CVE tracker
394 subscribers
5.74K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-93578 - Netty: netty-handler-ssl-ocsp: io.netty/netty-handler-ssl-ocsp: netty: missing extended key usage (eku) check in ocsp client allows certificate revocation bypass

CVE ID :CVE-2026-93578
Published : Sept. 18, 2026, 11:17 a.m. | 1 hour, 4 minutes ago
Description :Missing Extended Key Usage (EKU) check in OCSP Client allows certificate revocation bypass
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-28199 - Sensitive File Disclosure via Relative Path Traversal in NetBackup Flex OS Shell

CVE ID :CVE-2026-28199
Published : Sept. 18, 2026, 11:19 a.m. | 1 hour, 2 minutes ago
Description :An authenticated user with access to the NetBackup Flex OS management shell could read arbitrary files from the underlying operating system by supplying a specially crafted path argument to a diagnostic command. Successful exploitation could expose sensitive system configuration and credential material stored on the appliance.
Severity: 4.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93488 - Io.netty/netty-codec-http: netty: denial of service via unbounded concurrent spdy streams

CVE ID :CVE-2026-93488
Published : Sept. 18, 2026, 11:47 a.m. | 34 minutes ago
Description :A flaw was found in Netty. SpdySessionHandler accepts an unlimited number of concurrent remote-initiated streams because localConcurrentStreams defaults to Integer.MAX_VALUE and the handler provides no API to change it. A remote peer can open a SPDY connection and send a large number of SYN_STREAM frames with FLAG_FIN=0, causing unbounded heap and direct memory allocation that can lead to JVM OutOfMemoryError and a denial of service.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-10751 - IBM MQ Java messaging is vulnerable to remote code execution

CVE ID :CVE-2026-10751
Published : Sept. 18, 2026, 3:56 p.m. | 25 minutes ago
Description :IBM MQ Java and JMS client libraries could allow an authenticated attacker to execute arbitrary code on client applications due to a deserialization filter bypass in exception handling.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84384 - libheif: brotli/zlib decompression paths lack output-size limits, allowing decompression-bomb OOM/DoS

CVE ID :CVE-2026-84384
Published : Sept. 18, 2026, 3:58 p.m. | 24 minutes ago
Description :libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.2, crafted HEIF or AVIF mime metadata and unci image data can cause decompress_brotli() and do_inflate() to grow accumulated output without an effective size limit or MemoryHandle accounting. The brotli path has no output bound, while the zlib path checks only a small temporary buffer in a branch that valid streams do not reach, and overlapping icef units can decompress the same payload repeatedly. HeifContext::interpret_heif_file_images() processes multiple compressed metadata items during file opening, allowing a small file to consume unbounded memory and terminate the process. This issue is fixed in version 1.23.2.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84447 - libheif: Derived-image indirect reference chains and tiled offsets bypass decode caching and MemoryHandle limits, causing CPU/memory amplification DoS

CVE ID :CVE-2026-84447
Published : Sept. 18, 2026, 4 p.m. | 22 minutes ago
Description :libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.1 and earlier, crafted grid, iovl, and iden reference graphs can repeatedly decode the same base image because processed_ids is copied per branch and ImageItem::decode_image() has no shared operation budget. This vulnerability is fixed in 1.23.2.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84451 - libheif: Incomplete fix for CVE-2026-62292 leaves libheif vulnerable to an out-of-bounds read

CVE ID :CVE-2026-84451
Published : Sept. 18, 2026, 4:02 p.m. | 20 minutes ago
Description :libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.3, the no-icef full-item branch of unc_decoder::get_compressed_image_data_uncompressed() in libheif/codecs/uncompressed/unc_decoder.cc retains an addition-based range check that can wrap when a crafted uncompressed tile grid produces a large range_start_offset and range_size. The overflow makes the bounds comparison pass and allows heif_image_handle_decode_image_tile() to call memcpy() with an invalid source pointer and a very large length when decoding a valid high-index advertised tile. This incomplete remediation of CVE-2026-62292 can reliably crash tile-processing applications, while whole-image decoding is not claimed to reach the demonstrated path. This issue is fixed in version 1.23.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84449 - libheif hOp_RGB24_32_to_YCbCr Memory Access Error / SEGV

CVE ID :CVE-2026-84449
Published : Sept. 18, 2026, 4:03 p.m. | 19 minutes ago
Description :libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.19.6, Op_RGB24_32_to_YCbCr::convert_colorspace() stores image-plane strides in an integer width that can overflow for extremely large RGB images created through heif_image_create() and heif_image_add_plane(). The resulting wrapped stride causes the conversion loop in libheif/color-conversion/rgb2yuv.cc to compute an invalid input pointer and read beyond the allocated interleaved plane while heif_context_encode_image() performs RGB-to-YCbCr conversion. This can crash the encoding process. This issue is fixed in version 1.19.6.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93736 - Mealie before 3.21.0 Information Disclosure via Ratings Endpoint

CVE ID :CVE-2026-93736
Published : Sept. 18, 2026, 4:04 p.m. | 18 minutes ago
Description :Mealie before 3.21.0 fails to validate user ownership in the ratings and favorites endpoints, allowing authenticated attackers to read any user's recipe ratings and favorites by specifying arbitrary user IDs in the URL path. Attackers can access private recipe identifiers, rating values, and favorite flags belonging to other users across different groups or households.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93737 - Azkaban through 4.0.0 Authorization Bypass via ScheduleServlet

CVE ID :CVE-2026-93737
Published : Sept. 18, 2026, 4:04 p.m. | 18 minutes ago
Description :Azkaban through 4.0.0 omits project permission checks in the ScheduleServlet fetchSchedule action, allowing authenticated users to read any project's schedule configuration. Attackers can supply arbitrary project and flow identifiers to retrieve sensitive schedule details including execution times, cron expressions, flow parameters, and notification email lists without proper authorization.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84450 - libheif: `clap` + oversized `ispe` aborts on an assert in `Fraction::Fraction` (incomplete fix for CVE-2026-62289)

CVE ID :CVE-2026-84450
Published : Sept. 18, 2026, 4:04 p.m. | 18 minutes ago
Description :libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.3, a crafted image item containing a clap property and an ispe width or height greater than INT32_MAX + 1 can reach crop calculations through heif_image_handle_get_image_tiling(). Box_clap::left_rounded() or Box_clap::top_rounded() passes the image dimension minus one to Fraction::Fraction(), whose uint32_t constructor uses an assertion as input validation, causing assert-enabled builds to abort. Release builds can instead compute invalid crop geometry, and the tiling API returns dimensions that the normal decode security limits reject. This issue is fixed in version 1.23.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-88259 - CareCam CM2507 Missing Authentication for Critical Function

CVE ID :CVE-2026-88259
Published : Sept. 18, 2026, 4:05 p.m. | 17 minutes ago
Description :CareCam CM2507 IP cameras do not require authentication for access to its network video streaming service. An unauthenticated attacker with network access to the affected device could retrieve live camera video.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-10841 - Multiple security vulnerabilities may affect IBM WebSphere Liberty that is shipped with IBM CICS TX Advanced.

CVE ID :CVE-2026-10841
Published : Sept. 18, 2026, 4:06 p.m. | 16 minutes ago
Description :IBM WebSphere Application Server 8.5, 9.0, and Liberty are vulnerable to HTTP request smuggling.
Severity: 4.2 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-68914 - Mojolicious pure-Perl Mojo::JSON decoder allows memory exhaustion via deeply nested data

CVE ID :CVE-2026-68914
Published : Sept. 18, 2026, 4:07 p.m. | 15 minutes ago
Description :Mojolicious is a real-time web framework for Perl. Prior to 9.47, the pure-Perl implementation of Mojo::JSON does not limit nesting depth when Cpanel::JSON::XS is unavailable or MOJO_NO_JSON_XS is enabled. An attacker who can supply untrusted JSON to decode_json, from_json, or j can submit deeply nested arrays or objects, causing unbounded recursion, memory exhaustion, and a process crash. Applications using the Cpanel::JSON::XS backend are not affected because that backend already enforces a nesting limit. This issue is fixed in version 9.47.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-10853 - IBM MQ queue manager is vulnerable to remote code execution

CVE ID :CVE-2026-10853
Published : Sept. 18, 2026, 4:07 p.m. | 15 minutes ago
Description :IBM MQ could allow an authenticated attacker with cluster access to cause a denial of service or potentially execute arbitrary code due to improper validation of cluster command message lengths.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84398 - CareCam CM2507 Empty Password in Configuration File

CVE ID :CVE-2026-84398
Published : Sept. 18, 2026, 4:07 p.m. | 15 minutes ago
Description :CM2507 IP cameras accept an empty password for a privileged account exposed through its ONVIF management service. An attacker with network access to the affected device could access privileged management functions and obtain device, user, media-profile, and stream configuration information.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-10858 - IBM MQ for HPE NonStop is vulnerable to a denial of service attack

CVE ID :CVE-2026-10858
Published : Sept. 18, 2026, 4:08 p.m. | 14 minutes ago
Description :IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer underflow when processing multi-segment messages.
Severity: 9.9 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-77568 - Mojolicious: CSRF tokens are vulnerable to BREACH attacks

CVE ID :CVE-2026-77568
Published : Sept. 18, 2026, 4:08 p.m. | 14 minutes ago
Description :Mojolicious is a real-time web framework for Perl. Prior to 9.48, the Mojolicious CSRF helpers csrf_field, csrf_token, and csrf_protect reuse an unchanged per-session token in rendered HTML. When response compression is enabled and attacker-influenced content is reflected in the same response, an unauthenticated attacker who can induce many victim requests and observe response sizes can use a BREACH compression side channel to recover the token and forge cross-site requests. API-only deployments that never render the token in HTML are not affected. This issue is fixed in version 9.48.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-11375 - IBM MQ queue manager is vulnerable to remote code execution

CVE ID :CVE-2026-11375
Published : Sept. 18, 2026, 4:09 p.m. | 13 minutes ago
Description :IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a stack buffer overflow when processing XA transaction identifiers.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-61682 - Semantic MediaWiki vulnerable to stored XSS through wikitext via improper use of non-reserved data attributes

CVE ID :CVE-2025-61682
Published : Sept. 18, 2026, 4:09 p.m. | 13 minutes ago
Description :Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Versions starting in 3.1.0 and prior to 7.0.0 insert the unsanitized value of a data attribute into the DOM as HTML, allowing for stored XSS through wikitext. Version 7.0.0 patches the issue.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-11378 - IBM MQ queue manager is vulnerable to remote code execution

CVE ID :CVE-2026-11378
Published : Sept. 18, 2026, 4:09 p.m. | 13 minutes ago
Description :IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in distribution list processing.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...