Daily digest
Thursday 12 March 2026
18 new CVEs this day, in line with the recent average. Severity skewed high: 1 critical and 8 high, 50% of the total. One arrived with exploitation evidence or public exploit code already attached. nodejs was the most-affected vendor with 3.
New this day, ranked by depth score
The 12 that matter most of the 18 published.
CVE-2026-32247High· 8.1PoCGraphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
CVE-2026-28384Critical· 9.9An improper sanitization of the compression_algorithm parameter in Canonical LXD allows an authenticated, unprivileged user to execute commands as the LXD daemon on the LXD server via API calls to the image and backup endpoints
An improper sanitization of the compression_algorithm parameter in Canonical LXD allows an authenticated, unprivileged user to execute commands as the LXD daemon on the LXD server via API calls to the image and backup endpoints. This iss…
CVE-2026-3989High· 7.8SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization
CVE-2026-32274High· 7.5Black: Arbitrary file writes from unsanitized user input in cache file name
Black: Arbitrary file writes from unsanitized user input in cache file name
CVE-2026-32141High· 7.5flatted is a circular JSON parser
flatted is a circular JSON parser. Prior to 3.4.0, flatted's parse() function uses a recursive revive() phase to resolve circular references in deserialized JSON. When given a crafted payload with deeply nested or self-referential $ indi…
CVE-2026-28356High· 7.5multipart is a fast multipart/form-data parser for python
multipart is a fast multipart/form-data parser for python. Prior to 1.2.2, 1.3.1 and 1.4.0-dev, the parse_options_header() function in multipart.py uses a regular expression with an ambiguous alternation, which can cause exponential back…
CVE-2026-2229High· 7.5ImpactThe undici WebSocket client is vulnerable to a denial-of-service attack due to improper validation of the server_max_window_bits parameter in the permessage-deflate extension
ImpactThe undici WebSocket client is vulnerable to a denial-of-service attack due to improper validation of the server_max_window_bits parameter in the permessage-deflate extension. When a WebSocket client connects to a server, it automa…
CVE-2026-1528High· 7.5ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length
ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's ByteParser overflows internal math, ends up in an invalid state, and throws a fatal TypeError that terminates the proces…
CVE-2026-1526High· 7.5The undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memory consumption during permessage-deflate decompression
The undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memory consumption during permessage-deflate decompression. When a WebSocket connection negotiates the permessage-deflate extension, the client decompr…
CVE-2026-32112Medium· 6.8ha-mcp has XSS via Unescaped HTML in OAuth Consent Form
ha-mcp has XSS via Unescaped HTML in OAuth Consent Form
CVE-2026-2514Medium· 6.1In Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, a vulnerability exists whereby an adversary with access to Flowmon monitoring ports may craft malicious network data that, when processed by Flowmon ADS and viewed by an authen…
In Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, a vulnerability exists whereby an adversary with access to Flowmon monitoring ports may craft malicious network data that, when processed by Flowmon ADS and viewed by an authen…
CVE-2026-2513Medium· 6.1A vulnerability exists in Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, whereby an administrator who clicks a malicious link provided by an attacker may inadvertently trigger unintended actions within their authenticated web …
A vulnerability exists in Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, whereby an administrator who clicks a malicious link provided by an attacker may inadvertently trigger unintended actions within their authenticated web …
Most-affected vendors
By CVEs published in the period.