24h | 7d | 30d

Overview

  • Linux
  • Linux

27 Jul 2026
Published
30 Jul 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
0.12%

KEV

Description

In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: reject oversized nested action attrs Open vSwitch stores generated flow actions as nlattrs, whose nla_len field is u16. Commit a1e64addf3ff ("net: openvswitch: remove misbehaving actions length check") allowed the total sw_flow_actions stream to grow beyond 64 KiB, which is valid, but also removed the last guard preventing a generated nested action attribute from exceeding U16_MAX. An oversized generated container can thus be closed with a truncated nla_len. A later dump or teardown then walks a structurally different stream than the one that was validated. In particular, an oversized nested CLONE/CT action may cause subsequent bytes in the generated stream to be interpreted as independent actions. Keep the larger total-action-stream behavior, but make nested action close reject generated containers that do not fit in nla_len, and return the error through all callers. For recursive SAMPLE, CLONE, DEC_TTL, and CHECK_PKT_LEN builders, trim resource-owning action-list tails in reverse construction order before discarding failed wrappers, so resources copied into the rejected tails are released before the wrappers are removed. Most failed outer wrappers are discarded by truncating actions_len after child resources have been released. CHECK_PKT_LEN also trims its parent after branch resources are gone. SET/TUNNEL close failures unwind their known tun_dst ownership directly, and SET_TO_MASKED has no external ownership and truncates on close failure.

Statistics

  • 1 Post

Last activity: 16 hours ago

Bluesky

Profile picture fallback
Falha OVSwrap ameaça servidores Linux com acesso root e já tem exploit público. Uma vulnerabilidade crítica no kernel do Linux, batizada de OVSwrap (CVE-2026-64531), permite que utilizadores locais sem privilégios obtenham acesso total de root. 🚨 #exploit #falha #linux #root
  • 0
  • 0
  • 0
  • 16h ago

Overview

  • bank-vaults
  • vault-secrets-webhook

31 Jul 2026
Published
31 Jul 2026
Updated

CVSS v3.1
CRITICAL (9.6)
EPSS
Pending

KEV

Description

vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in pkg/webhook/config.go accepts the vault.security.banzaicloud.io/vault-addr annotation, MutateConfigMap and MutateSecret call newVaultClient in pkg/webhook/webhook.go, and vault.security.banzaicloud.io/vault-serviceaccount can cause a ServiceAccount JWT to be sent to an attacker-controlled Vault address. This issue is fixed in version 1.23.1.

Statistics

  • 1 Post

Last activity: 6 hours ago

Fediverse

Profile picture fallback

bank-vaults vault-secrets-webhook is impacted by CVE-2026-54725 (CRITICAL, CVSS 9.6). SSRF flaw lets attackers exfiltrate ServiceAccount JWTs via attacker-controlled Vault addresses. Update to 1.23.1 ASAP. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 6h ago

Overview

  • nocobase
  • nocobase

15 Jul 2026
Published
20 Jul 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
0.59%

KEV

Description

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.0.61, NocoBase @nocobase/plugin-notification-in-app-message exposed GET /api/myInAppChannels:list, where the filter[latestMsgReceiveTimestamp][$lt] value was inserted into a Sequelize.literal() template string without escaping or parameter binding, allowing a signed-up authenticated user to run stacked PostgreSQL statements and potentially execute commands with COPY ... TO PROGRAM. This vulnerability is fixed in 2.0.61.

Statistics

  • 1 Post

Last activity: Last hour

Fediverse

Profile picture fallback

CVE-2026-52887: @nocobase/plugin-notification-in-app-message <2.0.61 suffers CRITICAL SQL injection in /api/myInAppChannels:list, enabling RCE as PG superuser 🛡️. Patch to 2.0.61+, disable anonymous signup, restrict DB roles. radar.offseq.com/threat/plugin

  • 0
  • 0
  • 0
  • Last hour

Overview

  • Red Hat
  • Red Hat Enterprise Linux 10
  • pipewire

16 Jul 2026
Published
28 Jul 2026
Updated

CVSS
Pending
EPSS
0.12%

KEV

Description

A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio compatibility layer. An attacker with minimal permissions within a sandboxed environment can load a malicious library, leading to arbitrary code execution outside the sandbox and potential compromise of the user's system.

Statistics

  • 1 Post

Last activity: 18 hours ago

Bluesky

Profile picture fallback
[RSS] Escaping Linux Sandboxes via PipeWire (CVE-2026-5674) embracethered.com -> Original->
  • 0
  • 0
  • 0
  • 18h ago

Overview

  • Microsoft
  • Windows 10 Version 1607

14 Jul 2026
Published
30 Jul 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
1.05%

KEV

Description

Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.

Statistics

  • 2 Posts

Last activity: 7 hours ago

Bluesky

Profile picture fallback
"Detecting CVE-2026-54121 (Certighost) with Microsoft Defender" buff.ly/5ljKdWg #Microsoft #techcommunity
  • 0
  • 0
  • 1
  • 7h ago

Overview

  • clastix
  • kamaji

30 Jul 2026
Published
31 Jul 2026
Updated

CVSS v3.1
HIGH (8.5)
EPSS
0.27%

KEV

Description

Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane datastore schema, database user, and etcd key prefix from a lossy namespace-and-name normalization in GetDefaultDatastoreSchema() and GetDefaultDatastoreUsername(), allowing distinct tenants with colliding normalized identifiers to share control-plane state and read, modify, or destroy another tenant's Kubernetes data. This issue is fixed in version 26.7.4-edge.

Statistics

  • 1 Post

Last activity: 7 hours ago

Fediverse

Profile picture fallback

CVE-2026-62246 - Kamaji tenant isolation bypass. Lossy name normalization lets tenants read, modify, or destroy other tenants' Kubernetes data. CVSS 8.5. Update to 26.7.4-edge immediately. #CVE #Kubernetes #infosec

valtersit.com/cve/CVE-2026-622

  • 0
  • 0
  • 0
  • 7h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post

Last activity: 4 hours ago

Fediverse

Profile picture fallback

CVE-2026-18420: CRITICAL RCE via prototype pollution in OpenSearch Dashboards TSVB plugin. Full system compromise possible. No patch yet — check AWS Security Bulletin, limit plugin access, monitor updates. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Microsoft
  • Azure Cosmos DB

30 Jul 2026
Published
31 Jul 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
0.49%

KEV

Description

Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.

Statistics

  • 1 Post

Last activity: 10 hours ago

Fediverse

Profile picture fallback

CVE-2026-66803 - Critical improper access control in Azure Cosmos DB allows remote code execution. CVSS 10. No patch yet - apply mitigations immediately. #CVE #Azure #infosec

valtersit.com/cve/CVE-2026-668

  • 0
  • 0
  • 0
  • 10h ago

Overview

  • Google
  • Chrome

04 Mar 2026
Published
05 Mar 2026
Updated

CVSS
Pending
EPSS
0.26%

KEV

Description

Insufficient data validation in Navigation in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Statistics

  • 1 Post

Last activity: 9 hours ago

Bluesky

Profile picture fallback
Chrome 149-151 fixed 1,442 flaws total, including 7 critical issues. A sandbox escape flaw, CVE-2026-3545, could enable local file access as Google speeds up releases and patching. #Chrome #CVE2026 #Google
  • 0
  • 0
  • 0
  • 9h ago

Overview

  • fast-uri
  • fast-uri

31 Jul 2026
Published
31 Jul 2026
Updated

CVSS v3.1
HIGH (7.5)
EPSS
Pending

KEV

Description

fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a reference that uses a backslash based introducer in place of it (backslash backslash, forward slash backslash, or backslash forward slash) is parsed with no authority and folds into the path. Node's native WHATWG URL parser instead treats a backslash as interchangeable with a forward slash for special schemes, so the two parsers extract different hosts from the same input. Applications that use fast-uri to enforce host based policy such as allowlists, SSRF filtering, or redirect validation before passing the same URL into Node's URL or fetch consumers can be steered to an unintended host. Upgrade to fast-uri 4.1.2, 3.1.5, or 2.4.4.

Statistics

  • 2 Posts

Last activity: 11 hours ago

Fediverse

Profile picture fallback

🚨 High-severity security fix in fast-uri@4.1.2 just released!

Patches CVE-2026-18446, fast-uri vulnerable to host confusion via backslash authority introducer

github.com/fastify/fast-uri/se

  • 0
  • 0
  • 1
  • 11h ago
Showing 21 to 30 of 46 CVEs