VulnSea

Daily digest

Wednesday 28 January 2026

7 new CVEs this day, in line with the recent average. Severity skewed high: 1 critical and 4 high, 71% of the total.

7
New CVEs
1
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 7 that matter most of the 7 published.

CVE-2025-61140Critical· 9.8
8mo ago

The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.

The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.

▾ Midnightdchester · jsonpathEPSS 0.51%via NVD
CVE-2026-24842High· 8.2
8mo ago

node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic

node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attac…

▾ Twilightisaacs · tarEPSS 0.62%via NVD
CVE-2025-61731High· 7.8
8mo ago

Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of the file content

Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of the file content. The "#cgo pkg-config:" directive in a Go source file provides command-line arguments to provide to…

▾ Twilightgolang · goEPSS 0.62%via NVD
CVE-2025-57283High· 7.8
8mo ago

The Node.js package browserstack-local 1.5.8 contains a command injection vulnerability

The Node.js package browserstack-local 1.5.8 contains a command injection vulnerability. This occurs because the logfile variable is not properly sanitized in lib/Local.js.

▾ Twilightbrowserstack · browserstack-localEPSS 0.81%via NVD
CVE-2025-61726High· 7.5
8mo ago

The net/url package does not set a limit on the number of query parameters in a query

The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can …

▾ Twilightgolang · goEPSS 2.3%via NVD
CVE-2025-61730Medium· 5.3
8mo ago

crypto/tls: Handshake messages may be processed at the incorrect encryption level in crypto/tls (CVE-2025-61730)

A TLS connection handling flaw has been discovered in the golang crypto/tls library. During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instance the Client Hello and Encrypted E…

▾ SunlitRed Hat · Red Hat Ceph Storage 6EPSS 0.33%via CSAF
CVE-2025-61728None
8mo ago

Excessive CPU consumption when building archive index in archive/zip

Excessive CPU consumption when building archive index in archive/zip

▾ Sunlitstdlib · stdlibEPSS 0.75%via OSV

Most-affected vendors

By CVEs published in the period.