Vulnerability Digest — May 25, 2026 · 29 Critical · 10 Exploited






Vulnerability Digest — Monday, May 25, 2026


Security Report

Monday, May 25, 2026  ·  Last 7 days  ·  Min severity: MEDIUM
Total Findings
216
Critical
29
High
90
Actively Exploited
10
CISA-KEV10
GitHub-GHSA206
Findings sorted by severity
CISA-KEV

CRITICAL
Drupal Core SQL Injection Vulnerability
CVE-2026-9082
pkg: Drupal Core

published: May 22, 2026

Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
Langflow Origin Validation Error Vulnerability
CVE-2025-34291
pkg: Langflow Langflow

published: May 21, 2026

Langflow contains an origin validation error vulnerability in which an overly permissive CORS configuration combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint…
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability
CVE-2026-34926
pkg: Trend Micro Apex One

published: May 21, 2026

Trend Micro Apex One (on-premise) contains a directory traversal vulnerability that could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
Microsoft Windows Buffer Overflow Vulnerability
CVE-2008-4250
pkg: Microsoft Windows

published: May 20, 2026

Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
Microsoft DirectX NULL Byte Overwrite Vulnerability
CVE-2009-1537
pkg: Microsoft DirectX

published: May 20, 2026

Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability
CVE-2009-3459
pkg: Adobe Acrobat and Reader

published: May 20, 2026

Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
Microsoft Internet Explorer Use-After-Free Vulnerability
CVE-2010-0249
pkg: Microsoft Internet Explorer

published: May 20, 2026

Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product util…
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
Microsoft Internet Explorer Use-After-Free Vulnerability
CVE-2010-0806
pkg: Microsoft Internet Explorer

published: May 20, 2026

Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users shou…
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
Microsoft Defender Link Following Vulnerability
CVE-2026-41091
pkg: Microsoft Defender

published: May 20, 2026

Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA-KEV

CRITICAL
Microsoft Defender Denial of Service Vulnerability
CVE-2026-45498
pkg: Microsoft Defender

published: May 20, 2026

Microsoft Defender contains an unspecified vulnerability that allows for denial of service.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
GitHub-GHSA

CRITICAL
BoxLite: Permission Bypass Allows Modification of Read-Only Files
GHSA-g6ww-w5j2-r7x3
pkg: boxlite, @boxlite-ai/boxlite, github.com/boxlite-ai/boxlite/sdks/go
eco: npm
published: May 21, 2026
#### Summary

Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code.

One of the core security features claimed by Boxlite is the ability to mount host directories in read-only mode (read_only=True) i…

CVE-2026-46695
GitHub-GHSA

CRITICAL
Malicious code in @beproduct/nestjs-auth (0.1.2 through 0.1.19) — Mini Shai-Hulud worm
GHSA-6xwp-cp5h-q856
pkg: @beproduct/nestjs-auth
eco: npm
published: May 19, 2026
## Summary

Between 2026-05-11 20:19 UTC and 22:56 UTC, an attacker used a compromised npm publish token to publish 18 malicious versions of `@beproduct/nestjs-auth` (0.1.2 through 0.1.19). The packages contained payloads from the **Mini Shai-Hulud** npm supply-chain worm campaign described by [Aiki…

CVE-2026-46412
GitHub-GHSA

CRITICAL
9router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes
GHSA-fhh6-4qxv-rpqj
pkg: 9router
eco: npm
published: May 19, 2026
## Summary

9router exposes two unauthenticated API endpoints that, when chained together, allow any network-adjacent attacker to execute arbitrary OS commands as the user running the 9router process — with **zero prerequisites** and **no credentials required**.

The vulnerability exists because t…

CVE-2026-46339
GitHub-GHSA

CRITICAL
Nezha Monitoring: RoleMember can run shell on every server (cross-tenant RCE) via POST /api/v1/cron
GHSA-99gv-2m7h-3hh9
pkg: github.com/nezhahq/nezha
eco: go
published: May 23, 2026
## Summary

`nezha`'s dashboard supports two user roles: `RoleAdmin` (Role==0) and `RoleMember` (Role==1). The cron routes `POST /api/v1/cron` and `PATCH /api/v1/cron/:id` are wired through `commonHandler` (any authenticated user) rather than `adminHandler`, and the per-server permission check on cr…

CVE-2026-46716
GitHub-GHSA

CRITICAL
Arcane Backend: Missing admin authorization on git repository endpoints allows non-admin users to exfiltrate stored Git credentials and tamper with GitOps configs
GHSA-7h26-hg47-p9hx
pkg: github.com/getarcaneapp/arcane/backend
eco: go
published: May 18, 2026
## Summary

Arcane's huma-based REST API exposes nine endpoints under `/api/customize/git-repositories` and `/api/git-repositories/sync` for managing GitOps source repositories and their stored credentials. Eight of those endpoints (`list`, `create`, `get`, `update`, `delete`, `test`, `listBranches`…

CVE-2026-45625
GitHub-GHSA

CRITICAL
Fission router exposes /fission-function/<ns>/<name> on its public listener, allowing invocation of any function without an HTTPTrigger
GHSA-3g33-6vg6-27m8
pkg: github.com/fission/fission
eco: go
published: May 21, 2026
### Summary

The Fission router registers an internal-style route — `/fission-function/<name>` and `/fission-function/<ns>/<name>` — for every `Function` object, independent of whether any `HTTPTrigger` exists for that function. The route was mounted on the same listener as user-defined `HTTPTri…

CVE-2026-46614
GitHub-GHSA

CRITICAL
Kopia: RCE via SSH ProxyCommand Injection
GHSA-2q4c-3mrw-63c3
pkg: github.com/kopia/kopia
eco: go
published: May 19, 2026
## Summary

Kopia's HTTP server, when started with `–without-password `, accepts unauthenticated requests to `/api/v1/repo/exists`. The handler forwards an attacker-supplied storage configuration to `blob.NewStorage`. For SFTP backends with `externalSSH: true`, that path constructs a process comman…

CVE-2026-45695
GitHub-GHSA

CRITICAL
Boxlite: Path Traversal Vulnerability Leads to Arbitrary File Write on the Host
GHSA-f396-4rp4-7v2j
pkg: boxlite, boxlite-cli, boxlite
eco: npm
published: May 21, 2026
#### Summary

Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and run OCI containers within them. Boxlite allows users to specify the OCI image used by containers in the sandbox. However, when processing tar entries in OCI images, Boxlite does not accoun…

CVE-2026-46703
GitHub-GHSA

CRITICAL
Malicious code in guardrails-ai 0.10.1 (supply chain compromise)
GHSA-xmpw-2vmm-p4p6
pkg: guardrails-ai
eco: pip
published: May 19, 2026
### Impact

On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of `guardrails-ai` (0.10.1) to PyPI.

**Affected:** any user who installed `guardrails-ai==0.10.1` from PyPI on May 11, 2026.

Security researchers identified the malicious package within approxim…

CVE-2026-45758
GitHub-GHSA

CRITICAL
Malware in @opensearch-project/opensearch
GHSA-27f5-xjrr-q9ff
pkg: @opensearch-project/opensearch, @opensearch-project/opensearch, @opensearch-project/opensearch
eco: npm
published: May 19, 2026
## Overview

The OpenSearch Project has sustained a security incident involving an external actor gaining force-push permissions within the project's CI infrastructure to embed malicious packages into four release versions of `@opensearch-project/opensearch`. Users are instructed to immediately take…

GitHub-GHSA

CRITICAL
Malicious dropper in mistralai 2.4.6 PyPI package
GHSA-wx9m-wx4f-4cmg
pkg: mistralai
eco: pip
published: May 18, 2026
The `mistralai` PyPI package version `2.4.6` contains a malicious dropper that executes on import on Linux. No `v2.4.6` tag, commit, or release workflow run exists in this repository, the legitimate latest version before the upload was `2.4.5`, and the upload bypassed this repository's normal releas…
GitHub-GHSA

CRITICAL
Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft
GHSA-6×44-w3xg-hqqf
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: May 19, 2026
## Summary

`azureidentity.Validate()` verifies that the PKCS#7 signer certificate chains to a trusted Azure CA but never verifies the PKCS#7 signature itself. An attacker can embed a legitimate Azure certificate alongside arbitrary content e.g. `{"vmId":"<target>"}` and the forged `vmId` will be ac…

CVE-2026-46354
GitHub-GHSA

CRITICAL
Algernon: handler.lua discovery walks parent directories above the server root
GHSA-xwcr-wm99-g9jc
pkg: github.com/xyproto/algernon
eco: go
published: May 19, 2026
### Summary

When Algernon is asked for any URL path that resolves to a directory *without* an index file, `DirPage` walks **upward through parent directories — past the configured server root** — looking for a file named `handler.lua` to execute as the request handler. The loop terminates only …

CVE-2026-45721
GitHub-GHSA

CRITICAL
FileBrowser Quantum: Path traversal in public share PATCH allows file ops outside shared directory
GHSA-qqqm-5547-774x
pkg: github.com/gtsteffaniak/filebrowser/backend
eco: go
published: May 22, 2026
## Summary

`publicPatchHandler` in `backend/http/public.go` joins user-controlled `fromPath` and `toPath` body fields with the trusted `d.share.Path` BEFORE the downstream sanitizer runs. Because `filepath.Join` collapses `..` segments during the join, the sanitizer in `resourcePatchHandler` never …

GitHub-GHSA

CRITICAL
@hulumi/policies: GitHub OIDC trust policy bypass via AWS set-qualified condition operators
GHSA-q2f7-m237-v562
pkg: @hulumi/policies
eco: npm
published: May 21, 2026
Impact: @hulumi/policies versions before 1.3.2 only checked exact AWS IAM StringLike/StringEquals condition operator keys in G_OIDC_1. Set-qualified operators such as ForAnyValue:StringLike could hide wildcard GitHub Actions OIDC sub conditions from the mandatory guardrail.

Patched in 1.3.2: the AW…

GitHub-GHSA

CRITICAL
Supply chain compromise via malicious package versions (@cap-js/sqlite, @cap-js/postgres, @cap-js/db-service)
GHSA-pvw4-cvr4-97p8
pkg: @cap-js/sqlite, @cap-js/postgres, @cap-js/db-service
eco: npm
published: May 20, 2026
## Impact

On April 29, 2026, compromised versions of `@cap-js/sqlite@2.2.2`, `@cap-js/postgres@2.2.2`, and `@cap-js/db-service@2.10.1` were published.
The malicious packages harvested credentials and attempted self-propagation.
If a compromised version was installed, all credentials accessible on t…

CVE-2026-46421
GitHub-GHSA

CRITICAL
MCP Gateway: Authority-injection and JWT/session bypass via the unauthenticated router hair-pin "router-key" / "mcp-init-host" path
GHSA-g53w-w6mj-hrpp
pkg: github.com/Kuadrant/mcp-gateway
eco: go
published: May 19, 2026
## Summary

The MCP router (ext_proc) exposes an `initialize`-method code path that, when a
request carries an `mcp-init-host` header, bypasses the gateway JWT session
validator and rewrites the upstream `:authority` header to whatever the caller
chooses, gated only by a single shared header value …

GitHub-GHSA

CRITICAL
rok Python ProxyShare can be used as an SSRF proxy through absolute URL paths
GHSA-jh67-hwqw-m5r7
pkg: zrok
eco: pip
published: May 19, 2026
## Summary

Alice exposes a Python SDK `ProxyShare` with a fixed target URL. Bob sends a request to the share with an absolute URL in the path. The Flask handler passes that path to `urllib.parse.urljoin`, which replaces Alice's configured target host with Bob's host and returns the server-side resp…

CVE-2026-45568
GitHub-GHSA

CRITICAL
HAXcms: Private Key Disclosure via Broken HMAC Implementation
GHSA-6c8g-9hfh-pq5h
pkg: @haxtheweb/haxcms-nodejs
eco: npm
published: May 19, 2026
### Summary
The `hmacBase64()` function in the HAXcms Node.js backend contains two critical cryptographic implementation errors that together allow any unauthenticated attacker to extract the system’s private signing key and forge arbitrary admin-level JSON Web Tokens (JWTs) allowing them to get f…
CVE-2026-46395
GitHub-GHSA

HIGH
Arcane: Missing admin authorization on global variables endpoint
GHSA-jpjh-jm2p-39hh
pkg: github.com/getarcaneapp/arcane/backend
eco: go
published: May 23, 2026
## Summary

The `PUT /api/environments/{id}/templates/variables` endpoint, which writes the system-wide `.env.global` file used for variable substitution in every project's compose file, is missing an admin authorization check. Any authenticated non-admin user can call this endpoint with their beare…

CVE-2026-47125
GitHub-GHSA

HIGH
MCP Server Kubernetes: Tool Access Control Bypass via Presentation-Layer Filtering Without Execution-Layer Enforcement
GHSA-cr22-wjx7-2w6m
pkg: mcp-server-kubernetes
eco: npm
published: May 21, 2026
## Summary

`mcp-server-kubernetes` exposes three environment variables (`ALLOW_ONLY_READONLY_TOOLS`, `ALLOW_ONLY_NON_DESTRUCTIVE_TOOLS`, `ALLOWED_TOOLS`) documented as access controls for restricting which Kubernetes operations are available. These controls are enforced at the tool discovery layer …

CVE-2026-46519
GitHub-GHSA

HIGH
Fission StorageSvc /v1/archive endpoint exposes unauthenticated CRUD over all function archives
GHSA-chf8-4hv6-8pg6
pkg: github.com/fission/fission
eco: go
published: May 21, 2026
### Summary

The Fission `storagesvc` component registers archive CRUD handlers (`/v1/archive` GET / POST / DELETE and `/v1/archives` list) directly on its HTTP router without performing any authentication or authorization. Any caller able to reach the `storagesvc` ClusterIP — including any other…

CVE-2026-46612
GitHub-GHSA

HIGH
PenPot MCP REPL server binds to 0.0.0.0 with unauthenticated /execute endpoint — RCE
GHSA-22qr-rp27-j9wm
pkg: @penpot/mcp
eco: npm
published: May 19, 2026
### Summary

The MCP module's `ReplServer` binds to all interfaces (`0.0.0.0:4403`) and exposes a `/execute` endpoint that runs arbitrary code with zero authentication. Anyone on the network can POST JavaScript and it runs on the server. The main `PenpotMcpServer` was partially fixed for a similar b…

CVE-2026-45805
GitHub-GHSA

HIGH
Budibase: Builder-to-Admin Privilege Escalation via onboardUsers Endpoint Without SMTP Configuration
GHSA-c54j-xp92-wh28
pkg: @budibase/worker
eco: npm
published: May 18, 2026
## Summary

The `POST /api/global/users/onboard` endpoint is protected by `workspaceBuilderOrAdmin` middleware, allowing any user with builder permissions to access it. When SMTP email is not configured (the default for self-hosted Budibase instances), this endpoint bypasses the admin-restricted inv…

CVE-2026-45716
GitHub-GHSA

HIGH
Dozzle: Pre-auth SSRF with response-body reflection via POST /api/notifications/test-webhook (default no-auth deploy)
GHSA-3v9w-6365-9w54
pkg: github.com/amir20/dozzle
eco: go
published: May 18, 2026
## Summary

In a default dozzle deploy (the documented quickstart, no `DOZZLE_AUTH_PROVIDER` set), `POST /api/notifications/test-webhook` is reachable without authentication and forwards an attacker-controlled URL into a `WebhookDispatcher` that:

– Sends an HTTP POST to the supplied URL with attack…

CVE-2026-45298
GitHub-GHSA

HIGH
Nezha Monitoring: RoleMember-reachable SSRF with full response-body reflection via POST /api/v1/notification
GHSA-w4g9-mxgg-j532
pkg: github.com/nezhahq/nezha
eco: go
published: May 23, 2026
## Summary

nezha's dashboard supports two user roles: `RoleAdmin` (Role==0) and `RoleMember` (Role==1). The notification routes `POST /api/v1/notification` and `PATCH /api/v1/notification/:id` are wired through `commonHandler` rather than `adminHandler` — so a `RoleMember` user can call them. The…

CVE-2026-46717
GitHub-GHSA

HIGH
wger: cross-tenant account deletion / deactivation / activation by gym.manage_gym + gym=None
GHSA-mw8f-w6p8-xrf4
pkg: wger
eco: pip
published: May 20, 2026
## Summary

GHSA-mhc8-p3jx-84mm (CVE-2026-43948) reported that wger's `reset_user_password` and `gym_permissions_user_edit` views in `wger/gym/views/user.py` performed a gym-scope authorization check using Django ORM object comparison (`if request.user.userprofile.gym != user.userprofile.gym`) which…

GitHub-GHSA

HIGH
SillyTavern: SSRF in SearXNG Search Proxy via Unvalidated baseUrl
GHSA-qg89-qwwh-5f3j
pkg: sillytavern
eco: npm
published: May 19, 2026
## Resolution

SillyTavern 1.18.0 added a generic server-side request filter (Private Request Whitelisting). Since we expect users to use the application in a trusted environment, the filter is disabled by default, however it is strongly advised to be enabled and properly configured when an instance…

CVE-2026-46372
GitHub-GHSA

HIGH
OpenMetadata: TEST_CONNECTION workflow leaks ingestion-bot JWT and database password to regular users
GHSA-9vmh-whc4-7phg
pkg: org.open-metadata:openmetadata-service
eco: maven
published: May 21, 2026
**This is not applicable if an application is configuring the Secrets Store to store credentials. Please make sure to follow the best practices when deploying in production**
In OpenMetadata 1.12.1, a non-admin SSO user can trigger a `TEST_CONNECTION` workflow for a Database Service and receive, in …
CVE-2026-46481
GitHub-GHSA

HIGH
Caddy Defender trusted proxy client IP bypass
GHSA-3h23-rrpc-3p87
pkg: pkg.jsn.cam/caddy-defender
eco: go
published: May 19, 2026
### Impact

Caddy Defender used `r.RemoteAddr` when evaluating whether a request should be blocked. `RemoteAddr` is the address of the immediate peer connected to Caddy.

In deployments where Caddy is behind a trusted proxy, CDN, or load balancer, the immediate peer is usually the proxy, not the ori…

CVE-2026-46415
GitHub-GHSA

HIGH
auth-fetch-mcp: SSRF and disk exfiltration via unvalidated auth_fetch and download_media URLs
GHSA-hv85-774v-26fg
pkg: auth-fetch-mcp
eco: npm
published: May 19, 2026
# SSRF + disk-exfil in `download_media` and `auth_fetch` tools — ymw0407/auth-fetch-mcp

## Severity
The `download_media` and `auth_fetch` MCP tools accept arbitrary URLs and reach them as the MCP server process, with `download_media` additionally persisting the fetched response body to a user-con…

GitHub-GHSA

HIGH
TinyIce: Missing authentication on WebRTC ingest endpoint allows unauthorized stream injection
GHSA-p7c4-8×34-8j8f
pkg: github.com/DatanoiseTV/tinyice
eco: go
published: May 18, 2026
## Title

Missing authentication on WebRTC ingest endpoint allows unauthenticated stream injection in TinyIce

## Ecosystem / Package

– **Ecosystem:** `Go` (or "Other" — TinyIce is shipped as a Go binary, not a Go module published to a registry)
– **Package name:** `github.com/DatanoiseTV/tinyice…

CVE-2026-45327
GitHub-GHSA

HIGH
@tmlmobilidade/utils has prototype pollution in its setValueAtPath
GHSA-cmxg-94mg-jq94
pkg: @tmlmobilidade/utils
eco: npm
published: May 18, 2026
### Impact
Prototype pollution vulnerability in @tmlmobilidade/utils for setValueAtPath().

### Patches
A fix is available in versions 20260509.0340.15 and up.

CVE-2026-45325
GitHub-GHSA

HIGH
parse-nested-form-data has Prototype Pollution via `__proto__` in FormData field names
GHSA-xp7r-j8r6-j9h3
pkg: parse-nested-form-data
eco: npm
published: May 18, 2026
## Summary

`parseFormData()` walks bracket and dot-notation FormData field names into nested objects without filtering reserved property keys. A single FormData field whose name begins with `__proto__`, or contains `.__proto__.` mid-path, causes the parser to traverse onto `Object.prototype` and as…

CVE-2026-45302
GitHub-GHSA

HIGH
Arcane Backend: Unauthenticated reflected XSS via SVG color parameter enables admin account takeover
GHSA-q2pj-8v84-9mh5
pkg: github.com/getarcaneapp/arcane/backend
eco: go
published: May 18, 2026
## Summary

The unauthenticated `GET /api/app-images/logo` endpoint reflects a user-supplied `color` query parameter into the body of an SVG document via `strings.ReplaceAll` with no escaping. The substitution lands inside a `<style>` element of the embedded `logo.svg`, allowing an attacker to close…

CVE-2026-45627
GitHub-GHSA

HIGH
form-data-objectizer: Prototype pollution in form-data-objectizer via bracket-notation form keys
GHSA-m2hg-wjq3-28wq
pkg: form-data-objectizer
eco: npm
published: May 18, 2026
## Summary

`form-data-objectizer` walks bracket-notation form keys (e.g. `name[sub]`) into nested objects without filtering `__proto__`, `constructor`, or `prototype`. A single HTTP form field whose name starts with `__proto__[…]` causes the library to mutate `Object.prototype`, which is a protot…

CVE-2026-46510
GitHub-GHSA

HIGH
ORAS Java: Path traversal in pullArtifact via attacker-controlled org.opencontainers.image.title annotation
GHSA-xm96-gfjx-jcrc
pkg: land.oras:oras-java-sdk
eco: maven
published: May 19, 2026
### Summary

The `pullArtifact` methods in `Registry` and `OCILayout` use the `org.opencontainers.image.title` annotation from a pulled manifest as a filename, resolving it against the caller supplied output directory without normalization or a containment check. A manifest publisher can set this an…

GitHub-GHSA

HIGH
n8n-MCP: Multi-tenant MCP requests fall back to process-level n8n credentials when tenant headers are absent or incomplete
GHSA-jxx9-px88-pj69
pkg: n8n-mcp
eco: npm
published: May 18, 2026
## Summary

When `ENABLE_MULTI_TENANT=true`, the HTTP transport documents that the target n8n instance is selected per-request from `x-n8n-url` / `x-n8n-key` headers. Requests that omitted those headers — or supplied only one of them — silently fell back to the process-level `N8N_API_URL` / `N8N…

CVE-2026-45707
GitHub-GHSA

HIGH
Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Files
GHSA-m675-2p33-xv9g
pkg: github.com/caddyserver/caddy/v2
eco: go
published: May 18, 2026
### Summary

The FastCGI transport's `splitPos()` in [`modules/caddyhttp/reverseproxy/fastcgi/fastcgi.go`](https://github.com/caddyserver/caddy/blob/master/modules/caddyhttp/reverseproxy/fastcgi/fastcgi.go) misuses `golang.org/x/text/search` with `search.IgnoreCase` when the request path contains a …

CVE-2026-45135
GitHub-GHSA

HIGH
lmdeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out
GHSA-9xq9-36w5-q796
pkg: lmdeploy
eco: pip
published: May 21, 2026
> ## 📋 Reframing (2026-05-02): implicit unsafe remote-code path, not "supply-chain"
>
> The accurate description of this vulnerability is:
> **"`get_model_arch` and related helpers hardcode `trust_remote_code=True`
> with no opt-out, creating an implicit unsafe remote-code load path
> on every mo…
CVE-2026-46517
GitHub-GHSA

HIGH
LMDeploy: Arbitrary code execution via hardcoded trust_remote_code=True in lmdeploy model initialization
GHSA-m549-qq94-fvhg
pkg: lmdeploy
eco: pip
published: May 21, 2026
## Summary

lmdeploy hardcodes `trust_remote_code=True` in multiple HuggingFace model-loading call sites.

The affected code paths are in:

“`text
lmdeploy/archs.py
lmdeploy/utils.py
““

The vulnerable call sites pass `trust_remote_code=True` into HuggingFace Transformers APIs such as `AutoConfig…

CVE-2026-46432
GitHub-GHSA

HIGH
Graphite Has a Pickle Deserialization Vulnerability
GHSA-qw48-84f6-28gv
pkg: graphitedb
eco: pip
published: May 18, 2026
### Impact
**Type of vulnerability:** Insecure Deserialization via Python's `pickle` module.

**Who is impacted:**
Users of *Graphite graph database engine* versions **before 0.2** who load database files from untrusted or third-party sources.
An attacker could craft a malicious database file th…

GitHub-GHSA

HIGH
Network-AI: Unauthenticated Cross-Origin MCP Tool Invocation via Empty Default Secret
GHSA-j3vx-cx2r-pvg8
pkg: network-ai
eco: npm
published: May 21, 2026
# Unauthenticated Cross-Origin MCP Tool Invocation via Empty Default Secret

| Field | Value |
| —————- | —– |
| Repository | Jovancoding/Network-AI |
| Affected version | v5.4.4 (commit c12686e181f231cf8d7bcf836a96d78f0f0877ac) |

## Summary

The MCP SSE server default…

CVE-2026-46701
GitHub-GHSA

HIGH
Budibase: Unrestricted Upload of File with Dangerous Type
GHSA-82rc-gxrg-v4gf
pkg: budibase
eco: npm
published: May 19, 2026
### Summary
The file upload endpoint `POST /api/attachments/process` does not enforce active-content restrictions for authenticated users. The checks for dangerous file extensions (`html`, `svg`, `js`, `php`, etc.) are conditionally wrapped inside `if (isPublicUser)` or `if (isPublicUser || !env.SEL…
CVE-2026-46426
GitHub-GHSA

HIGH
aiosend: Deserialization of request body before signature verification (Pre-auth DoS) in webhook handler
GHSA-7m8f-hgjq-8gc9
pkg: aiosend
eco: pip
published: May 22, 2026
# Vulnerability Description

In `aiosend/webhook/base.py`, the `WebhookHandler.feed_update()` method performs full deserialization of the incoming JSON via Pydantic **before** verifying the HMAC signature. Anyone can send a request with an arbitrary body — the server will parse it, spend CPU and m…

GitHub-GHSA

HIGH
js-libp2p: Memory DoS via subscription flood of unique topics
GHSA-4f8r-922h-2vgv
pkg: @libp2p/gossipsub
eco: npm
published: May 21, 2026
### Summary
Three cooperating omissions in `@libp2p/gossipsub` allow an unauthenticated single peer to exhaust the Node.js heap of any gossipsub node with default options.

1. **`defaultDecodeRpcLimits.maxSubscriptions = Infinity`** (`packages/gossipsub/src/message/decodeRpc.ts:11`): no decode-level…

CVE-2026-46679
GitHub-GHSA

HIGH
JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection
GHSA-qjx8-664m-686j
pkg: js-cookie
eco: npm
published: May 21, 2026
## Summary

`js-cookie`'s internal `assign()` helper copies properties with `for…in` + plain assignment. When the source object is produced by `JSON.parse`, the JSON object's `"__proto__"` member is an *own enumerable* property, so the `for…in` enumerates it and the `target[key] = source[key]` w…

CVE-2026-46625
GitHub-GHSA

HIGH
Russh: Unchecked CryptoVec allocation and growth handling is reachable
GHSA-g9f8-wqj9-fjw5
pkg: russh-cryptovec, russh
eco: rust
published: May 21, 2026
### Title
Unchecked `CryptoVec` allocation and growth handling was reachable from local agent inputs in current `russh` releases and from remote SSH traffic in historical pre-`0.58.0` releases

### Summary
`CryptoVec` used unchecked capacity growth, unchecked length arithmetic, and unsafe allocation…

CVE-2026-46673
GitHub-GHSA

HIGH
nimiq-primitives: Panic DoS in trie chunk processing via ROOT-keyed item
GHSA-mw3q-r9wh-h2ff
pkg: nimiq-primitives
eco: rust
published: May 21, 2026
### Impact

A remote, unauthenticated denial-of-service vulnerability in `MerkleRadixTrie::put_chunk` allows any state-sync peer to crash any node performing state synchronization (freshly joining nodes and recovering nodes).

A malicious peer can respond to a `RequestChunk` with a `ResponseChunk::C…

CVE-2026-46545
GitHub-GHSA

HIGH
Diffusers: TOCTOU Trust Remote Code Bypass
GHSA-7wx4-6vff-v64p
pkg: diffusers
eco: pip
published: May 20, 2026
## Background

This vulnerability is found in the `diffusers` package – the `transformers`-equivalent library for diffusion models.

It is found in the `DiffusionPipeline.from_pretrained` flow, which is used to load a pipeline from the HuggingFace Hub.

This function has a `trust_remote_code` guard:…

CVE-2026-45804
GitHub-GHSA

HIGH
SQLFluff: Uncontrolled Resource Consumption in SQLFluff Parser
GHSA-73jc-5mrq-prw7
pkg: sqlfluff
eco: pip
published: May 19, 2026
### Impact

In deployments where untrusted users can provide SQL queries to be linted, an untrusted user can submit a malicious long query to any application using the parser to trigger a Denial of Service through resource exhaustion.

### Patches

Versions 4.2.0 and up contain a configurable parse …

CVE-2026-46374
GitHub-GHSA

HIGH
SQLFluff: Recursive Stack Overflow in Parser
GHSA-wmhf-fqc8-vxhh
pkg: sqlfluff
eco: pip
published: May 19, 2026
### Impact

In deployments where untrusted users can provide SQL queries to be linted, an untrusted user can submit a malicious query with deliberate excessive nesting to any application using the parser to trigger a Denial of Service through resource exhaustion.

### Patches

Versions 4.1.0 and up …

CVE-2026-46373
GitHub-GHSA

HIGH
Dasel: Denial of service in dasel selector lexer due to infinite loop on unterminated regex literal
GHSA-m6xr-fvfg-5g64
pkg: github.com/tomwright/dasel/v3
eco: go
published: May 19, 2026
### Summary

`dasel`'s selector lexer enters a non-terminating loop when tokenizing an unterminated regex pattern such as `r/abc`. A 2-byte input (`r/`) is sufficient to cause the tokenizer to consume 100% CPU on one core indefinitely.

I confirmed the issue on `v3.3.1` (`fba653c7f248aff10f2b89fca93…

CVE-2026-46378
GitHub-GHSA

HIGH
Dasel: Index-out-of-range panic in dasel selector lexer on trailing backslash in quoted string
GHSA-m5j3-4634-c2vq
pkg: github.com/tomwright/dasel/v3
eco: go
published: May 19, 2026
### Summary

`dasel`'s selector lexer panics with an index-out-of-range error when tokenizing a quoted string that ends with a trailing backslash (e.g., `"\` or `'\`). A 2-byte input causes an immediate process crash via Go runtime panic.

I confirmed the issue on `v3.3.1` (`fba653c7f248aff10f2b89fc…

CVE-2026-46377
GitHub-GHSA

HIGH
@libp2p/kad-dht: Unvalidated PUT_VALUE records allow unbounded disk exhaustion on DHT server nodes
GHSA-32mq-hpph-xfvr
pkg: @libp2p/kad-dht
eco: npm
published: May 19, 2026
### Summary
An unauthenticated remote peer can exhaust the disk storage of any `@libp2p/kad-dht` node running in server mode by sending an unbounded stream of `PUT_VALUE` messages whose keys bypass all content validation. No credentials, no prior relationship, and no protocol deviation beyond a craf…
CVE-2026-45783
GitHub-GHSA

HIGH
Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service
GHSA-7xpr-hc2w-34m9
pkg: com.squareup.wire:wire-runtime-jvm, com.squareup.wire:wire-runtime, com.squareup.wire:wire-runtime
eco: maven
published: May 19, 2026
# CVE-2026-45799

## Maintainer summary

Wire's protobuf group-skipping logic did not reject negative lengths before skipping a
length-delimited field inside a group. A crafted protobuf payload could cause Wire to throw an
unchecked runtime exception during decoding instead of the documented `IOExce…

CVE-2026-45799
GitHub-GHSA

HIGH
Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes
GHSA-fpxj-m5q8-fphw
pkg: github.com/axllent/mailpit
eco: go
published: May 19, 2026
### Summary
The Mailpit SMTP server has a Server.MaxSize int field that controls the maximum allowed DATA payload size, but the field is never assigned anywhere outside test code, leaving it at Go's zero value (0 ⇒ "no limit"). The same applies to the HTTP /api/v1/send endpoint, whose request body…
CVE-2026-45713
GitHub-GHSA

HIGH
Algernon: Single-file mode unconditionally enables debug mode
GHSA-fwqx-8365-9983
pkg: github.com/xyproto/algernon
eco: go
published: May 19, 2026
### Summary

When Algernon is invoked with a single file path instead of a directory — the documented "quick demo" workflow (`algernon foo.lua`, `algernon page.po2`, `algernon index.html`, `algernon mywebsite.alg`) — `singleFileMode` is set to true and **`debugMode` is forcibly enabled** with no…

CVE-2026-45728
GitHub-GHSA

HIGH
ImageMagick: Infinite Loop in the MIFF decoder can lead to CPU exhaustion
GHSA-7gg8-qqx7-92g5
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 18, 2026
Due to a missing check in the MIFF decoder a crafted file could cause an infinite loop resulting in CPU exhaustion.
CVE-2026-46522
GitHub-GHSA

HIGH
ImageMagick: Heap Buffer Over-Write in IPL decoder when reading multiple images of different dimensions
GHSA-36wm-hprc-mcf5
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 18, 2026
When reading multiple images with different dimensions an out of bounds heap write can occur.
CVE-2026-46520
GitHub-GHSA

HIGH
HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint
GHSA-3653-68v6-rq57
pkg: ca.uhn.hapi.fhir:org.hl7.fhir.dstu2, ca.uhn.hapi.fhir:org.hl7.fhir.dstu2016may, ca.uhn.hapi.fhir:org.hl7.fhir.dstu3
eco: maven
published: May 18, 2026
## Summary

All implementations of FHIRPathEngine accept arbitrary FHIRPath expressions and evaluate them without input validation. The FHIRPath functions `matches()`, `matchesFull()`, and `replaceMatches()` pass user-controlled regular expressions directly to Java's `Pattern.compile()` and `String.…

CVE-2026-45367
GitHub-GHSA

HIGH
NiceGUI: Local file disclosure via Docutils file insertion in ui.restructured_text()
GHSA-jfrm-rx66-g536
pkg: nicegui
eco: pip
published: May 18, 2026
### Summary

`ui.restructured_text()` renders reStructuredText server-side with Docutils without disabling file insertion directives.

When a NiceGUI application passes attacker-controlled content to `ui.restructured_text()`, an attacker can use standard Docutils directives (`include`, `csv-table` w…

CVE-2026-45553
GitHub-GHSA

HIGH
OpenTelemetry eBPF Instrumentation: Memcached payload length overflow can crash OBI
GHSA-43g7-cwr8-q3jh
pkg: go.opentelemetry.io/obi
eco: go
published: May 18, 2026
### Summary

A remotely reachable integer overflow in OBI's memcached text protocol parser can crash the OBI process and cause denial of service. When parsing memcached storage commands such as `set`, `add`, `replace`, `append`, `prepend`, or `cas`, OBI accepts extremely large `<bytes>` values and a…

CVE-2026-45686
GitHub-GHSA

HIGH
OpenTelemetry eBPF Instrumentation: MongoDB parser panics on malformed wire messages
GHSA-j8p6-96vp-f3r9
pkg: go.opentelemetry.io/obi
eco: go
published: May 18, 2026
### Summary

Malformed MongoDB wire messages can trigger uncaught panics in the MongoDB TCP parser, allowing a remote unauthenticated attacker to crash the telemetry agent and cause a denial of service. The parser operates on raw attacker-controlled network payloads before the input is fully validat…

CVE-2026-45685
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-42899 – ASP.NET Core Denial of Service Vulnerability
GHSA-9v76-4qcc-frgh
pkg: Microsoft.AspNetCore.App.Runtime.win-arm, Microsoft.AspNetCore.App.Runtime.win-arm64, Microsoft.AspNetCore.App.Runtime.win-x64
eco: nuget
published: May 18, 2026
## Executive Summary:

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 8.0, .NET 9.0, and .NET 10.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

Loop with unreachable ex…

CVE-2026-42899
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-32175 – .NET Core Tampering Vulnerability
GHSA-rg75-q538-x34v
pkg: Microsoft.NetCore.App.Runtime.win-arm, Microsoft.NetCore.App.Runtime.win-arm, Microsoft.NetCore.App.Runtime.win-arm
eco: nuget
published: May 18, 2026
## Executive Summary:

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 8.0, .NET 9.0, and .NET 10.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A tampering vulnerabil…

CVE-2026-32175
GitHub-GHSA

HIGH
OpenTelemetry eBPF Instrumentation: Postgres BIND parsing can panic on malformed payloads
GHSA-pgvv-q3wf-mm9m
pkg: go.opentelemetry.io/obi
eco: go
published: May 18, 2026
### Summary

The Postgres protocol parser assumes `BIND` message payloads contain a valid NUL-terminated portal name. A crafted empty or unterminated payload can make OBI slice beyond the end of the captured buffer and panic.

### Details

The vulnerable logic is in [pkg/ebpf/common/sql_detect_postg…

CVE-2026-45678
GitHub-GHSA

HIGH
multiparty vulnerable to ReDoS via filename parsing
GHSA-65×3-rw7q-gx94
pkg: multiparty
eco: npm
published: May 18, 2026
### Impact

multiparty@4.2.3 and lower versions are vulnerable to denial of service via regular expression backtracking in the `Content-Disposition` filename parameter parser. A multipart upload with a long header value containing `!filename="1` repeated can cause regex matching to take seconds, blo…

CVE-2026-8159
GitHub-GHSA

HIGH
multiparty vulnerable to Denial of Service via Uncaught Exception in filename* parameter parsing
GHSA-xh3c-6gcq-g4rv
pkg: multiparty
eco: npm
published: May 18, 2026
### Impact

multiparty@4.2.3 and lower versions are vulnerable to denial of service via uncaught exception. By sending a `multipart/form-data` request with a `Content-Disposition: filename*=utf-8''` header containing a malformed percent-encoding (e.g., `%FF`, `%GG`), the parser invokes `decodeURI` o…

CVE-2026-8162
GitHub-GHSA

HIGH
multiparty: Denial of Service via Prototype Pollution leads to Uncaught Exception
GHSA-qxch-whhj-8956
pkg: multiparty
eco: npm
published: May 18, 2026
### Impact

multiparty@4.2.3 and lower versions are vulnerable to denial of service via uncaught exception. By sending a `multipart/form-data` request with a field name that collides with an inherited `Object.prototype` property (e.g., `__proto__`, `constructor`, `toString`), the parser invokes `.pu…

CVE-2026-8161
GitHub-GHSA

HIGH
dynoxide: DNS rebinding and cross-origin CSRF via MCP HTTP transport
GHSA-fvh2-gm75-j4j7
pkg: dynoxide-rs, dynoxide
eco: npm
published: May 18, 2026
## Summary

dynoxide's MCP HTTP transport was vulnerable to DNS rebinding via its transitive `rmcp` dependency, plus a related cross-origin CSRF gap. A malicious web page could make the user's browser send requests to a local `dynoxide mcp –http` or `dynoxide serve –mcp` server with a non-loopback…

GitHub-GHSA

HIGH
iskorotkov/avro: CPU Exhaustion in Decoder
GHSA-w8j3-pq8g-8m7w
pkg: github.com/iskorotkov/avro/v2
eco: go
published: May 18, 2026
# CPU Exhaustion in Avro Decoder via Unbounded Block-Count Iteration

## Summary

The Avro array and map decoders looped over an attacker-controlled block-count value without checking the underlying reader's error state inside the loop body. `Reader.ReadBlockHeader` returns the count as a Go `int`, …

CVE-2026-46385
GitHub-GHSA

HIGH
iskorotkov/avro: Integer Overflow in Decoder
GHSA-mc57-h6j3-3hmv
pkg: github.com/iskorotkov/avro/v2
eco: go
published: May 18, 2026
# Integer Overflow in Avro Decoder

## Summary

Several Avro decoder paths read attacker-controlled 64-bit values from the wire format and either narrowed them to platform-sized `int` before bounds-checking, or summed them with overflow-prone signed-`int` arithmetic. On 32-bit targets (`GOARCH=386`,…

CVE-2026-46384
GitHub-GHSA

HIGH
iskorotkov/avro: Denial-of-Service Vulnerability in Decoder
GHSA-mx64-mj3q-7prj
pkg: github.com/iskorotkov/avro/v2
eco: go
published: May 18, 2026
# Memory Exhaustion via Unbounded Map Allocations in Avro Decoder

## Summary

The Avro map decoder accepted attacker-controlled block-element counts from the wire format and grew the destination map without enforcing an upper bound. The slice decoder already had `Config.MaxSliceAllocSize` for the e…

GitHub-GHSA

HIGH
ruby-jwt: Empty-key HMAC bypass; cross-language sibling of CVE-2026-44351
GHSA-c32j-vqhx-rx3x
pkg: jwt
eco: rubygems
published: May 18, 2026
`JWT.decode(token, '', true, algorithm: 'HS256')` accepts an attacker-forged token.
`OpenSSL::HMAC.digest('SHA256', '', payload)` returns a valid digest under an empty key, and no `raise
InvalidKeyError if key.empty?` precondition exists in the HMAC algorithm.

“`
JWT.decode(token, "", true, algo…

CVE-2026-45363
GitHub-GHSA

HIGH
async-http-client: Cookie header not stripped on cross-origin redirect
GHSA-fmxf-pm6p-7xgm
pkg: org.asynchttpclient:async-http-client, org.asynchttpclient:async-http-client
eco: maven
published: May 18, 2026
## Summary

async-http-client leaks `Cookie` headers to cross-origin redirect targets. When following a redirect across a security boundary (different origin, or HTTPS→HTTP downgrade), the `propagatedHeaders()` method in `Redirect30xInterceptor.java` strips `Authorization` and `Proxy-Authorization…

CVE-2026-45300
GitHub-GHSA

HIGH
Microsoft APM: Symlinks under `.apm/prompts/` and `.apm/agents/` are dereferenced during `apm install`, copying host-local file contents into the project tree
GHSA-q5pp-gvjg-h7v4
pkg: apm
eco: pip
published: May 18, 2026
## Summary

Two primitive integrators in `apm-cli` enumerate package files with bare `Path.glob()` / `Path.rglob()` calls and read each match with `Path.read_text()`, transparently following symbolic links.

A symlink committed inside a remote APM dependency under `.apm/prompts/<x>.prompt.md` or `.a…

CVE-2026-45539
GitHub-GHSA

HIGH
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation
GHSA-h98r-wv3h-fr38
pkg: github.com/argoproj/argo-cd/v3, github.com/argoproj/argo-cd/v3, github.com/argoproj/argo-cd/v3
eco: go
published: May 19, 2026
### Summary

A user with **application write access (developer role)** can set `link.argocd.argoproj.io/*` annotations on any ArgoCD Application. These annotation values are rendered in the Summary tab's **URLs section** as `<a href>` elements without URL validation. Using the pipe-separator trick (…

CVE-2026-45738
GitHub-GHSA

HIGH
Microsoft Security Advisory CVE-2026-35433 – .NET Elevation of Privilege Vulnerability
GHSA-8x9c-mqxv-q2pp
pkg: Microsoft.WindowsDesktop.App.Runtime.win-arm64, Microsoft.WindowsDesktop.App.Runtime.win-x64, Microsoft.WindowsDesktop.App.Runtime.win-x86
eco: nuget
published: May 18, 2026
## Executive Summary:

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 8.0, .NET 9.0, and .NET 10.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

Improper input validatio…

CVE-2026-35433
GitHub-GHSA

HIGH
md-fileserver: Stored/Reflected XSS when viewing Markdown (raw HTML allowed)
GHSA-32q2-hhr5-6qvv
pkg: md-fileserver
eco: npm
published: May 21, 2026
### Summary
A cross-site scripting (XSS) vulnerability exists in the application’s Markdown rendering logic. When user-supplied Markdown content is rendered, embedded raw HTML—including <script> tags—is processed and injected into the resulting page without sanitization, allowing arbitrary Jav…
CVE-2026-46492
GitHub-GHSA

HIGH
Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK ModelBuilder/Serve path
GHSA-7hh5-prp2-mfh5
pkg: sagemaker, sagemaker
eco: pip
published: May 21, 2026
## Summary
Amazon SageMaker Python SDK is an open-source library for training and deploying machine learning models on Amazon SageMaker. An issue exists where, under certain circumstances, the ModelBuilder/Serve component stores an HMAC signing key in cleartext as a container environment variable, w…
CVE-2026-8596
GitHub-GHSA

HIGH
Docker: Race condition in docker cp allows bind mount redirection to host path
GHSA-rg2x-37c3-w2rh
pkg: github.com/docker/docker, github.com/moby/moby/v2, github.com/moby/moby
eco: go
published: May 18, 2026
## Summary

A race condition during `docker cp` mount setup allows a malicious container to redirect a bind mount target to an arbitrary host path, potentially overwriting host files or causing denial of service.

## Details

When copying files into a container, the daemon sets up a temporary filesy…

CVE-2026-42306
GitHub-GHSA

HIGH
Docker: `PUT /containers/{id}/archive` executes container binary on the host
GHSA-x86f-5xw2-fm2r
pkg: github.com/moby/moby/v2, github.com/docker/docker, github.com/moby/moby
eco: go
published: May 18, 2026
## Summary

When a user uploads a compressed archive into a container, a malicious image can execute arbitrary code with daemon (host root) privileges.

## Details

When handling `PUT /containers/{id}/archive` requests with compressed archives, the daemon decompresses them using external system bina…

CVE-2026-41567
GitHub-GHSA

HIGH
Spring AI MCP Security: Unvalidated URL Fetching (SSRF)
GHSA-qjp4-4jvr-xqg3
pkg: org.springaicommunity:mcp-client-security
eco: maven
published: May 18, 2026
### Summary

The mcp-security framework fails to implement the mandatory SSRF mitigations outlined in the Model Context Protocol (MCP) [security specifications](https://modelcontextprotocol.io/docs/tutorials/security/security_best_practices#mitigation-3). Specifically, it processes untrusted URLs fo…

CVE-2026-45609
GitHub-GHSA

HIGH
Parse Server: Pre-authentication denial of service via client version header regex backtracking
GHSA-38m6-82c8-4xfm
pkg: parse-server, parse-server
eco: npm
published: May 23, 2026
### Impact

An unauthenticated attacker who knows a publicly-known Parse Application ID can submit a single HTTP request whose client SDK version field contains adversarial input that triggers polynomial backtracking in a request-header parser. The parsing runs before session authentication and befo…

CVE-2026-47138
GitHub-GHSA

HIGH
@nevware21/ts-utils: Prototype Pollution in objDeepCopy/objCopyProps via for…in without hasOwnProperty
GHSA-x7j8-49r8-mr43
pkg: @nevware21/ts-utils
eco: npm
published: May 21, 2026
## Summary

The _copyProps function in lib/src/object/copy.ts uses for…in to iterate over source object properties without an Object.hasOwnProperty check, and does not filter dangerous keys (__proto__, constructor, prototype). This allows an attacker to pollute the prototype chain of all objects i…

CVE-2026-46681
GitHub-GHSA

HIGH
containerd user ID handling bypass allows runAsNonRoot evasion
GHSA-fqw6-gf59-qr4w
pkg: github.com/containerd/containerd, github.com/containerd/containerd/v2, github.com/containerd/containerd/v2
eco: go
published: May 21, 2026
### Impact
A bug was found in containerd where containers launched with a numeric `User` directive that cannot be parsed as a 32-bit integer are incorrectly treated as a username. If a crafted image provides an `/etc/passwd` file mapping this large numeric string to root, the container ultimately ru…
CVE-2026-46680
GitHub-GHSA

HIGH
@hulumi/policies: Stack-wide evidence bypassed Cloudflare and deployment-governance guardrails
GHSA-59f3-7227-wmh4
pkg: @hulumi/policies
eco: npm
published: May 21, 2026
Impact: @hulumi/policies versions before 1.3.2 used stack-wide evidence shortcuts in several Cloudflare and deployment-governance validators. Unrelated compliant-looking evidence could suppress violations for different zones, hostnames, origins, or repositories in the same stack.

Patched in 1.3.2: …

GitHub-GHSA

HIGH
@hulumi/policies: CIS 1.16 admin policy bypass for inline and attached IAM policies
GHSA-4xrh-5m3m-328w
pkg: @hulumi/policies
eco: npm
published: May 21, 2026
Impact: @hulumi/policies versions before 1.3.2 did not fully inspect inline and attached IAM policy evidence for the administrator-policy guardrail, so some admin-equivalent policy paths could pass policy evaluation.

Patched in 1.3.2: the validator inspects the affected policy shapes and includes r…

GitHub-GHSA

HIGH
@hulumi/policies: HULUMI-H1 SecureBucket parent spoof bypass
GHSA-g43v-9x7q-83pq
pkg: @hulumi/policies
eco: npm
published: May 21, 2026
Impact: @hulumi/policies versions before 1.3.2 could accept spoofed SecureBucket parent evidence for HULUMI-H1, allowing policy evaluation to miss an unsafe bucket shape.

Patched in 1.3.2: the validator now correlates evidence to the expected component/resource relationship and includes regression …

GitHub-GHSA

HIGH
@hulumi/drift: Orphan reconciler accepted externally supplied execute plans
GHSA-2ffm-hxrq-qqmm
pkg: @hulumi/drift
eco: npm
published: May 21, 2026
Impact: @hulumi/drift versions before 1.3.2 could accept externally supplied execute plans without sufficient provenance checks, allowing unsafe reconciliation input to be treated as trusted.

Patched in 1.3.2: execute-plan handling now validates provenance and rejects untrusted plans, with regressi…

GitHub-GHSA

HIGH
Plonky3 MultiField32Challenger: transcript malleability and challenge entropy loss
GHSA-vj64-rjf3-w3v7
pkg: p3-challenger, p3-challenger
eco: rust
published: May 21, 2026
### Impact

– **Key**: `challenger/src/multi_field_challenger.rs` | `MultiField32Challenger::duplexing` | `transcript_malleability`
– **Affected files**: `challenger/src/multi_field_challenger.rs`, `field/src/helpers.rs`
– **Violated invariant**: The Fiat-Shamir sponge must bind challenges to the ex…

CVE-2026-46654
GitHub-GHSA

HIGH
Fission runtime pods automount the fission-fetcher service-account token into the user function container, granting function code namespace-wide secret / configmap read
GHSA-85g2-pmrx-r49q
pkg: github.com/fission/fission
eco: go
published: May 21, 2026
### Summary

Fission runtime pods were created with `ServiceAccountName: fission-fetcher`, and the `fission-fetcher` ServiceAccount was granted namespace-wide `get` on `secrets` and `configmaps` (it needs that to load function code, env vars, and config). The runtime pod's automounted token was reac…

CVE-2026-46617
GitHub-GHSA

HIGH
samlify: XML Injection in AttributeValue Allows Privilege Escalation in Signed SAML Assertions
GHSA-34r5-q4jw-r36m
pkg: samlify
eco: npm
published: May 21, 2026
## Summary

samlify’s template substitution only escapes attribute contexts. Values inserted into element text (e.g., `<saml:AttributeValue>`) are not escaped. A normal user can inject XML markup into an attribute value (e.g., email, name) and add new `<saml:Attribute>` elements inside the signed …

CVE-2026-46490
GitHub-GHSA

HIGH
Windows-MCP: HTTP transports expose unauthenticated PowerShell control with wildcard CORS
GHSA-vrxg-gm77-7q5g
pkg: windows-mcp
eco: pip
published: May 21, 2026
HTTP transports expose unauthenticated PowerShell control with wildcard CORS

There is an issue in the SSE and Streamable HTTP transport modes. The default stdio mode is not affected, but the documented HTTP modes expose the MCP control plane without authentication and add wildcard CORS handling aro…

GitHub-GHSA

HIGH
@angular/platform-server: SSRF via Hostname Hijacking
GHSA-rfh7-fxqc-q52v
pkg: @angular/platform-server, @angular/platform-server, @angular/platform-server
eco: npm
published: May 19, 2026
### Impact

A Server-Side Request Forgery (SSRF) vulnerability exists in `@angular/platform-server`. The issue stems from how the server-side rendering (SSR) engine processes the request URL provided to the rendering entry points.

When an absolute-form URL (e.g., `http://evil.com`) is passed to the…

CVE-2026-46417
GitHub-GHSA

HIGH
FileBrowser Quantum: unauthenticated user share share info
GHSA-3jmg-p96m-m328
pkg: github.com/gtsteffaniak/filebrowser/backend, github.com/gtsteffaniak/filebrowser
eco: go
published: May 19, 2026
### Impact
Some sensitive info — such as source and path can get exposed.

### Patches
Update to the latest version

### Workarounds
no

CVE-2026-46410
GitHub-GHSA

HIGH
CamoFox MCP: Unauthenticated HTTP MCP browser-control surface
GHSA-7hgr-7h44-33w2
pkg: camofox-mcp
eco: npm
published: May 19, 2026
# Unauthenticated HTTP MCP browser-control surface in `camofox-mcp`

## Summary

`camofox-mcp` exposed a Streamable HTTP MCP endpoint at `/mcp` with rate limiting but no inbound MCP-layer authentication. When HTTP mode was enabled, any client that could reach `/mcp` could list and invoke browser-con…

GitHub-GHSA

HIGH
libcrux-ml-dsa: Signature Verification on AVX2 Platforms Mishandles Edge Case
GHSA-fhvh-vw7h-9xf3
pkg: libcrux-ml-dsa
eco: rust
published: May 19, 2026
The AVX2 implementation of ML-DSA verification incorrectly implemented
the `use_hint` function, mishandling an edge case that should lead to
signature rejection.

## Impact
An attacker could make the ML-DSA verifier accept a crafted invalid
signature under a maliciously generated verification key, i…

GitHub-GHSA

HIGH
libcrux: Potential Panic on Overlong Ciphertext Buffer
GHSA-hc3c-63hc-2r9f
pkg: libcrux-chacha20poly1305
eco: rust
published: May 19, 2026
An application that passes in a ciphertext buffer of length greater
than `ptxt.len() + TAG_LEN` to `libcrux_chacha20poly1305::encrypt` or
`libcrux_chacha20poly1305::xchacha20_poly1305::encrypt` would
experience a panic.

## Impact
An application where the length of the ciphertext buffer is under
att…

GitHub-GHSA

HIGH
zrok copy writes attacker-controlled WebDAV paths outside the destination root
GHSA-c656-jcx2-7pqj
pkg: github.com/openziti/zrok/v2, github.com/openziti/zrok
eco: go
published: May 19, 2026
## Summary

Alice runs `zrok2 copy` from a WebDAV or zrok drive controlled by Bob into a local filesystem target. Bob returns a DAV `href` such as `/../outside.txt`. The sync pipeline stores that path in the source inventory and passes it to `FilesystemTarget.WriteStream`, which joins it with the ta…

CVE-2026-45576
GitHub-GHSA

HIGH
HAXcms: Mass Token Exfiltration and Cross-Tenant Hijack
GHSA-x3x5-7h4h-gwxg
pkg: @haxtheweb/haxcms-nodejs
eco: npm
published: May 19, 2026
### Summary
An attack chain utilizing **Stored XSS** alongside dynamic token exposure in the `/system/api/connectionSettings` endpoint allows an authenticated attacker to perform a complete cross-tenant account takeover. The API dynamically leaks the active session's authentication tokens (including…
CVE-2026-46511
GitHub-GHSA

HIGH
Stored XSS via <iframe> in HAX CMS allows access to sensitive client-side data and account takeover
GHSA-jh3h-rpxg-fr36
pkg: @haxtheweb/haxcms-nodejs, @haxtheweb/video-player, @haxtheweb/iframe-loader
eco: npm
published: May 19, 2026
### Summary
A stored cross-site scripting (XSS) vulnerability exists in HAX CMS due to improper sanitization of `<iframe>` elements.

The application allows `javascript:` URIs in the `src` attribute, which are executed when a malicious page is viewed. This enables attackers to execute arbitrary Java…

CVE-2026-46396
GitHub-GHSA

HIGH
HAX open-apis: Credential Theft via Server-Side Request Forgery (SSRF) in open-apis
GHSA-4fg7-f244-3j49
pkg: @haxtheweb/open-apis
eco: npm
published: May 19, 2026
### Summary
Multiple functions conduct substring-only matching to validate hostnames to which basic authorization should be sent. An attacker can append the matched substrings to an attacker-controlled endpoint and capture authentication.

### Details
[api/services/website/cacheAddress.js](https://g…

CVE-2026-46391
GitHub-GHSA

HIGH
HAXcms createSite SSRF Enables Arbitrary File Read
GHSA-q862-gcgq-5m6g
pkg: @haxtheweb/haxcms-nodejs
eco: npm
published: May 19, 2026
### Summary
An authenticated Server-Side Request Forgery (SSRF) vulnerability in HAXcms allows users to fetch arbitrary internal or local resources and write the responses to a web-accessible directory, enabling arbitrary file read and internal network access.

### Details
The `createSite` endpo…

CVE-2026-46393
GitHub-GHSA

HIGH
Scriban: array.insert_at index parameter DoS bypasses LoopLimit and LimitToString
GHSA-24c8-4792-22hx
pkg: scriban
eco: nuget
published: May 19, 2026
## Summary

`ArrayFunctions.InsertAt` in Scriban allocates `index – list.Count` null entries in a tight C# `for` loop with no bound on `index`. The function is exposed to template authors as `array.insert_at`, and the fill loop ignores every existing safety control: `LoopLimit`, `LimitToString`, `Ob…

GitHub-GHSA

HIGH
CloakBrowser: Unauthenticated path traversal via fingerprint parameter in cloakserve leads to arbitrary directory deletion
GHSA-mf33-gv72-w2h5
pkg: cloakbrowser
eco: pip
published: May 18, 2026
The `cloakserve` CDP multiplexer uses the user-supplied `fingerprint` query parameter directly as a filesystem path component when creating Chrome profile directories. An unauthenticated attacker who can reach the cloakserve port can supply a crafted `fingerprint` value containing path traversal seq…
CVE-2026-45727
GitHub-GHSA

HIGH
eduMFA Passkeys: missing expiration flag may allow replay attacks and reuse of old challenges
GHSA-j5rm-v3vh-vx94
pkg: edumfa
eco: pip
published: May 18, 2026
### Impact
In eduMFA < 2.9.1 userless Passkey/WebAuthn challenges might be replayed and do not expire

### Patches
Fixed in eduMFA >= 2.9.1 by adding validity information to the userless challenges.

### Workarounds
No known workarounds besides disabling userless login altogether.

GitHub-GHSA

HIGH
eduMFA: Incorrect InnoDB snapshot isolation possibly allows token reusage
GHSA-qq2p-4282-cfc5
pkg: edumfa
eco: pip
published: May 18, 2026
### Impact

For deployments using MySQL or MariaDB < 11.6.2 (or newer with innodb_snapshot_isolation=off) reusage of token values might be possible due to faulty transaction isolation inside the database. Exploiting this requires racing this transaction.
Affected are all tokentypes whose values are …

GitHub-GHSA

MEDIUM
n8n: Credential exfiltration via Allowed HTTP Request Domains Bypass
GHSA-3875-8gcx-7v46
pkg: n8n
eco: npm
published: May 19, 2026
## Impact
The `POST /rest/dynamic-node-parameters/options` endpoint allowed any authenticated user to cause the n8n server to issue HTTP requests including credentials bypassing the intended restrictions on which hosts could be contacted for that credential (Allowed HTTP Request Domains). The user n…
GitHub-GHSA

MEDIUM
Amazon SageMaker Python SDK is missing integrity verification in its Triton inference handler
GHSA-rq6v-x3j8-7qgf
pkg: sagemaker, sagemaker
eco: pip
published: May 21, 2026
## Summary
Amazon SageMaker Python SDK is an open-source library for training and deploying machine learning models on Amazon SageMaker. An issue exists where, under certain circumstances, the Triton inference handler deserializes model artifacts without performing integrity verification, allowing s…
CVE-2026-8597
GitHub-GHSA

MEDIUM
Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of CVE-2026-25580)
GHSA-cqp8-fcvh-x7r3
pkg: pydantic-ai, pydantic-ai-slim
eco: pip
published: May 21, 2026
## Summary

When an application using Pydantic AI opts a URL into `force_download='allow-local'` (which disables the default block on private/internal IPs), the cloud-metadata blocklist could be bypassed by encoding the metadata IP in an IPv6 transition form (IPv4-mapped IPv6, 6to4, or NAT64). Dual-…

CVE-2026-46678
GitHub-GHSA

MEDIUM
Nezha Monitoring: Nezha WebSocket server stream discloses cross-tenant server telemetry to authenticated members
GHSA-hvv7-hfrh-7gxj
pkg: github.com/nezhahq/nezha
eco: go
published: May 23, 2026
### Summary

Any authenticated non-admin member can connect to the server-status WebSocket and receive telemetry for all servers, including servers owned by other users. The normal server list API filters objects by `HasPermission`, but the WebSocket stream treats the presence of any authenticated u…

CVE-2026-47124
GitHub-GHSA

MEDIUM
instagrapi: Unsafe signup challenge path handling in instagrapi
GHSA-ggxf-37hm-9wqf
pkg: instagrapi
eco: pip
published: May 23, 2026
instagrapi versions before 2.6.9 accepted server-supplied signup challenge paths and used them to build request URLs before validating that the paths were relative Instagram API paths. A malicious or tampered challenge payload could cause challenge handling requests to be sent outside the intended I…
GitHub-GHSA

MEDIUM
aiograpi: Unsafe signup challenge path handling
GHSA-jh37-x3fv-4×72
pkg: aiograpi
eco: pip
published: May 23, 2026
aiograpi versions before 0.9.10 accepted server-supplied signup challenge paths and used them to build request URLs before validating that the paths were relative Instagram API paths. A malicious or tampered challenge payload could cause challenge handling requests to be sent outside the intended In…
CVE-2026-47157
GitHub-GHSA

MEDIUM
FlaskBB: SSRF in get_image_info() via unrestricted avatar URL
GHSA-xq32-9g7q-7297
pkg: flaskbb
eco: pip
published: May 21, 2026
###Summary
A Server-Side Request Forgery (SSRF) vulnerability in get_image_info() allows any authenticated user to force the server to send HTTP requests to arbitrary internal endpoints, including cloud metadata services (e.g., AWS 169.254.169.254). This is a blind SSRF with confirmed internal port …
CVE-2026-46556
GitHub-GHSA

MEDIUM
NocoDB: Missing File Size Enforcement in Upload-by-URL Allows Denial of Service via Disk Exhaustion
GHSA-99vc-2jx2-688p
pkg: nocodb
eco: npm
published: May 21, 2026
### Summary

The `uploadViaURL` path in the v1/v2 attachment API did not enforce `NC_ATTACHMENT_FIELD_SIZE` against the remote `content-length` or against the response stream. An authenticated user (Editor+) could direct the server to download arbitrarily large files, exhausting disk space and causi…

CVE-2026-46551
GitHub-GHSA

MEDIUM
Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint
GHSA-686c-7vgv-v3fx
pkg: github.com/coder/coder/v2, github.com/coder/coder/v2, github.com/coder/coder/v2
eco: go
published: May 19, 2026
## Summary

Unauthenticated semi-blind Server-Side Request Forgery (SSRF) via the Azure instance identity endpoint (`POST /api/v2/workspaceagents/azure-instance-identity`). An external attacker can force the Coder server to issue HTTP GET requests to arbitrary internal or external hosts by submittin…

CVE-2026-45796
GitHub-GHSA

MEDIUM
HAX CMS: Denial of Service using Malicious Import Request
GHSA-9r33-xhw8-4qqp
pkg: @haxtheweb/haxcms-nodejs
eco: npm
published: May 19, 2026
### Summary

The HAX CMS NodeJS application crashes when an authenticated attacker sends a specially crafted site creation request to the createSite endpoint. A single request is sufficient to take the entire application offline, requiring a manual server restart to restore service.

### Details

Th…

CVE-2026-46357
GitHub-GHSA

MEDIUM
OpenTelemetry eBPF Instrumentation: Redis error text is exported in span status messages
GHSA-8rrq-wcg8-cv5q
pkg: go.opentelemetry.io/obi
eco: go
published: May 18, 2026
### Summary

OBI exports raw Redis error text as the span status message. Because Redis error replies can contain attacker-controlled or sensitive values, this behavior can exfiltrate tokens, PII, or other confidential input into telemetry backends and inject untrusted text into downstream analysis …

CVE-2026-45679
GitHub-GHSA

MEDIUM
Budibase: CouchDB Reduce Injection via Unsanitized Calculation Parameter in V1 Views API
GHSA-363w-hvwh-w7m6
pkg: @budibase/server
eco: npm
published: May 18, 2026
# Security Advisory: CouchDB Reduce Injection via Unsanitized Calculation Parameter in V1 Views API

**Affected Software:** Budibase
**Affected Component:** `packages/server/src/api/controllers/view/viewBuilder.ts`, `packages/server/src/api/routes/view.ts`
**CWE:** CWE-94 (Improper Control of Genera…

CVE-2026-45719
GitHub-GHSA

MEDIUM
brace-expansion: Large numeric range defeats documented `max` DoS protection
GHSA-jxxr-4gwj-5jf2
pkg: brace-expansion
eco: npm
published: May 18, 2026
The `max` option was being applied too late:

When expanding a single large numeric range like `{1..10000000}`, the sequence generation loop generates all 10 million intermediate elements before the `max` limit is applied With `max=10`, the output is correctly limited to 10 items, but the process st…

CVE-2026-45149
GitHub-GHSA

MEDIUM
eduMFA: Unauthenticated Failcounter Increment on Resolver Tokens via /validate/check
GHSA-74r7-3mjm-jc5v
pkg: edumfa
eco: pip
published: May 18, 2026
### Impact
If the resolver parameter is passed, but the user does not exist, all failcounters of tokens in that resolver will be increased.

### Patches
This, along with other issues, was fixed in eduMFA v2.9.1.

### Workarounds
Limiting access to `/validate/check` to client applications (i.e. Shibb…

GitHub-GHSA

MEDIUM
n8n-MCP: Workflow telemetry sanitizer could retain partial values from URL-shaped node parameters
GHSA-f3rg-xqjj-cj9w
pkg: n8n-mcp
eco: npm
published: May 18, 2026
## Summary

In affected versions of n8n-mcp, the workflow telemetry sanitizer could retain partial fragments of URL-shaped node parameters before sending workflow data to the project's anonymous telemetry backend. Values placed in HTTP-Request-style node parameters — such as customer or tenant ide…

CVE-2026-45582
GitHub-GHSA

MEDIUM
n8n: Legacy ExecuteWorkflow Node Bypassed File Path Restrictions
GHSA-2vx9-7wpg-88jq
pkg: n8n
eco: npm
published: May 19, 2026
## Impact
The `ExecuteWorkflow` node's `localFile` source option read workflow files from disk without applying checks enforced by other file-reading nodes. An authenticated user with permission to create or modify workflows could supply an arbitrary file path via the REST API, bypassing the `N8N_RE…
GitHub-GHSA

MEDIUM
Klever-Go KVM read-only execution can commit contract delete and upgrade side effects
GHSA-jc6w-wmfc-fh33
pkg: github.com/klever-io/klever-go
eco: go
published: May 21, 2026
## Publisher note

**Fixed in `v1.7.17`.** Operators running `< v1.7.17` should upgrade. Contract delete and upgrade host-core paths now reject execution when `runtime.ReadOnly()` is true. The invariant is regression-tested for delete, upgrade, storage writes, value transfers, and any VM output fiel…

CVE-2026-46403
GitHub-GHSA

MEDIUM
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations
GHSA-rg3g-4rw9-gqrp
pkg: github.com/argoproj/argo-cd/v3, github.com/argoproj/argo-cd/v3, github.com/argoproj/argo-cd/v3
eco: go
published: May 19, 2026
### Summary
The original fix for [GHSA-3v3m-wc6v-x4x3](https://github.com/argoproj/argo-cd/security/advisories/GHSA-3v3m-wc6v-x4x3) is incomplete. argocd app diff –server-side-diff can still expose Kubernetes Secret values embedded in the kubectl.kubernetes.io/last-applied-configuration annotation.…
CVE-2026-45737
GitHub-GHSA

MEDIUM
Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameter
GHSA-9mvm-4gwg-v8mp
pkg: github.com/getarcaneapp/arcane/backend
eco: go
published: May 18, 2026
## Summary

`GET /environments/{id}/volumes/{volumeName}/browse` accepts a `path` query parameter that is passed to a shell command (`sh -c "find … | while …"`) inside an Arcane helper container. The path sanitiser blocks `../` traversal but does not strip Bourne-shell metacharacters such as `$(…

CVE-2026-45626
GitHub-GHSA

MEDIUM
ImageMagick: Heap Buffer Over-Write in json and yaml encoder of a single byte due to incorrect fix
GHSA-jqq5-8px3-9m6m
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 21, 2026
An incorrect fix that was applied in GHSA-5592-p365-24xh could result in a heap buffer over-write of a single byte.
GitHub-GHSA

MEDIUM
OpenMcdf: Uncatchable infinite loop in DirectoryTree.TryGetDirectoryEntry on crafted CFB directory cycle
GHSA-5qwm-7pvp-w988
pkg: OpenMcdf
eco: nuget
published: May 19, 2026
### Summary
The BST name-lookup loop in `DirectoryTree.TryGetDirectoryEntry` (`OpenMcdf/DirectoryTree.cs:35-46`) walks directory entries by repeatedly calling `directories.TryGetSibling(child, siblingType, validateColor)`. A crafted CFB file with cyclic Left/Right sibling links among directory entri…
CVE-2026-45785
GitHub-GHSA

MEDIUM
ImageMagick: Stack overflow in fx operation
GHSA-rcr6-g7jc-f57g
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 18, 2026
Due to a missing depth check a stack overflow can occur in the fx operation by passing a crafted argument.
CVE-2026-46557
GitHub-GHSA

MEDIUM
ImageMagick: Use-After-Free in MSL decoder.
GHSA-5r4x-w6p5-222q
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 18, 2026
A crafted MSL image can trigger a heap-use-after-free.
CVE-2026-46523
GitHub-GHSA

MEDIUM
NocoDB: Reflected Cross-Site Scripting via Page Leaving Redirect URL
GHSA-9qgr-6vpg-9gh9
pkg: nocodb
eco: npm
published: May 21, 2026
### Summary
A reflected XSS vulnerability exists in the Page Leaving Warning page. The `ncRedirectUrl` and `ncBackUrl` query parameters are used in `window.location.href` and `<a>` tag bindings without validation, allowing `javascript:` URI injection.

### Details
`PageLeavingWarning.vue` reads `ncR…

CVE-2026-46547
GitHub-GHSA

MEDIUM
Apify Model Context Protocol (MCP) server: Domain Allowlist Bypass in fetch-apify-docs via String Prefix Matching
GHSA-jwp7-wg77-3w9v
pkg: @apify/actors-mcp-server
eco: npm
published: May 19, 2026
### Summary
The `fetch-apify-docs` tool validates URLs against a domain allowlist using `String.startsWith()` instead of proper URL hostname comparison. This allows bypass via attacker-controlled subdomains (e.g., `https://docs.apify.com.evil.com/`), enabling the tool to fetch and return arbitrary w…
CVE-2026-46341
GitHub-GHSA

MEDIUM
Docker: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swap
GHSA-vp62-88p7-qqf5
pkg: github.com/docker/docker, github.com/moby/moby/v2, github.com/moby/moby
eco: go
published: May 18, 2026
## Summary

A race condition during `docker cp` mount setup allows a malicious container to create empty files or directories at arbitrary absolute paths on the host filesystem.

This advisory covers the race during mountpoint creation. The related race during the subsequent mount syscall is tracked…

CVE-2026-41568
GitHub-GHSA

MEDIUM
nimiq-primitives: BlockInclusionProof interlink issue when hops are empty
GHSA-799f-29jm-gr6c
pkg: nimiq-primitives
eco: rust
published: May 21, 2026
### Impact
A logic flaw in `BlockInclusionProof::is_block_proven` causes the function to return true without performing any cryptographic verification when `get_interlink_hops` yields an empty hop list. This occurs when the target block is at the election block position immediately preceding the ele…
CVE-2026-46539
GitHub-GHSA

MEDIUM
Mailpit: Concurrent map read & write in proxy CSS rewriter – remote unauth crash (fatal error: concurrent map read and map write)
GHSA-w4vj-r5pg-3722
pkg: github.com/axllent/mailpit
eco: go
published: May 19, 2026
### Summary
The screenshot/print proxy (/proxy?data=…) maintains a package-level assets map[string]MessageAssets cache, but reads the map without holding assetsMutex while a long-running cleanup goroutine and (re-entrant) CSS-rewriting code path concurrently write to it under the lock. When the un…
CVE-2026-45712
GitHub-GHSA

MEDIUM
Mailpit: Path traversal & arbitrary file write in mailpit dump –http via attacker-controlled message IDs
GHSA-qx5x-85p8-vg4j
pkg: github.com/axllent/mailpit
eco: go
published: May 19, 2026
### Summary
The mailpit dump –http <base-url> <out-dir> sub-command downloads every message from a remote Mailpit instance and writes each one as <id>.eml inside the user-supplied output directory. The message ID field is taken verbatim from the JSON response of the remote server and concatenated i…
CVE-2026-45711
GitHub-GHSA

MEDIUM
OpenTelemetry eBPF Instrumentation: CPU-mismatch fallback uses 256-byte buffer with 8KB size
GHSA-r6c9-g6q5-qrf9
pkg: go.opentelemetry.io/obi
eco: go
published: May 18, 2026
### Summary

The per-CPU message-buffer fallback path uses a 256-byte backup buffer but preserves the original payload size, which can be up to 8KB. If a CPU mismatch occurs, OBI can read beyond the fallback buffer and leak adjacent memory into telemetry.

### Details

https://github.com/open-teleme…

CVE-2026-45681
GitHub-GHSA

MEDIUM
OpenTelemetry eBPF Instrumentation: Unbounded BPF internal metrics replay can exhaust CPU
GHSA-89c6-vpcj-7vj4
pkg: go.opentelemetry.io/obi
eco: go
published: May 18, 2026
### Summary

OBI replays BPF probe hits into histogram observations by looping once per recorded run count. On busy systems, the run-count delta can become very large, causing the metrics exporter to spend excessive CPU time in a tight loop every collection interval.

### Details

The vulnerable loo…

CVE-2026-45680
GitHub-GHSA

MEDIUM
NocoDB: Shared-base link access can invite arbitrary users as persistent base members
GHSA-chqv-vrj7-qffp
pkg: nocodb
eco: npm
published: May 21, 2026
### Summary

Shared-base sessions were granted the same base-member capabilities as authenticated viewers. Using only the shared-base UUID (`xc-shared-base-id`), an attacker could enumerate base members and invite an arbitrary email into the base as a real member. The invited user could then redeem …

CVE-2026-46552
GitHub-GHSA

MEDIUM
Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer
GHSA-j3fj-qppj-fmmc
pkg: github.com/axllent/mailpit
eco: go
published: May 19, 2026
## Summary

The fix for GHSA-6jxm-fv7w-rw5j (CVE-2026-23845, "Server-Side Request Forgery (SSRF) via HTML Check API"), shipped in mailpit `v1.28.3`, hardened `internal/htmlcheck/css.go::downloadCSSToBytes` with a 5MB size cap, a `text/css` content-type check, login-info stripping in `isValidURL`, an…

CVE-2026-45709
GitHub-GHSA

MEDIUM
ImageMagick: Heap Buffer Over-Read in distributed pixel cache server
GHSA-6gxq-f64p-5w6f
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 22, 2026
An attacker who can connect to a magick -distribute-cache service can cause a heap buffer over-read in the server process.
CVE-2026-47166
GitHub-GHSA

MEDIUM
ImageMagick: Out-of-Bounds Read in connected components when the user supplies an invalid keep-top define
GHSA-vhrh-72hq-w8m7
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 18, 2026
An invalid `connected-components:keep-top` value could result in a heap buffer over-read when performing the connected components operation.
CVE-2026-45359
GitHub-GHSA

MEDIUM
fabric-chaincode-java: TLS Private Key Password Disclosed in INFO Startup Logs in Chaincode-as-a-Service Mode
GHSA-wg5x-3g47-v38r
pkg: org.hyperledger.fabric-chaincode-java:fabric-chaincode-shim
eco: maven
published: May 19, 2026
When chaincode is deployed in chaincode-as-a-service mode with TLS enabled, the chaincode server INFO level logging includes the TLS private key password in plaintext. An attacker with access to the chaincode server logs could recover the TLS private key password. If the attacker can also obtain the…
CVE-2026-45581
GitHub-GHSA

MEDIUM
ImageMagick: Heap Buffer Over-Write in MIFF encoder when using LZMA compression
GHSA-jcqp-6r6f-3mfx
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 18, 2026
When using LZMA compression in the MIFF encoder an out of bounds write can occur due to a missing check.
CVE-2026-46521
GitHub-GHSA

MEDIUM
OpenTelemetry eBPF Instrumentation: Unsafe fastelf parsing allows malformed ELF to crash agent
GHSA-wp73-mwgf-4jq9
pkg: go.opentelemetry.io/obi
eco: go
published: May 18, 2026
### Summary

OBI's replacement ELF parser trusts section offsets, counts, and string offsets from the executable file. A crafted local ELF can make OBI dereference invalid section pointers or slice past string tables, causing the agent to panic while determining the process language.

### Details

`…

CVE-2026-45676
GitHub-GHSA

MEDIUM
Nezha Monitoring: RoleMember can fire other users' cron tasks via AlertRule.FailTriggerTasks (no ownership check)
GHSA-rxf6-wjh4-jfj6
pkg: github.com/nezhahq/nezha
eco: go
published: May 23, 2026
## Summary

`createAlertRule` and `createService` (and their `update*` siblings) accept `FailTriggerTasks []uint64` and `RecoverTriggerTasks []uint64` — IDs of cron tasks to fire when the alert/service trips. The validation function only validates the alert's `Rules.Ignore` server map; it never ch…

CVE-2026-47120
GitHub-GHSA

MEDIUM
NocoDB: Refresh Token Cookie Set Without `secure` and `sameSite` Flags
GHSA-f74w-272x-mqcv
pkg: nocodb
eco: npm
published: May 21, 2026
### Summary

The refresh-token cookie was set with `httpOnly: true` but missing both the `secure` flag and the `sameSite` attribute. Over plain HTTP the cookie could be intercepted on the network; without `sameSite`, browsers attached it to cross-site POSTs, enabling CSRF against the token-refresh e…

CVE-2026-46550
GitHub-GHSA

MEDIUM
Umbraco.Cms: Open Redirect Vulnerability in Surface Controllers
GHSA-2qjj-h6wp-c7h7
pkg: Umbraco.Cms, Umbraco.Cms
eco: nuget
published: May 21, 2026
### Impact
Some of the Surface Controllers in the CMS provide to support member related operations fail to validate redirect URLs, making Razor templates that derive 'RedirectUrl' from user-controlled query parameters vulnerable to malicious redirect attacks.

### Patches
The issue is resolved in ve…

CVE-2026-46616
GitHub-GHSA

MEDIUM
Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalization
GHSA-x5w9-xh9r-mvfc
pkg: github.com/caddyserver/caddy/v2
eco: go
published: May 19, 2026
This report is not about a normal textual prefix-expansion case.

The issue here is that the authorization layer and the `/config` traversal layer do **not agree on what object the path refers to**.

In this case, a path authorized for one config object is accepted, but then resolves to a **diffe…

CVE-2026-45692
GitHub-GHSA

MEDIUM
go-git: Crafted repositories may modify main and submodule .git directories
GHSA-crhj-59gh-8×96
pkg: github.com/go-git/go-git/v5, github.com/go-git/go-git/v6, github.com/go-git/go-git
eco: go
published: May 19, 2026
### Impact
A path validation issue in `go-git` could allow crafted repository data to affect files outside the intended checkout target, including the repository's `.git` directory.

These validations were introduced in upstream Git years ago, so the vulnerability arose from go-git drifting from tho…

CVE-2026-45571
GitHub-GHSA

MEDIUM
Budibase: Row Action Trigger Bypasses View Row Filter Security Boundary Allowing Action on Out-of-Scope Rows
GHSA-3263-v5v9-xq8q
pkg: budibase
eco: npm
published: May 18, 2026
## Summary

The row action trigger endpoint (`POST /api/tables/:sourceId/actions/:actionId/trigger`) fails to validate that the user-supplied `rowId` is within the scope of the view's row filters. A user with access to a filtered view can trigger row actions on any row in the underlying table, inclu…

CVE-2026-45718
GitHub-GHSA

MEDIUM
qs has a remotely triggerable DoS: qs.stringify crashes with TypeError on null/undefined entries in comma-format arrays when encodeValuesOnly is set
GHSA-q8mj-m7cp-5q26
pkg: qs
eco: npm
published: May 22, 2026
### Summary

`qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The throw is synchronous and not handled by any of qs's null-related options (`skipNulls`, `strictNullHandling`).

### Details

In the com…

CVE-2026-8723
GitHub-GHSA

MEDIUM
nimiq-blockchain: Genesis batch set request
GHSA-vghx-352f-93jm
pkg: nimiq-blockchain
eco: rust
published: May 21, 2026
### Impact
A remote peer can crash any full node by sending a RequestBatchSet message containing the genesis block's hash. The handler calls `get_epoch_chunks` which iterates backwards through macro blocks using `Policy::macro_block_before`. When it reaches the genesis block number, `macro_block_bef…
CVE-2026-46543
GitHub-GHSA

MEDIUM
protobufjs: Denial of Service via unbounded recursive JSON descriptor expansion
GHSA-jggg-4jg4-v7c6
pkg: protobufjs, protobufjs
eco: npm
published: May 19, 2026
## Summary

protobufjs could recurse without a depth limit while expanding nested JSON descriptors through `Root.fromJSON()` and `Namespace.addJSON()`.

A crafted JSON descriptor with deeply nested namespace definitions could cause the JavaScript call stack to be exhausted during descriptor loading.…

CVE-2026-45740
GitHub-GHSA

MEDIUM
Algernon: Auto-refresh SSE event server binds to all interfaces with Access-Control-Allow-Origin: * and no authentication
GHSA-9v4j-7g44-qcqw
pkg: github.com/xyproto/algernon
eco: go
published: May 19, 2026
### Summary

When auto-refresh is enabled, Algernon spins up an SSE handler that streams a `data:` line for every filesystem event under the watched directory. The handler performs **no authentication** of any kind — no shared token, no cookie check against the `permissions2` userstate, no IP allo…

GitHub-GHSA

MEDIUM
ImageMagick: Policy Bypass in MNG coder could
GHSA-g5mf-wqq5-vwg6
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 18, 2026
Because of a missing check in the MNG coder it would be possible to read more images than the list limit policy would allow resulting in excessive resource use.
CVE-2026-45664
GitHub-GHSA

MEDIUM
NiceGUI: Unauthenticated log-volume denial of service in dynamic resource routes
GHSA-pq7c-x8g4-rvp6
pkg: nicegui
eco: pip
published: May 18, 2026
### Summary

Two FastAPI routes that serve per-component static assets in NiceGUI accept a sub-path parameter that may resolve to a directory rather than a file. Requests that resolve to a directory raise an unhandled `RuntimeError` inside Starlette's `FileResponse`, which Uvicorn writes to the serv…

CVE-2026-45554
GitHub-GHSA

MEDIUM
ImageMagick: Policy Bypass in PSD decoder
GHSA-cwpj-h54c-xjpx
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 18, 2026
Due to a missing check in the PSD decoder it would be possible to bypass the `list-length` resource policy when decoding a PSD image. Other security limits would still apply.
CVE-2026-45031
GitHub-GHSA

MEDIUM
ImageMagick: Out-of-Bounds Read of a single byte in meta encoder
GHSA-cr6r-hmj8-pr7r
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 18, 2026
An of by one in the meta encoder could result in an out of bounds read of a single byte in the meta encoder.
CVE-2026-45358
GitHub-GHSA

MEDIUM
webpack-dev-server vulnerable to cross-origin source code exposure on non-HTTPS origins
GHSA-79cf-xcqc-c78w
pkg: webpack-dev-server
eco: npm
published: May 18, 2026
### Impact

When webpack-dev-server is running on a non-HTTPS origin (the default), cross-origin requests from malicious websites can load the dev server's JavaScript bundles via `<script>` tags. The fix introduced in v5.2.1 (CVE-2025-30359) relied on `Sec-Fetch-Mode` and `Sec-Fetch-Site` request he…

CVE-2026-6402
GitHub-GHSA

MEDIUM
ImageMagick: Heap Buffer Over-Read of a 4 bytes in distort operation.
GHSA-pfvh-m9xv-8966
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 18, 2026
When performing a polynomial distortion an out of bounds over-read of 24 bytes can occur when specifying specific arguments.
CVE-2026-45624
GitHub-GHSA

MEDIUM
OpenTelemetry eBPF Instrumentation: CappedConcurrentHashMap leaks keys after removals
GHSA-962q-hwm5-52×5
pkg: go.opentelemetry.io/obi
eco: go
published: May 18, 2026
### Summary

The custom `CappedConcurrentHashMap` introduced for Java TLS state tracking never removes keys from its insertion-order queue when entries are deleted. In long-running instrumented JVMs, repeated connection churn can therefore grow the queue without bound and exhaust heap memory.

### D…

CVE-2026-45682
GitHub-GHSA

MEDIUM
ImageMagick: Heap Buffer Over-Read in IPTC encoder
GHSA-7wff-wpr6-vmhm
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 18, 2026
When writing an IPTC output file a malicious input file could cause an out of bounds read of a single byte.
CVE-2026-42326
GitHub-GHSA

MEDIUM
pyload-ng: SSRF via HTTP Redirect Bypass in parse_urls API
GHSA-8rp3-xc6w-5qp5
pkg: pyload-ng
eco: pip
published: May 21, 2026
## Summary

The SSRF mitigation added in commit `33c55da` for GHSA-7gvf-3w72-p2pg is incomplete. The `PREREQFUNCTION`-based private IP check was correctly applied to `HTTPChunk` (download path) but not to `HTTPRequest` (used by the `parse_urls` API). An authenticated attacker can supply a URL pointi…

CVE-2026-46561
GitHub-GHSA

MEDIUM
OpenTelemetry eBPF Instrumentation: Log enricher writev path can overread and overwrite user buffers
GHSA-vvmg-8mjr-g6q3
pkg: go.opentelemetry.io/obi
eco: go
published: May 18, 2026
### Summary

OBI's log enricher mishandles `writev` buffers by reading only the first `iovec` entry but using the total `iov_iter.count` as the copy length. When log injection is enabled, a crafted multi-segment `writev` call can make OBI read and overwrite memory beyond the first segment.

### Deta…

CVE-2026-45684
GitHub-GHSA

MEDIUM
Umbraco.Cms: XSS/HTML Injection in Umbraco Backoffice confirmation dialog
GHSA-vr9v-27gg-qgx4
pkg: Umbraco.Cms
eco: nuget
published: May 21, 2026
### Impact
Authenticated users are able to inject HTML vulnerability into an input field, which is rendered in the confirmation dialog without proper output encoding.

### Patches
This issue has been patched in 17.4.0

CVE-2026-46609
GitHub-GHSA

MEDIUM
Rust OneNote File Parser: Path traversal in `Parser::parse_notebook` allows reading files outside the notebook directory
GHSA-4j5m-wc25-pvh7
pkg: onenote_parser
eco: rust
published: May 21, 2026
### Impact
A maliciously crafted `.onetoc2` table-of-contents file can cause `Parser::parse_notebook` to open arbitrary files on the host filesystem outside the notebook's directory. The parser reads entry names listed inside the `.onetoc2` and joins them against the notebook's base directory withou…
CVE-2026-46671
GitHub-GHSA

MEDIUM
ws: Uninitialized memory disclosure
GHSA-58qx-3vcg-4xpx
pkg: ws
eco: npm
published: May 18, 2026
### Impact

The `websocket.close()` implementation is vulnerable to uninitialized memory disclosure when a `TypedArray` is passed as the reason argument.

### Proof of concept

“`js
import { deepStrictEqual } from 'node:assert';
import { WebSocket, WebSocketServer } from 'ws';

const wss = new WebS…

CVE-2026-45736
GitHub-GHSA

MEDIUM
SQLAdmin: Authorization Bypass on `ajax_lookup`
GHSA-54mc-gghv-4cfj
pkg: sqladmin
eco: pip
published: May 21, 2026
### Impact

The `ajax_lookup` endpoint in `application.py` bypasses the `is_accessible()` access control check that all other endpoints enforce.

If a developer restricts model access by overriding `is_accessible()`, an authenticated user can still query that model's data through the `ajax_lookup` e…

CVE-2026-46645
GitHub-GHSA

MEDIUM
NocoDB: SSRF Protection Bypass in Notification Webhook Plugins (Slack, Discord, Mattermost, Teams)
GHSA-2c5x-4jgf-88mj
pkg: nocodb
eco: npm
published: May 21, 2026
### Summary

The `request-filtering-agent` SSRF protection was non-functional in the four notification webhook plugins (Slack, Discord, Mattermost, Teams) because `httpAgent` / `httpsAgent` were passed as part of the request **body** rather than the axios **config**. An authenticated user with hook-…

CVE-2026-46548
GitHub-GHSA

MEDIUM
nimiq-keys: Denial of service in Ed25519 multisig delinearization via invalid curve points
GHSA-h9cc-w26m-j342
pkg: nimiq-keys
eco: rust
published: May 21, 2026
### Impact

A denial-of-service vulnerability exists in the Ed25519 multisig delinearization code path. `Ed25519PublicKey::delinearize()` in `keys/src/multisig/mod.rs` called `.unwrap()` on curve point decompression, which panics when a public key is
constructed from 32 bytes that do not represent a…

CVE-2026-46542
GitHub-GHSA

MEDIUM
Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: *
GHSA-hw27-4v2q-5qff
pkg: github.com/xyproto/algernon
eco: go
published: May 20, 2026
### Summary

The SSE event server's `Access-Control-Allow-Origin` response header was hardcoded to the wildcard `*` regardless of the caller's `Origin`. Because `EventSource` does not preflight and does not send cookies, the wildcard is sufficient to let any third-party page the developer visits ope…

CVE-2026-46431
GitHub-GHSA

MEDIUM
Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS
GHSA-gj84-924c-48fx
pkg: github.com/xyproto/algernon
eco: go
published: May 20, 2026
### Summary

The SSE event server bound to `0.0.0.0:5553` on Linux/macOS by default because the platform-dependent host default in `engine/flags.go:39-46` set `host = ""` for non-Windows, and `utils.JoinHostPort("", ":5553")` resolves to `":5553"` — a Go `http.Server.Addr` of `":5553"` listens on …

CVE-2026-46430
GitHub-GHSA

MEDIUM
Regression in pymdownx.snippets reintroduces sibling-prefix path traversal bypass despite restrict_base_path
GHSA-62q4-447f-wv8h
pkg: pymdown-extensions
eco: pip
published: May 19, 2026
# Summary

`pymdownx.snippets` has a regression of the CVE-2023-32309 / GHSA-jh85-wwv9-24hv fix. With `restrict_base_path: True` (the default), the current `filename.startswith(base)` containment check does not enforce a directory boundary. As a result, a markdown snippet directive can read files fr…

CVE-2026-46338
GitHub-GHSA

MEDIUM
Caddy: Remote Admin Authorization Bypass on PKI Endpoints via Prefix-Based Path Matching
GHSA-gx7w-56w6-g48x
pkg: github.com/caddyserver/caddy/v2
eco: go
published: May 19, 2026
## AI Disclosure

I used an LLM to help review the source code, reason about attack surface, and help draft and refine this report.
I manually validated the finding by reproducing it locally, confirming the vulnerable code path, and verifying the HTTP behavior with `curl -v`.

## Summary

Ca…

GitHub-GHSA

MEDIUM
Budibase: Missing Cache Invalidation on Public API Role Unassignment Allows Revoked Users to Retain Privileges for Up to 1 Hour
GHSA-6vp2-6r7m-2jvx
pkg: @budibase/backend-core
eco: npm
published: May 19, 2026
## Summary

The public API role unassignment endpoint (`POST /api/public/v1/roles/unassign`) updates user documents in CouchDB but does not invalidate the corresponding Redis user cache entries. Because the authentication middleware resolves user identity and permissions from this cache (TTL: 3600 s…

CVE-2026-46424
GitHub-GHSA

MEDIUM
ImageMagick: Information Disclosure in distributed pixel cache server because it is not using a challenge–response authentication model
GHSA-2rgj-gx5x-f62w
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 22, 2026
The distributed pixel cache was originally designed to operate without a challenge–response authentication model. However, given today’s heightened security expectations, we have changed our implementation.
CVE-2026-47165
GitHub-GHSA

MEDIUM
ImageMagick: Race Condition in distributed pixel cache server can result in file descriptor hijacking
GHSA-4g75-9r48-jf92
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 22, 2026
An attacker who can connect to a magick -distribute-cache service can hijack a file descriptor in the server process when a race condition is met.
CVE-2026-46693
GitHub-GHSA

MEDIUM
ImageMagick: Heap Buffer Over-Write in distributed pixel cache server
GHSA-p93h-f2jc-477j
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 22, 2026
An attacker who can connect to a `magick -distribute-cache` service can cause a heap buffer over-write in the server process.
CVE-2026-46692
GitHub-GHSA

MEDIUM
ImageMagick: Heap Buffer Over-Write of a single byte in the JP2 encoder.
GHSA-533m-3wf6-c33v
pkg: Magick.NET-Q16-AnyCPU, Magick.NET-Q16-HDRI-AnyCPU, Magick.NET-Q16-HDRI-OpenMP-arm64
eco: nuget
published: May 18, 2026
An incorrect check in the JP2 will result in an heap buffer over-write of a single byte when specifying certain options.
CVE-2026-46559
GitHub-GHSA

MEDIUM
Flask-Security-Too OAuth reauthentication freshness bypass via cross- user OAuth identity acceptance
GHSA-97r5-pg8x-p63p
pkg: Flask-Security-Too
eco: pip
published: May 22, 2026
### Summary

Flask-Security-Too 5.8.0's OAuth reauthentication flow can mark a
session as fresh after verifying an OAuth account that belongs to a
different user.

If an attacker can operate an already-authenticated but stale victim
session, they can complete OAuth verification using their…

CVE-2026-46715
GitHub-GHSA

MEDIUM
@hulumi/baseline: CloudTrail selector tampering events were not fully detected
GHSA-gfp8-mp24-5vxg
pkg: @hulumi/baseline
eco: npm
published: May 21, 2026
Impact: @hulumi/baseline versions before 1.3.2 could miss some CloudTrail event-selector tampering evidence, reducing coverage for changes to audit logging configuration.

Patched in 1.3.2: detection coverage and regression tests were expanded.

Remediation: upgrade @hulumi/baseline to 1.3.2 or late…

GitHub-GHSA

MEDIUM
Fission builder accepts arbitrary buildcmd strings from Environment.spec.builder.command, allowing the builder pod to invoke arbitrary executables
GHSA-7pjr-qpvh-m339
pkg: github.com/fission/fission
eco: go
published: May 21, 2026
### Summary

Before the round-1 security sweep, `pkg/builder/builder.go` passed `Environment.spec.builder.command` directly into `exec.Command(…)` after a `strings.Fields` split, with no validation of the executable path or its arguments. A user who could create or update `Environment` CRDs in a n…

CVE-2026-46618
GitHub-GHSA

MEDIUM
@sveltejs/kit: `query.batch` cross-talk
GHSA-hgv7-v322-mmgr
pkg: @sveltejs/kit
eco: npm
published: May 21, 2026
`query.batch()` could, under very rare and specific timings, cause concurrent requests from different users to merge and resolve under single request context, enabling cross-user data disclosure.
GitHub-GHSA

MEDIUM
Mobile Verification Toolkit (MVT): Path Traversal via unsanitized File identifiers in iOS Backup processing
GHSA-5h3g-px23-w6vw
pkg: mvt
eco: pip
published: May 21, 2026
### Summary

The `fileID` field from `Manifest.db` (a SQLite database inside iOS backups, generated by the device) is used directly in filesystem path construction without validation. This affects two commands through a shared code path:

– **`mvt-ios decrypt-backup`** (`decrypt.py`): `file_id` is u…

CVE-2026-46486
GitHub-GHSA

MEDIUM
Flowise: Cross-Workspace Chatflow Disclosure via chatflows/apikey Endpoint Returns All Unprotected Chatflows
GHSA-c2c9-mfw7-p8hw
pkg: flowise
eco: npm
published: May 20, 2026
## Summary

The `/api/v1/chatflows/apikey/:apikey` endpoint (whitelisted, accessible with API key auth only) returns all chatflows bound to the provided API key AND all chatflows across the entire system that have no API key assigned. This crosses workspace boundaries, allowing a user in Workspace A…

GitHub-GHSA

MEDIUM
Flowise: Mass Assignment in PUT /api/v1/user Allows Authenticated Users to Override Password Hash and Bypass Password Change Verification
GHSA-59fh-9f3p-7m39
pkg: flowise
eco: npm
published: May 20, 2026
### Summary
A Mass Assignment vulnerability in the PUT /api/v1/user endpoint allows authenticated users to directly modify restricted user fields, including the credential (password hash), bypassing the intended password change workflow.

Because the endpoint forwards the entire request body to the …

GitHub-GHSA

MEDIUM
Flowise: Hardcoded CORS wildcard on TTS endpoint enables cross-origin credential abuse from any webpage
GHSA-m837-xvxr-vqwg
pkg: flowise
eco: npm
published: May 20, 2026
### Summary

The TTS generation endpoint sets `Access-Control-Allow-Origin: *` as a hardcoded response header, independent of the server's CORS configuration. This enables any webpage to make cross-origin requests to generate speech using stored credentials.

### Root Cause

“`typescript
// package…

GitHub-GHSA

MEDIUM
RTK improperly trusts project-local filter configuration, allowing silent tampering of command output shown to LLM
GHSA-fvvm-949w-qj4w
pkg: rtk
eco: rust
published: May 20, 2026
RTK (Rust Token Killer) improperly trusts project-local configuration files. In versions prior to 0.32.0, RTK automatically loads `.rtk/filters.toml` from the working directory with highest priority and without user notification. An attacker can place a malicious filter file in a repository to apply…
CVE-2026-45792
GitHub-GHSA

MEDIUM
rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
GHSA-phqj-4mhp-q6mq
pkg: openssl
eco: rust
published: May 19, 2026
`CipherCtxRef::cipher_update_inplace` incorrectly sized output buffers when used with AES key-wrap-with-padding ciphers (EVP_aes_{128,192,256}_wrap_pad). For a non-multiple-of-8 input, OpenSSL writes up to 7 bytes past the end of the caller's buffer or Vec, producing attacker-controllable heap corru…
CVE-2026-45784
GitHub-GHSA

MEDIUM
Trubo: Login callback CSRF/session fixation
GHSA-hcf7-66rw-9f5r
pkg: turbo
eco: npm
published: May 19, 2026
### Impact

Turborepo's self-hosted login and SSO browser flows did not validate a CSRF state value on the localhost callback. While the CLI was waiting for authentication, a malicious web page could send a request to the local callback server with an attacker-controlled token. If accepted before th…

CVE-2026-45773
GitHub-GHSA

MEDIUM
Diesel: Command injection in Diesel's implementation of `COPY FROM`/`COPY TO`
GHSA-m9p2-fxp5-v3fp
pkg: diesel
eco: rust
published: May 19, 2026
Diesel allows users to configure various options for PostgreSQL's `COPY FROM` and `COPY TO` statements. These configurations are partially provided as strings or characters.

Diesel did not check if any these user-provided options contain a quote character `'`, which can lead to the injection of ad…

GitHub-GHSA

MEDIUM
Diesel: Possible unaligned data access for implementations of `SqliteAggregate`
GHSA-q8x8-jrhj-fh9p
pkg: diesel
eco: rust
published: May 19, 2026
Diesel allows to register custom aggregate SQL functions for SQLite via the `SqliteAggregate` interface.

To store an instance of the custom aggregate processor Diesel relied on the `sqlite3_aggregate_context` function provided by sqlite. This function doesn't provide any guarantees about alignment …

GitHub-GHSA

MEDIUM
Caddy CVE-2026-30852 Fix Bypass
GHSA-wwhq-w58m-w29c
pkg: github.com/caddyserver/caddy/v2
eco: go
published: May 19, 2026
#

## TL;DR

CVE-2026-30852 fixed double expansion in `vars_regexp` when the variable key is a placeholder (e.g. `{http.vars.x}`). The fix does NOT protect literal key names (e.g. `tenant_id`). An attacker injects `{env.AWS_SECRET_ACCESS_KEY}` or `{file./etc/passwd}` via a request header → Caddy …

GitHub-GHSA

MEDIUM
Kong Ingress Controller for Kubernetes (KIC): Cross-namespace TLS Secret Exfiltration in Gateways with GatewayClass missing `konghq.com/gatewayclass-unmanaged: 'true'` annotation
GHSA-m23h-6mwm-39m8
pkg: github.com/kong/kubernetes-ingress-controller/v3, github.com/kong/kubernetes-ingress-controller/v3, github.com/kong/kubernetes-ingress-controller/v2
eco: go
published: May 19, 2026
## Summary

A vulnerability in the Kong Ingress Controller (KIC) allows for the unauthorized exfiltration of TLS certificates and private keys across Kubernetes namespace boundaries. In "managed" mode (where the `GatewayClass` lacks an unmanaged annotation), the Gateway TLS translator skips critical…

GitHub-GHSA

MEDIUM
Kong Ingress Controller for Kubernetes (KIC): Secret-backed plugin configurations leak through non-sensitive diagnostics endpoint
GHSA-3278-c88v-xrh4
pkg: github.com/kong/kubernetes-ingress-controller/v3, github.com/kong/kubernetes-ingress-controller/v2, github.com/kong/kubernetes-ingress-controller
eco: go
published: May 19, 2026
## Summary

A vulnerability in the Kong Ingress Controller (KIC) allows for the unauthorized exposure of sensitive plugin credentials through the diagnostics interface. Even when configured to redact sensitive information (using `–dump-sensitive-config=false`), KIC fails to sanitize the `Plugins` f…

GitHub-GHSA

MEDIUM
Envoy AI Proxy – MCP Message Smuggling Vulnerability
GHSA-4gph-2hhr-5mwg
pkg: github.com/envoyproxy/ai-gateway
eco: go
published: May 19, 2026
Envoy AI Gateway was found to be affected by a protocol parser differential vulnerability due to improper implementation of the JSON-RPC 2.0 specification. Such differential causes a MCP message alteration, potentially causing a bypass of security controls in a multi-layered architecture.

According…

GitHub-GHSA

MEDIUM
Nuxt: Dev server exposes built source over LAN to malicious sites (incomplete fix for GHSA-4gf7-ff8x-hq99)
GHSA-6m52-m754-pw2g
pkg: @nuxt/rspack-builder, @nuxt/rspack-builder, @nuxt/webpack-builder
eco: npm
published: May 19, 2026
### Summary
This is an incomplete fix for [GHSA-4gf7-ff8x-hq99](https://github.com/nuxt/nuxt/security/advisories/GHSA-4gf7-ff8x-hq99). Source code may be stolen during dev when using the webpack / rspack builder if the dev server is bound to a non-loopback address (e.g. `nuxt dev –host`) and the de…
CVE-2026-45670
GitHub-GHSA

MEDIUM
Nuxt: Reflected XSS in `navigateTo()` external redirect
GHSA-fx6j-w5w5-h468
pkg: nuxt, nuxt
eco: npm
published: May 19, 2026
### Summary
`navigateTo()` with `external: true` generates a server-side HTML redirect body containing a `<meta http-equiv="refresh">` tag. The destination URL is only sanitized by replacing `"` with `%22`, leaving `<`, `>`, `&`, and `'` unencoded. An attacker who can influence the URL passed to `na…
CVE-2026-45669
GitHub-GHSA

MEDIUM
HAX CMS: Stored XSS via '<video-player>' component allows arbitrary JavaScript execution and token theft
GHSA-2m6p-hm3w-6jm3
pkg: @haxtheweb/haxcms-nodejs, @haxtheweb/video-player
eco: npm
published: May 19, 2026
### Summary
A stored cross-site scripting (XSS) vulnerability exists in HAX CMS due to improper sanitization of the `<video-player>` component.

The component allows `javascript:` URIs in the `source` attribute, which are executed when the page is viewed. This enables attackers to execute arbitrary …

CVE-2026-46496
GitHub-GHSA

MEDIUM
Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix
GHSA-65pc-fj4g-8rjx
pkg: idna
eco: pip
published: May 19, 2026
This is the same issue as CVE-2024-3651, however the original remediation in 2024 was not a complete fix. Payloads such as `"\u0660" * N` or `"\u30fb" * N + "\u6f22"` utilize the `valid_contexto` function prior to length rejection, and for high values of `N` will take a long time to process.

### Im…

CVE-2026-45409
GitHub-GHSA

MEDIUM
Microsoft DirectX12: .spritefont multiply overflow only in 32-bit builds
GHSA-5r97-79vw-qvm4
pkg: directxtk12_desktop_win10, directxtk12_uwp
eco: nuget
published: May 18, 2026
### Impact
The spritefont reader can be induced to perform a 32-bit overflow multiply that could in theory result in a RCE.

This impacts the use of the *DirectX Tool Kit* **SpriteFont** class file loading ctor if given untrusted data files.

> Note this only applies to x86/ARM builds of the library…

GitHub-GHSA

MEDIUM
Microsoft DirectX: .spritefont multiply overflow only in 32-bit builds
GHSA-c55g-rp4x-fx84
pkg: directxtk_desktop_win10, directxtk_uwp
eco: nuget
published: May 18, 2026
### Impact
The spritefont reader can be induced to perform a 32-bit overflow multiply that could in theory result in a RCE.

This impacts the use of the *DirectX Tool Kit* **SpriteFont** class file loading ctor if given untrusted data files.

> Note this only applies to x86/ARM builds of the library…

GitHub-GHSA

MEDIUM
Neotoma: Unauthenticated Inspector/API access via reverse-proxy loopback auth bypass
GHSA-5cvp-p7p4-mcx9
pkg: neotoma
eco: npm
published: May 18, 2026
Neotoma versions starting at v0.6.0 can treat public reverse-proxied requests as local when the app receives them over a loopback socket and no Bearer token is present.

In affected deployments, the REST auth middleware can resolve unauthenticated requests as the local development user, making the h…

CVE-2026-45577