Daily digest
Tuesday 2 June 2026
26 new CVEs this day, in line with the recent average. Of those, 1 critical and 7 high. 9 arrived with exploitation evidence or public exploit code already attached. elixir-tesla was the most-affected vendor with 5.
New this day, ranked by depth score
The 12 that matter most of the 26 published.
CVE-2026-47117Critical· 9.8PoCOpenMed vulnerable to remote code injection through privacy-filter model loading path
OpenMed vulnerable to remote code injection through privacy-filter model loading path
CVE-2026-30652High· 8.8A remote buffer overflow vulnerability exists in the /cgi-bin/dido/setdo.cgi endpoint of the admin interface of Vivotek FD8136 cameras running firmware version FD8136-VVTK-0300a
A remote buffer overflow vulnerability exists in the /cgi-bin/dido/setdo.cgi endpoint of the admin interface of Vivotek FD8136 cameras running firmware version FD8136-VVTK-0300a. This flaw allows an authenticated attacker to execute arbi…
CVE-2026-27145Medium· 6.5PoC(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries
(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SA…
CVE-2026-1784High· 8.8The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy
The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a contro…
RUSTSEC-2026-0279High· 8.1Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
Rojo development server vulnerable to DNS rebinding, allowing unauthenticated read/write access and local program execution
CVE-2026-48597Medium· 5.9PoC⚖ disputedAllocation of Resources Without Limits or Throttling vulnerability in elixir-tesla tesla allows denial of service via atom table exhaustion in Tesla.Adapter.Mint. Tesla.Adapter.Mint.open_conn/2 converts the URL scheme of every outgoing …
Allocation of Resources Without Limits or Throttling vulnerability in elixir-tesla tesla allows denial of service via atom table exhaustion in Tesla.Adapter.Mint. Tesla.Adapter.Mint.open_conn/2 converts the URL scheme of every outgoing …
CVE-2026-48595Medium· 5.9PoC⚖ disputedImproper Handling of Case Sensitivity vulnerability in elixir-tesla tesla allows credential leakage to a third-party origin on cross-origin redirects. Tesla.Middleware.FollowRedirects strips security-sensitive headers on cross-origin re…
Improper Handling of Case Sensitivity vulnerability in elixir-tesla tesla allows credential leakage to a third-party origin on cross-origin redirects. Tesla.Middleware.FollowRedirects strips security-sensitive headers on cross-origin re…
CVE-2026-43965Medium· 5.6PoCPath traversal vulnerability in Gleam's dependency management allows arbitrary directory deletion via malicious build/packages/packages.toml content. Package keys read from build/packages/packages.toml by LocalPackages::read_from_disc a…
Path traversal vulnerability in Gleam's dependency management allows arbitrary directory deletion via malicious build/packages/packages.toml content. Package keys read from build/packages/packages.toml by LocalPackages::read_from_disc a…
CVE-2026-48594High· 7.5Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in elixir-tesla tesla allows a denial of service via decompression bomb in HTTP response bodies. When Tesla.Middleware.DecompressResponse or Tesla.Middleware…
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in elixir-tesla tesla allows a denial of service via decompression bomb in HTTP response bodies. When Tesla.Middleware.DecompressResponse or Tesla.Middleware…
CVE-2026-42504High· 7.5Quadratic complexity in WordDecoder.DecodeHeader in mime
Quadratic complexity in WordDecoder.DecodeHeader in mime
CVE-2026-3514High· 7.5Prefect has an Authentication Middleware Bypass when URL paths are appended with 'health' or 'ready'
Prefect has an Authentication Middleware Bypass when URL paths are appended with 'health' or 'ready'
CVE-2026-42795Medium· 5.1PoCSymlink following vulnerability in Gleam's Hex package export allows files outside the project root to be embedded in the generated package tarball. The file collection helpers (gleam_files, native_files, private_files) in compiler-cli/…
Symlink following vulnerability in Gleam's Hex package export allows files outside the project root to be embedded in the generated package tarball. The file collection helpers (gleam_files, native_files, private_files) in compiler-cli/…
Most-affected vendors
By CVEs published in the period.