[UPDATE] [high] Netty: Multiple vulnerabilities
A remote, anonymous attacker can exploit multiple vulnerabilities in Netty to bypass security measures, manipulate data, disclose confidential information, or cause a denial-of-service condition.
● Live advisory feed
Security advisories from 24 sources — CISA, CERT-EU, NCSC-UK, BSI, CERT-FR, NCSC-NL, JPCERT/CC, JVN, HKCERT, the Canadian Cyber Centre, NVD, GitHub, Microsoft, Cisco, Fortinet, Palo Alto Networks and more — normalized, translated to English and flagged against the CISA KEV catalog. One global feed for CSIRTs, SOCs and defenders.
A remote, anonymous attacker can exploit multiple vulnerabilities in Netty to bypass security measures, manipulate data, disclose confidential information, or cause a denial-of-service condition.
A remote, anonymous attacker can exploit multiple vulnerabilities in Apache Traffic Server to bypass security measures, disclose or manipulate data, trigger a Denial-of-Service, and potentially achieve code execution.
Cisco has fixed a vulnerability in Cisco Secure Firewall Management Center. The vulnerability is located in the web interface of Cisco Secure Firewall Management Center and concerns a hard-coded, static password for a low-privileged account. This allows unauthenticated external a…
GitLab Inc. has fixed multiple vulnerabilities in GitLab, specifically in versions prior to 19.0.5, 19.1.3, and 19.2.1, including GitLab Enterprise Edition (EE) versions within these ranges. The vulnerabilities concern various components of GitLab: - Incorrect access control allo…
Trend Micro Incorporated has released a security update for TrendAI Vision One Service Gateway.
Multiple security issues were discovered in expat, an XML parsing C library, including integer overflows, out-of-bounds write, NULL pointer dereferences, excessive resource consumption, and memory corruption through re-entrant parser API calls, which may result in denial of servi…
Multiple vulnerabilities have been discovered in Node.js. Some of them allow an attacker to cause a remote denial of service, a breach of data confidentiality, and a breach of data integrity.
A vulnerability has been discovered in Cisco Firewall Management Center. It allows an attacker to cause a breach of data confidentiality and a bypass of security policy. Cisco indicates that the vulnerability CVE-2026-20316 is actively exploited.
A vulnerability has been discovered in Ruby on Rails activestorage. It allows an attacker to cause remote arbitrary code execution and a breach of data confidentiality.
Multiple vulnerabilities have been discovered in Google Chrome. They allow an attacker to cause an unspecified security issue by the vendor.
Multiple vulnerabilities have been discovered in VMware products. Some of them allow an attacker to cause remote arbitrary code execution, a remote denial of service, and a breach of data confidentiality.
Multiple vulnerabilities have been discovered in GitLab. Some of them allow an attacker to cause a remote denial of service, a breach of data confidentiality, and remote indirect code injection (XSS).
A vulnerability has been discovered in CPython. It allows an attacker to cause a remote denial of service.
It was discovered that Sinatra did not properly handle header parsing, causing ETag generation to hang when given specific input. A remote attacker could possibly use this issue to cause a denial of service.
Summary Despite the 0.104.0 patch escaping attribute-bearing constructs (\htmlData, \href), text-content reflection was missed. The \text{}, \mbox{} commands accept arbitrary characters in their body and emit them raw and unescaped into both the HTML markup and the MathML output…
OpenTelemetry Java Instrumentation JDBC auto-instrumentation may fail to sanitize passwords in SQL CONNECT statements when the password is double-quoted. As a result, clear-text database passwords can be added to trace span attributes and exported to observability backends.
The RMI context propagation payload reader limits the number of context entries but does not limit the aggregate size of the strings read from the stream. An attacker who can reach an RMI endpoint on an instrumented JVM can send an oversized context propagation payload. This can…
Summary Active Record Tenanted's override of Active Storage's DiskService#path_for does not validate that the resolved filesystem path remains within the storage root directory. If a blob key containing path traversal sequences (e.g. ../) is used, it could allow reading, writing…
Summary 0.0.0.0 was used instead of NXDOMAIN for block responses. On Linux, which is the target platform for netfoil, the 0.0.0.0 is sent to localhost rather than just dropped. Impact Unintended traffic could be sent to localhost. Impact depends on running services and firewall …
Summary The Fluentd configuration renderer in Logging operator writes strings from CRDs such as Flow directly into fluent.conf without escaping them. As a result, a user who can create Flow resources can inject Fluentd configuration by providing values that contain newlines. In…
Summary A vulnerability in Zitadel's self-management capability allowed users to mark their email and phone as verified without going through an actual verification process. While GHSA-282g-fhmx-xf54 (CVE-2026-27946, "Users Can Self-Verify Email/Phone via UpdateHumanUser API") …
Affected Component - Package: proot-distro - Affected command: restore - Attack surface: Host-side Termux CLI processing a user-supplied backup archive - Vulnerability type: Container Isolation Bypass / Cross-Container Read and Write Affected Versions | Component | Version | |…
Repository: termux/proot-distro Component: proot_distro/commands/install.py → _extract_plain_tar(); also helpers/docker.py → _apply_layer() Affected Versions | Component | Version | |---------------|------------------------------| | proot-distro | 5.0.2 (confirmed vulnerable) |…
Summary Easy!Appointments allows administrators to define a custom "booking disabled" message through the booking settings page. That value is stored in the disable_booking_message setting via a rich-text editor and later passed directly to the public booking_message view withou…
Summary Google::oauth at application/controllers/Google.php:278 stores its URL-supplied provider_id in the session, and oauth_callback saves the issued Google OAuth token against that row without checking the caller owns the provider. Any logged-in backend user (admin, provider,…
Summary The booking reschedule view at /index.php/booking/reschedule/{appointment_hash} (handled by Booking::index()) embeds the entire customer record as inline JavaScript (const vars = {... "customer_data": {...}, ...}) without authentication and without field whitelisting. An…
Summary Easy!Appointments correctly filters provider-scoped appointments in the appointments/search response, proving that provider isolation is an intended security boundary. However, the direct mutation endpoints appointments/store and appointments/update only check generic ap…
Summary Caldav::connect_to_server at application/controllers/Caldav.php:60 hands the request's caldav_url to a Guzzle REPORT call without scheme or host validation. A logged-in backend user (admin, provider, or secretary) reaches loopback, RFC1918, and link-local hosts on the de…
Summary An Excessive Data Exposure vulnerability in the customers search endpoint allows an authenticated user to obtain appointment hashes belonging to other users. Using these hashes, an attacker can modify or delete appointments of other providers, resulting in an Appointments…
Problem Multiple vulnerabilities were disclosed in 2024 affecting libolm (Olm): AES timing / side‑channel, Ed25519 signature malleability, and timing leaks in base64 decoding; several CVEs were assigned. Patches and mitigations were published; maintainers recommend upgrading to …
Summary The AgentCore CLI (@aws/agentcore) is a developer tool for managing agent infrastructure lifecycle on Amazon Bedrock AgentCore. An issue exists where, under certain circumstances, a crafted collaborationInstruction value stored in Bedrock Agent collaborator metadata can b…
Impact Certain bidder adapters accept user-supplied parameters that are interpolated into outbound request URLs. Without proper input validation, a malicious actor could craft bid request parameters that cause the server to send HTTP requests to unintended destinations, potential…
On August 5, 2026, the Cisco Product Security Incident Response Team (PSIRT) will publish advisories to disclose security vulnerability information along with fixed software releases for the following Cisco products: Catalyst SD-WAN Integrated Management Controller (IMC) IOS Soft…
Quarkus HTTP path-based authorization policies can be bypassed using encoded semicolons (%3B) to smuggle matrix parameters past the security layer, and using encoded slashes (%2F) or backslashes (%5C) to access protected static resources. This is a distinct issue from CVE-2026-39…
Summary A missing human-approval gate on the create_dynatrace_notebook tool allows a caller to create persistent tenant-visible documents containing arbitrary content (including embedded DQL that other users execute when opening the notebook) without operator consent. Details dy…
Summary Penelope versions prior to 0.19.3 extracted tar archives received from remote sessions without validating archive member paths. When using the affected Unix download path, a malicious or compromised remote session could return a crafted tar archive containing path traver…
Summary Req's multipart form encoder interpolates the per-part name, filename, and content_type directly into the part headers without escaping. An attacker who can influence any of those values can inject CRLF-separated header lines, smuggle additional form fields, or prepend a…
Summary Req's default response pipeline auto-decodes archive and compressed bodies based on the server-supplied content-type (or URL extension) and materialises the full decompressed contents in memory with no size cap. An attacker who controls (or can redirect a victim into) an…
Summary Description A PostScript-interpreter-driven Denial of Service (CWE-1325) vulnerability in veraPDF allows a remote attacker to exhaust validator memory or CPU by submitting a PDF whose Type 1 font /FontFile is a font program containing attacker-supplied PostScript. veraP…
Summary Description A PostScript-interpreter-driven Denial of Service (CWE-1325) vulnerability in veraPDF allows a remote attacker to exhaust validator memory or CPU by submitting a PDF whose Type 0 font /Encoding (or any /ToUnicode) is a CMap stream containing attacker-supplie…
Summary veraPDF-validation has an XML External Entity (XXE) vulnerability in two PDF parsing paths (validate and GFPDAcroForm.getdynamicRender()). A malicious/crafted PDF supplied to a veraPDF consumer can lead to the expansion of external entities while parsing rich-text annota…
Summary Description An XML External Entity Injection (CWE-611) vulnerability in veraPDF allows a remote attacker to read arbitrary files on the server file system and perform Server-Side Request Forgery by submitting a crafted PDF containing a malicious rich-text (/RC or /RV) en…
Summary Description An XML External Entity Injection (CWE-611) vulnerability in veraPDF allows a remote attacker to read arbitrary files on the server file system and perform Server-Side Request Forgery by submitting a crafted PDF containing a malicious XFA stream. This affects …