Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-56015

Net::IP::LPM versions through 1.10 for Perl allow a heap out-of-bounds read via an unbounded prefix length. add() passes the prefix string to the trie builder addPrefixToTrie() without checking it against the address width. addPrefixToTrie() then walks the prefix buffer by prefix_length bits, reading prefix[byte] for byte up to prefix_len/8, where prefix is the 4-byte (IPv4) or 16-byte (IPv6) packed address. A prefix length greater than 32 for IPv4 or 128 for IPv6, for example add("1.2.3.4/255

PUBLISHED
Vendor
TPODER
Product
Net::IP::LPM
Provider severity
CRITICAL
Conflicts
0

CVE-2026-56014

Unauthenticated Cross Site Scripting (XSS) in Master Slider <= 3.11.2 versions.

PUBLISHED
Vendor
Averta
Product
Master Slider
Provider severity
HIGH
Conflicts
0

CVE-2026-56013

Unauthenticated Insecure Direct Object References (IDOR) in License Manager for WooCommerce <= 3.0.15 versions.

PUBLISHED
Vendor
myCred
Product
License Manager for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-56012

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant allows Blind SQL Injection. This issue affects Media LIbrary Assistant: from n/a through 3.35.

PUBLISHED
Vendor
David Lingren
Product
Media LIbrary Assistant
Provider severity
HIGH
Conflicts
0

CVE-2026-56011

Unauthenticated Cross Site Scripting (XSS) in MapPress Maps for WordPress <= 2.97.3 versions.

PUBLISHED
Vendor
chrisvrichardson
Product
MapPress Maps for WordPress
Provider severity
HIGH
Conflicts
0

CVE-2026-56010

Subscriber Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.

PUBLISHED
Vendor
Tyche Softwares.
Product
Abandoned Cart Pro for WooCommerce
Provider severity
HIGH
Conflicts
0

CVE-2026-5601

A vulnerability was found in Acrel Electrical Prepaid Cloud Platform 1.0. This issue affects some unknown processing of the file /bin.rar of the component Backup File Handler. The manipulation results in information disclosure. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Acrel Electrical
Product
Prepaid Cloud Platform
Provider severity
MEDIUM
Conflicts
2

CVE-2026-56009

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bricksable for Bricks Builder allows Stored XSS. This issue affects Bricksable for Bricks Builder: from n/a through 1.6.83.

PUBLISHED
Vendor
Bricksable
Product
Bricksable for Bricks Builder
Provider severity
MEDIUM
Conflicts
0

CVE-2026-56008

Contributor Privilege Escalation in Fusion Builder <= 3.15.4 versions.

PUBLISHED
Vendor
ThemeFusion
Product
Fusion Builder
Provider severity
HIGH
Conflicts
0

CVE-2026-56007

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OceanWP Ocean Product Sharing allows Stored XSS. This issue affects Ocean Product Sharing: from n/a through 2.2.2.

PUBLISHED
Vendor
OceanWP
Product
Ocean Product Sharing
Provider severity
MEDIUM
Conflicts
0

CVE-2026-56006

Unauthenticated Cross Site Scripting (XSS) in H5P <= 1.17.6 versions.

PUBLISHED
Vendor
H5P
Product
H5P
Provider severity
HIGH
Conflicts
0

CVE-2026-56005

Subscriber Cross Site Scripting (XSS) in WP Activity Log <= 5.6.3.1 versions.

PUBLISHED
Vendor
Melapress
Product
WP Activity Log
Provider severity
HIGH
Conflicts
0

CVE-2026-56004

A shellcode injection in the mercurial handler of the obs tar_scm source service before version 0.12.4 could be used by attackers able to provide a _service file to execute code as the source service or the local user checking out the malicious services

PUBLISHED
Vendor
openSUSE
Product
buildservice
Provider severity
CRITICAL
Conflicts
0

CVE-2026-56003

A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXfont2 before 2.0.8 could be used by attackers using authenticated X clients to execute code within the X server.

PUBLISHED
Vendor
X.Org
Product
libXfont2
Provider severity
HIGH
Conflicts
0

CVE-2026-56002

A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8  allows attackers authenticated as X client to execute code within the X server.

PUBLISHED
Vendor
X.Org
Product
libXfont2
Provider severity
HIGH
Conflicts
0

CVE-2026-56001

A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit size could be used by attackers able to access the X Server to execute code within the X server cont

PUBLISHED
Vendor
X.Org
Product
libXfont2
Provider severity
HIGH
Conflicts
0

CVE-2026-56000

Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a Heap Use After Free, due to CommonMakeCurrent() pointing into potentially reallocated memory.

PUBLISHED
Vendor
X.Org, X.Org
Product
xwayland, xorg-x11-server
Provider severity
CRITICAL
Conflicts
1

CVE-2026-5600

A new API endpoint introduced in pretix 2025 that is supposed to return all check-in events of a specific event in fact returns all check-in events belonging to the respective organizer. This allows an API consumer to access information for all other events under the same organizer, even those they should not have access to. These records contain information on the time and result of every ticket scan as well as the ID of the matched ticket. Example: { "id": 123, "successful": true,

PUBLISHED
Vendor
pretix
Product
pretix
Provider severity
MEDIUM
Conflicts
0

CVE-2026-55999

Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer overflow via SetFont due to missing glyph boundary checks.

PUBLISHED
Vendor
X.Org, X.Org
Product
xorg-server, xwayland
Provider severity
HIGH
Conflicts
1

CVE-2026-55995

A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS. This issue affects open-iscsi: from ? through 56718d4e9d1a4f51c30697b5c0534144bb41c9bb.

PUBLISHED
Vendor
open-iscsi
Product
open-iscsi
Provider severity
HIGH
Conflicts
0

CVE-2026-55994

Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel in Iggy component. The camel-iggy consumer mapped the user-headers of inbound Iggy messages into the Camel Exchange header map without applying any HeaderFilterStrategy (IggyFetchRecords copied the message user-headers straight into the Exchange). Because nothing blocked the Camel header namespace, an actor able to publish to the consumed Iggy s

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Camel Iggy
Provider severity
HIGH
Conflicts
1

CVE-2026-55993

Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel in Atmosphere Websocket Component. The camel-atmosphere-websocket consumer mapped inbound WebSocket query parameters into the Camel Exchange header map without applying any HeaderFilterStrategy (WebsocketConsumer.sendEventNotification() iterates the query-string map collected in WebsocketConsumer.service() and copies each entry into the Exchange

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Camel Atmosphere Websocket
Provider severity
HIGH
Conflicts
1

CVE-2026-55991

In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a remote unauthenticated client can trigger a libngtcp2 assertion (if compiled with assertions on) and terminate the entire Unbound process using a single DNS-over-QUIC (DoQ) connection and one normal DNS query. This is caused by an erroneous error value passed to libngtcp2. When 'ngtcp2_conn_writev_stream()' returns 'NGTCP2_ERR_STREAM_DATA_BLOCKED', Unbound continues to call 'ngtcp2_ccerr_set_application_error()' with a '-1' error value.

PUBLISHED
Vendor
NLnet Labs
Product
Unbound
Provider severity
MEDIUM
Conflicts
0

CVE-2026-55990

In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' clause lists more 'dnscrypt-provider-cert:' files than there are matching 'dnscrypt-secret-key:' files, Unbound fills only the matched prefix and leaves the tail slots at the '0xdb' fill that libsodium's allocator writes into every allocation. Unbound would then iterate over the number of cert files, not the actual slots, so it walks into a slot with garbage data filled with '0xdb' bytes. Any unauthenticated client that

PUBLISHED
Vendor
NLnet Labs
Product
Unbound
Provider severity
MEDIUM
Conflicts
0

CVE-2026-5599

A user with API access and "manage users" permission in any venueless world is able to trigger deletion of user accounts in other worlds.

PUBLISHED
Vendor
pretix
Product
Venueless
Provider severity
HIGH
Conflicts
0

CVE-2026-55985

The web management interface in  Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext on a certain configuration page accessible to authenticated users. Any party with access to the administrative dashboard can immediately read these credentials, which may be used to compromise other systems on the local network.

PUBLISHED
Vendor
Tycon Systems
Product
TPDIN-Monitor-WEB2
Provider severity
MEDIUM
Conflicts
1

CVE-2026-5598

A flaw was found in Legion of the Bouncy Castle Inc. BC-JAVA core. A covert timing channel vulnerability, caused by non-constant time comparisons, risks the leakage of private keys in the FrodoKEM implementation. An unauthenticated, remote attacker can potentially exploit this timing discrepancy to gain unauthorized access to sensitive cryptographic information.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Legion of the Bouncy Castle Inc., Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Single Sign-On 7, Red Hat build of Apicurio Registry 3, Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8, Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 9, Red Hat build of Debezium 3, Red Hat build of Apache Camel for Spring Boot 4, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat build of Apache Camel for Spring Boot 4, Red Hat JBoss Enterprise Application Platform 8, Red Hat JBoss Enterprise Application Platform 8.1, Red Hat Enterprise Linux 8, BC-JAVA, Red Hat Enterprise Linux 9, Red Hat OpenShift Dev Spaces, Red Hat OpenShift AI (RHOAI), Red Hat build of Debezium 3, Red Hat Data Grid 8, Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7, Red Hat Fuse 7, Red Hat OpenShift AI (RHOAI), Red Hat Build of Keycloak, Red Hat JBoss Enterprise Application Platform 7, Red Hat Data Grid 8, Red Hat JBoss Enterprise Application Platform 8, Red Hat Process Automation 7, Red Hat build of Apicurio Registry 3, Red Hat Fuse 7, Red Hat build of Debezium 2, OpenShift Developer Tools and Services, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat Fuse 7, Red Hat Enterprise Linux 8, Red Hat Process Automation 7, streams for Apache Kafka 3, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat JBoss Enterprise Application Platform 8, streams for Apache Kafka 2, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat JBoss Enterprise Application Platform 7, Red Hat build of Debezium 2, Red Hat AMQ Clients, Red Hat Fuse 7, Cryostat 4, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9, Red Hat Enterprise Linux 9, streams for Apache Kafka 3, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat OpenShift Dev Spaces, Red Hat build of Apache Camel for Spring Boot 4, Red Hat JBoss Enterprise Application Platform 8, Red Hat Fuse 7, OpenShift Developer Tools and Services, OpenShift Developer Tools and Services, Red Hat build of Quarkus, Red Hat Satellite 6, OpenShift Developer Tools and Services, Red Hat JBoss Enterprise Application Platform 8, Red Hat Satellite 6, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat AMQ Broker 7, Red Hat JBoss Enterprise Application Platform 7, Red Hat build of Debezium 3, Red Hat AMQ Clients, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 8, Red Hat AMQ Broker 7, Red Hat JBoss Enterprise Application Platform 7, streams for Apache Kafka 2, Red Hat Data Grid 8, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat JBoss Enterprise Application Platform 7, Red Hat Data Grid 8, Red Hat build of Apache Camel for Spring Boot 4, Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8
Provider severity
HIGH
Conflicts
3

CVE-2026-55977

Successful exploitation of this vulnerability could allow an attacker with local network access to bypass the application's rate-limiting mechanism, enabling brute-forcing of the screen-sharing code and potentially displaying harmful content on the affected screen.

PUBLISHED
Vendor
EShare
Product
ESharePro
Provider severity
LOW
Conflicts
0

CVE-2026-55975

A vulnerability exists in H.View IP cameras that could allow an authenticated user to supply unsanitized XML fields to the device's certificate generation interface, which are incorporated into a backend certificate creation command without proper input validation. This may allow for command execution with elevated privileges during certificate generation.

PUBLISHED
Vendor
H.VIEW
Product
HV-500S6 IP Camera
Provider severity
HIGH
Conflicts
1

CVE-2026-55973

In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the EDNS Report-Channel option (code 18) from the last upstream response is read and uses the option's length as the length of the agent domain. When a domain name check is performed on the agent domain, the returned lenght is not used and if the agent domain is followed by garbage, those bytes are moved onto the tail of the synthetic '_er.' report query name. That query name is later used in the ite

PUBLISHED
Vendor
NLnet Labs
Product
Unbound
Provider severity
HIGH
Conflicts
0

CVE-2026-55971

Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Thrift
Provider severity
CRITICAL
Conflicts
0

CVE-2026-55970

Buffer Over-read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Thrift
Provider severity
MEDIUM
Conflicts
0

CVE-2026-5597

A flaw has been found in griptape-ai griptape 0.19.4. This affects an unknown part of the file griptape\tools\computer\tool.py of the component ComputerTool. Executing a manipulation of the argument filename can lead to path traversal. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
griptape-ai
Product
griptape
Provider severity
MEDIUM
Conflicts
1

CVE-2026-55969

Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

PUBLISHED
Vendor
Apache Software Foundation, Apache Software Foundation, Apache Software Foundation, Apache Software Foundation, Apache Software Foundation, Apache Software Foundation
Product
Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift
Provider severity
HIGH
Conflicts
1

CVE-2026-55968

Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Node.js bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Thrift
Provider severity
HIGH
Conflicts
1

CVE-2026-55967

AES-GCM encryption/decryption with extremely large cumulative single message sizes (>64 GiB) were not properly rejected by the streaming APIs, allowing counter wrap, keystream reuse, and consequent plaintext recovery.

PUBLISHED
Vendor
wolfSSL
Product
wolfSSL
Provider severity
LOW
Conflicts
0

CVE-2026-55964

Chain intermediate CA:TRUE without keyCertSign accepted as a signing CA. Intermediate CA certificates are required to have the keyCertSign key usage when a Key Usage extension is present, but chain-supplied temporary CAs (WOLFSSL_TEMP_CA) added while building a certificate path were previously exempted from this check, so an intermediate asserting CA:TRUE but lacking keyCertSign was accepted as a signing CA. The check now applies to chain-supplied temporary CAs as well; only operator-loaded root

PUBLISHED
Vendor
wolfSSL
Product
wolfSSL
Provider severity
MEDIUM
Conflicts
0

CVE-2026-55962

TLS 1.3 post-handshake authentication (PHA) issue where a server could accept a client's Finished message without the client having sent a Certificate and CertificateVerify. The post-handshake-auth exemption that allows an empty/absent peer certificate was only intended for the initial handshake, but it was also being applied while a post-handshake CertificateRequest was still outstanding. The check is now scoped to the initial handshake only: on the server, once a post-handshake CertificateRequ

PUBLISHED
Vendor
wolfSSL
Product
wolfSSL
Provider severity
MEDIUM
Conflicts
0

CVE-2026-55961

wolfSSL_PKCS7_verify() returning success for a degenerate (certs-only) PKCS#7 object that contains no signer. Such an object has empty signerInfos, so the underlying signed-data verification succeeds without authenticating any content. The compatibility-layer verify path now rejects the object when no signer signature has actually been verified, so a PKCS#7 carrying no valid signature is no longer reported as verified. This is enforced regardless of the PKCS7_NOVERIFY flag, which only suppresses

PUBLISHED
Vendor
wolfSSL
Product
wolfSSL
Provider severity
HIGH
Conflicts
0

CVE-2026-55960

Un-negotiated Raw Public Key (RFC 7250) accepted in place of an X.509 certificate, bypassing chain validation. A raw public key has no chain, so ParseCertRelative() accepts it without performing any trust verification; it must therefore only be accepted when RPK was actually negotiated for that peer. The check now defaults the expected type to X.509 (per RFC 7250/8446) when no type was negotiated, comparing against the received server certificate type on the client and the selected client certif

PUBLISHED
Vendor
wolfSSL
Product
wolfSSL
Provider severity
HIGH
Conflicts
0

CVE-2026-5596

A vulnerability was detected in griptape-ai griptape 0.19.4. Affected by this issue is some unknown functionality of the file griptape/tools/sql/tool.py of the component SqlTool. Performing a manipulation results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
griptape-ai
Product
griptape
Provider severity
MEDIUM
Conflicts
2

CVE-2026-55958

Out-of-bounds write in the Renesas TSIP TLS 1.3 transcript buffer. In tsip_StoreMessage() the capacity check guarding the fixed message bag (MSGBAG_SIZE) sets an error code but fails to return, so execution falls through to an XMEMCPY that writes past the end of the buffer once the accumulated TLS 1.3 handshake transcript exceeds MSGBAG_SIZE (8 KB), corrupting adjacent heap state and potentially causing a remote denial of service crash. The bag is sized to hold a normal handshake, so this is rea

PUBLISHED
Vendor
wolfSSL
Product
wolfSSL
Provider severity
HIGH
Conflicts
1

CVE-2026-55957

Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate binds using GSSAPI allowed attackers to authenticate without provided the correct password. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.4, from 10.1.0-M1 through 10.1.36, from 9.0.0.M1 through 9.0.100, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Users are recommended to upgrade to version 11.0.5, 10.1.37 or 9.0.101, which fixes the issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Tomcat
Provider severity
HIGH
Conflicts
0

CVE-2026-55956

Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Tomcat
Provider severity
MEDIUM
Conflicts
0

CVE-2026-55955

Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.13 through 9.0.18, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are recommended to upgrade to version 11.0.23, 10.1.56, 9.0.119, which fixes the issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Tomcat
Provider severity
MEDIUM
Conflicts
0

CVE-2026-55954

Authentication Bypass by Spoofing vulnerability in ueberauth ueberauth_apple allows account takeover via unvalidated ID token claims. The Ueberauth.Strategy.Apple.Token.payload/2 function verifies the JWT signature of the callback id_token against Apple's JWKS but does not validate any registered claims. The iss, aud, exp, and iat claims are read from the token and passed on to Ueberauth.Strategy.Apple.handle_callback!/1, which derives the logged-in user's uid and email directly from the unvali

PUBLISHED
Vendor
ueberauth, ueberauth
Product
ueberauth_apple, ueberauth_apple
Provider severity
CRITICAL
Conflicts
1

CVE-2026-55953

The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does not verify that the cipher suite selected by the server in ServerHello was among the suites offered by the client in ClientHello. The client-side tls_handshake:hello/5 handler validates the negotiated protocol version and the downgrade sentinel but hands the server-chosen suite directly to ssl_handshake:handle_server_hello_extensions/9, which installs it without a membership check. The TLS 1.3 client path performs this check (per RFC

PUBLISHED
Vendor
Erlang, Erlang, Erlang
Product
OTP, OTP, OTP
Provider severity
CRITICAL
Conflicts
1

CVE-2026-55952

The Erlang/OTP ssl application does not validate that the PSK identity list and binder list carried in a TLS 1.3 ClientHello pre-shared key extension have equal length before passing them to the session ticket handler. In tls_handshake_1_3:handle_pre_shared_key/3, an OfferedPreSharedKeys record with a mismatched number of identities and binders is forwarded directly to tls_server_session_ticket:use/4, which crashes the session ticket handler process. An unauthenticated remote attacker can send

PUBLISHED
Vendor
Erlang, Erlang
Product
OTP, OTP
Provider severity
HIGH
Conflicts
1

CVE-2026-55950

Time-of-check Time-of-use (TOCTOU) race condition vulnerability in Erlang/OTP ssl (dtls_packet_demux module) allows an unauthenticated remote attacker to crash all active DTLS sessions on a listener. A DTLS server listener uses a single shared dtls_packet_demux gen_server process to route incoming UDP datagrams to the correct connection handler. When a DTLS client reconnects rapidly from the same source address and port (sending multiple ClientHello messages in quick succession), a race conditi

PUBLISHED
Vendor
Erlang, Erlang
Product
OTP, OTP
Provider severity
HIGH
Conflicts
1

CVE-2026-5595

A security vulnerability has been detected in griptape-ai griptape 0.19.4. Affected by this vulnerability is the function load_files_from_disk/list_files_from_disk/save_content_to_file/save_memory_artifacts_to_disk of the component FileManagerTool. Such manipulation leads to path traversal. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
griptape-ai
Product
griptape
Provider severity
MEDIUM
Conflicts
1