🚨 CVE-2026-18751
External control of file name or path vulnerability in Citrix WorkSpace App on MacOS.
This issue affects WorkSpace App: 2607.
🎖@cveNotify
External control of file name or path vulnerability in Citrix WorkSpace App on MacOS.
This issue affects WorkSpace App: 2607.
🎖@cveNotify
🚨 CVE-2026-17106
The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine filesystem operations to the destination directory. The extractor decides where each archive entry lands using lexical string checks and then performs the filesystem operation on a path that is resolved by the OS, so links introduced by the archive can be followed out of the destination directory. An attacker who controls the contents of an archive can create or overwrite files at arbitrary paths writable by the extracting process.
🎖@cveNotify
The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine filesystem operations to the destination directory. The extractor decides where each archive entry lands using lexical string checks and then performs the filesystem operation on a path that is resolved by the OS, so links introduced by the archive can be followed out of the destination directory. An attacker who controls the contents of an archive can create or overwrite files at arbitrary paths writable by the extracting process.
🎖@cveNotify
Docker Documentation
Docker Desktop release notes
Find the Docker Desktop release notes for Mac, Linux, and Windows.
🚨 CVE-2026-65609
nnn is vulnerable to Out-of-Bound write vulnerability. Due to lack of validation of attacker-controlled length fields deserialized from a session file, a crafted session file can cause nnn to write data beyond the bounds of fixed-size global buffers when loaded with the -s option. An attacker who can place a malicious session file in the victim's nnn session directory can exploit this to corrupt adjacent global state.
Maintainer of this project was notified about this vulnerability. It might has been addressed, but the maintainer did not provide a vulnerable version range. Only version 5.2 was tested and confirmed as vulnerable.
🎖@cveNotify
nnn is vulnerable to Out-of-Bound write vulnerability. Due to lack of validation of attacker-controlled length fields deserialized from a session file, a crafted session file can cause nnn to write data beyond the bounds of fixed-size global buffers when loaded with the -s option. An attacker who can place a malicious session file in the victim's nnn session directory can exploit this to corrupt adjacent global state.
Maintainer of this project was notified about this vulnerability. It might has been addressed, but the maintainer did not provide a vulnerable version range. Only version 5.2 was tested and confirmed as vulnerable.
🎖@cveNotify
cert.pl
Vulnerabilities in nnn software
CERT Polska has received a report about 4 vulnerabilities (from CVE-2026-65609 to CVE-2026-65612) found in nnn software.
🚨 CVE-2026-65610
nnn stores homelen variable as uchar_t, which can only represent values in the range 0-255. An attacker who can influence the victim's execution environment can provide an arbitrary HOME path with length that is truncated to 0. The expression (homelen - 1) is promoted to signed int and becomes -1 and producing an out-of-bounds read and an out-of-bounds write one byte before the path buffer.
Maintainer of this project was notified about this vulnerability. It might has been addressed, but the maintainer did not provide a vulnerable version range. Only version 5.2 was tested and confirmed as vulnerable.
🎖@cveNotify
nnn stores homelen variable as uchar_t, which can only represent values in the range 0-255. An attacker who can influence the victim's execution environment can provide an arbitrary HOME path with length that is truncated to 0. The expression (homelen - 1) is promoted to signed int and becomes -1 and producing an out-of-bounds read and an out-of-bounds write one byte before the path buffer.
Maintainer of this project was notified about this vulnerability. It might has been addressed, but the maintainer did not provide a vulnerable version range. Only version 5.2 was tested and confirmed as vulnerable.
🎖@cveNotify
cert.pl
Vulnerabilities in nnn software
CERT Polska has received a report about 4 vulnerabilities (from CVE-2026-65609 to CVE-2026-65612) found in nnn software.
🚨 CVE-2026-65611
nnn does not sanitize the path variable. An attacker can create a directory on a shared filesystem, removable media, or inside an extracted archive whose name contains a single quote followed by shell syntax. If the victim enters that directory in nnn and uses the batch copy or move workflow, the crafted directory name is embedded into the generated shell command and the injected payload executes with the privileges of the nnn process.
Maintainer of this project was notified about this vulnerability. It might has been addressed, but the maintainer did not provide a vulnerable version range. Only version 5.2 was tested and confirmed as vulnerable.
🎖@cveNotify
nnn does not sanitize the path variable. An attacker can create a directory on a shared filesystem, removable media, or inside an extracted archive whose name contains a single quote followed by shell syntax. If the victim enters that directory in nnn and uses the batch copy or move workflow, the crafted directory name is embedded into the generated shell command and the injected payload executes with the privileges of the nnn process.
Maintainer of this project was notified about this vulnerability. It might has been addressed, but the maintainer did not provide a vulnerable version range. Only version 5.2 was tested and confirmed as vulnerable.
🎖@cveNotify
cert.pl
Vulnerabilities in nnn software
CERT Polska has received a report about 4 vulnerabilities (from CVE-2026-65609 to CVE-2026-65612) found in nnn software.
🚨 CVE-2026-65612
nnn does not sanitize the filename variable. An attacker can place a file with a crafted name on a shared filesystem, removable media, or inside an extracted archive whose name contains a single quote followed by shell syntax. If the victim navigates
to that file and opens it with preview-tabbed, the filename is embedded into the generated shell command and the injected payload executes with the privileges of the nnn process.
Maintainer of this project was notified about this vulnerability. It might has been addressed, but the maintainer did not provide a vulnerable version range. Only version 5.2 was tested and confirmed as vulnerable.
🎖@cveNotify
nnn does not sanitize the filename variable. An attacker can place a file with a crafted name on a shared filesystem, removable media, or inside an extracted archive whose name contains a single quote followed by shell syntax. If the victim navigates
to that file and opens it with preview-tabbed, the filename is embedded into the generated shell command and the injected payload executes with the privileges of the nnn process.
Maintainer of this project was notified about this vulnerability. It might has been addressed, but the maintainer did not provide a vulnerable version range. Only version 5.2 was tested and confirmed as vulnerable.
🎖@cveNotify
cert.pl
Vulnerabilities in nnn software
CERT Polska has received a report about 4 vulnerabilities (from CVE-2026-65609 to CVE-2026-65612) found in nnn software.
🚨 CVE-2026-18526
HumHub Community Edition 1.18.4 and 1.18.4-pl1 contain a stored Cross-Site Scripting (XSS) vulnerability in the oEmbed confirmation rendering workflow.
🎖@cveNotify
HumHub Community Edition 1.18.4 and 1.18.4-pl1 contain a stored Cross-Site Scripting (XSS) vulnerability in the oEmbed confirmation rendering workflow.
🎖@cveNotify
Fluidattacks
HumHub 1.18.4 / 1.18.4-pl1 – Stored Cross-Site Scripting in oEmbed confirmation | Fluid Attacks
AppSec solution that integrates AI, automated tools, and pentesters to help you prevent, detect, manage, and fix vulnerabilities continuously across your SDLC.
🚨 CVE-2026-18756
HumHub Community Edition 1.18.4 contains a reflected cross-site scripting vulnerability in the Space membership-request workflow. An attacker can place attacker-controlled button configuration in the options query-string parameter of space/membership/request-membership-form, lure an authenticated non-member into submitting the legitimate membership request form, and cause the server to return JavaScript containing attacker-controlled code.
🎖@cveNotify
HumHub Community Edition 1.18.4 contains a reflected cross-site scripting vulnerability in the Space membership-request workflow. An attacker can place attacker-controlled button configuration in the options query-string parameter of space/membership/request-membership-form, lure an authenticated non-member into submitting the legitimate membership request form, and cause the server to return JavaScript containing attacker-controlled code.
🎖@cveNotify
Fluidattacks
HumHub Community Edition 1.18.4-pl1 - Reflected XSS in Space membership request button rendering | Fluid Attacks
AppSec solution that integrates AI, automated tools, and pentesters to help you prevent, detect, manage, and fix vulnerabilities continuously across your SDLC.
🚨 CVE-2026-18430
HumHub 1.18.4 contains a stored cross-site scripting vulnerability in the comment-deletion notification flow. A Space administrator can delete another user's comment, choose to notify the original author, and place HTML/JavaScript in the deletion reason.
🎖@cveNotify
HumHub 1.18.4 contains a stored cross-site scripting vulnerability in the comment-deletion notification flow. A Space administrator can delete another user's comment, choose to notify the original author, and place HTML/JavaScript in the deletion reason.
🎖@cveNotify
Fluidattacks
HumHub 1.18.4 - Stored XSS in comment-deletion notifications through unescaped administrator reason | Fluid Attacks
CVE-2026-18430: HumHub 1.18.4 contains a stored cross-site scripting vulnerability in the comment-deletion notification flow. A Space administrator can delete another user's comment, choose to notify the original author, and place HTML/JavaScript in the deletion…
🚨 CVE-2026-19198
Akaunting 3.1.21 contains an authenticated improper authorization vulnerability in the common BulkActions dispatcher.This issue affects Akaunting: 3.1.21.
🎖@cveNotify
Akaunting 3.1.21 contains an authenticated improper authorization vulnerability in the common BulkActions dispatcher.This issue affects Akaunting: 3.1.21.
🎖@cveNotify
Fluidattacks
Akaunting 3.1.21 - Improper authorization in BulkActions handle dispatch | Fluid Attacks
CVE-2026-19198: Akaunting 3.1.21 contains an authenticated improper authorization vulnerability in the common BulkActions dispatcher.
🚨 CVE-2026-76880
RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
Fix potential heap corruption in UMTS RRC (#21478) · Issues · Wireshark Foundation / Wireshark · GitLab
A protocol-valid, packet-controlled RB-Identity value in the UMTS RRC dissector is stored in RRC private state and later used directly as an index into rrc_ciphering_info.seq_no, whose...
🚨 CVE-2026-76881
CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
CMS MessageDigest verification dereferences missing algorithm (#21446) · Issues · Wireshark Foundation / Wireshark · GitLab
From AISLE Research: [Security] CMS MessageDigest verification dereferences missing algorithm
🚨 CVE-2026-76882
Bluetooth Attribute Protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
Bluetooth Attribute Protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
Heap OOB read in packet-btatt.c:11504 (#21424) · Issues · Wireshark Foundation / Wireshark · GitLab
Summary Heap out-of-bounds read in the Bluetooth ATT dissector when handling Read Multiple Variable Response (opcode 0x21). The...
🚨 CVE-2026-76883
Catapult DCT2000 file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
Catapult DCT2000 file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
Heap OOB write in wiretap/catapult_dct2000.c:1382 - off-by-one in DCT2000 file reader (#21427) · Issues · Wireshark Foundation…
Summary Heap out-of-bounds write in the Catapult DCT2000 wiretap file reader at catapult_dct2000.c:1382. floor(data_chars/2) bytes are allocated but...
🚨 CVE-2026-76884
ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
Short ERF provenance gen_time tag causes an eight-byte heap out-of-bounds read (#21415) · Issues · Wireshark Foundation / Wireshark…
Summary The ERF metadata parser copies an eight-byte gen_time value without checking that the tag contains eight value...
🚨 CVE-2026-76885
Tektronix K12xx file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
Tektronix K12xx file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
Tektronix K12 .rf5 blob handling causes a heap out-of-bounds read (#21414) · Issues · Wireshark Foundation / Wireshark · GitLab
Summary The Tektronix K12 .rf5 reader can pass a length larger than its record buffer to process_packet_data().
🚨 CVE-2026-76886
C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
EAX CMAC 16-bit length truncation can overflow heap on large C12.22 cleartext-auth payloads (#21439) · Issues · Wireshark Foundation…
From AISLE Security: [Security] EAX CMAC 16-bit length truncation can overflow heap on large C12.22 cleartext-auth payloads
🚨 CVE-2026-76887
Crash in the Wireshark dissection engine in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
Crash in the Wireshark dissection engine in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
Wireshark reassembly memory-safety report (#21423) · Issues · Wireshark Foundation / Wireshark · GitLab
Daniel Birtwhistle reported the following: Case: WS-REASM-WRAP-01 Audience: Wireshark security team Hello Wireshark Security Team, My name is Daniel Birtwhistle....
🚨 CVE-2026-76888
RDP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
RDP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
RDP8/ZGFX decompressor: off-by-one heap overflow in zgfx_write_literal() (outputSegment[65536]) (ANT-2026-05VXN1Y6) (#21396) ·…
I am writing to report a stack-buffer-overflow (write) that is triggerable by way of the Wireshark fuzzing harness fuzzshark) This is a security issue that...
🚨 CVE-2026-76889
UMTS FP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
UMTS FP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
UMTS FP MAC-is descriptor count causes fixed-array out-of-bounds writes (#21413) · Issues · Wireshark Foundation / Wireshark ·…
Summary The UMTS FP dissector does not limit the number of MAC-is SDU descriptors before using the count...
🚨 CVE-2026-76890
Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
sharkd: use-after-return via dangling stack-array iograph tap listeners on error path (ANT-2026-GACTPNVK) (#21399) · Issues · Wireshark…
I am writing to report stack-use-after-return in tshark sharkd This is a security issue that was found by Anthropic using Claude to find...