linux

published: Jul 22, 2026

A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for local privilege escalation to root of an already authenticated user on GNU/Linux or Oracle Solaris. The Fsas Technologies PSIRT obtained that intelligence internally and…
CWE: CWE-269
NVD

HIGH
CVE-2026-16414
CVE-2026-16414
pkg: google chrome

published: Jul 21, 2026

Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High)
CWE: CWE-20
NVD

HIGH
CVE-2026-60570
CVE-2026-60570
pkg: go

published: Jul 21, 2026

Vulnerability in Oracle GoldenGate (component: Libraries). Supported versions that are affected are 23.4-23.26.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle GoldenGate executes to compromise Oracle GoldenGate. Successful attacks of…
NVD

HIGH
CVE-2026-47054
CVE-2026-47054
pkg: windows

published: Jul 21, 2026

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle …
CWE: CWE-269
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-50650 – .NET Elevation of Privilege Vulnerability
GHSA-2969-4q4w-w5h3
pkg: Microsoft.WindowsDesktop.App.Runtime.win-x64, Microsoft.WindowsDesktop.App.Runtime.win-x86, Microsoft.WindowsDesktop.App.Runtime.win-arm64
eco: nuget
published: Jul 21, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in Windows Presentation Foundation (WPF). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

An elevation of privil…

CVE-2026-50650
NVD

HIGH
CVE-2026-15905
CVE-2026-15905
pkg: google chrome

published: Jul 20, 2026

Use after free in Aura in Google Chrome prior to 150.0.7871.128 allowed a local attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-64191
CVE-2026-64191
pkg: linux

published: Jul 20, 2026

In the Linux kernel, the following vulnerability has been resolved:

i2c: stub: Reject I2C block transfers with invalid length

The I2C_SMBUS_I2C_BLOCK_DATA case in stub_xfer() uses data->block[0]
as the transfer length. The existing check only clamps it to avoid
overrunning the chip->words[256] reg…

NVD

HIGH
CVE-2026-64189
CVE-2026-64189
pkg: linux

published: Jul 20, 2026

In the Linux kernel, the following vulnerability has been resolved:

netfilter: ipset: fix race between dump and ip_set_list resize

The release path of ip_set_dump_do() and ip_set_dump_done() read
inst->ip_set_list via ip_set_ref_netlink(), a plain rcu_dereference_raw()
of the array pointer. These …

NVD

HIGH
CVE-2026-64188
CVE-2026-64188
pkg: linux

published: Jul 20, 2026

In the Linux kernel, the following vulnerability has been resolved:

net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink()

rmnet_dellink() removes the endpoint from the hash table with
hlist_del_init_rcu() and then immediately frees it with kfree(). However,
RCU readers on the receiv…

GitHub-GHSA

HIGH
Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF)
GHSA-pvcr-8mvp-w8qr
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
### Summary

The Budibase AI chat-link handoff flow (`GET/POST /api/chat-links/:instance/:token/handoff`) binds an **external chat identity** (Slack/Discord/MS Teams/Telegram) to a **Budibase user account**. The confirmation endpoint is on a **public route** (no CSRF middleware, no auth-group gate) …

GitHub-GHSA

HIGH
Budibase: S3 presigned URL endpoint authorization regression in v3.39.4 allows BASIC users to obtain S3 PutObject presigned URLs
GHSA-xcx6-4f2g-hhgx
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
## Impact

In Budibase v3.39.4, a regression in the authorization level for the S3 attachment upload endpoint allows any BASIC app user to obtain S3 PutObject presigned URLs. The endpoint uses TABLE/WRITE permission level instead of the intended BUILDER level defined in v3.39.3. Additionally, the co…

GitHub-GHSA

HIGH
open-webui terminal proxy path traversal guard bypass via 9x encoded traversal
GHSA-frvj-c5qp-xj4w
pkg: open-webui
eco: pip
published: Jul 24, 2026
AI assistance was used to help inspect the code and prepare this report.

## Summary

The fix for GHSA-r2wg-2mcr-66rv is incomplete in v0.9.6 and current main. `backend/open_webui/routers/terminals.py` documents `_sanitize_proxy_path()` as decoding until stable, but the implementation stops after 8 …

CVE-2026-59221
GitHub-GHSA

HIGH
Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id
GHSA-74h3-cxq7-vc5q
pkg: open-webui
eco: pip
published: Jul 24, 2026
## Summary

An authenticated low-privilege user can execute arbitrary code-interpreter Python and tools inside **another** user's authenticated session. The Socket.IO event-caller (`get_event_call`) delivers `execute:python` / `execute:tool` events to a **client-supplied** `session_id` after only ch…

CVE-2026-59216
GitHub-GHSA

HIGH
Gitea: Two SSRF findings
GHSA-2fcr-jfvc-vgg2
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
| — | — |
| Versions tested | `gitea/gitea:1.26.2` (digest `sha256:7d13848af12645600a5f9d93ee2560daa9c6fa6b5b859b7bff3a5e1c0b661031`); `gitea/gitea:latest` resolves to the same digest at time of writing |
| Source review | `git checkout v1.26.2` (commit `2c749ce`) |
| Reproduction | `bash run_po…
CVE-2026-58314
GitHub-GHSA

HIGH
Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories
GHSA-7wvc-rvp7-w99x
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary

A flaw in SSH LFS sub-verb handling allows any authenticated SSH user to obtain valid LFS credentials for any repository on the instance, including private repositories they have no access to. This enables unauthorized download of all LFS objects from any private repository.

### Detail…

CVE-2026-58423
NVD

HIGH
CVE-2026-46555
CVE-2026-46555
pkg: docker

published: Jul 20, 2026

WhatsApp MCP Server is a Model Context Protocol (MCP) server for WhatsApp, enabling Claude to read and send WhatsApp messages. Prior to version 0.2.1, the `whatsapp-bridge` HTTP API listens on `127.0.0.1:8080` without authentication and without Host header validation, and the `/api/send` endpoint ac…
CWE: CWE-22, CWE-306, CWE-346
NVD

HIGH
CVE-2026-54910
CVE-2026-54910
pkg: jwt

published: Jul 20, 2026

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.4.3-beta, the `subtitlesHandler` endpoint (`GET /api/media/subtitles`) accepts two user-controlled query parameters: `path` and `name`, both of which are used in filesystem operations without sanitization, creatin…
CWE: CWE-22, CWE-23
GitHub-GHSA

HIGH
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal
GHSA-95cv-r8x4-vh75
pkg: github.com/OpenListTeam/OpenList/v4
eco: go
published: Jul 24, 2026
### Summary

The `/api/fs/batch_rename` handler validates and authorizes only the requested source directory. It rejects path separators in `new_name`, but it does not validate `src_name`. The handler concatenates `src_dir` and attacker-controlled `src_name`, then passes the result to the filesystem…

GitHub-GHSA

HIGH
Budibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database Connector
GHSA-2xgg-r2wc-c5r2
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
### Summary
**This is a related but independently fixable vulnerability to GHSA-qqf5-x7mj-v43p
(PostgreSQL SQL injection), reported in the same original disclosure and
split per GitHub CNA guidance (rule 4.2.11) since it affects a separate
integration, has a distinct attack precondition, and require…
GitHub-GHSA

HIGH
Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim
GHSA-vgj4-345g-jcf8
pkg: github.com/cloudreve/Cloudreve/v4
eco: go
published: Jul 20, 2026
## Summary

Cloudreve's OAuth access tokens can bypass OAuth scope enforcement.

This does not appear to be the intended design. The documentation describes OAuth client permissions/scopes, the API
has an insufficient-scope error code, and the code comments say `RequiredScopes(…)` should ver…

CVE-2026-54560
NVD

HIGH
CVE-2026-63720
CVE-2026-63720
pkg: express

published: Jul 26, 2026

datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who control input schemas to achieve remote code execution by supplying a malicious customBasePath value containing embedded newlines and a dot-free Python expression. The crafted value is …
CWE: CWE-94
GitHub-GHSA

HIGH
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
GHSA-jvxp-qmx7-gjpx
pkg: aws-smithy-http-server
eco: rust
published: Jul 24, 2026
## Summary
Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits…
CVE-2026-16756
GitHub-GHSA

HIGH
libp2p: yamux connection DoS via oversized data frame
GHSA-hmj8-5xmh-5573
pkg: libp2p
eco: pip
published: Jul 24, 2026
### Summary
The yamux stream multiplexer in py-libp2p does not validate incoming DATA frame lengths against the receive window before reading the frame body. Any peer that completes a standard libp2p handshake can send a single 12-byte frame claiming a 4 GB body, causing the victim's yamux read loop…
GitHub-GHSA

HIGH
OmniFaces: Forged combined-resource IDs and related output/push boundaries
GHSA-fp43-vj7g-pg92
pkg: org.omnifaces:omnifaces, org.omnifaces:omnifaces, org.omnifaces:omnifaces
eco: maven
published: Jul 24, 2026
## 1. Forged combined-resource IDs
`CombinedResourceInfo` accepts a path-derived ID without an authenticity check,
inflates it without an output limit, converts it to attacker-selected resource
identifiers, and retains unique IDs in an unbounded static cache. In bounded
tests, 20,754 encoded bytes i…
GitHub-GHSA

HIGH
blaze: Unbounded WebSocket message aggregation in http4s-blaze-server
GHSA-7ppr-r889-mcf2
pkg: org.http4s:http4s-blaze-server_2.13, org.http4s:http4s-blaze-server_2.13, org.http4s:http4s-blaze-server_2.12
eco: maven
published: Jul 24, 2026
## Summary

`http4s-blaze-server` aggregates the fragments of an incoming WebSocket
message with no limit on total size or fragment count. A client that
completes a WebSocket handshake can send an unterminated fragmented
message and drive unbounded heap growth in the server JVM, resulting in
denial …

GitHub-GHSA

HIGH
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
GHSA-mh99-v99m-4gvg
pkg: brace-expansion
eco: npm
published: Jul 24, 2026
### Summary

`expand()` bounds the *number* of results it produces (the `max` option,
`100_000` by default) but not their *length*. By chaining many brace groups,
an attacker keeps the result count under `max` while making every result grow
with the number of groups. Building `max` long results — …

CVE-2026-14257
GitHub-GHSA

HIGH
@anephenix/hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion
GHSA-g5vv-q72c-7j78
pkg: @anephenix/hub
eco: npm
published: Jul 24, 2026
### Summary

`@anephenix/hub` starts a `setInterval` polling loop for every incoming WebSocket connection to request a client ID via RPC. If the remote client never replies — which requires no authentication or special configuration — the interval and the pending request object are never cleaned…

GitHub-GHSA

HIGH
GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)
GHSA-94p4-4cq8-9g67
pkg: GitPython
eco: pip
published: Jul 24, 2026
## Summary

The fix for [GHSA-rwj8-pgh3-r573](https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-rwj8-pgh3-r573) stopped `Repo.clone_from()` from running caller-supplied URLs through `os.path.expandvars()`, but it guarded only that one caller. `Remote.create()` — reached fr…

GitHub-GHSA

HIGH
Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint
GHSA-hr66-5mqr-8mpx
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
#### Summary
The Budibase Worker service exposes a public, unauthenticated API endpoint (`GET /api/global/users/tenant/:id`) that returns sensitive user information including `tenantId`, `userId`, `email`, and `ssoId`. The endpoint is registered in the `PUBLIC_ENDPOINTS` list with a `TODO` comment a…
GitHub-GHSA

HIGH
react-server-dom: Denial of Service in Server Functions
GHSA-wx67-qw84-cm4g
pkg: react-server-dom-webpack, react-server-dom-turbopack, react-server-dom-turbopack
eco: npm
published: Jul 24, 2026
### Impact

A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to out-of-memory exceptions or excessive CPU usage.

We recommend updating immediately.

The vulnerability exists in versions 19.0.0 through 19.0.…

CVE-2026-44907
GitHub-GHSA

HIGH
yt-dlp: Downstream command injection via improper sanitization of yt-dlp –write-link output
GHSA-6v4j-43gg-vj32
pkg: yt-dlp
eco: pip
published: Jul 24, 2026
### Summary
If the `–write-link`, `–write-url-link` or `–write-desktop-link` options are used with yt-dlp, it may produce output that can lead to downstream remote code execution. An attacker can craft a malicious metadata payload to achieve arbitrary command injection in the `.url` and `.desktop…
CVE-2026-55404
NVD

HIGH
CVE-2026-66033
CVE-2026-66033
pkg: express

published: Jul 24, 2026

libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AES-GCM ciphers during handshake. Attackers can exploit…
CWE: CWE-125, CWE-191
GitHub-GHSA

HIGH
Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion
GHSA-v74w-7mr3-4qg3
pkg: io.netty:netty-codec-xml, io.netty:netty-codec-xml
eco: maven
published: Jul 24, 2026
### Summary
An attacker can cause Denial of Service by sending a specially crafted malicious XML payload (e.g., repeated `</` characters) to a Netty server utilizing XmlFrameDecoder, causing the server's EventLoop thread to exhaust CPU resources and become unresponsive.

### Details
`io.netty.handle…

GitHub-GHSA

HIGH
js-yaml: Exponential parsing time in flow collections leads to denial of service
GHSA-pm4m-ph32-ghv5
pkg: js-yaml
eco: npm
published: Jul 24, 2026
### Summary
Parsing a small YAML document can take exponential time. An application that calls `load()` or `loadAll()` on untrusted input can be hung by a payload under 200 bytes.

### Details
When an entry in a flow sequence turns out to be a `key: value` pair, the parser rewinds and parses that en…

GitHub-GHSA

HIGH
@fastify/static vulnerable to route guard bypass via path traversal
GHSA-83w8-p2f5-377r
pkg: @fastify/static
eco: npm
published: Jul 24, 2026
### Impact

`@fastify/static` is vulnerable to a bypass of route-based middleware and guards via non-leading `..` and `%2E%2E` path segments. `find-my-way` does not normalize `..` when matching routes, so a request such as `/foo/../deep/secret.txt` matches the static plugin's catch-all instead of th…

CVE-2026-15074
GitHub-GHSA

HIGH
GitPython: Incomplete unsafe_git_clone_options denylist omits –template enabling arbitrary command execution via clone hooks
GHSA-6p8h-3wgx-97gf
pkg: GitPython
eco: pip
published: Jul 24, 2026
## Summary
GitPython's `unsafe_git_clone_options` denylist omits `–template`. `git clone –template=<dir>` copies `<dir>/hooks/` into the new repository and runs them (`post-checkout` fires during clone), so a caller who can influence clone options can achieve arbitrary command execution in the def…
GitHub-GHSA

HIGH
PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
GHSA-r28c-9q8g-f849
pkg: postcss
eco: npm
published: Jul 24, 2026
## Vulnerability Details

**File**: `lib/previous-map.js`
**Line**: 87-98 (`loadFile`), 129-144 (`loadMap`)

### Root Cause
PostCSS auto-detects a `/*# sourceMappingURL=… */` comment inside the CSS text it is asked to parse and, unless the caller explicitly passes `map: false`, attempts to load t…

NVD

HIGH
CVE-2026-64210
CVE-2026-64210
pkg: linux

published: Jul 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

net/mlx5e: xsk: Fix unlocked writing to ICOSQ

During napi poll, when the affinity changes and there's still XSK work
to be done, we trigger an ICOSQ interrupt on the new CPU. However, this
triggering on the ICOSQ is done unprotect…

NVD

HIGH
CVE-2026-64208
CVE-2026-64208
pkg: linux

published: Jul 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks

Change the krb5 crypto library to provide facilities to precheck the length
of the message about to be decrypted or verified.

Fix AF_RXRPC to make use of this t…

GitHub-GHSA

HIGH
Microsoft Kiota: Code Generation Literal Injection in Kiota Python Generator
GHSA-7f3j-j7jj-r3vr
pkg: Microsoft.OpenAPI.Kiota, Microsoft.OpenAPI.Kiota.Builder
eco: nuget
published: Jul 24, 2026
Code Generation Literal Injection in Kiota Python Generator Leads to Arbitrary Code Execution at Import Time.

The Kiota Python code generator is vulnerable to a code generation literal injection issue when processing malicious or untrusted OpenAPI specifications. Specifically, attacker-controlled e…

CVE-2026-59862
GitHub-GHSA

HIGH
Microsoft Kiota: Code Generation Literal Injection in Kiota Ruby Generator
GHSA-xg2h-5xr2-29jw
pkg: Microsoft.OpenAPI.Kiota, Microsoft.OpenAPI.Kiota.Builder
eco: nuget
published: Jul 24, 2026
Code Generation Literal Injection in Kiota Ruby Generator Leads to Arbitrary Code Execution

# Impact

The Kiota Ruby code generator is vulnerable to a code generation literal injection attack. The generator embeds string values from OpenAPI default fields and property names directly into Ruby doubl…

CVE-2026-59861
GitHub-GHSA

HIGH
httplib2: Decompression Bomb Denial of Service via Unbounded gzip/deflate Response Handling
GHSA-j5g9-f88f-gfj3
pkg: httplib2
eco: pip
published: Jul 24, 2026
### Summary

The `httplib2` HTTP client library performs unbounded decompression of HTTP response bodies encoded with `Content-Encoding: gzip` or `deflate`. A malicious or compromised HTTP server can return a small compressed payload (approximately 150 KB) that expands to an arbitrarily large size i…

CVE-2026-59939
GitHub-GHSA

HIGH
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
GHSA-4w2j-m93h-cj5j
pkg: quinn-proto
eco: rust
published: Jul 24, 2026
## Summary

The `Assembler` component that assembles unordered stream fragments into consecutive chunks of the stream incurs some overhead for non-contiguous fragments. Readers that read from a `RecvStream` in order (through an `AsyncRead` impl for example) will be sensitive to peers that send fragm…

GitHub-GHSA

HIGH
find-my-way: DDoS with HTTP2
GHSA-c96f-x56v-gq3h
pkg: find-my-way
eco: npm
published: Jul 23, 2026
### Impact
Remotely triggerable DoS in find-my-way when it is used with Node's HTTP/2 server.

The short version is that `lookup()` passes `req.method` into `find()`, and `find()` indexes `this.trees[method]`. Since `this.trees` is a normal object, HTTP/2 method values like constructor, `toString`, …

CVE-2026-47219
GitHub-GHSA

HIGH
PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments
GHSA-6g55-p6wh-862q
pkg: postcss
eco: npm
published: Jul 23, 2026
## Summary

PostCSS's `PreviousMap` parses the `/*# sourceMappingURL=PATH */` comment from any CSS string passed to `process()` and dereferences `PATH` against the local filesystem with no scheme, allowlist, or traversal check. An attacker who controls the CSS input can cause the host process to rea…

CVE-2026-45623
GitHub-GHSA

HIGH
Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers
GHSA-xmf8-cvqr-rfgj
pkg: @auth/core, next-auth, next-auth
eco: npm
published: Jul 23, 2026
## Summary

The exported `getToken()` helper (`next-auth/jwt` and `@auth/core/jwt`) can throw an uncaught exception when it reads a malformed `Authorization: Bearer …` header. When no session cookie is present, `getToken()` URL-decodes the bearer value before validating it, and malformed percent-e…

NVD

HIGH
CVE-2026-14257
CVE-2026-14257
pkg: node

published: Jul 23, 2026

brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max option (default 100,000) but does not bound the length of each result string. By chaining multiple brace groups, an attacker keeps the result count un…
CWE: CWE-400, CWE-770
GitHub-GHSA

HIGH
Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requests
GHSA-9299-c6m4-mjhc
pkg: org.eclipse.jetty:jetty-server, org.eclipse.jetty:jetty-server
eco: maven
published: Jul 22, 2026
### Impact
The original report:

> Server handling of 100-Continue requests can lead to memory leak that can be abused to cause a Denial of Service state.

After investigation, turns out that every request that has a body, but reading the body may end up in reading 0 bytes, leaks a buffer.
This is p…

CVE-2024-7708
GitHub-GHSA

HIGH
Netty: Memory Exhaustion via HTTP/3 Reserved Frame Types
GHSA-hpcc-26xq-25fv
pkg: io.netty:netty-codec-http3
eco: maven
published: Jul 22, 2026
### Summary
Netty's Http3FrameCodec buffers incoming data for HTTP/3 reserved frame types up to the specified payload length without any limits. The payload length is read directly from the wire and trusted without validation. A bad actor can send a reserved frame with a payload length of up to Inte…
CVE-2026-56816
GitHub-GHSA

HIGH
Netty SPDY zlib header block continues decoded expansion after maxHeaderSize truncation
GHSA-mvh2-crg5-v77c
pkg: io.netty:netty-codec-http, io.netty:netty-codec-http
eco: maven
published: Jul 22, 2026
### Summary
Netty SPDY header decoding continues inflating zlib-compressed header blocks after the raw header parser has already exceeded maxHeaderSize and marked the frame truncated. At commit b2d2137c4404af425bf9d5d601a62576f5c06925, a 12,253-byte compressed SPDY header block can declare and infla…
CVE-2026-55833
GitHub-GHSA

HIGH
Netty SPDY SETTINGS frame count materializes unbounded settings map
GHSA-6jqx-86gh-f27w
pkg: io.netty:netty-codec-http, io.netty:netty-codec-http
eco: maven
published: Jul 22, 2026
### Summary
Netty's SPDY SETTINGS decoder accepts a peer-declared SETTINGS entry count up to the 24-bit frame-length limit and materializes every unique setting ID in `DefaultSpdySettingsFrame` without an implementation-level count cap. A remote SPDY/3.1 peer can send one syntactically valid roughly…
CVE-2026-55831
NVD

HIGH
CVE-2026-16422
CVE-2026-16422
pkg: google chrome, linux linux_kernel

published: Jul 21, 2026

Insufficient validation of untrusted input in Certificate in Google Chrome on Linux prior to 150.0.7871.182 allowed an attacker in a privileged network position to perform domain spoofing via malicious network traffic. (Chromium security severity: High)
CWE: CWE-20
NVD

HIGH
CVE-2026-65315
CVE-2026-65315
pkg: go

published: Jul 21, 2026

Ollama (HEAD f0078ae) contains an uncontrolled memory allocation vulnerability in the GGUF metadata parser that allows remote attackers to crash the server by supplying a crafted GGUF file with attacker-controlled length and count fields in string lengths, tensor dimension counts, and metadata array…
CWE: CWE-789
GitHub-GHSA

HIGH
GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL
GHSA-rwj8-pgh3-r573
pkg: gitpython
eco: pip
published: Jul 21, 2026
### Summary
`Repo.clone_from()` passes the caller-supplied remote URL through `Git.polish_url()`, which on every non-Cygwin platform calls `os.path.expandvars()` on the URL before handing it to `git clone`. An attacker who controls the URL argument — the documented use case for `clone_from()` in "…
GitHub-GHSA

HIGH
Gitea: Notification API leaks private issue metadata after access revocation
GHSA-44qc-pgvp-wx7v
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
# Summary

An information disclosure issue in the Gitea Notification API allows users who have lost access to a private repository to continue accessing private issue or pull request information through existing notification threads. Although repository information is hidden after access revocation,…

CVE-2026-58419
GitHub-GHSA

HIGH
Gitea: Unauthorized Access to Labels of Private Organizations
GHSA-v73x-hx65-6pf4
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
## Summary

Gitea 1.26.2 does not properly enforce organization visibility restrictions on organization label read endpoints.

A user without access to a private organization can retrieve labels belonging to that organization through the Organization Labels API. As a result, label metadata intended …

CVE-2026-25038
GitHub-GHSA

HIGH
Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private
GHSA-wrf9-r3h7-7x5v
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary

The `POST /api/v1/repos/{owner}/{repo}/merge-upstream` endpoint continues to synchronize commits from a parent repository after the parent repository has been changed from public to private.

A fork created while the parent repository was public can still receive commits made after the …

CVE-2026-24451
GitHub-GHSA

HIGH
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override
GHSA-94v3-77j7-vm48
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
Summary

Gitea's internal API HTTP client (modules/private/internal.go) hardcodes
TLSClientConfig.InsecureSkipVerify = true with no configuration override. It is the only
outbound TLS client in the codebase that cannot be made to verify its peer's certificate —
webhook, migrations, MinIO, LDAP, SM…

CVE-2026-54481
GitHub-GHSA

HIGH
Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service
GHSA-v96j-25gv-g2w9
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
This issue has been found by a security agent and review by myself.

Gitea's CODEOWNERS feature uses the regexp2 library to match file paths against ownership rules. User-supplied patterns are passed directly to regexp2.Compile with no sanitisation and no match timeout. This allows an attacker to wr…

CVE-2026-58421
GitHub-GHSA

HIGH
pyasn1: Uncontrolled resource consumption when converting decoded REAL values
GHSA-hm4w-wwcw-mr6r
pkg: pyasn1
eco: pip
published: Jul 21, 2026
### Impact
The univ.Real type converted its (mantissa, base, exponent) value to a Python float using exact big-integer exponentiation. A BER/CER/DER-encoded REAL value only a few bytes long can carry a very large exponent, causing this computation to attempt to materialize an astronomically large in…
CVE-2026-59886
GitHub-GHSA

HIGH
pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service
GHSA-8ppf-4f7h-5ppj
pkg: pyasn1
eco: pip
published: Jul 21, 2026
### Impact
The BER/CER/DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs. A small crafted payload (tens of kilobytes) containing an OID with many arcs consumes seconds of CPU per decode() call, allowing denial of service in any applicatio…
CVE-2026-59885
GitHub-GHSA

HIGH
pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs
GHSA-m4p7-r5rc-7g4j
pkg: pyssn1
eco: pip
published: Jul 21, 2026
### Impact
The BER decoder (shared by the CER and DER codecs) parses long-form tags by accumulating continuation octets in a loop with no upper bound on the size of the tag ID. A crafted input can force the decoder to build an arbitrarily large integer, with CPU cost growing quadratically in input s…
CVE-2026-59884
NVD

HIGH
CVE-2026-44907
CVE-2026-44907
pkg: react

published: Jul 21, 2026

A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack (versions 19.0.0 throu…
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-56170 – .NET Denial of Service Vulnerability
GHSA-j8gr-8fp3-5q5h
pkg: Microsoft.AspNetCore.App.Runtime.linux-arm, Microsoft.AspNetCore.App.Runtime.linux-arm64, Microsoft.AspNetCore.App.Runtime.linux-musl-arm
eco: nuget
published: Jul 21, 2026
# Microsoft Security Advisory CVE-2026-56170 – .NET Denial of Service Vulnerability

## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core SignalR (Microsoft.AspNetCore.App.Runtime). This advisory also provides guidance on …

CVE-2026-56170
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-50527 – .NET Denial of Service Vulnerability
GHSA-mmjf-rqrv-855v
pkg: System.Security.Cryptography.Xml, System.Security.Cryptography.Xml, System.Security.Cryptography.Xml
eco: nuget
published: Jul 21, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET XML Encryption (System.Security.Cryptography.Xml). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A den…

CVE-2026-50527
GitHub-GHSA

HIGH
Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch
GHSA-9hw9-ch79-4vh6
pkg: pillow
eco: pip
published: Jul 20, 2026
### Summary

Pillow's public `ImageCms.ImageCmsTransform.apply(im, imOut)` API can trigger
controlled native heap corruption when the caller supplies an output image whose
mode does not match the transform's declared output mode.

For example, a transform built as `RGBA -> RGBA` can be applied to an…

CVE-2026-59205
GitHub-GHSA

HIGH
Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()
GHSA-jjj6-mw9f-p565
pkg: Pillow
eco: pip
published: Jul 20, 2026
### Summary
`PdfParser.PdfStream.decode()` in Pillow's `PdfParser.py` calls `zlib.decompress()` with the `bufsize` parameter set to the value of the PDF stream's `Length` field, without any upper bound on the actual decompressed output size. Python's `zlib.decompress()` `bufsize` argument is an *ini…
CVE-2026-59200
GitHub-GHSA

HIGH
Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow
GHSA-6r8x-57c9-28j4
pkg: Pillow
eco: pip
published: Jul 20, 2026
### Summary

Pillow's public image coordinate APIs can trigger a native heap out-of-bounds
write when given coordinates near the signed 32-bit integer limits. In 4-byte
pixel modes such as `RGBA`, this becomes a controlled backward heap underwrite:
for a source image of width `W`, Pillow writes `4 *…

CVE-2026-59199
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-50651 – .NET Denial of Service Vulnerability
GHSA-wp74-jgxh-gv4q
pkg: Microsoft.NetCore.App.Runtime.linux-arm, Microsoft.NetCore.App.Runtime.linux-arm64, Microsoft.NetCore.App.Runtime.linux-musl-arm
eco: nuget
published: Jul 20, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET HTTP client (System.Net.Http). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A denial of service vulne…

CVE-2026-50651
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-50525 – .NET Denial of Service Vulnerability
GHSA-8q5v-6pqq-x66h
pkg: System.Security.Cryptography.Xml, System.Security.Cryptography.Xml, System.Security.Cryptography.Xml
eco: nuget
published: Jul 20, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET XML Encryption (System.Security.Cryptography.Xml). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A den…

CVE-2026-50525
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-50648 – .NET Denial of Service Vulnerability
GHSA-23rf-6693-g89p
pkg: System.Security.Cryptography.Xml, System.Security.Cryptography.Xml, System.Security.Cryptography.Xml
eco: nuget
published: Jul 20, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET XML Encryption (System.Security.Cryptography.Xml). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A den…

CVE-2026-50648
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-50524 – .NET Denial of Service Vulnerability
GHSA-w7cw-xp7h-6j5j
pkg: Microsoft.NetCore.App.Runtime.linux-arm, Microsoft.NetCore.App.Runtime.linux-arm64, Microsoft.NetCore.App.Runtime.linux-musl-arm
eco: nuget
published: Jul 20, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET TLS/SSL (System.Net.Security). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A denial of service vulne…

CVE-2026-50524
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-47302 – .NET Denial of Service Vulnerability
GHSA-cvvh-rhrc-wg4q
pkg: System.Security.Cryptography.Xml, Microsoft.NetCore.App.Runtime.linux-arm, Microsoft.NetCore.App.Runtime.linux-arm64
eco: nuget
published: Jul 20, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET XML processing (System.Security.Cryptography.Xml, System.Xml). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerabi…

CVE-2026-47302
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-57108 – .NET Denial of Service Vulnerability
GHSA-rp2p-6cmp-jxj9
pkg: Microsoft.NetCore.App.Runtime.linux-arm, Microsoft.NetCore.App.Runtime.linux-arm64, Microsoft.NetCore.App.Runtime.linux-musl-arm
eco: nuget
published: Jul 20, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in the .NET runtime cryptography layer (CryptoNative_GetX509NameInfo). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerabi…

CVE-2026-57108
GitHub-GHSA

HIGH
Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert)
GHSA-c8j7-8cv4-2xmq
pkg: mistune
eco: pip
published: Jul 20, 2026
## Summary

**Type:** Algorithmic-complexity denial of service. A run of N closed pairs `~~x~~~~x~~…` (or the analogous `==x==` for `mark`, `^^x^^` for `insert`) causes O(N²) work in the formatting parser. With the `strikethrough`, `mark`, or `insert` plugin enabled, an 8 KB input pegs the CPU fo…

CVE-2026-59922
GitHub-GHSA

HIGH
Mistune inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs
GHSA-4j32-57v6-6g45
pkg: mistune
eco: pip
published: Jul 20, 2026
## Summary

**Type:** Algorithmic-complexity DoS in core emphasis parsing. A long sequence of well-formed `**x**` (strong) or `***x***` (strong-emphasis combined) pairs causes O(N²) parser work. Distinct from the bracket-bomb DoS (`[` repetition) and from the formatting-plugin DoS (`~~`/`==`/`^^`);…

CVE-2026-59925
GitHub-GHSA

HIGH
Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions
GHSA-ffq3-xpv3-j92q
pkg: mistune
eco: pip
published: Jul 20, 2026
## Summary

**Type:** Algorithmic-complexity DoS in reference-link definition handling. A markdown document with N reference-link definitions of the same key (or many distinct keys) takes O(N²) parser time. 5000 repeated `[a]: u\n` definitions take ~1.1 second; 10000 → ~4.5 seconds.
**File:** `sr…

CVE-2026-59928
GitHub-GHSA

HIGH
Pillow `GdImageFile._open()`: image dimensions accepted without `_decompression_bomb_check()`
GHSA-phj9-mv4w-65pm
pkg: pillow
eco: pip
published: Jul 20, 2026
## Description

`PIL/GdImageFile.py` `GdImageFile._open()` reads image dimensions from the GD 2.x header and stores them in `self._size` without calling `Image._decompression_bomb_check()`. Because `GdImageFile` is **not registered with `Image.register_open()`**, it never passes through the standard…

CVE-2026-55380
GitHub-GHSA

HIGH
Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading
GHSA-45hq-cxwh-f6vc
pkg: pillow
eco: pip
published: Jul 20, 2026
### Summary
`PIL/BdfFontFile.py` `bdf_char()` (lines 84–88) reads the `BBX width height` field from a BDF font file and passes the dimensions directly to `Image.new()` without calling `Image._decompression_bomb_check()`. This completely bypasses Pillow's documented decompression bomb protection.

CVE-2026-55379
GitHub-GHSA

HIGH
Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`
GHSA-5×94-69rx-g8h2
pkg: pillow
eco: pip
published: Jul 20, 2026
## Description

`PIL/FontFile.py` `FontFile.compile()` assembles per-glyph images into a single combined bitmap using `Image.new("1", (xsize, ysize))` without calling `Image._decompression_bomb_check()`. This is the base-class method shared by both `BdfFontFile` and `PcfFontFile`, and it is triggere…

CVE-2026-54060
GitHub-GHSA

HIGH
Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading
GHSA-8v84-f9pq-wr9x
pkg: pillow
eco: pip
published: Jul 20, 2026
## Description
`PIL/PcfFontFile.py` `_load_bitmaps()` (line 227) reads glyph dimensions from the PCF `METRICS` section and passes them directly to `Image.frombytes()` without calling `Image._decompression_bomb_check()`. Dimensions originate from unsigned 16-bit values:

“`
xsize = right – left …

CVE-2026-54059
GitHub-GHSA

HIGH
Tornado: Quadratic DoS via Crafted Multipart Parameters
GHSA-jhmp-mqwm-3gq8
pkg: tornado
eco: pip
published: Jul 20, 2026
## Summary

The `_parseparam` function in Tornado's `httputil.py` is used to parse specific HTTP header values, such as those in `multipart/form-data`. This function uses an inefficient algorithm that repeatedly calls `string.count()` within a nested loop while processing quoted semicolons (e.g., `p…

CVE-2025-67726
GitHub-GHSA

HIGH
Tornado: Quadratic DoS via Repeated Header Coalescing
GHSA-c98p-7wgm-6p64
pkg: tornado
eco: pip
published: Jul 20, 2026
## Summary

The `HTTPHeaders.add` method in Tornado accumulates values using string concatenation when the same header name is repeated. Due to Python string immutability, each concatenation copies the entire string, resulting in O(n²) time complexity.

Given Tornado's single event loop architectur…

CVE-2025-67725
NVD

HIGH
CVE-2026-45713
CVE-2026-45713
pkg: go

published: Jul 20, 2026

Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the Mailpit SMTP server has a Server.MaxSize int field that controls the maximum allowed DATA payload size, but the field is never assigned anywhere outside test code, leaving it at Go's zero value (0 ⇒ "no limit"). …
CWE: CWE-400, CWE-770
GitHub-GHSA

HIGH
blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)
GHSA-46q4-43ph-c6fr
pkg: org.http4s:blaze-http_2.13, org.http4s:blaze-http_2.12, org.http4s:blaze-http_3
eco: maven
published: Jul 24, 2026
### Summary
blaze-server can merge HTTP/1.1 chunked-body trailer fields into `Request.headers`. Because trailer fields are attacker-controlled, an unauthenticated remote client can inject arbitrary header names/values (e.g. `X-Forwarded-For`, internal-auth headers) that a fronting proxy sanitized …
GitHub-GHSA

HIGH
blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser
GHSA-mhvj-jhpq-885v
pkg: org.http4s:http4s-blaze-server_2.13, org.http4s:blaze-http_2.13, org.http4s:blaze-http_3
eco: maven
published: Jul 24, 2026
### Summary
Five independent HTTP/1.1 conformance laxities in blaze's hand-written Java parser (`http/src/main/java/org/http4s/blaze/http/parser/`) cause request-boundary disagreement with a stricter intermediary. All are reachable from a default `BlazeServerBuilder` with no non-default configurat…
GitHub-GHSA

HIGH
Netty: TOCTOU in OcspServerCertificateValidator
GHSA-wc96-39fc-566f
pkg: io.netty:netty-handler-ssl-ocsp, io.netty:netty-handler-ssl-ocsp
eco: maven
published: Jul 22, 2026
### Summary
Netty's OcspServerCertificateValidator forwards the SslHandshakeCompletionEvent before the asynchronous OCSP validation completes. This allows the client's downstream handlers to send sensitive application data (e.g., HTTP requests) to a revoked server before the channel is closed by the…
CVE-2026-56822
GitHub-GHSA

HIGH
Netty: Out-of-date OCSP Responses Accepted by OcspServerCertificateValidator
GHSA-g7hg-vrcf-mvmr
pkg: io.netty:netty-handler-ssl-ocsp, io.netty:netty-handler-ssl-ocsp
eco: maven
published: Jul 22, 2026
### Summary
`OcspServerCertificateValidator` flags an out-of-date OCSP response but does not stop processing it, so an expired GOOD response is still reported as `VALID`, letting an on-path attacker replay a stale GOOD response to bypass revocation of a since-revoked certificate.

### Details
In `io…

CVE-2026-56821
GitHub-GHSA

HIGH
Netty: Missing CertificateID Validation in OCSP Response Allows Replay Attacks
GHSA-272m-gcwp-mpwg
pkg: io.netty:netty-handler-ssl-ocsp, io.netty:netty-handler-ssl-ocsp
eco: maven
published: Jul 22, 2026
### Summary
Netty's OcspClient does not validate that the CertificateID in an OCSP response matches the requested CertificateID. A bad actor can replay a `GOOD` status response issued for an unrelated certificate (by the same CA) to bypass revocation checks for any certificate.

### Details
`io.nett…

CVE-2026-56820
GitHub-GHSA

HIGH
AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()
GHSA-j6g5-3hh3-pgw8
pkg: bedrock-agentcore
eco: pip
published: Jul 24, 2026
### Summary

The AWS Bedrock AgentCore Python SDK (bedrock-agentcore) provides tools for building AI agents, including a Code Interpreter client that installs Python packages into a managed sandbox. An issue exists where, under certain circumstances, improper neutralization of argument delimiters in…

CVE-2026-16796
GitHub-GHSA

HIGH
Open WebUI: Stored web worker XSS via Pyodide
GHSA-4r2p-27mh-5m22
pkg: open-webui
eco: pip
published: Jul 24, 2026
**Title:** Same-origin Pyodide code execution allows server-side RCE via a shared chat

### Summary

Open WebUI runs client-side Python (Pyodide) in a same-origin web worker. Through Pyodide's JavaScript API (`pyodide.http.pyfetch`, or the `js` module which exposes the page's `fetch` / `XMLHttpReque…

CVE-2026-59214
NVD

HIGH
CVE-2026-16796
CVE-2026-16796
pkg: python

published: Jul 23, 2026

Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK before 1.18.1 might allow a remote authenticated user to execute arbitrary commands within the Code Interpreter sandbox via crafted package name arguments.

To mitigate this issue, u…

CWE: CWE-88
NVD

HIGH
CVE-2026-56624
CVE-2026-56624
pkg: openssh

published: Jul 20, 2026

Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a Java library for client-side and server-side SSH.

Server-side OpenSSH user certificate validation during user authentication in an Apache MINA SSHD server did not check for the unsupported force-command or …

CWE: CWE-295
NVD

HIGH
CVE-2026-32825
CVE-2026-32825
pkg: jwt

published: Jul 20, 2026

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, the application accepts unlimited password guesses against both the brow…
CWE: CWE-307
NVD

HIGH
CVE-2026-16247
CVE-2026-16247
pkg: windows

published: Jul 20, 2026

In _connect.BRAIN versions prior to 5.06,
the application LogPathConfig.exe is executed during setup. During this
process, existing permissions on %ProgramData% are deleted and replaced,
granting the Windows group Everyone full control instead of restricting
access to %ProgramData%\Bizerba\_connect.…
CWE: CWE-276
NVD

HIGH
CVE-2026-16246
CVE-2026-16246
pkg: windows

published: Jul 20, 2026

In BRAIN2 versions prior to 3.09, the
application LogPathConfig.exe is executed during setup. As a result, the
Windows group Everyone is granted full control over %ProgramData% instead of
being restricted to %ProgramData%\Bizerba\BRAIN2\.

Starting with BRAIN2 3.09, the setup no
longer executes …

CWE: CWE-276
NVD

HIGH
CVE-2026-65693
CVE-2026-65693
pkg: express

published: Jul 24, 2026

Microweber CMS through 2.0.20 contains a server-side template injection vulnerability that allows authenticated administrators to achieve arbitrary OS command execution by injecting Twig expressions into mail templates. Attackers can exploit the unsandboxed Twig environment in TwigView::render(), wh…
CWE: CWE-94
NVD

HIGH
CVE-2026-66138
CVE-2026-66138
pkg: python

published: Jul 24, 2026

In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic-Python-Agent via a maliciously constructed configuration, because the value of ntp_server is passed to a shell.
CWE: CWE-78
NVD

HIGH
CVE-2026-60396
CVE-2026-60396
pkg: go

published: Jul 21, 2026

Vulnerability in Oracle GoldenGate (component: Distribution Server executable). Supported versions that are affected are 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle GoldenGate. Successful attacks …
CWE: CWE-306
GitHub-GHSA

HIGH
Budibase: NoSQL injection in MongoDB integration: collection dump, $where JS exec, cross-collection pivot, arbitrary update/delete
GHSA-pmpg-2mxq-6xwr
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
## Summary

An end-user injection in Budibase's MongoDB datasource lets any BASIC app user bypass the builder's query-level access controls. Builders scope MongoDB reads per-user with bindings like `{"email": "{{ currentUser.email }}"}` so each app user only sees their own rows. Because the binding …

GitHub-GHSA

HIGH
Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials
GHSA-hq88-5×99-x3gf
pkg: github.com/cloudreve/Cloudreve/v4, github.com/cloudreve/Cloudreve/v3
eco: go
published: Jul 24, 2026
## Summary

Cloudreve 4.16.1 has an OAuth scope authorization bypass in the admin storage policy routes. An OAuth bearer token scoped to `Admin.Read` but not `Admin.Write` can call `POST /api/v4/admin/policy/oauth/signin` and update OneDrive storage policy credentials.

The route is inside the admin…

CVE-2026-55502
GitHub-GHSA

HIGH
Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids)
GHSA-x2ff-v5v8-m75m
pkg: open-webui
eco: pip
published: Jul 24, 2026
## Summary

Any authenticated user can overwrite the content of a message in a channel they do not belong to (including private and DM channels) by sending a chat completion request with a `channel:`-prefixed `chat_id` and a target `message_id`. The `channel:` path routes pipeline output through `_m…

CVE-2026-59714
GitHub-GHSA

HIGH
Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout
GHSA-855v-hq7w-jmjw
pkg: open-webui
eco: pip
published: Jul 24, 2026
## Summary

With Redis configured, Open WebUI supports JWT revocation: `POST /api/v1/auths/signout` (per-token `jti`) and OIDC back-channel logout (per-user `revoked_at`) record revocations in Redis, and HTTP auth (`get_current_user`) rejects revoked tokens with 401. The realtime authentication surf…

CVE-2026-59219
GitHub-GHSA

HIGH
Microsoft Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
GHSA-rg4h-fpcp-2qm8
pkg: Microsoft.OpenApi.Kiota, Microsoft.OpenApi.Kiota.Builder
eco: nuget
published: Jul 24, 2026
## Summary

Microsoft Kiota resolved OpenAPI `$ref`s by fetching remote `http(s)` URLs and reading local files
(including absolute / out-of-tree paths), inlining the referenced schema into the generated client.
Running `kiota generate` on a spec whose `$ref` pointed at an attacker/internal URL or an…

CVE-2026-59867
GitHub-GHSA

HIGH
@better-auth/stripe: cross-organization billing tampering in organization subscription actions
GHSA-h3rm-78g3-j7cp
pkg: @better-auth/stripe, @better-auth/stripe
eco: npm
published: Jul 24, 2026
### Am I affected?

You are affected if all of these are true:

– You use `@better-auth/stripe` from version 1.4.11 up to a patched version below. This covers the stable line through 1.6.20 and every 1.7.0 beta through 1.7.0-beta.9.
– The Stripe plugin has subscriptions turned on (`subscription.enab…

NVD

HIGH
CVE-2026-57767
CVE-2026-57767
pkg: go

published: Jul 23, 2026

Unauthenticated Cross Site Scripting (XSS) in WP Google Maps Pro <= 10.1.02 versions.
CWE: CWE-79
GitHub-GHSA

HIGH
Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface
GHSA-gx3v-q759-g323
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary

I'm reporting **two related TOTP one-time-use defects** in Gitea that survive the CVE-2021-45331 fix. The 2018 fix (PR #3878) introduced the `TwoFactor.LastUsedPasscode` field and added an in-memory inequality check on the web 2FA login path. That check works correctly in the single-req…

CVE-2026-20779
GitHub-GHSA

HIGH
Gitea: Repository Visibility Manipulation via Git Push Options
GHSA-8p9h-49rc-qgxj
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Repository Visibility Manipulation via Git Push Options

| Field | Value |
|——-|——-|
| **Affected File** | `routers/private/hook_post_receive.go` |
| **Affected Function** | `HookPostReceive()` |
| **Affected Lines** | 173–225 |
| **Prerequisite** | Attacker must have owner-level or ad…

CVE-2026-58437
GitHub-GHSA

HIGH
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
GHSA-2m9v-5q2g-58vq
pkg: gitea.dev
eco: go
published: Jul 21, 2026
## Summary

A user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object.

The issue appears to be …

CVE-2026-28740
NVD

HIGH
CVE-2026-21575
CVE-2026-21575
pkg: windows

published: Jul 21, 2026

This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.11 of Sourcetree for Mac and Sourcetree for Windows.

This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to execute arbitrary code which has high impa…

CWE: CWE-94
NVD

HIGH
CVE-2026-56623
CVE-2026-56623
pkg: windows

published: Jul 20, 2026

Path traversal on Windows in Apache MINA SSHD component sshd-git. Apache MINA SSHD is a Java library for client-side and server-side SSH.

A git server implemented with Apache MINA SSHD component sshd-git and running on Windows could allow an authenticated remote user access to git repositories …

CWE: CWE-22
GitHub-GHSA

HIGH
AWS API MCP Server Security Policy Bypass via Startup Initialization Failure
GHSA-29w2-fq35-v728
pkg: awslabs.aws-api-mcp-server
eco: pip
published: Jul 24, 2026
## Summary
The AWS API MCP Server is an open source Model Context Protocol (MCP) server that enables AI assistants to interact with AWS services and resources through AWS CLI commands. It provides programmatic access to manage your AWS infrastructure while maintaining proper security controls. It in…
CVE-2026-16584
GitHub-GHSA

HIGH
GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)
GHSA-3rp5-jjmw-4wv2
pkg: gitpython
eco: pip
published: Jul 24, 2026
### Summary

In GitPython `<= 3.1.52`, the config writer neutralizes only CR, LF, and NUL in configuration **names**, but writes section names into the `[…]` header with no other escaping. A section/subsection name that contains `] [ "` closes the intended header and opens a second same-line secti…

NVD

HIGH
CVE-2026-64222
CVE-2026-64222
pkg: linux

published: Jul 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

octeontx2-pf: avoid double free of pool->stack on AQ init failure

otx2_pool_aq_init() frees pool->stack when mailbox sync or retry
allocation fails, but leaves the pointer unchanged. Later,
otx2_sq_aura_pool_init() unwinds the par…

NVD

HIGH
CVE-2026-64219
CVE-2026-64219
pkg: linux

published: Jul 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async

[Why&How]
dc_process_dmub_aux_transfer_async() copies payload->length bytes into a
16-byte stack buffer (dpaux.data[16]) guarded only by…

GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-50526 – .NET Tampering Vulnerability
GHSA-55jh-fwmh-39m4
pkg: Microsoft.NET.Build.Containers, Microsoft.NET.Build.Containers, Microsoft.NET.Build.Containers
eco: nuget
published: Jul 21, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET SDK (Microsoft.NET.Build.Containers). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A tampering vulner…

CVE-2026-50526
GitHub-GHSA

HIGH
etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline
GHSA-6vch-q96h-7gc3
pkg: go.etcd.io/etcd/v3, go.etcd.io/etcd/v3, go.etcd.io/etcd/v3
eco: go
published: Jul 24, 2026
### Impact
_What kind of vulnerability is it? Who is impacted?_

A network attacker who can reach an etcd TLS listener can open many TCP connections and never send a ClientHello. Each connection spawns a goroutine in the etcd server process that blocks indefinitely inside tls.Conn.Handshake(), and e…

GitHub-GHSA

HIGH
etcd: Watch API authorization bypass via open-ended range requests
GHSA-xg4h-6gfc-h4m8
pkg: go.etcd.io/etcd/v3, go.etcd.io/etcd/v3, go.etcd.io/etcd/v3
eco: go
published: Jul 24, 2026
### Impact
_What kind of vulnerability is it? Who is impacted?_

A user granted READ permission on a single, exact key can use the Watch gRPC API with `clientv3.WithFromKey()` (an open-ended, "from this key to the end of the keyspace" watch) to receive watch events for every key lexicographically gr…

GitHub-GHSA

HIGH
Shescape: Quadratic-time denial of service in the flag-protection
GHSA-gm3r-q2wp-hw87
pkg: shescape, shescape
eco: npm
published: Jul 24, 2026
### Impact

This impacts users of Shescape that have flag protection enabled, which is on by default, regardless of the API being used.

An attacker can cause a runtime quadratic in the input size, causing denial of service for large inputs.

“`javascript
import { Shescape } from "shescape";

// 1.…

GitHub-GHSA

HIGH
vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review
GHSA-47w6-gwp4-w6vc
pkg: vantage6
eco: pip
published: Jul 24, 2026
### Impact
Edit permission lacks ownership check, so another developer could alter metadata that is later trusted by nodes.

Worst they could do is update the image or image tag. If that is not noted, another image is approved than the one actually under review

### Patches
No

### Workarounds
No

GitHub-GHSA

HIGH
frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow
GHSA-26gq-p25f-99cp
pkg: github.com/fatedier/frp
eco: go
published: Jul 24, 2026
## Summary

An integer-overflow vulnerability in the frp server's optional SSH Tunnel Gateway lets any unauthenticated remote attacker crash the entire `frps` process with a single five-byte message. When the gateway parses an SSH `exec` channel request in `pkg/ssh/server.go`, it adds a small consta…

GitHub-GHSA

HIGH
Budibase: Server Filesystem Existence/Read Oracle via Builder-Controlled MongoDB tlsCertificateKeyFile
GHSA-ppr4-5f46-j9c6
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
## Summary
When creating a MongoDB datasource, Budibase passes the `tlsCertificateKeyFile` and `tlsCAFile` fields straight to the MongoDB driver as server-side file paths. On Budibase Cloud a customer cannot place files on the server, so these fields only let a builder reference arbitrary absolute p…
GitHub-GHSA

HIGH
Budibase: Email Change IDOR via POST /api/v2/email allows full Account Takeover (accountId not validated against session)
GHSA-c8vc-7pv3-g98p
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
## Summary

`POST /api/v2/email` on the account portal (`account.budibase.app`) starts an email-change workflow using a client-supplied `accountId` that is **not validated against the authenticated session**. A logged-in attacker supplies a victim's `accountId` and an email address they control; the…

GitHub-GHSA

HIGH
Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution
GHSA-7835-87q9-rgvv
pkg: @anthropic-ai/claude-code
eco: npm
published: Jul 24, 2026
Claude Code's worktree handling allowed creation of worktrees named ".git" and navigation to worktrees outside the sandbox context, enabling git directory confusion attacks. By exploiting symlink manipulation and git fsmonitor execution during worktree operations, an attacker could overwrite files i…
CVE-2026-55607
GitHub-GHSA

HIGH
React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response
GHSA-qwww-vcr4-c8h2
pkg: react-router
eco: npm
published: Jul 24, 2026
This is a follow up to CVE-2026-22030 to address related CSRF flows in unstable RSC code paths.

> [!NOTE]
> This only affects your application if you are using the unstable RSC APIs

GitHub-GHSA

HIGH
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
GHSA-4vv7-jj25-4gh6
pkg: Microsoft.OpenApi.Kiota, Microsoft.OpenApi.Kiota.Builder
eco: nuget
published: Jul 24, 2026
### Summary

Microsoft Kiota emitted the `x-ms-kiota-info` extension's `clientClassName` or `clientNamespaceName` value
**raw**, with no identifier or path sanitization, as **both** the generated client's class/namespace name
**and** part of the generated output path. When `kiota generate` is run **…

CVE-2026-59866
GitHub-GHSA

HIGH
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
GHSA-4rj6-vrwv-wr8m
pkg: Microsoft.OpenApi.Kiota, Microsoft.OpenApi.Kiota.Builder
eco: nuget
published: Jul 24, 2026
### Summary

Microsoft Kiota honors a poisoned `.kiota/workspace.json` — the workspace configuration that Kiota's
documented team workflow has developers commit to their repository — **unvalidated** on
`kiota client generate` / `kiota plugin generate`. A repository (or pull request) containing a…

CVE-2026-59863
GitHub-GHSA

HIGH
Microsoft Kiota: Code Generation Literal Injection in Kiota PHP Generator
GHSA-jqwh-526h-c92j
pkg: Microsoft.OpenApi.Kiota, Microsoft.OpenApi.Kiota.Builder
eco: nuget
published: Jul 24, 2026
# Impact

The Kiota PHP code generator is vulnerable to a code generation literal injection attack. The generator embeds string values from OpenAPI fields (e.g. `description`, default values, and property names) directly into PHP double-quoted string literals without properly escaping the `$` charac…

CVE-2026-59859
GitHub-GHSA

HIGH
Microsoft Kiota: XML Doc-Comment Newline Breakout Code Injection
GHSA-3hrf-2gc2-mx32
pkg: Microsoft.OpenApi.Kiota, Microsoft.OpenApi.Kiota.Builder
eco: nuget
published: Jul 24, 2026
### Summary

Kiota versions **prior to 1.32.3** are affected by a code-generation injection vulnerability in the C# XML documentation-comment sink (the `description`, `externalDocs` label, and `externalDocs` link fields emitted as `/// …` comments).

When text from an OpenAPI description is writte…

CVE-2026-59860
GitHub-GHSA

HIGH
React Router: Unauthenticated Denial of Service via Inefficient Route Matching
GHSA-chx6-hx7r-mcp5
pkg: react-router
eco: npm
published: Jul 24, 2026
This is a follow up to https://github.com/remix-run/react-router/security/advisories/GHSA-8x6r-g9mw-2r78 that covers additional reported scenarios in which the manifest endpoint could be accessed via unauthenticated targeted requests that would put heavy load on the server and slow down response tim…
CVE-2026-55685
GitHub-GHSA

HIGH
LiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce
GHSA-g357-x5c3-c72p
pkg: liquidjs
eco: npm
published: Jul 24, 2026
# `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce

**CWE**: CWE-770 (Allocation of Resources Without Limits or Throttling) — sibling class of GHSA-8xx9-69p8-7jp3 and GHSA-2546-xv4c-mc8g, applied to `memoryLimit` instead of `renderLimit`

## Summary

The `pop` …

CVE-2026-55575
GitHub-GHSA

HIGH
electron-updater: Cross-origin redirect leaks `PRIVATE-TOKEN` and mixed-case `Authorization` credentials in `builder-util-runtime`
GHSA-p2f4-r6v6-j797
pkg: builder-util-runtime
eco: npm
published: Jul 24, 2026
## Summary

In `electron-builder`'s `builder-util-runtime` package, the HTTP redirect handler (`HttpExecutor.prepareRedirectUrlOptions`) only stripped a credential header whose key string matched exactly lowercase `"authorization"`. Other credential-bearing headers — most notably `PRIVATE-TOKEN` (…

CVE-2026-54673
GitHub-GHSA

HIGH
pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)
GHSA-g867-7843-wf8q
pkg: pypdf
eco: pip
published: Jul 23, 2026
### Impact

An attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires parsing the content stream of a page with a not terminated inline image, as done when extracting the page text for example. It only affects the ASCII85 and ASCIIHex filters.

### Patche…

CVE-2026-59935
GitHub-GHSA

HIGH
pypdf: Possible infinite loop for not terminated inline images
GHSA-5xf7-4p34-54qr
pkg: pypdf
eco: pip
published: Jul 23, 2026
### Impact

An attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires parsing the content stream of a page with a not terminated inline image, as done when extracting the page text for example.

### Patches

This has been fixed in [pypdf==6.14.1](https://…

CVE-2026-59936
GitHub-GHSA

HIGH
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
GHSA-pppj-hq3g-57pj
pkg: jupyterlab, jupyterlab
eco: pip
published: Jul 22, 2026
JupyterLab 4.5+ allows notebook settings to be shared and applied through an `overrides.json` file using the `Import` button in the Settings Editor.

Certain notebook display settings were not properly validated before being applied. As a result, a crafted settings file could contain hidden instruct…

GitHub-GHSA

HIGH
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
GHSA-gx64-gj6p-pc4c
pkg: jupyterlab, jupyterlab
eco: pip
published: Jul 22, 2026
JupyterLab's image viewer allows for cross-site scripting (XSS) when a specially-crafted image file is opened through the image viewer and then opened in a new tab. This XSS issue can be used to cause remote code execution (RCE) on the JupyterLab server.

### Impact

This vulnerability allows for ar…

GitHub-GHSA

HIGH
Next.js: Server-Side Request Forgery in Server Actions on custom servers
GHSA-89xv-2m56-2m9x
pkg: next, next
eco: npm
published: Jul 22, 2026
## Impact

When a Server Action forwards or redirects a request, an attacker can cause the server to send that outbound request to a malicious host (Server-Side Request Forgery). This requires the attacker's request to control Host-associated headers. In some configurations, it's also possible to ob…

CVE-2026-64649
GitHub-GHSA

HIGH
Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname
GHSA-p9j2-gv94-2wf4
pkg: next, next
eco: npm
published: Jul 22, 2026
## Impact

A `rewrites()` or `redirects()` rule that builds its external destination hostname from request-controlled input can be pointed at an arbitrary hostname, regardless of the rule's hostname suffix. For a rewrite, Next.js proxies the request to that arbitrary host and serves the response fr…

CVE-2026-64645
GitHub-GHSA

HIGH
Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale
GHSA-6gpp-xcg3-4w24
pkg: next
eco: npm
published: Jul 22, 2026
## Impact

Crafted requests targeting Next.js applications using App Router built with Turbopack and a **single** entry in `config.i18n.locales` can bypass middleware/proxy based authentication.

## Workarounds

If you cannot upgrade immediately, enforce authorization in the page's server-side data …

CVE-2026-64642
GitHub-GHSA

HIGH
Next.js: Denial of Service in App Router using Server Actions
GHSA-m99w-x7hq-7vfj
pkg: next, next
eco: npm
published: Jul 22, 2026
## Impact

Crafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processing of further requests in the same process.

## Workarounds

No workaround exists besides upgrading. Applications using Pages Router or not usi…

CVE-2026-64641
GitHub-GHSA

HIGH
Eclipse Jetty Digest Authentication: ISO-8859-1 lossy encoding allows authentication bypass via character substitution
GHSA-2fvj-hgj9-j2gr
pkg: org.eclipse.jetty:jetty-security, org.eclipse.jetty:jetty-security, org.eclipse.jetty:jetty-security
eco: maven
published: Jul 22, 2026
### Summary
The `DigestAuthentication.apply()` method in Jetty's HTTP client uses `getBytes(StandardCharsets.ISO_8859_1)` at three locations (lines 171, 179, 196) to compute Digest auth response hashes. ISO-8859-1 silently replaces any character above U+00FF (Chinese, Japanese, Cyrillic, Arabic, Emo…
CVE-2026-10050
GitHub-GHSA

HIGH
LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback
GHSA-7488-6r32-c95q
pkg: litellm
eco: pip
published: Jul 22, 2026
### Impact

LiteLLM's MCP Streamable HTTP endpoint could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.

The MCP auth handler supported OAuth2 passthrough for upstream MCP servers, but the fallback path could replace failed LiteLLM key va…

CVE-2026-59822
GitHub-GHSA

HIGH
n8n: Prototype Pollution via Dot-Notation Field Names Leads To Instance-Wide Denial of Service
GHSA-xwx6-jjhv-84p8
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact

The Edit Fields (Set) node assigned output fields through a dot-notation path setter without restricting the field name, so an authenticated user could name a field after an inherited built-in method path and corrupt a shared global in the main Node.js process. Because that global was use…

GitHub-GHSA

HIGH
n8n: Edit Image Node Format Injection Allows Arbitrary File Write
GHSA-xmc9-4f2h-jf9c
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact

The n8n Edit Image node passed its output format to the underlying image library without validation, so a crafted value could write bytes to a location outside the node's working directory. An authenticated user able to run workflows could use this to write arbitrary files in the n8n inst…

GitHub-GHSA

HIGH
n8n: Shared-Workflow Editor Can Exfiltrate Credentials via Inline Sub-Workflow JSON
GHSA-cj9h-qx8g-pq2g
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact

n8n's credential-access checks validated only a node's top-level credentials, not credentials referenced inside an Execute Sub-workflow node's inline workflow JSON. A member with editor access to a shared workflow could reference a credential they were not permitted to use inside that inl…

GitHub-GHSA

HIGH
n8n: Credential Authorization Bypass via Expression in HTTP Request Node `genericAuthType`
GHSA-6qc9-mqvw-jg7x
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact

An authenticated member with edit access to a shared workflow could reference another user's credential in an HTTP Request node while specifying the credential type through an expression. Because the pre-execution permission check compared the unresolved expression instead of the real cre…

GitHub-GHSA

HIGH
n8n: Expression sandbox escape via arrow-function bodies enabling command execution
GHSA-gv7g-jm28-cr3m
pkg: n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact

An authenticated user with permission to create or modify workflows could abuse crafted expressions using arrow functions to bypass the expression sandbox, triggering unintended system command execution on the host running n8n.

## Patches

The issue has been fixed in n8n versions 2.31.5 …

GitHub-GHSA

HIGH
n8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion
GHSA-2×35-3fw4-9jr4
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact

The n8n Send Email node did not enforce that its message fields were strings, so a crafted untrusted non-string value from a workflow expression could be treated by the underlying mail library as a file path or URL. This could allow disclosure of local files on the n8n host.

Exploitation…

GitHub-GHSA

HIGH
n8n: Authenticated code execution in the n8n Git node
GHSA-rcv6-pvrj-4xcg
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact

Authenticated n8n users with rights to create and execute workflows could achieve code execution on the n8n host. Using the Git node, under the default `git` security settings, by staging a crafted local repository, an attacker could cause `git` to run hooks, executing arbitrary commands …

GitHub-GHSA

HIGH
n8n: Git Node fetch/pull/pushTags Operations Bypass Sandbox Path Restriction
GHSA-gf29-4f56-r2jf
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact

Authenticated n8n users with workflow create/execute rights could use the Git node's fetch, pull, or push-tags operations to bypass the repository-path containment checks that already protected clone and push. By pointing an allowlisted remote configuration value at a local path outside t…

GitHub-GHSA

HIGH
n8n: Bypass "Allowed HTTP Request Domains" Credential Restriction in Multiple AI and LLM Nodes
GHSA-64xh-79j6-r5v8
pkg: n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact

The credential "Allowed HTTP Request Domains" allowlist was intended to restrict which hosts a credential's secret could be sent to, protecting shared credentials from users who could use but not view them. Several AI/LLM nodes did not enforce this allowlist when a user-supplied base or e…

GitHub-GHSA

HIGH
n8n: Account Takeover via Unverified Email Claim in Token Exchange Embed Login
GHSA-8342-988q-86cr
pkg: n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact

In an n8n instance, when a validly-signed incoming token was matched to a local account by its email claim, the service did not check that the trusted key's permitted role ceiling covered that account, nor that the email claim was verified. As a result, anyone able to obtain a token accep…

GitHub-GHSA

HIGH
n8n: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner
GHSA-35q8-9mj6-wjmf
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact
n8n's Enterprise SSO instance-role provisioning maps a role claim asserted by the configured Identity Provider (IdP) to an n8n global role and applies it during authentication. The provisioning path did not prevent assignment of the `global:owner` role, unlike the token-exchange identity p…
CVE-2026-65016
GitHub-GHSA

HIGH
n8n: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution
GHSA-pm35-fqvh-cq5g
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact
The legacy expression evaluator's computed-member sanitizer can be bypassed by an authenticated user with workflow create or modify permissions. Successful exploitation grants the attacker host-level code execution as the n8n process.

The legacy expression engine is the default engine in …

CVE-2026-65591
GitHub-GHSA

HIGH
Netty: [Bzip2Decoder] Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang
GHSA-558v-64gr-wgg4
pkg: io.netty:netty-codec-compression, io.netty:netty-codec
eco: maven
published: Jul 22, 2026
The `Bzip2Decoder` handler in Netty's compression codec pipeline is vulnerable to a denial-of-service attack through a malformed bzip2 stream that permanently captures the event-loop thread in an infinite loop. The vulnerability exists in the run-length encoding (RLE) state machine within [`Bzip2Blo…
CVE-2026-59901
GitHub-GHSA

HIGH
Netty XML: Injection / Risky Sink — unconfigured XML factory with active DTD and entity handling
GHSA-4qhr-g3c6-fcfx
pkg: io.netty:netty-codec-xml, io.netty:netty-codec-xml
eco: maven
published: Jul 22, 2026
Any caller that can deliver bytes to a Netty channel pipeline containing `XmlDecoder` can send XML with a DOCTYPE declaration to a parser instantiated with no security configuration — but whether external entities are actually resolved depends on Aalto XML's async parser behavior, making this a co…
CVE-2026-56817
GitHub-GHSA

HIGH
Netty: [SpdyHttpDecoder] ByteBuf Reference Leak on RST_STREAM Leads to Native Memory Exhaustion
GHSA-jppx-w49h-x2qq
pkg: io.netty:netty-codec-http, io.netty:netty-codec-http
eco: maven
published: Jul 22, 2026
The `SpdyHttpDecoder` handler in Netty's SPDY-to-HTTP codec allocates a pooled `ByteBuf` when processing a client-initiated `SYN_STREAM` frame with `FLAG_FIN=0`, storing the partially-constructed `FullHttpRequest` in an internal map (`messageMap`) to accumulate subsequent `DATA` frames. When the rem…
CVE-2026-56745
GitHub-GHSA

HIGH
Netty: [codec-haproxy] Signed-Byte Sentinel Collision in HAProxyMessageDecoder Leads to Unbounded Memory Exhaustion
GHSA-q6cq-mhr2-jmr5
pkg: io.netty:netty-codec-haproxy, io.netty:netty-codec-haproxy
eco: maven
published: Jul 22, 2026
The `HAProxyMessageDecoder` in netty's `codec-haproxy` module performs protocol version detection by reading the 13th byte of the inbound stream as a signed Java `byte` and widening it to `int` without masking. When an attacker sends a PROXY protocol v2 binary prefix (`0D 0A 0D 0A 00 0D 0A 51 55 49 …
CVE-2026-55851
GitHub-GHSA

HIGH
gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
GHSA-hrxh-6v49-42gf
pkg: google.golang.org/grpc
eco: go
published: Jul 21, 2026
Multiple security vulnerabilities have been identified and addressed in grpc-go affecting the xDS RBAC authorization engine (internal/xds/rbac) and the HTTP/2 transport server implementation (internal/transport). These vulnerabilities could result in:

– Authorization Bypass (Fail-Open) when transla…

GitHub-GHSA

HIGH
jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
GHSA-r7wm-3cxj-wff9
pkg: com.fasterxml.jackson.core:jackson-core, com.fasterxml.jackson.core:jackson-core, com.fasterxml.jackson.core:jackson-core
eco: maven
published: Jul 21, 2026
## Summary

The fix released in jackson-core `2.18.6` and `2.21.1` for [GHSA-72hv-8253-57qq](https://github.com/FasterXML/jackson-core/security/advisories/GHSA-72hv-8253-57qq) (Number Length Constraint Bypass in Async Parser, published 2026-02-28) is incomplete. The fix commit `b0c428e6` (#1555) wir…

GitHub-GHSA

HIGH
Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts
GHSA-g9g6-qhrc-p3qc
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary

The OAuth2 sign-in callback in Gitea 1.26.1 unconditionally re-enables a locally-disabled account whenever the user authenticates through a linked external identity provider, silently undoing any administrator-initiated `Disable Account` action and issuing a fresh authenticated session …

CVE-2026-58422
GitHub-GHSA

HIGH
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests
GHSA-fw57-jgch-pgf3
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary

The Locale middleware that runs in front of every unauthenticated request
calls `golang.org/x/text/language.ParseAcceptLanguage` on the raw
`Accept-Language` header without imposing a size or shape filter. The
underlying parser has quadratic-time behaviour on long lists of malformed
lan…

CVE-2026-58436
GitHub-GHSA

HIGH
Gitea: Privilege Escalation via Access Token Scope Escalation in API
GHSA-683j-3ff6-hh2x
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
Gitea's API endpoint for creating Personal Access Tokens (`POST /users/{username}/tokens`) is protected by a middleware (`reqBasicOrRevProxyAuth`) that is intended to require password-based authentication, preventing a compromised token from being used to mint new ones. However, when a token is pass…
CVE-2026-56654
GitHub-GHSA

HIGH
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload
GHSA-6hm7-3pwj-22rm
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
Gitea's Debian package registry parser contains an unbounded decompression vulnerability in [ParseControlFile](https://github.com/go-gitea/gitea/blob/689ace1ce28fd74244b8aa335d9928cdbf6b22f9/modules/packages/debian/metadata.go#L140). When processing an uploaded `.deb` file, the parser decompresses `…
CVE-2026-56755
GitHub-GHSA

HIGH
GitPython unsafe clone option gate bypass through joined short options
GHSA-v396-v7q4-x2qj
pkg: GitPython
eco: pip
published: Jul 21, 2026
`GitPython` version `3.1.50` blocks unsafe `git clone` options such as `–upload-pack`, `-u`, `–config`, and `-c` unless callers explicitly pass `allow_unsafe_options=True`. However, the default unsafe-option gate does not recognize joined short-option forms such as `-u/path/to/helper`.

Git itself…

GitHub-GHSA

HIGH
websocket-driver-ruby: Denial of service via malformed Host header
GHSA-2×63-gw47-w4mm
pkg: websocket-driver
eco: rubygems
published: Jul 21, 2026
### Impact

If this library is used to implement a WebSocket server on top of a TCP server, by using the `WebSocket::Driver.server()` method, then a client can cause the server to crash by sending a `Host` header that is not a valid `host[:port]` string. When this happens, a `URI::InvalidURIError` e…

CVE-2026-61666
GitHub-GHSA

HIGH
PostgreSQL JDBC Driver: Silent channel-binding authentication downgrade via unsupported certificate algorithms
GHSA-j92g-9f8w-j867
pkg: org.postgresql:postgresql
eco: maven
published: Jul 21, 2026
### Impact

`channelBinding=require` connections can be silently downgraded from `SCRAM-SHA-256-PLUS` (with channel binding) to plain `SCRAM-SHA-256` (without it), losing the man-in-the-middle protection the setting is meant to guarantee. An attacker who can intercept the TLS connection triggers the…

CVE-2026-54291
GitHub-GHSA

HIGH
Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service
GHSA-vjc4-5qp5-m44j
pkg: pillow
eco: pip
published: Jul 20, 2026
### Summary
`src/libImaging/Jpeg2KDecode.c:853` accumulates `total_component_width` across every tile in a JPEG2000 image instead of recomputing it per tile. That accumulated value is then used in the `tile_bytes` calculation at `src/libImaging/Jpeg2KDecode.c:868`, which can make the decoder grow `s…
CVE-2026-59204
GitHub-GHSA

HIGH
Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)
GHSA-62p4-gmf7-7g93
pkg: pillow
eco: pip
published: Jul 20, 2026
## Summary

When Pillow loads an uncompressed image whose tile uses the `raw` codec and a mode in `Image._MAPMODES`, and the image was opened **from a filename**, it memory-maps the file and builds the image's row pointers directly into the mapping via `PyImaging_MapBuffer` (`src/map.c`). The per-ro…

CVE-2026-54058
GitHub-GHSA

HIGH
vLLM denial of service via prompt embeds on M-RoPE models
GHSA-33cg-gxv8-3p8g
pkg: vllm
eco: pip
published: Jul 20, 2026
### Summary
_Short summary of the problem. Make the impact and severity as clear as possible. For example: An unsafe deserialization vulnerability allows any unauthenticated user to execute arbitrary code on the server._

Sending a pure prompt embeds payload in a `/v1/completions` request with a mod…

CVE-2026-55514
GitHub-GHSA

MEDIUM
React Router: Open redirect leading to XSS
GHSA-jjmj-jmhj-qwj2
pkg: react-router-dom, react-router
eco: npm
published: Jul 23, 2026
Applications with open redirects could permit attacker crafted links to result in redirects to unexpected external location or XSS vectors.
CVE-2026-53668
GitHub-GHSA

MEDIUM
React Router: RSCErrorHandler Missing Protocol Validation (XSS)
GHSA-h8fp-f39c-q6mh
pkg: react-router
eco: npm
published: Jul 23, 2026
This is a follow up to https://github.com/remix-run/react-router/security/advisories/GHSA-8646-j5j9-6r62. React Router was alerted of a code path in the (unstable) RSC error handling path in which redirects from untrusted sources could still result in an XSS vector via attacker-supplied redirect ta…
CVE-2026-53667
GitHub-GHSA

MEDIUM
Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them
GHSA-x445-f3h2-j279
pkg: @auth/core, next-auth, next-auth
eco: npm
published: Jul 23, 2026
## Summary

Auth.js stores the OAuth/OIDC anti-CSRF checks (`state`, `nonce`, and the PKCE verifier) in global cookies that are not bound to the provider that created them. On callback, a check value minted during a sign-in started with one provider can satisfy the callback for a different provider,…

NVD

MEDIUM
CVE-2026-16615
CVE-2026-16615
pkg: oauth

published: Jul 22, 2026

A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated "code verifier" lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer th…
CWE: CWE-338
GitHub-GHSA

MEDIUM
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content
GHSA-66m4-5jjr-2rg5
pkg: gitea.dev
eco: go
published: Jul 21, 2026
## Affected product
Gitea — `services/repository/collaboration.go` (`DeleteCollaboration`) + webhook delivery

## Summary
When a collaborator with admin permission on a private repo creates a webhook, that webhook keeps firing
after the collaborator's access is revoked. Gitea's revocation cleanup …

CVE-2026-58440
GitHub-GHSA

MEDIUM
File Browser: Archive builder turns backslash filenames into path traversal (zip-slip)
GHSA-83xp-526h-j3ww
pkg: github.com/filebrowser/filebrowser/v2
eco: go
published: Jul 20, 2026
## Summary

The fix for `GHSA-gxjx-7m74-hcq8` / `CVE-2026-54093` (shipped in v2.63.6) added a `strings.ReplaceAll(nameInArchive, "\\", "/")` step to the archive builder; this was the advisory's recommended "Primary Fix." On a Linux host a backslash is a legal, non-separator filename character, so re…

CVE-2026-62843
NVD

MEDIUM
CVE-2026-60406
CVE-2026-60406
pkg: kubernetes

published: Jul 21, 2026

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where TimesTen In…
CWE: CWE-269
NVD

MEDIUM
CVE-2026-63729
CVE-2026-63729
pkg: node

published: Jul 21, 2026

The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedded by downstream consumers such as GNOME Evince contains a heap use-after-free vulnerability that allows attackers to crash applications or potentially execute arbitrary code by supplying a malformed .synctex or .synctex.gz file. …
CWE: CWE-416
GitHub-GHSA

MEDIUM
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API
GHSA-86cx-wwf4-phq4
pkg: github.com/OpenListTeam/OpenList/v4
eco: go
published: Jul 24, 2026
### Summary
An authorization bypass vulnerability exists in the file sharing mechanism of `Openlist`. Due to a flawed, non-separator-aware path validation check, an authenticated user can create share links for files outside their restricted base directory. This allows an attacker to bypass tenant/u…
GitHub-GHSA

MEDIUM
Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources
GHSA-c534-2w9c-x7fm
pkg: github.com/zxh326/kite
eco: go
published: Jul 24, 2026
## Summary

Kite versions 0.6.9 through 0.14.0 authorize Kubernetes proxy requests against the pod or service identified by the original route parameters. Encoded path traversal segments can cause the upstream URL to resolve to a different Kubernetes API endpoint after authorization.

## Impact

An …

GitHub-GHSA

MEDIUM
Cloudreve: Denial of Service – Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server
GHSA-g9j2-8w95-3vwv
pkg: github.com/cloudreve/Cloudreve/v4, github.com/cloudreve/Cloudreve/v3
eco: go
published: Jul 24, 2026
## Summary

Cloudreve's built-in image processor decodes user-supplied images with Go's standard-library decoders (`image/png`, `image/jpeg`, `image/gif`) and guards **only the compressed file size** — never the *decoded* pixel dimensions. Go's decoders allocate a pixel buffer sized `bytesPerPixel…

CVE-2026-55497
GitHub-GHSA

MEDIUM
Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config
GHSA-ffpj-xv5c-p3gw
pkg: open-webui
eco: pip
published: Jul 24, 2026
## Summary
Two regexes in `backend/open_webui/utils/middleware.py` that parse `<$skillId|label>` skill-mention tags backtrack in O(n²) on input that contains `<$` followed by a long run with no closing `>`. Both run synchronously, on the asyncio event loop, on **every** chat completion with no feat…
CVE-2026-59220
GitHub-GHSA

MEDIUM
Mongoose: Prototype pollution in mongoose update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter)
GHSA-664h-wqgq-64gw
pkg: mongoose, mongoose, mongoose
eco: npm
published: Jul 24, 2026
### Impact
_What kind of vulnerability is it? Who is impacted?_

Prototype pollution in update casting: passing a user-controlled update to a Mongoose update, like `MyModel.updateOne(filter, req.body)`, can cause Mongoose to set `$fullPath` and `$parentSchemaDocArray` on `Object.prototype`.

Example…

GitHub-GHSA

MEDIUM
LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges
GHSA-xx22-p4ch-683r
pkg: at.yawk.lz4:lz4-java, org.lz4:lz4-java
eco: maven
published: Jul 24, 2026
### Summary

Insufficient validation of byte array arguments in JNI-based XXHash implementations in lz4-java 1.11.0 and earlier allows callers to crash the JVM by passing an invalid array reference or invalid range to native XXHash methods.

This affects applications where an attacker can influence …

CVE-2026-59949
NVD

MEDIUM
CVE-2026-16798
CVE-2026-16798
pkg: oauth

published: Jul 24, 2026

Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with scoped job or script read permission to obtain another user's stored OAuth refresh token via job read responses that fail to strip t…
CWE: CWE-201
GitHub-GHSA

MEDIUM
Netty: STOMP CONNECT Frame Header Injection in Netty
GHSA-3g8r-4pfx-jmfh
pkg: io.netty:netty-codec-stomp, io.netty:netty-codec-stomp
eco: maven
published: Jul 22, 2026
# Security Vulnerability Report: STOMP CONNECT Frame Header Injection in Netty

## 1. Vulnerability Summary

| Field | Value |
|——-|——-|
| **Product** | Netty |
| **Version** | 4.2.12.Final (and all prior versions with codec-stomp) |
| **Component** | `io.netty.handler.codec.stomp.StompSubfr…

CVE-2026-59920
GitHub-GHSA

MEDIUM
Netty: Security Control Bypass via CORS Short-Circuit Failure
GHSA-6cqp-g7gg-8hr5
pkg: io.netty:netty-codec-http, io.netty:netty-codec-http
eco: maven
published: Jul 22, 2026
### Summary
Netty's CorsHandler provides a `shortCircuit()` configuration designed to reject unauthorized cross-origin requests immediately, acting as a security control before requests reach the application. However, due to a logical operator error in the origin evaluation process, this protection …
CVE-2026-56746
NVD

MEDIUM
CVE-2026-9737
CVE-2026-9737
pkg: express

published: Jul 22, 2026

During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly handle the meta expression case. This may lead to incorrect transformations leading to invariant failure.
CWE: CWE-617
NVD

MEDIUM
CVE-2026-13071
CVE-2026-13071
pkg: express

published: Jul 22, 2026

An authenticated user with read access can cause the mongod process to be terminated through certain aggregation expressions that execute server-side JavaScript. The issue involves improper memory handling during document processing.
CWE: CWE-416
NVD

MEDIUM
CVE-2026-13065
CVE-2026-13065
pkg: express

published: Jul 22, 2026

A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window function operator with a specific sortBy expression type to cause the mongod process to terminate abnormally, resulting in denial of service. The issue stems from insufficient validation of sort sp…
CWE: CWE-476
NVD

MEDIUM
CVE-2026-13056
CVE-2026-13056
pkg: express

published: Jul 22, 2026

Using expressions that generate large arrays it is possible to craft a query that creates very large intermediate objects in memory, causing the server to crash with OOM error.
CWE: CWE-1325
NVD

MEDIUM
CVE-2026-13055
CVE-2026-13055
pkg: express

published: Jul 22, 2026

The `$_internalIndexKey` aggregation expression can be used by any authenticated user to crash a MongoDB server (mongod). The expression fails to handle compound wildcard index specifications, triggering an internal consistency check that aborts the server process. The user must be able to run an ag…
CWE: CWE-617
NVD

MEDIUM
CVE-2026-13192
CVE-2026-13192
pkg: windows

published: Jul 22, 2026

In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of content submitted to the RadEditor PDF export feature may allow an authenticated attacker to trigger server-side requests to arbitrary hosts, resulting in outbound network connections and potential exposure of Windo…
CWE: CWE-918
NVD

MEDIUM
CVE-2026-63263
CVE-2026-63263
pkg: node

published: Jul 22, 2026

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Data Expansion (CAPEC-197). An authenticated user may submit a specially crafted query to the ES|QL engine that causes exponential CPU consumption during query evaluation. Because the resource …
CWE: CWE-400
NVD

MEDIUM
CVE-2026-63144
CVE-2026-63144
pkg: node

published: Jul 21, 2026

Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a specially crafted search request submitted by a low-privileged authenticated user. A user with read-level index access can submit a request that triggers unbounded recursive processing within the Elasticsearch quer…
CWE: CWE-674
NVD

MEDIUM
CVE-2026-60404
CVE-2026-60404
pkg: kubernetes

published: Jul 21, 2026

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTe…
CWE: CWE-400
NVD

MEDIUM
CVE-2026-60403
CVE-2026-60403
pkg: kubernetes

published: Jul 21, 2026

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTe…
CWE: CWE-400
NVD

MEDIUM
CVE-2026-60401
CVE-2026-60401
pkg: kubernetes

published: Jul 21, 2026

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where TimesTen In-…
CWE: CWE-284
NVD

MEDIUM
CVE-2026-60399
CVE-2026-60399
pkg: go

published: Jul 21, 2026

Vulnerability in Oracle GoldenGate (component: Receiver Service Executable). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle GoldenGate. Su…
CWE: CWE-400
NVD

MEDIUM
CVE-2026-10677
CVE-2026-10677
pkg: node

published: Jul 21, 2026

The CONFIG_USERSPACE syscall verifier z_vrfy_k_poll() in kernel/poll.c allocates a kernel-side copy of the user-supplied k_poll_event[] via z_thread_malloc() and then validates each event's object handle. Before this fix, validation used K_OOPS(K_SYSCALL_OBJ(…)) inline inside the loop, which kills…
CWE: CWE-401
GitHub-GHSA

MEDIUM
jackson-databind: @JsonView ypassed for @JsonUnwrapped container properties on deserialization
GHSA-5gvw-p9qm-jgwh
pkg: com.fasterxml.jackson.core:jackson-databind, tools.jackson.core:jackson-databind, com.fasterxml.jackson.core:jackson-databind
eco: maven
published: Jul 21, 2026
## Summary
`UnwrappedPropertyHandler.processUnwrapped()` replays the buffered JSON for a `@JsonUnwrapped` property by iterating its properties and calling `prop.deserializeAndSet()` with **no `prop.visibleInView(ctxt.getActiveView())` guard** — the exact guard `processUnwrappedCreatorProperties()`…
CVE-2026-59889
GitHub-GHSA

MEDIUM
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs
GHSA-frpw-3h2q-4jj6
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
**Author:** Prakhar Porwal
**Date:** 2026-05-24
**Target:** Gitea (self-hosted Git service)
**Branch tested:** `main` @ `b7e95cc48c` (development build, go1.26.3)
**Component:** `routers/api/v1/org/action.go` (org-level Actions API)
**OWASP:** API3:2023 Broken Object Property Level Authorization

–…

CVE-2026-57897
NVD

MEDIUM
CVE-2026-63140
CVE-2026-63140
pkg: node

published: Jul 21, 2026

Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted search request containing a null value in a specific query clause causes an internal assertion to be raised during query parsing. Because Elasticsearch treats ass…
CWE: CWE-617
NVD

MEDIUM
CVE-2026-63136
CVE-2026-63136
pkg: node

published: Jul 21, 2026

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A user with search privileges can submit a specially crafted search request that causes a data node to exhaust available heap memory, resulting in node unavailability and …
CWE: CWE-400
NVD

MEDIUM
CVE-2026-46556
CVE-2026-46556
pkg: python

published: Jul 21, 2026

FlaskBB is a Forum Software written in Python using the micro framework Flask. Prior to version 2.2.1, a Server-Side Request Forgery (SSRF) vulnerability in get_image_info() allows any authenticated user to force the server to send HTTP requests to arbitrary internal endpoints, including cloud metad…
CWE: CWE-918
NVD

MEDIUM
CVE-2026-16317
CVE-2026-16317
pkg: tls

published: Jul 21, 2026

Missing validation of the outer content_type byte on TLS 1.3 encrypted records in s2n-tls allows an active man-in-the-middle to silently discard individual application data records without either endpoint detecting the modification. RFC 8446 Section 5.2 requires that the outer content_type of all en…
CWE: CWE-354
GitHub-GHSA

MEDIUM
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint
GHSA-wwqq-x6w4-frm2
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary
An unbounded `io.ReadAll(ctx.Req.Body)` call in the NPM package tag API endpoint allows any authenticated user to crash the Gitea server by sending a single large HTTP request. The request body is read entirely into memory with no size limit, causing an Out-of-Memory (OOM) kill. With con…
CVE-2026-42931
GitHub-GHSA

MEDIUM
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass
GHSA-h2x6-g7q6-344v
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary

Gitea's repository migration URL validation can be bypassed when a migration hostname resolves to multiple IP addresses. The validation logic accepts the destination if **any** resolved IP is allowed, even if another resolved IP is loopback, private, or otherwise blocked. The later `git…

CVE-2026-58442
GitHub-GHSA

MEDIUM
Gitea: SSRF via HTTP Redirect in Repository Migration
GHSA-rqhx-647v-wx32
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
## Summary

Gitea 1.25.4 validates the initial URL provided to the repository migration endpoint (`POST /api/v1/repos/migrate`) and correctly blocks requests to internal addresses like `127.0.0.1` or RFC1918 ranges. However, if the initial URL points to an attacker-controlled server that responds wi…

CVE-2026-58418
GitHub-GHSA

MEDIUM
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
GHSA-25gq-j9jx-43pg
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
## Summary

The web handler `EditReleasePost` (`routers/web/repo/release.go`) reads form fields with prefix `attachment-edit-{uuid}` into a `map[uuid]newName`, passes that map to `release_service.UpdateRelease`, which writes the new name to the database via `repo_model.UpdateAttachmentByUUID` WITHOU…

CVE-2026-58428
NVD

MEDIUM
CVE-2026-56145
CVE-2026-56145
pkg: node

published: Jul 21, 2026

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user with permission to execute EQL sequence queries against an index they control can send a specially crafted query that triggers excessiv…
CWE: CWE-400
GitHub-GHSA

MEDIUM
jackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)`
GHSA-mhm7-754m-9p8w
pkg: com.fasterxml.jackson.core:jackson-databind, com.fasterxml.jackson.core:jackson-databind
eco: maven
published: Jul 21, 2026
## Summary

In `BeanDeserializer.deserializeUsingPropertyBasedWithExternalTypeId`, the active-view (`@JsonView`) filter was applied only to the regular bean-property branch; the creator-property branch performed no `creatorProp.visibleInView(activeView)` check. A constructor parameter annotated with…

GitHub-GHSA

MEDIUM
jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategy
GHSA-3pjw-73gf-8qr5
pkg: com.fasterxml.jackson.core:jackson-databind, com.fasterxml.jackson.core:jackson-databind, tools.jackson.core:jackson-databind
eco: maven
published: Jul 21, 2026
## Summary
For Java Records, `POJOPropertiesCollector._removeUnwantedIgnorals()` records a `@JsonIgnore`-annotated component under its original implicit name before `_renameUsing()` applies the `PropertyNamingStrategy`. After the rename, `_ignoredPropertyNames` still holds only the pre-rename name, …
CVE-2026-59888
GitHub-GHSA

MEDIUM
Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images
GHSA-fj7v-r99m-22gq
pkg: Pillow
eco: pip
published: Jul 20, 2026
### Summary

Pillow's TGA RLE encoder reads past its row buffer when saving a mode `"1"`
image. Adjacent process heap bytes can be copied into the generated TGA file.

The bug is reachable through the public save API:

“`python
im.save(out, format="TGA", compression="tga_rle")
“`

Older affected P…

CVE-2026-59198
GitHub-GHSA

MEDIUM
Microsoft Security Advisory CVE-2026-50659 – .NET Spoofing Vulnerability
GHSA-74jp-vm22-8q8x
pkg: Microsoft.NetCore.App.Runtime.linux-arm, Microsoft.NetCore.App.Runtime.linux-arm64, Microsoft.NetCore.App.Runtime.linux-musl-arm
eco: nuget
published: Jul 20, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET SMTP client (System.Net.Mail). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A spoofing vulnerability …

CVE-2026-50659
GitHub-GHSA

MEDIUM
Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses
GHSA-x756-g4x3-c64m
pkg: github.com/cloudreve/Cloudreve/v4, github.com/cloudreve/Cloudreve/v3
eco: go
published: Jul 20, 2026
## Summary

Cloudreve's remote download workflow accepts user-supplied URLs and passes them to the configured downloader without blocking loopback, localhost, IPv6 localhost, or redirect-to-loopback targets.

When the remote download permission is granted to a non-admin user group, a normal authenti…

CVE-2026-54562
NVD

MEDIUM
CVE-2026-63737
CVE-2026-63737
pkg: surrealdb surrealdb

published: Jul 20, 2026

SurrealDB versions before 3.1.5 contain a denial of service vulnerability where authenticated users can crash the server with queries containing long chains of operators. Attackers can submit queries with tens of thousands of chained operators that create unbounded expression trees, causing stack ov…
CWE: CWE-674
NVD

MEDIUM
CVE-2026-61217
CVE-2026-61217
pkg: ssl

published: Jul 21, 2026

Vulnerability in the Oracle Security Service product of Oracle Fusion Middleware (component: Oracle SSL API). The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows low privileged attacker with network access via TLS to compromise Oracle Security Service. …
CWE: CWE-284, CWE-290, CWE-352
GitHub-GHSA

MEDIUM
Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored
GHSA-c3jm-gv5r-9wcp
pkg: github.com/cloudreve/Cloudreve/v4, github.com/cloudreve/Cloudreve/v3
eco: go
published: Jul 24, 2026
## Summary

Cloudreve WOPI access tokens are generated as `<session-id>.<random-secret>`, but the WOPI middleware validates only the session id prefix and never compares the supplied token to the stored token. In addition, a WOPI viewer session does not store or enforce the requested viewer action. …

CVE-2026-62323
NVD

MEDIUM
CVE-2026-13067
CVE-2026-13067
pkg: tls

published: Jul 22, 2026

When PROXY protocol v2 is used on the Unix domain socket path, roles derived from X.509 client certificates may not be validated against the configured tlsCATrusts allow-list. This can result in unintended role assignments following MONGODB-X509 authentication. Affected scenarios require local acces…
CWE: CWE-863
GitHub-GHSA

MEDIUM
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)
GHSA-fj8v-hjwv-qm88
pkg: gitea.dev
eco: go
published: Jul 21, 2026
### Summary

`GetActionsUserRepoPermission` (`models/perm/access/repo_permission.go`) decides whether an Actions
task token may access a target repo. Its cross-repo branches each enforce a fork-PR discriminator —
**except the collaborative-owner branch**, which is missing the `!task.IsForkPullRequ…

CVE-2026-58416
GitHub-GHSA

MEDIUM
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL
GHSA-xmj7-xj85-hfc3
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary
Gitea's `restore-repo` CLI command restores a repository from a dump
directory/archive. When parsing `pull_request.yml` from that dump, the
`Head.CloneURL` field is used to add a git remote and fetch from it with
no validation, because the safety check that's supposed to guard it
(`Check…
CVE-2026-58441
NVD

MEDIUM
CVE-2026-46403
CVE-2026-46403
pkg: go

published: Jul 21, 2026

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, KVM exposes `ExecuteReadOnlyWithTypedArguments` as a read-only execution mechanism. The hook saves the previous read-only state, sets `runtime.SetReadOnly(true)`, executes the destination context, and then restore…
CWE: CWE-693
GitHub-GHSA

MEDIUM
File Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scope
GHSA-8wc8-hf36-mjh9
pkg: github.com/filebrowser/filebrowser/v2
eco: go
published: Jul 20, 2026
## Summary

`ScopedFs` confines every File Browser user to a scope directory. Its `within()` guard is meant to reject any operation that follows a symbolic link out of that scope. When the link target does not exist yet, the guard walks up to the nearest existing ancestor and validates that instead.…

CVE-2026-55668
GitHub-GHSA

MEDIUM
Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data
GHSA-fwjx-9p69-h25h
pkg: github.com/jandedobbeleer/oh-my-posh
eco: go
published: Jul 24, 2026
### Summary
Oh My Posh renders dynamic, potentially attacker-controlled strings (the current directory name, Git commit metadata, environment variable values, command output) into the prompt without neutralizing raw terminal control characters. An attacker who controls one of these values can inject…
GitHub-GHSA

MEDIUM
OpenAM Reflected XSS in the OAuth2/OIDC `wap` consent page
GHSA-vqxv-6xrh-49cp
pkg: org.openidentityplatform.openam:openam-oauth2
eco: maven
published: Jul 24, 2026
### Description
The OAuth2/OIDC consent page rendered for `display=wap` authorize requests reflected several request-derived values into the HTML response without escaping. An attacker who induces a user with an active OpenAM session to follow a crafted authorize link can execute arbitrary JavaScrip…
CVE-2026-62280
GitHub-GHSA

MEDIUM
ImageMagick: Policy Bypass in concatenate operation due to missing checks
GHSA-82mp-vp5c-9pf7
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Jul 24, 2026
The `-concatenate` operation is missing policy checks and that could result in both reading and writing to paths disallowed by the security policy.
CVE-2026-55628
GitHub-GHSA

MEDIUM
React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration
GHSA-337j-9hxr-rhxg
pkg: react-router
eco: npm
published: Jul 23, 2026
If application code allows attacker supplied input to overwrite certain aspects of errors caught by the SSR process, then it was possible for attacker to trigger unexpected constructor execution on the client which would trigger outbound network traffic. This is only possible with very specific (an…
CVE-2026-53666
NVD

MEDIUM
CVE-2026-65901
CVE-2026-65901
pkg: node

published: Jul 23, 2026

DOMPurify through 3.4.6 contains a cross-site scripting vulnerability in IN_PLACE mode that trusts attacker-controlled nodeName on live non-form nodes. Attackers can supply hostile live DOM objects with real script children whose observable nodeName is clobbered to appear as allowed elements, causin…
CWE: CWE-79
NVD

MEDIUM
CVE-2026-65900
CVE-2026-65900
pkg: express

published: Jul 23, 2026

DOMPurify versions >=3.0.0 and before 3.4.8, when configured with SAFE_FOR_TEMPLATES together with a DOM output mode (RETURN_DOM, RETURN_DOM_FRAGMENT, or IN_PLACE), fail to strip template expressions (e.g. ${evil}, {{evil}}, <%evil%>) inside <template> element content. The final normalization/scrub …
CWE: CWE-79
GitHub-GHSA

MEDIUM
setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+
GHSA-h35f-9h28-mq5c
pkg: setuptools
eco: pip
published: Jul 21, 2026
## Summary

When building a source distribution (`python -m build –sdist` / `setup.py sdist`), setuptools' `FileList` applies `MANIFEST.in` directives (`exclude`, `global-exclude`, `recursive-exclude`, `prune`) by matching a compiled glob against on-disk file names **byte-for-byte, with no Unicode …

CVE-2026-59890
GitHub-GHSA

MEDIUM
Mistune renderers/html.safe_url: HARMFUL_PROTOCOLS list misses legacy and chained schemes that historically chain to `javascript:` execution
GHSA-qfrw-5rxm-mhh2
pkg: mistune
eco: pip
published: Jul 20, 2026
## Summary

**Type:** URL-scheme allowlist gap. The `safe_url` filter only blocks the four schemes `javascript:`, `vbscript:`, `file:`, `data:`. Several other schemes are accepted into rendered `<a href="…">` and `<img src="…">` tags despite being known XSS vectors in legacy or chain-handling br…

CVE-2026-59929
GitHub-GHSA

MEDIUM
Mistune: XSS via percent-encoded javascript URI bypass in safe_url()
GHSA-8c25-4j27-2rv3
pkg: mistune
eco: pip
published: Jul 20, 2026
### Summary
An XSS vulnerability in Mistune allows bypassing of safe_url() protections via percent-encoded javascript URIs.

### Details
The vulnerability exists in HTMLRenderer.safe_url() in Mistune.

The function is intended to block harmful URL schemes such as "javascript:" by checking the prefi…

CVE-2026-59923
GitHub-GHSA

MEDIUM
FrontMCP: Server-Side Request Forgery (SSRF) in the OpenAPI adapter spec-change poller
GHSA-8q49-2h5h-434x
pkg: @frontmcp/adapters
eco: npm
published: Jul 24, 2026
## Summary

The OpenAPI adapter's spec-change **poller** (`OpenApiSpecPoller`) re-fetched the
configured spec `url` on a timer using a raw global `fetch()`, bypassing the SSRF
guard (`safeFetch` / `assertUrlSafe`) that `OpenAPIToolGenerator.fromURL()` applies
to the initial spec load. As a result, t…

NVD

MEDIUM
CVE-2026-55990
CVE-2026-55990
pkg: nlnetlabs unbound

published: Jul 22, 2026

In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' clause lists more 'dnscrypt-provider-cert:' files than there are matching 'dnscrypt-secret-key:' files, Unbound fills only the matched prefix and leaves the tail slots at the '0xdb' fill that libsodium's allocator writes in…
CWE: CWE-457
NVD

MEDIUM
CVE-2026-50046
CVE-2026-50046
pkg: nlnetlabs unbound

published: Jul 22, 2026

In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS server name used for DNS-over-TLS (DoT) forwarded queries is tied to a struct's ('serviced_query') lifetime but also referenced by another struct ('waiting_tcp'). When the owning struct is jostled out of the mesh while the DoT TCP stre…
CWE: CWE-416
NVD

MEDIUM
CVE-2026-60266
CVE-2026-60266
pkg: tls

published: Jul 21, 2026

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Orac…
CWE: CWE-200
NVD

MEDIUM
CVE-2026-46968
CVE-2026-46968
pkg: tls

published: Jul 21, 2026

Vulnerability in Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit vulnerability allo…
CWE: CWE-284
GitHub-GHSA

MEDIUM
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content
GHSA-6c6r-5xr4-cr5m
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
## Summary

Gitea's issue and comment attachment update paths accept attachment UUIDs without verifying that each attachment belongs to the target issue/comment repository. If an authenticated attacker knows a victim attachment UUID, they can re-link that attachment to an attacker-controlled issue o…

CVE-2026-57886
GitHub-GHSA

MEDIUM
Gitea: draft release attachment disclosure via missing web authorization
GHSA-q9pg-jj6x-j9p6
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary

Gitea's draft-release access control is enforced only on the API release endpoints (`/api/v1/repos/{owner}/{repo}/releases/{id}` and its `/assets/…` sub-routes) but not on the web-level UUID-based attachment endpoints (`/attachments/{uuid}`, `/{owner}/{repo}/attachments/{uuid}`, `/{ow…

CVE-2026-58432
NVD

MEDIUM
CVE-2026-59847
CVE-2026-59847
pkg: openssl

published: Jul 21, 2026

A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection.
CWE: CWE-1310
GitHub-GHSA

MEDIUM
Mistune: Arbitrary File Read via Include directive path traversal
GHSA-r4rv-85jg-w4mf
pkg: mistune
eco: pip
published: Jul 20, 2026
### Summary

A path traversal issue exists in mistune's `Include` directive when markdown files are processed using `md.read()`. A crafted include path can cause files outside the intended markdown directory to be accessed.

### Details

The issue occurs in the `Include.parse()` method where user-su…

CVE-2026-59924
NVD

MEDIUM
CVE-2026-45712
CVE-2026-45712
pkg: go

published: Jul 20, 2026

Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the screenshot/print proxy (/proxy?data=…) maintains a package-level assets map[string]MessageAssets cache, but reads the map without holding assetsMutex while a long-running cleanup goroutine and (re-entrant) CSS-re…
CWE: CWE-362, CWE-770
NVD

MEDIUM
CVE-2026-63226
CVE-2026-63226
pkg: node

published: Jul 23, 2026

Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement restrictions on SSH port forwarding, allowing to connect to arbitrary destinations. When SSH is enabled on an affected product, SSH port forwarding may be leveraged to connect to other node on the LAN.
CWE: CWE-923
NVD

MEDIUM
CVE-2026-61079
CVE-2026-61079
pkg: go

published: Jul 21, 2026

Vulnerability in Oracle GoldenGate (component: Libraries). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.2. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle GoldenGate executes to compromise …
CWE: CWE-20, CWE-284, CWE-362
GitHub-GHSA

MEDIUM
Budibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other Builders
GHSA-gh4h-34gr-87r7
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
## Summary

When an SSO-authenticated user tests an automation in the Budibase builder, their OAuth2 access token and refresh token are included in the automation test results. These results are broadcast via WebSocket to all builders connected to the same dev app and stored in an in-memory cache ac…

GitHub-GHSA

MEDIUM
ImageMagick: Code injection in HTML encoder due to incomplete fix of CVE-2026-25797
GHSA-hc76-7mpc-qjqh
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Jul 24, 2026
An incomplete fix of CVE-2026-25797 can result in code injection in the HTML encoder.
GitHub-GHSA

MEDIUM
Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder
GHSA-gcjf-9mgh-3p7g
pkg: io.netty:netty-codec-http, io.netty:netty-codec-http
eco: maven
published: Jul 22, 2026
# Security Vulnerability Report: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder

## 1. Vulnerability Summary

| Field | Value |
|——-|——-|
| **Product** | Netty |
| **Version** | 4.2.12.Final (and all prior versions with codec-http multipart) |
| **Component** | `io.net…

CVE-2026-59921
NVD

MEDIUM
CVE-2026-60409
CVE-2026-60409
pkg: kubernetes

published: Jul 21, 2026

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where TimesTen In…
CWE: CWE-284
GitHub-GHSA

MEDIUM
Quasar: Prototype pollution in the extend() utility
GHSA-3r53-75j5-3g7j
pkg: quasar
eco: npm
published: Jul 24, 2026
### Summary

`quasar@2.20.1`, the latest published version at the time of testing, appears to be vulnerable to prototype pollution through the public `extend()` utility exported from the package root.

When `extend(true, target, source)` is used for a deep merge, attacker-controlled object keys are …

NVD

MEDIUM
CVE-2026-60407
CVE-2026-60407
pkg: kubernetes

published: Jul 21, 2026

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where TimesTen I…
CWE: CWE-284
GitHub-GHSA

MEDIUM
AWS CLI: Overly permissive File Permissions
GHSA-wfp6-f47h-hxc3
pkg: awscli
eco: pip
published: Jul 24, 2026
### Summary
The AWS Command Line Interface (AWS CLI) is a unified tool for managing AWS services from the command line. Certain CLI subcommands wrote credential and configuration files with world-readable permissions on Unix-like systems with a default umask, allowing other local users on the same h…
CVE-2026-13769
GitHub-GHSA

MEDIUM
ImageMagick: Heap Buffer Over-Write in JP2 encoder when due to incorrect handling of arguments
GHSA-c4v7-w88g-m6c4
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Jul 24, 2026
Due to incorrect handling of arguments a heap buffer over-write can occur in the JP2 encoder.
CVE-2026-55597
GitHub-GHSA

MEDIUM
ImageMagick: Use-After-Free in crafted 8BIM when identifying an image
GHSA-ff5c-8x9r-8qcw
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Jul 24, 2026
When identifying an image with a crafted 8BIM profile with a specific format string a use-after-free will occur.
CVE-2026-55510
NVD

MEDIUM
CVE-2026-54422
CVE-2026-54422
pkg: python

published: Jul 24, 2026

In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.
CWE: CWE-522
GitHub-GHSA

MEDIUM
Netty: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address
GHSA-wh89-7897-x99h
pkg: io.netty:netty-codec-haproxy, io.netty:netty-codec-haproxy
eco: maven
published: Jul 22, 2026
# Security Vulnerability Report: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address in Netty

## 1. Vulnerability Summary

| Field | Value |
|——-|——-|
| **Product** | Netty |
| **Version** | 4.2.12.Final (and all prior versions with codec-haproxy) |
| **Component** | `io.netty.handler.co…

CVE-2026-59919
GitHub-GHSA

MEDIUM
Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests
GHSA-v6w6-358x-2433
pkg: github.com/cloudreve/Cloudreve/v4, github.com/cloudreve/Cloudreve/v3
eco: go
published: Jul 24, 2026
## Summary

Cloudreve exposes two admin node test endpoints under the `Admin.Read` OAuth scope. These endpoints accept attacker-controlled node definitions and cause Cloudreve to make outbound server-side network requests. This allows an OAuth client authorized only for `Admin.Read` to trigger opera…

GitHub-GHSA

MEDIUM
Open WebUI: Arena task endpoints can bypass underlying model access controls
GHSA-m3qf-58wf-w979
pkg: open-webui
eco: pip
published: Jul 24, 2026
## Summary

An authenticated non-admin user with read access to an arena wrapper model can reach a restricted underlying model through task endpoints such as `/api/v1/tasks/moa/completions`.

The normal chat route resolves arena models before the final chat dispatch and therefore re-checks the selec…

CVE-2026-59225
GitHub-GHSA

MEDIUM
Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete
GHSA-2xwm-4h2q-ggfx
pkg: open-webui
eco: pip
published: Jul 24, 2026
## Summary

Current `main` and `v0.9.6` still allow an authenticated user to turn read-only access to another user's file into write/delete access by attaching that file ID to an attacker-controlled workspace model.

This is an incomplete-fix variant of `GHSA-vjqm-6gcc-62cr`. The current fix adds `_…

CVE-2026-59212
NVD

MEDIUM
CVE-2026-57530
CVE-2026-57530
pkg: node

published: Jul 24, 2026

Milkdown before 7.21.3 contains a stored cross-site scripting vulnerability in the @milkdown/preset-commonmark and @milkdown/components packages that allows attackers with document write access to execute arbitrary JavaScript in the browser context of any user who opens the document or clicks a rend…
CWE: CWE-79
NVD

MEDIUM
CVE-2026-16415
CVE-2026-16415
pkg: google chrome

published: Jul 21, 2026

Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-20
GitHub-GHSA

MEDIUM
Gitea LFS Deploy-Key Privilege Escalation
GHSA-rh79-75qm-gwjr
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
## Vulnerability Header

| Field | Value |
| ——————- | ———————————————————– |
| Vulnerability Title | Gitea LFS Deploy-Key Privilege Escalation |
| Severity Rating…

CVE-2026-58435
NVD

MEDIUM
CVE-2026-47671
CVE-2026-47671
pkg: jwt

published: Jul 21, 2026

Nhost is an open source Firebase alternative with GraphQL. In versions of Nhost CLI prior to 1.46.0, the hidden `nhost configserver` used by `nhost dev` exposes the Mimir GraphQL API with dummy authorization directives and permissive CORS. When a developer is running the local development environmen…
CWE: CWE-306
GitHub-GHSA

MEDIUM
Tornado vulnerable to Header Injection and XSS via reason argument
GHSA-pr2v-jx2c-wg9f
pkg: tornado
eco: pip
published: Jul 20, 2026
# Header injection and XSS via `reason` argument

## Summary

The `reason` argument (used by both `RequestHandler.set_status` and `tornado.web.HTTPError` is designed to allow applications to pass custom "reason" phrases (the "Not Found" in `HTTP/1.1 404 Not Found`) to the HTTP status line (mainly fo…

CVE-2025-67724
GitHub-GHSA

MEDIUM
kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating a request against a `content` parameter whose media type has no schema
GHSA-jpcw-4wr7-c3vq
pkg: github.com/getkin/kin-openapi
eco: go
published: Jul 24, 2026
| Field | Value |
|—|—|
| Ecosystem | Go |
| Package | `github.com/getkin/kin-openapi` |
| Affected versions | `<= 0.143.0` (introduced in `v0.2.0`, PR #90, 2019-05-07; reproduced on `HEAD` `30e2923`) |
| Patched versions | 0.144.0 |

### Summary

`openapi3filter.ValidateRequest` contains a …

GitHub-GHSA

MEDIUM
Budibase: Account Enumeration via Login Lockout Response Differential
GHSA-cr7p-cr3q-h5cm
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
## Summary

The login lockout mechanism in Budibase creates an observable response discrepancy that allows unauthenticated attackers to enumerate valid email addresses. When an existing user's account is locked after 5 failed login attempts, the server returns a distinct `403` response with `X-Accou…

GitHub-GHSA

MEDIUM
webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules
GHSA-g35j-m5xg-vh3q
pkg: github.com/quic-go/webtransport-go
eco: go
published: Jul 24, 2026
## Summary

An attacker can cause excessive memory allocation in webtransport-go by sending an unknown WebTransport capsule with a large payload. The implementation skips unknown capsules by reading the entire capsule body into memory, instead of draining it without retaining the data. This can lead…

CVE-2026-57497
GitHub-GHSA

MEDIUM
Open WebUI: Account enumeration via observable login timing discrepancy
GHSA-7rw5-9f7q-xj36
pkg: open-webui
eco: pip
published: Jul 24, 2026
### Summary

The `/api/v1/auths/signin` endpoint leaked whether an email address belonged to a registered account through a response-time side channel. Password verification ran bcrypt only when the email was found in the database; for a non-existent email the request returned early without hashing.…

CVE-2026-59218
GitHub-GHSA

MEDIUM
Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names
GHSA-mfg7-5gfp-c4w3
pkg: io.netty:netty-codec-dns, io.netty:netty-codec-dns
eco: maven
published: Jul 24, 2026
### Summary
A memory leak can be caused in Netty's DNS codec by sending malicious DNS packets containing invalid domain names. Because the leak occurs incrementally per packet, sustained malicious requests will cause a gradual Denial of Service.

### Details
Inside `io.netty.handler.codec.dns.Abstra…

GitHub-GHSA

MEDIUM
Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)
GHSA-g9hv-x236-4qp3
pkg: russh
eco: rust
published: Jul 24, 2026
### Summary
A malicious SSH server can crash a `russh` client session with a single
malformed key-exchange reply, causing a pre-authentication Denial-of-Service
before the server host key is verified. The embedding process itself stays
up, but the connection is killed deterministically.

### Details…

GitHub-GHSA

MEDIUM
Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB)
GHSA-5xvq-cp9x-6p6r
pkg: russh
eco: rust
published: Jul 24, 2026
A pre-authentication denial-of-service panic in `russh` 0.62.2 (commit
`c4be19f1915c8682f4615c3fd50008512b474491`, current default branch `main` as
of 2026-07-22). An unauthenticated client sends a single `SSH_MSG_KEX_ECDH_INIT`
whose `Q_C` is 32 zero bytes. russh's Curve25519 KEX does not reject th…
GitHub-GHSA

MEDIUM
@fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths
GHSA-8pvw-jcv7-9cmj
pkg: @fastify/static
eco: npm
published: Jul 24, 2026
### Impact

`@fastify/static` evaluates the `allowedPath` callback before normalizing dot segments and duplicate slashes in the pathname used for file resolution. Non-canonical pathnames such as `//file`, `/./file`, or `/public/../private/file` bypass `allowedPath` filtering while resolving to the i…

CVE-2026-7120
GitHub-GHSA

MEDIUM
node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection
GHSA-r292-9mhp-454m
pkg: tar
eco: npm
published: Jul 24, 2026
## Summary
`node-tar` (npm `tar`) contains an uncontrolled-recursion stack-exhaustion DoS in the internal `mapHas` helper used by `filesFilter`. When a consumer calls `tar.t(…)` or `tar.x(…)` with a non-empty member-selection list, node-tar installs a filter that closes over the recursive `mapHa…
GitHub-GHSA

MEDIUM
PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path
GHSA-9xwg-3r6f-jcx2
pkg: pymdown-extensions
eco: pip
published: Jul 24, 2026
### Summary

The `b64` extension inlines images referenced by `<img src="…">` as base64 data URIs. When resolving the `src` path it joins it onto the configured `base_path` with `os.path.normpath` and opens the result directly, with no check that the resolved path stays inside `base_path`. A `src`…

CVE-2026-61632
GitHub-GHSA

MEDIUM
SvelteKit: Big remote form function payloads can cause Node process to crash
GHSA-wqjv-9729-c5q2
pkg: @sveltejs/kit
eco: npm
published: Jul 24, 2026
Big remote form function payloads can cause the Node process to crash. Doing this repeatedly can cause DoS.
GitHub-GHSA

MEDIUM
ImageMagick: Stack Overflow in MVG decoder due to missing depth check.
GHSA-mx48-2qq3-23hf
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Jul 24, 2026
A missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided.
CVE-2026-55594
NVD

MEDIUM
CVE-2026-12353
CVE-2026-12353
pkg: tls

published: Jul 23, 2026

An unauthenticated attacker could trigger an Out of Memory condition to crash the Java process for RHCS by repeatedly sending HTTP requests to the TLS endpoint. Depending on how the RHCS server is configured, a manual intervention to restart it may prove necessary.
CWE: CWE-772
GitHub-GHSA

MEDIUM
ImageMagick: Information Disclosure in MNG decoder because allocated memory is left unchanged
GHSA-8g53-9m3c-69xg
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Jul 23, 2026
In the MNG decoder there is a possible heap information disclosure because part of the pixels are left unchanged.
CVE-2026-53467
NVD

MEDIUM
CVE-2026-25466
CVE-2026-25466
pkg: go

published: Jul 23, 2026

Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04 versions.
CWE: CWE-862
GitHub-GHSA

MEDIUM
Eclipse Jetty: Path parameter traversal
GHSA-w7x5-g22v-xqhr
pkg: org.eclipse.jetty:jetty-util, org.eclipse.jetty:jetty-util
eco: maven
published: Jul 22, 2026
### Description (as reported)

#### Summary

In Jetty 12.1.8, org.eclipse.jetty.util.URIUtil.canonicalPath() may leave dot-dot path segments unnormalized when a semicolon path parameter marker is followed by a slash and a dot
segment.

A minimal example is:

`/public;/../admin/secret`

In my local…

CVE-2026-8384
GitHub-GHSA

MEDIUM
Eclipse Jetty: HTTP Authority/Host mismatch
GHSA-7p3p-8qv8-m2vh
pkg: org.eclipse.jetty:jetty-server, org.eclipse.jetty:jetty-server, org.eclipse.jetty:jetty-server
eco: maven
published: Jul 22, 2026
#### Summary

Jetty currently accepts HTTP/2 and HTTP/3 requests where the regular
Host header and the pseudo-header :authority
do not match. As a result, the same request can carry two different host identities
through Jetty:

– logic based on `HttpURI` / `Request.getServerName(request)` uses `:aut…

CVE-2026-6790
NVD

MEDIUM
CVE-2026-13070
CVE-2026-13070
pkg: tls

published: Jul 22, 2026

A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP response from a remote peer during the TLS handshake. OCSP stapling validation is enabled by default for outgoing TLS connections. Affected scenarios require the remote peer to hold a cer…
CWE: CWE-476
NVD

MEDIUM
CVE-2026-50251
CVE-2026-50251
pkg: nlnetlabs unbound

published: Jul 22, 2026

In NLnet Labs Unbound up to and including version 1.25.1, when 'unwanted-reply-threshold' is enabled (set to any value greater than zero), glue records of 0.0.0.0/::0 can short-circuit Unbound, on systems that can direct such traffic, by issuing DNS queries and receiving seemingly unwanted replies s…
CWE: CWE-184
NVD

MEDIUM
CVE-2026-60394
CVE-2026-60394
pkg: go

published: Jul 21, 2026

Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle GoldenGate. Successful attacks of this…
CWE: CWE-200
NVD

MEDIUM
CVE-2026-46917
CVE-2026-46917
pkg: tls

published: Jul 21, 2026

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalV…
CWE: CWE-284
NVD

MEDIUM
CVE-2026-16318
CVE-2026-16318
pkg: tls

published: Jul 21, 2026

The QUIC transport parameters extension handler in s2n-tls incorrectly uses s2n_alloc instead of s2n_realloc to store the peer's transport parameters. When a TLS 1.3 connection goes through a HelloRetryRequest, the handler is called twice on the same connection. On the second call, s2n_alloc zeroes …
CWE: CWE-401
GitHub-GHSA

MEDIUM
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint
GHSA-p4mj-98mv-xq26
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
| Field | Value |
|——-|——-|
| **Affected File** | `routers/web/repo/githttp.go`, `services/context/repo.go` |
| **Affected Functions** | `httpBase()`, `EarlyResponseForGoGetMeta()` |
| **Affected Lines** | `githttp.go:63–66`, `services/context/repo.go:374–396` |
| **Prerequisite** | None…
CVE-2026-58507
GitHub-GHSA

MEDIUM
Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service
GHSA-pg7v-jwj7-p798
pkg: pillow
eco: pip
published: Jul 20, 2026
### Summary

Pillow's EPS parser (PIL/EpsImagePlugin.py) accepts a negative byte count in the %%BeginBinary directive. A crafted EPS file can cause Image.open() to seek backwards to the same directive and parse it repeatedly, resulting in an infinite loop and CPU denial of service.

The issue is tri…

CVE-2026-59203
GitHub-GHSA

MEDIUM
Mistune directives/include: mutual `.. include::` recursion crashes the renderer with `RecursionError`, denial of service via two attacker-controlled markdown files
GHSA-8mpj-m6qm-5qr8
pkg: mistune
eco: pip
published: Jul 20, 2026
## Summary

**Type:** Uncontrolled recursion via mutual include. The `Include` directive checks for direct self-reference (`a.md` cannot include `a.md`), but does not detect indirect cycles. Two markdown files that include each other (`a.md` → includes `b.md` → includes `a.md`) cause unbounded r…

CVE-2026-59927
NVD

MEDIUM
CVE-2026-55219
CVE-2026-55219
pkg: go

published: Jul 20, 2026

Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.5, the credit payment implementation in app/Livewire/Invoices/Show.php executes a pessimistic row lock (lockForUpdate()) outside of an active database transaction. Because MySQL/MariaDB …
CWE: CWE-362
GitHub-GHSA

MEDIUM
changedetection.io is vulnerable to unauthenticated static path traversal
GHSA-9jj8-v89v-xjvw
pkg: changedetection.io
eco: pip
published: Jul 20, 2026
## Summary
The `/static/<group>/<filename>` route accepts `group=".."`, which causes `send_from_directory("static/..", filename)` to execute. This moves the base directory up to `/app/changedetectionio`, enabling **unauthenticated local file read** of application source files (e.g., `flask_app.py`).…
CVE-2026-25527
NVD

MEDIUM
CVE-2026-11804
CVE-2026-11804
pkg: linux

published: Jul 23, 2026

Improper handling of insufficient permissions or privileges vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Privilege Abuse.

This issue affects Niagara Framework: before 4.14.6, before 4.15.5; Niagara Enterprise Se…

CWE: CWE-280
GitHub-GHSA

MEDIUM
ImageMagick: Integer Overflow in JNX decoder causes heap buffer over-write when processing extremly large files on 32-bit builds
GHSA-h22j-f9xw-xjjm
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-x86
eco: nuget
published: Jul 24, 2026
When processing an extremely large JNX file on 32-bit platforms an integer overflow will happen that can cause a heap buffer over-write.
CVE-2026-62946
GitHub-GHSA

MEDIUM
ImageMagick: Heap Buffer Over-Write in fx operation
GHSA-422r-8c97-xcg4
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Jul 24, 2026
A heap buffer over-write can occur in the fx operation by passing a crafted argument.
CVE-2026-62363
GitHub-GHSA

MEDIUM
Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role Users
GHSA-fcrw-f7gg-6g9f
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
## Summary

The `/api/users/metadata` and `/api/users/metadata/:id` endpoints in `@budibase/server` return full global user profiles to any user with POWER role or above. For SSO-authenticated users (OIDC, Google), the response includes `oauth2.accessToken` and `oauth2.refreshToken` fields, leaking …

GitHub-GHSA

MEDIUM
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
GHSA-fq2p-5p22-8g6j
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary
A personal access token restricted with the public-only scope can still retrieve private organization membership and organization permission details for its own account through organization-listing endpoints. This bypass breaks the intended guarantee that such tokens are limited to publi…
CVE-2026-58429
GitHub-GHSA

MEDIUM
@backstage/plugin-auth-backend: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass
GHSA-38hq-7×33-php4
pkg: @backstage/plugin-auth-backend
eco: npm
published: Jul 24, 2026
### Impact
The allowlist matching used by the experimental dynamic client registration and client ID metadata document (CIMD) features in `@backstage/plugin-auth-backend` matched glob patterns against the full URL string. A * wildcard could therefore match across URL component boundaries: a pattern …
GitHub-GHSA

MEDIUM
ImageMagick: Heap Buffer Over-Write in morphology operation when an invalid kernel is provided
GHSA-f5m7-cqgw-8hm7
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Jul 24, 2026
An invalid kernel can cause a heap buffer over-write when performing a morphology operation with a user supplied kernel.
CVE-2026-62343
GitHub-GHSA

MEDIUM
ImageMagick: Policy Bypass due to an incomplete fix of CVE-2026-49219
GHSA-56m6-8q75-f2rw
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Jul 24, 2026
An incomplete fix of CVE-2026-49219 could result in a policy bypass.
GitHub-GHSA

MEDIUM
ImageMagick: Infinite Loop in connected-components when providing invalid arguments
GHSA-qhmf-7fc4-8q3h
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Jul 24, 2026
When providing invalid arguments to the connected-components option an infinite loop will occur.
CVE-2026-55595
NVD

MEDIUM
CVE-2026-65904
CVE-2026-65904
pkg: node

published: Jul 23, 2026

DOMPurify through 3.3.3 fails to sanitize DOM elements passed via IN_PLACE mode when the element originates from a different window/realm (e.g., an iframe's contentDocument). A cross-realm instanceof check in the private _isNode() function returns false for foreign-realm nodes, causing DOMPurify to …
CWE: CWE-754
GitHub-GHSA

MEDIUM
Loofah: SVG `href` attribute bypasses local-reference restriction
GHSA-9wjq-cp2p-hrgf
pkg: loofah
eco: rubygems
published: Jul 21, 2026
## Summary

Loofah's HTML5 sanitizer restricted only the `xlink:href` attribute on certain SVG elements to local, same-document references. Browsers also accept a plain `href` attribute as an alternative to the deprecated `xlink:href` per the SVG 2 spec, but Loofah did not apply the same restriction…

GitHub-GHSA

MEDIUM
Trix: Stored XSS via HTMLParser attribute injection on paste
GHSA-53g2-mvcc-q9x3
pkg: trix, action_text-trix
eco: npm
published: Jul 24, 2026
### Impact

The Trix editor, in versions prior to 2.1.18, is vulnerable to XSS when crafted HTML is pasted into the editor. The `HTMLParser` processed a mock attachment, a `<span>` carrying an empty `data-trix-attachment="{}"`. The empty attachment object caused the element to bypass attachment hand…

GitHub-GHSA

MEDIUM
Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path
GHSA-4x4j-2g7c-83w6
pkg: Pillow
eco: pip
published: Jul 20, 2026
### 1. Summary

`WindowsViewer.get_command()` constructs a `cmd.exe` shell command by directly embedding a
file path into an f-string without escaping. The result is passed to
`subprocess.Popen(…, shell=True)`. Shell metacharacters in the file path — most
importantly a double-quote (`"`) that br…

CVE-2026-55798
NVD

MEDIUM
CVE-2026-15786
CVE-2026-15786
pkg: ssl

published: Jul 23, 2026

The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 7.8.6.6 via the 'imploded' parameter parameter. This makes it possible for authenticated attackers, with ad…
CWE: CWE-22
NVD

MEDIUM
CVE-2026-61084
CVE-2026-61084
pkg: go

published: Jul 21, 2026

Vulnerability in Oracle GoldenGate (component: Libraries). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle GoldenGate executes to compromise Ora…
CWE: CWE-284
GitHub-GHSA

MEDIUM
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search
GHSA-p6ph-3jx2-3337
pkg: github.com/OpenListTeam/OpenList/v4
eco: go
published: Jul 24, 2026
### Summary
An authorization bypass and information disclosure vulnerability exists in the search API of `Openlist`. Due to a non-separator-aware path check and unfiltered backend counting, a low-privileged user can bypass their assigned `BasePath` restrictions to discover and access metadata of fil…
GitHub-GHSA

MEDIUM
Budibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappings
GHSA-4qcj-m5wp-jmf4
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
## Summary

The `GET /api/global/groups` endpoint on the worker service has no role-based authorization middleware. Any authenticated user (including BASIC role) can enumerate all user groups in the tenant, including their role mappings, user memberships, builder permissions, and the isDefault flag.…

GitHub-GHSA

MEDIUM
Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching
GHSA-qg3f-8x3j-ggf2
pkg: open-webui
eco: pip
published: Jul 24, 2026
## Summary

The administrator-configured `WEB_FETCH_FILTER_LIST` (the allow/block list applied to server-side web fetches: RAG URL ingestion, URL-to-markdown, web-search content fetch) matches hostnames incorrectly, so the filter can be bypassed.

## Details

`is_string_allowed` (`backend/open_webui…

CVE-2026-59223
GitHub-GHSA

MEDIUM
Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and receives activity events for unshared siblings
GHSA-w8x7-h2px-xmq8
pkg: github.com/cloudreve/Cloudreve/v4, github.com/cloudreve/Cloudreve/v3
eco: go
published: Jul 24, 2026
## Summary

When an authenticated recipient of a **single-file** share opens the file event stream (`GET /api/v4/file/events?uri=<share-root>`), Cloudreve validates the URI by listing it and then subscribes the caller to `parent.ID()`. For a single-file share, the share navigator resolves the bare …

CVE-2026-55499
GitHub-GHSA

MEDIUM
Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails
GHSA-8r7f-r8hj-r3rv
pkg: github.com/cloudreve/Cloudreve/v4, github.com/cloudreve/Cloudreve/v3
eco: go
published: Jul 24, 2026
## Summary

`GET /api/v4/user/search` is available to any logged-in user. The service calls `userClient.SearchActive`, but despite its name that method filters only by email/nickname keyword and **never adds a `StatusActive` predicate** — while the sibling lookups `GetActiveByID` and `GetActiveBy…

CVE-2026-55496
GitHub-GHSA

MEDIUM
Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account
GHSA-49h3-cwhj-4737
pkg: github.com/cloudreve/Cloudreve/v4, github.com/cloudreve/Cloudreve/v3
eco: go
published: Jul 24, 2026
## Summary

Cloudreve's WOPI `PUT_RELATIVE` handler treats `X-WOPI-SuggestedTarget` as a path, not a filename. It splits the header on `/` and joins the segments onto the source file's directory with `URI.JoinRaw`, which feeds Go's `url.JoinPath`. `url.JoinPath` resolves `.`/`..` segments, so a sla…

CVE-2026-55495
GitHub-GHSA

MEDIUM
Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)
GHSA-7r7x-gjvr-448g
pkg: open-webui
eco: pip
published: Jul 24, 2026
# Open WebUI upload metadata can add files to knowledge bases without write permission

## Summary

Open WebUI's file upload background processing trusts the client-supplied `metadata.knowledge_id` value and inserts a `knowledge_file` association before validating that the uploading user has write a…

CVE-2026-59217
GitHub-GHSA

MEDIUM
Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission
GHSA-rqj7-6wrp-6g2g
pkg: open-webui
eco: pip
published: Jul 24, 2026
## Summary

`POST /api/v1/images/edit` performed no authorization beyond requiring a verified account. Every other image-editing surface in Open WebUI enforces the global image-edit switch and the per-user image-generation permission — the `/api/v1/images/generations` route, the built-in `edit_ima…

CVE-2026-59227
GitHub-GHSA

MEDIUM
Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records
GHSA-cqjc-rmpq-xprq
pkg: russh
eco: rust
published: Jul 24, 2026
## Summary

A post-authentication denial-of-service panic in `russh` 0.62.2 (commit
`c4be19f1915c8682f4615c3fd50008512b474491`, current default branch `main` as
of 2026-07-22). An authenticated client sends a `pty-req` channel request
carrying more than 130 terminal-mode records. The parser uses a f…

GitHub-GHSA

MEDIUM
SvelteKit: Prototype pollution in file input deletion path in remote-function forms
GHSA-866w-xmhq-wj7x
pkg: @sveltejs/kit
eco: npm
published: Jul 24, 2026
If you use remote form functions, have an input field of type `file`, and accept arbitrary user-controlled path names for the field, then you are vulnerable to a prototype pollution attack where the attacker can remove e.g. methods on the prototype.
NVD

MEDIUM
CVE-2026-60410
CVE-2026-60410
pkg: kubernetes

published: Jul 21, 2026

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTe…
CWE: CWE-400
NVD

MEDIUM
CVE-2026-60408
CVE-2026-60408
pkg: kubernetes

published: Jul 21, 2026

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTe…
CWE: CWE-200
NVD

MEDIUM
CVE-2026-60397
CVE-2026-60397
pkg: go

published: Jul 21, 2026

Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the ha…
CWE: CWE-404
NVD

MEDIUM
CVE-2026-60395
CVE-2026-60395
pkg: go

published: Jul 21, 2026

Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle GoldenGate. Succe…
CWE: CWE-200
GitHub-GHSA

MEDIUM
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private
GHSA-q423-49rw-g9mh
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
## Summary

GHSA-8fwc-qjw5-rvgp ("Gitea may send release notification emails for private repositories to users whose access has been revoked", fix in PR #36319 / commit 8a98ac22) added `repo_model.ClearRepoWatches` as a defense for the state transition public→private. The cleanup was wired into `s…

CVE-2026-58510
GitHub-GHSA

MEDIUM
Gitea: Public-only API token restriction is not enforced on team API routes
GHSA-h56g-4qw7-2mxg
pkg: gitea.dev
eco: go
published: Jul 21, 2026
### Summary

Gitea's `/api/v1/teams/{id}` API routes do not correctly enforce the `public-only` access token restriction.

A `public-only` token is intended to limit API access to public repositories and public organizations. However, several team API routes continue to return private team repositor…

CVE-2026-58431
GitHub-GHSA

MEDIUM
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)
GHSA-6cqf-375w-639g
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary

Gitea's RSS/Atom feed handlers accept API-token Basic auth but perform **no token-scope or
public-only enforcement**. A personal access token that is correctly blocked (HTTP 403) from a
private repository on `/raw`, `/media`, `/archive`, and `/releases/download/…` — because it is
ma…

CVE-2026-50105
GitHub-GHSA

MEDIUM
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents
GHSA-cp3q-vrj2-ghhh
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary
A personal access token (PAT) or OAuth2 token that does **not** carry the
`repository` scope or that is **public-only** is correctly rejected (HTTP 403)
by the recently hardened web content routes (archive download, raw/media file
download, and repository RSS/Atom feeds). However, the re…
CVE-2026-58444
GitHub-GHSA

MEDIUM
Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data
GHSA-3pww-vcvm-3gmj
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary
A Gitea personal access token (PAT) restricted to a non-repository scope (e.g. `read:issue`) can read the commit history of any private repository the token owner can access, via the repository RSS/Atom feed endpoints. The same token is correctly denied (403) on `/raw`, `/media`, `/archi…
CVE-2026-27761
GitHub-GHSA

MEDIUM
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)
GHSA-vxv2-8j6r-pcpg
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
## Live reproduction against Gitea 1.26.1

Setup: Gitea 1.26.1 docker stack with two users (`admin` and `victim`) and two OAuth applications owned by different users:

“`
Client A: id=5dda747d-7fdd-4694-85ff-ce4f893ce51e owner=admin
Client B: id=588f778f-4a41-4914-ae01-85d776c369db owner=victim…

CVE-2026-58425
GitHub-GHSA

MEDIUM
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118
GHSA-7p4h-3gxq-x3h3
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
## Summary

After [PR #37118](https://github.com/go-gitea/gitea/pull/37118) / **CVE-2026-25714**
(`fix: Unify public-only token filtering in API queries and repo access checks`,
merged 2026-05-18, backport `#37773` to 1.26.2 — the May 2026 unification pass
for public-only token filtering, reporter…

CVE-2026-56443
GitHub-GHSA

MEDIUM
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times`
GHSA-qf2f-qh6p-7v89
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
## Summary
CVE-2026-20800 fixed private-info leakage to revoked users only for the notification endpoint. Two
sibling endpoints that return data keyed on the caller's own relationship still do not re-check repo
access at output time:
– `GET /api/v1/user/starred` — `getStarredRepos()` computes a pe…
CVE-2026-59766
NVD

MEDIUM
CVE-2026-16336
CVE-2026-16336
pkg: oauth

published: Jul 21, 2026

A vulnerability was found in trinodb trino 481. Affected is an unknown function of the file core/trino-main/src/main/java/io/trino/server/ExternalUriInfo.java of the component OAuth2/OIDC. Performing a manipulation of the argument redirect_uri results in open redirect. It is possible to initiate the…
CWE: CWE-601
GitHub-GHSA

MEDIUM
Mistune toc / TableOfContents directive: heading IDs use predictable `toc_N` numbering with no slugification, allowing collision with attacker-controlled `id="toc_N"` content
GHSA-2hm2-hc3v-44h9
pkg: mistune
eco: pip
published: Jul 20, 2026
## Summary

**Type:** Predictable identifier generation. The `toc` plugin and `TableOfContents` directive both default to generating heading IDs of the form `toc_1`, `toc_2`, `toc_3`, … with no input-derived component. An attacker who can place a heading anywhere in the document can predict which …

CVE-2026-59930
NVD

MEDIUM
CVE-2026-63768
CVE-2026-63768
pkg: oauth

published: Jul 20, 2026

cal.diy through 6.2.0 contains an open redirect vulnerability in the conferencing OAuth callback endpoint that allows attackers to redirect users to arbitrary URLs by crafting malicious state parameters. Attackers can exploit the unsigned state parameter and onErrorReturnTo field to silently redirec…
CWE: CWE-601
NVD

MEDIUM
CVE-2026-13724
CVE-2026-13724
pkg: go

published: Jul 20, 2026

Client-Side Enforcement of Server-Side Security vulnerability in Gobito Informatics Technologies Engineering Industry and Trade Ltd. Co. Corporate Training Management System allows Input Data Manipulation.

This issue affects Corporate Training Management System: before dd1a9df64.

CWE: CWE-602
NVD

MEDIUM
CVE-2026-63761
CVE-2026-63761
pkg: surrealdb surrealdb

published: Jul 20, 2026

SurrealDB before 3.1.0 silently substitutes the ES384 algorithm when a JWT access method is configured with ALGORITHM ES512 (DEFINE ACCESS … TYPE JWT ALGORITHM ES512), because the underlying jsonwebtoken crate (v10.x) has no ES512 variant and the mapping defaults to ES384 without any error, warnin…
CWE: CWE-327
NVD

MEDIUM
CVE-2026-63749
CVE-2026-63749
pkg: surrealdb surrealdb

published: Jul 20, 2026

SurrealDB versions before 3.1.0 contain an authentication bypass vulnerability in LIVE SELECT subscriptions where permission expressions referencing $value, $before, $after, or $event are evaluated against attacker-controlled bindings instead of actual documents. Authenticated subscribers can bind c…
CWE: CWE-863
GitHub-GHSA

MEDIUM
Shescape: Home-directory disclosure in assignment context on Unix with Dash
GHSA-q53c-4prm-w95q
pkg: shescape, shescape
eco: npm
published: Jul 24, 2026
### Impact

This impacts users of Shescape on Unix systems that explicitly configure `shell` to Dash, or `true` when the default shell is Dash, using the `escape` and `escapeAll` APIs in assignments prefixed to a command.

An attacker may be able to obtain the location of the home directory and, dep…

GitHub-GHSA

MEDIUM
Shescape: Path disclosure on Unix with Zsh
GHSA-6v4m-fw66-8r4x
pkg: shescape, shescape
eco: npm
published: Jul 24, 2026
### Impact

This impacts users of Shescape on Unix systems that explicitly configure `shell` to Zsh, or `true` when the default shell is Zsh, using the `escape` and `escapeAll`. The Zsh options `EXTENDED_GLOB` and `MAGIC_EQUAL_SUBST` exacerbate the problem.

In certain case, an attacker can leverage…

GitHub-GHSA

MEDIUM
Hubuum client library (Rust): Configured custom transports may be bypassed, exposing credentials and network traffic
GHSA-qqc3-94qv-7fw3
pkg: hubuum_client
eco: rust
published: Jul 24, 2026
## Summary

When an application configures hubuum_client with ClientBuilder::with_transport, several client operations still use the built-in reqwest client directly. The bypass includes password login, bearer-token validation, authentication-provider discovery, health and readiness probes, export-o…

GitHub-GHSA

MEDIUM
Hubuum client library (Rust): Authenticated requests may escape the configured base path through redirects
GHSA-f45q-w629-wr25
pkg: hubuum_client
eco: rust
published: Jul 24, 2026
## Impact

The built-in async and blocking clients used reqwest's default redirect policy. `BaseUrl` constrains the initial request to the configured origin and path prefix, but redirect processing occurs after that validation. reqwest retains sensitive headers when a redirect changes only the path …

GitHub-GHSA

MEDIUM
Budibase: SSRF via bare fetch() in uploadUrl during AI table generation
GHSA-hfhx-w8p8-4hc7
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
# Budibase: SSRF via bare fetch() in uploadUrl during AI table generation

## Summary

The `uploadUrl()` function in `packages/server/src/utilities/fileUtils.ts` uses a bare `fetch(url)` call without any SSRF protection. This function is invoked when the AI table generation feature processes LLM-gen…

GitHub-GHSA

MEDIUM
Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials
GHSA-gh7p-78×6-jw6m
pkg: open-webui
eco: pip
published: Jul 24, 2026
### Summary

The channel members endpoint serializes and returns **full user models** for channel participants, including settings objects. A normal user in a DM can retrieve admin-only sensitive configuration such as webhook URLs and tool server key material (`settings.ui.toolServers[].key`), which…

CVE-2026-59222
GitHub-GHSA

MEDIUM
cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag
GHSA-gcjh-h69q-9w9g
pkg: github.com/google/cel-go
eco: go
published: Jul 24, 2026
The function `ext.NativeTypes(ParseStructTag("json"))` does not honour the `encoding/json` skip directive `json:"-"`. Fields tagged `json:"-"` are registered in the CEL type system under the literal name `"-"` and are readable from any user-submitted CEL expression via `dyn(obj)["-"]`.

Additionall…

GitHub-GHSA

MEDIUM
Microsoft Kiota: Path traversal in generated plugin manifest static_template.file reference (percent-encoding bypass)
GHSA-p5rm-jg5c-8c77
pkg: Microsoft.OpenApi.Kiota
eco: nuget
published: Jul 24, 2026
### Impact

Kiota generates AI plugin manifests from an OpenAPI description. When the description contains an `x-ai-capabilities` response semantics `static_template` (or the adaptive-card extension `x-ai-adaptive-card`), the `file` reference is written into the generated manifest's `response_semant…

GitHub-GHSA

MEDIUM
Valibot: record() issue paths can make flatten() throw for inherited Object property names
GHSA-5qjj-4xww-7phc
pkg: valibot
eco: npm
published: Jul 24, 2026
## Summary

`valibot` 1.4.1 can throw a `TypeError` inside its `flatten()` helper when validation issues contain attacker-controlled object keys such as `toString`, `valueOf`, or `hasOwnProperty`.

The issue is reachable through normal `record()` validation. `record()` intentionally filters `__proto…

CVE-2026-59952
GitHub-GHSA

MEDIUM
c3p0 can, in combination with other libraries, compose to a "sink" for deserialization gadgets
GHSA-w6w4-rjh9-9r58
pkg: com.mchange:c3p0
eco: maven
published: Jul 23, 2026
### Impact

The JDBC spec defines the interface `DataSource`, with a method called `getConnection()`, and `ConnectionPoolDataSource`, with a method called `getPooledConnection()`. These methods are potentially dangerous. One way or another they trigger calls into JDBC drivers, which themselves are c…

CVE-2026-55223
GitHub-GHSA

MEDIUM
React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)
GHSA-wrjc-x8rr-h8h6
pkg: react-router
eco: npm
published: Jul 23, 2026
This is a follow up to [CVE-2025-68470](https://github.com/remix-run/react-router/security/advisories/GHSA-9jcx-v3wj-wh4m). React Router was alerted to certain scenarios in which the fix there was incomplete so there still existed some scenarios where attacker supplied paths passed to navigation me…
CVE-2026-53669
GitHub-GHSA

MEDIUM
pypdf: Possible long runtimes for repeated malformed cross-reference entries
GHSA-55h5-xmcq-c37v
pkg: pypdf
eco: pip
published: Jul 23, 2026
### Impact

An attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires cross-reference streams with repeated malformed cross-reference streams.

### Patches

This has been fixed in [pypdf==6.14.0](https://github.com/py-pdf/pypdf/releases/tag/6.14.0).

### Wor…

CVE-2026-59937
GitHub-GHSA

MEDIUM
pypdf: Possible large memory usage for wrong image dimensions
GHSA-5qjq-93h5-hrgp
pkg: pypdf
eco: pip
published: Jul 23, 2026
### Impact

An attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires loading images where the declared size values are much too large compared to the actual data.

### Patches

This has been fixed in [pypdf==6.14.0](https://github.com/py-pdf/pypdf/rele…

CVE-2026-59938
GitHub-GHSA

MEDIUM
n8n: Snowflake Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation
GHSA-652q-gvq3-74qv
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact

The n8n Snowflake node's Execute Query operation interpolated expression values directly into the SQL string, making queries built with untrusted data susceptible to SQL injection.

Exploitation requires that a workflow author has already embedded untrusted expression data directly in a r…

GitHub-GHSA

MEDIUM
n8n: PostgresTrigger Node SQL Injection Allows Authenticated Users to Execute Arbitrary SQL on Connected PostgreSQL Instances
GHSA-jqwr-vx3p-r266
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact

The Postgres Trigger node interpolated user-supplied identifier parameters (channel, function, and trigger names) into SQL statements without proper escaping, so an authenticated user could inject arbitrary SQL executed against the connected PostgreSQL database with the configured credent…

GitHub-GHSA

MEDIUM
n8n: Cross-Tenant Module-Cache Poisoning in the JS Task Runner
GHSA-9cmh-xcqm-5hqr
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact

n8n's JavaScript task runner shared one module cache across all users' Code-node executions, so a user able to run a Code node could poison a cached module and alter other users' Code-node executions on the same runner, affecting their confidentiality, integrity, or availability.

This is…

GitHub-GHSA

MEDIUM
JupyterLab: PyPI extension blocklist package-name canonicalization bypass
GHSA-89vp-jrxv-24w8
pkg: jupyterlab, jupyterlab
eco: pip
published: Jul 22, 2026
JupyterLab's PyPI extension manager enforces `blocked_extensions_uris` by comparing the requested install name to blocklist entries with a custom string normalization that is weaker than PyPI package-name canonicalization. An authenticated user can request a PyPI-equivalent spelling such as `Jupyter…
GitHub-GHSA

MEDIUM
JupyterLab PluginManager lock-rule enforcement bypass
GHSA-h5v5-8746-g7mm
pkg: jupyterlab, jupyterlab
eco: pip
published: Jul 22, 2026
JupyterLab's plugin manager exposes administrator controls intended to prevent users from enabling or disabling selected plugins. Two server-side enforcement gaps let an authenticated user bypass those controls with direct requests to `/lab/api/plugins`.

### Impact

Users could workaround the plugi…

GitHub-GHSA

MEDIUM
Next.js: Cache confusion of response bodies for requests with bodies
GHSA-68g3-v927-f742
pkg: next, next
eco: npm
published: Jul 22, 2026
## Impact

A server-side `fetch` with a request body may return a cached **response** body from a different request to the same URL but different body. Confidential data in the `POST`'s **response** body would then leak to unauthorized requests. Though the request itself will not be deduped.

This o…

CVE-2026-64648
GitHub-GHSA

MEDIUM
Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences
GHSA-4633-3j49-mh5q
pkg: next, next
eco: npm
published: Jul 22, 2026
## Impact

A server-side `fetch` with a request body may return a cached **response** body from a different request to the same URL but different body. Confidential data in the `POST`'s **response** body would then leak to unauthorized requests. Though the request itself will not be deduped.

This i…

CVE-2026-64647
GitHub-GHSA

MEDIUM
Next.js: Unbounded Server Action payload in Edge runtime
GHSA-4c39-4ccg-62r3
pkg: next, next
eco: npm
published: Jul 22, 2026
## Impact

Requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive memory consumption if that Server Actions uses the Edge runtime

## Workarounds

If you cannot upgrade, ensure your hosting provider limits the request's body size. 5 MiB should …

CVE-2026-64646
GitHub-GHSA

MEDIUM
Next.js: Denial of Service in the Image Optimization API using SVGs
GHSA-q8wf-6r8g-63ch
pkg: next, next
eco: npm
published: Jul 22, 2026
### Impact

When self-hosting Next.js with the default image loader, the Image Optimization API can optimize remotely hosted images if configured (not enabled by default). If those images contain malicious content, they can cause CPU exhaustion in `/_next/image` endpoints.

– If you are using `conf…

CVE-2026-64644
GitHub-GHSA

MEDIUM
Next.js: Unauthenticated disclosure of internal Server Function endpoints
GHSA-955p-x3mx-jcvp
pkg: next, next
eco: npm
published: Jul 22, 2026
## Impact

In Next.js applications using App Router, Server Actions (`use server`) or `use cache` endpoints can be disclosed bypassing any authentication on the pages where these endpoints are usually used.

Server Action IDs can be disclosed to unauthenticated users via publicly served client artif…

CVE-2026-64643
GitHub-GHSA

MEDIUM
Eclipse Jetty: Cross-Request Leakage for trailers on HTTP/1.1 keep-alive connections
GHSA-f4v5-65jj-pcr2
pkg: org.eclipse.jetty:jetty-server, org.eclipse.jetty:jetty-server
eco: maven
published: Jul 22, 2026
### Description

> FINDING — MEDIUM (HTTP/1.1 keep-alive connections with trailers)
> HttpConnection._trailers Cross-Request Leakage (Never Reset Between Requests)
>
> Location:
> jetty-core/jetty-server/src/main/java/org/eclipse/jetty/server/internal/
> HttpConnection.java:107, 1157-1161, 11…

CVE-2026-10051
GitHub-GHSA

MEDIUM
n8n: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data
GHSA-89gh-3pgc-v5h2
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact
Custom HTTP headers configured in credentials for certain LLM sub-nodes (including OpenAI, Anthropic, and Lemonade) are masked in the n8n UI but are written in plaintext into execution data during workflow runs. Any authenticated user with access to the execution data for an affected workf…
CVE-2026-65589
GitHub-GHSA

MEDIUM
LiteLLM: Arbitrary file write via path traversal in Skills archive extraction
GHSA-5jmr-gcrj-2c9q
pkg: litellm
eco: pip
published: Jul 22, 2026
### Impact

LiteLLM Skills archive extraction did not sufficiently validate file paths from uploaded skill ZIP archives. An authenticated user with access to LiteLLM LLM API routes, or a key whose `allowed_routes` includes `/v1/skills`, `anthropic_routes`, or `llm_api_routes`, could upload a crafted…

CVE-2026-59820
GitHub-GHSA

MEDIUM
n8n: Unauthenticated Endpoint Allows Cancellation of Any User's Active Test Webhook
GHSA-33q9-f52j-gc75
pkg: n8n
eco: npm
published: Jul 22, 2026
## Impact
The `DELETE /${restEndpoint}/test-webhook/:id` route is registered before the authentication middleware is applied, allowing any unauthenticated network caller who knows a workflow ID to cancel that workflow's active test webhook registration.

The impact is limited to disrupting in-progr…

CVE-2026-65014
GitHub-GHSA

MEDIUM
n8n: GraphQL Node Bypasses "Allowed HTTP Request Domains" Restriction
GHSA-gq66-9cw5-j5jm
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact
The GraphQL node did not enforce the "Allowed HTTP Request Domains" restriction on HTTP-based credentials (such as Header Auth, Basic Auth, Query Auth, and OAuth), unlike the HTTP Request node. An authenticated user able to create or edit workflows could therefore point the node's endpoint…
CVE-2026-65596
GitHub-GHSA

MEDIUM
n8n: Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows via Missing OAuth Authorization Check
GHSA-q5xf-xhwf-cwqf
pkg: n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact
The OAuth 2.1 consent and token-issuance flow introduced in n8n 2.27.0 does not verify that the authenticated user has access to the workflow referenced as the OAuth resource. A member-level user can register an OAuth client, self-approve consent for another user's `n8n OAuth2`-protected M…
CVE-2026-65594
GitHub-GHSA

MEDIUM
n8n: computer-use Shell Sandbox Not Enforced on Linux and Windows
GHSA-fpg6-x68q-5793
pkg: n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact
The shell tool in the `@n8n/computer-use` package applied its sandbox restrictions only on macOS. On Linux and Windows, shell commands executed by the tool ran without any filesystem or network restrictions, allowing unrestricted access to the host filesystem and network from within the co…
CVE-2026-65590
GitHub-GHSA

MEDIUM
n8n: Authenticated Users Can Exhaust Temporary Disk Storage via Data-Table File Uploads
GHSA-w867-jm58-p9pv
pkg: n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact
An authenticated user can repeatedly upload files to the data-table upload endpoint, bypassing the per-request quota check, which does not account for files already written to the shared temporary directory. This causes temporary files to accumulate on disk until the periodic cleanup runs,…
CVE-2026-58661
GitHub-GHSA

MEDIUM
n8n: Improper Authorization Allows Authenticated Users to Assign Workflows to Folders in Other Projects
GHSA-2xgm-wc4g-5jvg
pkg: n8n
eco: npm
published: Jul 22, 2026
## Impact
An authenticated user with permission to create workflows in one project could bypass project/folder authorization boundaries during workflow creation. By supplying a crafted request payload, the user could associate a newly created workflow with a folder belonging to a different project t…
CVE-2026-59253
GitHub-GHSA

MEDIUM
n8n: External Secrets Accessible via Workflow Expressions Outside Credentials
GHSA-2434-3x6q-8r99
pkg: n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact
External secrets were incorrectly resolved in workflow node expressions, where they are not intended to be available. An authenticated user with project editor access could read the plaintext value of external secrets by referencing them in a node expression, without needing explicit secre…
CVE-2026-59254
GitHub-GHSA

MEDIUM
n8n: MySQL v1 Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation
GHSA-hwmj-qg4v-cvg9
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact
The legacy MySQL v1 node's `executeQuery` operation substitutes evaluated `{{ … }}` expression values directly into the raw SQL string without parameterization. If a workflow uses this operation with expression-sourced values in the query and is connected to an externally-reachable trigg…
CVE-2026-59257
GitHub-GHSA

MEDIUM
n8n: External Secrets Permission Bypass via Expression Parser Mismatch
GHSA-jp7m-xcgx-57qm
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact
Due to a mismatch between the static validation check and the runtime expression engine, an authenticated user with credential create or update permissions, but without the `externalSecret:list` scope, could embed external secret references into credentials in forms the validation did not …
CVE-2026-59259
GitHub-GHSA

MEDIUM
n8n: Path-Confinement Bypass in computer-use search_files Allows Reading Files Outside the Base Directory
GHSA-pf2q-pxhf-hgmw
pkg: n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact

The component `@n8n/computer-use` file-search tool confined searches to a configured base directory. A crafted search pattern could bypass the confinement check and expand to locations outside that directory, causing the tool to return the names and contents of files anywhere the daemon's…

GitHub-GHSA

MEDIUM
n8n: Prototype Pollution via VM Expression Engine Sandbox Escape Leads to Denial of Service
GHSA-hx4h-vr3m-45vh
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact

An authenticated user able to create or edit a workflow expression could abuse the expression engine's array-element access to obtain a reference to a host built-in and pollute its prototype in the main n8n process, leading to a denial of service.

Both self-hosted and cloud instances run…

GitHub-GHSA

MEDIUM
n8n: SSRF Protection Bypass via MCP Client Node
GHSA-vhf8-cg2h-cg3p
pkg: n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact

On an n8n instance with SSRF protection enabled, the MCP Client node sent requests to a user-supplied endpoint without routing them through that protection and without pinning the resolved address. An authenticated user who could create or edit a workflow could therefore cause the server …

GitHub-GHSA

MEDIUM
Netty: [codec-http2] Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass
GHSA-c69g-56f8-xwqj
pkg: io.netty:netty-codec-http2, io.netty:netty-codec-http2
eco: maven
published: Jul 22, 2026
Netty's HTTP/2-to-HTTP/1.x translation layer (`Http2StreamFrameToHttpObjectCodec` and `InboundHttp2ToHttpAdapter`) fails to deduplicate or validate `Host` headers when an HTTP/2 client supplies both the `:authority` pseudo-header and a literal `host` header in a single HEADERS frame. The translator …
CVE-2026-59900
GitHub-GHSA

MEDIUM
Netty: [HttpContentEncoder] Unbounded Per-Connection Queue Growth via HTTP/1.1 Pipelining Leads to Denial of Service
GHSA-q4f6-jm68-57ww
pkg: io.netty:netty-codec-http, io.netty:netty-codec-http
eco: maven
published: Jul 22, 2026
### Impact
`HttpContentEncoder` (the superclass of the production handler `HttpContentCompressor`) maintains a per-channel `ArrayDeque<CharSequence>` named `acceptEncodingQueue` that accumulates attacker-controlled data without any size limit. The queue is filled on the I/O thread for every inbound …
CVE-2026-59899
GitHub-GHSA

MEDIUM
Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation
GHSA-4mp9-239f-g9hg
pkg: io.netty:netty-codec-http, io.netty:netty-codec-http
eco: maven
published: Jul 22, 2026
## Summary
An attacker can force WebSocket upgrade via the lax V07 (or V08) handshaker by sending `Sec-WebSocket-Version: 7` and omitting `Connection: Upgrade` / `Upgrade: websocket` headers, completing a protocol switch that a proxy would not recognize as an Upgrade request and enabling HTTP reques…
CVE-2026-59898
GitHub-GHSA

MEDIUM
Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations
GHSA-cj75-f6xr-r4g7
pkg: rails-html-sanitizer
eco: rubygems
published: Jul 21, 2026
## Summary

There is a possible cross-site scripting vulnerability in rails-html-sanitizer when the sanitizer is configured to allow an SVG reference element such as `<use>`. See related [GHSA-9wjq-cp2p-hrgf](https://github.com/flavorjones/loofah/security/advisories/GHSA-9wjq-cp2p-hrgf) in Loofah, w…

GitHub-GHSA

MEDIUM
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata
GHSA-2wm4-vwp6-v7xc
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary

Gitea has robust SSRF protection via `hostmatcher.NewDialContext()` for webhook and migration clone URLs, which validates resolved IPs at the TCP dial level. However, three code paths use raw `http.Get()` (Go's `DefaultClient`) which completely bypasses this protection, enabling SSRF to…

CVE-2026-59765
GitHub-GHSA

MEDIUM
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145
GHSA-prr9-9mp4-5gp2
pkg: gitea.dev
eco: go
published: Jul 21, 2026
## Summary
PR #38145 fixed ListPublicMembers and IsPublicMember but missed
ListMembers. Any authenticated user can enumerate ALL members
(not just public ones) of a private organization.

## Affected Versions
<= v1.26.4 (latest) and main branch

## Root Cause
routers/api/v1/org/member.go — ListM…

CVE-2026-58427
GitHub-GHSA

MEDIUM
Gitea SSH Key Parser Denial of Service
GHSA-4xjf-493q-98p3
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
Gitea's SSH key ingestion endpoint accepts keys in RFC 4716 (SSH2) format and normalises them before storage. The normalisation function contains an O(N²) string concatenation loop with no input size limit, meaning a single malicious key submission can force the server to perform an amount of work …
CVE-2026-56657
GitHub-GHSA

MEDIUM
Gitea: Local File Inclusion via file:// URI in Migration Restore
GHSA-5ggr-2f2h-jmvm
pkg: gitea.dev
eco: go
published: Jul 21, 2026
# Local File Inclusion via file:// URI in Migration Restore

Target: go-gitea/gitea
Component: services/migrations/gitea_uploader.go, modules/uri/uri.go
Severity: High
Affected Versions: <= v1.22.x (all releases), master as of latest commit
Researchers:
– Isa Can — Eresus Security (https://github.…

CVE-2026-58420
GitHub-GHSA

MEDIUM
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes
GHSA-mg4f-x9v4-6h2p
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary

The OIDC userinfo endpoint (`GET /login/oauth/userinfo`) accepts Gitea API tokens as bearer credentials but does not enforce API token scopes before returning identity claims.

A personal access token scoped only to `read:misc` can successfully retrieve user information from the OIDC us…

CVE-2026-55982
GitHub-GHSA

MEDIUM
Gitea: REST API exposes organization membership of private organizations to public
GHSA-jr5x-6h83-wrxf
pkg: gitea.dev
eco: go
published: Jul 21, 2026
### Summary

The endpoint "/orgs/{org}/public_members/{username}" + GET exposes organization membership of public members in a private organization.

### PoC

1. Spin up the nightly container of Gitea.
2. Perform the default installation.
3. Register a new user (let's call this user "user1").
4. Cr…

CVE-2026-58417
GitHub-GHSA

MEDIUM
Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions
GHSA-rjvx-x5h2-6px5
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary

The API endpoint used to fork repositories into organizations performs a weaker authorization check than the corresponding web UI and other repository creation endpoints.

When a repository is forked into an organization through the API, the endpoint only verifies that the user is an or…

GitHub-GHSA

MEDIUM
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads
GHSA-9mq6-mqjj-c2c5
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
## Summary

Hello Gitea Security Team,

Thank you for your continued work on Gitea. I would like to responsibly report a potential availability-impact issue that I observed in Gitea’s Arch package registry implementation.

During local testing, I noticed that Gitea records non-dot regular file ent…

CVE-2026-59763
GitHub-GHSA

MEDIUM
Mistune: XSS via unescaped class option in Admonition directive
GHSA-g97x-gvcm-x72h
pkg: mistune
eco: pip
published: Jul 20, 2026
In `src/mistune/directives/admonition.py`, the `render_admonition()` function concatenates the `:class:` option directly into the HTML class attribute without escaping (lines 63-68).

This allows attribute injection and XSS even when `HTMLRenderer(escape=True)` is used.

The directive name parameter…

CVE-2026-59926
GitHub-GHSA

MEDIUM
pillow-heif: Integer Overflow in Encode Path Buffer Validation Leads to Heap Out-of-Bounds Read
GHSA-5gjj-6r7v-ph3x
pkg: pi-heif, pillow-heif
eco: pip
published: Jul 20, 2026
### Summary

An integer overflow in the encode path buffer validation of `_pillow_heif.c` allows an attacker to bypass bounds checks by providing large image dimensions, resulting in a heap out-of-bounds read. This can lead to information disclosure (server heap memory leaking into encoded images) o…

CVE-2026-28231


Vulnerability Digest — July 13, 2026 · 52 Critical · 6 Exploited






Vulnerability Digest — Monday, July 13, 2026


Security Report

Monday, July 13, 2026  ·  Last 7 days  ·  Min severity: MEDIUM
Total Findings
358
Critical
52
High
156
Actively Exploited
6
CISA-KEV6
NVD199
GitHub-GHSA153
Findings sorted by severity
CISA-KEV

CRITICAL
Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability
CVE-2026-56291
pkg: Balbooa Forms

published: Jul 10, 2026

Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability
CVE-2026-48939
pkg: iCagenda iCagenda

published: Jul 10, 2026

iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Adobe ColdFusion Path Traversal Vulnerability
CVE-2026-48282
pkg: Adobe ColdFusion

published: Jul 7, 2026

Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Joomlack Page Builder Improper Access Control Vulnerability
CVE-2026-56290
pkg: Joomlack Page Builder

published: Jul 7, 2026

Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability
CVE-2026-48908
pkg: JoomShaper SP Page Builder

published: Jul 7, 2026

JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Langflow Authorization Bypass Through User-Controlled Key Vulnerability
CVE-2026-55255
pkg: Langflow Langflow

published: Jul 7, 2026

Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
NVD

CRITICAL
CVE-2026-61447
CVE-2026-61447
pkg: python

published: Jul 11, 2026

PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement. Attackers can influence LLM output through prompt injection to exfiltrate all environment…
CWE: CWE-94
NVD

CRITICAL
CVE-2026-54769
CVE-2026-54769
pkg: python

published: Jul 10, 2026

Langroid is a framework for building large-language-model-powered applications. Versions prior to 0.65.2 are vulnerable to a critical Sandbox Escape leading to Remote Code Execution (RCE) in its `TableChatAgent` and `VectorStore` capabilities. When these agents evaluate LLM-generated tool messages w…
CWE: CWE-94
NVD

CRITICAL
CVE-2026-59726
CVE-2026-59726
pkg: docker

published: Jul 9, 2026

Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-compose deployment exposed the MCP bridge POST /mcp and POST /mcp/:group endpoints without authentication, allowing an unauthenticated network attacker to invoke tools/call to terminal_execute, obtain a…
CWE: CWE-78, CWE-306, CWE-942
NVD

CRITICAL
CVE-2026-54782
CVE-2026-54782
pkg: windows

published: Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML 1.1 and SAML 2.0 token validation does not correctly resolve the issuer signing key or require signed tokens when IdentityConfiguration is used with federated bindings…
CWE: CWE-290, CWE-347
GitHub-GHSA

CRITICAL
Nuclio: Unsanitized cron trigger event headers/body injected into CronJob shell command leads to persistent RCE
GHSA-v5px-423j-pf7p
pkg: github.com/nuclio/nuclio
eco: go
published: Jul 8, 2026
## Summary

Nuclio controller builds a `curl` invocation string for each cron trigger and stores it as the `args` of a Kubernetes CronJob container (`/bin/sh`, `-c`, `<command>`). Two fields in the trigger specification flow into this string without adequate sanitization:

– `event.headers` keys —…

CVE-2026-52831
GitHub-GHSA

CRITICAL
9router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats
GHSA-vjc7-jrh9-9j86
pkg: 9router
eco: npm
published: Jul 6, 2026

title: Unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats
product: 9Router
version: <= 0.4.41
severity: critical
cve_request: true

## Summary

Multiple critical API security vulnerabilities were discovered in 9Router's Next.js dashboard. The `/api/providers` e…

NVD

CRITICAL
CVE-2026-57572
CVE-2026-57572
pkg: kidocode crawl4ai

published: Jul 6, 2026

Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server accepted request-supplied browser_config.extra_args, which flowed into Chromium's launch arguments. An attacker could inject Chromium switches that replace a child-process launch command together w…
CWE: CWE-88, CWE-94
GitHub-GHSA

CRITICAL
Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent
GHSA-q9p7-wqxg-mrhc
pkg: langroid
eco: pip
published: Jul 6, 2026
### Advisory Details
**Title**: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent

**Description**:
### Summary
Langroid is vulnerable to a critical Sandbox Escape leading to Remote Code Execution (RCE) in its `TableChatAgent` and `VectorStore` capabilities…

CVE-2026-54769
NVD

CRITICAL
CVE-2026-14480
CVE-2026-14480
pkg: python

published: Jul 10, 2026

OpenPLC Runtime v3 contains an authenticated arbitrary file write
vulnerability in the legacy web UI program‑upload workflow. The
application stores an attacker‑supplied filename (prog_file) directly
into the Programs.File database field and later uses this value as the
destination path for …
CWE: CWE-73
GitHub-GHSA

CRITICAL
SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content
GHSA-56mp-4f3v-fgj2
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: Jul 10, 2026
SiYuan v3.6.5 and earlier versions contain a stored cross-site scripting (XSS) vulnerability in the Attribute View (database) asset cell renderer that escalates to remote code execution (RCE) in the Electron desktop client. This is a neighbor-bug of CVE-2026-44588: the fix for -44588 used `escapeAri…
CVE-2026-50551
GitHub-GHSA

CRITICAL
SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML()
GHSA-5xfx-xj4h-5p7r
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: Jul 10, 2026
### Summary

The attribute-view (database) cell renderer `genAVValueHTML` interpolates cell content raw in four of its branches: `text`, `url`, `phone`, and `mAsset`. A cell value like `</textarea><img src=x onerror="…">` or `"><img src=x onerror="…">` breaks out of its surrounding tag and runs …

CVE-2026-54158
GitHub-GHSA

CRITICAL
SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet()
GHSA-mvjr-vv3c-w4qv
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: Jul 10, 2026
### Summary

A CSS snippet body containing `</style>` breaks out of its surrounding `<style>` tag when `renderSnippet()` interpolates it via `insertAdjacentHTML`. A payload like `</style><img src=x onerror="…">` runs arbitrary JavaScript in the renderer. On Electron desktop builds the renderer run…

CVE-2026-54067
NVD

CRITICAL
CVE-2026-55500
CVE-2026-55500
pkg: jwt

published: Jul 10, 2026

9Router is an AI router & token saver. Prior to 0.4.80, the /api/settings/database endpoint allows full database export (containing all credentials, API keys, OAuth tokens, and settings) and full database import (complete overwrite) without any authentication requirement beyond the ALWAYS_PROTECTED …
CWE: CWE-200
GitHub-GHSA

CRITICAL
9routers has Exposure of Sensitive Information and Unprotected Database Import/Export, Allowing Complete Credential Theft and Database Takeover
GHSA-qvfm-67h2-2qfx
pkg: 9router
eco: npm
published: Jul 6, 2026
## Summary

The `/api/settings/database` endpoint allows full database export (containing all credentials, API keys, OAuth tokens, and settings) and full database import (complete overwrite) without any authentication requirement beyond the `ALWAYS_PROTECTED` middleware check, which only validates J…

CVE-2026-55500
NVD

CRITICAL
CVE-2026-34038
CVE-2026-34038
pkg: docker

published: Jul 6, 2026

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, an authenticated remote command injection vulnerability in application deployment handling allows users with application write permissions to achieve remote code execution and…
CWE: CWE-78
NVD

CRITICAL
CVE-2026-56271
CVE-2026-56271
pkg: jwt

published: Jul 12, 2026

Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience and issuer values ('AUDIENCE', 'ISSUER') in the enterprise passport authentication middleware (packages/server/src/enterprise/middleware/passport/i…
CWE: CWE-321
NVD

CRITICAL
CVE-2026-57807
CVE-2026-57807
pkg: oauth

published: Jul 10, 2026

Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd. OAuth Single Sign On – SSO (OAuth Client) allows Password Recovery Exploitation.

This issue affects OAuth Single Sign On – SSO (OAuth Client): from n/a through 38.5.8.

CWE: CWE-288
NVD

CRITICAL
CVE-2026-12761
CVE-2026-12761
pkg: oauth

published: Jul 10, 2026

The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass leading to account takeover in versions up to and including 7.7.0. This is due to the Profile Completion flow accepting an arbitrary email address via the 'email_…
CWE: CWE-287
NVD

CRITICAL
CVE-2026-61459
CVE-2026-61459
pkg: kubernetes

published: Jul 10, 2026

MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) that allows attackers to bypass the assertNoDangerousFlags security check by supplying resourceType and name parameters with leading dashes. Attackers c…
CWE: CWE-88
NVD

CRITICAL
CVE-2026-13019
CVE-2026-13019
pkg: esri portal_for_arcgis, kubernetes kubernetes, linux linux_kernel

published: Jul 7, 2026

Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API.
CWE: CWE-640
NVD

CRITICAL
CVE-2026-9182
CVE-2026-9182
pkg: esri arcgis_server, linux linux_kernel, microsoft windows

published: Jul 6, 2026

Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endpoint. Successful exploitation could allow arbitrary file upload, potentially allowing for other attacks. This issue impacts all …
CWE: CWE-434
NVD

CRITICAL
CVE-2026-9181
CVE-2026-9181
pkg: esri arcgis_server, linux linux_kernel, microsoft windows

published: Jul 6, 2026

Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An unauthenticated attacker could exploit this issue by sending crafted path parameters. Successful exploitation could allow overwriting sensitive files on the system. Abuse of this issu…
CWE: CWE-22
NVD

CRITICAL
CVE-2026-59151
CVE-2026-59151
pkg: jwt

published: Jul 10, 2026

Prowler is a cloud security platform. Prior to 5.30.3, Prowler's SAML authentication flow trusted the email domain asserted in a SAMLResponse when deciding which tenant should receive the final token, and the ACS finish logic in api/src/backend/api/v1/views.py recalculated the tenant from user.email…
CWE: CWE-287
NVD

CRITICAL
CVE-2026-13461
CVE-2026-13461
pkg: ssl

published: Jul 9, 2026

When coupled with the SSL bypass vulnerability, JavaScript can be injected into a WebView in the PayRange version 7.0.7 app. The injection of specific JavaScript function calls allows the attacker to escape the WebView sandbox and perform a number of dangerous actions on the user's device.
NVD

CRITICAL
CVE-2026-15113
CVE-2026-15113
pkg: google chrome, google android

published: Jul 8, 2026

Use after free in Autofill in Google Chrome on Android prior to 150.0.7871.115 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
GitHub-GHSA

CRITICAL
Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE
GHSA-xqhv-chqm-fhcc
pkg: github.com/BishopFox/joro
eco: go
published: Jul 8, 2026
# Unauthenticated Cross-Origin Plugin Upload Leads to RCE (Joro ≤ v1.1.0)

**Severity:** Critical
**CVSS v3.1:** 9.6 (AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H)
**Affected versions:** Joro ≤ v1.1.0, proxy mode (default), Linux/macOS
**Reporter:** cstover
**Date:** 2026-05-27

## Summary

Joro's d…

CVE-2026-53649
NVD

CRITICAL
CVE-2026-15062
CVE-2026-15062
pkg: python

published: Jul 8, 2026

SQL injection vulnerabilities in the Snowflake Snowpark Python SDK (snowpark-python) versions prior to 1.53.0 could allow authenticated low-privilege users to execute SQL beyond their authorization scope. An attacker could exploit these vulnerabilities by embedding SQL payloads in source database co…
CWE: CWE-89
GitHub-GHSA

CRITICAL
Goploy: Cross-namespace IDOR and RCE via body-supplied row id in project and project_file handlers
GHSA-26rh-24rg-j3vv
pkg: github.com/zhenorzz/goploy
eco: go
published: Jul 7, 2026
### Summary

`Project.AddFile`, `Project.EditFile`, `Project.RemoveFile`, and `Project.Edit` in `cmd/server/api/project/handler.go` accept a project or project-file row id from the JSON body and act on it without checking that the project belongs to the caller's namespace. The corresponding `model.P…

CVE-2026-53552
GitHub-GHSA

CRITICAL
@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints
GHSA-5rr4-8452-hf4v
pkg: @better-auth/sso
eco: npm
published: Jul 7, 2026
### Am I affected?

Users are affected if all of the following are true:

– Their application uses `@better-auth/sso` at a version `>= 0.1.0, < 1.6.11` on the stable line, or any `1.7.0-beta.x` on the pre-release line.
– The `sso()` plugin is added to their application's `betterAuth({ plugins: […]…

CVE-2026-53513
NVD

CRITICAL
CVE-2026-55879
CVE-2026-55879
pkg: jwt

published: Jul 10, 2026

OpenReplay is a self-hosted session replay suite. From 1.24.0 before 1.25.0, the OpenReplay tracking SDK accepts custom event names and captured page URLs from any visitor using a public project key, stores them in ClickHouse without output encoding, and later renders them in the authenticated dashb…
CWE: CWE-79
GitHub-GHSA

CRITICAL
Authorizer: Unvalidated redirect_uri in /authorize leaks OAuth2 tokens to attacker-controlled URL
GHSA-h29v-hj44-q8cv
pkg: github.com/authorizerdev/authorizer
eco: go
published: Jul 10, 2026
## Summary

The `/authorize` endpoint accepts any `redirect_uri` without validating it against `AllowedOrigins`. When `response_type=token` or `response_type=id_token`, the server appends `access_token`, `id_token`, and `refresh_token` as query parameters and issues a 302 redirect to the attacker-su…

CVE-2026-54072
NVD

CRITICAL
CVE-2026-15378
CVE-2026-15378
pkg: kubernetes

published: Jul 10, 2026

A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind Server-Side Request Forgery (SSRF) by submitting a specially crafted XML Schema Definition (XSD) string. This can lead to unauthorized access to sensitive information, including c…
CWE: CWE-918
GitHub-GHSA

CRITICAL
Zebra: Missing copy constraint in halo2_gadgets variable-base scalar multiplication allows under-constrained base, breaking Orchard Action circuit soundness
GHSA-ww9q-8r59-xv46
pkg: zebrad, halo2_gadgets, orchard
eco: rust
published: Jul 6, 2026
### Summary

A soundness vulnerability in the variable-base scalar multiplication gadget of `halo2_gadgets` allowed a malicious prover to produce a valid proof for an Orchard Action with an *under-constrained* base point. Because this gadget enforces the diversified-address-integrity condition of th…

CVE-2026-54496
GitHub-GHSA

CRITICAL
Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access
GHSA-3fcv-jvfp-m4q9
pkg: github.com/cilium/cilium, github.com/cilium/cilium, github.com/cilium/cilium
eco: go
published: Jul 6, 2026
### Impact

When Cilium L7 functionality is enabled on a cluster, the Envoy instance supporting this functionality creates a world-accessible socket on cluster nodes. A local attacker would be able to access Envoy admin endpoints. Depending on deployment configuration, this can expose sensitive info…

CVE-2026-49445
NVD

CRITICAL
CVE-2026-56260
CVE-2026-56260
pkg: docker

published: Jul 12, 2026

Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. The output_path parameter accepts arbitrary filesystem paths without validation, allowing an attacker to supply absolute or path-traversal values to write to any location w…
CWE: CWE-22
GitHub-GHSA

CRITICAL
File Browser: Authentication Bypass via Proxy Auth Header Forgery
GHSA-xqp3-jq6g-x3qm
pkg: github.com/filebrowser/filebrowser/v2
eco: go
published: Jul 10, 2026
## Summary

When FileBrowser is configured with proxy authentication (`auth.method=proxy`), any unauthenticated attacker who can reach the server directly can impersonate **any user – including admin** – by sending a single forged HTTP header. No credentials are required. Additionally, specifying a …

CVE-2026-54089
NVD

CRITICAL
CVE-2026-61444
CVE-2026-61444
pkg: python

published: Jul 10, 2026

PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file parameter is directly interpolated into an f-string without sanitization. Attackers can inject arbitrary Python code that executes when the generated server code runs via subprocess.Popen()…
CWE: CWE-94
NVD

CRITICAL
CVE-2026-58122
CVE-2026-58122
pkg: oauth

published: Jul 9, 2026

Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to circumvent local-origin IP restrictions on onboarding endpoints by supplying a spoofed X-Forwarded-For header with a loopback address. Attackers can exploit this bypass to per…
CWE: CWE-348
GitHub-GHSA

CRITICAL
Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins
GHSA-pw9m-5jxm-xr6h
pkg: better-auth
eco: npm
published: Jul 7, 2026
### Am I affected?

Users are affected if all of the following are true:

– Their application uses `better-auth` and has enabled at least one of: `oidcProvider()` (imported from `better-auth/plugins/oidc-provider`), or `mcp()` (imported from `better-auth/plugins/mcp`).
– Their application has at lea…

CVE-2026-53512
GitHub-GHSA

CRITICAL
Decompress: Archive extraction can create files and links outside of the target directory
GHSA-mp2f-45pm-3cg9
pkg: @xhmikosr/decompress, @xhmikosr/decompress, decompress
eco: npm
published: Jul 6, 2026
### Impact

When extracting an archive to a directory, a crafted archive can read or write files outside that directory. The flaw is in the code that writes the parsed entries, so it affects every format decompress handles: tar, tar.gz, tar.bz2, and zip by default, plus any others added through the …

CVE-2026-53486
GitHub-GHSA

CRITICAL
TSDProxy: Internal proxy auth token forwarded to backend services enables management API escalation
GHSA-g936-7jqj-mwv8
pkg: github.com/almeidapaulopt/tsdproxy
eco: go
published: Jul 10, 2026
## Description

A vulnerability was discovered in TSDProxy where it forwards its internal per-process authentication token to all proxied backend services. When `identityHeaders` is enabled (the default), tsdproxy injects `x-tsdproxy-auth-token` into every upstream HTTP request alongside user identi…

GitHub-GHSA

CRITICAL
File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)
GHSA-m93h-4hw7-5qcm
pkg: github.com/filebrowser/filebrowser/v2
eco: go
published: Jul 10, 2026
## Overview

The Hook Authentication feature in File Browser allows administrators to delegate login verification to an external shell command. User-supplied credentials (username and password) are interpolated into this command string using `os.Expand` without sanitization. An **unauthenticated rem…

CVE-2026-54088
GitHub-GHSA

CRITICAL
`exploration` was removed from crates.io for malicious code
GHSA-99j7-fhr2-xfj4
pkg: exploration
eco: rust
published: Jul 10, 2026
A method within the `exploration` crate attempted to download and execute a payload from a remote site.

The malicious crate had 1 version published on 2026-06-02, approximately 1 hour before removal, and had no evidence of actual usage. This crate had no dependencies on crates.io.

Rustsec to Kiril…

GitHub-GHSA

CRITICAL
SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist
GHSA-hvr9-72v2-fff3
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: Jul 10, 2026
## Summary

SiYuan Note's kernel HTTP server unconditionally trusts all `chrome-extension://` origins, granting `RoleAdministrator` access to every installed browser extension without any authentication. Combined with the default empty `AccessAuthCode` on desktop installs, any Chrome/Chromium extens…

CVE-2026-54069
GitHub-GHSA

CRITICAL
Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditional RCE), mirroring the SQLChatAgent bug fixed in CVE-2026-25879
GHSA-2pq5-3q89-j7cc
pkg: langroid
eco: pip
published: Jul 6, 2026
Neo4jChatAgent passes LLM-generated Cypher queries straight to the Neo4j driver with no validation, no statement-type allowlist, and no opt-out gate. The query text is influenceable by prompt injection (direct user input or indirect content the agent reads back via RAG), so an attacker who can influ…
CVE-2026-55615
GitHub-GHSA

CRITICAL
Langroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema-qualified pg_read_file calls
GHSA-6xc5-4r68-67fc
pkg: langroid
eco: pip
published: Jul 6, 2026
# SQLChatAgent `_validate_query` dangerous-pattern regex is bypassable via quoted/commented/qualified function names

## Summary

The `SQLChatAgent` SQL-injection mitigation, with default `allow_dangerous_operations=False`, combines a raw-text regex blocklist (`_DANGEROUS_SQL_PATTERNS`) with a `sqlg…

CVE-2026-54760
NVD

HIGH
CVE-2026-14262
CVE-2026-14262
pkg: jwt

published: Jul 11, 2026

The Simple JWT Login – Allows you to use JWT on REST endpoints. plugin for WordPress is vulnerable to Authentication Bypass to Privilege Escalation in all versions up to, and including, 3.6.6 via the `payload` parameter. The vulnerability exists because `AuthenticateService::generatePayload()` onl…
CWE: CWE-269
NVD

HIGH
CVE-2026-13353
CVE-2026-13353
pkg: express

published: Jul 11, 2026

The WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.0.1 via the 'MappedFields' parameter. This is due to missing capability checks on the AJAX handlers for install_addon, s…
CWE: CWE-94
GitHub-GHSA

HIGH
SafeInstall agent guard shell parsing can miss raw package execution
GHSA-xrmc-c5cg-rv7x
pkg: safeinstall-cli
eco: npm
published: Jul 10, 2026
## Summary

SafeInstall CLI through 0.10.1 can fail to recognize some package-manager and registry-runner commands in its agent guard. Case-variant launcher names, leading file-descriptor redirections, and supported shell wrappers with options can cause a raw install command to receive no guard deci…

NVD

HIGH
CVE-2026-54149
CVE-2026-54149
pkg: node

published: Jul 10, 2026

MaxKB is an open-source AI assistant for enterprise. Prior to 2.10.0-lts, MaxKB tool import functionality in apps/tools/serializers/tool.py and MCP referencing mode in apps/application/chat_pipeline/step/chat_step/impl/base_chat_step.py do not consistently validate MCP transport type, allowing an au…
CWE: CWE-78
NVD

HIGH
CVE-2026-59148
CVE-2026-59148
pkg: express

published: Jul 9, 2026

Mockoon provides way to design and run mock APIs. Prior to 9.7.0, Mockoon's admin API in commons-server/src/libs/server/admin-api.ts is mounted on the same Express listener as user-defined mock routes, enabled by default in shipped runtimes, serves Access-Control-Allow-Origin: * with write methods a…
CWE: CWE-306, CWE-352, CWE-732, CWE-942
NVD

HIGH
CVE-2026-15133
CVE-2026-15133
pkg: google chrome

published: Jul 8, 2026

Use after free in InterestGroups in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-15132
CVE-2026-15132
pkg: google chrome

published: Jul 8, 2026

Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-457
NVD

HIGH
CVE-2026-15129
CVE-2026-15129
pkg: google chrome

published: Jul 8, 2026

Use after free in Views in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-15126
CVE-2026-15126
pkg: google chrome

published: Jul 8, 2026

Use after free in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-15125
CVE-2026-15125
pkg: google chrome

published: Jul 8, 2026

Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-863
NVD

HIGH
CVE-2026-15123
CVE-2026-15123
pkg: google chrome

published: Jul 8, 2026

Inappropriate implementation in DOM in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-122
NVD

HIGH
CVE-2026-15121
CVE-2026-15121
pkg: google chrome

published: Jul 8, 2026

Use after free in WebRTC in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-15118
CVE-2026-15118
pkg: google chrome

published: Jul 8, 2026

Use after free in Input in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-15116
CVE-2026-15116
pkg: google chrome

published: Jul 8, 2026

Use after free in Actor in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-15114
CVE-2026-15114
pkg: google chrome

published: Jul 8, 2026

Out of bounds read and write in Codecs in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. (Chromium security severity: High)
CWE: CWE-125, CWE-787
NVD

HIGH
CVE-2026-15112
CVE-2026-15112
pkg: google chrome

published: Jul 8, 2026

Use after free in Ozone in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-15110
CVE-2026-15110
pkg: google chrome

published: Jul 8, 2026

Use after free in Extensions in Google Chrome prior to 150.0.7871.115 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-15107
CVE-2026-15107
pkg: google chrome

published: Jul 8, 2026

Use after free in IndexedDB in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-416
NVD

HIGH
CVE-2026-59257
CVE-2026-59257
pkg: n8n n8n

published: Jul 8, 2026

n8n before 1.123.61, 2.x before 2.27.4, and 2.28.x before 2.28.1 contains a SQL injection vulnerability in the legacy MySQL v1 node's executeQuery operation. The operation substitutes evaluated {{ … }} expression values directly into the raw SQL string without parameterization. When a workflow use…
CWE: CWE-89
NVD

HIGH
CVE-2026-34158
CVE-2026-34158
pkg: docker

published: Jul 7, 2026

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, the executeInDocker() helper wraps user-controlled commands in single quotes without escaping embedded single quotes. Attackers who can edit application settings can inject a …
CWE: CWE-78
NVD

HIGH
CVE-2026-34168
CVE-2026-34168
pkg: docker

published: Jul 7, 2026

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the LocalPersistentVolume.name field is interpolated directly into docker volume shell commands without shell argument escaping, allowing an authenticated user to set a storag…
CWE: CWE-78
NVD

HIGH
CVE-2026-42204
CVE-2026-42204
pkg: docker

published: Jul 6, 2026

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. From 4.0.0-beta.471 through 4.0.0-beta.473, a regression in SHELL_SAFE_COMMAND_PATTERN allowed ampersands in custom Docker Compose build, start, and pre/post-deployment command fields, allowing an aut…
CWE: CWE-78
NVD

HIGH
CVE-2026-34599
CVE-2026-34599
pkg: docker

published: Jul 6, 2026

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, there is an authenticated command injection vulnerability in the GetLogs Livewire component which allows users with team membership (lowest privilege member role) to execute a…
CWE: CWE-78
GitHub-GHSA

HIGH
Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requests
GHSA-659f-rgp5-w4wf
pkg: github.com/zalando/skipper
eco: go
published: Jul 8, 2026
### Summary

`zalando/skipper`'s OpenPolicyAgent integration silently bypasses request-body
inspection on HTTP/1.1 `Transfer-Encoding: chunked` and HTTP/2 requests that
omit the `content-length` pseudo-header. When the
`opaAuthorizeRequestWithBody` filter is configured, the
`OpenPolicyAgentInstance.…

CVE-2026-50197
NVD

HIGH
CVE-2026-14891
CVE-2026-14891
pkg: docker

published: Jul 8, 2026

HashiCorp Nomad and Nomad Enterprise are vulnerable to a sandbox escape in the Docker task driver that may allow a job submitter to bind-mount a host path into a container even when volume bind mounts are disabled, potentially leading to reading and writing files on the host. This vulnerability, CVE…
CWE: CWE-59
GitHub-GHSA

HIGH
Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default
GHSA-9h47-pqcx-hjr4
pkg: better-auth
eco: npm
published: Jul 7, 2026
### Am I affected?

Users are affected if all of the following are true:

– Their application uses `better-auth` at a version below the patched release.
– Their application enables `oidcProvider()` from `better-auth/plugins/oidc-provider` or `mcp()` from `better-auth/plugins/mcp` (the mcp plugin del…

GitHub-GHSA

HIGH
Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID
GHSA-9rjw-3gwp-f59v
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

`UpsertWorkspaceApp` overwrites an existing app's `agent_id` on a primary-key conflict and `insertAgentApp` accepts the app ID from the provisioner's `CompleteJob` payload without verifying it belongs to the workspace being built. `CompleteJob` runs under `dbauthz.AsProvisionerd` so the…

CVE-2026-55429
NVD

HIGH
CVE-2026-52747
CVE-2026-52747
pkg: nginx

published: Jul 10, 2026

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Prior to 3.0.16, the multipart/form-data request body parser in libmodsecurity silently removes embedded line breaks from non-file form-field values before exporting them to ARGS and ARGS_P…
CWE: CWE-180
NVD

HIGH
CVE-2026-56261
CVE-2026-56261
pkg: docker

published: Jul 10, 2026

Crawl4AI before 0.8.7 contains a server-side request forgery (SSRF) vulnerability in the Docker API server's /crawl/job and /llm/job endpoints, which accept webhook URLs without destination validation. An attacker can supply webhook URLs pointing to private or internal IP ranges, Docker networks, or…
CWE: CWE-918
NVD

HIGH
CVE-2026-57573
CVE-2026-57573
pkg: kidocode crawl4ai

published: Jul 6, 2026

Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server applied its SSRF destination check on the non-streaming /crawl path but not on the streaming path. handle_stream_crawl_request passed seed URLs straight to the crawler with no destination validatio…
CWE: CWE-918
NVD

HIGH
CVE-2026-54765
CVE-2026-54765
pkg: traefik traefik

published: Jul 6, 2026

Traefik is an open source HTTP reverse proxy and load balancer. From v3.7.0 prior to v3.7.6, Traefik's Kubernetes Gateway API provider may resolve two accepted HTTPRoutes that target the same backend Service:port but configure different backendRef filters to the same child service and apply only one…
CWE: CWE-284, CWE-863
GitHub-GHSA

HIGH
flyto-core has Unauthenticated Command Execution via HTTP MCP `execute_module`
GHSA-h9f9-h6gm-wc85
pkg: flyto-core
eco: pip
published: Jul 6, 2026
## Unauthenticated Command Execution via HTTP MCP `execute_module`

### Summary

The HTTP MCP endpoint (`POST /mcp`) in flyto-core accepts unauthenticated JSON-RPC `tools/call` requests and dispatches them to arbitrary registered modules, including `sandbox.execute_shell`, which passes attacker-cont…

CVE-2026-55786
GitHub-GHSA

HIGH
melange: Incomplete package integrity verification allows data section substitution
GHSA-fpg8-7664-jc5q
pkg: chainguard.dev/apko, chainguard.dev/melange
eco: go
published: Jul 10, 2026
Previously, Apko verified the control section hash (`.PKGINFO` etc.) against the signed `APKINDEX`, but never verified the data section hash (the actual package files that get installed). An attacker who could compromise a mirror, poison a cache, or MITM a package fetch could substitute arbitrary fi…
CVE-2026-54174
NVD

HIGH
CVE-2026-47829
CVE-2026-47829
pkg: openssh

published: Jul 9, 2026

Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-spawned ssh process when an operator runs bosh ssh -c, bosh logs -f, or other non-interactive SSH paths, leading to local command execution on the operator's workstation.
Affected v…
NVD

HIGH
CVE-2026-15122
CVE-2026-15122
pkg: google chrome, microsoft windows

published: Jul 8, 2026

Insufficient validation of untrusted input in Codecs in Google Chrome on Windows prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-20
NVD

HIGH
CVE-2026-15120
CVE-2026-15120
pkg: google chrome, microsoft windows

published: Jul 8, 2026

Use after free in Core in Google Chrome on Windows prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-15119
CVE-2026-15119
pkg: google chrome

published: Jul 8, 2026

Race in GetUserMedia in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-362
NVD

HIGH
CVE-2026-55830
CVE-2026-55830
pkg: python

published: Jul 8, 2026

RestrictedPython is a tool that helps to define a subset of the Python language which allows to provide a program input into a trusted environment. Prior to 8.3, check_function_argument_names() rejected protected guard hook names for regular, variadic, and keyword-only arguments but omitted position…
CWE: CWE-184
GitHub-GHSA

HIGH
Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE
GHSA-37h2-6p4f-mp3q
pkg: serena-agent
eco: pip
published: Jul 8, 2026
### Summary

Serena's built-in web dashboard exposes an unauthenticated Flask API on a fixed, predictable port (TCP 24282, hardcoded as `0x5EDA` in `constants.py`). The server has no authentication, no CSRF protection, and no Host header validation. A DNS rebinding attack allows a malicious webpage …

CVE-2026-49471
GitHub-GHSA

HIGH
@better-auth/scim: Account/provider takeover via missing owner binding on non-org SCIM providers
GHSA-j8v8-g9cx-5qf4
pkg: @better-auth/scim
eco: npm
published: Jul 7, 2026
### Am I affected?

Users are affected if all of these hold:

– They install and register the `@better-auth/scim` plugin (`plugins: [scim()]`).
– They create SCIM providers without an `organizationId`, that is, non-organization ("personal") providers. Organization-scoped providers are not affected b…

GitHub-GHSA

HIGH
Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email
GHSA-g38m-r43w-p2q7
pkg: better-auth
eco: npm
published: Jul 7, 2026
### Am I affected?

Users are affected if all of the following are true:

– Their application uses `better-auth` at a version `< 1.6.11` on the stable line, or any current `next` pre-release.
– `emailAndPassword.enabled: true` is set in their application's `betterAuth({ … })` configuration.
– At l…

CVE-2026-53516
GitHub-GHSA

HIGH
Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write
GHSA-qrwj-vh9x-gw5v
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

`agentConn.apiClient()` used the default redirect behavior of `http.Client` while its custom transport dialed the host from the request URL as long as the port was the workspace agent HTTP API port (`4`). Agent tailnet IPs are deterministic from agent UUIDs, so a malicious workspace age…

GitHub-GHSA

HIGH
Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`
GHSA-mcqq-fqgf-rxwm
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

`coder config-ssh` wrote server-supplied SSH settings (`HostnameSuffix`, `SSHConfigOptions`) into the user's `~/.ssh/config` without sanitizing embedded newlines or restricting directives so a malicious or compromised Coder server could inject arbitrary SSH configuration.

> **Note:** P…

CVE-2026-55427
NVD

HIGH
CVE-2026-56259
CVE-2026-56259
pkg: docker

published: Jul 12, 2026

Crawl4AI before 0.8.8 contains credential exfiltration vulnerabilities in the Docker API server that allow attackers to redirect LLM API calls to attacker-controlled endpoints and read arbitrary environment variables. Attackers can exploit the unauthenticated /md, /llm, and /llm/job endpoints by sup…
CWE: CWE-200
NVD

HIGH
CVE-2026-53657
CVE-2026-53657
pkg: linux

published: Jul 10, 2026

Lima launches Linux virtual machines, typically on macOS, for running containerd. Prior to 2.1.3, on an instance of Lima running with the qemu driver, an arbitrary user in the VM could access /run/lima-guestagent.sock when the guest agent is enabled, which could result in running arbitrary commands …
CWE: CWE-276, CWE-668
NVD

HIGH
CVE-2026-54423
CVE-2026-54423
pkg: node

published: Jul 10, 2026

In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI commands to a node, bypassing Ironic's access control.
CWE: CWE-424
GitHub-GHSA

HIGH
`lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes
GHSA-4jhm-jv67-739f
pkg: lxml_html_clean
eco: pip
published: Jul 8, 2026
# `lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes (`xlink:href`)

**Reporter:** Guillem Lefait <guillem@datamq.com> · **Date:** 2026-05-10
**Affected:** `lxml` ≤ 6.1.0 and `lxml_html_clean` ≤ 0.4.4 (latest stable)
**Confirmed against:** lxml 6.1.0 + lx…

CVE-2026-49825
GitHub-GHSA

HIGH
Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator
GHSA-wrq8-fcv5-8hvp
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

The tailnet coordinator validates that an agent's `Addresses` derive from its authenticated UUID but applies no equivalent check to `AllowedIPs`. The coordinator forwards agent-supplied `AllowedIPs` verbatim to tunnel peers which install them into the WireGuard peer configuration.

### …

CVE-2026-55428
NVD

HIGH
CVE-2026-59195
CVE-2026-59195
pkg: pnpm pnpm

published: Jul 6, 2026

pnpm is a package manager. Prior to 10.34.4 and 11.8.0, pnpm accepts package names from the env lockfile configDependencies section and uses those names directly when creating config dependency symlinks under node_modules/.pnpm-config. A malicious repository can commit a crafted pnpm-lock.yaml whose…
CWE: CWE-22
NVD

HIGH
CVE-2026-56668
CVE-2026-56668
pkg: oauth

published: Jul 10, 2026

ZITADEL is an open source identity management platform. Prior to 4.15.3, ZITADEL's OAuth2 Token Exchange endpoint for urn:ietf:params:oauth:grant-type:token-exchange does not verify that the subject token belongs to the requesting client or that requested scopes remain within the original token's sc…
CWE: CWE-862
NVD

HIGH
CVE-2026-12597
CVE-2026-12597
pkg: oauth

published: Jul 10, 2026

The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via the GitHub OAuth callback in versions up to, and including, 6.2.3. The vulnerability exists in the loginpress_on_github_login() function, which blindly trusts the first element (profile[0]['email']) of the array retur…
CWE: CWE-287
NVD

HIGH
CVE-2026-12595
CVE-2026-12595
pkg: oauth

published: Jul 10, 2026

The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via Unverified OAuth Email in all versions up to and including 6.2.3. The vulnerability exists in the loginpress_on_discord_login() Discord OAuth callback handler, which accepts the email field returned by Discord's /user…
CWE: CWE-287
NVD

HIGH
CVE-2026-31985
CVE-2026-31985
pkg: tls

published: Jul 9, 2026

When the upstream Guardian or CMC was configured in the Remote Collector via n2os-tui, the generated configuration disabled TLS certificate verification, and no option was provided to enable it. A malicious actor could perform a man-in-the-middle attack and intercept the communication between the Re…
CWE: CWE-671
NVD

HIGH
CVE-2026-54591
CVE-2026-54591
pkg: python

published: Jul 8, 2026

AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Prior to 2.23.1, a malicious SSH server can write arbitrary files on the asyncssh SCP client's filesystem by sending filenames containing ../ tra…
CWE: CWE-22
GitHub-GHSA

HIGH
NL Portal: IDOR allows any authenticated user to complete and tamper with another user's taak
GHSA-6h3c-r723-7fx3
pkg: nl.nl-portal:taak
eco: maven
published: Jul 8, 2026
## Impact

In versions from 1.5.0 up to and including 3.0.0, any authenticated portal user could complete and tamper with another user's open task by submitting it on their behalf. The task submission endpoint accepted a task ID and a payload, but it never checked whether the task actually belonged …

CVE-2026-49464
NVD

HIGH
CVE-2026-54652
CVE-2026-54652
pkg: nginx

published: Jul 8, 2026

Frigate is an open source network video recorder. In version 0.17.1, the GET /api/logs/{service} endpoint allows any authenticated user including the viewer role to download Frigate and nginx logs, exposing auto-generated admin passwords and camera credentials logged in request query strings and ena…
CWE: CWE-269, CWE-532, CWE-598, CWE-863
GitHub-GHSA

HIGH
@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive
GHSA-7w99-5wm4-3g79
pkg: @better-auth/oauth-provider, better-auth
eco: npm
published: Jul 7, 2026
### Am I affected?

Users are affected if all of the following are true:

– Their project depends on `@better-auth/oauth-provider` at a version `>= 1.6.0, < 1.6.11`, or uses the embedded plugin in `better-auth >= 1.4.8-beta.7, < 1.6.0`, or enables the legacy `oidc-provider` or `mcp` plugins from `be…

CVE-2026-53518
GitHub-GHSA

HIGH
Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption
GHSA-392p-2q2v-4372
pkg: @better-auth/oauth-provider, better-auth
eco: npm
published: Jul 7, 2026
### Am I affected?

Users are affected if all of the following are true:

– Their project depends on `@better-auth/oauth-provider` at a version `>= 1.6.0, < 1.6.11`, or uses the embedded plugin in `better-auth >= 1.4.8-beta.7, < 1.6.0`.
– At least one OAuth client served by their application's autho…

CVE-2026-53517
NVD

HIGH
CVE-2026-13020
CVE-2026-13020
pkg: esri portal_for_arcgis, kubernetes kubernetes, linux linux_kernel

published: Jul 7, 2026

A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. ArcGIS Administrators should configure an …
CWE: CWE-640
GitHub-GHSA

HIGH
Langroid: handle_message() executes user-supplied tool JSON without sender verification
GHSA-gjgq-w2m6-wr5q
pkg: langroid
eco: pip
published: Jul 6, 2026
## Summary

A Langroid application exposing a chat interface to untrusted users may allow direct tool invocation via raw JSON payloads, even when tools are registered with `use=False, handle=True`.

## Details

`enable_message(…, use=False, handle=True)` only prevents the LLM from being instructed…

CVE-2026-54771
NVD

HIGH
CVE-2026-49297
CVE-2026-49297
pkg: apache apache-airflow-providers-google

published: Jul 6, 2026

Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object names returned by the bucket listing API directly to a destination filesystem path without normalisation or containment check. A user with write access to the source GCS bucket (ty…
CWE: CWE-22
GitHub-GHSA

HIGH
DSpace has possible Remote Code Execution (RCE) through Velocity Templates used by LDN
GHSA-9×82-rm84-c6x7
pkg: org.dspace:dspace-api, org.dspace:dspace-api, org.dspace:dspace-api
eco: maven
published: Jul 8, 2026
## Overview

Remote Code Execution (RCE) is possible via Velocity Templates used by DSpace for [COAR Notify/LDN messages](https://wiki.lyrasis.org/spaces/DSDOC9x/pages/379126679/COAR+Notify). _This vulnerability impacts DSpace versions 8.0 <= 8.3, 9.0 <= 9.2._ The attacker MUST already have DSpace a…

CVE-2026-49832
NVD

HIGH
CVE-2026-10667
CVE-2026-10667
pkg: node

published: Jul 12, 2026

Zephyr's dynamic kernel-object tracking (kernel/userspace/userspace.c, formerly kernel/userspace.c) maintains a doubly-linked list (obj_list) of dynamically allocated kernel objects. Iteration over this list in k_object_wordlist_foreach() was performed under lists_lock using the SAFE iterator (which…
CWE: CWE-416
GitHub-GHSA

HIGH
BabelDOC: Arbitrary Code Execution via CMap Pickle Deserialization in babeldoc/pdfminer/cmapdb.py
GHSA-m8gf-v64p-gfmg
pkg: BabelDOC
eco: pip
published: Jul 10, 2026
## Arbitrary Code Execution via CMap Pickle Deserialization in babeldoc/pdfminer/cmapdb.py

### Summary

BabelDOC's vendored PDF parser (`babeldoc/pdfminer/cmapdb.py`) deserializes untrusted pickle data when loading CMap files. The `_load_data()` method strips only NUL bytes from a PDF-controlled CM…

CVE-2026-54071
NVD

HIGH
CVE-2026-61437
CVE-2026-61437
pkg: python

published: Jul 10, 2026

PraisonAI (pip package praisonaiagents) before 1.6.78 contains an unsafe dynamic module loading vulnerability in AgentFlow._resolve_pydantic_class (src/praisonai-agents/praisonaiagents/workflows/workflows.py). When a workflow step uses a string output_pydantic reference, the framework locates and im…
CWE: CWE-693
NVD

HIGH
CVE-2026-22927
CVE-2026-22927
pkg: omnissa workspace_one_tunnel, microsoft windows

published: Jul 8, 2026

Omnissa Workspace ONE® Tunnel for Windows addresses a Local Privilege Escalation Vulnerability.
CWE: CWE-22
GitHub-GHSA

HIGH
Linuxfabrik Monitoring Plugins have local privilege escalation using embedded command
GHSA-798h-hpph-m24j
pkg: linuxfabrik-lib
eco: pip
published: Jul 6, 2026
### Summary
When a check plugin places user provided input inside a command which is passed to `shell_exec`, an attacker can abuse this to run arbitrary commands. This is mainly dangerous for plugins which are listed in the sudoers file, because this allows an attacker controlling the nagios user to…
CVE-2026-55426
GitHub-GHSA

HIGH
Open Babel has out-of-bounds write in MOPAC translationVectors[] (UNIT CELL TRANSLATION)
GHSA-55f6-pf8r-c2f4
pkg: openbabel
eco: pip
published: Jul 6, 2026
### Summary

A memory-safety vulnerability in Open Babel's MOPAC output parser
allowed an out-of-bounds write into the `translationVectors[]` array
when reading the "UNIT CELL TRANSLATION" block of a crafted input
file.

### Details

The MOPAC output reader stored translation vectors from the UNIT C…

CVE-2022-46292
NVD

HIGH
CVE-2026-55659
CVE-2026-55659
pkg: oauth

published: Jul 10, 2026

Grist is spreadsheet software using Python as its formula language. Prior to 1.7.15, several server-rendered Grist pages embedded user-controlled values into the page and into inline scripts without fully escaping them, allowing cross-site scripting. On the main application page, a document's name o…
CWE: CWE-79, CWE-116
GitHub-GHSA

HIGH
mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment
GHSA-g5r6-gv6m-f5jv
pkg: mcp-atlassian
eco: pip
published: Jul 10, 2026
### Summary
`confluence_upload_attachment` passes `file_path` directly to `open(file_path, "rb")` with no path validation. Any authenticated MCP client — or an AI agent manipulated via prompt injection — can read any file the server process can access and exfiltrate it to Confluence as an attach…
GitHub-GHSA

HIGH
mcp-atlassian: Arbitrary server-side file read via attachment upload
GHSA-wm45-qh3g-v83f
pkg: mcp-atlassian
eco: pip
published: Jul 10, 2026
### Summary

A client that can invoke MCP tools can read **arbitrary files from the server host** and exfiltrate them as Atlassian attachments. The attachment-upload tools take a client-supplied `file_path` and `open()` it on the **server's** filesystem.

The upload tools are meant to attach a file …

NVD

HIGH
CVE-2026-33655
CVE-2026-33655
pkg: go

published: Jul 9, 2026

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0-alpha.1, the default SSRF protection configuration did not apply IP filtering to hostnames; with ApplyIPFilterForDomain disabled by default, URL validation checked domain allow/bl…
CWE: CWE-918
NVD

HIGH
CVE-2026-59216
CVE-2026-59216
pkg: python

published: Jul 9, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call delivered execute:python and execute:tool Socket.IO events to a client-supplied session_id after checking only that the session was connected, allowing authenticated users who learne…
CWE: CWE-94, CWE-200, CWE-639, CWE-862
GitHub-GHSA

HIGH
Phantom: Arbitrary file write and decode-bomb DoS via unconfined MCP tool paths
GHSA-52vm-mxx8-f227
pkg: phantom-audio
eco: pip
published: Jul 9, 2026
### Impact

In Phantom <= 1.3.0, when `PHANTOM_OUTPUT_DIR` was unset (the default), the MCP tools accepted arbitrary absolute output paths with no confinement. Anything able to send tool calls (e.g. an AI agent driving the MCP interface) could **write or overwrite arbitrary files** the process user …

NVD

HIGH
CVE-2026-14373
CVE-2026-14373
pkg: docker

published: Jul 8, 2026

HashiCorp Nomad and Nomad Enterprise did not enforce the allow_privileged restriction for the Docker task driver's host namespace mode options. This may allow an authenticated job submitter to run a container in a host namespace and access information belonging to the host or to other workloads on t…
CWE: CWE-862
NVD

HIGH
CVE-2026-60002
CVE-2026-60002
pkg: openbsd openssh

published: Jul 8, 2026

ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)
CWE: CWE-416
GitHub-GHSA

HIGH
Goploy: Arbitrary File Read via Path Traversal in /deploy/fileDiff allows Remote Server Compromise
GHSA-4g5x-hcwm-82jw
pkg: github.com/zhenorzz/goploy
eco: go
published: Jul 7, 2026
> [ Click here to jump to the Simplified Chinese version (点击跳转到简体中文版本)](#goploy-系统任意文件读取)
# Goploy System Arbitrary File Read Vulnerability

## Basic Information
– **Vulnerability Name**: Goploy Endpoints Arbitrary File Read via Path Traversal
– **Vulnerability …

CVE-2026-53553
GitHub-GHSA

HIGH
Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp
GHSA-86j7-9j95-vpqj
pkg: better-auth, better-auth
eco: npm
published: Jul 7, 2026
### Am I affected?

Check each condition. Users are affected when all of the first three hold.

– Their application enables the `oidc-provider` plugin or the `mcp` plugin from `better-auth/plugins`. The `mcp` plugin wraps the same provider and carries the same defect. Both are on the migration path …

GitHub-GHSA

HIGH
Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin
GHSA-fmh4-wcc4-5jm3
pkg: better-auth
eco: npm
published: Jul 7, 2026
### Am I affected?

Users are affected if all of the following are true:

– Their application uses `better-auth` with the `organization` plugin (`import { organization } from "better-auth/plugins/organization"`).
– Their application enables a sign-up surface that allows arbitrary unverified email re…

CVE-2026-53514
GitHub-GHSA

HIGH
New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs
GHSA-6qcr-qxgr-m7fv
pkg: github.com/QuantumNous/new-api
eco: go
published: Jul 7, 2026
## Summary

The default SSRF protection configuration did not apply IP filtering to hostnames. With `ApplyIPFilterForDomain` disabled by default, URL validation checked domain allow/block rules but did not resolve a hostname and validate the resolved IP address. Authenticated users could configure n…

CVE-2026-33655
GitHub-GHSA

HIGH
Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps
GHSA-v54h-cp2w-9x4g
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

`coder open app` opens external workspace-app URLs without validating the scheme or host. When an external app URL contains the `$SESSION_TOKEN` placeholder the CLI replaces it with the user's real session token before handing the URL to the OS open handler.

> **Note:** Practical explo…

CVE-2026-55431
GitHub-GHSA

HIGH
OpenRemote has Cross-Realm User Information Disclosure in UserResourceImpl
GHSA-xqr9-4wvv-gvch
pkg: io.openremote:openremote-manager
eco: maven
published: Jul 6, 2026
### Summary

A realm admin of tenant B can read the profile, client roles, and realm roles of any user in any other realm (including the master realm) by supplying the target user's UUID in the REST API path. Three read endpoints in UserResourceImpl check whether the caller holds the read:admin role…

CVE-2026-54641
GitHub-GHSA

HIGH
OpenRemote has an incomplete fix for CVE-2026-40882: XXE in KNXProtocol.startAssetImport() allows arbitrary file read via unprotected XMLInputFactory
GHSA-7v6w-c3f4-9wpq
pkg: io.openremote:openremote-agent
eco: maven
published: Jul 6, 2026
### Summary
The fix for CVE-2026-40882 addressed only the Velbus asset import handler. The KNX asset import handler (`KNXProtocol`) processes user-uploaded ETS project ZIP files through Saxon XSLT and `XMLInputFactory.newInstance()` with no XXE protection, allowing any authenticated user to read arb…
CVE-2026-54640
NVD

HIGH
CVE-2026-55229
CVE-2026-55229
pkg: docker

published: Jul 10, 2026

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.34.0, Gotenberg's /forms/libreoffice/convert endpoint allows a specially crafted document to cause LibreOffice to automatically retrieve external HTTP(S) resources and local file resources during document conversion, enabling blin…
CWE: CWE-918
GitHub-GHSA

HIGH
Excelize: Unbounded Row Index Allocation in Worksheet Parser (checkSheet OOM/Panic DoS)
GHSA-h69g-9hx6-f3v4
pkg: github.com/xuri/excelize/v2
eco: go
published: Jul 10, 2026
## Unbounded Row Index Allocation in Worksheet Parser (checkSheet OOM/Panic DoS)

### Summary
The `checkSheet()` function in `github.com/xuri/excelize/v2` uses an attacker-controlled `<row r="N">` XML attribute value directly as the length argument to `make([]xlsxRow, row)` without validating it aga…

CVE-2026-54063
GitHub-GHSA

HIGH
SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894
GHSA-p4m3-mgmm-c664
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: Jul 10, 2026
## Summary
The patch for CVE-2026-41894 ("Path Traversal via Double URL Encoding") sanitized the `/export/` route but the
**identical root cause remains in the `/assets/*path` route**. In publish mode (anonymous read-only HTTP endpoint,
default port 6808), an unauthenticated remote attacker ca…
CVE-2026-54066
NVD

HIGH
CVE-2026-54063
CVE-2026-54063
pkg: go

published: Jul 10, 2026

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, the checkSheet() function in github.com/xuri/excelize/v2 uses an attacker-controlled <row r="N"> XML attribute value directly as the length argument to make([]xlsxRow, row) without validating it …
CWE: CWE-770
GitHub-GHSA

HIGH
libp2p: CPU DoS via oversized IHAVE and IWANT control message arrays
GHSA-cwc9-cp4j-mcvv
pkg: @libp2p/gossipsub
eco: npm
published: Jul 10, 2026
### Summary
gossipsub processes IHAVE and IWANT control messages by iterating every received message ID synchronously before doing anything with the results. There is no cap on how many IDs a single frame may contain. The default LP frame limit is 4MB, which fits roughly 180,000 message IDs. Iterati…
CVE-2026-49866
GitHub-GHSA

HIGH
Mistune: Potential DoS via quadratic-time parsing in parse_link_text
GHSA-qcq2-496w-v96p
pkg: mistune
eco: pip
published: Jul 9, 2026
### Summary
Mistune is vulnerable to a CPU exhaustion DoS due to superlinear (approximately O(n²)) behavior in parse_link_text. A relatively small input consisting of repeated [ characters causes significant parsing slowdown.

### Affected component
mistune/inline_parser.py → **parse_link_text**

CVE-2026-49851
NVD

HIGH
CVE-2026-54695
CVE-2026-54695
pkg: python

published: Jul 9, 2026

Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. Prior to 1.4.0, the pipecat development runner registers a /ws WebSocket endpoint for telephony testing that accepts connections without authentication, reads an attacker-supplied callSid fr…
CWE: CWE-862
NVD

HIGH
CVE-2026-13462
CVE-2026-13462
pkg: ssl

published: Jul 9, 2026

PayRange Android app, version 7.0.7 and below, contains an SSL bypass vulnerability that allows invalid certificates to be accepted in application webviews. A remote and unauthenticated attacker can steal information that the user sends.
NVD

HIGH
CVE-2026-11404
CVE-2026-11404
pkg: tls

published: Jul 9, 2026

Cesanta Mongoose before 7.22 contains an out-of-bounds read in the built-in TLS server function mg_tls_server_recv_hello(), which uses an attacker-controlled session_id_len byte from a TLS ClientHello as a buffer index without validating it against the length of received data. A remote, unauthentica…
CWE: CWE-125
GitHub-GHSA

HIGH
org.hl7.fhir.core: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint
GHSA-7cmj-v6x8-frvv
pkg: ca.uhn.hapi.fhir:org.hl7.fhir.dstu2, ca.uhn.hapi.fhir:org.hl7.fhir.dstu2016may, ca.uhn.hapi.fhir:org.hl7.fhir.dstu3
eco: maven
published: Jul 9, 2026
# Summary
All implementations of FHIRPathEngine accept arbitrary FHIRPath expressions and evaluate them without input validation. The utility intended to secure this evaluation did so incorrectly, and did not fully cover all places in which evaluation was being done. An attacker can send a resource …
CVE-2026-49485
GitHub-GHSA

HIGH
Soup Sieve: Regular Expression Denial of Service (ReDoS) via Selector Parser
GHSA-836r-79rf-4m37
pkg: soupsieve
eco: pip
published: Jul 9, 2026
### Summary

The CSS selector parser in soupsieve (the CSS selector engine for Beautiful Soup 4) contains a regular expression vulnerable to catastrophic backtracking. When processing an attribute selector with an unterminated quoted value, the `VALUE` regex pattern in `css_parser.py` enters exponen…

CVE-2026-49477
GitHub-GHSA

HIGH
Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists
GHSA-2wc2-fm75-p42x
pkg: soupsieve
eco: pip
published: Jul 9, 2026
### Summary

The CSS selector parser in soupsieve (the CSS selector engine for Beautiful Soup 4) allocates unbounded memory when compiling large comma-separated selector lists. An attacker who can supply a crafted CSS selector string to `soupsieve.compile()` or Beautiful Soup's `.select()` / `.selec…

CVE-2026-49476
GitHub-GHSA

HIGH
Micronaut doesn't set a maximum redirect count for its HTTP Client, enabling infinite loop DoS
GHSA-387m-935m-c4vw
pkg: io.micronaut:micronaut-http-client, io.micronaut:micronaut-http-client, io.micronaut:micronaut-http-client
eco: maven
published: Jul 9, 2026
The Netty-based Micronaut HTTP Client does not impose a limit on HTTP redirections, potentially allowing an infinite redirect loop that could lead to a denial-of-service attack.

### Patches

The following versions are patched:

– For Micronaut 5, versions equal or greater than [5.0.1](https://gith…

NVD

HIGH
CVE-2026-54772
CVE-2026-54772
pkg: windows

published: Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, an unauthenticated remote attacker that can reach a NetTcpBinding, NetNamedPipeBinding, or UnixDomainSocketBinding endpoint can trigger premature EOF handling in the CoreWCF net.tc…
CWE: CWE-400, CWE-835
NVD

HIGH
CVE-2026-54499
CVE-2026-54499
pkg: python

published: Jul 8, 2026

Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human languages. Prior to 1.12.2, Stanza model loaders such as stanza.models.common.pretrain.Pretrain.load() attempt torch.load(…, weights_only=True) but fall back to torch.load(…, weights_o…
CWE: CWE-502, CWE-676
NVD

HIGH
CVE-2026-15117
CVE-2026-15117
pkg: google chrome

published: Jul 8, 2026

Use after free in Payments in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-15111
CVE-2026-15111
pkg: google chrome

published: Jul 8, 2026

Use after free in Views in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-31309
CVE-2026-31309
pkg: node

published: Jul 8, 2026

Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node before v1.36.0 allows unauthenticated attackers to arbitrarily overwrite the node's configuration and achieve a full node takeover via supplying a crafted POST request.
CWE: CWE-862
NVD

HIGH
CVE-2026-49866
CVE-2026-49866
pkg: node

published: Jul 8, 2026

libp2p is a JavaScript Implementation of libp2p networking stack. Prior to 16.0.0, @libp2p/gossipsub defaultDecodeRpcLimits set maxIhaveMessageIDs and maxIwantMessageIDs to Infinity, allowing oversized IHAVE and IWANT control message arrays in message/decodeRpc.ts and gossipsub.ts to synchronously i…
CWE: CWE-770
NVD

HIGH
CVE-2026-59939
CVE-2026-59939
pkg: python

published: Jul 8, 2026

httplib2 is a comprehensive HTTP client library for Python. Prior to 0.32.0, httplib2 performs unbounded decompression of HTTP response bodies encoded with Content-Encoding: gzip or deflate in _decompressContent in httplib2/init.py, allowing a malicious or compromised HTTP server to return a small c…
CWE: CWE-409
NVD

HIGH
CVE-2026-55404
CVE-2026-55404
pkg: linux

published: Jul 8, 2026

yt-dlp and youtube-dl are command-line audio/video downloaders. Prior to 2026.7.4, the –write-link, –write-url-link, and –write-desktop-link options can write .url or .desktop shortcut files using attacker-controlled webpage_url or filename metadata without sufficient validation or escaping, allo…
CWE: CWE-74
NVD

HIGH
CVE-2026-59928
CVE-2026-59928
pkg: mistune_project mistune

published: Jul 8, 2026

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a Markdown document containing many repeated or distinct reference-link definitions causes quadratic work in src/mistune/block_parser.py and the ref_links environment dictionary handling, allowing denial of service throu…
CWE: CWE-407, CWE-1333
NVD

HIGH
CVE-2026-59925
CVE-2026-59925
pkg: mistune_project mistune

published: Jul 8, 2026

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, long sequences of well-formed double-asterisk or triple-asterisk emphasis pairs around a character cause quadratic work in src/mistune/inline_parser.py because the parser scans forward for matching close markers from eve…
CWE: CWE-407, CWE-1333, CWE-407
NVD

HIGH
CVE-2026-59922
CVE-2026-59922
pkg: mistune_project mistune

published: Jul 8, 2026

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a run of closed tilde, equals-sign, or caret marker pairs around a character causes quadratic work in src/mistune/plugins/formatting.py when the strikethrough, mark, or insert plugin scans for matching markers from each …
CWE: CWE-407, CWE-1333, CWE-407
NVD

HIGH
CVE-2026-59892
CVE-2026-59892
pkg: node

published: Jul 8, 2026

OpenTelemetry JavaScript is the OpenTelemetry JavaScript client. Prior to 2.9.0, @opentelemetry/propagator-jaeger decodes incoming uber-trace-id and uberctx-* HTTP header values with decodeURIComponent() without handling decode errors, allowing an unauthenticated remote attacker to send a malformed …
CWE: CWE-248
NVD

HIGH
CVE-2026-59874
CVE-2026-59874
pkg: isaacs tar

published: Jul 8, 2026

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeatedly parsing the same header. This issue is fixed in version 7.5.18.
CWE: CWE-835
NVD

HIGH
CVE-2026-59873
CVE-2026-59873
pkg: isaacs tar

published: Jul 8, 2026

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to exhaust disk space a…
CWE: CWE-770
NVD

HIGH
CVE-2026-10708
CVE-2026-10708
pkg: jwt

published: Jul 8, 2026

This vulnerability enables large‑scale data harvesting without requiring app‑specific secrets. A single request to a minimal leaderboard component may return user records containing emails, UUIDs, and custom fields. The combination of wildcard CORS behavior, long‑lived twenty‑day JWTs, and t…
NVD

HIGH
CVE-2026-58656
CVE-2026-58656
pkg: jwt

published: Jul 8, 2026

Grav API plugin before v1.0.0-rc.16 accepts JWT tokens via the ?token= URL query parameter and responds with Access-Control-Allow-Origin: *, allowing unauthenticated attackers to make fully authenticated cross-origin API requests from any malicious website. Attackers who obtain a leaked JWT token fr…
CWE: CWE-598
NVD

HIGH
CVE-2026-14895
CVE-2026-14895
pkg: express

published: Jul 7, 2026

String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service.

The trim and rtrim functions stripped trailing whitespace with s/\s*$//u. Because \s* matches greedily and the $ anchor fails whenever a non-whitespace character follows the whitespace, the regex e…

CWE: CWE-1333
NVD

HIGH
CVE-2026-56811
CVE-2026-56811
pkg: phoenixframework phoenix

published: Jul 7, 2026

Allocation of Resources Without Limits or Throttling vulnerability in phoenixframework phoenix (Phoenix.Socket module) allows an unauthenticated attacker to cause a denial of service against any endpoint that mounts a Phoenix socket with a reachable channel transport (WebSocket or LongPoll).

This v…

CWE: CWE-770
NVD

HIGH
CVE-2026-55574
CVE-2026-55574
pkg: vllm vllm

published: Jul 6, 2026

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, the structured_outputs.regex API parameter passes a user-supplied regular expression string directly to the grammar compiler backends with no compilation timeout; in the xgrammar backend the string…
CWE: CWE-1333
NVD

HIGH
CVE-2026-55380
CVE-2026-55380
pkg: python pillow

published: Jul 6, 2026

Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompression_bomb_check(), allowing a crafted .gd file to trigger excessive C-heap allocation when loaded. Th…
CWE: CWE-789
NVD

HIGH
CVE-2026-55379
CVE-2026-55379
pkg: python pillow

published: Jul 6, 2026

Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling Image._decompression_bomb_check(), bypassing Pillow's documented decompression bomb pro…
CWE: CWE-789
NVD

HIGH
CVE-2026-54060
CVE-2026-54060
pkg: python pillow

published: Jul 6, 2026

Pillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.new("1", (xsize, ysize)) without calling Image._decompression_bomb_check(), allowing a font to trigger excessive allocation during conversion or saving…
CWE: CWE-789
NVD

HIGH
CVE-2026-54059
CVE-2026-54059
pkg: python pillow

published: Jul 6, 2026

Pillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without calling Image._decompression_bomb_check(), allowing crafted PCF font data to cause excessive memory allocat…
CWE: CWE-789
NVD

HIGH
CVE-2026-13698
CVE-2026-13698
pkg: openvpn openvpn

published: Jul 6, 2026

A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers with a valid tls-crypt-v2 client key to potentially cause a denial of service
CWE: CWE-401, CWE-770, CWE-401
NVD

HIGH
CVE-2026-55672
CVE-2026-55672
pkg: oauth

published: Jul 10, 2026

ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's OAuth2 and OIDC CodeExchange, RefreshToken, and device token flows fail to verify that the requesting client matches the client that initiated the authorization flow, allowing intercepted grants or refresh …
CWE: CWE-287, CWE-863
NVD

HIGH
CVE-2026-54919
CVE-2026-54919
pkg: ssl

published: Jul 10, 2026

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. In affected Mbed TLS backend versions from 0.31.0 through 0.46.1 and wolfSSL backend versions from 0.33.0 through 0.46.1, when cpp-httplib is built with CPPHTTPLIB_MBEDTLS_SUPPORT or CPPHTTPLIB_WOLFSSL_SUPPORT and a cl…
CWE: CWE-295
NVD

HIGH
CVE-2026-54784
CVE-2026-54784
pkg: windows

published: Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. In version 1.9.0, CoreWCF SPNEGO SecurityContextToken negotiation can expose the proof key recovered from the RSTR when TransportWithMessageCredential with Windows client credentials and session establishme…
CWE: CWE-311, CWE-523
NVD

HIGH
CVE-2026-54783
CVE-2026-54783
pkg: windows

published: Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF WS-Security endorsing and supporting signature verification does not ensure the selected ds:Signature covers the expected Security header target, allowing an attacker with …
CWE: CWE-294, CWE-345, CWE-347
NVD

HIGH
CVE-2026-54781
CVE-2026-54781
pkg: windows

published: Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML token validation does not enforce SubjectConfirmation method URIs or holder-of-key proof keys in SamlSecurityTokenHandler, allowing holder-of-key downgrade or custom c…
CWE: CWE-287, CWE-345
NVD

HIGH
CVE-2026-54774
CVE-2026-54774
pkg: windows

published: Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, SamlSerializer skips final SignatureValue verification when a CoreWCF service validates SAML tokens using a non-X.509 signing token, allowing an attacker to reference a non-X.509 S…
CWE: CWE-345, CWE-347
NVD

HIGH
CVE-2026-55436
CVE-2026-55436
pkg: coder coder

published: Jul 8, 2026

Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and prior to versions 2.32.7, 2.33.8, and 2.34.2, the AI Bridge Proxy (`aibridgeproxyd`) created a goproxy server whose default transport set `InsecureSkipVerify: true` and only assigned…
CWE: CWE-295
NVD

HIGH
CVE-2026-55076
CVE-2026-55076
pkg: coder coder

published: Jul 7, 2026

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, Coder's OIDC callback checked `email_verified` with a direct Go `bool` type assertion. When an IdP returned the claim as a non-boolean (for example the string …
CWE: CWE-287, CWE-704
GitHub-GHSA

HIGH
Coder's AI Bridge Proxy skips TLS certificate verification in default configuration
GHSA-84rm-42xw-mx52
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

The AI Bridge Proxy (`aibridgeproxyd`) created a goproxy server whose default transport set `InsecureSkipVerify: true` and only assigned a secure transport when an upstream proxy was configured. In the default configuration (no upstream proxy), outbound HTTPS to the Coder access URL acc…

CVE-2026-55436
GitHub-GHSA

HIGH
Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass
GHSA-9r87-mvcw-x35f
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

Two flaws in Coder's OIDC login chained into account takeover: email-based user matching fell back to linking by email without checking for an existing link to a different IdP subject and the `email_verified` claim was only enforced when present as a boolean `false` so an absent or non-…

CVE-2026-55075
GitHub-GHSA

HIGH
Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking
GHSA-75vm-6w67-gwvp
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

Coder's OIDC callback checked `email_verified` with a direct Go `bool` type assertion. When an IdP returned the claim as a non-boolean (for example the string `"false"`) or omitted it, the assertion failed open and the email was treated as verified. Combined with an unconditional email-…

CVE-2026-55076
NVD

HIGH
CVE-2026-15497
CVE-2026-15497
pkg: jwt

published: Jul 12, 2026

A vulnerability was determined in SonicCloudOrg sonic-agent up to 2.7.2. This affects an unknown function of the file sonic-server-controller/src/main/java/org/cloud/sonic/controller/controller/ExchangeController.java of the component JWT Authentication Filter. This manipulation causes code injectio…
CWE: CWE-74, CWE-94
NVD

HIGH
CVE-2026-59214
CVE-2026-59214
pkg: openwebui open_webui

published: Jul 9, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, Open WebUI runs client-side Python with Pyodide in a same-origin web worker, allowing stored chat payloads that use pyodide.http.pyfetch or the js module fetch and XMLHttpRequest APIs to issue auth…
CWE: CWE-79
GitHub-GHSA

HIGH
Open WebUI vulnerable to Stored XSS via iFrame embeds in response messages
GHSA-vjm7-m4xh-7wrc
pkg: open-webui
eco: pip
published: Jul 7, 2026
### Summary
Manually modifying chat history allows setting the `embeds` property on a response message, the content of which is loaded into an iFrame with a sandbox that has `allow-scripts` and `allow-same-origin` set, ignoring the "iframe Sandbox Allow Same Origin" configuration. This enables store…
CVE-2026-26193
GitHub-GHSA

HIGH
Open WebUI vulnerable to Stored XSS via iFrame in citations model
GHSA-xc8p-9rr6-97r2
pkg: open-webui
eco: pip
published: Jul 7, 2026
### Summary
Manually modifying chat history allows setting the `html` property within document metadata. This causes the frontend to enter a code path that treats document contents as HTML, and render them in an iFrame when the citation is previewed. This allows stored XSS via a weaponised document …
CVE-2026-26192
GitHub-GHSA

HIGH
9router: Login brute-force protection bypass via spoofed X-Forwarded-For header
GHSA-7cfm-pqrj-xgq7
pkg: 9router
eco: npm
published: Jul 6, 2026
## Summary

The 9router dashboard login rate limiter derives the client identity from the attacker-controlled `X-Forwarded-For` HTTP header. When 9router is directly exposed, or deployed behind a reverse proxy that does not overwrite untrusted forwarding headers, a remote attacker can rotate the `X-…

CVE-2026-55501
GitHub-GHSA

HIGH
chmod: –preserve-root bypassed by any path that resolves to root (e.g. /../)
GHSA-4c7q-4928-8445
pkg: uu_chmod
eco: rust
published: Jul 6, 2026
`Chmoder::chmod()` only compares the literal argument against `Path::new("/")`, so the `–preserve-root` guard is bypassed by any path that *resolves* to root — a symlink to `/` or simply `/../`.

“`
if self.recursive && self.preserve_root && file == Path::new("/") {
return Err(ChmodError::Pr…

CVE-2026-35338
NVD

HIGH
CVE-2026-3576
CVE-2026-3576
pkg: curl

published: Jul 11, 2026

The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forgery leading to Local File Inclusion in all versions up to, and including, 3.0. The ulap.php file acts as an AJAX proxy and is directly accessible without WordPress bootstrapping or any authentication. …
CWE: CWE-20
NVD

HIGH
CVE-2026-59721
CVE-2026-59721
pkg: node

published: Jul 9, 2026

Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the updateInfraConfigs GraphQL mutation in admin/infra.resolver.ts accepts an attacker-controlled MAILER_SMTP_URL value, and validateSMTPUrl in utils.ts permits path, query, or fragment content that nodemailer parses into sen…
CWE: CWE-77, CWE-78, CWE-915
GitHub-GHSA

HIGH
Coder: User-admin role can reset owner account password
GHSA-29xf-69gq-m9jx
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

The `PUT /api/v2/users/{user}/password` endpoint authorized only `ActionUpdatePersonal` and did not prevent a `user-admin` from resetting an `owner` account's password. It also did not require the current password when an admin reset another user's password.

> **Note:** Exploitation re…

CVE-2026-55077
GitHub-GHSA

HIGH
SiYuan: Stored XSS in Bazaar marketplace via package README event handlers
GHSA-w7cg-whh7-xp28
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: Jul 10, 2026
## Summary

`renderPackageREADME` in `kernel/bazaar/readme.go` renders a Bazaar package README from Markdown to HTML with the lute engine and `SetSanitize(true)`. The lute sanitizer is an event-handler blocklist: `allowAttr` rejects only attribute names present in a fixed `eventAttrs` map copied fro…

CVE-2026-54070
NVD

HIGH
CVE-2026-59219
CVE-2026-59219
pkg: openwebui open_webui

published: Jul 9, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 before 0.10.0 with Redis configured, Socket.IO connect, user-join, join-channels, join-note, and the terminal websocket first-message authentication used decode_token without the Redis-backed is_valid_to…
CWE: CWE-613
NVD

HIGH
CVE-2026-47828
CVE-2026-47828
pkg: tls

published: Jul 9, 2026

During bosh create-env and bosh delete-env, the CLI uploads compiled CPI packages and rendered job templates to the new VM's DAV blobstore over HTTPS without verifying the server certificate, even though a CA certificate for that endpoint is available in the installation manifest. A network attacker…
NVD

HIGH
CVE-2026-58583
CVE-2026-58583
pkg: windows

published: Jul 7, 2026

FluxInk (formerly Sunia SPB Peripheral) Color Management Driver (TcnPeripheral64.sys) 1.0.7.2 allows local privilege escalation for a standard user account via arbitrary physical memory mapping at \Device\PhysicalMemory. Fixed in version 1.0.7.6. The fixed driver is currently available in the Window…
CWE: CWE-269
GitHub-GHSA

HIGH
mkfifo: permissions of an existing file are changed after FIFO creation fails
GHSA-pmf6-rcx4-v53v
pkg: uu_mkfifo
eco: rust
published: Jul 6, 2026
When `mkfifo()` fails (e.g. target already exists), the code shows an error but is missing a `continue;`, so it falls through to `fs::set_permissions` and changes the permissions of the pre-existing file to the default FIFO mode (`0o666` & umask -> `0644`).

“`
$ touch secret; chmod 000 secret
$ co…

CVE-2026-35341
GitHub-GHSA

HIGH
flyto-core has SSRF guard bypass via IPv6 transition addresses (IPv4-mapped / 6to4 / NAT64) in validate_url_ssrf
GHSA-794r-5rp2-fpg8
pkg: flyto-core
eco: pip
published: Jul 6, 2026
## Summary

`flyto-core`'s SSRF protection (`validate_url_ssrf` / `is_private_ip` in `src/core/utils.py`) blocks private and metadata destinations by resolving the host and testing the resulting IP for membership in a hardcoded `PRIVATE_IP_RANGES` list. That list contains only the *native* RFC 1918 …

CVE-2026-55787
NVD

HIGH
CVE-2026-59196
CVE-2026-59196
pkg: pnpm pnpm

published: Jul 6, 2026

pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted lockfile alias could be joined directly under a hoisted node_modules directory. Traversal aliases could escape that directory, while reserved aliases such as .bin or .pnpm could overwrite pnpm-owned layout. This vulnerability is fixe…
CWE: CWE-22, CWE-73
GitHub-GHSA

HIGH
Clauster: Non-loopback deployments can serve the dashboard unauthenticated when auth.enabled is unset
GHSA-h4g2-xfmw-q2c9
pkg: clauster
eco: pip
published: Jul 10, 2026
### Summary
A Clauster instance bound to a **non-loopback** address (e.g. `0.0.0.0` or a LAN IP) can serve the entire dashboard and its API **without any authentication** — even when the operator has configured a password — if `auth.enabled` is left at its default (`false`). The operator believe…
GitHub-GHSA

HIGH
Ruby CSS Parser: SSRF and Local File Disclosure in `CssParser::Parser#read_remote_file`
GHSA-9pmc-p236-855h
pkg: css_parser
eco: rubygems
published: Jul 9, 2026
## Summary

`CssParser::Parser#read_remote_file` (and therefore `load_uri!`, and the `@import`-following branch of `add_block!`) issues HTTP/HTTPS requests against any host, port and URI it is handed, with no scheme allowlist, no host / IP filtering, and no protection against link-local, loopback or…

CVE-2026-53727
GitHub-GHSA

HIGH
Note Mark: Path traversal via unsanitized book/note slug in migrate export (sibling of GHSA-g49p)
GHSA-rqrh-8wpv-x7hh
pkg: github.com/enchant97/note-mark/backend
eco: go
published: Jul 9, 2026
## Summary

Note Mark validates book and note `slug` values with the OpenAPI/huma tag `pattern:"[a-z0-9-]+"`. huma compiles this with `regexp.MustCompile(s.Pattern)` and tests it with `patternRe.MatchString(str)`, an UNANCHORED match. Because the pattern is not anchored (`^…$`), any string that me…

CVE-2026-50553
GitHub-GHSA

HIGH
ratex-parser panics on `\verb` with a multibyte delimiter (UTF-8 byte-boundary slice)
GHSA-4hgp-59h5-gvrj
pkg: ratex-parser
eco: rust
published: Jul 7, 2026
### Summary

The public parser entrypoint `ratex_parser::parse(&str)` panics on the **9-byte** input `\verbéxé` (i.e. `\verb` followed by the non-ASCII delimiter `é`). When handling a `\verb` command, the parser slices the verbatim argument with **byte** indices (`arg[1..arg.len() – 1]`); if the …

CVE-2026-53530
GitHub-GHSA

HIGH
uutils coreutils: cp/install/mv/ln –suffix alone does not enable backup mode (silent data loss vs GNU)
GHSA-fqf6-gxhh-2xhw
pkg: uucore
eco: rust
published: Jul 7, 2026
`determine_backup_mode` in `src/uucore/src/lib/features/backup_control.rs` only checks `–backup`/`-b` and returns `BackupMode::None` when only `–suffix` is given. GNU enables backup mode when `–suffix` is used alone (defaulting to existing/numbered, or `$VERSION_CONTROL`). Affects `cp`, `install`…
GitHub-GHSA

HIGH
Open WebUI vulnerable to stored XSS via unescaped markdown token in MarkdownTokens.svelte leading to full account takeover and RCE via functions
GHSA-9f4f-jv96-8766
pkg: open-webui
eco: pip
published: Jul 7, 2026
### Summary

A vulnerability in the way certain html tags in chat messages are rendered allows attackers to inject JavaScript code into a chat transcript. The JavaScript code will be executed in the user's browser every time that chat transcript is opened, allowing attackers to retrieve the user's a…

CVE-2025-46719
GitHub-GHSA

HIGH
XWiki Platform Old Core: Resource path traversal via /skin/ action endpoint in Jetty 12+
GHSA-qj4x-9g63-25g6
pkg: org.xwiki.platform:xwiki-platform-oldcore, org.xwiki.platform:xwiki-platform-oldcore
eco: maven
published: Jul 7, 2026
### Impact

With Jetty 12+ a user can craft a URL to access any resource the Jetty instance is allowed to access.

For example `http://[host]/xwiki/bin/skin/..%252f/..%252f..%252f..%252f..%252f..%252f..%252f..%252fetc/passwd` allows downloading the content of the /etc/passwd file, provided Jetty is …

CVE-2026-34151
GitHub-GHSA

HIGH
OpenRemote has Authenticated SQL Injection via Datapoint Crosstab Export
GHSA-cgfv-jrfp-2r7v
pkg: io.openremote:openremote-manager
eco: maven
published: Jul 6, 2026
## Summary

The datapoint export API builds a PostgreSQL crosstab export query by concatenating asset display names into raw SQL. An authenticated user who can create or rename an asset and then request a crosstab datapoint export can inject SQL through the asset name. The injected query output is s…

GitHub-GHSA

HIGH
Scriban: Template Writes to Arbitrary CLR Properties via `TypedObjectAccessor` (Mass Assignment + `private` / `init` / `internal` Setter Bypass)
GHSA-7jvp-hj45-2f2m
pkg: Scriban
eco: nuget
published: Jul 6, 2026
<!– obsidian –><h2 data-heading="Description">Description</h2>
<p>When a host pushes a CLR object into a Scriban <code>TemplateContext</code> via the standard, documented pattern —</p>
<pre><code class="language-csharp">var so = new ScriptObject();
so["user"] = currentUser; // direct CLR refer…
GitHub-GHSA

MEDIUM
CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation
GHSA-q6h5-q3q6-f87x
pkg: github.com/cilium/cilium, github.com/cilium/cilium, github.com/cilium/cilium
eco: go
published: Jul 6, 2026
### Impact

Users with the ability to create CiliumLocalRedirectPolicies can specify arbitrary ClusterIPs via addressMatcher, which enables hijacking traffic to Services in any namespace, bypassing the namespace-scoping guarantees enforced by serviceMatcher.

In addition, deleting such a policy can …

CVE-2026-53935
NVD

MEDIUM
CVE-2026-55689
CVE-2026-55689
pkg: jwt

published: Jul 9, 2026

OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, OpenFGA's OIDC authenticator skipped JWT audience validation when authn.method was set to oidc, authn.oidc.issuer was configured, and authn.oidc.audience was not set, allowing a token minted for an unrelated service…
CWE: CWE-287
NVD

MEDIUM
CVE-2026-59208
CVE-2026-59208
pkg: n8n n8n

published: Jul 9, 2026

n8n is an open source workflow automation platform. Prior to 2.27.4 and from 2.28.0 prior to 2.28.1, n8n instances configured with more than one trusted token-exchange issuer resolved external identities to local accounts using only the JWT sub claim and ignored the iss claim, allowing an attacker w…
CWE: CWE-287, CWE-346, CWE-346
GitHub-GHSA

MEDIUM
Micronaut: DefaultHttpClient follows redirects, forwarding Authorization, Cookie, and Proxy-Authorization headers
GHSA-q6gh-6v2r-hjv3
pkg: io.micronaut:micronaut-http-client, io.micronaut:micronaut-http-client, io.micronaut:micronaut-http-client
eco: maven
published: Jul 9, 2026
### Impact

> DefaultHttpClient follows redirects and forwards Authorization, Cookie, and Proxy-Authorization headers to redirect targets across domain boundaries. The blocklist only filters Host/Connection/TE/CT/CL.
> Additionally, no maximum redirect count exists, enabling infinite loop DoS.
> Aff…

GitHub-GHSA

MEDIUM
rm: –preserve-root bypassed via a symlink to / (string check instead of dev/inode)
GHSA-7cr3-h577-g38j
pkg: uu_rm
eco: rust
published: Jul 6, 2026
The `–preserve-root` check uses a path-string test (`path.has_root() && path.parent().is_none()`) rather than comparing device/inode. A symlink to `/` (e.g. `/tmp/rootlink -> /`) has a parent component, so it passes the check. GNU caches `/`'s dev/inode at startup and compares every traversed direc…
CVE-2026-35349
GitHub-GHSA

MEDIUM
mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)
GHSA-h444-6j9x-p8vh
pkg: uu_mv
eco: rust
published: Jul 6, 2026
When moving directories across filesystems, uutils `mv` dereferences symlinks inside the tree, copying their targets as real files/dirs instead of preserving the symlinks. GNU preserves symlinks by default. E.g. a `etc_link -> /etc` inside the source becomes a full copy of `/etc` at the destination.…
CVE-2026-35365
NVD

MEDIUM
CVE-2026-57211
CVE-2026-57211
pkg: windows

published: Jul 10, 2026

RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm_static can pass URL-encoded backslashes to erl_prim_loader:read_file_info before path validation when multiple management extension plugins are enable…
CWE: CWE-36, CWE-918
GitHub-GHSA

MEDIUM
Excon does not redact additional sensitive/risky headers when following redirects
GHSA-48rx-c7pg-q66r
pkg: excon
eco: rubygems
published: Jul 10, 2026
### Impact
The redirect follower middleware previously failed to strip a number of headers that are known to be sensitive and did not provide a way to provide a custom list of headers to strip.

_What kind of vulnerability is it? Who is impacted?_
This could cause inadvertent leakage of sensitive d…

CVE-2026-54171
GitHub-GHSA

MEDIUM
MCP Atlassian: DNS-rebinding TOCTOU bypass of the SSRF fix (CVE-2026-27826)
GHSA-489g-7rxv-6c8q
pkg: mcp-atlassian
eco: pip
published: Jul 10, 2026
### Summary
GHSA-7r34-79r5-rcc9's fix added `validate_url_for_ssrf`, which resolves the attacker-controlled `X-Atlassian-{Jira,Confluence}-Url` header host **once at middleware time** and trusts the result. But the outbound request is later built with the **raw hostname** and **re-resolves at connec…
GitHub-GHSA

MEDIUM
Avo: Direct attachment upload endpoint lacks upload authorization and bypasses field-level upload policy
GHSA-pqpw-cvm4-8mv9
pkg: avo
eco: rubygems
published: Jul 9, 2026
### Summary

Avo's direct attachment upload endpoint lacks server-side upload authorization and bypasses the documented field-level upload policy methods such as `upload_{FIELD_ID}?`.

An authenticated Avo user who can reach the Avo attachment upload endpoint can replace or add attachment content, i…

CVE-2026-53769
NVD

MEDIUM
CVE-2026-59220
CVE-2026-59220
pkg: openwebui open_webui

published: Jul 9, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.2 before 0.10.0, the SKILL_MENTION_RE and strip_re regular expressions in backend/open_webui/utils/middleware.py parsed <$skillId|label> skill mentions with overlapping quantifiers, allowing an authenticat…
CWE: CWE-1333
GitHub-GHSA

MEDIUM
Gittensory: Missing contributor-scoped access control on profile endpoint and MCP tool leaks miner financial data
GHSA-382c-vx95-w3p5
pkg: @jsonbored/gittensory-mcp
eco: npm
published: Jul 9, 2026
### Summary

`GET /v1/contributors/:login/profile` and the `gittensory_get_contributor_profile` MCP tool skip the contributor-scoped access check that every sibling endpoint enforces. Any authenticated session/API/MCP token holder can read any contributor's profile; for confirmed Gittensor miners t…

GitHub-GHSA

MEDIUM
pyLoad: Unbounded Memory Growth Leading to DoS and Potential DDoS in EventManager
GHSA-c2f9-4mc8-j656
pkg: pyload-ng
eco: pip
published: Jul 9, 2026
## Description:
The `EventManager` module in `pyload` manages a list of `Client` instances for subscribing to events. The addition of each unique `uuid` from the `get_events` API causes the creation of a `Client` instance that gets appended to the `clients` list. Although there is a `clean()` method…
CVE-2026-48987
NVD

MEDIUM
CVE-2026-54775
CVE-2026-54775
pkg: windows

published: Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, a CoreWCF service listening on a Kafka topic stops processing new records from that topic when KafkaTransportPump receives a null-value tombstone record, causing a persistent endpo…
CWE: CWE-248, CWE-754, CWE-755
NVD

MEDIUM
CVE-2026-15109
CVE-2026-15109
pkg: google chrome

published: Jul 8, 2026

Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-457
NVD

MEDIUM
CVE-2026-54777
CVE-2026-54777
pkg: windows

published: Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF NetNamedPipe transport accepts attachment to a pre-existing named pipe instance, allowing local interception of NetNamedPipe traffic when an attacker races NamedPipeListene…
CWE: CWE-367, CWE-665
GitHub-GHSA

MEDIUM
NL Portal: Missing per-user authorization on document and decision GraphQL queries in nl-portal-backend-libraries
GHSA-qpm9-h556-mwxm
pkg: nl.nl-portal:documenten-api, nl.nl-portal:besluiten
eco: maven
published: Jul 8, 2026
## Impact

In versions up to and including 3.0.0, two parts of the GraphQL API returned data without checking whether the data belonged to the logged-in user:

– **Document content.** A logged-in user could download the raw content of any document by its ID, regardless of who owned it. The resolver …

CVE-2026-49463
GitHub-GHSA

MEDIUM
Waku: Cross-Origin CSRF on RSC Server Action Dispatch
GHSA-75w3-gmqx-993q
pkg: waku
eco: npm
published: Jul 8, 2026
## Summary

Waku's RSC request dispatcher invokes server actions without validating the request's `Origin` (or `Sec-Fetch-Site`) header. A cross-origin web attacker can therefore cause a victim browser to issue an authenticated `POST` to a registered server action endpoint using a CORS-safelisted co…

CVE-2026-49455
NVD

MEDIUM
CVE-2026-15154
CVE-2026-15154
pkg: redhat openshift_ai

published: Jul 8, 2026

A flaw was found in `guardrails-detectors`, a component of Red Hat OpenShift AI. This vulnerability, known as Regular Expression Denial of Service (ReDoS), allows a remote attacker to provide specially crafted regular expressions to the public detection API. This can cause catastrophic backtracking,…
CWE: CWE-1333
NVD

MEDIUM
CVE-2026-60001
CVE-2026-60001
pkg: openbsd openssh

published: Jul 8, 2026

sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.
CWE: CWE-770
GitHub-GHSA

MEDIUM
ha-mcp: Add-on settings and policy routes are reachable without authentication at the bare root path
GHSA-q855-8rh5-jfgq
pkg: ha-mcp
eco: pip
published: Jul 7, 2026
### Summary

In add-on mode, the ha-mcp settings UI routes are mounted both under the MCP secret path **and** at the bare root of the published port (`:9583`), so Home Assistant ingress can serve the "Open Web UI" button. The root-mounted routes perform no authentication — no secret, no `Origin` c…

NVD

MEDIUM
CVE-2026-55490
CVE-2026-55490
pkg: openwrt openwrt

published: Jul 7, 2026

OpenWrt is a Linux operating system targeting embedded devices. Before v25.12.5, an integer underflow in handle_send_a() of the Emergency Access Daemon allows any unauthenticated attacker on the local network to crash the daemon by sending a single crafted UDP packet. The message length underflows b…
CWE: CWE-191
GitHub-GHSA

MEDIUM
Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpoints
GHSA-f5vp-w269-392g
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

AI Bridge provider handlers read request bodies with `io.ReadAll` without a maximum size so an authenticated user with AI Bridge access could send an arbitrarily large body and exhaust memory.

> **Note:** Exploitation requires authenticated access to the AI Bridge endpoints and the imp…

CVE-2026-55434
GitHub-GHSA

MEDIUM
Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service
GHSA-2mg2-p7r7-g27f
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

`POST /api/v2/files` converts zip uploads to tar in memory via `CreateTarFromZip`, which enforced a per-entry size limit but no aggregate limit on total decompressed output, writing to an unbounded in-memory buffer.

> **Note:** Exploitation requires authenticated file-upload access and…

CVE-2026-55078
GitHub-GHSA

MEDIUM
WeasyPrint has CSS Injection via Presentational Hints
GHSA-jhhc-3hcp-qhm5
pkg: weasyprint
eco: pip
published: Jul 6, 2026
### Summary
A CSS injection issue exists in WeasyPrint when HTML presentational hints are enabled. Unescaped attribute values are embedded into CSS, allowing injection of arbitrary CSS declarations. This affects applications processing untrusted HTML input.

### Details
File: weasyprint/css/__init__…

CVE-2026-49452
NVD

MEDIUM
CVE-2026-11321
CVE-2026-11321
pkg: express

published: Jul 10, 2026

The DataInjection plugin for GLPI 2.15.6 (GLPI 11 builds) concatenates user-supplied CSV field values directly into SQL queries during CSV import, without parameterization or escaping, resulting in authenticated SQL injection. An authenticated user with access to the Data injection feature can embed…
CWE: CWE-89
GitHub-GHSA

MEDIUM
@better-auth/oauth-provider may provide access tokens for unauthorized audiences via unbound resource indicators
GHSA-p2fr-6hmx-4528
pkg: @better-auth/oauth-provider
eco: npm
published: Jul 7, 2026
### Am I affected?

Users are affected if all of the following hold:

– Their application depends on `@better-auth/oauth-provider` on any stable `1.6.x` release (the stable line is not patched) or on a pre-release before `1.7.0-beta.4`.
– Their application either configures validAudiences` with mor…

NVD

MEDIUM
CVE-2026-12154
CVE-2026-12154
pkg: go

published: Jul 6, 2026

The Reviews Widgets for Google, Yelp & TripAdvisor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_id' shortcode attribute of the [fbrev] shortcode in versions up to and including 2.7.3. This is due to insufficient input sanitization and output escaping in the Feed_Sh…
CWE: CWE-79
NVD

MEDIUM
CVE-2026-15063
CVE-2026-15063
pkg: go

published: Jul 8, 2026

A flaw was found in the gorch service template, which is part of the trustyai-service-operator. Even when authentication is enabled, the gorch service exposes unproxied orchestrator and detector metrics ports. This allows any pod on the cluster network to directly access these ports, bypassing the k…
CWE: CWE-306
NVD

MEDIUM
CVE-2026-15044
CVE-2026-15044
pkg: go

published: Jul 8, 2026

A flaw was found in the TrustyAI Service Operator. When deploying services like gorch or NemoGuardrails, if a specific security setting is not enabled, these services can expose their communication channels without requiring users to prove their identity. This allows any other program within the clu…
GitHub-GHSA

MEDIUM
install -D: symlink race in directory creation allows arbitrary file overwrite
GHSA-gwm6-q8ch-hcfr
pkg: uu_install
eco: rust
published: Jul 6, 2026
The `-D` path runs `fs::create_dir_all` on a pathname then later opens the destination via path-based `File::create`/`fs::copy`, neither anchored to a directory fd. Between the two, an attacker can replace a path component with a symlink, redirecting the write.

**Impact:** an attacker with concurre…

CVE-2026-35356
GitHub-GHSA

MEDIUM
install: TOCTOU symlink race (unlink-then-create without O_EXCL) allows arbitrary file overwrite
GHSA-239g-2685-54×3
pkg: uu_install
eco: rust
published: Jul 6, 2026
`copy_file` in `install/src/install.rs` removes the destination then recreates it by pathname via `File::create` / `fs::copy` without `O_EXCL`/`create_new`. Between the unlink and the recreate, a local attacker with write access to the destination directory can drop in a symlink and redirect the wri…
CVE-2026-35355
NVD

MEDIUM
CVE-2026-54778
CVE-2026-54778
pkg: windows

published: Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF UnixDomainSocket POSIX peer identity resolution uses non-reentrant getpwuid and getgrgid calls, allowing concurrent connections to attribute one connection's identity to an…
CWE: CWE-362, CWE-825
NVD

MEDIUM
CVE-2026-10663
CVE-2026-10663
pkg: node

published: Jul 12, 2026

In Zephyr's experimental USB host stack (CONFIG_USB_HOST_STACK), usbh_device_disconnect() (subsys/usb/host/usbh_device.c) freed the root usb_device slab object without clearing the cached pointer ctx->root. The bus removal handler dev_removed_handler() (subsys/usb/host/usbh_core.c) decides what to t…
CWE: CWE-416
NVD

MEDIUM
CVE-2026-15128
CVE-2026-15128
pkg: google chrome

published: Jul 8, 2026

Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-79
NVD

MEDIUM
CVE-2026-15127
CVE-2026-15127
pkg: google chrome

published: Jul 8, 2026

Inappropriate implementation in WebGL in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-79
NVD

MEDIUM
CVE-2026-59929
CVE-2026-59929
pkg: mistune_project mistune

published: Jul 8, 2026

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the safe_url filter in src/mistune/renderers/html.py blocks only javascript:, vbscript:, file:, and data: schemes, allowing legacy or chained schemes such as feed:, view-source:, jar:, livescript:, mocha:, ms-its:, mk:, …
CWE: CWE-79, CWE-184
NVD

MEDIUM
CVE-2026-59926
CVE-2026-59926
pkg: mistune_project mistune

published: Jul 8, 2026

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, render_admonition() in src/mistune/directives/admonition.py concatenates the Admonition directive :class: option into the HTML class attribute without escaping, allowing attribute injection and cross-site scripting even …
CWE: CWE-79
NVD

MEDIUM
CVE-2026-59923
CVE-2026-59923
pkg: mistune_project mistune

published: Jul 8, 2026

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, HTMLRenderer.safe_url() does not block percent-encoded javascript URIs, allowing attacker-supplied Markdown links or images to bypass URL protections and execute script in rendered HTML. This issue is fixed in version 3.…
CWE: CWE-79
NVD

MEDIUM
CVE-2026-59890
CVE-2026-59890
pkg: python

published: Jul 8, 2026

setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compiled glob patterns against on-disk file names without Unicode …
CWE: CWE-176, CWE-697
GitHub-GHSA

MEDIUM
Kiwi TCMS has an Open Redirect via unvalidated next parameter in account confirmation endpoint
GHSA-hmj5-jm8h-h9fh
pkg: kiwitcms
eco: pip
published: Jul 6, 2026
### Summary

An open redirect vulnerability in the account confirmation endpoint allows an unauthenticated attacker to craft a URL hosted on a legitimate Kiwi TCMS instance that redirects victims to an arbitrary external domain. The attack surface is particularly relevant for phishing campaigns targ…

CVE-2026-54724
NVD

MEDIUM
CVE-2026-9571
CVE-2026-9571
pkg: oauth

published: Jul 13, 2026

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth refresh tokens upon user account deactivation, which allows a deactivated user or an attacker in possession of a valid refresh token to obtain new functional access tokens via the OAuth refresh token…
CWE: CWE-305
GitHub-GHSA

MEDIUM
SiYuan: Unauthenticated SQLite Data Exfiltration via Template Injection in /api/icon/getDynamicIcon
GHSA-gcm7-57gf-953c
pkg: github.com/siyuan-note/siyuan/kernel
eco: go
published: Jul 10, 2026
### Summary

The `/api/icon/getDynamicIcon` endpoint is explicitly excluded from authentication in SiYuan's kernel router (`router.go`, "不需要鉴权" — no auth needed). When called with `type=8` and a valid block `id` parameter, this endpoint invokes `RenderDynamicIconContentTemplate`, which ex…

CVE-2026-54068
GitHub-GHSA

MEDIUM
GoBGP confederation validation panics on empty AS_PATH attribute
GHSA-frrj-87jh-2772
pkg: github.com/osrg/gobgp/v4
eco: go
published: Jul 9, 2026
Found through variant analysis based on `CVE-2026-41643`

## Summary
GoBGP accepts a zero-length AS_PATH during UPDATE decoding and later panics while validating that attribute for a confederation eBGP peer. The vulnerable path is in the BGP UPDATE validator: a malformed UPDATE that should be reject…

CVE-2026-49838
GitHub-GHSA

MEDIUM
GoBGP: BGP OPEN capability parser may read capability values outside declared CapLen boundaries
GHSA-gjrg-jjr3-56cm
pkg: github.com/osrg/gobgp/v4
eco: go
published: Jul 9, 2026
### Summary
GoBGP contains a BGP OPEN capability parsing issue where several concrete capability decoders may parse data from the full remaining capability buffer instead of the slice bounded by the declared capability length, `CapLen`.
A malformed BGP OPEN message can cause bytes from a fol…
CVE-2026-49837
GitHub-GHSA

MEDIUM
sigstore-go has a multi-log threshold bypass via single compromised log
GHSA-9vcr-p3rj-q5q6
pkg: github.com/sigstore/sigstore-go
eco: go
published: Jul 9, 2026
### Impact
_What kind of vulnerability is it? Who is impacted?_

A verifier configured with WithTransparencyLog(N>1) or WithSignedCertificateTimestamps(N>1) expected defense-in-depth against the compromise of a single log instance. However, threshold counting counted verified witnesses per-entry or …

CVE-2026-49834
NVD

MEDIUM
CVE-2026-57022
CVE-2026-57022
pkg: ssl

published: Jul 9, 2026

An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX with SPC3 and SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).

When an affected device initiates a TCP conne…

CWE: CWE-754
NVD

MEDIUM
CVE-2026-54779
CVE-2026-54779
pkg: windows

published: Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML token replay protection is inoperative because DefaultTokenReplayCache.TryAdd does not reject duplicate tokens when DetectReplayedTokens is enabled, allowing a capture…
CWE: CWE-294, CWE-613
NVD

MEDIUM
CVE-2026-54773
CVE-2026-54773
pkg: windows

published: Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF WS-Security signature verification performs a document-wide ds:Signature lookup, allowing an unauthenticated remote attacker to place a SOAP header before wsse:Security and…
CWE: CWE-347
NVD

MEDIUM
CVE-2026-54590
CVE-2026-54590
pkg: python

published: Jul 8, 2026

AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Version 2.23.0 contains an incomplete fix for CVE-2026-45309 in SSHServerConfig._set_tokens that blocks /, , and .. before %u substitution in Aut…
CWE: CWE-22, CWE-639
NVD

MEDIUM
CVE-2026-58501
CVE-2026-58501
pkg: python-zeep zeep

published: Jul 8, 2026

Zeep is a Python SOAP client. From 4.0.0 before 4.3.3, Settings.forbid_external is defined but not enforced when parsing WSDL or XSD documents, allowing transitive xsd:import, xsd:include, wsdl:import, and lxml entity or DTD references to fetch attacker-chosen HTTP or HTTPS URLs. This issue is fixed…
CWE: CWE-918
NVD

MEDIUM
CVE-2026-59924
CVE-2026-59924
pkg: mistune_project mistune

published: Jul 8, 2026

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Include.parse() joins and normalizes user-supplied include paths without verifying that the result remains within the intended markdown directory, allowing crafted include paths to access files outside that directory whe…
CWE: CWE-22
NVD

MEDIUM
CVE-2026-55761
CVE-2026-55761
pkg: portainer portainer

published: Jul 8, 2026

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. In versions 2.39.0 through 2.39.3 and 2.40.0 until 2.43.0, unauthenticated restore and administrator initialization endpoin…
CWE: CWE-287
NVD

MEDIUM
CVE-2026-59999
CVE-2026-59999
pkg: openbsd openssh

published: Jul 8, 2026

In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.
CWE: CWE-348
GitHub-GHSA

MEDIUM
Weblate SSRF: outbound URL guard misses some private ranges
GHSA-vmfc-9982-2m45
pkg: weblate
eco: pip
published: Jul 7, 2026
### Impact

Weblate's `VCS_RESTRICT_PRIVATE` did not properly account for some transitional IPv6 ranges, multicast addresses, or some semi-private IPv4 ranges, which allowed some addresses to bypass private range restrictions.

### Patches

* https://github.com/WeblateOrg/weblate/pull/19768

### Res…

CVE-2026-50127
GitHub-GHSA

MEDIUM
KEDA has PostgreSQL connection string parameter injection via incomplete whitespace escaping
GHSA-6w3m-4hhp-775q
pkg: github.com/kedacore/keda/v2
eco: go
published: Jul 7, 2026
### Summary
`pkg/scalers/postgresql_scaler.go` builds libpq-style connection strings by concatenating `key=value` pairs separated by spaces. Each tenant-controllable field (`host`, `port`, `userName`, `dbName`, `sslmode`) is passed through `escapePostgreConnectionParameter`:
“`go
func escapePostgre…
CVE-2026-53572
NVD

MEDIUM
CVE-2026-54291
CVE-2026-54291
pkg: postgresql postgresql_jdbc_driver

published: Jul 6, 2026

pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections can be silently downgraded from SCRAM-SHA-256-PLUS with channel binding to plain SCRAM-SHA-256 without it, losing the man-in-the-middle protection the setting is meant to guarantee…
CWE: CWE-636, CWE-757
NVD

MEDIUM
CVE-2026-52761
CVE-2026-52761
pkg: nginx

published: Jul 10, 2026

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 through 3.0.15, the t:utf8toUnicode transformation in src/actions/transformations/utf8_to_unicode.cc produces wrong output on i386 architecture because snprintf uses sizeof on a …
CWE: CWE-467
GitHub-GHSA

MEDIUM
Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing
GHSA-5wg6-jmq2-53pw
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

Coder's subdomain-based workspace app proxy allowed the same-owner CORS check to be bypassed. When a workspace-name subdomain segment parsed as a UUID, the workspace was resolved by ID without confirming the URL's username matched the real owner, while the CORS middleware trusted the un…

CVE-2026-55438
GitHub-GHSA

MEDIUM
Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access
GHSA-5g4w-3vw9-478w
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

The workspace app proxy resolves the target app from `httpapi.RequestHost()` which prefers the `X-Forwarded-Host` header over the real `Host` header. No middleware strips `X-Forwarded-Host` before routing and the header is not browser-forbidden so client-side JavaScript can set it on `f…

CVE-2026-55430
GitHub-GHSA

MEDIUM
@aborruso/ckan-mcp-server: SSRF via base_url allows access to internal networks (Potential fix bypass of CVE-2026-33060)
GHSA-g84h-j7jj-x32p
pkg: @aborruso/ckan-mcp-server
eco: npm
published: Jul 7, 2026
### Summary
A known vulnerability CVE-2026-33060 indicated tools including ckan_package_search and sparql_query that accept a base_url parameter had the risk of making HTTP requests to arbitrary endpoints without restriction. A fix was applied to filter out ip addresses. However, a method to bypass …
CVE-2026-53509
GitHub-GHSA

MEDIUM
rm: 'rm -rf ./' (and ./// variants) silently deletes current directory contents, bypassing dot protection
GHSA-89p7-7cq3-hhr2
pkg: uu_rm
eco: rust
published: Jul 6, 2026
`rm -rf .` is correctly refused, but `clean_trailing_slashes` normalizes `.///` to `./` while `path_is_current_or_parent_directory` only matches `.`/`..` (and `/.`/`/..`), not `./` or `../`. So `rm -rf ./` recursively deletes the directory's contents and then prints a misleading `cannot remove './':…
CVE-2026-35363
GitHub-GHSA

MEDIUM
CredSweeper: Recursive archive size-limit bypass in deep scanner allows crafted compressed inputs to exhaust resources
GHSA-9mqm-qcwf-5qhg
pkg: credsweeper
eco: pip
published: Jul 10, 2026
### Summary
CredSweeper's deep scanner does not enforce `recursive_limit_size` as a hard limit. Several recursive scanners fully decompress or fully read attacker-controlled content before the remaining budget is validated, and `AbstractScanner.recursive_scan()` continues processing even when the re…
NVD

MEDIUM
CVE-2026-44918
CVE-2026-44918
pkg: node

published: Jul 10, 2026

OpenStack Ironic through before 37.0.1 allows creation or modification of nodes cross-project without authorization.
CWE: CWE-862
NVD

MEDIUM
CVE-2026-15165
CVE-2026-15165
pkg: wireshark wireshark

published: Jul 8, 2026

TLS ECH decryptor crash in Wireshark 4.6.0 to 4.6.6 allows denial of service
CWE: CWE-122
GitHub-GHSA

MEDIUM
DSpace: Path Traversal is possible through LDN message generation
GHSA-9qm4-rh6w-pq5x
pkg: org.dspace:dspace-api, org.dspace:dspace-api, org.dspace:dspace-api
eco: maven
published: Jul 8, 2026
## Overview

A path traversal vulnerability is possible via the [COAR Notify / LDN](https://wiki.lyrasis.org/spaces/DSDOC9x/pages/379126679/COAR+Notify) service in DSpace. _This vulnerability impacts DSpace versions 8.0 <= 8.3, 9.0 <= 9.2._ The attacker MUST already have DSpace administrator creden…

CVE-2026-49833
GitHub-GHSA

MEDIUM
DSpace has a possible Path Traversal Vulnerability in its Curation Task Reporter output path
GHSA-v66x-68f2-pxf5
pkg: org.dspace:dspace-api, org.dspace:dspace-api, org.dspace:dspace-api
eco: maven
published: Jul 8, 2026
## Overview

The [Curation Task](https://wiki.lyrasis.org/spaces/DSDOC9x/pages/379126845/Curation+Tasks) feature allows an output path to be used by the reporter (`-r` parameter), typically used to stream results and status of curation task operations. It is not restricted to any particular base pat…

CVE-2026-49831
NVD

MEDIUM
CVE-2026-44512
CVE-2026-44512
pkg: node

published: Jul 8, 2026

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.9.0 before 1.22.0, onnx.version_converter.convert_version() can dereference a null pointer in Upsample_6_7::adapt_upsample_6_7() in onnx/version_converter/adapters/upsample_6_7.h when processing an …
CWE: CWE-476
NVD

MEDIUM
CVE-2026-58468
CVE-2026-58468
pkg: node

published: Jul 7, 2026

NocoBase through 2.1.20 contains a server-side request forgery vulnerability in the serverRequest wrapper that allows authenticated administrators to issue arbitrary outbound HTTP requests by supplying malicious URLs to workflow request nodes, custom request action buttons, or the AI plugin. Attacke…
CWE: CWE-918
GitHub-GHSA

MEDIUM
ONNX has Null Pointer Dereference in Upsample Version Converter Adapter (Zero Inputs)
GHSA-hwpq-hmq9-wj77
pkg: onnx
eco: pip
published: Jul 7, 2026
### Summary

Null pointer dereference (SIGSEGV) in `Upsample_6_7::adapt_upsample_6_7()` (`onnx/version_converter/adapters/upsample_6_7.h:31`) when `convert_version()` processes a model with an Upsample node that has zero inputs. The adapter accesses `node->inputs()[0]->sizes()` without checking inpu…

CVE-2026-44512
NVD

MEDIUM
CVE-2026-50135
CVE-2026-50135
pkg: gohugo hugo

published: Jul 6, 2026

Hugo is a static site generator. From 0.123.0 to 0.161.1, a regression made  RootMappingFs.statRoot  use  Stat  (follows symlinks) instead of  Lstat , so a direct  resources.Get  of a symlink pointing outside its mount returned the target's contents — letting a symlink planted in a local m…
CWE: CWE-59
NVD

MEDIUM
CVE-2026-44362
CVE-2026-44362
pkg: trustedfirmware op-tee

published: Jul 6, 2026

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.20.0 and prior to version 4.11.0, a vulnerability in OP-TEE’s subkey rollback protection allows the use of revoked…
CWE: CWE-285
GitHub-GHSA

MEDIUM
kill: 'kill -1' parsed as PID -1, sending SIGTERM to all processes (system crash / DoS)
GHSA-p6rv-2qpm-fwvg
pkg: uu_kill
eco: rust
published: Jul 6, 2026
`kill -1` is incorrectly parsed as a positional `pid = -1`; combined with the default SIGTERM this calls `kill(-1, SIGTERM)`, signaling nearly every process the caller can see. GNU `kill` recognizes `-1`/`-9` as signals and reports "not enough arguments".

“`
$ kill -1 # uutils: kill(-1, SIG…

CVE-2026-35369
GitHub-GHSA

MEDIUM
chmod: recursive mode returns exit code 0 even when some files fail (last-file-wins)
GHSA-4×34-chg5-mwjj
pkg: uu_chmod
eco: rust
published: Jul 6, 2026
In `Chmoder::chmod()` the recursive branch overwrites the running result instead of accumulating it, so the exit code reflects only the *last* file processed:

“`
if self.recursive {
r = self.walk_dir_with_context(file, true); // overwrites r
} else {
r = self.chmod_file(file).and(r);
}
`…

CVE-2026-35339
NVD

MEDIUM
CVE-2026-40257
CVE-2026-40257
pkg: trustedfirmware op-tee

published: Jul 6, 2026

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.21.0 and prior to version 4.11.0, the ARM Crypto Extensions accelerated SHA-3 implementation has an off-by-one error…
CWE: CWE-787
GitHub-GHSA

MEDIUM
Rattler vulnerable to package cache path traversal via conda package build string
GHSA-h672-p7h7-97v9
pkg: rattler_cache, py_rattler
eco: pip
published: Jul 9, 2026
`rattler_cache` and `py-rattler` were vulnerable to package-cache path traversal when handling package metadata from conda channels.

During cache materialization, the `ratter_cache` code used the package record `build` string as part of a cache key that was joined into a filesystem path. A maliciou…

CVE-2026-53956
NVD

MEDIUM
CVE-2026-60120
CVE-2026-60120
pkg: vue

published: Jul 9, 2026

Bagisto before 2.4.4 contains a stored cross-site scripting vulnerability via client-side template injection that allows unauthenticated attackers to execute arbitrary JavaScript in administrator browsers by registering a customer account with malicious payload in the first or last name field. The c…
CWE: CWE-79
NVD

MEDIUM
CVE-2026-5005
CVE-2026-5005
pkg: go

published: Jul 9, 2026

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Twiser Informatics Technology Consulting, Trade and Education Inc. OKRs & Goals allows Stored XSS.

This issue affects OKRs & Goals: from 28220 before 28398.

CWE: CWE-79
NVD

MEDIUM
CVE-2026-56359
CVE-2026-56359
pkg: n8n n8n

published: Jul 8, 2026

n8n before 2.8.0 contains a cross-site scripting vulnerability in the credential management flow where authenticated users can inject malicious JavaScript URLs into OAuth2 credential Authorization URL fields. Attackers can craft malicious credentials and trick victims into clicking the OAuth authori…
CWE: CWE-79
GitHub-GHSA

MEDIUM
Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component
GHSA-7qw2-f75v-62f7
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

The `AgentLogLine` dashboard component instantiated `ansi-to-html` without `escapeXML: true` and inserted the result via `dangerouslySetInnerHTML` so HTML embedded in workspace agent log lines was rendered as live markup. Server-side sanitization did not neutralize HTML metacharacters.

CVE-2026-55437
GitHub-GHSA

MEDIUM
Suspended Coder users retain access to AI Bridge LLM proxy endpoints
GHSA-wqxv-w64v-5wh6
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

AI Bridge proxy endpoints authenticate via `Server.IsAuthorized` in `coderd/aibridgedserver`, which validates key format, expiry, secret and deleted or system users but does not check whether the account is suspended. Because suspension does not revoke existing API keys, a suspended use…

CVE-2026-55435
GitHub-GHSA

MEDIUM
Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers
GHSA-jqj2-x4c5-jfxm
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

The devcontainer recreate endpoint relied on route middleware that checked only `ActionRead` on the workspace and, unlike the sibling delete endpoint, performed no `ActionUpdate` check before triggering the destructive rebuild.

> **Note:** Exploitation requires an existing low-privileg…

CVE-2026-55433
GitHub-GHSA

MEDIUM
Coder's sub-agent app registration bypasses template port-sharing policy enforcement
GHSA-x9qq-2qh5-8rxf
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

The `CreateSubAgent` RPC did not validate a requested app sharing level against the template's `MaxPortSharingLevel` before persisting workspace apps, letting a workspace owner exceed the administrator's configured maximum.

> **Note:** Exploitation requires the ability to register sub-…

CVE-2026-55432
NVD

MEDIUM
CVE-2026-8609
CVE-2026-8609
pkg: oauth

published: Jul 10, 2026

An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service).
CWE: CWE-400, CWE-400
GitHub-GHSA

MEDIUM
morgan vulnerable to Log Forging via unneutralized control characters in :remote-user
GHSA-4vj7-5mj6-jm8m
pkg: morgan
eco: npm
published: Jul 10, 2026
### Impact

Morgan's `:remote-user` token extracts the Basic auth username from the `Authorization` header and writes it to the log stream without neutralizing control characters. An attacker can send a crafted `Authorization: Basic` header containing CR/LF characters to inject forged log lines, cor…

CVE-2026-5078
NVD

MEDIUM
CVE-2026-44342
CVE-2026-44342
pkg: oauth

published: Jul 9, 2026

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0-alpha.1, the email and WeChat account binding endpoints GET /api/oauth/email/bind and GET /api/oauth/wechat/bind used GET requests for state-changing account operations, allowing …
CWE: CWE-352
NVD

MEDIUM
CVE-2026-59817
CVE-2026-59817
pkg: node

published: Jul 9, 2026

Ghost is a Node.js content management system. From 6.27.0 before 6.44.0, Ghost's public donation checkout flow allowed an unauthenticated attacker to control donation checkout metadata and obtain full paid gift memberships for a minimal payment without exposing customer or member data or stealing mo…
CWE: CWE-472, CWE-639
GitHub-GHSA

MEDIUM
Note Mark: Unauthenticated disclosure of soft-deleted note metadata via deleted=true on public books
GHSA-588f-fvcv-xhvf
pkg: github.com/enchant97/note-mark/backend
eco: go
published: Jul 9, 2026
Summary

GET /api/books/{bookID}/notes is an unauthenticated endpoint that accepts a "deleted" query parameter. When the request is ?deleted=true, the
service runs the query with Unscoped() (bypassing GORM's soft-delete scope) but keeps the read-authorization clause as "owner_id = ? OR is_public…

CVE-2026-50554
NVD

MEDIUM
CVE-2026-9027
CVE-2026-9027
pkg: go

published: Jul 9, 2026

The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Payment Bypass via Improper Verification of Cryptographic Signature in all versions up to, and including, 2.7.4. The `corvuspay_success_handler` function registers the REST endpoint `POST /wp-json/corvuspay/success/` wit…
CWE: CWE-347
GitHub-GHSA

MEDIUM
Trapster Community: Unauthenticated malformed DNS compression pointers crash per-packet honeypot handler
GHSA-mxwc-wh95-pw4g
pkg: trapster
eco: pip
published: Jul 8, 2026
## Summary

`trapster.libs.dns.decode_labels()` decodes DNS names from attacker-supplied UDP packets and recurses **once per RFC 1035 compression pointer** with **no cycle detection and no depth bound**. A single unauthenticated UDP datagram sent to the DNS honeypot drives the function past CPython'…

NVD

MEDIUM
CVE-2026-45045
CVE-2026-45045
pkg: express

published: Jul 8, 2026

Fiber is an Express inspired web framework written in Go. Prior to 3.3.0 and 2.52.14, the BalancerForward proxy helper in middleware/proxy/proxy.go uses Header.Add() instead of Header.Set() when injecting X-Real-IP, allowing an attacker-supplied first X-Real-IP value to be forwarded to upstream serv…
CWE: CWE-290
NVD

MEDIUM
CVE-2026-44332
CVE-2026-44332
pkg: express

published: Jul 8, 2026

Fiber is an Express inspired web framework written in Go. Prior to 3.3.0, the default Authorizer function in the BasicAuth middleware in middleware/basicauth/config.go uses short-circuit evaluation that skips password hash comparison for non-existent usernames, enabling reliable remote username enum…
CWE: CWE-203
NVD

MEDIUM
CVE-2026-59927
CVE-2026-59927
pkg: mistune_project mistune

published: Jul 8, 2026

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the Include directive in src/mistune/directives/include.py detects only direct self-includes and not indirect cycles, allowing two markdown files that include each other to trigger unbounded recursion, raise RecursionErr…
CWE: CWE-674, CWE-755, CWE-674
NVD

MEDIUM
CVE-2026-59875
CVE-2026-59875
pkg: node

published: Jul 8, 2026

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.17, node-tar does not strip NUL bytes from PAX path and linkpath records in src/pax.ts, allowing a crafted archive with values to reach fs.lstat or fs.open and terminate the process with an uncaught exception. This issue is fix…
CWE: CWE-248
NVD

MEDIUM
CVE-2026-59871
CVE-2026-59871
pkg: isaacs tar

published: Jul 8, 2026

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, node-tar coerces all-digit PAX path and linkpath values in src/pax.ts to JavaScript numbers, causing downstream path handling such as normalizeWindowsPath(entry.path).split('/') to throw an uncaught TypeError. This issue is…
CWE: CWE-704
GitHub-GHSA

MEDIUM
New API is vulnerable to CSRF through user email binding
GHSA-26v7-h57m-gh9m
pkg: github.com/QuantumNous/new-api
eco: go
published: Jul 7, 2026
## Summary

The email and WeChat account binding endpoints used GET requests for state-changing account operations. In deployments where session cookies could be sent on cross-site navigations, an attacker could trigger a logged-in user's browser to bind an attacker-controlled email address or OAuth…

CVE-2026-44342
GitHub-GHSA

MEDIUM
pyLoad: SSRF guard bypass via IPv6 6to4/NAT64 transition wrappers of internal IPs
GHSA-m5x5-28jr-gpjj
pkg: pyload-ng
eco: pip
published: Jul 9, 2026
## Summary

`is_global_address` in [`src/pyload/core/utils/web/check.py`](https://github.com/pyload/pyload/blob/1b12dc7f348db8c144e0f39215680415e90ca4d2/src/pyload/core/utils/web/check.py) is the central guard against SSRF-style outbound connections in pyload-ng. It tests whether a given IP is "glob…

CVE-2026-48737
NVD

MEDIUM
CVE-2026-14362
CVE-2026-14362
pkg: node

published: Jul 8, 2026

HashiCorp memberlist before version 0.6.0 is vulnerable to a denial-of-service issue in its push/pull state handling that may allow an attacker with network access to the gossip port to exhaust memory on a receiving node and cause the process to terminate. This vulnerability (CVE-2026-14362) is fixe…
CWE: CWE-770
GitHub-GHSA

MEDIUM
Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service
GHSA-f962-qm93-mj4c
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

`NewDataBuilder` in `provisionersdk/proto/dataupload.go` allocated a byte slice using the client-supplied `FileSize` from a `DataUpload` message without an upper-bound check. Although the DRPC wire limit is 4 MiB, the `FileSize` value itself was unconstrained

### Impact

An authenticat…

CVE-2026-55079
NVD

MEDIUM
CVE-2026-53624
CVE-2026-53624
pkg: express

published: Jul 8, 2026

Fiber is an Express inspired web framework written in Go. Prior to 3.4.0, the helmet middleware in middleware/helmet/helmet.go never sets the Strict-Transport-Security response header even when HSTSMaxAge is configured because it checks c.Protocol() for https instead of c.Scheme(). This issue is fix…
CWE: CWE-319
NVD

MEDIUM
CVE-2026-59998
CVE-2026-59998
pkg: openbsd openssh

published: Jul 8, 2026

sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.
CWE: CWE-573
GitHub-GHSA

MEDIUM
GoFiber never set HSTS header in helmet middleware due to incorrect protocol check
GHSA-gv83-gqw6-9j2c
pkg: github.com/gofiber/fiber
eco: go
published: Jul 6, 2026
### Summary

The `helmet` middleware in gofiber/fiber never sets the `Strict-Transport-Security` (HSTS) response header, even when `HSTSMaxAge` is explicitly configured, because the condition check at `helmet.go:67` uses `c.Protocol()` — which returns the HTTP protocol version string (e.g., `"HTTP…

CVE-2026-53624
GitHub-GHSA

MEDIUM
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
GHSA-rqq5-2gf9-4w4q
pkg: secure_headers
eco: rubygems
published: Jul 10, 2026
## Summary

`secure_headers` builds the `Content-Security-Policy` value by stitching every configured directive together with `; ` separators. Three directive builders (`build_sandbox_list_directive`, `build_media_type_list_directive`, `build_report_to_directive`) interpolate caller-supplied strings…

CVE-2026-54163
NVD

MEDIUM
CVE-2026-46672
CVE-2026-46672
pkg: go

published: Jul 7, 2026

Actual is a local-first personal finance app. Prior to 26.6.0, @actual-app/cli ships a hand-rolled CSV serializer in packages/cli/src/output.ts used whenever the global –format csv option is passed, whose escapeCsv helper only handles RFC 4180 delimiter, quote, and newline escaping and does not neu…
CWE: CWE-1236
NVD

MEDIUM
CVE-2026-55798
CVE-2026-55798
pkg: python pillow

published: Jul 6, 2026

Pillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get_command() constructed a cmd.exe shell command by directly embedding a file path into an f-string without escaping and passed the result to subprocess.Popen(…, shell=True), allowing shell metacharacters in the file path to injec…
CWE: CWE-78
NVD

MEDIUM
CVE-2026-3367
CVE-2026-3367
pkg: oauth

published: Jul 11, 2026

The Lockme OAuth2 calendars integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'App ID' setting in all versions up to, and including, 2.11.0. This is due to insufficient input sanitization and output escaping. The register_setting() call on line 197 lacks a sanitiz…
CWE: CWE-79
NVD

MEDIUM
CVE-2026-54776
CVE-2026-54776
pkg: windows

published: Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, a CoreWCF service hosted on Unix Domain Sockets with PosixIdentity client credentials can accept connections that skip the application/unixposix stream upgrade before dispatching m…
CWE: CWE-306
GitHub-GHSA

MEDIUM
DSpace: ORE resource URI does not validate scheme for non-web resources
GHSA-c827-pw3m-67w7
pkg: org.dspace:dspace-api, org.dspace:dspace-api, org.dspace:dspace-api
eco: maven
published: Jul 8, 2026
## Overview

When ingesting an aggregated ORE resource by URI (using the [OAI-ORE Harvester](https://wiki.lyrasis.org/spaces/DSDOC9x/pages/379125906/OAI#OAI-OAI-PMH/OAI-OREHarvester(Client))), the ORE Ingestion Crosswalk does not validate the URI scheme. This may allow for local file inclusion via m…

CVE-2026-49830
GitHub-GHSA

MEDIUM
printenv: environment variables with invalid UTF-8 are silently skipped (evades inspection)
GHSA-p7h3-7q52-72w8
pkg: uu_printenv
eco: rust
published: Jul 6, 2026
The printenv utility in uutils coreutils fails to display environment variables containing invalid UTF-8 byte sequences. While POSIX permits arbitrary bytes in environment strings, the uutils implementation silently skips these entries rather than printing the raw bytes. This vulnerability allows ma…
CVE-2026-35366
GitHub-GHSA

MEDIUM
cp: -R reads device nodes as streams, destroying device semantics
GHSA-8vrf-r662-2w2v
pkg: uu_cp
eco: rust
published: Jul 6, 2026
The cp utility in uutils coreutils, when performing recursive copies (-R), incorrectly treats character and block device nodes as stream sources rather than preserving them. Because the implementation reads bytes into regular files at the destination instead of using mknod, device semantics are dest…
CVE-2026-35358
GitHub-GHSA

MEDIUM
comm: FIFO/pipe inputs are drained before comparison (data loss / hang)
GHSA-3wfc-mgpm-9rq6
pkg: uu_comm
eco: rust
published: Jul 6, 2026
The comm utility in uutils coreutils incorrectly consumes data from non-regular file inputs before performing comparison operations. The are_files_identical function opens and reads from both input paths to compare content without first verifying if the paths refer to regular files. If an input path…
CVE-2026-35347
GitHub-GHSA

MEDIUM
id: groups= computed from real GID instead of effective GID
GHSA-47c7-qrm7-mqw7
pkg: uu_id
eco: rust
published: Jul 6, 2026
The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and automated processes rely…
CVE-2026-35370
NVD

MEDIUM
CVE-2026-56240
CVE-2026-56240
pkg: express

published: Jul 11, 2026

Capgo before 12.128.12 contains a billing authorization bypass vulnerability in the plan_valid calculation that allows organizations with exhausted or expired usage credit grants to bypass billing gates. Attackers can exploit the divergence between the plugin hot-path plan_valid expression and the a…
CWE: CWE-285
NVD

MEDIUM
CVE-2026-55664
CVE-2026-55664
pkg: python

published: Jul 10, 2026

Grist is spreadsheet software using Python as its formula language. Prior to 1.7.15, the GET /forms endpoint read table and column metadata without applying the document's access rules and did not check that the requested section was actually a form. A user with only partial read access, including p…
CWE: CWE-200, CWE-285
GitHub-GHSA

MEDIUM
tarteaucitron: data-cookie attribute can be used to delete arbitrary cookies
GHSA-jxj7-g6gm-49j7
pkg: tarteaucitronjs
eco: npm
published: Jul 10, 2026
### Summary

tarteaucitron provides a list of cookies and buttons to delete them. If an attacker can write HTML with data attributes, they could create an element that silently deletes a cookie when clicked and trick a user to delete this cookie.

### Details

`tarteaucitron.cookie.purge()` is calle…

CVE-2026-49977
NVD

MEDIUM
CVE-2026-6440
CVE-2026-6440
pkg: oauth

published: Jul 10, 2026

The GoodMeet – Google Meet Integration for Webinar, Meeting & Video Conference plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.1.8. This is due to a missing nonce verification in the reset_credential() function, which handles the wp_ajax_goodmeet_…
CWE: CWE-352
NVD

MEDIUM
CVE-2026-4298
CVE-2026-4298
pkg: go

published: Jul 9, 2026

The DSGVO All in one for WP plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 4.9. This is due to the dsgvo_reset_policy_service_func() function lacking both capability checks and nonce verification while processing user-supplied parameters to reset plug…
CWE: CWE-862
NVD

MEDIUM
CVE-2026-15131
CVE-2026-15131
pkg: google chrome

published: Jul 8, 2026

Inappropriate implementation in Navigation in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-20
NVD

MEDIUM
CVE-2026-15130
CVE-2026-15130
pkg: google chrome

published: Jul 8, 2026

Insufficient policy enforcement in Navigation in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-602
NVD

MEDIUM
CVE-2026-15124
CVE-2026-15124
pkg: google chrome

published: Jul 8, 2026

Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-20
NVD

MEDIUM
CVE-2026-15108
CVE-2026-15108
pkg: google chrome

published: Jul 8, 2026

Integer overflow in Extensions API in Google Chrome prior to 150.0.7871.115 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory read via a crafted Chrome Extension. (Chromium security severity: High)
CWE: CWE-190
NVD

MEDIUM
CVE-2026-59930
CVE-2026-59930
pkg: mistune_project mistune

published: Jul 8, 2026

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the toc plugin and TableOfContents directive generate heading IDs as predictable toc_N values without slugifying the heading text, allowing attacker-controlled id="toc_N" content to collide with generated anchors and red…
CWE: CWE-345, CWE-1284
GitHub-GHSA

MEDIUM
Kite has an authenticated cluster RBAC bypass in /api/v1/overview
GHSA-gvhc-wv3v-7pf8
pkg: github.com/zxh326/kite
eco: go
published: Jul 7, 2026
## Summary

Authenticated Kite users with any role can request `/api/v1/overview` for a cluster that their roles do not permit by selecting that cluster with `x-cluster-name`. The overview route is registered before `middleware.RBACMiddleware()` and `GetOverview` only checks `len(user.Roles) > 0`, s…

CVE-2026-53487
NVD

MEDIUM
CVE-2026-46700
CVE-2026-46700
pkg: go

published: Jul 7, 2026

Actual is a local-first personal finance tool. Prior to 26.6.0, the GET /secret/:name endpoint in @actual-app/sync-server checks only that the caller has a valid session and does not verify the caller is an admin, while the sibling POST /secret/ handler enforces an admin check in OpenID mode. Any au…
CWE: CWE-285
GitHub-GHSA

MEDIUM
Open WebUI has Blind Server Side Request Forgery in its Image Edit Functionality
GHSA-jgx9-jr5x-mvpv
pkg: open-webui
eco: pip
published: Jul 7, 2026
### Summary
There is a blind server side request forgery in the functionality that allows editing an image via a prompt. The affected function will perform a GET request on the URL provided by the user. There is no restriction on the domain of the provided URL allowing the local address space to be …
CVE-2026-34225
GitHub-GHSA

MEDIUM
OpenRemote read-only asset users can write predicted datapoints
GHSA-xj53-j257-hxvg
pkg: io.openremote:openremote-manager
eco: maven
published: Jul 6, 2026
# Summary

The predicted datapoint write endpoint allows users with only `read:assets` privileges to write predicted datapoints.

The endpoint:

“`text
PUT /api/{realm}/asset/predicted/{assetId}/{attributeName}
“`

accepts write requests from users lacking `write:assets`.

The implementation appea…

CVE-2026-49439
NVD

MEDIUM
CVE-2026-56665
CVE-2026-56665
pkg: jwt

published: Jul 10, 2026

ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL is an open source identity management platform. From 3.0.0-rc.1 through 3.4.11 and from 4.0.0-rc.1 through 4.15.1, ZITADEL's external JWT Identity Provider validation in internal/idp/providers/jwt/session.go …
CWE: CWE-613
NVD

MEDIUM
CVE-2026-56664
CVE-2026-56664
pkg: jwt

published: Jul 10, 2026

ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's external JWT Identity Provider validation in internal/idp/providers/jwt/session.go skips the maximum token age freshness check when an incoming token omits the iat claim, allowing arbitrarily old tokens fro…
CWE: CWE-613
NVD

MEDIUM
CVE-2026-55669
CVE-2026-55669
pkg: jwt

published: Jul 10, 2026

ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's external JWT Identity Provider validates a token's signature and issuer (iss) but not the audience (aud) claim, allowing a validly signed token from a trusted issuer for another relying party to be accepted…
CWE: CWE-346
NVD

MEDIUM
CVE-2026-59997
CVE-2026-59997
pkg: openbsd openssh

published: Jul 8, 2026

internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.
CWE: CWE-1284
NVD

MEDIUM
CVE-2026-59996
CVE-2026-59996
pkg: openbsd openssh

published: Jul 8, 2026

scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.
CWE: CWE-23
NVD

MEDIUM
CVE-2026-59995
CVE-2026-59995
pkg: openbsd openssh

published: Jul 8, 2026

sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.
CWE: CWE-23
NVD

MEDIUM
CVE-2026-50179
CVE-2026-50179
pkg: go

published: Jul 7, 2026

Actual is a local-first personal finance tool. Prior to 26.6.0, exportToCSV and exportQueryToCSV in packages/loot-core/src/server/transactions/export/export-to-csv.ts pass user-controlled Payee, Notes, Account, and Category strings to csv-stringify with no cast callback and no formula-prefix neutral…
CWE: CWE-1236
NVD

MEDIUM
CVE-2026-56354
CVE-2026-56354
pkg: node

published: Jul 10, 2026

n8n before 1.123.24, 2.10.4, and 2.12.0 (across its 1.x and 2.x branches) contains cross-site scripting and open redirect vulnerabilities in the Form Node due to unsanitized HTML description fields and overly permissive iframe sandbox policies. Authenticated users with workflow creation permissions …
CWE: CWE-79
NVD

MEDIUM
CVE-2026-56360
CVE-2026-56360
pkg: n8n n8n

published: Jul 8, 2026

n8n before versions 1.123.18 and 2.6.2 fails to verify HMAC-SHA256 signatures on Zendesk webhooks in the ZendeskTrigger node. Attackers who know the webhook URL can send unsigned POST requests to trigger workflows with arbitrary malicious data.
CWE: CWE-290
GitHub-GHSA

MEDIUM
Windmill: Resource-scoped API tokens can read script contents outside their allowed path via scripts/list_search
GHSA-2ppx-66jv-wpw5
pkg: windmill-api
eco: rust
published: Jul 10, 2026
### Summary

A resource-scoped API token can read script contents outside its allowed path scope via `GET /api/w/{workspace}/scripts/list_search`.

This appears to be a remaining variant of the scoped-token authorization class previously addressed for other endpoints. The route-level scope middlewar…

CVE-2026-54136
GitHub-GHSA

MEDIUM
psd-tools vulnerable to arbitrary file write via smart-object filename
GHSA-2rmg-vrx8-9j2f
pkg: psd-tools
eco: pip
published: Jul 9, 2026
# psd-tools: arbitrary file write/read via smart-object path traversal

## Summary

In `psd-tools` (all releases exposing the `SmartObject` API through **v1.17.0**), `SmartObject.save()` writes an embedded smart object to a path taken verbatim from the PSD file. Because that name is attacker-control…

CVE-2026-49836
GitHub-GHSA

MEDIUM
OpenRun: Redirect URL validation bypass using  //host  paths leads to Open Redirect
GHSA-h5g6-xmh4-hc37
pkg: github.com/openrundev/openrun
eco: go
published: Jul 9, 2026
### Summary
The restrictions on redirect URLs in `openrun` can be bypassed by attackers, leading to open redirect attacks.

### Details

In the current project, the referrer header value is used for subsequent redirects, so there is currently a validation for this redirect value. The current validat…

CVE-2026-55252
GitHub-GHSA

MEDIUM
pypdf: Possible infinite loop when processing threads/articles in writer
GHSA-g9xf-7f8q-9mcj
pkg: pypdf
eco: pip
published: Jul 9, 2026
### Impact

An attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires merging a file with threads/articles into a writer.

### Patches

This has been fixed in [pypdf==6.13.1](https://github.com/py-pdf/pypdf/releases/tag/6.13.1).

### Workarounds

If users…

CVE-2026-54651
GitHub-GHSA

MEDIUM
nebula-mesh: Host revocation is not durable – blocked/offboarded hosts can regain a valid certificate
GHSA-339v-266x-79xr
pkg: github.com/forgekeep/nebula-mesh
eco: go
published: Jul 9, 2026
## Summary

Two related authorization gaps let a host that should no longer be trusted obtain a fresh, valid Nebula certificate, because nebula-mgmt does not re-evaluate revocation/authorization state at certificate *issuance* time — only at poll time.

## 1. Blocklist not enforced at sign / re-en…

CVE-2026-53602
GitHub-GHSA

MEDIUM
pymonocypher: Potential heap buffer overflow on nb_blocks in argon2i_32 when provided buffer is too small
GHSA-8f95-v3jq-cj86
pkg: pymonocypher
eco: pip
published: Jul 9, 2026
### Impact
The argon2i_32 implementation does not check the nb_blocks size. If the caller does not provide a sufficiently large buffer based on the API contract, then argon2i_32 will write past the end of the buffer and possibly corrupt the heap.

### Patches
Fixed in 4.0.2.8, which now verifies th…

CVE-2026-53720
GitHub-GHSA

MEDIUM
OneRingBuf has a Use After Free Vulnerability
GHSA-q95x-7g78-rccv
pkg: oneringbuf
eco: rust
published: Jul 8, 2026
Affected versions of `oneringbuf` exposed the obsolete `IntoRef::into_ref` method through the public `IntoRef` trait. For heap-backed ring buffers, this method returned a `DroppableRef` handle.

`DroppableRef` stored an owning raw pointer created from `Box::into_raw`. Its `Clone` implementation copi…

GitHub-GHSA

MEDIUM
async-tar PAX extension-header desync enables tar entry/content smuggling
GHSA-35rm-7j9c-2f7m
pkg: async-tar
eco: rust
published: Jul 8, 2026
## Summary

`async-tar` v0.6.0 mis-applies a buffered PAX `size` extension to an intermediary
extension header (a GNU longname `L`, a GNU longlink `K`, or a PAX `x`/`g`
header) instead of to the next *file* entry. POSIX requires a PAX extended-header
record set to describe the next file entry, never…

CVE-2026-53600
GitHub-GHSA

MEDIUM
oasdiff does not enforce –allow-external-refs=false on the git-revision load path (SSRF / local file read)
GHSA-2jcc-mxv7-p3f9
pkg: github.com/oasdiff/oasdiff
eco: go
published: Jul 7, 2026
## Summary

From **v1.13.2** through **v1.18.0**, oasdiff did not enforce `–allow-external-refs=false` (library: `openapi3.Loader.IsExternalRefsAllowed = false`) when loading a spec from a **git revision** (the `rev:path` form, e.g. `main:openapi.yaml`). External `$ref`s were resolved on that load …

CVE-2026-53508
GitHub-GHSA

MEDIUM
Flask-Security-Too: WebAuthn reauthentication freshness bypass via cross-user assertion
GHSA-f66q-9rf6-8795
pkg: Flask-Security-Too
eco: pip
published: Jul 7, 2026
### Summary

Flask-Security-Too 5.8.0 and 5.8.1 mark a session as reauthentication-fresh after processing a WebAuthn assertion whose proven credential belongs to a different user than the currently authenticated session user. The check that `GHSA-97r5-pg8x-p63p` added on the OAuth reauthentication p…

GitHub-GHSA

MEDIUM
aiosmtplib vulnerable to SMTP command injection via CR/LF in sender/recipient address
GHSA-v3q9-hj7j-63hq
pkg: aiosmtplib
eco: pip
published: Jul 7, 2026
### Summary

`aiosmtplib`'s `SMTP.mail()`, `SMTP.rcpt()`, `SMTP.vrfy()` and `SMTP.expn()` send the caller-supplied email address to the server without rejecting embedded CR/LF (`\r\n`) bytes. An address that contains a CR/LF is written verbatim onto the SMTP control connection, so the bytes after th…

CVE-2026-53533
GitHub-GHSA

MEDIUM
ratex-parser has unbounded parser recursion that leads to stack overflow (process abort)
GHSA-4w5h-hx6r-28q7
pkg: ratex-parser
eco: rust
published: Jul 7, 2026
### Summary

RaTeX’s recursive-descent parser recurses one (or more) native stack frame per nesting level at `{`, `\left`, `\sqrt{`, `^{`, etc, with **no maximum depth limit**. A short, ~10 KB input of nested groups overflows the 8 MB main-thread stack and aborts the process. With `panic = "abort…

CVE-2026-53531
GitHub-GHSA

MEDIUM
netfoil has a domain name filter bypass via multiple questions
GHSA-59qp-cfj3-rp64
pkg: github.com/tinfoil-factory/netfoil
eco: go
published: Jul 7, 2026
### Summary
Potential bypass of domain name filter by crafting a DNS request with multiple questions, with the first question being legitimate.

### Impact
Depends on a local attackers ability to craft multiple questions and the remote DoH server supporting them.

GitHub-GHSA

MEDIUM
Open WebUI allows limited stored XSS vila uploaded html file
GHSA-8gh5-qqh8-hq3x
pkg: open-webui
eco: pip
published: Jul 7, 2026
### Summary
Low privileged users can upload HTML files which contain JavaScript code via the `/api/v1/files/` backend endpoint. This endpoint returns a file id, which can be used to open the file in the browser and trigger the JavaScript code in the user's browser. Under the default settings, files …
CVE-2025-46571
GitHub-GHSA

MEDIUM
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile
GHSA-chwm-m7g7-685g
pkg: d7y.io/dragonfly/v2
eco: go
published: Jul 6, 2026
## Summary

The Dragonfly **scheduler**'s v1 gRPC service contains an unauthenticated Server-Side Request Forgery (SSRF). When a peer reports a successful download of a TINY task, the scheduler calls `Peer.DownloadTinyFile()` and issues an HTTP `GET` to a host and port taken verbatim from the attack…

CVE-2026-54637


Vulnerability Digest — July 10, 2026 · 34 Critical · 4 Exploited






Vulnerability Digest — Friday, July 10, 2026


Security Report

Friday, July 10, 2026  ·  Last 7 days  ·  Min severity: MEDIUM
Total Findings
308
Critical
34
High
140
Actively Exploited
4
CISA-KEV4
NVD178
GitHub-GHSA126
Findings sorted by severity
CISA-KEV

CRITICAL
Langflow Authorization Bypass Through User-Controlled Key Vulnerability
CVE-2026-55255
pkg: Langflow Langflow

published: Jul 7, 2026

Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Joomlack Page Builder Improper Access Control Vulnerability
CVE-2026-56290
pkg: Joomlack Page Builder

published: Jul 7, 2026

Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Adobe ColdFusion Path Traversal Vulnerability
CVE-2026-48282
pkg: Adobe ColdFusion

published: Jul 7, 2026

Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability
CVE-2026-48908
pkg: JoomShaper SP Page Builder

published: Jul 7, 2026

JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
NVD

CRITICAL
CVE-2026-54769
CVE-2026-54769
pkg: python

published: Jul 10, 2026

Langroid is a framework for building large-language-model-powered applications. Versions prior to 0.65.2 are vulnerable to a critical Sandbox Escape leading to Remote Code Execution (RCE) in its `TableChatAgent` and `VectorStore` capabilities. When these agents evaluate LLM-generated tool messages w…
CWE: CWE-94
NVD

CRITICAL
CVE-2026-59726
CVE-2026-59726
pkg: docker

published: Jul 9, 2026

Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-compose deployment exposed the MCP bridge POST /mcp and POST /mcp/:group endpoints without authentication, allowing an unauthenticated network attacker to invoke tools/call to terminal_execute, obtain a…
CWE: CWE-78, CWE-306, CWE-942
NVD

CRITICAL
CVE-2026-54782
CVE-2026-54782
pkg: windows

published: Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML 1.1 and SAML 2.0 token validation does not correctly resolve the issuer signing key or require signed tokens when IdentityConfiguration is used with federated bindings…
CWE: CWE-290, CWE-347
GitHub-GHSA

CRITICAL
Nuclio: Unsanitized cron trigger event headers/body injected into CronJob shell command leads to persistent RCE
GHSA-v5px-423j-pf7p
pkg: github.com/nuclio/nuclio
eco: go
published: Jul 8, 2026
## Summary

Nuclio controller builds a `curl` invocation string for each cron trigger and stores it as the `args` of a Kubernetes CronJob container (`/bin/sh`, `-c`, `<command>`). Two fields in the trigger specification flow into this string without adequate sanitization:

– `event.headers` keys —…

CVE-2026-52831
GitHub-GHSA

CRITICAL
9router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats
GHSA-vjc7-jrh9-9j86
pkg: 9router
eco: npm
published: Jul 6, 2026

title: Unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats
product: 9Router
version: <= 0.4.41
severity: critical
cve_request: true

## Summary

Multiple critical API security vulnerabilities were discovered in 9Router's Next.js dashboard. The `/api/providers` e…

NVD

CRITICAL
CVE-2026-57572
CVE-2026-57572
pkg: kidocode crawl4ai

published: Jul 6, 2026

Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server accepted request-supplied browser_config.extra_args, which flowed into Chromium's launch arguments. An attacker could inject Chromium switches that replace a child-process launch command together w…
CWE: CWE-88, CWE-94
GitHub-GHSA

CRITICAL
Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent
GHSA-q9p7-wqxg-mrhc
pkg: langroid
eco: pip
published: Jul 6, 2026
### Advisory Details
**Title**: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent

**Description**:
### Summary
Langroid is vulnerable to a critical Sandbox Escape leading to Remote Code Execution (RCE) in its `TableChatAgent` and `VectorStore` capabilities…

CVE-2026-54769
GitHub-GHSA

CRITICAL
9routers has Exposure of Sensitive Information and Unprotected Database Import/Export, Allowing Complete Credential Theft and Database Takeover
GHSA-qvfm-67h2-2qfx
pkg: 9router
eco: npm
published: Jul 6, 2026
## Summary

The `/api/settings/database` endpoint allows full database export (containing all credentials, API keys, OAuth tokens, and settings) and full database import (complete overwrite) without any authentication requirement beyond the `ALWAYS_PROTECTED` middleware check, which only validates J…

CVE-2026-55500
NVD

CRITICAL
CVE-2026-34038
CVE-2026-34038
pkg: docker

published: Jul 6, 2026

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, an authenticated remote command injection vulnerability in application deployment handling allows users with application write permissions to achieve remote code execution and…
CWE: CWE-78
NVD

CRITICAL
CVE-2026-13019
CVE-2026-13019
pkg: esri portal_for_arcgis, kubernetes kubernetes, linux linux_kernel

published: Jul 7, 2026

Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API.
CWE: CWE-640
NVD

CRITICAL
CVE-2026-9182
CVE-2026-9182
pkg: esri arcgis_server, linux linux_kernel, microsoft windows

published: Jul 6, 2026

Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endpoint. Successful exploitation could allow arbitrary file upload, potentially allowing for other attacks. This issue impacts all …
CWE: CWE-434
NVD

CRITICAL
CVE-2026-9181
CVE-2026-9181
pkg: esri arcgis_server, linux linux_kernel, microsoft windows

published: Jul 6, 2026

Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An unauthenticated attacker could exploit this issue by sending crafted path parameters. Successful exploitation could allow overwriting sensitive files on the system. Abuse of this issu…
CWE: CWE-22
NVD

CRITICAL
CVE-2026-53913
CVE-2026-53913
pkg: apache camel

published: Jul 6, 2026

Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulnerability in Apache Camel Keycloak Component.

The KeycloakSecurityPolicy of camel-keycloak guards a route by running KeycloakSecurityProcessor.beforeProcess(), which performs three check…

CWE: CWE-287, CWE-306, CWE-636
NVD

CRITICAL
CVE-2026-58422
CVE-2026-58422
pkg: oauth

published: Jul 3, 2026

Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts
CWE: CWE-284
NVD

CRITICAL
CVE-2026-20896
CVE-2026-20896
pkg: docker

published: Jul 3, 2026

Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled.
CWE: CWE-284
NVD

CRITICAL
CVE-2026-15113
CVE-2026-15113
pkg: google chrome, google android

published: Jul 8, 2026

Use after free in Autofill in Google Chrome on Android prior to 150.0.7871.115 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
GitHub-GHSA

CRITICAL
Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE
GHSA-xqhv-chqm-fhcc
pkg: github.com/BishopFox/joro
eco: go
published: Jul 8, 2026
# Unauthenticated Cross-Origin Plugin Upload Leads to RCE (Joro ≤ v1.1.0)

**Severity:** Critical
**CVSS v3.1:** 9.6 (AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H)
**Affected versions:** Joro ≤ v1.1.0, proxy mode (default), Linux/macOS
**Reporter:** cstover
**Date:** 2026-05-27

## Summary

Joro's d…

CVE-2026-53649
NVD

CRITICAL
CVE-2026-15062
CVE-2026-15062
pkg: python

published: Jul 8, 2026

SQL injection vulnerabilities in the Snowflake Snowpark Python SDK (snowpark-python) versions prior to 1.53.0 could allow authenticated low-privilege users to execute SQL beyond their authorization scope. An attacker could exploit these vulnerabilities by embedding SQL payloads in source database co…
CWE: CWE-89
GitHub-GHSA

CRITICAL
Goploy: Cross-namespace IDOR and RCE via body-supplied row id in project and project_file handlers
GHSA-26rh-24rg-j3vv
pkg: github.com/zhenorzz/goploy
eco: go
published: Jul 7, 2026
### Summary

`Project.AddFile`, `Project.EditFile`, `Project.RemoveFile`, and `Project.Edit` in `cmd/server/api/project/handler.go` accept a project or project-file row id from the JSON body and act on it without checking that the project belongs to the caller's namespace. The corresponding `model.P…

CVE-2026-53552
GitHub-GHSA

CRITICAL
@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints
GHSA-5rr4-8452-hf4v
pkg: @better-auth/sso
eco: npm
published: Jul 7, 2026
### Am I affected?

Users are affected if all of the following are true:

– Their application uses `@better-auth/sso` at a version `>= 0.1.0, < 1.6.11` on the stable line, or any `1.7.0-beta.x` on the pre-release line.
– The `sso()` plugin is added to their application's `betterAuth({ plugins: […]…

CVE-2026-53513
NVD

CRITICAL
CVE-2026-15378
CVE-2026-15378
pkg: kubernetes

published: Jul 10, 2026

A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind Server-Side Request Forgery (SSRF) by submitting a specially crafted XML Schema Definition (XSD) string. This can lead to unauthorized access to sensitive information, including c…
CWE: CWE-918
GitHub-GHSA

CRITICAL
Zebra: Missing copy constraint in halo2_gadgets variable-base scalar multiplication allows under-constrained base, breaking Orchard Action circuit soundness
GHSA-ww9q-8r59-xv46
pkg: zebrad, halo2_gadgets, orchard
eco: rust
published: Jul 6, 2026
### Summary

A soundness vulnerability in the variable-base scalar multiplication gadget of `halo2_gadgets` allowed a malicious prover to produce a valid proof for an Orchard Action with an *under-constrained* base point. Because this gadget enforces the diversified-address-integrity condition of th…

CVE-2026-54496
GitHub-GHSA

CRITICAL
Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access
GHSA-3fcv-jvfp-m4q9
pkg: github.com/cilium/cilium, github.com/cilium/cilium, github.com/cilium/cilium
eco: go
published: Jul 6, 2026
### Impact

When Cilium L7 functionality is enabled on a cluster, the Envoy instance supporting this functionality creates a world-accessible socket on cluster nodes. A local attacker would be able to access Envoy admin endpoints. Depending on deployment configuration, this can expose sensitive info…

CVE-2026-49445
NVD

CRITICAL
CVE-2026-58122
CVE-2026-58122
pkg: oauth

published: Jul 9, 2026

Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to circumvent local-origin IP restrictions on onboarding endpoints by supplying a spoofed X-Forwarded-For header with a loopback address. Attackers can exploit this bypass to per…
CWE: CWE-348
GitHub-GHSA

CRITICAL
Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins
GHSA-pw9m-5jxm-xr6h
pkg: better-auth
eco: npm
published: Jul 7, 2026
### Am I affected?

Users are affected if all of the following are true:

– Their application uses `better-auth` and has enabled at least one of: `oidcProvider()` (imported from `better-auth/plugins/oidc-provider`), or `mcp()` (imported from `better-auth/plugins/mcp`).
– Their application has at lea…

CVE-2026-53512
GitHub-GHSA

CRITICAL
Decompress: Archive extraction can create files and links outside of the target directory
GHSA-mp2f-45pm-3cg9
pkg: @xhmikosr/decompress, @xhmikosr/decompress, decompress
eco: npm
published: Jul 6, 2026
### Impact

When extracting an archive to a directory, a crafted archive can read or write files outside that directory. The flaw is in the code that writes the parsed entries, so it affects every format decompress handles: tar, tar.gz, tar.bz2, and zip by default, plus any others added through the …

CVE-2026-53486
NVD

CRITICAL
CVE-2026-26247
CVE-2026-26247
pkg: oauth

published: Jul 3, 2026

Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowing token exchange without the expected verifier check.
CWE: CWE-284
NVD

CRITICAL
CVE-2026-26232
CVE-2026-26232
pkg: oauth

published: Jul 3, 2026

Gitea versions before 1.25.5 do not consistently enforce OAuth2 authorization code expiry and single-use behavior during token exchange.
CWE: CWE-294
GitHub-GHSA

CRITICAL
Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditional RCE), mirroring the SQLChatAgent bug fixed in CVE-2026-25879
GHSA-2pq5-3q89-j7cc
pkg: langroid
eco: pip
published: Jul 6, 2026
Neo4jChatAgent passes LLM-generated Cypher queries straight to the Neo4j driver with no validation, no statement-type allowlist, and no opt-out gate. The query text is influenceable by prompt injection (direct user input or indirect content the agent reads back via RAG), so an attacker who can influ…
CVE-2026-55615
GitHub-GHSA

CRITICAL
Langroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema-qualified pg_read_file calls
GHSA-6xc5-4r68-67fc
pkg: langroid
eco: pip
published: Jul 6, 2026
# SQLChatAgent `_validate_query` dangerous-pattern regex is bypassable via quoted/commented/qualified function names

## Summary

The `SQLChatAgent` SQL-injection mitigation, with default `allow_dangerous_operations=False`, combines a raw-text regex blocklist (`_DANGEROUS_SQL_PATTERNS`) with a `sqlg…

CVE-2026-54760
NVD

HIGH
CVE-2026-59148
CVE-2026-59148
pkg: express

published: Jul 9, 2026

Mockoon provides way to design and run mock APIs. Prior to 9.7.0, Mockoon's admin API in commons-server/src/libs/server/admin-api.ts is mounted on the same Express listener as user-defined mock routes, enabled by default in shipped runtimes, serves Access-Control-Allow-Origin: * with write methods a…
CWE: CWE-306, CWE-352, CWE-732, CWE-942
NVD

HIGH
CVE-2026-15133
CVE-2026-15133
pkg: google chrome

published: Jul 8, 2026

Use after free in InterestGroups in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-15132
CVE-2026-15132
pkg: google chrome

published: Jul 8, 2026

Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-457
NVD

HIGH
CVE-2026-15129
CVE-2026-15129
pkg: google chrome

published: Jul 8, 2026

Use after free in Views in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-15126
CVE-2026-15126
pkg: google chrome

published: Jul 8, 2026

Use after free in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-15125
CVE-2026-15125
pkg: google chrome

published: Jul 8, 2026

Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-863
NVD

HIGH
CVE-2026-15123
CVE-2026-15123
pkg: google chrome

published: Jul 8, 2026

Inappropriate implementation in DOM in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-122
NVD

HIGH
CVE-2026-15121
CVE-2026-15121
pkg: google chrome

published: Jul 8, 2026

Use after free in WebRTC in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-15118
CVE-2026-15118
pkg: google chrome

published: Jul 8, 2026

Use after free in Input in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-15116
CVE-2026-15116
pkg: google chrome

published: Jul 8, 2026

Use after free in Actor in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-15114
CVE-2026-15114
pkg: google chrome

published: Jul 8, 2026

Out of bounds read and write in Codecs in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. (Chromium security severity: High)
CWE: CWE-125, CWE-787
NVD

HIGH
CVE-2026-15112
CVE-2026-15112
pkg: google chrome

published: Jul 8, 2026

Use after free in Ozone in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-15110
CVE-2026-15110
pkg: google chrome

published: Jul 8, 2026

Use after free in Extensions in Google Chrome prior to 150.0.7871.115 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-15107
CVE-2026-15107
pkg: google chrome

published: Jul 8, 2026

Use after free in IndexedDB in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-416
NVD

HIGH
CVE-2026-59257
CVE-2026-59257
pkg: n8n n8n

published: Jul 8, 2026

n8n before 1.123.61, 2.x before 2.27.4, and 2.28.x before 2.28.1 contains a SQL injection vulnerability in the legacy MySQL v1 node's executeQuery operation. The operation substitutes evaluated {{ … }} expression values directly into the raw SQL string without parameterization. When a workflow use…
CWE: CWE-89
NVD

HIGH
CVE-2026-34158
CVE-2026-34158
pkg: docker

published: Jul 7, 2026

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, the executeInDocker() helper wraps user-controlled commands in single quotes without escaping embedded single quotes. Attackers who can edit application settings can inject a …
CWE: CWE-78
NVD

HIGH
CVE-2026-34168
CVE-2026-34168
pkg: docker

published: Jul 7, 2026

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the LocalPersistentVolume.name field is interpolated directly into docker volume shell commands without shell argument escaping, allowing an authenticated user to set a storag…
CWE: CWE-78
NVD

HIGH
CVE-2026-42204
CVE-2026-42204
pkg: docker

published: Jul 6, 2026

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. From 4.0.0-beta.471 through 4.0.0-beta.473, a regression in SHELL_SAFE_COMMAND_PATTERN allowed ampersands in custom Docker Compose build, start, and pre/post-deployment command fields, allowing an aut…
CWE: CWE-78
NVD

HIGH
CVE-2026-34599
CVE-2026-34599
pkg: docker

published: Jul 6, 2026

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, there is an authenticated command injection vulnerability in the GetLogs Livewire component which allows users with team membership (lowest privilege member role) to execute a…
CWE: CWE-78
NVD

HIGH
CVE-2026-14535
CVE-2026-14535
pkg: node

published: Jul 4, 2026

In Trail of Bits fickling versions up to and including 0.1.11, the UnsafeImportsML analysis pass unconditionally calls AnalysisContext.shorten_code(node) on every import node it inspects, regardless of whether the import is flagged as unsafe. This call registers the shortened code representation in …
CWE: CWE-693
NVD

HIGH
CVE-2026-14534
CVE-2026-14534
pkg: python

published: Jul 4, 2026

Trail of Bits fickling versions up to and including 0.1.10 do not include the Python standard library modules _posixsubprocess, site, and atexit in the UNSAFE_IMPORTS denylist (fickle.py). Because these modules are absent from the denylist, fickling's check_safety() function returns LIKELY_SAFE with…
CWE: CWE-184, CWE-502
NVD

HIGH
CVE-2025-71380
CVE-2025-71380
pkg: node

published: Jul 4, 2026

The Execute Command node in n8n allows authenticated users to execute arbitrary commands on the host system where n8n runs. Attackers with user access or compromised credentials can exploit this node to run malicious commands, potentially leading to data exfiltration, service disruption, or complete…
CWE: CWE-284
GitHub-GHSA

HIGH
Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding — chunked / HTTP/2 requests
GHSA-659f-rgp5-w4wf
pkg: github.com/zalando/skipper
eco: go
published: Jul 8, 2026
### Summary

`zalando/skipper`'s OpenPolicyAgent integration silently bypasses request-body
inspection on HTTP/1.1 `Transfer-Encoding: chunked` and HTTP/2 requests that
omit the `content-length` pseudo-header. When the
`opaAuthorizeRequestWithBody` filter is configured, the
`OpenPolicyAgentInstance.…

CVE-2026-50197
NVD

HIGH
CVE-2026-14891
CVE-2026-14891
pkg: docker

published: Jul 8, 2026

HashiCorp Nomad and Nomad Enterprise are vulnerable to a sandbox escape in the Docker task driver that may allow a job submitter to bind-mount a host path into a container even when volume bind mounts are disabled, potentially leading to reading and writing files on the host. This vulnerability, CVE…
CWE: CWE-59
GitHub-GHSA

HIGH
Better Auth has insecure cryptographic defaults in oidcProvider: alg=none advertised and plain PKCE accepted by default
GHSA-9h47-pqcx-hjr4
pkg: better-auth
eco: npm
published: Jul 7, 2026
### Am I affected?

Users are affected if all of the following are true:

– Their application uses `better-auth` at a version below the patched release.
– Their application enables `oidcProvider()` from `better-auth/plugins/oidc-provider` or `mcp()` from `better-auth/plugins/mcp` (the mcp plugin del…

GitHub-GHSA

HIGH
Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID
GHSA-9rjw-3gwp-f59v
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

`UpsertWorkspaceApp` overwrites an existing app's `agent_id` on a primary-key conflict and `insertAgentApp` accepts the app ID from the provisioner's `CompleteJob` payload without verifying it belongs to the workspace being built. `CompleteJob` runs under `dbauthz.AsProvisionerd` so the…

CVE-2026-55429
NVD

HIGH
CVE-2026-57573
CVE-2026-57573
pkg: kidocode crawl4ai

published: Jul 6, 2026

Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server applied its SSRF destination check on the non-streaming /crawl path but not on the streaming path. handle_stream_crawl_request passed seed URLs straight to the crawler with no destination validatio…
CWE: CWE-918
NVD

HIGH
CVE-2026-54765
CVE-2026-54765
pkg: traefik traefik

published: Jul 6, 2026

Traefik is an open source HTTP reverse proxy and load balancer. From v3.7.0 prior to v3.7.6, Traefik's Kubernetes Gateway API provider may resolve two accepted HTTPRoutes that target the same backend Service:port but configure different backendRef filters to the same child service and apply only one…
CWE: CWE-284, CWE-863
GitHub-GHSA

HIGH
flyto-core has Unauthenticated Command Execution via HTTP MCP `execute_module`
GHSA-h9f9-h6gm-wc85
pkg: flyto-core
eco: pip
published: Jul 6, 2026
## Unauthenticated Command Execution via HTTP MCP `execute_module`

### Summary

The HTTP MCP endpoint (`POST /mcp`) in flyto-core accepts unauthenticated JSON-RPC `tools/call` requests and dispatches them to arbitrary registered modules, including `sandbox.execute_shell`, which passes attacker-cont…

CVE-2026-55786
NVD

HIGH
CVE-2026-54424
CVE-2026-54424
pkg: windows

published: Jul 4, 2026

An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege. This issue affects Parsec through v2026-05-04.0. The patched version is Parsec for Windows version 150-104a. A user can generate a situation where there is an instance of …
CWE: CWE-648
NVD

HIGH
CVE-2026-47829
CVE-2026-47829
pkg: openssh

published: Jul 9, 2026

Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-spawned ssh process when an operator runs bosh ssh -c, bosh logs -f, or other non-interactive SSH paths, leading to local command execution on the operator's workstation.
Affected v…
NVD

HIGH
CVE-2026-15122
CVE-2026-15122
pkg: google chrome, microsoft windows

published: Jul 8, 2026

Insufficient validation of untrusted input in Codecs in Google Chrome on Windows prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-20
NVD

HIGH
CVE-2026-15120
CVE-2026-15120
pkg: google chrome, microsoft windows

published: Jul 8, 2026

Use after free in Core in Google Chrome on Windows prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-15119
CVE-2026-15119
pkg: google chrome

published: Jul 8, 2026

Race in GetUserMedia in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-362
NVD

HIGH
CVE-2026-55830
CVE-2026-55830
pkg: python

published: Jul 8, 2026

RestrictedPython is a tool that helps to define a subset of the Python language which allows to provide a program input into a trusted environment. Prior to 8.3, check_function_argument_names() rejected protected guard hook names for regular, variadic, and keyword-only arguments but omitted position…
CWE: CWE-184
GitHub-GHSA

HIGH
Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE
GHSA-37h2-6p4f-mp3q
pkg: serena-agent
eco: pip
published: Jul 8, 2026
### Summary

Serena's built-in web dashboard exposes an unauthenticated Flask API on a fixed, predictable port (TCP 24282, hardcoded as `0x5EDA` in `constants.py`). The server has no authentication, no CSRF protection, and no Host header validation. A DNS rebinding attack allows a malicious webpage …

CVE-2026-49471
GitHub-GHSA

HIGH
@better-auth/scim: Account/provider takeover via missing owner binding on non-org SCIM providers
GHSA-j8v8-g9cx-5qf4
pkg: @better-auth/scim
eco: npm
published: Jul 7, 2026
### Am I affected?

Users are affected if all of these hold:

– They install and register the `@better-auth/scim` plugin (`plugins: [scim()]`).
– They create SCIM providers without an `organizationId`, that is, non-organization ("personal") providers. Organization-scoped providers are not affected b…

GitHub-GHSA

HIGH
Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email
GHSA-g38m-r43w-p2q7
pkg: better-auth
eco: npm
published: Jul 7, 2026
### Am I affected?

Users are affected if all of the following are true:

– Their application uses `better-auth` at a version `< 1.6.11` on the stable line, or any current `next` pre-release.
– `emailAndPassword.enabled: true` is set in their application's `betterAuth({ … })` configuration.
– At l…

CVE-2026-53516
GitHub-GHSA

HIGH
Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write
GHSA-qrwj-vh9x-gw5v
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

`agentConn.apiClient()` used the default redirect behavior of `http.Client` while its custom transport dialed the host from the request URL as long as the port was the workspace agent HTTP API port (`4`). Agent tailnet IPs are deterministic from agent UUIDs, so a malicious workspace age…

GitHub-GHSA

HIGH
Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`
GHSA-mcqq-fqgf-rxwm
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

`coder config-ssh` wrote server-supplied SSH settings (`HostnameSuffix`, `SSHConfigOptions`) into the user's `~/.ssh/config` without sanitizing embedded newlines or restricting directives so a malicious or compromised Coder server could inject arbitrary SSH configuration.

> **Note:** P…

CVE-2026-55427
NVD

HIGH
CVE-2026-54423
CVE-2026-54423
pkg: node

published: Jul 10, 2026

In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI commands to a node, bypassing Ironic's access control.
CWE: CWE-424
GitHub-GHSA

HIGH
`lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes
GHSA-4jhm-jv67-739f
pkg: lxml_html_clean
eco: pip
published: Jul 8, 2026
# `lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes (`xlink:href`)

**Reporter:** Guillem Lefait <guillem@datamq.com> · **Date:** 2026-05-10
**Affected:** `lxml` ≤ 6.1.0 and `lxml_html_clean` ≤ 0.4.4 (latest stable)
**Confirmed against:** lxml 6.1.0 + lx…

CVE-2026-49825
GitHub-GHSA

HIGH
Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator
GHSA-wrq8-fcv5-8hvp
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

The tailnet coordinator validates that an agent's `Addresses` derive from its authenticated UUID but applies no equivalent check to `AllowedIPs`. The coordinator forwards agent-supplied `AllowedIPs` verbatim to tunnel peers which install them into the WireGuard peer configuration.

### …

CVE-2026-55428
NVD

HIGH
CVE-2026-59195
CVE-2026-59195
pkg: pnpm pnpm

published: Jul 6, 2026

pnpm is a package manager. Prior to 10.34.4 and 11.8.0, pnpm accepts package names from the env lockfile configDependencies section and uses those names directly when creating config dependency symlinks under node_modules/.pnpm-config. A malicious repository can commit a crafted pnpm-lock.yaml whose…
CWE: CWE-22
NVD

HIGH
CVE-2026-46591
CVE-2026-46591
pkg: apache camel

published: Jul 6, 2026

Improper Neutralization of Special Elements in Data Query Logic vulnerability in Apache Camel Neo4J component.

The camel-neo4j producer builds the Cypher WHERE clause for its match/retrieve and delete operations from the CamelNeo4jMatchProperties map. CVE-2025-66169 addressed Cypher injection throu…

CWE: CWE-943
NVD

HIGH
CVE-2026-12597
CVE-2026-12597
pkg: oauth

published: Jul 10, 2026

The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via the GitHub OAuth callback in versions up to, and including, 6.2.3. The vulnerability exists in the loginpress_on_github_login() function, which blindly trusts the first element (profile[0]['email']) of the array retur…
CWE: CWE-287
NVD

HIGH
CVE-2026-12595
CVE-2026-12595
pkg: oauth

published: Jul 10, 2026

The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via Unverified OAuth Email in all versions up to and including 6.2.3. The vulnerability exists in the loginpress_on_discord_login() Discord OAuth callback handler, which accepts the email field returned by Discord's /user…
CWE: CWE-287
NVD

HIGH
CVE-2026-31985
CVE-2026-31985
pkg: tls

published: Jul 9, 2026

When the upstream Guardian or CMC was configured in the Remote Collector via n2os-tui, the generated configuration disabled TLS certificate verification, and no option was provided to enable it. A malicious actor could perform a man-in-the-middle attack and intercept the communication between the Re…
CWE: CWE-671
NVD

HIGH
CVE-2026-54591
CVE-2026-54591
pkg: python

published: Jul 8, 2026

AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Prior to 2.23.1, a malicious SSH server can write arbitrary files on the asyncssh SCP client's filesystem by sending filenames containing ../ tra…
CWE: CWE-22
GitHub-GHSA

HIGH
NL Portal: IDOR allows any authenticated user to complete and tamper with another user's taak
GHSA-6h3c-r723-7fx3
pkg: nl.nl-portal:taak
eco: maven
published: Jul 8, 2026
## Impact

In versions from 1.5.0 up to and including 3.0.0, any authenticated portal user could complete and tamper with another user's open task by submitting it on their behalf. The task submission endpoint accepted a task ID and a payload, but it never checked whether the task actually belonged …

CVE-2026-49464
NVD

HIGH
CVE-2026-54652
CVE-2026-54652
pkg: nginx

published: Jul 8, 2026

Frigate is an open source network video recorder. In version 0.17.1, the GET /api/logs/{service} endpoint allows any authenticated user including the viewer role to download Frigate and nginx logs, exposing auto-generated admin passwords and camera credentials logged in request query strings and ena…
CWE: CWE-269, CWE-532, CWE-598, CWE-863
GitHub-GHSA

HIGH
@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive
GHSA-7w99-5wm4-3g79
pkg: @better-auth/oauth-provider, better-auth
eco: npm
published: Jul 7, 2026
### Am I affected?

Users are affected if all of the following are true:

– Their project depends on `@better-auth/oauth-provider` at a version `>= 1.6.0, < 1.6.11`, or uses the embedded plugin in `better-auth >= 1.4.8-beta.7, < 1.6.0`, or enables the legacy `oidc-provider` or `mcp` plugins from `be…

CVE-2026-53518
GitHub-GHSA

HIGH
Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption
GHSA-392p-2q2v-4372
pkg: @better-auth/oauth-provider, better-auth
eco: npm
published: Jul 7, 2026
### Am I affected?

Users are affected if all of the following are true:

– Their project depends on `@better-auth/oauth-provider` at a version `>= 1.6.0, < 1.6.11`, or uses the embedded plugin in `better-auth >= 1.4.8-beta.7, < 1.6.0`.
– At least one OAuth client served by their application's autho…

CVE-2026-53517
NVD

HIGH
CVE-2026-13020
CVE-2026-13020
pkg: esri portal_for_arcgis, kubernetes kubernetes, linux linux_kernel

published: Jul 7, 2026

A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. ArcGIS Administrators should configure an …
CWE: CWE-640
GitHub-GHSA

HIGH
Langroid: handle_message() executes user-supplied tool JSON without sender verification
GHSA-gjgq-w2m6-wr5q
pkg: langroid
eco: pip
published: Jul 6, 2026
## Summary

A Langroid application exposing a chat interface to untrusted users may allow direct tool invocation via raw JSON payloads, even when tools are registered with `use=False, handle=True`.

## Details

`enable_message(…, use=False, handle=True)` only prevents the LLM from being instructed…

CVE-2026-54771
NVD

HIGH
CVE-2026-49297
CVE-2026-49297
pkg: apache apache-airflow-providers-google

published: Jul 6, 2026

Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object names returned by the bucket listing API directly to a destination filesystem path without normalisation or containment check. A user with write access to the source GCS bucket (ty…
CWE: CWE-22
NVD

HIGH
CVE-2026-43865
CVE-2026-43865
pkg: apache camel

published: Jul 6, 2026

Deserialization of Untrusted Data vulnerability in Apache Camel Hazelcast component.

The camel-hazelcast component creates and manages Hazelcast instances using a default configuration that applies no Java deserialization filter. When Camel builds the Hazelcast Config itself – that is, when no user…

CWE: CWE-502
NVD

HIGH
CVE-2026-40859
CVE-2026-40859
pkg: apache camel

published: Jul 6, 2026

Deserialization of Untrusted Data vulnerability in Apache Camel.

The camel-vertx-http component deserializes HTTP response bodies carrying the Content-Type application/x-java-serialized-object using a raw java.io.ObjectInputStream, without applying any ObjectInputFilter (VertxHttpHelper.deserialize…

CWE: CWE-502
NVD

HIGH
CVE-2026-12746
CVE-2026-12746
pkg: oauth

published: Jul 4, 2026

Dancer2::Plugin::Auth::OAuth::Provider versions before 0.23 for Perl do not support the OAuth 2.0 state parameter.

The authentication_url method builds the provider authorization redirect without issuing a state value, and the callback method exchanges the callback code and registers the resulting …

CWE: CWE-352
NVD

HIGH
CVE-2026-12740
CVE-2026-12740
pkg: oauth

published: Jul 4, 2026

Plack::Middleware::OAuth versions through 0.10 for Perl do not support the OAuth 2.0 state parameter.

RequestTokenV2 builds the provider authorization redirect without issuing a state value, and AccessTokenV2 exchanges the callback code and registers the resulting token into the session (register_s…

CWE: CWE-352
NVD

HIGH
CVE-2025-71372
CVE-2025-71372
pkg: python

published: Jul 4, 2026

Picklescan before 0.0.33 fails to detect the numpy.f2py.crackfortran.getlincoef gadget in pickle __reduce__ methods, allowing arbitrary code execution. Attackers can craft malicious pickle files that execute arbitrary Python code when loaded, bypassing Picklescan's safety checks and enabling supply-…
CWE: CWE-502
NVD

HIGH
CVE-2026-28699
CVE-2026-28699
pkg: oauth

published: Jul 3, 2026

Gitea versions up to and including 1.26.1 allow OAuth2 access token scope enforcement to be bypassed through HTTP Basic authentication.
CWE: CWE-284, CWE-863
GitHub-GHSA

HIGH
DSpace has possible Remote Code Execution (RCE) through Velocity Templates used by LDN
GHSA-9×82-rm84-c6x7
pkg: org.dspace:dspace-api, org.dspace:dspace-api, org.dspace:dspace-api
eco: maven
published: Jul 8, 2026
## Overview

Remote Code Execution (RCE) is possible via Velocity Templates used by DSpace for [COAR Notify/LDN messages](https://wiki.lyrasis.org/spaces/DSDOC9x/pages/379126679/COAR+Notify). _This vulnerability impacts DSpace versions 8.0 <= 8.3, 9.0 <= 9.2._ The attacker MUST already have DSpace a…

CVE-2026-49832
NVD

HIGH
CVE-2026-22927
CVE-2026-22927
pkg: windows

published: Jul 8, 2026

Omnissa Workspace ONE® Tunnel for Windows addresses a Local Privilege Escalation Vulnerability.
CWE: CWE-22
GitHub-GHSA

HIGH
Linuxfabrik Monitoring Plugins have local privilege escalation using embedded command
GHSA-798h-hpph-m24j
pkg: linuxfabrik-lib
eco: pip
published: Jul 6, 2026
### Summary
When a check plugin places user provided input inside a command which is passed to `shell_exec`, an attacker can abuse this to run arbitrary commands. This is mainly dangerous for plugins which are listed in the sudoers file, because this allows an attacker controlling the nagios user to…
CVE-2026-55426
GitHub-GHSA

HIGH
Open Babel has out-of-bounds write in MOPAC translationVectors[] (UNIT CELL TRANSLATION)
GHSA-55f6-pf8r-c2f4
pkg: openbabel
eco: pip
published: Jul 6, 2026
### Summary

A memory-safety vulnerability in Open Babel's MOPAC output parser
allowed an out-of-bounds write into the `translationVectors[]` array
when reading the "UNIT CELL TRANSLATION" block of a crafted input
file.

### Details

The MOPAC output reader stored translation vectors from the UNIT C…

CVE-2022-46292
NVD

HIGH
CVE-2026-33655
CVE-2026-33655
pkg: go

published: Jul 9, 2026

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0-alpha.1, the default SSRF protection configuration did not apply IP filtering to hostnames; with ApplyIPFilterForDomain disabled by default, URL validation checked domain allow/bl…
CWE: CWE-918
NVD

HIGH
CVE-2026-59216
CVE-2026-59216
pkg: python

published: Jul 9, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call delivered execute:python and execute:tool Socket.IO events to a client-supplied session_id after checking only that the session was connected, allowing authenticated users who learne…
CWE: CWE-94, CWE-200, CWE-639, CWE-862
GitHub-GHSA

HIGH
Phantom: Arbitrary file write and decode-bomb DoS via unconfined MCP tool paths
GHSA-52vm-mxx8-f227
pkg: phantom-audio
eco: pip
published: Jul 9, 2026
### Impact

In Phantom <= 1.3.0, when `PHANTOM_OUTPUT_DIR` was unset (the default), the MCP tools accepted arbitrary absolute output paths with no confinement. Anything able to send tool calls (e.g. an AI agent driving the MCP interface) could **write or overwrite arbitrary files** the process user …

NVD

HIGH
CVE-2026-14373
CVE-2026-14373
pkg: docker

published: Jul 8, 2026

HashiCorp Nomad and Nomad Enterprise did not enforce the allow_privileged restriction for the Docker task driver's host namespace mode options. This may allow an authenticated job submitter to run a container in a host namespace and access information belonging to the host or to other workloads on t…
CWE: CWE-862
NVD

HIGH
CVE-2026-60002
CVE-2026-60002
pkg: openbsd openssh

published: Jul 8, 2026

ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)
CWE: CWE-416
GitHub-GHSA

HIGH
Goploy: Arbitrary File Read via Path Traversal in /deploy/fileDiff allows Remote Server Compromise
GHSA-4g5x-hcwm-82jw
pkg: github.com/zhenorzz/goploy
eco: go
published: Jul 7, 2026
> [ Click here to jump to the Simplified Chinese version (点击跳转到简体中文版本)](#goploy-系统任意文件读取)
# Goploy System Arbitrary File Read Vulnerability

## Basic Information
– **Vulnerability Name**: Goploy Endpoints Arbitrary File Read via Path Traversal
– **Vulnerability …

CVE-2026-53553
GitHub-GHSA

HIGH
Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp
GHSA-86j7-9j95-vpqj
pkg: better-auth, better-auth
eco: npm
published: Jul 7, 2026
### Am I affected?

Check each condition. Users are affected when all of the first three hold.

– Their application enables the `oidc-provider` plugin or the `mcp` plugin from `better-auth/plugins`. The `mcp` plugin wraps the same provider and carries the same defect. Both are on the migration path …

GitHub-GHSA

HIGH
Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin
GHSA-fmh4-wcc4-5jm3
pkg: better-auth
eco: npm
published: Jul 7, 2026
### Am I affected?

Users are affected if all of the following are true:

– Their application uses `better-auth` with the `organization` plugin (`import { organization } from "better-auth/plugins/organization"`).
– Their application enables a sign-up surface that allows arbitrary unverified email re…

CVE-2026-53514
GitHub-GHSA

HIGH
New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs
GHSA-6qcr-qxgr-m7fv
pkg: github.com/QuantumNous/new-api
eco: go
published: Jul 7, 2026
## Summary

The default SSRF protection configuration did not apply IP filtering to hostnames. With `ApplyIPFilterForDomain` disabled by default, URL validation checked domain allow/block rules but did not resolve a hostname and validate the resolved IP address. Authenticated users could configure n…

CVE-2026-33655
GitHub-GHSA

HIGH
Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps
GHSA-v54h-cp2w-9x4g
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

`coder open app` opens external workspace-app URLs without validating the scheme or host. When an external app URL contains the `$SESSION_TOKEN` placeholder the CLI replaces it with the user's real session token before handing the URL to the OS open handler.

> **Note:** Practical explo…

CVE-2026-55431
GitHub-GHSA

HIGH
OpenRemote has Cross-Realm User Information Disclosure in UserResourceImpl
GHSA-xqr9-4wvv-gvch
pkg: io.openremote:openremote-manager
eco: maven
published: Jul 6, 2026
### Summary

A realm admin of tenant B can read the profile, client roles, and realm roles of any user in any other realm (including the master realm) by supplying the target user's UUID in the REST API path. Three read endpoints in UserResourceImpl check whether the caller holds the read:admin role…

CVE-2026-54641
NVD

HIGH
CVE-2026-9165
CVE-2026-9165
pkg: kubernetes

published: Jul 6, 2026

A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQL queries served on the authenticated GraphQL API. An authenticated user with a valid API token can send deeply nested queries that cause excessive resource consumption in Central,…
CWE: CWE-400
GitHub-GHSA

HIGH
OpenRemote has an incomplete fix for CVE-2026-40882: XXE in KNXProtocol.startAssetImport() allows arbitrary file read via unprotected XMLInputFactory
GHSA-7v6w-c3f4-9wpq
pkg: io.openremote:openremote-agent
eco: maven
published: Jul 6, 2026
### Summary
The fix for CVE-2026-40882 addressed only the Velbus asset import handler. The KNX asset import handler (`KNXProtocol`) processes user-uploaded ETS project ZIP files through Saxon XSLT and `XMLInputFactory.newInstance()` with no XXE protection, allowing any authenticated user to read arb…
CVE-2026-54640
GitHub-GHSA

HIGH
Mistune: Potential DoS via quadratic-time parsing in parse_link_text
GHSA-qcq2-496w-v96p
pkg: mistune
eco: pip
published: Jul 9, 2026
### Summary
Mistune is vulnerable to a CPU exhaustion DoS due to superlinear (approximately O(n²)) behavior in parse_link_text. A relatively small input consisting of repeated [ characters causes significant parsing slowdown.

### Affected component
mistune/inline_parser.py → **parse_link_text**

CVE-2026-49851
NVD

HIGH
CVE-2026-54695
CVE-2026-54695
pkg: python

published: Jul 9, 2026

Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. Prior to 1.4.0, the pipecat development runner registers a /ws WebSocket endpoint for telephony testing that accepts connections without authentication, reads an attacker-supplied callSid fr…
CWE: CWE-862
NVD

HIGH
CVE-2026-13462
CVE-2026-13462
pkg: ssl

published: Jul 9, 2026

PayRange Android app, version 7.0.7 and below, contains an SSL bypass vulnerability that allows invalid certificates to be accepted in application webviews. A remote and unauthenticated attacker can steal information that the user sends.
NVD

HIGH
CVE-2026-11404
CVE-2026-11404
pkg: tls

published: Jul 9, 2026

Cesanta Mongoose before 7.22 contains an out-of-bounds read in the built-in TLS server function mg_tls_server_recv_hello(), which uses an attacker-controlled session_id_len byte from a TLS ClientHello as a buffer index without validating it against the length of received data. A remote, unauthentica…
CWE: CWE-125
GitHub-GHSA

HIGH
org.hl7.fhir.core: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint
GHSA-7cmj-v6x8-frvv
pkg: ca.uhn.hapi.fhir:org.hl7.fhir.dstu2, ca.uhn.hapi.fhir:org.hl7.fhir.dstu2016may, ca.uhn.hapi.fhir:org.hl7.fhir.dstu3
eco: maven
published: Jul 9, 2026
# Summary
All implementations of FHIRPathEngine accept arbitrary FHIRPath expressions and evaluate them without input validation. The utility intended to secure this evaluation did so incorrectly, and did not fully cover all places in which evaluation was being done. An attacker can send a resource …
CVE-2026-49485
GitHub-GHSA

HIGH
Soup Sieve: Regular Expression Denial of Service (ReDoS) via Selector Parser
GHSA-836r-79rf-4m37
pkg: soupsieve
eco: pip
published: Jul 9, 2026
### Summary

The CSS selector parser in soupsieve (the CSS selector engine for Beautiful Soup 4) contains a regular expression vulnerable to catastrophic backtracking. When processing an attribute selector with an unterminated quoted value, the `VALUE` regex pattern in `css_parser.py` enters exponen…

CVE-2026-49477
GitHub-GHSA

HIGH
Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists
GHSA-2wc2-fm75-p42x
pkg: soupsieve
eco: pip
published: Jul 9, 2026
### Summary

The CSS selector parser in soupsieve (the CSS selector engine for Beautiful Soup 4) allocates unbounded memory when compiling large comma-separated selector lists. An attacker who can supply a crafted CSS selector string to `soupsieve.compile()` or Beautiful Soup's `.select()` / `.selec…

CVE-2026-49476
GitHub-GHSA

HIGH
Micronaut doesn't set a maximum redirect count for its HTTP Client, enabling infinite loop DoS
GHSA-387m-935m-c4vw
pkg: io.micronaut:micronaut-http-client, io.micronaut:micronaut-http-client, io.micronaut:micronaut-http-client
eco: maven
published: Jul 9, 2026
The Netty-based Micronaut HTTP Client does not impose a limit on HTTP redirections, potentially allowing an infinite redirect loop that could lead to a denial-of-service attack.

### Patches

The following versions are patched:

– For Micronaut 5, versions equal or greater than [5.0.1](https://gith…

NVD

HIGH
CVE-2026-54772
CVE-2026-54772
pkg: windows

published: Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, an unauthenticated remote attacker that can reach a NetTcpBinding, NetNamedPipeBinding, or UnixDomainSocketBinding endpoint can trigger premature EOF handling in the CoreWCF net.tc…
CWE: CWE-400, CWE-835
NVD

HIGH
CVE-2026-54499
CVE-2026-54499
pkg: python

published: Jul 8, 2026

Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human languages. Prior to 1.12.2, Stanza model loaders such as stanza.models.common.pretrain.Pretrain.load() attempt torch.load(…, weights_only=True) but fall back to torch.load(…, weights_o…
CWE: CWE-502, CWE-676
NVD

HIGH
CVE-2026-15117
CVE-2026-15117
pkg: google chrome

published: Jul 8, 2026

Use after free in Payments in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-15111
CVE-2026-15111
pkg: google chrome

published: Jul 8, 2026

Use after free in Views in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-31309
CVE-2026-31309
pkg: node

published: Jul 8, 2026

Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node before v1.36.0 allows unauthenticated attackers to arbitrarily overwrite the node's configuration and achieve a full node takeover via supplying a crafted POST request.
CWE: CWE-862
NVD

HIGH
CVE-2026-49866
CVE-2026-49866
pkg: node

published: Jul 8, 2026

libp2p is a JavaScript Implementation of libp2p networking stack. Prior to 16.0.0, @libp2p/gossipsub defaultDecodeRpcLimits set maxIhaveMessageIDs and maxIwantMessageIDs to Infinity, allowing oversized IHAVE and IWANT control message arrays in message/decodeRpc.ts and gossipsub.ts to synchronously i…
CWE: CWE-770
NVD

HIGH
CVE-2026-59939
CVE-2026-59939
pkg: python

published: Jul 8, 2026

httplib2 is a comprehensive HTTP client library for Python. Prior to 0.32.0, httplib2 performs unbounded decompression of HTTP response bodies encoded with Content-Encoding: gzip or deflate in _decompressContent in httplib2/init.py, allowing a malicious or compromised HTTP server to return a small c…
CWE: CWE-409
NVD

HIGH
CVE-2026-55404
CVE-2026-55404
pkg: linux

published: Jul 8, 2026

yt-dlp and youtube-dl are command-line audio/video downloaders. Prior to 2026.7.4, the –write-link, –write-url-link, and –write-desktop-link options can write .url or .desktop shortcut files using attacker-controlled webpage_url or filename metadata without sufficient validation or escaping, allo…
CWE: CWE-74
NVD

HIGH
CVE-2026-59928
CVE-2026-59928
pkg: mistune_project mistune

published: Jul 8, 2026

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a Markdown document containing many repeated or distinct reference-link definitions causes quadratic work in src/mistune/block_parser.py and the ref_links environment dictionary handling, allowing denial of service throu…
CWE: CWE-407, CWE-1333
NVD

HIGH
CVE-2026-59925
CVE-2026-59925
pkg: mistune_project mistune

published: Jul 8, 2026

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, long sequences of well-formed double-asterisk or triple-asterisk emphasis pairs around a character cause quadratic work in src/mistune/inline_parser.py because the parser scans forward for matching close markers from eve…
CWE: CWE-407, CWE-1333, CWE-407
NVD

HIGH
CVE-2026-59922
CVE-2026-59922
pkg: mistune_project mistune

published: Jul 8, 2026

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a run of closed tilde, equals-sign, or caret marker pairs around a character causes quadratic work in src/mistune/plugins/formatting.py when the strikethrough, mark, or insert plugin scans for matching markers from each …
CWE: CWE-407, CWE-1333, CWE-407
NVD

HIGH
CVE-2026-59892
CVE-2026-59892
pkg: node

published: Jul 8, 2026

OpenTelemetry JavaScript is the OpenTelemetry JavaScript client. Prior to 2.9.0, @opentelemetry/propagator-jaeger decodes incoming uber-trace-id and uberctx-* HTTP header values with decodeURIComponent() without handling decode errors, allowing an unauthenticated remote attacker to send a malformed …
CWE: CWE-248
NVD

HIGH
CVE-2026-10708
CVE-2026-10708
pkg: jwt

published: Jul 8, 2026

This vulnerability enables large‑scale data harvesting without requiring app‑specific secrets. A single request to a minimal leaderboard component may return user records containing emails, UUIDs, and custom fields. The combination of wildcard CORS behavior, long‑lived twenty‑day JWTs, and t…
NVD

HIGH
CVE-2026-58656
CVE-2026-58656
pkg: jwt

published: Jul 8, 2026

Grav API plugin before v1.0.0-rc.16 accepts JWT tokens via the ?token= URL query parameter and responds with Access-Control-Allow-Origin: *, allowing unauthenticated attackers to make fully authenticated cross-origin API requests from any malicious website. Attackers who obtain a leaked JWT token fr…
CWE: CWE-598
NVD

HIGH
CVE-2026-14895
CVE-2026-14895
pkg: express

published: Jul 7, 2026

String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service.

The trim and rtrim functions stripped trailing whitespace with s/\s*$//u. Because \s* matches greedily and the $ anchor fails whenever a non-whitespace character follows the whitespace, the regex e…

CWE: CWE-1333
NVD

HIGH
CVE-2026-56811
CVE-2026-56811
pkg: phoenixframework phoenix

published: Jul 7, 2026

Allocation of Resources Without Limits or Throttling vulnerability in phoenixframework phoenix (Phoenix.Socket module) allows an unauthenticated attacker to cause a denial of service against any endpoint that mounts a Phoenix socket with a reachable channel transport (WebSocket or LongPoll).

This v…

CWE: CWE-770
NVD

HIGH
CVE-2026-55574
CVE-2026-55574
pkg: vllm vllm

published: Jul 6, 2026

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, the structured_outputs.regex API parameter passes a user-supplied regular expression string directly to the grammar compiler backends with no compilation timeout; in the xgrammar backend the string…
CWE: CWE-1333
NVD

HIGH
CVE-2026-55380
CVE-2026-55380
pkg: python pillow

published: Jul 6, 2026

Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompression_bomb_check(), allowing a crafted .gd file to trigger excessive C-heap allocation when loaded. Th…
CWE: CWE-789
NVD

HIGH
CVE-2026-55379
CVE-2026-55379
pkg: python pillow

published: Jul 6, 2026

Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling Image._decompression_bomb_check(), bypassing Pillow's documented decompression bomb pro…
CWE: CWE-789
NVD

HIGH
CVE-2026-54060
CVE-2026-54060
pkg: python pillow

published: Jul 6, 2026

Pillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.new("1", (xsize, ysize)) without calling Image._decompression_bomb_check(), allowing a font to trigger excessive allocation during conversion or saving…
CWE: CWE-789
NVD

HIGH
CVE-2026-54059
CVE-2026-54059
pkg: python pillow

published: Jul 6, 2026

Pillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without calling Image._decompression_bomb_check(), allowing crafted PCF font data to cause excessive memory allocat…
CWE: CWE-789
NVD

HIGH
CVE-2026-13698
CVE-2026-13698
pkg: openvpn openvpn

published: Jul 6, 2026

A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers with a valid tls-crypt-v2 client key to potentially cause a denial of service
CWE: CWE-401, CWE-770, CWE-401
NVD

HIGH
CVE-2026-54784
CVE-2026-54784
pkg: windows

published: Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. In version 1.9.0, CoreWCF SPNEGO SecurityContextToken negotiation can expose the proof key recovered from the RSTR when TransportWithMessageCredential with Windows client credentials and session establishme…
CWE: CWE-311, CWE-523
NVD

HIGH
CVE-2026-54783
CVE-2026-54783
pkg: windows

published: Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF WS-Security endorsing and supporting signature verification does not ensure the selected ds:Signature covers the expected Security header target, allowing an attacker with …
CWE: CWE-294, CWE-345, CWE-347
NVD

HIGH
CVE-2026-54781
CVE-2026-54781
pkg: windows

published: Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML token validation does not enforce SubjectConfirmation method URIs or holder-of-key proof keys in SamlSecurityTokenHandler, allowing holder-of-key downgrade or custom c…
CWE: CWE-287, CWE-345
NVD

HIGH
CVE-2026-54774
CVE-2026-54774
pkg: windows

published: Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, SamlSerializer skips final SignatureValue verification when a CoreWCF service validates SAML tokens using a non-X.509 signing token, allowing an attacker to reference a non-X.509 S…
CWE: CWE-345, CWE-347
NVD

HIGH
CVE-2026-55436
CVE-2026-55436
pkg: coder coder

published: Jul 8, 2026

Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and prior to versions 2.32.7, 2.33.8, and 2.34.2, the AI Bridge Proxy (`aibridgeproxyd`) created a goproxy server whose default transport set `InsecureSkipVerify: true` and only assigned…
CWE: CWE-295
NVD

HIGH
CVE-2026-55076
CVE-2026-55076
pkg: coder coder

published: Jul 7, 2026

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, Coder's OIDC callback checked `email_verified` with a direct Go `bool` type assertion. When an IdP returned the claim as a non-boolean (for example the string …
CWE: CWE-287, CWE-704
GitHub-GHSA

HIGH
Coder's AI Bridge Proxy skips TLS certificate verification in default configuration
GHSA-84rm-42xw-mx52
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

The AI Bridge Proxy (`aibridgeproxyd`) created a goproxy server whose default transport set `InsecureSkipVerify: true` and only assigned a secure transport when an upstream proxy was configured. In the default configuration (no upstream proxy), outbound HTTPS to the Coder access URL acc…

CVE-2026-55436
GitHub-GHSA

HIGH
Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass
GHSA-9r87-mvcw-x35f
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

Two flaws in Coder's OIDC login chained into account takeover: email-based user matching fell back to linking by email without checking for an existing link to a different IdP subject and the `email_verified` claim was only enforced when present as a boolean `false` so an absent or non-…

CVE-2026-55075
GitHub-GHSA

HIGH
Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking
GHSA-75vm-6w67-gwvp
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

Coder's OIDC callback checked `email_verified` with a direct Go `bool` type assertion. When an IdP returned the claim as a non-boolean (for example the string `"false"`) or omitted it, the assertion failed open and the email was treated as verified. Combined with an unconditional email-…

CVE-2026-55076
NVD

HIGH
CVE-2026-59214
CVE-2026-59214
pkg: python

published: Jul 9, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, Open WebUI runs client-side Python with Pyodide in a same-origin web worker, allowing stored chat payloads that use pyodide.http.pyfetch or the js module fetch and XMLHttpRequest APIs to issue auth…
CWE: CWE-79
GitHub-GHSA

HIGH
Open WebUI vulnerable to Stored XSS via iFrame embeds in response messages
GHSA-vjm7-m4xh-7wrc
pkg: open-webui
eco: pip
published: Jul 7, 2026
### Summary
Manually modifying chat history allows setting the `embeds` property on a response message, the content of which is loaded into an iFrame with a sandbox that has `allow-scripts` and `allow-same-origin` set, ignoring the "iframe Sandbox Allow Same Origin" configuration. This enables store…
CVE-2026-26193
GitHub-GHSA

HIGH
Open WebUI vulnerable to Stored XSS via iFrame in citations model
GHSA-xc8p-9rr6-97r2
pkg: open-webui
eco: pip
published: Jul 7, 2026
### Summary
Manually modifying chat history allows setting the `html` property within document metadata. This causes the frontend to enter a code path that treats document contents as HTML, and render them in an iFrame when the citation is previewed. This allows stored XSS via a weaponised document …
CVE-2026-26192
GitHub-GHSA

HIGH
9router: Login brute-force protection bypass via spoofed X-Forwarded-For header
GHSA-7cfm-pqrj-xgq7
pkg: 9router
eco: npm
published: Jul 6, 2026
## Summary

The 9router dashboard login rate limiter derives the client identity from the attacker-controlled `X-Forwarded-For` HTTP header. When 9router is directly exposed, or deployed behind a reverse proxy that does not overwrite untrusted forwarding headers, a remote attacker can rotate the `X-…

CVE-2026-55501
GitHub-GHSA

HIGH
chmod: –preserve-root bypassed by any path that resolves to root (e.g. /../)
GHSA-4c7q-4928-8445
pkg: uu_chmod
eco: rust
published: Jul 6, 2026
`Chmoder::chmod()` only compares the literal argument against `Path::new("/")`, so the `–preserve-root` guard is bypassed by any path that *resolves* to root — a symlink to `/` or simply `/../`.

“`
if self.recursive && self.preserve_root && file == Path::new("/") {
return Err(ChmodError::Pr…

CVE-2026-35338
NVD

HIGH
CVE-2026-14802
CVE-2026-14802
pkg: react

published: Jul 6, 2026

A vulnerability was detected in react create-react-app up to 5.0.1 on macOS. This affects the function startBrowserProcess of the file openBrowser.js of the component react-dev-utils. Performing a manipulation results in os command injection. Remote exploitation of the attack is possible. The exploi…
CWE: CWE-77, CWE-78
NVD

HIGH
CVE-2026-59721
CVE-2026-59721
pkg: node

published: Jul 9, 2026

Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the updateInfraConfigs GraphQL mutation in admin/infra.resolver.ts accepts an attacker-controlled MAILER_SMTP_URL value, and validateSMTPUrl in utils.ts permits path, query, or fragment content that nodemailer parses into sen…
CWE: CWE-77, CWE-78, CWE-915
GitHub-GHSA

HIGH
Coder: User-admin role can reset owner account password
GHSA-29xf-69gq-m9jx
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

The `PUT /api/v2/users/{user}/password` endpoint authorized only `ActionUpdatePersonal` and did not prevent a `user-admin` from resetting an `owner` account's password. It also did not require the current password when an admin reset another user's password.

> **Note:** Exploitation re…

CVE-2026-55077
NVD

HIGH
CVE-2026-59219
CVE-2026-59219
pkg: jwt

published: Jul 9, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 before 0.10.0 with Redis configured, Socket.IO connect, user-join, join-channels, join-note, and the terminal websocket first-message authentication used decode_token without the Redis-backed is_valid_to…
CWE: CWE-613
NVD

HIGH
CVE-2026-47828
CVE-2026-47828
pkg: tls

published: Jul 9, 2026

During bosh create-env and bosh delete-env, the CLI uploads compiled CPI packages and rendered job templates to the new VM's DAV blobstore over HTTPS without verifying the server certificate, even though a CA certificate for that endpoint is available in the installation manifest. A network attacker…
NVD

HIGH
CVE-2026-58583
CVE-2026-58583
pkg: windows

published: Jul 7, 2026

FluxInk (formerly Sunia SPB Peripheral) Color Management Driver (TcnPeripheral64.sys) 1.0.7.2 allows local privilege escalation for a standard user account via arbitrary physical memory mapping at \Device\PhysicalMemory. Fixed in version 1.0.7.6. The fixed driver is currently available in the Window…
CWE: CWE-269
GitHub-GHSA

HIGH
mkfifo: permissions of an existing file are changed after FIFO creation fails
GHSA-pmf6-rcx4-v53v
pkg: uu_mkfifo
eco: rust
published: Jul 6, 2026
When `mkfifo()` fails (e.g. target already exists), the code shows an error but is missing a `continue;`, so it falls through to `fs::set_permissions` and changes the permissions of the pre-existing file to the default FIFO mode (`0o666` & umask -> `0644`).

“`
$ touch secret; chmod 000 secret
$ co…

CVE-2026-35341
GitHub-GHSA

HIGH
flyto-core has SSRF guard bypass via IPv6 transition addresses (IPv4-mapped / 6to4 / NAT64) in validate_url_ssrf
GHSA-794r-5rp2-fpg8
pkg: flyto-core
eco: pip
published: Jul 6, 2026
## Summary

`flyto-core`'s SSRF protection (`validate_url_ssrf` / `is_private_ip` in `src/core/utils.py`) blocks private and metadata destinations by resolving the host and testing the resulting IP for membership in a hardcoded `PRIVATE_IP_RANGES` list. That list contains only the *native* RFC 1918 …

CVE-2026-55787
NVD

HIGH
CVE-2026-59196
CVE-2026-59196
pkg: pnpm pnpm

published: Jul 6, 2026

pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted lockfile alias could be joined directly under a hoisted node_modules directory. Traversal aliases could escape that directory, while reserved aliases such as .bin or .pnpm could overwrite pnpm-owned layout. This vulnerability is fixe…
CWE: CWE-22, CWE-73
GitHub-GHSA

HIGH
Ruby CSS Parser: SSRF and Local File Disclosure in `CssParser::Parser#read_remote_file`
GHSA-9pmc-p236-855h
pkg: css_parser
eco: rubygems
published: Jul 9, 2026
## Summary

`CssParser::Parser#read_remote_file` (and therefore `load_uri!`, and the `@import`-following branch of `add_block!`) issues HTTP/HTTPS requests against any host, port and URI it is handed, with no scheme allowlist, no host / IP filtering, and no protection against link-local, loopback or…

CVE-2026-53727
GitHub-GHSA

HIGH
Note Mark: Path traversal via unsanitized book/note slug in migrate export (sibling of GHSA-g49p)
GHSA-rqrh-8wpv-x7hh
pkg: github.com/enchant97/note-mark/backend
eco: go
published: Jul 9, 2026
## Summary

Note Mark validates book and note `slug` values with the OpenAPI/huma tag `pattern:"[a-z0-9-]+"`. huma compiles this with `regexp.MustCompile(s.Pattern)` and tests it with `patternRe.MatchString(str)`, an UNANCHORED match. Because the pattern is not anchored (`^…$`), any string that me…

CVE-2026-50553
GitHub-GHSA

HIGH
ratex-parser panics on `\verb` with a multibyte delimiter (UTF-8 byte-boundary slice)
GHSA-4hgp-59h5-gvrj
pkg: ratex-parser
eco: rust
published: Jul 7, 2026
### Summary

The public parser entrypoint `ratex_parser::parse(&str)` panics on the **9-byte** input `\verbéxé` (i.e. `\verb` followed by the non-ASCII delimiter `é`). When handling a `\verb` command, the parser slices the verbatim argument with **byte** indices (`arg[1..arg.len() – 1]`); if the …

CVE-2026-53530
GitHub-GHSA

HIGH
uutils coreutils: cp/install/mv/ln –suffix alone does not enable backup mode (silent data loss vs GNU)
GHSA-fqf6-gxhh-2xhw
pkg: uucore
eco: rust
published: Jul 7, 2026
`determine_backup_mode` in `src/uucore/src/lib/features/backup_control.rs` only checks `–backup`/`-b` and returns `BackupMode::None` when only `–suffix` is given. GNU enables backup mode when `–suffix` is used alone (defaulting to existing/numbered, or `$VERSION_CONTROL`). Affects `cp`, `install`…
GitHub-GHSA

HIGH
Open WebUI vulnerable to stored XSS via unescaped markdown token in MarkdownTokens.svelte leading to full account takeover and RCE via functions
GHSA-9f4f-jv96-8766
pkg: open-webui
eco: pip
published: Jul 7, 2026
### Summary

A vulnerability in the way certain html tags in chat messages are rendered allows attackers to inject JavaScript code into a chat transcript. The JavaScript code will be executed in the user's browser every time that chat transcript is opened, allowing attackers to retrieve the user's a…

CVE-2025-46719
GitHub-GHSA

HIGH
XWiki Platform Old Core: Resource path traversal via /skin/ action endpoint in Jetty 12+
GHSA-qj4x-9g63-25g6
pkg: org.xwiki.platform:xwiki-platform-oldcore, org.xwiki.platform:xwiki-platform-oldcore
eco: maven
published: Jul 7, 2026
### Impact

With Jetty 12+ a user can craft a URL to access any resource the Jetty instance is allowed to access.

For example `http://[host]/xwiki/bin/skin/..%252f/..%252f..%252f..%252f..%252f..%252f..%252f..%252fetc/passwd` allows downloading the content of the /etc/passwd file, provided Jetty is …

CVE-2026-34151
GitHub-GHSA

HIGH
OpenRemote has Authenticated SQL Injection via Datapoint Crosstab Export
GHSA-cgfv-jrfp-2r7v
pkg: io.openremote:openremote-manager
eco: maven
published: Jul 6, 2026
## Summary

The datapoint export API builds a PostgreSQL crosstab export query by concatenating asset display names into raw SQL. An authenticated user who can create or rename an asset and then request a crosstab datapoint export can inject SQL through the asset name. The injected query output is s…

GitHub-GHSA

HIGH
Scriban: Template Writes to Arbitrary CLR Properties via `TypedObjectAccessor` (Mass Assignment + `private` / `init` / `internal` Setter Bypass)
GHSA-7jvp-hj45-2f2m
pkg: Scriban
eco: nuget
published: Jul 6, 2026
<!– obsidian –><h2 data-heading="Description">Description</h2>
<p>When a host pushes a CLR object into a Scriban <code>TemplateContext</code> via the standard, documented pattern —</p>
<pre><code class="language-csharp">var so = new ScriptObject();
so["user"] = currentUser; // direct CLR refer…
GitHub-GHSA

MEDIUM
CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation
GHSA-q6h5-q3q6-f87x
pkg: github.com/cilium/cilium, github.com/cilium/cilium, github.com/cilium/cilium
eco: go
published: Jul 6, 2026
### Impact

Users with the ability to create CiliumLocalRedirectPolicies can specify arbitrary ClusterIPs via addressMatcher, which enables hijacking traffic to Services in any namespace, bypassing the namespace-scoping guarantees enforced by serviceMatcher.

In addition, deleting such a policy can …

CVE-2026-53935
NVD

MEDIUM
CVE-2026-55689
CVE-2026-55689
pkg: jwt

published: Jul 9, 2026

OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, OpenFGA's OIDC authenticator skipped JWT audience validation when authn.method was set to oidc, authn.oidc.issuer was configured, and authn.oidc.audience was not set, allowing a token minted for an unrelated service…
CWE: CWE-287
NVD

MEDIUM
CVE-2026-59208
CVE-2026-59208
pkg: n8n n8n

published: Jul 9, 2026

n8n is an open source workflow automation platform. Prior to 2.27.4 and from 2.28.0 prior to 2.28.1, n8n instances configured with more than one trusted token-exchange issuer resolved external identities to local accounts using only the JWT sub claim and ignored the iss claim, allowing an attacker w…
CWE: CWE-287, CWE-346, CWE-346
GitHub-GHSA

MEDIUM
Micronaut: DefaultHttpClient follows redirects, forwarding Authorization, Cookie, and Proxy-Authorization headers
GHSA-q6gh-6v2r-hjv3
pkg: io.micronaut:micronaut-http-client, io.micronaut:micronaut-http-client, io.micronaut:micronaut-http-client
eco: maven
published: Jul 9, 2026
### Impact

> DefaultHttpClient follows redirects and forwards Authorization, Cookie, and Proxy-Authorization headers to redirect targets across domain boundaries. The blocklist only filters Host/Connection/TE/CT/CL.
> Additionally, no maximum redirect count exists, enabling infinite loop DoS.
> Aff…

GitHub-GHSA

MEDIUM
rm: –preserve-root bypassed via a symlink to / (string check instead of dev/inode)
GHSA-7cr3-h577-g38j
pkg: uu_rm
eco: rust
published: Jul 6, 2026
The `–preserve-root` check uses a path-string test (`path.has_root() && path.parent().is_none()`) rather than comparing device/inode. A symlink to `/` (e.g. `/tmp/rootlink -> /`) has a parent component, so it passes the check. GNU caches `/`'s dev/inode at startup and compares every traversed direc…
CVE-2026-35349
GitHub-GHSA

MEDIUM
mv: symlinks expanded during cross-device move (resource exhaustion / data duplication)
GHSA-h444-6j9x-p8vh
pkg: uu_mv
eco: rust
published: Jul 6, 2026
When moving directories across filesystems, uutils `mv` dereferences symlinks inside the tree, copying their targets as real files/dirs instead of preserving the symlinks. GNU preserves symlinks by default. E.g. a `etc_link -> /etc` inside the source becomes a full copy of `/etc` at the destination.…
CVE-2026-35365
GitHub-GHSA

MEDIUM
Avo: Direct attachment upload endpoint lacks upload authorization and bypasses field-level upload policy
GHSA-pqpw-cvm4-8mv9
pkg: avo
eco: rubygems
published: Jul 9, 2026
### Summary

Avo's direct attachment upload endpoint lacks server-side upload authorization and bypasses the documented field-level upload policy methods such as `upload_{FIELD_ID}?`.

An authenticated Avo user who can reach the Avo attachment upload endpoint can replace or add attachment content, i…

CVE-2026-53769
NVD

MEDIUM
CVE-2026-59220
CVE-2026-59220
pkg: express

published: Jul 9, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.2 before 0.10.0, the SKILL_MENTION_RE and strip_re regular expressions in backend/open_webui/utils/middleware.py parsed <$skillId|label> skill mentions with overlapping quantifiers, allowing an authenticat…
CWE: CWE-1333
GitHub-GHSA

MEDIUM
Gittensory: Missing contributor-scoped access control on profile endpoint and MCP tool leaks miner financial data
GHSA-382c-vx95-w3p5
pkg: @jsonbored/gittensory-mcp
eco: npm
published: Jul 9, 2026
### Summary

`GET /v1/contributors/:login/profile` and the `gittensory_get_contributor_profile` MCP tool skip the contributor-scoped access check that every sibling endpoint enforces. Any authenticated session/API/MCP token holder can read any contributor's profile; for confirmed Gittensor miners t…

GitHub-GHSA

MEDIUM
pyLoad: Unbounded Memory Growth Leading to DoS and Potential DDoS in EventManager
GHSA-c2f9-4mc8-j656
pkg: pyload-ng
eco: pip
published: Jul 9, 2026
## Description:
The `EventManager` module in `pyload` manages a list of `Client` instances for subscribing to events. The addition of each unique `uuid` from the `get_events` API causes the creation of a `Client` instance that gets appended to the `clients` list. Although there is a `clean()` method…
CVE-2026-48987
NVD

MEDIUM
CVE-2026-54775
CVE-2026-54775
pkg: windows

published: Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, a CoreWCF service listening on a Kafka topic stops processing new records from that topic when KafkaTransportPump receives a null-value tombstone record, causing a persistent endpo…
CWE: CWE-248, CWE-754, CWE-755
NVD

MEDIUM
CVE-2026-15109
CVE-2026-15109
pkg: google chrome

published: Jul 8, 2026

Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-457
NVD

MEDIUM
CVE-2026-54777
CVE-2026-54777
pkg: windows

published: Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF NetNamedPipe transport accepts attachment to a pre-existing named pipe instance, allowing local interception of NetNamedPipe traffic when an attacker races NamedPipeListene…
CWE: CWE-367, CWE-665
GitHub-GHSA

MEDIUM
NL Portal: Missing per-user authorization on document and decision GraphQL queries in nl-portal-backend-libraries
GHSA-qpm9-h556-mwxm
pkg: nl.nl-portal:documenten-api, nl.nl-portal:besluiten
eco: maven
published: Jul 8, 2026
## Impact

In versions up to and including 3.0.0, two parts of the GraphQL API returned data without checking whether the data belonged to the logged-in user:

– **Document content.** A logged-in user could download the raw content of any document by its ID, regardless of who owned it. The resolver …

CVE-2026-49463
GitHub-GHSA

MEDIUM
Waku: Cross-Origin CSRF on RSC Server Action Dispatch
GHSA-75w3-gmqx-993q
pkg: waku
eco: npm
published: Jul 8, 2026
## Summary

Waku's RSC request dispatcher invokes server actions without validating the request's `Origin` (or `Sec-Fetch-Site`) header. A cross-origin web attacker can therefore cause a victim browser to issue an authenticated `POST` to a registered server action endpoint using a CORS-safelisted co…

CVE-2026-49455
NVD

MEDIUM
CVE-2026-15154
CVE-2026-15154
pkg: express

published: Jul 8, 2026

A flaw was found in `guardrails-detectors`, a component of Red Hat OpenShift AI. This vulnerability, known as Regular Expression Denial of Service (ReDoS), allows a remote attacker to provide specially crafted regular expressions to the public detection API. This can cause catastrophic backtracking,…
CWE: CWE-1333
NVD

MEDIUM
CVE-2026-60001
CVE-2026-60001
pkg: openbsd openssh

published: Jul 8, 2026

sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.
CWE: CWE-770
GitHub-GHSA

MEDIUM
ha-mcp: Add-on settings and policy routes are reachable without authentication at the bare root path
GHSA-q855-8rh5-jfgq
pkg: ha-mcp
eco: pip
published: Jul 7, 2026
### Summary

In add-on mode, the ha-mcp settings UI routes are mounted both under the MCP secret path **and** at the bare root of the published port (`:9583`), so Home Assistant ingress can serve the "Open Web UI" button. The root-mounted routes perform no authentication — no secret, no `Origin` c…

NVD

MEDIUM
CVE-2026-55490
CVE-2026-55490
pkg: linux

published: Jul 7, 2026

OpenWrt is a Linux operating system targeting embedded devices. Before v25.12.5, an integer underflow in handle_send_a() of the Emergency Access Daemon allows any unauthenticated attacker on the local network to crash the daemon by sending a single crafted UDP packet. The message length underflows b…
CWE: CWE-191
GitHub-GHSA

MEDIUM
Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpoints
GHSA-f5vp-w269-392g
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

AI Bridge provider handlers read request bodies with `io.ReadAll` without a maximum size so an authenticated user with AI Bridge access could send an arbitrarily large body and exhaust memory.

> **Note:** Exploitation requires authenticated access to the AI Bridge endpoints and the imp…

CVE-2026-55434
GitHub-GHSA

MEDIUM
Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service
GHSA-2mg2-p7r7-g27f
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

`POST /api/v2/files` converts zip uploads to tar in memory via `CreateTarFromZip`, which enforced a per-entry size limit but no aggregate limit on total decompressed output, writing to an unbounded in-memory buffer.

> **Note:** Exploitation requires authenticated file-upload access and…

CVE-2026-55078
GitHub-GHSA

MEDIUM
WeasyPrint has CSS Injection via Presentational Hints
GHSA-jhhc-3hcp-qhm5
pkg: weasyprint
eco: pip
published: Jul 6, 2026
### Summary
A CSS injection issue exists in WeasyPrint when HTML presentational hints are enabled. Unescaped attribute values are embedded into CSS, allowing injection of arbitrary CSS declarations. This affects applications processing untrusted HTML input.

### Details
File: weasyprint/css/__init__…

CVE-2026-49452
GitHub-GHSA

MEDIUM
@better-auth/oauth-provider may provide access tokens for unauthorized audiences via unbound resource indicators
GHSA-p2fr-6hmx-4528
pkg: @better-auth/oauth-provider
eco: npm
published: Jul 7, 2026
### Am I affected?

Users are affected if all of the following hold:

– Their application depends on `@better-auth/oauth-provider` on any stable `1.6.x` release (the stable line is not patched) or on a pre-release before `1.7.0-beta.4`.
– Their application either configures validAudiences` with mor…

NVD

MEDIUM
CVE-2026-12154
CVE-2026-12154
pkg: go

published: Jul 6, 2026

The Reviews Widgets for Google, Yelp & TripAdvisor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_id' shortcode attribute of the [fbrev] shortcode in versions up to and including 2.7.3. This is due to insufficient input sanitization and output escaping in the Feed_Sh…
CWE: CWE-79
NVD

MEDIUM
CVE-2026-15063
CVE-2026-15063
pkg: go

published: Jul 8, 2026

A flaw was found in the gorch service template, which is part of the trustyai-service-operator. Even when authentication is enabled, the gorch service exposes unproxied orchestrator and detector metrics ports. This allows any pod on the cluster network to directly access these ports, bypassing the k…
CWE: CWE-306
NVD

MEDIUM
CVE-2026-15044
CVE-2026-15044
pkg: go

published: Jul 8, 2026

A flaw was found in the TrustyAI Service Operator. When deploying services like gorch or NemoGuardrails, if a specific security setting is not enabled, these services can expose their communication channels without requiring users to prove their identity. This allows any other program within the clu…
GitHub-GHSA

MEDIUM
install -D: symlink race in directory creation allows arbitrary file overwrite
GHSA-gwm6-q8ch-hcfr
pkg: uu_install
eco: rust
published: Jul 6, 2026
The `-D` path runs `fs::create_dir_all` on a pathname then later opens the destination via path-based `File::create`/`fs::copy`, neither anchored to a directory fd. Between the two, an attacker can replace a path component with a symlink, redirecting the write.

**Impact:** an attacker with concurre…

CVE-2026-35356
GitHub-GHSA

MEDIUM
install: TOCTOU symlink race (unlink-then-create without O_EXCL) allows arbitrary file overwrite
GHSA-239g-2685-54×3
pkg: uu_install
eco: rust
published: Jul 6, 2026
`copy_file` in `install/src/install.rs` removes the destination then recreates it by pathname via `File::create` / `fs::copy` without `O_EXCL`/`create_new`. Between the unlink and the recreate, a local attacker with write access to the destination directory can drop in a symlink and redirect the wri…
CVE-2026-35355
NVD

MEDIUM
CVE-2026-14784
CVE-2026-14784
pkg: docker

published: Jul 6, 2026

A vulnerability was identified in vxcontrol PentAGI up to 2.1.0. This affects an unknown function of the file backend/pkg/docker/client.go of the component Docker API. The manipulation leads to sandbox issue. The attack may be initiated remotely. The pull request to fix this issue awaits acceptance.
CWE: CWE-264, CWE-265
NVD

MEDIUM
CVE-2026-14716
CVE-2026-14716
pkg: go

published: Jul 5, 2026

A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.13.0-beta.2. Impacted is the function MethodRouter.Handle of the file internal/gateway/router.go of the component WebSocket RPC Handler. Such manipulation leads to incorrect authorization. The attack may be launched remote…
CWE: CWE-285, CWE-863
NVD

MEDIUM
CVE-2026-54778
CVE-2026-54778
pkg: windows

published: Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF UnixDomainSocket POSIX peer identity resolution uses non-reentrant getpwuid and getgrgid calls, allowing concurrent connections to attribute one connection's identity to an…
CWE: CWE-362, CWE-825
NVD

MEDIUM
CVE-2026-15128
CVE-2026-15128
pkg: google chrome

published: Jul 8, 2026

Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-79
NVD

MEDIUM
CVE-2026-15127
CVE-2026-15127
pkg: google chrome

published: Jul 8, 2026

Inappropriate implementation in WebGL in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-79
NVD

MEDIUM
CVE-2026-59929
CVE-2026-59929
pkg: mistune_project mistune

published: Jul 8, 2026

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the safe_url filter in src/mistune/renderers/html.py blocks only javascript:, vbscript:, file:, and data: schemes, allowing legacy or chained schemes such as feed:, view-source:, jar:, livescript:, mocha:, ms-its:, mk:, …
CWE: CWE-79, CWE-184
NVD

MEDIUM
CVE-2026-59926
CVE-2026-59926
pkg: mistune_project mistune

published: Jul 8, 2026

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, render_admonition() in src/mistune/directives/admonition.py concatenates the Admonition directive :class: option into the HTML class attribute without escaping, allowing attribute injection and cross-site scripting even …
CWE: CWE-79
NVD

MEDIUM
CVE-2026-59923
CVE-2026-59923
pkg: mistune_project mistune

published: Jul 8, 2026

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, HTMLRenderer.safe_url() does not block percent-encoded javascript URIs, allowing attacker-supplied Markdown links or images to bypass URL protections and execute script in rendered HTML. This issue is fixed in version 3.…
CWE: CWE-79
NVD

MEDIUM
CVE-2026-59890
CVE-2026-59890
pkg: python

published: Jul 8, 2026

setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compiled glob patterns against on-disk file names without Unicode …
CWE: CWE-176, CWE-697
GitHub-GHSA

MEDIUM
Kiwi TCMS has an Open Redirect via unvalidated next parameter in account confirmation endpoint
GHSA-hmj5-jm8h-h9fh
pkg: kiwitcms
eco: pip
published: Jul 6, 2026
### Summary

An open redirect vulnerability in the account confirmation endpoint allows an unauthenticated attacker to craft a URL hosted on a legitimate Kiwi TCMS instance that redirects victims to an arbitrary external domain. The attack surface is particularly relevant for phishing campaigns targ…

CVE-2026-54724
GitHub-GHSA

MEDIUM
GoBGP confederation validation panics on empty AS_PATH attribute
GHSA-frrj-87jh-2772
pkg: github.com/osrg/gobgp/v4
eco: go
published: Jul 9, 2026
Found through variant analysis based on `CVE-2026-41643`

## Summary
GoBGP accepts a zero-length AS_PATH during UPDATE decoding and later panics while validating that attribute for a confederation eBGP peer. The vulnerable path is in the BGP UPDATE validator: a malformed UPDATE that should be reject…

CVE-2026-49838
GitHub-GHSA

MEDIUM
GoBGP: BGP OPEN capability parser may read capability values outside declared CapLen boundaries
GHSA-gjrg-jjr3-56cm
pkg: github.com/osrg/gobgp/v4
eco: go
published: Jul 9, 2026
### Summary
GoBGP contains a BGP OPEN capability parsing issue where several concrete capability decoders may parse data from the full remaining capability buffer instead of the slice bounded by the declared capability length, `CapLen`.
A malformed BGP OPEN message can cause bytes from a fol…
CVE-2026-49837
GitHub-GHSA

MEDIUM
sigstore-go has a multi-log threshold bypass via single compromised log
GHSA-9vcr-p3rj-q5q6
pkg: github.com/sigstore/sigstore-go
eco: go
published: Jul 9, 2026
### Impact
_What kind of vulnerability is it? Who is impacted?_

A verifier configured with WithTransparencyLog(N>1) or WithSignedCertificateTimestamps(N>1) expected defense-in-depth against the compromise of a single log instance. However, threshold counting counted verified witnesses per-entry or …

CVE-2026-49834
NVD

MEDIUM
CVE-2026-57022
CVE-2026-57022
pkg: ssl

published: Jul 9, 2026

An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX with SPC3 and SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).

When an affected device initiates a TCP conne…

CWE: CWE-754
NVD

MEDIUM
CVE-2026-54779
CVE-2026-54779
pkg: windows

published: Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML token replay protection is inoperative because DefaultTokenReplayCache.TryAdd does not reject duplicate tokens when DetectReplayedTokens is enabled, allowing a capture…
CWE: CWE-294, CWE-613
NVD

MEDIUM
CVE-2026-54773
CVE-2026-54773
pkg: windows

published: Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF WS-Security signature verification performs a document-wide ds:Signature lookup, allowing an unauthenticated remote attacker to place a SOAP header before wsse:Security and…
CWE: CWE-347
NVD

MEDIUM
CVE-2026-54590
CVE-2026-54590
pkg: python

published: Jul 8, 2026

AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Version 2.23.0 contains an incomplete fix for CVE-2026-45309 in SSHServerConfig._set_tokens that blocks /, , and .. before %u substitution in Aut…
CWE: CWE-22, CWE-639
NVD

MEDIUM
CVE-2026-58501
CVE-2026-58501
pkg: python

published: Jul 8, 2026

Zeep is a Python SOAP client. From 4.0.0 before 4.3.3, Settings.forbid_external is defined but not enforced when parsing WSDL or XSD documents, allowing transitive xsd:import, xsd:include, wsdl:import, and lxml entity or DTD references to fetch attacker-chosen HTTP or HTTPS URLs. This issue is fixed…
CWE: CWE-918
NVD

MEDIUM
CVE-2026-59924
CVE-2026-59924
pkg: mistune_project mistune

published: Jul 8, 2026

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Include.parse() joins and normalizes user-supplied include paths without verifying that the result remains within the intended markdown directory, allowing crafted include paths to access files outside that directory whe…
CWE: CWE-22
NVD

MEDIUM
CVE-2026-59999
CVE-2026-59999
pkg: openbsd openssh

published: Jul 8, 2026

In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.
CWE: CWE-348
GitHub-GHSA

MEDIUM
Weblate SSRF: outbound URL guard misses some private ranges
GHSA-vmfc-9982-2m45
pkg: weblate
eco: pip
published: Jul 7, 2026
### Impact

Weblate's `VCS_RESTRICT_PRIVATE` did not properly account for some transitional IPv6 ranges, multicast addresses, or some semi-private IPv4 ranges, which allowed some addresses to bypass private range restrictions.

### Patches

* https://github.com/WeblateOrg/weblate/pull/19768

### Res…

CVE-2026-50127
GitHub-GHSA

MEDIUM
KEDA has PostgreSQL connection string parameter injection via incomplete whitespace escaping
GHSA-6w3m-4hhp-775q
pkg: github.com/kedacore/keda/v2
eco: go
published: Jul 7, 2026
### Summary
`pkg/scalers/postgresql_scaler.go` builds libpq-style connection strings by concatenating `key=value` pairs separated by spaces. Each tenant-controllable field (`host`, `port`, `userName`, `dbName`, `sslmode`) is passed through `escapePostgreConnectionParameter`:
“`go
func escapePostgre…
CVE-2026-53572
NVD

MEDIUM
CVE-2026-54291
CVE-2026-54291
pkg: postgresql postgresql_jdbc_driver

published: Jul 6, 2026

pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections can be silently downgraded from SCRAM-SHA-256-PLUS with channel binding to plain SCRAM-SHA-256 without it, losing the man-in-the-middle protection the setting is meant to guarantee…
CWE: CWE-636, CWE-757
GitHub-GHSA

MEDIUM
Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing
GHSA-5wg6-jmq2-53pw
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

Coder's subdomain-based workspace app proxy allowed the same-owner CORS check to be bypassed. When a workspace-name subdomain segment parsed as a UUID, the workspace was resolved by ID without confirming the URL's username matched the real owner, while the CORS middleware trusted the un…

CVE-2026-55438
GitHub-GHSA

MEDIUM
Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access
GHSA-5g4w-3vw9-478w
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

The workspace app proxy resolves the target app from `httpapi.RequestHost()` which prefers the `X-Forwarded-Host` header over the real `Host` header. No middleware strips `X-Forwarded-Host` before routing and the header is not browser-forbidden so client-side JavaScript can set it on `f…

CVE-2026-55430
GitHub-GHSA

MEDIUM
@aborruso/ckan-mcp-server: SSRF via base_url allows access to internal networks (Potential fix bypass of CVE-2026-33060)
GHSA-g84h-j7jj-x32p
pkg: @aborruso/ckan-mcp-server
eco: npm
published: Jul 7, 2026
### Summary
A known vulnerability CVE-2026-33060 indicated tools including ckan_package_search and sparql_query that accept a base_url parameter had the risk of making HTTP requests to arbitrary endpoints without restriction. A fix was applied to filter out ip addresses. However, a method to bypass …
CVE-2026-53509
GitHub-GHSA

MEDIUM
rm: 'rm -rf ./' (and ./// variants) silently deletes current directory contents, bypassing dot protection
GHSA-89p7-7cq3-hhr2
pkg: uu_rm
eco: rust
published: Jul 6, 2026
`rm -rf .` is correctly refused, but `clean_trailing_slashes` normalizes `.///` to `./` while `path_is_current_or_parent_directory` only matches `.`/`..` (and `/.`/`/..`), not `./` or `../`. So `rm -rf ./` recursively deletes the directory's contents and then prints a misleading `cannot remove './':…
CVE-2026-35363
NVD

MEDIUM
CVE-2026-14355
CVE-2026-14355
pkg: php php, debian debian_linux

published: Jul 3, 2026

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length withou…
CWE: CWE-122
NVD

MEDIUM
CVE-2026-44918
CVE-2026-44918
pkg: node

published: Jul 10, 2026

OpenStack Ironic through before 37.0.1 allows creation or modification of nodes cross-project without authorization.
CWE: CWE-862
NVD

MEDIUM
CVE-2026-15165
CVE-2026-15165
pkg: wireshark wireshark

published: Jul 8, 2026

TLS ECH decryptor crash in Wireshark 4.6.0 to 4.6.6 allows denial of service
CWE: CWE-122
GitHub-GHSA

MEDIUM
DSpace: Path Traversal is possible through LDN message generation
GHSA-9qm4-rh6w-pq5x
pkg: org.dspace:dspace-api, org.dspace:dspace-api, org.dspace:dspace-api
eco: maven
published: Jul 8, 2026
## Overview

A path traversal vulnerability is possible via the [COAR Notify / LDN](https://wiki.lyrasis.org/spaces/DSDOC9x/pages/379126679/COAR+Notify) service in DSpace. _This vulnerability impacts DSpace versions 8.0 <= 8.3, 9.0 <= 9.2._ The attacker MUST already have DSpace administrator creden…

CVE-2026-49833
GitHub-GHSA

MEDIUM
DSpace has a possible Path Traversal Vulnerability in its Curation Task Reporter output path
GHSA-v66x-68f2-pxf5
pkg: org.dspace:dspace-api, org.dspace:dspace-api, org.dspace:dspace-api
eco: maven
published: Jul 8, 2026
## Overview

The [Curation Task](https://wiki.lyrasis.org/spaces/DSDOC9x/pages/379126845/Curation+Tasks) feature allows an output path to be used by the reporter (`-r` parameter), typically used to stream results and status of curation task operations. It is not restricted to any particular base pat…

CVE-2026-49831
NVD

MEDIUM
CVE-2026-44512
CVE-2026-44512
pkg: node

published: Jul 8, 2026

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.9.0 before 1.22.0, onnx.version_converter.convert_version() can dereference a null pointer in Upsample_6_7::adapt_upsample_6_7() in onnx/version_converter/adapters/upsample_6_7.h when processing an …
CWE: CWE-476
NVD

MEDIUM
CVE-2026-58468
CVE-2026-58468
pkg: node

published: Jul 7, 2026

NocoBase through 2.1.20 contains a server-side request forgery vulnerability in the serverRequest wrapper that allows authenticated administrators to issue arbitrary outbound HTTP requests by supplying malicious URLs to workflow request nodes, custom request action buttons, or the AI plugin. Attacke…
CWE: CWE-918
GitHub-GHSA

MEDIUM
ONNX has Null Pointer Dereference in Upsample Version Converter Adapter (Zero Inputs)
GHSA-hwpq-hmq9-wj77
pkg: onnx
eco: pip
published: Jul 7, 2026
### Summary

Null pointer dereference (SIGSEGV) in `Upsample_6_7::adapt_upsample_6_7()` (`onnx/version_converter/adapters/upsample_6_7.h:31`) when `convert_version()` processes a model with an Upsample node that has zero inputs. The adapter accesses `node->inputs()[0]->sizes()` without checking inpu…

CVE-2026-44512
NVD

MEDIUM
CVE-2026-50135
CVE-2026-50135
pkg: gohugo hugo

published: Jul 6, 2026

Hugo is a static site generator. From 0.123.0 to 0.161.1, a regression made  RootMappingFs.statRoot  use  Stat  (follows symlinks) instead of  Lstat , so a direct  resources.Get  of a symlink pointing outside its mount returned the target's contents — letting a symlink planted in a local m…
CWE: CWE-59
NVD

MEDIUM
CVE-2026-44362
CVE-2026-44362
pkg: trustedfirmware op-tee

published: Jul 6, 2026

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.20.0 and prior to version 4.11.0, a vulnerability in OP-TEE’s subkey rollback protection allows the use of revoked…
CWE: CWE-285
GitHub-GHSA

MEDIUM
kill: 'kill -1' parsed as PID -1, sending SIGTERM to all processes (system crash / DoS)
GHSA-p6rv-2qpm-fwvg
pkg: uu_kill
eco: rust
published: Jul 6, 2026
`kill -1` is incorrectly parsed as a positional `pid = -1`; combined with the default SIGTERM this calls `kill(-1, SIGTERM)`, signaling nearly every process the caller can see. GNU `kill` recognizes `-1`/`-9` as signals and reports "not enough arguments".

“`
$ kill -1 # uutils: kill(-1, SIG…

CVE-2026-35369
GitHub-GHSA

MEDIUM
chmod: recursive mode returns exit code 0 even when some files fail (last-file-wins)
GHSA-4×34-chg5-mwjj
pkg: uu_chmod
eco: rust
published: Jul 6, 2026
In `Chmoder::chmod()` the recursive branch overwrites the running result instead of accumulating it, so the exit code reflects only the *last* file processed:

“`
if self.recursive {
r = self.walk_dir_with_context(file, true); // overwrites r
} else {
r = self.chmod_file(file).and(r);
}
`…

CVE-2026-35339
NVD

MEDIUM
CVE-2026-40257
CVE-2026-40257
pkg: trustedfirmware op-tee

published: Jul 6, 2026

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.21.0 and prior to version 4.11.0, the ARM Crypto Extensions accelerated SHA-3 implementation has an off-by-one error…
CWE: CWE-787
GitHub-GHSA

MEDIUM
Rattler vulnerable to package cache path traversal via conda package build string
GHSA-h672-p7h7-97v9
pkg: rattler_cache, py_rattler
eco: pip
published: Jul 9, 2026
`rattler_cache` and `py-rattler` were vulnerable to package-cache path traversal when handling package metadata from conda channels.

During cache materialization, the `ratter_cache` code used the package record `build` string as part of a cache key that was joined into a filesystem path. A maliciou…

CVE-2026-53956
NVD

MEDIUM
CVE-2026-60120
CVE-2026-60120
pkg: vue

published: Jul 9, 2026

Bagisto before 2.4.4 contains a stored cross-site scripting vulnerability via client-side template injection that allows unauthenticated attackers to execute arbitrary JavaScript in administrator browsers by registering a customer account with malicious payload in the first or last name field. The c…
CWE: CWE-79
NVD

MEDIUM
CVE-2026-5005
CVE-2026-5005
pkg: go

published: Jul 9, 2026

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Twiser Informatics Technology Consulting, Trade and Education Inc. OKRs & Goals allows Stored XSS.

This issue affects OKRs & Goals: from 28220 before 28398.

CWE: CWE-79
NVD

MEDIUM
CVE-2026-56359
CVE-2026-56359
pkg: n8n n8n

published: Jul 8, 2026

n8n before 2.8.0 contains a cross-site scripting vulnerability in the credential management flow where authenticated users can inject malicious JavaScript URLs into OAuth2 credential Authorization URL fields. Attackers can craft malicious credentials and trick victims into clicking the OAuth authori…
CWE: CWE-79
GitHub-GHSA

MEDIUM
Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component
GHSA-7qw2-f75v-62f7
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

The `AgentLogLine` dashboard component instantiated `ansi-to-html` without `escapeXML: true` and inserted the result via `dangerouslySetInnerHTML` so HTML embedded in workspace agent log lines was rendered as live markup. Server-side sanitization did not neutralize HTML metacharacters.

CVE-2026-55437
GitHub-GHSA

MEDIUM
Suspended Coder users retain access to AI Bridge LLM proxy endpoints
GHSA-wqxv-w64v-5wh6
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

AI Bridge proxy endpoints authenticate via `Server.IsAuthorized` in `coderd/aibridgedserver`, which validates key format, expiry, secret and deleted or system users but does not check whether the account is suspended. Because suspension does not revoke existing API keys, a suspended use…

CVE-2026-55435
GitHub-GHSA

MEDIUM
Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers
GHSA-jqj2-x4c5-jfxm
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

The devcontainer recreate endpoint relied on route middleware that checked only `ActionRead` on the workspace and, unlike the sibling delete endpoint, performed no `ActionUpdate` check before triggering the destructive rebuild.

> **Note:** Exploitation requires an existing low-privileg…

CVE-2026-55433
GitHub-GHSA

MEDIUM
Coder's sub-agent app registration bypasses template port-sharing policy enforcement
GHSA-x9qq-2qh5-8rxf
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

The `CreateSubAgent` RPC did not validate a requested app sharing level against the template's `MaxPortSharingLevel` before persisting workspace apps, letting a workspace owner exceed the administrator's configured maximum.

> **Note:** Exploitation requires the ability to register sub-…

CVE-2026-55432
NVD

MEDIUM
CVE-2026-44342
CVE-2026-44342
pkg: oauth

published: Jul 9, 2026

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0-alpha.1, the email and WeChat account binding endpoints GET /api/oauth/email/bind and GET /api/oauth/wechat/bind used GET requests for state-changing account operations, allowing …
CWE: CWE-352
NVD

MEDIUM
CVE-2026-59817
CVE-2026-59817
pkg: node

published: Jul 9, 2026

Ghost is a Node.js content management system. From 6.27.0 before 6.44.0, Ghost's public donation checkout flow allowed an unauthenticated attacker to control donation checkout metadata and obtain full paid gift memberships for a minimal payment without exposing customer or member data or stealing mo…
CWE: CWE-472, CWE-639
GitHub-GHSA

MEDIUM
Note Mark: Unauthenticated disclosure of soft-deleted note metadata via deleted=true on public books
GHSA-588f-fvcv-xhvf
pkg: github.com/enchant97/note-mark/backend
eco: go
published: Jul 9, 2026
Summary

GET /api/books/{bookID}/notes is an unauthenticated endpoint that accepts a "deleted" query parameter. When the request is ?deleted=true, the
service runs the query with Unscoped() (bypassing GORM's soft-delete scope) but keeps the read-authorization clause as "owner_id = ? OR is_public…

CVE-2026-50554
NVD

MEDIUM
CVE-2026-9027
CVE-2026-9027
pkg: go

published: Jul 9, 2026

The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Payment Bypass via Improper Verification of Cryptographic Signature in all versions up to, and including, 2.7.4. The `corvuspay_success_handler` function registers the REST endpoint `POST /wp-json/corvuspay/success/` wit…
CWE: CWE-347
GitHub-GHSA

MEDIUM
Trapster Community: Unauthenticated malformed DNS compression pointers crash per-packet honeypot handler
GHSA-mxwc-wh95-pw4g
pkg: trapster
eco: pip
published: Jul 8, 2026
## Summary

`trapster.libs.dns.decode_labels()` decodes DNS names from attacker-supplied UDP packets and recurses **once per RFC 1035 compression pointer** with **no cycle detection and no depth bound**. A single unauthenticated UDP datagram sent to the DNS honeypot drives the function past CPython'…

NVD

MEDIUM
CVE-2026-45045
CVE-2026-45045
pkg: express

published: Jul 8, 2026

Fiber is an Express inspired web framework written in Go. Prior to 3.3.0 and 2.52.14, the BalancerForward proxy helper in middleware/proxy/proxy.go uses Header.Add() instead of Header.Set() when injecting X-Real-IP, allowing an attacker-supplied first X-Real-IP value to be forwarded to upstream serv…
CWE: CWE-290
NVD

MEDIUM
CVE-2026-44332
CVE-2026-44332
pkg: express

published: Jul 8, 2026

Fiber is an Express inspired web framework written in Go. Prior to 3.3.0, the default Authorizer function in the BasicAuth middleware in middleware/basicauth/config.go uses short-circuit evaluation that skips password hash comparison for non-existent usernames, enabling reliable remote username enum…
CWE: CWE-203
NVD

MEDIUM
CVE-2026-59927
CVE-2026-59927
pkg: mistune_project mistune

published: Jul 8, 2026

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the Include directive in src/mistune/directives/include.py detects only direct self-includes and not indirect cycles, allowing two markdown files that include each other to trigger unbounded recursion, raise RecursionErr…
CWE: CWE-674, CWE-755, CWE-674
NVD

MEDIUM
CVE-2026-59875
CVE-2026-59875
pkg: node

published: Jul 8, 2026

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.17, node-tar does not strip NUL bytes from PAX path and linkpath records in src/pax.ts, allowing a crafted archive with values to reach fs.lstat or fs.open and terminate the process with an uncaught exception. This issue is fix…
CWE: CWE-248
NVD

MEDIUM
CVE-2026-59871
CVE-2026-59871
pkg: node

published: Jul 8, 2026

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, node-tar coerces all-digit PAX path and linkpath values in src/pax.ts to JavaScript numbers, causing downstream path handling such as normalizeWindowsPath(entry.path).split('/') to throw an uncaught TypeError. This issue is…
CWE: CWE-704
GitHub-GHSA

MEDIUM
New API is vulnerable to CSRF through user email binding
GHSA-26v7-h57m-gh9m
pkg: github.com/QuantumNous/new-api
eco: go
published: Jul 7, 2026
## Summary

The email and WeChat account binding endpoints used GET requests for state-changing account operations. In deployments where session cookies could be sent on cross-site navigations, an attacker could trigger a logged-in user's browser to bind an attacker-controlled email address or OAuth…

CVE-2026-44342
NVD

MEDIUM
CVE-2026-14631
CVE-2026-14631
pkg: webpack.js webpack-dev-server

published: Jul 3, 2026

webpack-dev-server versions 5.2.5 and earlier terminate the whole Node.js process when an unauthenticated peer sends either a normal HTTP request with a malformed Host header or a WebSocket upgrade to the default /ws endpoint with a malformed Origin header. The malformed value causes an uncaught exc…
CWE: CWE-20, CWE-248
GitHub-GHSA

MEDIUM
pyLoad: SSRF guard bypass via IPv6 6to4/NAT64 transition wrappers of internal IPs
GHSA-m5x5-28jr-gpjj
pkg: pyload-ng
eco: pip
published: Jul 9, 2026
## Summary

`is_global_address` in [`src/pyload/core/utils/web/check.py`](https://github.com/pyload/pyload/blob/1b12dc7f348db8c144e0f39215680415e90ca4d2/src/pyload/core/utils/web/check.py) is the central guard against SSRF-style outbound connections in pyload-ng. It tests whether a given IP is "glob…

CVE-2026-48737
NVD

MEDIUM
CVE-2026-14362
CVE-2026-14362
pkg: node

published: Jul 8, 2026

HashiCorp memberlist before version 0.6.0 is vulnerable to a denial-of-service issue in its push/pull state handling that may allow an attacker with network access to the gossip port to exhaust memory on a receiving node and cause the process to terminate. This vulnerability (CVE-2026-14362) is fixe…
CWE: CWE-770
GitHub-GHSA

MEDIUM
Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service
GHSA-f962-qm93-mj4c
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: Jul 6, 2026
### Summary

`NewDataBuilder` in `provisionersdk/proto/dataupload.go` allocated a byte slice using the client-supplied `FileSize` from a `DataUpload` message without an upper-bound check. Although the DRPC wire limit is 4 MiB, the `FileSize` value itself was unconstrained

### Impact

An authenticat…

CVE-2026-55079
NVD

MEDIUM
CVE-2026-53624
CVE-2026-53624
pkg: express

published: Jul 8, 2026

Fiber is an Express inspired web framework written in Go. Prior to 3.4.0, the helmet middleware in middleware/helmet/helmet.go never sets the Strict-Transport-Security response header even when HSTSMaxAge is configured because it checks c.Protocol() for https instead of c.Scheme(). This issue is fix…
CWE: CWE-319
NVD

MEDIUM
CVE-2026-59998
CVE-2026-59998
pkg: openbsd openssh

published: Jul 8, 2026

sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.
CWE: CWE-573
GitHub-GHSA

MEDIUM
GoFiber never set HSTS header in helmet middleware due to incorrect protocol check
GHSA-gv83-gqw6-9j2c
pkg: github.com/gofiber/fiber
eco: go
published: Jul 6, 2026
### Summary

The `helmet` middleware in gofiber/fiber never sets the `Strict-Transport-Security` (HSTS) response header, even when `HSTSMaxAge` is explicitly configured, because the condition check at `helmet.go:67` uses `c.Protocol()` — which returns the HTTP protocol version string (e.g., `"HTTP…

CVE-2026-53624
NVD

MEDIUM
CVE-2026-14620
CVE-2026-14620
pkg: webpack.js webpack-dev-server

published: Jul 3, 2026

webpack-dev-server versions 5.2.5 and earlier expose two internal developer endpoints, /webpack-dev-server/open-editor and /webpack-dev-server/invalidate, that perform state-changing actions on any GET request without verifying that the request originated from the dev server's own page. Any website …
CWE: CWE-352, CWE-749
NVD

MEDIUM
CVE-2026-46672
CVE-2026-46672
pkg: go

published: Jul 7, 2026

Actual is a local-first personal finance app. Prior to 26.6.0, @actual-app/cli ships a hand-rolled CSV serializer in packages/cli/src/output.ts used whenever the global –format csv option is passed, whose escapeCsv helper only handles RFC 4180 delimiter, quote, and newline escaping and does not neu…
CWE: CWE-1236
NVD

MEDIUM
CVE-2026-55798
CVE-2026-55798
pkg: python pillow

published: Jul 6, 2026

Pillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get_command() constructed a cmd.exe shell command by directly embedding a file path into an f-string without escaping and passed the result to subprocess.Popen(…, shell=True), allowing shell metacharacters in the file path to injec…
CWE: CWE-78
NVD

MEDIUM
CVE-2026-54776
CVE-2026-54776
pkg: windows

published: Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, a CoreWCF service hosted on Unix Domain Sockets with PosixIdentity client credentials can accept connections that skip the application/unixposix stream upgrade before dispatching m…
CWE: CWE-306
GitHub-GHSA

MEDIUM
DSpace: ORE resource URI does not validate scheme for non-web resources
GHSA-c827-pw3m-67w7
pkg: org.dspace:dspace-api, org.dspace:dspace-api, org.dspace:dspace-api
eco: maven
published: Jul 8, 2026
## Overview

When ingesting an aggregated ORE resource by URI (using the [OAI-ORE Harvester](https://wiki.lyrasis.org/spaces/DSDOC9x/pages/379125906/OAI#OAI-OAI-PMH/OAI-OREHarvester(Client))), the ORE Ingestion Crosswalk does not validate the URI scheme. This may allow for local file inclusion via m…

CVE-2026-49830
GitHub-GHSA

MEDIUM
printenv: environment variables with invalid UTF-8 are silently skipped (evades inspection)
GHSA-p7h3-7q52-72w8
pkg: uu_printenv
eco: rust
published: Jul 6, 2026
The printenv utility in uutils coreutils fails to display environment variables containing invalid UTF-8 byte sequences. While POSIX permits arbitrary bytes in environment strings, the uutils implementation silently skips these entries rather than printing the raw bytes. This vulnerability allows ma…
CVE-2026-35366
GitHub-GHSA

MEDIUM
cp: -R reads device nodes as streams, destroying device semantics
GHSA-8vrf-r662-2w2v
pkg: uu_cp
eco: rust
published: Jul 6, 2026
The cp utility in uutils coreutils, when performing recursive copies (-R), incorrectly treats character and block device nodes as stream sources rather than preserving them. Because the implementation reads bytes into regular files at the destination instead of using mknod, device semantics are dest…
CVE-2026-35358
GitHub-GHSA

MEDIUM
comm: FIFO/pipe inputs are drained before comparison (data loss / hang)
GHSA-3wfc-mgpm-9rq6
pkg: uu_comm
eco: rust
published: Jul 6, 2026
The comm utility in uutils coreutils incorrectly consumes data from non-regular file inputs before performing comparison operations. The are_files_identical function opens and reads from both input paths to compare content without first verifying if the paths refer to regular files. If an input path…
CVE-2026-35347
GitHub-GHSA

MEDIUM
id: groups= computed from real GID instead of effective GID
GHSA-47c7-qrm7-mqw7
pkg: uu_id
eco: rust
published: Jul 6, 2026
The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID to compute the group list, leading to potentially divergent output compared to GNU coreutils. Because many scripts and automated processes rely…
CVE-2026-35370
NVD

MEDIUM
CVE-2026-6440
CVE-2026-6440
pkg: oauth

published: Jul 10, 2026

The GoodMeet – Google Meet Integration for Webinar, Meeting & Video Conference plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.1.8. This is due to a missing nonce verification in the reset_credential() function, which handles the wp_ajax_goodmeet_…
CWE: CWE-352
NVD

MEDIUM
CVE-2026-4298
CVE-2026-4298
pkg: go

published: Jul 9, 2026

The DSGVO All in one for WP plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 4.9. This is due to the dsgvo_reset_policy_service_func() function lacking both capability checks and nonce verification while processing user-supplied parameters to reset plug…
CWE: CWE-862
NVD

MEDIUM
CVE-2026-15131
CVE-2026-15131
pkg: google chrome

published: Jul 8, 2026

Inappropriate implementation in Navigation in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-20
NVD

MEDIUM
CVE-2026-15130
CVE-2026-15130
pkg: google chrome

published: Jul 8, 2026

Insufficient policy enforcement in Navigation in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-602
NVD

MEDIUM
CVE-2026-15124
CVE-2026-15124
pkg: google chrome

published: Jul 8, 2026

Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-20
NVD

MEDIUM
CVE-2026-15108
CVE-2026-15108
pkg: google chrome

published: Jul 8, 2026

Integer overflow in Extensions API in Google Chrome prior to 150.0.7871.115 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory read via a crafted Chrome Extension. (Chromium security severity: High)
CWE: CWE-190
NVD

MEDIUM
CVE-2026-59930
CVE-2026-59930
pkg: mistune_project mistune

published: Jul 8, 2026

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the toc plugin and TableOfContents directive generate heading IDs as predictable toc_N values without slugifying the heading text, allowing attacker-controlled id="toc_N" content to collide with generated anchors and red…
CWE: CWE-345, CWE-1284
GitHub-GHSA

MEDIUM
Kite has an authenticated cluster RBAC bypass in /api/v1/overview
GHSA-gvhc-wv3v-7pf8
pkg: github.com/zxh326/kite
eco: go
published: Jul 7, 2026
## Summary

Authenticated Kite users with any role can request `/api/v1/overview` for a cluster that their roles do not permit by selecting that cluster with `x-cluster-name`. The overview route is registered before `middleware.RBACMiddleware()` and `GetOverview` only checks `len(user.Roles) > 0`, s…

CVE-2026-53487
NVD

MEDIUM
CVE-2026-46700
CVE-2026-46700
pkg: go

published: Jul 7, 2026

Actual is a local-first personal finance tool. Prior to 26.6.0, the GET /secret/:name endpoint in @actual-app/sync-server checks only that the caller has a valid session and does not verify the caller is an admin, while the sibling POST /secret/ handler enforces an admin check in OpenID mode. Any au…
CWE: CWE-285
GitHub-GHSA

MEDIUM
Open WebUI has Blind Server Side Request Forgery in its Image Edit Functionality
GHSA-jgx9-jr5x-mvpv
pkg: open-webui
eco: pip
published: Jul 7, 2026
### Summary
There is a blind server side request forgery in the functionality that allows editing an image via a prompt. The affected function will perform a GET request on the URL provided by the user. There is no restriction on the domain of the provided URL allowing the local address space to be …
CVE-2026-34225
GitHub-GHSA

MEDIUM
OpenRemote read-only asset users can write predicted datapoints
GHSA-xj53-j257-hxvg
pkg: io.openremote:openremote-manager
eco: maven
published: Jul 6, 2026
# Summary

The predicted datapoint write endpoint allows users with only `read:assets` privileges to write predicted datapoints.

The endpoint:

“`text
PUT /api/{realm}/asset/predicted/{assetId}/{attributeName}
“`

accepts write requests from users lacking `write:assets`.

The implementation appea…

CVE-2026-49439
NVD

MEDIUM
CVE-2026-59997
CVE-2026-59997
pkg: openbsd openssh

published: Jul 8, 2026

internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.
CWE: CWE-1284
NVD

MEDIUM
CVE-2026-59996
CVE-2026-59996
pkg: openbsd openssh

published: Jul 8, 2026

scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.
CWE: CWE-23
NVD

MEDIUM
CVE-2026-59995
CVE-2026-59995
pkg: openbsd openssh

published: Jul 8, 2026

sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.
CWE: CWE-23
NVD

MEDIUM
CVE-2026-50179
CVE-2026-50179
pkg: go

published: Jul 7, 2026

Actual is a local-first personal finance tool. Prior to 26.6.0, exportToCSV and exportQueryToCSV in packages/loot-core/src/server/transactions/export/export-to-csv.ts pass user-controlled Payee, Notes, Account, and Category strings to csv-stringify with no cast callback and no formula-prefix neutral…
CWE: CWE-1236
NVD

MEDIUM
CVE-2026-14612
CVE-2026-14612
pkg: oauth

published: Jul 3, 2026

Two off-by-one errors in the FreeIPA ipa-otpd daemon's OAuth2 device authorization handler can cause out-of-bounds memory access when processing an oversized response from a configured external OAuth2/OIDC Identity Provider. An attacker who controls or can man-in-the-middle the IdP endpoint may be a…
CWE: CWE-787
NVD

MEDIUM
CVE-2026-56360
CVE-2026-56360
pkg: n8n n8n

published: Jul 8, 2026

n8n before versions 1.123.18 and 2.6.2 fails to verify HMAC-SHA256 signatures on Zendesk webhooks in the ZendeskTrigger node. Attackers who know the webhook URL can send unsigned POST requests to trigger workflows with arbitrary malicious data.
CWE: CWE-290
GitHub-GHSA

MEDIUM
psd-tools vulnerable to arbitrary file write via smart-object filename
GHSA-2rmg-vrx8-9j2f
pkg: psd-tools
eco: pip
published: Jul 9, 2026
# psd-tools: arbitrary file write/read via smart-object path traversal

## Summary

In `psd-tools` (all releases exposing the `SmartObject` API through **v1.17.0**), `SmartObject.save()` writes an embedded smart object to a path taken verbatim from the PSD file. Because that name is attacker-control…

CVE-2026-49836
GitHub-GHSA

MEDIUM
OpenRun: Redirect URL validation bypass using  //host  paths leads to Open Redirect
GHSA-h5g6-xmh4-hc37
pkg: github.com/openrundev/openrun
eco: go
published: Jul 9, 2026
### Summary
The restrictions on redirect URLs in `openrun` can be bypassed by attackers, leading to open redirect attacks.

### Details

In the current project, the referrer header value is used for subsequent redirects, so there is currently a validation for this redirect value. The current validat…

CVE-2026-55252
GitHub-GHSA

MEDIUM
pypdf: Possible infinite loop when processing threads/articles in writer
GHSA-g9xf-7f8q-9mcj
pkg: pypdf
eco: pip
published: Jul 9, 2026
### Impact

An attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires merging a file with threads/articles into a writer.

### Patches

This has been fixed in [pypdf==6.13.1](https://github.com/py-pdf/pypdf/releases/tag/6.13.1).

### Workarounds

If users…

CVE-2026-54651
GitHub-GHSA

MEDIUM
nebula-mesh: Host revocation is not durable – blocked/offboarded hosts can regain a valid certificate
GHSA-339v-266x-79xr
pkg: github.com/forgekeep/nebula-mesh
eco: go
published: Jul 9, 2026
## Summary

Two related authorization gaps let a host that should no longer be trusted obtain a fresh, valid Nebula certificate, because nebula-mgmt does not re-evaluate revocation/authorization state at certificate *issuance* time — only at poll time.

## 1. Blocklist not enforced at sign / re-en…

CVE-2026-53602
GitHub-GHSA

MEDIUM
pymonocypher: Potential heap buffer overflow on nb_blocks in argon2i_32 when provided buffer is too small
GHSA-8f95-v3jq-cj86
pkg: pymonocypher
eco: pip
published: Jul 9, 2026
### Impact
The argon2i_32 implementation does not check the nb_blocks size. If the caller does not provide a sufficiently large buffer based on the API contract, then argon2i_32 will write past the end of the buffer and possibly corrupt the heap.

### Patches
Fixed in 4.0.2.8, which now verifies th…

CVE-2026-53720
GitHub-GHSA

MEDIUM
OneRingBuf has a Use After Free Vulnerability
GHSA-q95x-7g78-rccv
pkg: oneringbuf
eco: rust
published: Jul 8, 2026
Affected versions of `oneringbuf` exposed the obsolete `IntoRef::into_ref` method through the public `IntoRef` trait. For heap-backed ring buffers, this method returned a `DroppableRef` handle.

`DroppableRef` stored an owning raw pointer created from `Box::into_raw`. Its `Clone` implementation copi…

GitHub-GHSA

MEDIUM
async-tar PAX extension-header desync enables tar entry/content smuggling
GHSA-35rm-7j9c-2f7m
pkg: async-tar
eco: rust
published: Jul 8, 2026
## Summary

`async-tar` v0.6.0 mis-applies a buffered PAX `size` extension to an intermediary
extension header (a GNU longname `L`, a GNU longlink `K`, or a PAX `x`/`g`
header) instead of to the next *file* entry. POSIX requires a PAX extended-header
record set to describe the next file entry, never…

CVE-2026-53600
GitHub-GHSA

MEDIUM
oasdiff does not enforce –allow-external-refs=false on the git-revision load path (SSRF / local file read)
GHSA-2jcc-mxv7-p3f9
pkg: github.com/oasdiff/oasdiff
eco: go
published: Jul 7, 2026
## Summary

From **v1.13.2** through **v1.18.0**, oasdiff did not enforce `–allow-external-refs=false` (library: `openapi3.Loader.IsExternalRefsAllowed = false`) when loading a spec from a **git revision** (the `rev:path` form, e.g. `main:openapi.yaml`). External `$ref`s were resolved on that load …

CVE-2026-53508
GitHub-GHSA

MEDIUM
Flask-Security-Too: WebAuthn reauthentication freshness bypass via cross-user assertion
GHSA-f66q-9rf6-8795
pkg: Flask-Security-Too
eco: pip
published: Jul 7, 2026
### Summary

Flask-Security-Too 5.8.0 and 5.8.1 mark a session as reauthentication-fresh after processing a WebAuthn assertion whose proven credential belongs to a different user than the currently authenticated session user. The check that `GHSA-97r5-pg8x-p63p` added on the OAuth reauthentication p…

GitHub-GHSA

MEDIUM
aiosmtplib vulnerable to SMTP command injection via CR/LF in sender/recipient address
GHSA-v3q9-hj7j-63hq
pkg: aiosmtplib
eco: pip
published: Jul 7, 2026
### Summary

`aiosmtplib`'s `SMTP.mail()`, `SMTP.rcpt()`, `SMTP.vrfy()` and `SMTP.expn()` send the caller-supplied email address to the server without rejecting embedded CR/LF (`\r\n`) bytes. An address that contains a CR/LF is written verbatim onto the SMTP control connection, so the bytes after th…

CVE-2026-53533
GitHub-GHSA

MEDIUM
ratex-parser has unbounded parser recursion that leads to stack overflow (process abort)
GHSA-4w5h-hx6r-28q7
pkg: ratex-parser
eco: rust
published: Jul 7, 2026
### Summary

RaTeX’s recursive-descent parser recurses one (or more) native stack frame per nesting level at `{`, `\left`, `\sqrt{`, `^{`, etc, with **no maximum depth limit**. A short, ~10 KB input of nested groups overflows the 8 MB main-thread stack and aborts the process. With `panic = "abort…

CVE-2026-53531
GitHub-GHSA

MEDIUM
netfoil has a domain name filter bypass via multiple questions
GHSA-59qp-cfj3-rp64
pkg: github.com/tinfoil-factory/netfoil
eco: go
published: Jul 7, 2026
### Summary
Potential bypass of domain name filter by crafting a DNS request with multiple questions, with the first question being legitimate.

### Impact
Depends on a local attackers ability to craft multiple questions and the remote DoH server supporting them.

GitHub-GHSA

MEDIUM
Open WebUI allows limited stored XSS vila uploaded html file
GHSA-8gh5-qqh8-hq3x
pkg: open-webui
eco: pip
published: Jul 7, 2026
### Summary
Low privileged users can upload HTML files which contain JavaScript code via the `/api/v1/files/` backend endpoint. This endpoint returns a file id, which can be used to open the file in the browser and trigger the JavaScript code in the user's browser. Under the default settings, files …
CVE-2025-46571
GitHub-GHSA

MEDIUM
Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile
GHSA-chwm-m7g7-685g
pkg: d7y.io/dragonfly/v2
eco: go
published: Jul 6, 2026
## Summary

The Dragonfly **scheduler**'s v1 gRPC service contains an unauthenticated Server-Side Request Forgery (SSRF). When a peer reports a successful download of a TINY task, the scheduler calls `Peer.DownloadTinyFile()` and issues an HTTP `GET` to a host and port taken verbatim from the attack…

CVE-2026-54637


Vulnerability Digest — June 29, 2026 · 80 Critical · 6 Exploited






Vulnerability Digest — Monday, June 29, 2026


Security Report

Monday, June 29, 2026  ·  Last 7 days  ·  Min severity: MEDIUM
Total Findings
466
Critical
80
High
217
Actively Exploited
6
CISA-KEV6
NVD236
GitHub-GHSA224
Findings sorted by severity
CISA-KEV

CRITICAL
PTC Windchill and FlexPLM Improper Input Validation Vulnerability
CVE-2026-12569
pkg: PTC Windchill and FlexPLM

published: Jun 25, 2026

PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability
CVE-2026-20230
pkg: Cisco Unified Communications Manager

published: Jun 25, 2026

Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an unauthenticated, remote attacker to write files to the underlying operating system tha…
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Lantronix EDS5000 Code Injection Vulnerability
CVE-2025-67038
pkg: Lantronix EDS5000

published: Jun 23, 2026

Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Ubiquiti UniFi OS Improper Input Validation Vulnerability
CVE-2026-34910
pkg: Ubiquiti UniFi OS

published: Jun 23, 2026

Ubiquiti UniFi OS contains an improper input validation vulnerability which could allow a malicious actor with access to the network to conduct command injection.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Ubiquiti UniFi OS Path Traversal Vulnerability
CVE-2026-34909
pkg: Ubiquiti UniFi OS

published: Jun 23, 2026

Ubiquiti UniFi OS contains a path traversal vulnerability which could allow a malicious actor with access to the network to access files on the underlying system that could be manipulated to access an underlying account.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Ubiquiti UniFi OS Improper Access Control Vulnerability
CVE-2026-34908
pkg: Ubiquiti UniFi OS

published: Jun 23, 2026

Ubiquiti UniFi OS contains an improper access control vulnerability which could allow a malicious actor with access to the network to make unauthorized changes to the system.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
NVD

CRITICAL
CVE-2026-53576
CVE-2026-53576
pkg: docker

published: Jun 26, 2026

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the authentication filter for the REST API (@Filter("/api/v1/**")) treats any request whose path ends in /configs as the public instance-config endpoint and forwards it without a credential check. kestra addre…
CWE: CWE-94, CWE-288
GitHub-GHSA

CRITICAL
mcp-pinot: Unauthenticated tool invocation via default oauth_enabled=False + host 0.0.0.0 bind
GHSA-73cv-556c-w3g6
pkg: mcp-pinot-server
eco: pip
published: Jun 26, 2026
## Resolution

Fixed in [v3.1.0](https://github.com/startreedata/mcp-pinot/releases/tag/v3.1.0), released 2026-05-25. The fix was merged in [PR #95](https://github.com/startreedata/mcp-pinot/pull/95) at commit [`1c7d3f9`](https://github.com/startreedata/mcp-pinot/commit/1c7d3f9cd384854bf72c127d230bd…

CVE-2026-49257
GitHub-GHSA

CRITICAL
golang.org/x/crypto/ssh: Invoking VerifiedPublicKeyCallback permissions skip enforcement
GHSA-x527-x647-q7gg
pkg: golang.org/x/crypto/ssh
eco: go
published: Jun 25, 2026
Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.
CVE-2026-46595
NVD

CRITICAL
CVE-2026-53622
CVE-2026-53622
pkg: traefik traefik

published: Jun 23, 2026

Traefik is an HTTP reverse proxy and load balancer. Prior to 3.7.3, there is a critical vulnerability in Traefik's HTTP/3 (QUIC) TLS configuration selection that allows unauthenticated clients to bypass router-specific mTLS enforcement. When HTTP/3 is enabled on an entrypoint, the TLS handshake sele…
CWE: CWE-288
NVD

CRITICAL
CVE-2026-48491
CVE-2026-48491
pkg: traefik traefik

published: Jun 23, 2026

Traefik is an HTTP reverse proxy and load balancer. From 3.7.0 until 3.7.3, there is a high severity vulnerability in Traefik's domain-fronting protection (SNICheck) that allows an unauthenticated client to bypass mutual TLS enforced through wildcard router TLSOptions. When a router uses a wildcard …
CWE: CWE-288
GitHub-GHSA

CRITICAL
Budibase has nonymous NoSQL operator injection via published-app query templates
GHSA-8qv3-p479-cj62
pkg: @budibase/server
eco: npm
published: Jun 23, 2026
## Summary

`enrichContext` at `packages/server/src/sdk/workspace/queries/queries.ts:121-138` substitutes parameter values into the raw JSON body of a query, then `JSON.parse`s the result. The validator `validateQueryInputs` at `packages/server/src/api/controllers/query/index.ts:61-71` rejects only …

CVE-2026-54350
GitHub-GHSA

CRITICAL
Gogs has Path Traversal in organization name that results in RCE through Git hooks
GHSA-c39w-43gm-34h5
pkg: gogs.io/gogs
eco: go
published: Jun 23, 2026
### Summary

Organization names containing path traversal sequences (`../`) are accepted by Gogs, and repositories under them are written to paths following these path traversals. This allows storing/retrieving data for repositories at arbitrary locations on the filesystem.
By creating nested struct…

CVE-2026-52813
NVD

CRITICAL
CVE-2026-10561
CVE-2026-10561
pkg: langflow langflow

published: Jun 22, 2026

IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arbitrary code on the host system, resulting in complete compromise
CWE: CWE-94
NVD

CRITICAL
CVE-2026-58053
CVE-2026-58053
pkg: docker

published: Jun 28, 2026

Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig and, when configured with privileged: false, forces only the Privileged flag off while merging options such as –pid=host, –cap-add, and –security-op…
CWE: CWE-269
GitHub-GHSA

CRITICAL
Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check
GHSA-q6xx-5vr8-p898
pkg: github.com/nezhahq/nezha, github.com/nezhahq/nezha
eco: go
published: Jun 26, 2026
### Summary

In nezha **v1.14.13–v1.14.14** and **v2.0.0–v2.0.9**, the WebSocket endpoints `GET /ws/terminal/:id` and `GET /ws/file/:id` authenticate the caller only by the presence of a valid stream UUID, with no ownership check tying that UUID to the user who created the stream. Any authentica…

GitHub-GHSA

CRITICAL
deepstream is vulnerable to prototype pollution
GHSA-9v98-6g37-x9g6
pkg: @deepstream/server
eco: npm
published: Jun 26, 2026
### Impact
Prototype pollution in deepstream server v <=10.0.4. Potential privilege escalation from any authenticated user with write permission to any record.

### Patches
Yes, upgrade to v10.0.5

### Workarounds
Filter out all messages containing the path `__proto__`, `constructor`, `prototype`, *…

CVE-2026-49252
NVD

CRITICAL
CVE-2026-46386
CVE-2026-46386
pkg: docker

published: Jun 26, 2026

OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docker image ships ENV SECRET_KEY_BASE=OVERWRITE_ME as the default Rails master key. Combined with cookies_serializer = :marshal, this gives any logged-in user a deterministic Marshal-d…
CWE: CWE-502, CWE-798, CWE-1188, CWE-1392
GitHub-GHSA

CRITICAL
Incus has an arbitrary file write on its client due to trusted image hash
GHSA-f6m5-xw2g-xc4x
pkg: github.com/lxc/incus/v7/cmd/incusd
eco: go
published: Jun 26, 2026
### Summary

An arbitrary file write exists in the Incus client when a malicious image server returns a crafted `Incus-Image-Hash` header. This can lead to arbitrary command execution as root on the server.

### Details

– `cmd/incusd/images.go:611-684` handles `source.type=url` by HEADing the user…

CVE-2026-48769
GitHub-GHSA

CRITICAL
Incus has an argument injection in backup compression algorithm leading to AFW and ACE
GHSA-v6mj-8pf4-hhw4
pkg: github.com/lxc/incus/v7/cmd/incusd
eco: go
published: Jun 26, 2026
### Summary

Improper validation of user-provided backup compression algorithm leads to argument injection in the constructed command line. This leads to an arbitrary file write on the host, possibly leading to arbitrary command execution.

### Details

Incus validates `compression_algorithm` by pa…

CVE-2026-48755
GitHub-GHSA

CRITICAL
Incus has an arbitrary file write via path traversal in S3 multipart upload
GHSA-ccjc-4qc3-jxqc
pkg: github.com/lxc/incus/v7/cmd/incusd
eco: go
published: Jun 26, 2026
## Summary

The S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. This behavior could lead to arbitrary command execution.

In `internal/server/storage/s3/local/multipart.go`, user-controlled upload ID is appended to the uploads directory…

CVE-2026-48753
GitHub-GHSA

CRITICAL
Incus has arbitrary file read+write on host via templates/ symlink in malicious image
GHSA-vxp5-584q-c479
pkg: github.com/lxc/incus/v7/cmd/incusd
eco: go
published: Jun 26, 2026
### Summary

A specially crafted image or instance backup can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution.

### Details

For container images, `internal/server/storage/utils.go` calls `archive.Unpack(imageFile, destPath, …)`. The ta…

CVE-2026-48752
GitHub-GHSA

CRITICAL
Incus has a restricted project bypass leading to arbitrary command execution
GHSA-48q5-w887-33wv
pkg: github.com/lxc/incus/v7/cmd/incusd
eco: go
published: Jun 26, 2026
### Summary

Instance snapshots ignore the `restricted.containers.lowlevel=block` setting; allowing for arbitrary command execution on the Incus server by abusing lowlevel hooks such as `raw.lxc` and `raw.qemu`.

### Details

Instance snapshots ignore the `restricted.containers.lowlevel=block` sett…

CVE-2026-48751
GitHub-GHSA

CRITICAL
Incus has an arbitrary file write on host via `exec-output` symlink in crafted image
GHSA-73hr-m85f-64v9
pkg: github.com/lxc/incus/v7/cmd/incusd
eco: go
published: Jun 26, 2026
### Summary

The `record-output` parameter of the `/instances/$name/exec` endpoint stores the output of the command in the `exec-output` directory of the instance. If `exec-output` is a symlink, file named `exec_UUID.stdout` and `exec_UUID.stderr` can be written to an arbitrary location where the `.…

CVE-2026-48750
GitHub-GHSA

CRITICAL
Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious image
GHSA-2q3f-q5pq-g8wv
pkg: github.com/lxc/incus/v7/cmd/incusd
eco: go
published: Jun 26, 2026
### Summary

A specially crafted image can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution.

### Details

Incus validates an image as soon as it sees a normal `metadata.yaml` and a `rootfs/` entry, but full extraction can later process a …

CVE-2026-48749
GitHub-GHSA

CRITICAL
Lemur: ACME SSRF + creator-equality IDOR lead to AWS IAM/PKI compromise
GHSA-v2wp-frmc-5q3v
pkg: lemur
eco: pip
published: Jun 25, 2026
<!– obsidian –><h1 data-heading="Lemur 1.9.0: any SSO-authenticated user achieves AWS IAM compromise and permanent PKI key access via ACME acme_url SSRF and creator-equality IDOR">Lemur 1.9.0: any SSO-authenticated user achieves AWS IAM compromise and permanent PKI key access via ACME acme_url SSR…
CVE-2026-55166
NVD

CRITICAL
CVE-2026-55454
CVE-2026-55454
pkg: appsmith appsmith

published: Jun 24, 2026

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the bundled Caddy reverse-proxy's admin API — which has no authentication by default — is bound on 0.0.0.0:2019 inside the container. While this listener is not directly published to the host by docker-co…
CWE: CWE-749, CWE-1188
NVD

CRITICAL
CVE-2026-54305
CVE-2026-54305
pkg: n8n n8n

published: Jun 23, 2026

n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, three EE endpoints used by the Dynamic Credentials feature accepted any authenticated n8n session without performing per-resource ownership or scope checks on the target workflow or credential. An authenticate…
CWE: CWE-200, CWE-284
NVD

CRITICAL
CVE-2026-44791
CVE-2026-44791
pkg: n8n n8n

published: Jun 23, 2026

n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with permission to create or modify workflows could bypass the patch for CVE-2026-42232 in the XML node. When combined with other nodes, this could lead to RCE on the n8n host. This vulne…
CWE: CWE-1321
NVD

CRITICAL
CVE-2026-44789
CVE-2026-44789
pkg: n8n n8n

published: Jun 23, 2026

n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with permission to create or modify workflows could achieve global prototype pollution via an unvalidated pagination parameter in the HTTP Request node. Combined with other techniques thi…
CWE: CWE-1321
GitHub-GHSA

CRITICAL
Gogs vulnerable to RCE via git rebase –exec argument injection in pull request merge
GHSA-qf6p-p7ww-cwr9
pkg: gogs.io/gogs
eco: go
published: Jun 23, 2026
# Gogs: RCE via `git rebase –exec` Argument Injection in PR Merge

## Summary

Gogs allows authenticated users to achieve Remote Code Execution (RCE) on the server by creating a pull request with a specially crafted branch name that injects the `–exec` flag into the `git rebase` command during the…

CVE-2026-52806
NVD

CRITICAL
CVE-2026-54310
CVE-2026-54310
pkg: n8n n8n

published: Jun 23, 2026

n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, an authenticated user with permission to create or modify workflows could supply a crafted parameters to the TimescaleDB and/or legacy Postgres v1 node's allowing arbitrary SQL to be injected and executed against the con…
CWE: CWE-89
GitHub-GHSA

CRITICAL
xwiki-pro-macros has remote code execution from page title and content via excerpt-include macro
GHSA-w56x-9778-rppx
pkg: com.xwiki.pro:xwiki-pro-macros
eco: maven
published: Jun 22, 2026
### Summary
The excerpt-include macro does not properly escape the title of the included page and executes the content of the excerpt with the macro's rights. Therefore, it is vulnerable to XWiki syntax injection via the included page's title and content, allowing remote code execution for any user …
CVE-2026-44179
GitHub-GHSA

CRITICAL
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
GHSA-44hj-4m45-frj3
pkg: fluentd
eco: rubygems
published: Jun 26, 2026
Fluentd allows dynamically constructing file paths using the `${tag}` placeholder.
It was discovered that validation for this placeholder was insufficient.

If a Fluentd instance is configured to receive logs from untrusted sources and uses the `${tag}` placeholder in file configurations (such as th…

CVE-2026-44024
NVD

CRITICAL
CVE-2026-0685
CVE-2026-0685
pkg: express

published: Jun 26, 2026

Server side template inject (SSTI) in the expression evaluation component in Genshi Template Engine version 0.7.9 allows a remote attacker to achieve remote code execution (RCE) via crafted template expressions.
NVD

CRITICAL
CVE-2026-48930
CVE-2026-48930
pkg: nodejs node.js

published: Jun 26, 2026

A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings.

This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CWE: CWE-284
NVD

CRITICAL
CVE-2026-7531
CVE-2026-7531
pkg: wolfssl wolfssl

published: Jun 25, 2026

Use-after-free in PQC hybrid key-share handling. This is an incomplete-fix follow-up to CVE-2026-5460 (released in 5.9.1): a malicious TLS 1.3 server sending a truncated PQC hybrid KeyShare can still trigger the error cleanup path to operate on freed memory.
CWE: CWE-416
NVD

CRITICAL
CVE-2026-52955
CVE-2026-52955
pkg: linux

published: Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

libceph: Fix potential out-of-bounds access in crush_decode()

A message of type CEPH_MSG_OSD_MAP containing a crush map with at least
one bucket has two fields holding the bucket algorithm. If the values
in these two fields differ…

NVD

CRITICAL
CVE-2026-56121
CVE-2026-56121
pkg: python

published: Jun 24, 2026

Feast before 0.63.0 contains an unsafe deserialization vulnerability that allows unauthenticated or unauthorized attackers to achieve remote code execution by sending a crafted gRPC request to the registry server. The user_defined_function.body field of an OnDemandFeatureView spec is decoded from ba…
CWE: CWE-502
NVD

CRITICAL
CVE-2026-52931
CVE-2026-52931
pkg: linux

published: Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

batman-adv: tp_meter: avoid use of uninit sender vars

batadv_tp_recv_ack() and batadv_tp_stop() are only valid for tp_vars in the
BATADV_TP_SENDER role. When called with a BATADV_TP_RECEIVER role, it
proceeds to read sender-only m…

NVD

CRITICAL
CVE-2026-52924
CVE-2026-52924
pkg: linux

published: Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

sctp: purge outqueue on stale COOKIE-ECHO handling

sctp_stream_update() is only invoked when the association is moved into
COOKIE_WAIT during association setup/reconfiguration. In this path, the
outbound stream scheduler state (st…

NVD

CRITICAL
CVE-2026-52914
CVE-2026-52914
pkg: linux

published: Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

batman-adv: fix fragment reassembly length accounting

batman-adv keeps a running payload length for queued fragments and uses it
to validate a fragment chain before reassembly.

That accounting currently allows the accumulated fra…

NVD

CRITICAL
CVE-2026-53753
CVE-2026-53753
pkg: python

published: Jun 23, 2026

Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.7, the _safe_eval_expression() function in the computed fields feature uses an AST validator that only blocks attributes starting with underscore. Python generator and frame object attributes (gi_frame, f_back, f_builtins) d…
CWE: CWE-94, CWE-913
GitHub-GHSA

CRITICAL
motionEye: LFI → pass‑the‑hash admin → unsafe restore → unauth action exec (RCE)
GHSA-qxvg-h7q2-hcxh
pkg: motioneye
eco: pip
published: Jun 23, 2026
## Summary
A multi‑stage chain in motionEye leads to remote code execution. The chain combines:

1. **Arbitrary file read (LFI)** via the picture download endpoint for **local motion cameras** using absolute paths.
2. **Pass‑the‑hash admin auth** due to accepting request signatures computed wi…

NVD

CRITICAL
CVE-2026-56315
CVE-2026-56315
pkg: python

published: Jun 23, 2026

picklescan before 1.0.4 fails to block at least seven Python standard library modules (including uuid, _osx_support, _aix_support, _pyrepl.pager, and imaplib) exposing eight functions that provide direct arbitrary command execution. Attackers can craft malicious pickle files importing these unblocke…
CWE: CWE-184
NVD

CRITICAL
CVE-2026-12866
CVE-2026-12866
pkg: express

published: Jun 23, 2026

All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. An attacker can execute arbitrary JavaScript by supplying crafted expressions that are compiled into native code using new Function(). Because user-controlled expressions are transformed directly into …
CWE: CWE-94, CWE-94
NVD

CRITICAL
CVE-2026-33646
CVE-2026-33646
pkg: python

published: Jun 26, 2026

mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.3.10, mise processes .tool-versions files through the Tera template engine during parsing, with the exec() function registered, enabling arbitrary command execution. Unlike .mise.toml files, .tool-versions files are not su…
CWE: CWE-94
NVD

CRITICAL
CVE-2026-13032
CVE-2026-13032
pkg: google chrome, google android

published: Jun 24, 2026

Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

CRITICAL
CVE-2026-13028
CVE-2026-13028
pkg: google chrome, google android

published: Jun 24, 2026

Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

CRITICAL
CVE-2026-11807
CVE-2026-11807
pkg: oauth

published: Jun 23, 2026

A missing authorization vulnerability was found in the Event-Driven Ansible (EDA) websocket API. The /api/eda/ws/ansible-rulebook endpoint does not verify user permissions when processing Worker messages. Any authenticated user can send a forged message with an arbitrary activation_id to receive pla…
CWE: CWE-862, CWE-862
NVD

CRITICAL
CVE-2026-55447
CVE-2026-55447
pkg: langflow langflow

published: Jun 23, 2026

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, by controlling a files that are digested into the RAG, an attacker can direct the node to read any file on the file-system by absolute path. All components based on BaseFileComponent are vulnerable to the …
CWE: CWE-61, CWE-200
NVD

CRITICAL
CVE-2026-48519
CVE-2026-48519
pkg: langflow langflow

published: Jun 23, 2026

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, the "Shareable Playground" (or "Public Flows" in code) contains a critical RCE vulnerability. Shareable Playground feature works by enabling the execution of workflows by unauthenticated users, by accessin…
CWE: CWE-94
GitHub-GHSA

CRITICAL
Budibase has arbitrary file read by workspace-builder via PWA-zip symlink upload
GHSA-w7mq-r738-x278
pkg: @budibase/server
eco: npm
published: Jun 22, 2026
## Summary

`POST /api/pwa/process-zip` at `packages/server/src/api/routes/static.ts:24` accepts a builder-uploaded `.zip`, extracts it with `extract-zip@2.0.1` into a temp directory, then for each entry listed in `icons.json` validates the icon path, opens it, and streams the bytes into MinIO. The …

CVE-2026-54352
GitHub-GHSA

CRITICAL
Mise Vulnerable to Arbitrary Code Execution via Tera Templates in .tool-versions Files (Trust Bypass)
GHSA-fjj5-v948-whjj
pkg: mise
eco: rust
published: Jun 22, 2026
## Summary

Mise processes `.tool-versions` files through the Tera template engine during parsing, with the `exec()` function registered, enabling arbitrary command execution. Unlike `.mise.toml` files, `.tool-versions` files are **not subject to trust verification** in non-paranoid mode. This means…

CVE-2026-33646
GitHub-GHSA

CRITICAL
OpenAM has pre-auth Reflected XSS in OAuth2 / OIDC response_mode=form_post via state parameter (FormPostResponse.ftl)
GHSA-fq9h-c788-fx73
pkg: org.openidentityplatform.openam:openam-oauth2
eco: maven
published: Jun 22, 2026
### Summary

The OAuth 2.0 / OpenID Connect authorization endpoint does not sufficiently sanitize certain user-supplied parameters before incorporating them into the HTML response generated for the `form_post` response mode. This may allow an attacker to inject content into the rendered page in the …

CVE-2026-44203
GitHub-GHSA

CRITICAL
Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key
GHSA-5c25-7vpj-9mqh
pkg: github.com/nezhahq/nezha
eco: go
published: Jun 26, 2026
### Summary
`fallbackToFrontend` in the dashboard's `NoRoute` handler treats any URL whose **raw string** starts with `/dashboard` as an admin-frontend asset request. The check uses `strings.HasPrefix`, not a path-segment match, so the input `/dashboard../data/config.yaml` is accepted; `strings.Trim…
CVE-2026-53519
GitHub-GHSA

CRITICAL
golang.org/x/crypto/ssh/knownhosts vulnerable to auth bypass via unenforced @revoked status
GHSA-5cgq-3rg8-m6cv
pkg: golang.org/x/crypto/ssh/knownhosts
eco: go
published: Jun 25, 2026
Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.
CVE-2026-42508
GitHub-GHSA

CRITICAL
golang.org/x/crypto/ssh vulnerable to infinite loop on large channel writes
GHSA-rm3j-f69w-wqmq
pkg: golang.org/x/crypto/ssh
eco: go
published: Jun 25, 2026
When writing data larger than 4GB in a single Write call on an SSH channel, an integer overflow in the internal payload size calculation caused the write loop to spin indefinitely, sending empty packets without making progress. The size comparison now uses int64 to prevent truncation.
CVE-2026-39834
GitHub-GHSA

CRITICAL
golang.org/x/crypto/ssh: FIDO/U2F security key physical presence check can be bypassed
GHSA-89gr-r52h-f8rx
pkg: golang.org/x/crypto/ssh
eco: go
published: Jun 25, 2026
The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not check the User Presence flag. Signatures generated without physical touch were accepted, allowing unattended use of a hardware security key. To restore the previous behavior, …
CVE-2026-39831
GitHub-GHSA

CRITICAL
golang.org/x/crypto/ssh: Invoking client can cause server deadlock on unexpected responses
GHSA-vgwf-h737-ff37
pkg: golang.org/x/crypto/ssh
eco: go
published: Jun 25, 2026
A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded.
CVE-2026-39830
GitHub-GHSA

CRITICAL
golang.org/x/crypto/ssh/agent doesn't drop invoking agent constraints when forwarding keys
GHSA-f5wc-c3c7-36mc
pkg: golang.org/x/crypto/ssh/agent
eco: go
published: Jun 25, 2026
When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all cons…
CVE-2026-39832
GitHub-GHSA

CRITICAL
golang.org/x/crypto/ssh/agent doesn't enforce invoking key constraints
GHSA-jppx-rxg9-jmrx
pkg: golang.org/x/crypto/ssh/agent
eco: go
published: Jun 25, 2026
The in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but never enforced it. The key would sign without any confirmation prompt, with no indication to the caller that the constraint was not in effect. NewKeyring() now returns an error when unsuppo…
CVE-2026-39833
GitHub-GHSA

CRITICAL
i18next-fs-backend vulnerable to prototype pollution via crafted missing-key string
GHSA-2933-q333-qg83
pkg: i18next-fs-backend
eco: npm
published: Jun 25, 2026
### Impact

`i18next-fs-backend` ≤ 2.6.5, when used to persist missing translation keys (e.g. via `i18next-http-middleware`'s `missingKeyHandler` exposed to untrusted input), is vulnerable to prototype pollution via crafted missing-key strings.

`Backend.writeFile()` splits each queued missing-key…

CVE-2026-48713
GitHub-GHSA

CRITICAL
i18next-http-middleware: MissingKeyHandler does not reject keys whose segments contain prototype-polluting names
GHSA-f49m-vf83-692w
pkg: i18next-http-middleware
eco: npm
published: Jun 25, 2026
### Impact

`i18next-http-middleware` ≤ 3.9.6's `missingKeyHandler` blocked the literal request-body keys `__proto__`, `constructor`, and `prototype` (added in 3.9.3, see GHSA-5fgg-jcpf-8jjw), but did not reject dotted variants such as `"__proto__.polluted"`. Downstream backends that split the mis…

CVE-2026-48714
NVD

CRITICAL
CVE-2026-45689
CVE-2026-45689
pkg: oauth

published: Jun 24, 2026

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, an unauthenticated network attacker obtains a valid Rocket.Chat OAuth access token for an arbitrary user by sending a single HTTP POST with Mongo…
CWE: CWE-943
GitHub-GHSA

CRITICAL
scimPatch vulnerable to prototype pollution via unfiltered keys in patch
GHSA-9m6g-wc8r-q59c
pkg: scim-patch
eco: npm
published: Jun 22, 2026
## Summary

`scim-patch` performs prototype pollution when applying a SCIM PATCH operation whose `value` object contains a key like `"__proto__.someProp"`. After one such patch,
`Object.prototype.someProp` is set process-wide, affecting every plain object in the Node process.

Any service that calls…

CVE-2026-48170
NVD

CRITICAL
CVE-2026-12628
CVE-2026-12628
pkg: ibm storage_protect

published: Jun 22, 2026

IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows 8.1.0.0 through 8.2.1.0 could allow a remote attacker to bypass authentication due to the use of a hardcoded credential in the FlashCopy Manager (FCM) authentication mechanism. The application contains a …
CWE: CWE-798
NVD

CRITICAL
CVE-2026-54636
CVE-2026-54636
pkg: dokku dokku

published: Jun 26, 2026

Dokku is a docker-powered PaaS. Prior to 0.38.7, the cron plugin utilizes commands in the app.json file to manage system cron running as the Dokku user. An app.json cron command utilizing special shell characters – including, but not limited to, > or ; – can break out of the Docker container and exe…
CWE: CWE-78
NVD

CRITICAL
CVE-2026-45408
CVE-2026-45408
pkg: dokku dokku

published: Jun 26, 2026

Dokku is a docker-powered PaaS. Prior to 0.38.2, the app name validation regex (^[a-z0-9][^/:_A-Z]*$) permits shell metacharacters. When an authenticated user pushes to a git remote with a crafted app name, the name is embedded unquoted into a bash pre-receive hook script via an unquoted heredoc (<<…
CWE: CWE-78
NVD

CRITICAL
CVE-2026-45406
CVE-2026-45406
pkg: dokku dokku

published: Jun 26, 2026

Dokku is a docker-powered PaaS. Prior to 0.38.2, the openresty-vhosts plugin copies files from an app's openresty/http-includes/ git repository directory to the host and then interpolates their filenames, unescaped, into a single-quoted shell string that is later parsed by eval. A filename containin…
CWE: CWE-95
NVD

CRITICAL
CVE-2026-45405
CVE-2026-45405
pkg: dokku dokku

published: Jun 26, 2026

Dokku is a docker-powered PaaS. Prior to 0.38.2, the git:from-archive and certs:add commands extract user-supplied tar/zip archives into temporary directories without sanitizing member paths or preventing symlink traversal. GNU tar creates symlinks during extraction and follows them for subsequent e…
CWE: CWE-59
NVD

CRITICAL
CVE-2026-12249
CVE-2026-12249
pkg: tls

published: Jun 22, 2026

An issue was discovered in Canonical ADSys upstream versions through v0.16.2. During Active Directory Certificate Services (AD CS) certificate auto-enrollment via the vendored Samba client script (internal/policies/certificate/python/vendor_samba/gp/gp_cert_auto_enroll_ext.py), ADSys utilizes a plai…
CWE: CWE-348
GitHub-GHSA

CRITICAL
semantic-router exposed to compromised litellm wheel (CVE-2026-42208) via unbounded transitive pin
GHSA-98×5-vq43-vc5p
pkg: semantic-router
eco: pip
published: Jun 26, 2026
## Impact
semantic-router versions 0.1.8 through 0.1.14 declare `litellm>=1.61.3` with no upper bound. During the window in which `litellm==1.82.8` was the latest release on PyPI, a fresh install of any affected semantic-router version could resolve to that compromised wheel.

The malicious `litellm…

GitHub-GHSA

CRITICAL
Backpropagate: backprop ui –auth and backprop ui –share do not enforce authentication
GHSA-f65r-h4g3-3h9h
pkg: backpropagate, @mcptoolshop/backpropagate
eco: npm
published: Jun 26, 2026
## Summary

In `backpropagate >= 1.1.0`, the optional Reflex web UI (`pip install backpropagate[ui]`, launched via `backprop ui`) exposes a training control plane: dataset upload, model load, training start/stop, multi-run orchestration, GGUF export, and HuggingFace Hub push.

The CLI accepts two op…

CVE-2026-48797
GitHub-GHSA

CRITICAL
OpenAM Pre-auth User Profile Tampering via Anonymous SOAP Authn in Liberty IDPP/Discovery Endpoints
GHSA-p462-xxwx-pqf4
pkg: org.openidentityplatform.openam:openam-federation-library
eco: maven
published: Jun 24, 2026
## Summary

**Description**

An Improper Authorization (CWE-285) issue in OpenAM's Liberty Web Services SOAP receiver allows an unauthenticated remote attacker to write persistent entries into the Liberty Discovery store on any user's LDAP entry, and into a shared root-realm Discovery branch. This i…

CVE-2026-45052
GitHub-GHSA

CRITICAL
OpenAM: Pre-auth RCE via Java Deserialization in WebAuthn Authenticator Storage
GHSA-6c99-87fr-6q7r
pkg: org.openidentityplatform.openam:openam-auth-webauthn
eco: maven
published: Jun 24, 2026
## Summary

**Description**

A deserialization of untrusted data vulnerability (CWE-502) exists in OpenAM's WebAuthn authentication module. Under certain conditions, this may allow an attacker to achieve arbitrary code execution in the context of the application server. This affects OpenAM Community…

CVE-2026-45051
GitHub-GHSA

CRITICAL
motionEye Partial Authentication Bypass: Unauthenticated Admin Credential Theft via Path Traversal
GHSA-phv5-334h-mxcw
pkg: motioneye
eco: pip
published: Jun 23, 2026
# Partial Authentication Bypass: Unauthenticated Admin Credential Theft via Path Traversal

### Summary

Myself and others have reported several RCE vulnerabilities to this project. However, due to the nature of the app, these are largely not of all that much value, as there is built-in functionalit…

GitHub-GHSA

CRITICAL
Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym
GHSA-89mr-xqfv-758m
pkg: gogs.io/gogs
eco: go
published: Jun 23, 2026
Summary

`(*Repository).UploadRepoFiles` checks for symlinks only on the **leaf** of the upload target (`osx.IsSymlink(targetPath)`). The siblings `UpdateRepoFile`, `DeleteRepoFile`, and `GetDiffPreview` use `hasSymlinkInPath`, which lstats every component — `UploadRepoFiles` is the lone outlier. …

CVE-2026-52811
GitHub-GHSA

CRITICAL
OpenDJ Pre-Auth RCE via Java Deserialization in JMX RMI
GHSA-43×2-g84q-fmqx
pkg: org.openidentityplatform.opendj:opendj-server-legacy
eco: maven
published: Jun 22, 2026
## Summary

**Description**

A Deserialization of Untrusted Data (CWE-502) issue in OpenDJ's JMX RMI connector allows an unauthenticated remote attacker to deserialize arbitrary Java objects on the server. The vulnerability exists because the platform reads and processes attacker-controlled bytes pr…

CVE-2026-46495
GitHub-GHSA

CRITICAL
motionEye: Authentication possible via password hash
GHSA-r3cw-c95m-wfh9
pkg: motioneye
eco: pip
published: Jun 22, 2026
### Summary
An authentication bypass vulnerability exists due to improper trust in client-controlled cookies. The application accepts user-supplied cookie values containing a username and password-hash-derived value as sufficient authentication material. These cookies can be set or modified prior to…
CVE-2026-46488
GitHub-GHSA

HIGH
Gogs has Stored XSS in `.ipynb` Preview
GHSA-jq8v-rmf6-65jw
pkg: gogs.io/gogs
eco: go
published: Jun 22, 2026
# Summary

Although `.ipynb` previews are sanitized on the server side via `/-/api/sanitize_ipynb`, the inserted content is **re-rendered on the client side without sanitization** using `marked()` on elements with the `.nb-markdown-cell` class. During this process, links containing schemes such as `…

CVE-2026-52798
GitHub-GHSA

HIGH
pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes
GHSA-w466-c33r-3gjp
pkg: pnpm, pnpm
eco: npm
published: Jun 26, 2026
<!– maintainer-action:start –>
## Maintainer Action Plan

This report is ready to review with the shared patch branch. Start with the PR and the expected fixed behavior, then use the detailed exploit narrative below only if you want to replay the original path.

– Advisory: `CAND-PNPM-063` / `GHSA…

CVE-2026-55698
GitHub-GHSA

HIGH
pnpm: Transitive dependency alias path traversal allows project path override via symlink replacement
GHSA-hwx4-2j3j-g496
pkg: pnpm, pnpm
eco: npm
published: Jun 26, 2026
## Summary

pnpm allows a transitive dependency alias from registry package metadata to contain path traversal segments. During install, pnpm later uses that alias as a filesystem path when linking dependency nodes. As a result, a registry package can cause `pnpm install – ignore-scripts` to replace…

CVE-2026-50016
GitHub-GHSA

HIGH
Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete)
GHSA-c6v2-3ffm-vcmc
pkg: github.com/juev/nebula-mesh
eco: go
published: Jun 26, 2026
## Summary

The web UI (`/ui/*`) does not apply the per-operator CA scoping the JSON API received for GHSA-598g-h2vc-h5vg. Any authenticated non-admin operator (for example, one created via self-registration or OIDC) can access resources belonging to other operators.

## Impact

A non-admin operator…

CVE-2026-49258
NVD

HIGH
CVE-2026-56767
CVE-2026-56767
pkg: oauth

published: Jun 25, 2026

Maxun before 0.0.42 contains a cross-tenant insecure direct object reference vulnerability in storage and webhook API handlers that allows authenticated users to access other users' robots and OAuth tokens. Attackers can read plaintext Google and Airtable access tokens, modify, delete, or execute ot…
CWE: CWE-862
GitHub-GHSA

HIGH
Lemur has an authorization bypass in StrictRolePermission / AuthorityCreatorPermission
GHSA-qcqw-jwxc-2hqg
pkg: lemur
eco: pip
published: Jun 25, 2026
## Summary

`StrictRolePermission` and `AuthorityCreatorPermission` in `lemur/auth/permissions.py` call `flask_principal.Permission.__init__()` with zero `Need`s when their config flags are unset. Both flags defaulted to `False` in code prior to the fix, so this was the state of any Lemur install th…

CVE-2026-48508
NVD

HIGH
CVE-2026-9155
CVE-2026-9155
pkg: gnu sed, linux linux_kernel

published: Jun 25, 2026

OS Command Injection vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the expression parameter due to insufficient input validation.
CWE: CWE-78
NVD

HIGH
CVE-2026-13038
CVE-2026-13038
pkg: google chrome, microsoft windows

published: Jun 24, 2026

Use after free in Autofill in Google Chrome on Windows prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-13036
CVE-2026-13036
pkg: google chrome, apple macos, linux linux_kernel

published: Jun 24, 2026

Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416, CWE-416
NVD

HIGH
CVE-2026-13035
CVE-2026-13035
pkg: google chrome, apple macos

published: Jun 24, 2026

Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code via a malicious peripheral. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-13033
CVE-2026-13033
pkg: google chrome, apple macos, linux linux_kernel

published: Jun 24, 2026

Out of bounds read and write in Blink>InterestGroups in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-125, CWE-125, CWE-787
NVD

HIGH
CVE-2026-13031
CVE-2026-13031
pkg: google chrome, apple macos, linux linux_kernel

published: Jun 24, 2026

Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-13027
CVE-2026-13027
pkg: google chrome, apple macos, linux linux_kernel

published: Jun 24, 2026

Use after free in FileSystem in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-13026
CVE-2026-13026
pkg: google chrome, apple macos

published: Jun 24, 2026

Use after free in Digital Credentials in Google Chrome on Mac prior to 149.0.7827.197 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-52952
CVE-2026-52952
pkg: linux

published: Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

iommu: Fix WARN_ON in __iommu_group_set_domain_nofail() due to reset

In __iommu_group_set_domain_internal(), concurrent domain attachments are
rejected when any device in the group is recovering. This is necessary to
fence concurr…

NVD

HIGH
CVE-2026-52934
CVE-2026-52934
pkg: linux

published: Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

batman-adv: tvlv: reject oversized TVLV packets

batadv_tvlv_container_ogm_append() builds a TVLV packet section from
the tvlv.container_list. The total size of this section is computed by
batadv_tvlv_container_list_size(), which s…

NVD

HIGH
CVE-2026-52918
CVE-2026-52918
pkg: linux

published: Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: serialize accept_q access

bt_sock_poll() walks the accept queue without synchronization, while
child teardown can unlink the same socket and drop its last reference.
The unsynchronized accept queue walk has existed sinc…

NVD

HIGH
CVE-2026-54639
CVE-2026-54639
pkg: node

published: Jun 24, 2026

Style Dictionary, a build system for creating cross-platform styles, has a prototype pollution vulnerability starting in version 4.3.0 and prior to version 5.4.4. Impact users have: direct usage of `convertTokenData(tokens, { output: 'object' });`; indirect usage, via using Expand API; and/or indire…
CWE: CWE-1321
NVD

HIGH
CVE-2026-56115
CVE-2026-56115
pkg: dhcpcd_project dhcpcd

published: Jun 23, 2026

Bootimus through 0.1.70 contains a broken access control vulnerability that allows authenticated low-privileged users to perform administrative actions by exploiting missing role enforcement in the JWTMiddleware function in internal/auth/auth.go, which validates JWT tokens and account status but fai…
CWE: CWE-862
NVD

HIGH
CVE-2026-44790
CVE-2026-44790
pkg: n8n n8n

published: Jun 23, 2026

n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with permission to create or modify workflows could inject CLI flags on the Git node's Push operation allowing an attacker to read arbitrary files from the n8n server potentially leading …
CWE: CWE-88
GitHub-GHSA

HIGH
Gogs Vulnerable to CSRF Leading to Organization Owner Takeover
GHSA-pwx3-qcgw-vh7h
pkg: gogs.io/gogs
eco: go
published: Jun 23, 2026
## Summary

In **Gogs 0.14.1**, organization team member management can be performed via **GET requests without CSRF protection**.
If a victim who is an **organization owner** is logged in and is tricked into visiting a crafted link, an attacker-controlled user can be added to the **Owners** team. A…

CVE-2026-52800
NVD

HIGH
CVE-2026-54232
CVE-2026-54232
pkg: vllm vllm

published: Jun 22, 2026

vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.1, the vLLM Dockerfile is vulnerable to a dependency confusion attack through the flashinfer-jit-cache package. The package is installed from a custom index (flashinfer.ai/whl/) using –extra-index-url, but the p…
CWE: CWE-427
NVD

HIGH
CVE-2026-49241
CVE-2026-49241
pkg: angular angular_language_service

published: Jun 22, 2026

The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. Prior to 21.2.4, the client-side Angular Language Service VS Code extension reads the custom TypeScript SDK paths typescript.tsdk and js/ts.tsdk.path directly from workspace configurations (.vsco…
CWE: CWE-79, CWE-94, CWE-427, CWE-494
NVD

HIGH
CVE-2026-56425
CVE-2026-56425
pkg: misp-project misp

published: Jun 22, 2026

The Azure Active Directory (AAD) authentication implementation contained multiple weaknesses in its OAuth 2.0 authorization flow that could allow attackers to bypass important security guarantees provided by the protocol.

The application used the PHP session identifier (session_id()) as the OAuth …

CWE: CWE-384
NVD

HIGH
CVE-2026-54099
CVE-2026-54099
pkg: windows

published: Jun 22, 2026

A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a Certificate Signing Request contains the organization system:wicd-nodes but does not reject additional organization values such as system:masters. A co…
CWE: CWE-269
NVD

HIGH
CVE-2026-55069
CVE-2026-55069
pkg: kubernetes

published: Jun 26, 2026

Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, this vulnerability exists in the BasicAuth authentication component of the Kestra OSS workflow orchestration platform. An attacker who gains read access to the PostgreSQL database can exploit SHA-512's high computation s…
CWE: CWE-916
GitHub-GHSA

HIGH
Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft
GHSA-g2f5-gjr4-qjvm
pkg: gogs.io/gogs
eco: go
published: Jun 23, 2026
# Migration URL validation bypass via HTTP redirect to blocked internal endpoints

## Summary

A Server-Side Request Forgery (SSRF) vulnerability exists in the repository migration functionality. The application validates only the initially submitted URL hostname, but `git clone –mirror` follows HT…

CVE-2026-52805
NVD

HIGH
CVE-2026-55441
CVE-2026-55441
pkg: python

published: Jun 26, 2026

mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.4, mise's trust feature gates config files (mise.toml, .tool-versions) through trust_check, but task-include files are loaded on a path that never reaches it. When a directory has a task-include dir (mise-tasks/, .mise/t…
CWE: CWE-78, CWE-94, CWE-732
NVD

HIGH
CVE-2026-54762
CVE-2026-54762
pkg: traefik traefik

published: Jun 23, 2026

Traefik is an HTTP reverse proxy and load balancer. From 3.7.0-ea.1 until 3.7.5, there is a medium severity vulnerability in Traefik's Kubernetes Ingress NGINX provider that causes affected routes to fail open. When an Ingress explicitly enables BasicAuth or DigestAuth through the supported nginx.in…
CWE: CWE-636, CWE-693
NVD

HIGH
CVE-2026-53755
CVE-2026-53755
pkg: docker

published: Jun 23, 2026

Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.9, the Docker API server applied its SSRF destination check to the crawl target URL only, not to the proxy address. An unauthenticated request could supply a proxy pointing at an internal IP and route the browser through it,…
CWE: CWE-918
GitHub-GHSA

HIGH
Mise vulnerable to arbitrary command execution via task-include files in an untrusted, config-less repository
GHSA-77g9-363w-rccq
pkg: mise
eco: rust
published: Jun 23, 2026
### Summary

mise's trust feature gates config files (`mise.toml`, `.tool-versions`) through `trust_check`, but task-include files are loaded on a path that never reaches it. When a directory has a task-include dir (`mise-tasks/`, `.mise/tasks/`, …) but no config file, mise falls back to the defau…

CVE-2026-55441
NVD

HIGH
CVE-2026-55602
CVE-2026-55602
pkg: chimurai http-proxy-middleware

published: Jun 22, 2026

http-proxy-middleware is node.js http-proxy middleware. From 0.16.0 until 2.0.10, 3.0.6, and 4.1.0, http-proxy-middleware documents router proxy-table entries as host, path, or host+path selectors, but the host+path implementation uses unanchored substring matching on attacker-controlled request met…
CWE: CWE-20, CWE-187
NVD

HIGH
CVE-2026-54008
CVE-2026-54008
pkg: openwebui open_webui

published: Jun 23, 2026

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, backend/open_webui/utils/oauth.py::_process_picture_url calls validate_url(picture_url) on the initial URL only, then invokes aiohttp.ClientSession.get(picture_url, …) without allow_r…
CWE: CWE-918
GitHub-GHSA

HIGH
OpenAM Authenticated Privilege Escalation via Raw Token Disclosure Session RPC
GHSA-vvhj-w2jq-263q
pkg: org.openidentityplatform.openam:openam-core
eco: maven
published: Jun 23, 2026
## Summary

Description

An insufficient authorization (CWE-285) and information exposure (CWE-200) issue in OpenAM's session management endpoint allows a low-privileged authenticated user to retrieve active session credentials belonging to other users, including those with higher privileges. This a…

CVE-2026-45048
NVD

HIGH
CVE-2026-49444
CVE-2026-49444
pkg: n8n n8n

published: Jun 23, 2026

n8n is an open source workflow automation platform. Prior to 1.123.48, 2.21.8, and 2.22.4, an authenticated user with permission to create or modify workflows containing a Python Code Node could escape the sandbox and achieve arbitrary code execution on the task runner container. This vulnerability …
CWE: CWE-20
NVD

HIGH
CVE-2026-54312
CVE-2026-54312
pkg: n8n n8n

published: Jun 23, 2026

n8n is an open source workflow automation platform. Prior to 2.24.0, an authenticated user with permission to create or modify workflows could achieve global prototype pollution via the Microsoft SQL node by supplying a crafted value as the table parameter. This pollutes Object.prototype process-wid…
CWE: CWE-1321
GitHub-GHSA

HIGH
@budibase/backend-core has potential SSRF DNS rebinding bypass in outbound fetch validation
GHSA-gfq7-5x4g-3xhf
pkg: @budibase/backend-core
eco: npm
published: Jun 22, 2026
Summary

Authenticated users with automation permissions can bypass Budibase's SSRF blacklist through DNS rebinding.

The outbound fetch flow validates a hostname against the blacklist before the request is sent, but the actual socket connection later performs a separate DNS lookup through node-fetc…

CVE-2026-54353
GitHub-GHSA

HIGH
Budibase: SSRF via OAuth2 token endpoint URL reaches internal hosts and cloud metadata
GHSA-4q6h-8p4v-67vq
pkg: @budibase/server
eco: npm
published: Jun 22, 2026
## Summary

`fetchToken` in the OAuth2 SDK makes a POST to a builder-supplied URL with plain node-fetch, skipping the `blacklist.isBlacklisted` check that every other outbound fetch path in the codebase uses. The Joi schema for the OAuth2 URL has no scheme or host restriction. Alice, a builder, poin…

CVE-2026-48153
GitHub-GHSA

HIGH
Spinnaker has uon-safe yaml deserialization, allowing RCE when using specific types
GHSA-c8q4-9h32-2ww8
pkg: io.spinnaker.rosco:rosco-core, io.spinnaker.orca:orca-core, io.spinnaker.rosco:rosco-core
eco: maven
published: Jun 22, 2026
### Impact
There's an unsafe YAML processing vulnerability that bypasses safe deserialization. This impacts users when when performing:
* CloudFormation deployments
* CloudFoundry Baking

The usage of a non-safe constructor use allows arbitrary loading of Java classes leading to RCE.

### Patches
2…

CVE-2026-44795
NVD

HIGH
CVE-2026-47267
CVE-2026-47267
pkg: go

published: Jun 24, 2026

Gogs is an open source self-hosted Git service. Prior to 0.14.3, the fix for CVE-2022-1285 prevents adding webooks or running webhooks with URLs with a hostname that resolves in localCIDRs. However, webhooks still follow redirects allowing to access hostname inside localCIDRs. This vulnerability is …
CWE: CWE-918
NVD

HIGH
CVE-2026-13025
CVE-2026-13025
pkg: google chrome, apple macos, linux linux_kernel

published: Jun 24, 2026

Race in DevTools in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-20
NVD

HIGH
CVE-2026-52920
CVE-2026-52920
pkg: linux

published: Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

netfilter: xt_policy: fix strict mode inbound policy matching

match_policy_in() walks sec_path entries from the last transform to the
first one, but strict policy matching needs to consume info->pol[] in
the same forward order as …

GitHub-GHSA

HIGH
OpenAM Unauthenticated Session Hijacking via Information Exposure in CDCServlet
GHSA-r9pv-5rpp-vm8g
pkg: org.openidentityplatform.openam:openam-federation
eco: maven
published: Jun 23, 2026
## Summary

**Description**

An Information Exposure Through Sent Data (CWE-201) issue in OpenAM's Cross-Domain Single Sign-On (CDSSO) servlet allows a logged-in user's raw OpenAM session token to be POSTed to an attacker-controlled URL. This impacts OpenAM Community Edition through version 16.0.6. …

CVE-2026-45049
NVD

HIGH
CVE-2026-50574
CVE-2026-50574
pkg: yt-dlp_project yt-dlp

published: Jun 23, 2026

yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, if aria2c is used as an external downloader for a fragmented manifest format (such as an HLS/DASH stream), yt-dlp passes insufficiently sanitized input to aria2c that allows an attacker to perform an arbitrary file write. On Windo…
CWE: CWE-74
GitHub-GHSA

HIGH
@actual-app/sync-server: Disabled OpenID users keep access through existing session tokens
GHSA-cq9c-6w48-qmfg
pkg: @actual-app/sync-server
eco: npm
published: Jun 22, 2026
### Summary

In OpenID multi-user mode, disabling a user only blocks future OpenID login for that identity. Existing Actual session tokens for the disabled user remain valid, so the user can continue calling authenticated server endpoints after an administrator has disabled the account.

### Details…

CVE-2026-49229
NVD

HIGH
CVE-2026-54100
CVE-2026-54100
pkg: windows

published: Jun 22, 2026

A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH connections to Windows worker nodes without verifying the remote server host key. An adjacent-network attacker who can intercept or redirect WMCO's SSH session can capture WI…
CWE: CWE-295
GitHub-GHSA

HIGH
pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config
GHSA-qrv3-253h-g69c
pkg: pnpm, pnpm
eco: npm
published: Jun 27, 2026
## Summary

`pnpm` accepts package names from the env lockfile `configDependencies` section and uses those names directly when creating config dependency symlinks under `node_modules/.pnpm-config`.

A malicious repository can commit a crafted `pnpm-lock.yaml` whose env-lockfile document contains a t…

NVD

HIGH
CVE-2026-52783
CVE-2026-52783
pkg: oauth

published: Jun 26, 2026

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, OpenProject's Storages module writes the OneDrive/SharePoint userless OAuth access_token plaintext to Rails.cache under the deterministic key storage.<id>.httpx_access_token, repopulated continuously by an…
CWE: CWE-313
GitHub-GHSA

HIGH
Remark42: Cross-Site Scripting (XSS) on /api/v1/img via content-type spoofing
GHSA-4c8j-mgm4-qqvp
pkg: github.com/umputun/remark42
eco: go
published: Jun 26, 2026
### Summary
The remark42 image proxy fetches an arbitrary remote URL and re-serves the response from remark42's own origin. The download path decides whether the fetched resource is an image by looking only at the `Content-Type` header the remote server claims — it never inspects the actual bytes.…
CVE-2026-48788
NVD

HIGH
CVE-2026-53268
CVE-2026-53268
pkg: tls

published: Jun 25, 2026

In the Linux kernel, the following vulnerability has been resolved:

netfilter: conntrack_irc: fix possible out-of-bounds read

When parsing fails after we've matched the command string we
should bail out instead of trying to match a different command.

This helper should be deprecated, given preval…

NVD

HIGH
CVE-2026-56351
CVE-2026-56351
pkg: n8n n8n

published: Jun 24, 2026

n8n before version 2.4.0 contains a sql injection vulnerability in MySQL, PostgreSQL, and Microsoft SQL nodes that allows authenticated users to inject arbitrary SQL through unescaped identifier values in node configuration parameters. Attackers with workflow creation permissions can supply speciall…
CWE: CWE-89
GitHub-GHSA

HIGH
Algernon: Host header path traversal in –domain mode reads files and runs Lua from parent dir
GHSA-jc3j-x6pg-4hmv
pkg: github.com/xyproto/algernon
eco: go
published: Jun 23, 2026
### Summary

When algernon is started with `–domain` (or `–letsencrypt`, which silently turns on `–domain` at `engine/flags.go:372`), the request handler resolves the served directory by joining the configured `–dir` with the value of the client-supplied `Host` header. The join is performed by `…

CVE-2026-48126
GitHub-GHSA

HIGH
Budibase: Mass Assignment in Webhook Trigger Allows Cross-Workspace Automation Execution via appId Override
GHSA-rgvg-3wpc-h44p
pkg: @budibase/server
eco: npm
published: Jun 22, 2026
## Summary

The webhook trigger endpoint in Budibase is publicly accessible and passes the full HTTP request body into automation execution parameters. A mass assignment vulnerability in `externalTrigger()` allows an attacker to overwrite the internal `appId` property by including it in the webhook …

CVE-2026-54351
GitHub-GHSA

HIGH
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host
GHSA-4gxv-p5g5-j7w7
pkg: go.senan.xyz/gonic
eco: go
published: Jun 26, 2026
## Summary

A logic error in `ServeCreateOrUpdatePlaylist` allows **any authenticated Subsonic user** (including non-admin) to write playlist M3U content to an attacker-controlled absolute filesystem path on the gonic host, and to create intermediate directories with `0o777` permissions.

The bug is…

CVE-2026-49340
GitHub-GHSA

HIGH
mcp-memory-service: OAuth read-only clients can write and delete memories through MCP tools/call
GHSA-2r68-g678-7qr3
pkg: mcp-memory-service
eco: pip
published: Jun 26, 2026
## Summary

The HTTP MCP JSON-RPC endpoint at `/mcp` requires only OAuth `read` scope for all requests, then dispatches `tools/call` directly to handlers that include mutating tools. A read-only OAuth client can call `store_memory` and `delete_memory` through MCP even though the corresponding REST e…

CVE-2026-49291
NVD

HIGH
CVE-2026-11800
CVE-2026-11800
pkg: jwt

published: Jun 25, 2026

A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow allows an attacker with valid client credentials to bypass signature verification. By forging an assertion, the attacker can create unauthorized access tokens. This enables the attacker to im…
CWE: CWE-347
NVD

HIGH
CVE-2025-71340
CVE-2025-71340
pkg: python

published: Jun 25, 2026

picklescan through 0.0.26 fails to detect malicious pickle files that invoke idlelib.pyshell.ModifiedInterpreter.runcode in __reduce__ methods. Attackers can embed undetected code in pickle files that executes arbitrary commands when the file is loaded via pickle.load(), enabling supply chain attack…
CWE: CWE-502
GitHub-GHSA

HIGH
jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)
GHSA-rmj7-2vxq-3g9f
pkg: com.fasterxml.jackson.core:jackson-databind, com.fasterxml.jackson.core:jackson-databind, com.fasterxml.jackson.core:jackson-databind
eco: maven
published: Jun 23, 2026
## Summary
`BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray()` allowlists any array type based only on `clazz.isArray()`, without validating the array's component (element) type against the configured allowlist. A PTV built with `allowIfSubTypeIsArray()` plus an explicit concrete-type al…
CVE-2026-54513
GitHub-GHSA

HIGH
jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instantiation
GHSA-j3rv-43j4-c7qm
pkg: com.fasterxml.jackson.core:jackson-databind, com.fasterxml.jackson.core:jackson-databind, com.fasterxml.jackson.core:jackson-databind
eco: maven
published: Jun 23, 2026
`jackson-databind`'s `PolymorphicTypeValidator` (PTV) is the primary safety mechanism guarding polymorphic deserialization. When polymorphic typing is enabled and a type identifier contains generic parameters (i.e. the type ID string contains `<`), `DatabindContext._resolveAndValidateGeneric()` vali…
CVE-2026-54512
NVD

HIGH
CVE-2026-52845
CVE-2026-52845
pkg: caddyserver caddy

published: Jun 23, 2026

Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, forward_auth copy_headers deletes the exact client-supplied identity header before copying the trusted value from the auth gateway. But when the request later goes through php_fastcgi, Caddy normalizes HTTP headers int…
CWE: CWE-287, CWE-290, CWE-444
NVD

HIGH
CVE-2026-49402
CVE-2026-49402
pkg: deno deno, microsoft windows

published: Jun 23, 2026

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.10, Deno's node:child_process implementation provided an escapeShellArg() helper used when callers passed shell: true to spawn / spawnSync / exec and friends. On Windows, the helper failed to quote arguments that contained cmd.e…
CWE: CWE-78
NVD

HIGH
CVE-2026-45135
CVE-2026-45135
pkg: caddyserver caddy

published: Jun 23, 2026

Caddy is an extensible server platform that uses TLS by default. From 2.7.0 until 2.11.3, the FastCGI transport's splitPos() in modules/caddyhttp/reverseproxy/fastcgi/fastcgi.go misuses golang.org/x/text/search with search.IgnoreCase when the request path contains a non-ASCII byte. Two distinct flaw…
CWE: CWE-20, CWE-176, CWE-178
NVD

HIGH
CVE-2026-45732
CVE-2026-45732
pkg: n8n n8n

published: Jun 23, 2026

n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, the OAuth1 and OAuth2 credential reconnect endpoints authorized access using credential:read rather than credential:update. An authenticated user with read-only access to a shared credential could initiate an …
CWE: CWE-639
GitHub-GHSA

HIGH
Gogs has the ability to import local repositories via Mirror Settings
GHSA-wv27-2vqp-j7g5
pkg: gogs.io/gogs
eco: go
published: Jun 23, 2026
### Summary
The Gogs Mirror Settings functionality provide an alternative way from the well protected New Migration functionality for any authenticated users to import local repositories. This issue stems from a lack of validation of SaveAddress function.

### Details
Here is the function implementa…

CVE-2026-52801
NVD

HIGH
CVE-2025-71339
CVE-2025-71339
pkg: python

published: Jun 22, 2026

Picklescan before 0.0.33 fails to detect the numpy.f2py.crackfortran._eval_length gadget in pickle __reduce__ methods, allowing arbitrary code execution. Attackers can craft malicious pickle files that execute arbitrary Python code when loaded by victims who trust Picklescan's safety validation.
CWE: CWE-502
NVD

HIGH
CVE-2026-55388
CVE-2026-55388
pkg: node

published: Jun 22, 2026

piscina is a node.js worker pool implementation. Prior to 6.0.0-rc.2, 5.2.0, and 4.9.3, piscina's constructor and run() paths read the filename option via plain member access. Both reads fall through the prototype chain when the caller's options object doesn't have filename as an own property. When …
CWE: CWE-94, CWE-1321
NVD

HIGH
CVE-2026-54030
CVE-2026-54030
pkg: oauth

published: Jun 25, 2026

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.5, LibreChat's MCP OAuth implementation does not validate that the resource parameter from OAuth Protected Resource metadata (RFC 9728) matches the configured MCP server URL, allowing a malicious MCP server to s…
CWE: CWE-346
NVD

HIGH
CVE-2026-23879
CVE-2026-23879
pkg: python

published: Jun 24, 2026

py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Versions 1.1.2 and below contain an an arbitrary file write vulnerability, which allows symbolic links to be recreated outside the destination directory via crafted malicious sy…
CWE: CWE-59
NVD

HIGH
CVE-2026-57456
CVE-2026-57456
pkg: vim vim

published: Jun 25, 2026

Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/python3complete.vim and the legacy pythoncomplete.vim) executes reconstructed function and class definitions from the current buffer with exec() as part of populating the completion dic…
CWE: CWE-94
NVD

HIGH
CVE-2026-46733
CVE-2026-46733
pkg: windows

published: Jun 25, 2026

Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
CWE: CWE-284
NVD

HIGH
CVE-2026-53267
CVE-2026-53267
pkg: express

published: Jun 25, 2026

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nft_ct: bail out on template ct in get eval

I noticed this issue while looking at a historic syzbot report [1].

A rule like the one below is enough to trigger the bug:

table ip t {
chain pre {

NVD

HIGH
CVE-2026-53194
CVE-2026-53194
pkg: python

published: Jun 25, 2026

In the Linux kernel, the following vulnerability has been resolved:

USB: serial: kl5kusb105: fix bulk-out buffer overflow

klsi_105_prepare_write_buffer() is called by the generic write path
with the bulk-out buffer and its size (bulk_out_size, 64 bytes). It
stores a two-byte length header at the s…

NVD

HIGH
CVE-2026-13037
CVE-2026-13037
pkg: google chrome, google android

published: Jun 24, 2026

Use after free in WebView in Google Chrome on Android prior to 149.0.7827.197 allowed a local attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-53094
CVE-2026-53094
pkg: go

published: Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

bpf: Fix stale offload->prog pointer after constant blinding

When a dev-bound-only BPF program (BPF_F_XDP_DEV_BOUND_ONLY) undergoes
JIT compilation with constant blinding enabled (bpf_jit_harden >= 2),
bpf_jit_blind_constants() cl…

NVD

HIGH
CVE-2026-53090
CVE-2026-53090
pkg: go

published: Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

bpf: Fix ld_{abs,ind} failure path analysis in subprogs

Usage of ld_{abs,ind} instructions got extended into subprogs some time
ago via commit 09b28d76eac4 ("bpf: Add abnormal return checks."). These
are only allowed in subprogram…

NVD

HIGH
CVE-2026-52975
CVE-2026-52975
pkg: go

published: Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

bonding: 3ad: implement proper RCU rules for port->aggregator

syzbot found a data-race in bond_3ad_get_active_agg_info /
bond_3ad_state_machine_handler [1] which hints at lack of proper
RCU implementation.

Add __rcu qualifier to …

NVD

HIGH
CVE-2026-52951
CVE-2026-52951
pkg: linux

published: Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

drm/xe/dma-buf: handle empty bo and UAF races

There look to be some nasty races here when triggering the
invalidate_mappings hook:

1) We do xe_bo_alloc() followed by the attach, before the actual full bo
init step in xe_dma_bu…

NVD

HIGH
CVE-2026-52950
CVE-2026-52950
pkg: linux

published: Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

drm/xe/dma-buf: fix UAF with retry loop

Retry doesn't work here, since bo will be freed on error, leading to
UAF. However, now that we do the alloc & init before the attach, we can
now combine this as one unit and have the init do…

NVD

HIGH
CVE-2026-52947
CVE-2026-52947
pkg: linux

published: Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove

In qrtr_port_remove(), the socket reference count is decremented via
__sock_put() before the port is removed from the qrtr_ports XArray and
before the RCU gr…

NVD

HIGH
CVE-2026-52943
CVE-2026-52943
pkg: linux

published: Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

net: skbuff: fix missing zerocopy reference in pskb_carve helpers

pskb_carve_inside_header() and pskb_carve_inside_nonlinear() both copy
the old skb_shared_info header into a new buffer via memcpy(), which
includes the destructor_…

NVD

HIGH
CVE-2026-52935
CVE-2026-52935
pkg: linux

published: Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

xfrm: espintcp: do not reuse an in-progress partial send

espintcp keeps a single in-flight transmit in ctx->partial.
Before building a new sk_msg, espintcp_sendmsg() first tries to flush
that state through espintcp_push_msgs().

F…

NVD

HIGH
CVE-2026-52933
CVE-2026-52933
pkg: linux

published: Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

io_uring/poll: fix signed comparison in io_poll_get_ownership()

io_poll_get_ownership() uses a signed comparison to check whether
poll_refs has reached the threshold for the slowpath:

if (unlikely(atomic_read(&req->poll_refs)…

NVD

HIGH
CVE-2026-52927
CVE-2026-52927
pkg: linux

published: Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

netfilter: ebtables: fix OOB read in compat_mtw_from_user

Luxiao Xu says:

The function compat_mtw_from_user() converts ebtables extensions from
32-bit user structures to kernel native structures. However, it lacks
proper valid…

NVD

HIGH
CVE-2026-52923
CVE-2026-52923
pkg: linux

published: Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

ipc: limit next_id allocation to the valid ID range

The checkpoint/restore sysctl path can request the next SysV IPC id
through ids->next_id. ipc_idr_alloc() currently forwards that request to
idr_alloc() with an open-ended upper…

NVD

HIGH
CVE-2026-52919
CVE-2026-52919
pkg: linux

published: Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

batman-adv: fix tp_meter counter underflow during shutdown

batadv_tp_sender_shutdown() unconditionally decrements the "sending"
atomic counter. If multiple paths (e.g. timeout, user cancel, and
normal finish) call this function, t…

NVD

HIGH
CVE-2026-52912
CVE-2026-52912
pkg: linux

published: Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_queue: hold bridge skb->dev while queued

br_pass_frame_up() rewrites skb->dev from the ingress port to the bridge
master before queueing bridge LOCAL_IN packets. NFQUEUE only holds
references on state.in/out and brid…

GitHub-GHSA

HIGH
Glances has arbitrary file write and command execution via `secure_popen` redirection and chaining operators in AMP command configuration
GHSA-3vwc-qwhc-3mj7
pkg: glances
eco: pip
published: Jun 23, 2026
### Summary

The `secure_popen()` function in `glances/secure.py` interprets `>` (file redirection), `|` (pipe), and `&&` (command chaining) operators in command strings. These operators are applied without any validation on the target file path, piped command, or chained command.

When Application …

CVE-2026-53925
GitHub-GHSA

HIGH
Glances has Insecure Pickle Deserialization in its Version Cache that Leads to Arbitrary Code Execution
GHSA-9837-48hr-q32j
pkg: glances
eco: pip
published: Jun 22, 2026
### Summary

`glances/outdated.py` uses `pickle.load()` to read a version-check cache file stored at a predictable, world-accessible path (`~/.cache/glances/glances-version.db` or `$XDG_CACHE_HOME/glances/glances-version.db`). No integrity check, signature verification, or format validation is perfo…

CVE-2026-46607
GitHub-GHSA

HIGH
Glances is Vulnerable to Command Injection via KVM/QEMU VM Domain Names in glances/plugins/vms/engines/virsh.py
GHSA-v5r2-qh84-fjx5
pkg: glances
eco: pip
published: Jun 22, 2026
### Summary

The Glances KVM/QEMU monitoring engine (`glances/plugins/vms/engines/virsh.py`) passes VM domain names, read directly from `virsh list –all` output, into f-string command templates that are processed by `secure_popen()`. `secure_popen()` is explicitly designed to interpret `&&`, `|`, a…

CVE-2026-46606
NVD

HIGH
CVE-2026-49984
CVE-2026-49984
pkg: windows

published: Jun 26, 2026

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.23, the local internal-storage backend validates user-supplied paths for .. traversal before it converts Windows-style backslashes to forward slashes. An attacker can therefore smuggle a traversal sequence past th…
CWE: CWE-22, CWE-180, CWE-200
NVD

HIGH
CVE-2026-8665
CVE-2026-8665
pkg: express

published: Jun 25, 2026

OS Command Injection vulnerability in the TR action of Rapid7 InsightConnect Translate Plugin on Linux allows remote attackers to execute arbitrary OS commands via the text or expression parameters due to insufficient input sanitization in shell command construction.
CWE: CWE-78
NVD

HIGH
CVE-2026-8592
CVE-2026-8592
pkg: express

published: Jun 25, 2026

OS Command Injection vulnerability in the process_string action of Rapid7 InsightConnect AWK Plugin on Linux allows remote attackers to execute arbitrary OS commands via the text or expression parameters due to unsafe shell command construction in the processing pipeline.
CWE: CWE-78
NVD

HIGH
CVE-2026-33235
CVE-2026-33235
pkg: express

published: Jun 24, 2026

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. In versions prior to 0.6.52, the Fill Text Template block is vulnerable to a Denial of Service (DoS) attack. While the backend implements a SandboxedEnvironment to prevent unaut…
CWE: CWE-400
NVD

HIGH
CVE-2026-54699
CVE-2026-54699
pkg: windows

published: Jun 24, 2026

Warp is an agentic development environment. From 0.2024.03.12.08.02.stable_01 until 0.2026.05.06.15.42.stable_01, Warp contains an OS command injection vulnerability in the WSL URL-opening fallback. When Warp is running under WSL and cannot open a URL through wslview, it falls back to a Windows comm…
CWE: CWE-78, CWE-116
NVD

HIGH
CVE-2026-54018
CVE-2026-54018
pkg: openwebui open_webui

published: Jun 23, 2026

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, the SafePlaywrightURLLoader implements a validate_url function to prevent SSRF attacks by checking the IP address of the user-provided URL. However, this validation is performed only on…
CWE: CWE-918
NVD

HIGH
CVE-2026-54304
CVE-2026-54304
pkg: n8n n8n

published: Jun 23, 2026

n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.1, an authenticated user with permission to create or modify workflows and access to a SecurityScorecard credential with limited allowed domains could configure the SecurityScorecard node's report download operat…
CWE: CWE-200
NVD

HIGH
CVE-2026-49465
CVE-2026-49465
pkg: n8n n8n

published: Jun 23, 2026

n8n is an open source workflow automation platform. Prior to 1.123.48, 2.21.8, and 2.22.4, an authenticated user with permission to create or modify workflows could supply a local filesystem path as the source repository in the Git node's Clone operation, or as the target repository in the Push oper…
CWE: CWE-22
NVD

HIGH
CVE-2026-54313
CVE-2026-54313
pkg: n8n n8n

published: Jun 23, 2026

n8n is an open source workflow automation platform. Prior to 2.24.0, an authenticated user with workflow edit access could supply a malicious filter value in the MongoDB node's Find And Replace operation. The value was not validated before being passed to MongoDB as a query filter, allowing unintend…
CWE: CWE-89
NVD

HIGH
CVE-2026-54311
CVE-2026-54311
pkg: n8n n8n

published: Jun 23, 2026

n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, an authenticated user with permission to create or modify workflows could pollute the sandbox used by the Merge node's SQL Query mode. Because the sandbox context was cached and reused across all workflow executions on t…
CWE: CWE-488
NVD

HIGH
CVE-2026-56268
CVE-2026-56268
pkg: flowiseai flowise

published: Jun 22, 2026

Flowise before 3.1.2 contains an information disclosure vulnerability in the /api/v1/chatflows/apikey/:apikey endpoint. When the keyonly query parameter is omitted (the default), the endpoint returns not only the chatflows bound to the supplied API key but also all chatflows across every workspace t…
CWE: CWE-863
GitHub-GHSA

HIGH
OpenCTI has Semi-Blind SSRF via Unvalidated External URL in Data Ingestion Feature
GHSA-ffm6-vvph-g5f5
pkg: pycti
eco: pip
published: Jun 22, 2026
### Summary
The OpenCTI platform’s data ingestion feature accepts user-supplied URLs without validation and uses the Axios HTTP client with its default configuration (allowAbsoluteUrls: true). This allows attackers to craft requests to arbitrary endpoints, including internal services, because Axio…
CVE-2026-21887
NVD

HIGH
CVE-2026-11998
CVE-2026-11998
pkg: express

published: Jun 24, 2026

A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and can lead to arbitrary JavaScript execution within the context of the victim's browser session.

SCE's purpose is to ensure that only trusted or safe values are used in certain sec…

CWE: CWE-791
GitHub-GHSA

HIGH
pnpm: Repository-controlled configDependencies can select a pacquet native install engine
GHSA-gj8w-mvpf-x27x
pkg: pnpm, pnpm
eco: npm
published: Jun 26, 2026
<!– maintainer-action:start –>
## Maintainer Action Plan

This report is ready to review with the shared patch branch. Start with the PR and the expected fixed behavior, then use the detailed exploit narrative below only if you want to replay the original path.

– Advisory: `CAND-PNPM-097` / `GHSA…

CVE-2026-55697
GitHub-GHSA

HIGH
pnpm: Manifest identity spoof satisfies allowBuilds and runs attacker lifecycle
GHSA-5wx6-mg75-v57r
pkg: pnpm, pnpm
eco: npm
published: Jun 26, 2026
## Summary

Keep build approval for opaque dependency sources byte-exact for GHSA-5wx6-mg75-v57r / CAND-PNPM-123.

Merged upstream commit `bf1b731ee6` fixed the original name-only approval bypass by making build policy consume the resolved dependency identity. One collision remained: the generic pee…

CVE-2026-55487
GitHub-GHSA

HIGH
js-toml vulnerable to CPU exhaustion via O(n^2) BigInt construction on radix-prefixed integer literals
GHSA-wp3c-266w-4qfq
pkg: js-toml
eco: npm
published: Jun 26, 2026
## Summary

`js-toml` versions up to and including **1.1.0** parse hexadecimal / octal / binary integer literals via a hand-written `parseBigInt` loop that multiplies a `BigInt` accumulator by the radix once per input digit. Each iteration performs a `BigInt * BigInt` operation on an accumulator tha…

CVE-2026-49293
GitHub-GHSA

HIGH
better-helperjs Vulnerable to Directory Traversal via String Prefix Bypass in Static Server
GHSA-3p34-w4f6-5xh2
pkg: better-helperjs
eco: npm
published: Jun 26, 2026
## Summary
A directory traversal vulnerability exists in the production static file server of `better-helperjs` (`<= 3.0.5`). Attackers can read arbitrary files located in adjacent directory structures that share the same string prefix as the intended static root directory.

## Details
The framework…

GitHub-GHSA

HIGH
Muhammara has a NULL pointer dereference in LZWDecode filter when DecodeParms omits EarlyChange key
GHSA-fhp4-pr5j-46m5
pkg: muhammara
eco: npm
published: Jun 26, 2026
## Summary

A NULL pointer dereference vulnerability exists in `PDFParser::CreateFilterForStream()` when processing a PDF stream with `/Filter /LZWDecode` and a `/DecodeParms` dictionary that does not contain the `EarlyChange` key. This causes an access violation (0xC0000005) and crashes the process…

GitHub-GHSA

HIGH
python-socketio: Binary attachment accumulation can cause denial of service
GHSA-5w7q-77mv-v69f
pkg: python-socketio
eco: pip
published: Jun 26, 2026
### Impact
The python-socketio server stores binary `EVENT` and `ACK` messages in memory while it waits to receive their binary attachments. Once all the attachments are received, these messages are then processed. An attacker can submit a binary message and intentionally omit sending one or more of…
CVE-2026-48804
GitHub-GHSA

HIGH
python-engineio has unbound thread allocation that can cause denial of service
GHSA-cgwc-pv48-fhj5
pkg: python-engineio
eco: pip
published: Jun 26, 2026
### Impact
An attacker can cause the creation of unnecessary background threads in the python-engineio server by exploiting the heartbeat mechanism, which launches a thread when a new connection is received, and when the client sends a PONG packet.

Note: this issue primarily affects synchronous ser…

CVE-2026-48802
GitHub-GHSA

HIGH
python-engineio has possible denial of service due to maximum payload size sometimes not being enforced
GHSA-m9gh-vj53-gvh9
pkg: python-engineio
eco: pip
published: Jun 26, 2026
### Impact
There are two specific configurations of the python-engineio server in which the size of incoming messages is not checked before the messages are loaded into memory. An attacker can take advantage of these to cause unnecessary memory allocations in the python-engineio server. The two case…
CVE-2026-48809
GitHub-GHSA

HIGH
Hysteria: http large header with sniff cause server DoS
GHSA-jqc5-2p7q-fqfc
pkg: github.com/apernet/hysteria
eco: go
published: Jun 26, 2026
### Summary

Sending an excessively large header by an attacker could lead to a server-side DoS attack.

### Details
The current sniff implementation does not explicitly specify the upper limit for HTTP headers. Attackers can continuously send excessively large headers without including \r\n\r\n, le…

GitHub-GHSA

HIGH
Hysteria vulnerable to server crash when max_datagram_frame_size very small
GHSA-qh5x-rfwf-rvfv
pkg: github.com/apernet/hysteria
eco: go
published: Jun 26, 2026
### Summary

An authenticated client can crash the Hysteria server by advertising a very small QUIC `max_datagram_frame_size` and then triggering a UDP response from the server. When the server tries to send the UDP response back via QUIC DATAGRAM, quic-go returns `DatagramTooLargeError`. The server…

GitHub-GHSA

HIGH
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
GHSA-j9cw-hwqf-85w7
pkg: fluentd
eco: rubygems
published: Jun 26, 2026
Fluentd's `in_http` and `in_forward` plugins support receiving gzip-compressed data.
While Fluentd correctly enforces size limits on the incoming compressed payloads (e.g., via `body_size_limit` or `chunk_size_limit`), it was discovered that there is no limit enforced on the size of the decompressed…
CVE-2026-44160
GitHub-GHSA

HIGH
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
GHSA-pr7j-96cj-549h
pkg: fluentd
eco: rubygems
published: Jun 26, 2026
Fluentd's Monitor Agent plugin (`in_monitor_agent`) exposes internal metrics and plugin information via a REST API.
It was discovered that the API response (`/api/plugins.json` and related endpoints) unintentionally includes internal instance variables of loaded plugins.

If any plugins store sensit…

CVE-2026-44025
NVD

HIGH
CVE-2026-49486
CVE-2026-49486
pkg: apache apache-airflow-providers-ftp

published: Jun 26, 2026

The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `prot_p()`, so although the control channel was TLS-protected the data channel was transmitted in cleartext. Any deployment using `FTPSHook` or `FTPSFileTransmitOperator` to move files ove…
CWE: CWE-319
GitHub-GHSA

HIGH
golang.org/x/crypto/ssh: Invoking pathological RSA/DSA parameters may cause DoS
GHSA-w879-237q-wc7r
pkg: golang.org/x/crypto/ssh
eco: go
published: Jun 25, 2026
The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA parameter could cause several minutes of CPU consumption during signature verification. This could be triggered by unauthenticated clients during public key…
CVE-2026-39829
NVD

HIGH
CVE-2026-6331
CVE-2026-6331
pkg: wolfssl wolfssl

published: Jun 25, 2026

HMAC zero-length tag forgery in EVP_DigestVerifyFinal, where a zero-length tag could be accepted as valid during HMAC verification. In the OpenSSL-compatibility HMAC verify path the supplied signature length was only checked as not exceeding the MAC length, so a zero-length or otherwise truncated ta…
CWE: CWE-347
GitHub-GHSA

HIGH
golang.org/x/crypto/ssh: Invoking byte arithmetic causes underflow and panic
GHSA-q4h4-gmj2-qvw2
pkg: golang.org/x/crypto/ssh
eco: go
published: Jun 25, 2026
An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.
CVE-2026-46597
GitHub-GHSA

HIGH
ImageMagick has out-of-bounds write in ICON decoder due to incorrect loop
GHSA-g22q-f7gc-5jhr
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Jun 25, 2026
An incorrect loop in the ICON decoder can result in an out of bounds heap write resulting in a crash.
CVE-2026-53461
GitHub-GHSA

HIGH
ImageMagick: Policy Bypass can Trigger an Out-of-Memory condition
GHSA-q62c-h75r-2xhc
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Jun 25, 2026
A missing check for maximum memory request in AcquireAlignedMemory could trigger an out-of-Memory condition.

## Credit
Aisle Research (Ze Sheng, Dmitrijs Trizna, Luigino Camastra, Guido Vranken)

CVE-2026-53460
GitHub-GHSA

HIGH
ImageMagick: Policy Bypass in DCM decoder could result in image with invalid dimensions
GHSA-8pj9-6897-74xc
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Jun 25, 2026
A missing check in the DCM decoder could result in an image with invalid dimensions and that could cause crashes in other operations.
CVE-2026-49218
GitHub-GHSA

HIGH
Rekor has an OOM Condition due to Unbounded gzip Decompression in Alpine APK Parsing Logic
GHSA-47q9-m4ww-924m
pkg: github.com/sigstore/rekor
eco: go
published: Jun 25, 2026
## Description

The `Package.Unmarshal()` function in `pkg/types/alpine/apk.go` decompresses the signature and control gzip members of an APK file into in-memory buffers without bounding the total decompressed size. The existing `max_apk_metadata_size` check (default 1MB) is only applied to individu…

CVE-2026-48702
NVD

HIGH
CVE-2026-55958
CVE-2026-55958
pkg: wolfssl wolfssl

published: Jun 25, 2026

Out-of-bounds write in the Renesas TSIP TLS 1.3 transcript buffer. In tsip_StoreMessage() the capacity check guarding the fixed message bag (MSGBAG_SIZE) sets an error code but fails to return, so execution falls through to an XMEMCPY that writes past the end of the buffer once the accumulated TLS 1…
CWE: CWE-393, CWE-787, CWE-787
NVD

HIGH
CVE-2026-11310
CVE-2026-11310
pkg: wolfssl wolfssl

published: Jun 25, 2026

X.509 trust-chain bypass in the OpenSSL compatibility certificate verifier (wolfSSL_X509_verify_cert()). This affects only builds with –enable-opensslextra (OPENSSL_EXTRA) and whose application validates certificates by calling X509_verify_cert() with caller-supplied untrusted intermediate certific…
CWE: CWE-295
GitHub-GHSA

HIGH
MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depth
GHSA-vh6j-jc39-fggf
pkg: MessagePack, MessagePack
eco: nuget
published: Jun 25, 2026
## Summary

`MessagePackReader.TrySkip()` recursively descends into nested arrays and maps without incrementing the reader depth or calling the configured depth checks. This bypasses `MessagePackSecurity.MaximumObjectGraphDepth`, the library's documented protection against deeply nested object graph…

CVE-2026-48506
NVD

HIGH
CVE-2026-55961
CVE-2026-55961
pkg: wolfssl wolfssl

published: Jun 25, 2026

wolfSSL_PKCS7_verify() returning success for a degenerate (certs-only) PKCS#7 object that contains no signer. Such an object has empty signerInfos, so the underlying signed-data verification succeeds without authenticating any content. The compatibility-layer verify path now rejects the object when …
CWE: CWE-347
NVD

HIGH
CVE-2026-11999
CVE-2026-11999
pkg: wolfssl wolfssl

published: Jun 25, 2026

X.509 trust-chain bypass (path-depth exhaustion) in the OpenSSL compatibility certificate verifier (wolfSSL_X509_verify_cert()). This affects only builds with –enable-opensslextra whose application calls X509_verify_cert() with caller-supplied untrusted intermediates; for those users it is critical…
CWE: CWE-295
GitHub-GHSA

HIGH
OpenAM: Unauthenticated Authentication Bypass via RADIUS Spoofing
GHSA-386j-6m86-78f9
pkg: org.openidentityplatform.openam:openam-radius
eco: maven
published: Jun 25, 2026
## Summary

**Description**

An Improper Verification of Cryptographic Signature (CWE-347) issue in OpenAM's RADIUS authentication module allows an unauthenticated network attacker to spoof an Access-Accept response and obtain an OpenAM session for any RADIUS username, without knowing the configured…

CVE-2026-46560
NVD

HIGH
CVE-2026-54841
CVE-2026-54841
pkg: vite

published: Jun 25, 2026

Unauthenticated Sensitive Data Exposure in Vitepos <= 3.4.2 versions.
CWE: CWE-201
NVD

HIGH
CVE-2026-12490
CVE-2026-12490
pkg: nlnetlabs nsd

published: Jun 25, 2026

When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate with that name. However, no client certificate is needed when the request comes in over TLS over the regular tls-port (and not the tls-auth-port) or over over TCP over the regular …
CWE: CWE-284, CWE-306
NVD

HIGH
CVE-2026-12245
CVE-2026-12245
pkg: nlnetlabs nsd

published: Jun 25, 2026

NSD from version 4.13.0 has a heap use-after-free bug in logging errors on TLS connections, causing a crash of the server process, which can be triggered trivially by sending a DNS query over a DoT connection, and closing the connection without reading the response.
CWE: CWE-416
NVD

HIGH
CVE-2026-52794
CVE-2026-52794
pkg: sentry sentry

published: Jun 24, 2026

Sentry is an error tracking and performance monitoring tool. From 24.4.0 until 26.5.2, a Regular Expression Denial of Service (ReDoS) vulnerability exists in Sentry's event ingestion pipeline, where a regex applied to attacker-controlled fields on incoming events can be made to consume disproportion…
CWE: CWE-1333
NVD

HIGH
CVE-2026-13029
CVE-2026-13029
pkg: google chrome, apple macos, linux linux_kernel

published: Jun 24, 2026

Use after free in Web Authentication in Google Chrome prior to 149.0.7827.197 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-44017
CVE-2026-44017
pkg: docling docling

published: Jun 24, 2026

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. Prior to 2.91.0, the EasyOCR model download functionality extracted ZIP archives without validating member paths, enabling Zip Slip attacks. If an attacker could compromise …
CWE: CWE-22
GitHub-GHSA

HIGH
OliveTin has a Concurrent Template Parsing Race Condition which Leads to Cross-Request Command Contamination
GHSA-7fq5-7wr8-rjwj
pkg: github.com/OliveTin/OliveTin
eco: go
published: Jun 24, 2026
## Summary

OliveTin's template engine uses a **single shared `text/template.Template` instance** (`tpl` package-level variable in `service/internal/tpl/templates.go`) across all goroutines. Every action execution calls `tpl.Parse(source)` followed by `t.Execute()` on this shared instance with no sy…

CVE-2026-48708
NVD

HIGH
CVE-2026-52974
CVE-2026-52974
pkg: tls

published: Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

net: tls: fix strparser anchor skb leak on offload RX setup failure

When tls_set_device_offload_rx() fails at tls_dev_add(), the error path
calls tls_sw_free_resources_rx() to clean up the SW context that was
initialized by tls_se…

NVD

HIGH
CVE-2026-52957
CVE-2026-52957
pkg: linux

published: Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

libceph: Fix potential null-ptr-deref in decode_choose_args()

A message of type CEPH_MSG_OSD_MAP contains an OSD map that itself
contains a CRUSH map. When decoding this CRUSH map in crush_decode(), an
array of max_buckets CRUSH b…

NVD

HIGH
CVE-2026-52956
CVE-2026-52956
pkg: linux

published: Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

libceph: Fix potential out-of-bounds access in __ceph_x_decrypt()

In __ceph_x_decrypt(), a part of the buffer p is interpreted as a
ceph_x_encrypt_header, and the magic field of this struct is accessed.
This happens without any gu…

NVD

HIGH
CVE-2026-52954
CVE-2026-52954
pkg: linux

published: Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

libceph: handle rbtree insertion error in decode_choose_args()

A message of type CEPH_MSG_OSD_MAP contains an OSD map that itself
contains a CRUSH map. The received CRUSH map may optionally contain
choose_args that get decoded in …

NVD

HIGH
CVE-2026-52946
CVE-2026-52946
pkg: linux

published: Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling

A SOFTIRQ-safe to SOFTIRQ-unsafe lock order deadlock can occur in
send_sigio() and send_sigurg() when a process group receives a signal.

When FASYNC is configured for a …

NVD

HIGH
CVE-2026-52945
CVE-2026-52945
pkg: linux

published: Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

Revert "wireguard: device: enable threaded NAPI"

This reverts commit 933466fc50a8e4eb167acbd0d8ec96a078462e9c which is
commit db9ae3b6b43c79b1ba87eea849fd65efa05b4b2e upstream.

We have had three independent production user report…

NVD

HIGH
CVE-2026-56270
CVE-2026-56270
pkg: flowiseai flowise

published: Jun 24, 2026

Flowise before 3.1.0 (versions 3.0.13 and earlier) contains a missing authentication vulnerability in the /api/v1/loginmethod endpoint that allows unauthenticated users to retrieve an organization's complete SSO configuration, including OAuth client secrets in cleartext, by providing an organization…
CWE: CWE-306
NVD

HIGH
CVE-2026-52932
CVE-2026-52932
pkg: linux

published: Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

xfrm: ipcomp: Free destination pages on acomp errors

Move the out_free_req label up by a couple of lines so that the
allocated dst SG list gets freed on error as well as success.

NVD

HIGH
CVE-2026-52929
CVE-2026-52929
pkg: linux

published: Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

sctp: stream: fully roll back denied add-stream state

When ADD_OUT_STREAMS is denied, SCTP only shrinks the queued chunks and
then lowers outcnt. That leaves removed stream metadata behind, so a
later re-add can reuse a stale ext …

NVD

HIGH
CVE-2026-52922
CVE-2026-52922
pkg: linux

published: Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

batman-adv: dat: handle forward allocation error

batadv_dat_forward_data() calls pskb_copy_for_clone() to duplicate an skb
for each DHT candidate, but does not check the return value before passing
it to batadv_send_skb_prepare_un…

NVD

HIGH
CVE-2026-50193
CVE-2026-50193
pkg: fasterxml jackson-databind

published: Jun 23, 2026

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.13.0 until 2.14.0, a potential Denial-of-Service exists when attacker sends deeply nested JSON if (and only if) the service reads deeply nested (1000s of levels) JSON as JsonNod…
CWE: CWE-400
NVD

HIGH
CVE-2026-53754
CVE-2026-53754
pkg: docker

published: Jun 23, 2026

Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.8, the Docker API server's SSRF protection (validate_webhook_url / validate_url_destination in deploy/docker/utils.py) used an explicit IPv4/IPv6 CIDR blocklist that missed several address families. An attacker could reach i…
CWE: CWE-918
NVD

HIGH
CVE-2026-52844
CVE-2026-52844
pkg: tls

published: Jun 23, 2026

Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, on Windows, Caddy path matchers treat /private\secret.txt as outside /private/*, but file_server later resolves the same request path as private\secret.txt on disk. An unauthenticated remote client can bypass Caddy pat…
CWE: CWE-22, CWE-284
NVD

HIGH
CVE-2025-61025
CVE-2025-61025
pkg: ssl

published: Jun 23, 2026

An issue in the sslr_qst_get component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
CWE: CWE-89, CWE-400
NVD

HIGH
CVE-2026-54314
CVE-2026-54314
pkg: n8n n8n

published: Jun 23, 2026

n8n is an open source workflow automation platform. Prior to 2.24.0, the Compression node's Decompress operation expanded attacker-controlled archives into memory without enforcing limits on decompressed output size. An unauthenticated attacker could send a small compressed archive to a public webho…
CWE: CWE-409
NVD

HIGH
CVE-2023-54365
CVE-2023-54365
pkg: go

published: Jun 23, 2026

Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inherited from the Go standard library's HTTP/2 implementation (CVE-2023-44487 / CVE-2023-39325, the 'Rapid Reset' technique). A remote attacker can rapidly create and cancel HTTP/2 stre…
CWE: CWE-400
GitHub-GHSA

HIGH
Gogs Missing Authorization in Attachment Download
GHSA-p9f5-h3rx-j5qw
pkg: gogs.io/gogs
eco: go
published: Jun 22, 2026
## Summary

In Gogs 0.14.1, `GET /attachments/:uuid` returns the raw attachment file **without verifying whether the requester has view permission for the associated Issue/Comment/Release or the repository**.
In a test environment with `REQUIRE_SIGNIN_VIEW = false`, we confirmed that **an unauthenti…

CVE-2026-52799
NVD

HIGH
CVE-2026-41523
CVE-2026-41523
pkg: vllm vllm

published: Jun 22, 2026

vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, an assert-based security check in vLLM's activation function loading allows any unauthenticated attacker to achieve arbitrary code execution on the server by publishing a malicious HuggingFace model, when vLLM…
CWE: CWE-94, CWE-617
NVD

HIGH
CVE-2026-55603
CVE-2026-55603
pkg: chimurai http-proxy-middleware

published: Jun 22, 2026

http-proxy-middleware is node.js http-proxy middleware. From 3.0.4 until 3.0.7 and 4.1.1, fixRequestBody() is the library's documented helper for re-emitting a request body that was already consumed by a body parser. When the outgoing Content-Type is multipart/form-data, it rebuilds the body with ha…
CWE: CWE-93
GitHub-GHSA

HIGH
ComfyUI-Manager has an Unprotected Alternate Channel (CWE-420)
GHSA-95pq-hr8p-f5g7
pkg: comfyui-manager
eco: pip
published: Jun 22, 2026
### Impact

An **Unprotected Alternate Channel (CWE-420)** vulnerability was discovered in ComfyUI-Manager versions prior to 3.38.

#### Vulnerability Details

In affected versions, ComfyUI-Manager stored its configuration in the `user/default/ComfyUI-Manager/` directory, which was accessible via Co…

CVE-2025-67303
NVD

HIGH
CVE-2026-54293
CVE-2026-54293
pkg: nltk nltk

published: Jun 22, 2026

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. Prior to 3.10.0-rc1, nltk.data.load() in NLTK is vulnerable to path traversal via URL-encoded path separators and traversal segments …
CWE: CWE-22
NVD

HIGH
CVE-2026-53779
CVE-2026-53779
pkg: windows

published: Jun 22, 2026

WebP Server Go through 0.14.4 contains a path traversal vulnerability on Windows that allows unauthenticated attackers to read files outside the configured IMG_PATH directory by sending requests with percent-encoded backslashes (%5C) that bypass the path.Clean() sanitization in handler/router.go. At…
CWE: CWE-22
NVD

HIGH
CVE-2026-54280
CVE-2026-54280
pkg: aiohttp aiohttp

published: Jun 22, 2026

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, payload resources are not closed correctly when a client disconnects in the middle of a write. If a payload is using an open file or similar limited resource, then an attacker may be able to cause resour…
CWE: CWE-404
NVD

HIGH
CVE-2026-54279
CVE-2026-54279
pkg: aiohttp aiohttp

published: Jun 22, 2026

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, host-only cookies that are saved with CookieJar.save() and then restored later with CookieJar.load() lose their host-only status. This vulnerability is fixed in 3.14.1.
CWE: CWE-665
NVD

HIGH
CVE-2026-54278
CVE-2026-54278
pkg: aiohttp aiohttp

published: Jun 22, 2026

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is possible for a compressed request body to be decompressed into memory in one chunk. An attacker may be able to send a compressed payload in specific situations that could be decompre…
CWE: CWE-409
NVD

HIGH
CVE-2026-54275
CVE-2026-54275
pkg: aiohttp aiohttp

published: Jun 22, 2026

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, the server_hostname TLS SNI check can be bypassed when an existing connection is reused. If an application makes multiple requests to the same domain, but with different per-request server_hostname param…
CWE: CWE-297
NVD

HIGH
CVE-2026-54274
CVE-2026-54274
pkg: aiohttp aiohttp

published: Jun 22, 2026

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, if an attacker sends large incomplete websocket frame payloads, it may be possible to bypass the usual size limits on memory use. This vulnerability is fixed in 3.14.1.
CWE: CWE-770
NVD

HIGH
CVE-2026-54273
CVE-2026-54273
pkg: aiohttp aiohttp

published: Jun 22, 2026

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, no limit was present on the number of pipelined requests that could be queued. An attacker may be able to use pipelined requests to use excessive amounts of memory, potentially leading to DoS. This vulne…
CWE: CWE-770
NVD

HIGH
CVE-2026-53571
CVE-2026-53571
pkg: vitejs vite, voidzero vite\+, microsoft windows

published: Jun 22, 2026

Vite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files that are specified by server.fs.deny can be returned to the browser on Windows. Vite’s dev server denies direct access to sensitive files through server.fs.deny, including entries such as …
CWE: CWE-22, CWE-200
NVD

HIGH
CVE-2026-53539
CVE-2026-53539
pkg: fastapiexpert python-multipart

published: Jun 22, 2026

Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, when parsing application/x-www-form-urlencoded bodies, QuerystringParser located the field separator with a two step lookup: it first scanned the entire remaining buffer for &, and only when no & existed anywhere ahead did…
CWE: CWE-400, CWE-407
NVD

HIGH
CVE-2026-50269
CVE-2026-50269
pkg: aiohttp aiohttp

published: Jun 22, 2026

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.0, attacker-controlled input included into multipart/payload headers can be used to modify a request to inject additional headers or similar. In the unlikely situation that an application is passing user-co…
CWE: CWE-93, CWE-113
NVD

HIGH
CVE-2026-48712
CVE-2026-48712
pkg: protobufjs_project protobufjs

published: Jun 22, 2026

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.1 and 8.4.1, protobufjs could recurse without a depth limit while converting decoded messages to plain objects or JSON. This affected generated toObject() conversion and the custom google.protobuf.Any JSON conversi…
CWE: CWE-674
NVD

HIGH
CVE-2026-54268
CVE-2026-54268
pkg: angularjs angularjs

published: Jun 22, 2026

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, 21.2.17, and 20.3.25, a Denial of Service (DoS) vulnerability exists in the @angular/common package of the Angular framework. The formatDate function, …
CWE: CWE-400, CWE-1333
GitHub-GHSA

HIGH
Hysteria has an authenticated UDP ACL bypass that enables localhost and private-network UDP SSRF
GHSA-vgrc-hq28-p3xp
pkg: github.com/apernet/hysteria/core/v2
eco: go
published: Jun 26, 2026
## Summary

Hysteria's UDP relay treats the destination address as packet-scoped, but ACL and outbound policy are applied only once when a new UDP session is created. After an authenticated client opens a UDP session using an allowed first destination, later packets in the same `Session ID` can be s…

NVD

HIGH
CVE-2026-55759
CVE-2026-55759
pkg: jwt

published: Jun 24, 2026

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13, Rocket.Chat's Apple Sign-In handler verifies JWT signatures but skips claims validation. Any Apple-signed JWT with a non-empty iss is accepted regardless…
CWE: CWE-287, CWE-294
NVD

HIGH
CVE-2026-49440
CVE-2026-49440
pkg: deno deno

published: Jun 23, 2026

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, node:crypto.checkPrime(candidate[, options][, callback]) and crypto.checkPrimeSync(candidate[, options]) ran no Miller-Rabin rounds at all when the caller left options.checks at its default of 0. In that mode, the only test a…
CWE: CWE-325
NVD

HIGH
CVE-2026-44726
CVE-2026-44726
pkg: deno deno

published: Jun 23, 2026

Deno is a JavaScript, TypeScript, and WebAssembly runtime. From 2.0.0 until 2.7.8, a flaw in Deno's Node.js tls compatibility layer could cause a TLS client to transmit application data in plaintext after a connection retry. When `autoSelectFamily was enabled and the first address-family attempt fai…
CWE: CWE-319
GitHub-GHSA

HIGH
Budibase: Unauthenticated S3 signed upload URL generation allows arbitrary writes with stored datasource credentials
GHSA-jj36-r9w3-3pfh
pkg: @budibase/server
eco: npm
published: Jun 22, 2026
The application server exposes an unauthenticated endpoint that generates S3 `PutObject` presigned URLs using credentials stored in a workspace datasource. The route is protected only by the recaptcha middleware and does not require authentication, table permission, datasource permission, or builder…
CVE-2026-50136
GitHub-GHSA

HIGH
Glances: XML-RPC Multi-Origin CORS Configuration Silently Falls Back to Wildcard (Incomplete Fix for CVE-2026-33533)
GHSA-87qc-fj39-wccr
pkg: glances
eco: pip
published: Jun 22, 2026
### Summary

The Glances XML-RPC server (`glances -s`) introduced a configurable CORS origin list in version 4.5.3 as a mitigation for CVE 2026-33533. However, the implementation silently falls back to `Access-Control-Allow-Origin: *` whenever `cors_origins` contains more than one entry. An operat…

CVE-2026-46608
GitHub-GHSA

HIGH
pnpm Vulnerable to Arbitrary File Write/Delete via Malicious Patch File (Path Traversal)
GHSA-rxhj-4m44-96r4
pkg: pnpm, pnpm
eco: npm
published: Jun 26, 2026
## Summary

pnpm's patch application pipeline (`@pnpm/patch-package`) performs no path validation on file paths extracted from `.patch` files. An attacker who contributes a malicious patch file via a pull request can write attacker-controlled content to or delete arbitrary files on the filesystem du…

CVE-2026-50015
NVD

HIGH
CVE-2026-13201
CVE-2026-13201
pkg: kubernetes

published: Jun 24, 2026

A flaw was found in KubeVirt's safepath package used by virt-handler. The OpenAtNoFollow function uses O_PATH|O_NOFOLLOW to obtain a file descriptor to a path leaf, but downstream operations resolve the path via /proc/self/fd/N using link-following syscalls. When the leaf is a symlink, the kernel de…
CWE: CWE-61
NVD

HIGH
CVE-2026-54328
CVE-2026-54328
pkg: linux

published: Jun 23, 2026

Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi versions with temporary npm or git extension package installs used predictable paths under the operating system temporary directory. On Linux-based multi-user systems, a local attacker who can write to the shared temporary directo…
CWE: CWE-379
GitHub-GHSA

HIGH
Budibase has an Account Impersonation Issue — Chat Identity Link Hijacking via Missing Consent & CSRF
GHSA-v7j5-vc4m-723w
pkg: @budibase/server
eco: npm
published: Jun 22, 2026
## Title

**Chat Identity Link Hijacking — Attacker Can Silently Map Their Slack/Discord Identity to Any Authenticated Budibase User's Account**

## Severity

**High** — CVSS 3.1: AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N = **7.3**

## Affected Product

– **Product:** Budibase
– **Version:** 3.37.2 (i…

CVE-2026-50132
GitHub-GHSA

HIGH
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
GHSA-72f5-rr8c-r6gr
pkg: fluentd
eco: rubygems
published: Jun 26, 2026
The `out_http` output plugin allows the use of placeholders (such as `${tag}`) in the `endpoint` configuration parameter.
It was discovered that if the placeholder value is derived from untrusted user input, an attacker can maliciously control the destination hostname of the outbound HTTP requests m…
CVE-2026-44161
NVD

HIGH
CVE-2026-50189
CVE-2026-50189
pkg: appsmith appsmith

published: Jun 24, 2026

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, Appsmith's bundled supervisord exposes an XML-RPC interface on port 9001, reachable from outside the container via a Caddy reverse-proxy route at /supervisor/* on the public ingress. Combined with the APPSMIT…
CWE: CWE-183, CWE-918
NVD

HIGH
CVE-2026-54308
CVE-2026-54308
pkg: n8n n8n

published: Jun 23, 2026

n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, the MicrosoftAgent365Trigger and StripeTrigger node did not validate that inbound requests. As a result, an unauthenticated attacker who knows the webhook URL could submit a forged payload and cause the workflow to execu…
CWE: CWE-290
GitHub-GHSA

HIGH
pnpm: `patch-remove` could delete project-selected files outside the patches directory
GHSA-72r4-9c5j-mj57
pkg: pnpm, pnpm
eco: npm
published: Jun 27, 2026
## Summary

The `patch-remove` deletion-scope issue tracked as GHSA-72r4-9c5j-mj57 / CAND-PNPM-030 has been addressed in pnpm.

A crafted patch entry could resolve outside the configured patches directory and cause `pnpm patch-remove` to delete an arbitrary reachable file. This patch validates the c…

GitHub-GHSA

HIGH
pnpm: Hoisted install imports lockfile alias outside node_modules
GHSA-fr4h-3cph-29xv
pkg: pnpm, pnpm
eco: npm
published: Jun 27, 2026
## Summary

The hoisted dependency alias issue tracked as GHSA-fr4h-3cph-29xv / CAND-PNPM-059 has been addressed in both pnpm and pacquet.

A crafted lockfile alias could be joined directly under a hoisted `node_modules` directory. Traversal aliases could escape that directory, while reserved aliase…

GitHub-GHSA

HIGH
pnpm: `stage download` writes outside its destination directory via manifest name/version traversal
GHSA-v23m-ccfg-pq9h
pkg: pnpm
eco: npm
published: Jun 26, 2026
## Summary

The staged-tarball filename traversal reported as GHSA-v23m-ccfg-pq9h / CAND-PNPM-038 is fixed on `main` by [pnpm/pnpm#12303](https://github.com/pnpm/pnpm/pull/12303), merged as `65443f4bdf1f0db9c8c7dc58fee25252607e9234`.

Before the fix, `pnpm stage download` derived a local filename fr…

CVE-2026-55700
GitHub-GHSA

HIGH
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR)
GHSA-hmgp-w9jm-vp95
pkg: go.senan.xyz/gonic
eco: go
published: Jun 26, 2026
## Summary

In gonic, the Subsonic API endpoints `/rest/deletePlaylist.view` and `/rest/getPlaylist.view` perform no per-resource authorization. Once authenticated as *any* user (admin or not), an attacker can:

1. **Delete any playlist owned by any other user** (including admin) by passing its `id`…

CVE-2026-49338
GitHub-GHSA

HIGH
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists
GHSA-2fp4-5v5c-4448
pkg: go.senan.xyz/gonic
eco: go
published: Jun 26, 2026
## Summary

The maintainer's recent fix in [`6dd71e6a3c966867ef8c900d359a7df75789f410`](https://github.com/sentriz/gonic/commit/6dd71e6) (`fix(subsonic): enforce playlist ownership on getPlaylist/deletePlaylist`) added an ownership check based on `playlist.UserID`. However, `playlist.UserID` is deri…

CVE-2026-49339
GitHub-GHSA

HIGH
amazon-braket-sdk vulnerable to Insecure Deserialization via pickle.loads()
GHSA-g697-2xrc-gc46
pkg: amazon-braket-sdk
eco: pip
published: Jun 25, 2026
**Summary**
Amazon Braket SDK is an open-source Python library for interacting with the Amazon Braket quantum computing service, including managing hybrid quantum jobs and retrieving job results. An issue exists where, under certain circumstances, a remote authenticated user with S3 write access to …
CVE-2026-9291
NVD

HIGH
CVE-2026-9154
CVE-2026-9154
pkg: gnu sed, linux linux_kernel

published: Jun 25, 2026

Arbitrary File Write vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to write attacker-controlled content to arbitrary file paths via the expression parameter.
CWE: CWE-22
NVD

HIGH
CVE-2026-53040
CVE-2026-53040
pkg: go

published: Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

ocfs2: validate bg_bits during freefrag scan

[BUG]
A crafted filesystem can trigger an out-of-bounds bitmap walk when
OCFS2_IOC_INFO is issued with OCFS2_INFO_FL_NON_COHERENT.

BUG: KASAN: use-after-free in instrument_atomic_read …

NVD

HIGH
CVE-2026-52988
CVE-2026-52988
pkg: go

published: Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_tables: join hook list via splice_list_rcu() in commit phase

Publish new hooks in the list into the basechain/flowtable using
splice_list_rcu() to ensure netlink dump list traversal via rcu is safe
while concurrent r…

NVD

HIGH
CVE-2026-52953
CVE-2026-52953
pkg: linux

published: Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

iommu/vt-d: Fix oops due to out of scope access

Below oops triggers when kill QEMU process:

Oops: general protection fault, probably for non-canonical address 0x7fffffff844eaaa7: 0000 [#1] SMP NOPTI
Call Trace:
<TASK>
d…

NVD

HIGH
CVE-2026-52942
CVE-2026-52942
pkg: linux

published: Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_log: validate MAC header was set before dumping it

The fallback path of dump_mac_header() guards the MAC header access
only with "skb->mac_header != skb->network_header", without checking
skb_mac_header_was_set(). Wh…

NVD

HIGH
CVE-2026-52917
CVE-2026-52917
pkg: linux

published: Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

sctp: diag: reject stale associations in dump_one path

The SCTP exact sock_diag lookup can hold a transport reference, block on
lock_sock(sk), and then resume after sctp_association_free() has marked
the association dead and freed…

NVD

HIGH
CVE-2026-52915
CVE-2026-52915
pkg: linux

published: Jun 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

netfilter: ip6t_hbh: reject oversized option lists

struct ip6t_opts stores at most IP6T_OPTS_OPTSNR option descriptors,
but hbh_mt6_check() does not reject larger optsnr values supplied from
userspace.

Validate optsnr in the rule…

NVD

HIGH
CVE-2026-54761
CVE-2026-54761
pkg: traefik traefik

published: Jun 23, 2026

Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.21 and 3.7.5, there is a high severity vulnerability in Traefik's Kubernetes Gateway provider affecting the crossProviderNamespaces allowlist. For HTTPRoute rules that declare multiple (WRR) backendRefs, Traefik evaluates the allowlist…
CWE: CWE-284, CWE-863
NVD

HIGH
CVE-2026-54318
CVE-2026-54318
pkg: home-assistant home_assistant_companion

published: Jun 23, 2026

Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.5.3, the LocationSensorManager BroadcastReceiver is exported with no permission. Any installed app, with zero runtime permissions, can broadcast a forged Google Play Services LocationResul…
CWE: CWE-926
GitHub-GHSA

HIGH
Gogs's write-level collaborators can mutate admin-only repository settings via API
GHSA-268j-37xf-pp52
pkg: gogs.io/gogs
eco: go
published: Jun 23, 2026
## Summary

Three API endpoints — `PATCH /api/v1/repos/:owner/:repo/issue-tracker`, `PATCH /api/v1/repos/:owner/:repo/wiki`, and `POST /api/v1/repos/:owner/:repo/mirror-sync` — are gated by `reqRepoWriter()` rather than `reqRepoAdmin()`. The equivalent operations in the web UI sit behind `reqRep…

CVE-2026-52808
NVD

HIGH
CVE-2026-56275
CVE-2026-56275
pkg: flowiseai flowise

published: Jun 23, 2026

Flowise before 3.1.0 contains a server-side request forgery vulnerability in the Execute Flow node that allows attackers to bypass security validation by providing intranet addresses through the base URL field. Attackers can initiate HTTP requests to internal network addresses, access cloud metadata…
CWE: CWE-918
GitHub-GHSA

HIGH
Blnk has an API key authorization bypass in owner and scope enforcement
GHSA-wcr3-9x4c-f5gj
pkg: github.com/blnkfinance/blnk
eco: go
published: Jun 26, 2026
Blnk API key endpoints had an authorization issue that allowed non-master API keys to perform key-management actions outside their intended authorization boundary.

In affected versions, API key operations trusted caller-controlled request values for owner and scope decisions. As a result, a non-mas…

GitHub-GHSA

HIGH
Streamable HTTP mode exposes LINE Desktop read/send tools without MCP authentication
GHSA-4hf8-5mjm-rfgq
pkg: line-desktop-mcp
eco: npm
published: Jun 26, 2026
# Streamable HTTP mode exposes LINE Desktop read/send tools without MCP authentication

## Summary

`line-desktop-mcp` supports a `–http-mode` Streamable HTTP transport for use with clients such as n8n. In this mode the server binds to `0.0.0.0` and exposes the MCP `/mcp` endpoint without an MCP-la…

CVE-2026-49357
GitHub-GHSA

HIGH
LinkifyIt#match scan loop has quadratic algorithmic complexity
GHSA-22p9-wv53-3rq4
pkg: linkify-it
eco: npm
published: Jun 26, 2026
## Summary

`LinkifyIt.prototype.match` — the package's primary public API — has **O(N²) algorithmic complexity** for inputs containing many fuzzy links or emails. This is not a regex backtrack bug; it's a structural issue in the JS-level scan loop that re-slices the input and re-runs unanchore…

CVE-2026-48801
GitHub-GHSA

HIGH
OpenAM Account Takeover via Unverified Password Change in OAuth2 Module
GHSA-gf57-4mp6-m85x
pkg: org.openidentityplatform.openam:openam-auth-oauth2
eco: maven
published: Jun 26, 2026
## Summary

**Description**

An Unverified Password Change (CWE-620) and Use of Weak Credentials (CWE-1391) issue in OpenAM's OAuth2 authentication module silently rewrites a local user's password to the literal string of their username on OAuth2 re-login of an existing account. The default ldapServ…

CVE-2026-46623
GitHub-GHSA

HIGH
OpenAM Authentication Bypass via MSISDN LDAP Injection
GHSA-xq73-fvmr-jvmm
pkg: org.openidentityplatform.openam:openam-auth-msisdn
eco: maven
published: Jun 26, 2026
## Summary

**Description**

An LDAP Injection (CWE-90) vulnerability in the MSISDN authentication module allows an unauthenticated, remote attacker to obtain an arbitrary OpenAM session without a password in the default trusted gateway configuration. This impacts OpenAM Community Edition through ve…

CVE-2026-46619
GitHub-GHSA

HIGH
MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows
GHSA-382j-8mxh-c7x2
pkg: MessagePack
eco: nuget
published: Jun 25, 2026
## Summary

`MessagePackReader.ReadDateTime()` can allocate stack memory based on an attacker-controlled MessagePack extension length. In the slow path for timestamp extension parsing, the computed `tokenSize` includes the extension body length from the wire and is used in a `stackalloc` operation b…

CVE-2026-48502
GitHub-GHSA

HIGH
chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header
GHSA-rjr7-jggh-pgcp
pkg: github.com/go-chi/chi/middleware, github.com/go-chi/chi/v2/middleware, github.com/go-chi/chi/v3/middleware
eco: go
published: Jun 25, 2026
### Summary
realip middleware in go-chi/chi trusts headers like x-forwarded-for without checking them, so attackers can fake their ip and bypass rate limits or access controls

### Details

the vuln is in middleware/realip.go , the realIP() function pulls IPs straight from client headers and replace…

GitHub-GHSA

HIGH
chi Middleware Vulnerable to Potential IP Spoofing via `X-Forwarded-For` Header in `Request.RemoteAddr` Resolution
GHSA-9g5q-2w5x-hmxf
pkg: github.com/go-chi/chi/middleware, github.com/go-chi/chi/v2/middleware, github.com/go-chi/chi/v3/middleware
eco: go
published: Jun 25, 2026
### Summary
The vulnerability allows the `Request.RemoteAddr` to be spoofed when determining the request source IP via the `X-Forwarded-For` header. This could result in misidentification of the request source and potentially compromise access control and logging integrity.

### Details
Currently, t…

GitHub-GHSA

HIGH
OpenAM Arbitrary OAuth Token Minting via Push Registration
GHSA-cj8f-2fhf-826r
pkg: org.openidentityplatform.openam:openam-oauth2
eco: maven
published: Jun 25, 2026
## Summary

**Description**

An Authorization Bypass Through User-Controlled Key (CWE-639) exists in OpenAM's stateful OAuth2 token-read path. Under certain conditions, this may allow an attacker to forge OAuth2 bearer tokens and OIDC ID tokens with arbitrary subject, client, realm, and scope. This …

CVE-2026-46498
GitHub-GHSA

HIGH
OpenAM has Unsafe Java Deserialization via SNS
GHSA-pp89-732f-3g8q
pkg: org.openidentityplatform.openam:openam-push-notification
eco: maven
published: Jun 25, 2026
## Summary

**Description**

A Deserialization of Untrusted Data (CWE-502) issue exists in OpenAM's Push Notification SNS callback resource. The REST route that handles SNS push messages is mounted with anonymous access and, when a supplied message identifier has expired from the in-memory dispatche…

CVE-2026-45794
GitHub-GHSA

HIGH
motionEye's Absolute Path Traversal in Media File Handlers Allows Arbitrary File Read
GHSA-rw9q-97r9-8gvh
pkg: motioneye
eco: pip
published: Jun 23, 2026
### Summary

mEye contains an absolute path traversal vulnerability in multiple media file handlers that allows an attacker to read arbitrary files from the filesystem.

The affected handlers accept a user-controlled filename parameter and construct filesystem paths using `os.path.join()`. When an a…

CVE-2026-55488
GitHub-GHSA

HIGH
OctoPrint has possible file exfiltration via query parameters on upload endpoints
GHSA-j4h9-pm27-4rfw
pkg: OctoPrint, OctoPrint
eco: pip
published: Jun 23, 2026
### Impact

OctoPrint versions up until and including 1.11.7 as well as 2.0.0rc1 and 2.0.0rc2 contain a vulnerability that allows an attacker with the `FILE_UPLOAD` permission to exfiltrate files from the host that OctoPrint has read access to, by moving them into the upload folder where they then c…

CVE-2026-54134
GitHub-GHSA

HIGH
Gogs: LFS dedupe path leaks private repo content across tenants
GHSA-6p9m-q3jp-47h4
pkg: gogs.io/gogs
eco: go
published: Jun 23, 2026
Summary

Git LFS storage is content-addressed by OID alone (`<LFS-root>/<oid[0]>/<oid[1]>/<oid>`) but per-repo authorization lives in the `lfs_object` table keyed `(repo_id, oid)`. `serveUpload` skips re-uploading when the OID file already exists on disk and inserts a new `(repo_id, oid)` row pointi…

CVE-2026-52812
GitHub-GHSA

HIGH
Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion
GHSA-wmfg-5p4h-5fw3
pkg: gogs.io/gogs
eco: go
published: Jun 23, 2026
### Summary

Git smart HTTP authorizes `POST …/git-receive-pack` using the client-supplied service query string (so `?service=git-upload-pack` is evaluated as read access) while routing still runs git receive-pack, allowing push where only read should be allowed.

### Details

Gogs' Git Smart HTTP…

CVE-2026-52810
GitHub-GHSA

HIGH
Gogs has DOM-based XSS via Milestone Name on New Issue Page
GHSA-vcm5-gvmp-78mp
pkg: gogs.io/gogs
eco: go
published: Jun 23, 2026
### Summary
The fix for GHSA-vgjm-2cpf-4g7c (DOM-based XSS via milestone selection) was only applied to `templates/repo/issue/view_content.tmpl` but not to `templates/repo/issue/new_form.tmpl`. An attacker can store an HTML/JavaScript payload in a milestone name, and when any user opens the New Issu…
CVE-2026-52807
GitHub-GHSA

HIGH
Budibase: POST /api/attachments/:datasourceId/url is unauthenticated and lets anonymous callers mint S3 PUT pre-signed URLs using stored datasource IAM credentials
GHSA-35c4-rvc8-frhm
pkg: @budibase/server
eco: npm
published: Jun 22, 2026
## Summary

The Budibase server route `POST /api/attachments/:datasourceId/url` ([`packages/server/src/api/routes/static.ts`](https://github.com/Budibase/budibase/blob/56d2a984/packages/server/src/api/routes/static.ts)) is registered with **only** the `recaptcha` middleware. There is no `authorized(…

CVE-2026-50137
GitHub-GHSA

HIGH
skillctl: argument injection, path traversal in –dest, FIFO/device DoS, hardlink exfiltration, and commit-trailer forgery
GHSA-74p7-6h78-gw8p
pkg: skillctl
eco: rust
published: Jun 22, 2026
## Impact

Following the path-safety patches in [GHSA-wx3m-whqv-xv47](https://github.com/umanio-agency/skillctl/security/advisories/GHSA-wx3m-whqv-xv47) (v0.1.2), a comprehensive multi-angle audit surfaced five further vulnerabilities, now patched in v0.1.3:

1. **`source_sha` argument injection in …

GitHub-GHSA

HIGH
OpenAM has LDAP Injection via `_queryId` Parameter
GHSA-2vg8-q4c2-5cw3
pkg: org.openidentityplatform.openam:openam-core-rest
eco: maven
published: Jun 22, 2026
OpenAM (Open Identity Platform) is an open-source IAM platform providing SSO, OAuth2, SAML, and OpenID Connect capabilities. The CREST REST API layer exposes user query endpoints under `/json/{realm}/users`. In `IdentityResourceV1.queryCollection()`, the HTTP query parameter `_queryId` is passed to …
CVE-2026-41573
GitHub-GHSA

HIGH
Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers
GHSA-w6j9-vw59-27wv
pkg: gogs.io/gogs
eco: go
published: Jun 22, 2026
## Summary

When `ENABLE_REVERSE_PROXY_AUTHENTICATION` is enabled, Gogs accepts the configured authentication header (default: `X-WEBAUTH-USER`) directly from client requests without validating that the request originated from a trusted reverse proxy. Any remote attacker who can reach the Gogs servi…

CVE-2026-25119
GitHub-GHSA

MEDIUM
MessagePack-CSharp: ExpandoObject formatter can perform quadratic insertion work on untrusted maps
GHSA-2×83-8g95-xh59
pkg: MessagePack, MessagePack
eco: nuget
published: Jun 25, 2026
## Summary

`ExpandoObjectFormatter.Deserialize` populates `System.Dynamic.ExpandoObject` by calling `IDictionary<string, object>.Add` for each map entry. `ExpandoObject` internally maintains member names in array-like structures, so inserting many distinct keys can require repeated linear scans and…

CVE-2026-48511
GitHub-GHSA

MEDIUM
MessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengths
GHSA-v72x-2h86-7f8m
pkg: MessagePack, MessagePack
eco: nuget
published: Jun 25, 2026
## Summary

When MessagePack-CSharp decompresses `Lz4Block` or `Lz4BlockArray` payloads, it reads declared uncompressed lengths from the wire and allocates output buffers based on those lengths before validating that the compressed data is valid or that the declared expansion is reasonable.

A small…

CVE-2026-48510
NVD

MEDIUM
CVE-2026-47693
CVE-2026-47693
pkg: go

published: Jun 23, 2026

Poweradmin is a web-based DNS administration tool for PowerDNS server. Versions prior to 4.2.4 and 4.3.3 are vulnerable to CSV Injection (Formula Injection) in its log export functionality. User-controlled data — specifically the username field — is written to exported CSV files without sanitizi…
CWE: CWE-1236
GitHub-GHSA

MEDIUM
Nezha Monitoring: OAuth2 Redirect URL — Host Header Injection
GHSA-9rc6-8cjv-rcvx
pkg: github.com/nezhahq/nezha
eco: go
published: Jun 26, 2026
## 1. Description

The `getRedirectURL` function in `oauth2.go:22-29` constructs the OAuth2 callback URL by concatenating the request's `Host` header with a fixed path, with **zero validation** of the Host header:

“`go
func getRedirectURL(c *gin.Context) string {
scheme := "http://"
refere…

CVE-2026-53523
GitHub-GHSA

MEDIUM
pnpm Has an Integrity Check Bypass via Missing Lockfile Integrity Field
GHSA-q6j5-fjx5-2mc3
pkg: pnpm, pnpm
eco: npm
published: Jun 26, 2026
## Summary

pnpm's tarball extraction worker skips integrity verification when the `integrity` field is absent from the lockfile resolution. If an attacker can both modify `pnpm-lock.yaml` to remove the `integrity:` field and cause the referenced registry URL to serve altered package content, `pnpm …

CVE-2026-50021
GitHub-GHSA

MEDIUM
pnpm: Unsafe default behavior breaks integrity check
GHSA-54hh-g5mx-jqcp
pkg: pnpm, pnpm
eco: npm
published: Jun 26, 2026
While it is unclear whether this should be classified as a vulnerability, it is being reported through this channel because the current behavior may represent an unsafe default.

## Summary

`pnpm install` in non-frozen mode can accept new remote package content after detecting that the downloaded t…

CVE-2026-50573
GitHub-GHSA

MEDIUM
regclient may leak authentication credentials to external blob stores
GHSA-qvqc-4c52-x6qp
pkg: github.com/regclient/regclient
eco: go
published: Jun 26, 2026
Credentials for a registry may be inadvertently leaked to external servers. A prerequisite for this attack is a malicious registry server, a malicious blob store, or a registry that does not restrict the external URLs for foreign blobs.

## Example attack

A malicious registry serves an OCI image ma…

CVE-2026-49349
GitHub-GHSA

MEDIUM
pydantic-ai: SSRF blocklist bypass via IPv4-compatible, SIIT/IVI, and local NAT64 IPv6 addresses (incomplete fix of CVE-2026-46678)
GHSA-cg7w-rg45-pc59
pkg: pydantic-ai-slim, pydantic-ai, pydantic-ai
eco: pip
published: Jun 26, 2026
## Summary

When an application using Pydantic AI opts a URL into `force_download='allow-local'` (which disables the default block on private/internal IPs) **and runs on a network that routes the affected IPv6 transition forms (NAT64- or ISATAP-configured networks)**, the cloud-metadata blocklist co…

CVE-2026-48782
NVD

MEDIUM
CVE-2026-47775
CVE-2026-47775
pkg: oauth

published: Jun 26, 2026

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, the OAuth2 HTTP filter's encrypt()/decrypt() functions use AES-256-CBC without an authentication tag (no HMAC, no AEAD). The /callback endpoint returns HTTP 302 on suc…
CWE: CWE-209, CWE-327
GitHub-GHSA

MEDIUM
LangGraph Checkpoint: Unsafe JSON deserialization in checkpoint loading
GHSA-fjqc-hq36-qh5p
pkg: langgraph-checkpoint
eco: pip
published: Jun 25, 2026
## Summary

LangGraph's `JsonPlusSerializer` can reconstruct Python objects from JSON checkpoint payloads. Under conditions where someone could modify checkpoint bytes at rest in the backing store, the deserialization path could reconstruct objects beyond what the application expects, which could in…

CVE-2026-48775
GitHub-GHSA

MEDIUM
Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES
GHSA-5c3f-6486-3g7g
pkg: gogs.io/gogs
eco: go
published: Jun 23, 2026
## Summary

Password-reset tokens are generated using `conf.Auth.ActivateCodeLives` (the account-activation lifetime), not `conf.Auth.ResetPasswordCodeLives`. The token lifetime is baked into the token itself at generation time and is re-extracted from the token at verification time, making `RESET_P…

CVE-2026-52809
NVD

MEDIUM
CVE-2026-56109
CVE-2026-56109
pkg: linux

published: Jun 22, 2026

The Advanced Linux Sound Architecture (ALSA) library before 1.2.16.1 contains a double-free vulnerability in parse_def() in src/conf.c that allows attackers to corrupt memory by supplying maliciously crafted ALSA configuration text. When parsing nested compound or array configuration blocks, parse_d…
CWE: CWE-415
GitHub-GHSA

MEDIUM
pnpm: Reserved bin name deletes PNPM_HOME during global remove
GHSA-4gxm-v5v7-fqc4
pkg: pnpm, pnpm
eco: npm
published: Jun 26, 2026
<details>
<summary>Maintainer Action Plan</summary>

## Maintainer Action Plan

This report is ready to review with the shared patch branch. Start with the PR and the expected fixed behavior, then use the detailed exploit narrative below only if you want to replay the original path.

– Advisory: `CA…

CVE-2026-55699
GitHub-GHSA

MEDIUM
pnpm: Repository config can expand victim environment secrets into registry requests before scripts run
GHSA-3qhv-2rgh-x77r
pkg: pnpm, pnpm
eco: npm
published: Jun 26, 2026
<!– maintainer-action:start –>
## Maintainer Action Plan

This report is ready to review with the shared patch branch. Start with the PR and the expected fixed behavior, then use the detailed exploit narrative below only if you want to replay the original path.

– Advisory: `CAND-PNPM-122` / `GHSA…

CVE-2026-55180
GitHub-GHSA

MEDIUM
Nezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoS
GHSA-jg62-j5h6-8mpq
pkg: github.com/nezhahq/nezha
eco: go
published: Jun 26, 2026
## 1. Description

The Nezha dashboard exposes two endpoints that create long-lived WebSocket streams to monitored agents:

– `POST /api/v1/terminal` → `createTerminal()` (terminal.go:27-67)
– `POST /api/v1/file` → `createFM()` (fm.go:28-67)

Both call `rpc.NezhaHandlerSingleton.CreateStream(str…

CVE-2026-53522
GitHub-GHSA

MEDIUM
Nezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing
GHSA-x6fg-52vr-hj4w
pkg: github.com/nezhahq/nezha
eco: go
published: Jun 26, 2026
### Summary
An authenticated non-admin user who owns any server can create or update a NAT profile whose `domain` is equal to the dashboard's own HTTP Host (for example, `dashboard.example:8008`). The dashboard's top-level HTTP/gRPC multiplexer checks `NATShared.GetNATConfigByDomain(r.Host)` before …
CVE-2026-53520
NVD

MEDIUM
CVE-2026-48618
CVE-2026-48618
pkg: nodejs node.js

published: Jun 26, 2026

A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismat.

This can lead to confidentiality impact or bypass of the intended security boundary under affec…

CWE: CWE-176
NVD

MEDIUM
CVE-2026-55962
CVE-2026-55962
pkg: wolfssl wolfssl

published: Jun 25, 2026

TLS 1.3 post-handshake authentication (PHA) issue where a server could accept a client's Finished message without the client having sent a Certificate and CertificateVerify. The post-handshake-auth exemption that allows an empty/absent peer certificate was only intended for the initial handshake, bu…
CWE: CWE-287
GitHub-GHSA

MEDIUM
golang.org/x/crypto/ssh: Invoking memory leak when rejecting channels can lead to DoS
GHSA-qpw4-5×99-6vjp
pkg: golang.org/x/crypto/ssh
eco: go
published: Jun 25, 2026
An authenticated SSH client that repeatedly opened channels which were rejected by the server caused unbounded memory growth, eventually crashing the server process and affecting all connected users. Rejected channels are now properly removed from the connection's internal state and released for gar…
CVE-2026-39827
NVD

MEDIUM
CVE-2026-54092
CVE-2026-54092
pkg: docker

published: Jun 25, 2026

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.6, unchecked passwords maximums allow for an arbitrarily large password to be passed into the login API. This spikes CPU and memory, and after testin…
CWE: CWE-400, CWE-1284
GitHub-GHSA

MEDIUM
FileBrowser: Missing Rate Limiting on Authentication Endpoint Enables Brute Force Attacks
GHSA-r4v7-6wcg-ghj5
pkg: github.com/gtsteffaniak/filebrowser
eco: go
published: Jun 25, 2026
### Summary
The `/api/auth/login` endpoint does not implement rate limiting, account lockout, or progressive backoff for repeated authentication failures. As a result, an attacker can perform unlimited login attempts against the endpoint. When combined with the username enumeration timing vulnerabil…
NVD

MEDIUM
CVE-2026-6091
CVE-2026-6091
pkg: wolfssl wolfssl

published: Jun 25, 2026

Partial-chain certificate verification may accept chains that terminate at a peer-supplied, untrusted intermediate certificate rather than a trusted anchor. An attacker could present a chain that ends at an intermediate they control and have it accepted as valid. This affects the OpenSSL compatibili…
CWE: CWE-295
NVD

MEDIUM
CVE-2026-9153
CVE-2026-9153
pkg: gnu sed, linux linux_kernel

published: Jun 25, 2026

Arbitrary File Read vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to read arbitrary files via the expression parameter due to insufficient input validation.
CWE: CWE-22, CWE-200, CWE-22
NVD

MEDIUM
CVE-2026-13022
CVE-2026-13022
pkg: google chrome, apple macos, linux linux_kernel

published: Jun 24, 2026

Inappropriate implementation in Autofill in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
GitHub-GHSA

MEDIUM
jackson-databind has a @JsonView bypass for unwrapped creator parameters
GHSA-rcqc-6cw3-h962
pkg: com.fasterxml.jackson.core:jackson-databind, tools.jackson.core:jackson-databind
eco: maven
published: Jun 23, 2026
## Summary
`UnwrappedPropertyHandler.processUnwrappedCreatorProperties()` replays buffered JSON into creator parameters but never consults `prop.visibleInView(activeView)`. The normal property-based creator path gates creator properties on the active view, but this unwrapped-creator replay path bypa…
CVE-2026-54518
NVD

MEDIUM
CVE-2026-54019
CVE-2026-54019
pkg: openwebui open_webui

published: Jun 23, 2026

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI added collection-level ACL checks, but the patch can still be bypassed when Milvus multitenancy mode is enabled. The ACL allows unknown non-KB collection names as legacy/ephe…
CWE: CWE-862, CWE-943
NVD

MEDIUM
CVE-2026-49411
CVE-2026-49411
pkg: deno deno

published: Jun 23, 2026

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.0, the Node.js compatibility TCP path checked the permission against the original hostname string before resolution and then did not re-check after resolution. A caller could therefore pass a numeric alias of an IP address (for …
CWE: CWE-284
NVD

MEDIUM
CVE-2026-54235
CVE-2026-54235
pkg: vllm vllm

published: Jun 22, 2026

vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, ll temperature validation gates use comparison operators (<, >), which silently evaluate to False for NaN and for positive Infinity in Python's IEEE 754 float semantics. Both values pass every guard and pro…
CWE: CWE-1287
GitHub-GHSA

MEDIUM
zeroconf: Unvalidated rdlength in record payload readers allows LAN-local cache corruption via crafted mDNS packet
GHSA-qc2x-6f54-m6h9
pkg: zeroconf
eco: pip
published: Jun 22, 2026
### Impact

`_read_character_string` and `_read_string` in `src/zeroconf/_protocol/incoming.py` sliced `self.data[self.offset : self.offset + length]` and advanced `self.offset` by the declared `length` without checking it against `self._data_len`. Python's slice silently returns fewer bytes when th…

CVE-2026-48487
NVD

MEDIUM
CVE-2026-54911
CVE-2026-54911
pkg: ultrajson_project ultrajson

published: Jun 22, 2026

UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.13.0, ujson.dumps() (or ujson.dump() or ujson.encode()) have a reject_bytes=False option. When set, they may accept malformed or truncated UTF-8 byte sequences, silently rewriting them into diffe…
CWE: CWE-20
NVD

MEDIUM
CVE-2026-39904
CVE-2026-39904
pkg: go

published: Jun 22, 2026

Gophish through 0.12.1 contains a denial of service vulnerability that allows authenticated users with the User role to exhaust server memory by uploading a crafted Office document as an email template attachment. The ApplyTemplate() function in models/attachment.go processes Office documents as ZIP…
CWE: CWE-770
GitHub-GHSA

MEDIUM
motionEye has an Arbitrary File Read via Path Traversal in Picture/Movie Preview Endpoint
GHSA-g9fx-5r4h-pcw3
pkg: motioneye
eco: pip
published: Jun 22, 2026
### Summary

motionEye v0.43.1 (latest stable) is vulnerable to path traversal in the picture and movie API endpoints, like `/picture/{id}/preview/{filename}`. Neither the API handlers, nor the `mediafiles.py` functions like `get_media_preview()` check for `..` sequences in the filename parameter, e…

CVE-2026-31978
GitHub-GHSA

MEDIUM
OpenCTI May Bypass Introspection Restriction
GHSA-4mvw-j8r9-xcgc
pkg: pycti
eco: pip
published: Jun 22, 2026
### Summary

The regex validation used to prevent Introspection queries can be bypassed by removing the extra whitespace, carriage return, and line feed characters from the query.

### Details

GraphQL Queries in OpenCTI can be validated using the `secureIntrospectionPlugin`.

### Impact
Bypassing t…

CVE-2024-37155
GitHub-GHSA

MEDIUM
Nezha Monitoring: Stored future DDNS profile ID allows unauthorized use of another user's DDNS profile context
GHSA-39g2-8×68-pmx8
pkg: github.com/nezhahq/nezha
eco: go
published: Jun 26, 2026
## Summary

`PATCH /server/{id}` accepts and persists nonexistent `ddns_profiles` IDs for a member-owned server. If another user later creates a DDNS profile with one of those IDs, the DDNS worker resolves the stored ID and dispatches an update using the other user's DDNS profile configuration in th…

CVE-2026-53521
GitHub-GHSA

MEDIUM
pnpm: Git Fetch Argument Injection via Lockfile resolution.commit
GHSA-p4xf-rf54-rj3x
pkg: pnpm, pnpm
eco: npm
published: Jun 26, 2026
## Summary

pnpm passes the lockfile-controlled git `resolution.commit` value to `git fetch` without a `–` separator or commit-format validation. For git dependencies fetched through the shallow-fetch path, a malicious lockfile can replace the expected 40-character commit hash with a Git option suc…

CVE-2026-50014
GitHub-GHSA

MEDIUM
nono-py has proxy-only network fallback bypass on older Linux kernels
GHSA-72w7-mf9g-733p
pkg: nono-py
eco: pip
published: Jun 26, 2026
## Summary

On Linux kernels that do not support Landlock network rules, `nono_py.sandboxed_exec()` could run `CapabilitySet.proxy_only(proxy)` without supervising the seccomp-notify proxy-only fallback returned by the Rust core.

In that configuration, a sandboxed child process could remove `HTTP_P…

NVD

MEDIUM
CVE-2026-9620
CVE-2026-9620
pkg: express

published: Jun 24, 2026

The WP Latest Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted image src attributes in post content in versions up to, and including, 5.0.11. This is due to insufficient output escaping in the field() and loop() functions, which extract the raw src attribute value …
CWE: CWE-79
NVD

MEDIUM
CVE-2026-54306
CVE-2026-54306
pkg: n8n n8n

published: Jun 23, 2026

n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, a prototype pollution vulnerability allowed a crafted public webhook payload to inject attacker-controlled fields into workflow data during internal object copying. These fields could be surfaced and consumed as normal v…
CWE: CWE-1321
NVD

MEDIUM
CVE-2026-55448
CVE-2026-55448
pkg: python

published: Jun 26, 2026

mise manages dev tools like node, python, cmake, and terraform. From 2026.3.15 until 2026.6.4, mise loads github.credential_command from local project config before any trust decision, then executes that value with sh -c when resolving a GitHub token. An attacker who can place a .mise.toml in a repo…
CWE: CWE-78
GitHub-GHSA

MEDIUM
golang.org/x/crypto/ssh vulnerable to invoking bypass of certificate restrictions
GHSA-45gg-vh54-h5m9
pkg: golang.org/x/crypto/ssh
eco: go
published: Jun 25, 2026
When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restrictions such as force-command after a second factor succeeded. Returning non-nil Permissions with PartialSuccessError now…
CVE-2026-39828
GitHub-GHSA

MEDIUM
Lemur Privilege Escalation: Non-admin role members can rewrite role membership via PUT /api/1/roles/<id>
GHSA-x3vf-mgxj-7785
pkg: lemur
eco: pip
published: Jun 25, 2026
## Summary

The `PUT /api/1/roles/<id>` handler in `lemur/roles/views.py` gates only on `RoleMemberPermission(role_id).can()`, which is satisfied for any user who is already a member of the target role. The handler then passes `data["users"]` and `data["name"]` directly to `service.update()`, permi…

CVE-2026-55163
GitHub-GHSA

MEDIUM
Lemur: Crafted CRL/OCSP URLs in uploaded certificates lead to post-authentication SSRF
GHSA-54vg-pfh7-jq95
pkg: lemur
eco: pip
published: Jun 25, 2026
## Summary

When verifying an uploaded certificate, `lemur/certificates/verify.py` extracts the CRL Distribution Point URL and the OCSP responder URL directly from the certificate's extensions and issues outbound requests to those URLs without scheme restriction or destination allow-listing. An aut…

CVE-2026-55162
GitHub-GHSA

MEDIUM
Mise's local credential_command executes untrusted config
GHSA-29hf-rm4x-xxph
pkg: mise
eco: rust
published: Jun 23, 2026
### Summary

`mise` loads `github.credential_command` from local project config before any trust decision, then executes that value with `sh -c` when resolving a GitHub token. An attacker who can place a `.mise.toml` in a repository can execute arbitrary shell commands when the victim runs a GitHub-…

CVE-2026-55448
GitHub-GHSA

MEDIUM
Build breakout using malicious Containerfile and Git Smart HTTP server or GitHub release tar archive
GHSA-49p4-px3h-rq49
pkg: github.com/containers/buildah
eco: go
published: Jun 22, 2026
### Impact

When processing a build contexts or `add`/`copy` instructions, a malicious server serving a Git repository or a tar archive file can cause files outside of the build context directory to be included in the build context or copied into the build.

### Patches

Fixed in Buildah 1.44 and 1.…

CVE-2026-44517
GitHub-GHSA

MEDIUM
ImageMagick has a Heap Buffer Over-Write in SF3 encoder when writing multi-frame image
GHSA-44cp-c3ww-9rv5
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Jun 26, 2026
An crafted multi-frame can result in a heap buffer over-write when encoding it with the SF3 encoder.
CVE-2026-53465
GitHub-GHSA

MEDIUM
opentelemetry-ebpf-profiler: Unprivileged process can trigger a denial of service on the ebpf-profiler agent
GHSA-f2r5-5m7w-p5cx
pkg: go.opentelemetry.io/ebpf-profiler
eco: go
published: Jun 23, 2026
### Summary

An unprivileged process can easily trigger the `processPIDEvents` goroutine to be blocked indefinitely, preventing the goroutine from analyzing any new ELF file. The goroutine stays blocked in the `openat2` syscall forever and the profiler can no longer work properly, it is a denial of …

CVE-2026-48496
GitHub-GHSA

MEDIUM
Dosage Vulnerable to Stored Cross-Site Scripting (XSS) in HTML/RSS Output Handlers
GHSA-75mw-h36v-2jv7
pkg: dosage
eco: pip
published: Jun 26, 2026
## Summary

The HTML and RSS output handlers in `dosagelib/events.py` write user-controlled content (comic text and page URLs) directly into generated files without proper HTML escaping. When a user scrapes a malicious webcomic and opens the generated HTML/RSS file, attacker-controlled JavaScript ca…

GitHub-GHSA

MEDIUM
justhtml: to_markdown() code-span blank-line breakout enables XSS
GHSA-jf6w-2mvx-633j
pkg: justhtml
eco: pip
published: Jun 25, 2026
# justhtml: to_markdown() code-span blank-line breakout enables XSS

### Summary

In `justhtml` 0.9.0 through 1.21.0, `to_markdown()` renders `<code>` text (and `<pre>` text inside a link) as an inline Markdown code span whose only protection is backtick-fence length. A blank line (`\n\n`) in that t…

GitHub-GHSA

MEDIUM
OpenTofu: Provider cache installation follows root-module-controlled package directory symlink and writes outside the working tree
GHSA-wcmj-x466-56mm
pkg: github.com/opentofu/opentofu, github.com/opentofu/opentofu
eco: go
published: Jun 23, 2026
## Summary

If a symlink already exists under the `.terraform/providers` directory where a provider package needs to be installed, `tofu init` would follow that symlink and install the new package content into it.

If an attacker can coerce an operator into running `tofu init` in a directory whose c…

NVD

MEDIUM
CVE-2026-50019
CVE-2026-50019
pkg: yt-dlp_project yt-dlp

published: Jun 23, 2026

yt-dlp is a command-line audio/video downloader. From 2023.09.24 until 2026.06.09, if curl is used as an external downloader for yt-dlp, cookies may be leaked to an unintended host upon HTTP redirect or when the host for download fragments differs from their parent manifest's. At the file download s…
CWE: CWE-200
NVD

MEDIUM
CVE-2026-56697
CVE-2026-56697
pkg: nuxt nuxt

published: Jun 22, 2026

Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 accept protocol-relative paths such as //evil.com in the reloadNuxtApp function; these pass the script-protocol check but resolve to a cross-origin URL against the current page protocol. Attackers can inject paths like //evil.com to redirect use…
CWE: CWE-601
NVD

MEDIUM
CVE-2026-56326
CVE-2026-56326
pkg: nuxt nuxt

published: Jun 22, 2026

Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 contain a server-side open redirect vulnerability in navigateTo that fails to properly validate path-normalized payloads like /..//evil.com and /.//evil.com. Attackers can bypass external-host checks using path-normalization techniques to redire…
CWE: CWE-601
NVD

MEDIUM
CVE-2026-44889
CVE-2026-44889
pkg: pylonsproject webob

published: Jun 22, 2026

WebOb provides objects for HTTP requests and responses. Prior to 1.8.10, the normalization of the HTTP Location header during a redirect is vulnerable to an open redirect: WebOb joins the redirect target to the request URI using Python's urljoin, and since Python 3.10 the underlying urlsplit strips …
CWE: CWE-601
GitHub-GHSA

MEDIUM
GitHub MCP Server: Lockdown mode singleton in HTTP server causes cross-user GraphQL client confusion
GHSA-pjp5-fpmr-3349
pkg: github.com/github/github-mcp-server
eco: go
published: Jun 25, 2026
### Summary

When running in HTTP mode with –lockdown-mode enabled, the RepoAccessCache is implemented as a process-global singleton initialized with the first authenticated user's GraphQL client. All subsequent requests from different users share this singleton and their lockdown-related GraphQL q…

CVE-2026-48529
NVD

MEDIUM
CVE-2026-48090
CVE-2026-48090
pkg: oauth

published: Jun 26, 2026

Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.37.0 until 1.37.5 and 1.38.3, the HTTP OAuth2 filter (envoy.filters.http.oauth2) can leave an in-flight async token exchange attached to a downstream stream that has already been torn down. A late AsyncClie…
CWE: CWE-416
GitHub-GHSA

MEDIUM
ImageMagick has a Use-After-Free when allocation in CheckPrimitiveExtent fails
GHSA-px7q-ggqj-hcf2
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Jun 26, 2026
When an allocation fails in CheckPrimitiveExtent this can result in a heap-use-after-free and result in a crash.
CVE-2026-53462
GitHub-GHSA

MEDIUM
ImageMagick has a Heap Buffer Over-Write in MAT decoder on 32-bit systems
GHSA-4v89-6mgq-6rgc
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Jun 25, 2026
A missing check of a return value could lead to a heap buffer over-write in the MAT decoder on 32-bit systems.
CVE-2026-48994
NVD

MEDIUM
CVE-2026-54323
CVE-2026-54323
pkg: tls

published: Jun 23, 2026

Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.185.0, the daemon's git clone implementation disabled TLS certificate verification. When a clone request carried Git credentials, the daemon sent the HTTP Basic Authorization header…
CWE: CWE-295
NVD

MEDIUM
CVE-2026-55568
CVE-2026-55568
pkg: guzzlephp guzzle

published: Jun 23, 2026

Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, in certain configurations, traffic expected to be protected by TLS on the hop to the proxy is transmitted in cleartext. Proxy authentication credentials (the Proxy-Authorization header, proxy userinfo in the proxy URL, or CURLOPT_PROXYUSERPWD…
CWE: CWE-311, CWE-319, CWE-636
NVD

MEDIUM
CVE-2026-54286
CVE-2026-54286
pkg: windows

published: Jun 22, 2026

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on Windows hosts, an encoded backslash (%5C) in the request path decodes to \, which the Windows path resolver treats as a separator. serve-static then resolves a single URL segment such as admin\…
CWE: CWE-22
NVD

MEDIUM
CVE-2026-54250
CVE-2026-54250
pkg: kubernetes

published: Jun 25, 2026

K3s is a fully conformant production-ready Kubernetes distribution. Prior to 1.35.3+k3s1, 1.34.6+k3s1, v1.33.10+k3s1, a path traversal vulnerability exists in K3s's etcd snapshot decompression functionality. Zip files containing archive members with maliciously crafted names can be written to arbitr…
CWE: CWE-22
NVD

MEDIUM
CVE-2026-53944
CVE-2026-53944
pkg: go

published: Jun 24, 2026

Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, when making an external request, it is possible to bypass the IP filter that ensures the request isn't going to an internal service using an IPv6 literal which maps to a private IPv4 address. This vulnerability is fixed in 6.21.1…
CWE: CWE-184, CWE-918
NVD

MEDIUM
CVE-2026-13543
CVE-2026-13543
pkg: oauth

published: Jun 29, 2026

A vulnerability was detected in Documenso up to 2.11.0. Affected by this vulnerability is an unknown functionality of the file packages/auth/server/lib/utils/handle-oauth-callback-url.ts of the component Google OAuth Login. The manipulation results in improper authentication. It is possible to launc…
CWE: CWE-287
NVD

MEDIUM
CVE-2026-13524
CVE-2026-13524
pkg: oauth

published: Jun 29, 2026

A security vulnerability has been detected in CherryHQ cherry-studio up to 1.9.6. This vulnerability affects unknown code of the file src/main/services/mcp/oauth/callback.ts of the component MCP OAuth Local Callback Server. The manipulation of the argument code leads to improper authorization. The a…
CWE: CWE-266, CWE-285
GitHub-GHSA

MEDIUM
turso-cli persists Turso platform JWT with world-readable (0o644) file permissions
GHSA-57f6-pvx8-hwj6
pkg: github.com/tursodatabase/turso-cli
eco: go
published: Jun 26, 2026
### Summary

`turso-cli` persists the user's Turso platform JWT to `settings.json` using Viper's default `configPermissions` of `0o644`, leaving the credential file world-readable on standard Linux and macOS systems. Any other local UID on the host can read the file and recover the platform JWT, whi…

CVE-2026-48790
NVD

MEDIUM
CVE-2026-54557
CVE-2026-54557
pkg: python

published: Jun 26, 2026

mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.1, the mise HTTP backend builds its install symlink destination from the raw resolved version string for non-latest versions. Normal tool install paths use the sanitized version pathname, but the HTTP backend's symlink p…
CWE: CWE-22
GitHub-GHSA

MEDIUM
ImageMagick: Policy Bypass can read disallowed files via symlink
GHSA-xcjm-wqff-m669
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Jun 25, 2026
An incorrect parsing of the filename can result in a policy bypass and read files disallowed by a security policy using a symlink.
CVE-2026-49219
GitHub-GHSA

MEDIUM
ImageMagick Vulnerable to Stack Overflow in its MVG Decoder
GHSA-h36c-3666-h489
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Jun 25, 2026
A crafted MVG file could result in a stack overflow due to a missing depth or visited-set check.
CVE-2026-48734
GitHub-GHSA

MEDIUM
ImageMagick has a Heap Buffer Underwrite in the Floyd-Steinberg depth dithering method
GHSA-2hhq-c99x-492r
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Jun 25, 2026
When using an image with mask the Floyd-Steinberg dithering method will cause a negative heap buffer over-write.
CVE-2026-48724
GitHub-GHSA

MEDIUM
nextflow auth login command has incorrect default permissions
GHSA-92qf-fcph-v5wr
pkg: io.nextflow:nextflow, io.nextflow:nextflow
eco: maven
published: Jun 25, 2026
### Impact

`nextflow auth login` persists Seqera Platform OIDC tokens to `${NXF_HOME:-~/.nextflow}/seqera-auth.config`. The file is created via Java NIO without specifying file permissions, so under the default `umask 022` it lands at mode `0644` (world-readable).

On a multi-user POSIX host — ty…

CVE-2026-48722
NVD

MEDIUM
CVE-2026-12163
CVE-2026-12163
pkg: fortra file_integrity_monitoring

published: Jun 23, 2026

Fortra File Integrity Monitoring (FIM), formerly Tripwire Enterprise, versions prior to 9.4.0.1 contain a stored cross-site scripting (XSS) vulnerability in the Asset View UI component. An authenticated user with sufficient privileges to create or modify affected node or database configuration field…
CWE: CWE-79
NVD

MEDIUM
CVE-2026-11819
CVE-2026-11819
pkg: windows

published: Jun 23, 2026

Module: plugins/modules/keyring_info.py

CVSS 3.1: 5.5 MEDIUM — AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Issue: The module retrieves a passphrase from the OS native keyring (GNOME Keyring, macOS Keychain, Windows Credential Manager) and places it directly into result["passphrase"] with no output sup…

CWE: CWE-532
NVD

MEDIUM
CVE-2026-49406
CVE-2026-49406
pkg: deno deno

published: Jun 23, 2026

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.12, when Deno was run in BYONM mode (nodeModulesDir: "manual"), the module resolver did not validate that a package's resolved entrypoint stayed within its node_modules/<pkg>/ directory. A malicious package.json whose main field…
CWE: CWE-22
GitHub-GHSA

MEDIUM
mise HTTP backend uses raw version path for install symlink destination
GHSA-f94h-j2qg-fxw3
pkg: mise
eco: rust
published: Jun 23, 2026
## Summary

The mise HTTP backend builds its install symlink destination from the raw resolved version string for non-latest versions. Normal tool install paths use the sanitized version pathname, but the HTTP backend's symlink path uses the raw value. On Unix-like systems, if that version is an abs…

CVE-2026-54557
NVD

MEDIUM
CVE-2026-56301
CVE-2026-56301
pkg: nuxt nuxt

published: Jun 23, 2026

Nuxt 4.0.0 before 4.4.7 and 3.18.0 before 3.21.7, when running the development server (nuxt dev) on Linux, binds the vite-node IPC server to an abstract-namespace Unix socket without permission restrictions, allowing local users to enumerate and connect. Unprivileged co-resident users can exploit th…
CWE: CWE-276
GitHub-GHSA

MEDIUM
motionEye's World-Readable Configuration File Exposes Admin Password Hash
GHSA-rhgp-6wq6-9j67
pkg: motioneye
eco: pip
published: Jun 22, 2026
# Security Advisory: World-Readable Configuration File Exposes Admin Password Hash in motionEye

## Summary

motionEye v0.43.1 and prior versions create the configuration file `/etc/motioneye/motion.conf` with `644` permissions (`-rw-r–r–`), making it readable by any local user on the system. This…

CVE-2026-32315
NVD

MEDIUM
CVE-2026-53655
CVE-2026-53655
pkg: isaacs tar

published: Jun 22, 2026

node-tar is a full-featured Tar for Node.js. Prior to 7.5.16, tar (node-tar) applies a PAX extended header's size= record (and other PAX overrides) to the next header entry of any type, including intermediary metadata headers such as a GNU long-name (L) or long-link (K) entry. Per POSIX pax, a PAX e…
CWE: CWE-436
NVD

MEDIUM
CVE-2026-29509
CVE-2026-29509
pkg: python

published: Jun 26, 2026

Patool before 4.0.5 contains a path traversal vulnerability in the safe_extract() function in patoolib/programs/py_tarfile.py when running on Python before 3.12, where the is_within_directory() helper uses os.path.commonprefix() for character-level string comparison instead of path-level comparison,…
CWE: CWE-22
GitHub-GHSA

MEDIUM
@sigstore/core has DSSE payloadType type-binding failure
GHSA-jfc7-64v2-mr8c
pkg: @sigstore/core
eco: npm
published: Jun 26, 2026
### Impact
The `preAuthEncoding` function in `@sigstore/core` uses Node.js `'ascii'` encoding when converting the PAE (Pre-Authentication Encoding) string to bytes. This allows `payloadType` to be mutated after signing without invalidating the signature, breaking the type-binding guarantee that DSSE…
CVE-2026-48758
NVD

MEDIUM
CVE-2026-56823
CVE-2026-56823
pkg: oauth

published: Jun 26, 2026

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to , the `POST /api/integrations/webhooks/{webhook_id}/ping` endpoint fetches the target webhook by primary key alone without verifying that the webhook belongs to the aut…
CWE: CWE-284, CWE-639
NVD

MEDIUM
CVE-2026-56358
CVE-2026-56358
pkg: n8n n8n

published: Jun 24, 2026

n8n before 1.123.25 (1.x) and before 2.11.2 (2.x), with the fix also included in 2.12.0, contains a stored cross-site scripting vulnerability in the Form Trigger node's CSS sanitization that allows authenticated users to inject malicious scripts. Attackers with workflow creation permissions can inje…
CWE: CWE-79
NVD

MEDIUM
CVE-2026-45692
CVE-2026-45692
pkg: caddyserver caddy

published: Jun 23, 2026

Caddy is an extensible server platform that uses TLS by default. From 2.4.0 until 2.11.3, the authorization layer and the /config traversal layer do not agree on what object the path refers to. In this case, a path authorized for one config object is accepted, but then resolves to a different config…
CWE: CWE-187, CWE-863
NVD

MEDIUM
CVE-2026-54301
CVE-2026-54301
pkg: n8n n8n

published: Jun 23, 2026

n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, an authenticated user with workflow edit access could configure a Respond to Webhook node to serve binary content with an attacker-controlled Content-Type. The binary response path bypassed the central Content…
CWE: CWE-79
GitHub-GHSA

MEDIUM
Gogs has an Open Redirect via redirect_to
GHSA-xxhq-69mf-w8cr
pkg: gogs.io/gogs
eco: go
published: Jun 23, 2026
### Summary
An open redirect vulnerability exists in Gogs where attacker-controlled `redirect_to` parameters can bypass validation, allowing redirection to arbitrary external sites.

### Details
All redirects in Gogs that are validated via the `IsSameSite` function are vulnerable:
“`go
func IsSame…

CVE-2026-52802
NVD

MEDIUM
CVE-2026-54303
CVE-2026-54303
pkg: n8n n8n

published: Jun 23, 2026

n8n is an open source workflow automation platform. Prior to 2.24.0, an endpoint in the Meta and Microsoft Teams trigger nodes reflects a query parameter into the HTTP response without sanitization or Content-Security-Policy headers, enabling reflected XSS in the n8n origin when a logged-in user vis…
CWE: CWE-79
GitHub-GHSA

MEDIUM
devbridge-autocomplete has XSS in its default formatters: formatGroup and formatResult fail to escape HTML in untrusted inputs
GHSA-hvqh-jw65-wcpq
pkg: devbridge-autocomplete
eco: npm
published: Jun 22, 2026
### Summary

The default `formatGroup` and `formatResult` functions in `devbridge-autocomplete` concatenate values into HTML without escaping, allowing XSS when an attacker controls (or can taint) the suggestion data source.

### Details

**1. `formatGroup` — `category` is interpolated raw.**

`sr…

NVD

MEDIUM
CVE-2026-41479
CVE-2026-41479
pkg: authlib authlib

published: Jun 22, 2026

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.10 and 1.7.1, Authlib's OAuth 2.0 authorization endpoint can be turned into an unauthenticated open redirect when a request uses an unsupported response_type and supplies an attacker-controlled redirect_uri. The …
CWE: CWE-601
GitHub-GHSA

MEDIUM
js-toml has silent type confusion via falsy-primitive duplicate-key bypass
GHSA-m34p-749j-x6m6
pkg: js-toml
eco: npm
published: Jun 26, 2026
### Summary

`js-toml`'s interpreter checks whether a key already exists in a parser-built container with `if (object[key])` instead of `if (key in object)`. When the prior value is a falsy primitive — `false`, `0`, `0n`, `0.0`, `-0`, or `""` — the duplicate-key branch is skipped and the value i…

CVE-2026-50029
GitHub-GHSA

MEDIUM
YARD static cache reads raw traversal paths before router sanitization
GHSA-pxcc-8665-phx8
pkg: yard
eco: rubygems
published: Jun 26, 2026
### Summary
YARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as `/../yard-cache-secret.html` is joined against that root and can return a readable sibling `.html` file outside the intended s…
CVE-2026-49342
GitHub-GHSA

MEDIUM
joserfc: b64=false RFC7797 JWS payloads bypass JWSRegistry payload-size limits during deserialization
GHSA-wphv-vfrh-23q5
pkg: joserfc
eco: pip
published: Jun 26, 2026
# RFC7797 b64=false JWS payloads bypass JWSRegistry payload-size limits during deserialization

## Summary

Testing revealed that `joserfc` accepts oversized RFC7797 `b64=false` JWS payloads without applying `JWSRegistry.max_payload_length`.

The normal JWS compact and flattened JSON paths reject pa…

CVE-2026-48990
GitHub-GHSA

MEDIUM
fluent-plugin-opentelemetry Has Denial of Service (DoS) via Large Payloads and Decompression Bombs in `in_opentelemetry`
GHSA-2jc5-xhx8-qj6h
pkg: fluent-plugin-opentelemetry
eco: rubygems
published: Jun 26, 2026
The `fluent-plugin-opentelemetry` plugin (specifically the `in_opentelemetry` HTTP input) lacked strict size limits on incoming requests.
It was discovered that the plugin read the entire request body and decompressed payloads into memory without enforcing maximum size thresholds.

If the OpenTeleme…

CVE-2026-44163
GitHub-GHSA

MEDIUM
golang.org/x/crypto/ssh is vulnerable to invoking server panic during CheckHostKey/Authenticate flow
GHSA-78mq-xcr3-xm33
pkg: golang.org/x/crypto/ssh
eco: go
published: Jun 25, 2026
SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.
CVE-2026-39835
GitHub-GHSA

MEDIUM
golang.org/x/crypto/ssh/agent: Invoking pathological inputs can lead to client panic
GHSA-9m57-25v3-79×9
pkg: golang.org/x/crypto/ssh/agent
eco: go
published: Jun 25, 2026
For certain crafted inputs, a 'ed25519.PrivateKey' was created by casting malformed wire bytes, leading to a panic when used.
CVE-2026-46598
NVD

MEDIUM
CVE-2026-55964
CVE-2026-55964
pkg: wolfssl wolfssl

published: Jun 25, 2026

Chain intermediate CA:TRUE without keyCertSign accepted as a signing CA. Intermediate CA certificates are required to have the keyCertSign key usage when a Key Usage extension is present, but chain-supplied temporary CAs (WOLFSSL_TEMP_CA) added while building a certificate path were previously exemp…
CWE: CWE-295
GitHub-GHSA

MEDIUM
opentelemetry_sdk has unbounded memory allocation in W3C Baggage propagation
GHSA-w9wp-h8wv-79jx
pkg: opentelemetry_sdk
eco: rust
published: Jun 25, 2026
## Summary

`BaggagePropagator::extract_with_context` in `opentelemetry_sdk` did not enforce the W3C Baggage size limits before parsing an inbound `baggage` header. A large attacker-controlled header could cause unnecessary CPU work and short-lived heap allocations while parsing entries that would l…

CVE-2026-48504
NVD

MEDIUM
CVE-2026-57437
CVE-2026-57437
pkg: nokogiri nokogiri

published: Jun 25, 2026

Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::XPathContext did not keep its source document alive for garbage collection. If an XPathContext outlived its document and the document was collected, evaluating an XPath expression could…
CWE: CWE-416
NVD

MEDIUM
CVE-2026-13030
CVE-2026-13030
pkg: google chrome, google android

published: Jun 24, 2026

Uninitialized Use in GPU in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-457
NVD

MEDIUM
CVE-2026-13023
CVE-2026-13023
pkg: google chrome, apple macos, linux linux_kernel

published: Jun 24, 2026

Uninitialized Use in GPU in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-457
GitHub-GHSA

MEDIUM
jackson-databind has @JsonView bypass for setterless creator properties
GHSA-5hh8-q8hv-fr38
pkg: com.fasterxml.jackson.core:jackson-databind, com.fasterxml.jackson.core:jackson-databind, tools.jackson.core:jackson-databind
eco: maven
published: Jun 23, 2026
## Summary
In `BeanDeserializer._deserializeUsingPropertyBased`, the active-view (`@JsonView`) filter was applied only to creator properties; the regular property-buffering branch performed no `prop.visibleInView(activeView)` check. A change making `SetterlessProperty.isMerging()` return `true` rout…
CVE-2026-54517
GitHub-GHSA

MEDIUM
jackson-databind's renamed @JsonIgnore'd setters can deserialize via private fields
GHSA-9fxm-vc8v-hj55
pkg: com.fasterxml.jackson.core:jackson-databind, com.fasterxml.jackson.core:jackson-databind, tools.jackson.core:jackson-databind
eco: maven
published: Jun 23, 2026
## Summary
`POJOPropertiesCollector._renameProperties()` allows a property with `@JsonProperty("renamed")` on the getter and `@JsonIgnore` on the setter to be renamed rather than dropped. With `MapperFeature.INFER_PROPERTY_MUTATORS` enabled (default), the private backing field is retained; during de…
CVE-2026-54516
GitHub-GHSA

MEDIUM
jackson-databind has case-insensitive deserialization bypasses per-property @JsonIgnoreProperties
GHSA-5jmj-h7xm-6q6v
pkg: com.fasterxml.jackson.core:jackson-databind, tools.jackson.core:jackson-databind, com.fasterxml.jackson.core:jackson-databind
eco: maven
published: Jun 23, 2026
## Summary
In `BeanDeserializerBase.createContextual()`, per-property `@JsonIgnoreProperties` exclusions are applied by `_handleByNameInclusion()`, producing a `contextual` deserializer whose `BeanPropertyMap` has the ignored properties removed. The subsequent per-property case-insensitivity block (…
CVE-2026-54515
GitHub-GHSA

MEDIUM
jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF)
GHSA-hgj6-7826-r7m5
pkg: com.fasterxml.jackson.core:jackson-databind, com.fasterxml.jackson.core:jackson-databind, com.fasterxml.jackson.core:jackson-databind
eco: maven
published: Jun 23, 2026
## Summary
`JDKFromStringDeserializer` constructed `InetSocketAddress` with `new InetSocketAddress(host, port)`, which performs eager DNS name resolution for hostname inputs at deserialization time. An application that binds untrusted JSON into a type containing an `InetSocketAddress` field issues a…
CVE-2026-54514
GitHub-GHSA

MEDIUM
motionEye's missing authentication on ActionHandler allows unauthenticated camera action execution
GHSA-j67x-q29f-qcvv
pkg: motioneye
eco: pip
published: Jun 23, 2026
## Summary

The `ActionHandler.post()` method in motionEye has no authentication decorator, allowing any unauthenticated attacker to trigger camera actions including snapshots, recording start/stop, and configured action scripts (PTZ controls, alarm triggers, etc.).

## Vulnerability Details

**File…

CVE-2026-55863
NVD

MEDIUM
CVE-2026-56762
CVE-2026-56762
pkg: node

published: Jun 23, 2026

Hono before 4.12.12 does not validate cookie names on the write path in the setCookie(), serialize(), and serializeSigned() functions, allowing invalid characters such as control characters (e.g. \r or \n) when an application passes a user-controlled cookie name. This can produce malformed Set-Cooki…
CWE: CWE-20
GitHub-GHSA

MEDIUM
Glances: XML-RPC Server Missing Host Header Validation Enables DNS Rebinding Attack
GHSA-w856-8p3r-p338
pkg: glances
eco: pip
published: Jun 22, 2026
### Summary

The Glances XML-RPC server (`glances -s`, implemented in `glances/server.py`) does not validate the HTTP `Host` header, leaving it vulnerable to DNS rebinding attacks. CVE-2026-32632 (patched in 4.5.2) added `TrustedHostMiddleware` to the REST/WebUI server; the MCP server has had equiv…

CVE-2026-46611
NVD

MEDIUM
CVE-2026-54300
CVE-2026-54300
pkg: express

published: Jun 22, 2026

@astrojs/netlify is an adapter that allows Astro to deploy your hybrid or server rendered site to Netlify. Prior to 7.0.13, @astrojs/netlify converts Astro image.remotePatterns into Netlify Image CDN images.remote_images regular expressions with broader semantics than Astro's canonical matcher. A si…
CWE: CWE-918
NVD

MEDIUM
CVE-2026-53550
CVE-2026-53550
pkg: nodeca js-yaml

published: Jun 22, 2026

js-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0, a crafted YAML document can trigger algorithmic CPU exhaustion in js-yaml merge-key processing (<<) by repeating the same alias many times in a merge sequence. This causes quadratic parse-time behavior relative to input size and can blo…
CWE: CWE-407
GitHub-GHSA

MEDIUM
nono-py's policy JSON accepts unknown security fields
GHSA-m8j6-rc5x-wv36
pkg: nono-py
eco: pip
published: Jun 26, 2026
### Summary

nono-py policy handling could fail open in two ways. First, resolving a policy-derived `ProxyConfig` did not automatically enforce `CapabilitySet.proxy_only`, allowing sandboxed children to bypass a resolved domain allowlist by using direct network access. Second, policy JSON accepted u…

GitHub-GHSA

MEDIUM
nono-py vulnerable to authorization bypass / policy confusion
GHSA-9j7f-3r4p-pwh6
pkg: nono-py
eco: pip
published: Jun 26, 2026
The python API made a restrictive-looking configuration unsafe by default. A caller could configure only reverse-
proxy credential routes, put the child in CapabilitySet.proxy_only, and reasonably expect network access to be limited
to those routes. Instead, because empty allowed_hosts meant allow-a…
NVD

MEDIUM
CVE-2026-49983
CVE-2026-49983
pkg: node

published: Jun 23, 2026

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, environment access is gated by the env permission. You can deny it with –deny-env, or restrict it to a specific allowlist with –allow-env=FOO,BAR. The expectation is that a program running without env permission cannot chan…
CWE: CWE-863
NVD

MEDIUM
CVE-2026-58057
CVE-2026-58057
pkg: windows

published: Jun 28, 2026

Flowise before 3.1.3 validates Custom MCP stdio environment variables against a denylist using a case-sensitive comparison, so on Windows, where environment names are case-insensitive, supplying 'node_options' bypasses the NODE_OPTIONS denylist entry. An authenticated user who can configure a Custom…
CWE: CWE-178
NVD

MEDIUM
CVE-2026-48770
CVE-2026-48770
pkg: windows

published: Jun 26, 2026

Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, a local process in the same interactive Windows session can send a malformed WM_COPYDATA message to Notepad++ using the COPYDATA_FULL_CMDLINE path. The handler appears to process COPYDATASTRUCT.lpData as an unbounded NUL-termi…
CWE: CWE-125
GitHub-GHSA

MEDIUM
Pterodactyl Wings: Chmod operation can be used to change permissions of files outside of the server container
GHSA-rhq6-9rgh-v45c
pkg: github.com/pterodactyl/wings
eco: go
published: Jun 26, 2026
In `wings/internal/ufs/fs_unix.go` (line 92-94), this function is defined and is used to change permissions of files in the server:

“`go
func (fs *UnixFS) fchmodat(op string, dirfd int, name string, mode FileMode) error {
return ensurePathError(unix.Fchmodat(dirfd, name, uint32(mode), 0), op, n…

NVD

MEDIUM
CVE-2026-45407
CVE-2026-45407
pkg: dokku dokku

published: Jun 26, 2026

Dokku is a docker-powered PaaS. Prior to 0.38.2, the git:auth command creates $DOKKU_ROOT/.netrc using bash's touch command, which applies the default umask of 0644. This pre-creation defeats the netrc binary's built-in 0600 permission setting, leaving git credentials readable by any local user who …
CWE: CWE-522
NVD

MEDIUM
CVE-2026-55655
CVE-2026-55655
pkg: openbsd openssh, redhat enterprise_linux

published: Jun 23, 2026

A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is enabled and a local UNIX-domain X socket is used. A successful attack can c…
CWE: CWE-923
GitHub-GHSA

MEDIUM
Lemur user-update path stores plaintext passwords
GHSA-q437-g7fv-2jvv
pkg: lemur
eco: pip
published: Jun 25, 2026
## Summary

`lemur.users.service.update()` writes a user's new password as plaintext to the `users.password` column. The `User` model wires bcrypt hashing to SQLAlchemy's `before_insert` event but registers no equivalent listener for `before_update`, and `service.update()` does not call `user.hash_p…

CVE-2026-55164
NVD

MEDIUM
CVE-2025-64719
CVE-2025-64719
pkg: go

published: Jun 24, 2026

Gogs is an open source self-hosted Git service. Prior to 0.14.3, a malicious user with rights to create a new file on a repository or wiki page can trigger a denial of service condition in which the pages containing the listing of files will return HTTP error 500 and render the web interface unusabl…
CWE: CWE-20
GitHub-GHSA

MEDIUM
Gogs has a Denial of Service in repository/wiki file listing web pages
GHSA-3qq3-668m-v9mj
pkg: gogs.io/gogs
eco: go
published: Jun 22, 2026
### Summary
A malicious user with rights to create a new file on a repository or wiki page can trigger a denial of service condition in which the pages containing the listing of files will return HTTP error 500 and render the web interface unusable for the repository or wiki.

### Details
The issue …

CVE-2025-64719
GitHub-GHSA

MEDIUM
Apptainer has incorrect path matching for 'limit container paths' directive
GHSA-cr2j-534f-mf3g
pkg: github.com/apptainer/apptainer
eco: go
published: Jun 26, 2026
### Impact

The `limit container paths directive` in `apptainer.conf` is intended to allow a system administrator limit the paths from which containers can be run, under setuid mode. Due to incorrect matching of a path string, sibling directories with similar names may incorrectly be allowed.

For e…

CVE-2026-48785
GitHub-GHSA

MEDIUM
Lemur: JWT verifier honors attacker-supplied alg, enabling ATO
GHSA-r9gp-7f88-9r54
pkg: lemur
eco: pip
published: Jun 25, 2026
<!– obsidian –><h1 data-heading="Lemur 1.9.0: JWT verifier trusts attacker-supplied alg from token header — defense-in-depth gap; chain-dependent ATO with secret disclosure">Lemur 1.9.0: JWT verifier trusts attacker-supplied alg from token header — defense-in-depth gap; chain-dependent ATO wit…
CVE-2026-55165
NVD

MEDIUM
CVE-2026-57289
CVE-2026-57289
pkg: jenkins bitbucket_push_and_pull_request

published: Jun 24, 2026

Jenkins Bitbucket Push and Pull Request Plugin 3.3.8 and earlier unconditionally disables SSL/TLS certificate and hostname validation for connections sending Bearer token authenticated requests to the configured Bitbucket Server endpoint, allowing attackers able to intercept network traffic to captu…
CWE: CWE-295
GitHub-GHSA

MEDIUM
ImageMagick has an Infinite Loop in subimage-search with crafted image
GHSA-5v62-8fq6-cp9m
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Jun 25, 2026
An infinite loop in the subimage-search operation can happen when using a crafted image.
CVE-2026-48733
NVD

MEDIUM
CVE-2026-13034
CVE-2026-13034
pkg: google chrome, apple macos, linux linux_kernel

published: Jun 24, 2026

Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-346
GitHub-GHSA

MEDIUM
Flask-Security has an Open Redirect issue
GHSA-w2j7-f3c6-g8cw
pkg: Flask-Security
eco: pip
published: Jun 23, 2026
# Open Redirect in Flask-Security

## Summary

`flask_security.utils.validate_redirect_url()` can allow an attacker-controlled redirect URL when subdomain redirects are enabled.

The bypass uses a backslash inside the URL authority/host:

“`text
http://evil.com\.whitelist.com
http://evil.com%5C.whi…

NVD

MEDIUM
CVE-2026-56269
CVE-2026-56269
pkg: flowiseai flowise

published: Jun 24, 2026

Flowise before 3.1.0 (npm package flowise, versions 3.0.13 and earlier) uses a weak hardcoded default value 'Secre$t' for the TOKEN_HASH_SECRET environment variable in packages/server/src/enterprise/utils/tempTokenUtils.ts when the variable is not configured. This secret derives the AES-256-CBC key …
CWE: CWE-798
GitHub-GHSA

MEDIUM
@actual-app/cli `–format csv` Output Vulnerable to CSV Formula Injection via Custom `escapeCsv` Helper
GHSA-7gh7-258j-4mpq
pkg: @actual-app/cli
eco: npm
published: Jun 22, 2026
## Summary

`@actual-app/cli` ships a hand-rolled CSV serializer in `packages/cli/src/output.ts` (used whenever the global `–format csv` option is passed) whose `escapeCsv` helper only handles RFC 4180 delimiter/quote/newline escaping. It does **not** neutralize the standard CSV formula-injection p…

CVE-2026-46672
GitHub-GHSA

MEDIUM
Fleet DM Vulnerable to Cross-Team Policy Data Exposure via Global Policy Read Endpoint
GHSA-gm7f-v959-fr2g
pkg: github.com/fleetdm/fleet/v4
eco: go
published: Jun 26, 2026
## Summary

The global policy read endpoint (`GET /api/latest/fleet/policies/{policy_id}`) performs authorization against an empty `fleet.Policy{}` struct with nil TeamID, then fetches any policy by ID from the database without verifying the fetched policy actually belongs to the global scope. This …

CVE-2026-41262
GitHub-GHSA

MEDIUM
ImageMagick has Null Pointer Dereference caused by the distort operation when passing incorrect arguments
GHSA-p9rq-q46c-g4x6
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Jun 26, 2026
When passing incorrect arguments in the distort operation a null pointer deference will occur.
CVE-2026-53463
NVD

MEDIUM
CVE-2026-48934
CVE-2026-48934
pkg: nodejs node.js

published: Jun 26, 2026

A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation.

This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

NVD

MEDIUM
CVE-2026-13021
CVE-2026-13021
pkg: google chrome, apple macos, linux linux_kernel

published: Jun 24, 2026

Inappropriate implementation in DeviceBoundSessionCredentials in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-346
NVD

MEDIUM
CVE-2026-48789
CVE-2026-48789
pkg: windows

published: Jun 24, 2026

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, on Windows, the document folder listing route can accept an encoded absolute Windows path that resolves outside the intended documents directory. The shared pa…
CWE: CWE-22
GitHub-GHSA

MEDIUM
OliveTin has Unvalidated `ot_`-prefixed Arguments that Bypass Input Filtering
GHSA-prj9-97mp-mwh2
pkg: github.com/OliveTin/OliveTin
eco: go
published: Jun 24, 2026
### Description

The `filterToDefinedArgumentsOnly` function in the executor is intended to discard any arguments not explicitly defined in the action's configuration. However, a special case allows any argument whose name starts with `ot_` to bypass this filter. While two system arguments (`ot_exec…

CVE-2026-53541
NVD

MEDIUM
CVE-2026-46548
CVE-2026-46548
pkg: axios

published: Jun 23, 2026

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the request-filtering-agent SSRF protection was non-functional in the four notification webhook plugins (Slack, Discord, Mattermost, Teams) because httpAgent / httpsAgent were passed as part of the request body rather tha…
CWE: CWE-918
NVD

MEDIUM
CVE-2026-55653
CVE-2026-55653
pkg: openbsd openssh, redhat hardened_images, redhat openshift_container_platform

published: Jun 23, 2026

A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX g…
CWE: CWE-415
GitHub-GHSA

MEDIUM
@actual-app/sync-server's missing authorization on GET /secret/:name allows non-admin OpenID users to enumerate admin-configured bank-sync secrets
GHSA-3f62-qv96-4p78
pkg: @actual-app/sync-server
eco: npm
published: Jun 22, 2026
## Summary

In `@actual-app/sync-server`, the `GET /secret/:name` endpoint (`app-secrets.js:53`) checks only that the caller has a valid session — it does not verify the caller is an admin. The sibling `POST /secret/` handler does enforce an admin check in OpenID mode, exposing an authorization as…

CVE-2026-46700
GitHub-GHSA

MEDIUM
LangGraph SDK has unsafe URL path construction
GHSA-w39p-vh2g-g8g5
pkg: langgraph-sdk
eco: pip
published: Jun 25, 2026
## Summary

`langgraph-sdk` constructs HTTP request paths for resource operations by interpolating caller-supplied identifier values into URL templates. Without sanitization of those values, identifiers that contain characters with special meaning in URL paths could cause the resulting request to ad…

CVE-2026-48776
NVD

MEDIUM
CVE-2026-13024
CVE-2026-13024
pkg: google chrome, apple macos, linux linux_kernel

published: Jun 24, 2026

Insufficient validation of untrusted input in Navigation in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-20
NVD

MEDIUM
CVE-2026-52846
CVE-2026-52846
pkg: tls

published: Jun 23, 2026

Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, Caddy’s stripHTML template function cannot reliably remove all HTML tags from input strings. Certain malformed HTML, such as <<>img src=x onerror=alert()>, can bypass the tag-stripping logic, potentially leaving dang…
CWE: CWE-116
GitHub-GHSA

MEDIUM
@actual-app/web has CSV Formula Injection in Transaction Export via Imported Payee/Notes Fields
GHSA-xqjm-27pc-rvwm
pkg: @actual-app/web
eco: npm
published: Jun 22, 2026
## Summary

`exportToCSV` and `exportQueryToCSV` in `packages/loot-core/src/server/transactions/export/export-to-csv.ts` pass user-controlled `Payee`, `Notes`, `Account`, and `Category` strings to `csv-stringify` with no `cast` callback and no formula-prefix neutralization. Strings that begin with `…

CVE-2026-50179
GitHub-GHSA

MEDIUM
ImageMagick: Memory Leak in wand option parser when providing invalid arguments
GHSA-j989-f892-2335
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Jun 26, 2026
When providing invalid options to the wand option parser a small memory leak will occur.
CVE-2026-53464
NVD

MEDIUM
CVE-2026-56357
CVE-2026-56357
pkg: n8n n8n

published: Jun 22, 2026

n8n before 1.123.15 and 2.5.0 contains a webhook forgery vulnerability in the GitHub Webhook Trigger node that fails to implement HMAC-SHA256 signature verification. Attackers who know the webhook URL can send unsigned POST requests to trigger workflows with arbitrary data, spoofing GitHub webhook e…
CWE: CWE-290
GitHub-GHSA

MEDIUM
runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations
GHSA-xjvp-4fhw-gc47
pkg: github.com/opencontainers/runc, github.com/opencontainers/runc, github.com/opencontainers/runc
eco: go
published: Jun 22, 2026
### Impact
When setting up the container rootfs, `setupPtmx` and `setupDevSymlinks` call `os.Remove` and `os.Symlink` with a `filepath.Join` string which allow an image with `/dev` as a symlink to trick runc into deleting files called `ptmx` on the host or creating a hardcoded set of symlinks with s…
CVE-2026-41579
GitHub-GHSA

MEDIUM
Nezha Dashboard: DDNS and Notification credential exposure via unredacted list API
GHSA-ww5p-j6cj-6mqq
pkg: github.com/nezhahq/nezha
eco: go
published: Jun 26, 2026
### Summary

The `GET /api/v1/ddns` and `GET /api/v1/notification` endpoints return full resource objects including plaintext third-party API credentials — Cloudflare API tokens, TencentCloud SecretKeys, Slack/Discord/Telegram webhook URLs with embedded bot tokens, and Authorization header values …

GitHub-GHSA

MEDIUM
pnpm binds unscoped user-level npm auth credentials to a repository-selected registry
GHSA-cjhr-43r9-cfmw
pkg: pnpm, pnpm
eco: npm
published: Jun 26, 2026
## Summary

pnpm can send user-level unscoped npm authentication credentials to a registry chosen by a repository-local `.npmrc` file.

In the reproduced case, the user's npm config contains a default registry and an unscoped `_authToken`. The repository does not provide a token-bearing auth line. I…

CVE-2026-50017
GitHub-GHSA

MEDIUM
@microsoft/kiota-http-fetchlibrary: Bearer token and Cookie leak across origin on redirect due to case-mismatched scrub in fetchRequestAdapter
GHSA-396q-4vc8-28×9
pkg: @microsoft/kiota-http-fetchlibrary
eco: npm
published: Jun 26, 2026
### Summary

`@microsoft/kiota-http-fetchlibrary`'s `RedirectHandler` is documented as stripping `Authorization` and `Cookie` from cross-origin redirect targets, but the default `scrubSensitiveHeaders` callback in `RedirectHandlerOptions` uses case-sensitive property deletion (`delete headers.Author…

CVE-2026-49336
GitHub-GHSA

MEDIUM
pnpm: Tarball hash of GitHub git dependencies is not stored in lockfile
GHSA-hg3w-7f8c-63hp
pkg: pnpm, pnpm
eco: npm
published: Jun 26, 2026
### Summary

A malicious `codeload.github.com` server can serve whatever tarball it wants and pnpm will install it regardless of the lockfile.

### Details

The lockfile does not store the hash of the dependencies from https://codeload.github.com

This means that if this server was compromised or a …

CVE-2026-48995
GitHub-GHSA

MEDIUM
Cargo crates in third party registries can override the cached source of other crates
GHSA-jq42-7mfv-hm57
pkg: cargo
eco: rust
published: Jun 26, 2026
The Rust Security Response Team was notified that Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry.

This vulnerability is tracked as CVE-2026-5223. The s…

CVE-2026-5223
GitHub-GHSA

MEDIUM
Scriban: ExpressionDepthLimit guard is non-enforcing — parser-recursion DoS in 6.6.0–7.2.0 (incomplete fix for GHSA-wgh7-7m3c-fx25 / GHSA-p6q4-fgr8-vx4p)
GHSA-6q7j-xr26-3h2c
pkg: Scriban
eco: nuget
published: Jun 26, 2026
### Summary

The `ExpressionDepthLimit` parser guard in Scriban does not actually stop parsing — it only logs a non-fatal error and lets recursive descent continue. As a result, a template containing a deeply nested expression (parentheses, array initializers, object initializers, or unary operato…

GitHub-GHSA

MEDIUM
Scriban: array * int (ScriptArray<T>.TryEvaluate) bypasses LoopLimit — incomplete fix for GHSA-c875-h985-hvrc, missed sibling of GHSA-24c8-4792-22hx
GHSA-q6rr-fm2g-g5x8
pkg: Scriban
eco: nuget
published: Jun 26, 2026
### Summary

The array multiplication operator (`array * integer`) in Scriban allocates a result whose size is the product of the attacker-controlled integer and the array length, with **no `LoopLimit` / `LimitToString` check and no overflow-safe arithmetic**. A ~40-byte template forces a multi-giga…

GitHub-GHSA

MEDIUM
@cyclonedx/cdxgen: Maven project scanning may allow shell command injection through repository-controlled module paths
GHSA-5vwr-qchf-q4pf
pkg: @cyclonedx/cdxgen
eco: npm
published: Jun 26, 2026
## Summary

A command injection vulnerability existed in the Maven scanning flow of cdxgen before version 12.4.3.

When cdxgen scanned an attacker-controlled Maven project, repository-controlled paths could be used in the Maven command construction. In affected versions, some Maven invocations were …

GitHub-GHSA

MEDIUM
MessagePack-CSharp: Typeless deserialization type restrictions do not recurse into arrays or generic arguments
GHSA-qhmf-xw27-6rqr
pkg: MessagePack, MessagePack
eco: nuget
published: Jun 25, 2026
## Summary

MessagePack-CSharp's typeless deserialization includes `MessagePackSerializerOptions.ThrowIfDeserializingTypeIsDisallowed(Type)` as a safety check for dangerous types. The default implementation checks the outer type name, but it does not recursively inspect array element types or generi…

CVE-2026-48517
GitHub-GHSA

MEDIUM
MessagePack-CSharp: InterfaceLookupFormatter bypasses collision-resistant comparer settings
GHSA-q2h6-ghwm-5qm8
pkg: MessagePack, MessagePack
eco: nuget
published: Jun 25, 2026
## Summary

`InterfaceLookupFormatter<TKey,TElement>` constructs an internal `Dictionary<TKey, IGrouping<TKey,TElement>>` with the default equality comparer instead of the security-aware comparer supplied by `options.Security.GetEqualityComparer<TKey>()`.

Other hash-based collection formatters use …

CVE-2026-48516
GitHub-GHSA

MEDIUM
MessagePack-CSharp: Multi-dimensional array formatters allocate from unchecked dimensions
GHSA-cxmj-83gh-fp49
pkg: MessagePack, MessagePack
eco: nuget
published: Jun 25, 2026
## Summary

MessagePack-CSharp's multi-dimensional array formatters read dimension lengths directly from the payload and allocate `T[,]`, `T[,,]`, or `T[,,,]` before validating that the dimension product matches the encoded element count.

The formatter reads a guarded element array header, but allo…

CVE-2026-48515
GitHub-GHSA

MEDIUM
MessagePack-CSharp: Unity unsafe blit formatter allocates from unbounded byte length
GHSA-w567-gjr2-hm5j
pkg: MessagePack, MessagePack
eco: nuget
published: Jun 25, 2026
## Summary

`UnsafeBlitFormatterBase<T>.Deserialize` reads an attacker-controlled `byteLength` from an extension payload and allocates an array based on that value before validating it against the extension header length or remaining payload bytes.

The outer extension header is bounded by available…

CVE-2026-48514
GitHub-GHSA

MEDIUM
MessagePack-CSharp: DynamicUnionResolver-generated deserializers miss depth enforcement
GHSA-wfr3-xj75-pfwh
pkg: MessagePack, MessagePack
eco: nuget
published: Jun 25, 2026
## Summary

Runtime-generated union deserializers emitted by `DynamicUnionResolver` do not call `MessagePackSecurity.DepthStep(ref reader)` and do not decrement `reader.Depth` around recursive deserialization and skip paths.

This means union deserialization does not consistently participate in the …

CVE-2026-48513
GitHub-GHSA

MEDIUM
MessagePack-CSharp: JSON conversion APIs can recurse without consistent depth enforcement
GHSA-cj9g-3mj2-g8vv
pkg: MessagePack, MessagePack
eco: nuget
published: Jun 25, 2026
## Summary

MessagePack-CSharp's JSON conversion helpers contain multiple recursion paths that do not consistently enforce a depth limit. These paths are in the JSON conversion component rather than normal typed MessagePack deserialization.

Three related issues are covered by this advisory:

1. `Me…

CVE-2026-48512
GitHub-GHSA

MEDIUM
MessagePack-CSharp: ASP.NET Core MessagePackInputFormatter defaults to TrustedData for HTTP request bodies
GHSA-2f33-pr97-265q
pkg: MessagePack, MessagePack
eco: nuget
published: Jun 25, 2026
## Summary

The parameterless `MessagePackInputFormatter()` constructor uses default serializer options, which resolve to `MessagePackSerializerOptions.Standard` with `MessagePackSecurity.TrustedData`. The formatter is designed for ASP.NET Core MVC request bodies, which commonly cross an HTTP trust …

CVE-2026-48509
GitHub-GHSA

MEDIUM
chi Has an IP Spoofing Vulnerability in `middleware.RealIP`
GHSA-3fxj-6jh8-hvhx
pkg: github.com/go-chi/chi/v5/middleware
eco: go
published: Jun 25, 2026
## Summary
The `RealIP` middleware in `go-chi/chi` is vulnerable to IP spoofing because it blindly trusts the first (leftmost) element of the `X-Forwarded-For` HTTP header. This allows a remote attacker to bypass IP-based access control lists (ACLs) and rate-limiting mechanisms by providing a spoofe…
GitHub-GHSA

MEDIUM
@anthropic-ai/claude-code has an Insecure Temporary File in /copy Command that Enables Response Disclosure and Symlink-Based File Write
GHSA-4vp2-6q8c-pvq2
pkg: @anthropic-ai/claude-code
eco: npm
published: Jun 25, 2026
The Claude Code `/copy` command wrote responses to a hardcoded, predictable path (`/tmp/claude/response.md`) without UID isolation, randomness, or symlink protection. The file was created world-readable (0644) in a world-traversable directory (0755), allowing any local user to read a privileged user…
CVE-2026-46406
GitHub-GHSA

MEDIUM
OHttpVersionChunkDraft: Missing Final-Chunk Enforcement Leads to Undetected Stream Truncation
GHSA-r6fj-869h-4f6q
pkg: io.netty.incubator:netty-incubator-codec-ohttp
eco: maven
published: Jun 23, 2026
The codec-ohttp implementation of draft-ietf-ohai-chunked-ohttp does not verify that a cryptographically-signed final chunk was received before the outer HTTP body terminates. An on-path adversary (the OHTTP relay itself, or any MITM on the relay↔gateway or relay↔client transport) can forward a …
CVE-2026-48480
GitHub-GHSA

MEDIUM
jackson-databind: Deeply nested JsonNode throws StackOverflowError for toString()
GHSA-3wrr-7qpf-2prh
pkg: com.fasterxml.jackson.core:jackson-databind
eco: maven
published: Jun 23, 2026
### Impact

Potential Denial-of-Service when attacker sends deeply nested JSON if (and only if) service:

1. Reads deeply nested (1000s of levels) JSON as `JsonNode` (ObjectMapper.readTree())
2. Writes out same (or modifided) node using `JsonNode.toString()`

which can consume significant amount of …

CVE-2026-50193
GitHub-GHSA

MEDIUM
Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS
GHSA-3w28-36p9-w929
pkg: gogs.io/gogs
eco: go
published: Jun 23, 2026
## Summary

The Jupyter Notebook (ipynb) sanitizer endpoint at `POST /-/api/sanitize_ipynb` allows arbitrary `data:` URIs without proper restrictions, potentially leading to Cross-Site Scripting (XSS). The endpoint uses `bluemonday.UGCPolicy()` with `p.AllowURLSchemes("data")` which permits all data…

CVE-2026-52816
GitHub-GHSA

MEDIUM
OctoPrint has XSS in its Suppressed Command Notifications
GHSA-p6qx-ghxm-389h
pkg: OctoPrint, OctoPrint
eco: pip
published: Jun 23, 2026
### Impact

OctoPrint versions up to and including 1.11.7 as well as 2.0.0rc1 and 2.0.0rc2 are affected by a vulnerability that allows injection of arbitrary HTML and JavaScript into Suppressed Command notifications popups generated by the printer.

An attacker who successfully convinces a victim to…

CVE-2026-35163
GitHub-GHSA

MEDIUM
Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API
GHSA-744x-3838-5r56
pkg: gogs.io/gogs
eco: go
published: Jun 23, 2026
## Summary

Gogs has an unauthenticated information disclosure vulnerability. The `GET /api/v1/orgs/:orgname/teams` endpoint at `internal/route/api/v1/org_team.go:8` returns all teams for any organization without requiring authentication. The route group at `internal/route/api/v1/api.go:380-385` lac…

CVE-2026-52815
GitHub-GHSA

MEDIUM
Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion)
GHSA-xp79-5mx3-jx52
pkg: gogs.io/gogs
eco: go
published: Jun 23, 2026
The Gogs built-in Go SSH server is vulnerable to an unauthenticated, asymmetric Denial of Service (DoS) attack. The application accepts inbound TCP connections and passes them to `golang.org/x/crypto/ssh.NewServerConn` inside a new goroutine without enforcing any read/write deadlines on the underlyi…
CVE-2026-52814
GitHub-GHSA

MEDIUM
Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation
GHSA-4565-r4x7-hg8j
pkg: gogs.io/gogs
eco: go
published: Jun 23, 2026
## Summary

A repository admin collaborator can escalate their privileges to owner-level access by exploiting an off-by-one error in the `ChangeCollaborationAccessMode` function.

## Vulnerable Code

In `internal/database/repo_collaboration.go`, line 129:

“`go
func (r *Repository) ChangeCollaborat…

CVE-2026-52804
GitHub-GHSA

MEDIUM
nebula-mesh's stores enrollment tokens unhashed in SQLite
GHSA-ghmh-jhmj-wcmf
pkg: github.com/juev/nebula-mesh
eco: go
published: Jun 22, 2026
`internal/store/sqlite.go:1177,1192,1221,1245` — the `enrollment_tokens.token` column holds the raw UUID token. `ConsumeToken` does `WHERE token = ?` against the raw string. Compare with `operator_api_keys.key_hash`, which is SHA-256 hex (constructed in `internal/api/middleware.go:51-53`).

## Aff…

GitHub-GHSA

MEDIUM
Gogs has SSRF in webhook deliveries
GHSA-c4v7-xg93-qf8g
pkg: gogs.io/gogs
eco: go
published: Jun 22, 2026
### Summary
The fix for CVE-2022-1285 prevents adding webooks or running webhooks with URLs with a hostname that resolves in localCIDRs. However, webhooks still follow redirects allowing to access hostname inside localCIDRs.

This was already communicated in the initial report but it looks like the…

CVE-2026-47267
GitHub-GHSA

MEDIUM
OpenAM Authenticated Server-Side Request Forgery (SSRF) via `/sessionservice`
GHSA-c556-q2mh-477v
pkg: org.openidentityplatform.openam:openam-core
eco: maven
published: Jun 22, 2026
OpenAM (Open Identity Platform) is an open-source Identity and Access Management (IAM) platform derived from ForgeRock OpenAM, providing SSO, OAuth2, SAML, and OpenID Connect capabilities. It is widely deployed in enterprise environments as a central authentication gateway.

The `/sessionservice` en…

CVE-2026-44202


Vulnerability Digest — June 22, 2026 · 46 Critical · 2 Exploited






Vulnerability Digest — Monday, June 22, 2026


Security Report

Monday, June 22, 2026  ·  Last 7 days  ·  Min severity: MEDIUM
Total Findings
335
Critical
46
High
161
Actively Exploited
2
CISA-KEV2
GitHub-GHSA333
Findings sorted by severity
CISA-KEV

CRITICAL
Splunk Enterprise Missing Authentication for Critical Function Vulnerability
CVE-2026-20253
pkg: Splunk Enterprise

published: Jun 18, 2026

Splunk Enterprise contains a missing authentication for critical function vulnerability which could allow an unauthenticated user to create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Widget Factory Joomla Content Editor Improper Access Control Vulnerability
CVE-2026-48907
pkg: Widget Factory Joomla Content Editor

published: Jun 16, 2026

Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
GitHub-GHSA

CRITICAL
CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation
GHSA-xjr9-gg9q-jx3v
pkg: CoreWCF.Primitives, CoreWCF.Primitives
eco: nuget
published: Jun 19, 2026
### Impact
Full impersonation of any principal the trusted STS could have issued an assertion for — including administrative principals when the relying party grants them via SAML claims. Affects both SAML 1.1 and SAML 2.0.

#### Preconditions
Relying-party service is hosted with WSFederationHttpB…

CVE-2026-54782
GitHub-GHSA

CRITICAL
Crawl4AI: Unauthenticated RCE via Chromium launch-argument injection in browser_config.extra_args
GHSA-r253-r9jw-qg44
pkg: crawl4ai
eco: pip
published: Jun 18, 2026
### Summary

The Docker API server accepted a request-supplied `browser_config.extra_args`, which flowed into Chromium's launch arguments. An attacker could inject Chromium switches that replace a child-process launch command (`–utility-cmd-prefix`, `–renderer-cmd-prefix`, `–gpu-launcher`, `–bro…

GitHub-GHSA

CRITICAL
Duplicate Advisory: PickleScan's pkgutil.resolve_name has a universal blocklist bypass
GHSA-82fg-2r99-h7v6
pkg: picklescan
eco: pip
published: Jun 17, 2026
### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-vvpj-8cmc-gx39. This link is maintained to preserve external references.

### Original Description
picklescan before 1.0.4 fails to block pkgutil.resolve_name, allowing attackers to bypass the entire blocklist …

GitHub-GHSA

CRITICAL
Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow
GHSA-qrpv-q767-xqq2
pkg: langflow
eco: pip
published: Jun 19, 2026
## Summary

Insecure Direct Object Reference (IDOR) vulnerability in `/api/v1/responses` endpoint allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request.

## Details

The vulnerability exists in the `get_flow_by_id_or_endpoint…

CVE-2026-55255
GitHub-GHSA

CRITICAL
Network-AI: Improper Neutralization of Special Elements used in an OS Command
GHSA-qw6v-5fcf-5666
pkg: network-ai
eco: npm
published: Jun 19, 2026
## Summary

The agent sandbox gates shell commands behind an allowlist (`SandboxPolicy.isCommandAllowed`), which THREAT_MODEL.md calls the main control against a compromised agent (Adversary 3.2). The allowlist glob-matches the whole command string, but `ShellExecutor` runs that string through `/bin…

CVE-2026-54051
GitHub-GHSA

CRITICAL
npm PraisonAI codeMode sandbox escape via Function constructor
GHSA-vmmj-pfw7-fjwp
pkg: praisonai
eco: npm
published: Jun 18, 2026
## Summary

The published npm package `praisonai` exports a TypeScript built-in tool named `codeMode`. The package describes this tool as executing code in a sandboxed environment, marks its capability as `sandbox: true`, and registers it through the public tools facade.

The implementation does not…

GitHub-GHSA

CRITICAL
gemini-mcp-tool vulnerable to OS command injection and @file exfiltration via prompt quoting (CVE-2026-0755)
GHSA-4h5r-5jm8-jxjm
pkg: gemini-mcp-tool
eco: npm
published: Jun 18, 2026
Untrusted prompt input could reach the Gemini CLI @file parser, allowing read/exfiltration of arbitrary local files (@/etc/passwd, @~/.ssh/id_rsa, @../../secret). On Windows, unquoted cmd.exe metacharacters could break out into OS command injection.

Fix (1.1.6): removed the broken shell:false doubl…

CVE-2026-0755
GitHub-GHSA

CRITICAL
python-statemachine SCXML <data expr> Eval Injection
GHSA-v4jc-pm6r-3vj8
pkg: python-statemachine
eco: pip
published: Jun 18, 2026
### Summary

python-statemachine 3.1.2 evaluates `<data expr="…">` attributes in SCXML documents using Python's `eval()`. Any application that passes attacker-controlled SCXML content to `SCXMLProcessor` is vulnerable to arbitrary code execution in the context of the hosting process.

### Details

CVE-2026-47103
GitHub-GHSA

CRITICAL
praisonai-platform: default JWT signing secret 'dev-secret-change-me' enables token forgery
GHSA-cwj8-7gp2-ggcw
pkg: praisonai-platform
eco: pip
published: Jun 18, 2026
# praisonai-platform: default JWT signing secret `dev-secret-change-me`

**Researcher:** Kai Aizen — SnailSploit (@SnailSploit), Adversarial & Offensive Security Research
**Target:** https://github.com/MervinPraison/PraisonAI

**Package:** `praisonai-platform` on PyPI
**Latest version (and ve…

GitHub-GHSA

CRITICAL
praisonai-platform 0.1.4 still boots on the hardcoded JWT secret dev-secret-change-me (default-open production guard)
GHSA-f38v-77qj-h4jq
pkg: praisonai-platform
eco: pip
published: Jun 18, 2026
– Affected: praisonai-platform (PyPI) <= 0.1.4 — including 0.1.4, the version GHSA-3qg8-5g3r-79v5 declares as the patch; main HEAD 8acf77c531e624c46d3d61dcae37e9942e90972c is also affected. File src/praisonai-platform/praisonai_platform/services/auth_service.py

– CWE: CWE-1188 (Insecure Default I…

GitHub-GHSA

CRITICAL
npm PraisonAI MCPServer exposes unauthenticated HTTP tools/call
GHSA-j4f3-55×4-r6q2
pkg: praisonai
eco: npm
published: Jun 18, 2026
## Summary

The published npm package `praisonai` exports a TypeScript `MCPServer` that can expose tools, resources, and prompts over an HTTP JSON-RPC transport with:

“`ts
await server.start({ port: 3000 });
“`

The HTTP transport has no authentication or authorization path. `MCPServerConfig` doe…

GitHub-GHSA

CRITICAL
PraisonAI: Remote Code Execution via Sandbox Escape in `codeMode` Tool
GHSA-p69m-4f92-2v84
pkg: praisonai
eco: npm
published: Jun 18, 2026
## Summary

The `codeMode` tool in `src/praisonai-ts/src/tools/builtins/code-mode.ts` uses `new Function()` with a `with(sandbox)` pattern to execute LLM-generated code. The blocklist-based "sandbox" can be trivially bypassed via `Function('return this')()` to recover the global object, followed by …

GitHub-GHSA

CRITICAL
PraisonAI: Missing Authentication for Critical Function and Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in praisonai
GHSA-p75f-6fp4-p57w
pkg: praisonai
eco: pip
published: Jun 18, 2026
# Unauthenticated PraisonAI UI MCP connect endpoint executes attacker-chosen local commands

## Summary

PraisonAI v4.6.48 exposes the PraisonAIUI MCP client management API through the default UI host apps without authentication. A remote unauthenticated client can send `POST /api/mcp/connect` with …

GitHub-GHSA

CRITICAL
PraisonAI: AgentOS remains unauthenticated after incomplete fix version and allows remote agent invocation
GHSA-892r-p3jq-jp24
pkg: praisonai
eco: pip
published: Jun 18, 2026
# AgentOS remains unauthenticated after GHSA-pm96 patched version and allows remote agent invocation

## Summary

PraisonAI's `AgentOS` FastAPI deployment surface remains unauthenticated in
current main and in releases after the published patched version for
`GHSA-pm96-6xpr-978x` / `CVE-2026-40151`.…

GitHub-GHSA

CRITICAL
PraisonAI AgentTeam.launch exposes unauthenticated remote agent listing and invocation endpoints
GHSA-x8cv-xmq7-p8xp
pkg: praisonaiagents
eco: pip
published: Jun 18, 2026
# PraisonAI `AgentTeam.launch()` exposes unauthenticated remote agent invocation endpoints

## Summary

PraisonAI's documented Python `AgentTeam.launch()` / `Agents.launch()` HTTP server starts externally reachable agent invocation endpoints without any authentication enforcement.

The current imple…

GitHub-GHSA

CRITICAL
PraisonAI: Jobs API exposes agent-execution endpoints with no authentication
GHSA-fq2m-6wqh-x44g
pkg: praisonai
eco: pip
published: Jun 18, 2026
# praisonai: Jobs API exposes agent-execution endpoints with no authentication

**Researcher:** Kai Aizen — SnailSploit (@SnailSploit), Adversarial & Offensive Security Research
**Target:** https://github.com/MervinPraison/PraisonAI

**Package:** `praisonai` on PyPI
**Affected version (empir…

GitHub-GHSA

CRITICAL
praisonai: recipe serve auth middleware silently disables itself when no secret is set
GHSA-j4hj-7hfh-g2f4
pkg: praisonai
eco: pip
published: Jun 18, 2026
# praisonai: `recipe serve` authentication middleware silently disables itself when no secret is set

**Researcher:** Kai Aizen — SnailSploit (@SnailSploit), Adversarial & Offensive Security Research
**Target:** https://github.com/MervinPraison/PraisonAI

**Package:** `praisonai` on PyPI
**Ve…

GitHub-GHSA

CRITICAL
PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass
GHSA-4869-x4pr-q22x
pkg: praisonai, praisonaiagents
eco: pip
published: Jun 18, 2026
# Unauthenticated Remote Code Execution via Jobs API and Approval Bypass in PraisonAI

## Summary

An unauthenticated attacker can execute arbitrary OS commands on any server running
the PraisonAI Jobs API by submitting a crafted workflow YAML. The attack chains two
weaknesses: the `/api/v1/runs` …

GitHub-GHSA

CRITICAL
PraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Origin validation; bundled SecurityConfig is never wired in
GHSA-x227-pf99-vffg
pkg: praisonaiagents
eco: pip
published: Jun 18, 2026
The MCP SSE server started via ToolsMCPServer.run_sse() / launch_tools_mcp_server(transport="sse")
binds to 0.0.0.0 by default and builds its Starlette application with no authentication middleware
and no Origin-header validation. The module mcp/mcp_security.py provides exactly the needed controls
(…
GitHub-GHSA

CRITICAL
Duplicate Advisory: picklescan missing detection by simple obfuscation of a `builtins.eval` call
GHSA-j6c9-qvp8-699f
pkg: picklescan
eco: pip
published: Jun 17, 2026
## Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-9m3x-qqw2-h32h. This link is maintained to preserve external references.

## Original Description
picklescan before 1.0.1 contains an unsafe deserialization vulnerability allowing unauthenticated users to exec…

GitHub-GHSA

CRITICAL
Duplicate Advisory: PickleScan's profile.run blocklist mismatch allows exec() bypass
GHSA-4mpj-78p6-rj59
pkg: picklescan
eco: pip
published: Jun 17, 2026
## Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-7wx9-6375-f5wh. This link is maintained to preserve external references.

## Original Description
picklescan before 1.0.4 contains an incomplete blocklist for the profile module that fails to block the module-l…

GitHub-GHSA

CRITICAL
Duplicate Advisory: Picklescan vulnerable to Arbitrary File Writing
GHSA-rmpp-8wf5-xx5q
pkg: picklescan
eco: pip
published: Jun 17, 2026
### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-m273-6v24-x4m4. This link is maintained to preserve external references.

### Original Description
picklescan before 0.0.33 contains an arbitrary file writing vulnerability that allows attackers to bypass the d…

GitHub-GHSA

CRITICAL
Duplicate Advisory: Picklescan has pickle parsing logic flaw that leads to malicious pickle file bypass
GHSA-5rph-q42j-36j9
pkg: picklescan
eco: pip
published: Jun 17, 2026
## Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-9gvj-pp9x-gcfr. This link is maintained to preserve external references.

## Original Description

picklescan before 0.0.27 contains a parsing logic error in the _list_globals function when handling STACK_GLOB…

GitHub-GHSA

CRITICAL
Duplicate Advisory: Picklescan does not block ctypes
GHSA-7f79-rvx6-vxc4
pkg: picklescan
eco: pip
published: Jun 17, 2026
### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-4675-36f9-wf6r. This link is maintained to preserve external references.

### Original Description
picklescan before 0.0.33 fails to block the ctypes module, allowing attackers to achieve remote code execution …

GitHub-GHSA

CRITICAL
Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure
GHSA-r989-cjhx-3v49
pkg: org.apache.dolphinscheduler:dolphinscheduler-api
eco: maven
published: Jun 17, 2026
DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler.

This issue affects Apache DolphinScheduler: before 3.4.2.

Users are recommended to upgrade to version 3.4.2, which fixes the issue.

CVE-2026-32966
GitHub-GHSA

CRITICAL
Rclone: Unauthenticated command execution in `rclone rcd –rc-serve` via inline remote instantiation, bypassing CVE-2026-41179 fix
GHSA-qw24-gh76-8rvv
pkg: github.com/rclone/rclone
eco: go
published: Jun 16, 2026
## Summary

`rclone rcd –rc-serve` accepts unauthenticated `GET` and `HEAD` requests to paths of the form:

“`text
/[remote:path]/object
“`

The `remote` value is parsed from the URL and passed to normal backend initialization. Inline remote configuration can set backend options that execute loca…

CVE-2026-49980
GitHub-GHSA

CRITICAL
OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete)
GHSA-h3m5-97jq-qjrf
pkg: io.openremote:openremote-manager
eco: maven
published: Jun 19, 2026
### Summary
OpenRemote Manager is vulnerable to a cross-tenant Insecure Direct
Object Reference (IDOR) in the bulk alarm deletion endpoint. An
authenticated user in any realm can delete alarms belonging to other
realms (tenants) by supplying arbitrary alarm IDs. The vulnerability
exists because the …
GitHub-GHSA

CRITICAL
Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit
GHSA-ccv6-r384-xp75
pkg: langflow
eco: pip
published: Jun 19, 2026
### Summary
All components based on `BaseFileComponent` are vulnerable to the following vulnerability:
1. Docling (`DoclingInlineComponent`)
2. Docling Serve (`DoclingRemoteComponent`)
3. Read File (`FileComponent`)
4. NVIDIA Retriever Extraction (`NvidiaIngestComponent`)
5. Video File (`VideoFileCo…
CVE-2026-55447
GitHub-GHSA

CRITICAL
Crawl4AI: Arbitrary file write (path traversal) in crawler downloads can lead to RCE
GHSA-2jq4-q6vv-4cp3
pkg: crawl4ai
eco: pip
published: Jun 18, 2026
### Summary

When the crawler saves a downloaded file, the destination filename was taken from attacker-influenced input and joined to the downloads directory with no confinement. A filename containing an absolute path (e.g. `/etc/cron.d/evil`) or `../` traversal escaped the downloads directory, giv…

GitHub-GHSA

CRITICAL
netlicensing-mcp: REST Path Traversal Bypasses Token Redaction
GHSA-hxpf-9xvq-wph8
pkg: netlicensing-mcp
eco: pip
published: Jun 18, 2026
## REST Path Traversal Bypasses Token Redaction in netlicensing-mcp

### Summary

The `netlicensing_get_product` MCP tool in `netlicensing-mcp` interpolates a caller-controlled `product_number` argument directly into a REST URL path without any validation. Passing `../token` as the product number ca…

GitHub-GHSA

CRITICAL
Avo: Missing Authorization in Avo Association Attach Endpoint Allows Unauthorized Relationship Manipulation and Privilege Escalation
GHSA-8fq9-273g-6mrg
pkg: avo, avo
eco: rubygems
published: Jun 17, 2026
## Summary

A critical missing authorization flaw exists in Avo's association attach workflow. The UI and `GET /resources/:resource/:id/:related/new` path can check `attach_<association>?`, but the actual write endpoint, `POST /resources/:resource/:id/:related`, does not run the same authorization c…

CVE-2026-55518
GitHub-GHSA

CRITICAL
npm PraisonAI AgentOS exposes unauthenticated agent listing and invocation
GHSA-9752-mhqh-h34f
pkg: praisonai
eco: npm
published: Jun 18, 2026
## Summary

The published npm package `praisonai` ships a TypeScript `AgentOS` HTTP server that defaults to `host: "0.0.0.0"` and registers sensitive agent routes without any authentication or authorization middleware.

When a developer starts `AgentOS`, a network attacker who can reach the service …

GitHub-GHSA

CRITICAL
Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak
GHSA-x223-p2gf-v735
pkg: langflow
eco: pip
published: Jun 17, 2026
### Summary
Unauthenticated users can upload any amount of data to the server without any limitations. No need for any prior knowledge, only network access to Langflow.

This can lead to space exhaustion on the server.

In adition, in the response, the absolute path of the uploaded file is reported …

CVE-2026-55450
GitHub-GHSA

CRITICAL
Network-AI: CVE-2026-46701 fix incomplete — empty default secret still authorizes all requests
GHSA-r78r-rwrf-rjwp
pkg: network-ai
eco: npm
published: Jun 19, 2026
## Advisory / Disclosure

# Network-AI — CVE-2026-46701 fix is incomplete: the "Empty Default Secret" unauth path survives

**Target:** Jovancoding/Network-AI (npm `network-ai`), **latest v5.7.1**
**Status:** the advisory ("Unauthenticated Cross-Origin MCP Tool Invocation via Empty
Default Secret"…

CVE-2026-48814
GitHub-GHSA

CRITICAL
PraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path Validation
GHSA-29w3-p9w9-wc47
pkg: praisonai
eco: pip
published: Jun 18, 2026
## Summary

The `multiedit` tool in `src/praisonai/praisonai/tools/multiedit.py` allows LLM-controlled arbitrary file read and write without any path validation, workspace boundary check, or protected path guard. This enables an attacker who can influence agent tool arguments (via crafted prompts, u…

GitHub-GHSA

CRITICAL
Apache DolphinScheduler: The `/v2` experimental interface lacks permission checks
GHSA-85g9-8j9g-p486
pkg: org.apache.dolphinscheduler:dolphinscheduler-api
eco: maven
published: Jun 17, 2026
Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler.

This issue affects Apache DolphinScheduler: before 3.4.2.

Users are recommended to upgrade to version 3.4.2, which fixes the issue.

CVE-2026-32967
GitHub-GHSA

CRITICAL
Crossplane: Signature verification TOCTOU allows installing unverified package content via mutable tag
GHSA-wfqx-gjrf-g28r
pkg: github.com/crossplane/crossplane/v2, github.com/crossplane/crossplane/v2, github.com/crossplane/crossplane
eco: go
published: Jun 19, 2026
## Summary

Crossplane allows package signature verification to be configured via the `ImageConfig` mechanism. When enabled, the package manager uses cosign to verify that packages are correctly signed before pulling and installing them.

When a package is installed using a tag reference (e.g., a se…

GitHub-GHSA

CRITICAL
DotVVM: Missing authorization in AuthorizeActionFilter
GHSA-c8qj-jx8j-fg2w
pkg: DotVVM, DotVVM, DotVVM
eco: nuget
published: Jun 19, 2026
### Impact

All users of the `AuthorizeActionFilter` class are affected. The `AuthorizeActionFilter` simply does nothing, no “hacking” is needed to bypass the filter.

### Patches

DotVVM 4.3.15, 4.2.11 and 5.0.0-preview09 fix this.

### Workarounds

As a workaround, you can use the `AuthorizeAt…

GitHub-GHSA

CRITICAL
Tilt: Missing authentication on the network-exposed Tilt HUD server
GHSA-c73q-8xxr-rgqm
pkg: github.com/tilt-dev/tilt
eco: go
published: Jun 19, 2026
## Summary
The Tilt HUD HTTP server exposes state-changing and sensitive-read endpoints with no authentication. When the HUD is bound to a non-loopback address, a network attacker can trigger the developer's pre-defined Tiltfile resources, tamper with Tiltfile arguments, read full engine state inclu…
CVE-2026-55884
GitHub-GHSA

CRITICAL
@acastellon/auth: Authentication bypass via spoofable headers in validateToken()
GHSA-gfj5-979r-92pw
pkg: @acastellon/auth
eco: npm
published: Jun 18, 2026
@acastellon/auth v2.2.0 appears to allow an unauthenticated authentication bypass in validateToken() through spoofable auth-user and Host request headers.

The validateToken middleware contains a service-to-service bypass for auth-user: service-brother when req.get('host').startsWith(getHostName()).…

GitHub-GHSA

CRITICAL
googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken)
GHSA-8fcc-w5hv-4gxv
pkg: github.com/googleapis/mcp-toolbox
eco: go
published: Jun 18, 2026
An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox.

When verifying an unparsed opaque token via an OAuth 2.0 introspection endpoint (RFC 7662), the toolbox decodes the response into an introspectResp struct where…

CVE-2026-11717
GitHub-GHSA

CRITICAL
googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken)
GHSA-wcpr-6g7x-p44r
pkg: github.com/googleapis/mcp-toolbox
eco: go
published: Jun 18, 2026
An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox.

When the toolbox validates an opaque token via an OAuth 2.0 introspection endpoint (RFC 7662), it decodes the response into an introspectResp struct. However, t…

CVE-2026-11718
GitHub-GHSA

CRITICAL
Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP
GHSA-fcw5-x6j4-ccmp
pkg: jupyter-server
eco: pip
published: Jun 18, 2026
The nbconvert HTTP handlers in jupyter_server render user-authored notebook HTML under the Jupyter origin without a sandbox directive in their `Content-Security-Policy`.

Combined with `nbconvert.HTMLExporter`'s default non-sanitizing behavior, a notebook carrying an HTML payload in a display_data …

CVE-2026-44727
GitHub-GHSA

CRITICAL
HAPI FHIR: XXE in XsltUtilities.saxonTransform via unhardened Saxon TransformerFactory
GHSA-2f55-g35j-5jmf
pkg: ca.uhn.hapi.fhir:org.hl7.fhir.utilities
eco: maven
published: Jun 17, 2026
### Summary

`org.hl7.fhir.utilities.XsltUtilities` exposes two parallel families of XSLT
transform helpers. The `transform(…)` overloads obtain their
`TransformerFactory` from the project's hardened helper
`XMLUtil.newXXEProtectedTransformerFactory()` (which sets
`ACCESS_EXTERNAL_DTD=""` and `ACC…

CVE-2026-55471
GitHub-GHSA

HIGH
Agentic-Flow: OS Command Injection in agentic-flow MCP server tools via unsanitized tool-parameter interpolation into execSync
GHSA-vcv2-r9jh-99m5
pkg: agentic-flow
eco: npm
published: Jun 19, 2026
## Summary

`agentic-flow` versions `<= 2.0.13` MCP server tools interpolated attacker-influenceable tool parameters (e.g. `agent`, `task`, `name`, `language`, `agentdb` arguments) directly into shell command strings passed to `execSync()`. A malicious value reaching any of the affected MCP tools co…

GitHub-GHSA

HIGH
CedarJava has policy injection vulnerability
GHSA-qmch-v2q9-wg4p
pkg: com.cedarpolicy:cedar-java, com.cedarpolicy:cedar-java, com.cedarpolicy:cedar-java
eco: maven
published: Jun 19, 2026
### Summary

CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisions. Under certain circumstances, improper input handling could allow policy injection.

### Impact

**Cedar-expression injection via unescaped `toCedarExpr()`**

The …

CVE-2026-55773
GitHub-GHSA

HIGH
CedarJava has type confusion vulnerability
GHSA-93g4-m6xv-cmvr
pkg: com.cedarpolicy:cedar-java, com.cedarpolicy:cedar-java, com.cedarpolicy:cedar-java
eco: maven
published: Jun 19, 2026
### Summary

CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisions. Under certain circumstances, improper input handling could allow type confusion across the Java-Rust FFI boundary.

### Impact

**Record-to-Entity type confusion …

CVE-2026-55772
GitHub-GHSA

HIGH
Duplicate Advisory: PraisonAI has Memory State Leakage and Path Traversal in MultiAgent Context Handling
GHSA-fwh2-95jw-g4j6
pkg: praisonai
eco: pip
published: Jun 19, 2026
## Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-766v-q9x3-g744. This link is maintained to preserve external references.

## Original Description
PraisonAI before 1.5.115 contains a path traversal vulnerability in MultiAgentMonitor that fails to sanitize ag…

GitHub-GHSA

HIGH
PraisonAI SandlockSandbox falls back to unrestricted subprocess execution when Landlock is unavailable
GHSA-6jcq-6546-qrrw
pkg: praisonai
eco: pip
published: Jun 18, 2026
## Summary

`praisonai.sandbox.SandlockSandbox` is documented and implemented as the kernel-enforced sandbox backend for untrusted code. Its `SandboxConfig.native()` path lets callers configure allowed filesystem paths and `network=False`.

On systems where the optional `sandlock` module imports but…

GitHub-GHSA

HIGH
PraisonAI: Server-Side Request Forgery (SSRF) in SearxNG / search_web tools via attacker-controlled searxng_url parameter
GHSA-4pcv-mg8v-vrgf
pkg: praisonaiagents
eco: pip
published: Jun 18, 2026
### Summary
A Server-Side Request Forgery (SSRF) vulnerability in the SearxNG / `search_web` search tools allows an attacker to make the server perform requests to arbitrary internal endpoints and read the responses back. The `searxng_url` argument is passed directly to `requests.get()` with no vali…
GitHub-GHSA

HIGH
npm PraisonAI utility shell safe-command wrapper allowlist bypass via shell chaining
GHSA-5jv7-2mjm-h6qj
pkg: praisonai
eco: npm
published: Jun 18, 2026
## Summary

The published npm package `praisonai` ships `dist/tools/utility-tools.js`, which exports a `shell(command)` helper described in source as:

“`text
Execute shell command (safe version – read-only commands)
“`

The helper attempts to enforce a safe read-only command allowlist by checking…

GitHub-GHSA

HIGH
npm PraisonAI AgentLoop onToolCall approval runs after tool execution
GHSA-h2w2-v7j6-xqm4
pkg: praisonai
eco: npm
published: Jun 18, 2026
## Summary

The published npm package `praisonai` exports `createAgentLoop()`, whose `onToolCall` callback is documented and exampled as an approval hook. The implementation calls PraisonAI's `generateText()` wrapper with the caller's executable tools first, receives `toolResults`, and only then cal…

GitHub-GHSA

HIGH
npm PraisonAI SandboxExecutor allowedCommands bypass via shell chaining
GHSA-vjv9-7m7j-h833
pkg: praisonai
eco: npm
published: Jun 18, 2026
## Summary

The published npm package `praisonai` exports `SandboxExecutor`, `CommandValidator`, and `sandboxExec` as "safe command execution with restrictions." When `allowedCommands` is configured, `CommandValidator` checks only the first whitespace-delimited token of the command string. `SandboxE…

GitHub-GHSA

HIGH
PraisonAI: Compute-bridged file tools allow shell command injection
GHSA-w6h2-fr4q-xvxv
pkg: praisonai
eco: pip
published: Jun 18, 2026
# Compute-bridged file tools allow shell command injection

## Summary

`LocalManagedAgent` / `SandboxedAgent` compute bridging wraps
`read_file`, `list_files`, and `write_file` when a compute provider is
attached. The bridge converts those file operations into shell command strings
using raw path a…

GitHub-GHSA

HIGH
PraisonAI: HTTPApproval dashboard renders tool arguments as raw HTML, allowing approval-page XSS to approve dangerous tools
GHSA-63v4-w882-g4x2
pkg: praisonai
eco: pip
published: Jun 18, 2026
# HTTPApproval dashboard renders tool arguments as raw HTML, allowing approval-page XSS to approve dangerous tools

## Summary

`praisonai.bots.HTTPApproval` renders pending tool approval arguments directly
into the approval dashboard HTML. An attacker-controlled tool argument can
inject JavaScript …

GitHub-GHSA

HIGH
PraisonAI DiscordApproval accepts unrelated channel messages as dangerous-tool approvals
GHSA-8579-rgg5-ph2m
pkg: praisonai
eco: pip
published: Jun 18, 2026
# DiscordApproval accepts unrelated channel messages as dangerous-tool approvals

## Summary

`praisonai.bots.DiscordApproval` approves a pending dangerous tool call when it
sees any later non-bot message in the configured Discord channel whose text is
classified as approval, such as `yes`.

The dec…

GitHub-GHSA

HIGH
OpenClaw: Pairing-scoped device session could restore revoked node token authority
GHSA-q99w-vh6v-q3v7
pkg: openclaw
eco: npm
published: Jun 18, 2026
### Summary

In affected releases, a surviving pairing-scoped session for a device could re-establish node token authority after that node token had been revoked. Revocation should require the device to lose that authority unless it is approved again through the normal pairing flow.

This issue affe…

CVE-2026-53843
GitHub-GHSA

HIGH
Duplicate Advisory: Picklescan Bypasses Unsafe Globals Check using pty.spawn
GHSA-5gp7-4733-2w2v
pkg: picklescan
eco: pip
published: Jun 17, 2026
## Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-hgrh-qx5j-jfwx. This link is maintained to preserve external references.

## Original Description

PickleScan before 0.0.33 fails to include the pty.spawn function in its unsafe globals list, allowing attacker…

GitHub-GHSA

HIGH
Gitea: Stored XSS via glTF `extensionsRequired` in Gitea 3D File Viewer
GHSA-9cpj-qc93-vw8v
pkg: code.gitea.io/gitea
eco: go
published: Jun 17, 2026
## Summary

Me again.

Gitea's built-in 3D file viewer (powered by Online3DViewer) is vulnerable to stored cross-site scripting (XSS) through crafted `.gltf` files. When a glTF file declares an unsupported required extension, Online3DViewer generates an error message containing the extension name an…

CVE-2026-28737
GitHub-GHSA

HIGH
Blocky DNSSEC validation bypass and validation-cache scope pollution
GHSA-x845-2f78-7v36
pkg: github.com/0xERR0R/blocky
eco: go
published: Jun 19, 2026
## Summary

Blocky accepts and caches forged DNS answers while `dnssec.validate: true` is enabled. The issue has two related exploit paths:

1. **Basic DNSSEC validation bypass.** If an untrusted upstream returns an unsigned positive answer for a DNSSEC-signed public domain, Blocky classifies the re…

GitHub-GHSA

HIGH
agent-coderag: Gradle Wrapper Execution During Dependency Discovery Enables Arbitrary Code Execution
GHSA-wg5p-8h9p-3mr7
pkg: agent-coderag
eco: pip
published: Jun 19, 2026
## Gradle Wrapper Execution During Dependency Discovery Enables Arbitrary Code Execution

### Summary

`agent-coderag` unconditionally executes a repository-controlled `gradlew` script during its default `sync` dependency-discovery flow. An attacker who can induce a victim to index a malicious Gradl…

GitHub-GHSA

HIGH
Crawl4AI: Unauthenticated SSRF on the Docker server streaming crawl path (/crawl/stream)
GHSA-wm69-2pc3-rmmf
pkg: crawl4ai
eco: pip
published: Jun 18, 2026
### Summary

The Docker API server applied its SSRF destination check (`validate_url_destination`) on the non-streaming `/crawl` path but not on the streaming path. `handle_stream_crawl_request` passed seed URLs straight to the crawler with no destination validation. A remote, unauthenticated client…

GitHub-GHSA

HIGH
PraisonAI: Webhook signature verification skipped (fail-open) when secret unset, allowing forged inbound webhooks (WhatsApp & Linear bots)
GHSA-x92v-rpx6-p6cw
pkg: praisonai
eco: pip
published: Jun 18, 2026
The WhatsApp and Linear bot adapters verify the inbound webhook HMAC signature only
when a secret is configured. When the secret environment variable is unset — the
default on a fresh install and common in development — verification is skipped entirely
and the webhook body is parsed and dispatch…
GitHub-GHSA

HIGH
PraisonAI LinearBot processes unsigned webhooks when LINEAR_WEBHOOK_SECRET is missing
GHSA-fc26-m9pf-v56q
pkg: praisonai
eco: pip
published: Jun 18, 2026
# PraisonAI LinearBot processes unsigned webhooks when `LINEAR_WEBHOOK_SECRET` is missing

## Summary

PraisonAI's LinearBot starts a public webhook listener on `0.0.0.0` and treats
`LINEAR_WEBHOOK_SECRET` as optional. When the secret is absent, startup only logs
a warning and `_handle_webhook()` sk…

GitHub-GHSA

HIGH
praisonaiagents: SSRF guard validates literal IPs only and never resolves DNS
GHSA-vxgj-xg5c-p4h7
pkg: praisonaiagents
eco: pip
published: Jun 18, 2026
# praisonaiagents: SSRF guard validates literal IPs only and never resolves DNS

**Researcher:** Kai Aizen — SnailSploit (@SnailSploit), Adversarial & Offensive Security Research
**Target:** https://github.com/MervinPraison/PraisonAI
**Weakness:** CWE-918 Server-Side Request Forgery (SSRF).

GitHub-GHSA

HIGH
Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo
GHSA-mm7c-rhg6-qr4r
pkg: code.gitea.io/gitea
eco: go
published: Jun 16, 2026
## Summary

Any authenticated low-privilege user with read access to a repository can push arbitrary commits directly to that repository, bypassing all write-access checks.

## Vulnerability

Gitea's "Allow edits from maintainers" PR option can be abused via reverse-fork PRs:

1. The web UI PR-creat…

CVE-2026-26231
GitHub-GHSA

HIGH
Gogs: Overwriting critical files results in a denial of service
GHSA-pm6v-2h4w-4rp2
pkg: gogs.io/gogs
eco: go
published: Jun 16, 2026
**Vulnerability type:** Path Traversal
**Impact:** DoS
**Exploitation prerequisite:** authorized user
**Description:** As an authorized user, an intruder can dictate the value which is passed to the `git diff` command which, together with bypassing the filtering of the passed value, allows the user …
CVE-2026-52797
GitHub-GHSA

HIGH
budibase: Database Connector SQL Injections in PostgreSQL, MS SQL, and MySQL
GHSA-qqf5-x7mj-v43p
pkg: budibase
eco: npm
published: Jun 18, 2026
### Summary
This advisory covers three distinct SQL Injection vulnerabilities within Budibase's database connectors (PostgreSQL, Microsoft SQL Server, and MySQL). Because user-controlled schema and table configurations are interpolated directly into raw SQL queries without proper escaping or paramet…
GitHub-GHSA

HIGH
pdfkit: Path traversal in from_string
GHSA-9g3x-6×24-vf9f
pkg: pdfkit
eco: pip
published: Jun 17, 2026
In JazzCore python-pdfkit 1.0.0, the from_string method enables the execution of JavaScript code within the context of the server application and the exfiltration of local files.
CVE-2025-26240
GitHub-GHSA

HIGH
PraisonAI Slack app_mention bypasses configured user/channel authorization
GHSA-qvpf-j64c-jmhr
pkg: praisonai
eco: pip
published: Jun 18, 2026
# PraisonAI Slack `app_mention` bypasses configured user/channel authorization

## Summary

PraisonAI's Slack bot applies its configured `allowed_users`,
`allowed_channels`, and unknown-user pairing policy in the normal Slack
`message` event handler, but not in the adjacent Slack `app_mention` event…

GitHub-GHSA

HIGH
PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered tools
GHSA-vmf9-xx9w-86wx
pkg: praisonaiagents, praisonai
eco: pip
published: Jun 18, 2026
# PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered tools

## Summary

`praisonaiagents.mcp.ToolsMCPServer.run_sse()` builds a Starlette MCP
HTTP+SSE server around `mcp.server.sse.SseServerTransport`. The server exposes
`/sse` and `/messages/`, but it …

GitHub-GHSA

HIGH
appium-mcp: Unescaped Locator Data XSS in MCP-UI Resource (createLocatorGeneratorUI)
GHSA-x975-rgx4-5fh4
pkg: appium-mcp
eco: npm
published: Jun 19, 2026
## Unescaped Locator Data XSS in MCP-UI Resource (createLocatorGeneratorUI)

### Summary

`appium-mcp`'s `createLocatorGeneratorUI` function interpolates attacker-controlled element attributes — `text`, `content-desc`, `resource-id`, and locator selector values — directly into an HTML template l…

GitHub-GHSA

HIGH
EverOS: Path traversal in EverOS /api/v1/memory/add via unvalidated sender_id
GHSA-c795-2g9c-j48m
pkg: everos
eco: pip
published: Jun 19, 2026
EverOS versions 1.0.0 and earlier are vulnerable to path traversal in the POST /api/v1/memory/add ingestion endpoint. The per-message sender_id field was not validated as a path-safe identifier (unlike app_id / project_id, which already enforced this). During user-memory extraction, sender_id is use…
GitHub-GHSA

HIGH
PraisonAI: PRAISONAI_CALL_AUTH=disabled environment variable unconditionally disables authentication
GHSA-8ccj-p46r-jwqq
pkg: praisonai
eco: pip
published: Jun 18, 2026
### Summary
Setting `PRAISONAI_CALL_AUTH=disabled` completely disables all authentication on the `/api/v1/agents/{id}/invoke` endpoint. This bypass is advertised in the application's own error messages, making it likely to appear in production Docker and Compose configurations.

### Details

“`pyth…

GitHub-GHSA

HIGH
npm PraisonAI MCPSecurity Basic/OAuth authentication policies accept invalid credentials without validation
GHSA-4qq2-2j2x-x62c
pkg: praisonai
eco: npm
published: Jun 18, 2026
## Summary

The published npm package `praisonai` exports an `MCPSecurity` helper described in source as:

“`text
MCP Security – Authentication, authorization, and rate limiting
Provides security policies for MCP servers.
“`

Its `AuthMethod` type advertises five authentication methods:

“`ts
exp…

GitHub-GHSA

HIGH
PraisonAI recipe serve Typer command bypasses the non-localhost authentication guard
GHSA-5qw8-f2g9-ff29
pkg: praisonai
eco: pip
published: Jun 18, 2026
# PraisonAI `recipe serve` Typer command bypasses the non-localhost authentication guard

## Summary

PraisonAI's installed console entrypoint is Typer-first. In current releases,
the `recipe` command is registered in the Typer app and
`praisonai recipe serve` dispatches to the deprecated Typer comm…

GitHub-GHSA

HIGH
OpenClaw: Discord allowFrom could bind to mutable display names
GHSA-cw4q-gqg5-g38h
pkg: openclaw
eco: npm
published: Jun 18, 2026
### Summary

Discord allowFrom could bind to mutable display names. In affected versions, a Discord account able to change display or global name metadata could match a policy entry through mutable display metadata.

This advisory is scoped to the named feature and configuration. It does not change …

CVE-2026-53849
GitHub-GHSA

HIGH
OpenClaw: Zalo allowFrom could bind to mutable display names
GHSA-8c59-hr4w-qg69
pkg: openclaw
eco: npm
published: Jun 18, 2026
### Summary

Zalo allowFrom could bind to mutable display names. In affected versions, a Zalo friend or contact with mutable display metadata could match a policy entry through mutable display metadata.

This advisory is scoped to the named feature and configuration. It does not change OpenClaw's tr…

CVE-2026-53857
GitHub-GHSA

HIGH
OpenClaw: Shell positional parameters could weaken strict inline-eval checks
GHSA-5cj2-3jr2-5h77
pkg: openclaw
eco: npm
published: Jun 18, 2026
### Summary

Shell positional parameters could weaken strict inline-eval checks. In affected versions, a command request that combines allowlisted tools with shell positional arguments could place inline-eval content in a shell carrier not covered by the strict check.

This advisory is scoped to the…

CVE-2026-53855
GitHub-GHSA

HIGH
PraisonAI: IMAP Command Injection via Unsanitized Email Search Parameters
GHSA-c969-5x3p-vq3v
pkg: praisonaiagents
eco: pip
published: Jun 18, 2026
## Summary

The email search tool in `src/praisonai-agents/praisonaiagents/tools/email_tools.py` constructs IMAP SEARCH commands by interpolating LLM-controlled parameters (from_addr, subject, query) directly into IMAP protocol strings using f-string formatting with double-quote delimiters. An attac…

GitHub-GHSA

HIGH
PraisonAI GitHub template cache path traversal allows outside-cache file write and directory deletion
GHSA-f44v-7qgw-9gh9
pkg: praisonai
eco: pip
published: Jun 18, 2026
## Summary

PraisonAI's template loader accepts GitHub template URIs with refs, for example
`github:owner/repo/template@v1.0.0`. The resolver stores the user-controlled
template path and ref verbatim, and the cache layer later joins those values into
`~/.praison/cache/templates/github/<owner>/<repo>…

GitHub-GHSA

HIGH
PraisonAI: Missing ownership check on DELETE endpoints allows members to delete others' content in Platform API
GHSA-rh39-9c67-59mh
pkg: praisonai-platform
eco: pip
published: Jun 18, 2026
### Summary
A workspace member can permanently delete any resource — projects, agents, issues, labels, issue dependencies, and issue-label attachments — created by the workspace owner or other members. All six content DELETE endpoints enforce workspace membership but perform no ownership or role…
GitHub-GHSA

HIGH
piscina: Prototype Pollution Gadget → RCE via inherited options.filename
GHSA-x9g3-xrwr-cwfg
pkg: piscina, piscina, piscina
eco: npm
published: Jun 18, 2026
## Summary

`piscina`'s constructor and `run()` paths read the `filename` option via plain member access:

“`js
// dist/index.js line 92 (constructor)
const filename = options.filename
? (0, common_1.maybeFileURLToPath)(options.filename)
: null;
this.options = { …kDefaultOptions, …options, …

CVE-2026-55388
GitHub-GHSA

HIGH
OpenClaw: Shell inline-command parsing could miss an allowlist check
GHSA-f397-5vjw-v2c2
pkg: openclaw
eco: npm
published: Jun 18, 2026
### Summary

Shell inline-command parsing could miss an allowlist check. In affected versions, a command request using shell inline-command forms could route an inline command through a parser case that did not receive the expected allowlist decision.

This advisory is scoped to the named feature an…

CVE-2026-53866
GitHub-GHSA

HIGH
OpenClaw: Host environment sanitizer missed two Node.js control variables
GHSA-ccwh-wwpp-6wg5
pkg: openclaw
eco: npm
published: Jun 18, 2026
### Summary

Host environment sanitizer missed two Node.js control variables. In affected versions, a lower-trust env source such as a workspace `.env`, tool env override, or skill env block could pass Node.js control variables through the shared sanitizer.

This advisory is scoped to the named feat…

CVE-2026-53864
GitHub-GHSA

HIGH
Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes
GHSA-wrr5-99h5-gq57
pkg: code.gitea.io/gitea
eco: go
published: Jun 17, 2026
## Summary

Many authenticated self routes under `/api/v1/user/…` do not enforce the `public-only` token restriction. As a result, a token or OAuth grant marked `public-only`, but otherwise carrying the route-required read/write scope category, can access or modify private account resources throug…

CVE-2026-24791
GitHub-GHSA

HIGH
Gitea: API Fork Missing CanCreateOrgRepo Check Allows Org Secret Exfiltration
GHSA-fhx7-m96w-mv29
pkg: code.gitea.io/gitea
eco: go
published: Jun 17, 2026
## Summary

The API endpoint `POST /api/v1/repos/{owner}/{repo}/forks` only checks `IsOrgMember()` when a user forks a repository into an organization, but does not check `CanCreateOrgRepo()`. The web UI fork handler correctly checks both. This allows a read-only organization member — in a team wi…

CVE-2026-22555
GitHub-GHSA

HIGH
Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication
GHSA-9r5x-wg6m-x2rc
pkg: code.gitea.io/gitea
eco: go
published: Jun 16, 2026
### Summary

Gitea fails to enforce OAuth2 access token scopes when the token is submitted via HTTP Basic authentication instead of a Bearer token. An OAuth2 application granted only `read:user` can use the same token as `Authorization: Basic base64(<token>:x-oauth-basic)` and perform write actions,…

CVE-2026-28699
GitHub-GHSA

HIGH
Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens
GHSA-cc8w-r4qh-3v65
pkg: code.gitea.io/gitea
eco: go
published: Jun 16, 2026
### Summary
Gitea v1.26.1 enforces repository-scoped access-token permissions on repository operations. In the Git Smart HTTP path, however, this check runs only when the token is presented via HTTP Basic authentication — `CheckRepoScopedToken()` returns early unless `ctx.IsBasicAuth` is true — …
CVE-2026-28744
GitHub-GHSA

HIGH
Caddy: FastCGI header normalization bypass in `forward_auth copy_headers`
GHSA-f59h-q822-g45g
pkg: github.com/caddyserver/caddy/v2, github.com/caddyserver/caddy
eco: go
published: Jun 16, 2026
### Summary

`forward_auth copy_headers` deletes the exact client-supplied identity header before copying the trusted value from the auth gateway. But when the request later goes through `php_fastcgi`, Caddy normalizes HTTP headers into CGI variables by replacing `-` with `_`.

This lets a client se…

CVE-2026-52845
GitHub-GHSA

HIGH
Deno: Command Injection via spawnSync & spawn on Windows
GHSA-7xh3-mhg9-jcw8
pkg: deno
eco: rust
published: Jun 16, 2026
## Summary

Deno's `node:child_process` implementation provided an `escapeShellArg()` helper used when callers passed `shell: true` to `spawn` / `spawnSync` / `exec` and friends. On Windows, the helper failed to quote arguments that contained `cmd.exe` metacharacters such as `&`, `|`, `<`, `>`, `^`,…

CVE-2026-49402
GitHub-GHSA

HIGH
py7zr: Arbitrary File Write Vulnerability
GHSA-q6rc-2cgv-63h7
pkg: py7zr
eco: pip
published: Jun 19, 2026
### Summary
There exists an **arbitrary file write vulnerability** in `py7zr` (1.1.0, latest), which allows symbolic links to be recreated outside the destination directory via crafted malicious symbolic link chains. When using `extractall` to extract an archive, the library restores these symbolic …
CVE-2026-23879
GitHub-GHSA

HIGH
Strimzi: Cross-namespace privilege escalation via `Kafka.spec.entityOperator`
GHSA-mw9r-p8xp-wx96
pkg: io.strimzi:strimzi
eco: maven
published: Jun 18, 2026
### Impact

Having the Topic and User operators to watch different namespaces than the one where the Kafka cluster is deployed, is a fully documented feature.

When the `watchedNamespace` field is used within the Topic or User operator (as part of the `Kafka.spec.entityOperator` field), the Cluster …

CVE-2026-55225
GitHub-GHSA

HIGH
VCR.py: Arbitrary code execution via unsafe YAML deserialization of cassette files
GHSA-rpj2-4hq8-938g
pkg: vcrpy
eco: pip
published: Jun 19, 2026
### Summary

vcrpy deserializes YAML cassette files with PyYAML's object-constructing loader (`yaml.CLoader` / `yaml.Loader`) instead of the safe loader (`yaml.CSafeLoader` / `yaml.SafeLoader`). A cassette containing a `!!python/object/apply:` (or similar) tag therefore executes arbitrary Python cod…

GitHub-GHSA

HIGH
@tinacms/cli: Remote Code Execution in @tinacms/cli via Forestry migration — unsanitised __TINA_INTERNAL__ marker in user-controlled YAML labels
GHSA-4936-9hrh-qqpw
pkg: @tinacms/cli
eco: npm
published: Jun 19, 2026
## Description

### Summary

`@tinacms/cli` contains a Remote Code Execution vulnerability in its
Forestry-to-Tina migration command. The internal helper `addVariablesToCode`
unquotes any value matching the marker `"__TINA_INTERNAL__:::(.*?):::"`
inside the stringified collection JSON. User-supplied…

CVE-2026-54074
GitHub-GHSA

HIGH
PraisonAI recipe workflow policy can be bypassed by declaring and YAML-approving dangerous tools outside TEMPLATE.yaml
GHSA-7qw2-w5rc-37×2
pkg: praisonai
eco: pip
published: Jun 18, 2026
## Summary

PraisonAI recipe execution has a dangerous-tool policy that is supposed to block default-denied tools unless the caller explicitly passes `allow_dangerous_tools=True`. That policy only checks tools declared in `TEMPLATE.yaml` `requires.tools`.

For steps-based recipes, the actual executi…

GitHub-GHSA

HIGH
PraisonAI recipe.run_stream skips dangerous-tool policy enforcement
GHSA-v847-hxxw-3pxg
pkg: praisonai
eco: pip
published: Jun 18, 2026
# PraisonAI `recipe.run_stream()` skips dangerous-tool policy enforcement

## Summary

PraisonAI recipe execution blocks default-denied dangerous tools unless the
caller explicitly passes `allow_dangerous_tools=True`. The normal `recipe.run()`
path enforces this with `_check_tool_policy()`. The stre…

GitHub-GHSA

HIGH
SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter
GHSA-cc8f-fcx3-gpjr
pkg: surrealdb
eco: rust
published: Jun 19, 2026
SurrealDB's full-text search lets you define a text analyzer whose `mapper` filter loads a term-mapping file from disk (`DEFINE ANALYZER … FILTERS mapper('<path>')`). A database user with the `EDITOR` or `OWNER` role could point that filter at any file the SurrealDB process can read and have its c…
GitHub-GHSA

HIGH
LangSmith SDK TracingMiddleware: Arbitrary server-side file read
GHSA-f4xh-w4cj-qxq8
pkg: langsmith
eco: pip
published: Jun 19, 2026
# Summary

An attacker who can send an HTTP request to a server running the LangSmith SDK's `TracingMiddleware` can cause that server to read an arbitrary file from its local filesystem and upload the contents to LangSmith as a trace attachment. Depending on how the distributed trace system is deplo…

GitHub-GHSA

HIGH
Daytona: Cross-org IDOR in organization role update/delete — any org owner can rewrite or destroy another org's roles
GHSA-qxvm-pcfm-qc39
pkg: github.com/daytonaio/daytona
eco: go
published: Jun 16, 2026
### Summary
Daytona's organization role update and delete endpoints authorized the caller as an owner of the organization named in the request path, but resolved and mutated the target role by its identifier alone, without verifying the role belonged to that organization. An authenticated user who o…
CVE-2026-54322
GitHub-GHSA

HIGH
Home Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LAN
GHSA-x84v-g949-293w
pkg: homeassistant
eco: pip
published: Jun 19, 2026
### Summary

The Konnected integration registers an HTTP endpoint, `KonnectedView` (`homeassistant/components/konnected/__init__.py`), that is marked as **not requiring authentication** (`requires_auth = False`). A comment next to that line says auth is instead handled "via the access token from con…

CVE-2026-54317
GitHub-GHSA

HIGH
npm PraisonAI SandboxExecutor network-isolated mode does not block non-proxy-aware network clients
GHSA-gqmf-56h7-rrpf
pkg: praisonai
eco: npm
published: Jun 18, 2026
## Summary

The published npm package `praisonai` exports a TypeScript `SandboxExecutor` with a `network-isolated` mode. The CLI lists that mode as:

“`text
network-isolated No network access (proxy blocked)
“`

The implementation does not create a network namespace, firewall rule, socket filter,…

GitHub-GHSA

HIGH
LangChain4j: SQL injection via metadata filters in langchain4j-mariadb and langchain4j-pgvector
GHSA-2mfg-cc43-9pcj
pkg: dev.langchain4j:langchain4j-mariadb, dev.langchain4j:langchain4j-mariadb, dev.langchain4j:langchain4j-mariadb
eco: maven
published: Jun 17, 2026
### Summary
The MariaDB and pgvector embedding stores build metadata-filter SQL by string-concatenating
filter **keys** (and, in MariaDB, string **values**) directly into the query without adequate
escaping. A crafted metadata key in `EmbeddingSearchRequest.filter()` can break out of its SQL
context…
CVE-2026-55405
GitHub-GHSA

HIGH
MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error
GHSA-6v7p-g79w-8964
pkg: msgpack
eco: pip
published: Jun 19, 2026
### Impact

If the Unpacker is used repeatedly after an error occurs, the process may crash with a SEGV.

If the Unpacker is used repeatedly to unpack untrusted input from external sources, it may be vulnerable to a DoS attack.

### Patches

v1.2.1

### Workarounds

Users should create a new Unpacke…

GitHub-GHSA

HIGH
SearXNG MCP Server: Unbounded Response Body Read Bypasses URL Size Limit in `web_url_read`
GHSA-xcqx-9jf5-w339
pkg: mcp-searxng
eco: npm
published: Jun 19, 2026
## Unbounded Response Body Read Bypasses URL Size Limit in `web_url_read`

### Summary

The `web_url_read` MCP tool in mcp-searxng enforces its 5 MiB response-size limit exclusively by inspecting the `Content-Length` header of a preliminary HEAD request. When a server omits `Content-Length` — a st…

GitHub-GHSA

HIGH
Langflow: Unauthenticated DoS through multipart form boundary file upload
GHSA-qwqc-p3q8-wcg9
pkg: langflow
eco: pip
published: Jun 19, 2026
### Summary
An attacker can send a `/api/v1/files/upload/` request without any authentication token/cookies and abuse a very long multipart form boundary to make the langflow app unusable for all users for an indefinite amount of time.

### Details
https://github.com/langflow-ai/langflow/blob/v1.0.…

CVE-2026-55446
GitHub-GHSA

HIGH
Ultimate Sitemap Parser (USP): XML Entity Expansion (Billion Laughs) DoS in XMLSitemapParser
GHSA-p5wc-9w9r-m232
pkg: ultimate-sitemap-parser
eco: pip
published: Jun 19, 2026
## XML Entity Expansion (Billion Laughs) DoS in XMLSitemapParser

### Summary

`ultimate-sitemap-parser` version 1.8.0 and earlier parse attacker-controlled XML content using Python's `xml.parsers.expat` without any restriction on DTD declarations or recursive entity references. An attacker who can …

GitHub-GHSA

HIGH
Ultimate Sitemap Parser (USP): Gzip Decompression Bomb Bypasses Sitemap Size Limit
GHSA-8823-qg2x-pv9f
pkg: ultimate-sitemap-parser
eco: pip
published: Jun 19, 2026
## Gzip Decompression Bomb Bypasses Sitemap Size Limit

### Summary

`ultimate-sitemap-parser` enforces a 100 MiB size limit on sitemap responses, but applies it only to the **compressed** bytes received over the network. When a `.gz` sitemap is fetched, `usp/helpers.py:239` calls `gzip_lib.decompre…

GitHub-GHSA

HIGH
flat-to-nested: Prototype pollution in flat-to-nested convert() via __proto__ parent/id key
GHSA-hp36-v28f-w3r4
pkg: flat-to-nested
eco: npm
published: Jun 19, 2026
### Summary
`convert()` builds the nested tree by using each flat record's `id` and `parent` field values directly as object keys, with no guard against `__proto__` / `constructor` / `prototype`. A record whose `parent` is the string `"__proto__"` makes `temp[parent]` resolve to `Object.prototype`…
CVE-2026-55091
GitHub-GHSA

HIGH
CoreWCF: Pre-authentication infinite-loop CPU exhaustion in CoreWCF net.tcp / net.pipe / net.uds framing handshake
GHSA-p86g-xrr2-pf7c
pkg: CoreWCF.NetFramingBase, CoreWCF.NetFramingBase
eco: nuget
published: Jun 19, 2026
### Impact
An unauthenticated remote attacker can pin one server thread‑pool worker at 100 % CPU per connection. With a few connections, the CPU usage can be exhausted.

#### Preconditions
An attacker being able to reach a service which is exposing an endpoint using one of NetTcpBinding, NetNamedP…

CVE-2026-54772
GitHub-GHSA

HIGH
Oj: Stack Buffer Overflow in Oj::Doc#each_child via Deeply Nested Input
GHSA-3m6q-jj5j-38c9
pkg: oj
eco: rubygems
published: Jun 19, 2026
### Summary

`Oj::Doc#each_child`, when invoked recursively over a deeply nested JSON
document, overflows a fixed-size stack buffer and aborts the process. This is a
denial of service reachable from untrusted JSON.

### Details

Two-step chain in `ext/oj/fast.c`:

1. **`doc_each_child` (~line 1501)*…

CVE-2026-54592
GitHub-GHSA

HIGH
Stanza: Remote Code Execution via Unsafe Pickle Deserialization in Model Loaders
GHSA-v5jw-96jm-7h2c
pkg: stanza
eco: pip
published: Jun 19, 2026
### Summary

Stanza 1.12.0 attempts to safely load PyTorch checkpoint files using `torch.load(…, weights_only=True)`, but automatically falls back to the fully unsafe `torch.load(…, weights_only=False)` when the safe load raises `pickle.UnpicklingError`. Because the `UnpicklingError` condition i…

CVE-2026-54499
GitHub-GHSA

HIGH
Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters
GHSA-98m9-hrrm-r99r
pkg: faraday
eco: rubygems
published: Jun 19, 2026
# Uncontrolled Recursion in NestedParamsEncoder Allows Stack Exhaustion DoS via Deeply Nested Query Parameters

## Summary

`Faraday::NestedParamsEncoder`, the default nested query parameter encoder/decoder in Faraday, decodes nested query strings without enforcing a maximum nesting depth.

A crafte…

CVE-2026-54297
GitHub-GHSA

HIGH
AlchemyCMS: Unauthenticated nested page API leaks restricted & unpublished content
GHSA-mqq5-j7w8-2hgh
pkg: alchemy_cms, alchemy_cms, alchemy_cms
eco: rubygems
published: Jun 19, 2026
# Unauthenticated nested page API leaks restricted & unpublished content

– **Location:** `app/controllers/alchemy/api/pages_controller.rb:28` (`Api::PagesController#nested`)
– **Affected version:** Alchemy CMS 8.3.0.dev (Rails 8.1.3)

## Description

The unauthenticated `GET /api/pages/nested` endp…

GitHub-GHSA

HIGH
OpenTofu: Possible arbitrary file read during certain git operations via a maliciously crafted URL
GHSA-q7j3-v8qv-22vq
pkg: github.com/opentofu/opentofu, github.com/opentofu/opentofu
eco: go
published: Jun 19, 2026
### Impact
Possible data exposure.
#### Summary
While downloading packages from a maliciously crafted URL, some git operations against that URL could allow arbitrary file read.
This might allow disclosure of confidential information.

#### Details
OpenTofu relies on [go-getter](https://github.com/ha…

GitHub-GHSA

HIGH
undici WebSocket client vulnerable to denial of service via fragment count bypass
GHSA-vxpw-j846-p89q
pkg: undici, undici, undici
eco: npm
published: Jun 19, 2026
## Impact

The undici WebSocket client enforces `maxPayloadSize` on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frames that each pass per-frame and cumulative-siz…

CVE-2026-12151
GitHub-GHSA

HIGH
undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse
GHSA-hm92-r4w5-c3mj
pkg: undici, undici
eco: npm
published: Jun 19, 2026
## Impact

When using `Socks5ProxyAgent`, undici reuses a single connection pool across different origins without verifying that the pool's origin matches the requested origin. All requests are dispatched through the pool connected to the first origin, regardless of the intended destination.

This c…

CVE-2026-6734
GitHub-GHSA

HIGH
Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
GHSA-j8cv-x86q-rj85
pkg: pipecat-ai
eco: pip
published: Jun 18, 2026
## Development Runner Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID

### Summary

The pipecat development runner registers a `/ws` WebSocket endpoint for telephony testing that accepts connections without any authentication. An unauthenticated remote att…

CVE-2026-54695
GitHub-GHSA

HIGH
undici WebSocket client vulnerable to denial of service via cumulative fragment bypass
GHSA-38rv-x7px-6hhq
pkg: undici
eco: npm
published: Jun 18, 2026
## Impact

The undici WebSocket client enforces `maxPayloadSize` per-frame but does not enforce the cumulative size of fragmented uncompressed messages. A malicious WebSocket server can stream many small fragments that each pass per-frame validation but collectively exceed the configured limit, caus…

CVE-2026-9675
GitHub-GHSA

HIGH
PraisonAI A2U incomplete authentication fix leaves current serve command unauthenticated by default
GHSA-jxcw-qp4h-6jfq
pkg: praisonai
eco: pip
published: Jun 18, 2026
## Summary

The published A2U advisory `GHSA-f292-66h9-fpmf` says unauthenticated A2U event streaming was fixed in `praisonai` `4.5.115`. Current head still exposes the same A2U subscription and event routes without authentication when the operator starts the documented CLI entrypoint:

“`text
prai…

GitHub-GHSA

HIGH
PraisonAI: Arbitrary File Read via `@file:` Mention Path Traversal
GHSA-2rcg-mm5h-xchx
pkg: praisonaiagents
eco: pip
published: Jun 18, 2026
## Summary

The MentionsParser in `src/praisonai-agents/praisonaiagents/tools/mentions.py` processes `@file:` mentions in agent prompts by reading arbitrary files from the filesystem. When a file path is not found relative to the workspace, the parser falls back to using the path as an absolute path…

GitHub-GHSA

HIGH
PraisonAI: Unauthenticated Local File Inclusion via agent_file path in PraisonAI Jobs API
GHSA-p4pj-vh7h-6cqh
pkg: praisonai
eco: pip
published: Jun 18, 2026
### Summary
An unauthenticated attacker can read arbitrary files on the server by supplying an absolute filesystem path in the `agent_file` field of the Jobs API. The field has no path validation, no allowlist, and no authentication is required to submit jobs.

### Details
The `agent_file` field in …

GitHub-GHSA

HIGH
PraisonAI dynamic-context artifact tools read arbitrary host files outside artifact storage
GHSA-j7qx-p75m-wp7g
pkg: praisonai
eco: pip
published: Jun 18, 2026
# PraisonAI dynamic-context artifact tools read arbitrary host files outside artifact storage

## Summary

PraisonAI's Dynamic Context Discovery feature exposes artifact helper tools
through `ctx.get_tools()`:

“`python
ctx = setup_dynamic_context()

agent = Agent(
instructions="You are a data …

GitHub-GHSA

HIGH
PraisonAI Dynamic Context history and terminal tools read files outside configured storage via path traversal
GHSA-22cj-m4wf-fv2c
pkg: praisonai
eco: pip
published: Jun 18, 2026
# PraisonAI Dynamic Context history and terminal tools read files outside configured storage via path traversal

## Summary

PraisonAI's Dynamic Context module provides filesystem-backed history and
terminal-log storage. The SDK reference describes the module as providing:

– artifact storage for to…

GitHub-GHSA

HIGH
JLine3 Telnet server: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVIRON Variables
GHSA-47qp-hqvx-6r3f
pkg: org.jline:jline-remote-telnet
eco: maven
published: Jun 18, 2026
### Summary

The JLine3 Telnet server (`remote-telnet` module) does not limit the number of
environment variables a client may inject via the Telnet NEW-ENVIRON option. An
unauthenticated attacker can flood the server with a large number of unique
variable pairs before sending the terminating IAC SE…

GitHub-GHSA

HIGH
JLine3 Telnet server: Unauthenticated Remote DoS via Unbounded Telnet NAWS Terminal Geometry
GHSA-2r2c-cx56-8933
pkg: org.jline:jline-remote-telnet
eco: maven
published: Jun 18, 2026
### Summary

The JLine3 Telnet server (`remote-telnet` module) does not apply an upper bound to
terminal dimensions received via the Telnet NAWS (Negotiate About Window Size) option.
An unauthenticated remote attacker can send a NAWS subnegotiation advertising a
65535×65535 terminal and repeatedly …

GitHub-GHSA

HIGH
http-proxy-middleware: multipart/form-data field injection via unescaped CRLF in `fixRequestBody`
GHSA-gcq2-9pq2-cxqm
pkg: http-proxy-middleware, http-proxy-middleware
eco: npm
published: Jun 18, 2026
## Summary
`fixRequestBody()` is the library's documented helper for re-emitting a request body that was already consumed by a body parser. When the **outgoing** `Content-Type` is `multipart/form-data`, it rebuilds the body with `handlerFormDataBodyData()`, which interpolates each `req.body` key and…
CVE-2026-55603
GitHub-GHSA

HIGH
Gotenberg: SSRF via LibreOffice document processing
GHSA-2mrg-35hw-x3x9
pkg: github.com/gotenberg/gotenberg/v8
eco: go
published: Jun 18, 2026
**Summary**

Server-Side Request Forgery (SSRF) vulnerability affecting the `/forms/libreoffice/convert` endpoint in Gotenberg v8.33.0 running with the default configuration.

By uploading a specially crafted DOCX document, an attacker can cause LibreOffice to automatically retrieve external resour…

CVE-2026-55229
GitHub-GHSA

HIGH
Hermes Agent contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to bypass Host and Origin validation
GHSA-4pqm-j46f-795x
pkg: hermes-agent
eco: pip
published: Jun 17, 2026
Hermes Agent before 0.16.0 contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to bypass Host and Origin validation. FastAPI HTTP middleware does not execute for WebSocket upgrade requests on /api/pty, /api/ws, /api/pub, and /api/events endpoints, enabling atta…
CVE-2026-53869
GitHub-GHSA

HIGH
HAPI FHIR: Incomplete fix for CVE-2026-45367: DSTU2 FHIRPathEngine.matches() missing RegexTimeout protection allows ReDoS
GHSA-fxj4-p9xp-37v5
pkg: ca.uhn.hapi.fhir:org.hl7.fhir.dstu2, ca.uhn.hapi.fhir:org.hl7.fhir.convertors, ca.uhn.hapi.fhir:org.hl7.fhir.validation
eco: maven
published: Jun 17, 2026
## Summary
The fix for CVE-2026-45367 added `RegexTimeout` protection to the `matches()` function in DSTU2016MAY, DSTU3, R4, R4B, and R5, but the DSTU2 module was incompletely patched. In `org.hl7.fhir.dstu2`, `replaceMatches()` was updated while `matches()` at line 2462 still calls the raw `String.…
CVE-2026-55470
GitHub-GHSA

HIGH
handlebars.java FileTemplateLoader Path Traversal
GHSA-r4gv-qr8j-p3pg
pkg: com.github.jknack:handlebars
eco: maven
published: Jun 17, 2026
### Impact
Any application that passes user-controlled input to Handlebars.compile() using a FileTemplateLoader (or ClassPathTemplateLoader) is vulnerable to arbitrary file read. This is a realistic attack surface for web applications that use template names from URL path parameters, request paramet…
CVE-2026-55760
GitHub-GHSA

HIGH
Duplicate Advisory: picklescan has Arbitrary file read using `io.FileIO`
GHSA-5v23-73v4-w2fp
pkg: picklescan
eco: pip
published: Jun 17, 2026
### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-9726-w42j-3qjr. This link is maintained to preserve external references.

### Original Description
picklescan before 0.0.35 contains an unsafe pickle deserialization vulnerability allowing unauthenticated attac…

GitHub-GHSA

HIGH
Multer vulnerable to Denial of Service via deeply nested field names
GHSA-72gw-mp4g-v24j
pkg: multer, multer
eco: npm
published: Jun 17, 2026
### Impact

Multer is vulnerable to a Denial of Service (DoS) via deeply nested field names in multipart form data. The `append-field` dependency parses bracket notation in field names (e.g., `a[b][c]`) with no limit on nesting depth, allowing an attacker to force allocation of deeply nested object …

CVE-2026-5079
GitHub-GHSA

HIGH
Caddy: Windows `file_server` path authorization bypass via encoded backslash
GHSA-qrp7-cvwr-j2c6
pkg: github.com/caddyserver/caddy/v2, github.com/caddyserver/caddy
eco: go
published: Jun 16, 2026
### Summary

On Windows, Caddy `path` matchers treat `/private\secret.txt` as outside `/private/*`, but `file_server` later resolves the same request path as `private\secret.txt` on disk.

An unauthenticated remote client can request `/private%5csecret.txt` and bypass Caddy path-scoped auth/deny rou…

CVE-2026-52844
GitHub-GHSA

HIGH
Netty: Unbounded pre-allocation in RedisArrayAggregator from RESP array length
GHSA-5w86-c3rq-vjj7
pkg: io.netty:netty-codec-redis, io.netty:netty-codec-redis
eco: maven
published: Jun 15, 2026
### Summary
RedisArrayAggregator pre-allocates ArrayList with initial capacity equal to the RESP array element count declared in an array header. That count is taken from the wire before the corresponding child messages exist. A small malicious header can claim a huge initial capacity.

### Details

CVE-2026-50011
GitHub-GHSA

HIGH
Netty: Wrapping plain trust manager silently disables hostname verification
GHSA-c653-97m9-rcg9
pkg: io.netty:netty-handler, io.netty:netty-handler
eco: maven
published: Jun 15, 2026
SimpleTrustManagerFactory.engineGetTrustManagers() and related paths wrap any user-supplied plain X509TrustManager in X509TrustManagerWrapper, which extends X509ExtendedTrustManager but implements the 3-arg checkServerTrusted(chain, authType, SSLEngine) by discarding the SSLEngine and calling the 2-…
CVE-2026-50010
GitHub-GHSA

HIGH
Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion
GHSA-4grm-h2qv-h6w6
pkg: io.netty:netty-codec-http3
eco: maven
published: Jun 15, 2026
### Summary
A memory exhaustion vulnerability in the Netty HTTP/3 codec allows the creation of an infinite number of blocked streams, which can cause OOM error.

### Details
The vulnerability exists in `io.netty.handler.codec.http3.QpackDecoder#shouldWaitForDynamicTableUpdates`:

If a client sends a…

CVE-2026-48748
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-45591 – ASP.NET Core Denial of Service Vulnerability
GHSA-f8h2-vmm9-qhj6
pkg: Microsoft.AspNetCore.App.Runtime.linux-x64, Microsoft.AspNetCore.App.Runtime.linux-x64, Microsoft.AspNetCore.App.Runtime.linux-x64
eco: nuget
published: Jun 15, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core SignalR and Blazor Server. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A denial of service v…

CVE-2026-45591
GitHub-GHSA

HIGH
CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality
GHSA-2288-8h3r-cqgg
pkg: CoreWCF.Primitives
eco: nuget
published: Jun 19, 2026
### Impact
When the proof key recovered from the RSTR can be observed by a party that is not the legitimate client, that party can impersonate the authenticated Windows principal for the lifetime of the SCT (default ~10 hours) and decrypt or forge any subsequent WS‑SecureConversation traffic that …
CVE-2026-54784
GitHub-GHSA

HIGH
CoreWCF: XML Signature Wrapping in WS-Security endorsing/supporting signature verification allows replay of captured signed messages
GHSA-gqv6-pwcg-87r8
pkg: CoreWCF.Primitives, CoreWCF.Primitives
eco: nuget
published: Jun 19, 2026
### Impact
The attacker, with one captured signed SOAP envelope from a victim and no other privileges, can invoke arbitrary operations on the service as the victim principal for the lifetime of the captured signing key. There is no rate limit on replays. The DetectReplays setting on transport-securi…
CVE-2026-54783
GitHub-GHSA

HIGH
CoreWCF: SAML SubjectConfirmation methods and holder-of-key proof keys are not enforced
GHSA-48pq-2xq3-c2m4
pkg: CoreWCF.Primitives, CoreWCF.Primitives
eco: nuget
published: Jun 19, 2026
### Impact
The relying application is given a ClaimsPrincipal for a subject whose authority over the assertion the sender never proved. There are two distinct exploit shapes:
– Holder-of-key downgrade. An attacker who obtains a holder-of-key SAML assertion that was issued without KeyInfo (issuer bug…
CVE-2026-54781
GitHub-GHSA

HIGH
CoreWCF: SamlSerializer skips SignatureValue verification when SAML signing token is not an X.509 certificate
GHSA-rpj7-hr7h-w6p9
pkg: CoreWCF.Primitives, CoreWCF.Primitives
eco: nuget
published: Jun 19, 2026
### Impact
When a service is configured to validate SAML tokens using a method other than X.509 certificate signing, the final signature verification is skipped.

#### Preconditions
The service is configured to authenticate using SAML tokens and an out of band token resolver (commonly the IssuerToke…

CVE-2026-54774
GitHub-GHSA

HIGH
undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent
GHSA-vmh5-mc38-953g
pkg: undici, undici
eco: npm
published: Jun 18, 2026
## Impact

undici's `ProxyAgent` silently drops the `requestTls` option when configured with a SOCKS5 proxy URI (`socks5://` or `socks://`). The target HTTPS connection through the SOCKS5 tunnel falls back to Node's default trust store, ignoring user-configured `ca`, `cert`, `key`, `rejectUnauthoriz…

CVE-2026-9697
GitHub-GHSA

HIGH
ZITADEL: Missing client_id binding in OIDC authorization code exchange and refresh token flows (RFC 6749 Section 4.1.3 violation)
GHSA-xqxv-4jc2-x56x
pkg: github.com/zitadel/zitadel
eco: go
published: Jun 18, 2026
### Summary

Zitadel's OAuth2 / OIDC `CodeExchange` and `RefreshToken` implementations omit a critical validation step to ensure that the requesting client matches the client that originally initiated the authorization flow. This violates RFC 6749 Section 4.1.3, which mandates that the authorization…

CVE-2026-55672
GitHub-GHSA

HIGH
Deno: Miller-Rabin Primality Test Allows Zero Rounds
GHSA-9xg4-qhm4-g43w
pkg: deno
eco: rust
published: Jun 16, 2026
## Summary

`node:crypto.checkPrime(candidate[, options][, callback])` and `crypto.checkPrimeSync(candidate[, options])` ran no Miller-Rabin rounds at all when the caller left `options.checks` at its default of `0`. In that mode, the only test applied to the candidate was trial division by the prime…

CVE-2026-49440
GitHub-GHSA

HIGH
Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()
GHSA-6rfw-mq36-jm8h
pkg: bedrock-agentcore
eco: pip
published: Jun 19, 2026
### Summary
The AWS Bedrock AgentCore Python SDK (bedrock-agentcore) is an open-source SDK that enables developers to build, deploy, and manage agents on AWS Bedrock AgentCore. An issue exists in the install_packages() method of the Code Interpreter client where crafted package name arguments can by…
CVE-2026-12530
GitHub-GHSA

HIGH
PraisonAI Code agent tools fail open without a workspace boundary
GHSA-gcq3-mfvh-3×25
pkg: praisonai
eco: pip
published: Jun 18, 2026
# PraisonAI Code agent tools fail open without a workspace boundary

## Summary

PraisonAI Code's agent-compatible `CODE_TOOLS` wrappers keep a global workspace root initialized to `None`. If an application uses `CODE_TOOLS`, `code_read_file`, `code_search_replace`, or `code_apply_diff` before calli…

GitHub-GHSA

HIGH
PraisonAI: Jobs webhook SSRF protection bypass via DNS rebinding
GHSA-rjvw-7vvw-549v
pkg: praisonai
eco: pip
published: Jun 18, 2026
# Jobs webhook SSRF protection bypass via DNS rebinding

## Summary

PraisonAI's Async Jobs API validates `webhook_url` when a job request is parsed
and again when the internal `Job` object is constructed. That validation blocks
direct loopback/private targets, but it is not bound to the later netwo…

GitHub-GHSA

HIGH
@jhb.software/payload-cloudinary-plugin: Arbitrary Cloudinary API Parameter Signing
GHSA-h5x8-xp6m-x6q4
pkg: @jhb.software/payload-cloudinary-plugin
eco: npm
published: Jun 19, 2026
## Arbitrary Cloudinary API Parameter Signing in @jhb.software/payload-cloudinary-plugin

### Summary

`@jhb.software/payload-cloudinary-plugin` v0.3.4 exposes a server-side signing endpoint (`POST /api/cloudinary-generate-signature`) that passes attacker-supplied `paramsToSign` directly to `cloudin…

GitHub-GHSA

HIGH
SearXNG MCP Server: DNS-resolved Private Hostname SSRF in `web_url_read`
GHSA-mrvx-jmjw-vggc
pkg: mcp-searxng
eco: npm
published: Jun 19, 2026
## DNS-resolved Private Hostname SSRF in `web_url_read`

### Summary

The `web_url_read` MCP tool in `mcp-searxng` is vulnerable to Server-Side Request Forgery (SSRF) via DNS rebinding bypass. The `assertUrlAllowed()` function at `src/url-reader.ts:85-93` validates only the syntactic hostname string…

GitHub-GHSA

HIGH
Network-AI: Poisoned environment backup manifest allows arbitrary recursive deletion during backup pruning
GHSA-2fmp-9rvw-hc96
pkg: network-ai
eco: npm
published: Jun 19, 2026
### Summary
`EnvironmentManager.listBackups()` reads each backup's `_manifest.json` and trusts the manifest's `path` field. `EnvironmentManager.pruneBackups()` later passes that trusted `entry.path` directly to `rmSync(entry.path, { recursive: true, force: true })`.

An attacker who can place or mod…

GitHub-GHSA

HIGH
jupyterlab-git excluded_paths Case-Sensitivity Bypass Allows Reading Excluded Directories
GHSA-436q-jwfr-rm2h
pkg: jupyterlab-git
eco: pip
published: Jun 19, 2026
## Summary

`jupyterlab-git` 0.53.0 (latest, 2026-04-30) uses `fnmatch.fnmatchcase()` in `GitHandler.prepare()` (`jupyterlab_git/handlers.py:91`) to enforce the admin-configured `excluded_paths` security control. Because `fnmatchcase` is unconditionally case-sensitive, an authenticated user on a cas…

CVE-2026-54528
GitHub-GHSA

HIGH
OpenClaw: Workspace-derived service PATH could influence trash command selection
GHSA-rx78-29qr-5hq8
pkg: openclaw
eco: npm
published: Jun 18, 2026
### Summary

Workspace-derived service PATH could influence trash command selection. In affected versions, a workspace-derived environment path could select an unintended `trash` executable during maintenance.

This advisory is scoped to the named feature and configuration. It does not change OpenCl…

CVE-2026-53865
GitHub-GHSA

HIGH
OpenClaw: Workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots
GHSA-wc84-j36w-pw4x
pkg: openclaw
eco: npm
published: Jun 18, 2026
### Summary

Workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots. In affected versions, a workspace `.env` in a repository opened by a trusted operator could set `STATE_DIRECTORY` before runtime dependency root resolution.

This advisory is scoped to the named feature and…

CVE-2026-53858
GitHub-GHSA

HIGH
OpenClaw: Workspace .env npm_execpath could influence bundled runtime dependency install
GHSA-24vr-rprv-67rf
pkg: openclaw
eco: npm
published: Jun 18, 2026
### Summary

Workspace .env npm_execpath could influence bundled runtime dependency install. In affected versions, a workspace `.env` in a repository opened by a trusted operator could override the package-manager executable path used by the install helper.

This advisory is scoped to the named feat…

CVE-2026-53846
GitHub-GHSA

HIGH
OpenClaw: Linux and macOS exec allowlists skipped configured argument patterns
GHSA-v2ww-5rh7-2h5v
pkg: openclaw
eco: npm
published: Jun 18, 2026
### Summary

OpenClaw's exec allowlist supported optional `argPattern` entries to restrict the arguments accepted for an allowlisted executable. In affected releases, Linux and macOS gateways skipped `argPattern` checks and treated a matching executable path as sufficient to satisfy the allowlist.

CVE-2026-53853
GitHub-GHSA

HIGH
Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message
GHSA-p6gq-j5cr-w38f
pkg: nodemailer
eco: npm
published: Jun 18, 2026
# Message-level `raw` option bypasses `disableFileAccess` / `disableUrlAccess`, enabling arbitrary file read and full-response SSRF in the sent message

– **Target:** nodemailer/nodemailer, npm `nodemailer` **v9.0.0** (HEAD `4e58450eb490e5097a74b2b2cce35a8d9e21856e`)
– **Verdict:** CONFIRMED (local …

GitHub-GHSA

HIGH
OpenClaw: Workspace .env CLOUDSDK_PYTHON could influence Gmail setup gcloud execution
GHSA-fq9j-vw4w-fr6v
pkg: openclaw
eco: npm
published: Jun 18, 2026
### Summary

Workspace .env CLOUDSDK_PYTHON could influence Gmail setup gcloud execution. In affected versions, a workspace `.env` in a repository opened by a trusted operator could influence which Python runtime `gcloud` used through `CLOUDSDK_PYTHON`.

This advisory is scoped to the named feature …

CVE-2026-53842
GitHub-GHSA

HIGH
OpenClaw: MCP Streamable HTTP redirects could forward configured custom headers to another origin
GHSA-rjxq-qqhf-8hwh
pkg: openclaw
eco: npm
published: Jun 17, 2026
### Summary

OpenClaw supports remote MCP Streamable HTTP servers with operator-configured custom headers. In affected releases, those headers could be forwarded when the MCP endpoint responded with a cross-origin redirect.

This issue is limited to configured MCP Streamable HTTP servers that use cu…

CVE-2026-53840
GitHub-GHSA

HIGH
Daytona: Public sandbox previews remain accessible for up to one hour after being made private
GHSA-ww63-pv5x-vfc8
pkg: github.com/daytonaio/daytona
eco: go
published: Jun 16, 2026
### Summary
Sandbox previews that were switched from public to private could remain reachable without authentication for a short period after the change, due to a cached visibility state that was not invalidated when the sandbox's visibility changed.

### Impact
When a sandbox owner changed a previe…

CVE-2026-54321
GitHub-GHSA

HIGH
Anki's local HTTP server does not sufficiently validate requests
GHSA-869j-r97x-hx2g
pkg: aqt
eco: pip
published: Jun 19, 2026
## Summary

Anki launches a local HTTP server to serve media files and web pages for parts of its interface. The server fails to validate requests in the following ways:
1. No sufficient validation of the Origin header.
2. Some endpoints are vulnerable to path traversal attacks.

This allows malicio…

GitHub-GHSA

HIGH
Lokka: Azure Resource Manager URL path validation issue
GHSA-g2gw-q38m-vjfc
pkg: @merill/lokka
eco: npm
published: Jun 19, 2026
Lokka versions prior to 2.1.2 constructed Azure Resource Manager request URLs using direct string concatenation with user-controlled path input. Specially crafted path values could alter URL authority parsing and cause Azure Resource Manager bearer tokens to be sent to an unintended host. Version 2.…
GitHub-GHSA

HIGH
Uni-CLI: Legacy HTTP MCP transport accepted browser-originated localhost requests
GHSA-v3f4-w7r7-v3hm
pkg: @zenalexa/unicli
eco: npm
published: Jun 19, 2026
## Impact

Uni-CLI versions before 0.225.2 exposed the legacy JSON-RPC-over-HTTP MCP transport on loopback without validating browser Origin headers before routing requests. A malicious web page could send a CORS simple POST request, such as text/plain, to the local /mcp endpoint and deliver a JSON-…

GitHub-GHSA

HIGH
stigmem-node: decay sweep expires and counts facts across all tenants (cross-tenant BOLA)
GHSA-6gqw-jqv7-v88m
pkg: stigmem-node
eco: pip
published: Jun 19, 2026
### Summary
On a multi-tenant stigmem node, a caller holding a `write` credential for **one** tenant can run a decay sweep that acts on **every** tenant's facts. The candidate-selection queries in `lifecycle/decay.py` (`_select_ttl_candidates`, `_select_confidence_candidates`) carried no `tenant_id`…
GitHub-GHSA

HIGH
stistigmem-node: quarantine review surface exposes and mutates other tenants' quarantined facts (cross-tenant BOLA)
GHSA-xhv3-q4xx-349r
pkg: stigmem-node
eco: pip
published: Jun 19, 2026
### Summary
On a multi-tenant stigmem node, a tenant administrator could list, read, and **admit or reject** quarantined facts belonging to **other** tenants. The list/count queries and `_get_quarantined_fact` in `routes/quarantine.py` lacked an `f.tenant_id = identity.tenant_id` predicate, and the …
GitHub-GHSA

HIGH
stigmem-node: RTBF tombstones are mis-attributed and suppress reads tenant-blind (cross-tenant BOLA)
GHSA-x26h-xmv8-gxf7
pkg: stigmem-node
eco: pip
published: Jun 19, 2026
### Summary
On a multi-tenant stigmem node, RTBF (right-to-be-forgotten) tombstones were mis-scoped two ways. (1) `issue_tombstone` defaulted the tenant to `"default"` instead of the caller's tenant, so tombstones could be written to the wrong tenant. (2) The read-suppression path — `_get_tombston…
GitHub-GHSA

HIGH
Gogs: XSS in .ipynb files renderer due to outdated notebookjs
GHSA-6vxv-wg6j-5qwp
pkg: gogs.io/gogs
eco: go
published: Jun 19, 2026
### Summary

Gogs renders Jupyter notebook files (`.ipynb`) using [jsvine/notebookjs](https://github.com/jsvine/notebookjs), but the version is outdated, missing patches for known XSS vulnerabilities.

### Details

Gogs uses version 0.4.2 of notebookjs to render Jupyter notebook files:

https://gith…

GitHub-GHSA

HIGH
http4k: `HmacSha256.hash` (despite the `Hmac` naming) computed a plain unkeyed digest; clarified by deprecation in favour of `Sha256.hash` / `Sha256.hmac`
GHSA-m4w9-hjfw-vwj4
pkg: org.http4k:http4k-core
eco: maven
published: Jun 19, 2026
### Impact

The `HmacSha256` class contained two functions:
– `hash(payload)` — a plain unkeyed SHA-256 digest. The `Hmac` prefix in the class name was misleading; this function has no key parameter, so it could never have been an HMAC.
– `hmacSHA256(key, data)` — a properly keyed HMAC-SHA256.

GitHub-GHSA

HIGH
TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover
GHSA-g5qx-h5f3-mp2f
pkg: tinacms, @tinacms/app
eco: npm
published: Jun 19, 2026
TinaCMS registers window message listeners — the useTina overlay handler, the OAuth authentication popup handler, and the admin↔preview iframe GraphQL reducer — that act on event.data without verifying event.origin or event.source, and post messages using non-specific target origins. A page th…
CVE-2026-55660
GitHub-GHSA

HIGH
@cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized –workspace Argument
GHSA-v75r-vx73-82pj
pkg: @cyclonedx/cyclonedx-npm
eco: npm
published: Jun 19, 2026
## Summary
A command injection vulnerability exists in `@cyclonedx/cyclonedx-npm` when the CLI is invoked with the `–workspace <value>` option while the environment variable `npm_execpath` is unset or empty.
User‑supplied `–workspace` values are passed to a subshell without proper sanitization…
CVE-2026-55849
GitHub-GHSA

HIGH
Concurrent Ruby : `AtomicReference#update` livelocks when the stored value is `Float::NAN`
GHSA-h8w8-99g7-qmvj
pkg: concurrent-ruby
eco: rubygems
published: Jun 19, 2026
### Summary
`Concurrent::AtomicReference#update` can enter a permanent busy retry loop when the current value is `Float::NAN`.

The issue is caused by the interaction between:
– `AtomicReference#update`, which retries until `compare_and_set(old_value, new_value)` succeeds.
– Numeric `compare_and_set…

CVE-2026-54904
GitHub-GHSA

HIGH
Oj: Integer Overflow in Oj.load 2GB String Handling
GHSA-475m-ph3x-64gp
pkg: oj
eco: rubygems
published: Jun 19, 2026
### Summary

`Oj.load` is vulnerable to heap corruption when parsing a JSON string longer than 2 GB. An integer overflow in `buf_append_string` (`buf.h:61`) converts the string length to a large negative `size_t`, causing `memcpy` to copy an astronomically large amount of data out of bounds. This cr…

CVE-2026-54903
GitHub-GHSA

HIGH
Oj: Use-After-Free in Oj::Parser SAJ Long Key Callback
GHSA-m578-w5vf-rfcm
pkg: oj
eco: rubygems
published: Jun 19, 2026
### Summary

`Oj::Parser` in SAJ mode does not protect cached object keys (≥ 35 bytes) from garbage collection. A Ruby callback that triggers GC inside `hash_end` can cause the key string to be reclaimed while the C parser still holds a pointer to it. The subsequent access to the freed string VALU…

CVE-2026-54902
GitHub-GHSA

HIGH
Oj: Use-After-Free in Oj::Parser array_class/hash_class GC Marking
GHSA-vwm4-62gf-x745
pkg: oj
eco: rubygems
published: Jun 19, 2026
### Summary

`Oj::Parser` in usual mode does not mark `array_class` and `hash_class` references during garbage collection. If GC runs after the class is assigned but before a parse, the class object is reclaimed, leaving the parser holding a dangling VALUE. The subsequent `parse` call dereferences t…

CVE-2026-54901
GitHub-GHSA

HIGH
Oj: Negative-Size memcpy in Oj::Parser create_id Attribute Handling
GHSA-9cv6-qcjw-4grx
pkg: oj
eco: rubygems
published: Jun 19, 2026
### Summary

`Oj::Parser#parse` in usual mode with `create_id` enabled is vulnerable to heap corruption via a negative-size `memcpy`. When a JSON object key is exactly 65,535 bytes long, an integer truncation in `form_attr` (`usual.c:63`) converts the length to `-1` before passing it to `memcpy`. Th…

CVE-2026-54900
GitHub-GHSA

HIGH
Kozou: Unauthenticated MCP HTTP server and bundled dev-stack hardening (DNS-rebinding, request-body limits, read-only reads, default network exposure)
GHSA-v52w-28xh-v562
pkg: kozou, @kozou/api, @kozou/mcp
eco: npm
published: Jun 19, 2026
Kozou compiles a PostgreSQL schema into an Admin UI, a REST API, and an MCP server. Several hardening gaps in the bundled HTTP surfaces and the scaffolded dev stack are fixed in **1.8.1**.

## Issues

1. **MCP HTTP server lacked DNS-rebinding protection.** The Streamable HTTP transport is unauthenti…

GitHub-GHSA

HIGH
Oj: Use-After-Free in Oj::Parser SAJ Callback via Input Mutation
GHSA-q2gm-54r6-8fwm
pkg: oj
eco: rubygems
published: Jun 19, 2026
### Summary

`Oj::Parser#parse` is vulnerable to a heap use-after-free when a SAJ/SAJ2 callback mutates the input JSON string during parsing. The C engine holds a raw `const byte *` pointer into the Ruby string's internal buffer. If a callback (e.g. `hash_start`) resizes the string — for example b…

CVE-2026-54898
GitHub-GHSA

HIGH
Oj: Use-After-Free in Oj::Doc Iterators via Reentrant Close
GHSA-9ppp-w3g4-fh4q
pkg: oj
eco: rubygems
published: Jun 19, 2026
### Summary

`Oj::Doc` iterators (`each_value`, `each_child`, `each_leaf`) are vulnerable to a heap use-after-free. When a Ruby block yielded during iteration calls `doc.close` or `d.close`, the document's heap memory is freed while the C iterator is still running. When control returns from the bloc…

CVE-2026-54897
GitHub-GHSA

HIGH
Oj: Heap Buffer Overflow in Oj.dump Exception Serialization via Large Indent
GHSA-35w3-pjm6-wj95
pkg: oj
eco: rubygems
published: Jun 19, 2026
### Summary

`Oj.dump` in object mode is vulnerable to a heap buffer overflow when serializing Exception objects with a large `:indent` value. The serializer allocates a buffer sized for the object's attributes but does not account for the indent bytes added on each write. With `indent: 5000`, the a…

CVE-2026-54896
GitHub-GHSA

HIGH
jupyterlab-git extension: Stored XSS leading to RCE
GHSA-f962-v9hr-pfg5
pkg: jupyterlab-git, jupyterlab-git-core, @jupyterlab/git
eco: npm
published: Jun 19, 2026
Overview

Amazon Web Services (AWS) Security has identified a stored cross-site scripting (XSS) issue in the jupyterlab-git JupyterLab extension that can lead to remote code execution (RCE). The issue exists in the PlainTextDiff.ts component, where the createHeader() method passes Git filenames dir…

CVE-2026-54527
GitHub-GHSA

HIGH
containerd CRI checkpoint restore CDI annotation smuggling
GHSA-33vj-92qq-66hc
pkg: github.com/containerd/containerd/v2, github.com/containerd/containerd/v2, github.com/containerd/containerd/v2
eco: go
published: Jun 19, 2026
### Impact

containerd's CRI implementation improperly trusts Container Device Interface (CDI) annotations found within untrusted checkpoint image metadata during container restoration. When restoring a container from a checkpoint, containerd preserves CDI-related annotations from the checkpoint arc…

CVE-2026-53492
GitHub-GHSA

HIGH
Arbitrary host CRI log file read via symlink following in CRI checkpoint restore
GHSA-rgh6-rfwx-v388
pkg: github.com/containerd/containerd/v2, github.com/containerd/containerd/v2, github.com/containerd/containerd/v2
eco: go
published: Jun 19, 2026
### Impact
A bug was found in containerd where the CRI plugin restores `container.log` from a checkpoint image without validating a symlinked path. This could result in reading an arbitrary file on the host via `kubectl logs`.

### Patches
This bug has been fixed in the following containerd versions…

CVE-2026-53489
GitHub-GHSA

HIGH
containerd CRI — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull
GHSA-xhf5-7wjv-pqxp
pkg: github.com/containerd/containerd, github.com/containerd/containerd/v2, github.com/containerd/containerd/v2
eco: go
published: Jun 19, 2026
### Impact
A bug was found in containerd where the CRI plugin propagates labels from an image config (`LABEL` instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host, via a plugin that consumes container labels for some operations.
CVE-2026-53488
GitHub-GHSA

HIGH
Oj: Stack Buffer Overflow in Oj.dump via Large Indent
GHSA-3v45-f3vh-wg7m
pkg: oj
eco: rubygems
published: Jun 19, 2026
### Summary

`Oj.dump` is vulnerable to a stack-based buffer overflow when a large `:indent` value is provided by the developer. `fill_indent` in `dump.h` calls `memset(indent_str, ' ', (size_t)opts->indent)` without validating the size. When `opts->indent` is set to `INT_MAX` (2,147,483,647), the `…

CVE-2026-54502
GitHub-GHSA

HIGH
Oj: Use-After-Free in Oj::Parser Symbol Key Cache Toggle
GHSA-2cw7-v8ff-p88r
pkg: oj
eco: rubygems
published: Jun 19, 2026
### Summary

Disabling `symbol_keys` on a reused `Oj::Parser` instance triggers a heap use-after-free. When `symbol_keys` is toggled from `true` to `false`, `opt_symbol_keys_set` frees the internal key cache (`cache_free`) but does not clear the pointer. The next `parse` call reads from the freed ca…

CVE-2026-54899
GitHub-GHSA

HIGH
Hugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF)
GHSA-r46f-3rpw-hxrv
pkg: github.com/gohugoio/hugo
eco: go
published: Jun 19, 2026
### Impact

The default `security.http.urls` policy denies requests to loopback, internal,
and cloud-metadata IPv4 literals (e.g. `http://127.0.0.1/`,
`http://169.254.169.254/`). The deny rule only matched dotted-decimal notation,
so alternate IPv4 encodings of the same addresses — integer…

GitHub-GHSA

HIGH
ouroboros-ai: Incomplete fix of CVE-2026-47211: untrusted project .env can still reach RCE via omitted execution-routing keys
GHSA-jv2h-4p9v-wf5w
pkg: ouroboros-ai
eco: pip
published: Jun 19, 2026
### Impact
The CVE-2026-47211 fix (0.39.0) added `_UNTRUSTED_ENV_DENYLIST` to stop an untrusted project-directory `.env` from redirecting execution. The denylist was incomplete — several execution-routing keys of the same RCE class were omitted, so a malicious cloned repo can still reach arbitrary…
GitHub-GHSA

HIGH
ReDoS in DotVVM routing
GHSA-c2g3-c4gc-w5wg
pkg: DotVVM, DotVVM, DotVVM
eco: nuget
published: Jun 19, 2026
### Impact

This impacts users which use multiple unconstrained route parameters not separated by a `/`. For instance, the following code is vulnerable:
“`
var route = new DotvvmRoute("edit/{a}-{b}-{c}/done", null, "testpage", null, null, configuration);

var adversarialInput = "edit/" + new string…

GitHub-GHSA

HIGH
parse-server: Denial of service via exponential-time processing of deeply nested query operators
GHSA-cgxm-vr2f-6fj8
pkg: parse-server, parse-server
eco: npm
published: Jun 19, 2026
### Impact

Parse Server is vulnerable to denial of service. A remote attacker can send a single, small query (~1 KB) containing deeply nested query condition operators. Parse Server processes the nested structure with exponential time complexity, which blocks the Node.js event loop and makes the se…

GitHub-GHSA

HIGH
Tilt: Cross-site WebSocket hijacking of the Tilt HUD stream
GHSA-6m68-r693-78qx
pkg: github.com/tilt-dev/tilt
eco: go
published: Jun 19, 2026
## Summary
The Tilt HUD WebSocket (`/ws/view`) is gated by a CSRF token, but the token is served by an unauthenticated endpoint and the upgrader accepts any client that omits an `Origin` header. When the HUD is network-exposed, an attacker can open the HUD stream and read the developer's session sta…
CVE-2026-55883
GitHub-GHSA

HIGH
Tilt: Unauthenticated pprof debug endpoints on the Tilt HUD server
GHSA-p749-9w62-w533
pkg: github.com/tilt-dev/tilt
eco: go
published: Jun 19, 2026
## Summary
The Tilt HUD server mounts Go's `net/http/pprof` handlers under `/debug` with no access control. When the HUD is network-exposed, an attacker can read process memory — including session and apiserver tokens — and hold the process under profiling.

## Details
A blank import of `net/htt…

CVE-2026-55882
GitHub-GHSA

HIGH
[Eclipse Theia] Indirect Prompt Injection via Auto-Loaded Workspace Prompt Template Files in AI Chat
GHSA-m973-pr9r-hp2w
pkg: @theia/ai-chat-ui, @theia/ai-chat, @theia/ai-claude-code
eco: npm
published: Jun 18, 2026
In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were automatically loaded and could override or extend the AI agent's system prompts. An attacker could craft a malicious repository containing prompt template files that, when the workspac…
CVE-2026-46580
GitHub-GHSA

HIGH
[Eclipse Theia] Arbitrary Command Execution via Untrusted Workspace Task Definitions
GHSA-g9jw-92q7-g7fj
pkg: @theia/debug, @theia/task, @theia/workspace
eco: npm
published: Jun 18, 2026
In Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. .theia/tasks.json, .vscode/tasks.json) could be executed without requiring workspace trust. An attacker could craft a malicious repository that, when cloned and opened in Theia, leads to execution of arbitrar…
CVE-2026-44691
GitHub-GHSA

HIGH
[Eclipse Theia] Indirect Prompt Injection via Adversarial Workspace File and Directory Names in AI Chat
GHSA-3jww-hxqj-wfq2
pkg: @theia/ai-chat-ui, @theia/ai-chat, @theia/ai-claude-code
eco: npm
published: Jun 18, 2026
In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its prompt context without distinguishing them from system instructions. An attacker could craft a malicious repository with adversarial directory or file names that, when analyzed by…
CVE-2026-44688
GitHub-GHSA

HIGH
AgenticMail: Unauthenticated inbound mail triggers bypassPermissions resume of the operator's Claude Code session (bridge-wake)
GHSA-fq4x-789w-jg5h
pkg: @agenticmail/core, @agenticmail/claudecode, @agenticmail/codex
eco: npm
published: Jun 18, 2026
## Summary
Two inbound-mail handlers act on a privileged effect without verifying that the sender is the operator, while a sibling handler in the same repo does. The higher-impact one: any external email routed to the bridge inbox causes the dispatcher to resume the operator's Claude Code session wi…
GitHub-GHSA

HIGH
AgenticMail: Cross-agent task authorization bypass in AgenticMail API
GHSA-hjwc-26pj-v3pm
pkg: @agenticmail/api
eco: npm
published: Jun 18, 2026
## Summary

A low-privileged authenticated AgenticMail agent can enumerate another agent's pending/claimed tasks by supplying the target agent name to `GET /api/agenticmail/tasks/pending?assignee=<name>`. The returned task objects include the task IDs and payloads. The same task IDs can then be used…

GitHub-GHSA

HIGH
MCP Toolbox for Databases: authenticated authorization bypass
GHSA-5gf6-gc35-xjpc
pkg: github.com/googleapis/mcp-toolbox
eco: go
published: Jun 18, 2026
An authenticated authorization bypass vulnerability exists in MCP Toolbox for Databases due to missing scope enforcement across older protocol handlers.

While the 2025-11-25 protocol version handler correctly enforces per-tool restrictions defined by scopesRequired, older supported protocol version…

CVE-2026-11719
GitHub-GHSA

HIGH
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode
GHSA-4jgr-pg2m-m988
pkg: github.com/dadrus/heimdall
eco: go
published: Jun 18, 2026
### Summary

When Heimdall operates in proxy mode, it constructs the `Forwarded` HTTP header after executing the matched rule pipeline by inserting the incoming request's `Host` header value directly into the header string without sanitizing commas or semicolons. This allows an attacker to inject ad…

GitHub-GHSA

HIGH
Heimdall: IP Spoofing via Unvalidated Forwarding Headers
GHSA-38×9-25wx-7fg2
pkg: https://github.com/dadrus/heimdall
eco: go
published: Jun 18, 2026
### Summary

When the `trusted_proxies` option is configured, heimdall extracts client IP addresses from the `Forwarded` (`for=` parameter) and `X-Forwarded-For` headers and exposes them as `Request.ClientIPAddresses` to the rule pipeline. However, extracted values are not validated to be syntactica…

GitHub-GHSA

HIGH
Karate Mock Server RCE via embedded expression evaluation of request-derived data
GHSA-2c85-rfcc-g74j
pkg: io.karatelabs:karate-core
eco: maven
published: Jun 18, 2026
### Summary

Karate Mock Server can execute embedded expressions found in attacker-controlled HTTP request data when a Mock Server feature assigns request-derived values such as `request`, `requestHeaders`, or `requestParams` to variables.

In affected scenarios, an unauthenticated remote attacker c…

GitHub-GHSA

HIGH
Docker MCP Gateway: Argument injection via OCI image label YAML
GHSA-r2xf-7jw5-pjg6
pkg: github.com/docker/mcp-gateway
eco: go
published: Jun 18, 2026
## Summary

A maliciously crafted OCI image label can inject arbitrary arguments into the `docker run` command line constructed by the MCP Gateway. An attacker who controls an image that the victim references via `docker://`, or that the victim's catalog pulls a snapshot from, can mount the host fil…

CVE-2026-55887
GitHub-GHSA

HIGH
Duplicate Advisory: Picklescan (scan_pytorch) Bypass via dynamic eval MAGIC_NUMBER
GHSA-cc5p-54×3-hcf8
pkg: picklescan
eco: pip
published: Jun 17, 2026
## Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-97f8-7cmv-76j2. This link is maintained to preserve external references.

## Original Description
picklescan before 1.0.3 contains a scanning bypass vulnerability in the scan_pytorch function that allows attac…

GitHub-GHSA

HIGH
Apache Shiro: LDAP DN Injection in DefaultLdapRealm
GHSA-x96m-rh44-vgv8
pkg: org.apache.shiro:shiro-core, org.apache.shiro:shiro-core
eco: maven
published: Jun 17, 2026
A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm class. User-supplied username input is directly concatenated into the LDAP DN template without any escaping of RFC 2253 special characters. This allows an attacker to manipulate the…
CVE-2026-49268
GitHub-GHSA

HIGH
Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts
GHSA-9cr8-q42q-g8m7
pkg: Traefik, github.com/traefik/traefik/v2, github.com/traefik/traefik
eco: go
published: Jun 16, 2026
## Summary

There is a critical vulnerability in Traefik's HTTP/3 (QUIC) TLS configuration selection that allows unauthenticated clients to bypass router-specific mTLS enforcement. When HTTP/3 is enabled on an entrypoint, the TLS handshake selects the applicable TLS configuration through an exact, c…

CVE-2026-53622
GitHub-GHSA

HIGH
Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypass
GHSA-5r4w-85f3-pw66
pkg: Traefik
eco: go
published: Jun 16, 2026
## Summary

There is a high severity vulnerability in Traefik's domain-fronting protection (`SNICheck`) that allows an unauthenticated client to bypass mutual TLS enforced through wildcard router `TLSOptions`. When a router uses a wildcard host rule such as `Host(`*.example.com`)` with stricter TLS …

CVE-2026-48491
GitHub-GHSA

MEDIUM
OpenBao: LDAPi ldaputil (wrong escape func)
GHSA-6mwx-4547-5vc9
pkg: github.com/openbao/openbao, github.com/openbao/openbao
eco: go
published: Jun 19, 2026
## 1. Description

### Component

`sdk/helper/ldaputil/client.go` — the shared LDAP utility library used by both the LDAP authentication backend and OpenLDAP secrets engine to construct LDAP search filters and bind DNs.

### Root Cause

The LDAP utility contains a **function selection error** that…

CVE-2026-55770
GitHub-GHSA

MEDIUM
dbt MCP Server: Unauthenticated OAuth Context Endpoint Leaks dbt Platform Tokens
GHSA-jr33-mw75-7j8f
pkg: dbt-mcp
eco: pip
published: Jun 19, 2026
## Unauthenticated OAuth Context Endpoint Leaks dbt Platform Tokens

### Summary

The local OAuth helper FastAPI server bundled with `dbt-mcp` exposes the `GET /dbt_platform_context` endpoint without any form of authentication or host-origin validation. After a user completes the OAuth login flow ag…

CVE-2026-55837
GitHub-GHSA

MEDIUM
OpenFGA: OIDC audience validation skipped when –authn-oidc-audience is unset
GHSA-hcxc-wf8j-23hv
pkg: github.com/openfga/openfga
eco: go
published: Jun 19, 2026
## Description

OpenFGA's OIDC authenticator skipped JWT audience (`aud`) validation when no audience was configured.
In deployments where one identity provider issues tokens for multiple services,
a token minted for an unrelated service could authenticate to OpenFGA.

## Preconditions

This applies…

CVE-2026-55689
GitHub-GHSA

MEDIUM
Microsoft Security Advisory CVE-2026-45491 – .NET Tampering Vulnerability
GHSA-7q4v-2mr6-5gpx
pkg: Microsoft.NETCore.App.Runtime.linux-x64, Microsoft.NETCore.App.Runtime.linux-x64, Microsoft.NETCore.App.Runtime.linux-x64
eco: nuget
published: Jun 16, 2026
## Executive Summary

Microsoft is releasing this security advisory to provide information about a vulnerability in System.Formats.Tar. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A tampering vulnerability exists in the `…

CVE-2026-45491
GitHub-GHSA

MEDIUM
OpenClaw: macOS Swift exec allowlist missed combined POSIX inline flags
GHSA-c226-q6fx-6j6c
pkg: openclaw
eco: npm
published: Jun 18, 2026
### Summary

macOS Swift exec allowlist missed combined POSIX inline flags. In affected versions, a command request using combined POSIX inline-command flags could miss inline-command content expressed through combined flags.

This advisory is scoped to the named feature and configuration. It does n…

CVE-2026-53861
GitHub-GHSA

MEDIUM
SurrealDB: Denial of Service via deep operator chains
GHSA-jv2j-mqmw-xvv5
pkg: surrealdb
eco: rust
published: Jun 19, 2026
An authenticated user could crash a SurrealDB server with a single query containing a long chain of operators.

Such a query — for example `RETURN 1 + 1 + 1 + …` with tens of thousands of terms — is parsed into an expression tree one level deep per operator. Because the chain is flat and the p…

GitHub-GHSA

MEDIUM
Anki: User scripts in iframes have access to the internal Anki API
GHSA-cw6h-ffmh-x6vh
pkg: aqt
eco: pip
published: Jun 19, 2026
## Summary

Anki's webview-based pages communicate with the Rust backend using an internal localhost API. Anki implements measures to prevent user scripts run in the reviewer/editor from accessing this API (https://github.com/ankitects/anki/pull/3925) but it inadvertently allows access to scripts in…

GitHub-GHSA

MEDIUM
Network-AI: AgentRuntime sandbox path-prefix checks allow file access outside the configured base directory
GHSA-jvcm-f35g-w78p
pkg: network-ai
eco: npm
published: Jun 19, 2026
### Summary
`AgentRuntime` promises scoped file access under a configured sandbox `basePath`, but its path containment checks use raw string prefix tests. A sandbox base such as `/tmp/network-ai-sandbox` also matches a sibling path such as `/tmp/network-ai-sandbox_evil/secret.txt`.

An agent/user th…

GitHub-GHSA

MEDIUM
OpenBao: Transit secrets engine crashes on key creation with `derived: true` for asymmetric key types
GHSA-8w8f-r2xv-4q4j
pkg: github.com/openbao/openbao, github.com/openbao/openbao
eco: go
published: Jun 19, 2026
On OpenBao 2.5.4 and 2.5.2(and likely earlier versions also), an authenticated caller with write access to `transit/keys/*` can crash the OpenBao server by issuing a single key-creation request that combines an asymmetric `type` (`rsa-*`, `ecdsa-*`, `ed25519`)
with `derived: true`. The server return…
CVE-2026-55776
GitHub-GHSA

MEDIUM
UltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson.dumps()
GHSA-3j69-69wj-xqx2
pkg: ujson
eco: pip
published: Jun 19, 2026
### Summary
`ujson.dumps()` (or `ujson.dump()` or `ujson.encode()`) have a `reject_bytes=False` option. When set, they may accept malformed or truncated UTF-8 byte sequences, silently rewriting them into different Unicode characters instead of rejecting them. This leads to input validation bypass an…
CVE-2026-54911
GitHub-GHSA

MEDIUM
CoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe instance
GHSA-6jj2-4q5c-x8g6
pkg: CoreWCF.NetNamedPipe, CoreWCF.NetNamedPipe
eco: nuget
published: Jun 19, 2026
### Impact
CoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe instance, allowing local interception of NetNamedPipe traffic. NetNamedPipe creates a shared memory object based on the listening url, then generated a unique GUID for the named pipe it will be using and saves this…
CVE-2026-54777
GitHub-GHSA

MEDIUM
CoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record), causing persistent endpoint denial of service.
GHSA-m744-jhq9-ppw6
pkg: CoreWCF.Kafka, CoreWCF.Kafka
eco: nuget
published: Jun 19, 2026
### Impact
A CoreWCF service is running and listening on a Kafka topic receiving a null-value record will stop processing new records from that topic.

#### Preconditions
The attacker has produce/write permission on a topic that CoreWCF is consuming from. If the broker permits anonymous publishes, n…

CVE-2026-54775
GitHub-GHSA

MEDIUM
OpenClaw: memory-wiki shared search could miss session visibility checks
GHSA-72fw-cqh5-f324
pkg: openclaw
eco: npm
published: Jun 18, 2026
### Summary

memory-wiki shared search could miss session visibility checks. In affected versions, a caller able to search shared memory could skip the session visibility guard on the affected search path.

This advisory is scoped to the named feature and configuration. It does not change OpenClaw's…

CVE-2026-53844
GitHub-GHSA

MEDIUM
OpenClaw: Hostname checks could treat trailing-dot hosts inconsistently
GHSA-gxg4-2rrr-jhc7
pkg: openclaw
eco: npm
published: Jun 18, 2026
### Summary

Hostname checks could treat trailing-dot hosts inconsistently. In affected versions, a request path that accepts model- or workspace-derived URLs could present the same hostname with a trailing dot and avoid a blocklist comparison.

This advisory is scoped to the named feature and confi…

CVE-2026-53859
GitHub-GHSA

MEDIUM
NL Portal Backend Libraries: Document contents remained downloadable by any logged-in user (incomplete fix of CVE-2026-49463)
GHSA-jr45-52cw-69h5
pkg: nl.nl-portal:documenten-api
eco: maven
published: Jun 18, 2026
## Summary

A previous advisory (CVE-2026-49463 / GHSA-qpm9-h556-mwxm) reported that any logged-in user could download any document by its identifier, and stated this was fixed in 3.0.1. For the document-content part that fix was **incomplete**: documents remained downloadable by any authenticated u…

CVE-2026-54683
GitHub-GHSA

MEDIUM
BBOT: Arbitrary File Write in postman_download Module
GHSA-m54h-vhf9-3w3m
pkg: bbot
eco: pip
published: Jun 18, 2026
The `postman_download` module uses the workspace `name` field from the Postman API to construct the local directory path without sanitization. If a malicious workspace has a name containing path traversal characters, pathlib resolves the path outside the intended output directory, allowing an attack…
CVE-2026-12568
GitHub-GHSA

MEDIUM
PraisonAI: execute_code sandbox bypass: str.format C-level attribute access reads every blocklisted dunder
GHSA-pv2j-rghr-v5r9
pkg: praisonaiagents
eco: pip
published: Jun 18, 2026
## Summary

The `execute_code` tool's subprocess sandbox advertises a three-layer defense (AST validation, text-pattern blocklist, restricted `__builtins__`). In **sandbox mode** (the default) only two layers are active — the text-pattern blocklist is skipped — and both remaining layers are bypa…

GitHub-GHSA

MEDIUM
PraisonAI: SpiderTools redirect-target SSRF protection bypass
GHSA-6h9p-93hq-q7h6
pkg: praisonaiagents
eco: pip
published: Jun 18, 2026
# SpiderTools redirect-target SSRF protection bypass

## Summary

`SpiderTools.scrape_page()` validates the initial URL and rejects direct
loopback, private, link-local, metadata, and internal hostnames. It then calls
`requests.Session.get()` without disabling automatic redirects or validating
redir…

GitHub-GHSA

MEDIUM
Apache DolphinScheduler: An incorrect authorization vulnerability allows authenticated users to access alert instances associated with alert groups they do not have permission to access.
GHSA-694g-j8pj-cjj5
pkg: org.apache.dolphinscheduler:dolphinscheduler-api
eco: maven
published: Jun 17, 2026
Allow authenticated users to access alert instances associated with alert groups they do not have permission to access. in Apache DolphinScheduler.

This issue affects Apache DolphinScheduler: before 3.4.2.

Users are recommended to upgrade to version 3.4.2, which fixes the issue.

CVE-2026-47340
GitHub-GHSA

MEDIUM
Apache DolphinScheduler: Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access.
GHSA-wv7f-c794-82v6
pkg: org.apache.dolphinscheduler:dolphinscheduler-api
eco: maven
published: Jun 17, 2026
Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access.

This issue affects Apache DolphinScheduler versions prior to 3.4.2.

Users are recommended to upgrade to version 3.4.2, which fixes this issue.

CVE-2026-42357
GitHub-GHSA

MEDIUM
Daytona: Cross-tenant data leak in notification WebSocket gateway via unverified organizationId join
GHSA-qwxf-2m7m-2m3x
pkg: github.com/daytonaio/daytona
eco: go
published: Jun 17, 2026
### Summary
A cross-tenant authorization flaw in Daytona's notification WebSocket gateway allowed any authenticated user to subscribe to another organization's realtime notification channel and passively receive that organization's events.

### Impact
The notification gateway's JWT handshake joined …

CVE-2026-54324
GitHub-GHSA

MEDIUM
Deno: Node TCPWrap numeric hostname aliases bypass –deny-net resolved-IP deny checks
GHSA-v8fw-85r8-5m23
pkg: deno
eco: rust
published: Jun 16, 2026
## Summary

Deno's network permission model is designed so that `–deny-net` rules apply to the **resolved IP address** of a destination, not just the literal string supplied by the caller. That means `–deny-net=127.0.0.1` (or `–deny-net=127.0.0.0/8`) is expected to block any attempt to reach loop…

CVE-2026-49411
GitHub-GHSA

MEDIUM
Allure Report: Path Traversal in HTTP Server Allows Arbitrary File Read
GHSA-82cg-3hv7-74gc
pkg: io.qameta.allure:allure-commandline
eco: maven
published: Jun 19, 2026
## Summary

The built-in HTTP server started by `allure serve` and `allure open` is vulnerable to path traversal. The server resolves request URI paths directly against the report directory without normalizing or validating that the resolved path stays within the report directory. An attacker who ca…

CVE-2026-55846
GitHub-GHSA

MEDIUM
CoreWCF: UnixDomainSocket Non-Reentrant POSIX Identity Resolution
GHSA-q6v9-43v5-jv9q
pkg: CoreWCF.UnixDomainSocket, CoreWCF.UnixDomainSocket
eco: nuget
published: Jun 19, 2026
### Impact
Race condition in POSIX peer identity resolution may attribute one connection’s identity to another (getpwuid/getgrgid non-reentrant) and may crash the host process under contention.

### Patches
Fixed in CoreWCF v1.8.1 and v1.9.1

### Workarounds
Restrict UDS filesystem permissions so …

CVE-2026-54778
GitHub-GHSA

MEDIUM
Network-AI: EnvironmentManager.restore() backup ID path traversal copies arbitrary directories into environment data
GHSA-48×2-6pr9-2jjf
pkg: network-ai
eco: npm
published: Jun 19, 2026
### Summary
`EnvironmentManager.restore(env, backupId)` computes the backup path with `join(envDir, '.backups', backupId)` and only checks that this path exists. It does not resolve the result or verify that it remains under `data/<env>/.backups`.

A caller can pass a traversal backup ID such as `..…

GitHub-GHSA

MEDIUM
Langflow: Logout button does not clear session
GHSA-7hw8-6q6r-4276
pkg: langflow
eco: pip
published: Jun 19, 2026
### Summary
The logout button does not clear the session. The previous user stays logged in unless another user explicitly logs in.

### Details
Not in auto login mode. Hosted on localhost. `access_token_lf` remains present in both Local Storage and Cookies. `refresh_token_lf` remains present in Coo…

CVE-2026-55423
GitHub-GHSA

MEDIUM
Allure Report: Stored XSS via unescaped ANSI helper in status message/trace rendering
GHSA-gx93-m64w-5m6h
pkg: io.qameta.allure:allure-generator
eco: maven
published: Jun 19, 2026
## Summary

The `ansi.js` Handlebars helper in allure-generator passes user-controlled `statusMessage` and `statusTrace` values from test result files through the `ansi-to-html` library and wraps the output in Handlebars `SafeString` without HTML escaping. Since `ansi-to-html` does not escape HTML e…

CVE-2026-55847
GitHub-GHSA

MEDIUM
tract: Arbitrary file read via unsanitized ONNX external_data `location` (path traversal) on model load in tract-onnx
GHSA-h668-6x6g-f8r5
pkg: tract-onnx, tract-onnx, tract-onnx
eco: rust
published: Jun 19, 2026
### Summary

`tract` (the `tract-onnx` crate) resolves an ONNX tensor's external-data `location` by joining it onto the model directory **without any sanitization**. Because `location` comes from the (untrusted) `.onnx` file, a malicious model can make `tract` open and read an **arbitrary local file…

CVE-2026-55832
GitHub-GHSA

MEDIUM
OpenClaw: Exported session HTML could keep unsafe markdown links
GHSA-w9hf-3pp7-pvxv
pkg: openclaw
eco: npm
published: Jun 18, 2026
### Summary

Exported session HTML could keep unsafe markdown links. In affected versions, content rendered into an exported session could preserve unsafe `javascript:` or `data:` links in generated HTML.

This advisory is scoped to the named feature and configuration. It does not change OpenClaw's …

CVE-2026-53841
GitHub-GHSA

MEDIUM
tract-nnef: integer overflow in NNEF `.dat` tensor parser yields an out-of-bounds read on model load
GHSA-x5mv-8wgw-29hg
pkg: tract-nnef, tract-nnef, tract-nnef
eco: rust
published: Jun 18, 2026
– **Component:** `tract-nnef` (`nnef/src/tensors.rs::read_tensor`) + `tract-data` (`data/src/tensor.rs`)
– **Affected versions:** `< 0.21.16`, `0.22.0`–`0.22.2`, `0.23.0`–`0.23.1` — the dense `DatLoader` path was unguarded across all three release lines; patched in 0.21.16 / 0.22.2 / 0.23.1
– …
CVE-2026-55093
GitHub-GHSA

MEDIUM
marimo contains a reflected cross-site scripting vulnerability in the notebook page
GHSA-8m59-7xv8-735h
pkg: marimo
eco: pip
published: Jun 18, 2026
marimo before 0.23.9 contains a reflected cross-site scripting vulnerability in the notebook page that allows unauthenticated attackers to inject arbitrary JavaScript by exploiting improper escaping of single quotes in the file query parameter reflected into an inline JavaScript string literal. Atta…
CVE-2026-54386
GitHub-GHSA

MEDIUM
OpenStack Horizon RC file generation does not escape special characters in project names
GHSA-6wrm-x65g-hr4p
pkg: horizon
eco: pip
published: Jun 17, 2026
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability.
CVE-2026-55748
GitHub-GHSA

MEDIUM
Zeep: Server-Side Request Forgery (SSRF)
GHSA-4cc2-g9w2-fhf6
pkg: zeep
eco: pip
published: Jun 19, 2026
## Summary

When parsing a WSDL or XSD document, python-zeep follows transitive references — xsd:import, xsd:include, wsdl:import, and lxml entity/DTD resolution — and will fetch http/https URLs found in those references. The Settings.forbid_external option, intended to disable this transitive r…

GitHub-GHSA

MEDIUM
Network-AI: ApprovalInbox HTTP server has no authentication — anyone can approve pending agent actions
GHSA-mxjx-28vx-xjjj
pkg: network-ai
eco: npm
published: Jun 19, 2026
## Summary

`network-ai`'s `ApprovalInbox` (`lib/approval-inbox.ts`) is a shipped, exported, documented feature — *"a web-accessible approval queue with REST API … and SSE streaming"* (SECURITY.md). It is the network surface of the **human-in-the-loop Approval Gate**, which `ApprovalGate` uses t…

GitHub-GHSA

MEDIUM
CoreWCF: SAML token replay protection is inoperative
GHSA-9jr3-rj99-8jq3
pkg: CoreWCF.Primitives, CoreWCF.Primitives
eco: nuget
published: Jun 19, 2026
### Impact
When enabling DetectReplayedTokens, a token can be replayed and will be detected despite it being reused.

### Patches
Fixed in CoreWCF v1.8.1 and v1.9.1

### Workarounds
Provide your own implementation of `ITokenReplayCache` with the correct behavior.

CVE-2026-54779
GitHub-GHSA

MEDIUM
CoreWCF: WS-Security signature substitution via document-wide Signature lookup
GHSA-jc6x-rj79-w4mx
pkg: CoreWCF.Primitives, CoreWCF.Primitives
eco: nuget
published: Jun 19, 2026
### Impact
An unauthenticated remote attacker who can place a SOAP header lexically before `wsse:Security` can embed a `ds:Signature` of their choosing inside that header and cause the server to verify the attacker-supplied signature instead of the one carried in the security header.

#### Precondit…

CVE-2026-54773
GitHub-GHSA

MEDIUM
TypeORM: SQL Injection in UpdateQueryBuilder/SoftDeleteQueryBuilder orderBy (MySQL/MariaDB)
GHSA-9ggv-8w38-r7pm
pkg: typeorm
eco: npm
published: Jun 19, 2026
### Impact

Blind SQL injection vulnerability in `UpdateQueryBuilder` and `SoftDeleteQueryBuilder` affecting MySQL and MariaDB users.

`UpdateQueryBuilder` and `SoftDeleteQueryBuilder` (including their `addOrderBy` variants) do not validate the `order` parameter against an allowlist of permitted val…

GitHub-GHSA

MEDIUM
undici vulnerable to HTTP header injection via Set-Cookie percent-decoding
GHSA-p88m-4jfj-68fv
pkg: undici, undici, undici
eco: npm
published: Jun 19, 2026
## Impact

undici's cookie parser in `parseSetCookie` percent-decodes cookie values via `qsUnescape`, turning encoded sequences like `%0D%0A`, `%00`, `%3B`, and `%3D` into their literal byte equivalents. RFC 6265 §5.4 does not specify any decoding and browsers do not decode either.

Applications th…

CVE-2026-9679
GitHub-GHSA

MEDIUM
undici vulnerable to cross-user information disclosure via shared cache whitespace bypass
GHSA-pr7r-676h-xcf6
pkg: undici, undici
eco: npm
published: Jun 18, 2026
## Impact

Undici's cache interceptor incorrectly classifies some responses as cacheable when the upstream `Cache-Control` header uses whitespace-padded qualified `private` or `no-cache` field names such as `private=" authorization"` or `no-cache="\tauthorization"`. The parser preserves the surround…

CVE-2026-9678
GitHub-GHSA

MEDIUM
Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms
GHSA-w4mc-hhc6-xp28
pkg: github.com/axllent/mailpit
eco: go
published: Jun 19, 2026
## Summary

The remediation shipped in mailpit v1.29.2 for [GHSA-mpf7-p9x7-96r3](https://github.com/axllent/mailpit/security/advisories/GHSA-mpf7-p9x7-96r3) (CVE-2026-27808) is incomplete. The `tools.IsInternalIP` deny-list relies on Go's stdlib classification helpers (`IsLoopback`, `IsPrivate`, `Is…

CVE-2026-55187
GitHub-GHSA

MEDIUM
Signal K Server: Server-Side Request Forgery via Remote Connection Endpoints
GHSA-q59x-jc9f-gfqf
pkg: signalk-server
eco: npm
published: Jun 18, 2026
### Summary
signalk-server versions up to and including 2.27.0 contain a Server-Side Request Forgery (SSRF) vulnerability in three administrative endpoints used for remote Signal K server connection management. The `makeRemoteRequest()` function accepts attacker-controlled `host`, `port`, `useTLS`, …
CVE-2026-55591
GitHub-GHSA

MEDIUM
Capsule: Incomplete fix of CVE-2026-30963: singular/plural typo leaves namespaces/finalize unprotected
GHSA-gwxr-7h77-7777
pkg: github.com/projectcapsule/capsule
eco: go
published: Jun 17, 2026
### Summary
Capsule v0.13.2 webhook rules contain `namespace/finalize` (singular) instead of `namespaces/finalize` (plural). K8s requires plural. The finalize defense from CVE-2026-30963 fix is absent.

### Details
PUT to `/api/v1/namespaces/<ns>/finalize` has resource=namespaces (plural). The singu…

CVE-2026-55636
GitHub-GHSA

MEDIUM
Cloudflare Quiche: Use-after-free in connection ID iterator FFI functions
GHSA-mh64-ph39-mrc9
pkg: quiche
eco: rust
published: Jun 19, 2026
### Impact

Cloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions.

The `quiche_connection_id_iter_next` and `quiche_conn_retired_scid_next` functions would return a pointer to a `ConnectionId` to the applications via function arguments, but t…

CVE-2026-11941
GitHub-GHSA

MEDIUM
ChatterBot: Symlink-Following Arbitrary Write via UbuntuCorpusTrainer
GHSA-wvrh-2f4m-924v
pkg: ChatterBot
eco: pip
published: Jun 19, 2026
## Summary

ChatterBot's `UbuntuCorpusTrainer.extract()` uses a predictable, home-rooted output directory (`~/ubuntu_data/ubuntu_dialogs`) with a check-then-create pattern (`if not os.path.exists: os.makedirs`) followed by `tar.extractall(path=self.data_path)`. A local attacker who pre-plants a syml…

GitHub-GHSA

MEDIUM
Network-AI: EnvironmentManager.backup() follows symlinked directories and copies files outside the environment root into backups
GHSA-6x2m-p4xp-wg22
pkg: network-ai
eco: npm
published: Jun 19, 2026
### Summary
`EnvironmentManager.backup()` recursively collects files using `_collectBackupFiles()`. `_collectBackupFiles()` uses `statSync(full)`, which follows symlinks. If `data/<env>` contains a symlink to a directory outside the environment root, backup recursion follows the symlink and copies e…
GitHub-GHSA

MEDIUM
Duplicate Advisory: PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands
GHSA-x44p-gg67-52fc
pkg: praisonai
eco: pip
published: Jun 19, 2026
## Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-ffp3-3562-8cv3. This link is maintained to preserve external references.

## Original Description
PraisonAI before 1.5.128 caches tool approval decisions by tool name only, not by invocation arguments, allowin…

GitHub-GHSA

MEDIUM
OpenClaw: Config recovery could restore openclaw.json with broad file permissions
GHSA-rwp6-7w3q-75fq
pkg: openclaw
eco: npm
published: Jun 18, 2026
### Summary

Config recovery could restore openclaw.json with broad file permissions. In affected versions, a local recovery path after configuration repair could leave the restored config file more readable than intended.

This advisory is scoped to the named feature and configuration. It does not …

CVE-2026-53856
GitHub-GHSA

MEDIUM
Hermes Agent creates response_store.db and webhook_subscriptions.json with world-readable permissions (mode 0o644)
GHSA-99f9-j8r3-p853
pkg: hermes-agent
eco: pip
published: Jun 17, 2026
Hermes Agent before 0.16.0 creates response_store.db and webhook_subscriptions.json with world-readable permissions (mode 0o644), exposing conversation history and HMAC secrets to local users. Attackers with local filesystem access can read these files directly to obtain sensitive data including con…
CVE-2026-53870
GitHub-GHSA

MEDIUM
Deno: BYONM module resolution allows `package.json` main path traversal to bypass `–allow-read` restrictions
GHSA-968w-xfqw-vp9q
pkg: deno
eco: rust
published: Jun 16, 2026
## Summary

When Deno was run in BYONM mode (`nodeModulesDir: "manual"`), the module resolver did not validate that a package's resolved entrypoint stayed within its `node_modules/<pkg>/` directory. A malicious `package.json` whose `main` field contained `..` segments was able to resolve to an arbit…

CVE-2026-49406
GitHub-GHSA

MEDIUM
Strimzi: Unrestricted access to all Secrets within namespace watched by the Topic operator
GHSA-r427-j2h7-wv3m
pkg: io.strimzi:strimzi
eco: maven
published: Jun 18, 2026
### Impact

When only the Topic or only the User operators are deployed as part of the Entity Operator in the `Kafka` custom resource, the RBAC rights are not following the principle of least-privilege and the Entity Operator ServiceAccount still has access rights corresponding to both operators. Th…

CVE-2026-55226
GitHub-GHSA

MEDIUM
pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size
GHSA-4xgf-cpjx-pc3j
pkg: pydantic-settings
eco: pip
published: Jun 19, 2026
### Summary

`NestedSecretsSettingsSource` reads secret values from files in a configured `secrets_dir`. When `secrets_nested_subdir=True`, a directory entry inside `secrets_dir` that is a symbolic link pointing **outside** `secrets_dir` is followed, so files outside the configured directory are rea…

GitHub-GHSA

MEDIUM
Oj: intern.c form_attr (uninitialized stack read)
GHSA-fm7p-mprw-wjm9
pkg: oj
eco: rubygems
published: Jun 19, 2026
### Summary

`Oj.load` in `:object` mode reads uninitialized stack memory (and, for long
keys, reads out of bounds) when parsing a JSON object whose key is 254 bytes
or longer. The interned bytes can surface to the caller, disclosing process
stack memory.

### Details

In `ext/oj/intern.c`, `form_at…

CVE-2026-54500
GitHub-GHSA

MEDIUM
DotVVM: Unrestricted file upload
GHSA-2rm3-333w-xvc4
pkg: DotVVM, DotVVM, DotVVM
eco: nuget
published: Jun 19, 2026
### Impact

All users of DotVVM with configured file upload storage are affected.

DotVVM allows anyone to upload files to the application, potentially causing denial of service by filling the disk.

### Patches

Since version 4.3.15, 4.2.11 and 5.0.0-preview09, DotVVM requires all file upload requ…

GitHub-GHSA

MEDIUM
NL Portal Backend Libraries: Unauthenticated form resolver forwards the privileged Objecten-API token to a caller-supplied URL (SSRF)
GHSA-xm3x-9cfw-jhx4
pkg: nl.nl-portal:form
eco: maven
published: Jun 19, 2026
## Summary

The public GraphQL resolvers `getFormDefinitionByObjectenApiUrl(url)` and the deprecated `getFormDefinitionById(id)` fetch a caller-supplied URL using the **privileged Objecten-API token**. Because the `/graphql` endpoint is `permitAll()` and these resolvers do not declare a `CommonGroun…

CVE-2026-55414
GitHub-GHSA

MEDIUM
ts-deepmerge: Prototype Method Override leads to DoS
GHSA-87mf-gv2c-c62c
pkg: ts-deepmerge
eco: npm
published: Jun 19, 2026
Versions of the package ts-deepmerge before 8.0.0 are vulnerable to Uncaught Exception due to the improper handling of built-in Object.prototype methods (such as toString, valueOf). When user-controlled input contains these keys with non-function values, the resulting merged object becomes broken ��…
CVE-2026-12644
GitHub-GHSA

MEDIUM
OpenClaw: Slack reaction events could ignore reaction notification settings
GHSA-fcvx-5cxc-v5p8
pkg: openclaw
eco: npm
published: Jun 18, 2026
### Summary

Slack reaction events could ignore reaction notification settings. In affected versions, a Slack reaction event delivered to the configured app could enter the agent pipeline even when reaction notifications were disabled.

This advisory is scoped to the named feature and configuration.…

CVE-2026-53851
GitHub-GHSA

MEDIUM
opentelemetry-collector-contrib sentryexporter: Path traversal in Sentry exporter via attacker-controlled service.name reaches privileged Sentry API endpoints with operator bearer token
GHSA-4jvg-4jfx-fmhc
pkg: github.com/open-telemetry/opentelemetry-collector-contrib/exporter/sentryexporter
eco: go
published: Jun 18, 2026
Summary

The Sentry exporter constructs Sentry API URLs by interpolating the span's service.name resource attribute into the URL path without validation. Because
service.name is controlled by remote OTLP senders and the operator-configured bearer token is attached to ever…

CVE-2026-47256
GitHub-GHSA

MEDIUM
BBOT: Path traversal (Zip-Slip) in unarchive module – incomplete fix for CVE-2025-10284
GHSA-3vgw-585j-4m45
pkg: bbot
eco: pip
published: Jun 18, 2026
The `unarchive` internal module's archive extraction commands perform no code-level validation on extracted file paths, relying entirely on the behavior of external tools (e.g. GNU tar) which varies by platform. While CVE-2025-10284 addressed git-specific RCE vectors, the underlying archive extracti…
CVE-2026-12565
GitHub-GHSA

MEDIUM
Podman: WORKDIR symlink traversal vulnerability
GHSA-q6r4-3wmg-fwcq
pkg: github.com/containers/podman/v5, github.com/containers/podman/v4, github.com/containers/podman/v3
eco: go
published: Jun 18, 2026
### Summary

Running a malicous container image where the WORKDIR path contains a symlink can create a directory or modify ownership on the host filesystem. Modified ownership is less likely to happen as that requires help from an untrusted/malicious process that mutates the host filesystem tree dur…

CVE-2026-55686
GitHub-GHSA

MEDIUM
webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies
GHSA-mx8g-39q3-5c79
pkg: webpack-dev-server
eco: npm
published: Jun 17, 2026
### Impact

When a user-configured proxy on `webpack-dev-server` has a broad context (e.g. `/`) and `ws: true`, it also intercepts the dev server's own HMR WebSocket and forwards it to the proxy target. This leaks the browser's cookies and `Origin` header to the backend, bypasses the dev server's Ho…

CVE-2026-9595
GitHub-GHSA

MEDIUM
Multer vulnerable to Denial of Service via incomplete cleanup of aborted uploads
GHSA-3p4h-7m6x-2hcm
pkg: multer, multer
eco: npm
published: Jun 17, 2026
### Impact

A vulnerability in Multer allows an attacker to trigger a Denial of Service (DoS) by aborting or sending malformed multipart uploads, causing orphaned partial files to accumulate on disk when using diskStorage.

### Patches

Users should upgrade to `2.2.0`, `3.0.0-alpha.2` or higher

###…

CVE-2026-5038
GitHub-GHSA

MEDIUM
Netty susceptible to HTTP/2 Reset Attack with different on-the-wire signature
GHSA-563q-j3cm-6jxm
pkg: io.netty:netty-codec-http2, io.netty:netty-codec-http2
eco: maven
published: Jun 15, 2026
### Summary

Netty HTTP/2 max header size handling produces attack similar to HTTP/2 Rapid Reset.

### Details

There is a setting in the http2 specification called `SETTINGS_MAX_HEADER_LIST_SIZE`. According to[ the RFC](https://www.rfc-editor.org/rfc/rfc9113.html#name-defined-settings): “This adv…

CVE-2026-50560
GitHub-GHSA

MEDIUM
Netty: HttpObjectDecoder skips arbitrary initial control characters when only initial CRLF characters are permitted
GHSA-hvcg-qmg6-jm4c
pkg: io.netty:netty-codec-http, io.netty:netty-codec-http
eco: maven
published: Jun 15, 2026
## Summary

Before reading the first request-line, `HttpObjectDecoder` skips every byte for which
`Character.isISOControl(b)` is `true` (0x00–0x1F and 0x7F) as well as all whitespace.
RFC 9112 §2.2 only asks servers to ignore **empty CRLF lines** preceding the request-line —
a carefully scoped …

CVE-2026-50020
GitHub-GHSA

MEDIUM
Deno: Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)
GHSA-8xpq-cjcf-3wh9
pkg: deno
eco: rust
published: Jun 16, 2026
## Summary

Deno's permission system enforces filesystem and execution restrictions by
comparing the requested path against the path supplied to `–deny-read`,
`–deny-write`, `–deny-run`, or `–deny-ffi`. On macOS, that comparison was
done at the raw-byte level while the APFS filesystem treats dif…

CVE-2026-49401
GitHub-GHSA

MEDIUM
Deno: process.loadEnvFile() bypasses env permission checks and mutates process.env with only read access
GHSA-4c8g-jvcx-v4hv
pkg: deno
eco: rust
published: Jun 16, 2026
## Summary

In Deno, environment access is gated by the `env` permission. You can deny it
with `–deny-env`, or restrict it to a specific allowlist with
`–allow-env=FOO,BAR`. The expectation is that a program running without `env`
permission cannot change `process.env`.

`process.loadEnvFile()` (th…

CVE-2026-49983
GitHub-GHSA

MEDIUM
Deno: WebSocket API sandbox bypass via missing post-DNS check
GHSA-83pc-3rw9-qpwj
pkg: deno
eco: rust
published: Jun 16, 2026
## Summary

When a WebSocket connection was opened, Deno checked the destination hostname
against `–deny-net` rules but did not re-check the IP addresses that hostname
resolved to. An attacker-controlled script could use a specially crafted domain
name that passes the hostname check yet resolves to…

CVE-2026-49860
GitHub-GHSA

MEDIUM
Deno: `fetch()` API sandbox bypass via missing DNS resolution check
GHSA-cpgj-f7g3-2pp2
pkg: deno
eco: rust
published: Jun 16, 2026
## Summary

When `fetch()` was called, Deno checked the destination hostname against
`–deny-net` rules but did not re-check the IP addresses that hostname
resolved to. An attacker-controlled script could use a specially crafted domain
name that passes the hostname check yet resolves to a denied IP,…

CVE-2026-49859
GitHub-GHSA

MEDIUM
Apache DolphinScheduler: Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects
GHSA-wh3w-v6gj-fqh2
pkg: org.apache.dolphinscheduler:dolphinscheduler-api
eco: maven
published: Jun 17, 2026
Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects

This issue affects Apache DolphinScheduler versions prior to 3.4.2.

Users are recommended to upgrade to version 3.4.2, which fixes this issue.

CVE-2026-41280
GitHub-GHSA

MEDIUM
NCalc: Denial of Service via Unbounded and Non-Terminating Factorial Evaluation
GHSA-3w5p-95mh-gq75
pkg: NCalc.Core, NCalcSync
eco: nuget
published: Jun 18, 2026
### Impact

A denial-of-service (DoS) vulnerability exists in the factorial operator implementation of NCalc. Specially crafted expressions containing extremely large factorial operands can trigger excessive CPU consumption or cause evaluation to enter a non-terminating loop due to integer overflow …

CVE-2026-55254
GitHub-GHSA

MEDIUM
Netty: QUIC stateless reset token material exposed through header-visible connection IDs
GHSA-cq4q-cv5g-r8q5
pkg: io.netty:netty-codec-classes-quic
eco: maven
published: Jun 15, 2026
### Summary
Netty QUIC exposes the stateless reset token on the network path when using the default HMAC-based connection-ID and stateless-reset-token generators. The reset token for the server's current source connection ID can be derived from bytes that appear as the connection ID in QUIC headers …
CVE-2026-50009
GitHub-GHSA

MEDIUM
Outerbase Studio: Stored XSS in Text Widget Leads to Authentication Token Exposure
GHSA-wwf9-7jrc-rv4q
pkg: @outerbase/studio
eco: npm
published: Jun 19, 2026
## Summary

A Stored Cross-Site Scripting (XSS) issue previously existed in the Text Widget in Board of Outerbase Studio where unsanitized HTML could be rendered using `dangerouslySetInnerHTML`

### Steps to Reproduce

1. Create a new dashboard.
2. Add a **Text widget**.
3. Insert the following payl…

CVE-2026-55650
GitHub-GHSA

MEDIUM
CoreWCF: Unix Domain Socket PosixIdentity transport accepts connections that skip the security upgrade
GHSA-wjpq-6766-7f5j
pkg: CoreWCF.UnixDomainSocket, CoreWCF.UnixDomainSocket
eco: nuget
published: Jun 19, 2026
### Impact
A CoreWCF service hosted on Unix Domain Sockets with the PosixIdentity client credential type (UnixDomainSocketBinding with Security.Mode = TransportCredentialOnly and Security.Transport.ClientCredentialType = PosixIdentity) does not require the client to perform the application/unixposix…
CVE-2026-54776
GitHub-GHSA

MEDIUM
SurrealDB: Field-level SELECT permissions bypassed via graph and reference traversals
GHSA-hv6h-hc26-q48p
pkg: surrealdb
eco: rust
published: Jun 19, 2026
A record user could read field values hidden from them by field-level SELECT permissions by reaching the records through a graph-edge (`->`) or back-reference (`<~`) traversal instead of a direct `SELECT`.

When a table was readable at the table level but carried a field hidden by a field-level perm…

GitHub-GHSA

MEDIUM
SurrealDB: Indexed ORDER BY leaks the value ordering of a SELECT-restricted field
GHSA-h4h3-3rfj-x6fq
pkg: surrealdb
eco: rust
published: Jun 19, 2026
A field can be hidden from a user with a field-level SELECT permission (`DEFINE FIELD code ON secret PERMISSIONS FOR select WHERE owner = $auth.id`). When that field is indexed, a record user who cannot read it could still recover the relative ordering of its values across every record by issuing `O…
GitHub-GHSA

MEDIUM
praisonai-platform: Authorization Bypass Through User-Controlled Key
GHSA-2fjj-qqg8-fg7x
pkg: praisonai-platform
eco: pip
published: Jun 18, 2026
## Summary

The issue create and update endpoints in `praisonai-platform` accept a `project_id` in the request body and persist it without validating that the project belongs to the URL workspace. A user who is a member of workspace `W_B` (and has no access to workspace `W_A`) can create issues that…

GitHub-GHSA

MEDIUM
PraisonAI: Unauthenticated Event Injection via SSE `/publish` Endpoint
GHSA-35w5-pcw4-jx94
pkg: praisonaiagents
eco: pip
published: Jun 18, 2026
## Summary

The SSE (Server-Sent Events) server in `src/praisonai-agents/praisonaiagents/server/server.py` exposes a `/publish` endpoint that broadcasts arbitrary messages to all connected clients without any authentication. The `ServerConfig` dataclass (line 24) defines an `auth_token` field, but t…

GitHub-GHSA

MEDIUM
Deno: Denial of service via non-ASCII bytes in WebSocket response headers
GHSA-x2qc-cmh9-f4hf
pkg: deno
eco: rust
published: Jun 17, 2026
## Summary

A Deno program that opens a client `WebSocket` connection could be crashed by
the remote server. While handling the WebSocket handshake response, Deno parsed
the `Sec-WebSocket-Protocol` and `Sec-WebSocket-Extensions` response headers in
a way that assumed their bytes were always printab…

CVE-2026-55517
GitHub-GHSA

MEDIUM
katello: missing repository authorization in content_uploads exposes cross-product content existence
GHSA-c43c-rf7g-5xpg
pkg: katello
eco: rubygems
published: Jun 17, 2026
A flaw was found in Katello's of Red Hat Satellite. A content upload functionality where insufficient authorization checks in the ContentUploadsController allowed users with the edit_products permission to query content information for repositories outside the products they were authorized to manage…
CVE-2026-12515
GitHub-GHSA

MEDIUM
Gitea: Missing repository-unit authorization on issue-template API endpoints
GHSA-3fwp-p5rj-2pxf
pkg: code.gitea.io/gitea
eco: go
published: Jun 16, 2026
## Summary

Three Gitea API endpoints — `GET /repos/{owner}/{repo}/issue_templates`,
`GET /repos/{owner}/{repo}/issue_config` and `GET /repos/{owner}/{repo}/issue_config/validate`
— read files from the repository's **Code** default branch (`.gitea/ISSUE_TEMPLATE/*`
and `issue_config.yaml`) and r…

CVE-2026-27783
GitHub-GHSA

MEDIUM
Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw
GHSA-8629-vc8r-5p58
pkg: code.gitea.io/gitea
eco: go
published: Jun 16, 2026
## Summary

Two related issues in the token public-only scope enforcement introduced by PR #32204 (CVE-2025-68941 fix). A public-only scoped API token can access private organization data.

## Issue 1: /user/orgs missing checkTokenPublicOnly()

`routers/api/v1/api.go` line 1599:
“`go
m.Get("/user/o…

CVE-2026-25714
GitHub-GHSA

MEDIUM
Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escape
GHSA-fjv8-j4p5-cr9m
pkg: github.com/daytonaio/daytona
eco: go
published: Jun 18, 2026
## Summary
A sandbox volume reference (`volumeId`, which may also be a volume name) was forwarded to the
runner and used to build the host bind-mount source path without confinement. A reference
containing path-traversal sequences could in principle resolve the mount source outside the
intended per-…
CVE-2026-54319
GitHub-GHSA

MEDIUM
ZITADEL: Missing Token Audience Validation (`aud`) in JWT IdP Provider
GHSA-g5h5-m4hm-xjrr
pkg: github.com/zitadel/zitadel
eco: go
published: Jun 18, 2026
### Summary

An authentication bypass vulnerability was discovered in ZITADEL's external JWT Identity Provider (IdP) implementation.

When validating JSON Web Tokens (JWTs) from an external provider, ZITADEL properly checks the token's cryptographic signature and issuer (`iss`), but it fails to vali…

CVE-2026-55669
GitHub-GHSA

MEDIUM
ZITADEL: Missing Token Lifecyle Validation (`exp` and `iat`) in JWT IdP Provider
GHSA-wxg7-w2v3-w38g
pkg: github.com/zitadel/zitadel
eco: go
published: Jun 18, 2026
### Summary

Two closely related token lifecycle validation vulnerabilities were discovered in ZITADEL's external JWT Identity Provider (IdP) implementation.

Specifically, within the validation pipeline:

* **Missing Expiration (`exp`) Enforcement:** If an incoming JWT omits the `exp` claim entirel…

GitHub-GHSA

MEDIUM
Caddy: stripHTML template function bypass
GHSA-vcc4-2c75-vc9v
pkg: github.com/caddyserver/caddy/v2, github.com/caddyserver/caddy
eco: go
published: Jun 16, 2026
### Summary
Caddy’s `stripHTML` template function cannot reliably remove all HTML tags from input strings. Certain malformed HTML, such as `<<>img src=x onerror=alert()>`, can bypass the tag-stripping logic, potentially leaving dangerous content in the output if it is later rendered as HTML. This …
CVE-2026-52846
GitHub-GHSA

MEDIUM
SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch
GHSA-h5rg-8p7f-47g2
pkg: surrealdb
eco: rust
published: Jun 19, 2026
SurrealDB fetches the JWKS document for a JWT or record access method using a bare `reqwest` client that follows HTTP redirects by default. The network capability check in `core/src/iam/jwks.rs` (`check_capabilities_url`) is applied only to the originally configured URL; redirect targets are not re-…
GitHub-GHSA

MEDIUM
MCPVault: PathFilter restricted directories (.git/.obsidian/node_modules) only denied at vault root, not nested
GHSA-9c83-rr99-vfwj
pkg: @bitbonsai/mcpvault
eco: npm
published: Jun 19, 2026
PathFilter's deny-list glob patterns are anchored, so `.git`, `.obsidian`, and `node_modules` were only blocked at the vault root. Nested copies inside the vault (e.g. `tools/cli/node_modules/…`, `tools/somerepo/.git/config`, a nested `.obsidian/`) were fully traversable via isAllowed/isAllowedFor…
GitHub-GHSA

MEDIUM
py7zr: O(n^2) algorithmic complexity DoS in PackInfo._read()
GHSA-h4gh-22qq-72r7
pkg: py7zr
eco: pip
published: Jun 19, 2026
### Summary

PackInfo._read() uses an O(n^2) cumulative sum pattern where
numstreams is read directly from the archive header. A crafted .7z
archive with a large numstreams value causes excessive CPU consumption
during SevenZipFile.__init__() — no extraction is needed. A 50 KB
archive tak…

CVE-2026-55206
GitHub-GHSA

MEDIUM
py7zr: Decompression bomb (zip bomb) denial of service via unchecked extraction size
GHSA-gjrg-mpp7-g774
pkg: py7zr
eco: pip
published: Jun 19, 2026
py7zr's `Worker.decompress()` extracts archive entries without tracking total decompressed size. A crafted `.7z` file can exhaust disk or memory before the extraction completes.

Measured: 15.6 KB archive → 100 MB output (6,556:1 ratio).

**Proof of concept:**

“`python
import py7zr, tempfile, os…

CVE-2026-55195
GitHub-GHSA

MEDIUM
Open Redirect Bypass in miniflux-v2
GHSA-m999-j542-5w3r
pkg: miniflux.app/v2
eco: go
published: Jun 19, 2026
### Summary
The URL restrictions in `miniflux-v2` can be bypassed by attackers, leading to an open redirect vulnerability.

### Details

Normally, the redirect URL needs to be validated using `IsRelativePath`.

<img width="1728" height="1386" alt="QQ20260526-175356-26-1" src="https://github.com/user…

CVE-2026-55185
GitHub-GHSA

MEDIUM
http4k: `ServerFilters.DigestAuth` / `DigestAuthProvider` defaulted to an always-true nonce verifier, disabling replay protection in default deployments
GHSA-c7jm-38gq-h67h
pkg: org.http4k:http4k-security-digest, org.http4k:http4k-security-digest, org.http4k:http4k-security-digest
eco: maven
published: Jun 19, 2026
### Impact

`ServerFilters.DigestAuth` and the underlying `DigestAuthProvider` both defaulted their `nonceVerifier` parameter to `{ true }` — i.e. every nonce was accepted regardless of value, age, or prior use. Any deployment using the default configuration had **no replay protection** on Digest …

GitHub-GHSA

MEDIUM
http4k: BasicCookieStorage` (renamed `InsecureCookieStorage`) did not enforce RFC 6265 cookie scoping; new `DefaultCookieStorage` is now the default
GHSA-pr33-38xx-6r26
pkg: org.http4k:http4k-core, org.http4k:http4k-core, org.http4k:http4k-core
eco: maven
published: Jun 19, 2026
### Impact

The previous `BasicCookieStorage` did not enforce RFC 6265 scoping rules around cookie domain, path, and `Secure` attribute. A client using a single storage instance to talk to multiple origins could have cookies leak across domains, or have `Secure` cookies sent over plain HTTP — the …

GitHub-GHSA

MEDIUM
http4k: `reverseProxy()` defaulted to substring (`Contains`) matching on `Host`; tightened to `Exact`
GHSA-jrpc-7vxp-69p6
pkg: org.http4k:http4k-core, org.http4k:http4k-core, org.http4k:http4k-core
eco: maven
published: Jun 19, 2026
### Impact

`reverseProxy()` and `reverseProxyRouting()` matched configured vhosts by substring on the `Host` header (`Contains` matcher) by default. The intended use of these functions in http4k is **outbound dispatch** (e.g. matching AWS service subdomains, per the `Contains` docstring) and **test…

GitHub-GHSA

MEDIUM
Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails
GHSA-4mr2-fg2p-w63c
pkg: github.com/traefik/traefik/v3
eco: go
published: Jun 19, 2026
## Summary

There is a medium severity vulnerability in Traefik's Kubernetes Ingress NGINX provider that causes affected routes to fail open. When an Ingress explicitly enables BasicAuth or DigestAuth through the supported `nginx.ingress.kubernetes.io/auth-type` and `auth-secret` annotations, but th…

CVE-2026-54762
GitHub-GHSA

MEDIUM
go.qbee.io/transport: Symlink-chain path traversal in tar extraction (one level outside destination)
GHSA-f9m7-vc86-p6jj
pkg: go.qbee.io/transport
eco: go
published: Jun 19, 2026
### Impact

The go.qbee.io/transport library is affected by a symlink-chain path traversal vulnerability in its extractTar routine. The library's path validation is strictly lexical and fails to account for on-disk symlinks created earlier in the extraction process. Consequently, a crafted tar archi…

CVE-2026-55828
GitHub-GHSA

MEDIUM
Grafana Operator: Privilege escalation from namespace admin to cluster admin via GrafanaDashboard jsonnetLib fileName
GHSA-fcw4-wwqm-m8cf
pkg: github.com/grafana/grafana-operator/v5, github.com/grafana/grafana-operator
eco: go
published: Jun 19, 2026
We have released version 5.24.0 of the Grafana Operator. This patch includes a MODERATE severity security fix for a path traversal/privilege escalation vulnerability in the Grafana Operator.

### Summary

The Grafana Operator supports loading dashboards & library panels using the jsonnet data templ…

CVE-2026-11769
GitHub-GHSA

MEDIUM
Python Liquid: Infinite loop when parsing malformed `{% case %}` tags
GHSA-vq2f-vcc9-j8mv
pkg: python-liquid
eco: pip
published: Jun 19, 2026
### Impact
Given a malformed `{% case %}` tag without associated `{% when %}` or `{% else %}` block, and no terminating `{% endcase %}` tag, Python Liquid hangs in an infinite loop at parse time. This allows malicious template authors to craft templates for a denial of service attack.

### Patches
T…

CVE-2026-55865
GitHub-GHSA

MEDIUM
containerd: CRI checkpoint import allows local image tag poisoning
GHSA-cvxm-645q-p574
pkg: github.com/containerd/containerd/v2, github.com/containerd/containerd/v2, github.com/containerd/containerd/v2
eco: go
published: Jun 19, 2026
## Impact
containerd's CRI checkpoint import process contains a vulnerability where it fails to validate the image references specified within a checkpoint image's configuration. An attacker with permissions to create pods can use a crafted checkpoint image to force containerd to pull a malicious im…
CVE-2026-50195
GitHub-GHSA

MEDIUM
parse-server: Relation `$relatedTo` query bypasses `protectedFields` and owning-object ACL
GHSA-wmwx-jr2p-4j4r
pkg: parse-server, parse-server
eco: npm
published: Jun 19, 2026
### Impact

A relation query using the `$relatedTo` operator could read the membership of a `Relation` field even when that field was hidden from the requesting client by `protectedFields`, and even when the object owning the relation was not readable by the client under its ACL or class-level permi…

CVE-2026-53726
GitHub-GHSA

MEDIUM
parse-server: Endpoints `/login` and `/verifyPassword` disclose MFA secrets and protected fields when `_User` get is denied
GHSA-75v4-m273-5j49
pkg: parse-server
eco: npm
published: Jun 19, 2026
### Impact

Apps that enable MFA and deny `get` on the `_User` class via Class-Level Permissions could expose sensitive user data through the `/login` and `/verifyPassword` endpoints.

These endpoints re-fetch the user through the access-controlled query pipeline (CLP, `protectedFields`, auth-adapte…

CVE-2026-53725
GitHub-GHSA

MEDIUM
parse-server: Server option routeAllowList is bypassable through batch sub-requests
GHSA-p84r-h6rx-f2xr
pkg: parse-server
eco: npm
published: Jun 19, 2026
### Impact

The `routeAllowList` server option restricts external client access to a configured list of REST API routes. The check is only enforced as Express middleware against the outer HTTP request URL, so the `/batch` handler dispatches each sub-request to the internal router without re-running …

CVE-2026-50008
GitHub-GHSA

MEDIUM
containerd image-triggered runtime DoS via unbounded group parsing
GHSA-jpcc-p29g-p8mq
pkg: github.com/containerd/containerd/v2, github.com/containerd/containerd, github.com/containerd/containerd/v2
eco: go
published: Jun 19, 2026
### Impact
A vulnerability in containerd allows a maliciously crafted image to cause a Denial of Service (DoS) condition. When creating a container from this image, memory exhaustion occurs, leading to an Out Of Memory (OOM) kill of the containerd process. This renders the container runtime API unav…
CVE-2026-47262
GitHub-GHSA

MEDIUM
Hugo: Symlink confinement bypass in os.ReadFile
GHSA-c3wq-j5vh-68rc
pkg: github.com/gohugoio/hugo
eco: go
published: Jun 19, 2026
**Affected versions:** v0.123.0 through v0.163.0. Earlier versions are not affected.
**Fixed in:** v0.163.1.
**Severity:** Medium. Requires the attacker to be able to place (or convince a site author to place) a symlink inside a mounted directory — for example, inside a locally-vendored theme unde…
GitHub-GHSA

MEDIUM
Hugo: XSS via unescaped code-fence language in default code block renderer
GHSA-q76j-gcg9-vxc6
pkg: github.com/gohugoio/hugo
eco: go
published: Jun 19, 2026
Hugo's default code-block renderer wrote the Markdown code-fence language / info-string into the `<code class="language-…" data-lang="…">` wrapper without HTML escaping. A fence info-string containing a quote and a `<script>` payload breaks out of the attribute and injects a live script element.…
GitHub-GHSA

MEDIUM
Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`
GHSA-5prr-v3j2-97mh
pkg: nokogiri
eco: rubygems
published: Jun 19, 2026
### Summary

`Nokogiri::XML::NodeSet#[]` (and its alias `#slice`) checked the requested index against the node set's bounds using a 32-bit-truncated copy of the index. A large negative index could pass the check and then be used at full width, reading outside the node set's storage. On CRuby this is…

GitHub-GHSA

MEDIUM
JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol
GHSA-vmhf-c436-hxj4
pkg: jupyterlab
eco: pip
published: Jun 19, 2026
A malicious PyPI package can place a `javascript:` URL in its `[project.urls]` metadata. JupyterLab's Extension Manager renders this as the extension's home-page link without validating the protocol, so a user who clicks the extension name executes attacker-controlled JavaScript in the JupyterLab or…
GitHub-GHSA

MEDIUM
Entire CLI: Path traversal in checkpoint session metadata allows arbitrary file write during resume/rewind
GHSA-2h46-9x5w-4wf7
pkg: github.com/entireio/cli
eco: go
published: Jun 19, 2026
### Impact

A path traversal vulnerability in Entire CLI allows an attacker with push access to the checkpoints repository to craft malicious checkpoint metadata that causes `entire session resume` or `entire checkpoint rewind` to write attacker-controlled transcript data outside of the expected ses…

GitHub-GHSA

MEDIUM
Canonical MicroCeph: path traversal issue in the remote-import AP
GHSA-xg3j-c7q4-f9ph
pkg: github.com/canonical/microceph/microceph
eco: go
published: Jun 19, 2026
Canonical MicroCeph versions from the squid and tentacle track are vulnerable to a path traversal issue in the remote-import API. Holders of a trusted cluster mTLS certificate (such as enrolled cluster members) or join token can manipulate files in an imported remote cluster within the /var/snap/mic…
CVE-2026-10720
GitHub-GHSA

MEDIUM
OpenClaw: Internal/webchat command auth could inherit ownerAllowFrom wildcard state
GHSA-4hpg-mp64-x7xq
pkg: openclaw
eco: npm
published: Jun 18, 2026
### Summary

Internal/webchat command auth could inherit ownerAllowFrom wildcard state. In affected versions, a sender on an affected internal or webchat path could inherit wildcard ownerAllowFrom state across channel boundaries.

This advisory is scoped to the named feature and configuration. It do…

CVE-2026-53854
GitHub-GHSA

MEDIUM
OpenClaw: Focus command could miss controlScope enforcement
GHSA-mpc8-jxjh-qpgh
pkg: openclaw
eco: npm
published: Jun 18, 2026
### Summary

Focus command could miss controlScope enforcement. In affected versions, a caller able to trigger the focus command could run the command without enforcing the expected control scope.

This advisory is scoped to the named feature and configuration. It does not change OpenClaw's trusted-…

CVE-2026-53850
GitHub-GHSA

MEDIUM
OpenClaw: Active Memory write scope could mutate global config
GHSA-x629-46cc-7xgw
pkg: openclaw
eco: npm
published: Jun 18, 2026
### Summary

Active Memory write scope could mutate global config. In affected versions, a Gateway caller with `operator.write` access to the affected command could change global configuration without requiring `operator.admin`.

This advisory is scoped to the named feature and configuration. It doe…

CVE-2026-53847
GitHub-GHSA

MEDIUM
[Eclipse Theia] Data Exfiltration via Markdown Image Rendering in AI Chat
GHSA-qwjm-9c66-w4q4
pkg: @theia/ai-chat-ui, @theia/ai-chat, @theia/ai-claude-code
eco: npm
published: Jun 18, 2026
In Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown image tags from AI responses, triggering HTTP requests to arbitrary external URLs without restriction. Combined with prompt injection in a malicious workspace, an attacker could induce the AI agent to construct image URLs encod…
CVE-2026-22551
GitHub-GHSA

MEDIUM
Armeria: External Control of File Name or Path in xDS SDS DataSource
GHSA-hgw6-8c77-v4gq
pkg: com.linecorp.armeria:armeria-xds
eco: maven
published: Jun 18, 2026
## External Control of File Name or Path in xDS SDS DataSource

### Summary

`DataSourceStream` in the `:xds` module resolves control-plane-supplied `filename` and `environment_variable` fields from SDS Secret resources without any allow-list or base-directory confinement. A semi-trusted or compromi…

CVE-2026-11752
GitHub-GHSA

MEDIUM
opentelemetry-collector-contrib: githubreceiver silently ignores configured required_headers authentication
GHSA-w5cv-pw74-4rxc
pkg: github.com/open-telemetry/opentelemetry-collector-contrib/receiver/githubreceiver
eco: go
published: Jun 18, 2026
## githubreceiver Silently Ignores Configured required_headers Authentication

### Summary

The githubreceiver webhook handler does not enforce the `required_headers` configuration. Headers are validated at startup (config rejects empty keys/values) but never checked on incoming requests. This follo…

CVE-2026-55701
GitHub-GHSA

MEDIUM
MCPVault: PathFilter restricted-directory deny-list bypass via case and trailing dot/space equivalence
GHSA-j99q-93c9-h869
pkg: @bitbonsai/mcpvault
eco: npm
published: Jun 18, 2026
On case-insensitive filesystems (macOS, Windows), PathFilter compiled its deny-list patterns case-sensitively and matched the path verbatim, so names like `.Git/config`, `.GIT/config`, or `.oBsIdIaN/secrets.md` slipped past the `.git`/`.obsidian`/`node_modules` restriction while the OS opened the re…
GitHub-GHSA

MEDIUM
pypdf: Missing stream length values ignore defined limits
GHSA-jm82-fx9c-mx94
pkg: pypdf
eco: pip
published: Jun 18, 2026
### Impact

An attacker who uses this vulnerability can craft a PDF which leads to large memory usage, as `MAX_DECLARED_STREAM_LENGTH` is sometimes ignored. This requires parsing a content stream without a `/Length` value.

### Patches
This has been fixed in [pypdf==6.13.3](https://github.com/py-pdf…

GitHub-GHSA

MEDIUM
DOMPurify: Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch)
GHSA-cmwh-pvxp-8882
pkg: dompurify
eco: npm
published: Jun 18, 2026
## Summary

DOMPurify 3.4.7 shipped a security fix ("permanent hook pollution") that makes a registered `uponSanitizeAttribute` hook's mutation of `data.allowedAttributes` **non-persistent** — so allowing an attribute for one element does not leak into later `sanitize()` calls. The fix clones `ALL…

GitHub-GHSA

MEDIUM
TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes
GHSA-2vcc-5v34-9jc8
pkg: tinacms, @tinacms/mdx
eco: npm
published: Jun 18, 2026
TinaCMS rich-text parsing and the default link/image renderers did not sanitize the `url` field on Slate link/image nodes. Content containing `javascript:` or `data:text/html` URLs — including case-variant, whitespace-padded, and control-character-obfuscated forms — is rendered into `href`/`src`…
CVE-2026-55661
GitHub-GHSA

MEDIUM
Hydro: Insufficient session expiration when recreating sessions
GHSA-94jp-7776-qj6q
pkg: hydrooj
eco: npm
published: Jun 18, 2026
### Impact

Hydro contains an insufficient session expiration vulnerability in its session recreation logic. When a session is recreated, including during logout or other session renewal flows, Hydro creates a new session token but does not delete the previous server-side session token.

As a result…

CVE-2026-55617
GitHub-GHSA

MEDIUM
http-proxy-middleware `router` host+path substring matching allows Host-header-driven backend routing bypass
GHSA-64mm-vxmg-q3vj
pkg: http-proxy-middleware, http-proxy-middleware
eco: npm
published: Jun 18, 2026
# Summary

`http-proxy-middleware` documents `router` proxy-table entries as host, path, or host+path selectors, but the host+path implementation uses unanchored substring matching on attacker-controlled request metadata. As a result, a crafted `Host` header that is only a superstring match for a co…

CVE-2026-55602
GitHub-GHSA

MEDIUM
jodit: Prototype pollution in Jodit via Jodit.modules.Helpers.set()
GHSA-vpmm-x3fm-qr5c
pkg: jodit
eco: npm
published: Jun 18, 2026
### Summary
`Jodit.modules.Helpers.set(chain, value, obj)` walks the dot-separated `chain`, creating and following each path segment, without filtering prototype-mutating keys. A chain that begins with (or contains) `__proto__`, `constructor`, or `prototype` lets the final assignment reach and mutat…
CVE-2026-55886
GitHub-GHSA

MEDIUM
OpenClaw: Tool group policy callers could accept unvalidated group IDs
GHSA-985f-72mj-8gf7
pkg: openclaw
eco: npm
published: Jun 18, 2026
### Summary

Tool group policy callers could accept unvalidated group IDs. In affected versions, a caller that can supply a group id to the affected policy resolver could resolve policy for an unvalidated group id.

This advisory is scoped to the named feature and configuration. It does not change O…

CVE-2026-53863
GitHub-GHSA

MEDIUM
Gitea: Open Redirect via redirect_to
GHSA-j5r2-4c8j-xc3m
pkg: github.com/go-gitea/gitea
eco: go
published: Jun 17, 2026
### Details

Despite the validation within `urlIsRelative` in `modules/httplib/url.go`, an open redirect is still possible due to usage of directory traversal sequences plus a back-slash in the "redirect_to" parameter.

### PoC

When a user uses this URL to login:

`https://gitea.com/user/login?redi…

CVE-2026-25779
GitHub-GHSA

MEDIUM
Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch
GHSA-fg94-h982-f3mm
pkg: @anthropic-ai/claude-code
eco: npm
published: Jun 17, 2026
Because the hostname huggingface.co was pre-approved as a bare hostname for the WebFetch tool, any path on that domain—including attacker-controlled model repositories—was auto-approved without a permission prompt or being subject to –allowedTools restrictions. An attacker able to inject untrus…
CVE-2026-54316
GitHub-GHSA

MEDIUM
Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services
GHSA-3g6v-2r68-prfc
pkg: github.com/traefik/traefik/v3, github.com/traefik/traefik/v2, github.com/traefik/traefik
eco: go
published: Jun 17, 2026
## Summary

There is a high severity vulnerability in Traefik's Kubernetes Gateway provider affecting the `crossProviderNamespaces` allowlist. For `HTTPRoute` rules that declare multiple (WRR) backendRefs, Traefik evaluates the allowlist against the target `backendRef.namespace` instead of the route…

CVE-2026-54761
GitHub-GHSA

MEDIUM
Gitea: Token scope bypass on web archive download endpoint
GHSA-cr4g-f395-h25h
pkg: code.gitea.io/gitea
eco: go
published: Jun 16, 2026
## Summary

PR #37698 added checkDownloadTokenScope to /raw/*, /media/*, and attachment download web endpoints. The /archive/* endpoint (repo.Download in routers/web/repo/repo.go:372) was not included in the fix. This endpoint accepts OAuth2 tokens via webAuth.AllowOAuth2 (registered at routers/web/…

CVE-2026-20706
GitHub-GHSA

MEDIUM
Hugo: Symlink confinement bypass in resources.Get
GHSA-fw87-fv5r-9fpw
pkg: github.com/gohugoio/hugo
eco: go
published: Jun 16, 2026
**Commit:** [f8b5fa09a6](https://github.com/gohugoio/hugo/commit/f8b5fa09a6) — _Fix prevention of direct symlink reads in resources.Get_
**Affected versions:** v0.123.0 through v0.161.1. Earlier versions are not affected.
**Fixed in:** v0.162.0.
**Severity:** Medium. Requires the attacker to be ab…
CVE-2026-50135
GitHub-GHSA

MEDIUM
Hugo: security.http.urls allow-list bypass via HTTP redirects
GHSA-vxgm-5rmg-5w8g
pkg: github.com/gohugoio/hugo
eco: go
published: Jun 16, 2026
**Commit:** [86fbb0f7a8](https://github.com/gohugoio/hugo/commit/86fbb0f7a8) — _security: Validate redirects against security.http.urls_
**Affected versions:** v0.91.0 (when `security.http.urls` was introduced) through v0.161.1.
**Fixed in:** v0.162.0.
**Severity:** Only relevant for sites that re…
CVE-2026-50134
GitHub-GHSA

MEDIUM
Hugo: XSS via text/html content files
GHSA-c54g-xjwj-8g82
pkg: github.com/gohugoio/hugo
eco: go
published: Jun 16, 2026
**Commit:** [e41a06447d](https://github.com/gohugoio/hugo/commit/e41a06447d) — _Disallow HTML content by default_
**Affected versions:** all Hugo versions prior to v0.162.0.
**Fixed in:** v0.162.0.
**Severity:** Low to Medium, depending on threat model. Not an issue if you fully trust every file u…
CVE-2026-50133


Vulnerability Digest — June 15, 2026 · 54 Critical · 5 Exploited






Vulnerability Digest — Monday, June 15, 2026


Security Report

Monday, June 15, 2026  ·  Last 7 days  ·  Min severity: MEDIUM
Total Findings
366
Critical
54
High
210
Actively Exploited
5
CISA-KEV5
NVD239
GitHub-GHSA122
Findings sorted by severity
CISA-KEV

CRITICAL
Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability
CVE-2026-35273
pkg: Oracle PeopleSoft Enterprise PeopleTools

published: Jun 12, 2026

Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Ivanti Sentry OS Command Injection Vulnerability
CVE-2026-10520
pkg: Ivanti Sentry

published: Jun 11, 2026

Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be successfully exploited in cases where the Sentry appliance is in an unmanaged stat…
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Google Chromium V8 Out-of-Bounds Read and Write Vulnerability
CVE-2026-11645
pkg: Google Chromium V8

published: Jun 9, 2026

Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Ed…
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability
CVE-2026-7473
pkg: Arista Extensible Operating System

published: Jun 9, 2026

Arista Extensible Operating System (EOS) contains an incomplete comparison with missing factors vulnerability when the switch incorrectly decapsulate and forwards other unexpected tunneled packet with a destination IP matching its configured decapsulation IP.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability
CVE-2026-20245
pkg: Cisco Catalyst SD-WAN Manager

published: Jun 9, 2026

Cisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability. This vulnerability could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
NVD

CRITICAL
CVE-2026-47208
CVE-2026-47208
pkg: node

published: Jun 12, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system. This issue has been patched in version 3.11.4.
CWE: CWE-913
NVD

CRITICAL
CVE-2026-47140
CVE-2026-47140
pkg: node

published: Jun 12, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM blocks several dangerous Node.js builtins such as module, worker_threads, cluster, vm, repl, and inspector. However, the denylist misses process and inspector/promises. Both can be used from sandboxed code to reach host-si…
CWE: CWE-693
NVD

CRITICAL
CVE-2026-47137
CVE-2026-47137
pkg: node

published: Jun 12, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the fix for GHSA-8hg8-63c5-gwmx (CVE-2023-37903) introduced a check in nodevm.js line 263 that blocks the combination nesting: true + require: false. However, the check uses strict equality (options.require === false), which is t…
CWE: CWE-913
NVD

CRITICAL
CVE-2026-47131
CVE-2026-47131
pkg: node

published: Jun 12, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, by combining Buffer.call.call({}.__lookupGetter__, Buffer, "__proto__"), Buffer.call.call({}.__lookupSetter__, Buffer, "__proto__"), and Node.js's ERR_INVALID_ARG_TYPE Error, the host's TypeError constructor can be obtained, whic…
CWE: CWE-913
NVD

CRITICAL
CVE-2026-49261
CVE-2026-49261
pkg: node

published: Jun 11, 2026

MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled would execute shell commands embedded in the name of the joiner node. This is fixed in 1…
CWE: CWE-78
NVD

CRITICAL
CVE-2026-50566
CVE-2026-50566
pkg: kubernetes

published: Jun 10, 2026

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, a tenant with environments.fission.io create/update RBAC can run privileged / allowPrivilegeEscalation / dangerous-capability contain…
CWE: CWE-250, CWE-269
NVD

CRITICAL
CVE-2026-50564
CVE-2026-50564
pkg: kubernetes

published: Jun 10, 2026

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, Fission's Environment CRD exposes spec.runtime.podSpec and spec.builder.podSpec, which are merged into the Kubernetes pod specs for r…
CWE: CWE-269, CWE-284, CWE-693
NVD

CRITICAL
CVE-2026-50563
CVE-2026-50563
pkg: kubernetes

published: Jun 10, 2026

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, Fission's Container Executor path lets a tenant supply Function.spec.podspec directly; the executor merges it into the executor-built…
CWE: CWE-269, CWE-284
NVD

CRITICAL
CVE-2026-50545
CVE-2026-50545
pkg: kubernetes

published: Jun 10, 2026

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, the Environment.spec.runtime.podSpec / spec.builder.podSpec passthrough lacked validation, and MergePodSpec propagated dangerous fiel…
CWE: CWE-269, CWE-284, CWE-693
NVD

CRITICAL
CVE-2026-45558
CVE-2026-45558
pkg: nginx

published: Jun 10, 2026

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the HAProxy section-save endpoints (POST /api/service/haproxy/<server_id>/section/<section_type> and the PUT / global / defaults variants) accept a JSON option field that is not vali…
CWE: CWE-20, CWE-77, CWE-78, CWE-94
NVD

CRITICAL
CVE-2026-45556
CVE-2026-45556
pkg: nginx

published: Jun 10, 2026

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, POST /waf/<service>/<server_ip>/rule/<rule_id>/save accepts a config_file_name form field that is passed straight through to config_mod.master_slave_upload_and_restart(…) as the de…
CWE: CWE-20, CWE-22, CWE-73, CWE-78
NVD

CRITICAL
CVE-2026-45552
CVE-2026-45552
pkg: nginx

published: Jun 10, 2026

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the install blueprint declares only bp.before_request → @jwt_required() (app/routes/install/routes.py:36-39). The individual endpoints install_exporter, install_waf, install_geoip,…
CWE: CWE-639, CWE-862, CWE-863
GitHub-GHSA

CRITICAL
nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation
GHSA-598g-h2vc-h5vg
pkg: github.com/juev/nebula-mesh
eco: go
published: Jun 8, 2026
The `/api/v1/*` route surface trusts the bearer token alone for authorisation on most endpoints. The codebase itself admits this at `internal/api/hosts.go:384`: *"API trusts the bearer token for authorisation; per-CA ownership is enforced only in the Web layer."*

The Web UI gates state-changing rou…

CVE-2026-47724
NVD

CRITICAL
CVE-2026-46442
CVE-2026-46442
pkg: flowiseai flowise

published: Jun 8, 2026

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, POST /api/v1/node-custom-function lacks route-level authorization, allowing any authenticated user or API key to submit arbitrary JavaScript to the Custom JS Function node. When E2B_APIKE…
CWE: CWE-94
NVD

CRITICAL
CVE-2026-54133
CVE-2026-54133
pkg: express

published: Jun 12, 2026

jmespath.php allows users to use JMESPath, software for declaratively specifying how to extract elements from a JSON document, in PHP applications with PHP data structures. Versions prior to 2.9.1 can generate and execute attacker-controlled PHP code when `JmesPath\CompilerRuntime` is used with an a…
CWE: CWE-20, CWE-94, CWE-116
NVD

CRITICAL
CVE-2026-47210
CVE-2026-47210
pkg: node

published: Jun 12, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, a sandbox escape vulnerability in vm2 allows arbitrary code execution in the host process when untrusted code is executed with async support on runtimes exposing WebAssembly JSPI (WebAssembly.promising / WebAssembly.Suspending). …
CWE: CWE-913
NVD

CRITICAL
CVE-2026-48611
CVE-2026-48611
pkg: oauth

published: Jun 12, 2026

Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations.
CWE: CWE-287
NVD

CRITICAL
CVE-2026-11561
CVE-2026-11561
pkg: express

published: Jun 11, 2026

Improper neutralization of special elements used in an expression language statement ('expression language injection') vulnerability in Soagen Informatics Technologies Software and Consulting Inc. Apinizer allows Code Injection.

This issue affects Apinizer: from 2026.04.0 before 2026.04.6.

CWE: CWE-917
NVD

CRITICAL
CVE-2026-46614
CVE-2026-46614
pkg: kubernetes

published: Jun 10, 2026

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.23.0, the Fission router registers an internal-style route — /fission-function/<name> and /fission-function/<ns>/<name> — for every Fun…
CWE: CWE-284, CWE-862
NVD

CRITICAL
CVE-2026-36721
CVE-2026-36721
pkg: jwt

published: Jun 9, 2026

A lack of cryptographic signature verification in the validateAccessToken function of bookcars v8.3 allows attackers to bypass authentication via a forged JWT token.
CWE: CWE-347
NVD

CRITICAL
CVE-2026-52778
CVE-2026-52778
pkg: express

published: Jun 8, 2026

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, an unsafe execution vulnerability exists in the Bazar form field calculator (CalcField.php) of YesWiki. The application attempts to sanitize user-defined mathematical formulas using a complex recursive regular expression before passing…
CWE: CWE-94, CWE-1333
NVD

CRITICAL
CVE-2026-46289
CVE-2026-46289
pkg: linux

published: Jun 8, 2026

In the Linux kernel, the following vulnerability has been resolved:

lib/scatterlist: fix length calculations in extract_kvec_to_sg

Patch series "Fix bugs in extract_iter_to_sg()", v3.

Fix bugs in the kvec and user variants of extract_iter_to_sg. This series
is growing due to useful remarks made …

NVD

CRITICAL
CVE-2026-39910
CVE-2026-39910
pkg: oauth

published: Jun 8, 2026

STACKIT IaaS API contains a missing authorization check vulnerability that allows authenticated, low-privileged attackers to escalate privileges to full organization compromise by attaching arbitrary service accounts to virtual machines they control. Attackers can exploit the unvalidated PUT servers…
CWE: CWE-862
NVD

CRITICAL
CVE-2026-44631
CVE-2026-44631
pkg: apache http_server

published: Jun 8, 2026

Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration.

This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.

Users are recommended to upgrade to version 2.4.68, which fixes the issue.

CWE: CWE-124
NVD

CRITICAL
CVE-2026-46703
CVE-2026-46703
pkg: docker

published: Jun 10, 2026

Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. Prior to version 0.9.0, Boxlite allows users to specify the OCI image used by containers in the sandbox. However, when processing tar entries in …
CWE: CWE-22
NVD

CRITICAL
CVE-2026-53474
CVE-2026-53474
pkg: kubernetes

published: Jun 10, 2026

A flaw was found in migration-planner. A remote authenticated attacker could exploit this vulnerability by uploading a specially crafted RVTools .xlsx file. Due to improper input sanitization, malicious SQL embedded within a spreadsheet cell is executed when cluster names are processed. This SQL Inj…
CWE: CWE-89
NVD

CRITICAL
CVE-2026-42904
CVE-2026-42904
pkg: microsoft windows_10_21h2, microsoft windows_10_22h2, microsoft windows_11_23h2

published: Jun 9, 2026

Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network.
CWE: CWE-122
NVD

CRITICAL
CVE-2026-11671
CVE-2026-11671
pkg: google chrome, apple macos, linux linux_kernel

published: Jun 9, 2026

Use after free in Navigation in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

CRITICAL
CVE-2026-11659
CVE-2026-11659
pkg: google chrome, linux linux_kernel

published: Jun 9, 2026

Integer overflow in UI in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-20
NVD

CRITICAL
CVE-2026-11654
CVE-2026-11654
pkg: google chrome, apple macos

published: Jun 9, 2026

Use after free in CameraCapture in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

CRITICAL
CVE-2026-11651
CVE-2026-11651
pkg: google chrome, apple macos, linux linux_kernel

published: Jun 9, 2026

Use after free in Network in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

CRITICAL
CVE-2026-11638
CVE-2026-11638
pkg: google chrome, apple macos, linux linux_kernel

published: Jun 9, 2026

Use after free in Printing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

CRITICAL
CVE-2026-11634
CVE-2026-11634
pkg: google chrome, microsoft windows

published: Jun 9, 2026

Use after free in Gamepad in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

CRITICAL
CVE-2026-50090
CVE-2026-50090
pkg: oauth

published: Jun 12, 2026

The Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.com/oauth/authorize) is vulnerable to a redirect bypass due to lax controls on domain matching, which is an instance of "CWE-1289: Improper Validation of Unsafe Equivalence in Input" and has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:R…
CWE: CWE-1289
NVD

CRITICAL
CVE-2026-46316
CVE-2026-46316
pkg: linux

published: Jun 9, 2026

In the Linux kernel, the following vulnerability has been resolved:

KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry

vgic_its_invalidate_cache() walks the per-ITS translation cache with
xa_for_each() and drops the cache's reference on each entry with
vgic_put_ir…

NVD

CRITICAL
CVE-2026-50083
CVE-2026-50083
pkg: oauth

published: Jun 12, 2026

The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which is an instance of "CWE-798: Use of Hard-coded Credentials." This issue has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N (9.1 Critical). When combined with CVE-2026-50082, CVE-5008…
CWE: CWE-798
NVD

CRITICAL
CVE-2026-9648
CVE-2026-9648
pkg: tls

published: Jun 11, 2026

The crypton-x509-validation Haskell library fails to enforce X.509 NameConstraints, allowing TLS clients to accept certificates whose Subject Alternative Names fall outside the issuing CA’s permitted subtrees. This oversight enables an attacker who compromises a name-constrained sub-CA to imperson…
GitHub-GHSA

CRITICAL
Meta Ads MCP: Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token
GHSA-9gw6-46qc-99vr
pkg: meta-ads-mcp
eco: pip
published: Jun 11, 2026
# Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token

| Field | Value |
| —————- | —– |
| Repository | pipeboard-co/meta-ads-mcp |
| Affected version | ≤ 1.0.101 (commit 496c988 ~ 7d14226); Versions 1.0.102–1.0.105 lack git tags, so patch statu…

CVE-2026-48039
NVD

CRITICAL
CVE-2026-45550
CVE-2026-45550
pkg: nginx

published: Jun 10, 2026

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, PUT /smon/check (app/routes/smon/routes.py:117-138) gates only on roxywi_common.check_user_group_for_flask() — which validates that the caller has some group, not that the target c…
CWE: CWE-639, CWE-862, CWE-863
GitHub-GHSA

CRITICAL
Go Restful API Boilerplate: Hardcoded JWT Secret "random" Allows Token Forgery
GHSA-mqq6-462x-jxmm
pkg: github.com/dhax/go-base
eco: go
published: Jun 10, 2026
## Vulnerability: CWE-798 — Hardcoded JWT Secret + Broken Mitigation

### Affected Component
– `github.com/dhax/go-base` — Go REST API boilerplate (go-chi/jwtauth/v5, Viper, PostgreSQL/Bun)
– 1,685 stars on GitHub

### Vulnerability Locations

| File | Line | Role |
|——|——|——|
| `dev…

CVE-2026-48031
NVD

CRITICAL
CVE-2026-36727
CVE-2026-36727
pkg: jwt

published: Jun 9, 2026

An insecure authentication vulnerability in the /api/social-sign-in endpoint of bookcars v8.3 allows attackers to bypass authentication via a forged JWT token.
CWE: CWE-287
NVD

CRITICAL
CVE-2026-34182
CVE-2026-34182
pkg: openssl

published: Jun 9, 2026

Issue Summary: Cryptographic Message Services (CMS) processing fails to perform
sufficient input validation on the cipher and tag length fields of
AuthEnvelopedData containers, leading to various potential compromises.

Impact Summary: Attackers making use of these vulnerabilities may achieve
key-eq…

CWE: CWE-354
GitHub-GHSA

CRITICAL
Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assign
GHSA-6xp4-cf37-ppjh
pkg: @budibase/server
eco: npm
published: Jun 12, 2026
## Summary

`/api/public/v1/roles/assign` is guarded by the `builderOrAdmin` middleware, which passes any user who is a builder for the app id in the `x-budibase-app-id` header. That check admits both global builders and workspace-scoped builders (`builder.apps` set but `builder.global` unset). The …

CVE-2026-48150
NVD

CRITICAL
CVE-2026-41005
CVE-2026-41005
pkg: oauth

published: Jun 11, 2026

Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a substitute for XML signatures from the Identity Provider (authenticity) in two SAML flows: the OAuth 2.0 SAML2 bearer grant (token endpoint) and browser SSO (ACS) when wantAssertionSigned is set to fa…
CWE: CWE-347
GitHub-GHSA

CRITICAL
Anyquery: AppleScript/JXA Code Injection via Unescaped URL in macOS Chrome Plugin
GHSA-hrj8-hjv8-mgwc
pkg: github.com/julien040/anyquery/plugins/chrome, github.com/julien040/anyquery/plugins/brave, github.com/julien040/anyquery/plugins/edge
eco: go
published: Jun 8, 2026
# AppleScript/JXA Code Injection via Unescaped URL in macOS Chrome Plugin

| Field | Value |
| —————- | —– |
| Repository | julien040/anyquery |
| Affected version | 0.4.4 (commit 0abd460) |
| Vulnerability | CWE-94 — Improper Control of Generation of Code |
| Seve…

CVE-2026-47252
NVD

CRITICAL
CVE-2026-11393
CVE-2026-11393
pkg: python

published: Jun 8, 2026

Improper neutralization of triple-quote characters during Python code generation in AgentCore CLI before v0.14.2 might allow an authenticated remote threat actor to execute arbitrary code on AWS AgentCore Runtime under the imported agent's IAM execution role and on the local environment of another u…
CWE: CWE-94
GitHub-GHSA

CRITICAL
shell-quote quote() does not escape newlines in object .op values
GHSA-w7jw-789q-3m8p
pkg: shell-quote
eco: npm
published: Jun 9, 2026
### Summary

`shell-quote`'s `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The `.op` field was backslash-escaped character by character using `/(.)/g`, which in JavaScript does not match line terminators (`\n`, `\r`, U+2028, U+2029). A line ter…

CVE-2026-9277
GitHub-GHSA

CRITICAL
Baileys has message upsert / hist sync spoofing and app state corruption when using maliciously crafted protocolMessage payload
GHSA-qvv5-jq5g-4cgg
pkg: baileys, @whiskeysockets/baileys, baileys
eco: npm
published: Jun 10, 2026
### Impact
Any baileys session under the latest version (< 7.0.0-rc12, and < 6.7.22) can be sent a malicious payload via the placeholderResendMessage and trigger a fake `messages.upsert` event with a **fake message key and payload**. This allows anyone to spoof messages. The same exploit also allows…
CVE-2026-48063
GitHub-GHSA

CRITICAL
Cordova Plugin InAppBrowser: iOS: Arbitrary Cordova callback IDs can be dispatched without validation from InAppBrowser WebViews.
GHSA-q42j-x8rq-pjg6
pkg: cordova-plugin-inappbrowser
eco: npm
published: Jun 8, 2026
## Summary

The iOS implementation of `cordova-plugin-inappbrowser` passes the `id` field from a `WKScriptMessage` body to `commandDelegate sendPluginResult:callbackId:` with no format validation (`CDVWKInAppBrowser.m:560–574`). Any web content loaded inside the InAppBrowser can fire any pending C…

CVE-2026-47430
NVD

HIGH
CVE-2026-46519
CVE-2026-46519
pkg: kubernetes

published: Jun 11, 2026

mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to version 3.6.0, mcp-server-kubernetes exposes three environment variables (ALLOW_ONLY_READONLY_TOOLS, ALLOW_ONLY_NON_DESTRUCTIVE_TOOLS, ALLOWED_TOOLS) documented as access controls for restricting whi…
CWE: CWE-863
GitHub-GHSA

HIGH
OpenZeppelin Contracts Wizard has Code Injection in Generated Hardhat and Foundry Tests via Unsanitized opts.name / opts.uri
GHSA-4×76-22×2-rx8v
pkg: @openzeppelin/wizard
eco: npm
published: Jun 11, 2026
## Summary

The OpenZeppelin Contracts Wizard generated Hardhat (`test/test.ts`) and Foundry (`test/<Name>.t.sol`) example test files that interpolated user-supplied strings (`opts.name`, `opts.uri`) into the test source without escaping. A crafted input could produce a generated test file in which …

CVE-2026-48054
NVD

HIGH
CVE-2026-46612
CVE-2026-46612
pkg: kubernetes

published: Jun 10, 2026

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.23.0, the Fission storagesvc component registers archive CRUD handlers (/v1/archive GET / POST / DELETE and /v1/archives list) directly on …
CWE: CWE-306
NVD

HIGH
CVE-2026-20251
CVE-2026-20251
pkg: python

published: Jun 10, 2026

In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132, and Splunk Secure Gateway versions below 3.10.6, 3.9.20, and 3.8.67, a low-privileged user that does not hold the 'admin' or 'power…
CWE: CWE-502
NVD

HIGH
CVE-2026-45564
CVE-2026-45564
pkg: nginx

published: Jun 10, 2026

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, POST /config/versions/<service>/<server_ip>/<configver>/save interpolates the URL-path configver parameter directly into a config-version path that ends up at os.system(f"dos2unix -q…
CWE: CWE-78
NVD

HIGH
CVE-2026-45447
CVE-2026-45447
pkg: openssl

published: Jun 9, 2026

Issue summary: A specially crafted PKCS#7 or S/MIME signed message could
trigger a use-after-free during PKCS#7 signature verification.

Impact summary: A use-after-free may result in process crashes, heap
corruption, or potentially remote code execution.

When processing a PKCS#7 or S/MIME signed m…

CWE: CWE-416
NVD

HIGH
CVE-2026-32193
CVE-2026-32193
pkg: kubernetes

published: Jun 9, 2026

Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to execute code locally.
CWE: CWE-22
NVD

HIGH
CVE-2026-46317
CVE-2026-46317
pkg: linux

published: Jun 9, 2026

In the Linux kernel, the following vulnerability has been resolved:

KVM: arm64: Reassign nested_mmus array behind mmu_lock

kvm->arch.nested_mmus[] is walked under kvm->mmu_lock, including from the
MMU notifier path (kvm_unmap_gfn_range() -> kvm_nested_s2_unmap()), which
can run at any time. kvm_vc…

NVD

HIGH
CVE-2026-11681
CVE-2026-11681
pkg: google chrome, linux linux_kernel

published: Jun 9, 2026

Use after free in Ozone in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-11680
CVE-2026-11680
pkg: google chrome, microsoft windows

published: Jun 9, 2026

Use after free in Media in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-11674
CVE-2026-11674
pkg: google chrome, apple macos, linux linux_kernel

published: Jun 9, 2026

Use after free in Guest View in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-11673
CVE-2026-11673
pkg: google chrome, apple macos, linux linux_kernel

published: Jun 9, 2026

Use after free in InterestGroups in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-11670
CVE-2026-11670
pkg: google chrome, apple macos, linux linux_kernel

published: Jun 9, 2026

Use after free in PDF in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-11664
CVE-2026-11664
pkg: google chrome, apple macos, linux linux_kernel

published: Jun 9, 2026

Use after free in Payments in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-11662
CVE-2026-11662
pkg: google chrome, apple macos, linux linux_kernel

published: Jun 9, 2026

Type Confusion in Bindings in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-843
NVD

HIGH
CVE-2026-11657
CVE-2026-11657
pkg: google chrome, apple macos

published: Jun 9, 2026

Use after free in Payments in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-11650
CVE-2026-11650
pkg: google chrome, apple macos, linux linux_kernel

published: Jun 9, 2026

Use after free in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-11649
CVE-2026-11649
pkg: google chrome, apple macos, linux linux_kernel

published: Jun 9, 2026

Use after free in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-11648
CVE-2026-11648
pkg: google chrome, microsoft windows

published: Jun 9, 2026

Use after free in FullScreen in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-11646
CVE-2026-11646
pkg: google chrome, apple macos, linux linux_kernel

published: Jun 9, 2026

Use after free in ViewTransitions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-11645
CVE-2026-11645
pkg: google chrome, apple macos, linux linux_kernel

published: Jun 9, 2026

Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-125, CWE-787
NVD

HIGH
CVE-2026-11637
CVE-2026-11637
pkg: google chrome, apple macos

published: Jun 9, 2026

Use after free in Views in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-11633
CVE-2026-11633
pkg: google chrome, apple macos

published: Jun 9, 2026

Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via a malicious peripheral. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-11630
CVE-2026-11630
pkg: google chrome, apple macos, linux linux_kernel

published: Jun 9, 2026

Use after free in File Input in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-11629
CVE-2026-11629
pkg: google chrome, apple macos, linux linux_kernel

published: Jun 9, 2026

Use after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-46490
CVE-2026-46490
pkg: samlify_project samlify

published: Jun 8, 2026

samlify is a Node.js library for SAML single sign-on. Prior to version 2.13.0, samlify’s template substitution only escapes attribute contexts. Values inserted into element text (e.g., <saml:AttributeValue>) are not escaped. A normal user can inject XML markup into an attribute value (e.g., email,…
CWE: CWE-91
NVD

HIGH
CVE-2026-11523
CVE-2026-11523
pkg: go

published: Jun 8, 2026

A flaw has been found in Tenda W20E 15.11.0.6. This issue affects the function formPortalAuth of the file /goform/PortalAuth of the component Web Management Interface. Executing a manipulation of the argument gotoUrl can lead to stack-based buffer overflow. The attack can be launched remotely. The e…
CWE: CWE-119, CWE-121
NVD

HIGH
CVE-2026-47135
CVE-2026-47135
pkg: node

published: Jun 12, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, Symbol.for override in setup-sandbox.js only intercepts 2 of 9 dangerous Node.js cross-realm symbols. Combined with the bridge's set/defineProperty/deleteProperty traps having no isDangerousCrossRealmSymbol key check, sandbox cod…
CWE: CWE-693
NVD

HIGH
CVE-2026-44494
CVE-2026-44494
pkg: axios axios

published: Jun 11, 2026

Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's dependency tree to be escalated into a full Man-in-the-Middle (MITM)…
CWE: CWE-441, CWE-1321
GitHub-GHSA

HIGH
Dex: Token-exchange endpoint is missing AllowedConnectors enforcement
GHSA-7qjx-gp9h-65qj
pkg: github.com/dexidp/dex
eco: go
published: Jun 9, 2026
## Summary

`server/handlers.go::handleTokenExchange` (lines 1804-1893) does not call `isConnectorAllowed(client.AllowedConnectors, connID)` before issuing tokens, while sibling handlers do. This is a per-client connector ACL gap on the token-exchange endpoint; the redirect-flow paths enforce the sa…

GitHub-GHSA

HIGH
Netty has Insufficient Bailiwick Validation for NS Records
GHSA-5pvg-856g-cp85
pkg: io.netty:netty-resolver-dns, io.netty:netty-resolver-dns
eco: maven
published: Jun 8, 2026
### Summary
Netty's `DnsResolveContext` insufficiently validates the bailiwick of NS records, enabling DNS Cache Poisoning. An attacker controlling an authoritative name server for a subdomain can poison the cache for parent domains (like `.co.uk`).

### Details
In `io.netty.resolver.dns.DnsResolveC…

CVE-2026-47691
GitHub-GHSA

HIGH
Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records
GHSA-676x-f7gg-47vc
pkg: io.netty:netty-resolver-dns, io.netty:netty-resolver-dns
eco: maven
published: Jun 8, 2026
### Summary
Netty's DnsResolveContext fails to validate the origin (bailiwick) of CNAME records in DNS responses.

### Details
In `io.netty.resolver.dns.DnsResolveContext#buildAliasMap`, the resolver processes the ANSWER section of a DNS response and blindly caches all CNAME records it finds.

Accor…

CVE-2026-45674
NVD

HIGH
CVE-2026-47209
CVE-2026-47209
pkg: node

published: Jun 12, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the BaseHandler.set trap in bridge.js (line 1231) ignores the receiver parameter and unconditionally writes to the host target object. Per the Proxy set trap specification, when receiver !== proxy (e.g., when a child object inher…
CWE: CWE-693
NVD

HIGH
CVE-2026-47139
CVE-2026-47139
pkg: tls

published: Jun 12, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM supports excluding public network builtins from the wildcard builtin option. With this configuration direct access to http, https, http2, net, dgram, tls, dns, and dns/promises is blocked. However, Node.js also exposes und…
CWE: CWE-693
NVD

HIGH
CVE-2026-44492
CVE-2026-44492
pkg: axios axios

published: Jun 11, 2026

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise IPv4-mapped IPv6 addresses. When NO_PROXY lists an IPv4 address such as 127.0.0.1 or 169.254.169.254, a request URL using the IPv4-mapped IPv6 form (::ffff:7f00:1, ::ffff:a9fe:a9fe)…
CWE: CWE-918
NVD

HIGH
CVE-2026-50570
CVE-2026-50570
pkg: kubernetes

published: Jun 10, 2026

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.25.0, Fission added PodSpec safety validation for tenant-facing Environment and Function CRDs (ValidatePodSpecSafety / ValidateContainerSaf…
CWE: CWE-269, CWE-732
NVD

HIGH
CVE-2026-49824
CVE-2026-49824
pkg: kubernetes

published: Jun 10, 2026

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, the Fission Function admission webhook (pkg/webhook/function.go) validated that spec.secrets[].namespace and spec.configmaps[].namesp…
CWE: CWE-284, CWE-863
NVD

HIGH
CVE-2026-45549
CVE-2026-45549
pkg: nginx

published: Jun 10, 2026

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, agent_action (app/routes/smon/agent_routes.py:166-179) has decorators @bp.post('/agent/action/<action>') and @jwt_required() only — no role check, no group ownership check on the s…
CWE: CWE-862, CWE-863
NVD

HIGH
CVE-2026-46288
CVE-2026-46288
pkg: linux

published: Jun 8, 2026

In the Linux kernel, the following vulnerability has been resolved:

of: unittest: fix use-after-free in of_unittest_changeset()

The variable 'parent' is assigned the value of 'nchangeset' earlier in the
function, meaning both point to the same struct device_node. The call to
of_node_put(nchangeset…

NVD

HIGH
CVE-2026-45567
CVE-2026-45567
pkg: nginx

published: Jun 10, 2026

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, there is an authentication bypass vulnerability via 'api' substring in URL + unauthenticated /api/gpt. At time of publication, there are no publicly available patches.
CWE: CWE-287, CWE-306, CWE-697
NVD

HIGH
CVE-2026-11682
CVE-2026-11682
pkg: google chrome, linux linux_kernel

published: Jun 9, 2026

Inappropriate implementation in Views in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-20
NVD

HIGH
CVE-2026-11679
CVE-2026-11679
pkg: google chrome, microsoft windows

published: Jun 9, 2026

Use after free in Codecs in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-11676
CVE-2026-11676
pkg: google chrome, google chrome_os, linux linux_kernel

published: Jun 9, 2026

Insufficient validation of untrusted input in Dawn in Google Chrome on Linux and ChromeOS prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-20
NVD

HIGH
CVE-2026-11672
CVE-2026-11672
pkg: google chrome, google android

published: Jun 9, 2026

Heap buffer overflow in GPU in Google Chrome on Android prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-787
NVD

HIGH
CVE-2026-11663
CVE-2026-11663
pkg: google chrome, apple macos, linux linux_kernel

published: Jun 9, 2026

Use after free in Skia in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-11661
CVE-2026-11661
pkg: google chrome, microsoft windows

published: Jun 9, 2026

Use after free in Views in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-11660
CVE-2026-11660
pkg: google chrome, apple macos, linux linux_kernel

published: Jun 9, 2026

Insufficient validation of untrusted input in New Tab Page in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-20
NVD

HIGH
CVE-2026-11656
CVE-2026-11656
pkg: google chrome, apple macos, linux linux_kernel

published: Jun 9, 2026

Use after free in ServiceWorker in Google Chrome prior to 149.0.7827.103 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-11655
CVE-2026-11655
pkg: google chrome, apple macos

published: Jun 9, 2026

Integer overflow in Media in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-472
NVD

HIGH
CVE-2026-11652
CVE-2026-11652
pkg: google chrome, apple macos, linux linux_kernel

published: Jun 9, 2026

Use after free in Extensions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-11647
CVE-2026-11647
pkg: google chrome, google android

published: Jun 9, 2026

Use after free in Printing in Google Chrome on Android prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-11642
CVE-2026-11642
pkg: google chrome, apple macos, linux linux_kernel

published: Jun 9, 2026

Use after free in Web Apps in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-11640
CVE-2026-11640
pkg: google chrome, apple macos, linux linux_kernel

published: Jun 9, 2026

Integer overflow in libyuv in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-472
NVD

HIGH
CVE-2026-11635
CVE-2026-11635
pkg: google chrome, apple macos

published: Jun 9, 2026

Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-11631
CVE-2026-11631
pkg: google chrome, microsoft windows

published: Jun 9, 2026

Use after free in Aura in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-46481
CVE-2026-46481
pkg: jwt

published: Jun 8, 2026

OpenMetadata is a unified metadata platform. Prior to version 1.12.4, a non-admin SSO user can trigger a TEST_CONNECTION workflow for a Database Service and receive, in the HTTP 201 response of POST /api/v1/automations/workflows, both the cleartext database password in request.connection.config.pass…
CWE: CWE-201
NVD

HIGH
CVE-2026-46307
CVE-2026-46307
pkg: linux

published: Jun 8, 2026

In the Linux kernel, the following vulnerability has been resolved:

wifi: ath5k: do not access array OOB

Vincent reports:
> The ath5k driver seems to do an array-index-out-of-bounds access as
> shown by the UBSAN kernel message:
> UBSAN: array-index-out-of-bounds in drivers/net/wireless/ath/ath5k/…

NVD

HIGH
CVE-2026-53721
CVE-2026-53721
pkg: nuxt nuxt

published: Jun 12, 2026

Nuxt is an open-source web development framework for Vue.js. From versions 3.11.0 to before 3.21.7 and 4.0.0 to before 4.4.7, there is a route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher. This issue has been patched in versions 3.21.7 and 4.4.7.
CWE: CWE-178, CWE-863
GitHub-GHSA

HIGH
MessagePack's LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad input
GHSA-hv8m-jj95-wg3x
pkg: MessagePack, MessagePack
eco: nuget
published: Jun 11, 2026
### Impact

A vulnerability exists in the optional LZ4 decompression path used by MessagePack compression modes `Lz4Block` and `Lz4BlockArray`.

The decoder implementation is based on a deprecated fast-decompression algorithm that does not take a source-length bound. A remote attacker can send a cra…

CVE-2026-48109
NVD

HIGH
CVE-2026-49982
CVE-2026-49982
pkg: node

published: Jun 11, 2026

tmp is a temporary file and directory creator for node.js. In version 0.2.6, the _assertPath guard added to tmp rejects only string values that contain the substring … It is bypassed when prefix, postfix, or template is supplied as a non-string value (Array, Buffer, or any object) whose includes('…
CWE: CWE-20, CWE-22
NVD

HIGH
CVE-2026-40998
CVE-2026-40998
pkg: express

published: Jun 11, 2026

Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed attacker-controlled XML with the JDK's default DocumentBuilderFactory behavior instead of Spring's hardened parser configuration. Applications that evaluate XPath against untrusted XML…
CWE: CWE-611
GitHub-GHSA

HIGH
FUXA: Unauthenticated SSRF via Socket.IO DEVICE_WEBAPI_REQUEST and DEVICE_PROPERTY with response reading
GHSA-w86f-rf9w-h3x6
pkg: fuxa-server
eco: npm
published: Jun 8, 2026
## Summary

An unauthenticated attacker (Alice) connects to FUXA's Socket.IO endpoint and emits a `device-webapi-request` event whose `property.address` field names an arbitrary URL. FUXA's `DEVICE_WEBAPI_REQUEST` handler at `server/runtime/index.js:296` calls `axios.get(address)` server-side and br…

CVE-2026-47719
NVD

HIGH
CVE-2026-46303
CVE-2026-46303
pkg: linux

published: Jun 8, 2026

In the Linux kernel, the following vulnerability has been resolved:

isofs: validate Rock Ridge CE continuation extent against volume size

rock_continue() reads rs->cont_extent verbatim from the Rock Ridge CE
record and passes it to sb_bread() without checking that the block
number is within the mo…

GitHub-GHSA

HIGH
esbuild: Missing binary integrity verification in Deno module enables remote code execution via NPM_CONFIG_REGISTRY
GHSA-gv7w-rqvm-qjhr
pkg: esbuild
eco: npm
published: Jun 12, 2026
### Summary

The esbuild Deno module (`lib/deno/mod.ts`) downloads native binary executables from an npm registry and writes them to disk with executable permissions (`0o755`) **without performing any integrity verification** (e.g., SHA-256 hash check). The Node.js equivalent (`lib/npm/node-install.…

GitHub-GHSA

HIGH
Appsmith: Configuration-dependent origin validation bypass in password reset and email verification link generation
GHSA-j9gf-vw2f-9hrw
pkg: com.appsmith:server
eco: maven
published: Jun 12, 2026
### Summary
A configuration-dependent origin validation bypass was identified in Appsmith’s password reset and email verification flows on current `release`.

Both flows derive the email-link base URL from the request `Origin` header. The current validation only enforces a trusted base URL when `A…

GitHub-GHSA

HIGH
Budibase: Basic app users can exfiltrate stored REST datasource auth by rewriting datasource base URL
GHSA-3gp5-q4jw-3v94
pkg: @budibase/server
eco: npm
published: Jun 12, 2026
### Summary
Budibase stores external REST datasource credentials server-side and documents that database credentials are applied server-side and are not exposed in the UI. The REST datasource implementation redacts stored Basic/Bearer/OAuth2 auth secrets before returning datasource data to clients. …
CVE-2026-48152
GitHub-GHSA

HIGH
Appsmith Super User Creation Race Condition Allows Multiple Instance Administrators
GHSA-9wcp-79g5-5c3c
pkg: com.appsmith:server
eco: maven
published: Jun 12, 2026
## Summary

The `/api/v1/users/super` endpoint enforces a restriction that only one super user (Instance Administrator) can be created during initial setup. However, due to a Time-of-Check-Time-of-Use (TOCTOU) race condition in the `signupAndLoginSuper()` method, concurrent requests can bypass this …

NVD

HIGH
CVE-2026-11816
CVE-2026-11816
pkg: docker

published: Jun 11, 2026

Keras versions prior to 3.14.0 are vulnerable to a path traversal issue in the archive extraction utilities located in `keras/src/utils/file_utils.py`. The functions `filter_safe_tarinfos()` and `filter_safe_zipinfos()` validate archive member paths against the process current working directory (CWD…
CWE: CWE-22
GitHub-GHSA

HIGH
Litestar has HTML Injection Through its CSRF Token
GHSA-542p-wvx7-72m4
pkg: litestar
eco: pip
published: Jun 10, 2026
# Overview

Litestar instances which use a template engine in conjunction with CSRF protection are vulnerable to HTML Injection which can be escalated to Cross Site Scripting due to the contents of the CSRF cookie being excluded from automatic escaping by the template engine when configured inline w…

CVE-2026-48060
NVD

HIGH
CVE-2026-45569
CVE-2026-45569
pkg: nginx

published: Jun 10, 2026

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, ommit d4d10006 ("Expand validation to block .. in config_file_name and configver for improved security") added a line in app/modules/config/config.py:462. This is tuple-membership, n…
CWE: CWE-22, CWE-697
NVD

HIGH
CVE-2026-45565
CVE-2026-45565
pkg: nginx

published: Jun 10, 2026

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, EscapedString (app/modules/roxywi/class_models.py:16-30) is the centralised Pydantic validator used on dozens of fields including SSH credential name, username, description, etc. Its…
CWE: CWE-20, CWE-22, CWE-117
GitHub-GHSA

HIGH
In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization
GHSA-xq69-5h5v-x9x4
pkg: org.springframework.kafka:spring-kafka, org.springframework.kafka:spring-kafka, org.springframework.kafka:spring-kafka
eco: maven
published: Jun 10, 2026
JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its subpackages. Combined with Jackson's default bean deserialization, a producer could supply crafted hea…
CVE-2026-41731
NVD

HIGH
CVE-2026-41729
CVE-2026-41729
pkg: express

published: Jun 10, 2026

Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch (application/json-patch+json) requests. When a persistent entity exposes a Map-typed property, the JSON Pointer path segment used as the map key is embedded directly into a SpEL expres…
CWE: CWE-917
NVD

HIGH
CVE-2026-41717
CVE-2026-41717
pkg: express

published: Jun 10, 2026

Spring Data MongoDB contains a SpEL (Spring Expression Language) expression injection vulnerability. The issue occurs during parameter binding when a user-defined repository query method is annotated with @Query and utilizes a capture-all placeholder.

Affected versions:
Spring Data MongoDB 5.0.0 th…

CWE: CWE-917
NVD

HIGH
CVE-2026-7383
CVE-2026-7383
pkg: openssl

published: Jun 9, 2026

Issue summary: A signed integer overflow when sizing the destination
buffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap
buffer overflow.

Impact summary: A heap buffer overflow may lead to a crash or possibly
attacker controlled code execution or other undefined behaviour.

In ASN…

CWE: CWE-787
NVD

HIGH
CVE-2026-42987
CVE-2026-42987
pkg: microsoft windows_server_2012, microsoft windows_server_2016, microsoft windows_server_2019

published: Jun 9, 2026

Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
CWE: CWE-416
NVD

HIGH
CVE-2026-42981
CVE-2026-42981
pkg: microsoft windows_11_23h2, microsoft windows_11_24h2, microsoft windows_11_25h2

published: Jun 9, 2026

Integer underflow (wrap or wraparound) in Windows Performance Monitor allows an unauthorized attacker to execute code over a network.
CWE: CWE-191
NVD

HIGH
CVE-2026-42974
CVE-2026-42974
pkg: microsoft windows_11_23h2, microsoft windows_11_24h2, microsoft windows_11_25h2

published: Jun 9, 2026

Integer underflow (wrap or wraparound) in Windows Performance Monitor allows an unauthorized attacker to execute code over a network.
CWE: CWE-190
NVD

HIGH
CVE-2026-49948
CVE-2026-49948
pkg: jwt

published: Jun 9, 2026

Mem0 versions through 0.2.8, fixed in commit ae7f406, contain a missing authorization vulnerability in the self-hosted server component where the POST /configure endpoint modifies global LLM provider and embedder configuration but only verifies authentication via JWT or X-API-Key without validating …
CWE: CWE-862
NVD

HIGH
CVE-2026-11643
CVE-2026-11643
pkg: google chrome, apple macos, linux linux_kernel

published: Jun 9, 2026

Use after free in Proxy in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-46484
CVE-2026-46484
pkg: node

published: Jun 8, 2026

Headplane is a feature-complete Web UI for Headscale. Prior to versions 0.6.3 and 0.7.0-beta.3, Headplane was vulnerable to a path traversal / authorization bypass in the Headscale API client used by node and user rename operations. This issue has been patched in versions 0.6.3 and 0.7.0-beta.3.
CWE: CWE-22, CWE-285
GitHub-GHSA

HIGH
Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking
GHSA-3qp7-7mw8-wx86
pkg: io.netty:netty-handler, io.netty:netty-handler
eco: maven
published: Jun 8, 2026
### Summary
An attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid public IP addresses can bypass the restrictions.

### Details
`io.netty.handler.ipfilter.IpSubnetFilterRule#compareTo(java.net.InetSocketAddress)` method performs a bit…

CVE-2026-44249
NVD

HIGH
CVE-2026-48165
CVE-2026-48165
pkg: node

published: Jun 12, 2026

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before 11.4.12, 11.8.1 to before 11.8.8, and 12.3.1, a high-privileged MariaDB user could've used wsrep_sst_receive_address or wsrep_sst_donor global system var…
CWE: CWE-78
NVD

HIGH
CVE-2026-48163
CVE-2026-48163
pkg: node

published: Jun 12, 2026

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before 11.4.12, 11.8.1 to before 11.8.8, and 12.3.1, during the SST the donor node is interpolating parameters that the joiner sent into the command line. Not a…
CWE: CWE-78
NVD

HIGH
CVE-2026-44168
CVE-2026-44168
pkg: node

published: Jun 12, 2026

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, during the SST the donor node is interpolating parameters that the joiner sent into the command line. Not a…
CWE: CWE-78
NVD

HIGH
CVE-2026-48612
CVE-2026-48612
pkg: oauth

published: Jun 12, 2026

Improper state verification in the OAuth implementation could allow an attacker to manipulate the authentication flow and cause a victim’s account to be linked to an attacker-controlled account. This can result in unauthorized account linking and potential account takeover.
CWE: CWE-352
GitHub-GHSA

HIGH
AWS Advanced Go Wrapper has Privilege Escalation in Aurora PostgreSQL instance
GHSA-r236-5pc3-3qcp
pkg: github.com/aws/aws-advanced-go-wrapper/awssql/v2, github.com/aws/aws-advanced-go-wrapper/xray, github.com/aws/aws-advanced-go-wrapper/aws-secrets-manager
eco: go
published: Jun 11, 2026
Aurora PostgreSQL is a fully managed relational database engine that's compatible with PostgreSQL.

An issue in Aurora PostgreSQL using the AWS Go Wrapper waa identified, see CVE-2026-11401.

Impact
An issue in AWS Wrappers for Amazon Aurora PostgreSQL may allow for privilege escalation to rds_supe…

CVE-2026-11401
GitHub-GHSA

HIGH
Jenkins: Stored XSS vulnerability in node offline cause description
GHSA-93qh-vwrm-c5pw
pkg: org.jenkins-ci.main:jenkins-core
eco: maven
published: Jun 10, 2026
Jenkins 2.483 through 2.567 (both inclusive), LTS 2.492.1 through 2.555.2 (both inclusive) does not escape the user-provided description of a generic offline cause that could be set through the `POST config.xml` API, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attac…
CVE-2026-53441
NVD

HIGH
CVE-2026-42851
CVE-2026-42851
pkg: python

published: Jun 12, 2026

Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, a program able to write bytes to a kitty terminal — a remote SSH peer, a downloaded file viewed with `cat`, a log line, an email body rendered in `less`, an issue body in a TUI, etc. — can cause kitty to execute attacker-…
CWE: CWE-94, CWE-862
NVD

HIGH
CVE-2026-44802
CVE-2026-44802
pkg: microsoft windows_10_1809, microsoft windows_10_21h2, microsoft windows_10_22h2

published: Jun 9, 2026

Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CWE: CWE-416
NVD

HIGH
CVE-2026-42991
CVE-2026-42991
pkg: microsoft windows_10_1809, microsoft windows_10_21h2, microsoft windows_10_22h2

published: Jun 9, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
CWE: CWE-362, CWE-416
NVD

HIGH
CVE-2026-42983
CVE-2026-42983
pkg: microsoft windows_10_1809, microsoft windows_10_21h2, microsoft windows_10_22h2

published: Jun 9, 2026

Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CWE: CWE-416
NVD

HIGH
CVE-2026-42980
CVE-2026-42980
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Jun 9, 2026

Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally.
CWE: CWE-122, CWE-191
NVD

HIGH
CVE-2026-42979
CVE-2026-42979
pkg: microsoft windows_10_1809, microsoft windows_10_21h2, microsoft windows_10_22h2

published: Jun 9, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
CWE: CWE-362, CWE-416
NVD

HIGH
CVE-2026-42978
CVE-2026-42978
pkg: microsoft windows_10_1809, microsoft windows_10_21h2, microsoft windows_10_22h2

published: Jun 9, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
CWE: CWE-362, CWE-416
NVD

HIGH
CVE-2026-42977
CVE-2026-42977
pkg: microsoft windows_10_1809, microsoft windows_10_21h2, microsoft windows_10_22h2

published: Jun 9, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
CWE: CWE-362
NVD

HIGH
CVE-2026-42916
CVE-2026-42916
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Jun 9, 2026

Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally.
CWE: CWE-190
NVD

HIGH
CVE-2026-42910
CVE-2026-42910
pkg: microsoft windows_11_24h2, microsoft windows_11_25h2, microsoft windows_11_26h1

published: Jun 9, 2026

Out-of-bounds write in Windows Hotpatch Monitoring Service allows an authorized attacker to elevate privileges locally.
CWE: CWE-787
NVD

HIGH
CVE-2026-42905
CVE-2026-42905
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Jun 9, 2026

Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CWE: CWE-416
NVD

HIGH
CVE-2026-42837
CVE-2026-42837
pkg: microsoft windows_10_1809, microsoft windows_10_21h2, microsoft windows_10_22h2

published: Jun 9, 2026

Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.
CWE: CWE-125
NVD

HIGH
CVE-2026-42829
CVE-2026-42829
pkg: microsoft windows_11_24h2, microsoft windows_11_25h2, microsoft windows_11_26h1

published: Jun 9, 2026

Improper access control in Windows Administrator Protection allows an authorized attacker to bypass a security feature locally.
CWE: CWE-284
NVD

HIGH
CVE-2026-42828
CVE-2026-42828
pkg: microsoft windows_10_1809, microsoft windows_10_21h2, microsoft windows_10_22h2

published: Jun 9, 2026

Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.
CWE: CWE-126
NVD

HIGH
CVE-2026-40409
CVE-2026-40409
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Jun 9, 2026

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
CWE: CWE-197
NVD

HIGH
CVE-2026-40404
CVE-2026-40404
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Jun 9, 2026

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
CWE: CWE-122, CWE-197
NVD

HIGH
CVE-2026-33828
CVE-2026-33828
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Jun 9, 2026

Trust boundary violation in Windows Attestation allows an authorized attacker to elevate privileges locally.
CWE: CWE-501
NVD

HIGH
CVE-2026-8795
CVE-2026-8795
pkg: windows

published: Jun 9, 2026

A YAML injection vulnerability exists in the Windows.Collectors.Remapping artifact of Rapid7 Velociraptor before version 0.76.6. The hostname field in client_info.json inside a collection ZIP is inserted into a YAML template via Go's text/template without escaping. An attacker providing a crafted co…
CWE: CWE-74, CWE-94, CWE-116
NVD

HIGH
CVE-2026-46311
CVE-2026-46311
pkg: linux

published: Jun 8, 2026

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu/userq: fix access to stale wptr mapping

Use drm_exec to take both locks i.e vm root bo and
wptr_obj bo to access the mapping data properly.

This fixes the security issue of unmap the wptr_obj while
a queue creation is …

NVD

HIGH
CVE-2026-46280
CVE-2026-46280
pkg: linux

published: Jun 8, 2026

In the Linux kernel, the following vulnerability has been resolved:

lib: test_hmm: evict device pages on file close to avoid use-after-free

Patch series "Minor hmm_test fixes and cleanups".

Two bugfixes a cleanup for the HMM kernel selftests. These were mostly
reported by Zenghui Yu with special…

NVD

HIGH
CVE-2026-46277
CVE-2026-46277
pkg: linux

published: Jun 8, 2026

In the Linux kernel, the following vulnerability has been resolved:

mm/zone_device: do not touch device folio after calling ->folio_free()

The contents of a device folio can immediately change after calling
->folio_free(), as the folio may be reallocated by a driver with a
different order. Instea…

NVD

HIGH
CVE-2026-46275
CVE-2026-46275
pkg: linux

published: Jun 8, 2026

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths

Vulnerabilities leading to Use-After-Free (UAF) and Null Pointer
Dereference (NPD) conditions were observed in the lifecycle management
of hci_uart.

The pr…

NVD

HIGH
CVE-2026-46274
CVE-2026-46274
pkg: linux

published: Jun 8, 2026

In the Linux kernel, the following vulnerability has been resolved:

io-wq: check that the predecessor is hashed in io_wq_remove_pending()

io_wq_remove_pending() needs to fix up wq->hash_tail[] if the cancelled
work was the tail of its hash bucket. When doing this, it checks whether
the preceding e…

GitHub-GHSA

HIGH
Radius Controller May Delete a Container Resource via an Injected Deployment Annotation (Multi-Tenant Installs)
GHSA-fp5j-4fj2-4jvq
pkg: github.com/radius-project/radius
eco: go
published: Jun 12, 2026
# Radius Controller May Delete a Container Resource via an Injected Deployment Annotation (Multi-Tenant Installs)

## Summary

A configuration-validation issue in the Radius Kubernetes controller can cause it to issue a `DELETE` for the container resource referenced by a tampered `radapp.io/status` …

CVE-2026-53999
GitHub-GHSA

HIGH
Budibase: SSRF via OAuth2 Config Validation — Missing fetchWithBlacklist Protection
GHSA-g6qx-g4pr-92v7
pkg: @budibase/server
eco: npm
published: Jun 12, 2026
### Summary

The OAuth2 token fetch function in `packages/server/src/sdk/workspace/oauth2/utils.ts` (line 59) uses raw `fetch(config.url)` with **no SSRF protection**. The safe wrapper `fetchWithBlacklist()` exists in the same codebase and is used in every other outbound HTTP call (automation steps,…

CVE-2026-48146
NVD

HIGH
CVE-2026-50567
CVE-2026-50567
pkg: kubernetes

published: Jun 10, 2026

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.25.0, Unarchive in pkg/utils/zip.go joined each archive entry name with the destination directory via filepath.Join and wrote the result wi…
CWE: CWE-22
NVD

HIGH
CVE-2026-49823
CVE-2026-49823
pkg: kubernetes

published: Jun 10, 2026

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, a Fission Function spec carries three reference types — Secret, ConfigMap, and Package. The first two were namespace-validated by t…
CWE: CWE-284, CWE-863
NVD

HIGH
CVE-2026-49822
CVE-2026-49822
pkg: kubernetes

published: Jun 10, 2026

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, a low-privilege developer who could create a KubernetesWatchTrigger (KWT) in their own namespace was able to establish a persistent s…
CWE: CWE-284, CWE-862
NVD

HIGH
CVE-2026-49821
CVE-2026-49821
pkg: kubernetes

published: Jun 10, 2026

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, Fission's buildermgr controller processed Package CRDs without verifying that Package.spec.environment.namespace matched Package.meta…
CWE: CWE-441, CWE-862
GitHub-GHSA

HIGH
OpenTelemetry Operator for Kubernetes's ServiceMonitor bearerTokenFile reads arbitrary local file and sends contents as bearer auth
GHSA-cxh2-4639-vmc5
pkg: github.com/open-telemetry/opentelemetry-operator
eco: go
published: Jun 10, 2026
## Affected

Repository: github.com/open-telemetry/opentelemetry-operator
Component: cmd/otel-allocator (TargetAllocator)
Companion: Prometheus Operator API types (CRDs)

## Summary

OpenTelemetry Operator's TargetAllocator watches `ServiceMonitor` resources via the Prometheus Operator CR watcher an…

CVE-2026-47701
GitHub-GHSA

HIGH
File Browser has incorrect access control for public directory shares via rule path rebasing
GHSA-j9jx-hp4c-ghhh
pkg: github.com/filebrowser/filebrowser/v2, github.com/filebrowser/filebrowser
eco: go
published: Jun 12, 2026
### Summary
File Browser's public share handlers rebase the share owner's filesystem root to the shared directory and then evaluate descendant paths against the owner's global and per-user rules using the rebased relative path instead of the original path relative to the owner's scope.

As a result,…

CVE-2026-54091
GitHub-GHSA

HIGH
Budibase: Webhook schema endpoint authorization bypass allows unauthenticated mutation of webhook and automation schema
GHSA-qhv3-wjg8-6fx6
pkg: @budibase/server
eco: npm
published: Jun 12, 2026
The webhook schema-building endpoint is registered under `builderRoutes`, but the generic authorization middleware skips authorization for all paths matching `/api/webhooks/schema`. As a result, an unauthenticated caller can update the body schema for a known webhook and mutate the corresponding aut…
CVE-2026-48151
NVD

HIGH
CVE-2026-50010
CVE-2026-50010
pkg: netty netty

published: Jun 12, 2026

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SimpleTrustManagerFactory.engineGetTrustManagers() and related paths wrap any user-supplied plain X509TrustManager in X509TrustManagerWrapper, which extends X50…
CWE: CWE-347
NVD

HIGH
CVE-2026-45416
CVE-2026-45416
pkg: netty netty

published: Jun 12, 2026

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SslClientHelloHandler.decode() reads the 24-bit TLS handshake length and, when the ClientHello does not fit in the first record, eagerly allocates `ctx.alloc().…
CWE: CWE-770
GitHub-GHSA

HIGH
Russh SSH message fields were decoded through allocation-first parsers before field-specific bounds
GHSA-4r3c-5hpg-58qr
pkg: russh
eco: rust
published: Jun 11, 2026
# SSH message fields were decoded through allocation-first parsers before field-specific bounds

### Summary

Several `russh` client and server message handlers decoded attacker-controlled SSH strings, name-lists, and byte fields into owned allocations before applying field-specific bounds. A remote…

CVE-2026-48110
NVD

HIGH
CVE-2026-44496
CVE-2026-44496
pkg: axios axios

published: Jun 11, 2026

Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and before 1.16.0 on the 1.x line build a regular expression from the configured XSRF cookie name without escaping regex metacharacters. In standard browser environments, an attacker who ca…
CWE: CWE-400, CWE-1333
NVD

HIGH
CVE-2026-44488
CVE-2026-44488
pkg: axios axios

published: Jun 11, 2026

Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce configured request and response size limits when requests were sent with the fetch adapter. Applications that selected adapter: 'fetch', or ran in environments where axios resolved t…
CWE: CWE-770
NVD

HIGH
CVE-2026-44487
CVE-2026-44487
pkg: axios axios

published: Jun 11, 2026

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapter may forward a Proxy-Authorization header to a redirected origin during specific proxy-to-direct redirect flows. This affects Node.js usage, where an initial HTTP request is se…
CWE: CWE-201
NVD

HIGH
CVE-2026-44486
CVE-2026-44486
pkg: axios axios

published: Jun 11, 2026

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapter can leak proxy credentials to a redirect target in affected versions. When a request is sent through an authenticated proxy, Axios may add a Proxy-Authorization header. If Axio…
CWE: CWE-200
GitHub-GHSA

HIGH
@grpc/grpc-js: A malformed request can cause a server crash
GHSA-5375-pq7m-f5r2
pkg: @grpc/grpc-js, @grpc/grpc-js, @grpc/grpc-js
eco: npm
published: Jun 11, 2026
### Impact
An invalid incoming HTTP/2 stream initiation can cause a server process to crash. This affects all servers created using @grpc/grpc-js.

### Patches
The following version have fixes for this vulnerability:

– 1.9.16
– 1.10.12
– 1.11.4
– 1.12.7
– 1.13.5
– 1.14.4

### Workarounds
Ther…

CVE-2026-48068
GitHub-GHSA

HIGH
@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash
GHSA-99f4-grh7-6pcq
pkg: @grpc/grpc-js, @grpc/grpc-js, @grpc/grpc-js
eco: npm
published: Jun 11, 2026
### Impact
An invalid incoming compressed message can cause a client or server process to crash. This affects all clients and servers that use @grpc/grpc-js

### Patches
The following version have fixes for this vulnerability:

– 1.9.16
– 1.10.12
– 1.11.4
– 1.12.7
– 1.13.5
– 1.14.4

### Workar…

CVE-2026-48069
NVD

HIGH
CVE-2026-46679
CVE-2026-46679
pkg: node

published: Jun 10, 2026

libp2p is a JavaScript Implementation of libp2p networking stack. Prior to version 15.0.23, three cooperating omissions in @libp2p/gossipsub allow an unauthenticated single peer to exhaust the Node.js heap of any gossipsub node with default options. This issue has been patched in version 15.0.23.
CWE: CWE-20, CWE-400, CWE-401
NVD

HIGH
CVE-2026-45783
CVE-2026-45783
pkg: node

published: Jun 10, 2026

libp2p is a JavaScript Implementation of libp2p networking stack. Prior to version 16.2.6, an unauthenticated remote peer can exhaust the disk storage of any @libp2p/kad-dht node running in server mode by sending an unbounded stream of PUT_VALUE messages whose keys bypass all content validation. No …
CWE: CWE-20, CWE-400
GitHub-GHSA

HIGH
Acknowledgement extension out of memory
GHSA-cqgj-h8vf-4w59
pkg: org.cometd.java:cometd-java-server-common, org.cometd.java:cometd-java-server-common, org.cometd.java:cometd-java-server-common
eco: maven
published: Jun 10, 2026
### Impact
Bad clients that always send a fixed batch value while the server is using the acknowledgement extension can cause the unacknowledged message queue to grow indefinitely, eventually resulting in an OutOfMemoryError.

Such bad clients would always send:

“`json
{
"channel": "/meta/connec…

CVE-2025-53114
NVD

HIGH
CVE-2025-71330
CVE-2025-71330
pkg: node

published: Jun 10, 2026

image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted ICNS image buffer. Attackers can craft an ICNS buffer containing valid magic bytes and a zero-valued entry length field to tri…
CWE: CWE-835
NVD

HIGH
CVE-2025-71329
CVE-2025-71329
pkg: node

published: Jun 10, 2026

image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF…
CWE: CWE-835
NVD

HIGH
CVE-2026-46545
CVE-2026-46545
pkg: node

published: Jun 10, 2026

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.5.0, a remote, unauthenticated denial-of-service vulnerability in MerkleRadixTrie::put_chunk allows any state-sync peer to crash any node performing state synchronizatio…
CWE: CWE-248
NVD

HIGH
CVE-2026-46541
CVE-2026-46541
pkg: node

published: Jun 10, 2026

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.4.0, iIn handle_dht_get(), the DhtResults accumulator is only initialized when the first DHT record passes verification. If the first record fails (from a malicious DHT …
CWE: CWE-754
NVD

HIGH
CVE-2026-44716
CVE-2026-44716
pkg: pipecat pipecat

published: Jun 10, 2026

Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. From version 0.0.90 to before version 1.2.0, a path traversal vulnerability exists in Pipecat's development runner (src/pipecat/runner/run.py). When the runner is started with the –folder f…
CWE: CWE-22
NVD

HIGH
CVE-2025-71319
CVE-2025-71319
pkg: node

published: Jun 9, 2026

image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF…
CWE: CWE-835
NVD

HIGH
CVE-2026-9076
CVE-2026-9076
pkg: openssl

published: Jun 9, 2026

Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap)
processes attacker-supplied CMS data, an attacker-chosen stream-mode KEK
cipher can trigger a heap out-of-bounds read in kek_unwrap_key().

Impact summary: A heap buffer over-read may trigger a crash which leads to
Denial…

CWE: CWE-125
NVD

HIGH
CVE-2026-45445
CVE-2026-45445
pkg: ssl

published: Jun 9, 2026

Issue summary: When an application drives an AES-OCB context through the
public EVP_Cipher() one-shot interface, the application-supplied
initialisation vector (IV) is silently discarded.

Impact summary: Every message encrypted under the same key uses the
same effective nonce regardless of the IV s…

CWE: CWE-325
NVD

HIGH
CVE-2026-42908
CVE-2026-42908
pkg: windows

published: Jun 9, 2026

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
CWE: CWE-125
NVD

HIGH
CVE-2026-42765
CVE-2026-42765
pkg: openssl

published: Jun 9, 2026

Issue summary: When a partial-chain certificate verification is enabled
together with OCSP response checking for the whole chain, a NULL dereference
will happen if the verified chain does not have a self-signed trusted anchor,
crashing the process.

Impact summary: A NULL pointer dereference can tri…

CWE: CWE-476
NVD

HIGH
CVE-2026-42764
CVE-2026-42764
pkg: ssl

published: Jun 9, 2026

Issue summary: Receiving a QUIC initial packet with an invalid token may
trigger a NULL pointer dereference in the OpenSSL QUIC server with
address validation disabled.

Impact summary: NULL pointer dereference typically causes abnormal termination
of the affected QUIC server process and a Denial of…

CWE: CWE-476
NVD

HIGH
CVE-2026-34183
CVE-2026-34183
pkg: openssl

published: Jun 9, 2026

Issue summary: Remote peer may exhaust heap memory of the QUIC
server or client by flooding it with packets containing PATH_CHALLENGE
frames.

Impact summary: A malicious remote peer can cause an unbounded
memory allocation which can lead to an abnormal termination of the
application acting as a QUI…

CWE: CWE-1325
NVD

HIGH
CVE-2026-34180
CVE-2026-34180
pkg: openssl

published: Jun 9, 2026

Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive
element whose content exceeds 2 gigabytes in length may cause a heap buffer
over-read on 64-bit Unix and Unix-like platforms.

Impact summary: The heap buffer over-read may crash the application (Denial of
Service) or to l…

CWE: CWE-125
NVD

HIGH
CVE-2026-41850
CVE-2026-41850
pkg: vmware spring_framework

published: Jun 9, 2026

Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algorithmic Denial of Service (DoS). By providing a specially crafted expression, an attacker can trigger excessive resource consumption during evaluation, leading to application degradation o…
CWE: CWE-407
NVD

HIGH
CVE-2026-41849
CVE-2026-41849
pkg: vmware spring_framework

published: Jun 9, 2026

An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker can exploit this by supplying a specially crafted SpEL expression that triggers excessive resource consumption, resulting in a Denial of Service (DoS).

Affected versions:
Spring Fr…

CWE: CWE-190
NVD

HIGH
CVE-2026-11667
CVE-2026-11667
pkg: google chrome, apple macos, linux linux_kernel

published: Jun 9, 2026

Out of bounds read in WebRTC in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the GPU process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-125
NVD

HIGH
CVE-2026-11644
CVE-2026-11644
pkg: google chrome, linux linux_kernel

published: Jun 9, 2026

Use after free in Views in Google Chrome on Linux prior to 149.0.7827.103 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-11641
CVE-2026-11641
pkg: google chrome, microsoft windows

published: Jun 9, 2026

Use after free in Bluetooth in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-11639
CVE-2026-11639
pkg: google chrome, apple macos

published: Jun 9, 2026

Use after free in Compositing in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-11636
CVE-2026-11636
pkg: google chrome, microsoft windows

published: Jun 9, 2026

Use after free in Autofill in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

HIGH
CVE-2026-11632
CVE-2026-11632
pkg: google chrome, apple macos, linux linux_kernel

published: Jun 9, 2026

Use after free in TabStrip in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
GitHub-GHSA

HIGH
Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections
GHSA-2vqw-3mp8-cgmx
pkg: puma, puma
eco: rubygems
published: Jun 9, 2026
### Impact

Puma is vulnerable to source IP spoofing when `set_remote_address proxy_protocol: :v1` is enabled and persistent connections are used.

PROXY protocol v1 is a connection-level protocol. [Support was added to Puma in v5.5.0](https://github.com/puma/puma/issues/2651). A proxy sends one PRO…

CVE-2026-47737
GitHub-GHSA

HIGH
Puma PROXY Protocol v1 Parser Allows Remote Memory Exhaustion
GHSA-qpgp-93vx-g8v8
pkg: puma, puma
eco: rubygems
published: Jun 8, 2026
### Impact

[PROXY protocol support for Puma](https://github.com/puma/puma/issues/2651) was added in version 5.5.0.

When PROXY protocol v1 support is enabled, Puma reads incoming bytes into an internal buffer. It waits for "\r\n" to determine whether a PROXY v1 line is present. If an attacker opens…

CVE-2026-47736
GitHub-GHSA

HIGH
Netty: SCTP reassembly nests buffers without bound
GHSA-5xrh-qmmq-w6ch
pkg: io.netty:netty-transport-sctp, io.netty:netty-transport-sctp
eco: maven
published: Jun 8, 2026
For each non-complete SctpMessage fragment the handler does `fragments.put(streamId, Unpooled.wrappedBuffer(frag, byteBuf))`, wrapping the previous accumulator and the new slice into a *new* CompositeByteBuf every time. After N fragments the accumulator is an N-deep chain of composites, each holding…
CVE-2026-46340
GitHub-GHSA

HIGH
Netty: SNI handler pre-allocates up to 16 MiB from nine attacker bytes
GHSA-x4gw-5cx5-pgmh
pkg: io.netty:netty-handler, io.netty:netty-handler
eco: maven
published: Jun 8, 2026
SslClientHelloHandler.decode() reads the 24-bit TLS handshake length and, when the ClientHello does not fit in the first record, eagerly allocates `ctx.alloc().buffer(handshakeLength)` (line 161). The guard at line 140 is `handshakeLength > maxClientHelloLength && maxClientHelloLength != 0`, and the…
CVE-2026-45416
GitHub-GHSA

HIGH
Netty's Default QUIC token handler accepts any client-supplied token
GHSA-cmm3-54f8-px4j
pkg: io.netty:netty-codec-classes-quic
eco: maven
published: Jun 8, 2026
NoQuicTokenHandler is the tokenHandler used when the application does not set one. Its writeToken() returns false (server will not send Retry — acceptable), but validateToken() unconditionally `return 0`. In QuicheQuicServerCodec.handlePacket(), a non-negative return from validateToken() is interp…
CVE-2026-44894
NVD

HIGH
CVE-2026-40519
CVE-2026-40519
pkg: nginx

published: Jun 8, 2026

Nginx Proxy Manager versions 2.9.14 through 2.15.1, fixed in commit a5db5ed, contain an authenticated remote code execution vulnerability via OS command injection in the setupCertbotPlugins() function in backend/setup.js, allowing attackers with certificates:manage permission to execute arbitrary co…
CWE: CWE-78
GitHub-GHSA

HIGH
Netty: HAProxy SSL TLV parsing leaks retained slice on invalid TLV length
GHSA-cc37-9q2j-3hfv
pkg: io.netty:netty-codec-haproxy, io.netty:netty-codec-haproxy
eco: maven
published: Jun 8, 2026
When decoding a PP2_TYPE_SSL TLV, HAProxyMessage.readNextTLV() first calls `header.retainedSlice(header.readerIndex(), length)` and only then reads the 1-byte client field and 4-byte verify field. If the attacker sets the TLV length below 5, the subsequent readByte/readInt throws IndexOutOfBoundsExc…
CVE-2026-44893
GitHub-GHSA

HIGH
Netty has a Vulnerable Default Configuration Which Leads to Denial of Service via Unbounded HTTP/3 Header Size
GHSA-c2rx-5r8w-8xr2
pkg: io.netty:netty-codec-http3
eco: maven
published: Jun 8, 2026
### Summary
The default configuration of the `Http3ConnectionHandler` in the Netty HTTP/3 codec lacks an enforced maximum header size limit. When a peer does not explicitly specify `HTTP3_SETTINGS_MAX_FIELD_SECTION_SIZE`, the implementation defaults to an unbounded limit. This insecure default confi…
CVE-2026-44892
GitHub-GHSA

HIGH
Netty has Unbounded Direct Memory Consumption in its RedisDecoder
GHSA-6ghj-frrj-jjj3
pkg: io.netty:netty-codec-redis, io.netty:netty-codec-redis
eco: maven
published: Jun 8, 2026
### Summary
An attacker can cause DoS by sending crafted Redis payloads across multiple connections without `\r\n`. This exhausts the server's direct memory pool (OutOfDirectMemoryError), preventing legitimate connections from being processed.

### Details
io.netty.handler.codec.redis.RedisDecoder d…

CVE-2026-44890
GitHub-GHSA

HIGH
Netty: Memory Exhaustion in RedisArrayAggregator due to Deeply Nested Arrays
GHSA-3244-j874-rhc2
pkg: io.netty:netty-codec-redis, io.netty:netty-codec-redis
eco: maven
published: Jun 8, 2026
### Summary
An attacker can cause DoS by sending a crafted Redis payload with deeply nested arrays. This forces the server to allocate a massive number of state objects and collections, leading to memory exhaustion and an OutOfMemoryError.

### Details
io.netty.handler.codec.redis.RedisArrayAggregat…

CVE-2026-44250
NVD

HIGH
CVE-2026-46306
CVE-2026-46306
pkg: linux

published: Jun 8, 2026

In the Linux kernel, the following vulnerability has been resolved:

flow_dissector: do not dissect PPPoE PFC frames

RFC 2516 Section 7 states that Protocol Field Compression (PFC) is NOT
RECOMMENDED for PPPoE. In practice, pppd does not support negotiating
PFC for PPPoE sessions, and the flow diss…

NVD

HIGH
CVE-2026-46304
CVE-2026-46304
pkg: linux

published: Jun 8, 2026

In the Linux kernel, the following vulnerability has been resolved:

nvmet: avoid recursive nvmet-wq flush in nvmet_ctrl_free

nvmet_tcp_release_queue_work() runs on nvmet-wq and can drop the
final controller reference through nvmet_cq_put(). If that triggers
nvmet_ctrl_free(), the teardown path flu…

GitHub-GHSA

HIGH
Routinator crashes when sending a maliciously crafted select-asn query parameter
GHSA-gc6q-cwcj-3vh9
pkg: routinator
eco: rust
published: Jun 8, 2026
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes.

This only affects users who allow API access from untrusted networks.

CVE-2026-49234
NVD

HIGH
CVE-2026-34181
CVE-2026-34181
pkg: openssl

published: Jun 9, 2026

Issue Summary: The PKCS#12 file processing fails to perform sufficient input
validation for files that use Password-Based Message Authentication Code 1
(PBMAC1) integrity mechanism allowing a certificate and private key forgery.

Impact Summary: An attacker impersonating a user can cause a service r…

CWE: CWE-354
NVD

HIGH
CVE-2026-48546
CVE-2026-48546
pkg: node

published: Jun 11, 2026

KanaDojo before 0.1.18 contains a sandbox escape vulnerability that allows an attacker to execute arbitrary code by exploiting the explicit passing of the global require function into a Node.js vm.runInNewContext() sandbox context in the issue-auto-respond.yml workflow. Attackers can submit a pull r…
CWE: CWE-693
NVD

HIGH
CVE-2026-11417
CVE-2026-11417
pkg: node

published: Jun 10, 2026

OS command injection in the NodejsFunction local bundling pipeline in aws-cdk-lib before 2.245.0 (2.246.0 on Windows) might allow an actor who controls the value of one or more bundling properties (externalModules, define, loader, inject, or esbuildArgs) to execute arbitrary commands on the host run…
CWE: CWE-78
GitHub-GHSA

HIGH
Anyquery has Path Traversal through `clear_plugin_cache`, Allowing Arbitrary Directory Deletion
GHSA-j9rx-rppg-6hh4
pkg: github.com/julien040/anyquery
eco: go
published: Jun 10, 2026
# Path Traversal in `clear_plugin_cache` Allows Arbitrary Directory Deletion

| Field | Value |
| —————- | —– |
| Repository | julien040/anyquery |
| Affected version | 0.4.4 |
| Vulnerability | CWE-22 — Improper Limitation of a Pathname to a Restricted Directory |…

CVE-2026-47253
NVD

HIGH
CVE-2026-42306
CVE-2026-42306
pkg: docker

published: Jun 12, 2026

Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior to version 2.0.0-beta.14, a race condition during docker cp mount setup allows a malicious container to redirect a bind mount target to an arbitrary ho…
CWE: CWE-61, CWE-367
GitHub-GHSA

HIGH
GeoServer has an arbitrary file write vulnerability in its Master Password Dump Page
GHSA-7qmg-grcp-qf25
pkg: org.geoserver.web:gs-web-app, org.geoserver.web:gs-web-sec-core, org.geoserver.web:gs-web-sec-core
eco: maven
published: Jun 12, 2026
### Summary
A vulnerability exists that allows an authenticated administrator with access to GeoServer's security system to pass arbitrary file names to the Master Password Dump web page and create files containing the master password in plaintext. The provided file name must be an absolute path to …
CVE-2025-52465
NVD

HIGH
CVE-2026-53816
CVE-2026-53816
pkg: openclaw openclaw

published: Jun 11, 2026

OpenClaw before 2026.5.18 contains an insufficient provenance validation vulnerability in node event handling that allows paired nodes to forge exec lifecycle events without system.run authorization. A malicious or compromised paired node can send crafted node.event messages to the gateway, steering…
CWE: CWE-862
GitHub-GHSA

HIGH
GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection
GHSA-g628-r368-6vh7
pkg: org.geoserver.extension:gs-db2
eco: maven
published: Jun 11, 2026
## Summary

Administrator can perform JNDI attack through specially crafted DB2 jdbc url leading to Remote Code Execution (RCE).

## Impact

If GeoServer has DB2 extension installed, this vulnerability can lead to executing arbitrary code.

## Details

Authenticated users can access Vector Data Sour…

CVE-2025-27511
GitHub-GHSA

HIGH
WsgiDAV encoded dot segments can escape filesystem share roots
GHSA-wxq4-cc2q-338q
pkg: wsgidav
eco: pip
published: Jun 11, 2026
### Impact
WsgiDAV 4.3.3 can allow a WebDAV request path containing an encoded parent-directory segment to escape the configured filesystem share root in a specific path layout.

### Patches
The issue is fixed with version 4.3.4.

### Preconditions

The practical impact depends on the deployment.

T…

CVE-2026-48099
GitHub-GHSA

HIGH
Nezha has cross-site GET request that can trigger stored cron commands on a victim's agents
GHSA-8qhj-4f8c-j8qg
pkg: github.com/nezhahq/nezha
eco: go
published: Jun 10, 2026
### Summary

The dashboard exposes the cron manual-trigger action as an authenticated `GET /api/v1/cron/:id/manual` endpoint. Dashboard JWTs are sent in the `nz-jwt` cookie and configured with `SameSite=Lax`, which browsers include on top-level cross-site GET navigations. Because this state-changing…

CVE-2026-49396
NVD

HIGH
CVE-2026-53674
CVE-2026-53674
pkg: express

published: Jun 10, 2026

BuddyPress 14.4.0 contains a regular expression injection vulnerability in the activity mention resolver that, when username compatibility mode is enabled, allows attackers to manipulate a REGEXP database clause by crafting mention names containing regex metacharacters. Attackers can submit @mention…
CWE: CWE-943
NVD

HIGH
CVE-2026-44495
CVE-2026-44495
pkg: axios

published: Jun 11, 2026

Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already polluted Object.prototype.transformResponse, affecte…
CWE: CWE-94, CWE-1321
NVD

HIGH
CVE-2026-42984
CVE-2026-42984
pkg: microsoft windows_10_1809, microsoft windows_10_21h2, microsoft windows_10_22h2

published: Jun 9, 2026

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CWE: CWE-416
NVD

HIGH
CVE-2026-42912
CVE-2026-42912
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Jun 9, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CWE: CWE-362
NVD

HIGH
CVE-2026-42911
CVE-2026-42911
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Jun 9, 2026

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CWE: CWE-416
NVD

HIGH
CVE-2026-41108
CVE-2026-41108
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Jun 9, 2026

Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally.
CWE: CWE-122
NVD

HIGH
CVE-2026-34335
CVE-2026-34335
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Jun 9, 2026

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CWE: CWE-416
NVD

HIGH
CVE-2026-46299
CVE-2026-46299
pkg: linux

published: Jun 8, 2026

In the Linux kernel, the following vulnerability has been resolved:

hfsplus: fix held lock freed on hfsplus_fill_super()

hfsplus_fill_super() calls hfs_find_init() to initialize a search
structure, which acquires tree->tree_lock. If the subsequent call to
hfsplus_cat_build_key() fails, the functio…

GitHub-GHSA

HIGH
File Browser has a DoS Vulnerability via Public Login API
GHSA-w5fm-68j4-fpc4
pkg: github.com/filebrowser/filebrowser/v2, github.com/filebrowser/filebrowser
eco: go
published: Jun 12, 2026
### Summary
Unchecked passwords maximums allow for an arbitrarily large password to be passed into the login API. This spikes CPU and memory, and after testing, crashes, heavily lags any container created, and has even made my docker daemon start to send errors with status code 500 even after the co…
CVE-2026-54092
GitHub-GHSA

HIGH
File Browser has a Command Execution Allowlist Bypass via Shell Metacharacter Injection
GHSA-8c9q-7855-wfxq
pkg: github.com/filebrowser/filebrowser/v2
eco: go
published: Jun 12, 2026
> [!NOTE]
> **This feature has been disabled by default for all installations from v2.33.8 onwards, including for existent installations**. To exploit this vulnerability, the instance administrator must turn on a feature and ignore all the warnings about known vulnerabilities. We're publishing this …
CVE-2026-54090
GitHub-GHSA

HIGH
File Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existent Path
GHSA-3q2p-72cj-682c
pkg: github.com/filebrowser/filebrowser/v2, github.com/filebrowser/filebrowser
eco: go
published: Jun 12, 2026
### Summary
This is similar vulnrability of **`CVE-2026-0035`**, which was fixed in Android `MediaProvider` with **high** severity. In the original Java issue, `MediaStore.createWriteRequest()` accepted attacker-controlled URIs and created a future grant even when the referenced media item did not e…
CVE-2026-54096
GitHub-GHSA

HIGH
File Browser: Cross-user unauthorized share-link deletion via unbounded prefix match in DeleteWithPathPrefix
GHSA-5ww9-jg6q-38r7
pkg: github.com/filebrowser/filebrowser, github.com/filebrowser/filebrowser/v2
eco: go
published: Jun 12, 2026
### Summary
A low-privileged authenticated user of filebrowser (with `create` + `delete` permissions in their own isolated scope) can silently destroy share-link records belonging to any other user — including the administrator — by performing a legitimate DELETE on a file in their own directory…
CVE-2026-54097
GitHub-GHSA

HIGH
PyO3 has an Out-of-bounds Read in `nth` / `nth_back` for `PyList` and `PyTuple` iterators
GHSA-36hh-v3qg-5jq4
pkg: pyo3
eco: rust
published: Jun 12, 2026
PyO3 0.24.0 added optimized implementations of `Iterator::nth` and `DoubleEndedIterator::nth_back` for the `BoundListIterator` and `BoundTupleIterator` types. These implementations computed the target index using unchecked `usize` addition (`index + n`) before bounds-checking against the sequence le…
GitHub-GHSA

HIGH
Chisel has an ACL Bypass via Post-Handshake SSH Channel ExtraData Injection
GHSA-24fp-5v3p-rvpw
pkg: github.com/jpillora/chisel
eco: go
published: Jun 12, 2026
### Summary

Authenticated chisel clients can bypass `–authfile` ACL restrictions and tunnel traffic to arbitrary destinations reachable from the server. The ACL is enforced only during the initial handshake against declared remotes, but never on subsequent SSH channels that carry actual traffic. A…

CVE-2026-48113
GitHub-GHSA

HIGH
DevGuard has improper authorization on public assets
GHSA-6p54-fw2f-q7gf
pkg: github.com/l3montree-dev/devguard
eco: go
published: Jun 11, 2026
### Impact

On a DevGuard API instance with one or more **public assets**, any authenticated user — including users from a different organization with no membership or role in the affected org/project — can create, update, reapply, and delete **VEX rules** on those public assets. The same flaw a…

CVE-2026-48089
GitHub-GHSA

HIGH
Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion
GHSA-h2qv-fj59-j46j
pkg: io.netty:netty-codec-haproxy, io.netty:netty-codec-haproxy
eco: maven
published: Jun 11, 2026
### Impact
The HAProxy PROXY protocol v2 codec in netty leaks native or heap memory on every connection when a client sends a syntactically valid header containing nested `PP2_TYPE_SSL` TLVs (type-length-value records) at depth two or greater. The leak occurs on the successful parse path — no exce…
CVE-2026-48059
GitHub-GHSA

HIGH
Arc: Unauthenticated access to Go debug pprof endpoints leaks runtime state and enables CPU-burn DoS
GHSA-j93g-rp6m-j32m
pkg: github.com/basekick-labs/arc
eco: go
published: Jun 11, 2026
### Summary

Arc registers Go's `net/http/pprof` handlers at `/debug/pprof/*` via `app.Use(pprof.New())` in `internal/api/server.go`, and `/debug/pprof` is added to `PublicPrefixes` in `cmd/arc/main.go`. The auth middleware short-circuits before the token check on prefix match, so the endpoints are …

CVE-2026-48050
GitHub-GHSA

HIGH
Traefik has a StripPrefix Route-Level Auth Bypass via Path Normalization
GHSA-xf64-8mw2-4gr2
pkg: github.com/traefik/traefik/v2, github.com/traefik/traefik/v3, github.com/traefik/traefik/v3
eco: go
published: Jun 11, 2026
## Summary

There is a high severity vulnerability in Traefik's `StripPrefix` middleware that allows an unauthenticated attacker to bypass route-level authentication and authorization. When a public router matches on a `PathPrefix` rule and applies the `StripPrefix` middleware, a request path contai…

CVE-2026-48020
GitHub-GHSA

HIGH
Element Call reports full URLs of visited pages to analytics server
GHSA-6vhh-4xw6-h2h2
pkg: @element-hq/element-call-embedded
eco: npm
published: Jun 11, 2026
### Impact

Element Call versions 0.5.17 through 0.19.3 report analytics data to a PostHog server, when configured to by a `posthog` key in config.json or by the `posthogApiHost` and `posthogApiKey` URL parameters. Several fields of this data (`$initial_person_info`, `$session_entry_url`, and `$curr…

CVE-2026-48007
GitHub-GHSA

HIGH
Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator
GHSA-6jv9-x5w9-2ccm
pkg: io.netty:netty-codec-redis, io.netty:netty-codec-redis
eco: maven
published: Jun 11, 2026
### Impact
The RedisArrayAggregator handler permanently leaks pooled direct-memory buffers when a Redis pipeline connection closes before a RESP array aggregate completes. The handler retains child messages in per-handler state (`depths` field) but defines no `channelInactive`, `handlerRemoved`, or …
CVE-2026-48006
GitHub-GHSA

HIGH
PDM: Project-Controlled `.pdm-plugins` Content Executes Before CLI Parsing
GHSA-qq6c-99pv-prvf
pkg: pdm
eco: pip
published: Jun 11, 2026
## Summary

PDM automatically loads project-local plugin paths from `.pdm-plugins` during `Core` initialization. Because this path is added via `site.addsitedir()`, attacker-controlled `.pth` files inside the project plugin directory are processed and can execute Python code before normal CLI handli…

CVE-2026-47781
GitHub-GHSA

HIGH
PDM wheel installation leads to Path Traversal via overridden write_to_fs
GHSA-78v8-vpjp-cjqh
pkg: pdm
eco: pip
published: Jun 10, 2026
InstallDestination.write_to_fs() in src/pdm/installers/installers.py overrides the base class to add symlink/hardlink support but replaces the safe _path_with_destdir() (which validates via Path.resolve() + is_relative_to()) with a bare os.path.join() that performs no path validation. A malicious wh…
CVE-2026-47764
GitHub-GHSA

HIGH
@hulumi/drift: Drift classifier fails open on adapter errors and over-promotes Mixed verdicts
GHSA-32g3-35g9-wc9g
pkg: @hulumi/drift
eco: npm
published: Jun 10, 2026
**Affected:** `@hulumi/drift` `< 1.4.0` — **Fixed in:** `1.4.0` — **Severity:** Medium — **CWE-755 (Improper Handling of Exceptional Conditions)**

#### Summary

`@hulumi/drift` runs four adapters that each ask a different question about whether a resource has drifted (Pulumi-state diff, provi…

CVE-2026-48036
GitHub-GHSA

HIGH
@hulumi/baseline: AccountFoundation audit-delivery S3 bucket could be silently weakened
GHSA-2mxr-p26x-mj73
pkg: @hulumi/baseline
eco: npm
published: Jun 10, 2026
**Affected:** `@hulumi/baseline` `< 1.4.0` — **Fixed in:** `1.4.0` — **Severity:** High — **CWE-1059 (Insufficient Technical Documentation / Behavioral Inconsistency)**

#### Summary

The S3 bucket that `AccountFoundation` creates to receive CloudTrail and AWS Config audit logs is meant to be …

CVE-2026-48035
GitHub-GHSA

HIGH
@hulumi/policies has a HULUMI-H5 bypass via decoy sibling resources targeting a different bucket
GHSA-9vc9-4jv3-rf86
pkg: @hulumi/policies
eco: npm
published: Jun 10, 2026
**Affected:** `@hulumi/policies` `< 1.4.0` — **Fixed in:** `1.4.0` — **Severity:** High — **CWE-284 (Improper Access Control)**

#### Summary

HULUMI-H1 forbids raw `aws:s3:Bucket` outside of Hulumi's `SecureBucket` component, with one exemption: a raw bucket that's a child of a `SecureBucket`…

CVE-2026-48034
GitHub-GHSA

HIGH
@hulumi/policies bypasses policy packs with a forged Pulumi-URN logical name
GHSA-rhgj-6g2c-frmm
pkg: @hulumi/policies
eco: npm
published: Jun 10, 2026
**Affected:** `@hulumi/policies` `< 1.4.0` — **Fixed in:** `1.4.0` — **Severity:** High — **CWE-693 (Protection Mechanism Failure)**

#### Summary

Pulumi gives every cloud resource a structured URN that includes the resource's type chain (`hulumi:baseline:aws:SecureBucket$aws:s3/bucketV2:Buck…

CVE-2026-48033
GitHub-GHSA

HIGH
@hulumi/policies bypasses IAM-role policy checks when the role trusts multiple OIDC providers
GHSA-g759-4pxw-6692
pkg: @hulumi/policies
eco: npm
published: Jun 10, 2026
**Affected:** `@hulumi/policies` `< 1.4.0` — **Fixed in:** `1.4.0` — **Severity:** High — **CWE-697 (Incorrect Comparison)**

#### Summary

AWS IAM trust policies can list more than one federated identity provider — for example, a role that accepts BOTH GitHub Actions OIDC and Google's OIDC.…

CVE-2026-48032
GitHub-GHSA

HIGH
Arc has an authenticated arbitrary local-file read via DuckDB I/O functions that bypasses RBAC table-level checks
GHSA-p2j4-c4g6-rpf5
pkg: github.com/basekick-labs/arc
eco: go
published: Jun 8, 2026
### Summary

Arc's user-SQL validator (`internal/api/query.go:ValidateSQLRequest`) blocked only `read_parquet(` and `arc_partition_agg(` via regex denylist. The broader DuckDB I/O function family — `read_csv_auto`, `read_csv`, `read_json`, `read_json_auto`, `read_text`, `read_blob`, `glob`, `parqu…

CVE-2026-47735
GitHub-GHSA

HIGH
nebula-mesh: GET /api/v1/audit-log discloses all entries to any operator
GHSA-qm33-p5p9-f8vg
pkg: github.com/juev/nebula-mesh
eco: go
published: Jun 8, 2026
`internal/api/audit.go:12` — `handleGetAuditLog` does no admin check. The route is bearer-auth gated only; any operator API key returns the full audit log via `store.ListAuditEntries` (up to limit=1000). This includes cross-tenant actor names, host/CA/operator IDs, action timestamps, and masked-IP…
CVE-2026-47726
GitHub-GHSA

HIGH
nebula-mesh's web UI lacks CSRF tokens on /ui/* mutating endpoints
GHSA-273q-qgh5-wrj6
pkg: github.com/juev/nebula-mesh
eco: go
published: Jun 8, 2026
Every `/ui/*` POST / PUT / PATCH / DELETE route processes the request as soon as the session cookie validates. `SameSite=Lax` on the session cookie prevents most cross-site form submits but does not protect:

– top-level form-submit navigations from third-party pages (some browsers still send Lax co…

CVE-2026-47725
GitHub-GHSA

HIGH
nebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS, etc.)
GHSA-w7w5-5gcp-38rw
pkg: github.com/juev/nebula-mesh
eco: go
published: Jun 8, 2026
None of the response paths in `internal/web/` or `internal/api/` set the standard browser-security headers. `grep` for `Content-Security-Policy`, `X-Frame-Options`, `Strict-Transport-Security`, `X-Content-Type-Options`, `Referrer-Policy` returns zero matches across the codebase.

## Impact
The admin…

CVE-2026-47723
GitHub-GHSA

HIGH
nebula-mesh: Host advanced overrides allow YAML injection into agent config.yml
GHSA-7hp6-g3pq-3pc3
pkg: github.com/juev/nebula-mesh
eco: go
published: Jun 8, 2026
`internal/configgen/generator.go:86,108,119` interpolates the operator-supplied `ListenHost` and `TunDevice` fields raw into a `text/template` that produces the agent's `config.yml`. `internal/web/advanced.go:20-35` accepts both with only `strings.TrimSpace` — no character or shape validation.

##…

CVE-2026-47722
GitHub-GHSA

HIGH
Routinator has cache path traversal when processing the module component of rsync URIs
GHSA-33mj-99mg-8g73
pkg: routinator
eco: rust
published: Jun 8, 2026
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache.
CVE-2026-49233
GitHub-GHSA

HIGH
Routinator crashes when encountering maliciously crafted RRDP XML files
GHSA-5qf9-cf9c-hjc6
pkg: routinator
eco: rust
published: Jun 8, 2026
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes.
CVE-2026-49235
NVD

MEDIUM
CVE-2026-53523
CVE-2026-53523
pkg: oauth

published: Jun 12, 2026

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.0.0 to before version 2.2.0, the getRedirectURL function in oauth2.go:22-29 constructs the OAuth2 callback URL by concatenating the request's Host header with a fixed path, with zero valida…
CWE: CWE-601
GitHub-GHSA

MEDIUM
File Browser: Symlink following lets scoped users read, overwrite, and share files outside their filebrowser scope
GHSA-239w-m3h6-ch8v
pkg: github.com/filebrowser/filebrowser/v2, github.com/filebrowser/filebrowser
eco: go
published: Jun 12, 2026
## Summary

File Browser enforces per-user scope with `afero.NewBasePathFs(afero.NewOsFs(), scope)`, set up in `users/users.go`. This blocks lexical `../` traversal, but it does not stop the HTTP file handlers from following symbolic links before they open, serve, write, share, or list a file. As a …

CVE-2026-54094
GitHub-GHSA

MEDIUM
Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList()
GHSA-9r4w-jg96-92mv
pkg: github.com/google/go-attestation
eco: go
published: Jun 12, 2026
## Summary

`parseEfiSignatureList()` in `attest/internal/events.go` does not skip `SignatureHeaderSize` vendor bytes before reading `EFI_SIGNATURE_LIST` signature entries, violating UEFI specification section 31.4.1.

## Impact

For `hashSHA256SigGUID` lists, attacker-controlled vendor header bytes…

NVD

MEDIUM
CVE-2026-11628
CVE-2026-11628
pkg: google chrome, apple macos, linux linux_kernel

published: Jun 9, 2026

Use after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a local attacker to potentially exploit heap corruption via physical access to the device. (Chromium security severity: Critical)
CWE: CWE-416
GitHub-GHSA

MEDIUM
Netty: DNS Cache Poisoning due to Predictable PRNG and Default Static Source Port
GHSA-xmv7-r254-6q78
pkg: io.netty:netty-resolver-dns, io.netty:netty-resolver-dns
eco: maven
published: Jun 8, 2026
### Summary
Netty's DNS resolver uses a predictable PRNG for generating DNS transaction IDs and defaults to a static UDP source port. This combination reduces the entropy of DNS queries, enabling DNS Cache Poisoning (Kaminsky attack).

### Details
Two factors contribute to this vulnerability in io.n…

CVE-2026-45673
GitHub-GHSA

MEDIUM
LangGraph has NoSQL parameter injection in MongoDBSaver, allowing cross-tenant state access
GHSA-98xf-r82g-9mhx
pkg: @langchain/langgraph-checkpoint-mongodb
eco: npm
published: Jun 12, 2026
## Summary

A NoSQL injection vulnerability existed in `MongoDBSaver` where checkpoint identifier fields from `config.configurable` were used in MongoDB queries without strict type enforcement. In vulnerable versions, attacker-controlled object payloads (for example MongoDB operators like `$gt` and …

CVE-2026-48121
GitHub-GHSA

MEDIUM
Fleet: Observer-level enrollment secret extraction via ORDER BY oracle on Apple MDM commands endpoint
GHSA-x4qr-qw6h-wvxq
pkg: github.com/fleetdm/fleet/v4
eco: go
published: Jun 12, 2026
### Summary

A vulnerability in Fleet's Apple MDM commands listing endpoint allowed authenticated users with the lowest-privilege Observer role to extract sensitive values from joined database tables — including host enrollment secrets and Apple Push Notification Service (APNS) tokens — through …

CVE-2026-46371
GitHub-GHSA

MEDIUM
Fleet has observer-level enrollment secret extraction via ORDER BY oracle on labels host-listing endpoint
GHSA-vxm7-9x8v-8gm4
pkg: github.com/fleetdm/fleet/v4
eco: go
published: Jun 12, 2026
### Summary

A vulnerability in Fleet's labels host-listing endpoint allowed authenticated users with the lowest-privilege Observer role to extract host enrollment secrets (`node_key`, `orbit_node_key`) through a cursor-based binary search oracle. The endpoint accepted a user-supplied `order_key` pa…

CVE-2026-46370
GitHub-GHSA

MEDIUM
Budibase: Unanchored Regex in `matchers.ts` Allows CSRF Bypass via Query String Injection in Budibase Worker
GHSA-wxq7-x3qp-vcr8
pkg: @budibase/backend-core
eco: npm
published: Jun 12, 2026
### Summary

The `buildMatcherRegex()` / `matches()` functions in `packages/backend-core/src/middleware/matchers.ts` share the same structural root cause as the recently patched CVE-2026-31816: route patterns are compiled into **unanchored regular expressions** and tested against `ctx.request.url`, …

CVE-2026-48147
GitHub-GHSA

MEDIUM
GeoServer has a Server-Side Request Forgery (SSRF) Vulnerability in its XML Entity Resolution
GHSA-x4r9-gmw3-hxww
pkg: org.geoserver.web:gs-web-app, org.geoserver:gs-main, org.geoserver:gs-main
eco: maven
published: Jun 12, 2026
### Summary
A GeoServer that uses `ENTITY_RESOLUTION_ALLOWLIST` may allow attacker to perform unauthenticated Server-Side Request Forgery (SSRF).

### Details
This vulnerability requires that GeoServer is set up to use a proxy base URL and the `ENTITY_RESOLUTION_ALLOWLIST` (default since 2.25.0):

#…

CVE-2025-58175
NVD

MEDIUM
CVE-2026-50630
CVE-2026-50630
pkg: apache cxf

published: Jun 12, 2026

A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class. When constructing the WWW-Authenticate response header, the 'realm' parameter is concatenated without sanitizing Carriage Return (CR) and Line Feed (LF) characters. If an attacker can control the realm value, they can inje…
CWE: CWE-113
NVD

MEDIUM
CVE-2026-50623
CVE-2026-50623
pkg: apache cxf

published: Jun 12, 2026

An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF. Due to a missing 'throw' keyword in the security context check, the introspection endpoint (/services/oauth2/introspect) can be accessed by any unauthenticated network attacker. However note that th…
CWE: CWE-287
GitHub-GHSA

MEDIUM
Russh: Unchecked keyboard-interactive prompt count in client auth path
GHSA-g9g7-5cgw-6v28
pkg: russh
eco: rust
published: Jun 11, 2026
### Summary
In the `russh` client keyboard-interactive authentication path, a malicious SSH server could send a `USERAUTH_INFO_REQUEST` with an attacker-controlled prompt count, and the client would use that raw count directly in `Vec::with_capacity(…)` before validating that enough prompt data wa…
CVE-2026-48107
NVD

MEDIUM
CVE-2026-47157
CVE-2026-47157
pkg: python

published: Jun 11, 2026

aiograpi is an asynchronous Instagram API for Python. aiograpi versions before 0.9.10 accepted server-supplied signup challenge paths and used them to build request URLs before validating that the paths were relative Instagram API paths. If an attacker can influence a challenge response, for example…
CWE: CWE-918
GitHub-GHSA

MEDIUM
python-zeroconf: Unbounded TC-deferred queue allows LAN-local memory exhaustion via spoofed-source flood
GHSA-9663-mqmp-p9mm
pkg: zeroconf
eco: pip
published: Jun 11, 2026
### Impact

`AsyncListener.handle_query_or_defer` retained every truncated (TC-bit) incoming query in `self._deferred[addr]` and armed a per-addr timer in `self._timers[addr]` that flushed the reassembled query within ~500 ms (RFC 6762 §18.5). Neither the per-addr list nor the number of distinct `a…

CVE-2026-48045
GitHub-GHSA

MEDIUM
@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects
GHSA-x426-x7cc-3fpc
pkg: @hapi/wreck
eco: npm
published: Jun 11, 2026
### Impact
Wreck strips credential headers (Authorization, Cookie, Proxy-Authorization) before following a cross-origin redirect, but the origin check compares hostnames only and ignores scheme and port. As a result, credentials are forwarded intact across same-host port changes and HTTPS-to-HTTP do…
CVE-2026-48022
GitHub-GHSA

MEDIUM
vLLM's Artifact Pin Decay allows pinned deployments to load unpinned code, weights, and processors
GHSA-3ww4-5jv9-j5gm
pkg: vllm
eco: pip
published: Jun 10, 2026
### Summary

vLLM's revision pinning controls do not consistently apply to all artifacts loaded for a model. A deployment that supplies `–revision` or `–code-revision` can still load dynamic code, GGUF files, image processors, retrieval side weights, or same-repository subfolder weights/config fro…

CVE-2026-47155
NVD

MEDIUM
CVE-2026-45561
CVE-2026-45561
pkg: nginx

published: Jun 10, 2026

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the /smon/agent/{version,uptime,status,checks}/<server_ip> family of routes takes the URL path component verbatim into requests.get(f'http://{server_ip}:{agent_port}/…'). The path …
CWE: CWE-918
GitHub-GHSA

MEDIUM
In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header
GHSA-xvfq-4q6q-gxx7
pkg: org.springframework.kafka:spring-kafka, org.springframework.kafka:spring-kafka, org.springframework.kafka:spring-kafka
eco: maven
published: Jun 10, 2026
When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending records with unique random spring.kafka.serialization.selector header values, eventually causing GC thrash and OutOfMemoryError.

Affected versions:
Spring for Apache Kafka 4.0.0 th…

CVE-2026-41726
NVD

MEDIUM
CVE-2026-9741
CVE-2026-9741
pkg: express

published: Jun 9, 2026

A bug in query analysis processing of the $vectorSearch aggregation stage for Queryable Encryption (QE) or Client-Side Field Level Encryption (CSFLE) results in literal values for encrypted fields within the $vectorSearch stage filter expressions to be sent to the server as plaintext instead of cip…
CWE: CWE-319
NVD

MEDIUM
CVE-2026-42907
CVE-2026-42907
pkg: microsoft windows_10_1809, microsoft windows_10_21h2, microsoft windows_10_22h2

published: Jun 9, 2026

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally.
CWE: CWE-200
NVD

MEDIUM
CVE-2026-42903
CVE-2026-42903
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Jun 9, 2026

Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a network.
CWE: CWE-476
NVD

MEDIUM
CVE-2026-11658
CVE-2026-11658
pkg: google chrome, apple macos, linux linux_kernel

published: Jun 9, 2026

Insufficient validation of untrusted input in Extensions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-20
NVD

MEDIUM
CVE-2026-11653
CVE-2026-11653
pkg: google chrome, apple macos, linux linux_kernel

published: Jun 9, 2026

Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-20
NVD

MEDIUM
CVE-2026-39908
CVE-2026-39908
pkg: windows

published: Jun 8, 2026

OpenBullet2 through version 0.3.2 on Windows contains a credential disclosure vulnerability that allows remote attackers to capture the NTLMv2 hash of the process user by configuring a job proxy source with a UNC path pointing to an attacker-controlled server. When the job starts, the application at…
CWE: CWE-522
NVD

MEDIUM
CVE-2026-40985
CVE-2026-40985
pkg: express

published: Jun 11, 2026

Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions.

Affected versions:
Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1.

CWE: CWE-917
NVD

MEDIUM
CVE-2026-12210
CVE-2026-12210
pkg: python

published: Jun 15, 2026

A vulnerability was detected in universal-tool-calling-protocol python-utcp 1.1.0. This affects an unknown function of the component utcp-gql/utcp-websocket. Performing a manipulation results in server-side request forgery. The attack can be initiated remotely. The exploit is now public and may be u…
CWE: CWE-918
GitHub-GHSA

MEDIUM
FUXA's scheduler API missing admin check enables operator-to-admin escalation via scheduled device actions
GHSA-8ghr-w65f-j3qr
pkg: fuxa-server
eco: npm
published: Jun 8, 2026
## Summary

An authorization issue in the Scheduler API allowed authenticated non-admin users to create or modify scheduled actions that should be restricted to administrators.

## Details

The Scheduler API did not correctly enforce administrator permissions when processing scheduler modifications.…

CVE-2026-47721
GitHub-GHSA

MEDIUM
GeoNode contains a server-side request forgery vulnerability in the service registration endpoint
GHSA-hw9r-6m78-w6h3
pkg: geonode, geonode
eco: pip
published: Jun 8, 2026
GeoNode versions 4.4.5 and 5.0.2 (and prior within their respective releases) contain a server-side request forgery vulnerability in the service registration endpoint that allows authenticated attackers to trigger outbound network requests to arbitrary URLs by submitting a crafted service URL during…
CVE-2026-39922
NVD

MEDIUM
CVE-2026-42771
CVE-2026-42771
pkg: openssl

published: Jun 9, 2026

Issue summary: When the X509_VERIFY_PARAM_set1_email is called by an
application to validate a crafted e-mail address, such as during S/MIME
message validation, an out of bounds read can happen.

Impact summary: This out of bounds read will not directly exfiltrate
the data read to the attacker so th…

CWE: CWE-125
NVD

MEDIUM
CVE-2026-41568
CVE-2026-41568
pkg: docker

published: Jun 12, 2026

Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior to version 2.0.0-beta.14, a race condition during docker cp mount setup allows a malicious container to create empty files or directories at arbitrary …
CWE: CWE-81, CWE-367
NVD

MEDIUM
CVE-2026-47250
CVE-2026-47250
pkg: kubernetes

published: Jun 11, 2026

mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to version 3.7.0, the kubectl_generic tool in mcp-server-kubernetes passes user-supplied flags directly to kubectl without any allowlist, enabling a privilege escalation attack within Kubernetes environ…
CWE: CWE-88
NVD

MEDIUM
CVE-2026-45566
CVE-2026-45566
pkg: nginx

published: Jun 10, 2026

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the login flow allow-lists next URLs by rejecting strings containing https:// or http:// substrings, then constructs https://{request.host}{next_url} and the JS client redirects via …
CWE: CWE-601
NVD

MEDIUM
CVE-2026-45560
CVE-2026-45560
pkg: nginx

published: Jun 10, 2026

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, wrap_line (app/modules/common/common.py:181-186) and highlight_word (app/modules/common/common.py:188-192) build raw HTML by string concatenation with no escaping. The frontend (app/…
CWE: CWE-79
NVD

MEDIUM
CVE-2026-41715
CVE-2026-41715
pkg: react

published: Jun 9, 2026

In specific scenarios involving HTTP redirects from a secure to an insecure endpoint, the Reactor Netty HTTP client may leak credentials. In order for this to happen, the HTTP client must have been explicitly configured to follow redirects.

Affected versions:
Reactor Netty 1.0.0 through 1.0.51; 1.1…

CWE: CWE-522
GitHub-GHSA

MEDIUM
gorest InMemorySecret2FA race condition allows process crash via concurrent map access (CWE-362)
GHSA-cpwg-x64r-rgwg
pkg: github.com/pilinux/gorest
eco: go
published: Jun 12, 2026
## Vulnerability: CWE-362 — Concurrent Map Access Race Condition in InMemorySecret2FA

**CWE:** CWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization)

### Affected Component
– `github.com/pilinux/gorest` — Go REST API boilerplate
– InMemorySecret2FA — in-memory 2FA…

CVE-2026-48154
GitHub-GHSA

MEDIUM
Litestar: AllowedHostsMiddleware bypasses host validation via client-controlled X-Forwarded-Host header
GHSA-3qmc-cj7q-62hv
pkg: litestar
eco: pip
published: Jun 10, 2026
### Summary

`AllowedHostsMiddleware` trusts the `X-Forwarded-Host` header as a fallback when the `Host` header is absent. Since `X-Forwarded-Host` is a client-controllable header, an attacker can bypass the allowed hosts validation by omitting the `Host` header and supplying an `X-Forwarded-Host` h…

CVE-2026-48061
NVD

MEDIUM
CVE-2026-41696
CVE-2026-41696
pkg: express

published: Jun 10, 2026

Spring Data MongoDB repository query methods annotated with @Query that use regex parameter binding perform insufficient validation of the bound parameter. An attacker can supply a crafted string to break out of the intended regular expression quoting.

Affected versions:
Spring Data MongoDB 5.0.0 t…

CWE: CWE-943
NVD

MEDIUM
CVE-2026-42767
CVE-2026-42767
pkg: openssl

published: Jun 9, 2026

Issue summary: An attacker-controlled CMP (Certificate Management Protocol)
server could trigger a NULL pointer dereference in a CMP client application.

Impact summary: A NULL pointer dereference causes a crash of the
application and a Denial of Service.

An attacker controlling a CMP server (or ac…

CWE: CWE-476
NVD

MEDIUM
CVE-2026-42766
CVE-2026-42766
pkg: openssl

published: Jun 9, 2026

Issue summary: A specially crafted password-encrypted CMS message
can trigger a NULL pointer dereference during CMS decryption.

Impact summary: This NULL pointer dereference leads to an application crash
and a Denial of Service.

The CMS PasswordRecipientInfo.keyDerivationAlgorithm field is defined…

CWE: CWE-476
GitHub-GHSA

MEDIUM
Kolibri has Unauthenticated Server-Side Request Forgery (SSRF) in RemoteFacilityUserViewset
GHSA-4mj9-pf4r-cqrc
pkg: kolibri
eco: pip
published: Jun 11, 2026
## Summary

Several Kolibri API endpoints accept an unvalidated `baseurl` parameter and fetch attacker-controlled URLs from the Kolibri server, reflecting the response body back to the caller. The original report identified two endpoints on the `RemoteFacilityUser*` viewsets; remediation review foun…

CVE-2026-48053
NVD

MEDIUM
CVE-2026-53723
CVE-2026-53723
pkg: node

published: Jun 11, 2026

Guzzle Services provides an implementation of the Guzzle Command library that uses Guzzle service descriptions to describe web services, serialize requests, and parse responses into easy to use model structures. Versions prior ro 1.5.4 do not safely serialize scalar XML element values containing the…
CWE: CWE-20, CWE-91
NVD

MEDIUM
CVE-2026-42915
CVE-2026-42915
pkg: microsoft windows_10_21h2, microsoft windows_10_22h2, microsoft windows_11_23h2

published: Jun 9, 2026

Incorrect calculation of buffer size in Windows TCP/IP allows an authorized attacker to deny service over an adjacent network.
CWE: CWE-131
GitHub-GHSA

MEDIUM
Dulwich has unbounded memory allocation in receive-pack from crafted thin packs
GHSA-xrvj-v92f-53gj
pkg: dulwich
eco: pip
published: Jun 8, 2026
## Impact

An uncontrolled-resource-consumption (memory exhaustion) denial-of-service vulnerability (CWE-400 / CWE-789).

A client with push access could push a tiny crafted thin pack (~174 bytes) whose delta header declares a huge dest_size. When dulwich ingested it via add_thin_pack / apply_de…

CVE-2026-47734
GitHub-GHSA

MEDIUM
nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs)
GHSA-9pg3-25fq-p6cc
pkg: github.com/juev/nebula-mesh
eco: go
published: Jun 10, 2026
`internal/web/operators.go:251` — after `handleOperatorCreateAPIKey` mints a fresh 32-byte bearer token, the redirect points the operator's browser at:

/ui/operators/<id>?new_key=<raw-token>&key_name=<name>

The raw API key ends up:
– in the browser's URL history
– in the `Referer` header on …

CVE-2026-47768
NVD

MEDIUM
CVE-2026-42973
CVE-2026-42973
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Jun 9, 2026

Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally.
CWE: CWE-200
NVD

MEDIUM
CVE-2026-42972
CVE-2026-42972
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Jun 9, 2026

Exposure of sensitive information to an unauthorized actor in Windows Hyper-V allows an authorized attacker to disclose information locally.
CWE: CWE-200
NVD

MEDIUM
CVE-2026-42971
CVE-2026-42971
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Jun 9, 2026

Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally.
CWE: CWE-200
NVD

MEDIUM
CVE-2026-42970
CVE-2026-42970
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Jun 9, 2026

Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally.
CWE: CWE-200
NVD

MEDIUM
CVE-2026-42969
CVE-2026-42969
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Jun 9, 2026

Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally.
CWE: CWE-908
NVD

MEDIUM
CVE-2026-42968
CVE-2026-42968
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Jun 9, 2026

Out-of-bounds read in Windows Telephony Service allows an authorized attacker to disclose information locally.
CWE: CWE-125
NVD

MEDIUM
CVE-2026-42906
CVE-2026-42906
pkg: microsoft windows_10_21h2, microsoft windows_10_22h2, microsoft windows_11_23h2

published: Jun 9, 2026

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally.
CWE: CWE-200
NVD

MEDIUM
CVE-2026-45581
CVE-2026-45581
pkg: tls

published: Jun 8, 2026

fabric-chaincode-java is a Java based implementation of Hyperledger Fabric chaincode shim APIs. From version 2.3.1 to before version 2.5.10, when chaincode is deployed in chaincode-as-a-service mode with TLS enabled, the chaincode server INFO level logging includes the TLS private key password in pl…
CWE: CWE-532
GitHub-GHSA

MEDIUM
Fabric.js improper escaping in fabric.Gradient colorStops leads to XSS in SVG serialization
GHSA-w22m-hvvm-xmwx
pkg: fabric
eco: npm
published: Jun 12, 2026
### Summary

A potential Cross-Site Scripting (XSS) vulnerability exists in Fabric.js due to improper escaping of user-controlled input during SVG serialization via the `toSVG()` method.

Specifically, the `color` field within the `colorStops` array of a `fabric.Gradient` object is not properly esca…

CVE-2026-44311
NVD

MEDIUM
CVE-2026-53722
CVE-2026-53722
pkg: nuxt nuxt

published: Jun 12, 2026

Nuxt is an open-source web development framework for Vue.js. Prior to versions 3.21.7 and 4.4.7, <NuxtLink> did not validate the URL scheme of values bound to its to or href props before rendering them into the href attribute of the underlying <a> element. When an application binds attacker-controll…
CWE: CWE-79, CWE-83
NVD

MEDIUM
CVE-2026-11666
CVE-2026-11666
pkg: google chrome, apple macos, linux linux_kernel

published: Jun 9, 2026

Insufficient validation of untrusted input in Input in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-20
GitHub-GHSA

MEDIUM
Authlib OAuth 2.0 has Open Redirect in Authorization API that allows attacker-controlled redirect_uri through unsupported response_type
GHSA-w8p2-r796-3vmq
pkg: authlib, authlib
eco: pip
published: Jun 8, 2026
### Summary
Authlib's OAuth 2.0 authorization endpoint can be turned into an unauthenticated open redirect when a request uses an unsupported response_type and supplies an attacker-controlled redirect_uri.

The vulnerable behavior happens before client lookup and before any redirect URI validation. …

CVE-2026-41479
NVD

MEDIUM
CVE-2026-50629
CVE-2026-50629
pkg: apache cxf

published: Jun 12, 2026

The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages without sanitizing control characters. This allows an attacker to inject arbitrary content, including fake log entries, into the server's log files. Users are recommended to upgrade…
CWE: CWE-93
GitHub-GHSA

MEDIUM
Russh: SSH identification parsing accepted non-canonical client banners and did not bound pre-banner input
GHSA-76r6-x97p-67vr
pkg: russh
eco: rust
published: Jun 11, 2026
### Summary

`russh` did not enforce the SSH identification-string rules as deliberately as OpenSSH. In particular, the server-side identification reader used the same permissive path as the client, allowing pre-banner lines from clients, and the reader did not enforce a bounded number of pre-banner…

CVE-2026-48108
GitHub-GHSA

MEDIUM
@hapi/inert has a static-file confinement bypass via sibling-prefix path
GHSA-rcvq-m9j9-6f4g
pkg: @hapi/inert
eco: npm
published: Jun 11, 2026
### Impact
`@hapi/inert` serves static files from a directory configured with `path` (in the `directory` / `file` handlers) or `relativeTo` (for `h.file()`), with confinement enforced by the `confine` option (default `true`). Before the patch, the confinement check compared the resolved absolute pat…
CVE-2026-48049
GitHub-GHSA

MEDIUM
netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion
GHSA-c2gf-v879-257j
pkg: io.netty:netty-codec-http2, io.netty:netty-codec-http2
eco: maven
published: Jun 11, 2026
### Impact

The `DelegatingDecompressorFrameListener` class orchestrates HTTP/2 decompression by embedding a per-stream `EmbeddedChannel` that runs the appropriate decompression codec (gzip, deflate, zstd) and forwards decompressed chunks to a wrapped listener. Each decompressed chunk is a pooled `B…

CVE-2026-48043
GitHub-GHSA

MEDIUM
joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas
GHSA-q7cg-457f-vx79
pkg: joi, joi
eco: npm
published: Jun 11, 2026
### Impact
Denial of service via untrapped exception in services validating user-supplied JSON / object input with recursive link schemas.

The blast radius depends on how the application invokes joi:
– Highest impact: `validate()` called without `try/catch` in a request handler would cause an unha…

CVE-2026-48038
NVD

MEDIUM
CVE-2026-48108
CVE-2026-48108
pkg: openssh

published: Jun 10, 2026

Russh is a Rust SSH client & server library. From version 0.34.0-beta.1 to before version 0.61.0, russh did not enforce the SSH identification-string rules as deliberately as OpenSSH. In particular, the server-side identification reader used the same permissive path as the client, allowing pre-banne…
CWE: CWE-20
GitHub-GHSA

MEDIUM
Nezha's private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data
GHSA-vrmh-5mmx-hjwx
pkg: github.com/nezhahq/nezha
eco: go
published: Jun 10, 2026
# Private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data

**CWE**: CWE-285 (Improper Authorization) via CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) and CWE-863 (Incorrect Authorization — inconsistent gating acr…

CVE-2026-49397
NVD

MEDIUM
CVE-2026-46543
CVE-2026-46543
pkg: node

published: Jun 10, 2026

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.5.0, a remote peer can crash any full node by sending a RequestBatchSet message containing the genesis block's hash. The handler calls get_epoch_chunks which iterates ba…
CWE: CWE-617
NVD

MEDIUM
CVE-2026-42914
CVE-2026-42914
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Jun 9, 2026

Windows Kerberos Denial of Service Vulnerability
CWE: CWE-125
NVD

MEDIUM
CVE-2026-42769
CVE-2026-42769
pkg: openssl

published: Jun 9, 2026

Issue Summary: An error in the callback used to verify the certificate
provided in a Root CA key update Certificate Management Protocol (CMP)
message response rendered the certificate validation ineffectual, which
could lead to escalation of credentials from the Registration Authority (RA)
level to …
CWE: CWE-295
NVD

MEDIUM
CVE-2026-41851
CVE-2026-41851
pkg: vmware spring_framework

published: Jun 9, 2026

Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack if the evaluation of a SpEL expression triggers unbounded cache growth.

Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 th…

CWE: CWE-770
NVD

MEDIUM
CVE-2026-11696
CVE-2026-11696
pkg: google chrome, microsoft windows

published: Jun 9, 2026

Uninitialized Use in Video in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-457
NVD

MEDIUM
CVE-2026-11669
CVE-2026-11669
pkg: google chrome, google chrome_os

published: Jun 9, 2026

Out of bounds read in Media in Google Chrome on ChromeOS prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-472
GitHub-GHSA

MEDIUM
FUXA has SQL Injection in its TDengine DAQ connector via backslash bypass of escapeTdString
GHSA-h9fj-c2qr-76g2
pkg: fuxa-server
eco: npm
published: Jun 8, 2026
## Summary

The TDengine DAQ storage connector's `escapeTdString` at `server/runtime/storage/tdengine/index.js:10` doubles single quotes but does not escape backslashes. TDengine's SQL parser treats `\'` as a literal single quote inside a string, so a tag id of the form `x\' OR 1=1–` escapes the fi…

CVE-2026-47720
GitHub-GHSA

MEDIUM
Netty HTTP/2: Advertised MAX_CONCURRENT_STREAMS are not enforced
GHSA-5x3r-wrvg-rp6q
pkg: io.netty:netty-codec-http2, io.netty:netty-codec-http2
eco: maven
published: Jun 8, 2026
### Impact
DefaultHttp2Connection.DefaultEndpoint initialises maxActiveStreams/maxStreams to Integer.MAX_VALUE, and Http2Settings never inserts SETTINGS_MAX_CONCURRENT_STREAMS by default (Http2Settings.java:305-307 only clamps a user-supplied value). Unless the application explicitly calls initialSe…
CVE-2026-47244
GitHub-GHSA

MEDIUM
OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poisoning
GHSA-8396-jffm-qx4w
pkg: github.com/openfga/openfga
eco: go
published: Jun 11, 2026
### Description
In OpenFGA, when iterator caching is enabled, two distinct check requests can produce the same cache key, leading to OpenFGA reusing an earlier cached result for a subsequent request.

### Preconditions
This applies if the following preconditions are present:

– FGA runs with SharedI…

CVE-2026-48096
NVD

MEDIUM
CVE-2026-35188
CVE-2026-35188
pkg: tls

published: Jun 9, 2026

Issue summary: A malicious server can exploit TLS OCSP stapling by delivering
a crafted response through the status_request extension, triggering a
double-free in the client's certificate verification path.

Impact summary: Successful exploitation allows an attacker to corrupt heap
memory via a doub…

CWE: CWE-415
NVD

MEDIUM
CVE-2026-50565
CVE-2026-50565
pkg: kubernetes

published: Jun 10, 2026

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, Fission builder pods were created with ServiceAccountName: fission-builder and no AutomountServiceAccountToken: false, so the kubelet…
CWE: CWE-250, CWE-269, CWE-538
NVD

MEDIUM
CVE-2026-45559
CVE-2026-45559
pkg: nginx

published: Jun 10, 2026

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, get_ldap_email (app/modules/roxywi/user.py:120-157) builds the LDAP search filter via f-string concatenation. The username URL path parameter is taken verbatim — no checkAjaxInput,…
CWE: CWE-90
NVD

MEDIUM
CVE-2026-44490
CVE-2026-44490
pkg: axios

published: Jun 11, 2026

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, axios exposes two read-side prototype-pollution gadgets. When Object.prototype is polluted by an upstream dependency in the same process (e.g. lodash _.merge / CVE-2018-16487), axios silently picks up the p…
CWE: CWE-1321
NVD

MEDIUM
CVE-2026-45446
CVE-2026-45446
pkg: openssl

published: Jun 9, 2026

Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV
(RFC 8452) mishandle the authentication of AAD (Additional Authenticated
Data) with an empty ciphertext allowing a forgery of such messages.

Impact summary: An attacker can forge empty messages with arbitrary AAD
to the victim…

CWE: CWE-325
NVD

MEDIUM
CVE-2026-50569
CVE-2026-50569
pkg: kubernetes

published: Jun 10, 2026

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.25.0, HTTPTriggerSpec.Validate() validated Methods, FunctionReference, Host, IngressConfig, and CorsConfig, but silently skipped RelativeUR…
CWE: CWE-20
NVD

MEDIUM
CVE-2026-45563
CVE-2026-45563
pkg: nginx

published: Jun 10, 2026

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, GET /history/<service>/<server_ip> re-uses the server_ip path parameter as a user-id when service == 'user', with no authorization check. Any authenticated user — even a guest in a…
CWE: CWE-639, CWE-863
NVD

MEDIUM
CVE-2026-11668
CVE-2026-11668
pkg: google chrome, google chrome_os, linux linux_kernel

published: Jun 9, 2026

Uninitialized Use in Codecs in Google Chrome on Linux, ChromeOS prior to 149.0.7827.103 allowed a remote attacker to leak cross-origin data via a crafted video file. (Chromium security severity: High)
CWE: CWE-457
NVD

MEDIUM
CVE-2026-11665
CVE-2026-11665
pkg: google chrome, microsoft windows

published: Jun 9, 2026

Out of bounds read in Dawn in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-125
NVD

MEDIUM
CVE-2026-41714
CVE-2026-41714
pkg: tls

published: Jun 10, 2026

Applications that configure their broker connection via RabbitConnectionFactoryBean.setUri("amqps://…") without also calling setUseSSL(true) get TLS encryption with no certificate validation and no hostname verification.

Affected versions:
Spring AMQP 4.0.0 through 4.0.3; 3.2.0 through 3.2.10; 3.…

CWE: CWE-295
GitHub-GHSA

MEDIUM
Netty: Unix-socket fd receive leaks descriptors when peer sends two at once
GHSA-w573-9ffj-6ff9
pkg: io.netty:netty-transport-native-epoll, io.netty:netty-transport-native-kqueue, io.netty:netty-transport-native-kqueue
eco: maven
published: Jun 8, 2026
netty_unix_socket_recvFd sets msg_control to `char control[CMSG_SPACE(sizeof(int))]` (line 940) — 24 bytes on 64-bit Linux. A peer-sent SCM_RIGHTS cmsg carrying two ints has cmsg_len = CMSG_LEN(8) = 24, which fits exactly with no MSG_CTRUNC, so the kernel installs both fds in the receiving process…
CVE-2026-45536
GitHub-GHSA

MEDIUM
pypdf: Possible long runtimes for zero-only width values in cross-reference streamsuntimes for zero-only width values in cross-reference streams
GHSA-248m-82v9-q6g6
pkg: pypdf
eco: pip
published: Jun 12, 2026
### Impact

An attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires cross-reference streams with `/W [0 0 0]` values and large `/Size` values.

### Patches

This has been fixed in [pypdf==6.12.0](https://github.com/py-pdf/pypdf/releases/tag/6.12.0).

### W…

CVE-2026-48156
GitHub-GHSA

MEDIUM
File Browser: FilePath traversal in download-as-zip/tar via Windows-style backslash separators in stored filenames
GHSA-gxjx-7m74-hcq8
pkg: github.com/filebrowser/filebrowser/v2, github.com/filebrowser/filebrowser
eco: go
published: Jun 12, 2026
### Summary
filebrowser builds the download-as-zip / download-as-tar archive entry names with `filepath.ToSlash`, which on a Linux host is a no-op for backslashes (`\` is only a path separator on Windows). A file whose name contains Windows-style traversal (`..\..\..\evil.txt`) is accepted by the re…
CVE-2026-54093
GitHub-GHSA

MEDIUM
ConnectBot SSH Client Library: Excessive allocation and integer overflow in DER private-key parsing
GHSA-vc8p-8pxg-rfwg
pkg: org.connectbot.sshlib:sshlib
eco: maven
published: Jun 12, 2026
## Summary

The DER parser used for application-supplied private keys did not safely validate encoded length values before converting them to `Int` values or allocating arrays.

A malformed private-key file could encode a length that overflowed or wrapped around, or request an allocation much larger…

GitHub-GHSA

MEDIUM
ConnectBot SSH Client Library: Unbounded SSH field lengths can cause excessive memory allocation
GHSA-ch3q-cw5r-f4hg
pkg: org.connectbot.sshlib:sshlib
eco: maven
published: Jun 12, 2026
## Summary

The SSH protocol parser trusted attacker-controlled length and count fields without first checking that the declared values fit within the containing packet.

When a client connects to a malicious or compromised SSH server, the server can send a small, malformed packet containing an inne…

GitHub-GHSA

MEDIUM
PyO3 has a missing `Sync` bound on `PyCFunction::new_closure` closures
GHSA-chgr-c6px-7xpp
pkg: pyo3
eco: rust
published: Jun 12, 2026
`PyCFunction::new_closure` (and the temporary `new_closure_bound` complement in the 0.21–0.22 series) required the supplied closure to be `Send + 'static` but not `Sync`. The resulting `PyCFunction` is a Python callable that can be invoked from any Python thread, which means the closure may be cal…
GitHub-GHSA

MEDIUM
pypdf: Possible large memory usage for large offsets for layout mode text
GHSA-cj93-chg6-vgv8
pkg: pypdf
eco: pip
published: Jun 12, 2026
### Impact

An attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires extracting text in layout mode with large character offsets.

### Patches

This has been fixed in [pypdf==6.12.0](https://github.com/py-pdf/pypdf/releases/tag/6.12.0).

### Workaround…

CVE-2026-48155
GitHub-GHSA

MEDIUM
Budibase: Unvalidated VectorDB Host Parameter Enables SSRF
GHSA-cv96-5348-p5p8
pkg: @budibase/server
eco: npm
published: Jun 12, 2026
### Summary

The VectorDB configuration endpoint in Budibase accepts a host parameter that undergoes no validation against internal IP ranges, reserved hostnames, or URL schemes. Any authenticated user with builder-level access can supply an arbitrary host value such as `169.254.169.254` or localhos…

CVE-2026-48148
GitHub-GHSA

MEDIUM
Budibase: SSRF via User-Controlled queryId in Automation Execute Query Step
GHSA-6964-pp88-6wp9
pkg: budibase
eco: npm
published: Jun 12, 2026
### Summary

The executeQuery automation step in Budibase accepts a queryId from automation step inputs and passes it directly to the query execution controller without additional validation. When combined with a REST datasource configured to target internal infrastructure, this creates a server-sid…

CVE-2026-48128
GitHub-GHSA

MEDIUM
netty-incubator-codec-ohttp's Incorrect Native Pointer Derivation in Pooled Direct ByteBuf Fallback Leads to Out-of-Bounds Native Memory Access
GHSA-32hf-8jw3-v4qq
pkg: io.netty.incubator:netty-incubator-codec-ohttp-hpke-native-boringssl
eco: maven
published: Jun 11, 2026
The netty-incubator-codec-ohttp library implements Oblivious HTTP (RFC 9458) using BoringSSL's HPKE C library via JNI. When deriving native memory addresses for cryptographic operations, provides a fallback path for direct ByteBufs that do not expose their memory address through `hasMemoryAddress()`…
CVE-2026-48040
GitHub-GHSA

MEDIUM
free5GC UDR has improper `ueId` validation in EE subscription handlers that allows arbitrary identifier persistence
GHSA-6gxq-gpr8-xgjp
pkg: github.com/free5gc/udr
eco: go
published: Jun 11, 2026
### Summary
The free5GC UDR accepts arbitrary non-3GPP ueId values in the EE subscription creation and query flows because the regular expression used for validation ends with the catch-all alternative |.+. This causes the validation logic to accept any non-empty string rather than restricting input…
CVE-2026-47780
GitHub-GHSA

MEDIUM
PDM: Project-Local State and Config Writes Follow Symlinks
GHSA-ghq2-5c67-fprm
pkg: pdm
eco: pip
published: Jun 10, 2026
## Summary

PDM writes several project-local state or configuration files without symlink protection. If a malicious repository places those files as symlinks, local PDM operations can overwrite the symlink targets.

This creates an arbitrary file clobber primitive relative to the privileges of the …

CVE-2026-47763
GitHub-GHSA

MEDIUM
Incus has a Nil-Pointer Dereference Panic via Instance Backup Import (volume omitted)
GHSA-8g7m-96c8-8wwc
pkg: github.com/lxc/incus/v7
eco: go
published: Jun 10, 2026
## Summary

`(*backend).CreateInstanceFromBackup` in [`internal/server/storage/backend.go`](https://github.com/lxc/incus/blob/1513600/internal/server/storage/backend.go) contains a nil-pointer dereference that an authenticated user with permission to create instances in any project can trigger remot…

CVE-2026-47753
GitHub-GHSA

MEDIUM
nebula-mesh: Session and OIDC state cookies lack the Secure attribute
GHSA-rqfj-vv8r-xhqc
pkg: github.com/juev/nebula-mesh
eco: go
published: Jun 10, 2026
`internal/web/session.go` and `internal/web/oidc.go` set `HttpOnly` and `SameSite=Lax` on every cookie but never `Secure`. A single plaintext request to the origin (operator on a LAN, mistyped URL, HTTP→HTTPS not strictly enforced, reverse proxy misconfiguration) discloses the session.

## Affecte…

CVE-2026-48058
GitHub-GHSA

MEDIUM
nebula-mesh: Decrypted CA private key persists in heap after signing
GHSA-8h84-fhqq-q58v
pkg: github.com/juev/nebula-mesh
eco: go
published: Jun 10, 2026
`internal/pki/resolver.go:36-64` constructs a `CAManager` with the plaintext `ed25519.PrivateKey` after unwrapping via the master key; `internal/pki/ca.go:13-16` stores it. Callers at `internal/api/enroll.go:116`, `internal/api/updates.go:297`, and `internal/api/mobile_bundle.go:40` use the manager …
CVE-2026-48025
GitHub-GHSA

MEDIUM
@hulumi/baseline: AccountFoundation reuse paths silently downgrade GuardDuty / Security Hub posture
GHSA-cj8g-prcm-mfg5
pkg: @hulumi/baseline
eco: npm
published: Jun 10, 2026
**Affected:** `@hulumi/baseline` `< 1.4.0` — **Fixed in:** `1.4.0` — **Severity:** Medium — **CWE-693 (Protection Mechanism Failure)**

#### Summary

`AccountFoundation` can either create AWS detective services (GuardDuty for threat detection, Security Hub for compliance dashboards) or reuse p…

CVE-2026-48037
GitHub-GHSA

MEDIUM
Net::IMAP: Command Injection via ID command argument
GHSA-46q3-7gv7-qmgg
pkg: net-imap, net-imap
eco: rubygems
published: Jun 9, 2026
### Summary

Two `Net::IMAP` commands, `#id` and `#enable`, do not validate their arguments. Arguments to either command could be used by an attacker to inject arbitrary IMAP commands.

Please note that passing untrusted inputs to these commands is usually inappropriate and expected to be uncommon.…

CVE-2026-47242
GitHub-GHSA

MEDIUM
Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument
GHSA-8p34-64r3-mwg8
pkg: net-imap, net-imap
eco: rubygems
published: Jun 9, 2026
Several Net::IMAP commands accept a "raw data" argument that is sent verbatim after validation to prevent command injection. However, if a server does not support non-synchronizing literals, it may still be possible to inject arbitrary IMAP commands inside non-synchronizing literals.

### Details

CVE-2026-47240
GitHub-GHSA

MEDIUM
actual Allows Electron to Run As Node
GHSA-7rvm-xjpp-63r9
pkg: actual
eco: npm
published: Jun 8, 2026
## Summary

A electron run as node vulnerability was identified in `actual` (macOS application, version `25.x (Electron 39.2.7)`).

**Vulnerability Type:** Electron Run As Node

## Description

ELECTRON_RUN_AS_NODE fuse enabled (Electron 39.2.7) — app can be converted to Node.js REPL for arbitrary…

CVE-2026-42890