VulnSea

Daily digest

Friday 9 January 2026

A quiet day: only 11 new CVEs against a recent average of about 49. Severity skewed high: 1 critical and 8 high, 82% of the total. fickling was the most-affected vendor with 5.

11
New CVEs
1
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 11 that matter most of the 11 published.

CVE-2025-70974Critical· 10.0
8mo ago

Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key is the name of a Java class, there may be calls to certain public methods of that class

Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key is the name of a Java class, there may be calls to certain public methods of that class. Depending on the behavior of …

▾ MidnightEPSS 0.77%via NVD
CVE-2025-9222High· 8.7
8mo ago

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.2 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to achieve stored cross-site scripting by exploitin…

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.2 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to achieve stored cross-site scripting by exploitin…

▾ Twilightgitlab · gitlabEPSS 0.43%via NVD
CVE-2025-13761High· 8.0
8mo ago

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an unauthenticated user to execute arbitrary code in the context of an authenticated user's br…

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an unauthenticated user to execute arbitrary code in the context of an authenticated user's br…

▾ Twilightgitlab · gitlabEPSS 0.71%via NVD
CVE-2026-22612High
8mo ago

Fickling vulnerable to detection bypass due to "builtins" blindness

Fickling vulnerable to detection bypass due to "builtins" blindness

▾ Twilightfickling · ficklingEPSS 0.31%via OSV
CVE-2026-22609High
8mo ago

Fickling has Static Analysis Bypass via Incomplete Dangerous Module Blocklist

Fickling has Static Analysis Bypass via Incomplete Dangerous Module Blocklist

▾ Twilightfickling · ficklingEPSS 0.64%via OSV
CVE-2026-22608High
8mo ago

Fickling vulnerable to use of ctypes and pydoc gadget chain to bypass detection

Fickling vulnerable to use of ctypes and pydoc gadget chain to bypass detection

▾ Twilightfickling · ficklingEPSS 0.40%via OSV
CVE-2026-22607High
8mo ago

Fickling Blocklist Bypass: cProfile.run()

Fickling Blocklist Bypass: cProfile.run()

▾ Twilightfickling · ficklingEPSS 0.53%via OSV
CVE-2026-22606High
8mo ago

Fickling has a bypass via runpy.run_path() and runpy.run_module()

Fickling has a bypass via runpy.run_path() and runpy.run_module()

▾ Twilightfickling · ficklingEPSS 0.49%via OSV
CVE-2025-13772High· 7.1
8mo ago

GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to access and utilize AI model settings from unauthorize…

GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to access and utilize AI model settings from unauthorize…

▾ Twilightgitlab · gitlabEPSS 0.43%via NVD
CVE-2026-22691Low
8mo ago

pypdf has possible long runtimes for malformed startxref

pypdf has possible long runtimes for malformed startxref

▾ Sunlitpypdf · pypdfEPSS 0.44%via OSV
CVE-2026-22690Low
8mo ago

pypdf has possible long runtimes for missing /Root object with large /Size values

pypdf has possible long runtimes for missing /Root object with large /Size values

▾ Sunlitpypdf · pypdfEPSS 0.44%via OSV

Most-affected vendors

By CVEs published in the period.