Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-39906

Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose a deprecated .NET Remoting TCP channel that allows remote unauthenticated attackers to leak NTLMv2 machine-account hashes by supplying a Windows UNC path as a target file argument through object-unmarshalling techniques. Attackers can capture the leaked NTLMv2 hash and relay it to other hosts to achieve privilege escalation or lateral movement depending on network configuration and patch level.

PUBLISHED
Vendor
Unisys
Product
WebPerfect Image Suite
Provider severity
HIGH
Conflicts
0

CVE-2026-39904

Gophish through 0.12.1 contains a denial of service vulnerability that allows authenticated users with the User role to exhaust server memory by uploading a crafted Office document as an email template attachment. The ApplyTemplate() function in models/attachment.go processes Office documents as ZIP archives and calls ioutil.ReadAll() on each contained file entry without enforcing size restrictions on uncompressed content, allowing a zip bomb payload to expand to several gigabytes in memory and

PUBLISHED
Vendor
gophish
Product
gophish
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-39903

Simple Machines Forum 2.1 prior to commit 7d048f8 and 3.0 prior to commit a7875e8 contains an authorization bypass vulnerability in Sources/Actions/AttachmentApprove.php where a single-character operator error causes the permission check to always pass regardless of user permissions. An authenticated low-privileged user can approve, reject, or delete any pending attachments on any board without holding the required approve_posts permission, bypass moderation queues for their own uploads, and enu

PUBLISHED
Vendor
SimpleMachines
Product
SMF
Provider severity
HIGH
Conflicts
1

CVE-2026-39901

monetr is a budgeting application focused on planning for recurring expenses. Prior to 1.12.3, a transaction integrity flaw allows an authenticated tenant user to soft-delete synced non-manual transactions through the transaction update endpoint, despite the application explicitly blocking deletion of those transactions via the normal DELETE path. This bypass undermines the intended protection for imported transaction records and allows protected transactions to be hidden from normal views. This

PUBLISHED
Vendor
monetr
Product
monetr
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39900

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Reflected XSS via tab parameter in the auth_profile.php JavaScript context. This issue has been fixed in version 1.2.31.

PUBLISHED
Vendor
Cacti
Product
cacti
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39899

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Path Traversal via filename parameter in package_import.php. This issue has been fixed in version 1.2.31.

PUBLISHED
Vendor
Cacti
Product
cacti
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39897

Cacti is an open source performance and fault management framework. Versions 1.2.30 and below contain a Reflected XSS vulnerability in the html_auth_footer. This issue has been fixed in version 1.2.31.

PUBLISHED
Vendor
Cacti
Product
cacti
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39894

Cacti is an open source performance and fault management framework. In versions 1.2.30 and below, the locale-dependent decimal formatting in rrdtool_function_update() can corrupt RRDtool metric values. The rrdtool_function_update() function checks metric values with is_numeric() and concatenates them into the RRDtool update command via PHP string interpolation. PHP's string cast of floats is locale-sensitive: if LC_NUMERIC uses comma as decimal separator (e.g., de_DE), a value of 1.5 becomes "1,

PUBLISHED
Vendor
Cacti
Product
cacti
Provider severity
LOW
Conflicts
0

CVE-2026-39893

Cacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request variable was concatenated into a RLIKE SQL clause without sanitization. The endpoint does not require authentication (graph viewing supports guest access via the configured guest user), so the SQLi was reachable pre-auth on installs with guest viewing enabled. This issue was fixed in version 1.2.31.

PUBLISHED
Vendor
Cacti
Product
cacti
Provider severity
CRITICAL
Conflicts
0

CVE-2026-39892

A flaw was found in the cryptography library. This vulnerability occurs when a non-contiguous buffer is passed to certain application programming interfaces (APIs) that accept Python buffers, such as Hash.update(). A remote attacker could exploit this to cause a buffer overflow, potentially leading to a denial of service.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, pyca, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Ansible Automation Platform 2.6, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI 2.25, Red Hat OpenShift AI (RHOAI), Red Hat Quay 3, Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Enterprise Linux AI 3.3, Red Hat OpenShift AI 3.3, Red Hat OpenShift AI (RHOAI), Red Hat Quay 3, Red Hat Quay 3.12, Red Hat Quay 3.15, Red Hat Quay 3.9, Lightspeed Core, Red Hat Trusted Artifact Signer 1.4, Red Hat Discovery 2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Satellite 6, Red Hat Enterprise Linux AI 3.3, Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2.6 for RHEL 9, Red Hat Quay 3.17, Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2.6 for RHEL 9, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Lightspeed Core, Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2, cryptography, Red Hat OpenShift AI 2.25, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat AI Inference Server 3.3, Red Hat AI Inference Server, Red Hat Enterprise Linux 9, Red Hat OpenShift AI (RHOAI), Red Hat Quay 3, Red Hat Quay 3, Red Hat OpenShift AI (RHOAI), Red Hat AI Inference Server, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2.6, Red Hat Enterprise Linux AI 3.3, Red Hat Enterprise Linux AI 3.3, Red Hat OpenShift AI (RHOAI), Red Hat Satellite 6, Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2.5 for RHEL 9, Red Hat OpenShift AI (RHOAI), Red Hat Hardened Images, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux AI 3.3, Red Hat Satellite 6, Red Hat OpenShift AI (RHOAI), Red Hat AI Inference Server 3.3, Red Hat OpenShift AI (RHOAI), Red Hat AI Inference Server, Red Hat OpenShift AI 3.3, OpenShift Lightspeed, Red Hat Ansible Automation Platform Ansible Core 2, Red Hat OpenShift AI (RHOAI), Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Quay 3.14, Red Hat Ansible Automation Platform Ansible Core 2, Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat Satellite 6, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2.6, Red Hat Enterprise Linux AI 3.3, Red Hat Ansible Automation Platform Ansible Core 2, Red Hat Quay 3.16, Red Hat Ansible Automation Platform 2.6, Red Hat Quay 3, Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Enterprise Linux AI 3.3, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, OpenShift Lightspeed, Red Hat Ansible Automation Platform 2.6, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat Ansible Automation Platform Ansible Core 2, Red Hat OpenShift AI (RHOAI), Red Hat Quay 3, Red Hat Quay 3, Red Hat OpenShift AI 3.3, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2.6, Migration Toolkit for Applications 8, Red Hat Quay 3.1
Provider severity
HIGH, MEDIUM
Conflicts
3

CVE-2026-39891

PraisonAI is a multi-agent teams system. Prior to 4.5.115, the create_agent_centric_tools() function returns tools (like acp_create_file) that process file content using template rendering. When user input from agent.start() is passed directly into these tools without escaping, template expressions in the input are executed rather than treated as literal text. This vulnerability is fixed in 4.5.115.

PUBLISHED
Vendor
MervinPraison
Product
PraisonAI
Provider severity
HIGH
Conflicts
0

CVE-2026-39890

PraisonAI is a multi-agent teams system. Prior to 4.5.115, the AgentService.loadAgentFromFile method uses the js-yaml library to parse YAML files without disabling dangerous tags (such as !!js/function and !!js/undefined). This allows an attacker to craft a malicious YAML file that, when parsed, executes arbitrary JavaScript code. An attacker can exploit this vulnerability by uploading a malicious agent definition file via the API endpoint, leading to remote code execution (RCE) on the server. T

PUBLISHED
Vendor
MervinPraison
Product
PraisonAI
Provider severity
CRITICAL
Conflicts
0

CVE-2026-3989

SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization. An attacker can take advantage of this by providing a malicious .pkl file, which will execute the attackers code on the device running the script.

PUBLISHED
Vendor
SGLang
Product
SGLang
Provider severity
HIGH
Conflicts
0

CVE-2026-39889

PraisonAI is a multi-agent teams system. Prior to 4.5.115, the A2U (Agent-to-User) event stream server in PraisonAI exposes all agent activity without authentication. The create_a2u_routes() function registers the following endpoints with NO authentication checks: /a2u/info, /a2u/subscribe, /a2u/events/{stream_name}, /a2u/events/sub/{id}, and /a2u/health. This vulnerability is fixed in 4.5.115.

PUBLISHED
Vendor
MervinPraison
Product
PraisonAI
Provider severity
HIGH
Conflicts
0

CVE-2026-39888

PraisonAI is a multi-agent teams system. Prior to 1.5.115, execute_code() in praisonaiagents.tools.python_tools defaults to sandbox_mode="sandbox", which runs user code in a subprocess wrapped with a restricted __builtins__ dict and an AST-based blocklist. The AST blocklist embedded inside the subprocess wrapper (blocked_attrs of python_tools.py) contains only 11 attribute names — a strict subset of the 30+ names blocked in the direct-execution path. The four attributes that form a frame-travers

PUBLISHED
Vendor
MervinPraison
Product
praisonaiagents
Provider severity
CRITICAL
Conflicts
1

CVE-2026-39886

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. Versions 3.4.0 through 3.4.9 have a signed integer overflow vulnerability in OpenEXR's HTJ2K (High-Throughput JPEG 2000) decompression path. The `ht_undo_impl()` function in `src/lib/OpenEXRCore/internal_ht.cpp` accumulates a bytes-per-line value (`bpl`) using a 32-bit signed integer with no overflow guard. A crafted EXR file with 16,385 FLOAT channels

PUBLISHED
Vendor
AcademySoftwareFoundation
Product
openexr
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39885

FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 2.3.0, the mcp-from-openapi library uses @apidevtools/json-schema-ref-parser to dereference $ref pointers in OpenAPI specifications without configuring any URL restrictions or custom resolvers. A malicious OpenAPI specification containing $ref values pointing to internal network addresses, cloud metadata endpoints, or local files will cause the library to fetch those resources during the initialize() call. Th

PUBLISHED
Vendor
frontmcp, @frontmcp, agentfront, @frontmcp
Product
mcp-from-openapi, adapters, frontmcp, sdk
Provider severity
HIGH
Conflicts
1

CVE-2026-39884

mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Versions 3.4.0 and prior contain an argument injection vulnerability in the port_forward tool in src/tools/port_forward.ts, where a kubectl command is constructed via string concatenation with user-controlled input and then naively split on spaces before being passed to spawn(). Unlike all other tools in the codebase which correctly use array-based argument passing with execFileSync(), port_forward treats

PUBLISHED
Vendor
Flux159
Product
mcp-server-kubernetes
Provider severity
HIGH
Conflicts
0

CVE-2026-39883

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg command to use an absolute path but left the BSD kenv command using a bare name, allowing the same PATH hijacking attack on BSD and Solaris platforms. This vulnerability is fixed in 1.43.0.

PUBLISHED
Vendor
open-telemetry, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
opentelemetry-go, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, multicluster engine for Kubernetes 2.8, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, multicluster engine for Kubernetes 2.8, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22, Red Hat Openshift Data Foundation 4.22
Provider severity
HIGH
Conflicts
3

CVE-2026-39882

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to 1.43.0, the otlp HTTP exporters (traces/metrics/logs) read the full HTTP response body into an in-memory bytes.Buffer without a size cap. This is exploitable for memory exhaustion when the configured collector endpoint is attacker-controlled (or a network attacker can mitm the exporter connection). This vulnerability is fixed in 1.43.0.

PUBLISHED
Vendor
open-telemetry
Product
opentelemetry-go
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39881

Vim is an open source, command line text editor. Prior to 9.2.0316, a command injection vulnerability in Vim's netbeans interface allows a malicious netbeans server to execute arbitrary Ex commands when Vim connects to it, via unsanitized strings in the defineAnnoType and specialKeys protocol messages. This vulnerability is fixed in 9.2.0316.

PUBLISHED
Vendor
vim
Product
vim
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39880

Remnawave Backend is the backend for the Remnawave proxy and user management solution. Prior to 2.7.5, a glitch in the HWID device registration logic allows an authenticated user to bypass the configured limit for HWID devices and register more devices than expected, allowing them to resell subscriptions and consume excessive traffic. This vulnerability is fixed in 2.7.5.

PUBLISHED
Vendor
remnawave
Product
backend
Provider severity
MEDIUM
Conflicts
0

CVE-2026-3988

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to cause a denial of service by making the GitLab instance unresponsive due to improper input validation in GraphQL request processing.

PUBLISHED
Vendor
GitLab
Product
GitLab
Provider severity
HIGH
Conflicts
0

CVE-2026-39879

Due to a missing sanitization call in [`afsql_dd_run_query`](https://github.com/syslog-ng/syslog-ng/blob/649e6e18e3459fb4467000a88dfb12fa97f9719c/modules/afsql/afsql.c#L219), syslog-ng before 4.12 are vulnerable to SQL injection from an untrusted source. This is not part of the default configuration, the SQL driver has to be manually configured. Fixes are in syslog-ng 4.12, syslog-ng Premium Edition 8.2 and syslog-ng Store Box 7.8

PUBLISHED
Vendor
syslog-ng
Product
syslog-ng
Provider severity
HIGH
Conflicts
0

CVE-2026-39878

Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registration form that allows any unauthenticated attacker to execute arbitrary JavaScript in an administrator's browser session, leading to full platform admin account takeover. This has been patched in 1.11.40.

PUBLISHED
Vendor
chamilo
Product
chamilo-lms
Provider severity
CRITICAL
Conflicts
0

CVE-2026-39877

A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An app may be able to disclose kernel memory.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
HIGH
Conflicts
1

CVE-2026-39875

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to gain root privileges.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
HIGH
Conflicts
1

CVE-2026-39874

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to gain root privileges.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
HIGH
Conflicts
1

CVE-2026-39873

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Connecting to a malicious SMB server may lead to unexpected system termination.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
CRITICAL
Conflicts
1

CVE-2026-39872

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple, Apple
Product
visionOS, tvOS, macOS, iOS and iPadOS, Safari, watchOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-39871

A path handling issue was addressed with improved logic. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to observe unprotected user data.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
HIGH
Conflicts
1

CVE-2026-39870

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. Processing a maliciously crafted image may corrupt process memory.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
HIGH
Conflicts
1

CVE-2026-3987

A path traversal vulnerability in the Fireware OS Web UI on WatchGuard Firebox systems may allow a privileged authenticated remote attacker to execute arbitrary code in the context of an elevated system process.This issue affects Fireware OS 12.6.1 up to and including 12.11.8 and 2025.1 up to and including 2026.1.2.

PUBLISHED
Vendor
WatchGuard
Product
Fireware OS
Provider severity
HIGH
Conflicts
0

CVE-2026-39869

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing an audio stream in a maliciously crafted media file may terminate the process.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple
Product
watchOS, iOS and iPadOS, visionOS, tvOS, macOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-39868

This issue was addressed with improved input validation. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or corrupt kernel memory.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple
Product
watchOS, iOS and iPadOS, tvOS, visionOS, macOS
Provider severity
CRITICAL
Conflicts
2

CVE-2026-39866

Lawnchair is a free, open-source home app for Android. Prior to commit fcba413f55dd47f8a3921445252849126c6266b2, command injection in release_update.yml workflow dispatch input allows arbitrary code execution. Commit fcba413f55dd47f8a3921445252849126c6266b2 patches the issue.

PUBLISHED
Vendor
LawnchairLauncher
Product
lawnchair
Provider severity
HIGH
Conflicts
0

CVE-2026-39865

Axios is a promise based HTTP client for the browser and Node.js. Starting in version 1.13.0 and prior to 1.13.2, Axios HTTP/2 session cleanup logic contains a state corruption bug that allows a malicious server to crash the client process through concurrent session closures. The vulnerability exists in the Http2Sessions.getSession() method in lib/adapters/http.js. The session cleanup logic contains a control flow error when removing sessions from the sessions array. This vulnerability is fixed

PUBLISHED
Vendor
axios
Product
axios
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39864

Kamailio is an open source implementation of a SIP Signaling Server. Prior to 6.0.5 and 5.8.7, an out-of-bounds read in the auth module of Kamailio (formerly OpenSER and SER) allows remote attackers to cause a denial of service (process crash) via a specially crafted SIP packet if a successful user authentication without a database backend is followed by additional user identity checks. This vulnerability is fixed in 6.0.5 and 5.8.7.

PUBLISHED
Vendor
kamailio
Product
kamailio
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39863

Kamailio is an open source implementation of a SIP Signaling Server. Prior to 6.1.1, 6.0.6, and 5.8.8, an out-of-bounds access in the core of Kamailio (formerly OpenSER and SER) allows remote attackers to cause a denial of service (process crash) via a specially crafted data packet sent over TCP. The issue impacts Kamailio instances having TCP or TLS listeners. This vulnerability is fixed in 5.1.1, 6.0.6, and 5.8.8.

PUBLISHED
Vendor
kamailio
Product
kamailio
Provider severity
HIGH
Conflicts
0

CVE-2026-39862

Tophat is a mobile applications testing harness. Prior to 2.5.1, Tophat is affected by remote code execution via crafted tophat:// or http://localhost:29070 URLs. The arguments query parameter flows unsanitized from URL parsing through to /bin/bash -c execution, allowing an attacker to execute arbitrary commands on a developer's macOS workstation. Any developer with Tophat installed is vulnerable. For previously trusted build hosts, no confirmation dialog appears. Attacker commands run with the

PUBLISHED
Vendor
Shopify
Product
tophat
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39861

Claude Code is an agentic coding tool. Prior to version 2.1.64, Claude Code's sandbox did not prevent sandboxed processes from creating symlinks pointing to locations outside the workspace. When Claude Code subsequently wrote to a path within such a symlink, its unsandboxed process followed the symlink and wrote to the target location outside the workspace without prompting the user for confirmation. This allowed a sandbox escape where neither the sandboxed command nor the unsandboxed app could

PUBLISHED
Vendor
anthropics
Product
claude-code
Provider severity
HIGH
Conflicts
1

CVE-2026-39860

Nix is a package manager for Linux and other Unix systems. A bug in the fix for CVE-2024-27297 allowed for arbitrary overwrites of files writable by the Nix process orchestrating the builds (typically the Nix daemon running as root in multi-user installations) by following symlinks during fixed-output derivation output registration. This affects sandboxed Linux builds - sandboxed macOS builds are unaffected. The location of the temporary output used for the output copy was located inside the bui

PUBLISHED
Vendor
NixOS
Product
nix
Provider severity
CRITICAL
Conflicts
0

CVE-2026-3986

The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form settings in all versions up to, and including, 5.4.5.0. This is due to insufficient capability checks on the form settings save handler and insufficient input sanitization of the `fcontent` field in `fhtml` field types. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user access

PUBLISHED
Vendor
codepeople
Product
Calculated Fields Form
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39859

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.3, liquidjs 10.25.0 documents root as constraining filenames passed to renderFile() and parseFile(), but top-level file loads do not enforce that boundary. A Liquid instance configured with an empty temporary directory as root can return the contents of arbitrary files. This vulnerability is fixed in 10.25.3.

PUBLISHED
Vendor
harttle
Product
liquidjs
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-39858

Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high severity authentication bypass vulnerability in Traefik's ForwardAuth and snippet-based authentication middleware. Traefik's forwarded-header sanitization logic targets only canonical header names (e.g., X-Forwarded-Proto) and does not strip or normalize alias variants that use underscores instead of dashes (e.g., X_Forwarded_Proto). These unsanitized alias headers are forwarded

PUBLISHED
Vendor
Red Hat, traefik
Product
Red Hat OpenShift Dev Spaces 3.28, traefik
Provider severity
HIGH
Conflicts
3

CVE-2026-39857

ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization bypass vulnerability in the choices and counts query parameters of the REST API, where these query builders execute MongoDB distinct() operations that bypass the publicApiProjection restrictions intended to limit which fields are exposed publicly. The choices and counts parameters are processed via applyBuildersSafely before the projection is applied, and MongoDB's distinct opera

PUBLISHED
Vendor
apostrophecms
Product
apostrophe
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39856

osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.13, an out-of-bounds read vulnerability exists in osslsigncode version 2.12 and earlier in the PE page-hash computation code (pe_page_hash_calc()). When processing PE sections for page hashing, the function uses PointerToRawData and SizeOfRawData values from section headers without validating that the referenced region lies within the mapped file. An attacker can craft a PE file with section headers that poi

PUBLISHED
Vendor
mtrojnar
Product
osslsigncode
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39855

osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.13, an integer underflow vulnerability exists in osslsigncode version 2.12 and earlier in the PE page-hash computation code (pe_page_hash_calc()). When page hash processing is performed on a PE file, the function subtracts hdrsize from pagesize without first validating that pagesize >= hdrsize. If a malicious PE file sets SizeOfHeaders (hdrsize) larger than SectionAlignment (pagesize), the subtraction underf

PUBLISHED
Vendor
mtrojnar
Product
osslsigncode
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39853

osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.12, A stack buffer overflow vulnerability exists in osslsigncode in several signature verification paths. During verification of a PKCS#7 signature, the code copies the digest value from a parsed SpcIndirectDataContent structure into a fixed-size stack buffer (mdbuf[EVP_MAX_MD_SIZE], 64 bytes) without validating that the source length fits within the destination buffer. This pattern is present in the verifi

PUBLISHED
Vendor
mtrojnar
Product
osslsigncode
Provider severity
HIGH
Conflicts
1

CVE-2026-39852

A flaw was found in io.quarkus:quarkus-vertx-http. A remote attacker can exploit an authorization bypass vulnerability by including semicolons, also known as matrix parameters, in HTTP requests. This allows bypassing path-based HTTP security policies, enabling unauthorized access to protected endpoints. The vulnerability arises because Quarkus's security layer performs authorization checks on the raw URL path, which preserves these matrix parameters.

PUBLISHED
Vendor
quarkusio, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
quarkus, OpenShift Serverless, OpenShift Serverless, Red Hat Fuse 7, Red Hat Build of Keycloak, Cryostat 4 on RHEL 9, Red Hat OpenShift AI (RHOAI), Red Hat build of OptaPlanner 8, OpenShift Serverless, Red Hat build of Apicurio Registry 3, Red Hat build of Apache Camel 4 for Quarkus 3, Cryostat 4 on RHEL 9, Streams for Apache Kafka 2.9.4, OpenShift Serverless, Red Hat Build of Apache Camel 4.14 for Quarkus 3.27, Cryostat 4 on RHEL 9, Red Hat Process Automation 7, OpenShift Serverless, HawtIO HawtIO 4.4.0, OpenShift Serverless, streams for Apache Kafka 3, Red Hat OpenShift AI (RHOAI), OpenShift Serverless, OpenShift Serverless, Red Hat build of Apicurio Registry 2, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat build of Debezium 3, Red Hat build of Quarkus 3.27.3.SP1, Red Hat build of Quarkus 3.20.6.SP1
Provider severity
HIGH
Conflicts
3