Vulnerability Digest — August 31, 2026 · 73 Critical · 10 Exploited






Vulnerability Digest — Monday, August 31, 2026


Security Report

Monday, August 31, 2026  ·  Last 7 days  ·  Min severity: MEDIUM
Total Findings
456
Critical
73
High
239
Actively Exploited
10
CISA-KEV10
NVD293
GitHub-GHSA153
Findings sorted by severity
CISA-KEV

CRITICAL
ownCloud Improper Authentication Vulnerability
CVE-2023-49105
pkg: ownCloud ownCloud

published: Aug 27, 2026

ownCloud contains an improper authentication vulnerability that allows an attacker to access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Linux Kernel Unspecified Vulnerability
CVE-2026-53362
pkg: Linux Kernel

published: Aug 27, 2026

Linux Kernel contains an unspecified vulnerability that can allow for privilege escalation via IPv6 networking subsystem. This vulnerability can impact multiple products, including but not limited to Suse, Red Hat, and other products using Linux.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
CVE-2026-66384
pkg: JFrog Artifactory

published: Aug 27, 2026

JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2019-1068
pkg: Microsoft SQL Server

published: Aug 26, 2026

Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Red Hat Libuser Race Condition Vulnerability
CVE-2015-3246
pkg: Red Hat Libuser

published: Aug 26, 2026

Red Hat libuser contains a race condition vulnerability that allows authenticated local users to corrupt the /etc/passwd file to cause a denial of service or privilege escalation.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
CVE-2015-5287
pkg: Red Hat Automatic Bug Reporting Tool

published: Aug 26, 2026

Red Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). U…
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Linux Kernel Out-of-Bounds Write Vulnerability
CVE-2022-0995
pkg: Linux Kernel

published: Aug 26, 2026

Linux Kernel contains an out-of-bounds memory write vulnerability which could allow a local user to gain privileged access or cause a denial of service on the system.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
CVE-2026-8452
pkg: Citrix NetScaler ADC and NetScaler Gateway

published: Aug 26, 2026

Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability which could lead to denial of service.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
CVE-2021-23758
pkg: Ajax.NET Professional Ajax.NET Professional

published: Aug 26, 2026

Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to …
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Gitea Code Injection Vulnerability
CVE-2026-60004
pkg: Gitea Gitea

published: Aug 25, 2026

Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
NVD

CRITICAL
CVE-2026-54745
CVE-2026-54745
pkg: kubernetes

published: Aug 28, 2026

Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0, the Kubeflow Pipelines frontend exposes an unauthenticated server-side request forgery vulnerability through the /_proxy/ route in frontend/server/proxy-middleware.ts. The _routePathW…
CWE: CWE-284, CWE-918
NVD

CRITICAL
CVE-2026-81096
CVE-2026-81096
pkg: python

published: Aug 27, 2026

ToolUniverse ran caller-supplied Python inside a sandbox that could be escaped, on a server that required no authentication. The executor behind the python_code_executor tool, in python_executor_tool.py, inspected the submitted source for a denied list of attribute names and calls but left the attri…
CWE: CWE-94
NVD

CRITICAL
CVE-2026-55565
CVE-2026-55565
pkg: express

published: Aug 28, 2026

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs LikeExpression.fillCode_getValueReturn in yamcs-core/src/main/java/org/yamcs/yarch/streamsql/LikeExpression.java inserts an unescaped LIKE pattern into Java source compiled by Expression.getCompiledExpression through SimpleCompi…
CWE: CWE-94
GitHub-GHSA

CRITICAL
Yamcs vulnerable to authenticated remote code execution via unescaped StreamSQL `LIKE` pattern compiled by Janino (`LikeExpression`)
GHSA-c64q-hj4j-375f
pkg: org.yamcs:yamcs-core, org.yamcs:yamcs-core
eco: maven
published: Aug 28, 2026
## Summary
Yamcs compiles StreamSQL query expressions to Java at runtime with Janino. The `LIKE` operator inserts the user-supplied pattern into the generated Java **unescaped**, inside a `"…"` literal, so a pattern containing `"` breaks out and injects arbitrary Java (e.g. a `static{}` block that…
CVE-2026-55565
NVD

CRITICAL
CVE-2026-65093
CVE-2026-65093
pkg: linux

published: Aug 25, 2026

NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
CWE: CWE-427
NVD

CRITICAL
CVE-2026-65083
CVE-2026-65083
pkg: linux

published: Aug 25, 2026

NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of disallowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, data tampering, and d…
CWE: CWE-184
GitHub-GHSA

CRITICAL
Yamcs vulnerable to Remote Code Execution via instance-template argument YAML injection (createInstance)
GHSA-73mf-m39p-wpm9
pkg: org.yamcs:yamcs-core, org.yamcs:yamcs-core
eco: maven
published: Aug 28, 2026
### Summary

`templateArgs` sent to `POST /api/instances` (and `PATCH /api/instances/{instance}`) are written into the rendered instance config as raw text, then parsed as YAML and loaded. Yamcs instantiates each `services:` entry by its `class:`, so injecting YAML through a template arg lets you ad…

CVE-2026-55559
NVD

CRITICAL
CVE-2026-80714
CVE-2026-80714
pkg: node

published: Aug 28, 2026

In the Linux kernel, the following vulnerability has been resolved:

ipvs: do not propagate one-packet flag to synced conns

Synced connections can be created before their destination exists. When
the destination is later added, ip_vs_bind_dest() copies connection flags
from the destination into cp-…

NVD

CRITICAL
CVE-2026-81934
CVE-2026-81934
pkg: tls

published: Aug 27, 2026

Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated attacker may be able to execute arbitrary commands with the privileges of the Redis server. Fixed in Red…
CWE: CWE-416
NVD

CRITICAL
CVE-2026-81707
CVE-2026-81707
pkg: openssl

published: Aug 27, 2026

openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attackers to inject ANSI escape sequences that forge the fingerprint verification line displayed to users. Attackers can deliver a crafted identity bundle through normal contact-exchange flows or …
CWE: CWE-20
NVD

CRITICAL
CVE-2026-81702
CVE-2026-81702
pkg: openssl

published: Aug 27, 2026

openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, allowing attackers to substitute public keys in identity stores. Attackers can replace legitimate public keys with their own while maintaining the claimed fingerprint, enabling silen…
CWE: CWE-345
NVD

CRITICAL
CVE-2026-81701
CVE-2026-81701
pkg: openssl

published: Aug 27, 2026

openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in top-level plugins/ directories and unknown subdirectories to bypass signature verification. Attackers can place malicious unsigned plugins following documented installation paths t…
CWE: CWE-347
NVD

CRITICAL
CVE-2026-81700
CVE-2026-81700
pkg: openssl

published: Aug 27, 2026

openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that accepts revoked and expired keys by only checking VALIDSIG status without inspecting REVKEYSIG, EXPKEYSIG, or gpg exit codes. Attackers holding compromised-then-revoked signing key…
CWE: CWE-347
NVD

CRITICAL
CVE-2026-54569
CVE-2026-54569
pkg: python

published: Aug 26, 2026

SENAITE.CORE is the core framework for the SENAITE laboratory information management system. From 2.0.0 to 2.6.0, the SENAITE.CORE JSON API permits unauthenticated remote code execution through a two-request chain involving missing authorization and unsafe evaluation. The state-changing routes in sr…
CWE: CWE-95, CWE-862
GitHub-GHSA

CRITICAL
senaite.core Vulnerable to Eval Injection and Missing Authorization
GHSA-jrw6-7x4q-w25j
pkg: senaite.core
eco: pip
published: Aug 26, 2026
### Summary

An unauthenticated remote code execution vulnerability in the SENAITE JSON API allows any network-reachable attacker to execute arbitrary Python on the Zope worker process via a two-request anonymous chain. The `/@@API/update` route is reachable to anonymous callers and runs `eval()` on…

CVE-2026-54569
NVD

CRITICAL
CVE-2026-80519
CVE-2026-80519
pkg: linux

published: Aug 26, 2026

In the Linux kernel, the following vulnerability has been resolved:

ovpn: finish crypto callback cleanup before peer release

Crypto completion callbacks hold both key-slot and peer references. The
peer reference pins the netdev, and dropping the last peer reference can
let netdev unregistration an…

NVD

CRITICAL
CVE-2026-74752
CVE-2026-74752
pkg: linux

published: Aug 26, 2026

In the Linux kernel, the following vulnerability has been resolved:

sctp: validate cookie AUTH state before use

When cookie authentication is disabled, COOKIE_ECHO restores fixed-size
AUTH fields directly from peer-controlled cookie bytes. A forged RANDOM
length, HMAC list, or CHUNKS list can the…

NVD

CRITICAL
CVE-2026-74746
CVE-2026-74746
pkg: linux

published: Aug 26, 2026

In the Linux kernel, the following vulnerability has been resolved:

netfilter: flowtable: publish GC-visible tuple last

nf_flow_table_iterate() only treats original-direction tuple nodes as
owning entries. Publishing the original node first lets GC observe and
free a flow while flow_offload_add() …

NVD

CRITICAL
CVE-2026-74744
CVE-2026-74744
pkg: linux

published: Aug 26, 2026

In the Linux kernel, the following vulnerability has been resolved:

ipvlan: inherit needed_headroom and needed_tailroom from phy_dev

ipvlan devices inherit hard_header_len from phy_dev during ipvlan_init(),
but leave needed_headroom and needed_tailroom set to 0.

When the underlying phy_dev (or st…

NVD

CRITICAL
CVE-2026-74743
CVE-2026-74743
pkg: linux

published: Aug 26, 2026

In the Linux kernel, the following vulnerability has been resolved:

macvlan: inherit needed_headroom and needed_tailroom from lowerdev

macvlan devices inherit hard_header_len from lowerdev during macvlan_init(),
but leave needed_headroom and needed_tailroom set to 0.

When the underlying lowerdev …

NVD

CRITICAL
CVE-2026-74737
CVE-2026-74737
pkg: linux

published: Aug 26, 2026

In the Linux kernel, the following vulnerability has been resolved:

net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG

On the packet reception path, the ID of the MAC Port on which the packet
was received, is embedded in the RX DMA Descriptor's metadata. The ID is
extracted usi…

NVD

CRITICAL
CVE-2026-65905
CVE-2026-65905
pkg: apache tomcat

published: Aug 25, 2026

Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made, a client makes a DIGEST
authenticated request with a nonceCount on the upper boundary of the
replay window then that request is replayable once only while t…
CWE: CWE-294
NVD

CRITICAL
CVE-2026-80104
CVE-2026-80104
pkg: python

published: Aug 25, 2026

DB-GPT builds the destination path for an uploaded skill from the multipart filename without constraining it to the upload directory. skill_upload in packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py takes file.filename as given and writes the request body to upload_dir / filename.…
CWE: CWE-22
NVD

CRITICAL
CVE-2026-45018
CVE-2026-45018
pkg: python

published: Aug 25, 2026

Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose the POST /mcp endpoint without requiring authentication. For stdio transport, the endpoi…
CWE: CWE-78
GitHub-GHSA

CRITICAL
Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution
GHSA-w3fx-mc44-mf6j
pkg: chainlit
eco: pip
published: Aug 25, 2026
### Am I affected?

Only if your deployment sets `features.mcp.enabled = true` in `.chainlit/config.toml`. **MCP has been disabled by default since v2.7.0**, so most Chainlit deployments are not affected. No authentication is required: `/mcp` is reachable by any client that can open a session.

### …

CVE-2026-45018
NVD

CRITICAL
CVE-2026-55546
CVE-2026-55546
pkg: express

published: Aug 25, 2026

QWED-MCP is a deterministic verification gateway for MCP. Prior to 0.2.1, verify_math_expression() in src/qwed_mcp/engines/math_engine.py passes attacker-controlled expression and claimed_result strings directly to SymPy's parse_expr() after only normalizing caret syntax to Python exponent syntax, w…
CWE: CWE-94
GitHub-GHSA

CRITICAL
qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input
GHSA-mw6r-2hvm-4rp2
pkg: qwed-mcp
eco: pip
published: Aug 25, 2026
### Summary

`verify_math_expression()` in `qwed-mcp` v0.2.0 passes attacker-controlled strings directly to SymPy's `parse_expr()` without restricting `global_dict` or validating the expression's AST. Because `parse_expr()` internally calls `eval()` and Python automatically injects the current modul…

CVE-2026-55546
GitHub-GHSA

CRITICAL
Apache Camel-Undertow: the endpoint discarded the undertow-specific header filter strategy in favour of the base HTTP one, so the undertow filtering never ran on endpoint-configured routes
GHSA-v7h8-xhh6-gfj4
pkg: org.apache.camel:camel-undertow, org.apache.camel:camel-undertow, org.apache.camel:camel-undertow
eco: maven
published: Aug 24, 2026
Improper input validation vulnerability in Apache Camel Undertow component.

This issue affects Apache Camel: from 4.11.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0.

UndertowEndpoint defaulted its headerFilterStrategy field to the base HttpHeaderFilterStrategy and pushed th…

CVE-2026-78329
GitHub-GHSA

CRITICAL
Apache Camel-Atmosphere-Websocket: WebSocket dispatch header injection – the producer selected its target peers through Exchange headers whose names sat outside the filtered Camel namespace
GHSA-m5r8-w65q-8wjf
pkg: org.apache.camel:camel-atmosphere-websocket, org.apache.camel:camel-atmosphere-websocket, org.apache.camel:camel-atmosphere-websocket
eco: maven
published: Aug 24, 2026
Improper input validation vulnerability in Apache Camel Atmosphere Websocket component.

This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0.

The camel-atmosphere-websocket producer selects which connected WebSocket peers a message is deli…

CVE-2026-71300
GitHub-GHSA

CRITICAL
Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token)
GHSA-cgc5-v3f2-8m2v
pkg: github.com/klever-io/klever-go
eco: go
published: Aug 28, 2026
## Summary

The per-entry percentages of a KDA asset's **split royalties** are validated by summing
them into a **`uint32`** accumulator and checking the *sum* against `HundredPercent (10000)`,
with **no upper bound on each individual entry**. Two split entries whose percentages sum to
just over `2^…

CVE-2026-54755
GitHub-GHSA

CRITICAL
Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped)
GHSA-p7gw-2pcp-5pf8
pkg: github.com/klever-io/klever-go
eco: go
published: Aug 28, 2026
## Summary

When a marketplace order is settled (`MarketBuy` / `BuyItNow`, and auction `Claim`), the buyer's
payment is split three ways — **referral**, **royalties**, and the **seller (market-order owner)
remainder**:

“`
marketOwnerAmount = CurrentBid − referralAmount − royaltiesAmount
“`

CVE-2026-54754
NVD

CRITICAL
CVE-2026-59354
CVE-2026-59354
pkg: oauth

published: Aug 27, 2026

In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client Registration is explicitly enabled, the registration endpoint performs insufficient validation of certain client metadata fields supplied by the registering client. An attacker who possesses …
CWE: CWE-20
GitHub-GHSA

CRITICAL
Kyverno's NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated — background controller creates RoleBindings in any namespace including kube-system
GHSA-79gf-7frw-68m9
pkg: github.com/kyverno/kyverno
eco: go
published: Aug 26, 2026
## Summary

In Kyverno v1.18.1, a tenant who can create a `NamespacedMutatingPolicy` in their own namespace can instruct the admission controller to generate resources in any namespace by passing an arbitrary namespace string to the CEL `generator.apply(namespace, resources)` function.

## Details

CVE-2026-54523
NVD

CRITICAL
CVE-2026-79138
CVE-2026-79138
pkg: google chrome, microsoft windows

published: Aug 25, 2026

Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-787
NVD

CRITICAL
CVE-2026-79019
CVE-2026-79019
pkg: google chrome, microsoft windows

published: Aug 25, 2026

Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-787
NVD

CRITICAL
CVE-2026-78989
CVE-2026-78989
pkg: google chrome, microsoft windows

published: Aug 25, 2026

Out of bounds read in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-125
NVD

CRITICAL
CVE-2026-78948
CVE-2026-78948
pkg: google chrome

published: Aug 25, 2026

Buffer overflow in WebGL in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-122
NVD

CRITICAL
CVE-2026-78945
CVE-2026-78945
pkg: google chrome

published: Aug 25, 2026

Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-416
NVD

CRITICAL
CVE-2026-78939
CVE-2026-78939
pkg: google chrome

published: Aug 25, 2026

Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

CRITICAL
CVE-2026-78937
CVE-2026-78937
pkg: google chrome, google android

published: Aug 25, 2026

Use after free in Search in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-416
NVD

CRITICAL
CVE-2026-78935
CVE-2026-78935
pkg: google chrome, apple iphone_os

published: Aug 25, 2026

Use of uninitialized variable in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-457
NVD

CRITICAL
CVE-2026-78909
CVE-2026-78909
pkg: google chrome

published: Aug 25, 2026

Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-416
NVD

CRITICAL
CVE-2026-78904
CVE-2026-78904
pkg: google chrome

published: Aug 25, 2026

Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-843
NVD

CRITICAL
CVE-2026-78900
CVE-2026-78900
pkg: google chrome

published: Aug 25, 2026

Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-20
NVD

CRITICAL
CVE-2026-78683
CVE-2026-78683
pkg: python

published: Aug 25, 2026

NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deserialization vulnerability in the TransitionParser.parse() method (nltk/parse/transitionparser.py). The method calls pickle_load() with the default restricted=False, routing deserialization through WarningUnpickler, which do…
CWE: CWE-502
NVD

CRITICAL
CVE-2026-76840
CVE-2026-76840
pkg: windows

published: Aug 24, 2026

RustDesk's Windows clipboard redirection copies a peer-supplied length into a fixed-size caller buffer without an upper bound check. When an OLE paste consumer such as explorer.exe calls IStream::Read with a buffer of cb bytes, CliprdrStream_Read in libs/clipboard/src/windows/wf_cliprdr.c requests t…
CWE: CWE-20, CWE-787
NVD

CRITICAL
CVE-2026-74751
CVE-2026-74751
pkg: linux

published: Aug 26, 2026

In the Linux kernel, the following vulnerability has been resolved:

riscv: lib: Fix ZBB strnlen reading past count boundary

The ZBB-optimized strnlen loop loads one word ahead before checking the
aligned boundary:

REG_L t1, SZREG(t0) // load next word
addi t0, t0, SZREG /…

NVD

CRITICAL
CVE-2026-82454
CVE-2026-82454
pkg: jwt

published: Aug 29, 2026

The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-in token verification. The decodeAppleToken function extracted the 'alg' field from the attacker-supplied JWT header and passed it as the sole allowed algorithm to jwt.verify(). Using jso…
CWE: CWE-347
NVD

CRITICAL
CVE-2026-55511
CVE-2026-55511
pkg: express

published: Aug 28, 2026

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs allows a user with SystemPrivilege.ControlArchiving to create a double-quoted StreamSQL column name that is interpolated into generated Java source by Expression.fillCode_InputDefVars and Expression.sanitizeName. A sum aggregate…
CWE: CWE-94
GitHub-GHSA

CRITICAL
plone.app.event vulnerable to denial of service via iCalendar import
GHSA-r82h-mqw3-fc56
pkg: plone.app.event, plone.app.event
eco: pip
published: Aug 28, 2026
### Impact
By abusing the iCalendar import functionality, a logged-in editor could take the whole site offline, make the server reach into the internal network and read calendar files off disk (SSRF), and store XSS.

### Patches
The problem has been patched in `plone.app.event`.

* For Plone 6.2: up…

CVE-2026-55247
GitHub-GHSA

CRITICAL
plone.app.portlets vulnerable to denial of service via RSS feed portlet
GHSA-x5g3-w747-2h8q
pkg: plone.app.portlets, plone.app.portlets, plone.app.portlets
eco: pip
published: Aug 28, 2026
### Impact
By adding an RSS portlet, and giving this a link to a very large file, a member can cause a denial of service attack, because Plone will use lots of memory. The member could also use different urls to try to get information about the internal network and open port numbers (SSRF). A malici…
CVE-2026-55248
GitHub-GHSA

CRITICAL
Yamcs vulnerable to authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs `executeSql`
GHSA-3g44-3m7x-cgg2
pkg: org.yamcs:yamcs-core, org.yamcs:yamcs-core
eco: maven
published: Aug 28, 2026
## Overview

Yamcs compiles StreamSQL expressions to Java on the fly with the Janino `SimpleCompiler` (no restrictive class-loading policy or expression sandbox). When a StreamSQL aggregate such as `sum(…)` is applied to a **column**, the column's *name* is interpolated **unescaped** into the gene…

CVE-2026-55511
NVD

CRITICAL
CVE-2026-82244
CVE-2026-82244
pkg: node

published: Aug 28, 2026

Budibase versions before 3.41.3 contain a remote code execution vulnerability in plugin handling that allows authenticated admin users to execute arbitrary code by uploading a malicious plugin tarball. The server calls eval() on plugin JavaScript files without sandboxing in the main Node.js process,…
CWE: CWE-94
NVD

CRITICAL
CVE-2026-61800
CVE-2026-61800
pkg: node

published: Aug 28, 2026

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.4.0 through 4.14.6, a party holding the cluster key can write, overwrite, or delete arbitrary files under /var/ossec on worker nodes, leading to remote code execution …
CWE: CWE-22
NVD

CRITICAL
CVE-2026-50152
CVE-2026-50152
pkg: node

published: Aug 28, 2026

Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Monitor subscription handler fails to properly authorize access to the configuration-key store, allowing any CephX user with only  `mon allow r` capabilities to…
CWE: CWE-285
NVD

CRITICAL
CVE-2026-59283
CVE-2026-59283
pkg: express

published: Aug 27, 2026

Applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationContext may be vulnerable to a safety guard bypass when the SpEL expression compiler is active.
Spring Framework 7.0.0 – 7.0.8
Spring Framework 6.2.0 – 6.2.19
Spring Framework 6.1.0 – 6.1.28
Spring Framewo…
CWE: CWE-913
NVD

CRITICAL
CVE-2026-55536
CVE-2026-55536
pkg: express

published: Aug 25, 2026

PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, Browser Server _handle_connection() checks Chrome extension origins with re.match() and the unanchored expression chrome-extension://[a-z0-9]{32}. Extra trailing characters pass before websocket.accept(), allowing start_session comm…
CWE: CWE-284, CWE-625
GitHub-GHSA

CRITICAL
nextcloud-mcp-server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default )
GHSA-8vh3-g2qg-2h2c
pkg: nextcloud-mcp-server
eco: pip
published: Aug 25, 2026
## Summary
The `POST /webhooks/nextcloud` endpoint has no authentication by default: `WEBHOOK_SECRET` defaults to `None` and is never required by startup validation. When unset, the receiver accepts any unauthenticated POST. The `user_id` is taken directly from the attacker-supplied payload and pass…
CVE-2026-55640
GitHub-GHSA

CRITICAL
PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92)
GHSA-6g6r-q6gw-w8fg
pkg: PraisonAI
eco: pip
published: Aug 25, 2026
### Summary

`praisonai/browser/server.py` validates incoming WebSocket connections using a Chrome
extension Origin check. The regex `chrome-extension://[a-z0-9]{32}` is applied with
`re.match()`, which **only anchors at the start of the string, not the end**. Any Origin
header with more than 32 alp…

CVE-2026-55536
GitHub-GHSA

CRITICAL
Apache Camel-Azure-Storage-Blob: the downloadBlobToFile operation built the local download target from the remote blob name without constraining it to the configured fileDir
GHSA-2×37-89hj-2j95
pkg: org.apache.camel:camel-azure-storage-blob, org.apache.camel:camel-azure-storage-blob, org.apache.camel:camel-azure-storage-blob
eco: maven
published: Aug 24, 2026
Relative path traversal vulnerability in Apache Camel Azure Storage Blob component.

This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0.

The camel-azure-storage-blob component can download an Azure Storage blob to the local filesystem thr…

CVE-2026-66906
NVD

CRITICAL
CVE-2026-76835
CVE-2026-76835
pkg: oauth

published: Aug 24, 2026

OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, because the guard added for CVE-2026-40575 is inert in the default reverse-proxy configuration. GetRequestURI in pkg/requests/util/util.go prefers that header over the real request …
CWE: CWE-290
GitHub-GHSA

CRITICAL
free5GC NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpoints
GHSA-x8mj-6p3q-g5pp
pkg: github.com/free5gc/free5gc
eco: go
published: Aug 28, 2026
### Summary

free5GC NRF (Docker image free5gc-fuzz:latest) accepts NF registration requests without validating any field constraints against 3GPP TS 29.510, allowing unauthenticated attackers to inject fake NF profiles with arbitrary service endpoint IP addresses. All 17 constraint violations teste…

CVE-2026-55068
GitHub-GHSA

CRITICAL
Trojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise)
GHSA-93qj-5q5v-3c2h
pkg: pantheon-agents
eco: pip
published: Aug 26, 2026
## Summary
The PyPI account that publishes `pantheon-agents` was compromised in the June 2026 "Hades" PyPI supply-chain attack (Mini Shai-Hulud / Miasma lineage). The attacker used a stolen, long-lived PyPI API token to upload **trojanized releases `pantheon-agents` 0.6.1 and 0.6.2 directly to PyPI*…
NVD

HIGH
CVE-2026-82635
CVE-2026-82635
pkg: windows

published: Aug 30, 2026

Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file Tauri command onto the user's Downloads directory with no sanitization. A filename containing path traversal sequences (for example ../Library/LaunchAgents/com.evil.plist) or an absolute path resolves outside ~/Downloads…
CWE: CWE-22
NVD

HIGH
CVE-2026-82278
CVE-2026-82278
pkg: node

published: Aug 28, 2026

BISHENG before 2.6.0 contains a remote code execution vulnerability in the workflow run_once endpoint that allows authenticated users to execute arbitrary Python code. Attackers can submit crafted Code node definitions to the POST /api/v1/workflow/run_once endpoint, which executes them with exec() w…
CWE: CWE-94
NVD

HIGH
CVE-2026-55485
CVE-2026-55485
pkg: python

published: Aug 28, 2026

Piccolo Admin is an admin interface and content management system for Python, built on top of Piccolo. Prior to 1.14.0, piccolo_admin/endpoints.py uses superuser_validators to block PUT, PATCH, DELETE, and POST requests by non-superusers but permits GET requests to configured user and session tables…
CWE: CWE-200, CWE-269, CWE-863
GitHub-GHSA

HIGH
piccolo-admin has a privilege escalation issue – admin to superuser via session-token disclosure in GET /api/tables/sessions/.
GHSA-2gh4-jmwq-rr8w
pkg: piccolo-admin
eco: pip
published: Aug 28, 2026
## Summary

`piccolo_admin` uses a helper called `superuser_validators` to gate access to the user and session tables for non-superusers. The helper rejects `PUT`, `PATCH`, `DELETE`, and `POST`, but **does not reject `GET`**.

The `sessions` table stores live session tokens **in plaintext**, and the…

CVE-2026-55485
GitHub-GHSA

HIGH
Yamcs Core API has Multiple Missing Function Level Access Control vulnerabilities
GHSA-962x-ccwf-8x6p
pkg: org.yamcs:yamcs-core, org.yamcs:yamcs-core
eco: maven
published: Aug 28, 2026
### Summary
Multiple Missing Function Level Access Control vulnerabilities exist in the Yamcs Core API. These vulnerabilities allow any authenticated user, regardless of their assigned roles or privileges (e.g., an unprivileged "Guest"), to bypass intended access controls. An attacker can exploit th…
CVE-2026-55521
NVD

HIGH
CVE-2026-10036
CVE-2026-10036
pkg: python

published: Aug 27, 2026

SpeechBrain before 1.1.1 contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary code by supplying a crafted CKPT.yaml checkpoint metadata file parsed with PyYAML's unsafe loader during candidate enumeration in Checkpointer.recover_if_possible(). Attackers can e…
CWE: CWE-502
NVD

HIGH
CVE-2026-81581
CVE-2026-81581
pkg: windows

published: Aug 27, 2026

Improper validation of memory boundaries in WibuKey64.sys of WibuKey up to 6.70 for Windows can be exploited by an attacker by setting the pointers outside the scope of the program. This usually results in a denial of service, yet we cannot rule out the possibility of exploits that can cause Remote …
CWE: CWE-119
NVD

HIGH
CVE-2026-81579
CVE-2026-81579
pkg: windows

published: Aug 27, 2026

In WibuKey for Windows before version 6.71, an untrusted pointer dereference in the WibuKey2_64.sys kernel driver for 64-bit Windows allows an attacker to exploit a write-what-where primitive, enabling local privilege escalation. This can be leveraged to execute arbitrary code, run an administrator …
CWE: CWE-123
NVD

HIGH
CVE-2026-58474
CVE-2026-58474
pkg: python

published: Aug 26, 2026

whichllm before 0.5.16 contains a code injection vulnerability in the run and snippet commands that allows a remote attacker who controls a HuggingFace repository to achieve arbitrary code execution by crafting a malicious GGUF filename containing double quotes or other special characters. The scrip…
CWE: CWE-94
NVD

HIGH
CVE-2026-80548
CVE-2026-80548
pkg: windows

published: Aug 26, 2026

In the Linux kernel, the following vulnerability has been resolved:

s390/vfio_ccw: Selectively expand io_mutex

The io_mutex was defined to serialize the io_regions, but then has
also sort of been associated with the I/O themselves because of
the close relationship they share.

With the handful of …

NVD

HIGH
CVE-2026-19042
CVE-2026-19042
pkg: linux

published: Aug 26, 2026

A command injection vulnerability in TeamViewer Full
Client and Host for Linux prior to version 15.81.5 allows a remote attacker to
execute arbitrary commands in the context of the current user via a specially
crafted URL sent through the out-of-session chat feature. Exploitation requires
user inter…
CWE: CWE-78
NVD

HIGH
CVE-2026-79240
CVE-2026-79240
pkg: windows

published: Aug 25, 2026

Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-787
NVD

HIGH
CVE-2026-79048
CVE-2026-79048
pkg: google chrome, microsoft windows

published: Aug 25, 2026

Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-787
NVD

HIGH
CVE-2026-78978
CVE-2026-78978
pkg: google chrome, microsoft windows

published: Aug 25, 2026

Out of bounds read in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-125
NVD

HIGH
CVE-2026-78944
CVE-2026-78944
pkg: google chrome

published: Aug 25, 2026

Use after free in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium)
CWE: CWE-416
NVD

HIGH
CVE-2026-78938
CVE-2026-78938
pkg: google chrome

published: Aug 25, 2026

Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-843
NVD

HIGH
CVE-2026-78910
CVE-2026-78910
pkg: google chrome

published: Aug 25, 2026

Buffer overflow in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-121
NVD

HIGH
CVE-2026-78905
CVE-2026-78905
pkg: google chrome

published: Aug 25, 2026

Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-843
NVD

HIGH
CVE-2026-78899
CVE-2026-78899
pkg: google chrome

published: Aug 25, 2026

Use after free in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-78891
CVE-2026-78891
pkg: google chrome

published: Aug 25, 2026

Buffer overflow in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-122
NVD

HIGH
CVE-2026-66152
CVE-2026-66152
pkg: linux

published: Aug 25, 2026

A Path traversal vulnerability in OPSWAT tarball in the SonicWall NetExtender Linux client allows an attacker to write arbitrary file as root.
CWE: CWE-29
NVD

HIGH
CVE-2026-55585
CVE-2026-55585
pkg: express

published: Aug 25, 2026

QWED is open-source AI verification infrastructure for deterministic verification of LLM outputs, tool calls, code, schemas, and agent state before production execution. Prior to 5.1.2, the qwed package passes caller-controlled math expressions directly to SymPy parse_expr() without restricted globa…
CWE: CWE-94
GitHub-GHSA

HIGH
qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`
GHSA-q27q-98j4-9pfv
pkg: qwed
eco: pip
published: Aug 25, 2026
### Summary

The `qwed` package (version 5.1.1) passes attacker-controlled input directly to SymPy's `parse_expr()` function without a restricted namespace. Because `parse_expr()` internally calls Python's `eval()`, any authenticated tenant can execute arbitrary Python code inside the API server pro…

CVE-2026-55585
NVD

HIGH
CVE-2026-75574
CVE-2026-75574
pkg: express

published: Aug 25, 2026

The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled Email action parameters as unsandboxed Twig templates. An authenticated remote user with only api.access and api.pages.write permissions can place a Twig expression in header.form.process.email.body, publis…
CWE: CWE-1336
NVD

HIGH
CVE-2026-76841
CVE-2026-76841
pkg: python

published: Aug 24, 2026

Xinference loads models with Hugging Face remote code execution unconditionally enabled, and before version 2.12.0 exposes no setting to disable it. Six loader call sites pass trust_remote_code=True as a literal or as an unconditional default: RerankModel._get_tokenizer in xinference/model/rerank/co…
CWE: CWE-94
NVD

HIGH
CVE-2026-59565
CVE-2026-59565
pkg: windows

published: Aug 24, 2026

A remotely exploitable buffer overflow bug can cause a local and kernel denial-of-service attack on affected versions of Zscaler Client Connector on Windows.
CWE: CWE-229
GitHub-GHSA

HIGH
Plate: Media embed provider metadata can bypass URL sanitization and execute iframe JavaScript
GHSA-qj6x-xx2h-8hvv
pkg: @platejs/media
eco: npm
published: Aug 25, 2026
## Summary

The media embed renderer trusts serialized `provider` or `sourceUrl` metadata and skips the URL protocol validation that normally blocks unsafe media embed URLs. A crafted Plate document can set a known video provider while keeping `url` as a `javascript:` iframe source. When a victim op…

CVE-2026-55596
NVD

HIGH
CVE-2026-59335
CVE-2026-59335
pkg: jwt

published: Aug 25, 2026

Improper handling of case sensitivity (CWE-178) in the identity zone authorization check in the Identity Zone Endpoint in Cloud Foundry UAA allows a remote authenticated attacker holding only the zones.write authority to bypass the intended restriction that this authority does not grant access to th…
CWE: CWE-178
GitHub-GHSA

HIGH
Sakai Conversations has a Stored XSS Issue
GHSA-w2x5-gv52-9ccv
pkg: org.sakaiproject.conversations:sakai-conversations-impl, org.sakaiproject.kernel:sakai-kernel-impl, org.sakaiproject.rubrics:rubrics-impl
eco: maven
published: Aug 24, 2026
### Summary

The Sakai Conversations tool stores topic and post messages without HTML sanitization, and the frontend renders them using LitElement's `unsafeHTML()` directive, resulting in stored cross-site scripting (XSS). Any authenticated user with access to a site that has the Conversations tool …

CVE-2026-54049
NVD

HIGH
CVE-2026-82641
CVE-2026-82641
pkg: tls

published: Aug 30, 2026

keploy versions 3.1.0 through 3.6.25 bind the agent control-plane HTTP server to all interfaces without authentication, exposing endpoints that stream TLS session keys and traffic data. Attackers can access the /agent/pcap/keylog endpoint to retrieve NSS keylog lines and decrypt recorded TLS traffic…
CWE: CWE-306
NVD

HIGH
CVE-2026-55848
CVE-2026-55848
pkg: kubernetes

published: Aug 28, 2026

mapfish-print is a component of MapFish for printing templated cartographic maps. Prior to 3.28.30, 3.30.32, 3.31.24, 3.33.16, and 4.0.5, MapFish Print accepts an attacker-controlled GML layer url in requests to the /api/print3/print endpoint and fetches XML parsed by core/src/main/java/org/mapfish/…
CWE: CWE-611
GitHub-GHSA

HIGH
MapFish Print has XXE that allows reading arbitrary files of certain types
GHSA-5v29-34h8-v68r
pkg: org.mapfish.print:print-lib, org.mapfish:print.print-servlet, org.mapfish.print:print-lib
eco: maven
published: Aug 28, 2026
### Summary
XXE on MapFish Print allows reading arbitrary files of certain types. Eg /etc/passwd or k8 secrets and certs.

https://github.com/mapfish/mapfish-print/commit/13020c0fbc299e5f604e4e66066311c4bf04d507

### Details
To trigger the XXE it is required to host a remote script and dtd file. Whe…

CVE-2026-55848
GitHub-GHSA

HIGH
9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass
GHSA-8gmq-j984-vp4r
pkg: 9router
eco: npm
published: Aug 28, 2026
## Summary

9router exposes an OpenAI/Anthropic-compatible LLM proxy. Remote access to this proxy is intended to be protected by an API-key check in the Next.js middleware.

However, 9router also defines a rewrite that maps `/codex/*` to the backend LLM endpoint `/api/v1/responses`. The middleware a…

CVE-2026-55638
GitHub-GHSA

HIGH
@logtape/syslog: syslog log injection via unescaped control characters and unvalidated SD-NAME keys
GHSA-8h6h-x5pq-56fq
pkg: @logtape/syslog, @logtape/syslog, @logtape/syslog
eco: npm
published: Aug 26, 2026
`@logtape/syslog` contains two related output-encoding bugs in the structured data formatting code. Both only affect deployments with `includeStructuredData: true`, which is non-default.

## 1. Unescaped C0 control characters in structured data values

`escapeStructuredDataValue()` in `packages/sysl…

CVE-2026-54511
GitHub-GHSA

HIGH
@arikusi/deepseek-mcp-server has an Authorization Bypass Through User-Controlled Key
GHSA-fh3r-g96v-f578
pkg: @arikusi/deepseek-mcp-server
eco: npm
published: Aug 25, 2026
# Cross-Session Data Exposure via Caller-Controlled `session_id`

Project / Repository: `arikusi/deepseek-mcp-server`
Affected version / commit tested: `1.6.0` / `04f28be2c6e99d3d4e443a6ae37cc35f0a71554a`
Vulnerability type: Authorization bypass / cross-session data exposure
Authentication requ…

CVE-2026-55604
GitHub-GHSA

HIGH
PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, cancel and delete
GHSA-2jgc-f764-c5r2
pkg: PraisonAI
eco: pip
published: Aug 25, 2026
### Summary
PraisonAI's async **Jobs API** (the FastAPI service in `praisonai/jobs/`) installs its router with no authentication middleware, no router-level dependency, and no per-route auth check. Any caller who can reach the jobs server can submit agent jobs (executed against the operator's config…
CVE-2026-55539
GitHub-GHSA

HIGH
PraisonAI serve agents –api-key is ignored, allowing unauthenticated remote agent execution
GHSA-7ww9-85pg-cv4x
pkg: PraisonAI
eco: pip
published: Aug 25, 2026
### Summary

PraisonAI's `praisonai serve agents` command exposes `–api-key` as the documented
authentication control for production/external deployments, but the configured key is not
enforced on the public agent invocation compatibility endpoints.

An operator can start the server with `-…

CVE-2026-55534
NVD

HIGH
CVE-2026-55108
CVE-2026-55108
pkg: node

published: Aug 28, 2026

KubeVela is an open source application delivery platform. Prior to 1.9.14, from 1.10.0-alpha.1 until 1.10.9, and from 1.11.0-alpha.1 until 1.11.0-alpha.4, the Terraform remote configuration loader in pkg/controller/utils/capability.go, GetTerraformConfigurationFromRemote, clones a repository supplie…
CWE: CWE-59, CWE-400
GitHub-GHSA

HIGH
KubeVela Terraform remote loader DoS via unbounded file read
GHSA-fmgp-q6jx-gg3x
pkg: github.com/oam-dev/kubevela, github.com/oam-dev/kubevela, github.com/oam-dev/kubevela
eco: go
published: Aug 28, 2026
### Summary

KubeVela's Terraform remote configuration loader can be abused to make `vela-core` read an unbounded byte stream into memory, causing an out-of-memory kill and a control-plane denial of service.

The issue is reachable when a user with permission to create or update a `core.oam.dev/v1be…

CVE-2026-55108
NVD

HIGH
CVE-2026-65092
CVE-2026-65092
pkg: linux

published: Aug 25, 2026

NVIDIA OpenShell Sandbox for Linux contains a vulnerability where an attacker could cause a path traversal bypass of L7 REST network policy. A successful exploit of this vulnerability might lead to information disclosure and data tampering.
CWE: CWE-22
GitHub-GHSA

HIGH
praisonaiagents has an SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)
GHSA-x44h-65qv-cw74
pkg: praisonaiagents
eco: pip
published: Aug 25, 2026
### Summary

`praisonaiagents/tools/spider_tools.py` contains an SSRF protection bypass. The function
`_host_is_blocked()` validates URLs against a list of blocked IP literals and hostname
aliases, but **never performs DNS resolution**. Any hostname that resolves to a private or
loopback IP address …

CVE-2026-55526
NVD

HIGH
CVE-2026-68960
CVE-2026-68960
pkg: windows

published: Aug 25, 2026

A stack-based buffer overflow vulnerability exists in SKYSEA Client View and SKYMEC IT Manager. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may be able to execute arbitrary code on another Windows system that has the a…
CWE: CWE-121
NVD

HIGH
CVE-2026-68959
CVE-2026-68959
pkg: windows

published: Aug 25, 2026

SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may be able to execute arbitrary code on another Windows system that has the affected product…
CWE: CWE-25
NVD

HIGH
CVE-2026-68062
CVE-2026-68062
pkg: windows

published: Aug 25, 2026

SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may be able to execute arbitrary code on another Windows system that has the affected product…
CWE: CWE-22
NVD

HIGH
CVE-2026-81683
CVE-2026-81683
pkg: openssl

published: Aug 27, 2026

openssl_encrypt (pip package openssl-encrypt) versions 1.4.8 and earlier store an mTLS client private key in cleartext within a world-readable (0644) SharedPreferences file via the desktop GUI's Settings screen 'combined certificate and private key' PEM field. A local attacker with file system acces…
CWE: CWE-312
NVD

HIGH
CVE-2026-55582
CVE-2026-55582
pkg: docker

published: Aug 25, 2026

mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default security.yaml allows /usr/bin/git, while security.go omits ! from containsShellMetacharacters and containsDangerousShellConstructs and applies no per-executable argument policy. A ca…
CWE: CWE-78
NVD

HIGH
CVE-2026-55581
CVE-2026-55581
pkg: docker

published: Aug 25, 2026

mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default Docker security.yaml includes /bin/bash in allowed_executables, while security.go validates only the first token and checkBlockedPatternsAndCommands does not reject the shell command…
CWE: CWE-78, CWE-183, CWE-1188
GitHub-GHSA

HIGH
mcp-shell has a Secure Mode Allowlist Bypass via Default `/bin/bash` Executable
GHSA-3×77-wg38-92r3
pkg: github.com/sonirico/mcp-shell
eco: go
published: Aug 25, 2026
### Summary

`mcp-shell` ships a default Docker configuration (`security.yaml`) that includes `/bin/bash` in the `allowed_executables` allowlist. The command validator (`security.go`) only checks whether the first token of the supplied command matches an allowed executable; it does not inspect or re…

CVE-2026-55581
GitHub-GHSA

HIGH
mcp-shell has a Secure Mode Allowlist Bypass via Git Shell Alias
GHSA-74hp-mggr-hv58
pkg: github.com/sonirico/mcp-shell
eco: go
published: Aug 25, 2026
### Summary

`mcp-shell`'s "secure mode" is designed to restrict command execution to an allowlist of executables defined in `security.yaml`. The default configuration includes `/usr/bin/git`. The security validator in `security.go` blocks common shell metacharacters (`|&;<>(){}[]$\“) but omits `!`…

CVE-2026-55582
GitHub-GHSA

HIGH
RestrictedPython guard hooks can be shadowed via positional-only arguments
GHSA-ffg3-p8fm-mjx2
pkg: RestrictedPython
eco: pip
published: Aug 28, 2026
### Impact

RestrictedPython rewrites sensitive operations to go through guard hooks. Attribute access becomes `_getattr_(obj, name)`, item access becomes `_getitem_(obj, key)`, writes go through `_write_`, and print goes through `_print_`. The embedding application supplies these hooks to enforce i…

CVE-2026-55830
NVD

HIGH
CVE-2026-79247
CVE-2026-79247
pkg: google chrome, microsoft windows

published: Aug 25, 2026

Use after free in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-79175
CVE-2026-79175
pkg: google chrome, microsoft windows

published: Aug 25, 2026

Type confusion in Accessibility in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-843
NVD

HIGH
CVE-2026-78952
CVE-2026-78952
pkg: google chrome, microsoft windows

published: Aug 25, 2026

Out of bounds write in Crashpad in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-787
NVD

HIGH
CVE-2026-78934
CVE-2026-78934
pkg: google chrome

published: Aug 25, 2026

Race condition in ReadAloud in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-362
NVD

HIGH
CVE-2026-78911
CVE-2026-78911
pkg: google chrome

published: Aug 25, 2026

Incorrect authorization in USB in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-863
GitHub-GHSA

HIGH
9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF
GHSA-86m2-fcxq-5q7c
pkg: 9router
eco: npm
published: Aug 28, 2026
## Summary

9router's request guard decides a request is "local" (and therefore exempt from API-key auth on the `/v1` LLM proxy) by reading the **client-controlled `Host` header**. Because 9router binds `0.0.0.0` by default (and the CLI misleadingly prints "localhost"), a remote, unauthenticated att…

CVE-2026-55641
NVD

HIGH
CVE-2026-59316
CVE-2026-59316
pkg: oauth

published: Aug 27, 2026

Spring Authorization Server's default consent page renders user-controlled values without HTML entity encoding. When using the DefaultConsentPage, an attacker can craft an OAuth2 authorization request containing a malicious value that is stored server-side and later rendered unencoded in the default…
CWE: CWE-79
NVD

HIGH
CVE-2026-80208
CVE-2026-80208
pkg: nginx

published: Aug 27, 2026

APITable through 1.13.0-beta.1 annotates both getUserHistories and closePausedUserAccount in InternalUserController with requiredLogin = false. ResourceInterceptor honours that annotation by returning before any session or API key is validated, and the nginx gateway shipped with the product proxies …
CWE: CWE-306
NVD

HIGH
CVE-2026-55571
CVE-2026-55571
pkg: react

published: Aug 25, 2026

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to 1.0.4, LiveViewConsumer.handle_mount sends a `{"type":"navigate","to":…}` frame when login_required, permission_required, or a redirecting on_mount hook denies a LiveView mount, …
CWE: CWE-285, CWE-306
NVD

HIGH
CVE-2026-55533
CVE-2026-55533
pkg: jwt

published: Aug 25, 2026

PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, create_auth_middleware() allows requests when auth=api-key lacks PRAISONAI_API_KEY or JWT authentication lacks PRAISONAI_JWT_SECRET. An externally bound Recipe server can therefore accept unauthenticated POST /v1/recipes/run request…
CWE: CWE-287, CWE-306
GitHub-GHSA

HIGH
djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls
GHSA-xx4j-w367-7247
pkg: djust
eco: pip
published: Aug 25, 2026
### Impact

djust's `LiveViewConsumer` mounts a `LiveView` over a WebSocket. When a view is gated (`login_required` / `permission_required`, or an `on_mount` hook that returns a redirect) and the connecting user is not authorized, the consumer sent the client a `{"type":"navigate","to":…}` redirec…

CVE-2026-55571
GitHub-GHSA

HIGH
utcp-http SSRF: HTTP tool invocation follows redirects without re-validating the target
GHSA-9qhg-99ww-9mqc
pkg: utcp-http
eco: pip
published: Aug 25, 2026
## Summary

`HttpCommunicationProtocol.call_tool` validates only the pre-redirect tool URL, then issues the request with redirects enabled and never re-checks where it lands. A tool whose endpoint is an attacker-controlled public URL can therefore `302`-redirect the UTCP client into an internal serv…

GitHub-GHSA

HIGH
PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret
GHSA-gfq8-hmph-9gjv
pkg: PraisonAI
eco: pip
published: Aug 25, 2026
### Summary

The PraisonAI Recipe HTTP server silently allows unauthenticated requests when `auth` is configured as `api-key` or `jwt` but the corresponding secret is missing.

This creates an authentication fail-open condition. An operator can start the Recipe server with authentication enabled, in…

CVE-2026-55533
GitHub-GHSA

HIGH
praisonaiagents: AgentServer declares auth_token but never enforces it on any route
GHSA-7g3p-92qq-8wvh
pkg: praisonaiagents
eco: pip
published: Aug 25, 2026
**Researcher:** Kai Aizen — SnailSploit (@SnailSploit), Adversarial & Offensive Security Research
**Target:** https://github.com/MervinPraison/PraisonAI

**Package:** `praisonaiagents` on PyPI
**Affected version (empirically tested):** 1.6.48
**Component:** `praisonaiagents.server.AgentServer…

CVE-2026-55528
NVD

HIGH
CVE-2026-76842
CVE-2026-76842
pkg: node

published: Aug 24, 2026

The Mercado Pago Node.js SDK interpolates caller-supplied identifiers into API request paths without percent-encoding them, so characters that are structural in a URL survive into the outgoing request. The payment (get, capture, cancel), paymentRefund (create, total, list, get), advancedPayment (get…
CWE: CWE-22
NVD

HIGH
CVE-2026-56100
CVE-2026-56100
pkg: jwt

published: Aug 28, 2026

SpringBlade versions from 2.7.3 up to but not including 5.0.0 contain a privilege escalation vulnerability that allows authenticated attackers to create system administrator accounts by sending crafted POST requests to an unprotected internal Feign user-creation endpoint exposed via @RestController …
CWE: CWE-862
GitHub-GHSA

HIGH
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
GHSA-2q2q-jr9g-v9rf
pkg: Weblate
eco: pip
published: Aug 28, 2026
### Impact
The API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to.

### Patches
* https://github.com/WeblateOrg/weblate/pull/19970

### References

Parts of this issue were indep…

CVE-2026-55228
GitHub-GHSA

HIGH
Vikunja vulnerable to Improper Authorization and Authorization Bypass Through User-Controlled Key
GHSA-gg93-x632-9ccv
pkg: code.vikunja.io/api
eco: go
published: Aug 28, 2026
### Summary

A user with only a single self-owned project can permanently destroy the Kanban bucket assignments (`task_buckets`) and task ordering (`task_positions`) of **any other project view in the entire instance**. The `ProjectView.Delete` model method runs three SQL statements: the first is pr…

CVE-2026-55065
NVD

HIGH
CVE-2026-81036
CVE-2026-81036
pkg: oauth

published: Aug 26, 2026

Stalwart Mail Server does not compare an OAuth redirect target against any registered destination in its default configuration. The validation routine in crates/http/src/auth/oauth/registration.rs returns success immediately when the client-authentication requirement is disabled, and that requiremen…
CWE: CWE-601
NVD

HIGH
CVE-2026-81029
CVE-2026-81029
pkg: jwt

published: Aug 26, 2026

OpenMetadata accepts a caller-supplied post-authentication redirect target and appends the issued token to it. SamlLoginServlet reads the callback request parameter and stores it in the HTTP session without comparing it against any configured or registered destination, and the assertion consumer ser…
CWE: CWE-601
GitHub-GHSA

HIGH
asyncssh has SCP Path Traversal to Arbitrary File Write
GHSA-2wxc-x7rj-hg8f
pkg: asyncssh
eco: pip
published: Aug 26, 2026
| | |
|—|—|
| Product | asyncssh (all versions through 2.23.0) |
| Related | CVE-2019-6111 (same class in OpenSSH) |
| Fix | AsyncSSH 2.23.1 |

A malicious SSH server can write arbitrary files on the asyncssh SCP client's filesystem by sending filenames containing `../` traversal sequences. The …

CVE-2026-54591
NVD

HIGH
CVE-2026-79194
CVE-2026-79194
pkg: google chrome, microsoft windows

published: Aug 25, 2026

Use after free in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-78913
CVE-2026-78913
pkg: google chrome

published: Aug 25, 2026

Use after free in Chromoting in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)
CWE: CWE-416
NVD

HIGH
CVE-2026-65105
CVE-2026-65105
pkg: linux

published: Aug 25, 2026

NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote attacker may access the inference service without authentication. A successful exploit of this vulnerability may lead to information disclosure and denial of service.
CWE: CWE-306
NVD

HIGH
CVE-2026-65098
CVE-2026-65098
pkg: linux

published: Aug 25, 2026

NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering.
CWE: CWE-1390
NVD

HIGH
CVE-2026-65084
CVE-2026-65084
pkg: linux

published: Aug 25, 2026

NVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, code execution, and escalation of privileges.
CWE: CWE-295
NVD

HIGH
CVE-2026-65081
CVE-2026-65081
pkg: linux

published: Aug 25, 2026

NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker could cause execution of untrusted code. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, information disclosure, and denial of service.
CWE: CWE-494
NVD

HIGH
CVE-2026-78379
CVE-2026-78379
pkg: python

published: Aug 25, 2026

Improper neutralization of input used for LLM prompting in the python_repl tool in Amazon Strands Agents Tools before 0.8.5 might allow remote actors to execute arbitrary Python code on the agent's host by bypassing the human consent gate, via a crafted prompt that forwards non_interactive_mode as a…
NVD

HIGH
CVE-2026-16231
CVE-2026-16231
pkg: express

published: Aug 25, 2026

hbs is an Express view engine that wraps Handlebars. Its registerAsyncHelper API bypasses Handlebars' automatic HTML escaping: an async helper returns an opaque placeholder during the first render pass, so the double-brace expression escapes only the placeholder, and after rendering hbs substitutes …
CWE: CWE-79
NVD

HIGH
CVE-2026-79662
CVE-2026-79662
pkg: jwt

published: Aug 25, 2026

Ech0 through 4.5.6 contains an OAuth redirect URI validation vulnerability in parseAndValidateClientRedirect (internal/service/auth/auth.go) that compares only the scheme and host of the client-supplied redirect_uri against the admin-configured allowlist, ignoring path, query, and fragment component…
CWE: CWE-601
NVD

HIGH
CVE-2026-78414
CVE-2026-78414
pkg: linux

published: Aug 24, 2026

Cross-site scripting in the Web Administration interface of Network Optix Nx Witness VMS before version 6.1.3 on Linux, Windows and MacOS allows an adjacent-network attacker to execute arbitrary JavaScript in the browser of an authenticated administrator and steal the administrator's session token, …
CWE: CWE-79
NVD

HIGH
CVE-2026-44629
CVE-2026-44629
pkg: windows

published: Aug 28, 2026

Improper access control to the Synergis Softwire installation folder. This vulnerability affects Streamvault all-in-one appliances (SV-100E and SV-300E series) and Synergis Softwire installed on Windows servers.
CWE: CWE-922
GitHub-GHSA

HIGH
Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data
GHSA-jw39-3688-r4rx
pkg: compliance-trestle, compliance-trestle
eco: pip
published: Aug 28, 2026
### Impact

A Server-Side Template Injection (SSTI) vulnerability exists in multiple locations of trestle's Jinja2 rendering pipeline due to a systemic pattern: **untrusted data is re-parsed as Jinja2 template source code without sandboxing**. This advisory tracks the root cause across all affected …

CVE-2026-54757
NVD

HIGH
CVE-2026-80710
CVE-2026-80710
pkg: express

published: Aug 28, 2026

In the Linux kernel, the following vulnerability has been resolved:

s390/dasd: Fix undersized format-check buffer

fmt_buffer_size in dasd_eckd_check_device_format() is declared as
int, even though one of the multiplicands, sizeof(struct eckd_count),
is a size_t. The expression

trkcount * rpt_…

NVD

HIGH
CVE-2026-80709
CVE-2026-80709
pkg: node

published: Aug 28, 2026

In the Linux kernel, the following vulnerability has been resolved:

s390/zcrypt: Fix wrong domain value verification with EP11 CPRBs

There is a wrong upper limit check for the domain value when an EP11
CPRB is processed for sending to a crypto card. This check is only
active on custom device nodes…

NVD

HIGH
CVE-2026-80682
CVE-2026-80682
pkg: express

published: Aug 28, 2026

In the Linux kernel, the following vulnerability has been resolved:

riscv/mm: use physical alignment for vmemmap_start_pfn

RISC-V computes vmemmap_start_pfn by rounding phys_ram_base down to
VMEMMAP_ADDR_ALIGN. That alignment must therefore be expressed in the
physical-address domain.

Commit 476…

NVD

HIGH
CVE-2026-80656
CVE-2026-80656
pkg: express

published: Aug 28, 2026

In the Linux kernel, the following vulnerability has been resolved:

hfsplus: Add a sanity check for btree node size

Syzbot reported an uninit-value bug in [1] with a corrupted HFS+ image,
during the file system mounting process, specifically while loading the
catalog, a corrupted node_size value o…

NVD

HIGH
CVE-2026-81719
CVE-2026-81719
pkg: openssl

published: Aug 27, 2026

openssl_encrypt before 1.4.9 executes untrusted third-party plugins with insufficient controls: the plugin signature policy defaulted to WARN, so an unsigned/unverifiable non-built-in plugin was compiled and executed in the host process at import time, before the runtime sandbox is installed. The on…
CWE: CWE-94
NVD

HIGH
CVE-2026-80522
CVE-2026-80522
pkg: linux

published: Aug 26, 2026

In the Linux kernel, the following vulnerability has been resolved:

crypto: tegra – fix rctx->cryptlen calculation in tegra_gcm_do_one_req()

Perform rctx->cryptlen calculation in tegra_gcm_do_one_req() the same way
it is done in tegra_ccm_crypt_init(). The current formulae may lead to a
crash if a…

NVD

HIGH
CVE-2026-80521
CVE-2026-80521
pkg: linux

published: Aug 26, 2026

In the Linux kernel, the following vulnerability has been resolved:

af_unix: Unlink scc_entry in unix_del_edge().

Kyle Zeng reported that GC could free a dead SCC partially.

The scenario is as follows:

1) Create two SCCs:

X -. A <-> B
^–'

2) Run the following concurrentl…

NVD

HIGH
CVE-2026-74753
CVE-2026-74753
pkg: linux

published: Aug 26, 2026

In the Linux kernel, the following vulnerability has been resolved:

perf: Reject exited events as group leaders

perf_event_remove_on_exec() sets remove-on-exec events to the EXIT state
and detaches their group relationships. The event's file descriptor can
remain open, however, and perf_event_ope…

NVD

HIGH
CVE-2026-74748
CVE-2026-74748
pkg: linux

published: Aug 26, 2026

In the Linux kernel, the following vulnerability has been resolved:

netfilter: ipset: fix refcount race between list:set GC and swap

__ip_set_put_byindex() resolved the index to a set pointer under RCU,
then took ip_set_ref_lock in __ip_set_put() to decrement set->ref.
ip_set_swap() holds that sam…

NVD

HIGH
CVE-2026-74747
CVE-2026-74747
pkg: linux

published: Aug 26, 2026

In the Linux kernel, the following vulnerability has been resolved:

ipvs: revalidate ihl to prevent out-of-bounds access

While the outer IP header is already pulled into the skb head,
we must be careful and revalidate the embedded headers after
reading them from the skb frags to prevent out-of-bou…

NVD

HIGH
CVE-2026-74739
CVE-2026-74739
pkg: linux

published: Aug 26, 2026

In the Linux kernel, the following vulnerability has been resolved:

net/sched: cls_u32: skip hash tables in u32_bind_class()

u32_walk() enumerates both struct tc_u_hnode and struct tc_u_knode
through the walker callback. u32_bind_class() unconditionally casts the
passed fh to tc_u_knode and access…

NVD

HIGH
CVE-2026-74736
CVE-2026-74736
pkg: linux

published: Aug 26, 2026

In the Linux kernel, the following vulnerability has been resolved:

net/sched: cls_bpf: reject dev-bound programs bound to a different device

cls_bpf_prog_from_efd() obtained a SCHED_CLS program via
bpf_prog_get_type_dev() but never verified that a device-bound (offloaded)
program's bound netdev m…

NVD

HIGH
CVE-2026-77658
CVE-2026-77658
pkg: linux

published: Aug 26, 2026

A stack-based buffer overflow vulnerability exists in the Dia diagram editor when processing Network Bus objects from Dia XML project files.

In objects/network/bus.c, bus_load() reads the number of bus handles from the file attribute "bus_handles" using attribute_num_data() without validating an up…

CWE: CWE-121
NVD

HIGH
CVE-2026-57170
CVE-2026-57170
pkg: express

published: Aug 26, 2026

Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions prior to 3.12.4 and 4.0.0 through 4.0.3, the custom Jinja2 include tags mdsection_include and md_clean_include re-parse the content of an included Markdown file as Jinja2 template …
CWE: CWE-94, CWE-1336
NVD

HIGH
CVE-2026-54757
CVE-2026-54757
pkg: express

published: Aug 25, 2026

Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, Trestle is vulnerable to server-side template injection that can lead to remote code execution. This occurs because the MDCleanInclu…
CWE: CWE-94
NVD

HIGH
CVE-2026-65099
CVE-2026-65099
pkg: linux

published: Aug 25, 2026

NVIDIA NemoClaw for Linux contains a vulnerability in its command-line interface, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.
CWE: CWE-78
NVD

HIGH
CVE-2026-65096
CVE-2026-65096
pkg: linux

published: Aug 25, 2026

NVIDIA NemoClaw for Linux contains a vulnerability in the Telegram bridge component, where an attacker could cause an OS command injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
CWE: CWE-78
NVD

HIGH
CVE-2026-65090
CVE-2026-65090
pkg: linux

published: Aug 25, 2026

NVIDIA NemoClaw for Linux contains a vulnerability in its NIM management component, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.
CWE: CWE-78
NVD

HIGH
CVE-2026-65089
CVE-2026-65089
pkg: linux

published: Aug 25, 2026

NVIDIA NemoClaw for Linux contains a vulnerability in its status and logs plugin commands, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.
CWE: CWE-78
NVD

HIGH
CVE-2025-71406
CVE-2025-71406
pkg: node

published: Aug 25, 2026

Nokogiri before 1.18.4 bundles a vulnerable version of libxslt (prior to 1.1.43) that contains two use-after-free vulnerabilities: CVE-2025-24855 (use-after-free of the XPath context node due to xsltEvalXPathStringNs leaking xpathCtxt->node) and CVE-2024-55549 (use-after-free related to excluded res…
CWE: CWE-416
GitHub-GHSA

HIGH
PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code
GHSA-hxmv-c4g6-5fqc
pkg: praisonaiagents, PraisonAI
eco: pip
published: Aug 25, 2026
## Summary

PraisonAI's workflow include implementation implicitly imports and executes an included recipe's `tools.py` file even when the documented `tools.py` autoload opt-in is unset.

This bypasses the hardening added for the prior automatic `tools.py` RCE advisory family. A workflow that includ…

CVE-2026-55522
NVD

HIGH
CVE-2026-69665
CVE-2026-69665
pkg: windows

published: Aug 25, 2026

SKYSEA Client View and SKYMEC IT Manager contain an issue with incorrect default permissions. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may execute arbitrary code with SYSTEM privilege.
CWE: CWE-276
NVD

HIGH
CVE-2026-66109
CVE-2026-66109
pkg: windows

published: Aug 25, 2026

A missing authorization vulnerability exists in SKYSEA Client View and SKYMEC IT Manager. If this vulnerability is exploited, an attacker who can log in to the Windows system on which the affected product is installed may execute arbitrary code with SYSTEM privilege.
CWE: CWE-862
NVD

HIGH
CVE-2026-78680
CVE-2026-78680
pkg: windows

published: Aug 25, 2026

NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot binary in dependencygraph.dot2img and AlignedSent._repr_svg_, allowing attackers to execute arbitrary code by placing a malicious dot binary in the search path or current working directory. Attackers can …
CWE: CWE-426
NVD

HIGH
CVE-2026-76843
CVE-2026-76843
pkg: python

published: Aug 24, 2026

The official Flair wheels for 0.15.0 and 0.15.1 still contain flair/models/clustering.py, whose ClusteringModel.load static method returns pickle.loads(joblib.load(str(model_file))) and so executes arbitrary Python while loading a model file. Loading a model supplied by an attacker therefore runs th…
CWE: CWE-502
NVD

HIGH
CVE-2026-30512
CVE-2026-30512
pkg: windows

published: Aug 24, 2026

A local privilege escalation vulnerability exists in the Restricted Access (Kiosk) Mode implementation of Scheidt & Bachmann entervo HMI prior to V2 R5 P0 M5. The vulnerability affects the external PDF viewer functionality used to display the application manual and its interaction with the underlyin…
CWE: CWE-250
GitHub-GHSA

HIGH
SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read
GHSA-56wq-x3wv-3ff4
pkg: github.com/seaweedfs/seaweedfs
eco: go
published: Aug 28, 2026
### Summary
The SeaweedFS S3 API gateway did not reject `..` path segments in the `X-Amz-Copy-Source` header used by `CopyObject` and `UploadPartCopy`. The request URL path was hardened against traversal in 4.30 (CVE-2026-54917), but the copy-source header was only checked for emptiness, so a `..` s…
CVE-2026-55874
GitHub-GHSA

HIGH
Incus has a project restriction bypass in instance copy across projects
GHSA-c9f5-j9c3-mhrg
pkg: github.com/lxc/incus/v7/cmd/incusd
eco: go
published: Aug 28, 2026
### Summary
Missing authorization checks exist for instance copying where an attacker knowing the name of a project that they don't have access to and the name of an instance in that project can copy the instance to a new project. This issue could allow an attacker to access secrets in instances the…
CVE-2026-55622
GitHub-GHSA

HIGH
Incus has a project restriction bypass for custom volume copy across projects
GHSA-64f3-v33m-w89f
pkg: github.com/lxc/incus/v7, github.com/lxc/incus/v6, github.com/lxc/incus
eco: go
published: Aug 28, 2026
### Summary

Missing authorization checks exist for custom volume copying where an attacker who knows the name of a project that they don't have access to and the name of a custom volume in that project can copy the custom volume to a new project. This issue could allow an attacker to access secrets…

CVE-2026-55621
NVD

HIGH
CVE-2026-75889
CVE-2026-75889
pkg: kubernetes

published: Aug 27, 2026

Grafana Alloy’s prometheus.operator.servicemonitors component allows a user who can create or modify ServiceMonitor resources in a watched namespace to specify an arbitrary local file through bearerTokenFile. Alloy reads the file and sends its contents as a bearer token to an attacker-controlled s…
CWE: CWE-552
NVD

HIGH
CVE-2026-61617
CVE-2026-61617
pkg: node

published: Aug 26, 2026

Wings is the server control plane for the Pterodactyl game-server management panel. In versions up to and including 1.13.2, the SFTP write path does not enforce a server's disk quota during a transfer, allowing a tenant with SFTP write access to a single server to exhaust the host node's physical di…
CWE: CWE-400, CWE-770
NVD

HIGH
CVE-2026-57171
CVE-2026-57171
pkg: python

published: Aug 26, 2026

Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, the catalog-generate, profile-generate, and ssp-generate author commands write generated Markdown to an attacker-influenced output p…
CWE: CWE-22
NVD

HIGH
CVE-2026-71366
CVE-2026-71366
pkg: node

published: Aug 24, 2026

A server-side request forgery (SSRF) vulnerability was found in multiple AWX notification backends. The webhook, Mattermost, Rocket.Chat, and Grafana notification backends use notification template URLs as direct HTTP request targets without validating the target address against private, loopback, o…
CWE: CWE-918
NVD

HIGH
CVE-2026-77368
CVE-2026-77368
pkg: jwt

published: Aug 26, 2026

SeaweedFS is a distributed storage system for files and blobs. In version 4.39, the filer's TUS resumable-upload handler checks JWT allowed_prefixes scoping only when a session is created, letting a low-privilege tenant hijack another tenant's upload session to write content to filer paths their own…
CWE: CWE-639
NVD

HIGH
CVE-2026-80186
CVE-2026-80186
pkg: linux

published: Aug 25, 2026

A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vuln…
CWE: CWE-120
GitHub-GHSA

HIGH
PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server
GHSA-pvph-5j39-v8qc
pkg: PraisonAI
eco: pip
published: Aug 25, 2026
### Summary

The PraisonAI MCP server exposes an HTTP-stream transport (praisonai mcp serve –transport http-stream) that binds to localhost and, by default, has no API key. Its only access control for browser-originated requests is an Origin allowlist, which the code implements as required by the M…

CVE-2026-55532
NVD

HIGH
CVE-2026-82644
CVE-2026-82644
pkg: curl

published: Aug 30, 2026

WWBN AVideo (current e01e41ecc and earlier) contains a brute-force rate limiting bypass in enforceRateLimit(), which protects login.json.php and 13 other endpoints. The function stores its attempt counter via a cache layer (ObjectYPT::setCacheGlobal) that silently discards writes for any client iden…
CWE: CWE-307
GitHub-GHSA

HIGH
free5GC AUSF authentication contexts can be overwritten by concurrent requests for the same SUPI
GHSA-334q-h5g3-fpxv
pkg: github.com/free5gc/ausf
eco: go
published: Aug 28, 2026
### Summary

The AUSF component of free5GC stores per-subscriber authentication state in a global `sync.Map` keyed only by SUPI. Every incoming authentication request creates a new `AusfUeContext` and stores it under that SUPI key without checking whether an authentication procedure is already in pr…

CVE-2026-55784
NVD

HIGH
CVE-2026-82333
CVE-2026-82333
pkg: node

published: Aug 28, 2026

multer is a middleware for handling multipart/form-data in Node.js. A small multipart request with two specially crafted text field names can make multer's field parser synchronously iterate a maximum-length sparse array, blocking the event loop so the process cannot handle other requests. A large n…
CWE: CWE-400
NVD

HIGH
CVE-2026-81518
CVE-2026-81518
pkg: tls

published: Aug 28, 2026

When mongosqld is configured with a client certificate authority file, the listener requests a client certificate during the TLS handshake but does not require one, so a client that presents no certificate is still accepted. In deployments that rely on client certificates as the sole means of identi…
CWE: CWE-295
NVD

HIGH
CVE-2026-77078
CVE-2026-77078
pkg: node

published: Aug 28, 2026

multer is a middleware for handling multipart/form-data in Node.js. A small multipart request containing two specially crafted text field names can cause an uncaught RangeError (Invalid array length) that terminates the Node.js process. The first field uses a very large numeric array index to alloca…
CWE: CWE-248
NVD

HIGH
CVE-2026-77037
CVE-2026-77037
pkg: node

published: Aug 28, 2026

multer is a middleware for handling multipart/form-data in Node.js. In version 2.2.0, when a disk-backed upload is aborted or truncated before the write stream finishes, multer's disk storage engine removes the visible file but does not close the underlying write file descriptor, leaving a deleted b…
CWE: CWE-400, CWE-459
GitHub-GHSA

HIGH
Fortigate syslog message parser can be exploited to modify or delete fields from the original message
GHSA-gqr6-r77p-c2pj
pkg: org.graylog2:graylog2-server, org.graylog2:graylog2-server, org.graylog2:graylog2-server
eco: maven
published: Aug 28, 2026
### Impact

A security issue has been identified in Graylog affecting the parsing of syslog messages that use a key-value format, such as those generated by Fortigate devices.

The vulnerability allows attackers to overwrite individual message fields, or to produce invalid messages which Graylog wil…

CVE-2026-55841
NVD

HIGH
CVE-2026-55215
CVE-2026-55215
pkg: ssl

published: Aug 28, 2026

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to versions 3.3.3, 3.4.6, and 3.5.3, when ssl is enabled without a pinned CA or server certificate, MariaDB Connector/Node.js sends credentials before completing certificate fingerpri…
CWE: CWE-295, CWE-522
GitHub-GHSA

HIGH
alos-http has unauthenticated remote DoS: malformed path starting with "?" triggers out-of-bounds panic in sanitizeRequestPath, crashing entire server
GHSA-hr6j-w4mw-g9mj
pkg: github.com/guno1928/alos-http
eco: go
published: Aug 28, 2026
### Summary
A single unauthenticated HTTP request to a path starting with `?` (e.g. `GET ? HTTP/1.1`) crashes the entire server process.
The request line parser passes the path to `sanitizeRequestPath` which indexes the first byte of the path after stripping the query string. It does so without chec…
CVE-2026-55484
GitHub-GHSA

HIGH
MariaDB's connector leaks the cleartext password to an MitM despite `ssl: true`
GHSA-cqhc-2h57-wpxf
pkg: mariadb, mariadb, mariadb
eco: npm
published: Aug 28, 2026
### Summary
When SSL/TLS is enabled but no CA / server certificate is provided, the
connector verifies the server's identity using fingerprint validation. The
check is effective, the connection is ultimately rejected when it fails,
but it happens *after* the authentication exchange. As a result, t…
CVE-2026-55215
GitHub-GHSA

HIGH
Spinnaker: Improper yaml processing on kustomize bake operations
GHSA-p68j-q7hf-3qcp
pkg: io.spinnaker.rosco:rosco-manifests, io.spinnaker.rosco:rosco-manifests, io.spinnaker.rosco:rosco-manifests
eco: maven
published: Aug 28, 2026
### Impact
Kustomize bake operations allow unsafe tag processing. This can lead to RCE type exploits on the rosco pods when doing kustomize bakes. This ONLY is possible when using Kustomize. The simple solution is to block kustomize operations and instead use another provider.

### Workarounds
Di…

CVE-2026-55175
GitHub-GHSA

HIGH
Yamcs has Unauthenticated Directory Traversal
GHSA-9jg3-g3wh-w9pj
pkg: org.yamcs:yamcs-core
eco: maven
published: Aug 28, 2026
### Attack type: 
Unauthenticated remote 

### Impact:
Attackers can access any system files from the underlying host.

### Affected components: HttpRequestHandler.java, StaticFileHandler.java

An Unauthenticated Directory Traversal vulnerability exists in Yamcs <=5.8.6, allowing anyone to acc…

CVE-2026-55552
GitHub-GHSA

HIGH
datadog-opentelemetry has unbounded W3C tracestate parsing that may lead to DoS
GHSA-gpwf-4h98-v82q
pkg: datadog-opentelemetry
eco: rust
published: Aug 28, 2026
### Impact
Datadog tracing libraries that implement W3C Trace Context (`tracecontext`) propagation parse the incoming `tracestate` header without enforcing a size cap on the Datadog vendor entry (`dd=…`). The `dd=` value contains semicolon-separated `key:value` pairs, and the parser allocates a ha…
CVE-2026-54788
NVD

HIGH
CVE-2026-75418
CVE-2026-75418
pkg: windows

published: Aug 28, 2026

A path traversal vulnerability exists in the built-in preview/development web server of Lektor <3.3.14 on Windows. An attacker with network access to the server can send a crafted HTTP request containing path traversal sequences to read arbitrary files accessible to the process, disclosing sensitive…
NVD

HIGH
CVE-2026-81721
CVE-2026-81721
pkg: openssl

published: Aug 27, 2026

openssl_encrypt before 1.4.9 fails to validate KDF cost parameters in encrypted file metadata and keystore headers, allowing attackers to trigger unbounded memory allocation. Attackers can craft malicious encrypted files declaring arbitrarily large Argon2, scrypt, or balloon KDF parameters to exhaus…
CWE: CWE-400
NVD

HIGH
CVE-2026-81718
CVE-2026-81718
pkg: openssl

published: Aug 27, 2026

openssl_encrypt versions before 1.4.9 use under-parameterized PBKDF2-HMAC-SHA256 with only 100,000 iterations to protect PQC keyfile private keys and 10,000 iterations for dual-encryption file-password verification. Attackers who obtain keyfiles or encrypted files can brute-force wrapping passwords …
CWE: CWE-326
NVD

HIGH
CVE-2026-81705
CVE-2026-81705
pkg: openssl

published: Aug 27, 2026

openssl-encrypt before 1.4.9 fails to redact the file password in its –debug argv dump when the password is supplied via bundled short-option spellings (e.g. -apHunter2) or abbreviated long-option spellings (e.g. –passw). The sanitizer only recognized exact option names, –option=value forms, and …
CWE: CWE-532
NVD

HIGH
CVE-2026-81704
CVE-2026-81704
pkg: openssl

published: Aug 27, 2026

openssl_encrypt versions before 1.4.9 contain a weak key derivation vulnerability in the D-Bus CryptoService.EncryptFile handler that uses unstretched SHA-256 instead of Argon2id. Attackers can perform offline password guessing against encrypted files roughly six to seven orders of magnitude faster …
CWE: CWE-916
NVD

HIGH
CVE-2026-81699
CVE-2026-81699
pkg: openssl

published: Aug 27, 2026

openssl_encrypt versions before 1.4.9 fail to properly validate key derivation function costs in crafted files, allowing attackers to trigger unbounded memory and CPU exhaustion during pre-authentication processing. Attackers can supply malicious files with excessive KDF parameters to exhaust system…
CWE: CWE-770
NVD

HIGH
CVE-2026-81698
CVE-2026-81698
pkg: openssl

published: Aug 27, 2026

openssl_encrypt versions before 1.4.9 contain a shell injection vulnerability in the info command's reconstructed CLI block that interpolates untrusted metadata fields without quoting. Attackers can craft metadata values like pepper_name containing shell commands that execute when users copy the pri…
CWE: CWE-78
NVD

HIGH
CVE-2026-81693
CVE-2026-81693
pkg: openssl

published: Aug 27, 2026

openssl_encrypt before 1.4.9 fails to validate the total field from QR JSON payloads before materializing ranges. Attackers can supply crafted QR images with extremely large total values to trigger unbounded memory allocation and cause denial of service through out-of-memory conditions.
CWE: CWE-789
NVD

HIGH
CVE-2026-81692
CVE-2026-81692
pkg: openssl

published: Aug 27, 2026

openssl_encrypt (pip: openssl-encrypt) versions 1.4.8 and earlier fail to validate the 36-bit STREAMINFO total_samples field of FLAC files before using it to size an allocation (np.random.randint(size=(total_samples, channels))). A ~50-byte crafted FLAC file declaring ~100 million samples causes a m…
CWE: CWE-789
NVD

HIGH
CVE-2026-81691
CVE-2026-81691
pkg: openssl

published: Aug 27, 2026

openssl_encrypt versions before 1.4.9 fail to validate server URLs in login and register_with_email functions, accepting unencrypted http:// URLs and unconfigured hosts. Attackers on the network path can intercept cleartext credentials including client_id, passwords, and JWTs to achieve full keyserv…
CWE: CWE-319
NVD

HIGH
CVE-2026-81689
CVE-2026-81689
pkg: openssl

published: Aug 27, 2026

openssl_encrypt versions before 1.4.9 derive the remote-pepper wrap key using unsalted HKDF-SHA256 or bare SHA-256 of the password, allowing identical keys across all users and files. Attackers with access to wrapped pepper blobs can precompute a single dictionary table and perform fleet-wide offlin…
CWE: CWE-916
NVD

HIGH
CVE-2026-81688
CVE-2026-81688
pkg: openssl

published: Aug 27, 2026

openssl_encrypt versions before 1.4.9 store an unkeyed SHA-256 hash of the plaintext in the cleartext file header metadata. Attackers can read this hash without the password to confirm guessed plaintexts offline or fingerprint identical plaintexts across separately-encrypted files.
CWE: CWE-311
NVD

HIGH
CVE-2026-47889
CVE-2026-47889
pkg: react

published: Aug 27, 2026

A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute.
Spring Framework 7.0.0 – 7.0.8
Spring Framework 6.2.0 – 6.2.19
CWE: CWE-1275
NVD

HIGH
CVE-2026-47886
CVE-2026-47886
pkg: express

published: Aug 27, 2026

Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power operator (^) is used with a BigDecimal or BigInteger operand and a large exponent value.
Spring Framework 7.0.0 – 7.0.8
Spring Framework 6.2.0 -…
CWE: CWE-400
NVD

HIGH
CVE-2026-19715
CVE-2026-19715
pkg: oauth

published: Aug 27, 2026

The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.3.1 does not restrict access to the debug log it writes, which is stored at a fixed and publicly reachable location, allowing unauthenticated users to read the OAuth tokens and authorisation codes it has issued as well as user re…
CWE: CWE-200
NVD

HIGH
CVE-2026-80520
CVE-2026-80520
pkg: linux

published: Aug 26, 2026

In the Linux kernel, the following vulnerability has been resolved:

ovpn: fix NULL dereference when killing missing key

ovpn_crypto_kill_key assumes both crypto slots are populated and
dereferences each slot before checking it. That is not guaranteed: a
peer can have only one installed key, and th…

NVD

HIGH
CVE-2026-74750
CVE-2026-74750
pkg: linux

published: Aug 26, 2026

In the Linux kernel, the following vulnerability has been resolved:

ovpn: defer key slot crypto freeing to workqueue

Key slots are released through a kref and the existing release path
frees the AEAD transforms from an RCU callback. That is not safe for all
crypto implementations: crypto_free_aead…

NVD

HIGH
CVE-2026-74745
CVE-2026-74745
pkg: linux

published: Aug 26, 2026

In the Linux kernel, the following vulnerability has been resolved:

eth: bnxt: avoid deadlock when canceling IRQ affinity notifier

Unregistering IRQ affinity notifiers waits for the callback synchronously.
bnxt takes the netdev instance lock in the notifier (to restart the queue)
and cancels the w…

NVD

HIGH
CVE-2026-74742
CVE-2026-74742
pkg: linux

published: Aug 26, 2026

In the Linux kernel, the following vulnerability has been resolved:

veth: fix queue index used to wake the peer txq in veth_poll

veth_poll() derives the index of the peer TX queue to wake from
rq->xdp_rxq.queue_index. That field is only initialized by
xdp_rxq_info_reg() in veth_enable_xdp_range(),…

NVD

HIGH
CVE-2026-74741
CVE-2026-74741
pkg: linux

published: Aug 26, 2026

In the Linux kernel, the following vulnerability has been resolved:

net: ngbe: fix NULL pointer dereference in non-MSI-X interrupt enabling

In non-MSI-X mode (such as legacy INTx or single MSI), wx->msix_entry is
not allocated or initialized. Calling NGBE_INTR_MISC(wx) dereferences
wx->msix_entry-…

NVD

HIGH
CVE-2026-80205
CVE-2026-80205
pkg: express

published: Aug 26, 2026

NLTK versions before 3.10.0 contain a regular expression denial of service vulnerability in Text.findall() and TokenSearcher.findall() methods that accept user-supplied regular expressions without validation or timeout. Attackers can supply crafted regex patterns that cause catastrophic backtracking…
CWE: CWE-1333
NVD

HIGH
CVE-2026-79139
CVE-2026-79139
pkg: google chrome, microsoft windows

published: Aug 25, 2026

Improper input validation in Media in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-20
NVD

HIGH
CVE-2026-78915
CVE-2026-78915
pkg: google chrome, microsoft windows

published: Aug 25, 2026

Race condition in Enterprise in Google Chrome on on Windows prior to 152.0.7977.65 allowed an adjacent attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Low)
CWE: CWE-362
NVD

HIGH
CVE-2026-78906
CVE-2026-78906
pkg: google chrome

published: Aug 25, 2026

Race condition in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-362
NVD

HIGH
CVE-2026-78901
CVE-2026-78901
pkg: google chrome

published: Aug 25, 2026

Race condition in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-362
NVD

HIGH
CVE-2026-65097
CVE-2026-65097
pkg: linux

published: Aug 25, 2026

NVIDIA NemoClaw for Linux contains a vulnerability in its installation scripts, where an attacker could cause a download of code without integrity check. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
CWE: CWE-494
NVD

HIGH
CVE-2026-55099
CVE-2026-55099
pkg: python

published: Aug 25, 2026

icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python. From 7.1.0 until 7.1.3, the Component equality method in src/icalendar/cal/component.py compares nested subcomponents with two membership loops, and each membership test invokes the same method on child component…
CWE: CWE-400, CWE-407
GitHub-GHSA

HIGH
icalendar has Algorithmic Complexity in Equality
GHSA-cv84-9p8j-fj68
pkg: icalendar
eco: pip
published: Aug 25, 2026
### Summary

`Component.__eq__` compares subcomponents in `O(2^n)` time relative to nesting depth. Because the parser accepts arbitrarily nested components, a sub-kilobyte `.ics` file is enough to make a single equality check run for minutes or hang indefinitely. Any application that compares parsed…

CVE-2026-55099
NVD

HIGH
CVE-2026-55620
CVE-2026-55620
pkg: python

published: Aug 25, 2026

eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information. Prior to 3.0.2, eml_parser.routing.noparenthesis in eml_parser/routing.py removes parenthesized CFWS comments from Received: headers with a regex-based fi…
CWE: CWE-770, CWE-1124
GitHub-GHSA

HIGH
eml_parser vulnerable to DoS via deeply nested parens in Received headers
GHSA-g7gc-gmgp-wgqg
pkg: eml_parser
eco: pip
published: Aug 25, 2026
### Summary

`eml_parser` strips parenthesised CFWS comments from `Received:` headers using a regex-based fix-point loop. The loop has quadratic time complexity in the number of nested parens. A single `Received:` header containing 5,000 nested parens causes ~1.3 seconds of CPU saturation per parsed…

CVE-2026-55620
GitHub-GHSA

HIGH
Trivy has a path traversal via a crafted vulnerability database or other downloaded artifacts
GHSA-mcj4-mphf-j9ff
pkg: github.com/aquasecurity/trivy
eco: go
published: Aug 25, 2026
## Summary

When Trivy downloads an OCI artifact, it uses the `org.opencontainers.image.title` annotation from the artifact manifest as the destination filename without validation. An attacker who can make Trivy fetch an attacker-controlled artifact can supply a crafted annotation that resolves to a…

CVE-2026-55092
NVD

HIGH
CVE-2026-55553
CVE-2026-55553
pkg: node

published: Aug 25, 2026

urllib is an HTTP client for Node.js that supports authentication, redirects, timeouts, and other request features. Prior to 4.9.1 and 2.44.1, urllib follows redirects through followRedirect but reuses caller-supplied options across origins. In src/HttpClient.ts, #requestInternal recursively calls t…
CWE: CWE-200, CWE-201, CWE-522
GitHub-GHSA

HIGH
urllib's cross-origin redirects preserve credential-bearing request headers, leading to potential credential leakage
GHSA-hq3h-g68c-hp78
pkg: urllib, urllib
eco: npm
published: Aug 25, 2026
## Summary

urllib supports redirect-following through `followRedirect`, which is expected behavior for an HTTP client. The issue is that, when following a redirect to a **different origin**, urllib preserves the caller-supplied request headers verbatim, including credential-bearing headers such as …

CVE-2026-55553
NVD

HIGH
CVE-2026-79770
CVE-2026-79770
pkg: express

published: Aug 25, 2026

Nokogiri versions before 1.19.3 contain regular expression denial of service vulnerabilities in the CSS selector tokenizer affecting string-literal and identifier tokenization. Attackers can inject adversarial CSS selectors into methods like Node#css, Node#at_css, and Searchable#search to cause expo…
CWE: CWE-1333
GitHub-GHSA

HIGH
Echo: Encoded slash (%2F) bypasses route-level protection and exposes static files
GHSA-vfp3-v2gw-7wfq
pkg: github.com/labstack/echo/v5, github.com/labstack/echo/v4, github.com/labstack/echo
eco: go
published: Aug 25, 2026
### Summary

Echo's router and static file handler disagree on URL path decoding. The router matches routes using the raw encoded path (preserving `%2F` as-is), while `StaticDirectoryHandler` unescapes `%2F` to `/` before resolving filesystem paths. This allows an attacker to bypass route-level acce…

CVE-2026-55677
GitHub-GHSA

HIGH
praisonaiagents vulnerable to SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap)
GHSA-vg6p-v9vm-6fgj
pkg: praisonaiagents
eco: pip
published: Aug 25, 2026
The web_crawl tool performs its SSRF check only on the initial URL: it resolves the hostname once
with socket.gethostbyname and rejects private/loopback/link-local results. It then passes the URL to
a fetcher that uses httpx.Client(follow_redirects=True) – or urllib.request.urlopen when httpx is
abs…
CVE-2026-55524
GitHub-GHSA

HIGH
praisonaiagents web_crawl vulnerable to SSRF via redirect-following
GHSA-5r34-2g38-6569
pkg: praisonaiagents
eco: pip
published: Aug 25, 2026
### Summary
`web_crawl` (an exported, model-callable tool) validates only the INITIAL URL's resolved IP against a private/loopback blocklist, then fetches with `httpx.Client(follow_redirects=True)` and never re-validates redirect targets.

An attacker who controls the agent's crawl target (a malici…

CVE-2026-55525
NVD

HIGH
CVE-2026-63076
CVE-2026-63076
pkg: openssl

published: Aug 25, 2026

Issue summary: OpenSSL CMP password based protection verification only
checks whether the protectionAlg parameter was not NULL and not its
ASN.1 type, before treating it as a PBMParameter. A crafted message can
contain a parameter of a different type, which is then dereferenced as an
invalid pointer…
CWE: CWE-476
NVD

HIGH
CVE-2026-63075
CVE-2026-63075
pkg: openssl

published: Aug 25, 2026

Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly
sends ack-eliciting packets while not acknowledging ACK-only responses, the
QUIC stack can retain ACK-only packet metadata for the lifetime of the
connection.

Impact summary: A remote peer that can complete a QUIC handsh…

CWE: CWE-770
NVD

HIGH
CVE-2026-63072
CVE-2026-63072
pkg: openssl

published: Aug 25, 2026

Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based
on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive
can write and cleanse more bytes than that query reports, causing an 8-byte
out-of-bounds heap write.

Impact summary: An attacker who supplies a c…

CWE: CWE-787
NVD

HIGH
CVE-2026-54874
CVE-2026-54874
pkg: openssl

published: Aug 25, 2026

Issue summary: Receiving a DTLS record for a future epoch while a handshake
is in progress causes OpenSSL to buffer far more memory than the record
itself requires.

Impact summary: A peer can use a small amount of network traffic to make an
OpenSSL DTLS endpoint retain a disproportionately large am…

CWE: CWE-405
NVD

HIGH
CVE-2026-18798
CVE-2026-18798
pkg: openssl

published: Aug 25, 2026

Issue summary: QUIC server may double free QRX (QUIC record layer RX) object
when channel creation fails for initial packet.

Impact summary: Double free leads to heap corruption, which typically results in
termination of QUIC server process, leading to Denial of Service. There is so
far no evidenc…

CWE: CWE-415
NVD

HIGH
CVE-2026-14457
CVE-2026-14457
pkg: ssl

published: Aug 25, 2026

Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs)
enabled, and only the private key (with no associated certificate) configured locally,
a NULL pointer dereference may occur when the remote peer solicits raw public keys and
also sends the typically omitted "signa…
CWE: CWE-476
NVD

HIGH
CVE-2026-79658
CVE-2026-79658
pkg: go

published: Aug 25, 2026

Ech0 before 5.0.1 does not impose any size or shape limit on the Accept-Language header processed by its i18n middleware, which runs on every HTTP request. The header is passed unfiltered to go-i18n's NewLocalizer, which internally calls golang.org/x/text/language.ParseAcceptLanguage. The CVE-2022-3…
CWE: CWE-400
NVD

HIGH
CVE-2026-66766
CVE-2026-66766
pkg: express

published: Aug 25, 2026

SAP S/4HANA (Private Cloud) uses a third-party component that contains a Regular Expression Denial of Service (ReDoS) vulnerability. An unauthenticated attacker could supply specially crafted input that triggers excessive processing within the affected functionality. Successful exploitation could ex…
CWE: CWE-1333
NVD

HIGH
CVE-2026-76098
CVE-2026-76098
pkg: python

published: Aug 24, 2026

Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates deeply nested emphasis tokens from consecutive asterisk characters, and recursive rendering in HTMLRenderer.render_token() can excee…
CWE: CWE-674
GitHub-GHSA

HIGH
Apache Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never validated, so any unexpired token signed by a trusted key was accepted
GHSA-fpm2-m4qq-wghr
pkg: org.apache.camel:camel-platform-http-main
eco: maven
published: Aug 24, 2026
Improper Authentication vulnerability in Apache Camel Platform HTTP Main component.

This issue affects Apache Camel: from 4.8.0 before 4.22.0.

The camel-main embedded HTTP server can protect its endpoints with JWT authentication, configured through authenticationEnabled together with the JWT keyst…

CVE-2026-66908
GitHub-GHSA

HIGH
Apache Camel-Google-Storage: the consumer appended the remote object name to the configured downloadFileName directory without constraining the result
GHSA-f78g-9385-qxqj
pkg: org.apache.camel:camel-google-storage, org.apache.camel:camel-google-storage, org.apache.camel:camel-google-storage
eco: maven
published: Aug 24, 2026
Relative path traversal vulnerability in Apache Camel Google Storage component.

This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0.

The camel-google-storage consumer downloads Google Cloud Storage objects to the local filesystem when the…

CVE-2026-66907
NVD

HIGH
CVE-2026-66908
CVE-2026-66908
pkg: apache camel

published: Aug 24, 2026

Improper Authentication vulnerability in Apache Camel Platform HTTP Main component.

This issue affects Apache Camel: from 4.8.0 before 4.22.0.

The camel-main embedded HTTP server can protect its endpoints with JWT authentication, configured through authenticationEnabled together with the JWT k…

CWE: CWE-287
NVD

HIGH
CVE-2026-66907
CVE-2026-66907
pkg: apache camel

published: Aug 24, 2026

Relative path traversal vulnerability in Apache Camel Google Storage component.

This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0.

The camel-google-storage consumer downloads Google Cloud Storage objects to the local filesystem when…

CWE: CWE-23
NVD

HIGH
CVE-2026-76848
CVE-2026-76848
pkg: express

published: Aug 24, 2026

TypeORM's SelectQueryBuilder.distinctOn accepts an array of strings and stores it on the expression map without validation. For PostgreSQL-family drivers, createSelectDistinctExpression in src/query-builder/SelectQueryBuilder.ts joins that array and interpolates the result into the generated stateme…
CWE: CWE-89
NVD

HIGH
CVE-2026-76172
CVE-2026-76172
pkg: node

published: Aug 24, 2026

fast-uri is a URI parser for Node.js. During parsing it runs a legacy decoding pass over the scheme component and never re-escapes the result, and serialization writes the scheme back out verbatim, unlike the host component which is re-escaped. As a result an input whose scheme carries percent-encod…
CWE: CWE-177
NVD

HIGH
CVE-2026-75975
CVE-2026-75975
pkg: node

published: Aug 24, 2026

fast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not validate the complete IPv6 grammar, so invalid trailing text in an authority can be silently discarded and a malformed attacker-controlled host is turned into a different valid IPv6 destination. For example,…
CWE: CWE-20, CWE-918
NVD

HIGH
CVE-2026-75931
CVE-2026-75931
pkg: node

published: Aug 24, 2026

fast-uri is a URI parser for Node.js. It canonicalizes a host to its ASCII form only when the input carries an explicit scheme, so a scheme-relative reference such as a host preceded by two slashes is returned with its host verbatim and no error set. As a result fast-uri's own entry points disagree …
CWE: CWE-436
NVD

HIGH
CVE-2026-75899
CVE-2026-75899
pkg: node

published: Aug 24, 2026

fast-uri is a URI parser for Node.js. It decodes percent escapes in a hostname during parsing and then decodes the parsed hostname a second time during authority recomposition, so a single call to normalize or resolve can turn nested percent-encoded input into a different network destination such as…
CWE: CWE-174, CWE-918
NVD

HIGH
CVE-2026-81020
CVE-2026-81020
pkg: tls

published: Aug 28, 2026

wolfEngine before 1.4.1 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record. As a result every TLS 1.2 and DTLS 1.2 AES-GCM record within a connection is encrypted under an identical key and nonce pair. Reusing a GCM key and nonce disclos…
CWE: CWE-323
NVD

HIGH
CVE-2026-81019
CVE-2026-81019
pkg: tls

published: Aug 28, 2026

wolfProvider before 1.2.2 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record. As a result every TLS 1.2 and DTLS 1.2 AES-GCM record within a connection is encrypted under an identical key and nonce pair. Reusing a GCM key and nonce discl…
CWE: CWE-323
NVD

HIGH
CVE-2026-73208
CVE-2026-73208
pkg: oauth

published: Aug 28, 2026

An attacker that holds a token intended for a different purpose can authenticate, because when an OAuth2 token response does not contain a scope claim, the audience claim is used in its place and checked against the configured required scopes. These are different concepts, and the audience claim doe…
CWE: CWE-287
NVD

HIGH
CVE-2026-18717
CVE-2026-18717
pkg: tls

published: Aug 28, 2026

ASE2000 2.35 through 2.37 is vulnerable to an improper certificate validation vulnerability, which may allow an attacker to impersonate the trusted peer, complete the TLS handshake, and read or modify protected communications.
CWE: CWE-295
GitHub-GHSA

HIGH
IzPack has Path Traversal in UnpackerBase that allows writing files outside the installation directory via malicious pack entries
GHSA-f63g-88cj-hjf9
pkg: org.codehaus.izpack:izpack-installer
eco: maven
published: Aug 26, 2026
### Summary

IzPack's `UnpackerBase.unpack()` resolves pack-file target paths without any
canonical-path or directory-containment check. An attacker who distributes a
trojanized installer JAR (the format is unsigned) can include pack entries whose
`targetPath` contains `../` sequences. When a victim…

CVE-2026-54550
NVD

HIGH
CVE-2026-41707
CVE-2026-41707
pkg: jwt

published: Aug 25, 2026

Authentication Bypass by Capture-replay vulnerability in Spring Spring Security allows Spring Security's DPoPProofJwtDecoderFactory contains a cache-based replay attack vulnerability. The internal cache storing JWT ID claims has a strict size limit, allowing attackers to evict legitimate entries by …
CWE: CWE-294
NVD

HIGH
CVE-2026-79664
CVE-2026-79664
pkg: jwt

published: Aug 25, 2026

Ech0 before 4.7.3 fails to properly revoke access tokens created with never-expire option, allowing attackers to maintain perpetual authenticated access after token theft. Three independent revocation mechanisms fail: logout panics on nil ExpiresAt field, RevokeToken skips when remainTTL is zero, an…
CWE: CWE-613
NVD

HIGH
CVE-2026-76844
CVE-2026-76844
pkg: webpack

published: Aug 24, 2026

webpack-dev-middleware resolves a request to a local file in getFilenameFromUrl by testing the request pathname against a traversal guard and then slicing it at a fixed character offset. The guard, UP_PATH_REGEXP applied to path.normalize(`./${pathname}`), only matches ".." that stands as a whole pa…
CWE: CWE-22
NVD

HIGH
CVE-2026-81690
CVE-2026-81690
pkg: openssl

published: Aug 27, 2026

openssl-encrypt (pip package) before 1.4.9 contains a symlink-following flaw in its verify-usb v2 added-file allowlist scan. The scan enumerated the drive with rglob(), which in CPython does not descend into symlinked directories and treats the symlink as an ordinary directory, while O_NOFOLLOW on t…
CWE: CWE-59
GitHub-GHSA

HIGH
PraisonAI: [Auth Bypass] `praisonai serve agents –api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticated
GHSA-r7v3-x45f-g7hp
pkg: PraisonAI
eco: pip
published: Aug 25, 2026
### Summary
`praisonai serve agents` exposes HTTP routes that invoke registered agents. The CLI advertises `–api-key` with help text "API key for authentication", parses it, and forwards it into `ServeHandler`. But `_create_agents_app()` **never reads `config["api_key"]` again** and installs no aut…
CVE-2026-55538
NVD

HIGH
CVE-2026-78637
CVE-2026-78637
pkg: node

published: Aug 25, 2026

A vulnerability was detected in Fdawgs node-poppler up to 9.1.2/10.0.1. The impacted element is the function pdfInfo/pdfToText/pdfToCairo/pdfToPpm/pdfImages/pdfToHtml/pdfToPs/pdfFonts/pdfDetach/pdfAttach/pdfSeparate/pdfUnite of the file src/index.js of the component Argument Injection Handler. Perfo…
CWE: CWE-74, CWE-88
NVD

HIGH
CVE-2026-45019
CVE-2026-45019
pkg: python

published: Aug 25, 2026

Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose the POST /mcp endpoint without requiring authentication. For sse and streamable-http tra…
CWE: CWE-918
GitHub-GHSA

HIGH
Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access
GHSA-hvfh-5mj3-5f3j
pkg: chainlit
eco: pip
published: Aug 25, 2026
### Am I affected?

Only if your deployment sets `features.mcp.enabled = true` in `.chainlit/config.toml`. **MCP has been disabled by default since v2.7.0**, so most Chainlit deployments are not affected. No authentication is required: `/mcp` is reachable by any client that can open a session.

### …

CVE-2026-45019
GitHub-GHSA

HIGH
3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation
GHSA-jm48-m3rr-9hgg
pkg: github.com/mhsanaei/3x-ui/v3, github.com/mhsanaei/3x-ui/v2
eco: go
published: Aug 24, 2026
# Summary

An authenticated administrator can abuse the database import functionality to achieve arbitrary file write on the host by modifying Xray configuration values stored in the database. This can be leveraged to obtain code execution and persistent access as the user running Xray (including ro…

CVE-2026-55477
NVD

HIGH
CVE-2026-71364
CVE-2026-71364
pkg: node

published: Aug 24, 2026

A path traversal vulnerability was found in AWX's project archive extraction. The project_archive action plugin extracts zip and tar archive members by joining the project directory path with the member filename without performing path normalization, boundary validation, or rejecting directory trave…
CWE: CWE-22
GitHub-GHSA

HIGH
Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id
GHSA-5pg6-m483-7vrg
pkg: code.vikunja.io/api
eco: go
published: Aug 28, 2026
## Summary

The kanban endpoint `POST /api/v1/projects/{project}/views/{view}/buckets/{bucket}/tasks`
moves a task into a bucket. The task is identified by `task_id` in the **request
body**. The endpoint's authorization check (`TaskBucket.CanUpdate`) only verifies
that the caller may update the *pro…

CVE-2026-55066
NVD

HIGH
CVE-2026-54085
CVE-2026-54085
pkg: windows

published: Aug 28, 2026

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.2.0 through 4.14.6, multiple active response scripts pass attacker-influenced alert fields to privileged system commands without validating their format, allowing argu…
CWE: CWE-88
NVD

HIGH
CVE-2026-80426
CVE-2026-80426
pkg: react

published: Aug 26, 2026

FiftyOne renders a dataset field's description as markup. The sidebar field-information component at app/packages/core/src/components/FieldLabelAndInfo/index.tsx passes the description string to React's dangerouslySetInnerHTML, and no layer between storage and render escapes or sanitises it; the nei…
CWE: CWE-79
GitHub-GHSA

HIGH
Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root
GHSA-w5fv-7x5q-g8qp
pkg: github.com/cloudreve/Cloudreve/v4, github.com/cloudreve/Cloudreve/v3
eco: go
published: Aug 26, 2026
## Summary

A Cloudreve WebDAV account stores a `uri` that defines the account's root folder. The WebDAV request handler (`stripPrefix` in `pkg/webdav/webdav.go`) trims the `/dav` prefix from the request path and joins the remainder to that root with `fs.URI.JoinRaw`, but never checks that the joine…

CVE-2026-54563
GitHub-GHSA

HIGH
Budibase authenticated arbitrary S3 signed upload URL issuance via `/api/attachments/:datasourceId/url`
GHSA-6x9p-4r67-5gjx
pkg: @budibase/server
eco: npm
published: Aug 26, 2026
### Summary
Budibase 3.39.7 allows a low-privilege authenticated published-app user with the built-in BASIC role to obtain arbitrary S3 pre-signed upload URLs backed by a workspace datasource's stored server-side credentials.

The affected endpoint is:

`POST /api/attachments/:datasourceId/url`

The…

CVE-2026-54356
NVD

HIGH
CVE-2026-78892
CVE-2026-78892
pkg: windows

published: Aug 25, 2026

Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a local attacker to bypass system access restrictions via a local program. (Chromium security severity: Medium)
CWE: CWE-863
NVD

HIGH
CVE-2026-79786
CVE-2026-79786
pkg: oauth

published: Aug 25, 2026

Coroot's unauthenticated MCP OAuth dynamic client registration endpoint accepts any syntactically valid redirect URI without validation, allowing attackers to register clients pointing to attacker-controlled hosts. Attackers can send authorization URLs to signed-in users, capture their authorization…
CWE: CWE-601
GitHub-GHSA

HIGH
consciousness-explorer / sublinear-time-solver MCP export_state has an arbitrary file write
GHSA-xc9g-j69q-37xw
pkg: consciousness-explorer, sublinear-time-solver
eco: npm
published: Aug 25, 2026
### Impact
An arbitrary file write vulnerability (CWE-73, External Control of File Name or Path) exists in the `consciousness-explorer` component of `sublinear-time-solver`. The MCP `export_state` (and `import_state`) tool accepted a user-supplied `filepath` argument and passed it directly to `fs.wr…
CVE-2026-55609
GitHub-GHSA

HIGH
utcp-http has an OAuth2 `tokenUrl` Trust Boundary Bypass in OpenAPI Conversion
GHSA-8cp3-qxj6-px34
pkg: utcp-http
eco: pip
published: Aug 25, 2026
### Summary

The `utcp-http` library (<= 1.1.3) unconditionally trusts the `tokenUrl` field embedded in remote OpenAPI security schemes. When a victim registers an attacker-controlled OpenAPI spec and invokes any generated OAuth2-protected tool, the library POSTs the victim's `client_id` and `client…

GitHub-GHSA

HIGH
praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location
GHSA-gxmw-5f7x-6g22
pkg: praisonaiagents
eco: pip
published: Aug 25, 2026
### Summary

`praisonaiagents/memory/file_memory.py::FileMemory.__init__()` constructs all
memory file paths by directly joining the `user_id` parameter to a base path:

“`python
self.user_path = self.base_path / user_id # LINE 145 — no sanitization
“`

No validation or normalization is app…

CVE-2026-55527
GitHub-GHSA

HIGH
PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114
GHSA-rg5q-pp8p-f7jm
pkg: PraisonAI
eco: pip
published: Aug 25, 2026
### Summary

`praisonai/jobs/models.py::JobSubmitRequest.validate_webhook_url()` validates webhook
URLs by resolving the hostname and checking whether the IP is private. When DNS
resolution fails (`socket.gaierror`), the validator **silently passes** the URL via
`except socket.gaierror: pass`. Addit…

CVE-2026-55537
GitHub-GHSA

HIGH
PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks
GHSA-ch89-h4r2-c8f8
pkg: PraisonAI
eco: pip
published: Aug 25, 2026
### Summary
PraisonAI's `praisonai.code` tool wrappers (exported as `CODE_TOOLS` for agents) expose a `workspace` setting that the module itself treats as a path-traversal **security boundary** — `read_file`, `write_file`, `apply_diff`, and `search_replace` explicitly call `is_path_within_director…
CVE-2026-55540
GitHub-GHSA

HIGH
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
GHSA-8jj7-4v57-frf5
pkg: django-cms
eco: pip
published: Aug 24, 2026
### Summary
The `move_plugin` admin endpoint does not prevent a plugin from being reparented under itself or one of its own descendants. Doing so creates a cycle in the plugin tree, after which the recursive descendant/ancestor SQL queries loop without terminating, stalling the request worker.

CVE-2026-54623
NVD

HIGH
CVE-2026-81714
CVE-2026-81714
pkg: openssl

published: Aug 27, 2026

openssl_encrypt (pip: openssl-encrypt) versions <= 1.4.8 use suffix-tolerant fingerprint matching in enroll_trust_key when binding a plugin-signing trust anchor. An operator who confirms a short (forgeable, ~32-bit) GPG key id could unknowingly enroll an attacker's colliding key as a trusted anchor,…
CWE: CWE-347
NVD

HIGH
CVE-2026-65082
CVE-2026-65082
pkg: linux

published: Aug 25, 2026

NVIDIA NemoClaw for Linux contains a vulnerability in its migration command, where a local attacker could cause code injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.
CWE: CWE-94
NVD

HIGH
CVE-2026-66153
CVE-2026-66153
pkg: linux

published: Aug 25, 2026

The NEService auto-upgrade process insecurely handles temporary files in SonicWall NetExtender Linux client which allows an attacker to manipulate file paths.
CWE: CWE-59
NVD

HIGH
CVE-2026-75037
CVE-2026-75037
pkg: linux

published: Aug 25, 2026

Polkit Authentication Based on UnixProcessSubject / Peer PID in LACT on Linux allows an Authentication Bypass. This issue affects LACT through 0.10.0. Fixed by commit d0478fe42c2219454e272f96b1cbd29ab37ee566.
CWE: CWE-290
NVD

HIGH
CVE-2026-78367
CVE-2026-78367
pkg: express

published: Aug 24, 2026

A vulnerability was found in RPM's rpmbuild tarball processing. When processing a crafted source archive, the getTarSpec() function in tools/rpmbuild.cc passes an attacker-controlled tar archive member name to rpmExpand() as part of a %{basename:…} macro expression. A specially crafted .spec membe…
CWE: CWE-94
GitHub-GHSA

HIGH
Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances
GHSA-x626-fcwx-f5pc
pkg: github.com/portainer/portainer, github.com/portainer/portainer
eco: go
published: Aug 28, 2026
## Summary
Portainer supports restoring an instance from a backup archive via the /api/restore endpoint. This endpoint is intentionally unauthenticated to allow restoring before the first admin account is created, and remains accessible for the five-minute initialization window that opens each time …
CVE-2026-55761
GitHub-GHSA

HIGH
klever-go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupply
GHSA-mrpp-v6pg-p54x
pkg: github.com/klever-io/klever-go
eco: go
published: Aug 28, 2026
## Summary
On the SFT add-quantity path the only supply bound is `SFTAddCirculation`, which does
`meta.Circulation += amount` with **no overflow guard**, then checks
`if meta.Circulation > meta.MaxSupply && meta.MaxSupply != 0`. If `amount` overflows `int64` and wraps
**negative**, `negative > MaxSu…
CVE-2026-55764
GitHub-GHSA

HIGH
klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits
GHSA-v358-wf77-39xv
pkg: github.com/klever-io/klever-go
eco: go
published: Aug 28, 2026
## Summary
In `processPercentageRoyaltiesTransfer` the royalty pool is collected from the sender by `SubFromBalance` that is
ordered **after** the split loop and after `if royaltiesToPay <= 0 { return Ok }`. The split-payout guard rejects
only an allocation that *exceeds* the pool (a strict `splitTo…
CVE-2026-55763
GitHub-GHSA

HIGH
Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching
GHSA-wjmf-p669-5m5p
pkg: Protego
eco: pip
published: Aug 28, 2026
### Problem description

Protego constructs regular expressions to match URLs against `robots.txt` `Allow:` and `Disallow:` directives, see `protego._urlpattern._URLPattern._prepare_pattern_for_regex()`. Every `*` in the directive value is translated into a lazy `.*?` regex piece, thus a specially c…

CVE-2026-55520
GitHub-GHSA

HIGH
PowSyBl Core has Command Injection in LocalCommandExecutor-s
GHSA-jqvf-j3ww-r8c7
pkg: com.powsybl:powsybl-computation-local
eco: maven
published: Aug 28, 2026
### Impact

#### Description
Both `AbstractLocalCommandExecutor` OS-dependent implementations are subject to **CWE-78** (OS Command Injection), with a secondary **CWE-88** (Argument Injection) concern via environment variables.

The local command executor build command strings via concatenation and …

CVE-2026-55673
GitHub-GHSA

HIGH
Bifrost's SSRF deny-list is incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL
GHSA-w98g-5w9p-p3rc
pkg: github.com/maximhq/bifrost/core
eco: go
published: Aug 28, 2026
## Summary

`isPublicIP` in `core/providers/utils/fetch.go` — the SSRF deny-list that gates `FetchAndEncodeURL` — does not reject several routable address ranges that map onto internal infrastructure. Carrier-Grade NAT (`100.64.0.0/10`, RFC 6598), IPv6 6to4 (`2002::/16`), NAT64 (`64:ff9b::/96` a…

CVE-2026-55245
GitHub-GHSA

HIGH
WsgiDAV MySQL provider has a blind SQL injection
GHSA-p6gw-4frg-j7jw
pkg: WsgiDAV
eco: pip
published: Aug 28, 2026
### Summary

The sample `MySQLBrowserProvider` builds its SQL queries by concatenating strings, and the record key from the request URL goes straight into the WHERE clause with no escaping. Any user who can reach a share backed by this provider can inject SQL through the URL. Since these read shares…

CVE-2026-55509
GitHub-GHSA

HIGH
Crossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature check
GHSA-mf7q-r4rv-jv94
pkg: github.com/crossplane/crossplane-runtime/v2, github.com/crossplane/crossplane-runtime/v2
eco: go
published: Aug 27, 2026
## Summary

Crossplane allows package signature verification to be configured via the `ImageConfig` mechanism. When enabled, the package manager uses cosign to verify that packages are correctly signed before pulling and installing them.

When a package is installed using a tag reference (e.g., a se…

GitHub-GHSA

HIGH
SunEditor Embed Plugin has DOM XSS via External Script Element After Iframe Embed
GHSA-w93q-cq9w-58p7
pkg: suneditor
eco: npm
published: Aug 26, 2026
Summary

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the SunEditor Embed plugin. Crafted iframe embed HTML followed by an external <script src=…> element bypasses the plugin’s sanitization logic. The plugin recreates and appends the attacker-controlled script element to the li…

CVE-2026-54606
GitHub-GHSA

HIGH
http4s has HTTP/2 Denial of Service with Ember Backend
GHSA-vmm3-xgcx-67hm
pkg: org.http4s:http4s-ember-core_2.12, org.http4s:http4s-ember-core_2.13, org.http4s:http4s-ember-core_3
eco: maven
published: Aug 26, 2026
### Summary

http4s 0.23.x and 1.0 servers running ember with http2 enabled are vulnerable to a denial of service attack using a HPACK bomb vulnerability recently disclosed as affecting other http2 servers.

### Impact

Denial of Service:
– Affects any http4s server running the ember backend with HT…

CVE-2026-54556
GitHub-GHSA

HIGH
Whistle vulnerable to path traversal
GHSA-3vfr-4gwf-qxfp
pkg: whistle
eco: npm
published: Aug 25, 2026
This bug was found by nova, which is an automated tool from group of Song Wu, intern, Zhejiang University; BoWang, independent researcher; Xingwei Lin, Zhejiang University.

**Vulnerability detail**:

In service.js, inside
`app.get('/cgi-bin/temp/get', …):
var filename = req.query.filename;
if (T…

CVE-2026-55629
GitHub-GHSA

HIGH
genieacs-mcp: DNS rebinding reaches local GenieACS MCP Streamable HTTP transport
GHSA-cmwv-wf9p-p8wx
pkg: github.com/geiserx/genieacs-mcp
eco: go
published: Aug 25, 2026
`genieacs-mcp` exposes a local Streamable HTTP MCP endpoint that accepts attacker-controlled `Host` and `Origin` headers. A malicious web page can use DNS rebinding to route browser requests to a victim's loopback MCP listener while preserving the attacker origin. The server accepts the request, ini…
CVE-2026-55637
GitHub-GHSA

HIGH
mcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment
GHSA-vwf3-4xxj-qg6h
pkg: mcp-contextforge-gateway
eco: pip
published: Aug 25, 2026
### Summary

`mcpgateway.services.prompt_service.PromptService` renders user-supplied prompt templates using Jinja2's plain `Environment()` rather than `SandboxedEnvironment`. An authenticated user with permission to register or update prompt templates can store a malicious template that, on subsequ…

GitHub-GHSA

HIGH
browse-mcp has an arbitrary file write via unconfined download and state paths
GHSA-m9mq-7m7q-xc6p
pkg: browse-mcp
eco: npm
published: Aug 25, 2026
### Impact
`browser_download` wrote a fetched file to `join(save_dir, filename)` with no validation of `save_dir`, and `browser_save_state` / `browser_load_state` honored an explicit `path` unchanged. The MCP caller controls these arguments (a malicious MCP client, or an autonomous agent steered by …
CVE-2026-55557
GitHub-GHSA

HIGH
pickem vulnerable to terminal escape-sequence injection via unsanitized item text
GHSA-8qx3-8gm5-9cj2
pkg: pickem
eco: npm
published: Aug 25, 2026
### Impact
pickem rendered item text (label, description, group, meta, name) to the terminal with no control-character sanitization. `chrome.row` only stripped ANSI from the **active** row; inactive rows, the public `createFormatter`, and selection-summary lines printed labels **raw**, and the ANSI …
GitHub-GHSA

HIGH
mcp-shell — Security Disabled by Default in Bare-Binary Deploy Path + Shell Interpreter in Secure-Mode Allowlist
GHSA-f5pj-2738-996m
pkg: github.com/sonirico/mcp-shell
eco: go
published: Aug 25, 2026
mcp-shell` at commit `17ac0eef5c9a5a42b8fb132d3d034973d55a5433` has two issues that together mean neither the default deploy path nor the recommended "secure mode" delivers the restriction they're marketed as providing. Filing these together because the two failure modes bracket the full intended au…
CVE-2026-55580
GitHub-GHSA

HIGH
PraisonAI: `–api-key` flag on `praisonai serve` is not properly enforced
GHSA-pvxx-r596-f5qj
pkg: PraisonAI
eco: pip
published: Aug 25, 2026
## Summary

`praisonai serve agents` and `praisonai serve unified` both accept `–api-key` for authentication. The flag is parsed but never wired into the FastAPI app — no middleware, no header check, nothing. The server runs wide open regardless of what key you set. Tested on 4.6.50 from PyPI.

#…

CVE-2026-55541
GitHub-GHSA

HIGH
praisonaiagents has a `web_crawl` SSRF protection bypass via unchecked redirect targets
GHSA-8hjw-25cg-g52h
pkg: praisonaiagents
eco: pip
published: Aug 25, 2026
## Summary

`praisonaiagents.tools.web_crawl_tools.web_crawl()` validates the initial URL and blocks direct loopback/private destinations by default, but the default httpx fallback still uses `httpx.Client(follow_redirects=True)` and does not revalidate redirect targets.

An attacker-controlled publ…

CVE-2026-55523
GitHub-GHSA

HIGH
postgres-protocol: Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service
GHSA-5×78-73v4-xg6w
pkg: postgres-protocol
eco: rust
published: Aug 24, 2026
A malicious, compromised, or man-in-the-middle server can supply an arbitrarily
large SCRAM-SHA-256 PBKDF2 iteration count during authentication. The client
runs it inline with no upper bound, pinning a `tokio` worker thread for minutes
per connection, possibly stalling the whole async runtime.

App…

GitHub-GHSA

MEDIUM
PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on local MCP server
GHSA-wj6g-v78p-6fx3
pkg: PraisonAI
eco: pip
published: Aug 25, 2026
### Summary

PraisonAI's MCP HTTP Stream transport uses an unsafe prefix match when validating the `Origin` header. The default localhost allowlist includes origins such as `http://localhost`, and the validation accepts any origin that starts with an allowed value.

As a result, an attacker-controll…

CVE-2026-55529
NVD

MEDIUM
CVE-2026-82255
CVE-2026-82255
pkg: curl

published: Aug 28, 2026

gitoxide versions from 0.25.4 contain an HTTP credential leak vulnerability in the curl-based transport backend where credentials are sent to attacker-controlled servers after HTTP redirects. The vulnerability occurs because credential validation checks the original URL instead of the effective URL …
CWE: CWE-522
NVD

MEDIUM
CVE-2026-81706
CVE-2026-81706
pkg: openssl

published: Aug 27, 2026

openssl_encrypt before 1.4.9 fails to prevent namespace collisions between own identities and contacts in IdentityStore, allowing attackers to create shadowed contact entries invisible until the corresponding own identity is deleted. When the own identity is deleted, the shadowed contact becomes vis…
CWE: CWE-345
NVD

MEDIUM
CVE-2026-59272
CVE-2026-59272
pkg: tls

published: Aug 27, 2026

Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of every log event.
Spring AMQP 4.1.0
Spring AMQP 4.0.0 – 4.0.4
Spring AMQP 3.2.0 – 3.2.12
Spring AMQP 2.4.18 and earlier
CWE: CWE-297
NVD

MEDIUM
CVE-2026-65086
CVE-2026-65086
pkg: linux

published: Aug 25, 2026

NVIDIA OpenShell for Linux contains a vulnerability in its sandbox exec handler, where an attacker could cause an OS command injection. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering.
CWE: CWE-78
GitHub-GHSA

MEDIUM
PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation
GHSA-hmfx-4v44-9qw9
pkg: PraisonAI
eco: pip
published: Aug 25, 2026
### Summary
The `webhook_url` field in the Jobs API silently passes validation when DNS resolution fails (`socket.gaierror`), enabling DNS rebinding attacks. An attacker's domain can initially resolve to a public IP (passing validation) then switch to an internal IP before the server makes the HTTP …
CVE-2026-55535
GitHub-GHSA

MEDIUM
Aqua's archive extraction follows attacker-planted symlinks, allowing writes outside the install directory
GHSA-mf5c-hw34-4hpp
pkg: github.com/aquaproj/aqua/v2
eco: go
published: Aug 28, 2026
### Summary

`aquaproj/aqua` extracts downloaded tool archives through `pkg/unarchive/archives.go` using `github.com/mholt/archives`. The archive handler creates symlink entries with `os.Symlink(f.LinkTarget, dstPath)` without validating that the symlink target resolves inside the extraction destina…

CVE-2026-55569
NVD

MEDIUM
CVE-2026-82662
CVE-2026-82662
pkg: tls

published: Aug 31, 2026

Nodemailer before 8.0.8 disables TLS certificate verification in lib/fetch/index.js through rejectUnauthorized: false, allowing attackers to intercept OAuth2 token requests. Attackers in a machine-in-the-middle position can capture OAuth client secrets, refresh tokens, and access tokens transmitted …
CWE: CWE-295
GitHub-GHSA

MEDIUM
MariaDB has possible SQL injection in Buffer parameter escaping under big5/gbk/sjis/cp932/gb18030 client charsets
GHSA-g5xc-5w98-jfvm
pkg: mariadb, mariadb, mariadb
eco: npm
published: Aug 28, 2026
### Summary

A SQL injection is possible when the connector escapes Buffer parameters client-side under a multi-byte client character set whose trail-byte range overlaps the ASCII backslash (0x5C): big5, gbk, sjis, cp932, and gb18030. Under these charsets, an attacker-controlled lead byte can absorb…

CVE-2026-55855
NVD

MEDIUM
CVE-2026-77939
CVE-2026-77939
pkg: express

published: Aug 28, 2026

Flextype CMS through v1.0.0-dev contains an expression language injection vulnerability that allows authenticated attackers with a valid API token to read arbitrary files by passing unsanitized user-supplied input to the Symfony ExpressionLanguage engine via the POST /api/v1/query endpoint. Attacker…
CWE: CWE-94, CWE-1336
GitHub-GHSA

MEDIUM
Yamcs has Reflected XSS in the URL of the Authorize Endpoint
GHSA-rxpg-wjf8-qv9c
pkg: org.yamcs:yamcs-core
eco: maven
published: Aug 28, 2026
### Attack type: 
Unauthenticated remote 

### Impact:
Attackers can execute arbitrary JavaScript in a user's browser, including obtaining a user's session token and refresh token.

### Affected components: authorize.html, AuthHandler.java, HandlerContext.java

A Reflected Cross-Site Scripting…

CVE-2026-55549
GitHub-GHSA

MEDIUM
Yamcs's WebSocket subscription handlers omit the privilege checks their REST siblings enforce
GHSA-fwww-cp23-7f5g
pkg: org.yamcs:yamcs-core, org.yamcs:yamcs-core
eco: maven
published: Aug 28, 2026
**Asset / scope:** Yamcs 5.12.7 WebSocket topics (`packets`, `algorithm-status`, `mdb-changes`)

## Summary

Several WebSocket subscription handlers do not perform the privilege check that their REST counterparts
enforce, so a principal subscribing over WebSocket receives data the REST API would hav…

CVE-2026-55545
NVD

MEDIUM
CVE-2026-81341
CVE-2026-81341
pkg: tls

published: Aug 28, 2026

wolfEngine before 1.4.1 sources the explicit AES-CCM nonce for TLS 1.2 and DTLS 1.2 records from the record input buffer instead of the TLS sequence number carried in the additional authenticated data. Because the record layer leaves the explicit-nonce field for the cipher to populate, the value rea…
CWE: CWE-323
GitHub-GHSA

MEDIUM
gix-packetline: reachable panic on empty side-band packet (pre-auth network DoS)
GHSA-2vh6-hw4j-32ww
pkg: gix-packetline
eco: rust
published: Aug 28, 2026
### Summary
`gix-packetline` panics when it receives a side-band packet line that contains only the band-id byte with an empty payload. A malicious Git server – or any remote a victim clones/fetches from – can abort the `gix` client process during a normal fetch. This is a pre-authentication, networ…
NVD

MEDIUM
CVE-2026-61802
CVE-2026-61802
pkg: node

published: Aug 28, 2026

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.14.0 through 4.14.6, a low-privilege API user can read the cleartext cluster key from a configuration endpoint that fails to redact it. The REST API provides a masking…
CWE: CWE-200, CWE-522
NVD

MEDIUM
CVE-2026-81527
CVE-2026-81527
pkg: express

published: Aug 27, 2026

A NoSQL/expression injection weakness exists in the LINQ-to-aggregation query translation layer of the MongoDB C# Driver, in both aggregation expression and query filter translation. When application-supplied values are embedded in certain query constructs, special elements contained within those va…
CWE: CWE-943
NVD

MEDIUM
CVE-2026-54732
CVE-2026-54732
pkg: node

published: Aug 27, 2026

libreoffice-convert is a Node.js module for converting office documents to different formats. Prior to 1.8.2, index.js uses the caller-controlled options.fileName value in path.join(tempDir.name, fileName) without reducing it to a base name. A filename containing ../ can escape the temporary directo…
CWE: CWE-22
GitHub-GHSA

MEDIUM
libreoffice-convert vulnerable to path traversal / arbitrary file write
GHSA-gmxc-r82q-347r
pkg: libreoffice-convert
eco: npm
published: Aug 27, 2026
### Impact
options.fileName is used to build a filesystem path
(path.join(tempDir.name, fileName)) and the caller-supplied document buffer is
written there, but fileName is never reduced to a base name. A fileName containing
"../" escapes the temporary directory, so a caller can write arbitrary cont…
CVE-2026-54732
NVD

MEDIUM
CVE-2026-62326
CVE-2026-62326
pkg: express

published: Aug 26, 2026

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a user with the built-in "Edit source" role can store a malicious regular expression in a source string's flags that is executed without any timeout, allowing them to stall requ…
CWE: CWE-400
NVD

MEDIUM
CVE-2026-46371
CVE-2026-46371
pkg: node

published: Aug 26, 2026

Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the Apple MDM commands listing endpoint (GET /api/v1/fleet/mdm/apple/commands) allowed an authenticated user with the lowest-privilege Observer role to extract sensitive values from joined da…
CWE: CWE-89, CWE-200
NVD

MEDIUM
CVE-2026-46370
CVE-2026-46370
pkg: node

published: Aug 26, 2026

Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the labels host-listing endpoint (GET /api/v1/fleet/labels/{id}/hosts) allowed an authenticated user with the lowest-privilege Observer role to extract host enrollment secrets through a sort-…
CWE: CWE-89, CWE-200
NVD

MEDIUM
CVE-2026-81034
CVE-2026-81034
pkg: tls

published: Aug 26, 2026

Netmaker disables certificate verification on the connection to the configured mail server. The sender in pro/email/smtp.go assigns a TLS configuration whose skip-verify field is set to true unconditionally, directly beneath a comment stating that the setting should be false in production. No config…
CWE: CWE-295
NVD

MEDIUM
CVE-2026-79285
CVE-2026-79285
pkg: windows

published: Aug 25, 2026

Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-908
NVD

MEDIUM
CVE-2026-79253
CVE-2026-79253
pkg: google chrome, microsoft windows

published: Aug 25, 2026

Improper input validation in Network in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)
CWE: CWE-20
NVD

MEDIUM
CVE-2026-79243
CVE-2026-79243
pkg: google chrome, microsoft windows

published: Aug 25, 2026

Improper input validation in ReadingList in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
CWE: CWE-20
NVD

MEDIUM
CVE-2026-79177
CVE-2026-79177
pkg: google chrome, microsoft windows

published: Aug 25, 2026

Incorrect authorization in Media in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
CWE: CWE-863
NVD

MEDIUM
CVE-2026-79123
CVE-2026-79123
pkg: google chrome, microsoft windows

published: Aug 25, 2026

Improper input validation in NTP Footer in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
CWE: CWE-20
NVD

MEDIUM
CVE-2026-78947
CVE-2026-78947
pkg: google chrome

published: Aug 25, 2026

Incomplete cleanup in Chromium in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Low)
CWE: CWE-459
NVD

MEDIUM
CVE-2026-78914
CVE-2026-78914
pkg: google chrome

published: Aug 25, 2026

Uninitialized resource in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
CWE: CWE-908
NVD

MEDIUM
CVE-2026-78907
CVE-2026-78907
pkg: google chrome

published: Aug 25, 2026

Incorrect authorization in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-863
NVD

MEDIUM
CVE-2026-78897
CVE-2026-78897
pkg: google chrome

published: Aug 25, 2026

Missing authorization in BrowserTag in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted Chrome extension. (Chromium security severity: Low)
CWE: CWE-862
NVD

MEDIUM
CVE-2026-78893
CVE-2026-78893
pkg: google chrome

published: Aug 25, 2026

Information leak in QUIC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-200
NVD

MEDIUM
CVE-2026-55618
CVE-2026-55618
pkg: python

published: Aug 25, 2026

eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information. Prior to 3.0.2, the clean_found_uri function in eml_parser/parser.py validates potential URL strings before unescaping HTML entities used for colon, slash…
CWE: CWE-116
GitHub-GHSA

MEDIUM
eml_parser has a URL extraction bypass via HTML entities in URLs
GHSA-fxgq-9m89-cxj9
pkg: eml_parser
eco: pip
published: Aug 25, 2026
## Summary

`eml_parser` performs certain validations on potential URL strings to discard bogus values. In versions prior to `3.0.2`, this validation was performed before unescaping any HTML entities that might occur in the string. This caused the library to wrongfully reject valid URLs that use HTM…

CVE-2026-55618
GitHub-GHSA

MEDIUM
PraisonAI MCP HTTP server has unauthenticated unbounded session accumulation (memory exhaustion; session TTL never enforced)
GHSA-wv94-5qcp-6m36
pkg: PraisonAI
eco: pip
published: Aug 25, 2026
### Summary

The PraisonAI MCP HTTP-stream server creates a new in-memory session on every initialize request and never removes it. The cleanup routine that would expire sessions (_cleanup_sessions) is defined but never called anywhere in the codebase, and the configured session TTL is never enforce…

CVE-2026-55531
NVD

MEDIUM
CVE-2026-75509
CVE-2026-75509
pkg: jwt

published: Aug 24, 2026

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. Prior to version 1.7.3, JWTClaimsRegistry applies membership matching to list-valued iss and sub claims, allowing an array-valued iss that contains the expected issuer to pass …
CWE: CWE-290, CWE-345
GitHub-GHSA

MEDIUM
Sakai Profile Image Deletion has an IDOR
GHSA-9284-fjc3-fmmj
pkg: org.sakaiproject.profile2:profile2-api, org.sakaiproject.profile2:profile2-api, org.sakaiproject.profile2:profile2-impl
eco: maven
published: Aug 24, 2026
### Summary

The Sakai REST API endpoint `DELETE /api/users/{userId}/profile/image` does not verify that the requesting user is authorized to modify the target user's profile. Any authenticated user can delete the profile image of any other user, including administrators, by supplying a different `u…

CVE-2026-54050
GitHub-GHSA

MEDIUM
Apache Camel-Mail: the MimeMultipart data format copied MIME headers onto the Camel message without a header filter strategy when unmarshalling with headersInline enabled
GHSA-cx47-qxp5-mmh2
pkg: org.apache.camel:camel-mail, org.apache.camel:camel-mail, org.apache.camel:camel-mail
eco: maven
published: Aug 24, 2026
Improper input validation vulnerability in Apache Camel.

This issue affects Apache Camel: from 2.17.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0.

The camel-mail component ships a MimeMultipart data format that can unmarshal a MIME multipart message. When it is configured w…

CVE-2026-59230
NVD

MEDIUM
CVE-2026-78323
CVE-2026-78323
pkg: tls

published: Aug 24, 2026

A flaw was found in JSS (Java Security Services). The JSSTrustManager class does not verify NSS trust flags when validating CA certificates, allowing certificates present in the NSS database without TRUSTED_CA flags to be accepted as trust anchors for TLS connections. In non-default configurations w…
CWE: CWE-295
GitHub-GHSA

MEDIUM
Hatchet allows cross-tenant write/DoS to other tenants' workers via Dispatcher gRPC UpsertWorkerLabels and Unsubscribe
GHSA-8x7x-83cf-c3pg
pkg: github.com/hatchet-dev/hatchet
eco: go
published: Aug 28, 2026
### Summary

A **cross-tenant write / DoS** vulnerability in the Hatchet `Dispatcher` gRPC service allows any holder of a normal tenant-scoped API token (the lowest credential Hatchet issues — an `OWNER` of a brand-new tenant) to overwrite the affinity labels of, or disconnect from the dispatcher,…

CVE-2026-54746
NVD

MEDIUM
CVE-2026-3129
CVE-2026-3129
pkg: express

published: Aug 28, 2026

The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted `<img>` tag attributes in all versions up to, and including, 7.7. This is due to a flawed regular expression that is used to strip `width` and `height` attributes from images when the "Lazy Load Images"…
CWE: CWE-79
NVD

MEDIUM
CVE-2026-18100
CVE-2026-18100
pkg: express

published: Aug 25, 2026

The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'mf_form_id' Widget Setting in all versions up to, and including, 4.1.8 due to insufficient input sanitization and output escaping. This makes it poss…
CWE: CWE-79
NVD

MEDIUM
CVE-2026-81720
CVE-2026-81720
pkg: openssl

published: Aug 27, 2026

openssl_encrypt before 1.4.9 fails to validate the memory_cost parameter from identity file protection blocks, allowing attackers to trigger out-of-memory conditions during key derivation. Attackers with write access to local identity stores can craft malicious identity files with excessive memory_c…
CWE: CWE-400
NVD

MEDIUM
CVE-2026-81686
CVE-2026-81686
pkg: openssl

published: Aug 27, 2026

openssl_encrypt 1.4.x before 1.4.9 contains an optional D-Bus crypto service whose org.freedesktop.DBus.Properties.Set method performs neither a polkit authorization check nor value validation. Any local user on the system bus can call Set without authorization and set MaxConcurrentOperations (to 0/…
CWE: CWE-20
NVD

MEDIUM
CVE-2026-81684
CVE-2026-81684
pkg: openssl

published: Aug 27, 2026

In openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8, the desktop GUI passes the steganography password to the CLI child process on the command line via the –stego-password argument (on both encrypt and decrypt paths) instead of via an environment variable as done for the main passwor…
CWE: CWE-214
NVD

MEDIUM
CVE-2026-81682
CVE-2026-81682
pkg: openssl

published: Aug 27, 2026

openssl_encrypt versions before 1.4.9 contain an insecure file permissions vulnerability in the desktop GUI that writes decrypted plaintext with world-readable default permissions. Attackers can read decrypted output files created by the GUI as unprivileged local users on multi-user systems.
CWE: CWE-276
GitHub-GHSA

MEDIUM
WebOb: Open redirect in Location header normalization via leading C0 control / space characters
GHSA-6hx8-3wjj-gr8g
pkg: webob
eco: pip
published: Aug 27, 2026
## Summary

This is a third follow-up to **CVE-2024-42353 / GHSA-mg3v-6m49-jhp3**
and **CVE-2026-44889 / GHSA-fh3h-vg37-cc95**.

WebOb makes the `Location` header absolute when it serves a redirect. To stop a
relative or protocol-relative target from redirecting users off-host, it checks
the value f…

CVE-2026-54770
NVD

MEDIUM
CVE-2026-19854
CVE-2026-19854
pkg: tls

published: Aug 27, 2026

When the ClickHouse plugin uses Native protocol (the default) with PDC or secure SOCKS, it asks for TLS but the connection library ignores that and talks to ClickHouse in the clear. Username, password, queries, and results can be read on the hop after the proxy. The server certificate is never check…
CWE: CWE-319
NVD

MEDIUM
CVE-2026-47848
CVE-2026-47848
pkg: react

published: Aug 26, 2026

In specific scenarios involving WebSocket handshake redirects to a different origin, the Reactor Netty WebSocket client may leak credentials. In order for this to happen, the HTTP client must have been explicitly configured to follow redirects.
Reactor Netty 1.3.0 – 1.3.6
Reactor Netty 1.1.0 – 1.2.1…
GitHub-GHSA

MEDIUM
praisonaiagents: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool
GHSA-cfxv-8fw8-rwpv
pkg: praisonaiagents
eco: pip
published: Aug 25, 2026
**Target:** PraisonAI (`MervinPraison/PraisonAI`)
**Affected component:** `praisonaiagents/tools/ast_grep_tool.py` — `ast_grep_rewrite`
**Affected versions:** master at `ce97667156a116c50b4a3d1aa21e09f048903fda`; reproduced against the current `praisonaiagents` PyPI release (`praisonaiagents` <= 1…
CVE-2026-55530
NVD

MEDIUM
CVE-2026-17113
CVE-2026-17113
pkg: node

published: Aug 24, 2026

A flaw was found in CRI-O's container-creation environment-variable handling
(`mergeEnvs` in `server/utils.go`, consumed by `setupContainerEnvironmentAndWorkdir` in
`server/container_create.go`). When a `CreateContainer` request supplies a `nil` CRI
`Envs` field, CRI-O falls back to using the target…
CWE: CWE-1287
NVD

MEDIUM
CVE-2026-55857
CVE-2026-55857
pkg: ssl

published: Aug 28, 2026

MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, PAM dialog authentication can be coerced into transmitting the account password over an insecure connection. The mysql_clear_password plugin is gated behind…
CWE: CWE-319, CWE-522
NVD

MEDIUM
CVE-2026-55856
CVE-2026-55856
pkg: ssl

published: Aug 28, 2026

MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, when a Java application connects with sslMode=verify-full or sslMode=verify-ca, supplies a password, and does not configure serverSslCert or trustStore, Con…
CWE: CWE-522
NVD

MEDIUM
CVE-2026-55854
CVE-2026-55854
pkg: ssl

published: Aug 28, 2026

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.4, 3.3.3, 3.4.6, and 3.5.3, MariaDB Connector/Node.js can disclose an account password when PAM dialog authentication is negotiated over an insecure transport. In lib/cmd/hands…
CWE: CWE-319, CWE-522
GitHub-GHSA

MEDIUM
org.mariadb:r2dbc-mariadb vulnerable to cleartext password disclosure to a man-in-the-middle server (clear-text auth plugins not gated on a secure transport)
GHSA-c857-9x2m-cvh2
pkg: org.mariadb:r2dbc-mariadb
eco: maven
published: Aug 28, 2026
### Summary

The connector does not gate clear-text password authentication plugins on transport encryption. A hostile or man-in-the-middle MariaDB server can request a clear-text plugin over an unencrypted (plain-TCP) connection, and the driver responds with the user's password in cleartext on the …

CVE-2026-55860
GitHub-GHSA

MEDIUM
org.mariadb:r2dbc-mariadb has Inappropriate Encoding for Output Context and Improper Encoding or Escaping of Output
GHSA-5rqc-86vf-g8r2
pkg: org.mariadb:r2dbc-mariadb
eco: maven
published: Aug 28, 2026
### Summary

The connector encodes and decodes all character data assuming the connection character set is UTF-8. A server can change character_set_client mid-session to a non-UTF-8 charset, after which the driver and server interpret the same bytes under different encodings, causing silent data cor…

CVE-2026-55859
GitHub-GHSA

MEDIUM
org.mariadb.jdbc:mariadb-java-client has Inappropriate Encoding for Output Context
GHSA-xvr9-35cr-46v9
pkg: org.mariadb.jdbc:mariadb-java-client, org.mariadb.jdbc:mariadb-java-client, org.mariadb.jdbc:mariadb-java-client
eco: maven
published: Aug 28, 2026
### Summary

The connector encodes and decodes all character data assuming the connection character set is UTF-8. A server can change character_set_client mid-session to a non-UTF-8 charset, after which the driver and server interpret the same bytes under different encodings, causing silent data cor…

CVE-2026-55858
GitHub-GHSA

MEDIUM
org.mariadb.jdbc:mariadb-java-client has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials
GHSA-qxvw-fvwx-5cp7
pkg: org.mariadb.jdbc:mariadb-java-client, org.mariadb.jdbc:mariadb-java-client, org.mariadb.jdbc:mariadb-java-client
eco: maven
published: Aug 28, 2026
### Summary

When PAM (dialog) authentication is used, the connector can be coerced into sending the account password in cleartext over an insecure connection. A hostile or man-in-the-middle server can trigger this with the default configuration, disclosing the user's password.

### Details

The my…

CVE-2026-55857
GitHub-GHSA

MEDIUM
MariaDB has cleartext password disclosure to a MITM on the initial-handshake
GHSA-g9jj-cgmh-9f38
pkg: org.mariadb.jdbc:mariadb-java-client, org.mariadb.jdbc:mariadb-java-client, org.mariadb.jdbc:mariadb-java-client
eco: maven
published: Aug 28, 2026
### Summary

When a Java application connects with sslMode=verify-full (or verify-ca) and a password but does not pin a server certificate, Connector/J deliberately accepts an untrusted/self-signed certificate at the TLS layer (the "MITM-proof without a CA" feature) and proves the server's identity …

CVE-2026-55856
NVD

MEDIUM
CVE-2025-36290
CVE-2025-36290
pkg: tls

published: Aug 28, 2026

IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques.
CWE: CWE-295
GitHub-GHSA

MEDIUM
MariaDB has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials
GHSA-42r5-vhpq-m858
pkg: mariadb, mariadb, mariadb
eco: npm
published: Aug 28, 2026
### Summary

When PAM (dialog) authentication is used, the connector can be coerced into sending the account password in cleartext over an insecure connection. A hostile or man-in-the-middle server can trigger this with the default configuration, disclosing the user's password.

### Details

The mys…

CVE-2026-55854
NVD

MEDIUM
CVE-2026-40205
CVE-2026-40205
pkg: oauth

published: Aug 28, 2026

An attacker that holds an OAuth2 token granting only part of the required scopes can authenticate, because when more than one scope is required in the configuration, the remote token validation paths accept a token that carries only one of them, while the local token validation path correctly requir…
CWE: CWE-287
GitHub-GHSA

MEDIUM
aiosmtplib: STARTTLS response injection
GHSA-vxj7-4xrp-5vr4
pkg: aiosmtplib
eco: pip
published: Aug 27, 2026
## Impact

When a connection is upgraded with STARTTLS, aiosmtplib reads the server's 220 go-ahead reply and immediately performs the TLS handshake without discarding any data still sitting in the receive buffer. Bytes the protocol read off the plaintext socket before the handshake survive across th…

CVE-2026-55558
NVD

MEDIUM
CVE-2026-47863
CVE-2026-47863
pkg: react

published: Aug 27, 2026

In Reactor Core, applications that use the Flux.bufferTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition.
Reactor Core 3.8.0 – 3.8.6
Reactor Core 3.7.19 and earlier
CWE: CWE-835
NVD

MEDIUM
CVE-2026-47857
CVE-2026-47857
pkg: react

published: Aug 27, 2026

In Reactor Core, applications that use the Flux.windowTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition.
Reactor Core 3.8.0 – 3.8.6
Reactor Core 3.5.0 – 3.7.19
Reactor Core 3.4.41 and earlier
CWE: CWE-190
GitHub-GHSA

MEDIUM
asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution
GHSA-qr67-gv47-xwwh
pkg: asyncssh
eco: pip
published: Aug 26, 2026
**Incomplete fix for CVE-2026-45309 (GHSA-g794-3fmp-753h).** The
2.23.0 guard that sanitises the SSH username before `%u` substitution
in `AuthorizedKeysFile` blocks `/`, `\` and `..`, but does not block a
leading `~` (or `${ENV}`), both of which are re-introduced by later
expansion and reac…
CVE-2026-54590
NVD

MEDIUM
CVE-2026-80206
CVE-2026-80206
pkg: express

published: Aug 26, 2026

NLTK before 3.10.3 contains a regular expression denial of service (ReDoS) vulnerability in the tgrep module. The _tgrep_node_action function compiles user-supplied regular expressions embedded in /regex/ pattern nodes and executes them via re.search against tree node labels without any validation o…
CWE: CWE-1333
NVD

MEDIUM
CVE-2026-79126
CVE-2026-79126
pkg: google chrome, microsoft windows

published: Aug 25, 2026

Incorrect provision of specified functionality in Proxy in Google Chrome on on Windows prior to 152.0.7977.65 allowed an adjacent attacker to potentially obtain sensitive information via crafted network traffic. (Chromium security severity: Low)
CWE: CWE-684
NVD

MEDIUM
CVE-2026-79785
CVE-2026-79785
pkg: ssl

published: Aug 25, 2026

X-AnyLabeling's model downloader disabled TLS certificate verification. download_with_retry in anylabeling/services/auto_labeling/model.py built a context with ssl._create_unverified_context() and passed it to urllib.request.urlopen, so neither the certificate chain nor the hostname was checked on a…
CWE: CWE-295
NVD

MEDIUM
CVE-2026-63074
CVE-2026-63074
pkg: openssl

published: Aug 25, 2026

Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches
additional certificates (extraCerts) sent in a CMP message, but never expunges
them (for instance if they are invalid). If a server reuses an OSSL_CMP_CTX
frequently, this cache of extraCerts may grow unboundedly, and a malicio…
CWE: CWE-770
NVD

MEDIUM
CVE-2026-79652
CVE-2026-79652
pkg: jwt

published: Aug 25, 2026

A flaw was found in the JWT Bearer authorization grant implementation within the keycloak-services component of Red Hat Build of Keycloak. This component handles various OAuth2 and OpenID Connect grant types used for issuing access tokens. The issue occurs because the JWT Bearer grant fails to check…
CWE: CWE-862
GitHub-GHSA

MEDIUM
mediasoup: SCTP state cookie lacks cryptographic authentication, enabling unauthorized association establishment (RFC 9260 violation)
GHSA-p7x2-g5cq-fhmq
pkg: mediasoup, mediasoup
eco: npm
published: Aug 25, 2026
### Summary

mediasoup's built-in SCTP stack (introduced in v3.20.0) authenticates SCTP state cookies using only hardcoded magic byte sequences rather than a per-instance HMAC keyed with a secret, violating RFC 9260 Section 5.1.3. An on-path attacker targeting a PlainTransport with SCTP enabled (and…

CVE-2026-55663
NVD

MEDIUM
CVE-2026-81703
CVE-2026-81703
pkg: openssl

published: Aug 27, 2026

openssl_encrypt versions before 1.4.9 fail to validate encryption status of embedded post-quantum private keys in file metadata. Attackers can craft files with unencrypted embedded PQC keys that decrypt under any password, bypassing authentication and producing attacker-chosen plaintext with false i…
CWE: CWE-287
NVD

MEDIUM
CVE-2026-81697
CVE-2026-81697
pkg: openssl

published: Aug 27, 2026

openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 contain a CWD-relative configuration file resolution flaw in crypt_settings.py, where CONFIG_FILE (originally the absolute per-user path ~/.crypt_settings.json) is reassigned at line 84 to the bare relative name 'crypt_settings.json'. A…
CWE: CWE-426
NVD

MEDIUM
CVE-2026-81687
CVE-2026-81687
pkg: openssl

published: Aug 27, 2026

openssl_encrypt versions before 1.4.9 fail to enforce a time ceiling on key derivation function iteration counts specified in file metadata. Attackers can craft files with extremely high KDF iteration counts to consume CPU resources for unbounded periods before password verification occurs.
CWE: CWE-400
NVD

MEDIUM
CVE-2026-68514
CVE-2026-68514
pkg: python

published: Aug 25, 2026

OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13, the PyOpenEXR Python bindings contain a heap out-of-bounds write triggered when reading a crafted deep scanl…
CWE: CWE-122, CWE-787
NVD

MEDIUM
CVE-2026-79769
CVE-2026-79769
pkg: node

published: Aug 25, 2026

Nokogiri versions before 1.19.4 contain a possible invalid (out-of-bounds) memory read in the protected internal Node#initialize_copy_with_args helper behind Node#dup and #clone, which unwrapped its source argument as an xmlNode without a type check. If application code calls this protected method w…
CWE: CWE-843
GitHub-GHSA

MEDIUM
Apache Camel-Azure-Storage-DataLake: the downloadToFile operation built the local download target from the remote path name without constraining it to the configured fileDir
GHSA-7jwc-q3fj-c9pq
pkg: org.apache.camel:camel-azure-storage-datalake, org.apache.camel:camel-azure-storage-datalake, org.apache.camel:camel-azure-storage-datalake
eco: maven
published: Aug 24, 2026
Relative path traversal vulnerability in Apache Camel Azure-Storage Datalake component

This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0.

The camel-azure-storage-datalake component can download an Azure Data Lake Storage Gen2 file to th…

CVE-2026-60093
NVD

MEDIUM
CVE-2026-82469
CVE-2026-82469
pkg: jwt

published: Aug 29, 2026

Rodauth before 2.47.0 contains an authentication bypass vulnerability in the jwt_refresh route that issues new JWT access tokens without requiring a refresh token. Attackers can present an access token to the refresh route via non-POST methods to obtain a new valid access token, enabling indefinite …
CWE: CWE-613
NVD

MEDIUM
CVE-2026-54553
CVE-2026-54553
pkg: python

published: Aug 26, 2026

Starlette-Admin is a fast, beautiful and extensible administrative interface framework for FastAPI and Starlette applications. Prior to 0.16.1, the list API does not validate user-supplied order_by and structured where field names against the configured sortable_fields and searchable_fields allowlis…
CWE: CWE-200, CWE-248, CWE-639
GitHub-GHSA

MEDIUM
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
GHSA-6753-gr46-6wpr
pkg: starlette-admin
eco: pip
published: Aug 26, 2026
## Summary

Affected versions of Starlette-Admin prior to 0.16.1 do not properly validate user-supplied sort and search parameters against the configured field allowlists. While the administrative UI restricts available fields based on field configuration, the backend accepts arbitrary field names s…

CVE-2026-54553
NVD

MEDIUM
CVE-2026-78912
CVE-2026-78912
pkg: google chrome

published: Aug 25, 2026

UI misrepresentation in Browser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-451
NVD

MEDIUM
CVE-2026-10618
CVE-2026-10618
pkg: go

published: Aug 24, 2026

Hugo's default fenced-code-block renderer writes attribute values taken from the code-fence info string into the rendered HTML without escaping them. New in markup/internal/attributes/attributes.go converts every attribute value from a byte slice to a string as it is stored, deliberately dropping th…
CWE: CWE-79
NVD

MEDIUM
CVE-2024-58379
CVE-2024-58379
pkg: express

published: Aug 31, 2026

nodemailer before 6.9.9 contains a regular expression denial of service vulnerability in email parsing when attachDataUrls parameter is set or processing embedded file attachments. Attackers can send specially crafted emails with malicious data URLs or embedded attachments to cause the event loop to…
CWE: CWE-1333
NVD

MEDIUM
CVE-2026-82417
CVE-2026-82417
pkg: express

published: Aug 30, 2026

### Summary

`qs.stringify` throws a `TypeError` when it serializes an object whose own `constructor` property has a truthy, non-callable `isBuffer` member. `utils.isBuffer` duck-types buffers by calling `obj.constructor.isBuffer(obj)` after checking only that the property is truthy, so a value su…

CWE: CWE-248, CWE-703
NVD

MEDIUM
CVE-2026-15603
CVE-2026-15603
pkg: node

published: Aug 28, 2026

morgan is an HTTP request logger middleware for Node.js. In versions prior to 1.12.0, the internal helper that escapes log token values did not neutralize the Unicode line separator characters U+0085 (Next Line), U+2028 (Line Separator), and U+2029 (Paragraph Separator). An unauthenticated remote cl…
CWE: CWE-117
NVD

MEDIUM
CVE-2026-82256
CVE-2026-82256
pkg: node

published: Aug 28, 2026

SvelteKit before 2.69.1 fails to properly validate remote form function payload sizes, allowing attackers to crash the Node process by sending large payloads. Repeated exploitation causes denial of service by repeatedly crashing the application process.
CWE: CWE-400
NVD

MEDIUM
CVE-2026-82248
CVE-2026-82248
pkg: windows

published: Aug 28, 2026

gix-worktree-state before 0.33.0 (part of gitoxide) allows writing files outside the worktree on Windows. gix_worktree_state::checkout() follows an existing terminal symlink during non-exclusive (incremental) materialization (destination_is_initially_empty: false) when core.symlinks is true. If a sy…
CWE: CWE-59
NVD

MEDIUM
CVE-2026-81724
CVE-2026-81724
pkg: python

published: Aug 27, 2026

NLTK before 3.10.3 contains an uncontrolled recursion vulnerability in nltk.featstruct.FeatStructReader that allows unauthenticated attackers to cause a denial of service by supplying deeply nested feature-structure input. Attackers can craft trivial payloads with nested brackets that exceed Python'…
CWE: CWE-674
NVD

MEDIUM
CVE-2026-80207
CVE-2026-80207
pkg: nginx

published: Aug 27, 2026

APITable through 1.13.0-beta.1 annotates the create handler of InternalNotifyController with requiredLogin = false. ResourceInterceptor honours that annotation by returning before any session or API key is validated, and the nginx gateway shipped with the product proxies every /api request to the ba…
CWE: CWE-306
NVD

MEDIUM
CVE-2026-47874
CVE-2026-47874
pkg: react

published: Aug 27, 2026

The vulnerability occurs when a client sends HTTP/1.1 pipelined requests over a single connection, causing the Reactor Netty HTTP server to consume an excessive amount of memory.
Reactor Netty 1.3.0 – 1.3.6
Reactor Netty 1.1.0 – 1.2.18
Reactor Netty 1.0.52 and earlier
CWE: CWE-770
NVD

MEDIUM
CVE-2026-47845
CVE-2026-47845
pkg: react

published: Aug 27, 2026

In specific scenarios, Reactor Netty HTTP Server may incorrectly evaluate the remote IP address when HAProxy Protocol is enabled. In order for this to happen, the application must be configured to use HAProxy Protocol.
Reactor Netty 1.3.0 – 1.3.6
Reactor Netty 1.1.0 – 1.2.18
Reactor Netty 1.0.52 and…
CWE: CWE-290
NVD

MEDIUM
CVE-2026-47844
CVE-2026-47844
pkg: react

published: Aug 26, 2026

In specific scenarios, the Reactor Netty HTTP Server may leak exception details across unrelated requests. In order for this to happen, the server must be configured with Brave Tracing.
Reactor Netty 1.3.0 – 1.3.6
Reactor Netty 1.1.0 – 1.2.18
Reactor Netty 1.0.52 and earlier
GitHub-GHSA

MEDIUM
OpenWISP IPAM has broken object-level authorization: ExportSubnetView lets a member of one organization export another organization's subnet and all its IP addresses
GHSA-x287-5c68-36wp
pkg: openwisp-ipam
eco: pip
published: Aug 26, 2026
## Summary

OpenWISP IPAM is multi-tenant: every `Subnet` belongs to an `organization`, and API access is scoped to the organizations a user belongs to. The CSV **export** endpoint, `ExportSubnetView`, omits the organization-membership check that its **import** sibling performs, and loads the subnet…

GitHub-GHSA

MEDIUM
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
GHSA-p43p-whwx-q52h
pkg: jupyterhub
eco: pip
published: Aug 25, 2026
### Impact

Invalid input to login resulted in unbounded logging output. Only form-based Authenticators (the default PAM Authenticator, but not the more widely used OAuthenticator) are affected.

### Patches

Upgrade to 5.5.0.

### Workarounds

Use an Authenticator that doesn't use a login form, suc…

CVE-2026-54338
NVD

MEDIUM
CVE-2026-55619
CVE-2026-55619
pkg: python

published: Aug 25, 2026

eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information. Prior to 3.0.2, eml_parser.parser.HeaderParser.header_fetch_parse in eml_parser/parser.py uses email.utils.getaddresses() to parse address-bearing e-mail …
CWE: CWE-770, CWE-1124
GitHub-GHSA

MEDIUM
@arikusi/deepseek-mcp-server: Missing Authentication on Self-Hosted HTTP MCP Endpoint
GHSA-72f3-6w86-7rv3
pkg: @arikusi/deepseek-mcp-server
eco: npm
published: Aug 25, 2026
## Summary
The self-hosted HTTP transport of `@arikusi/deepseek-mcp-server` exposes `POST /mcp` without any authentication: `createMcpExpressApp` is called without an `authProvider` and no middleware guards the route, so any network-reachable client can issue an unauthenticated `initialize` request …
CVE-2026-55605
GitHub-GHSA

MEDIUM
eml_parser has parser DoS via deeply nested parentheses in e-mail headers
GHSA-m66c-fw79-6359
pkg: eml_parser
eco: pip
published: Aug 25, 2026
### Summary

`eml_parser` uses the `email.utils.getaddresses()` function from the CPython standard library to parse e-mail headers that contain e-mail addresses (such as `To`, `Cc`, `Bcc`, `From`, `Reply-To`, `Sender`, …). When the input header contains a deeply nested CFWS (comment / folding whit…

CVE-2026-55619
GitHub-GHSA

MEDIUM
reachy_mini Allows Unrestricted Upload of File with Dangerous Type
GHSA-m2pc-3q4q-w6jr
pkg: reachy-mini
eco: pip
published: Aug 25, 2026
## Summary

The Reachy Mini daemon exposes the “/api/media/sounds/upload” endpoint without authentication and file validation mechanisms.
An attacker can use this endpoint to upload malicious files into the file system that will propagate in future attacks.

## Compromise Chain: Unauthenticate…

CVE-2026-55419
NVD

MEDIUM
CVE-2026-79778
CVE-2026-79778
pkg: go

published: Aug 25, 2026

rclone before v1.75.0 contains a denial of service vulnerability in the WebDAV TUS creation handler that dereferences a nil response before checking for transport errors. A malicious or compromised configured endpoint can reset connections during TUS uploads to trigger a panic that terminates unreco…
CWE: CWE-248
GitHub-GHSA

MEDIUM
Cloudreve has Broken Access Control – Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint
GHSA-vx2m-jpxr-xv7w
pkg: github.com/cloudreve/Cloudreve/v4
eco: go
published: Aug 24, 2026
## Summary

Cloudreve's file-listing responses hand the client a `context_hint` (UUID) that is meant to speed up follow-up operations. When that hint is replayed on the `file/url` (and `file/thumb`) routes, DBFS caches a `shareNavigatorState` containing the already-loaded share root and share row.

GitHub-GHSA

MEDIUM
Apache Camel-Knative: CloudEvent extension fields received in structured content mode were mapped onto message headers without applying any header filter strategy
GHSA-vvwm-3j43-7pfm
pkg: org.apache.camel:camel-knative, org.apache.camel:camel-knative, org.apache.camel:camel-knative
eco: maven
published: Aug 24, 2026
Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache Camel Knative component

The Knative consumer in camel-knative maps inbound CloudEvent attributes onto Camel message headers. In binary content mode t…

CVE-2026-63621
NVD

MEDIUM
CVE-2026-81716
CVE-2026-81716
pkg: openssl

published: Aug 27, 2026

openssl_encrypt (pip: openssl-encrypt) versions before 1.4.9 contain a path traversal flaw in PluginSandbox._is_safe_path, which authorized file access using a bare string-prefix match. A sandboxed plugin without the READ_FILES permission could read or write another plugin's directory that merely sh…
CWE: CWE-22
NVD

MEDIUM
CVE-2026-65085
CVE-2026-65085
pkg: linux

published: Aug 25, 2026

NVIDIA OpenShell for Linux contains a vulnerability in its inference proxy, where an attacker could cause an improper encoding or escaping of output. A successful exploit of this vulnerability might lead to information disclosure and data tampering.
CWE: CWE-116
GitHub-GHSA

MEDIUM
Graylog Server: System Catalog titles endpoint can be used to retrieve values of protected database fields
GHSA-q79r-r9xg-r863
pkg: org.graylog2:graylog2-server
eco: maven
published: Aug 28, 2026
### Impact

A vulnerability was found in Graylog's API endpoint for retrieving system catalog entity titles. Authenticated users could retrieve database fields of supported entities by sending a custom API request. These fields can include e.g. the password hash of a user (but not the password itsel…

CVE-2026-55425
GitHub-GHSA

MEDIUM
Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment
GHSA-569v-q83c-3j3g
pkg: code.vikunja.io/api
eco: go
published: Aug 28, 2026
## Summary

`POST /api/v1/projects/{project}/views/{view}/buckets/{bucket}` mass-assigns the request body's `project_view_id` onto the bucket row. The permission check only verifies that the URL-supplied bucket already belongs to the URL-supplied `(project, view)` pair; the body's `project_view_id` …

CVE-2026-55067
GitHub-GHSA

MEDIUM
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
GHSA-fwjf-m4qw-9f2x
pkg: django-cms
eco: pip
published: Aug 24, 2026
### Summary
The CMS page cache key ignores the request headers that plugins declare via `get_vary_cache_on()`. The header is added to the response `Vary` header, but the CMS's own cache key does not incorporate the header values, so the first visitor's variant is served to all subsequent visitors re…
CVE-2026-54625
NVD

MEDIUM
CVE-2026-82274
CVE-2026-82274
pkg: oauth

published: Aug 28, 2026

Twenty through 2.35.0 contains an open redirect vulnerability in the OAuthPropagatorController.propagateOAuthCallback endpoint that treats the state query parameter as a redirect URL. Attackers can craft malicious requests to redirect users to arbitrary hosts while forwarding OAuth authorization cod…
CWE: CWE-601
GitHub-GHSA

MEDIUM
utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins
GHSA-ppx3-28rw-8fpf
pkg: utcp-gql, utcp-websocket
eco: pip
published: Aug 25, 2026
### Summary

The fix for CVE-2026-44661 (commit `5b16e43`) added the `ensure_secure_url()` / `is_secure_url()` helpers and wired them into the three HTTP-family plugins, but it did not reach the GraphQL or WebSocket plugins. The GraphQL plugin (`utcp-gql`) still uses the `startswith` prefix check th…

CVE-2026-12210
NVD

MEDIUM
CVE-2026-81681
CVE-2026-81681
pkg: openssl

published: Aug 27, 2026

openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 advertise a portable USB workspace as an 'Encrypted USB Workspace' with AES-256-GCM encryption and write a marker declaring the workspace encrypted, but the workspace directory is actually stored in cleartext and the derived encryption …
CWE: CWE-311
NVD

MEDIUM
CVE-2026-75573
CVE-2026-75573
pkg: tls

published: Aug 27, 2026

In MongoDB Connector for BI, mongodrdl may write a TLS private-key password to standard error when the password is supplied through both the connection URI and the corresponding command-line option. A local user with access to the captured command output and encrypted key file may use the disclosed …
CWE: CWE-532
GitHub-GHSA

MEDIUM
SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets
GHSA-hgpf-8634-g44c
pkg: github.com/seaweedfs/seaweedfs
eco: go
published: Aug 28, 2026
### Summary
SeaweedFS routes requests signed with SigV4 service `s3tables` to the S3Tables
management API. Authorization on that path collapsed account-less S3 identities
into the shared `admin` account and failed open, so a user holding only ordinary
S3 `Read` credentials — and no S3Tables-specif…
CVE-2026-55873
GitHub-GHSA

MEDIUM
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
GHSA-2p9g-x3cv-5hh4
pkg: weblate
eco: pip
published: Aug 28, 2026
### Impact
The several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404.

### Patches
* https://github.com/WeblateOrg/weblate/pull/19971

### References
Thanks to Yaohui Wang for reporting this via GitHub.

CVE-2026-55227
GitHub-GHSA

MEDIUM
Yamcs has DOM XSS in Extension Routing
GHSA-9272-wg2r-7xmx
pkg: org.yamcs:yamcs-core, org.yamcs:yamcs-core
eco: maven
published: Aug 28, 2026
**Attack type**: Unauthenticated remote
**Impact**: Execution of arbitrary JavaScript in a user’s browser.
**Affected components**: extension.matcher.ts:12, extension.component.ts:40, app.component.ts:134.

Yamcs is vulnerable to cross-site scripting in the /ext URL endpoint. By inputting special…

CVE-2026-55566
GitHub-GHSA

MEDIUM
Yamcs: Insecure Direct Object Reference (IDOR) in PacketsApi allows unprivileged users to dump all telemetry packets
GHSA-8xjq-pr36-ccgf
pkg: org.yamcs:yamcs-core, org.yamcs:yamcs-core
eco: maven
published: Aug 28, 2026
## Summary
The `PacketsApi.exportPackets` endpoint in Yamcs fails to properly enforce object-level privileges (`ReadPacket`) when an API request omits specific packet names. As a result, an attacker with a low-privileged account (or any authenticated user with zero privileges) can dump the entire ar…
CVE-2026-55548
GitHub-GHSA

MEDIUM
Yamcs's Missing Authorization on Role and Privilege Enumeration Endpoints Allows Any Authenticated User to Disclose Full Security Configuration
GHSA-cvw4-55pp-3hfq
pkg: org.yamcs:yamcs-core, org.yamcs:yamcs-core
eco: maven
published: Aug 28, 2026
## Summary

Missing authorization checks on three IAM API endpoints (`GET /api/roles`, `GET /api/roles/{name}`, `GET /api/privileges`) allow any authenticated user — regardless of their assigned permissions — to enumerate the complete list of system privileges and role definitions. An attacker w…

CVE-2026-55547
GitHub-GHSA

MEDIUM
Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0
GHSA-44v6-7fxq-vgf4
pkg: code.vikunja.io/api
eco: go
published: Aug 28, 2026
## Summary

The fix for CVE-2026-35595 (project re-parenting privilege escalation) only gates reparent operations when `parent_project_id > 0`. A user with Write (but not Admin) permission on a shared child project can detach it from its parent by sending `parent_project_id: 0`, bypassing the Admin …

CVE-2026-55064
GitHub-GHSA

MEDIUM
Pocket-ID has an Open Redirect on the OIDC /authorize page via unvalidated redirect_uri with prompt=none
GHSA-2wvm-8mvp-22qv
pkg: github.com/pocket-id/pocket-id/backend
eco: go
published: Aug 28, 2026
### Summary
The OIDC authorization page in the pocket-id frontend redirects the browser to an attacker-controlled URL without consulting the backend redirect_uri allow-list when the request uses prompt=none. An attacker who knows a valid client_id can craft an /authorize link that sends a victim (or…
CVE-2026-55834
NVD

MEDIUM
CVE-2026-33263
CVE-2026-33263
pkg: tls

published: Aug 28, 2026

When mail_max_userip_connections is set (default 10) and reached, submission-login can crash with epoll() panic caused by file descriptor handling issues. If running in high-security mode (default for community releases), only the new submission connection gets terminated. If running in high-perform…
CWE: CWE-403
NVD

MEDIUM
CVE-2026-77789
CVE-2026-77789
pkg: react

published: Aug 26, 2026

The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.1 does not verify that a subscription belongs to the customer bound to the requesting customer-portal session before acting on it, allowing a user with a confirmed portal session to cancel, reactivate or modify subscriptions belong…
CWE: CWE-639
NVD

MEDIUM
CVE-2026-79084
CVE-2026-79084
pkg: google chrome, microsoft windows

published: Aug 25, 2026

Inadequate encryption strength in Notifications in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-326
NVD

MEDIUM
CVE-2026-78979
CVE-2026-78979
pkg: google chrome, microsoft windows

published: Aug 25, 2026

Race condition in Core in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
CWE: CWE-362
NVD

MEDIUM
CVE-2026-78946
CVE-2026-78946
pkg: google chrome

published: Aug 25, 2026

Incorrect authorization in Select in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
CWE: CWE-863
NVD

MEDIUM
CVE-2026-78942
CVE-2026-78942
pkg: google chrome

published: Aug 25, 2026

Incorrect reference resolution in Loader in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via crafted network traffic. (Chromium security severity: Medium)
CWE: CWE-706
NVD

MEDIUM
CVE-2026-78940
CVE-2026-78940
pkg: google chrome

published: Aug 25, 2026

Improper initialization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
CWE: CWE-665
NVD

MEDIUM
CVE-2026-78908
CVE-2026-78908
pkg: google chrome

published: Aug 25, 2026

Information leak in Canvas in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-200
NVD

MEDIUM
CVE-2026-78896
CVE-2026-78896
pkg: google chrome

published: Aug 25, 2026

Information leak in StorageAccessAPI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Low)
CWE: CWE-200
NVD

MEDIUM
CVE-2026-78895
CVE-2026-78895
pkg: google chrome

published: Aug 25, 2026

Information leak in Paint in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-200
NVD

MEDIUM
CVE-2026-62986
CVE-2026-62986
pkg: python

published: Aug 25, 2026

OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13, the PyOpenEXR Python bindings return stale heap data when reading a crafted deep scanline EXR that uses laye…
CWE: CWE-200, CWE-457, CWE-908
NVD

MEDIUM
CVE-2026-21753
CVE-2026-21753
pkg: go

published: Aug 25, 2026

HCL Hive is affected by weak software supply chain governance, which could lead to the inclusion of vulnerable, unmaintained, or malicious third-party dependencies within the application environment.
CWE: CWE-1104
NVD

MEDIUM
CVE-2026-81680
CVE-2026-81680
pkg: openssl

published: Aug 27, 2026

openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presence in envelope-format encrypted files, allowing attackers to remove recovery slots without re-encrypting the payload. Attackers can modify the file header to delete recovery-slot fields and bypass authentication, silently…
CWE: CWE-347
GitHub-GHSA

MEDIUM
AsyncHttpClient stores cookie for an unrelated domain (cookie tossing) via ThreadSafeCookieStore
GHSA-m452-q8c9-rg2f
pkg: org.asynchttpclient:async-http-client, org.asynchttpclient:async-http-client
eco: maven
published: Aug 26, 2026
### Impact
A **cookie tossing / cookie injection** issue (CWE-1275). `ThreadSafeCookieStore` stored a cookie under the value of its `Domain` attribute without verifying that the responding host is allowed to set a cookie for that domain (RFC 6265 §5.3 step 6). A host the client connects to can the…
CVE-2026-55688
GitHub-GHSA

MEDIUM
Graylog token revocation endpoint allows authenticated users to delete other users’ access tokens
GHSA-j769-9gv9-65gr
pkg: org.graylog2:graylog2-server, org.graylog2:graylog2-server, org.graylog2:graylog2-server
eco: maven
published: Aug 28, 2026
### Impact

Graylog contains an insecure direct object reference (IDOR) vulnerability in the token revocation endpoint. An authenticated user can delete access tokens belonging to other users, including service account tokens and administrator tokens, if they know or can guess a valid token identifi…

CVE-2026-55867
GitHub-GHSA

MEDIUM
arc has unauthenticated cluster node admission when `cluster.shared_secret` is unset
GHSA-p378-jp5r-gpgw
pkg: github.com/basekick-labs/arc
eco: go
published: Aug 28, 2026
## Summary

Arc Enterprise clustering accepts cluster join requests without authentication when `cluster.enabled=true` but `cluster.shared_secret` is not configured. The coordinator validates HMAC authentication only if a shared secret is non-empty; otherwise, a network attacker who can reach the co…

CVE-2026-55678
GitHub-GHSA

MEDIUM
AIIR verification and policy gates could report success without enforcing the control (fail-open)
GHSA-73p9-6hrp-8qhr
pkg: aiir
eco: pip
published: Aug 28, 2026
### Summary
Several of AIIR's verification and policy paths could return a success/"verified" result without actually enforcing the control they represent — they could **fail open** rather than fail closed. For a tool whose purpose is trustworthy verification, a consumer relying on these gates may…
GitHub-GHSA

MEDIUM
Buffa Vulnerable to Memory Exhaustion Denial of Service in decode_unknown_field via Unbounded Allocation
GHSA-f9qc-qg88-7pq5
pkg: buffa
eco: rust
published: Aug 28, 2026
The `decode_unknown_field` function in buffa's protobuf decoder allocated heap memory in proportion to untrusted input (unknown fields in the serialized protobuf) without enforcing an allocation budget. Any message decoded from untrusted input using code generated with `preserve_unknown_fields=true`…
CVE-2026-55407
GitHub-GHSA

MEDIUM
Buffa has a Use-After-Free in OwnedView via Unsound 'static Lifetime Promotion in Deref
GHSA-9pwq-gcrx-wghh
pkg: buffa
eco: rust
published: Aug 28, 2026
A soundness bug in `buffa`'s `OwnedView<V>` allowed safe Rust code to trigger a use-after-free. The `OwnedView::decode` constructor transmuted a borrowed slice to `&'static [u8]`, and the `Deref` implementation exposed the promoted `'static` lifetime on borrowed view fields (such as `&'static str` a…
CVE-2026-55406
GitHub-GHSA

MEDIUM
Vikunja has a project duplication bypasses write-permission check on the target parent project
GHSA-f27p-pw2p-9pr4
pkg: code.vikunja.io/api
eco: go
published: Aug 28, 2026
## Summary

The project-duplication endpoint fails to enforce write access to the target parent project. Any authenticated (non-link-share) user can duplicate a project they can read into **any** parent project on the instance, regardless of whether they have write access to that parent — injectin…

CVE-2026-54766
GitHub-GHSA

MEDIUM
n8n-nodes-sqlite3 vulnerable to path traversal via user-controlled database file path (db_path parameter)
GHSA-q7m3-rhxg-7vxr
pkg: n8n-nodes-sqlite3
eco: npm
published: Aug 27, 2026
## Affected versions
< 1.0.0

## Patched version
1.0.0

## Description
In versions prior to 1.0.0, the SQLite node accepted the database file
path as a direct node parameter visible and editable in the workflow.
A workflow author who mapped untrusted user input to the db_path field
could allow an at…

CVE-2026-54687
GitHub-GHSA

MEDIUM
vibeio-http has a DoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously crafted chunk lengths
GHSA-fx4f-mhw4-qm7j
pkg: vibeio-http
eco: rust
published: Aug 24, 2026
When using the affected versions of the `vibeio-http` crate, an attacker could craft a malicious HTTP/1.x request with a large chunk length (between `usize::MAX – 1` and `usize::MAX` inclusive) and send it, causing the server to crash (integer overflow panic in debug builds, split_to out of bounds p…
GitHub-GHSA

MEDIUM
Cloudreve's remote download file paths can escape the selected destination directory
GHSA-w8j7-39hp-8×59
pkg: github.com/cloudreve/Cloudreve/v4
eco: go
published: Aug 24, 2026
### Summary

Cloudreve trusts file paths returned by the configured remote downloader. A downloader-reported path such as `../../escaped.txt` can cause a downloaded file to be created outside the user-selected destination directory.

### Details

In the remote download master transfer path, Cloudrev…

GitHub-GHSA

MEDIUM
Gorilla WebSocket Uses Cryptographically Weak PRNG for WebSocket Mask Key
GHSA-w67g-5rqw-f597
pkg: github.com/gorilla/websocket
eco: go
published: Aug 24, 2026
gorilla/websocket used `math/rand` (cryptographically weak pseudo-random number generator) to generate WebSocket frame mask keys prior to commit d67f4185. WebSocket masking keys MUST be unpredictable to prevent frame content injection attacks. math/rand produces deterministic output when seeded with…
GitHub-GHSA

MEDIUM
tokio-postgres: Panic on a `DataRow` with fewer fields than columns allows denial of service
GHSA-3gjw-f78c-vvpw
pkg: tokio-postgres
eco: rust
published: Aug 24, 2026
A malicious or compromised server can send a row containing fewer fields than
its row description declares columns. Reading one of the missing columns then
panics with an out-of-bounds index, aborting the calling task. This affects even
the otherwise non-panicking `try_get`, and both `Row` and `Simp…
GitHub-GHSA

MEDIUM
postgres-protocol: Panic decoding a malformed `hstore` value allows denial of service
GHSA-rgqc-3x5p-6gwg
pkg: postgres-protocol
eco: rust
published: Aug 24, 2026
A malicious or compromised server can return a binary `hstore` value with an
invalid internal length field, causing the client to panic while decoding it.

Applications that connect only to a trusted database are not exposed; the risk
applies to clients that may connect to untrusted or user-supplied…