VulnSea

CWE-248

CVEs classified under CWE-248, newest first.

80 CVEsRSS

CVE-2026-32641High· 7.5
3d ago

Parseable is a log analytics platform built for high-volume data ingestion and analysis

Parseable is a log analytics platform built for high-volume data ingestion and analysis. Prior to 3.0.0, src/handlers/http/middleware.rs uses unwrap() while parsing the x-amz-firehose-common-attributes header before authentication. A rem…

Twilightparseablehq · parseableEPSS 0.64%via NVD
CVE-2026-92954High· 8.6PoC
4d ago

vm2 is a sandbox library for running untrusted JavaScript in Node.js

vm2 is a sandbox library for running untrusted JavaScript in Node.js. In versions >= 3.10.0 and <= 3.11.7, Promises returned from the host realm into the sandbox are not marked as handled at the bridge boundary; only Promises created ins…

Midnightpatriksimek · vm2EPSS 0.34%via NVD
CVE-2026-82410High· 8.7
5d ago

Pocketbase is an open source web backend written in go

Pocketbase is an open source web backend written in go. Prior to 0.22.48 and 0.39.7, PocketBase's panic-recovery middleware covers regular request handling but not internal child and worker goroutines. A panic in one of these internal go…

Twilightpocketbase · pocketbaseEPSS 0.58%via NVD
CVE-2026-92081Medium· 5.9
5d ago

fastify is a fast and low-overhead web framework for Node.js

fastify is a fast and low-overhead web framework for Node.js. In versions before 5.12.5, when a route registers a response trailer via reply.trailer() and is served over HTTP/2, fastify unconditionally sets the Transfer-Encoding: chunked…

Sunlitfastify · fastifyEPSS 0.40%via NVD
CVE-2026-61544High· 8.2PoC
6d ago

libp2p-rust is the official Rust language implementation of the libp2p networking stack

libp2p-rust is the official Rust language implementation of the libp2p networking stack. Prior to 0.13.1, libp2p-quic could panic during an inbound QUIC handshake when a remote peer presented a valid short-lived libp2p TLS certificate an…

Midnightlibp2p · rust-libp2pEPSS 0.23%via NVD
CVE-2026-65410High· 7.5
1w ago

The issue was addressed with improved checks

The issue was addressed with improved checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system …

Twilightapple · ipadosEPSS 0.39%via NVD
CVE-2026-54529Medium· 5.3
1w ago

SQLAdmin is a flexible Admin interface for SQLAlchemy models

SQLAdmin is a flexible Admin interface for SQLAlchemy models. Prior to 0.27.1, ModelView.sort_query in sqladmin/models.py accepts the attacker-controlled sortBy list-view query parameter without enforcing the configured column_sortable_l…

Sunlitsmithyhq · sqladminEPSS 0.38%via NVD
CVE-2026-84445High· 8.7
1w ago

gRPC-Go is the Go language implementation of gRPC

gRPC-Go is the Go language implementation of gRPC. Prior to 1.82.2 and 1.83.2, servers created with xds.NewGRPCServer() allow internal/transport/http2_server.go to accept an RPC containing neither the :authority header nor the Host heade…

Twilightgrpc · grpc-goEPSS 0.69%via NVD
CVE-2026-55244Medium· 5.0PoC
1w ago

ASTEVAL is an evaluator of Python expressions and statements

ASTEVAL is an evaluator of Python expressions and statements. Prior to 1.0.9, FROM_PY in asteval/astutils.py exposes BaseException, SystemExit, KeyboardInterrupt, and GeneratorExit to expressions evaluated by asteval.Interpreter.eval(), …

Twilightlmfit · astevalEPSS 0.19%via NVD
CVE-2026-53496Medium· 5.3PoC
1w ago

ExifReader is a JavaScript Exif information parser

ExifReader is a JavaScript Exif information parser. Prior to 4.40.1, ExifReader.load() and the asynchronous file and URL loaders can pass attacker-supplied HEIC or AVIF data to the ISO-BMFF parser in src/image-header-iso-bmff.js, where f…

Twilightmattiasw · ExifReaderEPSS 0.45%via NVD
CVE-2026-54541Low· 3.7
1w ago

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to 1.6.0, a malicious state-sync peer can crash a syncing node by sending a crafted TrieChunk proof containing two Trie…

Sunlitnimiq-primitives · nimiq-primitivesEPSS 0.27%via NVD
CVE-2026-89090Medium· 5.9
1w ago

An unrecovered panic in the event stream header decoder in Amazon AWS SDK for Go v2 before release-2026-03-23 might allow an unauthenticated remote actor to terminate the consuming application process via a crafted event stream response …

An unrecovered panic in the event stream header decoder in Amazon AWS SDK for Go v2 before release-2026-03-23 might allow an unauthenticated remote actor to terminate the consuming application process via a crafted event stream response …

SunlitAWS · AWS SDK for Go v2EPSS 0.31%via NVD
CVE-2026-87123Medium· 5.9
1w ago

hbs is an Express view engine wrapper for Handlebars

hbs is an Express view engine wrapper for Handlebars. Version 4.3.0 can crash the Node.js process during output escaping when an async helper, registered with registerAsyncHelper, resolves to an object whose toHTML property is truthy but…

Sunlithbs · hbsEPSS 0.26%via NVD
CVE-2026-88015Medium· 5.3PoC
1w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, backend/local with --links or links=true exposes symlink targets as .rclonelink objects, and fs.RangeOption.De…

Twilightrclone · rcloneEPSS 0.35%via NVD
CVE-2026-77078High· 7.5
1w ago

multer vulnerable to Denial of Service via crafted multipart field names

multer vulnerable to Denial of Service via crafted multipart field names

Twilightmulter · multerEPSS 0.29%via GHSA
CVE-2026-69839Medium· 6.5
1w ago

Uncaught exception in Windows iSCSI Target Service allows an authorized attacker to deny service over a network.

Uncaught exception in Windows iSCSI Target Service allows an authorized attacker to deny service over a network.

Sunlitmicrosoft · windows_10_1607EPSS 1.1%via NVD
CVE-2026-82058Medium· 6.5
1w ago

A flaw in MongoDB's JSON Schema validation error generation code allows an authenticated user with readWrite privileges to crash the mongod server

A flaw in MongoDB's JSON Schema validation error generation code allows an authenticated user with readWrite privileges to crash the mongod server. When a BSON document containing an array with a malformed numeric field name fails a $jso…

Sunlitmongodb · mongodbEPSS 0.28%via NVD
CVE-2022-51014Medium· 6.5
2w ago

PocketMine-MP before 4.0.7 contains an unhandled exception vulnerability in the ModalFormResponsePacket handler when processing malformed JSON from clients

PocketMine-MP before 4.0.7 contains an unhandled exception vulnerability in the ModalFormResponsePacket handler when processing malformed JSON from clients. Attackers can send specially crafted form response packets with invalid JSON to …

Sunlitpmmp · PocketMine-MPEPSS 0.51%via NVD
CVE-2022-51009High· 7.5
2w ago

PocketMine-MP before 4.7.2 fails to properly handle exceptions from the adhocore/json-comment library when parsing skin geometry data

PocketMine-MP before 4.7.2 fails to properly handle exceptions from the adhocore/json-comment library when parsing skin geometry data. Attackers can send login or skin packets with invalid geometry JSON to trigger an unhandled RuntimeExc…

Twilightpmmp · PocketMine-MPEPSS 0.34%via NVD
CVE-2026-85024Medium· 5.9
2w ago

undici bundles a WebSocket client whose permessage-deflate size-limit cleanup removes all listeners from the internal zlib inflate stream, including its error listener, while that stream can still emit

undici bundles a WebSocket client whose permessage-deflate size-limit cleanup removes all listeners from the internal zlib inflate stream, including its error listener, while that stream can still emit. When a remote peer sends a compres…

Sunlitnodejs · undiciEPSS 0.26%via NVD
CVE-2026-85014Medium· 5.9
2w ago

undici's experimental WebSocketStream client crashes the whole Node.js process when a remote peer closes the TCP connection without a WebSocket close handshake

undici's experimental WebSocketStream client crashes the whole Node.js process when a remote peer closes the TCP connection without a WebSocket close handshake. On an unclean close the internal socket-close handler calls abort on the wri…

Sunlitnodejs · undiciEPSS 0.37%via NVD
CVE-2026-84947Low· 3.7⚖ disputed
2w ago

undici's dump interceptor reads and discards a response body up to a configurable maximum size

undici's dump interceptor reads and discards a response body up to a configurable maximum size. When a response declares a Content-Length that exceeds the maximum, the interceptor aborts cleanly, but when a response has no Content-Length…

Sunlitnodejs · undiciEPSS 0.20%via NVD
CVE-2026-19534High· 7.5
2w ago

undici's WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that the client never requested

undici's WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that the client never requested. A default WebSocket connection sends no subprotocol, but if the server's …

Twilightnodejs · undiciEPSS 0.39%via NVD
CVE-2026-82417Medium· 5.3⚖ disputed
3w ago

### Summary `qs.stringify` throws a `TypeError` when it serializes an object whose own `constructor` property has a truthy, non-callable `isBuffer` member

### Summary `qs.stringify` throws a `TypeError` when it serializes an object whose own `constructor` property has a truthy, non-callable `isBuffer` member. `utils.isBuffer` duck-types buffers by calling `obj.constructor.isBuffer(obj)`…

SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.26%via NVD
CVE-2026-55484High· 7.5
3w ago

ALOS HTTP is a Linux-first Go web framework and application server built around a custom networking stack

ALOS HTTP is a Linux-first Go web framework and application server built around a custom networking stack. Prior to 0.0.0-20260617230736-314b6783e196, core/utils.go::sanitizeRequestPath calls splitPathQuery on a request path beginning wi…

Twilightguno1928 · github.com/guno1928/alos-httpEPSS 0.34%via NVD
CVE-2026-54553Medium· 5.4
3w ago

Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS

Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS

Sunlitstarlette-admin · starlette-adminEPSS 0.34%via OSV
CVE-2026-63403None
3w ago

Faktory is a language-agnostic background job server

Faktory is a language-agnostic background job server. In versions prior to 1.10.0, the server is vulnerable to an unauthenticated denial of service in which a single malformed command crashes the entire process. Its wire protocol is line…

SunlitEPSS 0.43%via NVD
CVE-2026-79778Medium· 5.3
3w ago

rclone before v1.75.0 contains a denial of service vulnerability in the WebDAV TUS creation handler that dereferences a nil response before checking for transport errors

rclone before v1.75.0 contains a denial of service vulnerability in the WebDAV TUS creation handler that dereferences a nil response before checking for transport errors. A malicious or compromised configured endpoint can reset connectio…

Sunlitrclone · github.com/rclone/rcloneEPSS 0.23%via NVD
GHSA-rgqc-3x5p-6gwgMedium
4w ago

postgres-protocol: Panic decoding a malformed `hstore` value allows denial of service

postgres-protocol: Panic decoding a malformed `hstore` value allows denial of service

Sunlitpostgres-protocol · postgres-protocolvia GHSA
CVE-2026-53530High
1mo ago

RaTeX is a KaTeX-compatible math rendering engine written in Rust

RaTeX is a KaTeX-compatible math rendering engine written in Rust. Prior to version 0.1.11, the public parser entrypoint `ratex_parser::parse(&str)` panics on the 9-byte input `\verbéxé` (i.e. `\verb` followed by the non-ASCII delimiter …

Twilightratex-parser · ratex-parserEPSS 0.31%via NVD
CWE-248 vulnerabilities (CVEs) · VulnSea