VulnSea

Tagged “csaf”

CVEs tagged csaf, newest first.

3071 CVEsRSS

CVE-2026-92560High· 7.5
yesterday

A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to ve…

A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to ve…

▾ TwilightApache Software Foundation · org.apache.qpid:qpid-broker-plugins-amqp-0-10-protocolEPSS 0.19%via NVD
CVE-2026-96448Medium· 6.6
yesterday

A flaw was found in the Fine-Grained Admin Permissions (FGAP v2) feature of Keycloak, an identity and access management solution

A flaw was found in the Fine-Grained Admin Permissions (FGAP v2) feature of Keycloak, an identity and access management solution. The issue occurs when the system checks if a delegated administrator has permission to assign a specific ro…

▾ SunlitRed Hat · keycloak-servicesEPSS 0.24%via NVD
CVE-2026-92609Critical· 9.8⚖ disputed
yesterday

Session fixation in HTTP management authentication allows remote attackers to gain unauthorized access to an authenticated management session via reuse of a session identifier retained across successful authentication. This issue affect…

Session fixation in HTTP management authentication allows remote attackers to gain unauthorized access to an authenticated management session via reuse of a session identifier retained across successful authentication. This issue affect…

▾ MidnightApache Software Foundation · org.apache.qpid:qpid-broker-plugins-management-httpEPSS 0.19%via NVD
CVE-2026-97846Medium· 6.8
yesterday

Keycloak provides a feature called mTLS holder-of-key binding which ensures that a token can only be used by the client that originally requested it by binding it to their digital certificate

Keycloak provides a feature called mTLS holder-of-key binding which ensures that a token can only be used by the client that originally requested it by binding it to their digital certificate. A flaw was discovered where the new Standard…

▾ SunlitRed Hat · keycloak-servicesEPSS 0.14%via NVD
CVE-2026-95811Medium· 6.5PoC
yesterday

Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow an equivalent spelling of a path to bypass the locationRules that restrict it. The handler matches each vhost…

Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow an equivalent spelling of a path to bypass the locationRules that restrict it. The handler matches each vhost…

▾ TwilightRed Hat · Lemonldap-NG-HandlerEPSS 0.40%via NVD
CVE-2026-92289Medium· 6.8PoC
yesterday

Lemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow a PKCE bypass for public Relying Parties in "PKCE or secret" mode because checkEndPointAuthenticationCredentials does not verify the client secret. With oidcRPMetaD…

Lemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow a PKCE bypass for public Relying Parties in "PKCE or secret" mode because checkEndPointAuthenticationCredentials does not verify the client secret. With oidcRPMetaD…

▾ TwilightRed Hat · Lemonldap-NG-PortalEPSS 0.22%via NVD
CVE-2026-92288Critical· 9.1PoC⚖ disputed
yesterday

Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth2 token introspection because checkEndPointAuthenticationCredentials does not verify the client secret of a public Re…

Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth2 token introspection because checkEndPointAuthenticationCredentials does not verify the client secret of a public Re…

▾ AbyssalRed Hat · Lemonldap-NG-PortalEPSS 0.21%via NVD
CVE-2026-93353Medium· 5.3PoC
2d ago

copyparty contains a volume restriction bypass vulnerability in its SFTP front end that allows authenticated SFTP users to create, remove, and truncate arbitrary paths outside permitted volume boundaries by exploiting three handlers that…

copyparty contains a volume restriction bypass vulnerability in its SFTP front end that allows authenticated SFTP users to create, remove, and truncate arbitrary paths outside permitted volume boundaries by exploiting three handlers that…

▾ Twilight9001 · copypartyEPSS 0.32%via NVD
CVE-2026-88387Medium· 5.5
2d ago

LibRaw 0.22.0 contains an incorrect numeric conversion vulnerability in LibRaw::parse_tiff_ifd() when processing TIFF tag 0x00fe (NewSubfileType)

LibRaw 0.22.0 contains an incorrect numeric conversion vulnerability in LibRaw::parse_tiff_ifd() when processing TIFF tag 0x00fe (NewSubfileType). A specially crafted RAW, TIFF, or DNG file can supply an attacker-controlled NewSubfileTyp…

▾ SunlitRed HatEPSS 0.15%via NVD
CVE-2026-88386Medium· 5.5PoC
2d ago

libsndfile 1.2.2 contains a misaligned memory access issue in psf_binheader_readf() while parsing WAV fmt chunks

libsndfile 1.2.2 contains a misaligned memory access issue in psf_binheader_readf() while parsing WAV fmt chunks. A specially crafted WAV file can cause the function to cast an unaligned destination address to unsigned int * and perform …

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.14%via NVD
CVE-2026-96747Medium· 5.0
2d ago

The client-side field level encryption support in the MongoDB Python Driver can treat a key management endpoint value ending in ".sock" as a local Unix domain socket path rather than a remote host

The client-side field level encryption support in the MongoDB Python Driver can treat a key management endpoint value ending in ".sock" as a local Unix domain socket path rather than a remote host. A user with write access to the encrypt…

▾ SunlitMongoDB · Python DriverEPSS 0.13%via NVD
CVE-2026-96749High· 8.4
2d ago

An integer overflow in the BSON document encoding component of the MongoDB Python Driver's bundled native extension may occur when a single document is built from an unusually large amount of caller-supplied data

An integer overflow in the BSON document encoding component of the MongoDB Python Driver's bundled native extension may occur when a single document is built from an unusually large amount of caller-supplied data. Size arithmetic is perf…

▾ TwilightMongoDB · Python DriverEPSS 0.13%via NVD
CVE-2026-96748Medium· 6.5
2d ago

PyMongo's connection string parsing decodes percent-encoded characters in the host portion before the host list is separated on its delimiters

PyMongo's connection string parsing decodes percent-encoded characters in the host portion before the host list is separated on its delimiters. When an application places a hostname value supplied by an unauthenticated party into a conne…

▾ SunlitMongoDB · Python DriverEPSS 0.26%via NVD
CVE-2026-57175Medium· 6.4
2d ago

Python Social Auth is a social authentication/registration mechanism

Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the SAML backend accepted SAML responses on the Assertion Consumer Service endpoint without verifying that they matched a previously issued `Au…

▾ Sunlitpython-social-auth · social-coreEPSS 0.23%via NVD
CVE-2026-57178High· 7.4
2d ago

Python Social Auth is a social authentication/registration mechanism

Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the `vk-app` backend accepted VK application callback data without verifying the callback signature when the `auth_key` parameter was omitted. …

▾ Twilightpython-social-auth · social-coreEPSS 0.16%via NVD
CVE-2026-57176Medium· 6.8
2d ago

Python Social Auth is a social authentication/registration mechanism

Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the Vend OAuth2 backend used only the numeric Vend user_id as the social-auth UID. When multiple Vend shops authenticate through the same appli…

▾ Sunlitpython-social-auth · social-coreEPSS 0.22%via NVD
CVE-2026-57177Medium· 4.3
2d ago

Python Social Auth is a social authentication/registration mechanism

Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the LoginRadius backend did not validate OAuth state during the authentication flow. Applications using this backend were vulnerable to login C…

▾ Sunlitpython-social-auth · social-coreEPSS 0.11%via NVD
CVE-2026-57179Medium· 4.2
2d ago

Python Social Auth is a social authentication/registration mechanism

Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the partial-pipeline resume mechanism accepted `partial_token` as a bearer credential without binding it to the browser session that created it…

▾ Sunlitpython-social-auth · social-coreEPSS 0.16%via NVD
CVE-2026-88372High· 7.5PoC⚖ disputed
2d ago

libsndfile 1.2.2 contains an integer overflow vulnerability in mat4_read_header() when parsing crafted MAT4 (MATLAB v4) files.

libsndfile 1.2.2 contains an integer overflow vulnerability in mat4_read_header() when parsing crafted MAT4 (MATLAB v4) files.

▾ MidnightRed Hat · Red Hat Enterprise Linux 10EPSS 0.39%via NVD
CVE-2026-93542Medium· 6.5
2d ago

An out-of-bounds read in libXi's XI2 class parsing via size_classes() and copy_classes() in libXi before 1.8.4 could be used by malicous servers to crash the X client.

An out-of-bounds read in libXi's XI2 class parsing via size_classes() and copy_classes() in libXi before 1.8.4 could be used by malicous servers to crash the X client.

▾ Sunlitx.org · libXiEPSS 0.25%via NVD
CVE-2026-97417High· 7.5
2d ago

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack: use get_unaligned_be32() in tcp_sack() The timestamp-only fast path dereferences the option stream as *(__be32 *)ptr, which assumes 4-byte ali…

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack: use get_unaligned_be32() in tcp_sack() The timestamp-only fast path dereferences the option stream as *(__be32 *)ptr, which assumes 4-byte ali…

▾ TwilightLinux · LinuxEPSS 0.43%via NVD
CVE-2026-88367Medium· 6.5PoC
2d ago

NanoSVG 239e102ec contains an incorrect numeric conversion vulnerability in nsvg__curveDivs() during SVG stroke rasterization

NanoSVG 239e102ec contains an incorrect numeric conversion vulnerability in nsvg__curveDivs() during SVG stroke rasterization. A specially crafted SVG document containing an extremely large stroke-width can cause floating-point rounding …

▾ TwilightRed HatEPSS 0.15%via NVD
CVE-2026-93543High· 7.4
2d ago

An out-of-bounds read in libXi's XI2 class parser in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.

An out-of-bounds read in libXi's XI2 class parser in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.

▾ Twilightx.org · libXiEPSS 0.25%via NVD
CVE-2026-93544Medium· 6.5
2d ago

An out-of-bounds read in libXi's XI2 XIQueryDevice reply parsing in libXi before 1.8.4 can be used by a malicious X server to crash an attached X client.

An out-of-bounds read in libXi's XI2 XIQueryDevice reply parsing in libXi before 1.8.4 can be used by a malicious X server to crash an attached X client.

▾ Sunlitx.org · libXiEPSS 0.24%via NVD
CVE-2026-93545Medium· 6.5
2d ago

An out-of-bounds read in libXi's XListInputDevices() in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.

An out-of-bounds read in libXi's XListInputDevices() in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.

▾ Sunlitx.org · libXiEPSS 0.20%via NVD
CVE-2026-88385High· 7.5
2d ago

Mini-XML 4.0.5 contains a memory leak vulnerability in mxml_load_data() during malformed XML parsing

Mini-XML 4.0.5 contains a memory leak vulnerability in mxml_load_data() during malformed XML parsing. Specially crafted XML input can cause text nodes allocated by mxmlNewText() to become unlinked before a parse error transfers control t…

▾ TwilightRed HatEPSS 0.15%via NVD
CVE-2026-94281Medium· 6.5
2d ago

An out-of-bounds read in libXi's XListInputDevices() class parsing in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.

An out-of-bounds read in libXi's XListInputDevices() class parsing in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.

▾ Sunlitx.org · libXiEPSS 0.20%via NVD
CVE-2026-88384Medium· 5.5PoC
2d ago

OpenEXR 3.4.14 contains a NULL Pointer Dereference in the C++ attribute parsing path

OpenEXR 3.4.14 contains a NULL Pointer Dereference in the C++ attribute parsing path. A specially crafted EXR file containing an unknown-type attribute with dataSize set to zero causes the parser to create an opaque attribute with a NULL…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.19%via NVD
CVE-2026-88383Medium· 6.5
2d ago

libical 4.0.6 contains an incompatible function pointer in icalparameter_string_to_kind()

libical 4.0.6 contains an incompatible function pointer in icalparameter_string_to_kind(). When parsing iCalendar data containing a parameterized property, the function passes icalparameter_compare_kind_map() to bsearch() through an inco…

▾ SunlitRed Hat · Red Hat Enterprise Linux 7EPSS 0.17%via NVD
CVE-2026-96746Medium· 6.5
2d ago

An out-of-bounds write in the connection-monitoring logic of the MongoDB C Driver may allow an unauthenticated party who controls name resolution and the responses of the hosts named in a client's connection string to write beyond the en…

An out-of-bounds write in the connection-monitoring logic of the MongoDB C Driver may allow an unauthenticated party who controls name resolution and the responses of the hosts named in a client's connection string to write beyond the en…

▾ SunlitMongoDB · C DriverEPSS 0.37%via NVD
CVEs tagged “csaf” — page 2 · VulnSea