Zeros312
CVE-2026-4110 | CVE-2026-4110 Ultimate WooCommerce Auction Pro <= 2.4.5 - Reflected XSS via uwa_auctions_bids_list | The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | NONE | 0.00 | NONE | 2026-06-22 06:00:01+03:00 | 2026-06-22 06:00:01+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-4110'] | ['CVE-2026-4110'] | 0ed32423c14088d5da7248436d8ab4f542cb8441e19d960db4160a7647d0e2b3 | 2026-06-23 15:06:55.636806+03:00 | 2026-06-23 15:06:55.636806+03:00 | {'id': 'CVELIST:CVE-2026-4110', 'cvss': {'score': 0.0, 'source': 'NONE', 'vector': 'NONE', 'version': 'NONE', 'severity': 'NONE'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-4110', 'type': 'cvelist', 'title': 'CVE-2026-4110 Ultimate WooCommerce Auction Pro <= 2.4.5 - Reflected XSS via uwa_auctions_bids_list', 'cvelist': ['CVE-2026-4110'], 'assigned': '2026-03-13T10:56:13', 'lastseen': '2026-06-22T17:20:51', 'modified': '2026-06-22T06:00:01', 'published': '2026-06-22T06:00:01', 'description': 'The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:FF547C51-1942-4CD2-B1C0-A95795119CB1']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-4110']}, {'type': 'cve', 'idList': ['CVE-2026-4110']}, {'type': 'euvd', 'idList': ['EUVD-2026-38211']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-4110']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51276']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-4110']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-4259 | CVE-2026-4259 Ultimate WooCommerce Auction Pro <= 2.4.5 - Reflected XSS via uwa_manage_auctions | The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | NONE | 0.00 | NONE | 2026-06-22 06:00:01+03:00 | 2026-06-22 06:00:01+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-4259'] | ['CVE-2026-4259'] | dca7319f57b5b9890bc3fca86fa875e03194e09a4f3575a190c044028bd3c835 | 2026-06-23 15:06:55.636806+03:00 | 2026-06-23 15:06:55.636806+03:00 | {'id': 'CVELIST:CVE-2026-4259', 'cvss': {'score': 0.0, 'source': 'NONE', 'vector': 'NONE', 'version': 'NONE', 'severity': 'NONE'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-4259', 'type': 'cvelist', 'title': 'CVE-2026-4259 Ultimate WooCommerce Auction Pro <= 2.4.5 - Reflected XSS via uwa_manage_auctions', 'cvelist': ['CVE-2026-4259'], 'assigned': '2026-03-16T10:30:53', 'lastseen': '2026-06-22T13:45:12', 'modified': '2026-06-22T06:00:01', 'published': '2026-06-22T06:00:01', 'description': 'The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:F1B11E66-1334-43A8-9AEB-537B6646E14E']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-4259']}, {'type': 'cve', 'idList': ['CVE-2026-4259']}, {'type': 'euvd', 'idList': ['EUVD-2026-38212']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-4259']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51277']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-4259']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-6645 | CVE-2026-6645 Insecure Search Path Vulnerability in PaperCut Print Deploy Client for Windows | An insecure process execution vulnerability exists in the pc-printer-updater.exe component of the PaperCut Print Deploy Client for Windows. The application, which typically operates with high-level system privileges, attempts to perform an internal validation check by invoking a secondary system utility using an unqualified file reference.
Because the application does not specify an absolute path to this utility, it relies on the operating system's default search order to locate the executable. Under specific conditions, a local attacker with the ability to modify directories within the system's search path could plant a malicious binary that mimics the expected utility. This could result in the malicious code being executed with SYSTEM privileges, leading to a full compromise of the affected host. | HIGH | 7.30 | CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/SC:H/VI:H/SI:H/VA:H/SA:H | 2026-06-22 03:24:06+03:00 | 2026-06-22 03:24:06+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-6645'] | ['CVE-2026-6645'] | b1dea75c081b954e58111411035d17dc31cf79cbb0b0783d544b49485c8466ba | 2026-06-23 15:06:55.636806+03:00 | 2026-06-23 15:06:55.636806+03:00 | {'id': 'CVELIST:CVE-2026-6645', 'cvss': {'score': 7.3, 'source': 'papercut', 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/SC:H/VI:H/SI:H/VA:H/SA:H', 'version': '4.0', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-6645', 'type': 'cvelist', 'title': 'CVE-2026-6645 Insecure Search Path Vulnerability in PaperCut Print Deploy Client for Windows', 'cvelist': ['CVE-2026-6645'], 'assigned': '2026-04-20T04:12:52', 'lastseen': '2026-06-23T05:14:40', 'modified': '2026-06-22T03:24:06', 'published': '2026-06-22T03:24:06', 'description': "An insecure process execution vulnerability exists in the pc-printer-updater.exe component of the PaperCut Print Deploy Client for Windows. The application, which typically operates with high-level system privileges, attempts to perform an internal validation check by invoking a secondary system utility using an unqualified file reference.\n\n\n\nBecause the application does not specify an absolute path to this utility, it relies on the operating system's default search order to locate the executable. Under specific conditions, a local attacker with the ability to modify directories within the system's search path could plant a malicious binary that mimics the expected utility. This could result in the malicious code being executed with SYSTEM privileges, leading to a full compromise of the affected host.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:93506F19-5C22-422D-925E-9E653F6DBABD']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-6645']}, {'type': 'cve', 'idList': ['CVE-2026-6645']}, {'type': 'euvd', 'idList': ['EUVD-2026-38209']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-6645']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51274']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-6645']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-7859 | CVE-2026-7859 Motors Car Dealership & Classified Listings < 1.4.110 - Unauthenticated Post-Meta Write via stm_ajax_add_a_car_media | The Motors WordPress plugin before 1.4.110 does not have proper authorisation and CSRF checks on one of its AJAX actions, allowing unauthenticated attackers to modify arbitrary post metadata, such as the gallery, featured image and, on WooCommerce sites, product prices. | NONE | 0.00 | NONE | 2026-06-22 06:00:02+03:00 | 2026-06-22 06:00:02+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-7859'] | ['CVE-2026-7859'] | 24ffdfaf1853e912f4f2b5a882dd7616280b4707ef5dfd180f27aaab7e8f7985 | 2026-06-23 15:06:55.636806+03:00 | 2026-06-23 15:06:55.636806+03:00 | {'id': 'CVELIST:CVE-2026-7859', 'cvss': {'score': 0.0, 'source': 'NONE', 'vector': 'NONE', 'version': 'NONE', 'severity': 'NONE'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-7859', 'type': 'cvelist', 'title': 'CVE-2026-7859 Motors Car Dealership & Classified Listings < 1.4.110 - Unauthenticated Post-Meta Write via stm_ajax_add_a_car_media', 'cvelist': ['CVE-2026-7859'], 'assigned': '2026-05-05T11:51:07', 'lastseen': '2026-06-22T13:45:09', 'modified': '2026-06-22T06:00:02', 'published': '2026-06-22T06:00:02', 'description': 'The Motors WordPress plugin before 1.4.110 does not have proper authorisation and CSRF checks on one of its AJAX actions, allowing unauthenticated attackers to modify arbitrary post metadata, such as the gallery, featured image and, on WooCommerce sites, product prices.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:60E39E17-A3B8-45B0-9E72-797DD229D4A3']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-7859']}, {'type': 'cve', 'idList': ['CVE-2026-7859']}, {'type': 'euvd', 'idList': ['EUVD-2026-38214']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-7859']}, {'type': 'patchstack', 'idList': ['PATCHSTACK:F80C1FFB06324183D30A07CE934BAED4']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51279']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-7859']}]}}, 'bulletinFamily': 'cve'} |
CVE-2025-62198 | CVE-2025-62198 Apache Atlas: Stored XSS in Create Entity page | An authenticated user can perform XSS.
This issue affects Apache Atlas versions 2.4.0 and earlier.
Users are recommended to upgrade to version 2.5.0, which fixes the issue. | NONE | 0.00 | NONE | 2026-06-22 07:47:11+03:00 | 2026-06-22 07:47:11+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2025-62198'] | ['CVE-2025-62198'] | f69d40845f3491a0de5cb9e12f12551bafdf06bac0cabe31bba79ab48d70f2da | 2026-06-23 15:06:55.636806+03:00 | 2026-06-23 15:06:55.636806+03:00 | {'id': 'CVELIST:CVE-2025-62198', 'cvss': {'score': 0.0, 'source': 'NONE', 'vector': 'NONE', 'version': 'NONE', 'severity': 'NONE'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2025-62198', 'type': 'cvelist', 'title': 'CVE-2025-62198 Apache Atlas: Stored XSS in Create Entity page', 'cvelist': ['CVE-2025-62198'], 'assigned': '2025-10-08T19:44:39', 'lastseen': '2026-06-22T17:20:57', 'modified': '2026-06-22T07:47:11', 'published': '2026-06-22T07:47:11', 'description': 'An authenticated user can perform XSS.\n\nThis issue affects Apache Atlas versions 2.4.0 and earlier.\n\nUsers are recommended to upgrade to version 2.5.0, which fixes the issue.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:F6971516-4396-4C18-AE10-94061C319005']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2025-62198']}, {'type': 'cve', 'idList': ['CVE-2025-62198']}, {'type': 'euvd', 'idList': ['EUVD-2025-210296']}, {'type': 'nvd', 'idList': ['NVD:CVE-2025-62198']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51187']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2025-62198']}]}}, 'bulletinFamily': 'cve'} |
CVE-2025-66336 | CVE-2025-66336 Apache Doris MCP Server: SQL injection leading the authentication bypass | Apache Doris MCP Server contains a SQL injection vulnerability in a metadata query path. A user-controlled database name is directly interpolated into a SQL query, and the query is executed without passing the caller's authorization context. This may allow an authenticated attacker, or an anonymous attacker if authentication is disabled, to bypass SQL security validation and access metadata outside the intended database scope.
Affected users are recommended to upgrade to Doris version 0.6.1 or later, which fixes the issue. | NONE | 0.00 | NONE | 2026-06-22 06:55:17+03:00 | 2026-06-22 06:55:17+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2025-66336'] | ['CVE-2025-66336'] | c42b51653105bb7d2b1a046c301dd0b302ca64377e4c3c2e1417725d3651fbc7 | 2026-06-23 15:06:55.636806+03:00 | 2026-06-23 15:06:55.636806+03:00 | {'id': 'CVELIST:CVE-2025-66336', 'cvss': {'score': 0.0, 'source': 'NONE', 'vector': 'NONE', 'version': 'NONE', 'severity': 'NONE'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2025-66336', 'type': 'cvelist', 'title': 'CVE-2025-66336 Apache Doris MCP Server: SQL injection leading the authentication bypass', 'cvelist': ['CVE-2025-66336'], 'assigned': '2025-11-27T03:24:32', 'lastseen': '2026-06-22T17:20:56', 'modified': '2026-06-22T06:55:17', 'published': '2026-06-22T06:55:17', 'description': "Apache Doris MCP Server contains a SQL injection vulnerability in a metadata query path. A user-controlled database name is directly interpolated into a SQL query, and the query is executed without passing the caller's authorization context. This may allow an authenticated attacker, or an anonymous attacker if authentication is disabled, to bypass SQL security validation and access metadata outside the intended database scope.\n\nAffected users are recommended to upgrade to Doris version 0.6.1 or later, which fixes the issue.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:73BEB738-08D7-4878-BA5C-D61F9747B002']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2025-66336']}, {'type': 'cve', 'idList': ['CVE-2025-66336']}, {'type': 'euvd', 'idList': ['EUVD-2025-210295']}, {'type': 'nvd', 'idList': ['NVD:CVE-2025-66336']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51281']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2025-66336']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-10530 | CVE-2026-10530 Pie Register < 3.8.4.10 - Unauthenticated Email Verification Bypass via Predictable Token | The Pie Register WordPress plugin before 3.8.4.10 does not use sufficiently random values when generating its account verification tokens, allowing unauthenticated attackers to predict a valid token and activate an account without access to the associated email inbox. | NONE | 0.00 | NONE | 2026-06-22 06:00:01+03:00 | 2026-06-22 06:00:01+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-10530'] | ['CVE-2026-10530'] | e0d92375328c31ac7fdba17d4dc415b7c6f84c8ded4fa9d7934b69e83ea5b397 | 2026-06-23 15:06:55.636806+03:00 | 2026-06-23 15:06:55.636806+03:00 | {'id': 'CVELIST:CVE-2026-10530', 'cvss': {'score': 0.0, 'source': 'NONE', 'vector': 'NONE', 'version': 'NONE', 'severity': 'NONE'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-10530', 'type': 'cvelist', 'title': 'CVE-2026-10530 Pie Register < 3.8.4.10 - Unauthenticated Email Verification Bypass via Predictable Token', 'cvelist': ['CVE-2026-10530'], 'assigned': '2026-06-01T11:10:04', 'lastseen': '2026-06-22T17:20:56', 'modified': '2026-06-22T06:00:01', 'published': '2026-06-22T06:00:01', 'description': 'The Pie Register WordPress plugin before 3.8.4.10 does not use sufficiently random values when generating its account verification tokens, allowing unauthenticated attackers to predict a valid token and activate an account without access to the associated email inbox.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:45ECB853-3DC9-4F38-9CEA-C26AB8C2F318']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-10530']}, {'type': 'cve', 'idList': ['CVE-2026-10530']}, {'type': 'euvd', 'idList': ['EUVD-2026-38210']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-10530']}, {'type': 'patchstack', 'idList': ['PATCHSTACK:4DFA2728274A1C0089618E2656A115DC']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51275']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-10530']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-6858 | CVE-2026-6858 Transbank Webpay < 1.14.0 - Unauthenticated Stored XSS | The Transbank Webpay WordPress plugin before 1.14.0 does not sanitize and escape logs to be displayed, allowing unauthenticated users to perform Stored XSS attacks against logged in administrator | NONE | 0.00 | NONE | 2026-06-22 06:00:02+03:00 | 2026-06-22 06:00:02+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-6858'] | ['CVE-2026-6858'] | a6c757e7c2f8518b8eae61e3832f7357cf856320e437dafbb1abbf16764b8fb7 | 2026-06-23 15:06:55.636806+03:00 | 2026-06-23 15:06:55.636806+03:00 | {'id': 'CVELIST:CVE-2026-6858', 'cvss': {'score': 0.0, 'source': 'NONE', 'vector': 'NONE', 'version': 'NONE', 'severity': 'NONE'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-6858', 'type': 'cvelist', 'title': 'CVE-2026-6858 Transbank Webpay < 1.14.0 - Unauthenticated Stored XSS', 'cvelist': ['CVE-2026-6858'], 'assigned': '2026-04-22T12:53:03', 'lastseen': '2026-06-22T13:45:09', 'modified': '2026-06-22T06:00:02', 'published': '2026-06-22T06:00:02', 'description': 'The Transbank Webpay WordPress plugin before 1.14.0 does not sanitize and escape logs to be displayed, allowing unauthenticated users to perform Stored XSS attacks against logged in administrator', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:3677D938-A0A6-4D39-88A9-04A2BD052CF4']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-6858']}, {'type': 'cve', 'idList': ['CVE-2026-6858']}, {'type': 'euvd', 'idList': ['EUVD-2026-38213']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-6858']}, {'type': 'patchstack', 'idList': ['PATCHSTACK:28EC951852509AE923742B4B90A335A9']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51278']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-6858']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-11745 | CVE-2026-11745 | A vulnerability has been identified in centraldogma-server-mirror-git versions prior to 0.84.0, where the Git mirror SSH client does not verify remote host keys for git+ssh:// connections, allowing an on-path attacker to perform man-in-the-middle attacks and compromise mirrored repositories. | HIGH | 8.80 | CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/SC:H/VI:H/SI:H/VA:N/SA:L | 2026-06-22 02:33:08+03:00 | 2026-06-22 02:33:08+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-11745'] | ['CVE-2026-11745'] | 50ba2808d6505112f9c55e012e167e86a1ec490d7eadf5d968bdcbd35fb6e906 | 2026-06-23 15:06:55.636806+03:00 | 2026-06-23 15:06:55.636806+03:00 | {'id': 'CVELIST:CVE-2026-11745', 'cvss': {'score': 8.8, 'source': 'ly-corporation', 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/SC:H/VI:H/SI:H/VA:N/SA:L', 'version': '4.0', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-11745', 'type': 'cvelist', 'title': 'CVE-2026-11745', 'cvelist': ['CVE-2026-11745'], 'assigned': '2026-06-09T06:46:10', 'lastseen': '2026-06-22T17:20:55', 'modified': '2026-06-22T02:33:08', 'published': '2026-06-22T02:33:08', 'description': 'A vulnerability has been identified in centraldogma-server-mirror-git versions prior to 0.84.0, where the Git mirror SSH client does not verify remote host keys for git+ssh:// connections, allowing an on-path attacker to perform man-in-the-middle attacks and compromise mirrored repositories.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:C1D827CC-671F-4390-8B70-34C72953B8EF']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-11745']}, {'type': 'cve', 'idList': ['CVE-2026-11745']}, {'type': 'euvd', 'idList': ['EUVD-2026-38206']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-11745']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51270']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-11745']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-11746 | CVE-2026-11746 | A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication.secret causes the server to silently fall back to a hard-coded, publicly known secret. This default credential authenticates the embedded ZooKeeper ensemble, allowing an attacker with network access to read the full replication log or join the quorum and execute arbitrary replicated commands across the cluster. | CRITICAL | 9.40 | CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/SC:H/VI:H/SI:H/VA:H/SA:H | 2026-06-22 02:35:51+03:00 | 2026-06-22 02:35:51+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-11746'] | ['CVE-2026-11746'] | 2368dc6d209bd9044bb5db43250efd5598b2513809ec1794c5f9da58c13257b4 | 2026-06-23 15:06:55.636806+03:00 | 2026-06-23 15:06:55.636806+03:00 | {'id': 'CVELIST:CVE-2026-11746', 'cvss': {'score': 9.4, 'source': 'ly-corporation', 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/SC:H/VI:H/SI:H/VA:H/SA:H', 'version': '4.0', 'severity': 'CRITICAL'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-11746', 'type': 'cvelist', 'title': 'CVE-2026-11746', 'cvelist': ['CVE-2026-11746'], 'assigned': '2026-06-09T06:48:47', 'lastseen': '2026-06-22T17:20:55', 'modified': '2026-06-22T02:35:51', 'published': '2026-06-22T02:35:51', 'description': 'A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication.secret causes the server to silently fall back to a hard-coded, publicly known secret. This default credential authenticates the embedded ZooKeeper ensemble, allowing an attacker with network access to read the full replication log or join the quorum and execute arbitrary replicated commands across the cluster.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:F4C234B1-88EE-4B98-970E-15B83EA668F6']}, {'type': 'cve', 'idList': ['CVE-2026-11746']}, {'type': 'euvd', 'idList': ['EUVD-2026-38207']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-11746']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51271']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-11746']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-11748 | CVE-2026-11748 | A vulnerability has been identified in centraldogma-server-auth-shiro versions prior to 0.84.0, where the SearchFirstActiveDirectoryRealm substitutes the login username into an LDAP search filter without neutralizing LDAP filter metacharacters, allowing an unauthenticated attacker to manipulate the filter to cause authentication confusion and enumerate the directory structure. | MEDIUM | 6.90 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/SC:L/VI:L/SI:N/VA:N/SA:N | 2026-06-22 02:37:35+03:00 | 2026-06-22 02:37:35+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-11748'] | ['CVE-2026-11748'] | cf8b781e95ce5a34f1600c391139d9ab898deafbf421113f5603d6adda14654a | 2026-06-23 15:06:55.636806+03:00 | 2026-06-23 15:06:55.636806+03:00 | {'id': 'CVELIST:CVE-2026-11748', 'cvss': {'score': 6.9, 'source': 'ly-corporation', 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/SC:L/VI:L/SI:N/VA:N/SA:N', 'version': '4.0', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-11748', 'type': 'cvelist', 'title': 'CVE-2026-11748', 'cvelist': ['CVE-2026-11748'], 'assigned': '2026-06-09T06:50:03', 'lastseen': '2026-06-22T17:20:55', 'modified': '2026-06-22T02:37:35', 'published': '2026-06-22T02:37:35', 'description': 'A vulnerability has been identified in centraldogma-server-auth-shiro versions prior to 0.84.0, where the SearchFirstActiveDirectoryRealm substitutes the login username into an LDAP search filter without neutralizing LDAP filter metacharacters, allowing an unauthenticated attacker to manipulate the filter to cause authentication confusion and enumerate the directory structure.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:F06A0281-2B2D-4735-BEF5-DB4524CE43D7']}, {'type': 'cve', 'idList': ['CVE-2026-11748']}, {'type': 'euvd', 'idList': ['EUVD-2026-38208']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-11748']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51272']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-11748']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-44911 | CVE-2026-44911 Apache NiFi: Incorrect Authorization for Configuration Verification Requests | Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 through 2.9.0 allows clients with read access to submit proposed configuration properties. The proposed properties override current configuration, enabling users with read access to invoke predefined verification methods with alternative settings. Apache NiFi installations that do not implement different levels of authorization for viewing and modifying component configuration are not subject to this vulnerability. Upgrading to Apache NiFi 2.10.0 is the recommended mitigation, requiring write access to submit configuration verification requests. | LOW | 2.30 | CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/SC:L/VI:L/SI:L/VA:L/SA:L/AU:Y/U:Amber/R:U/V:C/RE:L | 2026-06-22 07:37:10+03:00 | 2026-06-22 07:37:10+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-44911'] | ['CVE-2026-44911'] | 8846f1893cf5ba6191b0e8d7eb12fba1c112cdec966803bec05d0cd0d71f83fc | 2026-06-23 15:06:55.636806+03:00 | 2026-06-23 15:06:55.636806+03:00 | {'id': 'CVELIST:CVE-2026-44911', 'cvss': {'score': 2.3, 'source': 'apache', 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/SC:L/VI:L/SI:L/VA:L/SA:L/AU:Y/U:Amber/R:U/V:C/RE:L', 'version': '4.0', 'severity': 'LOW'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-44911', 'type': 'cvelist', 'title': 'CVE-2026-44911 Apache NiFi: Incorrect Authorization for Configuration Verification Requests', 'cvelist': ['CVE-2026-44911'], 'assigned': '2026-05-08T03:42:57', 'lastseen': '2026-06-22T13:45:11', 'modified': '2026-06-22T07:37:10', 'published': '2026-06-22T07:37:10', 'description': 'Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 through 2.9.0 allows clients with read access to submit proposed configuration properties. The proposed properties override current configuration, enabling users with read access to invoke predefined verification methods with alternative settings. Apache NiFi installations that do not implement different levels of authorization for viewing and modifying component configuration are not subject to this vulnerability. Upgrading to Apache NiFi 2.10.0 is the recommended mitigation, requiring write access to submit configuration verification requests.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:2D3B3BB7-1A17-4912-BB66-1C540FE3E6B2']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-44911']}, {'type': 'cve', 'idList': ['CVE-2026-44911']}, {'type': 'euvd', 'idList': ['EUVD-2026-38218']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-44911']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51282']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-44911']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-44913 | CVE-2026-44913 Apache NiFi: Improper Escaping of Table Names in CaptureChangeMySQL | Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache NiFi 1.2.0 through 2.9.0 allows for injecting SQL commands using crafted naming. Manual quoted boundaries added in Apache NiFi 1.8.0 narrowed the scope of potential injection options, but did not cover additional strategies. Apache NiFi installations that do not use the CaptureChangeMySQL Processor are not subject to this vulnerability. Upgrading to Apache NiFi 2.10.0 is the recommended mitigation, which incorporates more robust identifier escaping. | MEDIUM | 5.20 | CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:N/SC:H/VI:N/SI:H/VA:N/SA:H/S:P/AU:Y/U:Clear/R:U/V:C/RE:L | 2026-06-22 07:36:40+03:00 | 2026-06-22 07:36:40+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-44913'] | ['CVE-2026-44913'] | 8737cc68e8882d96495c854dd4f297e39454e9fb618fa20b0200a8f8ec7c728a | 2026-06-23 15:06:55.636806+03:00 | 2026-06-23 15:06:55.636806+03:00 | {'id': 'CVELIST:CVE-2026-44913', 'cvss': {'score': 5.2, 'source': 'apache', 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:N/SC:H/VI:N/SI:H/VA:N/SA:H/S:P/AU:Y/U:Clear/R:U/V:C/RE:L', 'version': '4.0', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-44913', 'type': 'cvelist', 'title': 'CVE-2026-44913 Apache NiFi: Improper Escaping of Table Names in CaptureChangeMySQL', 'cvelist': ['CVE-2026-44913'], 'assigned': '2026-05-08T04:15:35', 'lastseen': '2026-06-22T13:45:11', 'modified': '2026-06-22T07:36:40', 'published': '2026-06-22T07:36:40', 'description': 'Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache NiFi 1.2.0 through 2.9.0 allows for injecting SQL commands using crafted naming. Manual quoted boundaries added in Apache NiFi 1.8.0 narrowed the scope of potential injection options, but did not cover additional strategies. Apache NiFi installations that do not use the CaptureChangeMySQL Processor are not subject to this vulnerability. Upgrading to Apache NiFi 2.10.0 is the recommended mitigation, which incorporates more robust identifier escaping.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:55F99D7B-D558-4A7D-AC4D-155EC90FF125']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-44913']}, {'type': 'cve', 'idList': ['CVE-2026-44913']}, {'type': 'euvd', 'idList': ['EUVD-2026-38217']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-44913']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51283']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-44913']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-44914 | CVE-2026-44914 Apache NiFi: Missing Authorization of Restricted Permissions when Replacing Flow Contents | Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additional privileges required, but framework authorization did not check restricted status when handling requests to replace Process Groups. The missing authorization permits a user with general write access to add components with Restricted status. Apache NiFi installations that do not implement specific authorization for Restricted components are not subject to this vulnerability because the framework enforces write permissions as the security boundary. Upgrading to Apache NiFi 2.9.0 is the recommended mitigation, which removes the implementation of Restricted status authorization from the framework. | HIGH | 7.50 | CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/SC:L/VI:H/SI:L/VA:H/SA:L/S:P/AU:Y/U:Clear/R:U/V:C/RE:L | 2026-06-22 07:38:01+03:00 | 2026-06-22 07:38:01+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-44914'] | ['CVE-2026-44914'] | 39a30011c50b5da44a67996ec8385a0b5a6e08c6da5854df8f04a682e3cb63d3 | 2026-06-23 15:06:55.636806+03:00 | 2026-06-23 15:06:55.636806+03:00 | {'id': 'CVELIST:CVE-2026-44914', 'cvss': {'score': 7.5, 'source': 'apache', 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/SC:L/VI:H/SI:L/VA:H/SA:L/S:P/AU:Y/U:Clear/R:U/V:C/RE:L', 'version': '4.0', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-44914', 'type': 'cvelist', 'title': 'CVE-2026-44914 Apache NiFi: Missing Authorization of Restricted Permissions when Replacing Flow Contents', 'cvelist': ['CVE-2026-44914'], 'assigned': '2026-05-08T04:30:00', 'lastseen': '2026-06-22T13:45:12', 'modified': '2026-06-22T07:38:01', 'published': '2026-06-22T07:38:01', 'description': 'Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additional privileges required, but framework authorization did not check restricted status when handling requests to replace Process Groups. The missing authorization permits a user with general write access to add components with Restricted status. Apache NiFi installations that do not implement specific authorization for Restricted components are not subject to this vulnerability because the framework enforces write permissions as the security boundary. Upgrading to Apache NiFi 2.9.0 is the recommended mitigation, which removes the implementation of Restricted status authorization from the framework.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:B711E1E7-B5E3-4CAE-9A8B-EB8224EE005E']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-44914']}, {'type': 'cve', 'idList': ['CVE-2026-44914']}, {'type': 'euvd', 'idList': ['EUVD-2026-38219']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-44914']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51284']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-44914']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-54665 | CVE-2026-54665 Apache NiFi: Missing Validation for Proxy Host Headers | Apache NiFi 0.0.1 through 2.9.0 support building qualified URLs from one of several HTTP request headers that provide an alternative to the standard Host header without validating the values provided. Apache NiFi 1.6.0 introduced a configurable application property to restrict values provided in the HTTP Host header, but did not apply the validation to alternative Proxy and Forwarded headers. The absence of proxy host header validation allowed a client to instruct Apache NiFi web services to construct invalid qualified URLs for redirection or data references. Upgrading to Apache NiFi 2.10.0 is the recommended mitigation, which implements validation for the X-ProxyHost and X-Forwarded-Host HTTP request headers based on the nifi.web.proxy.host property. Enabling header validation requires configuring the application with HTTPS. Reverse proxy servers in front of Apache NiFi are responsible for filtering input request headers and providing allowed values to the application. | MEDIUM | 6.30 | CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/SC:N/VI:L/SI:L/VA:N/SA:N/S:N/AU:Y/U:Green/R:A/V:D/RE:L | 2026-06-22 07:34:13+03:00 | 2026-06-22 07:34:13+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-54665'] | ['CVE-2026-54665'] | 9d90d6808684a8d9910384504693a9661c1634ffb0e62901aea7bb527e0ccfb0 | 2026-06-23 15:06:55.636806+03:00 | 2026-06-23 15:06:55.636806+03:00 | {'id': 'CVELIST:CVE-2026-54665', 'cvss': {'score': 6.3, 'source': 'apache', 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/SC:N/VI:L/SI:L/VA:N/SA:N/S:N/AU:Y/U:Green/R:A/V:D/RE:L', 'version': '4.0', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-54665', 'type': 'cvelist', 'title': 'CVE-2026-54665 Apache NiFi: Missing Validation for Proxy Host Headers', 'cvelist': ['CVE-2026-54665'], 'assigned': '2026-06-15T20:22:59', 'lastseen': '2026-06-22T17:20:44', 'modified': '2026-06-22T07:34:13', 'published': '2026-06-22T07:34:13', 'description': 'Apache NiFi 0.0.1 through 2.9.0 support building qualified URLs from one of several HTTP request headers that provide an alternative to the standard Host header without validating the values provided. Apache NiFi 1.6.0 introduced a configurable application property to restrict values provided in the HTTP Host header, but did not apply the validation to alternative Proxy and Forwarded headers. The absence of proxy host header validation allowed a client to instruct Apache NiFi web services to construct invalid qualified URLs for redirection or data references. Upgrading to Apache NiFi 2.10.0 is the recommended mitigation, which implements validation for the X-ProxyHost and X-Forwarded-Host HTTP request headers based on the nifi.web.proxy.host property. Enabling header validation requires configuring the application with HTTPS. Reverse proxy servers in front of Apache NiFi are responsible for filtering input request headers and providing allowed values to the application.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:7DAA55DD-2A66-4747-9AC5-E2FF48A55015']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-54665']}, {'type': 'cve', 'idList': ['CVE-2026-54665']}, {'type': 'euvd', 'idList': ['EUVD-2026-38216']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-54665']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51195']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-54665']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-8157 | CVE-2026-8157 Vitepos < 3.4.2 - Outlet Manager+ Privilege Escalation | The Vitepos WordPress plugin before 3.4.2 does not properly restrict the roles that can be assigned when creating new users via one of its REST API endpoints, allowing authenticated users with a custom Vitepos WordPress plugin before 3.4.2 role to escalate privileges to administrator. | NONE | 0.00 | NONE | 2026-06-22 06:00:02+03:00 | 2026-06-22 06:00:02+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-8157'] | ['CVE-2026-8157'] | 704c6bebce05e709f005b7c453d4eb55cf841f0287768ff3b806d0cfa8907889 | 2026-06-23 15:06:55.636806+03:00 | 2026-06-23 15:06:55.636806+03:00 | {'id': 'CVELIST:CVE-2026-8157', 'cvss': {'score': 0.0, 'source': 'NONE', 'vector': 'NONE', 'version': 'NONE', 'severity': 'NONE'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-8157', 'type': 'cvelist', 'title': 'CVE-2026-8157 Vitepos < 3.4.2 - Outlet Manager+ Privilege Escalation', 'cvelist': ['CVE-2026-8157'], 'assigned': '2026-05-08T09:14:33', 'lastseen': '2026-06-22T13:45:08', 'modified': '2026-06-22T06:00:02', 'published': '2026-06-22T06:00:02', 'description': 'The Vitepos WordPress plugin before 3.4.2 does not properly restrict the roles that can be assigned when creating new users via one of its REST API endpoints, allowing authenticated users with a custom Vitepos WordPress plugin before 3.4.2 role to escalate privileges to administrator.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:E3C9FF3B-9249-4CDB-8DEA-E944BB87734F']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-8157']}, {'type': 'cve', 'idList': ['CVE-2026-8157']}, {'type': 'euvd', 'idList': ['EUVD-2026-38215']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-8157']}, {'type': 'patchstack', 'idList': ['PATCHSTACK:2CBF2A1F1BE08EFFD66ACBEAF4394A1C']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51280']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-8157']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-8918 | CVE-2026-8918 | A permissive list of allowed inputs in ASUS Armoury Crate allows a local administrator to perform arbitrary memory read/write operations or cause a system crash (BSOD) by bypassing the validation mechanism.Refer to the '
Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information. | HIGH | 7.10 | CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/SC:N/VI:H/SI:N/VA:H/SA:N | 2026-06-22 02:00:12+03:00 | 2026-06-22 02:00:12+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-8918'] | ['CVE-2026-8918'] | 367663285dfd53f92345d056c176058b73e09662e97aa02f5c603ff9e5f0a347 | 2026-06-23 15:06:55.636806+03:00 | 2026-06-23 15:06:55.636806+03:00 | {'id': 'CVELIST:CVE-2026-8918', 'cvss': {'score': 7.1, 'source': 'asus', 'vector': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/SC:N/VI:H/SI:N/VA:H/SA:N', 'version': '4.0', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-8918', 'type': 'cvelist', 'title': 'CVE-2026-8918', 'cvelist': ['CVE-2026-8918'], 'assigned': '2026-05-19T05:57:37', 'lastseen': '2026-06-22T13:45:08', 'modified': '2026-06-22T02:00:12', 'published': '2026-06-22T02:00:12', 'description': "A permissive list of allowed inputs in ASUS Armoury Crate allows a local administrator to perform arbitrary memory read/write operations or cause a system crash (BSOD) by bypassing the validation mechanism.Refer to the '\nSecurity Update for Armoury Crate App\xa0' section on the ASUS Security Advisory for more information.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:B1F7AB83-9015-4B72-9A64-5580C1984EAD']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-8918']}, {'type': 'cve', 'idList': ['CVE-2026-8918']}, {'type': 'euvd', 'idList': ['EUVD-2026-38205']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-8918']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51273']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-8918']}]}}, 'bulletinFamily': 'cve'} |
CVE-2020-37256 | CVE-2020-37256 Grav - Cross-Site Scripting in Admin Plugin Page Editor | Grav before 1.6.30 contains a cross-site scripting vulnerability in the Admin plugin page editor default security configuration. Privileged users with page editing capabilities can inject malicious scripts to execute arbitrary code and install malicious plugins for system access. | MEDIUM | 5.40 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N | 2026-06-25 21:41:00+03:00 | 2026-06-25 21:41:00+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2020-37256'] | ['CVE-2020-37256'] | f1d8af1a6c821e1b9230d173fc73424d3dbd85e204cae6b630d4e8538c3903b9 | 2026-06-26 15:06:33.367280+03:00 | 2026-06-26 15:06:33.367280+03:00 | {'id': 'CVELIST:CVE-2020-37256', 'cvss': {'score': 5.4, 'source': 'vulncheck', 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N', 'version': '3.1', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2020-37256', 'type': 'cvelist', 'title': 'CVE-2020-37256 Grav - Cross-Site Scripting in Admin Plugin Page Editor', 'cvelist': ['CVE-2020-37256'], 'assigned': '2026-06-22T21:55:13', 'lastseen': '2026-06-25T21:59:22', 'modified': '2026-06-25T21:41:00', 'published': '2026-06-25T21:41:00', 'description': 'Grav before 1.6.30 contains a cross-site scripting vulnerability in the Admin plugin page editor default security configuration. Privileged users with page editing capabilities can inject malicious scripts to execute arbitrary code and install malicious plugins for system access.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:1BEE21E6-5D18-4BFB-81CC-43999B31DAD2']}, {'type': 'cve', 'idList': ['CVE-2020-37256']}, {'type': 'euvd', 'idList': ['EUVD-2020-31260']}, {'type': 'nvd', 'idList': ['NVD:CVE-2020-37256']}, {'type': 'ptsecurity', 'idList': ['PT-2026-52606']}]}}, 'bulletinFamily': 'cve'} |
CVE-2023-54365 | CVE-2023-54365 Traefik - Denial of Service via HTTP/2 Request Handling | Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inherited from the Go standard library's HTTP/2 implementation (CVE-2023-44487 / CVE-2023-39325, the 'Rapid Reset' technique). A remote attacker can rapidly create and cancel HTTP/2 streams to exhaust server resources and cause service unavailability. | HIGH | 8.70 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/SC:N/VI:N/SI:N/VA:H/SA:N | 2026-06-23 12:12:51+03:00 | 2026-06-23 12:12:51+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2023-54365'] | ['CVE-2023-54365'] | 403a6819bd2287927a7c9885a7080a5dd7592ad010ae8506db6d4f4d76da587d | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2023-54365', 'cvss': {'score': 8.7, 'source': 'vulncheck', 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/SC:N/VI:N/SI:N/VA:H/SA:N', 'version': '4.0', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2023-54365', 'type': 'cvelist', 'title': 'CVE-2023-54365 Traefik - Denial of Service via HTTP/2 Request Handling', 'cvelist': ['CVE-2023-54365'], 'assigned': '2026-06-22T21:54:30', 'lastseen': '2026-06-23T18:50:59', 'modified': '2026-06-23T12:12:51', 'published': '2026-06-23T12:12:51', 'description': "Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inherited from the Go standard library's HTTP/2 implementation (CVE-2023-44487 / CVE-2023-39325, the 'Rapid Reset' technique). A remote attacker can rapidly create and cancel HTTP/2 streams to exhaust server resources and cause service unavailability.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:ADB6030A-3F7E-4FE2-B825-0D60A828CEBD']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2023-54365']}, {'type': 'cve', 'idList': ['CVE-2023-54365']}, {'type': 'euvd', 'idList': ['EUVD-2023-60596']}, {'type': 'nvd', 'idList': ['NVD:CVE-2023-54365']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51489']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2023-54365']}]}}, 'bulletinFamily': 'cve'} |
CVE-2025-13162 | CVE-2025-13162 Advant Master Online Builder DLL vulnerability | Uncontrolled Search Path Element vulnerability in ABB Control Builder A, ABB 800xA for Advant Master.
This issue affects Control Builder A: through 1.4/4; 800xA for Advant Master: through 6.0.3-1, through 6.1.1-1, 6.1.1-3, 6.2.0-1. | MEDIUM | 4.40 | CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N | 2026-06-23 16:12:54+03:00 | 2026-06-23 16:19:27+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2025-13162'] | ['CVE-2025-13162'] | 3aad640ebb3c0a4c2777aeaf7f91954c1dd9b7dc40bea990c94da924bccf09e4 | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2025-13162', 'cvss': {'score': 4.4, 'source': 'abb', 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N', 'version': '3.1', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2025-13162', 'type': 'cvelist', 'title': 'CVE-2025-13162 Advant Master Online Builder DLL vulnerability', 'cvelist': ['CVE-2025-13162'], 'assigned': '2025-11-14T03:20:45', 'lastseen': '2026-06-23T17:21:07', 'modified': '2026-06-23T16:19:27', 'published': '2026-06-23T16:12:54', 'description': 'Uncontrolled Search Path Element vulnerability in ABB Control Builder A, ABB 800xA for Advant Master.\n\nThis issue affects Control Builder A: through 1.4/4; 800xA for Advant Master: through 6.0.3-1, through 6.1.1-1, 6.1.1-3, 6.2.0-1.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:F1184D30-E4EE-49F9-B722-76828C59BAAA']}, {'type': 'cve', 'idList': ['CVE-2025-13162']}, {'type': 'euvd', 'idList': ['EUVD-2025-210312']}, {'type': 'nvd', 'idList': ['NVD:CVE-2025-13162']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51536']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2025-13162']}]}}, 'bulletinFamily': 'cve'} |
CVE-2025-33128 | CVE-2025-33128 IBM Engineering Lifecycle Management - Engineering Workflow Management is impacted by vulnerabilities HTML / XSS Injection observed | IBM Engineering Workflow Management 7.0.3 through 7.0.3 Interim Fix 020, and 7.1 through 7.1 Interim Fix 007 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | MEDIUM | 5.40 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N | 2026-06-22 13:20:14+03:00 | 2026-06-22 13:20:14+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2025-33128'] | ['CVE-2025-33128'] | 0f4d97a14767b874bf290ae56566e6ba321221d20157df68370e03b05c59be12 | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2025-33128', 'cvss': {'score': 5.4, 'source': 'ibm', 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N', 'version': '3.1', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2025-33128', 'type': 'cvelist', 'title': 'CVE-2025-33128 IBM Engineering Lifecycle Management - Engineering Workflow Management is impacted by vulnerabilities HTML / XSS Injection observed', 'cvelist': ['CVE-2025-33128'], 'assigned': '2025-04-15T17:51:11', 'lastseen': '2026-06-23T14:38:45', 'modified': '2026-06-22T13:20:14', 'published': '2026-06-22T13:20:14', 'description': 'IBM Engineering Workflow Management 7.0.3 through 7.0.3 Interim Fix 020, and 7.1 through 7.1 Interim Fix 007 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:EEAAC1BC-D6E8-4E02-A3AC-D59F1FD378EA']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2025-33128']}, {'type': 'cve', 'idList': ['CVE-2025-33128']}, {'type': 'euvd', 'idList': ['EUVD-2025-210300']}, {'type': 'ibm', 'idList': ['7566794E33524AD01D321DA9156E41999550443F03430173A12658C8D2FF4C6D']}, {'type': 'nvd', 'idList': ['NVD:CVE-2025-33128']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51296']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2025-33128']}]}}, 'bulletinFamily': 'cve'} |
CVE-2025-4994 | CVE-2025-4994 Authentication Bypass for SafeLine SL6 and SL6+ | The SafeLine SL6 and SL6+ devices integrated into elevator emergency intercom systems are vulnerable to an authentication bypass. This vulnerability allows attackers to bypass authentication requirements and access the device's configuration service via the Bluetooth Low Energy (BLE) interface. Consequently, an attacker within wireless range can gain unauthorized administrative access to the device configuration. | HIGH | 8.70 | CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/SC:N/VI:H/SI:N/VA:H/SA:N | 2026-06-22 08:10:29+03:00 | 2026-06-22 08:10:29+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2025-4994'] | ['CVE-2025-4994'] | 55b15578149fe218e9314e5a06a5d5f89de06600b54a651fc027151f7ee55385 | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2025-4994', 'cvss': {'score': 8.7, 'source': 'schutzwerk', 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/SC:N/VI:H/SI:N/VA:H/SA:N', 'version': '4.0', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2025-4994', 'type': 'cvelist', 'title': 'CVE-2025-4994 Authentication Bypass for SafeLine SL6 and SL6+', 'cvelist': ['CVE-2025-4994'], 'assigned': '2025-05-20T08:40:34', 'lastseen': '2026-06-22T13:45:16', 'modified': '2026-06-22T08:10:29', 'published': '2026-06-22T08:10:29', 'description': "The SafeLine SL6 and SL6+ devices integrated into elevator emergency intercom systems are vulnerable to an authentication bypass. This vulnerability allows attackers to bypass authentication requirements and access the device's configuration service via the Bluetooth Low Energy (BLE) interface. Consequently, an attacker within wireless range can gain unauthorized administrative access to the device configuration.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:16BB0AD7-954A-41DA-9321-F28520B10EAD']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2025-4994']}, {'type': 'cve', 'idList': ['CVE-2025-4994']}, {'type': 'euvd', 'idList': ['EUVD-2025-210297']}, {'type': 'nvd', 'idList': ['NVD:CVE-2025-4994']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51287']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2025-4994']}]}}, 'bulletinFamily': 'cve'} |
CVE-2025-61018 | CVE-2025-61018 | An issue in the sqlo_place_dt_set component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | NONE | 0.00 | NONE | 2026-06-23 00:00:00+03:00 | 2026-06-23 16:27:47+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2025-61018'] | ['CVE-2025-61018'] | 6b2010e147b3c5cafc7061469c2f182e835f6474c779b922dc444e122acc291c | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2025-61018', 'cvss': {'score': 0.0, 'source': 'NONE', 'vector': 'NONE', 'version': 'NONE', 'severity': 'NONE'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2025-61018', 'type': 'cvelist', 'title': 'CVE-2025-61018', 'cvelist': ['CVE-2025-61018'], 'assigned': '2025-09-26T00:00:00', 'lastseen': '2026-06-23T17:09:05', 'modified': '2026-06-23T16:27:47', 'published': '2026-06-23T00:00:00', 'description': 'An issue in the sqlo_place_dt_set component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:F6573896-9423-47E3-98B5-8AAEDE8DC9D4']}, {'type': 'cve', 'idList': ['CVE-2025-61018']}, {'type': 'euvd', 'idList': ['EUVD-2025-210313']}, {'type': 'nvd', 'idList': ['NVD:CVE-2025-61018']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51537']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2025-61018']}]}}, 'bulletinFamily': 'cve'} |
CVE-2021-47986 | CVE-2021-47986 Parse Server - Unreviewed Code Execution via Malicious Version Tags | Parse Server before 4.10.0 contains a supply chain vulnerability where incorrect version tags were pushed to the repository linking to unreviewed code in a personal fork. Attackers could exploit this by specifying affected version tags in dependency declarations to execute unreviewed and potentially malicious code. | HIGH | 7.70 | CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/SC:N/VI:H/SI:N/VA:H/SA:N | 2026-06-25 21:41:01+03:00 | 2026-06-25 21:41:01+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2021-47986'] | ['CVE-2021-47986'] | cd301c70359ee23ebef2c6b9a7e3c83e4a50041675c3492d6560a31b7573f4f7 | 2026-06-26 15:06:33.367280+03:00 | 2026-06-26 15:06:33.367280+03:00 | {'id': 'CVELIST:CVE-2021-47986', 'cvss': {'score': 7.7, 'source': 'vulncheck', 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/SC:N/VI:H/SI:N/VA:H/SA:N', 'version': '4.0', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2021-47986', 'type': 'cvelist', 'title': 'CVE-2021-47986 Parse Server - Unreviewed Code Execution via Malicious Version Tags', 'cvelist': ['CVE-2021-47986'], 'assigned': '2026-06-21T02:08:33', 'lastseen': '2026-06-26T11:02:41', 'modified': '2026-06-25T21:41:01', 'published': '2026-06-25T21:41:01', 'description': 'Parse Server before 4.10.0 contains a supply chain vulnerability where incorrect version tags were pushed to the repository linking to unreviewed code in a personal fork. Attackers could exploit this by specifying affected version tags in dependency declarations to execute unreviewed and potentially malicious code.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:2F9390AC-E9D6-47EA-B782-500C41AD4324']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2021-47986']}, {'type': 'cve', 'idList': ['CVE-2021-47986']}, {'type': 'euvd', 'idList': ['EUVD-2021-34852']}, {'type': 'nvd', 'idList': ['NVD:CVE-2021-47986']}, {'type': 'ptsecurity', 'idList': ['PT-2026-52607']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2021-47986']}]}}, 'bulletinFamily': 'cve'} |
CVE-2025-61019 | CVE-2025-61019 | An issue in the sqlo_key_part_best component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | NONE | 0.00 | NONE | 2026-06-23 00:00:00+03:00 | 2026-06-23 16:05:10+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2025-61019'] | ['CVE-2025-61019'] | d437b9e1eb0fd07f2661c7a72baef69965fbf685e45e0ef4b56b974cee3563a1 | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2025-61019', 'cvss': {'score': 0.0, 'source': 'NONE', 'vector': 'NONE', 'version': 'NONE', 'severity': 'NONE'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2025-61019', 'type': 'cvelist', 'title': 'CVE-2025-61019', 'cvelist': ['CVE-2025-61019'], 'assigned': '2025-09-26T00:00:00', 'lastseen': '2026-06-23T16:39:09', 'modified': '2026-06-23T16:05:10', 'published': '2026-06-23T00:00:00', 'description': 'An issue in the sqlo_key_part_best component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:F0B3C4B0-78E4-4979-B40A-53F46F8F79FA']}, {'type': 'cve', 'idList': ['CVE-2025-61019']}, {'type': 'euvd', 'idList': ['EUVD-2025-210314']}, {'type': 'nvd', 'idList': ['NVD:CVE-2025-61019']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51538']}]}}, 'bulletinFamily': 'cve'} |
CVE-2025-61020 | CVE-2025-61020 | An issue in the sqlo_strip_in_join component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | NONE | 0.00 | NONE | 2026-06-23 00:00:00+03:00 | 2026-06-23 16:31:26+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2025-61020'] | ['CVE-2025-61020'] | 3fd2ef71290fb0cb1c9507e13e88f4f710bdff0f5ca3778edf1b809cb7aee11c | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2025-61020', 'cvss': {'score': 0.0, 'source': 'NONE', 'vector': 'NONE', 'version': 'NONE', 'severity': 'NONE'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2025-61020', 'type': 'cvelist', 'title': 'CVE-2025-61020', 'cvelist': ['CVE-2025-61020'], 'assigned': '2025-09-26T00:00:00', 'lastseen': '2026-06-23T17:03:05', 'modified': '2026-06-23T16:31:26', 'published': '2026-06-23T00:00:00', 'description': 'An issue in the sqlo_strip_in_join component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:E6975176-4C1D-4D44-9264-FE005D4F8F3D']}, {'type': 'cve', 'idList': ['CVE-2025-61020']}, {'type': 'euvd', 'idList': ['EUVD-2025-210315']}, {'type': 'nvd', 'idList': ['NVD:CVE-2025-61020']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51539']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2025-61020']}]}}, 'bulletinFamily': 'cve'} |
CVE-2025-61021 | CVE-2025-61021 | An issue in the sqlo_natural_join_cond component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | NONE | 0.00 | NONE | 2026-06-23 00:00:00+03:00 | 2026-06-23 16:02:27+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2025-61021'] | ['CVE-2025-61021'] | 5f842f0d7e4ad70ea751f70179e892c37c1c0333c6b1306c8bca7d5273a8a1c1 | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2025-61021', 'cvss': {'score': 0.0, 'source': 'NONE', 'vector': 'NONE', 'version': 'NONE', 'severity': 'NONE'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2025-61021', 'type': 'cvelist', 'title': 'CVE-2025-61021', 'cvelist': ['CVE-2025-61021'], 'assigned': '2025-09-26T00:00:00', 'lastseen': '2026-06-23T16:39:09', 'modified': '2026-06-23T16:02:27', 'published': '2026-06-23T00:00:00', 'description': 'An issue in the sqlo_natural_join_cond component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:B0AE8D9A-C526-431A-B3E3-8036DDADF379']}, {'type': 'cve', 'idList': ['CVE-2025-61021']}, {'type': 'euvd', 'idList': ['EUVD-2025-210316']}, {'type': 'nvd', 'idList': ['NVD:CVE-2025-61021']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51540']}]}}, 'bulletinFamily': 'cve'} |
CVE-2025-61022 | CVE-2025-61022 | An issue in the sqlo_tb_col_preds component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | NONE | 0.00 | NONE | 2026-06-23 00:00:00+03:00 | 2026-06-23 16:34:07+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2025-61022'] | ['CVE-2025-61022'] | 70172505b0ecb86ca70c58d2c2a1b5131ca91cc9458dc1d399267038ba889c2c | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2025-61022', 'cvss': {'score': 0.0, 'source': 'NONE', 'vector': 'NONE', 'version': 'NONE', 'severity': 'NONE'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2025-61022', 'type': 'cvelist', 'title': 'CVE-2025-61022', 'cvelist': ['CVE-2025-61022'], 'assigned': '2025-09-26T00:00:00', 'lastseen': '2026-06-23T17:03:05', 'modified': '2026-06-23T16:34:07', 'published': '2026-06-23T00:00:00', 'description': 'An issue in the sqlo_tb_col_preds component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:AB2CB8A1-9532-4188-A25A-8A38F8A16C50']}, {'type': 'cve', 'idList': ['CVE-2025-61022']}, {'type': 'euvd', 'idList': ['EUVD-2025-210317']}, {'type': 'nvd', 'idList': ['NVD:CVE-2025-61022']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51541']}, {'type': 'redhatcve', 'idList': ['RH:CVE-2025-61022']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2025-61022']}]}}, 'bulletinFamily': 'cve'} |
CVE-2025-61023 | CVE-2025-61023 | An issue in the st_compare component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | NONE | 0.00 | NONE | 2026-06-23 00:00:00+03:00 | 2026-06-23 16:19:19+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2025-61023'] | ['CVE-2025-61023'] | 3724850f174f674170915f3a0969f7cebfe099e970b4ecfb48eacd1d41f5abbb | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2025-61023', 'cvss': {'score': 0.0, 'source': 'NONE', 'vector': 'NONE', 'version': 'NONE', 'severity': 'NONE'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2025-61023', 'type': 'cvelist', 'title': 'CVE-2025-61023', 'cvelist': ['CVE-2025-61023'], 'assigned': '2025-09-26T00:00:00', 'lastseen': '2026-06-23T16:39:09', 'modified': '2026-06-23T16:19:19', 'published': '2026-06-23T00:00:00', 'description': 'An issue in the st_compare component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:019EE181-A0F5-4A15-8629-64DB742ADEC4']}, {'type': 'cve', 'idList': ['CVE-2025-61023']}, {'type': 'euvd', 'idList': ['EUVD-2025-210318']}, {'type': 'nvd', 'idList': ['NVD:CVE-2025-61023']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51542']}]}}, 'bulletinFamily': 'cve'} |
CVE-2025-61024 | CVE-2025-61024 | An issue in the sqlo_try_in_loop component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | NONE | 0.00 | NONE | 2026-06-23 00:00:00+03:00 | 2026-06-23 16:40:30+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2025-61024'] | ['CVE-2025-61024'] | 6053c2ee5461122e1a2f8781853bd65d1d6f71db32ea50f94235cc6ecb2af4b5 | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2025-61024', 'cvss': {'score': 0.0, 'source': 'NONE', 'vector': 'NONE', 'version': 'NONE', 'severity': 'NONE'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2025-61024', 'type': 'cvelist', 'title': 'CVE-2025-61024', 'cvelist': ['CVE-2025-61024'], 'assigned': '2025-09-26T00:00:00', 'lastseen': '2026-06-23T17:56:42', 'modified': '2026-06-23T16:40:30', 'published': '2026-06-23T00:00:00', 'description': 'An issue in the sqlo_try_in_loop component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:F6F6CDA0-278E-4DCF-880C-E14550D43D21']}, {'type': 'cve', 'idList': ['CVE-2025-61024']}, {'type': 'euvd', 'idList': ['EUVD-2025-210323']}, {'type': 'nvd', 'idList': ['NVD:CVE-2025-61024']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51569']}, {'type': 'redhatcve', 'idList': ['RH:CVE-2025-61024']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2025-61024']}]}}, 'bulletinFamily': 'cve'} |
CVE-2025-61025 | CVE-2025-61025 | An issue in the sslr_qst_get component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | NONE | 0.00 | NONE | 2026-06-23 00:00:00+03:00 | 2026-06-23 16:36:40+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2025-61025'] | ['CVE-2025-61025'] | 7d6d87ab9ba2c774bf316e06fb06d419d62999ef8e3e840597f5f8279fa0994c | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2025-61025', 'cvss': {'score': 0.0, 'source': 'NONE', 'vector': 'NONE', 'version': 'NONE', 'severity': 'NONE'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2025-61025', 'type': 'cvelist', 'title': 'CVE-2025-61025', 'cvelist': ['CVE-2025-61025'], 'assigned': '2025-09-26T00:00:00', 'lastseen': '2026-06-23T16:57:05', 'modified': '2026-06-23T16:36:40', 'published': '2026-06-23T00:00:00', 'description': 'An issue in the sslr_qst_get component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:29035747-D3AC-41FF-9E3F-13545641B123']}, {'type': 'cve', 'idList': ['CVE-2025-61025']}, {'type': 'euvd', 'idList': ['EUVD-2025-210319']}, {'type': 'nvd', 'idList': ['NVD:CVE-2025-61025']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51543']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2025-61025']}]}}, 'bulletinFamily': 'cve'} |
CVE-2025-61027 | CVE-2025-61027 | An issue in the t_set_push component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | NONE | 0.00 | NONE | 2026-06-23 00:00:00+03:00 | 2026-06-23 16:24:33+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2025-61027'] | ['CVE-2025-61027'] | c80a4982ce907c94bdb1e32872238020be948382cee459a8888b3cde28f80bfe | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2025-61027', 'cvss': {'score': 0.0, 'source': 'NONE', 'vector': 'NONE', 'version': 'NONE', 'severity': 'NONE'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2025-61027', 'type': 'cvelist', 'title': 'CVE-2025-61027', 'cvelist': ['CVE-2025-61027'], 'assigned': '2025-09-26T00:00:00', 'lastseen': '2026-06-23T16:39:09', 'modified': '2026-06-23T16:24:33', 'published': '2026-06-23T00:00:00', 'description': 'An issue in the t_set_push component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:7340418F-BA84-4EC2-B301-7A63C5021D1E']}, {'type': 'cve', 'idList': ['CVE-2025-61027']}, {'type': 'euvd', 'idList': ['EUVD-2025-210320']}, {'type': 'nvd', 'idList': ['NVD:CVE-2025-61027']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51544']}]}}, 'bulletinFamily': 'cve'} |
CVE-2025-61028 | CVE-2025-61028 | An issue in the time_t_to_dt component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | NONE | 0.00 | NONE | 2026-06-23 00:00:00+03:00 | 2026-06-23 16:12:07+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2025-61028'] | ['CVE-2025-61028'] | d13b545d7b9544d25af309051bf9ae5bff888d8c82bba4b22ba75f6f6f6897ed | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2025-61028', 'cvss': {'score': 0.0, 'source': 'NONE', 'vector': 'NONE', 'version': 'NONE', 'severity': 'NONE'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2025-61028', 'type': 'cvelist', 'title': 'CVE-2025-61028', 'cvelist': ['CVE-2025-61028'], 'assigned': '2025-09-26T00:00:00', 'lastseen': '2026-06-23T16:39:09', 'modified': '2026-06-23T16:12:07', 'published': '2026-06-23T00:00:00', 'description': 'An issue in the time_t_to_dt component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:684D1D37-A747-419F-BFD0-FDCC7A5FB870']}, {'type': 'cve', 'idList': ['CVE-2025-61028']}, {'type': 'euvd', 'idList': ['EUVD-2025-210321']}, {'type': 'nvd', 'idList': ['NVD:CVE-2025-61028']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51545']}]}}, 'bulletinFamily': 'cve'} |
CVE-2025-61029 | CVE-2025-61029 | An issue in the sqlo_untry component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | NONE | 0.00 | NONE | 2026-06-23 00:00:00+03:00 | 2026-06-23 16:38:50+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2025-61029'] | ['CVE-2025-61029'] | 086e2f66788fa941b2a9e10c971051ae3beb3f5b194da710a7d17072583332c0 | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2025-61029', 'cvss': {'score': 0.0, 'source': 'NONE', 'vector': 'NONE', 'version': 'NONE', 'severity': 'NONE'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2025-61029', 'type': 'cvelist', 'title': 'CVE-2025-61029', 'cvelist': ['CVE-2025-61029'], 'assigned': '2025-09-26T00:00:00', 'lastseen': '2026-06-23T17:56:42', 'modified': '2026-06-23T16:38:50', 'published': '2026-06-23T00:00:00', 'description': 'An issue in the sqlo_untry component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:A2C21E4F-B91A-4936-94CB-5032AD3F3D9A']}, {'type': 'cve', 'idList': ['CVE-2025-61029']}, {'type': 'euvd', 'idList': ['EUVD-2025-210324']}, {'type': 'nvd', 'idList': ['NVD:CVE-2025-61029']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51570']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2025-61029']}]}}, 'bulletinFamily': 'cve'} |
CVE-2025-66389 | CVE-2025-66389 | GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler URI parameter to fetch_webpage. Therefore, exfiltration could occur if there is indirect prompt injection. | NONE | 0.00 | NONE | 2026-06-22 00:00:00+03:00 | 2026-06-22 13:38:54+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2025-66389'] | ['CVE-2025-66389'] | 9377522ea971ca9045efba3eeb1ccabc0d71fffe84fd19813562c3e22a7dd3f9 | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2025-66389', 'cvss': {'score': 0.0, 'source': 'NONE', 'vector': 'NONE', 'version': 'NONE', 'severity': 'NONE'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2025-66389', 'type': 'cvelist', 'title': 'CVE-2025-66389', 'cvelist': ['CVE-2025-66389'], 'assigned': '2025-11-28T00:00:00', 'lastseen': '2026-06-22T17:20:56', 'modified': '2026-06-22T13:38:54', 'published': '2026-06-22T00:00:00', 'description': 'GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler URI parameter to fetch_webpage. Therefore, exfiltration could occur if there is indirect prompt injection.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:D062C4C0-6FDD-475F-B400-00C5BC73499E']}, {'type': 'cve', 'idList': ['CVE-2025-66389']}, {'type': 'euvd', 'idList': ['EUVD-2025-210298']}, {'type': 'nvd', 'idList': ['NVD:CVE-2025-66389']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51297']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2025-66389']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-10521 | CVE-2026-10521 Authenticated unintended access to critical program parameters | An high privileged remote attacker can access a hidden configuration method, that should not be accessible by any user, to modify critical program parameters. This can result in a total loss of confidentiality, integrity and availability. | HIGH | 8.60 | CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/SC:N/VI:H/SI:N/VA:H/SA:N | 2026-06-23 07:34:10+03:00 | 2026-06-23 07:34:10+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-10521'] | ['CVE-2026-10521'] | 8f3ea93e5eeeb3e2cec5a088c83f6ecd99b953223bb298ae553270598e4f59b7 | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2026-10521', 'cvss': {'score': 8.6, 'source': 'certvde', 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/SC:N/VI:H/SI:N/VA:H/SA:N', 'version': '4.0', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-10521', 'type': 'cvelist', 'title': 'CVE-2026-10521 Authenticated unintended access to critical program parameters', 'cvelist': ['CVE-2026-10521'], 'assigned': '2026-06-01T08:47:49', 'lastseen': '2026-06-23T12:50:43', 'modified': '2026-06-23T07:34:10', 'published': '2026-06-23T07:34:10', 'description': 'An high privileged remote attacker can access a hidden configuration method, that should not be accessible by any user, to modify critical program parameters. This can result in a total loss of confidentiality, integrity and availability.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:80A4FB9C-5E22-4BD6-B40C-0010A2E077D8']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-10521']}, {'type': 'cve', 'idList': ['CVE-2026-10521']}, {'type': 'euvd', 'idList': ['EUVD-2026-38422']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-10521']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51480']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-10561 | CVE-2026-10561 Unauthenticated Remote Code Execution in Langflow OSS PythonREPLComponent via Builtins Injection | IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arbitrary code on the host system, resulting in complete compromise | CRITICAL | 10.00 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H | 2026-06-22 13:22:07+03:00 | 2026-06-22 13:22:07+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-10561'] | ['CVE-2026-10561'] | f343c2a8fe163aab613cb8f9c2a404389cb5858bcdbc1c8682b349e00c309f02 | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2026-10561', 'cvss': {'score': 10.0, 'source': 'ibm', 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H', 'version': '3.1', 'severity': 'CRITICAL'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-10561', 'type': 'cvelist', 'title': 'CVE-2026-10561 Unauthenticated Remote Code Execution in Langflow OSS PythonREPLComponent via Builtins Injection', 'cvelist': ['CVE-2026-10561'], 'assigned': '2026-06-01T15:41:38', 'lastseen': '2026-06-23T18:50:58', 'modified': '2026-06-22T13:22:07', 'published': '2026-06-22T13:22:07', 'description': 'IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arbitrary code on the host system, resulting in complete compromise', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:618952DE-56B2-41CA-B0B8-711278BD4702']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-10561']}, {'type': 'cve', 'idList': ['CVE-2026-10561']}, {'type': 'euvd', 'idList': ['EUVD-2026-38245']}, {'type': 'ibm', 'idList': ['56013D9C8566ACFFEE8029C83F51DFCEBD6F884B6E5E543D37F9E207D84E86A2']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-10561']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51298']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-10561']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-10601 | CVE-2026-10601 Path Traversal in Tempo and Loki Data Source Plugins — Credential Leakage and Admin Endpoint Access | The Tempo and Loki datasource plugins construct backend HTTP requests by interpolating user-supplied input into URL paths without sanitization, enabling path traversal. A Viewer-role user can: (1) capture admin-configured datasource credentials (secureJsonData custom headers) by traversing to an attacker-controlled endpoint, (2) invoke state-changing admin endpoints on Tempo (e.g. /flush, /shutdown), and (3) exfiltrate internal service data via Loki's CallResource which returns full HTTP response bodies. | MEDIUM | 5.40 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L | 2026-06-22 13:18:31+03:00 | 2026-06-22 13:18:31+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-10601'] | ['CVE-2026-10601'] | 82d46fd6a7ad05f1e90469a225b5b18d522afb50893fc537c943fbf96ab4f5f1 | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2026-10601', 'cvss': {'score': 5.4, 'source': 'grafana', 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L', 'version': '3.1', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-10601', 'type': 'cvelist', 'title': 'CVE-2026-10601 Path Traversal in Tempo and Loki Data Source Plugins — Credential Leakage and Admin Endpoint Access', 'cvelist': ['CVE-2026-10601'], 'assigned': '2026-06-02T09:57:26', 'lastseen': '2026-06-22T15:44:33', 'modified': '2026-06-22T13:18:31', 'published': '2026-06-22T13:18:31', 'description': "The Tempo and Loki datasource plugins construct backend HTTP requests by interpolating user-supplied input into URL paths without sanitization, enabling path traversal. A Viewer-role user can: (1) capture admin-configured datasource credentials (secureJsonData custom headers) by traversing to an attacker-controlled endpoint, (2) invoke state-changing admin endpoints on Tempo (e.g. /flush, /shutdown), and (3) exfiltrate internal service data via Loki's CallResource which returns full HTTP response bodies.", 'enchantments': {'dependencies': {'references': [{'type': 'alpinelinux', 'idList': ['ALPINE:CVE-2026-10601']}, {'type': 'attackerkb', 'idList': ['AKB:3797A643-C112-4546-B357-4EE065C21121']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-10601']}, {'type': 'cve', 'idList': ['CVE-2026-10601']}, {'type': 'euvd', 'idList': ['EUVD-2026-38242']}, {'type': 'nessus', 'idList': ['UNPATCHED_CVE_2026_10601.NASL']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-10601']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51299']}, {'type': 'redhatcve', 'idList': ['RH:CVE-2026-10601']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-10601']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-10609 | CVE-2026-10609 Openshift/cluster-logging-operator: cluster logging operator creates and forwards serviceaccount tokens without verifying clf creator authorization | A missing authorization flaw was found in the OpenShift Cluster Logging Operator. The operator creates and forwards ServiceAccount tokens to output destinations without verifying that the ClusterLogForwarder creator has permission to use those credentials, allowing a delegated editor to exfiltrate SA tokens and escalate privileges. | MEDIUM | 6.80 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N | 2026-06-23 13:26:43+03:00 | 2026-06-23 13:26:43+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-10609'] | ['CVE-2026-10609'] | 60fa6b63b95782a923f7249eab58c8e40ea27d6cf4122727bf73f6830028317b | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2026-10609', 'cvss': {'score': 6.8, 'source': 'redhat', 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N', 'version': '3.1', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-10609', 'type': 'cvelist', 'title': 'CVE-2026-10609 Openshift/cluster-logging-operator: cluster logging operator creates and forwards serviceaccount tokens without verifying clf creator authorization', 'cvelist': ['CVE-2026-10609'], 'assigned': '2026-06-02T11:48:09', 'lastseen': '2026-06-23T14:02:41', 'modified': '2026-06-23T13:26:43', 'published': '2026-06-23T13:26:43', 'description': 'A missing authorization flaw was found in the OpenShift Cluster Logging Operator. The operator creates and forwards ServiceAccount tokens to output destinations without verifying that the ClusterLogForwarder creator has permission to use those credentials, allowing a delegated editor to exfiltrate SA tokens and escalate privileges.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:84A99022-2AAE-4BCB-AD22-84F720E878A6']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-10609']}, {'type': 'cve', 'idList': ['CVE-2026-10609']}, {'type': 'euvd', 'idList': ['EUVD-2026-38448']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-10609']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51518']}, {'type': 'redhatcve', 'idList': ['RH:CVE-2026-10609']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-10609']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-10645 | CVE-2026-10645 fs: ext2: Missing structural validation of directory entries can cause out-of-bounds read and zero-progress directory traversal | Zephyr's ext2 directory-entry parser does not fully validate on-disk directory entry structure before copying the entry name and advancing traversal state. In ext2_fetch_direntry() (subsys/fs/ext2/ext2_diskops.c), the code only checks de_name_len <= EXT2_MAX_FILE_NAME and then copies the name with memcpy without validating the structural relationship between de_rec_len, de_name_len, and the directory block boundary (for example that de_rec_len is non-zero, at least the size of the entry header, and that the record fits within the block). Callers such as find_dir_entry() and ext2_get_direntry() (subsys/fs/ext2/ext2_impl.c) then advance traversal using the unvalidated de_rec_len. A crafted ext2 image can therefore cause an out-of-bounds read from the directory block buffer when a malformed entry near the end of a block triggers an oversized name copy, or a zero-progress infinite loop when de_rec_len == 0. The issue is not reached at mount time but later through directory traversal paths such as pathname lookup, stat/open/unlink/rename, and readdir. The primary impact is denial of service and out-of-bounds reads under attacker-controlled ext2 images mounted from untrusted media. | MEDIUM | 4.90 | CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H | 2026-06-22 23:48:11+03:00 | 2026-06-22 23:48:11+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-10645'] | ['CVE-2026-10645'] | 9931b8a7e72ad83e30c74b1d82ff99eebfc616856ecda8fbaaf529396f5726f9 | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2026-10645', 'cvss': {'score': 4.9, 'source': 'zephyr', 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H', 'version': '3.1', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-10645', 'type': 'cvelist', 'title': 'CVE-2026-10645 fs: ext2: Missing structural validation of directory entries can cause out-of-bounds read and zero-progress directory traversal', 'cvelist': ['CVE-2026-10645'], 'assigned': '2026-06-02T15:11:47', 'lastseen': '2026-06-23T12:50:43', 'modified': '2026-06-22T23:48:11', 'published': '2026-06-22T23:48:11', 'description': "Zephyr's ext2 directory-entry parser does not fully validate on-disk directory entry structure before copying the entry name and advancing traversal state. In ext2_fetch_direntry() (subsys/fs/ext2/ext2_diskops.c), the code only checks de_name_len <= EXT2_MAX_FILE_NAME and then copies the name with memcpy without validating the structural relationship between de_rec_len, de_name_len, and the directory block boundary (for example that de_rec_len is non-zero, at least the size of the entry header, and that the record fits within the block). Callers such as find_dir_entry() and ext2_get_direntry() (subsys/fs/ext2/ext2_impl.c) then advance traversal using the unvalidated de_rec_len. A crafted ext2 image can therefore cause an out-of-bounds read from the directory block buffer when a malformed entry near the end of a block triggers an oversized name copy, or a zero-progress infinite loop when de_rec_len == 0. The issue is not reached at mount time but later through directory traversal paths such as pathname lookup, stat/open/unlink/rename, and readdir. The primary impact is denial of service and out-of-bounds reads under attacker-controlled ext2 images mounted from untrusted media.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:410B4A8A-2E8F-4E1F-8C8B-BD2A216AF00E']}, {'type': 'cve', 'idList': ['CVE-2026-10645']}, {'type': 'euvd', 'idList': ['EUVD-2026-38408']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-10645']}, {'type': 'osv', 'idList': ['OSV:UBUNTU-CVE-2026-10645']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51425']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-10645']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-10651 | CVE-2026-10651 Bluetooth Classic SDP parser truncation bug in bt_sdp_parse_attribute() leads to reachable assertion and possible out-of-bounds read | A malformed Bluetooth Classic SDP attribute can trigger a reachable assertion in Zephyr's SDP parser. In subsys/bluetooth/host/classic/sdp.c, bt_sdp_parse_attribute() accepts an input buffer once it contains the 1-byte attribute type and 2-byte attribute id, but then unconditionally pulls an additional byte for the value type without verifying that the byte is present. A truncated 3-byte attribute (for example 09 00 09) therefore reaches net_buf_simple_pull() with insufficient remaining length, triggering the __ASSERT_NO_MSG(buf->len >= len) check and a kernel panic in assert-enabled builds (denial of service). In builds where assertions are disabled, parsing may continue past the end of the available buffer, leading to an out-of-bounds read and undefined behavior. | HIGH | 7.10 | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H | 2026-06-22 23:54:36+03:00 | 2026-06-22 23:54:36+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-10651'] | ['CVE-2026-10651'] | 3a6fa7da5f3ba0103d8272fcb191af57a8dbdcfee3757689632949bfe12bbc80 | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2026-10651', 'cvss': {'score': 7.1, 'source': 'zephyr', 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H', 'version': '3.1', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-10651', 'type': 'cvelist', 'title': 'CVE-2026-10651 Bluetooth Classic SDP parser truncation bug in bt_sdp_parse_attribute() leads to reachable assertion and possible out-of-bounds read', 'cvelist': ['CVE-2026-10651'], 'assigned': '2026-06-02T15:24:24', 'lastseen': '2026-06-23T12:50:43', 'modified': '2026-06-22T23:54:36', 'published': '2026-06-22T23:54:36', 'description': "A malformed Bluetooth Classic SDP attribute can trigger a reachable assertion in Zephyr's SDP parser. In subsys/bluetooth/host/classic/sdp.c, bt_sdp_parse_attribute() accepts an input buffer once it contains the 1-byte attribute type and 2-byte attribute id, but then unconditionally pulls an additional byte for the value type without verifying that the byte is present. A truncated 3-byte attribute (for example 09 00 09) therefore reaches net_buf_simple_pull() with insufficient remaining length, triggering the __ASSERT_NO_MSG(buf->len >= len) check and a kernel panic in assert-enabled builds (denial of service). In builds where assertions are disabled, parsing may continue past the end of the available buffer, leading to an out-of-bounds read and undefined behavior.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:A523E1B0-EDCD-4F27-9F32-04032D408748']}, {'type': 'cve', 'idList': ['CVE-2026-10651']}, {'type': 'euvd', 'idList': ['EUVD-2026-38409']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-10651']}, {'type': 'osv', 'idList': ['OSV:UBUNTU-CVE-2026-10651']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51426']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-10651']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-10658 | CVE-2026-10658 Bluetooth Host ISO RX Missing SDU Header Length Validation in bt_iso_recv() Leads to DoS | A missing length validation in the Zephyr Bluetooth Host ISO receive path can be triggered by malformed HCI ISO data. In bt_iso_recv() (subsys/bluetooth/host/iso.c), when processing PB=START/SINGLE fragments, the code pulls a TS SDU header (8 bytes, ts=1) or a non-TS SDU header (4 bytes, ts=0) without first verifying that buf->len contains at least that many bytes. The outer HCI ISO length check in hci_iso() validates payload length consistency but not the minimum inner SDU header size, so a packet with payload length 1 passes hci_iso() and then reaches net_buf_pull_mem(), which asserts buf->len >= len. As a result, malformed ISO traffic deterministically triggers a kernel assert (denial of service) in assert-enabled builds, and in non-assert builds the same path may proceed with an undersized buffer, leading to out-of-bounds read behavior. The issue affects products using the Zephyr Host with CONFIG_BT_ISO_RX enabled, particularly where incoming HCI data can be influenced by a malicious or compromised controller or malformed forwarded ISO traffic. | HIGH | 7.10 | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H | 2026-06-22 23:58:47+03:00 | 2026-06-22 23:58:47+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-10658'] | ['CVE-2026-10658'] | 7fdab092e867a55ae9f77b5c7b90a722b19dd0b1bc7fbf50e90afc4fe5e1a2f0 | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2026-10658', 'cvss': {'score': 7.1, 'source': 'zephyr', 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H', 'version': '3.1', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-10658', 'type': 'cvelist', 'title': 'CVE-2026-10658 Bluetooth Host ISO RX Missing SDU Header Length Validation in bt_iso_recv() Leads to DoS', 'cvelist': ['CVE-2026-10658'], 'assigned': '2026-06-02T15:24:35', 'lastseen': '2026-06-23T12:50:43', 'modified': '2026-06-22T23:58:47', 'published': '2026-06-22T23:58:47', 'description': 'A missing length validation in the Zephyr Bluetooth Host ISO receive path can be triggered by malformed HCI ISO data. In bt_iso_recv() (subsys/bluetooth/host/iso.c), when processing PB=START/SINGLE fragments, the code pulls a TS SDU header (8 bytes, ts=1) or a non-TS SDU header (4 bytes, ts=0) without first verifying that buf->len contains at least that many bytes. The outer HCI ISO length check in hci_iso() validates payload length consistency but not the minimum inner SDU header size, so a packet with payload length 1 passes hci_iso() and then reaches net_buf_pull_mem(), which asserts buf->len >= len. As a result, malformed ISO traffic deterministically triggers a kernel assert (denial of service) in assert-enabled builds, and in non-assert builds the same path may proceed with an undersized buffer, leading to out-of-bounds read behavior. The issue affects products using the Zephyr Host with CONFIG_BT_ISO_RX enabled, particularly where incoming HCI data can be influenced by a malicious or compromised controller or malformed forwarded ISO traffic.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:B0B795A3-2C8C-4ED3-A0D3-215FED5BF494']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-10658']}, {'type': 'cve', 'idList': ['CVE-2026-10658']}, {'type': 'euvd', 'idList': ['EUVD-2026-38410']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-10658']}, {'type': 'osv', 'idList': ['OSV:UBUNTU-CVE-2026-10658']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51427']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-10658']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-10711 | CVE-2026-10711 RCE in Akınsoft's CafePlus | Missing authentication for critical function vulnerability in AKIN Software Computer Import Export Industry and Trade Ltd. CafePlus allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects CafePlus: from 12.05.03 before 12.05.04. | HIGH | 8.80 | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 2026-06-23 12:08:33+03:00 | 2026-06-23 12:08:33+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-10711'] | ['CVE-2026-10711'] | b8286ba6e28c113f0c7a87061b002670d0b90652a8cd2a21dcf5391f28eee9ec | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2026-10711', 'cvss': {'score': 8.8, 'source': 'tr-cert', 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'version': '3.1', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-10711', 'type': 'cvelist', 'title': "CVE-2026-10711 RCE in Akınsoft's CafePlus", 'cvelist': ['CVE-2026-10711'], 'assigned': '2026-06-02T18:23:11', 'lastseen': '2026-06-23T13:40:43', 'modified': '2026-06-23T12:08:33', 'published': '2026-06-23T12:08:33', 'description': 'Missing authentication for critical function vulnerability in AKIN Software Computer Import Export Industry and Trade Ltd. CafePlus allows Accessing Functionality Not Properly Constrained by ACLs.\n\nThis issue affects CafePlus: from 12.05.03 before 12.05.04.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:92E458C2-DC59-4439-9B88-A6BDC5BCDA0B']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-10711']}, {'type': 'cve', 'idList': ['CVE-2026-10711']}, {'type': 'euvd', 'idList': ['EUVD-2026-38426']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-10711']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51495']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-10711']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-12479 | CVE-2026-12479 Path Traversal in keras-team/keras | A path traversal vulnerability exists in keras-team/keras version 3.14.0, specifically in the `DiskIOStore.make` method within the Keras 3 model saving and loading library. This vulnerability arises from the improper handling of user-provided layer names, which are used to construct directory paths without sanitizing for parent directory components (`..`). While forward slashes (`/`) are restricted in layer names, directory traversal sequences are not. This allows an attacker to craft a malicious Keras model that, when saved or loaded, can escape the intended temporary working directory and perform unauthorized file system operations, such as creating directories or writing files in arbitrary locations. | MEDIUM | 6.10 | CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L | 2026-06-22 15:21:19+03:00 | 2026-06-22 15:21:19+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-12479'] | ['CVE-2026-12479'] | c8d216643576e168ce46c6a8ebcad6656dc0827c0fcae930b0f6d10025334892 | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2026-12479', 'cvss': {'score': 6.1, 'source': '@huntr_ai', 'vector': 'CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L', 'version': '3.0', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-12479', 'type': 'cvelist', 'title': 'CVE-2026-12479 Path Traversal in keras-team/keras', 'cvelist': ['CVE-2026-12479'], 'assigned': '2026-06-17T00:28:44', 'lastseen': '2026-06-22T16:32:44', 'modified': '2026-06-22T15:21:19', 'published': '2026-06-22T15:21:19', 'description': 'A path traversal vulnerability exists in keras-team/keras version 3.14.0, specifically in the `DiskIOStore.make` method within the Keras 3 model saving and loading library. This vulnerability arises from the improper handling of user-provided layer names, which are used to construct directory paths without sanitizing for parent directory components (`..`). While forward slashes (`/`) are restricted in layer names, directory traversal sequences are not. This allows an attacker to craft a malicious Keras model that, when saved or loaded, can escape the intended temporary working directory and perform unauthorized file system operations, such as creating directories or writing files in arbitrary locations.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:88689AE2-5FBA-4B36-A2C1-4B1F331A617D']}, {'type': 'cve', 'idList': ['CVE-2026-12479']}, {'type': 'euvd', 'idList': ['EUVD-2026-38265']}, {'type': 'huntr', 'idList': ['188836B9-12FC-49C7-8DBF-04F60FE33743']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-12479']}, {'type': 'osv', 'idList': ['OSV:UBUNTU-CVE-2026-12479']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51329']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-12479']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-12549 | CVE-2026-12549 Libsoup: incomplete fix for cve-2026-2443: range suffix overflow in libsoup soupserver | The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a general signed comparison. When a client sends a Range request with a suffix length exceeding the content size, the resulting negative start value is not properly clamped, leading to malformed HTTP 206 responses and log flooding. | MEDIUM | 4.80 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L | 2026-06-22 13:55:06+03:00 | 2026-06-22 13:55:06+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-12549'] | ['CVE-2026-12549'] | 0fe15d89bea64fc03131faec8451892514037344bfcd7495505b1797e6d00709 | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2026-12549', 'cvss': {'score': 4.8, 'source': 'redhat', 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L', 'version': '3.1', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-12549', 'type': 'cvelist', 'title': 'CVE-2026-12549 Libsoup: incomplete fix for cve-2026-2443: range suffix overflow in libsoup soupserver', 'cvelist': ['CVE-2026-12549'], 'assigned': '2026-06-17T18:40:22', 'lastseen': '2026-06-23T14:38:44', 'modified': '2026-06-22T13:55:06', 'published': '2026-06-22T13:55:06', 'description': 'The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a general signed comparison. When a client sends a Range request with a suffix length exceeding the content size, the resulting negative start value is not properly clamped, leading to malformed HTTP 206 responses and log flooding.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:3F015C39-8E5D-460C-9C04-E0E033BE27A5']}, {'type': 'cve', 'idList': ['CVE-2026-12549']}, {'type': 'euvd', 'idList': ['EUVD-2026-38279']}, {'type': 'nessus', 'idList': ['UNPATCHED_CVE_2026_12549.NASL']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-12549']}, {'type': 'osv', 'idList': ['OSV:UBUNTU-CVE-2026-12549']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51330']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-12549']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-12580 | CVE-2026-12580 Digiwin|EasyFlow .NET - Stored Cross-Site Scripting | EasyFlow .NET developed by Digiwin has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers to inject persistent JavaScript code executed in users' browsers upon page load. | MEDIUM | 5.40 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N | 2026-06-22 09:26:04+03:00 | 2026-06-22 09:26:04+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-12580'] | ['CVE-2026-12580'] | 419c4d5aa396f71806b20f613efb35c09877e4e0dec25e7cfaf09c31d4fe20f2 | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2026-12580', 'cvss': {'score': 5.4, 'source': 'twcert', 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N', 'version': '3.1', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-12580', 'type': 'cvelist', 'title': 'CVE-2026-12580 Digiwin|EasyFlow .NET - Stored Cross-Site Scripting', 'cvelist': ['CVE-2026-12580'], 'assigned': '2026-06-18T06:51:12', 'lastseen': '2026-06-22T10:32:40', 'modified': '2026-06-22T09:26:04', 'published': '2026-06-22T09:26:04', 'description': "EasyFlow .NET developed by Digiwin has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers to inject persistent JavaScript code executed in users' browsers upon page load.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:0F303076-B2C0-40A8-A597-5A38A49C507B']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-12580']}, {'type': 'cve', 'idList': ['CVE-2026-12580']}, {'type': 'euvd', 'idList': ['EUVD-2026-38222']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-12580']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51288']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-12580']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-12581 | CVE-2026-12581 Digiwin|EasyFlow .NET - Session Fixation | EasyFlow .NET developed by Digiwin has a Session Fixation vulnerability. If unauthenticated remote attackers replace a specific session ID for a user, they can gain the user's privilege once the user logs in. | HIGH | 7.70 | CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/SC:N/VI:H/SI:N/VA:H/SA:N | 2026-06-22 09:30:38+03:00 | 2026-06-22 09:30:38+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-12581'] | ['CVE-2026-12581'] | 959d19ae1562a763272b10723208351d26d195668a46bd4b5ad6199bafad4932 | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2026-12581', 'cvss': {'score': 7.7, 'source': 'twcert', 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/SC:N/VI:H/SI:N/VA:H/SA:N', 'version': '4.0', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-12581', 'type': 'cvelist', 'title': 'CVE-2026-12581 Digiwin|EasyFlow .NET - Session Fixation', 'cvelist': ['CVE-2026-12581'], 'assigned': '2026-06-18T06:51:13', 'lastseen': '2026-06-22T10:26:40', 'modified': '2026-06-22T09:30:38', 'published': '2026-06-22T09:30:38', 'description': "EasyFlow .NET developed by Digiwin has a Session Fixation vulnerability. If unauthenticated remote attackers replace a specific session ID for a user, they can gain the user's privilege once the user logs in.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:26D9F7EF-E0F1-42E6-B457-1D72BF655414']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-12581']}, {'type': 'cve', 'idList': ['CVE-2026-12581']}, {'type': 'euvd', 'idList': ['EUVD-2026-38223']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-12581']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51289']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-12581']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-12602 | CVE-2026-12602 Incorrect permissions in ArubaSign by Aruba | Incorrect default permissions in ArubaSign, affecting versions prior to v4.6.6. The vulnerability is caused by the assignment of inappropriate permissions during the software’s default installation, whereby the main executable and other programme files located in C:\Program Files have excessive permissions for the ‘Everyone’ group. This could allow an unprivileged user to replace the main executable and/or its components with a malicious file, thereby enabling the execution of arbitrary code. In the worst-case scenario, if the malicious code is executed with elevated privileges (such as those of Administrator or SYSTEM), the attacker could escalate privileges and gain full control of the system, compromising both security and data integrity. | HIGH | 8.80 | CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/SC:H/VI:H/SI:H/VA:H/SA:H | 2026-06-22 12:34:49+03:00 | 2026-06-22 12:34:49+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-12602'] | ['CVE-2026-12602'] | 8783aebc07463a3025b64eb9cc0255c303d57db742de49135f55316dbf44e619 | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2026-12602', 'cvss': {'score': 8.8, 'source': 'incibe', 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/SC:H/VI:H/SI:H/VA:H/SA:H', 'version': '4.0', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-12602', 'type': 'cvelist', 'title': 'CVE-2026-12602 Incorrect permissions in ArubaSign by Aruba', 'cvelist': ['CVE-2026-12602'], 'assigned': '2026-06-18T11:18:05', 'lastseen': '2026-06-22T17:20:54', 'modified': '2026-06-22T12:34:49', 'published': '2026-06-22T12:34:49', 'description': 'Incorrect default permissions in ArubaSign, affecting versions prior to v4.6.6. The vulnerability is caused by the assignment of inappropriate permissions during the software’s default installation, whereby the main executable and other programme files located in C:\\Program Files have excessive permissions for the ‘Everyone’ group. This could allow an unprivileged user to replace the main executable and/or its components with a malicious file, thereby enabling the execution of arbitrary code. In the worst-case scenario, if the malicious code is executed with elevated privileges (such as those of Administrator or SYSTEM), the attacker could escalate privileges and gain full control of the system, compromising both security and data integrity.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:7948B7E9-C6DE-40B4-B63F-FB8B285A6F97']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-12602']}, {'type': 'cve', 'idList': ['CVE-2026-12602']}, {'type': 'euvd', 'idList': ['EUVD-2026-38230']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-12602']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51300']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-12602']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-12628 | CVE-2026-12628 Hardcoded credential in the IBM Storage Protect Snapshot For Windows leads to unauthorized access to system | IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows 8.1.0.0 through 8.2.1.0 could allow a remote attacker to bypass authentication due to the use of a hardcoded credential in the FlashCopy Manager (FCM) authentication mechanism. The application contains a static credential embedded in multiple authentication code paths, and does not properly validate authentication responses, which may allow an unauthenticated attacker to establish a trusted session and access protected services. This vulnerability affects client components across multiple versions and may allow an attacker to impersonate legitimate clients, potentially leading to unauthorized access to system resources. | CRITICAL | 9.10 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N | 2026-06-22 13:43:33+03:00 | 2026-06-23 18:52:31+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-12628'] | ['CVE-2026-12628'] | 2895137f6fdccb2066768e7375b470eeee2987444ed692c379a21c724335b205 | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2026-12628', 'cvss': {'score': 9.1, 'source': 'ibm', 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N', 'version': '3.1', 'severity': 'CRITICAL'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-12628', 'type': 'cvelist', 'title': 'CVE-2026-12628 Hardcoded credential in the IBM Storage Protect Snapshot For Windows leads to unauthorized access to system', 'cvelist': ['CVE-2026-12628'], 'assigned': '2026-06-18T15:18:16', 'lastseen': '2026-06-23T19:40:19', 'modified': '2026-06-23T18:52:31', 'published': '2026-06-22T13:43:33', 'description': 'IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows 8.1.0.0 through 8.2.1.0 could allow a remote attacker to bypass authentication due to the use of a hardcoded credential in the FlashCopy Manager (FCM) authentication mechanism. The application contains a static credential embedded in multiple authentication code paths, and does not properly validate authentication responses, which may allow an unauthenticated attacker to establish a trusted session and access protected services. This vulnerability affects client components across multiple versions and may allow an attacker to impersonate legitimate clients, potentially leading to unauthorized access to system resources.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:3672989E-24CF-446D-BC88-6943CD3AC7AD']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-12628']}, {'type': 'cve', 'idList': ['CVE-2026-12628']}, {'type': 'euvd', 'idList': ['EUVD-2026-38277']}, {'type': 'ibm', 'idList': ['1AF0FD585992D2BAD69C0E0E47B05C79E3D356B2A735778FDA0073F2B6A29B5B']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-12628']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51331']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-12628']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-12725 | CVE-2026-12725 Dnsmasq: dnsmasq: heap buffer overflow in log_query() when logging unsupported ds/dnskey replies | A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and
query logging are both enabled, logging of DS or DNSKEY replies containing
unsupported algorithm or digest types can cause dnsmasq to write past the end
of an internal logging buffer. A remote attacker able to supply such a DNS
response may crash the dnsmasq process, resulting in denial of service. | MEDIUM | 5.90 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H | 2026-06-22 13:55:05+03:00 | 2026-06-22 14:12:03+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-12725'] | ['CVE-2026-12725'] | 2e587d27eca4fdbac0588f1dc9281c6e8901b73c0cb9bf714d514931a4f226b4 | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2026-12725', 'cvss': {'score': 5.9, 'source': 'redhat', 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H', 'version': '3.1', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-12725', 'type': 'cvelist', 'title': 'CVE-2026-12725 Dnsmasq: dnsmasq: heap buffer overflow in log_query() when logging unsupported ds/dnskey replies', 'cvelist': ['CVE-2026-12725'], 'assigned': '2026-06-19T14:44:05', 'lastseen': '2026-06-22T18:48:30', 'modified': '2026-06-22T14:12:03', 'published': '2026-06-22T13:55:05', 'description': 'A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and\nquery logging are both enabled, logging of DS or DNSKEY replies containing\nunsupported algorithm or digest types can cause dnsmasq to write past the end\nof an internal logging buffer. A remote attacker able to supply such a DNS\nresponse may crash the dnsmasq process, resulting in denial of service.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:86457FB5-C1E8-4414-9FC4-D0F827ABABE9']}, {'type': 'cve', 'idList': ['CVE-2026-12725']}, {'type': 'euvd', 'idList': ['EUVD-2026-38278']}, {'type': 'nessus', 'idList': ['UNPATCHED_CVE_2026_12725.NASL']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-12725']}, {'type': 'osv', 'idList': ['OSV:UBUNTU-CVE-2026-12725']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51332']}, {'type': 'susecve', 'idList': ['SUSECVE:CVE-2026-12725']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-12725']}]}}, 'bulletinFamily': 'cve'} |
CVE-2021-47987 | CVE-2021-47987 Parse Server - Arbitrary Code Execution via Malicious Version Tags | Parse Server before 4.10.0 was affected by a supply chain incident in which incorrect version tags were pushed to the official repository pointing to an unreviewed personal fork of a contributor with write access. No releases were published with these tags; a project was exposed only if it defined a git-based dependency referencing one of the affected tags (for example, parse-server#4.9.3). The code behind the tags was not reviewed or approved, and although no malicious code was identified, the introduction of security vulnerabilities could not be ruled out. | HIGH | 7.70 | CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/SC:N/VI:H/SI:N/VA:H/SA:N | 2026-06-25 21:41:02+03:00 | 2026-06-25 21:41:02+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2021-47987'] | ['CVE-2021-47987'] | ce9042b542d091b363b8f3787a0b9017bde6a53b5545fdff0f4edea51e7c4b6e | 2026-06-26 15:06:33.367280+03:00 | 2026-06-26 15:06:33.367280+03:00 | {'id': 'CVELIST:CVE-2021-47987', 'cvss': {'score': 7.7, 'source': 'vulncheck', 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/SC:N/VI:H/SI:N/VA:H/SA:N', 'version': '4.0', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2021-47987', 'type': 'cvelist', 'title': 'CVE-2021-47987 Parse Server - Arbitrary Code Execution via Malicious Version Tags', 'cvelist': ['CVE-2021-47987'], 'assigned': '2026-06-21T02:08:33', 'lastseen': '2026-06-25T21:59:22', 'modified': '2026-06-25T21:41:02', 'published': '2026-06-25T21:41:02', 'description': 'Parse Server before 4.10.0 was affected by a supply chain incident in which incorrect version tags were pushed to the official repository pointing to an unreviewed personal fork of a contributor with write access. No releases were published with these tags; a project was exposed only if it defined a git-based dependency referencing one of the affected tags (for example, parse-server#4.9.3). The code behind the tags was not reviewed or approved, and although no malicious code was identified, the introduction of security vulnerabilities could not be ruled out.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:68B60196-76BF-4B2A-A08C-7AA32F2CF5FA']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2021-47987']}, {'type': 'cve', 'idList': ['CVE-2021-47987']}, {'type': 'euvd', 'idList': ['EUVD-2021-34853']}, {'type': 'nvd', 'idList': ['NVD:CVE-2021-47987']}, {'type': 'ptsecurity', 'idList': ['PT-2026-52608']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-12862 | CVE-2026-12862 XLSX formula injection in exports | Untrusted user data was passed verbatim to Excel exports for administrators. This allowed formula injection which can be used to compromise the environment of the user loading the file or other data in the file. | MEDIUM | 5.10 | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/SC:N/VI:L/SI:L/VA:N/SA:N | 2026-06-22 08:26:10+03:00 | 2026-06-22 08:26:10+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-12862'] | ['CVE-2026-12862'] | 0608521c4ad29a5282f58d6e0cd16ccd45751d75223110a502ec55d9e42bc5f0 | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2026-12862', 'cvss': {'score': 5.1, 'source': 'rami.io', 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/SC:N/VI:L/SI:L/VA:N/SA:N', 'version': '4.0', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-12862', 'type': 'cvelist', 'title': 'CVE-2026-12862 XLSX formula injection in exports', 'cvelist': ['CVE-2026-12862'], 'assigned': '2026-06-22T08:16:55', 'lastseen': '2026-06-22T13:45:14', 'modified': '2026-06-22T08:26:10', 'published': '2026-06-22T08:26:10', 'description': 'Untrusted user data was passed verbatim to Excel exports for administrators. This allowed formula injection which can be used to compromise the environment of the user loading the file or other data in the file.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:6D57D0CE-A977-4AC4-81A2-ABF9326106A1']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-12862']}, {'type': 'cve', 'idList': ['CVE-2026-12862']}, {'type': 'euvd', 'idList': ['EUVD-2026-38220']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-12862']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51290']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-12862']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-12863 | CVE-2026-12863 Open redirect | An unvalidated redirect was contained in Venueless' social login functionality and could be exploited for phishing using trusted domains. | MEDIUM | 5.10 | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/SC:N/VI:L/SI:L/VA:N/SA:N | 2026-06-22 08:41:33+03:00 | 2026-06-23 11:54:38+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-12863'] | ['CVE-2026-12863'] | e9491d9e1ea59a03fbb0cb1352e4c5646e04ea32854023789a448bc7d3f990f9 | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2026-12863', 'cvss': {'score': 5.1, 'source': 'rami.io', 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/SC:N/VI:L/SI:L/VA:N/SA:N', 'version': '4.0', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-12863', 'type': 'cvelist', 'title': 'CVE-2026-12863 Open redirect', 'cvelist': ['CVE-2026-12863'], 'assigned': '2026-06-22T08:17:20', 'lastseen': '2026-06-23T12:50:43', 'modified': '2026-06-23T11:54:38', 'published': '2026-06-22T08:41:33', 'description': "An unvalidated redirect was contained in Venueless' social login functionality and could be exploited for phishing using trusted domains.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:C117D061-EC7C-41E4-9F12-83A3BD2F32E4']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-12863']}, {'type': 'cve', 'idList': ['CVE-2026-12863']}, {'type': 'euvd', 'idList': ['EUVD-2026-38221']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-12863']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51291']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-12863']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-12866 | CVE-2026-12866 | All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. An attacker can execute arbitrary JavaScript by supplying crafted expressions that are compiled into native code using new Function(). Because user-controlled expressions are transformed directly into executable JavaScript, attackers can escape the intended expression sandbox and run arbitrary code within the application's context. | CRITICAL | 9.80 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 2026-06-23 05:00:00+03:00 | 2026-06-23 05:00:00+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-12866'] | ['CVE-2026-12866'] | 9851d5a0289b19473dedbbe173d234b7175af4f2d6388f507976d56af5d1d05b | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2026-12866', 'cvss': {'score': 9.8, 'source': 'snyk', 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H', 'version': '3.1', 'severity': 'CRITICAL'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-12866', 'type': 'cvelist', 'title': 'CVE-2026-12866', 'cvelist': ['CVE-2026-12866'], 'assigned': '2026-06-22T08:22:34', 'lastseen': '2026-06-23T12:50:43', 'modified': '2026-06-23T05:00:00', 'published': '2026-06-23T05:00:00', 'description': "All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. An attacker can execute arbitrary JavaScript by supplying crafted expressions that are compiled into native code using new Function(). Because user-controlled expressions are transformed directly into executable JavaScript, attackers can escape the intended expression sandbox and run arbitrary code within the application's context.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:B9AD2EB5-7004-4EF8-B473-06E59884E4C8']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-12866']}, {'type': 'cve', 'idList': ['CVE-2026-12866']}, {'type': 'euvd', 'idList': ['EUVD-2026-38415']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-12866']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51474']}, {'type': 'snyk', 'idList': ['SNYK:JS-EXPREVAL-15054690']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-12866']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-12888 | CVE-2026-12888 HTML injection in the Canarytoken Google Chat notification | An HTML injection vulnerability exists in the Google Chat webhook notification sent by Thinkst Applied Research Canarytokens, enabling Interface Manipulation in Google Chat. An attacker can insert limited HTML content including links.
This issue affects Canarytokens: from Docker tag sha-4aef1db90 before sha-8ab4dccd, from Git commit 4aef1db90 before 8ab4dccd. | MEDIUM | 5.10 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/SC:N/VI:N/SI:L/VA:N/SA:N/E:P/AU:N/U:Green/RE:L | 2026-06-22 13:05:53+03:00 | 2026-06-22 13:05:53+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-12888'] | ['CVE-2026-12888'] | 387a6a537f3ba7dfe28d9f27e5172c85e53f97bc43146bc52df69578a3fa8f34 | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2026-12888', 'cvss': {'score': 5.1, 'source': 'thinkstappliedresearch', 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/SC:N/VI:N/SI:L/VA:N/SA:N/E:P/AU:N/U:Green/RE:L', 'version': '4.0', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-12888', 'type': 'cvelist', 'title': 'CVE-2026-12888 HTML injection in the Canarytoken Google Chat notification', 'cvelist': ['CVE-2026-12888'], 'assigned': '2026-06-22T10:56:11', 'lastseen': '2026-06-22T15:44:28', 'modified': '2026-06-22T13:05:53', 'published': '2026-06-22T13:05:53', 'description': 'An HTML injection vulnerability exists in the Google Chat webhook notification\xa0 sent by Thinkst Applied Research Canarytokens, enabling Interface Manipulation in Google Chat. An attacker can insert limited HTML content including links.\n\n\nThis issue affects Canarytokens: from Docker tag sha-4aef1db90 before sha-8ab4dccd, from Git commit 4aef1db90 before 8ab4dccd.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:D54A113B-EDEF-40AD-8021-D343C8F8ADBE']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-12888']}, {'type': 'cve', 'idList': ['CVE-2026-12888']}, {'type': 'euvd', 'idList': ['EUVD-2026-38240']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-12888']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51301']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-12888']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-12891 | CVE-2026-12891 Gstreamer1-plugins-bad: gstreamer1-plugins-bad: global buffer overflow (oob read) in h.266/vvc vui parameter parser | A flaw was found in the GStreamer gst-plugins-bad package. When processing a malformed H.266/VVC video stream with a crafted aspect ratio indicator value, the H.266 parser performs an out-of-bounds read of up to 8 bytes from adjacent memory. This flaw allows an attacker to craft a malicious H.266 video file or stream that, when processed by a GStreamer-based application, could leak limited memory contents through video metadata, potentially exposing sensitive information from the application's address space. | MEDIUM | 4.30 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N | 2026-06-23 19:53:21+03:00 | 2026-06-23 19:53:21+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-12891'] | ['CVE-2026-12891'] | 215c9cb672a8dcf7c08d60a33ed5c4fbc4f7fdc2044a1a22622957286bff7fa5 | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2026-12891', 'cvss': {'score': 4.3, 'source': 'redhat', 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N', 'version': '3.1', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-12891', 'type': 'cvelist', 'title': 'CVE-2026-12891 Gstreamer1-plugins-bad: gstreamer1-plugins-bad: global buffer overflow (oob read) in h.266/vvc vui parameter parser', 'cvelist': ['CVE-2026-12891'], 'assigned': '2026-06-22T11:31:30', 'lastseen': '2026-06-23T20:20:10', 'modified': '2026-06-23T19:53:21', 'published': '2026-06-23T19:53:21', 'description': "A flaw was found in the GStreamer gst-plugins-bad package. When processing a malformed H.266/VVC video stream with a crafted aspect ratio indicator value, the H.266 parser performs an out-of-bounds read of up to 8 bytes from adjacent memory. This flaw allows an attacker to craft a malicious H.266 video file or stream that, when processed by a GStreamer-based application, could leak limited memory contents through video metadata, potentially exposing sensitive information from the application's address space.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:F57D6483-B818-4FAA-B2D2-3980B8457F9D']}, {'type': 'cve', 'idList': ['CVE-2026-12891']}, {'type': 'euvd', 'idList': ['EUVD-2026-38606']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-12891']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51589']}, {'type': 'redhatcve', 'idList': ['RH:CVE-2026-12891']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-12892 | CVE-2026-12892 Gstreamer1-plugins-bad: gstreamer1-plugins-bad: 1-byte heap out-of-bounds read in h.264 nal extension slice parser | A flaw was found in GStreamer's gst-plugins-bad package. When processing a specially crafted H.264 video file containing malformed MVC or SVC extension slice NAL units, a 1-byte heap out-of-bounds read can occur during parsing. This happens when the parser attempts to check slice boundary information without first verifying that the NAL unit contains enough data beyond the extension header. An attacker could exploit this by tricking a user into opening a malicious H.264 video file, potentially causing the application to crash or leak a single byte of heap memory. | MEDIUM | 4.40 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L | 2026-06-23 19:53:23+03:00 | 2026-06-23 19:53:23+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-12892'] | ['CVE-2026-12892'] | 65975a0dd3d870cfd59a94958dbac8ad16cb911a27ca274fe63e027a365057e8 | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2026-12892', 'cvss': {'score': 4.4, 'source': 'redhat', 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L', 'version': '3.1', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-12892', 'type': 'cvelist', 'title': 'CVE-2026-12892 Gstreamer1-plugins-bad: gstreamer1-plugins-bad: 1-byte heap out-of-bounds read in h.264 nal extension slice parser', 'cvelist': ['CVE-2026-12892'], 'assigned': '2026-06-22T11:32:29', 'lastseen': '2026-06-23T20:20:10', 'modified': '2026-06-23T19:53:23', 'published': '2026-06-23T19:53:23', 'description': "A flaw was found in GStreamer's gst-plugins-bad package. When processing a specially crafted H.264 video file containing malformed MVC or SVC extension slice NAL units, a 1-byte heap out-of-bounds read can occur during parsing. This happens when the parser attempts to check slice boundary information without first verifying that the NAL unit contains enough data beyond the extension header. An attacker could exploit this by tricking a user into opening a malicious H.264 video file, potentially causing the application to crash or leak a single byte of heap memory.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:69D839D5-CC5C-4DAF-AFE4-BCB9D2D99161']}, {'type': 'cve', 'idList': ['CVE-2026-12892']}, {'type': 'euvd', 'idList': ['EUVD-2026-38607']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-12892']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51590']}, {'type': 'redhatcve', 'idList': ['RH:CVE-2026-12892']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-12957 | CVE-2026-12957 Arbitrary Code Execution in Language Servers for AWS | Improper trust boundary enforcement in Language Servers for AWS before version 1.65.0 on all supported platforms may allow a for arbitrary code execution. If a local user opens a maliciously crafted workspace, any commands within the project configuration files may be automatically executed. This issue requires the user to trust the workspace when prompted.
To remediate this issue, users should upgrade to Language Servers for AWS version 1.65.0 or higher. | HIGH | 8.50 | CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/SC:N/VI:H/SI:N/VA:H/SA:N | 2026-06-23 16:02:53+03:00 | 2026-06-23 17:37:44+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-12957'] | ['CVE-2026-12957'] | da868c84186713cc8d2e158280f527489bb2b6defd747c30c2c293785910daf5 | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2026-12957', 'cvss': {'score': 8.5, 'source': 'amzn', 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/SC:N/VI:H/SI:N/VA:H/SA:N', 'version': '4.0', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-12957', 'type': 'cvelist', 'title': 'CVE-2026-12957 Arbitrary Code Execution in Language Servers for AWS', 'cvelist': ['CVE-2026-12957'], 'assigned': '2026-06-23T01:55:35', 'lastseen': '2026-06-23T18:08:57', 'modified': '2026-06-23T17:37:44', 'published': '2026-06-23T16:02:53', 'description': 'Improper trust boundary enforcement in Language Servers for AWS before version 1.65.0 on all supported platforms may allow a for arbitrary code execution. If a local user opens a maliciously crafted workspace, any commands within the project configuration files may be automatically executed. This issue requires the user to trust the workspace when prompted.\n\n\n\nTo remediate this issue, users should upgrade to Language Servers for AWS version 1.65.0 or higher.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:0FA62E27-2ECB-48A9-AE2A-DE377EBE1437']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-12957']}, {'type': 'cve', 'idList': ['CVE-2026-12957']}, {'type': 'euvd', 'idList': ['EUVD-2026-38488']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-12957']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51547']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-12957']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-12958 | CVE-2026-12958 Arbitrary file write in Language Servers for AWS | Missing symlink validation in Language Servers for AWS may allow an arbitrary file write outside of the workspace trust boundary. This may occur when a local user opens a workspace with a maliciously crafted symlink that resolves to a file path outside the workspace trust boundary.
To remediate this issue, users should upgrade to version 1.69.0 or higher. | HIGH | 8.50 | CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/SC:N/VI:H/SI:N/VA:H/SA:N | 2026-06-23 16:03:01+03:00 | 2026-06-23 17:38:05+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-12958'] | ['CVE-2026-12958'] | fe5584d45ce889c92f4e78fe0c5227429027fbb47250183658c4adc96e09f177 | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2026-12958', 'cvss': {'score': 8.5, 'source': 'amzn', 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/SC:N/VI:H/SI:N/VA:H/SA:N', 'version': '4.0', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-12958', 'type': 'cvelist', 'title': 'CVE-2026-12958 Arbitrary file write in Language Servers for AWS', 'cvelist': ['CVE-2026-12958'], 'assigned': '2026-06-23T01:55:37', 'lastseen': '2026-06-23T18:08:57', 'modified': '2026-06-23T17:38:05', 'published': '2026-06-23T16:03:01', 'description': 'Missing symlink validation in Language Servers for AWS may allow an arbitrary file write outside of the workspace trust boundary. This may occur when a local user opens a workspace with a maliciously crafted symlink that resolves to a file path outside the workspace trust boundary.\n\n\n\nTo remediate this issue, users should upgrade to version 1.69.0 or higher.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:1EAAA15A-21DD-4C13-A7DD-0642AFF998BE']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-12958']}, {'type': 'cve', 'idList': ['CVE-2026-12958']}, {'type': 'euvd', 'idList': ['EUVD-2026-38489']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-12958']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51548']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-12958']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-12969 | CVE-2026-12969 Dnsmasq: dnsmasq: out-of-bounds read in find_soa() due to missing extrabytes validation | An out-of-bounds read vulnerability exists in dnsmasq's find_soa() function in src/rfc1035.c. When parsing NS section records, extract_name() is called with extrabytes=0, failing to validate that 10 additional bytes exist for fixed-length DNS record fields. A remote attacker controlling a DNS zone can exploit this via a crafted NXDOMAIN response to cause a 10-byte heap out-of-bounds read, potentially accessing stale data from prior transactions. | MEDIUM | 5.30 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N | 2026-06-23 13:28:56+03:00 | 2026-06-23 13:28:56+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-12969'] | ['CVE-2026-12969'] | 32e58aae6ae9c79bda7d6107668fd399914427342df890efcad885c2e5687b58 | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2026-12969', 'cvss': {'score': 5.3, 'source': 'redhat', 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N', 'version': '3.1', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-12969', 'type': 'cvelist', 'title': 'CVE-2026-12969 Dnsmasq: dnsmasq: out-of-bounds read in find_soa() due to missing extrabytes validation', 'cvelist': ['CVE-2026-12969'], 'assigned': '2026-06-23T09:25:06', 'lastseen': '2026-06-23T15:52:49', 'modified': '2026-06-23T13:28:56', 'published': '2026-06-23T13:28:56', 'description': "An out-of-bounds read vulnerability exists in dnsmasq's find_soa() function in src/rfc1035.c. When parsing NS section records, extract_name() is called with extrabytes=0, failing to validate that 10 additional bytes exist for fixed-length DNS record fields. A remote attacker controlling a DNS zone can exploit this via a crafted NXDOMAIN response to cause a 10-byte heap out-of-bounds read, potentially accessing stale data from prior transactions.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:7B02CA65-C1E4-4A75-B0A3-86E4FCA76D45']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-12969']}, {'type': 'cve', 'idList': ['CVE-2026-12969']}, {'type': 'euvd', 'idList': ['EUVD-2026-38449']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-12969']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51520']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-12969']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-13007 | CVE-2026-13007 Insecure Public Caching on REST API Endpoints in Tenable Identity Exposure | Tenable Identity Exposure contains multiple unauthenticated API endpoints under /w/api/* that expose sensitive application configuration data including cleartext LDAP credentials, SAML configuration, user accounts, and directory settings to unauthenticated remote attackers. Affected responses are served with Cache-Control: public headers and without Vary: Cookie, allowing reverse proxies and CDNs to cache and serve sensitive data to unauthenticated users even after authentication is applied. | HIGH | 8.70 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/SC:L/VI:N/SI:L/VA:N/SA:N | 2026-06-23 15:59:50+03:00 | 2026-06-23 15:59:50+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-13007'] | ['CVE-2026-13007'] | 138072f4a8a75ed33292d935fc06cfa24e2eb7f8da8fd09b4cb13c8ef5e1bfa9 | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2026-13007', 'cvss': {'score': 8.7, 'source': 'tenable', 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/SC:L/VI:N/SI:L/VA:N/SA:N', 'version': '4.0', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-13007', 'type': 'cvelist', 'title': 'CVE-2026-13007 Insecure Public Caching on REST API Endpoints in Tenable Identity Exposure', 'cvelist': ['CVE-2026-13007'], 'assigned': '2026-06-23T14:57:21', 'lastseen': '2026-06-23T18:08:57', 'modified': '2026-06-23T15:59:50', 'published': '2026-06-23T15:59:50', 'description': 'Tenable Identity Exposure contains multiple unauthenticated API endpoints under /w/api/* that expose sensitive application configuration data including cleartext LDAP credentials, SAML configuration, user accounts, and directory settings to unauthenticated remote attackers. Affected responses are served with Cache-Control: public headers and without Vary: Cookie, allowing reverse proxies and CDNs to cache and serve sensitive data to unauthenticated users even after authentication is applied.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:45773FCF-F8DF-49F7-BA11-CC99F75ED6C3']}, {'type': 'cve', 'idList': ['CVE-2026-13007']}, {'type': 'euvd', 'idList': ['EUVD-2026-38487']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-13007']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51549']}, {'type': 'tenable', 'idList': ['TENABLE:62B57783F3E5F5A03959DD4C1BB5FC9A']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-13007']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-10097 | CVE-2026-10097 ML-KEM-1024 x64 AVX2 implicit rejection failure breaks IND-CCA2 security | ML-KEM-1024 x64 AVX2 implicit rejection failure in the Fujisaki-Okamoto transform breaks IND-CCA2 security, allowing decapsulation to deviate from the implicit-rejection behavior required by the standard. The AVX2 constant-time ciphertext comparison used during decapsulation never compared the final 32-byte block of the 1568-byte ML-KEM-1024 ciphertext, so a ciphertext manipulated only in those final bytes would compare as equal and decapsulation returned the real shared secret instead of performing the required implicit rejection. | MEDIUM | 6.30 | CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/SC:N/VI:L/SI:N/VA:N/SA:N | 2026-06-25 19:59:30+03:00 | 2026-06-25 19:59:30+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-10097'] | ['CVE-2026-10097'] | 532b814996297006e8b13cd5fbaac16765121b99a8f1254042b4f9f756faeb0d | 2026-06-26 15:06:33.367280+03:00 | 2026-06-26 15:06:33.367280+03:00 | {'id': 'CVELIST:CVE-2026-10097', 'cvss': {'score': 6.3, 'source': 'wolfssl', 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/SC:N/VI:L/SI:N/VA:N/SA:N', 'version': '4.0', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-10097', 'type': 'cvelist', 'title': 'CVE-2026-10097 ML-KEM-1024 x64 AVX2 implicit rejection failure breaks IND-CCA2 security', 'cvelist': ['CVE-2026-10097'], 'assigned': '2026-05-29T15:01:16', 'lastseen': '2026-06-25T20:22:25', 'modified': '2026-06-25T19:59:30', 'published': '2026-06-25T19:59:30', 'description': 'ML-KEM-1024 x64 AVX2 implicit rejection failure in the Fujisaki-Okamoto transform breaks IND-CCA2 security, allowing decapsulation to deviate from the implicit-rejection behavior required by the standard. The AVX2 constant-time ciphertext comparison used during decapsulation never compared the final 32-byte block of the 1568-byte ML-KEM-1024 ciphertext, so a ciphertext manipulated only in those final bytes would compare as equal and decapsulation returned the real shared secret instead of performing the required implicit rejection.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:815FDAD5-DED6-4D76-BFE8-56B87A6337C8']}, {'type': 'cve', 'idList': ['CVE-2026-10097']}, {'type': 'euvd', 'idList': ['EUVD-2026-39553']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-10097']}, {'type': 'ptsecurity', 'idList': ['PT-2026-52560']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-28381 | CVE-2026-28381 Local File Read/Write to Potential Privilege Escalation via Snowflake GET/PUT | The Snowflake datasource allows for GET/PUT commands, which can allow any user with access to run queries against the data source to read/write files between the local grafana server and the connected Snowflake host. | CRITICAL | 9.60 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N | 2026-06-22 13:20:29+03:00 | 2026-06-22 13:20:29+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-28381'] | ['CVE-2026-28381'] | 7bacb97641385f1ef587d971857b854658c03aa31a7a115fa20d24412cda9b55 | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2026-28381', 'cvss': {'score': 9.6, 'source': 'grafana', 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N', 'version': '3.1', 'severity': 'CRITICAL'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-28381', 'type': 'cvelist', 'title': 'CVE-2026-28381 Local File Read/Write to Potential Privilege Escalation via Snowflake GET/PUT', 'cvelist': ['CVE-2026-28381'], 'assigned': '2026-02-27T07:16:12', 'lastseen': '2026-06-22T15:44:25', 'modified': '2026-06-22T13:20:29', 'published': '2026-06-22T13:20:29', 'description': 'The Snowflake datasource allows for GET/PUT commands, which can allow any user with access to run queries against the data source to read/write files between the local grafana server and the connected Snowflake host.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:40CDBF9D-F93F-45D5-B231-40359370B5E9']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-28381']}, {'type': 'cve', 'idList': ['CVE-2026-28381']}, {'type': 'euvd', 'idList': ['EUVD-2026-38244']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-28381']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51302']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-28381']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-33760 | CVE-2026-33760 Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpoints | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow's /api/v1/monitor router exposes 7 endpoints that perform read, write, and delete operations on user-owned resources — messages, sessions, build artifacts, and LLM transaction logs — without verifying that the authenticated requester owns the targeted resource. Any authenticated user can read, modify, rename, or permanently delete another user's data by supplying the target's resource ID or flow_id. This is a classic IDOR/BOLA vulnerability. Notably, the same source file (monitor.py) contains one correctly-implemented endpoint that uses an ownership check, demonstrating the correct pattern was known but inconsistently applied. This vulnerability is fixed in 1.9.0. | HIGH | 8.80 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | 2026-06-23 16:30:16+03:00 | 2026-06-23 16:30:16+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-33760'] | ['CVE-2026-33760'] | 8cee75751706f1a80dc78e1b72f002e6622fb9e343adc4d81243d7e4efbed147 | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2026-33760', 'cvss': {'score': 8.8, 'source': 'github_m', 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'version': '3.1', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-33760', 'type': 'cvelist', 'title': 'CVE-2026-33760 Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpoints', 'cvelist': ['CVE-2026-33760'], 'assigned': '2026-03-23T18:30:14', 'lastseen': '2026-06-23T16:38:56', 'modified': '2026-06-23T16:30:16', 'published': '2026-06-23T16:30:16', 'description': "Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow's /api/v1/monitor router exposes 7 endpoints that perform read, write, and delete operations on user-owned resources — messages, sessions, build artifacts, and LLM transaction logs — without verifying that the authenticated requester owns the targeted resource. Any authenticated user can read, modify, rename, or permanently delete another user's data by supplying the target's resource ID or flow_id. This is a classic IDOR/BOLA vulnerability. Notably, the same source file (monitor.py) contains one correctly-implemented endpoint that uses an ownership check, demonstrating the correct pattern was known but inconsistently applied. This vulnerability is fixed in 1.9.0.", 'enchantments': {'dependencies': {'references': [{'type': 'circl', 'idList': ['CIRCL:CVE-2026-33760']}, {'type': 'cve', 'idList': ['CVE-2026-33760']}, {'type': 'euvd', 'idList': ['EUVD-2026-38519']}, {'type': 'github', 'idList': ['GHSA-9C59-2MVC-VFR8']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-33760']}, {'type': 'osv', 'idList': ['OSV:GHSA-9C59-2MVC-VFR8']}, {'type': 'ptsecurity', 'idList': ['PT-2026-50139']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-34912 | CVE-2026-34912 | A missing access control check when linking banners or campaigns to a zone through the zone-include.php script of Revive Adserver 6.0.6 and earlier, or via its API allows a low‑privileged user could link their zones to banners or campaigns owned by other managers on the same instance, resulting in inconsistent ownership relationships. Ownership validation has been added to ensure that banners and campaigns can only be linked to zones managed by the same account. | MEDIUM | 4.30 | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N | 2026-06-23 16:14:38+03:00 | 2026-06-23 16:14:38+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-34912'] | ['CVE-2026-34912'] | 4cf886cc31c9f1089edb7db297aef445c5dc2a335b39a58a978f284ae82071f6 | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2026-34912', 'cvss': {'score': 4.3, 'source': 'hackerone', 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N', 'version': '3.0', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-34912', 'type': 'cvelist', 'title': 'CVE-2026-34912', 'cvelist': ['CVE-2026-34912'], 'assigned': '2026-03-31T15:00:06', 'lastseen': '2026-06-23T18:08:57', 'modified': '2026-06-23T16:14:38', 'published': '2026-06-23T16:14:38', 'description': 'A missing access control check when linking banners or campaigns to a zone through the zone-include.php script of Revive Adserver 6.0.6 and earlier, or via its API allows a low‑privileged user could link their zones to banners or campaigns owned by other managers on the same instance, resulting in inconsistent ownership relationships. Ownership validation has been added to ensure that banners and campaigns can only be linked to zones managed by the same account.', 'enchantments': {'dependencies': {'references': [{'type': 'cve', 'idList': ['CVE-2026-34912']}, {'type': 'euvd', 'idList': ['EUVD-2026-38501']}, {'type': 'hackerone', 'idList': ['H1:3650504']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-34912']}, {'type': 'packetstorm', 'idList': ['PACKETSTORM:222880']}, {'type': 'packetstormnews', 'idList': ['PACKETSTORMNEWS:222800']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51550']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-34912']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-34913 | CVE-2026-34913 | A missing access control check when linking trackers to campaigns through the campaign-trackers.php script of Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to link their trackers to campaigns owned by other managers on the same instance, resulting in inconsistent ownership relationships. Ownership validation has been added to ensure that campaigns can only be linked to trackers owned by the same advertiser. | MEDIUM | 4.30 | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N | 2026-06-23 16:14:38+03:00 | 2026-06-23 16:14:38+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-34913'] | ['CVE-2026-34913'] | 1cacb4b136300ef694439293ae50a1a5dfabb5beb725860b161b3f72e89f28b1 | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2026-34913', 'cvss': {'score': 4.3, 'source': 'hackerone', 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N', 'version': '3.0', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-34913', 'type': 'cvelist', 'title': 'CVE-2026-34913', 'cvelist': ['CVE-2026-34913'], 'assigned': '2026-03-31T15:00:06', 'lastseen': '2026-06-23T17:26:52', 'modified': '2026-06-23T16:14:38', 'published': '2026-06-23T16:14:38', 'description': 'A missing access control check when linking trackers to campaigns through the campaign-trackers.php script of Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to link their trackers to campaigns owned by other managers on the same instance, resulting in inconsistent ownership relationships. Ownership validation has been added to ensure that campaigns can only be linked to trackers owned by the same advertiser.', 'enchantments': {'dependencies': {'references': [{'type': 'cve', 'idList': ['CVE-2026-34913']}, {'type': 'euvd', 'idList': ['EUVD-2026-38510']}, {'type': 'hackerone', 'idList': ['H1:3650582']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-34913']}, {'type': 'packetstorm', 'idList': ['PACKETSTORM:222880']}, {'type': 'packetstormnews', 'idList': ['PACKETSTORMNEWS:222800']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51551']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-34913']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-10098 | CVE-2026-10098 OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status | OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status allows a same-issuer SingleResponse whose serial is a prefix of the target serial to be reported as the revocation status of a different certificate. The lookup compared serial-number bytes without first requiring the two serial numbers to be of equal length, so a SingleResponse for one certificate (same issuer) whose serial is a prefix of the target's serial would match, returning the wrong certificate's status. The fix requires the serial lengths to be equal before comparing the serial bytes. | MEDIUM | 6.30 | CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/SC:N/VI:L/SI:N/VA:N/SA:N | 2026-06-25 21:16:45+03:00 | 2026-06-25 21:16:45+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-10098'] | ['CVE-2026-10098'] | 9ae072931d8fad30616ce956124bea5f449835323d3e7262596e8df1378cbb77 | 2026-06-26 15:06:33.367280+03:00 | 2026-06-26 15:06:33.367280+03:00 | {'id': 'CVELIST:CVE-2026-10098', 'cvss': {'score': 6.3, 'source': 'wolfssl', 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/SC:N/VI:L/SI:N/VA:N/SA:N', 'version': '4.0', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-10098', 'type': 'cvelist', 'title': 'CVE-2026-10098 OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status', 'cvelist': ['CVE-2026-10098'], 'assigned': '2026-05-29T15:03:08', 'lastseen': '2026-06-26T11:02:40', 'modified': '2026-06-25T21:16:45', 'published': '2026-06-25T21:16:45', 'description': "OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status allows a same-issuer SingleResponse whose serial is a prefix of the target serial to be reported as the revocation status of a different certificate. The lookup compared serial-number bytes without first requiring the two serial numbers to be of equal length, so a SingleResponse for one certificate (same issuer) whose serial is a prefix of the target's serial would match, returning the wrong certificate's status. The fix requires the serial lengths to be equal before comparing the serial bytes.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:B05531BB-61EB-4917-A3D7-39EA09236C19']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-10098']}, {'type': 'cve', 'idList': ['CVE-2026-10098']}, {'type': 'euvd', 'idList': ['EUVD-2026-39578']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-10098']}, {'type': 'ptsecurity', 'idList': ['PT-2026-52590']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-10098']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-34914 | CVE-2026-34914 | A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier. A low‑privileged user could exploit the clientid parameter to perform blind SQL injection attacks. Input sanitisation has been improved to ensure that all parameters processed by the script are properly validated. | HIGH | 8.30 | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H | 2026-06-23 16:14:38+03:00 | 2026-06-23 16:14:38+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-34914'] | ['CVE-2026-34914'] | de9a3ee58517c95597f4595009b02f7896291955b5bf8e1656f7dd442d15d6b2 | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2026-34914', 'cvss': {'score': 8.3, 'source': 'hackerone', 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H', 'version': '3.0', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-34914', 'type': 'cvelist', 'title': 'CVE-2026-34914', 'cvelist': ['CVE-2026-34914'], 'assigned': '2026-03-31T15:00:06', 'lastseen': '2026-06-23T17:32:54', 'modified': '2026-06-23T16:14:38', 'published': '2026-06-23T16:14:38', 'description': 'A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier. A low‑privileged user could exploit the clientid parameter to perform blind SQL injection attacks. Input sanitisation has been improved to ensure that all parameters processed by the script are properly validated.', 'enchantments': {'dependencies': {'references': [{'type': 'cve', 'idList': ['CVE-2026-34914']}, {'type': 'euvd', 'idList': ['EUVD-2026-38506']}, {'type': 'hackerone', 'idList': ['H1:3653196']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-34914']}, {'type': 'packetstorm', 'idList': ['PACKETSTORM:222880']}, {'type': 'packetstormnews', 'idList': ['PACKETSTORMNEWS:222800']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51552']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-34914']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-34915 | CVE-2026-34915 | A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to exploit the clientid parameter to perform blind SQL injection attacks. Input sanitisation has been improved to ensure that all parameters processed by the script are properly validated. | MEDIUM | 6.10 | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N | 2026-06-23 16:14:38+03:00 | 2026-06-23 16:14:38+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-34915'] | ['CVE-2026-34915'] | 9c134c3c4305adda6582738e8492e4d56b2467d87738ced5b64ba1f53a4ae5db | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2026-34915', 'cvss': {'score': 6.1, 'source': 'hackerone', 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N', 'version': '3.0', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-34915', 'type': 'cvelist', 'title': 'CVE-2026-34915', 'cvelist': ['CVE-2026-34915'], 'assigned': '2026-03-31T15:00:06', 'lastseen': '2026-06-23T18:08:56', 'modified': '2026-06-23T16:14:38', 'published': '2026-06-23T16:14:38', 'description': 'A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to exploit the clientid parameter to perform blind SQL injection attacks. Input sanitisation has been improved to ensure that all parameters processed by the script are properly validated.', 'enchantments': {'dependencies': {'references': [{'type': 'cve', 'idList': ['CVE-2026-34915']}, {'type': 'euvd', 'idList': ['EUVD-2026-38499']}, {'type': 'hackerone', 'idList': ['H1:3653316']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-34915']}, {'type': 'packetstorm', 'idList': ['PACKETSTORM:222880']}, {'type': 'packetstormnews', 'idList': ['PACKETSTORMNEWS:222800']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51553']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-34915']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-34916 | CVE-2026-34916 | A missing validation of user input when saving delivery limitations in Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to use the logical parameter to inject malicious PHP code into the compiledlimitations field on the database and have it executed during banner delivery. Input sanitisation has been improved to ensure that the parameter is properly validated. | HIGH | 8.80 | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | 2026-06-23 16:14:38+03:00 | 2026-06-23 16:14:38+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-34916'] | ['CVE-2026-34916'] | f8816f1a808fdb29d07b0bc684cc32dce608bdd23a0efc20af1404e254de6b5d | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2026-34916', 'cvss': {'score': 8.8, 'source': 'hackerone', 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H', 'version': '3.0', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-34916', 'type': 'cvelist', 'title': 'CVE-2026-34916', 'cvelist': ['CVE-2026-34916'], 'assigned': '2026-03-31T15:00:06', 'lastseen': '2026-06-23T17:26:52', 'modified': '2026-06-23T16:14:38', 'published': '2026-06-23T16:14:38', 'description': 'A missing validation of user input when saving delivery limitations in Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to use the logical parameter to inject malicious PHP code into the compiledlimitations field on the database and have it executed during banner delivery. Input sanitisation has been improved to ensure that the parameter is properly validated.', 'enchantments': {'dependencies': {'references': [{'type': 'cve', 'idList': ['CVE-2026-34916']}, {'type': 'euvd', 'idList': ['EUVD-2026-38507']}, {'type': 'hackerone', 'idList': ['H1:3656781']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-34916']}, {'type': 'packetstorm', 'idList': ['PACKETSTORM:222880']}, {'type': 'packetstormnews', 'idList': ['PACKETSTORMNEWS:222800']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51554']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-34916']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-34917 | CVE-2026-34917 | Low‑privileged session IDs generated for the web admin console could be reused in the XML‑RPC API, whose authentication is normally restricted to admin users. An attacker could leverage this to gain unauthorised access and exploit API‑level vulnerabilities. The session context (web/API) is now recorded along with other session data, preventing session IDs from being used interchangeably. | MEDIUM | 4.30 | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N | 2026-06-23 16:14:38+03:00 | 2026-06-23 16:14:38+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-34917'] | ['CVE-2026-34917'] | 48b14897e38546757908a5fba67b4bc05b6e34cd632abb4d742fd1430a637369 | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2026-34917', 'cvss': {'score': 4.3, 'source': 'hackerone', 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N', 'version': '3.0', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-34917', 'type': 'cvelist', 'title': 'CVE-2026-34917', 'cvelist': ['CVE-2026-34917'], 'assigned': '2026-03-31T15:00:06', 'lastseen': '2026-06-23T17:26:52', 'modified': '2026-06-23T16:14:38', 'published': '2026-06-23T16:14:38', 'description': 'Low‑privileged session IDs generated for the web admin console could be reused in the XML‑RPC API, whose authentication is normally restricted to admin users. An attacker could leverage this to gain unauthorised access and exploit API‑level vulnerabilities. The session context (web/API) is now recorded along with other session data, preventing session IDs from being used interchangeably.', 'enchantments': {'dependencies': {'references': [{'type': 'cve', 'idList': ['CVE-2026-34917']}, {'type': 'euvd', 'idList': ['EUVD-2026-38502', 'EUVD-2026-38509']}, {'type': 'hackerone', 'idList': ['H1:3672641']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-34917']}, {'type': 'packetstorm', 'idList': ['PACKETSTORM:222880']}, {'type': 'packetstormnews', 'idList': ['PACKETSTORMNEWS:222800']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51555']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-34917']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-39904 | CVE-2026-39904 Gophish 0.12.1 Denial of Service via Office Document Upload | Gophish through 0.12.1 contains a denial of service vulnerability that allows authenticated users with the User role to exhaust server memory by uploading a crafted Office document as an email template attachment. The ApplyTemplate() function in models/attachment.go processes Office documents as ZIP archives and calls ioutil.ReadAll() on each contained file entry without enforcing size restrictions on uncompressed content, allowing a zip bomb payload to expand to several gigabytes in memory and cause the process to be terminated by the operating system. | HIGH | 7.10 | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/SC:N/VI:N/SI:N/VA:H/SA:N | 2026-06-22 20:11:14+03:00 | 2026-06-22 20:11:14+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-39904'] | ['CVE-2026-39904'] | a28a9e22303a227fa892683fd6d235d352abfac19bf71542fbf75908a5fca179 | 2026-06-24 06:24:34.230611+03:00 | 2026-06-24 06:24:34.230611+03:00 | {'id': 'CVELIST:CVE-2026-39904', 'cvss': {'score': 7.1, 'source': 'vulncheck', 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/SC:N/VI:N/SI:N/VA:H/SA:N', 'version': '4.0', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-39904', 'type': 'cvelist', 'title': 'CVE-2026-39904 Gophish 0.12.1 Denial of Service via Office Document Upload', 'cvelist': ['CVE-2026-39904'], 'assigned': '2026-04-07T20:57:06', 'lastseen': '2026-06-23T14:38:43', 'modified': '2026-06-22T20:11:14', 'published': '2026-06-22T20:11:14', 'description': 'Gophish through 0.12.1 contains a denial of service vulnerability that allows authenticated users with the User role to exhaust server memory by uploading a crafted Office document as an email template attachment. The ApplyTemplate() function in models/attachment.go processes Office documents as ZIP archives and calls ioutil.ReadAll() on each contained file entry without enforcing size restrictions on uncompressed content, allowing a zip bomb payload to expand to several gigabytes in memory and cause the process to be terminated by the operating system.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:3FB4157A-6FBF-41EB-8BBA-631996E7D618']}, {'type': 'cve', 'idList': ['CVE-2026-39904']}, {'type': 'euvd', 'idList': ['EUVD-2026-38351']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-39904']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51379']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-39904']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-11310 | CVE-2026-11310 X.509 trust-chain bypass in wolfSSL_X509_verify_cert() via untrusted intermediate anchoring | X.509 trust-chain bypass in the OpenSSL compatibility certificate verifier (wolfSSL_X509_verify_cert()). This affects only builds with --enable-opensslextra (OPENSSL_EXTRA) and whose application validates certificates by calling X509_verify_cert() with caller-supplied untrusted intermediate certificates; for those users it is critical, otherwise the library is unaffected. In particular, native wolfSSL TLS/DTLS usage is not impacted. wolfSSL's X509_verify_cert() temporarily loads each caller-supplied untrusted intermediate into the certificate manager but failed to drop them before the trusted-store check, so an untrusted intermediate could anchor the path itself. An attacker can present a chain that never reaches a configured trust anchor and have it accepted, resulting in acceptance of an attacker-controlled certificate. This is certificate verification independent of TLS (e.g. S/MIME/CMS, code/firmware signing, JWT/JWS x5c), is not specific to any key type or algorithm, and a single untrusted intermediate suffices. The default wolfSSL TLS handshake (WOLFSSL_VERIFY_PEER) is not affected; only TLS applications doing manual or deferred peer verification through this API are, which also requires --enable-sessioncerts. | HIGH | 8.70 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/SC:N/VI:H/SI:N/VA:N/SA:N | 2026-06-25 19:38:19+03:00 | 2026-06-25 19:38:19+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-11310'] | ['CVE-2026-11310'] | d95d10df5f91008a9cce37dffd6fd78043ad25ecc2a15f3f34dccb17408f2518 | 2026-06-26 15:06:33.367280+03:00 | 2026-06-26 15:06:33.367280+03:00 | {'id': 'CVELIST:CVE-2026-11310', 'cvss': {'score': 8.7, 'source': 'wolfssl', 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/SC:N/VI:H/SI:N/VA:N/SA:N', 'version': '4.0', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-11310', 'type': 'cvelist', 'title': 'CVE-2026-11310 X.509 trust-chain bypass in wolfSSL_X509_verify_cert() via untrusted intermediate anchoring', 'cvelist': ['CVE-2026-11310'], 'assigned': '2026-06-04T17:58:49', 'lastseen': '2026-06-25T19:56:47', 'modified': '2026-06-25T19:38:19', 'published': '2026-06-25T19:38:19', 'description': "X.509 trust-chain bypass in the OpenSSL compatibility certificate verifier (wolfSSL_X509_verify_cert()). This affects only builds with --enable-opensslextra (OPENSSL_EXTRA) and whose application validates certificates by calling X509_verify_cert() with caller-supplied untrusted intermediate certificates; for those users it is critical, otherwise the library is unaffected. In particular, native wolfSSL TLS/DTLS usage is not impacted. wolfSSL's X509_verify_cert() temporarily loads each caller-supplied untrusted intermediate into the certificate manager but failed to drop them before the trusted-store check, so an untrusted intermediate could anchor the path itself. An attacker can present a chain that never reaches a configured trust anchor and have it accepted, resulting in acceptance of an attacker-controlled certificate. This is certificate verification independent of TLS (e.g. S/MIME/CMS, code/firmware signing, JWT/JWS x5c), is not specific to any key type or algorithm, and a single untrusted intermediate suffices. The default wolfSSL TLS handshake (WOLFSSL_VERIFY_PEER) is not affected; only TLS applications doing manual or deferred peer verification through this API are, which also requires --enable-sessioncerts.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:3FB961E1-EDA1-4A2C-9C5A-114FDD091A90']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-11310']}, {'type': 'cve', 'idList': ['CVE-2026-11310']}, {'type': 'euvd', 'idList': ['EUVD-2026-39548']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-11310']}, {'type': 'ptsecurity', 'idList': ['PT-2026-52563']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-12340 | CVE-2026-12340 Out-of-bounds heap read in SM2/SM3 certificate Subject Key Identifier computation | Out-of-bounds heap read during SM2/SM3 certificate signature verification. When parsing a certificate with an SM3wSM2 signature, the Subject Key Identifier computation reads the trailing 65 bytes of the public key without checking that the key is at least that long. A public key shorter than 65 bytes results in an out-of-bounds heap read, leading to a potential crash (denial of service); there is no out-of-bounds write. Note this only affects builds with SM2 support (--enable-sm2 or --enable-all). | MEDIUM | 6.30 | CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/SC:N/VI:N/SI:N/VA:L/SA:N | 2026-06-25 19:36:21+03:00 | 2026-06-25 19:36:21+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-12340'] | ['CVE-2026-12340'] | fa24bf8a94b921b18c54b9cb49dd3ea5df8c5131ff4273abcaa9a703eca91c4a | 2026-06-26 15:06:33.367280+03:00 | 2026-06-26 15:06:33.367280+03:00 | {'id': 'CVELIST:CVE-2026-12340', 'cvss': {'score': 6.3, 'source': 'wolfssl', 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/SC:N/VI:N/SI:N/VA:L/SA:N', 'version': '4.0', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-12340', 'type': 'cvelist', 'title': 'CVE-2026-12340 Out-of-bounds heap read in SM2/SM3 certificate Subject Key Identifier computation', 'cvelist': ['CVE-2026-12340'], 'assigned': '2026-06-15T16:30:26', 'lastseen': '2026-06-25T19:56:47', 'modified': '2026-06-25T19:36:21', 'published': '2026-06-25T19:36:21', 'description': 'Out-of-bounds heap read during SM2/SM3 certificate signature verification. When parsing a certificate with an SM3wSM2 signature, the Subject Key Identifier computation reads the trailing 65 bytes of the public key without checking that the key is at least that long. A public key shorter than 65 bytes results in an out-of-bounds heap read, leading to a potential crash (denial of service); there is no out-of-bounds write. Note this only affects builds with SM2 support (--enable-sm2 or --enable-all).', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:142B8861-742B-46E4-86A9-F447AC86A168']}, {'type': 'cve', 'idList': ['CVE-2026-12340']}, {'type': 'euvd', 'idList': ['EUVD-2026-39547']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-12340']}, {'type': 'ptsecurity', 'idList': ['PT-2026-52564']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-2053 | CVE-2026-2053 Unauthenticated Server-Side Request Forgery via WS-Addressing in WSO2 API Manager | The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or restrict user-controlled input within these headers. This omission allows an attacker to manipulate WS-Addressing headers to specify arbitrary destinations for server-initiated requests.
Successful exploitation allows an unauthenticated attacker to control the destination of server-initiated requests originating from the WSO2 API Manager. This direct control can enable unauthorized access to internal network resources or services that would typically be inaccessible from external networks. | HIGH | 8.30 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L | 2026-06-26 07:26:15+03:00 | 2026-06-26 07:26:15+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-2053'] | ['CVE-2026-2053'] | 4537d2dc6ed91ea96c6052ae27a47d4d892a27b73ad020eac98bff49d7b5c778 | 2026-06-26 15:06:33.367280+03:00 | 2026-06-26 15:06:33.367280+03:00 | {'id': 'CVELIST:CVE-2026-2053', 'cvss': {'score': 8.3, 'source': 'wso2', 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L', 'version': '3.1', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-2053', 'type': 'cvelist', 'title': 'CVE-2026-2053 Unauthenticated Server-Side Request Forgery via WS-Addressing in WSO2 API Manager', 'cvelist': ['CVE-2026-2053'], 'assigned': '2026-02-06T06:12:48', 'lastseen': '2026-06-26T07:39:38', 'modified': '2026-06-26T07:26:15', 'published': '2026-06-26T07:26:15', 'description': "The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or restrict user-controlled input within these headers. This omission allows an attacker to manipulate WS-Addressing headers to specify arbitrary destinations for server-initiated requests.\n\nSuccessful exploitation allows an unauthenticated attacker to control the destination of server-initiated requests originating from the WSO2 API Manager. This direct control can enable unauthorized access to internal network resources or services that would typically be inaccessible from external networks.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:75CEFD01-AC57-4CD7-A102-51541407168F']}, {'type': 'cve', 'idList': ['CVE-2026-2053']}, {'type': 'euvd', 'idList': ['EUVD-2026-39638']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-2053']}, {'type': 'ptsecurity', 'idList': ['PT-2026-52667']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-2299 | CVE-2026-2299 Improper Access Control in Mattermost Google Drive Plugin File Creation Endpoint | The Mattermost Google Drive plugin before version 1.1.0 fails to validate channel membership in the file creation endpoint, allowing authenticated users with a connected Google account to share Google Drive files to unauthorized private channels and disclose private channel membership. | MEDIUM | 4.20 | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N | 2026-06-25 18:55:11+03:00 | 2026-06-25 18:55:11+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-2299'] | ['CVE-2026-2299'] | 44ecdfa260db2dc82a332cdd7b06485590531b4854e0e58e29074ee3b7a4b919 | 2026-06-26 15:06:33.367280+03:00 | 2026-06-26 15:06:33.367280+03:00 | {'id': 'CVELIST:CVE-2026-2299', 'cvss': {'score': 4.2, 'source': 'mattermost', 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N', 'version': '3.1', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-2299', 'type': 'cvelist', 'title': 'CVE-2026-2299 Improper Access Control in Mattermost Google Drive Plugin File Creation Endpoint', 'cvelist': ['CVE-2026-2299'], 'assigned': '2026-02-10T16:46:56', 'lastseen': '2026-06-25T19:56:47', 'modified': '2026-06-25T18:55:11', 'published': '2026-06-25T18:55:11', 'description': 'The Mattermost Google Drive plugin before version 1.1.0 fails to validate channel membership in the file creation endpoint, allowing authenticated users with a connected Google account to share Google Drive files to unauthorized private channels and disclose private channel membership.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:363C9B40-C228-41DB-9A99-7E2DA1507D8A']}, {'type': 'cve', 'idList': ['CVE-2026-2299']}, {'type': 'euvd', 'idList': ['EUVD-2026-39540']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-2299']}, {'type': 'ptsecurity', 'idList': ['PT-2026-52566']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-40080 | CVE-2026-40080 Cacti: Open Redirect via HTTP_REFERER substring check in auth_login_redirect | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Open Redirect through a substring check rather than a host check at str_contains($referer, CACTI_PATH_URL). When the user's login_opts == '1' (redirect to referer after login), the function used $_SERVER['HTTP_REFERER'] directly. An attacker could craft a referer such as https://evil.com/cacti/. Where CACTI_PATH_URL is /cacti/, the substring matches and the user is redirected to evil.com after login. The pre-existing validate_redirect_url() helper at lib/html_utility.php performed proper validation but was not invoked from auth_login_redirect(). This issue has been fixed in version 1.2.31. | MEDIUM | 6.10 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N | 2026-06-25 22:29:51+03:00 | 2026-06-25 22:29:51+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-40080'] | ['CVE-2026-40080'] | 9fec44baa2454f3a2b1196d37cda0aeecc92390c42b5784d3b346d8ad8ad2c7e | 2026-06-26 15:06:33.367280+03:00 | 2026-06-26 15:06:33.367280+03:00 | {'id': 'CVELIST:CVE-2026-40080', 'cvss': {'score': 6.1, 'source': 'github_m', 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N', 'version': '3.1', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-40080', 'type': 'cvelist', 'title': 'CVE-2026-40080 Cacti: Open Redirect via HTTP_REFERER substring check in auth_login_redirect', 'cvelist': ['CVE-2026-40080'], 'assigned': '2026-04-09T00:39:12', 'lastseen': '2026-06-25T22:32:40', 'modified': '2026-06-25T22:29:51', 'published': '2026-06-25T22:29:51', 'description': "Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Open Redirect through a substring check rather than a host check at str_contains($referer, CACTI_PATH_URL). When the user's login_opts == '1' (redirect to referer after login), the function used $_SERVER['HTTP_REFERER'] directly. An attacker could craft a referer such as https://evil.com/cacti/. Where CACTI_PATH_URL is /cacti/, the substring matches and the user is redirected to evil.com after login. The pre-existing validate_redirect_url() helper at lib/html_utility.php performed proper validation but was not invoked from auth_login_redirect(). This issue has been fixed in version 1.2.31.", 'enchantments': {'dependencies': {'references': [{'type': 'alpinelinux', 'idList': ['ALPINE:CVE-2026-40080']}, {'type': 'attackerkb', 'idList': ['AKB:6C4D4E9E-3B39-46BE-92AC-4FFECF6662D6']}, {'type': 'cve', 'idList': ['CVE-2026-40080']}, {'type': 'debiancve', 'idList': ['DEBIANCVE:CVE-2026-40080']}, {'type': 'euvd', 'idList': ['EUVD-2026-39585']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-40080']}, {'type': 'ptsecurity', 'idList': ['PT-2026-52624']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-41479 | CVE-2026-41479 Authlib OAuth 2.0 authorization endpoint open redirects to attacker-controlled redirect_uri on unsupported response_type | Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.10 and 1.7.1, Authlib's OAuth 2.0 authorization endpoint can be turned into an unauthenticated open redirect when a request uses an unsupported response_type and supplies an attacker-controlled redirect_uri. The vulnerable behavior happens before client lookup and before any redirect URI validation. As a result, an attacker does not need a valid client registration, an authenticated user, or any prior state. A single request to the authorization endpoint is enough to obtain a 302 Location response to an arbitrary attacker-controlled URL. This vulnerability is fixed in 1.6.10 and 1.7.1. | MEDIUM | 5.40 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N | 2026-06-22 20:35:13+03:00 | 2026-06-22 20:35:13+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-41479'] | ['CVE-2026-41479'] | ccd4b8777c34088332a547d7880d38379c9b5ff6f389cbe10f55c94fa1fb8f84 | 2026-06-24 06:24:34.817328+03:00 | 2026-06-24 06:24:34.817328+03:00 | {'id': 'CVELIST:CVE-2026-41479', 'cvss': {'score': 5.4, 'source': 'github_m', 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N', 'version': '3.1', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-41479', 'type': 'cvelist', 'title': 'CVE-2026-41479 Authlib OAuth 2.0 authorization endpoint open redirects to attacker-controlled redirect_uri on unsupported response_type', 'cvelist': ['CVE-2026-41479'], 'assigned': '2026-04-20T16:14:19', 'lastseen': '2026-06-23T15:52:49', 'modified': '2026-06-22T20:35:13', 'published': '2026-06-22T20:35:13', 'description': "Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.10 and 1.7.1, Authlib's OAuth 2.0 authorization endpoint can be turned into an unauthenticated open redirect when a request uses an unsupported response_type and supplies an attacker-controlled redirect_uri. The vulnerable behavior happens before client lookup and before any redirect URI validation. As a result, an attacker does not need a valid client registration, an authenticated user, or any prior state. A single request to the authorization endpoint is enough to obtain a 302 Location response to an arbitrary attacker-controlled URL. This vulnerability is fixed in 1.6.10 and 1.7.1.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:0189293F-3039-4DCF-A55B-DF05671B08F0']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-41479']}, {'type': 'cve', 'idList': ['CVE-2026-41479']}, {'type': 'debiancve', 'idList': ['DEBIANCVE:CVE-2026-41479']}, {'type': 'euvd', 'idList': ['EUVD-2026-38360']}, {'type': 'github', 'idList': ['GHSA-W8P2-R796-3VMQ']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-41479']}, {'type': 'osv', 'idList': ['OSV:DEBIAN-CVE-2026-41479', 'OSV:GHSA-W8P2-R796-3VMQ', 'OSV:MINI-P297-6W5V-99R9', 'OSV:MINI-V75P-C3RC-GQF7', 'OSV:UBUNTU-CVE-2026-41479']}, {'type': 'ptsecurity', 'idList': ['PT-2026-47598']}, {'type': 'snyk', 'idList': ['SNYK:PYTHON-AUTHLIB-17266082']}, {'type': 'vulnersosv', 'idList': ['VULNERSOSV:BM445WB5DIMB3ALISMPXQBHPTQ', 'VULNERSOSV:UW6ZIHF7JU2A3BFBWRQBEIRYSM']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-41479']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-41523 | CVE-2026-41523 vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution | vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, an assert-based security check in vLLM's activation function loading allows any unauthenticated attacker to achieve arbitrary code execution on the server by publishing a malicious HuggingFace model, when vLLM runs in Python optimized mode (python -O or PYTHONOPTIMIZE=1). This vulnerability is fixed in 0.22.0. | HIGH | 7.50 | CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H | 2026-06-22 22:18:14+03:00 | 2026-06-22 22:18:14+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-41523'] | ['CVE-2026-41523'] | 8e4564d898227aa3bde77cc23eaa619d0584372dfdf6b0a2aa5e1669c13c72c1 | 2026-06-24 06:24:34.817328+03:00 | 2026-06-24 06:24:34.817328+03:00 | {'id': 'CVELIST:CVE-2026-41523', 'cvss': {'score': 7.5, 'source': 'github_m', 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H', 'version': '3.1', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-41523', 'type': 'cvelist', 'title': 'CVE-2026-41523 vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution', 'cvelist': ['CVE-2026-41523'], 'assigned': '2026-04-20T18:18:50', 'lastseen': '2026-06-23T12:50:42', 'modified': '2026-06-22T22:18:14', 'published': '2026-06-22T22:18:14', 'description': "vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, an assert-based security check in vLLM's activation function loading allows any unauthenticated attacker to achieve arbitrary code execution on the server by publishing a malicious HuggingFace model, when vLLM runs in Python optimized mode (python -O or PYTHONOPTIMIZE=1). This vulnerability is fixed in 0.22.0.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:BC5FFF6D-47D3-4CF8-A9A3-C0BF1718CFC7']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-41523']}, {'type': 'cve', 'idList': ['CVE-2026-41523']}, {'type': 'euvd', 'idList': ['EUVD-2026-38406']}, {'type': 'github', 'idList': ['GHSA-Q8GQ-377P-JQ3R']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-41523']}, {'type': 'osv', 'idList': ['OSV:GHSA-Q8GQ-377P-JQ3R', 'OSV:MINI-7P69-F6M2-CC4R', 'OSV:MINI-JX2C-GF52-2PW6', 'OSV:MINI-RJGP-HVFC-VVGM']}, {'type': 'ptsecurity', 'idList': ['PT-2026-50140']}, {'type': 'snyk', 'idList': ['SNYK:PYTHON-VLLM-17353931']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-41523']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-42127 | CVE-2026-42127 Grafana pre-auth DoS through arbitrarily large input to public dashboard query handler | The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability. | HIGH | 7.50 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H | 2026-06-22 16:31:28+03:00 | 2026-06-22 16:31:28+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-42127'] | ['CVE-2026-42127'] | fffe4985c3a889a95cad2c4ef28361510271ae490ca79021e7681e3dae88a4a8 | 2026-06-24 06:24:34.817328+03:00 | 2026-06-24 06:24:34.817328+03:00 | {'id': 'CVELIST:CVE-2026-42127', 'cvss': {'score': 7.5, 'source': 'grafana', 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'version': '3.1', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-42127', 'type': 'cvelist', 'title': 'CVE-2026-42127 Grafana pre-auth DoS through arbitrarily large input to public dashboard query handler', 'cvelist': ['CVE-2026-42127'], 'assigned': '2026-04-24T15:38:08', 'lastseen': '2026-06-22T17:32:46', 'modified': '2026-06-22T16:31:28', 'published': '2026-06-22T16:31:28', 'description': 'The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.', 'enchantments': {'dependencies': {'references': [{'type': 'alpinelinux', 'idList': ['ALPINE:CVE-2026-42127']}, {'type': 'attackerkb', 'idList': ['AKB:C32F0E1A-B842-4F97-B2D0-50B904370097']}, {'type': 'cve', 'idList': ['CVE-2026-42127']}, {'type': 'euvd', 'idList': ['EUVD-2026-38309']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-42127']}, {'type': 'osv', 'idList': ['OSV:UBUNTU-CVE-2026-42127']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51363']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-42127']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-42129 | CVE-2026-42129 Path Traversal in Loki Datasource leads to Internal Information Disclosure | The Loki datasource plugin's callResource handler contains a path traversal vulnerability. An authenticated Viewer-role user can escape the plugin's resource sandbox and access administrative Loki endpoints (e.g. /config, /services, /ready) to extract sensitive backend configuration and internal service information. | HIGH | 7.70 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N | 2026-06-22 13:18:27+03:00 | 2026-06-22 13:18:27+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-42129'] | ['CVE-2026-42129'] | 1df068f5ce7b1f6bb84aa7f41723f83adaefe56cfa7d0573bcf92a023435eaa2 | 2026-06-24 06:24:34.817328+03:00 | 2026-06-24 06:24:34.817328+03:00 | {'id': 'CVELIST:CVE-2026-42129', 'cvss': {'score': 7.7, 'source': 'grafana', 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N', 'version': '3.1', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-42129', 'type': 'cvelist', 'title': 'CVE-2026-42129 Path Traversal in Loki Datasource leads to Internal Information Disclosure', 'cvelist': ['CVE-2026-42129'], 'assigned': '2026-04-24T15:38:08', 'lastseen': '2026-06-22T17:20:50', 'modified': '2026-06-22T13:18:27', 'published': '2026-06-22T13:18:27', 'description': "The Loki datasource plugin's callResource handler contains a path traversal vulnerability. An authenticated Viewer-role user can escape the plugin's resource sandbox and access administrative Loki endpoints (e.g. /config, /services, /ready) to extract sensitive backend configuration and internal service information.", 'enchantments': {'dependencies': {'references': [{'type': 'alpinelinux', 'idList': ['ALPINE:CVE-2026-42129']}, {'type': 'attackerkb', 'idList': ['AKB:CDFF8776-A1DD-4F41-B836-EED0B0A8A34D']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-42129']}, {'type': 'cve', 'idList': ['CVE-2026-42129']}, {'type': 'euvd', 'idList': ['EUVD-2026-38241']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-42129']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51303']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-42129']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-42867 | CVE-2026-42867 Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vulnerable to Path Traversal in the Knowledge Bases API (POST /api/v1/knowledge_bases). This occurs because user-supplied knowledge base names are used directly to create file paths without proper sanitization or containment checks. An authenticated attacker can exploit this flaw to create directories and write files anywhere on the server's filesystem. This vulnerability is fixed in 1.9.0. | MEDIUM | 6.50 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L | 2026-06-23 16:29:11+03:00 | 2026-06-23 16:29:11+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-42867'] | ['CVE-2026-42867'] | 6d8419916e1775461aac1ca2b0ae0b459cb4976da22d499d8d6f36dca27956c5 | 2026-06-24 06:24:34.817328+03:00 | 2026-06-24 06:24:34.817328+03:00 | {'id': 'CVELIST:CVE-2026-42867', 'cvss': {'score': 6.5, 'source': 'github_m', 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L', 'version': '3.1', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-42867', 'type': 'cvelist', 'title': 'CVE-2026-42867 Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint', 'cvelist': ['CVE-2026-42867'], 'assigned': '2026-04-30T18:49:06', 'lastseen': '2026-06-23T17:02:48', 'modified': '2026-06-23T16:29:11', 'published': '2026-06-23T16:29:11', 'description': "Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vulnerable to Path Traversal in the Knowledge Bases API (POST /api/v1/knowledge_bases). This occurs because user-supplied knowledge base names are used directly to create file paths without proper sanitization or containment checks. An authenticated attacker can exploit this flaw to create directories and write files anywhere on the server's filesystem. This vulnerability is fixed in 1.9.0.", 'enchantments': {'dependencies': {'references': [{'type': 'circl', 'idList': ['CIRCL:CVE-2026-42867']}, {'type': 'cve', 'idList': ['CVE-2026-42867']}, {'type': 'euvd', 'idList': ['EUVD-2026-38518']}, {'type': 'github', 'idList': ['GHSA-79PH-745M-6WXQ']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-42867']}, {'type': 'osv', 'idList': ['OSV:GHSA-79PH-745M-6WXQ']}, {'type': 'ptsecurity', 'idList': ['PT-2026-50141']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-42867']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-40082 | CVE-2026-40082 Cacti: Session Fixation via missing session_regenerate_id() after login | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have missing session_regenerate_id() after login, leading to Session Fixation. session_regenerate_id() is NOT called after successful login. The login flow at auth_login.php:203-207 directly sets $_SESSION[SESS_USER_ID] without rotating the session ID. The session cookie configuration is otherwise good (httponly=true, samesite=Strict, secure=true for HTTPS at include/global.php:513-537), but these do not prevent session fixation via same-site vectors. This issue has been fixed in version 1.2.31. | MEDIUM | 5.40 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N | 2026-06-25 22:33:45+03:00 | 2026-06-25 22:33:45+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-40082'] | ['CVE-2026-40082'] | 841c225ad7c0671f401a34033f22bbf5ea615da452121b9240210ce18b29fd49 | 2026-06-26 15:06:33.367280+03:00 | 2026-06-26 15:06:33.367280+03:00 | {'id': 'CVELIST:CVE-2026-40082', 'cvss': {'score': 5.4, 'source': 'github_m', 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N', 'version': '3.1', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-40082', 'type': 'cvelist', 'title': 'CVE-2026-40082 Cacti: Session Fixation via missing session_regenerate_id() after login', 'cvelist': ['CVE-2026-40082'], 'assigned': '2026-04-09T00:39:12', 'lastseen': '2026-06-25T23:08:40', 'modified': '2026-06-25T22:33:45', 'published': '2026-06-25T22:33:45', 'description': 'Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have missing session_regenerate_id() after login, leading to Session Fixation. session_regenerate_id() is NOT called after successful login. The login flow at auth_login.php:203-207 directly sets $_SESSION[SESS_USER_ID] without rotating the session ID. The session cookie configuration is otherwise good (httponly=true, samesite=Strict, secure=true for HTTPS at include/global.php:513-537), but these do not prevent session fixation via same-site vectors. This issue has been fixed in version 1.2.31.', 'enchantments': {'dependencies': {'references': [{'type': 'alpinelinux', 'idList': ['ALPINE:CVE-2026-40082']}, {'type': 'attackerkb', 'idList': ['AKB:6CE54899-FC0E-423A-B9C1-AA8149E6EEC3']}, {'type': 'cve', 'idList': ['CVE-2026-40082']}, {'type': 'debiancve', 'idList': ['DEBIANCVE:CVE-2026-40082']}, {'type': 'euvd', 'idList': ['EUVD-2026-39586']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-40082']}, {'type': 'ptsecurity', 'idList': ['PT-2026-52625']}, {'type': 'redhatcve', 'idList': ['RH:CVE-2026-40082']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-45034 | CVE-2026-45034 PhpSpreadsheet: File::prohibitWrappers bypass | PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.5, CVE-2026-34084 was patched by the helper File::prohibitWrappers. The helper calls parse_url($filename, PHP_URL_SCHEME) and then checks is_string($scheme) && strlen($scheme) > 1 to reject stream wrappers such as phar://, php://, data:// or expect://. The check is not equivalent to "does the path contain a wrapper". When the input has the form phar:///path/file.phar/inner with three or more slashes after the scheme, parse_url returns boolean false instead of returning the scheme string. The is_string($scheme) branch is therefore skipped, the helper returns without throwing, and the caller proceeds. PHP's stream layer, however, still treats phar:///... as a valid phar wrapper and opens the underlying phar file. The result is that IOFactory::load($attackerPath) walks past the patch and still touches the phar wrapper. On PHP 7.x, simply reaching the phar wrapper via is_file is enough for PHP to automatically deserialize the phar metadata, which in turn invokes the magic methods __wakeup and __destruct of an attacker controlled object and gives full RCE. On PHP 8.x, automatic metadata deserialization for plain file ops was removed, so the chain at the PhpSpreadsheet layer reduces to a phar wrapper file read primitive, and RCE only resurfaces if the downstream consumer ever calls Phar::getMetadata. This vulnerability is fixed in 1.30.5. | CRITICAL | 9.20 | CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/SC:N/VI:H/SI:N/VA:H/SA:N | 2026-06-22 20:32:32+03:00 | 2026-06-22 20:32:32+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-45034'] | ['CVE-2026-45034'] | 47dd5b44c4aea3422aa0e86e2dadeecef22225f0a3c35c9440464977b9e2ef2d | 2026-06-24 06:24:34.817328+03:00 | 2026-06-24 06:24:34.817328+03:00 | {'id': 'CVELIST:CVE-2026-45034', 'cvss': {'score': 9.2, 'source': 'github_m', 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/SC:N/VI:H/SI:N/VA:H/SA:N', 'version': '4.0', 'severity': 'CRITICAL'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-45034', 'type': 'cvelist', 'title': 'CVE-2026-45034 PhpSpreadsheet: File::prohibitWrappers bypass', 'cvelist': ['CVE-2026-45034'], 'assigned': '2026-05-08T16:58:28', 'lastseen': '2026-06-23T15:56:50', 'modified': '2026-06-22T20:32:32', 'published': '2026-06-22T20:32:32', 'description': 'PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.5, CVE-2026-34084 was patched by the helper File::prohibitWrappers. The helper calls parse_url($filename, PHP_URL_SCHEME) and then checks is_string($scheme) && strlen($scheme) > 1 to reject stream wrappers such as phar://, php://, data:// or expect://. The check is not equivalent to "does the path contain a wrapper". When the input has the form phar:///path/file.phar/inner with three or more slashes after the scheme, parse_url returns boolean false instead of returning the scheme string. The is_string($scheme) branch is therefore skipped, the helper returns without throwing, and the caller proceeds. PHP\'s stream layer, however, still treats phar:///... as a valid phar wrapper and opens the underlying phar file. The result is that IOFactory::load($attackerPath) walks past the patch and still touches the phar wrapper. On PHP 7.x, simply reaching the phar wrapper via is_file is enough for PHP to automatically deserialize the phar metadata, which in turn invokes the magic methods __wakeup and __destruct of an attacker controlled object and gives full RCE. On PHP 8.x, automatic metadata deserialization for plain file ops was removed, so the chain at the PhpSpreadsheet layer reduces to a phar wrapper file read primitive, and RCE only resurfaces if the downstream consumer ever calls Phar::getMetadata. This vulnerability is fixed in 1.30.5.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:E1C3206B-50FA-4F32-8F4F-CA1E25690ED0']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-45034']}, {'type': 'cve', 'idList': ['CVE-2026-45034']}, {'type': 'euvd', 'idList': ['EUVD-2026-38359']}, {'type': 'github', 'idList': ['GHSA-87M4-826X-3CRX']}, {'type': 'githubexploit', 'idList': ['6E759A42-6EB5-5158-BC5F-E1FD8AE27F04']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-45034']}, {'type': 'osv', 'idList': ['OSV:GHSA-87M4-826X-3CRX']}, {'type': 'ptsecurity', 'idList': ['PT-2026-47606']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-45034']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-45135 | CVE-2026-45135 Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Files | Caddy is an extensible server platform that uses TLS by default. From 2.7.0 until 2.11.3, the FastCGI transport's splitPos() in modules/caddyhttp/reverseproxy/fastcgi/fastcgi.go misuses golang.org/x/text/search with search.IgnoreCase when the request path contains a non-ASCII byte. Two distinct flaws in that fallback let an attacker mislead Caddy's FastCGI splitting into treating a non-.php (or other configured split_path extension) file as a script. In any deployment where the attacker can place content into a file served via FastCGI (uploads, file storage, etc.), this can be escalated to remote code execution by crafting a URL whose path triggers either flaw. This vulnerability is fixed in 2.11.3. | HIGH | 8.10 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H | 2026-06-23 17:56:42+03:00 | 2026-06-23 17:56:42+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-45135'] | ['CVE-2026-45135'] | 4943e35f90de6afb5dd99ef32986bd9db1362d5c58bd4bfbf36682d8b54e34bb | 2026-06-24 06:24:34.817328+03:00 | 2026-06-24 06:24:34.817328+03:00 | {'id': 'CVELIST:CVE-2026-45135', 'cvss': {'score': 8.1, 'source': 'github_m', 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H', 'version': '3.1', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-45135', 'type': 'cvelist', 'title': 'CVE-2026-45135 Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Files', 'cvelist': ['CVE-2026-45135'], 'assigned': '2026-05-08T20:08:17', 'lastseen': '2026-06-23T18:32:50', 'modified': '2026-06-23T17:56:42', 'published': '2026-06-23T17:56:42', 'description': "Caddy is an extensible server platform that uses TLS by default. From 2.7.0 until 2.11.3, the FastCGI transport's splitPos() in modules/caddyhttp/reverseproxy/fastcgi/fastcgi.go misuses golang.org/x/text/search with search.IgnoreCase when the request path contains a non-ASCII byte. Two distinct flaws in that fallback let an attacker mislead Caddy's FastCGI splitting into treating a non-.php (or other configured split_path extension) file as a script. In any deployment where the attacker can place content into a file served via FastCGI (uploads, file storage, etc.), this can be escalated to remote code execution by crafting a URL whose path triggers either flaw. This vulnerability is fixed in 2.11.3.", 'enchantments': {'dependencies': {'references': [{'type': 'alpinelinux', 'idList': ['ALPINE:CVE-2026-45135']}, {'type': 'attackerkb', 'idList': ['AKB:C6170DB6-4D03-4A31-9104-566D9609E46E']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-45135']}, {'type': 'cve', 'idList': ['CVE-2026-45135']}, {'type': 'euvd', 'idList': ['EUVD-2026-38560']}, {'type': 'github', 'idList': ['GHSA-M675-2P33-XV9G']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-45135']}, {'type': 'osv', 'idList': ['OSV:GHSA-M675-2P33-XV9G', 'OSV:MINI-8QH5-R8H3-45GP']}, {'type': 'ptsecurity', 'idList': ['PT-2026-41687']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-45135']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-45692 | CVE-2026-45692 Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalization | Caddy is an extensible server platform that uses TLS by default. From 2.4.0 until 2.11.3, the authorization layer and the /config traversal layer do not agree on what object the path refers to. In this case, a path authorized for one config object is accepted, but then resolves to a different config object during traversal. This happens because the authorization layer uses string prefix matching and the /config traversal layer parses array indices numerically using strconv.Atoi(). This vulnerability is fixed in 2.11.3. | MEDIUM | 5.40 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N | 2026-06-23 17:55:11+03:00 | 2026-06-23 17:55:11+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-45692'] | ['CVE-2026-45692'] | ab99c465f011b3522cd792bb7fc481de227c066890089dd0da181b4919404691 | 2026-06-24 06:24:34.817328+03:00 | 2026-06-24 06:24:34.817328+03:00 | {'id': 'CVELIST:CVE-2026-45692', 'cvss': {'score': 5.4, 'source': 'github_m', 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N', 'version': '3.1', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-45692', 'type': 'cvelist', 'title': 'CVE-2026-45692 Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalization', 'cvelist': ['CVE-2026-45692'], 'assigned': '2026-05-13T04:38:01', 'lastseen': '2026-06-23T18:08:46', 'modified': '2026-06-23T17:55:11', 'published': '2026-06-23T17:55:11', 'description': 'Caddy is an extensible server platform that uses TLS by default. From 2.4.0 until 2.11.3, the authorization layer and the /config traversal layer do not agree on what object the path refers to. In this case, a path authorized for one config object is accepted, but then resolves to a different config object during traversal. This happens because the authorization layer uses string prefix matching and the /config traversal layer parses array indices numerically using strconv.Atoi(). This vulnerability is fixed in 2.11.3.', 'enchantments': {'dependencies': {'references': [{'type': 'alpinelinux', 'idList': ['ALPINE:CVE-2026-45692']}, {'type': 'attackerkb', 'idList': ['AKB:AF9DF82A-3475-4611-831A-342F285692B5']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-45692']}, {'type': 'cve', 'idList': ['CVE-2026-45692']}, {'type': 'euvd', 'idList': ['EUVD-2026-38559']}, {'type': 'github', 'idList': ['GHSA-X5W9-XH9R-MVFC']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-45692']}, {'type': 'osv', 'idList': ['OSV:GHSA-X5W9-XH9R-MVFC', 'OSV:MINI-FF5F-X2FR-4VXM', 'OSV:MINI-X239-2FFX-M95M']}, {'type': 'ptsecurity', 'idList': ['PT-2026-41964']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-4610 | CVE-2026-4610 ProfileGrid <= 5.9.9.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Message Content | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pm_author_message' parameter in the pm_send_message_to_author function in all versions up to, and including, 5.9.9.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability was partially patched in version 5.9.8.5. | MEDIUM | 6.40 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N | 2026-06-23 12:32:56+03:00 | 2026-06-23 12:32:56+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-4610'] | ['CVE-2026-4610'] | 502e6e087946b2a0535265db38e17749fd9cc143c63601582c988830181633f8 | 2026-06-24 06:24:34.817328+03:00 | 2026-06-24 06:24:34.817328+03:00 | {'id': 'CVELIST:CVE-2026-4610', 'cvss': {'score': 6.4, 'source': 'wordfence', 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N', 'version': '3.1', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-4610', 'type': 'cvelist', 'title': 'CVE-2026-4610 ProfileGrid <= 5.9.9.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Message Content', 'cvelist': ['CVE-2026-4610'], 'assigned': '2026-03-23T04:44:36', 'lastseen': '2026-06-23T12:50:42', 'modified': '2026-06-23T12:32:56', 'published': '2026-06-23T12:32:56', 'description': "The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pm_author_message' parameter in the pm_send_message_to_author function in all versions up to, and including, 5.9.9.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability was partially patched in version 5.9.8.5.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:2F7706EB-2F4A-4229-9118-8E4625677B7B']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-4610']}, {'type': 'cve', 'idList': ['CVE-2026-4610']}, {'type': 'euvd', 'idList': ['EUVD-2026-38447']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-4610']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51498']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-47155 | CVE-2026-47155 vLLM: Artifact Pin Decay in vLLM allows pinned deployments to load unpinned code, weights, and processors | vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, vLLM's revision pinning controls do not consistently apply to all artifacts loaded for a model. A deployment that supplies --revision or --code-revision can still load dynamic code, GGUF files, image processors, retrieval side weights, or same-repository subfolder weights/config from an unpinned/default revision. This is a supply-chain integrity issue for pinned vLLM deployments. Operators can believe they are serving a reviewed model revision while vLLM resolves behavior-affecting nested or sibling artifacts outside that reviewed revision. This vulnerability is fixed in 0.22.0. | MEDIUM | 6.50 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N | 2026-06-22 22:20:10+03:00 | 2026-06-22 22:20:10+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-47155'] | ['CVE-2026-47155'] | f00f45de1ad47470b3dd70c24be33c19688063cdefca7810863f7cc826d995f6 | 2026-06-24 06:24:34.817328+03:00 | 2026-06-24 06:24:34.817328+03:00 | {'id': 'CVELIST:CVE-2026-47155', 'cvss': {'score': 6.5, 'source': 'github_m', 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N', 'version': '3.1', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-47155', 'type': 'cvelist', 'title': 'CVE-2026-47155 vLLM: Artifact Pin Decay in vLLM allows pinned deployments to load unpinned code, weights, and processors', 'cvelist': ['CVE-2026-47155'], 'assigned': '2026-05-18T21:25:34', 'lastseen': '2026-06-23T12:50:42', 'modified': '2026-06-22T22:20:10', 'published': '2026-06-22T22:20:10', 'description': "vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, vLLM's revision pinning controls do not consistently apply to all artifacts loaded for a model. A deployment that supplies --revision or --code-revision can still load dynamic code, GGUF files, image processors, retrieval side weights, or same-repository subfolder weights/config from an unpinned/default revision. This is a supply-chain integrity issue for pinned vLLM deployments. Operators can believe they are serving a reviewed model revision while vLLM resolves behavior-affecting nested or sibling artifacts outside that reviewed revision. This vulnerability is fixed in 0.22.0.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:8D1042DF-5142-40FE-8430-BC144877C7DA']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-47155']}, {'type': 'cve', 'idList': ['CVE-2026-47155']}, {'type': 'euvd', 'idList': ['EUVD-2026-38407']}, {'type': 'github', 'idList': ['GHSA-3WW4-5JV9-J5GM']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-47155']}, {'type': 'osv', 'idList': ['OSV:GHSA-3WW4-5JV9-J5GM', 'OSV:MINI-265M-796R-J4H6', 'OSV:MINI-4GX2-8QXV-64X8', 'OSV:MINI-9M3H-GJV4-V4J8']}, {'type': 'ptsecurity', 'idList': ['PT-2026-48537']}, {'type': 'snyk', 'idList': ['SNYK:PYTHON-VLLM-17304846']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-47155']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-47240 | CVE-2026-47240 Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument | Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, several Net::IMAP commands accept a "raw data" argument that is sent verbatim after validation to prevent command injection. However, if a server does not support non-synchronizing literals, it may still be possible to inject arbitrary IMAP commands inside non-synchronizing literals. A server without support for non-synchronizing literals may interpret the "+}\r\n" as the end of a malformed command line and respond with a tagged BAD. In that case, the contents of the literal will be interpreted as one or more new pipelined commands, allowing a CRLF command injection attack to succeed. This affects criteria for #search and #uid_search; search_keys for #sort, #thread, #uid_sort, and #uid_thread; and attr for #fetch and #uid_fetch. This vulnerability is fixed in 0.6.5 and 0.5.15. | MEDIUM | 5.80 | CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/SC:N/VI:H/SI:N/VA:L/SA:N | 2026-06-22 20:17:15+03:00 | 2026-06-22 20:17:15+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-47240'] | ['CVE-2026-47240'] | 61a432211e1be856d987688eda9d986b7f564872efae224c3fd541164a37c837 | 2026-06-24 06:24:34.817328+03:00 | 2026-06-24 06:24:34.817328+03:00 | {'id': 'CVELIST:CVE-2026-47240', 'cvss': {'score': 5.8, 'source': 'github_m', 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/SC:N/VI:H/SI:N/VA:L/SA:N', 'version': '4.0', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-47240', 'type': 'cvelist', 'title': 'CVE-2026-47240 Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument', 'cvelist': ['CVE-2026-47240'], 'assigned': '2026-05-18T22:54:18', 'lastseen': '2026-06-23T15:52:48', 'modified': '2026-06-22T20:17:15', 'published': '2026-06-22T20:17:15', 'description': 'Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, several Net::IMAP commands accept a "raw data" argument that is sent verbatim after validation to prevent command injection. However, if a server does not support non-synchronizing literals, it may still be possible to inject arbitrary IMAP commands inside non-synchronizing literals. A server without support for non-synchronizing literals may interpret the "+}\\r\\n" as the end of a malformed command line and respond with a tagged BAD. In that case, the contents of the literal will be interpreted as one or more new pipelined commands, allowing a CRLF command injection attack to succeed. This affects criteria for #search and #uid_search; search_keys for #sort, #thread, #uid_sort, and #uid_thread; and attr for #fetch and #uid_fetch. This vulnerability is fixed in 0.6.5 and 0.5.15.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:5306386D-D6FF-4C21-9F65-9D0CCECFBEB7']}, {'type': 'cgr', 'idList': ['CHAINGUARD:CVE-2026-47240']}, {'type': 'cve', 'idList': ['CVE-2026-47240']}, {'type': 'euvd', 'idList': ['EUVD-2026-38352']}, {'type': 'github', 'idList': ['GHSA-8P34-64R3-MWG8']}, {'type': 'nessus', 'idList': ['RUBY_GEM_NETIMAP_CVE_2026_47240_47241_47242.NASL']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-47240']}, {'type': 'osv', 'idList': ['OSV:CGA-V4XC-FXJJ-9W6P', 'OSV:GHSA-8P34-64R3-MWG8', 'OSV:MINI-2VXC-4X6H-CJ2X', 'OSV:MINI-35G3-2376-MR42', 'OSV:MINI-7F2C-6F6R-HXMX', 'OSV:MINI-G3G9-72PV-X22M', 'OSV:MINI-JCMF-HH2H-WR2J', 'OSV:MINI-MP8Q-Q7CP-8366', 'OSV:MINI-MX77-7RCX-8WMG', 'OSV:MINI-P933-3M9M-964V', 'OSV:MINI-R499-82Q3-WRRX', 'OSV:MINI-V6H4-QGQH-5VV3', 'OSV:MINI-WG6R-8Q3G-M86G', 'OSV:MINI-WJ69-P77W-8MX6']}, {'type': 'ptsecurity', 'idList': ['PT-2026-48340']}, {'type': 'rubygems', 'idList': ['RUBY:NET-IMAP-2026-47240']}, {'type': 'snyk', 'idList': ['SNYK:RUBY-NETIMAP-17277006']}, {'type': 'susecve', 'idList': ['SUSECVE:CVE-2026-47240']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-47240']}, {'type': 'wolfi', 'idList': ['WOLFI:CVE-2026-47240']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-47241 | CVE-2026-47241 Net::IMAP: Denial of Service via incomplete raw argument validation | Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, several Net::IMAP commands accept a raw string argument which is only validated to prevent CRLF injection and then sent verbatim. If this string is derived from user-controlled input, an attacker can force the next command to be absorbed as a continuation of the first command. This will cause the first command to eventually fail, but also prevents it from returning until another command is sent (from another thread). That other command will not return until the connection is closed. This vulnerability is fixed in 0.6.5 and 0.5.15. | LOW | 2.10 | CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/SC:N/VI:N/SI:N/VA:L/SA:N | 2026-06-22 20:11:04+03:00 | 2026-06-22 20:11:04+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-47241'] | ['CVE-2026-47241'] | 9c863f2812d98e2c0f229f07af4c6641162684dfb36aceda7f4941e1af17da51 | 2026-06-24 06:24:34.817328+03:00 | 2026-06-24 06:24:34.817328+03:00 | {'id': 'CVELIST:CVE-2026-47241', 'cvss': {'score': 2.1, 'source': 'github_m', 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/SC:N/VI:N/SI:N/VA:L/SA:N', 'version': '4.0', 'severity': 'LOW'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-47241', 'type': 'cvelist', 'title': 'CVE-2026-47241 Net::IMAP: Denial of Service via incomplete raw argument validation', 'cvelist': ['CVE-2026-47241'], 'assigned': '2026-05-18T22:54:18', 'lastseen': '2026-06-23T14:38:43', 'modified': '2026-06-22T20:11:04', 'published': '2026-06-22T20:11:04', 'description': 'Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, several Net::IMAP commands accept a raw string argument which is only validated to prevent CRLF injection and then sent verbatim. If this string is derived from user-controlled input, an attacker can force the next command to be absorbed as a continuation of the first command. This will cause the first command to eventually fail, but also prevents it from returning until another command is sent (from another thread). That other command will not return until the connection is closed. This vulnerability is fixed in 0.6.5 and 0.5.15.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:2B0D91DA-14FD-4704-B5D8-F968A333D186']}, {'type': 'cgr', 'idList': ['CHAINGUARD:CVE-2026-47241']}, {'type': 'cve', 'idList': ['CVE-2026-47241']}, {'type': 'euvd', 'idList': ['EUVD-2026-38350']}, {'type': 'github', 'idList': ['GHSA-C4FP-CXRR-MJ66']}, {'type': 'nessus', 'idList': ['RUBY_GEM_NETIMAP_CVE_2026_47240_47241_47242.NASL']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-47241']}, {'type': 'osv', 'idList': ['OSV:CGA-29Q6-JFHG-VHHF', 'OSV:GHSA-C4FP-CXRR-MJ66', 'OSV:MINI-2528-PGG6-H4WP', 'OSV:MINI-2VF5-V3CJ-MWCC', 'OSV:MINI-2XHF-Q398-Q93X', 'OSV:MINI-5PC8-MVX4-VVV3', 'OSV:MINI-7J24-3V7W-QHMM', 'OSV:MINI-7PX6-FX4C-7F32', 'OSV:MINI-G4VQ-X5W2-66P9', 'OSV:MINI-HWW9-R2JP-9C2R', 'OSV:MINI-JQ65-38WF-QM57', 'OSV:MINI-R6PM-CCQM-647F', 'OSV:MINI-V2G8-5PHM-C9Q7', 'OSV:MINI-W8MM-H7MC-M5C5']}, {'type': 'ptsecurity', 'idList': ['PT-2026-48341']}, {'type': 'rubygems', 'idList': ['RUBY:NET-IMAP-2026-47241']}, {'type': 'snyk', 'idList': ['SNYK:RUBY-NETIMAP-17277057']}, {'type': 'susecve', 'idList': ['SUSECVE:CVE-2026-47241']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-47241']}, {'type': 'wolfi', 'idList': ['WOLFI:CVE-2026-47241']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-47242 | CVE-2026-47242 Net::IMAP: Command Injection via ID command argument | Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, when Net::IMAP#id is called with a hash argument, although the ID field value strings are correctly quoted (escaping quoted specials), they were not validated to prohibit CRLF sequences. While Net::IMAP#enable does process its arguments for aliases, it does not validate them as valid atoms (or as a list of valid atoms). The #to_s value is sent verbatim. Arguments to either command could be used by an attacker to inject arbitrary IMAP commands. This vulnerability is fixed in 0.6.5 and 0.5.15. | MEDIUM | 5.80 | CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/SC:N/VI:H/SI:N/VA:L/SA:N | 2026-06-22 20:19:41+03:00 | 2026-06-22 20:19:41+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-47242'] | ['CVE-2026-47242'] | e1c360e6d607f08b71a1e3c520641e58e74304d9240795d5328255d12b13755d | 2026-06-24 06:24:34.817328+03:00 | 2026-06-24 06:24:34.817328+03:00 | {'id': 'CVELIST:CVE-2026-47242', 'cvss': {'score': 5.8, 'source': 'github_m', 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/SC:N/VI:H/SI:N/VA:L/SA:N', 'version': '4.0', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-47242', 'type': 'cvelist', 'title': 'CVE-2026-47242 Net::IMAP: Command Injection via ID command argument', 'cvelist': ['CVE-2026-47242'], 'assigned': '2026-05-18T22:54:18', 'lastseen': '2026-06-23T12:50:42', 'modified': '2026-06-22T20:19:41', 'published': '2026-06-22T20:19:41', 'description': 'Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, when Net::IMAP#id is called with a hash argument, although the ID field value strings are correctly quoted (escaping quoted specials), they were not validated to prohibit CRLF sequences. While Net::IMAP#enable does process its arguments for aliases, it does not validate them as valid atoms (or as a list of valid atoms). The #to_s value is sent verbatim. Arguments to either command could be used by an attacker to inject arbitrary IMAP commands. This vulnerability is fixed in 0.6.5 and 0.5.15.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:F2DE48BF-CF55-4A76-88A6-E2385999FB83']}, {'type': 'cgr', 'idList': ['CHAINGUARD:CVE-2026-47242']}, {'type': 'cve', 'idList': ['CVE-2026-47242']}, {'type': 'euvd', 'idList': ['EUVD-2026-38353']}, {'type': 'github', 'idList': ['GHSA-46Q3-7GV7-QMGG']}, {'type': 'nessus', 'idList': ['RUBY_GEM_NETIMAP_CVE_2026_47240_47241_47242.NASL']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-47242']}, {'type': 'osv', 'idList': ['OSV:CGA-3P52-Q9CM-66F5', 'OSV:GHSA-46Q3-7GV7-QMGG', 'OSV:MINI-5RRX-5QWR-WQVM', 'OSV:MINI-5WPW-974X-P8Q7', 'OSV:MINI-6R5V-VJHV-QGRG', 'OSV:MINI-FPQQ-FPJX-CR84', 'OSV:MINI-M4MM-6G6W-Q6HW', 'OSV:MINI-P5C7-GV53-JF2W', 'OSV:MINI-PCGG-WV5G-PFR2', 'OSV:MINI-Q3J4-8CVR-7VHW', 'OSV:MINI-QJHR-4QC2-QFPR', 'OSV:MINI-RH55-X2W5-88RC', 'OSV:MINI-VJC3-GXHX-7458', 'OSV:MINI-XHPX-XG48-Q48C']}, {'type': 'ptsecurity', 'idList': ['PT-2026-48342']}, {'type': 'rubygems', 'idList': ['RUBY:NET-IMAP-2026-47242']}, {'type': 'snyk', 'idList': ['SNYK:RUBY-NETIMAP-17277096']}, {'type': 'susecve', 'idList': ['SUSECVE:CVE-2026-47242']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-47242']}, {'type': 'wolfi', 'idList': ['WOLFI:CVE-2026-47242']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-47279 | CVE-2026-47279 NocoDB: Hidden LTAR Column Exposure in Public Shared-View Relation Endpoints | NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the public shared-view relation endpoints accepted a caller-supplied column ID without verifying that the column was visible in the shared view, so anyone holding a share UUID could read links from any LTAR column on the view's table — including columns the view owner had hidden. publicMmList, publicHmList, and relDataList already ensured that the requested column belonged to the view's model, but did not check the view-column entry's show flag. This vulnerability is fixed in 2026.05.1. | MEDIUM | 6.90 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/SC:N/VI:N/SI:N/VA:N/SA:N | 2026-06-23 20:18:57+03:00 | 2026-06-23 20:18:57+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-47279'] | ['CVE-2026-47279'] | ca871a200a328e258d1b51b3f4970116c50c04a5524159b01b6cadfffc9e52af | 2026-06-24 06:24:34.817328+03:00 | 2026-06-24 06:24:34.817328+03:00 | {'id': 'CVELIST:CVE-2026-47279', 'cvss': {'score': 6.9, 'source': 'github_m', 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/SC:N/VI:N/SI:N/VA:N/SA:N', 'version': '4.0', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-47279', 'type': 'cvelist', 'title': 'CVE-2026-47279 NocoDB: Hidden LTAR Column Exposure in Public Shared-View Relation Endpoints', 'cvelist': ['CVE-2026-47279'], 'assigned': '2026-05-18T23:03:37', 'lastseen': '2026-06-23T21:02:41', 'modified': '2026-06-23T20:18:57', 'published': '2026-06-23T20:18:57', 'description': "NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the public shared-view relation endpoints accepted a caller-supplied column ID without verifying that the column was visible in the shared view, so anyone holding a share UUID could read links from any LTAR column on the view's table — including columns the view owner had hidden. publicMmList, publicHmList, and relDataList already ensured that the requested column belonged to the view's model, but did not check the view-column entry's show flag. This vulnerability is fixed in 2026.05.1.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:87145375-9C7F-446B-B807-D2A855D92D91']}, {'type': 'cve', 'idList': ['CVE-2026-47279']}, {'type': 'euvd', 'idList': ['EUVD-2026-38620']}, {'type': 'github', 'idList': ['GHSA-9WGH-M22W-9XJ8']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-47279']}, {'type': 'osv', 'idList': ['OSV:GHSA-9WGH-M22W-9XJ8']}, {'type': 'ptsecurity', 'idList': ['PT-2026-46992']}, {'type': 'snyk', 'idList': ['SNYK:JS-NOCODB-17279618']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-48491 | CVE-2026-48491 Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypass | Traefik is an HTTP reverse proxy and load balancer. From 3.7.0 until 3.7.3, there is a high severity vulnerability in Traefik's domain-fronting protection (SNICheck) that allows an unauthenticated client to bypass mutual TLS enforced through wildcard router TLSOptions. When a router uses a wildcard host rule such as Host(*.example.com) with stricter TLS options (for example RequireAndVerifyClientCert), SNICheck resolves the TLS options for the HTTP Host header using exact map lookups only and never applies wildcard matching. If another permissive SNI is served on the same entrypoint, an attacker can complete the TLS handshake under the permissive options and then send an HTTP Host header targeting the wildcard-protected backend, reaching it without presenting a client certificate. This affects the regular HTTPS / HTTP-2 path and does not require HTTP/3. This vulnerability is fixed in 3.7.3. | HIGH | 7.80 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/SC:H/VI:N/SI:H/VA:N/SA:N | 2026-06-23 19:12:10+03:00 | 2026-06-23 19:12:10+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-48491'] | ['CVE-2026-48491'] | b0ae1ac3eafc078325f9c11a5077dc73de7ed38da8f2ea918eb29ae741482075 | 2026-06-24 06:24:34.817328+03:00 | 2026-06-24 06:24:34.817328+03:00 | {'id': 'CVELIST:CVE-2026-48491', 'cvss': {'score': 7.8, 'source': 'github_m', 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/SC:H/VI:N/SI:H/VA:N/SA:N', 'version': '4.0', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-48491', 'type': 'cvelist', 'title': 'CVE-2026-48491 Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypass', 'cvelist': ['CVE-2026-48491'], 'assigned': '2026-05-21T15:33:08', 'lastseen': '2026-06-23T19:40:19', 'modified': '2026-06-23T19:12:10', 'published': '2026-06-23T19:12:10', 'description': "Traefik is an HTTP reverse proxy and load balancer. From 3.7.0 until 3.7.3, there is a high severity vulnerability in Traefik's domain-fronting protection (SNICheck) that allows an unauthenticated client to bypass mutual TLS enforced through wildcard router TLSOptions. When a router uses a wildcard host rule such as Host(*.example.com) with stricter TLS options (for example RequireAndVerifyClientCert), SNICheck resolves the TLS options for the HTTP Host header using exact map lookups only and never applies wildcard matching. If another permissive SNI is served on the same entrypoint, an attacker can complete the TLS handshake under the permissive options and then send an HTTP Host header targeting the wildcard-protected backend, reaching it without presenting a client certificate. This affects the regular HTTPS / HTTP-2 path and does not require HTTP/3. This vulnerability is fixed in 3.7.3.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:4339F627-A564-484E-B3D0-9AAA0913072C']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-48491']}, {'type': 'cve', 'idList': ['CVE-2026-48491']}, {'type': 'euvd', 'idList': ['EUVD-2026-38575']}, {'type': 'freebsd', 'idList': ['57E69B2C-67B2-11F1-B3B6-5404A68AD561']}, {'type': 'github', 'idList': ['GHSA-5R4W-85F3-PW66']}, {'type': 'nessus', 'idList': ['FREEBSD_PKG_57E69B2C67B211F1B3B65404A68AD561.NASL']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-48491']}, {'type': 'opensuse', 'idList': ['OPENSUSE-SU-2026:11047-1']}, {'type': 'osv', 'idList': ['OSV:GHSA-5R4W-85F3-PW66', 'OSV:OPENSUSE-SU-2026:11047-1']}, {'type': 'ptsecurity', 'idList': ['PT-2026-50143']}, {'type': 'susecve', 'idList': ['SUSECVE:CVE-2026-48491']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-48500 | CVE-2026-48500 Filament: Unauthenticated temporary file upload on auth pages | Filament is a collection of full-stack components for accelerated Laravel development. From 3.0.0 until 3.3.52, 4.11.5, and 5.6.5, any schema can contain a file upload form field, so Filament applies Livewire's WithFileUploads trait to the Livewire component the schema is embedded in. However, some schemas, such as the panel login form, do not require file uploads, and exposing unauthenticated temporary file uploads on these components is not an acceptable risk. On these components, an unauthenticated attacker could upload arbitrary files to the application's temporary storage, which could be abused to exhaust disk space or inflate storage costs. This vulnerability is fixed in 3.3.52, 4.11.5, and 5.6.5. | MEDIUM | 6.50 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L | 2026-06-22 21:41:17+03:00 | 2026-06-22 21:41:17+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-48500'] | ['CVE-2026-48500'] | 0e149a3b0a9d4606915bfa72da51a091f3696c110890776366b50c06bcfbb9ea | 2026-06-24 06:24:34.817328+03:00 | 2026-06-24 06:24:34.817328+03:00 | {'id': 'CVELIST:CVE-2026-48500', 'cvss': {'score': 6.5, 'source': 'github_m', 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L', 'version': '3.1', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-48500', 'type': 'cvelist', 'title': 'CVE-2026-48500 Filament: Unauthenticated temporary file upload on auth pages', 'cvelist': ['CVE-2026-48500'], 'assigned': '2026-05-21T15:33:08', 'lastseen': '2026-06-23T14:38:43', 'modified': '2026-06-22T21:41:17', 'published': '2026-06-22T21:41:17', 'description': "Filament is a collection of full-stack components for accelerated Laravel development. From 3.0.0 until 3.3.52, 4.11.5, and 5.6.5, any schema can contain a file upload form field, so Filament applies Livewire's WithFileUploads trait to the Livewire component the schema is embedded in. However, some schemas, such as the panel login form, do not require file uploads, and exposing unauthenticated temporary file uploads on these components is not an acceptable risk. On these components, an unauthenticated attacker could upload arbitrary files to the application's temporary storage, which could be abused to exhaust disk space or inflate storage costs. This vulnerability is fixed in 3.3.52, 4.11.5, and 5.6.5.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:D2B11DF5-C877-4E51-9C37-B77449B94585']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-48500']}, {'type': 'cve', 'idList': ['CVE-2026-48500']}, {'type': 'euvd', 'idList': ['EUVD-2026-38394']}, {'type': 'github', 'idList': ['GHSA-44WP-G8F4-F4V5']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-48500']}, {'type': 'osv', 'idList': ['OSV:GHSA-44WP-G8F4-F4V5']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51389']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-48500']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-48502 | CVE-2026-48502 MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows | MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePackReader.ReadDateTime() can allocate stack memory based on an attacker-controlled MessagePack extension length. In the slow path for timestamp extension parsing, the computed tokenSize includes the extension body length from the wire and is used in a stackalloc operation before the extension length is validated as one of the valid timestamp sizes. A very small payload can claim a large timestamp extension body and cause a stack allocation large enough to trigger an uncatchable StackOverflowException, terminating the host process. This vulnerability is fixed in 2.5.301 and 3.1.7. | HIGH | 8.20 | CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/SC:N/VI:N/SI:N/VA:H/SA:N | 2026-06-22 21:18:29+03:00 | 2026-06-22 21:18:29+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-48502'] | ['CVE-2026-48502'] | 1d7ae6d2df8ed705e86b24ed225c84f45b3540e897f92a2a7b2a3fad0758d142 | 2026-06-24 06:24:34.817328+03:00 | 2026-06-24 06:24:34.817328+03:00 | {'id': 'CVELIST:CVE-2026-48502', 'cvss': {'score': 8.2, 'source': 'github_m', 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/SC:N/VI:N/SI:N/VA:H/SA:N', 'version': '4.0', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-48502', 'type': 'cvelist', 'title': 'CVE-2026-48502 MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows', 'cvelist': ['CVE-2026-48502'], 'assigned': '2026-05-21T15:33:08', 'lastseen': '2026-06-23T15:52:48', 'modified': '2026-06-22T21:18:29', 'published': '2026-06-22T21:18:29', 'description': 'MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePackReader.ReadDateTime() can allocate stack memory based on an attacker-controlled MessagePack extension length. In the slow path for timestamp extension parsing, the computed tokenSize includes the extension body length from the wire and is used in a stackalloc operation before the extension length is validated as one of the valid timestamp sizes. A very small payload can claim a large timestamp extension body and cause a stack allocation large enough to trigger an uncatchable StackOverflowException, terminating the host process. This vulnerability is fixed in 2.5.301 and 3.1.7.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:D330B63C-4C7E-4809-911E-0DC7F6ECF8B9']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-48502']}, {'type': 'cve', 'idList': ['CVE-2026-48502']}, {'type': 'euvd', 'idList': ['EUVD-2026-38389']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-48502']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51390']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-48502']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-48505 | CVE-2026-48505 Filament: Multi-factor authentication (app) recovery codes can still be used multiple times via concurrent submission | Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5, a flaw in the handling of recovery codes for app-based multi-factor authentication allows the same recovery code to be reused via concurrent submission. This issue does not affect email-based MFA. It also only applies when recovery codes are enabled. If an attacker gains access to both the user's password and their recovery codes, they get two authenticated sessions per recovery code burned instead of one, or more if they batch the parallel submissions wider, materially extending the attacker's window of access compared to what the single-use guarantee implies. This vulnerability is fixed in 4.11.5 and 5.6.5. | HIGH | 7.40 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N | 2026-06-22 21:39:26+03:00 | 2026-06-22 21:42:19+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-48505'] | ['CVE-2026-48505'] | 5a750776c807361c8f96ea3589f10196c776ebf30b5b81d5e3017223e52b0a92 | 2026-06-24 06:24:34.817328+03:00 | 2026-06-24 06:24:34.817328+03:00 | {'id': 'CVELIST:CVE-2026-48505', 'cvss': {'score': 7.4, 'source': 'github_m', 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N', 'version': '3.1', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-48505', 'type': 'cvelist', 'title': 'CVE-2026-48505 Filament: Multi-factor authentication (app) recovery codes can still be used multiple times via concurrent submission', 'cvelist': ['CVE-2026-48505'], 'assigned': '2026-05-21T16:18:10', 'lastseen': '2026-06-23T14:38:43', 'modified': '2026-06-22T21:42:19', 'published': '2026-06-22T21:39:26', 'description': "Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5, a flaw in the handling of recovery codes for app-based multi-factor authentication allows the same recovery code to be reused via concurrent submission. This issue does not affect email-based MFA. It also only applies when recovery codes are enabled. If an attacker gains access to both the user's password and their recovery codes, they get two authenticated sessions per recovery code burned instead of one, or more if they batch the parallel submissions wider, materially extending the attacker's window of access compared to what the single-use guarantee implies. This vulnerability is fixed in 4.11.5 and 5.6.5.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:9833D710-90E4-4DE3-9650-056BE4E65728']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-48505']}, {'type': 'cve', 'idList': ['CVE-2026-48505']}, {'type': 'euvd', 'idList': ['EUVD-2026-38392']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-48505']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51391']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-48505']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-48506 | CVE-2026-48506 MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depth | MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePackReader.TrySkip() recursively descends into nested arrays and maps without incrementing the reader depth or calling the configured depth checks. This bypasses MessagePackSecurity.MaximumObjectGraphDepth, the library's documented protection against deeply nested object graphs. Many generated and dynamic formatters call reader.Skip() when they encounter unknown map keys, unknown array members, ignored fields, or data that should be skipped for forward compatibility. A deeply nested value in one of these skipped positions can therefore cause unbounded recursion and an uncatchable StackOverflowException. This vulnerability is fixed in 2.5.301 and 3.1.7. | HIGH | 7.50 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H | 2026-06-22 21:17:35+03:00 | 2026-06-22 21:17:35+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-48506'] | ['CVE-2026-48506'] | 78405c095a322c16593d778ed6f757e1e6c6b8303da2b3bf9fea0f9203dd1cb4 | 2026-06-24 06:24:34.817328+03:00 | 2026-06-24 06:24:34.817328+03:00 | {'id': 'CVELIST:CVE-2026-48506', 'cvss': {'score': 7.5, 'source': 'github_m', 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H', 'version': '3.1', 'severity': 'HIGH'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-48506', 'type': 'cvelist', 'title': 'CVE-2026-48506 MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depth', 'cvelist': ['CVE-2026-48506'], 'assigned': '2026-05-21T16:18:10', 'lastseen': '2026-06-23T12:50:42', 'modified': '2026-06-22T21:17:35', 'published': '2026-06-22T21:17:35', 'description': "MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePackReader.TrySkip() recursively descends into nested arrays and maps without incrementing the reader depth or calling the configured depth checks. This bypasses MessagePackSecurity.MaximumObjectGraphDepth, the library's documented protection against deeply nested object graphs. Many generated and dynamic formatters call reader.Skip() when they encounter unknown map keys, unknown array members, ignored fields, or data that should be skipped for forward compatibility. A deeply nested value in one of these skipped positions can therefore cause unbounded recursion and an uncatchable StackOverflowException. This vulnerability is fixed in 2.5.301 and 3.1.7.", 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:34445DE6-5B1F-46A0-8455-89E2CAE7C4E2']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-48506']}, {'type': 'cve', 'idList': ['CVE-2026-48506']}, {'type': 'euvd', 'idList': ['EUVD-2026-38388']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-48506']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51392']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-48506']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-48509 | CVE-2026-48509 MessagePack-CSharp: ASP.NET Core MessagePackInputFormatter defaults to TrustedData for HTTP request bodies | MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, the parameterless MessagePackInputFormatter() constructor uses default serializer options, which resolve to MessagePackSerializerOptions.Standard with MessagePackSecurity.TrustedData. The formatter is designed for ASP.NET Core MVC request bodies, which commonly cross an HTTP trust boundary. This insecure default can expose applications to denial-of-service attacks that MessagePackSecurity.UntrustedData is intended to mitigate, such as hash-collision attacks against dictionary-like model properties. This vulnerability is fixed in 2.5.301 and 3.1.7. | MEDIUM | 6.30 | CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/SC:N/VI:L/SI:N/VA:L/SA:N | 2026-06-22 21:16:50+03:00 | 2026-06-22 21:16:50+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-48509'] | ['CVE-2026-48509'] | 50c5b9782780309c4b91371abae57e3f9ea380c95a31e146e355d030e32b181b | 2026-06-24 06:24:34.817328+03:00 | 2026-06-24 06:24:34.817328+03:00 | {'id': 'CVELIST:CVE-2026-48509', 'cvss': {'score': 6.3, 'source': 'github_m', 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/SC:N/VI:L/SI:N/VA:L/SA:N', 'version': '4.0', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-48509', 'type': 'cvelist', 'title': 'CVE-2026-48509 MessagePack-CSharp: ASP.NET Core MessagePackInputFormatter defaults to TrustedData for HTTP request bodies', 'cvelist': ['CVE-2026-48509'], 'assigned': '2026-05-21T16:18:10', 'lastseen': '2026-06-23T13:44:44', 'modified': '2026-06-22T21:16:50', 'published': '2026-06-22T21:16:50', 'description': 'MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, the parameterless MessagePackInputFormatter() constructor uses default serializer options, which resolve to MessagePackSerializerOptions.Standard with MessagePackSecurity.TrustedData. The formatter is designed for ASP.NET Core MVC request bodies, which commonly cross an HTTP trust boundary. This insecure default can expose applications to denial-of-service attacks that MessagePackSecurity.UntrustedData is intended to mitigate, such as hash-collision attacks against dictionary-like model properties. This vulnerability is fixed in 2.5.301 and 3.1.7.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:033E4CB7-BB90-424E-99BC-26B1D1B96DF3']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-48509']}, {'type': 'cve', 'idList': ['CVE-2026-48509']}, {'type': 'euvd', 'idList': ['EUVD-2026-38387']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-48509']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51393']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-48509']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-48510 | CVE-2026-48510 MessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengths | MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, when MessagePack-CSharp decompresses Lz4Block or Lz4BlockArray payloads, it reads declared uncompressed lengths from the wire and allocates output buffers based on those lengths before validating that the compressed data is valid or that the declared expansion is reasonable. A small payload can claim a very large uncompressed length and force a large allocation before LZ4 decoding begins. This vulnerability is fixed in 2.5.301 and 3.1.7. | MEDIUM | 6.30 | CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/SC:N/VI:N/SI:N/VA:L/SA:N | 2026-06-22 21:16:04+03:00 | 2026-06-22 21:16:04+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-48510'] | ['CVE-2026-48510'] | 2d027a0f159f5ab8e9173b55f3bddb503f40a6292368c027eb18f19badc5af31 | 2026-06-24 06:24:34.817328+03:00 | 2026-06-24 06:24:34.817328+03:00 | {'id': 'CVELIST:CVE-2026-48510', 'cvss': {'score': 6.3, 'source': 'github_m', 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/SC:N/VI:N/SI:N/VA:L/SA:N', 'version': '4.0', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-48510', 'type': 'cvelist', 'title': 'CVE-2026-48510 MessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengths', 'cvelist': ['CVE-2026-48510'], 'assigned': '2026-05-21T16:18:10', 'lastseen': '2026-06-23T12:50:42', 'modified': '2026-06-22T21:16:04', 'published': '2026-06-22T21:16:04', 'description': 'MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, when MessagePack-CSharp decompresses Lz4Block or Lz4BlockArray payloads, it reads declared uncompressed lengths from the wire and allocates output buffers based on those lengths before validating that the compressed data is valid or that the declared expansion is reasonable. A small payload can claim a very large uncompressed length and force a large allocation before LZ4 decoding begins. This vulnerability is fixed in 2.5.301 and 3.1.7.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:8E68392E-0D81-4614-801C-B2D86034677E']}, {'type': 'circl', 'idList': ['CIRCL:CVE-2026-48510']}, {'type': 'cve', 'idList': ['CVE-2026-48510']}, {'type': 'euvd', 'idList': ['EUVD-2026-38386']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-48510']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51394']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-48510']}]}}, 'bulletinFamily': 'cve'} |
CVE-2026-48511 | CVE-2026-48511 MessagePack-CSharp: ExpandoObject formatter can perform quadratic insertion work on untrusted maps | MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, ExpandoObjectFormatter.Deserialize populates System.Dynamic.ExpandoObject by calling IDictionary<string, object>.Add for each map entry. ExpandoObject internally maintains member names in array-like structures, so inserting many distinct keys can require repeated linear scans and array copies. For large attacker-controlled maps, this produces quadratic CPU and allocation behavior. The issue is especially surprising because ExpandoObjectResolver.Options is configured with MessagePackSecurity.UntrustedData, but collision-resistant dictionary comparers cannot protect ExpandoObject insertion internals. This vulnerability is fixed in 2.5.301 and 3.1.7. | MEDIUM | 6.30 | CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/SC:N/VI:N/SI:N/VA:L/SA:N | 2026-06-22 21:14:54+03:00 | 2026-06-22 21:14:54+03:00 | ['https://www.cve.org/CVERecord?id=CVE-2026-48511'] | ['CVE-2026-48511'] | 67aa93be9feb7fc88f6d15035bf1ffbc793b2dad30b60df200de7500645de21c | 2026-06-24 06:24:34.817328+03:00 | 2026-06-24 06:24:34.817328+03:00 | {'id': 'CVELIST:CVE-2026-48511', 'cvss': {'score': 6.3, 'source': 'github_m', 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/SC:N/VI:N/SI:N/VA:L/SA:N', 'version': '4.0', 'severity': 'MEDIUM'}, 'href': 'https://www.cve.org/CVERecord?id=CVE-2026-48511', 'type': 'cvelist', 'title': 'CVE-2026-48511 MessagePack-CSharp: ExpandoObject formatter can perform quadratic insertion work on untrusted maps', 'cvelist': ['CVE-2026-48511'], 'assigned': '2026-05-21T16:18:10', 'lastseen': '2026-06-23T15:52:48', 'modified': '2026-06-22T21:14:54', 'published': '2026-06-22T21:14:54', 'description': 'MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, ExpandoObjectFormatter.Deserialize populates System.Dynamic.ExpandoObject by calling IDictionary<string, object>.Add for each map entry. ExpandoObject internally maintains member names in array-like structures, so inserting many distinct keys can require repeated linear scans and array copies. For large attacker-controlled maps, this produces quadratic CPU and allocation behavior. The issue is especially surprising because ExpandoObjectResolver.Options is configured with MessagePackSecurity.UntrustedData, but collision-resistant dictionary comparers cannot protect ExpandoObject insertion internals. This vulnerability is fixed in 2.5.301 and 3.1.7.', 'enchantments': {'dependencies': {'references': [{'type': 'attackerkb', 'idList': ['AKB:7B279375-3AC4-4C47-BA64-133E7B7B41EC']}, {'type': 'cve', 'idList': ['CVE-2026-48511']}, {'type': 'euvd', 'idList': ['EUVD-2026-38385']}, {'type': 'nvd', 'idList': ['NVD:CVE-2026-48511']}, {'type': 'ptsecurity', 'idList': ['PT-2026-51395']}, {'type': 'vulnrichment', 'idList': ['VULNRICHMENT:CVE-2026-48511']}]}}, 'bulletinFamily': 'cve'} |