Open Source Vulnerabilities
YesWiki: Unauthenticated ActivityPub Signature-Verification Bypass via `!openssl_verify(...)` accepting `int(-1)`
YesWiki: Unauthenticated ActivityPub Signature-Verification Bypass via `!openssl_verify(...)` accepting `int(-1)`
YesWiki: Unauthenticated arbitrary page deletion via `{{erasespamedcomments}}` action
YesWiki: Unauthenticated arbitrary page deletion via `{{erasespamedcomments}}` action
YesWiki: SQL injection via the `recentchanges` action `period` argument leading to arbitrary DB read
YesWiki: SQL injection via the `recentchanges` action `period` argument leading to arbitrary DB read
YesWiki: Authenticated (Admin) Server-Side Template Injection to Remote Code Execution via Bazar Semantic Templates
YesWiki: Authenticated (Admin) Server-Side Template Injection to Remote Code Execution via Bazar Semantic Templates
netcdf, netcdf, netcdf, netcdf-parallel, netcdf-parallel, netcdf-parallel
netcdf/ netcdf/ netcdf/ netcdf-parallel/ netcdf-parallel/ netcdf-parallel
ntopng
CVE-2026-86098 affecting package ntopng 5.2.1-6
netcdf
CVE-2026-86095 affecting package netcdf 4.9.0-4
ndpi, ndpi, ndpi, ndpi, ndpi, ndpi
netcdf, netcdf, netcdf, netcdf, netcdf-parallel, netcdf, netcdf-parallel, netcdf, netcdf-parallel, netcdf, netcdf-parallel
netcdf/ netcdf/ netcdf/ netcdf/ netcdf-parallel/ netcdf/ netcdf-parallel/ netcdf/ netcdf-parallel/ netcdf/ netcdf-parallel
php-laravel-framework, php-laravel-framework, php-laravel-framework
php-laravel-framework/ php-laravel-framework/ php-laravel-framework
Camaleon CMS 2.7.5 through 2.9.1 SSRF via HTTP Redirect in Upload from URL
Camaleon CMS 2.7.5 through 2.9.1 SSRF via HTTP Redirect in Upload from URL
ntop nDPI before 6.0 Heap Buffer Overflow via ndpi_json_string_escape
ntop nDPI before 6.0 Heap Buffer Overflow via ndpi_json_string_escape
PX4 Autopilot through 1.17.0 Null Pointer Dereference via param select
PX4 Autopilot through 1.17.0 Null Pointer Dereference via param select
PX4 Autopilot through 1.17.0 Use-After-Free via Temperature Calibration Task Startup
PX4 Autopilot through 1.17.0 Use-After-Free via Temperature Calibration Task Startup
Unidata netcdf-c through 4.10.1 Out-of-bounds Write via Oversized HDF5 Attribute Name
Unidata netcdf-c through 4.10.1 Out-of-bounds Write via Oversized HDF5 Attribute Name
xmldom
TuxCare security update for xmldom (1 CVE)
undici
TuxCare security update for undici (14 CVEs)
ip-address
TuxCare security update for ip-address (1 CVE)
ip-address
TuxCare security update for ip-address (1 CVE)
tar-fs
TuxCare security update for tar-fs (3 CVEs)
browserslist
TuxCare security update for browserslist (1 CVE)
browserslist
TuxCare security update for browserslist (1 CVE)
systeminformation
TuxCare security update for systeminformation (4 CVEs)
systeminformation
TuxCare security update for systeminformation (4 CVEs)
ws
TuxCare security update for ws (3 CVEs)
ws
TuxCare security update for ws (3 CVEs)
ws
TuxCare security update for ws (3 CVEs)
dset
TuxCare security update for dset (1 CVE)
ntopng
CVE-2026-86090 affecting package ntopng 5.2.1-6
ntopng
CVE-2026-86091 affecting package ntopng 5.2.1-6
ntopng, ntopng, ntopng, ntopng, ntopng
ntopng, ntopng, ntopng, ntopng, ntopng
flatpak, flatpak, flatpak, flatpak, flatpak
php-twig, php-twig, php-twig, php-twig, php-twig
CRLF injection in Laravel's default email rule enables SMTP smuggling and spoofed-mail relay
CRLF injection in Laravel's default email rule enables SMTP smuggling and spoofed-mail relay
Twig: Sandbox method allowlist bypass via `Markup` subclass
ntopng before 6.7.260717 Missing Authorization on the Host Pool Bulk Delete Handler
ntopng before 6.7.260717 Missing Authorization on the Host Pool Bulk Delete Handler
ntopng before 6.7.260717 Missing Authorization on the Notification Endpoint and Recipient Delete Handlers
ntopng before 6.7.260717 Missing Authorization on the Notification Endpoint and Recipient Delete Handlers
@typespec/spector
TypeSpec: Unauthenticated Remote Shutdown of Spector Mock Server via POST /.admin/stop
@typespec/spector
TypeSpec: Unauthenticated Remote Shutdown of Spector Mock Server via POST /.admin/stop
github.com/openchoreo/openchoreo, github.com/openchoreo/openchoreo, github.com/openchoreo/openchoreo
OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation
github.com/openchoreo/openchoreo/ github.com/openchoreo/openchoreo/ github.com/openchoreo/openchoreo
OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation
vllm
vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts
vllm
vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts
vllm
vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m
vllm
vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m
vllm
vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages
vllm
vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages
vllm
vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds
vllm
vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds
jitsucom-jitsu-console, jitsucom-jitsu-console
