<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Hashicorp Boundary (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/boundary.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/boundary-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Hashicorp Boundary (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:30 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-4035 – A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for the resolut...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4035</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4035</guid>
    <pubDate>Wed, 03 Jun 2026 09:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-4035</strong></p>
  <p>A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for the resolution of environment variables in AI Gateway secrets, which can be exploited to exfiltrate sensitive server-side environment credentials to an attacker-controlled endpoint. This issue arises because the `api_key` field in gateway secrets can accept `$ENV_VAR` references, which are resolved against the MLflow server's en…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-201</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4035">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10701 – Incorrect boundary conditions in the Graphics: Text component. This vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10701</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10701</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10701</strong></p>
  <p>Incorrect boundary conditions in the Graphics: Text component. This vulnerability was fixed in Firefox 151.0.3.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10701">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5422 – A path traversal vulnerability exists in jupyter-server version 2.17.0 due to an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5422</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5422</guid>
    <pubDate>Tue, 02 Jun 2026 10:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5422</strong></p>
  <p>A path traversal vulnerability exists in jupyter-server version 2.17.0 due to an incorrect root directory boundary check in the _get_os_path() function within jupyter_server/services/contents/fileio.py. The check uses startswith(root) without appending a trailing path separator, allowing sibling directories with names starting with the same prefix as root_dir to bypass the check. Additionally, th…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5422">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8796 – Sereal::Decoder versions before 5.005 for Perl allow heap out-of-bounds read via...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8796</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8796</guid>
    <pubDate>Sun, 31 May 2026 20:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8796</strong></p>
  <p>Sereal::Decoder versions before 5.005 for Perl allow heap out-of-bounds read via crafted input.  In Perl/Decoder/srl_decoder.c, srl_read_object() and srl_read_hash() process a COPY tag, a back-reference whose target byte the decoder re-decodes as a fresh tag. When that target byte matches the SHORT_BINARY pattern (an inline string whose length is encoded in the low bits of the tag), the resulting…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8796">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44973 – Billy is an interface filesystem abstraction for Go. Prior to 5.9.0, multiple pa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44973</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44973</guid>
    <pubDate>Thu, 28 May 2026 22:16:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44973</strong></p>
  <p>Billy is an interface filesystem abstraction for Go. Prior to 5.9.0, multiple path traversal issues exist across different components of go-billy. Insufficient path sanitization and boundary enforcement may allow crafted paths (e.g., using ..) to escape intended base directories. While go-billy was not originally designed to provide a strong security boundary, some of these issues were inconsiste…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44973">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-49127 – Music Player Daemon (MPD) before version 0.24.11 contains a stack buffer overflo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49127</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49127</guid>
    <pubDate>Thu, 28 May 2026 20:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-49127</strong></p>
  <p>Music Player Daemon (MPD) before version 0.24.11 contains a stack buffer overflow vulnerability in the pcm_unpack_24be function in src/pcm/Pack.cxx that allows unauthenticated attackers to corrupt stack memory by triggering an off-by-one write in the PCM decoder plugin. Attackers can issue two MPD commands referencing a malicious HTTP audio source to cause the unpack loop to write 1366 entries in…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-193</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49127">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-45311 – CodeWhale is a DeepSeek + MiMo coding agent in terminal. From 0.3.0 to 0.8.23, t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45311</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45311</guid>
    <pubDate>Thu, 28 May 2026 18:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-45311</strong></p>
  <p>CodeWhale is a DeepSeek + MiMo coding agent in terminal. From 0.3.0 to 0.8.23, the run_tests tool executes cargo test in the workspace with ApprovalRequirement::Auto, meaning it runs without any user approval prompt. cargo test compiles and executes arbitrary code: test binaries, build.rs build scripts, and proc macros. While auto-approving test execution is a deliberate design choice, it creates…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45311">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45296 – OpenReplay is a self-hosted session replay suite. Prior to 1.26.0, OpenReplay's ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45296</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45296</guid>
    <pubDate>Thu, 28 May 2026 18:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45296</strong></p>
  <p>OpenReplay is a self-hosted session replay suite. Prior to 1.26.0, OpenReplay's Python API exposes several app_apikey routes that trust a caller-provided projectKey after validating only that the API key itself is valid and that the target projectKey exists. The authorization flow does not verify that the authenticated API key and the requested project belong to the same tenant. Because the publi…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45296">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-49238 – An issue was discovered in Canonical Multipass before version 1.16.3. The host-s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49238</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49238</guid>
    <pubDate>Thu, 28 May 2026 14:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-49238</strong></p>
  <p>An issue was discovered in Canonical Multipass before version 1.16.3. The host-side SFTP server component (sshfs_server), which executes with root privileges on the host, contains a path containment bypass vulnerability within its validate_path function in src/sshfs_mount/sftp_server.cpp. The function performs a plain string prefix comparison on requested paths without path separator validation o…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49238">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46111 – In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46111</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46111</guid>
    <pubDate>Thu, 28 May 2026 10:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46111</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: hci_conn: fix potential UAF in create_big_sync  Add hci_conn_valid() check in create_big_sync() to detect stale connections before proceeding with BIG creation. Handle the resulting -ECANCELED in create_big_complete() and re-validate the connection under hci_dev_lock() before dereferencing, matching the pattern used b…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46111">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-44327 – free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44327</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44327</guid>
    <pubDate>Wed, 27 May 2026 17:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-44327</strong></p>
  <p>free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-oam route group without inbound OAuth2/bearer-token authorization. A network attacker who can reach NEF on the SBI can hit the OAM route with no Authorization header at all and the handler returns 200 OK. The current OAM handler is a stub that returns null, but the structural defect is r…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44327">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44320 – free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44320</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44320</guid>
    <pubDate>Wed, 27 May 2026 17:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44320</strong></p>
  <p>free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-callback route group without inbound OAuth2/bearer-token authorization. A forged or arbitrary bearer token (e.g. Authorization: Bearer not-a-real-token) is enough to reach the SMF-callback handler -- the callback body is parsed and dispatched into NEF business logic instead of being reje…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44320">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46078 – In the Linux kernel, the following vulnerability has been resolved:

erofs: fix ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46078</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46078</guid>
    <pubDate>Wed, 27 May 2026 14:17:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46078</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  erofs: fix the out-of-bounds nameoff handling for trailing dirents  Currently we already have boundary-checks for nameoffs, but the trailing dirents are special since the namelens are calculated with strnlen() with unchecked nameoffs.  If a crafted EROFS has a trailing dirent with nameoff >= maxsize, maxsize - nameoff can underf…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46078">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46070 – In the Linux kernel, the following vulnerability has been resolved:

md/raid5: v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46070</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46070</guid>
    <pubDate>Wed, 27 May 2026 14:17:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46070</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  md/raid5: validate payload size before accessing journal metadata  r5c_recovery_analyze_meta_block() and r5l_recovery_verify_data_checksum_for_mb() iterate over payloads in a journal metadata block using on-disk payload size fields without validating them against the remaining space in the metadata block.  A corrupted journal co…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46070">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46062 – In the Linux kernel, the following vulnerability has been resolved:

ntfs3: fix ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46062</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46062</guid>
    <pubDate>Wed, 27 May 2026 14:17:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46062</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ntfs3: fix integer overflow in run_unpack() volume boundary check  The volume boundary check `lcn + len > sbi->used.bitmap.nbits` uses raw addition which can wrap around for large lcn and len values, bypassing the validation.  Use check_add_overflow() as is already done for the adjacent prev_lcn + dlcn and vcn64 + len checks add…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46062">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-38426 – Buffer Overflow vulnerability in arendst Tasmota v.15.3.0.3 and before allows a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-38426</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-38426</guid>
    <pubDate>Wed, 27 May 2026 14:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-38426</strong></p>
  <p>Buffer Overflow vulnerability in arendst Tasmota v.15.3.0.3 and before allows a remote attacker to execute arbitrary code via the xdrv_10_scripter.ino, fetch_jpg(), jpg_task.boundary[40], strcpy() function.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-38426">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43988 – Vanetza is an open-source implementation of the ETSI C-ITS protocol suite. In 26...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43988</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43988</guid>
    <pubDate>Tue, 26 May 2026 22:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43988</strong></p>
  <p>Vanetza is an open-source implementation of the ETSI C-ITS protocol suite. In 26.02 and earlier, a denial-of-service vulnerability was identified in the ASN.1/OER parsing pipeline of Vanetza. When processing malformed network packets containing corrupted ASN.1/OER structures (e.g., invalid length fields or malformed certificate encoding), the ASN.1 wrapper (asn1c_wrapper.cpp) raises a std::runtim…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-248</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43988">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-44451 – Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the component ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44451</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44451</guid>
    <pubDate>Tue, 26 May 2026 21:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-44451</strong></p>
  <p>Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the component override system transpiles user-supplied TSX via Sucrase and evaluates it with new Function, shadowing dangerous globals (fetch, window, eval, etc.) with undefined. A static source validator (validateComponentOverrideSource) additionally blocks these identifiers by word-boundary regex. Both controls are bypassed. Stri…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-693</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44451">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43982 – Algernon is a small self-contained pure-Go web server. Prior to 1.17.6, uploaded...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43982</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43982</guid>
    <pubDate>Tue, 26 May 2026 17:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43982</strong></p>
  <p>Algernon is a small self-contained pure-Go web server. Prior to 1.17.6, uploadedFileSaveIn() in lua/upload/upload.go uses filepath.Join() with the caller-supplied directory but performs no boundary check after joining. A directory of ../../../tmp resolves cleanly to /tmp, outside the web root. This vulnerability is fixed in 1.17.6.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43982">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8959 – Sandbox escape due to incorrect boundary conditions in the Widget: Win32 compone...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8959</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8959</guid>
    <pubDate>Tue, 19 May 2026 14:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8959</strong></p>
  <p>Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8959">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8954 – Incorrect boundary conditions, integer overflow in the Audio/Video component. Th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8954</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8954</guid>
    <pubDate>Tue, 19 May 2026 14:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8954</strong></p>
  <p>Incorrect boundary conditions, integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8954">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8946 – Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8946</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8946</guid>
    <pubDate>Tue, 19 May 2026 14:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8946</strong></p>
  <p>Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8946">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-45230 – DumbAssets through 1.0.11 contains a path traversal vulnerability in the POST /a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45230</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45230</guid>
    <pubDate>Mon, 18 May 2026 18:17:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-45230</strong></p>
  <p>DumbAssets through 1.0.11 contains a path traversal vulnerability in the POST /api/delete-file endpoint and filesToDelete array parameters that allows unauthenticated attackers to delete arbitrary files by supplying ../ sequences that bypass directory boundary validation. Attackers can exploit the optional and disabled-by-default authentication control to traverse outside the intended application…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45230">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45395 – Open WebUI is a self-hosted artificial intelligence platform designed to operate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45395</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45395</guid>
    <pubDate>Fri, 15 May 2026 21:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45395</strong></p>
  <p>Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, the tool update endpoint (POST /api/v1/tools/id/{id}/update) is missing the workspace.tools permission check that is present on the tool create endpoint. This allows a user who has been explicitly denied tool management capabilities ( and who the administrator considers untrusted for…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45395">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44647 – OneDev is a Git server with CI/CD, kanban, and packages. Prior to 15.0.2, there ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44647</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44647</guid>
    <pubDate>Thu, 14 May 2026 21:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44647</strong></p>
  <p>OneDev is a Git server with CI/CD, kanban, and packages. Prior to 15.0.2, there is behavior that breaks the expected boundary between repository-controlled LFS metadata and server-local filesystem paths. A repository object can steer raw blob reads to arbitrary local files that the server account can access. User with push permission to any repository will be able to access any server files acces…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44647">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27886 – Strapi is an open source headless content management system. Strapi versions sta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27886</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27886</guid>
    <pubDate>Thu, 14 May 2026 19:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27886</strong></p>
  <p>Strapi is an open source headless content management system. Strapi versions starting in 4.0.0 and prior to 5.37.0 did not sufficiently sanitize query parameters when filtering content via relational fields. An unauthenticated attacker could use the `where` query parameter on any publicly-accessible content-type with an `updatedBy` (or other admin-relation) field to perform a boolean-oracle attac…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27886">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42596 – Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42596</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42596</guid>
    <pubDate>Thu, 14 May 2026 16:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42596</strong></p>
  <p>Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, the default deny-lists used by Gotenberg's downloadFrom feature and webhook feature are bypassable. Because the filter is regex-based and case-sensitive, an unauthenticated attacker can supply URLs such as http://[::ffff:127.0.0.1]:... and reach loopback or private HTTP services that the default deny-list is intended to b…</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42596">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8466 – Allocation of Resources Without Limits or Throttling vulnerability in ninenines ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8466</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8466</guid>
    <pubDate>Wed, 13 May 2026 19:17:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8466</strong></p>
  <p>Allocation of Resources Without Limits or Throttling vulnerability in ninenines cowboy allows denial of service via unbounded buffer accumulation in multipart header parsing.  cowboy_req:read_part/3 in src/cowboy_req.erl accumulates incoming request bytes into a Buffer binary with no upper-bound check. When cow_multipart:parse_headers/2 returns more or {more, Buffer2}, the function reads up to Le…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8466">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41217 – A vulnerability exists in an undisclosed BIG-IP TMOS Shell (tmsh) command that m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41217</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41217</guid>
    <pubDate>Wed, 13 May 2026 16:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41217</strong></p>
  <p>A vulnerability exists in an undisclosed BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with resource administrator or administrator role to execute arbitrary system commands with higher privileges. In Appliance mode deployments, a successful exploit can allow the attacker to cross a security boundary.   Note: Software versions which have reached End of Technical Suppor…</p>
  <p><strong>CVSS:</strong> 7.9 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41217">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40061 – When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed iContro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40061</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40061</guid>
    <pubDate>Wed, 13 May 2026 16:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40061</strong></p>
  <p>When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute arbitrary system commands with higher privileges. In Appliance mode deployments, a successful exploit can allow the attacker to cross a security boundary.  Note: Softwar…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40061">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34176 – When running in Appliance mode, an authenticated remote command injection vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34176</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34176</guid>
    <pubDate>Wed, 13 May 2026 16:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34176</strong></p>
  <p>When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary.    Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34176">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32673 – A vulnerability exists in BIG-IP scripted monitors that may allow an authenticat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32673</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32673</guid>
    <pubDate>Wed, 13 May 2026 16:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32673</strong></p>
  <p>A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute arbitrary system commands with higher privileges. In appliance mode deployments, a successful exploit can allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support (EoTS) are not eva…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32673">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42854 – arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ES...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42854</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42854</guid>
    <pubDate>Tue, 12 May 2026 22:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42854</strong></p>
  <p>arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Prior to 3.3.8, the WebServer multipart form parser in arduino-esp32 allocates a Variable Length Array (VLA) on the stack whose size is derived from an attacker-controlled HTTP header field (Content-Type: multipart/form-data; boundary=...) without enforcing any length limit. Sendi…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42854">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44011 – Craft CMS is a content management system (CMS). From 4.0.0 to before 4.17.12 and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44011</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44011</guid>
    <pubDate>Tue, 12 May 2026 21:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44011</strong></p>
  <p>Craft CMS is a content management system (CMS). From 4.0.0 to before 4.17.12 and 5.9.18, Craft CMS which contains an input-handling flaw in a Yii object creation path that let any authenticated user inject malicious configuration and execute arbitrary commands on the server. The request-controlled condition field layouts data is converted into a live FieldLayout object without a Component::cleans…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-479</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44011">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42048 – Langflow is a tool for building and deploying AI-powered agents and workflows. P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42048</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42048</guid>
    <pubDate>Tue, 12 May 2026 18:17:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42048</strong></p>
  <p>Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vulnerable to Path Traversal in the Knowledge Bases API (DELETE /api/v1/knowledge_bases). This occurs because user-supplied knowledge base names are concatenated directly into file paths without proper sanitization or boundary validation. An authenticated attacker can exploit this flaw to de…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42048">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-45321 – On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45321</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45321</guid>
    <pubDate>Tue, 12 May 2026 01:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-45321</strong></p>
  <p>On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The attacker chained three known vulnerability classes — a pull_request_target "Pwn…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-506</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45321">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-43899 – DeepChat is an open-source artificial intelligence agent platform that unifies m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43899</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43899</guid>
    <pubDate>Mon, 11 May 2026 23:20:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-43899</strong></p>
  <p>DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to v1.0.4-beta.1, An incomplete mitigation for CVE-2025-55733 leaves DeepChat vulnerable to an arbitrary protocol execution bypass (RCE). While the patch correctly restricted api.openExternal() inside the renderer's preload/index.ts script, it structurally neglected to sanitize native E…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43899">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42564 – jotty·page is a self-hosted app for your checklists and notes. Prior to 1.22.0, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42564</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42564</guid>
    <pubDate>Mon, 11 May 2026 22:22:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42564</strong></p>
  <p>jotty·page is a self-hosted app for your checklists and notes. Prior to 1.22.0, an unauthenticated path traversal vulnerability exists in /api/app-icons/[filename]. The filename route parameter is joined into a filesystem path without traversal/boundary validation, allowing file reads outside data/uploads/app-icons/. This vulnerability is fixed in 1.22.0.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42564">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6664 – An integer overflow in network packet parsing code in PgBouncer before 1.25.2 by...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6664</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6664</guid>
    <pubDate>Sat, 09 May 2026 01:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6664</strong></p>
  <p>An integer overflow in network packet parsing code in PgBouncer before 1.25.2 bypasses a boundary check and can lead to a crash. An unauthenticated remote attacker can crash PgBouncer with a malformed SCRAM authentication packet.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6664">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43442 – In the Linux kernel, the following vulnerability has been resolved:

io_uring: f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43442</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43442</guid>
    <pubDate>Fri, 08 May 2026 15:16:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43442</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  io_uring: fix physical SQE bounds check for SQE_MIXED 128-byte ops  When IORING_SETUP_SQE_MIXED is used without IORING_SETUP_NO_SQARRAY, the boundary check for 128-byte SQE operations in io_init_req() validated the logical SQ head position rather than the physical SQE index.  The existing check:    !(ctx->cached_sq_head & (ctx->…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43442">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8091 – Incorrect boundary conditions in the Audio/Video: Playback component. This vulne...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8091</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8091</guid>
    <pubDate>Thu, 07 May 2026 13:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8091</strong></p>
  <p>Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, Thunderbird 140.10.1, and Firefox ESR 115.35.2.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8091">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40076 – OpenMRS Core is an open source electronic medical record system platform. In ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40076</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40076</guid>
    <pubDate>Wed, 06 May 2026 20:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40076</strong></p>
  <p>OpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earlier and versions 2.8.0 through 2.8.5, the module upload endpoint at POST `/openmrs/ws/rest/v1/module` is vulnerable to a Zip Slip path traversal attack. During automatic extraction of uploaded .omod archives in `WebModuleUtil.startModule()`, ZIP entries under web/module/ are checked only to see whe…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40076">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7875 – NanoClaw version 1.2.0 and prior contains a host/container filesystem boundary v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7875</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7875</guid>
    <pubDate>Wed, 06 May 2026 17:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7875</strong></p>
  <p>NanoClaw version 1.2.0 and prior contains a host/container filesystem boundary vulnerability in outbound attachment handling and outbox cleanup that allows a compromised or prompt-injected container to read files outside the intended outbox directory by supplying crafted messages_out.id and content.files values or creating symlinked outbox files. Attackers can exploit this vulnerability to trigge…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7875">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43233 – In the Linux kernel, the following vulnerability has been resolved:

netfilter: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43233</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43233</guid>
    <pubDate>Wed, 06 May 2026 12:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43233</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  netfilter: nf_conntrack_h323: fix OOB read in decode_choice()  In decode_choice(), the boundary check before get_len() uses the variable `len`, which is still 0 from its initialization at the top of the function:      unsigned int type, ext, len = 0;     ...     if (ext || (son->attr & OPEN)) {         BYTE_ALIGN(bs);         if…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43233">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43190 – In the Linux kernel, the following vulnerability has been resolved:

netfilter: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43190</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43190</guid>
    <pubDate>Wed, 06 May 2026 12:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43190</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  netfilter: xt_tcpmss: check remaining length before reading optlen  Quoting reporter:   In net/netfilter/xt_tcpmss.c (lines 53-68), the TCP option parser reads  op[i+1] directly without validating the remaining option length.    If the last byte of the option field is not EOL/NOP (0/1), the code attempts   to index op[i+1]. In t…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43190">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43113 – In the Linux kernel, the following vulnerability has been resolved:

wifi: wl125...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43113</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43113</guid>
    <pubDate>Wed, 06 May 2026 10:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43113</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  wifi: wl1251: validate packet IDs before indexing tx_frames  wl1251_tx_packet_cb() uses the firmware completion ID directly to index the fixed 16-entry wl->tx_frames[] array. The ID is a raw u8 from the completion block, and the callback does not currently verify that it fits the array before dereferencing it.  Reject completion…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43113">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40075 – OpenMRS Core is an open source electronic medical record system platform. In ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40075</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40075</guid>
    <pubDate>Tue, 05 May 2026 22:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40075</strong></p>
  <p>OpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earlier and versions 2.8.0 through 2.8.5, the `/openmrs/moduleResources/{moduleid}` endpoint is vulnerable to a path traversal attack. The ModuleResourcesServlet constructs a filesystem path from user-controlled input without performing path boundary validation — the getFile() method concatenates the u…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40075">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43533 – OpenClaw before 2026.4.10 contains an arbitrary file read vulnerability in QQBot...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43533</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43533</guid>
    <pubDate>Tue, 05 May 2026 12:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43533</strong></p>
  <p>OpenClaw before 2026.4.10 contains an arbitrary file read vulnerability in QQBot media tags that allows attackers to reference host-local paths outside the intended media storage boundary. Attackers can craft malicious reply text containing media tags to disclose arbitrary local files through outbound media handling.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43533">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7776 – Boundary Community Edition and Boundary Enterprise (“Boundary”) workers are vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7776</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7776</guid>
    <pubDate>Mon, 04 May 2026 22:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7776</strong></p>
  <p>Boundary Community Edition and Boundary Enterprise (“Boundary”) workers are vulnerable to a denial-of-service condition during node enrollment TLS handshakes. An attacker with network access to the worker authentication listener may open a connection and delay or withhold the client certificate during the TLS handshake, causing worker connection handling to block. This may prevent legitimate work…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7776">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42811 – In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials
...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42811</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42811</guid>
    <pubDate>Mon, 04 May 2026 17:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42811</strong></p>
  <p>In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, but a crafted namespace or table name can cause those credentials to work across the configured bucket instead.   Apache Polaris builds Google Cloud Storage downscoped credentials by creating a Credential Access Boundary (CAB) with CEL conditions that are intended to restrict acce…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42811">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43025 – In the Linux kernel, the following vulnerability has been resolved:

netfilter: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43025</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43025</guid>
    <pubDate>Fri, 01 May 2026 15:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43025</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  netfilter: ctnetlink: ignore explicit helper on new expectations  Use the existing master conntrack helper, anything else is not really supported and it just makes validation more complicated, so just ignore what helper userspace suggests for this expectation.  This was uncovered when validating CTA_EXPECT_CLASS via different he…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43025">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31707 – In the Linux kernel, the following vulnerability has been resolved:

ksmbd: vali...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31707</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31707</guid>
    <pubDate>Fri, 01 May 2026 14:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31707</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ksmbd: validate response sizes in ipc_validate_msg()  ipc_validate_msg() computes the expected message size for each response type by adding (or multiplying) attacker-controlled fields from the daemon response to a fixed struct size in unsigned int arithmetic.  Three cases can overflow:    KSMBD_EVENT_RPC_REQUEST:       msg_sz =…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31707">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-31705 – In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31705</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31705</guid>
    <pubDate>Fri, 01 May 2026 14:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-31705</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ksmbd: fix out-of-bounds write in smb2_get_ea() EA alignment  smb2_get_ea() applies 4-byte alignment padding via memset() after writing each EA entry. The bounds check on buf_free_len is performed before the value memcpy, but the alignment memset fires unconditionally afterward with no check on remaining space.  When the EA valu…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31705">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42423 – OpenClaw before 2026.4.8 contains an approval-timeout fallback mechanism that by...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42423</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42423</guid>
    <pubDate>Tue, 28 Apr 2026 19:37:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42423</strong></p>
  <p>OpenClaw before 2026.4.8 contains an approval-timeout fallback mechanism that bypasses strictInlineEval explicit-approval requirements on gateway and node exec hosts. Attackers can exploit this timeout fallback to execute inline eval commands that should require explicit user approval, circumventing the intended security boundary.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-636</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42423">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-7321 – Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7321</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7321</guid>
    <pubDate>Tue, 28 Apr 2026 15:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-7321</strong></p>
  <p>Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, and Thunderbird 140.10.1.</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7321">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7320 – Information disclosure due to incorrect boundary conditions in the Audio/Video c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7320</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7320</guid>
    <pubDate>Tue, 28 Apr 2026 15:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7320</strong></p>
  <p>Information disclosure due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Firefox ESR 115.35.1, Thunderbird 150.0.1, and Thunderbird 140.10.1.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7320">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41502 – BACnet Stack is a BACnet open source protocol stack C library for embedded syste...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41502</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41502</guid>
    <pubDate>Fri, 24 Apr 2026 20:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41502</strong></p>
  <p>BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, an off-by-one out-of-bounds read vulnerability in bacnet-stack's ReadPropertyMultiple service decoder allows unauthenticated remote attackers to read one byte past an allocated buffer boundary by sending a crafted RPM request with a truncated object identifier. The vulnerability is in rpm_decode_ob…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41502">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41433 – OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the Op...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41433</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41433</guid>
    <pubDate>Fri, 24 Apr 2026 20:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41433</strong></p>
  <p>OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From 0.4.0 to before 0.8.0, a flaw in the Java agent injection path allows a local attacker controlling a Java workload to overwrite arbitrary host files when Java injection is enabled and OBI is running with elevated privileges. The injector trusted TMPDIR from the target process and used unsafe…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41433">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31588 – In the Linux kernel, the following vulnerability has been resolved:

KVM: x86: U...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31588</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31588</guid>
    <pubDate>Fri, 24 Apr 2026 15:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31588</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  KVM: x86: Use scratch field in MMIO fragment to hold small write values  When exiting to userspace to service an emulated MMIO write, copy the to-be-written value to a scratch field in the MMIO fragment if the size of the data payload is 8 bytes or less, i.e. can fit in a single chunk, instead of pointing the fragment directly a…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31588">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6940 – radare2 prior to 6.1.4 contains a path traversal vulnerability in project deleti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6940</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6940</guid>
    <pubDate>Thu, 23 Apr 2026 21:16:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6940</strong></p>
  <p>radare2 prior to 6.1.4 contains a path traversal vulnerability in project deletion that allows local attackers to recursively delete arbitrary directories by supplying absolute paths that escape the configured dir.projects root directory. Attackers can craft absolute paths to project marker files outside the project storage boundary to cause recursive deletion of attacker-chosen directories with…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6940">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41208 – Paperclip is a Node.js server and React UI that orchestrates a team of AI agents...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41208</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41208</guid>
    <pubDate>Thu, 23 Apr 2026 02:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41208</strong></p>
  <p>Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Versions of @paperclipai/server prior to 2026.416.0 contain a privilege escalation vulnerability that allows an attacker with an Agent API key to execute arbitrary OS commands on the Paperclip server host. An attacker with an agent credential can escalate privileges from the agent runtime to the Pa…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41208">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31513 – In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31513</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31513</guid>
    <pubDate>Wed, 22 Apr 2026 14:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31513</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: L2CAP: Fix stack-out-of-bounds read in l2cap_ecred_conn_req  Syzbot reported a KASAN stack-out-of-bounds read in l2cap_build_cmd() that is triggered by a malformed Enhanced Credit Based Connection Request.  The vulnerability stems from l2cap_ecred_conn_req(). The function allocates a local stack buffer (`pdu`) designe…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31513">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6832 – Hermes WebUI contains an arbitrary file deletion vulnerability in the /api/sessi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6832</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6832</guid>
    <pubDate>Tue, 21 Apr 2026 22:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6832</strong></p>
  <p>Hermes WebUI contains an arbitrary file deletion vulnerability in the /api/session/delete endpoint that allows authenticated attackers to delete files outside the session directory by supplying an absolute path or path traversal payload in the session_id parameter. Attackers can exploit unvalidated session identifiers to construct paths that bypass the SESSION_DIR boundary and delete writable JSO…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6832">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-40887 – Vendure is an open-source headless commerce platform. Starting in version 1.7.4 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40887</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40887</guid>
    <pubDate>Tue, 21 Apr 2026 20:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-40887</strong></p>
  <p>Vendure is an open-source headless commerce platform. Starting in version 1.7.4 and prior to versions 2.3.4, 3.5.7, and 3.6.2, an unauthenticated SQL injection vulnerability exists in the Vendure Shop API. A user-controlled query string parameter is interpolated directly into a raw SQL expression without parameterization or validation, allowing an attacker to execute arbitrary SQL against the dat…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40887">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40876 – goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs contains...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40876</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40876</guid>
    <pubDate>Tue, 21 Apr 2026 20:17:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40876</strong></p>
  <p>goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs contains an SFTP root escape caused by prefix-based path validation. An authenticated SFTP user can read from and write to filesystem paths outside the configured SFTP root, which breaks the intended jail boundary and can expose or modify unrelated server files. The SFTP subsystem routes requests through sftpserver/sftpserver…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40876">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-40576 – excel-mcp-server is a Model Context Protocol server for Excel file manipulation...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40576</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40576</guid>
    <pubDate>Tue, 21 Apr 2026 17:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-40576</strong></p>
  <p>excel-mcp-server is a Model Context Protocol server for Excel file manipulation. A path traversal vulnerability exists in excel-mcp-server versions up to and including 0.1.7. When running in SSE or Streamable-HTTP transport mode (the documented way to use this server remotely), an unauthenticated attacker on the network can read, write, and overwrite arbitrary files on the host filesystem by supp…</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40576">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3298 – The method "sock_recvfrom_into()" of "asyncio.ProacterEventLoop" (Windows only) ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3298</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3298</guid>
    <pubDate>Tue, 21 Apr 2026 15:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3298</strong></p>
  <p>The method "sock_recvfrom_into()" of "asyncio.ProacterEventLoop" (Windows only) was missing a boundary check for the data buffer when using nbytes parameter. This allowed for an out-of-bounds buffer write if data was larger than the buffer size. Non-Windows platforms are not affected.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3298">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6776 – Incorrect boundary conditions in the WebRTC: Networking component. This vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6776</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6776</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6776</strong></p>
  <p>Incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6776">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6772 – Incorrect boundary conditions in the Libraries component in NSS. This vulnerabil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6772</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6772</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6772</strong></p>
  <p>Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6772">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6766 – Incorrect boundary conditions in the Libraries component in NSS. This vulnerabil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6766</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6766</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6766</strong></p>
  <p>Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6766">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6753 – Incorrect boundary conditions in the WebRTC component. This vulnerability was fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6753</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6753</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6753</strong></p>
  <p>Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6753">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6752 – Incorrect boundary conditions in the WebRTC component. This vulnerability was fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6752</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6752</guid>
    <pubDate>Tue, 21 Apr 2026 13:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6752</strong></p>
  <p>Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6752">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41295 – OpenClaw before 2026.4.2 contains an improper trust boundary vulnerability allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41295</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41295</guid>
    <pubDate>Tue, 21 Apr 2026 00:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41295</strong></p>
  <p>OpenClaw before 2026.4.2 contains an improper trust boundary vulnerability allowing untrusted workspace channel shadows to execute during built-in channel setup and login. Attackers can clone a workspace with a malicious plugin claiming a bundled channel id to achieve unintended in-process code execution before the plugin is explicitly trusted.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-829</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41295">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-29646 – In OpenXiangShan NEMU prior to 55295c4, when running with RVH (Hypervisor extens...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29646</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29646</guid>
    <pubDate>Mon, 20 Apr 2026 21:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-29646</strong></p>
  <p>In OpenXiangShan NEMU prior to 55295c4, when running with RVH (Hypervisor extension) enabled, a VS-mode guest write to the supervisor interrupt-enable CSR (sie) may be handled incorrectly and can influence machine-level interrupt enable state (mie). This breaks privilege/virtualization isolation and can lead to denial of service or privilege-boundary violation in environments relying on NEMU for…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-267</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29646">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5478 – The Everest Forms plugin for WordPress is vulnerable to Arbitrary File Read and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5478</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5478</guid>
    <pubDate>Mon, 20 Apr 2026 20:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5478</strong></p>
  <p>The Everest Forms plugin for WordPress is vulnerable to Arbitrary File Read and Deletion in all versions up to, and including, 3.4.4. This is due to the plugin trusting attacker-controlled old_files data from public form submissions as legitimate server-side upload state, and converting attacker-supplied URLs into local filesystem paths using regex-based string replacement without canonicalizatio…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5478">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5710 – The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5710</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5710</guid>
    <pubDate>Fri, 17 Apr 2026 18:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5710</strong></p>
  <p>The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Path Traversal leading to Arbitrary File Read in versions up to and including 1.3.9.6. This is due to the plugin using client-supplied mfile[] POST values as the source of truth for email attachment selection without performing any server-side upload provenance check, path canonicalization, or director…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5710">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40318 – SiYuan is an open-source personal knowledge management system. In versions 3.6.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40318</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40318</guid>
    <pubDate>Thu, 16 Apr 2026 23:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40318</strong></p>
  <p>SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and prior, the /api/av/removeUnusedAttributeView endpoint constructs a filesystem path using the user-controlled id parameter without validation or path boundary enforcement. An attacker can inject path traversal sequences such as ../ into the id value to escape the intended directory and delete arbitrary .json files…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-24</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40318">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40170 – ngtcp2 is a C implementation of the IETF QUIC protocol. In versions prior to 1.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40170</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40170</guid>
    <pubDate>Thu, 16 Apr 2026 22:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40170</strong></p>
  <p>ngtcp2 is a C implementation of the IETF QUIC protocol. In versions prior to 1.22.1, ngtcp2_qlog_parameters_set_transport_params() serializes peer transport parameters into a fixed 1024-byte stack buffer without bounds checking. When qlog is enabled, a remote peer can send sufficiently large transport parameters during the QUIC handshake to cause writes beyond the buffer boundary, resulting in a…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40170">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39884 – mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39884</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39884</guid>
    <pubDate>Wed, 15 Apr 2026 04:17:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39884</strong></p>
  <p>mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Versions 3.4.0 and prior contain an argument injection vulnerability in the port_forward tool in src/tools/port_forward.ts, where a kubectl command is constructed via string concatenation with user-controlled input and then naively split on spaces before being passed to spawn(). Unlike all other tools in t…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-88</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39884">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40156 – PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI automatical...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40156</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40156</guid>
    <pubDate>Fri, 10 Apr 2026 17:17:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40156</strong></p>
  <p>PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI automatically loads a file named tools.py from the current working directory to discover and register custom agent tools. This loading process uses importlib.util.spec_from_file_location and immediately executes module-level code via spec.loader.exec_module() without explicit user consent, validation, or sandboxing. The tools.py…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40156">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35669 – OpenClaw before 2026.3.25 contains a privilege escalation vulnerability in gatew...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35669</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35669</guid>
    <pubDate>Fri, 10 Apr 2026 17:17:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35669</strong></p>
  <p>OpenClaw before 2026.3.25 contains a privilege escalation vulnerability in gateway-authenticated plugin HTTP routes that incorrectly mint operator.admin runtime scope regardless of caller-granted scopes. Attackers can exploit this scope boundary bypass to gain elevated privileges and perform unauthorized administrative actions.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-648</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35669">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-5503 – In TLSX_EchChangeSNI, the ctx-&gt;extensions branch set extensions unconditionally ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5503</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5503</guid>
    <pubDate>Thu, 09 Apr 2026 23:17:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-5503</strong></p>
  <p>In TLSX_EchChangeSNI, the ctx->extensions branch set extensions unconditionally even when TLSX_Find returned NULL. This caused TLSX_UseSNI to attach the attacker-controlled publicName to the shared WOLFSSL_CTX when no inner SNI was configured. TLSX_EchRestoreSNI then failed to clean it up because its removal was gated on serverNameX != NULL. The inner ClientHello was sized before the pollution bu…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5503">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39859 – LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39859</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39859</guid>
    <pubDate>Wed, 08 Apr 2026 20:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39859</strong></p>
  <p>LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.3, liquidjs 10.25.0 documents root as constraining filenames passed to renderFile() and parseFile(), but top-level file loads do not enforce that boundary. A Liquid instance configured with an empty temporary directory as root can return the contents of arbitrary files. This vulnerability is fixed i…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39859">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-31789 – Issue summary: Converting an excessively large OCTET STRING value to
a hexadecim...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31789</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31789</guid>
    <pubDate>Tue, 07 Apr 2026 22:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-31789</strong></p>
  <p>Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms.  Impact summary: A heap buffer overflow may lead to a crash or possibly an attacker controlled code execution or other undefined behavior.  If an attacker can supply a crafted X.509 certificate with an excessively large OCTET STRING value in extensions suc…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31789">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28390 – Issue summary: During processing of a crafted CMS EnvelopedData message
with Key...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28390</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28390</guid>
    <pubDate>Tue, 07 Apr 2026 22:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28390</strong></p>
  <p>Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen.  Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service.  When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP enc…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28390">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28389 – Issue summary: During processing of a crafted CMS EnvelopedData message
with Key...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28389</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28389</guid>
    <pubDate>Tue, 07 Apr 2026 22:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28389</strong></p>
  <p>Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen.  Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service.  When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optiona…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28389">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28388 – Issue summary: When a delta CRL that contains a Delta CRL Indicator extension
is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28388</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28388</guid>
    <pubDate>Tue, 07 Apr 2026 22:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28388</strong></p>
  <p>Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing.  Impact summary: A NULL pointer dereference can trigger a crash which leads to a Denial of Service for an application.  When CRL processing and delta CRL processing is enabled during X.509 certificate verification, the…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28388">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28387 – Issue summary: An uncommon configuration of clients performing DANE TLSA-based
s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28387</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28387</guid>
    <pubDate>Tue, 07 Apr 2026 22:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28387</strong></p>
  <p>Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side.  Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of arbitrary code.  However, the issue…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28387">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28386 – Issue summary: Applications using AES-CFB128 encryption or decryption on
systems...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28386</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28386</guid>
    <pubDate>Tue, 07 Apr 2026 22:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28386</strong></p>
  <p>Issue summary: Applications using AES-CFB128 encryption or decryption on systems with AVX-512 and VAES support can trigger an out-of-bounds read of up to 15 bytes when processing partial cipher blocks.  Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application if the input buffer ends at a memory page boundary and the following page is unmappe…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28386">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5733 – Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerabil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5733</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5733</guid>
    <pubDate>Tue, 07 Apr 2026 13:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5733</strong></p>
  <p>Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 149.0.2 and Thunderbird 149.0.2.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5733">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5732 – Incorrect boundary conditions, integer overflow in the Graphics: Text component...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5732</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5732</guid>
    <pubDate>Tue, 07 Apr 2026 13:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5732</strong></p>
  <p>Incorrect boundary conditions, integer overflow in the Graphics: Text component. This vulnerability was fixed in Firefox 149.0.2, Firefox ESR 140.9.1, Thunderbird 149.0.2, and Thunderbird 140.9.1.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5732">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23457 – In the Linux kernel, the following vulnerability has been resolved:

netfilter: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23457</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23457</guid>
    <pubDate>Fri, 03 Apr 2026 16:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23457</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  netfilter: nf_conntrack_sip: fix Content-Length u32 truncation in sip_help_tcp()  sip_help_tcp() parses the SIP Content-Length header with simple_strtoul(), which returns unsigned long, but stores the result in unsigned int clen.  On 64-bit systems, values exceeding UINT_MAX are silently truncated before computing the SIP messag…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23457">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23456 – In the Linux kernel, the following vulnerability has been resolved:

netfilter: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23456</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23456</guid>
    <pubDate>Fri, 03 Apr 2026 16:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23456</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  netfilter: nf_conntrack_h323: fix OOB read in decode_int() CONS case  In decode_int(), the CONS case calls get_bits(bs, 2) to read a length value, then calls get_uint(bs, len) without checking that len bytes remain in the buffer. The existing boundary check only validates the 2 bits for get_bits(), not the subsequent 1-4 bytes t…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23456">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32145 – Allocation of Resources Without Limits or Throttling vulnerability in gleam-wisp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32145</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32145</guid>
    <pubDate>Thu, 02 Apr 2026 11:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32145</strong></p>
  <p>Allocation of Resources Without Limits or Throttling vulnerability in gleam-wisp wisp allows a denial of service via multipart form body parsing.  The multipart_body function bypasses configured max_body_size and max_files_size limits. When a multipart boundary is not present in a chunk, the parser takes the MoreRequiredForBody path, which appends the chunk to the output but passes the quota unch…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32145">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34430 – ByteDance DeerFlow versions prior to commit 92c7a20 contain a sandbox escape vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34430</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34430</guid>
    <pubDate>Wed, 01 Apr 2026 14:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34430</strong></p>
  <p>ByteDance DeerFlow versions prior to commit 92c7a20 contain a sandbox escape vulnerability in bash tool handling that allows attackers to execute arbitrary commands on the host system by bypassing regex-based validation using shell features such as directory changes and relative paths. Attackers can exploit the incomplete shell semantics modeling to read and modify files outside the sandbox bound…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-184</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34430">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23406 – In the Linux kernel, the following vulnerability has been resolved:

apparmor: f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23406</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23406</guid>
    <pubDate>Wed, 01 Apr 2026 09:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23406</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  apparmor: fix side-effect bug in match_char() macro usage  The match_char() macro evaluates its character parameter multiple times when traversing differential encoding chains. When invoked with *str++, the string pointer advances on each iteration of the inner do-while loop, causing the DFA to check different characters at each…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23406">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32726 – SciTokens C++ is a minimal library for creating and using SciTokens from C or C+...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32726</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32726</guid>
    <pubDate>Tue, 31 Mar 2026 18:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32726</strong></p>
  <p>SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior to version 1.4.1, scitokens-cpp is vulnerable to an authorization bypass in path-based scope validation. The enforcer used a simple string-prefix comparison when checking whether a requested resource path was covered by a token's authorized scope path. Because the check did not require a path-segment boundary…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32726">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34359 – HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34359</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34359</guid>
    <pubDate>Tue, 31 Mar 2026 17:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34359</strong></p>
  <p>HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, ManagedWebAccessUtils.getServer() uses String.startsWith() to match request URLs against configured server URLs for authentication credential dispatch. Because configured server URLs (e.g., http://tx.fhir.org) lack a trailing slash or host boundary check, an attacker-co…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-346</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34359">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32988 – OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in fs...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32988</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32988</guid>
    <pubDate>Tue, 31 Mar 2026 12:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32988</strong></p>
  <p>OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in fs-bridge staged writes where temporary file creation and population are not pinned to a verified parent directory. Attackers can exploit a race condition in parent-path alias changes to write attacker-controlled bytes outside the intended validated path before the final guarded replace step executes.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32988">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33573 – OpenClaw before 2026.3.11 contains an authorization bypass vulnerability in the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33573</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33573</guid>
    <pubDate>Sun, 29 Mar 2026 13:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33573</strong></p>
  <p>OpenClaw before 2026.3.11 contains an authorization bypass vulnerability in the gateway agent RPC that allows authenticated operators with operator.write permission to override workspace boundaries by supplying attacker-controlled spawnedBy and workspaceDir values. Remote operators can escape the configured workspace boundary and execute arbitrary file and exec operations from any process-accessi…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33573">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
