{"published_count":432,"discovered_count":440,"count":432,"cves":[{"cve_id":"CVE-2026-24908","title":"SQL injection in the Patient REST API via the _sort parameter","description":"OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, an SQL injection vulnerability in the Patient REST API endpoint allows authenticated users with API access to execute arbitrary SQL queries through the `_sort` parameter. This could potentially lead to database access, PHI (Protected Health Information) exposure, and credential compromise. The issue occurs when user-supplied sort field names are used in ORDER BY clauses without proper validation or identifier escaping. Version 8.0.0 fixes the issue.","severity":"critical","cvss_score":10.0,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","cwe":"CWE-89","product":"openemr","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-24908","published":"2026-02-25"},{"cve_id":"CVE-2026-24898","title":"Unauthenticated MedEx API token disclosure via the callback endpoint","description":"OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0, an unauthenticated token disclosure vulnerability in the MedEx callback endpoint allows any unauthenticated visitor to obtain the practice's MedEx API tokens, leading to complete third-party service compromise, PHI exfiltration, unauthorized actions on the MedEx platform, and HIPAA violations. The vulnerability exists because the endpoint bypasses authentication ($ignoreAuth = true) and performs a MedEx login whenever $_POST['callback_key'] is provided, returning the full JSON response including sensitive API tokens. This vulnerability is fixed in 8.0.0.","severity":"critical","cvss_score":10,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","cwe":"CWE-287","product":"openemr","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-24898","published":"2026-03-03"},{"cve_id":"CVE-2025-10230","title":"Unauthenticated command injection via NetBIOS names in the WINS server hook script","description":"A flaw was found in Samba, in the front-end WINS hook handling: NetBIOS names from registration packets are passed to a shell without proper validation or escaping. Unsanitized NetBIOS name data from WINS registration packets are inserted into a shell command and executed by the Samba Active Directory Domain Controller’s wins hook, allowing an unauthenticated network attacker to achieve remote command execution as the Samba process.","severity":"critical","cvss_score":10,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","cwe":"CWE-78","product":"Samba","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2025-10230","published":"2025-11-07"},{"cve_id":"CVE-2026-40472","title":"Stored XSS via package metadata rendered unescaped in href attributes","description":"In hackage-server, user-controlled metadata from .cabal files are rendered into HTML\nhref attributes without proper sanitization, enabling stored\nCross-Site Scripting (XSS) attacks.","severity":"critical","cvss_score":9.9,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L","cwe":"CWE-79","product":"hackage-server","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-40472","published":"2026-04-23"},{"cve_id":"CVE-2026-75143","title":"FFmpeg Heap Buffer Overflow via RIST Protocol Reader","description":"FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (libavformat/librist.c). librist_read() ignored its size argument and copied the full received payload length into the caller-provided destination buffer, overflowing it when the payload exceeds the destination size. This is reachable via the async:rist:// URL scheme, where the async wrapper supplies a smaller buffer than the received payload. A remote RIST sender can trigger the overflow by sending a packet whose payload exceeds the caller buffer size.","severity":"critical","cvss_score":9.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":"CWE-122","product":"FFmpeg","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-75143","published":"2026-08-20"},{"cve_id":"CVE-2026-58097","title":"ppp(8): missing length validation in mp_SetEnddisc()","description":"mp_SetEnddisc() copied a user-supplied PSN endpoint value without length validation, allowing a buffer overflow via the ppp(8) command interface.\n\nA local user with access to the ppp(8) command interface can crash ppp(8) or potentially execute arbitrary code as root.","severity":"critical","cvss_score":9.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":"CWE-130","product":"FreeBSD","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-58097","published":"2026-08-26"},{"cve_id":"CVE-2026-58096","title":"ppp(8): missing length validation in LcpDecodeConfig()","description":"LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the minimum required by RFC 1717.  Undersized options would trigger an out-of-bounds write.\n\nA malicious PPP peer can exploit CVE-2026-58095 and CVE-2026-58096 to crash ppp(8) or potentially execute arbitrary code as root.","severity":"critical","cvss_score":9.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":"CWE-130","product":"FreeBSD","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-58096","published":"2026-08-26"},{"cve_id":"CVE-2026-58095","title":"ppp(8): incorrect length calculation in mp_Enddisc()","description":"mp_Enddisc() used incorrect length calculations when formatting endpoint discriminator addresses for display, allowing a received endpoint option to overflow a global result buffer.\n\nA malicious PPP peer can crash ppp(8) or potentially execute arbitrary code as root.","severity":"critical","cvss_score":9.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":"CWE-122","product":"FreeBSD","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-58095","published":"2026-08-26"},{"cve_id":"CVE-2026-49420","title":"Buffer overflow in libalias RTSP handler","description":"The RTSP handler in libalias rewrote outgoing packets into a fixed-length stack buffer without checking whether the rewritten data fit in the buffer, or whether the result fit back in the original packet.\n\nA host sending crafted RTSP traffic from inside a NAT gateway using libalias can overflow a stack buffer, potentially achieving remote code execution in the kernel (when using ipfw(4) NAT) or in the natd(8) process (which generally runs as the root user).","severity":"critical","cvss_score":9.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":"CWE-121","product":"FreeBSD","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-49420","published":"2026-08-19"},{"cve_id":"CVE-2026-44170","title":"Argument injection in the CONNECT engine's curl command line via the table HTTP attribute","description":"MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, MariaDB on WIndows with installed CONNECT engine and enabled REST support interpolated table HTTP attribute into the curl command line without proper sanitizing. This allows the user to execute shell commands on the server. This issue has been patched in versions 10.6.26, 10.11.17, 11.4.11, 11.8.7, and 12.3.2.","severity":"critical","cvss_score":9.8,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N","cwe":"CWE-78","product":"MariaDB","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-44170","published":"2026-06-12"},{"cve_id":"CVE-2026-42010","title":"Authentication bypass via NUL character in RSA-PSK usernames","description":"A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process.","severity":"critical","cvss_score":9.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","cwe":"CWE-170","product":"GnuTLS","reference_count":21,"url":"https://www.cve.org/CVERecord?id=CVE-2026-42010","published":"2026-05-07"},{"cve_id":"CVE-2026-29167","title":"Use-after-free in mod_ldap with per-directory configuration","description":"Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.\n\nUsers are recommended to upgrade to version 2.4.68, which fixes the issue.","severity":"critical","cvss_score":9.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":"CWE-416","product":"Apache HTTP Server","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-29167","published":"2026-06-08"},{"cve_id":"CVE-2026-28808","title":"Authentication bypass for ScriptAlias CGI scripts via a mod_auth/mod_cgi path mismatch","description":"Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protected by directory rules when served via script_alias.\n\nWhen script_alias maps a URL prefix to a directory outside DocumentRoot, mod_auth evaluates directory-based access controls against the DocumentRoot-relative path while mod_cgi executes the script at the ScriptAlias-resolved path. This path mismatch allows unauthenticated access to CGI scripts that directory rules were meant to protect.\n\nThis vulnerability is associated with program files lib/inets/src/http_server/mod_alias.erl, lib/inets/src/http_server/mod_auth.erl, and lib/inets/src/http_server/mod_cgi.erl.\n\nThis issue affects OTP from OTP 17.0 until OTP 28.4.2, 27.3.4.10 and 26.2.5.19 corresponding to inets from 5.10 until 9.6.2, 9.3.2.4 and 9.1.0.6.","severity":"critical","cvss_score":9.8,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N","cwe":"CWE-863","product":"OTP","reference_count":6,"url":"https://www.cve.org/CVERecord?id=CVE-2026-28808","published":"2026-04-07"},{"cve_id":"CVE-2026-28474","title":"Allowlist bypass via spoofed actor.name display names in the Nextcloud Talk plugin","description":"OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matching on the mutable actor.name display name field for allowlist validation, allowing attackers to bypass DM and room allowlists. An attacker can change their Nextcloud display name to match an allowlisted user ID and gain unauthorized access to restricted conversations.","severity":"critical","cvss_score":9.8,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","cwe":"CWE-863","product":"nextcloud-talk","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-28474","published":"2026-03-05"},{"cve_id":"CVE-2026-28470","title":"Exec allowlist bypass via command substitution inside double-quoted strings","description":"OpenClaw versions prior to 2026.2.2 contain an exec approvals (must be enabled) allowlist bypass vulnerability that allows attackers to execute arbitrary commands by injecting command substitution syntax. Attackers can bypass the allowlist protection by embedding unescaped $() or backticks inside double-quoted strings to execute unauthorized commands.","severity":"critical","cvss_score":9.8,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","cwe":"CWE-78","product":"OpenClaw","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-28470","published":"2026-03-05"},{"cve_id":"CVE-2026-28391","title":"Command injection via cmd.exe metacharacters in allowlist-gated exec requests","description":"OpenClaw versions prior to 2026.2.2 fail to properly validate Windows cmd.exe metacharacters in allowlist-gated exec requests (non-default configuration), allowing attackers to bypass command approval restrictions. Remote attackers can craft command strings with shell metacharacters like & or %...% to execute unapproved commands beyond the allowlisted operations.","severity":"critical","cvss_score":9.8,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","cwe":"CWE-78","product":"OpenClaw","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-28391","published":"2026-03-05"},{"cve_id":"CVE-2026-25560","title":"LDAP filter injection via unescaped usernames during authentication","description":"WeKan versions prior to 8.19 contain an LDAP filter injection vulnerability in LDAP authentication. User-supplied username input is incorporated into LDAP search filters and DN-related values without adequate escaping, allowing an attacker to manipulate LDAP queries during authentication.","severity":"critical","cvss_score":9.8,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","cwe":"CWE-90","product":"WeKan","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-25560","published":"2026-02-07"},{"cve_id":"CVE-2026-25241","title":"Unauthenticated SQL injection in the /get/<package>/<version> endpoint","description":"PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, an unauthenticated SQL injection in the /get/<package>/<version> endpoint allows remote attackers to execute arbitrary SQL via a crafted package version. This issue has been patched in version 1.33.0.","severity":"critical","cvss_score":9.8,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","cwe":"CWE-89","product":"pearweb","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-25241","published":"2026-02-03"},{"cve_id":"CVE-2026-25240","title":"SQL injection in user::maintains() via role filters interpolated into an IN() clause","description":"PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability can occur in user::maintains() when role filters are provided as an array and interpolated into an IN (...) clause. This issue has been patched in version 1.33.0.","severity":"critical","cvss_score":9.8,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","cwe":"CWE-89","product":"pearweb","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-25240","published":"2026-02-03"},{"cve_id":"CVE-2026-25238","title":"SQL injection in bug subscription deletion via a crafted email value","description":"PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in bug subscription deletion may allow attackers to inject SQL via a crafted email value. This issue has been patched in version 1.33.0.","severity":"critical","cvss_score":9.8,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","cwe":"CWE-89","product":"pearweb","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-25238","published":"2026-02-03"},{"cve_id":"CVE-2026-25237","title":"PHP code execution via preg_replace /e in bug update email handling","description":"PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, use of preg_replace() with the /e modifier in bug update email handling can enable PHP code execution if attacker-controlled content reaches the evaluated replacement. This issue has been patched in version 1.33.0.","severity":"critical","cvss_score":9.8,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","cwe":"CWE-624","product":"pearweb","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-25237","published":"2026-02-03"},{"cve_id":"CVE-2026-25236","title":"SQL injection in Damblan_Karma via unsafe literal substitution in an IN() list","description":"PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection risk exists in karma queries due to unsafe literal substitution for an IN (...) list. This issue has been patched in version 1.33.0.","severity":"critical","cvss_score":9.8,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","cwe":"CWE-89","product":"pearweb","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-25236","published":"2026-02-03"},{"cve_id":"CVE-2026-25234","title":"SQL injection in category deletion via the category id","description":"PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in category deletion can allow an attacker with access to the category manager workflow to inject SQL via a category id. This issue has been patched in version 1.33.0.","severity":"critical","cvss_score":9.8,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","cwe":"CWE-89","product":"pearweb","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-25234","published":"2026-02-03"},{"cve_id":"CVE-2026-10536","title":"Use-after-free in HTTP/2 stream-dependency handling after curl_easy_reset()","description":"A use-after-free vulnerability exists in libcurl when an application\nconfigures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or\n`CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and\nfinally terminates the handle with `curl_easy_cleanup()`. During this final\ncleanup phase, libcurl attempts to access and modify an internal structure\nthat was already freed during the reset operation.","severity":"critical","cvss_score":9.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":"CWE-416","product":"curl","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-10536","published":"2026-07-16"},{"cve_id":"CVE-2026-8925","title":"Double free of the GSASL context during SASL authentication cleanup","description":"The curl logic that works with SASL authentication could end up cleaning up\nthe GSASL context *twice* without clearing the pointer in between, making it\n`free()` the same pointer twice.","severity":"critical","cvss_score":9.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":"CWE-415","product":"curl","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-8925","published":"2026-07-16"},{"cve_id":"CVE-2026-2757","title":"Incorrect boundary conditions in the WebRTC audio/video component","description":"Incorrect boundary conditions in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.","severity":"critical","cvss_score":9.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":"CWE-1384","product":"Firefox","reference_count":6,"url":"https://www.cve.org/CVERecord?id=CVE-2026-2757","published":"2026-02-24"},{"cve_id":"CVE-2026-1963","title":"Improper access control in the attachment storage move operation","description":"A vulnerability was found in WeKan up to 8.20. This affects an unknown function of the file models/attachments.js of the component Attachment Storage. The manipulation results in improper access controls. The attack may be launched remotely. Upgrading to version 8.21 mitigates this issue. The patch is identified as c413a7e860bc4d93fe2adcf82516228570bf382d. Upgrading the affected component is advised.","severity":"critical","cvss_score":9.8,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X","cwe":"CWE-284","product":"WeKan","reference_count":6,"url":"https://www.cve.org/CVERecord?id=CVE-2026-1963","published":"2026-02-05"},{"cve_id":"CVE-2026-1962","title":"Improper access control in the attachment migration routine","description":"A vulnerability has been found in WeKan up to 8.20. The impacted element is an unknown function of the file server/attachmentMigration.js of the component Attachment Migration. The manipulation leads to improper access controls. The attack may be initiated remotely. Upgrading to version 8.21 is sufficient to resolve this issue. The identifier of the patch is 053bf1dfb76ef230db162c64a6ed50ebedf67eee. It is recommended to upgrade the affected component.","severity":"critical","cvss_score":9.8,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X","cwe":"CWE-284","product":"WeKan","reference_count":6,"url":"https://www.cve.org/CVERecord?id=CVE-2026-1962","published":"2026-02-05"},{"cve_id":"CVE-2025-14321","title":"Use-after-free in the WebRTC signaling component","description":"Use-after-free in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.","severity":"critical","cvss_score":9.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":"CWE-416","product":"Firefox","reference_count":5,"url":"https://www.cve.org/CVERecord?id=CVE-2025-14321","published":"2025-12-09"},{"cve_id":"CVE-2025-11624","title":"Stack buffer overwrite when processing oversized file handles in the SFTP server","description":"Potential stack buffer overwrite on the SFTP server side when receiving a malicious packet that has a handle size larger than the system handle or file descriptor size, but smaller than max handle size allowed.","severity":"critical","cvss_score":9.8,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:L","cwe":"CWE-787","product":"wolfSSH","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2025-11624","published":"2025-10-21"},{"cve_id":"CVE-2026-40471","title":"Missing CSRF protection allows cross-site package uploads and admin actions","description":"hackage-server lacked Cross-Site Request Forgery (CSRF) protection across its endpoints. Scripts on foreign sites could trigger requests to hackage server, possibly abusing latent credentials to upload packages or perform other administrative actions. Some unauthenticated actions could also be abused (e.g. creating new user accounts).","severity":"critical","cvss_score":9.6,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L","cwe":"CWE-352","product":"hackage-server","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-40471","published":"2026-04-23"},{"cve_id":"CVE-2026-82466","title":"Rodauth before 2.46.0 Authentication Bypass via webauthn_login","description":"Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in users to authenticate as any other account. Attackers can exploit improper account resolution logic that falls back to session account identifiers instead of validating the credential binding to complete authentication as arbitrary users.","severity":"critical","cvss_score":9.4,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N","cwe":"CWE-287","product":"rodauth","reference_count":4,"url":"https://www.cve.org/CVERecord?id=CVE-2026-82466","published":"2026-08-29"},{"cve_id":"CVE-2026-28446","title":"Inbound allowlist bypass in the voice-call extension via empty or suffix-matched caller IDs","description":"OpenClaw versions prior to 2026.2.1 with the voice-call extension installed and enabled contain an authentication bypass vulnerability in inbound allowlist policy validation that accepts empty caller IDs and uses suffix-based matching instead of strict equality. Remote attackers can bypass inbound access controls by placing calls with missing caller IDs or numbers ending with allowlisted digits to reach the voice-call agent and execute tools.","severity":"critical","cvss_score":9.4,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N","cwe":"CWE-303","product":"OpenClaw","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-28446","published":"2026-03-05"},{"cve_id":"CVE-2026-23941","title":"Request smuggling via first-wins Content-Length parsing in inets httpd","description":"Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling.\n\nThis vulnerability is associated with program files lib/inets/src/http_server/httpd_request.erl and program routines httpd_request:parse_headers/7.\n\nThe server does not reject or normalize duplicate Content-Length headers. The earliest Content-Length in the request is used for body parsing while common reverse proxies (nginx, Apache httpd, Envoy) honor the last Content-Length value. This violates RFC 9112 Section 6.3 and allows front-end/back-end desynchronization, leaving attacker-controlled bytes queued as the start of the next request.\n\nThis issue affects OTP from OTP 17.0 until OTP 28.4.1, OTP 27.3.4.9 and OTP 26.2.5.18, corresponding to inets from 5.10 until 9.6.1, 9.3.2.3 and 9.1.0.5.","severity":"critical","cvss_score":9.4,"cvss_vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:L","cwe":"CWE-444","product":"OTP","reference_count":7,"url":"https://www.cve.org/CVERecord?id=CVE-2026-23941","published":"2026-03-13"},{"cve_id":"CVE-2026-65049","title":"Site-scoped capability check in nf_delete_all_data enables network-wide data deletion","description":"Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorization vulnerability that allows a subsite Administrator to trigger network-wide deletion of all Ninja Forms data by exploiting a site-scoped capability check combined with unsafe multisite migration defaults. Attackers can send a crafted POST request to the admin-ajax.php endpoint with the nf_delete_all_data action and a per-site nonce to invoke migration routines that unconditionally iterate all blogs via switch_to_blog(), dropping all nf3_* tables and clearing options and transients across every subsite in the network without requiring super-admin or network-admin privileges.","severity":"critical","cvss_score":9.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:H","cwe":"CWE-863","product":"Ninja Forms","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-65049","published":"2026-07-22"},{"cve_id":"CVE-2026-65048","title":"Unauthenticated stored XSS via crafted Repeatable Fieldset submission indexes","description":"Ninja Forms plugin for WordPress versions 3.10.4 through 3.14.9 contains an unauthenticated stored cross-site scripting vulnerability in the Repeatable Fieldset feature where parseSubmissionIndex() accepts arbitrary strings as submission indexes without numeric validation, and admin_form_element() interpolates the index directly into HTML without escaping. An unauthenticated attacker can submit a public form with a crafted repeater child key containing malicious script payloads, which execute in an administrator's browser when viewing submissions in the WordPress admin panel, enabling session-cookie theft, creation of administrator accounts, installation of malicious plugins, and arbitrary modification of site content.","severity":"critical","cvss_score":9.3,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N","cwe":"CWE-79","product":"Ninja Forms","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-65048","published":"2026-07-22"},{"cve_id":"CVE-2026-33845","title":"Out-of-bounds read via integer underflow when reassembling zero-length DTLS fragments","description":"A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.","severity":"critical","cvss_score":9.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-191","product":"GnuTLS","reference_count":18,"url":"https://www.cve.org/CVERecord?id=CVE-2026-33845","published":"2026-04-30"},{"cve_id":"CVE-2026-25233","title":"Roadmap authorization bypass via an operator precedence bug in the role check","description":"PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, logic bug in the roadmap role check allows non-lead maintainers to create, update, or delete roadmaps. This issue has been patched in version 1.33.0.","severity":"critical","cvss_score":9.1,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","cwe":"CWE-783","product":"pearweb","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-25233","published":"2026-02-03"},{"cve_id":"CVE-2026-8926","title":"Password for another .netrc user sent when the URL specifies only a username","description":"When asking curl to use a `.netrc` file to find credentials and at the same\ntime specifying a URL with a username(without a password), like\n`https://user@example.com/`, curl could wrongly get and use the password for\n*another* user set in the `.netrc` file for that host if such a one exists and\nthere is no match for the specified user.","severity":"critical","cvss_score":9.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","cwe":"CWE-522","product":"curl","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-8926","published":"2026-07-16"},{"cve_id":"CVE-2026-32118","title":"Stored XSS in the Graphical Pain Map (clickmap) encounter form","description":"OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, stored cross-site scripting (XSS) in the Graphical Pain Map (\"clickmap\") form allows any authenticated clinician to inject arbitrary JavaScript that executes in the browser of every subsequent user who views the affected encounter form. Because session cookies are not marked HttpOnly, this enables full session hijacking of other users, including administrators. This vulnerability is fixed in 8.0.0.1.","severity":"critical","cvss_score":9,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","cwe":"CWE-79","product":"openemr","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-32118","published":"2026-03-11"},{"cve_id":"CVE-2026-93546","title":"Apache HTTP Server: mod_dav_fs namespace overflow","description":"Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XML namespaces.","severity":"high","cvss_score":8.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":"CWE-190","product":"Apache HTTP Server","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-93546","published":"2026-10-02"},{"cve_id":"CVE-2026-76208","title":"Authentication Bypass via LDAP","description":"phpMyFAQ versions 3.1.0 through 4.1.6 contain an authentication bypass vulnerability in AuthLdap::create(). When LDAP authentication is enabled, after a successful LDAP bind the code calls User::setStatus('active') unconditionally, which overwrites the account_status column of a pre-existing local account from 'blocked' to 'active'. As a result, a user whose local phpMyFAQ account has been administratively blocked can restore their account and log in by authenticating via LDAP. The state transition is not logged, so administrators cannot detect that the block was overridden. Fixed in 4.1.7.","severity":"high","cvss_score":8.8,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N","cwe":"CWE-778","product":"phpMyFAQ","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-76208","published":"2026-08-21"},{"cve_id":"CVE-2026-74997","title":"Remote code execution via crafted mail headers","description":"In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeholder replacement values. This issue only affects Roundcube instances using the markasjunk plugin with its cmd_learn driver.","severity":"high","cvss_score":8.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":"CWE-78","product":"Roundcube","reference_count":6,"url":"https://www.cve.org/CVERecord?id=CVE-2026-74997","published":"2026-08-26"},{"cve_id":"CVE-2026-64835","title":"Out-of-bounds read and write in the ADX audio decoder via a mid-stream channel layout change","description":"FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds reads and writes by supplying a crafted ADX or AAX audio file with a mid-stream channel layout change. When AV_PKT_DATA_NEW_EXTRADATA side data is received mid-stream, the adx_decode_frame function re-parses the stream header but fails to update the internal channel state, causing subsequent decoding operations to access the prev[] state array using a stale channel count.","severity":"high","cvss_score":8.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":"CWE-787","product":"FFmpeg","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-64835","published":"2026-07-23"},{"cve_id":"CVE-2026-64832","title":"Double free in the NVDEC hardware decoder when no decoder surfaces remain","description":"FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. When no decoder surfaces remain, the ff_nvdec_start_frame_sep_ref error path frees memory via nvdec_fdd_priv_free while the calling layer subsequently frees the same frame description data, resulting in a double-free of the underlying decoder context in any FFmpeg-based application using NVDEC hardware-accelerated decoding.","severity":"high","cvss_score":8.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":"CWE-415","product":"FFmpeg","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-64832","published":"2026-07-23"},{"cve_id":"CVE-2026-64831","title":"Stack buffer overflow in the Vulkan HEVC decoder via oversized vps_num_hrd_parameters","description":"FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses and adjacent stack frames by supplying a crafted HEVC/H.265 bitstream. Attackers can embed a malicious vps_num_hrd_parameters value exceeding HEVC_MAX_SUB_LAYERS in any supported container format to overflow stack-allocated arrays in the vk_hevc_end_frame function, potentially achieving arbitrary code execution.","severity":"high","cvss_score":8.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":"CWE-121","product":"FFmpeg","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-64831","published":"2026-07-23"},{"cve_id":"CVE-2026-64830","title":"Heap buffer overflow in the VobSub subtitle demuxer via excessive distinct stream IDs","description":"FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more distinct stream IDs than the fixed-size array bounds in libavformat/mpeg.c. Attackers can craft a subtitle file with excessive distinct stream IDs to trigger unbounded writes beyond the vobsub->q[] array boundary via ff_subtitles_queue_insert(), potentially achieving arbitrary code execution in any application using FFmpeg's VobSub demuxer.","severity":"high","cvss_score":8.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":"CWE-122","product":"FFmpeg","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-64830","published":"2026-07-23"},{"cve_id":"CVE-2026-59851","title":"Missing Kerberos principal check in the gssapi-keyex path allows login as arbitrary users","description":"A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for the requested local user, allowing authenticated clients to log in as arbitrary users.","severity":"high","cvss_score":8.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":"CWE-863","product":"libssh","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-59851","published":"2026-07-24"},{"cve_id":"CVE-2026-39461","title":"Stack buffer overflow in libcasper via file descriptors exceeding FD_SETSIZE in select()","description":"libcasper(3) communicates with helper processes via UNIX domain sockets, and uses the select(2) system call to wait for data to become available.  However, it does not verify that its socket descriptor fits within select(2)'s descriptor set size limit of FD_SETSIZE (1024).\n\nAn attacker able to cause an application using libcasper(3) to allocate large file descriptors, e.g., by opening many descriptors and executing a program which is not careful to close them upon startup, may trigger stack corruption.  If the target application runs with setuid root privileges, this could be used to escalate local privileges.","severity":"high","cvss_score":8.8,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","cwe":"CWE-121","product":"FreeBSD","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-39461","published":"2026-05-21"},{"cve_id":"CVE-2026-33918","title":"Missing authorization on get_claim_file.php lets any user download and delete claim files","description":"OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the billing file-download endpoint `interface/billing/get_claim_file.php` only verifies that the caller has a valid session and CSRF token, but does not check any ACL permissions. This allows any authenticated OpenEMR user — regardless of whether they have billing privileges — to download and permanently delete electronic claim batch files containing protected health information (PHI). Version 8.0.0.3 patches the issue.","severity":"high","cvss_score":8.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L","cwe":"CWE-862","product":"openemr","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-33918","published":"2026-03-25"},{"cve_id":"CVE-2026-26323","title":"Command injection in the update-clawtributors maintainer script via commit author emails","description":"OpenClaw is a personal AI assistant. Versions 2026.1.8 through 2026.2.13 have a command injection in the maintainer/dev script `scripts/update-clawtributors.ts`. The issue affects contributors/maintainers (or CI) who run `bun scripts/update-clawtributors.ts` in a source checkout that contains a malicious commit author email (e.g. crafted `@users[.]noreply[.]github[.]com` values). Normal CLI usage is not affected (`npm i -g openclaw`): this script is not part of the shipped CLI and is not executed during routine operation. The script derived a GitHub login from `git log` author metadata and interpolated it into a shell command (via `execSync`). A malicious commit record could inject shell metacharacters and execute arbitrary commands when the script is run. Version 2026.2.14 contains a patch.","severity":"high","cvss_score":8.8,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","cwe":"CWE-78","product":"OpenClaw","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-26323","published":"2026-02-19"},{"cve_id":"CVE-2026-25859","title":"Insufficient permission checks allow non-admin users to run migration operations","description":"Wekan versions prior to 8.20 allow non-administrative users to access migration functionality due to insufficient permission checks, potentially resulting in unauthorized migration operations.","severity":"high","cvss_score":8.8,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N","cwe":"CWE-863","product":"WeKan","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-25859","published":"2026-02-07"},{"cve_id":"CVE-2026-23627","title":"SQL injection in the Immunization module via the patient_id parameter","description":"OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, an SQL injection vulnerability in the Immunization module allows any authenticated user to execute arbitrary SQL queries, leading to complete database compromise, PHI exfiltration, credential theft, and potential remote code execution. The vulnerability exists because user-supplied `patient_id` values are directly concatenated into SQL WHERE clauses without parameterization or escaping. Version 8.0.0 patches the issue.","severity":"high","cvss_score":8.8,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P","cwe":"CWE-89","product":"openemr","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-23627","published":"2026-02-25"},{"cve_id":"CVE-2026-13087","title":"Heap out-of-bounds write in the linux kernel rpc-over-rdma server reply path...","description":"A heap out-of-bounds write vulnerability was found in the Linux kernel's RPC-over-RDMA server reply path in net/sunrpc/xprtrdma/svc_rdma_sendto.c. When a crafted RPC-over-RDMA client sends a large NFS READ request with an empty Write list and no Reply chunk, the server linearizes the entire multi-page reply into a fixed-size 4096-byte heap buffer without bounds checking, resulting in a kernel heap overflow. This can lead to denial of service via kernel crash or potential code execution through corruption of adjacent kernel heap objects.","severity":"high","cvss_score":8.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":"CWE-787","product":"Linux","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-13087","published":"2026-09-24"},{"cve_id":"CVE-2026-6638","title":"SQL injection in logical replication via crafted table names at REFRESH PUBLICATION","description":"SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table creator to execute arbitrary SQL with the subscription's publication-side credentials.  The attack takes effect at the next REFRESH PUBLICATION.  Within major versions 16, 17, and 18, minor versions before PostgreSQL 18.4, 17.10, and 16.14 are affected.  Versions before PostgreSQL 16 are unaffected.","severity":"high","cvss_score":8.8,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N","cwe":"CWE-89","product":"PostgreSQL","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-6638","published":"2026-05-14"},{"cve_id":"CVE-2026-6473","title":"Integer wraparound undersizes allocations, letting unprivileged users write out of bounds","description":"Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds.  This may execute arbitrary code as the operating system user running the database.  In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault.  Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.","severity":"high","cvss_score":8.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":"CWE-190","product":"PostgreSQL","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-6473","published":"2026-05-14"},{"cve_id":"CVE-2026-5136","title":"Privilege escalation to administrator via unvalidated usergroup role assignments","description":"A flaw was found in Foreman. The Usergroup model in Foreman does not properly validate role assignments against the calling user's permissions. This allows an authenticated user with usergroup management permissions to attach arbitrary roles, including administrative roles, to a user group and then add themselves as a member. Successful exploitation of this vulnerability leads to full privilege escalation, granting the attacker administrator-level access.","severity":"high","cvss_score":8.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":"CWE-266","product":"Foreman","reference_count":6,"url":"https://www.cve.org/CVERecord?id=CVE-2026-5136","published":"2026-07-16"},{"cve_id":"CVE-2026-2206","title":"Improper access control in the fixDuplicateLists admin repair method","description":"A security flaw has been discovered in WeKan up to 8.20. This vulnerability affects unknown code of the file server/methods/fixDuplicateLists.js of the component Administrative Repair Handler. Performing a manipulation results in improper access controls. It is possible to initiate the attack remotely. Upgrading to version 8.21 is able to resolve this issue. The patch is named 4ce181d17249778094f73d21515f7f863f554743. It is advisable to upgrade the affected component.","severity":"high","cvss_score":8.8,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X","cwe":"CWE-284","product":"WeKan","reference_count":6,"url":"https://www.cve.org/CVERecord?id=CVE-2026-2206","published":"2026-02-08"},{"cve_id":"CVE-2025-66287","title":"Memory corruption when processing crafted web content leading to a process crash","description":"A flaw was found in WebKitGTK. Processing malicious web content can cause an unexpected process crash due to improper memory handling.","severity":"high","cvss_score":8.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":"CWE-120","product":"WebKitGTK","reference_count":14,"url":"https://www.cve.org/CVERecord?id=CVE-2025-66287","published":"2025-12-04"},{"cve_id":"CVE-2025-62525","title":"Arbitrary kernel memory read and write via ltq-ptm driver ioctls","description":"OpenWrt Project is a Linux operating system targeting embedded devices. Prior to version 24.10.4, local users could read and write arbitrary kernel memory using the ioctls of the ltq-ptm driver which is used to drive the datapath of the DSL line. This only effects the lantiq target supporting xrx200, danube and amazon SoCs from Lantiq/Intel/MaxLinear with the DSL in PTM mode. The DSL driver for the VRX518 is not affected. ATM mode is also not affected. Most VDSL lines use PTM mode and most ADSL lines use ATM mode. OpenWrt is normally running as a single user system, but some services are sandboxed. This vulnerability could allow attackers to escape a ujail sandbox or other contains. This is fixed in OpenWrt 24.10.4. There are no workarounds.","severity":"high","cvss_score":8.8,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H","cwe":"CWE-20","product":"openwrt","reference_count":4,"url":"https://www.cve.org/CVERecord?id=CVE-2025-62525","published":"2025-10-22"},{"cve_id":"CVE-2025-15467","title":"Stack buffer overflow via an oversized AEAD IV in CMS (Auth)EnvelopedData parsing","description":"Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with\nmaliciously crafted AEAD parameters can trigger a stack buffer overflow.\n\nImpact summary: A stack buffer overflow may lead to a crash, causing Denial\nof Service, or potentially remote code execution.\n\nWhen parsing CMS (Auth)EnvelopedData structures that use AEAD ciphers such as\nAES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is\ncopied into a fixed-size stack buffer without verifying that its length fits\nthe destination. An attacker can supply a crafted CMS message with an\noversized IV, causing a stack-based out-of-bounds write before any\nauthentication or tag verification occurs.\n\nApplications and services that parse untrusted CMS or PKCS#7 content using\nAEAD ciphers (e.g., S/MIME (Auth)EnvelopedData with AES-GCM) are vulnerable.\nBecause the overflow occurs prior to authentication, no valid key material\nis required to trigger it. While exploitability to remote code execution\ndepends on platform and toolchain mitigations, the stack-based write\nprimitive represents a severe risk.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the CMS implementation is outside the OpenSSL FIPS module\nboundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue.\n\nOpenSSL 1.1.1 and 1.0.2 are not affected by this issue.","severity":"high","cvss_score":8.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":"CWE-787","product":"OpenSSL","reference_count":6,"url":"https://www.cve.org/CVERecord?id=CVE-2025-15467","published":"2026-01-27"},{"cve_id":"CVE-2025-10680","title":"Shell command injection by a malicious server via DNS variables with --dns-updown","description":"OpenVPN 2.7_alpha1 through 2.7_beta1 on POSIX based platforms allows a remote authenticated server to inject shell commands via DNS variables when --dns-updown is in use","severity":"high","cvss_score":8.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":"CWE-78","product":"OpenVPN","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2025-10680","published":"2025-10-24"},{"cve_id":"CVE-2026-75140","title":"Uncontrolled Resource Consumption in XmlTreeBuilder","description":"jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolled resource consumption vulnerability in XmlTreeBuilder that allows remote attackers to exhaust JVM heap memory by supplying a deeply nested XML document with uniquely-namespaced elements. The builder copies the entire inherited namespace map on every start element, causing quadratic time and memory complexity, which attackers can exploit to trigger an OutOfMemoryError and terminate the application.","severity":"high","cvss_score":8.7,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","cwe":"CWE-770","product":"jsoup","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-75140","published":"2026-08-20"},{"cve_id":"CVE-2026-67215","title":"Stack exhaustion via uncontrolled recursion when applying crafted JSON Patch documents","description":"cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(). A patch containing add and copy operations grafts duplicated subtrees to amplify document depth beyond the parser's nesting limit: cJSON_Delete() recurses with no depth bound, and the cJSON_Duplicate() guard CJSON_CIRCULAR_LIMIT is set to 10000, ten times the parser's 1000-level nesting limit and high enough to overflow a default thread stack. An attacker who can supply the patch document can crash the process, resulting in denial of service.","severity":"high","cvss_score":8.7,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","cwe":"CWE-674","product":"cJSON","reference_count":4,"url":"https://www.cve.org/CVERecord?id=CVE-2026-67215","published":"2026-07-29"},{"cve_id":"CVE-2026-65052","title":"Payment total tampering via fail-open get_calc_value() in ListSelect and ListRadio fields","description":"Ninja Forms WordPress plugin version 3.14.8 and prior contains an improper input validation vulnerability that allows unauthenticated attackers to inject arbitrary numeric values into form calculations and payment totals by submitting values that do not match any configured option in ListSelect or ListRadio fields. Attackers can tamper with form submission payloads to the ajax submit endpoint, causing the get_calc_value() method to fail open and return attacker-controlled values, enabling manipulation of payment amounts to zero or arbitrary figures and bypassing admin-configured pricing logic.","severity":"high","cvss_score":8.7,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","cwe":"CWE-472","product":"Ninja Forms","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-65052","published":"2026-07-22"},{"cve_id":"CVE-2026-64834","title":"Infinite loop in rtp_asf_fix_header() via an undersized ASF chunksize","description":"FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of service by sending a crafted RTP/ASF stream. The rtp_asf_fix_header function fails to validate a minimum chunksize when iterating over ASF objects, causing the loop pointer to never advance when a chunksize is smaller than the 24-byte minimum ASF object header size, resulting in CPU exhaustion that denies service to legitimate users.","severity":"high","cvss_score":8.7,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","cwe":"CWE-835","product":"FFmpeg","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-64834","published":"2026-07-23"},{"cve_id":"CVE-2026-33346","title":"Stored XSS in the patient portal payment flow executing in staff browsers","description":"OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, a stored cross-site scripting (XSS) vulnerability in the patient portal payment flow allows a patient portal user to persist arbitrary JavaScript that executes in the browser of a staff member who reviews the payment submission. The payload is stored via `portal/lib/paylib.php` and rendered without escaping in `portal/portal_payment.php`. Version 8.0.0.2 fixes the issue.","severity":"high","cvss_score":8.7,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","cwe":"CWE-79","product":"openemr","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-33346","published":"2026-03-19"},{"cve_id":"CVE-2026-3505","title":"Unbounded PGP AEAD chunk size allows pre-authentication resource exhaustion","description":"Allocation of resources without limits or throttling, Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpg on all (pg modules).\n\n This vulnerability is associated with program files AEADEncDataPacket.Java, BcAEADUtil.Java, JceAEADUtil.Java, OperatorHelper.Java.\n\n\n\nThis issue affects BC-JAVA: from 1.74 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.","severity":"high","cvss_score":8.7,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","cwe":"CWE-770","product":"BC-JAVA","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-3505","published":"2026-04-15"},{"cve_id":"CVE-2026-82463","title":"pac4j-core before 6.5.6 Authorization Bypass via Reversed Profile Type Check","description":"pac4j-core before 6.5.6 contains an authentication bypass vulnerability in CheckProfileTypeAuthorizer that reverses the profile type validation logic. Attackers can authenticate through a weaker client and access resources requiring a stronger profile type by satisfying generic profile checks.","severity":"high","cvss_score":8.6,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","cwe":"CWE-863","product":"pac4j","reference_count":5,"url":"https://www.cve.org/CVERecord?id=CVE-2026-82463","published":"2026-08-29"},{"cve_id":"CVE-2026-82461","title":"pac4j-oidc before 6.5.6 Privilege Escalation via Unverified Keycloak Access Token","description":"pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audiences, or expiry when extracting Keycloak realm and client roles. Attackers can forge access tokens with administrative roles paired with valid ID tokens to bypass authorization checks in applications relying on pac4j role validation.","severity":"high","cvss_score":8.6,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","cwe":"CWE-347","product":"pac4j","reference_count":5,"url":"https://www.cve.org/CVERecord?id=CVE-2026-82461","published":"2026-08-29"},{"cve_id":"CVE-2026-76207","title":"2FA Bypass via Remember-Me Cookie","description":"phpMyFAQ before 4.1.7 contains a two-factor authentication bypass vulnerability where remember-me tokens are issued before 2FA verification completes. Attackers with valid credentials can obtain a remember-me cookie, skip the 2FA challenge, and replay the cookie to gain full authenticated access without second-factor verification.","severity":"high","cvss_score":8.6,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","cwe":"CWE-304","product":"phpMyFAQ","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-76207","published":"2026-08-21"},{"cve_id":"CVE-2026-10649","title":"Integer overflow in remote message decompression crashes the CIB remote listener","description":"A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption, leading to a denial of service (DoS) in the CIB remote listener. This can result in the affected service crashing.","severity":"high","cvss_score":8.6,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","cwe":"CWE-190","product":"Pacemaker","reference_count":7,"url":"https://www.cve.org/CVERecord?id=CVE-2026-10649","published":"2026-06-16"},{"cve_id":"CVE-2025-68473","title":"Out-of-bounds write in bta_dm_sdp_result() when SDP discovery returns more than 32 services","description":"ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, and earlier, in the ESP-IDF Bluetooth host stack (BlueDroid), the function bta_dm_sdp_result() used a fixed-size array uuid_list[32][MAX_UUID_SIZE] to store discovered service UUIDs during the SDP (Service Discovery Protocol) process. On modern Bluetooth devices, it is possible for the number of available services to exceed this fixed limit (32). In such cases, if more than 32 services are discovered, subsequent writes to uuid_list could exceed the bounds of the array, resulting in a potential out-of-bounds write condition.","severity":"high","cvss_score":8.6,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N","cwe":"CWE-787","product":"esp-idf","reference_count":8,"url":"https://www.cve.org/CVERecord?id=CVE-2025-68473","published":"2025-12-26"},{"cve_id":"CVE-2026-75144","title":"FFmpeg Heap Buffer Overflow in VC-2/Dirac RTP Packetizer","description":"FFmpeg before commit 1cdeb3c contains a heap buffer overflow vulnerability in the VC-2/Dirac RTP packetizer (libavformat/rtpenc_vc2hq.c) that allows attackers to trigger memory corruption by supplying a crafted Dirac data unit. The packetizer copies an input-derived data unit or fragment size into a fixed-size buffer without an upper bound check, causing a heap buffer overflow when the crafted input is packetized for RTP output.","severity":"high","cvss_score":8.5,"cvss_vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","cwe":"CWE-122","product":"FFmpeg","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-75144","published":"2026-08-20"},{"cve_id":"CVE-2026-75142","title":"FFmpeg Stack Buffer Overflow in MPEG-PS Muxer via mpegenc.c","description":"FFmpeg before commit 9d786e4 contains a stack buffer overflow in the MPEG-PS muxer (libavformat/mpegenc.c). When muxing input with more streams than the muxer's fixed-size stack buffer accommodates, the buffer is overflowed. A crafted input with an excessive number of streams triggers the overflow during MPEG-PS muxing.","severity":"high","cvss_score":8.5,"cvss_vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","cwe":"CWE-121","product":"FFmpeg","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-75142","published":"2026-08-20"},{"cve_id":"CVE-2026-75141","title":"FFmpeg Heap Buffer Overflow in hvcC Box Writer via HEVC Muxing","description":"FFmpeg before commit acf5d7c contains a heap buffer overflow in the hvcC box writer. When writing an HEVC configuration record with more NAL units of a single type than the count field can represent, the NAL unit count overflows, causing a heap buffer overflow. A crafted HEVC input file triggers the overflow during muxing.","severity":"high","cvss_score":8.5,"cvss_vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","cwe":"CWE-122","product":"FFmpeg","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-75141","published":"2026-08-20"},{"cve_id":"CVE-2026-0861","title":"Integer overflow in the memalign function family leading to heap corruption","description":"Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc) in the GNU C Library version 2.30 to 2.42 may result in an integer overflow, which could consequently result in a heap corruption.\n\nNote that the attacker must have control over both, the size as well as the alignment arguments of the memalign function to be able to exploit this.  The size parameter must be close enough to PTRDIFF_MAX so as to overflow size_t along with the large alignment argument.  This limits the malicious inputs for the alignment for memalign to the range [1<<62+ 1, 1<<63] and exactly 1<<63 for posix_memalign and aligned_alloc.\n\nTypically the alignment argument passed to such functions is a known constrained quantity (e.g. page size, block size, struct sizes) and is not attacker controlled, because of which this may not be easily exploitable in practice.  An application bug could potentially result in the input alignment being too large, e.g. due to a different buffer overflow or integer overflow in the application or its dependent libraries, but that is again an uncommon usage pattern given typical sources of alignments.","severity":"high","cvss_score":8.4,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":"CWE-190","product":"glibc","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-0861","published":"2026-01-14"},{"cve_id":"CVE-2026-67216","title":"Exponential runtime in cJSON_Compare() on deeply nested JSON, leading to denial of service","description":"cJSON through 1.7.19 contains an inefficient algorithmic complexity flaw in cJSON_Compare(). When comparing objects, the function recurses into each shared subtree twice, once in each direction, with no depth guard, making the running time exponential in nesting depth. A small, deeply nested document of a few hundred bytes (depth around 40) compared for equality consumes hours of CPU, and the cost roughly doubles with each additional level of nesting. An application that calls cJSON_Compare() on attacker-influenced JSON that is structurally equal to a reference document is exposed to a denial-of-service condition.","severity":"high","cvss_score":8.2,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","cwe":"CWE-407","product":"cJSON","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-67216","published":"2026-07-29"},{"cve_id":"CVE-2026-47688","title":"Unauthenticated deletion of host AES keys and power schedules via clearAES and clearPMTasks","description":"The clearAES and clearPMTasks methods in FOGPage can be invoked by an unauthenticated attacker via a single HTTP GET request through the public client node endpoint. This allows remote wiping of host AES encryption credentials and deletion of all power management scheduled tasks, with no login, session, or CSRF token required. Host and group IDs are sequential integers, so an attacker can enumerate and wipe all targets. Affects any FOG deployment where the management web interface is reachable by untrusted clients.","severity":"high","cvss_score":8.2,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","cwe":"CWE-862","product":"FOG","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-47688","published":"2026-05-19"},{"cve_id":"CVE-2026-42013","title":"Certificate validation falls back to Common Name checks on an oversized SAN","description":"A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validation process to incorrectly fall back to checking the Common Name (CN) field. This could allow a remote attacker to bypass proper certificate validation, potentially leading to spoofing or man-in-the-middle attacks.","severity":"high","cvss_score":8.2,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","cwe":"CWE-295","product":"GnuTLS","reference_count":15,"url":"https://www.cve.org/CVERecord?id=CVE-2026-42013","published":"2026-05-26"},{"cve_id":"CVE-2026-5260","title":"Heap overread in RSA key exchange with a PKCS#11-backed key via a short premaster secret","description":"A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a short heap overread. This memory corruption vulnerability could lead to information disclosure.","severity":"high","cvss_score":8.2,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","cwe":"CWE-126","product":"GnuTLS","reference_count":15,"url":"https://www.cve.org/CVERecord?id=CVE-2026-5260","published":"2026-05-26"},{"cve_id":"CVE-2025-11931","title":"Integer underflow leading to out-of-bounds access in wc_XChaCha20Poly1305_Decrypt()","description":"Integer Underflow Leads to Out-of-Bounds Access in XChaCha20-Poly1305 Decrypt. This issue is hit specifically with a call to the function wc_XChaCha20Poly1305_Decrypt() which is not used with TLS connections, only from direct calls from an application.","severity":"high","cvss_score":8.2,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N","cwe":"CWE-191","product":"wolfSSL","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2025-11931","published":"2025-11-21"},{"cve_id":"CVE-2026-76886","title":"Heap-based Buffer Overflow in Wireshark","description":"C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service","severity":"high","cvss_score":8.1,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":"CWE-122","product":"Wireshark","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-76886","published":"2026-08-21"},{"cve_id":"CVE-2026-75146","title":"FFmpeg Out-of-Bounds Read in DASH Demuxer via dashdec.c","description":"FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/dashdec.c). When a live DASH manifest is refreshed with a startNumber that is lower than the previous value, the current sequence number is driven negative. The fragment retrieval function checked only the upper bound before indexing the fragments array, allowing a negative index to be used and causing an out-of-bounds read. A malicious or misconfigured DASH server can trigger this by serving a live manifest with a decreasing startNumber across a manifest refresh.","severity":"high","cvss_score":8.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","cwe":"CWE-125","product":"FFmpeg","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-75146","published":"2026-08-20"},{"cve_id":"CVE-2026-44169","title":"Authorization bypass exposes stored routine definitions to role-granted EXECUTE users","description":"MariaDB server is a community developed fork of MySQL server. From versions 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, a user getting EXECUTE access to a stored routine via a role, could see the routine definition even without SHOW CREATE ROUTINE privilege. This issue has been patched in versions 11.4.11, 11.8.7, and 12.3.2.","severity":"high","cvss_score":8.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","cwe":"CWE-863","product":"MariaDB","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-44169","published":"2026-06-12"},{"cve_id":"CVE-2026-42512","title":"Heap buffer overflow in dhclient's environment array resizing via a crafted packet","description":"As dhclient is building an environment to pass to dhclient-script, it may need to resize the array of string pointers.  The code which expands the array incorrectly calculates its new size when requesting memory, resulting in a heap buffer overrun.\n\nA specially crafted packet can cause dhclient to overrun its buffer of environment entries.  This can result in a crash, but it may be possible to leverage this bug to achieve remote code execution.","severity":"high","cvss_score":8.1,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":"CWE-122","product":"FreeBSD","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-42512","published":"2026-04-30"},{"cve_id":"CVE-2026-42511","title":"dhclient.conf directive injection via the BOOTP file field, leading to root code execution","description":"The BOOTP file field is written to the lease file without escaping embedded double-quotes, allowing injection of arbitrary dhclient.conf directives.  When the lease file is subsequently re-parsed by dhclient, e.g., after a system restart, an attacker-controlled field from the lease is passed to dhclient-script(8), which evaluates it.\n\nA rogue DHCP server may be able to execute arbirary code as root on a system running dhclient.","severity":"high","cvss_score":8.1,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":"CWE-149","product":"FreeBSD","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-42511","published":"2026-04-30"},{"cve_id":"CVE-2026-34055","title":"IDOR in the patient notes web UI allows modifying and deleting arbitrary notes","description":"OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the legacy patient notes functions in `library/pnotes.inc.php` perform updates and deletes using `WHERE id = ?` without verifying that the note belongs to a patient the user is authorized to access. Multiple web UI callers pass user-controlled note IDs directly to these functions. This is the same class of vulnerability as CVE-2026-25745 (REST API IDOR), but affects the web UI code paths. Version 8.0.0.3 patches the issue.","severity":"high","cvss_score":8.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","cwe":"CWE-639","product":"openemr","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-34055","published":"2026-03-25"},{"cve_id":"CVE-2026-34053","title":"Missing authorization lets any user delete procedure orders via handle_deletions.php","description":"OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, missing authorization in the AJAX deletion endpoint `interface/forms/procedure_order/handle_deletions.php` allows any authenticated user, regardless of role, to irreversibly delete procedure orders, answers, and specimens belonging to any patient in the system. Version 8.0.0.3 patches the issue.","severity":"high","cvss_score":8.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L","cwe":"CWE-862","product":"openemr","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-34053","published":"2026-03-25"},{"cve_id":"CVE-2026-33302","title":"Module ACL check in zhAclCheck() ignores explicit deny entries","description":"OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, the module ACL function `AclMain::zhAclCheck()` only checks for the presence of any \"allow\" (user or group). It never checks for explicit \"deny\" (allowed=0). As a result, administrators cannot revoke access by setting a user or group to \"deny\"; if the user is in a group that has \"allow,\" access is granted regardless of explicit denies. Version 8.0.0.2 fixes the issue.","severity":"high","cvss_score":8.1,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:P","cwe":"CWE-863","product":"openemr","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-33302","published":"2026-03-19"},{"cve_id":"CVE-2026-32126","title":"Inverted ACL check in the CDR ControllerRouter lets any user modify clinical rules","description":"OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, an inverted boolean condition in ControllerRouter::route() causes the admin/super ACL check to be enforced only for controllers that already have their own internal authorization (review, log), while leaving all other CDR controllers — alerts, ajax, edit, add, detail, browse — accessible to any authenticated user. This allows any logged-in user to suppress clinical decision support alerts system-wide, delete or modify clinical plans, and edit rule configurations — all operations intended to require administrator privileges. This vulnerability is fixed in 8.0.0.1.","severity":"high","cvss_score":8.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L","cwe":"CWE-862","product":"openemr","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-32126","published":"2026-03-11"},{"cve_id":"CVE-2026-28472","title":"Unvalidated auth.token skips device identity checks in the gateway WebSocket handshake","description":"OpenClaw versions prior to 2026.2.2 contain a vulnerability in the gateway WebSocket connect handshake in which it allows skipping device identity checks when auth.token is present but not validated. Attackers can connect to the gateway without providing device identity or pairing by exploiting the presence check instead of validation, potentially gaining operator access in vulnerable deployments.","severity":"high","cvss_score":8.1,"cvss_vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","cwe":"CWE-306","product":"OpenClaw","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-28472","published":"2026-03-05"},{"cve_id":"CVE-2026-28387","title":"Use-after-free in client-side DANE TLSA certificate checking","description":"Issue summary: An uncommon configuration of clients performing DANE TLSA-based\nserver authentication, when paired with uncommon server DANE TLSA records, may\nresult in a use-after-free and/or double-free on the client side.\n\nImpact summary: A use after free can have a range of potential consequences\nsuch as the corruption of valid data, crashes or execution of arbitrary code.\n\nHowever, the issue only affects clients that make use of TLSA records with both\nthe PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate\nusage.\n\nBy far the most common deployment of DANE is in SMTP MTAs for which RFC7672\nrecommends that clients treat as 'unusable' any TLSA records that have the PKIX\ncertificate usages.  These SMTP (or other similar) clients are not vulnerable\nto this issue.  Conversely, any clients that support only the PKIX usages, and\nignore the DANE-TA(2) usage are also not vulnerable.\n\nThe client would also need to be communicating with a server that publishes a\nTLSA RRset with both types of TLSA records.\n\nNo FIPS modules are affected by this issue, the problem code is outside the\nFIPS module boundary.","severity":"high","cvss_score":8.1,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":"CWE-416","product":"OpenSSL","reference_count":6,"url":"https://www.cve.org/CVERecord?id=CVE-2026-28387","published":"2026-04-07"},{"cve_id":"CVE-2026-26247","title":"OAuth2 PKCE bypass via unpersisted S256 code_challenge_method during authorization","description":"An OAuth2 PKCE flaw in Gitea where code_challenge_method=S256 was not handled correctly during authorization, causing the S256 method not to be persisted and weakening or bypassing the expected PKCE verifier enforcement during the token exchange.","severity":"high","cvss_score":8.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","cwe":"CWE-284","product":"Gitea","reference_count":4,"url":"https://www.cve.org/CVERecord?id=CVE-2026-26247","published":"2026-07-16"},{"cve_id":"CVE-2026-25941","title":"Out-of-bounds read in the RDPGFX channel via a crafted WIRE_TO_SURFACE_2 PDU","description":"FreeRDP is a free implementation of the Remote Desktop Protocol. Versions on the 2.x branch prior to to 2.11.8 and on the 3.x branch prior to 3.23.0 have an out-of-bounds read vulnerability in the FreeRDP client's RDPGFX channel that allows a malicious RDP server to read uninitialized heap memory by sending a crafted WIRE_TO_SURFACE_2 PDU with a `bitmapDataLength` value larger than the actual data in the packet. This can lead to information disclosure or client crashes when a user connects to a malicious server. Versions 2.11.8 and 3.23.0 fix the issue.","severity":"high","cvss_score":8.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","cwe":"CWE-20","product":"FreeRDP","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-25941","published":"2026-02-25"},{"cve_id":"CVE-2026-25164","title":"Missing ACL checks on the document and insurance REST API routes","description":"OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the REST API route table in `apis/routes/_rest_routes_standard.inc.php` does not call `RestConfig::request_authorization_check()` for the document and insurance routes. Other patient routes in the same file (e.g. encounters, patients/med) call it with the appropriate ACL. As a result, any valid API bearer token can access or modify every patient's documents and insurance data, regardless of the token’s OpenEMR ACLs—effectively exposing all document and insurance PHI to any authenticated API client. Version 8.0.0 patches the issue.","severity":"high","cvss_score":8.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","cwe":"CWE-862","product":"openemr","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-25164","published":"2026-02-25"},{"cve_id":"CVE-2026-24890","title":"Provider signature forgery via missing authorization in the portal signature endpoint","description":"OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, an authorization bypass vulnerability in the patient portal signature endpoint allows authenticated portal users to upload and overwrite provider signatures by setting `type=admin-signature` and specifying any provider user ID. This could potentially lead to signature forgery on medical documents, legal compliance violations, and fraud. The issue occurs when portal users are allowed to modify provider signatures without proper authorization checks. Version 8.0.0 fixes the issue.","severity":"high","cvss_score":8.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","cwe":"CWE-285","product":"openemr","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-24890","published":"2026-02-25"},{"cve_id":"CVE-2025-15382","title":"Heap buffer over-read in wolfSSH_CleanPath() via SCP paths containing '/./' sequences","description":"A heap buffer over-read vulnerability exists in the wolfSSH_CleanPath() function in wolfSSH. An authenticated remote attacker can trigger the issue via crafted SCP path input containing '/./' sequences, resulting in a heap over read by 1 byte.","severity":"high","cvss_score":8.1,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N","cwe":"CWE-125","product":"wolfSSH","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2025-15382","published":"2026-01-06"},{"cve_id":"CVE-2026-25532","title":"Integer underflow in WPS Enrollee fragment length handling via truncated EAP-WSC packets","description":"ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.2, 5.4.3, 5.3.4, 5.2.6, and 5.1.6, a vulnerability exists in the WPS (Wi-Fi Protected Setup) Enrollee implementation where malformed EAP-WSC packets with truncated payloads can cause integer underflow during fragment length calculation. When processing EAP-Expanded (WSC) messages, the code computes frag_len by subtracting header sizes from the total packet length. If an attacker sends a packet where the EAP Length field covers only the header and flags but omits the expected payload (such as the 2-byte Message Length field when WPS_MSG_FLAG_LEN is set), frag_len becomes negative. This negative value is then implicitly cast to size_t when passed to wpabuf_put_data(), resulting in a very large unsigned value. This issue has been patched in versions 5.5.3, 5.4.4, 5.3.5, 5.2.7, and 5.1.7.","severity":"high","cvss_score":8,"cvss_vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","cwe":"CWE-191","product":"esp-idf","reference_count":8,"url":"https://www.cve.org/CVERecord?id=CVE-2026-25532","published":"2026-02-04"},{"cve_id":"CVE-2026-95519","title":"Code execution via macro expansion of manifest entries in `rpmgi` (`-q -p` / verify manifest flows)","description":"A flaw was found in rpm. An attacker can supply a crafted manifest file that, when processed by a user or automation using `rpm -q -p` or similar manifest-processing flows, leads to arbitrary code execution. This occurs because manifest entries are unexpectedly macro-expanded before being opened, allowing embedded shell commands to run with the privileges of the `rpm` process. Successful exploitation can lead to a full compromise of confidentiality, integrity, and availability for the affected account.","severity":"high","cvss_score":7.8,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":"CWE-78","product":"rpm","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-95519","published":"2026-09-24"},{"cve_id":"CVE-2026-86320","title":"Host code execution via `git am` hook execution in patch source extraction (`use-git-am`)","description":"A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources with use-git-am: true. An attacker who can provide a malicious source containing a Git post-applypatch hook can cause the hook to execute on the host during the build process, resulting in arbitrary code execution with the privileges of the user running flatpak-builder.","severity":"high","cvss_score":7.8,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":"CWE-94","product":"flatpak-builder","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-86320","published":"2026-09-18"},{"cve_id":"CVE-2026-84838","title":"Command injection in rpmuncompress via unescaped filenames passed to popen()","description":"A flaw was found in rpmuncompress. This command injection vulnerability allows a local attacker to execute arbitrary commands. This occurs when rpmuncompress processes a specially crafted archive filename containing shell metacharacters, which are not properly escaped before being passed to shell command strings. Successful exploitation requires user interaction, where a user or automated workflow invokes rpmuncompress on the malicious file, leading to high impact on the confidentiality, integrity, and availability of data accessible to the invoking user.","severity":"high","cvss_score":7.8,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":"CWE-78","product":"rpm","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-84838","published":"2026-09-04"},{"cve_id":"CVE-2026-84837","title":"Command injection in rpmbuild via unescaped tarball path","description":"A flaw was found in rpm. An attacker can exploit a command injection vulnerability by influencing the path or filename of a tarball processed by `rpmbuild -t*` to include shell metacharacters. This is particularly relevant in automated build or continuous integration (CI) workflows that ingest externally supplied artifact names. Successful exploitation allows for arbitrary command execution with the privileges of the build user, which could lead to information disclosure or disruption of the build environment.","severity":"high","cvss_score":7.8,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":"CWE-78","product":"rpm","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-84837","published":"2026-09-04"},{"cve_id":"CVE-2026-72693","title":"Local privilege escalation in openvt via incorrect process owner verification allowing passwordless root login","description":"`openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged context. In the documented `kbrequest`/init usage, the ownership test in `authenticate_user()` relies on `stat(\"/proc/<pid>/fd/0\")`. `stat()` on `/proc/<pid>/fd/0` follows the symlink to the underlying TTY device node. As a result, `buf.st_uid` reflects the owner of the TTY node rather than the owner of the process holding the file descriptor. If the TTY owner returns to `root` or the getty owner after logout while an unprivileged process still has `fd 0` attached to that TTY, the check can incorrectly treat that process as belonging to the privileged console owner. Once that check succeeds, the `-u` path executes a passwordless login as the selected user. In the documented `kbrequest`/init deployment using `openvt -us`, this can result in passwordless `login -f root` on the spawned VT. This report establishes that privilege escalation path for that documented deployment; it does not claim equivalent reachability for deployments that do not use `openvt -u` from a privileged `kbrequest`/init path.","severity":"high","cvss_score":7.8,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":"CWE-284","product":"openvt","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-72693","published":"2026-08-11"},{"cve_id":"CVE-2026-48864","title":"Heap buffer overflow when decompressing page data from crafted .solv files","description":"A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds memory access. This could result in information disclosure, alteration of program execution, or a denial of service.","severity":"high","cvss_score":7.8,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":"CWE-787","product":"libsolv","reference_count":6,"url":"https://www.cve.org/CVERecord?id=CVE-2026-48864","published":"2026-05-26"},{"cve_id":"CVE-2026-43958","title":"Stack buffer overflow in rrdcached via an oversized CREATE request","description":"A flaw was found in rrdcached, a component of rrdtool. A local attacker with access to a rrdcached socket can exploit a stack-based buffer overflow by sending an oversized CREATE request. This vulnerability can lead to a denial of service by crashing the daemon or potentially allow for arbitrary code execution, impacting the integrity and confidentiality of data.","severity":"high","cvss_score":7.8,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":"CWE-121","product":"rrdtool","reference_count":5,"url":"https://www.cve.org/CVERecord?id=CVE-2026-43958","published":"2026-06-01"},{"cve_id":"CVE-2026-39457","title":"Stack buffer overflow in libnv via file descriptors exceeding FD_SETSIZE in select()","description":"When exchanging data over a socket, libnv uses select(2) to wait for data to arrive.  However, it does not verify whether the provided socket descriptor fits in select(2)'s file descriptor set size limit of FD_SETSIZE (1024).\n\nAn attacker who is able to force a libnv application to allocate large file descriptors, e.g., by opening many descriptors and executing a program which is not careful to close them upon startup, can trigger stack corruption.  If the target application is setuid-root, then this could be used to elevate local privileges.","severity":"high","cvss_score":7.8,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":"CWE-121","product":"FreeBSD","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-39457","published":"2026-04-30"},{"cve_id":"CVE-2026-32647","title":"Buffer over-read and over-write in ngx_http_mp4_module when processing crafted MP4 files","description":"NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read or over-write to the NGINX worker memory resulting in its termination or possibly code execution, using a specially crafted MP4 file. This issue affects NGINX Open Source and NGINX Plus if it is built with the ngx_http_mp4_module module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted MP4 file with the ngx_http_mp4_module module. \n\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.","severity":"high","cvss_score":7.8,"cvss_vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","cwe":"CWE-125","product":"NGINX Open Source","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-32647","published":"2026-03-24"},{"cve_id":"CVE-2026-18157","title":"Argument injection in the APT backend via crafted package names leading to root code execution","description":"A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system could exploit an argument injection vulnerability in the APT backend. This allows specially crafted package names, which begin with a hyphen, to be misinterpreted as command options by apt-get. Successful exploitation could lead to remote code execution (RCE) with root privileges, enabling the attacker to fully compromise the system's integrity, confidentiality, and availability.","severity":"high","cvss_score":7.8,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":"CWE-88","product":"yggdrasil-worker-package-manager","reference_count":5,"url":"https://www.cve.org/CVERecord?id=CVE-2026-18157","published":"2026-07-31"},{"cve_id":"CVE-2026-10118","title":"Integer overflow in SplashOutputDev::tilingPatternFill leading to heap buffer overflow","description":"A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the `tilingPatternFill` function. This overflow leads to an undersized heap memory allocation, allowing a subsequent out-of-bounds write. Successful exploitation could result in arbitrary code execution, information disclosure, or denial of service within the context of the application processing the PDF.","severity":"high","cvss_score":7.8,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":"CWE-190","product":"Poppler","reference_count":20,"url":"https://www.cve.org/CVERecord?id=CVE-2026-10118","published":"2026-06-01"},{"cve_id":"CVE-2025-59534","title":"Command injection in initialize_kerberos_keytab_file_login()","description":"CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.2, there is a command Injection vulnerability in initialize_kerberos_keytab_file_login(). The vulnerability exists because the code directly interpolates user-controlled input into a shell command and executes it via system() without any sanitization or validation. This issue has been patched in version 1.4.2.","severity":"high","cvss_score":7.8,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","cwe":"CWE-78","product":"CryptoLib","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2025-59534","published":"2025-09-23"},{"cve_id":"CVE-2026-46518","title":"Stored XSS in the prescription multi-print view via patient demographic fields","description":"OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.1, a stored cross-site scripting vulnerability in the prescription CSS/HTML multi-print feature allows a patient portal user to execute arbitrary JavaScript in a clinician's browser session. Patient demographic fields (name, address) are rendered without output encoding in multiprintcss_header(), and portal patients can write attacker-controlled HTML directly into patient_data by calling the PUT api/patient/:num endpoint, which bypasses the intended audit review workflow. Because the XSS fires in the clinician's authenticated session on the main OpenEMR interface, the attacker can access CSRF tokens, session data, and perform actions as the clinician — crossing the patient-to-clinician trust boundary. This issue has been patched in version 8.0.0.1.","severity":"high","cvss_score":7.7,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N","cwe":"CWE-79","product":"openemr","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-46518","published":"2026-06-09"},{"cve_id":"CVE-2026-32123","title":"Broken sensitivity check lets restricted users view sensitive group encounters","description":"OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, sensitivity checks for group encounters are broken because the code only consults form_encounter for sensitivity, while group encounters store sensitivity in form_groups_encounter. As a result, sensitivity is never correctly applied to group encounters, and users who should be restricted from viewing sensitive (e.g. mental health) encounters can view them. This vulnerability is fixed in 8.0.0.1.","severity":"high","cvss_score":7.7,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","cwe":"CWE-863","product":"openemr","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-32123","published":"2026-03-11"},{"cve_id":"CVE-2026-32121","title":"Stored DOM XSS in the portal signer modal via unsanitized patient names","description":"OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1,  Stored XSS in prescription CSS/HTML print view via patient demographics. That finding involves server-side rendering of patient names via raw PHP echo. This finding involves client-side DOM-based rendering via jQuery .html() in a completely different component (portal/sign/assets/signer_api.js). The two share the same root cause (unsanitized patient names in patient_data), but they have different sinks, different affected components, different trigger actions, and require independent fixes. This vulnerability is fixed in 8.0.0.1.","severity":"high","cvss_score":7.7,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N","cwe":"CWE-79","product":"openemr","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-32121","published":"2026-03-11"},{"cve_id":"CVE-2026-19499","title":"Buffer overflow in strfmon and strfmon_l right-justification padding","description":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.\n\nExploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.\n\nAt the time of publication, no network-facing application impact is known.","severity":"high","cvss_score":7.7,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H","cwe":"CWE-122","product":"glibc","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-19499","published":"2026-09-14"},{"cve_id":"CVE-2026-33932","title":"Stored XSS in the CCDA document preview via unsanitized linkHtml attributes","description":"OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, a stored cross-site scripting vulnerability in the CCDA document preview allows an attacker who can upload or send a CCDA document to execute arbitrary JavaScript in a clinician's browser session when the document is previewed. The XSL stylesheet sanitizes attributes for all other narrative elements but not for `linkHtml`, allowing `href=\"javascript:...\"` and event handler attributes to pass through unchanged. Version 8.0.0.3 patches the issue.","severity":"high","cvss_score":7.6,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N","cwe":"CWE-79","product":"openemr","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-33932","published":"2026-03-25"},{"cve_id":"CVE-2025-68474","title":"Out-of-bounds write in avrc_vendor_msg() when handling AVRCP vendor commands","description":"ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, and earlier, in the avrc_vendor_msg() function of the ESP-IDF BlueDroid AVRCP stack, the allocated buffer size was validated using AVRC_MIN_CMD_LEN (20 bytes). However, the actual fixed header data written before the vendor payload exceeds this value. This totals 29 bytes written before p_msg->p_vendor_data is copied. Using the old AVRC_MIN_CMD_LEN could allow an out-of-bounds write if vendor_len approaches the buffer limit. For commands where vendor_len is large, the original buffer allocation may be insufficient, causing writes beyond the allocated memory. This can lead to memory corruption, crashes, or other undefined behavior. The overflow could be larger when assertions are disabled.","severity":"high","cvss_score":7.6,"cvss_vector":"CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:L","cwe":"CWE-787","product":"esp-idf","reference_count":7,"url":"https://www.cve.org/CVERecord?id=CVE-2025-68474","published":"2025-12-26"},{"cve_id":"CVE-2026-94640","title":"Unbounded memory allocation in rpcbind statistics tracking allows unauthenticated remote denial of service","description":"A flaw was found in rpcbind. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a large number of unique requests. The rpcbind service records previously unseen RPC (Remote Procedure Call) statistics in unbounded in-memory lists, leading to persistent memory growth and increased CPU usage. This can degrade or exhaust service availability.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-400","product":"rpcbind","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-94640","published":"2026-09-24"},{"cve_id":"CVE-2026-92550","title":"Excessive allocation pre-authentication in the AMQP 0-8/0-9/0-9-1 decoder","description":"A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service.\n\nThis issue affects Apache Qpid Broker-J: through 10.1.0.\n\nUsers are recommended to upgrade to version 10.1.1, which fixes the issue.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-789","product":"Broker-J","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-92550","published":"2026-09-25"},{"cve_id":"CVE-2026-91149","title":"Denial of service via unbounded connection thread spawning","description":"A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this vulnerability by initiating and sustaining numerous simultaneous connections to the `cockpit-tls` service. This forces the service to create an unbounded number of detached threads, consuming system resources such as memory and file descriptors. The primary consequence is a denial of service (DoS), leading to degradation or complete unavailability of the Cockpit service for legitimate users.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-770","product":"cockpit","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-91149","published":"2026-09-20"},{"cve_id":"CVE-2026-85234","title":"Denial of service due to out-of-bounds read/write in remap engine","description":"A flaw was found in tftp-hpa. When the `in.tftpd` remap engine processes an inverse remap rule that also aborts with a non-empty custom error message, it can pass invalid match offsets to the `genmatchstring()` function. This leads to out-of-bounds read/write operations. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted request, causing the daemon to crash and resulting in a denial of service.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-125","product":"tftp-hpa","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-85234","published":"2026-09-15"},{"cve_id":"CVE-2026-76928","title":"NULL Pointer Dereference in Wireshark","description":"X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-476","product":"Wireshark","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-76928","published":"2026-08-21"},{"cve_id":"CVE-2026-76880","title":"Out-of-bounds Write in Wireshark","description":"RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-787","product":"Wireshark","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-76880","published":"2026-08-21"},{"cve_id":"CVE-2026-76879","title":"Stack-based Buffer Overflow in Wireshark","description":"C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-121","product":"Wireshark","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-76879","published":"2026-08-21"},{"cve_id":"CVE-2026-73198","title":"Unauthenticated DoS in via unbounded request body read","description":"A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_messages` endpoint by sending an arbitrarily large request body. This can cause the service to consume excessive memory, leading to memory exhaustion, degraded responsiveness, and a denial of service (DoS) condition.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-770","product":"freeipa","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-73198","published":"2026-08-21"},{"cve_id":"CVE-2026-73197","title":"Unauthenticated DoS in `/ipa/migration/migration.py` via unbounded request body read","description":"A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form POST requests to the `/ipa/migration/migration.py` endpoint. This can force the migration handler to read attacker-controlled request bodies fully into memory, leading to increased memory usage, slower request handling, and potential service disruption or denial of service.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-770","product":"freeipa","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-73197","published":"2026-08-21"},{"cve_id":"CVE-2026-72897","title":"Out-of-Bounds Access After SSL_set_SSL_CTX() During a Handshake","description":"Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a\nconnection to a different SSL_CTX part way through a handshake may access\nmemory beyond the end of an internal array if the replacement context knows\nabout more provider signature algorithms than the context the connection was\ncreated from. Applications which never call SSL_set_SSL_CTX() are not\naffected.\n\nImpact summary: A remote peer may be able to cause a small out-of-bounds\nread, and in some circumstances a fixed-value out-of-bounds write, on the\nserver heap. This may lead to a Denial of Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: A TLS connection records how many certificate slots it has\nwhen it is created, taken from the SSL_CTX that created it: the built-in\ncertificate types plus one slot for each provider TLS-SIGALG entry that\ncontext was aware of. That count sizes an internal array of per-slot\ncertificate validity flags.\n\nAn application may replace a connection's SSL_CTX part way through the\nhandshake by calling SSL_set_SSL_CTX(), most commonly from a servername\ncallback in order to serve a different virtual host. Doing so did not\nrefresh the recorded count. A provider signature algorithm's slot index is\nits position in the list of whichever context resolves it, so if the\nreplacement context is aware of more of them than the original, an\nalgorithm offered by the peer can resolve to an index beyond the end of the\narray. Processing the peer's signature algorithms then reads one four byte\nword past the end for each such algorithm and, where the word read is zero,\nwrites a fixed value over it. A peer offering many of them can corrupt heap\nmetadata and abort the process.\n\nOnly provider signature algorithms which occupy one of the excess slots,\nand which the server also has configured, have this effect. Codepoints the\nreplacement context does not recognise are discarded without being resolved\nto a slot, and provider signature algorithms are usable only from TLS 1.3.\n\nThe two contexts must therefore be aware of different numbers of provider\nsignature algorithms, which requires separate library contexts, a provider\nloaded between the two being created, or providers which differ in what\nthey advertise - in 4.0, for example, the default provider advertises SM2\nwhere the FIPS provider does not. A deployment meeting the condition is\nalso unable to negotiate the affected algorithms with legitimate clients,\nsince the same stale count hides the corresponding certificates, so the\nmisconfiguration is likely to be noticed. For that reason, and because the\nconfiguration is not the default, this issue has been assessed as Low\nseverity.\n\nFIPS impact: no\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-787","product":"OpenSSL","reference_count":5,"url":"https://www.cve.org/CVERecord?id=CVE-2026-72897","published":"2026-09-30"},{"cve_id":"CVE-2026-71217","title":"Unbounded peer-controlled json parameters enables remote denial of service via resource exhaustion","description":"A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON with oversized numeric parameters, such as `parallel` and `len`, which are not properly validated by the server. This improper input validation can lead to excessive stream and thread creation, as well as large buffer allocations, causing resource exhaustion. Consequently, this can result in a Denial of Service (DoS) on the affected iperf3 server.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-20","product":"Iperf3","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-71217","published":"2026-08-11"},{"cve_id":"CVE-2026-54554","title":"Unauthenticated disclosure of the Active Directory default join password via adInfo()","description":"The adInfo() method in FOGProject returns the Active Directory default join password in plaintext within JSON responses. The endpoint lacks authorization checks and is reachable through unauthenticated request paths via the node=ipxe parameter, allowing attackers to retrieve stored Active Directory credentials without authentication. The affected logic lives in packages/web/lib/fog/fogpage.class.php, with related handling in packages/web/management/index.php and packages/web/lib/fog/fogpagemanager.class.php.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":"CWE-200","product":"FOG","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-54554","published":"2026-06-14"},{"cve_id":"CVE-2026-53460","title":"Unbounded memory request in AcquireAlignedMemory leading to out-of-memory condition","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, a missing check for maximum memory request in AcquireAlignedMemory could trigger an out-of-Memory condition. This issue has been patched in versions 6.9.13-50 and 7.1.2-25.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-770","product":"ImageMagick","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-53460","published":"2026-06-10"},{"cve_id":"CVE-2026-49218","title":"Missing check in the DCM decoder allows images with invalid dimensions, causing crashes","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, a missing check in the DCM decoder could result in an image with invalid dimensions and that could cause crashes in other operation. This issue has been patched in versions 6.9.13-48 and 7.1.2-24.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-20","product":"ImageMagick","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-49218","published":"2026-06-10"},{"cve_id":"CVE-2026-48863","title":"Stack buffer overflow verifying EdDSA PGP signatures with mismatched MPI lengths","description":"A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to incorrect length handling when copying EdDSA 's' MPI into a stack buffer. A remote attacker could craft a malicious Ed25519 PGP signature with mismatched MPI lengths. Processing this crafted signature could lead to a denial of service in automated package or repository processing workflows.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-121","product":"libsolv","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-48863","published":"2026-07-24"},{"cve_id":"CVE-2026-42765","title":"NULL pointer dereference during OCSP chain checking with partial-chain verification","description":"Issue summary: When a partial-chain certificate verification is enabled\ntogether with OCSP response checking for the whole chain, a NULL dereference\nwill happen if the verified chain does not have a self-signed trusted anchor,\ncrashing the process.\n\nImpact summary: A NULL pointer dereference can trigger a crash which leads to a\nDenial of Service for an application.\n\nWhen performing OCSP response checking for certificates in the verification\nchain, the code always tries to access the next certificate as the issuer.\nThere is a check for a self-signed certificate. However with the partial\nchain verification enabled when the chain does not have a self-signed trusted\nanchor, the issuer will be NULL for the last certificate in the chain. A NULL\npointer dereference then happens.\n\nThis issue affects only applications which enable both OCSP verification\nof the certificate chain (X509_V_FLAG_OCSP_RESP_CHECK_ALL) and partial\nchain verification (X509_V_FLAG_PARTIAL_CHAIN) in the certificate\nverification. Both flags are disabled by default. For that reason, we have\nassigned Low severity to the issue.\n\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-476","product":"OpenSSL","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-42765","published":"2026-06-09"},{"cve_id":"CVE-2026-42009","title":"Denial of service via duplicate sequence numbers in DTLS packet reordering","description":"A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined behavior, resulting in a denial of service.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-475","product":"GnuTLS","reference_count":22,"url":"https://www.cve.org/CVERecord?id=CVE-2026-42009","published":"2026-05-18"},{"cve_id":"CVE-2026-29169","title":"NULL pointer dereference in mod_dav_lock via a malicious request","description":"A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.mod_dav_lock is not used internally by mod_dav or mod_dav_fs.\n\nThe only known use-case for mod_dav_lock was mod_dav_svn from Apache Subversion earlier than version 1.2.0.\n\nUsers are recommended to upgrade to version 2.4.66, which fixes this issue, or remove mod_dav_lock.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-476","product":"GnuTLS","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-29169","published":"2026-05-04"},{"cve_id":"CVE-2026-28454","title":"Unvalidated Telegram webhook secret allows forged updates that bypass sender allowlists","description":"OpenClaw versions prior to 2026.2.2 fail to validate webhook secrets in Telegram webhook mode (must be enabled), allowing unauthenticated HTTP POST requests to the webhook endpoint that trust attacker-controlled JSON payloads. Remote attackers can forge Telegram updates by spoofing message.from.id and chat.id fields to bypass sender allowlists and execute privileged bot commands.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","cwe":"CWE-345","product":"OpenClaw","reference_count":6,"url":"https://www.cve.org/CVERecord?id=CVE-2026-28454","published":"2026-03-05"},{"cve_id":"CVE-2026-28390","title":"NULL pointer dereference when processing CMS KeyTransportRecipientInfo","description":"Issue summary: During processing of a crafted CMS EnvelopedData message\nwith KeyTransportRecipientInfo a NULL pointer dereference can happen.\n\nImpact summary: Applications that process attacker-controlled CMS data may\ncrash before authentication or cryptographic operations occur resulting in\nDenial of Service.\n\nWhen a CMS EnvelopedData message that uses KeyTransportRecipientInfo with\nRSA-OAEP encryption is processed, the optional parameters field of\nRSA-OAEP SourceFunc algorithm identifier is examined without checking\nfor its presence. This results in a NULL pointer dereference if the field\nis missing.\n\nApplications and services that call CMS_decrypt() on untrusted input\n(e.g., S/MIME processing or CMS-based protocols) are vulnerable.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-476","product":"OpenSSL","reference_count":6,"url":"https://www.cve.org/CVERecord?id=CVE-2026-28390","published":"2026-04-07"},{"cve_id":"CVE-2026-28389","title":"NULL pointer dereference when processing CMS KeyAgreeRecipientInfo","description":"Issue summary: During processing of a crafted CMS EnvelopedData message\nwith KeyAgreeRecipientInfo a NULL pointer dereference can happen.\n\nImpact summary: Applications that process attacker-controlled CMS data may\ncrash before authentication or cryptographic operations occur resulting in\nDenial of Service.\n\nWhen a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is\nprocessed, the optional parameters field of KeyEncryptionAlgorithmIdentifier\nis examined without checking for its presence. This results in a NULL\npointer dereference if the field is missing.\n\nApplications and services that call CMS_decrypt() on untrusted input\n(e.g., S/MIME processing or CMS-based protocols) are vulnerable.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-476","product":"OpenSSL","reference_count":6,"url":"https://www.cve.org/CVERecord?id=CVE-2026-28389","published":"2026-04-07"},{"cve_id":"CVE-2026-28388","title":"NULL pointer dereference when processing a delta CRL missing the CRL Number extension","description":"Issue summary: When a delta CRL that contains a Delta CRL Indicator extension\nis processed a NULL pointer dereference might happen if the required CRL\nNumber extension is missing.\n\nImpact summary: A NULL pointer dereference can trigger a crash which\nleads to a Denial of Service for an application.\n\nWhen CRL processing and delta CRL processing is enabled during X.509\ncertificate verification, the delta CRL processing does not check\nwhether the CRL Number extension is NULL before dereferencing it.\nWhen a malformed delta CRL file is being processed, this parameter\ncan be NULL, causing a NULL pointer dereference.\n\nExploiting this issue requires the X509_V_FLAG_USE_DELTAS flag to be enabled in\nthe verification context, the certificate being verified to contain a\nfreshestCRL extension or the base CRL to have the EXFLAG_FRESHEST flag set, and\nan attacker to provide a malformed CRL to an application that processes it.\n\nThe vulnerability is limited to Denial of Service and cannot be escalated to\nachieve code execution or memory disclosure. For that reason the issue was\nassessed as Low severity according to our Security Policy.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the affected code is outside the OpenSSL FIPS module boundary.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-476","product":"OpenSSL","reference_count":6,"url":"https://www.cve.org/CVERecord?id=CVE-2026-28388","published":"2026-04-07"},{"cve_id":"CVE-2026-28386","title":"Out-of-bounds read when processing partial AES-CFB128 blocks on AVX-512 systems","description":"Issue summary: Applications using AES-CFB128 encryption or decryption on\nsystems with AVX-512 and VAES support can trigger an out-of-bounds read\nof up to 15 bytes when processing partial cipher blocks.\n\nImpact summary: This out-of-bounds read may trigger a crash which leads to\nDenial of Service for an application if the input buffer ends at a memory\npage boundary and the following page is unmapped. There is no information\ndisclosure as the over-read bytes are not written to output.\n\nThe vulnerable code path is only reached when processing partial blocks\n(when a previous call left an incomplete block and the current call provides\nfewer bytes than needed to complete it). Additionally, the input buffer\nmust be positioned at a page boundary with the following page unmapped.\nCFB mode is not used in TLS/DTLS protocols, which use CBC, GCM, CCM, or\nChaCha20-Poly1305 instead. For these reasons the issue was assessed as\nLow severity according to our Security Policy.\n\nOnly x86-64 systems with AVX-512 and VAES instruction support are affected.\nOther architectures and systems without VAES support use different code\npaths that are not affected.\n\nOpenSSL FIPS module in 3.6 version is affected by this issue.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","cwe":"CWE-125","product":"OpenSSL","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-28386","published":"2026-04-07"},{"cve_id":"CVE-2026-27571","title":"Pre-authentication memory exhaustion via a WebSocket compression bomb","description":"NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The WebSockets handling of NATS messages handles compressed messages via the WebSockets negotiated compression. Prior to versions 2.11.2 and 2.12.3, the implementation bound the memory size of a NATS message but did not independently bound the memory consumption of the memory stream when constructing a NATS message which might then fail validation for size reasons. An attacker can use a compression bomb to cause excessive memory consumption, often resulting in the operating system terminating the server process. The use of compression is negotiated before authentication, so this does not require valid NATS credentials to exploit. The fix, present in versions 2.11.2 and 2.12.3, was to bounds the decompression to fail once the message was too large, instead of continuing on. The vulnerability only affects deployments which use WebSockets and which expose the network port to untrusted end-points.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-409","product":"nats-server","reference_count":4,"url":"https://www.cve.org/CVERecord?id=CVE-2026-27571","published":"2026-02-24"},{"cve_id":"CVE-2026-26932","title":"Improper array index validation in the PostgreSQL protocol parser causing a panic","description":"Improper Validation of Array Index (CWE-129) in the PostgreSQL protocol parser in Packetbeat can lead Denial of Service via Input Data Manipulation (CAPEC-153). An attacker can send a specially crafted packet causing a Go runtime panic that terminates the Packetbeat process. This vulnerability requires the pgsql protocol to be explicitly enabled and configured to monitor traffic on the targeted port.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-129","product":"Packetbeat","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-26932","published":"2026-02-26"},{"cve_id":"CVE-2026-26316","title":"Webhook authentication bypass in the BlueBubbles plugin via loopback address trust","description":"OpenClaw is a personal AI assistant. Prior to 2026.2.13, the optional BlueBubbles iMessage channel plugin could accept webhook requests as authenticated based only on the TCP peer address being loopback (`127.0.0.1`, `::1`, `::ffff:127.0.0.1`) even when the configured webhook secret was missing or incorrect. This does not affect the default iMessage integration unless BlueBubbles is installed and enabled. Version 2026.2.13 contains a patch. Other mitigations include setting a non-empty BlueBubbles webhook password and avoiding deployments where a public-facing reverse proxy forwards to a loopback-bound Gateway without strong upstream authentication.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","cwe":"CWE-863","product":"OpenClaw","reference_count":4,"url":"https://www.cve.org/CVERecord?id=CVE-2026-26316","published":"2026-02-19"},{"cve_id":"CVE-2026-25564","title":"Cross-board IDOR in checklist deletion via unverified cardId-to-board relationship","description":"WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in checklist creation and related checklist routes. The implementation does not verify that the supplied cardId belongs to the supplied boardId, allowing cross-board ID tampering by manipulating identifiers.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N","cwe":"CWE-639","product":"WeKan","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-25564","published":"2026-02-07"},{"cve_id":"CVE-2026-25563","title":"Cross-board IDOR in checklist creation via unverified cardId-to-board relationship","description":"WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in checklist creation and related checklist routes. The implementation does not verify that the supplied cardId belongs to the supplied boardId, allowing cross-board ID tampering by manipulating identifiers.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","cwe":"CWE-639","product":"WeKan","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-25563","published":"2026-02-07"},{"cve_id":"CVE-2026-25561","title":"Missing object relationship validation in the attachment upload API","description":"WeKan versions prior to 8.19 contain an authorization weakness in the attachment upload API. The API does not fully validate that provided identifiers (such as boardId, cardId, swimlaneId, and listId) are consistent and refer to a coherent card/board relationship, enabling attempts to upload attachments with mismatched object relationships.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","cwe":"CWE-863","product":"WeKan","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-25561","published":"2026-02-07"},{"cve_id":"CVE-2026-25556","title":"Double free in fz_fill_pixmap_from_display_list() error handling during barcode decoding","description":"MuPDF versions 1.23.0 through 1.27.0 contain a double-free vulnerability in fz_fill_pixmap_from_display_list() when an exception occurs during display list rendering. The function accepts a caller-owned fz_pixmap pointer but incorrectly drops the pixmap in its error handling path before rethrowing the exception. Callers (including the barcode decoding path in fz_decode_barcode_from_display_list) also drop the same pixmap in cleanup, resulting in a double-free that can corrupt the heap and crash the process. This issue affects applications that enable and use MuPDF barcode decoding and can be triggered by processing crafted input that causes a rendering-time error while decoding barcodes.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","cwe":"CWE-415","product":"MuPDF","reference_count":4,"url":"https://www.cve.org/CVERecord?id=CVE-2026-25556","published":"2026-02-06"},{"cve_id":"CVE-2026-25476","title":"Session timeout bypass via the skip_timeout_reset parameter","description":"OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the session expiration check in `library/auth.inc.php` runs only when `skip_timeout_reset` is not present in the request. When `skip_timeout_reset=1` is sent, the entire block that calls `SessionTracker::isSessionExpired()` and forces logout on timeout is skipped. As a result, any request that includes this parameter (e.g. from auto-refresh pages like the Patient Flow Board) never runs the expiration check: expired sessions can continue to access data indefinitely, abandoned workstations stay active, and an attacker with a stolen session cookie can keep sending `skip_timeout_reset=1` to avoid being logged out. Version 8.0.0 fixes the issue.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":"CWE-613","product":"openemr","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-25476","published":"2026-02-25"},{"cve_id":"CVE-2026-25239","title":"SQL injection in apidoc queue insertion via an unescaped filename","description":"PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in apidoc queue insertion can allow query manipulation if an attacker can influence the inserted filename value. This issue has been patched in version 1.33.0.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","cwe":"CWE-89","product":"pearweb","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-25239","published":"2026-02-03"},{"cve_id":"CVE-2026-25235","title":"Predictable verification hashes in election account requests","description":"PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, predictable verification hashes may allow attackers to guess verification tokens and potentially verify election account requests without authorization. This issue has been patched in version 1.33.0.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","cwe":"CWE-337","product":"pearweb","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-25235","published":"2026-02-03"},{"cve_id":"CVE-2026-24138","title":"Unauthenticated SSRF in getversion.php via the url parameter","description":"FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Versions 1.5.10.1754 and below contain an unauthenticated SSRF vulnerability in getversion.php which can be triggered by providing a user-controlled url parameter. It can be used to fetch both internal websites and files on the machine running FOG. This appears to be reachable without an authenticated web session when the request includes newService=1. The issue does not have a fixed release version at the time of publication.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":"CWE-918","product":"FOG","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-24138","published":"2026-01-23"},{"cve_id":"CVE-2026-22245","title":"SSRF protection bypass via address ranges missing from the local IP denylist","description":"Mastodon is a free, open-source social network server based on ActivityPub. By nature, Mastodon performs a lot of outbound requests to user-provided domains. Mastodon, however, has some protection mechanism to disallow requests to local IP addresses (unless specified in `ALLOWED_PRIVATE_ADDRESSES`) to avoid the \"confused deputy\" problem. The list of disallowed IP address ranges was lacking some IP address ranges that can be used to reach local IP addresses. An attacker can use an IP address in the affected ranges to make Mastodon perform HTTP requests against loopback or local network hosts, potentially allowing access to otherwise private resources and services. This is fixed in Mastodon v4.5.4, v4.4.11, v4.3.17 and v4.2.29.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","cwe":"CWE-918","product":"mastodon","reference_count":4,"url":"https://www.cve.org/CVERecord?id=CVE-2026-22245","published":"2026-01-08"},{"cve_id":"CVE-2026-22045","title":"Unauthenticated resource exhaustion via stalled ACME TLS-ALPN handshakes","description":"Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.35 and 3.6.7, there is a potential vulnerability in Traefik ACME TLS certificates' automatic generation: the ACME TLS-ALPN fast path can allow unauthenticated clients to tie up go routines and file descriptors indefinitely when the ACME TLS challenge is enabled. A malicious client can open many connections, send a minimal ClientHello with acme-tls/1, then stop responding, leading to denial of service of the entry point. The vulnerability is fixed in 2.11.35 and 3.6.7.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-770","product":"traefik","reference_count":4,"url":"https://www.cve.org/CVERecord?id=CVE-2026-22045","published":"2026-01-15"},{"cve_id":"CVE-2026-18358","title":"Missing connection throttling in the system-mode RDP listener allows unauthenticated DoS","description":"A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the incoming connection handler bypasses the connection throttler, allowing an unauthenticated remote attacker to open many parallel pre-authentication connections to the RDP listener. This can accumulate accepted sockets and pending routing-token operations until timeout, exhausting resources and preventing legitimate users from establishing RDP sessions. This issue does not affect the upstream version.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-400","product":"gnome-remote-desktop","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-18358","published":"2026-07-31"},{"cve_id":"CVE-2026-8932","title":"Connection reuse ignores changed client certificate and private key TLS options","description":"libcurl would reuse a previously created connection even when some mTLS config\nrelated option had been changed that should have prohibited reuse.\n\nlibcurl keeps previously used connections in a connection pool for subsequent\ntransfers to reuse if one of them matches the setup. However, some TLS\nsettings related to client certificates were left out from the configuration\nmatch checks, making them match too easily. In particular options related to\nthe private key.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","cwe":"CWE-305","product":"curl","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-8932","published":"2026-07-16"},{"cve_id":"CVE-2026-6893","title":"Command injection via crafted DHCP options allows root code execution in the initramfs","description":"A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's legacy DHCP path. These options are improperly handled and written into temporary shell scripts without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs, potentially compromising the system's boot and network behavior.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":"CWE-78","product":"dracut","reference_count":6,"url":"https://www.cve.org/CVERecord?id=CVE-2026-6893","published":"2026-06-10"},{"cve_id":"CVE-2026-3336","title":"Certificate chain verification bypass in PKCS7_verify() with multiple signers","description":"Improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate chain verification when processing PKCS7 objects with multiple signers, except the final signer.\n\nCustomers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC version 1.69.0.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","cwe":"CWE-295","product":"AWS-LC","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-3336","published":"2026-03-02"},{"cve_id":"CVE-2026-3312","title":"Local file exposure allows any user to read internal system files","description":"A local file exposure vulnerability allowed any user to read and print the contents of internal system files.","severity":"high","cvss_score":7.5,"cvss_vector":"","cwe":"CWE-200","product":"Pagure","reference_count":0,"url":"https://www.cve.org/CVERecord?id=CVE-2026-3312","published":"2026-03-17"},{"cve_id":"CVE-2026-2229","title":"Unhandled exception in the WebSocket client via an out-of-range server_max_window_bits","description":"ImpactThe undici WebSocket client is vulnerable to a denial-of-service attack due to improper validation of the server_max_window_bits parameter in the permessage-deflate extension. When a WebSocket client connects to a server, it automatically advertises support for permessage-deflate compression. A malicious server can respond with an out-of-range server_max_window_bits value (outside zlib's valid range of 8-15). When the server subsequently sends a compressed frame, the client attempts to create a zlib InflateRaw instance with the invalid windowBits value, causing a synchronous RangeError exception that is not caught, resulting in immediate process termination.\n\nThe vulnerability exists because:\n\n  *  The isValidClientWindowBits() function only validates that the value contains ASCII digits, not that it falls within the valid range 8-15\n  *  The createInflateRaw() call is not wrapped in a try-catch block\n  *  The resulting exception propagates up through the call stack and crashes the Node.js process","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-248","product":"undici","reference_count":5,"url":"https://www.cve.org/CVERecord?id=CVE-2026-2229","published":"2026-03-12"},{"cve_id":"CVE-2026-0915","title":"Stack memory disclosure to the DNS resolver in getnetbyaddr and getnetbyaddr_r","description":"Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack contents to the configured DNS resolver.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":"CWE-908","product":"glibc","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-0915","published":"2026-01-15"},{"cve_id":"CVE-2026-0528","title":"Denial of service via malformed payloads in the Graphite, Zookeeper, and Prometheus metricsets","description":"Improper Validation of Array Index (CWE-129) exists in Metricbeat can allow an attacker to cause a Denial of Service through Input Data Manipulation (CAPEC-153) via specially crafted, malformed payloads sent to the Graphite server metricset or Zookeeper server metricset. Additionally, Improper Input Validation (CWE-20) exists in the Prometheus helper module that can allow an attacker to cause a Denial of Service through Input Data Manipulation (CAPEC-153) via specially crafted, malformed metric data.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-129","product":"Metricbeat","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-0528","published":"2026-01-13"},{"cve_id":"CVE-2025-69421","title":"NULL pointer dereference in PKCS12_item_decrypt_d2i_ex() on malformed PKCS#12 files","description":"Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer\ndereference in the PKCS12_item_decrypt_d2i_ex() function.\n\nImpact summary: A NULL pointer dereference can trigger a crash which leads to\nDenial of Service for an application processing PKCS#12 files.\n\nThe PKCS12_item_decrypt_d2i_ex() function does not check whether the oct\nparameter is NULL before dereferencing it. When called from\nPKCS12_unpack_p7encdata() with a malformed PKCS#12 file, this parameter can\nbe NULL, causing a crash. The vulnerability is limited to Denial of Service\nand cannot be escalated to achieve code execution or memory disclosure.\n\nExploiting this issue requires an attacker to provide a malformed PKCS#12 file\nto an application that processes it. For that reason the issue was assessed as\nLow severity according to our Security Policy.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the PKCS#12 implementation is outside the OpenSSL FIPS module boundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-476","product":"OpenSSL","reference_count":6,"url":"https://www.cve.org/CVERecord?id=CVE-2025-69421","published":"2026-01-27"},{"cve_id":"CVE-2025-69420","title":"Type confusion in TS_RESP_verify_response() causing a NULL pointer dereference","description":"Issue summary: A type confusion vulnerability exists in the TimeStamp Response\nverification code where an ASN1_TYPE union member is accessed without first\nvalidating the type, causing an invalid or NULL pointer dereference when\nprocessing a malformed TimeStamp Response file.\n\nImpact summary: An application calling TS_RESP_verify_response() with a\nmalformed TimeStamp Response can be caused to dereference an invalid or\nNULL pointer when reading, resulting in a Denial of Service.\n\nThe functions ossl_ess_get_signing_cert() and ossl_ess_get_signing_cert_v2()\naccess the signing cert attribute value without validating its type.\nWhen the type is not V_ASN1_SEQUENCE, this results in accessing invalid memory\nthrough the ASN1_TYPE union, causing a crash.\n\nExploiting this vulnerability requires an attacker to provide a malformed\nTimeStamp Response to an application that verifies timestamp responses. The\nTimeStamp protocol (RFC 3161) is not widely used and the impact of the\nexploit is just a Denial of Service. For these reasons the issue was\nassessed as Low severity.\n\nThe FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the TimeStamp Response implementation is outside the OpenSSL FIPS module\nboundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.\n\nOpenSSL 1.0.2 is not affected by this issue.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-754","product":"OpenSSL","reference_count":6,"url":"https://www.cve.org/CVERecord?id=CVE-2025-69420","published":"2026-01-27"},{"cve_id":"CVE-2025-64756","title":"Command injection via shell metacharacters in filenames with the CLI -c/--cmd option","description":"Glob matches files using patterns the shell uses. Starting in version 10.2.0 and prior to versions 10.5.0 and 11.1.0, the glob CLI contains a command injection vulnerability in its -c/--cmd option that allows arbitrary command execution when processing files with malicious names. When glob -c <command> <patterns> are used, matched filenames are passed to a shell with shell: true, enabling shell metacharacters in filenames to trigger command injection and achieve arbitrary code execution under the user or CI account privileges. This issue has been patched in versions 10.5.0 and 11.1.0.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":"CWE-78","product":"node-glob","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2025-64756","published":"2025-11-17"},{"cve_id":"CVE-2025-59464","title":"Memory leak converting X.509 certificate fields in socket.getPeerCertificate(true)","description":"A memory leak in Node.js’s OpenSSL integration occurs when converting `X.509` certificate fields to UTF-8 without freeing the allocated buffer. When applications call `socket.getPeerCertificate(true)`, each certificate field leaks memory, allowing remote clients to trigger steady memory growth through repeated TLS connections. Over time this can lead to resource exhaustion and denial of service.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","cwe":"CWE-400","product":"node","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2025-59464","published":"2026-01-20"},{"cve_id":"CVE-2025-55753","title":"Integer overflow in the mod_md ACME renewal backoff leading to delay-free retries","description":"An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempts to renew the certificate then are repeated without delays until it succeeds.\n\nThis issue affects Apache HTTP Server: from 2.4.30 before 2.4.66.\n\n\nUsers are recommended to upgrade to version 2.4.66, which fixes the issue.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":"CWE-190","product":"Apache HTTP Server","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2025-55753","published":"2025-12-05"},{"cve_id":"CVE-2025-13502","title":"Out-of-bounds read and integer underflow in the GLib remote inspector server","description":"A flaw was found in WebKitGTK and WPE WebKit. This vulnerability allows an out-of-bounds read and integer underflow, leading to a UIProcess crash (DoS) via a crafted payload to the GLib remote inspector server.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-125","product":"WebKitGTK","reference_count":14,"url":"https://www.cve.org/CVERecord?id=CVE-2025-13502","published":"2025-11-25"},{"cve_id":"CVE-2025-13016","title":"Incorrect boundary conditions in the JavaScript WebAssembly component","description":"Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird 140.5.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":"CWE-703","product":"Firefox","reference_count":5,"url":"https://www.cve.org/CVERecord?id=CVE-2025-13016","published":"2025-11-11"},{"cve_id":"CVE-2025-9230","title":"Out-of-bounds read and write in RFC 3211 KEK unwrap when decrypting CMS messages","description":"Issue summary: An application trying to decrypt CMS messages encrypted using\npassword based encryption can trigger an out-of-bounds read and write.\n\nImpact summary: This out-of-bounds read may trigger a crash which leads to\nDenial of Service for an application. The out-of-bounds write can cause\na memory corruption which can have various consequences including\na Denial of Service or Execution of attacker-supplied code.\n\nAlthough the consequences of a successful exploit of this vulnerability\ncould be severe, the probability that the attacker would be able to\nperform it is low. Besides, password based (PWRI) encryption support in CMS\nmessages is very rarely used. For that reason the issue was assessed as\nModerate severity according to our Security Policy.\n\nThe FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this\nissue, as the CMS implementation is outside the OpenSSL FIPS module\nboundary.","severity":"high","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-125","product":"OpenSSL","reference_count":8,"url":"https://www.cve.org/CVERecord?id=CVE-2025-9230","published":"2025-09-30"},{"cve_id":"CVE-2026-93543","title":"Out-of-bounds read in libXi's XI2 class parser","description":"An out-of-bounds read in libXi's XI2 class parser in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.","severity":"high","cvss_score":7.4,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H","cwe":"CWE-125","product":"libXi","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-93543","published":"2026-09-24"},{"cve_id":"CVE-2026-84961","title":"undici vulnerable to TLS certificate validation bypass via dropped connect options in BalancedPool","description":"undici's BalancedPool constructor passes its entire options object through an internal deep-clone that serializes and reparses the value as JSON. Because JSON cannot represent functions, any function-valued TLS option, such as a caller-supplied checkServerIdentity callback or a custom connector inside the connect option, is silently discarded before it reaches the TLS layer. As a result a peer whose certificate the application's custom checkServerIdentity was written to reject, but which still passes Node's default hostname and chain checks, is accepted when reached through BalancedPool. The Client, Pool, and Agent dispatchers are not affected because they extract the connect and tls options before cloning. This affects undici versions from 7.24.1 up to 7.29.1 and from 8.0.0 up to 8.10.2, and only when the application supplies a function-valued connect or tls option to BalancedPool. Users should upgrade to undici 7.29.1 or 8.10.2.","severity":"high","cvss_score":7.4,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","cwe":"CWE-295","product":"undici","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-84961","published":"2026-09-04"},{"cve_id":"CVE-2026-80230","title":"OpenSSL pinning bypass","description":"When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable\nstandard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and\n`CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on\nconnections established without a presented server certificate. Bypassing the\npinning check under these disabled-verification conditions allows\nunauthenticated connections to succeed when they should be rejected.","severity":"high","cvss_score":7.4,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","cwe":"CWE-295","product":"curl","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-80230","published":"2026-09-07"},{"cve_id":"CVE-2026-32144","title":"OCSP designated-responder authorization bypass via missing signature verification","description":"Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_ocsp module) allows OCSP designated-responder authorization bypass via missing signature verification.\n\nThe OCSP response validation in public_key:pkix_ocsp_validate/5 does not verify that a CA-designated responder certificate was cryptographically signed by the issuing CA. Instead, it only checks that the responder certificate's issuer name matches the CA's subject name and that the certificate has the OCSPSigning extended key usage. An attacker who can intercept or control OCSP responses can create a self-signed certificate with a matching issuer name and the OCSPSigning EKU, and use it to forge OCSP responses that mark revoked certificates as valid.\n\nThis affects SSL/TLS clients using OCSP stapling, which may accept connections to servers with revoked certificates, potentially transmitting sensitive data to compromised servers. Applications using the public_key:pkix_ocsp_validate/5 API directly are also affected, with impact depending on usage context.\n\nThis vulnerability is associated with program files lib/public_key/src/pubkey_ocsp.erl and program routines pubkey_ocsp:is_authorized_responder/3.\n\nThis issue affects OTP from OTP 27.0 until OTP 28.4.2 and 27.3.4.10 corresponding to public_key from 1.16 until 1.20.3 and 1.17.1.2, and ssl from 11.2 until 11.5.4 and 11.2.12.7.","severity":"high","cvss_score":7.4,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N","cwe":"CWE-295","product":"OTP","reference_count":6,"url":"https://www.cve.org/CVERecord?id=CVE-2026-32144","published":"2026-04-07"},{"cve_id":"CVE-2026-9547","title":"Known-host key type mismatch silently accepted via the CURLOPT_SSH_KEYFUNCTION callback","description":"When a libcurl-based application performs transfers via `SCP://` or `SFTP://`\nand utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an\nuntrusted server. This vulnerability occurs when a server presents a host key\ntype that does not match the specific key type already recorded for that host\nin the `known_hosts` file. Instead of rejecting the mismatch, the callback\nmechanism fails to properly enforce the restriction, allowing the connection\nto succeed without warning and risking a potential man-in-the-middle attack.","severity":"high","cvss_score":7.4,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","cwe":"CWE-297","product":"curl","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-9547","published":"2026-07-16"},{"cve_id":"CVE-2026-3833","title":"Name constraints bypass via case-sensitive dNSName and rfc822Name comparison","description":"A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure.","severity":"high","cvss_score":7.4,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","cwe":"CWE-178","product":"GnuTLS","reference_count":15,"url":"https://www.cve.org/CVERecord?id=CVE-2026-3833","published":"2026-04-30"},{"cve_id":"CVE-2025-69419","title":"Out-of-bounds write in PKCS12_get_friendlyname() UTF-8 conversion","description":"Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously\ncrafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing\nnon-ASCII BMP code point can trigger a one byte write before the allocated\nbuffer.\n\nImpact summary: The out-of-bounds write can cause a memory corruption\nwhich can have various consequences including a Denial of Service.\n\nThe OPENSSL_uni2utf8() function performs a two-pass conversion of a PKCS#12\nBMPString (UTF-16BE) to UTF-8. In the second pass, when emitting UTF-8 bytes,\nthe helper function bmp_to_utf8() incorrectly forwards the remaining UTF-16\nsource byte count as the destination buffer capacity to UTF8_putc(). For BMP\ncode points above U+07FF, UTF-8 requires three bytes, but the forwarded\ncapacity can be just two bytes. UTF8_putc() then returns -1, and this negative\nvalue is added to the output length without validation, causing the\nlength to become negative. The subsequent trailing NUL byte is then written\nat a negative offset, causing write outside of heap allocated buffer.\n\nThe vulnerability is reachable via the public PKCS12_get_friendlyname() API\nwhen parsing attacker-controlled PKCS#12 files. While PKCS12_parse() uses a\ndifferent code path that avoids this issue, PKCS12_get_friendlyname() directly\ninvokes the vulnerable function. Exploitation requires an attacker to provide\na malicious PKCS#12 file to be parsed by the application and the attacker\ncan just trigger a one zero byte write before the allocated buffer.\nFor that reason the issue was assessed as Low severity according to our\nSecurity Policy.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the PKCS#12 implementation is outside the OpenSSL FIPS module boundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.\n\nOpenSSL 1.0.2 is not affected by this issue.","severity":"high","cvss_score":7.4,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","cwe":"CWE-787","product":"OpenSSL","reference_count":6,"url":"https://www.cve.org/CVERecord?id=CVE-2025-69419","published":"2026-01-27"},{"cve_id":"CVE-2026-85013","title":"Command injection in environment-modules bash completion via malicious module names containing shell metacharacters","description":"A flaw was found in environment-modules. A local attacker can exploit this vulnerability by placing a maliciously named modulefile in a location visible to the victim's `MODULEPATH`. When the victim uses Bash completion for `module` or `ml` commands, the malicious module name, containing shell metacharacters, is evaluated as a command. This can lead to arbitrary command execution in the completing user's shell, impacting their confidentiality, integrity, and availability.","severity":"high","cvss_score":7.3,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","cwe":"CWE-78","product":"environment-modules","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-85013","published":"2026-09-15"},{"cve_id":"CVE-2026-71226","title":"Memory corruption from uncanceled AIO requests in the one-shot AIO error path","description":"Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all submitted IOCBs are drained, allowing later kernel writes into caller-owned output buffers.","severity":"high","cvss_score":7.3,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","cwe":"CWE-416","product":"libkcapi","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-71226","published":"2026-08-05"},{"cve_id":"CVE-2026-47687","title":"Stored XSS in the Inventory Report via unescaped option labels in selectForm()","description":"The selectForm() helper renders <option> labels using unescaped user input. An unauthenticated attacker with knowledge of a registered host’s MAC address can POST malicious sysproduct values to an unauthenticated inventory endpoint, which are stored in the database. When administrators access the Inventory Report, the payload executes arbitrary JavaScript in their browser.","severity":"high","cvss_score":7.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","cwe":"CWE-79","product":"FOG","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-47687","published":"2026-05-19"},{"cve_id":"CVE-2026-47685","title":"Stored XSS in the Host Management page via the unauthenticated inventory endpoint","description":"The unauthenticated inventory service endpoint fails to sanitize client-supplied values before persisting them. When administrators view the Host Management Inventory page, these unescaped static inventory fields render as raw HTML, enabling stored XSS attacks. An attacker knowing a host’s MAC address can inject persistent JavaScript that executes in any administrator’s browser session. The vulnerable code is in packages/web/service/inventory.php and the data is rendered in packages/web/lib/pages/hostmanagementpage.class.php.","severity":"high","cvss_score":7.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","cwe":"CWE-79","product":"FOG","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-47685","published":"2026-05-19"},{"cve_id":"CVE-2026-29168","title":"Unbounded resource allocation in mod_md when processing OCSP response data","description":"Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's  mod_md via OCSP response data.\n\nThis issue affects Apache HTTP Server: from 2.4.30 through 2.4.66.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes the issue.","severity":"high","cvss_score":7.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","cwe":"CWE-770","product":"Apache HTTP Server","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-29168","published":"2026-05-05"},{"cve_id":"CVE-2026-28448","title":"allowFrom allowlist bypass in the Twitch plugin when allowedRoles is empty","description":"OpenClaw versions 2026.1.29 prior to 2026.2.1 contain a vulnerability in the Twitch plugin (must be installed and enabled) in which it fails to enforce the allowFrom allowlist when allowedRoles is unset or empty, allowing unauthorized Twitch users to trigger agent dispatch. Remote attackers can mention the bot in Twitch chat to bypass access control and invoke the agent pipeline, potentially causing unintended actions or resource exhaustion.","severity":"high","cvss_score":7.3,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N","cwe":"CWE-285","product":"OpenClaw","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-28448","published":"2026-03-05"},{"cve_id":"CVE-2026-9080","title":"Use-after-free when curl_easy_pause() is called from the socket callback","description":"Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION`\ncallback triggers a use-after-free vulnerability, where libcurl attempts to\nstore a flag using a dangling struct pointer immediately after that pointer's\nmemory has been freed.","severity":"high","cvss_score":7.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","cwe":"CWE-416","product":"curl","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-9080","published":"2026-07-16"},{"cve_id":"CVE-2026-94286","title":"Out-of-bounds read in libXtst's RECORD reply parser","description":"An out-of-bounds read in libXtst's RECORD reply parser in libXtst before 1.2.6 could be used by malicious X servers to crash attached X clients.","severity":"high","cvss_score":7.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","cwe":"CWE-126","product":"libXtst","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-94286","published":"2026-09-28"},{"cve_id":"CVE-2026-86759","title":"Missing Authorization via asset-history CSV importer","description":"Snipe-IT versions before 8.7.0 fail to authorize the POST /hardware/history endpoint, allowing any authenticated user to reassign arbitrary assets and modify audit logs. Attackers can submit a CSV file to reassign assets across companies and inject fraudulent audit trail entries, compromising inventory integrity and accountability.","severity":"high","cvss_score":7.1,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N","cwe":"CWE-862","product":"snipe-it","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-86759","published":"2026-09-10"},{"cve_id":"CVE-2026-86758","title":"License Key Exposure via CSV Export","description":"Snipe-IT before 8.7.0 fails to properly enforce the viewKeys authorization gate in CSV export and API index endpoints, allowing authenticated users with only licenses.view permission to access product keys. Attackers can download all license keys in bulk via CSV export or validate candidate keys through API response discrepancies without needing the viewKeys permission.","severity":"high","cvss_score":7.1,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","cwe":"CWE-204","product":"snipe-it","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-86758","published":"2026-09-10"},{"cve_id":"CVE-2026-86757","title":"Information Disclosure via Custom Fields","description":"Snipe-IT before 8.7.0 fails to properly gate access to encrypted custom-field values in asset form templates for listbox, textarea, markdown-textarea, and date/datetime picker elements. Authenticated users with assets.edit, assets.checkin, assets.checkout, or assets.audit permissions can read plaintext encrypted custom field values by opening asset forms, bypassing the assets.view.encrypted_custom_fields permission check.","severity":"high","cvss_score":7.1,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","cwe":"CWE-862","product":"snipe-it","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-86757","published":"2026-09-10"},{"cve_id":"CVE-2026-77220","title":"PDFio < 1.6.5 Dangling Pointer via Dictionary String-Formatting","description":"PDFio before 1.6.5 contains a dangling pointer vulnerability in the dictionary string-formatting function that stores a pointer to a stack-local buffer in the document dictionary without copying the string value. In multi-threaded or pooled-request environments, attackers or concurrent users can trigger stack memory reuse across requests, causing cross-tenant document content corruption by silently overwriting one caller's dictionary string values with another caller's data.","severity":"high","cvss_score":7.1,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","cwe":"CWE-825","product":"pdfio","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-77220","published":"2026-08-21"},{"cve_id":"CVE-2026-75147","title":"FFmpeg Out-of-Bounds Read in AV1 RTP Packetizer via rtpenc_av1.c","description":"FFmpeg before commit 983dae9 contains an out-of-bounds read in the AV1 RTP packetizer (libavformat/rtpenc_av1.c). The keyframe detection loop that searches for a sequence header OBU advanced its pointer and remaining-size counter by the encoded header length plus the OBU payload size without first bounding the OBU size against the remaining data. A crafted OBU size causes the remaining-size counter to wrap to a positive value, causing the next loop iteration to dereference a pointer beyond the end of the packet buffer. A crafted AV1 input packet muxed to RTP triggers the out-of-bounds read.","severity":"high","cvss_score":7.1,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","cwe":"CWE-125","product":"FFmpeg","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-75147","published":"2026-08-20"},{"cve_id":"CVE-2026-72694","title":"Symlink-following chown allows local privilege escalation via pid file path manipulation","description":"A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops privileges, a local, low-privileged attacker can exploit a symbolic link (symlink) following vulnerability. By influencing or pre-placing a symlink in the process ID (PID) file path, the attacker can trick the root process into changing the ownership of an arbitrary existing file to the daemon user. This can lead to local privilege escalation, allowing unauthorized access to or modification of sensitive files.","severity":"high","cvss_score":7.1,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","cwe":"CWE-59","product":"mrtg","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-72694","published":"2026-08-11"},{"cve_id":"CVE-2026-67419","title":"RabbitMQ: Consecutive topic wildcards cause combinatorial routing work","description":"An authenticated user who can bind a queue to a topic exchange and publish to\nthat exchange can force the routing engine into combinatorial recursion by using\na binding key that contains **consecutive `#` segments**.\n\nWhen such a binding is matched against a routing key of comparable depth, the\nmatcher repeatedly re-enters identical `{trie node, remaining routing-key\nsuffix}` states without memoization, and builds a duplicate list of destination\nresults that is only deduplicated **after** the full traversal completes.\n\nA binding and routing key only tens of bytes long can therefore drive millions\nto billions of recursive matcher invocations and allocate a correspondingly\nlarge intermediate result list, all while producing exactly **one** queue\ndelivery. The work is performed inline in the routing path with no connection,\nchannel, queue, message-size, or memory-alarm limit interrupting a single\nin-progress traversal.","severity":"high","cvss_score":7.1,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","cwe":"CWE-407","product":"RabbitMQ","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-67419","published":"2026-08-18"},{"cve_id":"CVE-2026-65050","title":"Missing authorization in the submissions-table block exposes form submissions to visitors","description":"Ninja Forms WordPress plugin version 3.14.8 and prior contains a missing authorization vulnerability in the render callback of the `ninja-forms/submissions-table` Gutenberg block that allows authenticated attackers with Author-level privileges to expose stored form submissions to unauthenticated visitors by embedding the block with an arbitrary formID on a published post. Attackers can retrieve the signed bearer token injected into every page visitor's browser via `wp_localize_script` and use it against the REST API submissions endpoint to access all saved form submission field values, including sensitive personally identifiable information such as names, email addresses, and phone numbers.","severity":"high","cvss_score":7.1,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","cwe":"CWE-862","product":"Ninja Forms","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-65050","published":"2026-07-22"},{"cve_id":"CVE-2026-64833","title":"Out-of-bounds read in the S/PDIF muxer via an oversized DTS core_size value","description":"FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger than the actual packet length. Attackers can exploit the missing bounds check in the spdif_header_dts4 function by providing a malicious DTS-HD audio stream during S/PDIF re-muxing to trigger unauthorized memory reads beyond the packet buffer.","severity":"high","cvss_score":7.1,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N","cwe":"CWE-125","product":"FFmpeg","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-64833","published":"2026-07-23"},{"cve_id":"CVE-2026-48613","title":"SQL injection during profile field migration via user-supplied profile field data","description":"SQL injection vulnerability in phpBB profile field migration due to improper handling of user-supplied profile field data during migration, allowing execution of arbitrary SQL queries. Only applies to phpBB forums that had been updated from versions prior to phpBB 3.3.8 and have not been updated to 3.3.11 or newer yet.","severity":"high","cvss_score":7.1,"cvss_vector":"CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:L/CR:H/IR:H/AR:H","cwe":"CWE-89","product":"phpBB","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-48613","published":"2026-06-12"},{"cve_id":"CVE-2026-25927","title":"IDOR in the DICOM viewer state API allows reading or modifying any document's state","description":"OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0,  the DICOM viewer state API (e.g. upload or state save/load) accepts a document ID (`doc_id`) without verifying that the document belongs to the current user’s authorized patient or encounter. An authenticated user can read or modify DICOM viewer state (e.g. annotations, view settings) for any document by enumerating document IDs. Version 8.0.0 fixes the issue.","severity":"high","cvss_score":7.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","cwe":"CWE-639","product":"openemr","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-25927","published":"2026-02-25"},{"cve_id":"CVE-2026-25147","title":"IDOR in the portal payment page via a user-supplied pid parameter","description":"OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, in `portal/portal_payment.php`, the patient id used for the page is taken from the request (`$pid = $_REQUEST['pid'] ?? $pid` and `$pid = ($_REQUEST['hidden_patient_code'] ?? null) > 0 ? $_REQUEST['hidden_patient_code'] : $pid`) instead of being fixed to the authenticated portal user. The portal session already has a valid `$pid` for the logged-in patient. Overwriting it with user-supplied values and using it without authorization allows a portal user to view and interact with another patient's demographics, invoices, and payment history—horizontal privilege escalation and IDOR. Version 8.0.0 contains a fix for the issue.","severity":"high","cvss_score":7.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","cwe":"CWE-639","product":"openemr","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-25147","published":"2026-02-27"},{"cve_id":"CVE-2026-24902","title":"SSRF and private network restriction bypass via numeric IP destinations","description":"TrustTunnel is an open-source VPN protocol with a server-side request forgery and and private network restriction bypass in versions prior to 0.9.114. In `tcp_forwarder.rs`, SSRF protection for `allow_private_network_connections = false` was only applied in the `TcpDestination::HostName(peer)` path. The `TcpDestination::Address(peer) => peer` path proceeded to `TcpStream::connect()` without equivalent checks (for example `is_global_ip`, `is_loopback`), allowing loopback/private targets to be reached by supplying a numeric IP. The vulnerability is fixed in version 0.9.114.","severity":"high","cvss_score":7.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N","cwe":"CWE-918","product":"TrustTunnel","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-24902","published":"2026-01-29"},{"cve_id":"CVE-2026-22695","title":"Heap buffer over-read in png_image_finish_read when reading interlaced 16-bit PNGs","description":"LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.6.51 to 1.6.53, there is a heap buffer over-read in the libpng simplified API function png_image_finish_read when processing interlaced 16-bit PNGs with 8-bit output format and non-minimal row stride. This is a regression introduced by the fix for CVE-2025-65018. This vulnerability is fixed in 1.6.54.","severity":"high","cvss_score":7.1,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","cwe":"CWE-125","product":"libpng","reference_count":4,"url":"https://www.cve.org/CVERecord?id=CVE-2026-22695","published":"2026-01-12"},{"cve_id":"CVE-2026-9808","title":"Owner-scope role restrictions not enforced on API v2 endpoints, exposing other users' data","description":"An authorization bypass vulnerability exists in the Mautic 7 API v2 endpoints (utilizing API Platform). Under certain conditions, roles configured with owner-scope restrictions (such as `viewown` or `editown`) are not properly enforced. This allows low-privilege authenticated API users to bypass ownership-logic controls and access or modify resources belonging to other users.","severity":"high","cvss_score":7.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","cwe":"CWE-863","product":"mautic/core","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-9808","published":"2026-05-29"},{"cve_id":"CVE-2025-39840","title":"Out-of-bounds read in audit_compare_dname_path() when watching the root directory","description":"In the Linux kernel, the following vulnerability has been resolved:\n\naudit: fix out-of-bounds read in audit_compare_dname_path()\n\nWhen a watch on dir=/ is combined with an fsnotify event for a\nsingle-character name directly under / (e.g., creating /a), an\nout-of-bounds read can occur in audit_compare_dname_path().\n\nThe helper parent_len() returns 1 for \"/\". In audit_compare_dname_path(),\nwhen parentlen equals the full path length (1), the code sets p = path + 1\nand pathlen = 1 - 1 = 0. The subsequent loop then dereferences\np[pathlen - 1] (i.e., p[-1]), causing an out-of-bounds read.\n\nFix this by adding a pathlen > 0 check to the while loop condition\nto prevent the out-of-bounds access.\n\n[PM: subject tweak, sign-off email fixes]","severity":"high","cvss_score":7.1,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","cwe":"CWE-125","product":"Linux","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2025-39840","published":"2025-09-19"},{"cve_id":"CVE-2025-39839","title":"Out-of-bounds read and write in batman-adv network-coding decode","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: fix OOB read/write in network-coding decode\n\nbatadv_nc_skb_decode_packet() trusts coded_len and checks only against\nskb->len. XOR starts at sizeof(struct batadv_unicast_packet), reducing\npayload headroom, and the source skb length is not verified, allowing an\nout-of-bounds read and a small out-of-bounds write.\n\nValidate that coded_len fits within the payload area of both destination\nand source sk_buffs before XORing.","severity":"high","cvss_score":7.1,"cvss_vector":"","cwe":"CWE-787","product":"Linux","reference_count":8,"url":"https://www.cve.org/CVERecord?id=CVE-2025-39839","published":"2025-09-19"},{"cve_id":"CVE-2026-102010","title":"Denial of service via use-after-free in binary heap erase_if","description":"A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption.","severity":"high","cvss_score":7.0,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","cwe":"CWE-825","product":"gcc","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-102010","published":"2026-09-29"},{"cve_id":"CVE-2026-56109","title":"Double free in parse_def() when parsing nested compound configuration blocks","description":"The Advanced Linux Sound Architecture (ALSA) library before 1.2.16.1 contains a double-free vulnerability in parse_def() in src/conf.c that allows attackers to corrupt memory by supplying maliciously crafted ALSA configuration text. When parsing nested compound or array configuration blocks, parse_def() fails to check return values before continuing, causing snd_config_delete() to be called twice on the same already-freed node, resulting in a NULL-pointer write or invalid memory read.","severity":"high","cvss_score":7,"cvss_vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N","cwe":"CWE-415","product":"alsa-lib","reference_count":4,"url":"https://www.cve.org/CVERecord?id=CVE-2026-56109","published":"2026-06-22"},{"cve_id":"CVE-2026-44604","title":"Command injection in rpmuncompress via an archive's top-level directory name","description":"A command injection vulnerability was discovered in the `rpmuncompress` utility of RPM. When extracting certain archive formats (ZIP, 7z, GEM) to a specified destination directory, the tool inserts the archive's top-level folder name into a shell command without properly sanitizing it. A specially crafted archive containing shell metacharacters in its folder name can execute arbitrary commands as the user running the extraction.","severity":"high","cvss_score":7,"cvss_vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":"CWE-78","product":"rpm","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-44604","published":"2026-05-28"},{"cve_id":"CVE-2026-82465","title":"pac4j-saml before 6.5.6 Session Destruction via Unsigned LogoutRequest","description":"pac4j-saml before 6.5.6 does not require signature validation of SAML LogoutRequest messages in SAML2LogoutValidator.validateLogoutRequest(). When an IdP sends no SessionIndex, a session can be destroyed based solely on the NameID, allowing an unauthenticated attacker to submit an unsigned LogoutRequest with a guessed identifier (e.g., an email address used as NameID) to terminate a victim's SAML session.","severity":"medium","cvss_score":6.9,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","cwe":"CWE-345","product":"pac4j","reference_count":5,"url":"https://www.cve.org/CVERecord?id=CVE-2026-82465","published":"2026-08-29"},{"cve_id":"CVE-2026-82462","title":"pac4j-oidc before 6.5.6 Authentication Bypass via Access Token Substitution","description":"pac4j-oidc before 6.5.6 accepts OIDC callbacks carrying only an access token without authorization code or ID token validation. Attackers can substitute access tokens minted for other clients to create authenticated sessions without proper issuer, audience, nonce, or subject verification.","severity":"medium","cvss_score":6.9,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N","cwe":"CWE-345","product":"pac4j","reference_count":5,"url":"https://www.cve.org/CVERecord?id=CVE-2026-82462","published":"2026-08-29"},{"cve_id":"CVE-2026-67217","title":"Non-atomic JSON Patch application destroys target document members on failed operations","description":"cJSON through 1.7.19 applies RFC 6902 JSON Patch operations non-atomically in apply_patch() in cJSON_Utils.c. For a replace operation that is missing its value member, or a move operation whose destination path cannot be resolved, the existing target member is detached and deleted before the operation is fully validated, so the target document is mutated while cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive() returns a failure status. An attacker who can supply the patch document can destroy addressable members of the target document even though the API reports that the patch failed, defeating the all-or-nothing behavior callers rely on to reject bad patches.","severity":"medium","cvss_score":6.9,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","cwe":"CWE-696","product":"cJSON","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-67217","published":"2026-07-29"},{"cve_id":"CVE-2026-65051","title":"Validation bypass via client-controlled field metadata in the AJAX submission handler","description":"Ninja Forms WordPress plugin version 3.14.8 contains a client-side enforcement of server-side security vulnerability that allows unauthenticated attackers to bypass all form validation by merging attacker-controlled field metadata over server-loaded form definitions before validation runs. Attackers can craft a malicious AJAX submission overriding field types, removing required flags, and disabling CAPTCHA checks through the nopriv AJAX endpoint to trigger form actions such as email notifications and database storage with unverified, attacker-controlled content.","severity":"medium","cvss_score":6.9,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N","cwe":"CWE-602","product":"Ninja Forms","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-65051","published":"2026-07-22"},{"cve_id":"CVE-2025-65092","title":"Out-of-bounds read when parsing JPEG headers for the ESP32-P4 hardware decoder","description":"ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.1, 5.4.3, and 5.3.4, when the ESP32-P4 uses its hardware JPEG decoder, the software parser lacks necessary validation checks. A specially crafted (malicious) JPEG image could exploit the parsing routine and trigger an out-of-bounds array access. This issue has been fixed in versions 5.5.2, 5.4.4, and 5.3.5. At time of publication versions 5.5.2, 5.4.4, and 5.3.5 have not been released but are fixed respectively in commits 4b8f585, c79cb4d, and 34e2726.","severity":"medium","cvss_score":6.9,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","cwe":"CWE-125","product":"esp-idf","reference_count":5,"url":"https://www.cve.org/CVERecord?id=CVE-2025-65092","published":"2025-11-21"},{"cve_id":"CVE-2026-93689","title":"NULL Pointer Dereference via Fast I/O","description":"WinFsp through 2.2.26215 contains a null pointer dereference vulnerability in the kernel driver's Fast I/O device control handler that fails to validate the volume context before use. An unprivileged local user can trigger a denial of service by opening the WinFsp control device and issuing FSP_IOCTL_TRANSACT requests, causing a system crash.","severity":"medium","cvss_score":6.8,"cvss_vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","cwe":"CWE-476","product":"winfsp","reference_count":8,"url":"https://www.cve.org/CVERecord?id=CVE-2026-93689","published":"2026-09-20"},{"cve_id":"CVE-2026-28450","title":"Missing authentication on the Nostr plugin's profile HTTP endpoints","description":"OpenClaw versions prior to 2026.2.12 with the optional Nostr plugin enabled expose unauthenticated HTTP endpoints at /api/channels/nostr/:accountId/profile and /api/channels/nostr/:accountId/profile/import that allow reading and modifying Nostr profiles without gateway authentication. Remote attackers can exploit these endpoints to read sensitive profile data, modify Nostr profiles, persist malicious changes to gateway configuration, and publish signed Nostr events using the bot's private key when the gateway HTTP port is accessible beyond localhost.","severity":"medium","cvss_score":6.8,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N","cwe":"CWE-306","product":"OpenClaw","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-28450","published":"2026-03-05"},{"cve_id":"CVE-2026-23893","title":"Symlink following in group-writable token directories leading to privilege escalation","description":"openCryptoki is a PKCS#11 library and provides tooling for Linux and AIX. Versions 2.3.2 and above are vulnerable to symlink-following when running in privileged contexts. A token-group user can redirect file operations to arbitrary filesystem targets by planting symlinks in group-writable token directories, resulting in privilege escalation or data exposure. Token and lock directories are 0770 (group-writable for token users), so any token-group member can plant files and symlinks inside them. When run as root, the base code handling token directory file access, as well as several openCryptoki tools used for administrative purposes, may reset ownership or permissions on existing files inside the token directories. An attacker with token-group membership can exploit the system when an administrator runs a PKCS#11 application or administrative tool that performs chown on files inside the token directory during normal maintenance. This issue is fixed in commit 5e6e4b4, but has not been included in a released version at the time of publication.","severity":"medium","cvss_score":6.8,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L","cwe":"CWE-59","product":"opencryptoki","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-23893","published":"2026-01-22"},{"cve_id":"CVE-2025-41117","title":"XSS via stack traces rendered as raw HTML in the Explore Traces view","description":"Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the browser. This would require malicious JavaScript to be entered into the stack trace field.\n\nOnly datasources with the Jaeger HTTP API appear to be affected; Jaeger gRPC and Tempo do not appear affected whatsoever.","severity":"medium","cvss_score":6.8,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","cwe":"CWE-79","product":"grafana/grafana","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2025-41117","published":"2026-02-12"},{"cve_id":"CVE-2026-73583","title":"Unsafe deserialization in sblim-sfcb provider-manager ipc allows out-of-bounds memory access via malformed operationhdr","description":"A flaw was found in sblim-sfcb. A local attacker with access to the system can exploit an unsafe deserialization vulnerability in the provider-manager's inter-process communication (IPC) message parsing. By sending a specially crafted message, the attacker can cause out-of-bounds memory access, leading to the termination of the provider-manager process and a denial of service. This could also potentially result in limited unintended information disclosure.","severity":"medium","cvss_score":6.6,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H","cwe":"CWE-125","product":"sblim-sfcb","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-73583","published":"2026-08-13"},{"cve_id":"CVE-2026-22791","title":"Heap buffer overflow in C_WrapKey with CKM_ECDH_AES_KEY_WRAP via compressed EC keys","description":"openCryptoki is a PKCS#11 library and tools for Linux and AIX. In 3.25.0 and 3.26.0, there is a heap buffer overflow vulnerability in the CKM_ECDH_AES_KEY_WRAP implementation allows an attacker with local access to cause out-of-bounds writes in the host process by supplying a compressed EC public key and invoking C_WrapKey. This can lead to heap corruption, or denial-of-service.","severity":"medium","cvss_score":6.6,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H","cwe":"CWE-131","product":"opencryptoki","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-22791","published":"2026-01-13"},{"cve_id":"CVE-2026-19696","title":"Out-of-bounds write in BLF file parsing","description":"Ixia IxVeriWave and Vector Informatik BLF file parser crashes in 4.6.0 to 4.6.7 allows denial of service on Windows","severity":"medium","cvss_score":6.6,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H","cwe":"CWE-787","product":"Wireshark","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-19696","published":"2026-08-13"},{"cve_id":"CVE-2026-94283","title":"Out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser","description":"An out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","cwe":"CWE-125","product":"libX11","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-94283","published":"2026-09-28"},{"cve_id":"CVE-2026-94281","title":"Out-of-bounds read in libXi's XListInputDevices() class parsing","description":"An out-of-bounds read in libXi's XListInputDevices() class parsing in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","cwe":"CWE-125","product":"libXi","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-94281","published":"2026-09-24"},{"cve_id":"CVE-2026-93545","title":"Out-of-bounds read in libXi's XListInputDevices()","description":"An out-of-bounds read in libXi's XListInputDevices() in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","cwe":"CWE-125","product":"libXi","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-93545","published":"2026-09-24"},{"cve_id":"CVE-2026-93544","title":"Out-of-bounds read in libXi's XI2 XIQueryDevice reply parsing","description":"An out-of-bounds read in libXi's XI2 XIQueryDevice reply parsing in libXi before 1.8.4 can be used by a malicious X server to crash an attached X client.","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","cwe":"CWE-125","product":"libXi","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-93544","published":"2026-09-24"},{"cve_id":"CVE-2026-93542","title":"Out-of-bounds read in libXi's XI2 class parsing via size_classes() and copy_classes()","description":"An out-of-bounds read in libXi's XI2 class parsing via size_classes() and copy_classes() in libXi before 1.8.4 could be used by malicous servers to crash the X client.","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","cwe":"CWE-125","product":"libXi","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-93542","published":"2026-09-24"},{"cve_id":"CVE-2026-93541","title":"Out-of-bounds read in libXi's XQueryDeviceState()","description":"An out-of-bounds read in libXi's XQueryDeviceState() in libXi before 1.8.4 could be used by a","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","cwe":"CWE-125","product":"libXi","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-93541","published":"2026-09-24"},{"cve_id":"CVE-2026-92573","title":"Uncontrolled resource consumption during AMQP delivery decompression, message conversion and HTTP management JSON rendering","description":"Improper handling of compressed data in the shared GZIP decompressor used for AMQP 0-8/0-9/0-9-1 and AMQP 0-10 message delivery, message conversion and HTTP management JSON rendering allows authenticated message producers to exhaust memory and disrupt broker availability via processing without a decompressed-output limit.\n\nThis issue affects Apache Qpid Broker-J: through 10.1.0.\n\nUsers are recommended to upgrade to version 10.1.1, which fixes the issue.","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-409","product":"Broker-J","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-92573","published":"2026-09-25"},{"cve_id":"CVE-2026-73199","title":"Null pointer dereference in `ipa-enrollment` extended operation (`join_oid`) via missing request value","description":"A flaw was found in the `ipa-enrollment` SLAPI plugin. A remote authenticated client can exploit a null pointer dereference vulnerability by sending a malformed Lightweight Directory Access Protocol (LDAP) extended operation. By omitting the request value for the `JOIN_OID` in the `ipa-enrollment` extended operation, an attacker can trigger a server crash, potentially causing a denial of service.","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-476","product":"freeipa","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-73199","published":"2026-08-21"},{"cve_id":"CVE-2026-71225","title":"IV reuse across chunks in one-shot symmetric cipher operations on large inputs","description":"A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stateful modes such as Counter (CTR) or Cipher Block Chaining (CBC), the library improperly reuses the Initialization Vector (IV) for each internal data chunk. A remote attacker could potentially exploit this by making an application that uses libkcapi process specially crafted large inputs. This can lead to a significant weakening of data confidentiality, as the repeated IV use can expose relationships in encrypted plaintext, and may also affect data integrity by causing incorrect cryptographic processing.","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N","cwe":"CWE-330","product":"libkcapi","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-71225","published":"2026-08-05"},{"cve_id":"CVE-2026-70368","title":"Stack out-of-bounds read in s_vlog() when handling oversized log messages","description":"A stack-based out-of-bounds read vulnerability exists in the \"s_vlog\" function of stunnel, when handling oversized log messages via \"vsnprintf\". A remote attacker with network access to a stunnel service can send protocol inputs that trigger a log message longer than 1024 bytes, leading to an out-of-bounds stack read and a potential crash. In certain corner cases, the same vulnerability could be used to replace a series of trailing \"\\n\" characters with \"\\0\".","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","cwe":"CWE-125","product":"stunnel","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-70368","published":"2026-08-04"},{"cve_id":"CVE-2026-55894","title":"Out-of-bounds read in sh_disassemble when disassembling crafted SH2A bytecode","description":"Capstone SH disassembler `sh_disassemble` out-of-bounds read via crafted SH2A bytecode","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","cwe":"CWE-125","product":"Capstone","reference_count":6,"url":"https://www.cve.org/CVERecord?id=CVE-2026-55894","published":"2026-06-16"},{"cve_id":"CVE-2026-55893","title":"Heap buffer overflow in set_reg_n when disassembling crafted SH2A FPU bytecode","description":"Capstone SH disassembler `set_reg_n` heap buffer overflow via crafted SH2A FPU bytecode ","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","cwe":"CWE-125","product":"Capstone","reference_count":6,"url":"https://www.cve.org/CVERecord?id=CVE-2026-55893","published":"2026-06-15"},{"cve_id":"CVE-2026-53583","title":"Inverted IP SubjectAltName comparison in the OpenSSL backend skips authenticity checks","description":"Logic flaw resulting in lack of authenticity checks in OpenSSL backend","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","cwe":"CWE-297","product":"libgit2","reference_count":6,"url":"https://www.cve.org/CVERecord?id=CVE-2026-53583","published":"2026-07-16"},{"cve_id":"CVE-2026-48744","title":"Permission check bypass in channelUpdate via all([]) lets anonymous users modify channels","description":"Saleor is an e-commerce platform. From 3.14.67 until 3.21.67, 3.22.63, and 3.23.22, a broken authorization check in saleor/permission/utils.py can incorrectly authorize unauthenticated GraphQL requests. The flaw permits anonymous callers to use the channelUpdate() mutation to change channel order settings such as allowUnpaidOrders even when the response reports PermissionDenied. The same permission utility can expose hidden objects through the pageType() and translation() queries, including attributes whose visibleInStorefront field is false and that should be visible only to users with management permissions. This issue is fixed in versions 3.21.67, 3.22.63, and 3.23.22.","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","cwe":"CWE-285","product":"saleor/saleor","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-48744","published":"2026-07-27"},{"cve_id":"CVE-2026-47729","title":"Out-of-bounds read parsing FTP directory listings leaks memory from other transactions","description":"Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway (src/clients/FtpGateway.cc), Squid is vulnerable to an out-of-bounds read: when a listing entry date in the TypeA or TypeB directory-listing formats is not followed by a filename, parsing was not restricted to the input buffer, so a trusted client accessing a misbehaving FTP server through Squid's gateway feature could read memory from random unrelated transactions. This issue is fixed in version 7.6.","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":"CWE-125","product":"squid","reference_count":5,"url":"https://www.cve.org/CVERecord?id=CVE-2026-47729","published":"2026-07-16"},{"cve_id":"CVE-2026-45254","title":"Privilege widening in cap_net when keys omitted from a new limit default to allow-any","description":"In the case of the cap_net service, when a key present in the old limit was omitted from the new limit, the missing key was treated as \"allow any\" instead of being rejected.\n\nIn certain scenarios, an application that had previously restricted a subset of network operations could ask for a new limit that extended the permissions of the process.","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","cwe":"CWE-269","product":"FreeBSD","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-45254","published":"2026-05-21"},{"cve_id":"CVE-2026-35549","title":"Stack overflow via alloca in the caching_sha2_password authentication plugin","description":"An issue was discovered in MariaDB Server before 11.4.10, 11.5.x through 11.8.x before 11.8.6, and 12.x before 12.2.2. If the caching_sha2_password authentication plugin is installed, and some user accounts are configured to use it, a large packet can crash the server because sha256_crypt_r uses alloca.","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-789","product":"MariaDB","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-35549","published":"2026-04-03"},{"cve_id":"CVE-2026-34276","title":"Resource exhaustion in the Group Replication plugin leading to denial of service","description":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin).  Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and  9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-400","product":"MySQL Server","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-34276","published":"2026-04-21"},{"cve_id":"CVE-2026-34271","title":"Hang or repeatable crash in the Group Replication plugin","description":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin).  Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and  9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-400","product":"MySQL Server","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-34271","published":"2026-04-21"},{"cve_id":"CVE-2026-34270","title":"Hang or repeatable crash in the Group Replication plugin","description":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin).  Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and  9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-400","product":"MySQL Server","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-34270","published":"2026-04-21"},{"cve_id":"CVE-2026-33931","title":"IDOR in the portal payment page exposes other patients' payment records via recid","description":"OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an Insecure Direct Object Reference (IDOR) vulnerability in the patient portal payment page allows any authenticated portal patient to access other patients' payment records — including invoice/billing data (PHI) and payment card metadata — by manipulating the `recid` query parameter in `portal/portal_payment.php`. Version 8.0.0.3 patches the issue.","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":"CWE-639","product":"openemr","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-33931","published":"2026-03-25"},{"cve_id":"CVE-2026-33304","title":"Authorization bypass in the dated reminders log exposes other users' reminder messages","description":"OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, an authorization bypass in the dated reminders log allows any authenticated non-admin user to view reminder messages belonging to other users, including associated patient names and free-text message content, by crafting a GET request with arbitrary user IDs in the `sentTo[]` or `sentBy[]` parameters. Version 8.0.0.2 fixes the issue.","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":"CWE-639","product":"openemr","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-33304","published":"2026-03-19"},{"cve_id":"CVE-2026-32120","title":"IDOR in fee sheet product save allows modifying other patients' drug sales records","description":"OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an Insecure Direct Object Reference (IDOR) vulnerability in the fee sheet product save logic (`library/FeeSheet.class.php`) allows any authenticated user with fee sheet ACL access to delete, modify, or read `drug_sales` records belonging to arbitrary patients by manipulating the hidden `prod[][sale_id]` form field. The `save()` method uses the user-supplied `sale_id` in five SQL queries (SELECT, UPDATE, DELETE) without verifying that the record belongs to the current patient and encounter. Version 8.0.0.3 contains a patch.","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","cwe":"CWE-639","product":"openemr","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-32120","published":"2026-03-25"},{"cve_id":"CVE-2026-28467","title":"SSRF in attachment and media URL hydration","description":"OpenClaw versions prior to 2026.2.2 contain a server-side request forgery vulnerability in attachment and media URL hydration that allows remote attackers to fetch arbitrary HTTP(S) URLs. Attackers who can influence media URLs through model-controlled sendAttachment or auto-reply mechanisms can trigger SSRF to internal resources and exfiltrate fetched response bytes as outbound attachments.","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L","cwe":"CWE-918","product":"OpenClaw","reference_count":4,"url":"https://www.cve.org/CVERecord?id=CVE-2026-28467","published":"2026-03-05"},{"cve_id":"CVE-2026-27943","title":"Insecure direct object reference in the eye exam (eye_mag) view via form_id","description":"OpenEMR is a free and open source electronic health records and medical practice management application. In versions up to and including 8.0.0, the eye exam (eye_mag) view loads data by `form_id` (or equivalent) without verifying that the form belongs to the current user’s patient/encounter context. An authenticated user can access or edit any patient’s eye exam by supplying another form ID; in some flows the session’s active patient may also be switched. A fix is available on the `main` branch of the OpenEMR GitHub repository.","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":"CWE-639","product":"openemr","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-27943","published":"2026-02-26"},{"cve_id":"CVE-2026-26327","title":"Trust of unauthenticated discovery TXT records for client routing and TLS pinning","description":"OpenClaw is a personal AI assistant. Discovery beacons (Bonjour/mDNS and DNS-SD) include TXT records such as `lanHost`, `tailnetDns`, `gatewayPort`, and `gatewayTlsSha256`. TXT records are unauthenticated. Prior to version 2026.2.14, some clients treated TXT values as authoritative routing/pinning inputs. iOS and macOS used TXT-provided host hints (`lanHost`/`tailnetDns`) and ports (`gatewayPort`) to build the connection URL. iOS and Android allowed the discovery-provided TLS fingerprint (`gatewayTlsSha256`) to override a previously stored TLS pin. On a shared/untrusted LAN, an attacker could advertise a rogue `_openclaw-gw._tcp` service. This could cause a client to connect to an attacker-controlled endpoint and/or accept an attacker certificate, potentially exfiltrating Gateway credentials (`auth.token` / `auth.password`) during connection. As of time of publication, the iOS and Android apps are alpha/not broadly shipped (no public App Store / Play Store release). Practical impact is primarily limited to developers/testers running those builds, plus any other shipped clients relying on discovery on a shared/untrusted LAN. Version 2026.2.14 fixes the issue. Clients now prefer the resolved service endpoint (SRV + A/AAAA) over TXT-provided routing hints. Discovery-provided fingerprints no longer override stored TLS pins. In iOS/Android, first-time TLS pins require explicit user confirmation (fingerprint shown; no silent TOFU) and discovery-based direct connects are TLS-only. In Android, hostname verification is no longer globally disabled (only bypassed when pinning).","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","cwe":"CWE-345","product":"OpenClaw","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-26327","published":"2026-02-19"},{"cve_id":"CVE-2026-25930","title":"IDOR in the printable LBF view allows viewing any patient's encounter forms","description":"OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the Layout-Based Form (LBF) printable view accepts `formid` and `visitid` (or `patientid`) from the request and does not verify that the form belongs to the current user’s authorized patient/encounter. An authenticated user with LBF access can enumerate form IDs and view or print any patient’s encounter forms. Version 8.0.0 fixes the issue.","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":"CWE-639","product":"openemr","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-25930","published":"2026-02-25"},{"cve_id":"CVE-2026-25929","title":"IDOR in the patient_picture document context allows retrieving any patient's photo","description":"OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the document controller’s `patient_picture` context serves the patient’s photo by document ID or patient ID without verifying that the current user is authorized to access that patient. An authenticated user with document ACL can supply another patient’s ID and retrieve their photo. Version 8.0.0 fixes the issue.","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":"CWE-639","product":"openemr","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-25929","published":"2026-02-25"},{"cve_id":"CVE-2026-25928","title":"Path traversal when zipping DICOM folders leads to arbitrary file write","description":"OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, the DICOM zip/export feature uses a user-supplied destination or path component when creating the zip file, without sanitizing path traversal sequences (e.g. `../`). An attacker with DICOM upload/export permission can write files outside the intended directory, potentially under the web root, leading to arbitrary file write and possibly remote code execution if PHP or other executable files can be written. Version 8.0.0.2 fixes the issue.","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","cwe":"CWE-22","product":"openemr","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-25928","published":"2026-03-19"},{"cve_id":"CVE-2026-25745","title":"IDOR in the message update endpoint allows modifying any patient's messages","description":"OpenEMR is a free and open source electronic health records and medical practice management application. In versions up to and including 8.0.0, the message/note update endpoint (e.g. PUT or POST) updates by message/note ID only and does not verify that the message belongs to the current patient (or that the user is allowed to edit that patient’s notes). An authenticated user with notes permission can modify any patient’s messages by supplying another message ID. Commit 92a2ff9eaaa80674b3a934a6556e35e7aded5a41 contains a fix for the issue.","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","cwe":"CWE-639","product":"openemr","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-25745","published":"2026-03-18"},{"cve_id":"CVE-2026-25744","title":"IDOR in the encounter vitals API allows overwriting any patient's vitals","description":"OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, the encounter vitals API accepts an `id` in the request body and treats it as an UPDATE. There is no verification that the vital belongs to the current patient or encounter. An authenticated user with encounters/notes permission can overwrite any patient's vitals by supplying another patient's vital `id`, leading to medical record tampering. Version 8.0.0.2 fixes the issue.","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","cwe":"CWE-639","product":"openemr","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-25744","published":"2026-03-19"},{"cve_id":"CVE-2026-25565","title":"Missing write-permission check lets read-only board members update cards","description":"WeKan versions prior to 8.19 contain an authorization vulnerability where certain card update API paths validate only board read access rather than requiring write permission. This can allow users with read-only roles to perform card updates that should require write access.","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","cwe":"CWE-863","product":"WeKan","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-25565","published":"2026-02-07"},{"cve_id":"CVE-2026-25554","title":"SQL injection via the JWT tag claim in jwt_db_authorize() enabling authentication bypass","description":"OpenSIPS versions 3.1 before 3.6.4 containing the auth_jwt module (prior to commit 3822d33) contain a SQL injection vulnerability in the jwt_db_authorize() function in modules/auth_jwt/authorize.c when db_mode is enabled and a SQL database backend is used. The function extracts the tag claim from a JWT without prior signature verification and incorporates the unescaped value directly into a SQL query. An attacker can supply a crafted JWT with a malicious tag claim to manipulate the query result and bypass JWT authentication, allowing impersonation of arbitrary identities.","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N","cwe":"CWE-89","product":"OpenSIPS","reference_count":5,"url":"https://www.cve.org/CVERecord?id=CVE-2026-25554","published":"2026-02-25"},{"cve_id":"CVE-2026-25220","title":"Missing admin check on the Message Center show_all parameter exposing all users' messages","description":"OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the Message Center accepts the URL parameter `show_all=yes` and passes it to `getPnotesByUser()`, which returns all internal messages (all users’ notes). The backend does not verify that the requesting user is an administrator before honoring `show_all=yes`. The \"Show All\" link is also visible to non-admin users. As a result, any authenticated user can view the entire internal message list by requesting `messages.php?show_all=yes`. Version 8.0.0 patches the issue.","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P","cwe":"CWE-639","product":"openemr","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-25220","published":"2026-02-25"},{"cve_id":"CVE-2026-24488","title":"Arbitrary file exfiltration via unrestricted file paths in the fax sending endpoint","description":"OpenEMR is a free and open source electronic health records and medical practice management application. In versions up to and including 8.0.0, an arbitrary file exfiltration vulnerability in the fax sending endpoint allows any authenticated user to read and transmit any file on the server (including database credentials, patient documents, system files, and source code) via fax to an attacker-controlled phone number. The vulnerability exists because the endpoint accepts arbitrary file paths from user input and streams them to the fax gateway without path restrictions or authorization checks. As of time of publication, no known patched versions are available.","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":"CWE-22","product":"openemr","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-24488","published":"2026-02-27"},{"cve_id":"CVE-2026-24487","title":"FHIR patient compartment bypass in the CareTeam endpoint exposing cross-patient data","description":"OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, an authorization bypass vulnerability in the FHIR CareTeam resource endpoint allows patient-scoped FHIR tokens to access care team data for all patients instead of being restricted to only the authenticated patient's data. This could potentially lead to unauthorized disclosure of Protected Health Information (PHI), including patient-provider relationships and care team structures across the entire system. The issue occurs because the `FhirCareTeamService` does not implement the `IPatientCompartmentResourceService` interface and does not pass the patient binding parameter to the underlying service, bypassing the patient compartment filtering mechanism. Version 8.0.0 contains a patch for this issue.","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P","cwe":"CWE-200","product":"openemr","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-24487","published":"2026-02-25"},{"cve_id":"CVE-2026-23964","title":"Insecure direct object reference in the web push subscription update endpoint","description":"Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.5, 4.4.12, and 4.3.18, an insecure direct object reference in the web push subscription update endpoint lets any authenticated user update another user's push subscription by guessing or obtaining the numeric subscription id. This can be used to disrupt push notifications for other users and also leaks the web push subscription endpoint. Any user with a web push subscription is impacted, because another authenticated user can tamper with their push subscription settings if they can guess or obtain the subscription id. This allows an attacker to disrupt push notifications by changing the policy (whether to filter notifications from non-followers or non-followed users) and subscribed notification types of their victims. Additionally, the endpoint returns the subscription object, which includes the push notification endpoint for this subscription, but not its keypair. Mastodon versions v4.5.5, v4.4.12, v4.3.18 are patched.","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","cwe":"CWE-863","product":"mastodon","reference_count":4,"url":"https://www.cve.org/CVERecord?id=CVE-2026-23964","published":"2026-01-22"},{"cve_id":"CVE-2026-22246","title":"Missing ownership check lets any user download other users' severed relationship lists","description":"Mastodon is a free, open-source social network server based on ActivityPub. Mastodon 4.3 added notifications of severed relationships, allowing end-users to inspect the relationships they lost as the result of a moderation action. The code allowing users to download lists of severed relationships for a particular event fails to check the owner of the list before returning the lost relationships. Any registered local user can access the list of lost followers and followed users caused by any severance event, and go through all severance events this way. The leaked information does not include the name of the account which has lost follows and followers. This has been fixed in Mastodon v4.3.17, v4.4.11 and v4.5.4.","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":"CWE-201","product":"mastodon","reference_count":4,"url":"https://www.cve.org/CVERecord?id=CVE-2026-22246","published":"2026-01-08"},{"cve_id":"CVE-2026-18728","title":"Integer underflow in iscsiuio ipv4 dhcp parsing","description":"A flaw was found in open-iscsi. An integer underflow vulnerability in the `iscsiuio` component, specifically during IPv4 Dynamic Host Configuration Protocol (DHCP) parsing, allows a remote attacker on the same local network segment to cause a denial of service. By sending a specially crafted IPv4/UDP DHCP reply, the attacker can trigger an out-of-bounds read, leading to the `iscsiuio` process crashing. This issue affects systems where `iscsiuio` is actively handling IPv4 DHCP traffic.","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-191","product":"open-iscsi","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-18728","published":"2026-08-19"},{"cve_id":"CVE-2026-18727","title":"Integer underflow in iscsiuio dhcpv6 parsing","description":"A flaw was found in open-iscsi's iscsiuio component. This vulnerability involves an integer underflow and out-of-bounds read during Dynamic Host Configuration Protocol for IPv6 (DHCPv6) packet parsing. Specifically, crafted DHCPv6 Advertise traffic with a short User Datagram Protocol (UDP) length can cause the DHCPv6 payload length to underflow. An unauthenticated attacker on an adjacent network segment can exploit this by sending specially crafted IPv6 UDP traffic while the client is in an active DHCPv6 exchange, leading to a denial of service due to a process crash or service disruption.","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-191","product":"open-iscsi","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-18727","published":"2026-08-19"},{"cve_id":"CVE-2026-18726","title":"Denial of service in iscsiuio router advertisement parsing","description":"A flaw was found in open-iscsi. This vulnerability allows a remote attacker on the same local network segment to cause a Denial of Service (DoS) in the iscsiuio daemon. By sending a specially crafted Internet Control Message Protocol version 6 (ICMPv6) Router Advertisement with a zero-length option, the attacker can trigger an infinite loop. This leads to sustained CPU usage, rendering the daemon unresponsive and impacting system availability. A secondary risk of out-of-bounds reads exists with a short IPv6 payload, though no memory corruption or data exposure has been confirmed.","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-835","product":"open-iscsi","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-18726","published":"2026-08-19"},{"cve_id":"CVE-2026-16461","title":"Stack buffer overflow in rpcinfo's rpcbdump() when formatting remote version lists","description":"A stack-based buffer overflow was found in rpcbind's rpcinfo utility. In rpcbdump() short mode (used by `rpcinfo -s`), version numbers from a remote RPCBPROC_DUMP reply are written into a fixed-size stack buffer without bounds checking. A user or administrator who runs `rpcinfo -s` against a malicious or compromised rpcbind endpoint could experience a crash or denial of service of the rpcinfo client.","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","cwe":"CWE-121","product":"rpcbind","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-16461","published":"2026-07-24"},{"cve_id":"CVE-2026-16277","title":"Stack buffer overflow in rpcinfo's rpcbaddrlist() via a malicious rpcbind server","description":"A stack-based buffer overflow was found in rpcbind's rpcinfo utility. When querying a remote rpcbind service with `rpcinfo -l`, address information returned by the server is copied into a fixed-size buffer without sufficient bounds checking. A malicious or compromised rpcbind server could use this flaw to crash the rpcinfo client, resulting in a denial of service. The highest threat from this vulnerability is to system availability.","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","cwe":"CWE-121","product":"rpcbind","reference_count":4,"url":"https://www.cve.org/CVERecord?id=CVE-2026-16277","published":"2026-07-24"},{"cve_id":"CVE-2026-14258","title":"Infinite loop and out-of-bounds read via a zero-length option in IPv6 Router Advertisements","description":"A flaw was found in dhcpcd's IPv6 Neighbor Discovery Router Advertisement processing. A specially crafted IPv6 Router Advertisement containing a zero-length Neighbor Discovery option can bypass validation during packet storage and later be reparsed without adequate validation, causing the parser to enter a non-advancing loop. Successful exploitation may result in excessive CPU consumption, leading to a denial of service.","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-835","product":"dhcpcd","reference_count":4,"url":"https://www.cve.org/CVERecord?id=CVE-2026-14258","published":"2026-07-16"},{"cve_id":"CVE-2026-9150","title":"Stack buffer overflow in the Debian metadata parser via SHA384/SHA512 checksum tags","description":"A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA512 checksum tags, leading to memory corruption and a denial of service (DoS) in the affected system.","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","cwe":"CWE-121","product":"libsolv","reference_count":6,"url":"https://www.cve.org/CVERecord?id=CVE-2026-9150","published":"2026-05-20"},{"cve_id":"CVE-2026-9149","title":"Heap buffer overflow in repo_add_solv() via negative size values in a crafted .solv file","description":"A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a subsequent out-of-bounds write. An attacker could exploit this to cause a denial of service (DoS).","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","cwe":"CWE-122","product":"libsolv","reference_count":5,"url":"https://www.cve.org/CVERecord?id=CVE-2026-9149","published":"2026-05-20"},{"cve_id":"CVE-2026-5142","title":"Cross-tenant private SSH key disclosure via taxonomy scoping bypass","description":"A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing them to download private SSH (Secure Shell) keys from other organizations by directly querying key pair IDs. This vulnerability leads to cross-tenant data exposure in multi-tenant deployments, potentially compromising sensitive information.","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":"CWE-639","product":"Foreman","reference_count":6,"url":"https://www.cve.org/CVERecord?id=CVE-2026-5142","published":"2026-07-16"},{"cve_id":"CVE-2026-5135","title":"Authorization bypass lets host editors retarget lookup value overrides to other hosts","description":"A flaw was found in Foreman. This broken access control vulnerability allows an authenticated user with host-edit permissions to retarget an existing lookup value override to a different host. This is achieved by modifying the match field through nested host attributes, effectively bypassing authorisation checks. The consequence is the potential for unauthorised modification of managed host configurations across different organisational and location boundaries.","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","cwe":"CWE-639","product":"Foreman","reference_count":6,"url":"https://www.cve.org/CVERecord?id=CVE-2026-5135","published":"2026-07-16"},{"cve_id":"CVE-2026-2340","title":"WORM protection bypass in vfs_worm via rename over a protected file","description":"A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write access to a share could overwrite a protected file by renaming a newly created file over the existing WORM-protected file.","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","cwe":"CWE-280","product":"Samba","reference_count":13,"url":"https://www.cve.org/CVERecord?id=CVE-2026-2340","published":"2026-05-27"},{"cve_id":"CVE-2026-2208","title":"Missing authorization in the rules publication","description":"A security vulnerability has been detected in WeKan up to 8.20. Impacted is an unknown function of the file server/publications/rules.js of the component Rules Handler. The manipulation leads to missing authorization. The attack can be initiated remotely. Upgrading to version 8.21 is recommended to address this issue. The identifier of the patch is a787bcddf33ca28afb13ff5ea9a4cb92dceac005. The affected component should be upgraded.","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X","cwe":"CWE-862","product":"WeKan","reference_count":6,"url":"https://www.cve.org/CVERecord?id=CVE-2026-2208","published":"2026-02-08"},{"cve_id":"CVE-2026-0529","title":"Buffer overflow in the MongoDB protocol parser via crafted network traffic","description":"Improper Validation of Array Index (CWE-129) in Packetbeat’s MongoDB protocol parser can allow an attacker to cause Overflow Buffers (CAPEC-100) through specially crafted network traffic. This requires an attacker to send a malformed payload to a monitored network interface where MongoDB protocol parsing is enabled.","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-129","product":"Packetbeat","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-0529","published":"2026-01-14"},{"cve_id":"CVE-2025-68382","title":"Out-of-bounds read in the NFS dissector when handling truncated XDR-encoded RPC messages","description":"Out-of-bounds read (CWE-125) allows an unauthenticated remote attacker to perform a buffer overflow (CAPEC-100) via the NFS protocol dissector, leading to a denial-of-service (DoS) through a reliable process crash when handling truncated XDR-encoded RPC messages.","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-125","product":"Packetbeat","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2025-68382","published":"2025-12-18"},{"cve_id":"CVE-2025-68381","title":"Buffer overflow via a crafted UDP packet with an invalid fragment sequence number","description":"Improper Bounds Check (CWE-787) in Packetbeat can allow a remote unauthenticated attacker to exploit a Buffer Overflow (CAPEC-100) and reliably crash the application or cause significant resource exhaustion via a single crafted UDP packet with an invalid fragment sequence number.","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-787","product":"Packetbeat","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2025-68381","published":"2025-12-18"},{"cve_id":"CVE-2025-14331","title":"Same-origin policy bypass in the Request Handling component","description":"Same-origin policy bypass in the Request Handling component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","cwe":"CWE-346","product":"Firefox","reference_count":6,"url":"https://www.cve.org/CVERecord?id=CVE-2025-14331","published":"2025-12-09"},{"cve_id":"CVE-2025-9231","title":"Timing side channel in SM2 signature computation on 64-bit ARM allows private key recovery","description":"Issue summary: A timing side-channel which could potentially allow remote\nrecovery of the private key exists in the SM2 algorithm implementation on 64 bit\nARM platforms.\n\nImpact summary: A timing side-channel in SM2 signature computations on 64 bit\nARM platforms could allow recovering the private key by an attacker..\n\nWhile remote key recovery over a network was not attempted by the reporter,\ntiming measurements revealed a timing signal which may allow such an attack.\n\nOpenSSL does not directly support certificates with SM2 keys in TLS, and so\nthis CVE is not relevant in most TLS contexts.  However, given that it is\npossible to add support for such certificates via a custom provider, coupled\nwith the fact that in such a custom provider context the private key may be\nrecoverable via remote timing measurements, we consider this to be a Moderate\nseverity issue.\n\nThe FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this\nissue, as SM2 is not an approved algorithm.","severity":"medium","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","cwe":"CWE-385","product":"OpenSSL","reference_count":5,"url":"https://www.cve.org/CVERecord?id=CVE-2025-9231","published":"2025-09-30"},{"cve_id":"CVE-2026-85592","title":"phpMyFAQ before 4.1.8 Authorization Bypass via question/create","description":"phpMyFAQ before 4.1.8 contains an authorization bypass vulnerability in the question creation endpoint where the isAddingQuestionsAllowed() method grants access to all callers when main.enableAskQuestions is enabled, ignoring the records.allowQuestionsForGuests setting. Unauthenticated attackers can submit questions via the question/create API endpoint to bypass guest submission restrictions and inject spam into the admin moderation queue.","severity":"medium","cvss_score":6.3,"cvss_vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","cwe":"CWE-863","product":"phpMyFAQ","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-85592","published":"2026-09-04"},{"cve_id":"CVE-2026-73585","title":"Insecure temporary file creation in sblim-cmpi-base provider registration scripts allows local symlink attack","description":"A flaw was found in sblim-cmpi-base. Insecure temporary file creation in the provider registration scripts allows a local unprivileged user to perform a symlink attack. By creating a symlink in a world-writable directory, an attacker can redirect privileged writes to an arbitrary file during script execution in a privileged context. This can lead to the overwrite of root-owned files, potentially disrupting system services or operation. Exploitation is conditional on the script running with elevated privileges and may be mitigated by sticky-directory symlink protections.","severity":"medium","cvss_score":6.3,"cvss_vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H","cwe":"CWE-377","product":"sblim-cmpi-base","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-73585","published":"2026-08-13"},{"cve_id":"CVE-2026-73584","title":"Privileged file corruption and denial of service via insecure temporary file handling","description":"A flaw was found in sblim-sfcb. A local, low-privileged attacker can exploit a race condition during privileged instance migration by manipulating a temporary file in the `/tmp` directory. By repeatedly recreating a symbolic link, the attacker can redirect privileged output to an arbitrary file. This can lead to privileged file corruption or a denial of service (DoS) on the system.","severity":"medium","cvss_score":6.3,"cvss_vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H","cwe":"CWE-377","product":"sblim-sfcb","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-73584","published":"2026-08-13"},{"cve_id":"CVE-2026-56350","title":"SSO enforcement bypass via the API lets SSO users create local password credentials","description":"n8n before 2.8.0 contains an authentication bypass vulnerability allowing authenticated SSO users to disable SSO enforcement through the API. Attackers can create local password credentials to authenticate directly, bypassing organizational SSO policies and identity-provider-enforced multi-factor authentication.","severity":"medium","cvss_score":6.3,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","cwe":"CWE-285","product":"n8n","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-56350","published":"2026-06-30"},{"cve_id":"CVE-2026-28471","title":"DM allowlist bypass in the Matrix plugin via display names and cross-homeserver localparts","description":"OpenClaw version 2026.1.14-1 prior to 2026.2.2, with the Matrix plugin installed and enabled, contain a vulnerability in which DM allowlist matching could be bypassed by exact-matching against sender display names and localparts without homeserver validation. Remote Matrix users can impersonate allowed identities by using attacker-controlled display names or matching localparts from different homeservers to reach the routing and agent pipeline.","severity":"medium","cvss_score":6.3,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","cwe":"CWE-287","product":"OpenClaw","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-28471","published":"2026-03-05"},{"cve_id":"CVE-2026-1898","title":"Improper access control in LDAP user synchronization","description":"A vulnerability was determined in WeKan up to 8.20. This affects an unknown part of the file packages/wekan-ldap/server/syncUser.js of the component LDAP User Sync. This manipulation causes improper access controls. It is possible to initiate the attack remotely. Upgrading to version 8.21 is able to mitigate this issue. Patch name: 146905a459106b5d00b4f09453a6554255e6965a. You should upgrade the affected component.","severity":"medium","cvss_score":6.3,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X","cwe":"CWE-284","product":"WeKan","reference_count":6,"url":"https://www.cve.org/CVERecord?id=CVE-2026-1898","published":"2026-02-05"},{"cve_id":"CVE-2026-1896","title":"Improper access control in the ComprehensiveBoardMigration operation via boardId","description":"A vulnerability has been found in WeKan up to 8.20. Affected by this vulnerability is the function ComprehensiveBoardMigration of the file server/migrations/comprehensiveBoardMigration.js of the component Migration Operation Handler. The manipulation of the argument boardId leads to improper access controls. The attack is possible to be carried out remotely. Upgrading to version 8.21 addresses this issue. The identifier of the patch is cc35dafef57ef6e44a514a523f9a8d891e74ad8f. Upgrading the affected component is advised.","severity":"medium","cvss_score":6.3,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X","cwe":"CWE-284","product":"WeKan","reference_count":6,"url":"https://www.cve.org/CVERecord?id=CVE-2026-1896","published":"2026-02-04"},{"cve_id":"CVE-2026-1895","title":"Improper access control in the applyWipLimit list method","description":"A flaw has been found in WeKan up to 8.20. Affected is the function applyWipLimit of the file models/lists.js of the component Attachment Storage Handler. Executing a manipulation can lead to improper access controls. The attack can be executed remotely. Upgrading to version 8.21 is able to address this issue. This patch is called 8c0b4f79d8582932528ec2fdf2a4487c86770fb9. It is recommended to upgrade the affected component.","severity":"medium","cvss_score":6.3,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X","cwe":"CWE-284","product":"WeKan","reference_count":7,"url":"https://www.cve.org/CVERecord?id=CVE-2026-1895","published":"2026-02-04"},{"cve_id":"CVE-2025-14017","title":"TLS options set on one thread apply globally in multi-threaded LDAPS transfers","description":"When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl,\nchanging TLS options in one thread would inadvertently change them globally\nand therefore possibly also affect other concurrently setup transfers.\n\nDisabling certificate verification for a specific transfer could\nunintentionally disable the feature for other threads as well.","severity":"medium","cvss_score":6.3,"cvss_vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","cwe":"CWE-567","product":"curl","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2025-14017","published":"2026-01-08"},{"cve_id":"CVE-2026-89329","title":"Local denial of service via blocking ipc send operations","description":"A flaw was found in `multipathd`. A local attacker with access to the `multipathd` UNIX control socket can exploit this vulnerability by sending valid commands and then ceasing to read replies. This action can cause the `multipathd` listener thread to block, leading to a Denial of Service (DoS) where legitimate Inter-Process Communication (IPC) operations may hang or time out. This issue does not result in privilege escalation, arbitrary code execution, or impact data confidentiality or integrity.","severity":"medium","cvss_score":6.2,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-1322","product":"device-mapper-multipath:","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-89329","published":"2026-09-12"},{"cve_id":"CVE-2026-68562","title":"Controller-side file disclosure via tampered Leapp report content during remediation","description":"A flaw was found in ansible-collection-redhat-leapp. An attacker with privileged write access to a managed node's Leapp report content can manipulate it. When an operator runs a specific remediation task, this manipulated report can cause the Ansible controller to read its own local files and copy them to the managed node. This vulnerability leads to information disclosure, potentially exposing sensitive controller-side data such as private keys or credentials.","severity":"medium","cvss_score":6.2,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N","cwe":"CWE-610","product":"ansible-collection-redhat-leapp","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-68562","published":"2026-07-30"},{"cve_id":"CVE-2026-18938","title":"Integer overflow in rpc attribute-array length calculation can under-allocate nested attribute storage on 32 bit systems","description":"A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could exploit an integer overflow vulnerability. By sending specially crafted messages, the attacker can cause the system to miscalculate memory allocation for nested attributes. This leads to a memory corruption issue, specifically a heap out-of-bounds write, which can crash the p11-kit RPC parsing process, resulting in a Denial of Service (DoS). This vulnerability is only exploitable on 32 bit systems.","severity":"medium","cvss_score":6.2,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-122","product":"p11-kit","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-18938","published":"2026-08-07"},{"cve_id":"CVE-2026-91202","title":"Arbitrary file ownership change via symlink following in privileged paste","description":"A flaw was found in cockpit-files. A low-privileged local user can exploit this vulnerability by crafting a directory containing a symbolic link (symlink) and then using the privileged \"Paste as owner\" function. This allows for arbitrary file ownership changes outside the intended pasted directory, leading to a compromise of data integrity. In some cases, this could also lead to reduced confidentiality if the new ownership grants unauthorized read access. Exploitation requires user interaction to select a non-original owner during the paste operation.","severity":"medium","cvss_score":6.1,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:L","cwe":"CWE-61","product":"cockpit","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-91202","published":"2026-09-20"},{"cve_id":"CVE-2026-82464","title":"pac4j-core before 6.5.6 Open Redirect via Backslash Logout","description":"pac4j-core before 6.5.6 contains an open redirect vulnerability in DefaultLogoutLogic.perform() that accepts backslash-prefixed logout redirect targets matching logoutUrlPattern. Attackers can craft logout links with backslash-prefixed external hosts that browsers normalize into network-path references, redirecting victims to attacker-controlled sites after logout.","severity":"medium","cvss_score":6.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","cwe":"CWE-601","product":"pac4j","reference_count":5,"url":"https://www.cve.org/CVERecord?id=CVE-2026-82464","published":"2026-08-29"},{"cve_id":"CVE-2026-33933","title":"Reflected XSS in the custom template editor via the contextName parameter","description":"OpenEMR is a free and open source electronic health records and medical practice management application. Starting in version 7.0.2.1 and prior to version 8.0.0.3, a reflected cross-site scripting (XSS) vulnerability in the custom template editor allows an attacker to execute arbitrary JavaScript in an authenticated staff member's browser session by sending them a crafted URL. The attacker does not need an OpenEMR account. Version 8.0.0.3 patches the issue.","severity":"medium","cvss_score":6.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","cwe":"CWE-79","product":"openemr","reference_count":4,"url":"https://www.cve.org/CVERecord?id=CVE-2026-33933","published":"2026-03-25"},{"cve_id":"CVE-2026-29170","title":"XSS in mod_proxy_ftp's FTP directory listing generation","description":"A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration.\n\nUsers are recommended to upgrade to version 2.4.68, which fixes this issue.","severity":"medium","cvss_score":6.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","cwe":"CWE-79","product":"Apache HTTP Server","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-29170","published":"2026-06-08"},{"cve_id":"CVE-2026-25901","title":"XSS in the multilingual associations component due to missing output escaping","description":"Lack of output escaping leads to a XSS vector in the multilingual associations component.","severity":"medium","cvss_score":6.1,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N","cwe":"CWE-79","product":"Joomla! CMS","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-25901","published":"2026-05-26"},{"cve_id":"CVE-2026-6367","title":"Cross-site scripting via improper neutralization of input during web page generation","description":"Improper Neutralization of Input During Web Page Generation (\"Cross-site Scripting\") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS).\n\nThis issue affects Drupal core: from 11.3.0 before 11.3.7.","severity":"medium","cvss_score":6.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","cwe":"CWE-79","product":"Drupal core","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-6367","published":"2026-05-19"},{"cve_id":"CVE-2025-65955","title":"Use-after-free and double free in Magick++ when Options::fontFamily clears the font family","description":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-9 and 6.9.13-34, there is a vulnerability in ImageMagick’s Magick++ layer that manifests when Options::fontFamily is invoked with an empty string. Clearing a font family calls RelinquishMagickMemory on _drawInfo->font, freeing the font string but leaving _drawInfo->font pointing to freed memory while _drawInfo->family is set to that (now-invalid) pointer. Any later cleanup or reuse of _drawInfo->font re-frees or dereferences dangling memory. DestroyDrawInfo and other setters (Options::font, Image::font) assume _drawInfo->font remains valid, so destruction or subsequent updates trigger crashes or heap corruption. This vulnerability is fixed in 7.1.2-9 and 6.9.13-34.","severity":"medium","cvss_score":6.1,"cvss_vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","cwe":"CWE-415","product":"ImageMagick","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2025-65955","published":"2025-12-02"},{"cve_id":"CVE-2025-11187","title":"Stack buffer overflow via unvalidated PBMAC1 parameters in PKCS#12 MAC verification","description":"Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation\nwhich can trigger a stack-based buffer overflow, invalid pointer or NULL\npointer dereference during MAC verification.\n\nImpact summary: The stack buffer overflow or NULL pointer dereference may\ncause a crash leading to Denial of Service for an application that parses\nuntrusted PKCS#12 files. The buffer overflow may also potentially enable\ncode execution depending on platform mitigations.\n\nWhen verifying a PKCS#12 file that uses PBMAC1 for the MAC, the PBKDF2\nsalt and keylength parameters from the file are used without validation.\nIf the value of keylength exceeds the size of the fixed stack buffer used\nfor the derived key (64 bytes), the key derivation will overflow the buffer.\nThe overflow length is attacker-controlled. Also, if the salt parameter is\nnot an OCTET STRING type this can lead to invalid or NULL pointer\ndereference.\n\nExploiting this issue requires a user or application to process\na maliciously crafted PKCS#12 file. It is uncommon to accept untrusted\nPKCS#12 files in applications as they are usually used to store private\nkeys which are trusted by definition. For this reason the issue was assessed\nas Moderate severity.\n\nThe FIPS modules in 3.6, 3.5 and 3.4 are not affected by this issue, as\nPKCS#12 processing is outside the OpenSSL FIPS module boundary.\n\nOpenSSL 3.6, 3.5 and 3.4 are vulnerable to this issue.\n\nOpenSSL 3.3, 3.0, 1.1.1 and 1.0.2 are not affected by this issue as they do\nnot support PBMAC1 in PKCS#12.","severity":"medium","cvss_score":6.1,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H","cwe":"CWE-787","product":"OpenSSL","reference_count":4,"url":"https://www.cve.org/CVERecord?id=CVE-2025-11187","published":"2026-01-27"},{"cve_id":"CVE-2026-91205","title":"Local attacker can hijack file ownership via symlink race","description":"A flaw was found in cockpit-files. A local unprivileged attacker can exploit a race condition during directory creation with owner assignment. By controlling a writable parent directory, the attacker can replace a newly created directory with a symbolic link (symlink) before the ownership change operation (chown) is applied. This allows the attacker to redirect the ownership change to an arbitrary file, potentially leading to information disclosure or unauthorized modification of sensitive files.","severity":"medium","cvss_score":6.0,"cvss_vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N","cwe":"CWE-363","product":"cockpit","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-91205","published":"2026-09-20"},{"cve_id":"CVE-2026-91203","title":"Arbitrary file ownership and permission modification via symlink race condition","description":"A flaw was found in cockpit-files. This vulnerability allows a local attacker to exploit a timing issue, known as a symlink race condition, during privileged file operations such as changing file ownership or permissions. By manipulating directory entries and winning this race, the attacker can redirect these operations to unintended files. This could lead to unauthorized changes in file ownership and permissions on arbitrary files, potentially compromising system integrity and availability by altering system or application states or rendering services unusable.","severity":"medium","cvss_score":6.0,"cvss_vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:H","cwe":"CWE-363","product":"cockpit","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-91203","published":"2026-09-20"},{"cve_id":"CVE-2026-91147","title":"Dnial of service in `cockpit-ws` due to url-root handling without a trailing slash","description":"A flaw was found in `cockpit-ws`. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a specially crafted request. When the `WebService.UrlRoot` is configured and a request is made to the exact URL-root prefix without a trailing slash, `cockpit-ws` can terminate unexpectedly. This issue leads to the unavailability of the Cockpit web service.","severity":"medium","cvss_score":5.9,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-617","product":"cockpit","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-91147","published":"2026-09-20"},{"cve_id":"CVE-2026-80489","title":"EUC_JISX0213 decoding may hang on crafted input","description":"Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome EUC_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used.  The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117.","severity":"medium","cvss_score":5.9,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-835","product":"glibc","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-80489","published":"2026-09-15"},{"cve_id":"CVE-2026-77117","title":"SHIFT_JISX0213 decoding may hang on crafted input","description":"Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.\n\nSome SHIFT_JISX0213 sequences decode to two code points.  If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call.  The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used.  The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489.","severity":"medium","cvss_score":5.9,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-835","product":"glibc","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-77117","published":"2026-09-15"},{"cve_id":"CVE-2026-48953","title":"XSS via missing escaping in the generic image output layout","description":"Lack of escaping leads to an XSS vulnerability in the generic image output layout.","severity":"medium","cvss_score":5.9,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:U","cwe":"CWE-79","product":"Joomla! CMS","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-48953","published":"2026-07-16"},{"cve_id":"CVE-2026-29613","title":"Webhook password bypass in the BlueBubbles plugin via trusted loopback remoteAddress","description":"OpenClaw versions prior to 2026.2.12 contain a vulnerability in the BlueBubbles (optional plugin) webhook handler in which it authenticates requests based solely on loopback remoteAddress without validating forwarding headers, allowing bypass of configured webhook passwords. When the gateway operates behind a reverse proxy, unauthenticated remote attackers can inject arbitrary BlueBubbles message and reaction events by reaching the proxy endpoint.","severity":"medium","cvss_score":5.9,"cvss_vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","cwe":"CWE-306","product":"OpenClaw","reference_count":4,"url":"https://www.cve.org/CVERecord?id=CVE-2026-29613","published":"2026-03-05"},{"cve_id":"CVE-2026-3337","title":"Timing side channel in AES-CCM authentication tag verification","description":"Observable timing discrepancy in AES-CCM decryption in AWS-LC allows an unauthenticated user to potentially determine authentication tag validity via timing analysis.\n\n\n\n\nThe impacted implementations are through the EVP CIPHER API: EVP_aes_128_ccm, EVP_aes_192_ccm, and EVP_aes_256_ccm.\n\n\n\n\nCustomers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC version 1.69.0.","severity":"medium","cvss_score":5.9,"cvss_vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","cwe":"CWE-208","product":"AWS-LC","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-3337","published":"2026-03-02"},{"cve_id":"CVE-2025-66491","title":"Inverted TLS verification in the ingress-nginx provider's proxy-ssl-verify annotation","description":"Traefik is an HTTP reverse proxy and load balancer. Versions 3.5.0 through 3.6.2 have inverted TLS verification logic in the nginx.ingress.kubernetes.io/proxy-ssl-verify annotation. Setting the annotation to \"on\" (intending to enable backend TLS certificate verification) actually disables verification, allowing man-in-the-middle attacks against HTTPS backends when operators believe they are protected. This issue is fixed in version 3.6.3.","severity":"medium","cvss_score":5.9,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":"CWE-295","product":"traefik","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2025-66491","published":"2025-12-09"},{"cve_id":"CVE-2025-66199","title":"Unbounded memory allocation when processing TLS 1.3 CompressedCertificate messages","description":"Issue summary: A TLS 1.3 connection using certificate compression can be\nforced to allocate a large buffer before decompression without checking\nagainst the configured certificate size limit.\n\nImpact summary: An attacker can cause per-connection memory allocations of\nup to approximately 22 MiB and extra CPU work, potentially leading to\nservice degradation or resource exhaustion (Denial of Service).\n\nIn affected configurations, the peer-supplied uncompressed certificate\nlength from a CompressedCertificate message is used to grow a heap buffer\nprior to decompression. This length is not bounded by the max_cert_list\nsetting, which otherwise constrains certificate message sizes. An attacker\ncan exploit this to cause large per-connection allocations followed by\nhandshake failure. No memory corruption or information disclosure occurs.\n\nThis issue only affects builds where TLS 1.3 certificate compression is\ncompiled in (i.e., not OPENSSL_NO_COMP_ALG) and at least one compression\nalgorithm (brotli, zlib, or zstd) is available, and where the compression\nextension is negotiated. Both clients receiving a server CompressedCertificate\nand servers in mutual TLS scenarios receiving a client CompressedCertificate\nare affected. Servers that do not request client certificates are not\nvulnerable to client-initiated attacks.\n\nUsers can mitigate this issue by setting SSL_OP_NO_RX_CERTIFICATE_COMPRESSION\nto disable receiving compressed certificates.\n\nThe FIPS modules in 3.6, 3.5, 3.4 and 3.3 are not affected by this issue,\nas the TLS implementation is outside the OpenSSL FIPS module boundary.\n\nOpenSSL 3.6, 3.5, 3.4 and 3.3 are vulnerable to this issue.\n\nOpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.","severity":"medium","cvss_score":5.9,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-789","product":"OpenSSL","reference_count":5,"url":"https://www.cve.org/CVERecord?id=CVE-2025-66199","published":"2026-01-27"},{"cve_id":"CVE-2025-15468","title":"NULL pointer dereference in SSL_CIPHER_find() on unknown cipher IDs from QUIC peers","description":"Issue summary: If an application using the SSL_CIPHER_find() function in\na QUIC protocol client or server receives an unknown cipher suite from\nthe peer, a NULL dereference occurs.\n\nImpact summary: A NULL pointer dereference leads to abnormal termination of\nthe running process causing Denial of Service.\n\nSome applications call SSL_CIPHER_find() from the client_hello_cb callback\non the cipher ID received from the peer. If this is done with an SSL object\nimplementing the QUIC protocol, NULL pointer dereference will happen if\nthe examined cipher ID is unknown or unsupported.\n\nAs it is not very common to call this function in applications using the QUIC \nprotocol and the worst outcome is Denial of Service, the issue was assessed\nas Low severity.\n\nThe vulnerable code was introduced in the 3.2 version with the addition\nof the QUIC protocol support.\n\nThe FIPS modules in 3.6, 3.5, 3.4 and 3.3 are not affected by this issue,\nas the QUIC implementation is outside the OpenSSL FIPS module boundary.\n\nOpenSSL 3.6, 3.5, 3.4 and 3.3 are vulnerable to this issue.\n\nOpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.","severity":"medium","cvss_score":5.9,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-476","product":"OpenSSL","reference_count":5,"url":"https://www.cve.org/CVERecord?id=CVE-2025-15468","published":"2026-01-27"},{"cve_id":"CVE-2025-13034","title":"Certificate pinning check skipped for QUIC connections with ngtcp2 and GnuTLS","description":"When using `CURLOPT_PINNEDPUBLICKEY` option with libcurl or `--pinnedpubkey`\nwith the curl tool,curl should check the public key of the server certificate\nto verify the peer.\n\nThis check was skipped in a certain condition that would then make curl allow\nthe connection without performing the proper check, thus not noticing a\npossible impostor. To skip this check, the connection had to be done with QUIC\nwith ngtcp2 built to use GnuTLS and the user had to explicitly disable the\nstandard certificate verification.","severity":"medium","cvss_score":5.9,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","cwe":"CWE-295","product":"curl","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2025-13034","published":"2026-01-08"},{"cve_id":"CVE-2025-9232","title":"Out-of-bounds read in HTTP client no_proxy handling","description":"Issue summary: An application using the OpenSSL HTTP client API functions may\ntrigger an out-of-bounds read if the 'no_proxy' environment variable is set and\nthe host portion of the authority component of the HTTP URL is an IPv6 address.\n\nImpact summary: An out-of-bounds read can trigger a crash which leads to\nDenial of Service for an application.\n\nThe OpenSSL HTTP client API functions can be used directly by applications\nbut they are also used by the OCSP client functions and CMP (Certificate\nManagement Protocol) client implementation in OpenSSL. However the URLs used\nby these implementations are unlikely to be controlled by an attacker.\n\nIn this vulnerable code the out of bounds read can only trigger a crash.\nFurthermore the vulnerability requires an attacker-controlled URL to be\npassed from an application to the OpenSSL function and the user has to have\na 'no_proxy' environment variable set. For the aforementioned reasons the\nissue was assessed as Low severity.\n\nThe vulnerable code was introduced in the following patch releases:\n3.0.16, 3.1.8, 3.2.4, 3.3.3, 3.4.0 and 3.5.0.\n\nThe FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this\nissue, as the HTTP client implementation is outside the OpenSSL FIPS module\nboundary.","severity":"medium","cvss_score":5.9,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-125","product":"OpenSSL","reference_count":6,"url":"https://www.cve.org/CVERecord?id=CVE-2025-9232","published":"2025-09-30"},{"cve_id":"CVE-2026-75145","title":"FFmpeg Integer Narrowing Conversion OOB Memory Access in AV1 RTP Packetizer","description":"FFmpeg before commit b4c199c contains an incorrect integer narrowing conversion in the AV1 RTP packetizer (libavformat/rtpenc_av1.c). The OBU size is cast to long before comparison against the remaining frame size. On targets where long is 32 bits, including 64-bit Windows, sufficiently large OBU size values are sign-flipped by the narrowing cast, producing a negative value that passes the payload size check. This allows an oversized OBU to bypass the safety bound on affected platforms, leading to out-of-bounds memory access when the oversized value is subsequently used as a copy length.","severity":"medium","cvss_score":5.8,"cvss_vector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N","cwe":"CWE-681","product":"FFmpeg","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-75145","published":"2026-08-20"},{"cve_id":"CVE-2026-75006","title":"SSRF in modcss","description":"In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. This issue exists because of insufficient fixes for CVE-2026-35540, CVE-2026-48843 and CVE-2026-62643.","severity":"medium","cvss_score":5.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N","cwe":"CWE-918","product":"Roundcube","reference_count":7,"url":"https://www.cve.org/CVERecord?id=CVE-2026-75006","published":"2026-08-26"},{"cve_id":"CVE-2026-26933","title":"Out-of-bounds reads in multiple protocol parsers via malformed network packets","description":"Improper Validation of Array Index (CWE-129) in multiple protocol parser components in Packetbeat can lead Denial of Service via Input Data Manipulation (CAPEC-153). An attacker with the ability to send specially crafted, malformed network packets to a monitored network interface can trigger out-of-bounds read operations, resulting in application crashes or resource exhaustion. This requires the attacker to be positioned on the same network segment as the Packetbeat deployment or to control traffic routed to monitored interfaces.","severity":"medium","cvss_score":5.7,"cvss_vector":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-129","product":"Packetbeat","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-26933","published":"2026-03-19"},{"cve_id":"CVE-2026-26931","title":"Excessive memory allocation in the Prometheus remote_write HTTP handler","description":"Memory Allocation with Excessive Size Value (CWE-789) in the Prometheus remote_write HTTP handler in Metricbeat can lead Denial of Service via Excessive Allocation (CAPEC-130).","severity":"medium","cvss_score":5.7,"cvss_vector":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-789","product":"Metricbeat","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-26931","published":"2026-03-19"},{"cve_id":"CVE-2026-94282","title":"Out-of-bounds read in libXi's XI2 enter/leave/focus cookie conversion","description":"An out-of-bounds read in libXi's XI2 enter/leave/focus cookie conversion in libXi before 1.8.4 could be used by malicious X server to crash an attached X client.","severity":"medium","cvss_score":5.6,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H","cwe":"CWE-125","product":"libXi","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-94282","published":"2026-09-28"},{"cve_id":"CVE-2026-19542","title":"Stack-based out-of-bounds write in tdelete during tree rebalancing","description":"Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.\n\nThe tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree.  Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete.  The written value is a pointer into a tree node and is not directly attacker controlled.  No affected application in common distributions has been identified.","severity":"medium","cvss_score":5.6,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","cwe":"CWE-121","product":"glibc","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-19542","published":"2026-09-14"},{"cve_id":"CVE-2026-95386","title":"Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark","description":"TTL file parser infinite loop in 4.6.0 to 4.6.8 allows denial of service","severity":"medium","cvss_score":5.5,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","cwe":"CWE-835","product":"Wireshark","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-95386","published":"2026-09-29"},{"cve_id":"CVE-2026-94287","title":"Denial of service via unsigned underflow in libXpm's write path","description":"A denial of service via unsigned underflow in libXpm's write path in libXpm before 3.5.19 could be used by local attackers to cause unbounded CPU usage and memory exhaustion.","severity":"medium","cvss_score":5.5,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","cwe":"CWE-1050","product":"libXpm","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-94287","published":"2026-09-28"},{"cve_id":"CVE-2026-94284","title":"Out-of-bounds read vulnerability in libX11's XIM trigger-keyregistration parser.registration parser","description":"An out-of-bounds read vulnerability in libX11's XIM trigger-key registration parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.","severity":"medium","cvss_score":5.5,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","cwe":"CWE-125","product":"libX11","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-94284","published":"2026-09-28"},{"cve_id":"CVE-2026-93433","title":"Denial of service via stack buffer overflow in scsi vpd page parsing","description":"A flaw was found in libstoragemgmt. An attacker with control over a local or virtual storage device could provide specially crafted SCSI (Small Computer System Interface) Vital Product Data (VPD) page 0x80 data. This malformed data, specifically an untrusted page length field, can lead to a stack buffer overflow in the `_sg_parse_vpd_80()` function during serial number parsing. Successful exploitation could result in a denial of service by crashing or destabilizing the process querying the serial number.","severity":"medium","cvss_score":5.5,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-121","product":"libstoragemgmt","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-93433","published":"2026-09-24"},{"cve_id":"CVE-2026-92768","title":"Sensitive data exposure via command-line arguments","description":"A flaw was found in cockpit-machines. This vulnerability allows a local attacker to expose sensitive Virtual Machine (VM) credentials, including plaintext passwords, by inspecting process command-line arguments during VM creation or installation. The cockpit-machines component passes password values directly on the command line, making them visible to other local users on systems where process arguments are not restricted. Successful exploitation leads to information disclosure, potentially compromising VM access.","severity":"medium","cvss_score":5.5,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":"CWE-214","product":"cockpit","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-92768","published":"2026-09-20"},{"cve_id":"CVE-2026-90995","title":"Denial of service due to null pointer dereference in pam responder","description":"A flaw was found in SSSD (System Security Services Daemon). A local attacker with privileges to connect to the PAM (Pluggable Authentication Modules) responder socket can send a specially crafted protocol request. If the `pam_app_services` configuration is enabled and the service item is omitted from the request, a NULL pointer dereference can occur. This vulnerability leads to a denial of service, causing the PAM responder to crash and disrupt authentication services.","severity":"medium","cvss_score":5.5,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-476","product":"sssd","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-90995","published":"2026-09-14"},{"cve_id":"CVE-2026-76924","title":"Out-of-bounds Read in Wireshark","description":"Kerberos protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service","severity":"medium","cvss_score":5.5,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","cwe":"CWE-125","product":"Wireshark","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-76924","published":"2026-08-21"},{"cve_id":"CVE-2026-76923","title":"Out-of-bounds Read in Wireshark","description":"Bluetooth HFP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service","severity":"medium","cvss_score":5.5,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","cwe":"CWE-125","product":"Wireshark","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-76923","published":"2026-08-21"},{"cve_id":"CVE-2026-76922","title":"NULL Pointer Dereference in Wireshark","description":"Bluetooth BR/EDR FHS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service","severity":"medium","cvss_score":5.5,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","cwe":"CWE-476","product":"Wireshark","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-76922","published":"2026-08-21"},{"cve_id":"CVE-2026-76921","title":"Use After Free in Wireshark","description":"CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service","severity":"medium","cvss_score":5.5,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","cwe":"CWE-416","product":"Wireshark","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-76921","published":"2026-08-21"},{"cve_id":"CVE-2026-68563","title":"Insecure permissions on the PostgreSQL data backup archive expose data to local users","description":"A flaw was found in ansible-collection-redhat-leapp. When a remediation task is executed with elevated privileges and the `leapp_old_postgresql_data` option is selected, a PostgreSQL data backup archive is created with insecure permissions. This allows a local non-root user on the managed node to read sensitive archived PostgreSQL data, leading to information disclosure.","severity":"medium","cvss_score":5.5,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":"CWE-732","product":"ansible-collection-redhat-leapp","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-68563","published":"2026-07-30"},{"cve_id":"CVE-2026-45252","title":"Heap overflow in FUSE_LISTXATTR handling via a non-NUL-terminated attribute list","description":"When a fusefs file system implements extended attributes, the kernel may send a FUSE_LISTXATTR message to the userspace daemon to retrieve the list of extended attributes for a given file.  The FUSE protocol requires the daemon to return a packed list of NUL-terminated strings.  The fusefs kernel module calls strlen() on this daemon-supplied buffer without first verifying that the entire list is NUL-terminated.\n\nIf a malicious daemon sends a non-NUL-terminated list, the fusefs kernel module may read beyond the end of one heap-allocated buffer and potentially write beyond the end of a second buffer.  A malicious daemon could disclose up to 253 bytes of kernel heap memory, or it could inject up to 250 attacker-controlled bytes into unallocated kernel heap space.","severity":"medium","cvss_score":5.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H","cwe":"CWE-122","product":"FreeBSD","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-45252","published":"2026-05-21"},{"cve_id":"CVE-2026-22795","title":"Type confusion in PKCS#12 parsing leading to a NULL pointer dereference","description":"Issue summary: An invalid or NULL pointer dereference can happen in\nan application processing a malformed PKCS#12 file.\n\nImpact summary: An application processing a malformed PKCS#12 file can be\ncaused to dereference an invalid or NULL pointer on memory read, resulting\nin a Denial of Service.\n\nA type confusion vulnerability exists in PKCS#12 parsing code where\nan ASN1_TYPE union member is accessed without first validating the type,\ncausing an invalid pointer read.\n\nThe location is constrained to a 1-byte address space, meaning any\nattempted pointer manipulation can only target addresses between 0x00 and 0xFF.\nThis range corresponds to the zero page, which is unmapped on most modern\noperating systems and will reliably result in a crash, leading only to a\nDenial of Service. Exploiting this issue also requires a user or application\nto process a maliciously crafted PKCS#12 file. It is uncommon to accept\nuntrusted PKCS#12 files in applications as they are usually used to store\nprivate keys which are trusted by definition. For these reasons, the issue\nwas assessed as Low severity.\n\nThe FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the PKCS12 implementation is outside the OpenSSL FIPS module boundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.\n\nOpenSSL 1.0.2 is not affected by this issue.","severity":"medium","cvss_score":5.5,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","cwe":"CWE-754","product":"OpenSSL","reference_count":6,"url":"https://www.cve.org/CVERecord?id=CVE-2026-22795","published":"2026-01-27"},{"cve_id":"CVE-2026-15171","title":"NULL pointer dereference in the SSH protocol dissector","description":"SSH protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service","severity":"medium","cvss_score":5.5,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","cwe":"CWE-476","product":"Wireshark","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-15171","published":"2026-07-16"},{"cve_id":"CVE-2025-40306","title":"Out-of-bounds read in the orangefs xattr_key() helper due to a non-terminating loop","description":"In the Linux kernel, the following vulnerability has been resolved:\n\norangefs: fix xattr related buffer overflow...\n\nWilly Tarreau <w@1wt.eu> forwarded me a message from\nDisclosure <disclosure@aisle.com> with the following\nwarning:\n\n> The helper `xattr_key()` uses the pointer variable in the loop condition\n> rather than dereferencing it. As `key` is incremented, it remains non-NULL\n> (until it runs into unmapped memory), so the loop does not terminate on\n> valid C strings and will walk memory indefinitely, consuming CPU or hanging\n> the thread.\n\nI easily reproduced this with setfattr and getfattr, causing a kernel\noops, hung user processes and corrupted orangefs files. Disclosure\nsent along a diff (not a patch) with a suggested fix, which I based\nthis patch on.\n\nAfter xattr_key started working right, xfstest generic/069 exposed an\nxattr related memory leak that lead to OOM. xattr_key returns\na hashed key.  When adding xattrs to the orangefs xattr cache, orangefs\nused hash_add, a kernel hashing macro. hash_add also hashes the key using\nhash_log which resulted in additions to the xattr cache going to the wrong\nhash bucket. generic/069 tortures a single file and orangefs does a\ngetattr for the xattr \"security.capability\" every time. Orangefs\nnegative caches on xattrs which includes a kmalloc. Since adds to the\nxattr cache were going to the wrong bucket, every getattr for\n\"security.capability\" resulted in another kmalloc, none of which were\never freed.\n\nI changed the two uses of hash_add to hlist_add_head instead\nand the memory leak ceased and generic/069 quit throwing furniture.","severity":"medium","cvss_score":5.5,"cvss_vector":"","cwe":"CWE-125","product":"Linux","reference_count":8,"url":"https://www.cve.org/CVERecord?id=CVE-2025-40306","published":"2025-12-08"},{"cve_id":"CVE-2025-15469","title":"Silent truncation of input over 16MB with one-shot signing algorithms in openssl dgst","description":"Issue summary: The 'openssl dgst' command-line tool silently truncates input\ndata to 16MB when using one-shot signing algorithms and reports success instead\nof an error.\n\nImpact summary: A user signing or verifying files larger than 16MB with\none-shot algorithms (such as Ed25519, Ed448, or ML-DSA) may believe the entire\nfile is authenticated while trailing data beyond 16MB remains unauthenticated.\n\nWhen the 'openssl dgst' command is used with algorithms that only support\none-shot signing (Ed25519, Ed448, ML-DSA-44, ML-DSA-65, ML-DSA-87), the input\nis buffered with a 16MB limit. If the input exceeds this limit, the tool\nsilently truncates to the first 16MB and continues without signaling an error,\ncontrary to what the documentation states. This creates an integrity gap where\ntrailing bytes can be modified without detection if both signing and\nverification are performed using the same affected codepath.\n\nThe issue affects only the command-line tool behavior. Verifiers that process\nthe full message using library APIs will reject the signature, so the risk\nprimarily affects workflows that both sign and verify with the affected\n'openssl dgst' command. Streaming digest algorithms for 'openssl dgst' and\nlibrary users are unaffected.\n\nThe FIPS modules in 3.5 and 3.6 are not affected by this issue, as the\ncommand-line tools are outside the OpenSSL FIPS module boundary.\n\nOpenSSL 3.5 and 3.6 are vulnerable to this issue.\n\nOpenSSL 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are not affected by this issue.","severity":"medium","cvss_score":5.5,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","cwe":"CWE-347","product":"OpenSSL","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2025-15469","published":"2026-01-27"},{"cve_id":"CVE-2026-90462","title":"Fail-open in ldap ppolicy access check allows continued authorization","description":"A flaw was found in SSSD. When configured with the LDAP access provider and `ldap_access_order` including `ppolicy` or `lockout`, a fail-open condition in the LDAP ppolicy access check can occur if a user lookup returns zero results. This can incorrectly return success and cache an allow decision, permitting continued authorization for a deleted or deprovisioned user. A remote attacker with prior valid account context could exploit this to maintain access to information and potentially make limited modifications to resources that should no longer be available.","severity":"medium","cvss_score":5.4,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","cwe":"CWE-280","product":"sssd","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-90462","published":"2026-09-24"},{"cve_id":"CVE-2026-85593","title":"phpMyFAQ before 4.1.8 Stored XSS via html_entity_decode","description":"phpMyFAQ versions before 4.1.8 contain a stored cross-site scripting vulnerability in FaqHelper::convertOldInternalLinks() that calls html_entity_decode() on sanitized FAQ content, reversing entity-encoding protection. Authenticated users with FAQ editing privileges can inject JavaScript payloads that execute in the browsers of all users viewing the affected FAQ pages.","severity":"medium","cvss_score":5.4,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","cwe":"CWE-79","product":"phpMyFAQ","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-85593","published":"2026-09-04"},{"cve_id":"CVE-2026-82470","title":"Rodauth before 2.47.0 TOTP Code Reuse via Drift Window","description":"Rodauth before 2.47.0 contains a time-based one-time password reuse vulnerability in the otp feature that fails to track the last accepted code timestamp. Attackers who observe a valid TOTP code can replay it during the drift window to bypass the second authentication factor.","severity":"medium","cvss_score":5.4,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","cwe":"CWE-294","product":"rodauth","reference_count":4,"url":"https://www.cve.org/CVERecord?id=CVE-2026-82470","published":"2026-08-29"},{"cve_id":"CVE-2026-82469","title":"Rodauth before 2.47.0 Authentication Bypass via jwt_refresh","description":"Rodauth before 2.47.0 contains an authentication bypass vulnerability in the jwt_refresh route that issues new JWT access tokens without requiring a refresh token. Attackers can present an access token to the refresh route via non-POST methods to obtain a new valid access token, enabling indefinite account access with temporary token possession.","severity":"medium","cvss_score":5.4,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","cwe":"CWE-613","product":"rodauth","reference_count":4,"url":"https://www.cve.org/CVERecord?id=CVE-2026-82469","published":"2026-08-29"},{"cve_id":"CVE-2026-70367","title":"SOCKS proxy localhost restriction bypass via IPv4-mapped IPv6 and unspecified addresses","description":"A Server-Side Request Forgery (SSRF) bypass vulnerability exists in “stunnel” 5.79 and lower when configured in SOCKS proxy mode. This flaw allows a client to bypass intended localhost restrictions by using IPv4-mapped IPv6 addresses (e.g., “::ffff:127.0.0.1”) or unspecified addresses (\"0.0.0.0\", \"::\"), enabling access to loopback-only services on the \"stunnel\" host that should not be network-reachable.","severity":"medium","cvss_score":5.4,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","cwe":"CWE-918","product":"stunnel","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-70367","published":"2026-08-04"},{"cve_id":"CVE-2026-33305","title":"Authorization bypass in the FaxSMS AppDispatch constructor exposes patient data","description":"OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, an authorization bypass in the optional FaxSMS module (`oe-module-faxsms`) allows any authenticated OpenEMR user to invoke controller methods — including `getNotificationLog()`, which returns patient appointment data (PHI) — regardless of whether they hold the required ACL permissions. The `AppDispatch` constructor dispatches user-controlled actions and exits the process before any calling code can enforce ACL checks. Version 8.0.0.2 fixes the issue.","severity":"medium","cvss_score":5.4,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","cwe":"CWE-696","product":"openemr","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-33305","published":"2026-03-19"},{"cve_id":"CVE-2026-33303","title":"Stored XSS via unescaped portal_login_username in the portal credential print view","description":"OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.2 are vulnerable to stored cross-site scripting (XSS) via unescaped `portal_login_username` in the portal credential print view. A patient portal user can set their login username to an XSS payload, which then executes in a clinic staff member's browser when they open the \"Create Portal Login\" page for that patient. This crosses from the patient session context into the staff/admin session context. Version 8.0.0.2 fixes the issue.","severity":"medium","cvss_score":5.4,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","cwe":"CWE-79","product":"openemr","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-33303","published":"2026-03-19"},{"cve_id":"CVE-2026-32125","title":"Stored XSS in Track Anything graphs via unescaped Dygraph titles and labels","description":"OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, track/item names from the Track Anything feature are stored from user input (POST) and later rendered in Dygraph charts (titles/labels) using innerHTML or equivalent without escaping. A user who can create or edit Track Anything items can inject script that runs when any user views the corresponding graph. This vulnerability is fixed in 8.0.0.1.","severity":"medium","cvss_score":5.4,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","cwe":"CWE-79","product":"openemr","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-32125","published":"2026-03-11"},{"cve_id":"CVE-2026-32124","title":"Stored XSS in the dynamic code picker via unescaped code descriptions","description":"OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, the dynamic code picker AJAX endpoint returns code descriptions (code_text) that are rendered in the front end (e.g. DataTables) without HTML escaping. If an administrator (or user with code management rights) creates or edits a code with a malicious description containing script, that script runs in the browser of every user who uses the picker. This vulnerability is fixed in 8.0.0.1.","severity":"medium","cvss_score":5.4,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","cwe":"CWE-79","product":"openemr","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-32124","published":"2026-03-11"},{"cve_id":"CVE-2026-25566","title":"Missing authorization checks on the destination board when moving cards","description":"WeKan versions prior to 8.19 contain an authorization vulnerability in card move logic. A user can specify a destination board/list/swimlane without adequate authorization checks for the destination and without validating that destination objects belong to the destination board, potentially enabling unauthorized cross-board moves.","severity":"medium","cvss_score":5.4,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N","cwe":"CWE-863","product":"WeKan","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-25566","published":"2026-02-07"},{"cve_id":"CVE-2026-24050","title":"Stored XSS in the user profile modal via group and channel names","description":"Zulip is an open-source team collaboration tool. From 5.0 to before 11.5, some administrative actions on the user profile were susceptible to stored XSS in group names or channel names. Exploiting these vulnerabilities required the user explicitly interacting with the problematic object. This vulnerability is fixed in 11.5.","severity":"medium","cvss_score":5.4,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U","cwe":"CWE-79","product":"zulip","reference_count":4,"url":"https://www.cve.org/CVERecord?id=CVE-2026-24050","published":"2026-02-06"},{"cve_id":"CVE-2026-23942","title":"Path traversal in ssh_sftpd via a string-prefix root directory check","description":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP (ssh_sftpd module) allows Path Traversal.\n\nThis vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl and program routines ssh_sftpd:is_within_root/2.\n\nThe SFTP server uses string prefix matching via lists:prefix/2 rather than proper path component validation when checking if a path is within the configured root directory. This allows authenticated users to access sibling directories that share a common name prefix with the configured root directory. For example, if root is set to /home/user1, paths like /home/user10 or /home/user1_backup would incorrectly be considered within the root.\n\nThis issue affects OTP from OTP 17.0 until OTP 28.4.1, OTP 27.3.4.9 and OTP 26.2.5.18, corresponding to ssh from 3.0.1 until 5.5.1, 5.2.11.6 and 5.1.4.14.","severity":"medium","cvss_score":5.4,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N","cwe":"CWE-22","product":"OTP","reference_count":7,"url":"https://www.cve.org/CVERecord?id=CVE-2026-23942","published":"2026-03-13"},{"cve_id":"CVE-2026-21724","title":"Authorization bypass in the provisioning contact points API for protected webhook URLs","description":"A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role to modify protected webhook URLs without the required alert.notifications.receivers.protected:write permission.","severity":"medium","cvss_score":5.4,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","cwe":"CWE-285","product":"grafana/grafana","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-21724","published":"2026-03-26"},{"cve_id":"CVE-2026-9811","title":"Stored XSS in the project selector via unsanitized project names","description":"A stored Cross-Site Scripting (XSS) vulnerability exists in the project selector component of Mautic 7. When rendering selection menus for associating projects with system entities, the application fails to sanitize project names returned via AJAX before injecting them into the DOM as option fields. An authenticated user with permissions to create projects can exploit this to store a malicious script payload in the project's name. When another administrative user subsequently opens an entity editor containing the project selector, the injected script executes within the context of their active browser session. This could allow an attacker to hijack the session, perform unauthorized state coordination, or access organizational data within the dashboard.","severity":"medium","cvss_score":5.4,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","cwe":"CWE-79","product":"mautic/core","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-9811","published":"2026-05-29"},{"cve_id":"CVE-2026-1894","title":"Improper authorization in the checklist items REST API","description":"A vulnerability was detected in WeKan up to 8.20. This impacts an unknown function of the file models/checklistItems.js of the component REST API. Performing a manipulation of the argument item.cardId/item.checklistId/card.boardId results in improper authorization. Remote exploitation of the attack is possible. Upgrading to version 8.21 will fix this issue. The patch is named 251d49eea94834cf351bb395808f4a56fb4dbb44. Upgrading the affected component is recommended.","severity":"medium","cvss_score":5.4,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X","cwe":"CWE-285","product":"WeKan","reference_count":6,"url":"https://www.cve.org/CVERecord?id=CVE-2026-1894","published":"2026-02-04"},{"cve_id":"CVE-2026-86469","title":"toctou symlink race in `g_file_create_replace_destination` fallback path","description":"A flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating the .goutputstream-XXXXXX temporary file fails, the library unlinks the destination and recreates it without exclusive creation or symlink protection. A local attacker who can write to the destination directory can win that race and redirect the write to another file.","severity":"medium","cvss_score":5.3,"cvss_vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L","cwe":"CWE-59","product":"glibc2","reference_count":4,"url":"https://www.cve.org/CVERecord?id=CVE-2026-86469","published":"2026-09-08"},{"cve_id":"CVE-2026-77923","title":"Authorization Bypass via clonetasks Mass Action","description":"Dolibarr 21.0.0 before 24.0.0 contains an authorization bypass vulnerability caused by an inverted boolean condition in the private-project membership check within the clonetasks mass action handler in htdocs/core/actions_massactions.inc.php. Authenticated users with project creation permission but without access to a target private project can exploit the flawed !in_array() check to clone tasks into unauthorized private projects.","severity":"medium","cvss_score":5.3,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","cwe":"CWE-863","product":"dolibarr","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-77923","published":"2026-08-25"},{"cve_id":"CVE-2026-76919","title":"Use of Uninitialized Variable in Wireshark","description":"ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service","severity":"medium","cvss_score":5.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","cwe":"CWE-457","product":"Wireshark","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-76919","published":"2026-08-21"},{"cve_id":"CVE-2026-71218","title":"Unbounded peer-controlled allocation in iperf3 json_read() allows unauthenticated remote memory exhaustion","description":"A flaw was found in iperf3. A remote unauthenticated attacker can exploit a vulnerability in the `JSON_read()` function, which accepts a peer-controlled message length and allocates memory without an upper bound. This allows the attacker to trigger excessive memory consumption, leading to a Denial of Service (DoS) through memory exhaustion, severe slowdown, or termination of the iperf3 service.","severity":"medium","cvss_score":5.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","cwe":"CWE-789","product":"Iperf3","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-71218","published":"2026-08-11"},{"cve_id":"CVE-2026-67416","title":"Descriptor prefix collision in the AMQP 1.0 parser lets stored messages crash consumers","description":"RabbitMQ is an open source multi-protocol messaging broker. The optimized AMQP 1.0 server-mode parser recognizes symbolic message body descriptors by matching a fixed textual prefix without validating the encoded symbol length, so an authenticated publisher with write permission to an exchange or queue can submit a described value whose descriptor merely begins with `amqp:data:binary`, `amqp:amqp-sequence:list`, or `amqp:amqp-value:*` (for example the well-formed but unknown descriptor `amqp:data:binary@`) and have it misclassified as a standard body section. The accepted bytes are retained unchanged through classic, quorum, and stream queues and forwarded to AMQP 1.0 consumers, whose strict decoders reject the unknown descriptor; conversion to AMQP 0-9-1 and other protocols performs a full decode on the broker side, causing an uncontrolled parser exit in the consumer protocol process. With acknowledgement-required consumers the stored poison entry can be repeatedly redelivered after reconnection, resulting in denial of service of consumer sessions or channels (the broker node itself remains alive). Fixed in RabbitMQ 4.3.4, 4.2.10, 4.1.15, and 4.0.24, which require exact symbolic descriptor lengths in the fast-path parsing clauses.","severity":"medium","cvss_score":5.3,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:L","cwe":"CWE-20","product":"RabbitMQ","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-67416","published":"2026-08-07"},{"cve_id":"CVE-2026-59848","title":"Unbounded memory growth in SFTP clients from responses with unknown request IDs","description":"A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded memory growth and client-side denial of service.","severity":"medium","cvss_score":5.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","cwe":"CWE-770","product":"libssh","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-59848","published":"2026-07-24"},{"cve_id":"CVE-2026-33007","title":"NULL pointer dereference in mod_authn_socache in caching forward proxy configurations","description":"A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated remote user to crash a child process in a caching forward proxy configuration.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes this issue.","severity":"medium","cvss_score":5.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","cwe":"CWE-476","product":"Apache HTTP Server","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-33007","published":"2026-05-04"},{"cve_id":"CVE-2026-26271","title":"Buffer overread in freerdp_image_copy_from_icon_data() via crafted TS_ICON_INFO data","description":"FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a buffer overread in `freerdp_image_copy_from_icon_data()` (libfreerdp/codec/color.c) can be triggered by crafted RDP Window Icon (TS_ICON_INFO) data. The bug is reachable over the network when a client processes icon data from an RDP server (or from a man-in-the-middle). Version 3.23.0 fixes the issue.","severity":"medium","cvss_score":5.3,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P","cwe":"CWE-126","product":"FreeRDP","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-26271","published":"2026-02-25"},{"cve_id":"CVE-2026-24904","title":"Rule bypass via fragmented TLS ClientHello skipping client_random_prefix matching","description":"TrustTunnel is an open-source VPN protocol with a rule bypass issue in versions prior to 0.9.115. In `tls_listener.rs`, `TlsListener::listen()` peeks 1024 bytes and calls `extract_client_random(...)`. If `parse_tls_plaintext` fails (for example, a fragmented/partial ClientHello split across TCP writes), `extract_client_random` returns `None`. In `rules.rs`, `RulesEngine::evaluate` only evaluates `client_random_prefix` when `client_random` is `Some(...)`. As a result, when extraction fails (`client_random == None`), any rule that relies on `client_random_prefix` matching is skipped and evaluation falls through to later rules. As an important semantics note: `client_random_prefix` is a match condition only. It does not mean \"block non-matching prefixes\" by itself. A rule with `client_random_prefix = ...` triggers its `action` only when the prefix matches (and the field is available to evaluate). Non-matches (or `None`) simply do not match that rule and continue to fall through. The vulnerability is fixed in version 0.9.115.","severity":"medium","cvss_score":5.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","cwe":"CWE-284","product":"TrustTunnel","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-24904","published":"2026-01-29"},{"cve_id":"CVE-2026-23943","title":"Pre-authentication memory exhaustion via unbounded zlib decompression in the SSH transport","description":"Improper Handling of Highly Compressed Data (Compression Bomb) vulnerability in Erlang OTP ssh (ssh_transport modules) allows Denial of Service via Resource Depletion.\n\nThe SSH transport layer advertises legacy zlib compression by default and inflates attacker-controlled payloads pre-authentication without any size limit, enabling reliable memory exhaustion DoS.\n\nTwo compression algorithms are affected:\n\n* zlib: Activates immediately after key exchange, enabling unauthenticated attacks\n* zlib@openssh.com: Activates post-authentication, enabling authenticated attacks\n\nEach SSH packet can decompress ~255 MB from 256 KB of wire data (1029:1 amplification ratio). Multiple packets can rapidly exhaust available memory, causing OOM kills in memory-constrained environments.\n\nThis vulnerability is associated with program files lib/ssh/src/ssh_transport.erl and program routines ssh_transport:decompress/2, ssh_transport:handle_packet_part/4.\n\nThis issue affects OTP from OTP 17.0 until OTP 28.4.1, 27.3.4.9 and 26.2.5.18 corresponding to ssh from 3.0.1 until 5.5.1, 5.2.11.6 and 5.1.4.14.","severity":"medium","cvss_score":5.3,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","cwe":"CWE-409","product":"OTP","reference_count":7,"url":"https://www.cve.org/CVERecord?id=CVE-2026-23943","published":"2026-03-13"},{"cve_id":"CVE-2026-22796","title":"Type confusion in PKCS7_digest_from_attributes() leading to a NULL pointer dereference","description":"Issue summary: A type confusion vulnerability exists in the signature\nverification of signed PKCS#7 data where an ASN1_TYPE union member is\naccessed without first validating the type, causing an invalid or NULL\npointer dereference when processing malformed PKCS#7 data.\n\nImpact summary: An application performing signature verification of PKCS#7\ndata or calling directly the PKCS7_digest_from_attributes() function can be\ncaused to dereference an invalid or NULL pointer when reading, resulting in\na Denial of Service.\n\nThe function PKCS7_digest_from_attributes() accesses the message digest attribute\nvalue without validating its type. When the type is not V_ASN1_OCTET_STRING,\nthis results in accessing invalid memory through the ASN1_TYPE union, causing\na crash.\n\nExploiting this vulnerability requires an attacker to provide a malformed\nsigned PKCS#7 to an application that verifies it. The impact of the\nexploit is just a Denial of Service, the PKCS7 API is legacy and applications\nshould be using the CMS API instead. For these reasons the issue was\nassessed as Low severity.\n\nThe FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the PKCS#7 parsing implementation is outside the OpenSSL FIPS module\nboundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.","severity":"medium","cvss_score":5.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","cwe":"CWE-754","product":"OpenSSL","reference_count":6,"url":"https://www.cve.org/CVERecord?id=CVE-2026-22796","published":"2026-01-27"},{"cve_id":"CVE-2026-2207","title":"Information disclosure in the linked-board activities publication","description":"A weakness has been identified in WeKan up to 8.20. This issue affects some unknown processing of the file server/publications/activities.js of the component Activity Publication Handler. Executing a manipulation can lead to information disclosure. It is possible to launch the attack remotely. Upgrading to version 8.21 is capable of addressing this issue. This patch is called 91a936e07d2976d4246dfe834281c3aaa87f9503. You should upgrade the affected component.","severity":"medium","cvss_score":5.3,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X","cwe":"CWE-200","product":"WeKan","reference_count":6,"url":"https://www.cve.org/CVERecord?id=CVE-2026-2207","published":"2026-02-08"},{"cve_id":"CVE-2026-1964","title":"Improper access control in the board title REST endpoint","description":"A vulnerability was determined in WeKan up to 8.20. This impacts an unknown function of the file models/boards.js of the component REST Endpoint. This manipulation causes improper access controls. Remote exploitation of the attack is possible. Upgrading to version 8.21 will fix this issue. Patch name: 545566f5663545d16174e0f2399f231aa693ab6e. It is advisable to upgrade the affected component.","severity":"medium","cvss_score":5.3,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X","cwe":"CWE-284","product":"WeKan","reference_count":6,"url":"https://www.cve.org/CVERecord?id=CVE-2026-1964","published":"2026-02-05"},{"cve_id":"CVE-2025-68388","title":"Unbounded memory and CPU allocation when reassembling malicious IPv4 fragments","description":"Allocation of resources without limits or throttling (CWE-770) allows an unauthenticated remote attacker to cause excessive allocation (CAPEC-130) of memory and CPU via the integration of malicious IPv4 fragments, leading to a degradation in Packetbeat.","severity":"medium","cvss_score":5.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","cwe":"CWE-770","product":"Packetbeat","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2025-68388","published":"2025-12-18"},{"cve_id":"CVE-2025-14819","title":"Trust chain policy bypass via a cached CA store with a stale partial-chain option","description":"When doing TLS related transfers with reused easy or multi handles and\naltering the  `CURLSSLOPT_NO_PARTIALCHAIN` option, libcurl could accidentally\nreuse a CA store cached in memory for which the partial chain option was\nreversed. Contrary to the user's wishes and expectations. This could make\nlibcurl find and accept a trust chain that it otherwise would not.","severity":"medium","cvss_score":5.3,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","cwe":"CWE-295","product":"curl","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2025-14819","published":"2026-01-08"},{"cve_id":"CVE-2026-94285","title":"Out-of-bounds read in libX11's byte-oriented codeset parser","description":"An out-of-bounds read in libX11's byte-oriented codeset parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.","severity":"medium","cvss_score":5.1,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","cwe":"CWE-125","product":"libX11","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-94285","published":"2026-09-28"},{"cve_id":"CVE-2026-86763","title":"Authorization Bypass via Importer","description":"Snipe-IT versions >= 7.0.12 and <= 8.6.3 contain an authorization bypass in the Livewire importer component (App\\Livewire\\Importer, mounted at the imports.index route). The component only checked the broad 'import' ability at mount time, while its files() and activeFile() computed properties queried the imports table with no owner or company scope. As a result, any authenticated non-superuser holding the import permission could view every Import record on the instance (original filename, file_path, filesize, import_type and creation timestamp) and could invoke the selectFile($id) Livewire action with any auto-incrementing Import ID to load another user's record, exposing its stored preview data (header_row column headers and first_row, the first data row of the CSV). Because import CSVs commonly contain personal data, asset serial numbers and license keys, this discloses sensitive information; in Full Multiple Companies Support (FMCS) deployments the disclosure also crosses company/tenant boundaries. Impact is limited to preview data rather than the full CSV file, and superusers were unaffected. Fixed in version 8.7.0, which scopes non-superuser reads to imports owned by the caller.","severity":"medium","cvss_score":5.1,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","cwe":"CWE-639","product":"snipe-it","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-86763","published":"2026-09-10"},{"cve_id":"CVE-2026-71227","title":"Infinite wait loop in _kcapi_aio_read_all() when reusing an AIO handle after an error","description":"A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the _kcapi_aio_read_all() function can enter a non-terminating wait loop. This can lead to a persistent denial of service, making the affected application or thread unresponsive.","severity":"medium","cvss_score":5.1,"cvss_vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-835","product":"libkcapi","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-71227","published":"2026-08-05"},{"cve_id":"CVE-2026-92747","title":"Sensitive data exposure of guest credentials via json argument in process list","description":"A flaw was found in `cockpit-machines`. This vulnerability allows a local attacker with the ability to inspect running processes to expose sensitive guest virtual machine (VM) credentials, such as `rootPassword` and `userPassword`. This occurs when the `install_machine.py` script passes these credentials as a JSON command-line argument during VM creation or installation. The exposure is limited to the period when the installation workflow is active and depends on host process-visibility policies.","severity":"medium","cvss_score":5.0,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","cwe":"CWE-214","product":"cockpit","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-92747","published":"2026-09-20"},{"cve_id":"CVE-2026-92745","title":"Information disclosure of rhsm offline token via process arguments","description":"A flaw was found in cockpit-machines. This vulnerability allows a local attacker with the ability to inspect process metadata to disclose a sensitive Red Hat Subscription Management (RHSM) offline token. The token is exposed when it is passed as a command-line argument to a helper script during the token validation process. Successful exploitation could lead to the compromise of confidentiality, as the exposed token can be used to request access tokens.","severity":"medium","cvss_score":5.0,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","cwe":"CWE-214","product":"cockpit","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-92745","published":"2026-09-20"},{"cve_id":"CVE-2026-55655","title":"Local mitm of x11 forwarding via abstract unix socket pre-binding in red hat enterprise linux openssh client versions","description":"A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is enabled and a local UNIX-domain X socket is used. A successful attack can compromise the confidentiality of forwarded X11 traffic, including sensitive window contents and input, and may allow some manipulation of the forwarded session.","severity":"medium","cvss_score":5.0,"cvss_vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N","cwe":"CWE-923","product":"OpenSSH","reference_count":7,"url":"https://www.cve.org/CVERecord?id=CVE-2026-55655","published":"2026-08-19"},{"cve_id":"CVE-2026-35188","title":"Double free in the TLS client when checking a crafted OCSP stapled response","description":"Issue summary: A malicious server can exploit TLS OCSP stapling by delivering\na crafted response through the status_request extension, triggering a\ndouble-free in the client's certificate verification path.\n\nImpact summary: Successful exploitation allows an attacker to corrupt heap\nmemory via a double-free, potentially leading to a Denial of Service or\npossibly an attacker controlled code execution or other undefined behavior.\n\nIf OCSP stapling is enabled and the TLS client connects to a malicious server,\na crafted OCSP stapled response can trigger a double free in the TLS client\nwhen the stapled response is checked.\n\nThe OCSP stapling is not enabled by default. Reliable code execution\nthrough a double-free is technically complex and highly environment-dependent\nbut the Denial of Service impact is straightforward to achieve, warranting\nModerate severity.\n\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary.","severity":"medium","cvss_score":5,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L","cwe":"CWE-415","product":"OpenSSL","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-35188","published":"2026-06-09"},{"cve_id":"CVE-2026-1892","title":"Improper authorization in the REST API's setBoardOrgs function","description":"A security vulnerability has been detected in WeKan up to 8.20. This affects the function setBoardOrgs of the file models/boards.js of the component REST API. Such manipulation of the argument item.cardId/item.checklistId/card.boardId leads to improper authorization. The attack may be launched remotely. A high complexity level is associated with this attack. The exploitability is reported as difficult. Upgrading to version 8.21 mitigates this issue. The name of the patch is cabfeed9a68e21c469bf206d8655941444b9912c. It is suggested to upgrade the affected component.","severity":"medium","cvss_score":5,"cvss_vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X","cwe":"CWE-285","product":"WeKan","reference_count":6,"url":"https://www.cve.org/CVERecord?id=CVE-2026-1892","published":"2026-02-04"},{"cve_id":"CVE-2026-82468","title":"Rodauth before 2.47.0 CSRF Protection Bypass via Content-Type","description":"Rodauth before 2.47.0 contains a cross-site request forgery protection bypass vulnerability in the JSON request content type validation. Attackers can craft cross-origin form posts with content types containing application/json substrings to bypass CSRF token validation and force victims to authenticate to attacker-controlled accounts.","severity":"medium","cvss_score":4.9,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N","cwe":"CWE-352","product":"rodauth","reference_count":4,"url":"https://www.cve.org/CVERecord?id=CVE-2026-82468","published":"2026-08-29"},{"cve_id":"CVE-2026-82467","title":"Rodauth before 2.47.0 Open Redirect via Return-to Path","description":"Rodauth before 2.47.0 fails to validate protocol-relative return-to paths in confirm_password, login_return_to_requested_location, and two_factor_auth_return_to_requested_location features. Attackers can craft paths with leading double slashes that browsers resolve as protocol-relative URLs, redirecting authenticated users to attacker-controlled sites after login or password confirmation.","severity":"medium","cvss_score":4.9,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N","cwe":"CWE-601","product":"rodauth","reference_count":4,"url":"https://www.cve.org/CVERecord?id=CVE-2026-82467","published":"2026-08-29"},{"cve_id":"CVE-2026-26228","title":"Path traversal in the Remote Access Server's /download endpoint via the file parameter","description":"VideoLAN VLC for Android prior to version 3.7.0 contains a path traversal vulnerability in the Remote Access Server routing for the authenticated endpoint GET /download. The file query parameter is concatenated into a filesystem path under the configured download directory without canonicalization or directory containment checks, allowing an authenticated attacker with network reachability to the Remote Access Server to request files outside the intended directory. The impact is bounded by the Android application sandbox and storage restrictions, typically limiting exposure to app-internal and app-specific external storage.","severity":"medium","cvss_score":4.9,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N","cwe":"CWE-22","product":"VLC for Android","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-26228","published":"2026-02-26"},{"cve_id":"CVE-2026-21899","title":"Out-of-bounds read in base64urlDecode when decoding an empty string","description":"CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, in base64urlDecode, padding-stripping dereferences input[inputLen - 1] before checking that inputLen > 0 or that input != NULL. For inputLen == 0, this becomes an OOB read at input[-1], potentially crashing the process. If input == NULL and inputLen == 0, it dereferences NULL - 1. This issue has been patched in version 1.4.3.","severity":"medium","cvss_score":4.9,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L","cwe":"CWE-125","product":"CryptoLib","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-21899","published":"2026-01-10"},{"cve_id":"CVE-2026-82208","title":"wolfSSL CA-cache hit overrides callback","description":"With the wolfSSL backend, when CA caching is enabled and an\n`CURLOPT_SSL_CTX_FUNCTION` callback replaces the trust store, libcurl can\nsilently reinstall the cached store after the callback returns. A certificate\ntrusted by the cached store but rejected by the callback-selected store is\nthen incorrectly accepted.","severity":"medium","cvss_score":4.8,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","cwe":"CWE-295","product":"curl","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-82208","published":"2026-09-07"},{"cve_id":"CVE-2026-80231","title":"native CA store conn reuse","description":"A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup\nfor a given hostname even when using a different Native CA Store setting\n(`CURLSSLOPT_NATIVE_CA`) than when the connection was created.","severity":"medium","cvss_score":4.8,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","cwe":"CWE-488","product":"curl","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-80231","published":"2026-09-07"},{"cve_id":"CVE-2026-43961","title":"Code injection via the mf command","description":"A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context during mark/unmark operations, allowing arbitrary Vimscript execution. This can be leveraged to run shell commands with the privileges of the user running Vim.","severity":"medium","cvss_score":4.8,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L","cwe":"CWE-74","product":"vim","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-43961","published":"2026-07-16"},{"cve_id":"CVE-2026-96420","title":"Buffer Over-read in Wireshark","description":"Toshiba file parser crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service","severity":"medium","cvss_score":4.7,"cvss_vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H","cwe":"CWE-126","product":"Wireshark","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-96420","published":"2026-09-29"},{"cve_id":"CVE-2026-76929","title":"Out-of-bounds Read in Wireshark","description":"Pcapng file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service","severity":"medium","cvss_score":4.7,"cvss_vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H","cwe":"CWE-125","product":"Wireshark","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-76929","published":"2026-08-21"},{"cve_id":"CVE-2026-76927","title":"NULL Pointer Dereference in Wireshark","description":"H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service","severity":"medium","cvss_score":4.7,"cvss_vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H","cwe":"CWE-476","product":"Wireshark","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-76927","published":"2026-08-21"},{"cve_id":"CVE-2026-76920","title":"Out-of-bounds Write in Wireshark","description":"3gpp phone log file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service","severity":"medium","cvss_score":4.7,"cvss_vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H","cwe":"CWE-787","product":"Wireshark","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-76920","published":"2026-08-21"},{"cve_id":"CVE-2026-76881","title":"NULL Pointer Dereference in Wireshark","description":"CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service","severity":"medium","cvss_score":4.7,"cvss_vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H","cwe":"CWE-476","product":"Wireshark","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-76881","published":"2026-08-21"},{"cve_id":"CVE-2025-68160","title":"Heap out-of-bounds write in BIO_f_linebuffer on short writes","description":"Issue summary: Writing large, newline-free data into a BIO chain using the\nline-buffering filter where the next BIO performs short writes can trigger\na heap-based out-of-bounds write.\n\nImpact summary: This out-of-bounds write can cause memory corruption which\ntypically results in a crash, leading to Denial of Service for an application.\n\nThe line-buffering BIO filter (BIO_f_linebuffer) is not used by default in\nTLS/SSL data paths. In OpenSSL command-line applications, it is typically\nonly pushed onto stdout/stderr on VMS systems. Third-party applications that\nexplicitly use this filter with a BIO chain that can short-write and that\nwrite large, newline-free data influenced by an attacker would be affected.\nHowever, the circumstances where this could happen are unlikely to be under\nattacker control, and BIO_f_linebuffer is unlikely to be handling non-curated\ndata controlled by an attacker. For that reason the issue was assessed as\nLow severity.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue,\nas the BIO implementation is outside the OpenSSL FIPS module boundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.","severity":"medium","cvss_score":4.7,"cvss_vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","cwe":"CWE-787","product":"OpenSSL","reference_count":6,"url":"https://www.cve.org/CVERecord?id=CVE-2025-68160","published":"2026-01-27"},{"cve_id":"CVE-2026-47689","title":"Stored XSS via unescaped inventory data in buildRow() on the Group Inventory tab","description":"The buildRow() method in fogpage.class.php substitutes data values into HTML table cell templates using str_replace() without any HTML escaping. An unauthenticated attacker who knows any registered host’s MAC address can POST malicious inventory values (e.g. sysproduct, sysserial) to /service/inventory.php, which stores them in the database. When an administrator opens the Group Inventory tab, the payload renders as executable HTML/JavaScript in the admin’s browser. This is distinct from the selectForm() unescaped option label issue: it affects a different function (buildRow()) and a different page (Group Inventory tab).","severity":"medium","cvss_score":4.6,"cvss_vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","cwe":"CWE-79","product":"FOG","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-47689","published":"2026-05-19"},{"cve_id":"CVE-2026-27659","title":"CSRF in the access control policy activation endpoint","description":"Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to properly validate CSRF tokens in the /api/v4/access_control_policies/{policy_id}/activate endpoint, which allows an attacker to trick an admin into changing access control policy active status via a crafted request.. Mattermost Advisory ID: MMSA-2026-00578","severity":"medium","cvss_score":4.6,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N","cwe":"CWE-352","product":"Mattermost","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-27659","published":"2026-03-25"},{"cve_id":"CVE-2025-11563","title":"Path traversal in wcurl via percent-encoded slashes","description":"URLs containing percent-encoded slashes (`/` or `\\`) can trick wcurl into\nsaving the output file outside of the current directory without the user\nexplicitly asking for it.\n\nThis flaw only affects the wcurl command line tool.","severity":"medium","cvss_score":4.6,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N","cwe":"CWE-35","product":"curl","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2025-11563","published":"2026-02-25"},{"cve_id":"CVE-2026-67421","title":"RabbitMQ: Stored HTML Injection in RabbitMQ Management OAuth Error Handling","description":"RabbitMQ Management renders an AMQP authorization-error reason as HTML when the OAuth management UI is enabled. A user who can configure a queue can place an HTML `<base>` element in the queue name. If a management administrator who can see that queue but lacks AMQP read permission clicks **Get Message(s)**, the queue name is returned in an `ACCESS_REFUSED` reason and inserted into the page without HTML escaping.\n\nThe default Content Security Policy blocks inline script execution in the current source, but it does not define `base-uri` or `connect-src`. An injected `<base>` element can therefore change the document base URL. The next automatic relative management API refresh is sent to an attacker-controlled CORS endpoint with the victim's explicit `Authorization` header.\n\nThe result is theft of a management administrator's Basic or Bearer credential and subsequent control of RabbitMQ through the management API. The demonstrated chain does not provide broker-host code execution or arbitrary file access.","severity":"medium","cvss_score":4.5,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:L/VI:L/VA:N/SC:H/SI:L/SA:N","cwe":"CWE-79","product":"RabbitMQ","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-67421","published":"2026-08-18"},{"cve_id":"CVE-2026-42307","title":"Command injection in the netrw plugin via crafted sftp:// and file:// URLs","description":"Vim is an open source, command line text editor. Prior to version 9.2.0383, an OS command injection vulnerability exists in the netrw standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the sftp:// or file:// protocol handlers), an attacker can execute arbitrary shell commands with the privileges of the Vim process. This issue has been patched in version 9.2.0383.","severity":"medium","cvss_score":4.4,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","cwe":"CWE-78","product":"vim","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-42307","published":"2026-05-08"},{"cve_id":"CVE-2026-32119","title":"Stored DOM XSS in the SearchHighlight plugin on the Custom Report page","description":"OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, DOM-based stored XSS in the jQuery SearchHighlight plugin (`library/js/SearchHighlight.js`) allows an authenticated user with encounter form write access to inject arbitrary JavaScript that executes in another clinician's browser session when they use the search/find feature on the Custom Report page. The plugin reverses server-side HTML entity encoding by reading decoded text from DOM text nodes, concatenating it into a raw HTML string, and passing it to jQuery's `$()` constructor for HTML parsing. Version 8.0.0.2 fixes the issue.","severity":"medium","cvss_score":4.4,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N","cwe":"CWE-79","product":"openemr","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-32119","published":"2026-03-19"},{"cve_id":"CVE-2026-73196","title":"Authenticated DoS in `otptoken-add` via unbounded otp key decoding/re-encoding","description":"A flaw was found in FreeIPA. A low-privilege authenticated user can exploit this vulnerability by submitting an oversized One-Time Password (OTP) key value. This oversized key is then decoded and re-encoded without proper size limits, consuming excessive CPU and memory resources. This can lead to a denial of service, degrading the availability of the IPA service.","severity":"medium","cvss_score":4.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","cwe":"CWE-770","product":"freeipa","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-73196","published":"2026-08-21"},{"cve_id":"CVE-2026-62377","title":"Reachable assertion in HeifContext::get_track() when opening an empty HEIF sequence file","description":"libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted HEIF sequence accepted by heif_context_read_from_memory() can leave the context with no registered sequence tracks and crash when heif_context_get_track(ctx, 0) is called. HeifContext::get_track() in libheif/context.cc executes assert(has_sequence()) before its normal error handling, so assert-enabled builds abort instead of allowing the public wrapper in libheif/api/libheif/heif_sequences.cc to return null. In release builds, removing the assertion lets the track_id zero path dereference m_tracks.begin()->second on an empty map, which is undefined behavior and typically crashes. The issue is reachable through documented public APIs after parsing attacker-controlled bytes. This issue is fixed in version 1.23.1.","severity":"medium","cvss_score":4.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","cwe":"CWE-617","product":"libheif","reference_count":4,"url":"https://www.cve.org/CVERecord?id=CVE-2026-62377","published":"2026-07-27"},{"cve_id":"CVE-2026-55653","title":"Double free in red hat enterprise linux versions of openssh dh-gex client path during fips known-group validation leads to client-side denial of service","description":"A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters. Successful exploitation leads to client-side process termination, resulting in a Denial of Service (DoS).","severity":"medium","cvss_score":4.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","cwe":"CWE-415","product":"OpenSSH","reference_count":7,"url":"https://www.cve.org/CVERecord?id=CVE-2026-55653","published":"2026-08-19"},{"cve_id":"CVE-2026-33934","title":"Missing authorization in show-signature.php lets portal patients read staff signatures","description":"OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.3 have a missing authorization check in `portal/sign/lib/show-signature.php` that allows any authenticated patient portal user to retrieve the drawn signature image of any staff member by supplying an arbitrary `user` value in the POST body. The companion write endpoint (`save-signature.php`) was already hardened against this same issue, but the read endpoint was not updated to match. Version 8.0.0.3 patches the issue.","severity":"medium","cvss_score":4.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","cwe":"CWE-639","product":"openemr","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-33934","published":"2026-03-25"},{"cve_id":"CVE-2026-32122","title":"Missing authorization on the Claim File Tracker AJAX endpoint exposes billing claim data","description":"OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, the Claim File Tracker feature exposes an AJAX endpoint that returns billing claim metadata (claim IDs, payer info, transmission logs). The endpoint does not enforce the same ACL as the main billing/claims workflow, so authenticated users without appropriate billing permissions can access this data. This vulnerability is fixed in 8.0.0.1.","severity":"medium","cvss_score":4.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","cwe":"CWE-862","product":"openemr","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-32122","published":"2026-03-11"},{"cve_id":"CVE-2026-28901","title":"Memory corruption when processing crafted web content leading to a process crash","description":"The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web content may lead to an unexpected process crash.","severity":"medium","cvss_score":4.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","cwe":"CWE-119","product":"Safari","reference_count":6,"url":"https://www.cve.org/CVERecord?id=CVE-2026-28901","published":"2026-05-11"},{"cve_id":"CVE-2026-26326","title":"Secret disclosure to operator.read clients via raw config values in skills.status","description":"OpenClaw is a personal AI assistant. Prior to version 2026.2.14, `skills.status` could disclose secrets to `operator.read` clients by returning raw resolved config values in `configChecks` for skill `requires.config` paths. Version 2026.2.14 stops including raw resolved config values in requirement checks (return only `{ path, satisfied }`) and narrows the Discord skill requirement to the token key. In addition to upgrading, users should rotate any Discord tokens that may have been exposed to read-scoped clients.","severity":"medium","cvss_score":4.3,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","cwe":"CWE-200","product":"OpenClaw","reference_count":4,"url":"https://www.cve.org/CVERecord?id=CVE-2026-26326","published":"2026-02-19"},{"cve_id":"CVE-2026-25783","title":"Denial of service via a malformed User-Agent header in getBrowserVersion","description":"Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validate User-Agent header tokens which allows an authenticated attacker to cause a request panic via a specially crafted User-Agent header. Mattermost Advisory ID: MMSA-2026-00586","severity":"medium","cvss_score":4.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","cwe":"CWE-1287","product":"Mattermost","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-25783","published":"2026-03-16"},{"cve_id":"CVE-2026-25568","title":"Public boards can be created despite the allowPrivateOnly setting","description":"WeKan versions prior to 8.19 contain an authorization logic vulnerability where the instance configuration setting allowPrivateOnly is not sufficiently enforced at board creation time. When allowPrivateOnly is enabled, users can still create public boards due to incomplete server-side enforcement.","severity":"medium","cvss_score":4.3,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","cwe":"CWE-863","product":"WeKan","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-25568","published":"2026-02-07"},{"cve_id":"CVE-2026-25567","title":"Comment author spoofing via a user-supplied authorId in the card comment API","description":"WeKan versions prior to 8.19 contain an insecure direct object reference (IDOR) in the card comment creation API. The endpoint accepts an authorId from the request body, allowing an authenticated user to spoof the recorded comment author by supplying another user's identifier.","severity":"medium","cvss_score":4.3,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N","cwe":"CWE-639","product":"WeKan","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-25567","published":"2026-02-07"},{"cve_id":"CVE-2026-25562","title":"Attachment metadata disclosure via unscoped results in the attachments publication","description":"WeKan versions prior to 8.19 contain an information disclosure vulnerability in the attachments publication. Attachment metadata can be returned without properly scoping results to boards and cards accessible to the requesting user, potentially exposing attachment metadata to unauthorized users.","severity":"medium","cvss_score":4.3,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","cwe":"CWE-203","product":"WeKan","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-25562","published":"2026-02-07"},{"cve_id":"CVE-2026-10028","title":"Infinite loop in the GnuTLS backend on circular certificate chains leading to denial of service","description":"A flaw was found in glib-networking. A remote attacker can exploit this vulnerability by presenting a specially crafted certificate chain to an application that uses glib-networking with the GnuTLS backend enabled and performs certificate verification. This crafted chain, which contains circular issuer relationships, can cause an infinite loop during certificate verification. The unbounded traversal consumes excessive CPU resources, leading to a denial of service for the affected process or worker.","severity":"medium","cvss_score":4.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","cwe":"CWE-835","product":"glib-networking","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-10028","published":"2026-05-28"},{"cve_id":"CVE-2026-5138","title":"Cross-tenant infrastructure metadata disclosure via unvalidated IDs in taxonomy_scope","description":"A flaw was found in Foreman. An authenticated user with host-edit permissions could exploit a cross-tenant information disclosure vulnerability. This flaw occurs because the taxonomy_scope controller method does not properly validate organization and location IDs from nested request parameters, bypassing existing authorization checks. This allows the user to leak sensitive infrastructure metadata, including subnet topology, IP ranges, gateways, DNS servers, and VLAN IDs, from organizations and locations they are not authorized to access.","severity":"medium","cvss_score":4.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","cwe":"CWE-639","product":"Foreman","reference_count":6,"url":"https://www.cve.org/CVERecord?id=CVE-2026-5138","published":"2026-07-16"},{"cve_id":"CVE-2026-2578","title":"Information disclosure of unrevealed burn-on-read posts via the WebSocket deletion event","description":"Mattermost versions 11.3.x <= 11.3.0 fail to preserve the redacted state of burn-on-read posts during deletion which allows channel members to access unrevealed burn-on-read message contents via the WebSocket post deletion event.. Mattermost Advisory ID: MMSA-2026-00579","severity":"medium","cvss_score":4.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","cwe":"CWE-201","product":"Mattermost","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-2578","published":"2026-03-16"},{"cve_id":"CVE-2026-2209","title":"Improper authorization in the setCreateTranslation custom translation handler","description":"A vulnerability was detected in WeKan up to 8.18. The affected element is the function setCreateTranslation of the file client/components/settings/translationBody.js of the component Custom Translation Handler. The manipulation results in improper authorization. The attack can be launched remotely. Upgrading to version 8.19 is sufficient to fix this issue. The patch is identified as f244a43771f6ebf40218b83b9f46dba6b940d7de. It is suggested to upgrade the affected component.","severity":"medium","cvss_score":4.3,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X","cwe":"CWE-285","product":"WeKan","reference_count":6,"url":"https://www.cve.org/CVERecord?id=CVE-2026-2209","published":"2026-02-08"},{"cve_id":"CVE-2026-2205","title":"Information disclosure in the cards Meteor publication","description":"A vulnerability was identified in WeKan up to 8.20. This affects an unknown part of the file server/publications/cards.js of the component Meteor Publication Handler. Such manipulation leads to information disclosure. The attack may be performed from remote. Upgrading to version 8.21 is able to mitigate this issue. The name of the patch is 0f5a9c38778ca550cbab6c5093470e1e90cb837f. Upgrading the affected component is advised.","severity":"medium","cvss_score":4.3,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X","cwe":"CWE-200","product":"WeKan","reference_count":6,"url":"https://www.cve.org/CVERecord?id=CVE-2026-2205","published":"2026-02-08"},{"cve_id":"CVE-2026-1897","title":"Missing authorization in the position-history server methods","description":"A vulnerability was found in WeKan up to 8.20. Affected by this issue is some unknown functionality of the file server/methods/positionHistory.js of the component Position-History Tracking. The manipulation results in missing authorization. The attack may be performed from remote. Upgrading to version 8.21 can resolve this issue. The patch is identified as 55576ec17722db094835470b386162c9a662fb60. It is advisable to upgrade the affected component.","severity":"medium","cvss_score":4.3,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X","cwe":"CWE-862","product":"WeKan","reference_count":6,"url":"https://www.cve.org/CVERecord?id=CVE-2026-1897","published":"2026-02-05"},{"cve_id":"CVE-2026-1629","title":"Cached permalink previews remain viewable after channel access is revoked","description":"Mattermost versions 10.11.x <= 10.11.10 Fail to invalidate cached permalink preview data when a user loses channel access which allows the user to continue viewing private channel content via previously cached permalink previews until cache reset or relogin.. Mattermost Advisory ID: MMSA-2026-00580","severity":"medium","cvss_score":4.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","cwe":"CWE-672","product":"Mattermost","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-1629","published":"2026-03-16"},{"cve_id":"CVE-2026-0930","title":"Out-of-bounds stack read in wolfSSHd on Windows when handling terminal resize requests","description":"Potential read out of bounds case with wolfSSHd on Windows while handling a terminal resize request. An authenticated user could trigger the out of bounds read after establishing a connection which would leak the adjacent stack memory to the pseudo-console output.","severity":"medium","cvss_score":4.3,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N","cwe":"CWE-126","product":"wolfSSH","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-0930","published":"2026-04-20"},{"cve_id":"CVE-2026-0396","title":"HTML injection in the web dashboard via crafted DNS queries","description":"An attacker might be able to inject HTML content into the internal web dashboard by sending crafted DNS queries to a DNSdist instance where domain-based dynamic rules have been enabled via either DynBlockRulesGroup:setSuffixMatchRule or DynBlockRulesGroup:setSuffixMatchRuleFFI.","severity":"medium","cvss_score":4.3,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N","cwe":"CWE-80","product":"DNSdist","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-0396","published":"2026-03-31"},{"cve_id":"CVE-2025-12443","title":"Out-of-bounds read in WebXR via a crafted HTML page","description":"Out of bounds read in WebXR in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)","severity":"medium","cvss_score":4.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","cwe":"CWE-125","product":"Chrome","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2025-12443","published":"2025-11-10"},{"cve_id":"CVE-2025-11932","title":"Timing side channel in TLS 1.3 PSK binder verification","description":"The server previously verified the TLS 1.3 PSK binder using a non-constant time method which could potentially leak information about the PSK binder","severity":"medium","cvss_score":4.3,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N","cwe":"CWE-203","product":"wolfSSL","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2025-11932","published":"2025-11-21"},{"cve_id":"CVE-2025-10966","title":"Missing SFTP host verification with the wolfSSH backend","description":"curl's code for managing SSH connections when SFTP was done using the wolfSSH\npowered backend was flawed and missed host verification mechanisms.\n\nThis prevents curl from detecting MITM attackers and more.","severity":"medium","cvss_score":4.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","cwe":"CWE-322","product":"curl","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2025-10966","published":"2025-11-07"},{"cve_id":"CVE-2026-90996","title":"Denial of service in nss responder via crafted zero-length requests","description":"A flaw was found in sssd. A local unprivileged user could send a specially crafted request with a zero-length body to the Network Security Services (NSS) responder. This could lead to a denial-of-service condition, causing the NSS responder to become unstable or terminate. This vulnerability affects the availability of the system responder.","severity":"medium","cvss_score":4.0,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","cwe":"CWE-191","product":"sssd","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-90996","published":"2026-09-14"},{"cve_id":"CVE-2026-90994","title":"Denial of service via malformed pam v1 requests","description":"A flaw was found in sssd, specifically within the PAM (Pluggable Authentication Modules) responder's protocol v1 parser, pam_parse_in_data(). A local client with access to the PAM responder's UNIX socket can exploit this by negotiating protocol v1 and sending an empty or truncated PAM request body. This can trigger an out-of-bounds read, potentially causing the PAM responder to terminate or restart, leading to a local denial of service.","severity":"medium","cvss_score":4.0,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","cwe":"CWE-125","product":"sssd","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-90994","published":"2026-09-14"},{"cve_id":"CVE-2026-90463","title":"OOB read in nss service request parsers","description":"A flaw was found in the sssd NSS responder. This input validation vulnerability allows a local attacker, by sending specially crafted service lookup requests to the NSS responder's UNIX socket, to cause an out-of-bounds read. This out-of-bounds read may lead to a denial of service (DoS) by crashing the NSS responder process. While unprivileged local clients can typically reach the socket, there is no evidence of privilege escalation or reliable data disclosure.","severity":"medium","cvss_score":4.0,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","cwe":"CWE-125","product":"sssd","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-90463","published":"2026-09-14"},{"cve_id":"CVE-2026-42014","title":"Use-after-free in gnutls_pkcs11_token_set_pin() with a NULL old PIN","description":"A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can lead to a use-after-free vulnerability. This occurs when an attacker attempts to change the PIN with a NULL old PIN for a token that lacks a protected authentication path.","severity":"medium","cvss_score":4,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H","cwe":"CWE-825","product":"GnuTLS","reference_count":16,"url":"https://www.cve.org/CVERecord?id=CVE-2026-42014","published":"2026-06-16"},{"cve_id":"CVE-2025-69418","title":"Trailing bytes left unencrypted and unauthenticated in low-level CRYPTO_ocb128 calls","description":"Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs whose length is not a multiple<br>of 16 bytes can leave the final partial block unencrypted and unauthenticated.<br><br>Impact summary: The trailing 1-15 bytes of a message may be exposed in<br>cleartext on encryption and are not covered by the authentication tag,<br>allowing an attacker to read or tamper with those bytes without detection.<br><br>The low-level OCB encrypt and decrypt routines in the hardware-accelerated<br>stream path process full 16-byte blocks but do not advance the input/output<br>pointers. The subsequent tail-handling code then operates on the original<br>base pointers, effectively reprocessing the beginning of the buffer while<br>leaving the actual trailing bytes unprocessed. The authentication checksum<br>also excludes the true tail bytes.<br><br>However, typical OpenSSL consumers using EVP are not affected because the<br>higher-level EVP and provider OCB implementations split inputs so that full<br>blocks and trailing partial blocks are processed in separate calls, avoiding<br>the problematic code path. Additionally, TLS does not use OCB ciphersuites.<br>The vulnerability only affects applications that call the low-level<br>CRYPTO_ocb128_encrypt() or CRYPTO_ocb128_decrypt() functions directly with<br>non-block-aligned lengths in a single call on hardware-accelerated builds.<br>For these reasons the issue was assessed as Low severity.<br><br>The FIPS modules in 3.6, 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected<br>by this issue, as OCB mode is not a FIPS-approved algorithm.<br><br>OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue.<br><br>OpenSSL 1.0.2 is not affected by this issue.","severity":"medium","cvss_score":4,"cvss_vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","cwe":"CWE-325","product":"OpenSSL","reference_count":6,"url":"https://www.cve.org/CVERecord?id=CVE-2025-69418","published":"2026-01-27"},{"cve_id":"CVE-2025-9820","title":"Stack buffer overflow in gnutls_pkcs11_token_init() when processing long token labels","description":"A flaw was found in the GnuTLS library, specifically in the gnutls_pkcs11_token_init() function that handles PKCS#11 token initialization. When a token label longer than expected is processed, the function writes past the end of a fixed-size stack buffer. This programming error can cause the application using GnuTLS to crash or, in certain conditions, be exploited for code execution. As a result, systems or applications relying on GnuTLS may be vulnerable to a denial of service or local privilege escalation attacks.","severity":"medium","cvss_score":4,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","cwe":"CWE-121","product":"GnuTLS","reference_count":14,"url":"https://www.cve.org/CVERecord?id=CVE-2025-9820","published":"2026-01-26"},{"cve_id":"CVE-2026-97026","title":"World-writable temporary child repositories in system-helper cache path","description":"Flatpak creates temporary child repository directories under the user cache with world-writable permissions (0777). On multi-user systems with a permissive umask, other local users could read or modify the temporary directory used while installing apps or runtimes, potentially causing installation failures (denial of service); tampered content would fail signature/digest verification rather than being trusted.","severity":"low","cvss_score":3.9,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L","cwe":"CWE-378","product":"flatpak","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-97026","published":"2026-09-29"},{"cve_id":"CVE-2025-15497","title":"Reachable assertion in epoch key slot processing leading to denial of service","description":"Insufficient epoch key slot processing in OpenVPN 2.7_alpha1 through 2.7_rc5 allows remote authenticated users to trigger an assert resulting in a denial of service","severity":"low","cvss_score":3.8,"cvss_vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:U","cwe":"CWE-617","product":"OpenVPN","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2025-15497","published":"2026-01-30"},{"cve_id":"CVE-2026-97399","title":"One-byte overread in strncasecmp on Power8","description":"The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.\n\nThis condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable.","severity":"low","cvss_score":3.7,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","cwe":"CWE-126","product":"glibc","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-97399","published":"2026-09-28"},{"cve_id":"CVE-2026-85008","title":"undici vulnerable to caching and replay of unsafe HTTP method responses","description":"undici's cache interceptor documents that only safe HTTP methods are cached, but its logic to skip caching is built by subtracting the configured methods from the set of safe methods, so an unsafe method such as POST, PUT, or DELETE is never placed in the skip list and instead falls through to the full cache-read path. The response-storage gate also lacked a method check, so a response to an unsafe request that is heuristically cacheable or carries an explicit Cache-Control directive is stored and later replayed from cache. Because response headers from a remote origin are untrusted, an origin can answer once with a cacheable status and then have the client's own subsequent state-changing requests to that path served from the stale cache entry without ever reaching the origin, an integrity failure that occurs under the interceptor's default configuration. This affects undici versions from 7.0.0 up to 7.29.1 and from 8.0.0 up to 8.10.2. Users should upgrade to undici 7.29.1 or 8.10.2.","severity":"low","cvss_score":3.7,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","cwe":"CWE-345","product":"undici","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-85008","published":"2026-09-04"},{"cve_id":"CVE-2026-82209","title":"domain-scoped PSL domain cookie","description":"When libpsl support is enabled, libcurl fails to enforce the Public Suffix\nList boundary check when processing a `Set-Cookie` header where the `Domain`\nattribute explicitly matches an origin host that is itself a public suffix\n(e.g., `Domain=co.uk` set by `co.uk`).\n\nInstead of coercing it into a strict host-only cookie, libcurl saves the\ncookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is\ninappropriately included in subsequent outbound requests or HTTP redirects to\narbitrary sibling subdomains under the same public suffix (e.g.,\n`attacker.co.uk`).","severity":"low","cvss_score":3.7,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","cwe":"CWE-201","product":"curl","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-82209","published":"2026-09-07"},{"cve_id":"CVE-2026-80255","title":"secure cookie attribute bypass with tab","description":"A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of\nspace (ascii code 32) immediately before the `Secure` attribute causes curl to\nstore the cookie without its Secure flag. The cookie might then wrongfully be\nsent over plaintext HTTP on subsequent requests to the same host.","severity":"low","cvss_score":3.7,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","cwe":"CWE-201","product":"curl","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-80255","published":"2026-09-07"},{"cve_id":"CVE-2026-55654","title":"Heap out-of-bounds read in red hat enterprise linux versions of openssh gssapi indicator cleanup due to missing null sentinel termination","description":"A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the auth-indicators array. A remote attacker, under specific configurations involving GSSAPI authentication and a Kerberos environment, could exploit this to cause the SSH authentication path to crash or abort. This leads to a denial of service (DoS), impacting the availability of the SSH service.","severity":"low","cvss_score":3.7,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","cwe":"CWE-125","product":"OpenSSH","reference_count":6,"url":"https://www.cve.org/CVERecord?id=CVE-2026-55654","published":"2026-08-19"},{"cve_id":"CVE-2026-54875","title":"Non-Constant-Time SM2 Scalar Multiplication on ARM64 and RISC-V","description":"Issue summary: A non-constant-time optimized implementation of scalar\npoint multiplication is used for SM2 private key operations on ARM64 and\nRISC-V platforms.\n\nImpact summary: An attacker able to measure the time taken by, or to observe\nthe cache-line access pattern of SM2 signing or decryption on an affected\nplatform can learn information about the secret scalar.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: On ARM64 and RISC-V processors, the SM2 curve uses an optimized\nscalar multiplication implementation whose conditional branches and table\nlook ups are chosen according to the bits of the secret scalar. The execution\ntime and the cache-access pattern therefore depend on the long-term private\nkey (during SM2 decryption) or the per-signature nonce (during SM2 signature\ngeneration), forming a timing and cache side-channel.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm and the optimized SM2 implementation is not part\nof the FIPS module.\n\nOpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and\nRISC-V.\n\nOpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.3.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.5.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.9.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.8.\n\nThis issue was reported on 2 May 2026 by Abhinav Agarwal.\nIt was independently reported on 6 June 2026 by Feng Xue.\nThe fix was developed by Igor Ustinov.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Abhinav Agarwal, Feng Xue\nFixed by: Igor Ustinov","severity":"low","cvss_score":3.7,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","cwe":"CWE-208","product":"OpenSSL","reference_count":5,"url":"https://www.cve.org/CVERecord?id=CVE-2026-54875","published":"2026-10-01"},{"cve_id":"CVE-2026-45232","title":"Off-by-one stack write in establish_proxy_connection() via a malformed HTTP proxy response","description":"Rsync versions before 3.4.3 contain an off-by-one out-of-bounds stack write vulnerability in the establish_proxy_connection() function in socket.c that allows network attackers to corrupt stack memory by sending a malformed HTTP proxy response. Attackers can exploit this by positioning themselves between the client and proxy or controlling the proxy server to send a response line of 1023 or more bytes without a newline terminator, causing a null byte to be written to an out-of-bounds stack address when the RSYNC_PROXY environment variable is set.","severity":"low","cvss_score":3.7,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","cwe":"CWE-193","product":"rsync","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-45232","published":"2026-05-20"},{"cve_id":"CVE-2026-28810","title":"Predictable DNS transaction IDs in the inet_res resolver enable cache poisoning","description":"Generation of Predictable Numbers or Identifiers vulnerability in Erlang/OTP kernel (inet_res, inet_db modules) allows DNS Cache Poisoning.\n\nThe built-in DNS resolver (inet_res) uses a sequential, process-global 16-bit transaction ID for UDP queries and does not implement source port randomization. Response validation relies almost entirely on this ID, making DNS cache poisoning practical for an attacker who can observe one query or predict the next ID. This conflicts with RFC 5452 recommendations for mitigating forged DNS answers.\n\ninet_res is intended for use in trusted network environments and with trusted recursive resolvers. Earlier documentation did not clearly state this deployment assumption, which could lead users to deploy the resolver in environments where spoofed DNS responses are possible.\n\nThis vulnerability is associated with program files lib/kernel/src/inet_db.erl and lib/kernel/src/inet_res.erl.\n\nThis issue affects OTP from OTP 17.0 until OTP 28.4.2, 27.3.4.10 and 26.2.5.19 corresponding to kernel from 3.0 until 10.6.2, 10.2.7.4 and 9.2.4.11.","severity":"low","cvss_score":3.7,"cvss_vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","cwe":"CWE-340","product":"OTP","reference_count":7,"url":"https://www.cve.org/CVERecord?id=CVE-2026-28810","published":"2026-04-07"},{"cve_id":"CVE-2026-3832","title":"Revoked server certificates accepted via crafted multi-record OCSP response","description":"A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly accept a revoked server certificate, potentially leading to a compromise of trust.","severity":"low","cvss_score":3.7,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","cwe":"CWE-179","product":"GnuTLS","reference_count":9,"url":"https://www.cve.org/CVERecord?id=CVE-2026-3832","published":"2026-04-30"},{"cve_id":"CVE-2026-95818","title":"AT_SECURE program buffer overflow via $ORIGIN processing","description":"A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.\n\nWhen such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory.","severity":"low","cvss_score":3.6,"cvss_vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","cwe":"CWE-121","product":"glibc","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-95818","published":"2026-09-24"},{"cve_id":"CVE-2026-91142","title":"Integer overflow in `do_lastlog()` offset calculation can misaddress `lastlog` entries on ilp32 builds","description":"A flaw was found in Cockpit. An integer overflow vulnerability in the `do_lastlog()` function, specifically in the offset calculation for `lastlog` entries on ILP32 (Integer, Long, Pointer 32-bit) builds, can be exploited. A low-privileged authenticated user with a specially provisioned large User ID (UID) can cause the computed offset to wrap around. This allows the user to perform unauthorized reads and writes to other users' `lastlog` records, potentially disclosing or altering sensitive login accounting information.","severity":"low","cvss_score":3.6,"cvss_vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","cwe":"CWE-787","product":"cockpit","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-91142","published":"2026-09-20"},{"cve_id":"CVE-2026-97025","title":"World-readable oci authentication token in system-helper cache path","description":"Flatpak writes the OCI repository authentication token with world-readable permissions (0644) in the system-helper's cache directory, allowing other local users on a multi-user system to read the token and impersonate the authenticated user against the OCI repository. Only OCI-based sources (e.g. as used by Fedora) are affected; libostree-based sources such as Flathub are not.","severity":"low","cvss_score":3.2,"cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N","cwe":"CWE-378","product":"flatpak","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-97025","published":"2026-09-29"},{"cve_id":"CVE-2026-80229","title":"OpenSSL provider use-after-free","description":"When performing transfers via libcurl’s multi interface, pooled TLS\nconnections can outlive their originating easy handles. In OpenSSL 3 provider\nconfigurations, libcurl attaches an allocated library context to the easy\nhandle's state and passes it to OpenSSL without acquiring an ownership\nreference; destroying the easy handle prematurely frees this context while the\nactive connection retains a dangling pointer, leading to a heap-use-after-free\nupon subsequent I/O or post-handshake operations.","severity":"low","cvss_score":3.1,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","cwe":"CWE-416","product":"curl","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-80229","published":"2026-09-07"},{"cve_id":"CVE-2026-76926","title":"Reachable Assertion in Wireshark","description":"BUSMASTER file parser abnormal exit in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service","severity":"low","cvss_score":3.1,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","cwe":"CWE-617","product":"Wireshark","reference_count":2,"url":"https://www.cve.org/CVERecord?id=CVE-2026-76926","published":"2026-08-21"},{"cve_id":"CVE-2026-59849","title":"Infinite loop in automatic certificate authentication leading to denial of service","description":"A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when configured certificates are missing or repeatedly rejected by a server, leading to denial of service.","severity":"low","cvss_score":3.1,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L","cwe":"CWE-835","product":"libssh","reference_count":3,"url":"https://www.cve.org/CVERecord?id=CVE-2026-59849","published":"2026-07-24"},{"cve_id":"CVE-2026-67420","title":"OAuth credential refresh retains revoked runtime tags","description":"When an existing AMQP connection refreshes from an OAuth token that grants the\n`impersonator` tag to a valid same-username token that **no longer** grants that\ntag, RabbitMQ updates the OAuth backend implementation (token/scopes/expiry) but\nleaves the connection's runtime `#user.tags` unchanged.\n\n`rabbit_access_control:check_user_id/2` then still honors the stale\n`impersonator` tag, so the connection (including newly opened channels) can\ncontinue publishing messages with a foreign AMQP `user_id` after that privilege\nshould have been revoked.\n\nA fresh connection using the downgraded token correctly refuses the same\npublish, proving the defect is stale session state rather than the token itself.","severity":"low","cvss_score":2.3,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N","cwe":"CWE-613","product":"RabbitMQ","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-67420","published":"2026-08-18"},{"cve_id":"CVE-2026-67418","title":"Inapplicable PUBLISH property disconnects matching subscribers","description":"RabbitMQ's MQTT 5 property parser accepts properties without checking whether\nthey are valid for the enclosing packet type. An authenticated publisher can\ninclude `Request-Problem-Information` (MQTT property 0x17) in a `PUBLISH` —\na property that the MQTT 5 specification restricts to `CONNECT` — and the\nbroker will store and route it.\n\nWhen a matching subscriber's reader later serializes the outbound `PUBLISH`,\n`serialise_prop/2` has **no clause** for `Request-Problem-Information`, raising\n`error:function_clause`. That exception is not contained at the victim\nqueue-event boundary, so the **victim's entire MQTT connection** is closed.\nThe publisher's connection and the broker remain healthy.","severity":"low","cvss_score":2.3,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","cwe":"CWE-20","product":"RabbitMQ","reference_count":1,"url":"https://www.cve.org/CVERecord?id=CVE-2026-67418","published":"2026-08-18"},{"cve_id":"CVE-2026-21620","title":"Relative path traversal in the tftp_file module","description":"Relative Path Traversal, Improper Isolation or Compartmentalization vulnerability in erlang otp erlang/otp (tftp_file modules), erlang otp inets (tftp_file modules), erlang otp tftp (tftp_file modules) allows Relative Path Traversal. This vulnerability is associated with program files lib/tftp/src/tftp_file.erl, src/tftp_file.erl.\n\nThis issue affects otp: from 17.0, from 07b8f441ca711f9812fad9e9115bab3c3aa92f79; otp: from 5.10 before 7.0; otp: from 1.0.","severity":"low","cvss_score":2.3,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N","cwe":"CWE-23","product":"OTP","reference_count":8,"url":"https://www.cve.org/CVERecord?id=CVE-2026-21620","published":"2026-02-20"}]}