π¨ CVE-2026-85089
FreeRDP versions 3.0.0 through 3.30.0 (before 3.31.0) transmit uninitialized heap memory in Save Session Info PDU reserved padding fields. Three PDU writers in libfreerdp/core/info.c (rdp_write_logon_info_v2, rdp_write_logon_info_plain, and rdp_write_logon_info_ex) use Stream_Seek instead of Stream_Zero for reserved pad bytes (up to 576 bytes), leaving previously freed heap contents in the outgoing PDU. Because the send buffer is allocated with malloc (not zeroed), stale heap data β which may include cleartext credentials from prior sessions β can be sent to the receiving peer. FreeRDP-based servers using rdpUpdate::SaveSessionInfo and freerdp-proxy (which forwards these PDUs) are affected, allowing disclosure of server/proxy process memory to a downstream client.
π@cveNotify
FreeRDP versions 3.0.0 through 3.30.0 (before 3.31.0) transmit uninitialized heap memory in Save Session Info PDU reserved padding fields. Three PDU writers in libfreerdp/core/info.c (rdp_write_logon_info_v2, rdp_write_logon_info_plain, and rdp_write_logon_info_ex) use Stream_Seek instead of Stream_Zero for reserved pad bytes (up to 576 bytes), leaving previously freed heap contents in the outgoing PDU. Because the send buffer is allocated with malloc (not zeroed), stale heap data β which may include cleartext credentials from prior sessions β can be sent to the receiving peer. FreeRDP-based servers using rdpUpdate::SaveSessionInfo and freerdp-proxy (which forwards these PDUs) are affected, allowing disclosure of server/proxy process memory to a downstream client.
π@cveNotify
GitHub
GitHub - FreeRDP/FreeRDP: FreeRDP is a free remote desktop protocol library and clients
FreeRDP is a free remote desktop protocol library and clients - FreeRDP/FreeRDP
π¨ CVE-2026-85090
FreeRDP before 3.31.0 contains a heap out-of-bounds read vulnerability in the general_ChromaV1ToYUV444 function during AVC444 chroma plane reconstruction. A malicious RDP server can craft a RFX_AVC444_BITMAP_STREAM with specific frame geometry to trigger an out-of-bounds memory read past the allocated luma plane.
π@cveNotify
FreeRDP before 3.31.0 contains a heap out-of-bounds read vulnerability in the general_ChromaV1ToYUV444 function during AVC444 chroma plane reconstruction. A malicious RDP server can craft a RFX_AVC444_BITMAP_STREAM with specific frame geometry to trigger an out-of-bounds memory read past the allocated luma plane.
π@cveNotify
GitHub
GitHub - FreeRDP/FreeRDP: FreeRDP is a free remote desktop protocol library and clients
FreeRDP is a free remote desktop protocol library and clients - FreeRDP/FreeRDP
π¨ CVE-2026-85091
zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary.
π@cveNotify
zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary.
π@cveNotify
Gist
zlib gz_vacate() Heap-Buffer Overflow via Non-Blocking Write
zlib gz_vacate() Heap-Buffer Overflow via Non-Blocking Write - README..md
π¨ CVE-2026-85092
LiME through 1.12.0 fails to validate the disk acquisition output path and does not use O_NOFOLLOW when opening the operator-supplied path parameter, allowing unprivileged local users to overwrite arbitrary root-owned files. An attacker who controls the output directory can create a symbolic link with the expected filename pointing to any root-owned file, and when the acquisition runs in kernel context, LiME follows the link and truncates the target file with the memory acquisition stream.
π@cveNotify
LiME through 1.12.0 fails to validate the disk acquisition output path and does not use O_NOFOLLOW when opening the operator-supplied path parameter, allowing unprivileged local users to overwrite arbitrary root-owned files. An attacker who controls the output directory can create a symbolic link with the expected filename pointing to any root-owned file, and when the acquisition runs in kernel context, LiME follows the link and truncates the target file with the memory acquisition stream.
π@cveNotify
Gist
LiME local disk acquisition symlink following allows root-owned file overwrite
LiME local disk acquisition symlink following allows root-owned file overwrite - 1README.md
π¨ CVE-2026-85093
Cheshire Cat AI's GET /memory/collections/{collection_id}/points endpoint fails to apply per-user filtering when retrieving episodic memory points. Authenticated attackers with MEMORY:READ permission can retrieve all users' stored conversation messages and personal data by paginating through the collection using the offset cursor.
π@cveNotify
Cheshire Cat AI's GET /memory/collections/{collection_id}/points endpoint fails to apply per-user filtering when retrieving episodic memory points. Authenticated attackers with MEMORY:READ permission can retrieve all users' stored conversation messages and personal data by paginating through the collection using the offset cursor.
π@cveNotify
GitHub
GitHub - cheshire-cat-ai/core: AI agent microservice
AI agent microservice. Contribute to cheshire-cat-ai/core development by creating an account on GitHub.
π¨ CVE-2026-85100
A vulnerability was detected in 2FastLabs agent-squad up to 1.1.4. Affected by this vulnerability is the function AgentSquad.routeRequest of the file agent-squad/typescript/src/orchestrator.ts of the component Streaming Agent Response Workflow. The manipulation results in resource consumption. It is possible to launch the attack remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
π@cveNotify
A vulnerability was detected in 2FastLabs agent-squad up to 1.1.4. Affected by this vulnerability is the function AgentSquad.routeRequest of the file agent-squad/typescript/src/orchestrator.ts of the component Streaming Agent Response Workflow. The manipulation results in resource consumption. It is possible to launch the attack remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
π@cveNotify
GitHub
GitHub - 2FastLabs/agent-squad: Flexible and powerful framework for managing multiple AI agents and handling complex conversations
Flexible and powerful framework for managing multiple AI agents and handling complex conversations - 2FastLabs/agent-squad
π¨ CVE-2026-85105
A flaw has been found in NousResearch hermes-agent 0.18.0. Affected by this issue is the function _sess_nowait of the file s71.py of the component Session Management. This manipulation of the argument session_id causes authorization bypass. The attack can be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way.
π@cveNotify
A flaw has been found in NousResearch hermes-agent 0.18.0. Affected by this issue is the function _sess_nowait of the file s71.py of the component Session Management. This manipulation of the argument session_id causes authorization bypass. The attack can be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way.
π@cveNotify
Vulnerability Database
CVE-2026-85105 in hermes-agent
A flaw has been found in NousResearch hermes-agent 0.18.0. This vulnerability is handled as CVE-2026-85105.
π¨ CVE-2026-85106
A vulnerability has been found in NousResearch hermes-agent 0.18.0. This affects the function fetchLinkTitle of the file apps/desktop/src/app/artifacts/index.tsx of the component Link Title Fetch. Such manipulation of the argument url leads to server-side request forgery. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.
π@cveNotify
A vulnerability has been found in NousResearch hermes-agent 0.18.0. This affects the function fetchLinkTitle of the file apps/desktop/src/app/artifacts/index.tsx of the component Link Title Fetch. Such manipulation of the argument url leads to server-side request forgery. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.
π@cveNotify
Vulnerability Database
CVE-2026-85106 in hermes-agent
A vulnerability has been found in NousResearch hermes-agent 0.18.0. This vulnerability is uniquely identified as CVE-2026-85106.
π¨ CVE-2026-85107
A vulnerability was found in NousResearch hermes-agent 0.18.0. This vulnerability affects the function resourceBufferFromUrl of the file apps/desktop/electron/main.ts of the component Electron Main Process. Performing a manipulation results in allocation of resources. The attack may be initiated remotely. copyImageFromUrl() entry point no longer reachable on current main. That function did exist at v2026.8.3 but was removed by v2026.8.19. The modern copy-image path is Electron-native event.sender.copyImageAt().
π@cveNotify
A vulnerability was found in NousResearch hermes-agent 0.18.0. This vulnerability affects the function resourceBufferFromUrl of the file apps/desktop/electron/main.ts of the component Electron Main Process. Performing a manipulation results in allocation of resources. The attack may be initiated remotely. copyImageFromUrl() entry point no longer reachable on current main. That function did exist at v2026.8.3 but was removed by v2026.8.19. The modern copy-image path is Electron-native event.sender.copyImageAt().
π@cveNotify
Vulnerability Database
CVE-2026-85107 in hermes-agent
A vulnerability was found in NousResearch hermes-agent 0.18.0. This vulnerability was named CVE-2026-85107.
π¨ CVE-2026-85124
@fastify/http-proxy versions before 11.6.2 do not validate proxied HTTP request paths for backslash based dot-segments before forwarding them to the configured upstream. The plain HTTP request handler skips the destination validation that the WebSocket path performs, and the underlying reply-from library only rejects forward-slash traversal, so a request containing backslash dot-segments can escape the boundary set by the prefix and rewritePrefix options. An unauthenticated network attacker can use this to reach upstream paths that were meant to stay hidden behind the proxy, resulting in disclosure of internal endpoints. This is a path traversal issue (CWE-22). Users should upgrade to @fastify/http-proxy 11.6.2 or later.
π@cveNotify
@fastify/http-proxy versions before 11.6.2 do not validate proxied HTTP request paths for backslash based dot-segments before forwarding them to the configured upstream. The plain HTTP request handler skips the destination validation that the WebSocket path performs, and the underlying reply-from library only rejects forward-slash traversal, so a request containing backslash dot-segments can escape the boundary set by the prefix and rewritePrefix options. An unauthenticated network attacker can use this to reach upstream paths that were meant to stay hidden behind the proxy, resulting in disclosure of internal endpoints. This is a path traversal issue (CWE-22). Users should upgrade to @fastify/http-proxy 11.6.2 or later.
π@cveNotify
cna.openjsf.org
Security Advisories | OpenJS Foundation CVE Numbering Authority
The OpenJS Foundation's CVE Numbering Authority (CNA)
π¨ CVE-2026-85150
A NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability occurs while parsing an Authorization or WWW-Authenticate header that uses Digest authentication. Specially crafted whitespace placement around a parameter's terminator can cause an internal length calculation to underflow, leading to a crash of the process parsing the header. On an RTSP server this can be triggered by a remote, unauthenticated attacker sending a single malformed request when the server has authentication enabled; the same flaw can also be triggered against an RTSP client by a malicious or compromised RTSP server. Successful exploitation results in a denial of service (application crash) and has no confirmed impact on confidentiality or integrity.
π@cveNotify
A NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability occurs while parsing an Authorization or WWW-Authenticate header that uses Digest authentication. Specially crafted whitespace placement around a parameter's terminator can cause an internal length calculation to underflow, leading to a crash of the process parsing the header. On an RTSP server this can be triggered by a remote, unauthenticated attacker sending a single malformed request when the server has authentication enabled; the same flaw can also be triggered against an RTSP client by a malicious or compromised RTSP server. Successful exploitation results in a denial of service (application crash) and has no confirmed impact on confidentiality or integrity.
π@cveNotify
Redhat
CVE-2026-85150 - Red Hat Customer Portal
CVE Details App
π¨ CVE-2026-85155
WWBN AVideo contains a SQL injection vulnerability in the sort column parameter of the get.json.php endpoint with APIName=channels that allows unauthenticated attackers to order results by arbitrary database columns including users.password and users.recoverPass. Attackers can exploit this ordering oracle to infer password hash values and recovery tokens, and trigger SQL errors that disclose the full query statement and database schema.
π@cveNotify
WWBN AVideo contains a SQL injection vulnerability in the sort column parameter of the get.json.php endpoint with APIName=channels that allows unauthenticated attackers to order results by arbitrary database columns including users.password and users.recoverPass. Attackers can exploit this ordering oracle to infer password hash values and recovery tokens, and trigger SQL errors that disclose the full query statement and database schema.
π@cveNotify
GitHub
SQL Injection (ORDER BY identifier) in get.json.php?APIName=channels: an unauthenticated caller selects the sort column, yieldingβ¦
### Summary
`/plugin/API/get.json.php?APIName=channels` lets an unauthenticated caller choose the column the query is sorted by. The column name is taken from the request and reaches `ORDER BY` ...
`/plugin/API/get.json.php?APIName=channels` lets an unauthenticated caller choose the column the query is sorted by. The column name is taken from the request and reaches `ORDER BY` ...
π¨ CVE-2026-85156
WWBN AVideo fails to properly validate access controls on the public channel page, allowing unauthenticated visitors to view unlisted and group-restricted videos through hardcoded visibility flags and an undefined property. Attackers can access the channel endpoint to retrieve sensitive video content that should be hidden, including full URLs to unlisted videos and thumbnails of member-only content, regardless of the operator's hidePrivateVideos setting.
π@cveNotify
WWBN AVideo fails to properly validate access controls on the public channel page, allowing unauthenticated visitors to view unlisted and group-restricted videos through hardcoded visibility flags and an undefined property. Attackers can access the channel endpoint to retrieve sensitive video content that should be hidden, including full URLs to unlisted videos and thumbnails of member-only content, regardless of the operator's hidePrivateVideos setting.
π@cveNotify
GitHub
Broken Access Control: public channel page returns unlisted and group-restricted videos to unauthenticated visitors, and an unsetβ¦
### Summary
The public channel page (`/channel/<name>`) discloses unlisted and group-restricted videos to anonymous visitors, and it does so even when the operator has switched the "h...
The public channel page (`/channel/<name>`) discloses unlisted and group-restricted videos to anonymous visitors, and it does so even when the operator has switched the "h...
π¨ CVE-2026-85157
WWBN AVideo contains a broken access control vulnerability in the unauthenticated feed/index.php endpoint that disables per-video visibility checks when a program_id parameter is supplied. Attackers can enumerate playlist identifiers and retrieve unlisted and group-restricted videos by requesting the RSS feed with any visible playlist id, including empty playlists that return the entire site's hidden video catalogue.
π@cveNotify
WWBN AVideo contains a broken access control vulnerability in the unauthenticated feed/index.php endpoint that disables per-video visibility checks when a program_id parameter is supplied. Attackers can enumerate playlist identifiers and retrieve unlisted and group-restricted videos by requesting the RSS feed with any visible playlist id, including empty playlists that return the entire site's hidden video catalogue.
π@cveNotify
GitHub
Broken Access Control: unauthenticated playlist feed (feed/index.php?program_id) returns unlisted and group-restricted videos,β¦
### Summary
`feed/index.php` is an unauthenticated RSS endpoint. When called with `program_id`, it checks that the **playlist** is visible and then lists the videos in it with per-video visibili...
`feed/index.php` is an unauthenticated RSS endpoint. When called with `program_id`, it checks that the **playlist** is visible and then lists the videos in it with per-video visibili...
π¨ CVE-2026-85158
AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in videoEmbeded.php that echoes the link parameter inside an HTML comment with zero escaping. Attackers can close the comment with --> and inject arbitrary JavaScript that executes when victims visit the crafted embed URL.
π@cveNotify
AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in videoEmbeded.php that echoes the link parameter inside an HTML comment with zero escaping. Attackers can close the comment with --> and inject arbitrary JavaScript that executes when victims visit the crafted embed URL.
π@cveNotify
GitHub
Reflected XSS: videoEmbeded.php echoes $_GET['link'] inside an HTML comment with zero escaping, allowing unauthenticated scriptβ¦
## Summary
`view/videoEmbeded.php:469` echoes `$_GET['link']` inside an HTML comment with zero escaping. An attacker closes the comment with `-->` and injects arbitrary HTML/JavaScript....
`view/videoEmbeded.php:469` echoes `$_GET['link']` inside an HTML comment with zero escaping. An attacker closes the comment with `-->` and injects arbitrary HTML/JavaScript....
π¨ CVE-2026-85159
AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in userLogin.php where the cancelUri parameter is echoed in an href attribute after isSafeRedirectURL checks protocol only, not HTML characters. Unauthenticated attackers can inject event handlers via relative URLs with embedded quotes to execute arbitrary JavaScript when users interact with the Cancel button.
π@cveNotify
AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in userLogin.php where the cancelUri parameter is echoed in an href attribute after isSafeRedirectURL checks protocol only, not HTML characters. Unauthenticated attackers can inject event handlers via relative URLs with embedded quotes to execute arbitrary JavaScript when users interact with the Cancel button.
π@cveNotify
GitHub
Reflected XSS: userLogin.php echoes cancelUri in an href attribute after isSafeRedirectURL checks protocol only, allowing attributeβ¦
## Summary
`view/userLogin.php:172` echoes `$_REQUEST['cancelUri']` inside an `href` attribute after `isSafeRedirectURL()` (line 168) checks protocol and domain only, not HTML characters. ...
`view/userLogin.php:172` echoes `$_REQUEST['cancelUri']` inside an `href` attribute after `isSafeRedirectURL()` (line 168) checks protocol and domain only, not HTML characters. ...
π¨ CVE-2026-85160
AVideo through commit c91b5975d contains a cross-site request forgery and path traversal vulnerability in stopLive.php that allows attackers to delete directories by exploiting missing token validation and unsanitized key parameter concatenation. Attackers can craft an image tag with a traversal payload like key=../../videos to trigger recursive deletion of the videos directory when an admin visits a malicious page.
π@cveNotify
AVideo through commit c91b5975d contains a cross-site request forgery and path traversal vulnerability in stopLive.php that allows attackers to delete directories by exploiting missing token validation and unsanitized key parameter concatenation. Attackers can craft an image tag with a traversal payload like key=../../videos to trigger recursive deletion of the videos directory when an admin visits a malicious page.
π@cveNotify
GitHub
CSRF and path traversal: plugin/Live/stopLive.php has no token check and passes unsanitized key to Live::stopLiveFromkey, whichβ¦
## Summary
`plugin/Live/stopLive.php` passes `$_REQUEST['key']` to `Live::stopLiveFromkey()` (line 25) with no `forbidIfNotPost()`, no `forbidIfInvalidToken()`, and no sanitization of `key...
`plugin/Live/stopLive.php` passes `$_REQUEST['key']` to `Live::stopLiveFromkey()` (line 25) with no `forbidIfNotPost()`, no `forbidIfInvalidToken()`, and no sanitization of `key...
π¨ CVE-2026-85161
AVideo through commit c91b5975d contains a cross-site request forgery vulnerability in removePoster.php that lacks forbidIfNotPost or forbidIfInvalidToken checks. Attackers can craft malicious image tags to delete authenticated victims' live poster and thumbnail files via GET requests.
π@cveNotify
AVideo through commit c91b5975d contains a cross-site request forgery vulnerability in removePoster.php that lacks forbidIfNotPost or forbidIfInvalidToken checks. Attackers can craft malicious image tags to delete authenticated victims' live poster and thumbnail files via GET requests.
π@cveNotify
GitHub
CSRF: plugin/Live/removePoster.php has no forbidIfNotPost or forbidIfInvalidToken, letting a cross-site GET delete the victim'sβ¦
## Summary
`plugin/Live/removePoster.php` reads `$_REQUEST['live_servers_id']` (line 11), checks only `User::isLogged()` (line 17), and `@unlink`s the poster and thumbnail files (lines 36-...
`plugin/Live/removePoster.php` reads `$_REQUEST['live_servers_id']` (line 11), checks only `User::isLogged()` (line 17), and `@unlink`s the poster and thumbnail files (lines 36-...
π¨ CVE-2026-85162
AVideo through commit c91b5975d contains a cross-site request forgery vulnerability in plugin/Live/saveLive.php that lacks forbidIfNotPost and forbidIfInvalidToken protections. Attackers can craft malicious image tags to overwrite authenticated streamers' RTMP keys, passwords, and titles, hijacking live broadcasts.
π@cveNotify
AVideo through commit c91b5975d contains a cross-site request forgery vulnerability in plugin/Live/saveLive.php that lacks forbidIfNotPost and forbidIfInvalidToken protections. Attackers can craft malicious image tags to overwrite authenticated streamers' RTMP keys, passwords, and titles, hijacking live broadcasts.
π@cveNotify
GitHub
CSRF: plugin/Live/saveLive.php has no forbidIfNotPost or forbidIfInvalidToken, letting a cross-site GET overwrite the streamer'sβ¦
## Summary
`plugin/Live/saveLive.php` reads every field from `$_REQUEST` (lines 12,20,27-32) and saves with `$l->save()` (line 36) with no `forbidIfNotPost()` or `forbidIfInvalidToken()` call. ...
`plugin/Live/saveLive.php` reads every field from `$_REQUEST` (lines 12,20,27-32) and saves with `$l->save()` (line 36) with no `forbidIfNotPost()` or `forbidIfInvalidToken()` call. ...
π¨ CVE-2026-85163
AVideo through commit c91b5975d contains a server-side request forgery vulnerability in the EPG parser that allows authenticated uploaders to fetch arbitrary internal URLs. An attacker can supply an internal URL via the epg_link parameter during video upload, which is validated only for syntax and later fetched server-side during EPG generation without SSRF protection checks.
π@cveNotify
AVideo through commit c91b5975d contains a server-side request forgery vulnerability in the EPG parser that allows authenticated uploaders to fetch arbitrary internal URLs. An attacker can supply an internal URL via the epg_link parameter during video upload, which is validated only for syntax and later fetched server-side during EPG generation without SSRF protection checks.
π@cveNotify
GitHub
SSRF: user-supplied epg_link reaches EpgParser url_get_contents with no isSSRFSafeURL check, fetching arbitrary internal URLs duringβ¦
## Summary
`videoAddNew.json.php` stores a user-supplied `epg_link` with only `isValidURL()` validation (`objects/videoAddNew.json.php:137`), which accepts internal URLs. The EPG parser later fetc...
`videoAddNew.json.php` stores a user-supplied `epg_link` with only `isValidURL()` validation (`objects/videoAddNew.json.php:137`), which accepts internal URLs. The EPG parser later fetc...
π¨ CVE-2026-85164
WWBN AVideo through commit c91b5975d contains a server-side request forgery vulnerability in the set_api_userImages API endpoint that fails to validate profileImg and backgroundImg URLs before fetching them. Authenticated API clients can supply internal URLs to fetch cloud metadata or internal services, with responses written to publicly accessible web paths for retrieval.
π@cveNotify
WWBN AVideo through commit c91b5975d contains a server-side request forgery vulnerability in the set_api_userImages API endpoint that fails to validate profileImg and backgroundImg URLs before fetching them. Authenticated API clients can supply internal URLs to fetch cloud metadata or internal services, with responses written to publicly accessible web paths for retrieval.
π@cveNotify
GitHub
SSRF: API set_api_userImages profileImg and backgroundImg reach file_get_contents with no isSSRFSafeURL check on the initial URLβ¦
## Summary
`url_get_contents()` calls `file_get_contents()` on the initial request URL with no `isSSRFSafeURL()` check (`objects/functions.php:2103-2105`). The SSRF filter runs only on redirect ho...
`url_get_contents()` calls `file_get_contents()` on the initial request URL with no `isSSRFSafeURL()` check (`objects/functions.php:2103-2105`). The SSRF filter runs only on redirect ho...