Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-42280

Auth0.js is a client-side JavaScript library for Auth0. From 8.11.0 to 9.32.0, under specific preconditions, the Auth0.js SDK may improperly return user profile information using a valid access token when a specifically crafted invalid ID token is provided. This vulnerability is fixed in 10.0.0.

PUBLISHED
Vendor
auth0
Product
auth0.js
Provider severity
HIGH
Conflicts
0

CVE-2026-4228

A vulnerability was detected in LB-LINK BL-WR9000 2.4.9. This affects the function sub_458754 of the file /goform/set_wifi. The manipulation results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
LB-LINK
Product
BL-WR9000
Provider severity
MEDIUM
Conflicts
2

CVE-2026-42279

solidtime is an open-source time-tracking app. In version 0.12.0, the PUT /api/v1/organizations/{organization}/time-entries/{timeEntry} API accepts a route-bound timeEntry from another organization when the caller has time-entries:update:all in the URL organization, allowing a known foreign time-entry UUID to be modified and rebound to objects in the caller's organization. This issue has been patched in version 0.12.1.

PUBLISHED
Vendor
solidtime-io
Product
solidtime
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42278

UltraDAG is a minimal DAG-BFT blockchain in Rust. Prior to commit fb6ef59, the UltraDAG StateEngine implementation of SmartTransferTx contains a critical logic flaw in its policy enforcement pipeline. When a transaction originates from a "Pocket" (a derived sub-address documented in the protocol as a way to organize funds), the engine fails to resolve the pocket's parent account before checking the spending policy. Because pockets are "virtual" addresses that exist only as entries in the pocket_

PUBLISHED
Vendor
UltraDAGcom
Product
core
Provider severity
HIGH
Conflicts
1

CVE-2026-42277

Onyx is an open-source AI platform. Prior to versions 3.0.9, 3.1.6, and 3.2.6, the GET /chat/file/{file_id} endpoint allows any authenticated user to download any other user's uploaded files by providing the file UUID. The endpoint verifies the caller is authenticated but never checks that the file belongs to them. An attacker who knows or obtains a file UUID can access confidential documents, chat attachments, and other files uploaded by any user in the system. This issue has been patched in ve

PUBLISHED
Vendor
onyx-dot-app
Product
onyx
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42276

Onyx is an open-source AI platform. Prior to versions 3.0.9, 3.1.6, and 3.2.6, the POST /chat/stop-chat-session/{chat_session_id} endpoint lets any authenticated user stop any other user's active chat session. The endpoint checks authentication but never verifies the session belongs to the caller. An attacker who knows a chat session UUID can kill another user's LLM generation mid-stream. This issue has been patched in versions 3.0.9, 3.1.6, and 3.2.6.

PUBLISHED
Vendor
onyx-dot-app
Product
onyx
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42275

zrok is software for sharing web services, files, and network resources. Prior to version 2.0.2, the zrok WebDAV drive backend (davServer.Dir) restricts path traversal through lexical normalization but does not prevent symlink following. When a symbolic link inside the shared DriveRoot points to a location outside that root, remote WebDAV consumers can read files and—on shares without OS-level permission restrictions—write or overwrite files anywhere on the host filesystem accessible to the zrok

PUBLISHED
Vendor
openziti
Product
zrok
Provider severity
HIGH
Conflicts
1

CVE-2026-42274

Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall performs rule matching on the raw (non-normalized) request path, while downstream components may normalize dot-segments according to RFC 3986, Section 6.2.2.3. This discrepancy can result in heimdall authorizing a request for one path (e.g., /user/../admin, or URL-encoded variants such as /user/%2e%2e/admin or /user/%2e%2e%2fadmin. The latter would require the allow_encoded_sla

PUBLISHED
Vendor
dadrus
Product
heimdall
Provider severity
HIGH
Conflicts
1

CVE-2026-42273

Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall performs host matching in a case-sensitive manner, while HTTP hostnames are case-insensitive. This discrepancy can result in heimdall failing to match a rule for a request host that differs only in letter casing, potentially causing the request to be classified differently than intended. This issue has been patched in version 0.17.14.

PUBLISHED
Vendor
dadrus
Product
heimdall
Provider severity
HIGH
Conflicts
1

CVE-2026-42272

Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall handles URL-encoded slashes (%2F) in a case-sensitive manner, while percent-encoding is defined to be case-insensitive. As a result, the lowercase equivalent (%2f) is not recognized and therefore not processed as expected when allow_encoded_slashes is set to off (the default setting). This discrepancy can lead to differences in how request paths are interpreted by heimdall and

PUBLISHED
Vendor
dadrus
Product
heimdall
Provider severity
HIGH
Conflicts
1

CVE-2026-42271

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list — accepted a full server configuration in the request body, including the command, args, and env fields used by the stdio transport. When called with a stdio configuration, the endpoints attempted to connect, which spawned the supplied com

PUBLISHEDCISA KEV
Vendor
Red Hat, BerriAI, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat OpenShift AI 3.4, litellm, Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI 3.3, Exploit Intelligence, Red Hat OpenShift AI 2.25
Provider severity
HIGH
Conflicts
3

CVE-2026-4227

A security vulnerability has been detected in LB-LINK BL-WR9000 2.4.9. The impacted element is the function sub_44D844 of the file /goform/get_hidessid_cfg. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
LB-LINK
Product
BL-WR9000
Provider severity
HIGH
Conflicts
2

CVE-2026-42268

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 to before 3.0.15, there is an unhandled exception (std::out_of_range) caused by unsigned integer underflow in libmodsecurity3 if the user (administrator) uses a rule any of @verifySSN, @verifyCPF, or @verifySVNR. This vulnerability is fixed in 3.0.15.

PUBLISHED
Vendor
owasp-modsecurity
Product
ModSecurity
Provider severity
HIGH
Conflicts
1

CVE-2026-42267

Kimai is an open-source time tracking application. From version 2.27.0 to before version 2.54.0, any ROLE_USER can create a tag with a formula string as its name (e.g. =SUM(54+51)) via POST /api/tags and assign it to a timesheet. When an admin exports timesheets to XLSX, ArrayFormatter.formatValue() joins tag names with implode() and returns the result unchanged. OpenSpout promotes any =-prefixed string to a FormulaCell, writing <f>SUM(54+51)</f> into the XLSX archive. Excel evaluates the formul

PUBLISHED
Vendor
kimai
Product
kimai
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42266

A flaw was found in JupyterLab, an extensible environment for interactive computing. The PyPI Extension Manager, responsible for installing extensions, failed to properly enforce its allow-list of approved extensions. This vulnerability allowed for the installation of unauthorized extensions from sources outside the default PyPI index. Exploitation of this flaw could lead to arbitrary code execution and significant system compromise.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, jupyterlab, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), jupyterlab, Red Hat OpenShift AI (RHOAI), Red Hat Migration Toolkit for Applications 8.2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI)
Provider severity
HIGH
Conflicts
2

CVE-2026-42264

A flaw was found in Axios, a widely used HTTP client. This vulnerability, known as prototype pollution, allows an attacker to inject malicious properties into core JavaScript objects. When another component in the same application environment is compromised and pollutes the system's object prototype, Axios can unknowingly use these manipulated values in its outbound network requests. This could lead to the disclosure of sensitive information or the alteration of network communications, compromis

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, axios, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat AMQ Broker 7, Red Hat Data Grid 8.6.2, Red Hat Enterprise Linux 9, Red Hat Developer Hub, OpenShift Service Mesh 2, Red Hat Discovery 2, Red Hat Ansible Automation Platform 2, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat OpenShift AI (RHOAI), OpenShift Service Mesh 3, Red Hat OpenShift Service Mesh 3.0, Cryostat 4, Red Hat Satellite 6, Red Hat Ansible Automation Platform 2, Red Hat OpenShift Container Platform 4, Migration Toolkit for Applications 8, Red Hat OpenShift Virtualization 4, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, Red Hat Migration Toolkit 1.8, Red Hat OpenShift Service Mesh 3.3, Red Hat Ansible Automation Platform 2, Red Hat Advanced Cluster Security for Kubernetes 4.10, Red Hat OpenShift AI (RHOAI), Red Hat Trusted Artifact Signer, Network Observability Operator, Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat build of Apicurio Registry 3, Red Hat OpenShift Service Mesh 3.0, Red Hat Advanced Cluster Security for Kubernetes 4.11, Red Hat OpenShift AI (RHOAI), Red Hat build of Apache Camel - HawtIO 4, Red Hat Quay 3, Red Hat OpenShift Service Mesh 3.3, Network Observability Operator, Cryostat 4, Red Hat build of Apicurio Registry 2, Red Hat OpenShift Service Mesh 3.2, Red Hat OpenShift AI (RHOAI), Red Hat build of Apache Camel for Spring Boot 4, Self-service automation portal 2, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Red Hat Ansible Automation Platform 2.7, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat Satellite 6, OpenShift Pipelines, Red Hat 3scale API Management Platform 2, Migration Toolkit for Applications 8, Red Hat OpenShift Service Mesh 3.1, Red Hat OpenShift Dev Spaces, OpenShift Service Mesh 2, Red Hat Ansible Automation Platform 2, OpenShift Pipelines, Network Observability Operator, Red Hat Quay 3, Gatekeeper 3, Red Hat OpenShift Virtualization 4, Red Hat Advanced Cluster Security 4.9, Red Hat build of Apicurio Registry 3, Red Hat OpenShift Container Platform 4, Red Hat Fuse 7, OpenShift Service Mesh 3, Red Hat 3scale API Management Platform 2, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Trusted Profile Analyzer, Red Hat Satellite 6, Red Hat OpenShift AI (RHOAI), axios, Red Hat OpenShift Service Mesh 3.2, Red Hat Enterprise Linux 8, Red Hat OpenShift Container Platform 4, Red Hat OpenShift AI (RHOAI), Self-service automation portal 2, Red Hat OpenShift Dev Spaces, Red Hat Ansible Automation Platform 2, Red Hat Process Automation 7, Red Hat 3scale API Management Platform 2, Red Hat OpenShift Container Platform 4, Multicluster Engine for Kubernetes, streams for Apache Kafka 2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Service Mesh 3.1, Red Hat Ansible Automation Platform 2, Network Observability Operator, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Enterprise Linux AI (RHEL AI) 3
Provider severity
HIGH
Conflicts
2

CVE-2026-42261

PromptHub is an all-in-one AI toolbox for prompt, skill, and agent management. From version 0.4.9 to before version 0.5.4, apps/web/src/routes/skills.ts exposes an authenticated endpoint POST /api/skills/fetch-remote that fetches a user-supplied URL server-side and reflects the response body (up to 5 MB) back to the caller. The SSRF protection in apps/web/src/utils/remote-http.ts (isPrivateIPv6) attempts to block private/loopback destinations, but multiple alternate-but-valid IPv6 representation

PUBLISHED
Vendor
legeling
Product
PromptHub
Provider severity
HIGH
Conflicts
1

CVE-2026-42260

Open-WebSearch is a multi-engine MCP server, CLI, and local daemon for agent web search and content retrieval. Prior to 2.1.7, isPublicHttpUrl / assertPublicHttpUrl in src/utils/urlSafety.ts do not recognize bracketed IPv6 literals and do not resolve DNS, which combine to allow non-blind SSRF with the response body returned to the caller. This vulnerability is fixed in 2.1.7.

PUBLISHED
Vendor
Aas-ee
Product
open-webSearch
Provider severity
HIGH
Conflicts
0

CVE-2026-4226

A weakness has been identified in LB-LINK BL-WR9000 2.4.9. The affected element is the function sub_44E8D0 of the file /goform/get_virtual_cfg. Executing a manipulation can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
LB-LINK
Product
BL-WR9000
Provider severity
HIGH
Conflicts
2

CVE-2026-42259

Saltcorn is an extensible, open source, no-code database application builder. Prior to versions 1.4.6, 1.5.6, and 1.6.0-beta.5, Saltcorn validates the post-login dest parameter with a string check that only blocks :/ and //. Because all WHATWG-compliant browsers normalise backslashes (\) to forward slashes (/) for special schemes, a payload such as /\evil.com/path slips through is_relative_url(), is emitted unchanged in the HTTP Location header, and causes the browser to navigate cross-origin to

PUBLISHED
Vendor
saltcorn
Product
saltcorn
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42258

A flaw was found in Net::IMAP, a Ruby library that provides Internet Message Access Protocol (IMAP) client functionality. This vulnerability allows a remote attacker to inject arbitrary IMAP commands. This is achieved by passing specially crafted symbol arguments to IMAP commands. Successful exploitation could lead to unauthorized actions on the IMAP server or client, potentially resulting in information disclosure or other integrity impacts.

PUBLISHED
Vendor
Red Hat, ruby, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 9, net-imap, Red Hat Enterprise Linux 9, Red Hat OpenShift AI (RHOAI), Red Hat 3scale API Management Platform 2, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat 3scale API Management Platform 2, Red Hat Hardened Images, Red Hat 3scale API Management Platform 2, Red Hat Hardened Images, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Red Hat Enterprise Linux 6, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Hardened Images, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions, Red Hat Enterprise Linux 8, Red Hat 3scale API Management Platform 2, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat OpenShift Dev Spaces, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat 3scale API Management Platform 2
Provider severity
HIGH, MEDIUM
Conflicts
3

CVE-2026-42257

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, several Net::IMAP commands accept a raw string argument that is sent to the server without validation or escaping. If this string is derived from user-controlled input, it may contain contain CRLF sequences, which an attacker can use to inject arbitrary IMAP commands. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.

PUBLISHED
Vendor
ruby
Product
net-imap
Provider severity
MEDIUM
Conflicts
1

CVE-2026-42256

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. From versions 0.4.0 to before 0.4.24, 0.5.0 to before 0.5.14, and 0.6.0 to before 0.6.4, when authenticating a connection with SCRAM-SHA1 or SCRAM-SHA256, a hostile server can perform a computational denial-of-service attack on the client process by sending a big iteration count value. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.

PUBLISHED
Vendor
ruby
Product
net-imap
Provider severity
MEDIUM
Conflicts
1

CVE-2026-42255

Technitium DNS Server before 15.0 allows DNS traffic amplification via cyclic name server delegation.

PUBLISHED
Vendor
Technitium
Product
DnsServer
Provider severity
HIGH
Conflicts
0

CVE-2026-42254

Hickory DNS hickory-recursor 0.1 through 0.25.2 allows cross-zone poisoning because cached data is not directly associated with a query that triggered a response.

PUBLISHED
Vendor
Hickory Project
Product
Hickory DNS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42253

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web. The MessageServlet in the ActiveMQ web console API copies every JMS message property into an HTTP response header without any validation. This can allow overwriting and injecting security headers by setting them on JMS messages that are returned by the servlet. This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ Web:

PUBLISHED
Vendor
Apache Software Foundation, Apache Software Foundation
Product
Apache ActiveMQ, Apache ActiveMQ Web
Provider severity
MEDIUM
Conflicts
1

CVE-2026-42252

Apache Airflow's official documentation at `core-concepts/dag-run.html` ("Passing Parameters when triggering Dags") showed a verbatim `BashOperator(bash_command="echo value: {{ dag_run.conf['conf1'] }}")` example without any quoting / sanitization warning. Dag authors who copied the pattern verbatim into deployments where users had `Dag.can_trigger` permission on the affected Dag (typical multi-team deployments, hosted offerings exposing a trigger API) could be exposed to shell-metacharacter inj

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Airflow
Provider severity
CRITICAL
Conflicts
0

CVE-2026-42251

Use of hard-coded credentials in KS-SOMED allowed an unauthorized attacker access to FTP server that hosted the application's update packages. The attacker with these credentials could upload a malicious update file, which then may have been distributed and installed on client machines as a legitimate update. This issue affects KS-SOMED with modules: KSPLUPDFTP.exe up to 30.00.00.056 and ANEKSKLIENT.EXE up to 29.00.02.026 Beside removing the hard-coded credentials from the code and changing th

PUBLISHED
Vendor
KAMSOFT, KAMSOFT
Product
KS-SOMED, KS-SOMED
Provider severity
HIGH
Conflicts
1

CVE-2026-42250

bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service). This issue was fixed in bzip2 patch 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67

PUBLISHED
Vendor
bzip2
Product
bzip2
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4225

A security flaw has been discovered in CMS Made Simple up to 2.2.21. Impacted is an unknown function of the file admin/listusers.php of the component User Management Module. Performing a manipulation of the argument Message results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.

PUBLISHED
Vendor
n/a
Product
CMS Made Simple
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-42249

Ollama for Windows contains a Remote Code Execution vulnerability in its update mechanism due to improper handling of attacker‑controlled HTTP response headers. When downloading updates, the application constructs local file paths using values derived from HTTP headers without validation. These values are passed directly to filepath.Join, allowing path traversal sequences (../) to be resolved and enabling files to be written outside the intended update staging directory. An attacker who can infl

PUBLISHED
Vendor
Ollama
Product
Ollama
Provider severity
HIGH
Conflicts
1

CVE-2026-42248

Ollama for Windows does not perform integrity or authenticity verification of downloaded update executables. Unlike other platforms, the Windows implementation of the update verification routine unconditionally returns success so no digital signature or trust validation is performed before staging or executing update payloads, enabling attacker‑supplied executables to be accepted and later executed by the application. Critically, Ollama for Windows performs silent automatic updates, so the mali

PUBLISHED
Vendor
Ollama
Product
Ollama
Provider severity
HIGH
Conflicts
0

CVE-2026-42246

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4, a man-in-the-middle attacker can cause Net::IMAP#starttls to return "successfully", without starting TLS. This issue has been patched in versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, ruby, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat 3scale API Management Platform 2, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat 3scale API Management Platform 2, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions, Red Hat Enterprise Linux 10, Red Hat 3scale API Management Platform 2, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions, Red Hat Hardened Images, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Hardened Images, Red Hat Enterprise Linux 9.6 Extended Update Support, net-imap, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Red Hat Hardened Images, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9.6 Extended Update Support
Provider severity
HIGH
Conflicts
3

CVE-2026-42245

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, Net::IMAP::ResponseReader has quadratic time complexity when reading large responses containing many string literals. A hostile server can send responses which are crafted to exhaust the client's CPU for a denial of service attack. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.

PUBLISHED
Vendor
ruby
Product
net-imap
Provider severity
LOW
Conflicts
0

CVE-2026-42241

ParquetSharp is a .NET library for reading and writing Apache Parquet files. From version 18.1.0 to before version 23.0.0.1, DecimalConverter.ReadDecimal makes a stackalloc using what might be an attacker-supplied value. If an attacker declares a decimal column with some unreasonable width, this could lead to a stack overflow. In a service environment, this would potentially take down a service. This affects applications using ParquetSharp to read untrusted Parquet files in a network service. Th

PUBLISHED
Vendor
G-Research
Product
ParquetSharp
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4224

When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs.

PUBLISHED
Vendor
Python Software Foundation
Product
CPython
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42239

Budibase is an open-source low-code platform. Prior to version 3.35.10, the budibase:auth cookie containing the JWT session token is set with httpOnly: false at packages/backend-core/src/utils/utils.ts:218. JavaScript can read this cookie via document.cookie. This means every XSS becomes a full account takeover — the attacker steals the JWT and has persistent access to the victim's account. The cookie also lacks secure: true (sent over plaintext HTTP) and sameSite attribute. This issue has been

PUBLISHED
Vendor
Budibase
Product
budibase
Provider severity
HIGH
Conflicts
0

CVE-2026-42238

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, nginx-ui exposes a backup restore endpoint (POST /api/restore) that is completely unauthenticated during the first 10 minutes after process startup on any fresh installation. An unauthenticated remote attacker can upload a crafted backup archive that overwrites the application's configuration file (app.ini) and SQLite database. Because the attacker controls the restored app.ini, they can inject an arbitrary OS com

PUBLISHED
Vendor
0xJacky
Product
nginx-ui
Provider severity
CRITICAL
Conflicts
0

CVE-2026-42237

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the fix for GHSA-f3f2-mcxc-pwjx did not cover the Snowflake node or the legacy MySQL v1 node. Both nodes construct SQL queries by directly interpolating user-controlled table names, column names, and update keys into query strings without identifier escaping, enabling SQL injection against the connected database. This issue has been patched in versions 1.123.32, 2.17.4, and 2.18.1.

PUBLISHED
Vendor
n8n-io
Product
n8n
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42236

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the MCP OAuth client registration endpoint accepted unauthenticated requests and stored client data without adequate resource controls. An unauthenticated remote attacker could exhaust server memory resources by sending large registration payloads, rendering the n8n instance unavailable. The MCP enable/disable toggle gates MCP access but did not restrict client registrations, meaning the endpoint

PUBLISHED
Vendor
n8n-io
Product
n8n
Provider severity
HIGH
Conflicts
0

CVE-2026-42235

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an unauthenticated attacker could register a malicious MCP OAuth client with a crafted client_name. If a victim user authorized the OAuth consent dialog and a second user subsequently revoked that access, a toast notification would render the injected script. Clicking the link would execute arbitrary JavaScript in the victim's authenticated n8n browser session, enabling credential and session toke

PUBLISHED
Vendor
n8n-io
Product
n8n
Provider severity
HIGH
Conflicts
1

CVE-2026-42234

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated user with permission to create or modify workflows containing a Python Code Node could escape the sandbox and achieve arbitrary code execution on the task runner container. This issue only affects instances where the Python Task Runner is enabled. This issue has been patched in versions 1.123.32, 2.17.4, and 2.18.1.

PUBLISHED
Vendor
n8n-io
Product
n8n
Provider severity
HIGH
Conflicts
0

CVE-2026-42233

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the Oracle Database node's select operation allowed user-controlled input passed into the Limit field via expressions to be interpolated directly into the SQL query without sanitization or parameterization. In workflows where external input is passed into the Limit field (e.g., from a webhook), an attacker could inject arbitrary SQL and exfiltrate data from the connected Oracle database.

PUBLISHED
Vendor
n8n-io
Product
n8n
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42232

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated user with permission to create or modify workflows could achieve global prototype pollution via the XML Node leading to RCE when combined with other nodes exploiting the prototype pollution. This issue has been patched in versions 1.123.32, 2.17.4, and 2.18.1.

PUBLISHED
Vendor
n8n-io
Product
n8n
Provider severity
CRITICAL
Conflicts
0

CVE-2026-42231

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the xml2js library used to parse XML request bodies in n8n's webhook handler allowed prototype pollution via a crafted XML payload. An authenticated user with permission to create or modify workflows could exploit this to pollute the JavaScript object prototype and, by chaining the pollution with the Git node's SSH operations, achieve remote code execution on the n8n host. This issue has

PUBLISHED
Vendor
n8n-io
Product
n8n
Provider severity
CRITICAL
Conflicts
0

CVE-2026-42230

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the /mcp-oauth/register endpoint accepted OAuth client registrations without authentication, allowing arbitrary redirect_uri values to be registered. When a user denies the MCP OAuth consent dialog, the handleDeny handler redirects the user to the registered redirect_uri without validation, enabling an open redirect to an attacker-controlled URL. An attacker can craft a phishing link and send it t

PUBLISHED
Vendor
n8n-io
Product
n8n
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4223

A vulnerability was identified in itsourcecode Payroll Management System 1.0. This issue affects some unknown processing of the file /manage_employee.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.

PUBLISHED
Vendor
itsourcecode
Product
Payroll Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-42229

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the SeaTable node's row:search and row:get operations allowed user-controlled input to be concatenated directly into SQL query strings without escaping or parameterization. In workflows where external user input is passed via expressions into the SeaTable node's search or row retrieval parameters, an attacker could manipulate the constructed query to retrieve unintended rows from the con

PUBLISHED
Vendor
n8n-io
Product
n8n
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42228

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the /chat WebSocket endpoint used by the Chat Trigger node's Hosted Chat feature did not verify that an incoming connection was authorized to interact with the target execution. An unauthenticated remote attacker who could identify a valid execution ID for a workflow in a waiting state could attach to that execution, receive the pending prompt intended for the legitimate user, and submit arbitrary

PUBLISHED
Vendor
n8n-io
Product
n8n
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42227

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated user with a valid API key scoped to variable:list could read variables from projects they are not a member of by supplying an arbitrary projectId query parameter to the public API variables endpoint. The handler queried the variables repository directly without enforcing project membership checks, bypassing the authorization-aware service layer used by the internal enterprise cont

PUBLISHED
Vendor
n8n-io
Product
n8n
Provider severity
MEDIUM
Conflicts
0