CWE-522
CVEs classified under CWE-522, newest first.
134 CVEsRSS
CVE-2026-71494MediumInfracost provides cloud cost intelligence for engineers, AI coding agents, and CI/CD
Infracost provides cloud cost intelligence for engineers, AI coding agents, and CI/CD. Prior to 0.10.45, internal/hcl/remote_variables_loader.go and related Terraform Cloud, remote-plan, and Terragrunt registry request paths can attach a…
CVE-2026-55765High· 8.5CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments
CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG embedded cleartext role passwords in `ALTER ROLE` and `CREATE ROLE` statements generated by Set…
CVE-2026-53586Medium· 6.5libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application
libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, the built-in HTTP transport in src/libgi…
CVE-2026-50192MediumKerberos Agent is an open source video (surveillance) management agent
Kerberos Agent is an open source video (surveillance) management agent. Prior to version 3.6.26, the Kerberos Hub upload path sends the agent's Hub credentials in the custom `X-Kerberos-Hub-PrivateKey` and `X-Kerberos-Hub-PublicKey` requ…
CVE-2026-53456NoneBlueprint Studio is a VS Code-like file editor for Home Assistant configuration files
Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio terminal SSH key authentication in custom_components/blueprint_studio/backend/terminal_manager.py wrote SSH private-k…
CVE-2026-23922Medium· 4.9The email media OAuth field 'Client secret' cannot be read after saving, but a Super Admin can leak it by setting a malicious 'Token endpoint'
The email media OAuth field 'Client secret' cannot be read after saving, but a Super Admin can leak it by setting a malicious 'Token endpoint'. Changes were made to reset the client secret upon changing the token endpoint.
CVE-2026-53454NoneBlueprint Studio is a VS Code-like file editor for Home Assistant configuration files
Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio configured Git's credential.helper store when saving Git credentials, causing Git credential-store to persist usernam…
CVE-2026-62684Low· 2.7File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, the Link storage struct is serialized directly by sharePostHandler, shareListHandl…
CVE-2026-57485High· 8.5Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files
Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. Prior to 2.9.0, the /api/v1/pipeline/handleData endpoint in app/core/src/main/java/stirling/software/SPDF/controller/api/pipeline/Pipeline…
CVE-2026-0289Medium· 6.5⚖ disputedA security bypass vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a user to bypass intended security controls.
A security bypass vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a user to bypass intended security controls.
CVE-2026-0290Medium· 5.5⚖ disputedAn information disclosure vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a local attacker to view sensitive data.
An information disclosure vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a local attacker to view sensitive data.
CVE-2026-72801High· 7.5SiYuan versions before v3.7.4 disclose encrypted-notebook key-derivation material and wrapped data keys through unauthenticated endpoints in publish mode
SiYuan versions before v3.7.4 disclose encrypted-notebook key-derivation material and wrapped data keys through unauthenticated endpoints in publish mode. Attackers can retrieve Argon2id salt, cost parameters, password verifiers, and wra…
CVE-2026-72793High· 8.6SiYuan versions before v3.7.4 fail to mask sensitive configuration fields in the /api/system/getConf endpoint, allowing anonymous or publish-reader users to obtain the session-cookie signing key, OS username via pandoc path, and encrypte…
SiYuan versions before v3.7.4 fail to mask sensitive configuration fields in the /api/system/getConf endpoint, allowing anonymous or publish-reader users to obtain the session-cookie signing key, OS username via pandoc path, and encrypte…
CVE-2026-49349Medium· 6.8regclient is a Docker and OCI Registry Client in Go
regclient is a Docker and OCI Registry Client in Go. Prior to version 0.11.5, credentials for a registry may be inadvertently leaked to external servers. A prerequisite for this attack is a malicious registry server, a malicious blob sto…
CVE-2026-62882Medium· 4.3Microsoft Outlook Spoofing Vulnerability
Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-62839Medium· 6.5Microsoft SharePoint Server Spoofing Vulnerability
Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-71577Medium· 6.3A flaw was found in multicluster-global-hub
A flaw was found in multicluster-global-hub. During a ManagedClusterMigration, the system incorrectly grants all managed hubs read access to a shared communication topic. This allows a compromised managed hub to intercept and collect sen…
CVE-2026-47662NonePathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics
Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling Server, Pathling's typed CRUD/search/batch FHIR surface allows an authenticated caller w…
CVE-2026-47660NonePathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics
Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling Server, Pathling's bulk-submit operation allows an allowed submitter to supply an explic…
CVE-2026-48039Critical· 9.1Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads
Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109, `AuthInjectionMiddleware.dispatch()` at `http_auth_integration.py:272` unconditionally forwards unauthenticated Streama…
GHSA-8mxv-9xhp-86h4Medium· 5.3rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys
rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys
GHSA-h4mf-4v27-hggjMedium· 5.3rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect
rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect
GHSA-gx4c-2hqx-cw2rLow· 3.1rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect
rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect
CVE-2026-17349Critical· 9.6/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones that server via Server.clone(), which copies every column from the source row, including u…
/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones that server via Server.clone(), which copies every column from the source row, including u…
CVE-2026-52855Critical· 9.9Wings is the server control plane for Pterodactyl, a free, open-source game server management panel
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg configuration-file templates allow a low-privileged user to read {{config.token}}, {{co…
CVE-2026-67427High· 8.6Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted
Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted
CVE-2026-67425High· 8.6Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url
Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url
CVE-2026-67426Critical· 9.3Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration
Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration
CVE-2026-54660High· 7.4swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`
swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`
CVE-2026-54422Medium· 5.5In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.
In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.