Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    USN-8746-1
    Fix available
    Packages

    libebml, libebml, libebml, libebml

    Summary

    libebml vulnerability

    Published
    10 Sept 2026
    CVE-2026-88014
    Fix available
    Packages

    Summary

    rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace

    Published
    10 Sept 2026
    ECHO-697c-1fee-1fce
    Fix available
    Packages

    org.springframework.security:spring-security-core

    Summary

    Published
    10 Sept 2026
    CGA-qp39-2g5g-qr7m
    Fix available
    Packages

    consul-k8s-1.6-cli

    Summary

    Published
    10 Sept 2026
    CVE-2026-88959
    Fix available
    Packages

    Summary

    Anchor CMS through 0.12.7 Privilege Escalation via Missing Authorization on Admin User-Management Endpoints

    Published
    10 Sept 2026
    CVE-2026-87912
    Fix available
    Packages

    Summary

    Missing S3 bucket ownership verification in the AWS Security Agent plugin for aws-agents-for-devsecops

    Published
    10 Sept 2026
    CVE-2026-88013
    Fix available
    Packages

    Summary

    rclone: http backend forwards custom/auth headers to a different host on redirect

    Published
    10 Sept 2026
    USN-8745-1
    Fix available
    Packages

    kissfft, kissfft, kissfft

    Summary

    kissfft vulnerabilities

    Published
    10 Sept 2026
    CGA-j9m2-5gr2-6fvr
    Fix available
    Packages

    telegraf-1.40

    Summary

    Published
    10 Sept 2026
    CGA-4fcf-x8qc-v8x6
    No fix available
    Packages

    telegraf-1.40

    Summary

    Published
    10 Sept 2026
    CVE-2026-88012
    Fix available
    Packages

    Summary

    Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded

    Published
    10 Sept 2026
    USN-8748-1
    Fix available
    Packages

    linux-nvidia-6.17

    Summary

    linux-nvidia-6.17 vulnerabilities

    Published
    10 Sept 2026
    CVE-2026-88011
    Fix available
    Packages

    Summary

    Traefik: ForwardAuth identity spoofing via dot-form header alias

    Published
    10 Sept 2026
    CVE-2026-88940
    Fix available
    Packages

    Summary

    knowns through 0.33.0 Arbitrary Directory Enumeration via workspace browse endpoint

    Published
    10 Sept 2026
    CVE-2026-88939
    Fix available
    Packages

    Summary

    knowns through 0.33.0 Authorization Bypass via project.set Bootstrap Exemption

    Published
    10 Sept 2026
    CVE-2026-88938
    Fix available
    Packages

    Summary

    knowns through 0.33.0 Path Traversal via code.find MCP tool

    Published
    10 Sept 2026
    CVE-2026-88937
    Fix available
    Packages

    Summary

    knowns through 0.33.0 Path Traversal via Template Engine

    Published
    10 Sept 2026
    CVE-2026-88899
    Fix available
    Packages

    Summary

    knowns before 0.31.0 External Control of Agent Working Directory via x-opencode-directory Header

    Published
    10 Sept 2026
    DEBIAN-CVE-2026-88924
    No fix available
    Packages

    gvfs, gvfs, gvfs

    Summary

    Published
    10 Sept 2026
    Packages

    suricata, suricata

    Summary

    Published
    10 Sept 2026
    Packages

    suricata, suricata

    Summary

    Published
    10 Sept 2026
    CGA-hp5j-5vg6-h48m
    Fix available
    Packages

    cilium-fips-1.19-operator-generic

    Summary

    Published
    10 Sept 2026
    GHSA-34ff-336r-5q23
    Fix available
    Packages

    n8n, n8n, n8n

    Summary

    n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Node

    Published
    10 Sept 2026
    GHSA-j535-v25q-vx3q
    Fix available
    Packages

    n8n, n8n, n8n

    Summary

    n8n: Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a Git Node Clone Path

    Published
    10 Sept 2026
    GHSA-hh89-3r9w-qj3j
    Fix available
    Packages

    n8n, n8n

    Summary

    n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint

    Published
    10 Sept 2026
    GHSA-hw8v-xxg5-vvvx
    Fix available
    Packages

    n8n, n8n, n8n

    Summary

    n8n: Expression Sandbox Escape via Class-Field Sanitizer Rebinding Can Lead to Code Execution

    Published
    10 Sept 2026
    GHSA-pcvc-8vrv-8q6w
    Fix available
    Packages

    open-webui

    Summary

    Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends

    Published
    10 Sept 2026
    GHSA-fmqh-xp37-5hr8
    Fix available
    Packages

    open-webui

    Summary

    Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint

    Published
    10 Sept 2026
    GHSA-jmc6-2wr8-h3wj
    Fix available
    Packages

    open-webui

    Summary

    Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin

    Published
    10 Sept 2026
    GHSA-4v28-j6q3-5m4r
    Fix available
    Packages

    open-webui

    Summary

    Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader

    Published
    10 Sept 2026
    GHSA-3pf7-q2g3-wj28
    Fix available
    Packages

    open-webui

    Summary

    Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions

    Published
    10 Sept 2026
    Packages

    ua-parser-js, @rootio/ua-parser-js

    Summary

    CVE-2022-25927 in ua-parser-js - Patched by Root

    Published
    10 Sept 2026
    GHSA-2724-6cpj-gf3v
    Fix available
    Packages

    open-webui

    Summary

    Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion

    Published
    10 Sept 2026
    GHSA-34r3-9m95-vq73
    Fix available
    Packages

    open-webui

    Summary

    Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch

    Published
    10 Sept 2026
    GHSA-4qg5-cxx4-g927
    Fix available
    Packages

    open-webui

    Summary

    Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange

    Published
    10 Sept 2026
    GHSA-q5j5-6p94-4gwc
    Fix available
    Packages

    github.com/xuri/excelize/v2, github.com/xuri/excelize

    Summary

    Excelize: Streaming GetRows row-bound bypass causes attacker-controlled allocation

    Published
    10 Sept 2026
    GHSA-fx5j-qcqg-grpf
    Fix available
    Packages

    github.com/xuri/excelize/v2, github.com/xuri/excelize

    Summary

    Excelize: Negative shared-string index causes panic in GetCellValue and GetRows

    Published
    10 Sept 2026
    Packages

    @koa/cors, koajs_cors

    Summary

    TuxCare security update for 2 packages (2 CVEs)

    Published
    10 Sept 2026
    CGA-w5pp-5qqr-m742
    Fix available
    Packages

    cilium-fips-1.19-operator-aws

    Summary

    Published
    10 Sept 2026
    GHSA-x7m8-jrm8-hpvx
    Fix available
    Packages

    @eigenpal/docx-editor-core, @eigenpal/docx-editor-react

    Summary

    @eigenpal/docx-editor-react: CSS injection and print-time XSS via unescaped embedded font-family name

    Published
    10 Sept 2026
    CGA-hv4q-qwpm-rppr
    Fix available
    Packages

    telegraf-1.40

    Summary

    Published
    10 Sept 2026
    CGA-4m9c-2rx8-9jqr
    No fix available
    Packages

    telegraf-1.40

    Summary

    Published
    10 Sept 2026
    CVE-2026-88009
    Fix available
    Packages

    Summary

    Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing path-scoped routing, middleware guards and access logging

    Published
    10 Sept 2026
    CGA-pw3f-g2hr-33xf
    Fix available
    Packages

    cilium-fips-1.19

    Summary

    Published
    10 Sept 2026
    CGA-722c-wc2m-jh7r
    Fix available
    Packages

    cilium-fips-1.19

    Summary

    Published
    10 Sept 2026
    Packages

    nodemailer

    Summary

    TuxCare security update for nodemailer (6 CVEs)

    Published
    10 Sept 2026
    CVE-2026-88008
    Fix available
    Packages

    Summary

    Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization

    Published
    10 Sept 2026
    CGA-95f2-2vj3-6fr3
    Fix available
    Packages

    cilium-fips-1.19-operator-azure

    Summary

    Published
    10 Sept 2026
    CGA-mhvm-fxf7-4wqr
    No fix available
    Packages

    langfuse-fips-3-worker

    Summary

    Published
    10 Sept 2026
    CGA-r6cf-xmqr-3gxw
    No fix available
    Packages

    langfuse-fips-3-worker

    Summary

    Published
    10 Sept 2026