CVE-2026-105295High· 7.5▾ TwilightGitAhead 2.5.0 through 2.7.1 contains an insecure update mechanism that installs downloaded updates without integrity or signature verification and permanently ignores TLS errors after one SSL error dialog. Network attackers presenting a…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
GitAhead 2.5.0 through 2.7.1 contains an insecure update mechanism that installs downloaded updates without integrity or signature verification and permanently ignores TLS errors after one SSL error dialog. Network attackers presenting an invalid certificate once can intercept later automatic update checks, offer a fake version, and execute code as the user upon installation.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-105137Medium· 5.0A vulnerability was found in Laradock up to 20.4
CVE-2026-55251Medium· 6.5NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox
CVE-2026-100265Medium· 4.8In JetBrains Rider before 2026.2.1 aI Assistant could auto-update third-party skills without user confirmation
CVE-2026-102930High· 7.7virtualenv is a tool for creating isolated virtual python environments
CVE-2026-73595Medium· 4.7Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains a Download of Code Without Integrity Check vulnerability
CVE-2026-100653Medium· 6.5vLLM is an inference and serving engine for large language models