VulnSea

CWE-770

CVEs classified under CWE-770, newest first.

499 CVEsRSS

CVE-2026-61629High· 7.5
today

nginx ignition is a user interface for the nginx web server

nginx ignition is a user interface for the nginx web server. In versions 2.29.0 through 2.40.0, the gin i18n middleware in nginx-ignition's API server runs in front of every HTTP request and calls `golang.org/x/text/language.ParseAcceptL…

Twilightlucasdillmann · nginx-ignitionvia NVD
CVE-2026-85220Low· 3.7
today

A vulnerability in the Thinkst Canary honeypot Redis service allows an unauthenticated remote attacker to execute a Denial-of-Service attack against the honeypot. The vulnerability is accessible when the Redis service is enabled only. …

A vulnerability in the Thinkst Canary honeypot Redis service allows an unauthenticated remote attacker to execute a Denial-of-Service attack against the honeypot. The vulnerability is accessible when the Redis service is enabled only. …

SunlitThinkst Applied Research · Canaryvia NVD
CVE-2026-65654High· 8.7
today

github.com/temporalio/ringpop-go enforces configured LabelOptions limits when an application changes the local node's labels, but affected versions do not apply those limits to label maps received in SWIM membership changes

github.com/temporalio/ringpop-go enforces configured LabelOptions limits when an application changes the local node's labels, but affected versions do not apply those limits to label maps received in SWIM membership changes. A network pe…

TwilightTemporal Technologies, Inc. · github.com/temporalio/ringpop-govia NVD
CVE-2026-91865High· 7.5
today

A small WS-Policy document using repeated policy references can force Neethi to re-expand the same references exponentially during normalization, consuming huge amounts of CPU and memory (denial of service). Users are recommended to upgr…

A small WS-Policy document using repeated policy references can force Neethi to re-expand the same references exponentially during normalization, consuming huge amounts of CPU and memory (denial of service). Users are recommended to upgr…

TwilightApache Software Foundation · org.apache.neethi:neethivia NVD
CVE-2026-91866High· 7.5
today

A specially crafted pair of WS-Policy documents can force Neethi's policy-intersection to do exponential amounts of work, pinning the CPU for a long time (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes…

A specially crafted pair of WS-Policy documents can force Neethi's policy-intersection to do exponential amounts of work, pinning the CPU for a long time (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes…

TwilightApache Software Foundation · org.apache.neethi:neethivia NVD
CVE-2026-91864High· 7.5
today

A specially crafted WS-Policy document can pack unlimited content inside a policy assertion, which Neethi copies into memory without counting it against its size limits, exhausting the heap (denial of service). Users are recommended to u…

A specially crafted WS-Policy document can pack unlimited content inside a policy assertion, which Neethi copies into memory without counting it against its size limits, exhausting the heap (denial of service). Users are recommended to u…

TwilightApache Software Foundation · org.apache.neethi:neethivia NVD
CVE-2026-57227High· 7.5
3d ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.0 until 7.0.17 and 8.0.6, the MQTT parser in rust/src/mqtt/mqtt.rs permits repeated PUBREC or PUBREL messages …

TwilightOISF · suricataEPSS 0.40%via NVD
CVE-2026-57224Medium· 6.5
3d ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the DHCP parser in rust/src/dhcp/dhcp.rs creates stateless transactions without recording their…

SunlitOISF · suricataEPSS 0.40%via NVD
CVE-2026-93838Medium· 5.9PoC
3d ago

SGLang versions through 0.5.20 contain an unbounded memory allocation vulnerability in handle_staging_req() that fails to validate chunk_idx from ZMQ STAGING_REQ frames in prefill/decode disaggregation deployments

SGLang versions through 0.5.20 contain an unbounded memory allocation vulnerability in handle_staging_req() that fails to validate chunk_idx from ZMQ STAGING_REQ frames in prefill/decode disaggregation deployments. Attackers with access …

Twilightsgl-project · sglangEPSS 0.46%via NVD
CVE-2026-77528Medium· 5.3
3d ago

Autobahn Python is a WebSocket and WAMP implementation for Python that supports Twisted and asyncio

Autobahn Python is a WebSocket and WAMP implementation for Python that supports Twisted and asyncio. Prior to 26.7.1, WebSocket endpoints that accept permessage-deflate and rely on maxMessagePayloadSize enforce that limit against the com…

Sunlitcrossbario · autobahn-pythonEPSS 0.40%via NVD
CVE-2026-64847Medium· 6.8
3d ago

AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio

AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Prior to 4.14.2, AnyIO starts process-pool workers with standard error connected to a pipe that the parent never drains,…

Sunlitagronholm · anyioEPSS 0.12%via NVD
CVE-2026-91149High· 7.5
3d ago

A flaw was found in Cockpit

A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this vulnerability by initiating and sustaining numerous simultaneous connections to the `cockpit-tls` service. This forces the service to create an unbounded nu…

TwilightRed Hat · cockpitEPSS 0.35%via NVD
CVE-2026-84447High· 7.5PoC
3d ago

libheif is a HEIF and AVIF file format decoder and encoder

libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.1 and earlier, crafted grid, iovl, and iden reference graphs can repeatedly decode the same base image because processed_ids is copied per branch and ImageItem::decode_i…

Midnightstrukturag · libheifEPSS 0.52%via NVD
CVE-2026-93688High· 7.5
3d ago

SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV transfer backend fails to validate bootstrap_room values, allowing unbounded transfer state allocation

SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV transfer backend fails to validate bootstrap_room values, allowing unbounded transfer state allocation. Unauthenticated attackers can reach the decode engine's …

Twilightsgl-project · sglangEPSS 0.40%via NVD
CVE-2026-10832Medium· 5.9
3d ago

A flaw was found in the DERDecoder class within wildfly-elytron-asn1

A flaw was found in the DERDecoder class within wildfly-elytron-asn1. A remote attacker can exploit this resource exhaustion vulnerability by sending a specially crafted DER (Distinguished Encoding Rules) payload. The decoder attempts to…

SunlitRed Hat · wildfly-elytron-asn1EPSS 0.28%via NVD
CVE-2026-93491High· 7.5
3d ago

A flaw was found in Netty's HttpServerCodec

A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipelining HTTP/1.1 requests on a single connection and withholding reads. This action causes the methodOverflowQueue to gr…

TwilightRed Hat · netty-codec-httpEPSS 0.44%via NVD
CVE-2026-93488High· 7.5
3d ago

A flaw was found in Netty

A flaw was found in Netty. SpdySessionHandler accepts an unlimited number of concurrent remote-initiated streams because localConcurrentStreams defaults to Integer.MAX_VALUE and the handler provides no API to change it. A remote peer can…

TwilightRed Hat · netty-codec-httpEPSS 0.46%via NVD
CVE-2026-93572High· 7.5
3d ago

A flaw was found in Netty's `RedisArrayAggregator` component

A flaw was found in Netty's `RedisArrayAggregator` component. A remote attacker can exploit this vulnerability by sending specially crafted nested Redis (RESP) array headers. This can cause the `RedisArrayAggregator` to eagerly prealloca…

TwilightRed Hat · netty-codec-redisEPSS 0.34%via NVD
CVE-2026-93310Medium· 5.3PoC
3d ago

A vulnerability was identified in O-RAN-SC SMO OAM 2025-06-10

A vulnerability was identified in O-RAN-SC SMO OAM 2025-06-10. This affects an unknown part of the component VES Collector. The manipulation leads to allocation of resources. Remote exploitation of the attack is possible. The exploit is …

TwilightO-RAN-SC · SMO OAMEPSS 0.40%via NVD
CVE-2026-93308Medium· 4.3PoC
3d ago

A vulnerability was found in O-RAN-SC SMO OAM 2025-06-10

A vulnerability was found in O-RAN-SC SMO OAM 2025-06-10. Affected by this vulnerability is an unknown functionality of the component VES Collector. Performing a manipulation results in allocation of resources. The attack may be initiate…

TwilightO-RAN-SC · SMO OAMEPSS 0.30%via NVD
CVE-2026-93309Medium· 4.3
3d ago

A vulnerability was determined in O-RAN-SC SMO OAM 2025-06-10

A vulnerability was determined in O-RAN-SC SMO OAM 2025-06-10. Affected by this issue is some unknown functionality of the component VES Collector. Executing a manipulation can lead to allocation of resources. The attack may be launched …

SunlitO-RAN-SC · SMO OAMEPSS 0.30%via NVD
CVE-2026-77281Medium· 6.5
4d ago

Caddy is an extensible server platform that uses TLS by default

Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, three configuration-dependent weaknesses affect the handler and placeholder layer. In modules/caddyhttp/rewrite/rewrite.go, Rewrite.Rewrite()…

Sunlitcaddyserver · caddyEPSS 0.36%via NVD
CVE-2026-50275High· 7.5
4d ago

The Datadog PHP Tracer provides application performance monitoring and distributed tracing for PHP

The Datadog PHP Tracer provides application performance monitoring and distributed tracing for PHP. Prior to 1.19.2, ddtrace_deserialize_baggage in ext/distributed_tracing_headers.c parses incoming W3C baggage HTTP headers without enforc…

TwilightDataDog · dd-trace-phpEPSS 0.48%via NVD
CVE-2026-50277High· 7.5
4d ago

dd-trace-cpp is the Datadog distributed tracing library for C++

dd-trace-cpp is the Datadog distributed tracing library for C++. Prior to 2.1.0, dd-trace-cpp parses incoming W3C baggage headers without enforcing DD_TRACE_BAGGAGE_MAX_ITEMS or DD_TRACE_BAGGAGE_MAX_BYTES on the extraction path, even tho…

TwilightDataDog · dd-trace-cppEPSS 0.56%via NVD
CVE-2026-54716High· 7.5
4d ago

Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data

Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. In 3.7.0 and earlier, a POST request to /sources_to_targets containing an exclude_polygons ring formed by three collinear points can ca…

Twilightvalhalla · valhallaEPSS 0.32%via NVD
CVE-2026-86040High· 7.5
4d ago

libp2p is a JavaScript implementation of the libp2p networking stack

libp2p is a JavaScript implementation of the libp2p networking stack. Prior to 11.0.26, @libp2p/floodsub accepts unauthenticated RPC frames on /floodsub/1.0.0 through PeerStreams.attachInboundStream in packages/floodsub/src/peer-streams.…

Twilightlibp2p · js-libp2pEPSS 0.37%via NVD
CVE-2026-87742High· 7.5
4d ago

A flaw was found in quarkus-websockets-next

A flaw was found in quarkus-websockets-next. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by streaming messages over a single connection faster than the application can process them. Due to unbounded mes…

TwilightRed Hat · exploit-intelligence/agent-client-rhel9EPSS 0.33%via NVD
CVE-2026-92961High· 7.5
4d ago

vm2 before 3.11.6 fails to enforce bufferAllocLimit on ArrayBuffer, SharedArrayBuffer, and TypedArray constructors, allowing attackers to allocate arbitrary host memory

vm2 before 3.11.6 fails to enforce bufferAllocLimit on ArrayBuffer, SharedArrayBuffer, and TypedArray constructors, allowing attackers to allocate arbitrary host memory. Attackers can bypass the buffer allocation cap by using these V8 in…

Twilightpatriksimek · vm2EPSS 0.38%via NVD
CVE-2026-92915High· 7.3PoC
4d ago

WWBN AVideo through commit e01e41ecc (no patched version available) contains a broken access control flaw in objects/userVerifyEmail.php

WWBN AVideo through commit e01e41ecc (no patched version available) contains a broken access control flaw in objects/userVerifyEmail.php. The script disables the login requirement ($global['ignoreUserMustBeLoggedIn'] = 1), takes users_id…

MidnightWWBN · AVideoEPSS 0.31%via NVD
CVE-2026-25281High· 7.4
4d ago

Transient DOS when processing large or numerous request buffers without sufficient memory allocation validation.

Transient DOS when processing large or numerous request buffers without sufficient memory allocation validation.

TwilightQualcomm, Inc. · SnapdragonEPSS 0.16%via NVD
CWE-770 vulnerabilities (CVEs) · VulnSea