π¨ CVE-2026-15310
When decompressing crafted zip files using the bzip/LZMA/Zstandard
compressions, Python could use an attacker-controlled size to
pre-allocate memory, possibly resulting in memory exhaustion.
π@cveNotify
When decompressing crafted zip files using the bzip/LZMA/Zstandard
compressions, Python could use an attacker-controlled size to
pre-allocate memory, possibly resulting in memory exhaustion.
π@cveNotify
GitHub
[3.12] gh-156002: Bound zipfile decompression for bzip2/LZMA/Zstandar⦠· python/cpython@09a2e7e
β¦d (GH-156003) (GH-156362) (#156739)
* gh-156002: Bound zipfile decompression for bzip2/LZMA/Zstandard (GH-156003) (GH-156362)
Patch by @tonghuaroot.
zipfile.ZipExtFile._read1() bounds the outpu...
* gh-156002: Bound zipfile decompression for bzip2/LZMA/Zstandard (GH-156003) (GH-156362)
Patch by @tonghuaroot.
zipfile.ZipExtFile._read1() bounds the outpu...
π¨ CVE-2026-87910
When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None.
π@cveNotify
When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None.
π@cveNotify
GitHub
[3.11] gh-157265: tarfile: Honor None result of filter for link fallb⦠· python/cpython@2eb0c2f
β¦acks (GH-157266) (#157306)
* gh-157265: tarfile: Honor None result of filter for link fallbacks (GH-157266)
(cherry picked from commit fb2f0bbc3b35264f09cc2cb2934b7987527a6bc2)
Co-authored-by: ...
* gh-157265: tarfile: Honor None result of filter for link fallbacks (GH-157266)
(cherry picked from commit fb2f0bbc3b35264f09cc2cb2934b7987527a6bc2)
Co-authored-by: ...
π¨ CVE-2026-19445
A remote, unauthenticated TLS client can make a server crash or call
through a freed pointer if its sni_callback assigns a different context to
SSLSocket.context (the documented way to select a certificate per server
name) and nothing else keeps the original ssl.SSLContext alive. Typical
cases are servers that create an SSLContext per connection or replace it
while connections are open; servers that wrap their listening socket with
it are not affected.
Mitigation: keep a reference to every SSLContext that sets sni_callback for
the lifetime of the server. TLS clients are not affected.
π@cveNotify
A remote, unauthenticated TLS client can make a server crash or call
through a freed pointer if its sni_callback assigns a different context to
SSLSocket.context (the documented way to select a certificate per server
name) and nothing else keeps the original ssl.SSLContext alive. Typical
cases are servers that create an SSLContext per connection or replace it
while connections are open; servers that wrap their listening socket with
it are not affected.
Mitigation: keep a reference to every SSLContext that sets sni_callback for
the lifetime of the server. TLS clients are not affected.
π@cveNotify
GitHub
gh-156293: Use-after-free for server-side SSLContext with sni_callbac⦠· python/cpython@34a53dc
β¦k (#158504)
Co-authored-by: Gregory P. Smith <68491+gpshead@users.noreply.github.com>
Co-authored-by: Gregory P. Smith <68491+gpshead@users.noreply.github.com>
π¨ CVE-2026-19553
ssl.SSLContext.wrap_bio() didn't require the server_hostname argument
to not be None if ssl.SSLContext.check_hostname was set. Due to a
missing parameter check in SSLObject, if the server_hostname argument
isn't supplied then hostname verification would be silently skipped.
This defect could lead to programs where certificate hostname verification
*appeared* to be succeeding with SSLContext.check_hostname = True and no
ValueError being raised due to misconfiguration.
If the program passes a server_hostname value that isn't an empty string
or None to any of these APIs then certificate hostname verification
proceeds as expected and the program is not affected by this vulnerability.
Mitigating this vulnerability doesn't require updating Python or applying
the patch. To mitigate, pass a valid non-None and non-empty
server_hostname value to SSLContext.wrap_bio(),
asyncio.create_connection(), or asyncio.loop.start_tls() and
certificate hostname verification will proceed as expected. Upgrading to
the latest version of Python or applying the patch only changes the
behavior from silently skipping hostname verification to raising a
ValueError, similar to SSLContext.wrap_socket(), when server_hostname
isn't supplied.
π@cveNotify
ssl.SSLContext.wrap_bio() didn't require the server_hostname argument
to not be None if ssl.SSLContext.check_hostname was set. Due to a
missing parameter check in SSLObject, if the server_hostname argument
isn't supplied then hostname verification would be silently skipped.
This defect could lead to programs where certificate hostname verification
*appeared* to be succeeding with SSLContext.check_hostname = True and no
ValueError being raised due to misconfiguration.
If the program passes a server_hostname value that isn't an empty string
or None to any of these APIs then certificate hostname verification
proceeds as expected and the program is not affected by this vulnerability.
Mitigating this vulnerability doesn't require updating Python or applying
the patch. To mitigate, pass a valid non-None and non-empty
server_hostname value to SSLContext.wrap_bio(),
asyncio.create_connection(), or asyncio.loop.start_tls() and
certificate hostname verification will proceed as expected. Upgrading to
the latest version of Python or applying the patch only changes the
behavior from silently skipping hostname verification to raising a
ValueError, similar to SSLContext.wrap_socket(), when server_hostname
isn't supplied.
π@cveNotify
GitHub
gh-156793: Validate SSLContext.wrap_bio() parameters like wrap_socket⦠· python/cpython@1697ea3
β¦() (#158503)
Co-authored-by: BΓ©nΓ©dikt Tran <10796600+picnixz@users.noreply.github.com>
Co-authored-by: Hugo van Kemenade <1324225+hugovk@users.noreply.github.com>
Co-authored-by: BΓ©nΓ©dikt Tran <10796600+picnixz@users.noreply.github.com>
Co-authored-by: Hugo van Kemenade <1324225+hugovk@users.noreply.github.com>
π¨ CVE-2026-103531
A flaw has been found in OpenSC up to 0.27.1. The impacted element is the function setcos_construct_fci_44 of the file src/libopensc/card-setcos.c. Executing a manipulation of the argument type_attr can lead to stack-based buffer overflow. The attack can be launched remotely. This patch is called ad730304052937c32b4eb489a06835ac6123632c. It is best practice to apply a patch to resolve this issue.
π@cveNotify
A flaw has been found in OpenSC up to 0.27.1. The impacted element is the function setcos_construct_fci_44 of the file src/libopensc/card-setcos.c. Executing a manipulation of the argument type_attr can lead to stack-based buffer overflow. The attack can be launched remotely. This patch is called ad730304052937c32b4eb489a06835ac6123632c. It is best practice to apply a patch to resolve this issue.
π@cveNotify
GitHub
GitHub - OpenSC/OpenSC: Open source smart card tools and middleware. PKCS#11/MiniDriver
Open source smart card tools and middleware. PKCS#11/MiniDriver - OpenSC/OpenSC
π¨ CVE-2025-6558
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
π@cveNotify
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
π@cveNotify
Chrome Releases
Stable Channel Update for Desktop
The Stable channel has been updated to 138.0.7204.157/.158 for Windows, Mac and 138.0.7204.157 for Linux which will roll out over the coming...
π¨ CVE-2026-101879
OpenClaw Windows Node before 2026.7.1-3 contains a missing authorization vulnerability in NodeService capture handlers that allows connected gateways or agents to perform screen snapshots, camera snaps, and location captures without consent prompts. Attackers can invoke screen.snapshot, camera.snap, and location.get over the node WebSocket to silently capture screenshots, photograph users through webcams, and obtain device geolocation without user interaction.
π@cveNotify
OpenClaw Windows Node before 2026.7.1-3 contains a missing authorization vulnerability in NodeService capture handlers that allows connected gateways or agents to perform screen snapshots, camera snaps, and location captures without consent prompts. Attackers can invoke screen.snapshot, camera.snap, and location.get over the node WebSocket to silently capture screenshots, photograph users through webcams, and obtain device geolocation without user interaction.
π@cveNotify
GitHub
openclaw-windows-node/src/OpenClaw.Tray.WinUI/Services/NodeService.cs at v2026.7.1-2 Β· openclaw/openclaw-windows-node
Windows companion suite for OpenClaw. Contribute to openclaw/openclaw-windows-node development by creating an account on GitHub.
π¨ CVE-2026-101880
OpenClaw Windows Node before 2026.7.1 contains an incorrect authorization vulnerability in the system.run exec-approval policy where ExecShellWrapperParser fails to split commands on pipe operators or extract command substitutions. Connected gateways or agents can bypass approval rules by placing denied commands behind allowed prefixes using pipe operators or command substitution syntax, achieving arbitrary command execution on Windows hosts.
π@cveNotify
OpenClaw Windows Node before 2026.7.1 contains an incorrect authorization vulnerability in the system.run exec-approval policy where ExecShellWrapperParser fails to split commands on pipe operators or extract command substitutions. Connected gateways or agents can bypass approval rules by placing denied commands behind allowed prefixes using pipe operators or command substitution syntax, achieving arbitrary command execution on Windows hosts.
π@cveNotify
GitHub
openclaw-windows-node/src/OpenClaw.Shared/ExecShellWrapperParser.cs at v0.6.12 Β· openclaw/openclaw-windows-node
Windows companion suite for OpenClaw. Contribute to openclaw/openclaw-windows-node development by creating an account on GitHub.
π¨ CVE-2026-101881
OpenClaw Windows Node before 2026.7.1 contains an allocation of resources without limits vulnerability in the gateway WebSocket transport that allows connected gateways to exhaust node memory. Attackers can send an unending sequence of WebSocket continuation frames without EndOfMessage to cause unbounded memory growth until the node process crashes.
π@cveNotify
OpenClaw Windows Node before 2026.7.1 contains an allocation of resources without limits vulnerability in the gateway WebSocket transport that allows connected gateways to exhaust node memory. Attackers can send an unending sequence of WebSocket continuation frames without EndOfMessage to cause unbounded memory growth until the node process crashes.
π@cveNotify
GitHub
openclaw-windows-node/src/OpenClaw.Shared/WebSocketClientBase.cs at v0.6.12 Β· openclaw/openclaw-windows-node
Windows companion suite for OpenClaw. Contribute to openclaw/openclaw-windows-node development by creating an account on GitHub.
π¨ CVE-2026-101882
OpenClaw Windows Node before 2026.7.1 contains an incomplete validation vulnerability in system.execApprovals.set that accepts wildcard-executable rules and abusable system binaries like mshta, rundll32, and certutil. Remote callers can add broad allow rules to execute arbitrary commands on the Windows host through system.run without operator checks or user prompts.
π@cveNotify
OpenClaw Windows Node before 2026.7.1 contains an incomplete validation vulnerability in system.execApprovals.set that accepts wildcard-executable rules and abusable system binaries like mshta, rundll32, and certutil. Remote callers can add broad allow rules to execute arbitrary commands on the Windows host through system.run without operator checks or user prompts.
π@cveNotify
GitHub
openclaw-windows-node/src/OpenClaw.Shared/Capabilities/SystemCapability.cs at v0.6.12 Β· openclaw/openclaw-windows-node
Windows companion suite for OpenClaw. Contribute to openclaw/openclaw-windows-node development by creating an account on GitHub.
π¨ CVE-2026-101883
OpenClaw Windows Node through 2026.9.4 contains a server-side request forgery vulnerability in the canvas.present capability that bypasses URL risk evaluation enforced by canvas.navigate. Attackers with gateway or agent access can issue canvas.present to make the node's WebView send requests to localhost, private networks, or tailnet services from the user's machine.
π@cveNotify
OpenClaw Windows Node through 2026.9.4 contains a server-side request forgery vulnerability in the canvas.present capability that bypasses URL risk evaluation enforced by canvas.navigate. Attackers with gateway or agent access can issue canvas.present to make the node's WebView send requests to localhost, private networks, or tailnet services from the user's machine.
π@cveNotify
GitHub
openclaw-windows-node/src/OpenClaw.Tray.WinUI/Windows/CanvasWindow.xaml.cs at v0.6.12 Β· openclaw/openclaw-windows-node
Windows companion suite for OpenClaw. Contribute to openclaw/openclaw-windows-node development by creating an account on GitHub.
π¨ CVE-2026-101884
OpenClaw Windows Node before 2026.7.1 contains an incomplete environment-variable sanitizer in system.run that fails to block GIT_CONFIG_*, DOTNET_STARTUP_HOOKS, and JAVA_TOOL_OPTIONS variables. Attackers with gateway or agent access can supply these variables to allowlisted tools like git, dotnet, or java to load attacker-controlled code and achieve arbitrary code execution.
π@cveNotify
OpenClaw Windows Node before 2026.7.1 contains an incomplete environment-variable sanitizer in system.run that fails to block GIT_CONFIG_*, DOTNET_STARTUP_HOOKS, and JAVA_TOOL_OPTIONS variables. Attackers with gateway or agent access can supply these variables to allowlisted tools like git, dotnet, or java to load attacker-controlled code and achieve arbitrary code execution.
π@cveNotify
GitHub
openclaw-windows-node/src/OpenClaw.Shared/ExecEnvSanitizer.cs at v0.6.12 Β· openclaw/openclaw-windows-node
Windows companion suite for OpenClaw. Contribute to openclaw/openclaw-windows-node development by creating an account on GitHub.
π¨ CVE-2026-101885
ZeroClaw versions before 0.8.5 built with plugins-wasm feature contain a path traversal vulnerability in plugin installation that fails to validate the wasm_path manifest field. Attackers can convince users to install crafted plugins that write arbitrary files to paths outside the plugins directory, such as shell startup files, enabling code execution.
π@cveNotify
ZeroClaw versions before 0.8.5 built with plugins-wasm feature contain a path traversal vulnerability in plugin installation that fails to validate the wasm_path manifest field. Attackers can convince users to install crafted plugins that write arbitrary files to paths outside the plugins directory, such as shell startup files, enabling code execution.
π@cveNotify
GitHub
zeroclaw/crates/zeroclaw-plugins/src/host.rs at v0.8.4 Β· zeroclaw-labs/zeroclaw
Fast, small, and fully autonomous AI personal assistant infrastructure, any OS, any platform β deploy anywhere, swap anything π¦ - zeroclaw-labs/zeroclaw
π¨ CVE-2026-102993
pypdf is a free and open-source pure-python PDF library. Prior to 6.17.0, a crafted PDF can provide unusually large Roman page-label values that cause pypdf/_page_labels.py to generate excessively large numeral strings when an application retrieves document page labels, consuming large amounts of memory and potentially making the application unavailable. This issue is fixed in version 6.17.0.
π@cveNotify
pypdf is a free and open-source pure-python PDF library. Prior to 6.17.0, a crafted PDF can provide unusually large Roman page-label values that cause pypdf/_page_labels.py to generate excessively large numeral strings when an application retrieves document page labels, consuming large amounts of memory and potentially making the application unavailable. This issue is fixed in version 6.17.0.
π@cveNotify
GitHub
SEC: Limit value for Roman numerals (#4047) Β· py-pdf/pypdf@89db7c4
A pure-python PDF library capable of splitting, merging, cropping, and transforming the pages of PDF files - SEC: Limit value for Roman numerals (#4047) Β· py-pdf/pypdf@89db7c4
π¨ CVE-2026-102994
pypdf is a free and open-source pure-python PDF library. Prior to 6.18.0, a crafted PDF containing indirect-object identifiers or generation-number tokens that continue for a long time without whitespace can cause pypdf/_reader.py and pypdf/generic/_base.py to scan excessive input through read_until_whitespace, resulting in long runtimes and application unavailability. This issue is fixed in version 6.18.0.
π@cveNotify
pypdf is a free and open-source pure-python PDF library. Prior to 6.18.0, a crafted PDF containing indirect-object identifiers or generation-number tokens that continue for a long time without whitespace can cause pypdf/_reader.py and pypdf/generic/_base.py to scan excessive input through read_until_whitespace, resulting in long runtimes and application unavailability. This issue is fixed in version 6.18.0.
π@cveNotify
GitHub
SEC: Limit allowed length of indirect object tokens (#4055) Β· py-pdf/pypdf@82501d2
These changes are based on the original changes proposed by the
reporter, but have been modified/extended quite a bit for the final
patch.
Disclosure: The original patches were assisted by Antigra...
reporter, but have been modified/extended quite a bit for the final
patch.
Disclosure: The original patches were assisted by Antigra...
π¨ CVE-2026-103387
A weakness has been identified in garycourt uri-js up to 4.4.1. This affects the function URI.parse of the file src/schemes/mailto.ts of the component Mailto Header Handler. This manipulation of the argument to causes uncaught exception. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
π@cveNotify
A weakness has been identified in garycourt uri-js up to 4.4.1. This affects the function URI.parse of the file src/schemes/mailto.ts of the component Mailto Header Handler. This manipulation of the argument to causes uncaught exception. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
π@cveNotify
GitHub
GitHub - garycourt/uri-js: An RFC 3986 compliant, scheme extendable URI parsing/validating/normalizing/resolving library for JavaScript
An RFC 3986 compliant, scheme extendable URI parsing/validating/normalizing/resolving library for JavaScript - garycourt/uri-js
π¨ CVE-2026-101276
iperf3 3.21 (esnet/iperf) contains a remote, unauthenticated heap use-after-free: the server's per-test watchdog server_timer_proc() frees streams without cancelling/joining their worker threads, so a blocked worker dereferences a freed iperf_stream; fixed in 3.22.
π@cveNotify
iperf3 3.21 (esnet/iperf) contains a remote, unauthenticated heap use-after-free: the server's per-test watchdog server_timer_proc() frees streams without cancelling/joining their worker threads, so a blocked worker dereferences a freed iperf_stream; fixed in 3.22.
π@cveNotify
newreleases.io
esnet/iperf 3.22 on GitHub
New release esnet/iperf version 3.22 iperf-3.22 on GitHub.
π¨ CVE-2026-102089
Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to a path traversal weakness in an administrative import function allowed an authenticated administrator to write files to arbitrary locations on the server. This could potentially be leveraged to execute arbitrary code on the underlying system.
π@cveNotify
Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to a path traversal weakness in an administrative import function allowed an authenticated administrator to write files to arbitrary locations on the server. This could potentially be leveraged to execute arbitrary code on the underlying system.
π@cveNotify
GitHub
[EPG] Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Improper Limitation of a Pathname to a Restrictedβ¦
### Description
A path traversal weakness in an administrative import function allowed an authenticated administrator to write files to arbitrary locations on the server. This could potentially be...
A path traversal weakness in an administrative import function allowed an authenticated administrator to write files to arbitrary locations on the server. This could potentially be...
π¨ CVE-2026-102090
Kiteworks Core before version 9.5.1 is vulnerable to Content Injection. A URL parameter in the PDF viewer was insufficiently validated, allowing an attacker-controlled document to be loaded and displayed under the trust of the legitimate application domain. This could increase the credibility of phishing attempts relying on malicious links embedded in the displayed content.
π@cveNotify
Kiteworks Core before version 9.5.1 is vulnerable to Content Injection. A URL parameter in the PDF viewer was insufficiently validated, allowing an attacker-controlled document to be loaded and displayed under the trust of the legitimate application domain. This could increase the credibility of phishing attempts relying on malicious links embedded in the displayed content.
π@cveNotify
GitHub
[Core] Kiteworks Core before version 9.5.1 is vulnerable to Content Injection
### Description
A URL parameter in the PDF viewer was insufficiently validated, allowing an attacker-controlled document to be loaded and displayed under the trust of the legitimate application do...
A URL parameter in the PDF viewer was insufficiently validated, allowing an attacker-controlled document to be loaded and displayed under the trust of the legitimate application do...
π¨ CVE-2026-102091
Kiteworks Secure Data Forms before version 9.5.0 is vulnerable to Server-Side Request Forgery that could allow an unauthenticated, remote attacker to make the server issue arbitrary outbound network requests and read back the responses. This could potentially be used to reach internal-only services or other network-restricted resources.
π@cveNotify
Kiteworks Secure Data Forms before version 9.5.0 is vulnerable to Server-Side Request Forgery that could allow an unauthenticated, remote attacker to make the server issue arbitrary outbound network requests and read back the responses. This could potentially be used to reach internal-only services or other network-restricted resources.
π@cveNotify
GitHub
[SDF] Kiteworks Secure Data Forms before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF)
### Description
Secure Data Forms contained a Server-Side Request Forgery vulnerability that could allow an unauthenticated, remote attacker to make the server issue arbitrary outbound network req...
Secure Data Forms contained a Server-Side Request Forgery vulnerability that could allow an unauthenticated, remote attacker to make the server issue arbitrary outbound network req...
π¨ CVE-2026-102092
Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-site Scripting (XSS) that could allow an authenticated user to store crafted content that executes arbitrary JavaScript in another user's authenticated session when they preview shared content. This could potentially lead to session compromise and account takeover.
π@cveNotify
Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-site Scripting (XSS) that could allow an authenticated user to store crafted content that executes arbitrary JavaScript in another user's authenticated session when they preview shared content. This could potentially lead to session compromise and account takeover.
π@cveNotify
GitHub
[Core] Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-site Scripting (XSS)
### Description
Kiteworks Core contained a stored Cross-site Scripting vulnerability that could allow an authenticated user to store crafted content that executes arbitrary JavaScript in another u...
Kiteworks Core contained a stored Cross-site Scripting vulnerability that could allow an authenticated user to store crafted content that executes arbitrary JavaScript in another u...