● Live advisory feed
Security Advisory Fusion for CSIRTs, SOCs & Defenders
Security advisories from 24 sources — CISA, CERT-EU, NCSC-UK, BSI, CERT-FR, NCSC-NL, JPCERT/CC, JVN, HKCERT, the Canadian Cyber Centre, NVD, GitHub, Microsoft, Cisco, Fortinet, Palo Alto Networks and more — normalized, translated to English and flagged against the CISA KEV catalog. One global feed for CSIRTs, SOCs and defenders.
Multiple vulnerabilities have been discovered in GitLab. Some of them allow an attacker to cause a breach of data confidentiality, an indirect remote code injection (XSS), and a security policy bypass.
Multiple vulnerabilities have been discovered in Microsoft Azure Linux. They allow an attacker to cause an unspecified security issue.
Multiple vulnerabilities have been discovered in Traefik. They allow an attacker to cause a security policy bypass.
Multiple vulnerabilities have been discovered in Juniper Networks products. Some of them allow an attacker to cause arbitrary code execution, a remote denial of service, and a breach of data confidentiality.
Multiple vulnerabilities have been discovered in Google Chrome. They allow an attacker to cause an unspecified security issue.
Multiple vulnerabilities have been discovered in Wireshark. They allow an attacker to cause a remote denial of service and a breach of data confidentiality.
Summary
Serena's built-in web dashboard exposes an unauthenticated Flask API on a fixed, predictable port (TCP 24282, hardcoded as 0x5EDA in constants.py). The server has no authentication, no CSRF protection, and no Host header validation. A DNS rebinding attack allows a malici…
Impact
In versions from 1.5.0 up to and including 3.0.0, any authenticated portal user could complete and tamper with another user's open task by submitting it on their behalf. The task submission endpoint accepted a task ID and a payload, but it never checked whether the task a…
Impact
In versions up to and including 3.0.0, two parts of the GraphQL API returned data without checking whether the data belonged to the logged-in user:
- Document content. A logged-in user could download the raw content of any document by its ID, regardless of who owned it. …
Summary
The unstable_redirect() helper exported from waku/router/server (packages/waku/src/router/define-router.tsx:156–161) accepts an arbitrary string and reflects it unchanged into the HTTP Location response header with no URL validation, scheme restriction, or path-only enfo…
Summary
Waku's RSC request dispatcher invokes server actions without validating the request's Origin (or Sec-Fetch-Site) header. A cross-origin web attacker can therefore cause a victim browser to issue an authenticated POST to a registered server action endpoint using a CORS-sa…
Unauthenticated Cross-Origin Plugin Upload Leads to RCE (Joro ≤ v1.1.0)
Severity: Critical
CVSS v3.1: 9.6 (AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H)
Affected versions: Joro ≤ v1.1.0, proxy mode (default), Linux/macOS
Reporter: cstover
Date: 2026-05-27
Summary
Joro's default proxy m…
Affected versions of oneringbuf exposed the obsolete IntoRef::into_ref method through the public IntoRef trait. For heap-backed ring buffers, this method returned a DroppableRef handle.
DroppableRef stored an owning raw pointer created from Box::into_raw. Its Clone implementatio…
Overview
A path traversal vulnerability is possible via the COAR Notify / LDN service in DSpace. _This vulnerability impacts DSpace versions 8.0 <= 8.3, 9.0 <= 9.2._ The attacker MUST already have DSpace administrator credentials in order to perform the attack.
When reading a f…
Overview
When ingesting an aggregated ORE resource by URI (using the OAI-ORE Harvester)), the ORE Ingestion Crosswalk does not validate the URI scheme. This may allow for local file inclusion via malicious paths like file:///etc/passwd. _This vulnerability impacts DSpace version…
Overview
The Curation Task feature allows an output path to be used by the reporter (-r parameter), typically used to stream results and status of curation task operations. It is not restricted to any particular base path, meaning that any path writable by the DSpace (often 'tom…
Overview
Remote Code Execution (RCE) is possible via Velocity Templates used by DSpace for COAR Notify/LDN messages. _This vulnerability impacts DSpace versions 8.0 <= 8.3, 9.0 <= 9.2._ The attacker MUST already have DSpace administrator credentials in order to perform the attac…
Summary
trapster.libs.dns.decode_labels() decodes DNS names from attacker-supplied UDP packets and recurses once per RFC 1035 compression pointer with no cycle detection and no depth bound. A single unauthenticated UDP datagram sent to the DNS honeypot drives the function past C…
Impact
The create and store endpoints of the Quick Creation Command feature did not enforce any authorization check. An authenticated Sharp user without create permission on a given entity could bypass the authorization layer and either retrieve the creation form or submit new re…
Summary
Nuclio controller builds a curl invocation string for each cron trigger and stores it as the args of a Kubernetes CronJob container (/bin/sh, -c, <command>). Two fields in the trigger specification flow into this string without adequate sanitization:
- event.headers key…
Summary
async-tar v0.6.0 mis-applies a buffered PAX size extension to an intermediary
extension header (a GNU longname L, a GNU longlink K, or a PAX x/g
header) instead of to the next *file* entry. POSIX requires a PAX extended-header
record set to describe the next file entry, …
Summary
zalando/skipper's OpenPolicyAgent integration silently bypasses request-body
inspection on HTTP/1.1 Transfer-Encoding: chunked and HTTP/2 requests that
omit the content-length pseudo-header. When the
opaAuthorizeRequestWithBody filter is configured, the
OpenPolicyAgentIn…
lxml_html_clean.Cleaner does not strip javascript: URLs from namespaced URL attributes (xlink:href)
Reporter: Guillem Lefait <guillem@datamq.com> · Date: 2026-05-10
Affected: lxml ≤ 6.1.0 and lxml_html_clean ≤ 0.4.4 (latest stable)
Confirmed against: lxml 6.1.0 + lxml_html_clean…
Serial number: AV26-678 Date: July 8, 2026 On July 8, 2026, Progress published security advisories to address vulnerabilities in the following product: MOVEit Transfer – version 2024.1.8 and prior MOVEit Transfer – version 2025.0.0 to 2025.0.7 MOVEit Transfer – version 2025.1.0 t…
Serial number: AV26-677 Date: July 8, 2026 On July 8, 2026, GitLab published a security advisory to address vulnerabilities in the following products: GitLab Community Edition (CE) – versions prior to 19.1.2, 19.0.4 and 18.11.7 GitLab Enterprise Edition (EE) – versions prior to 1…
Serial number: AV26-676 Date: July 8, 2026 On July 8, 2026, Drupal published security updates for multiple products. Included was a critical update for the following: Location Selector – versions prior to 1.3.0 The Cyber Centre encourages users and administrators to review the pr…
Serial number: AV26-675 Date: July 8, 2026 On July 8, 2026, Juniper Networks published security advisories to address vulnerabilities in the following products: Juniper cRPD – all versions Juniper CTPView – all versions Juniper Network Director – versions prior to 7.1R3 Junos OS …
Serial number: AV26-674 Date: July 8, 2026 On July 8, 2026, Palo Alto Networks published security advisories to address vulnerabilities in the following products: PAN-OS 12.1 – versions prior to 12.1.4-h8 PAN-OS 12.1 – versions prior to 12.1.7-h2 PAN-OS 12.1 – versions prior to 1…
Aaron Rainbolt discovered that the cautious-launcher utility in the mailcap package did not properly restrict the execution of certain file types. An attacker could use this issue to escape a sandboxed application and execute arbitrary code on the host operating system.
Serial number: AV26-673 Date: July 8, 2026 On July 7, 2026, Tanium published a security advisory to address a vulnerability in the following products: Tanium Server 2025H1 Release – versions prior to Update MR21 (v7.7.3.8298) Tanium Server 2025H2 Release – versions prior to Updat…
Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-hwmj-qg4v-cvg9. This link is maintained to preserve external references.
Original Description
n8n before 1.123.61, 2.x before 2.27.4, and 2.28.x before 2.28.1 contains a SQL injection vulnerab…
Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-2xgm-wc4g-5jvg. This link is maintained to preserve external references.
Original Description
n8n before 2.28.0 contains an improper authorization vulnerability allowing authenticated users t…
Serial number: AV26-672 Date: July 8, 2026 On July 8, 2026, n8n published security advisories to address vulnerabilities in the following product: n8n – versions prior to 1.123.64 n8n – versions prior to 2.30.1 n8n – versions prior to 2.29.8 The Cyber Centre encourages users and …
Serial number: AV26-671 Date: July 8, 2026 On July 2, 2026, Ubiquiti published a security advisory to address critical vulnerabilities in the following products: EF-Core – version 5.1.18 and prior EFG – version 5.1.15 and prior ENVR – version 5.1.15 and prior ENVR-Core – version …
It was discovered that ClamAV incorrectly handled certain PE files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. (CVE-2026-20213, CVE-2026-20214, CVE-2026-20217) It was discovered that ClamAV incorrectly handled certa…
It was discovered that Apache HTTP Server's mod_ldap module incorrectly handled memory when processing per-directory configurations. An attacker could use this issue to cause the server to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-2916…