Daily digest
Monday 9 February 2026
A heavy day: 18 new CVEs, well above the recent average of about 10. Of those, 2 critical and 5 high. One arrived with exploitation evidence or public exploit code already attached. litestar was the most-affected vendor with 3.
New this day, ranked by depth score
The 12 that matter most of the 18 published.
CVE-2026-1529High· 8.1PoCA flaw was found in Keycloak
A flaw was found in Keycloak. An attacker can exploit this vulnerability by modifying the organization ID and target email within a legitimate invitation token's JSON Web Token (JWT) payload. This lack of cryptographic signature verifica…
CVE-2026-1615Critical· 9.8Versions of the package jsonpath before 1.3.0 are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path expressions
Versions of the package jsonpath before 1.3.0 are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path expressions. The library relies on the static-eval module to process JSON Path input, which is not …
CVE-2025-66630CriticalFiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure
Fiber has an insecure fallback in utils.UUIDv4() / utils.UUID() — predictable / zero‑UUID on crypto/rand failure
CVE-2026-1486High· 8.8A flaw was found in Keycloak
A flaw was found in Keycloak. A vulnerability exists in the jwt-authorization-grant flow where the server fails to verify if an Identity Provider (IdP) is enabled before issuing tokens. The issuer lookup mechanism (lookupIdentityProvider…
CVE-2026-25639High· 7.5Axios is a promise based HTTP client for the browser and Node.js
Axios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.5, the mergeConfig function in axios crashes with a TypeError when processing configuration objects containing __proto__ as an own proper…
CVE-2026-25478High· 7.4Litestar's CORS origin allowlist has a bypass due to unescaped regex metacharacters in allowed origins
Litestar's CORS origin allowlist has a bypass due to unescaped regex metacharacters in allowed origins
CVE-2026-24678High· 7.5FreeRDP is a free implementation of the Remote Desktop Protocol
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, A capture thread sends sample responses using a freed channel callback after a device channel close, leading to a use after free in ecam_channel_write. Thi…
CVE-2025-7708Medium· 6.8Insertion of Sensitive Information Into Sent Data vulnerability in Atlas Educational Software Industry Ltd
Insertion of Sensitive Information Into Sent Data vulnerability in Atlas Educational Software Industry Ltd. Co. K12net allows Communication Channel Manipulation. This issue affects k12net: through 26072025.
CVE-2026-25480Medium· 6.5Litestar's FileStore key canonicalization collisions allow response cache mixup/poisoning (ASCII ord + Unicode NFKD)
Litestar's FileStore key canonicalization collisions allow response cache mixup/poisoning (ASCII ord + Unicode NFKD)
CVE-2026-25479Medium· 6.5Litestar's AllowedHosts has a validation bypass due to unescaped regex metacharacters in configured host patterns
Litestar's AllowedHosts has a validation bypass due to unescaped regex metacharacters in configured host patterns
CVE-2026-24098Medium· 6.5Apache Airflow UI Exposes DAG Import Errors to Unauthorized Authenticated Users
Apache Airflow UI Exposes DAG Import Errors to Unauthorized Authenticated Users
CVE-2026-22922Medium· 6.5Apache Airflow Has an Authorization Bypass That Allows Unauthorized Task Log Access
Apache Airflow Has an Authorization Bypass That Allows Unauthorized Task Log Access
Most-affected vendors
By CVEs published in the period.