Daily digest
Wednesday 28 January 2026
7 new CVEs this day, in line with the recent average. Severity skewed high: 1 critical and 4 high, 71% of the total.
New this day, ranked by depth score
The 7 that matter most of the 7 published.
CVE-2025-61140Critical· 9.8The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.
The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.
CVE-2026-24842High· 8.2node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic
node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attac…
CVE-2025-61731High· 7.8Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of the file content
Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of the file content. The "#cgo pkg-config:" directive in a Go source file provides command-line arguments to provide to…
CVE-2025-57283High· 7.8The Node.js package browserstack-local 1.5.8 contains a command injection vulnerability
The Node.js package browserstack-local 1.5.8 contains a command injection vulnerability. This occurs because the logfile variable is not properly sanitized in lib/Local.js.
CVE-2025-61726High· 7.5The net/url package does not set a limit on the number of query parameters in a query
The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can …
CVE-2025-61730Medium· 5.3crypto/tls: Handshake messages may be processed at the incorrect encryption level in crypto/tls (CVE-2025-61730)
A TLS connection handling flaw has been discovered in the golang crypto/tls library. During the TLS 1.3 handshake if multiple messages are sent in records that span encryption level boundaries (for instance the Client Hello and Encrypted E…
CVE-2025-61728NoneExcessive CPU consumption when building archive index in archive/zip
Excessive CPU consumption when building archive index in archive/zip
Most-affected vendors
By CVEs published in the period.