Vulnerability Digest — July 27, 2026 · 76 Critical · 6 Exploited






Vulnerability Digest — Monday, July 27, 2026


Security Report

Monday, July 27, 2026  ·  Last 7 days  ·  Min severity: MEDIUM
Total Findings
534
Critical
76
High
242
Actively Exploited
6
CISA-KEV6
NVD187
GitHub-GHSA341
Findings sorted by severity
CISA-KEV

CRITICAL
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
CVE-2026-50522
pkg: Microsoft SharePoint

published: Jul 22, 2026

Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Check Point SmartConsole Improper Authentication Vulnerability
CVE-2026-16232
pkg: Check Point SmartConsole

published: Jul 22, 2026

Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
WordPress Core SQL Injection Vulnerability
CVE-2026-60137
pkg: WordPress Core

published: Jul 21, 2026

WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
WordPress Core Interpretation Conflict Vulnerability
CVE-2026-63030
pkg: WordPress Core

published: Jul 21, 2026

WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
CVE-2026-0770
pkg: Langflow Langflow

published: Jul 21, 2026

Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV

CRITICAL
DD-WRT Stack-Based Buffer Overflow Vulnerability
CVE-2021-27137
pkg: DD-WRT DD-WRT

published: Jul 21, 2026

DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
NVD

CRITICAL
CVE-2026-66012
CVE-2026-66012
pkg: jwt

published: Jul 25, 2026

SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This exposes 31 MCP tools, including a file tool with list/read/write/delete/rename/copy ac…
CWE: CWE-862
GitHub-GHSA

CRITICAL
Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer
GHSA-w28w-gp39-m4p6
pkg: @prompty/core, @prompty/core
eco: npm
published: Jul 24, 2026
## Summary
The TypeScript Nunjucks renderer evaluated untrusted `.prompty` template bodies with unrestricted JavaScript member access. An attacker-controlled template could traverse constructor and prototype properties to execute JavaScript in the host Node.js process.

## Affected packages
– npm `@…

NVD

CRITICAL
CVE-2026-56163
CVE-2026-56163
pkg: kubernetes

published: Jul 24, 2026

Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
CWE: CWE-306
NVD

CRITICAL
CVE-2025-71389
CVE-2025-71389
pkg: react

published: Jul 23, 2026

Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) request handling deserializes attacker-controlled input. A remote attacker can send a crafted RSC request to the server and cause a…
CWE: CWE-94
NVD

CRITICAL
CVE-2026-47668
CVE-2026-47668
pkg: node

published: Jul 23, 2026

DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection in the `functionName` parameter of JSON script `assign` commands. The `functionName` value is interpolated directly into dynamic…
CWE: CWE-20, CWE-94, CWE-1188
NVD

CRITICAL
CVE-2026-46412
CVE-2026-46412
pkg: oauth

published: Jul 20, 2026

@beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support. Between 2026-05-11 20:19 UTC and 22:56 UTC, an attacker used a compromised npm publish token to publish 18 malicious versions of `@beproduct/nestjs-auth` (0.1.2 through 0.1.19). …
CWE: CWE-506
GitHub-GHSA

CRITICAL
@better-auth/scim: account takeover and stale access via SCIM provider-id collision
GHSA-rjg6-39jm-rgg4
pkg: @better-auth/scim, @better-auth/scim
eco: npm
published: Jul 24, 2026
### Am I affected?

You are affected if your application registers the `@better-auth/scim` plugin and lets authenticated users generate SCIM tokens. The default `canGenerateToken` policy was affected, and custom policies were affected when they did not reject provider IDs already used by other accou…

NVD

CRITICAL
CVE-2026-63732
CVE-2026-63732
pkg: node

published: Jul 23, 2026

9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default password (123456) that authenticates any fresh installation, a bypass of the LOCAL_ONLY network gate via a spoofed Host header, and unvalidated arguments passed to child_process.spawn() when registering MCP plu…
CWE: CWE-78
NVD

CRITICAL
CVE-2026-47752
CVE-2026-47752
pkg: docker

published: Jul 23, 2026

Tugtainer is a self-hosted app for automating updates of Docker containers. Versions prior to 1.30.2 are vulnerable to Server-Side Template Injection (SSTI) in the notification template feature. The `title_template` and `body_template` fields are rendered using an unsandboxed `jinja2.Environment`, a…
CWE: CWE-1336
NVD

CRITICAL
CVE-2026-60402
CVE-2026-60402
pkg: kubernetes

published: Jul 21, 2026

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTe…
CWE: CWE-284
NVD

CRITICAL
CVE-2026-47392
CVE-2026-47392
pkg: python

published: Jul 21, 2026

PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praisonaiagents, `execute_code()` in `praisonaiagents/tools/python_tools.py` (v1.6.37, subprocess sandbox mode) can be fully bypassed using `print.__self__` to retrieve the real Python `…
CWE: CWE-184, CWE-693
NVD

CRITICAL
CVE-2026-64459
CVE-2026-64459
pkg: node

published: Jul 25, 2026

In the Linux kernel, the following vulnerability has been resolved:

tcp: restore RCU grace period in tcp_ao_destroy_sock

Commit 51e547e8c89c ("tcp: Free TCP-AO/TCP-MD5 info/keys without RCU")
removed the call_rcu() callback from tcp_ao_destroy_sock(), arguing that
"the destruction of info/keys is …

GitHub-GHSA

CRITICAL
OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback
GHSA-wg5r-wc3x-39vc
pkg: org.openidentityplatform.openam:openam-core
eco: maven
published: Jul 24, 2026
## Summary
A pre-authentication remote code execution vulnerability affects OpenAM. The
remote authentication endpoint (`/authservice`, PLL) accepts an XML element
that names an arbitrary Java class, which the server then loads and
instantiates without validation. On a default configuration this is …
CVE-2026-62379
GitHub-GHSA

CRITICAL
Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix)
GHSA-7gfh-x38p-prh3
pkg: velocityjs
eco: npm
published: Jul 24, 2026
### Summary

Remote Code Execution (RCE) in velocityjs v2.1.6 via property-read to the Function constructor. This bypasses the fix for GHSA-j658-c2gf-x6pq ("Prototype Pollution in #set path assignment") — that advisory blocked constructor/__proto__/prototype only in the #set assignment handler (se…

NVD

CRITICAL
CVE-2026-64232
CVE-2026-64232
pkg: linux

published: Jul 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

block: recompute nr_integrity_segments in blk_insert_cloned_request

blk_insert_cloned_request() already recomputes nr_phys_segments
against the bottom queue, because "the queue settings related to
segment counting may differ from …

NVD

CRITICAL
CVE-2026-64216
CVE-2026-64216
pkg: linux

published: Jul 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

netfs: Fix potential UAF in netfs_unlock_abandoned_read_pages()

netfs_unlock_abandoned_read_pages(rreq) accesses the index of the folios it
is wanting to unlock and compares that to rreq->no_unlock_folio so that it
doesn't unlock …

GitHub-GHSA

CRITICAL
seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization
GHSA-mv8w-475r-vwqw
pkg: seroval
eco: npm
published: Jul 24, 2026
## Summary

A type confusion issue in `seroval.fromJSON()` allowed attacker-controlled JSON input to cause Promise control nodes to operate on values from the general deserialization reference table without first verifying that those values were genuine internal promise resolver records.

In applica…

CVE-2026-59940
NVD

CRITICAL
CVE-2026-15981
CVE-2026-15981
pkg: openssl

published: Jul 23, 2026

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.4. This is due to the mo_saml_validate_signature() function performing a loose boolean check on the raw tri-state integer returned by PHP's openssl_verify(), ca…
CWE: CWE-287
NVD

CRITICAL
CVE-2026-15015
CVE-2026-15015
pkg: oauth

published: Jul 23, 2026

The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to…
CWE: CWE-862
NVD

CRITICAL
CVE-2026-14282
CVE-2026-14282
pkg: go

published: Jul 23, 2026

The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 1.12.2. This is due to insufficient file type validation in the save_video_file() function hoo…
CWE: CWE-434
NVD

CRITICAL
CVE-2026-16606
CVE-2026-16606
pkg: linux

published: Jul 22, 2026

A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for unauthenticated remote code execution (pre-auth RCE) on GNU/Linux or Oracle Solaris. The Fsas Technologies PSIRT obtained that intelligence internally and covers the CVE b…
CWE: CWE-94
GitHub-GHSA

CRITICAL
Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER`
GHSA-f75j-4cw6-rmx4
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
# Summary

The Gitea Docker images ship an `app.ini` template that hard-codes:

“`
REVERSE_PROXY_TRUSTED_PROXIES = *
“`

The documented default for this setting, in `custom/conf/app.example.ini`, is `127.0.0.0/8,::1/128`, i.e. only loopback is trusted.

When an admin enables `ENABLE_REVERSE_PROXY_…

CVE-2026-20896
NVD

CRITICAL
CVE-2026-59147
CVE-2026-59147
pkg: node

published: Jul 21, 2026

Data::DisjointSet::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via an unvalidated parent index in dsu_find.

The attach-time validator dsu_validate_header checks the header scalars and region layout against the file size, but does not validate the array contents it then…

CWE: CWE-125, CWE-787
NVD

CRITICAL
CVE-2026-47410
CVE-2026-47410
pkg: jwt

published: Jul 21, 2026

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an insecure default cryptographic key. The JWT signing secret defaults to the hardcoded literal `"dev-secret-change-me"` when `PLATFORM_JWT_SECRET` is unset. A safety check exists but on…
CWE: CWE-321, CWE-798
NVD

CRITICAL
CVE-2026-47391
CVE-2026-47391
pkg: python

published: Jul 21, 2026

PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's first-party A2A server example exposes an unauthenticated A2A JSON-RPC endpoint and registers a `calculate(expression)` tool implemented with Python `eval()`. The example also binds to `0.0.0.0`. A remote unauthenticated a…
CWE: CWE-95, CWE-306
GitHub-GHSA

CRITICAL
OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check
GHSA-p279-2cqp-84jg
pkg: org.openidentityplatform.opendj:opendj-server-legacy
eco: maven
published: Jul 24, 2026
### Summary
When a SASL PLAIN bind supplies an authorization identity (authzid) that resolves to a **different** user, PlainSASLMechanismHandler verified only the PROXIED_AUTH privilege and never evaluated the "proxy" access-control right (the mayProxy ACI scope check). As a result, any account hold…
GitHub-GHSA

CRITICAL
Budibase: SQL Injection via `multipleStatements: true`
GHSA-q6x4-v3qx-85qw
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
## Summary
A critical SQL injection vulnerability was discovered in Budibase's MySQL integration that allows remote attackers to execute arbitrary SQL commands.

## Details
### Vulnerability Type
SQL Injection

### Description
The MySQL integration component in Budibase is configured with `multipleS…

NVD

CRITICAL
CVE-2026-65606
CVE-2026-65606
pkg: node

published: Jul 23, 2026

SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler. When a siyuan://plugins/<name> link references a name that is not an installed plugin, the application opens a custom tab and inserts the link's icon parameter into the tab header via innerHTML with…
CWE: CWE-79
NVD

CRITICAL
CVE-2026-65605
CVE-2026-65605
pkg: node

published: Jul 23, 2026

SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell rendering. A Template column value is rendered as HTML via text/template without auto-escaping, and EscapeHTML is only applied when HasUnclosedHtmlTag returns true; because balanced self-closi…
CWE: CWE-79
NVD

CRITICAL
CVE-2026-16424
CVE-2026-16424
pkg: google chrome, google android

published: Jul 21, 2026

Use after free in GPU in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

CRITICAL
CVE-2026-16419
CVE-2026-16419
pkg: google chrome, google android

published: Jul 21, 2026

Out of bounds read and write in ANGLE in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-125, CWE-787
GitHub-GHSA

CRITICAL
Gitea: Public-only repository tokens can update private PR head branches
GHSA-xxjv-752h-3vp2
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary
Gitea allows a `public-only,write:repository` token to update a private pull request head branch through a public base repository route.

The vulnerable endpoint is:

“`text
POST /api/v1/repos/{public-owner}/{public-repo}/pulls/{index}/update
“`

Gitea checks the token's public-only re…

CVE-2026-58443
GitHub-GHSA

CRITICAL
Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write
GHSA-hg5r-vq93-9fv6
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary

Gitea Actions Artifacts V4 signed upload/download URLs can be rewritten to access a different running task and repository context while preserving the original HMAC signature. An attacker with permission to run a Gitea Actions job can turn a signed URL for an attacker-controlled artifac…

CVE-2026-58426
GitHub-GHSA

CRITICAL
Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter
GHSA-2r5c-gw76-rh3w
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
## Summary

Gitea's default SSRF allow-list ([`MatchBuiltinExternal`](https://github.com/go-gitea/gitea/blob/4c37f4dacbac022f7beca75272439331f0368830/modules/hostmatcher/hostmatcher.go#L26-L27), used by both webhook delivery and repository migrations) relies on Go's standard library [`net.IP.IsPriva…

CVE-2026-22874
NVD

CRITICAL
CVE-2026-15901
CVE-2026-15901
pkg: google chrome

published: Jul 20, 2026

Use after free in Network in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

CRITICAL
CVE-2026-15900
CVE-2026-15900
pkg: google chrome, google android

published: Jul 20, 2026

Use after free in GPU in Google Chrome on Android prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
NVD

CRITICAL
CVE-2026-15899
CVE-2026-15899
pkg: go

published: Jul 20, 2026

Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CWE: CWE-416
GitHub-GHSA

CRITICAL
OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway
GHSA-68r5-9hpg-7qw9
pkg: org.openidentityplatform.opendj:opendj-dsml-servlet
eco: maven
published: Jul 24, 2026
The DSMLv2 SOAP gateway (opendj-dsml-servlet) in OpenIdentityPlatform OpenDJ through 5.1.1 dereferences attacker-supplied xsd:anyURI values server-side without a scheme allowlist, egress filtering, or a size cap, and is reachable without authentication by default. A remote unauthenticated attacker c…
GitHub-GHSA

CRITICAL
LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests
GHSA-6x6h-qqr7-855w
pkg: lightrag-hku
eco: pip
published: Jul 20, 2026
### Summary
The server defaults to CORS_ORIGINS=* combined with allow_credentials=True. Starlette's CORSMiddleware echoes the requesting origin in preflight responses when credentials are enabled, meaning every origin is effectively whitelisted for credentialed cross-origin requests. Any malicious w…
CVE-2026-61736
GitHub-GHSA

CRITICAL
sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock
GHSA-vh45-f885-3848
pkg: sm-crypto
eco: npm
published: Jul 24, 2026
## Summary

`sm-crypto` (npm package **0.4.0**, the latest release, published 2026-01-20)
generates SM2 private keys and signing ephemeral scalars from a single
module-wide RNG instance (`src/sm2/utils.js`: `const rng = new SecureRandom()`).
`SecureRandom` is jsbn's PRNG, which seeds an **ARC4** str…

NVD

CRITICAL
CVE-2026-48021
CVE-2026-48021
pkg: tls

published: Jul 24, 2026

In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU handshake with attacker-controlled keys and obtain the session encryption keys. All inner HTTP traffic (patient consent decisions, medication data, docum…
CWE: CWE-295, CWE-347
GitHub-GHSA

CRITICAL
kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default
GHSA-r277-6w6q-xmqw
pkg: github.com/getkin/kin-openapi
eco: go
published: Jul 24, 2026
### Summary
`ValidationHandler.Load()` in `getkin/kin-openapi` silently replaces a nil `AuthenticationFunc` with `NoopAuthenticationFunc`, which always returns `nil` without performing any credential check. Because this substitution happens unconditionally when the caller omits the field, every Open…
NVD

CRITICAL
CVE-2026-60267
CVE-2026-60267
pkg: tls

published: Jul 21, 2026

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle…
CWE: CWE-284
NVD

CRITICAL
CVE-2026-47731
CVE-2026-47731
pkg: python

published: Jul 21, 2026

The AMMOS Instrument Toolkit (Formerly the Bespoke Links to Instruments for Surface and Space (BLISS)) is a Python-based software suite developed to handle Ground Data System (GDS), Electronic Ground Support Equipment (EGSE), commanding, telemetry uplink/downlink, and sequencing for instrument and C…
CWE: CWE-22
NVD

CRITICAL
CVE-2026-59141
CVE-2026-59141
pkg: node

published: Jul 21, 2026

Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated node and arena indices in rdx_find_locked.

The attach-time validator rdx_validate_header checks the header scalars and region layout against the file size, but does not validate the node records it the…

CWE: CWE-125
NVD

CRITICAL
CVE-2026-59140
CVE-2026-59140
pkg: node

published: Jul 21, 2026

Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds read via unvalidated node indices in the rank and min/max query paths.

The attach-time validator ss_validate_header bounds only the root index against the node pool (node_capacity). The order-statistics and min/max queries…

CWE: CWE-125
NVD

CRITICAL
CVE-2026-28321
CVE-2026-28321
pkg: solarwinds serv-u

published: Jul 21, 2026

SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate privileges and execute code as root. A domain administrator access is required, and the impact is lower in Windows installations.
CWE: CWE-284
NVD

CRITICAL
CVE-2026-28317
CVE-2026-28317
pkg: solarwinds serv-u

published: Jul 21, 2026

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires domain administrator access. The impact is lower in Windows deployments.
CWE: CWE-639
NVD

CRITICAL
CVE-2026-28316
CVE-2026-28316
pkg: solarwinds serv-u

published: Jul 21, 2026

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability to execute commands as the root user. This issue requires a domain account with administrator access. The impact is lower in Wind…
CWE: CWE-639
NVD

CRITICAL
CVE-2026-28314
CVE-2026-28314
pkg: solarwinds serv-u

published: Jul 21, 2026

SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. User authentication is required. The impact is lower in Windows deployments.
CWE: CWE-639
NVD

CRITICAL
CVE-2026-28313
CVE-2026-28313
pkg: solarwinds serv-u

published: Jul 21, 2026

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary account takeover. The impact is lower in Windows deployments.
CWE: CWE-639
NVD

CRITICAL
CVE-2026-28312
CVE-2026-28312
pkg: solarwinds serv-u

published: Jul 21, 2026

SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system administrator and allow code execution as root. The impact is lower in Windows deployments.
CWE: CWE-285
NVD

CRITICAL
CVE-2026-28310
CVE-2026-28310
pkg: solarwinds serv-u

published: Jul 21, 2026

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate their user type to that of a system administrator. The impact is lower in Windows deployments.
CWE: CWE-862
NVD

CRITICAL
CVE-2026-28309
CVE-2026-28309
pkg: solarwinds serv-u

published: Jul 21, 2026

SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts. The impact is lower in Windows deployments.
CWE: CWE-862
NVD

CRITICAL
CVE-2026-28308
CVE-2026-28308
pkg: solarwinds serv-u

published: Jul 21, 2026

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrator access is required. The impact is lower in Windows deployments.
CWE: CWE-639
NVD

CRITICAL
CVE-2026-28307
CVE-2026-28307
pkg: solarwinds serv-u

published: Jul 21, 2026

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an administrator group. The impact is lower in Windows deployments.
CWE: CWE-284
NVD

CRITICAL
CVE-2026-28306
CVE-2026-28306
pkg: solarwinds serv-u

published: Jul 21, 2026

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a system administrator. The impact is lower in Windows deployments.
CWE: CWE-284
NVD

CRITICAL
CVE-2026-28305
CVE-2026-28305
pkg: solarwinds serv-u

published: Jul 21, 2026

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution as root. A domain account with admin privileges and read and write access to the home directory is required. The impact is lower in Windows deployments.
CWE: CWE-639
NVD

CRITICAL
CVE-2026-28304
CVE-2026-28304
pkg: solarwinds serv-u

published: Jul 21, 2026

SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary execution of code remotely as root. The impact is lower in Windows deployments.
CWE: CWE-284
NVD

CRITICAL
CVE-2026-28302
CVE-2026-28302
pkg: solarwinds serv-u

published: Jul 21, 2026

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root. This issue requires group administrator access. The impact is lower in Windows deployments.
CWE: CWE-639
GitHub-GHSA

CRITICAL
Shescape: Shell injection via unescaped parentheses on Windows with CMD
GHSA-w4hw-qcx7-56pr
pkg: shescape, shescape
eco: npm
published: Jul 24, 2026
### Impact

This impacts users of Shescape on Windows that explicitly configure `shell` to CMD, or `true` with the default shell being CMD, using the `escape` and `escapeAll` APIs.

An attacker may be able to achieve shell injection depending on the original command.

“`javascript
import * as cp fr…

GitHub-GHSA

CRITICAL
Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak
GHSA-mqhr-6j6h-74p5
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
## Summary
Budibase attaches a REST datasource's stored credentials (Bearer/Basic tokens and static headers) to an outgoing request before it decides which host the request goes to, and never checks that the destination host matches the datasource. A query's request path can be pointed at any host (…
GitHub-GHSA

CRITICAL
Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified
GHSA-hp6v-6jw7-gv2f
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
### Summary
Budibase's OIDC SSO login links an incoming SSO identity to an existing Budibase account **by email address alone**, without ever checking the `email_verified` claim of the OIDC ID token. Budibase first tries to match the IdP `sub`; when that misses (any fresh attacker IdP account) it si…
GitHub-GHSA

CRITICAL
OpenAM: WebAuthn Java deserialization RCE via ObjectInputFilter depth>1 bypass
GHSA-gf8h-gq53-288j
pkg: org.openidentityplatform.openam:openam-auth-webauthn
eco: maven
published: Jul 24, 2026
### Summary
The GHSA-6c99-87fr-6q7r fix wrapped WebAuthn authenticator deserialization in an `ObjectInputFilter` meant to allow only `AuthenticatorImpl`, but it short-circuits to `ALLOWED` for any object at stream `depth > 1`. Because the Java serialization filter is consulted for every class in the…
CVE-2026-62263
GitHub-GHSA

CRITICAL
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
GHSA-hq9q-27g5-qwpj
pkg: Microsoft.OpenApi.Kiota, Microsoft.OpenApi.Kiota.Builder
eco: nuget
published: Jul 24, 2026
### Summary

`kiota info` — the command developers run to learn which packages to install after generating a client —
read the `x-ms-kiota-info` extension from the OpenAPI description and presented the spec-supplied
`dependencyInstallCommand` (and dependency `name`/`version`) **as the tool's own…

CVE-2026-59865
GitHub-GHSA

CRITICAL
Microsoft Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions
GHSA-4jwf-m4wg-8p66
pkg: Microsoft.OpenApi.Kiota, Microsoft.OpenApi.Kiota.Builder
eco: nuget
published: Jul 24, 2026
### Summary

`kiota plugin add` / `kiota plugin generate` (with `-t APIPlugin`) emits an attacker-controlled `static_template.file` path from the AI-plugin extensions (`x-ai-adaptive-card`, `x-ai-capabilities`) **verbatim**, with no path validation, into the generated Microsoft 365 Copilot / Teams p…

CVE-2026-59864
GitHub-GHSA

CRITICAL
Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)
GHSA-8fpg-xm3f-6cx3
pkg: next-auth
eco: npm
published: Jul 23, 2026
### Impact

`next-auth` (Auth.js) v5 applications that gate access by checking only for the **existence** of the `auth` object — the pattern shown in the official [session management / protecting resources guide](https://authjs.dev/getting-started/session-management/protecting) — are affected.

GitHub-GHSA

CRITICAL
Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
GHSA-7rqj-j65f-68wh
pkg: @auth/core, next-auth, next-auth
eco: npm
published: Jul 23, 2026
## Summary

The default email-address normalizer used by the email/magic-link sign-in flow validates the address **before** applying Unicode normalization. An address can contain a Unicode character that is not an ASCII `@` (U+0040) but canonicalizes to one under NFKC/NFKD normalization (the normali…

GitHub-GHSA

CRITICAL
Gitea Remember-Me Token Theft Not Invalidating Attacker Session
GHSA-rgv6-xp99-6mgj
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
The vulnerability is in the Remember-Me (gitea_incredible) token validation logic, specifically when handling a compromised token (hash mismatch).

The vulnerable function is this one:

https://github.com/go-gitea/gitea/blob/689ace1ce28fd74244b8aa335d9928cdbf6b22f9/services/auth/auth_token.go#L33-L6…

CVE-2026-56750
GitHub-GHSA

CRITICAL
LightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection
GHSA-f4vv-55c2-5789
pkg: lightrag-hku
eco: pip
published: Jul 20, 2026
## Summary

When LightRAG is deployed with `LIGHTRAG_API_KEY` set but `AUTH_ACCOUNTS` unset (an officially documented "API-Key authentication" mode), the `X-API-Key` protection can be bypassed by any remote unauthenticated attacker. The bypass does not require network contact with the victim server …

CVE-2026-61740
NVD

HIGH
CVE-2024-58355
CVE-2024-58355
pkg: react

published: Jul 23, 2026

Cal.com (calcom/cal.diy) versions through 4.7.15 contain a stored cross-site scripting vulnerability. The single booking view (e.g., https://app.cal.com/booking/<id>) renders booking-question field labels via React's dangerouslySetInnerHTML without sanitizing or escaping user input. An attacker who …
CWE: CWE-80
NVD

HIGH
CVE-2024-58353
CVE-2024-58353
pkg: react

published: Jul 23, 2026

Cal.com (repository calcom/cal.diy) in versions <= 4.7.15 is vulnerable to cross-site scripting (XSS) on the publicly accessible single booking view (e.g., /booking/<id>). Booking question (form field) labels are rendered via React's dangerouslySetInnerHTML without proper input sanitization or CSP, …
CWE: CWE-80
GitHub-GHSA

HIGH
Gitea: Permanent Fork PR Workflow Approval Gate Bypass
GHSA-777r-4v59-6486
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
| Field | Value |
|——-|——-|
| **Identifier (researcher-assigned)** | GITEA-2026-004 |
| **Product** | Gitea (self-hosted Git service) |
| **Component** | Gitea Actions — fork pull request approval gate |
| **Affected versions** | All Gitea releases **`v1.20.0` and later**, including the la…
CVE-2026-58424
NVD

HIGH
CVE-2026-64467
CVE-2026-64467
pkg: node

published: Jul 25, 2026

In the Linux kernel, the following vulnerability has been resolved:

rust_binder: use a u64 stride when cleaning up the offsets array

Allocation's Drop walks the offsets array (binder_size_t = u64 entries),
cleaning up the objects, but it used usize instead of u64 for both the
stride and the per-en…

NVD

HIGH
CVE-2026-64394
CVE-2026-64394
pkg: windows

published: Jul 25, 2026

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: add a WRITE_DAC/WRITE_OWNER check to SMB2 SET_INFO SECURITY

commit cc57232cae23 ("ksmbd: fix FSCTL permission bypass by adding a
permission check for FSCTL_SET_SPARSE") added a fp->daccess gate to
fsctl_set_sparse and noted…

GitHub-GHSA

HIGH
Budibase: Privilege escalation via public role assignment API missing app-level authorization
GHSA-j9fc-w3mr-x6mv
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
### Summary

Budibase `3.39.19` (commit `03fbabae4`) is affected by a privilege-escalation / missing-authorization flaw in the public role-assignment API. An **app-scoped builder** (a user who builds only specific apps — `user.builder.apps = [appA]`, not a global builder or admin) can grant **them…

GitHub-GHSA

HIGH
GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution
GHSA-r9mr-m37c-5fr3
pkg: GitPython
eco: pip
published: Jul 24, 2026
## Summary
GitPython's `check_unsafe_options` guard (the control introduced by CVE-2026-42215 / GHSA-2f96 and hardened since) can be bypassed for **every** guarded method (`clone`/`clone_from`, `fetch`/`pull`/`push`, `ls_remote`, `iter_commits`, `blame`, `archive`) by smuggling an option token insid…
GitHub-GHSA

HIGH
Ray: Arbitrary code execution via ray.data.read_webdataset default decoder: pickle.loads(value) and torch.load(weights_only=False)
GHSA-hhrp-gw25-jr43
pkg: ray
eco: pip
published: Jul 24, 2026
## Summary

`ray.data.read_webdataset(paths=…)` is a `@PublicAPI(stability="alpha")`
reader for WebDataset-format TAR files. Its default `decoder=True` invokes
`_default_decoder` on every sample's keys, which routes file extension to a
decoder by extension. Two of those branches deserialize attack…

CVE-2026-57516
NVD

HIGH
CVE-2026-16745
CVE-2026-16745
pkg: kubernetes

published: Jul 23, 2026

A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized…
CWE: CWE-346
NVD

HIGH
CVE-2025-44089
CVE-2025-44089
pkg: express

published: Jul 22, 2026

An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.
CWE: CWE-693
NVD

HIGH
CVE-2026-16423
CVE-2026-16423
pkg: google chrome

published: Jul 21, 2026

Use after free in UI in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-16421
CVE-2026-16421
pkg: google chrome

published: Jul 21, 2026

Inappropriate implementation in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-20
NVD

HIGH
CVE-2026-16420
CVE-2026-16420
pkg: google chrome

published: Jul 21, 2026

Type Confusion in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-843
NVD

HIGH
CVE-2026-16418
CVE-2026-16418
pkg: google chrome

published: Jul 21, 2026

Stack buffer overflow in V8 in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-121
NVD

HIGH
CVE-2026-60400
CVE-2026-60400
pkg: go

published: Jul 21, 2026

Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle GoldenGate. Succe…
CWE: CWE-284
NVD

HIGH
CVE-2026-60398
CVE-2026-60398
pkg: go

published: Jul 21, 2026

Vulnerability in Oracle GoldenGate (component: Oracle GoldenGate Microservices). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle GoldenGate.…
CWE: CWE-306
NVD

HIGH
CVE-2026-60157
CVE-2026-60157
pkg: go

published: Jul 21, 2026

Vulnerability in Oracle GoldenGate (component: Service Manager). Supported versions that are affected are 19.1.0.0.0-19.29.0.0, 21.3-21.21 and 23.4-23.26.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle GoldenGate. Successful…
CWE: CWE-284
GitHub-GHSA

HIGH
Gitea: Cached Per-Branch Permission Check in Pre-Receive Hook Allows Full Repository Write
GHSA-649p-mmhf-85c7
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
## Vulnerability Header

| Field | Value |
| ——————- | ———————————————————————————– |
| Vulnerability Title | Cached Per-Branch Permission Ch…

CVE-2026-27775
GitHub-GHSA

HIGH
GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
GHSA-2f96-g7mh-g2hx
pkg: GitPython
eco: pip
published: Jul 21, 2026
## Command injection via long-option prefix abbreviation bypassing `check_unsafe_options` (incomplete fix of CVE-2026-42215 / GHSA-rpm5-65cw-6hj4)

**Component:** gitpython-developers/GitPython (PyPI: GitPython)
**Affected:** all versions carrying the 3.1.47 blocklist fix, through current `main` (ve…

NVD

HIGH
CVE-2026-55084
CVE-2026-55084
pkg: express

published: Jul 21, 2026

DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. A SQL injection vulnerability was identified in the SqlView API endpoint of the DHIS2 application in the `filter` parameter used by the
`/api/sqlViews/{viewId}/data.json` endpoint. An authen…
CWE: CWE-89
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-47300 – .NET Elevation of Privilege Vulnerability
GHSA-8prm-248r-h957
pkg: Microsoft.AspNetCore.Authentication.Negotiate, Microsoft.AspNetCore.Authentication.Negotiate, Microsoft.AspNetCore.Authentication.Negotiate
eco: nuget
published: Jul 21, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core Negotiate Authentication (Microsoft.AspNetCore.Authentication.Negotiate). This advisory also provides guidance on what developers can do to update their applications to re…

CVE-2026-47300
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-47303 – .NET Elevation of Privilege Vulnerability
GHSA-2p3q-h3hg-jcqq
pkg: Microsoft.AspNetCore.Authentication.Negotiate, Microsoft.AspNetCore.Authentication.Negotiate, Microsoft.AspNetCore.Authentication.Negotiate
eco: nuget
published: Jul 21, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core Negotiate Authentication (Microsoft.AspNetCore.Authentication.Negotiate). This advisory also provides guidance on what developers can do to update their applications to re…

CVE-2026-47303
NVD

HIGH
CVE-2026-15904
CVE-2026-15904
pkg: google chrome, linux linux_kernel

published: Jul 20, 2026

Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.128 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-15903
CVE-2026-15903
pkg: google chrome

published: Jul 20, 2026

Out of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-125, CWE-787, CWE-125, CWE-787
NVD

HIGH
CVE-2026-15902
CVE-2026-15902
pkg: google chrome

published: Jul 20, 2026

Use after free in Cast in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-12341
CVE-2026-12341
pkg: oauth

published: Jul 20, 2026

This vulnerability
impacts all versions of IdentityIQ and allows an unauthenticated attacker
unauthorized access to protected APIs and data due to improper validation of
OAuth bearer tokens.
CWE: CWE-287
NVD

HIGH
CVE-2026-64206
CVE-2026-64206
pkg: linux

published: Jul 20, 2026

In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock

l2cap_conn_del() takes conn->lock and then calls cancel_work_sync() for
pending_rx_work. process_pending_rx() takes the same mutex, so teardown
can deadlock agains…

NVD

HIGH
CVE-2026-25039
CVE-2026-25039
pkg: windows

published: Jul 20, 2026

Parsec is a cloud-based application for simple and cryptographically secure file sharing. The application does not sanitize the workspace name, creating a vulnerability if that workspace name is a UNC path. When creating mountpoint in the windows filesystem to mount the workspace of an organization,…
CWE: CWE-40
NVD

HIGH
CVE-2026-65908
CVE-2026-65908
pkg: python

published: Jul 23, 2026

In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open
CWE: CWE-829
GitHub-GHSA

HIGH
Budibase: SSRF via DNS rebinding in the REST datasource integration
GHSA-v42f-v8xc-j435
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
### Summary
Budibase's central outbound-fetch guard (`fetchWithBlacklist`) prevents SSRF/DNS-rebinding by resolving the target hostname, checking every resolved IP against the blacklist, and **pinning** the connection to the validated IP. The pin is implemented as a Node `http(s).Agent` (`makePinned…
GitHub-GHSA

HIGH
Budibase: DNS rebinding SSRF bypasses remain in OpenAPI import and REST query execution
GHSA-xg5g-26×8-cvf4
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
## Impact

A builder-level user can make Budibase issue server-side HTTP requests to loopback or private-network targets by using DNS rebinding against two outbound fetch paths that are still not pinned to the validated DNS answer.

The first path is OpenAPI query import. It validates the supplied h…

NVD

HIGH
CVE-2026-17107
CVE-2026-17107
pkg: kubernetes

published: Jul 24, 2026

A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first removing caller-supplied values, and the spoke Servi…
CWE: CWE-441
GitHub-GHSA

HIGH
Gitea: Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration
GHSA-82f7-87hm-852x
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
# Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration

## Summary

Gitea validates the user-supplied repository migration URL, but the actual clone and later mirror fetch operations are performed by the Git command-line clie…

CVE-2026-57894
NVD

HIGH
CVE-2026-64806
CVE-2026-64806
pkg: node

published: Jul 23, 2026

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter
CWE: CWE-829
GitHub-GHSA

HIGH
GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`
GHSA-956x-8gvw-wg5v
pkg: GitPython
eco: pip
published: Jul 21, 2026
## Summary

GitPython spawns the real `git` binary with an argument vector built from caller-supplied values. To prevent argument injection, GitPython maintains denylists of "unsafe" Git options (`–upload-pack`, `–receive-pack`, `–exec`, `-c`, `–config`, …) that can be abused to run arbitrary …

NVD

HIGH
CVE-2026-64824
CVE-2026-64824
pkg: docker

published: Jul 21, 2026

Home Assistant Core before 2026.7.0 contains a path traversal vulnerability in the backup-restore function that allows attackers to write files to arbitrary absolute filesystem paths by supplying a crafted tar archive with a SYMTYPE entry containing a benign member name paired with an absolute linkn…
CWE: CWE-22
NVD

HIGH
CVE-2026-28220
CVE-2026-28220
pkg: node

published: Jul 20, 2026

Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.14.5, issues in the Cluster Distributed API (DAPI) handling allow a cluster peer, or any actor able to authenticate to the cluster channel using the shared cluster key, to make the master…
CWE: CWE-502
NVD

HIGH
CVE-2026-17497
CVE-2026-17497
pkg: python

published: Jul 26, 2026

NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore invoke plugin:shell|execute to run attacker-controlled operating …
CWE: CWE-78, CWE-276, CWE-1249
GitHub-GHSA

HIGH
Budibase: NoSQL Injection via JSON Parameter Interpolation in MongoDB Query Execution
GHSA-qw6m-8fw2-2v64
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
## Summary

Budibase's MongoDB query execution endpoint (`POST /api/v2/queries/:queryId`) is vulnerable to NoSQL injection through user-supplied query parameters. The `enrichContext()` function interpolates parameter values into JSON query templates using Handlebars with `noEscaping: true`, then par…

GitHub-GHSA

HIGH
Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in
GHSA-qq9h-g4jm-xgf3
pkg: better-auth, better-auth
eco: npm
published: Jul 24, 2026
### Am I affected

You are affected if all of the following hold:

– You run a `better-auth` version below 1.6.22, or a `1.7.0-beta` below `1.7.0-beta.10`.
– You enable the magic-link plugin or the email-OTP plugin.
– You also enable email and password sign-up with open registration.
– An account ca…

NVD

HIGH
CVE-2026-16416
CVE-2026-16416
pkg: google chrome

published: Jul 21, 2026

Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High)
CWE: CWE-190
NVD

HIGH
CVE-2026-16413
CVE-2026-16413
pkg: google chrome

published: Jul 21, 2026

Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-787
NVD

HIGH
CVE-2026-47688
CVE-2026-47688
pkg: node

published: Jul 21, 2026

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `clearAES` and `clearPMTasks` methods in `FOGPage` can be invoked by an unauthenticated attacker via a single HTTP GET request through the public `client` node e…
CWE: CWE-862
GitHub-GHSA

HIGH
Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`
GHSA-xj96-63gp-2gmr
pkg: Pillow
eco: pip
published: Jul 20, 2026
### Summary

Pillow's public rank-filter API can trigger a native heap out-of-bounds write
when given a very large odd filter size.

Minimal public API trigger:

“`python
from PIL import Image, ImageFilter

im = Image.new("L", (3, 3), 128)
im.filter(ImageFilter.MedianFilter(4294967295))
“`

`Image…

CVE-2026-59197
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-50528 – .NET Security Feature Bypass Vulnerability
GHSA-qvw7-jm5c-6hqw
pkg: Microsoft.NetCore.App.Runtime.linux-arm, Microsoft.NetCore.App.Runtime.linux-arm64, Microsoft.NetCore.App.Runtime.linux-musl-arm
eco: nuget
published: Jul 20, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET TLS/SSL (System.Net.Security). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A security feature bypass…

CVE-2026-50528
NVD

HIGH
CVE-2026-47255
CVE-2026-47255
pkg: tls

published: Jul 20, 2026

AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0.9.10 had weakness related to validation and and binding of inactive-agent hour filtering; storage SQL identifier validation; metadata-backed ownership…
CWE: CWE-20, CWE-89, CWE-284, CWE-319, CWE-798
GitHub-GHSA

HIGH
File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup
GHSA-fmm7-x4gx-8jhr
pkg: github.com/filebrowser/filebrowser/v2
eco: go
published: Jul 20, 2026
## Summary

A scoped, non-admin File Browser user holding only the **Create** permission can delete arbitrary files outside their scope (other tenants' data, and the application's own database) via the upload failure-cleanup path. This is an incomplete fix of CVE-2026-54094: the v2.63.14 `ScopedFs` …

CVE-2026-55667
NVD

HIGH
CVE-2026-54342
CVE-2026-54342
pkg: tls

published: Jul 24, 2026

In epa4all, prior to version 2026-05-20, an attacker on the network path between epa4all and any backend (ePA Aktensystem, Konnektor, IDP, TSS) can present a self-signed TLS certificate and intercept the connection. For non-VAU connections (Konnektor, IDP), this allows direct read and modification o…
CWE: CWE-295
GitHub-GHSA

HIGH
GitPython: Arbitrary file overwrite via git diff –output argument injection in Diffable.diff (key- and value-controlled)
GHSA-fjr4-x663-mwxc
pkg: GitPython
eco: pip
published: Jul 24, 2026
## Summary
`Diffable.diff()` forwards `**kwargs` straight into `diff`/`diff_tree` with **no** `check_unsafe_options` guard. `Diffable` is mixed into `Commit`, `Tree`, `IndexFile`, and `Submodule`, giving a broad surface. `git diff –output=<path>` writes real patch content to an attacker-chosen path…
NVD

HIGH
CVE-2026-64235
CVE-2026-64235
pkg: linux

published: Jul 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

x86/ftrace: Relocate %rip-relative percpu refs in dynamic trampolines

With CONFIG_CALL_DEPTH_TRACKING enabled on an x86 retbleed-affected platform
(eg: Skylake), with retbleed=stuff, registering a dynamic ftrace trampoline
crashes…

NVD

HIGH
CVE-2026-64223
CVE-2026-64223
pkg: linux

published: Jul 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

wifi: mac80211: consume only present negotiated TTLM maps

ieee80211_tid_to_link_map_size_ok() validates negotiated TTLM elements
against the number of link-map entries indicated by link_map_presence.
ieee80211_parse_neg_ttlm() mus…

NVD

HIGH
CVE-2026-61106
CVE-2026-61106
pkg: go

published: Jul 21, 2026

Vulnerability in Oracle GoldenGate (component: Config Service Executable). Supported versions that are affected are 23.4-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GoldenGate. Successful attacks of this vulnerabilit…
CWE: CWE-284, CWE-306
GitHub-GHSA

HIGH
Gitea: OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)
GHSA-vrhc-jjfc-m3m3
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
## Description

Gitea's OAuth2 sign-in callback reactivates a deactivated user account (`IsActive=false`) when the user signs in through an authentication source that does not issue refresh tokens (notably GitHub, and any OIDC/OAuth2 source configured without `offline_access`). PR #38009 added a gat…

CVE-2026-55987
GitHub-GHSA

HIGH
Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
GHSA-w5pg-649r-p6gg
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
## Summary

Gitea does not re-evaluate the `official` flag on existing pull request reviews when a PR's target branch is changed. An attacker with write access to a repository can obtain an `official: true` approval on a PR targeting an unprotected branch, then retarget the PR to a protected branch …

CVE-2026-58439
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-47304 – .NET Security Feature Bypass Vulnerability
GHSA-g8r8-53c2-pm3f
pkg: System.Security.Cryptography.Xml, System.Security.Cryptography.Xml, System.Security.Cryptography.Xml
eco: nuget
published: Jul 20, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET XML Encryption (System.Security.Cryptography.Xml). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A sec…

CVE-2026-47304
GitHub-GHSA

HIGH
File Browser: Colliding username normalization gives two users the same home directory
GHSA-7rc3-g7h6-22m7
pkg: github.com/filebrowser/filebrowser/v2
eco: go
published: Jul 20, 2026
## Summary

FileBrowser confines each user to a *scope*: a home directory that acts as the boundary for everything they can read or write. When self-registration and automatic home-directory creation are both enabled (`Signup=true` and `CreateUserDir=true`), a new user's scope is built from their us…

CVE-2026-62685
GitHub-GHSA

HIGH
Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)
GHSA-j657-m4c4-24jq
pkg: open-webui
eco: pip
published: Jul 24, 2026
## Summary

The terminal proxy in `backend/open_webui/routers/terminals.py` forwards the Open WebUI user's identity to the upstream terminal server / backend coordinator as an authorization claim, with no cryptographic binding to the session that produced it. The forwarded identity is attacker-influ…

CVE-2026-59224
NVD

HIGH
CVE-2026-61224
CVE-2026-61224
pkg: tls

published: Jul 21, 2026

Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Security). The supported version that is affected is 8.3. Difficult to exploit vulnerability allows high privileged attacker with network access via TLS to compromise Oracle Communi…
CWE: CWE-284
NVD

HIGH
CVE-2026-47237
CVE-2026-47237
pkg: kubernetes

published: Jul 21, 2026

Kubeflow Community Distribution helps users to install Kubeflow Platform in popular Kubernetes clusters. Prior to version 26.03-rc.1, a Kubeflow setup based on the official manifests or most other packaged Kubeflow distributions is vulnerable to authorization token stealing from any user of the Kube…
CWE: CWE-266
NVD

HIGH
CVE-2026-64418
CVE-2026-64418
pkg: node

published: Jul 25, 2026

In the Linux kernel, the following vulnerability has been resolved:

mm: shrinker: fix shrinker_info teardown race with expansion

expand_shrinker_info() iterates all visible memcgs under shrinker_mutex,
including memcgs that have not finished ->css_online() yet.

Once pn->shrinker_info has been pub…

NVD

HIGH
CVE-2026-64361
CVE-2026-64361
pkg: node

published: Jul 25, 2026

In the Linux kernel, the following vulnerability has been resolved:

hfs/hfsplus: fix u32 overflow in check_and_correct_requested_length

check_and_correct_requested_length() compares (off + len) against
node_size using u32 arithmetic. When the caller passes a large len
value (e.g. from an underflo…

NVD

HIGH
CVE-2026-64293
CVE-2026-64293
pkg: express

published: Jul 25, 2026

In the Linux kernel, the following vulnerability has been resolved:

iommufd: Use sizeof(*hdr) instead of sizeof(hdr) in veventq read

The bound-check in iommufd_veventq_fops_read() for the normal vEVENT
path uses sizeof(hdr) where the surrounding code uses sizeof(*hdr):

if (!vevent_for_lost_event…

NVD

HIGH
CVE-2026-64277
CVE-2026-64277
pkg: node

published: Jul 25, 2026

In the Linux kernel, the following vulnerability has been resolved:

Input: synaptics-rmi4 – bound the F3A keymap to the GPIO count

rmi_f3a_initialize() takes the GPIO count from the device query register
(f3a->gpio_count = buf & RMI_F3A_GPIO_COUNT, range 0..127).
rmi_f3a_map_gpios() then allocates…

GitHub-GHSA

HIGH
Oh My Posh: Arbitrary command execution via template injection in the path segment
GHSA-6xj8-qv9j-xcjq
pkg: github.com/jandedobbeleer/oh-my-posh
eco: go
published: Jul 24, 2026
### Summary
Oh My Posh re-renders the resolved path string, which contains the raw folder names taken from the filesystem, through the Go `text/template` engine. That engine's function map exposes a `cmd` function that runs arbitrary OS commands. A directory whose name contains a Go template express…
NVD

HIGH
CVE-2025-71408
CVE-2025-71408
pkg: express

published: Jul 24, 2026

NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls command-line arguments to execute arbitrary Python code. When collocations.py is invoked directly, the __main__ block passes command-line…
CWE: CWE-95
NVD

HIGH
CVE-2026-64226
CVE-2026-64226
pkg: linux

published: Jul 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

sched_ext: Avoid UAF in scx_root_enable_workfn() init failure path

In scx_root_enable_workfn(), put_task_struct(p) is called before scx_error()
dereferences p->comm and p->pid. If the iterator's reference is the last
drop, the tas…

NVD

HIGH
CVE-2026-64221
CVE-2026-64221
pkg: linux

published: Jul 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

spi: ti-qspi: fix use-after-free after DMA setup failure

The driver falls back to PIO mode if DMA setup fails during probe.

Make sure to clear the DMA channel pointer also if buffer allocation
fails to avoid passing a pointer to …

NVD

HIGH
CVE-2026-64218
CVE-2026-64218
pkg: linux

published: Jul 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

batman-adv: bla: fix report_work leak on backbone_gw purge

batadv_bla_purge_backbone_gw() removes stale backbone gateway entries,
but fails to properly handle their associated report_work:

– If report_work is running, the purge m…

NVD

HIGH
CVE-2026-64217
CVE-2026-64217
pkg: linux

published: Jul 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

netfs: Fix overrun check in netfs_extract_user_iter()

Fix netfs_extract_user_iter() so that if iov_iter_extract_pages() overfills
pages[], then those pages don't get included in the iterator constructed at
the end of the function.…

GitHub-GHSA

HIGH
electron-updater: Uncontrolled search path elements within `AppImage` built by `app-builder-lib`
GHSA-7g7r-gx96-252g
pkg: app-builder-lib
eco: npm
published: Jul 24, 2026
### Summary

`AppImage` targets built by `app-builder-lib` could use an empty path component when setting the `LD_LIBRARY_PATH` environment variable at runtime. This causes the current working directory to be added to the dynamic linker search path, which may allow an attacker to execute arbitrary c…

CVE-2026-54672
NVD

HIGH
CVE-2026-64802
CVE-2026-64802
pkg: go

published: Jul 23, 2026

In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration
CWE: CWE-94
NVD

HIGH
CVE-2026-64600
CVE-2026-64600
pkg: linux

published: Jul 23, 2026

In the Linux kernel, the following vulnerability has been resolved:

xfs: resample the data fork mapping after cycling ILOCK

xfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode,
a data fork mapping, and a cow fork mapping. Unfortunately, these two
helpers cycle the ILOCK to grab …

NVD

HIGH
CVE-2026-16607
CVE-2026-16607
pkg: linux

published: Jul 22, 2026

A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for local privilege escalation to root of an already authenticated user on GNU/Linux or Oracle Solaris. The Fsas Technologies PSIRT obtained that intelligence internally and…
CWE: CWE-269
NVD

HIGH
CVE-2026-16414
CVE-2026-16414
pkg: google chrome

published: Jul 21, 2026

Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High)
CWE: CWE-20
NVD

HIGH
CVE-2026-60570
CVE-2026-60570
pkg: go

published: Jul 21, 2026

Vulnerability in Oracle GoldenGate (component: Libraries). Supported versions that are affected are 23.4-23.26.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle GoldenGate executes to compromise Oracle GoldenGate. Successful attacks of…
NVD

HIGH
CVE-2026-47054
CVE-2026-47054
pkg: windows

published: Jul 21, 2026

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle …
CWE: CWE-269
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-50650 – .NET Elevation of Privilege Vulnerability
GHSA-2969-4q4w-w5h3
pkg: Microsoft.WindowsDesktop.App.Runtime.win-x64, Microsoft.WindowsDesktop.App.Runtime.win-x86, Microsoft.WindowsDesktop.App.Runtime.win-arm64
eco: nuget
published: Jul 21, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in Windows Presentation Foundation (WPF). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

An elevation of privil…

CVE-2026-50650
NVD

HIGH
CVE-2026-15905
CVE-2026-15905
pkg: google chrome

published: Jul 20, 2026

Use after free in Aura in Google Chrome prior to 150.0.7871.128 allowed a local attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High)
CWE: CWE-416
NVD

HIGH
CVE-2026-64191
CVE-2026-64191
pkg: linux

published: Jul 20, 2026

In the Linux kernel, the following vulnerability has been resolved:

i2c: stub: Reject I2C block transfers with invalid length

The I2C_SMBUS_I2C_BLOCK_DATA case in stub_xfer() uses data->block[0]
as the transfer length. The existing check only clamps it to avoid
overrunning the chip->words[256] reg…

NVD

HIGH
CVE-2026-64189
CVE-2026-64189
pkg: linux

published: Jul 20, 2026

In the Linux kernel, the following vulnerability has been resolved:

netfilter: ipset: fix race between dump and ip_set_list resize

The release path of ip_set_dump_do() and ip_set_dump_done() read
inst->ip_set_list via ip_set_ref_netlink(), a plain rcu_dereference_raw()
of the array pointer. These …

NVD

HIGH
CVE-2026-64188
CVE-2026-64188
pkg: linux

published: Jul 20, 2026

In the Linux kernel, the following vulnerability has been resolved:

net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink()

rmnet_dellink() removes the endpoint from the hash table with
hlist_del_init_rcu() and then immediately frees it with kfree(). However,
RCU readers on the receiv…

GitHub-GHSA

HIGH
Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF)
GHSA-pvcr-8mvp-w8qr
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
### Summary

The Budibase AI chat-link handoff flow (`GET/POST /api/chat-links/:instance/:token/handoff`) binds an **external chat identity** (Slack/Discord/MS Teams/Telegram) to a **Budibase user account**. The confirmation endpoint is on a **public route** (no CSRF middleware, no auth-group gate) …

GitHub-GHSA

HIGH
Budibase: S3 presigned URL endpoint authorization regression in v3.39.4 allows BASIC users to obtain S3 PutObject presigned URLs
GHSA-xcx6-4f2g-hhgx
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
## Impact

In Budibase v3.39.4, a regression in the authorization level for the S3 attachment upload endpoint allows any BASIC app user to obtain S3 PutObject presigned URLs. The endpoint uses TABLE/WRITE permission level instead of the intended BUILDER level defined in v3.39.3. Additionally, the co…

GitHub-GHSA

HIGH
open-webui terminal proxy path traversal guard bypass via 9x encoded traversal
GHSA-frvj-c5qp-xj4w
pkg: open-webui
eco: pip
published: Jul 24, 2026
AI assistance was used to help inspect the code and prepare this report.

## Summary

The fix for GHSA-r2wg-2mcr-66rv is incomplete in v0.9.6 and current main. `backend/open_webui/routers/terminals.py` documents `_sanitize_proxy_path()` as decoding until stable, but the implementation stops after 8 …

CVE-2026-59221
GitHub-GHSA

HIGH
Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id
GHSA-74h3-cxq7-vc5q
pkg: open-webui
eco: pip
published: Jul 24, 2026
## Summary

An authenticated low-privilege user can execute arbitrary code-interpreter Python and tools inside **another** user's authenticated session. The Socket.IO event-caller (`get_event_call`) delivers `execute:python` / `execute:tool` events to a **client-supplied** `session_id` after only ch…

CVE-2026-59216
GitHub-GHSA

HIGH
Gitea: Two SSRF findings
GHSA-2fcr-jfvc-vgg2
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
| — | — |
| Versions tested | `gitea/gitea:1.26.2` (digest `sha256:7d13848af12645600a5f9d93ee2560daa9c6fa6b5b859b7bff3a5e1c0b661031`); `gitea/gitea:latest` resolves to the same digest at time of writing |
| Source review | `git checkout v1.26.2` (commit `2c749ce`) |
| Reproduction | `bash run_po…
CVE-2026-58314
GitHub-GHSA

HIGH
Gitea: LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories
GHSA-7wvc-rvp7-w99x
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary

A flaw in SSH LFS sub-verb handling allows any authenticated SSH user to obtain valid LFS credentials for any repository on the instance, including private repositories they have no access to. This enables unauthorized download of all LFS objects from any private repository.

### Detail…

CVE-2026-58423
NVD

HIGH
CVE-2026-46555
CVE-2026-46555
pkg: docker

published: Jul 20, 2026

WhatsApp MCP Server is a Model Context Protocol (MCP) server for WhatsApp, enabling Claude to read and send WhatsApp messages. Prior to version 0.2.1, the `whatsapp-bridge` HTTP API listens on `127.0.0.1:8080` without authentication and without Host header validation, and the `/api/send` endpoint ac…
CWE: CWE-22, CWE-306, CWE-346
NVD

HIGH
CVE-2026-54910
CVE-2026-54910
pkg: jwt

published: Jul 20, 2026

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.4.3-beta, the `subtitlesHandler` endpoint (`GET /api/media/subtitles`) accepts two user-controlled query parameters: `path` and `name`, both of which are used in filesystem operations without sanitization, creatin…
CWE: CWE-22, CWE-23
GitHub-GHSA

HIGH
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal
GHSA-95cv-r8x4-vh75
pkg: github.com/OpenListTeam/OpenList/v4
eco: go
published: Jul 24, 2026
### Summary

The `/api/fs/batch_rename` handler validates and authorizes only the requested source directory. It rejects path separators in `new_name`, but it does not validate `src_name`. The handler concatenates `src_dir` and attacker-controlled `src_name`, then passes the result to the filesystem…

GitHub-GHSA

HIGH
Budibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database Connector
GHSA-2xgg-r2wc-c5r2
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
### Summary
**This is a related but independently fixable vulnerability to GHSA-qqf5-x7mj-v43p
(PostgreSQL SQL injection), reported in the same original disclosure and
split per GitHub CNA guidance (rule 4.2.11) since it affects a separate
integration, has a distinct attack precondition, and require…
GitHub-GHSA

HIGH
Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim
GHSA-vgj4-345g-jcf8
pkg: github.com/cloudreve/Cloudreve/v4
eco: go
published: Jul 20, 2026
## Summary

Cloudreve's OAuth access tokens can bypass OAuth scope enforcement.

This does not appear to be the intended design. The documentation describes OAuth client permissions/scopes, the API
has an insufficient-scope error code, and the code comments say `RequiredScopes(…)` should ver…

CVE-2026-54560
NVD

HIGH
CVE-2026-63720
CVE-2026-63720
pkg: express

published: Jul 26, 2026

datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who control input schemas to achieve remote code execution by supplying a malicious customBasePath value containing embedded newlines and a dot-free Python expression. The crafted value is …
CWE: CWE-94
GitHub-GHSA

HIGH
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
GHSA-jvxp-qmx7-gjpx
pkg: aws-smithy-http-server
eco: rust
published: Jul 24, 2026
## Summary
Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. An issue exists where, under certain circumstances, allocation of resources without limits…
CVE-2026-16756
GitHub-GHSA

HIGH
libp2p: yamux connection DoS via oversized data frame
GHSA-hmj8-5xmh-5573
pkg: libp2p
eco: pip
published: Jul 24, 2026
### Summary
The yamux stream multiplexer in py-libp2p does not validate incoming DATA frame lengths against the receive window before reading the frame body. Any peer that completes a standard libp2p handshake can send a single 12-byte frame claiming a 4 GB body, causing the victim's yamux read loop…
GitHub-GHSA

HIGH
OmniFaces: Forged combined-resource IDs and related output/push boundaries
GHSA-fp43-vj7g-pg92
pkg: org.omnifaces:omnifaces, org.omnifaces:omnifaces, org.omnifaces:omnifaces
eco: maven
published: Jul 24, 2026
## 1. Forged combined-resource IDs
`CombinedResourceInfo` accepts a path-derived ID without an authenticity check,
inflates it without an output limit, converts it to attacker-selected resource
identifiers, and retains unique IDs in an unbounded static cache. In bounded
tests, 20,754 encoded bytes i…
GitHub-GHSA

HIGH
blaze: Unbounded WebSocket message aggregation in http4s-blaze-server
GHSA-7ppr-r889-mcf2
pkg: org.http4s:http4s-blaze-server_2.13, org.http4s:http4s-blaze-server_2.13, org.http4s:http4s-blaze-server_2.12
eco: maven
published: Jul 24, 2026
## Summary

`http4s-blaze-server` aggregates the fragments of an incoming WebSocket
message with no limit on total size or fragment count. A client that
completes a WebSocket handshake can send an unterminated fragmented
message and drive unbounded heap growth in the server JVM, resulting in
denial …

GitHub-GHSA

HIGH
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
GHSA-mh99-v99m-4gvg
pkg: brace-expansion
eco: npm
published: Jul 24, 2026
### Summary

`expand()` bounds the *number* of results it produces (the `max` option,
`100_000` by default) but not their *length*. By chaining many brace groups,
an attacker keeps the result count under `max` while making every result grow
with the number of groups. Building `max` long results — …

CVE-2026-14257
GitHub-GHSA

HIGH
@anephenix/hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion
GHSA-g5vv-q72c-7j78
pkg: @anephenix/hub
eco: npm
published: Jul 24, 2026
### Summary

`@anephenix/hub` starts a `setInterval` polling loop for every incoming WebSocket connection to request a client ID via RPC. If the remote client never replies — which requires no authentication or special configuration — the interval and the pending request object are never cleaned…

GitHub-GHSA

HIGH
GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)
GHSA-94p4-4cq8-9g67
pkg: GitPython
eco: pip
published: Jul 24, 2026
## Summary

The fix for [GHSA-rwj8-pgh3-r573](https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-rwj8-pgh3-r573) stopped `Repo.clone_from()` from running caller-supplied URLs through `os.path.expandvars()`, but it guarded only that one caller. `Remote.create()` — reached fr…

GitHub-GHSA

HIGH
Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint
GHSA-hr66-5mqr-8mpx
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
#### Summary
The Budibase Worker service exposes a public, unauthenticated API endpoint (`GET /api/global/users/tenant/:id`) that returns sensitive user information including `tenantId`, `userId`, `email`, and `ssoId`. The endpoint is registered in the `PUBLIC_ENDPOINTS` list with a `TODO` comment a…
GitHub-GHSA

HIGH
react-server-dom: Denial of Service in Server Functions
GHSA-wx67-qw84-cm4g
pkg: react-server-dom-webpack, react-server-dom-turbopack, react-server-dom-turbopack
eco: npm
published: Jul 24, 2026
### Impact

A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to out-of-memory exceptions or excessive CPU usage.

We recommend updating immediately.

The vulnerability exists in versions 19.0.0 through 19.0.…

CVE-2026-44907
GitHub-GHSA

HIGH
yt-dlp: Downstream command injection via improper sanitization of yt-dlp –write-link output
GHSA-6v4j-43gg-vj32
pkg: yt-dlp
eco: pip
published: Jul 24, 2026
### Summary
If the `–write-link`, `–write-url-link` or `–write-desktop-link` options are used with yt-dlp, it may produce output that can lead to downstream remote code execution. An attacker can craft a malicious metadata payload to achieve arbitrary command injection in the `.url` and `.desktop…
CVE-2026-55404
NVD

HIGH
CVE-2026-66033
CVE-2026-66033
pkg: express

published: Jul 24, 2026

libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AES-GCM ciphers during handshake. Attackers can exploit…
CWE: CWE-125, CWE-191
GitHub-GHSA

HIGH
Netty: Denial of Service in XmlFrameDecoder via CPU Exhaustion
GHSA-v74w-7mr3-4qg3
pkg: io.netty:netty-codec-xml, io.netty:netty-codec-xml
eco: maven
published: Jul 24, 2026
### Summary
An attacker can cause Denial of Service by sending a specially crafted malicious XML payload (e.g., repeated `</` characters) to a Netty server utilizing XmlFrameDecoder, causing the server's EventLoop thread to exhaust CPU resources and become unresponsive.

### Details
`io.netty.handle…

GitHub-GHSA

HIGH
js-yaml: Exponential parsing time in flow collections leads to denial of service
GHSA-pm4m-ph32-ghv5
pkg: js-yaml
eco: npm
published: Jul 24, 2026
### Summary
Parsing a small YAML document can take exponential time. An application that calls `load()` or `loadAll()` on untrusted input can be hung by a payload under 200 bytes.

### Details
When an entry in a flow sequence turns out to be a `key: value` pair, the parser rewinds and parses that en…

GitHub-GHSA

HIGH
@fastify/static vulnerable to route guard bypass via path traversal
GHSA-83w8-p2f5-377r
pkg: @fastify/static
eco: npm
published: Jul 24, 2026
### Impact

`@fastify/static` is vulnerable to a bypass of route-based middleware and guards via non-leading `..` and `%2E%2E` path segments. `find-my-way` does not normalize `..` when matching routes, so a request such as `/foo/../deep/secret.txt` matches the static plugin's catch-all instead of th…

CVE-2026-15074
GitHub-GHSA

HIGH
GitPython: Incomplete unsafe_git_clone_options denylist omits –template enabling arbitrary command execution via clone hooks
GHSA-6p8h-3wgx-97gf
pkg: GitPython
eco: pip
published: Jul 24, 2026
## Summary
GitPython's `unsafe_git_clone_options` denylist omits `–template`. `git clone –template=<dir>` copies `<dir>/hooks/` into the new repository and runs them (`post-checkout` fires during clone), so a caller who can influence clone options can achieve arbitrary command execution in the def…
GitHub-GHSA

HIGH
PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
GHSA-r28c-9q8g-f849
pkg: postcss
eco: npm
published: Jul 24, 2026
## Vulnerability Details

**File**: `lib/previous-map.js`
**Line**: 87-98 (`loadFile`), 129-144 (`loadMap`)

### Root Cause
PostCSS auto-detects a `/*# sourceMappingURL=… */` comment inside the CSS text it is asked to parse and, unless the caller explicitly passes `map: false`, attempts to load t…

NVD

HIGH
CVE-2026-64210
CVE-2026-64210
pkg: linux

published: Jul 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

net/mlx5e: xsk: Fix unlocked writing to ICOSQ

During napi poll, when the affinity changes and there's still XSK work
to be done, we trigger an ICOSQ interrupt on the new CPU. However, this
triggering on the ICOSQ is done unprotect…

NVD

HIGH
CVE-2026-64208
CVE-2026-64208
pkg: linux

published: Jul 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks

Change the krb5 crypto library to provide facilities to precheck the length
of the message about to be decrypted or verified.

Fix AF_RXRPC to make use of this t…

GitHub-GHSA

HIGH
Microsoft Kiota: Code Generation Literal Injection in Kiota Python Generator
GHSA-7f3j-j7jj-r3vr
pkg: Microsoft.OpenAPI.Kiota, Microsoft.OpenAPI.Kiota.Builder
eco: nuget
published: Jul 24, 2026
Code Generation Literal Injection in Kiota Python Generator Leads to Arbitrary Code Execution at Import Time.

The Kiota Python code generator is vulnerable to a code generation literal injection issue when processing malicious or untrusted OpenAPI specifications. Specifically, attacker-controlled e…

CVE-2026-59862
GitHub-GHSA

HIGH
Microsoft Kiota: Code Generation Literal Injection in Kiota Ruby Generator
GHSA-xg2h-5xr2-29jw
pkg: Microsoft.OpenAPI.Kiota, Microsoft.OpenAPI.Kiota.Builder
eco: nuget
published: Jul 24, 2026
Code Generation Literal Injection in Kiota Ruby Generator Leads to Arbitrary Code Execution

# Impact

The Kiota Ruby code generator is vulnerable to a code generation literal injection attack. The generator embeds string values from OpenAPI default fields and property names directly into Ruby doubl…

CVE-2026-59861
GitHub-GHSA

HIGH
httplib2: Decompression Bomb Denial of Service via Unbounded gzip/deflate Response Handling
GHSA-j5g9-f88f-gfj3
pkg: httplib2
eco: pip
published: Jul 24, 2026
### Summary

The `httplib2` HTTP client library performs unbounded decompression of HTTP response bodies encoded with `Content-Encoding: gzip` or `deflate`. A malicious or compromised HTTP server can return a small compressed payload (approximately 150 KB) that expands to an arbitrarily large size i…

CVE-2026-59939
GitHub-GHSA

HIGH
Quinn: Remote memory exhaustion in quinn-proto from unbounded out-of-order stream reassembly
GHSA-4w2j-m93h-cj5j
pkg: quinn-proto
eco: rust
published: Jul 24, 2026
## Summary

The `Assembler` component that assembles unordered stream fragments into consecutive chunks of the stream incurs some overhead for non-contiguous fragments. Readers that read from a `RecvStream` in order (through an `AsyncRead` impl for example) will be sensitive to peers that send fragm…

GitHub-GHSA

HIGH
find-my-way: DDoS with HTTP2
GHSA-c96f-x56v-gq3h
pkg: find-my-way
eco: npm
published: Jul 23, 2026
### Impact
Remotely triggerable DoS in find-my-way when it is used with Node's HTTP/2 server.

The short version is that `lookup()` passes `req.method` into `find()`, and `find()` indexes `this.trees[method]`. Since `this.trees` is a normal object, HTTP/2 method values like constructor, `toString`, …

CVE-2026-47219
GitHub-GHSA

HIGH
PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments
GHSA-6g55-p6wh-862q
pkg: postcss
eco: npm
published: Jul 23, 2026
## Summary

PostCSS's `PreviousMap` parses the `/*# sourceMappingURL=PATH */` comment from any CSS string passed to `process()` and dereferences `PATH` against the local filesystem with no scheme, allowlist, or traversal check. An attacker who controls the CSS input can cause the host process to rea…

CVE-2026-45623
GitHub-GHSA

HIGH
Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers
GHSA-xmf8-cvqr-rfgj
pkg: @auth/core, next-auth, next-auth
eco: npm
published: Jul 23, 2026
## Summary

The exported `getToken()` helper (`next-auth/jwt` and `@auth/core/jwt`) can throw an uncaught exception when it reads a malformed `Authorization: Bearer …` header. When no session cookie is present, `getToken()` URL-decodes the bearer value before validating it, and malformed percent-e…

NVD

HIGH
CVE-2026-14257
CVE-2026-14257
pkg: node

published: Jul 23, 2026

brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max option (default 100,000) but does not bound the length of each result string. By chaining multiple brace groups, an attacker keeps the result count un…
CWE: CWE-400, CWE-770
GitHub-GHSA

HIGH
Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requests
GHSA-9299-c6m4-mjhc
pkg: org.eclipse.jetty:jetty-server, org.eclipse.jetty:jetty-server
eco: maven
published: Jul 22, 2026
### Impact
The original report:

> Server handling of 100-Continue requests can lead to memory leak that can be abused to cause a Denial of Service state.

After investigation, turns out that every request that has a body, but reading the body may end up in reading 0 bytes, leaks a buffer.
This is p…

CVE-2024-7708
GitHub-GHSA

HIGH
Netty: Memory Exhaustion via HTTP/3 Reserved Frame Types
GHSA-hpcc-26xq-25fv
pkg: io.netty:netty-codec-http3
eco: maven
published: Jul 22, 2026
### Summary
Netty's Http3FrameCodec buffers incoming data for HTTP/3 reserved frame types up to the specified payload length without any limits. The payload length is read directly from the wire and trusted without validation. A bad actor can send a reserved frame with a payload length of up to Inte…
CVE-2026-56816
GitHub-GHSA

HIGH
Netty SPDY zlib header block continues decoded expansion after maxHeaderSize truncation
GHSA-mvh2-crg5-v77c
pkg: io.netty:netty-codec-http, io.netty:netty-codec-http
eco: maven
published: Jul 22, 2026
### Summary
Netty SPDY header decoding continues inflating zlib-compressed header blocks after the raw header parser has already exceeded maxHeaderSize and marked the frame truncated. At commit b2d2137c4404af425bf9d5d601a62576f5c06925, a 12,253-byte compressed SPDY header block can declare and infla…
CVE-2026-55833
GitHub-GHSA

HIGH
Netty SPDY SETTINGS frame count materializes unbounded settings map
GHSA-6jqx-86gh-f27w
pkg: io.netty:netty-codec-http, io.netty:netty-codec-http
eco: maven
published: Jul 22, 2026
### Summary
Netty's SPDY SETTINGS decoder accepts a peer-declared SETTINGS entry count up to the 24-bit frame-length limit and materializes every unique setting ID in `DefaultSpdySettingsFrame` without an implementation-level count cap. A remote SPDY/3.1 peer can send one syntactically valid roughly…
CVE-2026-55831
NVD

HIGH
CVE-2026-16422
CVE-2026-16422
pkg: google chrome, linux linux_kernel

published: Jul 21, 2026

Insufficient validation of untrusted input in Certificate in Google Chrome on Linux prior to 150.0.7871.182 allowed an attacker in a privileged network position to perform domain spoofing via malicious network traffic. (Chromium security severity: High)
CWE: CWE-20
NVD

HIGH
CVE-2026-65315
CVE-2026-65315
pkg: go

published: Jul 21, 2026

Ollama (HEAD f0078ae) contains an uncontrolled memory allocation vulnerability in the GGUF metadata parser that allows remote attackers to crash the server by supplying a crafted GGUF file with attacker-controlled length and count fields in string lengths, tensor dimension counts, and metadata array…
CWE: CWE-789
GitHub-GHSA

HIGH
GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL
GHSA-rwj8-pgh3-r573
pkg: gitpython
eco: pip
published: Jul 21, 2026
### Summary
`Repo.clone_from()` passes the caller-supplied remote URL through `Git.polish_url()`, which on every non-Cygwin platform calls `os.path.expandvars()` on the URL before handing it to `git clone`. An attacker who controls the URL argument — the documented use case for `clone_from()` in "…
GitHub-GHSA

HIGH
Gitea: Notification API leaks private issue metadata after access revocation
GHSA-44qc-pgvp-wx7v
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
# Summary

An information disclosure issue in the Gitea Notification API allows users who have lost access to a private repository to continue accessing private issue or pull request information through existing notification threads. Although repository information is hidden after access revocation,…

CVE-2026-58419
GitHub-GHSA

HIGH
Gitea: Unauthorized Access to Labels of Private Organizations
GHSA-v73x-hx65-6pf4
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
## Summary

Gitea 1.26.2 does not properly enforce organization visibility restrictions on organization label read endpoints.

A user without access to a private organization can retrieve labels belonging to that organization through the Organization Labels API. As a result, label metadata intended …

CVE-2026-25038
GitHub-GHSA

HIGH
Gitea: Fork Synchronization Continues After Parent Repository Changes from Public to Private
GHSA-wrf9-r3h7-7x5v
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary

The `POST /api/v1/repos/{owner}/{repo}/merge-upstream` endpoint continues to synchronize commits from a parent repository after the parent repository has been changed from public to private.

A fork created while the parent repository was public can still receive commits made after the …

CVE-2026-24451
GitHub-GHSA

HIGH
Gitea: Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override
GHSA-94v3-77j7-vm48
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
Summary

Gitea's internal API HTTP client (modules/private/internal.go) hardcodes
TLSClientConfig.InsecureSkipVerify = true with no configuration override. It is the only
outbound TLS client in the codebase that cannot be made to verify its peer's certificate —
webhook, migrations, MinIO, LDAP, SM…

CVE-2026-54481
GitHub-GHSA

HIGH
Gitea: Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service
GHSA-v96j-25gv-g2w9
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
This issue has been found by a security agent and review by myself.

Gitea's CODEOWNERS feature uses the regexp2 library to match file paths against ownership rules. User-supplied patterns are passed directly to regexp2.Compile with no sanitisation and no match timeout. This allows an attacker to wr…

CVE-2026-58421
GitHub-GHSA

HIGH
pyasn1: Uncontrolled resource consumption when converting decoded REAL values
GHSA-hm4w-wwcw-mr6r
pkg: pyasn1
eco: pip
published: Jul 21, 2026
### Impact
The univ.Real type converted its (mantissa, base, exponent) value to a Python float using exact big-integer exponentiation. A BER/CER/DER-encoded REAL value only a few bytes long can carry a very large exponent, causing this computation to attempt to materialize an astronomically large in…
CVE-2026-59886
GitHub-GHSA

HIGH
pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service
GHSA-8ppf-4f7h-5ppj
pkg: pyasn1
eco: pip
published: Jul 21, 2026
### Impact
The BER/CER/DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs. A small crafted payload (tens of kilobytes) containing an OID with many arcs consumes seconds of CPU per decode() call, allowing denial of service in any applicatio…
CVE-2026-59885
GitHub-GHSA

HIGH
pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs
GHSA-m4p7-r5rc-7g4j
pkg: pyssn1
eco: pip
published: Jul 21, 2026
### Impact
The BER decoder (shared by the CER and DER codecs) parses long-form tags by accumulating continuation octets in a loop with no upper bound on the size of the tag ID. A crafted input can force the decoder to build an arbitrarily large integer, with CPU cost growing quadratically in input s…
CVE-2026-59884
NVD

HIGH
CVE-2026-44907
CVE-2026-44907
pkg: react

published: Jul 21, 2026

A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack (versions 19.0.0 throu…
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-56170 – .NET Denial of Service Vulnerability
GHSA-j8gr-8fp3-5q5h
pkg: Microsoft.AspNetCore.App.Runtime.linux-arm, Microsoft.AspNetCore.App.Runtime.linux-arm64, Microsoft.AspNetCore.App.Runtime.linux-musl-arm
eco: nuget
published: Jul 21, 2026
# Microsoft Security Advisory CVE-2026-56170 – .NET Denial of Service Vulnerability

## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core SignalR (Microsoft.AspNetCore.App.Runtime). This advisory also provides guidance on …

CVE-2026-56170
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-50527 – .NET Denial of Service Vulnerability
GHSA-mmjf-rqrv-855v
pkg: System.Security.Cryptography.Xml, System.Security.Cryptography.Xml, System.Security.Cryptography.Xml
eco: nuget
published: Jul 21, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET XML Encryption (System.Security.Cryptography.Xml). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A den…

CVE-2026-50527
GitHub-GHSA

HIGH
Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch
GHSA-9hw9-ch79-4vh6
pkg: pillow
eco: pip
published: Jul 20, 2026
### Summary

Pillow's public `ImageCms.ImageCmsTransform.apply(im, imOut)` API can trigger
controlled native heap corruption when the caller supplies an output image whose
mode does not match the transform's declared output mode.

For example, a transform built as `RGBA -> RGBA` can be applied to an…

CVE-2026-59205
GitHub-GHSA

HIGH
Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()
GHSA-jjj6-mw9f-p565
pkg: Pillow
eco: pip
published: Jul 20, 2026
### Summary
`PdfParser.PdfStream.decode()` in Pillow's `PdfParser.py` calls `zlib.decompress()` with the `bufsize` parameter set to the value of the PDF stream's `Length` field, without any upper bound on the actual decompressed output size. Python's `zlib.decompress()` `bufsize` argument is an *ini…
CVE-2026-59200
GitHub-GHSA

HIGH
Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow
GHSA-6r8x-57c9-28j4
pkg: Pillow
eco: pip
published: Jul 20, 2026
### Summary

Pillow's public image coordinate APIs can trigger a native heap out-of-bounds
write when given coordinates near the signed 32-bit integer limits. In 4-byte
pixel modes such as `RGBA`, this becomes a controlled backward heap underwrite:
for a source image of width `W`, Pillow writes `4 *…

CVE-2026-59199
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-50651 – .NET Denial of Service Vulnerability
GHSA-wp74-jgxh-gv4q
pkg: Microsoft.NetCore.App.Runtime.linux-arm, Microsoft.NetCore.App.Runtime.linux-arm64, Microsoft.NetCore.App.Runtime.linux-musl-arm
eco: nuget
published: Jul 20, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET HTTP client (System.Net.Http). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A denial of service vulne…

CVE-2026-50651
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-50525 – .NET Denial of Service Vulnerability
GHSA-8q5v-6pqq-x66h
pkg: System.Security.Cryptography.Xml, System.Security.Cryptography.Xml, System.Security.Cryptography.Xml
eco: nuget
published: Jul 20, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET XML Encryption (System.Security.Cryptography.Xml). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A den…

CVE-2026-50525
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-50648 – .NET Denial of Service Vulnerability
GHSA-23rf-6693-g89p
pkg: System.Security.Cryptography.Xml, System.Security.Cryptography.Xml, System.Security.Cryptography.Xml
eco: nuget
published: Jul 20, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET XML Encryption (System.Security.Cryptography.Xml). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A den…

CVE-2026-50648
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-50524 – .NET Denial of Service Vulnerability
GHSA-w7cw-xp7h-6j5j
pkg: Microsoft.NetCore.App.Runtime.linux-arm, Microsoft.NetCore.App.Runtime.linux-arm64, Microsoft.NetCore.App.Runtime.linux-musl-arm
eco: nuget
published: Jul 20, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET TLS/SSL (System.Net.Security). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A denial of service vulne…

CVE-2026-50524
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-47302 – .NET Denial of Service Vulnerability
GHSA-cvvh-rhrc-wg4q
pkg: System.Security.Cryptography.Xml, Microsoft.NetCore.App.Runtime.linux-arm, Microsoft.NetCore.App.Runtime.linux-arm64
eco: nuget
published: Jul 20, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET XML processing (System.Security.Cryptography.Xml, System.Xml). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerabi…

CVE-2026-47302
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-57108 – .NET Denial of Service Vulnerability
GHSA-rp2p-6cmp-jxj9
pkg: Microsoft.NetCore.App.Runtime.linux-arm, Microsoft.NetCore.App.Runtime.linux-arm64, Microsoft.NetCore.App.Runtime.linux-musl-arm
eco: nuget
published: Jul 20, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in the .NET runtime cryptography layer (CryptoNative_GetX509NameInfo). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerabi…

CVE-2026-57108
GitHub-GHSA

HIGH
Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert)
GHSA-c8j7-8cv4-2xmq
pkg: mistune
eco: pip
published: Jul 20, 2026
## Summary

**Type:** Algorithmic-complexity denial of service. A run of N closed pairs `~~x~~~~x~~…` (or the analogous `==x==` for `mark`, `^^x^^` for `insert`) causes O(N²) work in the formatting parser. With the `strikethrough`, `mark`, or `insert` plugin enabled, an 8 KB input pegs the CPU fo…

CVE-2026-59922
GitHub-GHSA

HIGH
Mistune inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs
GHSA-4j32-57v6-6g45
pkg: mistune
eco: pip
published: Jul 20, 2026
## Summary

**Type:** Algorithmic-complexity DoS in core emphasis parsing. A long sequence of well-formed `**x**` (strong) or `***x***` (strong-emphasis combined) pairs causes O(N²) parser work. Distinct from the bracket-bomb DoS (`[` repetition) and from the formatting-plugin DoS (`~~`/`==`/`^^`);…

CVE-2026-59925
GitHub-GHSA

HIGH
Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions
GHSA-ffq3-xpv3-j92q
pkg: mistune
eco: pip
published: Jul 20, 2026
## Summary

**Type:** Algorithmic-complexity DoS in reference-link definition handling. A markdown document with N reference-link definitions of the same key (or many distinct keys) takes O(N²) parser time. 5000 repeated `[a]: u\n` definitions take ~1.1 second; 10000 → ~4.5 seconds.
**File:** `sr…

CVE-2026-59928
GitHub-GHSA

HIGH
Pillow `GdImageFile._open()`: image dimensions accepted without `_decompression_bomb_check()`
GHSA-phj9-mv4w-65pm
pkg: pillow
eco: pip
published: Jul 20, 2026
## Description

`PIL/GdImageFile.py` `GdImageFile._open()` reads image dimensions from the GD 2.x header and stores them in `self._size` without calling `Image._decompression_bomb_check()`. Because `GdImageFile` is **not registered with `Image.register_open()`**, it never passes through the standard…

CVE-2026-55380
GitHub-GHSA

HIGH
Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading
GHSA-45hq-cxwh-f6vc
pkg: pillow
eco: pip
published: Jul 20, 2026
### Summary
`PIL/BdfFontFile.py` `bdf_char()` (lines 84–88) reads the `BBX width height` field from a BDF font file and passes the dimensions directly to `Image.new()` without calling `Image._decompression_bomb_check()`. This completely bypasses Pillow's documented decompression bomb protection.

CVE-2026-55379
GitHub-GHSA

HIGH
Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`
GHSA-5×94-69rx-g8h2
pkg: pillow
eco: pip
published: Jul 20, 2026
## Description

`PIL/FontFile.py` `FontFile.compile()` assembles per-glyph images into a single combined bitmap using `Image.new("1", (xsize, ysize))` without calling `Image._decompression_bomb_check()`. This is the base-class method shared by both `BdfFontFile` and `PcfFontFile`, and it is triggere…

CVE-2026-54060
GitHub-GHSA

HIGH
Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading
GHSA-8v84-f9pq-wr9x
pkg: pillow
eco: pip
published: Jul 20, 2026
## Description
`PIL/PcfFontFile.py` `_load_bitmaps()` (line 227) reads glyph dimensions from the PCF `METRICS` section and passes them directly to `Image.frombytes()` without calling `Image._decompression_bomb_check()`. Dimensions originate from unsigned 16-bit values:

“`
xsize = right – left …

CVE-2026-54059
GitHub-GHSA

HIGH
Tornado: Quadratic DoS via Crafted Multipart Parameters
GHSA-jhmp-mqwm-3gq8
pkg: tornado
eco: pip
published: Jul 20, 2026
## Summary

The `_parseparam` function in Tornado's `httputil.py` is used to parse specific HTTP header values, such as those in `multipart/form-data`. This function uses an inefficient algorithm that repeatedly calls `string.count()` within a nested loop while processing quoted semicolons (e.g., `p…

CVE-2025-67726
GitHub-GHSA

HIGH
Tornado: Quadratic DoS via Repeated Header Coalescing
GHSA-c98p-7wgm-6p64
pkg: tornado
eco: pip
published: Jul 20, 2026
## Summary

The `HTTPHeaders.add` method in Tornado accumulates values using string concatenation when the same header name is repeated. Due to Python string immutability, each concatenation copies the entire string, resulting in O(n²) time complexity.

Given Tornado's single event loop architectur…

CVE-2025-67725
NVD

HIGH
CVE-2026-45713
CVE-2026-45713
pkg: go

published: Jul 20, 2026

Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the Mailpit SMTP server has a Server.MaxSize int field that controls the maximum allowed DATA payload size, but the field is never assigned anywhere outside test code, leaving it at Go's zero value (0 ⇒ "no limit"). …
CWE: CWE-400, CWE-770
GitHub-GHSA

HIGH
blaze: Chunked-body trailer fields promoted into Request.headers in blaze-server (front-end header-sanitization bypass)
GHSA-46q4-43ph-c6fr
pkg: org.http4s:blaze-http_2.13, org.http4s:blaze-http_2.12, org.http4s:blaze-http_3
eco: maven
published: Jul 24, 2026
### Summary
blaze-server can merge HTTP/1.1 chunked-body trailer fields into `Request.headers`. Because trailer fields are attacker-controlled, an unauthenticated remote client can inject arbitrary header names/values (e.g. `X-Forwarded-For`, internal-auth headers) that a fronting proxy sanitized …
GitHub-GHSA

HIGH
blaze: Multiple HTTP/1.1 request-smuggling primitives in blaze's Java wire parser
GHSA-mhvj-jhpq-885v
pkg: org.http4s:http4s-blaze-server_2.13, org.http4s:blaze-http_2.13, org.http4s:blaze-http_3
eco: maven
published: Jul 24, 2026
### Summary
Five independent HTTP/1.1 conformance laxities in blaze's hand-written Java parser (`http/src/main/java/org/http4s/blaze/http/parser/`) cause request-boundary disagreement with a stricter intermediary. All are reachable from a default `BlazeServerBuilder` with no non-default configurat…
GitHub-GHSA

HIGH
Netty: TOCTOU in OcspServerCertificateValidator
GHSA-wc96-39fc-566f
pkg: io.netty:netty-handler-ssl-ocsp, io.netty:netty-handler-ssl-ocsp
eco: maven
published: Jul 22, 2026
### Summary
Netty's OcspServerCertificateValidator forwards the SslHandshakeCompletionEvent before the asynchronous OCSP validation completes. This allows the client's downstream handlers to send sensitive application data (e.g., HTTP requests) to a revoked server before the channel is closed by the…
CVE-2026-56822
GitHub-GHSA

HIGH
Netty: Out-of-date OCSP Responses Accepted by OcspServerCertificateValidator
GHSA-g7hg-vrcf-mvmr
pkg: io.netty:netty-handler-ssl-ocsp, io.netty:netty-handler-ssl-ocsp
eco: maven
published: Jul 22, 2026
### Summary
`OcspServerCertificateValidator` flags an out-of-date OCSP response but does not stop processing it, so an expired GOOD response is still reported as `VALID`, letting an on-path attacker replay a stale GOOD response to bypass revocation of a since-revoked certificate.

### Details
In `io…

CVE-2026-56821
GitHub-GHSA

HIGH
Netty: Missing CertificateID Validation in OCSP Response Allows Replay Attacks
GHSA-272m-gcwp-mpwg
pkg: io.netty:netty-handler-ssl-ocsp, io.netty:netty-handler-ssl-ocsp
eco: maven
published: Jul 22, 2026
### Summary
Netty's OcspClient does not validate that the CertificateID in an OCSP response matches the requested CertificateID. A bad actor can replay a `GOOD` status response issued for an unrelated certificate (by the same CA) to bypass revocation checks for any certificate.

### Details
`io.nett…

CVE-2026-56820
GitHub-GHSA

HIGH
AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()
GHSA-j6g5-3hh3-pgw8
pkg: bedrock-agentcore
eco: pip
published: Jul 24, 2026
### Summary

The AWS Bedrock AgentCore Python SDK (bedrock-agentcore) provides tools for building AI agents, including a Code Interpreter client that installs Python packages into a managed sandbox. An issue exists where, under certain circumstances, improper neutralization of argument delimiters in…

CVE-2026-16796
GitHub-GHSA

HIGH
Open WebUI: Stored web worker XSS via Pyodide
GHSA-4r2p-27mh-5m22
pkg: open-webui
eco: pip
published: Jul 24, 2026
**Title:** Same-origin Pyodide code execution allows server-side RCE via a shared chat

### Summary

Open WebUI runs client-side Python (Pyodide) in a same-origin web worker. Through Pyodide's JavaScript API (`pyodide.http.pyfetch`, or the `js` module which exposes the page's `fetch` / `XMLHttpReque…

CVE-2026-59214
NVD

HIGH
CVE-2026-16796
CVE-2026-16796
pkg: python

published: Jul 23, 2026

Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK before 1.18.1 might allow a remote authenticated user to execute arbitrary commands within the Code Interpreter sandbox via crafted package name arguments.

To mitigate this issue, u…

CWE: CWE-88
NVD

HIGH
CVE-2026-56624
CVE-2026-56624
pkg: openssh

published: Jul 20, 2026

Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a Java library for client-side and server-side SSH.

Server-side OpenSSH user certificate validation during user authentication in an Apache MINA SSHD server did not check for the unsupported force-command or …

CWE: CWE-295
NVD

HIGH
CVE-2026-32825
CVE-2026-32825
pkg: jwt

published: Jul 20, 2026

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, the application accepts unlimited password guesses against both the brow…
CWE: CWE-307
NVD

HIGH
CVE-2026-16247
CVE-2026-16247
pkg: windows

published: Jul 20, 2026

In _connect.BRAIN versions prior to 5.06,
the application LogPathConfig.exe is executed during setup. During this
process, existing permissions on %ProgramData% are deleted and replaced,
granting the Windows group Everyone full control instead of restricting
access to %ProgramData%\Bizerba\_connect.…
CWE: CWE-276
NVD

HIGH
CVE-2026-16246
CVE-2026-16246
pkg: windows

published: Jul 20, 2026

In BRAIN2 versions prior to 3.09, the
application LogPathConfig.exe is executed during setup. As a result, the
Windows group Everyone is granted full control over %ProgramData% instead of
being restricted to %ProgramData%\Bizerba\BRAIN2\.

Starting with BRAIN2 3.09, the setup no
longer executes …

CWE: CWE-276
NVD

HIGH
CVE-2026-65693
CVE-2026-65693
pkg: express

published: Jul 24, 2026

Microweber CMS through 2.0.20 contains a server-side template injection vulnerability that allows authenticated administrators to achieve arbitrary OS command execution by injecting Twig expressions into mail templates. Attackers can exploit the unsandboxed Twig environment in TwigView::render(), wh…
CWE: CWE-94
NVD

HIGH
CVE-2026-66138
CVE-2026-66138
pkg: python

published: Jul 24, 2026

In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic-Python-Agent via a maliciously constructed configuration, because the value of ntp_server is passed to a shell.
CWE: CWE-78
NVD

HIGH
CVE-2026-60396
CVE-2026-60396
pkg: go

published: Jul 21, 2026

Vulnerability in Oracle GoldenGate (component: Distribution Server executable). Supported versions that are affected are 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle GoldenGate. Successful attacks …
CWE: CWE-306
GitHub-GHSA

HIGH
Budibase: NoSQL injection in MongoDB integration: collection dump, $where JS exec, cross-collection pivot, arbitrary update/delete
GHSA-pmpg-2mxq-6xwr
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
## Summary

An end-user injection in Budibase's MongoDB datasource lets any BASIC app user bypass the builder's query-level access controls. Builders scope MongoDB reads per-user with bindings like `{"email": "{{ currentUser.email }}"}` so each app user only sees their own rows. Because the binding …

GitHub-GHSA

HIGH
Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials
GHSA-hq88-5×99-x3gf
pkg: github.com/cloudreve/Cloudreve/v4, github.com/cloudreve/Cloudreve/v3
eco: go
published: Jul 24, 2026
## Summary

Cloudreve 4.16.1 has an OAuth scope authorization bypass in the admin storage policy routes. An OAuth bearer token scoped to `Admin.Read` but not `Admin.Write` can call `POST /api/v4/admin/policy/oauth/signin` and update OneDrive storage policy credentials.

The route is inside the admin…

CVE-2026-55502
GitHub-GHSA

HIGH
Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids)
GHSA-x2ff-v5v8-m75m
pkg: open-webui
eco: pip
published: Jul 24, 2026
## Summary

Any authenticated user can overwrite the content of a message in a channel they do not belong to (including private and DM channels) by sending a chat completion request with a `channel:`-prefixed `chat_id` and a target `message_id`. The `channel:` path routes pipeline output through `_m…

CVE-2026-59714
GitHub-GHSA

HIGH
Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout
GHSA-855v-hq7w-jmjw
pkg: open-webui
eco: pip
published: Jul 24, 2026
## Summary

With Redis configured, Open WebUI supports JWT revocation: `POST /api/v1/auths/signout` (per-token `jti`) and OIDC back-channel logout (per-user `revoked_at`) record revocations in Redis, and HTTP auth (`get_current_user`) rejects revoked tokens with 401. The realtime authentication surf…

CVE-2026-59219
GitHub-GHSA

HIGH
Microsoft Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
GHSA-rg4h-fpcp-2qm8
pkg: Microsoft.OpenApi.Kiota, Microsoft.OpenApi.Kiota.Builder
eco: nuget
published: Jul 24, 2026
## Summary

Microsoft Kiota resolved OpenAPI `$ref`s by fetching remote `http(s)` URLs and reading local files
(including absolute / out-of-tree paths), inlining the referenced schema into the generated client.
Running `kiota generate` on a spec whose `$ref` pointed at an attacker/internal URL or an…

CVE-2026-59867
GitHub-GHSA

HIGH
@better-auth/stripe: cross-organization billing tampering in organization subscription actions
GHSA-h3rm-78g3-j7cp
pkg: @better-auth/stripe, @better-auth/stripe
eco: npm
published: Jul 24, 2026
### Am I affected?

You are affected if all of these are true:

– You use `@better-auth/stripe` from version 1.4.11 up to a patched version below. This covers the stable line through 1.6.20 and every 1.7.0 beta through 1.7.0-beta.9.
– The Stripe plugin has subscriptions turned on (`subscription.enab…

NVD

HIGH
CVE-2026-57767
CVE-2026-57767
pkg: go

published: Jul 23, 2026

Unauthenticated Cross Site Scripting (XSS) in WP Google Maps Pro <= 10.1.02 versions.
CWE: CWE-79
GitHub-GHSA

HIGH
Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth `X-Gitea-OTP` surface
GHSA-gx3v-q759-g323
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary

I'm reporting **two related TOTP one-time-use defects** in Gitea that survive the CVE-2021-45331 fix. The 2018 fix (PR #3878) introduced the `TwoFactor.LastUsedPasscode` field and added an in-memory inequality check on the web 2FA login path. That check works correctly in the single-req…

CVE-2026-20779
GitHub-GHSA

HIGH
Gitea: Repository Visibility Manipulation via Git Push Options
GHSA-8p9h-49rc-qgxj
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Repository Visibility Manipulation via Git Push Options

| Field | Value |
|——-|——-|
| **Affected File** | `routers/private/hook_post_receive.go` |
| **Affected Function** | `HookPostReceive()` |
| **Affected Lines** | 173–225 |
| **Prerequisite** | Attacker must have owner-level or ad…

CVE-2026-58437
GitHub-GHSA

HIGH
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects
GHSA-2m9v-5q2g-58vq
pkg: gitea.dev
eco: go
published: Jul 21, 2026
## Summary

A user with Code write access to one repository may be able to associate an existing Git LFS object from a private source repository with their target repository, even when they do not have Code access to the source repository that currently owns the LFS object.

The issue appears to be …

CVE-2026-28740
NVD

HIGH
CVE-2026-21575
CVE-2026-21575
pkg: windows

published: Jul 21, 2026

This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.11 of Sourcetree for Mac and Sourcetree for Windows.

This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to execute arbitrary code which has high impa…

CWE: CWE-94
NVD

HIGH
CVE-2026-56623
CVE-2026-56623
pkg: windows

published: Jul 20, 2026

Path traversal on Windows in Apache MINA SSHD component sshd-git. Apache MINA SSHD is a Java library for client-side and server-side SSH.

A git server implemented with Apache MINA SSHD component sshd-git and running on Windows could allow an authenticated remote user access to git repositories …

CWE: CWE-22
GitHub-GHSA

HIGH
AWS API MCP Server Security Policy Bypass via Startup Initialization Failure
GHSA-29w2-fq35-v728
pkg: awslabs.aws-api-mcp-server
eco: pip
published: Jul 24, 2026
## Summary
The AWS API MCP Server is an open source Model Context Protocol (MCP) server that enables AI assistants to interact with AWS services and resources through AWS CLI commands. It provides programmatic access to manage your AWS infrastructure while maintaining proper security controls. It in…
CVE-2026-16584
GitHub-GHSA

HIGH
GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)
GHSA-3rp5-jjmw-4wv2
pkg: gitpython
eco: pip
published: Jul 24, 2026
### Summary

In GitPython `<= 3.1.52`, the config writer neutralizes only CR, LF, and NUL in configuration **names**, but writes section names into the `[…]` header with no other escaping. A section/subsection name that contains `] [ "` closes the intended header and opens a second same-line secti…

NVD

HIGH
CVE-2026-64222
CVE-2026-64222
pkg: linux

published: Jul 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

octeontx2-pf: avoid double free of pool->stack on AQ init failure

otx2_pool_aq_init() frees pool->stack when mailbox sync or retry
allocation fails, but leaves the pointer unchanged. Later,
otx2_sq_aura_pool_init() unwinds the par…

NVD

HIGH
CVE-2026-64219
CVE-2026-64219
pkg: linux

published: Jul 24, 2026

In the Linux kernel, the following vulnerability has been resolved:

drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async

[Why&How]
dc_process_dmub_aux_transfer_async() copies payload->length bytes into a
16-byte stack buffer (dpaux.data[16]) guarded only by…

GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-50526 – .NET Tampering Vulnerability
GHSA-55jh-fwmh-39m4
pkg: Microsoft.NET.Build.Containers, Microsoft.NET.Build.Containers, Microsoft.NET.Build.Containers
eco: nuget
published: Jul 21, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET SDK (Microsoft.NET.Build.Containers). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A tampering vulner…

CVE-2026-50526
GitHub-GHSA

HIGH
etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline
GHSA-6vch-q96h-7gc3
pkg: go.etcd.io/etcd/v3, go.etcd.io/etcd/v3, go.etcd.io/etcd/v3
eco: go
published: Jul 24, 2026
### Impact
_What kind of vulnerability is it? Who is impacted?_

A network attacker who can reach an etcd TLS listener can open many TCP connections and never send a ClientHello. Each connection spawns a goroutine in the etcd server process that blocks indefinitely inside tls.Conn.Handshake(), and e…

GitHub-GHSA

HIGH
etcd: Watch API authorization bypass via open-ended range requests
GHSA-xg4h-6gfc-h4m8
pkg: go.etcd.io/etcd/v3, go.etcd.io/etcd/v3, go.etcd.io/etcd/v3
eco: go
published: Jul 24, 2026
### Impact
_What kind of vulnerability is it? Who is impacted?_

A user granted READ permission on a single, exact key can use the Watch gRPC API with `clientv3.WithFromKey()` (an open-ended, "from this key to the end of the keyspace" watch) to receive watch events for every key lexicographically gr…

GitHub-GHSA

HIGH
Shescape: Quadratic-time denial of service in the flag-protection
GHSA-gm3r-q2wp-hw87
pkg: shescape, shescape
eco: npm
published: Jul 24, 2026
### Impact

This impacts users of Shescape that have flag protection enabled, which is on by default, regardless of the API being used.

An attacker can cause a runtime quadratic in the input size, causing denial of service for large inputs.

“`javascript
import { Shescape } from "shescape";

// 1.…

GitHub-GHSA

HIGH
vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review
GHSA-47w6-gwp4-w6vc
pkg: vantage6
eco: pip
published: Jul 24, 2026
### Impact
Edit permission lacks ownership check, so another developer could alter metadata that is later trusted by nodes.

Worst they could do is update the image or image tag. If that is not noted, another image is approved than the one actually under review

### Patches
No

### Workarounds
No

GitHub-GHSA

HIGH
frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow
GHSA-26gq-p25f-99cp
pkg: github.com/fatedier/frp
eco: go
published: Jul 24, 2026
## Summary

An integer-overflow vulnerability in the frp server's optional SSH Tunnel Gateway lets any unauthenticated remote attacker crash the entire `frps` process with a single five-byte message. When the gateway parses an SSH `exec` channel request in `pkg/ssh/server.go`, it adds a small consta…

GitHub-GHSA

HIGH
Budibase: Server Filesystem Existence/Read Oracle via Builder-Controlled MongoDB tlsCertificateKeyFile
GHSA-ppr4-5f46-j9c6
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
## Summary
When creating a MongoDB datasource, Budibase passes the `tlsCertificateKeyFile` and `tlsCAFile` fields straight to the MongoDB driver as server-side file paths. On Budibase Cloud a customer cannot place files on the server, so these fields only let a builder reference arbitrary absolute p…
GitHub-GHSA

HIGH
Budibase: Email Change IDOR via POST /api/v2/email allows full Account Takeover (accountId not validated against session)
GHSA-c8vc-7pv3-g98p
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
## Summary

`POST /api/v2/email` on the account portal (`account.budibase.app`) starts an email-change workflow using a client-supplied `accountId` that is **not validated against the authenticated session**. A logged-in attacker supplies a victim's `accountId` and an email address they control; the…

GitHub-GHSA

HIGH
Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution
GHSA-7835-87q9-rgvv
pkg: @anthropic-ai/claude-code
eco: npm
published: Jul 24, 2026
Claude Code's worktree handling allowed creation of worktrees named ".git" and navigation to worktrees outside the sandbox context, enabling git directory confusion attacks. By exploiting symlink manipulation and git fsmonitor execution during worktree operations, an attacker could overwrite files i…
CVE-2026-55607
GitHub-GHSA

HIGH
React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response
GHSA-qwww-vcr4-c8h2
pkg: react-router
eco: npm
published: Jul 24, 2026
This is a follow up to CVE-2026-22030 to address related CSRF flows in unstable RSC code paths.

> [!NOTE]
> This only affects your application if you are using the unstable RSC APIs

GitHub-GHSA

HIGH
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
GHSA-4vv7-jj25-4gh6
pkg: Microsoft.OpenApi.Kiota, Microsoft.OpenApi.Kiota.Builder
eco: nuget
published: Jul 24, 2026
### Summary

Microsoft Kiota emitted the `x-ms-kiota-info` extension's `clientClassName` or `clientNamespaceName` value
**raw**, with no identifier or path sanitization, as **both** the generated client's class/namespace name
**and** part of the generated output path. When `kiota generate` is run **…

CVE-2026-59866
GitHub-GHSA

HIGH
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
GHSA-4rj6-vrwv-wr8m
pkg: Microsoft.OpenApi.Kiota, Microsoft.OpenApi.Kiota.Builder
eco: nuget
published: Jul 24, 2026
### Summary

Microsoft Kiota honors a poisoned `.kiota/workspace.json` — the workspace configuration that Kiota's
documented team workflow has developers commit to their repository — **unvalidated** on
`kiota client generate` / `kiota plugin generate`. A repository (or pull request) containing a…

CVE-2026-59863
GitHub-GHSA

HIGH
Microsoft Kiota: Code Generation Literal Injection in Kiota PHP Generator
GHSA-jqwh-526h-c92j
pkg: Microsoft.OpenApi.Kiota, Microsoft.OpenApi.Kiota.Builder
eco: nuget
published: Jul 24, 2026
# Impact

The Kiota PHP code generator is vulnerable to a code generation literal injection attack. The generator embeds string values from OpenAPI fields (e.g. `description`, default values, and property names) directly into PHP double-quoted string literals without properly escaping the `$` charac…

CVE-2026-59859
GitHub-GHSA

HIGH
Microsoft Kiota: XML Doc-Comment Newline Breakout Code Injection
GHSA-3hrf-2gc2-mx32
pkg: Microsoft.OpenApi.Kiota, Microsoft.OpenApi.Kiota.Builder
eco: nuget
published: Jul 24, 2026
### Summary

Kiota versions **prior to 1.32.3** are affected by a code-generation injection vulnerability in the C# XML documentation-comment sink (the `description`, `externalDocs` label, and `externalDocs` link fields emitted as `/// …` comments).

When text from an OpenAPI description is writte…

CVE-2026-59860
GitHub-GHSA

HIGH
React Router: Unauthenticated Denial of Service via Inefficient Route Matching
GHSA-chx6-hx7r-mcp5
pkg: react-router
eco: npm
published: Jul 24, 2026
This is a follow up to https://github.com/remix-run/react-router/security/advisories/GHSA-8x6r-g9mw-2r78 that covers additional reported scenarios in which the manifest endpoint could be accessed via unauthenticated targeted requests that would put heavy load on the server and slow down response tim…
CVE-2026-55685
GitHub-GHSA

HIGH
LiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce
GHSA-g357-x5c3-c72p
pkg: liquidjs
eco: npm
published: Jul 24, 2026
# `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce

**CWE**: CWE-770 (Allocation of Resources Without Limits or Throttling) — sibling class of GHSA-8xx9-69p8-7jp3 and GHSA-2546-xv4c-mc8g, applied to `memoryLimit` instead of `renderLimit`

## Summary

The `pop` …

CVE-2026-55575
GitHub-GHSA

HIGH
electron-updater: Cross-origin redirect leaks `PRIVATE-TOKEN` and mixed-case `Authorization` credentials in `builder-util-runtime`
GHSA-p2f4-r6v6-j797
pkg: builder-util-runtime
eco: npm
published: Jul 24, 2026
## Summary

In `electron-builder`'s `builder-util-runtime` package, the HTTP redirect handler (`HttpExecutor.prepareRedirectUrlOptions`) only stripped a credential header whose key string matched exactly lowercase `"authorization"`. Other credential-bearing headers — most notably `PRIVATE-TOKEN` (…

CVE-2026-54673
GitHub-GHSA

HIGH
pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)
GHSA-g867-7843-wf8q
pkg: pypdf
eco: pip
published: Jul 23, 2026
### Impact

An attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires parsing the content stream of a page with a not terminated inline image, as done when extracting the page text for example. It only affects the ASCII85 and ASCIIHex filters.

### Patche…

CVE-2026-59935
GitHub-GHSA

HIGH
pypdf: Possible infinite loop for not terminated inline images
GHSA-5xf7-4p34-54qr
pkg: pypdf
eco: pip
published: Jul 23, 2026
### Impact

An attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires parsing the content stream of a page with a not terminated inline image, as done when extracting the page text for example.

### Patches

This has been fixed in [pypdf==6.14.1](https://…

CVE-2026-59936
GitHub-GHSA

HIGH
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
GHSA-pppj-hq3g-57pj
pkg: jupyterlab, jupyterlab
eco: pip
published: Jul 22, 2026
JupyterLab 4.5+ allows notebook settings to be shared and applied through an `overrides.json` file using the `Import` button in the Settings Editor.

Certain notebook display settings were not properly validated before being applied. As a result, a crafted settings file could contain hidden instruct…

GitHub-GHSA

HIGH
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
GHSA-gx64-gj6p-pc4c
pkg: jupyterlab, jupyterlab
eco: pip
published: Jul 22, 2026
JupyterLab's image viewer allows for cross-site scripting (XSS) when a specially-crafted image file is opened through the image viewer and then opened in a new tab. This XSS issue can be used to cause remote code execution (RCE) on the JupyterLab server.

### Impact

This vulnerability allows for ar…

GitHub-GHSA

HIGH
Next.js: Server-Side Request Forgery in Server Actions on custom servers
GHSA-89xv-2m56-2m9x
pkg: next, next
eco: npm
published: Jul 22, 2026
## Impact

When a Server Action forwards or redirects a request, an attacker can cause the server to send that outbound request to a malicious host (Server-Side Request Forgery). This requires the attacker's request to control Host-associated headers. In some configurations, it's also possible to ob…

CVE-2026-64649
GitHub-GHSA

HIGH
Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname
GHSA-p9j2-gv94-2wf4
pkg: next, next
eco: npm
published: Jul 22, 2026
## Impact

A `rewrites()` or `redirects()` rule that builds its external destination hostname from request-controlled input can be pointed at an arbitrary hostname, regardless of the rule's hostname suffix. For a rewrite, Next.js proxies the request to that arbitrary host and serves the response fr…

CVE-2026-64645
GitHub-GHSA

HIGH
Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale
GHSA-6gpp-xcg3-4w24
pkg: next
eco: npm
published: Jul 22, 2026
## Impact

Crafted requests targeting Next.js applications using App Router built with Turbopack and a **single** entry in `config.i18n.locales` can bypass middleware/proxy based authentication.

## Workarounds

If you cannot upgrade immediately, enforce authorization in the page's server-side data …

CVE-2026-64642
GitHub-GHSA

HIGH
Next.js: Denial of Service in App Router using Server Actions
GHSA-m99w-x7hq-7vfj
pkg: next, next
eco: npm
published: Jul 22, 2026
## Impact

Crafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage blocking processing of further requests in the same process.

## Workarounds

No workaround exists besides upgrading. Applications using Pages Router or not usi…

CVE-2026-64641
GitHub-GHSA

HIGH
Eclipse Jetty Digest Authentication: ISO-8859-1 lossy encoding allows authentication bypass via character substitution
GHSA-2fvj-hgj9-j2gr
pkg: org.eclipse.jetty:jetty-security, org.eclipse.jetty:jetty-security, org.eclipse.jetty:jetty-security
eco: maven
published: Jul 22, 2026
### Summary
The `DigestAuthentication.apply()` method in Jetty's HTTP client uses `getBytes(StandardCharsets.ISO_8859_1)` at three locations (lines 171, 179, 196) to compute Digest auth response hashes. ISO-8859-1 silently replaces any character above U+00FF (Chinese, Japanese, Cyrillic, Arabic, Emo…
CVE-2026-10050
GitHub-GHSA

HIGH
LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback
GHSA-7488-6r32-c95q
pkg: litellm
eco: pip
published: Jul 22, 2026
### Impact

LiteLLM's MCP Streamable HTTP endpoint could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.

The MCP auth handler supported OAuth2 passthrough for upstream MCP servers, but the fallback path could replace failed LiteLLM key va…

CVE-2026-59822
GitHub-GHSA

HIGH
n8n: Prototype Pollution via Dot-Notation Field Names Leads To Instance-Wide Denial of Service
GHSA-xwx6-jjhv-84p8
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact

The Edit Fields (Set) node assigned output fields through a dot-notation path setter without restricting the field name, so an authenticated user could name a field after an inherited built-in method path and corrupt a shared global in the main Node.js process. Because that global was use…

GitHub-GHSA

HIGH
n8n: Edit Image Node Format Injection Allows Arbitrary File Write
GHSA-xmc9-4f2h-jf9c
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact

The n8n Edit Image node passed its output format to the underlying image library without validation, so a crafted value could write bytes to a location outside the node's working directory. An authenticated user able to run workflows could use this to write arbitrary files in the n8n inst…

GitHub-GHSA

HIGH
n8n: Shared-Workflow Editor Can Exfiltrate Credentials via Inline Sub-Workflow JSON
GHSA-cj9h-qx8g-pq2g
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact

n8n's credential-access checks validated only a node's top-level credentials, not credentials referenced inside an Execute Sub-workflow node's inline workflow JSON. A member with editor access to a shared workflow could reference a credential they were not permitted to use inside that inl…

GitHub-GHSA

HIGH
n8n: Credential Authorization Bypass via Expression in HTTP Request Node `genericAuthType`
GHSA-6qc9-mqvw-jg7x
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact

An authenticated member with edit access to a shared workflow could reference another user's credential in an HTTP Request node while specifying the credential type through an expression. Because the pre-execution permission check compared the unresolved expression instead of the real cre…

GitHub-GHSA

HIGH
n8n: Expression sandbox escape via arrow-function bodies enabling command execution
GHSA-gv7g-jm28-cr3m
pkg: n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact

An authenticated user with permission to create or modify workflows could abuse crafted expressions using arrow functions to bypass the expression sandbox, triggering unintended system command execution on the host running n8n.

## Patches

The issue has been fixed in n8n versions 2.31.5 …

GitHub-GHSA

HIGH
n8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion
GHSA-2×35-3fw4-9jr4
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact

The n8n Send Email node did not enforce that its message fields were strings, so a crafted untrusted non-string value from a workflow expression could be treated by the underlying mail library as a file path or URL. This could allow disclosure of local files on the n8n host.

Exploitation…

GitHub-GHSA

HIGH
n8n: Authenticated code execution in the n8n Git node
GHSA-rcv6-pvrj-4xcg
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact

Authenticated n8n users with rights to create and execute workflows could achieve code execution on the n8n host. Using the Git node, under the default `git` security settings, by staging a crafted local repository, an attacker could cause `git` to run hooks, executing arbitrary commands …

GitHub-GHSA

HIGH
n8n: Git Node fetch/pull/pushTags Operations Bypass Sandbox Path Restriction
GHSA-gf29-4f56-r2jf
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact

Authenticated n8n users with workflow create/execute rights could use the Git node's fetch, pull, or push-tags operations to bypass the repository-path containment checks that already protected clone and push. By pointing an allowlisted remote configuration value at a local path outside t…

GitHub-GHSA

HIGH
n8n: Bypass "Allowed HTTP Request Domains" Credential Restriction in Multiple AI and LLM Nodes
GHSA-64xh-79j6-r5v8
pkg: n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact

The credential "Allowed HTTP Request Domains" allowlist was intended to restrict which hosts a credential's secret could be sent to, protecting shared credentials from users who could use but not view them. Several AI/LLM nodes did not enforce this allowlist when a user-supplied base or e…

GitHub-GHSA

HIGH
n8n: Account Takeover via Unverified Email Claim in Token Exchange Embed Login
GHSA-8342-988q-86cr
pkg: n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact

In an n8n instance, when a validly-signed incoming token was matched to a local account by its email claim, the service did not check that the trusted key's permitted role ceiling covered that account, nor that the email claim was verified. As a result, anyone able to obtain a token accep…

GitHub-GHSA

HIGH
n8n: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner
GHSA-35q8-9mj6-wjmf
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact
n8n's Enterprise SSO instance-role provisioning maps a role claim asserted by the configured Identity Provider (IdP) to an n8n global role and applies it during authentication. The provisioning path did not prevent assignment of the `global:owner` role, unlike the token-exchange identity p…
CVE-2026-65016
GitHub-GHSA

HIGH
n8n: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution
GHSA-pm35-fqvh-cq5g
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact
The legacy expression evaluator's computed-member sanitizer can be bypassed by an authenticated user with workflow create or modify permissions. Successful exploitation grants the attacker host-level code execution as the n8n process.

The legacy expression engine is the default engine in …

CVE-2026-65591
GitHub-GHSA

HIGH
Netty: [Bzip2Decoder] Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang
GHSA-558v-64gr-wgg4
pkg: io.netty:netty-codec-compression, io.netty:netty-codec
eco: maven
published: Jul 22, 2026
The `Bzip2Decoder` handler in Netty's compression codec pipeline is vulnerable to a denial-of-service attack through a malformed bzip2 stream that permanently captures the event-loop thread in an infinite loop. The vulnerability exists in the run-length encoding (RLE) state machine within [`Bzip2Blo…
CVE-2026-59901
GitHub-GHSA

HIGH
Netty XML: Injection / Risky Sink — unconfigured XML factory with active DTD and entity handling
GHSA-4qhr-g3c6-fcfx
pkg: io.netty:netty-codec-xml, io.netty:netty-codec-xml
eco: maven
published: Jul 22, 2026
Any caller that can deliver bytes to a Netty channel pipeline containing `XmlDecoder` can send XML with a DOCTYPE declaration to a parser instantiated with no security configuration — but whether external entities are actually resolved depends on Aalto XML's async parser behavior, making this a co…
CVE-2026-56817
GitHub-GHSA

HIGH
Netty: [SpdyHttpDecoder] ByteBuf Reference Leak on RST_STREAM Leads to Native Memory Exhaustion
GHSA-jppx-w49h-x2qq
pkg: io.netty:netty-codec-http, io.netty:netty-codec-http
eco: maven
published: Jul 22, 2026
The `SpdyHttpDecoder` handler in Netty's SPDY-to-HTTP codec allocates a pooled `ByteBuf` when processing a client-initiated `SYN_STREAM` frame with `FLAG_FIN=0`, storing the partially-constructed `FullHttpRequest` in an internal map (`messageMap`) to accumulate subsequent `DATA` frames. When the rem…
CVE-2026-56745
GitHub-GHSA

HIGH
Netty: [codec-haproxy] Signed-Byte Sentinel Collision in HAProxyMessageDecoder Leads to Unbounded Memory Exhaustion
GHSA-q6cq-mhr2-jmr5
pkg: io.netty:netty-codec-haproxy, io.netty:netty-codec-haproxy
eco: maven
published: Jul 22, 2026
The `HAProxyMessageDecoder` in netty's `codec-haproxy` module performs protocol version detection by reading the 13th byte of the inbound stream as a signed Java `byte` and widening it to `int` without masking. When an attacker sends a PROXY protocol v2 binary prefix (`0D 0A 0D 0A 00 0D 0A 51 55 49 …
CVE-2026-55851
GitHub-GHSA

HIGH
gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
GHSA-hrxh-6v49-42gf
pkg: google.golang.org/grpc
eco: go
published: Jul 21, 2026
Multiple security vulnerabilities have been identified and addressed in grpc-go affecting the xDS RBAC authorization engine (internal/xds/rbac) and the HTTP/2 transport server implementation (internal/transport). These vulnerabilities could result in:

– Authorization Bypass (Fail-Open) when transla…

GitHub-GHSA

HIGH
jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
GHSA-r7wm-3cxj-wff9
pkg: com.fasterxml.jackson.core:jackson-core, com.fasterxml.jackson.core:jackson-core, com.fasterxml.jackson.core:jackson-core
eco: maven
published: Jul 21, 2026
## Summary

The fix released in jackson-core `2.18.6` and `2.21.1` for [GHSA-72hv-8253-57qq](https://github.com/FasterXML/jackson-core/security/advisories/GHSA-72hv-8253-57qq) (Number Length Constraint Bypass in Async Parser, published 2026-02-28) is incomplete. The fix commit `b0c428e6` (#1555) wir…

GitHub-GHSA

HIGH
Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts
GHSA-g9g6-qhrc-p3qc
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary

The OAuth2 sign-in callback in Gitea 1.26.1 unconditionally re-enables a locally-disabled account whenever the user authenticates through a linked external identity provider, silently undoing any administrator-initiated `Disable Account` action and issuing a fresh authenticated session …

CVE-2026-58422
GitHub-GHSA

HIGH
Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests
GHSA-fw57-jgch-pgf3
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary

The Locale middleware that runs in front of every unauthenticated request
calls `golang.org/x/text/language.ParseAcceptLanguage` on the raw
`Accept-Language` header without imposing a size or shape filter. The
underlying parser has quadratic-time behaviour on long lists of malformed
lan…

CVE-2026-58436
GitHub-GHSA

HIGH
Gitea: Privilege Escalation via Access Token Scope Escalation in API
GHSA-683j-3ff6-hh2x
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
Gitea's API endpoint for creating Personal Access Tokens (`POST /users/{username}/tokens`) is protected by a middleware (`reqBasicOrRevProxyAuth`) that is intended to require password-based authentication, preventing a compromised token from being used to mint new ones. However, when a token is pass…
CVE-2026-56654
GitHub-GHSA

HIGH
Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload
GHSA-6hm7-3pwj-22rm
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
Gitea's Debian package registry parser contains an unbounded decompression vulnerability in [ParseControlFile](https://github.com/go-gitea/gitea/blob/689ace1ce28fd74244b8aa335d9928cdbf6b22f9/modules/packages/debian/metadata.go#L140). When processing an uploaded `.deb` file, the parser decompresses `…
CVE-2026-56755
GitHub-GHSA

HIGH
GitPython unsafe clone option gate bypass through joined short options
GHSA-v396-v7q4-x2qj
pkg: GitPython
eco: pip
published: Jul 21, 2026
`GitPython` version `3.1.50` blocks unsafe `git clone` options such as `–upload-pack`, `-u`, `–config`, and `-c` unless callers explicitly pass `allow_unsafe_options=True`. However, the default unsafe-option gate does not recognize joined short-option forms such as `-u/path/to/helper`.

Git itself…

GitHub-GHSA

HIGH
websocket-driver-ruby: Denial of service via malformed Host header
GHSA-2×63-gw47-w4mm
pkg: websocket-driver
eco: rubygems
published: Jul 21, 2026
### Impact

If this library is used to implement a WebSocket server on top of a TCP server, by using the `WebSocket::Driver.server()` method, then a client can cause the server to crash by sending a `Host` header that is not a valid `host[:port]` string. When this happens, a `URI::InvalidURIError` e…

CVE-2026-61666
GitHub-GHSA

HIGH
PostgreSQL JDBC Driver: Silent channel-binding authentication downgrade via unsupported certificate algorithms
GHSA-j92g-9f8w-j867
pkg: org.postgresql:postgresql
eco: maven
published: Jul 21, 2026
### Impact

`channelBinding=require` connections can be silently downgraded from `SCRAM-SHA-256-PLUS` (with channel binding) to plain `SCRAM-SHA-256` (without it), losing the man-in-the-middle protection the setting is meant to guarantee. An attacker who can intercept the TLS connection triggers the…

CVE-2026-54291
GitHub-GHSA

HIGH
Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service
GHSA-vjc4-5qp5-m44j
pkg: pillow
eco: pip
published: Jul 20, 2026
### Summary
`src/libImaging/Jpeg2KDecode.c:853` accumulates `total_component_width` across every tile in a JPEG2000 image instead of recomputing it per tile. That accumulated value is then used in the `tile_bytes` calculation at `src/libImaging/Jpeg2KDecode.c:868`, which can make the decoder grow `s…
CVE-2026-59204
GitHub-GHSA

HIGH
Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)
GHSA-62p4-gmf7-7g93
pkg: pillow
eco: pip
published: Jul 20, 2026
## Summary

When Pillow loads an uncompressed image whose tile uses the `raw` codec and a mode in `Image._MAPMODES`, and the image was opened **from a filename**, it memory-maps the file and builds the image's row pointers directly into the mapping via `PyImaging_MapBuffer` (`src/map.c`). The per-ro…

CVE-2026-54058
GitHub-GHSA

HIGH
vLLM denial of service via prompt embeds on M-RoPE models
GHSA-33cg-gxv8-3p8g
pkg: vllm
eco: pip
published: Jul 20, 2026
### Summary
_Short summary of the problem. Make the impact and severity as clear as possible. For example: An unsafe deserialization vulnerability allows any unauthenticated user to execute arbitrary code on the server._

Sending a pure prompt embeds payload in a `/v1/completions` request with a mod…

CVE-2026-55514
GitHub-GHSA

MEDIUM
React Router: Open redirect leading to XSS
GHSA-jjmj-jmhj-qwj2
pkg: react-router-dom, react-router
eco: npm
published: Jul 23, 2026
Applications with open redirects could permit attacker crafted links to result in redirects to unexpected external location or XSS vectors.
CVE-2026-53668
GitHub-GHSA

MEDIUM
React Router: RSCErrorHandler Missing Protocol Validation (XSS)
GHSA-h8fp-f39c-q6mh
pkg: react-router
eco: npm
published: Jul 23, 2026
This is a follow up to https://github.com/remix-run/react-router/security/advisories/GHSA-8646-j5j9-6r62. React Router was alerted of a code path in the (unstable) RSC error handling path in which redirects from untrusted sources could still result in an XSS vector via attacker-supplied redirect ta…
CVE-2026-53667
GitHub-GHSA

MEDIUM
Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them
GHSA-x445-f3h2-j279
pkg: @auth/core, next-auth, next-auth
eco: npm
published: Jul 23, 2026
## Summary

Auth.js stores the OAuth/OIDC anti-CSRF checks (`state`, `nonce`, and the PKCE verifier) in global cookies that are not bound to the provider that created them. On callback, a check value minted during a sign-in started with one provider can satisfy the callback for a different provider,…

NVD

MEDIUM
CVE-2026-16615
CVE-2026-16615
pkg: oauth

published: Jul 22, 2026

A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated "code verifier" lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer th…
CWE: CWE-338
GitHub-GHSA

MEDIUM
Gitea: Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content
GHSA-66m4-5jjr-2rg5
pkg: gitea.dev
eco: go
published: Jul 21, 2026
## Affected product
Gitea — `services/repository/collaboration.go` (`DeleteCollaboration`) + webhook delivery

## Summary
When a collaborator with admin permission on a private repo creates a webhook, that webhook keeps firing
after the collaborator's access is revoked. Gitea's revocation cleanup …

CVE-2026-58440
GitHub-GHSA

MEDIUM
File Browser: Archive builder turns backslash filenames into path traversal (zip-slip)
GHSA-83xp-526h-j3ww
pkg: github.com/filebrowser/filebrowser/v2
eco: go
published: Jul 20, 2026
## Summary

The fix for `GHSA-gxjx-7m74-hcq8` / `CVE-2026-54093` (shipped in v2.63.6) added a `strings.ReplaceAll(nameInArchive, "\\", "/")` step to the archive builder; this was the advisory's recommended "Primary Fix." On a Linux host a backslash is a legal, non-separator filename character, so re…

CVE-2026-62843
NVD

MEDIUM
CVE-2026-60406
CVE-2026-60406
pkg: kubernetes

published: Jul 21, 2026

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where TimesTen In…
CWE: CWE-269
NVD

MEDIUM
CVE-2026-63729
CVE-2026-63729
pkg: node

published: Jul 21, 2026

The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedded by downstream consumers such as GNOME Evince contains a heap use-after-free vulnerability that allows attackers to crash applications or potentially execute arbitrary code by supplying a malformed .synctex or .synctex.gz file. …
CWE: CWE-416
GitHub-GHSA

MEDIUM
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API
GHSA-86cx-wwf4-phq4
pkg: github.com/OpenListTeam/OpenList/v4
eco: go
published: Jul 24, 2026
### Summary
An authorization bypass vulnerability exists in the file sharing mechanism of `Openlist`. Due to a flawed, non-separator-aware path validation check, an authenticated user can create share links for files outside their restricted base directory. This allows an attacker to bypass tenant/u…
GitHub-GHSA

MEDIUM
Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources
GHSA-c534-2w9c-x7fm
pkg: github.com/zxh326/kite
eco: go
published: Jul 24, 2026
## Summary

Kite versions 0.6.9 through 0.14.0 authorize Kubernetes proxy requests against the pod or service identified by the original route parameters. Encoded path traversal segments can cause the upstream URL to resolve to a different Kubernetes API endpoint after authorization.

## Impact

An …

GitHub-GHSA

MEDIUM
Cloudreve: Denial of Service – Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server
GHSA-g9j2-8w95-3vwv
pkg: github.com/cloudreve/Cloudreve/v4, github.com/cloudreve/Cloudreve/v3
eco: go
published: Jul 24, 2026
## Summary

Cloudreve's built-in image processor decodes user-supplied images with Go's standard-library decoders (`image/png`, `image/jpeg`, `image/gif`) and guards **only the compressed file size** — never the *decoded* pixel dimensions. Go's decoders allocate a pixel buffer sized `bytesPerPixel…

CVE-2026-55497
GitHub-GHSA

MEDIUM
Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config
GHSA-ffpj-xv5c-p3gw
pkg: open-webui
eco: pip
published: Jul 24, 2026
## Summary
Two regexes in `backend/open_webui/utils/middleware.py` that parse `<$skillId|label>` skill-mention tags backtrack in O(n²) on input that contains `<$` followed by a long run with no closing `>`. Both run synchronously, on the asyncio event loop, on **every** chat completion with no feat…
CVE-2026-59220
GitHub-GHSA

MEDIUM
Mongoose: Prototype pollution in mongoose update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter)
GHSA-664h-wqgq-64gw
pkg: mongoose, mongoose, mongoose
eco: npm
published: Jul 24, 2026
### Impact
_What kind of vulnerability is it? Who is impacted?_

Prototype pollution in update casting: passing a user-controlled update to a Mongoose update, like `MyModel.updateOne(filter, req.body)`, can cause Mongoose to set `$fullPath` and `$parentSchemaDocArray` on `Object.prototype`.

Example…

GitHub-GHSA

MEDIUM
LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges
GHSA-xx22-p4ch-683r
pkg: at.yawk.lz4:lz4-java, org.lz4:lz4-java
eco: maven
published: Jul 24, 2026
### Summary

Insufficient validation of byte array arguments in JNI-based XXHash implementations in lz4-java 1.11.0 and earlier allows callers to crash the JVM by passing an invalid array reference or invalid range to native XXHash methods.

This affects applications where an attacker can influence …

CVE-2026-59949
NVD

MEDIUM
CVE-2026-16798
CVE-2026-16798
pkg: oauth

published: Jul 24, 2026

Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with scoped job or script read permission to obtain another user's stored OAuth refresh token via job read responses that fail to strip t…
CWE: CWE-201
GitHub-GHSA

MEDIUM
Netty: STOMP CONNECT Frame Header Injection in Netty
GHSA-3g8r-4pfx-jmfh
pkg: io.netty:netty-codec-stomp, io.netty:netty-codec-stomp
eco: maven
published: Jul 22, 2026
# Security Vulnerability Report: STOMP CONNECT Frame Header Injection in Netty

## 1. Vulnerability Summary

| Field | Value |
|——-|——-|
| **Product** | Netty |
| **Version** | 4.2.12.Final (and all prior versions with codec-stomp) |
| **Component** | `io.netty.handler.codec.stomp.StompSubfr…

CVE-2026-59920
GitHub-GHSA

MEDIUM
Netty: Security Control Bypass via CORS Short-Circuit Failure
GHSA-6cqp-g7gg-8hr5
pkg: io.netty:netty-codec-http, io.netty:netty-codec-http
eco: maven
published: Jul 22, 2026
### Summary
Netty's CorsHandler provides a `shortCircuit()` configuration designed to reject unauthorized cross-origin requests immediately, acting as a security control before requests reach the application. However, due to a logical operator error in the origin evaluation process, this protection …
CVE-2026-56746
NVD

MEDIUM
CVE-2026-9737
CVE-2026-9737
pkg: express

published: Jul 22, 2026

During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly handle the meta expression case. This may lead to incorrect transformations leading to invariant failure.
CWE: CWE-617
NVD

MEDIUM
CVE-2026-13071
CVE-2026-13071
pkg: express

published: Jul 22, 2026

An authenticated user with read access can cause the mongod process to be terminated through certain aggregation expressions that execute server-side JavaScript. The issue involves improper memory handling during document processing.
CWE: CWE-416
NVD

MEDIUM
CVE-2026-13065
CVE-2026-13065
pkg: express

published: Jul 22, 2026

A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window function operator with a specific sortBy expression type to cause the mongod process to terminate abnormally, resulting in denial of service. The issue stems from insufficient validation of sort sp…
CWE: CWE-476
NVD

MEDIUM
CVE-2026-13056
CVE-2026-13056
pkg: express

published: Jul 22, 2026

Using expressions that generate large arrays it is possible to craft a query that creates very large intermediate objects in memory, causing the server to crash with OOM error.
CWE: CWE-1325
NVD

MEDIUM
CVE-2026-13055
CVE-2026-13055
pkg: express

published: Jul 22, 2026

The `$_internalIndexKey` aggregation expression can be used by any authenticated user to crash a MongoDB server (mongod). The expression fails to handle compound wildcard index specifications, triggering an internal consistency check that aborts the server process. The user must be able to run an ag…
CWE: CWE-617
NVD

MEDIUM
CVE-2026-13192
CVE-2026-13192
pkg: windows

published: Jul 22, 2026

In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of content submitted to the RadEditor PDF export feature may allow an authenticated attacker to trigger server-side requests to arbitrary hosts, resulting in outbound network connections and potential exposure of Windo…
CWE: CWE-918
NVD

MEDIUM
CVE-2026-63263
CVE-2026-63263
pkg: node

published: Jul 22, 2026

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Data Expansion (CAPEC-197). An authenticated user may submit a specially crafted query to the ES|QL engine that causes exponential CPU consumption during query evaluation. Because the resource …
CWE: CWE-400
NVD

MEDIUM
CVE-2026-63144
CVE-2026-63144
pkg: node

published: Jul 21, 2026

Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a specially crafted search request submitted by a low-privileged authenticated user. A user with read-level index access can submit a request that triggers unbounded recursive processing within the Elasticsearch quer…
CWE: CWE-674
NVD

MEDIUM
CVE-2026-60404
CVE-2026-60404
pkg: kubernetes

published: Jul 21, 2026

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTe…
CWE: CWE-400
NVD

MEDIUM
CVE-2026-60403
CVE-2026-60403
pkg: kubernetes

published: Jul 21, 2026

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTe…
CWE: CWE-400
NVD

MEDIUM
CVE-2026-60401
CVE-2026-60401
pkg: kubernetes

published: Jul 21, 2026

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where TimesTen In-…
CWE: CWE-284
NVD

MEDIUM
CVE-2026-60399
CVE-2026-60399
pkg: go

published: Jul 21, 2026

Vulnerability in Oracle GoldenGate (component: Receiver Service Executable). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle GoldenGate. Su…
CWE: CWE-400
NVD

MEDIUM
CVE-2026-10677
CVE-2026-10677
pkg: node

published: Jul 21, 2026

The CONFIG_USERSPACE syscall verifier z_vrfy_k_poll() in kernel/poll.c allocates a kernel-side copy of the user-supplied k_poll_event[] via z_thread_malloc() and then validates each event's object handle. Before this fix, validation used K_OOPS(K_SYSCALL_OBJ(…)) inline inside the loop, which kills…
CWE: CWE-401
GitHub-GHSA

MEDIUM
jackson-databind: @JsonView ypassed for @JsonUnwrapped container properties on deserialization
GHSA-5gvw-p9qm-jgwh
pkg: com.fasterxml.jackson.core:jackson-databind, tools.jackson.core:jackson-databind, com.fasterxml.jackson.core:jackson-databind
eco: maven
published: Jul 21, 2026
## Summary
`UnwrappedPropertyHandler.processUnwrapped()` replays the buffered JSON for a `@JsonUnwrapped` property by iterating its properties and calling `prop.deserializeAndSet()` with **no `prop.visibleInView(ctxt.getActiveView())` guard** — the exact guard `processUnwrappedCreatorProperties()`…
CVE-2026-59889
GitHub-GHSA

MEDIUM
Gitea: Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs
GHSA-frpw-3h2q-4jj6
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
**Author:** Prakhar Porwal
**Date:** 2026-05-24
**Target:** Gitea (self-hosted Git service)
**Branch tested:** `main` @ `b7e95cc48c` (development build, go1.26.3)
**Component:** `routers/api/v1/org/action.go` (org-level Actions API)
**OWASP:** API3:2023 Broken Object Property Level Authorization

–…

CVE-2026-57897
NVD

MEDIUM
CVE-2026-63140
CVE-2026-63140
pkg: node

published: Jul 21, 2026

Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted search request containing a null value in a specific query clause causes an internal assertion to be raised during query parsing. Because Elasticsearch treats ass…
CWE: CWE-617
NVD

MEDIUM
CVE-2026-63136
CVE-2026-63136
pkg: node

published: Jul 21, 2026

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A user with search privileges can submit a specially crafted search request that causes a data node to exhaust available heap memory, resulting in node unavailability and …
CWE: CWE-400
NVD

MEDIUM
CVE-2026-46556
CVE-2026-46556
pkg: python

published: Jul 21, 2026

FlaskBB is a Forum Software written in Python using the micro framework Flask. Prior to version 2.2.1, a Server-Side Request Forgery (SSRF) vulnerability in get_image_info() allows any authenticated user to force the server to send HTTP requests to arbitrary internal endpoints, including cloud metad…
CWE: CWE-918
NVD

MEDIUM
CVE-2026-16317
CVE-2026-16317
pkg: tls

published: Jul 21, 2026

Missing validation of the outer content_type byte on TLS 1.3 encrypted records in s2n-tls allows an active man-in-the-middle to silently discard individual application data records without either endpoint detecting the modification. RFC 8446 Section 5.2 requires that the outer content_type of all en…
CWE: CWE-354
GitHub-GHSA

MEDIUM
Gitea: Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint
GHSA-wwqq-x6w4-frm2
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary
An unbounded `io.ReadAll(ctx.Req.Body)` call in the NPM package tag API endpoint allows any authenticated user to crash the Gitea server by sending a single large HTTP request. The request body is read entirely into memory with no size limit, causing an Out-of-Memory (OOM) kill. With con…
CVE-2026-42931
GitHub-GHSA

MEDIUM
Gitea: Repository migration SSRF via multi-answer DNS allow-list bypass
GHSA-h2x6-g7q6-344v
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary

Gitea's repository migration URL validation can be bypassed when a migration hostname resolves to multiple IP addresses. The validation logic accepts the destination if **any** resolved IP is allowed, even if another resolved IP is loopback, private, or otherwise blocked. The later `git…

CVE-2026-58442
GitHub-GHSA

MEDIUM
Gitea: SSRF via HTTP Redirect in Repository Migration
GHSA-rqhx-647v-wx32
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
## Summary

Gitea 1.25.4 validates the initial URL provided to the repository migration endpoint (`POST /api/v1/repos/migrate`) and correctly blocks requests to internal addresses like `127.0.0.1` or RFC1918 ranges. However, if the initial URL points to an attacker-controlled server that responds wi…

CVE-2026-58418
GitHub-GHSA

MEDIUM
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
GHSA-25gq-j9jx-43pg
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
## Summary

The web handler `EditReleasePost` (`routers/web/repo/release.go`) reads form fields with prefix `attachment-edit-{uuid}` into a `map[uuid]newName`, passes that map to `release_service.UpdateRelease`, which writes the new name to the database via `repo_model.UpdateAttachmentByUUID` WITHOU…

CVE-2026-58428
NVD

MEDIUM
CVE-2026-56145
CVE-2026-56145
pkg: node

published: Jul 21, 2026

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user with permission to execute EQL sequence queries against an index they control can send a specially crafted query that triggers excessiv…
CWE: CWE-400
GitHub-GHSA

MEDIUM
jackson-databind: `@JsonView` bypass for creator properties with `@JsonTypeInfo(include=As.EXTERNAL_PROPERTY)`
GHSA-mhm7-754m-9p8w
pkg: com.fasterxml.jackson.core:jackson-databind, com.fasterxml.jackson.core:jackson-databind
eco: maven
published: Jul 21, 2026
## Summary

In `BeanDeserializer.deserializeUsingPropertyBasedWithExternalTypeId`, the active-view (`@JsonView`) filter was applied only to the regular bean-property branch; the creator-property branch performed no `creatorProp.visibleInView(activeView)` check. A constructor parameter annotated with…

GitHub-GHSA

MEDIUM
jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategy
GHSA-3pjw-73gf-8qr5
pkg: com.fasterxml.jackson.core:jackson-databind, com.fasterxml.jackson.core:jackson-databind, tools.jackson.core:jackson-databind
eco: maven
published: Jul 21, 2026
## Summary
For Java Records, `POJOPropertiesCollector._removeUnwantedIgnorals()` records a `@JsonIgnore`-annotated component under its original implicit name before `_renameUsing()` applies the `PropertyNamingStrategy`. After the rename, `_ignoredPropertyNames` still holds only the pre-rename name, …
CVE-2026-59888
GitHub-GHSA

MEDIUM
Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images
GHSA-fj7v-r99m-22gq
pkg: Pillow
eco: pip
published: Jul 20, 2026
### Summary

Pillow's TGA RLE encoder reads past its row buffer when saving a mode `"1"`
image. Adjacent process heap bytes can be copied into the generated TGA file.

The bug is reachable through the public save API:

“`python
im.save(out, format="TGA", compression="tga_rle")
“`

Older affected P…

CVE-2026-59198
GitHub-GHSA

MEDIUM
Microsoft Security Advisory CVE-2026-50659 – .NET Spoofing Vulnerability
GHSA-74jp-vm22-8q8x
pkg: Microsoft.NetCore.App.Runtime.linux-arm, Microsoft.NetCore.App.Runtime.linux-arm64, Microsoft.NetCore.App.Runtime.linux-musl-arm
eco: nuget
published: Jul 20, 2026
## Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET SMTP client (System.Net.Mail). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A spoofing vulnerability …

CVE-2026-50659
GitHub-GHSA

MEDIUM
Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses
GHSA-x756-g4x3-c64m
pkg: github.com/cloudreve/Cloudreve/v4, github.com/cloudreve/Cloudreve/v3
eco: go
published: Jul 20, 2026
## Summary

Cloudreve's remote download workflow accepts user-supplied URLs and passes them to the configured downloader without blocking loopback, localhost, IPv6 localhost, or redirect-to-loopback targets.

When the remote download permission is granted to a non-admin user group, a normal authenti…

CVE-2026-54562
NVD

MEDIUM
CVE-2026-63737
CVE-2026-63737
pkg: surrealdb surrealdb

published: Jul 20, 2026

SurrealDB versions before 3.1.5 contain a denial of service vulnerability where authenticated users can crash the server with queries containing long chains of operators. Attackers can submit queries with tens of thousands of chained operators that create unbounded expression trees, causing stack ov…
CWE: CWE-674
NVD

MEDIUM
CVE-2026-61217
CVE-2026-61217
pkg: ssl

published: Jul 21, 2026

Vulnerability in the Oracle Security Service product of Oracle Fusion Middleware (component: Oracle SSL API). The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows low privileged attacker with network access via TLS to compromise Oracle Security Service. …
CWE: CWE-284, CWE-290, CWE-352
GitHub-GHSA

MEDIUM
Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored
GHSA-c3jm-gv5r-9wcp
pkg: github.com/cloudreve/Cloudreve/v4, github.com/cloudreve/Cloudreve/v3
eco: go
published: Jul 24, 2026
## Summary

Cloudreve WOPI access tokens are generated as `<session-id>.<random-secret>`, but the WOPI middleware validates only the session id prefix and never compares the supplied token to the stored token. In addition, a WOPI viewer session does not store or enforce the requested viewer action. …

CVE-2026-62323
NVD

MEDIUM
CVE-2026-13067
CVE-2026-13067
pkg: tls

published: Jul 22, 2026

When PROXY protocol v2 is used on the Unix domain socket path, roles derived from X.509 client certificates may not be validated against the configured tlsCATrusts allow-list. This can result in unintended role assignments following MONGODB-X509 authentication. Affected scenarios require local acces…
CWE: CWE-863
GitHub-GHSA

MEDIUM
Gitea: Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)
GHSA-fj8v-hjwv-qm88
pkg: gitea.dev
eco: go
published: Jul 21, 2026
### Summary

`GetActionsUserRepoPermission` (`models/perm/access/repo_permission.go`) decides whether an Actions
task token may access a target repo. Its cross-repo branches each enforce a fork-PR discriminator —
**except the collaborative-owner branch**, which is missing the `!task.IsForkPullRequ…

CVE-2026-58416
GitHub-GHSA

MEDIUM
Gitea: SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL
GHSA-xmj7-xj85-hfc3
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary
Gitea's `restore-repo` CLI command restores a repository from a dump
directory/archive. When parsing `pull_request.yml` from that dump, the
`Head.CloneURL` field is used to add a git remote and fetch from it with
no validation, because the safety check that's supposed to guard it
(`Check…
CVE-2026-58441
NVD

MEDIUM
CVE-2026-46403
CVE-2026-46403
pkg: go

published: Jul 21, 2026

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, KVM exposes `ExecuteReadOnlyWithTypedArguments` as a read-only execution mechanism. The hook saves the previous read-only state, sets `runtime.SetReadOnly(true)`, executes the destination context, and then restore…
CWE: CWE-693
GitHub-GHSA

MEDIUM
File Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scope
GHSA-8wc8-hf36-mjh9
pkg: github.com/filebrowser/filebrowser/v2
eco: go
published: Jul 20, 2026
## Summary

`ScopedFs` confines every File Browser user to a scope directory. Its `within()` guard is meant to reject any operation that follows a symbolic link out of that scope. When the link target does not exist yet, the guard walks up to the nearest existing ancestor and validates that instead.…

CVE-2026-55668
GitHub-GHSA

MEDIUM
Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data
GHSA-fwjx-9p69-h25h
pkg: github.com/jandedobbeleer/oh-my-posh
eco: go
published: Jul 24, 2026
### Summary
Oh My Posh renders dynamic, potentially attacker-controlled strings (the current directory name, Git commit metadata, environment variable values, command output) into the prompt without neutralizing raw terminal control characters. An attacker who controls one of these values can inject…
GitHub-GHSA

MEDIUM
OpenAM Reflected XSS in the OAuth2/OIDC `wap` consent page
GHSA-vqxv-6xrh-49cp
pkg: org.openidentityplatform.openam:openam-oauth2
eco: maven
published: Jul 24, 2026
### Description
The OAuth2/OIDC consent page rendered for `display=wap` authorize requests reflected several request-derived values into the HTML response without escaping. An attacker who induces a user with an active OpenAM session to follow a crafted authorize link can execute arbitrary JavaScrip…
CVE-2026-62280
GitHub-GHSA

MEDIUM
ImageMagick: Policy Bypass in concatenate operation due to missing checks
GHSA-82mp-vp5c-9pf7
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Jul 24, 2026
The `-concatenate` operation is missing policy checks and that could result in both reading and writing to paths disallowed by the security policy.
CVE-2026-55628
GitHub-GHSA

MEDIUM
React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration
GHSA-337j-9hxr-rhxg
pkg: react-router
eco: npm
published: Jul 23, 2026
If application code allows attacker supplied input to overwrite certain aspects of errors caught by the SSR process, then it was possible for attacker to trigger unexpected constructor execution on the client which would trigger outbound network traffic. This is only possible with very specific (an…
CVE-2026-53666
NVD

MEDIUM
CVE-2026-65901
CVE-2026-65901
pkg: node

published: Jul 23, 2026

DOMPurify through 3.4.6 contains a cross-site scripting vulnerability in IN_PLACE mode that trusts attacker-controlled nodeName on live non-form nodes. Attackers can supply hostile live DOM objects with real script children whose observable nodeName is clobbered to appear as allowed elements, causin…
CWE: CWE-79
NVD

MEDIUM
CVE-2026-65900
CVE-2026-65900
pkg: express

published: Jul 23, 2026

DOMPurify versions >=3.0.0 and before 3.4.8, when configured with SAFE_FOR_TEMPLATES together with a DOM output mode (RETURN_DOM, RETURN_DOM_FRAGMENT, or IN_PLACE), fail to strip template expressions (e.g. ${evil}, {{evil}}, <%evil%>) inside <template> element content. The final normalization/scrub …
CWE: CWE-79
GitHub-GHSA

MEDIUM
setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+
GHSA-h35f-9h28-mq5c
pkg: setuptools
eco: pip
published: Jul 21, 2026
## Summary

When building a source distribution (`python -m build –sdist` / `setup.py sdist`), setuptools' `FileList` applies `MANIFEST.in` directives (`exclude`, `global-exclude`, `recursive-exclude`, `prune`) by matching a compiled glob against on-disk file names **byte-for-byte, with no Unicode …

CVE-2026-59890
GitHub-GHSA

MEDIUM
Mistune renderers/html.safe_url: HARMFUL_PROTOCOLS list misses legacy and chained schemes that historically chain to `javascript:` execution
GHSA-qfrw-5rxm-mhh2
pkg: mistune
eco: pip
published: Jul 20, 2026
## Summary

**Type:** URL-scheme allowlist gap. The `safe_url` filter only blocks the four schemes `javascript:`, `vbscript:`, `file:`, `data:`. Several other schemes are accepted into rendered `<a href="…">` and `<img src="…">` tags despite being known XSS vectors in legacy or chain-handling br…

CVE-2026-59929
GitHub-GHSA

MEDIUM
Mistune: XSS via percent-encoded javascript URI bypass in safe_url()
GHSA-8c25-4j27-2rv3
pkg: mistune
eco: pip
published: Jul 20, 2026
### Summary
An XSS vulnerability in Mistune allows bypassing of safe_url() protections via percent-encoded javascript URIs.

### Details
The vulnerability exists in HTMLRenderer.safe_url() in Mistune.

The function is intended to block harmful URL schemes such as "javascript:" by checking the prefi…

CVE-2026-59923
GitHub-GHSA

MEDIUM
FrontMCP: Server-Side Request Forgery (SSRF) in the OpenAPI adapter spec-change poller
GHSA-8q49-2h5h-434x
pkg: @frontmcp/adapters
eco: npm
published: Jul 24, 2026
## Summary

The OpenAPI adapter's spec-change **poller** (`OpenApiSpecPoller`) re-fetched the
configured spec `url` on a timer using a raw global `fetch()`, bypassing the SSRF
guard (`safeFetch` / `assertUrlSafe`) that `OpenAPIToolGenerator.fromURL()` applies
to the initial spec load. As a result, t…

NVD

MEDIUM
CVE-2026-55990
CVE-2026-55990
pkg: nlnetlabs unbound

published: Jul 22, 2026

In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' clause lists more 'dnscrypt-provider-cert:' files than there are matching 'dnscrypt-secret-key:' files, Unbound fills only the matched prefix and leaves the tail slots at the '0xdb' fill that libsodium's allocator writes in…
CWE: CWE-457
NVD

MEDIUM
CVE-2026-50046
CVE-2026-50046
pkg: nlnetlabs unbound

published: Jul 22, 2026

In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS server name used for DNS-over-TLS (DoT) forwarded queries is tied to a struct's ('serviced_query') lifetime but also referenced by another struct ('waiting_tcp'). When the owning struct is jostled out of the mesh while the DoT TCP stre…
CWE: CWE-416
NVD

MEDIUM
CVE-2026-60266
CVE-2026-60266
pkg: tls

published: Jul 21, 2026

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Orac…
CWE: CWE-200
NVD

MEDIUM
CVE-2026-46968
CVE-2026-46968
pkg: tls

published: Jul 21, 2026

Vulnerability in Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit vulnerability allo…
CWE: CWE-284
GitHub-GHSA

MEDIUM
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content
GHSA-6c6r-5xr4-cr5m
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
## Summary

Gitea's issue and comment attachment update paths accept attachment UUIDs without verifying that each attachment belongs to the target issue/comment repository. If an authenticated attacker knows a victim attachment UUID, they can re-link that attachment to an attacker-controlled issue o…

CVE-2026-57886
GitHub-GHSA

MEDIUM
Gitea: draft release attachment disclosure via missing web authorization
GHSA-q9pg-jj6x-j9p6
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary

Gitea's draft-release access control is enforced only on the API release endpoints (`/api/v1/repos/{owner}/{repo}/releases/{id}` and its `/assets/…` sub-routes) but not on the web-level UUID-based attachment endpoints (`/attachments/{uuid}`, `/{owner}/{repo}/attachments/{uuid}`, `/{ow…

CVE-2026-58432
NVD

MEDIUM
CVE-2026-59847
CVE-2026-59847
pkg: openssl

published: Jul 21, 2026

A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection.
CWE: CWE-1310
GitHub-GHSA

MEDIUM
Mistune: Arbitrary File Read via Include directive path traversal
GHSA-r4rv-85jg-w4mf
pkg: mistune
eco: pip
published: Jul 20, 2026
### Summary

A path traversal issue exists in mistune's `Include` directive when markdown files are processed using `md.read()`. A crafted include path can cause files outside the intended markdown directory to be accessed.

### Details

The issue occurs in the `Include.parse()` method where user-su…

CVE-2026-59924
NVD

MEDIUM
CVE-2026-45712
CVE-2026-45712
pkg: go

published: Jul 20, 2026

Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the screenshot/print proxy (/proxy?data=…) maintains a package-level assets map[string]MessageAssets cache, but reads the map without holding assetsMutex while a long-running cleanup goroutine and (re-entrant) CSS-re…
CWE: CWE-362, CWE-770
NVD

MEDIUM
CVE-2026-63226
CVE-2026-63226
pkg: node

published: Jul 23, 2026

Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement restrictions on SSH port forwarding, allowing to connect to arbitrary destinations. When SSH is enabled on an affected product, SSH port forwarding may be leveraged to connect to other node on the LAN.
CWE: CWE-923
NVD

MEDIUM
CVE-2026-61079
CVE-2026-61079
pkg: go

published: Jul 21, 2026

Vulnerability in Oracle GoldenGate (component: Libraries). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.2. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle GoldenGate executes to compromise …
CWE: CWE-20, CWE-284, CWE-362
GitHub-GHSA

MEDIUM
Budibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other Builders
GHSA-gh4h-34gr-87r7
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
## Summary

When an SSO-authenticated user tests an automation in the Budibase builder, their OAuth2 access token and refresh token are included in the automation test results. These results are broadcast via WebSocket to all builders connected to the same dev app and stored in an in-memory cache ac…

GitHub-GHSA

MEDIUM
ImageMagick: Code injection in HTML encoder due to incomplete fix of CVE-2026-25797
GHSA-hc76-7mpc-qjqh
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Jul 24, 2026
An incomplete fix of CVE-2026-25797 can result in code injection in the HTML encoder.
GitHub-GHSA

MEDIUM
Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder
GHSA-gcjf-9mgh-3p7g
pkg: io.netty:netty-codec-http, io.netty:netty-codec-http
eco: maven
published: Jul 22, 2026
# Security Vulnerability Report: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder

## 1. Vulnerability Summary

| Field | Value |
|——-|——-|
| **Product** | Netty |
| **Version** | 4.2.12.Final (and all prior versions with codec-http multipart) |
| **Component** | `io.net…

CVE-2026-59921
NVD

MEDIUM
CVE-2026-60409
CVE-2026-60409
pkg: kubernetes

published: Jul 21, 2026

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where TimesTen In…
CWE: CWE-284
GitHub-GHSA

MEDIUM
Quasar: Prototype pollution in the extend() utility
GHSA-3r53-75j5-3g7j
pkg: quasar
eco: npm
published: Jul 24, 2026
### Summary

`quasar@2.20.1`, the latest published version at the time of testing, appears to be vulnerable to prototype pollution through the public `extend()` utility exported from the package root.

When `extend(true, target, source)` is used for a deep merge, attacker-controlled object keys are …

NVD

MEDIUM
CVE-2026-60407
CVE-2026-60407
pkg: kubernetes

published: Jul 21, 2026

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where TimesTen I…
CWE: CWE-284
GitHub-GHSA

MEDIUM
AWS CLI: Overly permissive File Permissions
GHSA-wfp6-f47h-hxc3
pkg: awscli
eco: pip
published: Jul 24, 2026
### Summary
The AWS Command Line Interface (AWS CLI) is a unified tool for managing AWS services from the command line. Certain CLI subcommands wrote credential and configuration files with world-readable permissions on Unix-like systems with a default umask, allowing other local users on the same h…
CVE-2026-13769
GitHub-GHSA

MEDIUM
ImageMagick: Heap Buffer Over-Write in JP2 encoder when due to incorrect handling of arguments
GHSA-c4v7-w88g-m6c4
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Jul 24, 2026
Due to incorrect handling of arguments a heap buffer over-write can occur in the JP2 encoder.
CVE-2026-55597
GitHub-GHSA

MEDIUM
ImageMagick: Use-After-Free in crafted 8BIM when identifying an image
GHSA-ff5c-8x9r-8qcw
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Jul 24, 2026
When identifying an image with a crafted 8BIM profile with a specific format string a use-after-free will occur.
CVE-2026-55510
NVD

MEDIUM
CVE-2026-54422
CVE-2026-54422
pkg: python

published: Jul 24, 2026

In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.
CWE: CWE-522
GitHub-GHSA

MEDIUM
Netty: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address
GHSA-wh89-7897-x99h
pkg: io.netty:netty-codec-haproxy, io.netty:netty-codec-haproxy
eco: maven
published: Jul 22, 2026
# Security Vulnerability Report: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address in Netty

## 1. Vulnerability Summary

| Field | Value |
|——-|——-|
| **Product** | Netty |
| **Version** | 4.2.12.Final (and all prior versions with codec-haproxy) |
| **Component** | `io.netty.handler.co…

CVE-2026-59919
GitHub-GHSA

MEDIUM
Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests
GHSA-v6w6-358x-2433
pkg: github.com/cloudreve/Cloudreve/v4, github.com/cloudreve/Cloudreve/v3
eco: go
published: Jul 24, 2026
## Summary

Cloudreve exposes two admin node test endpoints under the `Admin.Read` OAuth scope. These endpoints accept attacker-controlled node definitions and cause Cloudreve to make outbound server-side network requests. This allows an OAuth client authorized only for `Admin.Read` to trigger opera…

GitHub-GHSA

MEDIUM
Open WebUI: Arena task endpoints can bypass underlying model access controls
GHSA-m3qf-58wf-w979
pkg: open-webui
eco: pip
published: Jul 24, 2026
## Summary

An authenticated non-admin user with read access to an arena wrapper model can reach a restricted underlying model through task endpoints such as `/api/v1/tasks/moa/completions`.

The normal chat route resolves arena models before the final chat dispatch and therefore re-checks the selec…

CVE-2026-59225
GitHub-GHSA

MEDIUM
Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete
GHSA-2xwm-4h2q-ggfx
pkg: open-webui
eco: pip
published: Jul 24, 2026
## Summary

Current `main` and `v0.9.6` still allow an authenticated user to turn read-only access to another user's file into write/delete access by attaching that file ID to an attacker-controlled workspace model.

This is an incomplete-fix variant of `GHSA-vjqm-6gcc-62cr`. The current fix adds `_…

CVE-2026-59212
NVD

MEDIUM
CVE-2026-57530
CVE-2026-57530
pkg: node

published: Jul 24, 2026

Milkdown before 7.21.3 contains a stored cross-site scripting vulnerability in the @milkdown/preset-commonmark and @milkdown/components packages that allows attackers with document write access to execute arbitrary JavaScript in the browser context of any user who opens the document or clicks a rend…
CWE: CWE-79
NVD

MEDIUM
CVE-2026-16415
CVE-2026-16415
pkg: google chrome

published: Jul 21, 2026

Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)
CWE: CWE-20
GitHub-GHSA

MEDIUM
Gitea LFS Deploy-Key Privilege Escalation
GHSA-rh79-75qm-gwjr
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
## Vulnerability Header

| Field | Value |
| ——————- | ———————————————————– |
| Vulnerability Title | Gitea LFS Deploy-Key Privilege Escalation |
| Severity Rating…

CVE-2026-58435
NVD

MEDIUM
CVE-2026-47671
CVE-2026-47671
pkg: jwt

published: Jul 21, 2026

Nhost is an open source Firebase alternative with GraphQL. In versions of Nhost CLI prior to 1.46.0, the hidden `nhost configserver` used by `nhost dev` exposes the Mimir GraphQL API with dummy authorization directives and permissive CORS. When a developer is running the local development environmen…
CWE: CWE-306
GitHub-GHSA

MEDIUM
Tornado vulnerable to Header Injection and XSS via reason argument
GHSA-pr2v-jx2c-wg9f
pkg: tornado
eco: pip
published: Jul 20, 2026
# Header injection and XSS via `reason` argument

## Summary

The `reason` argument (used by both `RequestHandler.set_status` and `tornado.web.HTTPError` is designed to allow applications to pass custom "reason" phrases (the "Not Found" in `HTTP/1.1 404 Not Found`) to the HTTP status line (mainly fo…

CVE-2025-67724
GitHub-GHSA

MEDIUM
kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating a request against a `content` parameter whose media type has no schema
GHSA-jpcw-4wr7-c3vq
pkg: github.com/getkin/kin-openapi
eco: go
published: Jul 24, 2026
| Field | Value |
|—|—|
| Ecosystem | Go |
| Package | `github.com/getkin/kin-openapi` |
| Affected versions | `<= 0.143.0` (introduced in `v0.2.0`, PR #90, 2019-05-07; reproduced on `HEAD` `30e2923`) |
| Patched versions | 0.144.0 |

### Summary

`openapi3filter.ValidateRequest` contains a …

GitHub-GHSA

MEDIUM
Budibase: Account Enumeration via Login Lockout Response Differential
GHSA-cr7p-cr3q-h5cm
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
## Summary

The login lockout mechanism in Budibase creates an observable response discrepancy that allows unauthenticated attackers to enumerate valid email addresses. When an existing user's account is locked after 5 failed login attempts, the server returns a distinct `403` response with `X-Accou…

GitHub-GHSA

MEDIUM
webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules
GHSA-g35j-m5xg-vh3q
pkg: github.com/quic-go/webtransport-go
eco: go
published: Jul 24, 2026
## Summary

An attacker can cause excessive memory allocation in webtransport-go by sending an unknown WebTransport capsule with a large payload. The implementation skips unknown capsules by reading the entire capsule body into memory, instead of draining it without retaining the data. This can lead…

CVE-2026-57497
GitHub-GHSA

MEDIUM
Open WebUI: Account enumeration via observable login timing discrepancy
GHSA-7rw5-9f7q-xj36
pkg: open-webui
eco: pip
published: Jul 24, 2026
### Summary

The `/api/v1/auths/signin` endpoint leaked whether an email address belonged to a registered account through a response-time side channel. Password verification ran bcrypt only when the email was found in the database; for a non-existent email the request returned early without hashing.…

CVE-2026-59218
GitHub-GHSA

MEDIUM
Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names
GHSA-mfg7-5gfp-c4w3
pkg: io.netty:netty-codec-dns, io.netty:netty-codec-dns
eco: maven
published: Jul 24, 2026
### Summary
A memory leak can be caused in Netty's DNS codec by sending malicious DNS packets containing invalid domain names. Because the leak occurs incrementally per packet, sustained malicious requests will cause a gradual Denial of Service.

### Details
Inside `io.netty.handler.codec.dns.Abstra…

GitHub-GHSA

MEDIUM
Russh: client wrong-length X25519 `clone_from_slice` panic (pre-auth DoS)
GHSA-g9hv-x236-4qp3
pkg: russh
eco: rust
published: Jul 24, 2026
### Summary
A malicious SSH server can crash a `russh` client session with a single
malformed key-exchange reply, causing a pre-authentication Denial-of-Service
before the server host key is verified. The embedding process itself stays
up, but the connection is killed deterministically.

### Details…

GitHub-GHSA

MEDIUM
Russh: Pre-auth remote panic via all-zero Curve25519 peer public value (encode_mpint OOB)
GHSA-5xvq-cp9x-6p6r
pkg: russh
eco: rust
published: Jul 24, 2026
A pre-authentication denial-of-service panic in `russh` 0.62.2 (commit
`c4be19f1915c8682f4615c3fd50008512b474491`, current default branch `main` as
of 2026-07-22). An unauthenticated client sends a single `SSH_MSG_KEX_ECDH_INIT`
whose `Q_C` is 32 zero bytes. russh's Curve25519 KEX does not reject th…
GitHub-GHSA

MEDIUM
@fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths
GHSA-8pvw-jcv7-9cmj
pkg: @fastify/static
eco: npm
published: Jul 24, 2026
### Impact

`@fastify/static` evaluates the `allowedPath` callback before normalizing dot segments and duplicate slashes in the pathname used for file resolution. Non-canonical pathnames such as `//file`, `/./file`, or `/public/../private/file` bypass `allowedPath` filtering while resolving to the i…

CVE-2026-7120
GitHub-GHSA

MEDIUM
node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection
GHSA-r292-9mhp-454m
pkg: tar
eco: npm
published: Jul 24, 2026
## Summary
`node-tar` (npm `tar`) contains an uncontrolled-recursion stack-exhaustion DoS in the internal `mapHas` helper used by `filesFilter`. When a consumer calls `tar.t(…)` or `tar.x(…)` with a non-empty member-selection list, node-tar installs a filter that closes over the recursive `mapHa…
GitHub-GHSA

MEDIUM
PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path
GHSA-9xwg-3r6f-jcx2
pkg: pymdown-extensions
eco: pip
published: Jul 24, 2026
### Summary

The `b64` extension inlines images referenced by `<img src="…">` as base64 data URIs. When resolving the `src` path it joins it onto the configured `base_path` with `os.path.normpath` and opens the result directly, with no check that the resolved path stays inside `base_path`. A `src`…

CVE-2026-61632
GitHub-GHSA

MEDIUM
SvelteKit: Big remote form function payloads can cause Node process to crash
GHSA-wqjv-9729-c5q2
pkg: @sveltejs/kit
eco: npm
published: Jul 24, 2026
Big remote form function payloads can cause the Node process to crash. Doing this repeatedly can cause DoS.
GitHub-GHSA

MEDIUM
ImageMagick: Stack Overflow in MVG decoder due to missing depth check.
GHSA-mx48-2qq3-23hf
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Jul 24, 2026
A missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided.
CVE-2026-55594
NVD

MEDIUM
CVE-2026-12353
CVE-2026-12353
pkg: tls

published: Jul 23, 2026

An unauthenticated attacker could trigger an Out of Memory condition to crash the Java process for RHCS by repeatedly sending HTTP requests to the TLS endpoint. Depending on how the RHCS server is configured, a manual intervention to restart it may prove necessary.
CWE: CWE-772
GitHub-GHSA

MEDIUM
ImageMagick: Information Disclosure in MNG decoder because allocated memory is left unchanged
GHSA-8g53-9m3c-69xg
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Jul 23, 2026
In the MNG decoder there is a possible heap information disclosure because part of the pixels are left unchanged.
CVE-2026-53467
NVD

MEDIUM
CVE-2026-25466
CVE-2026-25466
pkg: go

published: Jul 23, 2026

Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04 versions.
CWE: CWE-862
GitHub-GHSA

MEDIUM
Eclipse Jetty: Path parameter traversal
GHSA-w7x5-g22v-xqhr
pkg: org.eclipse.jetty:jetty-util, org.eclipse.jetty:jetty-util
eco: maven
published: Jul 22, 2026
### Description (as reported)

#### Summary

In Jetty 12.1.8, org.eclipse.jetty.util.URIUtil.canonicalPath() may leave dot-dot path segments unnormalized when a semicolon path parameter marker is followed by a slash and a dot
segment.

A minimal example is:

`/public;/../admin/secret`

In my local…

CVE-2026-8384
GitHub-GHSA

MEDIUM
Eclipse Jetty: HTTP Authority/Host mismatch
GHSA-7p3p-8qv8-m2vh
pkg: org.eclipse.jetty:jetty-server, org.eclipse.jetty:jetty-server, org.eclipse.jetty:jetty-server
eco: maven
published: Jul 22, 2026
#### Summary

Jetty currently accepts HTTP/2 and HTTP/3 requests where the regular
Host header and the pseudo-header :authority
do not match. As a result, the same request can carry two different host identities
through Jetty:

– logic based on `HttpURI` / `Request.getServerName(request)` uses `:aut…

CVE-2026-6790
NVD

MEDIUM
CVE-2026-13070
CVE-2026-13070
pkg: tls

published: Jul 22, 2026

A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP response from a remote peer during the TLS handshake. OCSP stapling validation is enabled by default for outgoing TLS connections. Affected scenarios require the remote peer to hold a cer…
CWE: CWE-476
NVD

MEDIUM
CVE-2026-50251
CVE-2026-50251
pkg: nlnetlabs unbound

published: Jul 22, 2026

In NLnet Labs Unbound up to and including version 1.25.1, when 'unwanted-reply-threshold' is enabled (set to any value greater than zero), glue records of 0.0.0.0/::0 can short-circuit Unbound, on systems that can direct such traffic, by issuing DNS queries and receiving seemingly unwanted replies s…
CWE: CWE-184
NVD

MEDIUM
CVE-2026-60394
CVE-2026-60394
pkg: go

published: Jul 21, 2026

Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle GoldenGate. Successful attacks of this…
CWE: CWE-200
NVD

MEDIUM
CVE-2026-46917
CVE-2026-46917
pkg: tls

published: Jul 21, 2026

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalV…
CWE: CWE-284
NVD

MEDIUM
CVE-2026-16318
CVE-2026-16318
pkg: tls

published: Jul 21, 2026

The QUIC transport parameters extension handler in s2n-tls incorrectly uses s2n_alloc instead of s2n_realloc to store the peer's transport parameters. When a TLS 1.3 connection goes through a HelloRetryRequest, the handler is called twice on the same connection. On the second call, s2n_alloc zeroes …
CWE: CWE-401
GitHub-GHSA

MEDIUM
Gitea: Private Repository Existence Disclosure via go-get Meta Endpoint
GHSA-p4mj-98mv-xq26
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
| Field | Value |
|——-|——-|
| **Affected File** | `routers/web/repo/githttp.go`, `services/context/repo.go` |
| **Affected Functions** | `httpBase()`, `EarlyResponseForGoGetMeta()` |
| **Affected Lines** | `githttp.go:63–66`, `services/context/repo.go:374–396` |
| **Prerequisite** | None…
CVE-2026-58507
GitHub-GHSA

MEDIUM
Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service
GHSA-pg7v-jwj7-p798
pkg: pillow
eco: pip
published: Jul 20, 2026
### Summary

Pillow's EPS parser (PIL/EpsImagePlugin.py) accepts a negative byte count in the %%BeginBinary directive. A crafted EPS file can cause Image.open() to seek backwards to the same directive and parse it repeatedly, resulting in an infinite loop and CPU denial of service.

The issue is tri…

CVE-2026-59203
GitHub-GHSA

MEDIUM
Mistune directives/include: mutual `.. include::` recursion crashes the renderer with `RecursionError`, denial of service via two attacker-controlled markdown files
GHSA-8mpj-m6qm-5qr8
pkg: mistune
eco: pip
published: Jul 20, 2026
## Summary

**Type:** Uncontrolled recursion via mutual include. The `Include` directive checks for direct self-reference (`a.md` cannot include `a.md`), but does not detect indirect cycles. Two markdown files that include each other (`a.md` → includes `b.md` → includes `a.md`) cause unbounded r…

CVE-2026-59927
NVD

MEDIUM
CVE-2026-55219
CVE-2026-55219
pkg: go

published: Jul 20, 2026

Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.5, the credit payment implementation in app/Livewire/Invoices/Show.php executes a pessimistic row lock (lockForUpdate()) outside of an active database transaction. Because MySQL/MariaDB …
CWE: CWE-362
GitHub-GHSA

MEDIUM
changedetection.io is vulnerable to unauthenticated static path traversal
GHSA-9jj8-v89v-xjvw
pkg: changedetection.io
eco: pip
published: Jul 20, 2026
## Summary
The `/static/<group>/<filename>` route accepts `group=".."`, which causes `send_from_directory("static/..", filename)` to execute. This moves the base directory up to `/app/changedetectionio`, enabling **unauthenticated local file read** of application source files (e.g., `flask_app.py`).…
CVE-2026-25527
NVD

MEDIUM
CVE-2026-11804
CVE-2026-11804
pkg: linux

published: Jul 23, 2026

Improper handling of insufficient permissions or privileges vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Privilege Abuse.

This issue affects Niagara Framework: before 4.14.6, before 4.15.5; Niagara Enterprise Se…

CWE: CWE-280
GitHub-GHSA

MEDIUM
ImageMagick: Integer Overflow in JNX decoder causes heap buffer over-write when processing extremly large files on 32-bit builds
GHSA-h22j-f9xw-xjjm
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-x86
eco: nuget
published: Jul 24, 2026
When processing an extremely large JNX file on 32-bit platforms an integer overflow will happen that can cause a heap buffer over-write.
CVE-2026-62946
GitHub-GHSA

MEDIUM
ImageMagick: Heap Buffer Over-Write in fx operation
GHSA-422r-8c97-xcg4
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Jul 24, 2026
A heap buffer over-write can occur in the fx operation by passing a crafted argument.
CVE-2026-62363
GitHub-GHSA

MEDIUM
Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role Users
GHSA-fcrw-f7gg-6g9f
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
## Summary

The `/api/users/metadata` and `/api/users/metadata/:id` endpoints in `@budibase/server` return full global user profiles to any user with POWER role or above. For SSO-authenticated users (OIDC, Google), the response includes `oauth2.accessToken` and `oauth2.refreshToken` fields, leaking …

GitHub-GHSA

MEDIUM
Gitea: Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints
GHSA-fq2p-5p22-8g6j
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary
A personal access token restricted with the public-only scope can still retrieve private organization membership and organization permission details for its own account through organization-listing endpoints. This bypass breaks the intended guarantee that such tokens are limited to publi…
CVE-2026-58429
GitHub-GHSA

MEDIUM
@backstage/plugin-auth-backend: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass
GHSA-38hq-7×33-php4
pkg: @backstage/plugin-auth-backend
eco: npm
published: Jul 24, 2026
### Impact
The allowlist matching used by the experimental dynamic client registration and client ID metadata document (CIMD) features in `@backstage/plugin-auth-backend` matched glob patterns against the full URL string. A * wildcard could therefore match across URL component boundaries: a pattern …
GitHub-GHSA

MEDIUM
ImageMagick: Heap Buffer Over-Write in morphology operation when an invalid kernel is provided
GHSA-f5m7-cqgw-8hm7
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Jul 24, 2026
An invalid kernel can cause a heap buffer over-write when performing a morphology operation with a user supplied kernel.
CVE-2026-62343
GitHub-GHSA

MEDIUM
ImageMagick: Policy Bypass due to an incomplete fix of CVE-2026-49219
GHSA-56m6-8q75-f2rw
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Jul 24, 2026
An incomplete fix of CVE-2026-49219 could result in a policy bypass.
GitHub-GHSA

MEDIUM
ImageMagick: Infinite Loop in connected-components when providing invalid arguments
GHSA-qhmf-7fc4-8q3h
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: Jul 24, 2026
When providing invalid arguments to the connected-components option an infinite loop will occur.
CVE-2026-55595
NVD

MEDIUM
CVE-2026-65904
CVE-2026-65904
pkg: node

published: Jul 23, 2026

DOMPurify through 3.3.3 fails to sanitize DOM elements passed via IN_PLACE mode when the element originates from a different window/realm (e.g., an iframe's contentDocument). A cross-realm instanceof check in the private _isNode() function returns false for foreign-realm nodes, causing DOMPurify to …
CWE: CWE-754
GitHub-GHSA

MEDIUM
Loofah: SVG `href` attribute bypasses local-reference restriction
GHSA-9wjq-cp2p-hrgf
pkg: loofah
eco: rubygems
published: Jul 21, 2026
## Summary

Loofah's HTML5 sanitizer restricted only the `xlink:href` attribute on certain SVG elements to local, same-document references. Browsers also accept a plain `href` attribute as an alternative to the deprecated `xlink:href` per the SVG 2 spec, but Loofah did not apply the same restriction…

GitHub-GHSA

MEDIUM
Trix: Stored XSS via HTMLParser attribute injection on paste
GHSA-53g2-mvcc-q9x3
pkg: trix, action_text-trix
eco: npm
published: Jul 24, 2026
### Impact

The Trix editor, in versions prior to 2.1.18, is vulnerable to XSS when crafted HTML is pasted into the editor. The `HTMLParser` processed a mock attachment, a `<span>` carrying an empty `data-trix-attachment="{}"`. The empty attachment object caused the element to bypass attachment hand…

GitHub-GHSA

MEDIUM
Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path
GHSA-4x4j-2g7c-83w6
pkg: Pillow
eco: pip
published: Jul 20, 2026
### 1. Summary

`WindowsViewer.get_command()` constructs a `cmd.exe` shell command by directly embedding a
file path into an f-string without escaping. The result is passed to
`subprocess.Popen(…, shell=True)`. Shell metacharacters in the file path — most
importantly a double-quote (`"`) that br…

CVE-2026-55798
NVD

MEDIUM
CVE-2026-15786
CVE-2026-15786
pkg: ssl

published: Jul 23, 2026

The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 7.8.6.6 via the 'imploded' parameter parameter. This makes it possible for authenticated attackers, with ad…
CWE: CWE-22
NVD

MEDIUM
CVE-2026-61084
CVE-2026-61084
pkg: go

published: Jul 21, 2026

Vulnerability in Oracle GoldenGate (component: Libraries). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle GoldenGate executes to compromise Ora…
CWE: CWE-284
GitHub-GHSA

MEDIUM
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search
GHSA-p6ph-3jx2-3337
pkg: github.com/OpenListTeam/OpenList/v4
eco: go
published: Jul 24, 2026
### Summary
An authorization bypass and information disclosure vulnerability exists in the search API of `Openlist`. Due to a non-separator-aware path check and unfiltered backend counting, a low-privileged user can bypass their assigned `BasePath` restrictions to discover and access metadata of fil…
GitHub-GHSA

MEDIUM
Budibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappings
GHSA-4qcj-m5wp-jmf4
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
## Summary

The `GET /api/global/groups` endpoint on the worker service has no role-based authorization middleware. Any authenticated user (including BASIC role) can enumerate all user groups in the tenant, including their role mappings, user memberships, builder permissions, and the isDefault flag.…

GitHub-GHSA

MEDIUM
Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching
GHSA-qg3f-8x3j-ggf2
pkg: open-webui
eco: pip
published: Jul 24, 2026
## Summary

The administrator-configured `WEB_FETCH_FILTER_LIST` (the allow/block list applied to server-side web fetches: RAG URL ingestion, URL-to-markdown, web-search content fetch) matches hostnames incorrectly, so the filter can be bypassed.

## Details

`is_string_allowed` (`backend/open_webui…

CVE-2026-59223
GitHub-GHSA

MEDIUM
Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and receives activity events for unshared siblings
GHSA-w8x7-h2px-xmq8
pkg: github.com/cloudreve/Cloudreve/v4, github.com/cloudreve/Cloudreve/v3
eco: go
published: Jul 24, 2026
## Summary

When an authenticated recipient of a **single-file** share opens the file event stream (`GET /api/v4/file/events?uri=<share-root>`), Cloudreve validates the URI by listing it and then subscribes the caller to `parent.ID()`. For a single-file share, the share navigator resolves the bare …

CVE-2026-55499
GitHub-GHSA

MEDIUM
Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails
GHSA-8r7f-r8hj-r3rv
pkg: github.com/cloudreve/Cloudreve/v4, github.com/cloudreve/Cloudreve/v3
eco: go
published: Jul 24, 2026
## Summary

`GET /api/v4/user/search` is available to any logged-in user. The service calls `userClient.SearchActive`, but despite its name that method filters only by email/nickname keyword and **never adds a `StatusActive` predicate** — while the sibling lookups `GetActiveByID` and `GetActiveBy…

CVE-2026-55496
GitHub-GHSA

MEDIUM
Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account
GHSA-49h3-cwhj-4737
pkg: github.com/cloudreve/Cloudreve/v4, github.com/cloudreve/Cloudreve/v3
eco: go
published: Jul 24, 2026
## Summary

Cloudreve's WOPI `PUT_RELATIVE` handler treats `X-WOPI-SuggestedTarget` as a path, not a filename. It splits the header on `/` and joins the segments onto the source file's directory with `URI.JoinRaw`, which feeds Go's `url.JoinPath`. `url.JoinPath` resolves `.`/`..` segments, so a sla…

CVE-2026-55495
GitHub-GHSA

MEDIUM
Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)
GHSA-7r7x-gjvr-448g
pkg: open-webui
eco: pip
published: Jul 24, 2026
# Open WebUI upload metadata can add files to knowledge bases without write permission

## Summary

Open WebUI's file upload background processing trusts the client-supplied `metadata.knowledge_id` value and inserts a `knowledge_file` association before validating that the uploading user has write a…

CVE-2026-59217
GitHub-GHSA

MEDIUM
Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission
GHSA-rqj7-6wrp-6g2g
pkg: open-webui
eco: pip
published: Jul 24, 2026
## Summary

`POST /api/v1/images/edit` performed no authorization beyond requiring a verified account. Every other image-editing surface in Open WebUI enforces the global image-edit switch and the per-user image-generation permission — the `/api/v1/images/generations` route, the built-in `edit_ima…

CVE-2026-59227
GitHub-GHSA

MEDIUM
Russh: Post-auth remote panic via pty-req with more than 130 terminal-mode records
GHSA-cqjc-rmpq-xprq
pkg: russh
eco: rust
published: Jul 24, 2026
## Summary

A post-authentication denial-of-service panic in `russh` 0.62.2 (commit
`c4be19f1915c8682f4615c3fd50008512b474491`, current default branch `main` as
of 2026-07-22). An authenticated client sends a `pty-req` channel request
carrying more than 130 terminal-mode records. The parser uses a f…

GitHub-GHSA

MEDIUM
SvelteKit: Prototype pollution in file input deletion path in remote-function forms
GHSA-866w-xmhq-wj7x
pkg: @sveltejs/kit
eco: npm
published: Jul 24, 2026
If you use remote form functions, have an input field of type `file`, and accept arbitrary user-controlled path names for the field, then you are vulnerable to a prototype pollution attack where the attacker can remove e.g. methods on the prototype.
NVD

MEDIUM
CVE-2026-60410
CVE-2026-60410
pkg: kubernetes

published: Jul 21, 2026

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTe…
CWE: CWE-400
NVD

MEDIUM
CVE-2026-60408
CVE-2026-60408
pkg: kubernetes

published: Jul 21, 2026

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTe…
CWE: CWE-200
NVD

MEDIUM
CVE-2026-60397
CVE-2026-60397
pkg: go

published: Jul 21, 2026

Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the ha…
CWE: CWE-404
NVD

MEDIUM
CVE-2026-60395
CVE-2026-60395
pkg: go

published: Jul 21, 2026

Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle GoldenGate. Succe…
CWE: CWE-200
GitHub-GHSA

MEDIUM
Gitea: GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private
GHSA-q423-49rw-g9mh
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
## Summary

GHSA-8fwc-qjw5-rvgp ("Gitea may send release notification emails for private repositories to users whose access has been revoked", fix in PR #36319 / commit 8a98ac22) added `repo_model.ClearRepoWatches` as a defense for the state transition public→private. The cleanup was wired into `s…

CVE-2026-58510
GitHub-GHSA

MEDIUM
Gitea: Public-only API token restriction is not enforced on team API routes
GHSA-h56g-4qw7-2mxg
pkg: gitea.dev
eco: go
published: Jul 21, 2026
### Summary

Gitea's `/api/v1/teams/{id}` API routes do not correctly enforce the `public-only` access token restriction.

A `public-only` token is intended to limit API access to public repositories and public organizations. However, several team API routes continue to return private team repositor…

CVE-2026-58431
GitHub-GHSA

MEDIUM
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)
GHSA-6cqf-375w-639g
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary

Gitea's RSS/Atom feed handlers accept API-token Basic auth but perform **no token-scope or
public-only enforcement**. A personal access token that is correctly blocked (HTTP 403) from a
private repository on `/raw`, `/media`, `/archive`, and `/releases/download/…` — because it is
ma…

CVE-2026-50105
GitHub-GHSA

MEDIUM
Gitea: Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents
GHSA-cp3q-vrj2-ghhh
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary
A personal access token (PAT) or OAuth2 token that does **not** carry the
`repository` scope or that is **public-only** is correctly rejected (HTTP 403)
by the recently hardened web content routes (archive download, raw/media file
download, and repository RSS/Atom feeds). However, the re…
CVE-2026-58444
GitHub-GHSA

MEDIUM
Gitea: API access token scope enforcement bypass on repository RSS/Atom feed endpoints leaks private repository commit data
GHSA-3pww-vcvm-3gmj
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary
A Gitea personal access token (PAT) restricted to a non-repository scope (e.g. `read:issue`) can read the commit history of any private repository the token owner can access, via the repository RSS/Atom feed endpoints. The same token is correctly denied (403) on `/raw`, `/media`, `/archi…
CVE-2026-27761
GitHub-GHSA

MEDIUM
Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)
GHSA-vxv2-8j6r-pcpg
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
## Live reproduction against Gitea 1.26.1

Setup: Gitea 1.26.1 docker stack with two users (`admin` and `victim`) and two OAuth applications owned by different users:

“`
Client A: id=5dda747d-7fdd-4694-85ff-ce4f893ce51e owner=admin
Client B: id=588f778f-4a41-4914-ae01-85d776c369db owner=victim…

CVE-2026-58425
GitHub-GHSA

MEDIUM
Gitea: Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118
GHSA-7p4h-3gxq-x3h3
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
## Summary

After [PR #37118](https://github.com/go-gitea/gitea/pull/37118) / **CVE-2026-25714**
(`fix: Unify public-only token filtering in API queries and repo access checks`,
merged 2026-05-18, backport `#37773` to 1.26.2 — the May 2026 unification pass
for public-only token filtering, reporter…

CVE-2026-56443
GitHub-GHSA

MEDIUM
Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times`
GHSA-qf2f-qh6p-7v89
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
## Summary
CVE-2026-20800 fixed private-info leakage to revoked users only for the notification endpoint. Two
sibling endpoints that return data keyed on the caller's own relationship still do not re-check repo
access at output time:
– `GET /api/v1/user/starred` — `getStarredRepos()` computes a pe…
CVE-2026-59766
NVD

MEDIUM
CVE-2026-16336
CVE-2026-16336
pkg: oauth

published: Jul 21, 2026

A vulnerability was found in trinodb trino 481. Affected is an unknown function of the file core/trino-main/src/main/java/io/trino/server/ExternalUriInfo.java of the component OAuth2/OIDC. Performing a manipulation of the argument redirect_uri results in open redirect. It is possible to initiate the…
CWE: CWE-601
GitHub-GHSA

MEDIUM
Mistune toc / TableOfContents directive: heading IDs use predictable `toc_N` numbering with no slugification, allowing collision with attacker-controlled `id="toc_N"` content
GHSA-2hm2-hc3v-44h9
pkg: mistune
eco: pip
published: Jul 20, 2026
## Summary

**Type:** Predictable identifier generation. The `toc` plugin and `TableOfContents` directive both default to generating heading IDs of the form `toc_1`, `toc_2`, `toc_3`, … with no input-derived component. An attacker who can place a heading anywhere in the document can predict which …

CVE-2026-59930
NVD

MEDIUM
CVE-2026-63768
CVE-2026-63768
pkg: oauth

published: Jul 20, 2026

cal.diy through 6.2.0 contains an open redirect vulnerability in the conferencing OAuth callback endpoint that allows attackers to redirect users to arbitrary URLs by crafting malicious state parameters. Attackers can exploit the unsigned state parameter and onErrorReturnTo field to silently redirec…
CWE: CWE-601
NVD

MEDIUM
CVE-2026-13724
CVE-2026-13724
pkg: go

published: Jul 20, 2026

Client-Side Enforcement of Server-Side Security vulnerability in Gobito Informatics Technologies Engineering Industry and Trade Ltd. Co. Corporate Training Management System allows Input Data Manipulation.

This issue affects Corporate Training Management System: before dd1a9df64.

CWE: CWE-602
NVD

MEDIUM
CVE-2026-63761
CVE-2026-63761
pkg: surrealdb surrealdb

published: Jul 20, 2026

SurrealDB before 3.1.0 silently substitutes the ES384 algorithm when a JWT access method is configured with ALGORITHM ES512 (DEFINE ACCESS … TYPE JWT ALGORITHM ES512), because the underlying jsonwebtoken crate (v10.x) has no ES512 variant and the mapping defaults to ES384 without any error, warnin…
CWE: CWE-327
NVD

MEDIUM
CVE-2026-63749
CVE-2026-63749
pkg: surrealdb surrealdb

published: Jul 20, 2026

SurrealDB versions before 3.1.0 contain an authentication bypass vulnerability in LIVE SELECT subscriptions where permission expressions referencing $value, $before, $after, or $event are evaluated against attacker-controlled bindings instead of actual documents. Authenticated subscribers can bind c…
CWE: CWE-863
GitHub-GHSA

MEDIUM
Shescape: Home-directory disclosure in assignment context on Unix with Dash
GHSA-q53c-4prm-w95q
pkg: shescape, shescape
eco: npm
published: Jul 24, 2026
### Impact

This impacts users of Shescape on Unix systems that explicitly configure `shell` to Dash, or `true` when the default shell is Dash, using the `escape` and `escapeAll` APIs in assignments prefixed to a command.

An attacker may be able to obtain the location of the home directory and, dep…

GitHub-GHSA

MEDIUM
Shescape: Path disclosure on Unix with Zsh
GHSA-6v4m-fw66-8r4x
pkg: shescape, shescape
eco: npm
published: Jul 24, 2026
### Impact

This impacts users of Shescape on Unix systems that explicitly configure `shell` to Zsh, or `true` when the default shell is Zsh, using the `escape` and `escapeAll`. The Zsh options `EXTENDED_GLOB` and `MAGIC_EQUAL_SUBST` exacerbate the problem.

In certain case, an attacker can leverage…

GitHub-GHSA

MEDIUM
Hubuum client library (Rust): Configured custom transports may be bypassed, exposing credentials and network traffic
GHSA-qqc3-94qv-7fw3
pkg: hubuum_client
eco: rust
published: Jul 24, 2026
## Summary

When an application configures hubuum_client with ClientBuilder::with_transport, several client operations still use the built-in reqwest client directly. The bypass includes password login, bearer-token validation, authentication-provider discovery, health and readiness probes, export-o…

GitHub-GHSA

MEDIUM
Hubuum client library (Rust): Authenticated requests may escape the configured base path through redirects
GHSA-f45q-w629-wr25
pkg: hubuum_client
eco: rust
published: Jul 24, 2026
## Impact

The built-in async and blocking clients used reqwest's default redirect policy. `BaseUrl` constrains the initial request to the configured origin and path prefix, but redirect processing occurs after that validation. reqwest retains sensitive headers when a redirect changes only the path …

GitHub-GHSA

MEDIUM
Budibase: SSRF via bare fetch() in uploadUrl during AI table generation
GHSA-hfhx-w8p8-4hc7
pkg: @budibase/server
eco: npm
published: Jul 24, 2026
# Budibase: SSRF via bare fetch() in uploadUrl during AI table generation

## Summary

The `uploadUrl()` function in `packages/server/src/utilities/fileUtils.ts` uses a bare `fetch(url)` call without any SSRF protection. This function is invoked when the AI table generation feature processes LLM-gen…

GitHub-GHSA

MEDIUM
Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials
GHSA-gh7p-78×6-jw6m
pkg: open-webui
eco: pip
published: Jul 24, 2026
### Summary

The channel members endpoint serializes and returns **full user models** for channel participants, including settings objects. A normal user in a DM can retrieve admin-only sensitive configuration such as webhook URLs and tool server key material (`settings.ui.toolServers[].key`), which…

CVE-2026-59222
GitHub-GHSA

MEDIUM
cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag
GHSA-gcjh-h69q-9w9g
pkg: github.com/google/cel-go
eco: go
published: Jul 24, 2026
The function `ext.NativeTypes(ParseStructTag("json"))` does not honour the `encoding/json` skip directive `json:"-"`. Fields tagged `json:"-"` are registered in the CEL type system under the literal name `"-"` and are readable from any user-submitted CEL expression via `dyn(obj)["-"]`.

Additionall…

GitHub-GHSA

MEDIUM
Microsoft Kiota: Path traversal in generated plugin manifest static_template.file reference (percent-encoding bypass)
GHSA-p5rm-jg5c-8c77
pkg: Microsoft.OpenApi.Kiota
eco: nuget
published: Jul 24, 2026
### Impact

Kiota generates AI plugin manifests from an OpenAPI description. When the description contains an `x-ai-capabilities` response semantics `static_template` (or the adaptive-card extension `x-ai-adaptive-card`), the `file` reference is written into the generated manifest's `response_semant…

GitHub-GHSA

MEDIUM
Valibot: record() issue paths can make flatten() throw for inherited Object property names
GHSA-5qjj-4xww-7phc
pkg: valibot
eco: npm
published: Jul 24, 2026
## Summary

`valibot` 1.4.1 can throw a `TypeError` inside its `flatten()` helper when validation issues contain attacker-controlled object keys such as `toString`, `valueOf`, or `hasOwnProperty`.

The issue is reachable through normal `record()` validation. `record()` intentionally filters `__proto…

CVE-2026-59952
GitHub-GHSA

MEDIUM
c3p0 can, in combination with other libraries, compose to a "sink" for deserialization gadgets
GHSA-w6w4-rjh9-9r58
pkg: com.mchange:c3p0
eco: maven
published: Jul 23, 2026
### Impact

The JDBC spec defines the interface `DataSource`, with a method called `getConnection()`, and `ConnectionPoolDataSource`, with a method called `getPooledConnection()`. These methods are potentially dangerous. One way or another they trigger calls into JDBC drivers, which themselves are c…

CVE-2026-55223
GitHub-GHSA

MEDIUM
React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)
GHSA-wrjc-x8rr-h8h6
pkg: react-router
eco: npm
published: Jul 23, 2026
This is a follow up to [CVE-2025-68470](https://github.com/remix-run/react-router/security/advisories/GHSA-9jcx-v3wj-wh4m). React Router was alerted to certain scenarios in which the fix there was incomplete so there still existed some scenarios where attacker supplied paths passed to navigation me…
CVE-2026-53669
GitHub-GHSA

MEDIUM
pypdf: Possible long runtimes for repeated malformed cross-reference entries
GHSA-55h5-xmcq-c37v
pkg: pypdf
eco: pip
published: Jul 23, 2026
### Impact

An attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires cross-reference streams with repeated malformed cross-reference streams.

### Patches

This has been fixed in [pypdf==6.14.0](https://github.com/py-pdf/pypdf/releases/tag/6.14.0).

### Wor…

CVE-2026-59937
GitHub-GHSA

MEDIUM
pypdf: Possible large memory usage for wrong image dimensions
GHSA-5qjq-93h5-hrgp
pkg: pypdf
eco: pip
published: Jul 23, 2026
### Impact

An attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires loading images where the declared size values are much too large compared to the actual data.

### Patches

This has been fixed in [pypdf==6.14.0](https://github.com/py-pdf/pypdf/rele…

CVE-2026-59938
GitHub-GHSA

MEDIUM
n8n: Snowflake Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation
GHSA-652q-gvq3-74qv
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact

The n8n Snowflake node's Execute Query operation interpolated expression values directly into the SQL string, making queries built with untrusted data susceptible to SQL injection.

Exploitation requires that a workflow author has already embedded untrusted expression data directly in a r…

GitHub-GHSA

MEDIUM
n8n: PostgresTrigger Node SQL Injection Allows Authenticated Users to Execute Arbitrary SQL on Connected PostgreSQL Instances
GHSA-jqwr-vx3p-r266
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact

The Postgres Trigger node interpolated user-supplied identifier parameters (channel, function, and trigger names) into SQL statements without proper escaping, so an authenticated user could inject arbitrary SQL executed against the connected PostgreSQL database with the configured credent…

GitHub-GHSA

MEDIUM
n8n: Cross-Tenant Module-Cache Poisoning in the JS Task Runner
GHSA-9cmh-xcqm-5hqr
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact

n8n's JavaScript task runner shared one module cache across all users' Code-node executions, so a user able to run a Code node could poison a cached module and alter other users' Code-node executions on the same runner, affecting their confidentiality, integrity, or availability.

This is…

GitHub-GHSA

MEDIUM
JupyterLab: PyPI extension blocklist package-name canonicalization bypass
GHSA-89vp-jrxv-24w8
pkg: jupyterlab, jupyterlab
eco: pip
published: Jul 22, 2026
JupyterLab's PyPI extension manager enforces `blocked_extensions_uris` by comparing the requested install name to blocklist entries with a custom string normalization that is weaker than PyPI package-name canonicalization. An authenticated user can request a PyPI-equivalent spelling such as `Jupyter…
GitHub-GHSA

MEDIUM
JupyterLab PluginManager lock-rule enforcement bypass
GHSA-h5v5-8746-g7mm
pkg: jupyterlab, jupyterlab
eco: pip
published: Jul 22, 2026
JupyterLab's plugin manager exposes administrator controls intended to prevent users from enabling or disabling selected plugins. Two server-side enforcement gaps let an authenticated user bypass those controls with direct requests to `/lab/api/plugins`.

### Impact

Users could workaround the plugi…

GitHub-GHSA

MEDIUM
Next.js: Cache confusion of response bodies for requests with bodies
GHSA-68g3-v927-f742
pkg: next, next
eco: npm
published: Jul 22, 2026
## Impact

A server-side `fetch` with a request body may return a cached **response** body from a different request to the same URL but different body. Confidential data in the `POST`'s **response** body would then leak to unauthorized requests. Though the request itself will not be deduped.

This o…

CVE-2026-64648
GitHub-GHSA

MEDIUM
Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences
GHSA-4633-3j49-mh5q
pkg: next, next
eco: npm
published: Jul 22, 2026
## Impact

A server-side `fetch` with a request body may return a cached **response** body from a different request to the same URL but different body. Confidential data in the `POST`'s **response** body would then leak to unauthorized requests. Though the request itself will not be deduped.

This i…

CVE-2026-64647
GitHub-GHSA

MEDIUM
Next.js: Unbounded Server Action payload in Edge runtime
GHSA-4c39-4ccg-62r3
pkg: next, next
eco: npm
published: Jul 22, 2026
## Impact

Requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive memory consumption if that Server Actions uses the Edge runtime

## Workarounds

If you cannot upgrade, ensure your hosting provider limits the request's body size. 5 MiB should …

CVE-2026-64646
GitHub-GHSA

MEDIUM
Next.js: Denial of Service in the Image Optimization API using SVGs
GHSA-q8wf-6r8g-63ch
pkg: next, next
eco: npm
published: Jul 22, 2026
### Impact

When self-hosting Next.js with the default image loader, the Image Optimization API can optimize remotely hosted images if configured (not enabled by default). If those images contain malicious content, they can cause CPU exhaustion in `/_next/image` endpoints.

– If you are using `conf…

CVE-2026-64644
GitHub-GHSA

MEDIUM
Next.js: Unauthenticated disclosure of internal Server Function endpoints
GHSA-955p-x3mx-jcvp
pkg: next, next
eco: npm
published: Jul 22, 2026
## Impact

In Next.js applications using App Router, Server Actions (`use server`) or `use cache` endpoints can be disclosed bypassing any authentication on the pages where these endpoints are usually used.

Server Action IDs can be disclosed to unauthenticated users via publicly served client artif…

CVE-2026-64643
GitHub-GHSA

MEDIUM
Eclipse Jetty: Cross-Request Leakage for trailers on HTTP/1.1 keep-alive connections
GHSA-f4v5-65jj-pcr2
pkg: org.eclipse.jetty:jetty-server, org.eclipse.jetty:jetty-server
eco: maven
published: Jul 22, 2026
### Description

> FINDING — MEDIUM (HTTP/1.1 keep-alive connections with trailers)
> HttpConnection._trailers Cross-Request Leakage (Never Reset Between Requests)
>
> Location:
> jetty-core/jetty-server/src/main/java/org/eclipse/jetty/server/internal/
> HttpConnection.java:107, 1157-1161, 11…

CVE-2026-10051
GitHub-GHSA

MEDIUM
n8n: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data
GHSA-89gh-3pgc-v5h2
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact
Custom HTTP headers configured in credentials for certain LLM sub-nodes (including OpenAI, Anthropic, and Lemonade) are masked in the n8n UI but are written in plaintext into execution data during workflow runs. Any authenticated user with access to the execution data for an affected workf…
CVE-2026-65589
GitHub-GHSA

MEDIUM
LiteLLM: Arbitrary file write via path traversal in Skills archive extraction
GHSA-5jmr-gcrj-2c9q
pkg: litellm
eco: pip
published: Jul 22, 2026
### Impact

LiteLLM Skills archive extraction did not sufficiently validate file paths from uploaded skill ZIP archives. An authenticated user with access to LiteLLM LLM API routes, or a key whose `allowed_routes` includes `/v1/skills`, `anthropic_routes`, or `llm_api_routes`, could upload a crafted…

CVE-2026-59820
GitHub-GHSA

MEDIUM
n8n: Unauthenticated Endpoint Allows Cancellation of Any User's Active Test Webhook
GHSA-33q9-f52j-gc75
pkg: n8n
eco: npm
published: Jul 22, 2026
## Impact
The `DELETE /${restEndpoint}/test-webhook/:id` route is registered before the authentication middleware is applied, allowing any unauthenticated network caller who knows a workflow ID to cancel that workflow's active test webhook registration.

The impact is limited to disrupting in-progr…

CVE-2026-65014
GitHub-GHSA

MEDIUM
n8n: GraphQL Node Bypasses "Allowed HTTP Request Domains" Restriction
GHSA-gq66-9cw5-j5jm
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact
The GraphQL node did not enforce the "Allowed HTTP Request Domains" restriction on HTTP-based credentials (such as Header Auth, Basic Auth, Query Auth, and OAuth), unlike the HTTP Request node. An authenticated user able to create or edit workflows could therefore point the node's endpoint…
CVE-2026-65596
GitHub-GHSA

MEDIUM
n8n: Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows via Missing OAuth Authorization Check
GHSA-q5xf-xhwf-cwqf
pkg: n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact
The OAuth 2.1 consent and token-issuance flow introduced in n8n 2.27.0 does not verify that the authenticated user has access to the workflow referenced as the OAuth resource. A member-level user can register an OAuth client, self-approve consent for another user's `n8n OAuth2`-protected M…
CVE-2026-65594
GitHub-GHSA

MEDIUM
n8n: computer-use Shell Sandbox Not Enforced on Linux and Windows
GHSA-fpg6-x68q-5793
pkg: n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact
The shell tool in the `@n8n/computer-use` package applied its sandbox restrictions only on macOS. On Linux and Windows, shell commands executed by the tool ran without any filesystem or network restrictions, allowing unrestricted access to the host filesystem and network from within the co…
CVE-2026-65590
GitHub-GHSA

MEDIUM
n8n: Authenticated Users Can Exhaust Temporary Disk Storage via Data-Table File Uploads
GHSA-w867-jm58-p9pv
pkg: n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact
An authenticated user can repeatedly upload files to the data-table upload endpoint, bypassing the per-request quota check, which does not account for files already written to the shared temporary directory. This causes temporary files to accumulate on disk until the periodic cleanup runs,…
CVE-2026-58661
GitHub-GHSA

MEDIUM
n8n: Improper Authorization Allows Authenticated Users to Assign Workflows to Folders in Other Projects
GHSA-2xgm-wc4g-5jvg
pkg: n8n
eco: npm
published: Jul 22, 2026
## Impact
An authenticated user with permission to create workflows in one project could bypass project/folder authorization boundaries during workflow creation. By supplying a crafted request payload, the user could associate a newly created workflow with a folder belonging to a different project t…
CVE-2026-59253
GitHub-GHSA

MEDIUM
n8n: External Secrets Accessible via Workflow Expressions Outside Credentials
GHSA-2434-3x6q-8r99
pkg: n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact
External secrets were incorrectly resolved in workflow node expressions, where they are not intended to be available. An authenticated user with project editor access could read the plaintext value of external secrets by referencing them in a node expression, without needing explicit secre…
CVE-2026-59254
GitHub-GHSA

MEDIUM
n8n: MySQL v1 Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation
GHSA-hwmj-qg4v-cvg9
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact
The legacy MySQL v1 node's `executeQuery` operation substitutes evaluated `{{ … }}` expression values directly into the raw SQL string without parameterization. If a workflow uses this operation with expression-sourced values in the query and is connected to an externally-reachable trigg…
CVE-2026-59257
GitHub-GHSA

MEDIUM
n8n: External Secrets Permission Bypass via Expression Parser Mismatch
GHSA-jp7m-xcgx-57qm
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact
Due to a mismatch between the static validation check and the runtime expression engine, an authenticated user with credential create or update permissions, but without the `externalSecret:list` scope, could embed external secret references into credentials in forms the validation did not …
CVE-2026-59259
GitHub-GHSA

MEDIUM
n8n: Path-Confinement Bypass in computer-use search_files Allows Reading Files Outside the Base Directory
GHSA-pf2q-pxhf-hgmw
pkg: n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact

The component `@n8n/computer-use` file-search tool confined searches to a configured base directory. A crafted search pattern could bypass the confinement check and expand to locations outside that directory, causing the tool to return the names and contents of files anywhere the daemon's…

GitHub-GHSA

MEDIUM
n8n: Prototype Pollution via VM Expression Engine Sandbox Escape Leads to Denial of Service
GHSA-hx4h-vr3m-45vh
pkg: n8n, n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact

An authenticated user able to create or edit a workflow expression could abuse the expression engine's array-element access to obtain a reference to a host built-in and pollute its prototype in the main n8n process, leading to a denial of service.

Both self-hosted and cloud instances run…

GitHub-GHSA

MEDIUM
n8n: SSRF Protection Bypass via MCP Client Node
GHSA-vhf8-cg2h-cg3p
pkg: n8n, n8n
eco: npm
published: Jul 22, 2026
## Impact

On an n8n instance with SSRF protection enabled, the MCP Client node sent requests to a user-supplied endpoint without routing them through that protection and without pinning the resolved address. An authenticated user who could create or edit a workflow could therefore cause the server …

GitHub-GHSA

MEDIUM
Netty: [codec-http2] Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass
GHSA-c69g-56f8-xwqj
pkg: io.netty:netty-codec-http2, io.netty:netty-codec-http2
eco: maven
published: Jul 22, 2026
Netty's HTTP/2-to-HTTP/1.x translation layer (`Http2StreamFrameToHttpObjectCodec` and `InboundHttp2ToHttpAdapter`) fails to deduplicate or validate `Host` headers when an HTTP/2 client supplies both the `:authority` pseudo-header and a literal `host` header in a single HEADERS frame. The translator …
CVE-2026-59900
GitHub-GHSA

MEDIUM
Netty: [HttpContentEncoder] Unbounded Per-Connection Queue Growth via HTTP/1.1 Pipelining Leads to Denial of Service
GHSA-q4f6-jm68-57ww
pkg: io.netty:netty-codec-http, io.netty:netty-codec-http
eco: maven
published: Jul 22, 2026
### Impact
`HttpContentEncoder` (the superclass of the production handler `HttpContentCompressor`) maintains a per-channel `ArrayDeque<CharSequence>` named `acceptEncodingQueue` that accumulates attacker-controlled data without any size limit. The queue is filled on the I/O thread for every inbound …
CVE-2026-59899
GitHub-GHSA

MEDIUM
Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation
GHSA-4mp9-239f-g9hg
pkg: io.netty:netty-codec-http, io.netty:netty-codec-http
eco: maven
published: Jul 22, 2026
## Summary
An attacker can force WebSocket upgrade via the lax V07 (or V08) handshaker by sending `Sec-WebSocket-Version: 7` and omitting `Connection: Upgrade` / `Upgrade: websocket` headers, completing a protocol switch that a proxy would not recognize as an Upgrade request and enabling HTTP reques…
CVE-2026-59898
GitHub-GHSA

MEDIUM
Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations
GHSA-cj75-f6xr-r4g7
pkg: rails-html-sanitizer
eco: rubygems
published: Jul 21, 2026
## Summary

There is a possible cross-site scripting vulnerability in rails-html-sanitizer when the sanitizer is configured to allow an SVG reference element such as `<use>`. See related [GHSA-9wjq-cp2p-hrgf](https://github.com/flavorjones/loofah/security/advisories/GHSA-9wjq-cp2p-hrgf) in Loofah, w…

GitHub-GHSA

MEDIUM
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata
GHSA-2wm4-vwp6-v7xc
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary

Gitea has robust SSRF protection via `hostmatcher.NewDialContext()` for webhook and migration clone URLs, which validates resolved IPs at the TCP dial level. However, three code paths use raw `http.Get()` (Go's `DefaultClient`) which completely bypasses this protection, enabling SSRF to…

CVE-2026-59765
GitHub-GHSA

MEDIUM
Gitea: Private org member list leaked via /members API endpoint — incomplete fix for PR #38145
GHSA-prr9-9mp4-5gp2
pkg: gitea.dev
eco: go
published: Jul 21, 2026
## Summary
PR #38145 fixed ListPublicMembers and IsPublicMember but missed
ListMembers. Any authenticated user can enumerate ALL members
(not just public ones) of a private organization.

## Affected Versions
<= v1.26.4 (latest) and main branch

## Root Cause
routers/api/v1/org/member.go — ListM…

CVE-2026-58427
GitHub-GHSA

MEDIUM
Gitea SSH Key Parser Denial of Service
GHSA-4xjf-493q-98p3
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
Gitea's SSH key ingestion endpoint accepts keys in RFC 4716 (SSH2) format and normalises them before storage. The normalisation function contains an O(N²) string concatenation loop with no input size limit, meaning a single malicious key submission can force the server to perform an amount of work …
CVE-2026-56657
GitHub-GHSA

MEDIUM
Gitea: Local File Inclusion via file:// URI in Migration Restore
GHSA-5ggr-2f2h-jmvm
pkg: gitea.dev
eco: go
published: Jul 21, 2026
# Local File Inclusion via file:// URI in Migration Restore

Target: go-gitea/gitea
Component: services/migrations/gitea_uploader.go, modules/uri/uri.go
Severity: High
Affected Versions: <= v1.22.x (all releases), master as of latest commit
Researchers:
– Isa Can — Eresus Security (https://github.…

CVE-2026-58420
GitHub-GHSA

MEDIUM
Gitea: OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes
GHSA-mg4f-x9v4-6h2p
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary

The OIDC userinfo endpoint (`GET /login/oauth/userinfo`) accepts Gitea API tokens as bearer credentials but does not enforce API token scopes before returning identity claims.

A personal access token scoped only to `read:misc` can successfully retrieve user information from the OIDC us…

CVE-2026-55982
GitHub-GHSA

MEDIUM
Gitea: REST API exposes organization membership of private organizations to public
GHSA-jr5x-6h83-wrxf
pkg: gitea.dev
eco: go
published: Jul 21, 2026
### Summary

The endpoint "/orgs/{org}/public_members/{username}" + GET exposes organization membership of public members in a private organization.

### PoC

1. Spin up the nightly container of Gitea.
2. Perform the default installation.
3. Register a new user (let's call this user "user1").
4. Cr…

CVE-2026-58417
GitHub-GHSA

MEDIUM
Gitea: API Fork Endpoint Authorization Bypass Allows Organization Members to Bypass Repository Creation Restrictions
GHSA-rjvx-x5h2-6px5
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
### Summary

The API endpoint used to fork repositories into organizations performs a weaker authorization check than the corresponding web UI and other repository creation endpoints.

When a repository is forked into an organization through the API, the endpoint only verifies that the user is an or…

GitHub-GHSA

MEDIUM
Gitea: Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads
GHSA-9mq6-mqjj-c2c5
pkg: code.gitea.io/gitea
eco: go
published: Jul 21, 2026
## Summary

Hello Gitea Security Team,

Thank you for your continued work on Gitea. I would like to responsibly report a potential availability-impact issue that I observed in Gitea’s Arch package registry implementation.

During local testing, I noticed that Gitea records non-dot regular file ent…

CVE-2026-59763
GitHub-GHSA

MEDIUM
Mistune: XSS via unescaped class option in Admonition directive
GHSA-g97x-gvcm-x72h
pkg: mistune
eco: pip
published: Jul 20, 2026
In `src/mistune/directives/admonition.py`, the `render_admonition()` function concatenates the `:class:` option directly into the HTML class attribute without escaping (lines 63-68).

This allows attribute injection and XSS even when `HTMLRenderer(escape=True)` is used.

The directive name parameter…

CVE-2026-59926
GitHub-GHSA

MEDIUM
pillow-heif: Integer Overflow in Encode Path Buffer Validation Leads to Heap Out-of-Bounds Read
GHSA-5gjj-6r7v-ph3x
pkg: pi-heif, pillow-heif
eco: pip
published: Jul 20, 2026
### Summary

An integer overflow in the encode path buffer validation of `_pillow_heif.c` allows an attacker to bypass bounds checks by providing large image dimensions, resulting in a heap out-of-bounds read. This can lead to information disclosure (server heap memory leaking into encoded images) o…

CVE-2026-28231