๐จ CVE-2026-93567
HTTP/1 authority-form CONNECT is translated to malformed HTTP/2 CONNECT with Host-controlled :authority
๐@cveNotify
HTTP/1 authority-form CONNECT is translated to malformed HTTP/2 CONNECT with Host-controlled :authority
๐@cveNotify
Redhat
CVE-2026-93567 - Red Hat Customer Portal
CVE Details App
๐จ CVE-2026-93568
HTTP/2 and HTTP/3 Extended CONNECT requests are downgraded as regular CONNECT requests
๐@cveNotify
HTTP/2 and HTTP/3 Extended CONNECT requests are downgraded as regular CONNECT requests
๐@cveNotify
Redhat
CVE-2026-93568 - Red Hat Customer Portal
CVE Details App
๐จ CVE-2026-93569
HTTP/1 absolute-form Host mismatch is translated to HTTP/2 :authority, overriding the request-target authority
๐@cveNotify
HTTP/1 absolute-form Host mismatch is translated to HTTP/2 :authority, overriding the request-target authority
๐@cveNotify
Redhat
CVE-2026-93569 - Red Hat Customer Portal
CVE Details App
๐จ CVE-2026-93573
Netty split Transfer-Encoding fields bypass final-chunked validation and enable request smuggling
๐@cveNotify
Netty split Transfer-Encoding fields bypass final-chunked validation and enable request smuggling
๐@cveNotify
Redhat
CVE-2026-93573 - Red Hat Customer Portal
CVE Details App
๐จ CVE-2026-93576
Netty netty-codec-smtp โ SMTP command-name field is not CRLF-validated (incomplete fix of CVE-2025-59419)
๐@cveNotify
Netty netty-codec-smtp โ SMTP command-name field is not CRLF-validated (incomplete fix of CVE-2025-59419)
๐@cveNotify
Redhat
CVE-2026-93576 - Red Hat Customer Portal
CVE Details App
๐จ CVE-2026-93652
Integer overflow in ยตD3TN v0.15.0 TCPCLv3 handshake causes heap overflow, allowing remote attackers to reliably cause DoS
๐@cveNotify
Integer overflow in ยตD3TN v0.15.0 TCPCLv3 handshake causes heap overflow, allowing remote attackers to reliably cause DoS
๐@cveNotify
GitLab
Integer overflow in the TCPCLv3 handshake causes heap overflow (#287) ยท Issues ยท D3TN / ยตD3TN ยท GitLab
This was reported by Andrei Visoiu via email. Thanks! Description The TCPCLv3 code has...
๐จ CVE-2026-93653
A denial of service flaw was found in Poppler's Splash backend. A crafted PDF with tiling-pattern geometry approaching the int32 boundary can cause SplashOutputDev::tilingPatternFill to compute an attacker-controlled repeat count that drives an excessively long loop in the pattern-fill scanline routine, without a corresponding memory allocation. An attacker could exploit this by supplying a malicious PDF to an application that renders it via Poppler's Splash backend, causing the rendering process to consume 100% CPU for an attacker-controlled, extended duration.
๐@cveNotify
A denial of service flaw was found in Poppler's Splash backend. A crafted PDF with tiling-pattern geometry approaching the int32 boundary can cause SplashOutputDev::tilingPatternFill to compute an attacker-controlled repeat count that drives an excessively long loop in the pattern-fill scanline routine, without a corresponding memory allocation. An attacker could exploit this by supplying a malicious PDF to an application that renders it via Poppler's Splash backend, causing the rendering process to consume 100% CPU for an attacker-controlled, extended duration.
๐@cveNotify
Redhat
CVE-2026-93653 - Red Hat Customer Portal
CVE Details App
๐จ CVE-2026-93657
hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and Resolver::lookup_ip() APIs, allowing invalid records to be returned as successful results. Attackers controlling the answering zone or positioned on the network path can have forged DNS records accepted as validated, bypassing DNSSEC authentication checks.
๐@cveNotify
hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and Resolver::lookup_ip() APIs, allowing invalid records to be returned as successful results. Attackers controlling the answering zone or positioned on the network path can have forged DNS records accepted as validated, bypassing DNSSEC authentication checks.
๐@cveNotify
GitHub
GitHub - hickory-dns/hickory-dns: A Rust based DNS client, server, and resolver
A Rust based DNS client, server, and resolver. Contribute to hickory-dns/hickory-dns development by creating an account on GitHub.
๐จ CVE-2026-93658
uutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership changes, allowing privileged users to leave setuid executables owned by the privileged invoker when ownership changes fail. Attackers can execute leftover setuid files with elevated privileges when ownership change operations fail on capability-restricted systems.
๐@cveNotify
uutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership changes, allowing privileged users to leave setuid executables owned by the privileged invoker when ownership changes fail. Attackers can execute leftover setuid files with elevated privileges when ownership change operations fail on capability-restricted systems.
๐@cveNotify
GitHub
GitHub - uutils/coreutils: Cross-platform Rust rewrite of the GNU coreutils
Cross-platform Rust rewrite of the GNU coreutils. Contribute to uutils/coreutils development by creating an account on GitHub.
๐จ CVE-2026-93659
Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and admin views. Unauthenticated attackers can store script payloads in billing name, email, or phone fields that execute in authenticated manager sessions to create rogue accounts or exfiltrate data.
๐@cveNotify
Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and admin views. Unauthenticated attackers can store script payloads in billing name, email, or phone fields that execute in authenticated manager sessions to create rogue accounts or exfiltrate data.
๐@cveNotify
GitHub
GitHub - concretecms-community-store/community_store: An open, free and community developed eCommerce system for Concrete CMS
An open, free and community developed eCommerce system for Concrete CMS - concretecms-community-store/community_store
๐จ CVE-2026-93660
SQLBot through 1.10.1 fails to verify dashboard ownership in update_resource and update_canvas endpoints, allowing authenticated workspace members to modify other users' private dashboards. Attackers can supply arbitrary dashboard IDs to rename dashboards and overwrite component data, canvas styles, and view information belonging to other workspace members.
๐@cveNotify
SQLBot through 1.10.1 fails to verify dashboard ownership in update_resource and update_canvas endpoints, allowing authenticated workspace members to modify other users' private dashboards. Attackers can supply arbitrary dashboard IDs to rename dashboards and overwrite component data, canvas styles, and view information belonging to other workspace members.
๐@cveNotify
GitHub
GitHub - dataease/SQLBot: ๐ฅ ๅบไบๅคงๆจกๅๅ RAG ็ๆบ่ฝ้ฎๆฐ็ณป็ป๏ผๅฏน่ฏๅผๆฐๆฎๅๆ็ฅๅจใText-to-SQL Generation via LLMs using RAG.
๐ฅ ๅบไบๅคงๆจกๅๅ RAG ็ๆบ่ฝ้ฎๆฐ็ณป็ป๏ผๅฏน่ฏๅผๆฐๆฎๅๆ็ฅๅจใText-to-SQL Generation via LLMs using RAG. - dataease/SQLBot
๐จ CVE-2026-93676
xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictions. This allows a sandboxed Flatpak application to intercept broadcast signals on the D-Bus session bus and AT-SPI bus that should be restricted, potentially exposing sensitive information to unauthorized applications.
๐@cveNotify
xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictions. This allows a sandboxed Flatpak application to intercept broadcast signals on the D-Bus session bus and AT-SPI bus that should be restricted, potentially exposing sensitive information to unauthorized applications.
๐@cveNotify
Redhat
CVE-2026-93676 - Red Hat Customer Portal
CVE Details App
๐จ CVE-2026-93685
A flaw was found in the multicluster-observability-addon. A remote attacker can access a debug endpoint without authentication, due to a misconfiguration in the underlying addon-framework library. This allows for the disclosure of sensitive operational information, such as goroutine, heap, and command-line details, after completing a basic encrypted connection. This vulnerability does not enable direct remote code execution.
๐@cveNotify
A flaw was found in the multicluster-observability-addon. A remote attacker can access a debug endpoint without authentication, due to a misconfiguration in the underlying addon-framework library. This allows for the disclosure of sensitive operational information, such as goroutine, heap, and command-line details, after completing a basic encrypted connection. This vulnerability does not enable direct remote code execution.
๐@cveNotify
Redhat
CVE-2026-93685 - Red Hat Customer Portal
CVE Details App
๐จ CVE-2023-1170
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1376.
๐@cveNotify
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1376.
๐@cveNotify
GitHub
patch 9.0.1376: accessing invalid memory with put in Visual block mode ยท vim/vim@1c73b65
Problem: Accessing invalid memory with put in Visual block mode.
Solution: Adjust the cursor column if needed.
Solution: Adjust the cursor column if needed.
๐จ CVE-2023-1175
Incorrect Calculation of Buffer Size in GitHub repository vim/vim prior to 9.0.1378.
๐@cveNotify
Incorrect Calculation of Buffer Size in GitHub repository vim/vim prior to 9.0.1378.
๐@cveNotify
GitHub
patch 9.0.1378: illegal memory access when using virtual editing ยท vim/vim@c99cbf8
Problem: Illegal memory access when using virtual editing.
Solution: Make sure "startspaces" is not negative.
Solution: Make sure "startspaces" is not negative.
๐จ CVE-2023-4734
Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1846.
๐@cveNotify
Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1846.
๐@cveNotify
seclists.org
Full Disclosure: APPLE-SA-10-25-2023-4 macOS Sonoma 14.1
๐จ CVE-2023-4738
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1848.
๐@cveNotify
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1848.
๐@cveNotify
seclists.org
Full Disclosure: APPLE-SA-10-25-2023-4 macOS Sonoma 14.1
๐จ CVE-2026-3438
A reflected cross-site scripting vulnerability exists in Sonatype Nexus Repository versions 3.0.0 through 3.90.2 that allows unauthenticated remote attackers to execute arbitrary JavaScript in a victim's browser through a specially crafted URL. Exploitation requires user interaction.
๐@cveNotify
A reflected cross-site scripting vulnerability exists in Sonatype Nexus Repository versions 3.0.0 through 3.90.2 that allows unauthenticated remote attackers to execute arbitrary JavaScript in a victim's browser through a specially crafted URL. Exploitation requires user interaction.
๐@cveNotify
๐จ CVE-2026-5189
CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated attacker with network access to gain unauthorized read/write access to the internal database and execute arbitrary OS commands as the Nexus process user. Exploitation requires the non-default nexus.orient.binaryListenerEnabled=true configuration to be enabled.
๐@cveNotify
CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated attacker with network access to gain unauthorized read/write access to the internal database and execute arbitrary OS commands as the Nexus process user. Exploitation requires the non-default nexus.orient.binaryListenerEnabled=true configuration to be enabled.
๐@cveNotify
๐จ CVE-2026-23926
An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator widget. This can allow the attacker to perform unauthorized actions depending on which user opens the tooltip.
๐@cveNotify
An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator widget. This can allow the attacker to perform unauthorized actions depending on which user opens the tooltip.
๐@cveNotify