CISA-KEV
CRITICAL
Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV
CRITICAL
Citrix NetScaler Improper Input Validation Vulnerability
Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV
CRITICAL
Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV
CRITICAL
Microsoft SharePoint Code Injection Vulnerability
Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV
CRITICAL
WordPress Core Remote File Inclusion Vulnerability
WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV
CRITICAL
WSO2 Multiple Products Path Traversal Vulnerability
WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV
CRITICAL
Adobe Commerce and Magento Incorrect Authorization Vulnerability
Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV
CRITICAL
F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability
F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV
CRITICAL
Check Point Multiple Products Path Traversal Vulnerability
Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticated attacker to upload and execute arbitrary scripts.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV
CRITICAL
Check Point Multiple Products Improper Certificate Validation Vulnerability
Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA-KEV
CRITICAL
Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchest…
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
GitHub-GHSA
CRITICAL
Decepticon: Role-boundary forgery via ChatML special-token literals in web crawl output composed into LLM context
GHSA-g5f9-3xfg-p9mf
pkg: decepticon-core, decepticon, decepticon-sdk
eco: pip
published: Sep 24, 2026
## Summary
Decepticon wraps web crawl results — the output of agent reconnaissance against target services — into LLM messages without neutralizing ChatML special-token literals. Under the BYOK (Bring Your Own Key) deployment model, users configure their own LLM credentials to any OpenAI-compat…
CVE-2026-61732
GitHub-GHSA
CRITICAL
SunEditor: Critical XSS vulnerability – sanitizer bypass
GHSA-6rf4-v2fh-m6p4
pkg: suneditor
eco: npm
published: Sep 24, 2026
## Summary
SUNEDITOR `v2.47.10` appears to allow JavaScript execution through crafted namespaced HTML elements.
The sanitization logic does not fully remove executable event-handler attributes from certain custom/namespaced tags. As a result, an attacker may be able to inject HTML content that exe…
CVE-2026-59167
NVD
CRITICAL
CVE-2026-86708
ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private key in the Applications Manager installer, which could allow an unauthenticated attacker to impersonate the service account and access or modify associated cloud…
CWE: CWE-321
GitHub-GHSA
CRITICAL
[mcp-atlassian] Authentication bypass in HTTP transport: AtlassianOpaqueTokenVerifier accepts any non-empty token
GHSA-wrhw-j3f9-8vc6
pkg: mcp-atlassian
eco: pip
published: Sep 22, 2026
**Description**
mcp-atlassian deploys in two common patterns:
Pattern A (single-user, server-side credentials): operator sets
JIRA_USERNAME + JIRA_API_TOKEN (or CONFLUENCE_USERNAME + CONFLUENCE_API_TOKEN)
in environment variables. Server uses these to call Jira/Confluence.
This is th…
CVE-2026-77244
NVD
CRITICAL
CVE-2026-77521
MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.5-lts, assistants with a tool, MCP tool, skill, or sub-application use SandboxShellBackend, which exposes an execute shell tool without excluding it and omits execute from interrupt_on, so human approval is not required. Untr…
CWE: CWE-78, CWE-250, CWE-749
NVD
CRITICAL
CVE-2026-100717
froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl rejects carriage return and line feed characters only in the path, query and fragment components returned by parse_url, and never inspects the userinfo (user:pass@) components. This is an incomplete fix f…
CWE: CWE-93
NVD
CRITICAL
CVE-2026-93425
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the patch.readRepoDirectories tRPC procedure passes the user-controlled repoPath value from apps/dokploy/server/api/routers/patch.ts into a shell command in packages/server/src/services/patch-repo.ts without safe argume…
CWE: CWE-78
NVD
CRITICAL
CVE-2026-93577
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on the GitLab server due to an integer overflow issue when compil…
CWE: CWE-190
NVD
CRITICAL
CVE-2026-89078
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on the GitLab server due to a double free issue when parsing a sp…
CWE: CWE-415
NVD
CRITICAL
CVE-2026-84719
A flaw was found in the Ansible Automation Platform automation-controller. When a
WorkflowJobTemplate is copied, the deep-copy permission sanitizer validates only the inventory,
unified_job_template, and credentials of each cloned node and fails to check the instance_groups
(and execution_environmen…
CWE: CWE-862
NVD
CRITICAL
CVE-2026-77602
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.1.0 until 7.3.0, authenticated non-administrator users can write content under targets_modified/ that is later executed by multiple configuration paths below the intended co…
CWE: CWE-94
GitHub-GHSA
CRITICAL
OpenC3 COSMOS: Authenticated remote code execution via the user-writable config overlay (table definitions, cmd/tlm definitions, and script suites)
GHSA-jjq7-m736-w977
pkg: openc3
eco: rubygems
published: Sep 23, 2026
### Summary
COSMOS reads configuration from a user-writable overlay (`targets_modified/`) before the read-only plugin-installed `targets/` tree, and the config subsystem executes code on those files: `ConfigParser` renders every file as ERB by default, a `GENERIC_READ_CONVERSION` / `GENERIC_WRITE_C…
CVE-2026-77602
GitHub-GHSA
CRITICAL
plone.app.portlets Vulnerable to Remote Code Execution via TALES Injection
GHSA-rr49-f9g6-c9r5
pkg: plone.app.portlets, plone.app.portlets, plone.app.portlets
eco: pip
published: Sep 23, 2026
### Impact
The Classic portlet (plone.app.portlets.portlets.classic) used its user-supplied template/macro fields to build a TALES path expression that was then evaluated by the TAL path() helper. Because the value was interpreted as a full TALES expression, a user able to add or edit a Classic port…
CVE-2026-57149
NVD
CRITICAL
CVE-2026-57149
plone.app.portlets.portlets provides a Plone-specific user interface for plone.portlets, as well as a standard set of portlets that ship with Plone. Starting in version 5.0.0 and prior to versions 5.0.8, 6.0.4, and 7.0.2, the Classic portlet (plone.app.portlets.portlets.classic) used its user-suppli…
CWE: CWE-95
NVD
CRITICAL
CVE-2026-79920
Ajenti is a Linux & BSD modular server admin panel. Prior to version 2.2.16, any authenticated user can call /api/core/tasks/start to enqueue InstallPlugin, UnInstallPlugin, or UpgradeAll from plugins/plugins/tasks.py without plugin-management authorization. InstallPlugin and UnInstallPlugin constru…
CWE: CWE-862
NVD
CRITICAL
CVE-2026-101090
Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect endpoint. When the new optional dashboard_host setting is empty, /api/v1/oauth2/{provider} (cmd/dashboard/controller/oauth2.go) reflects the attacker-supplied HTTP Host header into the redirect_uri sent to the identity pr…
CWE: CWE-601
NVD
CRITICAL
CVE-2026-101065
Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the Docker quickstart command documented in the README starts the container listening on 0.0.0.0:8080 with authentication disabled by default. When authentication is disabled, every request is mapped to…
CWE: CWE-306
NVD
CRITICAL
CVE-2026-100741
Eval injection in the JScript event-script dispatcher in Progressive Robot Ltd's hMailServer, versions 6.0.0 through 6.3.3 on Windows, allows a remote, unauthenticated attacker to run arbitrary JScript inside the hMailServer service process, with the privileges of the service account, via a password…
CWE: CWE-95
NVD
CRITICAL
CVE-2026-92161
FriendsOfFlarum OAuth allows users to log in to Flarum with GitHub, Twitter, Facebook, and other providers. Prior to 1.7.4 and 2.0.0-beta.4, the Discord OAuth provider does not check the verified field returned for an OAuth email before passing the address to Flarum core as trusted through provideTr…
CWE: CWE-345
NVD
CRITICAL
CVE-2026-97230
IO::Socket::SSL::SelfCertificate versions 1.00 for Perl contains malware which executes Python code from an obfuscated URL.
The generate_certificate runs a Python script saved as a certificate file. The pyhton script attempts to retrieve code from a hardcoded http URL that is obfuscated with base6…
CWE: CWE-506
NVD
CRITICAL
CVE-2026-93207
In the Linux kernel, the following vulnerability has been resolved:
SUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decode_credbody() entry
svcauth_gss_decode_credbody() writes the caller's
rpc_gss_wire_cred field by field and assigns gc_ctx.len only on
the success tail. The caller storage is svcda…
NVD
CRITICAL
CVE-2026-88351
An integer overflow vulnerability exists in the MPack Node API in MPack 1.1.1 on 32-bit platforms. When parsing a specially crafted MessagePack array32 or map32 object with an excessively large element count, the page allocation size calculation in mpack_tree_parse_children() can overflow size_t and…
CWE: CWE-190
NVD
CRITICAL
CVE-2026-96758
orval @orval/core before 8.28.0 contains a code injection vulnerability in the form-data serializer that fails to escape multipart property names in generated template literals. Attackers can inject ${…} expressions into OpenAPI schema property names that execute as live interpolation when the gen…
CWE: CWE-94
NVD
CRITICAL
CVE-2026-96755
orval versions 8.14.0 through 8.28.1 contain a code injection vulnerability in the @orval/effect generator that converts OpenAPI schema defaults into template literals. Attackers can inject arbitrary JavaScript expressions via schema defaults containing ${…} syntax, which are executed at module sc…
CWE: CWE-94
NVD
CRITICAL
CVE-2026-82331
Improper link resolution before file access ('link following') vulnerability in the `tar` source plugin of Apache BuildStream running on Python < 3.12 allows malicious source tarballs to write files on the host, with the privileges of the user running BuildStream, via symlinks as part of source fetc…
CWE: CWE-59
NVD
CRITICAL
CVE-2026-94127
When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth C…
CWE: CWE-122
NVD
CRITICAL
CVE-2026-65113
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of hard-coded credentials. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, denial of service, and information disclosure.
CWE: CWE-798
NVD
CRITICAL
CVE-2026-93012
Email::Sender::Transport::Sendmail versions before 2.602 for Perl allow arbitrary command execution on Windows sending a message whose envelope address reaches the shell in _sendmail_pipe.
On MSWin32 the envelope sender and every recipient go into a single command string, which open() passes to a s…
CWE: CWE-78
NVD
CRITICAL
CVE-2026-85751
Mailu is a mail server distributed as a set of Docker images. From Mailu 2.0 until 2024.06.55 and prior to Mailu helm-charts 2.7.3, deployments with PROXY_AUTH_WHITELIST configured but REAL_IP_HEADER unset trusted a client-controlled X-Forwarded-By header for header-based proxy authentication. The p…
CWE: CWE-290, CWE-807
NVD
CRITICAL
CVE-2026-101084
obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated user to connect to restricted MCP servers if they possess the server ID. Attackers can bypass authorization checks to access and manipulate sensitive backend systems through MCP…
CWE: CWE-639
GitHub-GHSA
CRITICAL
Moquette: Pattern-ACL wildcard injection (cross-tenant authorization bypass) plus a remote-unauthenticated DoS cluster, a Will-message authorization bypass, and a cross-session durable-corruption bug
GHSA-5f42-97gr-vfhq
pkg: io.moquette:moquette-broker
eco: maven
published: Sep 23, 2026
moquette is reachable by untrusted MQTT clients (anonymous by default), so every byte from any client, including pre-authentication, is untrusted. This is a memory-safe JVM: the ceiling is authorization/ACL bypass + denial of service + cross-session integrity, **not RCE** (I did not find one and do …
CVE-2026-85724
NVD
CRITICAL
CVE-2026-86059
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy organization members without Git provider access can retrieve plaintext provider credentials through github.one, gitlab.one, gitea.one, and bitbucket.one because those protected procedures return full provider r…
CWE: CWE-200, CWE-862
GitHub-GHSA
CRITICAL
http4s-scala-xml has an XML External Entity (XXE) processing issue
GHSA-cjx3-73hr-rpw7
pkg: org.http4s:http4s-scala-xml_2.12, org.http4s:http4s-scala-xml_2.13, org.http4s:http4s-scala-xml_2.13
eco: maven
published: Sep 24, 2026
http4s-scala-xml provides `EntityDecoder[F, scala.xml.Elem]` instances that parse XML message bodies. These decoders used a `javax.xml.parsers.SAXParserFactory` obtained from `SAXParserFactory.newInstance` without any security configuration. With the JDK's default settings, the parser resolves DOCT…
CVE-2026-61741
NVD
CRITICAL
CVE-2026-18872
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to stored cross-site scripting (CWE-79) in the FTM UI NetworkAcknowledgement React component (NetworkAcknowledgement.jsx:42). A malicious actor can inject script into stored network acknowledgement data that executes in authe…
CWE: CWE-79
NVD
CRITICAL
CVE-2026-58491
Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.5, the /@warpgate/api/sso/providers/:name/start endpoint stores an attacker-controlled next parameter that the POST /@warpgate/api/sso/return handler inserts without HTML escaping into the response generated by war…
CWE: CWE-79
NVD
CRITICAL
CVE-2026-92288
Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth2 token introspection because checkEndPointAuthenticationCredentials does not verify the client secret of a public Relying Party.
checkEndPointAuthenticationCredentials() skips th…
CWE: CWE-1390
NVD
CRITICAL
CVE-2026-86930
An out-of-bounds read vulnerability in FileMaker Server for Linux allowed an attacker uploading a specially crafted image file to a container field to disclose process memory during thumbnail generation in FileMaker WebDirect. This vulnerability is addressed in FileMaker Server version 26.0.3.
CWE: CWE-125
GitHub-GHSA
CRITICAL
lightrag-hku: No Rate Limiting on /login Endpoint Allows Brute-Force Attacks
GHSA-frch-4w6v-q5xx
pkg: lightrag-hku
eco: pip
published: Sep 22, 2026
### Summary
The POST /login endpoint has no rate limiting, account lockout, or delay on failed attempts. An attacker can submit unlimited password guesses at full network speed.
### Details
“`python
# lightrag/api/lightrag_server.py:2161
@app.post("/login")
async def login(form_data: OAuth2Passwo…
CVE-2026-85734
NVD
CRITICAL
CVE-2026-89282
The Apache Lounge Windows distribution of Apache HTTP Server build contains an insecure installation directory permissions vulnerability through its default install directory on C:\, which inherits write access for Authenticated Users.
CWE: CWE-732
NVD
CRITICAL
CVE-2026-94456
Postiz generates security-sensitive credentials using `Math.random()` instead of a cryptographically secure source. The same helper is used for OAuth access tokens, authorization codes, client secrets, organization API keys, and PKCE verifiers, meaning these credentials depend entirely on V8’s det…
CWE: CWE-330, CWE-338, CWE-341
NVD
CRITICAL
CVE-2026-82378
Incorrect Authorization in the OAuth 1.0a authorization endpoint of Apache Roller 6.1.5 allows an unauthenticated remote attacker who learns an outstanding request token for a configured site-wide consumer to bind that token to an arbitrary user account, including an administrator, by submitting an …
CWE: CWE-863
NVD
CRITICAL
CVE-2026-82843
The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.4.0 does not bind the OpenID Connect identity assertion it issues to the authorization grant being exchanged, returning instead the assertion belonging to whichever user authenticated most recently, which allows users with the Su…
CWE: CWE-287
GitHub-GHSA
CRITICAL
DBHub HTTP transport DNS rebinding allows unauthenticated browser-origin SQL execution
GHSA-fm8p-53ww-hf6w
pkg: @bytebase/dbhub
eco: npm
published: Sep 24, 2026
### Summary
DBHub `0.21.2` exposes an unauthenticated HTTP MCP endpoint when started with the documented HTTP transport mode, for example `–transport http –port 8080`.
The HTTP server attempts to protect browser-origin access by checking whether the `Origin` hostname equals the `Host` hostname, …
CVE-2026-61742
GitHub-GHSA
CRITICAL
ixo Blockchain x/bonds DID-resolved payer drain + x/entity ICA authorization bypass
GHSA-w3rp-4cm2-4wgc
pkg: github.com/ixofoundation/ixo-blockchain/v8, github.com/ixofoundation/ixo-blockchain/v7, github.com/ixofoundation/ixo-blockchain/v6
eco: go
published: Sep 24, 2026
Impact
Type: Improper authorization leading to unauthorized movement of user funds.
The x/bonds module moved funds from an address that was resolved from a DID verification method, without verifying that the resolved address belonged to the transaction signer. Affected handlers included MsgMak…
CVE-2026-61604
GitHub-GHSA
CRITICAL
Home Assistant: XSS in Statistics Graph Card
GHSA-wx4m-69m9-gx3m
pkg: homeassistant
eco: pip
published: Sep 22, 2026
### Summary
An authenticated party can add a malicious name to any statistics-capable entity, allowing for
Cross-Site Scripting attacks against anyone who views a Statistics Graph card containing that
entity, when they hover over any data point on the chart.
**Payload**
<img width="1529" height="44…
CVE-2026-91130
GitHub-GHSA
CRITICAL
OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack
GHSA-34fc-gh42-pj53
pkg: github.com/openbao/openbao, github.com/openbao/openbao
eco: go
published: Sep 22, 2026
### Impact
When running in the highly privileged recovery mode, OpenBao was vulnerable to a timing attack against the single recovery token. This allowed an attacker to extract the recovery token and use it to perform operations against the OpenBao instance, including reading or modification of dat…
CVE-2026-63132
NVD
HIGH
CVE-2026-101062
Obot before v0.23.0 (affected versions <= v0.22.1) running with OBOT_SERVER_ENABLE_AUTHENTICATION=true exposes OAuth dynamic client registration without authentication and without any restriction on the redirect URIs a client may register. Because the authorization flow auto-completes for an already…
CWE: CWE-863
NVD
HIGH
CVE-2026-100871
Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 fail to include firewall identification in JWT tokens issued by separate Admin and Shop API endpoints. Attackers can register a shop customer account using an administrator's email address and obtain a token that the Admin API resol…
CWE: CWE-287
NVD
HIGH
CVE-2026-100865
Heym before 0.0.53 evaluates workflow condition expressions using Python's eval() with insufficient sandboxing in the workflow executor service. Authenticated users can edit workflow condition nodes or import malicious templates to execute arbitrary Python and OS commands as the backend process user…
CWE: CWE-94
NVD
HIGH
CVE-2026-100864
heym before 0.0.91 contains a sandbox escape vulnerability in the expression engine's DotList map/filter and fallback resolver that allows authenticated users to execute arbitrary Python code. Attackers can craft workflow expressions using dunder attribute access through item expressions or the fall…
CWE: CWE-94
NVD
HIGH
CVE-2026-96795
Horilla is an HR and CRM software. Prior to 2.0.0, HorillaListView.export_data in horilla_views/generic/cbv/views.py accepts an authenticated user's columns POST parameter, takes field_tuple[1], interpolates it into dynamic_fn_str as Python source, and passes the generated function definition to exe…
CWE: CWE-94
GitHub-GHSA
HIGH
Knowns Unrestricted Path Traversal leading to out-of-bounds arbitrary .md file read, write, and deletion in MCP Docs + Memory Tools
GHSA-9gfj-28hw-jchp
pkg: knowns
eco: npm
published: Sep 25, 2026
## Overview
Verified. Multiple **Unrestricted Path Traversal** vulnerabilities exist in the Knowns MCP `docs` and `memory` tools, allowing arbitrary file read, write, and deletion operations outside the project sandbox. The storage layer functions (`Get`, `Create`, `Update`, `Rename`, `Delete`) in …
CVE-2026-86439
GitHub-GHSA
HIGH
Cline: Cross-Origin WebSocket Hijacking in Cline Hub Dashboard (`/browser` endpoint)
GHSA-3cj3-hqcr-g934
pkg: cline
eco: npm
published: Sep 24, 2026
### Summary
The Cline Hub dashboard server (`@cline/cline-hub`), launched via the `cline dashboard` CLI command, accepts WebSocket connections on the `/browser` endpoint without validating the HTTP `Origin` header. When `ROOM_SECRET` is not set—the default for local (`127.0.0.1`) binds—`isAutho…
CVE-2026-59723
NVD
HIGH
CVE-2026-77601
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.12.0 until 7.3.0, an authenticated actor can write the pypi_url setting through set_setting at POST /openc3-api/api, then cause OpenC3::PluginModel.install_phase2 in openc3/…
CWE: CWE-78
GitHub-GHSA
HIGH
OpenC3 COSMOS: Authenticated OS command injection via the `pypi_url` setting
GHSA-vp3w-52v9-q57f
pkg: openc3
eco: rubygems
published: Sep 23, 2026
## Summary
An authenticated user can execute arbitrary operating system commands on the `openc3-cosmos-cmd-tlm-api` service. The `pypi_url` setting is interpolated, unescaped, into a command line that is run through a shell backtick when a plugin is installed. Shell metacharacters in the setting val…
CVE-2026-77601
NVD
HIGH
CVE-2026-18490
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to unauthenticated remote code execution via Java native deserialization on the PayDir Business Rules Manager RMI SSL endpoint (BrmRMISSLServerSocketFactory.java:95, EP8). An adjacent-network attacker can deliver a crafted se…
CWE: CWE-502
NVD
HIGH
CVE-2026-96455
The Reachy Mini daemon exposes an HTTP API for managing the robot. Its app installation endpoint, POST /apps/install in src/reachy_mini/daemon/app/routers/apps.py, has no authentication. The handler's only dependency is Depends(get_app_manager), which just hands back the manager object from applicat…
CWE: CWE-306, CWE-494
GitHub-GHSA
HIGH
KubeEdge: Command Injection in NodeUpgradeJob – RCE on edge nodes via v1alpha2 API
GHSA-5jpj-293f-rhvj
pkg: github.com/kubeedge/kubeedge, github.com/kubeedge/kubeedge, github.com/kubeedge/kubeedge
eco: go
published: Sep 22, 2026
## Impact
The KubeEdge NodeUpgradeJob handler constructed the `keadm upgrade edge` command by concatenating the user-controlled `spec.version` and `spec.image` fields into a shell command.
An authenticated user with permission to create or update `NodeUpgradeJob` resources through the v1alpha2 API…
CVE-2026-62371
GitHub-GHSA
HIGH
KubeEdge: ConfigUpdateJob updateFields enables remote shell injection and code execution on edge nodes
GHSA-m3c6-2p7h-cfr3
pkg: github.com/kubeedge/kubeedge, github.com/kubeedge/kubeedge, github.com/kubeedge/kubeedge
eco: go
published: Sep 22, 2026
## Description
KubeEdge ConfigUpdateJob processing was vulnerable to command injection on edge nodes.
The `updateFields` values from a ConfigUpdateJob were concatenated into a command string and executed through a system shell. An authenticated user with sufficient permissions to create or update …
CVE-2026-62182
GitHub-GHSA
HIGH
MCP Atlassian: ENABLED_TOOLS / Toolset authorization bypass
GHSA-3r68-hf9h-887v
pkg: mcp-atlassian
eco: pip
published: Sep 22, 2026
### Summary
`ENABLED_TOOLS` and `TOOLSETS` filters are enforced at `tools/list` time only. `tools/call` dispatches from the full unfiltered tool registry (73 tools). Any user with access to the server endpoint that knows a tool name can invoke it directly. Tool names are not secret since mcp-atlass…
CVE-2026-77243
GitHub-GHSA
HIGH
deepstream: PATCH_MULTI action bypasses Valve permission system allowing unauthorized record writes
GHSA-89vx-jh4q-vg3w
pkg: @deepstream/server
eco: npm
published: Sep 22, 2026
## Summary
The `RECORD_ACTION.PATCH_MULTI` action is not registered in the Valve permission system's `RULES_MAP` (`src/services/permission/valve/rules-map.ts`). When `ConfigPermission.canPerformAction()` is called for a PATCH_MULTI message, `getRulesForMessage()` returns `null` because the action i…
CVE-2026-63116
NVD
HIGH
CVE-2026-13087
A heap out-of-bounds write vulnerability was found in the Linux kernel's RPC-over-RDMA server reply path in net/sunrpc/xprtrdma/svc_rdma_sendto.c. When a crafted RPC-over-RDMA client sends a large NFS READ request with an empty Write list and no Reply chunk, the server linearizes the entire multi-pa…
CWE: CWE-787
NVD
HIGH
CVE-2026-65128
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause SQL injection. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.
CWE: CWE-89
NVD
HIGH
CVE-2026-62182
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.21.0 until 1.21.2, 1.22.2, and 1.23.1, ConfigUpdateJob processing in edge/pkg/taskmanager/actions/configupdatejob.go concatenates authenticated user-controlled updateF…
CWE: CWE-78
NVD
HIGH
CVE-2026-62371
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.12.0 until 1.21.2, 1.22.2, and 1.23.1, the v1alpha2 NodeUpgradeJob handler in edge/pkg/taskmanager/actions/nodeupgradejob.go concatenates authenticated user-controlled…
CWE: CWE-78
NVD
HIGH
CVE-2026-53940
Conda is a system-level binary package and environment manager that runs on major operating systems and platforms. Prior to 26.5.2, parse_entry_point_def in conda/common/path/python.py accepted an unvalidated entry-point command from a noarch:python package's info/link.json metadata. CreatePythonEnt…
CWE: CWE-22, CWE-73
NVD
HIGH
CVE-2026-92574
A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container to bypass the destination Kubernetes security context. The restored process may retain credentials, Linux capabilities, no_new_privs, and seccomp state from the checkpoint instead o…
CWE: CWE-250
NVD
HIGH
CVE-2026-100720
Froxlor 2.0.0 through 2.3.10 is vulnerable to stored cross-site scripting. When a customer (the lowest-privileged authenticated role) uploads an SSL certificate for one of their own domains, the Certificates API add()/update() methods parse it with openssl_x509_parse() and store the issuer organizat…
CWE: CWE-79
GitHub-GHSA
HIGH
ZITADEL: Actions V1 sandbox escape: host file read via require()
GHSA-fgmf-7rf8-m6vf
pkg: github.com/zitadel/zitadel
eco: go
published: Sep 24, 2026
### Summary
A vulnerability in ZITADEL Actions V1 allows an organization Action author to read files from the ZITADEL host filesystem through the JavaScript `require()` module loader. On common self-hosted deployments this can be chained to steal bootstrap credentials (including the Login Client PA…
CVE-2026-85057
NVD
HIGH
CVE-2026-85057
ZITADEL is an open source identity management platform. From 3.0.0 until 3.4.13 and 4.16.1, ZITADEL Actions V1 enables the goja Node-compatible require() registry without restricting its filesystem source loader. An organization Action author with ORG_OWNER, org.action.write, and org.flow.write perm…
CWE: CWE-284
NVD
HIGH
CVE-2026-84691
A flaw was found in Red Hat Ansible Automation Platform's automation-
controller. The setting that formats the log message emitted for API 4XX errors
is an administrator-controlled Python format-string template that is rendered
with a live user object as an argument. Because Python string formatting…
CWE: CWE-134
NVD
HIGH
CVE-2026-86064
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /log WebSocket route configured in config/node/api.yaml and registered by network/api/api.go does not require authentication. The first client message is parsed as a logger Profile in network/…
CWE: CWE-200, CWE-306
GitHub-GHSA
HIGH
Klever-Go: /log controls global node logging
GHSA-9v8p-frvj-2pcm
pkg: github.com/klever-io/klever-go
eco: go
published: Sep 23, 2026
An unauthenticated client can connect to `GET /log`, send an arbitrary logger profile as the first WebSocket message, and mutate the node's global logging configuration before receiving live logs from the process. I confirmed this against a local validator built from this repository: an unauthentica…
CVE-2026-86064
GitHub-GHSA
HIGH
Nuclei: Arbitrary Code Execution via Goja JavaScript Engine Vulnerability
GHSA-vxg7-f2jj-jmqm
pkg: github.com/projectdiscovery/nuclei/v3
eco: go
published: Sep 22, 2026
A vulnerability in the Goja JavaScript engine used by Nuclei's `javascript:` protocol allows arbitrary native code execution on the scanner host when running untrusted JavaScript templates.
**Affected Component**
The issue is in the Goja JavaScript runtime embedded in Nuclei's JavaScript protocol …
CVE-2026-76819
GitHub-GHSA
HIGH
MCP Atlassian: Path Traversal / Arbitrary File Read in confluence_upload_attachment MCP tool (incomplete fix of GHSA-xjgw-4wvw-rgm4)
GHSA-p6hp-93wp-fh6p
pkg: mcp-atlassian
eco: pip
published: Sep 22, 2026
## Summary
`mcp-atlassian` exposes an MCP tool `confluence_upload_attachment` whose `file_path` argument is passed directly to `open(file_path, "rb")` without any path validation. An attacker able to invoke the tool can read arbitrary files readable by the server process and exfiltrate them into a …
CVE-2026-77262
GitHub-GHSA
HIGH
MCP Atlassian: Arbitrary File Read & Exfiltration (Confused Deputy) in JIRA update_issue
GHSA-2xj6-xx86-cwwc
pkg: mcp-atlassian
eco: pip
published: Sep 22, 2026
### Summary
A critical Confused Deputy (Arbitrary File Read & Exfiltration) vulnerability in the Atlassian MCP server (Python) allows an AI agent to exfiltrate sensitive host files and environment secrets. By providing absolute system paths to the attachments parameter of the update_issue tool, an a…
CVE-2026-77255
GitHub-GHSA
HIGH
MCP Atlassian: Unauthenticated arbitrary local file read via upload_attachment file_path, chained with missing auth on streamable-http transport
GHSA-cc5h-2pwp-pvcc
pkg: mcp-atlassian
eco: pip
published: Sep 22, 2026
### Summary
In the documented multi-user HTTP deployment (`–transport streamable-http` with global operator Atlassian credentials), sooperset/mcp-atlassian exposes all tools to **unauthenticated network clients**, and the `upload_attachment` tool reads an attacker-supplied `file_path` with **no pat…
CVE-2026-77248
NVD
HIGH
CVE-2026-76086
Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/integrations/form-settings control panel action in IntegrationsController::actionFormSettings is reachable without the required form integration permissions and passes request-supplied settings to a configur…
CWE: CWE-862, CWE-915, CWE-918
NVD
HIGH
CVE-2026-79310
webpy web.py 0.76 is vulnerable to server-side template injection (SSTI). The template engine can be tricked into executing attacker-controlled template code that built-in security checks are designed to reject. When an application precompiles templates from a directory the attacker can write to and…
CWE: CWE-94
NVD
HIGH
CVE-2026-100844
MONAI before 1.6.0 is vulnerable to OS command injection in the nnUNetV2Runner component (monai.apps.nnunet.nnunetv2_runner). User-controlled values taken from the YAML configuration file (notably dataset_name_or_id) and from CLI/kwargs arguments are concatenated into a command string without quotin…
CWE: CWE-78
NVD
HIGH
CVE-2026-100839
Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.18.0, the guest kernel's ACPI/AML handling is vulnerable to an AML injection attack ("BadAML"). ACPI tables containing AML bytecode are passed from the untrusted host (QEMU) to the guest firmware (OVMF) and on to the L…
CWE: CWE-94
GitHub-GHSA
HIGH
CliInvoke.Specializations has command injection in PowerShell and Cmd shell wrappers
GHSA-wrvw-254r-wpmv
pkg: CliInvoke.Specializations, CliInvoke.Specializations, CliInvoke.Specializations
eco: nuget
published: Sep 25, 2026
### Impact
An OS command injection vulnerability exists in the PowerShell and Cmd shell wrappers provided by the `CliInvoke.Specializations` package (the `PowershellProcessInvoker`/`CmdProcessInvoker` invokers, and the `UsePowerShell`/`UseCmd` middleware in v3 pre-release versions).
The wrappers re…
CVE-2026-100368
GitHub-GHSA
HIGH
CliInvoke: Argument Injection in Extensibility Runner Factory
GHSA-j73w-8hfr-4gc9
pkg: CliInvoke, CliInvoke, CliInvoke
eco: nuget
published: Sep 25, 2026
### Impact
An argument-injection vulnerability exists in the `CliInvoke`
package's runner factory: `RunnerProcessFactory` on the 2.x line and
`RunnerConfigurationFactory` on the 3.x line.
The factory joins the runner arguments, the caller's target, and the
caller's arguments into a single `ProcessS…
CVE-2026-100369
NVD
HIGH
CVE-2026-100368
CliInvoke is a .NET library for invoking command-line programs, and its `CliInvoke.Specializations` packages provide specialized wrappers for shells such as PowerShell and Windows Command Prompt. `CliInvoke.Specializations` versions 2.2.0 through 2.8.4, 2.9.0 through 2.9.3, 2.10.0 through 2.10.4, 3.…
CWE: CWE-78
GitHub-GHSA
HIGH
Trestle is vulnerable to arbitrary file write via path traversal in author generate commands (Incomplete fix of CVE-2026-46345)
GHSA-r4vp-3vw6-r2x5
pkg: compliance-trestle, compliance-trestle
eco: pip
published: Sep 24, 2026
**At a glance**
– **Actor:** attacker who controls the -o/–output argument to trestle author {catalog,profile,ssp}-generate (e.g. via a CI pipeline that derives the output directory from repository-controlled data)
– **Primitive:** attacker-controlled –output value reaches trestle_root / args.ou…
CVE-2026-57171
NVD
HIGH
CVE-2026-96749
An integer overflow in the BSON document encoding component of the MongoDB Python Driver's bundled native extension may occur when a single document is built from an unusually large amount of caller-supplied data. Size arithmetic is performed in a signed 32-bit type, and the guard meant to catch the…
CWE: CWE-190
NVD
HIGH
CVE-2026-89281
The Apache Lounge Windows distribution of Apache HTTP Server build contains a hardcoded configuration path vulnerability within openssl.cnf path that can allow local code execution.
CWE: CWE-732
NVD
HIGH
CVE-2026-74766
Net::IDN::Punycode versions from 2.301 before 2.590 for Perl allow a heap use-after-free via a decoded code point that reallocates the output buffer in decode_punycode.
The XS backend inserts each decoded code point into the string buffer of the scalar it returns. decode_punycode computes the inser…
CWE: CWE-416
NVD
HIGH
CVE-2026-55071
MCP-for-Stata is a MCP server for integrating Stata into agent loops with a safety-first design. Prior to version 1.19.0, the ado_package_install MCP tool in stata-mcp concatenates user-controlled input directly into a Stata command string without any validation or sanitization. An attacker who can …
CWE: CWE-94
NVD
HIGH
CVE-2026-100608
Flowise through 3.1.4 does not enforce authorization on the BullMQ admin dashboard. When the server runs in queue mode with the dashboard enabled and not in cloud mode (MODE=queue, ENABLE_BULLMQ_DASHBOARD=true, and !isCloud()), the /admin/queues mount is protected only by the verifyTokenForBullMQDas…
CWE: CWE-862
NVD
HIGH
CVE-2026-100551
OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 do not enforce saved Gateway TLS pins in the Control UI. While native connections enforced the saved Gateway fingerprint, the authenticated Terminal and session Dashboard WebViews omitted it. If a user had accepted a Gateway fingerprint, an attac…
CWE: CWE-295
GitHub-GHSA
HIGH
9router /v1 APIs has unauthenticated access via reverse proxy locality collapse
GHSA-x5c9-v98j-722r
pkg: 9router
eco: npm
published: Sep 23, 2026
## Summary
9router treats local loopback requests as trusted and allows access to `/v1/*` without an
API key. In a documented/common reverse-proxy deployment where nginx forwards public
traffic to the backend via `127.0.0.1`, external non-`Origin` requests are misclassified as
local. This allows un…
CVE-2026-56675
NVD
HIGH
CVE-2026-65114
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause missing authentication for a critical function. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information disclosure.
CWE: CWE-306
NVD
HIGH
CVE-2026-101060
python-utcp versions before 1.1.4 contain a server-side request forgery vulnerability in HttpCommunicationProtocol.call_tool that validates the initial tool URL but follows HTTP redirects without re-validating the target. Attackers controlling a tool endpoint can return a 302 redirect to internal se…
CWE: CWE-918
NVD
HIGH
CVE-2026-100833
Contrast (edgelesssys/contrast) versions 1.14.0 before 1.23.1 generate runtime policies that fail to detect all container image substitutions. A bad rebase during a Kata Containers update accidentally introduced an `allow_storage` rule that accepts storage entries using the `image_guest_pull` driver…
CWE: CWE-20
GitHub-GHSA
HIGH
ZITADEL: MFA bypass via session reuse in Login V2
GHSA-9993-rfwp-rhwf
pkg: github.com/zitadel/zitadel
eco: go
published: Sep 24, 2026
### Summary
A vulnerability in ZITADEL’s Login V2 UI allowed a password-verified browser session to be reused for a new authentication request without re-checking a user’s enrolled second factor (TOTP, OTP, or U2F). An attacker who already knows valid credentials can fully authenticate to an ap…
CVE-2026-85056
NVD
HIGH
CVE-2026-19179
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to manipulate database queries due to improper neutralization of special elements in a boolean expression.
CWE: CWE-74
NVD
HIGH
CVE-2026-65121
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an improper authentication issue. A successful exploit of this vulnerability might lead to escalation of privileges, information disclosure, and data tampering.
CWE: CWE-287
NVD
HIGH
CVE-2026-100838
Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.19.1, the Kata agent policies generated by the Contrast CLI contained a flaw in the CopyFile verification that allowed arbitrary writes to the guest root filesystem. A malicious process on the untrusted host able to co…
CWE: CWE-59
NVD
HIGH
CVE-2026-100680
Budibase versions before 3.45.0 fail to disable external JSON reference resolution in the OpenAPI/Swagger import validator, allowing authenticated builders to read arbitrary local files. Attackers with builder access can embed file:// references in OpenAPI specifications submitted to the import endp…
CWE: CWE-200
NVD
HIGH
CVE-2026-93354
Taskview Community before 1.56.0 contains a missing authentication vulnerability that allows unauthenticated attackers to register arbitrary OAuth clients and take over user accounts by exploiting the OAuth 2.0 Dynamic Client Registration endpoint, which is enabled by default and requires no authent…
CWE: CWE-1188
NVD
HIGH
CVE-2026-94611
authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik API serializers return stored credentials when an account has view permission on an affected configuration, even when that account is not authorized to change the configuration or read its secrets. Af…
CWE: CWE-200, CWE-522
NVD
HIGH
CVE-2026-93224
In the Linux kernel, the following vulnerability has been resolved:
svcrdma: Fix unmatched rn_unregister on failed accept
When svc_rdma_accept() takes the errout path before
rpcrdma_rn_register() has succeeded, the existing cleanup block
calls rpcrdma_rn_unregister(dev, &newxprt->sc_rn) unconditio…
NVD
HIGH
CVE-2026-93221
In the Linux kernel, the following vulnerability has been resolved:
nfsd: convert nfsd_net boolean flags to unsigned long flags word
nfsd_net contains several boolean fields that are accessed from
concurrent contexts without serialization. In particular,
nfsd4_end_grace() guards its drain path wi…
NVD
HIGH
CVE-2026-90959
A path traversal vulnerability was found in pulpcore. The content upload API accepts a 'file_url' parameter that allows users with file repository privileges to specify a local file URL for Pulp to download and store. A URL scheme validation check uses a string prefix comparison that only rejects UR…
CWE: CWE-22
NVD
HIGH
CVE-2026-97055
SigNoz from v0.8.0 before v0.143.0 defaults the JWT tokenizer signing secret (tokenizer::jwt::secret, set via SIGNOZ_TOKENIZER_JWT_SECRET or the deprecated SIGNOZ_JWT_SECRET) to an empty string, and Config.Validate() does not reject the empty value, so a deployment that does not configure a secret s…
CWE: CWE-1188
NVD
HIGH
CVE-2026-96756
orval versions before 8.30.0 contain a code injection vulnerability in the @orval/core factory generator that fails to escape date default values in new Date() calls. Attackers can inject arbitrary expressions through apostrophes in OpenAPI schema defaults to execute code with the privileges of the …
CWE: CWE-94
GitHub-GHSA
HIGH
Tinyauth: forward-auth per-app ACL is matched case-sensitively against the (case-insensitive) hostname, letting an authenticated user reach apps they are not on the allowlist for
GHSA-328g-jx67-v94g
pkg: github.com/tinyauthapp/tinyauth
eco: go
published: Sep 22, 2026
# tinyauth: forward-auth per-app ACL is matched case-sensitively against the (case-insensitive) hostname, letting an authenticated user reach apps they are not on the allowlist for
## GitHub Advisory Details (form fields — paste-ready)
**Affected products**
| Field | Value |
|——-|——-|
…
CVE-2026-77560
GitHub-GHSA
HIGH
KubeEdge: keadm DecompressTarGz path traversal enables arbitrary file write on Windows during edge node join
GHSA-9vm9-pqxx-x83v
pkg: github.com/kubeedge/kubeedge, github.com/kubeedge/kubeedge, github.com/kubeedge/kubeedge
eco: go
published: Sep 22, 2026
## Description
KubeEdge `keadm` contains a path traversal vulnerability in the `DecompressTarGz` archive extraction function.
Archive entry names were joined directly with the extraction destination without sufficient validation. A crafted tar.gz archive containing parent-directory components, Win…
CVE-2026-62369
NVD
HIGH
CVE-2026-75607
Frigate is an open source network video recorder. Prior to 0.17.2, the WebSocket handler in frigate/comms/ws.py forwards attacker-selected message topics to the dispatcher without checking the authenticated user's role because the nginx authentication subrequest does not provide role-aware authoriza…
CWE: CWE-862
GitHub-GHSA
HIGH
Sync-in Server has a complete 2FA Bypass via `POST /api/auth/token`
GHSA-92cr-jxw4-5wjg
pkg: @sync-in/server
eco: npm
published: Sep 22, 2026
**Affected component:** Sync-in Server v2.3.0, `POST /api/auth/token` (`auth.controller.ts:50-55`).
**Required attacker capability:** Valid username and password for a 2FA-enabled account.
## Summary
`POST /api/auth/token` authenticates with username and password only, then calls `getTokens()`, w…
CVE-2026-58269
GitHub-GHSA
HIGH
nginx ignition has Unauthenticated Admin Account Creation via Onboarding Race Condition
GHSA-pxcx-fv34-x9p5
pkg: github.com/lucasdillmann/nginx-ignition
eco: go
published: Sep 21, 2026
## Summary
`POST /api/users/onboarding/finish` is registered as **anonymous (unauthenticated)** and creates a user with **full ReadWrite admin permissions**. Because the handler uses a check-then-act (TOCTOU) pattern between the "onboarding already completed?" check and the user-creation write, wit…
CVE-2026-61628
NVD
HIGH
CVE-2026-58269
Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, `POST /api/auth/token` authenticates with username and password only, then calls `getTokens()`, which returns full access and refresh JWTs without checking whether the account has…
CWE: CWE-288
NVD
HIGH
CVE-2026-62369
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.16.0 until 1.21.2, 1.22.2, and 1.23.1, the DecompressTarGz function in keadm/cmd/keadm/app/cmd/util/common.go joins archive entry names to the extraction destination w…
CWE: CWE-22
NVD
HIGH
CVE-2026-77560
Tinyauth is an authentication and authorization server. Prior to 5.1.2, Tinyauth compares forwarded hostnames case-sensitively while reverse proxies route equivalent hostnames case-insensitively, allowing an authenticated low-privilege user to bypass per-app access controls with a differently cased …
CWE: CWE-178, CWE-636, CWE-863
NVD
HIGH
CVE-2026-61628
nginx ignition is a user interface for the nginx web server. Prior to version 2.41.1, `POST /api/users/onboarding/finish` is registered as anonymous (unauthenticated) and creates a user with full ReadWrite admin permissions. Because the handler uses a check-then-act (TOCTOU) pattern between the "onb…
CWE: CWE-362
NVD
HIGH
CVE-2026-100857
AzuraCast before 0.23.4 contains a code injection vulnerability in the ConfigWriter::cleanUpString() method that fails to sanitize Liquidsoap string interpolation sequences, allowing authenticated users with Media or Profile permissions to inject arbitrary Liquidsoap code into station configuration.…
CWE: CWE-94
NVD
HIGH
CVE-2026-65130
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.
CWE: CWE-78
NVD
HIGH
CVE-2026-100840
MONAI through 1.6.0 contains a remote code execution vulnerability in the bundle configuration engine that resolves _target_ values to arbitrary importable callables without an allow list and passes $ expressions to Python eval(). Attackers can publish a malicious bundle with crafted configuration c…
CWE: CWE-95
NVD
HIGH
CVE-2026-100570
OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and < 2026.8.1 allow an untrusted workspace .env file to set the CLOUDSDK_PYTHON_ARGS environment variable. When an operator starts OpenClaw in attacker-controlled workspace content and then runs the Gmail setup flow, that value is inherited wh…
CWE: CWE-88
NVD
HIGH
CVE-2026-98122
In the Linux kernel, the following vulnerability has been resolved:
vxlan: mdb: Fix use-after-free in vxlan_mdb_remote_src_del()
vxlan_mdb_is_valid_source(), which validates MDBE_ATTR_SOURCE and every
MDBE_ATTR_SRC_LIST member, accepts the all-zeros address.
A source list is only accepted on a (*…
GitHub-GHSA
HIGH
Trestle SSTI in Jinja2 include tags allows arbitrary code execution (Incomplete fix of CVE-2026-46439)
GHSA-mr95-65j8-9mxp
pkg: compliance-trestle, compliance-trestle
eco: pip
published: Sep 24, 2026
Reporter: Cavan Loughran, Celvex Group Inc.
Summary
——-
The fix for CVE-2026-46439 (3.12.2 / 4.0.3) removed the recursive re-render loop in trestle/core/commands/author/jinja.py render_template, but the custom include tags in trestle/core/jinja/tags.py (MDSectionInclude, MDCleanInclude) still r…
CVE-2026-57170
NVD
HIGH
CVE-2026-89325
An uncontrolled search path element in InsightVM assessment content in Rapid7 Insight Agent on Windows allows a local, low-privileged user to execute arbitrary code as SYSTEM via a planted executable resolved from the machine PATH.
Assessment content at or below version 0.0.261.0 included a check t…
CWE: CWE-427
GitHub-GHSA
HIGH
Language Servers for AWS vulnerable to arbitrary file write
GHSA-6v3r-4p5c-mrp5
pkg: @aws/lsp-codewhisperer
eco: npm
published: Sep 24, 2026
## Summary
Language Servers for AWS (the aws/language-servers project) provides the Language Server Protocol implementations that power AWS developer tooling, including the Amazon Q Developer agentic chat experience, across IDEs such as VS Code, JetBrains, Visual Studio, and Eclipse.
Missing symlin…
CVE-2026-12958
NVD
HIGH
CVE-2026-93798
In the Linux kernel, the following vulnerability has been resolved:
btrfs: fix reloc root cleanup in merge_reloc_roots()
If the root we got has zero root refs in its root item, we are resetting
the root's ->reloc_root without using barriers like we do everywhere else.
Sashiko complained about this…
NVD
HIGH
CVE-2026-95831
Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfuscated URL.
The generate_certificate runs a Python script saved as a certificate file. The pyhton script attempts to retrieve code from a hardcoded http URL that is obfuscated wi…
CWE: CWE-506
NVD
HIGH
CVE-2026-77605
Notepad++ is a free and open-source source code editor. Prior to 8.9.8, the Folder as Workspace Run by system action in Notepad++ can resolve a different sibling file than the file selected by the user. When an attacker places a command script whose name is the selected text-file path with .cmd appe…
CWE: CWE-20, CWE-706
NVD
HIGH
CVE-2026-83598
Netdata is an open source observability tool. From rom 2.0.0 until 2.10.4, during Netdata Windows Agent MSI repair, powershell.exe runs as SYSTEM without -NoProfile and loads %USERPROFILE%\Documents\WindowsPowerShell\Microsoft.PowerShell_profile.ps1 from the low-privileged user who initiated repair.…
CWE: CWE-269, CWE-427
NVD
HIGH
CVE-2026-55567
BleachBit cleans files to free disk space and to maintain privacy. Prior to 6.0.1, privileged Windows cleaning does not lock and validate a target's parent directory before deletion. A local unprivileged user can replace that directory with a Windows junction and use a native symlink to redirect the…
CWE: CWE-367
NVD
HIGH
CVE-2026-100850
AzuraCast before 0.23.8 contains a server-side request forgery and local file read vulnerability in the AutoDJ remote playlist fetch (backend/src/Radio/AutoDJ/QueueBuilder.php, getMediaFromRemoteUrl()). A user with the station Media permission can create or update a playlist with source=remote_url a…
CWE: CWE-918
NVD
HIGH
CVE-2026-100704
Kyverno is a policy engine for Kubernetes. In versions 1.14.0 through 1.19.0, the ImageValidatingPolicy (policies.kyverno.io/v1beta1) evaluator never reads the spec.images and spec.allowedValues fields of a PolicyException. Any PolicyException whose policyRefs and matchConditions match a resource ca…
CWE: CWE-863
NVD
HIGH
CVE-2026-97448
In the Linux kernel, the following vulnerability has been resolved:
ACPICA: Add validation for node in acpi_ns_build_normalized_path()
Add validation for node in acpi_ns_build_normalized_path()
to prevent use-after-free vulnerabilities.
NVD
HIGH
CVE-2026-93265
In the Linux kernel, the following vulnerability has been resolved:
PCI/pwrctrl: tc9563: Fix parsing the integrated Ethernet MAC Endpoint node
DSP3 has an integrated Ethernet MAC Endpoint which has its own set of
config registers for configuring settings such as ASPM. The Endpoint device
has two p…
NVD
HIGH
CVE-2026-84499
A flaw was found in Red Hat Ansible Automation Platform's automation-
controller. Survey questions of type password are write-only and stored
encrypted, displayed only as a placeholder on read. When a schedule or
workflow job template node is revalidated against a tightened survey
specification, the…
CWE: CWE-209
GitHub-GHSA
HIGH
MCP Atlassian: Arbitrary file read/exfiltration via upload_attachment missing validate_safe_path()
GHSA-93xw-j965-9mx3
pkg: mcp-atlassian
eco: pip
published: Sep 22, 2026
## Summary
The `upload_attachment` method in `confluence/attachments.py` reads and uploads arbitrary local files to Confluence without calling `validate_safe_path()`. Both download methods (`download_attachment` at line 223, `download_content_attachments` at line 272) correctly call `validate_safe_…
CVE-2026-77258
GitHub-GHSA
HIGH
MCP Atlassian: Arbitrary file read via confluence_upload_attachment allows exfiltration of server credentials
GHSA-6cr4-ccf3-x7h4
pkg: mcp-atlassian
eco: pip
published: Sep 22, 2026
### Summary
Missing path validation in `confluence_upload_attachment` allows any authenticated MCP client to read arbitrary files from the server filesystem and exfiltrate their contents to Confluence. On Linux deployments, `/proc/self/environ` yields all runtime secrets in a single call.
—
### …
CVE-2026-77259
NVD
HIGH
CVE-2026-75608
Frigate is an open source network video recorder. Prior to 0.18.0, the prefix-matched location /api/go2rtc/api in docker/main/rootfs/usr/local/nginx/conf/nginx.conf requires authentication but does not require an administrator role for GET requests, exposing the proxied go2rtc API to viewer users. A…
CWE: CWE-863
NVD
HIGH
CVE-2026-63330
Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.6, api_get_recording_stream in warpgate-admin/src/api/recordings_detail.rs protects /@warpgate/admin/api/recordings/{uuid}/stream only with session authentication and omits require_admin_permission for AdminPermiss…
CWE: CWE-285, CWE-862
GitHub-GHSA
HIGH
OpenC3 COSMOS: Stored, cross-user XSS via Telemetry screen BUTTON widget
GHSA-gvf2-2rh5-mpgf
pkg: @openc3/vue-common
eco: npm
published: Sep 23, 2026
## Summary
A user who can save a telemetry **screen** (permission `system_set`) can embed JavaScript in a screen `BUTTON` widget. The `BUTTON` widget **`eval()`s the stored button text in the browser** when the button is activated, and screens are **shared content rendered to other users in the scop…
CVE-2026-77394
NVD
HIGH
CVE-2026-84706
A flaw was found in Ansible Automation Platform's automation-controller. The custom
Credential Type environment-variable injector validates variable names against a
deny-list (an ANSIBLE_* prefix check plus a fixed ENV_BLOCKLIST) that omits
process-hijacking loader variables such as BASH_ENV, ENV, L…
CWE: CWE-184
NVD
HIGH
CVE-2026-100847
AzuraCast before 0.23.8 contains a DQL injection vulnerability in the sortOrder API parameter of AbstractSearchableListAction.php. Attackers can inject arbitrary DQL expressions through the sortOrder parameter to extract sensitive database information including user credentials and station settings.
CWE: CWE-89
NVD
HIGH
CVE-2026-100669
Grav before 2.0.25 ships web server configuration samples whose access-control deny rules are matched case-sensitively. In webserver-configs/web.config (IIS), every deny rule (user_sensitive_folders, user_accounts, user_data, user_error_redirect, user_pages, system, vendor, ignore_folders) sets igno…
CWE: CWE-178
NVD
HIGH
CVE-2026-100665
Netty versions from 4.2.11.Final before 4.2.18.Final contain an incomplete hostname verification fix in the QUIC certificate verification path when using a plain X509TrustManager. The BoringSSLCertificateVerifyCallback discards the SSLEngine for plain trust managers, preventing endpoint identificati…
CWE: CWE-295
GitHub-GHSA
HIGH
SCBE-AETHERMOORE Unauthenticated AetherBrowser Ops API Exposes Operator Email Digests
GHSA-q986-4x7x-gx39
pkg: scbe-aethermoore
eco: pip
published: Sep 25, 2026
### Summary
The AetherBrowser API server (`scripts/aetherbrowser/api_server.py`) exposes the `POST /api/ops/check-email` endpoint without any authentication. Any remote attacker can call this endpoint and trigger execution of the `email_reader.py` subprocess, which connects to configured ProtonMail…
CVE-2026-57443
GitHub-GHSA
HIGH
@rsdoctor/rspack-plugin has Unauthenticated HTTP API that Exposes Project Source Code and Build Metadata
GHSA-jmg2-rcxh-w8q3
pkg: @rsdoctor/rspack-plugin
eco: npm
published: Sep 24, 2026
### Summary
The default Rsdoctor report HTTP server started by `@rsdoctor/rspack-plugin` binds to all network interfaces (`0.0.0.0`) and serves a `POST /api/data/key` endpoint with no authentication and wildcard CORS (`Access-Control-Allow-Origin: *`). Any network-adjacent or remote attacker can se…
CVE-2026-61782
GitHub-GHSA
HIGH
Podman: Malformed Image can trick podman run into leaking host environment variables into the container
GHSA-4hq8-gpf5-8p68
pkg: github.com/containers/podman/v5, go.podman.io/podman/v6, github.com/containers/podman/v4
eco: go
published: Sep 24, 2026
## Summary
An container image that contains a environment variable with just a key and no value can trick podman into passing that variable from the host into the container. This is made worse by the fact that using an asterisk (*) will cause podman to pass all host variables into the container. So…
CVE-2026-57231
GitHub-GHSA
HIGH
langchain-nvidia-ai-endpoints has local file disclosure through VLM image inputs
GHSA-g28h-2cmm-rj9x
pkg: langchain-nvidia-ai-endpoints
eco: pip
published: Sep 24, 2026
## Summary
`langchain-nvidia-ai-endpoints` versions before 1.4.2 accepted local filesystem paths as image inputs for Vision Language Model (VLM) requests. If an application passed attacker-controlled image input to `ChatNVIDIA` or VLM reranking APIs, an attacker could cause files readable by the ap…
NVD
HIGH
CVE-2026-97057
redis-parser through 3.0.0 fails to validate the multi-bulk length value in RESP protocol parsing, allowing attackers to trigger an uncaught RangeError by supplying an excessively large declared length. A malicious or compromised Redis endpoint can deliver a crafted RESP header with a length above 2…
CWE: CWE-1284
GitHub-GHSA
HIGH
elysia has Inefficient Algorithmic Complexity and Interpretation Conflict
GHSA-9643-4qgh-g8mx
pkg: elysia
eco: npm
published: Sep 23, 2026
Elysia v1.4.28 is vulnerable to denial-of-service attacks due to CPU exhaustion in the form data normalization code.
Elysia uses `getAll` to retrieve value from FormData. It is called directly relative to the total number of key-value pairs in the form data. The total amount of work the for loop ha…
CVE-2026-56669
GitHub-GHSA
HIGH
ReactPress has SQL injection via dynamic column names in TypeORM query builders
GHSA-wmw4-mw6x-6vfm
pkg: @fecommunity/reactpress
eco: npm
published: Sep 23, 2026
## Summary
ReactPress API list endpoints build TypeORM `QueryBuilder` conditions using
unsanitized HTTP query parameter *names* as SQL column identifiers
(e.g. “ `article.${key}` “). TypeORM parameterizes values but not column
names, allowing unauthenticated attackers to inject SQL through crafte…
CVE-2026-61685
GitHub-GHSA
HIGH
Jawn: Quadratic parsing effort in AsyncParser
GHSA-w4cm-gvhj-cgw6
pkg: org.typelevel:jawn-parser_2.12, org.typelevel:jawn-parser_2.13, org.typelevel:jawn-parser_3
eco: maven
published: Sep 23, 2026
`AsyncParser` can be forced to perform O(n^2) work on the length of the input. When a single JSON token arrives across many small chunks, each `absorb` call rescans the incomplete token from the start.
### Impact
Denial of service via CPU exhaustion when parsing untrusted JSON.
Preconditions:
– …
CVE-2026-61814
GitHub-GHSA
HIGH
Jawn: Uncontrolled nesting depth in JSON parser
GHSA-cc4v-rvgp-2pf3
pkg: org.typelevel:jawn-parser_2.12, org.typelevel:jawn-parser_2.13, org.typelevel:jawn-parser_3
eco: maven
published: Sep 23, 2026
The Jawn parser before 1.6.1 is vulnerable to a denial of service attack via untrusted input.
### Impact
A remote attacker who can submit JSON to any jawn-backed parse method can exhaust JVM heap and trigger `java.lang.OutOfMemoryError`. This is treated by Scala as a fatal error and not typically…
CVE-2026-59990
NVD
HIGH
CVE-2026-86065
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /subscribe endpoint in network/api/websocket/routes.go accepts unauthenticated WebSocket clients with permissive origin handling, does not call SetReadLimit to bound message size, and has no l…
CWE: CWE-770
NVD
HIGH
CVE-2026-77423
JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in less viewer passes user-controlled search and display-filter patterns from getPattern(boolean doDisplayPattern) in builtins/src/main/java/org/jline/builtins/Less.java directly to Java's backtra…
CWE: CWE-1333
NVD
HIGH
CVE-2026-77422
JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in grep command in builtins/src/main/java/org/jline/builtins/PosixCommands.java accepts a user-controlled regular expression in grep(…) and, unless line-regexp mode is used, automatically adds a…
CWE: CWE-1333
GitHub-GHSA
HIGH
Klever-Go: Unauthenticated WebSocket /subscribe: no read-size limit, no connection cap, permissive origin -> remote node memory/goroutine exhaustion (DoS)
GHSA-4fwh-wrm6-97xm
pkg: github.com/klever-io/klever-go
eco: go
published: Sep 23, 2026
## Summary
The unauthenticated WebSocket endpoint `GET /subscribe` is registered `open: true` by default
(`config/node/api.yaml`) and lets a remote, unauthenticated client exhaust the node's memory and
goroutines. Because the REST API runs IN-PROCESS with the node — `network/api/api.go` `Start(……
CVE-2026-86065
GitHub-GHSA
HIGH
JLine: ReDoS in Built-in grep Command Amplified by Automatic `.*` Wrapping
GHSA-r2xf-8xr9-62gw
pkg: org.jline:jline-builtins, org.jline:jline-builtins
eco: maven
published: Sep 23, 2026
### Summary
The JLine3 built-in `grep` command wraps the user-supplied regular expression with
`.*` before compiling it with Java's backtracking regex engine. This amplifies
catastrophic backtracking and allows a short pattern such as `(a+)+b` to hang the
command thread on non-matching input. In en…
CVE-2026-77422
NVD
HIGH
CVE-2026-88830
A unit confusion in BusyBox TLS Montgomery reduction buffer allocation causes a pre-authentication heap buffer overflow when processing a crafted ClientKeyExchange message.
CWE: CWE-131
NVD
HIGH
CVE-2026-96673
Photoview through 2.4.0 contains an SQL injection vulnerability in the album download route that allows unauthenticated attackers to inject SQL by manipulating the album_id path segment. Attackers can supply crafted SQL expressions in the album_id parameter to extract arbitrary data from the databas…
CWE: CWE-89
NVD
HIGH
CVE-2026-86243
Buffer over-read vulnerability in Apache Tomcat Native during the TLS handshake permits a malicious user to trigger a DoS via a JVM crash.
This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Earlier, unsupported versions may also be affected.
Users are…
CWE: CWE-126
NVD
HIGH
CVE-2026-31377
An Improper Authentication vulnerability in the Apache Doris Frontend (FE) meta service allows an unauthenticated remote attacker to access internal metadata service endpoints.
The affected endpoints relied on client-supplied node information for authentication without providing sufficient authen…
CWE: CWE-287
NVD
HIGH
CVE-2026-61685
ReactPress is a publishing system for React developers. Prior to version 3.7.0, ReactPress API list endpoints build TypeORM `QueryBuilder` conditions using unsanitized HTTP query parameter names as SQL column identifiers (e.g. “ `article.${key}` “). TypeORM parameterizes values but not column name…
CWE: CWE-89
GitHub-GHSA
HIGH
SIPGO: DoS via unvalidated WebSocket frame length
GHSA-8h6x-h86x-75wh
pkg: github.com/emiago/sipgo
eco: go
published: Sep 22, 2026
### Summary
The WebSocket transport allocates a buffer from the frame payload length before validating its size, which can lead to an unauthenticated DoS.
### Details
`WSConnection.Read` allocates a buffer from the declared WebSocket frame length before reading the payload (https://github.com/emi…
CVE-2026-77322
GitHub-GHSA
HIGH
MPXJ: XXE Vulnerability in MerlinReader
GHSA-5vvx-3h34-f3gj
pkg: net.sf.mpxj:mpxj, mpxj, MPXJ.Net
eco: pip
published: Sep 22, 2026
### Impact
MPXJ used the default configuration when creating a DocumentBuilder instance, which leaves doctype declarations enabled, when parsing the XML content of the ZTIMEINTERVALS column from a Merlin project SQLite file. This would allow a carefully crafted XML payload to read an arbitrary file.…
CVE-2026-61570
NVD
HIGH
CVE-2026-77322
SIPGO is a library for writing SIP services in the GO language. Prior to 1.4.3, WSConnection.Read in sip/transport_ws.go creates a wsutil.Reader without setting MaxFrameSize, allowing NextFrame to accept a client-controlled header.Length before ParseMaxMessageLength is applied. An unauthenticated WS…
CWE: CWE-789
NVD
HIGH
CVE-2026-62985
request-filtering-agent is an http(s).Agent implementation that blocks requests to Private/Reserved IP addresses. Prior to 3.2.1, RequestFilteringHttpAgent and RequestFilteringHttpsAgent synchronously threw from createConnection when rejecting a literal private-IP host such as 169.254.169.254 or 127…
CWE: CWE-248
NVD
HIGH
CVE-2026-59991
psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to 1.17.4, PSDImage.composite() and PSDImage.numpy() allocated output buffers from attacker-controlled PSD header geometry, including width, height, channels, depth, and per-layer rectangles, before validating those valu…
CWE: CWE-789
NVD
HIGH
CVE-2026-58268
SIPGO is a library for writing SIP services in the GO language. Prior to 1.4.1, ParserStream.parseSingle in sip/parser_stream.go allocates a SIP body buffer from the client-controlled Content-Length header before ParseMaxMessageLength is enforced. An unauthenticated peer can send a stream-transport …
CWE: CWE-789
GitHub-GHSA
HIGH
SIPGO: DoS via unvalidated Content-Length in the stream parser
GHSA-pg59-5vwg-4jxq
pkg: github.com/emiago/sipgo
eco: go
published: Sep 22, 2026
### Summary
The stream parser allocates the SIP body buffer from the `Content-Length` header before validating its size, which can lead to an unauthenticated DoS.
### Details
`ParserStream.parseSingle` allocates the body buffer from the declared `Content-Length` with no size check (https://github…
CVE-2026-58268
GitHub-GHSA
HIGH
request-filtering-agent: Synchronous throw from createConnection() for literal private-IP hosts bypasses req.on('error'), crashing the Node.js process
GHSA-r3r9-wp5j-pq5g
pkg: request-filtering-agent
eco: npm
published: Sep 22, 2026
### Summary
`RequestFilteringHttpAgent` / `RequestFilteringHttpsAgent` block requests to private IPs, but the blocking happens via a **synchronous `throw`** inside `createConnection()` for literal private-IP hostnames (e.g. `169.254.169.254`, `127.0.0.1`). Node.js's `http.request` / `http.get` expec…
CVE-2026-62985
GitHub-GHSA
HIGH
psd-tools composite/numpy has uncontrolled memory allocation via crafted PSD geometry
GHSA-8q6g-vjhf-jp8m
pkg: psd-tools
eco: pip
published: Sep 22, 2026
### Summary
`PSDImage.composite()` (and `.numpy()`) allocate the output image buffer from the PSD's header geometry (width × height × channels × depth, and per-layer rectangles) before validating those values against the actual file contents. A tiny crafted PSD declaring huge dimensions causes a …
CVE-2026-59991
NVD
HIGH
CVE-2026-95653
Concrete CMS Community Store before 2.7.8 derives digital product download tokens from order creation timestamps instead of random values, making tokens predictable. Unauthenticated attackers can enumerate sequential order and file identifiers to calculate valid download tokens and retrieve digital …
CWE: CWE-340
NVD
HIGH
CVE-2026-89407
NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates "stringified numbers" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9]*[\.]?[0-9]+([eE][+-]?[0-9]+)?), present since 2.17.0, and PATTERN_FLOAT_TRAILING_DOT, added in 2.17.2. PATTERN_FLOAT places adjacent quantifiers ov…
CWE: CWE-400, CWE-1333
NVD
HIGH
CVE-2026-65118
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service.
CWE: CWE-295
NVD
HIGH
CVE-2026-87081
Net::IDN::UTS46 versions before 2.590 for Perl allow CPU exhaustion via quadratic punycode encoding of an overlong label before the length check in to_ascii.
to_ascii punycode encodes each label and only then applies the 63-byte DNS limit. encode_punycode in both backends follows the sample impleme…
CWE: CWE-407
GitHub-GHSA
HIGH
nginx ignition has ParseAcceptLanguage `_` separator bypass that enables ~75x CPU amplification via Accept-Language header in i18nMiddleware
GHSA-jr34-h97m-9hpx
pkg: github.com/lucasdillmann/nginx-ignition
eco: go
published: Sep 21, 2026
### Summary
The gin i18n middleware in nginx-ignition's API server runs in front of every HTTP request and calls `golang.org/x/text/language.ParseAcceptLanguage` on the raw `Accept-Language` header without imposing any size or shape filter. The underlying parser has quadratic-time behaviour on long…
CVE-2026-61629
NVD
HIGH
CVE-2026-88407
An out-of-bounds read in the node_token_count/relation_token_count component of FalkorDB (Redis module) v4.20.1 to v4.20.4 allows attackers to cause a Denial of Service (DoS) via a crafted input.
CWE: CWE-787
NVD
HIGH
CVE-2026-61629
nginx ignition is a user interface for the nginx web server. In versions 2.29.0 through 2.40.0, the gin i18n middleware in nginx-ignition's API server runs in front of every HTTP request and calls `golang.org/x/text/language.ParseAcceptLanguage` on the raw `Accept-Language` header without imposing a…
CWE: CWE-770
NVD
HIGH
CVE-2026-100835
Contrast before 1.16.0 is susceptible to remote attestation relay attacks. Contrast accepted any TEE attestation report that verified correctly and contained the expected firmware patch levels and software measurements, regardless of which machine produced it, so attestation was not bound to specifi…
CWE: CWE-295
GitHub-GHSA
HIGH
social-auth-core: VK App backend accepts unsigned callback data when auth_key is missing
GHSA-3c93-f73f-qc9h
pkg: social-auth-core
eco: pip
published: Sep 24, 2026
### Impact
The `vk-app` backend accepted VK application callback data without verifying the callback signature when the `auth_key` parameter was omitted.
Applications using this backend could treat unsigned attacker-controlled data as a verified VK identity. An attacker could choose callback field…
CVE-2026-57178
GitHub-GHSA
HIGH
@bytebase/dbhub's read-only mode does not prevent database writes
GHSA-mwwr-p57h-56pf
pkg: @bytebase/dbhub
eco: npm
published: Sep 24, 2026
### Summary
Setting `readonly = true` on the `execute_sql` tool does not make the connection read-only. The connectors are written to set PostgreSQL `default_transaction_read_only=on` (and open SQLite in `readOnly` mode), but that code is gated on a config value that is never populated, so it neve…
CVE-2026-61788
NVD
HIGH
CVE-2026-57178
Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the `vk-app` backend accepted VK application callback data without verifying the callback signature when the `auth_key` parameter was omitted. Applications using this backend could treat unsigned attacker-c…
CWE: CWE-287, CWE-347
NVD
HIGH
CVE-2026-93225
In the Linux kernel, the following vulnerability has been resolved:
phy: fsl-imx8mq-usb: fix typec switch leak on probe error path
If probe fails after imx95_usb_phy_get_tca() succeeds, the typec
switch leaks because the only cleanup path was in .remove(), which
never runs on probe failure.
Use d…
GitHub-GHSA
HIGH
9router: Image prefetch DNS rebinding allows SSRF to internal services
GHSA-cmhj-wh2f-9cgx
pkg: 9router
eco: npm
published: Sep 23, 2026
## Summary
9router validates image URLs by resolving the host before fetching, but the later
server-side fetch performs a separate DNS resolution. An attacker-controlled DNS name can
resolve to a public IP during validation and then rebind to an internal Docker/private IP
during the fetch. This all…
CVE-2026-56676
NVD
HIGH
CVE-2026-42801
NULL pointer dereference vulnerability in ASR Crane,Falcon on Linux (as_rrc module) allows Pointer Manipulation.
This vulnerability is associated with program file 3g.mod/lib/src/urrsir.c.
CWE: CWE-476
GitHub-GHSA
HIGH
MCP Atlassian: MCP HTTP Client Server-Local File Exfiltration via Unvalidated Attachment Upload Path
GHSA-wv8v-v4c5-v75j
pkg: mcp-atlassian
eco: pip
published: Sep 22, 2026
### Summary
The `mcp-atlassian` server exposes an MCP tool (`confluence_upload_attachment` and the Jira attachment variant) that accepts an arbitrary server-side file path and opens it for upload without any path validation. When the server is deployed in HTTP transport mode (`streamable-http` or `…
CVE-2026-77246
NVD
HIGH
CVE-2026-75939
A flaw was found in openshift/oc-mirror. The tool incorrectly verifies PGP (Pretty Good Privacy) release image signatures by checking for signature errors before the entire signed body is processed, leading to a bypass of the signature verification. A remote attacker, by intercepting or manipulating…
CWE: CWE-347
NVD
HIGH
CVE-2026-100901
A vulnerability was found in athlon1600 youtube-downloader up to 4.0.1. Affected by this vulnerability is the function stream of the file public/stream.php. The manipulation of the argument url results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been…
CWE: CWE-918
NVD
HIGH
CVE-2025-71425
Contrast (Edgeless Systems) before 1.8.1 logs the workload secret to stderr, and thus to Kubernetes logs, when the Contrast initializer is configured with CONTRAST_LOG_LEVEL set to info or debug. Because info is the default, all installations that do not customize the initializer log level are affec…
CWE: CWE-532
NVD
HIGH
CVE-2025-71423
Edgelesssys Contrast is a confidential-computing runtime for Kubernetes. In versions 1.9.0 before 1.12.2, the initializer logs the full NewMeshCert response — which contains the workload secret — to standard output at INFO level. As a result, workload secrets are exposed to any Kubernetes user w…
CWE: CWE-532
NVD
HIGH
CVE-2026-97877
A vulnerability was determined in zhistaredu StarTraining up to 3.8.1. This issue affects the function UserLoginService.createToken of the file application.yml of the component JWT Token Handler. This manipulation of the argument user_id/company_id causes use of hard-coded password. The attack is po…
CWE: CWE-255, CWE-259
NVD
HIGH
CVE-2026-93901
The Optima Express IDX plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 8.7.5. This is due to the `provisionBlogCredentials()` function in `iHomefinderAdmin.php` being reachable via the `wp_ajax_nopriv_ihf_clear_cache` AJAX action — through the call …
CWE: CWE-269
NVD
HIGH
CVE-2026-86938
A DLL hijacking vulnerability in the FileMaker Pro installer for Windows allowed a local user to execute arbitrary code with elevated administrator privileges by placing a malicious DLL file in the installer directory. This vulnerability is addressed in FileMaker Pro version 26.0.3.
CWE: CWE-639
GitHub-GHSA
HIGH
9Router has an Authentication Bypass in Public LLM API via Spoofable X-9r-Real-Ip Header
GHSA-5mj8-gf6m-fhw8
pkg: 9router
eco: npm
published: Sep 22, 2026
## Summary
9router determines whether an incoming request originates from localhost by trusting the X-9r-Real-Ip HTTP request header. This header is intended to be produced and sanitized exclusively by the bundled custom-server.js layer from the TCP socket address. In deployment modes where request…
CVE-2026-56681
NVD
HIGH
CVE-2026-42324
Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/element_set_ranks.php stores administrator-controlled image_order[] values without enforcing the existing sort-field whitelist. The stored album image_order expression is later concatenated into ORDER…
CWE: CWE-89
NVD
HIGH
CVE-2026-42323
Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/batch_manager.php accepts administrator-controlled dimension width, height, and ratio values and filesize values from the Batch Manager filter URL without numeric validation. The URL filter parser sto…
CWE: CWE-89
NVD
HIGH
CVE-2026-101059
utcp-http before 1.1.4 fails to validate the OAuth2 tokenUrl field from remote OpenAPI specifications, allowing attackers to redirect credential submission to arbitrary endpoints. When a victim registers an attacker-controlled OpenAPI spec and invokes a generated OAuth2-protected tool, the library P…
CWE: CWE-918
NVD
HIGH
CVE-2025-71426
Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.4.1, a recovering Coordinator does not verify the seed supplied by the recovering party. An attacker can therefore stand up a rogue Coordinator whose manifest passes validation but whose secret seed is attacker-control…
CWE: CWE-285
NVD
HIGH
CVE-2026-100708
Froxlor before 2.3.13 returns the ssl_key_file column — which stores the raw PEM TLS private-key content — verbatim in the JSON responses of the Certificates.get and Certificates.listing API commands, because the results of the underlying domain_ssl_settings queries are passed through ApiCommand…
CWE: CWE-200
NVD
HIGH
CVE-2026-100598
OpenClaw (npm package openclaw) before 2026.7.1 incorrectly binds Signal approval reactions. In affected versions, a reaction intended to resolve a structured approval request could instead attach to ordinary outbound text when unrelated outbound messages and a pending approval are present in the sa…
CWE: CWE-346
NVD
HIGH
CVE-2026-97520
In the Linux kernel, the following vulnerability has been resolved:
gfs2: move quota_init qc iterator increment
Move qc++ from the loop body into the for-loop increment
expression in gfs2_quota_init().
This keeps iterator progression explicit and avoids mixing pointer
advance with duplicate-slot …
NVD
HIGH
CVE-2026-96744
Improper neutralization of special elements in data query logic in the cache lock implementation of the MongoDB integration for Laravel can cause a caller-supplied lock owner value to be evaluated as an aggregation expression rather than as a literal value. An authenticated user who can influence th…
CWE: CWE-943
NVD
HIGH
CVE-2026-84714
A flaw was found in the automation-controller input-validation
guard sanitize_jinja(). The function uses two regular
expressions to reject user-supplied Jinja, but the patterns
stop at the first interior '}' or '%' character, so a Jinja
…
CWE: CWE-184
GitHub-GHSA
HIGH
Cloudreve: Storage-quota TOCTOU race allows quota bypass and storage-based denial of service
GHSA-xj3h-wwxq-gfcj
pkg: github.com/cloudreve/Cloudreve/v4
eco: go
published: Sep 22, 2026
## Summary
Cloudreve v4 splits the storage-quota **check** (reading the user's `used` bytes and comparing them to `MaxStorage`) and the **charge** (incrementing `users.storage`) into two non-atomic steps in the `PrepareUpload` code path. This creates a Time-of-Check to Time-of-Use (TOCTOU) race con…
CVE-2026-77633
GitHub-GHSA
HIGH
Spree: Broken Access Control in `PATCH /api/v3/store/carts/:id/associate` (IDOR)
GHSA-4825-p4xm-pcf2
pkg: spree_api, spree_api
eco: rubygems
published: Sep 22, 2026
## Summary
The Store API v3 endpoint `PATCH /api/v3/store/carts/:id/associate` binds a guest cart to the authenticated caller without verifying possession of that cart. It locates the cart by prefixed ID only — `current_store.carts.where(user: [nil, current_user]).find_by_prefix_id!(params[:id])`…
CVE-2026-94462
GitHub-GHSA
HIGH
lightrag-hku: SSRF via IPv6-transition address bypass (NAT64, IPv4-compatible, 6to4) of the native-markdown image-download guard
GHSA-vv3m-f8x4-7377
pkg: lightrag-hku
eco: pip
published: Sep 22, 2026
## Summary
LightRAG's native markdown parser downloads external images referenced by an uploaded markdown or textpack document. The only SSRF guard, `_validated_addresses()` in `lightrag/parser/markdown/parser.py`, resolves the image host and rejects it when the resolved IP is not `is_global`. That…
CVE-2026-85740
GitHub-GHSA
HIGH
MCP Atlassian: SSRF redirect protection missing for basic-auth and OAuth authentication branches
GHSA-6529-c226-h328
pkg: mcp-atlassian
eco: pip
published: Sep 22, 2026
### Summary
`_make_ssrf_safe_hook()` blocks HTTP redirects to private/internal IPs by validating the `Location` header before the client follows a `3xx` response. The problem is that this hook is only attached in one of three authentication branches — the header-PAT path. Basic auth and OAuth bra…
CVE-2026-77261
GitHub-GHSA
HIGH
MCP Atlassian: Jira and Confluence attachment upload tools can read arbitrary server-local files
GHSA-vc25-24vv-fxxm
pkg: mcp-atlassian
eco: pip
published: Sep 22, 2026
### Summary
MCP Atlassian exposes Jira and Confluence attachment upload tools that accept arbitrary local filesystem paths and upload those file contents to Atlassian. In HTTP or multi-user deployments, an MCP caller who can invoke write tools can cause the server to read any file accessible to the…
CVE-2026-77253
NVD
HIGH
CVE-2026-77261
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, _make_ssrf_safe_hook is omitted from JiraFetcher and ConfluenceFetcher sessions created through the basic-auth and oauth_pat branches. If an attacker-controlled or compromised config…
CWE: CWE-918
NVD
HIGH
CVE-2026-49450
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Desktop for Windows omits publisherName from packages/app-desktop/package.json, so the generated app-update.yml causes NsisUpdater.verifySignature() to skip comparison of …
CWE: CWE-345, CWE-353, CWE-494
NVD
HIGH
CVE-2026-61687
Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, ValidateOAuthState clears the oauth_state_ session value to an empty string after a successful OAuth callback and later accepts an empty state parameter as equal, allowing an unauthe…
CWE: CWE-287, CWE-352, CWE-384, CWE-1275
GitHub-GHSA
HIGH
Hatchet – Unauthenticated OAuth state CSRF / login-CSRF via empty-state collision in ValidateOAuthState
GHSA-phg3-3g28-wq9v
pkg: hatchet
eco: go
published: Sep 21, 2026
### Summary
Hatchet version v0.86.26 and below is vulnerable to OAuth state CSRF (login CSRF / account fixation).
The vulnerable code clears the session `oauth_state_<integration>` value to the empty string `""` after a successful OAuth callback rather than removing the key, and the subsequent st…
CVE-2026-61687
NVD
HIGH
CVE-2026-100842
MONAI through 1.6.0 contains an eval injection vulnerability in _get_fake_spatial_shape() in monai/bundle/scripts.py. The function validates shape expressions with a helper that walks the AST and only collects ast.Name nodes, rejecting any name other than 'p' or 'n', before passing the string to eva…
CWE: CWE-95
NVD
HIGH
CVE-2026-83597
Netdata is an open source observability tool. From version 2.0.0 until 2.10.4, Netdata Windows Agent MSI repair launches powershell.exe and wevtutil.exe as elevated interactive processes in the initiating user's desktop session. A low-privileged local user who triggers repair can interact with or hi…
CWE: CWE-269
GitHub-GHSA
HIGH
khoj has an unauthenticated path traversal in /home/ endpoint that allows file read from server filesystem
GHSA-62mm-xwmv-crhg
pkg: khoj
eco: pip
published: Sep 25, 2026
### Summary
The `/home/{file_path:path}` endpoint in `web_client.py` serves static files by directly concatenating the user-supplied `file_path` with the `home_directory` constant. There is no path traversal filtering, no path normalization check, and no authentication required. An attacker can use …
GitHub-GHSA
HIGH
OpenZeppelin Confidential Contracts `VestingWalletConfidential`: a malicious ERC-7984 token is able to extract private data from the vesting wallet
GHSA-29h2-jr22-frmh
pkg: @openzeppelin/confidential-contracts, @openzeppelin/confidential-contracts, @openzeppelin/confidential-contracts
eco: npm
published: Sep 25, 2026
### Impact
Two locations consume an encrypted handle returned by an untrusted external party and use it without verifying that the party is ACL-authorized on it.
#### `VestingWalletConfidential`
Malicious users can call `release` with a malicious token. This token could return an alternative hand…
GitHub-GHSA
HIGH
`@bsv/wallet-toolbox` / `-client` / `-mobile` don't verify storage-supplied recipient output scripts against caller-requested outputs in createAction
GHSA-36f9-7rg5-cpf8
pkg: @bsv/wallet-toolbox, @bsv/wallet-toolbox-client, @bsv/wallet-toolbox-mobile
eco: npm
published: Sep 24, 2026
Reported by @echennells (Eric Chennells). Migrated from public issue #191 to a private advisory.
**Affected:** `@bsv/wallet-toolbox` / `-client` / `-mobile`. Verified in `2.1.21` and `2.1.21-parity-fix.2`; the relevant code is the same at current HEAD
**Summary:**
When `createAction` runs against …
CVE-2026-56744
GitHub-GHSA
HIGH
Language Servers for AWS Vulnerable to Arbitrary Code Execution
GHSA-xhcr-j4j9-3gh7
pkg: @aws/lsp-codewhisperer
eco: npm
published: Sep 24, 2026
### Summary
Language Servers for AWS (the aws/language-servers project) provide the underlying language-server runtime that powers Amazon Q Developer's AI coding assistance across its IDE plugins (Visual Studio Code, JetBrains, Eclipse, and
Visual Studio).
Improper trust boundary enforcement in Lan…
CVE-2026-12957
GitHub-GHSA
HIGH
Klever-Go: Validator registration accepts an unvalidated BLS public key → consensus liveness DoS
GHSA-9wh6-9hq7-9688
pkg: github.com/klever-io/klever-go
eco: go
published: Sep 23, 2026
**Location:** `core/kapp/validators/validators.go:201` (`Register`), (`genesis/checking/nodesSetupChecker.go:73`). `core/consensus/slot/bls/subslotStartSlot.go:165` `core/consensus/…/headerSignatureVerify.go:123` (`Create(…)`).
### Description
Klever uses a BDN (Boneh-Drijvers-Neven) BLS multi…
CVE-2026-82407
GitHub-GHSA
HIGH
Klever-Go: Elasticsearch bulk / painless injection via on-chain account name -> explorer/indexer data forgery
GHSA-7c7c-373r-gfjj
pkg: github.com/klever-io/klever-go
eco: go
published: Sep 23, 2026
**Component:** Elasticsearch indexer (`indexer/`)
**Primary location:** `indexer/common.go:2395-2407` (`serializedDataForUpdateAccounts`)
**Entry point:** `SetAccountName` native transaction (contract type 12) — `core/process/transaction/txProcess.go:688`
—
## Description
When the node indexe…
CVE-2026-82409
GitHub-GHSA
HIGH
Klever-Go: Zombie-order theft: `Buy` missing `IsClaimed` guard in native marketplace
GHSA-26r5-4mm2-px5c
pkg: github.com/klever-io/klever-go
eco: go
published: Sep 23, 2026
**Location:** `core/kapp/market/market.go` — `Buy()` (approx. L281–436)\
**Severity:** High
The native marketplace enforces an `IsClaimed` guard in `Claim` (`market.go:752`), `CancelOrder` (`market.go:1125`), and `orderEscrowAmount` (`market.go:251`), but **not in `Buy`**.
Marketplace escrow i…
CVE-2026-82406
GitHub-GHSA
HIGH
Klever-Go Account takeover: `kleverUpdateAccountPermission` authorizes on attacker-controlled `RecipientAddr` instead of the authenticated caller
GHSA-97cv-x867-6xhm
pkg: github.com/klever-io/klever-go
eco: go
published: Sep 23, 2026
### Description
The VM built-in function `KleverUpdateAccountPermission` (registered always-active, `creator.go:381-390` / `core/vmconstants.go:234`) rewrites an account's entire permission set. Its authorization check uses `vmInput.RecipientAddr` **attacker-controlled** instead of the authenticat…
CVE-2026-82405
GitHub-GHSA
HIGH
9router: Mass assignment in PATCH /api/settings allows authenticated authorization downgrade
GHSA-vmjq-hvgq-2wv4
pkg: 9router
eco: npm
published: Sep 23, 2026
### Summary
The `PATCH /api/settings` endpoint writes the entire request body to persistent settings without a field whitelist. An authenticated user can set security-critical fields that are not meant to be modifiable here — notably `requireLogin`. Setting `requireLogin: false` disables authentic…
CVE-2026-56679
GitHub-GHSA
HIGH
Zapros: Streaming decoders ignored the requested chunk size, allowing a single compressed response chunk to allocate unbounded memory (decompression bomb)
GHSA-6cp7-3m3c-5x5c
pkg: zapros
eco: pip
published: Sep 23, 2026
### Impact
Denial of service via memory exhaustion. Affects all callers who streamed compressed responses relying on the chunk size — explicit (`iter_bytes(chunk_size=…)`) or the default — to bound memory. The decoder ignored that bound, so a chunk could be far larger than requested and a sin…
CVE-2026-61652
GitHub-GHSA
HIGH
OpenBao's Templated Policies Allow Privilege Escalation via Wildcard Characters
GHSA-59w7-v8rr-pr4p
pkg: github.com/openbao/openbao, github.com/openbao/openbao
eco: go
published: Sep 22, 2026
## Impact
### ACL Policies
OpenBao supports "templated polices": Policies with placeholders that are replaced at evaluation time.
This allows you to write a single policy which e.g. grants user "alice" access to all entries in a key value engine prefixed with `alice/` while granting "bob" access …
CVE-2026-71543
GitHub-GHSA
HIGH
Unleash: Missing await on permission check + cross-project IDOR in admin API
GHSA-72h8-wp98-7hch
pkg: unleash-server
eco: npm
published: Sep 22, 2026
## Summary
Multiple authorization vulnerabilities in Unleash admin API, including a critical missing `await` that completely bypasses a permission check.
## Vulnerability 1: Missing `await` on Permission Check (HIGH)
**File:** `src/lib/features/segment/segment-controller.ts` (line 345)
`POST /ap…
CVE-2026-77426
GitHub-GHSA
HIGH
MCP Atlassian: Arbitrary server-local file upload to Jira/Confluence attachments via unrestricted file_path parameters
GHSA-f6pj-qv47-g96w
pkg: mcp-atlassian
eco: pip
published: Sep 22, 2026
## Summary
The Jira and Confluence attachment upload tools accept caller-controlled file path parameters and read those paths from the MCP server's local filesystem before uploading the file as an Atlassian attachment.
In local `stdio` deployments, this can expose files readable by the user's MCP …
CVE-2026-77247
GitHub-GHSA
HIGH
MCP Atlassian: SSRF Protection Bypass
GHSA-hgcf-4mq8-5266
pkg: mcp-atlassian
eco: pip
published: Sep 22, 2026
## Environment
– Project: `sooperset/mcp-atlassian`
– Affected function: `validate_url_for_ssrf()`
– Affected path: header-based Jira/Confluence URL authentication flow
– Tested endpoint: `POST /mcp`
– Tested version: `2.14.5`
## Description
The SSRF protection in `validate_url_for_ssrf()` can be…
CVE-2026-77274
GitHub-GHSA
HIGH
MCP Atlassian: Incomplete path traversal fix allows intra-CWD module overwrite and RCE (bypass of GHSA-xjgw-4wvw-rgm4)
GHSA-6vmq-24h2-pj7j
pkg: mcp-atlassian
eco: pip
published: Sep 22, 2026
### Summary
The path traversal fix introduced in v0.17.0 (GHSA-xjgw-4wvw-rgm4) is incomplete. `validate_safe_path()` is called without an explicit `base_dir`, defaulting to `os.getcwd()`. In standard container deployments the process CWD is the application directory (e.g. `/app`), so paths within t…
CVE-2026-77271
GitHub-GHSA
HIGH
mcp-atlassian has an incomplete SSRF remediation
GHSA-5wf4-jqxh-8gm3
pkg: mcp-atlassian
eco: pip
published: Sep 22, 2026
### Summary
The `UserTokenMiddleware` extracts URLs from `X-Atlassian-Jira-Url` and `X-Atlassian-Confluence-Url` HTTP headers and passes them directly to API client constructors without any SSRF validation.
### Affected Package
– **Ecosystem:** PyPI
– **Package:** mcp-atlassian
– **Affected versi…
CVE-2026-77267
GitHub-GHSA
HIGH
MCP Atlassian: Arbitrary local file READ via unconstrained file_path in upload_attachment (Confluence + Jira)
GHSA-f4p7-qx46-wc5j
pkg: mcp-atlassian
eco: pip
published: Sep 22, 2026
## Summary
This is an arbitrary local file READ vulnerability on the Confluence and Jira `upload_attachment` tool paths. It's the symmetric counterpart of the file-write vulnerability you patched as CVE-2026-27825. The write direction was fixed; the read direction was left open.
**Reporter:** Sean…
CVE-2026-77260
GitHub-GHSA
HIGH
MCP Atlassian: HTTP upload tools accept arbitrary server-local file paths
GHSA-mrq8-fv7v-hhjg
pkg: mcp-atlassian
eco: pip
published: Sep 22, 2026
# sooperset/mcp-atlassian: HTTP upload tools can attach arbitrary server-local files
Date: 2026-05-05
Target: `sooperset/mcp-atlassian`
Commit: `d8bc78698a63cb6b321c7ca796d6329d448f7f6d`
## Summary
`mcp-atlassian` supports HTTP/SSE deployment for persistent, remote, and multi-user use. In that mo…
CVE-2026-77257
GitHub-GHSA
HIGH
MCP Atlassian: JIRA_PROJECTS_FILTER / CONFLUENCE_SPACES_FILTER allow forbidden-project content exfiltration (one LIVE-proven on Atlassian Cloud)
GHSA-w66g-j6c4-hcfc
pkg: mcp-atlassian
eco: pip
published: Sep 22, 2026
### Summary
`mcp-atlassian` is a popular community MCP server wrapper exposing Jira / Confluence to MCP clients. Operators commonly restrict the surface to a small allowlist of projects/spaces via the `JIRA_PROJECTS_FILTER` and `CONFLUENCE_SPACES_FILTER` environment variables, which the README docu…
CVE-2026-77251
GitHub-GHSA
HIGH
@roomi-fields/notebooklm-mcp has a path traversal in vault.batch tool that allows arbitrary file write outside intended vault directory
GHSA-jjhp-8crj-mppq
pkg: @roomi-fields/notebooklm-mcp
eco: npm
published: Sep 22, 2026
## Summary
The `vault_batch` MCP tool (and the equivalent `POST /batch-to-vault` HTTP endpoint) accepted a caller-supplied `vault_dir` path that was passed directly to `path.resolve()` + `fs.mkdir()` with no containment check. A caller — or a prompt-injected LLM driving the MCP — could therefor…
CVE-2026-61647
NVD
MEDIUM
CVE-2026-101058
python-utcp (pip package utcp-http) before 1.1.12 does not verify whether tool URLs declared in a hand-written UTCP manual point at the agent's own loopback interface when that manual is discovered from a remote, non-loopback origin. Because ensure_secure_url intentionally permits loopback HTTP for …
CWE: CWE-918
GitHub-GHSA
MEDIUM
social-auth-core Vulnerable to Account Takeover via Identity Binding Flaw in Vend Backend
GHSA-fp7w-m676-w7gc
pkg: social-auth-core
eco: pip
published: Sep 24, 2026
### Impact
The Vend OAuth2 backend used only the numeric Vend `user_id` as the social-auth UID.
When multiple Vend shops authenticate through the same application, users from different shops with the same internal Vend user ID could collide in the social-auth association table. A user from one sho…
CVE-2026-57176
NVD
MEDIUM
CVE-2026-57176
Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the Vend OAuth2 backend used only the numeric Vend user_id as the social-auth UID. When multiple Vend shops authenticate through the same application, users from different shops with the same internal Vend …
CWE: CWE-289
GitHub-GHSA
MEDIUM
@sync-in/server vulnerable to TOTP Brute-Force via `POST /api/app/sync/register`
GHSA-274f-6w77-8qm9
pkg: @sync-in/server
eco: npm
published: Sep 22, 2026
**Affected component:** Sync-in Server v2.3.0, `POST /api/app/sync/register`.
**Required attacker capability:** Valid login and password for a TOTP-enabled account with desktop sync permission.
## Summary
`POST /api/app/sync/register` accepts credentials and a TOTP code to register a desktop sync…
CVE-2026-58271
NVD
MEDIUM
CVE-2026-58271
Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, `POST /api/app/sync/register` accepts credentials and a TOTP code to register a desktop sync client. On a failed TOTP, `SyncClientsManager.register()` calls `updateAccesses(user, …
CWE: CWE-307
NVD
MEDIUM
CVE-2026-100584
OpenClaw is an npm-distributed agent runtime. In versions >= 2026.2.26 and < 2026.7.1, PowerShell command analysis on Windows hosts running in exec allowlist mode could approve an exact executable resolved from PATH but subsequently execute a same-named executable located in the workspace directory.…
CWE: CWE-426
NVD
MEDIUM
CVE-2026-65129
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service.
CWE: CWE-295
NVD
MEDIUM
CVE-2026-84724
An argument-injection flaw was found in the Ansible Automation Platform automation-controller
system-job subsystem. The system-job template launch endpoint stores a user-supplied "days"
variable without running the integer validation defined elsewhere for that field, and the
dispatcher flattens the …
CWE: CWE-88
NVD
MEDIUM
CVE-2026-84716
A flaw was found in the automation-controller instance
install-bundle endpoint. When a System Administrator downloads
an execution/hop node's install bundle, the controller signs an
X.509 certificate with the receptor mesh certificate authority
…
CWE: CWE-266
NVD
MEDIUM
CVE-2026-65125
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause external control of a file name or path. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and denial of service.
CWE: CWE-73
NVD
MEDIUM
CVE-2026-100668
Grav 2.0.0 through 2.0.24 contain a Twig content sandbox escape. The `array` filter (and its identical function form) is on the sandbox allowlist but is registered without the needs_is_sandboxed guard that print_r, vardump, json_encode, yaml_encode and string carry, and its implementation calls toAr…
CWE: CWE-200
NVD
MEDIUM
CVE-2026-100633
SiYuan is a self-hosted personal knowledge management system. In versions 3.8.0 through 3.8.3, the MCP file tool's sensitive-path guard (util.IsForbiddenAbsPath(), invoked from resolvePath()) is applied only to the allowed root of recursive operations and not to each resolved descendant path — an …
CWE: CWE-863
NVD
MEDIUM
CVE-2026-100611
Capgo (capgo.app backend, versions ≤ 12.261.0) improperly restricts which roles the apikey_manager organization role may bind to newly created API keys. When an authenticated user holding only apikey_manager (permissions org.manage_apikeys and org.read) calls POST /apikey with a JWT session, the o…
CWE: CWE-269
NVD
MEDIUM
CVE-2026-100582
OpenClaw channel plugins (@openclaw/msteams, @openclaw/feishu, @openclaw/matrix, and @openclaw/googlechat) before 2026.8.1 do not enforce the configured channel read allowlist for caller-supplied explicit read targets in message, reaction, pin, member, and related metadata read actions. A lower-trus…
CWE: CWE-862
NVD
MEDIUM
CVE-2026-91767
php_openssl_matches_wildcard_name() in ext/openssl/xp_ssl.c underflows the length argument passed to memchr() when a TLS server certificate presents a wildcard name whose literal characters are together longer than the hostname being verified. A malicious server presenting such a certificate makes t…
CWE: CWE-122
NVD
MEDIUM
CVE-2026-95811
Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow an equivalent spelling of a path to bypass the locationRules that restrict it.
The handler matches each vhost's locationRules regular expressions against REQUEST_URI, the r…
CWE: CWE-180, CWE-863
NVD
MEDIUM
CVE-2026-61811
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. From 3.8.0 until 4.14.7, the _getattributes() function in src/os_xml/os_xml.c recursively processes every XML attribute without a depth limit while allocating two large local buffer…
CWE: CWE-674
NVD
MEDIUM
CVE-2026-54461
Habitica is a habit tracker application that treats goals like a role-playing game. From 4.172.1 until 5.48.2, a query parameter on Habitica's /api/v3/groups/:groupId/members route is not sanitized before being interpreted as a regular expression. An authenticated caller can supply a computationally…
CWE: CWE-1333
GitHub-GHSA
MEDIUM
Streamlink: HTTPSession follows HTTP redirects into file:// URLs, reading local files
GHSA-vf2x-4v53-pm7v
pkg: streamlink
eco: pip
published: Sep 24, 2026
## Summary
`HTTPSession` mounts a `FileAdapter` for the `file://` scheme and inherits redirect handling
unchanged from `requests.Session`. `requests` does not check for scheme downgrades or
cross-protocol transitions when it follows a redirect, so any http(s) request Streamlink makes can
be redirec…
CVE-2026-92164
GitHub-GHSA
MEDIUM
plone.app.contenttypes has a Denial of Service in File Upload due to excessive filename length
GHSA-8pcw-h6w9-h46g
pkg: plone.app.contenttypes, plone.app.contenttypes, plone.app.contenttypes
eco: pip
published: Sep 23, 2026
### Impact
When creating an Image or File with a very large filename, Plone can become unresponsive. Even if the content loads, it can be hard to edit or delete, because the UI is unwieldy.
### Patches
The problem has been patched in `plone.app.contenttypes`.
* On Plone 6.2, upgrade to `plone.app.…
GitHub-GHSA
MEDIUM
plone.app.dexterity has a Denial of Service due to excessive title or description length
GHSA-5426-92w4-wvhv
pkg: plone.app.dexterity, plone.app.dexterity, plone.app.dexterity
eco: pip
published: Sep 23, 2026
### Impact
When creating content with a very large title or description field, Plone can become unresponsive. Even if the content loads, it can be hard to edit or delete, because the UI is unwieldy.
### Patches
The problem has been patched in `plone.app.dexterity`.
* On Plone 6.2, upgrade to `plon…
CVE-2026-57576
NVD
MEDIUM
CVE-2026-84720
A flaw was found in the Ansible Automation Platform automation-controller. The
WorkflowJobNode.ancestor_artifacts database column, which stores the raw merged set_stats
artifacts propagated between workflow nodes, is not wrapped in prevent_search() and is therefore
accepted for arbitrary field looku…
CWE: CWE-639
NVD
MEDIUM
CVE-2026-77421
JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in nano editor's regex search mode passes a user-controlled search term from doSearch(String text) in builtins/src/main/java/org/jline/builtins/Nano.java to Java's backtracking regular expression …
CWE: CWE-1333
GitHub-GHSA
MEDIUM
JLine: ReDoS in Nano Editor Regex Search Mode
GHSA-ph9c-7hw9-vhhw
pkg: org.jline:jline-builtins, org.jline:jline-builtins
eco: maven
published: Sep 23, 2026
### Summary
When regex search mode is enabled in the JLine3 `nano` editor, the user-supplied
search term is compiled directly as a Java regular expression with no timeout or
backtracking bound. A crafted pattern such as `(a+)+b` can hang the editor session
thread at high CPU, causing a denial of se…
CVE-2026-77421
NVD
MEDIUM
CVE-2026-73581
Improper Check for Certificate Revocation vulnerability in Apache Tomcat. Both the OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.58, from 9.0.0-M1 through 9.0.…
CWE: CWE-299
GitHub-GHSA
MEDIUM
Cloudreve: SSRF guard bypass: checkIP does not decode IPv6-transition wrappers (NAT64, IPv4-compatible, 6to4) reaching internal and cloud-metadata addresses
GHSA-jvh5-97xg-v99f
pkg: github.com/cloudreve/Cloudreve/v4
eco: go
published: Sep 22, 2026
**Summary**
Cloudreve's server-side request forgery guard `ValidateExternalURL` (`pkg/request/ssrf.go`) resolves a user-supplied URL host and rejects it when any resolved IP is a loopback, private, link-local, multicast, unspecified, CGNAT, or the cloud-metadata address. The classification is perfo…
CVE-2026-79913
GitHub-GHSA
MEDIUM
KubeEdge: Unbounded allocation in viaduct packer enables authenticated remote DoS against CloudHub
GHSA-gfw4-49f9-cp25
pkg: github.com/kubeedge/kubeedge, github.com/kubeedge/kubeedge, github.com/kubeedge/kubeedge
eco: go
published: Sep 22, 2026
## Summary
KubeEdge CloudHub uses the viaduct packer to decode messages received from connected peers. The packer reads a 32-bit payload length from the message header and previously allocated a buffer of that size without enforcing an upper bound.
An authenticated peer that can establish a viaduc…
CVE-2026-62370
GitHub-GHSA
MEDIUM
MCP Atlassian: Arbitrary File Read via Upload Attachment Tools
GHSA-f26r-j276-ggg4
pkg: mcp-atlassian
eco: pip
published: Sep 22, 2026
## Summary
The upload attachment tools in both Confluence and Jira accept arbitrary file paths without path traversal validation. The upload_attachment methods read any file accessible to the server process and upload it to a Confluence page or Jira issue. Despite the existence of a validate_safe_p…
CVE-2026-77270
GitHub-GHSA
MEDIUM
MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read and exfiltration via MCP tool call
GHSA-mfv2-4wvm-9pgp
pkg: mcp-atlassian
eco: pip
published: Sep 22, 2026
### Summary
The `upload_attachment` functions in both the Jira and Confluence modules accept a user-controlled `file_path` parameter and open the specified file for reading **without calling `validate_safe_path()`**. An authenticated MCP client can supply an arbitrary path such as `/etc/passwd` or …
CVE-2026-77266
GitHub-GHSA
MEDIUM
MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read (incomplete fix for CVE-2026-27825)
GHSA-h7wj-5v37-59r2
pkg: mcp-atlassian
eco: pip
published: Sep 22, 2026
### Summary
The `confluence_upload_attachment` and `confluence_upload_attachments` MCP tools accept a `file_path` parameter and do not validate that the path is confined to an allowed directory before opening the file. An attacker who can call these tools can read any file accessible to the MCP ser…
CVE-2026-77269
GitHub-GHSA
MEDIUM
OpenCVE: Server-Side Request Forgery (SSRF) in notifications
GHSA-ch3g-4xvr-674q
pkg: opencve
eco: pip
published: Sep 22, 2026
### Impact
OpenCVE contains a Server-Side Request Forgery (SSRF) vulnerability in the notification testing functionality for both Webhook and Slack integrations.
An authenticated user with permission to configure notification channels can trigger test requests to arbitrary HTTP(S) endpoints. Insuf…
CVE-2026-62282
GitHub-GHSA
MEDIUM
microsandbox: Secret values exposed in world-readable process arguments
GHSA-m8f5-rh7h-vgg3
pkg: microsandbox
eco: rust
published: Sep 22, 2026
## Summary
When the SDK spawns a sandbox, the `msb sandbox` child process receives the full network configuration as an inline `–network-config <json>` command-line argument, and any per-sandbox environment as repeated `–env KEY=VALUE` arguments. On Linux a process's arguments are world-readable …
CVE-2026-61670
NVD
MEDIUM
CVE-2026-77399
icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python. From 6.1.0 until 7.2.2, vInt.from_ical accepts an attacker-controlled VALARM REPEAT value and applications that request alarm times can eagerly expand it without an application-level limit. Alarms.times and Alarm…
CWE: CWE-400, CWE-834
NVD
MEDIUM
CVE-2026-79913
Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, the ValidateExternalURL server-side request forgery guard in pkg/request/ssrf.go passes resolved addresses to checkIP without decoding NAT64, IPv4-compatible, and 6to4 IPv4-in-IPv6 transition forms. An authenticated user…
CWE: CWE-697, CWE-918
NVD
MEDIUM
CVE-2026-65115
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker may cause uncontrolled resource consumption. A successful exploit of this vulnerability may lead to denial of service.
CWE: CWE-400
NVD
MEDIUM
CVE-2026-65112
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service.
CWE: CWE-400
GitHub-GHSA
MEDIUM
Sync-in Server has a ReDoS via Unsanitized Regex in Sync Diff `pathFilters`
GHSA-jx63-h26r-8cph
pkg: @sync-in/server
eco: npm
published: Sep 22, 2026
**Affected component:** Sync-in Server v2.3.0, `POST /api/app/sync/operation/diff/:id`, vulnerable implementation of `pathFilters` in `backend/src/applications/sync/dtos/sync-operations.dto.ts`.
## Summary
In the vulnerable version, the sync diff endpoint accepted a user-controlled regex pattern t…
CVE-2026-58270
NVD
MEDIUM
CVE-2026-58270
Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, the sync diff endpoint compiles a user-supplied string into a `RegExp` with no complexity validation. A catastrophic-backtracking pattern (e.g. `^(a+)+b`) blocks the Node.js event…
CWE: CWE-1333
GitHub-GHSA
MEDIUM
social-auth-core has an Improper Authentication issue
GHSA-vq6g-g6c7-5f2j
pkg: social-auth-core
eco: pip
published: Sep 24, 2026
### Impact
The SAML backend accepted SAML responses on the Assertion Consumer Service endpoint without verifying that they matched a previously issued `AuthnRequest`.
Applications using SAML account association could allow an attacker with a valid account on a trusted IdP to link the attacker's SA…
CVE-2026-57175
NVD
MEDIUM
CVE-2026-57175
Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the SAML backend accepted SAML responses on the Assertion Consumer Service endpoint without verifying that they matched a previously issued `AuthnRequest`. Applications using SAML account association could …
CWE: CWE-287
NVD
MEDIUM
CVE-2026-84721
A server-side request forgery flaw was found in the Ansible Automation Platform
automation-controller email notification backend. The email backend passes the user-supplied SMTP
host and port from a notification template directly to the SMTP client without validating that
the target is not an intern…
CWE: CWE-918
GitHub-GHSA
MEDIUM
9router: Kiro region injection allows authenticated SSRF with Authorization header forwarding
GHSA-6mwv-4mrm-5p3m
pkg: 9router
eco: npm
published: Sep 23, 2026
### Summary
The Kiro API-key validation endpoint builds an upstream URL using a user-controlled
`region` value. By supplying a crafted region such as `kiro-canary.local:8443#`, an
authenticated attacker can cause 9router to send the Kiro validation request to an
attacker-controlled host under the c…
CVE-2026-56678
NVD
MEDIUM
CVE-2026-96672
Frappe ERPNext versions before 16.34.1 fail to validate that Financial Report Template calculation_formula values reference whitelisted methods before passing them to frappe.call(). Accounts Managers can supply arbitrary dotted Python paths to invoke non-whitelisted internal server-side methods and …
CWE: CWE-470
NVD
MEDIUM
CVE-2026-5924
The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Maps block's 'customStyle' attribute in all versions up to, and including, 2.1.3. This is due to the use of eval() on user-controlled block content in the frontend JavaScript mapStyles() …
CWE: CWE-79
GitHub-GHSA
MEDIUM
Nautobot: Authorization bypass in approval workflow REST API allows self-approval and unauthorized activation of scheduled jobs
GHSA-q4c5-2j6f-r476
pkg: nautobot
eco: pip
published: Sep 22, 2026
### Impact
This is an authorization bypass that escalates into unauthorized server-side job execution.
1. Primary impact – self-approval: The approver checks (approver-group membership, `change` permission on the object under review, one-response-per-user) are enforced only in the `approve`/`deny` …
CVE-2026-83805
NVD
MEDIUM
CVE-2026-97366
A security flaw has been discovered in jhen0409 react-native-debugger up to 0.14.0. The impacted element is the function openDevTools of the file electron/window.js of the component Open in Editor Handler. The manipulation of the argument host results in os command injection. It is possible to launc…
CWE: CWE-77, CWE-78
GitHub-GHSA
MEDIUM
Graylog: Manager-to-Owner privilege escalation on saved searches and dashboards
GHSA-m9c2-85gv-8xr5
pkg: org.graylog2:graylog2-server, org.graylog2:graylog2-server, org.graylog2:graylog2-server
eco: maven
published: Sep 22, 2026
### Impact
A vulnerability was found in Graylog's API endpoint for updating saved searches and dashboards. A user with edit permissions on a dashboard or saved search could grant owner permissions to an arbitrary account, which could then be used to delete the respective saved search or dashboard o…
CVE-2026-69190
GitHub-GHSA
MEDIUM
Hatchet: Cross-Tenant Durable Task Event Log Disclosure via Missing Authorization Check
GHSA-g26x-m427-f48f
pkg: github.com/hatchet-dev/hatchet
eco: go
published: Sep 22, 2026
### Summary
The `GET /api/v1/stable/durable-tasks/{durable-task}` endpoint (`listDurableEventLog`) is missing tenant authorization validation, allowing any authenticated user to read durable task event logs from any tenant.
### Impact
This CVE requires the attacker to successfully guess the targe…
CVE-2026-63342
NVD
MEDIUM
CVE-2026-84301
FastGPT is an open-source LLM platform for building AI applications on a knowledge base. Prior to 4.15.2, the safe Axios request interceptor in packages/service/common/api/axios.ts validates a hostname with isInternalAddress() before a later HTTP connection performs an independent DNS lookup, creati…
CWE: CWE-918
NVD
MEDIUM
CVE-2026-86805
A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the lexically normal…
CWE: CWE-367
NVD
MEDIUM
CVE-2026-79919
MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.6-lts, function-library code running under the LD_PRELOAD sandbox can invoke ctypes.CDLL from an importlib.abc.MetaPathFinder callback so the dlopen call-stack heuristic sees a Python import frame, then use unhooked dlsym wit…
CWE: CWE-693
GitHub-GHSA
MEDIUM
Dasel: Selector lexer panics on trailing whitespace in `parseCurRune`
GHSA-65gg-g7rw-6cpc
pkg: github.com/tomwright/dasel/v3
eco: go
published: Sep 22, 2026
Same panic class as GHSA-m5j3-4634-c2vq and GHSA-m6xr-fvfg-5g64, sister site on the same function. Trigger is any selector ending in whitespace: `dasel query 'a '` panics at `selector/lexer/tokenize.go:60`.
The whitespace-skip loop right above (lines 55-57) advances `p.i` to `p.srcLen` when the inp…
CVE-2026-62866
GitHub-GHSA
MEDIUM
Dasel: Unbounded recursion in JSON and XML readers causes unrecoverable stack-overflow DoS
GHSA-cqxr-jxr2-85pq
pkg: github.com/tomwright/dasel/v3
eco: go
published: Sep 22, 2026
## Summary
`dasel`'s JSON and XML readers parse nested structures with unbounded recursion, one
native stack frame per nesting level, with no depth guard. A small (sub-10 MB), deeply
nested document drives the Go runtime past its goroutine stack limit and triggers a
`fatal error: stack overflow`. T…
CVE-2026-59168
NVD
MEDIUM
CVE-2026-59168
Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.11.1, parsing/json/json_reader.go decodeValue, decodeObject, and decodeArray, and parsing/xml/reader.go parseElement, recurse once per input nesting level without a depth guard. Dee…
CWE: CWE-674
NVD
MEDIUM
CVE-2026-17577
The SSL Zen plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'uri' (and 'host') parameters in versions up to, and including, 4.7.42. The ssl_zen_messages::getMessages() function builds the 'token_missmatch' message using base64_decode(sanitize_text_field($_REQUEST['uri'])…
CWE: CWE-79
GitHub-GHSA
MEDIUM
xhtml-purifier has HTML attribute-injection (sanitizer bypass) that leads to XSS
GHSA-j8r4-32c5-33rc
pkg: xhtml-purifier
eco: npm
published: Sep 24, 2026
xhtml-purifier does not HTML-entity-encode attribute values when serializing its sanitized output. In attributeString() (XHTMLPurifier.js, around line 148) the attribute value is concatenated directly into a double-quoted attribute without encoding. As a result, an attacker-controlled value in any a…
CVE-2026-61784
NVD
MEDIUM
CVE-2026-93405
Mailspring is a fast, cross-platform, open-source email client. Prior to 1.17.0, attachment quick preview converts Markdown, DOCX, and XLSX attachments with Snarkdown, Mammoth, and SheetJS and inserts the resulting HTML into the preview document through innerHTML without sanitization. A remote sende…
CWE: CWE-79
NVD
MEDIUM
CVE-2026-61784
xhtml-purifier is a Node.js library to take in raw/unknown/untrusted HTML and output cleaned, purified, trusted HTML. Versions prior to 0.4.3 do not HTML-entity-encode attribute values when serializing its sanitized output. In attributeString() (XHTMLPurifier.js, around line 148) the attribute value…
CWE: CWE-79, CWE-116
GitHub-GHSA
MEDIUM
lightrag-hku: Stored Cross-Site Scripting (XSS) in the LightRAG WebUI chat/answer renderer via ingested content
GHSA-xpjq-3w4w-w5wr
pkg: lightrag-hku
eco: pip
published: Sep 22, 2026
### Summary
The LightRAG WebUI renders assistant/answer chat content as **raw HTML** — `react-markdown` is
configured with `rehypePlugins={[rehypeRaw]}` and `skipHtml={false}` and **no** HTML sanitizer
(`rehype-sanitize`), element allow-list, or custom `urlTransform`. Because answer content is der…
CVE-2026-86062
GitHub-GHSA
MEDIUM
MCP Atlassian: OAuth fallback token storage writes plaintext access and refresh tokens with group-readable permissions
GHSA-g5xv-mhgm-v5f6
pkg: mcp-atlassian
eco: pip
published: Sep 22, 2026
### Summary
When OAuth tokens are saved, MCP Atlassian always writes a plaintext fallback copy under `~/.mcp-atlassian/oauth-<client_id>.json`. The fallback file is created with the process default umask rather than restrictive permissions. In this environment the file was created as mode `0664`, e…
CVE-2026-77250
NVD
MEDIUM
CVE-2026-77250
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, OAuthConfig writes a plaintext fallback file containing access and refresh tokens under the user's .mcp-atlassian directory using process-default permissions. On systems with a permi…
CWE: CWE-312
NVD
MEDIUM
CVE-2026-86062
LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, lightrag_webui/src/components/retrieval/ChatMessage.tsx renders answer and thinking content with react-markdown, rehypeRaw, and skipHtml=false without an HTML sanitizer. An attacker who can add a document can store raw…
CWE: CWE-79
NVD
MEDIUM
CVE-2026-100701
Nodemailer versions 5.0.0 through 10.0.1 use a process-global DNS cache that is keyed only by the DNS host, while each cache entry also stores the caller-specific TLS servername. When two direct TLS/SMTPS transports (secure: true) resolve the same non-IP host with different tls.servername values, th…
CWE: CWE-295
GitHub-GHSA
MEDIUM
Cilium: Namespaced HTTPRoutes can redirect traffic to other namespaces
GHSA-w7c2-w76w-5hmj
pkg: github.com/cilium/cilium, github.com/cilium/ciliumCilium, github.com/cilium/cilium
eco: go
published: Sep 24, 2026
### Impact
In Cilium clusters using [Gateway API](https://docs.cilium.io/en/stable/network/servicemesh/gateway-api/gateway-api/), users with permissions to create or update namespaced HTTPRoutes can mirror HTTP traffic to any Service in any namespace, bypassing the ReferenceGrant authorization mech…
CVE-2026-56742
NVD
MEDIUM
CVE-2026-95625
The Tauri updater plugin verifies update binaries using minisign signatures, but the signature covers only the raw binary bytes. The update manifest — which contains the version number, download URL, and signature — is fetched over TLS but is never itself signed or authenticated. Because the only …
CWE: CWE-354
GitHub-GHSA
MEDIUM
lightrag-hku: Plaintext Passwords Compared Without Constant-Time Function
GHSA-c759-cx9p-mrwq
pkg: lightrag-hku
eco: pip
published: Sep 22, 2026
### Summary
When plaintext passwords are stored in AUTH_ACCOUNTS, the comparison uses Python's == operator which is not constant-time. An attacker with low-latency access can exploit timing differences to recover the password character by character.
### Details
“`python
# lightrag/api/passwords.p…
CVE-2026-85725
GitHub-GHSA
MEDIUM
MCP Atlassian: SSRF via DNS Rebinding in Header-Based Authentication Flow
GHSA-49xv-9743-pw8w
pkg: mcp-atlassian
eco: pip
published: Sep 22, 2026
## Summary
The SSRF protection for header-based authentication uses a validate-then-use pattern vulnerable to DNS rebinding. validate_url_for_ssrf resolves the hostname via DNS and checks that the resolved IP is globally routable. However, the actual HTTP request happens later, during which the DNS…
CVE-2026-77265
NVD
MEDIUM
CVE-2026-85725
LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, verify_password in lightrag/api/passwords.py compares plaintext AUTH_ACCOUNTS password values with Python's == operator. The comparison can return after the first mismatching byte, creating response-time differences ba…
CWE: CWE-208
NVD
MEDIUM
CVE-2026-65124
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an XML injection. A successful exploit of this vulnerability might lead to data tampering and denial of service.
CWE: CWE-91
GitHub-GHSA
MEDIUM
Fabio – Incomplete fix for CVE-2025-48865: operator-configured trust headers (clientip/tls/requestid) still strippable via the Connection header
GHSA-fq95-v8xc-jm3v
pkg: github.com/fabiolb/fabio
eco: go
published: Sep 22, 2026
**Affected:** github.com/fabiolb/fabio >= 1.6.6 through 1.7.1 and master HEAD (c75f8a6).
### Summary
The v1.6.6 fix for CVE-2025-48865 sweeps the client `Connection` header against a hardcoded allowlist `protectHeaders` (proxy/http_headers.go:28-36) containing only the 7 X-Forwarded family headers.…
CVE-2026-62987
NVD
MEDIUM
CVE-2026-62987
Fabio is an HTTP(S) and TCP router for deploying applications managed by consul. From 1.6.6 until 1.7.2, the CVE-2025-48865 fix in proxy/http_headers.go uses protectHeaders for a hardcoded set of forwarded headers but omits the operator-configured ClientIPHeader, TLSHeader, and RequestID names. In p…
CWE: CWE-290, CWE-348
NVD
MEDIUM
CVE-2025-71422
Contrast is a Kubernetes runtime for confidential containers. In versions before 1.12.1, the secure persistent volume feature is vulnerable to a malicious host supplying a crafted LUKS2 volume to a pod VM. LUKS2 volume metadata is not authenticated and, with cryptsetup versions prior to 2.8.1, a hea…
CWE: CWE-347
GitHub-GHSA
MEDIUM
@aborruso/ckan-mcp-server has SSRF via DNS-name → internal IP — incomplete fix of CVE-2026-53509
GHSA-798p-78g2-v556
pkg: @aborruso/ckan-mcp-server
eco: npm
published: Sep 22, 2026
## Summary
The SSRF guard `validateServerUrl` (added for CVE-2026-33060, extended for CVE-2026-53509) validates only the **hostname string** and never resolves DNS. Any caller-supplied `server_url` whose hostname *resolves* to an internal address passes the guard, so the server issues requests to **…
CVE-2026-61612
NVD
MEDIUM
CVE-2026-91166
Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. From 0.25.0 until 0.27.6, the browser SSH path in warpgate-web-ssh/src/manager.rs handles RCEvent::HostKeyUnknown without the presenting hop identity and instead passes ssh_options.host and ssh_options.port for the final target …
CWE: CWE-297, CWE-923
NVD
MEDIUM
CVE-2026-100860
heym before 0.0.105 does not act on the result of the credential authorization lookup in the Redis workflow node (backend/app/services/node_execution/nodes/redis_node.py). When _get_accessible_credential returns None — because the credential ID does not exist or the caller is not authorized to use…
CWE: CWE-636
NVD
MEDIUM
CVE-2026-92680
Araxis Merge for Windows version 2011.4074 through 2026.0 stores user-configured credentials for remote servers in the Windows registry and does not apply sufficient cryptographic protection. An authenticated, non-administrative attacker could retrieve and unencrypt all credentials the target user h…
CWE: CWE-522
NVD
MEDIUM
CVE-2026-77420
JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, DefaultHistory.matchPatterns(String patterns, String line) in reader/src/main/java/org/jline/reader/impl/history/DefaultHistory.java converts the HISTORY_IGNORE configuration value into a Java regular expression …
CWE: CWE-1333
GitHub-GHSA
MEDIUM
JLine: ReDoS via `HISTORY_IGNORE` Configuration Variable
GHSA-5q95-hrpc-m3w3
pkg: org.jline:jline-reader, org.jline:jline-reader
eco: maven
published: Sep 23, 2026
### Summary
The JLine3 `HISTORY_IGNORE` variable is converted into a Java regular expression with
only partial escaping. As a result, regex metacharacters other than `*` and `:` are
passed through to the regex engine. A crafted value such as `(a+)+b` can cause
catastrophic backtracking each time a …
CVE-2026-77420
NVD
MEDIUM
CVE-2026-96259
Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to apply the internal-connection filter to OAuth endpoint requests, which allows a System Administrator to make the server issue requests to internal network addresses and read the responses via the co…
CWE: CWE-918
GitHub-GHSA
MEDIUM
Gardener: Authorization Bypass via Group Subject Injection
GHSA-gfjv-gqf2-c888
pkg: github.com/gardener/gardener, gardener/gardener, gardener/gardener
eco: go
published: Sep 22, 2026
## Overview
The `manage-members` custom verb authorization check in the Gardener API server's `customverbauthorizer` admission plugin can be bypassed by adding `Group` or `ServiceAccount` subjects to a Project's member list. The check is documented as controlling "human users or groups", but the imp…
CVE-2026-79767
GitHub-GHSA
MEDIUM
Nuclei: Local File Read via Workflow File-Protocol Gate Bypass
GHSA-qgw5-7j4f-fg97
pkg: github.com/projectdiscovery/nuclei/v3
eco: go
published: Sep 22, 2026
A vulnerability in Nuclei's workflow template loader allows `file:` protocol templates to execute without the `-file` flag, bypassing a security gate that is meant to prevent local file reads on the scanner host.
**Affected Component**
The issue is in the workflow template loading path. The main t…
CVE-2026-76804
GitHub-GHSA
MEDIUM
MCP Atlassian: Insecure File Permissions on OAuth Token Storage
GHSA-4596-2p6p-28cv
pkg: mcp-atlassian
eco: pip
published: Sep 22, 2026
## Summary
The OAuth token fallback file storage in `OAuthConfig._save_tokens_to_file()` creates token files containing access tokens, refresh tokens, and cloud IDs with default filesystem permissions (typically `0644` on Linux, world-readable). Any local user on a shared system can read these file…
CVE-2026-77268
NVD
MEDIUM
CVE-2026-79767
Gardener implements the automated management and operation of Kubernetes clusters as a service. Prior to 1.142.6, 1.143.3, 1.144.2, and 1.145.0, the customverbauthorizer admission plugin's mustCheckProjectMembers manage-members check compares changes to User subjects but does not account for Group o…
CWE: CWE-863
NVD
MEDIUM
CVE-2026-77268
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the OAuth fallback token directory and JSON file are created without explicit owner-only modes. Local users or processes with access through the resulting group or world permission b…
CWE: CWE-732
NVD
MEDIUM
CVE-2026-86056
Notepad++ is a free and open-source source code editor. Prior to 8.9.8, the NPPM_SAVESESSION handler in PowerEditor/src/NppBigSwitch.cpp converts lParam to a sessionInfo pointer and dereferences its nbFile, files, and sessionFilePathName members without checking for null. A process running at the sa…
CWE: CWE-476
NVD
MEDIUM
CVE-2026-81886
radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Windows 64-bit crash-dump dmp64 parser was vulnerable because the Windows dmp64 parser used an input-controlled physical-memory-run PageCount directly as the bound of a per-page allocation loop. …
CWE: CWE-770
NVD
MEDIUM
CVE-2026-101048
Cloudreve before 4.17.0 registers the administrative node test endpoints (POST /api/v4/admin/node/test and POST /api/v4/admin/node/test/downloader) without requiring the Admin.Write OAuth scope, unlike the node create/update/delete routes. An OAuth client that has been authorized by an administrator…
CWE: CWE-863
NVD
MEDIUM
CVE-2026-100681
Budibase before 3.45.0 contains an unauthenticated server-side request forgery and credential exfiltration vulnerability in the Microsoft Teams webhook endpoint that accepts forged Bot Framework activities with arbitrary serviceUrl values. Attackers can submit a crafted POST request to inject an att…
CWE: CWE-918
NVD
MEDIUM
CVE-2026-97736
tinyauth before 5.1.3 allows rule bypass by appending an allowed route string. This is caused by an unanchored regular expression.
CWE: CWE-777
NVD
MEDIUM
CVE-2026-48543
Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the web form description field. Attackers can craft a web form descriptio…
CWE: CWE-79
NVD
MEDIUM
CVE-2026-48542
Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the product name field. Attackers can craft a product name containing dou…
CWE: CWE-79
NVD
MEDIUM
CVE-2026-48541
Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the person name field. Attackers can craft a person name containing doubl…
CWE: CWE-79
NVD
MEDIUM
CVE-2026-48540
Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the lead title field. Attackers can craft a lead title containing double-…
CWE: CWE-79
GitHub-GHSA
MEDIUM
Home Assistant: mDNS Server-Side Request Forgery
GHSA-4ghv-53cq-7wp3
pkg: homeassistant
eco: pip
published: Sep 22, 2026
## Summary
Home Assistant Green is vulnerable to a Server-Side Request Forgery (SSRF) via the mDNS/Zeroconf IPP integration. An unauthenticated attacker on the local network can send a crafted mDNS response to trick Home Assistant into making HTTP requests to arbitrary hosts, including internal ser…
CVE-2026-91129
GitHub-GHSA
MEDIUM
Nautobot: Stored cross-site scripting (XSS) in object create/edit form help text
GHSA-56v6-2fhr-wxgq
pkg: nautobot, nautobot
eco: pip
published: Sep 22, 2026
### Impact
_What kind of vulnerability is it? Who is impacted?_
It has two related instances that share the same root cause: a user-controlled model field is assigned verbatim to a form field's `help_text`, which is rendered with Django's `|safe` filter (`render_field.html`), bypassing auto-escapin…
CVE-2026-83801
GitHub-GHSA
MEDIUM
MCP Atlassian: Reflected XSS in OAuth Setup Callback Handler
GHSA-g2r2-3j32-j27x
pkg: mcp-atlassian
eco: pip
published: Sep 22, 2026
## Summary
The OAuth 2.0 setup wizard's local callback HTTP server reflects the `error` query parameter directly into an HTML response without any sanitization or encoding. An attacker can craft a malicious callback URL containing JavaScript in the `error` parameter that executes in the victim's br…
CVE-2026-77272
NVD
MEDIUM
CVE-2026-77272
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the OAuth error query parameter is passed to CallbackHandler._send_response in oauth_setup.py and interpolated into an HTML page without escaping. A crafted authorization callback ca…
CWE: CWE-79
NVD
MEDIUM
CVE-2026-54915
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the unauthenticated /auth/redirect endpoint in plexpy/webauth.py removes forward slashes from the user-controlled redirect_uri parameter but leaves tab, line-feed, and carriage-return characters intact. W…
CWE: CWE-601
NVD
MEDIUM
CVE-2026-100613
capgo.app is an over-the-air (OTA) update platform for Capacitor apps. In all versions up to and including the current release (no patch available at time of publication), the `transfer_app()` database function transfers an app, its channels, versions and related records to a destination organizatio…
CWE: CWE-863
NVD
MEDIUM
CVE-2026-100230
Input Leap (aka input-leap) through 3.0.3, when the non-default –enable-drag-drop option is used on Windows or macOS, mishandles the / versus \ distinction and allows directory traversal, with resultant code execution if a file is written to a startup directory. This occurs via a DDRG message.
CWE: CWE-180
NVD
MEDIUM
CVE-2026-84712
A flaw was found in the automation-controller API. The
unauthenticated health-check endpoint /api/v2/ping/
(ApiV2PingView, AllowAny) over-serializes RBAC-gated
automation-mesh data into its anonymous response, exposing the
full …
CWE: CWE-497
NVD
MEDIUM
CVE-2026-88840
BusyBox TLS get_client_hello() reads past the end of the input buffer when parsing a truncated ClientHello message.
CWE: CWE-125
NVD
MEDIUM
CVE-2026-73858
Solspace Freeform plugin for Craft CMS 5.x is a super flexible form-building tool. From 5.0.0 through 5.10.13, submitted values from public Freeform forms can be evaluated by the isolated Twig renderer when rendered into HTML attributes. An unauthenticated attacker can place Twig expressions in subm…
CWE: CWE-1336
NVD
MEDIUM
CVE-2025-12767
IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to cause a denial of service using a specially crafted regular expression that would cause excessive resource consumption.
CWE: CWE-770
GitHub-GHSA
MEDIUM
lightrag-hku: Sensitive Information Exposure Through Raw Exception Messages in API Error Responses
GHSA-hrmj-7rvj-4hg8
pkg: lightrag-hku
eco: pip
published: Sep 22, 2026
### Summary
The LightRAG API server passes raw Python exception messages directly into HTTP
error responses across 30+ error handlers in every router. When combined with
the default unauthenticated configuration (see companion report on CWE-306), any
network-reachable client can trigger exceptions …
CVE-2026-85709
GitHub-GHSA
MEDIUM
Autobahn Python permessage-deflate bypasses maxMessagePayloadSize after inflation
GHSA-hxp9-w8x3-p566
pkg: autobahn, crossbar
eco: pip
published: Sep 22, 2026
### Summary
Autobahn Python enforces `maxMessagePayloadSize` against the compressed WebSocket frame length before permessage-deflate inflation, then delivers the inflated message to application callbacks without a second size check. A client frame that is only 22 compressed bytes can inflate to 4096…
CVE-2026-77528
GitHub-GHSA
MEDIUM
Nuclei: Environment Variable Disclosure via Response-Derived Data in DAST/Fuzz Mode
GHSA-jpvm-9frm-hjcq
pkg: github.com/projectdiscovery/nuclei/v3
eco: go
published: Sep 22, 2026
A vulnerability in Nuclei's DAST/fuzz expression evaluation path allows a malicious target server to trigger disclosure of scanner-host environment variables when the `-env-vars` / `-ev` option is explicitly enabled.
This is an incomplete fix for [CVE-2026-41645](https://github.com/projectdiscovery…
CVE-2026-76805
GitHub-GHSA
MEDIUM
Nuclei: Local File Read via MySQL Client Sandbox Bypass
GHSA-xhmx-w2j4-rw3q
pkg: github.com/projectdiscovery/nuclei/v3
eco: go
published: Sep 22, 2026
A vulnerability in Nuclei's JavaScript MySQL client library allows arbitrary local file reads that bypass the `-allow-local-file-access` (`-lfa`) sandbox restriction.
**Affected Component**
The issue is in the `nuclei/mysql` JavaScript library used by `javascript:` protocol templates. The MySQL cl…
CVE-2026-76803
GitHub-GHSA
MEDIUM
Tinyauth: Unauthenticated login attempts can trigger global login lockdown denial of service
GHSA-9xhm-w3wj-xhqh
pkg: github.com/steveiliop56/tinyauth
eco: go
published: Sep 22, 2026
### Summary
Tinyauth's login rate-limit bookkeeping can enter a global lockdown mode when its in-memory login-attempt map reaches 256 distinct identifiers. Because unauthenticated `POST /api/user/login` requests for unknown usernames are recorded in this same map, a remote unauthenticated attacker …
CVE-2026-77561
GitHub-GHSA
MEDIUM
MCP Atlassian: Incomplete fix for GHSA-7r34-79r5-rcc9: redirect-based SSRF via unhooked requests session in Jira user-permission lookup
GHSA-v9m3-wfh8-5646
pkg: mcp-atlassian
eco: pip
published: Sep 22, 2026
Summary
The fix for the SSRF vulnerability tracked as GHSA-7r34-79r5-rcc9 / CVE-2026-27826 is incomplete. That fix added two defenses: validate_url_for_ssrf() on the per-request X-Atlassian-Jira-Url / X-Atlassian-Confluence-Url headers (blocking a directly-internal base URL), and a redirect-validat…
CVE-2026-77249
GitHub-GHSA
MEDIUM
MPXJ: Potential Path Traversal Vulnerability in Primavera P3 PRX and SureTrak STX readers
GHSA-7952-gx68-cjqr
pkg: MPXJ.Net, mpxj, mpxj
eco: pip
published: Sep 22, 2026
### Impact
When reading a suitably crafted PRX or STX file, MPXJ can be made to write files to arbitrary locations in the file system.
### Patches
This issue is addressed in MPXJ version 16.5.0.
### Workarounds
Do not read PRX or STX files from untrusted sources.
CVE-2026-65829
NVD
MEDIUM
CVE-2026-85709
LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the LightRAG API server returns raw Python exception text from error handlers in document_routes.py, graph_routes.py, query_routes.py, ollama_api.py, and lightrag_server.py. The detail=str(e), detail=str(exc), and equi…
CWE: CWE-209
NVD
MEDIUM
CVE-2026-76805
Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST/fuzz payload path in pkg/fuzz/parts.go can evaluate substituted runtime data more than once, creating a second evaluation pass that allows response content captured by an internal: true extractor in…
CWE: CWE-200
GitHub-GHSA
MEDIUM
9Router has a Login Brute-Force Lockout Bypass via Spoofable X-9r-Real-Ip Header
GHSA-32gc-64m7-hj7v
pkg: 9router
eco: npm
published: Sep 22, 2026
# Summary
9router enforces a progressive login lockout (5 failed attempts → temporary 30s+ lock) keyed on the client IP. The client IP used for this limiter is taken from the X-9r-Real-Ip request header, which is intended to be set only by the bundled custom-server.js layer from the unspoofable T…
CVE-2026-56682
GitHub-GHSA
MEDIUM
Sync-in Server has Username/Login Enumeration via Timing Side-Channel on POST /api/auth/login (incomplete fix of the prior timing-attack advisory)
GHSA-29hq-23m2-2j47
pkg: @sync-in/server
eco: npm
published: Sep 22, 2026
## Summary
validateUser() in backend/src/authentication/providers/mysql/auth-provider-mysql.service.ts returns immediately when the supplied login/email does not match any account, without ever calling comparePassword():
async validateUser(loginOrEmail: string, password: string, ip?: string, s…
CVE-2026-58272
NVD
MEDIUM
CVE-2026-100863
Heym versions 0.0.90 and earlier contain two server-side request forgery (SSRF) egress gaps, both remediated in app/services/ssrf_guard.py in 0.0.91. First, the LLM image-edit input loader (_load_image_bytes) fetched caller-controlled HTTP/HTTPS URLs with a bare httpx.get, applying only a scheme che…
CWE: CWE-918
NVD
MEDIUM
CVE-2026-100502
Flame through 2.4.0 contains an insufficient session expiration vulnerability in the login endpoint that allows attackers with former admin access to obtain tokens with arbitrary lifespans by supplying unvalidated duration parameters. Attackers can mint near-permanent administrator tokens that survi…
CWE: CWE-613
GitHub-GHSA
MEDIUM
CyberChef: Prototype pollution in Series Chart operation
GHSA-fx6f-382r-j72c
pkg: cyberchef
eco: npm
published: Sep 24, 2026
On 5 June 2026 CyberChef received a security vulnerability report from @hyuunnn detailing a vulnerability in the Series Chart operation, where malicious input could result in prototype pollution of the data structures outputted from the operation.
Other operations following Series Chart could have t…
CVE-2026-57439
NVD
MEDIUM
CVE-2026-96747
The client-side field level encryption support in the MongoDB Python Driver can treat a key management endpoint value ending in ".sock" as a local Unix domain socket path rather than a remote host. A user with write access to the encryption key metadata stored in the database can cause an applicatio…
CWE: CWE-918
NVD
MEDIUM
CVE-2026-65126
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper enforcement of a behavioral workflow. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information disclosure.
CWE: CWE-841
NVD
MEDIUM
CVE-2026-65117
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of a hard-coded password. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information disclosure.
CWE: CWE-259
NVD
MEDIUM
CVE-2026-100862
heym, a workflow automation platform, stores and returns multiple capability secrets in plaintext in versions prior to 0.0.91. Affected secrets include webhook header-auth values (returned in cleartext by GET /api/workflows/{id} and persisted unsanitized into execution history), MCP API keys (stored…
CWE: CWE-312
NVD
MEDIUM
CVE-2026-17602
The SSL Zen — SSL Certificate Installer & HTTPS Redirects plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.7.42 via the 'file_name' parameter parameter. This makes it possible for authenticated attackers, with administrator-level access and above, t…
CWE: CWE-22
NVD
MEDIUM
CVE-2026-63329
Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.6, copy_server_request in warpgate-protocol-http/src/proxy.rs forwards a client-supplied x-warpgate-username header before inject_own_headers appends the authenticated username. Because the request builder preserve…
CWE: CWE-116, CWE-290
NVD
MEDIUM
CVE-2026-55625
GoCD is a continuous deliver server. From 16.1.0 until 26.1.0, the internal material connection test APIs at /go/api/admin/internal/material_test and /go/api/internal/config_repos/*/material_test accept an arbitrary existing pipeline and pipeline-group context without sufficient validation. A pipeli…
CWE: CWE-639, CWE-863
NVD
MEDIUM
CVE-2026-101061
utcp-gql before 1.1.1 and utcp-websocket before 1.1.1 contain server-side request forgery vulnerabilities due to incomplete application of CVE-2026-44661 fixes. The GraphQL plugin uses a vulnerable prefix check allowing bypass URLs like http://127.0.0.1.attacker.example, while the WebSocket plugin p…
CWE: CWE-918
NVD
MEDIUM
CVE-2026-100634
SiYuan before v3.8.4 does not validate the sender or restrict recipients in the 'siyuan-send-windows' IPC handler of the Electron main process (app/electron/main.js). The handler ignores event.sender and forwards any received payload to every BrowserWindow returned by BrowserWindow.getAllWindows(), …
CWE: CWE-862
GitHub-GHSA
MEDIUM
Nuclei: Arbitrary Command Execution via DAST Code Signature Bypass
GHSA-jpf4-98qj-qr67
pkg: github.com/projectdiscovery/nuclei/v3
eco: go
published: Sep 22, 2026
A vulnerability in Nuclei's DAST template loading path allows unsigned `code:` protocol templates to execute, bypassing the cryptographic signature requirement that is meant to prevent arbitrary command execution from untrusted templates.
**Affected Component**
The issue is in the template loader'…
CVE-2026-76802
NVD
MEDIUM
CVE-2026-79315
A reflected cross-site scripting vulnerability exists in x-ui 0.3.2. The management interface reflects the raw request URI into a client-side template binding expression used for sidebar menu highlighting. Server-side HTML entity escaping is ineffective in this context: the browser decodes the entit…
CWE: CWE-79
NVD
MEDIUM
CVE-2026-46650
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, isAcceptedUrl() in packages/renderer/htmlUtils.ts uses an unanchored regular expression for internal resource URLs, allowing a javascript: URL containing a matching 32-character …
CWE: CWE-79
NVD
MEDIUM
CVE-2026-91769
PHP's OpenSSL stream peer verification checks the certificate's subjectAltName entries first and, whenever no entry matches, falls back to the Common Name. RFC 6125 requires the CN to be ignored once the certificate presents any service identity, so a certificate carrying a non-matching DNS SAN was …
CWE: CWE-297
NVD
MEDIUM
CVE-2026-19775
The OpenStation — Desktop Windows, Dock & Virtual Desktops for WP Admin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible fo…
CWE: CWE-862
NVD
MEDIUM
CVE-2026-97724
A prototype pollution vulnerability in Software Mansion React Native Worklets before 0.12.2 allows an attacker-controlled object containing a __proto__ property to modify the prototype of an object created during serialization in clonePlainJSObject in packages/react-native-worklets/src/memory/serial…
CWE: CWE-1321
NVD
MEDIUM
CVE-2026-97325
A security flaw has been discovered in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected by this vulnerability is the function validOAuthClientFromCache of the file yudao-module-system/src/main/java/cn/iocoder/yudao/module/system/service/oauth2/OAuth2ClientServiceImpl.java of the component …
CWE: CWE-601
GitHub-GHSA
MEDIUM
social-auth-core has Login CSRF via Missing State Parameter in LoginRadius Backend
GHSA-x7qq-23vw-7pfg
pkg: social-auth-core
eco: pip
published: Sep 24, 2026
### Impact
The LoginRadius backend did not validate OAuth state during the authentication flow.
Applications using this backend were vulnerable to login CSRF. An attacker could cause a victim's browser session to complete authentication using an attacker-controlled LoginRadius token, making the vi…
CVE-2026-57177
NVD
MEDIUM
CVE-2026-77321
TREK is a collaborative travel planner. Prior to 3.3.0, the get_trip_summary tool in server/src/mcp/tools/trips.ts is registered for scoped OAuth MCP tokens without requiring trips:read and returns core trip summary data regardless of the delegated scopes. A token granted only an unrelated capabilit…
CWE: CWE-200, CWE-284, CWE-862
NVD
MEDIUM
CVE-2026-62286
Dozzle is a realtime log viewer for docker containers. Prior to 10.6.7, streamEvents in internal/web/events.go applies a restricted user's label filter to container lists but not to the container-stat and container-event channels returned by GET /api/events/stream. In a simple-auth deployment using …
CWE: CWE-200, CWE-285
NVD
MEDIUM
CVE-2026-57177
Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the LoginRadius backend did not validate OAuth state during the authentication flow. Applications using this backend were vulnerable to login CSRF. An attacker could cause a victim's browser session to comp…
CWE: CWE-352
GitHub-GHSA
MEDIUM
Dozzle label filters do not restrict container event and statistics streams
GHSA-xcw9-qmmf-vqxj
pkg: github.com/amir20/dozzle
eco: go
published: Sep 24, 2026
## Summary
Dozzle supports per-user label filters in `users.yml` that are documented as an access-control boundary: "Filters are used to restrict the containers that a user can see" and "the `guest` user can only see containers with the label `com.example.app` … useful for restricting access to s…
CVE-2026-62286
NVD
MEDIUM
CVE-2026-96892
A flaw has been found in Edimax BR-6428nC 1.16. The impacted element is the function websRedirect of the component goform Handler. Executing a manipulation of the argument submit-url can lead to open redirect. The attack may be launched remotely. The exploit has been published and may be used. Multi…
CWE: CWE-601
NVD
MEDIUM
CVE-2026-96764
A weakness has been identified in kvcache-ai mooncake up to 0.3.12/0.3.14-rc1. Impacted is the function MasterService::GetReplicaListByRegex of the component Regular Expression Handler. Executing a manipulation can lead to allocation of resources. The attack may be performed from remote. The exploit…
CWE: CWE-400, CWE-770
NVD
MEDIUM
CVE-2026-92529
GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to bypass admin-configured AI tool governance controls for wor…
CWE: CWE-863
NVD
MEDIUM
CVE-2026-55632
GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the internal pipeline structure API used for autocompletion while editing pipeline, template, environment, and user-preference configuration returns its users-and-roles mode to regular authenticated users without requiring an administrat…
CWE: CWE-863
GitHub-GHSA
MEDIUM
Hatchet DurableTask WorkerStatus gRPC resolves caller-supplied durable-task UUIDs via ListSatisfiedEntries with no tenant_id filter
GHSA-992g-9cr3-vm5x
pkg: github.com/hatchet-dev/hatchet
eco: go
published: Sep 22, 2026
# Cross-tenant disclosure risk on `DurableTask` bidi RPC
This is a low-severity, low-risk cross-tenant data exposure vuln caused by blindly accepting a durable task id, in addition to a list of node and branch ids that identify records in that task's event log, and returning them to the caller via …
CVE-2026-88978
GitHub-GHSA
MEDIUM
Unleash: A project member can reorder activation strategies belonging to any other project / environment (cross-project integrity write), bypassing project RBAC and the audit log
GHSA-5ffh-6f9q-5hhr
pkg: unleash-server
eco: npm
published: Sep 22, 2026
## Summary
Unleash scopes write permissions per project and per environment: a user with the `UPDATE_FEATURE_STRATEGY` permission on project `A` is supposed to be able to mutate activation strategies only within project `A`. The endpoint `POST /api/admin/projects/:projectId/features/:featureName/en…
CVE-2026-77425
NVD
MEDIUM
CVE-2026-95666
Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to limit the length of the post ID array accepted by the bulk reactions endpoint which allows an authenticated user to cause excessive database load via a crafted request to {{POST /api/v4/posts/ids/re…
CWE: CWE-770
NVD
MEDIUM
CVE-2026-18345
The WP User Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Connect::complete() function in versions up to, and including, 2.9.18. The function is registered on the admin_init hook (which fires for every authenticated user that…
CWE: CWE-862
NVD
MEDIUM
CVE-2026-12995
The Custom Field Template plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.7.8 via the edit_meta_value due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with contributor-level access a…
CWE: CWE-639
GitHub-GHSA
MEDIUM
k8saudit shipped rules do not detect privileged/sensitive settings on init or ephemeral containers
GHSA-jhjp-4c2q-xmx4
pkg: github.com/falcosecurity/plugins/plugins/k8saudit, github.com/falcosecurity/plugins/plugins/k8saudit-eks, github.com/falcosecurity/plugins/plugins/k8saudit-gke
eco: go
published: Sep 21, 2026
The `k8saudit` plugin's per-container fields (`ka.req.pod.containers.*`) and the shipped `k8s_audit_rules.yaml` evaluated only `requestObject.spec.containers`. Security-relevant settings on a pod's `initContainers` or `ephemeralContainers` were not inspected, so the shipped `Create Privileged Pod` r…
NVD
MEDIUM
CVE-2026-91164
Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. From 0.23.0 until 0.27.3, HTTP API token authentication resolves ConfigProvider::validate_api_token into RequestAuthorization::UserToken without enforcing the owning user's allowed_ip_ranges against the trusted client address in…
CWE: CWE-284, CWE-863
NVD
MEDIUM
CVE-2026-88978
Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.106.1, the WorkerStatus gRPC polling path in pkg/repository/durable_events.go passes caller-supplied durable task, node, and branch identifiers to ListSatisfiedEntries without a tenant fil…
CWE: CWE-639, CWE-863
NVD
MEDIUM
CVE-2026-52743
GoCD is a continuous deliver server. Prior to 26.1.0, the internal GoCD UI /jobStatus.json API does not validate that a requested server-assigned job ID belongs to the pipeline and stage named in the request. An authenticated user can guess job IDs and retrieve status for jobs in pipelines the user …
CWE: CWE-639, CWE-863
GitHub-GHSA
MEDIUM
social-auth-core has a Session Fixation issue
GHSA-vqg6-3fw6-j9jg
pkg: social-auth-core
eco: pip
published: Sep 24, 2026
### Impact
The partial-pipeline resume mechanism accepted `partial_token` as a bearer credential without binding it to the browser session that created it.
Applications using resumable partial pipeline steps could allow an attacker to start an authentication flow, obtain a valid partial token and …
CVE-2026-57179
NVD
MEDIUM
CVE-2026-57179
Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the partial-pipeline resume mechanism accepted `partial_token` as a bearer credential without binding it to the browser session that created it. Applications using resumable partial pipeline steps could all…
CWE: CWE-384
GitHub-GHSA
MEDIUM
podman quadlet install –replace does not fully replace the old file
GHSA-fx76-2j3w-2mx6
pkg: github.com/containers/podman/v5
eco: go
published: Sep 24, 2026
### Impact
When running `podman quadlet install –replace` to replace a Quadlet file, if the original Quadlet is larger than the new Quadlet, the file would not be truncated and content from the original would be preserved. There is no risk of information leakage as the user already had access to t…
CVE-2026-19730
GitHub-GHSA
MEDIUM
nginx ignition has TOTP Reuse During Validity Window
GHSA-hf33-q6cf-c66f
pkg: github.com/lucasdillmann/nginx-ignition
eco: go
published: Sep 21, 2026
### Summary
Any user that has enabled the OTP 2FA can have their TOTP reused during the standard 30 second validity window.
### Details
The https://github.com/pquerna/otp package [doesn't include](https://github.com/pquerna/otp/issues/61) checking for already used TOTPs within its the validity wind…
CVE-2026-61630
NVD
MEDIUM
CVE-2026-63373
draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.7, the OAuth callback handler in src/main/java/com/mxgraph/online/AbsAuth.java skips comparison of stateToken and cookieToken whenever IS_GAE is false, which affects self-hosted Docker and WAR deployments. An …
CWE: CWE-352
NVD
MEDIUM
CVE-2026-61630
nginx ignition is a user interface for the nginx web server. In versions 2.33.0 through 2.35.0, any user that has enabled the OTP 2FA can have their TOTP reused during the standard 30 second validity window. Version 2.35.1 patches the issue.
CWE: CWE-287
GitHub-GHSA
MEDIUM
Hatchet: SSRF via Unsigned UnsubscribeURL in SNS UnsubscribeConfirmation Handler
GHSA-fjwv-jf2v-j499
pkg: hatchet-dev/hatchet
eco: go
published: Sep 22, 2026
### Summary
The SNS `UnsubscribeConfirmation` handler in `internal/integrations/ingestors/sns/sns.go` makes an unvalidated
`http.Get()` call to `payload.UnsubscribeURL` without any URL restriction. Because `UnsubscribeURL` is intentionally
excluded from the `BuildSignature()` signed field list…
CVE-2026-61681
NVD
MEDIUM
CVE-2026-65127
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause exposure of sensitive system information due to uncleared debug information. A successful exploit of this vulnerability might lead to information disclosure.
CWE: CWE-1258
GitHub-GHSA
MEDIUM
Containerd has image-pull DoS via crafted OCI index graph amplification
GHSA-pg57-6jwg-q645
pkg: github.com/containerd/containerd/v2, github.com/containerd/containerd, github.com/containerd/containerd/v2
eco: go
published: Sep 25, 2026
### Impact
A vulnerability exists in containerd's image pull handlers where a crafted OCI image index containing deeply nested or heavily fanned-out descriptor graphs can cause unbounded CPU and memory consumption. During the `PullImage` operation, the recursive traversal and processing of child de…
CVE-2026-53493
GitHub-GHSA
MEDIUM
hpack: Unbounded variable integer decoding can cause run-away computation on malformed input
GHSA-8v8h-hg4w-mvq2
pkg: hpack
eco: pip
published: Sep 24, 2026
### Impact
Users of the python-hyper/hpack library, most commonly used as downstream dependency of the python-hyper/h2 library (an HTTP/2 client and server implementation). Unbounded variable integer decoding can cause run-away computation on malformed input leading to O(n^2) runtime, effectively b…
CVE-2026-59980
GitHub-GHSA
MEDIUM
yara-x: Unvalidated deserialization in safe `Rules::deserialize` allows memory corruption and UB
GHSA-2jx3-ff3v-j7jj
pkg: yara-x
eco: rust
published: Sep 24, 2026
> [!NOTE]
> This finding was identified during an agentic unsafe Rust code review performed by Gemini AI, followed by human review and verification.
## The Issue
The crate exports a public safe API [`Rules::deserialize`](https://github.com/VirusTotal/yara-x/blob/5bd1f35db783679c90a3ea1a66bd15fe4e…
GitHub-GHSA
MEDIUM
Mesop: Unauthenticated ANSI Escape Sequence Injection in CSP Reporting Endpoint
GHSA-g7f6-rxc4-qhph
pkg: mesop
eco: pip
published: Sep 23, 2026
### Summary
The `/__csp__` endpoint accepts unauthenticated JSON reports and logs user-controlled values directly to stdout using `print()` without escaping control characters.
A remote attacker can include ANSI/VT100 escape sequences in fields such as `blocked-uri` or `document-uri`. When the log…
CVE-2026-93421
GitHub-GHSA
MEDIUM
Zapros has an Unbounded Content-Encoding decompression chain that allows denial of service
GHSA-5vjj-2r48-q622
pkg: zapros
eco: pip
published: Sep 23, 2026
### Impact
**Who is impacted**:
– Any application using Zapros to make HTTP requests to untrusted servers
– Applications that follow redirects to attacker-controlled hosts
**Attack vector**:
– A malicious HTTP server returns a response with many chained content encodings. When the client att…
CVE-2026-61541
GitHub-GHSA
MEDIUM
Traefik: BasicAuth singleflight coalescing reintroduces an unauthenticated username-enumeration timing oracle
GHSA-8fcf-v89g-xpg6
pkg: Traefik
eco: go
published: Sep 22, 2026
## Summary
Traefik's BasicAuth middleware coalesces concurrent credential checks through a `singleflight.Group` to avoid hashing the same password many times at once. Since v3.6.11 the deduplication key was built from the submitted password plus the stored secret, so it depended on server state: a …
CVE-2026-88010
GitHub-GHSA
MEDIUM
Tinyauth: User enumeration attack by timing oracle
GHSA-456h-ww26-f758
pkg: github.com/tinyauthapp/tinyauth
eco: go
published: Sep 22, 2026
### Summary
It's possible to enumerate users through a timing oracle. In other words: I can easily check if a username exists or not by observing the timing differences between logins.
### PoC
Setup a tinyauth server with a local user. It can be over the network.
Try to log in with the local user,…
CVE-2026-77582
GitHub-GHSA
MEDIUM
OpenBao Skips Stricter Deny Policy for LIST operations
GHSA-xp3c-3jw3-4vcr
pkg: github.com/openbao/openbao, github.com/openbao/openbao
eco: go
published: Sep 22, 2026
## Impact
When a policy operator has written `capabilities = ["deny"]` on a path with a trailing wildcard but allowed a broader list operation (e.g., a `deny` on `secrets/metadata/restricted/*` but allowed `list` on `secrets/metadata/*`), OpenBao would incorrectly allow the operation. This did not …
CVE-2026-63131
GitHub-GHSA
MEDIUM
Unleash: Clone-feature lets a user copy a feature from a project they cannot read
GHSA-8xcj-9hfr-fh9j
pkg: unleash-server
eco: npm
published: Sep 22, 2026
### Summary
The clone-feature endpoint supports copying features across projects, but it does not verify that the caller can access the source project. A user with _create_ permissions in one project can clone a feature from another project they cannot read and then inspect the copied configuration…
CVE-2026-76910
GitHub-GHSA
MEDIUM
Novu: Stored XSS in In-App Inbox via notification redirect.url javascript: scheme
GHSA-8gr3-5j6f-25gp
pkg: @novu/js
eco: npm
published: Sep 22, 2026
## Summary
The `@novu/js` In-App Inbox renderer passes a notification's `redirect.url` to `window.open()` with no URL-scheme validation. The value originates from a notification's call-to-action and is delivered to the recipient verbatim.
An authenticated organization member (or any holder of the …
CVE-2026-75510
GitHub-GHSA
MEDIUM
mppx: Gas Draining with access list
GHSA-vc9j-9wph-qghj
pkg: mppx
eco: npm
published: Sep 22, 2026
### Details
When the server acts as the fee_payer, `mppx` 0.6.27 copies the client-supplied EIP-2930 access list verbatim into the cosigned fee-payer transaction. The TypeScript SDK's fee-payer cosigning path accepts any `access_list` the client includes in the 0x78 `FeePayerEnvelope` without inspec…
CVE-2026-63628
GitHub-GHSA
MEDIUM
mppx: Gas Draining with padding
GHSA-727h-3vm5-qwq6
pkg: mppx
eco: npm
published: Sep 22, 2026
### Details
When the server acts as the fee_payer, `mppx` 0.6.27 validates calldata using viem's `decodeFunctionData`, which is lenient about trailing bytes. The `FeePayerPolicy` caps `gas_limit` (≤ 2 M) and `max_fee_per_gas` (≤ 100 Gwei) but does **not** check calldata length.
Tempo uses legac…
CVE-2026-63627