Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    CVE-2026-52767
    Fix available
    Packages

    Summary

    YesWiki: Unauthenticated ActivityPub Signature-Verification Bypass via `!openssl_verify(...)` accepting `int(-1)`

    Published
    4 Sept 2026
    CVE-2026-52766
    Fix available
    Packages

    Summary

    YesWiki: Unauthenticated arbitrary page deletion via `{{erasespamedcomments}}` action

    Published
    4 Sept 2026
    CVE-2026-52763
    Fix available
    Packages

    Summary

    YesWiki: SQL injection via the `recentchanges` action `period` argument leading to arbitrary DB read

    Published
    4 Sept 2026
    CVE-2026-52762
    Fix available
    Packages

    Summary

    YesWiki: Authenticated (Admin) Server-Side Template Injection to Remote Code Execution via Bazar Semantic Templates

    Published
    4 Sept 2026
    DEBIAN-CVE-2026-86098
    No fix available
    Packages

    ndpi, ndpi, ndpi

    Summary

    Published
    4 Sept 2026
    DEBIAN-CVE-2026-86095
    No fix available
    Packages

    netcdf, netcdf, netcdf, netcdf-parallel, netcdf-parallel, netcdf-parallel

    Summary

    Published
    4 Sept 2026
    AZL-99945
    No fix available
    Packages

    ntopng

    Summary

    CVE-2026-86098 affecting package ntopng 5.2.1-6

    Published
    4 Sept 2026
    AZL-99894
    No fix available
    Packages

    netcdf

    Summary

    CVE-2026-86095 affecting package netcdf 4.9.0-4

    Published
    4 Sept 2026
    UBUNTU-CVE-2026-86098
    No fix available
    Packages

    ndpi, ndpi, ndpi, ndpi, ndpi, ndpi

    Summary

    Published
    4 Sept 2026
    UBUNTU-CVE-2026-86095
    No fix available
    Packages

    netcdf, netcdf, netcdf, netcdf, netcdf-parallel, netcdf, netcdf-parallel, netcdf, netcdf-parallel, netcdf, netcdf-parallel

    Summary

    Published
    4 Sept 2026
    DEBIAN-CVE-2026-48019
    No fix available
    Packages

    php-laravel-framework, php-laravel-framework, php-laravel-framework

    Summary

    Published
    4 Sept 2026
    CVE-2026-86100
    Fix available
    Packages

    Summary

    Camaleon CMS 2.7.5 through 2.9.1 SSRF via HTTP Redirect in Upload from URL

    Published
    4 Sept 2026
    CVE-2026-86098
    Fix available
    Packages

    Summary

    ntop nDPI before 6.0 Heap Buffer Overflow via ndpi_json_string_escape

    Published
    4 Sept 2026
    CVE-2026-86097
    Fix available
    Packages

    Summary

    PX4 Autopilot through 1.17.0 Null Pointer Dereference via param select

    Published
    4 Sept 2026
    CVE-2026-86096
    Fix available
    Packages

    Summary

    PX4 Autopilot through 1.17.0 Use-After-Free via Temperature Calibration Task Startup

    Published
    4 Sept 2026
    CVE-2026-86095
    Fix available
    Packages

    Summary

    Unidata netcdf-c through 4.10.1 Out-of-bounds Write via Oversized HDF5 Attribute Name

    Published
    4 Sept 2026
    Packages

    xmldom

    Summary

    TuxCare security update for xmldom (1 CVE)

    Published
    4 Sept 2026
    Packages

    undici

    Summary

    TuxCare security update for undici (14 CVEs)

    Published
    4 Sept 2026
    Packages

    ip-address

    Summary

    TuxCare security update for ip-address (1 CVE)

    Published
    4 Sept 2026
    Packages

    tar-fs

    Summary

    TuxCare security update for tar-fs (3 CVEs)

    Published
    4 Sept 2026
    Packages

    browserslist

    Summary

    TuxCare security update for browserslist (1 CVE)

    Published
    4 Sept 2026
    Packages

    systeminformation

    Summary

    TuxCare security update for systeminformation (4 CVEs)

    Published
    4 Sept 2026
    Packages

    ws

    Summary

    TuxCare security update for ws (3 CVEs)

    Published
    4 Sept 2026
    Packages

    ws

    Summary

    TuxCare security update for ws (3 CVEs)

    Published
    4 Sept 2026
    Packages

    ws

    Summary

    TuxCare security update for ws (3 CVEs)

    Published
    4 Sept 2026
    Packages

    dset

    Summary

    TuxCare security update for dset (1 CVE)

    Published
    4 Sept 2026
    AZL-99690
    No fix available
    Packages

    ntopng

    Summary

    CVE-2026-86090 affecting package ntopng 5.2.1-6

    Published
    4 Sept 2026
    AZL-99693
    No fix available
    Packages

    ntopng

    Summary

    CVE-2026-86091 affecting package ntopng 5.2.1-6

    Published
    4 Sept 2026
    Packages

    php-twig, php-twig, php-twig

    Summary

    Published
    4 Sept 2026
    UBUNTU-CVE-2026-86091
    No fix available
    Packages

    ntopng, ntopng, ntopng, ntopng, ntopng

    Summary

    Published
    4 Sept 2026
    UBUNTU-CVE-2026-86090
    No fix available
    Packages

    ntopng, ntopng, ntopng, ntopng, ntopng

    Summary

    Published
    4 Sept 2026
    UBUNTU-CVE-2026-76925
    No fix available
    Packages

    flatpak, flatpak, flatpak, flatpak, flatpak

    Summary

    Published
    4 Sept 2026
    UBUNTU-CVE-2026-46636
    No fix available
    Packages

    php-twig, php-twig, php-twig, php-twig, php-twig

    Summary

    Published
    4 Sept 2026
    CVE-2026-48019
    Fix available
    Packages

    Summary

    CRLF injection in Laravel's default email rule enables SMTP smuggling and spoofed-mail relay

    Published
    4 Sept 2026
    CVE-2026-46636
    Fix available
    Packages

    Summary

    Twig: Sandbox method allowlist bypass via `Markup` subclass

    Published
    4 Sept 2026
    CGA-chrc-xf5p-j39v
    Fix available
    Packages

    nacos-docker

    Summary

    Published
    4 Sept 2026
    CGA-62pr-fq56-2x55
    Fix available
    Packages

    nacos-docker

    Summary

    Published
    4 Sept 2026
    CVE-2026-86091
    Fix available
    Packages

    Summary

    ntopng before 6.7.260717 Missing Authorization on the Host Pool Bulk Delete Handler

    Published
    4 Sept 2026
    CVE-2026-86090
    Fix available
    Packages

    Summary

    ntopng before 6.7.260717 Missing Authorization on the Notification Endpoint and Recipient Delete Handlers

    Published
    4 Sept 2026
    CGA-xjj4-4742-xh4m
    No fix available
    Packages

    vllm-openai-cuda-13.0

    Summary

    Published
    4 Sept 2026
    CGA-6462-g436-xgg3
    No fix available
    Packages

    vllm-openai-cuda-13.0

    Summary

    Published
    4 Sept 2026
    CGA-pcfw-2fcw-4cxv
    No fix available
    Packages

    vllm-openai-cuda-13.0

    Summary

    Published
    4 Sept 2026
    CGA-6f8h-m22c-rch2
    No fix available
    Packages

    vllm-openai-cuda-13.0

    Summary

    Published
    4 Sept 2026
    GHSA-7q9c-hpx7-9cwm
    Fix available
    Packages

    @typespec/spector

    Summary

    TypeSpec: Unauthenticated Remote Shutdown of Spector Mock Server via POST /.admin/stop

    Published
    4 Sept 2026
    GHSA-rh53-xvx2-j327
    Fix available
    Packages

    github.com/openchoreo/openchoreo, github.com/openchoreo/openchoreo, github.com/openchoreo/openchoreo

    Summary

    OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation

    Published
    4 Sept 2026
    GHSA-pr7f-p5mw-fc87
    Fix available
    Packages

    vllm

    Summary

    vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts

    Published
    4 Sept 2026
    GHSA-48jh-3gj7-fg8v
    Fix available
    Packages

    vllm

    Summary

    vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m

    Published
    4 Sept 2026
    GHSA-hwrm-c4cx-rf4j
    Fix available
    Packages

    vllm

    Summary

    vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages

    Published
    4 Sept 2026
    GHSA-8737-qx52-hjff
    Fix available
    Packages

    vllm

    Summary

    vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds

    Published
    4 Sept 2026
    CGA-f293-4xjv-p63g
    Fix available
    Packages

    jitsucom-jitsu-console, jitsucom-jitsu-console

    Summary

    Published
    4 Sept 2026