<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – TLS</title>
  <link>https://cvedaily.com/pages/tags/tls.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/tls.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – TLS</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:27 +0000</lastBuildDate>
  <item>
    <title>[Unknown] CVE-2026-8874 – Version 3.0.7 of the Securly Chrome Extension downloads JSON files containing cr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8874</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8874</guid>
    <pubDate>Wed, 03 Jun 2026 19:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2026-8874</strong></p>
  <p>Version 3.0.7 of the Securly Chrome Extension downloads JSON files containing crisis alert keywords and filtering rules over unencrypted HTTP via the Fetch API. Other endpoints in the same extension correctly fetch IWF and CIPA data over HTTPS, demonstrating an inconsistent implementation of TLS.</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8874">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Unknown] CVE-2026-46250 – In the Linux kernel, the following vulnerability has been resolved:

MIPS: Work ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46250</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46250</guid>
    <pubDate>Wed, 03 Jun 2026 18:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2026-46250</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  MIPS: Work around LLVM bug when gp is used as global register variable  On MIPS, __current_thread_info is defined as global register variable locating in $gp, and is simply assigned with new address during kernel relocation.  This however is broken with LLVM, which always restores $gp if it finds $gp is clobbered in any form, in…</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46250">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Unknown] CVE-2026-36610 – Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 transmits DDNS credenti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-36610</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-36610</guid>
    <pubDate>Wed, 03 Jun 2026 18:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2026-36610</strong></p>
  <p>Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 transmits DDNS credentials over plaintext HTTP with only Base64 encoding. The firmware contains no TLS implementation, allowing man-in-the-middle interception of DDNS service credentials.</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-36610">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-45683 – OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the Op...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45683</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45683</guid>
    <pubDate>Tue, 02 Jun 2026 16:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-45683</strong></p>
  <p>OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the Java TLS ioctl probe reads user-controlled ioctl pointers with bpf_probe_read instead of bpf_probe_read_user. An instrumented local process can therefore point OBI at kernel memory and cause that memory to be copied into telemetry. This issue has been patched in versio…</p>
  <p><strong>CVSS:</strong> 3.8 · <strong>CWE:</strong> CWE-127</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45683">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-45682 – OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the Op...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45682</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45682</guid>
    <pubDate>Tue, 02 Jun 2026 16:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-45682</strong></p>
  <p>OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the custom CappedConcurrentHashMap introduced for Java TLS state tracking never removes keys from its insertion-order queue when entries are deleted. In long-running instrumented JVMs, repeated connection churn can therefore grow the queue without bound and exhaust heap me…</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45682">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-41017 – Apache Airflow's `JWTRefreshMiddleware` set the JWT auth cookie without the `Sec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41017</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41017</guid>
    <pubDate>Mon, 01 Jun 2026 09:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-41017</strong></p>
  <p>Apache Airflow's `JWTRefreshMiddleware` set the JWT auth cookie without the `Secure` flag, so deployments running the Airflow API server behind an HTTPS-terminating reverse proxy (e.g. nginx / Envoy / a managed load balancer that terminates TLS and forwards plaintext to the API server, the default cloud-native topology) would have the user's session JWT replayed over any cleartext HTTP request to…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-614</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41017">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35563 – It was identified that the LDAP client implementation in version 2.1.7 does not ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35563</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35563</guid>
    <pubDate>Mon, 01 Jun 2026 08:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35563</strong></p>
  <p>It was identified that the LDAP client implementation in version 2.1.7 does not verify if the server certificate matches the intended LDAP  hostname. While the underlying code validates the certificate chain  against a trusted authority, the absence of endpoint identification  allows a valid certificate issued for an entirely unrelated host to be  improperly accepted. This oversight leaves the co…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-297</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35563">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46579 – A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46579</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46579</guid>
    <pubDate>Fri, 29 May 2026 11:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46579</strong></p>
  <p>A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Client-*` headers from incoming requests. This allows an unauthenticated attacker to send plain HTTP requests with crafted `X-SSL-Client-*` headers. As a result, backends relying on these headers for mutual TLS (Transport Layer Security) authentication…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46579">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46835 – Vulnerability in the Net Service component of Oracle Database Server.  Supported...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46835</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46835</guid>
    <pubDate>Thu, 28 May 2026 21:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46835</strong></p>
  <p>Vulnerability in the Net Service component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Net Service.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Net Servi…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46835">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46834 – Vulnerability in the Net Service component of Oracle Database Server.  Supported...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46834</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46834</guid>
    <pubDate>Thu, 28 May 2026 21:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46834</strong></p>
  <p>Vulnerability in the Net Service component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Net Service.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Net Servi…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46834">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-46833 – Vulnerability in the Net Service component of Oracle Database Server.  Supported...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46833</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46833</guid>
    <pubDate>Thu, 28 May 2026 21:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-46833</strong></p>
  <p>Vulnerability in the Net Service component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Net Service.  While the vulnerability is in Net Service, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerab…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46833">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32847 – DeepCode through commit c991dc2 contains a path traversal vulnerability in the S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32847</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32847</guid>
    <pubDate>Thu, 28 May 2026 20:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32847</strong></p>
  <p>DeepCode through commit c991dc2 contains a path traversal vulnerability in the SPA catch-all route in new_ui/backend/main.py that allows unauthenticated attackers to read arbitrary files by supplying percent-encoded path segments to the GET /{full_path:path} endpoint. Attackers can bypass Starlette's path normalization by encoding slashes as %2F and dots as %2E%2E, causing the joined path to trav…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32847">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-46685 – RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46685</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46685</guid>
    <pubDate>Thu, 28 May 2026 19:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-46685</strong></p>
  <p>RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, when RUSTFS_CORS_ALLOWED_ORIGINS is unset, the RustFS S3 listener's ConditionalCorsLayer reflects any request Origin value back as Access-Control-Allow-Origin and also sets Access-Control-Allow-Credentials: true and Access-Control-Allow-Headers: * on responses, including preflight responses and error responses. Th…</p>
  <p><strong>CVSS:</strong> 6.0 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46685">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42790 – Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42790</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42790</guid>
    <pubDate>Wed, 27 May 2026 17:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42790</strong></p>
  <p>Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_cert and public_key modules) allows a DNS nameConstraints bypass via subject CommonName fallback in TLS hostname verification.  Two flaws combine to allow a subordinate CA whose DNS nameConstraints are restricted (e.g. permitted;DNS:allowed.example.com) to issue a leaf certificate that an OTP TLS client accepts as a va…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42790">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-42791 – Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42791</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42791</guid>
    <pubDate>Wed, 27 May 2026 14:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-42791</strong></p>
  <p>Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_ocsp module) allows forged OCSP responses signed with an expired responder certificate to be accepted as valid.  OCSP response verification in pubkey_ocsp:verify_response/5 and pubkey_ocsp:is_authorized_responder/3 in lib/public_key/src/pubkey_ocsp.erl does not check the validity period (notBefore/notAfter) of the OCSP…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42791">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42789 – Improper Following of a Certificate's Chain of Trust vulnerability in Erlang OTP...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42789</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42789</guid>
    <pubDate>Wed, 27 May 2026 14:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42789</strong></p>
  <p>Improper Following of a Certificate's Chain of Trust vulnerability in Erlang OTP public_key (pubkey_cert module) allows a non-CA certificate to be accepted as an intermediate issuer, enabling certificate chain forgery.  In lib/public_key/src/pubkey_cert.erl, pubkey_cert:validate_extensions/7 contains two flaws that together allow a certificate with basicConstraints cA:false and no keyUsage extens…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42789">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45574 – epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrast...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45574</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45574</guid>
    <pubDate>Tue, 26 May 2026 22:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45574</strong></p>
  <p>epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker on the network path between the ePA service and the Konnektor can present any TLS certificate (self-signed, expired, wrong CN) and intercept all SOAP traffic. This includes patient identifiers (KVNR), SMC-B card operations (authentication, signing), document content, and credential…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45574">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44213 – The OpenTelemetry.Exporter.Instana exports telemetry to Instana backend. Prior t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44213</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44213</guid>
    <pubDate>Tue, 26 May 2026 22:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44213</strong></p>
  <p>The OpenTelemetry.Exporter.Instana exports telemetry to Instana backend. Prior to 1.1.0, the OpenTelemetry.Exporter.Instana NuGet package does not validate HTTPS/TLS certificates are valid when sending telemetry to a configured Instana back-end when a proxy is configured using the INSTANA_ENDPOINT_PROXY environment variable. If a network attacker can Man-in-the-Middle (MitM) the proxy connection,…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44213">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45575 – epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrast...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45575</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45575</guid>
    <pubDate>Tue, 26 May 2026 21:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45575</strong></p>
  <p>epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker who can MITM the TLS connection between the client and the IDP (within the TI network) can substitute a forged discovery document. The forged document redirects uri_puk_idp_enc and uri_puk_idp_sig to attacker-controlled URLs. The client then encrypts the SMC-B-signed challenge respo…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-347</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45575">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8855 – IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8855</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8855</guid>
    <pubDate>Tue, 26 May 2026 18:16:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8855</strong></p>
  <p>IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mutual authentication (client authentication).</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8855">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48697 – FastNetMon Community Edition through 1.2.9 does not verify TLS certificates on o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48697</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48697</guid>
    <pubDate>Tue, 26 May 2026 17:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48697</strong></p>
  <p>FastNetMon Community Edition through 1.2.9 does not verify TLS certificates on outbound HTTPS connections. The execute_web_request_secure() function in src/fast_library.cpp creates a boost::asio::ssl::context with tls_client mode and calls set_default_verify_paths() to load CA certificates, but never calls set_verify_mode(boost::asio::ssl::verify_peer). Without this call, OpenSSL performs the TLS…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48697">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-47071 – Uncontrolled Resource Consumption vulnerability in benoitc hackney allows Floodi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47071</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47071</guid>
    <pubDate>Mon, 25 May 2026 15:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-47071</strong></p>
  <p>Uncontrolled Resource Consumption vulnerability in benoitc hackney allows Flooding. The SOCKS5 transport in src/hackney_socks5.erl correctly applies the caller-supplied timeout to the SOCKS5 negotiation phase, but then upgrades the connection to TLS using the two-argument form ssl:connect/2, which defaults to an infinite timeout. The Timeout value is in scope at the call site but is not forwarded…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47071">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-48249 – Open ISES Tickets before 3.44.2 disables TLS certificate verification in rm/incs...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48249</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48249</guid>
    <pubDate>Thu, 21 May 2026 18:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-48249</strong></p>
  <p>Open ISES Tickets before 3.44.2 disables TLS certificate verification in rm/incs/mobile_login.inc.php by setting CURLOPT_SSL_VERIFYPEER to false (and not setting CURLOPT_SSL_VERIFYHOST) when issuing outbound HTTPS requests issued during the mobile (RouteMate) login flow. An attacker positioned on the network path between the server and the remote endpoint can present a forged certificate to inter…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48249">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-48248 – Open ISES Tickets before 3.44.2 disables TLS certificate verification in incs/lo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48248</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48248</guid>
    <pubDate>Thu, 21 May 2026 18:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-48248</strong></p>
  <p>Open ISES Tickets before 3.44.2 disables TLS certificate verification in incs/login.inc.php by setting CURLOPT_SSL_VERIFYPEER to false (and not setting CURLOPT_SSL_VERIFYHOST) when issuing outbound HTTPS requests issued during the login/authentication flow. An attacker positioned on the network path between the server and the remote endpoint can present a forged certificate to intercept, monitor,…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48248">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-48247 – Open ISES Tickets before 3.44.2 disables TLS certificate verification in incs/fu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48247</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48247</guid>
    <pubDate>Thu, 21 May 2026 18:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-48247</strong></p>
  <p>Open ISES Tickets before 3.44.2 disables TLS certificate verification in incs/functions.inc.php by setting CURLOPT_SSL_VERIFYPEER to false (and not setting CURLOPT_SSL_VERIFYHOST) when issuing outbound HTTPS requests for general-purpose outbound HTTPS requests issued by the shared helper functions. An attacker positioned on the network path between the server and the remote endpoint can present a…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48247">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-48246 – Open ISES Tickets before 3.44.2 disables TLS certificate verification in ajax/re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48246</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48246</guid>
    <pubDate>Thu, 21 May 2026 18:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-48246</strong></p>
  <p>Open ISES Tickets before 3.44.2 disables TLS certificate verification in ajax/reports.php by setting CURLOPT_SSL_VERIFYPEER to false (and not setting CURLOPT_SSL_VERIFYHOST) when issuing outbound HTTPS requests for Google Maps Directions API lookups during incident report generation. An attacker positioned on the network path between the server and the remote endpoint can present a forged certifi…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48246">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9133 – Active debug code exists in the ARN resolver of amazon-mq rabbitmq-aws before ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9133</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9133</guid>
    <pubDate>Wed, 20 May 2026 20:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9133</strong></p>
  <p>Active debug code exists in the ARN resolver of amazon-mq rabbitmq-aws before version 0.2.1. A debug ARN scheme (arn:aws-debug:file) accepted by the PUT /api/aws/arn/validate validation endpoint might allow remote authenticated users to perform arbitrary file reads on any file accessible to the RabbitMQ process.     To remediate this issue, customers should upgrade to version 0.2.1 of rabbitmq-aw…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-489</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9133">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-14575 – An Uncontrolled Search Path Element vulnerability in the OpenSSL TLS backend of ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14575</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14575</guid>
    <pubDate>Tue, 19 May 2026 14:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-14575</strong></p>
  <p>An Uncontrolled Search Path Element vulnerability in the OpenSSL TLS backend of Qt Network (qtbase) in Qt Qt Framework (Unix) allows a local attacker to load a rogue CA certificate as a trusted system authority via a crafted certificate file placed in the application's working directory.</p>
  <p><strong>CVSS:</strong> 1.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14575">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23998 – Fleet is open source device management software. Prior to version 4.81.0, a vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23998</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23998</guid>
    <pubDate>Thu, 14 May 2026 19:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23998</strong></p>
  <p>Fleet is open source device management software. Prior to version 4.81.0, a vulnerability in Fleet’s Windows MDM management endpoint could allow requests to be processed without proper client certificate validation. In certain circumstances, this could allow an attacker to impersonate an enrolled Windows device and retrieve sensitive configuration data. Fleet’s Windows MDM management endpoint rel…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23998">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44363 – MISP modules are autonomous modules that can be used to extend MISP for new serv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44363</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44363</guid>
    <pubDate>Wed, 13 May 2026 20:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44363</strong></p>
  <p>MISP modules are autonomous modules that can be used to extend MISP for new services. Prior to 3.0.7, an unsafe remote resource fetching vulnerability existed in MISP Modules expansion modules. The html_to_markdown module accepted arbitrary HTTP(S) URLs without sufficient validation, which could allow Server-Side Request Forgery against loopback, private, or link-local network resources. Addition…</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44363">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8367 – aria2c accepts a server certificate with incorrect Extended Key Usage (EKU). If ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8367</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8367</guid>
    <pubDate>Wed, 13 May 2026 16:17:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8367</strong></p>
  <p>aria2c accepts a server certificate with incorrect Extended Key Usage (EKU). If the attackers compromise a certificate (with the associated private key) issued for a different purpose, they may be able to reuse it for TLS server authentication.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8367">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-7009 – When curl is told to use the Certificate Status Request TLS extension, often
ref...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7009</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7009</guid>
    <pubDate>Wed, 13 May 2026 13:01:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-7009</strong></p>
  <p>When curl is told to use the Certificate Status Request TLS extension, often referred to as *OCSP stapling*, to verify that the server certificate is valid, it fails to detect OCSP problems and instead wrongly consider the response as fine.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7009">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-4873 – A vulnerability exists where a connection requiring TLS incorrectly reuses an
ex...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4873</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4873</guid>
    <pubDate>Wed, 13 May 2026 13:01:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-4873</strong></p>
  <p>A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection pool. If an initial transfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request to that same host bypasses the TLS requirement and instead transmit data unencrypted.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4873">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44305 – Lemur manages TLS certificate creation. Prior to 1.9.0, when LDAP TLS is enabled...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44305</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44305</guid>
    <pubDate>Tue, 12 May 2026 22:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44305</strong></p>
  <p>Lemur manages TLS certificate creation. Prior to 1.9.0, when LDAP TLS is enabled (LDAP_USE_TLS = True), Lemur's LDAP authentication module unconditionally disables TLS certificate verification at the global ldap module level. This allows a man-in-the-middle attacker positioned between Lemur and the LDAP server to intercept all authentication credentials. This vulnerability is fixed in 1.9.0.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44305">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44304 – Lemur manages TLS certificate creation. Prior to 1.9.0, Lemur's LDAP authenticat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44304</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44304</guid>
    <pubDate>Tue, 12 May 2026 22:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44304</strong></p>
  <p>Lemur manages TLS certificate creation. Prior to 1.9.0, Lemur's LDAP authentication module (lemur/auth/ldap.py) constructs LDAP search filters using unsanitized user input via Python string interpolation. An authenticated LDAP user can inject LDAP filter metacharacters through the username field to manipulate group membership queries and escalate their privileges to administrator. This vulnerabil…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44304">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44296 – Deskflow is a keyboard and mouse sharing app. Prior to 1.26.0.167, a remote, una...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44296</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44296</guid>
    <pubDate>Tue, 12 May 2026 22:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44296</strong></p>
  <p>Deskflow is a keyboard and mouse sharing app. Prior to 1.26.0.167, a remote, unauthenticated denial of service (DoS) vulnerability affects Deskflow servers running with TLS enabled (the default). When any TCP peer connects to the listening port and its first bytes do not parse as a valid TLS ClientHello, SecureSocket::secureAccept enters its fatal-error branch and calls Arch::sleep(1) (a blocking…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44296">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-45185 – Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45185</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45185</guid>
    <pubDate>Tue, 12 May 2026 20:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-45185</strong></p>
  <p>Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CHUNKING transfer, followed by a final cleartext byte on the same TCP connection. This can lead to heap corruption. An unauthenticated network attacker exploiting this vulnerability could execute arbit…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45185">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-44219 – ciguard is a static security auditor for CI/CD pipelines. From 0.6.0 to 0.8.1, b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44219</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44219</guid>
    <pubDate>Tue, 12 May 2026 20:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-44219</strong></p>
  <p>ciguard is a static security auditor for CI/CD pipelines. From 0.6.0 to 0.8.1, both SCA HTTP clients (src/ciguard/analyzer/sca/osv.py and src/ciguard/analyzer/sca/endoflife.py) call payload = json.loads(resp.read().decode('utf-8')) without a maximum-bytes cap. A hostile or compromised endoflife.date / OSV.dev (or a successful TLS MITM) could return a multi-GB response, exhausting the ciguard proc…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44219">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33603 – Attacker can use a specially crafted base64 exchange between Dovecot and Client ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33603</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33603</guid>
    <pubDate>Tue, 12 May 2026 14:17:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33603</strong></p>
  <p>Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This requires that the attacker is able to position itself between Dovecot and the client connection. If successful, the attacker can eavesdrop communications between Dovecot and client as MITM proxy. Install fixed version. No publicly available exploits are known.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-99</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33603">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45001 – OpenClaw before 2026.4.20 contains a guard bypass vulnerability in the agent-fac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45001</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45001</guid>
    <pubDate>Mon, 11 May 2026 18:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45001</strong></p>
  <p>OpenClaw before 2026.4.20 contains a guard bypass vulnerability in the agent-facing gateway config.patch and config.apply endpoints that fails to protect operator-trusted settings including sandbox policy, plugin enablement, gateway auth/TLS, hook routing, MCP server configuration, SSRF policy, and filesystem hardening. A prompt-injected model with access to the owner-only gateway tool can persis…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45001">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42312 – pyLoad is a free and open-source download manager written in Python. Prior to 0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42312</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42312</guid>
    <pubDate>Mon, 11 May 2026 18:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42312</strong></p>
  <p>pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API method (@permission(Perms.SETTINGS)) in src/pyload/core/api/__init__.py gates security-sensitive options behind a hand-maintained allowlist ADMIN_ONLY_CORE_OPTIONS. The option ("general", "ssl_verify") is not on that allowlist. Any authenticated user with the non-admin SETTINGS…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42312">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1677 – Zephyr sockets created with `IPPROTO_TLS_1_3` can still negotiate a TLS 1.2 conn...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1677</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1677</guid>
    <pubDate>Mon, 11 May 2026 06:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1677</strong></p>
  <p>Zephyr sockets created with `IPPROTO_TLS_1_3` can still negotiate a TLS 1.2 connection when both TLS versions are enabled in Kconfig, because the socket-level protocol selection is not propagated to mbedTLS (e.g. via `mbedtls_ssl_conf_min_tls_version`). The ClientHello advertises both versions and the peer can establish TLS 1.2, so applications that assumed `IPPROTO_TLS_1_3` enforces TLS 1.3 may…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-757</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1677">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42246 – Net::IMAP implements Internet Message Access Protocol (IMAP) client functionalit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42246</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42246</guid>
    <pubDate>Sat, 09 May 2026 20:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42246</strong></p>
  <p>Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4, a man-in-the-middle attacker can cause Net::IMAP#starttls to return "successfully", without starting TLS. This issue has been patched in versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42246">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42225 – PJSIP is a free and open source multimedia communication library written in C. P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42225</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42225</guid>
    <pubDate>Thu, 07 May 2026 20:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42225</strong></p>
  <p>PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, on GnuTLS builds, the SIP TLS transport (sip_transport_tls) can accept connections with invalid or untrusted certificates even when the application explicitly enables certificate verification via verify_server = PJ_TRUE or verify_client = PJ_TRUE. This issue has been patched in version 2.17.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42225">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-40243 – Incus is a system container and virtual machine manager. In versions before 7.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40243</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40243</guid>
    <pubDate>Wed, 06 May 2026 21:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-40243</strong></p>
  <p>Incus is a system container and virtual machine manager. In versions before 7.0.0, broken TLS validation logic in the OVN database connection logic can allow connections to an attacker's OVN database. The OVN client implementations disable Go standard TLS server verification and replace it with custom peer-certificate verification logic. That replacement verifier does not anchor trust in the conf…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40243">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6860 – A TCP client can perform a TLS handshake and present the server name extension w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6860</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6860</guid>
    <pubDate>Wed, 06 May 2026 10:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6860</strong></p>
  <p>A TCP client can perform a TLS handshake and present the server name extension with a server name that is accepted by a server wildcard name, e.g. if the server is configured with a certificate accepting *.example.com, any XYZ.example.com where xyz is a valid name can be used.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6860">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7776 – Boundary Community Edition and Boundary Enterprise (“Boundary”) workers are vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7776</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7776</guid>
    <pubDate>Mon, 04 May 2026 22:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7776</strong></p>
  <p>Boundary Community Edition and Boundary Enterprise (“Boundary”) workers are vulnerable to a denial-of-service condition during node enrollment TLS handshakes. An attacker with network access to the worker authentication listener may open a connection and delay or withhold the client certificate during the TLS handshake, causing worker connection handling to block. This may prevent legitimate work…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7776">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0073 – In adbd_tls_verify_cert of auth.cpp, there is a possible bypass of wireless ADB ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0073</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0073</guid>
    <pubDate>Mon, 04 May 2026 18:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0073</strong></p>
  <p>In adbd_tls_verify_cert of auth.cpp, there is a possible bypass of wireless ADB mutual authentication due to a logic error in the code. This could lead to remote (proximal/adjacent) code execution as the shell user with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-303</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0073">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-39807 – Reliance on Untrusted Inputs in a Security Decision vulnerability in mtrudel ban...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39807</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39807</guid>
    <pubDate>Fri, 01 May 2026 21:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-39807</strong></p>
  <p>Reliance on Untrusted Inputs in a Security Decision vulnerability in mtrudel bandit allows unauthenticated transport-state spoofing on plaintext HTTP connections.  'Elixir.Bandit.Pipeline':determine_scheme/2 in lib/bandit/pipeline.ex returns the client-supplied URI scheme verbatim, ignoring the transport's secure? flag. HTTP/1.1 absolute-form request targets (e.g. GET https://victim/path HTTP/1.1…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-807</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39807">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-3832 – A flaw was found in gnutls. A remote attacker could exploit this vulnerability b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3832</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3832</guid>
    <pubDate>Thu, 30 Apr 2026 18:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-3832</strong></p>
  <p>A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly accept a revoked server certificate, potentially leading to a compromise of trust.</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-179</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3832">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-41016 – Apache Airflow's SMTP provider `SmtpHook` called Python's `smtplib.SMTP.starttls...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41016</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41016</guid>
    <pubDate>Thu, 30 Apr 2026 10:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-41016</strong></p>
  <p>Apache Airflow's SMTP provider `SmtpHook` called Python's `smtplib.SMTP.starttls()` without an SSL context, so no certificate validation was performed on the TLS upgrade. A man-in-the-middle between the Airflow worker and the SMTP server could present a self-signed certificate, complete the STARTTLS upgrade, and capture the SMTP credentials sent during the subsequent `login()` call. Users are adv…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41016">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6528 – TLS protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 allows denial o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6528</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6528</guid>
    <pubDate>Thu, 30 Apr 2026 07:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6528</strong></p>
  <p>TLS protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 allows denial of service</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-835</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6528">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5402 – TLS protocol dissector heap overflow in Wireshark 4.6.0 to 4.6.4 allows denial o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5402</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5402</guid>
    <pubDate>Thu, 30 Apr 2026 07:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5402</strong></p>
  <p>TLS protocol dissector heap overflow in Wireshark 4.6.0 to 4.6.4 allows denial of service and possible code execution</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5402">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1858 – wget2 accepts a server certificate with incorrect Key Usage (KU) or Extended Key...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1858</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1858</guid>
    <pubDate>Wed, 29 Apr 2026 21:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1858</strong></p>
  <p>wget2 accepts a server certificate with incorrect Key Usage (KU) or Extended Key Usage (EKU). If the attackers compromise a certificate (with the associated private key) issued for a different purpose, they may be able to reuse it for TLS server authentication.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1858">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-10539 – Due to improper TLS certificate validation in the DeskTime Time Tracking App bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10539</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10539</guid>
    <pubDate>Tue, 28 Apr 2026 09:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-10539</strong></p>
  <p>Due to improper TLS certificate validation in the DeskTime Time Tracking App before version 1.3.674, attackers who can position themselves in the network path between the client and the DeskTime update servers can return a malicious executable in response to an update request. This allows the attacker to achieve user-level remote code execution on the affected client.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10539">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-41369 – OpenClaw before 2026.3.31 contains insufficient environment variable sanitizatio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41369</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41369</guid>
    <pubDate>Tue, 28 Apr 2026 00:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-41369</strong></p>
  <p>OpenClaw before 2026.3.31 contains insufficient environment variable sanitization in host exec operations, failing to filter package, registry, Docker, compiler, and TLS override variables. Attackers can exploit this by injecting malicious environment variables to override critical system configurations and compromise host execution integrity.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41369">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-41081 – Improper Handling of TLS Client Authentication Failure Leading to Anonymous Prin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41081</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41081</guid>
    <pubDate>Mon, 27 Apr 2026 14:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-41081</strong></p>
  <p>Improper Handling of TLS Client Authentication Failure Leading to Anonymous Principal Assignment in Apache Storm  Versions Affected: up to 2.8.7  Description: When TLS transport is enabled in Apache Storm without requiring client certificate authentication (the default configuration), the TlsTransportPlugin assigns a fallback principal (CN=ANONYMOUS) if no client certificate is presented or if ce…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41081">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-40557 – Improper Certificate Validation via Global SSL Context Downgrade in Apache Storm...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40557</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40557</guid>
    <pubDate>Mon, 27 Apr 2026 14:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-40557</strong></p>
  <p>Improper Certificate Validation via Global SSL Context Downgrade in Apache Storm Prometheus Reporter   Versions Affected: from 2.6.3 to 2.8.6   Description:   In production deployments where an administrator enables storm.daemon.metrics.reporter.plugin.prometheus.skip_tls_validation (by default it is disabled) intending to affect only the Prometheus reporter, the undocumented global side effect c…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40557">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-6986 – A security vulnerability has been detected in Cesanta Mongoose up to 7.20. This ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6986</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6986</guid>
    <pubDate>Sat, 25 Apr 2026 17:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-6986</strong></p>
  <p>A security vulnerability has been detected in Cesanta Mongoose up to 7.20. This issue affects the function mg_aes_gcm_decrypt of the file /src/tls_aes128.c of the component GCM Authentication Tag Handler. Such manipulation leads to improper verification of cryptographic signature. The attack may be performed from remote. A high complexity level is associated with this attack. The exploitability i…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-345</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6986">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-41319 – MailKit is a cross-platform mail client library built on top of MimeKit. A START...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41319</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41319</guid>
    <pubDate>Fri, 24 Apr 2026 04:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-41319</strong></p>
  <p>MailKit is a cross-platform mail client library built on top of MimeKit. A STARTTLS Response Injection vulnerability in versions prior to 4.16.0 allows a Man-in-the-Middle attacker to inject arbitrary protocol responses across the plaintext-to-TLS trust boundary, enabling SASL authentication mechanism downgrade (e.g., forcing PLAIN instead of SCRAM-SHA-256). The internal read buffer in `SmtpStrea…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41319">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-25874 – LeRobot through 0.5.1 contains an unsafe deserialization vulnerability in the as...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25874</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25874</guid>
    <pubDate>Thu, 23 Apr 2026 20:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-25874</strong></p>
  <p>LeRobot through 0.5.1 contains an unsafe deserialization vulnerability in the async inference pipeline where pickle.loads() is used to deserialize data received over unauthenticated gRPC channels without TLS in the policy server and robot client components. An unauthenticated network-reachable attacker can achieve arbitrary code execution on the server or client by sending a crafted pickle payloa…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25874">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-31533 – In the Linux kernel, the following vulnerability has been resolved:

net/tls: fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31533</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31533</guid>
    <pubDate>Thu, 23 Apr 2026 18:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-31533</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption  The -EBUSY handling in tls_do_encryption(), introduced by commit 859054147318 ("net: tls: handle backlogging of crypto requests"), has a use-after-free due to double cleanup of encrypt_pending and the scatterlist entry.  When crypto_aead_encrypt() returns -EB…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31533">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-33596 – A client might theoretically be able to cause a mismatch between queries sent to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33596</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33596</guid>
    <pubDate>Wed, 22 Apr 2026 14:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-33596</strong></p>
  <p>A client might theoretically be able to cause a mismatch between queries sent to a backend and the received responses by sending a flood of perfectly timed queries that are routed to a TCP-only or DNS over TLS backend.</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33596">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-40944 – Oxia is a metadata store and coordination system. Prior to 0.16.2, the trustedCe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40944</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40944</guid>
    <pubDate>Tue, 21 Apr 2026 22:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-40944</strong></p>
  <p>Oxia is a metadata store and coordination system. Prior to 0.16.2, the trustedCertPool() function in the TLS configuration only parses the first PEM block from CA certificate files. When a CA bundle contains multiple certificates (e.g., intermediate + root CA), only the first certificate is loaded. This silently breaks certificate chain validation for mTLS. This vulnerability is fixed in 0.16.2.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40944">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-40606 – mitmproxy is a interactive TLS-capable intercepting HTTP proxy for penetration t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40606</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40606</guid>
    <pubDate>Tue, 21 Apr 2026 18:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-40606</strong></p>
  <p>mitmproxy is a interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers and mitmweb is a web-based interface for mitmproxy. In mitmproxy 12.2.1 and below, the builtin LDAP proxy authentication does not correctly sanitize the username when querying the LDAP server. This allows a malicious client to bypass authentication. Only mitmproxy instances using the pro…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40606">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-40594 – pyLoad is a free and open-source download manager written in Python. Prior to 0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40594</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40594</guid>
    <pubDate>Tue, 21 Apr 2026 18:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-40594</strong></p>
  <p>pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev98, the set_session_cookie_secure before_request handler in src/pyload/webui/app/__init__.py reads the X-Forwarded-Proto header from any HTTP request without validating that the request originates from a trusted proxy, then mutates the global Flask configuration SESSION_COOKIE_SECURE on every request. Because…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-346</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40594">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-41330 – OpenClaw before 2026.3.31 contains an environment variable override vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41330</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41330</guid>
    <pubDate>Tue, 21 Apr 2026 00:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-41330</strong></p>
  <p>OpenClaw before 2026.3.31 contains an environment variable override vulnerability in host exec policy that fails to properly enforce proxy, TLS, Docker, and Git TLS controls. Attackers can bypass security controls by overriding environment variables to circumvent proxy settings, TLS verification, Docker restrictions, and Git TLS enforcement.</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-453</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41330">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32105 – xrdp is an open source RDP server. In versions through 0.10.5, xrdp does not imp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32105</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32105</guid>
    <pubDate>Fri, 17 Apr 2026 20:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32105</strong></p>
  <p>xrdp is an open source RDP server. In versions through 0.10.5, xrdp does not implement verification for the Message Authentication Code (MAC) signature of encrypted RDP packets when using the "Classic RDP Security" layer. While the sender correctly generates signatures, the receiving logic lacks the necessary implementation to validate the 8-byte integrity signature, causing it to be silently ign…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-354</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32105">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-5052 – Vault’s PKI engine’s ACME validation did not reject local targets when issuing h...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5052</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5052</guid>
    <pubDate>Fri, 17 Apr 2026 04:16:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-5052</strong></p>
  <p>Vault’s PKI engine’s ACME validation did not reject local targets when issuing http-01 and tls-alpn-01 challenges. This may lead to these requests being sent to local network targets, potentially leading to information disclosure. Fixed in Vault Community Edition 2.0.0 and Vault Enterprise 2.0.0, 1.21.5, 1.20.10, and 1.19.16.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5052">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41113 – sagredo qmail before 2026.04.07 allows tls_quit remote code execution because of...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41113</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41113</guid>
    <pubDate>Thu, 16 Apr 2026 22:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41113</strong></p>
  <p>sagredo qmail before 2026.04.07 allows tls_quit remote code execution because of popen in notlshosts_auto in qmail-remote.c.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41113">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-6264 – A critical vulnerability in the Talend JobServer and Talend Runtime allows unaut...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6264</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6264</guid>
    <pubDate>Tue, 14 Apr 2026 03:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-6264</strong></p>
  <p>A critical vulnerability in the Talend JobServer and Talend Runtime allows unauthenticated remote code execution via the JMX monitoring port. The attack vector is the JMX monitoring port of the Talend JobServer. The vulnerability can be mitigated for the Talend JobServer by requiring TLS client authentication for the monitoring port; however, the patch must be applied for full mitigation. For Tal…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6264">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34478 – Apache Log4j Core's  Rfc5424Layout https://logging.apache.org/log4j/2.x/manual/l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34478</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34478</guid>
    <pubDate>Fri, 10 Apr 2026 16:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34478</strong></p>
  <p>Apache Log4j Core's  Rfc5424Layout https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layout , in versions 2.21.0 through 2.25.3, is vulnerable to log injection via CRLF sequences due to undocumented renames of security-relevant configuration attributes.  Two distinct issues affect users of stream-based syslog services who configure Rfc5424Layout directly:    *  The newLineEscape att…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-117</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34478">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-34477 – The fix for  CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34477</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34477</guid>
    <pubDate>Fri, 10 Apr 2026 16:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-34477</strong></p>
  <p>The fix for  CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161  was incomplete: it addressed hostname verification only when enabled via the  log4j2.sslVerifyHostName https://logging.apache.org/log4j/2.x/manual/systemproperties.html#log4j2.sslVerifyHostName  system property, but not when configured through the  verifyHostName https://logging.apache.org/log4j/2.x/manual/append…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-297</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34477">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39304 – Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39304</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39304</guid>
    <pubDate>Fri, 10 Apr 2026 11:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39304</strong></p>
  <p>Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ.  ActiveMQ NIO SSL transports do not correctly handle TLSv1.3 handshake KeyUpdates triggered by clients. This makes it possible for a client to rapidly trigger updates which causes the broker to exhaust all its memory in the SSL engine leading to DoS.  Note: TLS versions before TLS…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39304">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5501 – wolfSSL_X509_verify_cert in the OpenSSL compatibility layer accepts a certificat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5501</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5501</guid>
    <pubDate>Fri, 10 Apr 2026 04:17:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5501</strong></p>
  <p>wolfSSL_X509_verify_cert in the OpenSSL compatibility layer accepts a certificate chain in which the leaf's signature is not checked, if the attacker supplies an untrusted intermediate with Basic Constraints `CA:FALSE` that is legitimately signed by a trusted root. An attacker who obtains any leaf certificate from a trusted CA (e.g. a free DV cert from Let's Encrypt) can forge a certificate for a…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5501">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-5460 – A heap use-after-free exists in wolfSSL's TLS 1.3 post-quantum cryptography (PQC...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5460</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5460</guid>
    <pubDate>Fri, 10 Apr 2026 00:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-5460</strong></p>
  <p>A heap use-after-free exists in wolfSSL's TLS 1.3 post-quantum cryptography (PQC) hybrid KeyShare processing. In the error handling path of TLSX_KeyShare_ProcessPqcHybridClient() in src/tls.c, the inner function TLSX_KeyShare_ProcessPqcClient_ex() frees a KyberKey object upon encountering an error. The caller then invokes TLSX_KeyShare_FreeAll(), which attempts to call ForceZero() on the already-…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5460">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-5448 – X.509 date buffer overflow in wolfSSL_X509_notAfter / wolfSSL_X509_notBefore. A ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5448</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5448</guid>
    <pubDate>Fri, 10 Apr 2026 00:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-5448</strong></p>
  <p>X.509 date buffer overflow in wolfSSL_X509_notAfter / wolfSSL_X509_notBefore. A buffer overflow may occur when parsing date fields from a crafted X.509 certificate via the compatibility layer API. This is only triggered when calling these two APIs directly from an application, and does not affect TLS or certificate verify operations in wolfSSL.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5448">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-5778 – Integer underflow in wolfSSL packet sniffer &lt;= 5.9.0 allows an attacker to cause...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5778</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5778</guid>
    <pubDate>Thu, 09 Apr 2026 22:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-5778</strong></p>
  <p>Integer underflow in wolfSSL packet sniffer <= 5.9.0 allows an attacker to cause a program crash in the AEAD decryption path by injecting a TLS record shorter than the explicit IV plus authentication tag into traffic inspected by ssl_DecodePacket. The underflow wraps a 16-bit length to a large value that is passed to AEAD decryption routines, causing a large out-of-bounds read and crash. An unaut…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-191</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5778">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5446 – In wolfSSL, ARIA-GCM cipher suites used in TLS 1.2 and DTLS 1.2 reuse an identic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5446</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5446</guid>
    <pubDate>Thu, 09 Apr 2026 21:16:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5446</strong></p>
  <p>In wolfSSL, ARIA-GCM cipher suites used in TLS 1.2 and DTLS 1.2 reuse an identical 12-byte GCM nonce for every application-data record. Because wc_AriaEncrypt is stateless and passes the caller-supplied IV verbatim to the MagicCrypto SDK with no internal counter, and because the explicit IV is zero-initialized at session setup and never incremented in non-FIPS builds. This vulnerability affects w…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-323</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5446">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-35207 – dde-control-center is the control panel of DDE, the Deepin Desktop Environment. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35207</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35207</guid>
    <pubDate>Thu, 09 Apr 2026 18:17:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-35207</strong></p>
  <p>dde-control-center is the control panel of DDE, the Deepin Desktop Environment. plugin-deepinid is a plugin in dde-control-center, which provides the deepinid cloud service. Prior to 6.1.80, plugin-deepinid is configured to skip TLS certificate verification when fetching the user's avatar from openapi.deepin.com or other providers. An MITM attacker could intercept the traffic, replace the avatar…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35207">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1584 – A flaw was found in gnutls. A remote, unauthenticated attacker can exploit this ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1584</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1584</guid>
    <pubDate>Thu, 09 Apr 2026 18:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1584</strong></p>
  <p>A flaw was found in gnutls. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted ClientHello message with an invalid Pre-Shared Key (PSK) binder value during the TLS handshake. This can lead to a NULL pointer dereference, causing the server to crash and resulting in a remote Denial of Service (DoS) condition.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1584">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-34179 – In Canonical LXD versions 4.12 through 6.7, the doCertificateUpdate function in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34179</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34179</guid>
    <pubDate>Thu, 09 Apr 2026 10:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-34179</strong></p>
  <p>In Canonical LXD versions 4.12 through 6.7, the doCertificateUpdate function in lxd/certificates.go does not validate the Type field when handling PUT/PATCH requests to /1.0/certificates/{fingerprint} for restricted TLS certificate users, allowing a remote authenticated attacker to escalate privileges to cluster admin.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-915</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34179">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39863 – Kamailio is an open source implementation of a SIP Signaling Server. Prior to 6...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39863</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39863</guid>
    <pubDate>Wed, 08 Apr 2026 20:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39863</strong></p>
  <p>Kamailio is an open source implementation of a SIP Signaling Server. Prior to 6.1.1, 6.0.6, and 5.8.8, an out-of-bounds access in the core of Kamailio (formerly OpenSER and SER) allows remote attackers to cause a denial of service (process crash) via a specially crafted data packet sent over TCP. The issue impacts Kamailio instances having TCP or TLS listeners. This vulnerability is fixed in 5.1.…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39863">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-4837 – An eval() injection vulnerability in the Rapid7 Insight Agent beaconing logic fo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4837</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4837</guid>
    <pubDate>Wed, 08 Apr 2026 17:21:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-4837</strong></p>
  <p>An eval() injection vulnerability in the Rapid7 Insight Agent beaconing logic for Linux versions could theoretically allow an attacker to achieve remote code execution as root via a crafted beacon response. Because the Agent uses mutual TLS (mTLS) to verify commands from the Rapid7 Platform, it is unlikely that the eval() function could be exploited remotely without prior, highly privileged acces…</p>
  <p><strong>CVSS:</strong> 6.6 · <strong>CWE:</strong> CWE-95</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4837">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32283 – If one side of the TLS connection sends multiple key update messages post-handsh...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32283</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32283</guid>
    <pubDate>Wed, 08 Apr 2026 02:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32283</strong></p>
  <p>If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32283">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32280 – During chain building, the amount of work that is done is not correctly limited ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32280</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32280</guid>
    <pubDate>Wed, 08 Apr 2026 02:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32280</strong></p>
  <p>During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32280">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-34582 – Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34582</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34582</guid>
    <pubDate>Tue, 07 Apr 2026 22:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-34582</strong></p>
  <p>Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records to be processed prior to the Finished message being received. A server which is attempting to enforce client authentication via certificates can by bypassed by a client which entirely omits Certificate, CertificateVerify, and the Finished message and instead sends application d…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-841</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34582">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28386 – Issue summary: Applications using AES-CFB128 encryption or decryption on
systems...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28386</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28386</guid>
    <pubDate>Tue, 07 Apr 2026 22:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28386</strong></p>
  <p>Issue summary: Applications using AES-CFB128 encryption or decryption on systems with AVX-512 and VAES support can trigger an out-of-bounds read of up to 15 bytes when processing partial cipher blocks.  Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application if the input buffer ends at a memory page boundary and the following page is unmappe…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28386">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39312 – SoftEtherVPN is a an open-source cross-platform multi-protocol VPN Program. In 5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39312</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39312</guid>
    <pubDate>Tue, 07 Apr 2026 17:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39312</strong></p>
  <p>SoftEtherVPN is a an open-source cross-platform multi-protocol VPN Program. In 5.2.5188 and earlier, a pre-authentication denial-of-service vulnerability exists in SoftEther VPN Developer Edition 5.2.5188 (and likely earlier versions of Developer Edition). An unauthenticated remote attacker can crash the vpnserver process by sending a single malformed EAP-TLS packet over raw L2TP (UDP/1701), term…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-789</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39312">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32144 – Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32144</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32144</guid>
    <pubDate>Tue, 07 Apr 2026 13:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32144</strong></p>
  <p>Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_ocsp module) allows OCSP designated-responder authorization bypass via missing signature verification.  The OCSP response validation in public_key:pkix_ocsp_validate/5 does not verify that a CA-designated responder certificate was cryptographically signed by the issuing CA. Instead, it only checks that the responder ce…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32144">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33752 – curl_cffi is the a Python binding for curl. Prior to 0.15.0, curl_cffi does not ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33752</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33752</guid>
    <pubDate>Mon, 06 Apr 2026 16:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33752</strong></p>
  <p>curl_cffi is the a Python binding for curl. Prior to 0.15.0, curl_cffi does not restrict requests to internal IP ranges, and follows redirects automatically via the underlying libcurl. Because of this, an attacker-controlled URL can redirect requests to internal services such as cloud metadata endpoints. In addition, curl_cffi’s TLS impersonation feature can make these requests appear as legitima…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33752">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-4986 – Hirschmann EagleSDV version 05.4.01 prior to 05.4.02 contains a denial-of-servic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-4986</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-4986</guid>
    <pubDate>Thu, 02 Apr 2026 22:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-4986</strong></p>
  <p>Hirschmann EagleSDV version 05.4.01 prior to 05.4.02 contains a denial-of-service vulnerability that causes the device to crash during session establishment when using TLS 1.0 or TLS 1.1. Attackers can trigger a crash by initiating TLS connections with these protocol versions to disrupt service availability.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-4986">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-14033 – Hirschmann EagleSDV firmware prior to 05.4.02 contains a denial-of-service vulne...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-14033</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-14033</guid>
    <pubDate>Thu, 02 Apr 2026 21:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-14033</strong></p>
  <p>Hirschmann EagleSDV firmware prior to 05.4.02 contains a denial-of-service vulnerability in TLS session establishment. Attackers can crash the device during TLS handshake by exploiting protocol downgrades to TLS 1.0 or TLS 1.1, interrupting service availability.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-14033">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-34877 – An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34877</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34877</guid>
    <pubDate>Thu, 02 Apr 2026 17:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-34877</strong></p>
  <p>An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insufficient protection of serialized SSL context or session structures allows an attacker who can modify the serialized structures to induce memory corruption, leading to arbitrary code execution. This is caused by Incorrect Use of Privileged APIs.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34877">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34876 – An issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34876</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34876</guid>
    <pubDate>Thu, 02 Apr 2026 16:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34876</strong></p>
  <p>An issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read vulnerability in mbedtls_ccm_finish() in library/ccm.c allows attackers to obtain adjacent CCM context data via invocation of the multipart CCM API with an oversized tag_len parameter. This is caused by missing validation of the tag_len parameter against the size of the internal 16-byte authentication buffer. The issue af…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34876">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31931 – Suricata is a network IDS, IPS and NSM engine. From version 8.0.0 to before vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31931</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31931</guid>
    <pubDate>Thu, 02 Apr 2026 14:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31931</strong></p>
  <p>Suricata is a network IDS, IPS and NSM engine. From version 8.0.0 to before version 8.0.4, use of the "tls.alpn" rule keyword can cause Suricata to crash with a NULL dereference. This issue has been patched in version 8.0.4.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31931">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23414 – In the Linux kernel, the following vulnerability has been resolved:

tls: Purge ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23414</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23414</guid>
    <pubDate>Thu, 02 Apr 2026 12:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23414</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  tls: Purge async_hold in tls_decrypt_async_wait()  The async_hold queue pins encrypted input skbs while the AEAD engine references their scatterlist data. Once tls_decrypt_async_wait() returns, every AEAD operation has completed and the engine no longer references those skbs, so they can be freed unconditionally.  A subsequent p…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23414">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-5246 – A vulnerability was determined in Cesanta Mongoose up to 7.20. Affected is the f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5246</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5246</guid>
    <pubDate>Thu, 02 Apr 2026 10:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-5246</strong></p>
  <p>A vulnerability was determined in Cesanta Mongoose up to 7.20. Affected is the function mg_tls_verify_cert_signature of the file mongoose.c of the component P-384 Public Key Handler. Executing a manipulation can lead to authorization bypass. The attack can be executed remotely. Attacks of this nature are highly complex. The exploitability is told to be difficult. The exploit has been publicly dis…</p>
  <p><strong>CVSS:</strong> 5.6 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5246">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5244 – A vulnerability has been found in Cesanta Mongoose up to 7.20. This affects the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5244</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5244</guid>
    <pubDate>Thu, 02 Apr 2026 08:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5244</strong></p>
  <p>A vulnerability has been found in Cesanta Mongoose up to 7.20. This affects the function mg_tls_recv_cert of the file mongoose.c of the component TLS 1.3 Handler. Such manipulation of the argument pubkey leads to heap-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 7.21 mitigates this issue. The name of…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5244">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-34873 – An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation ca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34873</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34873</guid>
    <pubDate>Wed, 01 Apr 2026 21:17:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-34873</strong></p>
  <p>An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34873">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
