Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    GHSA-74pj-6g7r-j55c
    Fix available
    Packages

    github.com/siyuan-note/siyuan/kernel

    Summary

    SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo

    Published
    8 Sept 2026
    GHSA-57v5-wqx3-cgj4
    Fix available
    Packages

    github.com/siyuan-note/siyuan/kernel

    Summary

    SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAttributeViewFieldViews

    Published
    8 Sept 2026
    CVE-2026-86074
    Fix available
    Packages

    Summary

    n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content

    Published
    8 Sept 2026
    CVE-2026-86670
    No fix available
    Packages

    Summary

    aircheng-org iWebShop-5 Authentication Storage admin.php weak password hash

    Published
    8 Sept 2026
    CVE-2026-48707
    Fix available
    Packages

    Summary

    InstantCMS vulnerable to SSRF via upload redirect bypass allows internal network service scanning

    Published
    8 Sept 2026
    USN-8670-3
    Fix available
    Packages

    curl

    Summary

    curl vulnerability

    Published
    8 Sept 2026
    CVE-2026-54611
    Fix available
    Packages

    Summary

    InstantCMS has Remote Code Execution in package installer

    Published
    8 Sept 2026
    Packages

    org.thymeleaf.extras:thymeleaf-extras-springsecurity5, org.thymeleaf.extras:thymeleaf-extras-springsecurity6, org.thymeleaf.testing:thymeleaf-testing, org.thymeleaf.testing:thymeleaf-testing-lib, org.thymeleaf.testing:thymeleaf-testing-spring5, org.thymeleaf.testing:thymeleaf-testing-spring6, org.thymeleaf:thymeleaf-lib, org.thymeleaf:thymeleaf-parent, org.thymeleaf:thymeleaf-spring5, org.thymeleaf:thymeleaf-spring6

    Summary

    TuxCare security update for 10 packages (1 CVE)

    Published
    8 Sept 2026
    CVE-2026-86669
    No fix available
    Packages

    Summary

    aircheng-org iWebShop-5 systemseller.php login improper authentication

    Published
    8 Sept 2026
    CVE-2026-72923
    Fix available
    Packages

    Summary

    Microsoft.OpenApi.YamlReader/Readers vulnerable to denial of service via YAML alias expansion

    Published
    8 Sept 2026
    USN-8679-2
    Fix available
    Packages

    vim

    Summary

    vim vulnerability

    Published
    8 Sept 2026
    CGA-cqh5-mfcq-j683
    Fix available
    Packages

    grafana-cloudmonitoring-datasource

    Summary

    Published
    8 Sept 2026
    Packages

    jinja2

    Summary

    TuxCare security update for jinja2 (2 CVEs)

    Published
    8 Sept 2026
    Packages

    scikit-learn

    Summary

    TuxCare security update for scikit-learn (1 CVE)

    Published
    8 Sept 2026
    CVE-2026-86073
    Fix available
    Packages

    Summary

    n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution

    Published
    8 Sept 2026
    USN-8738-1
    Fix available
    Packages

    ffmpeg

    Summary

    ffmpeg vulnerabilities

    Published
    8 Sept 2026
    CVE-2026-82533
    Fix available
    Packages

    Summary

    DeepSeek Harness < 0.1.2-alpha.1 Authentication Bypass via Host Header Spoofing

    Published
    8 Sept 2026
    GHSA-3gq4-3j92-5w49
    Fix available
    Packages

    nltk

    Summary

    NLTK: Corpus Reader Sandbox Bypass

    Published
    8 Sept 2026
    GHSA-p4rw-rvv2-7xwr
    Fix available
    Packages

    nltk

    Summary

    NLTK: Corpus readers follow symlinks outside trusted roots despite pathsec enforcement

    Published
    8 Sept 2026
    Packages

    govulncheck-vulndb

    Summary

    Security update for govulncheck-vulndb

    Published
    8 Sept 2026
    CVE-2026-75156
    Fix available
    Packages

    Summary

    Apache Airflow FAB provider: FAB Azure AD OAuth: id_token issuer/audience not validated — cross-tenant authentication bypass

    Published
    8 Sept 2026
    CGA-7673-6w8c-q6j9
    Fix available
    Packages

    grafana-clickhouse-datasource

    Summary

    Published
    8 Sept 2026
    CVE-2026-86668
    No fix available
    Packages

    Summary

    aircheng-org iWebShop-5 pic.php uploadFile cross site scripting

    Published
    8 Sept 2026
    GHSA-x99w-6fgc-pmfw
    Fix available
    Packages

    nltk

    Summary

    NLTK: Allowlisted pickle loaders still permit code execution in current source

    Published
    8 Sept 2026
    CVE-2026-78216
    Fix available
    Packages

    Summary

    AshLua eval read operations can read field-policy-protected fields via aggregates

    Published
    8 Sept 2026
    EEF-CVE-2026-78216
    Fix available
    Packages

    ash_lua,

    Summary

    AshLua eval read operations can read field-policy-protected fields via aggregates

    Published
    8 Sept 2026
    GHSA-97qj-x29f-37w7
    Fix available
    Packages

    nltk

    Summary

    NLTK: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parses

    Published
    8 Sept 2026
    CVE-2026-78230
    Fix available
    Packages

    Summary

    AshAi aggregate tool can read field-policy-protected fields

    Published
    8 Sept 2026
    EEF-CVE-2026-78230
    Fix available
    Packages

    ash_ai,

    Summary

    AshAi aggregate tool can read field-policy-protected fields

    Published
    8 Sept 2026
    GHSA-6ww7-3frv-cqxh
    Fix available
    Packages

    nltk

    Summary

    NLTK: pathsec SSRF protection can be bypassed when a proxy is configured

    Published
    8 Sept 2026
    GHSA-rhp5-r9x4-f5g2
    Fix available
    Packages

    nltk

    Summary

    NLTK: Unsafe Pickle Deserialization in TransitionParser Allows Remote Code Execution

    Published
    8 Sept 2026
    GHSA-3hhw-38pf-pxj6
    Fix available
    Packages

    nltk

    Summary

    NLTK: Symlink-based arbitrary file read in IPIPANCorpusReader, bypasses nltk.pathsec entirely

    Published
    8 Sept 2026
    GHSA-f833-7jw8-xwrv
    Fix available
    Packages

    nltk

    Summary

    NLTK: Symlink-based sandbox bypass in FramenetCorpusReader (bypasses the fix for CVE-2026-54292)

    Published
    8 Sept 2026
    GHSA-568f-pv23-39p4
    Fix available
    Packages

    nltk

    Summary

    NLTK: Stable FrameNet and NKJP readers parse outside-root XML

    Published
    8 Sept 2026
    SUSE-SU-2026:4093-1
    Fix available
    Packages

    multipath-tools

    Summary

    Security update for multipath-tools

    Published
    8 Sept 2026
    SUSE-SU-2026:4092-1
    Fix available
    Packages

    libzypp, zypper

    Summary

    Security update for libzypp, zypper

    Published
    8 Sept 2026
    CVE-2026-86667
    No fix available
    Packages

    Summary

    aircheng-org iWebShop-5 member.php member_list sql injection

    Published
    8 Sept 2026
    CGA-h6cf-j8c7-g8h3
    Fix available
    Packages

    grafana-mssql-datasource

    Summary

    Published
    8 Sept 2026
    CVE-2026-86666
    No fix available
    Packages

    Summary

    aircheng-org iWebShop-5 pic.php uploadFile unrestricted upload

    Published
    8 Sept 2026
    CGA-pcjv-r868-xpgx
    Fix available
    Packages

    grafana-cloudmonitoring-datasource

    Summary

    Published
    8 Sept 2026
    CVE-2026-86600
    Fix available
    Packages

    Summary

    Workload identity attestation generated before login host validation in Snowflake drivers

    Published
    8 Sept 2026
    CGA-3rw3-vp2f-g6h6
    Fix available
    Packages

    percona-grafana

    Summary

    Published
    8 Sept 2026
    CGA-jq22-5wcq-j452
    No fix available
    Packages

    percona-grafana

    Summary

    Published
    8 Sept 2026
    CGA-57j6-7vj7-x63v
    No fix available
    Packages

    percona-grafana

    Summary

    Published
    8 Sept 2026
    CGA-x33x-6hg2-qhqv
    No fix available
    Packages

    percona-grafana

    Summary

    Published
    8 Sept 2026
    CGA-qfg9-mpfh-5jw5
    No fix available
    Packages

    percona-grafana

    Summary

    Published
    8 Sept 2026
    CGA-mjcx-fx7g-qrgw
    No fix available
    Packages

    percona-grafana

    Summary

    Published
    8 Sept 2026
    CGA-hq69-532q-h7x5
    No fix available
    Packages

    percona-grafana

    Summary

    Published
    8 Sept 2026
    CGA-h377-4356-fq6c
    No fix available
    Packages

    percona-grafana

    Summary

    Published
    8 Sept 2026
    CGA-7725-xrgv-8x2j
    No fix available
    Packages

    percona-grafana

    Summary

    Published
    8 Sept 2026