● Live advisory feed
Security Advisory Fusion for CSIRTs, SOCs & Defenders
Security advisories from 24 sources — CISA, CERT-EU, NCSC-UK, BSI, CERT-FR, NCSC-NL, JPCERT/CC, JVN, HKCERT, the Canadian Cyber Centre, NVD, GitHub, Microsoft, Cisco, Fortinet, Palo Alto Networks and more — normalized, translated to English and flagged against the CISA KEV catalog. One global feed for CSIRTs, SOCs and defenders.
Serial number: AV26-670 Date: July 8, 2026 On July 7, 2026, Langflow updated a security advisory to address vulnerabilities in the following product: Langflow – versions prior to 1.9.1 On July 7, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-55255 t…
A remote, anonymous attacker can exploit multiple vulnerabilities in IBM Operational Decision Manager to bypass security restrictions, cause a denial of service, and execute code.
A remote attacker can exploit multiple vulnerabilities in Joomla to perform a cross-site scripting attack and bypass security mechanisms.
A remote, anonymous attacker can exploit multiple vulnerabilities in ESRI ArcGIS to bypass security measures or gain user rights.
An attacker can exploit multiple vulnerabilities in ILIAS to bypass security measures, disclose sensitive information, or conduct cross-site scripting attacks.
A remote, anonymous attacker can exploit a vulnerability in dpkg to disclose information.
A remote, anonymous attacker can exploit a vulnerability in Red Hat JBoss Enterprise Application Platform to conduct a cross-site scripting attack.
A remote, anonymous attacker can exploit a vulnerability in OpenSC to execute arbitrary program code.
An attacker can exploit multiple vulnerabilities in Fleet to bypass security mechanisms, disclose confidential information, cause a denial-of-service condition, or manipulate security configurations.
A remote, anonymous attacker can exploit a vulnerability in libxml2 to conduct a denial of service attack.
An attacker can exploit multiple vulnerabilities in Gitea to bypass security measures, manipulate data, disclose confidential information, trigger a Denial-of-Service condition, or carry out other unspecified attacks.
A remote, anonymous attacker can exploit multiple vulnerabilities in MIT Kerberos to carry out a Denial of Service attack.
A remote, anonymous attacker can exploit a vulnerability in Apache log4j to execute arbitrary program code.
A remote, anonymous attacker can exploit multiple vulnerabilities in Red Hat Enterprise Linux to carry out a Denial of Service attack.
An attacker can exploit multiple vulnerabilities in Apache Airflow to execute arbitrary program code, bypass security measures, and disclose information.
An attacker can exploit multiple vulnerabilities in BeyondTrust Privileged Remote Access and BeyondTrust Remote Support to conduct a denial of service attack, gain elevated privileges, bypass security measures, and disclose confidential information.
An attacker can exploit multiple vulnerabilities in Langflow to execute arbitrary program code, bypass security measures, manipulate data, disclose confidential information, or cause a Denial-of-Service condition.
An attacker can exploit multiple vulnerabilities in Tenable Security Nessus to carry out an SQL injection attack.
A remote, authenticated or anonymous attacker can exploit multiple vulnerabilities in QNAP NAS to gain elevated privileges, bypass security mechanisms, cause a Denial of Service condition, execute arbitrary commands, disclose information, or achieve unspecified impacts.
The installer for Pupsman provided by Fuji Electric Co.,Ltd. contains multiple vulnerabilities.
Multiple vulnerabilities have been discovered in Foxit products. Some of them allow an attacker to cause remote arbitrary code execution, privilege escalation, and data confidentiality breaches.
On July 8, 2026, we released versions 19.1.2, 19.0.4, 18.11.7 for GitLab Community Edition (CE) and Enterprise Edition (EE). These versions contain important bug and security fixes, and we strongly recommend that all self-managed GitLab installations be upgraded to one of these v…
On July 8, 2026, we released versions 19.1.2, 19.0.4, 18.11.7 for GitLab Community Edition (CE) and Enterprise Edition (EE). These versions contain important bug and security fixes, and we strongly recommend that all self-managed GitLab installations be upgraded to one of these v…
Multiple vulnerabilities have been discovered in Joomla!. Some of them allow an attacker to cause data confidentiality breaches, data integrity breaches, and remote indirect code injection (XSS).
Multiple vulnerabilities have been discovered in HPE Aruba Networking products. They allow an attacker to cause remote denial of service, data confidentiality breaches, and security policy bypass.
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. https://security-tracker.debian.org/tracker/DSA-6384-1
Guillaume Winter discovered that pgextwlist, an extension for PostgreSQL implementing a whitelist mechanism for PostgreSQL extensions, was susceptible to SQL injection via crafted schema and user names. https://security-tracker.debian.org/tracker/DSA-6385-1
Impact
Weblate's VCS_RESTRICT_PRIVATE did not properly account for some transitional IPv6 ranges, multicast addresses, or some semi-private IPv4 ranges, which allowed some addresses to bypass private range restrictions.
Patches
- https://github.com/WeblateOrg/weblate/pull/1976…
Summary
From v1.13.2 through v1.18.0, oasdiff did not enforce --allow-external-refs=false (library: openapi3.Loader.IsExternalRefsAllowed = false) when loading a spec from a git revision (the rev:path form, e.g. main:openapi.yaml). External $refs were resolved on that load path …
Summary
pkg/scalers/postgresql_scaler.go builds libpq-style connection strings by concatenating key=value pairs separated by spaces. Each tenant-controllable field (host, port, userName, dbName, sslmode) is passed through escapePostgreConnectionParameter:
func escapePostgreConne…
Summary
Flask-Security-Too 5.8.0 and 5.8.1 mark a session as reauthentication-fresh after processing a WebAuthn assertion whose proven credential belongs to a different user than the currently authenticated session user. The check that GHSA-97r5-pg8x-p63p added on the OAuth reau…
Click here to jump to the Simplified Chinese version (点击跳转到简体中文版本)
Goploy System Arbitrary File Read Vulnerability
Basic Information
- Vulnerability Name: Goploy Endpoints Arbitrary File Read via Path Traversal
- Vulnerability Type: Path Traversal (CWE-22) / Arbitrary File Read
…
Summary
Project.AddFile, Project.EditFile, Project.RemoveFile, and Project.Edit in cmd/server/api/project/handler.go accept a project or project-file row id from the JSON body and act on it without checking that the project belongs to the caller's namespace. The corresponding mo…
Summary
In add-on mode, the ha-mcp settings UI routes are mounted both under the MCP secret path and at the bare root of the published port (:9583), so Home Assistant ingress can serve the "Open Web UI" button. The root-mounted routes perform no authentication — no secret, no Or…
Resolved: https://github.com/plabayo/rama/commit/89ddff578fd78bbebec99482d7030f28c07757a3
Summary
plabayo/rama contains a stored/reflected cross-site scripting issue in the ServeDir HTML directory listing feature.
When ServeDir is configured with DirectoryServeMode::HtmlFileLi…
Summary
aiosmtplib's SMTP.mail(), SMTP.rcpt(), SMTP.vrfy() and SMTP.expn() send the caller-supplied email address to the server without rejecting embedded CR/LF (\r\n) bytes. An address that contains a CR/LF is written verbatim onto the SMTP control connection, so the bytes afte…
Summary
Authenticated Kite users with any role can request /api/v1/overview for a cluster that their roles do not permit by selecting that cluster with x-cluster-name. The overview route is registered before middleware.RBACMiddleware() and GetOverview only checks len(user.Roles)…
Impact
Webauthn\SimpleFakeCredentialGenerator is the library-provided default implementation of the FakeCredentialGenerator interface. It returns a stable list of decoy PublicKeyCredentialDescriptor objects for a given username so that an assertion request for an unknown user lo…
Summary
RaTeX’s recursive-descent parser recurses one (or more) native stack frame per nesting level at {, \left, \sqrt{, ^{, etc, with no maximum depth limit. A short, ~10 KB input of nested groups overflows the 8 MB main-thread stack and aborts the process. With panic = "abort…
Summary
The public parser entrypoint ratex_parser::parse(&str) panics on the 9-byte input \verbéxé (i.e. \verb followed by the non-ASCII delimiter é). When handling a \verb command, the parser slices the verbatim argument with byte indices (arg[1..arg.len() - 1]); if the delimit…
Bulletin ID: 2026-053-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/07/2026 09:45 AM PDT Description: AWS Research and Engineering Studio (RES) is an open-source solution that enables researchers and engineers to create and manage secure virtual…
Am I affected?
Users are affected if all of these hold:
- They install and register the @better-auth/scim plugin (plugins: [scim()]).
- They create SCIM providers without an organizationId, that is, non-organization ("personal") providers. Organization-scoped providers are not …
Am I affected?
Users are affected if all of the following are true:
- They configure secondaryStorage on betterAuth(...) (Redis, KV, or any external session cache).
- session.storeSessionInDatabase is left unset or set to false (the default).
- Their application's deployment us…
Am I affected?
Users are affected if all of the following are true:
- Their project depends on @better-auth/oauth-provider at a version >= 1.6.0, < 1.6.11, or uses the embedded plugin in better-auth >= 1.4.8-beta.7, < 1.6.0, or enables the legacy oidc-provider or mcp plugins fr…
Am I affected?
Users are affected if all of the following are true:
- Their application uses @better-auth/sso at a version >= 0.1.0, < 1.6.11 on the stable line, or any 1.7.0-beta.x on the pre-release line.
- The sso() plugin is added to their application's betterAuth({ plugins…
Am I affected?
Users are affected if all of the following are true:
- Their project depends on @better-auth/oauth-provider at a version >= 1.6.0, < 1.6.11, or uses the embedded plugin in better-auth >= 1.4.8-beta.7, < 1.6.0.
- At least one OAuth client served by their applicati…
Am I affected?
Users are affected if all of the following are true:
- Their application uses better-auth at a version below the patched release.
- Their application enables oidcProvider() from better-auth/plugins/oidc-provider or mcp() from better-auth/plugins/mcp (the mcp plug…
Am I affected?
Check each condition. Users are affected when all of the first three hold.
- Their application enables the oidc-provider plugin or the mcp plugin from better-auth/plugins. The mcp plugin wraps the same provider and carries the same defect. Both are on the migrati…
Am I affected?
Users are affected if all of the following are true:
- Their application uses better-auth at a version < 1.6.11 on the stable line, or any current next pre-release.
- emailAndPassword.enabled: true is set in their application's betterAuth({ ... }) configuration.
…