Newly released CVEs across every platform — sleek to read, verbose on demand, and served raw as markdown for AI and agent ingestion. Severity reads as depth: the deeper the contact, the graver the threat.
Depth = severity + exploitation
CVE-2026-56860High· 7.5Avoid quadratic complexity in resolvePath in net/url
CVE-2026-56858High· 8.1Fix Javascript regexp context tracking in html/template
CVE-2026-56862High· 7.5Limit handshake messages we are willing to accept post-handshake in crypto/tls
CVE-2026-56859High· 7.5Add recursion depth guard during decode in encoding/xml
CVE-2026-33818High· 7.5Enforce maximum recursion depth in encoding/asn1
CVE-2026-42504High· 7.5Quadratic complexity in WordDecoder.DecodeHeader in mime
CVE-2025-68121NoneUnexpected session resumption in crypto/tls
CVE-2025-61728NoneExcessive CPU consumption when building archive index in archive/zip
CVE-2025-61729NoneExcessive resource consumption when printing error string for host certificate validation in crypto/x509
CVE-2025-58183NoneUnbounded allocation when parsing GNU sparse map in archive/tar
CVE-2024-34158NoneStack exhaustion in Parse in go/build/constraint
CVE-2022-41715NoneMemory exhaustion when compiling regular expressions in regexp/syntax
CVE-2022-2880NoneIncorrect sanitization of forwarded query parameters in net/http/httputil
CVE-2022-2879NoneUnbounded memory consumption when reading headers in archive/tar
CVE-2022-32190NoneFailure to strip relative path components in net/url
A summary of everything that shipped over the last two weeks — the whole corpus is open, agents get change feeds, alias resolution and EPSS movers, and the data now includes CVE.org, vendor CSAF, aggregated exploits and per-source scores.
A step-by-step guide to plugging VulnSea into automated and agentic workflows — poll the delta, triage without burning tokens, match an SBOM, and let an MCP-native model do the reasoning.
CVE and 0day intelligence that reads like an instrument — built for analysts and AI agents alike. Here's what it does and where it's going.