Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-4021

The Contest Gallery plugin for WordPress is vulnerable to an authentication bypass leading to admin account takeover in all versions up to, and including, 28.1.5. This is due to the email confirmation handler in `users-registry-check-after-email-or-pin-confirmation.php` using the user's email string in a `WHERE ID = %s` clause instead of the numeric user ID, combined with an unauthenticated key-based login endpoint in `ajax-functions-frontend.php`. When the non-default `RegMailOptional=1` settin

PUBLISHED
Vendor
contest-gallery
Product
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe
Provider severity
HIGH
Conflicts
0

CVE-2026-40209

An attacker might be able to cause outgoing TCP connections to backend to be stuck until a timeout occurs instead of being released immediately, by sending IXFR queries. This could be used to cause a denial of service if there is a limit to the number of concurrent connections to this backend, or if the process runs out of file descriptors.

PUBLISHED
Vendor
PowerDNS
Product
DNSdist
Provider severity
MEDIUM
Conflicts
1

CVE-2026-40208

An attacker might be able to delay the processing of DoH3 queries by sending DoH3 GET queries with an invalid DATA frame.

PUBLISHED
Vendor
PowerDNS
Product
DNSdist
Provider severity
LOW
Conflicts
1

CVE-2026-40201

@diplodoc/search-extension 1.0.0 through 3.x before 3.0.3 allows stored XSS via the title in a .md file.

PUBLISHED
Vendor
diplodoc-platform
Product
@diplodoc/search-extension
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40200

An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory corruption can occur during qsort of very large arrays, due to incorrectly implemented double-word primitives. The number of elements must exceed about seven million, i.e., the 32nd Leonardo number on 32-bit platforms (or the 64th Leonardo number on 64-bit platforms, which is not practical).

PUBLISHED
Vendor
musl-libc
Product
musl
Provider severity
HIGH
Conflicts
0

CVE-2026-4020

The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4. This is due to a REST API endpoint registered at /wp-json/gravitysmtp/v1/tests/mock-data with a permission_callback that unconditionally returns true, allowing any unauthenticated visitor to access it. When the ?page=gravitysmtp-settings query parameter is appended, the plugin's register_connector_data() method populates internal connector data, causing the endpoint

PUBLISHED
Vendor
RocketGenius
Product
Gravity SMTP
Provider severity
HIGH
Conflicts
0

CVE-2026-40199

Net::CIDR::Lite versions before 0.23 for Perl mishandles IPv4 mapped IPv6 addresses, which may allow IP ACL bypass. _pack_ipv6() includes the sentinel byte from _pack_ipv4() when building the packed representation of IPv4 mapped addresses like ::ffff:192.168.1.1. This produces an 18 byte value instead of 17 bytes, misaligning the IPv4 part of the address. The wrong length causes incorrect results in mask operations (bitwise AND truncates to the shorter operand) and in find() / bin_find() which

PUBLISHED
Vendor
STIGTSP
Product
Net::CIDR::Lite
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40198

Net::CIDR::Lite versions before 0.23 for Perl does not validate IPv6 group count, which may allow IP ACL bypass. _pack_ipv6() does not check that uncompressed IPv6 addresses (without ::) have exactly 8 hex groups. Inputs like "abcd", "1:2:3", or "1:2:3:4:5:6:7" are accepted and produce packed values of wrong length (3, 7, or 15 bytes instead of 17). The packed values are used internally for mask and comparison operations. find() and bin_find() use Perl string comparison (lt/gt) on these values

PUBLISHED
Vendor
STIGTSP
Product
Net::CIDR::Lite
Provider severity
HIGH
Conflicts
0

CVE-2026-40197

Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage volume import logic allows an authenticated user with access to the storage volume feature to cause the Incus daemon to crash. The custom volume backup import subsystem contains a nil-pointer dereference vulnerability during import operations. In the snapshot import loop, the daemon iterates over entries from `srcBackup.Config.VolumeSnapshots` and assumes that each slice ele

PUBLISHED
Vendor
lxc
Product
incus
Provider severity
HIGH
Conflicts
0

CVE-2026-40196

HomeBox is a home inventory and organization system. Versions prior to 0.25.0 contain a vulnerability where the defaultGroup ID remained permanently assigned to a user after being invited to a group, even after their access to that group was revoked. While the web interface correctly enforced the access revocation and prevented the user from viewing or modifying the group's contents, the API did not. Because the original group ID persisted as the user's defaultGroup, and this value was not prope

PUBLISHED
Vendor
sysadminsmedia
Product
homebox
Provider severity
HIGH
Conflicts
0

CVE-2026-40195

Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage bucket import logic allows an authenticated user with access to the storage bucket feature to cause the Incus daemon to crash. The vulnerability is present in the backup metadata handling logic, where the daemon processes the index.yaml file from an imported archive and accesses members of the parsed backup configuration without first verifying that the configuration object

PUBLISHED
Vendor
lxc
Product
incus
Provider severity
HIGH
Conflicts
0

CVE-2026-40194

phpseclib is a PHP secure communications library. Starting in 0.1.1 and prior to 3.0.51, 2.0.53, and 1.0.28, phpseclib\Net\SSH2::get_binary_packet() uses PHP's != operator to compare a received SSH packet HMAC against the locally computed HMAC. != on equal-length binary strings in PHP uses memcmp(), which short-circuits on the first differing byte. This is a real variable-time comparison (CWE-208), proven by scaling benchmarks. This vulnerability is fixed in 3.0.51, 2.0.53, and 1.0.28.

PUBLISHED
Vendor
phpseclib
Product
phpseclib
Provider severity
LOW
Conflicts
0

CVE-2026-40193

maddy is a composable, all-in-one mail server. Versions prior to 0.9.3 contain an LDAP injection vulnerability in the auth.ldap module where user-supplied usernames are interpolated into LDAP search filters and DN strings via strings.ReplaceAll() without any LDAP filter escaping, despite the go-ldap/ldap/v3 library's ldap.EscapeFilter() function being available in the same import. This affects three code paths: the Lookup() filter, the AuthPlain() DN template, and the AuthPlain() filter. An atta

PUBLISHED
Vendor
foxcpp
Product
maddy
Provider severity
HIGH
Conflicts
0

CVE-2026-40192

A flaw was found in Pillow, a Python imaging library. This vulnerability allows a remote attacker to trigger a denial of service (DoS) by providing a specially crafted FITS image file. The library's failure to limit the amount of GZIP-compressed data during decoding can lead to unbounded memory consumption, causing the system to crash or experience severe performance issues.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, python-pillow, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Satellite 6.18 for RHEL 9, Red Hat OpenShift AI (RHOAI), Red Hat Satellite 6.19 for RHEL 9, Red Hat Quay 3.17, Red Hat AI Inference Server 3.3, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Red Hat Enterprise Linux AI 3.3, Red Hat AI Inference Server 3.3, Red Hat OpenShift AI 3.3, Red Hat OpenShift AI 3.3, Red Hat OpenShift AI 3.3, Red Hat Enterprise Linux AI 3.3, Red Hat Satellite 6.16 for RHEL 9, Red Hat Enterprise Linux AI 3.3, Red Hat Quay 3.16, Red Hat OpenShift AI 3.3, Red Hat OpenShift AI 3.3, Red Hat Enterprise Linux AI 3.3, Red Hat Ansible Automation Platform 2.6, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2.6 for RHEL 9, Red Hat OpenShift AI (RHOAI), Red Hat AI Inference Server, Red Hat OpenShift AI 3.3, OpenShift Lightspeed, Red Hat OpenShift AI 3.3, Red Hat OpenShift AI 3.3, Lightspeed Core, Red Hat OpenShift AI 3.3, Red Hat Enterprise Linux AI 3.3, Red Hat AI Inference Server, Red Hat OpenShift AI (RHOAI), Red Hat Satellite 6.17 for RHEL 9, Red Hat OpenShift AI 3.3, Red Hat Quay 3.14, Red Hat Quay 3.15, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat AI Inference Server, Red Hat OpenShift AI 3.3, Red Hat AI Inference Server 3.3, Red Hat Satellite 6.16 for RHEL 8, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux 7, Red Hat OpenShift AI 3.3, Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat OpenShift AI 3.3, Red Hat Enterprise Linux 8, Red Hat OpenShift AI 3.3, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI 3.3, Red Hat OpenShift AI (RHOAI), Red Hat Quay 3.1, Red Hat OpenShift AI 3.3, Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2.6, Red Hat OpenShift AI 3.3, Red Hat AI Inference Server 3.3, Red Hat Enterprise Linux AI 3.3, Pillow, Red Hat OpenShift AI 2.25, Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI 3.3, Red Hat Quay 3.12, OpenShift Lightspeed, OpenShift Lightspeed, Red Hat Enterprise Linux AI 3.3, Red Hat Quay 3.9
Provider severity
HIGH
Conflicts
3

CVE-2026-40191

ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to 5.0.4-beta-1f46165, ClearanceKit's Endpoint Security event handler only checked the source path of dual-path file operations against File Access Authorization (FAA) rules and App Jail policies. The destination path was ignored entirely. This allowed any local process to bypass file-access protection by using rename, link, copyfile, exchangedata, or clone operations to place or replace f

PUBLISHED
Vendor
craigjbass
Product
clearancekit
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40190

LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.5.18, the LangSmith JavaScript/TypeScript SDK (langsmith) contains an incomplete prototype pollution fix in its internally vendored lodash set() utility. The baseAssignValue() function only guards against the __proto__ key, but fails to prevent traversal via constructor.prototype. This allows an attacker who controls keys in data processed by the createAnonymizer() API to pollute Object.prototype, affecti

PUBLISHED
Vendor
langchain-ai
Product
langsmith-sdk
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4019

The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to unauthorized data access in all versions up to, and including, 7.4.5 This is due to the REST API endpoint at /wp-json/complianz/v1/consent-area/{post_id}/{block_id} using __return_true as the permission_callback, allowing any unauthenticated user to access it. The cmplz_rest_consented_content() function retrieves a post by ID via get_post() and returns the consentedContent attribute of any complianz/consent-area block

PUBLISHED
Vendor
complianz
Product
Complianz – GDPR/CCPA Cookie Consent
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40189

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.4, goshs enforces the documented per-folder .goshs ACL/basic-auth mechanism for directory listings and file reads, but it does not enforce the same authorization checks for state-changing routes. An unauthenticated attacker can upload files with PUT, upload files with multipart POST /upload, create directories with ?mkdir, and delete files with ?delete inside a .goshs-protected directory. By deleting the .goshs file itself, the attac

PUBLISHED
Vendor
patrickhener
Product
goshs
Provider severity
CRITICAL
Conflicts
0

CVE-2026-40188

goshs is a SimpleHTTPServer written in Go. From 1.0.7 to before 2.0.0-beta.4, the SFTP command rename sanitizes only the source path and not the destination, so it is possible to write outside of the root directory of the SFTP. This vulnerability is fixed in 2.0.0-beta.4.

PUBLISHED
Vendor
patrickhener
Product
goshs
Provider severity
HIGH
Conflicts
0

CVE-2026-40187

In egroupware version 26.0 and earlier, an authenticated administrator can achieve OS-level Remote Code Execution (RCE) by uploading a malicious eTemplate XML file (`.xet`) to the VFS `/etemplates` mount. The `Widget::expand_name()` method passes template widget attribute values directly into a PHP `eval()` call with only double-quote escaping applied - **backtick characters are not escaped**. In PHP, backticks inside a double-quoted `eval()` string execute shell commands. This allows an admin-l

PUBLISHED
Vendor
EGroupware
Product
egroupware
Provider severity
HIGH
Conflicts
1

CVE-2026-40186

ApostropheCMS is an open-source Node.js content management system. A regression introduced in commit 49d0bb7, included in versions 2.17.1 of the ApostropheCMS-maintained sanitize-html package bypasses allowedTags enforcement for text inside nonTextTagsArray elements (textarea and option). ApostropheCMS version 4.28.0 is affected through its dependency on the vulnerable sanitize-html version. The code at packages/sanitize-html/index.js:569-573 incorrectly assumes that htmlparser2 does not decode

PUBLISHED
Vendor
apostrophecms, apostrophecms
Product
sanitize-html, apostrophe
Provider severity
MEDIUM
Conflicts
1

CVE-2026-40185

TREK is a collaborative travel planner. Prior to 2.7.2, TREK was missing authorization checks on the Immich trip photo management routes. This vulnerability is fixed in 2.7.2.

PUBLISHED
Vendor
mauriceboe
Product
TREK
Provider severity
HIGH
Conflicts
0

CVE-2026-40184

TREK is a collaborative travel planner. Prior to 2.7.2, TREK served uploaded photos without requiring authentication. This vulnerability is fixed in 2.7.2.

PUBLISHED
Vendor
mauriceboe
Product
TREK
Provider severity
LOW
Conflicts
0

CVE-2026-40183

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-19, the JXL encoder has an heap write overflow when a user specifies that the image should be encoded as 16 bit floats. This issue has been fixed in version 7.1.2-19.

PUBLISHED
Vendor
ImageMagick
Product
ImageMagick
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40182

OpenTelemetry dotnet is a dotnet telemetry framework. From 1.13.1 to before 1.15.2, When exporting telemetry to a back-end/collector over gRPC or HTTP using OpenTelemetry Protocol format (OTLP), if the request results in a unsuccessful request (i.e. HTTP 4xx or 5xx), the response is read into memory with no upper-bound on the number of bytes consumed. This could cause memory exhaustion in the consuming application if the configured back-end/collector endpoint is attacker-controlled (or a network

PUBLISHED
Vendor
open-telemetry
Product
opentelemetry-dotnet
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40181

React Router is a router for React. In versions 7.0.0 through 7.14.0 and 6.7.0 through 6.30.3, certain URLs passed to the redirect function can trigger an open redirect to an external domain due to path values starting with // being reinterpreted as protocol-relative URLs. The level of impact depends on the validation done by the application prior to returning the redirect. This does not impact applications using Declarative Mode (<BrowserRouter>). This is patched in versions 7.14.1 and 6.30.4.

PUBLISHED
Vendor
remix-run
Product
react-router
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40180

Quarkus OpenAPI Generator is Quarkus' extensions for generation of Rest Clients and server stubs generation. Prior to 2.16.0 and 2.15.0-lts, the unzip() method in ApicurioCodegenWrapper.java extracts ZIP entries without validating that the resolved file path stays within the intended output directory. At line 101, the destination is constructed as new File(toOutputDir, entry.getName()) and the content is written immediately. A malicious ZIP archive containing entries with path traversal sequence

PUBLISHED
Vendor
quarkiverse
Product
quarkus-openapi-generator
Provider severity
HIGH
Conflicts
0

CVE-2026-4018

TOCTOU Race Condition in specific trace commands of the TraceEvent() system call could allow an attacker with local access and with the PROCMGR_AID_TRACE ability, to cause information disclosure, data tampering or a crash of the QNX Neutrino kernel.

PUBLISHED
Vendor
BlackBerry Ltd, BlackBerry Ltd., BlackBerry Ltd
Product
QNX OS for Safety, QNX OS for Medical, QNX Software Development Platform
Provider severity
MEDIUM
Conflicts
1

CVE-2026-40179

Prometheus is an open-source monitoring system and time series database. Versions 3.0 through 3.5.1 and 3.6.0 through 3.11.1 have stored cross-site scripting vulnerabilities in multiple components of the Prometheus web UI where metric names and label values are injected into innerHTML without escaping. In both the Mantine UI and old React UI, chart tooltips on the Graph page render metric names containing HTML/JavaScript without sanitization. In the old React UI, the Metric Explorer fuzzy search

PUBLISHED
Vendor
prometheus
Product
prometheus
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40178

ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly. Prior to 0.112, if the 2FA was activated, it was possible during a short moment after the authentication of an user to bypass its authentication. This vulnerability is fixed in 0.112.

PUBLISHED
Vendor
ajenti
Product
ajenti
Provider severity
MEDIUM
Conflicts
1

CVE-2026-40177

ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly. Prior to 0.112, if the 2FA was activated, it was possible to bypass the password authentication This vulnerability is fixed in 0.112.

PUBLISHED
Vendor
ajenti
Product
ajenti
Provider severity
CRITICAL
Conflicts
0

CVE-2026-40176

Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection vulnerability in the Perforce::generateP4Command() method, which constructs shell commands by interpolating user-supplied Perforce connection parameters (port, user, client) without proper escaping. An attacker can inject arbitrary commands through these values in a malicious composer.json declaring a Perforce VCS repository, leading to command execution in the context of the u

PUBLISHED
Vendor
composer, Red Hat
Product
composer, Red Hat Hardened Images
Provider severity
HIGH
Conflicts
2

CVE-2026-40175

A flaw was found in Axios, a promise-based HTTP client. This vulnerability, known as Prototype Pollution, can be exploited through a specific "Gadget" attack chain. This allows an attacker to escalate a Prototype Pollution vulnerability in a third-party dependency, potentially leading to remote code execution or a full cloud compromise, such as bypassing AWS IMDSv2.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Siemens, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, axios, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
OpenShift Pipelines, Red Hat OpenShift Container Platform 4.15, Red Hat OpenShift Virtualization 4, Red Hat Migration Toolkit 1.8, Red Hat OpenShift Container Platform 4.2, Network Observability (NETOBSERV) 1.11.1, Red Hat 3scale API Management Platform 2, Streams for Apache Kafka 3.2.0, Red Hat 3scale API Management Platform 2, Red Hat build of Apicurio Registry 2, Red Hat OpenShift Container Platform 4.21, OpenShift Service Mesh 3, Red Hat Advanced Cluster Management for Kubernetes 2.14, Red Hat Trusted Artifact Signer 1.3, Logging Subsystem for Red Hat OpenShift, multicluster engine for Kubernetes 2.1, Red Hat OpenShift Service Mesh 3.1, Red Hat build of Apicurio Registry 3, Red Hat Build of Kueue, Red Hat OpenShift Container Platform 4.21, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI 3.3, Red Hat Ansible Automation Platform 2, Red Hat Build of Kueue, Red Hat Developer Hub 1.9, Red Hat Trusted Profile Analyzer, Red Hat OpenShift Dev Spaces 3.27, Red Hat OpenShift Service Mesh 3.2, Red Hat OpenShift AI 3.3, Red Hat Ansible Automation Platform 2, OpenShift Service Mesh 3, Network Observability (NETOBSERV) 1.11.1, Red Hat 3scale API Management Platform 2, Red Hat OpenShift Container Platform 4.19, Red Hat Ansible Automation Platform 2, Red Hat 3scale API Management Platform 2, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Ansible Automation Platform 2, Red Hat OpenShift Container Platform 4.2, Red Hat OpenShift Service Mesh 3.0, Red Hat OpenShift Service Mesh 2.6, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Gatekeeper 3, Red Hat OpenShift Service Mesh 3.3, Red Hat Fuse 7, Red Hat build of Apache Camel - HawtIO 4, Logging Subsystem for Red Hat OpenShift, Red Hat Satellite 6.18, Red Hat Discovery 2, Logging Subsystem for Red Hat OpenShift, Red Hat OpenShift Service Mesh 3.3, Red Hat OpenShift AI 3.3, Red Hat OpenShift Service Mesh 3.1, Red Hat Quay 3, multicluster engine for Kubernetes 2.6, Red Hat Satellite 6.18, Red Hat Ansible Automation Platform 2, Cryostat 4, Red Hat Satellite 6.18, Red Hat OpenShift Service Mesh 3.2, Self-service automation portal 2, Logging Subsystem for Red Hat OpenShift, Red Hat OpenShift AI (RHOAI), Red Hat Developer Hub 1.8, Red Hat 3scale API Management Platform 2, gWAP, Red Hat Ansible Automation Platform 2, Red Hat 3scale API Management Platform 2, Logging Subsystem for Red Hat OpenShift, Red Hat OpenShift AI (RHOAI), Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, multicluster engine for Kubernetes 2.9, Red Hat Ansible Automation Platform 2, Red Hat Data Grid 8, Red Hat Advanced Cluster Security 4.9, OpenShift Pipelines, Red Hat OpenShift Dev Spaces 3.27, Red Hat Developer Hub, Red Hat Build of Podman Desktop - Tech Preview, Red Hat Process Automation 7, Red Hat Build of Kueue, Red Hat Enterprise Linux AI (RHEL AI) 3, streams for Apache Kafka 2, Red Hat Ansible Automation Platform 2, multicluster engine for Kubernetes 2.8, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2.6 for RHEL 9, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift Container Platform 4.16, axios, Red Hat Build of Kueue, Red Hat Ansible Automation Platform 2, Red Hat OpenShift Service Mesh 2.6, Red Hat OpenShift Service Mesh 3.0, Red Hat OpenShift AI (RHOAI), Red Hat Quay 3, Red Hat OpenShift Virtualization 4, Red Hat OpenShift Container Platform 4.14, Red Hat build of Apicurio Registry 3, Migration Toolkit for Applications 8, Red Hat 3scale API Management Platform 2, Red Hat OpenShift AI 3.3, Logging Subsystem for Red Hat OpenShift, Red Hat Enterprise Linux 9, Red Hat Advanced Cluster Management for Kubernetes 2.15
Provider severity
CRITICAL, MEDIUM
Conflicts
3

CVE-2026-40174

Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the cUsers.updateAddress function does not properly validate anti-CSRF tokens for user address management operations. An attacker can induce a logged-in administrator to submit a forged request that adds, modifies, or deletes user address records, including email addresses and phone numbers. This can be used to alter contact information, redirect organizational communications, and corrupt address data i

PUBLISHED
Vendor
MasaCMS
Product
MasaCMS
Provider severity
HIGH
Conflicts
0

CVE-2026-40173

Dgraph is an open source distributed GraphQL database. Versions 25.3.1 and prior contain an unauthenticated credential disclosure vulnerability where the /debug/pprof/cmdline endpoint is registered on the default mux and reachable without authentication, exposing the full process command line including the admin token configured via the --security "token=..." startup flag. An attacker can retrieve the leaked token and reuse it in the X-Dgraph-AuthToken header to gain unauthorized access to admin

PUBLISHED
Vendor
dgraph-io
Product
dgraph
Provider severity
CRITICAL
Conflicts
1

CVE-2026-40172

authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, the PATCH /api/v3/core/users/{pk}/ API allows a caller with change_user on a target user to assign arbitrary groups through UserSerializer, including groups with is_superuser=True, without requiring enable_group_superuser, leading to privilege escalation. This bypasses the stricter permission model enforced in group-management paths and enables delegated user-management permissions to

PUBLISHED
Vendor
goauthentik
Product
authentik
Provider severity
HIGH
Conflicts
0

CVE-2026-40171

In Jupyter Notebook versions 7.0.0 through 7.5.5, JupyterLab versions 4.5.6 and earlier, and the corresponding @jupyter-notebook/help-extension and @jupyterlab/help-extension packages before 7.5.6 and 4.5.7, a stored cross-site scripting issue in the help command linker can be chained with attacker-controlled notebook content to steal authentication tokens with a single click. An attacker can craft a malicious notebook file containing elements that appear indistinguishable from legitimate contr

PUBLISHED
Vendor
jupyterlab, jupyter, jupyter-notebook, jupyterlab
Product
help-extension, notebook, help-extension, jupyterlab
Provider severity
HIGH
Conflicts
1

CVE-2026-40170

ngtcp2 is a C implementation of the IETF QUIC protocol. In versions prior to 1.22.1, ngtcp2_qlog_parameters_set_transport_params() serializes peer transport parameters into a fixed 1024-byte stack buffer without bounds checking. When qlog is enabled, a remote peer can send sufficiently large transport parameters during the QUIC handshake to cause writes beyond the buffer boundary, resulting in a stack buffer overflow. This affects deployments that enable the qlog callback and process untrusted p

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, ngtcp2, Red Hat, Red Hat
Product
Red Hat Hardened Images, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9, ngtcp2, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10
Provider severity
HIGH
Conflicts
2

CVE-2026-4017

Buffer Overflow in the entry handler of the TraceEvent() system call could allow an attacker with local access to cause information disclosure, data tampering or a crash of the QNX Neutrino kernel.

PUBLISHED
Vendor
BlackBerry Ltd, BlackBerry Ltd, BlackBerry Ltd.
Product
QNX OS for Safety, QNX Software Development Platform, QNX OS for Medical
Provider severity
HIGH
Conflicts
1

CVE-2026-40169

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-19, a crafted image could result in an out of bounds heap write when writing a yaml or json output, resulting in a crash. This issue has been fixed in version 7.1.2-19.

PUBLISHED
Vendor
ImageMagick
Product
ImageMagick
Provider severity
MEDIUM
Conflicts
1

CVE-2026-40168

Postiz is an AI social media scheduling tool. Prior to 2.21.5, the /api/public/stream endpoint is vulnerable to SSRF. Although the application validates the initially supplied URL and blocks direct private/internal hosts, it does not re-validate the final destination after HTTP redirects. As a result, an attacker can supply a public HTTPS URL that passes validation and then redirects the server-side request to an internal resource.

PUBLISHED
Vendor
gitroomhq
Product
postiz-app
Provider severity
HIGH
Conflicts
0

CVE-2026-40166

authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, authenticated non-admin users with at least one OAuth2 access token can retrieve the client_secret of confidential OAuth2 providers they have previously authenticated against, exposing sensitive information to users without the correct permissions. This logic is GET /api/v3/oauth2/access_tokens/. The API response includes a nested provider object containing client_id and client_secret

PUBLISHED
Vendor
goauthentik
Product
authentik
Provider severity
HIGH
Conflicts
1

CVE-2026-40165

authentik is an open-source identity provider. Versions 2025.12.4 and prior, and versions 2026.2.0-rc1 through 2026.2.2 were vulnerable to Authentication Bypass through SAML NameID XML Comment Injection. Due to how authentik extracted the NameID value from a SAML assertion, it was possible for an attacker to trick authentik into only seeing a part of the NameID value, potentially allowing an attacker to gain access to other accounts. This issue could be exploited on an authentik instance with a

PUBLISHED
Vendor
goauthentik
Product
authentik
Provider severity
HIGH
Conflicts
1

CVE-2026-40164

jq is a command-line JSON processor. Before commit 0c7d133c3c7e37c00b6d46b658a02244fdd3c784, jq used MurmurHash3 with a hardcoded, publicly visible seed (0x432A9843) for all JSON object hash table operations, which allowed an attacker to precompute key collisions offline. By supplying a crafted JSON object (~100 KB) where all keys hashed to the same bucket, hash table lookups degraded from O(1) to O(n), turning any jq expression into an O(n²) operation and causing significant CPU exhaustion. Thi

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, jqlang, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 10, Red Hat OpenShift Container Platform 4.14, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat AI Inference Server 3.3, Red Hat Enterprise Linux 8, jq, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4.18, Red Hat OpenShift Container Platform 4.16, Red Hat Enterprise Linux 8.6 Telecommunications Update Service, Red Hat AI Inference Server 3.2, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat AI Inference Server 3.3, Red Hat Hardened Images, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat AI Inference Server 3.3, Red Hat OpenShift Container Platform 4.19, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 9.4 Extended Update Support, Red Hat OpenShift Container Platform 4.12, Red Hat AI Inference Server 3.3, Red Hat OpenShift Container Platform 4.17, Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat OpenShift Container Platform 4.15, Red Hat OpenShift Container Platform 4.13
Provider severity
HIGH
Conflicts
2

CVE-2026-40163

Saltcorn is an extensible, open source, no-code database application builder. Prior to 1.4.5, 1.5.5, and 1.6.0-beta.4, the POST /sync/offline_changes endpoint allows an unauthenticated attacker to create arbitrary directories and write a changes.json file with attacker-controlled JSON content anywhere on the server filesystem. The GET /sync/upload_finished endpoint allows an unauthenticated attacker to list arbitrary directory contents and read specific JSON files. This vulnerability is fixed in

PUBLISHED
Vendor
saltcorn
Product
saltcorn
Provider severity
HIGH
Conflicts
0

CVE-2026-40162

Bugsink is a self-hosted error tracking tool. In 2.1.0, an authenticated file write vulnerability was identified in Bugsink 2.1.0 in the artifact bundle assembly flow. A user with a valid authentication token could cause the application to write attacker-controlled content to a filesystem location writable by the Bugsink process. This vulnerability is fixed in 2.1.1.

PUBLISHED
Vendor
bugsink
Product
bugsink
Provider severity
HIGH
Conflicts
0

CVE-2026-40161

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, the Tekton Pipelines git resolver in API mode sends the system-configured Git API token to a user-controlled serverURL when the user omits the token parameter. A tenant with TaskRun or PipelineRun create permission can exfiltrate the shared API token (GitHub PAT, GitLab token, etc.) by pointing serverURL to an attacker-

PUBLISHED
Vendor
tektoncd
Product
pipeline
Provider severity
HIGH
Conflicts
0

CVE-2026-40160

PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, web_crawl's httpx fallback path passes user-supplied URLs directly to httpx.AsyncClient.get() with follow_redirects=True and no host validation. An LLM agent tricked into crawling an internal URL can reach cloud metadata endpoints (169.254.169.254), internal services, and localhost. The response content is returned to the agent and may appear in output visible to the attacker. This fallback is the default crawl path on a fresh Prai

PUBLISHED
Vendor
MervinPraison
Product
PraisonAIAgents
Provider severity
HIGH
Conflicts
0

CVE-2026-4016

A security vulnerability has been detected in GPAC 26.03-DEV. Affected by this vulnerability is the function svgin_process of the file src/filters/load_svg.c of the component SVG Parser. The manipulation leads to out-of-bounds write. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used. The identifier of the patch is 7618d7206cdeb3c28961dc97ab0ecabaff0c8af2. It is suggested to install a patch to address this issue.

PUBLISHED
Vendor
n/a
Product
GPAC
Provider severity
MEDIUM
Conflicts
2

CVE-2026-40159

PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI’s MCP (Model Context Protocol) integration allows spawning background servers via stdio using user-supplied command strings (e.g., MCP("npx -y @smithery/cli ...")). These commands are executed through Python’s subprocess module. By default, the implementation forwards the entire parent process environment to the spawned subprocess. As a result, any MCP command executed in this manner inherits all environment variables from the

PUBLISHED
Vendor
MervinPraison
Product
PraisonAI
Provider severity
MEDIUM
Conflicts
1