Daily digest
Wednesday 29 April 2026
A quiet day: only 10 new CVEs against a recent average of about 23. Severity skewed high: 7 high, 70% of the total. One arrived with exploitation evidence or public exploit code already attached. ckan was the most-affected vendor with 3.
New this day, ranked by depth score
The 10 that matter most of the 10 published.
CVE-2026-42031HighPoCCKAN has Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`
CKAN has Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`
CVE-2026-42352High· 8.6pygeoapi 0.23.x: Unauthenticated SSRF via OGC API - Processes Subscriber
pygeoapi 0.23.x: Unauthenticated SSRF via OGC API - Processes Subscriber
CVE-2026-7111High· 8.4Text::CSV_XS versions before 1.62 for Perl have a use-after-free when registered callbacks extend the Perl argument stack, which may enable type confusion or memory corruption. The Parse, print, getline, and getline_all methods invoke r…
Text::CSV_XS versions before 1.62 for Perl have a use-after-free when registered callbacks extend the Perl argument stack, which may enable type confusion or memory corruption. The Parse, print, getline, and getline_all methods invoke r…
CVE-2026-42198High· 7.5pgjdbc is an open source postgresql JDBC Driver
pgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 to before version 42.7.11, pgjdbc is vulnerable to a client-side denial of service during SCRAM-SHA-256 authentication. A malicious server can instruct the driver to pe…
CVE-2026-42351High· 7.5pygeoapi 0.23.x: Path Traversal in STAC FileSystemProvider
pygeoapi 0.23.x: Path Traversal in STAC FileSystemProvider
CVE-2026-41643High· 7.5GoBGP has Remote Denial of Service (Panic) in UpdatePathAttrs4ByteAs via Malformed BGP UPDATE
GoBGP has Remote Denial of Service (Panic) in UpdatePathAttrs4ByteAs via Malformed BGP UPDATE
CVE-2026-7404High· 7.3mcpo-simple-server has a Path Traversal issue
mcpo-simple-server has a Path Traversal issue
CVE-2026-41255Medium· 6.1CKAN has CSRF exemption primed by anonymous requests
CKAN has CSRF exemption primed by anonymous requests
CVE-2026-41132MediumCKAN has no certificate validation on STMP connection
CKAN has no certificate validation on STMP connection
CVE-2026-23773Medium· 4.3Dell Disk Library for Mainframe, version(s) DLm 8700/2700 contain(s) a Server-Side Request Forgery (SSRF) vulnerability
Dell Disk Library for Mainframe, version(s) DLm 8700/2700 contain(s) a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side re…
Most-affected vendors
By CVEs published in the period.