● Live advisory feed
Security Advisory Fusion for CSIRTs, SOCs & Defenders
Security advisories from 24 sources — CISA, CERT-EU, NCSC-UK, BSI, CERT-FR, NCSC-NL, JPCERT/CC, JVN, HKCERT, the Canadian Cyber Centre, NVD, GitHub, Microsoft, Cisco, Fortinet, Palo Alto Networks and more — normalized, translated to English and flagged against the CISA KEV catalog. One global feed for CSIRTs, SOCs and defenders.
Impact
@fastify/static evaluates the allowedPath callback before normalizing dot segments and duplicate slashes in the pathname used for file resolution. Non-canonical pathnames such as //file, /./file, or /public/../private/file bypass allowedPath filtering while resolving to t…
Impact
@fastify/static is vulnerable to a bypass of route-based middleware and guards via non-leading .. and %2E%2E path segments. find-my-way does not normalize .. when matching routes, so a request such as /foo/../deep/secret.txt matches the static plugin's catch-all instead o…
Summary
GitPython's check_unsafe_options guard (the control introduced by CVE-2026-42215 / GHSA-2f96 and hardened since) can be bypassed for every guarded method (clone/clone_from, fetch/pull/push, ls_remote, iter_commits, blame, archive) by smuggling an option token inside the V…
Summary
GitPython's unsafe_git_clone_options denylist omits --template. git clone --template=<dir> copies <dir>/hooks/ into the new repository and runs them (post-checkout fires during clone), so a caller who can influence clone options can achieve arbitrary command execution in …
Summary
Diffable.diff() forwards **kwargs straight into diff/diff_tree with no check_unsafe_options guard. Diffable is mixed into Commit, Tree, IndexFile, and Submodule, giving a broad surface. git diff --output=<path> writes real patch content to an attacker-chosen path, enablin…
Summary
node-tar (npm tar) contains an uncontrolled-recursion stack-exhaustion DoS in the internal mapHas helper used by filesFilter. When a consumer calls tar.t(...) or tar.x(...) with a non-empty member-selection list, node-tar installs a filter that closes over the recursive m…
Vulnerability Details
File: lib/previous-map.js
Line: 87-98 (loadFile), 129-144 (loadMap)
Root Cause
PostCSS auto-detects a /*# sourceMappingURL=... */ comment inside the CSS text it is asked to parse and, unless the caller explicitly passes map: false, attempts to load that pa…
Summary
The TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies with unrestricted JavaScript member access. An attacker-controlled template could traverse constructor and prototype properties to execute JavaScript in the host Node.js process.
Affected packa…
Impact
_What kind of vulnerability is it? Who is impacted?_
Prototype pollution in update casting: passing a user-controlled update to a Mongoose update, like MyModel.updateOne(filter, req.body), can cause Mongoose to set $fullPath and $parentSchemaDocArray on Object.prototype.
…
Summary
In GitPython <= 3.1.52, the config writer neutralizes only CR, LF, and NUL in configuration names, but writes section names into the [...] header with no other escaping. A section/subsection name that contains ] [ " closes the intended header and opens a second same-line…
Summary
Remote Code Execution (RCE) in velocityjs v2.1.6 via property-read to the Function constructor. This bypasses the fix for GHSA-j658-c2gf-x6pq ("Prototype Pollution in #set path assignment") — that advisory blocked constructor/proto/prototype only in the #set assignment h…
Impact
The allowlist matching used by the experimental dynamic client registration and client ID metadata document (CIMD) features in @backstage/plugin-auth-backend matched glob patterns against the full URL string. A * wildcard could therefore match across URL component boundari…
When processing an extremely large JNX file on 32-bit platforms an integer overflow will happen that can cause a heap buffer over-write.
A heap buffer over-write can occur in the fx operation by passing a crafted argument.
An invalid kernel can cause a heap buffer over-write when performing a morphology operation with a user supplied kernel.
Serial number: AV26-742 Date: July 24, 2026 On July 24, 2026, Moxa published security advisories to address vulnerabilities in the following products: Moxa UC Series – multiple versions and models Moxa V Series – multiple versions and models Moxa VM-1220 Series – version MIL3 v1.…
Serial number: AV26-741 Date: July 24, 2026 On July 23, 2026, Google published a security advisory to address vulnerabilities in the following product: Stable Channel Chrome for Desktop – versions prior to 150.0.7871.186/.187 (Windows/Mac), and 150.0.7871.186 (Linux) The Cyber Ce…
An incomplete fix of CVE-2026-25797 can result in code injection in the HTML encoder.
An incomplete fix of CVE-2026-49219 could result in a policy bypass.
Matrix bases operations like -canny are missing a check for allowed memory allocation that could result allocating more memory than allowed.
Summary
The Assembler component that assembles unordered stream fragments into consecutive chunks of the stream incurs some overhead for non-contiguous fragments. Readers that read from a RecvStream in order (through an AsyncRead impl for example) will be sensitive to peers that…
This is a follow up to https://github.com/remix-run/react-router/security/advisories/GHSA-8x6r-g9mw-2r78 that covers additional reported scenarios in which the manifest endpoint could be accessed via unauthenticated targeted requests that would put heavy load on the server and sl…
The -concatenate operation is missing policy checks and that could result in both reading and writing to paths disallowed by the security policy.
Due to incorrect handling of arguments a heap buffer over-write can occur in the JP2 encoder.
When providing invalid arguments to the connected-components option an infinite loop will occur.
A missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided.
pop filter bypasses memoryLimit accounting that its array-filter siblings enforce
CWE: CWE-770 (Allocation of Resources Without Limits or Throttling) — sibling class of GHSA-8xx9-69p8-7jp3 and GHSA-2546-xv4c-mc8g, applied to memoryLimit instead of renderLimit
Summary
The pop a…
When identifying an image with a crafted 8BIM profile with a specific format string a use-after-free will occur.
Summary
In electron-builder's builder-util-runtime package, the HTTP redirect handler (HttpExecutor.prepareRedirectUrlOptions) only stripped a credential header whose key string matched exactly lowercase "authorization". Other credential-bearing headers — most notably PRIVATE-TO…
Summary
AppImage targets built by app-builder-lib could use an empty path component when setting the LD_LIBRARY_PATH environment variable at runtime. This causes the current working directory to be added to the dynamic linker search path, which may allow an attacker to execute a…
Serial number: AV26-740 Date: July 24, 2026 On July 23, 2026, Microsoft published a security update to address vulnerabilities in the following product: Microsoft Edge Stable Channel – versions prior to 150.0.4078.96 The Cyber Centre encourages users and administrators to review …
Check Point has fixed vulnerabilities in SmartConsole, Gaia Portal, Security Management, and Multi-Domain Security Management. The vulnerabilities involve authentication bypasses and privilege escalations within various Check Point management components. - In SmartConsole, unauth…
An attacker can exploit multiple vulnerabilities in vim to execute arbitrary code, conduct a denial of service attack, and cause unspecified impacts.
ZohoCorp has fixed a vulnerability in ManageEngine ADAudit Plus. The vulnerability is located in the agent API of ManageEngine ADAudit Plus versions earlier than 8606. Due to improper validation in the API, attackers can execute arbitrary code remotely without authentication. All…
An attacker can exploit multiple vulnerabilities in Progress Software MOVEit Transfer to bypass security measures, gain elevated privileges, manipulate or disclose data, or conduct cross-site scripting attacks.
An attacker can exploit multiple vulnerabilities in Netty to conduct a denial of service attack.
An attacker can exploit multiple vulnerabilities in ffmpeg to execute arbitrary code or to cause a denial-of-service condition.
A remote, authenticated attacker can exploit multiple vulnerabilities in CyberPanel to bypass security measures and manipulate files.
Maxim Suhanov discovered that the NTFS file system implementation in the Linux kernel did not properly validate file name length in certain situations, leading to an out-of-bounds read. An attacker could use this to construct a malicious NTFS image that, when mounted and operated…
Maxim Suhanov discovered that the NTFS file system implementation in the Linux kernel did not properly validate file name length in certain situations, leading to an out-of-bounds read. An attacker could use this to construct a malicious NTFS image that, when mounted and operated…
An attacker can exploit multiple vulnerabilities in cPanel cPanel/WHM to potentially execute arbitrary code, disclose confidential information, bypass security measures, manipulate data, or cause a denial-of-service condition.
A remote, authenticated attacker can exploit multiple vulnerabilities in RabbitMQ to conduct a denial of service attack and bypass security precautions.
A local attacker can exploit multiple vulnerabilities in JetBrains WebStorm to execute arbitrary program code.
It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local attacker could use this to expose sensitive information. (CVE-2025-54505) It was discovered that some AMD Zen 2 processors did not prope…
It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local attacker could use this to expose sensitive information. (CVE-2025-54505) It was discovered that some AMD Zen 2 processors did not prope…
A remote, anonymous attacker can exploit multiple vulnerabilities in JetBrains IntelliJ IDEA to disclose information, execute code, and bypass security measures.
A remote, authenticated attacker can exploit multiple vulnerabilities in JetBrains TeamCity to execute arbitrary program code.
It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local attacker could use this to expose sensitive information. (CVE-2025-54505) It was discovered that some AMD Zen 2 processors did not prope…
It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local attacker could use this to expose sensitive information. (CVE-2025-54505) It was discovered that some AMD Zen 2 processors did not prope…
It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local attacker could use this to expose sensitive information. (CVE-2025-54505) It was discovered that some AMD Zen 2 processors did not prope…