Overview
- Go standard library
- encoding/xml
- encoding/xml
13 Aug 2026
Published
14 Aug 2026
Updated
CVSS
Pending
EPSS
0.57%
KEV
Description
Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.
Statistics
- 2 Posts
Last activity: 4 hours ago
Bluesky
following vulnerability: CVE-2026-84445 N/A Security fixes for apigee-prom-prometheus. This addresses the following vulnerabilities: CVE-2026-33818 CVE-2026-39821 CVE-2026-46600 CVE-2026-56853 CVE-2026-56858 CVE-2026-56859 CVE-2026-56860 CVE-2026-56862 CVE-2026-56864
Overview
- Go standard library
- net/http
- net/http
22 May 2026
Published
17 Sep 2026
Updated
CVSS
Pending
EPSS
0.69%
KEV
Description
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".
Statistics
- 2 Posts
Last activity: 4 hours ago
Bluesky
following vulnerability: CVE-2026-84445 N/A Security fixes for apigee-prom-prometheus. This addresses the following vulnerabilities: CVE-2026-33818 CVE-2026-39821 CVE-2026-46600 CVE-2026-56853 CVE-2026-56858 CVE-2026-56859 CVE-2026-56860 CVE-2026-56862 CVE-2026-56864
Overview
- FasterXML
- jackson-databind
23 Jun 2026
Published
24 Jun 2026
Updated
CVSS v3.1
MEDIUM (5.3)
EPSS
0.44%
KEV
Description
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.8.0 until 2.18.9, 2.21.5, and 3.1.4, in BeanDeserializerBase.createContextual(), per-property @JsonIgnoreProperties exclusions are applied by _handleByNameInclusion(), producing a contextual deserializer whose BeanPropertyMap has the ignored properties removed. The subsequent per-property case-insensitivity block (triggered by @JsonFormat(ACCEPT_CASE_INSENSITIVE_PROPERTIES)) rebuilds from this._beanProperties (the original, unfiltered map) instead of contextual._beanProperties, then overwrites the filtered map — restoring every property _handleByNameInclusion had just removed. The ignored property becomes writable again. This vulnerability is fixed in 2.18.9, 2.21.5, and 3.1.4.
Statistics
- 1 Post
Last activity: 4 hours ago
Overview
- Go standard library
- crypto/tls
- crypto/tls
13 Aug 2026
Published
14 Aug 2026
Updated
CVSS
Pending
EPSS
0.57%
KEV
Description
Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.
Statistics
- 2 Posts
Last activity: 4 hours ago
Bluesky
following vulnerability: CVE-2026-84445 N/A Security fixes for apigee-prom-prometheus. This addresses the following vulnerabilities: CVE-2026-33818 CVE-2026-39821 CVE-2026-46600 CVE-2026-56853 CVE-2026-56858 CVE-2026-56859 CVE-2026-56860 CVE-2026-56862 CVE-2026-56864
Overview
- Go standard library
- html/template
- html/template
13 Aug 2026
Published
14 Aug 2026
Updated
CVSS
Pending
EPSS
0.31%
KEV
Description
Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.
Statistics
- 2 Posts
Last activity: 4 hours ago
Bluesky
following vulnerability: CVE-2026-84445 N/A Security fixes for apigee-prom-prometheus. This addresses the following vulnerabilities: CVE-2026-33818 CVE-2026-39821 CVE-2026-46600 CVE-2026-56853 CVE-2026-56858 CVE-2026-56859 CVE-2026-56860 CVE-2026-56862 CVE-2026-56864
Overview
- FasterXML
- jackson-databind
23 Jun 2026
Published
14 Sep 2026
Updated
CVSS v3.1
HIGH (8.1)
EPSS
1.23%
KEV
Description
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.
Statistics
- 1 Post
Last activity: 4 hours ago
Overview
- Go standard library
- encoding/asn1
- encoding/asn1
13 Aug 2026
Published
01 Oct 2026
Updated
CVSS
Pending
EPSS
0.57%
KEV
Description
Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.
Statistics
- 2 Posts
Last activity: 4 hours ago
Bluesky
following vulnerability: CVE-2026-84445 N/A Security fixes for apigee-prom-prometheus. This addresses the following vulnerabilities: CVE-2026-33818 CVE-2026-39821 CVE-2026-46600 CVE-2026-56853 CVE-2026-56858 CVE-2026-56859 CVE-2026-56860 CVE-2026-56862 CVE-2026-56864
Overview
- Go standard library
- crypto/x509
- crypto/x509
28 Jan 2025
Published
21 Feb 2025
Updated
CVSS
Pending
EPSS
0.48%
KEV
Description
A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain. Certificates containing URIs are not permitted in the web PKI, so this only affects users of private PKIs which make use of URIs.
Statistics
- 1 Post
Last activity: 4 hours ago
Overview
- Go standard library
- net/http
- net/http
11 Jun 2025
Published
11 Jun 2025
Updated
CVSS
Pending
EPSS
0.67%
KEV
Description
Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information.
Statistics
- 1 Post
Last activity: 4 hours ago
Overview
- Apache Software Foundation
- Apache Commons IO
- commons-io:commons-io
03 Oct 2024
Published
31 Jan 2025
Updated
CVSS
Pending
EPSS
1.32%
KEV
Description
Uncontrolled Resource Consumption vulnerability in Apache Commons IO.
The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input.
This issue affects Apache Commons IO: from 2.0 before 2.14.0.
Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue.
Statistics
- 1 Post
Last activity: 4 hours ago