VulnSea

Daily digest

Friday 13 March 2026

11 new CVEs this day, in line with the recent average. Of those, 1 critical and 4 high. 2 arrived with exploitation evidence or public exploit code already attached. erlang was the most-affected vendor with 3.

11
New CVEs
1
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 11 that matter most of the 11 published.

CVE-2026-32597High· 7.5PoC
6mo ago

PyJWT is a JSON Web Token implementation in Python

PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not …

▾ Midnightpyjwt_project · pyjwtEPSS 0.28%via NVD
CVE-2026-31899High· 7.5PoC
6mo ago

CairoSVG vulnerable to Exponential DoS via recursive <use> element amplification

CairoSVG vulnerable to Exponential DoS via recursive <use> element amplification

▾ Midnightcairosvg · cairosvgEPSS 0.52%via OSV
CVE-2026-23941Critical· 9.4
6mo ago

Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling. This vulnerability is associated with program files lib/inets/src/http_server/httpd_…

Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling. This vulnerability is associated with program files lib/inets/src/http_server/httpd_…

▾ Midnighterlang · erlang/inetsEPSS 0.45%via NVD
CVE-2026-4111High· 7.5
6mo ago

A flaw was identified in the RAR5 archive decompression logic of the libarchive library, specifically within the archive_read_data() processing path

A flaw was identified in the RAR5 archive decompression logic of the libarchive library, specifically within the archive_read_data() processing path. When a specially crafted RAR5 archive is processed, the decompression routine may enter…

▾ TwilightEPSS 0.88%via NVD
CVE-2026-32116High
6mo ago

Magic Wormhole: "wormhole receive" allows arbitrary local file overwrite

Magic Wormhole: "wormhole receive" allows arbitrary local file overwrite

▾ Twilightmagic-wormhole · magic-wormholeEPSS 0.51%via OSV
CVE-2026-4105Medium· 6.7
6mo ago

A flaw was found in systemd

A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged use…

▾ SunlitEPSS 0.15%via NVD
CVE-2026-23940Medium· 6.5
6mo ago

Uncontrolled Resource Consumption vulnerability in hexpm hexpm/hexpm allows Excessive Allocation. Publishing an oversized package can cause Hex.pm to run out of memory while extracting the uploaded package tarball

Uncontrolled Resource Consumption vulnerability in hexpm hexpm/hexpm allows Excessive Allocation. Publishing an oversized package can cause Hex.pm to run out of memory while extracting the uploaded package tarball. This can terminate th…

▾ Sunlithex · hexpmEPSS 0.44%via NVD
CVE-2025-8766Medium· 6.4
6mo ago

A container privilege escalation flaw was found in certain Multi-Cloud Object Gateway Core images

A container privilege escalation flaw was found in certain Multi-Cloud Object Gateway Core images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an atta…

▾ Sunlitredhat · openshift_data_foundationEPSS 0.17%via NVD
CVE-2026-23942Medium· 5.4
6mo ago

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP (ssh_sftpd module) allows Path Traversal. This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl and progr…

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP (ssh_sftpd module) allows Path Traversal. This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl and progr…

▾ Sunliterlang · erlang/otpEPSS 0.36%via NVD
CVE-2026-23943Medium· 5.3
6mo ago

Improper Handling of Highly Compressed Data (Compression Bomb) vulnerability in Erlang OTP ssh (ssh_transport modules) allows Denial of Service via Resource Depletion. The SSH transport layer advertises legacy zlib compression by defaul…

Improper Handling of Highly Compressed Data (Compression Bomb) vulnerability in Erlang OTP ssh (ssh_transport modules) allows Denial of Service via Resource Depletion. The SSH transport layer advertises legacy zlib compression by defaul…

▾ Sunliterlang · erlang/otpEPSS 0.64%via NVD
CVE-2026-32594Medium
6mo ago

Parse Server's GraphQL WebSocket endpoint bypasses security middleware

Parse Server's GraphQL WebSocket endpoint bypasses security middleware

▾ Sunlitparse-server · parse-serverEPSS 0.47%via GHSA

Most-affected vendors

By CVEs published in the period.