🚨 CVE-2026-86843
The Apache Airflow Teradata provider's compute-cluster example Dag declared every one of its Dag Params as unconstrained free text and templated them straight into the compute-cluster operators, which interpolate those values into Teradata DDL. A user who is permitted to trigger that Dag - a lower-trust role than the Dag author, and one that needs no Teradata credentials of its own - could therefore supply SQL fragments that execute under the connection the task runs as, and could additionally redirect the task at any other connection defined in the deployment, because the connection id was itself a free-text Param. Only deployments that run this example Dag, or a Dag copied from it, are affected; the provider's operator code is unchanged. Users of apache-airflow-providers-teradata are recommended to upgrade to version 3.7.0 or later, whose example constrains the Params to validated identifiers and a closed value set and removes connection selection and free-form option strings from trigger-time input. Upgrading does not change a Dag already copied from the example; users who copied it should apply the same constraints to their copy.
🎖@cveNotify
The Apache Airflow Teradata provider's compute-cluster example Dag declared every one of its Dag Params as unconstrained free text and templated them straight into the compute-cluster operators, which interpolate those values into Teradata DDL. A user who is permitted to trigger that Dag - a lower-trust role than the Dag author, and one that needs no Teradata credentials of its own - could therefore supply SQL fragments that execute under the connection the task runs as, and could additionally redirect the task at any other connection defined in the deployment, because the connection id was itself a free-text Param. Only deployments that run this example Dag, or a Dag copied from it, are affected; the provider's operator code is unchanged. Users of apache-airflow-providers-teradata are recommended to upgrade to version 3.7.0 or later, whose example constrains the Params to validated identifiers and a closed value set and removes connection selection and free-form option strings from trigger-time input. Upgrading does not change a Dag already copied from the example; users who copied it should apply the same constraints to their copy.
🎖@cveNotify
GitHub
Constrain the Teradata compute-cluster example Dag's user-settable Params by potiuk · Pull Request #72714 · apache/airflow
The Teradata compute-cluster operators build DDL by interpolating names into SQL text. Object names cannot be passed as bind parameters, so whatever reaches them has to be constrained where it is d...
🚨 CVE-2026-8065
An authentication bypass vulnerability in the firmware update endpoint of Hitachi Energy RTU500 end-of-life versions allows an unauthenticated attacker to upload arbitrary firmware through a crafted POST request. Successful exploitation could allow the attacker to modify device functionality or compromise the integrity or availability of the device.
🎖@cveNotify
An authentication bypass vulnerability in the firmware update endpoint of Hitachi Energy RTU500 end-of-life versions allows an unauthenticated attacker to upload arbitrary firmware through a crafted POST request. Successful exploitation could allow the attacker to modify device functionality or compromise the integrity or availability of the device.
🎖@cveNotify
🚨 CVE-2026-8066
A directory traversal vulnerability in the file upload functionality of Hitachi Energy RTU500 end-of-life versions allows an unauthenticated attacker to write or overwrite arbitrary files on the device file system. Depending on the files affected, successful exploitation could result in unauthorized modification of device data or disruption of the device’s intended operation.
🎖@cveNotify
A directory traversal vulnerability in the file upload functionality of Hitachi Energy RTU500 end-of-life versions allows an unauthenticated attacker to write or overwrite arbitrary files on the device file system. Depending on the files affected, successful exploitation could result in unauthorized modification of device data or disruption of the device’s intended operation.
🎖@cveNotify
🚨 CVE-2026-8937
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to read private child issue contents, including titles and descriptions, from projects they had no access to, due to missing authorization checks on linked work items within visible epics.
🎖@cveNotify
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to read private child issue contents, including titles and descriptions, from projects they had no access to, due to missing authorization checks on linked work items within visible epics.
🎖@cveNotify
GitLab Docs
GitLab Critical Patch Release: 19.4.1, 19.3.3, 19.2.7 | GitLab Docs
Learn more about GitLab Critical Patch Release: 19.4.1, 19.3.3, 19.2.7 for GitLab Community Edition (CE) and Enterprise Edition (EE).
🚨 CVE-2026-95387
SPDY protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
SPDY protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
SPDY Data Frame Reassembly Integer Overflow (#21487) · Issues · Wireshark Foundation / Wireshark · GitLab
SPDY Data Frame Reassembly Integer Overflow 1. Executive Summary
🚨 CVE-2026-95389
SCTP protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
SCTP protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
SCTP Fragment Reassembly integer overflow in fragment_reassembly() leads to heap buffer overflow (#21481) · Issues · Wireshark…
SCTP Reassembly Integer Overflow Vulnerability — Technical Report
🚨 CVE-2026-95390
PEAK CAN TRC file parser crash in 4.6.0 to 4.6.8 allows denial of service
🎖@cveNotify
PEAK CAN TRC file parser crash in 4.6.0 to 4.6.8 allows denial of service
🎖@cveNotify
GitLab
PEAK TRC v1 error-frame parser dereferences missing data tokens (#21503) · Issues · Wireshark Foundation / Wireshark · GitLab
Summary The PEAK TRC v1 ERROR-frame parser splits the data column and passes bytes[0] or bytes[1]...
🚨 CVE-2026-95391
ZigBee ZCL protocol dissector crash in 4.6.0 to 4.6.8 allows denial of service
🎖@cveNotify
ZigBee ZCL protocol dissector crash in 4.6.0 to 4.6.8 allows denial of service
🎖@cveNotify
GitLab
ZigBee ZCL Touchlink: empty the commissioning map on a redissect. (!26096) · Merge requests · Wireshark Foundation / Wireshark…
All of the entries in the commissioning map are allocated with "file" scope, which means that, before a redissect pass, they will all be freed. On...
🚨 CVE-2026-95392
MBIM protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
MBIM protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
MBIM GSM 7-bit character-count wrap causes full-tree analysis denial of service (#21549) · Issues · Wireshark Foundation / Wireshark…
Executive Summary Mallory can send Alice a Linux usbmon capture whose outer USB and MBIM framing...
🚨 CVE-2026-95393
CSN.1 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
CSN.1 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
Heap buffer overflow (WRITE) in CSN.1 dissector (#21510) · Issues · Wireshark Foundation / Wireshark · GitLab
Heap buffer overflow (WRITE) in CSN.1 dissector — CSN_RECURSIVE_ARRAY writes past destination array with no capacity check (packet-csn1.c)
🚨 CVE-2026-95394
Microsoft Network Monitor file parser large loop in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
Microsoft Network Monitor file parser large loop in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
NetMon 2.x timestamp normalization permits CPU denial of service from a small capture file (#21523) · Issues · Wireshark Foundation…
Summary A valid 868-byte Microsoft Network Monitor 2.0 capture can keep Wireshark's ordinary file reader CPU-bound in timestamp...
🚨 CVE-2026-95395
IEEE C37.118 Synchrophasor protocol dissector memory leak in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
IEEE C37.118 Synchrophasor protocol dissector memory leak in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
Wireshark SYNCHROPHASOR CFG3 frame parser memory exhaustion (#21492) · Issues · Wireshark Foundation / Wireshark · GitLab
Summary The SYNCHROPHASOR dissector (packet-synphasor.c) parses CFG3 configuration frames. The function config_3_frame_fast() reads the num_ph (number of phasors)...
🚨 CVE-2026-96415
Catapult DCT2000 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
Catapult DCT2000 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
Catapult DCT2000 NR-UP padding loop writes past a 200-byte static buffer (#21589) · Issues · Wireshark Foundation / Wireshark ·…
This issue was found by Anthropic using Claude to study open source software, and I'm from Ada Logics and have manually validated the issue. Summary
🚨 CVE-2026-96416
IEEE 802.11 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
IEEE 802.11 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
802.11 FT MIC check: length desync between two FTE elements passes a negative length to `gcry_mac_write()`, causing a huge out…
This issue was discovered by an AI agent (Claude) and independently validated by a me. Scope note
🚨 CVE-2026-96417
RF4CE protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
RF4CE protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
ZDI-CAN-31780: RF4CE Packet Parsing Buffer Overflow (#21574) · Issues · Wireshark Foundation / Wireshark · GitLab
ZDI-CAN-31780: Wireshark RF4CE Packet Parsing Buffer Overflow Remote Code Execution Vulnerability -- CVSS ----------------------------------------- 7.8: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H -- ABSTRACT ------------------------------------- Trend...
🚨 CVE-2026-96418
TIFF protocol dissector infinite loop in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
TIFF protocol dissector infinite loop in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
TIFF dissector: IFD chain has no cycle detection, so a self-referential IFD makes the dissector loop forever (infinite loop, DoS)…
This issue was discovered by a AI agent (Claude) and independently validated by a me. Summary
🚨 CVE-2026-96419
Profile import crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service and possible code execution
🎖@cveNotify
Profile import crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service and possible code execution
🎖@cveNotify
GitLab
Incomplete fix for CVE-2026-5656: Windows patch bypass via #ifndef _WIN32 guard in WiresharkZipHelper::unzip() (#21553) · Issues…
Summary Incomplete fix for CVE-2026-5656: Windows patch bypass via #ifndef _WIN32 guard in WiresharkZipHelper::unzip() Steps...
🚨 CVE-2026-96420
Toshiba file parser crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
Toshiba file parser crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
Malformed Toshiba OFFSET line can make parser read stale stack memory (#21541) · Tasks · Wireshark Foundation / Wireshark · GitLab
From AISLE Security: Description Toshiba captures are attacker-controlled text files processed after the handler recognizes the...
🚨 CVE-2026-96421
USB HID protocol dissector infinite loop and memory leak in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
USB HID protocol dissector infinite loop and memory leak in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
USB HID: extended Usage Maximum `0xFFFFFFFF` wraps the usage-range loop at UINT32_MAX → infinite loop + unbounded allocation (bypasses…
This issue was discovered by a AI agent (Claude) and independently validated by a me. Summary
🚨 CVE-2026-96422
Frame protocol metadissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
Frame protocol metadissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
🎖@cveNotify
GitLab
pcapng packet comments can abort TShark while building a protocol tree (#21525) · Issues · Wireshark Foundation / Wireshark · GitLab
Summary A syntactically valid pcapng file containing many repeated packet-comment options can abort TShark when it builds the...