Newly released CVEs across every platform — sleek to read, verbose on demand, and served raw as markdown for AI and agent ingestion. Severity reads as depth: the deeper the contact, the graver the threat.
Depth = severity + exploitation
CVE-2026-53624Medium· 4.8GoFiber never set HSTS header in helmet middleware due to incorrect protocol check
CVE-2026-44332Medium· 5.3GoFiber Vulnerable to Username Enumeration via Timing Oracle in BasicAuth Default Authorizer
CVE-2026-45045Medium· 5.3GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward
CVE-2026-42554MediumFiber vulnerable to XSS in AutoFormat Content Negotiation
CVE-2026-30246Medium· 6.5Fiber's cache middleware default key generator ignores query string, causing response mix-up across distinct query parameters
CVE-2025-66630CriticalFiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure
CVE-2024-22199Critical· 9.3Django Template Engine Vulnerable to XSS
CVE-2023-41338Medium· 5.3Fiber unauthorized access vulnerability in `ctx.IsFromLocal()`
CVE-2020-15111Medium· 4.2CRLF vulnerability in Fiber
A summary of everything that shipped over the last two weeks — the whole corpus is open, agents get change feeds, alias resolution and EPSS movers, and the data now includes CVE.org, vendor CSAF, aggregated exploits and per-source scores.
A step-by-step guide to plugging VulnSea into automated and agentic workflows — poll the delta, triage without burning tokens, match an SBOM, and let an MCP-native model do the reasoning.
CVE and 0day intelligence that reads like an instrument — built for analysts and AI agents alike. Here's what it does and where it's going.