Daily digest
Saturday 10 January 2026
A quiet day: only 8 new CVEs against a recent average of about 48. Severity skewed high: 1 critical and 3 high, 50% of the total. 2 arrived with exploitation evidence or public exploit code already attached. shopify was the most-affected vendor with 4.
New this day, ranked by depth score
The 8 that matter most of the 8 published.
CVE-2025-61686Critical· 9.1PoCReact Router is a router for React
React Router is a router for React. In @react-router/node versions 7.0.0 through 7.9.3, @remix-run/deno prior to version 2.17.2, and @remix-run/node prior to version 2.17.2, if createFileSessionStorage() is being used from @react-router/…
CVE-2025-59057High· 7.6PoCReact Router is a router for React
React Router is a router for React. In @remix-run/react versions 1.15.0 through 2.17.0. and react-router versions 7.0.0 through 7.8.2, a XSS vulnerability exists in in React Router's meta()/<Meta> APIs in Framework Mode when generating s…
CVE-2026-21884High· 8.2React Router is a router for React
React Router is a router for React. In @remix-run/react version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, a XSS vulnerability exists in in React Router's <ScrollRestoration> API in Framework Mode when using the getKey/stora…
CVE-2026-22029High· 8.0React Router is a router for React
React Router is a router for React. In @remix-run/router version prior to 1.23.2 and react-router 7.0.0 through 7.11.0, React Router (and Remix v1/v2) SPA open navigation redirects originating from loaders or actions in Framework Mode, D…
CVE-2026-22773Medium· 6.5vLLM is an inference and serving engine for large language models (LLMs)
vLLM is an inference and serving engine for large language models (LLMs). In versions from 0.6.4 to before 0.12.0, users can crash the vLLM engine serving multimodal models that use the Idefics3 vision model implementation by sending a s…
CVE-2026-22703Medium· 5.5github.com/sigstore/cosign: Cosign verification accepts any valid Rekor entry under certain conditions (CVE-2026-22703)
A data verification flaw has been discovered in the golang cosign library. A Cosign bundle can be crafted to successfully verify an artifact even if the embedded Rekor entry does not reference the artifact's digest, signature or public key…
CVE-2026-22701Medium· 5.3filelock: filelock Time-of-Check-Time-of-Use (TOCTOU) in SoftFileLock (CVE-2026-22701)
A Time-of-Check-Time-of-Use (TOCTOU) flaw has been discovered in the pypi filelock package. The TOCTOU race condition vulnerability exists in the SoftFileLock implementation of the filelock package. An attacker with local filesystem access…
CVE-2025-15504Low· 3.3LIEF is vulnerable to segmentation fault
LIEF is vulnerable to segmentation fault
Most-affected vendors
By CVEs published in the period.