๐จ CVE-2026-102995
pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can place unusually large source-code or destination-string tokens in a font /ToUnicode mapping, causing pypdf/_cmap.py parse_bfchar to decode and retain oversized values during operations such as text extraction and consume excessive memory. This is a second follow-up to earlier /ToUnicode resource-consumption fixes and is limited to the remaining token-length path. This issue is fixed in version 6.18.1.
๐@cveNotify
pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can place unusually large source-code or destination-string tokens in a font /ToUnicode mapping, causing pypdf/_cmap.py parse_bfchar to decode and retain oversized values during operations such as text extraction and consume excessive memory. This is a second follow-up to earlier /ToUnicode resource-consumption fixes and is limited to the remaining token-length path. This issue is fixed in version 6.18.1.
๐@cveNotify
GitHub
SEC: Limit allowed length of tokens in parse_bfchar (#4071) ยท py-pdf/pypdf@319d0b8
Additionally, we introduce further length validation checks while we are
at it to better deal with malformed inputs.
at it to better deal with malformed inputs.
๐จ CVE-2026-102996
pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can provide a TrueType or Type1 simple font with an unusually large /Widths array, causing pypdf/_font.py Font._collect_tt_t1_character_widths to process entries beyond the 256 character codes meaningful for a simple font and consume excessive memory during operations such as text extraction. This issue is fixed in version 6.18.1.
๐@cveNotify
pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can provide a TrueType or Type1 simple font with an unusually large /Widths array, causing pypdf/_font.py Font._collect_tt_t1_character_widths to process entries beyond the 256 character codes meaningful for a simple font and consume excessive memory during operations such as text extraction. This issue is fixed in version 6.18.1.
๐@cveNotify
GitHub
SEC: Limit entry count for TrueType and Type1 font `/Widths` (#4072) ยท py-pdf/pypdf@0fb26eb
A pure-python PDF library capable of splitting, merging, cropping, and transforming the pages of PDF files - SEC: Limit entry count for TrueType and Type1 font `/Widths` (#4072) ยท py-pdf/pypdf@0fb26eb
๐จ CVE-2026-102997
pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF containing a partially malformed /FlateDecode stream with padded data can force pypdf/filters.py to use inefficient byte-by-byte decompression while the earlier recovery counter fails to advance for bytes that successfully decode, causing long runtimes and application unavailability. This is a residual issue after the malformed FlateDecode recovery fix. This issue is fixed in version 6.18.1.
๐@cveNotify
pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF containing a partially malformed /FlateDecode stream with padded data can force pypdf/filters.py to use inefficient byte-by-byte decompression while the earlier recovery counter fails to advance for bytes that successfully decode, causing long runtimes and application unavailability. This is a residual issue after the malformed FlateDecode recovery fix. This issue is fixed in version 6.18.1.
๐@cveNotify
GitHub
SEC: Further restrict FlateDecode recovery (#4073) ยท py-pdf/pypdf@d9d38cf
Previously, we would only count invalid bytes which could not be decoded
in `/FlateDecode` recovery. This avoids excessive iteration for the
completely broken data we tested with, as every input by...
in `/FlateDecode` recovery. This avoids excessive iteration for the
completely broken data we tested with, as every input by...
๐จ CVE-2026-102998
pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF with form field values can cause pypdf/generic/_appearance_stream.py appearance-stream generation to repeat invariant selection-data work inside a loop when an application updates fields with flattening enabled, resulting in excessive runtimes and application unavailability. This issue is fixed in version 6.19.0.
๐@cveNotify
pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF with form field values can cause pypdf/generic/_appearance_stream.py appearance-stream generation to repeat invariant selection-data work inside a loop when an application updates fields with flattening enabled, resulting in excessive runtimes and application unavailability. This issue is fixed in version 6.19.0.
๐@cveNotify
GitHub
PI: Move static value out of loop body for appearance stream data (#4โฆ ยท py-pdf/pypdf@959467a
โฆ087)
๐จ CVE-2026-102999
pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF containing many embedded files can cause the dictionary-based attachments API in pypdf/_doc_common.py to reparse the full attachment list for each content lookup, producing repeated work and long runtimes when an application accesses the embedded-file mapping. This issue is fixed in version 6.19.0.
๐@cveNotify
pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF containing many embedded files can cause the dictionary-based attachments API in pypdf/_doc_common.py to reparse the full attachment list for each content lookup, producing repeated work and long runtimes when an application accesses the embedded-file mapping. This issue is fixed in version 6.19.0.
๐@cveNotify
GitHub
PI: Reduce number of full data lookups for attachment mapping API (#4โฆ ยท py-pdf/pypdf@6b10556
โฆ081)
With the old implementation, when iterating over the attachment mapping
using `.items()`, each content retrieval would re-parse the whole
attachment list to find the correct attachments. Thi...
With the old implementation, when iterating over the attachment mapping
using `.items()`, each content retrieval would re-parse the whole
attachment list to find the correct attachments. Thi...
๐จ CVE-2026-103000
pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF can provide unusually large alphabetical page-label values that cause pypdf/_page_labels.py to generate strings beyond a reasonable page-label length when an application retrieves document page labels, consuming excessive memory and potentially making the application unavailable. This issue is fixed in version 6.19.0.
๐@cveNotify
pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF can provide unusually large alphabetical page-label values that cause pypdf/_page_labels.py to generate strings beyond a reasonable page-label length when an application retrieves document page labels, consuming excessive memory and potentially making the application unavailable. This issue is fixed in version 6.19.0.
๐@cveNotify
GitHub
SEC: Limit size of alphabetical page labels (#4096) ยท py-pdf/pypdf@0d8b5a8
A pure-python PDF library capable of splitting, merging, cropping, and transforming the pages of PDF files - SEC: Limit size of alphabetical page labels (#4096) ยท py-pdf/pypdf@0d8b5a8
๐จ CVE-2026-51568
modelscope Agentscope v1.0.18-v1.0.0 is vulnerable to Path Traversal in write_text_file.
๐@cveNotify
modelscope Agentscope v1.0.18-v1.0.0 is vulnerable to Path Traversal in write_text_file.
๐@cveNotify
Gist
CVE-2026-51568 - Directory Traversal in AgentScope (_write_text_file.py:write_text_file)
CVE-2026-51568 - Directory Traversal in AgentScope (_write_text_file.py:write_text_file) - CVE-2026-51568.md
๐จ CVE-2026-51570
modelscope Agentscope v1.0.0-v1.0.8 is vulnerable to Path Traversal in insert_text_file.
๐@cveNotify
modelscope Agentscope v1.0.0-v1.0.8 is vulnerable to Path Traversal in insert_text_file.
๐@cveNotify
Gist
CVE-2026-51570 - Directory Traversal in AgentScope (_write_text_file.py:insert_text_file)
CVE-2026-51570 - Directory Traversal in AgentScope (_write_text_file.py:insert_text_file) - CVE-2026-51570.md
๐จ CVE-2026-51859
bisheng 2.3.0, 2.4.0, and 2.4.0-beta1 is vulnerable to directory traversal in save_download_file (src/backend/bisheng/core/cache/utils.py:290).
๐@cveNotify
bisheng 2.3.0, 2.4.0, and 2.4.0-beta1 is vulnerable to directory traversal in save_download_file (src/backend/bisheng/core/cache/utils.py:290).
๐@cveNotify
Gist
CVE-2026-51859 - Directory Traversal in bisheng (utils.py:save_download_file)
CVE-2026-51859 - Directory Traversal in bisheng (utils.py:save_download_file) - CVE-2026-51859.md
๐จ CVE-2026-51860
bisheng 2.3.0, 2.4.0, and 2.4.0-beta1 is vulnerable to Directory Traversal in src/backend/bisheng/linsight/domain/task_exec.py.
๐@cveNotify
bisheng 2.3.0, 2.4.0, and 2.4.0-beta1 is vulnerable to Directory Traversal in src/backend/bisheng/linsight/domain/task_exec.py.
๐@cveNotify
Gist
CVE-2026-51860 - Directory Traversal in bisheng (task_exec.py:LinsightWorkflowTask._download_file)
CVE-2026-51860 - Directory Traversal in bisheng (task_exec.py:LinsightWorkflowTask._download_file) - CVE-2026-51860.md
๐จ CVE-2026-51862
DB-GPT 0.8.0 contains directory traversal in skill_upload (packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py:40). A remote attacker can use the validated exploitation path to write files outside the intended workspace or storage boundary.
๐@cveNotify
DB-GPT 0.8.0 contains directory traversal in skill_upload (packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py:40). A remote attacker can use the validated exploitation path to write files outside the intended workspace or storage boundary.
๐@cveNotify
Gist
CVE-2026-51862 - Directory Traversal in DB-GPT (agentic_data_api.py:skill_upload)
CVE-2026-51862 - Directory Traversal in DB-GPT (agentic_data_api.py:skill_upload) - CVE-2026-51862.md
๐จ CVE-2026-51864
DB-GPT v0.7.5 and v0.8.0 contains directory traversal in python_file_upload (packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/python_upload_api.py:42). A remote attacker can use the validated exploitation path to write files outside the intended workspace or storage boundary.
๐@cveNotify
DB-GPT v0.7.5 and v0.8.0 contains directory traversal in python_file_upload (packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/python_upload_api.py:42). A remote attacker can use the validated exploitation path to write files outside the intended workspace or storage boundary.
๐@cveNotify
Gist
CVE-2026-51864 - Directory Traversal in DB-GPT (python_upload_api.py:python_file_upload)
CVE-2026-51864 - Directory Traversal in DB-GPT (python_upload_api.py:python_file_upload) - CVE-2026-51864.md
๐จ CVE-2026-51866
In DB-GPT 0.7.5 and 0.8.0, a skill uploaded through the real /api/v1/skills/upload route can later be executed through the real /api/v1/chat/react-agent flow.
๐@cveNotify
In DB-GPT 0.7.5 and 0.8.0, a skill uploaded through the real /api/v1/skills/upload route can later be executed through the real /api/v1/chat/react-agent flow.
๐@cveNotify
Gist
CVE-2026-51866 - Code Execution in DB-GPT (manage.py:SkillManager.execute_skill_script_file)
CVE-2026-51866 - Code Execution in DB-GPT (manage.py:SkillManager.execute_skill_script_file) - CVE-2026-51866.md
๐จ CVE-2026-51869
DB-GPT v0.8.0 sandbox API silently falls back to LocalRuntime and executes code on host.
๐@cveNotify
DB-GPT v0.8.0 sandbox API silently falls back to LocalRuntime and executes code on host.
๐@cveNotify
Gist
CVE-2026-51869 - Incorrect Access Control in DB-GPT (runtime_factory.py:RuntimeFactory.create)
CVE-2026-51869 - Incorrect Access Control in DB-GPT (runtime_factory.py:RuntimeFactory.create) - CVE-2026-51869.md
๐จ CVE-2026-51870
DeepTutor v1.4.0 is vulnerable to command execution in /tutorbot/agent/tools/shell.py:ExecTool.execute.
๐@cveNotify
DeepTutor v1.4.0 is vulnerable to command execution in /tutorbot/agent/tools/shell.py:ExecTool.execute.
๐@cveNotify
Gist
CVE-2026-51870 - Command Execution in DeepTutor (shell.py:ExecTool.execute)
CVE-2026-51870 - Command Execution in DeepTutor (shell.py:ExecTool.execute) - CVE-2026-51870.md
๐จ CVE-2026-92172
Prior to v66.0.0.733.524 of Meta Horizon OS, OVRMediaService could be induced to send a privileged PendingIntent including a com.oculus.horizon CallerIdentity to an arbitrary application registering for com.oculus.systemactivities.SCREENSHOT via a broadcast receiver. That would allow the application to impersonate the com.oculus.horizon package towards any endpoint within the OS that uses CallerIdentity authentication.
๐@cveNotify
Prior to v66.0.0.733.524 of Meta Horizon OS, OVRMediaService could be induced to send a privileged PendingIntent including a com.oculus.horizon CallerIdentity to an arbitrary application registering for com.oculus.systemactivities.SCREENSHOT via a broadcast receiver. That would allow the application to impersonate the com.oculus.horizon package towards any endpoint within the OS that uses CallerIdentity authentication.
๐@cveNotify
๐จ CVE-2026-92173
Prior to v74.0.0.878.1682 of Meta Horizon OS, MediaSyncJobReceiver could be induced to send a privileged PendingIntent including a com.oculus.vrshell CallerIdentity to an arbitrary application listening via NotificationListenerService. That would allow the application to impersonate the com.oculus.vrshell package, as well as packages signed with the same key, towards any endpoint within the OS that uses CallerIdentity authentication.
๐@cveNotify
Prior to v74.0.0.878.1682 of Meta Horizon OS, MediaSyncJobReceiver could be induced to send a privileged PendingIntent including a com.oculus.vrshell CallerIdentity to an arbitrary application listening via NotificationListenerService. That would allow the application to impersonate the com.oculus.vrshell package, as well as packages signed with the same key, towards any endpoint within the OS that uses CallerIdentity authentication.
๐@cveNotify
๐จ CVE-2026-101283
iperf3 3.20โ3.21 (esnet/iperf) has a pre-auth heap buffer overflow in decrypt_rsa_message(): a 256-byte RSA buffer is BIO_read with the attacker-controlled ciphertext length (guard warns only), so an unauthenticated client overflows the heap via an oversized authtoken; fixed in 3.22
๐@cveNotify
iperf3 3.20โ3.21 (esnet/iperf) has a pre-auth heap buffer overflow in decrypt_rsa_message(): a 256-byte RSA buffer is BIO_read with the attacker-controlled ciphertext length (guard warns only), so an unauthenticated client overflows the heap via an oversized authtoken; fixed in 3.22
๐@cveNotify
newreleases.io
esnet/iperf 3.22 on GitHub
New release esnet/iperf version 3.22 iperf-3.22 on GitHub.
๐จ CVE-2026-103001
PyJWT is a Python implementation of JSON Web Token standards. From 2.11.0 through 2.13.0, PyJWT's PyJWT._merge_options() method can modify a caller-supplied mutable options mapping when verify_signature is false. If an application reuses that same mapping for a later decode() or decode_complete() call and changes verify_signature to true, the mapping can retain false values for expiration, not-before, issued-at, audience, issuer, subject, and JWT ID checks. A signed token with invalid registered claims can then be accepted without disabling signature verification, but applications that create a fresh options mapping for each call are not affected.
๐@cveNotify
PyJWT is a Python implementation of JSON Web Token standards. From 2.11.0 through 2.13.0, PyJWT's PyJWT._merge_options() method can modify a caller-supplied mutable options mapping when verify_signature is false. If an application reuses that same mapping for a later decode() or decode_complete() call and changes verify_signature to true, the mapping can retain false values for expiration, not-before, issued-at, audience, issuer, subject, and JWT ID checks. A signed token with invalid registered claims can then be accepted without disabling signature verification, but applications that create a fresh options mapping for each call are not affected.
๐@cveNotify
GitHub
Merge commit from fork ยท jpadilla/pyjwt@0c87c8c
Co-authored-by: Josรฉ Padilla <jpadilla@users.noreply.github.com>
๐จ CVE-2026-103592
simple-php-router through 5.4.1.7 contains an IP restriction bypass vulnerability in the IpRestrictAccess middleware that allows remote unauthenticated attackers to bypass IP whitelist and blacklist protections. Attackers can spoof X-Forwarded-For, CF-Connecting-IP, or Client-IP headers to impersonate whitelisted addresses or evade blacklists, gaining access to IP-restricted routes.
๐@cveNotify
simple-php-router through 5.4.1.7 contains an IP restriction bypass vulnerability in the IpRestrictAccess middleware that allows remote unauthenticated attackers to bypass IP whitelist and blacklist protections. Attackers can spoof X-Forwarded-For, CF-Connecting-IP, or Client-IP headers to impersonate whitelisted addresses or evade blacklists, gaining access to IP-restricted routes.
๐@cveNotify
GitHub
GitHub - skipperbent/simple-php-router: Simple, fast and yet powerful PHP router that is easy to get integrated and in any project.โฆ
Simple, fast and yet powerful PHP router that is easy to get integrated and in any project. Heavily inspired by the way Laravel handles routing, with both simplicity and expand-ability in mind. - s...
๐จ CVE-2026-103531
A flaw has been found in OpenSC up to 0.27.1. The impacted element is the function setcos_construct_fci_44 of the file src/libopensc/card-setcos.c. Executing a manipulation of the argument type_attr can lead to stack-based buffer overflow. The attack can be launched remotely. This patch is called ad730304052937c32b4eb489a06835ac6123632c. It is best practice to apply a patch to resolve this issue.
๐@cveNotify
A flaw has been found in OpenSC up to 0.27.1. The impacted element is the function setcos_construct_fci_44 of the file src/libopensc/card-setcos.c. Executing a manipulation of the argument type_attr can lead to stack-based buffer overflow. The attack can be launched remotely. This patch is called ad730304052937c32b4eb489a06835ac6123632c. It is best practice to apply a patch to resolve this issue.
๐@cveNotify
GitHub
GitHub - OpenSC/OpenSC: Open source smart card tools and middleware. PKCS#11/MiniDriver
Open source smart card tools and middleware. PKCS#11/MiniDriver - OpenSC/OpenSC