Open Source Vulnerabilities
libebml, libebml, libebml, libebml
libebml vulnerability
rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace
rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace
org.springframework.security:spring-security-core
Anchor CMS through 0.12.7 Privilege Escalation via Missing Authorization on Admin User-Management Endpoints
Anchor CMS through 0.12.7 Privilege Escalation via Missing Authorization on Admin User-Management Endpoints
Missing S3 bucket ownership verification in the AWS Security Agent plugin for aws-agents-for-devsecops
Missing S3 bucket ownership verification in the AWS Security Agent plugin for aws-agents-for-devsecops
rclone: http backend forwards custom/auth headers to a different host on redirect
rclone: http backend forwards custom/auth headers to a different host on redirect
kissfft, kissfft, kissfft
kissfft vulnerabilities
Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded
Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded
linux-nvidia-6.17
linux-nvidia-6.17 vulnerabilities
Traefik: ForwardAuth identity spoofing via dot-form header alias
Traefik: ForwardAuth identity spoofing via dot-form header alias
knowns through 0.33.0 Arbitrary Directory Enumeration via workspace browse endpoint
knowns through 0.33.0 Arbitrary Directory Enumeration via workspace browse endpoint
knowns through 0.33.0 Authorization Bypass via project.set Bootstrap Exemption
knowns through 0.33.0 Authorization Bypass via project.set Bootstrap Exemption
knowns through 0.33.0 Path Traversal via code.find MCP tool
knowns through 0.33.0 Path Traversal via Template Engine
knowns before 0.31.0 External Control of Agent Working Directory via x-opencode-directory Header
knowns before 0.31.0 External Control of Agent Working Directory via x-opencode-directory Header
cilium-fips-1.19-operator-generic
n8n, n8n, n8n
n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Node
n8n/ n8n/ n8n
n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Node
n8n, n8n, n8n
n8n: Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a Git Node Clone Path
n8n/ n8n/ n8n
n8n: Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a Git Node Clone Path
n8n, n8n
n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint
n8n/ n8n
n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint
n8n, n8n, n8n
n8n: Expression Sandbox Escape via Class-Field Sanitizer Rebinding Can Lead to Code Execution
n8n/ n8n/ n8n
n8n: Expression Sandbox Escape via Class-Field Sanitizer Rebinding Can Lead to Code Execution
open-webui
Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends
open-webui
Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends
open-webui
Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint
open-webui
Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint
open-webui
Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin
open-webui
Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin
open-webui
Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader
open-webui
Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader
open-webui
Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions
open-webui
Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions
ua-parser-js, @rootio/ua-parser-js
CVE-2022-25927 in ua-parser-js - Patched by Root
ua-parser-js/ @rootio/ua-parser-js
CVE-2022-25927 in ua-parser-js - Patched by Root
open-webui
Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion
open-webui
Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion
open-webui
Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch
open-webui
Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch
open-webui
Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange
open-webui
Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange
github.com/xuri/excelize/v2, github.com/xuri/excelize
Excelize: Streaming GetRows row-bound bypass causes attacker-controlled allocation
github.com/xuri/excelize/v2/ github.com/xuri/excelize
Excelize: Streaming GetRows row-bound bypass causes attacker-controlled allocation
github.com/xuri/excelize/v2, github.com/xuri/excelize
Excelize: Negative shared-string index causes panic in GetCellValue and GetRows
github.com/xuri/excelize/v2/ github.com/xuri/excelize
Excelize: Negative shared-string index causes panic in GetCellValue and GetRows
@koa/cors, koajs_cors
TuxCare security update for 2 packages (2 CVEs)
@koa/cors/ koajs_cors
TuxCare security update for 2 packages (2 CVEs)
@eigenpal/docx-editor-core, @eigenpal/docx-editor-react
@eigenpal/docx-editor-react: CSS injection and print-time XSS via unescaped embedded font-family name
@eigenpal/docx-editor-core/ @eigenpal/docx-editor-react
@eigenpal/docx-editor-react: CSS injection and print-time XSS via unescaped embedded font-family name
Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing path-scoped routing, middleware guards and access logging
Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing path-scoped routing, middleware guards and access logging
nodemailer
TuxCare security update for nodemailer (6 CVEs)
nodemailer
TuxCare security update for nodemailer (6 CVEs)
Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization
Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization
