Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    CVE-2026-88050
    No fix available
    Packages

    Summary

    Tesseract: Out-of-bounds write in UnicharCompress via unvalidated recoder code values

    Published
    10 Sept 2026
    CVE-2026-88049
    No fix available
    Packages

    Summary

    Tesseract: Heap out-of-bounds write in LSTM::Forward via na_/gate-matrix dimension mismatch

    Published
    10 Sept 2026
    CVE-2026-88048
    No fix available
    Packages

    Summary

    Tesseract: Heap out-of-bounds write/read in FullyConnected::Forward via layer/weight-matrix dimension mismatch

    Published
    10 Sept 2026
    DEBIAN-CVE-2026-88018
    No fix available
    Packages

    rclone, rclone

    Summary

    Published
    10 Sept 2026
    DEBIAN-CVE-2026-88017
    No fix available
    Packages

    rclone, rclone

    Summary

    Published
    10 Sept 2026
    DEBIAN-CVE-2026-88016
    No fix available
    Packages

    rclone, rclone

    Summary

    Published
    10 Sept 2026
    DEBIAN-CVE-2026-88015
    No fix available
    Packages

    rclone, rclone

    Summary

    Published
    10 Sept 2026
    DEBIAN-CVE-2026-88014
    No fix available
    Packages

    rclone, rclone

    Summary

    Published
    10 Sept 2026
    DEBIAN-CVE-2026-88013
    No fix available
    Packages

    rclone, rclone

    Summary

    Published
    10 Sept 2026
    CVE-2026-88047
    No fix available
    Packages

    Summary

    Tesseract: ReadNormProtos stack buffer overflow

    Published
    10 Sept 2026
    CVE-2026-88046
    Fix available
    Packages

    Summary

    rclone: source object names can escape the configured root on upload

    Published
    10 Sept 2026
    CVE-2026-88045
    Fix available
    Packages

    Summary

    rclone: S3 multipart declared-length memory exhaustion

    Published
    10 Sept 2026
    CVE-2026-88044
    Fix available
    Packages

    Summary

    rclone: RC per-server auth-proxy bypass

    Published
    10 Sept 2026
    CGA-p4xp-h6hq-3q64
    No fix available
    Packages

    cilium-fips-1.19-host-utils

    Summary

    Published
    10 Sept 2026
    CVE-2026-79987
    Fix available
    Packages

    Summary

    Low-privilege RCE through element-search eager loading

    Published
    10 Sept 2026
    SUSE-SU-2026:3835-1
    Fix available
    Packages

    openssl, openssl-3, nodejs24

    Summary

    Security update for openssl, openssl-3

    Published
    10 Sept 2026
    CVE-2026-88018
    Fix available
    Packages

    Summary

    rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass

    Published
    10 Sept 2026
    USN-8747-1
    Fix available
    Packages

    beets, beets, beets, beets, beets, beets

    Summary

    beets vulnerability

    Published
    10 Sept 2026
    CVE-2026-88017
    Fix available
    Packages

    Summary

    rclone: FTP cross-session auth-proxy backend confusion

    Published
    10 Sept 2026
    CVE-2026-88016
    Fix available
    Packages

    Summary

    rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination

    Published
    10 Sept 2026
    CVE-2026-88015
    Fix available
    Packages

    Summary

    rclone local: crafted Range request against a translated symlink panics (DoS)

    Published
    10 Sept 2026
    USN-8746-1
    Fix available
    Packages

    libebml, libebml, libebml, libebml

    Summary

    libebml vulnerability

    Published
    10 Sept 2026
    CVE-2026-88014
    Fix available
    Packages

    Summary

    rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace

    Published
    10 Sept 2026
    ECHO-697c-1fee-1fce
    Fix available
    Packages

    org.springframework.security:spring-security-core

    Summary

    Published
    10 Sept 2026
    CGA-qp39-2g5g-qr7m
    No fix available
    Packages

    consul-k8s-1.6-cli

    Summary

    Published
    10 Sept 2026
    CVE-2026-88959
    No fix available
    Packages

    Summary

    Anchor CMS through 0.12.7 Privilege Escalation via Missing Authorization on Admin User-Management Endpoints

    Published
    10 Sept 2026
    CVE-2026-88013
    Fix available
    Packages

    Summary

    rclone: http backend forwards custom/auth headers to a different host on redirect

    Published
    10 Sept 2026
    USN-8745-1
    Fix available
    Packages

    kissfft, kissfft, kissfft

    Summary

    kissfft vulnerabilities

    Published
    10 Sept 2026
    CGA-j9m2-5gr2-6fvr
    No fix available
    Packages

    telegraf-1.40

    Summary

    Published
    10 Sept 2026
    CGA-4fcf-x8qc-v8x6
    No fix available
    Packages

    telegraf-1.40

    Summary

    Published
    10 Sept 2026
    CVE-2026-88012
    Fix available
    Packages

    Summary

    Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded

    Published
    10 Sept 2026
    USN-8748-1
    Fix available
    Packages

    linux-nvidia-6.17

    Summary

    linux-nvidia-6.17 vulnerabilities

    Published
    10 Sept 2026
    CVE-2026-88011
    Fix available
    Packages

    Summary

    Traefik: ForwardAuth identity spoofing via dot-form header alias

    Published
    10 Sept 2026
    CVE-2026-88940
    No fix available
    Packages

    Summary

    knowns through 0.33.0 Arbitrary Directory Enumeration via workspace browse endpoint

    Published
    10 Sept 2026
    CVE-2026-88939
    No fix available
    Packages

    Summary

    knowns through 0.33.0 Authorization Bypass via project.set Bootstrap Exemption

    Published
    10 Sept 2026
    CVE-2026-88938
    No fix available
    Packages

    Summary

    knowns through 0.33.0 Path Traversal via code.find MCP tool

    Published
    10 Sept 2026
    CVE-2026-88937
    No fix available
    Packages

    Summary

    knowns through 0.33.0 Path Traversal via Template Engine

    Published
    10 Sept 2026
    CVE-2026-88899
    Fix available
    Packages

    Summary

    knowns before 0.31.0 External Control of Agent Working Directory via x-opencode-directory Header

    Published
    10 Sept 2026
    DEBIAN-CVE-2026-88924
    No fix available
    Packages

    gvfs, gvfs, gvfs

    Summary

    Published
    10 Sept 2026
    Packages

    suricata, suricata

    Summary

    Published
    10 Sept 2026
    Packages

    suricata, suricata

    Summary

    Published
    10 Sept 2026
    CGA-hp5j-5vg6-h48m
    No fix available
    Packages

    cilium-fips-1.19-operator-generic

    Summary

    Published
    10 Sept 2026
    GHSA-34ff-336r-5q23
    Fix available
    Packages

    n8n, n8n, n8n

    Summary

    n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Node

    Published
    10 Sept 2026
    GHSA-j535-v25q-vx3q
    Fix available
    Packages

    n8n, n8n, n8n

    Summary

    n8n: Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a Git Node Clone Path

    Published
    10 Sept 2026
    GHSA-hh89-3r9w-qj3j
    Fix available
    Packages

    n8n, n8n

    Summary

    n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint

    Published
    10 Sept 2026
    GHSA-hw8v-xxg5-vvvx
    Fix available
    Packages

    n8n, n8n, n8n

    Summary

    n8n: Expression Sandbox Escape via Class-Field Sanitizer Rebinding Can Lead to Code Execution

    Published
    10 Sept 2026
    GHSA-pcvc-8vrv-8q6w
    Fix available
    Packages

    open-webui

    Summary

    Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends

    Published
    10 Sept 2026
    GHSA-fmqh-xp37-5hr8
    Fix available
    Packages

    open-webui

    Summary

    Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint

    Published
    10 Sept 2026
    GHSA-jmc6-2wr8-h3wj
    Fix available
    Packages

    open-webui

    Summary

    Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin

    Published
    10 Sept 2026
    GHSA-4v28-j6q3-5m4r
    Fix available
    Packages

    open-webui

    Summary

    Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader

    Published
    10 Sept 2026