CVE-2026-105161Medium· 5.3▾ SunlitA flaw has been found in invariant-systems-ai aiir up to 1.7.0. The affected element is an unknown function of the component Policy Gate Handler. Executing a manipulation can lead to improper verification of cryptographic signature. The …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A flaw has been found in invariant-systems-ai aiir up to 1.7.0. The affected element is an unknown function of the component Policy Gate Handler. Executing a manipulation can lead to improper verification of cryptographic signature. The attack can be executed remotely. It is advisable to upgrade the affected component. The GitHub repository of this project is not available anymore. This vulnerability only affects products that are no longer supported by the maintainer.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
GHSA-73p9-6hrp-8qhrMediumAIIR verification and policy gates could report success without enforcing the control (fail-open)
CVE-2026-71887High· 8.2In Bouncy Castle for Java before 1.86, the high-level OpenPGP API accepted a data signature made by a signing subkey whose Subkey Binding signature carried no embedded Primary Key Binding (cross-certification) signature, in the case wher…
CVE-2026-55174Medium· 5.9UltrafastSecp256k1 is a high-performance, multi-backend secp256k1 engine with reproducible audit evidence, compatibility shims, and profile-based review scopes
CVE-2026-102275Medium· 6.5PyJWT is a Python implementation of JSON Web Token standards
CVE-2026-54581High· 8.3mport is the MidnightBSD Package Manager
CVE-2026-86038High· 7.5libp2p is a JavaScript implementation of the libp2p networking stack