VulnSea

Tagged “csaf”

CVEs tagged csaf, newest first.

3138 CVEsRSS

CVE-2026-40860Critical· 9.8PoC⚖ disputed
5mo ago

JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, deserialized the payload of incoming JMS ObjectMessage values via javax.jms.ObjectMessage.getObject() without applying any ObjectInputFilter…

JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, deserialized the payload of incoming JMS ObjectMessage values via javax.jms.ObjectMessage.getObject() without applying any ObjectInputFilter…

▾ Abyssalapache · camelEPSS 1.5%via NVD
CVE-2026-6357Medium· 5.8
5mo ago

pip: pip: Arbitrary code execution or information disclosure via malicious wheel package installation (CVE-2026-6357)

A flaw was found in pip. Prior to version 26.1, pip's self-update check functionality would execute after installing wheel packages. This process involved importing newly installed Python modules. A malicious actor could craft a specially …

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.17%via CSAF
CVE-2026-33454Critical· 9.4PoC
5mo ago

The Camel-Mail component is vulnerable to Camel message header injection

The Camel-Mail component is vulnerable to Camel message header injection. The custom header filter strategy used by the component (MailHeaderFilterStrategy) only filters the 'out' direction via setOutFilterStartsWith, while it does not c…

▾ AbyssalRed Hat · Red Hat build of Apache Camel 4 for Quarkus 3EPSS 1.0%via NVD
CVE-2026-40453Critical· 9.9PoC
5mo ago

The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such as 'CAmelExecCommandExecutable' are filtered out alongside 'CamelExecCommandExecutable'

The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such as 'CAmelExecCommandExecutable' are filtered out alongside 'CamelExecCommandExecutable'. The same setLowerCase(true) c…

▾ AbyssalRed Hat · OpenShift ServerlessEPSS 1.9%via NVD
CVE-2026-6993Medium· 5.3
5mo ago

go-kratos: go-kratos kratos: Information disclosure via unintended HTTP server intermediary (CVE-2026-6993)

A flaw was found in go-kratos kratos. A remote attacker could exploit a vulnerability in the HTTP server's `NewServer` function, specifically within the `http.DefaultServeMux Fallback Handler`. This manipulation creates an unintended inter…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.54%via CSAF
CVE-2026-6951Critical· 9.8PoC
5mo ago

Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221) that blocks the -c option but not the e…

Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221) that blocks the -c option but not the e…

▾ Abyssalsimple-git_project · simple-gitEPSS 1.0%via NVD
CVE-2026-31555Medium· 5.5
5mo ago

kernel: futex: Clear stale exiting pointer in futex_lock_pi() retry path (CVE-2026-31555)

A flaw was found in the Linux kernel. A local user could exploit a race condition within the `futex_lock_pi()` retry path. This vulnerability occurs because a stale pointer to an exiting process is not cleared, leading to a kernel warning.…

▾ SunlitRed Hat · Red Hat Enterprise Linux BaseOS (v. 9)EPSS 0.17%via CSAF
CVE-2026-31663High· 7.8
5mo ago

In the Linux kernel, the following vulnerability has been resolved: xfrm: hold dev ref until after transport_finish NF_HOOK After async crypto completes, xfrm_input_resume() calls dev_put() immediately on re-entry before the skb reache…

In the Linux kernel, the following vulnerability has been resolved: xfrm: hold dev ref until after transport_finish NF_HOOK After async crypto completes, xfrm_input_resume() calls dev_put() immediately on re-entry before the skb reache…

▾ Twilightlinux · linux_kernelEPSS 0.13%via NVD
CVE-2026-41140High· 8.7
5mo ago

poetry: Poetry: Path traversal vulnerability allows arbitrary file write via malicious package extraction (CVE-2026-41140)

A flaw was found in Poetry, a dependency manager for Python. This vulnerability allows a remote attacker to perform a path traversal attack. By crafting a malicious software package, the `extractall()` function in Poetry can be tricked int…

▾ TwilightRed Hat · Red Hat Ansible Automation Platform 2.6EPSS 0.47%via CSAF
CVE-2026-42044Medium· 6.5PoC
5mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.2, he Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's depend…

▾ Twilightaxios · axiosEPSS 0.86%via NVD
CVE-2026-42043High· 7.2PoC
5mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axios request can use any address in the 127.0.0.0/8 range (other than 127.0.0.1) to complet…

▾ Midnightaxios · axiosEPSS 0.58%via NVD
CVE-2026-42041Medium· 4.8PoC⚖ disputed
5mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution to silently suppress all HT…

▾ Twilightaxios · axiosEPSS 0.81%via NVD
CVE-2026-42039High· 7.5PoC
5mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, toFormData recursively walks nested objects with no depth limit, so a deeply nested value passed as request data crashes the Node.js process wi…

▾ Midnightaxios · axiosEPSS 0.97%via NVD
CVE-2026-42033High· 7.4PoC
5mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when Object.prototype has been polluted by any co-dependency with keys that axios reads without a hasOwnProperty guard, an attacker can (a) sil…

▾ Midnightaxios · axiosEPSS 0.92%via NVD
CVE-2026-21728High· 7.5
5mo ago

Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy. Mitigation can be done by setting max_result_limit in the search config, e.g

Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy. Mitigation can be done by setting max_result_limit in the search config, e.g. to …

▾ Twilightgrafana · tempoEPSS 0.64%via NVD
CVE-2026-41989High· 7.5
5mo ago

Libgcrypt: Libgcrypt: Denial of Service and buffer overflow via crafted ECDH ciphertext (CVE-2026-41989)

A flaw was found in Libgcrypt. A remote attacker could exploit this vulnerability by sending crafted Elliptic Curve Diffie-Hellman (ECDH) ciphertext to the `gcry_pk_decrypt` function. This can lead to a heap-based buffer overflow, potentia…

▾ TwilightRed Hat · Red Hat Enterprise Linux BaseOS (v. 8)EPSS 0.19%via CSAF
CVE-2026-6862Medium· 5.5
5mo ago

A flaw was found in libefiboot, a component of efivar

A flaw was found in libefiboot, a component of efivar. The device path node parser in libefiboot fails to validate that each node's Length field is at least 4 bytes, which is the minimum size for an EFI (Extensible Firmware Interface) de…

▾ Sunlitubuntu · libefibootEPSS 0.17%via NVD
CVE-2026-31503Medium· 5.5
5mo ago

kernel: udp: Fix wildcard bind conflict check when using hash2 (CVE-2026-31503)

A flaw was found in the Linux kernel's User Datagram Protocol (UDP) implementation. When a significant number of UDP sockets are bound to specific local addresses on the same port, the kernel's conflict detection mechanism can fail. This a…

▾ SunlitRed Hat · Red Hat Enterprise Linux BaseOS (v. 10)EPSS 0.16%via CSAF
CVE-2026-40542High· 7.3
5mo ago

Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification

Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. Users are recommended to upgrade to version…

▾ Twilightapache · httpclientEPSS 0.70%via NVD
CVE-2026-6857High· 7.5PoC
5mo ago

A flaw was found in camel-infinispan

A flaw was found in camel-infinispan. This vulnerability involves unsafe deserialization in the ProtoStream remote aggregation repository. A remote attacker with low privileges could exploit this by sending specially crafted data, leadin…

▾ MidnightRed Hat · camel-infinispanEPSS 1.2%via NVD
CVE-2026-34282High· 7.5
5mo ago

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking)

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 8u481-perf, 11.0.30, 17.0.18, 21.…

▾ Twilightoracle · jreEPSS 0.89%via NVD
CVE-2026-22016High· 7.5PoC
5mo ago

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP)

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 8u481, 8u481-b50, 8u481-perf, 11.0.30, …

▾ Midnightoracle · jreEPSS 0.70%via NVD
CVE-2026-40890High· 7.5
5mo ago

github.com/gomarkdown/markdown: github.com/gomarkdown/markdown: Denial of Service via malformed Markdown input (CVE-2026-40890)

A flaw was found in github.com/gomarkdown/markdown, a Go library for parsing Markdown text and rendering as HTML. A remote attacker could exploit this vulnerability by providing a specially crafted malformed input. Specifically, input cont…

▾ TwilightRed Hat · Multicluster Global Hub 1.4.9EPSS 0.52%via CSAF
CVE-2026-33813High· 7.5
5mo ago

Parsing a WEBP image with an invalid, large size panics on 32-bit platforms.

Parsing a WEBP image with an invalid, large size panics on 32-bit platforms.

▾ TwilightRed Hat · Red Hat Enterprise Linux 8EPSS 0.62%via NVD
CVE-2026-40293High· 7.5
5mo ago

OpenFGA: github.com/openfga/openfga: OpenFGA: Information disclosure of preshared API key via playground endpoint (CVE-2026-40293)

A flaw was found in OpenFGA, an authorization/permission engine. When OpenFGA is configured to use preshared-key authentication and the built-in playground is enabled and accessible beyond localhost or trusted networks, a remote attacker c…

▾ TwilightRed Hat · Multicluster Global Hub 1.7.3EPSS 0.50%via CSAF
CVE-2026-5598High· 7.5
5mo ago

Covert timing channel vulnerability in Legion of the Bouncy Castle Inc

Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). This vulnerability is associated with program files FrodoEngine.Java. This issue affects BC-JAVA: from 1.71 before 1.80.2, f…

▾ TwilightLegion of the Bouncy Castle Inc. · coreEPSS 0.96%via NVD
CVE-2026-3505High· 7.5
5mo ago

Allocation of resources without limits or throttling, Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc

Allocation of resources without limits or throttling, Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpg on all (pg modules). This vulnerability is associated with program files AEADEncData…

▾ TwilightLegion of the Bouncy Castle Inc. · bcpgEPSS 0.88%via NVD
CVE-2026-40575Critical· 9.1
5mo ago

OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing

OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing

▾ Midnightoauth2-proxy · github.com/oauth2-proxy/oauth2-proxy/v7EPSS 0.73%via OSV
CVE-2025-41118Critical· 9.1
5mo ago

Pyroscope is an open-source continuous profiling database

Pyroscope is an open-source continuous profiling database. The database supports various storage backends, including Tencent Cloud Object Storage (COS). If the database is configured to use Tencent COS as the storage backend, an attacke…

▾ Midnightgrafana · pyroscopeEPSS 0.41%via NVD
CVE-2026-5588High· 7.5
5mo ago

Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc

Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all (pkix modules), Legion of the Bouncy Castle Inc. BCPKIX-FIPS bcpkix on All (pkix modules), Legion of the Bouncy Cast…

▾ TwilightLegion of the Bouncy Castle Inc. · bcpkixEPSS 0.69%via NVD
CVEs tagged “csaf” — page 91 · VulnSea