DEV Community

CVE Reports profile picture

CVE Reports

CVEReports provides daily, automated deep-dives into the latest vulnerabilities, transforming emerging threats into comprehensive technical intelligence.

Joined Joined on  Personal website https://www.cvereports.com
CVE-2026-88016: CVE-2026-88016: Arbitrary Filesystem Metadata Modification and Directory Traversal in rclone

CVE-2026-88016: CVE-2026-88016: Arbitrary Filesystem Metadata Modification and Directory Traversal in rclone

Comments
2 min read
GHSA-M3WP-48JR-VR4G: GHSA-m3wp-48jr-vr4g: Unbounded Remote Media Fetch and Video Frame Expansion DoS in mistral.rs

GHSA-M3WP-48JR-VR4G: GHSA-m3wp-48jr-vr4g: Unbounded Remote Media Fetch and Video Frame Expansion DoS in mistral.rs

Comments
2 min read
CVE-2026-86083: CVE-2026-86083: Sandbox Escape and Remote Code Execution via Code-Printer Injection in n8n Legacy Expression Engine

CVE-2026-86083: CVE-2026-86083: Sandbox Escape and Remote Code Execution via Code-Printer Injection in n8n Legacy Expression Engine

Comments
2 min read
CVE-2026-87017: CVE-2026-87017: Broken Object-Level Authorization (BOLA) in Open WebUI Knowledge Search

CVE-2026-87017: CVE-2026-87017: Broken Object-Level Authorization (BOLA) in Open WebUI Knowledge Search

Comments
2 min read
CVE-2026-86076: CVE-2026-86076: Remote Code Execution via Expression Sandbox Escape in n8n

CVE-2026-86076: CVE-2026-86076: Remote Code Execution via Expression Sandbox Escape in n8n

Comments
2 min read
CVE-2026-86075: CVE-2026-86075: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint in n8n

CVE-2026-86075: CVE-2026-86075: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint in n8n

Comments
2 min read
CVE-2025-21587: CVE-2025-21587: Timing Side-Channel Vulnerability in JSSE RSA Decryption

CVE-2025-21587: CVE-2025-21587: Timing Side-Channel Vulnerability in JSSE RSA Decryption

Comments
2 min read
CVE-2026-86081: CVE-2026-86081: Regular Expression Denial of Service in n8n Git Node

CVE-2026-86081: CVE-2026-86081: Regular Expression Denial of Service in n8n Git Node

Comments
2 min read
CVE-2026-86082: CVE-2026-86082: Server-Side Request Forgery and Credential Leakage in n8n OpenAI Chat Model Node

CVE-2026-86082: CVE-2026-86082: Server-Side Request Forgery and Credential Leakage in n8n OpenAI Chat Model Node

Comments
2 min read
GHSA-HXJG-93WC-H8P8: GHSA-hxjg-93wc-h8p8: Cross-Site Request Forgery in Komari Management Interface

GHSA-HXJG-93WC-H8P8: GHSA-hxjg-93wc-h8p8: Cross-Site Request Forgery in Komari Management Interface

Comments
2 min read
CVE-2026-88002: CVE-2026-88002: Infinite Loop Denial of Service in Open WebUI Chat History Reconstruction

CVE-2026-88002: CVE-2026-88002: Infinite Loop Denial of Service in Open WebUI Chat History Reconstruction

Comments
2 min read
CVE-2026-88001: CVE-2026-88001: Server-Side Request Forgery via Redirect Bypass in Open WebUI

CVE-2026-88001: CVE-2026-88001: Server-Side Request Forgery via Redirect Bypass in Open WebUI

Comments
2 min read
CVE-2026-88000: CVE-2026-88000: Denial of Service via Infinite Loop in Open WebUI Chat History Deletion

CVE-2026-88000: CVE-2026-88000: Denial of Service via Infinite Loop in Open WebUI Chat History Deletion

Comments
2 min read
CVE-2026-71328: CVE-2026-71328: Heap-Based Buffer Overflow in Microsoft .NET and Visual Studio Parser

CVE-2026-71328: CVE-2026-71328: Heap-Based Buffer Overflow in Microsoft .NET and Visual Studio Parser

Comments
2 min read
CVE-2026-69439: CVE-2026-69439: Heap-based Buffer Overflow in Microsoft .NET and Visual Studio

CVE-2026-69439: CVE-2026-69439: Heap-based Buffer Overflow in Microsoft .NET and Visual Studio

Comments
2 min read
CVE-2026-85730: CVE-2026-85730: Infinite Loop Denial of Service in smol-toml Parser

CVE-2026-85730: CVE-2026-85730: Infinite Loop Denial of Service in smol-toml Parser

Comments
2 min read
CVE-2026-69522: .NET and Visual Studio Remote Code Execution Vulnerability (CVE-2026-69522)

CVE-2026-69522: .NET and Visual Studio Remote Code Execution Vulnerability (CVE-2026-69522)

Comments
2 min read
CVE-2026-69304: CVE-2026-69304: Denial of Service via Request Decompression Data Amplification in ASP.NET Core

CVE-2026-69304: CVE-2026-69304: Denial of Service via Request Decompression Data Amplification in ASP.NET Core

Comments
3 min read
CVE-2026-84361: CVE-2026-84361: Remote Code Execution in Composer Perforce VCS Driver

CVE-2026-84361: CVE-2026-84361: Remote Code Execution in Composer Perforce VCS Driver

Comments
2 min read
CVE-2026-84376: CVE-2026-84376: Authorization Bypass via Missing Path-Segment Boundary Validation in Astro

CVE-2026-84376: CVE-2026-84376: Authorization Bypass via Missing Path-Segment Boundary Validation in Astro

Comments 1
2 min read
GHSA-26W7-CXV4-GFX2: GHSA-26W7-CXV4-GFX2: Remote Code Execution in Astro via Outdated Sharp Native Dependency

GHSA-26W7-CXV4-GFX2: GHSA-26W7-CXV4-GFX2: Remote Code Execution in Astro via Outdated Sharp Native Dependency

Comments
2 min read
CVE-2026-81525: CVE-2026-81525: Cross-Tenant Database Retargeting via Dot and Null Injection in MongoDB PHP Driver

CVE-2026-81525: CVE-2026-81525: Cross-Tenant Database Retargeting via Dot and Null Injection in MongoDB PHP Driver

Comments
3 min read
CVE-2026-84452: CVE-2026-84452: Localhost Remote Code Execution via CORS Misconfiguration in Windows ML CLI

CVE-2026-84452: CVE-2026-84452: Localhost Remote Code Execution via CORS Misconfiguration in Windows ML CLI

Comments
2 min read
CVE-2026-15603: CVE-2026-15603: Log Forging via Unescaped Unicode Line Separators in morgan Middleware

CVE-2026-15603: CVE-2026-15603: Log Forging via Unescaped Unicode Line Separators in morgan Middleware

Comments
2 min read
CVE-2026-82333: CVE-2026-82333: Remote Denial of Service via Sparse Array Manipulation in Multer

CVE-2026-82333: CVE-2026-82333: Remote Denial of Service via Sparse Array Manipulation in Multer

Comments
2 min read
CVE-2026-77063: CVE-2026-77063: File Size Limit Bypass via Asynchronous Race Condition in Multer

CVE-2026-77063: CVE-2026-77063: File Size Limit Bypass via Asynchronous Race Condition in Multer

Comments
2 min read
CVE-2026-77037: CVE-2026-77037: File Descriptor Leak and Denial of Service in Multer Disk Storage

CVE-2026-77037: CVE-2026-77037: File Descriptor Leak and Denial of Service in Multer Disk Storage

Comments
2 min read
CVE-2026-77078: CVE-2026-77078: Remote Denial of Service in Multer Middleware via Array Suffix Handling

CVE-2026-77078: CVE-2026-77078: Remote Denial of Service in Multer Middleware via Array Suffix Handling

Comments
2 min read
GHSA-2Q42-4Q24-7RGV: Path Traversal Vulnerability in Microsoft TypeSpec Core and Emitter Packages

GHSA-2Q42-4Q24-7RGV: Path Traversal Vulnerability in Microsoft TypeSpec Core and Emitter Packages

Comments
2 min read
GHSA-CC9R-2J5M-2M83: GHSA-CC9R-2J5M-2M83: Parser Differential and Domain Validation Bypass in Nodemailer

GHSA-CC9R-2J5M-2M83: GHSA-CC9R-2J5M-2M83: Parser Differential and Domain Validation Bypass in Nodemailer

Comments
2 min read
GHSA-2X7J-588G-CCC2: GHSA-2x7j-588g-ccc2: Algorithmic Complexity Denial of Service in Nodemailer

GHSA-2X7J-588G-CCC2: GHSA-2x7j-588g-ccc2: Algorithmic Complexity Denial of Service in Nodemailer

Comments
2 min read
GHSA-WMMP-3585-3RMP: GHSA-WMMP-3585-3RMP: IDN/Punycode Domain Allow-list Bypass in Nodemailer

GHSA-WMMP-3585-3RMP: GHSA-WMMP-3585-3RMP: IDN/Punycode Domain Allow-list Bypass in Nodemailer

Comments
1 min read
CVE-2026-86996: CVE-2026-86996: Missing Authorization in n8n AI Agent Workflow Tool Execution

CVE-2026-86996: CVE-2026-86996: Missing Authorization in n8n AI Agent Workflow Tool Execution

Comments
2 min read
CVE-2026-83612: CVE-2026-83612: Algorithmic Complexity and Denial of Service via Output Amplification in xmldom

CVE-2026-83612: CVE-2026-83612: Algorithmic Complexity and Denial of Service via Output Amplification in xmldom

Comments
2 min read
CVE-2026-78679: CVE-2026-78679: Arbitrary File Read via Command-Line Option Injection in GitPython

CVE-2026-78679: CVE-2026-78679: Arbitrary File Read via Command-Line Option Injection in GitPython

Comments
2 min read
CVE-2026-78677: CVE-2026-78677: Path Traversal and Arbitrary File Write in GitPython

CVE-2026-78677: CVE-2026-78677: Path Traversal and Arbitrary File Write in GitPython

Comments
2 min read
CVE-2026-72925: CVE-2026-72925: Cross-Site Scripting via Improper JSON Escaping in SWC HTML Minifier

CVE-2026-72925: CVE-2026-72925: Cross-Site Scripting via Improper JSON Escaping in SWC HTML Minifier

Comments
2 min read
CVE-2026-79674: CVE-2026-79674: Path Sandbox Bypass in NLTK CorpusReader Constructors

CVE-2026-79674: CVE-2026-79674: Path Sandbox Bypass in NLTK CorpusReader Constructors

Comments
2 min read
CVE-2026-12259: CVE-2026-12259: Improper Integrity Verification (Extract-Before-Verify) in NLTK Downloader

CVE-2026-12259: CVE-2026-12259: Improper Integrity Verification (Extract-Before-Verify) in NLTK Downloader

Comments
2 min read
CVE-2026-75856: CVE-2026-75856: Server-Side Request Forgery (SSRF) Bypass via DNS Resolution TOCTOU in CodeWhale

CVE-2026-75856: CVE-2026-75856: Server-Side Request Forgery (SSRF) Bypass via DNS Resolution TOCTOU in CodeWhale

Comments
2 min read
CVE-2026-75912: CVE-2026-75912: Argument Injection and Arbitrary File Disclosure in CodeWhale Git Tools

CVE-2026-75912: CVE-2026-75912: Argument Injection and Arbitrary File Disclosure in CodeWhale Git Tools

Comments
2 min read
CVE-2026-63735: CVE-2026-63735: Cross-Tenant Authorization Bypass in SurrealDB Custom API Routing Handler

CVE-2026-63735: CVE-2026-63735: Cross-Tenant Authorization Bypass in SurrealDB Custom API Routing Handler

Comments
2 min read
CVE-2026-63733: CVE-2026-63733: Incorrect Authorization in SurrealDB Permissions Clause

CVE-2026-63733: CVE-2026-63733: Incorrect Authorization in SurrealDB Permissions Clause

Comments
2 min read
CVE-2026-72799: CVE-2026-72799: Missing Authorization in SiYuan Filetree Path-Resolution API

CVE-2026-72799: CVE-2026-72799: Missing Authorization in SiYuan Filetree Path-Resolution API

Comments
2 min read
CVE-2026-72798: CVE-2026-72798: Missing Authorization and Information Disclosure in SiYuan renderAttributeView

CVE-2026-72798: CVE-2026-72798: Missing Authorization and Information Disclosure in SiYuan renderAttributeView

Comments
2 min read
CVE-2026-72797: CVE-2026-72797: Missing Authorization in SiYuan Notebook Metadata Endpoint

CVE-2026-72797: CVE-2026-72797: Missing Authorization in SiYuan Notebook Metadata Endpoint

Comments
2 min read
CVE-2026-72794: CVE-2026-72794: Cryptographic Key Leakage and Session Forgery in SiYuan

CVE-2026-72794: CVE-2026-72794: Cryptographic Key Leakage and Session Forgery in SiYuan

Comments
2 min read
CVE-2026-72795: CVE-2026-72795: Missing Authorization in SiYuan Block DOM Rendering

CVE-2026-72795: CVE-2026-72795: Missing Authorization in SiYuan Block DOM Rendering

Comments
2 min read
CVE-2026-72793: CVE-2026-72793: Information Disclosure and Session Forgery in SiYuan Note-Taking Application

CVE-2026-72793: CVE-2026-72793: Information Disclosure and Session Forgery in SiYuan Note-Taking Application

Comments
2 min read
CVE-2026-72792: CVE-2026-72792: Information Disclosure via Tag API Endpoint in SiYuan

CVE-2026-72792: CVE-2026-72792: Information Disclosure via Tag API Endpoint in SiYuan

Comments
2 min read
CVE-2026-71486: CVE-2026-71486: Uncontrolled Resource Consumption in vLLM Derender Endpoints

CVE-2026-71486: CVE-2026-71486: Uncontrolled Resource Consumption in vLLM Derender Endpoints

Comments
2 min read
CVE-2026-73555: CVE-2026-73555: Environment and Information Disclosure via Exception Handling in vLLM

CVE-2026-73555: CVE-2026-73555: Environment and Information Disclosure via Exception Handling in vLLM

Comments
2 min read
CVE-2026-73556: CVE-2026-73556: Regular Expression Denial of Service (ReDoS) in vLLM lm-format-enforcer Backend

CVE-2026-73556: CVE-2026-73556: Regular Expression Denial of Service (ReDoS) in vLLM lm-format-enforcer Backend

Comments
2 min read
CVE-2026-73557: CVE-2026-73557: Race Condition in PyTorch Tensor Invariant Checks within vLLM Engine

CVE-2026-73557: CVE-2026-73557: Race Condition in PyTorch Tensor Invariant Checks within vLLM Engine

Comments
2 min read
CVE-2026-73842: CVE-2026-73842: Missing Authentication and Authorization on Internal Management Listener in OpenChoreo cluster-gateway

CVE-2026-73842: CVE-2026-73842: Missing Authentication and Authorization on Internal Management Listener in OpenChoreo cluster-gateway

Comments
2 min read
GHSA-7Q9C-HPX7-9CWM: GHSA-7Q9C-HPX7-9CWM: Unauthenticated Remote Shutdown in @typespec/spector Mock Server

GHSA-7Q9C-HPX7-9CWM: GHSA-7Q9C-HPX7-9CWM: Unauthenticated Remote Shutdown in @typespec/spector Mock Server

Comments
2 min read
CVE-2026-72796: CVE-2026-72796: Access Control Bypass via Static Routes in SiYuan

CVE-2026-72796: CVE-2026-72796: Access Control Bypass via Static Routes in SiYuan

Comments
2 min read
CVE-2026-75858: CVE-2026-75858: Silent Remote Code Execution via Approval Bypass in CodeWhale Interactive Tools

CVE-2026-75858: CVE-2026-75858: Silent Remote Code Execution via Approval Bypass in CodeWhale Interactive Tools

Comments
2 min read
CVE-2026-75911: CVE-2026-75911: Remote Code Execution via Configuration Override in CodeWhale

CVE-2026-75911: CVE-2026-75911: Remote Code Execution via Configuration Override in CodeWhale

Comments
2 min read
CVE-2026-75914: CVE-2026-75914: Improper Link Resolution and Path Traversal in CodeWhale image_analyze Tool

CVE-2026-75914: CVE-2026-75914: Improper Link Resolution and Path Traversal in CodeWhale image_analyze Tool

Comments
2 min read
loading...