CVE tracker
363 subscribers
4.93K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-17107 - Cluster-proxy: cluster-proxy: impersonation header injection in service-proxy grants cluster-admin on every managed cluster

CVE ID :CVE-2026-17107
Published : July 24, 2026, 7:16 p.m. | 1 hour, 10 minutes ago
Description :A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first removing caller-supplied values, and the spoke ServiceAccount holds unrestricted impersonation permissions. An authenticated hub principal can inject an Impersonate-Group header to escalate to cluster-admin on every managed cluster.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48021 - epa4all Security Incident: Implement keystore based on Telematik TSL, implement hostname check and certificate check for lib-vau

CVE ID :CVE-2026-48021
Published : July 24, 2026, 7:16 p.m. | 1 hour, 10 minutes ago
Description :In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU handshake with attacker-controlled keys and obtain the session encryption keys. All inner HTTP traffic (patient consent decisions, medication data, document operations, authorization tokens, and entitlement queries) becomes readable and modifiable. The attacker can also inject arbitrary requests through the hijacked channel. This issue has been patched in version 2026-05-20.
Severity: 9.1 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48032 - Hulumi: IAM-role policy checks bypassed when the role trusts multiple OIDC providers

CVE ID :CVE-2026-48032
Published : July 24, 2026, 7:16 p.m. | 1 hour, 10 minutes ago
Description :Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, IAM-role policy checks can be bypassed when the role trusts multiple OIDC providers. This issue has been patched in version 1.4.0.
Severity: 8.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48033 - Hulumi: Policy packs bypassed by a forged Pulumi-URN logical name

CVE ID :CVE-2026-48033
Published : July 24, 2026, 7:16 p.m. | 1 hour, 10 minutes ago
Description :Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, policy packs can be bypassed by a forged Pulumi-URN logical name. This issue has been patched in version 1.4.0.
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48034 - HULUMI-H5 bypass via decoy sibling resources targeting a different bucket

CVE ID :CVE-2026-48034
Published : July 24, 2026, 7:16 p.m. | 1 hour, 10 minutes ago
Description :Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, there is a bypass via decoy sibling resources targeting a different bucket. This issue has been patched in version 1.4.0.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48035 - Hulumi: AccountFoundation audit-delivery S3 bucket could be silently weakened

CVE ID :CVE-2026-48035
Published : July 24, 2026, 7:16 p.m. | 1 hour, 10 minutes ago
Description :Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, consumers using AccountFoundation could ship an AWS account whose CloudTrail / Config audit logs were deletable by any S3-delete-capable principal — while believing the startup-hardened tier guaranteed tamper-resistance. Sandbox-tier deployments had no audit immutability at all (defects 1 and 3 compounded). This issue has been patched in version 1.4.0.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48036 - Hulumi: Drift classifier fails open on adapter errors and over-promotes Mixed verdicts

CVE ID :CVE-2026-48036
Published : July 24, 2026, 7:16 p.m. | 1 hour, 10 minutes ago
Description :Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, consumers running drift detection in CI / cron could see transient adapter failures silently cached as "all clear" — masking real attacks for up to six hours — or see ordinary provider-version churn falsely promoted to incident severity. Either way, the verdict source was unreliable for downstream incident workflows that gate on it. This issue has been patched in version 1.4.0.
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48037 - Hulumi: AccountFoundation reuse paths silently downgrade GuardDuty / Security Hub posture

CVE ID :CVE-2026-48037
Published : July 24, 2026, 7:16 p.m. | 1 hour, 10 minutes ago
Description :Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, AccountFoundation reuse paths silently downgrade GuardDuty / Security Hub posture. This issue has been patched in version 1.4.0.
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-54342 - TLS Certificate Verification Disabled on CXF Transport Clients in epa4all

CVE ID :CVE-2026-54342
Published : July 24, 2026, 7:16 p.m. | 1 hour, 10 minutes ago
Description :In epa4all, prior to version 2026-05-20, an attacker on the network path between epa4all and any backend (ePA Aktensystem, Konnektor, IDP, TSS) can present a self-signed TLS certificate and intercept the connection. For non-VAU connections (Konnektor, IDP), this allows direct read and modification of the inner traffic, including smartcard operations and OIDC authentication exchanges. For the ePA backend, the disabled TLS verification is the transport-level enabler for the VAU MITM described in GHSA-vvh7-x6c7-46gh. This issue has been patched in version 2026-05-20.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-62835 - Azure Portal Information Disclosure Vulnerability

CVE ID :CVE-2026-62835
Published : July 24, 2026, 7:21 p.m. | 1 hour, 5 minutes ago
Description :None
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66036 - FFmpeg Heap Out-of-Bounds Write in vf_hqdn3d Filter

CVE ID :CVE-2026-66036
Published : July 24, 2026, 7:34 p.m. | 52 minutes ago
Description :FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when filtergraph reinitialization is disabled via the -reinit_filter 0 option. Attackers can provide a malicious video input where vf_hqdn3d.config_input() allocates undersized per-plane line-history buffers based on the initial frame width, and subsequent larger frames cause denoise_spatial() to write beyond the allocation boundary, resulting in heap memory corruption.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66037 - FFmpeg IAMF Demuxer Uncontrolled Resource Consumption via mix_presentation_obu()

CVE ID :CVE-2026-66037
Published : July 24, 2026, 7:36 p.m. | 50 minutes ago
Description :FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte memory allocation from a 17-byte input file by supplying a crafted count_label field. The mix_presentation_obu() function in libavformat/iamf_parse.c calls av_calloc(count_label, sizeof(*language_label)) with an attacker-controlled value before validating available OBU data, enabling an allocation amplification of approximately 126 million bytes per input byte that exhausts process memory or triggers an OOM-kill during format probing.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66038 - FFmpeg LCL/ZLIB Video Decoder Information Disclosure via lcldec.c

CVE ID :CVE-2026-66038
Published : July 24, 2026, 7:39 p.m. | 47 minutes ago
Description :FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a valid zlib stream that inflates to fewer bytes than the expected frame size. The zlib_decomp() function in lcldec.c treats short decompression as non-fatal and continues to the RGB24 conversion path, which copies a full frame's worth of rows from the allocation buffer using original frame dimensions, causing uninitialized heap contents including pointer-derived allocator bytes to be copied into the attacker-observable AVFrame output and potentially defeating ASLR in long-lived media processing services.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66039 - FFmpeg MACE6 Audio Decoder Heap Out-of-Bounds Write via CAF File

CVE ID :CVE-2026-66039
Published : July 24, 2026, 7:42 p.m. | 44 minutes ago
Description :FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attackers can craft a CAF file with oversized bytes_per_packet and frames_per_packet values in the desc chunk to trigger an integer overflow in mace_decode_frame() during output sample count computation, resulting in an undersized buffer allocation and heap out-of-bounds write that could enable code execution.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66040 - FFmpeg Heap Out-of-Bounds Write via PNG/APNG eXIf Encoder

CVE ID :CVE-2026-66040
Published : July 24, 2026, 7:46 p.m. | 40 minutes ago
Description :FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Attackers can craft an eXIf chunk where multiple IFD entries reference the same large value payload, causing canonical serialization to expand the output far beyond the undersized allocation estimated by add_exif_profile_size(), resulting in png_write_chunk() writing tens of thousands of bytes past the buffer boundary, leading to deterministic heap corruption, process crash, and potentially arbitrary code execution.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66041 - FFmpeg 7.0 - 8.1.2 Heap Out-of-Bounds Write via vf_quirc Filter

CVE ID :CVE-2026-66041
Published : July 24, 2026, 7:54 p.m. | 33 minutes ago
Description :FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc filter that allows an attacker to corrupt heap memory by supplying a crafted PGS/SUP subtitle file with mismatched frame dimensions. Attackers can provide a subtitle file whose second presentation has larger dimensions than its first, causing av_image_copy_plane() to copy data exceeding the initial allocation size into the undersized libquirc grayscale image buffer, resulting in heap corruption and process crash with potential for code execution.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-71408 - NLTK < 3.9.2 Eval Injection via collocations.py Command-Line Arguments

CVE ID :CVE-2025-71408
Published : July 24, 2026, 10:16 p.m. | 2 hours, 11 minutes ago
Description :NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls command-line arguments to execute arbitrary Python code. When collocations.py is invoked directly, the __main__ block passes command-line arguments directly to eval() as suffixes of BigramAssocMeasures without allowlist validation or sanitization, enabling an attacker to supply a Python expression that escapes the intended attribute lookup and executes arbitrary code including OS commands via the os module.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-55985 - Tycon Systems TPDIN-Monitor-WEB2 Cleartext Storage of Sensitive Information

CVE ID :CVE-2026-55985
Published : July 24, 2026, 10:16 p.m. | 2 hours, 11 minutes ago
Description :The web management interface in  Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext on a certain configuration page accessible to authenticated users. Any party with access to the administrative dashboard can immediately read these credentials, which may be used to compromise other systems on the local network.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-61884 - Tycon Systems TPDIN-Monitor-WEB2 Authentication Bypass Using an Alternate Path or Channel

CVE ID :CVE-2026-61884
Published : July 24, 2026, 10:16 p.m. | 2 hours, 11 minutes ago
Description :The web management interface of Tycon Systems TPDIN-Monitor-WEB2  does not perform server-side validation of credentials during the login process. By submitting empty values for both credential fields, an unauthenticated remote attacker can bypass the authentication check and establish a valid administrative session. This grants full access to device controls including power relay management, device reboot, remote access service configuration, and network settings, which could allow an attacker to disrupt connected infrastructure or cause physical damage to equipment.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16280 - GPU DDK - Integer overflow in _PMRLogicalOffsetToPhysicalOffset

CVE ID :CVE-2026-16280
Published : July 24, 2026, 11:16 p.m. | 1 hour, 11 minutes ago
Description :An integer overflow when calculating physical offsets for sparse PMRs may result in 32-bit truncation of address computations for PMRs larger than 4 GB. This can lead to incorrect GPU MMU mappings and may allow a non-privileged user to trigger access to unintended physical memory, resulting in memory corruption or information disclosure.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-60134 - Weintek cMT3092X Reliance on Cookies without Validation and Integrity Checking in a Security Decision

CVE ID :CVE-2026-60134
Published : July 24, 2026, 11:16 p.m. | 1 hour, 11 minutes ago
Description :Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...