Daily digest
Tuesday 23 December 2025
A quiet day: only 5 new CVEs against a recent average of about 25. Severity skewed high: 2 critical and 1 high, 60% of the total. One arrived with exploitation evidence or public exploit code already attached.
New this day, ranked by depth score
The 5 that matter most of the 5 published.
CVE-2025-68664Critical· 9.3PoClangchain-core: LangChain: Arbitrary code execution via serialization injection (CVE-2025-68664)
A flaw was found in LangChain, a framework for building agents and LLM-powered applications. A remote attacker can exploit a serialization injection vulnerability in LangChain's `dumps()` and `dumpd()` functions. This occurs because the fu…
CVE-2025-67108Critical· 10.0eProsima Fast-DDS v3.3 was discovered to contain improper validation for ticket revocation, resulting in insecure communications and connections.
eProsima Fast-DDS v3.3 was discovered to contain improper validation for ticket revocation, resulting in insecure communications and connections.
CVE-2025-65865High· 7.5An integer overflow in eProsima Fast-DDS v3.3 allows attackers to cause a Denial of Service (DoS) via a crafted input.
An integer overflow in eProsima Fast-DDS v3.3 allows attackers to cause a Denial of Service (DoS) via a crafted input.
CVE-2025-67743Medium· 6.3Local Deep Research is Vulnerable to Server-Side Request Forgery (SSRF) in Download Service
Local Deep Research is Vulnerable to Server-Side Request Forgery (SSRF) in Download Service
CVE-2025-65713MediumHome Assistant Core before is vulnerable to Directory Traversal
Home Assistant Core before is vulnerable to Directory Traversal
Most-affected vendors
By CVEs published in the period.