CVE Feed

    Dashboard / CVE

    6
    Medium

    CVE-2026-79780

    Last Modified: 25 Aug 2026

    rclone before v1.75.0 fails to sanitize IBM IAM bearer tokens and SSE-C encryption keys during S3 redirect callbacks, allowing credentials to be preserved across scheme or host changes. Attackers observing network traffic from a trusted endpoint can capture reusable IBM IAM tokens on same-host HTTPS-to-HTTP downgrades or SSE-C keys on cross-origin redirects to access protected S3 objects.

    Published: 25 Aug 2026
    6
    Medium

    CVE-2026-79778

    Last Modified: 25 Aug 2026

    rclone before v1.75.0 contains a denial of service vulnerability in the WebDAV TUS creation handler that dereferences a nil response before checking for transport errors. A malicious or compromised configured endpoint can reset connections during TUS uploads to trigger a panic that terminates unrecovered goroutines and halts unrelated work in long-lived processes.

    Published: 25 Aug 2026
    5.1
    Medium

    CVE-2026-79777

    Last Modified: 28 Aug 2026

    rclone before v1.75.0 includes full Go stack traces in RC API error responses when panics occur. Attackers can trigger panics to leak internal file paths, module versions, goroutine states, and memory addresses.

    Published: 25 Aug 2026
    6.9
    Medium

    CVE-2026-79776

    Last Modified: 25 Aug 2026

    rclone before 1.75.0 mounts the pprof debug handler as its own router route, bypassing the fail-closed authentication rule in the main handler. Attackers can access the /debug/pprof/cmdline endpoint unauthenticated to retrieve the full process argv including backend credentials.

    Published: 25 Aug 2026
    7.1
    High

    CVE-2026-79775

    Last Modified: 29 Aug 2026

    rclone versions >= v1.72.0 and <= v1.74.4 (fixed in v1.75.0) contain multiple denial-of-service vulnerabilities in the archive backend's SquashFS parser, which relies on the github.com/diskfs/go-diskfs dependency. The parser fails to validate attacker-controlled superblock and metadata values before use. An attacker who can place or modify a SquashFS image in storage exposed through an rclone :archive: remote can craft a malicious image that triggers an integer division-by-zero panic (zero block size), an out-of-bounds slice panic (out-of-range inode metadata offset), or a non-progress CPU loop (truncated metadata stream). Variants 1 and 2 terminate the rclone process and, via 'rclone serve sftp', can crash the entire SFTP server; variant 3 causes sustained CPU consumption. Parsing is lazy, so a victim or remote client must address or descend into the malicious archive object to trigger it.

    Published: 25 Aug 2026
    9.3
    Critical

    CVE-2026-79774

    Last Modified: 26 Aug 2026

    Winter CMS versions before 1.2.13 contain an incomplete fix for a Twig sandbox escape vulnerability in System\\Twig\\SecurityPolicy that allows authenticated backend users with template-editing permissions to bypass sandbox restrictions. Attackers can exploit method forwarding through Eloquent models and query builders using methods like saveQuietly(), deleteQuietly(), increment(), decrement(), and newQuery() to read and modify arbitrary database records, execute arbitrary SQL, and achieve remote code execution by injecting PHP into template code sections.

    Published: 25 Aug 2026
    6.9
    Medium

    CVE-2026-79773

    Last Modified: 28 Aug 2026

    Winter CMS before 1.2.13 contains a local file inclusion vulnerability in the JavascriptImporter filter that allows authenticated users with cms.manage_assets permission to disclose arbitrary server-readable files by placing =include or =require directives in theme JavaScript assets. Attackers can reference files like .env outside the theme directory, and the combined output served through the combine route becomes readable by unauthenticated visitors, exposing application keys and database credentials.

    Published: 25 Aug 2026
    6.9
    Medium

    CVE-2026-79772

    Last Modified: 1 Sept 2026

    Nokogiri versions before 1.19.1 fail to check the return value from xmlC14NExecute in the canonicalize method, returning an empty string on failure instead of raising an exception. Attackers can exploit this to bypass signature validation in downstream SAML libraries by providing invalid canonicalized XML that is incorrectly accepted as valid.

    Published: 25 Aug 2026
    8.7
    High

    CVE-2026-79770

    Last Modified: 1 Sept 2026

    Nokogiri versions before 1.19.3 contain regular expression denial of service vulnerabilities in the CSS selector tokenizer affecting string-literal and identifier tokenization. Attackers can inject adversarial CSS selectors into methods like Node#css, Node#at_css, and Searchable#search to cause exponential regex backtracking and denial of service.

    Published: 25 Aug 2026
    6.9
    Medium

    CVE-2026-79771

    Last Modified: 1 Sept 2026

    Nokogiri versions before 1.19.3 contain a memory leak in the XSLT Stylesheet transform method when processing Ruby strings containing null bytes. Attackers can exploit this by passing attacker-controlled input with null bytes to transform parameters, causing heap allocations to leak and enabling denial of service against long-running processes.

    Published: 25 Aug 2026
    8.7
    High

    CVE-2026-79769

    Last Modified: 26 Aug 2026

    Nokogiri versions before 1.19.4 contain a possible invalid (out-of-bounds) memory read in the protected internal Node#initialize_copy_with_args helper behind Node#dup and #clone, which unwrapped its source argument as an xmlNode without a type check. If application code calls this protected method with a non-Node argument (e.g., a Namespace), it reads an xmlNs out of bounds, crashing the process. This is only triggerable by a programming error and cannot be triggered by untrusted input or normal use of the public API. Only CRuby is affected. Version 1.19.4 adds a type check and raises TypeError.

    Published: 25 Aug 2026
    8.2
    High

    CVE-2026-79676

    Last Modified: 25 Aug 2026

    NLTK versions before 3.10.3 contain a path traversal vulnerability in corpus readers that reopen root-derived paths using built-in open() instead of nltk.pathsec.open(), allowing symlinks to escape trusted roots. Attackers who stage symlinked corpus files under a trusted data root can disclose outside-root content through normal corpus reader methods like channels(), domains(), and synonyms().

    Published: 25 Aug 2026
    8.8
    High

    CVE-2026-79674

    Last Modified: 25 Aug 2026

    NLTK versions before 3.10.3 contain a path sandbox bypass vulnerability in corpus-reader constructors that allows attackers to read files outside the intended data root. Attackers can supply arbitrary corpus root paths to LinThesaurusCorpusReader and PanLexLiteCorpusReader constructors to access filesystem content and SQLite databases outside the pathsec sandbox boundary.

    Published: 25 Aug 2026
    9.3
    Critical

    CVE-2026-79675

    Last Modified: 1 Sept 2026

    NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, allowing attackers to inject dangerous JVM flags. Attackers can supply malicious options like -agentpath, -javaagent, or @argfile to Stanford wrapper classes to achieve arbitrary code execution.

    Published: 25 Aug 2026
    Unknown

    CVE-2025-71407

    Last Modified: 1 Sept 2026

    This CVE ID has been rejected as a duplicate.

    Published: 25 Aug 2026
    7.8
    High

    CVE-2025-71406

    Last Modified: 1 Sept 2026

    This CVE ID has been rejected as a duplicate.

    Published: 25 Aug 2026
    Unknown

    CVE-2024-58378

    Last Modified: 1 Sept 2026

    This CVE ID has been rejected as a duplicate.

    Published: 25 Aug 2026
    2.9
    Low

    CVE-2025-71346

    Last Modified: 1 Sept 2026

    This CVE ID has been rejected as a duplicate.

    Published: 25 Aug 2026
    Unknown

    CVE-2024-58377

    Last Modified: 1 Sept 2026

    This CVE ID has been rejected as a duplicate.

    Published: 25 Aug 2026
    7.5
    High

    CVE-2023-54354

    Last Modified: 8 Sept 2026

    This CVE ID has been rejected as a duplicate.

    Published: 25 Aug 2026
    8.8
    High

    CVE-2022-51000

    Last Modified: 8 Sept 2026

    This CVE ID has been rejected as a duplicate.

    Published: 25 Aug 2026
    8.6
    High

    CVE-2022-50999

    Last Modified: 8 Sept 2026

    This CVE ID has been rejected as a duplicate.

    Published: 25 Aug 2026
    7.5
    High

    CVE-2022-50998

    Last Modified: 8 Sept 2026

    This CVE ID has been rejected as a duplicate.

    Published: 25 Aug 2026
    7.5
    High

    CVE-2021-47996

    Last Modified: 8 Sept 2026

    This CVE ID has been rejected as a duplicate.

    Published: 25 Aug 2026
    8.2
    High

    CVE-2026-55533

    Last Modified: 25 Aug 2026

    PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, create_auth_middleware() allows requests when auth=api-key lacks PRAISONAI_API_KEY or JWT authentication lacks PRAISONAI_JWT_SECRET. An externally bound Recipe server can therefore accept unauthenticated POST /v1/recipes/run requests despite authentication being enabled. This issue is fixed in version 4.6.58.

    Published: 25 Aug 2026
    8.6
    High

    CVE-2026-55539

    Last Modified: 25 Aug 2026

    PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, the Jobs API create_app function mounts /api/v1/runs without authentication. Any reachable caller can submit jobs, read results, cancel runs, or delete jobs using operator credentials. The fix adds PRAISONAI_JOBS_API_KEY middleware for Authorization or X-API-Key. This issue is fixed in version 4.6.58.

    Published: 25 Aug 2026
    7.6
    High

    CVE-2026-69104

    Last Modified: 25 Aug 2026

    An authenticated user may initiate repository migration operations without required repository permissions, potentially causing information disclosure, unauthorized state changes, and service disruption. Fixed versions address the issue.

    Published: 25 Aug 2026
    7.1
    High

    CVE-2026-55527

    Last Modified: 25 Aug 2026

    PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the FileMemory constructor joins unsanitized user_id into self.user_path. A caller supplying ../ or path separators can escape the memory directory and write JSON data to arbitrary process-writable locations. The fix sanitizes user_id before constructing self.user_path. This issue is fixed in version 1.6.58.

    Published: 25 Aug 2026
    2.1
    Low

    CVE-2026-15310

    Last Modified: 11 Sept 2026

    When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions, Python could use an attacker-controlled size to pre-allocate memory, possibly resulting in memory exhaustion.

    Published: 25 Aug 2026
    8.5
    High

    CVE-2026-70551

    Last Modified: 26 Aug 2026

    A user who can read an existing remote VCS repository can replace its configured origin or supply an absolute VCS data URL.

    Published: 25 Aug 2026
    8.8
    High

    CVE-2026-55541

    Last Modified: 25 Aug 2026

    PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, praisonai serve agents and praisonai serve unified parse --api-key but _create_agents_app() and _create_unified_app() do not install a credential check. Unauthenticated callers can reach POST /agents and POST /api/v1/agents/{id}/invoke. This issue is fixed in version 4.6.58.

    Published: 25 Aug 2026
    6.8
    Medium

    CVE-2026-55535

    Last Modified: 25 Aug 2026

    PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the Jobs API validate_webhook_url() path fails open on socket.gaierror and does not bind the validated address to the later request. An attacker webhook_url can later resolve to 127.0.0.1, 169.254.169.254, or another internal address. This issue is fixed in version 4.6.58.

    Published: 25 Aug 2026
    7.1
    High

    CVE-2026-2035366

    Last Modified: 25 Aug 2026

    A flaw was found in OpenStack Keystone where an application credential token can escape its intended project scope through token-method reauthentication. Keystone rejects an explicit scope change for an application credential token, but an omitted scope falls through to the owner's default project. If the owner has roles on that default project, Keystone issues a new token scoped there while still carrying the original application credential identity. Custom Keystone authentication plugins are subject to the same incomplete rescope guard. This allows a limited-scope application credential for one project to access another project within the owner's role assignments.

    Published: 25 Aug 2026
    8.1
    High

    CVE-2026-2035364

    Last Modified: 26 Aug 2026

    A flaw was found in OpenStack Keystone where delegation boundary enforcement is incomplete across trust, application credential, and OAuth1 authorization endpoints. Tokens obtained via delegated authentication methods, such as OAuth1 access tokens or custom Keystone authentication plugins, can perform operations beyond their intended scope because endpoint guards only recognized specific delegation types rather than using a comprehensive allowlist. This allows creating trusts that delegate roles beyond the token's authorized scope, creating persistent application credentials, and authorizing new OAuth1 delegations. These derived credentials persist independently and survive revocation of the original credential, enabling an attacker with a compromised narrow-scope credential to escalate to the user's full privileges and maintain persistent access.

    Published: 25 Aug 2026
    7.6
    High

    CVE-2026-80184

    Last Modified: 26 Aug 2026

    In OpenStack Keystone before 29.0.3, tokens obtained via delegated authentication mechanisms (OAuth1 access tokens, application credentials, trusts) could be submitted to the token-method authentication path for reauthentication to escape their intended project scope. When an application credential token was presented with no explicit scope, Keystone would issue a new token scoped to the credential owner's default project rather than the project for which the credential was issued, bypassing the intended project boundary. All Keystone deployments that permit delegated authentication through OAuth1 access tokens, application credentials, or trusts are affected.

    Published: 25 Aug 2026
    7.6
    High

    CVE-2026-80182

    Last Modified: 26 Aug 2026

    In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token, application credential, or trust-scoped authentication could create new long-lived credentials or authorize new delegations that persist independently of, and outlive, the credential used to obtain them. The delegation restrictions that block these operations did not consistently apply to all delegated token types, allowing an OAuth1-scoped token, for example, to create application credentials or authorize OAuth1 request tokens despite those operations being restricted for other delegated token types. All Keystone deployments that permit delegated authentication through OAuth1 access tokens, application credentials, or trusts are affected.

    Published: 25 Aug 2026
    7.1
    High

    CVE-2026-55537

    Last Modified: 25 Aug 2026

    PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, JobSubmitRequest.validate_webhook_url() accepts webhook_url when resolution raises socket.gaierror because the exception path uses except socket.gaierror: pass. JobExecutor._send_webhook() later performs a fresh lookup, allowing DNS changes to direct the request to an internal service. This issue is fixed in version 4.6.58.

    Published: 25 Aug 2026
    7.3
    High

    CVE-2026-55538

    Last Modified: 25 Aug 2026

    PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, praisonai serve agents parses config["api_key"] but _create_agents_app() does not authenticate POST /agents or POST /agents/{agent_name}. Missing or incorrect bearer and X-API-Key values still reach agent execution. This issue is fixed in version 4.6.58.

    Published: 25 Aug 2026
    5.3
    Medium

    CVE-2026-55624

    Last Modified: 28 Aug 2026

    MintyItanium Lost-Auction is an auction plugin for Minecraft. Prior to commit 88c920b05042929db334ba06d57f052b42d6b3f8, players can take items like barrier blocks or duplicate items from the GUI. Commit 88c920b05042929db334ba06d57f052b42d6b3f8 fixes the issue.

    Published: 25 Aug 2026
    7.1
    High

    CVE-2026-55540

    Last Modified: 27 Aug 2026

    PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, is_path_within_directory() uses os.path.abspath() rather than os.path.realpath() for the workspace boundary. A symlink inside workspace can point outside and still pass the check, allowing read_file and other code tools to access files outside the configured workspace. This issue is fixed in version 4.6.58.

    Published: 25 Aug 2026
    6.1
    Medium

    CVE-2026-55530

    Last Modified: 25 Aug 2026

    PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, ast_grep_rewrite lacks the @require_approval decorator used by sibling mutation tools. With dry_run=False, an agent-controlled call can pass --update-all and a broad path to rewrite matching files without the expected authorization gate. This issue is fixed in version 1.6.58.

    Published: 25 Aug 2026
    8.6
    High

    CVE-2026-55534

    Last Modified: 27 Aug 2026

    PraisonAI is a multi-agent teams system. From praisonai 4.6.34 until 4.6.58, praisonai serve agents accepts --api-key but _create_agents_app() does not authenticate POST /agents or POST /agents/{agent_name}. A network caller can invoke configured agents without credentials even when an API key was supplied. This issue is fixed in version 4.6.58.

    Published: 25 Aug 2026
    8.5
    High

    CVE-2026-55526

    Last Modified: 25 Aug 2026

    PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, spider_tools._host_is_blocked() does not resolve ordinary hostnames before scrape_page fetches them. A hostname such as 127.0.0.1.nip.io passes validation and resolves to loopback, permitting internal HTTP access. The fix uses socket.getaddrinfo and fails closed on DNS errors. This issue is fixed in version 1.6.58.

    Published: 25 Aug 2026
    6.5
    Medium

    CVE-2026-55531

    Last Modified: 25 Aug 2026

    PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the MCP HTTP Stream mcp_post handler creates a new _sessions entry for every initialize request but does not call _cleanup_sessions or enforce a maximum. An unauthenticated caller can exhaust memory. The fix invokes cleanup and limits sessions through PRAISONAI_MCP_MAX_SESSIONS. This issue is fixed in version 4.6.58.

    Published: 25 Aug 2026
    8.2
    High

    CVE-2026-55528

    Last Modified: 25 Aug 2026

    PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, AgentServer exposes ServerConfig.auth_token but AgentServer._create_app does not check it on any route. A remote caller can subscribe, publish, and perform other actions without a valid bearer token or X-Auth-Token even when authentication is configured. This issue is fixed in version 1.6.58.

    Published: 25 Aug 2026
    Unknown

    CVE-2021-48005

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected.

    Published: 25 Aug 2026
    Unknown

    CVE-2021-48004

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected.

    Published: 25 Aug 2026
    Unknown

    CVE-2021-48003

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected.

    Published: 25 Aug 2026
    Unknown

    CVE-2021-48002

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected.

    Published: 25 Aug 2026
    Unknown

    CVE-2021-48001

    Last Modified: 27 Aug 2026

    This CVE ID has been rejected.

    Published: 25 Aug 2026