Overview
Description
gRPC-Go is the Go language implementation of gRPC. Prior to 1.82.2 and 1.83.2, servers created with xds.NewGRPCServer() allow internal/transport/http2_server.go to accept an RPC containing neither the :authority header nor the Host header, while RouteAndProcess in internal/xds/server/routing.go assumes that an authority value exists and indexes the empty slice. A remote client that can complete transport connection establishment can trigger an index-out-of-bounds panic that is not recovered by the per-RPC goroutine and terminates the entire server process. In insecure or ordinary TLS deployments the request can be unauthenticated, while strict mTLS or ALTS deployments require valid transport credentials before the malformed RPC can reach the interceptor. This issue is fixed in versions 1.82.2 and 1.83.2.
Statistics
- 8 Posts
Last activity: 19 hours ago
Bluesky
This addresses the following vulnerabilities: CVE-2026-84303 CVE-2026-84304 CVE-2026-84445 N/A Security fixes for apigee-prom-prometheus
This addresses the following vulnerabilities: CVE-2026-81870 CVE-2026-84303 CVE-2026-84304 CVE-2026-84445 N/A Security fixes for apigee-watcher. This addresses the following vulnerabilities: CVE-2026-84303 CVE-2026-84304 CVE-2026-84445
This addresses the following vulnerabilities: CVE-2026-43871 CVE-2026-81870 CVE-2026-81871 CVE-2026-81872 CVE-2026-84303 CVE-2026-84304 CVE-2026-84445 N/A Security fixes for apigee-operators
Overview
- IBM
- DataPower Gateway 10.6CD
08 Oct 2026
Published
08 Oct 2026
Updated
CVSS v3.1
CRITICAL (9.8)
EPSS
Pending
KEV
Description
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write.
Statistics
- 1 Post
Last activity: 8 hours ago
Fediverse
IBM fixes 23 IBM DataPower Gateway vulnerabilities, including critical RCE flaws CVE-2026-15762 and CVE-2026-16340. Upgrade to 11.0.0.3 now.
#IBM #DataPower #APIGateway #CVE202615762 #CVE202616340 #CVE202614990 #RCE #Vulnerability
Overview
Description
This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.
Statistics
- 1 Post
Last activity: 3 hours ago
Overview
Description
gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, the xDS RBAC HTTP filter in internal/xds/httpfilter/rbac/rbac.go does not lowercase header matcher names in normalizeHeaderMatcher even though incoming metadata keys are lowercase. A DENY policy using a mixed-case name such as X-Role or User-Agent therefore does not match and fails open, allowing requests that should be rejected. The same case mismatch permits :Scheme or Grpc-Status to evade gRFC A41 validation and prevents Host from being rewritten to :authority. This issue is fixed in version 1.83.1.
Statistics
- 8 Posts
Last activity: 19 hours ago
Bluesky
This addresses the following vulnerabilities: CVE-2026-84303 CVE-2026-84304 CVE-2026-84445 N/A Security fixes for apigee-prom-prometheus
This addresses the following vulnerabilities: CVE-2026-81870 CVE-2026-84303 CVE-2026-84304 CVE-2026-84445 N/A Security fixes for apigee-watcher. This addresses the following vulnerabilities: CVE-2026-84303 CVE-2026-84304 CVE-2026-84445
This addresses the following vulnerabilities: CVE-2026-43871 CVE-2026-81870 CVE-2026-81871 CVE-2026-81872 CVE-2026-84303 CVE-2026-84304 CVE-2026-84445 N/A Security fixes for apigee-operators
Overview
- Satel
- Satel Netco Design
08 Oct 2026
Published
08 Oct 2026
Updated
CVSS v4.0
HIGH (8.5)
EPSS
Pending
KEV
Description
Satel Netco Design versions prior to v2.1.7 contains a stored cross site scripting vulnerability. An authenticated user with Network Operator privileges could store untrusted content that is rendered without adequate neutralization. Successful exploitation could allow script execution in another user's browser when the affected content is viewed.
Statistics
- 1 Post
Last activity: 3 hours ago
Overview
- The GNU C Library
- glibc
22 Sep 2026
Published
22 Sep 2026
Updated
CVSS v3.1
LOW (3.6)
EPSS
0.13%
KEV
Description
A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.
When such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory.
Statistics
- 1 Post
Last activity: 16 hours ago
Overview
Description
This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.
Statistics
- 1 Post
Last activity: 3 hours ago
Overview
Description
This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.
Statistics
- 1 Post
Last activity: 3 hours ago
Overview
Description
gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, internal/transport/transport.go stores each fragmented HTTP/2 DATA frame as a separate recvMsg in recvBuffer, so millions of one-byte frames can consume disproportionate heap memory even when payload bytes remain within connection and stream flow-control windows. An unauthenticated remote attacker can use concurrent multiplexed streams to exhaust process memory and cause a runtime panic or out-of-memory termination. Receive-buffer compaction is enabled by default and can be controlled temporarily with GRPC_GO_EXPERIMENTAL_ENABLE_RECEIVE_BUFFER_COMPACTION. This issue is fixed in version 1.83.1.
Statistics
- 8 Posts
Last activity: 19 hours ago
Bluesky
This addresses the following vulnerabilities: CVE-2026-84303 CVE-2026-84304 CVE-2026-84445 N/A Security fixes for apigee-prom-prometheus
This addresses the following vulnerabilities: CVE-2026-81870 CVE-2026-84303 CVE-2026-84304 CVE-2026-84445 N/A Security fixes for apigee-watcher. This addresses the following vulnerabilities: CVE-2026-84303 CVE-2026-84304 CVE-2026-84445
This addresses the following vulnerabilities: CVE-2026-43871 CVE-2026-81870 CVE-2026-81871 CVE-2026-81872 CVE-2026-84303 CVE-2026-84304 CVE-2026-84445 N/A Security fixes for apigee-operators
Overview
Description
This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.
Statistics
- 1 Post
Last activity: 3 hours ago