CVE-2025-14946Medium· 4.8▾ SunlitA flaw was found in libnbd. A malicious actor could exploit this by convincing libnbd to open a specially crafted Uniform Resource Identifier (URI). This vulnerability arises because non-standard hostnames starting with '-o' are incorrec…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 26.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.1%
A flaw was found in libnbd. A malicious actor could exploit this by convincing libnbd to open a specially crafted Uniform Resource Identifier (URI). This vulnerability arises because non-standard hostnames starting with '-o' are incorrectly interpreted as arguments to the Secure Shell (SSH) process, rather than as hostnames. This could lead to arbitrary code execution with the privileges of the user running libnbd.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-40938High· 7.5Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines
CVE-2026-102904Medium· 5.4JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture
CVE-2026-24061Critical· 9.8telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
CVE-2026-102827High· 8.1simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript
CVE-2026-81529High· 7.1Improper neutralization of delimiters in connection-URL construction allows connection-option injection in the MongoDB C# Driver
CVE-2026-86035High· 8.5Weblate is a web-based continuous localization platform used to manage software translations