CVE Notify
19.6K subscribers
4 photos
338K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
๐Ÿšจ CVE-2026-25684
A file type attribution issue in Zscaler Internet Access File Type Control evaluation rules may allow improper evaluation of File Type Control policies in rare circumstances.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-77927
ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability that allows authenticated users to extract arbitrary data from the database by submitting the check_photo parameter as an array to bypass the clean_requests() sanitization function in ClipBucket.class.php. Attackers can pass unsanitized array elements through the bulk deletion handler in manage_photos.php to photo_exists() in photos.class.php, where non-numeric values are interpolated directly into a SQL query, enabling time-based blind SQL injection to retrieve credential hashes and other sensitive data.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-77928
ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability that allows authenticated users to extract arbitrary database contents by submitting the msg_id parameter as an array to bypass the clean_requests() sanitization function in ClipBucket.class.php. Attackers can pass unsanitized array elements through the deletion handler in private_message.php into cb_pm::delete_msg(), which interpolates the unescaped message ID directly into a SQL query string, enabling time-based blind SQL injection to retrieve all user credential hashes and email addresses.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-77929
ClipBucket v5 before 5.5.3-#182 contains a file upload vulnerability that allows authenticated users to achieve remote code execution by uploading a PHP file with valid image magic bytes through the photo upload endpoint. The FileUpload::manageFile() function in fileupload.class.php fails to update the file extension after MIME validation, allowing an attacker-controlled .php extension to persist on disk and execute as PHP via PHP-FPM when the uploaded file is retrieved.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-85511
A flaw was found in EAP's Elytron. An EAP application whose security domain is backed by an Elytron token-realm with oauth2-introspection would allow parameter substitution due to missing URL encoding.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-93505
A vulnerability was found in SveltyCMS 0.0.6. This vulnerability affects unknown code of the file src/utils/media/media-service.server.ts of the component SVG Media Upload. Performing a manipulation results in cross site scripting. The attack can be initiated remotely. The patch is named 05b4f9efeb79e9d72a693232334d7529687f896f. Applying a patch is the recommended action to fix this issue.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-93558
Unbounded Per-Connection Queue Growth in WebSocketServerExtensionHandler Leads to Denial of Service

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-93564
HAProxy PROXY-v2 nested-TLV grandchild ByteBuf reference-count leak (incomplete fix of PR #16881)

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-93565
### Summary
`RtspMethods.valueOf()` silently strips trailing control bytes (any character with code point <= 0x20, the full range that `String.trim()` removes) before performing a cache lookup against its ten pre-populated method constants. A wire-delivered RTSP request whose method token ends with a trailing control byte โ€” for example `PLAY\x00` or `PLAY\r`, immediately before the separating space โ€” is decoded by `RtspDecoder` as a fully successful PLAY request, with `decoderResult().isSuccess() == true and request.method() == RtspMethods.PLAY` (same object reference as the cached singleton). The application layer cannot distinguish this from a clean
`PLAY` request.

This is the same root cause as #16723 and #16971, in a sibling that those fixes did not reach. The fix for `HttpMethod` hardened `HttpMethod.valueOf()` directly, but `RtspMethods.valueOf()` has its own independent `checkNonEmptyAfterTrim()` call that runs before the cache lookup โ€” meaning a trailing-control-byte token hits the cache before the hardened `HttpMethod` constructor ever sees it.

### Reproduction

Minimal wire-level reproduction

Send the following raw bytes to any Netty-based RTSP server using R

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-93566
### Summary
Netty skips strict chunk size line validation when the line has no chunk extension (`;`), so a chunk size line containing an embedded bare CR (e.g. `0\rX`) is accepted instead of rejected, enabling HTTP request smuggling.

### Details
`io.netty.handler.codec.http.HttpObjectDecoder#checkChunkExtensions` only runs the strict validator `HttpChunkLineValidatingByteProcessor` when a `;` is present:

```java
int extensionsStart = line.bytesBefore((byte) ';');
if (extensionsStart == -1) {
return;
}
```

According to RFC 9112 https://datatracker.ietf.org/doc/html/rfc9112#appendix-A

`chunk-size = 1*HEXDIG`

### PoC

```java
@Test
public void test() {
String requestStr = "POST / HTTP/1.1\r\n" +
"Host: localhost\r\n" +
"Transfer-Encoding: chunked\r\n\r\n" +
"0\rX\r\n" +
"\r\n" +
"GET /smuggled HTTP/1.1\r\n" +
"Host: localhost\r\n" +
"Content-Length: 0\r\n" +
"\r\n";

EmbeddedChannel channel = new EmbeddedChannel(new HttpRequestDecoder());
assertTrue(channel.writeInbound(Unpooled.copiedBuffer(requestStr, Ch

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-93567
HTTP/1 authority-form CONNECT is translated to malformed HTTP/2 CONNECT with Host-controlled :authority

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-93568
HTTP/2 and HTTP/3 Extended CONNECT requests are downgraded as regular CONNECT requests

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-93569
HTTP/1 absolute-form Host mismatch is translated to HTTP/2 :authority, overriding the request-target authority

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-93573
Netty split Transfer-Encoding fields bypass final-chunked validation and enable request smuggling

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-93576
Netty netty-codec-smtp โ€” SMTP command-name field is not CRLF-validated (incomplete fix of CVE-2025-59419)

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-93653
A denial of service flaw was found in Poppler's Splash backend. A crafted PDF with tiling-pattern geometry approaching the int32 boundary can cause SplashOutputDev::tilingPatternFill to compute an attacker-controlled repeat count that drives an excessively long loop in the pattern-fill scanline routine, without a corresponding memory allocation. An attacker could exploit this by supplying a malicious PDF to an application that renders it via Poppler's Splash backend, causing the rendering process to consume 100% CPU for an attacker-controlled, extended duration.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-93657
hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and Resolver::lookup_ip() APIs, allowing invalid records to be returned as successful results. Attackers controlling the answering zone or positioned on the network path can have forged DNS records accepted as validated, bypassing DNSSEC authentication checks.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-93658
uutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership changes, allowing privileged users to leave setuid executables owned by the privileged invoker when ownership changes fail. Attackers can execute leftover setuid files with elevated privileges when ownership change operations fail on capability-restricted systems.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-93659
Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and admin views. Unauthenticated attackers can store script payloads in billing name, email, or phone fields that execute in authenticated manager sessions to create rogue accounts or exfiltrate data.

๐ŸŽ–@cveNotify