CVE Notify
19.6K subscribers
4 photos
338K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
๐Ÿšจ CVE-2026-93567
HTTP/1 authority-form CONNECT is translated to malformed HTTP/2 CONNECT with Host-controlled :authority

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-93568
HTTP/2 and HTTP/3 Extended CONNECT requests are downgraded as regular CONNECT requests

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-93569
HTTP/1 absolute-form Host mismatch is translated to HTTP/2 :authority, overriding the request-target authority

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-93573
Netty split Transfer-Encoding fields bypass final-chunked validation and enable request smuggling

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-93576
Netty netty-codec-smtp โ€” SMTP command-name field is not CRLF-validated (incomplete fix of CVE-2025-59419)

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-93653
A denial of service flaw was found in Poppler's Splash backend. A crafted PDF with tiling-pattern geometry approaching the int32 boundary can cause SplashOutputDev::tilingPatternFill to compute an attacker-controlled repeat count that drives an excessively long loop in the pattern-fill scanline routine, without a corresponding memory allocation. An attacker could exploit this by supplying a malicious PDF to an application that renders it via Poppler's Splash backend, causing the rendering process to consume 100% CPU for an attacker-controlled, extended duration.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-93657
hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and Resolver::lookup_ip() APIs, allowing invalid records to be returned as successful results. Attackers controlling the answering zone or positioned on the network path can have forged DNS records accepted as validated, bypassing DNSSEC authentication checks.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-93658
uutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership changes, allowing privileged users to leave setuid executables owned by the privileged invoker when ownership changes fail. Attackers can execute leftover setuid files with elevated privileges when ownership change operations fail on capability-restricted systems.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-93659
Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and admin views. Unauthenticated attackers can store script payloads in billing name, email, or phone fields that execute in authenticated manager sessions to create rogue accounts or exfiltrate data.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-93676
xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictions. This allows a sandboxed Flatpak application to intercept broadcast signals on the D-Bus session bus and AT-SPI bus that should be restricted, potentially exposing sensitive information to unauthorized applications.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-93685
A flaw was found in the multicluster-observability-addon. A remote attacker can access a debug endpoint without authentication, due to a misconfiguration in the underlying addon-framework library. This allows for the disclosure of sensitive operational information, such as goroutine, heap, and command-line details, after completing a basic encrypted connection. This vulnerability does not enable direct remote code execution.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2023-4734
Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1846.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2023-4738
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1848.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2023-4733
Use After Free in GitHub repository vim/vim prior to 9.0.1840.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-3438
A reflected cross-site scripting vulnerability exists in Sonatype Nexus Repository versions 3.0.0 through 3.90.2 that allows unauthenticated remote attackers to execute arbitrary JavaScript in a victim's browser through a specially crafted URL. Exploitation requires user interaction.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-5189
CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated attacker with network access to gain unauthorized read/write access to the internal database and execute arbitrary OS commands as the Nexus process user. Exploitation requires the non-default nexus.orient.binaryListenerEnabled=true configuration to be enabled.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-23926
An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator widget. This can allow the attacker to perform unauthorized actions depending on which user opens the tooltip.

๐ŸŽ–@cveNotify