Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    GHSA-6v2g-fpxh-pmmh
    Fix available
    Packages

    deepseek-tui, deepseek-tui, codewhale-tui, codewhale

    Summary

    CodeWhale: SSRF‌ bypass - TOCTOU on DNS failure for DNS pinning

    Published
    4 Sept 2026
    GHSA-h539-c7r8-3xq4
    Fix available
    Packages

    deepseek-tui, deepseek-tui, codewhale-tui, codewhale

    Summary

    CodeWhale: js_execution leaks parent environment to model context via missing env scrub

    Published
    4 Sept 2026
    GHSA-7j5w-7r7x-9v27
    Fix available
    Packages

    deepseek-tui, deepseek-tui, codewhale-tui, codewhale

    Summary

    CodeWhale: Argument Injection in `git_show` Tool Allows Arbitrary File Write Without Approval

    Published
    4 Sept 2026
    GHSA-g29h-pfmp-qp9r
    Fix available
    Packages

    deepseek-tui, deepseek-tui, codewhale-tui, codewhale

    Summary

    CodeWhale: exec_shell_interact sends LLM-controlled input to a running shell without an approval prompt (privilege escalation)

    Published
    4 Sept 2026
    CVE-2026-53761
    Fix available
    Packages

    Summary

    Frappe CRM: Authentication Bypass via Logged Invitation Keys in crm/api

    Published
    4 Sept 2026
    GHSA-62f5-cp2p-vq95
    Fix available
    Packages

    deepseek-tui, deepseek-tui, codewhale-tui, codewhale

    Summary

    CodeWhale: Project config `instructions` override enables arbitrary file read into AI system prompt via cloned repository

    Published
    4 Sept 2026
    CGA-58fv-cjmh-5gr7
    Fix available
    Packages

    cilium-fips-1.17

    Summary

    Published
    4 Sept 2026
    CGA-5jfp-56hf-wvhv
    Fix available
    Packages

    cilium-fips-1.17

    Summary

    Published
    4 Sept 2026
    CVE-2026-9317
    Fix available
    Packages

    Summary

    Nango < 0.71.6 Missing Authentication RCE via runner tRPC server

    Published
    4 Sept 2026
    USN-8714-2
    Fix available
    Packages

    linux-aws-5.4, linux-gcp-5.4, linux-gcp

    Summary

    linux-aws-5.4, linux-gcp, linux-gcp-5.4 vulnerabilities

    Published
    4 Sept 2026
    CVE-2026-53760
    Fix available
    Packages

    Summary

    Admidio: CSRF on Plugin Install, Uninstall, and Update via Unprotected GET Requests

    Published
    4 Sept 2026
    MGASA-2026-0374
    Fix available
    Packages

    microcode, microcode

    Summary

    Updated microcode packages fix security vulnerabilities

    Published
    4 Sept 2026
    MGASA-2026-0375
    Fix available
    Packages

    mbedtls

    Summary

    Updated mbedtls packages fix security vulnerabilities

    Published
    4 Sept 2026
    MGASA-2026-0376
    Fix available
    Packages

    tomcat, tomcat

    Summary

    Updated tomcat packages fix security vulnerabilities

    Published
    4 Sept 2026
    USN-8725-1
    Fix available
    Packages

    linux-aws, linux-lts-xenial, linux, linux-kvm, linux-fips

    Summary

    linux, linux-aws, linux-fips, linux-kvm, linux-lts-xenial vulnerabilities

    Published
    4 Sept 2026
    CVE-2026-61688
    Fix available
    Packages

    Summary

    SolidInvoice allows cross-user access to API token request history via writable DataGrid LiveComponent props

    Published
    4 Sept 2026
    CVE-2026-61614
    Fix available
    Packages

    Summary

    SolidInvoice's long-lived API tokens accepted as URL query parameters, exposing credentials in server logs and browser history

    Published
    4 Sept 2026
    CVE-2026-85769
    Fix available
    Packages

    Summary

    Libtpms: libtpms: heap out-of-bounds read in tpm2 state unmarshalling via unchecked block_skip_read() blocksize

    Published
    4 Sept 2026
    CVE-2026-73848
    No fix available
    Packages

    Summary

    Emlog: Stored XSS via Tag Name in Article Editor

    Published
    4 Sept 2026
    CVE-2026-53757
    No fix available
    Packages

    Summary

    Emlog: Zip Slip Path Traversal in Plugin/Template ZIP Upload Enables RCE

    Published
    4 Sept 2026
    CVE-2026-53758
    No fix available
    Packages

    Summary

    Emlog: Stored XSS via Parsedown Markdown Processing - Raw HTML Not Sanitized

    Published
    4 Sept 2026
    CVE-2026-53756
    Fix available
    Packages

    Summary

    Emlog Blind SQL Injection via Authentication Cookie

    Published
    4 Sept 2026
    CVE-2026-61608
    Fix available
    Packages

    Summary

    SolidInvoice's user invitation tokens have no expiry, allowing indefinite unauthorized company access via leaked or old invitation links

    Published
    4 Sept 2026
    CVE-2026-61686
    Fix available
    Packages

    Summary

    SolidInvoice: PHP unserialize() called on client-controlled data in DataGrid LiveComponent context prop

    Published
    4 Sept 2026
    CGA-xwj9-xg32-248x
    Fix available
    Packages

    cilium-fips-1.17-host-utils

    Summary

    Published
    4 Sept 2026
    CVE-2026-82538
    Fix available
    Packages

    Summary

    ILIAS Arbitrary SQL Injection via Repository Trash Table Sort Parameter

    Published
    4 Sept 2026
    GHSA-w7wx-5q49-r59w
    Fix available
    Packages

    deepseek-tui, deepseek-tui, codewhale-tui, codewhale

    Summary

    CodeWhale: image_analyze follows workspace symlinks, leaking external file bytes

    Published
    4 Sept 2026
    GHSA-6hxq-p678-4hr2
    Fix available
    Packages

    @simplewebauthn/server

    Summary

    SimpleWebAuthn: Registration verification does not sufficiently ensure that attestation certificates chain to a trust anchor

    Published
    4 Sept 2026
    GHSA-m3c3-78fh-w3w7
    Fix available
    Packages

    SurrealDB, SurrealDB, SurrealDB, SurrealDB

    Summary

    SurrealDB allows bypass of deny-net flags via DNS resolution

    Published
    4 Sept 2026
    CVE-2026-50553
    Fix available
    Packages

    Summary

    Note Mark: Path traversal via unsanitized book/note slug in migrate export (sibling of GHSA-g49p)

    Published
    4 Sept 2026
    CVE-2026-18149
    Fix available
    Packages

    Summary

    undici vulnerable to Denial of Service via orphaned RetryHandler response body

    Published
    4 Sept 2026
    CVE-2026-80913
    Fix available
    Packages

    , Kernel

    Summary

    selinux: require every boolean value to be defined

    Published
    4 Sept 2026
    CVE-2026-80912
    Fix available
    Packages

    , Kernel

    Summary

    selinux: reject an unclaimed class value in security_get_classes()

    Published
    4 Sept 2026
    CVE-2026-80911
    Fix available
    Packages

    , Kernel

    Summary

    ASoC: SOF: sof-audio: Fix error path in sof_widget_setup_unlocked()

    Published
    4 Sept 2026
    CVE-2026-80910
    Fix available
    Packages

    , Kernel

    Summary

    ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses

    Published
    4 Sept 2026
    CVE-2026-80909
    Fix available
    Packages

    , Kernel

    Summary

    drm/amdgpu: Reject UVD message with invalid number of h265 refs

    Published
    4 Sept 2026
    CVE-2026-80908
    Fix available
    Packages

    , Kernel

    Summary

    drm/amdgpu: Reject UVD message with dimensions above 4096

    Published
    4 Sept 2026
    CVE-2026-80907
    Fix available
    Packages

    , Kernel

    Summary

    drm/amdgpu: Fix UVD dpb min size calculation for H264

    Published
    4 Sept 2026
    CVE-2026-80906
    Fix available
    Packages

    , Kernel

    Summary

    net: packet: fix wrong transport_header when sending VLAN-tagged frame

    Published
    4 Sept 2026
    CVE-2026-80905
    Fix available
    Packages

    , Kernel

    Summary

    net: tap: fix wrong transport_header when sending VLAN-tagged frame

    Published
    4 Sept 2026
    CVE-2026-80904
    Fix available
    Packages

    , Kernel

    Summary

    net/tls: Fail tls_sw_splice_read() after a failed async decrypt

    Published
    4 Sept 2026
    CVE-2026-80903
    Fix available
    Packages

    , Kernel

    Summary

    drm/xe/oa: Fix sync entry leak on OA config emit failure

    Published
    4 Sept 2026
    Packages

    node-undici, node-undici, node-undici

    Summary

    Published
    4 Sept 2026
    Packages

    node-undici, node-undici, node-undici

    Summary

    Published
    4 Sept 2026
    Packages

    node-undici, node-undici, node-undici

    Summary

    Published
    4 Sept 2026
    Packages

    node-undici, node-undici, node-undici

    Summary

    Published
    4 Sept 2026
    Packages

    node-undici, node-undici, node-undici

    Summary

    Published
    4 Sept 2026
    Packages

    node-undici, node-undici, node-undici

    Summary

    Published
    4 Sept 2026
    Packages

    node-undici, node-undici, node-undici

    Summary

    Published
    4 Sept 2026
    Packages

    linux, linux, linux

    Summary

    Published
    4 Sept 2026