Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-33267

Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Traffic Server
Provider severity
CRITICAL, HIGH
Conflicts
1

CVE-2026-33266

Use of Hard-coded Cryptographic Key vulnerability in Apache OpenMeetings. The remember-me cookie encryption key is set to default value in openmeetings.properties and not being auto-rotated. In case OM admin hasn't changed the default encryption key, an attacker who has stolen a cookie from a logged-in user can get full user credentials. This issue affects Apache OpenMeetings: from 6.1.0 before 9.0.0. Users are recommended to upgrade to version 9.0.0, which fixes the issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache OpenMeetings
Provider severity
HIGH
Conflicts
0

CVE-2026-33265

In LibreChat 0.8.1-rc2, a logged-in user obtains a JWT for both the LibreChat API and the RAG API.

PUBLISHED
Vendor
LibreChat
Product
LibreChat
Provider severity
MEDIUM
Conflicts
0

CVE-2026-33264

A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server loaded a serialized DAG: a DAG author could embed a malicious trigger into a DAG to gain remote code execution on the API Server / Scheduler process, crossing the Airflow security boundary that DAG-author code must never execute in those processes. Users are advised to upgrade to `apache-airflow` 3.3.0 or later. As a defense-in-depth mitigation, dep

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Airflow
Provider severity
CRITICAL
Conflicts
0

CVE-2026-33262

An attacker can send replies that result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service. Cookies are disabled by default.

PUBLISHED
Vendor
PowerDNS
Product
Recursor
Provider severity
MEDIUM
Conflicts
1

CVE-2026-33261

A zone transition from NSEC to NSEC3 might trigger an internal inconsistency and cause a denial of service.

PUBLISHED
Vendor
PowerDNS
Product
Recursor
Provider severity
MEDIUM
Conflicts
1

CVE-2026-33260

An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.

PUBLISHED
Vendor
PowerDNS, PowerDNS, PowerDNS
Product
DNSdist, Authoritative, Recursor
Provider severity
MEDIUM
Conflicts
2

CVE-2026-3326

The Xstore WordPress theme before 9.7.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

PUBLISHED
Vendor
Unknown
Product
Xstore
Provider severity
HIGH
Conflicts
1

CVE-2026-33259

Having many concurrent transfers of the same RPZ can lead to inconsistent RPZ data, use after free and/or a crash of the recursor. Normally concurrent transfers of the same RPZ zone can only occur with a malfunctioning RPZ provider.

PUBLISHED
Vendor
PowerDNS
Product
Recursor
Provider severity
MEDIUM
Conflicts
1

CVE-2026-33258

By publishing and querying a crafted zone an attacker can cause allocation of large entries in the negative and aggressive NSEC(3) caches.

PUBLISHED
Vendor
PowerDNS
Product
Recursor
Provider severity
MEDIUM
Conflicts
1

CVE-2026-33257

An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.

PUBLISHED
Vendor
PowerDNS, PowerDNS, PowerDNS
Product
Authoritative, Recursor, DNSdist
Provider severity
MEDIUM
Conflicts
2

CVE-2026-33256

An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.

PUBLISHED
Vendor
PowerDNS
Product
Recursor
Provider severity
MEDIUM
Conflicts
1

CVE-2026-33254

An attacker can create a large number of concurrent DoQ or DoH3 connections, causing unlimited memory allocation in DNSdist and leading to a denial of service. DOQ and DoH3 are disabled by default.

PUBLISHED
Vendor
PowerDNS
Product
DNSdist
Provider severity
MEDIUM
Conflicts
1

CVE-2026-33253

SANUPS SOFTWARE provided by SANYO DENKI CO., LTD. registers Windows services with unquoted file paths. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege.

PUBLISHED
Vendor
SANYO DENKI CO., LTD., SANYO DENKI CO., LTD.
Product
SANUPS SOFTWARE STANDALONE, SANUPS SOFTWARE
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-33252

The Go MCP SDK used Go's standard encoding/json. Prior to version 1.4.1, the Go SDK's Streamable HTTP transport accepted browser-generated cross-site `POST` requests without validating the `Origin` header and without requiring `Content-Type: application/json`. In deployments without Authorization, especially stateless or sessionless configurations, this allows an arbitrary website to send MCP requests to a local server and potentially trigger tool execution. Version 1.4.1 contains a patch for th

PUBLISHED
Vendor
modelcontextprotocol
Product
go-sdk
Provider severity
HIGH
Conflicts
0

CVE-2026-33251

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, an authorization bypass vulnerability in hidden Solved topics may allow unauthorized users to accept or unaccept solutions. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 contain a patch. As a workaround, ensure only trusted users are part of the Site Setting for accept_all_solutions_allowed_groups.

PUBLISHED
Vendor
discourse
Product
discourse
Provider severity
MEDIUM
Conflicts
0

CVE-2026-33250

Freeciv21 is a free open source, turn-based, empire-building strategy game. Versions prior to 3.1.1 crash with a stack overflow when receiving specially-crafted packets. A remote attacker can use this to take down any public server. A malicious server can use this to crash the game on the player's machine. Authentication is not needed and, by default, logs do not contain any useful information. All users should upgrade to Freeciv21 version 3.1.1. Running the server behind a firewall can help mit

PUBLISHED
Vendor
longturn
Product
freeciv21
Provider severity
HIGH
Conflicts
1

CVE-2026-3325

SQL injection (SQLi) in MegaCMS v12.0.0, specifically in the “id_territorio” parameter of the “/web_comunications/cms/get_provincias” endpoint. The vulnerability arises from inadequate validation and sanitisation of user input. Specifically, via a POST request, the “id_territorio” parameter, used immediately after the registration form is submitted, could be manipulated by an unauthenticated attacker to execute arbitrary SQL queries.

PUBLISHED
Vendor
CRM Sistemas de Fidelización
Product
MegaCMS
Provider severity
CRITICAL
Conflicts
0

CVE-2026-33249

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Starting in version 2.11.0 and prior to versions 2.11.15 and 2.12.6, a valid client which uses message tracing headers can indicate that the trace messages can be sent to an arbitrary valid subject, including those to which the client does not have publish permission. The payload is a valid trace message and not chosen by the attacker. Versions 2.11.15 and 2.12.6 contain a fix. No known workarounds ar

PUBLISHED
Vendor
nats-io
Product
nats-server
Provider severity
MEDIUM
Conflicts
0

CVE-2026-33248

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, when using mTLS for client identity, with `verify_and_map` to derive a NATS identity from the client certificate's Subject DN, certain patterns of RDN would not be correctly enforced, allowing for authentication bypass. This does require a valid certificate from a CA already trusted for client certificates, and `DN` naming patterns which the NATS maintainers consi

PUBLISHED
Vendor
nats-io
Product
nats-server
Provider severity
MEDIUM
Conflicts
1

CVE-2026-33247

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, if a nats-server is run with static credentials for all clients provided via argv (the command-line), then those credentials are visible to any user who can see the monitoring port, if that too is enabled. The `/debug/vars` end-point contains an unredacted copy of argv. Versions 2.11.15 and 2.12.6 contain a fix. As a workaround, configure credentials inside a conf

PUBLISHED
Vendor
nats-io, Red Hat, Red Hat, Red Hat, Red Hat
Product
nats-server, Red Hat OpenShift Container Platform 4, Red Hat multicluster global hub 1.6.0, Multicluster Global Hub 1.5.4, Red Hat multicluster global hub 1.4.4
Provider severity
HIGH
Conflicts
3

CVE-2026-33246

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The nats-server offers a `Nats-Request-Info:` message header, providing information about a request. This is supposed to provide enough information to allow for account/user identification, such that NATS clients could make their own decisions on how to trust a message, provided that they trust the nats-server as a broker. A leafnode connecting to a nats-server is not fully trusted unless the system a

PUBLISHED
Vendor
nats-io
Product
nats-server
Provider severity
MEDIUM
Conflicts
1

CVE-2026-33245

React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a potential client-side Cross-Site Scripting (XSS) vulnerability in the RSC redirect handling if redirects come from untrusted sources. This does not impact applications that are not using the unstable RSC APIs in React Router. This is patched in version 7.13.2.

PUBLISHED
Vendor
remix-run
Product
react-router
Provider severity
HIGH
Conflicts
0

CVE-2026-33244

React Router is a router for React. In versions 7.5.1 through 7.13.1, when using Framework Mode with pre-rendering enabled, improper neutralization of the HTTP `Location` header value can permit Cross-Site Scripting (XSS) in the statically generated HTML files if the redirect location comes from an untrusted source. This does not impact applications using Declarative Mode (`<BrowserRouter>`) or Data Mode (`createBrowserRouter/<RouterProvider>`). This is patched in version 7.13.2.

PUBLISHED
Vendor
remix-run
Product
react-router
Provider severity
MEDIUM
Conflicts
0

CVE-2026-33243

barebox is a bootloader. In barebox from version 2016.03.0 to before version 2026.03.1 (and the corresponding backport to 2025.09.3), an attacker could exploit a FIT signature verification vulnerability to trick the bootloader into booting different images than those that were verified as part of a signed configuration. mkimage(1) sets the hashed-nodes property of the FIT signature node to list which nodes of the FIT were hashed as part of the signing process as these will need to be verified la

PUBLISHED
Vendor
barebox
Product
barebox
Provider severity
HIGH
Conflicts
0

CVE-2026-33242

Salvo is a Rust web framework. Versions 0.39.0 through 0.89.2 have a Path Traversal and Access Control Bypass vulnerability in the salvo-proxy component. The vulnerability allows an unauthenticated external attacker to bypass proxy routing constraints and access unintended backend paths (e.g., protected endpoints or administrative dashboards). This issue stems from the encode_url_path function, which fails to normalize "../" sequences and inadvertently forwards them verbatim to the upstream serv

PUBLISHED
Vendor
salvo-rs
Product
salvo
Provider severity
HIGH
Conflicts
0

CVE-2026-33241

Salvo is a Rust web framework. Prior to version 0.89.3, Salvo's form data parsing implementations (`form_data()` method and `Extractible` macro) do not enforce payload size limits before reading request bodies into memory. This allows attackers to cause Out-of-Memory (OOM) conditions by sending extremely large payloads, leading to service crashes and denial of service. Version 0.89.3 contains a patch.

PUBLISHED
Vendor
salvo-rs
Product
salvo
Provider severity
HIGH
Conflicts
0

CVE-2026-3324

Zohocorp ManageEngine Log360 versions 13000 through 13013 are vulnerable to authentication bypass on certain actions due to improper filter configuration.

PUBLISHED
Vendor
Zohocorp
Product
ManageEngine Log360
Provider severity
HIGH
Conflicts
0

CVE-2026-33238

WWBN AVideo is an open source video platform. Prior to version 26.0, the `listFiles.json.php` endpoint accepts a `path` POST parameter and passes it directly to `glob()` without restricting the path to an allowed base directory. An authenticated uploader can traverse the entire server filesystem by supplying arbitrary absolute paths, enumerating `.mp4` filenames and their full absolute filesystem paths wherever they exist on the server — including locations outside the web root, such as private

PUBLISHED
Vendor
WWBN
Product
AVideo
Provider severity
MEDIUM
Conflicts
0

CVE-2026-33237

WWBN AVideo is an open source video platform. Prior to version 26.0, the Scheduler plugin's `run()` function in `plugin/Scheduler/Scheduler.php` calls `url_get_contents()` with an admin-configurable `callbackURL` that is validated only by `isValidURL()` (URL format check). Unlike other AVideo endpoints that were recently patched for SSRF (GHSA-9x67-f2v7-63rw, GHSA-h39h-7cvg-q7j6), the Scheduler's callback URL is never passed through `isSSRFSafeURL()`, which blocks requests to RFC-1918 private ad

PUBLISHED
Vendor
WWBN
Product
AVideo
Provider severity
MEDIUM
Conflicts
0

CVE-2026-33236

A flaw was found in NLTK (Natural Language Toolkit), a suite of open-source Python modules for Natural Language Processing. The NLTK downloader does not validate `subdir` and `id` attributes when processing remote XML index files. A remote attacker can exploit this path traversal vulnerability by controlling a malicious XML index server, providing specially crafted values. This can lead to arbitrary directory creation, arbitrary file creation, and arbitrary file overwrite on the system where NLT

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, nltk, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat OpenShift AI 2.25, Red Hat Ansible Automation Platform 2, OpenShift Lightspeed, OpenShift Lightspeed, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, nltk, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI 2.25, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI 2.25, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI 3.3, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Lightspeed Core, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI 3.3, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI 3.3, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), OpenShift Lightspeed, Red Hat Ansible Automation Platform 2, Lightspeed Core, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2
Provider severity
HIGH
Conflicts
2

CVE-2026-33235

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. In versions prior to 0.6.52, the Fill Text Template block is vulnerable to a Denial of Service (DoS) attack. While the backend implements a SandboxedEnvironment to prevent unauthorized attribute access (e.g., blocking __class__), it fails to limit the computational complexity or execution time of the expressions. An attacker can input computationally expensive Python/Jinja2

PUBLISHED
Vendor
Significant-Gravitas
Product
AutoGPT
Provider severity
HIGH
Conflicts
0

CVE-2026-33234

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. In versions 0.1.0 through 0.6.51, SendEmailBlock in autogpt_platform/backend/backend/blocks/email_block.py accepts a user-supplied smtp_server (string) and smtp_port (integer) as per-execution block inputs, then passes them directly to Python's smtplib.SMTP() to open a raw TCP connection with no IP address validation. This completely bypasses the platform's hardened SSRF pr

PUBLISHED
Vendor
Significant-Gravitas
Product
AutoGPT
Provider severity
MEDIUM
Conflicts
0

CVE-2026-33233

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. In versions 0.6.34 through 0.6.51, the backend deserializes Redis cache bytes using pickle.loads without integrity/authenticity checks. The write path serializes values with pickle.dumps(...) into Redis and the read path blindly invokes pickle.loads(...) on bytes with no HMAC/signature or strict schema validation gating deserialization. If an attacker can poison a shared-cac

PUBLISHED
Vendor
Significant-Gravitas
Product
AutoGPT
Provider severity
HIGH
Conflicts
1

CVE-2026-33232

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions 0.4.2 through 0.6.51 are vulnerable to an unauthenticated Denial of Service (DoS) through the server due to uncontrolled disk space consumption. The download_agent_file endpoint creates persistent temporary files for every request but fails to delete them after they are served. An unauthenticated attacker can repeatedly call this endpoint to exhaust the server's dis

PUBLISHED
Vendor
Significant-Gravitas
Product
AutoGPT
Provider severity
HIGH
Conflicts
1

CVE-2026-33231

A flaw was found in NLTK (Natural Language Toolkit), specifically in the `nltk.app.wordnet_app` component. An unauthenticated remote attacker can exploit this vulnerability by sending a specially crafted GET request to the local WordNet Browser HTTP server when it is running in its default configuration. This action causes the server process to terminate immediately, leading to a denial of service.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, nltk, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
OpenShift Lightspeed, Red Hat OpenShift AI 2.25, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Lightspeed Core, Red Hat OpenShift AI 3.3, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI 3.3, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, OpenShift Lightspeed, Red Hat Ansible Automation Platform 2, OpenShift Lightspeed, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Lightspeed Core, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI 2.25, nltk, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI 3.3, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2, Red Hat Ansible Automation Platform 2
Provider severity
HIGH
Conflicts
2

CVE-2026-33230

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, `nltk.app.wordnet_app` contains a reflected cross-site scripting issue in the `lookup_...` route. A crafted `lookup_<payload>` URL can inject arbitrary HTML/JavaScript into the response page because attacker-controlled `word` data is reflected into HTML without escaping. This impacts users running the l

PUBLISHED
Vendor
nltk
Product
nltk
Provider severity
MEDIUM
Conflicts
0

CVE-2026-3323

An unsecured configuration interface on affected devices allows unauthenticated remote attackers to access sensitive information, including hashed credentials and access codes.

PUBLISHED
Vendor
VEGA Grieshaber, VEGA Grieshaber
Product
VEGAPULS 6X Two-wire PROFINET, Modbus TCP, OPC UA (Ethernet-APL), VEGAPULS 6X Two-wire PROFINET, Modbus TCP, OPC UA (Ethernet-APL)
Provider severity
HIGH
Conflicts
1

CVE-2026-33229

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.4.8 and 17.10.1, an improperly protected scripting API allows any user with script right to bypass the sandboxing of the Velocity scripting API and execute, e.g., arbitrary Python scripts, allowing full access to the XWiki instance and thereby compromising the confidentiality, integrity and availability of the whole instance. Note that script right already constitutes a high level

PUBLISHED
Vendor
org.xwiki.platform, org.xwiki.platform, xwiki
Product
xwiki-platform-oldcore, xwiki-platform-legacy-oldcore, xwiki-platform
Provider severity
CRITICAL, HIGH
Conflicts
2

CVE-2026-33228

flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted can use attacker-controlled string values from the parsed JSON as direct array index keys, without validating that they are numeric. Since the internal input buffer is a JavaScript Array, accessing it with the key "__proto__" returns Array.prototype via the inherited getter. This object is then treated as a legitimate parsed value and assigned as a property of the output object, effectively leaking a live

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, WebReflection, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat 3scale API Management Platform 2, Red Hat Enterprise Linux 9, Red Hat 3scale API Management Platform 2, Red Hat Enterprise Linux 9, Red Hat Build of Podman Desktop, Logging Subsystem for Red Hat OpenShift, Logging Subsystem for Red Hat OpenShift, Red Hat Enterprise Linux 8, Red Hat build of Apicurio Registry 2, Red Hat JBoss Enterprise Application Platform 8, Red Hat Directory Server 13, Red Hat Process Automation 7, Logging Subsystem for Red Hat OpenShift, Cluster Observability Operator 1.5.0, Multicluster Engine for Kubernetes, Cryostat 4, Red Hat 3scale API Management Platform 2, Red Hat 3scale API Management Platform 2, Cluster Observability Operator 1.5.0, Red Hat 3scale API Management Platform 2, Red Hat Quay 3, Red Hat 3scale API Management Platform 2, Red Hat OpenShift Container Platform 4, Red Hat Directory Server 12, Red Hat Process Automation 7, Red Hat Single Sign-On 7, Red Hat Quay 3, Red Hat Process Automation 7, streams for Apache Kafka 2, Logging Subsystem for Red Hat OpenShift, Red Hat Data Grid 8, Red Hat 3scale API Management Platform 2, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat OpenShift AI (RHOAI), Red Hat Build of Keycloak, Red Hat Fuse 7, Red Hat OpenShift Container Platform 4, Red Hat Build of Podman Desktop, Cluster Observability Operator 1.5.0, Red Hat Directory Server 11, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat 3scale API Management Platform 2, Red Hat Enterprise Linux 8, Red Hat AMQ Broker 7, Red Hat Developer Hub 1.9, flatted, Red Hat Enterprise Linux 10, Red Hat Developer Hub 1.8, Red Hat 3scale API Management Platform 2, Logging Subsystem for Red Hat OpenShift, Red Hat build of OptaPlanner 8, Red Hat Enterprise Linux 9, Logging Subsystem for Red Hat OpenShift, Red Hat JBoss Enterprise Application Platform 7, streams for Apache Kafka 3, Red Hat OpenShift AI (RHOAI)
Provider severity
CRITICAL, HIGH
Conflicts
3

CVE-2026-33227

Improper validation and restriction of a classpath path name vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ Web, Apache ActiveMQ. In two instances (when creating a Stomp consumer and also browsing messages in the Web console) an authenticated user provided "key" value could be constructed to traverse the classpath due to path concatenation. As a result, the application is exposed to a classpath path resource loading vulnerability that

PUBLISHED
Vendor
Apache Software Foundation, Apache Software Foundation, Apache Software Foundation, Apache Software Foundation, Apache Software Foundation
Product
Apache ActiveMQ, Apache ActiveMQ Client, Apache ActiveMQ Web, Apache ActiveMQ All, Apache ActiveMQ Broker
Provider severity
MEDIUM
Conflicts
1

CVE-2026-33226

Budibase is a low code platform for creating internal tools, workflows, and admin panels. In versions from 3.30.6 and prior, the REST datasource query preview endpoint (POST /api/queries/preview) makes server-side HTTP requests to any URL supplied by the user in fields.path with no validation. An authenticated admin can reach internal services that are not exposed to the internet — including cloud metadata endpoints (AWS/GCP/Azure), internal databases, Kubernetes APIs, and other pods on the inte

PUBLISHED
Vendor
Budibase
Product
budibase
Provider severity
HIGH
Conflicts
0

CVE-2026-33223

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, the NATS message header `Nats-Request-Info:` is supposed to be a guarantee of identity by the NATS server, but the stripping of this header from inbound messages was not fully effective. An attacker with valid credentials for any regular client interface could thus spoof their identity to services which rely upon this header. Versions 2.11.15 and 2.12.6 contain a

PUBLISHED
Vendor
nats-io
Product
nats-server
Provider severity
MEDIUM
Conflicts
0

CVE-2026-33222

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, users with JetStream admin API access to restore one stream could restore to other stream names, impacting data which should have been protected against them. Versions 2.11.15 and 2.12.6 contain a fix. As a workaround, if developers have configured users to have limited JetStream restore permissions, temporarily remove those permissions.

PUBLISHED
Vendor
nats-io
Product
nats-server
Provider severity
MEDIUM
Conflicts
0

CVE-2026-33221

Nhost is an open source Firebase alternative with GraphQL. Prior to version 0.12.0, the storage service's file upload handler trusts the client-provided Content-Type header without performing server-side MIME type detection. This allows an attacker to upload files with an arbitrary MIME type, bypassing any MIME-type-based restrictions configured on storage buckets. This issue has been patched in version 0.12.0.

PUBLISHED
Vendor
nhost
Product
nhost
Provider severity
LOW
Conflicts
1

CVE-2026-33220

Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpoints, which in turn didn't perform proper access control. This issue has been fixed in version 5.17. If developers are unable to update immediately, they can disable this feature as the CDN add-on is not enabled by default.

PUBLISHED
Vendor
WeblateOrg
Product
weblate
Provider severity
MEDIUM
Conflicts
1

CVE-2026-33219

A flaw was found in NATS-Server. A malicious client connecting to the WebSockets port can cause unbounded memory use before authentication by sending a large amount of data. This resource exhaustion vulnerability can lead to a Denial of Service (DoS) for the server, making it unavailable to legitimate users.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, nats-io
Product
Red Hat OpenShift Container Platform 4, Red Hat multicluster global hub 1.6.0, Multicluster Global Hub 1.5.4, Red Hat multicluster global hub 1.4.4, nats-server
Provider severity
HIGH, MEDIUM
Conflicts
3

CVE-2026-33218

A flaw was found in NATS-Server, a high-performance messaging system. A remote attacker, by connecting to the leafnode port and sending a specially crafted malformed message before authentication, can cause the nats-server to crash. This vulnerability leads to a Denial of Service (DoS), making the server unavailable to legitimate users.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, nats-io
Product
Multicluster Global Hub 1.5.4, Red Hat multicluster global hub 1.4.4, Red Hat OpenShift Container Platform 4, Red Hat multicluster global hub 1.6.0, nats-server
Provider severity
HIGH
Conflicts
2

CVE-2026-33217

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, when using ACLs on message subjects, these ACLs were not applied in the `$MQTT.>` namespace, allowing MQTT clients to bypass ACL checks for MQTT subjects. Versions 2.11.15 and 2.12.6 contain a fix. No known workarounds are available.

PUBLISHED
Vendor
nats-io, Red Hat, Red Hat, Red Hat, Red Hat
Product
nats-server, Red Hat OpenShift Container Platform 4, Red Hat multicluster global hub 1.4.4, Red Hat multicluster global hub 1.6.0, Multicluster Global Hub 1.5.4
Provider severity
HIGH
Conflicts
3

CVE-2026-33216

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, for MQTT deployments using usercodes/passwords: MQTT passwords are incorrectly classified as a non-authenticating identity statement (JWT) and exposed via monitoring endpoints. Versions 2.11.14 and 2.12.6 contain a fix. As a workaround, ensure monitoring end-points are adequately secured. Best practice remains to not expose the monitoring endpoint to the Internet

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, nats-io
Product
Multicluster Global Hub 1.5.4, Red Hat multicluster global hub 1.4.4, Red Hat multicluster global hub 1.6.0, Red Hat OpenShift Container Platform 4, nats-server
Provider severity
HIGH
Conflicts
2