Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    MINI-7wfm-7rxr-278q
    No fix available
    Packages

    spark-4.0-scala-2.13

    Summary

    Published
    3 Sept 2026
    MINI-m4vq-vf75-3rmw
    No fix available
    Packages

    spark-3.5-scala-2.12, spark-3.5-scala-2.13

    Summary

    Published
    3 Sept 2026
    GHSA-vpjw-wf5h-cgpq
    Fix available
    Packages

    github.com/siyuan-note/siyuan/kernel

    Summary

    SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents

    Published
    3 Sept 2026
    GHSA-67x2-mq63-v9vm
    Fix available
    Packages

    github.com/siyuan-note/siyuan/kernel

    Summary

    SiYuan: Missing publish-access check on getBlockBreadcrumb, getRefText, and getBlockTreeInfos discloses content and metadata of protected/forbidden documents

    Published
    3 Sept 2026
    GHSA-6mcf-g667-w3qv
    Fix available
    Packages

    github.com/siyuan-note/siyuan/kernel

    Summary

    SiYuan: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents without the password (publish mode)

    Published
    3 Sept 2026
    CGA-xxr9-crqr-5wgv
    Fix available
    Packages

    crossplane-provider-aws-lambda-fips

    Summary

    Published
    3 Sept 2026
    CGA-vg3g-c293-qc5h
    Fix available
    Packages

    crossplane-provider-aws-lambda-fips

    Summary

    Published
    3 Sept 2026
    CGA-35xx-9rjh-j7j5
    Fix available
    Packages

    crossplane-provider-aws-keyspaces-fips

    Summary

    Published
    3 Sept 2026
    CGA-2x7q-9334-rmcv
    Fix available
    Packages

    crossplane-provider-aws-keyspaces-fips

    Summary

    Published
    3 Sept 2026
    GHSA-x67c-8pwr-m8g3
    Fix available
    Packages

    github.com/siyuan-note/siyuan/kernel

    Summary

    SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel

    Published
    3 Sept 2026
    MINI-3fw2-6vj2-xvmf
    No fix available
    Packages

    redpanda-25.1-fips

    Summary

    Published
    3 Sept 2026
    MINI-9p8f-pgrw-4w72
    No fix available
    Packages

    redpanda-25.1-fips

    Summary

    Published
    3 Sept 2026
    GHSA-v7ph-r5r6-4jcj
    Fix available
    Packages

    github.com/siyuan-note/siyuan/kernel

    Summary

    SiYuan: Missing publish-access filter on getFileAnnotation discloses private PDF annotations of forbidden/protected documents (publish mode)

    Published
    3 Sept 2026
    CGA-45jx-7ggf-r4wv
    Fix available
    Packages

    cilium-1.20

    Summary

    Published
    3 Sept 2026
    CGA-gmc5-hr5h-wvw2
    Fix available
    Packages

    cilium-1.20

    Summary

    Published
    3 Sept 2026
    CGA-683p-mr65-6px7
    Fix available
    Packages

    cilium-1.20

    Summary

    Published
    3 Sept 2026
    CGA-3mrw-f2gx-cfj9
    Fix available
    Packages

    cilium-1.20

    Summary

    Published
    3 Sept 2026
    CGA-rq67-vg2w-x4hg
    Fix available
    Packages

    cilium-1.20

    Summary

    Published
    3 Sept 2026
    CGA-4wj7-4g9g-4562
    Fix available
    Packages

    cilium-1.20

    Summary

    Published
    3 Sept 2026
    CGA-2hhg-p7hp-chw7
    Fix available
    Packages

    cilium-1.20

    Summary

    Published
    3 Sept 2026
    MINI-2mwx-pcrw-m5hv
    No fix available
    Packages

    prometheus-node-exporter-fips-1.9

    Summary

    Published
    3 Sept 2026
    MINI-46cg-26jr-7g28
    No fix available
    Packages

    prometheus-node-exporter-fips-1.9

    Summary

    Published
    3 Sept 2026
    CGA-h8pg-gq5f-qgjx
    Fix available
    Packages

    crossplane-provider-aws-sqs, crossplane-provider-aws-sqs

    Summary

    Published
    3 Sept 2026
    CGA-3hfc-3825-8jj9
    Fix available
    Packages

    crossplane-provider-aws-sqs, crossplane-provider-aws-sqs

    Summary

    Published
    3 Sept 2026
    MINI-8465-h7hx-9f9c
    No fix available
    Packages

    prometheus-node-exporter-1.9

    Summary

    Published
    3 Sept 2026
    MINI-hgcc-7vh4-9hfp
    No fix available
    Packages

    prometheus-node-exporter-1.9

    Summary

    Published
    3 Sept 2026
    CVE-2026-85456
    Fix available
    Packages

    Summary

    MOOS-IvP through 24.8.1 alog Splitting Path Traversal on Windows

    Published
    3 Sept 2026
    CVE-2026-85455
    Fix available
    Packages

    Summary

    MOOS core-moos through 10.4.0 MOOSDB Out-of-Bounds Read via Short Packet

    Published
    3 Sept 2026
    CVE-2026-85454
    Fix available
    Packages

    Summary

    MOOS core-moos through 10.4.0 Off-by-One Buffer Overflow in Serial Telegram Handling

    Published
    3 Sept 2026
    CVE-2026-85453
    Fix available
    Packages

    Summary

    MOOS core-moos through 10.4.0 MOOSDB HTTP Pages Stored Cross-Site Scripting

    Published
    3 Sept 2026
    CVE-2026-85451
    Fix available
    Packages

    Summary

    MOOS core-moos through 10.4.0 Remote Process Termination via Hard-Coded Multicast Passphrase

    Published
    3 Sept 2026
    CVE-2026-85450
    Fix available
    Packages

    Summary

    MOOS core-moos through 10.4.0 MOOSDB HTTP Server Resource Exhaustion

    Published
    3 Sept 2026
    CVE-2026-85449
    Fix available
    Packages

    Summary

    MOOS-IvP through 24.8.1 pMarineViewer Unbounded Memory Consumption via NODE_REPORT

    Published
    3 Sept 2026
    CVE-2026-85448
    Fix available
    Packages

    Summary

    MOOS-IvP through 24.8.1 uFldShoreBroker Unbounded Community State Retention

    Published
    3 Sept 2026
    CVE-2026-85447
    Fix available
    Packages

    Summary

    MOOS-IvP through 24.8.1 pRealm Unbounded REALMCAST_REQ Subscription Denial of Service

    Published
    3 Sept 2026
    CVE-2026-85446
    Fix available
    Packages

    Summary

    MOOS-IvP through 24.8.1 uFldNodeComms Quadratic Processing Denial of Service

    Published
    3 Sept 2026
    CVE-2026-85445
    Fix available
    Packages

    Summary

    MOOS-IvP through 24.8.1 BHV_IPF Demultiplexer Memory Exhaustion via Packet Count

    Published
    3 Sept 2026
    CVE-2026-85444
    Fix available
    Packages

    Summary

    MOOS-IvP through 24.8.1 Out-of-Bounds Read in isBraced, isQuoted and isChevroned

    Published
    3 Sept 2026
    CVE-2026-85443
    Fix available
    Packages

    Summary

    MOOS core-moos through 10.4.0 MOOSDB Accept Loop Denial of Service

    Published
    3 Sept 2026
    CVE-2026-85442
    Fix available
    Packages

    Summary

    MOOS core-moos through 10.4.0 MOOSDB Denial of Service via Unbounded Packet Allocation

    Published
    3 Sept 2026
    CVE-2026-85441
    Fix available
    Packages

    Summary

    MOOS core-moos through 10.4.0 MOOSDB Denial of Service via Negative Serialized String Length

    Published
    3 Sept 2026
    CVE-2026-85440
    Fix available
    Packages

    Summary

    MOOS core-moos through 10.4.0 MOOSDB Pre-Authentication Heap Overflow via Negative Packet Length

    Published
    3 Sept 2026
    CVE-2026-85439
    Fix available
    Packages

    Summary

    MOOS-IvP through 24.8.1 alogsplit Command Injection via Input Pathname

    Published
    3 Sept 2026
    CVE-2026-85438
    Fix available
    Packages

    Summary

    MOOS-IvP through 24.8.1 Out-of-Bounds Write via Unvalidated IvP Payload Counts

    Published
    3 Sept 2026
    CVE-2026-85437
    Fix available
    Packages

    Summary

    MOOS-IvP through 24.8.1 Buffer Overflow in IvP Function String Decoders

    Published
    3 Sept 2026
    CVE-2026-85436
    Fix available
    Packages

    Summary

    MOOS essential-moos through 10.0.1 pMOOSBridge Heap Corruption via Negative UDP Length

    Published
    3 Sept 2026
    CVE-2026-85435
    Fix available
    Packages

    Summary

    MOOS-IvP through 24.8.1 uFldNodeBroker Unauthenticated Shore Route Enrollment

    Published
    3 Sept 2026
    CVE-2026-85434
    Fix available
    Packages

    Summary

    MOOS-IvP through 24.8.1 uFldShoreBroker Bridge Route Injection via Unverified Node Ping

    Published
    3 Sept 2026
    CVE-2026-85433
    Fix available
    Packages

    Summary

    MOOS essential-moos through 10.0.1 pShare Unauthorized Runtime Route Reconfiguration

    Published
    3 Sept 2026
    CVE-2026-85432
    Fix available
    Packages

    Summary

    MOOS core-moos through 10.4.0 MOOSDB Message Source Spoofing via Wire Identity

    Published
    3 Sept 2026