24h | 7d | 30d

Overview

  • Go standard library
  • net
  • net

07 May 2026
Published
08 May 2026
Updated

CVSS
Pending
EPSS
0.01%

KEV

Description

When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.

Statistics

  • 1 Post

Last activity: 5 hours ago

Bluesky

Profile picture fallback
🚨 New UNKNOWN CVE detected in AWS Lambda 🚨 CVE-2026-33811 impacts stdlib in 26 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/496 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless
  • 0
  • 0
  • 0
  • 5h ago

Overview

  • golang.org/x/net
  • golang.org/x/net/http2
  • golang.org/x/net/http2

07 May 2026
Published
07 May 2026
Updated

CVSS
Pending
EPSS
0.01%

KEV

Description

When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.

Statistics

  • 1 Post

Last activity: 5 hours ago

Bluesky

Profile picture fallback
🚨 New UNKNOWN CVE detected in AWS Lambda 🚨 CVE-2026-33814 impacts stdlib in 26 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/497 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless
  • 0
  • 0
  • 0
  • 5h ago

Overview

  • Microsoft
  • Azure Cloud Shell

07 May 2026
Published
07 May 2026
Updated

CVSS v3.1
CRITICAL (9.6)
EPSS
0.06%

KEV

Description

Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unauthorized attacker to perform spoofing over a network.

Statistics

  • 1 Post

Last activity: 11 hours ago

Fediverse

Profile picture fallback

🛡️ CVE-2026-35428 (CRITICAL, CVSS 9.6) affects Microsoft Azure Cloud Shell via command injection (CWE-77). Exploitation enables spoofing over networks. Microsoft has deployed a fix — update your environments! Details: radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 11h ago

Overview

  • mesa3d
  • Mesa

12 Apr 2026
Published
13 Apr 2026
Updated

CVSS v3.1
HIGH (8.1)
EPSS
0.05%

KEV

Description

In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party, and is then used for alloca.

Statistics

  • 1 Post

Last activity: 3 hours ago

Bluesky

Profile picture fallback
CVE-2026-40393 isn't going anywhere. Check your #openSUSE Mesa version, run this 1‑minute script, and lock down WebGPU for good Read more - > tinyurl.com/5n6hwtww #Security
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • AWS
  • Amazon ECS Agent

30 Apr 2026
Published
01 May 2026
Updated

CVSS v3.1
HIGH (7.2)
EPSS
0.04%

KEV

Description

Improper neutralization of inputs used in an OS command in the FSx Windows File Server volume mounting component in Amazon ECS Agent on Windows before version 1.103.0 might allow a remote authenticated threat actor to execute shell commands with SYSTEM privileges on the underlying host via a specially crafted username field in an ECS task definition. This issue requires permissions to register ECS task definitions or write to the Secrets Manager or SSM Parameter Store credentials used by the FSx volume configuration. To remediate this issue, users should upgrade to version 1.103.0.

Statistics

  • 1 Post

Last activity: 1 hour ago

Bluesky

Profile picture fallback
Zero-Day to SYSTEM (RCE): Escaping AWS ECS Containers via OS Command Injection CVE-2026–7461 https://medium.com/@sachinpatilsp/zero-day-to-system-escaping-aws-ecs-containers-via-os-command-injection-cve-2026-7461-3d44f5f367e8?source=rss------bug_bounty-5
  • 0
  • 0
  • 0
  • 1h ago

Overview

  • gravitational
  • teleport

17 Jun 2025
Published
18 Jun 2025
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
17.82%

KEV

Description

Teleport provides connectivity, authentication, access controls and audit for infrastructure. Community Edition versions before and including 17.5.1 are vulnerable to remote authentication bypass. At time of posting, there is no available open-source patch.

Statistics

  • 1 Post

Last activity: 12 hours ago

Bluesky

Profile picture fallback
Exploiting CVE-2025-49825 (authentication bypass vulnerability in Teleport)
  • 0
  • 0
  • 0
  • 12h ago

Overview

  • Microsoft
  • Azure Managed Instance for Apache Cassandra

07 May 2026
Published
07 May 2026
Updated

CVSS v3.1
CRITICAL (9.0)
EPSS
0.05%

KEV

Description

Improper input validation in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.

Statistics

  • 1 Post

Last activity: 10 hours ago

Fediverse

Profile picture fallback

⚠️ CRITICAL: CVE-2026-33844 in Azure Managed Instance for Apache Cassandra allows authorized attackers to execute code remotely via improper input validation. Microsoft manages remediation — verify your instances are patched. More info: radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 10h ago

Overview

  • Remote Spark (https://www.remotespark.com/)
  • SparkView

08 May 2026
Published
08 May 2026
Updated

CVSS v4.0
CRITICAL (10.0)
EPSS
0.19%

KEV

Description

A vulnerability in Remote Spark SparkView before build 1122 allows an attacker to bypasses the local connection check and achieve arbitrary code execution as root on the server side. Depending on implementation the vulnerability can be exploited by an unauthenticated attacker.

Statistics

  • 1 Post

Last activity: 7 hours ago

Fediverse

Profile picture fallback

CRITICAL: Remote Spark SparkView (<1122) vuln (CVE-2026-6213) lets unauth attackers run code as root via untrusted input. Full server takeover possible. Restrict access & monitor. Patch status unconfirmed. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 7h ago

Overview

  • ollama
  • ollama
  • ollama/ollama

04 May 2026
Published
04 May 2026
Updated

CVSS v3.1
CRITICAL (9.1)
EPSS
0.09%

KEV

Description

Ollama before 0.17.1 contains a heap out-of-bounds read vulnerability in the GGUF model loader. The /api/create endpoint accepts an attacker-supplied GGUF file in which the declared tensor offset and size exceed the file's actual length; during quantization in fs/ggml/gguf.go and server/quantization.go (WriteTo()), the server reads past the allocated heap buffer. The leaked memory contents may include environment variables, API keys, system prompts, and concurrent users' conversation data, and can be exfiltrated by uploading the resulting model artifact through the /api/push endpoint to an attacker-controlled registry. The /api/create and /api/push endpoints have no authentication in the upstream distribution. Default deployments bind to 127.0.0.1, but the documented OLLAMA_HOST=0.0.0.0 configuration is widely used in practice (large public-internet exposure observed).

Statistics

  • 1 Post

Last activity: 2 hours ago

Bluesky

Profile picture fallback
📢 CVE-2026-7482 : Fuite mémoire critique non authentifiée dans Ollama (Bleeding Llama) 📝 ## 🔍 Contexte Publié le 5 mai 2026 par Dor Attias de Cyera … https://cyberveille.ch/posts/2026-05-08-cve-2026-7482-fuite-memoire-critique-non-authentifiee-dans-ollama-bleeding-llama/ #CVE_2026_7482 #Cyberveille
  • 0
  • 0
  • 0
  • 2h ago

Overview

  • axios
  • axios

24 Apr 2026
Published
24 Apr 2026
Updated

CVSS v4.0
MEDIUM (6.9)
EPSS
0.05%

KEV

Description

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, toFormData recursively walks nested objects with no depth limit, so a deeply nested value passed as request data crashes the Node.js process with a RangeError. This vulnerability is fixed in 1.15.1 and 0.31.1.

Statistics

  • 1 Post

Last activity: 5 hours ago

Bluesky

Profile picture fallback
🚨 New MEDIUM CVE detected in AWS Lambda 🚨 CVE-2026-42039 impacts axios in 3 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/507 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless
  • 0
  • 0
  • 0
  • 5h ago
Showing 31 to 40 of 117 CVEs