Уязвимости, исследования и мониторинг сообществ

Единая лента из публичных источников: каталоги уязвимостей (CISA KEV, NVD, GitHub Advisories), вендорские бюллетени и учебные разборы значимых уязвимостей.

342
записей в ленте
266
критичных и высоких
30 сент. 2026 г.
дата снапшота
342
после фильтров

Мои ключевые слова

nginx: 0kubernetes: 0kerberos: 0openssl: 1chrome: 0windows: 27linux: 0
GitHub AdvisorieshighCVE-2026-102281уязвимости
GHSA-m8vh-jmq9-5rjg: Nest: Remote process termination via a deeply nested microservice message pattern
| Field | Value | | --- | --- | | Ecosystem | npm | | Package | `@nestjs/microservices` | | Affected versions | `>= 12.0.0, < 12.0.2` and `< 11.2.4` | | Patched versions | `12.0.2` and `11.2.4` (upgrade to `12.0.3` / `11.2.5`) | ### Summary A single message whose `pattern` is a deeply nested object terminates a NestJS microservice that us
29 сент. 2026 г.
GitHub AdvisoriesmediumCVE-2026-86472уязвимости
GHSA-hrr3-gc8f-f4qj: fast-uri vulnerable to inconsistent host case normalization via percent-encoded octets
### Impact `fast-uri` folds the host to lowercase before it percent-decodes the host, so a percent-encoded uppercase unreserved octet such as `%41` decodes to a literal `A` that is never folded. For a scheme-relative reference (`//host`) there is no scheme, so the host canonicalization that repairs this on a scheme-bearing URL does not ru
29 сент. 2026 г.
GitHub AdvisoriesmediumCVE-2026-86818уязвимости
GHSA-jvvf-x445-j334: fast-uri vulnerable to mailto header injection via percent-encoded field-name desynchronization
### Impact `fast-uri`'s `mailto` scheme parser compares each query field name to the reserved names (`to`, `subject`, `body`) while the name is still percent-encoded, and only percent-decodes it when storing it as a generic header. On serialize, the decoded name is re-emitted, so a field name such as `%74o` (percent-encoded `to`) is not r
29 сент. 2026 г.
GitHub AdvisoriescriticalCVE-2026-101894уязвимости
GHSA-hrh2-vp3x-79xf: @xhmikosr/decompress: Path traversal via symlink chain
### Impact When extracting an untrusted archive with the default `decompress(input, output)` API, a crafted archive containing a chain of symlink entries can make a later entry resolve **outside** the output directory. The lexical containment checks pass, but the kernel follows the planted symlinks to a path outside `output`, letting an a
29 сент. 2026 г.
GitHub AdvisoriesmediumCVE-2026-101912уязвимости
GHSA-j6r3-76f7-8jcv: ip-address: isInSubnet() and isHostInSubnet() compare addresses of different families as if they shared an address space, allowing an allowlist check to admit an address outside its range
### Summary `isInSubnet()` and `isHostInSubnet()` accept an address of either family and compare masked binary strings without checking that both operands are the same family. `Address4` pads to 32 bits and `Address6` to 128, so whenever the leading bits agree the strings are equal: `new Address6('a00::1').isInSubnet(new Address4('10.0.0.
29 сент. 2026 г.
GitHub AdvisoriesmediumCVE-2026-101911уязвимости
GHSA-h3mg-xc3c-68pw: ip-address: Address6 builds a parse diagnostic proportional to the input with no length bound, allowing a single long string to stall or crash the process
### Summary `new Address6()` and `Address6.isValid()` place no bound on the length of the string they parse. When the string contains a character that cannot appear in an IPv6 address, the parser builds a diagnostic that wraps every such character in a 34-byte `<span class="parse-error">`, so the work and the memory scale with the input r
29 сент. 2026 г.
GitHub AdvisoriesmediumCVE-2026-17495уязвимости
GHSA-4p3w-j4w9-5jqw: moment vulnerable to Path Traversal via crafted non-string locale name
### Impact moment before 2.31.0 is vulnerable to path traversal in `moment.locale()`. When an application passes a non-string, attacker-influenced value to `moment.locale()`, a specially crafted object can bypass the locale name validation and cause moment to load a file from an attacker-controlled path. This is a further bypass of the va
29 сент. 2026 г.
GitHub AdvisoriesmediumCVE-2026-102277уязвимости
GHSA-q2hr-2g5m-vwhr: brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of service
### Summary Expanding `{a},b}`-shaped input takes time quadratic in the number of literal `}` characters, blocking the event loop. Bash preserves a quirk where a brace group followed by a comma set still expands (`{a},b}`). The parser implements this by rewriting the string and restarting the scan. Each pass absorbs exactly one `}` and re
29 сент. 2026 г.
GitHub AdvisorieshighCVE-2026-102278уязвимости
GHSA-qhr7-859c-m2p7: brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion
### Summary `expand_()` recurses once per level of brace *nesting*. Deeply nested input exhausts the native stack and crashes the process. This is distinct from CVE-2026-14257 / GHSA-mh99-v99m-4gvg, which made the *tail* iterative (recursion on `m.post`, driven by how many groups are chained). Nesting depth drives a different recursion th
29 сент. 2026 г.
GitHub AdvisorieshighCVE-2026-102276уязвимости
GHSA-6j4f-fj2g-mc7p: brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion
### Summary `parseCommaParts()` can exhaust the native stack and crash the process. There are two distinct ways to trigger it, both reachable from a single untrusted pattern string. This is the parsing-side counterpart to CVE-2026-14257 / GHSA-mh99-v99m-4gvg. That fix made `expand_()` iterative and documented a constant-stack-depth guaran
29 сент. 2026 г.
GitHub AdvisorieshighCVE-2026-102599уязвимости
GHSA-2gc4-cqfq-p2gv: Socket.IO: Engine.IO Protocol Revision Mismatch DoS
### Impact A denial-of-service vulnerability exists in Engine.IO / Socket.IO servers that allow transport upgrades. The Engine.IO protocol revision is negotiated during the initial handshake and stored on the session, but a newly-created transport, including a WebSocket upgrade transport, could independently derive a different protocol re
29 сент. 2026 г.
GitHub Advisoriesmediumуязвимости
GHSA-g57g-f23g-4646: Nodemailer: Quoted local-part can produce malformed envelope recipient through RFC 5322 comment parsing
## Summary Nodemailer's address parser can produce an unexpected recipient address when an RFC 5322 comment follows the domain of an address whose local-part is a quoted string. For example: ```text "user"@example.com(x)evil.com ``` is parsed as: ```text { address: "user@example.com evil.com", name: "" } ``` The resulting address therefor
29 сент. 2026 г.
GitHub Advisorieshighуязвимости
GHSA-v53p-9fqp-m79j: Nodemailer: Quadratic backtracking in the addressparser free-text fallback allows remote denial of service
### Summary When `addressparser` finds no address by its strict reading, it falls back to pulling one out of the free text with `/\s*\b[^@\s]+@[^\s]+\b\s*/`. That pattern backtracks quadratically: `[^@\s]+` is retried from every offset and rescans the run to the next `@` each time. A single header value holding a long whitespace-free run
29 сент. 2026 г.
GitHub AdvisorieshighCVE-2026-102266уязвимости
GHSA-9j54-fg26-wv3r: PyJWT: PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation
### Summary A service that verifies HS256 tokens using an empty oct JWK through PyJWK, including a PyJWK obtained from PyJWKSet, can therefore accept attacker-generated tokens as authenticated. PyJWT 2.13.0 rejects an empty HMAC key when it is supplied through the raw `str`/`bytes` key path, but accepts the same zero-length key when it is
29 сент. 2026 г.
GitHub AdvisoriesmediumCVE-2026-102265уязвимости
GHSA-8wjv-2p76-3863: PyJWT: Uncaught RecursionError in jwt.decode() on deeply nested token header
## Package pyjwt (PyPI) ## Affected versions tested & verified on: 2.13.0. Every version whose `PyJWS._load()` translates only `ValueError` is affected ## Description `PyJWS._looad()` (`jwt/api_jws.py:337`) splits the compact token, base64url decodes the header segment and hands it to `json.loads()` before `_verify_signature()` runs. The
29 сент. 2026 г.
GitHub AdvisoriesmediumCVE-2026-102269уязвимости
GHSA-hxm8-2xgr-2p9m: PyJWT: Non-canonical signature segments enable raw-token revocation bypass
## Summary PyJWT 2.13.0 accepts compact JWS signature segments containing characters that are not in the Base64URL alphabet. Appending `!!!!` to a valid signature does not change the decoded signature bytes or authenticated claims, but it changes the serialized token and its SHA-256 hash. An application that indexes logout or revocation s
29 сент. 2026 г.
GitHub AdvisoriescriticalCVE-2026-102268уязвимости
GHSA-ffc3-869f-jxw9: PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip the HS/asymmetric confusion guard
**Prerequisites** (both conditions must hold; both are deployment properties, not attacker-controlled at request time): - The `jwt.decode` allow-list mixes an HMAC algorithm with an asymmetric one, e.g. `algorithms=["ES256", "HS256"]` (the RFC 8725 footgun the guard exists to backstop). - The verification key is passed as raw PEM text/byt
29 сент. 2026 г.
GitHub AdvisorieshighCVE-2026-102273уязвимости
GHSA-w2cx-738m-mc7w: PyJWT accepts public JWK containers as HMAC secrets
### Summary PyJWT 2.13.0 contains an incomplete defense against algorithm confusion when an application mixes symmetric and asymmetric algorithms in one verification path. A public RSA, EC, or OKP JWK can be accepted as an HMAC secret when it is wrapped in a JWKS object, nested in an array, or represented in another container form that do
29 сент. 2026 г.
GitHub AdvisorieshighCVE-2026-102267уязвимости
GHSA-9v7f-9g4p-ffgj: PyJWT: PyJWKClient follows redirects when fetching JWKS
### Summary PyJWT 2.13.0 `PyJWKClient` followed HTTP redirects while fetching a JWKS, without validating the redirect destination. A configured trusted endpoint could therefore redirect the client to a different host. ### Impact When an application uses `PyJWKClient` with caller-supplied request headers and an attacker can influence the c
29 сент. 2026 г.
GitHub AdvisorieshighCVE-2026-102271уязвимости
GHSA-p4g4-x82p-q773: PyJWT: Public keys in DER form are accepted as HMAC secrets, bypassing the CVE-2022-29217 guard
### Summary `HMACAlgorithm.prepare_key` blocks asymmetric keys from being used as HMAC secrets by searching for text markers only. It looks for `-----BEGIN` and for an `ssh-` prefix. The same key in DER form is binary ASN.1 and has neither marker, so it passes the check and is used as an HMAC secret. An application that verifies tokens wi
29 сент. 2026 г.
GitHub AdvisorieshighCVE-2026-102272уязвимости
GHSA-r6x4-923q-g947: PyJWT BOM Bypass
## Affected Package - **Package**: PyJWT (`pyjwt` on PyPI) - **Repository**: https://www.google.com/url?q=https://github.com/jpadilla/pyjwt&source=gmail&ust=1781794518474000&sa=E - **Affected version**: 2.13.0 - **Vulnerability class**: Algorithm confusion / patch bypass --- ## Root Cause PyJWT 2.13.0 introduced a guard in `HMACAlgorithm.
29 сент. 2026 г.
GitHub AdvisoriesmediumCVE-2026-101917уязвимости
GHSA-2gx3-rcp4-g85q: PyJWT: PyJWKClient still amplifies unauthenticated JWKS fetches on unknown kid values (incomplete fix of CVE-2026-48524)
Summary CVE-2026-48524 (GHSA-fhv5-28vv-h8m8, "PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)") was fixed in 2.13.0 by stopping fetch_data() from clearing the cache on a fetch error. That closed one amplification path but did not add the mitigation the advisory's title implies: there is still no rate-
29 сент. 2026 г.
GitHub Advisoriesmediumуязвимости
GHSA-p634-w6r4-rjp2: adm-zip: Duplicate ZIP entry names: getEntry() and extractAllTo() resolve to different content
### Summary A ZIP file can contain two entries with the identical name. adm-zip keeps both in its internal entry list, but its name-lookup table only retains the last one written. `getEntry(name)` and `extractAllTo()` walk these two different internal structures, so they can each resolve a duplicate name to a *different* entry. An applica
29 сент. 2026 г.
GitHub Advisoriesmediumуязвимости
GHSA-c6fg-446q-cg94: adm-zip: getDataAsync() bypasses the maxOutputLength size guard enforced by the synchronous getData() path
### Summary adm-zip enforces a `maxOutputLength` guard against decompression bombs on its synchronous `getData()` path, but the equivalent asynchronous `getDataAsync()` path does not enforce it — it accumulates and returns the entire decompressed output regardless of the entry's declared size. An application that checks an entry's declare
29 сент. 2026 г.
GitHub Advisorieshighуязвимости
GHSA-8238-w5pm-2374: adm-zip: Unhandled error event in async DEFLATE decompression crashes Node.js process (DoS)
## Summary Denial of Service in `adm-zip`'s async decompression API allows an unauthenticated attacker to crash the entire Node.js host process by supplying a single malformed ZIP file. ## Details **Affected package**: adm-zip **Affected versions**: at least 0.6.0 (current latest); likely all versions containing the current `inflateAsync`
29 сент. 2026 г.
GitHub AdvisoriesmediumCVE-2026-102342уязвимости
GHSA-m6mh-2hw2-555x: Ammonia: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The following SVG will produce a link with a `javascript` scheme. If the user clicks this link, they will run it. ```svg <svg xmlns="http://www.w3.org/2000/svg"> <a> <set attributeName="href" to="javascript:alert('SET_XSS')"></set> <text y="30">Click set</text> </a> </svg> ``` ### Impact Allows stored XSS in applications that allow the `a
29 сент. 2026 г.
GitHub Advisorieshighуязвимости
GHSA-rcw4-f5rp-g42v: adm-zip: Decompression-bomb protection (fix for CVE-2026-39244) can be bypassed by declaring uncompressed size as 0
**Affected package:** adm-zip (npm) **Affected version:** 0.6.0 ## Summary The fix shipped for CVE-2026-39244 (`methods/inflater.js`) caps zlib's decompression output via `maxOutputLength: expectedLength`, where `expectedLength` is read directly from the ZIP entry's attacker-controlled "uncompressed size" header field (`CENLEN`/`LOCLEN`).
29 сент. 2026 г.
GitHub AdvisorieshighCVE-2026-102282уязвимости
GHSA-j5f4-cc29-5x44: adm-zip extraction preserves SUID/SGID bits from untrusted ZIPs -> local privilege escalation
## Summary adm-zip applies the Unix permission bits stored in a zip entry directly to the extracted file via `fs.chmodSync()` when `keepOriginalPermission=true` is passed to `extractAllTo()`/`extractEntryTo()` — and it never filters the setuid/setgid/sticky bits out of those bits. A zip crafted by an attacker can therefore produce an extr
29 сент. 2026 г.
GitHub AdvisorieslowCVE-2026-102279уязвимости
GHSA-jh5r-qr3c-85q8: Laravel: XSS in Debug Page Information
### Impact When `APP_DEBUG=true`, attacker-controlled input is passed to a Tippy.js tooltip configured with `allowHTML: true`, enabling DOM-based XSS during mouse hover. ### Patches [#61381](https://github.com/laravel/framework/pull/61381)
29 сент. 2026 г.
GitHub Advisoriesmediumуязвимости
GHSA-8vvx-rff5-p5rq: Nodemailer: Nested structured recipient arrays bypass the parser depth limit and cause stack exhaustion DoS
## Submission metadata | Field | Value | |---|---| | Ecosystem | npm | | Package | `nodemailer` | | Repository | https://github.com/nodemailer/nodemailer | | Tested commit | `40d52215aac65b811d7e131bc916f68605efd9d2` | | Current tested version | `10.0.1` | | Confirmed vulnerable versions | `2.7.2`, `3.0.0`, `7.0.11`, `9.1.1`, `10.0.1` | |
29 сент. 2026 г.
GitHub AdvisoriesmediumCVE-2026-102274уязвимости
GHSA-w6j9-cwv2-h6wq: PyJWT: Malformed RSA JWK aborts parsing of an entire JWK Set
## Summary A malformed RSA JWK inside a JWK Set aborts parsing of the entire set instead of being skipped, because `RSAAlgorithm.from_jwk` can raise a plain `ValueError` that isn't caught by `PyJWKSet`'s per-key error-skipping logic. ## Affected component / version - Package: `PyJWT` (PyPI, ecosystem `pip`) - Files: `jwt/api_jwk.py` (`PyJ
29 сент. 2026 г.
GitHub AdvisoriesmediumCVE-2026-18149уязвимости
GHSA-pmjh-fq2x-6v4x: undici vulnerable to Denial of Service via orphaned RetryHandler response body
### Impact undici's `RetryHandler` can leave a response body pending indefinitely. When a retried request receives a non-retryable response after a truncated one, the original `response.body` held by the application is never settled, so reads such as `response.body.text()` hang and `bodyTimeout` does not fire. A malicious server can repea
29 сент. 2026 г.
GitHub AdvisorieslowCVE-2026-18540уязвимости
GHSA-r53p-7pc4-xj5r: undici vulnerable to downstream response splitting via retry interceptor
### Impact Undici's `interceptors.retry()` can resume a request after a partial response and append the resumed bytes to an already partially delivered body, while the application still receives the original response's status and headers. When that response carried a `Content-Length`, the application can receive a longer body. Application
29 сент. 2026 г.
GitHub AdvisorieshighCVE-2026-19534уязвимости
GHSA-rfgv-xxqx-mfg5: undici vulnerable to Denial of Service via unrequested WebSocket subprotocol
### Impact The undici WebSocket client throws an uncaught `TypeError` during the opening handshake when a server's `101` response includes a `Sec-WebSocket-Protocol` header that the client never requested. The throw occurs in a `queueMicrotask` callback with no surrounding `try`/`catch`, so it propagates as an uncaught exception and termi
29 сент. 2026 г.
GitHub AdvisoriesmediumCVE-2026-84890уязвимости
GHSA-3xpg-4rpp-hhhm: undici vulnerable to Denial of Service via unbounded decompression of compressed responses
### Impact The `interceptors.decompress()` interceptor decompresses HTTP response bodies according to the untrusted `Content-Encoding` header. The number of decompression layers is capped at 5, but the total decompressed output size is not bounded and there is no option to limit it. A malicious or faulty upstream can return a small compre
29 сент. 2026 г.
GitHub AdvisoriesmediumCVE-2026-84933уязвимости
GHSA-2jfj-6hjv-fm6j: undici vulnerable to cross-user cookie disclosure via Set-Cookie caching in shared caches
### Impact undici's `interceptors.cache()` does not handle `Set-Cookie` in the cache path. In shared-cache mode (`type: 'shared'`, the default), a cacheable response (for example `Cache-Control: public, max-age=...`) carrying a `Set-Cookie` header is stored, and the stored `Set-Cookie` is re-served to a later caller that hits the same cac
29 сент. 2026 г.
GitHub AdvisorieslowCVE-2026-84947уязвимости
GHSA-2gqq-gqf2-x968: undici vulnerable to response truncation via oversized chunked responses in the dump interceptor
### Impact undici's `interceptors.dump()` reads and discards response bodies up to a configurable `maxSize`. When a response declares a `Content-Length` that exceeds `maxSize`, the request is aborted cleanly. When a response is sent chunked (no `Content-Length`) and its body exceeds `maxSize`, it is not aborted: the interceptor ends the r
29 сент. 2026 г.
GitHub AdvisorieshighCVE-2026-84961уязвимости
GHSA-w293-vg96-wgc3: undici vulnerable to TLS certificate validation bypass via dropped connect options in BalancedPool
### Impact undici's `BalancedPool` passes its constructor options through a JSON-based deep clone (`JSON.parse(JSON.stringify(...))`) before forwarding them to each per-upstream `Pool`. JSON cannot represent functions, so a caller-supplied `connect` or `tls` option containing a `checkServerIdentity` callback (or a custom connector functio
29 сент. 2026 г.
GitHub AdvisorieslowCVE-2026-85008уязвимости
GHSA-8436-99hf-9mmv: undici vulnerable to caching and replay of unsafe HTTP method responses
### Impact undici's `interceptors.cache()` documents that it caches only safe HTTP methods. However, its internal skip-list is built by subtracting the configured methods from the safe-methods set, so an unsafe method (`POST`, `PUT`, `PATCH`, `DELETE`) never lands in the skip-list and is looked up against the cache store. Combined with th
29 сент. 2026 г.
GitHub AdvisorieshighCVE-2026-85152уязвимости
GHSA-vp8m-p9jh-q5pm: undici vulnerable to cross-origin cache poisoning via missing origin isolation in interceptors
## Impact When `interceptors.cache()` or `interceptors.deduplicate()` is used with a dispatcher that does not carry a single authoritative origin, or when a request supplies its own `origin`, undici builds the cache and deduplication keys without the actual destination origin. If a cache store or interceptor instance is shared across more
29 сент. 2026 г.
GitHub AdvisoriesmediumCVE-2026-85014уязвимости
GHSA-rx4f-c7p8-82vq: undici vulnerable to Denial of Service via WebSocketStream unclean close
## Impact undici's `WebSocketStream` crashes the client process when a WebSocket connection is closed abruptly without a close handshake. On such an unclean close, the internal socket-close handler calls `abort()` on the writable stream even when the application holds a writer lock. Per the WHATWG Streams standard, aborting a locked strea
29 сент. 2026 г.
GitHub AdvisorieslowCVE-2026-102601уязвимости
GHSA-cxf4-7mrp-vvpr: Flysystem: WhitespacePathNormalizer's control-character (CorruptedPathDetected) check is bypassed by malformed UTF-8 in the path, affecting every adapter
## Related public issue (context, not a duplicate) Closed issue #1429 ("Handle non-UTF-8 paths", 2024-03-24) raised exactly this general concern and even suggested detection via `preg_match('//u', $path) !== 1` -- note the reporter's suggested check explicitly compares `!== 1`, which *would* correctly treat PCRE's `false` return as "rejec
29 сент. 2026 г.
GitHub Advisorieshighуязвимости
GHSA-6h2x-m376-mqjq: joi: Quadratic regular-expression backtracking in `Joi.string().isoDate()`
### Impact Any application that validates a user-supplied string with `Joi.string().isoDate()` can be stalled by a single request. One of the regular expressions the rule runs over the input was unanchored, so a valid ISO date followed by a long run of fractional-second digits made the regex engine restart its search from every position i
29 сент. 2026 г.
GitHub AdvisoriesmediumCVE-2026-102672уязвимости
GHSA-vv43-5jgx-7qv8: Electron: Local race condition in Squirrel.Mac update installation on macOS
### Impact On macOS, Electron bundles the Squirrel.Mac auto-update framework, whose privileged `ShipIt` helper performs the final step of an update as root. A local attacker could cause that helper to overwrite a different application's files, as root, instead of the app that started the update. Exploitation requires local access to the m
29 сент. 2026 г.
GitHub AdvisorieshighCVE-2026-102673уязвимости
GHSA-hq2x-r82h-9wj4: Electron drops inherited HTML sandbox restrictions for popups opened through OpenURLFromTab
### Impact Popups opened from a sandboxed iframe through a link (for example `target="_blank"` or a middle-click) did not inherit the iframe's HTML `sandbox` restrictions. Content that was meant to run sandboxed could open a popup with the embedding app's full origin, gaining access to that origin's cookies, storage, and same-origin scrip
29 сент. 2026 г.
GitHub AdvisorieshighCVE-2026-102674windowsуязвимости
GHSA-gr2m-v5gq-v685: Electron: Windows opened from a sandboxed top-level document do not inherit its sandbox restrictions
### Impact Windows opened from a sandboxed top-level document did not inherit that document's HTML `sandbox` restrictions, so content that was meant to run sandboxed could open a window with the app's full origin. GHSA-hq2x-r82h-9wj4 covers the same issue for sandboxed iframes. Apps are only affected if they render untrusted content in a
29 сент. 2026 г.
GitHub AdvisorieshighCVE-2026-102675windowsуязвимости
GHSA-j84w-jfhq-vhvj: Electron: File and HTTP protocol handlers allow cross-origin reads without corsEnabled
### Impact Responses served through `protocol.registerFileProtocol` or `protocol.registerHttpProtocol` for a custom scheme registered with `supportFetchAPI: true` but without `corsEnabled: true` could be read cross-origin by web content. This completes the fix for CVE-2026-70604. Apps are only affected if they register such a scheme, serv
29 сент. 2026 г.
GitHub AdvisorieshighCVE-2026-102676уязвимости
GHSA-9qh4-3jw8-366w: Electron: <webview> can enable Node.js integration in Web Workers despite embedder restrictions
### Impact A `<webview>` could enable Node.js integration in its Web Workers even when its embedder had Node.js integration disabled, giving guest content more privilege than the embedder allowed. Apps are only affected if they enable the `<webview>` tag and the embedder is unsandboxed. Apps that do not use `<webview>`, or that keep the e
29 сент. 2026 г.
GitHub AdvisorieshighCVE-2026-102677уязвимости
GHSA-qmv3-fv6v-rmhq: Electron: Sandboxed preload code cache can be poisoned by a compromised renderer
### Impact The cache Electron keeps for sandboxed preload scripts did not verify that a cached entry matched the preload it was served for. A compromised renderer could use this to run its own code in the preload context on a later load. Apps are only affected if they load untrusted content. Apps that do not load untrusted content are not
29 сент. 2026 г.
GitHub AdvisoriesmediumCVE-2026-81872уязвимости
GHSA-hjf4-fphr-2h65: OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full
### Summary A `BatchingProcessor` in `go.opentelemetry.io/otel/sdk/log` can enter a tight CPU loop when the asynchronous export buffer is full. Under exporter backpressure, attacker-driven high-volume log emission can keep the queue at or above the batch size, causing repeated immediate export retries and a denial of service through CPU e
29 сент. 2026 г.
GitHub AdvisoriesmediumCVE-2026-81869уязвимости
GHSA-p9f8-wvj8-2fg8: OpenTelemetry-Go: UTF-8 replacement rune bypasses attribute length truncation
### Summary The OpenTelemetry Go SDK trace package can fail to enforce `AttributeValueLengthLimit` for string attributes containing the valid Unicode replacement character U+FFFD. An oversized attacker-controlled attribute value that includes U+FFFD is returned untruncated, bypassing the configured memory/DoS protection and allowing incre
29 сент. 2026 г.
GitHub Advisoriesmediumуязвимости
GHSA-253c-mchw-3w2r: markdown-it linkify: true has two quadratic paths, so a few hundred KB of markdown blocks the event loop for tens of seconds
## Summary Two independent quadratic paths in the `linkify: true` handling. Both are in markdown-it's own code rather than in linkify-it, which stays linear on both payloads. `src/rules_core/linkify.ts` calls `arrayReplaceAt` once per linkified text token, and that rebuilds the whole `children` array each time. A paragraph of N soft-broke
29 сент. 2026 г.
GitHub Advisoriesmediumуязвимости
GHSA-r3ph-w7gj-g6xm: js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources
## Summary `maxTotalMergeKeys` does not count empty mappings. An attacker can repeatedly merge a large sequence of them and consume significant CPU without reaching the configured limit. ## Example ```yaml arr: &arr [{}, {}, {}, ...] # N empty mappings targets: - <<: *arr # repeated K times ``` For every target, the loader iterates all `N
29 сент. 2026 г.
GitHub AdvisorieshighCVE-2026-65954уязвимости
GHSA-r6hr-vr92-vv28: PHPCSUtils: Remote code execution via eval() in AbstractArrayDeclarationSniff::getActualArrayKey()
### Impact PHPCSUtils versions 1.0.0-alpha1 through 1.2.2 contain an arbitrary code execution vulnerability in `PHPCSUtils\AbstractSniffs\AbstractArrayDeclarationSniff::getActualArrayKey()`. The vulnerable method is reached by any sniff that extends `AbstractArrayDeclarationSniff` and calls `getActualArrayKey()`. Running PHPCS over untrus
29 сент. 2026 г.
GitHub AdvisoriesmediumCVE-2026-49265уязвимости
GHSA-xpv3-w29h-x7cv: Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)
## Summary A timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation of the Authorization Code Grant flow. The `code_challenge_method_plain` function uses Python's standard `==` operator for string comparison instead of a constant-time comparison function, potentially allowing timing-based attacks. ## Affected Compo
29 сент. 2026 г.
GitHub AdvisoriesmediumCVE-2026-49264уязвимости
GHSA-hj66-6f7g-4r5v: Oauthlib : Unsafe JSONP callback injection in RevocationEndpoint allows arbitrary JavaScript response generation
### Summary When `enable_jsonp=True`, oauthlib's `RevocationEndpoint` reflects the user-supplied `callback` parameter directly into JavaScript response bodies on both success and error paths without validating that it is a legal JSONP callback name. This allows arbitrary JavaScript response generation instead of a restricted function call
29 сент. 2026 г.
GitHub AdvisorieshighCVE-2026-76844уязвимости
GHSA-g84c-rxfj-3j2c: webpack-dev-middleware vulnerable to Path Traversal via non-slash-terminated publicPath
> [!IMPORTANT] > CVE-2026-76844 was assigned and published for this issue by VulnCheck on 2026-08-24 without prior coordination with the webpack maintainers or the OpenJS Foundation, which holds the CVE Numbering Authority scope for webpack projects. Neither the maintainers nor the OpenJS CNA were notified before publication, and no fix w
29 сент. 2026 г.
GitHub Advisoriesmediumуязвимости
GHSA-6vj9-mwq6-2f5v: Nodemailer: Process-global DNS cache reuses TLS `servername` across transports, enabling cross-tenant SMTP credential disclosure
### Summary Nodemailer's process-global DNS cache is keyed only by `host`, but each cache entry also stores the caller-specific TLS `servername`. When two direct SMTPS transports use the same DNS host with different `tls.servername` values, the first transport's server name is returned to the second transport and overwrites its explicitly
28 сент. 2026 г.
GitHub AdvisoriesmediumCVE-2026-85024уязвимости
GHSA-3wwx-pv8p-q78v: undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression
## Impact undici's WebSocket client (including Node.js's bundled `globalThis.WebSocket`) crashes the entire Node.js process when a remote WebSocket peer sends a permessage-deflate compressed message that crosses the decompressed-payload size limit and then contains a malformed DEFLATE block. In `lib/web/websocket/permessage-deflate.js`, t
28 сент. 2026 г.
GitHub AdvisoriesmediumCVE-2026-88932уязвимости
GHSA-3pph-fpjx-jg34: multer vulnerable to Denial of Service via orphaned disk writes on aborted uploads
### Impact Multer's `diskStorage` can leave complete, orphaned files on disk when a multipart upload is aborted in the brief window before the storage engine assigns the file path. This is an incomplete fix of CVE-2026-5038: the earlier cleanup removes only in-flight uploads that already have a path, so an upload aborted inside that windo
28 сент. 2026 г.
GitHub AdvisoriesmediumCVE-2026-87859уязвимости
GHSA-9f6g-j8ch-79g4: morgan vulnerable to Log Injection via unescaped double quote in quoted log fields
### Impact Morgan writes attacker-controlled request data to the access log. Its escaping (added in 1.11.0 and 1.12.0) neutralizes control characters, the Unicode line separators, and backslash, but not the double quote (`0x22`), which is the field delimiter of the Apache combined log format morgan emits. An attacker who controls a quoted
28 сент. 2026 г.
GitHub AdvisorieshighCVE-2026-101895уязвимости
GHSA-f67j-2jqw-jpq7: Angular SSR: Denial of Service (DoS) via Infinite Loop on Malformed DOCTYPE
A Denial of Service (DoS) vulnerability exists in `@angular/platform-server`'s DOM emulation parser (`domino`). When processing untrusted user input containing an incomplete DOCTYPE declaration ending with whitespace before EOF (such as `<!DOCTYPE html `), the HTML parser enters an infinite synchronous loop, pegging CPU utilization at 100
28 сент. 2026 г.
GitHub AdvisorieshighCVE-2026-84292уязвимости
GHSA-qw65-cvwx-89v3: fast-uri vulnerable to authority injection via an unvalidated port in serialize
### Impact `fast-uri` serializes the `port` component of a URI without validating it. When recomposing the authority, `fast-uri` escapes the userinfo and host components but concatenates the port verbatim, so a `port` value that is not a sequence of digits can inject authority delimiters. For example, serializing a component whose `port`
28 сент. 2026 г.
GitHub AdvisorieshighCVE-2026-84394уязвимости
GHSA-58mr-gqgx-xq4g: fast-uri vulnerable to host confusion via an unclosed bracket in the URI authority
### Impact `fast-uri` accepts a host that contains an unbalanced or misplaced authority bracket (`[` or `]`) without reporting an error. A host that starts with `[` but does not end with `]`, such as `[@127.0.0.1`, is neither validated as an IP literal nor canonicalized as a domain name, so `parse()` returns it as the host with `error` un
28 сент. 2026 г.
GitHub AdvisoriesmediumCVE-2026-83557уязвимости
GHSA-gx83-3vf8-gh7j: jackson-databind: Comparable missing from DefaultBaseTypeLimitingValidator's unsafe base types (incomplete PolymorphicTypeValidator denylist)
### Summary `DefaultBaseTypeLimitingValidator` — the `PolymorphicTypeValidator` used automatically whenever `@JsonTypeInfo` is applied without an explicitly configured custom validator — denies polymorphic resolution only for nine specific "unsafe base types" (`Object`, `Serializable`, `Closeable`, `AutoCloseable`, `Cloneable`, `Runnable`
28 сент. 2026 г.
GitHub AdvisoriesmediumCVE-2026-101913уязвимости
GHSA-rpw4-54j3-4h4q: ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SSRF and trust-boundary bypass to on-link hosts
### Summary `Address6.isLinkLocal()` recognizes `fe80::/64` rather than `fe80::/10`. Link-local unicast is the whole `/10` under RFC 4291 §2.4 and the IANA IPv6 Special-Purpose Address Registry, so the method returns `false` for every link-local address outside the one `/64` that stateless address autoconfiguration happens to use. `new Ad
28 сент. 2026 г.
GitHub AdvisoriesmediumCVE-2026-101910уязвимости
GHSA-2vr4-cq9g-pvrc: ip-address: no classifier recognizes the NAT64 local-use range 64:ff9b:1::/48, allowing SSRF and trust-boundary bypass
### Summary No classifier on `Address6` recognizes the NAT64 local-use range `64:ff9b:1::/48` (RFC 8215). `isPrivate()`, `isLoopback()`, `isLinkLocal()` and their siblings all return `false` for every address in it, so an internal IPv4 destination written through a local-use NAT64 prefix (`64:ff9b:1:7f00:0:100::` for `127.0.0.1`, `64:ff9b
28 сент. 2026 г.
GitHub AdvisorieshighCVE-2026-88058уязвимости
GHSA-j3r3-mxqp-r2p4: Angular SSR: XSS via Unescaped Processing Instruction (<?...?>) Nodes in Fallback Raw-Content Elements
### Summary An XSS vulnerability exists in `@angular/platform-server` during server-side rendering (SSR) HTML serialization of `ProcessingInstruction` DOM nodes (`<?target data?>`, `nodeType === 7`) when nested inside fallback raw-content elements (`<noscript>`, `<iframe>`, `<noembed>`, `<noframes>`). While processing instruction data esc
28 сент. 2026 г.
GitHub AdvisorieshighCVE-2026-68497уязвимости
GHSA-q4xh-88c3-wmh7: jackson-databind: Duration XMLGregorianCalendar Unbounded Number Parse DoS
### Summary `jackson-databind` 3.2.1 deserializes a JSON **string** bound to a `javax.xml.datatype.Duration` or `javax.xml.datatype.XMLGregorianCalendar` field by passing the raw string verbatim to `DatatypeFactory.newDuration(value)` / `newXMLGregorianCalendar(value)`. Per the XML-Schema lexical grammar these factory methods accept numer
28 сент. 2026 г.
GitHub AdvisoriesmediumCVE-2026-19032уязвимости
GHSA-wjgm-6hv5-3cvf: jackson-databind: Path Deserialization Missing Scheme Allowlist for FileSystemProvider Resolution
### Summary A `java.nio.file.Path` field bound from untrusted JSON reaches `JDKFromStringDeserializer.NioPathHelper.deserialize`. The attacker string flows through `new URI(value)` → `Path.of(uri)`, then on `FileSystemNotFoundException` into a `ServiceLoader<FileSystemProvider>` enumeration that calls `provider.getPath(uri)` on the first
28 сент. 2026 г.
GitHub AdvisoriesmediumCVE-2026-77310уязвимости
GHSA-vvgp-rfg2-7rr6: jackson-databind: Incomplete fix for CVE-2026-54514: eager DNS resolution (SSRF) still present in InetAddress deserialization
### Summary CVE-2026-54514 (GHSA-hgj6-7826-r7m5) fixed an eager-DNS-resolution / SSRF issue in jackson-databind's deserialization of `java.net.InetSocketAddress` by switching to `InetSocketAddress.createUnresolved(...)` (PR #5951, commit 1f5a1037, released in 2.18.8 / 2.21.4 / 3.1.4). That fix did not cover the sibling `java.net.InetAddre
28 сент. 2026 г.
GitHub AdvisoriesmediumCVE-2026-101914уязвимости
GHSA-88h9-xgvx-hvf2: @grpc/grpc-js: The exact path match matcher incorrectly only applies a prefix match for case-insensitive matches
### Impact When using RBAC to apply authentication rules, the exact path (method name) matcher applies a prefix match instead of an exact match for case-insensitive matches. As a result, if a service has a method with a name that is a prefix of the name of a different method, and they have different access rules, and case-insensitive matc
28 сент. 2026 г.
GitHub AdvisoriesmediumCVE-2026-61834уязвимости
GHSA-2mhw-wcx5-v3xj: scim-patch: Mutation of Inherited Built-in Method Objects
## Summary Incomplete Prototype Pollution Fix Allows Mutation of Inherited Built-in Method Objects `scim-patch` blocks direct dangerous path segments such as `__proto__`, `constructor`, and `prototype`, but still traverses inherited properties when applying SCIM patch paths. An attacker who controls a SCIM PATCH operation can use paths su
28 сент. 2026 г.
GitHub Advisorieshighуязвимости
GHSA-456v-xq2p-r4cj: code-ollama: `grep_search` Command Injection via Unescaped `$()` Shell Substitution (CWE-78)
## `grep_search` Command Injection via Unescaped `$()` Shell Substitution (CWE-78) ### Summary The `grep_search` tool in `code-ollama` constructs a shell command string by interpolating attacker-controlled `pattern` and `path` arguments, then executes it via `child_process.exec()`. The sanitization only escapes backslashes and double-quot
28 сент. 2026 г.
GitHub AdvisorieshighCVE-2026-57443уязвимости
GHSA-q986-4x7x-gx39: SCBE-AETHERMOORE Unauthenticated AetherBrowser Ops API Exposes Operator Email Digests
### Summary The AetherBrowser API server (`scripts/aetherbrowser/api_server.py`) exposes the `POST /api/ops/check-email` endpoint without any authentication. Any remote attacker can call this endpoint and trigger execution of the `email_reader.py` subprocess, which connects to configured ProtonMail or Gmail accounts via IMAP and returns e
25 сент. 2026 г.
GitHub Advisorieshighуязвимости
GHSA-vj8p-hp9x-gh47: mpp vulnerable to Gas Draining with low gas limit
## Vulnerability When the server acts as the fee payer, `mpp` Elixir 0.4.0 (ZenHive/mpp) does not validate whether the `gas_limit` set by the client is enough before broadcasting. A malicious client can drain the server's gas without paying. A `transferWithMemo` call on Tempo Moderato testnet requires **~51,299 gas** to complete successfu
25 сент. 2026 г.
GitHub Advisoriesmediumуязвимости
GHSA-qpxh-ff8m-c62v: mpp vulnerable to Gas Draining with access list
### Details When the server acts as the fee_payer, `mpp` Elixir 0.4.0 copies the client-supplied EIP-2930 access list verbatim into the cosigned fee-payer transaction. In `cosign_fee_payer`, the server re-signs the raw `base_fields` (index 5 of the 0x76 AASigned envelope) without inspecting the access list field, which is part of the sign
25 сент. 2026 г.
GitHub Advisorieshighуязвимости
GHSA-vv77-66rf-pm86: mpp vulnerable to Gas Draining with no limit
### Details When the server acts as the fee_payer, the `mpp` Elixir 0.4.0 does not validate `gas_limit`, `max_fee_per_gas` and `max_priority_fee_per_gas` before cosigning the client's fee-payer transaction. A malicious client embeds arbitrarily large `max_fee_per_gas` and `max_priority_fee_per_gas` values in the signed envelope. The serve
25 сент. 2026 г.
GitHub AdvisorieshighCVE-2026-100368уязвимости
GHSA-wrvw-254r-wpmv: CliInvoke.Specializations has command injection in PowerShell and Cmd shell wrappers
### Impact An OS command injection vulnerability exists in the PowerShell and Cmd shell wrappers provided by the `CliInvoke.Specializations` package (the `PowershellProcessInvoker`/`CmdProcessInvoker` invokers, and the `UsePowerShell`/`UseCmd` middleware in v3 pre-release versions). The wrappers re-run a caller-supplied target and argumen
25 сент. 2026 г.
GitHub AdvisorieshighCVE-2026-100369уязвимости
GHSA-j73w-8hfr-4gc9: CliInvoke: Argument Injection in Extensibility Runner Factory
### Impact An argument-injection vulnerability exists in the `CliInvoke` package's runner factory: `RunnerProcessFactory` on the 2.x line and `RunnerConfigurationFactory` on the 3.x line. The factory joins the runner arguments, the caller's target, and the caller's arguments into a single `ProcessStartInfo.Arguments` string and hands it t
25 сент. 2026 г.
GitHub Advisorieshighуязвимости
GHSA-62mm-xwmv-crhg: khoj has an unauthenticated path traversal in /home/ endpoint that allows file read from server filesystem
### Summary The `/home/{file_path:path}` endpoint in `web_client.py` serves static files by directly concatenating the user-supplied `file_path` with the `home_directory` constant. There is no path traversal filtering, no path normalization check, and no authentication required. An attacker can use `../` sequences to read arbitrary files
25 сент. 2026 г.
GitHub AdvisorieshighCVE-2026-86439уязвимости
GHSA-9gfj-28hw-jchp: Knowns Unrestricted Path Traversal leading to out-of-bounds arbitrary .md file read, write, and deletion in MCP Docs + Memory Tools
## Overview Verified. Multiple **Unrestricted Path Traversal** vulnerabilities exist in the Knowns MCP `docs` and `memory` tools, allowing arbitrary file read, write, and deletion operations outside the project sandbox. The storage layer functions (`Get`, `Create`, `Update`, `Rename`, `Delete`) in both `doc_store.go` and `memory_store.go`
25 сент. 2026 г.
GitHub Advisorieshighуязвимости
GHSA-29h2-jr22-frmh: OpenZeppelin Confidential Contracts `VestingWalletConfidential`: a malicious ERC-7984 token is able to extract private data from the vesting wallet
### Impact Two locations consume an encrypted handle returned by an untrusted external party and use it without verifying that the party is ACL-authorized on it. #### `VestingWalletConfidential` Malicious users can call `release` with a malicious token. This token could return an alternative handle on `confidentialBalanceOf`, which repres
25 сент. 2026 г.
GitHub AdvisoriesmediumCVE-2026-53493уязвимости
GHSA-pg57-6jwg-q645: Containerd has image-pull DoS via crafted OCI index graph amplification
### Impact A vulnerability exists in containerd's image pull handlers where a crafted OCI image index containing deeply nested or heavily fanned-out descriptor graphs can cause unbounded CPU and memory consumption. During the `PullImage` operation, the recursive traversal and processing of child descriptors lack sufficient depth and bread
25 сент. 2026 г.
GitHub AdvisoriescriticalCVE-2026-92161уязвимости
GHSA-g7vj-c29h-3h5m: FriendsOfFlarum OAuth: Unauthenticated account takeover via unverified email trust in Discord OAuth provider
### Impact An unauthenticated account takeover vulnerability exists in `fof/oauth` when the Discord OAuth provider is enabled. Discord allows an account to use an unverified email address when its phone number has been verified. During OAuth authentication, Discord may return that email address with `"verified": false`. Affected versions
25 сент. 2026 г.
GitHub AdvisorieshighCVE-2026-57440уязвимости
GHSA-v65j-hff3-753c: Mediawiki EmbedVideo Extension has stored XSS via malformed src url with $wgEmbedVideoRequireConsent disabled
### Summary With $wgEmbedVideoRequireConsent disabled (not the default), the urls for videos are passed into an iframe src attribute without sanitization. When given a malformed url or id, the src attribute can be escaped via double quotes, allowing for html/javascript injection. ### Details The iframe assembled [here](https://github.com/
25 сент. 2026 г.
GitHub AdvisorieshighCVE-2026-61823уязвимости
GHSA-qxg3-46rw-79j8: code16 Sharp vulnerable to stored XSS via iframe srcdoc Attribute
### Impact A Stored Cross-Site Scripting (XSS) vulnerability exists in the rich text editor due to improper sanitization of the srcdoc attribute on <iframe> elements. While the underlying Symfony HtmlSanitizer correctly HTML-encodes special characters inside the attribute value (e.g., converting <script> to &lt;script&gt;), the HTML speci
25 сент. 2026 г.
GitHub AdvisorieshighCVE-2026-61825уязвимости
GHSA-vj3q-vp3g-j9c8: code16/sharp has a stored XSS via data-html-content Sanitizer Bypass
### Impact The vulnerability allows an attacker to bypass the HTML sanitizer by using the `data-html-content` attribute in the content of a `SharpEditorFormField`. ### Patches The field must now explicitly configure `SharpFormEditorField::RAW_HTML` in the toolbar to keep this behavior. **When using the `RAW_HTML` button, the application u
25 сент. 2026 г.
GitHub AdvisorieslowCVE-2026-57232уязвимости
GHSA-87mg-5grr-rhwh: Contao: Server-Side Request Forgery (SSRF) via Unvalidated RSS Feed URL in Feed Reader Module
### Summary The Feed Reader front-end module passes RSS feed URLs from its configuration directly to `$this->feedIo->read($url)` without any scheme validation or private-IP blocklist. A backend user with module-edit permissions can configure an arbitrary URL pointing to internal network services, cloud-provider metadata endpoints, or loop
24 сент. 2026 г.
GitHub AdvisoriesmediumCVE-2026-57179уязвимости
GHSA-vqg6-3fw6-j9jg: social-auth-core has a Session Fixation issue
### Impact The partial-pipeline resume mechanism accepted `partial_token` as a bearer credential without binding it to the browser session that created it. Applications using resumable partial pipeline steps could allow an attacker to start an authentication flow, obtain a valid partial token and verification data, and cause a victim's br
24 сент. 2026 г.
GitHub AdvisorieshighCVE-2026-57178уязвимости
GHSA-3c93-f73f-qc9h: social-auth-core: VK App backend accepts unsigned callback data when auth_key is missing
### Impact The `vk-app` backend accepted VK application callback data without verifying the callback signature when the `auth_key` parameter was omitted. Applications using this backend could treat unsigned attacker-controlled data as a verified VK identity. An attacker could choose callback fields such as `viewer_id`, `access_token`, `ap
24 сент. 2026 г.
GitHub AdvisoriesmediumCVE-2026-57177уязвимости
GHSA-x7qq-23vw-7pfg: social-auth-core has Login CSRF via Missing State Parameter in LoginRadius Backend
### Impact The LoginRadius backend did not validate OAuth state during the authentication flow. Applications using this backend were vulnerable to login CSRF. An attacker could cause a victim's browser session to complete authentication using an attacker-controlled LoginRadius token, making the victim authenticated as the attacker's Login
24 сент. 2026 г.
GitHub AdvisoriesmediumCVE-2026-57176уязвимости
GHSA-fp7w-m676-w7gc: social-auth-core Vulnerable to Account Takeover via Identity Binding Flaw in Vend Backend
### Impact The Vend OAuth2 backend used only the numeric Vend `user_id` as the social-auth UID. When multiple Vend shops authenticate through the same application, users from different shops with the same internal Vend user ID could collide in the social-auth association table. A user from one shop could then be authenticated as the local
24 сент. 2026 г.
GitHub AdvisoriesmediumCVE-2026-57175уязвимости
GHSA-vq6g-g6c7-5f2j: social-auth-core has an Improper Authentication issue
### Impact The SAML backend accepted SAML responses on the Assertion Consumer Service endpoint without verifying that they matched a previously issued `AuthnRequest`. Applications using SAML account association could allow an attacker with a valid account on a trusted IdP to link the attacker's SAML identity to a logged-in victim's local
24 сент. 2026 г.
GitHub AdvisoriesmediumCVE-2026-55736уязвимости
GHSA-f4hc-ppw9-4hhw: Ash: Private action arguments can be set by user input via string-keyed params and atomic changesets
### Summary Ash fails to consistently strip private action arguments (those declared with `public?: false`) when a changeset is built from an untrusted parameter map. Private arguments are meant to be set only by trusted server-side code, but a caller who controls the parameters supplied to an action can inject a value for one. Any actor
24 сент. 2026 г.
GitHub AdvisorieshighCVE-2026-57171уязвимости
GHSA-r4vp-3vw6-r2x5: Trestle is vulnerable to arbitrary file write via path traversal in author generate commands (Incomplete fix of CVE-2026-46345)
**At a glance** - **Actor:** attacker who controls the -o/--output argument to trestle author {catalog,profile,ssp}-generate (e.g. via a CI pipeline that derives the output directory from repository-controlled data) - **Primitive:** attacker-controlled --output value reaches trestle_root / args.output write sink with only is_directory_nam
24 сент. 2026 г.
GitHub AdvisorieshighCVE-2026-57170уязвимости
GHSA-mr95-65j8-9mxp: Trestle SSTI in Jinja2 include tags allows arbitrary code execution (Incomplete fix of CVE-2026-46439)
Reporter: Cavan Loughran, Celvex Group Inc. Summary ------- The fix for CVE-2026-46439 (3.12.2 / 4.0.3) removed the recursive re-render loop in trestle/core/commands/author/jinja.py render_template, but the custom include tags in trestle/core/jinja/tags.py (MDSectionInclude, MDCleanInclude) still re-parse the CONTENT of an included markdo
24 сент. 2026 г.
GitHub AdvisorieshighCVE-2026-59723уязвимости
GHSA-3cj3-hqcr-g934: Cline: Cross-Origin WebSocket Hijacking in Cline Hub Dashboard (`/browser` endpoint)
### Summary The Cline Hub dashboard server (`@cline/cline-hub`), launched via the `cline dashboard` CLI command, accepts WebSocket connections on the `/browser` endpoint without validating the HTTP `Origin` header. When `ROOM_SECRET` is not set—the default for local (`127.0.0.1`) binds—`isAuthorizedBrowserRequest()` returns `true` uncondi
24 сент. 2026 г.
GitHub AdvisorieshighCVE-2026-61815уязвимости
GHSA-36h5-qg4p-q2qf: zbateson/mail-mime-parser has CRLF header injection via attachment filename
### Impact A CRLF (carriage-return / line-feed) header injection affecting any application that uses this library to build or forward MIME messages with an attacker-influenced attachment filename. Attachment filenames are interpolated into the `Content-Type` and `Content-Disposition` header values without stripping CR/LF, so a filename co
24 сент. 2026 г.
GitHub AdvisorieshighCVE-2026-61816уязвимости
GHSA-f6v3-2qmr-vfjx: zbateson/mail-mime-parser has uncontrolled resource consumption (CPU/memory DoS) parsing untrusted MIME
### Impact An uncontrolled resource consumption / algorithmic complexity vulnerability affecting any application that parses untrusted email with this library. Three independent parsing paths are super-linear in cost, so a byte-size cap on the caller side does **not** bound the work done. A crafted message under 2 MB can consume seconds o
24 сент. 2026 г.
Разбор: Palo Alto NetworkscriticalCVE-2024-3400разбор
CVE-2024-3400 — PAN-OS GlobalProtect: внедрение команд без аутентификации
Внедрение команд в компоненте VPN-доступа с последующим закреплением в среде. Урок: пограничные устройства требуют приоритетного обновления, внешнего мониторинга интерфейсов и проверки журналов на предмет посторонних обращений.
01 апр. 2024 г. · Palo Alto Networks
Разбор: CitrixcriticalCVE-2023-4966разбор
CVE-2023-4966 — Citrix Bleed: утечка сессионных данных в NetScaler ADC и Gateway
Утечка памяти позволяла получить токены сессий и обойти многофакторную аутентификацию. Урок: шлюзы удалённого доступа — критичные активы; при подозрении на компрометацию обязательна инвалидация всех сессий, а не только установка исправления.
10 окт. 2023 г. · Citrix
Разбор: ProgresscriticalCVE-2023-34362разбор
CVE-2023-34362 — MOVEit Transfer: внедрение SQL с последующим развёртыванием
Уязвимость сервиса передачи файлов привела к массовым утечкам данных у множества организаций. Урок: внешние сервисы обмена файлами требуют приоритетного мониторинга, ограничения исходящих соединений и сегментации от внутренних сетей.
01 июн. 2023 г. · Progress
Разбор: MicrosoftcriticalCVE-2023-23397разбор
CVE-2023-23397 — Microsoft Outlook: утечка хеша учётных данных через напоминание
Обработка напоминания вызывала обращение к внешнему ресурсу, раскрывая материал для аутентификации. Урок: ограничение исходящих соединений с рабочих станций и серверов мешает таким техникам работать.
14 мар. 2023 г. · Microsoft
Разбор: WindowshighCVE-2022-30190windowsразбор
CVE-2022-30190 — Follina: выполнение кода через служебный обработчик Windows
Документ с внешней ссылкой запускал обработчик, способный выполнить код. Урок: контроль запуска приложений и ограничение внешних ссылок в документах снижают риск даже при отсутствии обновления.
01 мая 2022 г. · Microsoft
Разбор: Log4jcriticalCVE-2021-44228разбор
CVE-2021-44228 — Log4Shell: удалённое выполнение кода в Apache Log4j 2 через подстановку JNDI
Обработка строки вида ${jndi:...} в журналируемых сообщениях позволяла инициировать загрузку и выполнение кода. Урок: нужен инвентарь зависимостей и SBOM — уязвимость затрагивала тысячи продуктов, и без состава компонентов невозможно было оценить применимость.
10 дек. 2021 г. · Apache
CISA KEVhighCVE-2020-29583уязвимости
CVE-2020-29583 — Zyxel Multiple Products Use of Hard-Coded Credentials Vulnerability
Zyxel firewalls (ATP, USG, VM) and AP Controllers (NXC2500 and NXC5500) contain a use of hard-coded credentials vulnerability in an undocumented account ("zyfwp") with an unchangeable password. Требуемое действие: Apply updates per vendor instructions.
03 нояб. 2021 г. · Zyxel
CISA KEVhighCVE-2019-8394уязвимости
CVE-2019-8394 — Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability
Zoho ManageEngine ServiceDesk Plus (SDP) contains an unspecified vulnerability that allows remote users to upload files via login page customization. Требуемое действие: Apply updates per vendor instructions.
03 нояб. 2021 г. · Zoho
CISA KEVhighCVE-2020-10189уязвимости
CVE-2020-10189 — Zoho ManageEngine Desktop Central File Upload Vulnerability
Zoho ManageEngine Desktop Central contains a file upload vulnerability that allows for unauthenticated remote code execution. Требуемое действие: Apply updates per vendor instructions.
03 нояб. 2021 г. · Zoho
CISA KEVhighCVE-2021-40539уязвимости
CVE-2021-40539 — Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability
Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution. Требуемое действие: Apply updates per vendor instructions.
03 нояб. 2021 г. · Zoho
CISA KEVhighCVE-2021-27561уязвимости
CVE-2021-27561 — Yealink Device Management Server-Side Request Forgery (SSRF) Vulnerability
Yealink Device Management contains a server-side request forgery (SSRF) vulnerability that allows for unauthenticated remote code execution. Требуемое действие: Apply updates per vendor instructions.
03 нояб. 2021 г. · Yealink
CISA KEVhighCVE-2019-9978уязвимости
CVE-2019-9978 — WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability
WordPress Social Warfare plugin contains a cross-site scripting (XSS) vulnerability that allows for remote code execution. This vulnerability affects Social Warfare and Social Warfare Pro. Требуемое действие: Apply updates per vendor instructions.
03 нояб. 2021 г. · WordPress
CISA KEVhighCVE-2020-11738уязвимости
CVE-2020-11738 — WordPress Snap Creek Duplicator Plugin File Download Vulnerability
WordPress Snap Creek Duplicator plugin contains a file download vulnerability when an administrator creates a new copy of their site that allows an attacker to download the generated files from their Wordpress dashboard. This vulnerability affects Duplicator and Dulplicator Pro. Требуемое действие: Apply updates per vendor instructions.
03 нояб. 2021 г. · WordPress
CISA KEVhighCVE-2020-25213уязвимости
CVE-2020-25213 — WordPress File Manager Plugin Remote Code Execution Vulnerability
WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site. Требуемое действие: Apply updates per vendor instructions.
03 нояб. 2021 г. · WordPress
CISA KEVhighCVE-2020-4006уязвимости
CVE-2020-4006 — Multiple VMware Products Command Injection Vulnerability
VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector contain a command injection vulnerability. An attacker with network access to the administrative configurator on port 8443 and a valid password for the configurator administrator account can execute commands with unrestricted privileges on the
03 нояб. 2021 г. · VMware
CISA KEVhighCVE-2021-21985уязвимости
CVE-2021-21985 — VMware vCenter Server Improper Input Validation Vulnerability
VMware vSphere Client contains an improper input validation vulnerability in the Virtual SAN Health Check plug-in, which is enabled by default in vCenter Server, which allows for remote code execution. Требуемое действие: Apply updates per vendor instructions.
03 нояб. 2021 г. · VMware
CISA KEVhighCVE-2021-21972уязвимости
CVE-2021-21972 — VMware vCenter Server Remote Code Execution Vulnerability
VMware vCenter Server vSphere Client contains a remote code execution vulnerability in a vCenter Server plugin which allows an attacker with network access to port 443 to execute commands with unrestricted privileges on the underlying operating system. Требуемое действие: Apply updates per vendor instructions.
03 нояб. 2021 г. · VMware
CISA KEVhighCVE-2020-3952уязвимости
CVE-2020-3952 — VMware vCenter Server Information Disclosure Vulnerability
VMware vCenter Server contains an information disclosure vulnerability in the VMware Directory Service (vmdir) when the Platform Services Controller (PSC) does not correctly implement access controls. Successful exploitation allows an attacker with network access to port 389 to extract sensitive information. Требуемое действие: Apply upda
03 нояб. 2021 г. · VMware
CISA KEVhighCVE-2021-22005уязвимости
CVE-2021-22005 — VMware vCenter Server File Upload Vulnerability
VMware vCenter Server contains a file upload vulnerability in the Analytics service that allows a user with network access to port 443 to execute code. Требуемое действие: Apply updates per vendor instructions.
03 нояб. 2021 г. · VMware
CISA KEVhighCVE-2020-3950уязвимости
CVE-2020-3950 — VMware Multiple Products Privilege Escalation Vulnerability
VMware Fusion, Remote Console (VMRC) for Mac, and Horizon Client for Mac contain a privilege escalation vulnerability due to improper use of setuid binaries that allows attackers to escalate privileges to root. Требуемое действие: Apply updates per vendor instructions.
03 нояб. 2021 г. · VMware

Источники мониторинга

Каталоги уязвимостей и эксплуатации
Вендорские бюллетени безопасности
Исследования и технические блоги
Новости и сводки
Легальные сообщества и площадки для мониторинга
Осознанно не включено в мониторинг: криминальные площадки, рынки утечек, закрытые каналы обмена украденными данными и любые ресурсы, распространяющие вредоносное ПО. Работа с такими источниками недопустима независимо от исследовательской мотивации.
CyberPath — обучение пентесту, кибербезопасности и сетевой грамотности