CVE tracker
383 subscribers
5.38K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-47860 - Unbounded decompression of attacker-supplied compressed message bodies

CVE ID :CVE-2026-47860
Published : Aug. 27, 2026, 1:17 a.m. | 2 hours, 22 minutes ago
Description :An attacker who can publish to a queue consumed by an application that has enabled message decompression can crash the consumer JVM with a single ~1 MB message. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-47861 - UDP adapter sends ack to attacker-supplied host:port parsed from packet body, even when acknowledge=false

CVE ID :CVE-2026-47861
Published : Aug. 27, 2026, 1:17 a.m. | 2 hours, 22 minutes ago
Description :An unauthenticated remote attacker who can send a single UDP packet to a Spring Integration UDP inbound adapter can cause the server to emit an outbound UDP datagram to an arbitrary internal or external host and port of the attacker's choosing. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12 Spring Integration 5.5.21 and earlier
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-47862 - ZipTransformer uses file_name header to build workDirectory path without sanitization

CVE ID :CVE-2026-47862
Published : Aug. 27, 2026, 1:17 a.m. | 2 hours, 22 minutes ago
Description :An attacker who can set the file_name header on a message reaching a ZipTransformer with ZipResultType.FILE (the default) can cause the resulting .zip archive to be written to an arbitrary filesystem path outside the configured workDirectory. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-47863 - Reactor Core bufferTimeout fair-backpressure pipeline permanently hangs when upstream delivers items during an active flush

CVE ID :CVE-2026-47863
Published : Aug. 27, 2026, 1:17 a.m. | 2 hours, 22 minutes ago
Description :In Reactor Core, applications that use the Flux.bufferTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition. Reactor Core 3.8.0 - 3.8.6 Reactor Core 3.7.19 and earlier
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-47874 - Reactor Netty HTTP Server Denial of Service With Pipelined Requests

CVE ID :CVE-2026-47874
Published : Aug. 27, 2026, 1:17 a.m. | 2 hours, 22 minutes ago
Description :The vulnerability occurs when a client sends HTTP/1.1 pipelined requests over a single connection, causing the Reactor Netty HTTP server to consume an excessive amount of memory. Reactor Netty 1.3.0 - 1.3.6 Reactor Netty 1.1.0 - 1.2.18 Reactor Netty 1.0.52 and earlier
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-80183 - OpenStack Keystone Authorization Bypass Vulnerability

CVE ID :CVE-2026-80183
Published : Aug. 27, 2026, 1:18 a.m. | 2 hours, 22 minutes ago
Description :In OpenStack Keystone before 29.0.3, any authenticated user holding role:reader on any project can list every project-scoped role assignment under any domain by passing a domain ID as scope.project.id with include_subtree to the GET /v3/role_assignments endpoint. The domain's project record has domain_id=null, causing the policy domain_id check to pass for any caller. With include_names, the response discloses the names and home-domain IDs of every user, group, project, and role involved. The literal "default" domain ID works against any deployment created with keystone-manage bootstrap. An attacker can harvest domain IDs from the response and repeat the query to map role assignments across the entire cloud. This is caused by misuse of "None" in  list_role_assignments_for_tree.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81421 - ddfourtwo sentry-selfhosted-mcp raw_sentry_api server-side request forgery

CVE ID :CVE-2026-81421
Published : Aug. 27, 2026, 1:18 a.m. | 2 hours, 22 minutes ago
Description :A security flaw has been discovered in ddfourtwo sentry-selfhosted-mcp 0.4.0. The affected element is an unknown function of the component raw_sentry_api. The manipulation of the argument endpoint results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19398 - ASUS BIOS SmiFlash Out-of-Bounds Write Vulnerability

CVE ID :CVE-2026-19398
Published : Aug. 27, 2026, 2:16 a.m. | 1 hour, 23 minutes ago
Description :“unsupported-when-assigned.” An out-of-bounds write in the SmiFlash SMM module of ASUS FA507NU and FA507NV BIOS allows a local  administrator to cause a system crash (BSOD) or BIOS corruption via a crafted software SMI (SW SMI) request with an oversized length value.Refer to the '  Security Update for ASUS FA507NV / FA507NU BIOS   ' section on the ASUS Security Advisory for more information.
Severity: 6.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81485 - danielpopamd linkedin-ads-mcp Media Upload campaign-management.ts fs.readFileSync path traversal

CVE ID :CVE-2026-81485
Published : Aug. 27, 2026, 2:16 a.m. | 1 hour, 23 minutes ago
Description :A security vulnerability has been detected in danielpopamd linkedin-ads-mcp 1.0.0. Affected by this vulnerability is the function fs.readFileSync of the file src/tools/campaign-management.ts of the component Media Upload. Such manipulation of the argument filePath leads to path traversal. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-81486 - bsmi021 mcp-file-context-server Path Resolution index.ts read_context path traversal

CVE ID :CVE-2026-81486
Published : Aug. 27, 2026, 2:16 a.m. | 1 hour, 23 minutes ago
Description :A vulnerability was detected in bsmi021 mcp-file-context-server 1.0.0. Affected by this issue is the function read_context of the file src/index.ts of the component Path Resolution. Performing a manipulation of the argument path results in path traversal. It is possible to initiate the attack remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-47889 - Spring Framework sameSite Attribute Dropped in JettyCoreServerHttpResponse

CVE ID :CVE-2026-47889
Published : Aug. 27, 2026, 6:17 a.m. | 1 hour, 24 minutes ago
Description :A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-47890 - Spring Framework Server Sent Event stream corruption while rendering fragments

CVE ID :CVE-2026-47890
Published : Aug. 27, 2026, 6:17 a.m. | 1 hour, 24 minutes ago
Description :Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-47891 - Spring Framework maxInMemorySize Bypassed in Jaxb2Decoder

CVE ID :CVE-2026-47891
Published : Aug. 27, 2026, 6:17 a.m. | 1 hour, 24 minutes ago
Description :A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-47892 - Spring Framework Header Predicate Bypass in WebFlux Functional Endpoints

CVE ID :CVE-2026-47892
Published : Aug. 27, 2026, 6:17 a.m. | 1 hour, 24 minutes ago
Description :A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predicate bypass in a pre-flight request. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.5.RELEASE - 5.2.25.RELEASE
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-47893 - Spring Framework Request Headers Included in Exception Reasons in HandshakeWebsocketService

CVE ID :CVE-2026-47893
Published : Aug. 27, 2026, 6:17 a.m. | 1 hour, 24 minutes ago
Description :A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user information by including request headers in an exception reason. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-47894 - Spring Cloud Config Server Native Environment Repository Exposure

CVE ID :CVE-2026-47894
Published : Aug. 27, 2026, 6:17 a.m. | 1 hour, 24 minutes ago
Description :Spring Cloud Config Server native environment repository allows exposure of configuration files outside of the configured repository path. Spring Cloud Config 5.0.0 - 5.0.4 Spring Cloud Config 4.3.0 - 4.3.4 Spring Cloud Config 4.0.0 - 4.2.8 Spring Cloud Config 3.1.14 and earlier
Severity: 4.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59270 - Spring Security embedded UnboundID LDAP server exposes well-known administrative bind DN on all network interfaces

CVE ID :CVE-2026-59270
Published : Aug. 27, 2026, 6:17 a.m. | 1 hour, 24 minutes ago
Description :Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Spring Security 6.5.0 - 6.5.11 Spring Security 6.4.0 - 6.4.18 Spring Security 5.8.0 - 5.8.27 Spring Security 5.7.0 - 5.7.25
Severity: 9.4 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59271 - Admin password disclosed in BrokerNotAliveException message

CVE ID :CVE-2026-59271
Published : Aug. 27, 2026, 6:17 a.m. | 1 hour, 24 minutes ago
Description :When the RabbitMQ management aliveness check fails, the configured admin password is embedded in cleartext in the thrown exception message. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59274 - Unbounded decompression in UnZipTransformer enables zip-bomb DoS

CVE ID :CVE-2026-59274
Published : Aug. 27, 2026, 6:17 a.m. | 1 hour, 24 minutes ago
Description :The UnZipTransformer does not limit decompressed entry size or entry count when processing archives. Consequently, an attacker can send a zip archive that can exhaust JVM heap memory, causing a denial-of-service outage. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59275 - Remote JVM termination: nested-array Java deserialization bypasses allowlist, triggers StackOverflowError, default JavaLangErrorHandler calls System.exit(99)

CVE ID :CVE-2026-59275
Published : Aug. 27, 2026, 6:17 a.m. | 1 hour, 24 minutes ago
Description :A single hostile AMQP message can terminate the entire consumer JVM (System.exit(99)), not just the listener thread — full availability loss for every workload co-located in that process. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier
Severity: 6.6 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-59278 - In Spring for Apache Kafka, SSRF via DNS resolution triggered by untrusted java.net types in header mapper default trusted packages

CVE ID :CVE-2026-59278
Published : Aug. 27, 2026, 6:17 a.m. | 1 hour, 24 minutes ago
Description :JsonKafkaHeaderMapper and DefaultKafkaHeaderMapper include java.net in their default trusted packages list. When these mappers are used — which is the default configuration for all @KafkaListener consumers — an external Kafka producer can inject a java.net.InetAddress type via the spring_json_header_types message header. Spring for Apache Kafka 4.1.0 Spring for Apache Kafka 4.0.0 - 4.0.6 Spring for Apache Kafka 3.0.0 - 3.3.16 Spring for Apache Kafka 2.9.0 - 2.9.14 Spring for Apache Kafka 2.8.12 and earlier
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...