24h | 7d | 30d

Overview

  • Python Software Foundation
  • CPython
  • http.client

10 Apr 2026
Published
21 Apr 2026
Updated

CVSS v4.0
MEDIUM (5.7)
EPSS
0.06%

KEV

Description

CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.

Statistics

  • 1 Post

Last activity: 21 hours ago

Bluesky

Profile picture fallback
CVE-2026-1502 (HTTP injection) and CVE-2026-4786 (command injection) hit Python 3.14 on Fedora. Don't just patch today. Build automation that finds ANY CVE. Read -> tinyurl.com/2krzcetb #Fedora #Security
  • 0
  • 0
  • 0
  • 21h ago

Overview

  • Python Software Foundation
  • CPython

13 Apr 2026
Published
14 Apr 2026
Updated

CVSS v4.0
HIGH (7.0)
EPSS
0.02%

KEV

Description

Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.

Statistics

  • 1 Post

Last activity: 21 hours ago

Bluesky

Profile picture fallback
CVE-2026-1502 (HTTP injection) and CVE-2026-4786 (command injection) hit Python 3.14 on Fedora. Don't just patch today. Build automation that finds ANY CVE. Read -> tinyurl.com/2krzcetb #Fedora #Security
  • 0
  • 0
  • 0
  • 21h ago

Overview

  • coreruleset
  • coreruleset

08 Jan 2026
Published
09 Apr 2026
Updated

CVSS v3.1
CRITICAL (9.3)
EPSS
0.07%

KEV

Description

The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 4.22.0 and 3.3.8, the current rule 922110 has a bug when processing multipart requests with multiple parts. When the first rule in a chain iterates over a collection (like `MULTIPART_PART_HEADERS`), the capture variables (`TX:0`, `TX:1`) get overwritten with each iteration. Only the last captured value is available to the chained rule, which means malicious charsets in earlier parts can be missed if a later part has a legitimate charset. Versions 4.22.0 and 3.3.8 patch the issue.

Statistics

  • 1 Post

Last activity: 5 hours ago

Bluesky

Profile picture fallback
MOVEit WAF Critical Security Bulletin – April 2026 – (CVE-2026-3517, CVE-2026-3518, CVE-2026-3519, CVE-2026-4048, CVE-2026-21876)
  • 0
  • 0
  • 0
  • 5h ago

Overview

  • Progress Software
  • LoadMaster

20 Apr 2026
Published
22 Apr 2026
Updated

CVSS v3.1
HIGH (8.4)
EPSS
0.05%

KEV

Description

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'killsession' command

Statistics

  • 1 Post

Last activity: 5 hours ago

Bluesky

Profile picture fallback
MOVEit WAF Critical Security Bulletin – April 2026 – (CVE-2026-3517, CVE-2026-3518, CVE-2026-3519, CVE-2026-4048, CVE-2026-21876)
  • 0
  • 0
  • 0
  • 5h ago

Overview

  • Progress Software
  • LoadMaster

20 Apr 2026
Published
22 Apr 2026
Updated

CVSS v3.1
HIGH (8.4)
EPSS
0.05%

KEV

Description

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “Geo Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'addcountry' command

Statistics

  • 1 Post

Last activity: 5 hours ago

Bluesky

Profile picture fallback
MOVEit WAF Critical Security Bulletin – April 2026 – (CVE-2026-3517, CVE-2026-3518, CVE-2026-3519, CVE-2026-4048, CVE-2026-21876)
  • 0
  • 0
  • 0
  • 5h ago

Overview

  • Progress Software
  • LoadMaster

20 Apr 2026
Published
22 Apr 2026
Updated

CVSS v3.1
HIGH (8.4)
EPSS
0.05%

KEV

Description

OS Command Injection Remote Code Execution Vulnerability in UI in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in a custom WAF rule file during the file upload process.

Statistics

  • 1 Post

Last activity: 5 hours ago

Bluesky

Profile picture fallback
MOVEit WAF Critical Security Bulletin – April 2026 – (CVE-2026-3517, CVE-2026-3518, CVE-2026-3519, CVE-2026-4048, CVE-2026-21876)
  • 0
  • 0
  • 0
  • 5h ago

Overview

  • Progress Software
  • LoadMaster

20 Apr 2026
Published
22 Apr 2026
Updated

CVSS v3.1
HIGH (8.4)
EPSS
0.05%

KEV

Description

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “VS Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'aclcontrol' command

Statistics

  • 1 Post

Last activity: 5 hours ago

Bluesky

Profile picture fallback
MOVEit WAF Critical Security Bulletin – April 2026 – (CVE-2026-3517, CVE-2026-3518, CVE-2026-3519, CVE-2026-4048, CVE-2026-21876)
  • 0
  • 0
  • 0
  • 5h ago
Showing 21 to 27 of 27 CVEs