π¨ CVE-2026-96746
An out-of-bounds write in the connection-monitoring logic of the MongoDB C Driver may allow an unauthenticated party who controls name resolution and the responses of the hosts named in a client's connection string to write beyond the end of a heap buffer. This may cause the application using the driver to terminate unexpectedly.
π@cveNotify
An out-of-bounds write in the connection-monitoring logic of the MongoDB C Driver may allow an unauthenticated party who controls name resolution and the responses of the hosts named in a client's connection string to write beyond the end of a heap buffer. This may cause the application using the driver to terminate unexpectedly.
π@cveNotify
GitHub
Release mongo-c-driver 1.30.12 Β· mongodb/mongo-c-driver
Announcing 1.30.12 of libbson and libmongoc, the libraries constituting the MongoDB C Driver.
libbson
No changes since 1.30.11. Version incremented to match the libmongoc version.
libmongoc
Fixes
...
libbson
No changes since 1.30.11. Version incremented to match the libmongoc version.
libmongoc
Fixes
...
π¨ CVE-2026-96750
MongoDB Compass can interpolate a database name without escaping into the initial input of its embedded MongoDB shell when a user opens the shell from that database's view. A user with privileges to create databases on a server that a Compass user connects to may, under specific conditions, have content evaluated as shell input within the Compass process, with that process's privileges. This requires the Compass user to open the shell for the affected database.
π@cveNotify
MongoDB Compass can interpolate a database name without escaping into the initial input of its embedded MongoDB shell when a user opens the shell from that database's view. A user with privileges to create databases on a server that a Compass user connects to may, under specific conditions, have content evaluated as shell input within the Compass process, with that process's privileges. This requires the Compass user to open the shell for the affected database.
π@cveNotify
GitHub
Release 1.49.12 Β· mongodb-js/compass
Release v1.49.12
What's Changed
New Features
feat(compass-editor): add hover styling to autocomplete dropdown item COMPASS-8227
Bug Fixes
fix(import-export): better escape for csv values COM...
What's Changed
New Features
feat(compass-editor): add hover styling to autocomplete dropdown item COMPASS-8227
Bug Fixes
fix(import-export): better escape for csv values COM...
π¨ CVE-2026-97226
A vulnerability has been found in DbGate up to 7.2.5/7.3.1-premium-beta.1. This impacts the function fs.readFile of the file packages/api/src/controllers/files.js of the component files-style Endpoint. The manipulation of the argument filePath/uri leads to path traversal. It is possible to initiate the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way.
π@cveNotify
A vulnerability has been found in DbGate up to 7.2.5/7.3.1-premium-beta.1. This impacts the function fs.readFile of the file packages/api/src/controllers/files.js of the component files-style Endpoint. The manipulation of the argument filePath/uri leads to path traversal. It is possible to initiate the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way.
π@cveNotify
Vulnerability Database
CVE-2026-97226 in DbGate
A vulnerability has been found in DbGate up to 7.2.5/7.3.1-premium-beta.1. This vulnerability is traded as CVE-2026-97226.
π¨ CVE-2026-47132
phpMyFAQ is an open source FAQ web application. Prior to version 4.2.0-alpha, an authenticated SQL LIKE wildcard injection vulnerability in phpMyFAQβs chat user search allows any logged-in user to bypass the intended display-name search filter and enumerate active users. The endpoint escapes SQL string syntax but does not escape `%` and `_`, which remain active `LIKE` wildcards. Version 4.2.0-alpha patches the issue.
π@cveNotify
phpMyFAQ is an open source FAQ web application. Prior to version 4.2.0-alpha, an authenticated SQL LIKE wildcard injection vulnerability in phpMyFAQβs chat user search allows any logged-in user to bypass the intended display-name search filter and enumerate active users. The endpoint escapes SQL string syntax but does not escape `%` and `_`, which remain active `LIKE` wildcards. Version 4.2.0-alpha patches the issue.
π@cveNotify
GitHub
fix: hardened query Β· thorsten/phpMyFAQ@bd4b08b
phpMyFAQ - Open Source FAQ web application for PHP 8.4+ and MySQL, PostgreSQL and other databases - fix: hardened query Β· thorsten/phpMyFAQ@bd4b08b
π¨ CVE-2026-62368
Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a user with the customfields.create permission can store markup in CustomField.name, and app/Presenters/AssetPresenter.php assigns that value as an unescaped bootstrap-table header title. When another user opens an asset-list page associated with the fieldset, the stored markup executes on page load in that user's Snipe-IT session. This can expose same-origin data and perform authenticated actions with the victim's privileges, including privilege escalation when a superuser views the affected list. This issue is fixed in version 8.7.0.
π@cveNotify
Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a user with the customfields.create permission can store markup in CustomField.name, and app/Presenters/AssetPresenter.php assigns that value as an unescaped bootstrap-table header title. When another user opens an asset-list page associated with the fieldset, the stored markup executes on page load in that user's Snipe-IT session. This can expose same-origin data and perform authenticated actions with the victim's privileges, including privilege escalation when a superuser views the affected list. This issue is fixed in version 8.7.0.
π@cveNotify
GitHub
Fixed FD-56252: escape fieldname in custom fields Β· grokability/snipe-it@58754e4
A free open source IT asset/license management system - Fixed FD-56252: escape fieldname in custom fields Β· grokability/snipe-it@58754e4
π¨ CVE-2026-79763
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.4.0 until 2.5.1, the POST /users/totp/disable and POST /users/totp/backup-codes endpoints accept the account password as the sole reauthentication factor after a 2.4.0 refactor regressed the two-factor check introduced for CVE-2026-45749. In src/backend/database/routes/user-totp-routes.ts, verifyTotpReauth returns success when bcrypt.compare validates the password, while each endpoint chooses password or totp_code as an interchangeable credential. An attacker who has a victim's authenticated session and knows the password can disable TOTP or regenerate and invalidate backup codes without an authenticator or valid second factor, weakening the account to single-factor authentication. This issue is fixed in version 2.5.1.
π@cveNotify
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.4.0 until 2.5.1, the POST /users/totp/disable and POST /users/totp/backup-codes endpoints accept the account password as the sole reauthentication factor after a 2.4.0 refactor regressed the two-factor check introduced for CVE-2026-45749. In src/backend/database/routes/user-totp-routes.ts, verifyTotpReauth returns success when bcrypt.compare validates the password, while each endpoint chooses password or totp_code as an interchangeable credential. An attacker who has a victim's authenticated session and knows the password can disable TOTP or regenerate and invalidate backup codes without an authenticator or valid second factor, weakening the account to single-factor authentication. This issue is fixed in version 2.5.1.
π@cveNotify
GitHub
Merge commit from fork Β· Termix-SSH/Termix@22124e1
Self-hosted SSH and remote desktop management. Contribute to Termix-SSH/Termix development by creating an account on GitHub.
π¨ CVE-2026-79764
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.5.0 until 2.5.1, the /homepage/proxy endpoint accepts an authenticated user's url query parameter and passes it to http.get or https.get without destination restrictions. In src/backend/database/routes/homepage-proxy-routes.ts, new URL performs only syntactic validation, allowing requests to loopback, RFC1918, link-local, and cloud metadata destinations. The endpoint returns the complete fetched JSON response, so a low-privilege or self-registered account can exfiltrate internal service data and cloud credentials. This issue is fixed in version 2.5.1.
π@cveNotify
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.5.0 until 2.5.1, the /homepage/proxy endpoint accepts an authenticated user's url query parameter and passes it to http.get or https.get without destination restrictions. In src/backend/database/routes/homepage-proxy-routes.ts, new URL performs only syntactic validation, allowing requests to loopback, RFC1918, link-local, and cloud metadata destinations. The endpoint returns the complete fetched JSON response, so a low-privilege or self-registered account can exfiltrate internal service data and cloud credentials. This issue is fixed in version 2.5.1.
π@cveNotify
GitHub
Merge commit from fork Β· Termix-SSH/Termix@4b2a60a
Self-hosted SSH and remote desktop management. Contribute to Termix-SSH/Termix development by creating an account on GitHub.
π¨ CVE-2026-84302
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, Discourse AI reviewables associated with private messages could appear in the moderator review queue of a moderator who was not a participant in the message. Reviewable visibility filtering did not restrict private-message reviewables to the audience permitted to access the underlying private-message topic, allowing the moderator to read otherwise confidential content. Depending on the available reviewable action, the moderator could also modify the private message by closing its topic or deleting a post. Exploitation requires an authenticated moderator account and a pre-existing Discourse AI reviewable associated with a private message. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.
π@cveNotify
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, Discourse AI reviewables associated with private messages could appear in the moderator review queue of a moderator who was not a participant in the message. Reviewable visibility filtering did not restrict private-message reviewables to the audience permitted to access the underlying private-message topic, allowing the moderator to read otherwise confidential content. Depending on the available reviewable action, the moderator could also modify the private message by closing its topic or deleting a post. Exploitation requires an authenticated moderator account and a pre-existing Discourse AI reviewable associated with a private message. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.
π@cveNotify
GitHub
SECURITY: Scope PM reviewables to their allowed audience Β· discourse/discourse@1566d04
A platform for community discussion. Free, open, simple. - SECURITY: Scope PM reviewables to their allowed audience Β· discourse/discourse@1566d04
π¨ CVE-2026-88372
libsndfile 1.2.2 contains an integer overflow vulnerability in mat4_read_header() when parsing crafted MAT4 (MATLAB v4) files.
π@cveNotify
libsndfile 1.2.2 contains an integer overflow vulnerability in mat4_read_header() when parsing crafted MAT4 (MATLAB v4) files.
π@cveNotify
GitHub
[Bug]signed integer overflow in mat4_read_header while validating a crafted MAT4 (MATLAB v4) file (CWE-190) Β· Issue #1151 Β· liβ¦
Summary mat4_read_header reads attacker-controlled rows/cols fields straight from the MAT4 file header (stored as raw 32-bit fields) and then evaluates channels * frames * bytewidth (mat4.c:318/322...
π¨ CVE-2026-91122
Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the video placeholder component allowed crafted HTML to cause an attribute breakout and inject an attacker-controlled event handler. An authenticated user with default trust-level posting privileges could store the crafted placeholder in a post. When another user opened the post and clicked the video play overlay, the handler could execute arbitrary JavaScript in the viewer's session. Default Content Security Policy settings block inline event handlers, but instances with CSP disabled or relaxed could allow the script to read page content and make authenticated requests as the viewer. This issue is fixed in versions 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0.
π@cveNotify
Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the video placeholder component allowed crafted HTML to cause an attribute breakout and inject an attacker-controlled event handler. An authenticated user with default trust-level posting privileges could store the crafted placeholder in a post. When another user opened the post and clicked the video play overlay, the handler could execute arbitrary JavaScript in the viewer's session. Default Content Security Policy settings block inline event handlers, but instances with CSP disabled or relaxed could allow the script to read page content and make authenticated requests as the viewer. This issue is fixed in versions 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0.
π@cveNotify
GitHub
SECURITY: Stored XSS in the video placeholder: sanitizeUrl does not r⦠· discourse/discourse@05d92b8
β¦eject double-quotes [backport 2026.7]
π¨ CVE-2026-91123
Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the iframe src traversal guard did not treat literal backslashes as path separators after decoded dot segments. A crafted source could therefore pass an allowed_iframes subpath check while browser URL normalization moved the iframe outside the intended allowed path. The resulting iframe could load content from a location that the administrator did not allow. This issue is fixed in versions 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0.
π@cveNotify
Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the iframe src traversal guard did not treat literal backslashes as path separators after decoded dot segments. A crafted source could therefore pass an allowed_iframes subpath check while browser URL normalization moved the iframe outside the intended allowed path. The resulting iframe could load content from a location that the administrator did not allow. This issue is fixed in versions 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0.
π@cveNotify
GitHub
SECURITY: Reject literal backslash path separators in iframe src trav⦠· discourse/discourse@042d7b1
β¦ersal guard [backport 2026.1]
π¨ CVE-2026-93542
An out-of-bounds read in libXi's XI2 class parsing via size_classes() and copy_classes() in libXi before 1.8.4 could be used by malicous servers to crash the X client.
π@cveNotify
An out-of-bounds read in libXi's XI2 class parsing via size_classes() and copy_classes() in libXi before 1.8.4 could be used by malicous servers to crash the X client.
π@cveNotify
GitLab
Fixes for AISLE reports (!23) Β· Merge requests Β· xorg / lib / libXi Β· GitLab
This fixes 7 issues reported downstream by AISLE Research in partnership with Red Hat: CVE-2026-93541: Out-of-bounds read in libXi's XQueryDeviceState(). CVE-2026-93542: Out-of-bounds read...
π¨ CVE-2026-93543
An out-of-bounds read in libXi's XI2 class parser in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.
π@cveNotify
An out-of-bounds read in libXi's XI2 class parser in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.
π@cveNotify
GitLab
Fixes for AISLE reports (!23) Β· Merge requests Β· xorg / lib / libXi Β· GitLab
This fixes 7 issues reported downstream by AISLE Research in partnership with Red Hat: CVE-2026-93541: Out-of-bounds read in libXi's XQueryDeviceState(). CVE-2026-93542: Out-of-bounds read...
π¨ CVE-2026-93544
An out-of-bounds read in libXi's XI2 XIQueryDevice reply parsing in libXi before 1.8.4 can be used by a malicious X server to crash an attached X client.
π@cveNotify
An out-of-bounds read in libXi's XI2 XIQueryDevice reply parsing in libXi before 1.8.4 can be used by a malicious X server to crash an attached X client.
π@cveNotify
GitLab
Fixes for AISLE reports (!23) Β· Merge requests Β· xorg / lib / libXi Β· GitLab
This fixes 7 issues reported downstream by AISLE Research in partnership with Red Hat: CVE-2026-93541: Out-of-bounds read in libXi's XQueryDeviceState(). CVE-2026-93542: Out-of-bounds read...
π¨ CVE-2026-93545
An out-of-bounds read in libXi's XListInputDevices() in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.
π@cveNotify
An out-of-bounds read in libXi's XListInputDevices() in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.
π@cveNotify
GitLab
Fixes for AISLE reports (!23) Β· Merge requests Β· xorg / lib / libXi Β· GitLab
This fixes 7 issues reported downstream by AISLE Research in partnership with Red Hat: CVE-2026-93541: Out-of-bounds read in libXi's XQueryDeviceState(). CVE-2026-93542: Out-of-bounds read...
π¨ CVE-2026-94281
An out-of-bounds read in libXi's XListInputDevices() class parsing in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.
π@cveNotify
An out-of-bounds read in libXi's XListInputDevices() class parsing in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.
π@cveNotify
GitLab
Fixes for AISLE reports (!23) Β· Merge requests Β· xorg / lib / libXi Β· GitLab
This fixes 7 issues reported downstream by AISLE Research in partnership with Red Hat: CVE-2026-93541: Out-of-bounds read in libXi's XQueryDeviceState(). CVE-2026-93542: Out-of-bounds read...
π¨ CVE-2026-94611
authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik API serializers return stored credentials when an account has view permission on an affected configuration, even when that account is not authorized to change the configuration or read its secrets. Affected configurations include one-time code delivery by mail or SMS, outbound provisioning targets, device trust integrations, identity sources, the Kubernetes outpost integration, applications using a client or shared secret, and applications using a proxy provider. Deployments are affected when view permission is granted to accounts that are not intended to read these credentials; deployments where every viewer is permitted to read them are not affected. This issue is fixed in versions 2026.2.7, 2026.5.7, and 2026.8.2.
π@cveNotify
authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik API serializers return stored credentials when an account has view permission on an affected configuration, even when that account is not authorized to change the configuration or read its secrets. Affected configurations include one-time code delivery by mail or SMS, outbound provisioning targets, device trust integrations, identity sources, the Kubernetes outpost integration, applications using a client or shared secret, and applications using a proxy provider. Deployments are affected when view permission is granted to accounts that are not intended to read these credentials; deployments where every viewer is permitted to read them are not affected. This issue is fixed in versions 2026.2.7, 2026.5.7, and 2026.8.2.
π@cveNotify
docs.goauthentik.io
Release 2026.2 | authentik
Highlights
π¨ CVE-2026-94612
authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an authentik SAML Source verifies an assertion's signature and validity period but does not ensure that the identity provider issued the assertion for that Source or in response to a login request from that Source. The SAML Source also does not record already accepted assertions, allowing replay. An unauthenticated actor who possesses such a valid assertion can use an assertion intended for another service provider or reuse an earlier assertion to authenticate as the user named by the assertion. Only SAML Sources are affected; SAML Providers and other Source types are not affected. This issue is fixed in versions 2026.2.7, 2026.5.7, and 2026.8.2.
π@cveNotify
authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an authentik SAML Source verifies an assertion's signature and validity period but does not ensure that the identity provider issued the assertion for that Source or in response to a login request from that Source. The SAML Source also does not record already accepted assertions, allowing replay. An unauthenticated actor who possesses such a valid assertion can use an assertion intended for another service provider or reuse an earlier assertion to authenticate as the user named by the assertion. Only SAML Sources are affected; SAML Providers and other Source types are not affected. This issue is fixed in versions 2026.2.7, 2026.5.7, and 2026.8.2.
π@cveNotify
docs.goauthentik.io
Release 2026.2 | authentik
Highlights
π¨ CVE-2026-54461
Habitica is a habit tracker application that treats goals like a role-playing game. From 4.172.1 until 5.48.2, a query parameter on Habitica's /api/v3/groups/:groupId/members route is not sanitized before being interpreted as a regular expression. An authenticated caller can supply a computationally expensive regular expression that degrades application performance or halts Node.js processes. This issue is fixed in version 5.48.2.
π@cveNotify
Habitica is a habit tracker application that treats goals like a role-playing game. From 4.172.1 until 5.48.2, a query parameter on Habitica's /api/v3/groups/:groupId/members route is not sanitized before being interpreted as a regular expression. An authenticated caller can supply a computationally expensive regular expression that degrades application performance or halts Node.js processes. This issue is fixed in version 5.48.2.
π@cveNotify
GitHub
Merge commit from fork Β· HabitRPG/habitica@7b7dc25
Co-authored-by: YoyoChaud <yoan-degans-1337-yoyo@proton.me>
π¨ CVE-2026-57175
Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the SAML backend accepted SAML responses on the Assertion Consumer Service endpoint without verifying that they matched a previously issued `AuthnRequest`. Applications using SAML account association could allow an attacker with a valid account on a trusted IdP to link the attacker's SAML identity to a logged-in victim's local account. The attacker could then authenticate through SAML and gain access to the victim's account. The issue affects applications using the SAML backend together with authenticated account association. The issue has been fixed in version 5.0.0 by validating SAML responses against stored `AuthnRequest` IDs.
π@cveNotify
Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the SAML backend accepted SAML responses on the Assertion Consumer Service endpoint without verifying that they matched a previously issued `AuthnRequest`. Applications using SAML account association could allow an attacker with a valid account on a trusted IdP to link the attacker's SAML identity to a logged-in victim's local account. The attacker could then authenticate through SAML and gain access to the victim's account. The issue affects applications using the SAML backend together with authenticated account association. The issue has been fixed in version 5.0.0 by validating SAML responses against stored `AuthnRequest` IDs.
π@cveNotify
GitHub
Improper SAML Authentication in social-auth-core
### Impact
The SAML backend accepted SAML responses on the Assertion Consumer Service endpoint without verifying that they matched a previously issued `AuthnRequest`.
Applications using SAML ...
The SAML backend accepted SAML responses on the Assertion Consumer Service endpoint without verifying that they matched a previously issued `AuthnRequest`.
Applications using SAML ...
π¨ CVE-2026-57176
Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the Vend OAuth2 backend used only the numeric Vend user_id as the social-auth UID. When multiple Vend shops authenticate through the same application, users from different shops with the same internal Vend user ID could collide in the social-auth association table. A user from one shop could then be authenticated as the local account previously associated with the same numeric user ID from another shop. The issue affects applications using the Vend OAuth2 backend with more than one Vend shop. Version 5.0.0 patches the issue.
π@cveNotify
Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the Vend OAuth2 backend used only the numeric Vend user_id as the social-auth UID. When multiple Vend shops authenticate through the same application, users from different shops with the same internal Vend user ID could collide in the social-auth association table. A user from one shop could then be authenticated as the local account previously associated with the same numeric user ID from another shop. The issue affects applications using the Vend OAuth2 backend with more than one Vend shop. Version 5.0.0 patches the issue.
π@cveNotify
GitHub
Account Takeover via Identity Binding Flaw in Vend Backend
### Impact
The Vend OAuth2 backend used only the numeric Vend `user_id` as the social-auth UID.
When multiple Vend shops authenticate through the same application, users from different shops ...
The Vend OAuth2 backend used only the numeric Vend `user_id` as the social-auth UID.
When multiple Vend shops authenticate through the same application, users from different shops ...