Daily digest
Sunday 21 June 2026
A quiet day: only 18 new CVEs against a recent average of about 97. Severity skewed high: 2 critical and 7 high, 50% of the total. 2 arrived with exploitation evidence or public exploit code already attached. litellm was the most-affected vendor with 9.
New this day, ranked by depth score
The 12 that matter most of the 18 published.
CVE-2026-56265Critical· 9.8PoCCrawl4AI: authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server
Crawl4AI: authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server
CVE-2025-71348High· 8.1PoCpicklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methods
picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methods. Attackers can craft pickle files embedding arbitrary code that evades detection but execut…
GHSA-24r3-p3x6-cqvxCritical· 9.6Duplicate Advisory: SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS
Duplicate Advisory: SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS
GHSA-qvp4-q2p5-22ggHigh· 8.1Duplicate Advisory: Picklescan missing detection when calling pytorch function torch.utils._config_module.load_config
Duplicate Advisory: Picklescan missing detection when calling pytorch function torch.utils._config_module.load_config
GHSA-fcqg-3mwf-cfcfHigh· 8.1Duplicate Advisory: Picklescan is missing detection when calling built-in Python cProfile.runctx
Duplicate Advisory: Picklescan is missing detection when calling built-in Python cProfile.runctx
GHSA-8mc5-7w9m-fqv6High· 8.1Duplicate Advisory: Picklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInterpreter.runcommand
Duplicate Advisory: Picklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInterpreter.runcommand
GHSA-fh2f-24rh-r2vqHighDuplicate Advisory: Picklescan missing detection when calling built-in python library function timeit.timeit()
Duplicate Advisory: Picklescan missing detection when calling built-in python library function timeit.timeit()
CVE-2026-12795High· 7.3LiteLLM: SSO Debug Flow Has Improper Authentication
LiteLLM: SSO Debug Flow Has Improper Authentication
CVE-2026-12773High· 7.3LiteLLM: MCP Proxy Has Improper Authentication
LiteLLM: MCP Proxy Has Improper Authentication
CVE-2026-12798Medium· 6.3BerriAI litellm has SSRF via Unvalidated spec_path URL in MCP OpenAPI Spec Loader
BerriAI litellm has SSRF via Unvalidated spec_path URL in MCP OpenAPI Spec Loader
CVE-2026-12797Medium· 6.3BerriAI litellm has Security Feature Bypass in BannedKeywords and AzureContentSafety Guardrails via call_type Mismatch on Async Endpoints
BerriAI litellm has Security Feature Bypass in BannedKeywords and AzureContentSafety Guardrails via call_type Mismatch on Async Endpoints
CVE-2026-12796Medium· 6.3BerriAI litellm: SSO Login Does Not Invalidate Previous UI Session Tokens
BerriAI litellm: SSO Login Does Not Invalidate Previous UI Session Tokens
Most-affected vendors
By CVEs published in the period.