π¨ CVE-2026-17572
Heap-based buffer overflow in the SOHM list-index deserialization code in HDF5 through 2.1.1 on all platforms allows attackers to cause a denial of service (crash) via a crafted HDF5 file whose shared-message list index declares a num_messages count exceeding list_max, triggering out-of-bounds heap reads and writes in H5SM__cache_list_deserialize and H5SM__cache_list_verify_chksum.
π@cveNotify
Heap-based buffer overflow in the SOHM list-index deserialization code in HDF5 through 2.1.1 on all platforms allows attackers to cause a denial of service (crash) via a crafted HDF5 file whose shared-message list index declares a num_messages count exceeding list_max, triggering out-of-bounds heap reads and writes in H5SM__cache_list_deserialize and H5SM__cache_list_verify_chksum.
π@cveNotify
GitHub
SOHM list message count exceeds list_max Β· Issue #6501 Β· HDFGroup/hdf5
When a shared object header message index is stored as a list, both H5SM__cache_list_verify_chksum() and H5SM__cache_list_deserialize() take the num_messages count straight from the on-disk index h...
π¨ CVE-2026-17573
A double free vulnerability was discovered in the HDF5 library. Processing a crafted HDF5 file containing an oversized chunk size field via h5repack may cause the application to abort due to a double free.
π@cveNotify
A double free vulnerability was discovered in the HDF5 library. Processing a crafted HDF5 file containing an oversized chunk size field via h5repack may cause the application to abort due to a double free.
π@cveNotify
GitHub
h5repack aborts due to double free when using -c with --enable-error-stack Β· Issue #6124 Β· HDFGroup/hdf5
Describe the bug Running h5repack with compression enabled using -c 10 and --enable-error-stack on a crafted HDF5 file causes the tool to abort due to a double free detected by the GNU C Library al...
π¨ CVE-2026-17574
HDF5 contains a NULL pointer dereference vulnerability. Processing a crafted HDF5 file containing an attribute with an invalid variable-length datatype type field may cause the application to crash when the attribute is read.
π@cveNotify
HDF5 contains a NULL pointer dereference vulnerability. Processing a crafted HDF5 file containing an attribute with an invalid variable-length datatype type field may cause the application to crash when the attribute is read.
π@cveNotify
GitHub
Validate VL datatype type during decode and check file pointer in H5T⦠· HDFGroup/hdf5@3fa6ed6
β¦_set_loc (#6395)
H5O__dtype_decode_helper() reads vlen.type from the file without
validation. With corrupted HDF5 files (e.g. from fuzzing), this field
can have an invalid value that is neither H...
H5O__dtype_decode_helper() reads vlen.type from the file without
validation. With corrupted HDF5 files (e.g. from fuzzing), this field
can have an invalid value that is neither H...
π¨ CVE-2026-42018
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
π@cveNotify
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
π@cveNotify
Release Information
Artifactory Self-Hosted Releases
This section contains the Release Notes for Artifactory Self-Hosted releases.
π¨ CVE-2026-14866
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to injection of rogue certificate authority due to publicly writeable truststore.
π@cveNotify
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to injection of rogue certificate authority due to publicly writeable truststore.
π@cveNotify
Ibm
Security Bulletin: IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities
IBM i Access Client Solutions (ACS) is vulnerable to multiple vulnerabilities [CVE-2026-13094, CVE-2026-13105, CVE-2026-13433, CVE-2026-14866, CVE-2026-14875, CVE-2026-16695] as described in the vulnerability details section.
π¨ CVE-2026-16480
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is affected by an improper authorization vulnerability in the certain command, allowing a non-privileged user to bypass authority checks and modify database catalog data.
π@cveNotify
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is affected by an improper authorization vulnerability in the certain command, allowing a non-privileged user to bypass authority checks and modify database catalog data.
π@cveNotify
π¨ CVE-2026-16695
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 could allow a local attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
π@cveNotify
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 could allow a local attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
π@cveNotify
Ibm
Security Bulletin: IBM i Access Client Solutions (ACS) is Affected By Multiple Vulnerabilities
IBM i Access Client Solutions (ACS) is vulnerable to multiple vulnerabilities [CVE-2026-13094, CVE-2026-13105, CVE-2026-13433, CVE-2026-14866, CVE-2026-14875, CVE-2026-16695] as described in the vulnerability details section.
π¨ CVE-2026-50769
The CRM+ application before and including version 2025.6 from Brainformatik is vulnerable to SQL Injection (time-based) vulnerability. The check conflict endpoint index.php?module=Appointments&action=CheckConflictOfDates&ajaxSkipHeader=true which is used to check any conflicts for user calendar is vulnerable to SQL injection allowing an attacker to execute arbitrary code.
π@cveNotify
The CRM+ application before and including version 2025.6 from Brainformatik is vulnerable to SQL Injection (time-based) vulnerability. The check conflict endpoint index.php?module=Appointments&action=CheckConflictOfDates&ajaxSkipHeader=true which is used to check any conflicts for user calendar is vulnerable to SQL injection allowing an attacker to execute arbitrary code.
π@cveNotify
GitHub
CVEs/CVE-2026-50769 at main Β· Henkel-CyberVM/CVEs
CVE reports created by Henkel AG & Co. KGaA's Cyber Defense team. - Henkel-CyberVM/CVEs
π¨ CVE-2026-50770
An issue in Squirro Cognitive Search before v.3.14.2 allows a remote attacker to escalate privileges via a crafted request.
π@cveNotify
An issue in Squirro Cognitive Search before v.3.14.2 allows a remote attacker to escalate privileges via a crafted request.
π@cveNotify
Squirro Documentation
Squirro Search
Introduction: Accessing the correct information quickly is increasingly difficult in a world filled with siloed data. End users canβt search all of their connected data sources easily, and their se...
π¨ CVE-2026-50772
An issue in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute arbitrary code via a crafted payload to the password reset function.
π@cveNotify
An issue in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute arbitrary code via a crafted payload to the password reset function.
π@cveNotify
Squirro Documentation
Squirro Search
Introduction: Accessing the correct information quickly is increasingly difficult in a world filled with siloed data. End users canβt search all of their connected data sources easily, and their se...
π¨ CVE-2026-50773
An issue in CGM Germany - CompuGroup Medical CGM ISIS MED 2510.1.0.20 allows a remote attacker to execute arbtirary code via a crafted .dll file.
π@cveNotify
An issue in CGM Germany - CompuGroup Medical CGM ISIS MED 2510.1.0.20 allows a remote attacker to execute arbtirary code via a crafted .dll file.
π@cveNotify
GitHub
CVEs/CVE-2026-50773 at main Β· Henkel-CyberVM/CVEs
CVE reports created by Henkel AG & Co. KGaA's Cyber Defense team. - Henkel-CyberVM/CVEs
π¨ CVE-2026-50774
An issue in GAPTEQ Designer v.3.5 allows a remote attacker to escalate privileges via the Company Manger role.
π@cveNotify
An issue in GAPTEQ Designer v.3.5 allows a remote attacker to escalate privileges via the Company Manger role.
π@cveNotify
Gapteq
GAPTEQ | The smart low-code platform with drag & drop - even for complex apps
The smart low-code platform for building web-based business applications. Without programming knowledge. With drag & drop. Even for complex applications.
π¨ CVE-2026-50775
A blind SSRF attack in DataHub v.1.5.0.1 allows a remote attacker to execute arbitrary code via the server retrieving an image from a crafted URL, and it fails to return the content or any errors directly.
π@cveNotify
A blind SSRF attack in DataHub v.1.5.0.1 allows a remote attacker to execute arbitrary code via the server retrieving an image from a crafted URL, and it fails to return the content or any errors directly.
π@cveNotify
DataHub
DataHub | AI & Data Context Management Platform
DataHub is the leading open-source data catalog helping teams discover, understand, and govern their data assets. Unlock data intelligence today.
π¨ CVE-2026-50776
Directory Traversal vulnerability in Pronis Loisirs Billetterie CSE - < 04/2026 allows a remote attacker to obtain sensitive information and execute arbitrary code.
π@cveNotify
Directory Traversal vulnerability in Pronis Loisirs Billetterie CSE - < 04/2026 allows a remote attacker to obtain sensitive information and execute arbitrary code.
π@cveNotify
GitHub
CVEs/CVE-2026-50776 at main Β· Henkel-CyberVM/CVEs
CVE reports created by Henkel AG & Co. KGaA's Cyber Defense team. - Henkel-CyberVM/CVEs
π¨ CVE-2026-68004
An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 allows a remote attacker to execute arbitrary code via RTMP publish authorization, vhost-level security configuration (security.enabled), SrsSecurity::check(), trunk/src/app/srs_app_security.cpp, and SRS RTMP listener components
π@cveNotify
An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 allows a remote attacker to execute arbitrary code via RTMP publish authorization, vhost-level security configuration (security.enabled), SrsSecurity::check(), trunk/src/app/srs_app_security.cpp, and SRS RTMP listener components
π@cveNotify
GitHub
Release Release v5.0-r3 Β· ossrs/srs
313913737f13f97d9816dbc3d729e7bcd454a531
RTC: Support dropping h.264 SEI from NALUs. v5.0.213 (#4057)
CHANGELOG
v5.0, 2024-06-03, Merge #4057: RTC: Support dropping h.264 SEI from NALUs. v5.0.213 ...
RTC: Support dropping h.264 SEI from NALUs. v5.0.213 (#4057)
CHANGELOG
v5.0, 2024-06-03, Merge #4057: RTC: Support dropping h.264 SEI from NALUs. v5.0.213 ...
π¨ CVE-2026-34789
FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, src/App/PropertyPythonObject.cpp in PropertyPythonObject::Restore() passes the attacker-controlled module attribute from serialized PropertyPythonObject XML directly to PyImport_ImportModule() while restoring a crafted FCStd document, which executes module-level Python code, and the legacy pickle branch also imports an attacker-controlled module and invokes its class constructor through PyObject_CallObject(). This issue is fixed in version 1.1.2.
π@cveNotify
FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, src/App/PropertyPythonObject.cpp in PropertyPythonObject::Restore() passes the attacker-controlled module attribute from serialized PropertyPythonObject XML directly to PyImport_ImportModule() while restoring a crafted FCStd document, which executes module-level Python code, and the legacy pickle branch also imports an attacker-controlled module and invokes its class constructor through PyObject_CallObject(). This issue is fixed in version 1.1.2.
π@cveNotify
GitHub
Security: validate module imports in Restore() Β· FreeCAD/FreeCAD@81b7392
Multi-stage validation of module imports when loading an FCStd file:
1) Has the module already been loaded? If so, it's OK
2) Is the module located in a known location? (e.g. Mod, Ext, etc....
1) Has the module already been loaded? If so, it's OK
2) Is the module located in a known location? (e.g. Mod, Ext, etc....
π¨ CVE-2026-44845
JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.10.17, an authenticated administrator with Applet Host management and deployment permissions can inject Jinja2 expressions into the IP/Host field or Core Service Address field, causing Ansible to evaluate ansible_host inventory data or playbook variables during Applet Host deployment and execute arbitrary commands on the JumpServer control node. This issue is fixed in version 4.10.17.
π@cveNotify
JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.10.17, an authenticated administrator with Applet Host management and deployment permissions can inject Jinja2 expressions into the IP/Host field or Core Service Address field, causing Ansible to evaluate ansible_host inventory data or playbook variables during Applet Host deployment and execute arbitrary commands on the JumpServer control node. This issue is fixed in version 4.10.17.
π@cveNotify
GitHub
fix:add ansible patchs to osm (#16886) Β· jumpserver/jumpserver@cc57ba0
* fix:add ansible patchs to osm
* fix: quote ansible gateway proxy command args
---------
Co-authored-by: Crane.z <1481445951@qq.com>
* fix: quote ansible gateway proxy command args
---------
Co-authored-by: Crane.z <1481445951@qq.com>
π¨ CVE-2026-47698
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, lib/bridge.js and lib/setup-sandbox.js fail to block stacked indirection through Function.prototype.call around dangerous host prototype getter and setter mutators, allowing sandbox code to sever a host intrinsic's prototype chain and reach e.constructor.constructor for arbitrary host command execution. This issue is fixed in version 3.11.6.
π@cveNotify
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, lib/bridge.js and lib/setup-sandbox.js fail to block stacked indirection through Function.prototype.call around dangerous host prototype getter and setter mutators, allowing sandbox code to sever a host intrinsic's prototype chain and reach e.constructor.constructor for arbitrary host command execution. This issue is fixed in version 3.11.6.
π@cveNotify
GitHub
fix(GHSA-cfcw-xp6x-25gj): refuse host prototype mutators and severed β¦ Β· patriksimek/vm2@a85acb6
β¦host values at the bridge
Root cause: the GHSA-v6mx-mf47-r5wg apply-trap defense peeled exactly one
layer of Function.prototype.{call,apply,bind} / Reflect.{apply,construct}
indirection. Stacking...
Root cause: the GHSA-v6mx-mf47-r5wg apply-trap defense peeled exactly one
layer of Function.prototype.{call,apply,bind} / Reflect.{apply,construct}
indirection. Stacking...
π¨ CVE-2026-43667
A reachable assertion was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. An attacker in a privileged network position may be able to cause a denial-of-service.
π@cveNotify
A reachable assertion was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. An attacker in a privileged network position may be able to cause a denial-of-service.
π@cveNotify
Apple Support
About the security content of iOS 18.7.10 and iPadOS 18.7.10 - Apple Support
This update delivers security fixes that were first made available in the iOS 26.6 and 27 and iPadOS 26.6 and 27 betas. This document describes the security content of iOS 18.7.10 and iPadOS 18.7.10.
π¨ CVE-2026-43794
A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to memory corruption.
π@cveNotify
A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to memory corruption.
π@cveNotify
Apple Support
About the security content of macOS Tahoe 26.6.2 - Apple Support
This update delivers security fixes that were first made available in the macOS Golden Gate 27 beta. This document describes the security content of macOS Tahoe 26.6.2.
π¨ CVE-2026-43795
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.
π@cveNotify
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.
π@cveNotify
Apple Support
About the security content of macOS Tahoe 26.6.2 - Apple Support
This update delivers security fixes that were first made available in the macOS Golden Gate 27 beta. This document describes the security content of macOS Tahoe 26.6.2.