<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Go (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/go.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/go-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Go (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:29 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-37462 – An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/bgp.go) of ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-37462</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-37462</guid>
    <pubDate>Wed, 03 Jun 2026 16:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-37462</strong></p>
  <p>An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-37462">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10617 – A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10617</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10617</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10617</strong></p>
  <p>A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.11.3. This affects the function resolveAuth of the file internal/http/auth.go of the component Webhook Verification Handler. The manipulation leads to missing authentication. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The project tagged the reported issue as b…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10617">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10219 – A vulnerability was found in nextlevelbuilder GoClaw up to 3.11.3. This impacts ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10219</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10219</guid>
    <pubDate>Mon, 01 Jun 2026 04:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10219</strong></p>
  <p>A vulnerability was found in nextlevelbuilder GoClaw up to 3.11.3. This impacts the function FsBridge.WriteFile of the file internal/sandbox/fsbridge.go of the component write_file Tool. Performing a manipulation results in os command injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The pull request to fix this issue awaits acceptan…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10219">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46385 – iskorotkov/avro is a fast Go Avro codec. Prior to 2.33.0, the Avro array and map...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46385</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46385</guid>
    <pubDate>Fri, 29 May 2026 20:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46385</strong></p>
  <p>iskorotkov/avro is a fast Go Avro codec. Prior to 2.33.0, the Avro array and map decoders looped over an attacker-controlled block-count value without checking the underlying reader's error state inside the loop body. Reader.ReadBlockHeader returns the count as a Go int, which is 64-bit on amd64 / arm64 targets — so a producer can declare a block of up to math.MaxInt64 (~9.2 × 10¹⁸) elements foll…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46385">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46384 – iskorotkov/avro is a fast Go Avro codec. Prior to 2.33.0, several Avro decoder p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46384</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46384</guid>
    <pubDate>Fri, 29 May 2026 20:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46384</strong></p>
  <p>iskorotkov/avro is a fast Go Avro codec. Prior to 2.33.0, several Avro decoder paths read attacker-controlled 64-bit values from the wire format and either narrowed them to platform-sized int before bounds-checking, or summed them with overflow-prone signed-int arithmetic. On 32-bit targets (GOARCH=386, arm, mips, wasm, etc.), the truncation paths can silently bypass byte-slice limits, select the…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46384">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44697 – Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44697</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44697</guid>
    <pubDate>Fri, 29 May 2026 18:17:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44697</strong></p>
  <p>Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, a remote, unauthenticated denial-of-service vulnerability in Batch.Decompress (data/batch/batch.go) allows any peer that participates in a topic served by MultiDataInterceptor to allocate multi-gigabyte heaps on the receiving node from a sub-50 KiB gossip payload. A single packet is sufficient to OOM-kill a val…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-409</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44697">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48501 – GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.93.0, GitHub ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48501</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48501</guid>
    <pubDate>Fri, 29 May 2026 16:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48501</strong></p>
  <p>GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.93.0, GitHub CLI incorrectly includes authorization header in API requests to TUF repository mirrors via gh attestation, gh release verify, and gh release verify-asset commands. The CLI uses a shared HTTP client with an authentication layer that automatically attaches tokens to outgoing requests. This layer lacks accurate host det…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48501">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44973 – Billy is an interface filesystem abstraction for Go. Prior to 5.9.0, multiple pa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44973</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44973</guid>
    <pubDate>Thu, 28 May 2026 22:16:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44973</strong></p>
  <p>Billy is an interface filesystem abstraction for Go. Prior to 5.9.0, multiple path traversal issues exist across different components of go-billy. Insufficient path sanitization and boundary enforcement may allow crafted paths (e.g., using ..) to escape intended base directories. While go-billy was not originally designed to provide a strong security boundary, some of these issues were inconsiste…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44973">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-44881 – Portainer Community Edition is a lightweight service delivery platform for conta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44881</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44881</guid>
    <pubDate>Thu, 28 May 2026 22:16:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-44881</strong></p>
  <p>Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and 2.41.0, Portainer supports deploying stacks from Git repositories. When a Git-backed stack is created or updated, Portainer clones the repository using go-git v5, which translates…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44881">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9098 – In Casdoor versions 2.362.0 and earlier, the SAML callback handler in controller...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9098</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9098</guid>
    <pubDate>Thu, 28 May 2026 17:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9098</strong></p>
  <p>In Casdoor versions 2.362.0 and earlier, the SAML callback handler in controllers/auth.go accepts any well-formed SAMLResponse sent to /api/acs without verifying that it corresponds to an AuthnRequest previously issued by Casdoor. Additionally, if an administrator disables or deletes an IdP (Identity Provider) after a SAML flow has started, the handler still processes the response using the provi…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9098">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9097 – Casdoor versions 2.362.0 and earlier do not verify that a JWT used for token exc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9097</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9097</guid>
    <pubDate>Thu, 28 May 2026 17:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9097</strong></p>
  <p>Casdoor versions 2.362.0 and earlier do not verify that a JWT used for token exchange is still active. The GetTokenExchangeToken() function in object/token_oauth.go validates the JWT signature and parses its claims, but never queries the Token table to verify whether the subject token has been revoked or invalidated. Because the revocation check is entirely absent, administrators are unable to te…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9097">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9095 – Casdoor versions 2.362.0 and earlier map SAML assertions to user sessions withou...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9095</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9095</guid>
    <pubDate>Thu, 28 May 2026 17:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9095</strong></p>
  <p>Casdoor versions 2.362.0 and earlier map SAML assertions to user sessions without replay protection. The ParseSamlResponse() function in object/saml_sp.go calls sp.RetrieveAssertionInfo() and immediately maps the result to a user session. There is no assertion ID cache, OneTimeUse condition enforcement, or replay detection anywhere in the SAML SP code path. As a result, an attacker can replay a p…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-294</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9095">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9094 – Casdoor versions 2.362.0 and earlier contain a vulnerability enabling cross-orga...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9094</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9094</guid>
    <pubDate>Thu, 28 May 2026 17:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9094</strong></p>
  <p>Casdoor versions 2.362.0 and earlier contain a vulnerability enabling cross-organization token exchange. The GetTokenExchangeToken function in object/token_oauth.go validates JWT signatures but does not verify that the token's user belongs to the same organization as the target application. This can result in privilege escalation across organizational boundaries.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9094">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9093 – In Casdoor versions 2.362.0 and earlier, the SAML service provider implementatio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9093</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9093</guid>
    <pubDate>Thu, 28 May 2026 17:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9093</strong></p>
  <p>In Casdoor versions 2.362.0 and earlier, the SAML service provider implementation does not validate the AudienceRestriction element in SAML assertions. The buildSp function in object/saml_sp.go never sets AudienceURI on the gosaml2 SAMLServiceProvider struct and never inspects WarningInfo.NotInAudience. This allows assertions issued for other service providers to be accepted by Casdoor.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9093">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46117 – In the Linux kernel, the following vulnerability has been resolved:

RDMA/mana: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46117</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46117</guid>
    <pubDate>Thu, 28 May 2026 10:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46117</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss()  Sashiko points out that the user can specify WQs sharing the same CQ as a part of the uAPI and this will trigger the WARN_ON() then go on to corrupt the kernel.  Just reject it outright and fail the QP creation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46117">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45090 – Dalfox is a powerful open-source XSS scanner and utility focused on automation. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45090</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45090</guid>
    <pubDate>Wed, 27 May 2026 18:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45090</strong></p>
  <p>Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, ParameterAnalysis in pkg/scanning/parameterAnalysis.go runs two sequential worker stages that both write to the same results channel. The channel is correctly closed after the first stage completes (close(results) at line 438), but the second stage — which processes POST-body parameters (dp) — is then…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45090">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45047 – bird-lg-go is a BIRD looking glass in Go. Prior to 1.4.5, the apiHandler (and si...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45047</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45047</guid>
    <pubDate>Wed, 27 May 2026 18:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45047</strong></p>
  <p>bird-lg-go is a BIRD looking glass in Go. Prior to 1.4.5, the apiHandler (and similarly webHandlerTelegramBot) processes user-provided JSON payloads by directly using json.NewDecoder(r.Body).Decode(&request) without restricting the maximum read size. An unauthenticated remote attacker can stream an extremely large, endless JSON payload (e.g., several Gigabytes of padding) over a single TCP connec…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45047">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44325 – free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44325</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44325</guid>
    <pubDate>Wed, 27 May 2026 17:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44325</strong></p>
  <p>free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NRF root SBI endpoint POST /oauth2/token contains a parser-level type-confusion bug family. The handler in NFs/nrf/internal/sbi/api_accesstoken.go reflects over models.NrfAccessTokenAccessTokenReq, special-cases only plain string and NrfNfManagementNfType fields, and treats every other field as if it were a…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44325">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44319 – free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44319</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44319</guid>
    <pubDate>Wed, 27 May 2026 17:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44319</strong></p>
  <p>free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF terminates the entire process when a stored PFD-subscription notifyUri cannot be reached. In PfdChangeNotifier.FlushNotifications(), the notifier calls NnefPFDmanagementNotify(...) and on any delivery error invokes logger.PFDManageLog.Fatal(err), which is os.Exit(1)-equivalent in Go. An attacker who can…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44319">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45022 – go-git is an extensible git implementation library written in pure Go. Prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45022</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45022</guid>
    <pubDate>Wed, 27 May 2026 15:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45022</strong></p>
  <p>go-git is an extensible git implementation library written in pure Go. Prior to 5.19.0 and 6.0.0-alpha.3, go-git may parse malformed Git objects in a way that differs from upstream Git. When commit or tag objects contain ambiguous or malformed headers, go-git’s decoded representation may expose values differently from how Git itself would interpret or reject the same object. Additionally, go-git’…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-180</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45022">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46076 – In the Linux kernel, the following vulnerability has been resolved:

KVM: nSVM: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46076</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46076</guid>
    <pubDate>Wed, 27 May 2026 14:17:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46076</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1  Explicitly synthesize a #UD for VMMCALL if L2 is active, L1 does NOT want to intercept VMMCALL, nested_svm_l2_tlb_flush_enabled() is true, and the hypercall is something other than one of the supported Hyper-V hypercalls. When all of the above conditions are met,…</p>
  <p><strong>CVSS:</strong> 7.9 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46076">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-36045 – picoclaw &lt;=v0.1.2 and earlier is vulnerable to OS command injection via the Exec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-36045</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-36045</guid>
    <pubDate>Wed, 27 May 2026 14:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-36045</strong></p>
  <p>picoclaw <=v0.1.2 and earlier is vulnerable to OS command injection via the ExecTool component (pkg/tools/shell.go). The guardCommand() function attempts to restrict shell command execution using a denylist of 8 regular expressions, but the denylist is incomplete.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-36045">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48126 – Algernon is a small self-contained pure-Go web server. Prior to 1.17.8, when alg...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48126</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48126</guid>
    <pubDate>Tue, 26 May 2026 17:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48126</strong></p>
  <p>Algernon is a small self-contained pure-Go web server. Prior to 1.17.8, when algernon is started with --domain (or --letsencrypt, which silently turns on --domain at engine/flags.go:372), the request handler resolves the served directory by joining the configured --dir with the value of the client-supplied Host header. The join is performed by filepath.Join with no validation, so a Host: .. heade…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48126">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45728 – Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Alg...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45728</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45728</guid>
    <pubDate>Tue, 26 May 2026 17:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45728</strong></p>
  <p>Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is invoked with a single file path instead of a directory, singleFileMode is set to true and debugMode is forcibly enabled. debugMode activates the PrettyError renderer, which on any Lua or template error response dumps the absolute path of the file that errored, complete byte contents of that file, and exceptio…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-209</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45728">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-45721 – Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Alg...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45721</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45721</guid>
    <pubDate>Tue, 26 May 2026 17:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-45721</strong></p>
  <p>Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is asked for any URL path that resolves to a directory without an index file, DirPage walks upward through parent directories — past the configured server root — looking for a file named handler.lua to execute as the request handler. The loop terminates only after 100 ancestor steps or when filepath.Dir returns…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45721">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43982 – Algernon is a small self-contained pure-Go web server. Prior to 1.17.6, uploaded...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43982</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43982</guid>
    <pubDate>Tue, 26 May 2026 17:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43982</strong></p>
  <p>Algernon is a small self-contained pure-Go web server. Prior to 1.17.6, uploadedFileSaveIn() in lua/upload/upload.go uses filepath.Join() with the caller-supplied directory but performs no boundary check after joining. A directory of ../../../tmp resolves cleanly to /tmp, outside the web root. This vulnerability is fixed in 1.17.6.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43982">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43981 – Algernon is a small self-contained pure-Go web server. Prior to 1.17.6, in engin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43981</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43981</guid>
    <pubDate>Tue, 26 May 2026 17:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43981</strong></p>
  <p>Algernon is a small self-contained pure-Go web server. Prior to 1.17.6, in engine/luahandler.go, the sync.RWMutex protecting LoadCommonFunctions is released before L.Push() and L.PCall() execute. Since gopher-lua's LState is explicitly not goroutine-safe, concurrent requests race on the shared state causing Lua VM corruption. The Go race detector confirms this immediately under modest concurrency…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43981">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-47358 – Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF)...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47358</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47358</guid>
    <pubDate>Tue, 19 May 2026 17:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-47358</strong></p>
  <p>Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in uploaded IaC templates when running in server mode. When Terrascan parses uploaded ARM templates or CloudFormation templates, it resolves external URLs referenced within those templates via hashicorp/go-getter with all default detectors enabled, including FileDetector. An unauthenticate…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47358">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-47357 – Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF)...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47357</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47357</guid>
    <pubDate>Tue, 19 May 2026 17:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-47357</strong></p>
  <p>Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in the remote directory scan endpoint (POST /v1/{iac}/{iacVersion}/{cloud}/remote/dir/scan) when running in server mode. An unauthenticated remote attacker can supply an attacker-controlled HTTP URL as remote_url with remote_type set to "http". The URL is passed directly to hashicorp/go-g…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47357">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44567 – Open WebUI is a self-hosted artificial intelligence platform designed to operate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44567</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44567</guid>
    <pubDate>Fri, 15 May 2026 22:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44567</strong></p>
  <p>Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.1.124, the API does not properly validate that the user has an authorized user role of user. By default, when Open WebUI is configured with new sign-ups enabled, the default user role is set to pending. In this configuration, an administrator is required to go into the Admin management pa…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-602</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44567">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-45375 – SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45375</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45375</guid>
    <pubDate>Thu, 14 May 2026 19:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-45375</strong></p>
  <p>SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan's Bazaar (community marketplace) renders the name and version fields of a package's plugin.json (and the equivalent theme.json / template.json / widget.json / icon.json) into the Settings → Marketplace UI without HTML escaping. The kernel-side helper sanitizePackageDisplayStrings in kernel/bazaar/package.go HTML…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45375">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44522 – Note Mark is an open-source note-taking application. From 0.13.0 to before 0.19...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44522</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44522</guid>
    <pubDate>Thu, 14 May 2026 19:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44522</strong></p>
  <p>Note Mark is an open-source note-taking application. From 0.13.0 to before 0.19.4, the Note Mark application allows authenticated users to upload assets to notes via POST /api/notes/{noteID}/assets, where the asset filename is provided through the X-Name HTTP request header. This value is stored directly in the database without any sanitization or validation - no path separator filtering, no dire…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44522">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42589 – Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gote...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42589</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42589</guid>
    <pubDate>Thu, 14 May 2026 16:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42589</strong></p>
  <p>Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg's /forms/pdfengines/metadata/write HTTP endpoint accepts a JSON metadata object and passes its keys directly to ExifTool via the go-exiftool library. No validation is performed on key characters. A \n embedded in a JSON key splits the ExifTool stdin stream into a new argument line, allowing an attacker to inject…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42589">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44166 – Pocketbase is an open source web backend written in go. Prior to 0.22.42 and 0.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44166</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44166</guid>
    <pubDate>Tue, 12 May 2026 18:17:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44166</strong></p>
  <p>Pocketbase is an open source web backend written in go. Prior to 0.22.42 and 0.37.4, in some situations, if an attacker knows the email address of the victim they can create and link an unverified PocketBase user in advance by authenticating with one of the OAuth2 app providers, e.g. "A". When the victim gets invited or decides to sign up to your app on their own with provider "B" (PocketBase OAu…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44166">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43983 – Pocket ID is an OIDC provider that allows users to authenticate with their passk...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43983</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43983</guid>
    <pubDate>Tue, 12 May 2026 15:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43983</strong></p>
  <p>Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.6.0, The createTokenFromRefreshToken function (oidc_service.go) validates the refresh token's cryptographic integrity but does not re-validate the user's current authorization state before issuing new tokens. This allows (1) the client to refresh the token indefinitely after authorizat…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43983">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42882 – oxyno-zeta/s3-proxy is an aws s3 proxy written in go. Prior to 5.0.0, s3-proxy c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42882</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42882</guid>
    <pubDate>Mon, 11 May 2026 20:25:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42882</strong></p>
  <p>oxyno-zeta/s3-proxy is an aws s3 proxy written in go. Prior to 5.0.0, s3-proxy contains an authentication bypass caused by inconsistent URL path interpretation between the authentication middleware and the bucket handler. The authentication middleware evaluates resource path patterns against the percent-encoded request URI (r.URL.RequestURI()), while the bucket handler constructs S3 object keys f…</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42882">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42297 – Argo Workflows is an open source container-native workflow engine for orchestrat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42297</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42297</guid>
    <pubDate>Sat, 09 May 2026 04:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42297</strong></p>
  <p>Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From version 4.0.0 to before version 4.0.5, the Sync Service's ConfigMap-backed provider (server/sync/sync_cm.go) performs zero authorization checks on all CRUD operations (create, read, update, delete). Any authenticated user — including those using fake Bearer tokens — can create, re…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42297">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-41889 – pgx is a PostgreSQL driver and toolkit for Go. Prior to version 5.9.2, SQL injec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41889</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41889</guid>
    <pubDate>Fri, 08 May 2026 17:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-41889</strong></p>
  <p>pgx is a PostgreSQL driver and toolkit for Go. Prior to version 5.9.2, SQL injection can occur when the non-default simple protocol is used, a dollar quoted string literal is used in the SQL query, that string literal contains text that would be would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker. This issue has been…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41889">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43328 – In the Linux kernel, the following vulnerability has been resolved:

cpufreq: go...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43328</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43328</guid>
    <pubDate>Fri, 08 May 2026 14:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43328</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  cpufreq: governor: fix double free in cpufreq_dbs_governor_init() error path  When kobject_init_and_add() fails, cpufreq_dbs_governor_init() calls kobject_put(&dbs_data->attr_set.kobj).  The kobject release callback cpufreq_dbs_data_release() calls gov->exit(dbs_data) and kfree(dbs_data), but the current error path then calls go…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-415</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43328">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42501 – A malicious module proxy can exploit a flaw in the go command's validation of mo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42501</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42501</guid>
    <pubDate>Thu, 07 May 2026 20:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42501</strong></p>
  <p>A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum database validation. This vulnerability affects any user using an untrusted module proxy (GOMODPROXY) or checksum database (GOSUMDB). A malicious module proxy can serve altered versions of the Go toolchain. When selecting a different version of the Go toolchain than the currently inst…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-347</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42501">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44349 – Daptin is a GraphQL/JSON-API headless CMS. Prior to version 0.11.5, processFuzzy...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44349</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44349</guid>
    <pubDate>Thu, 07 May 2026 15:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44349</strong></p>
  <p>Daptin is a GraphQL/JSON-API headless CMS. Prior to version 0.11.5, processFuzzySearch in server/resource/resource_findallpaginated.go:1484 splits the user-supplied column parameter by comma and interpolates each segment directly into goqu.L(fmt.Sprintf("LOWER(%s) LIKE ?", prefix+col)) raw SQL with no column whitelist check. The entry point is GET /api/<entity> with operator=fuzzy (or fuzzy_any,…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44349">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42285 – GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42285</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42285</guid>
    <pubDate>Thu, 07 May 2026 12:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42285</strong></p>
  <p>GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. In version 4.4.0, an unauthenticated remote BGP peer can trigger a fatal panic in GoBGP by sending a specially crafted BGP UPDATE message. When the server receives a message with inconsistent attribute lengths, it improperly handles the internal state transition to a "withdraw" action, leading to…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42285">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41643 – GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41643</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41643</guid>
    <pubDate>Thu, 07 May 2026 12:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41643</strong></p>
  <p>GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Prior to version 4.3.0, a remote Denial of Service (DoS) vulnerability exists in GoBGP where a malformed BGP UPDATE message can trigger a runtime error: index out of range panic. This occurs during the processing of 4-byte AS attributes when the message structure causes an internal slice index shi…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-129</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41643">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41642 – GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41642</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41642</guid>
    <pubDate>Thu, 07 May 2026 12:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41642</strong></p>
  <p>GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. In version 4.3.0, a remote Denial of Service (DoS) vulnerability exists in GoBGP due to a nil pointer dereference. When a malformed BGP UPDATE message contains an unrecognized Path Attribute marked as "Well-known," the daemon fails to interrupt the message handling flow. This results in an illegal…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41642">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43226 – In the Linux kernel, the following vulnerability has been resolved:

net/rds: No...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43226</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43226</guid>
    <pubDate>Wed, 06 May 2026 12:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43226</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  net/rds: No shortcut out of RDS_CONN_ERROR  RDS connections carry a state "rds_conn_path::cp_state" and transitions from one state to another and are conditional upon an expected state: "rds_conn_path_transition."  There is one exception to this conditionality, which is "RDS_CONN_ERROR" that can be enforced by "rds_conn_path_dro…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43226">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43116 – In the Linux kernel, the following vulnerability has been resolved:

netfilter: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43116</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43116</guid>
    <pubDate>Wed, 06 May 2026 10:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43116</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  netfilter: ctnetlink: ensure safe access to master conntrack  Holding reference on the expectation is not sufficient, the master conntrack object can just go away, making exp->master invalid.  To access exp->master safely:  - Grab the nf_conntrack_expect_lock, this gets serialized with   clean_from_lists() which also holds this…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43116">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39383 – Gotenberg is an API-based document conversion tool. In version 8.29.1, an unauth...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39383</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39383</guid>
    <pubDate>Tue, 05 May 2026 21:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39383</strong></p>
  <p>Gotenberg is an API-based document conversion tool. In version 8.29.1, an unauthenticated attacker with network access can force the server to make outbound HTTP POST requests to arbitrary internal or external destinations by supplying a crafted URL in the Gotenberg-Webhook-Url request header. The FilterDeadline function in filter.go is intended to gate outbound URLs, but when both the allow-list…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39383">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-35579 – CoreDNS is a DNS server written in Go. In versions prior to 1.14.3, the gRPC, QU...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35579</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35579</guid>
    <pubDate>Tue, 05 May 2026 21:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-35579</strong></p>
  <p>CoreDNS is a DNS server written in Go. In versions prior to 1.14.3, the gRPC, QUIC, DoH, and DoH3 transport implementations incorrectly handle TSIG authentication. For gRPC and QUIC, the server checks whether the TSIG key name exists in the configuration but never calls dns.TsigVerify() to validate the HMAC. If the key name matches a configured key, the tsigStatus field remains nil and the tsig p…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35579">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40280 – Gotenberg is an API-based document conversion tool. In versions 8.30.1 and earli...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40280</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40280</guid>
    <pubDate>Tue, 05 May 2026 20:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40280</strong></p>
  <p>Gotenberg is an API-based document conversion tool. In versions 8.30.1 and earlier, the default private-IP deny-lists for the --webhook-deny-list and --api-download-from-deny-list flags use a case-sensitive regular expression (^https?://) to match URL schemes. Because Go's net/url.Parse() normalizes the scheme to lowercase before establishing the outbound TCP connection, an attacker can bypass th…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40280">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33489 – CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the tr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33489</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33489</guid>
    <pubDate>Tue, 05 May 2026 20:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33489</strong></p>
  <p>CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the transfer plugin can select the wrong ACL stanza when both a parent zone and a more-specific subzone are configured. The longestMatch() function in plugin/transfer/transfer.go uses a lexicographic string comparison instead of an actual longest-suffix match to select the winning zone. As a result, a permissive parent-zone…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33489">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43060 – In the Linux kernel, the following vulnerability has been resolved:

netfilter: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43060</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43060</guid>
    <pubDate>Tue, 05 May 2026 16:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43060</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  netfilter: nft_ct: drop pending enqueued packets on removal  Packets sitting in nfqueue might hold a reference to:  - templates that specify the conntrack zone, because a percpu area is   used and module removal is possible. - conntrack timeout policies and helper, where object removal leave   a stale reference.  Since these obj…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43060">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-41571 – Note Mark is an open-source note-taking application. In version 0.19.2, IsPasswo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41571</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41571</guid>
    <pubDate>Mon, 04 May 2026 18:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-41571</strong></p>
  <p>Note Mark is an open-source note-taking application. In version 0.19.2, IsPasswordMatch in backend/db/models.go falls back to a hard-coded bcrypt("null") placeholder whenever a user has no stored password. OIDC-registered users are created with an empty password, so anyone who submits password: "null" to the internal login endpoint receives a valid session for that user. The bypass is unauthentic…</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41571">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-37461 – An out-of-bounds read in the ParseIP6Extended function (/bgp/bgp.go) of gobgp v4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-37461</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-37461</guid>
    <pubDate>Mon, 04 May 2026 17:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-37461</strong></p>
  <p>An out-of-bounds read in the ParseIP6Extended function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-37461">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-7482 – Ollama before 0.17.1 contains a heap out-of-bounds read vulnerability in the GGU...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7482</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7482</guid>
    <pubDate>Mon, 04 May 2026 13:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-7482</strong></p>
  <p>Ollama before 0.17.1 contains a heap out-of-bounds read vulnerability in the GGUF model loader. The /api/create endpoint accepts an attacker-supplied GGUF file in which the declared tensor offset and size exceed the file's actual length; during quantization in fs/ggml/gguf.go and server/quantization.go (WriteTo()), the server reads past the allocated heap buffer. The leaked memory contents may in…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7482">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7736 – A vulnerability was determined in osrg GoBGP up to 4.3.0. Affected by this vulne...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7736</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7736</guid>
    <pubDate>Mon, 04 May 2026 07:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7736</strong></p>
  <p>A vulnerability was determined in osrg GoBGP up to 4.3.0. Affected by this vulnerability is the function parseRibEntry of the file pkg/packet/mrt/mrt.go. Executing a manipulation can lead to integer underflow. It is possible to launch the attack remotely. Upgrading to version 4.4.0 addresses this issue. This patch is called 76d911046344a3923cbe573364197aa081944592. It is suggested to upgrade the…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-189</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7736">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7735 – A vulnerability was found in osrg GoBGP up to 4.3.0. Affected is the function Pa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7735</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7735</guid>
    <pubDate>Mon, 04 May 2026 06:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7735</strong></p>
  <p>A vulnerability was found in osrg GoBGP up to 4.3.0. Affected is the function PathAttributeAigp.DecodeFromBytes of the file pkg/packet/bgp/bgp.go of the component AIGP Attribute Parser. Performing a manipulation results in buffer overflow. It is possible to initiate the attack remotely. Upgrading to version 4.4.0 is able to address this issue. The patch is named 51ad1ada06cb41ce47b7066799981816f5…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7735">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43049 – In the Linux kernel, the following vulnerability has been resolved:

HID: logite...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43049</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43049</guid>
    <pubDate>Fri, 01 May 2026 15:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43049</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure  Presently, if the force feedback initialisation fails when probing the Logitech G920 Driving Force Racing Wheel for Xbox One, an error number will be returned and propagated before the userspace infrastructure (sysfs and /dev/input) has been to…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43049">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-38651 – Authentication Bypass vulnerability exists in Netmaker versions prior to 1.5.0. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-38651</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-38651</guid>
    <pubDate>Tue, 28 Apr 2026 16:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-38651</strong></p>
  <p>Authentication Bypass vulnerability exists in Netmaker versions prior to 1.5.0. The VerifyHostToken function in logic/jwts.go fails to validate the JWT signature when verifying host tokens. An attacker can forge a JWT signed with any arbitrary key and use it to impersonate any host in the network, gaining access to sensitive information</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-347</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-38651">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41602 – Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport G...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41602</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41602</guid>
    <pubDate>Tue, 28 Apr 2026 10:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41602</strong></p>
  <p>Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation  This issue affects Apache Thrift: before 0.23.0.  Users are recommended to upgrade to version 0.23.0, which fixes the issue.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41602">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7082 – A flaw has been found in Tenda F456 1.0.0.5. Affected by this vulnerability is t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7082</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7082</guid>
    <pubDate>Mon, 27 Apr 2026 04:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7082</strong></p>
  <p>A flaw has been found in Tenda F456 1.0.0.5. Affected by this vulnerability is the function formWrlExtraSet of the file /goform/WrlExtraSet of the component httpd. Executing a manipulation of the argument Go can lead to buffer overflow. The attack can be executed remotely. The exploit has been published and may be used.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7082">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7055 – A security vulnerability has been detected in Tenda F456 1.0.0.5. This issue aff...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7055</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7055</guid>
    <pubDate>Sun, 26 Apr 2026 22:17:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7055</strong></p>
  <p>A security vulnerability has been detected in Tenda F456 1.0.0.5. This issue affects the function fromVirtualSer of the file /goform/VirtualSer of the component httpd. The manipulation of the argument menufacturer/Go leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7055">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7035 – A vulnerability was determined in Tenda FH1202 1.2.0.14. This affects the functi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7035</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7035</guid>
    <pubDate>Sun, 26 Apr 2026 12:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7035</strong></p>
  <p>A vulnerability was determined in Tenda FH1202 1.2.0.14. This affects the function fromWrlclientSet of the file /goform/WrlclientSet of the component httpd. Executing a manipulation of the argument Go can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7035">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7034 – A vulnerability was found in Tenda FH1202 1.2.0.14(408). Affected by this issue ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7034</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7034</guid>
    <pubDate>Sun, 26 Apr 2026 12:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7034</strong></p>
  <p>A vulnerability was found in Tenda FH1202 1.2.0.14(408). Affected by this issue is the function WrlExtraSet of the file /goform/WrlExtraSet of the component httpd. Performing a manipulation of the argument Go results in stack-based buffer overflow. The attack may be initiated remotely. The exploit has been made public and could be used.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7034">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7033 – A vulnerability has been found in Tenda F456 1.0.0.5. Affected by this vulnerabi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7033</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7033</guid>
    <pubDate>Sun, 26 Apr 2026 11:16:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7033</strong></p>
  <p>A vulnerability has been found in Tenda F456 1.0.0.5. Affected by this vulnerability is the function fromSafeClientFilter of the file /goform/SafeClientFilter. Such manipulation of the argument menufacturer/Go leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7033">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7029 – A weakness has been identified in Tenda F456 1.0.0.5. The impacted element is th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7029</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7029</guid>
    <pubDate>Sun, 26 Apr 2026 09:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7029</strong></p>
  <p>A weakness has been identified in Tenda F456 1.0.0.5. The impacted element is the function fromaddressNat of the file /goform/addressNat. Executing a manipulation of the argument menufacturer/Go can lead to buffer overflow. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7029">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7019 – A vulnerability was identified in Tenda F456 1.0.0.5. The impacted element is th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7019</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7019</guid>
    <pubDate>Sun, 26 Apr 2026 05:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7019</strong></p>
  <p>A vulnerability was identified in Tenda F456 1.0.0.5. The impacted element is the function fromP2pListFilter of the file /goform/P2pListFilter. The manipulation of the argument menufacturer/Go leads to buffer overflow. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7019">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-41328 – Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, a vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41328</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41328</guid>
    <pubDate>Fri, 24 Apr 2026 19:17:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-41328</strong></p>
  <p>Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, a vulnerability has been found in Dgraph that gives an unauthenticated attacker full read access to every piece of data in the database. This affects Dgraph's default configuration where ACL is not enabled. The attack requires two HTTP POSTs to port 8080. The first sets up a schema predicate with @unique @index(exact) @lang v…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-943</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41328">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31578 – In the Linux kernel, the following vulnerability has been resolved:

media: as10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31578</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31578</guid>
    <pubDate>Fri, 24 Apr 2026 15:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31578</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  media: as102: fix to not free memory after the device is registered in as102_usb_probe()  In as102_usb driver, the following race condition occurs: ``` 		CPU0						CPU1 as102_usb_probe()   kzalloc(); // alloc as102_dev_t   ....   usb_register_dev(); 						fd = sys_open("/path/to/dev"); // open as102 fd 						....   usb_deregiste…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31578">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41246 – Contour is a Kubernetes ingress controller using Envoy proxy. From v1.19.0 to be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41246</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41246</guid>
    <pubDate>Thu, 23 Apr 2026 19:17:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41246</strong></p>
  <p>Contour is a Kubernetes ingress controller using Envoy proxy. From v1.19.0 to before v1.33.4, v1.32.5, and v1.31.6, Contour's Cookie Rewriting feature is vulnerable to Lua code injection. An attacker with RBAC permissions to create or modify HTTPProxy resources can craft a malicious value in spec.routes[].cookieRewritePolicies[].pathRewrite.value or spec.routes[].services[].cookieRewritePolicies[…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41246">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-40946 – Oxia is a metadata store and coordination system. Prior to 0.16.2, the OIDC auth...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40946</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40946</guid>
    <pubDate>Tue, 21 Apr 2026 22:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-40946</strong></p>
  <p>Oxia is a metadata store and coordination system. Prior to 0.16.2, the OIDC authentication provider unconditionally sets SkipClientIDCheck: true in the go-oidc verifier configuration, disabling the standard audience (aud) claim validation at the library level. This allows tokens issued for unrelated services by the same OIDC issuer to be accepted by Oxia. This vulnerability is fixed in 0.16.2.</p>
  <p><strong>CVSS:</strong> 9.2 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40946">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-40903 – goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs has an A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40903</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40903</guid>
    <pubDate>Tue, 21 Apr 2026 20:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-40903</strong></p>
  <p>goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs has an ArtiPACKED vulnerability. ArtiPACKED can lead to leakage of the GITHUB_TOKEN through workflow artifacts, even though the token is not present in the repository source code. This vulnerability is fixed in 2.0.0-beta.6.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-829</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40903">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40890 – The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40890</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40890</guid>
    <pubDate>Tue, 21 Apr 2026 20:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40890</strong></p>
  <p>The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Processing a malformed input containing a < character that is not followed by a > character anywhere in the remaining text with a SmartypantsRenderer will lead to Out of Bounds read or a panic. This vulnerability is fixed with commit 759bbc3e32073c3bc4e25969c132fc520eda2778.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40890">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40885 – goshs is a SimpleHTTPServer written in Go. From 2.0.0-beta.4 to 2.0.0-beta.5, go...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40885</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40885</guid>
    <pubDate>Tue, 21 Apr 2026 20:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40885</strong></p>
  <p>goshs is a SimpleHTTPServer written in Go. From 2.0.0-beta.4 to 2.0.0-beta.5, goshs leaks file-based ACL credentials through its public collaborator feed when the server is deployed without global basic auth. Requests to .goshs-protected folders are logged before authorization is enforced, and the collaborator websocket broadcasts raw request headers, including Authorization. An unauthenticated o…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40885">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-40884 – goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs contains...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40884</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40884</guid>
    <pubDate>Tue, 21 Apr 2026 20:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-40884</strong></p>
  <p>goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs contains an SFTP authentication bypass when the documented empty-username basic-auth syntax is used. If the server is started with -b ':pass' together with -sftp, goshs accepts that configuration but does not install any SFTP password handler. As a result, an unauthenticated network attacker can connect to the SFTP service an…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40884">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40883 – goshs is a SimpleHTTPServer written in Go. From 2.0.0-beta.4 to 2.0.0-beta.5, go...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40883</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40883</guid>
    <pubDate>Tue, 21 Apr 2026 20:17:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40883</strong></p>
  <p>goshs is a SimpleHTTPServer written in Go. From 2.0.0-beta.4 to 2.0.0-beta.5, goshs contains a cross-site request forgery issue in its state-changing HTTP GET routes. An external attacker can cause an already authenticated browser to trigger destructive actions such as ?delete and ?mkdir because goshs relies on HTTP basic auth alone and performs no CSRF, Origin, or Referer validation for those ro…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40883">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40876 – goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs contains...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40876</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40876</guid>
    <pubDate>Tue, 21 Apr 2026 20:17:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40876</strong></p>
  <p>goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs contains an SFTP root escape caused by prefix-based path validation. An authenticated SFTP user can read from and write to filesystem paths outside the configured SFTP root, which breaks the intended jail boundary and can expose or modify unrelated server files. The SFTP subsystem routes requests through sftpserver/sftpserver…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40876">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40868 – Kyverno is a policy engine designed for cloud native platform engineering teams...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40868</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40868</guid>
    <pubDate>Tue, 21 Apr 2026 19:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40868</strong></p>
  <p>Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to 1.16.4, kyverno’s apiCall servicecall helper implicitly injects Authorization: Bearer ... using the kyverno controller serviceaccount token when a policy does not explicitly set an Authorization header. Because context.apiCall.service.url is policy-controlled, this can send the kyverno serviceaccount token t…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-922</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40868">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40611 – Let's Encrypt client and ACME library written in Go (Lego). Prior to 4.34.0, the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40611</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40611</guid>
    <pubDate>Tue, 21 Apr 2026 18:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40611</strong></p>
  <p>Let's Encrypt client and ACME library written in Go (Lego). Prior to 4.34.0, the webroot HTTP-01 challenge provider in lego is vulnerable to arbitrary file write and deletion via path traversal. A malicious ACME server can supply a crafted challenge token containing ../ sequences, causing lego to write attacker-influenced content to any path writable by the lego process. This vulnerability is fix…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40611">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6632 – A vulnerability was identified in Tenda F451 1.0.0.7_cn_svn7958. The affected el...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6632</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6632</guid>
    <pubDate>Mon, 20 Apr 2026 11:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6632</strong></p>
  <p>A vulnerability was identified in Tenda F451 1.0.0.7_cn_svn7958. The affected element is the function fromSafeClientFilter of the file /goform/SafeClientFilter of the component httpd. The manipulation of the argument menufacturer/Go leads to buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6632">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40476 – graphql-go is a Go implementation of GraphQL. In versions 15.31.4 and below, the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40476</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40476</guid>
    <pubDate>Fri, 17 Apr 2026 22:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40476</strong></p>
  <p>graphql-go is a Go implementation of GraphQL. In versions 15.31.4 and below, the OverlappingFieldsCanBeMerged validation rule performs O(n²) pairwise comparisons of fields sharing the same response name. An attacker can send a query with thousands of repeated identical fields, causing excessive CPU usage during validation before execution begins. This is not mitigated by existing QueryDepth or Qu…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-407</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40476">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35469 – spdystream is a Go library for multiplexing streams over SPDY connections. In ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35469</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35469</guid>
    <pubDate>Thu, 16 Apr 2026 22:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35469</strong></p>
  <p>spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. Three allocation paths are affected: the SETTINGS frame entry count, the header count in parseHeaderValueBlock, and individual header field sizes — all read as 32-bit integers and used dir…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35469">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40193 – maddy is a composable, all-in-one mail server. Versions prior to 0.9.3 contain a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40193</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40193</guid>
    <pubDate>Thu, 16 Apr 2026 00:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40193</strong></p>
  <p>maddy is a composable, all-in-one mail server. Versions prior to 0.9.3 contain an LDAP injection vulnerability in the auth.ldap module where user-supplied usernames are interpolated into LDAP search filters and DN strings via strings.ReplaceAll() without any LDAP filter escaping, despite the go-ldap/ldap/v3 library's ldap.EscapeFilter() function being available in the same import. This affects th…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40193">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33414 – Podman is a tool for managing OCI containers and pods. Versions 4.8.0 through 5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33414</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33414</guid>
    <pubDate>Tue, 14 Apr 2026 23:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33414</strong></p>
  <p>Podman is a tool for managing OCI containers and pods. Versions 4.8.0 through 5.8.1 contain a command injection vulnerability in the HyperV machine backend in pkg/machine/hyperv/stubber.go, where the VM image path is inserted into a PowerShell double-quoted string without sanitization, allowing $() subexpression injection. Because PowerShell evaluates subexpressions inside double-quoted strings b…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33414">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6200 – A vulnerability was determined in Tenda F456 1.0.0.5. The affected element is th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6200</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6200</guid>
    <pubDate>Mon, 13 Apr 2026 19:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6200</strong></p>
  <p>A vulnerability was determined in Tenda F456 1.0.0.5. The affected element is the function formwebtypelibrary of the file /goform/webtypelibrary. This manipulation of the argument menufacturer/Go causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6200">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6121 – A flaw has been found in Tenda F451 1.0.0.7. Affected by this vulnerability is t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6121</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6121</guid>
    <pubDate>Sun, 12 Apr 2026 08:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6121</strong></p>
  <p>A flaw has been found in Tenda F451 1.0.0.7. Affected by this vulnerability is the function WrlclientSet of the file /goform/WrlclientSet of the component httpd. This manipulation of the argument GO causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been published and may be used.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6121">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6105 – A security vulnerability has been detected in perfree go-fastdfs-web up to 1.3.7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6105</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6105</guid>
    <pubDate>Sat, 11 Apr 2026 22:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6105</strong></p>
  <p>A security vulnerability has been detected in perfree go-fastdfs-web up to 1.3.7. This affects an unknown part of the file src/main/java/com/perfree/controller/InstallController.java of the component doInstall Interface. The manipulation leads to improper authorization. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early ab…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6105">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-40189 – goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.4, goshs enforces...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40189</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40189</guid>
    <pubDate>Fri, 10 Apr 2026 20:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-40189</strong></p>
  <p>goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.4, goshs enforces the documented per-folder .goshs ACL/basic-auth mechanism for directory listings and file reads, but it does not enforce the same authorization checks for state-changing routes. An unauthenticated attacker can upload files with PUT, upload files with multipart POST /upload, create directories with ?mkdir, and delete…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40189">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40188 – goshs is a SimpleHTTPServer written in Go. From 1.0.7 to before 2.0.0-beta.4, th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40188</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40188</guid>
    <pubDate>Fri, 10 Apr 2026 20:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40188</strong></p>
  <p>goshs is a SimpleHTTPServer written in Go. From 1.0.7 to before 2.0.0-beta.4, the SFTP command rename sanitizes only the source path and not the destination, so it is possible to write outside of the root directory of the SFTP. This vulnerability is fixed in 2.0.0-beta.4.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-1314</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40188">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35595 – Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35595</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35595</guid>
    <pubDate>Fri, 10 Apr 2026 17:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35595</strong></p>
  <p>Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CanUpdate check at pkg/models/project_permissions.go:139-148 only requires CanWrite on the new parent project when changing parent_project_id. However, Vikunja's permission model uses a recursive CTE that walks up the project hierarchy to compute permissions. Moving a project under a different parent changes the p…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35595">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5991 – A vulnerability was found in Tenda F451 1.0.0.7. Affected by this issue is the f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5991</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5991</guid>
    <pubDate>Fri, 10 Apr 2026 00:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5991</strong></p>
  <p>A vulnerability was found in Tenda F451 1.0.0.7. Affected by this issue is the function formWrlExtraSet of the file /goform/WrlExtraSet. The manipulation of the argument GO results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been made public and could be used.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5991">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-62718 – Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62718</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62718</guid>
    <pubDate>Thu, 09 Apr 2026 15:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-62718</strong></p>
  <p>Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules. Requests to loopback addresses like localhost. (with a trailing dot) or [::1] (IPv6 literal) skip NO_PROXY matching and go through the configured proxy. This goes against what developers expect and lets attackers force r…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-441</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62718">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4660 – HashiCorp’s go-getter library up to v1.8.5 may allow arbitrary file reads on the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4660</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4660</guid>
    <pubDate>Thu, 09 Apr 2026 14:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4660</strong></p>
  <p>HashiCorp’s go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously crafted URL. This vulnerability, CVE-2026-4660, is fixed in go-getter v1.8.6. This vulnerability does not affect the go-getter/v2 branch and package.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4660">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-34179 – In Canonical LXD versions 4.12 through 6.7, the doCertificateUpdate function in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34179</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34179</guid>
    <pubDate>Thu, 09 Apr 2026 10:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-34179</strong></p>
  <p>In Canonical LXD versions 4.12 through 6.7, the doCertificateUpdate function in lxd/certificates.go does not validate the Type field when handling PUT/PATCH requests to /1.0/certificates/{fingerprint} for restricted TLS certificate users, allowing a remote authenticated attacker to escalate privileges to cluster admin.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-915</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34179">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-34177 – Canonical LXD versions 4.12 through 6.7 contain an incomplete denylist in isVMLo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34177</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34177</guid>
    <pubDate>Thu, 09 Apr 2026 10:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-34177</strong></p>
  <p>Canonical LXD versions 4.12 through 6.7 contain an incomplete denylist in isVMLowLevelOptionForbidden (lxd/project/limits/permissions.go), which omits raw.apparmor and raw.qemu.conf from the set of keys blocked under the restricted.virtual-machines.lowlevel=block project restriction. A remote attacker with can_edit permission on a VM instance in a restricted project can inject an AppArmor rule an…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-184</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34177">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39883 – OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39883</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39883</guid>
    <pubDate>Wed, 08 Apr 2026 21:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39883</strong></p>
  <p>OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg command to use an absolute path but left the BSD kenv command using a bare name, allowing the same PATH hijacking attack on BSD and Solaris platforms. This vulnerability is fixed in 1.43.0.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-426</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39883">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-29181 – OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29181</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29181</guid>
    <pubDate>Tue, 07 Apr 2026 21:17:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-29181</strong></p>
  <p>OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregates members across values. This allows an attacker to amplify cpu and allocations by sending many baggage: header lines, even when each individual value is within the 8192-byte per-value parse limit. This vulnerability is…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29181">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35606 – File Browser is a file managing interface for uploading, deleting, previewing, r...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35606</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35606</guid>
    <pubDate>Tue, 07 Apr 2026 17:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35606</strong></p>
  <p>File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.1, the resourceGetHandler in http/resource.go returns full text file content without checking the Perm.Download permission flag. All three other content-serving endpoints (/api/raw, /api/preview, /api/subtitle) correctly verify this permission befo…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35606">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35605 – File Browser is a file managing interface for uploading, deleting, previewing, r...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35605</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35605</guid>
    <pubDate>Tue, 07 Apr 2026 17:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35605</strong></p>
  <p>File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.1, the Matches() function in rules/rules.go uses strings.HasPrefix() without a trailing directory separator when matching paths against access rules. A rule for /uploads also matches /uploads_backup/, granting or denying access to unintended direct…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35605">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-35471 – goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, tdeleteFile() ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35471</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35471</guid>
    <pubDate>Mon, 06 Apr 2026 22:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-35471</strong></p>
  <p>goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, tdeleteFile() missing return after path traversal check. This vulnerability is fixed in 2.0.0-beta.3.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35471">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-35393 – goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, the POST multi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35393</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35393</guid>
    <pubDate>Mon, 06 Apr 2026 21:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-35393</strong></p>
  <p>goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, the POST multipart upload directory not sanitized. This vulnerability is fixed in 2.0.0-beta.3.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35393">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
