VulnSea

Daily digest

Monday 9 February 2026

A heavy day: 18 new CVEs, well above the recent average of about 10. Of those, 2 critical and 5 high. One arrived with exploitation evidence or public exploit code already attached. litestar was the most-affected vendor with 3.

18
New CVEs
2
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 18 published.

CVE-2026-1529High· 8.1PoC
7mo ago

A flaw was found in Keycloak

A flaw was found in Keycloak. An attacker can exploit this vulnerability by modifying the organization ID and target email within a legitimate invitation token's JSON Web Token (JWT) payload. This lack of cryptographic signature verifica…

▾ MidnightEPSS 0.47%via NVD
CVE-2026-1615Critical· 9.8
7mo ago

Versions of the package jsonpath before 1.3.0 are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path expressions

Versions of the package jsonpath before 1.3.0 are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path expressions. The library relies on the static-eval module to process JSON Path input, which is not …

▾ MidnightEPSS 1.1%via NVD
CVE-2025-66630Critical
7mo ago

Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure

Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure

▾ Midnightgofiber · github.com/gofiber/fiber/v2EPSS 0.50%via OSV
CVE-2026-1486High· 8.8
7mo ago

A flaw was found in Keycloak

A flaw was found in Keycloak. A vulnerability exists in the jwt-authorization-grant flow where the server fails to verify if an Identity Provider (IdP) is enabled before issuing tokens. The issuer lookup mechanism (lookupIdentityProvider…

▾ TwilightEPSS 0.47%via NVD
CVE-2026-25639High· 7.5
7mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.5, the mergeConfig function in axios crashes with a TypeError when processing configuration objects containing __proto__ as an own proper…

▾ Twilightaxios · axiosEPSS 1.8%via NVD
CVE-2026-25478High· 7.4
7mo ago

Litestar's CORS origin allowlist has a bypass due to unescaped regex metacharacters in allowed origins

Litestar's CORS origin allowlist has a bypass due to unescaped regex metacharacters in allowed origins

▾ Twilightlitestar · litestarEPSS 0.48%via OSV
CVE-2026-24678High· 7.5
7mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, A capture thread sends sample responses using a freed channel callback after a device channel close, leading to a use after free in ecam_channel_write. Thi…

▾ Twilightfreerdp · freerdpEPSS 0.67%via NVD
CVE-2025-7708Medium· 6.8
7mo ago

Insertion of Sensitive Information Into Sent Data vulnerability in Atlas Educational Software Industry Ltd

Insertion of Sensitive Information Into Sent Data vulnerability in Atlas Educational Software Industry Ltd. Co. K12net allows Communication Channel Manipulation. This issue affects k12net: through 26072025.

▾ SunlitEPSS 0.26%via NVD
CVE-2026-25480Medium· 6.5
7mo ago

Litestar's FileStore key canonicalization collisions allow response cache mixup/poisoning (ASCII ord + Unicode NFKD)

Litestar's FileStore key canonicalization collisions allow response cache mixup/poisoning (ASCII ord + Unicode NFKD)

▾ Sunlitlitestar · litestarEPSS 0.52%via OSV
CVE-2026-25479Medium· 6.5
7mo ago

Litestar's AllowedHosts has a validation bypass due to unescaped regex metacharacters in configured host patterns

Litestar's AllowedHosts has a validation bypass due to unescaped regex metacharacters in configured host patterns

▾ Sunlitlitestar · litestarEPSS 0.42%via OSV
CVE-2026-24098Medium· 6.5
7mo ago

Apache Airflow UI Exposes DAG Import Errors to Unauthorized Authenticated Users

Apache Airflow UI Exposes DAG Import Errors to Unauthorized Authenticated Users

▾ Sunlitapache-airflow · apache-airflowEPSS 0.75%via OSV
CVE-2026-22922Medium· 6.5
7mo ago

Apache Airflow Has an Authorization Bypass That Allows Unauthorized Task Log Access

Apache Airflow Has an Authorization Bypass That Allows Unauthorized Task Log Access

▾ Sunlitapache-airflow · apache-airflowEPSS 0.39%via OSV

Most-affected vendors

By CVEs published in the period.