Go incidents
Recent Go vulnerabilities and malicious packages from OSV and CISA KEV, enriched with EPSS exploit probability.
ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider
ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider
ZITADEL: Auto-linking by email: IdP-side email verification is not checked
ZITADEL: Auto-linking by email: IdP-side email verification is not checked
Infracost: Terraform Cloud and registry token disclosure via unvalidated hostname in github.com/infracost/infracost
Infracost: Terraform Cloud and registry token disclosure via unvalidated hostname in github.com/infracost/infracost
Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock match in github.com/cilium/cilium
Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock match in github.com/cilium/cilium
SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check in github.com/siyuan-note/siyuan/kernel
SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check in github.com/siyuan-note/siyuan/kernel
Gitea draft releases and attachments are exposed without write permission in code.gitea.io/gitea
Gitea draft releases and attachments are exposed without write permission in code.gitea.io/gitea
SiYuan: Missing publish-access filter on getBlockAttrs and batchGetBlockAttrs discloses block attributes (name, alias, memo, custom fields) of protected documents in github.com/siyuan-note/siyuan/kernel
SiYuan: Missing publish-access filter on getBlockAttrs and batchGetBlockAttrs discloses block attributes (name, alias, memo, custom fields) of protected documents in github.com/siyuan-note/siyuan/kernel
OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass) in github.com/openchoreo/openchoreo
OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass) in github.com/openchoreo/openchoreo
Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection in github.com/axllent/mailpit
Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection in github.com/axllent/mailpit
SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write in github.com/siyuan-note/siyuan/kernel
SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write in github.com/siyuan-note/siyuan/kernel
Semaphore U: OS Command Injection in github.com/semaphoreui/semaphore
Semaphore U: OS Command Injection in github.com/semaphoreui/semaphore
SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf in github.com/siyuan-note/siyuan/kernel
SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf in github.com/siyuan-note/siyuan/kernel
SiYuan: Missing authorization on refreshBacklink allows anonymous readers to trigger persistent server-side writes and unauthenticated resource amplification (publish mode) in github.com/siyuan-note/siyuan/kernel
SiYuan: Missing authorization on refreshBacklink allows anonymous readers to trigger persistent server-side writes and unauthenticated resource amplification (publish mode) in github.com/siyuan-note/siyuan/kernel
SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f) in github.com/siyuan-note/siyuan/kernel
SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f) in github.com/siyuan-note/siyuan/kernel
OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs in github.com/openchoreo/openchoreo
OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs in github.com/openchoreo/openchoreo
Gitea tracked-time deletion is not scoped to the requested issue in code.gitea.io/gitea
Gitea tracked-time deletion is not scoped to the requested issue in code.gitea.io/gitea
rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass
rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass
SiYuan: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeration oracles (publish mode) in github.com/siyuan-note/siyuan/kernel
SiYuan: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeration oracles (publish mode) in github.com/siyuan-note/siyuan/kernel
Traefik: ForwardAuth identity spoofing via dot-form header alias
Traefik: ForwardAuth identity spoofing via dot-form header alias
SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers in github.com/siyuan-note/siyuan/kernel
SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers in github.com/siyuan-note/siyuan/kernel
Gitea LFS mirror operations bypass migration HTTP transport protections in code.gitea.io/gitea
Gitea LFS mirror operations bypass migration HTTP transport protections in code.gitea.io/gitea
SiYuan: Localhost-trust admin bypass on auth-code-gated endpoints, with potential remote reachability via the fixed-port proxy in github.com/siyuan-note/siyuan/kernel
SiYuan: Localhost-trust admin bypass on auth-code-gated endpoints, with potential remote reachability via the fixed-port proxy in github.com/siyuan-note/siyuan/kernel
SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling paths in github.com/seaweedfs/seaweedfs
SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling paths in github.com/seaweedfs/seaweedfs
SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers in github.com/siyuan-note/siyuan/kernel
SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers in github.com/siyuan-note/siyuan/kernel
rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace
rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace
ffuf denial of service (OOM) via HTTP response decompression bomb in github.com/ffuf/ffuf
ffuf denial of service (OOM) via HTTP response decompression bomb in github.com/ffuf/ffuf
SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode) in github.com/siyuan-note/siyuan/kernel
SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode) in github.com/siyuan-note/siyuan/kernel
rclone: S3 multipart declared-length memory exhaustion
rclone: S3 multipart declared-length memory exhaustion
Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db in github.com/siyuan-note/siyuan/kernel
Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db in github.com/siyuan-note/siyuan/kernel
rclone: RC per-server auth-proxy bypass
rclone: RC per-server auth-proxy bypass
SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content in github.com/siyuan-note/siyuan/kernel
SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content in github.com/siyuan-note/siyuan/kernel
SiYuan: Cross-boundary metadata disclosure via getBlockInfo (publish mode): reader-reachable document title/root info for publish-forbidden docs; sibling getDocInfo is filtered in github.com/siyuan-note/siyuan/kernel
SiYuan: Cross-boundary metadata disclosure via getBlockInfo (publish mode): reader-reachable document title/root info for publish-forbidden docs; sibling getDocInfo is filtered in github.com/siyuan-note/siyuan/kernel
SiYuan: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline master-password cracking in github.com/siyuan-note/siyuan/kernel
SiYuan: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline master-password cracking in github.com/siyuan-note/siyuan/kernel
Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing path-scoped routing, middleware guards and access logging
Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing path-scoped routing, middleware guards and access logging
rclone: http backend forwards custom/auth headers to a different host on redirect
rclone: http backend forwards custom/auth headers to a different host on redirect
SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure in github.com/siyuan-note/siyuan/kernel
SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure in github.com/siyuan-note/siyuan/kernel
SiYuan: Non-administrator responses from /api/system/getConf omit three secrets that the configuration-export path explicitly strips, disclosing the session-cookie signing key and the OS username to anonymous readers in github.com/siyuan-note/siyuan/kernel
SiYuan: Non-administrator responses from /api/system/getConf omit three secrets that the configuration-export path explicitly strips, disclosing the session-cookie signing key and the OS username to anonymous readers in github.com/siyuan-note/siyuan/kernel
rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination
rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination
OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints in github.com/openchoreo/openchoreo
OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints in github.com/openchoreo/openchoreo
SiYuan: Absolute filesystem path and OS username disclosure via resolveAssetPath in github.com/siyuan-note/siyuan/kernel
SiYuan: Absolute filesystem path and OS username disclosure via resolveAssetPath in github.com/siyuan-note/siyuan/kernel
Traefik entrypoint header-name sanitization bypassed via request trailers
Traefik entrypoint header-name sanitization bypassed via request trailers
SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-forbidden docs; sibling list endpoints are filtered in github.com/siyuan-note/siyuan/kernel
SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-forbidden docs; sibling list endpoints are filtered in github.com/siyuan-note/siyuan/kernel
SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers in github.com/siyuan-note/siyuan/kernel
SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers in github.com/siyuan-note/siyuan/kernel
rclone: source object names can escape the configured root on upload
rclone: source object names can escape the configured root on upload
SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAttributeViewFieldViews in github.com/siyuan-note/siyuan/kernel
SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAttributeViewFieldViews in github.com/siyuan-note/siyuan/kernel
SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB in github.com/siyuan-note/siyuan/kernel
SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB in github.com/siyuan-note/siyuan/kernel
SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass in github.com/siyuan-note/siyuan/kernel
SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass in github.com/siyuan-note/siyuan/kernel
rclone: FTP cross-session auth-proxy backend confusion
rclone: FTP cross-session auth-proxy backend confusion
SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo in github.com/siyuan-note/siyuan/kernel
SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo in github.com/siyuan-note/siyuan/kernel
Gitea pre-receive hook scanner errors allow branch-protection bypass in code.gitea.io/gitea
Gitea pre-receive hook scanner errors allow branch-protection bypass in code.gitea.io/gitea
Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization
Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization
OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged pods in github.com/openchoreo/openchoreo
OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged pods in github.com/openchoreo/openchoreo
Gitea forwarded-proto validation allows canonical URL spoofing in code.gitea.io/gitea
Gitea forwarded-proto validation allows canonical URL spoofing in code.gitea.io/gitea
SiYuan: Missing publish-access filter on getFileAnnotation discloses private PDF annotations of forbidden/protected documents (publish mode) in github.com/siyuan-note/siyuan/kernel
SiYuan: Missing publish-access filter on getFileAnnotation discloses private PDF annotations of forbidden/protected documents (publish mode) in github.com/siyuan-note/siyuan/kernel
Traefik HTTP/3 Backend NTLM Connection Reuse
Traefik HTTP/3 Backend NTLM Connection Reuse
Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded
Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded
Infracost: Arbitrary file read via config-template readFile symlink traversal in github.com/infracost/infracost
Infracost: Arbitrary file read via config-template readFile symlink traversal in github.com/infracost/infracost
SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel in github.com/siyuan-note/siyuan/kernel
SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel in github.com/siyuan-note/siyuan/kernel
SiYuan: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns in github.com/siyuan-note/siyuan/kernel
SiYuan: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns in github.com/siyuan-note/siyuan/kernel
SiYuan: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents without the password (publish mode) in github.com/siyuan-note/siyuan/kernel
SiYuan: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents without the password (publish mode) in github.com/siyuan-note/siyuan/kernel
Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation in github.com/semaphoreui/semaphore
Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation in github.com/semaphoreui/semaphore
Gitea: Remote Code Execution via diffpatch Git Hook Installation in gitea.dev
Gitea: Remote Code Execution via diffpatch Git Hook Installation in gitea.dev
Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling in github.com/axllent/mailpit
Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling in github.com/axllent/mailpit
OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation in github.com/openchoreo/openchoreo
OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation in github.com/openchoreo/openchoreo
Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision in github.com/semaphoreui/semaphore
Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision in github.com/semaphoreui/semaphore
SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle in github.com/siyuan-note/siyuan/kernel
SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle in github.com/siyuan-note/siyuan/kernel
SiYuan: getEncryptedNotebookStatus discloses names and current lock/unlock state of all encrypted notebooks to anonymous readers in github.com/siyuan-note/siyuan/kernel
SiYuan: getEncryptedNotebookStatus discloses names and current lock/unlock state of all encrypted notebooks to anonymous readers in github.com/siyuan-note/siyuan/kernel
MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints in github.com/googleapis/mcp-toolbox
MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints in github.com/googleapis/mcp-toolbox
SiYuan: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlocked in github.com/siyuan-note/siyuan/kernel
SiYuan: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlocked in github.com/siyuan-note/siyuan/kernel
SiYuan: Missing publish-access check on getBlockBreadcrumb, getRefText, and getBlockTreeInfos discloses content and metadata of protected/forbidden documents in github.com/siyuan-note/siyuan/kernel
SiYuan: Missing publish-access check on getBlockBreadcrumb, getRefText, and getBlockTreeInfos discloses content and metadata of protected/forbidden documents in github.com/siyuan-note/siyuan/kernel
rclone local: crafted Range request against a translated symlink panics (DoS)
rclone local: crafted Range request against a translated symlink panics (DoS)
SiYuan: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including protected/forbidden documents (publish mode) in github.com/siyuan-note/siyuan/kernel
SiYuan: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including protected/forbidden documents (publish mode) in github.com/siyuan-note/siyuan/kernel
SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password in github.com/siyuan-note/siyuan/kernel
SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password in github.com/siyuan-note/siyuan/kernel
SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents in github.com/siyuan-note/siyuan/kernel
SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents in github.com/siyuan-note/siyuan/kernel
SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control in github.com/seaweedfs/seaweedfs
SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control in github.com/seaweedfs/seaweedfs
Excelize: Streaming GetRows row-bound bypass causes attacker-controlled allocation
Excelize: Streaming GetRows row-bound bypass causes attacker-controlled allocation
Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher in github.com/amir20/dozzle
Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher in github.com/amir20/dozzle
Excelize: Negative shared-string index causes panic in GetCellValue and GetRows
Excelize: Negative shared-string index causes panic in GetCellValue and GetRows
OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool in github.com/OpenListTeam/OpenList
OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool in github.com/OpenListTeam/OpenList
Komari: Management Interface CSRF
Komari: Management Interface CSRF
containerd: CRI ExecSync Goroutine Leak Leads to Node-Level Denial of Service
containerd: CRI ExecSync Goroutine Leak Leads to Node-Level Denial of Service
LF Edge eKuiper: Self-XSS in External Service Creation
LF Edge eKuiper: Self-XSS in External Service Creation
Signature verification TOCTOU allows installing unverified package content in github.com/crossplane/crossplane-runtime/v2
Signature verification TOCTOU allows installing unverified package content in github.com/crossplane/crossplane-runtime/v2
Identrail Cross-tenant IDOR: Client-supplied GitHub App installation_id is bound to the caller's workspace without ownership verification
Identrail Cross-tenant IDOR: Client-supplied GitHub App installation_id is bound to the caller's workspace without ownership verification
webhookd: Unrestricted HTTP Header to Shell Variable Injection
webhookd: Unrestricted HTTP Header to Shell Variable Injection
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
LF Edge eKuiper: SSRF in External Service
LF Edge eKuiper: SSRF in External Service
Joker linter executed project-local .jokerd/linter.* files during linting
Joker linter executed project-local .jokerd/linter.* files during linting
Infracost: Arbitrary file read via config-template readFile symlink traversal
Infracost: Arbitrary file read via config-template readFile symlink traversal
gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers
gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers
Semaphore U: OS Command Injection
Semaphore U: OS Command Injection
Infracost: Terraform Cloud and registry token disclosure via unvalidated hostname
Infracost: Terraform Cloud and registry token disclosure via unvalidated hostname
Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher
Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher
SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAttributeViewFieldViews
SiYuan: Database view structure (all view names, layout types and per-field visibility) is returned to anonymous readers by /api/av/getAttributeViewFieldViews
SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo
SiYuan: Notebook name, document count, size and timestamps are returned for any notebook, including notebooks hidden from readers, by /api/notebook/getNotebookInfo
Gitea: Remote Code Execution via diffpatch Git Hook Installation
Gitea: Remote Code Execution via diffpatch Git Hook Installation
SiYuan: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlocked
SiYuan: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlocked
gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion
gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion
SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers
SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers
SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password
SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password
SiYuan: getEncryptedNotebookStatus discloses names and current lock/unlock state of all encrypted notebooks to anonymous readers
SiYuan: getEncryptedNotebookStatus discloses names and current lock/unlock state of all encrypted notebooks to anonymous readers
SiYuan: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns
SiYuan: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns
SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers
SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers
OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation
OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation
SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers
SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers
SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf
SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf
SiYuan: Non-administrator responses from /api/system/getConf omit three secrets that the configuration-export path explicitly strips, disclosing the session-cookie signing key and the OS username to anonymous readers
SiYuan: Non-administrator responses from /api/system/getConf omit three secrets that the configuration-export path explicitly strips, disclosing the session-cookie signing key and the OS username to anonymous readers
SiYuan: Missing authorization on refreshBacklink allows anonymous readers to trigger persistent server-side writes and unauthenticated resource amplification (publish mode)
SiYuan: Missing authorization on refreshBacklink allows anonymous readers to trigger persistent server-side writes and unauthenticated resource amplification (publish mode)
SiYuan: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline master-password cracking
SiYuan: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline master-password cracking
SiYuan: Missing publish-access filter on getBlockAttrs and batchGetBlockAttrs discloses block attributes (name, alias, memo, custom fields) of protected documents
SiYuan: Missing publish-access filter on getBlockAttrs and batchGetBlockAttrs discloses block attributes (name, alias, memo, custom fields) of protected documents
SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-forbidden docs; sibling list endpoints are filtered
SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-forbidden docs; sibling list endpoints are filtered
SiYuan: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeration oracles (publish mode)
SiYuan: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeration oracles (publish mode)
SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f)
SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f)
SiYuan: Localhost-trust admin bypass on auth-code-gated endpoints, with potential remote reachability via the fixed-port proxy
SiYuan: Localhost-trust admin bypass on auth-code-gated endpoints, with potential remote reachability via the fixed-port proxy
SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write
SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write
SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents
SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents
Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision
Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision
amqp091-go has a Potential Memory Exhaustion/Protocol Violation via Broker-Controlled Oversized Payload
amqp091-go has a Potential Memory Exhaustion/Protocol Violation via Broker-Controlled Oversized Payload
SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)
SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)
SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB
SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB
SiYuan: Cross-boundary metadata disclosure via getBlockInfo (publish mode): reader-reachable document title/root info for publish-forbidden docs; sibling getDocInfo is filtered
SiYuan: Cross-boundary metadata disclosure via getBlockInfo (publish mode): reader-reachable document title/root info for publish-forbidden docs; sibling getDocInfo is filtered
SiYuan: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents without the password (publish mode)
SiYuan: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents without the password (publish mode)
SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle
SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle
SiYuan: Missing publish-access check on getBlockBreadcrumb, getRefText, and getBlockTreeInfos discloses content and metadata of protected/forbidden documents
SiYuan: Missing publish-access check on getBlockBreadcrumb, getRefText, and getBlockTreeInfos discloses content and metadata of protected/forbidden documents
ffuf denial of service (OOM) via HTTP response decompression bomb
ffuf denial of service (OOM) via HTTP response decompression bomb
SiYuan: Missing publish-access filter on getFileAnnotation discloses private PDF annotations of forbidden/protected documents (publish mode)
SiYuan: Missing publish-access filter on getFileAnnotation discloses private PDF annotations of forbidden/protected documents (publish mode)
SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure
SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure
Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock match
Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock match
SiYuan: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including protected/forbidden documents (publish mode)
SiYuan: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including protected/forbidden documents (publish mode)
SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check
SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check
SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel
SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel
OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool
OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool
SiYuan: Absolute filesystem path and OS username disclosure via resolveAssetPath
SiYuan: Absolute filesystem path and OS username disclosure via resolveAssetPath
Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation
Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation
SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass
SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass
free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA in github.com/free5gc/ausf
free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA in github.com/free5gc/ausf
SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read in github.com/seaweedfs/seaweedfs
SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read in github.com/seaweedfs/seaweedfs
Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db
Siyuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db
Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 in code.vikunja.io/api
Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0 in code.vikunja.io/api
Grafana Tempo vulnerable to an out-of-memory crash in github.com/grafana/tempo
Grafana Tempo vulnerable to an out-of-memory crash in github.com/grafana/tempo
Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id in code.vikunja.io/api
Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id in code.vikunja.io/api
Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection
Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection
Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances in github.com/portainer/portainer
Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances in github.com/portainer/portainer
free5GC AUSF authentication contexts can be overwritten by concurrent requests for the same SUPI in github.com/free5gc/ausf
free5GC AUSF authentication contexts can be overwritten by concurrent requests for the same SUPI in github.com/free5gc/ausf
Hatchet allows cross-tenant write/DoS to other tenants' workers via Dispatcher gRPC UpsertWorkerLabels and Unsubscribe in github.com/hatchet-dev/hatchet
Hatchet allows cross-tenant write/DoS to other tenants' workers via Dispatcher gRPC UpsertWorkerLabels and Unsubscribe in github.com/hatchet-dev/hatchet
Vikunja vulnerable to Improper Authorization and Authorization Bypass Through User-Controlled Key in code.vikunja.io/api
Vikunja vulnerable to Improper Authorization and Authorization Bypass Through User-Controlled Key in code.vikunja.io/api
SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets in github.com/seaweedfs/seaweedfs
SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets in github.com/seaweedfs/seaweedfs
KubeVela Terraform remote loader DoS via unbounded file read in github.com/oam-dev/kubevela
KubeVela Terraform remote loader DoS via unbounded file read in github.com/oam-dev/kubevela
Prevent DoS on deadlocked undecided channel in golang.org/x/crypto/ssh
Prevent DoS on deadlocked undecided channel in golang.org/x/crypto/ssh
Pocket-ID has an Open Redirect on the OIDC /authorize page via unvalidated redirect_uri with prompt=none in github.com/pocket-id/pocket-id/backend
Pocket-ID has an Open Redirect on the OIDC /authorize page via unvalidated redirect_uri with prompt=none in github.com/pocket-id/pocket-id/backend
Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Gitea repository creation accepts insufficiently validated fields in code.gitea.io/gitea
Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
Gitea OAuth2 authorization codes can be reused after expiry in code.gitea.io/gitea
OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints
OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints
Aqua's archive extraction follows attacker-planted symlinks, allowing writes outside the install directory in github.com/aquaproj/aqua
Aqua's archive extraction follows attacker-planted symlinks, allowing writes outside the install directory in github.com/aquaproj/aqua
free5GC NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpoints in github.com/free5gc/free5gc
free5GC NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpoints in github.com/free5gc/free5gc
Vikunja has a project duplication bypasses write-permission check on the target parent project in code.vikunja.io/api
Vikunja has a project duplication bypasses write-permission check on the target parent project in code.vikunja.io/api
Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment in code.vikunja.io/api
Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment in code.vikunja.io/api
Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Gitea release asset dumps permit path traversal through crafted names in code.gitea.io/gitea
Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Gitea organization permission APIs expose hidden membership and private organization data in code.gitea.io/gitea
Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh
Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh
Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token) in github.com/klever-io/klever-go
Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token) in github.com/klever-io/klever-go
ORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource Consumption in oras.land/oras
ORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource Consumption in oras.land/oras
Incus has a project restriction bypass in instance copy across projects in github.com/lxc/incus
Incus has a project restriction bypass in instance copy across projects in github.com/lxc/incus
Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Gitea exposes tracked time entries without repository authorization in code.gitea.io/gitea
Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Gitea git grep searches allow server resource exhaustion in code.gitea.io/gitea
Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
Gitea primary email ownership bypass allows cross-user email changes in code.gitea.io/gitea
OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged pods
OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged pods
alos-http has unauthenticated remote DoS: malformed path starting with "?" triggers out-of-bounds panic in sanitizeRequestPath, crashing entire server in github.com/guno1928/alos-http
alos-http has unauthenticated remote DoS: malformed path starting with "?" triggers out-of-bounds panic in sanitizeRequestPath, crashing entire server in github.com/guno1928/alos-http
Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling
Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling
arc has unauthenticated cluster node admission when `cluster.shared_secret` is unset in github.com/basekick-labs/arc
arc has unauthenticated cluster node admission when `cluster.shared_secret` is unset in github.com/basekick-labs/arc
Incus has a project restriction bypass for custom volume copy across projects in github.com/lxc/incus
Incus has a project restriction bypass for custom volume copy across projects in github.com/lxc/incus
SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control
SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control
SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling paths
SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling paths
Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Gitea pull request branch permission checks allow unauthorized updates and rebases in code.gitea.io/gitea
Bifrost's SSRF deny-list is incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL in github.com/maximhq/bifrost/core
Bifrost's SSRF deny-list is incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL in github.com/maximhq/bifrost/core
klever-go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupply in github.com/klever-io/klever-go
klever-go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupply in github.com/klever-io/klever-go
Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
Gitea OAuth2 PKCE S256 verifier bypass in code.gitea.io/gitea
SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content
SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content
Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped) in github.com/klever-io/klever-go
Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped) in github.com/klever-io/klever-go
OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass)
OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass)
OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs
OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs
klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits in github.com/klever-io/klever-go
klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits in github.com/klever-io/klever-go
Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Gitea template repository generation follows unsafe filesystem paths in code.gitea.io/gitea
Centrifugo: Client-forgeable headers emulation lets any client spoof headers forwarded to proxy backends
Centrifugo: Client-forgeable headers emulation lets any client spoof headers forwarded to proxy backends
gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation
gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation
free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA
free5GC AUSF uses non-constant-time authentication comparisons and logs XRES* in 5G-AKA
ORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource Consumption
ORAS CLI: Cyclic Referrer Graph Can Cause Unbounded Recursion and Resource Consumption
free5GC NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpoints
free5GC NRF nnrf-nfm lacks NF Profile input validation — enables NF Registration Poisoning with arbitrary service endpoints
Hatchet allows cross-tenant write/DoS to other tenants' workers via Dispatcher gRPC UpsertWorkerLabels and Unsubscribe
Hatchet allows cross-tenant write/DoS to other tenants' workers via Dispatcher gRPC UpsertWorkerLabels and Unsubscribe
SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read
SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read
Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0
Vikunja has an incomplete fix for CVE-2026-35595: Write-only user can detach shared project from parent hierarchy via parent_project_id=0
Aqua's archive extraction follows attacker-planted symlinks, allowing writes outside the install directory
Aqua's archive extraction follows attacker-planted symlinks, allowing writes outside the install directory
Incus has a project restriction bypass for custom volume copy across projects
Incus has a project restriction bypass for custom volume copy across projects
Vikunja vulnerable to Improper Authorization and Authorization Bypass Through User-Controlled Key
Vikunja vulnerable to Improper Authorization and Authorization Bypass Through User-Controlled Key
arc has unauthenticated cluster node admission when `cluster.shared_secret` is unset
arc has unauthenticated cluster node admission when `cluster.shared_secret` is unset
free5GC AUSF authentication contexts can be overwritten by concurrent requests for the same SUPI
free5GC AUSF authentication contexts can be overwritten by concurrent requests for the same SUPI
Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id
Vikunja has cross-tenant IDOR in kanban move-task endpoint via unauthorized body task_id
Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped)
Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped)
klever-go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupply
klever-go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupply
Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances
Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances
Vikunja has a project duplication bypasses write-permission check on the target parent project
Vikunja has a project duplication bypasses write-permission check on the target parent project
Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token)
Klever: Integer overflow in split-royalty validation enables unbounded minting of KLV (native token)
alos-http has unauthenticated remote DoS: malformed path starting with "?" triggers out-of-bounds panic in sanitizeRequestPath, crashing entire server
alos-http has unauthenticated remote DoS: malformed path starting with "?" triggers out-of-bounds panic in sanitizeRequestPath, crashing entire server
Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment
Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment
Pocket-ID has an Open Redirect on the OIDC /authorize page via unvalidated redirect_uri with prompt=none
Pocket-ID has an Open Redirect on the OIDC /authorize page via unvalidated redirect_uri with prompt=none
Bifrost's SSRF deny-list is incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL
Bifrost's SSRF deny-list is incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL
Source-address critical option not enforced for non-public-key auth callbacks in golang.org/x/crypto/ssh
Source-address critical option not enforced for non-public-key auth callbacks in golang.org/x/crypto/ssh
KubeVela Terraform remote loader DoS via unbounded file read
KubeVela Terraform remote loader DoS via unbounded file read
SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets
SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets
Incus has a project restriction bypass in instance copy across projects
Incus has a project restriction bypass in instance copy across projects
klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits
klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits
Filestash allows attackers to escalate privileges via sending a crafted request in github.com/mickael-kerjean/filestash
Filestash allows attackers to escalate privileges via sending a crafted request in github.com/mickael-kerjean/filestash
Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter
Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter
Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo
Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo
Kyverno's NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system in github.com/kyverno/kyverno
Kyverno's NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system in github.com/kyverno/kyverno
linx-server has an issue in the uploadPostHandler component that allows attackers to cause a Denial of Service (DoS) via a crafted POST request in github.com/andreimarcu/linx-server
linx-server has an issue in the uploadPostHandler component that allows attackers to cause a Denial of Service (DoS) via a crafted POST request in github.com/andreimarcu/linx-server
Crossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature check
Crossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature check
statping-ng allows attackers to escalate privileges to Administrator and access sensitive components in github.com/statping-ng/statping-ng
statping-ng allows attackers to escalate privileges to Administrator and access sensitive components in github.com/statping-ng/statping-ng
Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root in github.com/cloudreve/Cloudreve
Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root in github.com/cloudreve/Cloudreve
Encoded slash (%2F) bypasses route-level protection and exposes static files in github.com/labstack/echo/v4 and github.com/labstack/echo/v5
Encoded slash (%2F) bypasses route-level protection and exposes static files in github.com/labstack/echo/v4 and github.com/labstack/echo/v5
Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root
Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root
Kyverno's NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system
Kyverno's NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy
Path traversal via crafted vulnerability database or other downloaded artifacts in github.com/aquasecurity/trivy
genieacs-mcp: DNS rebinding reaches local GenieACS MCP Streamable HTTP transport in github.com/geiserx/genieacs-mcp
genieacs-mcp: DNS rebinding reaches local GenieACS MCP Streamable HTTP transport in github.com/geiserx/genieacs-mcp
mcp-shell — Security Disabled by Default in Bare-Binary Deploy Path + Shell Interpreter in Secure-Mode Allowlist in github.com/sonirico/mcp-shell
mcp-shell — Security Disabled by Default in Bare-Binary Deploy Path + Shell Interpreter in Secure-Mode Allowlist in github.com/sonirico/mcp-shell
mcp-shell has a Secure Mode Allowlist Bypass via Git Shell Alias in github.com/sonirico/mcp-shell
mcp-shell has a Secure Mode Allowlist Bypass via Git Shell Alias in github.com/sonirico/mcp-shell
mcp-shell has a Secure Mode Allowlist Bypass via Default `/bin/bash` Executable in github.com/sonirico/mcp-shell
mcp-shell has a Secure Mode Allowlist Bypass via Default `/bin/bash` Executable in github.com/sonirico/mcp-shell
Uprobe gadgets: unprivileged container's ld.so.cache causes high CPU utilization and container startup DoS in github.com/inspektor-gadget/inspektor-gadget
Uprobe gadgets: unprivileged container's ld.so.cache causes high CPU utilization and container startup DoS in github.com/inspektor-gadget/inspektor-gadget
mcp-shell has a Secure Mode Allowlist Bypass via Git Shell Alias
mcp-shell has a Secure Mode Allowlist Bypass via Git Shell Alias
netfoil vulnerable to improper handling of untrusted DoH response data in github.com/tinfoil-factory/netfoil
netfoil vulnerable to improper handling of untrusted DoH response data in github.com/tinfoil-factory/netfoil
kin-openapi has uncontrolled resource consumption in openapi3filter deepObject query parameter decoding in github.com/getkin/kin-openapi
kin-openapi has uncontrolled resource consumption in openapi3filter deepObject query parameter decoding in github.com/getkin/kin-openapi
Gorilla WebSocket Uses Cryptographically Weak PRNG for WebSocket Mask Key in github.com/gorilla/websocket
Gorilla WebSocket Uses Cryptographically Weak PRNG for WebSocket Mask Key in github.com/gorilla/websocket
Echo: Encoded slash (%2F) bypasses route-level protection and exposes static files
Echo: Encoded slash (%2F) bypasses route-level protection and exposes static files
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write in github.com/aquasecurity/trivy
Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint in github.com/cloudreve/Cloudreve
Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint in github.com/cloudreve/Cloudreve
vouch-proxy has an Unbounded Multipart Cookie Allocation DoS in github.com/vouch/vouch-proxy
vouch-proxy has an Unbounded Multipart Cookie Allocation DoS in github.com/vouch/vouch-proxy
moby/go-archive: Crafted tar archive can write outside the extraction directory in github.com/moby/go-archive
moby/go-archive: Crafted tar archive can write outside the extraction directory in github.com/moby/go-archive
Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement in github.com/axllent/mailpit
Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement in github.com/axllent/mailpit
Trivy has a path traversal via a crafted vulnerability database or other downloaded artifacts
Trivy has a path traversal via a crafted vulnerability database or other downloaded artifacts
Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation in github.com/mattermost/mattermost-server
Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation in github.com/mattermost/mattermost-server
Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations in github.com/mattermost/mattermost-server
Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations in github.com/mattermost/mattermost-server
OpenTelemetry-Go: Unsynchronized baggage map can panic under concurrent access in go.opentelemetry.io/otel/bridge/opentracing
OpenTelemetry-Go: Unsynchronized baggage map can panic under concurrent access in go.opentelemetry.io/otel/bridge/opentracing
Velero vulnerable to file path traversal when extracting from backup's tarball in github.com/vmware-tanzu/velero
Velero vulnerable to file path traversal when extracting from backup's tarball in github.com/vmware-tanzu/velero
Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel in github.com/mattermost/mattermost-server
Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel in github.com/mattermost/mattermost-server
Tekton Pipelines-as-Code: Unscoped GitHub App installation token allows unauthorized access to private repositories via remote task resolution in github.com/openshift-pipelines/pipelines-as-code
Tekton Pipelines-as-Code: Unscoped GitHub App installation token allows unauthorized access to private repositories via remote task resolution in github.com/openshift-pipelines/pipelines-as-code
BuildKit has a possible runtime DoS via unbounded group parsing in github.com/moby/buildkit
BuildKit has a possible runtime DoS via unbounded group parsing in github.com/moby/buildkit
Ember has unneutralized terminal escape/control sequences from Caddy logs injected into the operator's TUI in github.com/alexandre-daubois/ember
Ember has unneutralized terminal escape/control sequences from Caddy logs injected into the operator's TUI in github.com/alexandre-daubois/ember
3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation in github.com/mhsanaei/3x-ui
3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation in github.com/mhsanaei/3x-ui
Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync in github.com/mattermost/mattermost-server
Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync in github.com/mattermost/mattermost-server
mcp-shell — Security Disabled by Default in Bare-Binary Deploy Path + Shell Interpreter in Secure-Mode Allowlist
mcp-shell — Security Disabled by Default in Bare-Binary Deploy Path + Shell Interpreter in Secure-Mode Allowlist
mcp-shell has a Secure Mode Allowlist Bypass via Default `/bin/bash` Executable
mcp-shell has a Secure Mode Allowlist Bypass via Default `/bin/bash` Executable
genieacs-mcp: DNS rebinding reaches local GenieACS MCP Streamable HTTP transport
genieacs-mcp: DNS rebinding reaches local GenieACS MCP Streamable HTTP transport
Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs in github.com/fleetdm/fleet
Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs in github.com/fleetdm/fleet
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation in github.com/runatlantis/atlantis
Fleet: SQL injection in Okta conditional access endpoint allows host-controlled compromise of the Fleet database in github.com/fleetdm/fleet
Fleet: SQL injection in Okta conditional access endpoint allows host-controlled compromise of the Fleet database in github.com/fleetdm/fleet
BuildKit: Custom frontend could bypass Seccomp/AppArmor in github.com/moby/buildkit
BuildKit: Custom frontend could bypass Seccomp/AppArmor in github.com/moby/buildkit
Mattermost doesn't require system-level permission when patching protected default system roles in github.com/mattermost/mattermost-server
Mattermost doesn't require system-level permission when patching protected default system roles in github.com/mattermost/mattermost-server
Mattermost doesn't validate that a username returned during bot registration belongs to a bot account in github.com/mattermost/mattermost-server
Mattermost doesn't validate that a username returned during bot registration belongs to a bot account in github.com/mattermost/mattermost-server
Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689) in github.com/axllent/mailpit
Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689) in github.com/axllent/mailpit
MCP Toolbox for Databases has an Origin Validation Error in github.com/googleapis/genai-toolbox
MCP Toolbox for Databases has an Origin Validation Error in github.com/googleapis/genai-toolbox
Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Cloudreve's remote download file paths can escape the selected destination directory in github.com/cloudreve/Cloudreve
Cloudreve's remote download file paths can escape the selected destination directory in github.com/cloudreve/Cloudreve
Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import in github.com/dgraph-io/dgraph
Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import in github.com/dgraph-io/dgraph
OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers in github.com/opentofu/opentofu
OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers in github.com/opentofu/opentofu
kin-openapi openai3filter: nil-pointer panic in ConvertErrors on malformed multipart/form-data body enables unauthenticated DoS in github.com/getkin/kin-openapi
kin-openapi openai3filter: nil-pointer panic in ConvertErrors on malformed multipart/form-data body enables unauthenticated DoS in github.com/getkin/kin-openapi
Pipelines-as-Code GitHub App token request can be redirected via untrusted Enterprise Host header in github.com/openshift-pipelines/pipelines-as-code
Pipelines-as-Code GitHub App token request can be redirected via untrusted Enterprise Host header in github.com/openshift-pipelines/pipelines-as-code
Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints in github.com/mattermost/mattermost-server
Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints in github.com/mattermost/mattermost-server
Fleet: ORDER BY column injection on activity list endpoints in github.com/fleetdm/fleet
Fleet: ORDER BY column injection on activity list endpoints in github.com/fleetdm/fleet
Gorilla WebSocket Uses Cryptographically Weak PRNG for WebSocket Mask Key
Gorilla WebSocket Uses Cryptographically Weak PRNG for WebSocket Mask Key
3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation
3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation
Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint
Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint
netfoil vulnerable to improper handling of untrusted DoH response data
netfoil vulnerable to improper handling of untrusted DoH response data
Cloudreve's remote download file paths can escape the selected destination directory
Cloudreve's remote download file paths can escape the selected destination directory
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation
kin-openapi has uncontrolled resource consumption in openapi3filter deepObject query parameter decoding
kin-openapi has uncontrolled resource consumption in openapi3filter deepObject query parameter decoding
kin-openapi openai3filter: nil-pointer panic in ConvertErrors on malformed multipart/form-data body enables unauthenticated DoS
kin-openapi openai3filter: nil-pointer panic in ConvertErrors on malformed multipart/form-data body enables unauthenticated DoS
Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings
Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings
vouch-proxy has an Unbounded Multipart Cookie Allocation DoS
vouch-proxy has an Unbounded Multipart Cookie Allocation DoS
Ember has unneutralized terminal escape/control sequences from Caddy logs injected into the operator's TUI
Ember has unneutralized terminal escape/control sequences from Caddy logs injected into the operator's TUI
Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import
Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import
Fleet: SQL injection in Okta conditional access endpoint allows host-controlled compromise of the Fleet database
Fleet: SQL injection in Okta conditional access endpoint allows host-controlled compromise of the Fleet database
OpenTelemetry-Go: Unsynchronized baggage map can panic under concurrent access
OpenTelemetry-Go: Unsynchronized baggage map can panic under concurrent access
Tekton Pipelines-as-Code: Unscoped GitHub App installation token allows unauthorized access to private repositories via remote task resolution
Tekton Pipelines-as-Code: Unscoped GitHub App installation token allows unauthorized access to private repositories via remote task resolution
Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison
Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison
OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers
OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers
Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689)
Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689)
Velero vulnerable to file path traversal when extracting from backup's tarball
Velero vulnerable to file path traversal when extracting from backup's tarball
Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs
Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs
Fleet: ORDER BY column injection on activity list endpoints
Fleet: ORDER BY column injection on activity list endpoints
Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement
Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement
Pipelines-as-Code GitHub App token request can be redirected via untrusted Enterprise Host header
Pipelines-as-Code GitHub App token request can be redirected via untrusted Enterprise Host header
SiYuan vulnerable to remote code execution via marketplace XSS in github.com/siyuan-note/siyuan/kernel
SiYuan vulnerable to remote code execution via marketplace XSS in github.com/siyuan-note/siyuan/kernel
BuildKit: Custom frontend could bypass Seccomp/AppArmor
BuildKit: Custom frontend could bypass Seccomp/AppArmor
BuildKit has a possible runtime DoS via unbounded group parsing
BuildKit has a possible runtime DoS via unbounded group parsing
Uprobe gadgets: unprivileged container's ld.so.cache causes high CPU utilization and container startup DoS
Uprobe gadgets: unprivileged container's ld.so.cache causes high CPU utilization and container startup DoS
Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts in github.com/authorizerdev/authorizer
Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts in github.com/authorizerdev/authorizer
ZITADEL Users Can Self-Verify Email/Phone via API in github.com/zitadel/zitadel
ZITADEL Users Can Self-Verify Email/Phone via API in github.com/zitadel/zitadel
free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure in github.com/free5gc/ausf
free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure in github.com/free5gc/ausf
openhole-server vulnerable to path traversal via URL-decoded request path in github.com/bablilayoub/openhole
openhole-server vulnerable to path traversal via URL-decoded request path in github.com/bablilayoub/openhole
Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass in github.com/traefik/traefik
Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass in github.com/traefik/traefik
goshs has a Path Traversal issue in github.com/patrickhener/goshs
goshs has a Path Traversal issue in github.com/patrickhener/goshs
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM in github.com/pterodactyl/wings
JSON private fields exposed via NativeTypes and ParseStructTag in github.com/google/cel-go
JSON private fields exposed via NativeTypes and ParseStructTag in github.com/google/cel-go
Watch API authorization bypass in go.etcd.io/etcd/server/v3
Watch API authorization bypass in go.etcd.io/etcd/server/v3
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal in github.com/OpenListTeam/OpenList
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal in github.com/OpenListTeam/OpenList
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in github.com/apache/answer
Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape in github.com/fission/fission
Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape in github.com/fission/fission
Credential leakage to untrusted hosts in github.com/chrismellard/docker-credential-acr-env
Credential leakage to untrusted hosts in github.com/chrismellard/docker-credential-acr-env
Assisted Migration Agent: Hardcoded insecure Transport Layer Security (TLS) connections during vCenter communication in github.com/kubev2v/assisted-migration-agent
Assisted Migration Agent: Hardcoded insecure Transport Layer Security (TLS) connections during vCenter communication in github.com/kubev2v/assisted-migration-agent
uniget CLI has an EDITOR Command Injection in gitlab.com/uniget-org/cli
uniget CLI has an EDITOR Command Injection in gitlab.com/uniget-org/cli
Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory in github.com/fission/fission
Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory in github.com/fission/fission
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp
Authorization bypass via double-encoded paths in github.com/valyala/fasthttp
Integer overflow in BTF parsing in github.com/cilium/ebpf
Integer overflow in BTF parsing in github.com/cilium/ebpf
Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass in github.com/traefik/traefik
Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass in github.com/traefik/traefik
sigstore-go fails to check signature timestamps against a signing key's validity period in github.com/sigstore/sigstore-go
sigstore-go fails to check signature timestamps against a signing key's validity period in github.com/sigstore/sigstore-go
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search in github.com/OpenListTeam/OpenList
frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow in github.com/fatedier/frp
frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow in github.com/fatedier/frp
Oh My Posh: Arbitrary command execution via template injection in the path segment in github.com/jandedobbeleer/oh-my-posh
Oh My Posh: Arbitrary command execution via template injection in the path segment in github.com/jandedobbeleer/oh-my-posh
WebDAV credential leakage on HTTPS to HTTP redirect in github.com/rclone/rclone
WebDAV credential leakage on HTTPS to HTTP redirect in github.com/rclone/rclone
Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method in github.com/pocket-id/pocket-id/backend
Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method in github.com/pocket-id/pocket-id/backend
Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data in github.com/jandedobbeleer/oh-my-posh
Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data in github.com/jandedobbeleer/oh-my-posh
GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler in github.com/github/github-mcp-server
GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler in github.com/github/github-mcp-server
Openshift Migration Advisor lacks proper authorization and filtering for its DELETE /api/v1/sources API in github.com/kubev2v/migration-planner
Openshift Migration Advisor lacks proper authorization and filtering for its DELETE /api/v1/sources API in github.com/kubev2v/migration-planner
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service in github.com/pterodactyl/wings
Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored in github.com/cloudreve/Cloudreve
Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored in github.com/cloudreve/Cloudreve
grepai Uses a Broken or Risky Cryptographic Algorithm in github.com/yoanbernabeu/grepai
grepai Uses a Broken or Risky Cryptographic Algorithm in github.com/yoanbernabeu/grepai
Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails in github.com/cloudreve/Cloudreve
Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails in github.com/cloudreve/Cloudreve
Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server in github.com/cloudreve/Cloudreve
Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server in github.com/cloudreve/Cloudreve
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite in github.com/patrickhener/goshs
GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS in github.com/gopacket/gopacket
GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS in github.com/gopacket/gopacket
Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket in github.com/lima-vm/lima
Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket in github.com/lima-vm/lima
goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884) in goshs.de/goshs
goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884) in goshs.de/goshs
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions in github.com/pterodactyl/wings
Weaviate has an Improper Authorization issue in github.com/weaviate/weaviate
Weaviate has an Improper Authorization issue in github.com/weaviate/weaviate
Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources in github.com/zxh326/kite
Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources in github.com/zxh326/kite
Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests in github.com/projectcapsule/capsule
Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests in github.com/projectcapsule/capsule
Path traversal in serve s3 in github.com/rclone/rclone
Path traversal in serve s3 in github.com/rclone/rclone
Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation) in github.com/projectcapsule/capsule
Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation) in github.com/projectcapsule/capsule
Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks in github.com/fission/fission
Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks in github.com/fission/fission
Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account in github.com/cloudreve/Cloudreve
Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account in github.com/cloudreve/Cloudreve
Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption in github.com/fission/fission
Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption in github.com/fission/fission
Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens in github.com/azukaar/cosmos-server
Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens in github.com/azukaar/cosmos-server
goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs
goshs has ACL Bypass & Path Traversal in github.com/patrickhener/goshs
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx) in github.com/patrickhener/goshs
OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check in github.com/OliveTin/OliveTin
OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check in github.com/OliveTin/OliveTin
Openshift Migration Advisor agent-API fails to validate JWT source_id claim, allowing cross-tenant data manipulation in github.com/kubev2v/migration-planner
Openshift Migration Advisor agent-API fails to validate JWT source_id claim, allowing cross-tenant data manipulation in github.com/kubev2v/migration-planner
Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions in github.com/pocket-id/pocket-id/backend
Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions in github.com/pocket-id/pocket-id/backend
Traefik: Gateway API route identity collision allows cross-namespace backend hijacking in github.com/traefik/traefik
Traefik: Gateway API route identity collision allows cross-namespace backend hijacking in github.com/traefik/traefik
netfoil: Incorrect block responses could lead to localhost traffic in github.com/tinfoil-factory/netfoil
netfoil: Incorrect block responses could lead to localhost traffic in github.com/tinfoil-factory/netfoil
Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs in github.com/kubev2v/migration-planner
Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs in github.com/kubev2v/migration-planner
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability in github.com/apache/answer
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation in github.com/QuantumNous/new-api
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability in github.com/apache/answer
Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware in github.com/traefik/traefik
Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware in github.com/traefik/traefik
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows
Assisted Migration Agent: Path traversal in gzipped tarball handling enables arbitrary file write and remote code execution in github.com/kubev2v/assisted-migration-agent
Assisted Migration Agent: Path traversal in gzipped tarball handling enables arbitrary file write and remote code execution in github.com/kubev2v/assisted-migration-agent
Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef in github.com/traefik/traefik
Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef in github.com/traefik/traefik
New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api
New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass in github.com/QuantumNous/new-api
GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS) in github.com/gopacket/gopacket
GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS) in github.com/gopacket/gopacket
Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth in github.com/traefik/traefik
Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth in github.com/traefik/traefik
New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging in github.com/QuantumNous/new-api
New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging in github.com/QuantumNous/new-api
OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output in github.com/OliveTin/OliveTin
OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output in github.com/OliveTin/OliveTin
New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api
New API: Integer overflow in quota billing yields negative charges (self-crediting) in github.com/QuantumNous/new-api
FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files in github.com/gtsteffaniak/filebrowser/backend
FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files in github.com/gtsteffaniak/filebrowser/backend
Openshift Migration Advisor: Improper input sanitization allows specially crafted RVTools .xlsx files to include malicious SQL commands in github.com/kubev2v/migration-planner
Openshift Migration Advisor: Improper input sanitization allows specially crafted RVTools .xlsx files to include malicious SQL commands in github.com/kubev2v/migration-planner
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api
New API: Admin can reset passkeys for same-level or higher-privileged users in github.com/QuantumNous/new-api
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer
Apache Answer: AdminToken not invalidated after admin deactivation in github.com/apache/answer
uniget CLI has Path Traversal in Hook Files - Directory Escape Vulnerability in gitlab.com/uniget-org/cli
uniget CLI has Path Traversal in Hook Files - Directory Escape Vulnerability in gitlab.com/uniget-org/cli
S3 redirect sanitization omits sensitive headers in github.com/rclone/rclone
S3 redirect sanitization omits sensitive headers in github.com/rclone/rclone
SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access in github.com/seaweedfs/seaweedfs
SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access in github.com/seaweedfs/seaweedfs
Path traversal via crafted reference names in github.com/go-git/go-git
Path traversal via crafted reference names in github.com/go-git/go-git
Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false in github.com/traefik/traefik
Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false in github.com/traefik/traefik
Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing in github.com/traefik/traefik
Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing in github.com/traefik/traefik
Terragrunt: Arbitrary File Deletion via Malicious Module Manifest in github.com/gruntwork-io/terragrunt
Terragrunt: Arbitrary File Deletion via Malicious Module Manifest in github.com/gruntwork-io/terragrunt
Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and receives activity events for unshared siblings in github.com/cloudreve/Cloudreve
Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and receives activity events for unshared siblings in github.com/cloudreve/Cloudreve
OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth) in github.com/OliveTin/OliveTin
OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth) in github.com/OliveTin/OliveTin
vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API in github.com/bank-vaults/vault-secrets-webhook
vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API in github.com/bank-vaults/vault-secrets-webhook
Vitess: Missing authorization on vttablet /debug/vrlog exposes live VReplication SQL data
Vitess: Missing authorization on vttablet /debug/vrlog exposes live VReplication SQL data
Verbose stack trace disclosure in RC API error responses in github.com/rclone/rclone
Verbose stack trace disclosure in RC API error responses in github.com/rclone/rclone
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer
Apache Answer vulnerable to Cross-site Scripting in github.com/apache/answer
grepai Uses a Broken or Risky Cryptographic Algorithm in github.com/yoanbernabeu/grepai
grepai Uses a Broken or Risky Cryptographic Algorithm in github.com/yoanbernabeu/grepai
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings
Wings exposes node configuration secrets through egg configuration-file templating in github.com/pterodactyl/wings
Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials in github.com/cloudreve/Cloudreve
Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials in github.com/cloudreve/Cloudreve
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write
Trivy Plugin Manager has Path Traversal that Allows Arbitrary File Write
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability in github.com/apache/answer
Panic on malformed XOR-MAPPED-ADDRESS attribute in github.com/pion/stun/v3
Panic on malformed XOR-MAPPED-ADDRESS attribute in github.com/pion/stun/v3
Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests in github.com/cloudreve/Cloudreve
Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests in github.com/cloudreve/Cloudreve
songquanpeng one-api has an issue that results in business logic errors
songquanpeng one-api has an issue that results in business logic errors
Worktree operations may follow symlinks in github.com/go-git/go-git
Worktree operations may follow symlinks in github.com/go-git/go-git
SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle in github.com/seaweedfs/seaweedfs
SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle in github.com/seaweedfs/seaweedfs
Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool in github.com/traefik/traefik
Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool in github.com/traefik/traefik
Logging operator has Fluentd configuration injection that allows remote code execution in github.com/kube-logging/logging-operator
Logging operator has Fluentd configuration injection that allows remote code execution in github.com/kube-logging/logging-operator
Cosmos-Server has an authentication bypass via forward-auth header smuggling on Constellation tunnel in github.com/azukaar/cosmos-server
Cosmos-Server has an authentication bypass via forward-auth header smuggling on Constellation tunnel in github.com/azukaar/cosmos-server
Denial of service via malformed IPv4 packet in github.com/insomniacslk/dhcp
Denial of service via malformed IPv4 packet in github.com/insomniacslk/dhcp
moby/go-archive: Crafted tar archive can write outside the extraction directory
moby/go-archive: Crafted tar archive can write outside the extraction directory
Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion
Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion
Gophish contains a denial of service vulnerability in github.com/gophish/gophish
Gophish contains a denial of service vulnerability in github.com/gophish/gophish
Nil-pointer panic on content parameter without schema in github.com/getkin/kin-openapi
Nil-pointer panic on content parameter without schema in github.com/getkin/kin-openapi
LDAP injection via unescaped username in github.com/hyperledger/fabric-ca
LDAP injection via unescaped username in github.com/hyperledger/fabric-ca
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion in github.com/aws/aws-cdk-go/awscdk
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion in github.com/aws/aws-cdk-go/awscdk
Panic while parsing crafted ECDHE_PSK ServerKeyExchange in github.com/pion/dtls/v3
Panic while parsing crafted ECDHE_PSK ServerKeyExchange in github.com/pion/dtls/v3
Server-side request forgery in bidder adapters in github.com/prebid/prebid-server/v4
Server-side request forgery in bidder adapters in github.com/prebid/prebid-server/v4
Authorization bypass in serve restic in github.com/rclone/rclone
Authorization bypass in serve restic in github.com/rclone/rclone
Nil pointer dereference in Infinite Scale TUS uploads in github.com/rclone/rclone
Nil pointer dereference in Infinite Scale TUS uploads in github.com/rclone/rclone
uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set in gitlab.com/uniget-org/cli
uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set in gitlab.com/uniget-org/cli
Unsafe file permission restoration from metadata in github.com/rclone/rclone
Unsafe file permission restoration from metadata in github.com/rclone/rclone
Arbitrary file write via --links symlinks in github.com/rclone/rclone
Arbitrary file write via --links symlinks in github.com/rclone/rclone
FTP command injection via custom encoding in github.com/rclone/rclone
FTP command injection via custom encoding in github.com/rclone/rclone
Path traversal via crafted archive paths in github.com/rclone/rclone
Path traversal via crafted archive paths in github.com/rclone/rclone
Authentication bypass via default NoopAuthenticationFunc in github.com/getkin/kin-openapi
Authentication bypass via default NoopAuthenticationFunc in github.com/getkin/kin-openapi
Resource exhaustion via unbounded HTTP CONNECT response in github.com/rclone/rclone
Resource exhaustion via unbounded HTTP CONNECT response in github.com/rclone/rclone
Path traversal via local backend encoding in github.com/rclone/rclone
Path traversal via local backend encoding in github.com/rclone/rclone
Command execution via PowerShell smart quotes in github.com/rclone/rclone
Command execution via PowerShell smart quotes in github.com/rclone/rclone
S3 session token leakage on HTTPS to HTTP redirect in github.com/rclone/rclone
S3 session token leakage on HTTPS to HTTP redirect in github.com/rclone/rclone
Path traversal in serve restic in github.com/rclone/rclone
Path traversal in serve restic in github.com/rclone/rclone
Unbounded memory allocation in proto.UnencryptedMessage.Decode in github.com/gotd/td
Unbounded memory allocation in proto.UnencryptedMessage.Decode in github.com/gotd/td
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API in github.com/OpenListTeam/OpenList
Cross-forge account takeover on login in codefloe.com/crowci/crow/v6
Cross-forge account takeover on login in codefloe.com/crowci/crow/v6
Stale blob descriptor cache invalidation in github.com/distribution/distribution
Stale blob descriptor cache invalidation in github.com/distribution/distribution
webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules in github.com/quic-go/webtransport-go
webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules in github.com/quic-go/webtransport-go
Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint in github.com/fleetdm/fleet
Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint in github.com/fleetdm/fleet
Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port in github.com/traefik/traefik
Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port in github.com/traefik/traefik
Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3
Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3
uniget CLI has an EDITOR Command Injection
uniget CLI has an EDITOR Command Injection
package pkcs12: Authentication bypass in Decode functions
package pkcs12: Authentication bypass in Decode functions
Terragrunt: Arbitrary File Deletion via Malicious Module Manifest
Terragrunt: Arbitrary File Deletion via Malicious Module Manifest
New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging
New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging
New API: Integer overflow in quota billing yields negative charges (self-crediting)
New API: Integer overflow in quota billing yields negative charges (self-crediting)
New API: Admin can reset passkeys for same-level or higher-privileged users
New API: Admin can reset passkeys for same-level or higher-privileged users
github.com/QuantumNous/new-api: 0.9.1.3 → 1.0.0-rc.7
New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass
New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass
uniget CLI has Path Traversal in Hook Files - Directory Escape Vulnerability
uniget CLI has Path Traversal in Hook Files - Directory Escape Vulnerability
uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set
uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation
New API: User List API Leaks Root User Access Token Leading to Privilege Escalation
Fabric CA Developer's Guide: LDAP Injection via Unescaped Username in GetUser Filter
Fabric CA Developer's Guide: LDAP Injection via Unescaped Username in GetUser Filter
Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket
Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket
Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts
Authorizer: Zero-click account takeover via OAuth identity linking to unverified email accounts
Excessive memory allocation during VP8L decoding in golang.org/x/image
Excessive memory allocation during VP8L decoding in golang.org/x/image
Enforce maximum recursion depth in encoding/asn1
Enforce maximum recursion depth in encoding/asn1
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)
Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Ignore unrelated, unauthenticated hashes in Lookup in golang.org/x/mod/sumdb
Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http
Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http
Avoid quadratic complexity in resolvePath in net/url
Avoid quadratic complexity in resolvePath in net/url
Add recursion depth guard during decode in encoding/xml
Add recursion depth guard during decode in encoding/xml
Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Fix transparency log tile verification bypass in golang.org/x/mod/sumdb/tlog
Limit handshake messages we are willing to accept post-handshake in crypto/tls
Limit handshake messages we are willing to accept post-handshake in crypto/tls
Fix Javascript regexp context tracking in html/template
Fix Javascript regexp context tracking in html/template
SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access
SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access
Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint
Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint
Nezha's authenticated agents can forge service-monitor results for other users' services in github.com/nezhahq/nezha
Nezha's authenticated agents can forge service-monitor results for other users' services in github.com/nezhahq/nezha
Unauthenticated backend instantiation in github.com/rclone/rclone
Unauthenticated backend instantiation in github.com/rclone/rclone
Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts in github.com/traefik/traefik
Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts in github.com/traefik/traefik
Unauthenticated restoreTenant mutation allows database overwrite and SSRF in github.com/dgraph-io/dgraph
Unauthenticated restoreTenant mutation allows database overwrite and SSRF in github.com/dgraph-io/dgraph
Pre-Auth DQL injection in upsert condition field in github.com/dgraph-io/dgraph
Pre-Auth DQL injection in upsert condition field in github.com/dgraph-io/dgraph
Authorization and Cookie headers forwarded to error page service in github.com/traefik/traefik
Authorization and Cookie headers forwarded to error page service in github.com/traefik/traefik
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall
Traefik: SNICheck ignores wildcard TLSOptions mappings in github.com/traefik/traefik
Traefik: SNICheck ignores wildcard TLSOptions mappings in github.com/traefik/traefik
LXD: Importing a crafted backup leads to project restriction bypass in github.com/canonical/lxd
LXD: Importing a crafted backup leads to project restriction bypass in github.com/canonical/lxd
Dgraph: Unauthenticated admin token disclosure via /debug/pprof/cmdline in github.com/dgraph-io/dgraph
Dgraph: Unauthenticated admin token disclosure via /debug/pprof/cmdline in github.com/dgraph-io/dgraph
VM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf in github.com/canonical/lxd
VM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf in github.com/canonical/lxd
Type field in restricted TLS certificate allows privilege escalation in github.com/canonical/lxd
Type field in restricted TLS certificate allows privilege escalation in github.com/canonical/lxd
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone
Unauthenticated command execution in rclone rcd via inline remotes in github.com/rclone/rclone
SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle
SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle
go-git: Worktree operations may follow symlinks
go-git: Worktree operations may follow symlinks
go-git: Malicious reference names may modify files outside the reference storage
go-git: Malicious reference names may modify files outside the reference storage
Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port
Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port
Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware
Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware
Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass
Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass
Traefik: Gateway API route identity collision allows cross-namespace backend hijacking
Traefik: Gateway API route identity collision allows cross-namespace backend hijacking
Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool
Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool
Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false
Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false
Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth
Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth
Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing
Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing
Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef
Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef
rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect
rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect
rclone: Incomplete path validation allows backend root escape in serve restic
rclone: Incomplete path validation allows backend root escape in serve restic
rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic
rclone: Infinite Scale TUS Creation Transport Error Causes a Nil-Response Panic
rclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Preserves Newlines
rclone: FTP Command Arguments Permit CRLF Injection When Custom Encoding Preserves Newlines
rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote
rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote
rclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone Memory
rclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone Memory
rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution
rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution
rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect
rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect
rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories
rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories
Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion
Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion
rclone local `--metadata` applies attacker-controlled mode/uid - setuid binary planted from an untrusted remote
rclone local `--metadata` applies attacker-controlled mode/uid - setuid binary planted from an untrusted remote
rclone: Path traversal in serve s3 allows reading and overwriting root-level files
rclone: Path traversal in serve s3 allows reading and overwriting root-level files
rclone: Verbose Stack Trace Disclosure in RC API Error Responses
rclone: Verbose Stack Trace Disclosure in RC API Error Responses
rclone archive extract allows S3 destination prefix escape via crafted archive paths
rclone archive extract allows S3 destination prefix escape via crafted archive paths
Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass
Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass
rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys
rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys
rclone: Local Encoding Path Traversal
rclone: Local Encoding Path Traversal
sigstore-go fails to check signature timestamps against a signing key's validity period
sigstore-go fails to check signature timestamps against a signing key's validity period
Pion DTLS vulnerable to denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message
Pion DTLS vulnerable to denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message
Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute
Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM
Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM
vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API
vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service
Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service
Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests
Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests
FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files
FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files
Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation)
Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation)
free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure
free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure
Wings exposes node configuration secrets through egg configuration-file templating
Wings exposes node configuration secrets through egg configuration-file templating
OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check
OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check
OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output
OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output
OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)
OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)
netfoil: Incorrect block responses could lead to localhost traffic
netfoil: Incorrect block responses could lead to localhost traffic
Logging operator has Fluentd configuration injection that allows remote code execution
Logging operator has Fluentd configuration injection that allows remote code execution
ZITADEL Users Can Self-Verify Email/Phone via API
ZITADEL Users Can Self-Verify Email/Phone via API
prebid-server's request forgery vulnerability allows for possible host environment data extraction
prebid-server's request forgery vulnerability allows for possible host environment data extraction
GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS)
GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS)
GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS
GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS
Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks
Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks
Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens
Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite
goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite
Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions
Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions
goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)
goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)
Cosmos-Server has an authentication bypass via forward-auth header smuggling on Constellation tunnel
Cosmos-Server has an authentication bypass via forward-auth header smuggling on Constellation tunnel
openhole-server vulnerable to path traversal via URL-decoded request path
openhole-server vulnerable to path traversal via URL-decoded request path
Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory
Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx)
goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx)
GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler
GitHub MCP Server has Nil Pointer Dereference DoS in completion/complete Handler
goshs has a Path Traversal issue
goshs has a Path Traversal issue
goshs has ACL Bypass & Path Traversal
goshs has ACL Bypass & Path Traversal
Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption
Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption
Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape
Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape
Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method
Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method
td has pre-auth denial of service via unbounded memory allocation in proto.UnencryptedMessage.Decode
td has pre-auth denial of service via unbounded memory allocation in proto.UnencryptedMessage.Decode
Improper parsing of W3C baggage headers may lead to DoS in github.com/DataDog/dd-trace-go
Improper parsing of W3C baggage headers may lead to DoS in github.com/DataDog/dd-trace-go
Integer overflow in Avro decoder in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2
Integer overflow in Avro decoder in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2
CPU exhaustion in Avro decoder in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2
CPU exhaustion in Avro decoder in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2
Denial of service via unbounded map allocations in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2
Denial of service via unbounded map allocations in github.com/iskorotkov/avro/v2 and github.com/hamba/avro/v2
Chi has an IP spoofing vulnerability in middleware.RealIP in github.com/go-chi/chi
Chi has an IP spoofing vulnerability in middleware.RealIP in github.com/go-chi/chi
Chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header in github.com/go-chi/chi
Chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header in github.com/go-chi/chi
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal
etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline
etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline
Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go
Oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens in oras.land/oras-go
Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm
Helm Chart extraction output directory collapse via Chart.yaml name dot-segment in helm.sh/helm
Go-git: Improper parsing of specially crafted objects may lead to inconsistent interpretation in github.com/go-git/go-git
Go-git: Improper parsing of specially crafted objects may lead to inconsistent interpretation in github.com/go-git/go-git
Oh My Posh: Arbitrary command execution via template injection in the path segment
Oh My Posh: Arbitrary command execution via template injection in the path segment
Go-git: Malformed Git object data may cause panics or resource exhaustion in github.com/go-git/go-git
Go-git: Malformed Git object data may cause panics or resource exhaustion in github.com/go-git/go-git
Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails
Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails
etcd: Watch API authorization bypass via open-ended range requests
etcd: Watch API authorization bypass via open-ended range requests
Go-billy: Symlink resolution lack of cycle detection leads to infinite loop in github.com/go-git/go-billy
Go-billy: Symlink resolution lack of cycle detection leads to infinite loop in github.com/go-git/go-billy
cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag
cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag
Hardlink path traversal during tar extraction in oras.land/oras-go
Hardlink path traversal during tar extraction in oras.land/oras-go
Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored
Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored
Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and receives activity events for unshared siblings
Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and receives activity events for unshared siblings
Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account
Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account
Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials
Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials
frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow
frp: Unauthenticated Remote Denial of Service in the frp SSH Tunnel Gateway via Integer Overflow
kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default
kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default
Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server
Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server
Go-git: Crafted repositories may modify main and submodule .git directories in github.com/go-git/go-git
Go-git: Crafted repositories may modify main and submodule .git directories in github.com/go-git/go-git
OpenTelemetry-Go: Multi-value baggage header extraction causes excessive allocations in go.opentelemetry.io/otel
OpenTelemetry-Go: Multi-value baggage header extraction causes excessive allocations in go.opentelemetry.io/otel
kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating a request against a `content` parameter whose media type has no schema
kin-openapi openapi3filter: unauthenticated nil-pointer panic when validating a request against a `content` parameter whose media type has no schema
Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources
Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search
Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests
Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests
Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data
Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data
Go-ntlmssp NTLM challenges can panic on malformed payloads in github.com/Azure/go-ntlmssp
Go-ntlmssp NTLM challenges can panic on malformed payloads in github.com/Azure/go-ntlmssp
Mongo-go-driver: Heap Out-of-Bounds Read in GSSAPI Error Handling in go.mongodb.org/mongo-driver
Mongo-go-driver: Heap Out-of-Bounds Read in GSSAPI Error Handling in go.mongodb.org/mongo-driver
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API
Opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking in go.opentelemetry.io/otel/sdk
Opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking in go.opentelemetry.io/otel/sdk
webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules
webtransport-go: Memory Exhaustion Attack due to Buffering of Unknown Capsules
Go-git: Credential leak via cross-host redirect in smart HTTP transport in github.com/go-git/go-git
Go-git: Credential leak via cross-host redirect in smart HTTP transport in github.com/go-git/go-git
Go-billy has path traversal vulnerabilities in github.com/go-git/go-billy
Go-billy has path traversal vulnerabilities in github.com/go-git/go-billy
Chi Middleware vulnerable to IP spoofing via X-Forwarded-For header in github.com/go-chi/chi
Chi Middleware vulnerable to IP spoofing via X-Forwarded-For header in github.com/go-chi/chi
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma
Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma
Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma
kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma
kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata in gitea.dev
gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
Gitea: Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata
Gitea: SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata
oapi-codegen: OpenAPI Server Description Escapes Generated Go Comment and Injects Executable Code
oapi-codegen: OpenAPI Server Description Escapes Generated Go Comment and Injects Executable Code
Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private` in github.com/forgekeep/nebula-mesh
Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private` in github.com/forgekeep/nebula-mesh
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode
Envoy Gateway: xDS Control Plane Information Disclosure when operating in GatewayNamespaceMode
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure
Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header
Envoy Gateway: OCI layer extraction allocates make([]byte, h.Size) from untrusted tar header
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock
Envoy Gateway: Wasm cache ServeHTTP reads mappingPath2Cache without lock
kumactl connects to control plane without verifying TLS certificate when no CA is configured
kumactl connects to control plane without verifying TLS certificate when no CA is configured
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit
Envoy Gateway: Wasm HTTP fetch decompresses gzip without output-size limit
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization
Envoy Gateway: Nil-dereference when SecurityPolicy targets TCPRoute without spec.authorization
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass
Envoy Gateway custom backendRef cross-namespace ReferenceGrant bypass
dd-trace-go: Improper parsing of W3C baggage headers may lead to DoS
dd-trace-go: Improper parsing of W3C baggage headers may lead to DoS
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser
Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser
Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private`
Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private`
K3s: ZIP Archive Path Traversal Vulnerability in etcd Snapshot Decompression
K3s: ZIP Archive Path Traversal Vulnerability in etcd Snapshot Decompression
Infinite loop on invalid input in golang.org/x/text
Infinite loop on invalid input in golang.org/x/text
Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage
Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage
melange: Incomplete package integrity verification allows data section substitution
melange: Incomplete package integrity verification allows data section substitution
sigstore-go has a multi-log threshold bypass via single compromised log
sigstore-go has a multi-log threshold bypass via single compromised log
GoBGP confederation validation panics on empty AS_PATH attribute
GoBGP confederation validation panics on empty AS_PATH attribute
Concourse login flow has an open redirect issue in github.com/concourse/concourse
Concourse login flow has an open redirect issue in github.com/concourse/concourse
Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check in github.com/nezhahq/nezha
Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check in github.com/nezhahq/nezha
DoS due to Panic in AWS SDK for Go v2 SDK EventStream Decoder in github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream
DoS due to Panic in AWS SDK for Go v2 SDK EventStream Decoder in github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream
KEDA has PostgreSQL connection string parameter injection via incomplete whitespace escaping
KEDA has PostgreSQL connection string parameter injection via incomplete whitespace escaping
Root escape via symlink plus trailing slash in os
Root escape via symlink plus trailing slash in os
Contour has Improper JWT Verification for Non-SNI Requests on Virtual Hosts with Fallback Certificate Enabled in github.com/projectcontour/contour
Contour has Improper JWT Verification for Non-SNI Requests on Virtual Hosts with Fallback Certificate Enabled in github.com/projectcontour/contour
Invoking Encrypted Client Hello privacy leak in crypto/tls
Invoking Encrypted Client Hello privacy leak in crypto/tls
CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation
CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation
Gitea LFS mirror operations bypass migration HTTP transport protections
Gitea LFS mirror operations bypass migration HTTP transport protections
Gitea OAuth2 PKCE S256 verifier bypass
Gitea OAuth2 PKCE S256 verifier bypass
Gitea template repository generation follows unsafe filesystem paths
Gitea template repository generation follows unsafe filesystem paths
Gitea git grep searches allow server resource exhaustion
Gitea git grep searches allow server resource exhaustion
Gitea organization permission APIs expose hidden membership and private organization data
Gitea organization permission APIs expose hidden membership and private organization data
Gitea primary email ownership bypass allows cross-user email changes
Gitea primary email ownership bypass allows cross-user email changes
Gitea repository creation accepts insufficiently validated fields
Gitea repository creation accepts insufficiently validated fields
Gitea release asset dumps permit path traversal through crafted names
Gitea release asset dumps permit path traversal through crafted names
Gitea OAuth2 authorization codes can be reused after expiry
Gitea OAuth2 authorization codes can be reused after expiry
Gitea pull request branch permission checks allow unauthorized updates and rebases
Gitea pull request branch permission checks allow unauthorized updates and rebases
Gitea exposes tracked time entries without repository authorization
Gitea exposes tracked time entries without repository authorization
Gitea tracked-time deletion is not scoped to the requested issue
Gitea tracked-time deletion is not scoped to the requested issue
Gitea draft releases and attachments are exposed without write permission
Gitea draft releases and attachments are exposed without write permission
Gitea pre-receive hook scanner errors allow branch-protection bypass
Gitea pre-receive hook scanner errors allow branch-protection bypass
Gitea forwarded-proto validation allows canonical URL spoofing
Gitea forwarded-proto validation allows canonical URL spoofing
golang.org/x/image/tiff has excessive resource consumption in PackBits decompression
golang.org/x/image/tiff has excessive resource consumption in PackBits decompression
Contour has Improper JWT Verification for Non-SNI Requests on Virtual Hosts with Fallback Certificate Enabled
Contour has Improper JWT Verification for Non-SNI Requests on Virtual Hosts with Fallback Certificate Enabled
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
oras-go blob upload vulnerable to credential forwarding via unvalidated Location header
oras-go blob upload vulnerable to credential forwarding via unvalidated Location header
Concourse login flow has an open redirect issue
Concourse login flow has an open redirect issue
Rancher has over-inclusive team membership expansion in GitHub App authentication provider
Rancher has over-inclusive team membership expansion in GitHub App authentication provider
oras-go has file store write outside workingDir via symlink traversal
oras-go has file store write outside workingDir via symlink traversal
Rancher has Privilege Escalation from Project Owner to Host
Rancher has Privilege Escalation from Project Owner to Host
ORAS Go forwards registry credentials across registry redirects
ORAS Go forwards registry credentials across registry redirects
`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution
`oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution
oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens
oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens
Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw)
Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw)
Rancher vulnerable to command injection through unsanitized YAML parameter
Rancher vulnerable to command injection through unsanitized YAML parameter
Sigstore Timestamp Authority has OOM due to unbounded metric label cardinality
Sigstore Timestamp Authority has OOM due to unbounded metric label cardinality
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage
MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints
MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints
Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check
Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check
regclient may leak authentication credentials to external blob stores
regclient may leak authentication credentials to external blob stores
chi Has an IP Spoofing Vulnerability in `middleware.RealIP`
chi Has an IP Spoofing Vulnerability in `middleware.RealIP`
ech0's acess tokens with expiry=never cannot be revoked: logout panics, delete does not blacklist JTI in github.com/lin-snow/ech0
ech0's acess tokens with expiry=never cannot be revoked: logout panics, delete does not blacklist JTI in github.com/lin-snow/ech0
golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoS
golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoS
Ech0's OAuth redirect URI validation ignores path component, enables exchange-code theft in github.com/lin-snow/ech0
Ech0's OAuth redirect URI validation ignores path component, enables exchange-code theft in github.com/lin-snow/ech0
golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses
golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses
Ech0's Unauthenticated Like Endpoint Enables Arbitrary Engagement Metric Inflation in github.com/lin-snow/ech0
Ech0's Unauthenticated Like Endpoint Enables Arbitrary Engagement Metric Inflation in github.com/lin-snow/ech0
golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow
golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow
golang.org/x/crypto vulnerable to infinite loop on large channel writes
golang.org/x/crypto vulnerable to infinite loop on large channel writes
OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing in github.com/oauth2-proxy/oauth2-proxy
OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing in github.com/oauth2-proxy/oauth2-proxy
Distribution's tag deletion bypasses `storage.delete.enabled` configuration in github.com/distribution/distribution
Distribution's tag deletion bypasses `storage.delete.enabled` configuration in github.com/distribution/distribution
golang.org/x/crypto vulnerable to invoking bypass of certificate restrictions
golang.org/x/crypto vulnerable to invoking bypass of certificate restrictions
Ech0 has Server-Side Request Forgery (SSRF) via Connect Handler fetchPeerConnectInfo in github.com/lin-snow/ech0
Ech0 has Server-Side Request Forgery (SSRF) via Connect Handler fetchPeerConnectInfo in github.com/lin-snow/ech0
Ech0's Missing Authorization on System Logs Allows Non-Admin Information Disclosure in github.com/lin-snow/ech0
Ech0's Missing Authorization on System Logs Allows Non-Admin Information Disclosure in github.com/lin-snow/ech0
Ech0 has SSRF via DNS Resolution Bypass in Webhook URL Validation in github.com/lin-snow/ech0
Ech0 has SSRF via DNS Resolution Bypass in Webhook URL Validation in github.com/lin-snow/ech0
Rekor has an OOM Condition due to Unbounded gzip Decompression in Alpine APK Parsing Logic
Rekor has an OOM Condition due to Unbounded gzip Decompression in Alpine APK Parsing Logic
golang.org/x/crypto vulnerable to auth bypass via unenforced @revoked status
golang.org/x/crypto vulnerable to auth bypass via unenforced @revoked status
Ech0: Missing authorization on dashboard log endpoints allows low-privilege users to access sensitive system logs in github.com/lin-snow/ech0
Ech0: Missing authorization on dashboard log endpoints allows low-privilege users to access sensitive system logs in github.com/lin-snow/ech0
chi Middleware Vulnerable to Potential IP Spoofing via `X-Forwarded-For` Header in `Request.RemoteAddr` Resolution
chi Middleware Vulnerable to Potential IP Spoofing via `X-Forwarded-For` Header in `Request.RemoteAddr` Resolution
Ech0 has Stored XSS via SVG Upload and Content-Type Validation Bypass in File Upload in github.com/lin-snow/ech0
Ech0 has Stored XSS via SVG Upload and Content-Type Validation Bypass in File Upload in github.com/lin-snow/ech0
golang.org/x/crypto: Invoking pathological inputs can lead to client panic
golang.org/x/crypto: Invoking pathological inputs can lead to client panic
golang.org/x/crypto: Invoking byte arithmetic causes underflow and panic
golang.org/x/crypto: Invoking byte arithmetic causes underflow and panic
chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header
chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header
Ech0 allows PUT /api/echo/like/:id unauthenticated: anonymous callers to modify any echo's fav_count in github.com/lin-snow/ech0
Ech0 allows PUT /api/echo/like/:id unauthenticated: anonymous callers to modify any echo's fav_count in github.com/lin-snow/ech0
golang.org/x/crypto: Invoking memory leak when rejecting channels can lead to DoS
golang.org/x/crypto: Invoking memory leak when rejecting channels can lead to DoS
Ech0: Scoped admin access tokens can bypass least-privilege controls on privileged endpoints, including backup export in github.com/lin-snow/ech0
Ech0: Scoped admin access tokens can bypass least-privilege controls on privileged endpoints, including backup export in github.com/lin-snow/ech0
golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcement
golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcement
Race condition in 'docker cp' in github.com/docker/docker allows creation of arbitrary files
Race condition in 'docker cp' in github.com/docker/docker allows creation of arbitrary files
Ech0 Comment Panel Endpoints Missing RequireScopes Middleware — Scoped Access Token Bypass in github.com/lin-snow/ech0
Ech0 Comment Panel Endpoints Missing RequireScopes Middleware — Scoped Access Token Bypass in github.com/lin-snow/ech0
Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
golang.org/x/crypto doesn't enforce invoking key constraints
golang.org/x/crypto doesn't enforce invoking key constraints
Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Ech0 Scope Bypass: profile:read Access Token Can Change Admin Password and Escalate to Unrestricted Session in github.com/lin-snow/ech0
Ech0 Scope Bypass: profile:read Access Token Can Change Admin Password and Escalate to Unrestricted Session in github.com/lin-snow/ech0
golang.org/x/crypto: FIDO/U2F security key physical presence check can be bypassed
golang.org/x/crypto: FIDO/U2F security key physical presence check can be bypassed
Ech0 comment model's Email field returned on public /api/comments endpoints in github.com/lin-snow/ech0
Ech0 comment model's Email field returned on public /api/comments endpoints in github.com/lin-snow/ech0
golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys
golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys
Ech0's RSS feed renders unescaped tag names and raw-HTML markdown, stored XSS against subscribers in github.com/lin-snow/ech0
Ech0's RSS feed renders unescaped tag names and raw-HTML markdown, stored XSS against subscribers in github.com/lin-snow/ech0
Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation
Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList() in github.com/google/go-attestation
OpenTofu: Provider cache installation follows root-module-controlled package directory symlink and writes outside the working tree in github.com/opentofu/opentofu
OpenTofu: Provider cache installation follows root-module-controlled package directory symlink and writes outside the working tree in github.com/opentofu/opentofu
opentelemetry-ebpf-profiler: Unprivileged process can trigger a denial of service on the ebpf-profiler agent
opentelemetry-ebpf-profiler: Unprivileged process can trigger a denial of service on the ebpf-profiler agent
OpenTofu: Provider cache installation follows root-module-controlled package directory symlink and writes outside the working tree
OpenTofu: Provider cache installation follows root-module-controlled package directory symlink and writes outside the working tree
runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations
runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations
Gophish contains a denial of service vulnerability
Gophish contains a denial of service vulnerability
OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset
OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset
containerd CRI checkpoint restore CDI annotation smuggling
containerd CRI checkpoint restore CDI annotation smuggling
containerd CRI — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull
containerd CRI — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull
Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails
Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails
containerd image-triggered runtime DoS via unbounded group parsing
containerd image-triggered runtime DoS via unbounded group parsing
containerd: CRI checkpoint import allows local image tag poisoning
containerd: CRI checkpoint import allows local image tag poisoning
Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms
Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms
Crossplane: Signature verification TOCTOU allows installing unverified package content via mutable tag
Crossplane: Signature verification TOCTOU allows installing unverified package content via mutable tag
Arbitrary host CRI log file read via symlink following in CRI checkpoint restore
Arbitrary host CRI log file read via symlink following in CRI checkpoint restore
Grafana Tempo vulnerable to an out-of-memory crash
Grafana Tempo vulnerable to an out-of-memory crash
OpenFGA Improper Policy Enforcement
OpenFGA Improper Policy Enforcement
Heimdall: IP Spoofing via Unvalidated Forwarding Headers
Heimdall: IP Spoofing via Unvalidated Forwarding Headers
Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services
Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services
Rclone: Unauthenticated command execution in `rclone rcd --rc-serve` via inline remote instantiation, bypassing CVE-2026-41179 fix
Rclone: Unauthenticated command execution in `rclone rcd --rc-serve` via inline remote instantiation, bypassing CVE-2026-41179 fix
Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypass
Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypass
Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts
Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts
Filestash allows attackers to escalate privileges via sending a crafted request
Filestash allows attackers to escalate privileges via sending a crafted request
linx-server has an issue in the uploadPostHandler component that allows attackers to cause a Denial of Service (DoS) via a crafted POST request
linx-server has an issue in the uploadPostHandler component that allows attackers to cause a Denial of Service (DoS) via a crafted POST request
statping-ng allows attackers to escalate privileges to Administrator and access sensitive components
statping-ng allows attackers to escalate privileges to Administrator and access sensitive components
MCP Toolbox for Databases has an Origin Validation Error
MCP Toolbox for Databases has an Origin Validation Error
Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations
Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations
Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync
Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync
Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints
Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints
Mattermost doesn't require system-level permission when patching protected default system roles
Mattermost doesn't require system-level permission when patching protected default system roles
Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation
Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation
Mattermost doesn't validate that a username returned during bot registration belongs to a bot account
Mattermost doesn't validate that a username returned during bot registration belongs to a bot account
Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList()
Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList()
Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel
Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel
OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poisoning
OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poisoning
Traefik has a StripPrefix Route-Level Auth Bypass via Path Normalization
Traefik has a StripPrefix Route-Level Auth Bypass via Path Normalization
Openshift Migration Advisor lacks proper authorization and filtering for its DELETE /api/v1/sources API
Openshift Migration Advisor lacks proper authorization and filtering for its DELETE /api/v1/sources API
OpenTelemetry Operator for Kubernetes's ServiceMonitor bearerTokenFile reads arbitrary local file and sends contents as bearer auth
OpenTelemetry Operator for Kubernetes's ServiceMonitor bearerTokenFile reads arbitrary local file and sends contents as bearer auth
Apache Answer: AdminToken not invalidated after admin deactivation
Apache Answer: AdminToken not invalidated after admin deactivation
Assisted Migration Agent: Path traversal in gzipped tarball handling enables arbitrary file write and remote code execution
Assisted Migration Agent: Path traversal in gzipped tarball handling enables arbitrary file write and remote code execution
Openshift Migration Advisor: Improper input sanitization allows specially crafted RVTools .xlsx files to include malicious SQL commands
Openshift Migration Advisor: Improper input sanitization allows specially crafted RVTools .xlsx files to include malicious SQL commands
Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs
Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs
Assisted Migration Agent: Hardcoded insecure Transport Layer Security (TLS) connections during vCenter communication
Assisted Migration Agent: Hardcoded insecure Transport Layer Security (TLS) connections during vCenter communication
Openshift Migration Advisor agent-API fails to validate JWT source_id claim, allowing cross-tenant data manipulation
Openshift Migration Advisor agent-API fails to validate JWT source_id claim, allowing cross-tenant data manipulation
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
Apache Answer has an Unrestricted Upload of File with Dangerous Type vulnerability
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
Apache Answer has an Exposure of Private Personal Information to an Unauthorized Actor vulnerability
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Apache Answer has an Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
Apache Answer has an Improper Neutralization of Alternate XSS Syntax vulnerability
Apache Answer vulnerable to Cross-site Scripting
Apache Answer vulnerable to Cross-site Scripting
Weaviate has an Improper Authorization issue
Weaviate has an Improper Authorization issue
grepai Uses a Broken or Risky Cryptographic Algorithm
grepai Uses a Broken or Risky Cryptographic Algorithm
songquanpeng one-api has an issue that results in business logic errors
songquanpeng one-api has an issue that results in business logic errors
grepai Uses a Broken or Risky Cryptographic Algorithm
grepai Uses a Broken or Risky Cryptographic Algorithm
ebpf-go is vulnerable to integer overflow via LoadCollectionSpecFromReader
ebpf-go is vulnerable to integer overflow via LoadCollectionSpecFromReader
quic-go: HTTP/3 QPACK Trailer Expansion Memory Exhaustion
quic-go: HTTP/3 QPACK Trailer Expansion Memory Exhaustion
Quadratic complexity in WordDecoder.DecodeHeader in mime
Quadratic complexity in WordDecoder.DecodeHeader in mime
Arbitrary inputs are included in errors without any escaping in net/textproto
Arbitrary inputs are included in errors without any escaping in net/textproto
Inefficient candidate hostname parsing in crypto/x509
Inefficient candidate hostname parsing in crypto/x509
Nezha's authenticated agents can forge service-monitor results for other users' services
Nezha's authenticated agents can forge service-monitor results for other users' services
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints
Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints
Gotenberg has an SSRF deny-list bypass in IsPublicIP via IPv6 6to4 / NAT64 / site-local prefixes
Gotenberg has an SSRF deny-list bypass in IsPublicIP via IPv6 6to4 / NAT64 / site-local prefixes
go-git: Malformed Git object data may cause panics or resource exhaustion
go-git: Malformed Git object data may cause panics or resource exhaustion
KubeVirt has a Link Following issue
KubeVirt has a Link Following issue
opentelemetry-go's baggage parsing no longer caps raw header length
opentelemetry-go's baggage parsing no longer caps raw header length
Calico Inserts Sensitive Information into Log File
Calico Inserts Sensitive Information into Log File
Calico Inserts Sensitive Information into Log File
Calico Inserts Sensitive Information into Log File
Go Net HTML parser is vulnerable to denial of service
Go Net HTML parser is vulnerable to denial of service
KubeVirt has a Link Following vulnerability
KubeVirt has a Link Following vulnerability
Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh
Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh
Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh
Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh
Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh
Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh
Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh
Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh
Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent
Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent
Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent
Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent
Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html
Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html
Invoking duplicate attributes can cause XSS in golang.org/x/net/html
Invoking duplicate attributes can cause XSS in golang.org/x/net/html
Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html
Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html
Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna
Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna
Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts
Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts
containerd user ID handling bypass allows runAsNonRoot evasion
containerd user ID handling bypass allows runAsNonRoot evasion
Gotenberg's DNS rebinding bypasses SSRF validation on Chromium URL conversion routes in github.com/gotenberg/gotenberg
Gotenberg's DNS rebinding bypasses SSRF validation on Chromium URL conversion routes in github.com/gotenberg/gotenberg
OpenTofu: Excessive resource usage in "tofu init" when installing dependencies from attacker-controlled server
OpenTofu: Excessive resource usage in "tofu init" when installing dependencies from attacker-controlled server
MCP Registry: OCI validator skips ownership check on upstream rate limits
MCP Registry: OCI validator skips ownership check on upstream rate limits
Dasel: Index-out-of-range panic in dasel selector lexer on trailing backslash in quoted string
Dasel: Index-out-of-range panic in dasel selector lexer on trailing backslash in quoted string
Dasel: Denial of service in dasel selector lexer due to infinite loop on unterminated regex literal
Dasel: Denial of service in dasel selector lexer due to infinite loop on unterminated regex literal
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation
go-git: Improper single-quote escaping in go-git SSH transport
go-git: Improper single-quote escaping in go-git SSH transport
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations
Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations
Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write)
Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write)
Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer
Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer
Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes
Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes
Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs
Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs
go-git: Crafted repositories may modify main and submodule .git directories
go-git: Crafted repositories may modify main and submodule .git directories
iskorotkov/avro: CPU Exhaustion in Decoder
iskorotkov/avro: CPU Exhaustion in Decoder
iskorotkov/avro: Integer Overflow in Decoder
iskorotkov/avro: Integer Overflow in Decoder
Docker: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swap
Docker: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swap
Docker: `PUT /containers/{id}/archive` executes container binary on the host
Docker: `PUT /containers/{id}/archive` executes container binary on the host
iskorotkov/avro: Denial-of-Service Vulnerability in Decoder
iskorotkov/avro: Denial-of-Service Vulnerability in Decoder
Docker: Race condition in docker cp allows bind mount redirection to host path
Docker: Race condition in docker cp allows bind mount redirection to host path
slack-go `SecretsVerifier` accepts empty signing secret without precondition
slack-go `SecretsVerifier` accepts empty signing secret without precondition
go-billy has path traversal vulnerabilities
go-billy has path traversal vulnerabilities
Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin
Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin
Grafana: SQL Expressions Read File From Disk
Grafana: SQL Expressions Read File From Disk
Grafana: Users can generate Service Account tokens after permissions removal
Grafana: Users can generate Service Account tokens after permissions removal
go-billy: Lack of depth and cycle detection in symlink resolution may lead to infinite loops and resource exhaustion
go-billy: Lack of depth and cycle detection in symlink resolution may lead to infinite loops and resource exhaustion
go-git's improper parsing of specially crafted objects may lead to inconsistent interpretation compared to upstream Git
go-git's improper parsing of specially crafted objects may lead to inconsistent interpretation compared to upstream Git
CloudNativePG's metrics exporter allows privilege escalation to PostgreSQL superuser and OS RCE
CloudNativePG's metrics exporter allows privilege escalation to PostgreSQL superuser and OS RCE
gitsign verify accepts signatures over go-git-normalized bytes, enabling trust confusion on malformed commits
gitsign verify accepts signatures over go-git-normalized bytes, enabling trust confusion on malformed commits
MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience
MCP Registry's GitHub OIDC tokens are replayable across registry deployments due to shared audience
MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl`
MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl`
MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist
MCP Registry has an unauthenticated SSRF: HTTP namespace verification dials 6to4 / NAT64 / site-local IPv6 addresses, bypassing private-address allowlist
in-toto-golang and in-toto-python have inconsistent negation behavior
in-toto-golang and in-toto-python have inconsistent negation behavior
gitsign --verify panics on empty-certificate PKCS7 and exits 0, bypassing exit-code callers
gitsign --verify panics on empty-certificate PKCS7 and exits 0, bypassing exit-code callers
MCP Registry has open redirect via protocol-relative path in trailing-slash middleware
MCP Registry has open redirect via protocol-relative path in trailing-slash middleware
ExternalSecrets vulnerable to privilege escalation with secret overwriting
ExternalSecrets vulnerable to privilege escalation with secret overwriting
Ech0's Unauthenticated Like Endpoint Enables Arbitrary Engagement Metric Inflation
Ech0's Unauthenticated Like Endpoint Enables Arbitrary Engagement Metric Inflation
Quadratic string concatentation in consumeComment in net/mail
Quadratic string concatentation in consumeComment in net/mail
Ech0's OAuth redirect URI validation ignores path component, enables exchange-code theft
Ech0's OAuth redirect URI validation ignores path component, enables exchange-code theft
Gotenberg's DNS rebinding bypasses SSRF validation on Chromium URL conversion routes
Gotenberg's DNS rebinding bypasses SSRF validation on Chromium URL conversion routes
Crash when handling long CNAME response in net
Crash when handling long CNAME response in net
Rancher Extensions have arbitrary file access via path traversal
Rancher Extensions have arbitrary file access via path traversal
go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth
go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth
etcd RBAC bypass allows unauthorized data access via PrevKv/lease attachment in nested transaction Put requests
etcd RBAC bypass allows unauthorized data access via PrevKv/lease attachment in nested transaction Put requests
Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net
Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net
Quadratic string concatenation in consumePhrase in net/mail
Quadratic string concatenation in consumePhrase in net/mail
Ech0's RSS feed renders unescaped tag names and raw-HTML markdown, stored XSS against subscribers
Ech0's RSS feed renders unescaped tag names and raw-HTML markdown, stored XSS against subscribers
ech0's acess tokens with expiry=never cannot be revoked: logout panics, delete does not blacklist JTI
ech0's acess tokens with expiry=never cannot be revoked: logout panics, delete does not blacklist JTI
Ech0 allows PUT /api/echo/like/:id unauthenticated: anonymous callers to modify any echo's fav_count
Ech0 allows PUT /api/echo/like/:id unauthenticated: anonymous callers to modify any echo's fav_count
Ech0 comment model's Email field returned on public /api/comments endpoints
Ech0 comment model's Email field returned on public /api/comments endpoints
ReverseProxy forwards queries with more than urlmaxqueryparams parameters in net/http/httputil
ReverseProxy forwards queries with more than urlmaxqueryparams parameters in net/http/httputil
Escaper bypass leads to XSS in html/template
Escaper bypass leads to XSS in html/template
Bypass of meta content URL escaping causes XSS in html/template
Bypass of meta content URL escaping causes XSS in html/template
Panic in Dial and LookupPort when handling NUL byte on Windows in net
Panic in Dial and LookupPort when handling NUL byte on Windows in net
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction
Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
Ech0 has Server-Side Request Forgery (SSRF) via Connect Handler fetchPeerConnectInfo
Ech0 has Server-Side Request Forgery (SSRF) via Connect Handler fetchPeerConnectInfo
Invoking "go tool pack" does not sanitize output paths in cmd/go
Invoking "go tool pack" does not sanitize output paths in cmd/go
Malicious module proxy can bypass checksum database in cmd/go
Malicious module proxy can bypass checksum database in cmd/go
opentelemetry-collector-contrib's azureauthextension Authenticate method does not validate bearer tokens, allowing auth bypass via replay
opentelemetry-collector-contrib's azureauthextension Authenticate method does not validate bearer tokens, allowing auth bypass via replay
Harvester's SUSE Virtualization Registration Client Vulnerable to MITM and DOS
Harvester's SUSE Virtualization Registration Client Vulnerable to MITM and DOS
Kyverno policy-reporter-ui has XSS via Stored Property Values in PropertyCard Component
Kyverno policy-reporter-ui has XSS via Stored Property Values in PropertyCard Component
Prometheus: Remote read endpoint allows denial of service via crafted snappy payload
Prometheus: Remote read endpoint allows denial of service via crafted snappy payload
Prometheus vulnerable to stored XSS via crafted histogram bucket label values in the old web UI heatmap display
Prometheus vulnerable to stored XSS via crafted histogram bucket label values in the old web UI heatmap display
Prometheus Azure AD remote write OAuth client secret exposed via config API
Prometheus Azure AD remote write OAuth client secret exposed via config API
MinIO vulnerable to Path Traversal via msgpack Body in `ReadMultiple` Storage-REST Endpoint
MinIO vulnerable to Path Traversal via msgpack Body in `ReadMultiple` Storage-REST Endpoint
Fiber vulnerable to XSS in AutoFormat Content Negotiation
Fiber vulnerable to XSS in AutoFormat Content Negotiation
External Secrets Operator has Namespace Isolation Bypass in CAProvider ConfigMap Resolution for SecretStore
External Secrets Operator has Namespace Isolation Bypass in CAProvider ConfigMap Resolution for SecretStore
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go)
Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go)
apko `DiscoverKeys` has a panic on non-rsa jwks key that causes crash during key discovery
apko `DiscoverKeys` has a panic on non-rsa jwks key that causes crash during key discovery
apko dirFS has a symlink-following path traversal that allows multiple entry points to escape the build root
apko dirFS has a symlink-following path traversal that allows multiple entry points to escape the build root
Ollama contains a heap out-of-bounds read vulnerability in the GGUF model loader
Ollama contains a heap out-of-bounds read vulnerability in the GGUF model loader
Distribution's tag deletion bypasses `storage.delete.enabled` configuration
Distribution's tag deletion bypasses `storage.delete.enabled` configuration
apko doesn't verify downloaded apk packages against APKINDEX checksum (package substitution possible)
apko doesn't verify downloaded apk packages against APKINDEX checksum (package substitution possible)
Argo has Missing Authorization in its Sync ConfigMap Provider
Argo has Missing Authorization in its Sync ConfigMap Provider
Traefik's errors middleware forwards Authorization and Cookie headers to separate error page service
Traefik's errors middleware forwards Authorization and Cookie headers to separate error page service
Argo vulnerable to exposure of artifact repository credentials
Argo vulnerable to exposure of artifact repository credentials
CoreDNS' DoQ worker pool does not bound stream backlog
CoreDNS' DoQ worker pool does not bound stream backlog
CoreDNS has TSIG authentication bypass on DoT, DoH, DoH3, DoQ, and gRPC
CoreDNS has TSIG authentication bypass on DoT, DoH, DoH3, DoQ, and gRPC
CoreDNS has TSIG authentication bypass on gRPC and QUIC transports
CoreDNS has TSIG authentication bypass on gRPC and QUIC transports
Apache Thrift TFramedTransport Go language implementation has an Integer Overflow or Wraparound vulnerability
Apache Thrift TFramedTransport Go language implementation has an Integer Overflow or Wraparound vulnerability
CoreDNS DoH GET oversized dns= query parameter causes pre-validation CPU and memory amplification
CoreDNS DoH GET oversized dns= query parameter causes pre-validation CPU and memory amplification
CoreDNS' transfer stanza selection uses lexicographic compare (subzone ACL bypass)
CoreDNS' transfer stanza selection uses lexicographic compare (subzone ACL bypass)
Ollama is Vulnerable to Path Traversal
Ollama is Vulnerable to Path Traversal
Cillium exposes sensitive information included in the cilium-bugtool debug archive
Cillium exposes sensitive information included in the cilium-bugtool debug archive
Contour has Lua code injection via Cookie Path Rewrite Policy
Contour has Lua code injection via Cookie Path Rewrite Policy
Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in NQuad Lang Field
Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in NQuad Lang Field
Dgraph: Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars
Dgraph: Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars
Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in Upsert Condition Field
Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in Upsert Condition Field
Grafana Tempo has an Uncontrolled Resource Consumption issue
Grafana Tempo has an Uncontrolled Resource Consumption issue
Kyverno Controller Denial of Service via forEach Mutation Panic
Kyverno Controller Denial of Service via forEach Mutation Panic
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller
Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller
go-ntlmssp NTLM challenges can panic on malformed payloads
go-ntlmssp NTLM challenges can panic on malformed payloads
pgx: SQL Injection via placeholder confusion with dollar quoted string literals
pgx: SQL Injection via placeholder confusion with dollar quoted string literals
Rclone: Unauthenticated options/set allows runtime auth bypass, leading to sensitive operations and command execution
Rclone: Unauthenticated options/set allows runtime auth bypass, leading to sensitive operations and command execution
OpenFGA has Improper Policy Enforcement
OpenFGA has Improper Policy Enforcement
RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution
RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution
Tekton Pipelines: HTTP Resolver Unbounded Response Body Read Enables Denial of Service via Memory Exhaustion
Tekton Pipelines: HTTP Resolver Unbounded Response Body Read Enables Denial of Service via Memory Exhaustion
OpenBao's SQL Injection in PostgreSQL database secrets engine
OpenBao's SQL Injection in PostgreSQL database secrets engine
OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate
OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate
Tekton Pipeline: Git Resolver Unsanitized Revision Parameter Enables git Argument Injection Leading to RCE
Tekton Pipeline: Git Resolver Unsanitized Revision Parameter Enables git Argument Injection Leading to RCE
OpenBao: Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)
OpenBao: Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)
OpenBao's Token Store Allows Cross-Namespace Renewal, Revocation
OpenBao's Token Store Allows Cross-Namespace Renewal, Revocation
Tekton Pipelines has VerificationPolicy regex pattern bypass via substring matching
Tekton Pipelines has VerificationPolicy regex pattern bypass via substring matching
Tekton Pipelines: VolumeMount path restriction bypass via missing filepath.Clean in /tekton/ check
Tekton Pipelines: VolumeMount path restriction bypass via missing filepath.Clean in /tekton/ check
Tekton Pipelines: Git resolver API mode leaks system-configured API token to user-controlled serverURL
Tekton Pipelines: Git resolver API mode leaks system-configured API token to user-controlled serverURL
go-git: Credential leak via cross-host redirect in smart HTTP transport
go-git: Credential leak via cross-host redirect in smart HTTP transport
HashiCorp Vault has Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS
HashiCorp Vault has Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service
Dapr: Service Invocation path traversal ACL bypass
Dapr: Service Invocation path traversal ACL bypass
goldmark vulnerable to Cross-site Scripting (XSS)
goldmark vulnerable to Cross-site Scripting (XSS)
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization
Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak)
Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak)
Kyverno: ServiceAccount token leaked to external servers via apiCall service URL
Kyverno: ServiceAccount token leaked to external servers via apiCall service URL
Dgraph: Unauthenticated /debug/pprof/cmdline discloses admin auth token, enabling unauthorized access to protected Alpha admin endpoints
Dgraph: Unauthenticated /debug/pprof/cmdline discloses admin auth token, enabling unauthorized access to protected Alpha admin endpoints
Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix)
Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix)
SpdyStream: DOS on CRI
SpdyStream: DOS on CRI
Istio: AuthorizationPolicy serviceAccounts regex injection via unescaped dots
Istio: AuthorizationPolicy serviceAccounts regex injection via unescaped dots
ACME Lego: Arbitrary File Write via Path Traversal in Webroot HTTP-01 Provider
ACME Lego: Arbitrary File Write via Path Traversal in Webroot HTTP-01 Provider
Istio: SSRF via RequestAuthentication jwksUri
Istio: SSRF via RequestAuthentication jwksUri
OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing
OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing
Grafana Loki Path Traversal - CVE-2021-36156 Bypass
Grafana Loki Path Traversal - CVE-2021-36156 Bypass
Pyroscope Exposes Storage Secret
Pyroscope Exposes Storage Secret
KubeVirt's authorization mechanism improperly truncates subresource names
KubeVirt's authorization mechanism improperly truncates subresource names
Go Markdown has an Out-of-bounds Read in SmartypantsRenderer
Go Markdown has an Out-of-bounds Read in SmartypantsRenderer
PowerShell Command Injection in Podman HyperV Machine
PowerShell Command Injection in Podman HyperV Machine
MinIO has an Unauthenticated Object Write via Query-String Credential Signature Bypass in Unsigned-Trailer Uploads
MinIO has an Unauthenticated Object Write via Query-String Credential Signature Bypass in Unsigned-Trailer Uploads
Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF
Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF
Kyverno has SSRF via CEL http.Get/http.Post in NamespacedValidatingPolicy allows cross-namespace data access
Kyverno has SSRF via CEL http.Get/http.Post in NamespacedValidatingPolicy allows cross-namespace data access
kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token
kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token
Sigstore Timestamp Authority has Improper Certificate Validation in verifier
Sigstore Timestamp Authority has Improper Certificate Validation in verifier
Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach
Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach
MinIO has an Unauthenticated Object Write via Missing Signature Verification in Unsigned-Trailer Uploads
MinIO has an Unauthenticated Object Write via Missing Signature Verification in Unsigned-Trailer Uploads
External Secrets Operator has DNS-based secret exfiltration via getHostByName in External Secrets v2 template engine
External Secrets Operator has DNS-based secret exfiltration via getHostByName in External Secrets v2 template engine
Prometheus has Stored XSS via metric names and label values in Prometheus web UI tooltips and metrics explorer
Prometheus has Stored XSS via metric names and label values in Prometheus web UI tooltips and metrics explorer
SiYuan: Publish Reader Path Traversal Delete via `removeUnusedAttributeView`
SiYuan: Publish Reader Path Traversal Delete via `removeUnusedAttributeView`
github.com/siyuan-note/siyuan/kernel: before 3.6.40.0.0-20260407035653-2f416e5253f1
Ech0 has SSRF via DNS Resolution Bypass in Webhook URL Validation
Ech0 has SSRF via DNS Resolution Bypass in Webhook URL Validation
Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segment
Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segment
Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint
Temporal does not enforce authentication and authorization for the streaming AdminService/StreamWorkflowReplicationMessages endpoint
Helm's plugin verification fails open when .prov is missing, allowing unsigned plugin install
Helm's plugin verification fails open when .prov is missing, allowing unsigned plugin install
Ech0: Scoped admin access tokens can bypass least-privilege controls on privileged endpoints, including backup export
Ech0: Scoped admin access tokens can bypass least-privilege controls on privileged endpoints, including backup export
Helm has a path traversal in plugin metadata version enables arbitrary file write outside Helm plugin directory
Helm has a path traversal in plugin metadata version enables arbitrary file write outside Helm plugin directory
Ech0's Missing Authorization on System Logs Allows Non-Admin Information Disclosure
Ech0's Missing Authorization on System Logs Allows Non-Admin Information Disclosure
Ech0 Scope Bypass: profile:read Access Token Can Change Admin Password and Escalate to Unrestricted Session
Ech0 Scope Bypass: profile:read Access Token Can Change Admin Password and Escalate to Unrestricted Session
Ech0: Missing authorization on dashboard log endpoints allows low-privilege users to access sensitive system logs
Ech0: Missing authorization on dashboard log endpoints allows low-privilege users to access sensitive system logs
Ech0 has Stored XSS via SVG Upload and Content-Type Validation Bypass in File Upload
Ech0 has Stored XSS via SVG Upload and Content-Type Validation Bypass in File Upload
LXD: Update of type field in restricted TLS certificate allows privilege escalation to cluster admin
LXD: Update of type field in restricted TLS certificate allows privilege escalation to cluster admin
LXD: VM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf
LXD: VM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf
LXD: Importing a crafted backup leads to project restriction bypass
LXD: Importing a crafted backup leads to project restriction bypass
Ech0 Comment Panel Endpoints Missing RequireScopes Middleware — Scoped Access Token Bypass
Ech0 Comment Panel Endpoints Missing RequireScopes Middleware — Scoped Access Token Bypass
MinIO affected a DoS via Unbounded Memory Allocation in S3 Select CSV Parsing
MinIO affected a DoS via Unbounded Memory Allocation in S3 Select CSV Parsing
HashiCorp's go-getter library may allow arbitrary file reads
HashiCorp's go-getter library may allow arbitrary file reads
kcp's cache server is accessible without authentication or authorization checks
kcp's cache server is accessible without authentication or authorization checks
OpenFGA: Unauthenticated playground endpoint discloses preshared API key in HTML response
OpenFGA: Unauthenticated playground endpoint discloses preshared API key in HTML response
opentelemetry-go: OTLP HTTP exporters read unbounded HTTP response bodies
opentelemetry-go: OTLP HTTP exporters read unbounded HTTP response bodies
Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder
Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder
mercure has Topic Selector Cache Key Collision
mercure has Topic Selector Cache Key Collision
opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking
opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking
Cosign's verify-blob-attestation reports false positive when payload parsing fails
Cosign's verify-blob-attestation reports false positive when payload parsing fails
File Browser has a Command Injection via Hook Runner
File Browser has a Command Injection via Hook Runner
pgx contains memory-safety vulnerability
pgx contains memory-safety vulnerability
OpenTelemetry-Go: multi-value `baggage` header extraction causes excessive allocations (remote dos amplification)
OpenTelemetry-Go: multi-value `baggage` header extraction causes excessive allocations (remote dos amplification)
Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls
Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls
Missing bound checks can lead to memory corruption in safe Go in cmd/compile
Missing bound checks can lead to memory corruption in safe Go in cmd/compile
Unexpected work during chain building in crypto/x509
Unexpected work during chain building in crypto/x509
OpenFGA's BatchCheck within-request deduplication produces incorrect authorization decisions via list-value cache-key collision
OpenFGA's BatchCheck within-request deduplication produces incorrect authorization decisions via list-value cache-key collision
Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509
Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509
Inefficient policy validation in crypto/x509
Inefficient policy validation in crypto/x509
Miscompilation allows memory corruption via CONVNOP-wrapped array copy in cmd/compile
Miscompilation allows memory corruption via CONVNOP-wrapped array copy in cmd/compile
Memory-safety vulnerability in github.com/jackc/pgx/v5.
Memory-safety vulnerability in github.com/jackc/pgx/v5.
TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix
TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix
go-ipld-prime: DAG-CBOR decoder unbounded memory allocation from CBOR headers
go-ipld-prime: DAG-CBOR decoder unbounded memory allocation from CBOR headers
Distribution: stale blob access resurrection via repo-scoped redis descriptor cache invalidation
Distribution: stale blob access resurrection via repo-scoped redis descriptor cache invalidation
Distribution affected by pull-through cache credential exfiltration via www-authenticate bearer realm
Distribution affected by pull-through cache credential exfiltration via www-authenticate bearer realm
Go JOSE Panics in JWE decryption
Go JOSE Panics in JWE decryption
Dgraph: Pre-Auth Database Overwrite + SSRF + File Read via restoreTenant Missing Authorization
Dgraph: Pre-Auth Database Overwrite + SSRF + File Read via restoreTenant Missing Authorization
Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster
Temporal Server: attacker-controlled namespace could signal, delete, and reset workflows or activities in a victim namespace on the same cluster
go-git: Maliciously crafted idx file can cause asymmetric memory consumption
go-git: Maliciously crafted idx file can cause asymmetric memory consumption
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover
github.com/0xJacky/Nginx-UI: all versions
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse
github.com/0xJacky/Nginx-UI: all versions
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation
github.com/0xJacky/Nginx-UI: all versions
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys
github.com/0xJacky/nginx-ui: all versions
go-git missing validation decoding Index v4 files leads to panic
go-git missing validation decoding Index v4 files leads to panic
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval
github.com/0xJacky/Nginx-UI: all versions
XPath: Boolean expression infinite loop leads to denial of service via CPU exhaustion
XPath: Boolean expression infinite loop leads to denial of service via CPU exhaustion
Traefik: Deny Rule Bypass via Unauthenticated Malicious gRPC Requests in gRPC-Go Dependency (CVE-2026-33186)
Traefik: Deny Rule Bypass via Unauthenticated Malicious gRPC Requests in gRPC-Go Dependency (CVE-2026-33186)
Flannel has cross-node remote code execution via extension backend BackendData injection
Flannel has cross-node remote code execution via extension backend BackendData injection
Moby has AuthZ plugin bypass when provided oversized request bodies
Moby has AuthZ plugin bypass when provided oversized request bodies
Traefik has Knative Ingress Rule Injection that Allows Host Restriction Bypass
Traefik has Knative Ingress Rule Injection that Allows Host Restriction Bypass
Grafana Tempo has Inadequate Encryption Strength
Grafana Tempo has Inadequate Encryption Strength
Traefik Vulnerable to BasicAuth/DigestAuth Identity Spoofing via Non-Canonical headerField
Traefik Vulnerable to BasicAuth/DigestAuth Identity Spoofing via Non-Canonical headerField
Moby has an Off-by-one error in its plugin privilege validation
Moby has an Off-by-one error in its plugin privilege validation
Grafana public dashboards disclose all direct mode datasources
Grafana public dashboards disclose all direct mode datasources
MinIO is Vulnerable to SSE Metadata Injection via Replication Headers
MinIO is Vulnerable to SSE Metadata Injection via Replication Headers
OpenFGA has an Authorization Bypass through cached keys
OpenFGA has an Authorization Bypass through cached keys
BuildKit Git URL subdir component can cause access to restricted files
BuildKit Git URL subdir component can cause access to restricted files
Grafana OSS: Authorization bypass allows users with Editor role to modify protected webhook URLs without permissions
Grafana OSS: Authorization bypass allows users with Editor role to modify protected webhook URLs without permissions
BuildKit's Malicious frontend can cause file escape outside of storage root
BuildKit's Malicious frontend can cause file escape outside of storage root
Cilium L7 proxy may bypass Kubernetes NetworkPolicy for same-node traffic
Cilium L7 proxy may bypass Kubernetes NetworkPolicy for same-node traffic
NATS: Pre-auth remote server crash via WebSocket frame length overflow in wsRead
NATS: Pre-auth remote server crash via WebSocket frame length overflow in wsRead
Go Images vulnerable to an out-of-memory error via a crafted TIFF file
Go Images vulnerable to an out-of-memory error via a crafted TIFF file
NATS Server: Incomplete Stripping of Nats-Request-Info Header Allows Identity Spoofing
NATS Server: Incomplete Stripping of Nats-Request-Info Header Allows Identity Spoofing
NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matching
NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matching
NATS: Message tracing can be redirected to arbitrary subject
NATS: Message tracing can be redirected to arbitrary subject
NATS is vulnerable to pre-auth DoS through WebSockets client service
NATS is vulnerable to pre-auth DoS through WebSockets client service
Trivy ecosystem supply chain was briefly compromised
Trivy ecosystem supply chain was briefly compromised
aquasecurity/trivy-action: before 0.35.0
NATS Server panic via malicious compression on leafnode port
NATS Server panic via malicious compression on leafnode port
NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headers
NATS: Leafnode connections allow spoofing of Nats-Request-Info identity headers
NATS JetStream has an authorization bypass through its Management API
NATS JetStream has an authorization bypass through its Management API
NATS allows MQTT clients to bypass ACL checks
NATS allows MQTT clients to bypass ACL checks
NATS has pre-auth server panic via leafnode handling
NATS has pre-auth server panic via leafnode handling
NATS credentials are exposed in monitoring port via command-line argv
NATS credentials are exposed in monitoring port via command-line argv
NATS is vulnerable to MQTT hijacking via Client ID
NATS is vulnerable to MQTT hijacking via Client ID
NATS has MQTT plaintext password disclosure
NATS has MQTT plaintext password disclosure
Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers
Vikunja has a Rate-Limit Bypass for Unauthenticated Users via Spoofed Headers
code.vikunja.io/api: 0.8 → 2.2.0
Vikunja has TOTP Reuse During Validity Window
Vikunja has TOTP Reuse During Validity Window
code.vikunja.io/api: ≥ 0.13
MinIO LDAP login brute-force via user enumeration and missing rate limit
MinIO LDAP login brute-force via user enumeration and missing rate limit
etcd: Authorization bypasses in multiple APIs
etcd: Authorization bypasses in multiple APIs
Syft improper temporary file cleanup
Syft improper temporary file cleanup
Ory Hydra has a SQL injection via forged pagination tokens
Ory Hydra has a SQL injection via forged pagination tokens
etcd: Nested etcd transactions bypass RBAC authorization checks
etcd: Nested etcd transactions bypass RBAC authorization checks
Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk
Improper handling of null Unicode character when parsing JSON in github.com/modelcontextprotocol/go-sdk
Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk
Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk
step-ca has Unauthenticated Certificate Issuance via SCEP UpdateReq (MessageType=18)
step-ca has Unauthenticated Certificate Issuance via SCEP UpdateReq (MessageType=18)
MinIO has JWT Algorithm Confusion in OIDC Authentication
MinIO has JWT Algorithm Confusion in OIDC Authentication
Metricbeat Allocates Memory with Excessive Size Value Leading to Denial of Service
Metricbeat Allocates Memory with Excessive Size Value Leading to Denial of Service
Dasel has unbounded YAML alias expansion in dasel leads to CPU/memory denial of service
Dasel has unbounded YAML alias expansion in dasel leads to CPU/memory denial of service
Packetbeat does not properly validate an array index in multiple protocol parser components
Packetbeat does not properly validate an array index in multiple protocol parser components
gosaml2 CBC Padding Panic — Unauthenticated Process Crash
gosaml2 CBC Padding Panic — Unauthenticated Process Crash
Zitadel is missing enforcement of organization scopes
Zitadel is missing enforcement of organization scopes
gRPC-Go has an authorization bypass via missing leading slash in :path
gRPC-Go has an authorization bypass via missing leading slash in :path
validateSignature Loop Variable Capture Signature Bypass in goxmldsig
validateSignature Loop Variable Capture Signature Bypass in goxmldsig
File Browser has an Authorization Policy Bypass in Public Share Download Flow
File Browser has an Authorization Policy Bypass in Public Share Download Flow
Denial of service in github.com/jackc/pgproto3/v2
Denial of service in github.com/jackc/pgproto3/v2
github.com/buger/jsonparser has a denial of service vulnerability
github.com/buger/jsonparser has a denial of service vulnerability
Denial of service in github.com/shamaton/msgpack
Denial of service in github.com/shamaton/msgpack
Path traversal in Tekton Pipelines git resolver allows reading arbitrary files from the resolver pod
Path traversal in Tekton Pipelines git resolver allows reading arbitrary files from the resolver pod
Unsigned SAML LogoutRequest Acceptance in gosaml2
Unsigned SAML LogoutRequest Acceptance in gosaml2
Tekton Pipelines controller panic via long resolver name in TaskRun/PipelineRun
Tekton Pipelines controller panic via long resolver name in TaskRun/PipelineRun
SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS
SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS
GoBGP vulnerable to a denial of service via the NEXT_HOP path attribute
GoBGP vulnerable to a denial of service via the NEXT_HOP path attribute
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode
Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode
Unauthorized access to Argo Workflows Template
Unauthorized access to Argo Workflows Template
Traefik: kubernetes gateway rule injection via unescaped backticks in HTTPRoute match values
Traefik: kubernetes gateway rule injection via unescaped backticks in HTTPRoute match values
CoreDNS Loop Detection Denial of Service Vulnerability
CoreDNS Loop Detection Denial of Service Vulnerability
Incorrect parsing of IPv6 host literals in net/url
Incorrect parsing of IPv6 host literals in net/url
Tooling for Go
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.