24h | 7d | 30d

Overview

  • GnuPG
  • GnuPG

27 Jan 2026
Published
27 Jan 2026
Updated

CVSS v3.1
HIGH (8.4)
EPSS
Pending

KEV

Description

In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys.

Statistics

  • 1 Post

Last activity: 16 hours ago

Fediverse

Profile picture

🟠 CVE-2026-24882 - High (8.4)

In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  • 0
  • 0
  • 0
  • 16h ago

Overview

  • vercel
  • next

26 Jan 2026
Published
27 Jan 2026
Updated

CVSS v3.1
MEDIUM (5.9)
EPSS
0.04%

KEV

Description

A denial of service vulnerability exists in self-hosted Next.js applications that have `remotePatterns` configured for the Image Optimizer. The image optimization endpoint (`/_next/image`) loads external images entirely into memory without enforcing a maximum size limit, allowing an attacker to cause out-of-memory conditions by requesting optimization of arbitrarily large images. This vulnerability requires that `remotePatterns` is configured to allow image optimization from external domains and that the attacker can serve or control a large image on an allowed domain. Strongly consider upgrading to 15.5.10 or 16.1.5 to reduce risk and prevent availability issues in Next applications.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 7 hours ago

Bluesky

Profile picture
vercel.com/changelog/summa... Summaries of CVE-2025-59471 and CVE-2025-59472 - Vercel
  • 0
  • 1
  • 0
  • 7h ago

Overview

  • vercel
  • next

26 Jan 2026
Published
27 Jan 2026
Updated

CVSS v3.1
MEDIUM (5.9)
EPSS
0.04%

KEV

Description

A denial of service vulnerability exists in Next.js versions with Partial Prerendering (PPR) enabled when running in minimal mode. The PPR resume endpoint accepts unauthenticated POST requests with the `Next-Resume: 1` header and processes attacker-controlled postponed state data. Two closely related vulnerabilities allow an attacker to crash the server process through memory exhaustion: 1. **Unbounded request body buffering**: The server buffers the entire POST request body into memory using `Buffer.concat()` without enforcing any size limit, allowing arbitrarily large payloads to exhaust available memory. 2. **Unbounded decompression (zipbomb)**: The resume data cache is decompressed using `inflateSync()` without limiting the decompressed output size. A small compressed payload can expand to hundreds of megabytes or gigabytes, causing memory exhaustion. Both attack vectors result in a fatal V8 out-of-memory error (`FATAL ERROR: Reached heap limit Allocation failed - JavaScript heap out of memory`) causing the Node.js process to terminate. The zipbomb variant is particularly dangerous as it can bypass reverse proxy request size limits while still causing large memory allocation on the server. To be affected you must have an application running with `experimental.ppr: true` or `cacheComponents: true` configured along with the NEXT_PRIVATE_MINIMAL_MODE=1 environment variable. Strongly consider upgrading to 15.6.0-canary.61 or 16.1.5 to reduce risk and prevent availability issues in Next applications.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 7 hours ago

Bluesky

Profile picture
vercel.com/changelog/summa... Summaries of CVE-2025-59471 and CVE-2025-59472 - Vercel
  • 0
  • 1
  • 0
  • 7h ago

Overview

  • qemu

31 Oct 2025
Published
12 Nov 2025
Updated

CVSS
Pending
EPSS
0.02%

KEV

Description

A stack-based buffer overflow was found in the QEMU e1000 network device. The code for padding short frames was dropped from individual network devices and moved to the net core code. The issue stems from the device's receive code still being able to process a short frame in loopback mode. This could lead to a buffer overrun in the e1000_receive_iov() function via the loopback code path. A malicious guest user could use this vulnerability to crash the QEMU process on the host, resulting in a denial of service.

Statistics

  • 1 Post

Last activity: 22 hours ago

Bluesky

Profile picture
🚨 Critical QEMU patch for SUSE Linux 15 SP7. Fixes CVE-2025-11234 (CVSS 8.7) & CVE-2025-12464. Exploitable via guest VM or network to crash host. Read more: 👉 tinyurl.com/msyfyyyk #SUSE #Security
  • 0
  • 0
  • 0
  • 22h ago

Overview

  • langflow-ai
  • langflow

07 Apr 2025
Published
29 Nov 2025
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
91.42%

Description

Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.

Statistics

  • 1 Post

Last activity: 7 hours ago

Bluesky

Profile picture
The latest update for #Indusface includes "CVE-2026-21858 (Ni8mare): Unauthenticated Remote Code Execution in Self-Hosted n8n" and "CVE-2025-3248: Critical Langflow Unauthenticated Remote Code Execution Vulnerability". #cybersecurity #infosec https://opsmtrs.com/3ySs2VF
  • 0
  • 0
  • 0
  • 7h ago

Overview

  • n8n-io
  • n8n

07 Jan 2026
Published
12 Jan 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
4.30%

KEV

Description

n8n is an open source workflow automation platform. Versions starting with 1.65.0 and below 1.121.0 enable an attacker to access files on the underlying server through execution of certain form-based workflows. A vulnerable workflow could grant access to an unauthenticated remote attacker, resulting in exposure of sensitive information stored on the system and may enable further compromise depending on deployment configuration and workflow usage. This issue is fixed in version 1.121.0.

Statistics

  • 1 Post

Last activity: 7 hours ago

Bluesky

Profile picture
The latest update for #Indusface includes "CVE-2026-21858 (Ni8mare): Unauthenticated Remote Code Execution in Self-Hosted n8n" and "CVE-2025-3248: Critical Langflow Unauthenticated Remote Code Execution Vulnerability". #cybersecurity #infosec https://opsmtrs.com/3ySs2VF
  • 0
  • 0
  • 0
  • 7h ago

Overview

  • qemu

03 Oct 2025
Published
22 Jan 2026
Updated

CVSS
Pending
EPSS
0.24%

KEV

Description

A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSource is leaked. This can lead to the callback firing later on and triggering a use-after-free in the use of the channel. This can be abused by a malicious client with network access to the VNC WebSocket port to cause a denial of service during the WebSocket handshake prior to the VNC client authentication.

Statistics

  • 1 Post

Last activity: 22 hours ago

Bluesky

Profile picture
🚨 Critical QEMU patch for SUSE Linux 15 SP7. Fixes CVE-2025-11234 (CVSS 8.7) & CVE-2025-12464. Exploitable via guest VM or network to crash host. Read more: 👉 tinyurl.com/msyfyyyk #SUSE #Security
  • 0
  • 0
  • 0
  • 22h ago

Overview

  • Artifex
  • Ghostscript

22 Sep 2025
Published
23 Sep 2025
Updated

CVSS v3.1
MEDIUM (4.3)
EPSS
0.01%

KEV

Description

In Artifex Ghostscript through 10.05.1, ocr_begin_page in devices/gdevpdfocr.c has an integer overflow that leads to a heap-based buffer overflow in ocr_line8.

Statistics

  • 1 Post

Last activity: Last hour

Bluesky

Profile picture
🚨 CRITICAL UPDATE: #Fedora 42 Ghostscript security patch released for CVE-2025-59798, CVE-2025-59799, CVE-2025-59800 Read more: 📷 tinyurl.com/mrauu6pk #Security
  • 0
  • 0
  • 0
  • Last hour

Overview

  • Artifex
  • Ghostscript

22 Sep 2025
Published
03 Nov 2025
Updated

CVSS v3.1
MEDIUM (4.3)
EPSS
0.02%

KEV

Description

Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdf_write_cmap in devices/vector/gdevpdtw.c.

Statistics

  • 1 Post

Last activity: Last hour

Bluesky

Profile picture
🚨 CRITICAL UPDATE: #Fedora 42 Ghostscript security patch released for CVE-2025-59798, CVE-2025-59799, CVE-2025-59800 Read more: 📷 tinyurl.com/mrauu6pk #Security
  • 0
  • 0
  • 0
  • Last hour

Overview

  • Artifex
  • Ghostscript

22 Sep 2025
Published
03 Nov 2025
Updated

CVSS v3.1
MEDIUM (4.3)
EPSS
0.01%

KEV

Description

Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdfmark_coerce_dest in devices/vector/gdevpdfm.c via a large size value.

Statistics

  • 1 Post

Last activity: Last hour

Bluesky

Profile picture
🚨 CRITICAL UPDATE: #Fedora 42 Ghostscript security patch released for CVE-2025-59798, CVE-2025-59799, CVE-2025-59800 Read more: 📷 tinyurl.com/mrauu6pk #Security
  • 0
  • 0
  • 0
  • Last hour
Showing 71 to 80 of 83 CVEs