Daily digest
Monday 30 March 2026
20 new CVEs this day, in line with the recent average. Severity skewed high: 3 critical and 7 high, 50% of the total. 3 arrived with exploitation evidence or public exploit code already attached. nodejs was the most-affected vendor with 8.
New this day, ranked by depth score
The 12 that matter most of the 20 published.
CVE-2026-21710High· 7.5PoCA flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `__proto__` and the application accesses `req.headersDistinct`. When this occurs, `dest["__proto__"]` resolves to `O…
A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `__proto__` and the application accesses `req.headersDistinct`. When this occurs, `dest["__proto__"]` resolves to `O…
CVE-2026-33641High· 7.8PoCGlances Vulnerable to Command Injection via Dynamic Configuration Values
Glances Vulnerable to Command Injection via Dynamic Configuration Values
CVE-2025-15379Critical· 10.0A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_install_model_dependencies_to_env()` function
A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_install_model_dependencies_to_env()` function. When deploying a model with `env_manager=LOCAL`, MLflow reads dependen…
CVE-2025-15036Critical· 9.6MLFlow path traversal vulnerability
MLFlow path traversal vulnerability
CVE-2026-34714Critical· 9.2Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.
Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.
CVE-2026-33030High· 8.8nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys
CVE-2026-21717Medium· 5.9PoCA flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash collisions trivially predictable
A flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash collisions trivially predictable. By crafting a request that causes many such collisions in V8's internal string table, …
CVE-2026-5121High· 7.5A flaw was found in libarchive
A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead t…
CVE-2026-27018HighGotenberg has Chromium deny-list bypass via case-insensitive URL scheme (bypass of GHSA-rh2x-ccvw-q7r3)
Gotenberg has Chromium deny-list bypass via case-insensitive URL scheme (bypass of GHSA-rh2x-ccvw-q7r3)
CVE-2026-3945High· 7.5An integer overflow vulnerability in the HTTP chunked transfer encoding parser in tinyproxy up to and including version 1.11.3 allows an unauthenticated remote attacker to cause a denial of service (DoS)
An integer overflow vulnerability in the HTTP chunked transfer encoding parser in tinyproxy up to and including version 1.11.3 allows an unauthenticated remote attacker to cause a denial of service (DoS). The issue occurs because chunk s…
CVE-2026-33533HighGlances Vulnerable to Cross-Origin System Information Disclosure via XML-RPC Server CORS Wildcard
Glances Vulnerable to Cross-Origin System Information Disclosure via XML-RPC Server CORS Wildcard
CVE-2026-4266Medium· 6.7An Insecure Deserialization vulnerability in WatchGuard Fireware OS allows an attacker that has obtained write access to the local filesystem through another vulnerability to execute arbitrary code in the context of the portald user. No…
An Insecure Deserialization vulnerability in WatchGuard Fireware OS allows an attacker that has obtained write access to the local filesystem through another vulnerability to execute arbitrary code in the context of the portald user. No…
Most-affected vendors
By CVEs published in the period.