๐จ CVE-2026-80230
When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable
standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and
`CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on
connections established without a presented server certificate. Bypassing the
pinning check under these disabled-verification conditions allows
unauthenticated connections to succeed when they should be rejected.
๐@cveNotify
When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable
standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and
`CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on
connections established without a presented server certificate. Bypassing the
pinning check under these disabled-verification conditions allows
unauthenticated connections to succeed when they should be rejected.
๐@cveNotify
๐จ CVE-2026-80231
A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup
for a given hostname even when using a different Native CA Store setting
(`CURLSSLOPT_NATIVE_CA`) than when the connection was created.
๐@cveNotify
A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup
for a given hostname even when using a different Native CA Store setting
(`CURLSSLOPT_NATIVE_CA`) than when the connection was created.
๐@cveNotify
๐จ CVE-2026-80255
A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of
space (ascii code 32) immediately before the `Secure` attribute causes curl to
store the cookie without its Secure flag. The cookie might then wrongfully be
sent over plaintext HTTP on subsequent requests to the same host.
๐@cveNotify
A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of
space (ascii code 32) immediately before the `Secure` attribute causes curl to
store the cookie without its Secure flag. The cookie might then wrongfully be
sent over plaintext HTTP on subsequent requests to the same host.
๐@cveNotify
๐จ CVE-2026-82208
With the wolfSSL backend, when CA caching is enabled and an
`CURLOPT_SSL_CTX_FUNCTION` callback replaces the trust store, libcurl can
silently reinstall the cached store after the callback returns. A certificate
trusted by the cached store but rejected by the callback-selected store is
then incorrectly accepted.
๐@cveNotify
With the wolfSSL backend, when CA caching is enabled and an
`CURLOPT_SSL_CTX_FUNCTION` callback replaces the trust store, libcurl can
silently reinstall the cached store after the callback returns. A certificate
trusted by the cached store but rejected by the callback-selected store is
then incorrectly accepted.
๐@cveNotify
๐จ CVE-2026-82209
When libpsl support is enabled, libcurl fails to enforce the Public Suffix
List boundary check when processing a `Set-Cookie` header where the `Domain`
attribute explicitly matches an origin host that is itself a public suffix
(e.g., `Domain=co.uk` set by `co.uk`).
Instead of coercing it into a strict host-only cookie, libcurl saves the
cookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is
inappropriately included in subsequent outbound requests or HTTP redirects to
arbitrary sibling subdomains under the same public suffix (e.g.,
`attacker.co.uk`).
๐@cveNotify
When libpsl support is enabled, libcurl fails to enforce the Public Suffix
List boundary check when processing a `Set-Cookie` header where the `Domain`
attribute explicitly matches an origin host that is itself a public suffix
(e.g., `Domain=co.uk` set by `co.uk`).
Instead of coercing it into a strict host-only cookie, libcurl saves the
cookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is
inappropriately included in subsequent outbound requests or HTTP redirects to
arbitrary sibling subdomains under the same public suffix (e.g.,
`attacker.co.uk`).
๐@cveNotify
๐จ CVE-2026-69727
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges over a network.
๐@cveNotify
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges over a network.
๐@cveNotify
๐จ CVE-2026-72992
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-72994
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-72996
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-72997
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-73000
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-73002
Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-73007
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-73015
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-77489
Null pointer dereference in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Null pointer dereference in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-77906
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
๐@cveNotify
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
๐@cveNotify
๐จ CVE-2026-78455
Out-of-bounds read in Xbox allows an unauthorized attacker to disclose information with a physical attack.
๐@cveNotify
Out-of-bounds read in Xbox allows an unauthorized attacker to disclose information with a physical attack.
๐@cveNotify
๐จ CVE-2026-80075
Heap-based buffer overflow in Windows Work Folders allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Heap-based buffer overflow in Windows Work Folders allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-84000
Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to execute code locally.
๐@cveNotify
Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to execute code locally.
๐@cveNotify
๐จ CVE-2026-84869
A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.
๐@cveNotify
A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.
๐@cveNotify
GitHub
Disclosures/CVE-2026-84869 at main ยท ConnectWise-Advisories/Disclosures
Disclosures. Contribute to ConnectWise-Advisories/Disclosures development by creating an account on GitHub.
๐จ CVE-2026-88890
OpenPanel through commit cd24bb8 contains an SQL injection vulnerability in the analytics filter builder that fails to validate profile.* filter column identifiers before interpolating them into ClickHouse WHERE clauses. An authenticated attacker with project-scoped read or root export credentials can inject arbitrary ClickHouse SQL to bypass project isolation and read other organizations' analytics data and profile PII via blind boolean oracle techniques.
๐@cveNotify
OpenPanel through commit cd24bb8 contains an SQL injection vulnerability in the analytics filter builder that fails to validate profile.* filter column identifiers before interpolating them into ClickHouse WHERE clauses. An authenticated attacker with project-scoped read or root export credentials can inject arbitrary ClickHouse SQL to bypass project isolation and read other organizations' analytics data and profile PII via blind boolean oracle techniques.
๐@cveNotify
GitHub
OpenPanel โ ClickHouse SQL injection via unvalidated profile.* filter column identifier
## Summary
OpenPanel's analytics query layer builds ClickHouse `WHERE` clauses from user-supplied event filters. Filters that reference a group column, a session column, or a bare event column...
OpenPanel's analytics query layer builds ClickHouse `WHERE` clauses from user-supplied event filters. Filters that reference a group column, a session column, or a bare event column...