Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    CVE-2026-86759
    Fix available
    Packages

    Summary

    Snipe-IT before 8.7.0 Missing Authorization via asset-history CSV importer

    Published
    9 Sept 2026
    CGA-jc5q-669v-8w5m
    Fix available
    Packages

    kubernetes-dns-node-cache, kubernetes-dns-node-cache

    Summary

    Published
    9 Sept 2026
    CVE-2026-86758
    Fix available
    Packages

    Summary

    Snipe-IT before 8.7.0 License Key Exposure via CSV Export

    Published
    9 Sept 2026
    CVE-2026-86757
    Fix available
    Packages

    Summary

    Snipe-IT before 8.7.0 Information Disclosure via Custom Fields

    Published
    9 Sept 2026
    CGA-frqf-h2p7-58mx
    No fix available
    Packages

    opentofu-1.11, opentofu-1.11

    Summary

    Published
    9 Sept 2026
    CVE-2026-86756
    Fix available
    Packages

    Summary

    Snipe-IT 8.5.0 through 8.6.3 Open Redirect via SAML RelayState

    Published
    9 Sept 2026
    CGA-xr5g-xxcq-x9v6
    Fix available
    Packages

    loki-fips-3.7-logcli

    Summary

    Published
    9 Sept 2026
    CGA-6q9j-2r4p-jpj2
    Fix available
    Packages

    knative-net-istio-fips-1.20-controller

    Summary

    Published
    9 Sept 2026
    CGA-432v-q93x-66rx
    Fix available
    Packages

    opentofu-1.11, opentofu-1.11

    Summary

    Published
    9 Sept 2026
    CVE-2026-86755
    Fix available
    Packages

    Summary

    Snipe-IT 4.2.0 through 8.6.3 Permission Bypass via OAuth

    Published
    9 Sept 2026
    CVE-2026-86754
    Fix available
    Packages

    Summary

    Snipe-IT before 8.7.0 Authorization Bypass via OAuth Clients

    Published
    9 Sept 2026
    CGA-p2wv-jg8w-w979
    Fix available
    Packages

    kubernetes-csi-external-snapshot-controller-8.6, kubernetes-csi-external-snapshot-controller-8.6

    Summary

    Published
    9 Sept 2026
    CVE-2026-86753
    Fix available
    Packages

    Summary

    snipe-it before 8.7.0 Business Logic Bypass via asset_model endpoint

    Published
    9 Sept 2026
    CGA-hhjj-6jrp-7v53
    Fix available
    Packages

    grype-db

    Summary

    Published
    9 Sept 2026
    CVE-2026-86752
    Fix available
    Packages

    Summary

    snipe-it before 8.7.0 Authorization Bypass via Asset Audit Endpoints

    Published
    9 Sept 2026
    CVE-2026-86751
    Fix available
    Packages

    Summary

    Snipe-IT before 8.7.0 Arbitrary File Read and SSRF via Markdown

    Published
    9 Sept 2026
    CVE-2026-86750
    Fix available
    Packages

    Summary

    snipe-it before 8.7.0 Authorization Bypass via API User Create/Update

    Published
    9 Sept 2026
    CGA-fr68-h8mh-73gc
    Fix available
    Packages

    coder-2.32

    Summary

    Published
    9 Sept 2026
    CVE-2026-86749
    Fix available
    Packages

    Summary

    snipe-it before 8.7.0 Data Loss via Failed Image Write

    Published
    9 Sept 2026
    CVE-2026-86748
    Fix available
    Packages

    Summary

    Snipe-IT before 8.7.0 Database Wipe via Invalid Backup Archive

    Published
    9 Sept 2026
    CVE-2026-86747
    Fix available
    Packages

    Summary

    snipe-it before 8.7.0 Authorization Bypass via Pivot-Only User

    Published
    9 Sept 2026
    CGA-p776-32jq-cq4v
    Fix available
    Packages

    calico-felix-3.32, calico-felix-3.32

    Summary

    Published
    9 Sept 2026
    CVE-2026-86746
    Fix available
    Packages

    Summary

    Snipe-IT before 8.7.0 Authorization Bypass via Livewire Snapshot Replay

    Published
    9 Sept 2026
    CGA-q5vq-42jc-h2p5
    Fix available
    Packages

    calico-felix-3.32, calico-felix-3.32

    Summary

    Published
    9 Sept 2026
    CGA-2vp2-jc39-fh7h
    Fix available
    Packages

    kubelet-fips-1.33

    Summary

    Published
    9 Sept 2026
    CGA-78w7-hwv4-9fq2
    Fix available
    Packages

    calico-felix-3.32, calico-felix-3.32

    Summary

    Published
    9 Sept 2026
    CGA-876x-r6p7-cqw3
    No fix available
    Packages

    kubelet-fips-1.33

    Summary

    Published
    9 Sept 2026
    CGA-9c6g-35mc-735p
    Fix available
    Packages

    calico-felix-3.32, calico-felix-3.32

    Summary

    Published
    9 Sept 2026
    CGA-h37q-88cv-x8cq
    Fix available
    Packages

    istio-cni-fips-1.27

    Summary

    Published
    9 Sept 2026
    CVE-2026-86745
    Fix available
    Packages

    Summary

    Snipe-IT before 8.7.0 CSV Formula Injection via Location-Scoping Export

    Published
    9 Sept 2026
    CVE-2026-86744
    Fix available
    Packages

    Summary

    snipe-it before 8.7.0 Race Condition in Asset Checkout

    Published
    9 Sept 2026
    CVE-2026-86743
    Fix available
    Packages

    Summary

    Snipe-IT before 8.7.0 Authorization Bypass via Asset Acceptance Report

    Published
    9 Sept 2026
    CGA-pf8c-jv45-pjwr
    Fix available
    Packages

    k3s-multicall-1.35, k3s-multicall-1.35

    Summary

    Published
    9 Sept 2026
    CVE-2026-86742
    Fix available
    Packages

    Summary

    Snipe-IT before 8.7.0 CSV Formula Injection via Asset Acceptance Report

    Published
    9 Sept 2026
    CVE-2026-86741
    Fix available
    Packages

    Summary

    Snipe-IT before 8.7.0 Arbitrary File Read and SSRF via Category EULA

    Published
    9 Sept 2026
    CVE-2026-86740
    Fix available
    Packages

    Summary

    Snipe-IT before 8.7.0 Attachment Deletion Reports Success While File Remains

    Published
    9 Sept 2026
    CVE-2026-86739
    Fix available
    Packages

    Summary

    Snipe-IT before 8.7.0 Acceptance Finalization Without Stored Evidence

    Published
    9 Sept 2026
    CVE-2026-86204
    Fix available
    Packages

    Summary

    PocketMine-MP before 5.39.2 Denial of Service via ModalFormResponsePacket

    Published
    9 Sept 2026
    CGA-jjr4-8m6g-x39q
    Fix available
    Packages

    gitlab-pages-fips-19.3

    Summary

    Published
    9 Sept 2026
    CGA-24c8-323w-xpfr
    Fix available
    Packages

    kubernetes-csi-external-provisioner-fips

    Summary

    Published
    9 Sept 2026
    CVE-2026-86203
    Fix available
    Packages

    Summary

    PocketMine-MP before 5.39.2 Item Duplication via Despawn State

    Published
    9 Sept 2026
    CVE-2026-86202
    Fix available
    Packages

    Summary

    PocketMine-MP before 5.39.2 Network Amplification via ActorEventPacket

    Published
    9 Sept 2026
    CGA-q4wh-px5q-c888
    No fix available
    Packages

    commercial-kyverno-background-controller-1.14

    Summary

    Published
    9 Sept 2026
    CGA-rqc6-7wpc-mg6x
    No fix available
    Packages

    commercial-kyverno-background-controller-1.14

    Summary

    Published
    9 Sept 2026
    CGA-3pcf-phg8-6mcw
    Fix available
    Packages

    gobgp-fips

    Summary

    Published
    9 Sept 2026
    CGA-m829-6r5p-jmp4
    Fix available
    Packages

    argo-workflow-controller-4.0, argo-workflow-controller-4.0

    Summary

    Published
    9 Sept 2026
    CVE-2026-86201
    Fix available
    Packages

    Summary

    PocketMine-MP before 5.41.1 LogDoS via LoginPacket clientData

    Published
    9 Sept 2026
    CGA-m7j8-rxjx-4799
    Fix available
    Packages

    gobgp-fips

    Summary

    Published
    9 Sept 2026
    CVE-2026-86200
    Fix available
    Packages

    Summary

    PocketMine-MP before 5.42.1 LogDoS via LoginPacket clientData JWT

    Published
    9 Sept 2026
    CVE-2026-86199
    Fix available
    Packages

    Summary

    PocketMine-MP before 5.43.1 Denial of Service via unauthenticated login

    Published
    9 Sept 2026