π¨ CVE-2026-69817
Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges locally.
π@cveNotify
Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-69818
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
π@cveNotify
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-69820
Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally.
π@cveNotify
Heap-based buffer overflow in Windows Hello allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-69822
Numeric truncation error in Windows Kerberos allows an authorized attacker to elevate privileges locally.
π@cveNotify
Numeric truncation error in Windows Kerberos allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-69829
Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to execute code over a network.
π@cveNotify
Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to execute code over a network.
π@cveNotify
π¨ CVE-2026-69832
Exposure of sensitive system information to an unauthorized control sphere in Windows Win32K allows an authorized attacker to disclose information locally.
π@cveNotify
Exposure of sensitive system information to an unauthorized control sphere in Windows Win32K allows an authorized attacker to disclose information locally.
π@cveNotify
π¨ CVE-2026-69834
Use after free in Windows ALPC allows an authorized attacker to elevate privileges locally.
π@cveNotify
Use after free in Windows ALPC allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-69838
Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.
π@cveNotify
Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-69839
Uncaught exception in Windows iSCSI Target Service allows an authorized attacker to deny service over a network.
π@cveNotify
Uncaught exception in Windows iSCSI Target Service allows an authorized attacker to deny service over a network.
π@cveNotify
π¨ CVE-2026-2756
A security vulnerability has been detected in OmniPEMF NeoRhythm up to 20260308. This affects an unknown function of the component BLE Interface. Such manipulation leads to missing authentication. The attack can only be initiated within the local network. This attack is characterized by high complexity. The exploitability is reported as difficult. The vendor was contacted early about this disclosure but did not respond in any way.
π@cveNotify
A security vulnerability has been detected in OmniPEMF NeoRhythm up to 20260308. This affects an unknown function of the component BLE Interface. Such manipulation leads to missing authentication. The attack can only be initiated within the local network. This attack is characterized by high complexity. The exploitability is reported as difficult. The vendor was contacted early about this disclosure but did not respond in any way.
π@cveNotify
π¨ CVE-2026-61591
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, for views that opt into state snapshots, the snapshot `state_json` embedded in the client page was restored on reconnect as trusted view state with no integrity check. A client could edit the unsigned `state_json` in their page and return it in the reconnect mount frame to inject arbitrary view attributes β e.g. flip `is_admin` to `True`, or change `account_id` / `balance` β escalating privilege or tampering with business state held in public view attributes (the normal djust pattern). This issue is fixed in djust 1.0.7. State snapshots are signed; unsigned or forged snapshots are rejected on the back-navigation restore path. As a workaround, do not enable state snapshots; do not hold authorization/ownership state in public view attributes.
π@cveNotify
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, for views that opt into state snapshots, the snapshot `state_json` embedded in the client page was restored on reconnect as trusted view state with no integrity check. A client could edit the unsigned `state_json` in their page and return it in the reconnect mount frame to inject arbitrary view attributes β e.g. flip `is_admin` to `True`, or change `account_id` / `balance` β escalating privilege or tampering with business state held in public view attributes (the normal djust pattern). This issue is fixed in djust 1.0.7. State snapshots are signed; unsigned or forged snapshots are rejected on the back-navigation restore path. As a workaround, do not enable state snapshots; do not hold authorization/ownership state in public view attributes.
π@cveNotify
GitHub
Release v1.0.7 Β· djust-org/djust
What's Changed
feat(checks): T017 β flag dj-view/dj-root on a table-section element (#1837) @johnrtipton (#1841)
test(js): make dj-transition active/end-on-next-frame test deterministic (#1830...
feat(checks): T017 β flag dj-view/dj-root on a table-section element (#1837) @johnrtipton (#1841)
test(js): make dj-transition active/end-on-next-frame test deterministic (#1830...
π¨ CVE-2026-61592
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, SSE sessions were keyed solely by a client-chosen `session_id` with no binding to the authenticated user β a control the WebSocket transport has but that was dropped on SSE. An attacker who learns (or a victim who leaks) a `session_id` could connect to the message endpoint and dispatch event handlers that execute with the victim's identity and state. This is fixed in djust 1.0.7. Each SSE session is bound to its owning principal at creation and cross-principal access is rejected; SSE session creation is additionally capped per principal. As a workaround, disable the SSE transport.
π@cveNotify
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, SSE sessions were keyed solely by a client-chosen `session_id` with no binding to the authenticated user β a control the WebSocket transport has but that was dropped on SSE. An attacker who learns (or a victim who leaks) a `session_id` could connect to the message endpoint and dispatch event handlers that execute with the victim's identity and state. This is fixed in djust 1.0.7. Each SSE session is bound to its owning principal at creation and cross-principal access is rejected; SSE session creation is additionally capped per principal. As a workaround, disable the SSE transport.
π@cveNotify
GitHub
Release v1.0.7 Β· djust-org/djust
What's Changed
feat(checks): T017 β flag dj-view/dj-root on a table-section element (#1837) @johnrtipton (#1841)
test(js): make dj-transition active/end-on-next-frame test deterministic (#1830...
feat(checks): T017 β flag dj-view/dj-root on a table-section element (#1837) @johnrtipton (#1841)
test(js): make dj-transition active/end-on-next-frame test deterministic (#1830...
π¨ CVE-2026-61594
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the live (WebSocket) transport authorizes a mount via `check_view_auth`, not Django's `View.dispatch()` chain. As a result, standard Django authorization β `LoginRequiredMixin`, `PermissionRequiredMixin`, `UserPassesTestMixin`, `@method_decorator(login_required, name="dispatch")`, and custom `dispatch()` guards β and the djust admin extension's staff gate (applied only in the HTTP `as_view` wrapper) were enforced on the initial HTTP GET but silently bypassed over WebSocket, where all events and state flow. An anonymous or under-privileged client could open a WebSocket and mount such a view β including admin list/create/change/delete β and dispatch its handlers. This is fixed in djust 1.0.7. `check_view_auth` now honors the Django `AccessMixin` family on every transport; a new system check S004 fails loud at startup on auth patterns the runtime cannot safely replay (decorator/overridden-`dispatch` forms); and the admin base mixin declares `login_required = True` + an active-staff `check_permissions` gate. As a workaround, gate views using djust's `login_required` / `permission_required` / `check_permissions` attributes (honored on all transports) rather than HTTP-only mixins/decorators.
π@cveNotify
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the live (WebSocket) transport authorizes a mount via `check_view_auth`, not Django's `View.dispatch()` chain. As a result, standard Django authorization β `LoginRequiredMixin`, `PermissionRequiredMixin`, `UserPassesTestMixin`, `@method_decorator(login_required, name="dispatch")`, and custom `dispatch()` guards β and the djust admin extension's staff gate (applied only in the HTTP `as_view` wrapper) were enforced on the initial HTTP GET but silently bypassed over WebSocket, where all events and state flow. An anonymous or under-privileged client could open a WebSocket and mount such a view β including admin list/create/change/delete β and dispatch its handlers. This is fixed in djust 1.0.7. `check_view_auth` now honors the Django `AccessMixin` family on every transport; a new system check S004 fails loud at startup on auth patterns the runtime cannot safely replay (decorator/overridden-`dispatch` forms); and the admin base mixin declares `login_required = True` + an active-staff `check_permissions` gate. As a workaround, gate views using djust's `login_required` / `permission_required` / `check_permissions` attributes (honored on all transports) rather than HTTP-only mixins/decorators.
π@cveNotify
GitHub
Release v1.0.7 Β· djust-org/djust
What's Changed
feat(checks): T017 β flag dj-view/dj-root on a table-section element (#1837) @johnrtipton (#1841)
test(js): make dj-transition active/end-on-next-frame test deterministic (#1830...
feat(checks): T017 β flag dj-view/dj-root on a table-section element (#1837) @johnrtipton (#1841)
test(js): make dj-transition active/end-on-next-frame test deterministic (#1830...
π¨ CVE-2026-61597
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, many djust built-in component template tags (`djust.components.templatetags.*`) render a developer/user-supplied URL into an `href` / `action` attribute, HTML-escaping it with `conditional_escape` but never validating the URL scheme. HTML escaping prevents attribute breakout but does not neutralize a `javascript:` URI (which needs no escapable characters), so a URL value of `javascript:alert(document.cookie)` lands verbatim in `<a href="javascript:alert(document.cookie)">` and executes in the victim's session on click. Version 1.0.7 contains a fix. As a workaround, do not pass user-controllable URLs to the affected built-in component tags; pre-validate URL schemes in application code before binding them to component arguments.
π@cveNotify
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, many djust built-in component template tags (`djust.components.templatetags.*`) render a developer/user-supplied URL into an `href` / `action` attribute, HTML-escaping it with `conditional_escape` but never validating the URL scheme. HTML escaping prevents attribute breakout but does not neutralize a `javascript:` URI (which needs no escapable characters), so a URL value of `javascript:alert(document.cookie)` lands verbatim in `<a href="javascript:alert(document.cookie)">` and executes in the victim's session on click. Version 1.0.7 contains a fix. As a workaround, do not pass user-controllable URLs to the affected built-in component tags; pre-validate URL schemes in application code before binding them to component arguments.
π@cveNotify
GitHub
Release v1.0.7 Β· djust-org/djust
What's Changed
feat(checks): T017 β flag dj-view/dj-root on a table-section element (#1837) @johnrtipton (#1841)
test(js): make dj-transition active/end-on-next-frame test deterministic (#1830...
feat(checks): T017 β flag dj-view/dj-root on a table-section element (#1837) @johnrtipton (#1841)
test(js): make dj-transition active/end-on-next-frame test deterministic (#1830...
π¨ CVE-2026-64684
RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.1.0, the rmcp crate's StreamableHttpClientTransport in crates/rmcp/src/transport/common/reqwest/streamable_http_client.rs builds its default_http_client with reqwest's automatic redirect policy and applies caller-supplied values from StreamableHttpClientTransportConfig.custom_headers without marking them as sensitive. When a malicious or compromised MCP endpoint returns a cross-origin 307 or 308 redirect, reqwest follows the redirect and apply_custom_headers causes custom API keys or authentication tokens to be replayed to the new origin, where an attacker can capture and reuse them. The separate auth_header path is not affected because it uses the standard Authorization header, which reqwest strips on cross-origin redirects. This issue is fixed in version 2.1.0.
π@cveNotify
RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.1.0, the rmcp crate's StreamableHttpClientTransport in crates/rmcp/src/transport/common/reqwest/streamable_http_client.rs builds its default_http_client with reqwest's automatic redirect policy and applies caller-supplied values from StreamableHttpClientTransportConfig.custom_headers without marking them as sensitive. When a malicious or compromised MCP endpoint returns a cross-origin 307 or 308 redirect, reqwest follows the redirect and apply_custom_headers causes custom API keys or authentication tokens to be replayed to the new origin, where an attacker can capture and reuse them. The separate auth_header path is not affected because it uses the standard Authorization header, which reqwest strips on cross-origin redirects. This issue is fixed in version 2.1.0.
π@cveNotify
GitHub
fix: block redirect header leaks (#936) Β· modelcontextprotocol/rust-sdk@496902b
The official Rust SDK for the Model Context Protocol - fix: block redirect header leaks (#936) Β· modelcontextprotocol/rust-sdk@496902b
π¨ CVE-2026-85469
A flaw was found in quay-builder-qemu. A remote attacker could exploit this by compromising the upstream `Noelware/docker-manifest-action` used in the release workflow, which is pinned to a mutable branch. This allows the attacker to inject arbitrary code, leading to the exfiltration of sensitive registry credentials or the publication of malicious images. The workflow also exposes the default GitHub token, increasing the severity of the compromise.
π@cveNotify
A flaw was found in quay-builder-qemu. A remote attacker could exploit this by compromising the upstream `Noelware/docker-manifest-action` used in the release workflow, which is pinned to a mutable branch. This allows the attacker to inject arbitrary code, leading to the exfiltration of sensitive registry credentials or the publication of malicious images. The workflow also exposes the default GitHub token, increasing the severity of the compromise.
π@cveNotify
Redhat
CVE-2026-85469 - Red Hat Customer Portal
CVE Details App
π¨ CVE-2026-89034
TCH QRing smart ring model R20_B006 running firmware RT09R20_1.00.00_250318 contains an unauthenticated Bluetooth Low Energy access vulnerability that allows any nearby attacker to connect to the device without pairing, authentication, or user approval by exploiting the exposed Nordic UART Service which enforces no client authentication or command authorization. Attackers within Bluetooth Low Energy range can connect directly to the ring, bypassing the official application and cloud authentication, to read battery levels, activate live heart rate monitoring, and retrieve stored historical heart rate and blood oxygen records.
π@cveNotify
TCH QRing smart ring model R20_B006 running firmware RT09R20_1.00.00_250318 contains an unauthenticated Bluetooth Low Energy access vulnerability that allows any nearby attacker to connect to the device without pairing, authentication, or user approval by exploiting the exposed Nordic UART Service which enforces no client authentication or command authorization. Attackers within Bluetooth Low Energy range can connect directly to the ring, bypassing the official application and cloud authentication, to read battery levels, activate live heart rate monitoring, and retrieve stored historical heart rate and blood oxygen records.
π@cveNotify
π¨ CVE-2026-92576
HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the _validate_url() function fails to block internal IP ranges and private addresses. Attackers can send messages instructing the bot to fetch cloud metadata endpoints, localhost services, and RFC 1918 addresses to extract IAM credentials and internal service data.
π@cveNotify
HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the _validate_url() function fails to block internal IP ranges and private addresses. Attackers can send messages instructing the bot to fetch cloud metadata endpoints, localhost services, and RFC 1918 addresses to extract IAM credentials and internal service data.
π@cveNotify
GitHub
ZDI-CAN-29369: Hong Kong University Data Intelligence Lab nanobot WebFetch Server-Side Request Forgery Information Disclosure Vulnerability
ZDI-CAN-29369: Hong Kong University Data Intelligence Lab nanobot WebFetch Server-Side Request Forgery Information Disclosure Vulnerability
-- CVSS -----------------------------------------
9...
-- CVSS -----------------------------------------
9...
π¨ CVE-2026-92577
In AVideo through 29.0, the API get_api_video endpoint contains a broken access control vulnerability in the clean_title branch that returns user-group-restricted videos with owner PII to anonymous callers. Attackers can query videos by their public slug to bypass group restrictions and retrieve sensitive user fields including email, phone, address, birth date, and administrator status.
π@cveNotify
In AVideo through 29.0, the API get_api_video endpoint contains a broken access control vulnerability in the clean_title branch that returns user-group-restricted videos with owner PII to anonymous callers. Attackers can query videos by their public slug to bypass group restrictions and retrieve sensitive user fields including email, phone, address, birth date, and administrator status.
π@cveNotify
GitHub
Broken Access Control: the clean_title branch of get_api_video returns a user-group-restricted video, with the owner's full PIIβ¦
### Summary
`API::get_api_video()` (`plugin/API/API.php:1639`) has two ways of selecting a video. They behave completely differently.
The `videos_id` branch calls `Video::getVideo($id, Video:...
`API::get_api_video()` (`plugin/API/API.php:1639`) has two ways of selecting a video. They behave completely differently.
The `videos_id` branch calls `Video::getVideo($id, Video:...
π¨ CVE-2026-92578
WWBN AVideo through 29.0 contains an authentication bypass vulnerability where the stored password hash is accepted as a valid login credential through two independent code paths in loginFromRequest() and encryptPasswordVerify(). Attackers who obtain the stored users.password hash value can authenticate as any user by submitting the hash directly to login endpoints, completely bypassing password verification.
π@cveNotify
WWBN AVideo through 29.0 contains an authentication bypass vulnerability where the stored password hash is accepted as a valid login credential through two independent code paths in loginFromRequest() and encryptPasswordVerify(). Attackers who obtain the stored users.password hash value can authenticate as any user by submitting the hash directly to login endpoints, completely bypassing password verification.
π@cveNotify
GitHub
Identification and Authentication Failures: the stored password hash is accepted as the password by two independent paths, so anyβ¦
### Summary
Submitting the value of `users.password` as the password logs the account in. No `encodedPass` flag is needed; the ordinary browser login form is enough.
Measured against the admi...
Submitting the value of `users.password` as the password logs the account in. No `encodedPass` flag is needed; the ordinary browser login form is enough.
Measured against the admi...
π¨ CVE-2026-92579
In AVideo through 29.0, the autoCSRFGuard() function maintains a hardcoded allowlist of exempt basenames tested without directory context, allowing plugin files matching core filenames to inherit CSRF exemptions. The LoginWordPress plugin file login.json.php inherits an exemption and unconditionally logs out authenticated users on cross-site POST requests before validating credentials.
π@cveNotify
In AVideo through 29.0, the autoCSRFGuard() function maintains a hardcoded allowlist of exempt basenames tested without directory context, allowing plugin files matching core filenames to inherit CSRF exemptions. The LoginWordPress plugin file login.json.php inherits an exemption and unconditionally logs out authenticated users on cross-site POST requests before validating credentials.
π@cveNotify
GitHub
Broken Access Control: autoCSRFGuard()'s exemption allowlist matches on basename only, so plugin files inherit exemptions writtenβ¦
### Summary
`autoCSRFGuard()` (`objects/functionsSecurity.php:870-972`) keeps a hardcoded list of 28 basenames that are exempt from the same-origin check, and tests membership with:
in_ar...
`autoCSRFGuard()` (`objects/functionsSecurity.php:870-972`) keeps a hardcoded list of 28 basenames that are exempt from the same-origin check, and tests membership with:
in_ar...