VulnSea

Daily digest

Saturday 18 April 2026

A quiet day: only 8 new CVEs against a recent average of about 48. Severity skewed high: 2 critical and 3 high, 63% of the total. 2 arrived with exploitation evidence or public exploit code already attached. apache-airflow-core was the most-affected vendor with 4.

8
New CVEs
2
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 8 that matter most of the 8 published.

CVE-2026-41242Critical· 9.8PoC
5mo ago

protobufjs compiles protobuf definitions into JavaScript (JS) functions

protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the "type" fields of protobuf definitions, which will then execute during object decodi…

▾ Abyssalprotobufjs_project · protobufjsEPSS 0.99%via NVD
CVE-2026-41490High· 8.3PoC
5mo ago

Dagster Vulnerable to SQL Injection via Dynamic Partition Keys in Database I/O Manager Integrations

Dagster Vulnerable to SQL Injection via Dynamic Partition Keys in Database I/O Manager Integrations

▾ Midnightdagster-duckdb · dagster-duckdbEPSS 0.45%via OSV
CVE-2026-41589Critical· 9.6
5mo ago

Wish has SCP Path Traversal that allows arbitrary file read/write

Wish has SCP Path Traversal that allows arbitrary file read/write

▾ Midnightwish · charm.land/wish/v2EPSS 0.51%via OSV
CVE-2026-32228High· 7.5
5mo ago

Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions

Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions

▾ Twilightapache-airflow-core · apache-airflow-coreEPSS 0.72%via OSV
CVE-2026-25917High· 7.2
5mo ago

Apache Airflow allows code execution through crafted XCom payloads

Apache Airflow allows code execution through crafted XCom payloads

▾ Twilightapache-airflow-core · apache-airflow-coreEPSS 1.1%via OSV
CVE-2026-40948Medium· 5.4
5mo ago

apache-airflow-providers-keycloak: Missing OAuth 2.0 State and PKCE Enables Login CSRF and Session Fixation

apache-airflow-providers-keycloak: Missing OAuth 2.0 State and PKCE Enables Login CSRF and Session Fixation

▾ Sunlitapache-airflow-providers-keycloak · apache-airflow-providers-keycloakEPSS 0.36%via OSV
CVE-2026-30912Medium· 5.3
5mo ago

Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false

Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false

▾ Sunlitapache-airflow-core · apache-airflow-coreEPSS 0.76%via OSV
CVE-2026-32690Low· 3.7
5mo ago

Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries

Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries

▾ Sunlitapache-airflow-core · apache-airflow-coreEPSS 0.66%via OSV

Most-affected vendors

By CVEs published in the period.