Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-42385

Unauthenticated Cross Site Scripting (XSS) in Profile Builder Pro <= 3.15.0 versions.

PUBLISHED
Vendor
Cozmoslabs
Product
Profile Builder Pro
Provider severity
HIGH
Conflicts
0

CVE-2026-42384

Unauthenticated Sensitive Data Exposure in Simply Schedule Appointments < 1.6.11.2 versions.

PUBLISHED
Vendor
NSquared
Product
Simply Schedule Appointments
Provider severity
HIGH
Conflicts
0

CVE-2026-42383

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YITH YITH WooCommerce Product Add-Ons allows Blind SQL Injection. This issue affects YITH WooCommerce Product Add-Ons: from n/a through 4.29.0.

PUBLISHED
Vendor
YITH
Product
YITH WooCommerce Product Add-Ons
Provider severity
HIGH
Conflicts
0

CVE-2026-42382

Unauthenticated Local File Inclusion in Audrey <= 1.5 versions.

PUBLISHED
Vendor
Elated-Themes
Product
Audrey
Provider severity
HIGH
Conflicts
0

CVE-2026-42381

Unauthenticated SQL Injection in Funnel Builder by FunnelKit <= 3.15.0.1 versions.

PUBLISHED
Vendor
FunnelKit
Product
Funnel Builder by FunnelKit
Provider severity
CRITICAL
Conflicts
0

CVE-2026-42380

Unauthenticated PHP Object Injection in AI Lab < 5.4.2 versions.

PUBLISHED
Vendor
jwsthemes
Product
AI Lab
Provider severity
CRITICAL
Conflicts
0

CVE-2026-4238

A vulnerability has been found in itsourcecode College Management System 1.0. This issue affects some unknown processing of the file /admin/courses.php. The manipulation of the argument course_code leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
itsourcecode
Product
College Management System
Provider severity
MEDIUM
Conflicts
2

CVE-2026-42379

Insertion of Sensitive Information Into Sent Data vulnerability in WPDeveloper Templately allows Retrieve Embedded Sensitive Data.This issue affects Templately: from n/a through 3.6.1.

PUBLISHED
Vendor
WPDeveloper
Product
Templately
Provider severity
HIGH
Conflicts
0

CVE-2026-42378

Subscriber Broken Authentication in WP Full Stripe Free <= 8.4.1 versions.

PUBLISHED
Vendor
Themeisle
Product
WP Full Stripe Free
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42377

Missing Authorization vulnerability in Brainstorm Force SureForms Pro allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SureForms Pro: from n/a through 2.8.0.

PUBLISHED
Vendor
Brainstorm Force
Product
SureForms Pro
Provider severity
HIGH
Conflicts
0

CVE-2026-42376

D-Link DIR-456U Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /etc/init0.d/S80telnetd.sh with the username "Alphanetworks" and the static password "whdrv01_dlob_dir456U" read from /etc/config/image_sign. The custom telnetd binary accepts a -u user:password flag, and the custom login binary uses strcmp() to validate credentials. Successful authentication grants an unauthenticated attacker on the local network a root she

PUBLISHED
Vendor
D-Link
Product
DIR-456U Firmware
Provider severity
CRITICAL
Conflicts
0

CVE-2026-42375

D-Link DIR-600L Hardware Revision A1 (End-of-Life) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the static password "wrgn35_dlwbr_dir600l" read from /etc/alpha_config/image_sign. The custom telnetd binary accepts a -u user:password flag, and the custom login binary uses strcmp() to validate credentials. Successful authentication grants an unauthenticated attacker on the local network a root shell with fu

PUBLISHED
Vendor
D-Link
Product
DIR-600L Firmware
Provider severity
CRITICAL
Conflicts
0

CVE-2026-42374

D-Link DIR-600L Hardware Revision B1 (End-of-Life) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the static password "wrgn61_dlwbr_dir600L" read from /etc/alpha_config/image_sign. The custom telnetd binary accepts a -u user:password flag, and the custom login binary uses strcmp() to validate credentials. Successful authentication grants an unauthenticated attacker on the local network a root shell with fu

PUBLISHED
Vendor
D-Link
Product
DIR-600L Firmware
Provider severity
CRITICAL
Conflicts
0

CVE-2026-42373

D-Link DIR-605L Hardware Revision B2 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the static password "wrgn76_dlwbr_dir605L" read from /etc/alpha_config/image_sign. The custom telnetd binary accepts a -u user:password flag, and the custom login binary uses strcmp() to validate credentials. Successful authentication grants an unauthenticated attacker on the local network a root shell wi

PUBLISHED
Vendor
D-Link
Product
DIR-605L Firmware
Provider severity
CRITICAL
Conflicts
0

CVE-2026-42372

D-Link DIR-605L Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the static password "wrgn35_dlwbr_dir605l" read from /etc/alpha_config/image_sign. The custom telnetd binary accepts a -u user:password flag, and the custom login binary uses strcmp() to validate credentials. Successful authentication grants an unauthenticated attacker on the local network a root shell wi

PUBLISHED
Vendor
D-Link
Product
DIR-605L Firmware
Provider severity
HIGH
Conflicts
0

CVE-2026-42371

uriparser before 1.0.1 has numeric truncation in text range comparison, if an application accepts URIs with a length in gigabytes.

PUBLISHED
Vendor
uriparser
Product
uriparser
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42370

A stack overflow vulnerability exists in the WebCam Server Login functionality of GeoVision GV-VMS V20 20.0.2. A specially crafted HTTP request can lead to an arbitrary code execution. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.

PUBLISHED
Vendor
GeoVision Inc.
Product
GV-VMS V20.0.2
Provider severity
CRITICAL
Conflicts
0

CVE-2026-4237

A flaw has been found in itsourcecode Free Hotel Reservation System 1.0. This vulnerability affects unknown code of the file /hotel/admin/mod_reports/index.php. Executing a manipulation of the argument Home can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used.

PUBLISHED
Vendor
itsourcecode
Product
Free Hotel Reservation System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-42369

GV-VMS V20 is a Video Monitoring Software used to gather the feeds of many surveillance cameras and manage other security devices. It is a native application accessed locally, but it is also possible to enable remote access via the "WebCam Server" feature. Once enabled, it is possible to access to the management and monitoring feature via a regular Web interface. This webersever is another native application, compiled without ASLR, which makes exploitation much easier and more likely. Most

PUBLISHED
Vendor
GeoVision Inc.
Product
GV-VMS V20.0.2
Provider severity
CRITICAL
Conflicts
0

CVE-2026-42368

A privilege escalation vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP request can lead to execute priviledged operation. An attacker can visit a webpage to trigger this vulnerability.

PUBLISHED
Vendor
GeoVision Inc.
Product
GV-LPC2011/LPC2211
Provider severity
CRITICAL
Conflicts
0

CVE-2026-42367

A privilege escalation vulnerability exists in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted HTTP request can lead to credentials leak. An attacker can visit a webpage to trigger this vulnerability.

PUBLISHED
Vendor
GeoVision Inc.
Product
GV-LPC2011/LPC2211
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42366

Multiple reflected cross-site scripting (xss) vulnerabilities exist in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted malicious url can lead to an arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability.

PUBLISHED
Vendor
GeoVision Inc.
Product
GV-LPC2011/LPC2211
Provider severity
HIGH
Conflicts
0

CVE-2026-42365

A guessable session cookie vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted series of HTTP requests can lead to an authentication bypas. An attacker can bruteforce session cookies to trigger this vulnerability.

PUBLISHED
Vendor
GeoVision Inc.
Product
GV-LPC2011/LPC2211
Provider severity
HIGH
Conflicts
0

CVE-2026-42364

An os command injection vulnerability exists in the DdnsSetting.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted DDNS configuration can lead to arbitrary command execution. An attacker can modify a configuration value to trigger this vulnerability.

PUBLISHED
Vendor
GeoVision Inc.
Product
GV-LPC2011/LPC2211
Provider severity
CRITICAL
Conflicts
0

CVE-2026-42363

An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Utility 9.0.5. Listening to broadcast packets can lead to credentials leak. An attacker can listen to broadcast messages to trigger this vulnerability. When interacting with various Geovision devices on the network, the utility may send privileged commands; in order to do so, the username and password of the device need to be provided. In some instances the command is broadcaste

PUBLISHED
Vendor
GeoVision Inc.
Product
GV-IP Device Utility
Provider severity
CRITICAL
Conflicts
0

CVE-2026-42360

A bug in Apache Airflow's rendered-template field handling caused nested sensitive-key masking (e.g. nested `password` / `token` / `secret` / `api_key` keys inside a JSON template structure) to be bypassed when the rendered field exceeded `[core] max_templated_field_length`: Airflow stringified the structure before redaction, losing the nested key context, and persisted the plaintext value into `rendered_fields`. An authenticated UI/API user with permission to read rendered template fields could

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Airflow
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4236

A security vulnerability has been detected in itsourcecode Online Enrollment System 1.0. Impacted is an unknown function of the file /enrollment/index.php?view=add. Such manipulation of the argument txtsearch/deptname/name leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.

PUBLISHED
Vendor
itsourcecode
Product
Online Enrollment System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-42359

A bug in Apache Airflow's XCom PATCH endpoint `PATCH /api/v2/xcomEntries/{key}` allowed an authenticated UI/API user with XCom write permission on a Dag to set XCom entries under reserved key names (e.g. `return_value`) that the matching POST endpoint already validated against `FORBIDDEN_XCOM_KEYS`. The endpoint also accepted serialized payload shapes the triggerer's deserializer treats as code; combined, this allowed RCE on the triggerer when the affected task next deferred. Affects deployments

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Airflow
Provider severity
HIGH
Conflicts
0

CVE-2026-42358

A bug in Apache Airflow's Variable response masker caused nested-key redaction (triggered by secret-suffixed key names like `password`, `token`, `secret`, `api_key`) to be bypassed when the JSON value's nesting depth exceeded the shared secrets masker's recursion limit: the masker returned the original nested item before checking the sensitive key name. An authenticated UI/API user with Variable read permission could harvest plaintext secret values stored under sensitive keys nested deep enough

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Airflow
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42357

Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access. This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes this issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache DolphinScheduler
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42355

NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an uncontrolled recursion vulnerability exists in the Electron Archive (ASAR) parser in NanaZip. When opening a crafted .asar file with deeply nested JSON in the header, both nlohmann::json::parse and the handler's GetAllPaths function recurse without depth limits, exhausting the thread stack and crashing the NanaZip process. This vulnerability is fixed in 6.0.1698.0.

PUBLISHED
Vendor
M2Team
Product
NanaZip
Provider severity
LOW
Conflicts
0

CVE-2026-42354

Sentry is an error tracking and performance monitoring tool. From version 21.12.0 to before version 26.4.1, a critical vulnerability was discovered in the SAML SSO implementation of Sentry. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. This issue has been patched in version 26.4.1.

PUBLISHED
Vendor
getsentry
Product
sentry
Provider severity
CRITICAL
Conflicts
0

CVE-2026-42353

i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. Prior to version 3.9.3, i18next-http-middleware passes the user-controlled lng and ns values from getResourcesHandler directly into i18next.services.backendConnector.load(languages, namespaces, …) without any sanitization. Depending on which backend is configured, the unvalidated path segments enable either path traversal or SSRF. This issue has been patched in version 3.9.3.

PUBLISHED
Vendor
i18next
Product
i18next-http-middleware
Provider severity
HIGH
Conflicts
1

CVE-2026-42352

pygeoapi is a Python server implementation of the OGC API suite of standards. From version 0.23.0 to before version 0.23.3, OGC API process execution requests can use the subscriber object to requests to internal HTTP services. This issue has been patched in version 0.23.3.

PUBLISHED
Vendor
geopython
Product
pygeoapi
Provider severity
HIGH
Conflicts
0

CVE-2026-42351

pygeoapi is a Python server implementation of the OGC API suite of standards. From version 0.23.0 to before version 0.23.3, a raw string path concatenation vulnerability in pygeoapi's STAC FileSystemProvider plugin can allow for requests to STAC collection based collections to expose directories without authentication. The issue manifests when pygeoapi is deployed without a proxy or web front end that would normalize URLs with .. values, along with a resource of type stac-collection defined in c

PUBLISHED
Vendor
geopython
Product
pygeoapi
Provider severity
HIGH
Conflicts
0

CVE-2026-42350

Kargo manages and automates the promotion of software artifacts. Prior to versions 1.7.10, 1.8.13, 1.9.8, and 1.10.2, Kargo is vulnerable to open redirect in UI OIDC login flow via the redirectTo query parameter. This issue has been patched in versions 1.7.10, 1.8.13, 1.9.8, and 1.10.2.

PUBLISHED
Vendor
akuity
Product
kargo
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4235

A weakness has been identified in itsourcecode Online Enrollment System 1.0. This issue affects some unknown processing of the file /sms/login.php. This manipulation of the argument user_email causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.

PUBLISHED
Vendor
itsourcecode
Product
Online Enrollment System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-42349

Clerk JavaScript is the official JavaScript repository for Clerk authentication. has(), auth.protect(), and related authorization predicates in @clerk/shared, @clerk/nextjs, @clerk/backend, and other framework SDKs can return true for certain combined authorization checks when the result should be false, allowing a gated action to proceed for a user who does not satisfy the full set of requested conditions. This call shape can be bypassed if certain conditions are met: a has() or auth.protect()

PUBLISHED
Vendor
@clerk, @clerk, @clerk, @clerk, @clerk, @clerk, @clerk, @clerk, @clerk, @clerk, @clerk, clerk, @clerk, @clerk, @clerk, @clerk, @clerk
Product
react, shared, hono, expo, clerk-expo, nuxt, vue, tanstack-react-start, react-router, chrome-extension, backend, javascript, clerk-react, express, fastify, nextjs, astro
Provider severity
HIGH
Conflicts
2

CVE-2026-42348

OpenTelemetry.OpAmp.Client is the OpAMP client for OpenTelemetry .NET. Prior to 0.2.0-alpha.1, when receiving responses from the OpAMP server over HTTP, the OpAMP client allocates an unbounded buffer to read all bytes from the server, with no upper-bound on the number of bytes consumed. This could cause memory exhaustion in the consuming application if the configured OpAMP server is attacker-controlled (or a network attacker can MitM the connection) and an extremely large body is returned in the

PUBLISHED
Vendor
open-telemetry
Product
opentelemetry-dotnet-contrib
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42346

Postiz is an AI social media scheduling tool. From version 2.16.6 to before version 2.21.7, all SSRF protections added in v2.21.4–v2.21.6 share a fundamental TOCTOU (Time-of-Check-Time-of-Use) vulnerability: isSafePublicHttpsUrl() resolves DNS to validate the target IP, but subsequent fetch() calls resolve DNS independently. An attacker controlling a DNS server can exploit this gap via DNS rebinding to redirect requests to internal network addresses. This issue has been patched in version 2.21.7

PUBLISHED
Vendor
gitroomhq
Product
postiz-app
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42345

FastGPT is an AI Agent building platform. In versions 4.14.11 and prior, FastGPT's isInternalAddress() function in packages/service/common/system/utils.ts blocks cloud metadata endpoints using a fullUrl.startsWith() check against a hardcoded list. This check can be bypassed using at least 7 different URL encoding techniques, all of which resolve to the same cloud metadata service but do not match the blocklist patterns. Additionally, the broader private IP check (isInternalIPv4/isInternalIPv6) i

PUBLISHED
Vendor
labring
Product
FastGPT
Provider severity
HIGH
Conflicts
0

CVE-2026-42344

FastGPT is an AI Agent building platform. In versions 4.14.11 and prior, FastGPT's isInternalAddress() function in packages/service/common/system/utils.ts is vulnerable to DNS rebinding (TOCTOU — Time-of-Check to Time-of-Use). The function resolves the hostname via dns.resolve4()/dns.resolve6() and checks resolved IPs against private ranges, but the actual HTTP request happens in a separate call with a new DNS resolution, allowing the DNS record to change between validation and fetch. At time of

PUBLISHED
Vendor
labring
Product
FastGPT
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42343

FastGPT is an AI Agent building platform. In versions 4.14.13 and prior, the code-sandbox component suffers from insufficient resource isolation and uncontrolled resource consumption. The service relies solely on an application-level soft limit (a 500ms polling interval) for memory management and lacks strict OS-level constraints such as cgroups or kernel-level namespaces. This architectural weakness allows attackers to easily bypass memory checks via time-window attacks, or exhaust the entire J

PUBLISHED
Vendor
labring
Product
FastGPT
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42342

React Router is a router for React. In versions 7.0.0 through 7.14.x of react-router and versions 2.10.0 through 2.17.4 of @remix-run/server-runtime, certain crafted requests can consume disproportionate server resources via unbounded path expansion in the __manifest endpoint, resulting in response time degradation and/or service unavailability for end users. This affects React Router Framework Mode applications as well as Remix applications. This does not impact applications using Declarative M

PUBLISHED
Vendor
remix-run, remix-run
Product
react-router, @remix-run/server-runtime
Provider severity
HIGH
Conflicts
1

CVE-2026-42341

FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have an unauthenticated payment bypass vulnerability in FOSSBilling's IPN callback endpoint. When the Custom payment adapter is enabled, an attacker can mark any unpaid invoice as paid and credit the associated client account without making an actual payment, by sending a single crafted HTTP request. Version 0.8.0 patches the issue. Some workarounds are available. Disable the Custom payment gate

PUBLISHED
Vendor
FOSSBilling
Product
FOSSBilling
Provider severity
CRITICAL
Conflicts
1

CVE-2026-4234

A security flaw has been discovered in SSCMS 7.4.0. This vulnerability affects unknown code of the file SitesAddController.Submit.cs of the component DDL Handler. The manipulation of the argument tableHandWrite results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
n/a
Product
SSCMS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-42339

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. In versions 0.11.9-alpha.1 and prior, the SSRF protection introduced in v0.9.0.5 (CVE-2025-59146) and hardened in v0.9.6 (CVE-2025-62155) does not block the unspecified address 0.0.0.0. A regular (non-admin) user holding any valid API token can send a multimodal request to /v1/chat/completions, /v1/responses, or /v1/messages with 0.0.0.0 as the image/file URL host, bypassing the private-IP fi

PUBLISHED
Vendor
QuantumNous
Product
new-api
Provider severity
HIGH
Conflicts
0

CVE-2026-42338

A flaw was found in ip-address, a JavaScript library for parsing and manipulating IPv4 and IPv6 addresses. This vulnerability allows a remote attacker to perform cross-site scripting (XSS) by providing untrusted input to the Address6 constructor. When an application renders the output of Address6.group(), Address6.link(), or the AddressError.parseMessage as HTML without proper escaping, the attacker-controlled content can be executed in the user's browser.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, beaugunderson, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat AMQ Broker 7, Red Hat Enterprise Linux 10, Confidential Compute Attestation, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift Container Platform 4.22, Red Hat Enterprise Linux 10, Red Hat OpenShift Container Platform 4.2, Red Hat OpenShift Service Mesh 3.0, Red Hat Satellite 6, Self-service automation portal 2, Red Hat OpenShift Service Mesh 3.3, Exploit Intelligence, Cryostat 4, Red Hat OpenShift Service Mesh 3.0, Red Hat OpenShift Service Mesh 3.1, OpenShift Pipelines, Red Hat OpenShift Service Mesh 3.1, Red Hat OpenShift Service Mesh 2.6, Red Hat OpenShift Dev Spaces, Red Hat Enterprise Linux 9, Multicluster Engine for Kubernetes, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Developer Hub 1.9, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Build of Podman Desktop, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift Service Mesh 2.6, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Dev Spaces 3.29, OpenShift Pipelines, Red Hat OpenShift Container Platform 4.21, Red Hat OpenShift Dev Spaces 3.29, Red Hat Hardened Images, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 8, Red Hat Ansible Automation Platform 2.6, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift Service Mesh 3.2, Red Hat build of Apache Camel - HawtIO 4, Red Hat Migration Toolkit 1.8, Red Hat Build of Podman Desktop - Tech Preview, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat OpenShift Service Mesh 3.3, Red Hat Developer Hub 1.10, ip-address, Cryostat 4, Red Hat Enterprise Linux 10, Red Hat build of Apache Camel for Spring Boot 4, Red Hat OpenShift Service Mesh 3.2
Provider severity
HIGH, MEDIUM
Conflicts
3

CVE-2026-42337

MaxKB is an open-source AI assistant for enterprise. MaxKB 2.8.0 and prior are vulnerable to a broken access control vulnerability in the OSS file service URL fetch API (chat/api/oss/get_url). The endpoint uses application_id from the URL path without validating ownership, allowing attackers to perform operations under other applications’ policies. This vulnerability is fixed in 2.8.1.

PUBLISHED
Vendor
1Panel-dev
Product
MaxKB
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42336

MaxKB is an open-source AI assistant for enterprise. MaxKB 2.8.0 and prior are vulnerable to a server-side request forgery (SSRF) bypass in the OSS file service URL fetch functionality due to inconsistent DNS resolution between validation and actual request execution, allowing attackers to access internal network services. This vulnerability is fixed in 2.8.1.

PUBLISHED
Vendor
1Panel-dev
Product
MaxKB
Provider severity
MEDIUM
Conflicts
1