🚨 CVE-2026-48702
Rekor is a software supply chain transparency log. Starting in version 0.3.0 and prior to version 1.5.2, the `Package.Unmarshal()` function in `pkg/types/alpine/apk.go` decompresses the signature and control gzip members of an APK file into in-memory buffers without bounding the total decompressed size. The existing `max_apk_metadata_size` check (default 1MB) is only applied to individual tar entry header sizes after decompression completes, so it does not prevent a decompression bomb from consuming unbounded heap memory. An attacker can craft a gzip stream that compresses at a ~1000:1 ratio (e.g., 2MB compressed zeros → 2GB decompressed). When submitted as spec.package.content in an Alpine `ProposedEntry`, the server decompresses the full payload into memory during request processing, triggering a fatal Go runtime out-of-memory error or OS OOM-kill that cannot be caught by the server's recover() middleware. This is reachable via two unauthenticated endpoints, `POST /api/v1/log/entries (createLogEntry)` and `POST /api/v1/log/entries/retrieve (searchLogQuery)`. Both invoke `V001Entry.Canonicalize()` → `fetchExternalEntities()` → `apk.Unmarshal(packageData)`, which performs the unbounded decompression. Version 1.5.2 patches the issue. There is no effective workaround. Setting `max_request_body_size` reduces but does not eliminate exposure due to the ~1000:1 compression ratio (a 1MB body limit still allows ~1GB heap allocation). Setting `max_apk_metadata_size` has no effect on this vulnerability since the check is applied after decompression.
🎖@cveNotify
Rekor is a software supply chain transparency log. Starting in version 0.3.0 and prior to version 1.5.2, the `Package.Unmarshal()` function in `pkg/types/alpine/apk.go` decompresses the signature and control gzip members of an APK file into in-memory buffers without bounding the total decompressed size. The existing `max_apk_metadata_size` check (default 1MB) is only applied to individual tar entry header sizes after decompression completes, so it does not prevent a decompression bomb from consuming unbounded heap memory. An attacker can craft a gzip stream that compresses at a ~1000:1 ratio (e.g., 2MB compressed zeros → 2GB decompressed). When submitted as spec.package.content in an Alpine `ProposedEntry`, the server decompresses the full payload into memory during request processing, triggering a fatal Go runtime out-of-memory error or OS OOM-kill that cannot be caught by the server's recover() middleware. This is reachable via two unauthenticated endpoints, `POST /api/v1/log/entries (createLogEntry)` and `POST /api/v1/log/entries/retrieve (searchLogQuery)`. Both invoke `V001Entry.Canonicalize()` → `fetchExternalEntities()` → `apk.Unmarshal(packageData)`, which performs the unbounded decompression. Version 1.5.2 patches the issue. There is no effective workaround. Setting `max_request_body_size` reduces but does not eliminate exposure due to the ~1000:1 compression ratio (a 1MB body limit still allows ~1GB heap allocation). Setting `max_apk_metadata_size` has no effect on this vulnerability since the check is applied after decompression.
🎖@cveNotify
GitHub
OOM condition due to Unbounded gzip decompression in Alpine APK parsing
## Description
The `Package.Unmarshal()` function in `pkg/types/alpine/apk.go` decompresses the signature and control gzip members of an APK file into in-memory buffers without bounding the tota...
The `Package.Unmarshal()` function in `pkg/types/alpine/apk.go` decompresses the signature and control gzip members of an APK file into in-memory buffers without bounding the tota...
🚨 CVE-2026-61960
Unauthenticated Cross Site Scripting (XSS) in WP Full Stripe Free <= 8.5.0 versions.
🎖@cveNotify
Unauthenticated Cross Site Scripting (XSS) in WP Full Stripe Free <= 8.5.0 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress WP Full Stripe Free Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-61962
Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions.
🎖@cveNotify
Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions.
🎖@cveNotify
Patchstack
Arbitrary Code Execution in WordPress WP BASE Booking Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-61965
Unauthenticated Cross Site Scripting (XSS) in GeekyBot <= 1.2.6 versions.
🎖@cveNotify
Unauthenticated Cross Site Scripting (XSS) in GeekyBot <= 1.2.6 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress GeekyBot Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-61974
Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.3.4 versions.
🎖@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.3.4 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Mang Board WP Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-61978
Unauthenticated Broken Access Control in Secure Card Gateway for ePay Paycenter (Piraeus Bank) <= 1.0.32 versions.
🎖@cveNotify
Unauthenticated Broken Access Control in Secure Card Gateway for ePay Paycenter (Piraeus Bank) <= 1.0.32 versions.
🎖@cveNotify
Patchstack
Broken Access Control in WordPress Secure Card Gateway for ePay Paycenter (Piraeus Bank) Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-61979
Unauthenticated Privilege Escalation in SAML SP Single Sign On <= 5.4.3 versions.
🎖@cveNotify
Unauthenticated Privilege Escalation in SAML SP Single Sign On <= 5.4.3 versions.
🎖@cveNotify
Patchstack
Privilege Escalation in WordPress SAML SP Single Sign On Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-66424
Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions.
🎖@cveNotify
Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions.
🎖@cveNotify
Patchstack
Privilege Escalation in WordPress SMS Alert Order Notifications Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-66429
Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.10 versions.
🎖@cveNotify
Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.10 versions.
🎖@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress Visitor Traffic Real Time Statistics Pro Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-66430
Subscriber SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.10 versions.
🎖@cveNotify
Subscriber SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.10 versions.
🎖@cveNotify
Patchstack
SQL Injection in WordPress Visitor Traffic Real Time Statistics Pro Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-66431
Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) <= 1.0.7 versions.
🎖@cveNotify
Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) <= 1.0.7 versions.
🎖@cveNotify
Patchstack
Broken Access Control in WordPress Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-66436
Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions.
🎖@cveNotify
Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions.
🎖@cveNotify
Patchstack
SQL Injection in WordPress Active Products Tables for WooCommerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
🚨 CVE-2026-66441
Unauthenticated Broken Access Control in MultiVendorX <= 5.0.10 versions.
🎖@cveNotify
Unauthenticated Broken Access Control in MultiVendorX <= 5.0.10 versions.
🎖@cveNotify
Patchstack
Broken Access Control in WordPress MultiVendorX Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.