Daily digest
Monday 27 April 2026
15 new CVEs this day, in line with the recent average. Severity skewed high: 3 critical and 5 high, 53% of the total. 4 arrived with exploitation evidence or public exploit code already attached. Red Hat was the most-affected vendor with 3.
New this day, ranked by depth score
The 12 that matter most of the 15 published.
CVE-2026-40453Critical· 9.9PoCThe fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such as 'CAmelExecCommandExecutable' are filtered out alongside 'CamelExecCommandExecutable'
The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such as 'CAmelExecCommandExecutable' are filtered out alongside 'CamelExecCommandExecutable'. The same setLowerCase(true) c…
CVE-2026-40860Critical· 9.8PoC⚖ disputedJmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, deserialized the payload of incoming JMS ObjectMessage values via javax.jms.ObjectMessage.getObject() without applying any ObjectInputFilter…
JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, deserialized the payload of incoming JMS ObjectMessage values via javax.jms.ObjectMessage.getObject() without applying any ObjectInputFilter…
CVE-2026-33454Critical· 9.4PoCThe Camel-Mail component is vulnerable to Camel message header injection
The Camel-Mail component is vulnerable to Camel message header injection. The custom header filter strategy used by the component (MailHeaderFilterStrategy) only filters the 'out' direction via setOutFilterStartsWith, while it does not c…
CVE-2026-40858High· 8.8PoCThe camel-infinispan component's ProtoStream-based remote aggregation repository deserializes data read from a remote Infinispan cache using java.io.ObjectInputStream without applying any ObjectInputFilter
The camel-infinispan component's ProtoStream-based remote aggregation repository deserializes data read from a remote Infinispan cache using java.io.ObjectInputStream without applying any ObjectInputFilter. An attacker who can write to t…
CVE-2026-3087High· 7.5If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted outside the target directory which is different than other operating systems
If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted outside the target directory which is different than other operating systems. Only Window…
CVE-2026-7158High· 7.3mcp-url-downloader has a Server-Side Request Forgery issue
mcp-url-downloader has a Server-Side Request Forgery issue
CVE-2026-7149High· 7.3kaggle-mcp has a Path Traversal issue
kaggle-mcp has a Path Traversal issue
CVE-2026-28747High· 7.1A weak key generation vulnerability exists in specific firmware versions of Milesight AIOT cameras allows authorization to be bypassed.
A weak key generation vulnerability exists in specific firmware versions of Milesight AIOT cameras allows authorization to be bypassed.
CVE-2026-7150Medium· 6.3auto-favicon has a Server-Side Request Forgery issue
auto-favicon has a Server-Side Request Forgery issue
CVE-2026-7142Medium· 6.3Wooey has an Incorrect Privilege Assignment issue
Wooey has an Incorrect Privilege Assignment issue
CVE-2026-6357Medium· 5.8pip: pip: Arbitrary code execution or information disclosure via malicious wheel package installation (CVE-2026-6357)
A flaw was found in pip. Prior to version 26.1, pip's self-update check functionality would execute after installing wheel packages. This process involved importing newly installed Python modules. A malicious actor could craft a specially …
CVE-2026-7141Medium· 5.6vLLM makes Use of Uninitialized Resource
vLLM makes Use of Uninitialized Resource
Most-affected vendors
By CVEs published in the period.