CVE Notify
19.6K subscribers
4 photos
315K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
๐Ÿšจ CVE-2026-17556
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to delete arbitrary files and directories on the instance, including the entire user storage directory containing Git LFS objects, release assets, attachments, and avatars. The X-GitHub-Request-Id request header was used without sanitization as a filesystem path segment for the upload buffer directory, so a traversal value pointed the buffer at an arbitrary path and the deferred cleanup routine recursively removed the traversed target. Exploitation required only network reachability to the instance and no authentication, and it worked even when private mode was enabled. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.21.4, 3.20.6, 3.19.10, 3.18.13 and 3.17.19. This vulnerability was reported via the GitHub Bug Bounty program.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-15996
A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause excessive CPU consumption and exhaust the pool of request-handling worker processes by sending a crafted form-encoded HTTP POST request containing deeply nested parameters. Because request parameters were parsed before routing and authentication, any POST endpoint could be used to trigger the condition, which could render the instance unresponsive. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.21 and was fixed in versions 3.20.3, 3.19.7, 3.18.10, and 3.17.16.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-18275
Authorization bypass in the process and annotation taxonomy serializers in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to run segmentation and transcription against other users' document parts, overwriting their content, via part primary keys supplied to a many=True related field whose queryset restriction was applied to the ManyRelatedField instead of its child_relation and therefore had no effect

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-18276
Missing authorization in the websocket consumer in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to subscribe to any document's event stream and observe another user's segmentation, transcription, import, export and training activity via the object_cls and object_pk values of a join-room message, which are passed to group_add without an access check

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-18277
Missing authorization in the OcrModelRight create and delete views in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to grant themselves access to another user's private OCR model and to revoke any user's OCR model access via a POST request, because the ownership check is placed in get_context_data() and therefore runs only on the GET rendering path

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-18359
Server-side request forgery in the METS and IIIF import URI handling in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to make the server issue arbitrary HTTP requests to internal hosts, including the cloud instance metadata service, via the mets_uri or iiif_uri parameter of POST /api/documents/{pk}/imports/, because the IMPORT_ALLOWED_DOMAINS setting defaults to '*' and no address filtering, redirect cap or timeout is applied

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-5423
@neo4j/graphql library versions prior to 7.5.6 fail to verify the authenticity of a client-supplied, pre-decoded JWT object passed through GraphQL subscription connectionParams. As a result, any unauthenticated remote client that can open a GraphQL-over-WebSocket connection can forge arbitrary JWT claims (e.g. sub, roles) in connectionParams.jwt and have them accepted as authenticated identity for the purposes of @authentication and @subscriptionsAuthorization directive evaluation. This allows a fully unauthenticated attacker to receive subscription events that should be restricted to specific authenticated roles/users.
Upgrade the library to versions 7.5.6+ or 5.12.14+. v6 is end-of-life and will not receive a fix.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-41861
Path Traversal in BOSH-Ecosystem / BOSH allows an IaaS-metadata attacker to make the agent write a root-owned file with partially attacker-controlled body to any path ending in .network, and create any missing parent directories with mode 0777 via network Alias on Ubuntu.



Affected versions: BOSH agent < v2.847.0 (jammy <= v1.1202, or noble <= v1.364). Lower bound unspecified in advisory ("All bosh agent versions").

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-9030
A denial-of-service
vulnerability exists in httpd service on Archer A6 v4 where the asynchronous systool
instruction handlng path in httpd does not properly synchronize or safely manage
concurrent systool operations. 





By sending
crafted systool instructions through the asynchronous request path, successful
exploitation may cause the httpd process or device management service to crash
and may result in temporary loss of access to the web management interface or
device reboot.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-9031
An input validation
vulnerability exists in the HTTP-WRITEOEM handler due to insufficient validation
of user-supplied data before it is processed by internal flash-write handling
logic.









Successful
exploitation may cause httpd process or device to crash, resulting in loss of access
to the web interface and a denial-of-service condition.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-21058
Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-21059
Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-21060
Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data across multiple user profiles.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-21061
Improper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM related functions. User interaction is required for triggering this vulnerability.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-21062
Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-21063
Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers to bypass app lock function.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-21064
Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device inoperability.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-21065
Out-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-21066
Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-21067
Improper input validation in libsmsd.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-21068
Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code.

๐ŸŽ–@cveNotify