Daily digest
Thursday 22 January 2026
A heavy day: 21 new CVEs, well above the recent average of about 11. Severity skewed high: 4 critical and 7 high, 52% of the total. 5 arrived with exploitation evidence or public exploit code already attached. gitea was the most-affected vendor with 4.
New this day, ranked by depth score
The 12 that matter most of the 21 published.
CVE-2026-23760Critical· 9.8CISA KEVPoCSmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API
SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a r…
CVE-2026-24009High· 8.1PoCdocling-core vulnerable to Remote Code Execution via unsafe PyYAML usage
docling-core vulnerable to Remote Code Execution via unsafe PyYAML usage
CVE-2025-67221HighPoCorjson does not limit recursion for deeply nested JSON documents
orjson does not limit recursion for deeply nested JSON documents
CVE-2026-24049High· 7.1PoCwheel is a command line tool for manipulating Python wheel files, as defined in PEP 427
wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after e…
CVE-2026-20912Critical· 9.1Gitea does not properly validate repository ownership when linking attachments to releases
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release in a different public repository, making it accessible to…
CVE-2026-20897Critical· 9.1Gitea does not properly validate repository ownership when deleting Git LFS locks
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other repositories.
CVE-2026-20750Critical· 9.1Gitea does not properly validate project ownership in organization project operations
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging to a different organization.
CVE-2026-1260High· 7.8Invalid memory access in Sentencepiece versions less than 0.2.1 when using a vulnerable model file, which is not created in the normal training procedure.
Invalid memory access in Sentencepiece versions less than 0.2.1 when using a vulnerable model file, which is not created in the normal training procedure.
CVE-2026-63763HighSurrealDB Affected by Confused Deputy Privilege Escalation through Future Fields and Functions
SurrealDB Affected by Confused Deputy Privilege Escalation through Future Fields and Functions
CVE-2026-24001High· 7.5jsdiff is a JavaScript text differencing implementation
jsdiff is a JavaScript text differencing implementation. Prior to versions 8.0.3, 5.2.2, 4.0.4, and 3.5.1, attempting to parse a patch whose filename headers contain the line break characters `\r`, `\u2028`, or `\u2029` can cause the `pa…
CVE-2026-20736High· 7.5Gitea does not properly verify repository context when deleting attachments
Gitea does not properly verify repository context when deleting attachments. A user who previously uploaded an attachment to a repository may be able to delete it after losing access to that repository by making the request through a dif…
CVE-2025-71176Medium· 6.8pytest has vulnerable tmpdir handling
pytest has vulnerable tmpdir handling
Most-affected vendors
By CVEs published in the period.