[UPDATE] [critical] Python: Vulnerability allows code execution
An attacker can exploit a vulnerability in Python to execute arbitrary program code.
● Live advisory feed
Security advisories from 24 sources — CISA, CERT-EU, NCSC-UK, BSI, CERT-FR, NCSC-NL, JPCERT/CC, JVN, HKCERT, the Canadian Cyber Centre, NVD, GitHub, Microsoft, Cisco, Fortinet, Palo Alto Networks and more — normalized, translated to English and flagged against the CISA KEV catalog. One global feed for CSIRTs, SOCs and defenders.
An attacker can exploit a vulnerability in Python to execute arbitrary program code.
An attacker can exploit multiple vulnerabilities in Juniper JUNOS, JUNOS Evolved, Juniper EX Series, Juniper MX Series, Juniper QFX Series, and Juniper SRX Series to cause a Denial of Service condition, disclose information, execute code, and trigger undefined behavior.
BeyondTrust has fixed vulnerabilities in the products Remote Support and Privileged Remote Access. The vulnerabilities affect multiple aspects of the products Remote Support and Privileged Remote Access. There is a pre-authentication vulnerability that allows a network-based atta…
GitLab has fixed multiple vulnerabilities in GitLab Enterprise Edition (EE) and Community Edition (CE) in versions ranging from 9.1 to before 18.11.7, 19.0 to before 19.0.4, and 19.1 to before 19.1.2. The vulnerabilities include: - Creating repositories with discrepancies between…
A local attacker can exploit a vulnerability in Microsoft Malware Protection Engine and Microsoft Defender to elevate their privileges.
An attacker can exploit multiple vulnerabilities in Flowise to execute arbitrary code and to disclose information.
Summary Tesla.Multipart.part_headers_for_disposition/1 interpolates Content-Disposition parameter values (field name, filename, and other opts) verbatim into the part header line without encoding or escaping any special characters. An attacker who controls a filename, field name…
Summary In the Mint adapter for the Tesla HTTP client library, Tesla.Adapter.Mint.open_conn/2 passes the URL scheme of every outgoing request through String.to_atom/1 with no allow-list validation. Because BEAM atoms are permanent (never garbage-collected) and the atom table is …
Summary Tesla.Middleware.FollowRedirects is meant to strip the Authorization header when following a cross-origin redirect, but performs the check with a case-sensitive comparison against the lowercase string "authorization". Because Tesla preserves header keys exactly as suppli…
Summary Any Tesla client pipeline that includes Tesla.Middleware.DecompressResponse or Tesla.Middleware.Compression eagerly decompresses HTTP response bodies with no size limit. A server under attacker control (or reached via a redirect) can return a tiny gzip-encoded payload th…
Summary Tesla.Multipart.add_content_type_param/2 appends caller-supplied strings to the multipart Content-Type header with no validation. A param value containing \r\n splits the header line, allowing an attacker who controls any content-type parameter (charset, boundary paramet…
Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE.
Multiple vulnerabilities have been discovered in Progress MOVEit Transfer. Some of them allow an attacker to cause privilege escalation, data confidentiality breaches, and remote indirect code injection (XSS).
A vulnerability has been discovered in NetApp ONTAP 9. It allows an attacker to cause remote denial of service and data integrity breaches.
Multiple vulnerabilities have been discovered in Microsoft Azure Linux. They allow an attacker to cause an unspecified security issue by the vendor.
Multiple vulnerabilities have been discovered in the SUSE Linux kernel. Some of them allow an attacker to cause data confidentiality breaches, data integrity breaches, and security policy bypass.
Kate Deplaix reported that .install file directives were insufficiently restricted in OPAM, a package manager for OCaml. Installing files through .install files did not check symlinks resolution on the target path, which could result in directory traversal out of the package area…
iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
Multiple vulnerabilities have been discovered in IBM products. Some of them allow an attacker to cause remote denial of service, data confidentiality breaches, and server-side request forgery (SSRF).
A vulnerability has been discovered in CPython. It allows an attacker to cause remote denial of service.
Multiple vulnerabilities have been discovered in the Ubuntu Linux kernel. Some of them allow an attacker to cause privilege escalation, data confidentiality breaches, and security policy bypass.
Multiple vulnerabilities have been discovered in Siemens products. Some of them allow an attacker to cause arbitrary code execution, privilege escalation, and remote denial of service.
Multiple vulnerabilities have been discovered in the Red Hat Linux kernel. Some of them allow an attacker to cause remote arbitrary code execution, privilege escalation, and remote denial of service.
Multiple vulnerabilities have been discovered in the Debian LTS Linux kernel. Some of them allow an attacker to cause privilege escalation, data confidentiality breaches, and denial of service.
Multiple vulnerabilities have been discovered in Suricata. They allow an attacker to cause an unspecified security issue by the vendor.
Summary Mistune is vulnerable to a CPU exhaustion DoS due to superlinear (approximately O(n²)) behavior in parse_link_text. A relatively small input consisting of repeated [ characters causes significant parsing slowdown. Affected component mistune/inline_parser.py → **parse_lin…
Found through variant analysis based on CVE-2026-41643 Summary GoBGP accepts a zero-length AS_PATH during UPDATE decoding and later panics while validating that attribute for a confederation eBGP peer. The vulnerable path is in the BGP UPDATE validator: a malformed UPDATE that s…
Summary GoBGP contains a BGP OPEN capability parsing issue where several concrete capability decoders may parse data from the full remaining capability buffer instead of the slice bounded by the declared capability length, CapLen. A malformed BGP OPEN message can cause bytes from…
psd-tools: arbitrary file write/read via smart-object path traversal Summary In psd-tools (all releases exposing the SmartObject API through v1.17.0), SmartObject.save() writes an embedded smart object to a path taken verbatim from the PSD file. Because that name is attacker-co…
Impact _What kind of vulnerability is it? Who is impacted?_ A verifier configured with WithTransparencyLog(N>1) or WithSignedCertificateTimestamps(N>1) expected defense-in-depth against the compromise of a single log instance. However, threshold counting counted verified witness…
rattler_cache and py-rattler were vulnerable to package-cache path traversal when handling package metadata from conda channels. During cache materialization, the ratter_cache code used the package record build string as part of a cache key that was joined into a filesystem path…
Summary The restrictions on redirect URLs in openrun can be bypassed by attackers, leading to open redirect attacks. Details In the current project, the referrer header value is used for subsequent redirects, so there is currently a validation for this redirect value. The curre…
Summary Mint's HTTP/2 client accepts PUSH_PROMISE frames from any server it connects to and inserts every promised stream into a per-connection map without consulting max_concurrent_streams. A malicious or compromised HTTP/2 server can flood the client with PUSH_PROMISE frames a…
Summary Mint's HTTP/2 client accumulates CONTINUATION header-block fragments into a per-connection buffer with no cap on size or frame count. A malicious or compromised HTTP/2 server can drive the client's memory to arbitrary size by streaming an endless chain of CONTINUATION fr…
Summary Mint's HTTP/1 client accepts Content-Length header values with a leading + sign (e.g. +0, +123), which RFC 7230 forbids (Content-Length = 1*DIGIT). On a connection shared with a strict fronting proxy or load balancer, this parser disagreement is a response-smuggling prim…
Summary Mint's HTTP/1 request encoder splices the caller-supplied method and target directly into the request line without character validation. An application that forwards attacker-controlled input as the HTTP method or the target to Mint.HTTP.request/5 is exposed to request-l…
Impact An attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires merging a file with threads/articles into a writer. Patches This has been fixed in pypdf==6.13.1. Workarounds If users cannot upgrade yet, consider applying the chan…
Impact The GET /api/v2/shop/payment-requests/{hash} and PUT /api/v2/shop/payment-requests/{hash} endpoints look up the payment request solely by the hash from the URL. No ownership check is performed against the authenticated customer or the underlying order. An attacker who obt…
Impact An authorization bypass vulnerability exists in the shop account API. The PATCH /api/v2/shop/account/orders/{tokenValue}/payments/{paymentId} endpoint, used by an authenticated shop customer to change the payment method of an order that has been placed but not yet paid (st…
Impact A user opens the cart page in the browser. In the background, the order gets completed, e.g. an admin changes the status, or the user finalizes payment in another tab. The browser still displays the old cart: the LiveComponent is unaware the underlying order state has chan…
Summary An unsafe execution vulnerability exists in the Bazar form field calculator (CalcField.php) of YesWiki. The application attempts to sanitize user-defined mathematical formulas using a complex recursive regular expression before passing them to the PHP eval() function. Th…
Details Sink tools/bazar/services/CSVManager.php line 372-399: public function importEntry(array $importedEntries, string $formId): ?array { if (!$this->importdone) { // ... foreach ($importedEntries as $entry) { $entry = unserialize(base64_decode($entry)); // <-- SINK $entry …
Summary YesWiki through the latest development branch contains a SQL injection vulnerability in ReactionManager::deleteUserReaction() that allows any authenticated user to inject arbitrary SQL via the {idreaction} and {id} URL path parameters. The parameters are concatenated dir…
Summary YesWiki's Bazar widget handler reflects the id GET parameter into HTML attributes using strip_tags() only. Because strip_tags() does not escape double quotes, an attacker can break out of the attribute value, inject an event handler such as onmouseover, and execute arbitr…
Summary YesWiki's archived-revision view reflects the time GET parameter into a hidden HTML input in handlers/page/show.php without escaping. Because MySQL coerces malformed DATETIME strings, an attacker can append HTML or JavaScript to a valid archived revision timestamp, still …
Bazar form-field templates still apply |raw('html') to field.label / field.hint in attribute and label-body contexts — stored XSS in form renders (sibling class of commit e6b66aa) CWE: CWE-79 (Improper Neutralization of Input During Web Page Generation, "Cross-site Scripting") v…
Summary ApiController::deletePage() interpolates a page tag retrieved from the database into a DELETE FROM …_links WHERE to_tag = '$tag' query without escaping. The page tag is attacker-controlled — the POST /api/pages/{tag} API accepts arbitrary URL-encoded values, including sin…
Summary YesWiki’s public Bazar entry-listing APIs are vulnerable to unauthenticated SQL injection in numeric query / queries filters. For Bazar fields whose value structure is numeric, YesWiki escapes the attacker-controlled filter value but inserts it into SQL without quotes or…
Summary The POST /api/forms/{formId}/actor/inbox route - exposed publicly with acl:"public" - accepts an HTTP Signature header whose keyId parameter is a URL. HttpSignatureService::verifySignature() parses the header and immediately makes a server-side HTTP GET to that URL, befor…
Summary HttpSignatureService::verifySignature() checks the result of PHP's openssl_verify() with a loose boolean negation - if (!openssl_verify(...)) { throw ... }. PHP's openssl_verify has four possible return values: | return | meaning | !return | | ------ | ------------------…