DEV Community

# cve

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
CVE-2026-23996: The Tell-Tale Delay: Timing Side-Channels in fastapi-api-key

CVE-2026-23996: The Tell-Tale Delay: Timing Side-Channels in fastapi-api-key

Comments
2 min read
GHSA-VX9W-5CX4-9796: Crawl4AI: When Web Scrapers Become File Servers

GHSA-VX9W-5CX4-9796: Crawl4AI: When Web Scrapers Become File Servers

Comments
2 min read
GHSA-F2MF-Q878-GH58: Parsl Tongue: SQL Injection in High-Performance Computing Visualization

GHSA-F2MF-Q878-GH58: Parsl Tongue: SQL Injection in High-Performance Computing Visualization

Comments
2 min read
CVE-2026-21441: The Invisible Avalanche: urllib3 Decompression Bomb

CVE-2026-21441: The Invisible Avalanche: urllib3 Decompression Bomb

Comments
2 min read
CVE-2026-22200: Paper Cuts to Pwnage: Turning osTicket PDF Exports into RCE

CVE-2026-22200: Paper Cuts to Pwnage: Turning osTicket PDF Exports into RCE

Comments
2 min read
CVE-2025-32444: Pickle Rick-Roll: Critical RCE in vLLM's Mooncake Integration

CVE-2025-32444: Pickle Rick-Roll: Critical RCE in vLLM's Mooncake Integration

Comments
2 min read
GHSA-RHFX-M35P-FF5J: Borrow Checker's Revenge: Stacked Borrows Violation in Rust's `lru` Crate

GHSA-RHFX-M35P-FF5J: Borrow Checker's Revenge: Stacked Borrows Violation in Rust's `lru` Crate

Comments
2 min read
CVE-2026-22708: Trust Issues: Bypassing Cursor AI's 'Safe Mode' via Shell Built-ins

CVE-2026-22708: Trust Issues: Bypassing Cursor AI's 'Safe Mode' via Shell Built-ins

Comments
2 min read
CVE-2025-61984: Bash a Newline: The SSH ProxyCommand RCE You Didn't Know You Had

CVE-2025-61984: Bash a Newline: The SSH ProxyCommand RCE You Didn't Know You Had

Comments
2 min read
CVE-2026-23498: Shopware 6: Mapping Your Way to RCE via Twig Type Juggling

CVE-2026-23498: Shopware 6: Mapping Your Way to RCE via Twig Type Juggling

Comments
2 min read
CVE-2025-66648: Vega's Visual Betrayal: Leaking the Window via Internal Functions

CVE-2025-66648: Vega's Visual Betrayal: Leaking the Window via Internal Functions

Comments
2 min read
CVE-2026-24785: The Sound of Silence: Breaking Clatter's Post-Quantum Promises (CVE-2026-24785)

CVE-2026-24785: The Sound of Silence: Breaking Clatter's Post-Quantum Promises (CVE-2026-24785)

Comments
2 min read
CVE-2025-69202: The Shared Hallucination: Authorization Bypass in axios-cache-interceptor

CVE-2025-69202: The Shared Hallucination: Authorization Bypass in axios-cache-interceptor

Comments
2 min read
CVE-2025-69256: Serverless Command Injection: When 'Experimental' Means 'Remote Shell'

CVE-2025-69256: Serverless Command Injection: When 'Experimental' Means 'Remote Shell'

Comments
2 min read
CVE-2026-21446: Bagisto's Open House: How an AJAX Header Stole the Admin Panel

CVE-2026-21446: Bagisto's Open House: How an AJAX Header Stole the Admin Panel

Comments
2 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.