CVE tracker
378 subscribers
5.29K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-66274 - Apache Qpid Proton-J: Unbounded type nesting can lead to pre-authentication stackoverflow

CVE ID :CVE-2026-66274
Published : Aug. 5, 2026, 7:16 a.m. | 44 minutes ago
Description :A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66275 - Apache Qpid Proton-J: Incoming session flow control window can be exceeded

CVE ID :CVE-2026-66275
Published : Aug. 5, 2026, 7:16 a.m. | 44 minutes ago
Description :An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66276 - Apache Qpid Proton-J: Unbounded disposition range handling can lead to denial of service

CVE ID :CVE-2026-66276
Published : Aug. 5, 2026, 7:16 a.m. | 44 minutes ago
Description :An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-66277 - Apache Qpid Proton-J: Unable to govern the maximum number of transfer frames per incoming delivery

CVE ID :CVE-2026-66277
Published : Aug. 5, 2026, 7:16 a.m. | 44 minutes ago
Description :It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-67552 - Apache Qpid Proton Dotnet: Unbounded type nesting can lead to pre-authentication stackoverflow

CVE ID :CVE-2026-67552
Published : Aug. 5, 2026, 7:16 a.m. | 44 minutes ago
Description :A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-Dotnet through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-67553 - Apache Qpid Proton Dotnet: Incoming session flow control window can be exceeded

CVE ID :CVE-2026-67553
Published : Aug. 5, 2026, 7:16 a.m. | 44 minutes ago
Description :An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-67554 - Apache Qpid Proton Dotnet: Unbounded disposition range handling can lead to denial of service

CVE ID :CVE-2026-67554
Published : Aug. 5, 2026, 7:16 a.m. | 44 minutes ago
Description :An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-67555 - Apache Qpid Proton Dotnet: Unable to govern the maximum number of transfer frames per incoming delivery

CVE ID :CVE-2026-67555
Published : Aug. 5, 2026, 7:16 a.m. | 44 minutes ago
Description :It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-67590 - Apache Qpid ProtonJ2: Unbounded type nesting can lead to pre-authentication stackoverflow

CVE ID :CVE-2026-67590
Published : Aug. 5, 2026, 7:16 a.m. | 44 minutes ago
Description :A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-67591 - Apache Qpid ProtonJ2: Incoming session flow control window can be exceeded

CVE ID :CVE-2026-67591
Published : Aug. 5, 2026, 7:16 a.m. | 44 minutes ago
Description :An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-67592 - Apache Qpid ProtonJ2: Unable to govern the maximum number of transfer frames per incoming delivery

CVE ID :CVE-2026-67592
Published : Aug. 5, 2026, 7:16 a.m. | 44 minutes ago
Description :It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-68073 - Apache Qpid Broker-J: Unbounded type nesting can lead to pre-authentication stack overflow

CVE ID :CVE-2026-68073
Published : Aug. 5, 2026, 7:16 a.m. | 44 minutes ago
Description :A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-68075 - Apache Qpid Broker-J: Incoming session flow control window can be exceeded

CVE ID :CVE-2026-68075
Published : Aug. 5, 2026, 7:16 a.m. | 44 minutes ago
Description :An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-68077 - Apache Qpid Broker-J: Unbounded disposition range handling can lead to denial of service

CVE ID :CVE-2026-68077
Published : Aug. 5, 2026, 7:16 a.m. | 44 minutes ago
Description :An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-68078 - Apache Qpid Broker-J: Unable to govern the maximum number of transfer frames per incoming delivery

CVE ID :CVE-2026-68078
Published : Aug. 5, 2026, 7:16 a.m. | 44 minutes ago
Description :It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-68080 - Apache Qpid Broker-J: Unbounded echo flow responses can lead to denial of service

CVE ID :CVE-2026-68080
Published : Aug. 5, 2026, 7:16 a.m. | 44 minutes ago
Description :It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-70374 - HashBrown CMS: OS Command Injection in Media Upload Thumbnail Generation

CVE ID :CVE-2026-70374
Published : Aug. 5, 2026, 7:16 a.m. | 44 minutes ago
Description :HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the media upload thumbnail generation routine. Media.generateThumbnail() in src/Server/Entity/Resource/Media.js builds a temporary file path as 'thumbnail' + Path.extname(filename) and passes it, unescaped, into a shell command executed via AppService.exec() ('convert ' + tempFile + ...). The MIME-type filter in getMIMEType() (src/Common/utilities.js) truncates the extracted extension at the first '?' character, while Path.extname() does not, allowing a filename such as 'x.jpg?$(command)' to pass the image-type check while still injecting a shell command substitution into the exec() call. An authenticated user holding the media resource scope can achieve arbitrary OS command execution in the context of the Node.js process via POST /api/{project}/{environment}/media/new.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-70375 - HashBrown CMS: OS Command Injection via Git Deployer Branch Field

CVE ID :CVE-2026-70375
Published : Aug. 5, 2026, 7:16 a.m. | 44 minutes ago
Description :HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the Git deployer component. GitDeployer.pullRepo() in src/Server/Entity/Deployer/GitDeployer.js executes AppService.exec(`git checkout ${this.branch || 'master'}`), interpolating the configured branch value directly into a shell command with no escaping. GitDeployer.validate() only rejects a single-quote character in the repo, branch, username, and password fields; shell metacharacters such as ';', '&&', '|', backticks, and '$()' are not filtered. A user able to configure a project's Git deployer settings can set a malicious branch value (e.g. 'master;#') that executes automatically on every subsequent deployer operation (media upload, content save, etc.), since pullRepo() is invoked unconditionally at the start of each such operation. This is related to CVE-2020-6948, which addressed single-quote escaping of the repo, username, and password fields in the same file's git clone invocation; the branch field used in the unquoted git checkout command was not covered by that fix and remains injectable.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-71201 - OpenStack Ironic Authorization Bypass via Portgroup Enumeration

CVE ID :CVE-2026-71201
Published : Aug. 5, 2026, 7:16 a.m. | 44 minutes ago
Description :In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assigned to Nodes owned or leased by another project.
Severity: 5.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-71233 - InvoiceNinja: Stored XSS via Invoice/Quote Terms Field

CVE ID :CVE-2026-71233
Published : Aug. 5, 2026, 11:16 a.m. | 45 minutes ago
Description :InvoiceNinja v5-stable renders an invoice or quote's "terms" field in the client portal using Laravel Blade's raw output directive {!! $entity->terms !!} (resources/views/portal/ninja2020/invoices/includes/terms.blade.php) with no HTML sanitization. StoreInvoiceRequest.php only strips newlines from the field and does not purify HTML. An authenticated user with invoice creation access can set the terms field via the REST API (PUT /api/v1/invoices/{id}) to an HTML/JavaScript payload that executes in the client's browser when they view the invoice, enabling session cookie theft and client account takeover. This is a distinct code path from the previously published invoice line-item description field XSS (GHSA-98wm-cxpw-847p / CVE-2026-33628).
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-71234 - Documize Community: Attachment Download Authorization Bypass via Non-Validated secure Token

CVE ID :CVE-2026-71234
Published : Aug. 5, 2026, 11:16 a.m. | 45 minutes ago
Description :Documize Community's attachment download route (domain/attachment/endpoint.go, Download function, registered via AddPublic with no auth middleware) accepts a `secure` query parameter and grants access whenever the parameter is simply non-empty (len(secureToken) > 0), without comparing it to any server-stored value. Any non-empty string, such as ?secure=x, bypasses authentication entirely and allows downloading any organization's attachments. Sibling handlers in the same file (togglePublish, delete) correctly enforce session-based authorization, confirming this is an inconsistency rather than intended design.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...