Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    CVE-2026-84942
    Fix available
    Packages

    Summary

    Stored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch Dashboards

    Published
    8 Sept 2026
    CGA-m9cq-xpqr-pgpw
    No fix available
    Packages

    elastic-agent-fips-9.5

    Summary

    Published
    8 Sept 2026
    CVE-2026-86808
    Fix available
    Packages

    Summary

    moltis-org moltis vault.rs vault_recovery_handler missing authentication

    Published
    8 Sept 2026
    CGA-5cc7-h98x-wprf
    Fix available
    Packages

    gitlab-elasticsearch-indexer

    Summary

    Published
    8 Sept 2026
    CVE-2026-86806
    Fix available
    Packages

    Summary

    opengeos GeoLibre _is_within_roots server-side request forgery

    Published
    8 Sept 2026
    CVE-2026-86804
    Fix available
    Packages

    Summary

    seakee CPA-Manager-Plus HTTP handler.go CPAResource improper authorization

    Published
    8 Sept 2026
    CVE-2026-86716
    No fix available
    Packages

    Summary

    Cesanta mJS mjs_tok.c skip_spaces_and_comments heap-based overflow

    Published
    8 Sept 2026
    CGA-q96j-gpmv-qpgq
    No fix available
    Packages

    elastic-agent-fips-9.5

    Summary

    Published
    8 Sept 2026
    GHSA-8mcc-hrx5-hvxc
    Fix available
    Packages

    gitpython

    Summary

    GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination

    Published
    8 Sept 2026
    GHSA-5xxx-qhh7-9287
    Fix available
    Packages

    gitpython

    Summary

    GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame()

    Published
    8 Sept 2026
    GHSA-284h-m62q-gf8w
    Fix available
    Packages

    gitpython

    Summary

    GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE

    Published
    8 Sept 2026
    Packages

    @astrojs/prism, @astrojs/webapi, astro, create-astro

    Summary

    TuxCare security update for 4 packages (1 CVE)

    Published
    8 Sept 2026
    GHSA-7833-fr7j-v32q
    Fix available
    Packages

    gitpython

    Summary

    GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)

    Published
    8 Sept 2026
    GHSA-4qhr-qf46-fcrx
    Fix available
    Packages

    Microsoft.DiaSymReader.Native

    Summary

    Duplicate Advisory: Microsoft Security Advisory CVE-2026-71328 – .NET and Visual Studio Remote Code Execution Vulnerability

    Published
    8 Sept 2026
    GHSA-q72m-f2r4-w4cw
    Fix available
    Packages

    Microsoft.DiaSymReader.Native

    Summary

    Duplicate Advisory: Microsoft Security Advisory CVE-2026-69522 – .NET and Visual Studio Remote Code Execution Vulnerability

    Published
    8 Sept 2026
    GHSA-mqvm-gmc4-6rv2
    Fix available
    Packages

    Microsoft.DiaSymReader.Native

    Summary

    Duplicate Advisory: Microsoft Security Advisory CVE-2026-69439 – .NET and Visual Studio Elevation of Privilege Vulnerability

    Published
    8 Sept 2026
    GHSA-v3f6-m9j2-437p
    Fix available
    Packages

    Microsoft.AspNetCore.Server.IISIntegration, Microsoft.AspNetCore.Server.IISIntegration, Microsoft.AspNetCore.Server.IISIntegration, Microsoft.AspNetCore.Server.IISIntegration

    Summary

    Duplicate Advisory: Microsoft Security Advisory CVE-2026-69304 – ASP.NET Core Denial of Service Vulnerability

    Published
    8 Sept 2026
    USN-8739-1
    Fix available
    Packages

    imagemagick, imagemagick, imagemagick, imagemagick, imagemagick, imagemagick

    Summary

    imagemagick vulnerabilities

    Published
    8 Sept 2026
    CVE-2026-81383
    Fix available
    Packages

    Summary

    Published
    8 Sept 2026
    CVE-2026-81379
    Fix available
    Packages

    Summary

    Published
    8 Sept 2026
    CVE-2026-81378
    Fix available
    Packages

    Summary

    Published
    8 Sept 2026
    CVE-2026-81377
    Fix available
    Packages

    Summary

    Published
    8 Sept 2026
    CVE-2026-81376
    Fix available
    Packages

    Summary

    Published
    8 Sept 2026
    CVE-2026-81357
    Fix available
    Packages

    Summary

    Published
    8 Sept 2026
    CVE-2026-81356
    Fix available
    Packages

    Summary

    Published
    8 Sept 2026
    CVE-2026-78462
    Fix available
    Packages

    Summary

    Published
    8 Sept 2026
    CVE-2026-78461
    Fix available
    Packages

    Summary

    Published
    8 Sept 2026
    CVE-2026-71328
    Fix available
    Packages

    Summary

    Published
    8 Sept 2026
    CVE-2026-70334
    Fix available
    Packages

    Summary

    Published
    8 Sept 2026
    GHSA-c4c3-7fpv-j4q5
    Fix available
    Packages

    io.netty:netty-handler, io.netty:netty-handler

    Summary

    Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext

    Published
    8 Sept 2026
    GHSA-fccg-mwvh-qqg4
    Fix available
    Packages

    io.netty:netty-handler, io.netty:netty-handler

    Summary

    Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsing

    Published
    8 Sept 2026
    GHSA-6x6c-w9w9-hv4h
    Fix available
    Packages

    github.com/infracost/infracost

    Summary

    Infracost: Terraform Cloud and registry token disclosure via unvalidated hostname

    Published
    8 Sept 2026
    GHSA-mmg6-4qmv-6pc8
    Fix available
    Packages

    github.com/infracost/infracost

    Summary

    Infracost: Arbitrary file read via config-template readFile symlink traversal

    Published
    8 Sept 2026
    GHSA-p2w3-6x73-2f6x
    Fix available
    Packages

    github.com/amir20/dozzle

    Summary

    Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher

    Published
    8 Sept 2026
    GHSA-4r6h-5v86-94p3
    Fix available
    Packages

    liquidjs

    Summary

    LiquidJS: Uncontrolled Resource Consumption in `join` filter allows template authors to bypass `memoryLimit` and crash the process

    Published
    8 Sept 2026
    GHSA-c2jg-2778-ggm4
    Fix available
    Packages

    prowler, prowler-cloud

    Summary

    Prowler: Stored XSS in HTML reports through unescaped cloud resource tags

    Published
    8 Sept 2026
    CVE-2026-76200
    Fix available
    Packages

    Summary

    Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)

    Published
    8 Sept 2026
    CVE-2026-76201
    Fix available
    Packages

    Summary

    Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)

    Published
    8 Sept 2026
    CVE-2026-77109
    Fix available
    Packages

    Summary

    Adobe Commerce | Incorrect Authorization (CWE-863)

    Published
    8 Sept 2026
    CVE-2026-77110
    Fix available
    Packages

    Summary

    Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)

    Published
    8 Sept 2026
    CVE-2026-77108
    Fix available
    Packages

    Summary

    Adobe Commerce | Incorrect Authorization (CWE-863)

    Published
    8 Sept 2026
    CVE-2026-76202
    Fix available
    Packages

    Summary

    Adobe Commerce | Incorrect Authorization (CWE-863)

    Published
    8 Sept 2026
    CVE-2026-77774
    Fix available
    Packages

    Summary

    Adobe Commerce | Incorrect Authorization (CWE-863)

    Published
    8 Sept 2026
    CVE-2026-77111
    Fix available
    Packages

    Summary

    Adobe Commerce | Incorrect Authorization (CWE-863)

    Published
    8 Sept 2026
    GHSA-8cw4-87c7-c6xx
    Fix available
    Packages

    csv-parse

    Summary

    node-csv: Prototype replacement still reachable via columns path

    Published
    8 Sept 2026
    GHSA-5qr2-v392-m9g8
    Fix available
    Packages

    @swc/html, swc_html_minifier

    Summary

    SWC HTML minifier may allow script element breakout when minifying embedded JSON

    Published
    8 Sept 2026
    GHSA-xp7j-h7jc-4w8p
    Fix available
    Packages

    github.com/semaphoreui/semaphore

    Summary

    Semaphore U: OS Command Injection

    Published
    8 Sept 2026
    GHSA-rcr6-4jqh-j84m
    Fix available
    Packages

    gitea.dev

    Summary

    Gitea: Remote Code Execution via diffpatch Git Hook Installation

    Published
    8 Sept 2026
    GHSA-v684-q882-jgmq
    Fix available
    Packages

    github.com/siyuan-note/siyuan/kernel

    Summary

    SiYuan: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlocked

    Published
    8 Sept 2026
    Packages

    io.undertow:undertow-benchmarks, io.undertow:undertow-core, io.undertow:undertow-dist, io.undertow:undertow-examples, io.undertow:undertow-parent, io.undertow:undertow-parser-generator, io.undertow:undertow-servlet, io.undertow:undertow-websockets-jsr

    Summary

    TuxCare security update for io.undertow (1 CVE)

    Published
    8 Sept 2026