Open Source Vulnerabilities
Tesseract: Out-of-bounds write in UnicharCompress via unvalidated recoder code values
Tesseract: Out-of-bounds write in UnicharCompress via unvalidated recoder code values
Tesseract: Heap out-of-bounds write in LSTM::Forward via na_/gate-matrix dimension mismatch
Tesseract: Heap out-of-bounds write in LSTM::Forward via na_/gate-matrix dimension mismatch
Tesseract: Heap out-of-bounds write/read in FullyConnected::Forward via layer/weight-matrix dimension mismatch
Tesseract: Heap out-of-bounds write/read in FullyConnected::Forward via layer/weight-matrix dimension mismatch
Tesseract: ReadNormProtos stack buffer overflow
rclone: source object names can escape the configured root on upload
rclone: source object names can escape the configured root on upload
rclone: S3 multipart declared-length memory exhaustion
rclone: RC per-server auth-proxy bypass
Low-privilege RCE through element-search eager loading
openssl, openssl-3, nodejs24
Security update for openssl, openssl-3
openssl/ openssl-3/ nodejs24
Security update for openssl, openssl-3
rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass
rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass
beets, beets, beets, beets, beets, beets
beets vulnerability
rclone: FTP cross-session auth-proxy backend confusion
rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination
rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination
rclone local: crafted Range request against a translated symlink panics (DoS)
rclone local: crafted Range request against a translated symlink panics (DoS)
libebml, libebml, libebml, libebml
libebml vulnerability
rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace
rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace
org.springframework.security:spring-security-core
Anchor CMS through 0.12.7 Privilege Escalation via Missing Authorization on Admin User-Management Endpoints
Anchor CMS through 0.12.7 Privilege Escalation via Missing Authorization on Admin User-Management Endpoints
rclone: http backend forwards custom/auth headers to a different host on redirect
rclone: http backend forwards custom/auth headers to a different host on redirect
kissfft, kissfft, kissfft
kissfft vulnerabilities
Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded
Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded
linux-nvidia-6.17
linux-nvidia-6.17 vulnerabilities
Traefik: ForwardAuth identity spoofing via dot-form header alias
Traefik: ForwardAuth identity spoofing via dot-form header alias
knowns through 0.33.0 Arbitrary Directory Enumeration via workspace browse endpoint
knowns through 0.33.0 Arbitrary Directory Enumeration via workspace browse endpoint
knowns through 0.33.0 Authorization Bypass via project.set Bootstrap Exemption
knowns through 0.33.0 Authorization Bypass via project.set Bootstrap Exemption
knowns through 0.33.0 Path Traversal via code.find MCP tool
knowns through 0.33.0 Path Traversal via code.find MCP tool
knowns through 0.33.0 Path Traversal via Template Engine
knowns before 0.31.0 External Control of Agent Working Directory via x-opencode-directory Header
knowns before 0.31.0 External Control of Agent Working Directory via x-opencode-directory Header
cilium-fips-1.19-operator-generic
n8n, n8n, n8n
n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Node
n8n/ n8n/ n8n
n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Node
n8n, n8n, n8n
n8n: Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a Git Node Clone Path
n8n/ n8n/ n8n
n8n: Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a Git Node Clone Path
n8n, n8n
n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint
n8n/ n8n
n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint
n8n, n8n, n8n
n8n: Expression Sandbox Escape via Class-Field Sanitizer Rebinding Can Lead to Code Execution
n8n/ n8n/ n8n
n8n: Expression Sandbox Escape via Class-Field Sanitizer Rebinding Can Lead to Code Execution
open-webui
Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends
open-webui
Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends
open-webui
Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint
open-webui
Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint
open-webui
Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin
open-webui
Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin
open-webui
Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader
open-webui
Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader
