<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Go</title>
  <link>https://cvedaily.com/pages/tags/go.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/go.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Go</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:29 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-37462 – An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/bgp.go) of ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-37462</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-37462</guid>
    <pubDate>Wed, 03 Jun 2026 16:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-37462</strong></p>
  <p>An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-37462">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-10722 – A vulnerability has been found in cilium ebpf up to 0.21.0. This affects the fun...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10722</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10722</guid>
    <pubDate>Wed, 03 Jun 2026 13:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-10722</strong></p>
  <p>A vulnerability has been found in cilium ebpf up to 0.21.0. This affects the function loadRawSpec of the file btf/btf.go of the component LoadCollectionSpec/LoadCollectionSpecFromReader. Such manipulation of the argument offset leads to integer overflow. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The name of the patch i…</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-189</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10722">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10617 – A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10617</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10617</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10617</strong></p>
  <p>A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.11.3. This affects the function resolveAuth of the file internal/http/auth.go of the component Webhook Verification Handler. The manipulation leads to missing authentication. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The project tagged the reported issue as b…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10617">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10616 – A weakness has been identified in nextlevelbuilder GoClaw up to 3.11.3. The impa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10616</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10616</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10616</strong></p>
  <p>A weakness has been identified in nextlevelbuilder GoClaw up to 3.11.3. The impacted element is the function TeamTasksTool.executeComplete of the file internal/tools/team_tasks_lifecycle.go of the component Team Task Completion Handler. Executing a manipulation can lead to missing authorization. The attack may be launched remotely. The exploit has been made available to the public and could be us…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10616">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10583 – A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10583</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10583</guid>
    <pubDate>Tue, 02 Jun 2026 04:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10583</strong></p>
  <p>A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.11.3. Affected by this issue is the function Import of the file internal/http/tts_config.go of the component TTS Configuration Endpoint. The manipulation leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The project tagged the r…</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10583">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44740 – Billy is an interface filesystem abstraction for Go. Prior to versions 5.9.0 and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44740</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44740</guid>
    <pubDate>Mon, 01 Jun 2026 17:17:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44740</strong></p>
  <p>Billy is an interface filesystem abstraction for Go. Prior to versions 5.9.0 and 6.0.0-alpha.1, multiple components may improperly handle crafted or malformed input, resulting in panics, infinite loops, uncontrolled recursion, or excessive resource consumption. These issues arise from insufficient validation and missing safety mechanisms such as cycle detection, recursion limits, or defensive han…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-674</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44740">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-10264 – A vulnerability was determined in lharries whatsapp-mcp 0.0.1. Affected by this ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10264</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10264</guid>
    <pubDate>Mon, 01 Jun 2026 15:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-10264</strong></p>
  <p>A vulnerability was determined in lharries whatsapp-mcp 0.0.1. Affected by this vulnerability is the function SendMessageRequest of the file whatsapp-bridge/main.go of the component Send API Endpoint. This manipulation of the argument mediaPath causes path traversal. The exploit has been publicly disclosed and may be utilized. Patch name: 6657cdceadd361e8fbe824afe9d00b4504009a5d. It is recommende…</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10264">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10219 – A vulnerability was found in nextlevelbuilder GoClaw up to 3.11.3. This impacts ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10219</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10219</guid>
    <pubDate>Mon, 01 Jun 2026 04:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10219</strong></p>
  <p>A vulnerability was found in nextlevelbuilder GoClaw up to 3.11.3. This impacts the function FsBridge.WriteFile of the file internal/sandbox/fsbridge.go of the component write_file Tool. Performing a manipulation results in os command injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The pull request to fix this issue awaits acceptan…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10219">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10218 – A vulnerability has been found in nextlevelbuilder GoClaw up to 3.11.3. This aff...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10218</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10218</guid>
    <pubDate>Mon, 01 Jun 2026 04:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10218</strong></p>
  <p>A vulnerability has been found in nextlevelbuilder GoClaw up to 3.11.3. This affects the function auth of the file internal/http/evolution_handlers.go. Such manipulation leads to improper authorization. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The project tagged the reported issue as bug.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10218">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10217 – A flaw has been found in nextlevelbuilder GoClaw up to 3.11.3. The impacted elem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10217</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10217</guid>
    <pubDate>Mon, 01 Jun 2026 04:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10217</strong></p>
  <p>A flaw has been found in nextlevelbuilder GoClaw up to 3.11.3. The impacted element is the function handleSave of the file internal/http/tts_config.go of the component RoleAdmin Gateway. This manipulation causes improper privilege management. Remote exploitation of the attack is possible. The exploit has been published and may be used. The project tagged the reported issue as bug.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10217">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46385 – iskorotkov/avro is a fast Go Avro codec. Prior to 2.33.0, the Avro array and map...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46385</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46385</guid>
    <pubDate>Fri, 29 May 2026 20:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46385</strong></p>
  <p>iskorotkov/avro is a fast Go Avro codec. Prior to 2.33.0, the Avro array and map decoders looped over an attacker-controlled block-count value without checking the underlying reader's error state inside the loop body. Reader.ReadBlockHeader returns the count as a Go int, which is 64-bit on amd64 / arm64 targets — so a producer can declare a block of up to math.MaxInt64 (~9.2 × 10¹⁸) elements foll…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46385">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46384 – iskorotkov/avro is a fast Go Avro codec. Prior to 2.33.0, several Avro decoder p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46384</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46384</guid>
    <pubDate>Fri, 29 May 2026 20:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46384</strong></p>
  <p>iskorotkov/avro is a fast Go Avro codec. Prior to 2.33.0, several Avro decoder paths read attacker-controlled 64-bit values from the wire format and either narrowed them to platform-sized int before bounds-checking, or summed them with overflow-prone signed-int arithmetic. On 32-bit targets (GOARCH=386, arm, mips, wasm, etc.), the truncation paths can silently bypass byte-slice limits, select the…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46384">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-45626 – Arcane is an interface for managing Docker containers, images, networks, and vol...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45626</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45626</guid>
    <pubDate>Fri, 29 May 2026 18:17:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-45626</strong></p>
  <p>Arcane is an interface for managing Docker containers, images, networks, and volumes. In 1.18.1 and earlier, GET /environments/{id}/volumes/{volumeName}/browse accepts a path query parameter that is passed to a shell command (sh -c "find … | while …") inside an Arcane helper container. The path sanitiser blocks ../ traversal but does not strip Bourne-shell metacharacters such as $() or backticks,…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45626">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44697 – Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44697</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44697</guid>
    <pubDate>Fri, 29 May 2026 18:17:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44697</strong></p>
  <p>Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, a remote, unauthenticated denial-of-service vulnerability in Batch.Decompress (data/batch/batch.go) allows any peer that participates in a topic served by MultiDataInterceptor to allocate multi-gigabyte heaps on the receiving node from a sub-50 KiB gossip payload. A single packet is sufficient to OOM-kill a val…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-409</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44697">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48501 – GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.93.0, GitHub ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48501</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48501</guid>
    <pubDate>Fri, 29 May 2026 16:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48501</strong></p>
  <p>GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.93.0, GitHub CLI incorrectly includes authorization header in API requests to TUF repository mirrors via gh attestation, gh release verify, and gh release verify-asset commands. The CLI uses a shared HTTP client with an authentication layer that automatically attaches tokens to outgoing requests. This layer lacks accurate host det…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48501">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44973 – Billy is an interface filesystem abstraction for Go. Prior to 5.9.0, multiple pa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44973</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44973</guid>
    <pubDate>Thu, 28 May 2026 22:16:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44973</strong></p>
  <p>Billy is an interface filesystem abstraction for Go. Prior to 5.9.0, multiple path traversal issues exist across different components of go-billy. Insufficient path sanitization and boundary enforcement may allow crafted paths (e.g., using ..) to escape intended base directories. While go-billy was not originally designed to provide a strong security boundary, some of these issues were inconsiste…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44973">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44885 – Portainer Community Edition is a lightweight service delivery platform for conta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44885</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44885</guid>
    <pubDate>Thu, 28 May 2026 22:16:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44885</strong></p>
  <p>Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, Portainer's backup restore feature accepts a .tar.gz archive and extracts it to a target directory on the server. The extraction function (ExtractTarGz in api/archive/targz.go) constructed out…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44885">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-44881 – Portainer Community Edition is a lightweight service delivery platform for conta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44881</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44881</guid>
    <pubDate>Thu, 28 May 2026 22:16:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-44881</strong></p>
  <p>Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and 2.41.0, Portainer supports deploying stacks from Git repositories. When a Git-backed stack is created or updated, Portainer clones the repository using go-git v5, which translates…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44881">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9098 – In Casdoor versions 2.362.0 and earlier, the SAML callback handler in controller...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9098</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9098</guid>
    <pubDate>Thu, 28 May 2026 17:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9098</strong></p>
  <p>In Casdoor versions 2.362.0 and earlier, the SAML callback handler in controllers/auth.go accepts any well-formed SAMLResponse sent to /api/acs without verifying that it corresponds to an AuthnRequest previously issued by Casdoor. Additionally, if an administrator disables or deletes an IdP (Identity Provider) after a SAML flow has started, the handler still processes the response using the provi…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9098">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9097 – Casdoor versions 2.362.0 and earlier do not verify that a JWT used for token exc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9097</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9097</guid>
    <pubDate>Thu, 28 May 2026 17:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9097</strong></p>
  <p>Casdoor versions 2.362.0 and earlier do not verify that a JWT used for token exchange is still active. The GetTokenExchangeToken() function in object/token_oauth.go validates the JWT signature and parses its claims, but never queries the Token table to verify whether the subject token has been revoked or invalidated. Because the revocation check is entirely absent, administrators are unable to te…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9097">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9095 – Casdoor versions 2.362.0 and earlier map SAML assertions to user sessions withou...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9095</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9095</guid>
    <pubDate>Thu, 28 May 2026 17:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9095</strong></p>
  <p>Casdoor versions 2.362.0 and earlier map SAML assertions to user sessions without replay protection. The ParseSamlResponse() function in object/saml_sp.go calls sp.RetrieveAssertionInfo() and immediately maps the result to a user session. There is no assertion ID cache, OneTimeUse condition enforcement, or replay detection anywhere in the SAML SP code path. As a result, an attacker can replay a p…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-294</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9095">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9094 – Casdoor versions 2.362.0 and earlier contain a vulnerability enabling cross-orga...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9094</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9094</guid>
    <pubDate>Thu, 28 May 2026 17:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9094</strong></p>
  <p>Casdoor versions 2.362.0 and earlier contain a vulnerability enabling cross-organization token exchange. The GetTokenExchangeToken function in object/token_oauth.go validates JWT signatures but does not verify that the token's user belongs to the same organization as the target application. This can result in privilege escalation across organizational boundaries.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9094">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9093 – In Casdoor versions 2.362.0 and earlier, the SAML service provider implementatio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9093</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9093</guid>
    <pubDate>Thu, 28 May 2026 17:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9093</strong></p>
  <p>In Casdoor versions 2.362.0 and earlier, the SAML service provider implementation does not validate the AudienceRestriction element in SAML assertions. The buildSp function in object/saml_sp.go never sets AudienceURI on the gosaml2 SAMLServiceProvider struct and never inspects WarningInfo.NotInAudience. This allows assertions issued for other service providers to be accepted by Casdoor.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9093">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9091 – Casdoor versions 2.362.0 and earlier contain a logic flaw in the social‑login bi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9091</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9091</guid>
    <pubDate>Thu, 28 May 2026 17:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9091</strong></p>
  <p>Casdoor versions 2.362.0 and earlier contain a logic flaw in the social‑login binding flow that allows users to bypass configured MFA requirements. The binding‑rule code path in controllers/auth.go calls HandleLoggedIn directly without invoking checkMfaEnable. Any user authenticating via this path is logged in without MFA enforcement.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9091">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46117 – In the Linux kernel, the following vulnerability has been resolved:

RDMA/mana: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46117</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46117</guid>
    <pubDate>Thu, 28 May 2026 10:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46117</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss()  Sashiko points out that the user can specify WQs sharing the same CQ as a part of the uAPI and this will trigger the WARN_ON() then go on to corrupt the kernel.  Just reject it outright and fail the QP creation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46117">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45090 – Dalfox is a powerful open-source XSS scanner and utility focused on automation. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45090</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45090</guid>
    <pubDate>Wed, 27 May 2026 18:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45090</strong></p>
  <p>Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, ParameterAnalysis in pkg/scanning/parameterAnalysis.go runs two sequential worker stages that both write to the same results channel. The channel is correctly closed after the first stage completes (close(results) at line 438), but the second stage — which processes POST-body parameters (dp) — is then…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45090">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45047 – bird-lg-go is a BIRD looking glass in Go. Prior to 1.4.5, the apiHandler (and si...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45047</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45047</guid>
    <pubDate>Wed, 27 May 2026 18:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45047</strong></p>
  <p>bird-lg-go is a BIRD looking glass in Go. Prior to 1.4.5, the apiHandler (and similarly webHandlerTelegramBot) processes user-provided JSON payloads by directly using json.NewDecoder(r.Body).Decode(&request) without restricting the maximum read size. An unauthenticated remote attacker can stream an extremely large, endless JSON payload (e.g., several Gigabytes of padding) over a single TCP connec…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45047">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42328 – go-ipld-prime is an implementation of the InterPlanetary Linked Data (IPLD) spec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42328</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42328</guid>
    <pubDate>Wed, 27 May 2026 18:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42328</strong></p>
  <p>go-ipld-prime is an implementation of the InterPlanetary Linked Data (IPLD) spec interfaces, a batteries-included codec implementations of IPLD for CBOR and JSON, and tooling for basic operations on IPLD objects. Prior to 0.23.0, the DAG-CBOR and DAG-JSON decoders recurse on each nested map or list without a depth limit. A payload containing deeply nested collections causes the decoder to recurse…</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-674</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42328">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44325 – free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44325</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44325</guid>
    <pubDate>Wed, 27 May 2026 17:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44325</strong></p>
  <p>free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NRF root SBI endpoint POST /oauth2/token contains a parser-level type-confusion bug family. The handler in NFs/nrf/internal/sbi/api_accesstoken.go reflects over models.NrfAccessTokenAccessTokenReq, special-cases only plain string and NrfNfManagementNfType fields, and treats every other field as if it were a…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44325">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44324 – free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44324</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44324</guid>
    <pubDate>Wed, 27 May 2026 17:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44324</strong></p>
  <p>free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's UDR nudr-dr DELETE /subscription-data/{ueId}/{servingPlmnId}/ee-subscriptions/{subsId}/amf-subscriptions handler panics on a single authenticated request against a fresh UDR instance when the supplied ueId does not exist in UESubsCollection. The processor checks value, ok := udrSelf.UESubsCollection.Load(ue…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-704</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44324">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44319 – free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44319</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44319</guid>
    <pubDate>Wed, 27 May 2026 17:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44319</strong></p>
  <p>free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF terminates the entire process when a stored PFD-subscription notifyUri cannot be reached. In PfdChangeNotifier.FlushNotifications(), the notifier calls NnefPFDmanagementNotify(...) and on any delivery error invokes logger.PFDManageLog.Fatal(err), which is os.Exit(1)-equivalent in Go. An attacker who can…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44319">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44318 – free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44318</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44318</guid>
    <pubDate>Wed, 27 May 2026 17:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44318</strong></p>
  <p>free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's BSF PUT /nbsf-management/v1/subscriptions/{subId} handler has an unsynchronized write on the global Subscriptions map. The handler first reads the map under RLock() via BSFContext.GetSubscription(subId), but if the subscription does not exist, ReplaceIndividualSubcription() writes back to the same map direc…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44318">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-45571 – go-git is an extensible git implementation library written in pure Go. Prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45571</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45571</guid>
    <pubDate>Wed, 27 May 2026 15:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-45571</strong></p>
  <p>go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, a path validation issue in go-git could allow crafted repository data to affect files outside the intended checkout target, including the repository's .git directory. These validations were introduced in upstream Git years ago, so the vulnerability arose from go-git drifting from those checks…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45571">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-45570 – go-git is an extensible git implementation library written in pure Go. Prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45570</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45570</guid>
    <pubDate>Wed, 27 May 2026 15:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-45570</strong></p>
  <p>go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, go-git's SSH transport constructs the remote exec command by wrapping the repository path in single quotes without escaping single quotes embedded inside the path. A repository path containing a single quote can therefore break out of the quoted region in the exec command and be appended as a…</p>
  <p><strong>CVSS:</strong> 2.3 · <strong>CWE:</strong> CWE-116</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45570">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45022 – go-git is an extensible git implementation library written in pure Go. Prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45022</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45022</guid>
    <pubDate>Wed, 27 May 2026 15:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45022</strong></p>
  <p>go-git is an extensible git implementation library written in pure Go. Prior to 5.19.0 and 6.0.0-alpha.3, go-git may parse malformed Git objects in a way that differs from upstream Git. When commit or tag objects contain ambiguous or malformed headers, go-git’s decoded representation may expose values differently from how Git itself would interpret or reject the same object. Additionally, go-git’…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-180</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45022">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46076 – In the Linux kernel, the following vulnerability has been resolved:

KVM: nSVM: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46076</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46076</guid>
    <pubDate>Wed, 27 May 2026 14:17:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46076</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1  Explicitly synthesize a #UD for VMMCALL if L2 is active, L1 does NOT want to intercept VMMCALL, nested_svm_l2_tlb_flush_enabled() is true, and the hypercall is something other than one of the supported Hyper-V hypercalls. When all of the above conditions are met,…</p>
  <p><strong>CVSS:</strong> 7.9 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46076">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Unknown] CVE-2026-46051 – In the Linux kernel, the following vulnerability has been resolved:

md/raid5: f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46051</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46051</guid>
    <pubDate>Wed, 27 May 2026 14:17:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2026-46051</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  md/raid5: fix soft lockup in retry_aligned_read()  When retry_aligned_read() encounters an overlapped stripe, it releases the stripe via raid5_release_stripe() which puts it on the lockless released_stripes llist. In the next raid5d loop iteration, release_stripe_list() drains the stripe onto handle_list (since STRIPE_HANDLE is…</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46051">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Unknown] CVE-2026-46038 – In the Linux kernel, the following vulnerability has been resolved:

net: qrtr: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46038</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46038</guid>
    <pubDate>Wed, 27 May 2026 14:17:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2026-46038</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  net: qrtr: ns: Free the node during ctrl_cmd_bye()  A node sends the BYE packet when it is about to go down. So the nameserver should advertise the removal of the node to all remote and local observers and free the node finally. But currently, the nameserver doesn't free the node memory even after processing the BYE packet. This…</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46038">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Unknown] CVE-2026-46012 – In the Linux kernel, the following vulnerability has been resolved:

rxrpc: Fix ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46012</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46012</guid>
    <pubDate>Wed, 27 May 2026 14:17:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2026-46012</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  rxrpc: Fix memory leaks in rxkad_verify_response()  Fix rxkad_verify_response() to free the ticket and the server key under all circumstances by initialising the ticket pointer to NULL and then making all paths through the function after the first allocation has been done go through a single common epilogue that just releases ev…</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46012">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Unknown] CVE-2026-45953 – In the Linux kernel, the following vulnerability has been resolved:

md/raid5: f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45953</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45953</guid>
    <pubDate>Wed, 27 May 2026 14:17:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2026-45953</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  md/raid5: fix IO hang with degraded array with llbitmap  When llbitmap bit state is still unwritten, any new write should force rcw, as bitmap_ops->blocks_synced() is checked in handle_stripe_dirtying(). However, later the same check is missing in need_this_block(), causing stripe to deadloop during handling because handle_strip…</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45953">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-36045 – picoclaw &lt;=v0.1.2 and earlier is vulnerable to OS command injection via the Exec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-36045</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-36045</guid>
    <pubDate>Wed, 27 May 2026 14:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-36045</strong></p>
  <p>picoclaw <=v0.1.2 and earlier is vulnerable to OS command injection via the ExecTool component (pkg/tools/shell.go). The guardCommand() function attempts to restrict shell command execution using a denylist of 8 regular expressions, but the denylist is incomplete.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-36045">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48126 – Algernon is a small self-contained pure-Go web server. Prior to 1.17.8, when alg...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48126</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48126</guid>
    <pubDate>Tue, 26 May 2026 17:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48126</strong></p>
  <p>Algernon is a small self-contained pure-Go web server. Prior to 1.17.8, when algernon is started with --domain (or --letsencrypt, which silently turns on --domain at engine/flags.go:372), the request handler resolves the served directory by joining the configured --dir with the value of the client-supplied Host header. The join is performed by filepath.Join with no validation, so a Host: .. heade…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48126">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-46431 – Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, the SSE ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46431</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46431</guid>
    <pubDate>Tue, 26 May 2026 17:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-46431</strong></p>
  <p>Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, the SSE event server's Access-Control-Allow-Origin response header was hardcoded to the wildcard * regardless of the caller's Origin. Because EventSource does not preflight and does not send cookies, the wildcard is sufficient to let any third-party page the developer visits open a cross-origin EventSource to the SSE port and…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-942</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46431">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-46430 – Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, the SSE ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46430</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46430</guid>
    <pubDate>Tue, 26 May 2026 17:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-46430</strong></p>
  <p>Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, the SSE event server bound to 0.0.0.0:5553 on Linux/macOS by default because the platform-dependent host default in engine/flags.go:39-46 set host = "" for non-Windows, and utils.JoinHostPort("", ":5553") resolves to ":5553". This vulnerability is fixed in 1.17.7.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46430">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45728 – Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Alg...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45728</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45728</guid>
    <pubDate>Tue, 26 May 2026 17:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45728</strong></p>
  <p>Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is invoked with a single file path instead of a directory, singleFileMode is set to true and debugMode is forcibly enabled. debugMode activates the PrettyError renderer, which on any Lua or template error response dumps the absolute path of the file that errored, complete byte contents of that file, and exceptio…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-209</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45728">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-45721 – Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Alg...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45721</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45721</guid>
    <pubDate>Tue, 26 May 2026 17:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-45721</strong></p>
  <p>Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is asked for any URL path that resolves to a directory without an index file, DirPage walks upward through parent directories — past the configured server root — looking for a file named handler.lua to execute as the request handler. The loop terminates only after 100 ancestor steps or when filepath.Dir returns…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45721">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43982 – Algernon is a small self-contained pure-Go web server. Prior to 1.17.6, uploaded...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43982</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43982</guid>
    <pubDate>Tue, 26 May 2026 17:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43982</strong></p>
  <p>Algernon is a small self-contained pure-Go web server. Prior to 1.17.6, uploadedFileSaveIn() in lua/upload/upload.go uses filepath.Join() with the caller-supplied directory but performs no boundary check after joining. A directory of ../../../tmp resolves cleanly to /tmp, outside the web root. This vulnerability is fixed in 1.17.6.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43982">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43981 – Algernon is a small self-contained pure-Go web server. Prior to 1.17.6, in engin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43981</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43981</guid>
    <pubDate>Tue, 26 May 2026 17:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43981</strong></p>
  <p>Algernon is a small self-contained pure-Go web server. Prior to 1.17.6, in engine/luahandler.go, the sync.RWMutex protecting LoadCommonFunctions is released before L.Push() and L.PCall() execute. Since gopher-lua's LState is explicitly not goroutine-safe, concurrent requests race on the shared state causing Lua VM corruption. The Go race detector confirms this immediately under modest concurrency…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43981">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-9306 – A security vulnerability has been detected in QuantumNous new-api up to 0.12.1. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9306</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9306</guid>
    <pubDate>Sat, 23 May 2026 16:19:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-9306</strong></p>
  <p>A security vulnerability has been detected in QuantumNous new-api up to 0.12.1. This affects the function RelayMidjourneyImage/GetByOnlyMJId of the file router/relay-router.go of the component Midjourney Image Relay Endpoint. Such manipulation leads to authorization bypass. The attack can be launched remotely. The attack requires a high level of complexity. The exploitability is reported as diffi…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9306">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9305 – A weakness has been identified in QuantumNous new-api up to 0.12.1. The impacted...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9305</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9305</guid>
    <pubDate>Sat, 23 May 2026 15:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9305</strong></p>
  <p>A weakness has been identified in QuantumNous new-api up to 0.12.1. The impacted element is the function SearchUserTopUps/SearchAllTopUps of the file model/topup.go of the component self Endpoint. This manipulation causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this d…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9305">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9299 – A flaw has been found in omec-project amf up to 2.1.1. Affected by this issue is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9299</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9299</guid>
    <pubDate>Sat, 23 May 2026 11:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9299</strong></p>
  <p>A flaw has been found in omec-project amf up to 2.1.1. Affected by this issue is the function PDUSessionResourceModifyIndication of the file /go/src/amf/ngap/handler.go. This manipulation causes memory corruption. Remote exploitation of the attack is possible. The exploit has been published and may be used. Applying a patch is the recommended action to fix this issue.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9299">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44390 – NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when h...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44390</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44390</guid>
    <pubDate>Wed, 20 May 2026 10:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44390</strong></p>
  <p>NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when handling replies with very large RRsets that Unbound needs to perform name compression for. Malicious upstream responses with very large RRsets with records that don't share a suffix above the root can cause Unbound to spend a considerable time applying name compression to downstream replies. This can lead to degraded…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-407</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44390">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-47358 – Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF)...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47358</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47358</guid>
    <pubDate>Tue, 19 May 2026 17:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-47358</strong></p>
  <p>Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in uploaded IaC templates when running in server mode. When Terrascan parses uploaded ARM templates or CloudFormation templates, it resolves external URLs referenced within those templates via hashicorp/go-getter with all default detectors enabled, including FileDetector. An unauthenticate…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47358">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-47357 – Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF)...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47357</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47357</guid>
    <pubDate>Tue, 19 May 2026 17:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-47357</strong></p>
  <p>Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in the remote directory scan endpoint (POST /v1/{iac}/{iacVersion}/{cloud}/remote/dir/scan) when running in server mode. An unauthenticated remote attacker can supply an attacker-controlled HTTP URL as remote_url with remote_type set to "http". The URL is passed directly to hashicorp/go-g…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47357">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8786 – A vulnerability has been found in Tencent WeKnora up to 0.3.6. Affected by this ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8786</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8786</guid>
    <pubDate>Mon, 18 May 2026 04:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8786</strong></p>
  <p>A vulnerability has been found in Tencent WeKnora up to 0.3.6. Affected by this issue is the function getKnowledgeBaseForInitialization of the file internal/handler/initialization.go of the component Config API Endpoint. The manipulation of the argument kbId leads to authorization bypass. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8786">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8783 – A security vulnerability has been detected in omec-project amf up to 2.1.3-dev. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8783</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8783</guid>
    <pubDate>Mon, 18 May 2026 04:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8783</strong></p>
  <p>A security vulnerability has been detected in omec-project amf up to 2.1.3-dev. This impacts the function UERadioCapabilityCheckResponse of the file ngap/dispatcher.go. Such manipulation leads to null pointer dereference. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 2.2.0 will fix this issue. Upgrading the affected component is…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-404</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8783">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8782 – A weakness has been identified in omec-project amf up to 2.1.3-dev. This affects...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8782</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8782</guid>
    <pubDate>Mon, 18 May 2026 02:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8782</strong></p>
  <p>A weakness has been identified in omec-project amf up to 2.1.3-dev. This affects an unknown function of the file ngap/handler.go of the component NGAP Message Handler. This manipulation causes null pointer dereference. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. Upgrading to version 2.2.0 mitigates this issue. It…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-404</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8782">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8781 – A security flaw has been discovered in omec-project amf up to 2.1.3-dev. The imp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8781</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8781</guid>
    <pubDate>Mon, 18 May 2026 02:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8781</strong></p>
  <p>A security flaw has been discovered in omec-project amf up to 2.1.3-dev. The impacted element is the function RANConfiguration of the file ngap/handler.go. The manipulation results in null pointer dereference. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 2.2.0 is sufficient to resolve this issue. Upgrading the a…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-404</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8781">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8780 – A vulnerability was identified in omec-project amf up to 2.1.3-dev. The affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8780</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8780</guid>
    <pubDate>Mon, 18 May 2026 02:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8780</strong></p>
  <p>A vulnerability was identified in omec-project amf up to 2.1.3-dev. The affected element is an unknown function of the file ngap/dispatcher.go of the component NGAP Message Handler. The manipulation leads to memory corruption. The attack may be initiated remotely. The exploit is publicly available and might be used. Upgrading to version 2.2.0 is sufficient to fix this issue. It is suggested to up…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8780">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8779 – A vulnerability was determined in omec-project amf up to 2.1.3-dev. Impacted is ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8779</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8779</guid>
    <pubDate>Mon, 18 May 2026 02:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8779</strong></p>
  <p>A vulnerability was determined in omec-project amf up to 2.1.3-dev. Impacted is the function NGSetupRequest of the file ngap/handler.go. Executing a manipulation of the argument InformationElement can lead to memory corruption. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.2.0 is recommended to address this issue. The affe…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8779">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44567 – Open WebUI is a self-hosted artificial intelligence platform designed to operate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44567</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44567</guid>
    <pubDate>Fri, 15 May 2026 22:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44567</strong></p>
  <p>Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.1.124, the API does not properly validate that the user has an authorized user role of user. By default, when Open WebUI is configured with new sign-ups enabled, the default user role is set to pending. In this configuration, an administrator is required to go into the Admin management pa…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-602</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44567">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44310 – Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44310</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44310</guid>
    <pubDate>Fri, 15 May 2026 17:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44310</strong></p>
  <p>Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. From 0.4.0 to before 0.15.0, CertVerifier.Verify() in pkg/git/verifier.go unconditionally dereferences certs[0] after sd.GetCertificates() without checking the slice length. A CMS/PKCS7 signed message with an empty certificate set is a structurally valid DER payload; GetCertificates() returns an empt…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-129</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44310">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44309 – Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44309</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44309</guid>
    <pubDate>Fri, 15 May 2026 17:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44309</strong></p>
  <p>Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. Prior to 0.16.0, gitsign verify and gitsign verify-tag re-encode commit/tag objects through go-git's EncodeWithoutSignature before checking the signature, instead of verifying against the raw git object bytes. For malformed objects with duplicate tree headers, git-core and go-git parse different tree…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44309">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-44427 – The MCP Registry provides MCP clients with a list of MCP servers, like an app st...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44427</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44427</guid>
    <pubDate>Thu, 14 May 2026 22:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-44427</strong></p>
  <p>The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. From 1.1.0 to 1.7.4, the TrailingSlashMiddleware in internal/api/server.go is vulnerable to an open redirect attack. An attacker can craft a URL with a protocol-relative path (e.g., //evil.com/) that, after trailing slash removal, results in a Location header of //evil.com — which browsers interpr…</p>
  <p><strong>CVSS:</strong> 0.0 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44427">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-45781 – The MCP Registry provides MCP clients with a list of MCP servers, like an app st...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45781</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45781</guid>
    <pubDate>Thu, 14 May 2026 21:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-45781</strong></p>
  <p>The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.9, OCI ownership validation skips label-match check when upstream OCI registry returns HTTP 429, letting any authenticated publisher bind their io.github.<user>/* namespace to OCI images they do not control. internal/validators/registries/oci.go:104-119 fails open on http.StatusTooMan…</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-636</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45781">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44430 – The MCP Registry provides MCP clients with a list of MCP servers, like an app st...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44430</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44430</guid>
    <pubDate>Thu, 14 May 2026 21:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44430</strong></p>
  <p>The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.7, the Registry's HTTP-based namespace verification (POST /v0/auth/http, POST /v0.1/auth/http) uses safeDialContext (internal/api/handlers/v0/auth/http.go:67-110) to refuse dialling private/internal addresses when fetching the well-known public-key file from a publisher-supplied domai…</p>
  <p><strong>CVSS:</strong> 4.0 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44430">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44429 – The MCP Registry provides MCP clients with a list of MCP servers, like an app st...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44429</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44429</guid>
    <pubDate>Thu, 14 May 2026 21:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44429</strong></p>
  <p>The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.7, the public catalogue UI served at GET / (file internal/api/handlers/v0/ui_index.html) is vulnerable to stored cross-site scripting via the server.websiteUrl field of any published server.json. Server-side validation in internal/validators/validators.go (validateWebsiteURL) only che…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44429">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-45375 – SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45375</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45375</guid>
    <pubDate>Thu, 14 May 2026 19:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-45375</strong></p>
  <p>SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan's Bazaar (community marketplace) renders the name and version fields of a package's plugin.json (and the equivalent theme.json / template.json / widget.json / icon.json) into the Settings → Marketplace UI without HTML escaping. The kernel-side helper sanitizePackageDisplayStrings in kernel/bazaar/package.go HTML…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45375">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44522 – Note Mark is an open-source note-taking application. From 0.13.0 to before 0.19...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44522</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44522</guid>
    <pubDate>Thu, 14 May 2026 19:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44522</strong></p>
  <p>Note Mark is an open-source note-taking application. From 0.13.0 to before 0.19.4, the Note Mark application allows authenticated users to upload assets to notes via POST /api/notes/{noteID}/assets, where the asset filename is provided through the X-Name HTTP request header. This value is stored directly in the database without any sanitization or validation - no path separator filtering, no dire…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44522">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42589 – Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gote...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42589</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42589</guid>
    <pubDate>Thu, 14 May 2026 16:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42589</strong></p>
  <p>Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg's /forms/pdfengines/metadata/write HTTP endpoint accepts a JSON metadata object and passes its keys directly to ExifTool via the go-exiftool library. No validation is performed on key characters. A \n embedded in a JSON key splits the ExifTool stdin stream into a new argument line, allowing an attacker to inject…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42589">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-43644 – podinfo through 6.11.2 contains a reflected cross-site scripting vulnerability i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43644</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43644</guid>
    <pubDate>Thu, 14 May 2026 13:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-43644</strong></p>
  <p>podinfo through 6.11.2 contains a reflected cross-site scripting vulnerability in the /echo and /api/echo endpoints where the echoHandler writes request body content directly to the response without setting explicit Content-Type or X-Content-Type-Options headers. Attackers can craft cross-origin HTML pages with auto-submitting forms containing script payloads in the request body, which are served…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43644">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44166 – Pocketbase is an open source web backend written in go. Prior to 0.22.42 and 0.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44166</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44166</guid>
    <pubDate>Tue, 12 May 2026 18:17:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44166</strong></p>
  <p>Pocketbase is an open source web backend written in go. Prior to 0.22.42 and 0.37.4, in some situations, if an attacker knows the email address of the victim they can create and link an unverified PocketBase user in advance by authenticating with one of the OAuth2 app providers, e.g. "A". When the victim gets invited or decides to sign up to your app on their own with provider "B" (PocketBase OAu…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44166">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43983 – Pocket ID is an OIDC provider that allows users to authenticate with their passk...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43983</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43983</guid>
    <pubDate>Tue, 12 May 2026 15:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43983</strong></p>
  <p>Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.6.0, The createTokenFromRefreshToken function (oidc_service.go) validates the refresh token's cryptographic integrity but does not re-validate the user's current authorization state before issuing new tokens. This allows (1) the client to refresh the token indefinitely after authorizat…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43983">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42554 – Fiber is a web framework for Go. Prior to 2.52.12 and 3.1.0, Cross-Site Scriptin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42554</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42554</guid>
    <pubDate>Mon, 11 May 2026 23:19:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42554</strong></p>
  <p>Fiber is a web framework for Go. Prior to 2.52.12 and 3.1.0, Cross-Site Scripting vulnerability in Go Fiber allows a remote attacker to inject arbitrary HTML/JavaScript by supplying Accept: text/html on any request whose handler passes attacker-influenced data to the AutoFormat() feature. The developer opts into content negotiation by calling AutoFormat(), but does not opt into raw HTML emission…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42554">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42882 – oxyno-zeta/s3-proxy is an aws s3 proxy written in go. Prior to 5.0.0, s3-proxy c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42882</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42882</guid>
    <pubDate>Mon, 11 May 2026 20:25:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42882</strong></p>
  <p>oxyno-zeta/s3-proxy is an aws s3 proxy written in go. Prior to 5.0.0, s3-proxy contains an authentication bypass caused by inconsistent URL path interpretation between the authentication middleware and the bucket handler. The authentication middleware evaluates resource path patterns against the percent-encoded request URI (r.URL.RequestURI()), while the bucket handler constructs S3 object keys f…</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42882">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-8276 – A flaw has been found in bettercap up to 2.41.5. Affected by this issue is some ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8276</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8276</guid>
    <pubDate>Mon, 11 May 2026 06:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-8276</strong></p>
  <p>A flaw has been found in bettercap up to 2.41.5. Affected by this issue is some unknown functionality of the file modules/mysql_server/mysql_server.go of the component MySQL Server. Executing a manipulation can lead to integer coercion error. The attack can be launched remotely. The attack requires a high level of complexity. The exploitation is known to be difficult. The exploit has been publish…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-189</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8276">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-8275 – A vulnerability was detected in bettercap up to 2.41.5. Affected by this vulnera...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8275</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8275</guid>
    <pubDate>Mon, 11 May 2026 06:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-8275</strong></p>
  <p>A vulnerability was detected in bettercap up to 2.41.5. Affected by this vulnerability is the function ippReadChunkedBody of the file modules/zerogod/zerogod_ipp_primitives.go of the component zerogod IPP Service. Performing a manipulation results in integer coercion error. The attack can be initiated remotely. The attack is considered to have high complexity. The exploitation appears to be diffi…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-189</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8275">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8210 – A security vulnerability has been detected in aandrew-me tgpt up to 2.11.1 on Li...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8210</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8210</guid>
    <pubDate>Sat, 09 May 2026 21:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8210</strong></p>
  <p>A security vulnerability has been detected in aandrew-me tgpt up to 2.11.1 on Linux/macOS. Affected by this vulnerability is the function helper.Update of the file helper.go of the component Update Handler. The manipulation leads to command injection. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used. The vendor was contacted early about thi…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8210">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42576 – apko allows users to build and publish OCI container images built from apk packa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42576</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42576</guid>
    <pubDate>Sat, 09 May 2026 20:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42576</strong></p>
  <p>apko allows users to build and publish OCI container images built from apk packages. Prior to version 1.2.7, DiscoverKeys in pkg/apk/apk/implementation.go unconditionally type-asserts JWKS keys as *rsa.PublicKey without checking the key type. If a repository JWKS endpoint returns a non-RSA key (e.g. EC), the unchecked assertion panics and crashes apko. This affects any workflow that initializes t…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-704</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42576">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42297 – Argo Workflows is an open source container-native workflow engine for orchestrat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42297</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42297</guid>
    <pubDate>Sat, 09 May 2026 04:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42297</strong></p>
  <p>Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From version 4.0.0 to before version 4.0.5, the Sync Service's ConfigMap-backed provider (server/sync/sync_cm.go) performs zero authorization checks on all CRUD operations (create, read, update, delete). Any authenticated user — including those using fake Bearer tokens — can create, re…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42297">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42183 – Argo Workflows is an open source container-native workflow engine for orchestrat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42183</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42183</guid>
    <pubDate>Sat, 09 May 2026 04:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42183</strong></p>
  <p>Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From version 4.0.0 to before version 4.0.5, a nil pointer dereference in server/auth/gatekeeper.go rbacAuthorization() causes a panic (denial of service) for SSO users whose claims match a namespace-level RBAC rule but not an SSO-namespace rule, when SSO_DELEGATE_RBAC_TO_NAMESPACE=true…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42183">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-41889 – pgx is a PostgreSQL driver and toolkit for Go. Prior to version 5.9.2, SQL injec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41889</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41889</guid>
    <pubDate>Fri, 08 May 2026 17:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-41889</strong></p>
  <p>pgx is a PostgreSQL driver and toolkit for Go. Prior to version 5.9.2, SQL injection can occur when the non-default simple protocol is used, a dollar quoted string literal is used in the SQL query, that string literal contains text that would be would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker. This issue has been…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41889">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-43472 – In the Linux kernel, the following vulnerability has been resolved:

unshare: fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43472</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43472</guid>
    <pubDate>Fri, 08 May 2026 15:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-43472</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  unshare: fix unshare_fs() handling  There's an unpleasant corner case in unshare(2), when we have a CLONE_NEWNS in flags and current->fs hadn't been shared at all; in that case copy_mnt_ns() gets passed current->fs instead of a private copy, which causes interesting warts in proof of correctness]  > I guess if private means fs->…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43472">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-43394 – In the Linux kernel, the following vulnerability has been resolved:

nfsd: Fix c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43394</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43394</guid>
    <pubDate>Fri, 08 May 2026 15:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-43394</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  nfsd: Fix cred ref leak in nfsd_nl_listener_set_doit().  nfsd_nl_listener_set_doit() uses get_current_cred() without put_cred().  As we can see from other callers, svc_xprt_create_from_sa() does not require the extra refcount.  nfsd_nl_listener_set_doit() is always in the process context, sendmsg(), and current->cred does not go…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43394">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43328 – In the Linux kernel, the following vulnerability has been resolved:

cpufreq: go...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43328</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43328</guid>
    <pubDate>Fri, 08 May 2026 14:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43328</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  cpufreq: governor: fix double free in cpufreq_dbs_governor_init() error path  When kobject_init_and_add() fails, cpufreq_dbs_governor_init() calls kobject_put(&dbs_data->attr_set.kobj).  The kobject release callback cpufreq_dbs_data_release() calls gov->exit(dbs_data) and kfree(dbs_data), but the current error path then calls go…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-415</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43328">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-43327 – In the Linux kernel, the following vulnerability has been resolved:

USB: dummy-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43327</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43327</guid>
    <pubDate>Fri, 08 May 2026 14:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-43327</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  USB: dummy-hcd: Fix locking/synchronization error  Syzbot testing was able to provoke an addressing exception and crash in the usb_gadget_udc_reset() routine in drivers/usb/gadgets/udc/core.c, resulting from the fact that the routine was called with a second ("driver") argument of NULL.  The bad caller was set_link_state() in du…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-667</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43327">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-41506 – go-git is an extensible git implementation library written in pure Go. Prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41506</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41506</guid>
    <pubDate>Fri, 08 May 2026 14:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-41506</strong></p>
  <p>go-git is an extensible git implementation library written in pure Go. Prior to versions 5.18.0 and 6.0.0-alpha.2, go-git may leak HTTP authentication credentials when following redirects during smart-HTTP clone and fetch operations. This issue has been patched in versions 5.18.0 and 6.0.0-alpha.2.</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41506">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42501 – A malicious module proxy can exploit a flaw in the go command's validation of mo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42501</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42501</guid>
    <pubDate>Thu, 07 May 2026 20:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42501</strong></p>
  <p>A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum database validation. This vulnerability affects any user using an untrusted module proxy (GOMODPROXY) or checksum database (GOSUMDB). A malicious module proxy can serve altered versions of the Go toolchain. When selecting a different version of the Go toolchain than the currently inst…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-347</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42501">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-39819 – The "go bug" command writes to two files with predictable names in the system te...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39819</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39819</guid>
    <pubDate>Thu, 07 May 2026 20:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-39819</strong></p>
  <p>The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp"). An attacker with access to the temporary directory can create a symlink in one of these names, causing "go bug" to overwrite the target of the symlink.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39819">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-39817 – The "go tool pack" subcommand (usually used only by the compiler as an internal ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39817</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39817</guid>
    <pubDate>Thu, 07 May 2026 20:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-39817</strong></p>
  <p>The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames. Extracting a malicious archive file with the "pack" subcommand can write files to arbitrary locations on the filesystem.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39817">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8081 – A vulnerability has been found in router-for-me CLIProxyAPI 6.9.29. Affected by ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8081</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8081</guid>
    <pubDate>Thu, 07 May 2026 18:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8081</strong></p>
  <p>A vulnerability has been found in router-for-me CLIProxyAPI 6.9.29. Affected by this issue is some unknown functionality of the file internal/api/handlers/management/api_tools.go of the component API Interface. The manipulation of the argument url leads to server-side request forgery. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8081">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44349 – Daptin is a GraphQL/JSON-API headless CMS. Prior to version 0.11.5, processFuzzy...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44349</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44349</guid>
    <pubDate>Thu, 07 May 2026 15:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44349</strong></p>
  <p>Daptin is a GraphQL/JSON-API headless CMS. Prior to version 0.11.5, processFuzzySearch in server/resource/resource_findallpaginated.go:1484 splits the user-supplied column parameter by comma and interpolates each segment directly into goqu.L(fmt.Sprintf("LOWER(%s) LIKE ?", prefix+col)) raw SQL with no column whitelist check. The entry point is GET /api/<entity> with operator=fuzzy (or fuzzy_any,…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44349">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42285 – GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42285</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42285</guid>
    <pubDate>Thu, 07 May 2026 12:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42285</strong></p>
  <p>GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. In version 4.4.0, an unauthenticated remote BGP peer can trigger a fatal panic in GoBGP by sending a specially crafted BGP UPDATE message. When the server receives a message with inconsistent attribute lengths, it improperly handles the internal state transition to a "withdraw" action, leading to…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42285">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41643 – GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41643</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41643</guid>
    <pubDate>Thu, 07 May 2026 12:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41643</strong></p>
  <p>GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Prior to version 4.3.0, a remote Denial of Service (DoS) vulnerability exists in GoBGP where a malformed BGP UPDATE message can trigger a runtime error: index out of range panic. This occurs during the processing of 4-byte AS attributes when the message structure causes an internal slice index shi…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-129</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41643">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41642 – GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41642</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41642</guid>
    <pubDate>Thu, 07 May 2026 12:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41642</strong></p>
  <p>GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. In version 4.3.0, a remote Denial of Service (DoS) vulnerability exists in GoBGP due to a nil pointer dereference. When a malformed BGP UPDATE message contains an unrecognized Path Attribute marked as "Well-known," the daemon fails to interrupt the message handling flow. This results in an illegal…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41642">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-40243 – Incus is a system container and virtual machine manager. In versions before 7.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40243</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40243</guid>
    <pubDate>Wed, 06 May 2026 21:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-40243</strong></p>
  <p>Incus is a system container and virtual machine manager. In versions before 7.0.0, broken TLS validation logic in the OVN database connection logic can allow connections to an attacker's OVN database. The OVN client implementations disable Go standard TLS server verification and replace it with custom peer-certificate verification logic. That replacement verifier does not anchor trust in the conf…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40243">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-43277 – In the Linux kernel, the following vulnerability has been resolved:

APEI/GHES: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43277</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43277</guid>
    <pubDate>Wed, 06 May 2026 12:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-43277</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  APEI/GHES: ensure that won't go past CPER allocated record  The logic at ghes_new() prevents allocating too large records, by checking if they're bigger than GHES_ESTATUS_MAX_SIZE (currently, 64KB). Yet, the allocation is done with the actual number of pages from the CPER bios table location, which can be smaller.  Yet, a bad fi…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43277">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-43266 – In the Linux kernel, the following vulnerability has been resolved:

EFI/CPER: d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43266</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43266</guid>
    <pubDate>Wed, 06 May 2026 12:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-43266</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  EFI/CPER: don't go past the ARM processor CPER record buffer  There's a logic inside GHES/CPER to detect if the section_length is too small, but it doesn't detect if it is too big.  Currently, if the firmware receives an ARM processor CPER record stating that a section length is big, kernel will blindly trust section_length, pro…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43266">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43226 – In the Linux kernel, the following vulnerability has been resolved:

net/rds: No...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43226</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43226</guid>
    <pubDate>Wed, 06 May 2026 12:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43226</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  net/rds: No shortcut out of RDS_CONN_ERROR  RDS connections carry a state "rds_conn_path::cp_state" and transitions from one state to another and are conditional upon an expected state: "rds_conn_path_transition."  There is one exception to this conditionality, which is "RDS_CONN_ERROR" that can be enforced by "rds_conn_path_dro…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43226">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-43201 – In the Linux kernel, the following vulnerability has been resolved:

APEI/GHES: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43201</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43201</guid>
    <pubDate>Wed, 06 May 2026 12:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-43201</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  APEI/GHES: ARM processor Error: don't go past allocated memory  If the BIOS generates a very small ARM Processor Error, or an incomplete one, the current logic will fail to deferrence  	err->section_length and 	ctx_info->size  Add checks to avoid that. With such changes, such GHESv2 records won't cause OOPSes like this:  [    1.…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43201">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
