CVE tracker
393 subscribers
5.75K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-91860 - Prototype Pollution in Vaadin Charts and Component Base via Unfiltered Deep Merge

CVE ID :CVE-2026-91860
Published : Sept. 30, 2026, 1:13 p.m. | 17 minutes ago
Description :A prototype pollution vulnerability exists in the deep merge helpers of Vaadin Charts and Vaadin Component Base. Merging an object the application does not control into a chart configuration or into a component's i18n property writes onto Object.prototype, making the injected properties visible to every object in the running application. Users of affected versions should apply the following mitigation or upgrade. Releases that have fixed this issue include: Product version Vaadin 23.0.0 - 23.6.13 Vaadin 24.0.0 - 24.9.20 Vaadin 24.10.0 - 24.10.9 Vaadin 25.0.0 - 25.1.11 Vaadin 25.2.0 - 25.2.6 Mitigation Upgrade to 23.6.14 Upgrade to 24.9.21 Upgrade to 24.10.10 Upgrade to 25.1.12 Upgrade to 25.2.7 or newer Please note that Vaadin versions 10-13 and 15-22 are no longer supported and you should update either to the latest 23, 24, 25 version. Artifacts Maven coordinates Vulnerable versions Fixed version com.vaadin:vaadin 23.0.0 - 23.6.13 >=23.6.14 com.vaadin:vaadin 24.0.0 - 24.9.20 >=24.9.21 com.vaadin:vaadin 24.10.0 - 24.10.9 >=24.10.10 com.vaadin:vaadin 25.0.0 - 25.1.11 >=25.1.12 com.vaadin:vaadin 25.2.0 - 25.2.6 >=25.2.7 com.vaadin:vaadin-core 24.7.0 - 24.9.20 >=24.9.21 com.vaadin:vaadin-core 24.10.0 - 24.10.9 >=24.10.10 com.vaadin:vaadin-core 25.0.0 - 25.1.11 >=25.1.12 com.vaadin:vaadin-core 25.2.0 - 25.2.6 >=25.2.7 com.vaadin:vaadin-charts-flow 23.0.0 - 23.6.13 >=23.6.14 com.vaadin:vaadin-charts-flow 24.0.0 - 24.9.20 >=24.9.21 com.vaadin:vaadin-charts-flow 24.10.0 - 24.10.9 >=24.10.10 com.vaadin:vaadin-charts-flow 25.0.0 - 25.1.11 >=25.1.12 com.vaadin:vaadin-charts-flow 25.2.0 - 25.2.6 >=25.2.7 npm packages npm package Vulnerable versions Fixed version @vaadin/charts 23.0.0 - 23.6.4 >=23.6.5 @vaadin/charts 24.0.0 - 24.9.17 >=24.9.18 @vaadin/charts 24.10.0 - 24.10.4 >=24.10.5 @vaadin/charts 25.0.0 - 25.1.11 >=25.1.12 @vaadin/charts 25.2.0 - 25.2.8 >=25.2.9 @vaadin/component-base 24.7.0 - 24.9.17 >=24.9.18 @vaadin/component-base 24.10.0 - 24.10.4 >=24.10.5 @vaadin/component-base 25.0.0 - 25.1.11 >=25.1.12 @vaadin/component-base 25.2.0 - 25.2.8 >=25.2.9
Severity: 6.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93547 - Missing Authorization Check in Vaadin Spreadsheet Allows Cell Comments to Be Written to Protected Sheets and Locked Cells

CVE ID :CVE-2026-93547
Published : Sept. 30, 2026, 1:13 p.m. | 16 minutes ago
Description :A missing authorization check in the Vaadin Spreadsheet component allows an authenticated user of an application that renders a spreadsheet to add or replace cell comments on a sheet that has protection enabled, including on cells that are locked. Writing a comment to a cell that does not exist yet also creates the row and the cell. Users of affected versions should apply the following mitigation or upgrade. Releases that have fixed this issue include: Product version Vaadin 23.1.0 - 23.6.13 Vaadin 24.0.0 - 24.9.21 Vaadin 24.10.0 - 24.10.9 Vaadin 25.0.0 - 25.1.11 Vaadin 25.2.0 - 25.2.6 Vaadin Framework 7 and 8 with the Spreadsheet add-on 2.0.0 - 3.1.0 Mitigation Upgrade to 23.6.14 Upgrade to 24.9.22 Upgrade to 24.10.10 Upgrade to 25.1.12 Upgrade to 25.2.7 or newer Upgrade the Spreadsheet add-on to 3.1.1 Please note that Vaadin versions 10-13 and 15-22 are no longer supported and you should update either to the latest 23, 24, 25 version. Artifacts Maven coordinates Vulnerable versions Fixed version com.vaadin:vaadin 23.1.0 - 23.6.13 >=23.6.14 com.vaadin:vaadin 24.0.0 - 24.9.21 >=24.9.22 com.vaadin:vaadin 24.10.0 - 24.10.9 >=24.10.10 com.vaadin:vaadin 25.0.0 - 25.1.11 >=25.1.12 com.vaadin:vaadin 25.2.0 - 25.2.6 >=25.2.7 com.vaadin:vaadin-spreadsheet-flow 23.1.0 - 23.6.13 >=23.6.14 com.vaadin:vaadin-spreadsheet-flow 24.0.0 - 24.9.21 >=24.9.22 com.vaadin:vaadin-spreadsheet-flow 24.10.0 - 24.10.9 >=24.10.10 com.vaadin:vaadin-spreadsheet-flow 25.0.0 - 25.1.11 >=25.1.12 com.vaadin:vaadin-spreadsheet-flow 25.2.0 - 25.2.6 >=25.2.7 com.vaadin:vaadin-spreadsheet 2.0.0 - 3.1.0 >=3.1.1
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82307 - Multiple Vulnerabilities in Dolusoft Software's SOPLOG

CVE ID :CVE-2026-82307
Published : Sept. 30, 2026, 1:20 p.m. | 9 minutes ago
Description :Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Dolusoft Software Technologies SOPLOG allows SQL Injection. This issue affects SOPLOG: before Soplog 2026.9.4.1.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-55174 - UltrafastSecp256k1: ECDSA adaptor verification accepts non-adaptable pre-signatures due to missing DLEQ binding

CVE ID :CVE-2026-55174
Published : Sept. 30, 2026, 4:17 p.m. | 1 hour, 13 minutes ago
Description :UltrafastSecp256k1 is a high-performance, multi-backend secp256k1 engine with reproducible audit evidence, compatibility shims, and profile-based review scopes. Prior to version 4.2.0, UltrafastSecp256k1's ECDSA adaptor pre-signature verification accepts forged adaptor pre-signatures whose "r" value is not cryptographically bound to the adaptor point "T". This issue has been patched in version 4.2.0.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-80490 - Algorithm::AhoCorasick::XS versions through 0.04 for Perl read the haystack string length before the scalar is stringified

CVE ID :CVE-2026-80490
Published : Sept. 30, 2026, 4:19 p.m. | 1 hour, 11 minutes ago
Description :Algorithm::AhoCorasick::XS versions through 0.04 for Perl read the haystack string length before the scalar is stringified. The matches, first_match and match_details methods use the T_STD_STRING typemap to translate Perl scalars (SVs) into strings via the std::string constructor, using the SvPV macro to stringify the haystack input, and the SvCUR macro to determine the length of the SV. When the input SVs are references, integers (IVs) or floats (NVs), the SvCUR macro will return an invalid length if it is run before the input is stringified, leading to an out-of-bounds read which can abort the process. Note that the evaluation order of arguments to std::string is unspecified. Depending on the compiler, SvCUR may be run first and lead to an abort that cannot be caught within Perl. This can be triggered when the haystack is a numeric value, for example, my $ac = Algorithm::AhoCorasick::XS->new( [ "11", "22" ] ); $ac->matches( 211 ); This can occur when the haystack is the result of reading data from decoded JSON or a numeric database column. It can also be triggered when using a blessed object as a haystack.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-87004 - Tugtainer: OIDC id_token claims accepted without signature/audience/expiry verification

CVE ID :CVE-2026-87004
Published : Sept. 30, 2026, 5:01 p.m. | 29 minutes ago
Description :Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.31.3, when the OIDC login flow completes, backend/modules/auth/providers/auth_oidc_provider.py decodes the id_token returned by the identity provider's token endpoint using jose.jwt.get_unverified_claims() instead of jwt.decode(). This skips signature verification, audience (aud) validation, issuer (iss) validation, and expiry (exp) checking entirely. The extracted claims (email/sub/preferred_username) are then used directly as the user_id for the resulting Tugtainer session. This issue has been patched in version 1.31.3.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-103445 - Stored XSS through PageForms #autoedit redirect links

CVE ID :CVE-2026-103445
Published : Sept. 30, 2026, 5:04 p.m. | 26 minutes ago
Description :Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Page_Forms extension allows Stored XSS. This issue affects MediaWiki Page_Forms extension: 1.46, 1.45, and 1.43.
Severity: 1.2 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-55107 - Kobako Vulnerable to Sandbox Escape: guest eval reaches host RCE via method_missing → public_send (any bound Service)

CVE ID :CVE-2026-55107
Published : Sept. 30, 2026, 5:06 p.m. | 25 minutes ago
Description :Kobako is a Ruby gem that embeds a Wasm-isolated mruby interpreter inside applications, allowing execution of untrusted Ruby scripts (LLM-generated code, user formulas, student submissions, third-party plugins) in-process without giving them access to host memory, files, network, or credentials. From version 0.1.0 to before version 0.9.1, a guest mruby script running inside the Kobako sandbox can execute arbitrary Ruby in the host process, fully escaping the sandbox. This issue has been patched in version 0.9.1.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-53605 - Reachy Mini Wireless: Local Privilege Escalation via Unrestricted sudo systemctl Grant

CVE ID :CVE-2026-53605
Published : Sept. 30, 2026, 5:09 p.m. | 21 minutes ago
Description :Reachy Mini ISO for Wireless contains the necessary files to build a custom Raspberry Pi OS image for the Reachy Mini Wireless robot, using pi-gen. Prior to version 0.2.4, the Reachy Mini Wireless OS image shipped with an overly broad sudoers entry granting the pollen daemon user (uid 1000) passwordless sudo access to /usr/bin/systemctl with no subcommand or argument restriction. This is a local privilege escalation (LPE). Any process running as pollen can obtain full root (uid 0) on the device in three commands, with no additional vulnerability required and no user interaction. This issue has been patched in version 0.2.4.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-103446 - WikiLambda exposes anonymous execution of unsaved Abstract Wikipedia fragments

CVE ID :CVE-2026-103446
Published : Sept. 30, 2026, 5:13 p.m. | 18 minutes ago
Description :Authorization bypass through User-Controlled key vulnerability in The Wikimedia Foundation MediaWiki WikiLambda extension allows Authentication Bypass. This issue affects MediaWiki WikiLambda extension: 1.46.
Severity: 7.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-103500 - Heap buffer overflow opening large email

CVE ID :CVE-2026-103500
Published : Sept. 30, 2026, 5:15 p.m. | 15 minutes ago
Description :An attacker could cause a heap buffer overflow by getting a user to open an email that is greater than or equal to 2GB in size. This vulnerability was fixed in Thunderbird 157.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-102489 - Undisclosed RCE in Zammad v6.3 and higher

CVE ID :CVE-2026-102489
Published : Sept. 30, 2026, 5:16 p.m. | 14 minutes ago
Description :Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.
Severity: 9.4 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-102490 - Undisclosed LPE in Zammad v1.5.0 to v7.1.0-alpha

CVE ID :CVE-2026-102490
Published : Sept. 30, 2026, 5:16 p.m. | 14 minutes ago
Description :All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
Severity: 9.4 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-103232 - AdithyaYelloju Restaurant-Management-System table_booking.php mysqli_query sql injection

CVE ID :CVE-2026-103232
Published : Sept. 30, 2026, 5:16 p.m. | 14 minutes ago
Description :A weakness has been identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This affects the function mysqli_query of the file admin/table_booking.php. This manipulation of the argument Name causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-103233 - AdithyaYelloju Restaurant-Management-System Admin Area admin authorization

CVE ID :CVE-2026-103233
Published : Sept. 30, 2026, 5:16 p.m. | 14 minutes ago
Description :A security vulnerability has been detected in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This impacts an unknown function of the file /admin/ of the component Admin Area. Such manipulation of the argument ID leads to authorization bypass. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-103241 - vllm-project vLLM Gemma4UnifiedParser gemma4.rs denial of service

CVE ID :CVE-2026-103241
Published : Sept. 30, 2026, 5:16 p.m. | 14 minutes ago
Description :A flaw has been found in vllm-project vLLM up to 0.26.0. This vulnerability affects unknown code of the file rust/src/parser/src/unified/gemma4.rs of the component Gemma4UnifiedParser. Executing a manipulation can lead to denial of service. The attack may be launched remotely. The exploit has been published and may be used. Upgrading to version 0.29.1rc0 is able to resolve this issue. This patch is called 3439bad37e68ba9755a46f4f6b44a4aeaf1f60a9. Upgrading the affected component is advised.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-103443 - API permits session-seeded javascript URL XSS

CVE ID :CVE-2026-103443
Published : Sept. 30, 2026, 5:16 p.m. | 14 minutes ago
Description :Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Collection (Book) extension allows XSS Targeting Non-Script Elements. This issue affects MediaWiki Collection (Book) extension: 1.46, 1.45, and 1.43.
Severity: 1.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-103444 - Stored XSS through system messages in WikiForum

CVE ID :CVE-2026-103444
Published : Sept. 30, 2026, 5:16 p.m. | 14 minutes ago
Description :Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki WikiForum extension allows Stored XSS. This issue affects MediaWiki WikiForum extension: master.
Severity: 1.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19445 - Use-after-free of a server-side SSLContext when sni_callback switches contexts

CVE ID :CVE-2026-19445
Published : Sept. 30, 2026, 5:16 p.m. | 14 minutes ago
Description :A remote, unauthenticated TLS client can make a server crash or call through a freed pointer if its sni_callback assigns a different context to SSLSocket.context (the documented way to select a certificate per server name) and nothing else keeps the original ssl.SSLContext alive. Typical cases are servers that create an SSLContext per connection or replace it while connections are open; servers that wrap their listening socket with it are not affected. Mitigation: keep a reference to every SSLContext that sets sni_callback for the lifetime of the server. TLS clients are not affected.
Severity: 9.2 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-19553 - SSLContext.wrap_bio() missing validation of server_hostname parameter

CVE ID :CVE-2026-19553
Published : Sept. 30, 2026, 5:16 p.m. | 14 minutes ago
Description :ssl.SSLContext.wrap_bio() didn't require the server_hostname argument to not be None if ssl.SSLContext.check_hostname was set. Due to a missing parameter check in SSLObject, if the server_hostname argument isn't supplied then hostname verification would be silently skipped. This defect could lead to programs where certificate hostname verification *appeared* to be succeeding with SSLContext.check_hostname = True and no ValueError being raised due to misconfiguration. If the program passes a server_hostname value that isn't an empty string or None to any of these APIs then certificate hostname verification proceeds as expected and the program is not affected by this vulnerability. Mitigating this vulnerability doesn't require updating Python or applying the patch. To mitigate, pass a valid non-None and non-empty server_hostname value to SSLContext.wrap_bio(), asyncio.create_connection(), or asyncio.loop.start_tls() and certificate hostname verification will proceed as expected. Upgrading to the latest version of Python or applying the patch only changes the behavior from silently skipping hostname verification to raising a ValueError, similar to SSLContext.wrap_socket(), when server_hostname isn't supplied.
Severity: 7.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-46711 - Soft Machine: Unauthenticated workspace API exposes arbitrary file read & directory exfiltration to any peer on the Fly private network

CVE ID :CVE-2026-46711
Published : Sept. 30, 2026, 5:16 p.m. | 14 minutes ago
Description :Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.247 and prior, the workspace HTTP service that listens on 0.0.0.0:8080 inside each sm-ws-* Fly Machine exposes endpoints (/health, /file/, /archive/