VulnSea

Daily digest

Monday 27 April 2026

15 new CVEs this day, in line with the recent average. Severity skewed high: 3 critical and 5 high, 53% of the total. 4 arrived with exploitation evidence or public exploit code already attached. Red Hat was the most-affected vendor with 3.

15
New CVEs
3
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 15 published.

CVE-2026-40453Critical· 9.9PoC
5mo ago

The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such as 'CAmelExecCommandExecutable' are filtered out alongside 'CamelExecCommandExecutable'

The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such as 'CAmelExecCommandExecutable' are filtered out alongside 'CamelExecCommandExecutable'. The same setLowerCase(true) c…

▾ AbyssalRed Hat · OpenShift ServerlessEPSS 1.9%via NVD
CVE-2026-40860Critical· 9.8PoC⚖ disputed
5mo ago

JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, deserialized the payload of incoming JMS ObjectMessage values via javax.jms.ObjectMessage.getObject() without applying any ObjectInputFilter…

JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, deserialized the payload of incoming JMS ObjectMessage values via javax.jms.ObjectMessage.getObject() without applying any ObjectInputFilter…

▾ Abyssalapache · camelEPSS 1.5%via NVD
CVE-2026-33454Critical· 9.4PoC
5mo ago

The Camel-Mail component is vulnerable to Camel message header injection

The Camel-Mail component is vulnerable to Camel message header injection. The custom header filter strategy used by the component (MailHeaderFilterStrategy) only filters the 'out' direction via setOutFilterStartsWith, while it does not c…

▾ AbyssalRed Hat · Red Hat build of Apache Camel 4 for Quarkus 3EPSS 1.0%via NVD
CVE-2026-40858High· 8.8PoC
5mo ago

The camel-infinispan component's ProtoStream-based remote aggregation repository deserializes data read from a remote Infinispan cache using java.io.ObjectInputStream without applying any ObjectInputFilter

The camel-infinispan component's ProtoStream-based remote aggregation repository deserializes data read from a remote Infinispan cache using java.io.ObjectInputStream without applying any ObjectInputFilter. An attacker who can write to t…

▾ Midnightapache · camelEPSS 1.2%via NVD
CVE-2026-3087High· 7.5
5mo ago

If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted outside the target directory which is different than other operating systems

If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted outside the target directory which is different than other operating systems. Only Window…

▾ Twilightpython · pythonEPSS 0.73%via NVD
CVE-2026-7158High· 7.3
5mo ago

mcp-url-downloader has a Server-Side Request Forgery issue

mcp-url-downloader has a Server-Side Request Forgery issue

▾ Twilightmcp-url-downloader · mcp-url-downloaderEPSS 0.47%via OSV
CVE-2026-7149High· 7.3
5mo ago

kaggle-mcp has a Path Traversal issue

kaggle-mcp has a Path Traversal issue

▾ Twilightkaggle-mcp · kaggle-mcpEPSS 0.59%via OSV
CVE-2026-28747High· 7.1
5mo ago

A weak key generation vulnerability exists in specific firmware versions of Milesight AIOT cameras allows authorization to be bypassed.

A weak key generation vulnerability exists in specific firmware versions of Milesight AIOT cameras allows authorization to be bypassed.

▾ TwilightEPSS 0.28%via NVD
CVE-2026-7150Medium· 6.3
5mo ago

auto-favicon has a Server-Side Request Forgery issue

auto-favicon has a Server-Side Request Forgery issue

▾ Sunlitauto-favicon · auto-faviconEPSS 0.35%via OSV
CVE-2026-7142Medium· 6.3
5mo ago

Wooey has an Incorrect Privilege Assignment issue

Wooey has an Incorrect Privilege Assignment issue

▾ Sunlitwooey · wooeyEPSS 0.37%via OSV
CVE-2026-6357Medium· 5.8
5mo ago

pip: pip: Arbitrary code execution or information disclosure via malicious wheel package installation (CVE-2026-6357)

A flaw was found in pip. Prior to version 26.1, pip's self-update check functionality would execute after installing wheel packages. This process involved importing newly installed Python modules. A malicious actor could craft a specially …

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.17%via CSAF
CVE-2026-7141Medium· 5.6
5mo ago

vLLM makes Use of Uninitialized Resource

vLLM makes Use of Uninitialized Resource

▾ Sunlitvllm · vllmEPSS 0.48%via OSV

Most-affected vendors

By CVEs published in the period.