● Live advisory feed
Security Advisory Fusion for CSIRTs, SOCs & Defenders
Security advisories from 24 sources — CISA, CERT-EU, NCSC-UK, BSI, CERT-FR, NCSC-NL, JPCERT/CC, JVN, HKCERT, the Canadian Cyber Centre, NVD, GitHub, Microsoft, Cisco, Fortinet, Palo Alto Networks and more — normalized, translated to English and flagged against the CISA KEV catalog. One global feed for CSIRTs, SOCs and defenders.
Summary
An XSS vulnerability in Mistune allows bypassing of safe_url() protections via percent-encoded javascript URIs.
Details
The vulnerability exists in HTMLRenderer.safe_url() in Mistune.
The function is intended to block harmful URL schemes such as "javascript:" by checkin…
Summary
Type: Algorithmic-complexity DoS in core emphasis parsing. A long sequence of well-formed x (strong) or *x* (strong-emphasis combined) pairs causes O(N²) parser work. Distinct from the bracket-bomb DoS ([ repetition) and from the formatting-plugin DoS (~~/==/^^); this on…
Summary
Type: Uncontrolled recursion via mutual include. The Include directive checks for direct self-reference (a.md cannot include a.md), but does not detect indirect cycles. Two markdown files that include each other (a.md → includes b.md → includes a.md) cause unbounded recu…
Summary
Type: Algorithmic-complexity DoS in reference-link definition handling. A markdown document with N reference-link definitions of the same key (or many distinct keys) takes O(N²) parser time. 5000 repeated [a]: u\n definitions take ~1.1 second; 10000 → ~4.5 seconds.
File:…
It was discovered that libde265 did not properly manage memory under certain circumstances. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service. This issue only affected Ubuntu 22.04 LTS. (CVE-2023-51792) It was discovered that l…
Summary
A maliciously crafted package, published on an untrusted third party repository other than Packagist.org or Private Packagist, can cause Composer to write files outside the vendor/ directory and outside your project, with attacker-controlled content, during a normal inst…
Summary
_Short summary of the problem. Make the impact and severity as clear as possible. For example: An unsafe deserialization vulnerability allows any unauthenticated user to execute arbitrary code on the server._
Sending a pure prompt embeds payload in a /v1/completions requ…
It was discovered that Wget did not properly validate the IP address provided in an FTP PASV response when operating in FTP passive mode. A remote attacker controlling a malicious FTP server, or an HTTP server that redirects to an FTP URL, could possibly use this issue to redirec…
Summary
An integer overflow in the encode path buffer validation of _pillow_heif.c allows an attacker to bypass bounds checks by providing large image dimensions, resulting in a heap out-of-bounds read. This can lead to information disclosure (server heap memory leaking into enc…
Summary
The /static/<group>/<filename> route accepts group="..", which causes send_from_directory("static/..", filename) to execute. This moves the base directory up to /app/changedetectionio, enabling unauthenticated local file read of application source files (e.g., flask_app.p…
Pavel Kohout and Arkadi Vainbrand discovered that Apache HTTP Server incorrectly handled certain memory operations in mod_authn_socache. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-33007) Haruki Oyama, Merih Mengisteab, and Dawit Jeong …
Summary
The _parseparam function in Tornado's httputil.py is used to parse specific HTTP header values, such as those in multipart/form-data. This function uses an inefficient algorithm that repeatedly calls string.count() within a nested loop while processing quoted semicolons …
Summary
The HTTPHeaders.add method in Tornado accumulates values using string concatenation when the same header name is repeated. Due to Python string immutability, each concatenation copies the entire string, resulting in O(n²) time complexity.
Given Tornado's single event lo…
Header injection and XSS via reason argument
Summary
The reason argument (used by both RequestHandler.set_status and tornado.web.HTTPError is designed to allow applications to pass custom "reason" phrases (the "Not Found" in HTTP/1.1 404 Not Found) to the HTTP status line (main…
Summary
Axios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON, the helper behind the public axios.formToJSON() / named formToJSON API and the default request transform used when FormData is sent with an application/json content type.
Applications are a…
Summary
Axios versions after the GHSA-q8qp-cvcw-x6jj fix still contain prototype-pollution read-side gadgets in Basic auth subfield handling. If a host application is already affected by prototype pollution and then makes an axios request with an own auth object that omits usern…
Summary
Axios versions starting with 0.28.0 contain uncontrolled recursion in formDataToJSON, which is exposed as axios.formToJSON() and used internally when axios serialises FormData with Content-Type: application/json.
If an application passes attacker-controlled FormData fie…
It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local attacker could use this to expose sensitive information. (CVE-2025-54505) It was discovered that some AMD Zen 2 processors did not prope…
Serial number: AV26-722 Date: July 20, 2026 On July 20, 2026, HPE published a security advisory to address vulnerabilities in the following product: HPE Telco Automated Assurance – version v1.4 and prior The Cyber Centre encourages users and administrators to review the provided …
Serial number: AV26-693 Date: July 14, 2026 Updated: July 20, 2026 On July 13, 2026, ServiceNow published a security advisory to address a critical vulnerability in the following products: Brazil - versions prior to Brazil EA and Brazil GA Australia - versions prior to Australia …
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Foo-over-UDP (FOU); - ARM64 architecture; - x86 architecture; - Block layer subsystem; - Drivers c…
Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) guest portals could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due to insuf…
It was discovered that some AMD Zen 2 processors did not properly isolate shared resources in the operation cache. A local attacker could possibly use this issue to corrupt instructions executed at a higher privilege level, resulting in privilege escalation. (CVE-2025-54518) Seve…
It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local attacker could use this to expose sensitive information. (CVE-2025-54505) It was discovered that some AMD Zen 2 processors did not prope…
Serial number: AV26-721 Date: July 20, 2026 On July 20, 2026, Zimbra published a security advisory to address vulnerabilities in the following product: Zimbra Collaboration Suite (ZCS) Classic Web Client – versions prior to v10.1.20 The Cyber Centre encourages users and administr…
Serial number: AV26-720 Date: July 20, 2026 On July 16, 2026, GitHub published security advisories to address vulnerabilities in the following products: GitHub Enterprise Server – versions 3.21.x prior to 3.21.3 GitHub Enterprise Server – versions 3.20.x prior to 3.20.5 GitHub En…
Serial number: AV26-719 Date: July 20, 2026 Between July 13 and 19, 2026, Red Hat published security advisories to address vulnerabilities in multiple products. Included were updates to address vulnerabilities in the Linux kernel for the following products: Red Hat CodeReady Linu…
It was discovered that some AMD Zen 2 processors did not properly isolate shared resources in the operation cache. A local attacker could possibly use this issue to corrupt instructions executed at a higher privilege level, resulting in privilege escalation. (CVE-2025-54518) Seve…
Serial number: AV26–718 Date: July 20, 2026 Between July 13 and 19, 2026, CISA published ICS advisories to address vulnerabilities in the following products: ABB 800xA for Advant Master – multiple versions ABB Ability Edgenius – multiple versions and models ABB Control Builder A …
Serial number: AV26-717 Date: July 20, 2026 Between July 13 and 19, 2026, Ubuntu published security notices to address vulnerabilities in the Linux kernel affecting the following products: Ubuntu 14.04 LTS Ubuntu 16.04 LTS Ubuntu 20.04 LTS Ubuntu 24.04 LTS Ubuntu 25.10 The Cyber …
Serial number: AV26-716 Date: July 20, 2026 Between July 13 and 19, 2026, Dell published security advisories to address vulnerabilities in multiple products: Dell DRAC9 – versions prior to 7.00.00.184 Dell PowerEdge Server – multiple versions and models Dell PowerProtect Data Man…
Serial number: AV26-715 Date: July 20, 2026 Between July 13 and 19, 2026, IBM published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following: IBM API Connect V12 OnPrem – versions v12.1.0.0 to v12.1.1.0 IBM Automati…
It was discovered that SQLite did not properly handle NULL pointer dereferences in the Session Extension when applying a corrupt changeset. An attacker could possibly use this issue to cause SQLite to crash, resulting in a denial of service. (CVE-2026-50812) It was discovered tha…
It was discovered that PHP incorrectly handled certain TLS setup failures, resulting in a NULL pointer dereference. An attacker could possibly use this issue to cause PHP to crash, resulting in a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-12184) It wa…
It was discovered that libXfont incorrectly handled scaling bitmap fonts, leading to a heap buffer overflow. An attacker able to access the X server could use this issue to cause libXfont to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-56…
It was discovered that rlottie incorrectly handled certain shift operations. An attacker could possibly use this issue to cause rlottie to read out of bounds, resulting in a denial of service or exposing sensitive information. (CVE-2026-10305) It was discovered that rlottie did n…
It was discovered that nginx incorrectly handled certain map directives using regex matching and capture variables. A remote attacker could use this issue to cause nginx to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-42533) It was discov…
A local attacker can exploit a vulnerability in systemd to disclose information.
A remote, anonymous attacker can exploit a vulnerability in various HTTP/2 implementations to conduct a denial of service attack.
A remote, anonymous attacker can exploit multiple vulnerabilities in Mattermost to carry out an unspecified attack.
A remote, anonymous attacker can exploit a vulnerability in Red Hat OpenShift Pipelines Operator to carry out a Denial of Service attack.
A remote, anonymous or authenticated attacker can exploit multiple vulnerabilities in Red Hat Developer Hub to carry out a Denial of Service attack, execute arbitrary code, bypass security measures, and manipulate data.
A remote, anonymous attacker can exploit multiple vulnerabilities in Red Hat OpenShift Service Mesh to bypass security measures, execute malicious code, or cause a Denial of Service.
A remote, anonymous attacker can exploit a vulnerability in Red Hat Enterprise Linux to bypass security measures.
A remote, anonymous attacker can exploit a vulnerability in Red Hat Enterprise Linux (Developer Hub) to carry out a Denial of Service attack.
A remote, anonymous attacker can exploit a vulnerability in Red Hat Enterprise Linux to carry out a denial of service attack.
An attacker can exploit multiple vulnerabilities in Atlassian Bamboo, Atlassian Bitbucket, Atlassian Confluence, Atlassian Crucible, Atlassian Fisheye, and Atlassian Jira to execute arbitrary code, conduct a denial of service attack, disclose information, perform a cross-site scr…
An attacker can exploit multiple vulnerabilities in Proxmox Virtual Environment to carry out a Cross-Site Scripting attack, bypass security measures, and disclose confidential information.
A remote, authenticated attacker can exploit multiple vulnerabilities in Microsoft GitHub Enterprise Server to carry out a Denial of Service attack, manipulate data, execute code, and disclose information.
An attacker can exploit multiple vulnerabilities in IBM DB2 to carry out a Denial of Service attack and execute arbitrary program code.