🚨 CVE-2026-30279
An arbitrary file overwrite vulnerability in Squareapps LLC My Location Travel Timeline v11.80 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.
🎖@cveNotify
An arbitrary file overwrite vulnerability in Squareapps LLC My Location Travel Timeline v11.80 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.
🎖@cveNotify
GitHub
My Location - Travel Timeline APP Arbitrary File Overwrite Vulnerability · Issue #28 · Secsys-FDU/AF_CVEs
Vendor:Squareapps LLC(https://lightapp3.firebaseapp.com/) Affected product:My Location - Travel Timeline (com.kaisquare.location) Version:V11.80 Google Play link:https://play.google.com/store/apps/...
🚨 CVE-2026-30283
An arbitrary file overwrite vulnerability in PEAKSEL D.O.O. NIS Animal Sounds and Ringtones v1.3.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.
🎖@cveNotify
An arbitrary file overwrite vulnerability in PEAKSEL D.O.O. NIS Animal Sounds and Ringtones v1.3.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.
🎖@cveNotify
GitHub
Animal Sounds and Ringtones APP Arbitrary File Overwrite Vulnerability · Issue #26 · Secsys-FDU/AF_CVEs
Vendor:PEAKSEL D.O.O. NIS(https://peaksel.com/) Affected product:Animal Sounds and Ringtones (com.animalsounds.natureringtoneapp) Version:V1.3.0 Google Play link:https://play.google.com/store/apps/...
🚨 CVE-2026-30286
An arbitrary file overwrite vulnerability in Funambol, Inc. Zefiro Cloud v32.0.2026011614 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.
🎖@cveNotify
An arbitrary file overwrite vulnerability in Funambol, Inc. Zefiro Cloud v32.0.2026011614 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.
🎖@cveNotify
GitHub
Zefiro Cloud APP Arbitrary File Overwrite Vulnerability · Issue #14 · Secsys-FDU/AF_CVEs
Vendor:Funambol, Inc.(https://zefiro.me/) Affected product:Zefiro Cloud (com.funambol.zefiro),https://play.google.com/store/apps/details?id=com.funambol.zefiro Version:32.0.2026011614 Google Play l...
🚨 CVE-2026-32113
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, the enter action in StaticController reads the sso_destination_url cookie and redirects to it with allow_other_host: true without validating the destination URL. While this cookie is normally set during legitimate DiscourseConnect Provider flows with cryptographically validated SSO payloads, cookies are client-controlled and can be set by attackers. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.
🎖@cveNotify
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, the enter action in StaticController reads the sso_destination_url cookie and redirects to it with allow_other_host: true without validating the destination URL. While this cookie is normally set during legitimate DiscourseConnect Provider flows with cryptographically validated SSO payloads, cookies are client-controlled and can be set by attackers. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.
🎖@cveNotify
GitHub
SECURITY: Validate sso_destination_url cookie to prevent open redirect · discourse/discourse@080408b
**Description**
Adds validation to ensure the `sso_destination_url` cookie value matches configured SSO provider domains before allowing external redirects. Previously, an attacker who could set c...
Adds validation to ensure the `sso_destination_url` cookie value matches configured SSO provider domains before allowing external redirects. Previously, an attacker who could set c...
🚨 CVE-2026-32143
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, moderators could export CSV data for admin-restricted reports, bypassing the report visibility restrictions. This could expose sensitive operational data intended only for admins. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.
🎖@cveNotify
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, moderators could export CSV data for admin-restricted reports, bypassing the report visibility restrictions. This could expose sensitive operational data intended only for admins. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.
🎖@cveNotify
GitHub
SECURITY: Prevent moderators from exporting admin-only reports via CSV · discourse/discourse@727029a
Moderators could bypass report visibility restrictions by using the CSV export endpoint to export admin-only reports like top_uploads.
---
**Security Advisory:** https://github.com/discourse/disc...
---
**Security Advisory:** https://github.com/discourse/disc...
🚨 CVE-2026-32243
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, an attacker with the ability to create shared AI conversations could inject arbitrary HTML and JavaScript via crafted conversation titles. This payload would execute in the browser of any user viewing the onebox preview, potentially allowing session hijacking or unauthorized actions on behalf of the victim. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.
🎖@cveNotify
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, an attacker with the ability to create shared AI conversations could inject arbitrary HTML and JavaScript via crafted conversation titles. This payload would execute in the browser of any user viewing the onebox preview, potentially allowing session hijacking or unauthorized actions on behalf of the victim. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.
🎖@cveNotify
GitHub
SECURITY: Stored XSS in discourse-ai shared conversations onebox · discourse/discourse@cac7d61
Fixes a stored XSS vulnerability in the shared AI conversation onebox rendering
---
**Security Advisory:** https://github.com/discourse/discourse/security/advisories/GHSA-pjc5-8x3w-rfwx
---
**Security Advisory:** https://github.com/discourse/discourse/security/advisories/GHSA-pjc5-8x3w-rfwx
🚨 CVE-2026-32273
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, updating a category description via API is not sanitizing the description string, which can lead to XSS attacks. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.
🎖@cveNotify
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, updating a category description via API is not sanitizing the description string, which can lead to XSS attacks. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.
🎖@cveNotify
GitHub
SECURITY: XSS on category description update via API · discourse/discourse@05e3da2
In discourse/discourse#36852 we added the ability to set the category description via the API, and sanitized this correctly on the create endpoint.
However, we forgot to sanitize the input, on the...
However, we forgot to sanitize the input, on the...
🚨 CVE-2026-32607
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, when the hidden prioritize_full_name_in_ux site setting is enabled (defaults to false, requires console access to change), user and group display names are rendered without HTML escaping in several assignment-related UI paths. This allows users with assign permission to inject arbitrary HTML/JavaScript that executes in the browser of any user viewing an affected topic. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.
🎖@cveNotify
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, when the hidden prioritize_full_name_in_ux site setting is enabled (defaults to false, requires console access to change), user and group display names are rendered without HTML escaping in several assignment-related UI paths. This allows users with assign permission to inject arbitrary HTML/JavaScript that executes in the browser of any user viewing an affected topic. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.
🎖@cveNotify
GitHub
SECURITY: Stored XSS via unescaped assignee name · discourse/discourse@46edb17
Escape user and group display names with `escapeExpression()` before interpolating into HTML strings wrapped in `trustHTML()`.
When `prioritize_full_name_in_ux` is enabled, `User.name` (which has ...
When `prioritize_full_name_in_ux` is enabled, `User.name` (which has ...
🚨 CVE-2026-32615
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, category group moderators could perform privileged actions on topics inside private categories they did not have read access to. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.
🎖@cveNotify
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, category group moderators could perform privileged actions on topics inside private categories they did not have read access to. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.
🎖@cveNotify
GitHub
SECURITY: Force regeneration for edit-outdated summaries and block st… · discourse/discourse@5a00b47
…ale fallback
Cached topic summaries that became outdated after post edits could remain visible longer than intended, and the 1-hour throttle could delay corrective regeneration. This update makes...
Cached topic summaries that became outdated after post edits could remain visible longer than intended, and the 1-hour throttle could delay corrective regeneration. This update makes...
🚨 CVE-2026-32618
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, there is possible channel membership inference from chat user search without authorization. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.
🎖@cveNotify
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, there is possible channel membership inference from chat user search without authorization. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.
🎖@cveNotify
GitHub
SECURITY: unauthorized channel membership inference · discourse/discourse@81fd89e
Adds guardian check to ensure that channel can be previewed before returning user search results.
---
**Security Advisory:** https://github.com/discourse/discourse/security/advisories/GHSA-pc8p-w...
---
**Security Advisory:** https://github.com/discourse/discourse/security/advisories/GHSA-pc8p-w...
🚨 CVE-2026-32619
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, users who lost access to a topic (e.g., removed from a private category group) could still interact with polls in that topic, including voting and toggling poll status. No content was exposed, but users could modify poll state in topics they should no longer have access to. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.
🎖@cveNotify
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, users who lost access to a topic (e.g., removed from a private category group) could still interact with polls in that topic, including voting and toggling poll status. No content was exposed, but users could modify poll state in topics they should no longer have access to. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.
🎖@cveNotify
GitHub
SECURITY: Check topic visibility before allowing poll interactions · discourse/discourse@d74ff25
## Summary
- Adds a `guardian.can_see_topic?` check in `DiscoursePoll::Poll` to prevent users from interacting with polls on topics they can no longer access
- Covers the case where a user loses g...
- Adds a `guardian.can_see_topic?` check in `DiscoursePoll::Poll` to prevent users from interacting with polls on topics they can no longer access
- Covers the case where a user loses g...
🚨 CVE-2026-32620
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, non-staff users could access read receipt information for staff-only posts they weren't supposed to see. No post content was exposed, only metadata about who read the post and when. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.
🎖@cveNotify
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, non-staff users could access read receipt information for staff-only posts they weren't supposed to see. No post content was exposed, only metadata about who read the post and when. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.
🎖@cveNotify
GitHub
SECURITY: Missing post-level authorization allows whisper metadata di… · discourse/discourse@bf8dbf6
…sclosure
## Summary
- Adds `guardian.ensure_can_see!` check in `PostReadersController#index` before returning reader data
- Prevents non-staff group members from accessing reader information for...
## Summary
- Adds `guardian.ensure_can_see!` check in `PostReadersController#index` before returning reader data
- Prevents non-staff group members from accessing reader information for...
🚨 CVE-2026-32725
SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior to version 1.4.1, scitokens-cpp is vulnerable to an authorization bypass when processing path-based scopes in tokens. The library normalizes the scope path from the token before authorization and collapses ".." path components instead of rejecting them. As a result, an attacker can use parent-directory traversal in the scope claim to broaden the effective authorization beyond the intended directory. This issue has been patched in version 1.4.1.
🎖@cveNotify
SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior to version 1.4.1, scitokens-cpp is vulnerable to an authorization bypass when processing path-based scopes in tokens. The library normalizes the scope path from the token before authorization and collapses ".." path components instead of rejecting them. As a result, an attacker can use parent-directory traversal in the scope claim to broaden the effective authorization beyond the intended directory. This issue has been patched in version 1.4.1.
🎖@cveNotify
GitHub
Implement path normalization and traversal protection in Enforcer · scitokens/scitokens-cpp@7951ed8
A C++ implementation of the SciTokens library with a C library interface - Implement path normalization and traversal protection in Enforcer · scitokens/scitokens-cpp@7951ed8
🚨 CVE-2026-32726
SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior to version 1.4.1, scitokens-cpp is vulnerable to an authorization bypass in path-based scope validation. The enforcer used a simple string-prefix comparison when checking whether a requested resource path was covered by a token's authorized scope path. Because the check did not require a path-segment boundary, a token scoped to one path could incorrectly authorize access to sibling paths that merely started with the same prefix. This issue has been patched in version 1.4.1.
🎖@cveNotify
SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior to version 1.4.1, scitokens-cpp is vulnerable to an authorization bypass in path-based scope validation. The enforcer used a simple string-prefix comparison when checking whether a requested resource path was covered by a token's authorized scope path. Because the check did not require a path-segment boundary, a token scoped to one path could incorrectly authorize access to sibling paths that merely started with the same prefix. This issue has been patched in version 1.4.1.
🎖@cveNotify
GitHub
Add path matching functions to enforce scope boundaries in Enforcer · scitokens/scitokens-cpp@decfe2f
A C++ implementation of the SciTokens library with a C library interface - Add path matching functions to enforce scope boundaries in Enforcer · scitokens/scitokens-cpp@decfe2f
🚨 CVE-2026-32951
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, an authenticated user can obtain shared draft topic titles by sending an inline onebox request with a category_id parameter matching the shared drafts category. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.
🎖@cveNotify
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, an authenticated user can obtain shared draft topic titles by sending an inline onebox request with a category_id parameter matching the shared drafts category. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.
🎖@cveNotify
GitHub
SECURITY: Check topic visibility in Oneboxer even when categories match · discourse/discourse@0b4e6ff
`Oneboxer.local_topic` skips the `can_see_topic?` check on the target topic when the request's `category_id` matchs the target's category. A user could bypass topic-level access con...
🚨 CVE-2026-33073
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, the discourse-subscriptions plugin leaks stripe API keys across sites in a multisite cluster resulting in the potential for stripe related information to be leaked across sites within the same multisite cluster. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.
🎖@cveNotify
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, the discourse-subscriptions plugin leaks stripe API keys across sites in a multisite cluster resulting in the potential for stripe related information to be leaked across sites within the same multisite cluster. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.
🎖@cveNotify
GitHub
SECURITY: Fixes for discourse-subscriptions · discourse/discourse@c34f2aa
This PR combines two security fixes for the discourse-subscriptions plugin.
## Commits
### 1. [`8f0a8e98e9`](https://github.com/discourse/discourse-private-mirror/commit/8f0a8e98e9) — SECURITY: F...
## Commits
### 1. [`8f0a8e98e9`](https://github.com/discourse/discourse-private-mirror/commit/8f0a8e98e9) — SECURITY: F...
🚨 CVE-2026-33074
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, a user may be able to purchase a lower tier subscription but grant themselves the benefits that comes along with a higher tier subscription. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.
🎖@cveNotify
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, a user may be able to purchase a lower tier subscription but grant themselves the benefits that comes along with a higher tier subscription. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.
🎖@cveNotify
GitHub
SECURITY: Fixes for discourse-subscriptions · discourse/discourse@c34f2aa
This PR combines two security fixes for the discourse-subscriptions plugin.
## Commits
### 1. [`8f0a8e98e9`](https://github.com/discourse/discourse-private-mirror/commit/8f0a8e98e9) — SECURITY: F...
## Commits
### 1. [`8f0a8e98e9`](https://github.com/discourse/discourse-private-mirror/commit/8f0a8e98e9) — SECURITY: F...
🚨 CVE-2026-33185
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, the group email settings test endpoint could be used to make the server initiate outbound connections to arbitrary hosts and ports. This could allow probing of internal network infrastructure. The endpoint was accessible to non-staff group owners. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.
🎖@cveNotify
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, the group email settings test endpoint could be used to make the server initiate outbound connections to arbitrary hosts and ports. This could allow probing of internal network infrastructure. The endpoint was accessible to non-staff group owners. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.
🎖@cveNotify
GitHub
SECURITY: Restrict group SMTP test to admins and block internal hosts · discourse/discourse@e75cf45
The `test_email_settings` endpoint in `GroupsController` allowed non-staff
group owners to make the server open outbound SMTP connections to arbitrary
`host:port` combinations, creating an SSRF pri...
group owners to make the server open outbound SMTP connections to arbitrary
`host:port` combinations, creating an SSRF pri...
🚨 CVE-2026-33300
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, an authorization bypass in the Category Chatables Controller show action allowed moderators to get information on hidden groups names and user count. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.
🎖@cveNotify
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, an authorization bypass in the Category Chatables Controller show action allowed moderators to get information on hidden groups names and user count. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.
🎖@cveNotify
GitHub
SECURITY: Respect group visibility in category chatables when accesse… · discourse/discourse@07f6665
…d by a moderator
**Description**
Hidden group names and member counts are exposed to moderators via the Chat category chatables permissions endpoint, bypassing Discourse's group visibilit...
**Description**
Hidden group names and member counts are exposed to moderators via the Chat category chatables permissions endpoint, bypassing Discourse's group visibilit...
🚨 CVE-2026-33415
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, an authenticated moderator-level user could retrieve post content, topic titles, and usernames from categories they were not authorized to view. Insufficient access controls on a sentiment analytics endpoint allowed category permission boundaries to be bypassed. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.
🎖@cveNotify
Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, an authenticated moderator-level user could retrieve post content, topic titles, and usernames from categories they were not authorized to view. Insufficient access controls on a sentiment analytics endpoint allowed category permission boundaries to be bypassed. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.
🎖@cveNotify
GitHub
SECURITY: Scope sentiment posts endpoint to allowed categories · discourse/discourse@e1bb146
Sentiment posts endpoint was not filtering by category permissions, allowing staff users to retrieve posts from categories they lack access to.
- Add `guardian.allowed_category_ids` filter to SQL ...
- Add `guardian.allowed_category_ids` filter to SQL ...
🚨 CVE-2026-5190
Out-of-bounds write in the streaming decoder component in aws-c-event-stream before 0.6.0 might allow a third party operating a server to cause memory corruption leading to arbitrary code execution on a client application that processes crafted event-stream messages.
To remediate this issue, users should upgrade to version 0.6.0 or later.
🎖@cveNotify
Out-of-bounds write in the streaming decoder component in aws-c-event-stream before 0.6.0 might allow a third party operating a server to cause memory corruption leading to arbitrary code execution on a client application that processes crafted event-stream messages.
To remediate this issue, users should upgrade to version 0.6.0 or later.
🎖@cveNotify