๐จ CVE-2026-77928
ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability that allows authenticated users to extract arbitrary database contents by submitting the msg_id parameter as an array to bypass the clean_requests() sanitization function in ClipBucket.class.php. Attackers can pass unsanitized array elements through the deletion handler in private_message.php into cb_pm::delete_msg(), which interpolates the unescaped message ID directly into a SQL query string, enabling time-based blind SQL injection to retrieve all user credential hashes and email addresses.
๐@cveNotify
ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability that allows authenticated users to extract arbitrary database contents by submitting the msg_id parameter as an array to bypass the clean_requests() sanitization function in ClipBucket.class.php. Attackers can pass unsanitized array elements through the deletion handler in private_message.php into cb_pm::delete_msg(), which interpolates the unescaped message ID directly into a SQL query string, enabling time-based blind SQL injection to retrieve all user credential hashes and email addresses.
๐@cveNotify
GitHub
Miscellaneous : Fix possible SQL injection (Thanks @QwesiRED !), Cleaโฆ ยท MacWarrior/clipbucket-v5@85907c5
โฆnup code
---------
Co-authored-by: MacWarrior <macwarrior94@gmail.com>
---------
Co-authored-by: MacWarrior <macwarrior94@gmail.com>
๐จ CVE-2026-77929
ClipBucket v5 before 5.5.3-#182 contains a file upload vulnerability that allows authenticated users to achieve remote code execution by uploading a PHP file with valid image magic bytes through the photo upload endpoint. The FileUpload::manageFile() function in fileupload.class.php fails to update the file extension after MIME validation, allowing an attacker-controlled .php extension to persist on disk and execute as PHP via PHP-FPM when the uploaded file is retrieved.
๐@cveNotify
ClipBucket v5 before 5.5.3-#182 contains a file upload vulnerability that allows authenticated users to achieve remote code execution by uploading a PHP file with valid image magic bytes through the photo upload endpoint. The FileUpload::manageFile() function in fileupload.class.php fails to update the file extension after MIME validation, allowing an attacker-controlled .php extension to persist on disk and execute as PHP via PHP-FPM when the uploaded file is retrieved.
๐@cveNotify
GitHub
Miscellaneous : Fix possible RCE (Thanks @QwesiRED !), Fix nginx vhosโฆ ยท MacWarrior/clipbucket-v5@61cce55
โฆt rules, Fix .htaccess rules
---------
Co-authored-by: MacWarrior <macwarrior94@gmail.com>
---------
Co-authored-by: MacWarrior <macwarrior94@gmail.com>
๐จ CVE-2026-85511
A flaw was found in EAP's Elytron. An EAP application whose security domain is backed by an Elytron token-realm with oauth2-introspection would allow parameter substitution due to missing URL encoding.
๐@cveNotify
A flaw was found in EAP's Elytron. An EAP application whose security domain is backed by an Elytron token-realm with oauth2-introspection would allow parameter substitution due to missing URL encoding.
๐@cveNotify
Redhat
CVE-2026-85511 - Red Hat Customer Portal
CVE Details App
๐จ CVE-2026-93505
A vulnerability was found in SveltyCMS 0.0.6. This vulnerability affects unknown code of the file src/utils/media/media-service.server.ts of the component SVG Media Upload. Performing a manipulation results in cross site scripting. The attack can be initiated remotely. The patch is named 05b4f9efeb79e9d72a693232334d7529687f896f. Applying a patch is the recommended action to fix this issue.
๐@cveNotify
A vulnerability was found in SveltyCMS 0.0.6. This vulnerability affects unknown code of the file src/utils/media/media-service.server.ts of the component SVG Media Upload. Performing a manipulation results in cross site scripting. The attack can be initiated remotely. The patch is named 05b4f9efeb79e9d72a693232334d7529687f896f. Applying a patch is the recommended action to fix this issue.
๐@cveNotify
GitHub
GitHub - SveltyCMS/SveltyCMS: SveltyCMS is a headless CMS. Built with modern and lightweight SvelteKit, This CMS is designed forโฆ
SveltyCMS is a headless CMS. Built with modern and lightweight SvelteKit, This CMS is designed for speed, flexibility, and scalability. Perfect for developers looking for a fast & fully cu...
๐จ CVE-2026-93558
Unbounded Per-Connection Queue Growth in WebSocketServerExtensionHandler Leads to Denial of Service
๐@cveNotify
Unbounded Per-Connection Queue Growth in WebSocketServerExtensionHandler Leads to Denial of Service
๐@cveNotify
๐จ CVE-2026-93564
HAProxy PROXY-v2 nested-TLV grandchild ByteBuf reference-count leak (incomplete fix of PR #16881)
๐@cveNotify
HAProxy PROXY-v2 nested-TLV grandchild ByteBuf reference-count leak (incomplete fix of PR #16881)
๐@cveNotify
๐จ CVE-2026-93565
### Summary
`RtspMethods.valueOf()` silently strips trailing control bytes (any character with code point <= 0x20, the full range that `String.trim()` removes) before performing a cache lookup against its ten pre-populated method constants. A wire-delivered RTSP request whose method token ends with a trailing control byte โ for example `PLAY\x00` or `PLAY\r`, immediately before the separating space โ is decoded by `RtspDecoder` as a fully successful PLAY request, with `decoderResult().isSuccess() == true and request.method() == RtspMethods.PLAY` (same object reference as the cached singleton). The application layer cannot distinguish this from a clean
`PLAY` request.
This is the same root cause as #16723 and #16971, in a sibling that those fixes did not reach. The fix for `HttpMethod` hardened `HttpMethod.valueOf()` directly, but `RtspMethods.valueOf()` has its own independent `checkNonEmptyAfterTrim()` call that runs before the cache lookup โ meaning a trailing-control-byte token hits the cache before the hardened `HttpMethod` constructor ever sees it.
### Reproduction
Minimal wire-level reproduction
Send the following raw bytes to any Netty-based RTSP server using R
๐@cveNotify
### Summary
`RtspMethods.valueOf()` silently strips trailing control bytes (any character with code point <= 0x20, the full range that `String.trim()` removes) before performing a cache lookup against its ten pre-populated method constants. A wire-delivered RTSP request whose method token ends with a trailing control byte โ for example `PLAY\x00` or `PLAY\r`, immediately before the separating space โ is decoded by `RtspDecoder` as a fully successful PLAY request, with `decoderResult().isSuccess() == true and request.method() == RtspMethods.PLAY` (same object reference as the cached singleton). The application layer cannot distinguish this from a clean
`PLAY` request.
This is the same root cause as #16723 and #16971, in a sibling that those fixes did not reach. The fix for `HttpMethod` hardened `HttpMethod.valueOf()` directly, but `RtspMethods.valueOf()` has its own independent `checkNonEmptyAfterTrim()` call that runs before the cache lookup โ meaning a trailing-control-byte token hits the cache before the hardened `HttpMethod` constructor ever sees it.
### Reproduction
Minimal wire-level reproduction
Send the following raw bytes to any Netty-based RTSP server using R
๐@cveNotify
๐จ CVE-2026-93566
### Summary
Netty skips strict chunk size line validation when the line has no chunk extension (`;`), so a chunk size line containing an embedded bare CR (e.g. `0\rX`) is accepted instead of rejected, enabling HTTP request smuggling.
### Details
`io.netty.handler.codec.http.HttpObjectDecoder#checkChunkExtensions` only runs the strict validator `HttpChunkLineValidatingByteProcessor` when a `;` is present:
```java
int extensionsStart = line.bytesBefore((byte) ';');
if (extensionsStart == -1) {
return;
}
```
According to RFC 9112 https://datatracker.ietf.org/doc/html/rfc9112#appendix-A
`chunk-size = 1*HEXDIG`
### PoC
```java
@Test
public void test() {
String requestStr = "POST / HTTP/1.1\r\n" +
"Host: localhost\r\n" +
"Transfer-Encoding: chunked\r\n\r\n" +
"0\rX\r\n" +
"\r\n" +
"GET /smuggled HTTP/1.1\r\n" +
"Host: localhost\r\n" +
"Content-Length: 0\r\n" +
"\r\n";
EmbeddedChannel channel = new EmbeddedChannel(new HttpRequestDecoder());
assertTrue(channel.writeInbound(Unpooled.copiedBuffer(requestStr, Ch
๐@cveNotify
### Summary
Netty skips strict chunk size line validation when the line has no chunk extension (`;`), so a chunk size line containing an embedded bare CR (e.g. `0\rX`) is accepted instead of rejected, enabling HTTP request smuggling.
### Details
`io.netty.handler.codec.http.HttpObjectDecoder#checkChunkExtensions` only runs the strict validator `HttpChunkLineValidatingByteProcessor` when a `;` is present:
```java
int extensionsStart = line.bytesBefore((byte) ';');
if (extensionsStart == -1) {
return;
}
```
According to RFC 9112 https://datatracker.ietf.org/doc/html/rfc9112#appendix-A
`chunk-size = 1*HEXDIG`
### PoC
```java
@Test
public void test() {
String requestStr = "POST / HTTP/1.1\r\n" +
"Host: localhost\r\n" +
"Transfer-Encoding: chunked\r\n\r\n" +
"0\rX\r\n" +
"\r\n" +
"GET /smuggled HTTP/1.1\r\n" +
"Host: localhost\r\n" +
"Content-Length: 0\r\n" +
"\r\n";
EmbeddedChannel channel = new EmbeddedChannel(new HttpRequestDecoder());
assertTrue(channel.writeInbound(Unpooled.copiedBuffer(requestStr, Ch
๐@cveNotify
๐จ CVE-2026-93567
HTTP/1 authority-form CONNECT is translated to malformed HTTP/2 CONNECT with Host-controlled :authority
๐@cveNotify
HTTP/1 authority-form CONNECT is translated to malformed HTTP/2 CONNECT with Host-controlled :authority
๐@cveNotify
Redhat
CVE-2026-93567 - Red Hat Customer Portal
CVE Details App
๐จ CVE-2026-93568
HTTP/2 and HTTP/3 Extended CONNECT requests are downgraded as regular CONNECT requests
๐@cveNotify
HTTP/2 and HTTP/3 Extended CONNECT requests are downgraded as regular CONNECT requests
๐@cveNotify
Redhat
CVE-2026-93568 - Red Hat Customer Portal
CVE Details App
๐จ CVE-2026-93569
HTTP/1 absolute-form Host mismatch is translated to HTTP/2 :authority, overriding the request-target authority
๐@cveNotify
HTTP/1 absolute-form Host mismatch is translated to HTTP/2 :authority, overriding the request-target authority
๐@cveNotify
Redhat
CVE-2026-93569 - Red Hat Customer Portal
CVE Details App
๐จ CVE-2026-93573
Netty split Transfer-Encoding fields bypass final-chunked validation and enable request smuggling
๐@cveNotify
Netty split Transfer-Encoding fields bypass final-chunked validation and enable request smuggling
๐@cveNotify
Redhat
CVE-2026-93573 - Red Hat Customer Portal
CVE Details App
๐จ CVE-2026-93576
Netty netty-codec-smtp โ SMTP command-name field is not CRLF-validated (incomplete fix of CVE-2025-59419)
๐@cveNotify
Netty netty-codec-smtp โ SMTP command-name field is not CRLF-validated (incomplete fix of CVE-2025-59419)
๐@cveNotify
Redhat
CVE-2026-93576 - Red Hat Customer Portal
CVE Details App
๐จ CVE-2026-93652
Integer overflow in ยตD3TN v0.15.0 TCPCLv3 handshake causes heap overflow, allowing remote attackers to reliably cause DoS
๐@cveNotify
Integer overflow in ยตD3TN v0.15.0 TCPCLv3 handshake causes heap overflow, allowing remote attackers to reliably cause DoS
๐@cveNotify
GitLab
Integer overflow in the TCPCLv3 handshake causes heap overflow (#287) ยท Issues ยท D3TN / ยตD3TN ยท GitLab
This was reported by Andrei Visoiu via email. Thanks! Description The TCPCLv3 code has...
๐จ CVE-2026-93653
A denial of service flaw was found in Poppler's Splash backend. A crafted PDF with tiling-pattern geometry approaching the int32 boundary can cause SplashOutputDev::tilingPatternFill to compute an attacker-controlled repeat count that drives an excessively long loop in the pattern-fill scanline routine, without a corresponding memory allocation. An attacker could exploit this by supplying a malicious PDF to an application that renders it via Poppler's Splash backend, causing the rendering process to consume 100% CPU for an attacker-controlled, extended duration.
๐@cveNotify
A denial of service flaw was found in Poppler's Splash backend. A crafted PDF with tiling-pattern geometry approaching the int32 boundary can cause SplashOutputDev::tilingPatternFill to compute an attacker-controlled repeat count that drives an excessively long loop in the pattern-fill scanline routine, without a corresponding memory allocation. An attacker could exploit this by supplying a malicious PDF to an application that renders it via Poppler's Splash backend, causing the rendering process to consume 100% CPU for an attacker-controlled, extended duration.
๐@cveNotify
Redhat
CVE-2026-93653 - Red Hat Customer Portal
CVE Details App
๐จ CVE-2026-93657
hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and Resolver::lookup_ip() APIs, allowing invalid records to be returned as successful results. Attackers controlling the answering zone or positioned on the network path can have forged DNS records accepted as validated, bypassing DNSSEC authentication checks.
๐@cveNotify
hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and Resolver::lookup_ip() APIs, allowing invalid records to be returned as successful results. Attackers controlling the answering zone or positioned on the network path can have forged DNS records accepted as validated, bypassing DNSSEC authentication checks.
๐@cveNotify
GitHub
GitHub - hickory-dns/hickory-dns: A Rust based DNS client, server, and resolver
A Rust based DNS client, server, and resolver. Contribute to hickory-dns/hickory-dns development by creating an account on GitHub.
๐จ CVE-2026-93658
uutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership changes, allowing privileged users to leave setuid executables owned by the privileged invoker when ownership changes fail. Attackers can execute leftover setuid files with elevated privileges when ownership change operations fail on capability-restricted systems.
๐@cveNotify
uutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership changes, allowing privileged users to leave setuid executables owned by the privileged invoker when ownership changes fail. Attackers can execute leftover setuid files with elevated privileges when ownership change operations fail on capability-restricted systems.
๐@cveNotify
GitHub
GitHub - uutils/coreutils: Cross-platform Rust rewrite of the GNU coreutils
Cross-platform Rust rewrite of the GNU coreutils. Contribute to uutils/coreutils development by creating an account on GitHub.
๐จ CVE-2026-93659
Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and admin views. Unauthenticated attackers can store script payloads in billing name, email, or phone fields that execute in authenticated manager sessions to create rogue accounts or exfiltrate data.
๐@cveNotify
Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and admin views. Unauthenticated attackers can store script payloads in billing name, email, or phone fields that execute in authenticated manager sessions to create rogue accounts or exfiltrate data.
๐@cveNotify
GitHub
GitHub - concretecms-community-store/community_store: An open, free and community developed eCommerce system for Concrete CMS
An open, free and community developed eCommerce system for Concrete CMS - concretecms-community-store/community_store
๐จ CVE-2026-93660
SQLBot through 1.10.1 fails to verify dashboard ownership in update_resource and update_canvas endpoints, allowing authenticated workspace members to modify other users' private dashboards. Attackers can supply arbitrary dashboard IDs to rename dashboards and overwrite component data, canvas styles, and view information belonging to other workspace members.
๐@cveNotify
SQLBot through 1.10.1 fails to verify dashboard ownership in update_resource and update_canvas endpoints, allowing authenticated workspace members to modify other users' private dashboards. Attackers can supply arbitrary dashboard IDs to rename dashboards and overwrite component data, canvas styles, and view information belonging to other workspace members.
๐@cveNotify
GitHub
GitHub - dataease/SQLBot: ๐ฅ ๅบไบๅคงๆจกๅๅ RAG ็ๆบ่ฝ้ฎๆฐ็ณป็ป๏ผๅฏน่ฏๅผๆฐๆฎๅๆ็ฅๅจใText-to-SQL Generation via LLMs using RAG.
๐ฅ ๅบไบๅคงๆจกๅๅ RAG ็ๆบ่ฝ้ฎๆฐ็ณป็ป๏ผๅฏน่ฏๅผๆฐๆฎๅๆ็ฅๅจใText-to-SQL Generation via LLMs using RAG. - dataease/SQLBot
๐จ CVE-2026-93676
xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictions. This allows a sandboxed Flatpak application to intercept broadcast signals on the D-Bus session bus and AT-SPI bus that should be restricted, potentially exposing sensitive information to unauthorized applications.
๐@cveNotify
xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictions. This allows a sandboxed Flatpak application to intercept broadcast signals on the D-Bus session bus and AT-SPI bus that should be restricted, potentially exposing sensitive information to unauthorized applications.
๐@cveNotify
Redhat
CVE-2026-93676 - Red Hat Customer Portal
CVE Details App
๐จ CVE-2026-93685
A flaw was found in the multicluster-observability-addon. A remote attacker can access a debug endpoint without authentication, due to a misconfiguration in the underlying addon-framework library. This allows for the disclosure of sensitive operational information, such as goroutine, heap, and command-line details, after completing a basic encrypted connection. This vulnerability does not enable direct remote code execution.
๐@cveNotify
A flaw was found in the multicluster-observability-addon. A remote attacker can access a debug endpoint without authentication, due to a misconfiguration in the underlying addon-framework library. This allows for the disclosure of sensitive operational information, such as goroutine, heap, and command-line details, after completing a basic encrypted connection. This vulnerability does not enable direct remote code execution.
๐@cveNotify
Redhat
CVE-2026-93685 - Red Hat Customer Portal
CVE Details App