Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    CGA-j9m2-5gr2-6fvr
    No fix available
    Packages

    telegraf-1.40

    Summary

    Published
    10 Sept 2026
    CGA-4fcf-x8qc-v8x6
    No fix available
    Packages

    telegraf-1.40

    Summary

    Published
    10 Sept 2026
    CVE-2026-88012
    Fix available
    Packages

    Summary

    Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded

    Published
    10 Sept 2026
    USN-8748-1
    Fix available
    Packages

    linux-nvidia-6.17

    Summary

    linux-nvidia-6.17 vulnerabilities

    Published
    10 Sept 2026
    CVE-2026-88011
    Fix available
    Packages

    Summary

    Traefik: ForwardAuth identity spoofing via dot-form header alias

    Published
    10 Sept 2026
    CVE-2026-88940
    No fix available
    Packages

    Summary

    knowns through 0.33.0 Arbitrary Directory Enumeration via workspace browse endpoint

    Published
    10 Sept 2026
    CVE-2026-88939
    No fix available
    Packages

    Summary

    knowns through 0.33.0 Authorization Bypass via project.set Bootstrap Exemption

    Published
    10 Sept 2026
    CVE-2026-88938
    No fix available
    Packages

    Summary

    knowns through 0.33.0 Path Traversal via code.find MCP tool

    Published
    10 Sept 2026
    CVE-2026-88937
    No fix available
    Packages

    Summary

    knowns through 0.33.0 Path Traversal via Template Engine

    Published
    10 Sept 2026
    CVE-2026-88899
    Fix available
    Packages

    Summary

    knowns before 0.31.0 External Control of Agent Working Directory via x-opencode-directory Header

    Published
    10 Sept 2026
    DEBIAN-CVE-2026-88924
    No fix available
    Packages

    gvfs, gvfs, gvfs

    Summary

    Published
    10 Sept 2026
    Packages

    suricata, suricata

    Summary

    Published
    10 Sept 2026
    Packages

    suricata, suricata

    Summary

    Published
    10 Sept 2026
    CGA-hp5j-5vg6-h48m
    No fix available
    Packages

    cilium-fips-1.19-operator-generic

    Summary

    Published
    10 Sept 2026
    GHSA-34ff-336r-5q23
    Fix available
    Packages

    n8n, n8n, n8n

    Summary

    n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Node

    Published
    10 Sept 2026
    GHSA-j535-v25q-vx3q
    Fix available
    Packages

    n8n, n8n, n8n

    Summary

    n8n: Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a Git Node Clone Path

    Published
    10 Sept 2026
    GHSA-hh89-3r9w-qj3j
    Fix available
    Packages

    n8n, n8n

    Summary

    n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint

    Published
    10 Sept 2026
    GHSA-hw8v-xxg5-vvvx
    Fix available
    Packages

    n8n, n8n, n8n

    Summary

    n8n: Expression Sandbox Escape via Class-Field Sanitizer Rebinding Can Lead to Code Execution

    Published
    10 Sept 2026
    GHSA-pcvc-8vrv-8q6w
    Fix available
    Packages

    open-webui

    Summary

    Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends

    Published
    10 Sept 2026
    GHSA-fmqh-xp37-5hr8
    Fix available
    Packages

    open-webui

    Summary

    Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint

    Published
    10 Sept 2026
    GHSA-jmc6-2wr8-h3wj
    Fix available
    Packages

    open-webui

    Summary

    Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin

    Published
    10 Sept 2026
    GHSA-4v28-j6q3-5m4r
    Fix available
    Packages

    open-webui

    Summary

    Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader

    Published
    10 Sept 2026
    GHSA-3pf7-q2g3-wj28
    Fix available
    Packages

    open-webui

    Summary

    Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions

    Published
    10 Sept 2026
    Packages

    ua-parser-js, @rootio/ua-parser-js

    Summary

    CVE-2022-25927 in ua-parser-js - Patched by Root

    Published
    10 Sept 2026
    GHSA-2724-6cpj-gf3v
    Fix available
    Packages

    open-webui

    Summary

    Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion

    Published
    10 Sept 2026
    GHSA-34r3-9m95-vq73
    Fix available
    Packages

    open-webui

    Summary

    Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch

    Published
    10 Sept 2026
    GHSA-4qg5-cxx4-g927
    Fix available
    Packages

    open-webui

    Summary

    Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange

    Published
    10 Sept 2026
    GHSA-q5j5-6p94-4gwc
    Fix available
    Packages

    github.com/xuri/excelize/v2, github.com/xuri/excelize

    Summary

    Excelize: Streaming GetRows row-bound bypass causes attacker-controlled allocation

    Published
    10 Sept 2026
    GHSA-fx5j-qcqg-grpf
    Fix available
    Packages

    github.com/xuri/excelize/v2, github.com/xuri/excelize

    Summary

    Excelize: Negative shared-string index causes panic in GetCellValue and GetRows

    Published
    10 Sept 2026
    Packages

    @koa/cors, koajs_cors

    Summary

    TuxCare security update for 2 packages (2 CVEs)

    Published
    10 Sept 2026
    CGA-w5pp-5qqr-m742
    No fix available
    Packages

    cilium-fips-1.19-operator-aws

    Summary

    Published
    10 Sept 2026
    GHSA-x7m8-jrm8-hpvx
    Fix available
    Packages

    @eigenpal/docx-editor-core, @eigenpal/docx-editor-react

    Summary

    @eigenpal/docx-editor-react: CSS injection and print-time XSS via unescaped embedded font-family name

    Published
    10 Sept 2026
    CGA-hv4q-qwpm-rppr
    No fix available
    Packages

    telegraf-1.40

    Summary

    Published
    10 Sept 2026
    CGA-4m9c-2rx8-9jqr
    No fix available
    Packages

    telegraf-1.40

    Summary

    Published
    10 Sept 2026
    CVE-2026-88009
    Fix available
    Packages

    Summary

    Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing path-scoped routing, middleware guards and access logging

    Published
    10 Sept 2026
    CGA-pw3f-g2hr-33xf
    No fix available
    Packages

    cilium-fips-1.19

    Summary

    Published
    10 Sept 2026
    CGA-722c-wc2m-jh7r
    No fix available
    Packages

    cilium-fips-1.19

    Summary

    Published
    10 Sept 2026
    Packages

    nodemailer

    Summary

    TuxCare security update for nodemailer (6 CVEs)

    Published
    10 Sept 2026
    CVE-2026-88008
    Fix available
    Packages

    Summary

    Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization

    Published
    10 Sept 2026
    CGA-95f2-2vj3-6fr3
    No fix available
    Packages

    cilium-fips-1.19-operator-azure

    Summary

    Published
    10 Sept 2026
    CGA-mhvm-fxf7-4wqr
    No fix available
    Packages

    langfuse-fips-3-worker

    Summary

    Published
    10 Sept 2026
    CGA-r6cf-xmqr-3gxw
    No fix available
    Packages

    langfuse-fips-3-worker

    Summary

    Published
    10 Sept 2026
    CGA-frmp-hw88-hr8r
    No fix available
    Packages

    datadog-agent-7.76, datadog-agent-7.76

    Summary

    Published
    10 Sept 2026
    GO-2026-6343
    Fix available
    Packages

    code.gitea.io/gitea

    Summary

    Gitea tracked-time deletion is not scoped to the requested issue in code.gitea.io/gitea

    Published
    10 Sept 2026
    GO-2026-6344
    Fix available
    Packages

    code.gitea.io/gitea

    Summary

    Gitea LFS mirror operations bypass migration HTTP transport protections in code.gitea.io/gitea

    Published
    10 Sept 2026
    GO-2026-6345
    Fix available
    Packages

    code.gitea.io/gitea

    Summary

    Gitea forwarded-proto validation allows canonical URL spoofing in code.gitea.io/gitea

    Published
    10 Sept 2026
    GO-2026-6346
    Fix available
    Packages

    code.gitea.io/gitea

    Summary

    Gitea pre-receive hook scanner errors allow branch-protection bypass in code.gitea.io/gitea

    Published
    10 Sept 2026
    GO-2026-6347
    Fix available
    Packages

    code.gitea.io/gitea

    Summary

    Gitea draft releases and attachments are exposed without write permission in code.gitea.io/gitea

    Published
    10 Sept 2026
    GO-2026-6350
    Fix available
    Packages

    github.com/siyuan-note/siyuan/kernel

    Summary

    Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db in github.com/siyuan-note/siyuan/kernel

    Published
    10 Sept 2026
    GO-2026-6351
    Fix available
    Packages

    github.com/seaweedfs/seaweedfs

    Summary

    SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control in github.com/seaweedfs/seaweedfs

    Published
    10 Sept 2026