VulnSea

Daily digest

Saturday 9 May 2026

A quiet day: only 7 new CVEs against a recent average of about 36. Of those, 3 high. Red Hat was the most-affected vendor with 3.

7
New CVEs
0
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 7 that matter most of the 7 published.

CVE-2026-42311High· 7.8
4mo ago

Pillow: python-pillow: Pillow: Arbitrary code execution via malicious PSD file processing (CVE-2026-42311)

A flaw was found in Pillow, a Python imaging library. An attacker could exploit this vulnerability by tricking a user into processing a specially crafted malicious PSD file. This could lead to memory corruption, potentially causing the app…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.22%via CSAF
CVE-2026-42246High· 7.4
4mo ago

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4, a man-in-the-middle attacker can cause Net::IMAP#starttls to return "successfully", without s…

▾ Twilightruby-lang · net::imapEPSS 0.40%via NVD
CVE-2026-42301High· 7.3
4mo ago

pyp2spec: pyp2spec: Arbitrary command execution via unescaped RPM macro directives (CVE-2026-42301)

A flaw was found in pyp2spec, a tool that generates Fedora RPM spec files for Python projects. This vulnerability allows a malicious Python Package Index (PyPI) package to execute arbitrary commands on a build machine. This occurs because …

▾ TwilightRed Hat · pyp2specEPSS 0.23%via CSAF
CVE-2026-44897Medium· 6.1
4mo ago

Mistune Heading ID Attribute has Injection XSS

Mistune Heading ID Attribute has Injection XSS

▾ Sunlitmistune · mistuneEPSS 0.27%via OSV
CVE-2026-42308Medium· 6.2
4mo ago

Pillow: Pillow: Denial of Service via integer overflow in font processing (CVE-2026-42308)

A flaw was found in Pillow, a Python imaging library. If a font advances for each glyph by an exceeding large amount, an integer overflow can occur when Pillow tracks the current position. This could lead to a denial of service (DoS) condi…

▾ SunlitRed Hat · Red Hat Enterprise Linux 8EPSS 0.16%via CSAF
CVE-2026-8213Medium· 5.5
4mo ago

A vulnerability has been found in OSGeo gdal up to 3.13.0dev-4. Affected by this issue is the function GDSDfldsrch of the file frmts/hdf4…

A vulnerability has been found in OSGeo gdal up to 3.13.0dev-4. Affected by this issue is the function GDSDfldsrch of the file frmts/hdf4/hdf-eos/GDapi.c of the component Grid File Handler. The manipulation leads to heap-based buffer ove…

▾ Sunlitgdal · gdalEPSS 0.23%via OSV
CVE-2026-42258Medium· 5.3
4mo ago

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, symbol arguments to commands are vulnerable to a CRLF Injection / IMAP Command injection via Symbol a…

▾ SunlitEPSS 1.3%via NVD

Most-affected vendors

By CVEs published in the period.