CVE tracker
384 subscribers
5.37K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-75330 - Super-diamond-server SQL Injection

CVE ID :CVE-2026-75330
Published : Aug. 26, 2026, 11:17 p.m. | 22 minutes ago
Description :The front-end interface /superdiamond/preview/{projectCode}/{module}/{type} of super-diamond-server <= 1.3.3 is vulnerable to SQL injection. The module parameter is directly concatenated into the SQL IN clause through StringUtils.split() and string concatenation without being parameterized and bound.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-75332 - Zyplayer-Doc Server-Side Request Forgery

CVE ID :CVE-2026-75332
Published : Aug. 26, 2026, 11:17 p.m. | 22 minutes ago
Description :Zyplayer-Doc <=1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via WikiPageWebService.download().
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-75336 - Funiture SQL Injection

CVE ID :CVE-2026-75336
Published : Aug. 26, 2026, 11:17 p.m. | 22 minutes ago
Description :Funiture 1.0.0 is vulnerable to SQL Injection in the backend tool interfaces /sys/tool/select.json and /sys/tool/update.json.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-75338 - Disconf Incorrect Access Control Vulnerability

CVE ID :CVE-2026-75338
Published : Aug. 26, 2026, 11:17 p.m. | 22 minutes ago
Description :disconf (Distributed Configuration Management Platform) 2.6.36 is vulnerable to Incorrect Access Control. The config-fetching APIs /api/config/item, /api/config/file, /api/config/list and /api/config/simple/list are exposed without authentication. The LoginInterceptor explicitly whitelists these four paths, so any anonymous attacker can read every configuration item and configuration file managed by the config center.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-75340 - JetLinks Community Server-Side Request Forgery

CVE ID :CVE-2026-75340
Published : Aug. 26, 2026, 11:17 p.m. | 22 minutes ago
Description :The device metadata import interface /device/instance/{productId}/property-metadata/import of jetlinks community 2.11 is vulnerable to Server-side request forgery (SSRF).
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-80158 - Ansible-collection-community-general: community.general: ipa_getkeytab does not set no_log on the bind_pw parameter, disclosing the ipa bind password in logs and process listings

CVE ID :CVE-2026-80158
Published : Aug. 26, 2026, 11:17 p.m. | 22 minutes ago
Description :A flaw was found in the ipa_getkeytab module of the community.general Ansible collection. The module's bind_pw parameter, used to supply the LDAP simple-bind password when retrieving a Kerberos keytab, is not declared with no_log, unlike the sibling password parameter in the same module. As a consequence, the supplied IPA/LDAP bind password is recorded in cleartext in the managed host's system journal/syslog (the module's "Invoked with" record), is included in the module's return values and verbose (-v) output, and is displayed in Automation Controller / AWX job output. The password is additionally passed on the command line to the ipa-getkeytab helper (as --bindpw ), exposing it in the process list to local users while the command runs. An attacker able to read these logs, job output, or the process table can obtain the directory bind credential, potentially compromising the accounts and objects that credential can access.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81203 - SourceCodester Simple Online Food Ordering System ajax.php login2 sql injection

CVE ID :CVE-2026-81203
Published : Aug. 26, 2026, 11:17 p.m. | 22 minutes ago
Description :A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown function of the file /admin/ajax.php?action=login2. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-47845 - Reactor Netty HTTP Server may incorrectly evaluate proxy addresses

CVE ID :CVE-2026-47845
Published : Aug. 27, 2026, 1:17 a.m. | 2 hours, 22 minutes ago
Description :In specific scenarios, Reactor Netty HTTP Server may incorrectly evaluate the remote IP address when HAProxy Protocol is enabled. In order for this to happen, the application must be configured to use HAProxy Protocol. Reactor Netty 1.3.0 - 1.3.6 Reactor Netty 1.1.0 - 1.2.18 Reactor Netty 1.0.52 and earlier
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-47850 - Spring Data REST allows mutation of the version property of immutable aggregates via PUT

CVE ID :CVE-2026-47850
Published : Aug. 27, 2026, 1:17 a.m. | 2 hours, 22 minutes ago
Description :Spring Data REST does not preserve the persisted version (@Version) property of an aggregate root when handling an HTTP PUT against an immutable target type. Spring Data REST 5.1.0 Spring Data REST 5.0.0 - 5.0.6 Spring Data REST 4.5.0 - 4.5.12 Spring Data REST 4.0.0 - 4.4.15 Spring Data REST 3.7.20 and earlier
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-47851 - Unbounded recursion over attacker-controlled PDF outline tree in Spring AI PDF Document Reader

CVE ID :CVE-2026-47851
Published : Aug. 27, 2026, 1:17 a.m. | 2 hours, 22 minutes ago
Description :Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError in the ingestion thread. Spring AI 2.0.0 Spring AI 1.1.0 - 1.1.8 Spring AI 1.0.0 - 1.0.9
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-47852 - Predictable cache directory location allows local ONNX model substitution in Spring AI

CVE ID :CVE-2026-47852
Published : Aug. 27, 2026, 1:17 a.m. | 2 hours, 22 minutes ago
Description :A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file. Spring AI 2.0.0 Spring AI 1.1.0 - 1.1.8 Spring AI 1.0.0 - 1.0.9
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-47856 - JsonToObjectTransformer resolves the json__TypeId__ message header to an arbitrary class without an allow-list

CVE ID :CVE-2026-47856
Published : Aug. 27, 2026, 1:17 a.m. | 2 hours, 22 minutes ago
Description :Spring Integration's JSON to object conversion uses the json__TypeId__ header to choose the deserialization target type, and resolves that header value to a class with ClassUtils.forName and no type/package allow-list. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12 Spring Integration 5.5.21 and earlier
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-47857 - Reactor Core windowTimeout fair-backpressure stream hang due to 20-bit index wrap-around

CVE ID :CVE-2026-47857
Published : Aug. 27, 2026, 1:17 a.m. | 2 hours, 22 minutes ago
Description :In Reactor Core, applications that use the Flux.windowTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition. Reactor Core 3.8.0 - 3.8.6 Reactor Core 3.5.0 - 3.7.19 Reactor Core 3.4.41 and earlier
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-47859 - Unbounded memory allocation in RFC6587SyslogDeserializer (octet-counted framing) — remote DoS

CVE ID :CVE-2026-47859
Published : Aug. 27, 2026, 1:17 a.m. | 2 hours, 22 minutes ago
Description :RFC6587SyslogDeserializer, used by the Spring Integration syslog TCP inbound adapter to decode RFC 6587 / RFC 5424 frames, trusts the sender-supplied octet count of an octet-counted frame and allocates a byte array of exactly that size with no upper bound. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12 Spring Integration 5.5.21 and earlier
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-47860 - Unbounded decompression of attacker-supplied compressed message bodies

CVE ID :CVE-2026-47860
Published : Aug. 27, 2026, 1:17 a.m. | 2 hours, 22 minutes ago
Description :An attacker who can publish to a queue consumed by an application that has enabled message decompression can crash the consumer JVM with a single ~1 MB message. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-47861 - UDP adapter sends ack to attacker-supplied host:port parsed from packet body, even when acknowledge=false

CVE ID :CVE-2026-47861
Published : Aug. 27, 2026, 1:17 a.m. | 2 hours, 22 minutes ago
Description :An unauthenticated remote attacker who can send a single UDP packet to a Spring Integration UDP inbound adapter can cause the server to emit an outbound UDP datagram to an arbitrary internal or external host and port of the attacker's choosing. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12 Spring Integration 5.5.21 and earlier
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-47862 - ZipTransformer uses file_name header to build workDirectory path without sanitization

CVE ID :CVE-2026-47862
Published : Aug. 27, 2026, 1:17 a.m. | 2 hours, 22 minutes ago
Description :An attacker who can set the file_name header on a message reaching a ZipTransformer with ZipResultType.FILE (the default) can cause the resulting .zip archive to be written to an arbitrary filesystem path outside the configured workDirectory. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-47863 - Reactor Core bufferTimeout fair-backpressure pipeline permanently hangs when upstream delivers items during an active flush

CVE ID :CVE-2026-47863
Published : Aug. 27, 2026, 1:17 a.m. | 2 hours, 22 minutes ago
Description :In Reactor Core, applications that use the Flux.bufferTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition. Reactor Core 3.8.0 - 3.8.6 Reactor Core 3.7.19 and earlier
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-47874 - Reactor Netty HTTP Server Denial of Service With Pipelined Requests

CVE ID :CVE-2026-47874
Published : Aug. 27, 2026, 1:17 a.m. | 2 hours, 22 minutes ago
Description :The vulnerability occurs when a client sends HTTP/1.1 pipelined requests over a single connection, causing the Reactor Netty HTTP server to consume an excessive amount of memory. Reactor Netty 1.3.0 - 1.3.6 Reactor Netty 1.1.0 - 1.2.18 Reactor Netty 1.0.52 and earlier
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-80183 - OpenStack Keystone Authorization Bypass Vulnerability

CVE ID :CVE-2026-80183
Published : Aug. 27, 2026, 1:18 a.m. | 2 hours, 22 minutes ago
Description :In OpenStack Keystone before 29.0.3, any authenticated user holding role:reader on any project can list every project-scoped role assignment under any domain by passing a domain ID as scope.project.id with include_subtree to the GET /v3/role_assignments endpoint. The domain's project record has domain_id=null, causing the policy domain_id check to pass for any caller. With include_names, the response discloses the names and home-domain IDs of every user, group, project, and role involved. The literal "default" domain ID works against any deployment created with keystone-manage bootstrap. An attacker can harvest domain IDs from the response and repeat the query to map role assignments across the entire cloud. This is caused by misuse of "None" in  list_role_assignments_for_tree.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81421 - ddfourtwo sentry-selfhosted-mcp raw_sentry_api server-side request forgery

CVE ID :CVE-2026-81421
Published : Aug. 27, 2026, 1:18 a.m. | 2 hours, 22 minutes ago
Description :A security flaw has been discovered in ddfourtwo sentry-selfhosted-mcp 0.4.0. The affected element is an unknown function of the component raw_sentry_api. The manipulation of the argument endpoint results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...