DEV Community

# cve

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
CVE-2026-27206: The Zumba Class Dance: RCE via PHP Object Injection in json-serializer

CVE-2026-27206: The Zumba Class Dance: RCE via PHP Object Injection in json-serializer

Comments
2 min read
GHSA-6QR9-G2XW-CW92: Dagu: The Friendly Ghost that Runs Your Malware (GHSA-6QR9-G2XW-CW92)

GHSA-6QR9-G2XW-CW92: Dagu: The Friendly Ghost that Runs Your Malware (GHSA-6QR9-G2XW-CW92)

Comments
2 min read
GHSA-GV8R-9RW9-9697: The Ghost in the Handshake: Traefik & Go mTLS Bypass in HTTP/3

GHSA-GV8R-9RW9-9697: The Ghost in the Handshake: Traefik & Go mTLS Bypass in HTTP/3

Comments
2 min read
CVE-2026-2472: Poisoned Notebooks: Stored XSS in Google Vertex AI SDK

CVE-2026-2472: Poisoned Notebooks: Stored XSS in Google Vertex AI SDK

Comments
2 min read
CVE-2026-25896: Regex Injection in fast-xml-parser: Shadowing the <

CVE-2026-25896: Regex Injection in fast-xml-parser: Shadowing the <

Comments
2 min read
GHSA-33HQ-FVWR-56PM: The Billion-Comma Attack: Nuking Svelte SSR with Sparse Arrays

GHSA-33HQ-FVWR-56PM: The Billion-Comma Attack: Nuking Svelte SSR with Sparse Arrays

Comments
2 min read
GHSA-6C9J-X93C-RW6J: OpenClaw Side-Channel: The `safeBins` File Existence Oracle

GHSA-6C9J-X93C-RW6J: OpenClaw Side-Channel: The `safeBins` File Existence Oracle

Comments
2 min read
CVE-2026-1669: Model Poisoning: Turning Keras Weights into Weaponized File Readers

CVE-2026-1669: Model Poisoning: Turning Keras Weights into Weaponized File Readers

Comments
2 min read
GHSA-VRHM-GVG7-FPCF: SvelteKit Remote Functions: Death by Type Coercion

GHSA-VRHM-GVG7-FPCF: SvelteKit Remote Functions: Death by Type Coercion

Comments
2 min read
GHSA-RWJ8-P9VQ-25GV: OpenClaw BlueBubbles: When Your iMessage Bridge Becomes a Spy

GHSA-RWJ8-P9VQ-25GV: OpenClaw BlueBubbles: When Your iMessage Bridge Becomes a Spy

Comments
2 min read
GHSA-9PPG-JX86-FQW7: Clinejection: When AI Agents Go Rogue and Poison Your Supply Chain

GHSA-9PPG-JX86-FQW7: Clinejection: When AI Agents Go Rogue and Poison Your Supply Chain

Comments
2 min read
GHSA-3288-P39F-RQPV: Rust Keccak: When 'Immutable' Inputs Go Rogue on ARMv8

GHSA-3288-P39F-RQPV: Rust Keccak: When 'Immutable' Inputs Go Rogue on ARMv8

Comments
2 min read
GHSA-PG2V-8XWH-QHCC: The Call Is Coming From Inside the House: OpenClaw SSRF Analysis

GHSA-PG2V-8XWH-QHCC: The Call Is Coming From Inside the House: OpenClaw SSRF Analysis

Comments
2 min read
GHSA-4564-PVR2-QQ4H: OpenClaw Keychain Injection: When Secure Storage Becomes a Shell

GHSA-4564-PVR2-QQ4H: OpenClaw Keychain Injection: When Secure Storage Becomes a Shell

Comments
2 min read
GHSA-JFV4-H8MC-JCP8: OpenClaw: The Cleanup Crew That Killed Everyone Else's Processes

GHSA-JFV4-H8MC-JCP8: OpenClaw: The Cleanup Crew That Killed Everyone Else's Processes

Comments
2 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.