Vulnerability Digest — August 17, 2026 · 54 Critical · 3 Exploited






Vulnerability Digest — Monday, August 17, 2026


Security Report

Monday, August 17, 2026  ·  Last 7 days  ·  Min severity: MEDIUM
Total Findings
289
Critical
54
High
153
Actively Exploited
3
CISA-KEV3
NVD244
GitHub-GHSA42
Findings sorted by severity
CISA-KEV

CRITICAL
Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
CVE-2026-68820
pkg: Microsoft Windows Ancillary Function Driver for WinSock

published: Aug 11, 2026

Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Metabase SQL Injection Vulnerability
CVE-2026-72898
pkg: Metabase Metabase

published: Aug 11, 2026

Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored c…
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability
CVE-2026-20349
pkg: Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)

published: Aug 11, 2026

Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
NVD

CRITICAL
CVE-2026-73678
CVE-2026-73678
pkg: python

published: Aug 14, 2026

MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by submitting crafted prompts to the unprotected POST /api/v1/responses/ endpoint, which reaches the Anton agent's …
CWE: CWE-94
NVD

CRITICAL
CVE-2026-73299
CVE-2026-73299
pkg: node

published: Aug 12, 2026

Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies with unrestricted JavaScript member access. An attacker-controlled template could traverse constructor and prototype properties…
CWE: CWE-94, CWE-1336
NVD

CRITICAL
CVE-2026-58115
CVE-2026-58115
pkg: node

published: Aug 11, 2026

A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to programming nodes that are c…
CWE: CWE-306
NVD

CRITICAL
CVE-2026-73269
CVE-2026-73269
pkg: node

published: Aug 12, 2026

A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, can trigger the creation of a cluster-scoped ClusterRoleBinding. This allows the user to escalate their privileges from namespace-local access to clust…
CWE: CWE-269
NVD

CRITICAL
CVE-2026-62420
CVE-2026-62420
pkg: node

published: Aug 12, 2026

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations. When moving an instance cross-project to a different cluster member via POST /1.0/instances/{name} with migration: true, project: <ta…
CWE: CWE-863
NVD

CRITICAL
CVE-2026-73263
CVE-2026-73263
pkg: kubernetes

published: Aug 12, 2026

Prowler is a cloud security platform. Prior to 5.36.0, the Kubernetes provider connection test accepted kubeconfig_content containing a legacy gcp auth-provider with config.cmd-path and config.cmd-args because kubeconfig_contains_exec_auth in api/src/backend/api/v1/serializers.py checked only exec b…
CWE: CWE-78
NVD

CRITICAL
CVE-2026-48765
CVE-2026-48765
pkg: oauth

published: Aug 11, 2026

TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege read collaborator to extract a workspace OAuth `credentialsId` from a readable bot configuration and then overwrite that credential through `handleUpdateOAuthCredentials()` by supplying an attacker-controlled writable …
CWE: CWE-639
NVD

CRITICAL
CVE-2026-72911
CVE-2026-72911
pkg: express

published: Aug 10, 2026

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.118.0 and 16.29.0, the validate_template and render_template calls in erpnext/accounts/doctype/process_statement_of_accounts/process_statement_of_accounts.py render subject, body, and pdf_name fields with unrestricted g…
CWE: CWE-1336
NVD

CRITICAL
CVE-2026-14450
CVE-2026-14450
pkg: kubernetes

published: Aug 10, 2026

A flaw was found in the MaaS API. This vulnerability allows any pod within the cluster to bypass the Kuadrant AuthPolicy gateway by forging HTTP headers, specifically `X-MaaS-Username` and `X-MaaS-Group`, which are trusted verbatim. This lack of first-party authentication enables an attacker to gain…
CWE: CWE-290
NVD

CRITICAL
CVE-2026-72901
CVE-2026-72901
pkg: docker

published: Aug 10, 2026

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated low-privilege member to execute arbitrary commands on the control-plane host because the volumeName field accepted by volumeBackup.create and volumeBackup.runManually is interpolated with…
CWE: CWE-78
NVD

CRITICAL
CVE-2026-72876
CVE-2026-72876
pkg: node

published: Aug 10, 2026

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, swarm.getNodes, swarm.getNodeInfo, swarm.getNodeApps, and swarm.getAppInfos in apps/dokploy/server/api/routers/swarm.ts accept another organization’s serverId without an activeOrganizationId ownership check, and getNo…
CWE: CWE-78, CWE-639, CWE-862
NVD

CRITICAL
CVE-2026-72869
CVE-2026-72869
pkg: docker

published: Aug 10, 2026

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC subscription passes the databaseName parameter to restore builders in packages/server/src/utils/restore/utils.ts, where PostgreSQL, MariaDB, MySQL, and MongoDB commands embed the va…
CWE: CWE-77, CWE-78
NVD

CRITICAL
CVE-2026-72868
CVE-2026-72868
pkg: docker

published: Aug 10, 2026

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, apps/dokploy/server/api/routers/destination.ts interpolates the accessKey, secretAccessKey, region, endpoint, provider, and bucket fields from destination.testConnection into an rclone ls command executed through child_…
CWE: CWE-78, CWE-862
NVD

CRITICAL
CVE-2026-72865
CVE-2026-72865
pkg: docker

published: Aug 10, 2026

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the compose.update operation stores an unvalidated composePath that packages/server/src/utils/builders/compose.ts and packages/server/src/services/compose.ts interpolate into docker compose -f, docker stack deploy -c, a…
CWE: CWE-78
NVD

CRITICAL
CVE-2026-72863
CVE-2026-72863
pkg: docker

published: Aug 10, 2026

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's WebSocket handlers (in-app terminals and log streamers) authenticate the session but never authorize it. They establish who the user is via validateRequest() and then proceed without consulting the role/permis…
CWE: CWE-269, CWE-639, CWE-862
NVD

CRITICAL
CVE-2026-72862
CVE-2026-72862
pkg: docker

published: Aug 10, 2026

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the mariadb.ts, mongo.ts, mysql.ts, postgres.ts, redis.ts, and libsql.ts Dokploy database service deployment functions pass user-controlled dockerImage fields unquoted into docker pull ${dockerImage} shell commands on t…
CWE: CWE-78
NVD

CRITICAL
CVE-2026-72736
CVE-2026-72736
pkg: docker

published: Aug 10, 2026

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy passes user-controlled values directly into shell commands via unquoted template literal interpolation in the registry credential testing and Docker Swarm cluster management endbpoints. Both endpoints have a saf…
CWE: CWE-77
NVD

CRITICAL
CVE-2026-74269
CVE-2026-74269
pkg: express

published: Aug 15, 2026

In the Linux kernel, the following vulnerability has been resolved:

bnxt: fix head underflow on XDP head-grow

The xdp.py test test_xdp_native_adjst_head_grow_data crashes when run on
a bnxt machine (and also crashes in NIPA).

It seems that the bug is an underflow in bnxt_rx_multi_page_skb, which

NVD

CRITICAL
CVE-2026-72317
CVE-2026-72317
pkg: tls

published: Aug 15, 2026

In the Linux kernel, the following vulnerability has been resolved:

SUNRPC: pin upper rpc_clnt across the TLS connect_worker

The TLS connect path has a use-after-free: nothing pins the
upper rpc_clnt across the delayed connect_worker. xs_connect()
stores task->tk_client in sock_xprt::clnt as a raw…

NVD

CRITICAL
CVE-2026-72222
CVE-2026-72222
pkg: tls

published: Aug 15, 2026

In the Linux kernel, the following vulnerability has been resolved:

sunrpc: pin svc_xprt across the asynchronous TLS handshake callback

svc_tcp_handshake() stores the raw svc_xprt pointer in
tls_handshake_args.ta_data and submits the request through
tls_server_hello_x509(). The handshake core take…

NVD

CRITICAL
CVE-2026-72221
CVE-2026-72221
pkg: tls

published: Aug 15, 2026

In the Linux kernel, the following vulnerability has been resolved:

sunrpc: wait for in-flight TLS handshake callback when cancel loses race

When wait_for_completion_interruptible_timeout() in
svc_tcp_handshake() returns 0 (timeout) or -ERESTARTSYS (signal) and
tls_handshake_cancel() then returns …

NVD

CRITICAL
CVE-2026-50027
CVE-2026-50027
pkg: oauth

published: Aug 14, 2026

mcp-memory-service is a semantic memory layer for AI applications. Prior to 10.67.1, all HTTP routes under /api/documents/* in mcp-memory-service are served without any authentication dependency, even when the server is configured with an API key (MCP_API_KEY) or OAuth. An unauthenticated remote att…
CWE: CWE-306
NVD

CRITICAL
CVE-2026-73649
CVE-2026-73649
pkg: express

published: Aug 13, 2026

Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for CVE-2026-44966 filtered constructor, __proto__, and prototype only in the #set assignment handler in src/compile/set.ts, while property-read expressions in src/compile/references.ts…
CWE: CWE-94
NVD

CRITICAL
CVE-2026-67614
CVE-2026-67614
pkg: jwt

published: Aug 13, 2026

CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote attackers to forge valid authentication tokens and obtain an interactive root shell via WebSocket on port 8888. Attackers can craft a forged JWT signed wit…
CWE: CWE-798
NVD

CRITICAL
CVE-2026-28185
CVE-2026-28185
pkg: go

published: Aug 13, 2026

Unauthenticated Broken Authentication in Log in with Google <= 1.4.2 versions.
CWE: CWE-345
NVD

CRITICAL
CVE-2026-28008
CVE-2026-28008
pkg: oauth

published: Aug 13, 2026

Unauthenticated Broken Authentication in OAuth Single Sign On – SSO (OAuth Client) <= 7.0.0 versions.
CWE: CWE-290
NVD

CRITICAL
CVE-2026-49819
CVE-2026-49819
pkg: jwt

published: Aug 13, 2026

UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerInitSuperuser` (`backend/pb/handlers.go:249`), reachable as `POST /api/upsnap/init-superuser`. The vulnerable code lacks any authentication, setup token…
CWE: CWE-78, CWE-269, CWE-306, CWE-862
NVD

CRITICAL
CVE-2026-73519
CVE-2026-73519
pkg: docker

published: Aug 12, 2026

WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs, allowing remote unauthenticated attackers to bypass authentication by supplying this value in the X-WolfStack-Secret header to the require_auth() gate…
CWE: CWE-798
NVD

CRITICAL
CVE-2026-73034
CVE-2026-73034
pkg: python

published: Aug 11, 2026

DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers to write arbitrary files to any location on the server by injecting directory traversal sequences into the user_id HTTP header of the Python file-upload endpoint. Attackers can send a crafted multipar…
CWE: CWE-22
NVD

CRITICAL
CVE-2026-73211
CVE-2026-73211
pkg: oauth

published: Aug 11, 2026

PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.1.6, ActorFollowModel.updateScore() interpolates the attacker-controlled ActivityPub actor inboxUrl into an SQL query, allowing an unauthenticated remote server to read and write PeerTube database tables, including oAuthToken.…
CWE: CWE-89
NVD

CRITICAL
CVE-2026-69102
CVE-2026-69102
pkg: jwt

published: Aug 11, 2026

MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in application-maxkey.properties that allows unauthenticated attackers to forge valid JWT tokens and authenticate as any user by exploiting the password-skipped login endpoint. Attackers can craft a JWT token…
CWE: CWE-798
NVD

CRITICAL
CVE-2026-72920
CVE-2026-72920
pkg: jwt

published: Aug 11, 2026

SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC service without mandatory authentication when jwt.filer_signing.key is unset, allowing any client that can reach the filer gRPC port to invoke CreateUser, CreateAccessKey, PutPolicy…
CWE: CWE-306
NVD

CRITICAL
CVE-2026-68160
CVE-2026-68160
pkg: go

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()

ceph_handle_caps() reads snap_trace_len from the wire-format
ceph_mds_caps header and uses it unconditionally to build a fake
end pointer (snaptrace + snaptr…

NVD

CRITICAL
CVE-2026-68127
CVE-2026-68127
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

ila: reload IPv6 header after pskb_may_pull in checksum adjust

ila_csum_adjust_transport() caches ip6h = ipv6_hdr(skb) before calling
pskb_may_pull(). On a non-linear skb whose transport header sits in a page
fragment, pskb_may_pu…

NVD

CRITICAL
CVE-2026-68123
CVE-2026-68123
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

openvswitch: fix GSO userspace truncation underflow

OVS_ACTION_ATTR_TRUNC currently stores a delta from the original skb
length in OVS_CB(skb)->cutlen. When a later userspace action segments a
GSO skb, queue_gso_packets() reuses t…

NVD

CRITICAL
CVE-2026-68117
CVE-2026-68117
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

tipc: clear sock->sk on the failed-insert path in tipc_sk_create()

When tipc_sk_create() fails to insert the new socket (tipc_sk_insert()
returns non-zero), its error path frees the sk with sk_free() but leaves
sock->sk pointing a…

NVD

CRITICAL
CVE-2026-73843
CVE-2026-73843
pkg: kubernetes

published: Aug 13, 2026

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, internal/cluster-gateway/server.go served caller-facing management APIs on the externally reachable agent listener without authentication, allowing network-reachable attackers to invoke /api/proxy/ and…
CWE: CWE-306, CWE-668, CWE-862
NVD

CRITICAL
CVE-2026-8715
CVE-2026-8715
pkg: kubernetes

published: Aug 13, 2026

Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissions to read files from the operator pod's filesystem and transmit their contents…
CWE: CWE-552
NVD

CRITICAL
CVE-2026-72877
CVE-2026-72877
pkg: docker

published: Aug 10, 2026

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the dockerImage field is interpolated without quoting into shell commands in buildRemoteDocker() in packages/server/src/utils/providers/docker.ts and is validated only as an optional string. An authenticated user with a…
CWE: CWE-78
NVD

CRITICAL
CVE-2026-68124
CVE-2026-68124
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

mctp: serial: handle zero-length frames to prevent rx buffer overflow

The MCTP serial receive state machine reads a frame length byte in
mctp_serial_push_header() case 2 and validates it upper-bound-only:

if (c > MCTP_SERIAL_FRA…

NVD

CRITICAL
CVE-2026-73653
CVE-2026-73653
pkg: vite

published: Aug 13, 2026

Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, takeScreenshot, screenshotMatcher, stopChunkTrace, deleteTracing, and annotateTraces accept browser-supplied file paths without enforcing the allowWrite …
CWE: CWE-22, CWE-552, CWE-862
NVD

CRITICAL
CVE-2026-50561
CVE-2026-50561
pkg: jwt

published: Aug 12, 2026

Yuxi is a large-model-based intelligent knowledge base and knowledge graph agent development platform. Prior to version 0.6.2, the project's authentication mechanism contains a flaw. In affected versions, the system does not sufficiently validate the identity token in the Authorization header — on…
CWE: CWE-287
NVD

CRITICAL
CVE-2026-50516
CVE-2026-50516
pkg: microsoft azure_kubernetes_service

published: Aug 11, 2026

Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
CWE: CWE-306
NVD

CRITICAL
CVE-2026-73080
CVE-2026-73080
pkg: jwt

published: Aug 11, 2026

SeaweedFS is a distributed storage system. Prior to 4.24, VolumeServer.FetchAndWriteNeedle in weed/server/volume_grpc_remote.go fetches a caller-supplied remote endpoint through weed/remote_storage/s3/s3_storage_client.go and writes the response into a needle. The RPC performs no authentication and …
CWE: CWE-918
GitHub-GHSA

CRITICAL
SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle
GHSA-87fv-vqqr-m4jr
pkg: github.com/seaweedfs/seaweedfs
eco: go
published: Aug 11, 2026
### Impact
`VolumeServer.FetchAndWriteNeedle` fetches a caller-supplied remote endpoint and writes the response into a needle. Before 4.24 this RPC performed no authentication and no validation of the target, so anyone able to reach a volume server's gRPC port could coerce the server into issuing re…
CVE-2026-73080
NVD

CRITICAL
CVE-2026-47754
CVE-2026-47754
pkg: node

published: Aug 10, 2026

Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.x through 2.19.1 and all 1.x versions contain an unauthenticated path traversal in the `archiveEntryName` parameter of the `action=read` endpoint that is part of the original 1.x Metacat API. `A…
CWE: CWE-22, CWE-862
NVD

CRITICAL
CVE-2026-49457
CVE-2026-49457
pkg: tls

published: Aug 14, 2026

erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and the hostname was not compared against the certificate,…
CWE: CWE-295, CWE-297
NVD

CRITICAL
CVE-2026-73501
CVE-2026-73501
pkg: oauth

published: Aug 12, 2026

kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces a nil AuthenticationFunc with NoopAuthenticationFunc, which returns nil without checking credentials. This substitution causes every OpenAPI se…
CWE: CWE-287
NVD

CRITICAL
CVE-2026-71290
CVE-2026-71290
pkg: tls

published: Aug 11, 2026

Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between the client and the server can impersonate…
CWE: CWE-295
NVD

CRITICAL
CVE-2026-68083
CVE-2026-68083
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix path resolution in ksmbd_vfs_kern_path_create

The SMB2 open lookup is rooted at the share with LOOKUP_BENEATH, but the
create/mkdir/hardlink sink is not: ksmbd_vfs_kern_path_create() builds an
absolute path with convert…

NVD

CRITICAL
CVE-2026-73842
CVE-2026-73842
pkg: kubernetes

published: Aug 13, 2026

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go exposed /api/proxy/, /api/exec/, and /api/wirelogs/ on an internal listener without requiring a client certificate or token, allowing any network-reachab…
CWE: CWE-269, CWE-306, CWE-862
NVD

HIGH
CVE-2026-72382
CVE-2026-72382
pkg: express

published: Aug 15, 2026

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: reject undersized DACLs before parsing ACEs

parse_dacl() limits the attacker-controlled ACE count by comparing it
with the number of minimal ACEs that fit in the DACL size. The DACL size
field is 16 bits, but the expression…

NVD

HIGH
CVE-2026-73841
CVE-2026-73841
pkg: kubernetes

published: Aug 13, 2026

OpenChoreo is a complete, open-source developer platform for Kubernetes. From 1.2.0-rc.1 until 1.2.0, internal/openchoreo-api/api/handlers/exec.go and internal/openchoreo-api/api/handlers/wirelogs.go authorize component:exec and wirelogs:view using the caller-supplied project query parameter instead…
CWE: CWE-639, CWE-863
NVD

HIGH
CVE-2026-73667
CVE-2026-73667
pkg: kubernetes

published: Aug 13, 2026

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.0-rc.2, OpenChoreo Workflow Plane templates under samples/getting-started/workflow-templates/ interpolated developer-controlled workflow parameters into shell program text executed through sh -c i…
CWE: CWE-78
NVD

HIGH
CVE-2026-15741
CVE-2026-15741
pkg: express

published: Aug 13, 2026

SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition. Attacks affect expression deparse consumers broadly, including pg_dump, psql commands like \sf, and any similar usage in non-core tools. Versions before Pos…
CWE: CWE-89
NVD

HIGH
CVE-2026-49473
CVE-2026-49473
pkg: express

published: Aug 13, 2026

@cedar-policy/authorization-for-expressjs is an open-source Express.js middleware that integrates Cedar authorization into Express applications by mapping HTTP requests to Cedar actions and evaluating authorization policies before allowing requests to proceed. Versions prior to 0.3.0 have an issue w…
CWE: CWE-436, CWE-863
NVD

HIGH
CVE-2026-13622
CVE-2026-13622
pkg: node

published: Aug 12, 2026

A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside the target virt-launcher pod via /proc/<pid>/root/ paths using net.Dial() without symlink protection. These socket paths reside in qemu-owned director…
CWE: CWE-22
NVD

HIGH
CVE-2026-49467
CVE-2026-49467
pkg: express

published: Aug 12, 2026

Pingvin Share X is a secure and easy self-hosted file sharing platform. A vulnerability in versions 1.5.0 through 1.18.0 allow an attacker to bypass password verification when managing Time-based One-Time Password (TOTP) settings. The root cause is a missing `await` keyword on calls to the asynchron…
CWE: CWE-303, CWE-304
NVD

HIGH
CVE-2026-44741
CVE-2026-44741
pkg: express

published: Aug 12, 2026

Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Versions prior to 2.3.6 and 1.7.18 have a SQL injection vulnerability in Pimcore's translation grid date filter — the user-supplied `property` field from the filter JSON is interpolated directly into a `UNIX_TIMESTAMP(DATE(FROM_UNIX…
CWE: CWE-89
NVD

HIGH
CVE-2026-65941
CVE-2026-65941
pkg: go

published: Aug 12, 2026

In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.
CWE: CWE-73, CWE-94, CWE-306, CWE-918
NVD

HIGH
CVE-2026-58076
CVE-2026-58076
pkg: apache airflow

published: Aug 12, 2026

Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and instantiating it with arguments from the same blob, with no restriction on what could be imported. An operator's `executor_config` reaches that branch, s…
CWE: CWE-502
NVD

HIGH
CVE-2026-19560
CVE-2026-19560
pkg: go

published: Aug 11, 2026

Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-19559
CVE-2026-19559
pkg: go

published: Aug 11, 2026

Use after free in HTML in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-19556
CVE-2026-19556
pkg: go

published: Aug 11, 2026

Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-55676
CVE-2026-55676
pkg: nginx

published: Aug 11, 2026

Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` and stores them in a directory served by the same nginx and php-fpm instance. The allow-list that should restrict accepted file types is an empty array …
CWE: CWE-434
NVD

HIGH
CVE-2026-73222
CVE-2026-73222
pkg: node

published: Aug 11, 2026

Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the –studio option in cli-tool/src/sandbox-server.js binds to all interfaces on port 3444, permits cross-origin requests, and requires no authentication. The PO…
CWE: CWE-78, CWE-306, CWE-352
NVD

HIGH
CVE-2026-18691
CVE-2026-18691
pkg: node

published: Aug 11, 2026

An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to influence which authentication mechanism is used when one replica set member connects to another. Under certain conditions, this could cause the cluster's shared internal credential to be …
CWE: CWE-757
NVD

HIGH
CVE-2026-49179
CVE-2026-49179
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.
CWE: CWE-77
NVD

HIGH
CVE-2026-72533
CVE-2026-72533
pkg: docker

published: Aug 11, 2026

An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privileged users to bypass Docker proxy authorization checks via non-canonical URL normalization, defeating all authorization middleware. The proxy endpoint fails to normalize request paths before applying…
CWE: CWE-287
NVD

HIGH
CVE-2026-15555
CVE-2026-15555
pkg: node

published: Aug 11, 2026

A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicated session data via the JBoss Marshalling River unmarshaller with no class filtering — enabling RCE via deserialization gadget chains on every cluster node.
CWE: CWE-502
NVD

HIGH
CVE-2026-18982
CVE-2026-18982
pkg: kubernetes

published: Aug 10, 2026

A flaw was found in the RHOAI training-operator. This vulnerability allows a user with standard edit or admin roles in any Kubernetes namespace to escalate their privileges. Through the creation of training jobs, an attacker can impersonate service accounts, access the host filesystem, and potential…
CWE: CWE-250
NVD

HIGH
CVE-2026-18951
CVE-2026-18951
pkg: kubernetes

published: Aug 10, 2026

A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly aggregates `trainjobs` management permissions into the native Kubernetes `edit ClusterRole`. This allows any user with `edit ClusterRole` permissions in a namespace to create, modify…
CWE: CWE-284
NVD

HIGH
CVE-2026-68341
CVE-2026-68341
pkg: express

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

ovpn: fix use after free in unlock_ovpn()

unlock_ovpn() iterates over the release_list using llist_for_each_entry()
and drops the peer reference inside the loop body via ovpn_peer_put().

If this drops the last reference, the peer…

NVD

HIGH
CVE-2026-68294
CVE-2026-68294
pkg: node

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

net: qrtr: restrict socket creation to the initial network namespace

QRTR keeps its entire port and node state in module-global variables
that are not partitioned per network namespace: qrtr_local_nid is a
single global node id (a…

NVD

HIGH
CVE-2026-68140
CVE-2026-68140
pkg: go

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

net/iucv: fix use-after-free of a severed iucv_path

af_iucv queues not-yet-received message notifications on iucv->message_q,
each holding a raw pointer to the connection's iucv_path. When the peer
severs the connection, iucv_sev…

NVD

HIGH
CVE-2026-68128
CVE-2026-68128
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

ice: reject out-of-range ptype in ice_parser_profile_init

set_bit(rslt->ptype, prof->ptypes) operates on a DECLARE_BITMAP of
ICE_FLOW_PTYPE_MAX (1024) bits. Nothing prevents a malicious VF from
providing ptype >= 1024 through VIRT…

NVD

HIGH
CVE-2026-68125
CVE-2026-68125
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

mac802154: llsec: reject frames shorter than the authentication tag

llsec_do_decrypt_auth() computes the associated-data length for the
AEAD request as

assoclen += datalen – authlen;

where datalen is the number of bytes after t…

NVD

HIGH
CVE-2026-68108
CVE-2026-68108
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu/vce: fix integer overflow in image size

Fix a security vulnerability where malicious VCE command streams
with oversized dimensions (e.g. 65536×65536) cause 32-bit integer
overflow, wrapping the calculated buffer size t…

NVD

HIGH
CVE-2026-68107
CVE-2026-68107
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu/vcn4: avoid rereading IB param length

Reuse the parameter length returned by
vcn_v4_0_enc_find_ib_param() instead of rereading it from
the IB.

This avoids a potential TOCTOU issue if the IB contents
change between read…

NVD

HIGH
CVE-2026-68098
CVE-2026-68098
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: bound DACL dedup walk to copied ACEs

set_ntacl_dacl() can stop copying ACEs before consuming the full input
DACL when size accounting overflows.

When that happens, num_aces reflects only the ACEs that were actually
copied …

NVD

HIGH
CVE-2026-68097
CVE-2026-68097
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: validate ACE size against SID sub-authorities

set_ntacl_dacl() validates sid.num_subauth before copying an ACE, but
does not verify that the declared ACE size contains all sub-authorities
described by that field. An undersi…

NVD

HIGH
CVE-2026-68091
CVE-2026-68091
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

HID: wacom: stop hardware after post-start probe failures

wacom_parse_and_register() starts HID hardware before registering inputs
and initializing pad LEDs/remotes. Those later steps can fail, but their
error paths currently rele…

NVD

HIGH
CVE-2026-49478
CVE-2026-49478
pkg: kubernetes

published: Aug 13, 2026

Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Versions through 1.8.5 improperly follow cross-host redirects and attach Kubernetes ServiceAccount tokens during OIDC discovery, allowing a malicious or compromised issuer to perform blind …
CWE: CWE-918
NVD

HIGH
CVE-2026-18608
CVE-2026-18608
pkg: kubernetes

published: Aug 10, 2026

A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which defines its permissions, includes extensive privileges beyond what is necessary for its operation. These excessive permissions, such as the ability to execute commands within pods and manage cluster-wid…
CWE: CWE-250
NVD

HIGH
CVE-2026-20349
CVE-2026-20349
pkg: cisco adaptive_security_appliance_software, cisco secure_firewall_threat_defense

published: Aug 11, 2026

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of servi…
CWE: CWE-244
GitHub-GHSA

HIGH
Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoS
GHSA-p28v-f755-9qrg
pkg: @trigger.dev/core
eco: npm
published: Aug 13, 2026
## Summary

The run-metadata update endpoint `PUT /api/v1/runs/:runId/metadata` applies client-supplied
"operations" by passing the **attacker-controlled `operation.key`** straight into
`new JSONHeroPath(operation.key).set(newMetadata, value)`
(`packages/core/src/v3/runMetadata/operations.ts:22-23`)…

CVE-2026-73654
NVD

HIGH
CVE-2026-73079
CVE-2026-73079
pkg: oauth

published: Aug 11, 2026

Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product subscriptions. From 0.1.135, to 0.1.168, platform API keys issued to tenants are exchanged for upstream requests made with shared provider accounts (ChatGPT/Codex OAuth, OpenAI platform keys, or an ope…
CWE: CWE-22, CWE-441
GitHub-GHSA

HIGH
Token Optimizer MCP: OS command injection in smart_user via username in get-user-info
GHSA-49mq-fc6q-3h46
pkg: @ooples/token-optimizer-mcp
eco: npm
published: Aug 14, 2026
### Summary

`token-optimizer-mcp` is vulnerable to OS command injection in the `smart_user` tool.

The `get-user-info` operation accepts a user-controlled `username` argument and later interpolates it into a shell command executed through `execAsync()`:

“`ts
getent passwd "${username}" || grep "^…

CVE-2026-55157
NVD

HIGH
CVE-2026-56865
CVE-2026-56865
pkg: go

published: Aug 13, 2026

A malicious GOPROXY was previously capable of forging up to two sumdb tiles that allow for a requested module to bypass the GOSUMDB check and persist attacker-controlled module content to a local Go module cache. This attack allows for a malicious GOPROXY to serve malicious module content that canno…
CWE: CWE-347
GitHub-GHSA

HIGH
MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`
GHSA-49m4-vp58-wgc9
pkg: stata-mcp
eco: pip
published: Aug 12, 2026
## Stata Command Injection via Unsanitized `package` in `ado_package_install`

### Summary

The `ado_package_install` MCP tool in `stata-mcp` concatenates user-controlled input directly into a Stata command string without any validation or sanitization. An attacker who can invoke the MCP tool or the…

CVE-2026-55071
NVD

HIGH
CVE-2026-67180
CVE-2026-67180
pkg: go

published: Aug 11, 2026

Google Turbinia allows arbitrary command execution via worker tasks. An attacker with privileges to submit a processing request or influence an evidence path/name obtains code execution on the worker fleet. Fixed on 2026-07-10.
CWE: CWE-78
NVD

HIGH
CVE-2026-8718
CVE-2026-8718
pkg: tls

published: Aug 10, 2026

tls_opt_dtls_peer_connection_id_value_get() in subsys/net/lib/sockets/sockets_tls.c, which handles getsockopt(SOL_TLS, TLS_DTLS_PEER_CID_VALUE), passed the caller-supplied optval directly to mbedtls_ssl_get_peer_cid() without verifying the buffer was at least MBEDTLS_SSL_CID_OUT_LEN_MAX (default 32)…
CWE: CWE-787
NVD

HIGH
CVE-2026-68371
CVE-2026-68371
pkg: node

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

usb: musb: omap2430: Do not put borrowed of_node in probe

omap2430_probe() stores pdev->dev.of_node in a local np variable. This is
a borrowed pointer and the probe function does not take a reference to
it.

The success and error …

NVD

HIGH
CVE-2026-19557
CVE-2026-19557
pkg: go

published: Aug 11, 2026

Use after free in TabStrip in Google Chrome on Mac prior to 151.0.7922.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-69119
CVE-2026-69119
pkg: oauth

published: Aug 11, 2026

Taubyte Tau v1.1.10 contains a missing authorization vulnerability in the services/auth HTTP service that allows any authenticated user to read or permanently delete another tenant's project by supplying an arbitrary project ID to the GET and DELETE /projects/{id} endpoints. The GitHubTokenHTTPAuth …
CWE: CWE-639
NVD

HIGH
CVE-2026-56179
CVE-2026-56179
pkg: microsoft windows_11_24h2, microsoft windows_11_25h2, microsoft windows_11_26h1

published: Aug 11, 2026

Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.
CWE: CWE-346
GitHub-GHSA

HIGH
Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket
GHSA-2j9v-p4xj-cjw2
pkg: github.com/lima-vm/lima/v2
eco: go
published: Aug 14, 2026
### Impact
On an instance of Lima running with `qemu` driver, an arbitrary user in the VM could access `/run/lima-guestagent.sock` when the guest agent is enabled.

This could result in running an arbitrary command with the root privileges in the VM (**not on the host**), as `lima-guestagent.sock` p…

CVE-2026-53657
NVD

HIGH
CVE-2026-73666
CVE-2026-73666
pkg: kubernetes

published: Aug 13, 2026

OpenChoreo is a developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.1, the OpenChoreo Backstage backend hardcoded backend.auth.dangerouslyDisableDefaultAuthPolicy and auth.providers.guest.dangerouslyAllowOutsideDevelopment to true, exposing /api/* without authentication and allowing un…
CWE: CWE-306
NVD

HIGH
CVE-2026-13048
CVE-2026-13048
pkg: express

published: Aug 13, 2026

Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the language attribute into the catalog filename.

load_lexicon builds the catalog path by appending `Messages/$lang.po` to the directory …

CWE: CWE-22, CWE-95
NVD

HIGH
CVE-2026-68118
CVE-2026-68118
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

tcp: challenge ACK for non-exact RST in SYN-RECEIVED

The SYN-RECEIVED request-socket path in tcp_check_req() accepts an
in-window RST without requiring SEG.SEQ to exactly match RCV.NXT. A
non-exact RST therefore removes the reque…

NVD

HIGH
CVE-2026-72665
CVE-2026-72665
pkg: go

published: Aug 13, 2026

Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who is able to author and evaluate Elastic Security detection rules can c…
CWE: CWE-862
NVD

HIGH
CVE-2026-55987
CVE-2026-55987
pkg: react

published: Aug 13, 2026

OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)
CWE: CWE-863
NVD

HIGH
CVE-2026-73289
CVE-2026-73289
pkg: jwt

published: Aug 12, 2026

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS evaluates the ForAllValues: and ForAnyValue: set qualifiers with the negated string operators StringNotEquals, StringNotEqualsIgnoreCase, StringNotLike, ArnNotEquals, and ArnNotLike using each other's semanti…
CWE: CWE-863
NVD

HIGH
CVE-2026-73286
CVE-2026-73286
pkg: jwt

published: Aug 12, 2026

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS get_condition_values folds attacker-controlled request headers from HeaderMap into server-derived userid, username, principaltype, groups, versionid, signatureversion, jwt:, and ldap: condition keys, allowing…
CWE: CWE-863
NVD

HIGH
CVE-2026-19594
CVE-2026-19594
pkg: python

published: Aug 12, 2026

Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-deputy privilege escalation through two related weaknesses: path traversal (CWE-22) via unencoded `..` identifier path segments, and HTTP parameter pollution (CWE-141) via unencoded `…
CWE: CWE-22, CWE-141
NVD

HIGH
CVE-2026-18961
CVE-2026-18961
pkg: oauth

published: Aug 12, 2026

The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnerable to Authentication Bypass via Unverified Provider Email in all versions up to, and including, 1.4.3. This is due to the plugin trusting the unverified email field returned by …
CWE: CWE-287
NVD

HIGH
CVE-2026-72921
CVE-2026-72921
pkg: jwt

published: Aug 11, 2026

SeaweedFS is a distributed storage system. Prior to 4.24, the weed/server/filer_server_handlers.go allowed_prefixes authorization check used strings.HasPrefix on raw path strings, so a filer JWT scoped to /tenant1 also authorized sibling paths such as /tenant1234, /tenant1-old, and /tenant1backup, e…
CWE: CWE-863
NVD

HIGH
CVE-2026-72903
CVE-2026-72903
pkg: windows

published: Aug 10, 2026

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.235, a malicious SFTP server can return a backslash traversal filename through entry.name. In tabby-ssh/src/session/sftp.ts, SFTPSession.readdir() and _makeFile() use POSIX path processing that preserves the backslash…
CWE: CWE-22
NVD

HIGH
CVE-2026-68100
CVE-2026-68100
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl

set_ntacl_dacl() copies each ACE from the attacker-controlled stored
security descriptor verbatim into the response DACL without checking
sid.num_subauth. The ACE byte…

NVD

HIGH
CVE-2026-70454
CVE-2026-70454
pkg: tls

published: Aug 13, 2026

rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation vulnerability that allows on-path attackers to intercept encrypted sessions by presenting self-signed or otherwise invalid certificates. Attackers can exploit the failure to valid…
CWE: CWE-295
NVD

HIGH
CVE-2026-65937
CVE-2026-65937
pkg: go

published: Aug 12, 2026

In WhatsUp Gold versions released before 2026.0.2, an authenticated attacker can bypass frontend controls and inject persistent script content.
CWE: CWE-79
NVD

HIGH
CVE-2026-68085
CVE-2026-68085
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled

HCI_UART_SENDING bit in tx_state means write_work is pending and blocks
queueing it again. Currently this bit is not cleared when canceling the
work in hci_u…

NVD

HIGH
CVE-2026-6726
CVE-2026-6726
pkg: tls

published: Aug 11, 2026

An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and falsify other TPM 2.…
CWE: CWE-704
NVD

HIGH
CVE-2026-68116
CVE-2026-68116
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

vxlan: mdb: Fix source list corruption on a failed replace

When replacing the source list of an MDB remote entry, all existing
sources are first marked for deletion and vxlan_mdb_remote_srcs_add()
is then called to add the new sou…

NVD

HIGH
CVE-2026-74270
CVE-2026-74270
pkg: tls

published: Aug 15, 2026

In the Linux kernel, the following vulnerability has been resolved:

handshake: Require admin permission for DONE command

ACCEPT and DONE are the two downcalls of the handshake genl
family, both intended for use by the trusted handshake agent
(tlshd). ACCEPT already requires GENL_ADMIN_PERM; DONE h…

NVD

HIGH
CVE-2026-73505
CVE-2026-73505
pkg: express

published: Aug 13, 2026

Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, the setStyle() function in src/segments/path.go passed pt.Path, which includes raw folder names, to template.Render, whose function map exposes cmd, so an attacker-controlled directory name co…
CWE: CWE-94, CWE-1336
NVD

HIGH
CVE-2026-73325
CVE-2026-73325
pkg: python

published: Aug 12, 2026

Fujitsu Research's OneCompression library 1.2.0 contains an unsafe deserialization vulnerability that allows attackers to execute arbitrary code by supplying a crafted model.pt checkpoint file, as QuantizedModelLoader.load_quantized_model_pt() unconditionally calls torch.load with weights_only=False…
CWE: CWE-502
NVD

HIGH
CVE-2026-73231
CVE-2026-73231
pkg: node

published: Aug 11, 2026

Faker generates massive amounts of fake data in the browser and Node.js. Prior to 10.5.0, the faker.helpers.fake method in src/modules/helpers/eval.ts allows attacker-controlled fake templates to access the Function constructor through fakeEval.resolveProperty when a function returns another functio…
CWE: CWE-95
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-62871 – .NET Elevation of Privilege Vulnerability
GHSA-vg44-h755-9hw7
pkg: Microsoft.WindowsDesktop.App.Runtime.win-arm64, Microsoft.WindowsDesktop.App.Runtime.win-x64, Microsoft.WindowsDesktop.App.Runtime.win-x86
eco: nuget
published: Aug 11, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in Windows Presentation Foundation. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

Out-of-bounds write in .NET …

CVE-2026-62871
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-70354 – .NET Core Remote Code Execution Vulnerability
GHSA-gg8c-3338-xw2f
pkg: Microsoft.WindowsDesktop.App.Runtime.win-arm64, Microsoft.WindowsDesktop.App.Runtime.win-x64, Microsoft.WindowsDesktop.App.Runtime.win-x86
eco: nuget
published: Aug 11, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in Windows Presentation Foundation. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

An out-of-bounds write in .N…

CVE-2026-70354
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-62886 – .NET Elevation of Privilege Vulnerability
GHSA-jqhp-238x-qhgf
pkg: Microsoft.WindowsDesktop.App.Runtime.win-arm64, Microsoft.WindowsDesktop.App.Runtime.win-x64, Microsoft.WindowsDesktop.App.Runtime.win-x86
eco: nuget
published: Aug 11, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in Windows Presentation Foundation. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

An integer overflow or wrapa…

CVE-2026-62886
NVD

HIGH
CVE-2026-61359
CVE-2026-61359
pkg: microsoft windows_11_23h2, microsoft windows_11_24h2, microsoft windows_11_25h2

published: Aug 11, 2026

Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.
CWE: CWE-122
NVD

HIGH
CVE-2026-61358
CVE-2026-61358
pkg: microsoft windows_10_1809, microsoft windows_10_21h2, microsoft windows_10_22h2

published: Aug 11, 2026

Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.
CWE: CWE-59
NVD

HIGH
CVE-2026-61356
CVE-2026-61356
pkg: microsoft windows_10_1809, microsoft windows_10_21h2, microsoft windows_10_22h2

published: Aug 11, 2026

Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
CWE: CWE-306
NVD

HIGH
CVE-2026-61355
CVE-2026-61355
pkg: microsoft windows_10_21h2, microsoft windows_10_22h2, microsoft windows_11_23h2

published: Aug 11, 2026

Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
CWE: CWE-122
NVD

HIGH
CVE-2026-61353
CVE-2026-61353
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CWE: CWE-122
NVD

HIGH
CVE-2026-61349
CVE-2026-61349
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.
CWE: CWE-362, CWE-416
NVD

HIGH
CVE-2026-59127
CVE-2026-59127
pkg: windows

published: Aug 11, 2026

Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally.
CWE: CWE-190
NVD

HIGH
CVE-2026-56174
CVE-2026-56174
pkg: microsoft windows_10_1809, microsoft windows_10_21h2, microsoft windows_10_22h2

published: Aug 11, 2026

Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.
CWE: CWE-426
NVD

HIGH
CVE-2026-54984
CVE-2026-54984
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.
CWE: CWE-122
NVD

HIGH
CVE-2026-54981
CVE-2026-54981
pkg: python

published: Aug 11, 2026

Inclusion of functionality from untrusted control sphere in Visual Studio Code – Python extension allows an unauthorized attacker to bypass a security feature locally.
CWE: CWE-693, CWE-829
NVD

HIGH
CVE-2026-42976
CVE-2026-42976
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally.
CWE: CWE-306
NVD

HIGH
CVE-2026-72693
CVE-2026-72693
pkg: node

published: Aug 11, 2026

`openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged context. In the documented `kbrequest`/init usage, the ownership test in `authenticate_user()` relies on `stat("/proc/<pid>/fd/0")`. `stat()` on `/proc/<pid>/fd/0` follows the syml…
CWE: CWE-284
NVD

HIGH
CVE-2026-68222
CVE-2026-68222
pkg: go

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

media: msi2500: Return queued buffers on start_streaming() failure

The vb2 framework hands buffers to the driver via buf_queue() before
calling start_streaming(). If start_streaming() returns an error
without first returning thos…

NVD

HIGH
CVE-2026-68121
CVE-2026-68121
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

pppoe: reload header pointer after dev_hard_header()

pppoe_sendmsg() saves a pointer to the PPPoE header before calling
dev_hard_header(). Device header callbacks are allowed to reallocate the
skb head, invalidating pointers into …

NVD

HIGH
CVE-2026-68106
CVE-2026-68106
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: fix division by zero with invalid uvd dimensions

When width or height is less than 16, width_in_mb or height_in_mb
becomes 0, leading to fs_in_mb being 0. This causes a division by
zero when calculating num_dpb_buffer …

NVD

HIGH
CVE-2026-68104
CVE-2026-68104
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: invoke pm_genpd_remove() before freeing genpd

Call pm_genpd_remove() to unregister from global list prior to releasing
acp_genpd memory, and clear the pointer after free.

(cherry picked from commit cd8650d7a91ee8b768e…

NVD

HIGH
CVE-2026-48767
CVE-2026-48767
pkg: oauth

published: Aug 11, 2026

TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege guest member of a workspace to obtain a live Google Sheets OAuth access token for that workspace by calling the Google Sheets helper `getAccessToken`. The vulnerable path checks only whether the caller has read access …
CWE: CWE-200
NVD

HIGH
CVE-2026-18621
CVE-2026-18621
pkg: node

published: Aug 10, 2026

A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security hardening by submitting a malicious Argo Workflow through the V1 API path. This allows the API server to create pods with elevated privileges, acting as a 'confused deputy' on behalf of…
CWE: CWE-266
NVD

HIGH
CVE-2026-74795
CVE-2026-74795
pkg: express

published: Aug 16, 2026

Scriban before 6.6.0 contains an uncontrolled recursion vulnerability in its recursive-descent parser. The parser does not enforce a default expression depth limit (the ExpressionDepthLimit property in ParserOptions defaults to null/disabled), so an attacker who controls template input can supply a …
CWE: CWE-674
NVD

HIGH
CVE-2026-74792
CVE-2026-74792
pkg: express

published: Aug 16, 2026

Scriban before 7.0.0 (affected versions <= 6.6.0) contains a stack overflow vulnerability in nested array initializer parsing. Deeply nested array initializers recurse through a path (ParseArrayInitializer → ParseExpression → ParseArrayInitializer) that is not covered by the ExpressionDepthLimit…
CWE: CWE-674
NVD

HIGH
CVE-2026-74789
CVE-2026-74789
pkg: express

published: Aug 16, 2026

Scriban before 7.0.0 (affected <= 6.6.0) applies its LoopLimit constraint only to script loop statements and not to expensive iteration performed inside built-in operators and functions. As a result, a single expression such as {{ 1..1000000 | array.size }} — or a memory-amplification expression s…
CWE: CWE-400
NVD

HIGH
CVE-2026-74783
CVE-2026-74783
pkg: express

published: Aug 16, 2026

Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimit guard that fails to stop recursive descent parsing of deeply nested expressions. Attackers can supply templates with deeply nested parentheses, array initializers, object initializers, or unary operators to trigger an …
CWE: CWE-674
NVD

HIGH
CVE-2026-72330
CVE-2026-72330
pkg: tls

published: Aug 15, 2026

In the Linux kernel, the following vulnerability has been resolved:

net/tls: Consume empty data records in tls_sw_read_sock()

A peer may send a zero-length TLS application_data record; TLS 1.3
explicitly permits these as a traffic-analysis countermeasure (RFC
8446, Section 5.1). After decryption s…

NVD

HIGH
CVE-2026-72254
CVE-2026-72254
pkg: express

published: Aug 15, 2026

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nft_fib: reject fib expression on the netdev egress hook

A fib expression in a netdev egress base chain dereferences nft_in(pkt),
NULL on the transmit path, causing a NULL pointer dereference at eval.
nft_fib_validate()…

NVD

HIGH
CVE-2026-56864
CVE-2026-56864
pkg: go

published: Aug 13, 2026

A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. This attack allows for a coordinating GOPROXY and GOSUMDB to serve a client malicious module content that cannot be detected by evaluating the transparency log. In order to determine if you…
CWE: CWE-347
GitHub-GHSA

HIGH
nltk: Arbitrary File Read via Path Traversal in nltk.data.load() through Percent-Encoded Sequences
GHSA-m42h-3232-vpv3
pkg: nltk
eco: pip
published: Aug 13, 2026
# Summary
nltk.data.load() and nltk.data.find() resolve user-supplied resource names to filesystem paths using url2pathname(), which decodes percent-encoded sequences (e.g. %2e%2e to ..). Path safety checks are performed on the raw, still-encoded string before decoding occurs. An attacker supplying …
CVE-2026-12243
NVD

HIGH
CVE-2026-73568
CVE-2026-73568
pkg: python

published: Aug 13, 2026

py-libp2p is the Python implementation of the libp2p networking stack. In 0.7.0 and earlier, the yamux handle_incoming() method in libp2p/stream_muxer/yamux/yamux.py reads an attacker-controlled 32-bit DATA frame length with read_exactly() before validating it against MAX_WINDOW_SIZE or checking whe…
CWE: CWE-400
NVD

HIGH
CVE-2024-58374
CVE-2024-58374
pkg: oauth

published: Aug 13, 2026

Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allows remote unauthenticated attackers to access protected resources by supplying a path traversal sequence in the request URI to bypass the oauthservlet authentication filter. Attackers …
CWE: CWE-89
NVD

HIGH
CVE-2026-14456
CVE-2026-14456
pkg: ssl

published: Aug 13, 2026

Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes
valid QUIC Initial packets for unknown destination connection IDs, it
can allocate and queue new incoming channels without enforcing any limit.

Impact summary: A remote peer that can make many Initial packets reach the
serve…

CWE: CWE-770
NVD

HIGH
CVE-2026-67991
CVE-2026-67991
pkg: express

published: Aug 13, 2026

crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in RubyLLM::Utils.underscore on Ruby 3.1.x. A very long crafted class, agent, or tool name can cause excessive CPU consumption and a denial of service.
CWE: CWE-1333
NVD

HIGH
CVE-2026-48702
CVE-2026-48702
pkg: go

published: Aug 13, 2026

Rekor is a software supply chain transparency log. Starting in version 0.3.0 and prior to version 1.5.2, the `Package.Unmarshal()` function in `pkg/types/alpine/apk.go` decompresses the signature and control gzip members of an APK file into in-memory buffers without bounding the total decompressed s…
CWE: CWE-770
NVD

HIGH
CVE-2026-19484
CVE-2026-19484
pkg: node

published: Aug 13, 2026

@fastify/busboy is a multipart form-data parser. In versions 3.1.0 through 3.2.0, a remote unauthenticated attacker can stall the Node.js event loop by sending a multipart request whose boundary is crafted to a specific length. The vendored streaming search stores its skip table in a fixed 256 entry…
CWE: CWE-835, CWE-1322
NVD

HIGH
CVE-2026-19481
CVE-2026-19481
pkg: node

published: Aug 13, 2026

@fastify/busboy is a multipart form-data parser. In versions 1.0.0 through 3.2.0, an attacker who can submit multipart form-data can crash the parser by sending a part header whose name is a prototype-inherited property such as __proto__ or constructor. The internal header parser stores headers in a…
CWE: CWE-754
GitHub-GHSA

HIGH
SIPSorcery: Malformed UDP datagram crashes TurnServer receive loop with no restart, disabling TURN UDP relay for all clients (DoS)
GHSA-pfvm-w89x-94jw
pkg: SIPSorcery
eco: nuget
published: Aug 12, 2026
## Summary
`TurnServer.ReceiveUdpAsync` places its generic `catch (Exception)` OUTSIDE the `while` receive loop, and `Start()` launches the loop fire-and-forget with no supervision or restart. A single pre-authentication UDP datagram whose STUN header first byte is in `0x80–0xFF` causes `STUNHeade…
GitHub-GHSA

HIGH
SIPSorcery vulnerable to Denial of Service via out-of-bounds read in SCTP SACK chunk parsing
GHSA-jwjp-4649-v8jp
pkg: SIPSorcery
eco: nuget
published: Aug 12, 2026
## Summary
`SctpSackChunk.ParseChunk` reads the `numGapAckBlocks` and `numDuplicateTSNs` fields (each up to 65535) directly from an attacker-controlled SCTP SACK chunk and loops that many times reading 4 bytes per iteration, with no validation of the counts against the chunk length or the receive bu…
GitHub-GHSA

HIGH
nimiq-blockchain: Validity store off by one error
GHSA-3763-qp59-59vf
pkg: nimiq-blockchain
eco: rust
published: Aug 12, 2026
### Impact
The validity store treats a transaction with stored `block_number = X` as "in window" only when `X > last_bn – transaction_validity_window_blocks` (strict inequality). However the protocol's `Transaction::is_valid_at` accepts a transaction for inclusion in any block in `[validity_start_he…
CVE-2026-46369
NVD

HIGH
CVE-2026-19558
CVE-2026-19558
pkg: go

published: Aug 11, 2026

Use after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-73232
CVE-2026-73232
pkg: go

published: Aug 11, 2026

ffuf is a fast web fuzzer written in Go. Prior to 2.2.0, ffuf allows a malicious target server to cause an out-of-memory denial of service because the response size guard in pkg/runner/simple.go checks only the compressed Content-Length while io.ReadAll reads gzip, brotli, deflate, transparently dec…
CWE: CWE-409
NVD

HIGH
CVE-2026-48804
CVE-2026-48804
pkg: python

published: Aug 11, 2026

python-socketio is a Python implementation of the Socket.IO realtime client and server. The python-socketio server stores binary `EVENT` and `ACK` messages in memory while it waits to receive their binary attachments. Once all the attachments are received, these messages are then processed. Prior to…
CWE: CWE-770
NVD

HIGH
CVE-2026-48809
CVE-2026-48809
pkg: python

published: Aug 11, 2026

python-engineio is a Python implementation of the Engine.IO realtime client and server. Versions prior to 4.13.2 have two specific configurations of the python-engineio server in which the size of incoming messages is not checked before the messages are loaded into memory. An attacker can take advan…
CWE: CWE-770
NVD

HIGH
CVE-2026-48802
CVE-2026-48802
pkg: python

published: Aug 11, 2026

python-engineio is a Python implementation of the Engine.IO realtime client and server. Prior to version 4.13.2, an attacker can cause the creation of unnecessary background threads in the python-engineio server by exploiting the heartbeat mechanism, which launches a thread when a new connection is …
CWE: CWE-770
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-62901 – .NET Denial of Service Vulnerability
GHSA-m93f-wj8c-rp8p
pkg: Microsoft.NETCore.App.Runtime.win-arm64, Microsoft.NETCore.App.Runtime.win-x64, Microsoft.NETCore.App.Runtime.win-x86
eco: nuget
published: Aug 11, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in System.Net.WebSockets. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

An unchecked input for loop condition …

CVE-2026-62901
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-62898 – .NET Information Disclosure Vulnerability
GHSA-c494-m2fq-59mx
pkg: Microsoft.NETCore.App.Runtime.win-arm64, Microsoft.NETCore.App.Runtime.win-x64, Microsoft.NETCore.App.Runtime.win-x86
eco: nuget
published: Aug 11, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in Microsoft QUIC. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A use after free in Microsoft QUIC allows an …

CVE-2026-62898
NVD

HIGH
CVE-2026-72713
CVE-2026-72713
pkg: docker

published: Aug 11, 2026

XAgent contains a path traversal vulnerability in the workspace file endpoint that allows self-registered or default-credential users to read arbitrary files on the host by supplying parent-directory segments in the `file_name` form field with no path containment check. Attackers can register an acc…
CWE: CWE-22
NVD

HIGH
CVE-2026-73089
CVE-2026-73089
pkg: node

published: Aug 11, 2026

Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, index.js retains every distinct `(queries, context)` result in cache and every parseQueries() AST in parseCache without a size cap, TTL, or eviction, allowing an attacker w…
CWE: CWE-770
NVD

HIGH
CVE-2026-73088
CVE-2026-73088
pkg: node

published: Aug 11, 2026

Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, normalizeStats() in node.js, reached unconditionally through getStat() and loadStat() on every browserslist() call, processes untrusted browserslist-stats.json, opts.stats,…
CWE: CWE-248, CWE-1321
NVD

HIGH
CVE-2026-59132
CVE-2026-59132
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.
CWE: CWE-476
NVD

HIGH
CVE-2026-54113
CVE-2026-54113
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network.
CWE: CWE-770
NVD

HIGH
CVE-2026-72605
CVE-2026-72605
pkg: jwt

published: Aug 11, 2026

A missing authentication vulnerability in Swing Music 3.0.0 allows unauthenticated remote attackers to create arbitrary user accounts via the POST /auth/profile/create endpoint. The endpoint is allowlisted from JWT verification, permitting unauthenticated account creation. An attacker can register a…
CWE: CWE-306
NVD

HIGH
CVE-2026-68131
CVE-2026-68131
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

rbd: Reset positive result codes to zero in object map update path

In a reply message to an RBD request, a positive result code indicates
a data payload, which is not allowed for writes. While
rbd_osd_req_callback() already resets…

NVD

HIGH
CVE-2026-68129
CVE-2026-68129
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

gve: fix Rx queue stall on alloc failure

When the system is under extreme memory pressure, page allocations can
fail during the Rx buffer refill loop. If the number of buffers posted
to hardware falls below a critical low threshol…

NVD

HIGH
CVE-2026-68120
CVE-2026-68120
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

rtase: Workaround for TX hang caused by hardware packet parsing

The hardware performs packet parsing before packet transmission.
Parsing incomplete IPv4, IPv6, TCP, or UDP headers may trigger a TX
hang because the hardware parser …

NVD

HIGH
CVE-2026-68119
CVE-2026-68119
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

tcp: initialize standalone TCP-AO response padding

tcp_v4_send_ack() and tcp_v6_send_response() construct standalone TCP
responses with TCP-AO options. The option length carries the actual MAC
length, but the TCP header length in…

NVD

HIGH
CVE-2026-68096
CVE-2026-68096
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

audit: fix recursive locking deadlock in audit_dupe_exe()

A deadlock occurs in the audit subsystem when duplicating
executable-related rules.

When a file is moved (e.g., via do_renameat2()), the VFS layer locks
the parent directo…

NVD

HIGH
CVE-2026-65942
CVE-2026-65942
pkg: tls

published: Aug 10, 2026

TLS hostname verification issue in Apache Ranger Client Code in versions <= 2.8.0.
Users are recommended to upgrade to version 2.9.0, which fixes this issue.
CWE: CWE-297
NVD

HIGH
CVE-2026-73655
CVE-2026-73655
pkg: go

published: Aug 13, 2026

Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.2, addGoogleStrategy() in apps/webapp/app/services/googleAuth.server.ts passes a Google profile email to findOrCreateGoogleUser() in apps/webapp/app/models/user.server.ts without requiring Google…
CWE: CWE-287
NVD

HIGH
CVE-2026-15554
CVE-2026-15554
pkg: ssl

published: Aug 11, 2026

the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authentication. This enables an unauthenticated attacker with direct TCP access to port 8009 to bypass CLIENT-CERT authentication by injecting a forged X.509 certificate via the AJP protoc…
CWE: CWE-295
NVD

HIGH
CVE-2026-18511
CVE-2026-18511
pkg: tls

published: Aug 13, 2026

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to generate a stack-based buffer overflow in the Native IBM i JSSE provider, caused by improper bounds checking during TLS session establishment. A local attacker could overflow a fixed-length buffer and execute arbitrary code o…
CWE: CWE-787
NVD

HIGH
CVE-2026-74564
CVE-2026-74564
pkg: express

published: Aug 15, 2026

In the Linux kernel, the following vulnerability has been resolved:

netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH

The XT_HASHLIMIT_RATE_MATCH flag mode changes the semantics of the
dsthash_ent structure which represents an entry in the hashtable. There
is a union ar…

GitHub-GHSA

HIGH
mchange-commons-java contains elements susceptible to abuse via JNDI injection and "deserialization gadgets"
GHSA-h84g-69h7-mw6v
pkg: com.mchange:mchange-commons-java
eco: maven
published: Aug 14, 2026
### Impact
Prior to version 0.6.0, mchange-commons-java includes a JNDI `ObjectFactory` implementation (`com.mchange.v2.naming.JavaBeanObjectFactory`) willing to construct objects of arbitrary classes and initialize "JavaBean"-style properties. There are classes for which this kind of initialization…
CVE-2026-55153
NVD

HIGH
CVE-2026-72632
CVE-2026-72632
pkg: express

published: Aug 13, 2026

Observable Discrepancy (CWE-203) in Kibana Fleet can lead to information disclosure via Excavation (CAPEC-116). Fleet removes the Elasticsearch API key value of an enrolled Elastic Agent from the responses of its agent listing capability, but that capability accepted caller-supplied filter expressio…
CWE: CWE-203
GitHub-GHSA

HIGH
SSH.NET: ScpClient Recursive Download Allows Arbitrary File Write via Server-Controlled SCP Filenames
GHSA-q939-rpr3-3284
pkg: SSH.NET
eco: nuget
published: Aug 12, 2026
## Summary

`ScpClient.Download(string directoryName, DirectoryInfo directoryInfo)` writes files and directories using names returned by the remote SCP server during recursive downloads, with no validation that the resulting path stays inside the requested local directory. A malicious, compromised, …

CVE-2026-48798
NVD

HIGH
CVE-2026-73291
CVE-2026-73291
pkg: node

published: Aug 12, 2026

Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.4.0, Seerr's ImageProxy in server/lib/imageproxy.ts uses the upstream ETag and Content-Type response headers to build a cache filename for the unauthenticated GET /avatarproxy/:jellyfinUserId…
CWE: CWE-22, CWE-94
NVD

HIGH
CVE-2026-63177
CVE-2026-63177
pkg: nginx

published: Aug 11, 2026

Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access control enforced in the Nginx OpenResty Lua layer evaluates the raw, unnormalized `ngx.var.request_uri`, while Nginx itself routes requests using the normalized path. An authenticated low-privilege user can…
CWE: CWE-863
NVD

HIGH
CVE-2026-48495
CVE-2026-48495
pkg: oauth

published: Aug 11, 2026

TypeBot is a chatbot builder tool. Prior to version 3.17.0, the Google Sheets OAuth callback decodes a base64-encoded JSON `state` parameter and trusts the embedded `workspaceId`, `typebotId`, `blockId`, and `redirectUrl` without cryptographic integrity protection or authorization checks. The callba…
CWE: CWE-862
NVD

HIGH
CVE-2026-42142
CVE-2026-42142
pkg: oauth

published: Aug 11, 2026

TypeBot is a chatbot builder tool. Prior to version 3.17.0, the `handleGetSheets` API handler (`POST /api/sheets/getSheets`) does not validate workspace membership, allowing any authenticated user to access and decrypt another workspace's Google Sheets OAuth credentials and retrieve spreadsheet data…
CWE: CWE-862
NVD

HIGH
CVE-2026-68103
CVE-2026-68103
pkg: linux

published: Aug 10, 2026

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: reject mapping a reserved doorbell to a new queue

When creating an user-queue, the user space
provides a doorbell BO handle and an offset within
the bo to obtain a doorbell.

However current implementation using xa_sto…

NVD

HIGH
CVE-2026-53996
CVE-2026-53996
pkg: node

published: Aug 12, 2026

NetBSD's hdaudio(4) driver in sys/dev/hdaudio/hdaudio.c contains a missing access control vulnerability that allows unprivileged local attackers to invoke the HDAUDIO_FGRP_SETCONFIG ioctl without elevated permissions by exploiting the absence of an access check on /dev/hdaudioN device nodes. Attacke…
CWE: CWE-862
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-62897 – .NET Remote Code Execution Vulnerability
GHSA-fx4q-gjrx-2jw6
pkg: Microsoft.WindowsDesktop.App.Runtime.win-arm64, Microsoft.WindowsDesktop.App.Runtime.win-x64, Microsoft.WindowsDesktop.App.Runtime.win-x86
eco: nuget
published: Aug 11, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in Windows Presentation Foundation. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

An integer overflow or wrapa…

CVE-2026-62897
NVD

HIGH
CVE-2026-61361
CVE-2026-61361
pkg: microsoft windows_11_24h2, microsoft windows_11_25h2, microsoft windows_11_26h1

published: Aug 11, 2026

Use after free in Windows DHCP Client allows an authorized attacker to execute code locally.
CWE: CWE-416
NVD

HIGH
CVE-2026-61348
CVE-2026-61348
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CWE: CWE-416
NVD

HIGH
CVE-2026-61346
CVE-2026-61346
pkg: microsoft windows_10_1809, microsoft windows_10_21h2, microsoft windows_10_22h2

published: Aug 11, 2026

Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.
CWE: CWE-416
NVD

HIGH
CVE-2026-59126
CVE-2026-59126
pkg: microsoft windows_10_21h2, microsoft windows_10_22h2, microsoft windows_11_23h2

published: Aug 11, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.
CWE: CWE-362
NVD

HIGH
CVE-2026-59122
CVE-2026-59122
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CWE: CWE-362, CWE-416
NVD

HIGH
CVE-2026-50472
CVE-2026-50472
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.
CWE: CWE-122
GitHub-GHSA

HIGH
OpenAM Insecure SSO Cookie Initialization
GHSA-fpmh-vx4h-xc33
pkg: org.openidentityplatform.openam:openam-core
eco: maven
published: Aug 14, 2026
## Summary

**Description**
An Insecure Default Initialization of Resource (CWE-1188) issue in the OpenAM default configuration ships the `iPlanetDirectoryPro` SSO cookie with `HttpOnly=false`. Also, the `iPlanetDirectoryPro` SSO cookie is used as a CSRF token in OAuth/OIDC flows. This affects OpenA…

CVE-2026-53660
GitHub-GHSA

HIGH
Budibase: SSRF in Automation Steps – Webhook, Zapier, N8N, Slack, Discord Bypass IP Blacklist
GHSA-5fpj-28rv-84r7
pkg: @budibase/server
eco: npm
published: Aug 14, 2026
## Summary

Budibase automation steps (outgoing webhook, Zapier, n8n, Slack, Discord, Make.com) make server-side HTTP requests to user-provided URLs using `node-fetch` directly, completely bypassing the IP blacklist protection that exists in the REST API integration. Additionally, the REST API black…

CVE-2026-35219
GitHub-GHSA

HIGH
Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts
GHSA-29rf-f4vv-pvq6
pkg: github.com/authorizerdev/authorizer
eco: go
published: Aug 14, 2026
The OAuth callback handler links incoming OAuth identities (Google, GitHub, etc.) to existing accounts matched by email address without verifying that the existing account's email was verified by its original owner. An attacker who pre-registers with a victim's email address (without verifying it) g…
CVE-2026-35511
GitHub-GHSA

HIGH
atomic-agents-stack: Dashboard HTTP server path traversal allows arbitrary file read
GHSA-rm43-82j9-r4mj
pkg: atomic-agents-stack
eco: pip
published: Aug 13, 2026
The optional dashboard HTTP server (`atomic_agents/dashboard/serve.py`) builds filesystem paths directly from the request path and serves them without a containment check. It is the only per-request untrusted-path site in the codebase that does not route through `_io.safe_resolve_under`. Literal `..…
GitHub-GHSA

HIGH
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)
GHSA-48p8-g2fx-3wwm
pkg: github.com/argoproj/argo-workflows/v4, github.com/argoproj/argo-workflows/v3, github.com/argoproj/argo-workflows
eco: go
published: Aug 13, 2026
### Summary

The allow-list fix for CVE-2026-31892 (GHSA-3wf5-g532-rcrr), and its follow-up coverage of `hostNetwork`/`securityContext`/`serviceAccountName` in GHSA-3775-99mw-8rp4, is incomplete. `workflow/util/merge.go` `ValidateUserOverrides` / `SanitizeUserWorkflowSpec` walk only the top-level fi…

CVE-2026-54526
GitHub-GHSA

HIGH
Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv)
GHSA-cxgv-hp74-jj7r
pkg: ansible-jailexec
eco: pip
published: Aug 12, 2026
Through version 1.3.0, the jailexec connection plugin's put_file resolved a transfer's destination to a path on the jail host (<jail filesystem root> + <destination>) and ran mkdir -p and mv there as root on the host. Those commands follow symbolic links, and the path was operated on outside the jai…
CVE-2026-55074
GitHub-GHSA

HIGH
SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access
GHSA-w62w-66v9-vvgv
pkg: github.com/seaweedfs/seaweedfs
eco: go
published: Aug 12, 2026
## Summary

The S3 API gateway and the Iceberg REST catalog gateway construct their routers with `mux.NewRouter().SkipClean(true)`. With path cleaning disabled, a `..` segment inside the URL survives routing, so a request such as:

“`
GET /bucket-A/../evil-bucket/key
“`

is matched as `bucket=buck…

CVE-2026-54917
GitHub-GHSA

HIGH
compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0
GHSA-h47f-gmjp-m7rr
pkg: compliance-trestle
eco: pip
published: Aug 12, 2026
### Summary

`compliance-trestle` 4.0.3 (latest) ships an `URLSecurityValidator` in `trestle/core/remote/security.py` to block SSRF to loopback / link-local / cloud-metadata endpoints from the HTTPSFetcher and SFTPFetcher remote-fetch paths. The allowlist is incomplete and can be bypassed by four eq…

CVE-2026-52776
GitHub-GHSA

MEDIUM
Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials
GHSA-h7p7-w5gc-xj3w
pkg: pydantic-ai-slim, pydantic-ai-slim, pydantic-ai
eco: pip
published: Aug 13, 2026
### Summary

A client that can submit message history to a Pydantic AI UI adapter can reference arbitrary files in the application's model-provider or cloud-storage account. The server forwards the reference to the model provider, which fetches it using the server's own credentials, allowing the cli…

CVE-2026-54249
GitHub-GHSA

MEDIUM
ep_etherpad-lite: Device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author token
GHSA-vqfp-p66c-xrp9
pkg: ep_etherpad-lite
eco: npm
published: Aug 13, 2026
Etherpad's device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author token in the GET response body

## Description

Etherpad ships an endpoint pair under `/tokenTransfer` (`src/node/hooks/express/tokenTransfer.ts`) that lets a logged-in user move…

CVE-2026-55088
NVD

MEDIUM
CVE-2026-73611
CVE-2026-73611
pkg: jwt

published: Aug 13, 2026

File Browser versions from 2.50.0 through 2.63.21 fail to validate JWT expiration when proxy authentication is configured with a non-default logout page. Attackers with a previously valid token can access protected routes and administrative endpoints indefinitely, and exchange expired tokens for fre…
CWE: CWE-613
NVD

MEDIUM
CVE-2026-73419
CVE-2026-73419
pkg: oauth

published: Aug 12, 2026

NextAuth.js provides authentication for Next.js. Prior to@auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, Auth.js stores the OAuth/OIDC anti-CSRF checks state, nonce, and the PKCE verifier in global cookies that are not bound to the provider that created them. On callback, a check value mi…
CWE: CWE-345, CWE-346, CWE-940
NVD

MEDIUM
CVE-2026-65940
CVE-2026-65940
pkg: go

published: Aug 12, 2026

In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible location on the host server.
CWE: CWE-276, CWE-732
NVD

MEDIUM
CVE-2026-65939
CVE-2026-65939
pkg: go

published: Aug 12, 2026

In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root.
CWE: CWE-22, CWE-73, CWE-434
NVD

MEDIUM
CVE-2026-49349
CVE-2026-49349
pkg: docker

published: Aug 12, 2026

regclient is a Docker and OCI Registry Client in Go. Prior to version 0.11.5, credentials for a registry may be inadvertently leaked to external servers. A prerequisite for this attack is a malicious registry server, a malicious blob store, or a registry that does not restrict the external URLs for …
CWE: CWE-522
NVD

MEDIUM
CVE-2026-19278
CVE-2026-19278
pkg: express

published: Aug 10, 2026

A flaw was found in StackRox/RHACS Central's Auth Machine-to-Machine (M2M) token exchange. When an administrator configures M2M role mappings, the system uses unanchored regular expressions for matching claim values. This allows an attacker with a valid OpenID Connect (OIDC) token, whose claim value…
CWE: CWE-625
NVD

MEDIUM
CVE-2026-66016
CVE-2026-66016
pkg: tls

published: Aug 12, 2026

Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessible to highly privileged local users.
CWE: CWE-312
GitHub-GHSA

MEDIUM
Microsoft Security Advisory CVE-2026-62909 – .NET Elevation of Privilege Vulnerability
GHSA-9mr8-pwpw-3j2w
pkg: Microsoft.NETCore.App.Runtime.linux-arm, Microsoft.NETCore.App.Runtime.linux-arm64, Microsoft.NETCore.App.Runtime.linux-musl-arm
eco: nuget
published: Aug 11, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET diagnostics IPC. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A missing error check in .NET causes an…

CVE-2026-62909
NVD

MEDIUM
CVE-2026-71969
CVE-2026-71969
pkg: express

published: Aug 10, 2026

OP-TEE OS through 4.10.0, fixed in commit 7b8b494, contains a buffer underwrite vulnerability in the RSA NOPAD encrypt and decrypt operations within the mbedTLS software backend and SE050 hardware driver that allows a malicious Trusted Application to corrupt secure-world heap memory by supplying an …
CWE: CWE-124, CWE-787
NVD

MEDIUM
CVE-2026-71968
CVE-2026-71968
pkg: node

published: Aug 10, 2026

OP-TEE OS through 4.10.0, fixed in commit 8794043, contains a use-after-free vulnerability in the Trusted Application loader that allows attackers with the ability to load a signed Trusted Application to corrupt secure-world kernel memory by setting the TA_FLAG_CONCURRENT flag in a user TA signed he…
CWE: CWE-362, CWE-416
GitHub-GHSA

MEDIUM
ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)
GHSA-9hgc-g3w5-67cm
pkg: mcp-contextforge-gateway
eco: pip
published: Aug 14, 2026
## Summary

The `/admin/gateways/test` endpoint validates submitted URLs by resolving the hostname at validation time and blocking private address ranges. The HTTP client independently re-resolves DNS at connection time with no IP binding between the two operations, creating a TOCTOU window exploita…

CVE-2026-53708
NVD

MEDIUM
CVE-2026-73330
CVE-2026-73330
pkg: express

published: Aug 12, 2026

CamaleonCMS 2.9.1 contains a server-side template injection vulnerability that allows authenticated administrators to execute arbitrary commands by embedding ERB tags in the email parameter of the test_email settings action, which are evaluated when an SMTP rejection reflects the recipient address b…
CWE: CWE-1336
NVD

MEDIUM
CVE-2026-74785
CVE-2026-74785
pkg: express

published: Aug 16, 2026

Scriban before 7.0.0 contains three distinct denial-of-service vulnerabilities in expression evaluation that bypass existing safety controls through unbounded string multiplication, uncontrolled BigInteger shift operations, and LoopLimit bypass via range enumeration in builtin functions. Attackers w…
CWE: CWE-400
GitHub-GHSA

MEDIUM
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users
GHSA-8rw6-p7m8-63jp
pkg: surrealdb
eco: rust
published: Aug 14, 2026
A `SELECT` permission defined on an array element (`DEFINE FIELD field.* … PERMISSIONS FOR select …`) is not enforced correctly for `RECORD` users. Instead of hiding the denied elements, the query leaks a subset of them: a deny-all returns the odd-indexed elements, and a per-element predicate ke…
NVD

MEDIUM
CVE-2026-72664
CVE-2026-72664
pkg: go

published: Aug 13, 2026

Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who holds only detection rule authoring privileges for the Elastic Security solution …
CWE: CWE-862
NVD

MEDIUM
CVE-2026-72663
CVE-2026-72663
pkg: express

published: Aug 13, 2026

Inefficient Algorithmic Complexity (CWE-407) in Kibana can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted, deeply nested expression submitted to a Kibana TSVB visualization is evaluated with a worst-case cost that grows disproportionately with the size of the …
CWE: CWE-407
NVD

MEDIUM
CVE-2026-72648
CVE-2026-72648
pkg: kubernetes

published: Aug 13, 2026

Cleartext Storage of Sensitive Information in an Environment Variable (CWE-526) in Elastic Cloud on Kubernetes (ECK) can lead to information disclosure via Retrieve Embedded Sensitive Data (CAPEC-37). When ECK reconciles a Fleet Server resource that authenticates to Elasticsearch with a service acco…
CWE: CWE-526
NVD

MEDIUM
CVE-2026-72640
CVE-2026-72640
pkg: kubernetes

published: Aug 13, 2026

The Elastic Cloud on Kubernetes (ECK) operator reads a list of secret references from an annotation on secrets it manages, and it accepts the namespace recorded in each reference without validating that the reference is authorized for the resource being reconciled. A user whose Kubernetes permission…
CWE: CWE-441
NVD

MEDIUM
CVE-2026-49089
CVE-2026-49089
pkg: express

published: Aug 13, 2026

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A query expression accepted by a connector reporting operation was processed without any limit on its size, and an oversized expression caused the Kibana proce…
CWE: CWE-770
GitHub-GHSA

MEDIUM
vLLM: Completion prompt lists fan out into unbounded engine requests
GHSA-87×5-vmc3-756j
pkg: vllm
eco: pip
published: Aug 13, 2026
## Summary

The `/v1/completions` request model accepts `prompt` as a list of text prompts or a list of token-id prompts without any outer prompt-count bound. The serving path turns each element into a separate engine input, creates one engine generator per element, merges all generators, and alloca…

CVE-2026-73559
NVD

MEDIUM
CVE-2026-14663
CVE-2026-14663
pkg: openssl

published: Aug 13, 2026

Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of the faulty ciphertext. The OpenSSL version and OpenSSL configuration determine the disabled ciphers. If the application accepts encrypted data as input, decryption will succeed e…
CWE: CWE-313, CWE-345
GitHub-GHSA

MEDIUM
Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint
GHSA-88p2-jj8w-j8qg
pkg: github.com/fleetdm/fleet/v4
eco: go
published: Aug 12, 2026
### Summary

The target search endpoint (`POST /api/latest/fleet/targets`) returned team enroll secrets and full team configuration, including credential-bearing agent options, to observer-class users. Other team-facing endpoints mask these fields for observers; the target search endpoint did not ap…

CVE-2026-48786
NVD

MEDIUM
CVE-2026-68868
CVE-2026-68868
pkg: go

published: Aug 12, 2026

The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections and Variables: the caller's `team_name` was accepted by the backend but dropped at the internal call boundary, so every lookup resolved against the team-agnosti…
CWE: CWE-1220
GitHub-GHSA

MEDIUM
Microsoft Security Advisory CVE-2026-62902 – .NET Information Disclosure Vulnerability
GHSA-9mrh-pw7c-9mqm
pkg: Microsoft.WindowsDesktop.App.Runtime.win-arm64, Microsoft.WindowsDesktop.App.Runtime.win-x64, Microsoft.WindowsDesktop.App.Runtime.win-x86
eco: nuget
published: Aug 11, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in Windows Presentation Foundation. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A specially crafted document…

CVE-2026-62902
NVD

MEDIUM
CVE-2026-69117
CVE-2026-69117
pkg: express

published: Aug 11, 2026

NetBox 4.5.8 contains an ORM injection vulnerability that allows authenticated attackers, including those with read-only API tokens, to inject arbitrary Django ORM lookup expressions into nested object references by supplying crafted JSON dictionary keys in POST, PUT, or PATCH requests to any REST A…
CWE: CWE-639
NVD

MEDIUM
CVE-2026-72739
CVE-2026-72739
pkg: docker

published: Aug 10, 2026

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the createCommand() function constructs shell commands by interpolating compose service names and configuration into bash command strings. When a compose with a maliciously crafted name or service definition is deployed…
CWE: CWE-78
NVD

MEDIUM
CVE-2026-65945
CVE-2026-65945
pkg: jwt

published: Aug 10, 2026

Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0
Users are recommended to upgrade to version 2.9.0, which fixes this issue.
CWE: CWE-532
NVD

MEDIUM
CVE-2026-19751
CVE-2026-19751
pkg: axios

published: Aug 13, 2026

A flaw has been found in EnzoVezzaro mcp-dominican-layer up to 39dd373786712650097ad31db27d5c477c8f9c82. The affected element is the function axios.get of the file src/index.ts of the component parse-csv tool. This manipulation of the argument csvUrl causes server-side request forgery. The attack is…
CWE: CWE-918
NVD

MEDIUM
CVE-2026-73576
CVE-2026-73576
pkg: jwt

published: Aug 13, 2026

In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability exists in the OnlyOffice integration. The zimbraDocumentEditingJwtSecret is generated using an insecure random number generator, resulting in insufficient entropy. An attacker who obtains a JWT signed with…
CWE: CWE-1241
GitHub-GHSA

MEDIUM
Duplicate Advisory: Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint
GHSA-4jjw-pwvw-q6w3
pkg: nuxt
eco: npm
published: Aug 11, 2026
## Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-7c4v-fwgw-9rf7. This link is maintained to preserve external references.

## Original Description
Nuxt versions >= 4.4.7 and < 4.5.1, and >= 3.21.7 and < 3.21.10, contain an information disclosure vulnerabilit…

NVD

MEDIUM
CVE-2026-73671
CVE-2026-73671
pkg: oauth

published: Aug 13, 2026

Saurus CMS Community Edition contains an unauthenticated open redirect vulnerability in the logout handling code in classes/port.inc.php, where the url parameter supplied via GET or POST is passed directly to the Location header without domain allowlist, scheme validation, or relative path enforceme…
CWE: CWE-601
GitHub-GHSA

MEDIUM
ep_etherpad-lite: Cache-poisoning Cross-site Scripting and Open Redirect via x-proxy-path Header
GHSA-fjgc-3mj7-8rg8
pkg: ep_etherpad-lite
eco: npm
published: Aug 13, 2026
# GHSA-03 — `x-proxy-path` header reflected into admin HTML/JS/CSS (cache-poisoning XSS) and concatenated into redirect (open-redirect)

**Severity:** Medium
**CVSS v3.1 vector:** `CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N`
**CVSS suggested base score:** ~6.1 — Medium
*(Re-validate in the f…

CVE-2026-55087
NVD

MEDIUM
CVE-2026-73084
CVE-2026-73084
pkg: oauth

published: Aug 11, 2026

Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /api/redirect OAuth callback endpoint embeds the user-supplied code query parameter directly into an inline script block without proper escaping. A crafted request to /api/redirect with a malicious code value can br…
CWE: CWE-79, CWE-94
NVD

MEDIUM
CVE-2026-69116
CVE-2026-69116
pkg: vue

published: Aug 10, 2026

FlyEnv before 4.18.0 fails to sanitize HTML from markdown rendering and AI chat content passed to Vue v-html directives. Attackers can inject malicious scripts through markdown sources or chat messages that execute in the Electron renderer process with access to Node.js APIs and the filesystem.
CWE: CWE-79
NVD

MEDIUM
CVE-2026-66455
CVE-2026-66455
pkg: react

published: Aug 13, 2026

Subscriber Broken Access Control in ReactPress <= 3.4.0 versions.
CWE: CWE-862
NVD

MEDIUM
CVE-2026-12233
CVE-2026-12233
pkg: tls

published: Aug 12, 2026

The PSA Protected Storage credential backend (subsys/net/lib/tls_credentials/tls_credentials_trusted.c) declared its credential-store mutex as a plain zero-filled static struct k_mutex credential_lock; and never called k_mutex_init() on it. A statically zero-filled k_mutex has an uninitialized wait …
CWE: CWE-665
GitHub-GHSA

MEDIUM
Microsoft Security Advisory CVE-2026-62899 – .NET Security Feature Bypass Vulnerability
GHSA-r6mh-95jw-g7qg
pkg: Microsoft.NETCore.App.Runtime.linux-arm, Microsoft.NETCore.App.Runtime.linux-arm64, Microsoft.NETCore.App.Runtime.linux-musl-arm
eco: nuget
published: Aug 11, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in System.Net.HttpListener. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

Inconsistent interpretation of http …

CVE-2026-62899
NVD

MEDIUM
CVE-2026-73068
CVE-2026-73068
pkg: jwt

published: Aug 11, 2026

ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.207, the ToolJet Database HTTP API in server/src/modules/tooljet-db/controller.ts authorizes operations against the :organizationId URL path value without ver…
CWE: CWE-639
NVD

MEDIUM
CVE-2026-72800
CVE-2026-72800
pkg: express

published: Aug 12, 2026

SiYuan versions before v3.7.4 fail to apply publish-access filtering to the getAttributeViewKeysByID endpoint, allowing authenticated readers to retrieve complete database column schemas including descriptions, select vocabularies, and template expressions. Additionally, getBlockDefIDsByRefText and …
CWE: CWE-862
NVD

MEDIUM
CVE-2026-73308
CVE-2026-73308
pkg: oauth

published: Aug 12, 2026

Budibase is an open-source low-code platform. Prior to 3.39.25, packages/server/src/api/controllers/automation.ts returned automation test results containing trigger.outputs.user.oauth2, broadcast BuilderSocketEvent.AutomationTestProgress to the app room, and stored progress in packages/server/src/a…
CWE: CWE-200
NVD

MEDIUM
CVE-2026-73647
CVE-2026-73647
pkg: vue

published: Aug 13, 2026

Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the public extend() utility in ui/src/utils/extend/extend.js recursively copied attacker-controlled object keys during extend(true, target, source) deep merges without rejecting an own __proto__ pr…
CWE: CWE-1321
NVD

MEDIUM
CVE-2026-19964
CVE-2026-19964
pkg: python

published: Aug 17, 2026

A vulnerability was found in Jij-Inc Jij-MCP-Server 0.1.0. This affects the function PythonREPL.run of the file jij_mcp/python_repr.py of the component jm_check. The manipulation of the argument code results in code injection. It is possible to launch the attack remotely. The exploit has been made p…
CWE: CWE-74, CWE-94
NVD

MEDIUM
CVE-2026-48790
CVE-2026-48790
pkg: jwt

published: Aug 11, 2026

Turso CLI is the command line interface (CLI) to the open-source database Turso. Versions prior to 1.0.26 persist the user's Turso platform JWT to `settings.json` using Viper's default `configPermissions` of `0o644`, leaving the credential file world-readable on standard Linux and macOS systems. Any…
CWE: CWE-276, CWE-732
NVD

MEDIUM
CVE-2026-61360
CVE-2026-61360
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally.
CWE: CWE-822
NVD

MEDIUM
CVE-2026-61347
CVE-2026-61347
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally.
CWE: CWE-126
NVD

MEDIUM
CVE-2026-59137
CVE-2026-59137
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally.
CWE: CWE-908
NVD

MEDIUM
CVE-2026-59136
CVE-2026-59136
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally.
CWE: CWE-908
NVD

MEDIUM
CVE-2026-59135
CVE-2026-59135
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.
CWE: CWE-1390
NVD

MEDIUM
CVE-2026-59128
CVE-2026-59128
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally.
CWE: CWE-125
NVD

MEDIUM
CVE-2026-18942
CVE-2026-18942
pkg: kubernetes

published: Aug 10, 2026

A flaw was found in the Feast operator. A malicious tenant could inject arbitrary code into their feature repository. This code would be executed by an automated process with elevated privileges, allowing the tenant to steal sensitive credentials. This could lead to a direct escalation of privileges…
CWE: CWE-94
NVD

MEDIUM
CVE-2026-74240
CVE-2026-74240
pkg: jwt

published: Aug 14, 2026

A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and single sign-on (SSO) authentication. Multiple issues related to audience verification and the enforcement of `azp` and `sub` claims were identified. These flaws could allow an attacker with a validly-…
CWE: CWE-287
NVD

MEDIUM
CVE-2026-19135
CVE-2026-19135
pkg: express

published: Aug 13, 2026

A JEXL expression sandbox bypass exists in multiple versions of OpenNMS Meridian and Horizon. A low-privileged authenticated user can submit a crafted expression to the Measurements REST API that escapes the sandbox and loads arbitrary Java classes on the server. This can potentially allow an attack…
CWE: CWE-470
GitHub-GHSA

MEDIUM
tablib: Stored XSS in the HTML export via unescaped dataset title
GHSA-gqgw-jghv-mxwx
pkg: tablib
eco: pip
published: Aug 12, 2026
tablib prior to 3.10.0 contains a stored cross-site scripting vulnerability in the HTML export functionality that allows attackers to execute arbitrary JavaScript by embedding malicious payloads in dataset titles, which are interpolated unsanitized into HTML output via the export_book method in the …
CVE-2026-9318
GitHub-GHSA

MEDIUM
s2n-quic has excessive memory allocation
GHSA-9q54-f358-3fqf
pkg: s2n-quic
eco: rust
published: Aug 14, 2026
s2n-quic is a Rust implementation of the QUIC protocol. An unauthenticated user can attempt to exhaust server memory on an s2n-quic endpoint by sending crafted CRYPTO frames with high offsets. The buffer used for processing CRYPTO frames does not enforce a maximum size. In the worst case, a single 1…
CVE-2026-10740
GitHub-GHSA

MEDIUM
Token Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API Endpoints
GHSA-76pc-mqxp-3rq5
pkg: @ooples/token-optimizer-mcp
eco: npm
published: Aug 14, 2026
# Unauthenticated Path Traversal in Dashboard Session Log API Endpoints

| Field | Value |
| —————- | —– |
| Repository | ooples/token-optimizer-mcp |
| Affected version | 5.0.1 (commit 8137147) |
| Vulnerability | CWE-22 — Improper Limitation of a Pathname to a Re…

CVE-2026-55156
NVD

MEDIUM
CVE-2026-73845
CVE-2026-73845
pkg: express

published: Aug 14, 2026

CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, the ckan_get_mqa_quality and ckan_get_mqa_quality_details tools in src/tools/quality.ts use isValidMqaServer to validate the server_url parameter with a prefix-only regular expression for dati.gov.it, allowing suffix-ho…
CWE: CWE-20, CWE-625, CWE-918
NVD

MEDIUM
CVE-2026-73840
CVE-2026-73840
pkg: kubernetes

published: Aug 13, 2026

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, the POST /api/v1alpha1/autobuild endpoint in internal/openchoreo-api/api/handlers/webhook_handler.go selected a webhook provider from caller-controlled X-Event-Key, accepted Bitbucket requ…
CWE: CWE-287, CWE-290, CWE-345
NVD

MEDIUM
CVE-2026-58507
CVE-2026-58507
pkg: go

published: Aug 13, 2026

Private Repository Existence Disclosure via go-get Meta Endpoint
CWE: CWE-284
NVD

MEDIUM
CVE-2026-19487
CVE-2026-19487
pkg: express

published: Aug 13, 2026

Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.

The prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one re…

CWE: CWE-670
NVD

MEDIUM
CVE-2026-73556
CVE-2026-73556
pkg: express

published: Aug 13, 2026

vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the structured_outputs.regex parameter in vllm/v1/structured_output/backend_lm_format_enforcer.py is passed to lmformatenforcer.RegexParser without compile_regex_with_timeout or validation in validate_structured_outp…
CWE: CWE-400, CWE-1333
NVD

MEDIUM
CVE-2026-73555
CVE-2026-73555
pkg: python

published: Aug 13, 2026

vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the validation_exception_handler in vllm/entrypoints/openai/server_utils.py converts FastAPI RequestValidationError objects with str(exc), and sanitize_message in vllm/entrypoints/utils.py does not remove traceback-s…
CWE: CWE-209
NVD

MEDIUM
CVE-2026-66384
CVE-2026-66384
pkg: docker

published: Aug 12, 2026

An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
CWE: CWE-22
NVD

MEDIUM
CVE-2026-33921
CVE-2026-33921
pkg: windows

published: Aug 11, 2026

The Windows installer deployed Npcap leaving its access restriction option at the insecure default value, so the driver was accessible to every local user of the host instead of being restricted to administrators only. A local user without administrative privileges could use the Npcap driver to capt…
CWE: CWE-1188
NVD

MEDIUM
CVE-2026-73304
CVE-2026-73304
pkg: oauth

published: Aug 13, 2026

Budibase is an open-source low-code platform. Prior to 3.39.25, GET /api/users/metadata and GET /api/users/metadata/:id returned user objects processed by packages/server/src/utilities/global.ts without removing oauth2.accessToken or oauth2.refreshToken. A user with the POWER role could retrieve the…
CWE: CWE-200
NVD

MEDIUM
CVE-2026-67613
CVE-2026-67613
pkg: ssl

published: Aug 13, 2026

CyberPanel before 3.0.0 contains a path traversal vulnerability that allows authenticated administrators to read arbitrary files from the server filesystem by supplying unsanitized file paths to the cloudAPI ReadReport endpoint. Attackers can manipulate the reportFile parameter in the JSON request b…
CWE: CWE-22
NVD

MEDIUM
CVE-2026-73282
CVE-2026-73282
pkg: openssh

published: Aug 11, 2026

In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.
CWE: CWE-416
NVD

MEDIUM
CVE-2026-73563
CVE-2026-73563
pkg: oauth

published: Aug 13, 2026

Backstage is an open framework for building developer portals. Prior to 0.29.2, the experimental dynamic client registration and client ID metadata document features in the @backstage/plugin-auth-backend use full-string matcher.isMatch glob matching for auth.experimentalDynamicClientRegistration.all…
CWE: CWE-601
NVD

MEDIUM
CVE-2026-49820
CVE-2026-49820
pkg: oauth

published: Aug 13, 2026

Probo is a self-hostable governance, risk, and compliance (GRC) platform built for engineering and security teams. Probo's `saferedirect` package validates redirect URLs used across authentication flows (OIDC, SAML, session transfer, OAuth connectors, and trust-center magic links). Prior to version …
CWE: CWE-601
NVD

MEDIUM
CVE-2026-61350
CVE-2026-61350
pkg: microsoft windows_10_1607, microsoft windows_10_1809, microsoft windows_10_21h2

published: Aug 11, 2026

Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.
CWE: CWE-126
NVD

MEDIUM
CVE-2026-73036
CVE-2026-73036
pkg: python

published: Aug 11, 2026

Bash-it 3.2.0 contains a terminal escape sequence injection vulnerability in the barbuk theme's Python virtualenv prompt segment that allows local attackers to inject arbitrary terminal control sequences by embedding escape sequences in the requires-python field of a pyproject.toml file. When a user…
CWE: CWE-150
NVD

MEDIUM
CVE-2026-58425
CVE-2026-58425
pkg: oauth

published: Aug 13, 2026

OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)
CWE: CWE-200, CWE-863
NVD

MEDIUM
CVE-2026-6470
CVE-2026-6470
pkg: express

published: Aug 13, 2026

Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations did check the privilege, but assigning a range subtype and referencing the type from an SQL expressio…
CWE: CWE-862
NVD

MEDIUM
CVE-2026-65938
CVE-2026-65938
pkg: go

published: Aug 12, 2026

In WhatsUp Gold versions released before 2026.0.2, an improper authorization vulnerability in the Scheduled Reports API allows any authenticated user to invoke restricted actions.
CWE: CWE-602, CWE-862
NVD

MEDIUM
CVE-2026-19078
CVE-2026-19078
pkg: oauth

published: Aug 11, 2026

A flaw was found in the oauth-server component. This open redirect vulnerability occurs when the 'then' parameter in the grant approval handler is not properly validated. A remote attacker can craft a malicious URL that, when approved or denied by an authenticated user, redirects them to an attacker…
CWE: CWE-601
NVD

MEDIUM
CVE-2026-72912
CVE-2026-72912
pkg: express

published: Aug 10, 2026

CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.3.0, CyberChef's pretty-recipe parser in src/core/Utils.mjs can exhaust client-side CPU when a malformed #recipe= URL fragment containing a large number of unmatched quote characters reaches Utils.parseRecip…
CWE: CWE-400, CWE-1333
NVD

MEDIUM
CVE-2026-18165
CVE-2026-18165
pkg: oauth

published: Aug 15, 2026

@fastify/oauth2 is an OAuth 2.0 plugin for Fastify. In versions from 7.2.0 up to but not including 8.3.0, the plugin validates the OAuth state, and with PKCE the code verifier, by comparing the callback query parameter against an unprefixed, predictable cookie, with no server-side binding to the bro…
CWE: CWE-352
GitHub-GHSA

MEDIUM
ep_etherpad-lite: Import/export uses Math.random() for temp file paths; predictable paths on shared /tmp enable symlink-based file overwrite
GHSA-2jwf-f4xq-f24h
pkg: ep_etherpad-lite
eco: npm
published: Aug 13, 2026
## Description

`src/node/handler/ImportHandler.ts` and `src/node/handler/ExportHandler.ts` both compute their temporary working-file paths as:

“`ts
const randNum = Math.floor(Math.random() * 0xFFFFFFFF);
const srcFile = `${os.tmpdir()}/etherpad_export_${randNum}.html`;
const destFile = `${os.tmpd…

CVE-2026-55086
NVD

MEDIUM
CVE-2026-14681
CVE-2026-14681
pkg: tls

published: Aug 13, 2026

Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules, via initial direct TLS connection. Despite a pg_hba.conf that appears to require GSSAPI, the connection may exchange data over TLS encryption alone. If the TLS se…
CWE: CWE-924
GitHub-GHSA

MEDIUM
Fabric CA Developer's Guide: LDAP Injection via Unescaped Username in GetUser Filter
GHSA-xghw-p77p-3r7x
pkg: github.com/hyperledger/fabric-ca
eco: go
published: Aug 14, 2026
When fabric-ca is configured with an LDAP backend, the username from HTTP Basic authentication is included in an LDAP uid search filter without proper escaping. An unauthenticated attacker with network access to the CA enrollment endpoint could exploit this to perform LDAP injection before password …
CVE-2026-53658
GitHub-GHSA

MEDIUM
hashi-vault-js: Vault token and secret values exposed in thrown errors
GHSA-5pq8-3ffp-7w5m
pkg: hashi-vault-js
eco: npm
published: Aug 13, 2026
## Summary

Vault token and secret values are exposed in thrown errors when using `hashi-vault-js`.

## Details

Every API method in `Vault.js` executes `throw parseAxiosError(err)`, which returns the raw `AxiosError` untouched. That error carries the full Axios configuration, including the `X-Vault…

CVE-2026-55102