VulnSea

Tagged “csaf”

CVEs tagged csaf, newest first.

3093 CVEsRSS

CVE-2026-20120Medium· 5.8
1w ago

A vulnerability in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthen…

A vulnerability in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthen…

▾ SunlitCisco · Cisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareEPSS 0.41%via NVD
CVE-2026-20248Medium· 6.8
1w ago

A vulnerability in the DNS over TCP implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the T…

A vulnerability in the DNS over TCP implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the T…

▾ SunlitCisco · Cisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareEPSS 0.34%via NVD
CVE-2026-20222High· 7.4
1w ago

A vulnerability in the EIGRP implementation in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to cause the device…

A vulnerability in the EIGRP implementation in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to cause the device…

▾ TwilightCisco · Cisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareEPSS 0.17%via NVD
CVE-2026-92615Medium· 6.6
1w ago

A flaw was found in flightctl

A flaw was found in flightctl. The configureRepoHTTPSClient() function in the device-render worker builds a per-repository tls.Config (which may include InsecureSkipVerify, a custom CA bundle, or tenant-supplied mTLS client certificates)…

▾ SunlitRed Hat · flightctlEPSS 0.15%via NVD
CVE-2026-17526High· 7.2
1w ago

Keycloak is an open-source identity and access management solution

Keycloak is an open-source identity and access management solution. A vulnerability was discovered where a user with the impersonation role can impersonate a realm administrator. This allows the attacker to gain full administrative contr…

▾ TwilightRed Hat · keycloak-rhel9-containerEPSS 0.45%via NVD
CVE-2026-19607Medium· 5.3
1w ago

A flaw was found in the first-broker-login flow of the keycloak-services component

A flaw was found in the first-broker-login flow of the keycloak-services component. This component handles the initial authentication and account linking when a user logs in via an external identity provider. The issue allows an attacker…

▾ SunlitRed Hat · keycloak-rhel9-containerEPSS 0.51%via NVD
CVE-2026-92627Medium· 4.6
1w ago

A heap-use-after-free vulnerability exists in H5T__conv_f_f() in src/H5Tconv.c in HDF5 before 1.14.2. When converting a compound datatype containing floating-point members during a dataset read, a temporary buffer allocated with calloc()…

A heap-use-after-free vulnerability exists in H5T__conv_f_f() in src/H5Tconv.c in HDF5 before 1.14.2. When converting a compound datatype containing floating-point members during a dataset read, a temporary buffer allocated with calloc()…

▾ SunlitThe HDF Group · HDF5EPSS 0.23%via NVD
CVE-2026-80274High· 7.5
1w ago

If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a valid wildcard answer and signed NSEC3 proof, followed by an unsigned NSEC at the same owner name, it will trigger an un…

If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a valid wildcard answer and signed NSEC3 proof, followed by an unsigned NSEC at the same owner name, it will trigger an un…

▾ TwilightISC · BIND 9EPSS 0.67%via NVD
CVE-2026-76163High· 7.5
1w ago

If BIND is loaded with a "`named.conf`" file that contains no global "`options`" block, an attacker can send a query of QTYPE TKEY which may cause an assertion failure and subsequent unexpected program exit. This issue affects BIND 9 ver…

If BIND is loaded with a "`named.conf`" file that contains no global "`options`" block, an attacker can send a query of QTYPE TKEY which may cause an assertion failure and subsequent unexpected program exit. This issue affects BIND 9 ver…

▾ TwilightISC · BIND 9EPSS 0.67%via NVD
CVE-2026-61709Medium· 5.3
1w ago

OpenFGA is an authorization and permission engine built for developers

OpenFGA is an authorization and permission engine built for developers. Prior to 1.18.1, the ListUsers API could return a user that should have been excluded when an authorization relation used an intersection containing a base but not e…

▾ Sunlitopenfga · openfgaEPSS 0.35%via NVD
CVE-2026-19666High· 7.5
1w ago

On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a specific way, the resolver `named` process will exit unexpectedly. This issue affects BIND 9 versions 9.11.0 through 9.18.…

On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a specific way, the resolver `named` process will exit unexpectedly. This issue affects BIND 9 versions 9.11.0 through 9.18.…

▾ TwilightISC · BIND 9EPSS 0.57%via NVD
CVE-2026-19033Medium· 6.5
1w ago

For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data provided in a zone transfer before the final message with the TSIG signature arrives

For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data provided in a zone transfer before the final message with the TSIG signature arrives. This could allow an attacker that does not actually possess…

▾ SunlitISC · BIND 9EPSS 0.24%via NVD
CVE-2026-19668Medium· 5.3
1w ago

A BIND recursive resolver may experience excessive resource consumption if it encounters large numbers of a particular kind of invalid DNSSEC record

A BIND recursive resolver may experience excessive resource consumption if it encounters large numbers of a particular kind of invalid DNSSEC record. Default limits on "max-records-per-type" and "max-types-per-name" help mitigate the ex…

▾ SunlitISC · BIND 9EPSS 0.47%via NVD
CVE-2026-77119Medium· 5.9
1w ago

A validly signed NSEC3 from an unrelated sibling zone may be accepted as an insecurity proof, downgrading a secure delegation and letting a forged unsigned answer through. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0…

A validly signed NSEC3 from an unrelated sibling zone may be accepted as an insecurity proof, downgrading a secure delegation and letting a forged unsigned answer through. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0…

▾ SunlitISC · BIND 9EPSS 0.23%via NVD
CVE-2026-75029Medium· 5.3
1w ago

In a query response, an attacker may send `named` multiple copies of a record that should only exist once (such as an SOA record)

In a query response, an attacker may send `named` multiple copies of a record that should only exist once (such as an SOA record). If the RDATA is the same on all the copies, the record is appended to the in-memory RDATA set, which can c…

▾ SunlitISC · BIND 9EPSS 0.71%via NVD
CVE-2026-77407High· 7.0
1w ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, PlainAuth values defined in auth.go retain passwords as exported plaintext fields in Connection.Config.SASL after a successful PLAIN authentication handshake. The Connection…

▾ Twilightrabbitmq · amqp091-goEPSS 0.13%via NVD
CVE-2026-77406High· 8.2
1w ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.Qos in channel.go accepts negative prefetchCount and prefetchSize integers and casts them directly to uint16 and uint32 fields in the basic.qos method because valida…

▾ Twilightrabbitmq · amqp091-goEPSS 0.41%via NVD
CVE-2026-77403High· 8.9
1w ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Connection.openTune in connection.go accepts a server-advertised FrameMax below the AMQP frameMinSize value of 4096 bytes because the connection negotiation loop does not en…

▾ Twilightrabbitmq · amqp091-goEPSS 0.52%via NVD
CVE-2026-77410High· 8.9
1w ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.recvContent in channel.go preallocates the message body slice with the uint64 ch.header.Size value supplied by an AMQP content header without capping the allocation …

▾ Twilightrabbitmq · amqp091-goEPSS 0.52%via NVD
CVE-2026-77404High· 8.7
1w ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, URI.String in uri.go concatenates CertFile, KeyFile, CACertFile, and ServerName values directly into an AMQPS query string instead of encoding them as URL query parameters w…

▾ Twilightrabbitmq · amqp091-goEPSS 0.10%via NVD
CVE-2026-77412High· 8.9
1w ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, readField in read.go reads the length of an AMQP byte-array field with type tag x into a signed int32 and passes the value directly to make when allocating the field buffer.…

▾ Twilightrabbitmq · amqp091-goEPSS 0.52%via NVD
CVE-2026-77409High· 8.2
1w ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.dispatch in channel.go, confirms.confirm in confirms.go, and Connection.dispatch0 in connection.go synchronously send publisher confirmations, flow-control events, c…

▾ Twilightrabbitmq · amqp091-goEPSS 0.52%via NVD
CVE-2026-63128High· 7.5PoC
1w ago

RMCP is an official Rust SDK for the Model Context Protocol

RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's stateful Streamable HTTP server in crates/rmcp/src/transport/streamable_http_server/tower.rs allows an unauthenticated client to send a well-fo…

▾ Midnightmodelcontextprotocol · rust-sdkEPSS 0.63%via NVD
CVE-2026-63127High· 8.2PoC
1w ago

RMCP is an official Rust SDK for the Model Context Protocol

RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's OAuth implementation in crates/rmcp/src/transport/auth.rs omits the RFC 9728 resource field from ResourceServerMetadata and allows discover_oau…

▾ Midnightmodelcontextprotocol · rust-sdkEPSS 0.20%via NVD
CVE-2026-18212High· 7.5
1w ago

A flaw was found in the SAML Redirect Binding implementation of Keycloak, an open-source identity and access management solution

A flaw was found in the SAML Redirect Binding implementation of Keycloak, an open-source identity and access management solution. The issue occurs because the custom DEFLATE compression and decompression helpers fail to release native zl…

▾ TwilightRed Hat · keycloak-rhel9-containerEPSS 0.52%via NVD
CVE-2026-74909High· 8.1
1w ago

Keycloak provides a policy enforcer to protect applications by matching incoming web requests against defined security policies

Keycloak provides a policy enforcer to protect applications by matching incoming web requests against defined security policies. A flaw was found where the enforcer fails to correctly normalize web addresses that contain special encoded …

▾ TwilightRed Hat · rhbk/keycloak-operator-bundleEPSS 0.85%via NVD
CVE-2026-79651High· 7.5
1w ago

A flaw was found in the theme localization endpoints of the keycloak-services component, which is the core service responsible for authentication flows and theme management in Keycloak

A flaw was found in the theme localization endpoints of the keycloak-services component, which is the core service responsible for authentication flows and theme management in Keycloak. The issue occurs because the system accepts arbitra…

▾ TwilightRed Hat · keycloak-rhel9-containerEPSS 0.81%via NVD
CVE-2026-92365Medium· 4.3⚖ disputed
1w ago

A vulnerability was found in vllm-project vllm up to 0.29.0

A vulnerability was found in vllm-project vllm up to 0.29.0. Affected by this issue is some unknown functionality of the file vllm/v1/sample/thinking_budget_state.py. The manipulation results in inefficient algorithmic complexity. It is …

▾ Sunlitvllm-project · vllmEPSS 0.52%via NVD
CVE-2026-92125High· 8.8
1w ago

Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject the @GroovyASTTransformationClass annotation, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to run an arbitra…

Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject the @GroovyASTTransformationClass annotation, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to run an arbitra…

▾ Twilightjenkins · script_securityEPSS 0.56%via NVD
CVE-2026-81563High· 7.5
1w ago

A BIND resolver encountering an SVCB/HTTPS AliasMode record referencing 14 or more SVCB/HTTPS ServiceMode records may fail to properly deallocate internal resources

A BIND resolver encountering an SVCB/HTTPS AliasMode record referencing 14 or more SVCB/HTTPS ServiceMode records may fail to properly deallocate internal resources. If this happens repeatedly, resource exhaustion will eventually prevent…

▾ TwilightISC · BIND 9EPSS 0.67%via NVD
CVEs tagged “csaf” — page 18 · VulnSea