24h | 7d | 30d

Overview

  • Go standard library
  • encoding/xml
  • encoding/xml

13 Aug 2026
Published
14 Aug 2026
Updated

CVSS
Pending
EPSS
0.57%

KEV

Description

Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.

Statistics

  • 2 Posts

Last activity: 4 hours ago

Bluesky

Profile picture fallback
following vulnerability: CVE-2026-84445 N/A Security fixes for apigee-prom-prometheus. This addresses the following vulnerabilities: CVE-2026-33818 CVE-2026-39821 CVE-2026-46600 CVE-2026-56853 CVE-2026-56858 CVE-2026-56859 CVE-2026-56860 CVE-2026-56862 CVE-2026-56864
  • 0
  • 0
  • 0
  • 4h ago
Profile picture fallback
CVE-2026-54513 CVE-2026-54514 CVE-2026-54515 CVE-2026-56853 CVE-2026-56858 CVE-2026-56859 CVE-2026-56860 CVE-2026-56862 CVE-2026-56864 CVE-2026-56865 GHSA-r7wm-3cxj-wff9 N/A Security fixes for apigee-hybrid-cassandra-client. This addresses the following vulnerabilities:
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Go standard library
  • net/http
  • net/http

22 May 2026
Published
17 Sep 2026
Updated

CVSS
Pending
EPSS
0.69%

KEV

Description

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".

Statistics

  • 2 Posts

Last activity: 4 hours ago

Bluesky

Profile picture fallback
following vulnerability: CVE-2026-84445 N/A Security fixes for apigee-prom-prometheus. This addresses the following vulnerabilities: CVE-2026-33818 CVE-2026-39821 CVE-2026-46600 CVE-2026-56853 CVE-2026-56858 CVE-2026-56859 CVE-2026-56860 CVE-2026-56862 CVE-2026-56864
  • 0
  • 0
  • 0
  • 4h ago
Profile picture fallback
CVE-2026-34477 CVE-2026-34480 CVE-2026-39817 CVE-2026-39819 CVE-2026-39820 CVE-2026-39821 CVE-2026-39822 CVE-2026-39823 CVE-2026-39825 CVE-2026-39826 CVE-2026-39836 CVE-2026-42499 CVE-2026-42501 CVE-2026-42504 CVE-2026-42505 CVE-2026-42507 CVE-2026-50193 CVE-2026-54512
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • FasterXML
  • jackson-databind

23 Jun 2026
Published
24 Jun 2026
Updated

CVSS v3.1
MEDIUM (5.3)
EPSS
0.44%

KEV

Description

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.8.0 until 2.18.9, 2.21.5, and 3.1.4, in BeanDeserializerBase.createContextual(), per-property @JsonIgnoreProperties exclusions are applied by _handleByNameInclusion(), producing a contextual deserializer whose BeanPropertyMap has the ignored properties removed. The subsequent per-property case-insensitivity block (triggered by @JsonFormat(ACCEPT_CASE_INSENSITIVE_PROPERTIES)) rebuilds from this._beanProperties (the original, unfiltered map) instead of contextual._beanProperties, then overwrites the filtered map — restoring every property _handleByNameInclusion had just removed. The ignored property becomes writable again. This vulnerability is fixed in 2.18.9, 2.21.5, and 3.1.4.

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
CVE-2026-54513 CVE-2026-54514 CVE-2026-54515 CVE-2026-56853 CVE-2026-56858 CVE-2026-56859 CVE-2026-56860 CVE-2026-56862 CVE-2026-56864 CVE-2026-56865 GHSA-r7wm-3cxj-wff9 N/A Security fixes for apigee-hybrid-cassandra-client. This addresses the following vulnerabilities:
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Go standard library
  • crypto/tls
  • crypto/tls

13 Aug 2026
Published
14 Aug 2026
Updated

CVSS
Pending
EPSS
0.57%

KEV

Description

Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.

Statistics

  • 2 Posts

Last activity: 4 hours ago

Bluesky

Profile picture fallback
following vulnerability: CVE-2026-84445 N/A Security fixes for apigee-prom-prometheus. This addresses the following vulnerabilities: CVE-2026-33818 CVE-2026-39821 CVE-2026-46600 CVE-2026-56853 CVE-2026-56858 CVE-2026-56859 CVE-2026-56860 CVE-2026-56862 CVE-2026-56864
  • 0
  • 0
  • 0
  • 4h ago
Profile picture fallback
CVE-2026-54513 CVE-2026-54514 CVE-2026-54515 CVE-2026-56853 CVE-2026-56858 CVE-2026-56859 CVE-2026-56860 CVE-2026-56862 CVE-2026-56864 CVE-2026-56865 GHSA-r7wm-3cxj-wff9 N/A Security fixes for apigee-hybrid-cassandra-client. This addresses the following vulnerabilities:
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Go standard library
  • html/template
  • html/template

13 Aug 2026
Published
14 Aug 2026
Updated

CVSS
Pending
EPSS
0.31%

KEV

Description

Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.

Statistics

  • 2 Posts

Last activity: 4 hours ago

Bluesky

Profile picture fallback
following vulnerability: CVE-2026-84445 N/A Security fixes for apigee-prom-prometheus. This addresses the following vulnerabilities: CVE-2026-33818 CVE-2026-39821 CVE-2026-46600 CVE-2026-56853 CVE-2026-56858 CVE-2026-56859 CVE-2026-56860 CVE-2026-56862 CVE-2026-56864
  • 0
  • 0
  • 0
  • 4h ago
Profile picture fallback
CVE-2026-54513 CVE-2026-54514 CVE-2026-54515 CVE-2026-56853 CVE-2026-56858 CVE-2026-56859 CVE-2026-56860 CVE-2026-56862 CVE-2026-56864 CVE-2026-56865 GHSA-r7wm-3cxj-wff9 N/A Security fixes for apigee-hybrid-cassandra-client. This addresses the following vulnerabilities:
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • FasterXML
  • jackson-databind

23 Jun 2026
Published
14 Sep 2026
Updated

CVSS v3.1
HIGH (8.1)
EPSS
1.23%

KEV

Description

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
CVE-2026-54513 CVE-2026-54514 CVE-2026-54515 CVE-2026-56853 CVE-2026-56858 CVE-2026-56859 CVE-2026-56860 CVE-2026-56862 CVE-2026-56864 CVE-2026-56865 GHSA-r7wm-3cxj-wff9 N/A Security fixes for apigee-hybrid-cassandra-client. This addresses the following vulnerabilities:
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Go standard library
  • encoding/asn1
  • encoding/asn1

13 Aug 2026
Published
01 Oct 2026
Updated

CVSS
Pending
EPSS
0.57%

KEV

Description

Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.

Statistics

  • 2 Posts

Last activity: 4 hours ago

Bluesky

Profile picture fallback
following vulnerability: CVE-2026-84445 N/A Security fixes for apigee-prom-prometheus. This addresses the following vulnerabilities: CVE-2026-33818 CVE-2026-39821 CVE-2026-46600 CVE-2026-56853 CVE-2026-56858 CVE-2026-56859 CVE-2026-56860 CVE-2026-56862 CVE-2026-56864
  • 0
  • 0
  • 0
  • 4h ago
Profile picture fallback
CVE-2025-68121 CVE-2025-68161 CVE-2026-25679 CVE-2026-27139 CVE-2026-27140 CVE-2026-27142 CVE-2026-27143 CVE-2026-27144 CVE-2026-27145 CVE-2026-32280 CVE-2026-32281 CVE-2026-32282 CVE-2026-32283 CVE-2026-32288 CVE-2026-32289 CVE-2026-33811 CVE-2026-33814 CVE-2026-33818
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Go standard library
  • crypto/x509
  • crypto/x509

28 Jan 2025
Published
21 Feb 2025
Updated

CVSS
Pending
EPSS
0.48%

KEV

Description

A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain. Certificates containing URIs are not permitted in the web PKI, so this only affects users of private PKIs which make use of URIs.

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
This addresses the following vulnerabilities: CVE-2022-42003 CVE-2022-42004 CVE-2024-45336 CVE-2024-45341 CVE-2024-47554 CVE-2025-0913 CVE-2025-22866 CVE-2025-22870 CVE-2025-22871 CVE-2025-22873 CVE-2025-4673 CVE-2025-4674 CVE-2025-47906 CVE-2025-47907 CVE-2025-47912
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Go standard library
  • net/http
  • net/http

11 Jun 2025
Published
11 Jun 2025
Updated

CVSS
Pending
EPSS
0.67%

KEV

Description

Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information.

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
This addresses the following vulnerabilities: CVE-2022-42003 CVE-2022-42004 CVE-2024-45336 CVE-2024-45341 CVE-2024-47554 CVE-2025-0913 CVE-2025-22866 CVE-2025-22870 CVE-2025-22871 CVE-2025-22873 CVE-2025-4673 CVE-2025-4674 CVE-2025-47906 CVE-2025-47907 CVE-2025-47912
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Apache Software Foundation
  • Apache Commons IO
  • commons-io:commons-io

03 Oct 2024
Published
31 Jan 2025
Updated

CVSS
Pending
EPSS
1.32%

KEV

Description

Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache Commons IO: from 2.0 before 2.14.0. Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue.

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
This addresses the following vulnerabilities: CVE-2022-42003 CVE-2022-42004 CVE-2024-45336 CVE-2024-45341 CVE-2024-47554 CVE-2025-0913 CVE-2025-22866 CVE-2025-22870 CVE-2025-22871 CVE-2025-22873 CVE-2025-4673 CVE-2025-4674 CVE-2025-47906 CVE-2025-47907 CVE-2025-47912
  • 0
  • 0
  • 0
  • 4h ago
Showing 111 to 120 of 184 CVEs