🚨 CVE-2026-76890
Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
sharkd: use-after-return via dangling stack-array iograph tap listeners on error path (ANT-2026-GACTPNVK) (#21399) · Issues · Wireshark…
I am writing to report stack-use-after-return in tshark sharkd This is a security issue that was found by Anthropic using Claude to find...
🚨 CVE-2026-76891
Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
sharkd: use-after-return via dangling stack-object rtp-streams tap listener on error path (ANT-2026-27KVBTTP) (#21395) · Issues…
I am writing to report stack-use-after-return in tshark sharkd This is a security issue that was found by Anthropic using Claude to find...
🚨 CVE-2026-76917
Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
AVRCP Vendor-Dependent Fragment Reassembly — uint32_t Integer Overflow → Heap Buffer Overflow (#21488) · Issues · Wireshark Foundation…
AVRCP Vendor-Dependent Fragment Reassembly — uint32_t Integer Overflow → Heap Buffer Overflow 1. Executive Summary
🚨 CVE-2026-76918
SSH protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
SSH protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
SSH dissector: heap buffer overflow in curve25519 key exchange (#21465) · Issues · Wireshark Foundation / Wireshark · GitLab
Affected: master, release-4.6, release-4.4. Introduced in 3.4.0 (2020-10-29) with SSH decryption support; unfixed on every branch as of 2026-08-02. Impact: heap out-of-bounds write of...
🚨 CVE-2026-76919
ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
Malformed ESS BIT STRING can use uninitialized TVB pointer in attribute-flag dissection (#21467) · Issues · Wireshark Foundation…
From AISLE Security: Summary A malformed BER BIT STRING in an ESS security-category attribute can make...
🚨 CVE-2026-76920
3gpp phone log file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
3gpp phone log file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
3GPP log decoder can write one byte past packet buffer (#21454) · Issues · Wireshark Foundation / Wireshark · GitLab
From Aisle Security: [Security] 3GPP log decoder writes one byte past packet buffer
🚨 CVE-2026-76921
CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
CMS RC2 parameter decoding reuses freed capability-tree pointer (#21457) · Issues · Wireshark Foundation / Wireshark · GitLab
From AISLE Security: [Security] CMS RC2 parameter decoding reuses freed capability-tree pointer
🚨 CVE-2026-76923
Bluetooth HFP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
Bluetooth HFP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
Short +XAPL accessory parameter causes heap out-of-bounds read (#21451) · Issues · Wireshark Foundation / Wireshark · GitLab
From AISLE Security: [Security] Short +XAPL accessory parameter causes heap out-of-bounds read
🚨 CVE-2026-76924
Kerberos protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
Kerberos protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
Kerberos learned-key formatting reads past short EncryptionKey (#21449) · Issues · Wireshark Foundation / Wireshark · GitLab
From AISLE Security: [Security] Kerberos learned-key formatting reads past short EncryptionKey
🚨 CVE-2026-76926
BUSMASTER file parser abnormal exit in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
BUSMASTER file parser abnormal exit in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
Malformed BUSMASTER header terminates the host process (#21435) · Issues · Wireshark Foundation / Wireshark · GitLab
From AISLE Security: [Security] Malformed BUSMASTER header terminates the host process
🚨 CVE-2026-76927
H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
H.245 returnedFunction nested GenericMessage dereferences NULL packet state (#21447) · Issues · Wireshark Foundation / Wireshark…
From AISLE Security: [Security] H.245 returnedFunction nested GenericMessage dereferences NULL packet state
🚨 CVE-2026-76928
X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
Nested DistinguishedName corrupts X.509IF DN/RDN formatting state (#21469) · Issues · Wireshark Foundation / Wireshark · GitLab
From AISLE Security: [Security] Nested DistinguishedName corrupts X.509IF DN/RDN formatting state
🚨 CVE-2026-76929
Pcapng file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
Pcapng file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
Out-of-bounds read in Netflix pcapng TCPINFO option parsing (#21460) · Issues · Wireshark Foundation / Wireshark · GitLab
[Security] Out-of-bounds read in Netflix pcapng TCPINFO option parsing
🚨 CVE-2025-23367
A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control management operations is secured using the Role Based Access Control provider, a user without the required privileges can suspend or resume the server. A user with a Monitor or Auditor role is supposed to have only read access permissions and should not be able to suspend the server.
The vulnerability is caused by the Suspend and Resume handlers not performing authorization checks to validate whether the current user has the required permissions to proceed with the action.
🎖@cveNotify
A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control management operations is secured using the Role Based Access Control provider, a user without the required privileges can suspend or resume the server. A user with a Monitor or Auditor role is supposed to have only read access permissions and should not be able to suspend the server.
The vulnerability is caused by the Suspend and Resume handlers not performing authorization checks to validate whether the current user has the required permissions to proceed with the action.
🎖@cveNotify
🚨 CVE-2022-4996
A flaw has been found in mruby 3.1.0. Affected is the function udiv of the file bigint.c. Executing a manipulation can lead to floating point comparison with incorrect operator. It is possible to launch the attack remotely. The exploit has been published and may be used. It is best practice to apply a patch to resolve this issue.
🎖@cveNotify
A flaw has been found in mruby 3.1.0. Affected is the function udiv of the file bigint.c. Executing a manipulation can lead to floating point comparison with incorrect operator. It is possible to launch the attack remotely. The exploit has been published and may be used. It is best practice to apply a patch to resolve this issue.
🎖@cveNotify
🚨 CVE-2026-76762
A vulnerability was detected in code-projects Assessment Management 1.0. The affected element is an unknown function of the file /welcome.php. The manipulation of the argument userid results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.
🎖@cveNotify
A vulnerability was detected in code-projects Assessment Management 1.0. The affected element is an unknown function of the file /welcome.php. The manipulation of the argument userid results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.
🎖@cveNotify
🚨 CVE-2026-76764
A flaw has been found in code-projects Employee Management System 1.0. The impacted element is an unknown function of the file /process/aprocess.php of the component Admin Login Endpoint. This manipulation of the argument mailuid causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used.
🎖@cveNotify
A flaw has been found in code-projects Employee Management System 1.0. The impacted element is an unknown function of the file /process/aprocess.php of the component Admin Login Endpoint. This manipulation of the argument mailuid causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used.
🎖@cveNotify
🚨 CVE-2026-8619
An
unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.0 and Archer MR600 v2, due to improper handling of exceptional request conditions
that may lead to a NULL pointer dereference.
A remote attacker on an adjacent network can send a specially crated
HTTP request to trigger a crash of the HTTP service process.
Successful
exploitation may cause the HTTP service to crash, making the web management
interface and HTTP-dependent functionality temporarily unavailable.
🎖@cveNotify
An
unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.0 and Archer MR600 v2, due to improper handling of exceptional request conditions
that may lead to a NULL pointer dereference.
A remote attacker on an adjacent network can send a specially crated
HTTP request to trigger a crash of the HTTP service process.
Successful
exploitation may cause the HTTP service to crash, making the web management
interface and HTTP-dependent functionality temporarily unavailable.
🎖@cveNotify
🚨 CVE-2026-42510
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface.
🎖@cveNotify
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface.
🎖@cveNotify
Launchpad
Bug #2148331 “Possible command injection in both console impleme...” : Bugs : Ironic
Tuomo Tanskanen (Ericsson Software Technology) and Dmitry Tantsur (Red Hat) from the Metal3.io security team have discovered a potential issue in Ironic using an AI-based security analysis tool. Here is the generated report followed by a review by the submitter.…
🚨 CVE-2026-9689
A flaw was found in Keycloak, an open-source identity and access management solution. When a client application is configured to accept broad redirect Uniform Resource Identifiers (URIs), a remote attacker can manipulate the authentication process by crafting a special web address. If a user clicks this link, the client application might incorrectly prioritize attacker-controlled information over legitimate data. This vulnerability, known as HTTP parameter pollution, could allow an attacker to bypass security measures or gain unauthorized access to resources.
🎖@cveNotify
A flaw was found in Keycloak, an open-source identity and access management solution. When a client application is configured to accept broad redirect Uniform Resource Identifiers (URIs), a remote attacker can manipulate the authentication process by crafting a special web address. If a user clicks this link, the client application might incorrectly prioritize attacker-controlled information over legitimate data. This vulnerability, known as HTTP parameter pollution, could allow an attacker to bypass security measures or gain unauthorized access to resources.
🎖@cveNotify
🚨 CVE-2026-9793
A flaw was found in Keycloak. When a JSON Web Encryption (JWE) encrypted request object is submitted, Keycloak may incorrectly process unsigned claims if the decrypted content is raw JSON, bypassing the configured signature policy. This allows a remote attacker to submit unauthorized claims, leading to a compromise of data integrity within the OpenID Connect (OIDC) authorization flow. While a redirect URI allowlist acts as a compensating control, this vulnerability violates OIDC Core and Financial-grade API (FAPI) signing requirements.
🎖@cveNotify
A flaw was found in Keycloak. When a JSON Web Encryption (JWE) encrypted request object is submitted, Keycloak may incorrectly process unsigned claims if the decrypted content is raw JSON, bypassing the configured signature policy. This allows a remote attacker to submit unauthorized claims, leading to a compromise of data integrity within the OpenID Connect (OIDC) authorization flow. While a redirect URI allowlist acts as a compensating control, this vulnerability violates OIDC Core and Financial-grade API (FAPI) signing requirements.
🎖@cveNotify