VulnSea

CWE-345

CVEs classified under CWE-345, newest first.

165 CVEsRSS

GHSA-77q5-rr5v-x43qHigh
2mo ago

OpenClaw: Trusted retry endpoint checks could match hostname prefixes

OpenClaw: Trusted retry endpoint checks could match hostname prefixes

▾ Twilightopenclaw · openclawvia GHSA
CVE-2026-44937High· 7.5
2mo ago

Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components

Rancher Fleet has Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components

▾ Twilightrancher · github.com/rancher/fleetEPSS 0.42%via GHSA
CVE-2026-48816Medium· 6.5
2mo ago

sigstore-js has Insufficient Verification of Data Authenticity

sigstore-js has Insufficient Verification of Data Authenticity

▾ Sunlitsigstore · @sigstore/verifyEPSS 0.16%via GHSA
CVE-2026-48815Medium· 5.9
2mo ago

sigstore: Sigstore: Unauthorized certificates accepted due to ignored `certificateOIDs` verification option (CVE-2026-48815)

A flaw was found in sigstore. The `certificateOIDs` option, intended to restrict which certificates can sign artifacts, is accepted by the public application programming interface (API) but is not used during the verification process. This…

▾ SunlitRed Hat · Red Hat Enterprise Linux 8EPSS 0.19%via CSAF
CVE-2026-13513Medium· 5.0
3mo ago

A security flaw has been discovered in MyScale MyScaleDB up to 1.8.0

A security flaw has been discovered in MyScale MyScaleDB up to 1.8.0. This vulnerability affects the function SegmentId::getCacheKey in the library src/VectorIndex/Common/SegmentId.h. The manipulation results in insufficient verification…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-13507Medium· 5.0
3mo ago

A vulnerability was detected in volcengine OpenViking up to 0.3.21

A vulnerability was detected in volcengine OpenViking up to 0.3.21. This affects the function str_to_uint64 of the file openviking/storage/vectordb/utils/str_to_uint64.py of the component Local VectorDB Primary-key Label Handler. The man…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-50573Medium· 6.8
3mo ago

pnpm: Unsafe default behavior breaks integrity check

pnpm: Unsafe default behavior breaks integrity check

▾ Sunlitpnpm · pnpmEPSS 0.17%via GHSA
CVE-2026-55698High· 8.8
3mo ago

pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes

pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes

▾ Twilightpnpm · pnpmEPSS 0.30%via GHSA
GHSA-3fxj-6jh8-hvhxMedium
3mo ago

chi Has an IP Spoofing Vulnerability in `middleware.RealIP`

chi Has an IP Spoofing Vulnerability in `middleware.RealIP`

▾ Sunlitgo-chi · github.com/go-chi/chi/v5/middlewarevia GHSA
CVE-2026-52812High
3mo ago

Gogs: LFS dedupe path leaks private repo content across tenants

Gogs: LFS dedupe path leaks private repo content across tenants

▾ Twilightgogs · gogs.io/gogsEPSS 0.24%via GHSA
CVE-2026-47155Medium· 6.5
3mo ago

vllm: vLLM: Supply-chain integrity issue due to inconsistent revision pinning controls (CVE-2026-47155)

A flaw was found in vLLM, an inference and serving engine for large language models (LLMs). The revision pinning controls in vLLM do not consistently apply to all artifacts loaded for a model. This allows a deployment configured with speci…

▾ SunlitRed Hat · Red Hat Enterprise Linux AI 3.3EPSS 0.25%via CSAF
CVE-2026-33731Medium· 6.5
3mo ago

AVideo has an Authorize.Net Webhook Signature Bypass that Enables Wallet Balance Inflation via Forged Payment Data

AVideo has an Authorize.Net Webhook Signature Bypass that Enables Wallet Balance Inflation via Forged Payment Data

▾ Sunlitwwbn · wwbn/avideoEPSS 0.21%via GHSA
CVE-2026-55883High
3mo ago

Tilt: Cross-site WebSocket hijacking of the Tilt HUD stream

Tilt: Cross-site WebSocket hijacking of the Tilt HUD stream

▾ Twilighttilt-dev · github.com/tilt-dev/tiltEPSS 0.26%via GHSA
CVE-2026-49212Low
3mo ago

symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding

symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding

▾ Sunlitsymfony · symfony/ux-live-componentEPSS 0.24%via GHSA
CVE-2026-50195Medium
3mo ago

containerd: CRI checkpoint import allows local image tag poisoning

containerd: CRI checkpoint import allows local image tag poisoning

▾ Sunlitcontainerd · github.com/containerd/containerd/v2EPSS 0.30%via GHSA
CVE-2026-54774High· 7.4
3mo ago

CoreWCF: SamlSerializer skips SignatureValue verification when SAML signing token is not an X.509 certificate

CoreWCF: SamlSerializer skips SignatureValue verification when SAML signing token is not an X.509 certificate

▾ TwilightCoreWCF · CoreWCF.PrimitivesEPSS 0.20%via GHSA
CVE-2026-54781High· 7.4
3mo ago

CoreWCF: SAML SubjectConfirmation methods and holder-of-key proof keys are not enforced

CoreWCF: SAML SubjectConfirmation methods and holder-of-key proof keys are not enforced

▾ TwilightCoreWCF · CoreWCF.PrimitivesEPSS 0.25%via GHSA
CVE-2026-54783High· 7.4
3mo ago

CoreWCF: XML Signature Wrapping in WS-Security endorsing/supporting signature verification allows replay of captured signed messages

CoreWCF: XML Signature Wrapping in WS-Security endorsing/supporting signature verification allows replay of captured signed messages

▾ TwilightCoreWCF · CoreWCF.PrimitivesEPSS 0.19%via GHSA
GHSA-wfqx-gjrf-g28rCritical· 9.0
3mo ago

Crossplane: Signature verification TOCTOU allows installing unverified package content via mutable tag

Crossplane: Signature verification TOCTOU allows installing unverified package content via mutable tag

▾ Midnightcrossplane · github.com/crossplane/crossplane/v2via GHSA
GHSA-m4w9-hjfw-vwj4High
3mo ago

http4k: `HmacSha256.hash` (despite the `Hmac` naming) computed a plain unkeyed digest; clarified by deprecation in favour of `Sha256.hash` / `Sha256.hmac`

http4k: `HmacSha256.hash` (despite the `Hmac` naming) computed a plain unkeyed digest; clarified by deprecation in favour of `Sha256.hash` / `Sha256.hmac`

▾ Twilighthttp4k · org.http4k:http4k-corevia GHSA
GHSA-8579-rgg5-ph2mHigh· 8.8
3mo ago

PraisonAI DiscordApproval accepts unrelated channel messages as dangerous-tool approvals

PraisonAI DiscordApproval accepts unrelated channel messages as dangerous-tool approvals

▾ Twilightpraisonai · praisonaivia GHSA
GHSA-x92v-rpx6-p6cwHigh· 8.6
3mo ago

PraisonAI: Webhook signature verification skipped (fail-open) when secret unset, allowing forged inbound webhooks (WhatsApp & Linear bots)

PraisonAI: Webhook signature verification skipped (fail-open) when secret unset, allowing forged inbound webhooks (WhatsApp & Linear bots)

▾ Twilightpraisonai · praisonaivia GHSA
GHSA-jc38-x7x8-2xc8High
3mo ago

PHP JWT Framework: JWSVerifier uses algorithm from unprotected header, enabling algorithm confusion attacks

PHP JWT Framework: JWSVerifier uses algorithm from unprotected header, enabling algorithm confusion attacks

▾ Twilightweb-token · web-token/jwt-frameworkvia GHSA
CVE-2026-54288Medium· 6.5
3mo ago

hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`

hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`

▾ Sunlithono · honoEPSS 0.15%via GHSA
CVE-2026-54266High
3mo ago

@angular/common: Weak 32-Bit Cache Key Hashing in `HttpTransferCache` Leading to Cross-Request Data Leakage and State Poisoning

@angular/common: Weak 32-Bit Cache Key Hashing in `HttpTransferCache` Leading to Cross-Request Data Leakage and State Poisoning

▾ Twilightangular · @angular/commonEPSS 0.13%via GHSA
CVE-2026-47691High· 8.7
3mo ago

Netty is a network application framework for development of protocol servers and clients

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's `DnsResolveContext` insufficiently validates the bailiwick of NS records, enabling DNS Ca…

▾ Twilightnetty · nettyEPSS 0.36%via NVD
CVE-2026-45674High· 8.7PoC
3mo ago

Netty is a network application framework for development of protocol servers and clients

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DnsResolveContext fails to validate the origin (bailiwick) of CNAME records in DNS respon…

▾ Midnightnetty · nettyEPSS 0.36%via NVD
CVE-2026-53406High· 7.8
3mo ago

Insufficient Verification of Data Authenticity in Remote Control for Zoom Contact Center for Windows before version 7.0.0 may allow an authenticated user to enable an escalation of privilege via local access.

Insufficient Verification of Data Authenticity in Remote Control for Zoom Contact Center for Windows before version 7.0.0 may allow an authenticated user to enable an escalation of privilege via local access.

▾ TwilightEPSS 0.11%via NVD
CVE-2026-48096Medium· 5.0
3mo ago

OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poiso…

OpenFGA has cache-key delimiter injection in shared-iterator and v2 iterator that caches enables intra-store authorization-decision poisoning

▾ Sunlitopenfga · github.com/openfga/openfgaEPSS 0.13%via OSV
CVE-2026-47737High· 7.5
3mo ago

Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections

Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections

▾ Twilightpuma · pumaEPSS 0.27%via GHSA
CWE-345 vulnerabilities (CVEs) — page 5 · VulnSea