24h | 7d | 30d

Overview

  • undici
  • undici

29 Jul 2026
Published
29 Jul 2026
Updated

CVSS v3.1
MEDIUM (4.8)
EPSS
Pending

KEV

Description

undici's retry interceptor can deliver a response whose body length does not match the Content-Length header exposed to the application after a retry or resume of a partial response. In undici before 6.28.0, from 7.0.0 up to before 7.29.0, and from 8.0.0 up to before 8.9.0, a malicious or faulty upstream can return a partial response with a mismatched framing header, close the socket early, and have the retry interceptor assemble a body of a different length while the original Content-Length stays attached. Applications that use the retry interceptor and forward upstream headers and bodies downstream, such as proxies or gateways, may then emit an invalid HTTP response with a stale Content-Length, leading to downstream response desynchronization, connection hangs, or response corruption. Exploitation requires the retry interceptor enabled, an upstream returning a mismatched partial response, and a downstream forwarder that does not remove or recalculate Content-Length. The issue is fixed in undici 6.28.0, 7.29.0, and 8.9.0.

Statistics

  • 2 Posts

Last activity: 2 hours ago

Fediverse

Profile picture fallback

🚨 Medium-severity security fix in undici@6.28.0, 7.29.0, and 8.9.0 just released!

Patches CVE-2026-16728: downstream response desynchronization via retry interceptor

github.com/nodejs/undici/secur

  • 0
  • 0
  • 1
  • 2h ago

Overview

  • Johnson Control
  • victor

23 Jul 2026
Published
24 Jul 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
0.16%

KEV

Description

Deserialization of untrusted data vulnerability in Johnson Control victor on Windows allows capec-586. This issue affects victor: from 2.9 before 3.0.

Statistics

  • 1 Post

Last activity: 9 hours ago

Fediverse

Profile picture fallback

A C-CURE 9000 vulnerability chain hits CVSS 9.6. CVE-2026-21655 allows remote code execution on Johnson Controls victor application servers.

securityonline.info/c-cure-900

  • 0
  • 0
  • 0
  • 9h ago

Overview

  • IBM
  • Aspera Desktop App

28 Jul 2026
Published
29 Jul 2026
Updated

CVSS v3.1
CRITICAL (9.3)
EPSS
0.45%

KEV

Description

IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination.

Statistics

  • 1 Post

Last activity: 21 hours ago

Fediverse

Profile picture fallback

IBM Aspera vulnerabilities affect Faspex 5 and the Desktop App. CVE-2026-14973 and two RCE flaws rate up to 9.3. Update to Faspex 5.0.16 and Desktop 1.1.0.

securityonline.info/ibm-aspera

  • 0
  • 0
  • 0
  • 21h ago

Overview

  • undici
  • undici

29 Jul 2026
Published
29 Jul 2026
Updated

CVSS v3.1
MEDIUM (4.2)
EPSS
Pending

KEV

Description

undici does not validate the type property of a duck-typed blob-like request body before using it as the Content-Type header on the HTTP/1.1 dispatcher. In undici before 6.28.0, from 7.0.0 up to before 7.29.0, and from 8.0.0 up to before 8.9.0, an application that passes a hand-rolled blob-like body (via request, stream, pipeline, or dispatch) whose type is derived from untrusted input allows an attacker to inject CRLF sequences and append arbitrary HTTP headers, potentially smuggling a second request past the upstream. Native Blob objects are safe because their constructor strips CRLF from the type, and fetch is unaffected because it validates headers, but ecosystem libraries that build duck-typed blob shapes from user input can reach the vulnerable path. This is the same defect class as CVE-2022-35948 and CVE-2026-1527, on a header sink that the earlier fixes did not cover. The issue is fixed in undici 6.28.0, 7.29.0, and 8.9.0.

Statistics

  • 2 Posts

Last activity: 2 hours ago

Fediverse

Profile picture fallback

🚨 Medium-severity security fix in undici@6.28.0, 7.29.0, and 8.9.0 just released!

Patches CVE-2026-15157: CRLF injection via a blob-like body type property

github.com/nodejs/undici/secur

  • 0
  • 0
  • 1
  • 2h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post

Last activity: 8 hours ago

Fediverse

Profile picture fallback

Node.js patched 11 vulnerabilities in its July 2026 release. The high-severity bugs include a HTTP/2 use-after-free (CVE-2026-56848). Update now.

securityonline.info/nodejs-jul

  • 0
  • 0
  • 0
  • 8h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 3 Posts

Last activity: 6 hours ago

Fediverse

Profile picture fallback

Broadcom released updates to fix a critical VMware authentication bypass (CVE-2026-59309). A directory traversal flaw (CVE-2026-59310) was also patched.

securityonline.info/vmware-aut

  • 0
  • 0
  • 0
  • 13h ago
Profile picture fallback

Broadcom patched a critical VMware vCenter vulnerability. CVE-2026-59309 and CVE-2026-59310 both score 9.8 CVSS and allow auth bypass or code execution.

meterpreter.org/vmware-vcenter

  • 0
  • 0
  • 0
  • 11h ago
Profile picture fallback

📰 VMware Patches Critical VM Escape Flaw (CVE-2026-47876) in ESXi

Broadcom patches critical VMware flaws, including a VM escape in ESXi (CVE-2026-47876) and unauthenticated RCE in vCenter (CVE-2026-59309, CVE-2026-59310). CVSS scores up to 9.8. Immediate patching is crucial. #VMware #CyberSecurity #PatchTuesday

🌐 cyber[.]netsecops[.]io

🔗 cyber.netsecops.io/articles/vm

  • 0
  • 0
  • 0
  • 6h ago

Overview

  • F5
  • NGINX Plus

15 Jul 2026
Published
29 Jul 2026
Updated

CVSS v3.1
HIGH (8.1)
EPSS
3.60%

KEV

Description

A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Impact: This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or to possibly trigger a code execution. There is no control plane exposure; this is a data plane issue only.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Statistics

  • 1 Post

Last activity: 12 hours ago

Fediverse

Profile picture fallback

En las últimas 24 horas, expertos revelan nuevas amenazas en criptografía impulsadas por IA, vulnerabilidades críticas en Check Point, OpenWrt y NGINX que permiten ejecuciones remotas, una masiva filtración que compromete la privacidad en VPNs y recomendaciones clave de EE.UU. y Australia para proteger infraestructuras críticas. Descubre estos y más detalles en el siguiente listado de noticias sobre seguridad informática:

🗞️ ÚLTIMAS NOTICIAS EN SEGURIDAD INFORMÁTICA 🔒
====| 🔥 LO QUE DEBES SABER HOY 29/07/26 📆 |====

🔐 ANÁLISIS DE CRIPTOANÁLISIS CON MODELOS DE LENGUAJE

Investigadores de Anthropic, utilizando la vista previa de Claude Mythos, han descubierto nuevas técnicas para atacar algoritmos criptográficos. Este avance revela cómo los potentes modelos de inteligencia artificial pueden identificar vulnerabilidades en la criptografía tradicional, planteando importantes desafíos para la seguridad futura y la necesidad de fortalecer los sistemas criptográficos ante estas nuevas amenazas. Profundiza en este análisis y sus implicaciones para proteger tus datos en la era digital visitando esta fuente clave 👉 djar.co/jewM

🚨 ANÁLISIS TÉCNICO DE VULNERABILIDAD EN CHECK POINT SMARTCONSOLE (CVE-2026-16232)

Se ha identificado una vulnerabilidad crítica de bypass de autenticación en el proceso de inicio de sesión de SmartConsole, que afecta a los servidores de gestión de seguridad de Check Point. Esta falla permite que atacantes eludan mecanismos de seguridad y comprometan el control de los sistemas afectados. Conocer en detalle esta vulnerabilidad y sus mitigaciones es esencial para administradores y profesionales de seguridad. Descubre el análisis detallado aquí 👉 djar.co/huOngt

⚠️ FALLO CRÍTICO EN OPENWRT DHCPV6 PERMITE EJECUCIÓN DE CÓDIGO REMOTO

La versión 24.10.8 de OpenWrt corrige una falla grave (CVE-2026-53921) en el servicio odhcpd, causada por solicitudes DHCPv6 manipuladas que provocan un desbordamiento de pila. Esta vulnerabilidad podría permitir que atacantes no autenticados ejecuten código con privilegios de root, poniendo en riesgo la integridad de dispositivos y redes basadas en OpenWrt. Actualiza tu sistema y conoce cómo proteger tu infraestructura accediendo a los detalles aquí 👉 djar.co/HXTzQ

🔥 VULNERABILIDAD CRÍTICA EN NGINX PUEDE CAUSAR CAÍDAS Y EJECUCIÓN REMOTA DE CÓDIGO

F5 ha publicado un parche para CVE-2026-42533, un error de desbordamiento en el heap del módulo regex map de NGINX. Esta vulnerabilidad puede provocar la caída de procesos esenciales y, bajo ciertas configuraciones, permitir la ejecución remota de código malicioso, afectando la disponibilidad y seguridad de los servidores web. Aprende cómo detectar, mitigar y actualizar tu entorno para evitar incidentes graves consultando la información completa aquí 👉 djar.co/lxu8x

🔍 FILTRACIÓN MASIVA EN VPN PONE EN DUDA SUS RECLAMOS DE PRIVACIDAD

Una conocida VPN, que aseguraba no almacenar registros, ha expuesto 58 millones de logs de conexión junto con datos sensibles de usuarios, dispositivos y pagos. Esta brecha contradice directamente sus políticas de privacidad, poniendo en riesgo la seguridad y anonimato de millones de usuarios. Conoce los detalles de esta filtración y cómo proteger tu privacidad digital aquí 👉 djar.co/LZurv

🛡️ CISA Y SOC DELGADOS DE AUS EMITEN RECOMENDACIONES PARA AISLAR SISTEMAS VITALES EN CIBERATAQUES

Las agencias de seguridad cibernética de EE. UU. y Australia han publicado guías para que las organizaciones que gestionan infraestructuras críticas puedan aislar sistemas tecnológicos esenciales durante ataques cibernéticos, minimizando daños y garantizando la continuidad operativa. Este consejo es vital para proteger sectores estratégicos frente a amenazas persistentes. Consulta las mejores prácticas para blindar tus sistemas aquí 👉 djar.co/HPgGvv

👨‍💻 ARCANUM SECURITY: CAPACITACIÓN Y CONSULTORÍA DE VANGUARDIA EN CIBERSEGURIDAD

La firma liderada por Jason Haddix ofrece soluciones modernas en seguridad informática mediante capacitación especializada y consultoría estratégica. Su enfoque innovador ayuda a organizaciones a anticipar y neutralizar amenazas, fortaleciendo su postura de ciberseguridad. Explora sus servicios y cómo pueden ayudarte a proteger tu empresa visitando su sitio oficial 👉 djar.co/Em1CSB

  • 0
  • 0
  • 0
  • 12h ago
Showing 51 to 57 of 57 CVEs