Daily digest
Friday 9 January 2026
A quiet day: only 11 new CVEs against a recent average of about 49. Severity skewed high: 1 critical and 8 high, 82% of the total. fickling was the most-affected vendor with 5.
New this day, ranked by depth score
The 11 that matter most of the 11 published.
CVE-2025-70974Critical· 10.0Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key is the name of a Java class, there may be calls to certain public methods of that class
Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key is the name of a Java class, there may be calls to certain public methods of that class. Depending on the behavior of …
CVE-2025-9222High· 8.7GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.2 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to achieve stored cross-site scripting by exploitin…
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.2 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to achieve stored cross-site scripting by exploitin…
CVE-2025-13761High· 8.0GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an unauthenticated user to execute arbitrary code in the context of an authenticated user's br…
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an unauthenticated user to execute arbitrary code in the context of an authenticated user's br…
CVE-2026-22612HighFickling vulnerable to detection bypass due to "builtins" blindness
Fickling vulnerable to detection bypass due to "builtins" blindness
CVE-2026-22609HighFickling has Static Analysis Bypass via Incomplete Dangerous Module Blocklist
Fickling has Static Analysis Bypass via Incomplete Dangerous Module Blocklist
CVE-2026-22608HighFickling vulnerable to use of ctypes and pydoc gadget chain to bypass detection
Fickling vulnerable to use of ctypes and pydoc gadget chain to bypass detection
CVE-2026-22607HighFickling Blocklist Bypass: cProfile.run()
Fickling Blocklist Bypass: cProfile.run()
CVE-2026-22606HighFickling has a bypass via runpy.run_path() and runpy.run_module()
Fickling has a bypass via runpy.run_path() and runpy.run_module()
CVE-2025-13772High· 7.1GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to access and utilize AI model settings from unauthorize…
GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to access and utilize AI model settings from unauthorize…
CVE-2026-22691Lowpypdf has possible long runtimes for malformed startxref
pypdf has possible long runtimes for malformed startxref
CVE-2026-22690Lowpypdf has possible long runtimes for missing /Root object with large /Size values
pypdf has possible long runtimes for missing /Root object with large /Size values
Most-affected vendors
By CVEs published in the period.