Overview
Description
Statistics
- 2 Posts
Overview
- Cap-go
- capgo
Description
Statistics
- 1 Post
Fediverse
CVE-2026-56073 (CRITICAL) affects Cap-go capgo <12.128.2: Insufficient data authenticity checks allow OTP bypass, enabling attackers to activate 2FA & take over accounts. No patch yet — monitor vendor updates. https://radar.offseq.com/threat/cve-2026-56073-insufficient-verification-of-data-a-d7403d6896f5b084 #OffSeq #CVE #Infosec #AppSec
Overview
Description
Statistics
- 1 Post
Overview
- golang.org/x/net
- golang.org/x/net/http2
- golang.org/x/net/http2
Description
Statistics
- 1 Post
Overview
Description
Statistics
- 1 Post
Overview
Description
Statistics
- 1 Post
Overview
Description
Statistics
- 1 Post
Fediverse
Node.js released 22.23.0, 24.17.0 and 26.3.1 on June 18, closing 13 CVEs. Two are HIGH severity: CVE-2026-48933, a WebCrypto AES integer overflow that triggers a remote process abort, and CVE-2026-48618, a TLS check where a Unicode dot separator defeats wildcard-depth validation and bypasses authentication. The releases also bundle llhttp 9.4.2, nghttp2 1.69.0 and openssl 3.5.7. How long does a Node patch take to reach your production fleet?