CVE-2024-3094Critical· 10.0▾ AbyssalPoC availableA backdoor was intentionally introduced into the xz-utils upstream release tarballs (5.6.0 / 5.6.1). When linked into sshd via liblzma, it allows a remote attacker holding a specific key to bypass authentication and execute commands.
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 55 · likelihood 17.2 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 5.
Disclosure to exploitation, from the record and what we observed since indexing it.
86%
84 GitHub repos
Releases 5.6.0 and 5.6.1 of xz-utils shipped source tarballs containing a
deliberately planted backdoor in liblzma. The malicious build logic was hidden in
test fixtures and a modified build-to-host.m4, activating only inside release
tarballs (not the git tree).
On systems where sshd is patched to link liblzma (Debian/Fedora-style systemd
notification), the backdoor hooks the RSA key verification path, allowing an attacker
with the correct private key to achieve pre-auth remote code execution.
Andres Freund noticed ~500 ms of extra latency on SSH logins and elevated CPU in
liblzma, then traced it to the planted payload — caught days after release, before
wide distro adoption.
Only 5.6.0 and 5.6.1 upstream tarballs. Most stable distros were still on 5.4.x
and were never exposed. Rolling distros (Fedora 40/41 beta, Debian sid, Kali,
openSUSE Tumbleweed) shipped the bad versions transiently.
xz --version # if 5.6.0 or 5.6.1 -> downgrade immediately
xz/liblzma to 5.4.x or upgrade to a patched 5.6.2+.Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-66747Critical· 9.8Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line
CVE-2026-48161Nonereact18-use is a React 19 use hook shim
CVE-2026-73533Critical· 9.8Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server
CVE-2026-48158Critical· 9.3use-context-selector is a React useContextSelector hook in userland Between 2026-05-18 15:57:18 and 2026-05-19 15:24:34, the default branch contained malicious commits 9d8481a513b7b0d1c0941b220c69b25de748641b through 6f2dae054ca014068bdb…
CVE-2026-73532Critical· 9.8Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server
CVE-2026-48160Nonereact-tracked provides state usage tracking with Proxies