VulnSea

CWE-488

CVEs classified under CWE-488, newest first.

16 CVEsRSS

CVE-2026-88017High· 7.3
1w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.64.0 until 1.75.1, the FTP auth-proxy driver in cmd/serve/ftp/ftp.go stores one obscured password per username in the se…

Twilightrclone · rcloneEPSS 0.23%via NVD
CVE-2026-84685Medium· 6.5
2w ago

The react-native-auth0 SDK's web platform implementation does not scope its in-memory token cache to individual user sessions when operating in a server-side rendering (SSR) environment where module state persists across HTTP requests

The react-native-auth0 SDK's web platform implementation does not scope its in-memory token cache to individual user sessions when operating in a server-side rendering (SSR) environment where module state persists across HTTP requests. U…

SunlitAuth0 · react-native-auth0EPSS 0.18%via NVD
CVE-2026-86492High· 8.5
2w ago

In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens

In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens

TwilightJetBrains · YouTrackEPSS 0.56%via NVD
CVE-2026-80231High· 7.5PoC⚖ disputed
2w ago

A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup for a given hostname even when using a different Native CA Store setting (`CURLSSLOPT_NATIVE_CA`) than when the connection was created.

A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup for a given hostname even when using a different Native CA Store setting (`CURLSSLOPT_NATIVE_CA`) than when the connection was created.

Midnighthaxx · curlEPSS 0.94%via NVD
CVE-2026-19931Critical· 9.8PoC⚖ disputed
2w ago

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previo…

Abyssalhaxx · curlEPSS 1.2%via NVD
CVE-2026-18489High· 7.4
2w ago

IBM ContextForge MCP Gateway - Translate utility <= 1.0.8 MCP Context Forge could allow a remote attacker to obtain sensitive information from other sessions due to exposure of data elements to the wrong session.

IBM ContextForge MCP Gateway - Translate utility <= 1.0.8 MCP Context Forge could allow a remote attacker to obtain sensitive information from other sessions due to exposure of data elements to the wrong session.

Twilightibm · contextforgeEPSS 0.26%via NVD
CVE-2026-82367None
3w ago

Exposure of Data Element to Wrong Session vulnerability in ash-project ash_graphql can deliver one subscription's resolved records to a different subscriber's topic. AshGraphql.Subscription.Batcher.do_send/5 reads the resolved batch fro…

Exposure of Data Element to Wrong Session vulnerability in ash-project ash_graphql can deliver one subscription's resolved records to a different subscriber's topic. AshGraphql.Subscription.Batcher.do_send/5 reads the resolved batch fro…

SunlitEPSS 0.24%via NVD
CVE-2026-71850Medium· 4.8
1mo ago

Hono is a Web application framework that provides support for any JavaScript runtime

Hono is a Web application framework that provides support for any JavaScript runtime. From 3.8.0 to 4.12.33, memo() from hono/jsx retains the result of a server side render and reuses it for later renders with comparator equal props, and…

Sunlithono · honoEPSS 0.16%via NVD
CVE-2026-54497Medium· 6.8
2mo ago

ViewComponent: Reused Component Instances Retain Stale Render Context

ViewComponent: Reused Component Instances Retain Stale Render Context

Sunlitview_component · view_componentEPSS 0.25%via GHSA
CVE-2026-14621Low· 3.1
2mo ago

A vulnerability has been found in FederatedAI FATE up to 2.2.0

A vulnerability has been found in FederatedAI FATE up to 2.2.0. This affects the function QueuePushReqStreamObserver.initEggroll of the file java/osx/osx-broker/src/main/java/org/fedai/osx/broker/grpc/QueuePushReqStreamObserver.java of t…

SunlitEPSS 0.36%via NVD
CVE-2026-8458Medium· 6.5PoC
2mo ago

libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different "services". libcurl features a pool of recent connections so that subsequent requests …

libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different "services". libcurl features a pool of recent connections so that subsequent requests …

Twilighthaxx · curlEPSS 0.37%via NVD
CVE-2026-54311Medium· 6.3
3mo ago

n8n: Merge Node SQL Mode Prototype Pollution

n8n: Merge Node SQL Mode Prototype Pollution

Sunlitn8n · n8nEPSS 0.39%via GHSA
CVE-2026-5773High· 7.5PoC
4mo ago

libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connectio…

libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connectio…

Midnighthaxx · curlEPSS 0.62%via NVD
CVE-2026-5545Medium· 6.5
4mo ago

libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a Negotiate-authenticated one, when both use the same host. libcurl features a pool of recent connections so that sub…

libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a Negotiate-authenticated one, when both use the same host. libcurl features a pool of recent connections so that sub…

Sunlithaxx · curlEPSS 0.41%via NVD
CVE-2026-23919Medium· 6.0
6mo ago

For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks)

For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks). This can lead to confidentiality loss where a regular (non-super) Zabbix administrator leaks data…

Sunlitzabbix · zabbixEPSS 0.24%via NVD
CVE-2025-1247High· 8.3
1y ago

A flaw was found in Quarkus REST that allows request parameters to leak between concurrent requests if endpoints use field injection without a CDI scope

A flaw was found in Quarkus REST that allows request parameters to leak between concurrent requests if endpoints use field injection without a CDI scope. This vulnerability allows attackers to manipulate request data, impersonate users, …

TwilightEPSS 0.79%via NVD
CWE-488 vulnerabilities (CVEs) · VulnSea