π¨ CVE-2026-95395
IEEE C37.118 Synchrophasor protocol dissector memory leak in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
π@cveNotify
IEEE C37.118 Synchrophasor protocol dissector memory leak in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
π@cveNotify
GitLab
Wireshark SYNCHROPHASOR CFG3 frame parser memory exhaustion (#21492) Β· Issues Β· Wireshark Foundation / Wireshark Β· GitLab
Summary The SYNCHROPHASOR dissector (packet-synphasor.c) parses CFG3 configuration frames. The function config_3_frame_fast() reads the num_ph (number of phasors)...
π¨ CVE-2026-96415
Catapult DCT2000 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
π@cveNotify
Catapult DCT2000 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
π@cveNotify
GitLab
Catapult DCT2000 NR-UP padding loop writes past a 200-byte static buffer (#21589) Β· Issues Β· Wireshark Foundation / Wireshark Β·β¦
This issue was found by Anthropic using Claude to study open source software, and I'm from Ada Logics and have manually validated the issue. Summary
π¨ CVE-2026-96416
IEEE 802.11 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
π@cveNotify
IEEE 802.11 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
π@cveNotify
GitLab
802.11 FT MIC check: length desync between two FTE elements passes a negative length to `gcry_mac_write()`, causing a huge outβ¦
This issue was discovered by an AI agent (Claude) and independently validated by a me. Scope note
π¨ CVE-2026-96417
RF4CE protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
π@cveNotify
RF4CE protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
π@cveNotify
GitLab
ZDI-CAN-31780: RF4CE Packet Parsing Buffer Overflow (#21574) Β· Issues Β· Wireshark Foundation / Wireshark Β· GitLab
ZDI-CAN-31780: Wireshark RF4CE Packet Parsing Buffer Overflow Remote Code Execution Vulnerability -- CVSS ----------------------------------------- 7.8: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H -- ABSTRACT ------------------------------------- Trend...
π¨ CVE-2026-96418
TIFF protocol dissector infinite loop in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
π@cveNotify
TIFF protocol dissector infinite loop in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
π@cveNotify
GitLab
TIFF dissector: IFD chain has no cycle detection, so a self-referential IFD makes the dissector loop forever (infinite loop, DoS)β¦
This issue was discovered by a AI agent (Claude) and independently validated by a me. Summary
π¨ CVE-2026-96419
Profile import crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service and possible code execution
π@cveNotify
Profile import crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service and possible code execution
π@cveNotify
GitLab
Incomplete fix for CVE-2026-5656: Windows patch bypass via #ifndef _WIN32 guard in WiresharkZipHelper::unzip() (#21553) Β· Issuesβ¦
Summary Incomplete fix for CVE-2026-5656: Windows patch bypass via #ifndef _WIN32 guard in WiresharkZipHelper::unzip() Steps...
π¨ CVE-2026-96420
Toshiba file parser crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
π@cveNotify
Toshiba file parser crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
π@cveNotify
GitLab
Malformed Toshiba OFFSET line can make parser read stale stack memory (#21541) Β· Tasks Β· Wireshark Foundation / Wireshark Β· GitLab
From AISLE Security: Description Toshiba captures are attacker-controlled text files processed after the handler recognizes the...
π¨ CVE-2026-96421
USB HID protocol dissector infinite loop and memory leak in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
π@cveNotify
USB HID protocol dissector infinite loop and memory leak in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
π@cveNotify
GitLab
USB HID: extended Usage Maximum `0xFFFFFFFF` wraps the usage-range loop at UINT32_MAX β infinite loop + unbounded allocation (bypassesβ¦
This issue was discovered by a AI agent (Claude) and independently validated by a me. Summary
π¨ CVE-2026-96422
Frame protocol metadissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
π@cveNotify
Frame protocol metadissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
π@cveNotify
GitLab
pcapng packet comments can abort TShark while building a protocol tree (#21525) Β· Issues Β· Wireshark Foundation / Wireshark Β· GitLab
Summary A syntactically valid pcapng file containing many repeated packet-comment options can abort TShark when it builds the...
π¨ CVE-2026-96423
X11 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
π@cveNotify
X11 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
π@cveNotify
GitLab
X11 dissector: out-of-bounds heap read from a stale keysyms-per-keycode width in `keycode2keysymString()` (#21563) Β· Issues Β· Wiresharkβ¦
This issue was discovered by an AI agent (Claude) and independently validated by a me. Summary
π¨ CVE-2026-102495
Apache XmlSchema doesn't limit how deeply schema imports and includes can be nested, so a malicious schema can make parsing recurse until the stack overflows. This causes a denial of service.
Users are recommended to upgrade to version 2.3.3, which fixes this issue.
π@cveNotify
Apache XmlSchema doesn't limit how deeply schema imports and includes can be nested, so a malicious schema can make parsing recurse until the stack overflows. This causes a denial of service.
Users are recommended to upgrade to version 2.3.3, which fixes this issue.
π@cveNotify
π¨ CVE-2026-102496
Apache XmlSchema doesn't limit how deeply schema structures can be nested when it builds its schema model, so a malicious schema can make parsing recurse until the stack overflows. This causes a denial of service.
Users are recommended to upgrade to version 2.3.3, which fixes this issue.
π@cveNotify
Apache XmlSchema doesn't limit how deeply schema structures can be nested when it builds its schema model, so a malicious schema can make parsing recurse until the stack overflows. This causes a denial of service.
Users are recommended to upgrade to version 2.3.3, which fixes this issue.
π@cveNotify
π¨ CVE-2026-102497
The Apache XmlSchema walker (xmlschema-walker) doesn't detect cycles in type derivation, substitution groups, model groups or attribute groups. A malicious schema with such a cycle can make the walker recurse until the stack overflows, causing a denial of service.
Users are recommended to upgrade to version 2.3.3, which fixes this issue.
π@cveNotify
The Apache XmlSchema walker (xmlschema-walker) doesn't detect cycles in type derivation, substitution groups, model groups or attribute groups. A malicious schema with such a cycle can make the walker recurse until the stack overflows, causing a denial of service.
Users are recommended to upgrade to version 2.3.3, which fixes this issue.
π@cveNotify
π¨ CVE-2026-66083
The /datasources/unauth-datasource endpoint does not properly enforce data source authorization. An authenticated user can invoke this endpoint to obtain information about data sources they are not authorized to access. This may expose data source configuration and other sensitive metadata, depending on the fields returned by the endpoint.
This issue affects Apache DolphinScheduler: before 3.4.3.
Users are recommended to upgrade to version 3.4.3, which fixes the issue.
π@cveNotify
The /datasources/unauth-datasource endpoint does not properly enforce data source authorization. An authenticated user can invoke this endpoint to obtain information about data sources they are not authorized to access. This may expose data source configuration and other sensitive metadata, depending on the fields returned by the endpoint.
This issue affects Apache DolphinScheduler: before 3.4.3.
Users are recommended to upgrade to version 3.4.3, which fixes the issue.
π@cveNotify
π¨ CVE-2026-73595
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains a Download of Code Without Integrity Check vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Code execution, Information disclosure, Information tampering, and Protection mechanism bypass.
π@cveNotify
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains a Download of Code Without Integrity Check vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Code execution, Information disclosure, Information tampering, and Protection mechanism bypass.
π@cveNotify
π¨ CVE-2026-73596
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Initialization of a Resource with an Insecure Default vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges, Information tampering, Protection mechanism bypass, and Unauthorized access.
π@cveNotify
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Initialization of a Resource with an Insecure Default vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges, Information tampering, Protection mechanism bypass, and Unauthorized access.
π@cveNotify
π¨ CVE-2026-100757
Use-after-free in the Widget component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
π@cveNotify
Use-after-free in the Widget component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
π@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2049352. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
π¨ CVE-2026-100766
Information disclosure in the Networking: JAR component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
π@cveNotify
Information disclosure in the Networking: JAR component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
π@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2061526. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
π¨ CVE-2026-73598
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
π@cveNotify
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
π@cveNotify
π¨ CVE-2026-82804
The scriptPath parameter is incorporated into a /bin/sh -c command without sufficient neutralization of shell metacharacters, allowing shell command substitution and execution.
An authenticated user can exploit this behavior by creating a resource whose filename contains shell command substitution syntax, such as $(...), and subsequently supplying the resulting path to the Alert Script plugin's /test-send endpoint. When the alert script is executed, the shell interprets the injected command, resulting in arbitrary command execution with the privileges of the DolphinScheduler service process.
This issue affects Apache DolphinScheduler: before 3.4.3.
Users are recommended to upgrade to version 3.4.3, which fixes the issue.
π@cveNotify
The scriptPath parameter is incorporated into a /bin/sh -c command without sufficient neutralization of shell metacharacters, allowing shell command substitution and execution.
An authenticated user can exploit this behavior by creating a resource whose filename contains shell command substitution syntax, such as $(...), and subsequently supplying the resulting path to the Alert Script plugin's /test-send endpoint. When the alert script is executed, the shell interprets the injected command, resulting in arbitrary command execution with the privileges of the DolphinScheduler service process.
This issue affects Apache DolphinScheduler: before 3.4.3.
Users are recommended to upgrade to version 3.4.3, which fixes the issue.
π@cveNotify
π¨ CVE-2026-71897
An improper authorization check in Apache DolphinScheduler allows an authenticated user to use the batch-copy and batch-move endpoints to operate on workflows in projects for which they lack the required permissions. This may allow the user to copy or move workflows from unauthorized projects.
This issue affects Apache DolphinScheduler: before 3.4.3.
Users are recommended to upgrade to version 3.4.3, which fixes the issue.
π@cveNotify
An improper authorization check in Apache DolphinScheduler allows an authenticated user to use the batch-copy and batch-move endpoints to operate on workflows in projects for which they lack the required permissions. This may allow the user to copy or move workflows from unauthorized projects.
This issue affects Apache DolphinScheduler: before 3.4.3.
Users are recommended to upgrade to version 3.4.3, which fixes the issue.
π@cveNotify