๐จ CVE-2026-69813
Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.
๐@cveNotify
Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.
๐@cveNotify
๐จ CVE-2026-69814
Use after free in Windows Credential Providers allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Use after free in Windows Credential Providers allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-69816
Use after free in Windows Accounts Control allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Use after free in Windows Accounts Control allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-69817
Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-69818
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-69820
Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-69822
Numeric truncation error in Windows Kerberos allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Numeric truncation error in Windows Kerberos allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-69829
Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to execute code over a network.
๐@cveNotify
Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to execute code over a network.
๐@cveNotify
๐จ CVE-2026-69832
Exposure of sensitive system information to an unauthorized control sphere in Windows Win32K allows an authorized attacker to disclose information locally.
๐@cveNotify
Exposure of sensitive system information to an unauthorized control sphere in Windows Win32K allows an authorized attacker to disclose information locally.
๐@cveNotify
๐จ CVE-2026-69834
Use after free in Windows ALPC allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Use after free in Windows ALPC allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-69838
Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-69839
Uncaught exception in Windows iSCSI Target Service allows an authorized attacker to deny service over a network.
๐@cveNotify
Uncaught exception in Windows iSCSI Target Service allows an authorized attacker to deny service over a network.
๐@cveNotify
๐จ CVE-2026-2756
A security vulnerability has been detected in OmniPEMF NeoRhythm up to 20260308. This affects an unknown function of the component BLE Interface. Such manipulation leads to missing authentication. The attack can only be initiated within the local network. This attack is characterized by high complexity. The exploitability is reported as difficult. The vendor was contacted early about this disclosure but did not respond in any way.
๐@cveNotify
A security vulnerability has been detected in OmniPEMF NeoRhythm up to 20260308. This affects an unknown function of the component BLE Interface. Such manipulation leads to missing authentication. The attack can only be initiated within the local network. This attack is characterized by high complexity. The exploitability is reported as difficult. The vendor was contacted early about this disclosure but did not respond in any way.
๐@cveNotify
๐จ CVE-2026-61591
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, for views that opt into state snapshots, the snapshot `state_json` embedded in the client page was restored on reconnect as trusted view state with no integrity check. A client could edit the unsigned `state_json` in their page and return it in the reconnect mount frame to inject arbitrary view attributes โ e.g. flip `is_admin` to `True`, or change `account_id` / `balance` โ escalating privilege or tampering with business state held in public view attributes (the normal djust pattern). This issue is fixed in djust 1.0.7. State snapshots are signed; unsigned or forged snapshots are rejected on the back-navigation restore path. As a workaround, do not enable state snapshots; do not hold authorization/ownership state in public view attributes.
๐@cveNotify
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, for views that opt into state snapshots, the snapshot `state_json` embedded in the client page was restored on reconnect as trusted view state with no integrity check. A client could edit the unsigned `state_json` in their page and return it in the reconnect mount frame to inject arbitrary view attributes โ e.g. flip `is_admin` to `True`, or change `account_id` / `balance` โ escalating privilege or tampering with business state held in public view attributes (the normal djust pattern). This issue is fixed in djust 1.0.7. State snapshots are signed; unsigned or forged snapshots are rejected on the back-navigation restore path. As a workaround, do not enable state snapshots; do not hold authorization/ownership state in public view attributes.
๐@cveNotify
GitHub
Release v1.0.7 ยท djust-org/djust
What's Changed
feat(checks): T017 โ flag dj-view/dj-root on a table-section element (#1837) @johnrtipton (#1841)
test(js): make dj-transition active/end-on-next-frame test deterministic (#1830...
feat(checks): T017 โ flag dj-view/dj-root on a table-section element (#1837) @johnrtipton (#1841)
test(js): make dj-transition active/end-on-next-frame test deterministic (#1830...
๐จ CVE-2026-61592
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, SSE sessions were keyed solely by a client-chosen `session_id` with no binding to the authenticated user โ a control the WebSocket transport has but that was dropped on SSE. An attacker who learns (or a victim who leaks) a `session_id` could connect to the message endpoint and dispatch event handlers that execute with the victim's identity and state. This is fixed in djust 1.0.7. Each SSE session is bound to its owning principal at creation and cross-principal access is rejected; SSE session creation is additionally capped per principal. As a workaround, disable the SSE transport.
๐@cveNotify
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, SSE sessions were keyed solely by a client-chosen `session_id` with no binding to the authenticated user โ a control the WebSocket transport has but that was dropped on SSE. An attacker who learns (or a victim who leaks) a `session_id` could connect to the message endpoint and dispatch event handlers that execute with the victim's identity and state. This is fixed in djust 1.0.7. Each SSE session is bound to its owning principal at creation and cross-principal access is rejected; SSE session creation is additionally capped per principal. As a workaround, disable the SSE transport.
๐@cveNotify
GitHub
Release v1.0.7 ยท djust-org/djust
What's Changed
feat(checks): T017 โ flag dj-view/dj-root on a table-section element (#1837) @johnrtipton (#1841)
test(js): make dj-transition active/end-on-next-frame test deterministic (#1830...
feat(checks): T017 โ flag dj-view/dj-root on a table-section element (#1837) @johnrtipton (#1841)
test(js): make dj-transition active/end-on-next-frame test deterministic (#1830...
๐จ CVE-2026-61594
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the live (WebSocket) transport authorizes a mount via `check_view_auth`, not Django's `View.dispatch()` chain. As a result, standard Django authorization โ `LoginRequiredMixin`, `PermissionRequiredMixin`, `UserPassesTestMixin`, `@method_decorator(login_required, name="dispatch")`, and custom `dispatch()` guards โ and the djust admin extension's staff gate (applied only in the HTTP `as_view` wrapper) were enforced on the initial HTTP GET but silently bypassed over WebSocket, where all events and state flow. An anonymous or under-privileged client could open a WebSocket and mount such a view โ including admin list/create/change/delete โ and dispatch its handlers. This is fixed in djust 1.0.7. `check_view_auth` now honors the Django `AccessMixin` family on every transport; a new system check S004 fails loud at startup on auth patterns the runtime cannot safely replay (decorator/overridden-`dispatch` forms); and the admin base mixin declares `login_required = True` + an active-staff `check_permissions` gate. As a workaround, gate views using djust's `login_required` / `permission_required` / `check_permissions` attributes (honored on all transports) rather than HTTP-only mixins/decorators.
๐@cveNotify
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the live (WebSocket) transport authorizes a mount via `check_view_auth`, not Django's `View.dispatch()` chain. As a result, standard Django authorization โ `LoginRequiredMixin`, `PermissionRequiredMixin`, `UserPassesTestMixin`, `@method_decorator(login_required, name="dispatch")`, and custom `dispatch()` guards โ and the djust admin extension's staff gate (applied only in the HTTP `as_view` wrapper) were enforced on the initial HTTP GET but silently bypassed over WebSocket, where all events and state flow. An anonymous or under-privileged client could open a WebSocket and mount such a view โ including admin list/create/change/delete โ and dispatch its handlers. This is fixed in djust 1.0.7. `check_view_auth` now honors the Django `AccessMixin` family on every transport; a new system check S004 fails loud at startup on auth patterns the runtime cannot safely replay (decorator/overridden-`dispatch` forms); and the admin base mixin declares `login_required = True` + an active-staff `check_permissions` gate. As a workaround, gate views using djust's `login_required` / `permission_required` / `check_permissions` attributes (honored on all transports) rather than HTTP-only mixins/decorators.
๐@cveNotify
GitHub
Release v1.0.7 ยท djust-org/djust
What's Changed
feat(checks): T017 โ flag dj-view/dj-root on a table-section element (#1837) @johnrtipton (#1841)
test(js): make dj-transition active/end-on-next-frame test deterministic (#1830...
feat(checks): T017 โ flag dj-view/dj-root on a table-section element (#1837) @johnrtipton (#1841)
test(js): make dj-transition active/end-on-next-frame test deterministic (#1830...
๐จ CVE-2026-61597
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, many djust built-in component template tags (`djust.components.templatetags.*`) render a developer/user-supplied URL into an `href` / `action` attribute, HTML-escaping it with `conditional_escape` but never validating the URL scheme. HTML escaping prevents attribute breakout but does not neutralize a `javascript:` URI (which needs no escapable characters), so a URL value of `javascript:alert(document.cookie)` lands verbatim in `<a href="javascript:alert(document.cookie)">` and executes in the victim's session on click. Version 1.0.7 contains a fix. As a workaround, do not pass user-controllable URLs to the affected built-in component tags; pre-validate URL schemes in application code before binding them to component arguments.
๐@cveNotify
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, many djust built-in component template tags (`djust.components.templatetags.*`) render a developer/user-supplied URL into an `href` / `action` attribute, HTML-escaping it with `conditional_escape` but never validating the URL scheme. HTML escaping prevents attribute breakout but does not neutralize a `javascript:` URI (which needs no escapable characters), so a URL value of `javascript:alert(document.cookie)` lands verbatim in `<a href="javascript:alert(document.cookie)">` and executes in the victim's session on click. Version 1.0.7 contains a fix. As a workaround, do not pass user-controllable URLs to the affected built-in component tags; pre-validate URL schemes in application code before binding them to component arguments.
๐@cveNotify
GitHub
Release v1.0.7 ยท djust-org/djust
What's Changed
feat(checks): T017 โ flag dj-view/dj-root on a table-section element (#1837) @johnrtipton (#1841)
test(js): make dj-transition active/end-on-next-frame test deterministic (#1830...
feat(checks): T017 โ flag dj-view/dj-root on a table-section element (#1837) @johnrtipton (#1841)
test(js): make dj-transition active/end-on-next-frame test deterministic (#1830...
๐จ CVE-2026-64684
RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.1.0, the rmcp crate's StreamableHttpClientTransport in crates/rmcp/src/transport/common/reqwest/streamable_http_client.rs builds its default_http_client with reqwest's automatic redirect policy and applies caller-supplied values from StreamableHttpClientTransportConfig.custom_headers without marking them as sensitive. When a malicious or compromised MCP endpoint returns a cross-origin 307 or 308 redirect, reqwest follows the redirect and apply_custom_headers causes custom API keys or authentication tokens to be replayed to the new origin, where an attacker can capture and reuse them. The separate auth_header path is not affected because it uses the standard Authorization header, which reqwest strips on cross-origin redirects. This issue is fixed in version 2.1.0.
๐@cveNotify
RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.1.0, the rmcp crate's StreamableHttpClientTransport in crates/rmcp/src/transport/common/reqwest/streamable_http_client.rs builds its default_http_client with reqwest's automatic redirect policy and applies caller-supplied values from StreamableHttpClientTransportConfig.custom_headers without marking them as sensitive. When a malicious or compromised MCP endpoint returns a cross-origin 307 or 308 redirect, reqwest follows the redirect and apply_custom_headers causes custom API keys or authentication tokens to be replayed to the new origin, where an attacker can capture and reuse them. The separate auth_header path is not affected because it uses the standard Authorization header, which reqwest strips on cross-origin redirects. This issue is fixed in version 2.1.0.
๐@cveNotify
GitHub
fix: block redirect header leaks (#936) ยท modelcontextprotocol/rust-sdk@496902b
The official Rust SDK for the Model Context Protocol - fix: block redirect header leaks (#936) ยท modelcontextprotocol/rust-sdk@496902b
๐จ CVE-2026-85469
A flaw was found in quay-builder-qemu. A remote attacker could exploit this by compromising the upstream `Noelware/docker-manifest-action` used in the release workflow, which is pinned to a mutable branch. This allows the attacker to inject arbitrary code, leading to the exfiltration of sensitive registry credentials or the publication of malicious images. The workflow also exposes the default GitHub token, increasing the severity of the compromise.
๐@cveNotify
A flaw was found in quay-builder-qemu. A remote attacker could exploit this by compromising the upstream `Noelware/docker-manifest-action` used in the release workflow, which is pinned to a mutable branch. This allows the attacker to inject arbitrary code, leading to the exfiltration of sensitive registry credentials or the publication of malicious images. The workflow also exposes the default GitHub token, increasing the severity of the compromise.
๐@cveNotify
Redhat
CVE-2026-85469 - Red Hat Customer Portal
CVE Details App
๐จ CVE-2026-89034
TCH QRing smart ring model R20_B006 running firmware RT09R20_1.00.00_250318 contains an unauthenticated Bluetooth Low Energy access vulnerability that allows any nearby attacker to connect to the device without pairing, authentication, or user approval by exploiting the exposed Nordic UART Service which enforces no client authentication or command authorization. Attackers within Bluetooth Low Energy range can connect directly to the ring, bypassing the official application and cloud authentication, to read battery levels, activate live heart rate monitoring, and retrieve stored historical heart rate and blood oxygen records.
๐@cveNotify
TCH QRing smart ring model R20_B006 running firmware RT09R20_1.00.00_250318 contains an unauthenticated Bluetooth Low Energy access vulnerability that allows any nearby attacker to connect to the device without pairing, authentication, or user approval by exploiting the exposed Nordic UART Service which enforces no client authentication or command authorization. Attackers within Bluetooth Low Energy range can connect directly to the ring, bypassing the official application and cloud authentication, to read battery levels, activate live heart rate monitoring, and retrieve stored historical heart rate and blood oxygen records.
๐@cveNotify
๐จ CVE-2026-92576
HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the _validate_url() function fails to block internal IP ranges and private addresses. Attackers can send messages instructing the bot to fetch cloud metadata endpoints, localhost services, and RFC 1918 addresses to extract IAM credentials and internal service data.
๐@cveNotify
HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the _validate_url() function fails to block internal IP ranges and private addresses. Attackers can send messages instructing the bot to fetch cloud metadata endpoints, localhost services, and RFC 1918 addresses to extract IAM credentials and internal service data.
๐@cveNotify
GitHub
ZDI-CAN-29369: Hong Kong University Data Intelligence Lab nanobot WebFetch Server-Side Request Forgery Information Disclosure Vulnerability
ZDI-CAN-29369: Hong Kong University Data Intelligence Lab nanobot WebFetch Server-Side Request Forgery Information Disclosure Vulnerability
-- CVSS -----------------------------------------
9...
-- CVSS -----------------------------------------
9...