{"resultsPerPage":106,"startIndex":0,"totalResults":106,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-05T13:48:12.886","vulnerabilities":[{"cve":{"id":"CVE-2026-24457","sourceIdentifier":"emo@eclipse.org","published":"2026-03-05T19:16:02.780","lastModified":"2026-08-05T08:16:32.897","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0, allows a remote attacker to read arbitrary files from a MQ Broker's server. A full exploitation could read unauthorized files of the OpenMQ’s host OS. In some scenarios RCE could be achieved. This is fixed in OpenMQ 6.5.2, 6.9.0, and in GlassFish 7.0.26, 7.1.1, and 8.0.2."},{"lang":"es","value":"Un análisis inseguro de la configuración de OpenMQ permite a un atacante remoto leer archivos arbitrarios de un servidor de MQ Broker. Una explotación completa podría leer archivos no autorizados del sistema operativo anfitrión de OpenMQ. En algunos escenarios se podría lograr RCE."}],"affected":[{"source":"emo@eclipse.org","affectedData":[{"vendor":"Eclipse Foundation","product":"Eclipse OpenMQ","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"6.5.2","versionType":"semver","status":"affected"},{"version":"6.6.0","lessThan":"6.9.0","versionType":"semver","status":"affected"}]},{"vendor":"Eclipse Foundation","product":"Eclipse GlassFish","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"7.0.26","versionType":"semver","status":"affected"},{"version":"7.1.0","lessThan":"7.1.1","versionType":"semver","status":"affected"},{"version":"8.0.0","lessThan":"8.0.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"emo@eclipse.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-06T16:00:31.715526Z","id":"CVE-2026-24457","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"emo@eclipse.org","type":"Secondary","description":[{"lang":"en","value":"CWE-22"},{"lang":"en","value":"CWE-27"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:eclipse:openmq:*:*:*:*:*:*:*:*","versionEndIncluding":"6.5.1","matchCriteriaId":"D0C54C08-8788-4481-97CC-EAFFC7702412"}]}]}],"references":[{"url":"https://gitlab.eclipse.org/security/cve-assignment/-/issues/84","source":"emo@eclipse.org","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-53703","sourceIdentifier":"secalert@redhat.com","published":"2026-06-15T20:16:33.563","lastModified":"2026-08-05T09:18:14.820","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a RealMedia (.rm) file, the demuxer parses MDPR (media properties) chunks to configure audio streams. For audio stream header versions 4 and 5, the parser reads fields such as codec type, packet size, sample rate, channel count, and extra codec data length from fixed offsets within the chunk without first checking that the chunk contains enough data. If a malicious file provides an MDPR chunk that is too small to contain a complete audio stream header, the parser reads beyond the end of the buffer. This can cause the application to crash. In some cases, bytes read past the buffer boundary may be incorporated into stream metadata, which could result in limited information disclosure."}],"affected":[{"source":"secalert@redhat.com","affectedData":[{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"gstreamer1-plugins-ugly-free","cpes":["cpe:/o:redhat:enterprise_linux:10.2"],"versions":[{"version":"0:1.26.7-2.el10_2.1","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10.0 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"gstreamer1-plugins-ugly-free","cpes":["cpe:/o:redhat:enterprise_linux_eus:10.0"],"versions":[{"version":"0:1.24.11-1.el10_0.2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"gstreamer1-plugins-ugly-free","cpes":["cpe:/a:redhat:enterprise_linux:9::appstream"],"versions":[{"version":"0:1.22.12-6.el9_8.1","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.6 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"gstreamer1-plugins-ugly-free","cpes":["cpe:/a:redhat:rhel_eus:9.6::appstream"],"versions":[{"version":"0:1.22.12-4.el9_6.1","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 7","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"gstreamer1-plugins-ugly-free","cpes":["cpe:/o:redhat:enterprise_linux:7"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"gstreamer1-plugins-ugly-free","cpes":["cpe:/o:redhat:enterprise_linux:8"]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":4.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-16T15:05:30.391525Z","id":"CVE-2026-53703","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"secalert@redhat.com","type":"Secondary","description":[{"lang":"en","value":"CWE-125"}]}],"references":[{"url":"https://access.redhat.com/errata/RHSA-2026:36673","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:36674","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:50688","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:50691","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2026-53703","source":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2487613","source":"secalert@redhat.com"}]}},{"cve":{"id":"CVE-2026-53704","sourceIdentifier":"secalert@redhat.com","published":"2026-06-15T20:16:33.697","lastModified":"2026-08-05T09:18:15.290","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package. When processing a RealMedia file containing a specially crafted FILEINFO metadata section, the demuxer parses variable-name and variable-value pairs using re_skip_pascal_string() without validating that offsets remain within the mapped buffer. Additionally, the element count controlling the parsing loop is read from attacker-controlled data without validation, which can cause an infinite loop. A crafted RealMedia file can cause the application to crash, hang, or potentially read limited adjacent memory contents."}],"affected":[{"source":"secalert@redhat.com","affectedData":[{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10.0 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"gstreamer1-plugins-ugly-free","cpes":["cpe:/o:redhat:enterprise_linux_eus:10.0"],"versions":[{"version":"0:1.24.11-1.el10_0.2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"gstreamer1-plugins-ugly-free","cpes":["cpe:/a:redhat:enterprise_linux:9::appstream"],"versions":[{"version":"0:1.22.12-6.el9_8.1","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.6 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"gstreamer1-plugins-ugly-free","cpes":["cpe:/a:redhat:rhel_eus:9.6::appstream"],"versions":[{"version":"0:1.22.12-4.el9_6.1","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"gstreamer1-plugins-ugly-free","cpes":["cpe:/o:redhat:enterprise_linux:10"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 7","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"gstreamer1-plugins-ugly-free","cpes":["cpe:/o:redhat:enterprise_linux:7"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"gstreamer1-plugins-ugly-free","cpes":["cpe:/o:redhat:enterprise_linux:8"]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":4.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-16T12:46:47.069346Z","id":"CVE-2026-53704","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"secalert@redhat.com","type":"Secondary","description":[{"lang":"en","value":"CWE-125"}]}],"references":[{"url":"https://access.redhat.com/errata/RHSA-2026:36674","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:50688","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:50691","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2026-53704","source":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2487614","source":"secalert@redhat.com"}]}},{"cve":{"id":"CVE-2026-16242","sourceIdentifier":"secalert@redhat.com","published":"2026-07-20T08:16:29.833","lastModified":"2026-08-05T08:16:30.670","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could connect as an unauthenticated agent, join the routing pool, and potentially proxy, inspect, modify, or drop control-plane-to-node traffic."}],"affected":[{"source":"secalert@redhat.com","affectedData":[{"vendor":"Red Hat","product":"multicluster engine for Kubernetes 2.1","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"multicluster-engine/hypershift-rhel9-operator","cpes":["cpe:/a:redhat:multicluster_engine:2.10::el9"],"versions":[{"version":"1784905766","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"multicluster engine for Kubernetes 2.1","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"multicluster-engine/hypershift-rhel9-operator","cpes":["cpe:/a:redhat:multicluster_engine:2.10::el9"],"versions":[{"version":"1784905766","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"multicluster engine for Kubernetes 2.11.0","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"multicluster-engine/hypershift-rhel9-operator","cpes":["cpe:/a:redhat:multicluster_engine:2.11::el9"],"versions":[{"version":"1784945966","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"multicluster engine for Kubernetes 2.17","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"multicluster-engine/hypershift-rhel9-operator","cpes":["cpe:/a:redhat:multicluster_engine:2.17::el9"],"versions":[{"version":"1784856942","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"multicluster engine for Kubernetes 2.6","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"multicluster-engine/hypershift-rhel9-operator","cpes":["cpe:/a:redhat:multicluster_engine:2.6::el9"],"versions":[{"version":"1784905804","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"multicluster engine for Kubernetes 2.8","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"multicluster-engine/hypershift-rhel9-operator","cpes":["cpe:/a:redhat:multicluster_engine:2.8::el9"],"versions":[{"version":"1784905783","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"multicluster engine for Kubernetes 2.9","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"multicluster-engine/hypershift-rhel9-operator","cpes":["cpe:/a:redhat:multicluster_engine:2.9::el9"],"versions":[{"version":"1784905769","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-hypershift-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1784913720","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.20","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-hypershift-rhel9","cpes":["cpe:/a:redhat:openshift:4.20::el9"],"versions":[{"version":"1785288843","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.21","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-hypershift-rhel9","cpes":["cpe:/a:redhat:openshift:4.21::el9"],"versions":[{"version":"1785301941","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.22","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-hypershift-rhel9","cpes":["cpe:/a:redhat:openshift:4.22::el9"],"versions":[{"version":"1785192936","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Logging Subsystem for Red Hat OpenShift","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-logging/cluster-logging-rhel9-operator","cpes":["cpe:/a:redhat:logging:6"]},{"vendor":"Red Hat","product":"Multicluster Engine for Kubernetes","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"multicluster-engine/cluster-curator-controller-rhel9","cpes":["cpe:/a:redhat:multicluster_engine"]},{"vendor":"Red Hat","product":"Multicluster Engine for Kubernetes","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"multicluster-engine/hypershift-addon-rhel9-operator","cpes":["cpe:/a:redhat:multicluster_engine"]},{"vendor":"Red Hat","product":"Multicluster Engine for Kubernetes","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"multicluster-engine/hypershift-cli-rhel9","cpes":["cpe:/a:redhat:multicluster_engine"]},{"vendor":"Red Hat","product":"Multicluster Engine for Kubernetes","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"multicluster-engine/managedcluster-import-controller-rhel9","cpes":["cpe:/a:redhat:multicluster_engine"]},{"vendor":"Red Hat","product":"OpenShift API for Data Protection","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"oadp/oadp-hypershift-velero-plugin-rhel9","cpes":["cpe:/a:redhat:openshift_api_data_protection:1"]},{"vendor":"Red Hat","product":"OpenShift API for Data Protection","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"oadp/oadp-rhel9-operator","cpes":["cpe:/a:redhat:openshift_api_data_protection:1"]},{"vendor":"Red Hat","product":"Red Hat Advanced Cluster Management for Kubernetes 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhacm2/acm-multicluster-observability-addon-rhel9","cpes":["cpe:/a:redhat:acm:2"]},{"vendor":"Red Hat","product":"Red Hat Advanced Cluster Management for Kubernetes 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhacm2/acm-must-gather-rhel9","cpes":["cpe:/a:redhat:acm:2"]},{"vendor":"Red Hat","product":"Red Hat Advanced Cluster Management for Kubernetes 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhacm2/endpoint-monitoring-rhel9-operator","cpes":["cpe:/a:redhat:acm:2"]},{"vendor":"Red Hat","product":"Red Hat Advanced Cluster Management for Kubernetes 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhacm2/grafana-dashboard-loader-rhel9","cpes":["cpe:/a:redhat:acm:2"]},{"vendor":"Red Hat","product":"Red Hat Advanced Cluster Management for Kubernetes 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhacm2/metrics-collector-rhel9","cpes":["cpe:/a:redhat:acm:2"]},{"vendor":"Red Hat","product":"Red Hat Advanced Cluster Management for Kubernetes 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhacm2/multicluster-observability-rhel9-operator","cpes":["cpe:/a:redhat:acm:2"]},{"vendor":"Red Hat","product":"Red Hat Advanced Cluster Management for Kubernetes 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhacm2/rbac-query-proxy-rhel9","cpes":["cpe:/a:redhat:acm:2"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-aws-ebs-csi-driver-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-aws-efs-csi-driver-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-azure-disk-csi-driver-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-azure-file-csi-driver-operator-rhel9","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-cluster-csi-snapshot-controller-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-cluster-network-operator","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-cluster-network-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-cluster-node-tuning-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-cluster-storage-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-csi-driver-manila-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-hypershift-rhel8","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-openstack-cinder-csi-driver-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-powervs-block-csi-driver-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-smb-csi-driver-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4"]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","baseScore":9.4,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":5.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-21T14:56:23.371685Z","id":"CVE-2026-16242","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"secalert@redhat.com","type":"Secondary","description":[{"lang":"en","value":"CWE-306"}]}],"references":[{"url":"https://access.redhat.com/errata/RHSA-2026:46885","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:47388","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:47735","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:47949","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:47953","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:47974","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:48284","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:48657","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:48670","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:48676","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:48693","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2026-16242","source":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2502690","source":"secalert@redhat.com"},{"url":"https://github.com/openshift/hypershift/pull/9031","source":"secalert@redhat.com"}]}},{"cve":{"id":"CVE-2026-65512","sourceIdentifier":"audit@patchstack.com","published":"2026-07-23T12:18:44.253","lastModified":"2026-08-05T09:18:15.727","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Cross-Site request forgery (CSRF) vulnerability in Melapress WP Activity Log and Melapress WP Activity Log Premium allows Cross Site Request Forgery.\n\nThis issue affects WP Activity Log: through 5.6.4; WP Activity Log Premium: through 5.6.4."}],"affected":[{"source":"audit@patchstack.com","affectedData":[{"vendor":"Melapress","product":"WP Activity Log","defaultStatus":"unaffected","collectionURL":"https://wordpress.org/plugins","packageName":"wp-security-audit-log","versions":[{"version":"0","lessThanOrEqual":"5.6.4","versionType":"custom","status":"affected","changes":[{"at":"5.6.5","status":"unaffected"}]}]},{"vendor":"Melapress","product":"WP Activity Log Premium","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"5.6.4","versionType":"custom","status":"affected","changes":[{"at":"5.6.5","status":"unaffected"}]}]}]}],"metrics":{"cvssMetricV31":[{"source":"audit@patchstack.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-23T13:40:38.178600Z","id":"CVE-2026-65512","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"audit@patchstack.com","type":"Secondary","description":[{"lang":"en","value":"CWE-352"}]}],"references":[{"url":"https://patchstack.com/database/WordPress/Plugin/wp-security-audit-log-premium/vulnerability/wordpress-wp-activity-log-premium-plugin-5-6-4-cross-site-request-forgery-csrf-vulnerability","source":"audit@patchstack.com"},{"url":"https://patchstack.com/database/wordpress/plugin/wp-security-audit-log/vulnerability/wordpress-wp-activity-log-plugin-5-6-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve","source":"audit@patchstack.com"}]}},{"cve":{"id":"CVE-2026-64534","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-27T08:16:22.643","lastModified":"2026-08-05T08:16:35.860","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path\n\nIn nvmet_tcp_try_recv_ddgst(), when a data digest mismatch is detected,\nnvmet_req_uninit() is called unconditionally. However, if the command\narrived via the nvmet_tcp_handle_req_failure() path, nvmet_req_init()\nhad returned false and percpu_ref_tryget_live() was never executed. The\nunconditional percpu_ref_put() inside nvmet_req_uninit() then causes a\nrefcount underflow, leading to a WARNING in\npercpu_ref_switch_to_atomic_rcu, a use-after-free diagnostic, and\neventually a permanent workqueue deadlock.\n\nCheck cmd->flags & NVMET_TCP_F_INIT_FAILED before calling\nnvmet_req_uninit(), matching the existing pattern in\nnvmet_tcp_execute_request()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/nvme/target/tcp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"91edfca6f8b364d60cde3ddefaf7d03ddf35774b","lessThan":"22ec7a9fe9153d2737ee9b2fa6d2e43a1491decf","versionType":"git","status":"affected"},{"version":"fda871c0ba5d2eed2cd1c881573168129da70058","lessThan":"ba35b1c674ca3841c0dfadd698f2c1b3ec542d4e","versionType":"git","status":"affected"},{"version":"fda871c0ba5d2eed2cd1c881573168129da70058","lessThan":"c7874dad84b20433c0fe3919f291a762d40de08b","versionType":"git","status":"affected"},{"version":"fda871c0ba5d2eed2cd1c881573168129da70058","lessThan":"e602c93b25bda4a9d0ff1791a4bdbfdcbb074af1","versionType":"git","status":"affected"},{"version":"fda871c0ba5d2eed2cd1c881573168129da70058","lessThan":"d306da8833e75f669d93424fd84940236f3850bc","versionType":"git","status":"affected"},{"version":"fda871c0ba5d2eed2cd1c881573168129da70058","lessThan":"2ed3c9d955e8cd6361f130623baa664a75fb345f","versionType":"git","status":"affected"},{"version":"fda871c0ba5d2eed2cd1c881573168129da70058","lessThan":"4606467a75cfc16721937272ed29462a750b60c8","versionType":"git","status":"affected"},{"version":"4b17476d809273617d3317fa0d4ae78aa488d760","versionType":"git","status":"affected"},{"version":"5.10.20","lessThan":"5.10.261","versionType":"semver","status":"affected"},{"version":"5.11.3","lessThan":"5.12","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/nvme/target/tcp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.12","status":"affected"},{"version":"0","lessThan":"5.12","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/22ec7a9fe9153d2737ee9b2fa6d2e43a1491decf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2ed3c9d955e8cd6361f130623baa664a75fb345f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4606467a75cfc16721937272ed29462a750b60c8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ba35b1c674ca3841c0dfadd698f2c1b3ec542d4e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c7874dad84b20433c0fe3919f291a762d40de08b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d306da8833e75f669d93424fd84940236f3850bc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e602c93b25bda4a9d0ff1791a4bdbfdcbb074af1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64535","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-27T08:16:22.773","lastModified":"2026-08-05T08:16:36.013","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-tcp: Fix potential UAF when ddgst mismatch\n\nShivam Kumar found via vulnerability testing:\nWhen data digest is enabled on an NVMe/TCP connection and a digest\nmismatch occurs on a non-final H2C_DATA PDU during an R2T-based\ndata transfer, the digest error handler in nvmet_tcp_try_recv_ddgst()\ncalls nvmet_req_uninit() — which performs percpu_ref_put() on the\nsubmission queue — but does NOT mark the command as completed. It\ndoes not set cqe->status, does not modify rbytes_done, and does not\nclear any flag. When the subsequent fatal error triggers queue\nteardown, nvmet_tcp_uninit_data_in_cmds() iterates all commands,\nchecks nvmet_tcp_need_data_in() for each one, and finds that the\nalready-uninited command still appears to need data (because\nrbytes_done < transfer_len and cqe->status == 0). It therefore calls\nnvmet_req_uninit() a second time on the same command — a double\npercpu_ref_put against a single percpu_ref_get."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/nvme/target/tcp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"fda871c0ba5d2eed2cd1c881573168129da70058","lessThan":"96fe2513df590e74b04253a45089cae75569570e","versionType":"git","status":"affected"},{"version":"fda871c0ba5d2eed2cd1c881573168129da70058","lessThan":"e091ff83d962f9ed00d9bd70443676de9fe98bdc","versionType":"git","status":"affected"},{"version":"fda871c0ba5d2eed2cd1c881573168129da70058","lessThan":"6f9442983a3e4227afd1c83a5251ddbca585ea21","versionType":"git","status":"affected"},{"version":"fda871c0ba5d2eed2cd1c881573168129da70058","lessThan":"088ee46c18d99baef453afd74181dd40ade044ad","versionType":"git","status":"affected"},{"version":"fda871c0ba5d2eed2cd1c881573168129da70058","lessThan":"dbbd07d0a7020b80f6a7028e561908f7b83b3d5a","versionType":"git","status":"affected"},{"version":"91edfca6f8b364d60cde3ddefaf7d03ddf35774b","versionType":"git","status":"affected"},{"version":"4b17476d809273617d3317fa0d4ae78aa488d760","versionType":"git","status":"affected"},{"version":"5.10.20","lessThan":"5.11","versionType":"semver","status":"affected"},{"version":"5.11.3","lessThan":"5.12","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/nvme/target/tcp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.12","status":"affected"},{"version":"0","lessThan":"5.12","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/088ee46c18d99baef453afd74181dd40ade044ad","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6f9442983a3e4227afd1c83a5251ddbca585ea21","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/96fe2513df590e74b04253a45089cae75569570e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dbbd07d0a7020b80f6a7028e561908f7b83b3d5a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e091ff83d962f9ed00d9bd70443676de9fe98bdc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-18477","sourceIdentifier":"secalert@redhat.com","published":"2026-08-03T17:16:33.897","lastModified":"2026-08-05T08:16:32.277","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue."}],"affected":[{"source":"secalert@redhat.com","affectedData":[{"vendor":"Red Hat","product":"Red Hat Hardened Images","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"tar-main","cpes":["cpe:/a:redhat:hummingbird:1"],"versions":[{"version":"1.35-9.1.hum1","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"tar","cpes":["cpe:/o:redhat:enterprise_linux:10"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 6","defaultStatus":"unknown","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"tar","cpes":["cpe:/o:redhat:enterprise_linux:6"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 7","defaultStatus":"unknown","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"tar","cpes":["cpe:/o:redhat:enterprise_linux:7"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"tar","cpes":["cpe:/o:redhat:enterprise_linux:8"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"tar","cpes":["cpe:/o:redhat:enterprise_linux:9"]},{"vendor":"Red Hat","product":"Red Hat Hardened Images","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"aardvark-dns","cpes":["cpe:/a:redhat:hummingbird:1"]},{"vendor":"Red Hat","product":"Red Hat Hardened Images","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"chunkah","cpes":["cpe:/a:redhat:hummingbird:1"]},{"vendor":"Red Hat","product":"Red Hat Hardened Images","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"grafana12.4","cpes":["cpe:/a:redhat:hummingbird:1"]},{"vendor":"Red Hat","product":"Red Hat Hardened Images","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"grafana13.1","cpes":["cpe:/a:redhat:hummingbird:1"]},{"vendor":"Red Hat","product":"Red Hat Hardened Images","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"netavark","cpes":["cpe:/a:redhat:hummingbird:1"]},{"vendor":"Red Hat","product":"Red Hat Hardened Images","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"nodejs26","cpes":["cpe:/a:redhat:hummingbird:1"]},{"vendor":"Red Hat","product":"Red Hat Hardened Images","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"python-cryptography","cpes":["cpe:/a:redhat:hummingbird:1"]},{"vendor":"Red Hat","product":"Red Hat Hardened Images","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rust","cpes":["cpe:/a:redhat:hummingbird:1"]},{"vendor":"Red Hat","product":"Red Hat Hardened Images","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rust-rpm-sequoia","cpes":["cpe:/a:redhat:hummingbird:1"]},{"vendor":"Red Hat","product":"Red Hat Hardened Images","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"yarnpkg","cpes":["cpe:/a:redhat:hummingbird:1"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhcos","cpes":["cpe:/a:redhat:openshift:4"]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N","baseScore":4.4,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":0.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-03T16:25:22.002230Z","id":"CVE-2026-18477","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"secalert@redhat.com","type":"Secondary","description":[{"lang":"en","value":"CWE-367"}]}],"references":[{"url":"https://access.redhat.com/errata/RHSA-2026:49361","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2026-18477","source":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2509735","source":"secalert@redhat.com"}]}},{"cve":{"id":"CVE-2026-66257","sourceIdentifier":"security@apache.org","published":"2026-08-05T06:16:38.423","lastModified":"2026-08-05T08:16:38.313","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.\n\nThis issue affects Apache Qpid Proton-J: through 0.34.1.\n\nUsers are recommended to upgrade to version 0.35.0, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Qpid Proton-J","defaultStatus":"unaffected","collectionURL":"https://repo.maven.apache.org/maven2","packageName":"org.apache.qpid:proton-j","versions":[{"version":"0","lessThanOrEqual":"0.34.1","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"references":[{"url":"https://lists.apache.org/thread/dnczt6bgfcq2x6q8ljco177h1qmv59fm","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/8","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-66273","sourceIdentifier":"security@apache.org","published":"2026-08-05T06:16:38.593","lastModified":"2026-08-05T08:16:38.423","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service.\n\nThis issue affects Apache Qpid Proton-J: through 0.34.1.\n\nUsers are recommended to upgrade to version 0.35.0, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Qpid Proton-J","defaultStatus":"unaffected","collectionURL":"https://repo.maven.apache.org/maven2","packageName":"org.apache.qpid:proton-j","versions":[{"version":"0","lessThanOrEqual":"0.34.1","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-789"}]}],"references":[{"url":"https://lists.apache.org/thread/z34s9v5w05qk4qqtz5fs3v9wpxz6fnbh","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/9","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-67465","sourceIdentifier":"security@apache.org","published":"2026-08-05T06:16:39.160","lastModified":"2026-08-05T08:16:38.947","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.\n\nThis issue affects Apache Qpid Proton-Dotnet: through 1.0.0.\n\nUsers are recommended to upgrade to version 1.1.0, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Qpid Proton Dotnet","defaultStatus":"unaffected","packageName":"Apache.Qpid.Proton","versions":[{"version":"0","lessThanOrEqual":"1.0.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"references":[{"url":"https://lists.apache.org/thread/zl2pj5fo32lbyrwof89tdyrgt67bbo0m","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/21","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-67551","sourceIdentifier":"security@apache.org","published":"2026-08-05T06:16:39.313","lastModified":"2026-08-05T08:16:39.053","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service.\n\nThis issue affects Apache Qpid Proton-Dotnet: through 1.0.0.\n\nUsers are recommended to upgrade to version 1.1.0, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Qpid Proton Dotnet","defaultStatus":"unaffected","packageName":"org.apache.qpid","versions":[{"version":"0","lessThanOrEqual":"1.0.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-789"}]}],"references":[{"url":"https://lists.apache.org/thread/o566fhkrr3gg0lyzt24xwvz9w94oo6ro","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/22","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-67588","sourceIdentifier":"security@apache.org","published":"2026-08-05T06:16:39.450","lastModified":"2026-08-05T08:16:39.577","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.\n\nThis issue affects Apache Qpid ProtonJ2: through 1.1.0.\n\nUsers are recommended to upgrade to version 1.2.0, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Qpid ProtonJ2","defaultStatus":"unaffected","collectionURL":"https://repo.maven.apache.org/maven2","packageName":"org.apache.qpid:protonj2","versions":[{"version":"0","lessThanOrEqual":"1.1.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"references":[{"url":"https://lists.apache.org/thread/vk4j02dzggfdrdkwvzmqo4jro2tgj0jt","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/27","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-67589","sourceIdentifier":"security@apache.org","published":"2026-08-05T06:16:39.583","lastModified":"2026-08-05T08:16:39.677","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service.\n\nThis issue affects Apache Qpid ProtonJ2: through 1.1.0.\n\nUsers are recommended to upgrade to version 1.2.0, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Qpid ProtonJ2","defaultStatus":"unaffected","collectionURL":"https://repo.maven.apache.org/maven2","packageName":"org.apache.qpid:protonj2","versions":[{"version":"0","lessThanOrEqual":"1.1.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-789"}]}],"references":[{"url":"https://lists.apache.org/thread/bs24x4778dh72xtfs299cy8krvdlo47q","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/28","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-68060","sourceIdentifier":"security@apache.org","published":"2026-08-05T06:16:39.737","lastModified":"2026-08-05T08:16:40.087","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service.\n\nThis issue affects Apache Qpid Broker-J: through 10.0.1.\n\nUsers are recommended to upgrade to version 10.1.0, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Qpid Broker-J","defaultStatus":"unaffected","collectionURL":"https://repo.maven.apache.org/maven2","packageName":"org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol","versions":[{"version":"0","lessThanOrEqual":"10.0.1","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"references":[{"url":"https://lists.apache.org/thread/0slvl8h25w3z4opnh08yyn8l3chko5c9","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/14","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-68074","sourceIdentifier":"security@apache.org","published":"2026-08-05T06:16:39.877","lastModified":"2026-08-05T08:16:40.290","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.\n\nThis issue affects Apache Qpid Broker-J: through 10.0.1.\n\nUsers are recommended to upgrade to version 10.1.0, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Qpid Broker-J","defaultStatus":"unaffected","collectionURL":"https://repo.maven.apache.org/maven2","packageName":"org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol","versions":[{"version":"0","lessThanOrEqual":"10.0.1","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"references":[{"url":"https://lists.apache.org/thread/9t1pvl36z69ssww6449od5g0tszqnhjs","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/16","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-49004","sourceIdentifier":"psirt@zte.com.cn","published":"2026-08-05T07:16:37.333","lastModified":"2026-08-05T08:16:33.327","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The built-in PostgreSQL service on the mobile device suffers from misconfiguration flaws and command injection vulnerabilities. This service listens on a specific port, runs with root privileges, and is protected by weak credentials. The database supports the COPY FROM PROGRAM syntax, allowing local attackers to bypass Android's permission sandbox and gain full root access."}],"affected":[{"source":"psirt@zte.com.cn","affectedData":[{"vendor":"ZTE","product":"NX799J (Red Magic 11 Air)","defaultStatus":"unaffected","versions":[{"version":"GEN_CN_NX799JV1.0.0B15","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@zte.com.cn","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"PHYSICAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":0.7,"impactScore":5.3}]},"weaknesses":[{"source":"psirt@zte.com.cn","type":"Secondary","description":[{"lang":"en","value":"CWE-89"}]}],"references":[{"url":"https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/460174866982027405","source":"psirt@zte.com.cn"}]}},{"cve":{"id":"CVE-2026-66274","sourceIdentifier":"security@apache.org","published":"2026-08-05T07:16:37.590","lastModified":"2026-08-05T08:16:38.523","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service.\n\nThis issue affects Apache Qpid Proton-J: through 0.34.1.\n\nUsers are recommended to upgrade to version 0.35.0, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Qpid Proton-J","defaultStatus":"unaffected","collectionURL":"https://repo.maven.apache.org/maven2","packageName":"org.apache.qpid:proton-j","versions":[{"version":"0","lessThanOrEqual":"0.34.1","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-674"}]}],"references":[{"url":"https://lists.apache.org/thread/h7xolzws2by2qhdjf7scbx87foxojb5h","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/10","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-66275","sourceIdentifier":"security@apache.org","published":"2026-08-05T07:16:37.717","lastModified":"2026-08-05T08:16:38.630","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service.\n\nThis issue affects Apache Qpid Proton-J: through 0.34.1.\n\nUsers are recommended to upgrade to version 0.35.0, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Qpid Proton-J","defaultStatus":"unaffected","collectionURL":"https://repo.maven.apache.org/maven2","packageName":"org.apache.qpid:proton-j","versions":[{"version":"0","lessThanOrEqual":"0.34.1","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"references":[{"url":"https://lists.apache.org/thread/jds59nxrgcxtlx7xl0kvl5hqt07thxzt","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/11","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-66276","sourceIdentifier":"security@apache.org","published":"2026-08-05T07:16:37.847","lastModified":"2026-08-05T08:16:38.730","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service.\n\nThis issue affects Apache Qpid Proton-J: through 0.34.1.\n\nUsers are recommended to upgrade to version 0.35.0, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Qpid Proton-J","defaultStatus":"unaffected","collectionURL":"https://repo.maven.apache.org/maven2","packageName":"org.apache.qpid:proton-j","versions":[{"version":"0","lessThanOrEqual":"0.34.1","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-606"}]}],"references":[{"url":"https://lists.apache.org/thread/14nj0lpsqpnd3q0hw0t0tw44qvdo1jc2","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/12","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-66277","sourceIdentifier":"security@apache.org","published":"2026-08-05T07:16:37.967","lastModified":"2026-08-05T08:16:38.837","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.\n\nThis issue affects Apache Qpid Proton-J: through 0.34.1.\n\nUsers are recommended to upgrade to version 0.35.0, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Qpid Proton-J","defaultStatus":"unaffected","collectionURL":"https://repo.maven.apache.org/maven2","packageName":"org.apache.qpid:proton-j","versions":[{"version":"0","lessThanOrEqual":"0.34.1","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"references":[{"url":"https://lists.apache.org/thread/48tflr3sx0sxq9bcdy5rh06oy3gmwx02","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/13","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-67552","sourceIdentifier":"security@apache.org","published":"2026-08-05T07:16:38.103","lastModified":"2026-08-05T08:16:39.160","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service.\n\nThis issue affects Apache Qpid Proton-Dotnet through 1.0.0.\n\nUsers are recommended to upgrade to version 1.1.0, which fixes the issue"}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Qpid Proton Dotnet","defaultStatus":"unaffected","packageName":"org.apache.qpid","versions":[{"version":"0","lessThanOrEqual":"1.0.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-674"}]}],"references":[{"url":"https://lists.apache.org/thread/4dyg0gycrv55ox4oywqght61b053g8xj","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/23","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-67553","sourceIdentifier":"security@apache.org","published":"2026-08-05T07:16:38.223","lastModified":"2026-08-05T08:16:39.257","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service.\n\nThis issue affects Apache Qpid Proton-Dotnet: through 1.0.0.\n\nUsers are recommended to upgrade to version 1.1.0, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Qpid Proton Dotnet","defaultStatus":"unaffected","packageName":"org.apache.qpid","versions":[{"version":"0","lessThanOrEqual":"1.0.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"references":[{"url":"https://lists.apache.org/thread/hvsncmcbgjrn85crs909nf4y3dqqrywo","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/24","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-67554","sourceIdentifier":"security@apache.org","published":"2026-08-05T07:16:38.347","lastModified":"2026-08-05T08:16:39.370","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service.\n\nThis issue affects Apache Qpid Proton-Dotnet: through 1.0.0.\n\nUsers are recommended to upgrade to version 1.1.0, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Qpid Proton Dotnet","defaultStatus":"unaffected","packageName":"org.apache.qpid","versions":[{"version":"0","lessThanOrEqual":"1.0.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-606"}]}],"references":[{"url":"https://lists.apache.org/thread/5ndlowz29464ytj98gz9z9ljhwnmb2hm","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/25","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-67555","sourceIdentifier":"security@apache.org","published":"2026-08-05T07:16:38.470","lastModified":"2026-08-05T08:16:39.470","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service\n\nThis issue affects Apache Qpid Proton-Dotnet: through 1.0.0.\n\nUsers are recommended to upgrade to version 1.1.0, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Qpid Proton Dotnet","defaultStatus":"unaffected","packageName":"org.apache.qpid","versions":[{"version":"0","lessThanOrEqual":"1.0.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"references":[{"url":"https://lists.apache.org/thread/dwrb02dp714lvlfxdj4o5bc9h3z54sw3","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/26","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-67590","sourceIdentifier":"security@apache.org","published":"2026-08-05T07:16:38.613","lastModified":"2026-08-05T08:16:39.780","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service.\n\nThis issue affects Apache Qpid ProtonJ2: through 1.1.0.\n\nUsers are recommended to upgrade to version 1.2.0, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Qpid ProtonJ2","defaultStatus":"unaffected","collectionURL":"https://repo.maven.apache.org/maven2","packageName":"org.apache.qpid:protonj2","versions":[{"version":"0","lessThanOrEqual":"1.1.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-674"}]}],"references":[{"url":"https://lists.apache.org/thread/kmov6k7f3moqy01m1s370fl61vgos3ly","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/29","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-67591","sourceIdentifier":"security@apache.org","published":"2026-08-05T07:16:38.737","lastModified":"2026-08-05T08:16:39.890","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service.\n\nThis issue affects Apache Qpid ProtonJ2: through 1.1.0.\n\nUsers are recommended to upgrade to version 1.2.0, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Qpid ProtonJ2","defaultStatus":"unaffected","collectionURL":"https://repo.maven.apache.org/maven2","packageName":"org.apache.qpid:protonj2","versions":[{"version":"0","lessThanOrEqual":"1.1.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"references":[{"url":"https://lists.apache.org/thread/rwmggh2bkm6qotxpdfcplht3jgw5n036","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/30","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-67592","sourceIdentifier":"security@apache.org","published":"2026-08-05T07:16:38.853","lastModified":"2026-08-05T08:16:39.983","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.\n\nThis issue affects Apache Qpid ProtonJ2: through 1.1.0.\n\nUsers are recommended to upgrade to version 1.2.0, which fixes the issue"}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Qpid ProtonJ2","defaultStatus":"unaffected","collectionURL":"https://repo.maven.apache.org/maven2","packageName":"org.apache.qpid:protonj2","versions":[{"version":"0","lessThanOrEqual":"1.1.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"references":[{"url":"https://lists.apache.org/thread/b4pv9hfdk7ox78pss77sb4nzwjrvqhhz","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/31","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-68073","sourceIdentifier":"security@apache.org","published":"2026-08-05T07:16:38.973","lastModified":"2026-08-05T08:16:40.183","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service.\n\nThis issue affects Apache Qpid Broker-J: through 10.0.1.\n\nUsers are recommended to upgrade to version 10.1.0, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Qpid Broker-J","defaultStatus":"unaffected","collectionURL":"https://repo.maven.apache.org/maven2","packageName":"org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol","versions":[{"version":"0","lessThanOrEqual":"10.0.1","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-674"}]}],"references":[{"url":"https://lists.apache.org/thread/djz1gnrk882vzjo8rykyf9bnywqbvwwr","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/15","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-68075","sourceIdentifier":"security@apache.org","published":"2026-08-05T07:16:39.090","lastModified":"2026-08-05T08:16:40.413","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service.\n\nThis issue affects Apache Qpid Broker-J: through 10.0.1.\n\nUsers are recommended to upgrade to version 10.1.0, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Qpid Broker-J","defaultStatus":"unaffected","collectionURL":"https://repo.maven.apache.org/maven2","packageName":"org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol","versions":[{"version":"0","lessThanOrEqual":"10.0.1","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"references":[{"url":"https://lists.apache.org/thread/lht725jgkowmyyjl039roffg6pyvbxz0","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/17","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-68077","sourceIdentifier":"security@apache.org","published":"2026-08-05T07:16:39.210","lastModified":"2026-08-05T08:16:40.530","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service.\n\nThis issue affects Apache Qpid Broker-J: through 10.0.1.\n\nUsers are recommended to upgrade to version 10.1.0, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Qpid Broker-J","defaultStatus":"unaffected","collectionURL":"https://repo.maven.apache.org/maven2","packageName":"org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol","versions":[{"version":"0","lessThanOrEqual":"10.0.1","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-606"}]}],"references":[{"url":"https://lists.apache.org/thread/gzc78gdrlw2711v8jzgmsto8bqvg28y8","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/18","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-68078","sourceIdentifier":"security@apache.org","published":"2026-08-05T07:16:39.327","lastModified":"2026-08-05T08:16:40.643","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.\n\nThis issue affects Apache Qpid Broker-J: through 10.0.1.\n\nUsers are recommended to upgrade to version 10.1.0, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Qpid Broker-J","defaultStatus":"unaffected","collectionURL":"https://repo.maven.apache.org/maven2","packageName":"org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol","versions":[{"version":"0","lessThanOrEqual":"10.0.1","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"references":[{"url":"https://lists.apache.org/thread/m8gs6pfp1fmbgwcjr8zsgn95hfh15f8o","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/19","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-68080","sourceIdentifier":"security@apache.org","published":"2026-08-05T07:16:39.443","lastModified":"2026-08-05T08:16:40.743","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.\n\nThis issue affects Apache Qpid Broker-J: through 10.0.1.\n\nUsers are recommended to upgrade to version 10.1.0, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Qpid Broker-J","defaultStatus":"unaffected","collectionURL":"https://repo.maven.apache.org/maven2","packageName":"org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol","versions":[{"version":"0","lessThanOrEqual":"10.0.1","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-406"}]}],"references":[{"url":"https://lists.apache.org/thread/tcnrv5nhmnsrzz92o4owxgycro6llt57","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/20","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-11454","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T08:16:28.770","lastModified":"2026-08-05T08:16:28.770","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.5.2 via the GET /wp-json/gh/v4/contacts/<id> REST endpoint. The endpoint's permission callback checks only the role-level view_contacts capability and read_single() returns the full contact record by sequential integer ID without the object-level view_contact ownership check applied elsewhere in the codebase. This makes it possible for authenticated attackers holding view_contacts but not view_others_contacts — notably Groundhogg's built-in Sales Rep role, designed to see only its own contacts — to read any contact record on the site, including PII, contact meta, owner IDs, the admin edit URL, and (for contacts linked to a WordPress user) that user's full capability set."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"trainingbusinesspros","product":"Groundhogg — CRM, Newsletters, and Marketing Automation","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"4.5.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-639"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.5.2/api/v4/base-object-api.php#L124","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.5.2/api/v4/contacts-api.php#L426","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.5.2/api/v4/contacts-api.php#L946","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.5.2/includes/main-roles.php#L163","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.5.2/includes/main-roles.php#L374","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.5.2/includes/main-roles.php#L43","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/groundhogg/tags/4.5.3/api/v4/contacts-api.php#L437","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?new=3569222%40groundhogg%2Ftags%2F4.5.3&old=3562726%40groundhogg%2Ftags%2F4.5.2","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/7fe3d251-4edf-4d94-a946-0aa918135784?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-11920","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T08:16:29.883","lastModified":"2026-08-05T08:16:29.883","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based SQL Injection via the 'order' parameter in all versions up to, and including, 5.7.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The affected admin page lacks nonce or CSRF protection on the GET request, meaning an unauthenticated attacker could exploit this vulnerability by tricking an authenticated administrator into issuing a crafted request. Additionally, the vulnerability is only triggered when the 'orderby' parameter is also present and non-empty alongside the 'order' parameter."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"beardev","product":"JoomSport – for Sports: Team & League, Football, Hockey & more","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"5.7.9","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-89"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/joomsport-sports-league-results-management/tags/5.7.8/includes/pages/joomsport-page-boxfields.php#L35","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/joomsport-sports-league-results-management/tags/5.7.8/includes/pages/joomsport-page-boxfields.php#L36","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3594276%40joomsport-sports-league-results-management%2Ftrunk%2Fincludes%2Fpages%2Fjoomsport-page-boxfields.php&old=3209054%40joomsport-sports-league-results-management%2Ftrunk%2Fincludes%2Fpages%2Fjoomsport-page-boxfields.php&sfp_email=&sfph_mail=","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ffc2fe31-9bc2-497a-a8f4-1bc4f93de5a2?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-11969","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T08:16:30.040","lastModified":"2026-08-05T08:16:30.040","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via 'curselrevs[]' Parameter in all versions up to, and including, 14.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"jgwhite33","product":"WP TripAdvisor Review Slider","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"14.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-89"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/wp-tripadvisor-review-slider/tags/14.2/admin/class-wp-tripadvisor-review-slider-admin.php#L599","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/wp-tripadvisor-review-slider/tags/14.2/admin/class-wp-tripadvisor-review-slider-admin.php#L671","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/wp-tripadvisor-review-slider/tags/14.2/includes/class-wp-tripadvisor-review-slider.php#L285","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/wp-tripadvisor-review-slider/tags/14.3/admin/class-wp-tripadvisor-review-slider-admin.php#L599","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/wp-tripadvisor-review-slider/tags/14.3/admin/class-wp-tripadvisor-review-slider-admin.php#L671","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/wp-tripadvisor-review-slider/tags/14.3/includes/class-wp-tripadvisor-review-slider.php#L285","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3570513%40wp-tripadvisor-review-slider%2Ftags%2F14.4%2Fadmin%2Fclass-wp-tripadvisor-review-slider-admin.php&old=3549944%40wp-tripadvisor-review-slider%2Ftags%2F14.3%2Fadmin%2Fclass-wp-tripadvisor-review-slider-admin.php&sfp_email=&sfph_mail=","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9bdfa6e8-0bf6-4ca5-b145-af66d99dbf6c?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-11977","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T08:16:30.217","lastModified":"2026-08-05T08:16:30.217","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars plugin for WordPress is vulnerable to generic SQL Injection via the 'wpma_metabox_authors_list' parameter in all versions up to, and including, 3.9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with author-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Exploitation is a two-step chain: an attacker first saves a crafted guest-author token via the wpma_metabox_authors_list parameter during post creation or editing, then triggers the injection when any admin user loads the post list screen at /wp-admin/edit.php, causing the injected SQL result to be rendered in the Authors column."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"afthemes","product":"WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"3.9.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-89"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/wp-post-author/trunk/includes/multi-authors/wpa-multi-authors.php#L110","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/wp-post-author/trunk/includes/multi-authors/wpa-multi-authors.php#L231","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/wp-post-author/trunk/includes/multi-authors/wpa-multi-authors.php#L312","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3577603%40wp-post-author%2Ftrunk%2Fincludes%2Fmulti-authors%2Fwpa-multi-authors.php&old=3166002%40wp-post-author%2Ftrunk%2Fincludes%2Fmulti-authors%2Fwpa-multi-authors.php&sfp_email=&sfph_mail=","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ca5cb925-6f95-4f81-92d0-5f3c8e5f7d59?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-12000","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T08:16:30.367","lastModified":"2026-08-05T08:16:30.367","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Page and Post Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 1.4.0 via the WordPress core REST endpoints /wp-json/wp/v2/pages, /wp-json/wp/v2/pages/<id>, /wp-json/wp/v2/posts, and /wp-json/wp/v2/posts/<id>. This is due to the plugin's REST guards — papr_restrict_page_post_rest_api() and the the_posts filter registered by papr_filter_posts() — sourcing their restricted-ID list exclusively from papr_get_restricted_posts_id(), which only reads the per-page metabox options papr_allowed_redirect_for_pages and papr_allowed_redirect_for_posts and never consults the two global toggles papr_access_for_only_loggedin and papr_access_for_only_loggedin_posts that the plugin's own UI describes as 'Make all Pages Private' / 'Make all Posts Private'. This makes it possible for unauthenticated attackers to read the full rendered content of every published page and post on sites configured with the documented global toggles, bypassing the security boundary enforced on the frontend by papr_restrict_logged_in_users()."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"cyberlord92","product":"Page and Post Restriction","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.4.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/page-and-post-restriction/tags/1.4.0/page-and-post-restriction.php#L484","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/page-and-post-restriction/tags/1.4.0/page-and-post-restriction.php#L69","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/page-and-post-restriction/tags/1.4.0/page-and-post-restriction.php#L94","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/page-and-post-restriction/tags/1.4.0/page-restriction-utility.php#L701","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/page-and-post-restriction/tags/1.4.1/page-and-post-restriction.php#L484","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/page-and-post-restriction/tags/1.4.1/page-and-post-restriction.php#L69","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/page-and-post-restriction/tags/1.4.1/page-and-post-restriction.php#L94","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/page-and-post-restriction/tags/1.4.1/page-restriction-utility.php#L701","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?new=3578420%40page-and-post-restriction%2Ftags%2F1.4.2&old=3560846%40page-and-post-restriction%2Ftags%2F1.4.1","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f01302aa-00ef-440a-9c37-4fde6bb4bb4d?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-15281","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T08:16:30.520","lastModified":"2026-08-05T08:16:30.520","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The User Access Manager plugin for WordPress is vulnerable to Second-Order SQL Injection via the 'id' parameter of the wp_ajax_save-attachment-compat AJAX action in versions up to, and including, 2.3.12. This is due to insufficient validation on the objectId value stored in the saveAjaxAttachmentData() function and subsequent unparameterized concatenation in the addQueryExcludedPostFilter() function — the stored value is later retrieved from the database and used as an array key, then directly imploded into a SQL NOT IN() clause without integer casting or prepared statements. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"gm_alex","product":"User Access Manager","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.3.12","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-89"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/user-access-manager/tags/2.3.12/src/Controller/Backend/PostObjectController.php#L103","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/user-access-manager/tags/2.3.12/src/Controller/Frontend/PostController.php#L275","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/user-access-manager/tags/2.3.12/src/UserGroup/AbstractUserGroup.php#L147","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/user-access-manager/tags/2.3.12/src/UserGroup/AbstractUserGroup.php#L253","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3607011%40user-access-manager%2Ftrunk%2Fsrc%2FController%2FFrontend%2FPostController.php&old=3447009%40user-access-manager%2Ftrunk%2Fsrc%2FController%2FFrontend%2FPostController.php&sfp_email=&sfph_mail=","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8ebfc52b-278c-49d5-9226-d28a59335d46?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-17505","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T08:16:31.977","lastModified":"2026-08-05T08:16:31.977","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Translate Multilingual sites – TranslatePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in versions up to, and including, 3.2.5. This is due to the translate_page() function unconditionally replacing the plugin's internal #!trpst# and #!trpen# marker tokens with literal angle brackets across the entire HTML page output after WordPress has already sanitized and escaped user input — allowing the attacker to bypass WordPress's normal HTML escaping by using these tokens, which are not HTML special characters, in the search query. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a specially crafted link."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"cozmoslabs","product":"TranslatePress – Translate Multilingual sites with AI Translation","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"3.2.5","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.2.5/class-translate-press.php#L443","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.2.5/includes/class-search.php#L150","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.2.5/includes/class-translation-render.php#L538","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3624567%40translatepress-multilingual%2Ftrunk%2Fincludes%2Fclass-translation-render.php&old=3617108","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/81d28e90-252f-4b5f-a55b-8cb96292538e?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-17532","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T08:16:32.123","lastModified":"2026-08-05T08:16:32.123","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Seraphinite Accelerator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'seraph_accel_prep' parameter in versions up to, and including, 2.29.15. This is due to the CacheExtractPreparePageParams() function using PHP's loose inequality operator (!=) to compare the expected HMAC string against the JSON-decoded 'nonce' value — supplying the JSON boolean true causes any non-empty HMAC string to compare as loosely equal, bypassing the signature check — combined with insufficient output escaping in the _CbContentFinishSkip() function, which concatenates the attacker-controlled 'selfTest' field directly into the HTML response body. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a specially crafted link."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"seraphinitesoft","product":"Seraphinite Accelerator","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.29.18","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/seraphinite-accelerator/tags/2.29.15/cache.php#L76","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/seraphinite-accelerator/tags/2.29.15/cache_ex.php#L838","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/seraphinite-accelerator/tags/2.29.15/common.php#L6036","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/seraphinite-accelerator/tags/2.29.18/cache.php#L76","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/seraphinite-accelerator/tags/2.29.18/cache_ex.php#L838","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/seraphinite-accelerator/tags/2.29.18/common.php#L6036","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3624461%40seraphinite-accelerator%2Ftrunk%2Fcache_ex.php&old=3619618%40seraphinite-accelerator%2Ftrunk%2Fcache_ex.php&sfp_email=&sfph_mail=","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3624461%40seraphinite-accelerator%2Ftrunk%2Fcommon.php&old=3619618%40seraphinite-accelerator%2Ftrunk%2Fcommon.php&sfp_email=&sfph_mail=","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5aeea62b-bd6c-4fe2-8c0f-8c9919688e87?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-18881","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T08:16:32.750","lastModified":"2026-08-05T08:16:32.750","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to blind SQL Injection via the `filter_data[comment_count]` parameter of the public `tableon_get_table_data` AJAX action in all versions up to, and including, 1.0.5.1. This is due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query — the value is split on `:` and both halves are interpolated directly into a `posts_where` SQL clause without `intval()` casting or `$wpdb->prepare()`. This makes it possible for unauthenticated attackers to append additional SQL queries into the already-existing query that can be used to extract sensitive information from the database (researcher demonstrated extraction of database(), wp_users.user_login, and wp_users.user_pass)."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"realmag777","product":"TableOn – WordPress Posts Table Filterable","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.0.5.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-89"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/posts-table-filterable/tags/1.0.6/profiles/default/default.php#L765","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/posts-table-filterable/trunk/index.php#L76","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/posts-table-filterable/trunk/profiles/default/default.php#L765","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3520311%40posts-table-filterable%2Ftrunk&new=3520313%40posts-table-filterable%2Ftrunk","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ac53ade6-b654-4169-a50a-96b3de3d108d?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-4431","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T08:16:33.457","lastModified":"2026-08-05T08:16:33.457","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `create_post()` function in all versions up to, and including, 2.3.0. This is due to the `rbsm_submit_post` AJAX action being registered for unauthenticated users via `wp_ajax_nopriv_rbsm_submit_post` without any authorization checks when a `postId` parameter is supplied. This makes it possible for unauthenticated attackers to modify the title, content, excerpt, categories, and tags of arbitrary posts, as well as change the post status to draft (effectively unpublishing them) via the 'postId' parameter."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"themeruby","product":"Easy Post Submission – Frontend Posting, Guest Publishing & Submit Content for WordPress","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.3.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.2}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/easy-post-submission/tags/2.2.0/includes/client-ajax-handler.php#L1157","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/easy-post-submission/tags/2.2.0/includes/client-ajax-handler.php#L38","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/easy-post-submission/tags/2.2.0/includes/client-ajax-handler.php#L974","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3488045%40easy-post-submission%2Ftrunk&old=3427523%40easy-post-submission%2Ftrunk","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/15494ccf-7c9d-4566-9e80-2da94172a3dd?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-54416","sourceIdentifier":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","published":"2026-08-05T08:16:33.637","lastModified":"2026-08-05T08:16:33.637","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Pluck CMS through 4.7.21 restricts dangerous file uploads in its admin file-management feature using a fixed blacklist in data/inc/files.php ('.php','php3','php4','php5','php6','php7','phtml','.phtm','.pht','.ph3','.ph4','.ph5','.asp','.cgi','.phar'), checked against the last 4-5 characters of the filename. The blacklist omits the '.php8' extension. An authenticated administrator can upload a file named e.g. shell.php8, which is stored unmodified and, on servers running PHP 8.x, is executed as PHP by the web server, resulting in remote code execution."}],"affected":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","affectedData":[{"vendor":"pluck-cms","product":"Pluck CMS","defaultStatus":"unknown","programFiles":["data/inc/files.php"],"versions":[{"version":"0","lessThanOrEqual":"4.7.21","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9}]},"weaknesses":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","description":[{"lang":"en","value":"CWE-434"}]}],"references":[{"url":"https://github.com/pluck-cms/pluck","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}]}},{"cve":{"id":"CVE-2026-55739","sourceIdentifier":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","published":"2026-08-05T08:16:33.903","lastModified":"2026-08-05T08:16:33.903","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Crater isolates data per company_id, and its Invoice/Estimate/Payment/Expense policies enforce both a Bouncer ability check and $user->hasCompany($model->company_id). CustomerPolicy's view/update/delete methods omit the company-ownership check entirely, checking only the blanket ability. Route-model-bound customer lookups and the bulk Customer::deleteCustomers() method are similarly unscoped (self::find($id) with no company filter). Any authenticated user of one company can read, reassign (steal), or delete another company's customer records, with deletion cascading to that customer's invoices and payments."}],"affected":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","affectedData":[{"vendor":"crater-invoice","product":"Crater","defaultStatus":"unknown","programFiles":["app/Policies/CustomerPolicy.php","app/Models/Customer.php"],"versions":[{"version":"6.0.6","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","baseScore":8.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":5.5}]},"weaknesses":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]}],"references":[{"url":"https://github.com/crater-invoice/crater","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}]}},{"cve":{"id":"CVE-2026-55747","sourceIdentifier":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","published":"2026-08-05T08:16:34.037","lastModified":"2026-08-05T08:16:34.037","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The pocketflow-coding-agent cookbook example in The-Pocket/PocketFlow implements a `_path(workdir, p)` helper as a thin os.path.join(workdir, p) wrapper with no canonicalization or containment check, used unguarded by the ReadFile, ListFiles, PatchRead, and PatchApply file-access tools. Because os.path.join returns an absolute `p` unchanged (ignoring workdir) and does not resolve '../' sequences, an agent invocation whose file-tool arguments include an absolute path or a traversal sequence can read or write files outside the configured working directory. Severity reflects that this affects an illustrative cookbook example rather than a core library API; applications that copy this pattern into production are affected."}],"affected":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","affectedData":[{"vendor":"The-Pocket","product":"PocketFlow (pocketflow-coding-agent cookbook example)","defaultStatus":"unknown","programFiles":["cookbook/pocketflow-coding-agent/nodes.py"],"versions":[{"version":"0","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":5.2}]},"weaknesses":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]}],"references":[{"url":"https://github.com/The-Pocket/PocketFlow","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}]}},{"cve":{"id":"CVE-2026-55996","sourceIdentifier":"meissner@suse.de","published":"2026-08-05T08:16:34.173","lastModified":"2026-08-05T08:16:34.173","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A denial-of-service vulnerability was identified in multiple TLS listeners in Rancher. Both the cattle-cluster-agent component running in downstream clusters and the Rancher server itself use the dynamiclistener library to serve TLS traffic. Without an effective CN filter configured, dynamiclistener automatically appended to each serving certificate any hostname presented via Server Name Indication (SNI) in incoming TLS requests.\n\n\n\nAn unauthenticated attacker with network access within the affected cluster could send a large number of TLS requests with distinct hostnames, causing the serving certificate to accumulate an unbounded number of Subject Alternative Names (SANs). Eventually, the certificate grows large enough that TLS handshakes fail with an excessive message size error, causing a denial of service on the affected listeners."}],"affected":[{"source":"meissner@suse.de","affectedData":[{"vendor":"SUSE","product":"Rancher","defaultStatus":"unaffected","packageName":"Rancher","versions":[{"version":"2.11.0","lessThan":"2.11.16","versionType":"semver","status":"affected"},{"version":"2.12.0","lessThan":"2.12.12","versionType":"semver","status":"affected"},{"version":"2.13.0","lessThan":"2.13.8","versionType":"semver","status":"affected"},{"version":"2.14.0","lessThan":"2.14.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"meissner@suse.de","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4}]},"references":[{"url":"https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-55996","source":"meissner@suse.de"},{"url":"https://github.com/rancher/rancher/security/advisories/GHSA-9jxv-832x-45q9","source":"meissner@suse.de"}]}},{"cve":{"id":"CVE-2026-55997","sourceIdentifier":"meissner@suse.de","published":"2026-08-05T08:16:34.330","lastModified":"2026-08-05T08:16:34.330","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens were stored and exposed in plaintext with no expiration, so a malicious user could obtain one either through the Rancher API, etcd, stored automation, or direct file access on a node, and could use it at any time to register a rogue node into the cluster."}],"affected":[{"source":"meissner@suse.de","affectedData":[{"vendor":"rancher","product":"rancher","defaultStatus":"unaffected","packageName":"github.com/rancher/rancher","versions":[{"version":"2.14.0","lessThan":"2.14.4","versionType":"semver","status":"affected"},{"version":"2.13.0","lessThan":"2.13.8","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"meissner@suse.de","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.0,"impactScore":6.0}]},"weaknesses":[{"source":"meissner@suse.de","type":"Primary","description":[{"lang":"en","value":"CWE-312"}]}],"references":[{"url":"https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-55997","source":"meissner@suse.de"},{"url":"https://github.com/rancher/rancher/security/advisories/GHSA-7r53-jvhg-9jq4","source":"meissner@suse.de"}]}},{"cve":{"id":"CVE-2026-55998","sourceIdentifier":"meissner@suse.de","published":"2026-08-05T08:16:34.460","lastModified":"2026-08-05T08:16:34.460","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The endpoint /v3/import/{token}_{clusterId}.yaml retrieves the cluster object before validating the token. When a valid cluster ID references a cluster that has private registry secrets configured, a nil pointer dereference in pkg/systemtemplate/private_registry.go causes the request to return HTTP 502 Bad Gateway. For cluster IDs that do not exist, the endpoint returns HTTP 200. This observable difference in response codes constitutes a reliable enumeration oracle."}],"affected":[{"source":"meissner@suse.de","affectedData":[{"vendor":"SUSE","product":"Rancher","defaultStatus":"unaffected","packageName":"Rancher","versions":[{"version":"2.14.0","lessThan":"2.14.4","versionType":"semver","status":"affected"},{"version":"2.13.0","lessThan":"2.13.8","versionType":"semver","status":"affected"},{"version":"2.12.0","lessThan":"2.12.12","versionType":"semver","status":"affected"},{"version":"2.11.0","lessThan":"2.11.16","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"meissner@suse.de","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}]},"weaknesses":[{"source":"meissner@suse.de","type":"Primary","description":[{"lang":"en","value":"CWE-204"}]}],"references":[{"url":"https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-55998","source":"meissner@suse.de"},{"url":"https://github.com/rancher/rancher/security/advisories/GHSA-23h9-rr79-r3gh","source":"meissner@suse.de"}]}},{"cve":{"id":"CVE-2026-59675","sourceIdentifier":"meissner@suse.de","published":"2026-08-05T08:16:34.593","lastModified":"2026-08-05T08:16:34.593","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"When API audit logging is enabled, the middleware reads the entire HTTP request body into memory without enforcing a size limit on login endpoints. Because the audit middleware is positioned earlier in the handler chain than Rancher's APIBodyLimitingHandler, the body-size cap (default 1 MiB) is bypassed for requests that pass through the audit copyReqBody path. An unauthenticated attacker can send arbitrarily large request bodies to the public login endpoints, causing the Rancher Manager server process to allocate memory proportional to the supplied body size. With just a few concurrent connections, this can exhaust available memory and terminate the Rancher Manager plane process, making the Rancher API and UI unavailable and interrupting management of all downstream clusters."}],"affected":[{"source":"meissner@suse.de","affectedData":[{"vendor":"SUSE","product":"Rancher","defaultStatus":"unaffected","packageName":"Rancher","versions":[{"version":"2.14.0","lessThan":"2.14.4","versionType":"semver","status":"affected"},{"version":"2.13.0","lessThan":"2.13.8","versionType":"semver","status":"affected"},{"version":"2.12.0","lessThan":"2.12.12","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"meissner@suse.de","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}]},"weaknesses":[{"source":"meissner@suse.de","type":"Primary","description":[{"lang":"en","value":"CWE-770"}]}],"references":[{"url":"https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-59675","source":"meissner@suse.de"},{"url":"https://github.com/rancher/rancher/security/advisories/GHSA-g4f6-44g4-23xm","source":"meissner@suse.de"}]}},{"cve":{"id":"CVE-2026-5108","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T08:16:34.730","lastModified":"2026-08-05T08:16:34.730","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Super Progressive Web Apps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `superpwa_settings[offline_message_txt]` setting in all versions up to, and including, 2.2.43. This is due to insufficient input sanitization and output escaping. The offline message value is stored without sanitization, passed to the frontend via `wp_localize_script()` without escaping, and rendered using `innerHTML` in the JavaScript snackbar component. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user triggers the offline snackbar."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"superpwa","product":"Super Progressive Web Apps","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.2.43","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N","baseScore":4.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.3,"impactScore":2.7}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/super-progressive-web-apps/tags/2.2.41/public/js/register-sw.js#L177","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/super-progressive-web-apps/tags/2.2.41/public/sw.php#L386","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&new=3506063%40super-progressive-web-apps%2Ftrunk&old=3494263%40super-progressive-web-apps%2Ftrunk","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0332e106-1f97-4c52-b084-ea15d31dee72?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-5116","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T08:16:34.870","lastModified":"2026-08-05T08:16:34.870","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.0.5. This is due to insufficient output escaping on form shortcode keys displayed in the admin \"Scan Forms for Post Meta and User Data Keys\" page. This makes it possible for authenticated attackers, with Editor-level access and above, to inject arbitrary web scripts that execute when an Administrator runs the scan feature."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"sevenspark","product":"DTX – Dynamic Text Extension for Contact Form 7","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"5.0.5","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N","baseScore":4.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.3,"impactScore":2.7}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/contact-form-7-dynamic-text-extension/tags/5.0.4/includes/admin/settings.php#L544","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/contact-form-7-dynamic-text-extension/tags/5.0.4/includes/admin/settings.php#L559","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?new=3561908%40contact-form-7-dynamic-text-extension%2Ftags%2F5.0.6&old=3463604%40contact-form-7-dynamic-text-extension%2Ftags%2F5.0.5","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/759add85-3d72-46d5-a973-dd8dcfb9f336?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-5581","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T08:16:35.007","lastModified":"2026-08-05T08:16:35.007","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary media deletion in all versions up to, and including, 1.1.8. This is due to missing capability checks in the `plupload_ajax_delete_file()` function, which is registered via `wp_ajax_nopriv_gfmu_delete_file`. The nonce intended for CSRF protection is exposed on any public-facing page containing a multi-uploader form field via the `GFMU_options` JavaScript object. This makes it possible for unauthenticated attackers to permanently delete any WordPress media attachment by supplying its attachment ID, potentially leading to complete media library destruction."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"sh1zen","product":"Multi Uploader for Gravity Forms","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.1.8","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.2}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/gf-multi-uploader/tags/1.1.8/GFMUAddon.class.php#L131","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/gf-multi-uploader/tags/1.1.8/inc/GFMUHandlePluploader.class.php#L66","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/gf-multi-uploader/trunk/GFMUAddon.class.php#L131","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/gf-multi-uploader/trunk/inc/GFMUHandlePluploader.class.php#L66","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3501985%40gf-multi-uploader%2Ftrunk&old=3421317%40gf-multi-uploader%2Ftrunk&sfp_email=&sfph_mail=","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/16dca898-1a98-4e0b-8f48-dc01ba2dc4e6?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-5651","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T08:16:35.150","lastModified":"2026-08-05T08:16:35.150","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Askeet plugin for WordPress is vulnerable to SQL Injection via the 'sql_query' parameter in multiple AJAX actions (askeet_execute_sql_query, askeet_export_all_results) in all versions up to, and including, 3.0. This is due to the askeet_is_safe_query() filter being bypassable using MySQL conditional comments (e.g., /*!UNION*/). The filter strips regular block comments before checking for forbidden SQL keywords, but MySQL interprets conditional comments as executable code. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"2wstechnologies","product":"Askeet — Talk to Your WooCommerce Data","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"3.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-89"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/askeet/tags/2.5/askeet.php#L563","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/askeet/tags/2.5/askeet.php#L767","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/askeet/trunk/askeet.php#L767","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?new=3525593%40askeet%2Ftrunk&old=3521172%40askeet%2Ftrunk","source":"security@wordfence.com"},{"url":"https://wordpress.org/plugins/askeet/","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b95af878-f324-44ae-a4bf-0c1e994bb3c1?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-61483","sourceIdentifier":"security@apache.org","published":"2026-08-05T08:16:35.330","lastModified":"2026-08-05T08:16:35.330","vulnStatus":"Received","cveTags":[{"sourceIdentifier":"security@apache.org","tags":["unsupported-when-assigned"]}],"descriptions":[{"lang":"en","value":"** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy.\n\nThis issue affects Apache Lucy: all versions.\n\nAs this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.\n\nNOTE: This vulnerability only affects products that are no longer supported by the maintainer."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Lucy","defaultStatus":"unaffected","collectionURL":"https://cpan.org/modules","packageName":"Lucy","packageURL":"pkg:cpan/Lucy","versions":[{"version":"0","lessThanOrEqual":"*","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Primary","description":[{"lang":"en","value":"CWE-674"}]}],"references":[{"url":"https://lists.apache.org/thread/ltp8320c0nsy45bpzm8342jd7yj05z1h","source":"security@apache.org"}]}},{"cve":{"id":"CVE-2026-61484","sourceIdentifier":"security@apache.org","published":"2026-08-05T08:16:35.487","lastModified":"2026-08-05T08:16:35.487","vulnStatus":"Received","cveTags":[{"sourceIdentifier":"security@apache.org","tags":["unsupported-when-assigned"]}],"descriptions":[{"lang":"en","value":"** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy.\n\nThis issue affects Apache Lucy: all versions.\n\nAs this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.\n\nNOTE: This vulnerability only affects products that are no longer supported by the maintainer."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Lucy","defaultStatus":"unaffected","collectionURL":"https://cpan.org/modules","packageName":"Lucy","packageURL":"pkg:cpan/Lucy","versions":[{"version":"0","lessThan":"*","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Primary","description":[{"lang":"en","value":"CWE-502"}]}],"references":[{"url":"https://lists.apache.org/thread/942t3pwgz2nrhnklrtyt5zr7g4wqc9cb","source":"security@apache.org"}]}},{"cve":{"id":"CVE-2026-61485","sourceIdentifier":"security@apache.org","published":"2026-08-05T08:16:35.610","lastModified":"2026-08-05T08:16:35.610","vulnStatus":"Received","cveTags":[{"sourceIdentifier":"security@apache.org","tags":["unsupported-when-assigned"]}],"descriptions":[{"lang":"en","value":"** UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with Excessive Size Value vulnerability in Apache Lucy.\n\nThis issue affects Apache Lucy: all versions.\n\nAs this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.\n\nNOTE: This vulnerability only affects products that are no longer supported by the maintainer."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Lucy","defaultStatus":"unaffected","collectionURL":"https://cpan.org/modules","packageName":"Lucy","packageURL":"pkg:cpan/Lucy","versions":[{"version":"0","lessThanOrEqual":"*","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Primary","description":[{"lang":"en","value":"CWE-789"}]}],"references":[{"url":"https://lists.apache.org/thread/4q9rfscp3tkjr3kt7lsg97szhmydl23s","source":"security@apache.org"}]}},{"cve":{"id":"CVE-2026-61486","sourceIdentifier":"security@apache.org","published":"2026-08-05T08:16:35.733","lastModified":"2026-08-05T08:16:35.733","vulnStatus":"Received","cveTags":[{"sourceIdentifier":"security@apache.org","tags":["unsupported-when-assigned"]}],"descriptions":[{"lang":"en","value":"** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy.\n\nThis issue affects Apache Lucy: all versions.\n\nAs this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.\n\nNOTE: This vulnerability only affects products that are no longer supported by the maintainer."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Lucy","defaultStatus":"unaffected","collectionURL":"https://cpan.org/modules","packageName":"Lucy","packageURL":"pkg:cpan/Lucy","versions":[{"version":"0","lessThanOrEqual":"*","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Primary","description":[{"lang":"en","value":"CWE-121"}]}],"references":[{"url":"https://lists.apache.org/thread/z88yv1z19ppsd4td4nqtg7q72fvqh01b","source":"security@apache.org"}]}},{"cve":{"id":"CVE-2026-64566","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-05T08:16:36.140","lastModified":"2026-08-05T08:16:36.140","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags()\n\nWhen iptfs_skb_add_frags() copies frag references from the source\nfrag walk into a new SKB, it increments the page reference count via\n__skb_frag_ref() but does not propagate SKBFL_SHARED_FRAG to the\ndestination SKB's skb_shinfo->flags.\n\nIf the source SKB carries shared frags (e.g. from a page-pool backed\nreceive path), the new inner SKB will appear to ESP as having privately\nowned frags.  A subsequent esp_input() call for a nested transport-mode\nSA then takes the no-COW fast path and decrypts in place, writing over\npages that are still referenced by the outer IPTFS SKB.  This causes\nkernel-visible memory corruption and can trigger a panic.\n\nAll other frag-transfer helpers in the kernel (skb_try_coalesce,\nskb_gro_receive, __pskb_copy_fclone, skb_shift, skb_segment) correctly\npropagate SKBFL_SHARED_FRAG; align iptfs_skb_add_frags() with this\nconvention by setting the flag inside the loop immediately after\n__skb_frag_ref() and nr_frags++, so every exit path that attaches a frag\nunconditionally propagates SKBFL_SHARED_FRAG."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/xfrm/xfrm_iptfs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5f2b6a9095743a6bf1f34c43c4fe78fa8bdf5ad7","lessThan":"d8aaf06b29f5a0b6186cf68d21c7d63678ee3891","versionType":"git","status":"affected"},{"version":"5f2b6a9095743a6bf1f34c43c4fe78fa8bdf5ad7","lessThan":"ffd64e0717efd83fbf3396ab4e5ac6d795dac4d0","versionType":"git","status":"affected"},{"version":"5f2b6a9095743a6bf1f34c43c4fe78fa8bdf5ad7","lessThan":"430ea57d6daf765e88f90046afbfd1e071cb7200","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/xfrm/xfrm_iptfs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/430ea57d6daf765e88f90046afbfd1e071cb7200","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d8aaf06b29f5a0b6186cf68d21c7d63678ee3891","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ffd64e0717efd83fbf3396ab4e5ac6d795dac4d0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64567","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-05T08:16:36.277","lastModified":"2026-08-05T08:16:36.277","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: reject free space cache with more entries than pages\n\nWhen loading a v1 free space cache, __load_free_space_cache() takes\nnum_entries and num_bitmaps straight from the on-disk\nbtrfs_free_space_header. That header is stored in the tree_root under a key\nwith type 0, which the tree-checker has no case for, so neither count is\nvalidated before the load trusts it.\n\nThe load loops num_entries times and maps the next page whenever the current\none runs out, going through io_ctl_check_crc() -> io_ctl_map_page(), which\ndoes io_ctl->pages[io_ctl->index++]. But pages[] is allocated in\nio_ctl_init() from the cache inode's i_size, not from num_entries:\n\n\tnum_pages = DIV_ROUND_UP(i_size_read(inode), PAGE_SIZE);\n\tio_ctl->pages = kcalloc(num_pages, sizeof(struct page *), GFP_NOFS);\n\nSo if num_entries claims more records than the pages can hold, io_ctl->index\nruns off the end of pages[]. The write side never hits this because\nio_ctl_add_entry() and io_ctl_add_bitmap() both stop once\nio_ctl->index >= io_ctl->num_pages; the read side just never had the same\ncheck.\n\nTo trigger it, take a clean cache (num_entries = <N> here), set num_entries\nin the header to 0x10000, and fix up the leaf checksum so it still passes\nthe tree-checker. The cache inode has i_size = 65536, so num_pages is 16 and\npages[] is a 16-pointer (kmalloc-128) array. The load now tries to read\n65536 entries, io_ctl->index walks up to 16, and pages[16] is read past the\narray:\n\n  BUG: KASAN: slab-out-of-bounds in io_ctl_check_crc (fs/btrfs/free-space-cache.c:420 fs/btrfs/free-space-cache.c:565)\n  Read of size 8 at addr ffff88800c833a80 by task kworker/u8:3/58\n   io_ctl_check_crc (fs/btrfs/free-space-cache.c:420 fs/btrfs/free-space-cache.c:565)\n   __load_free_space_cache (fs/btrfs/free-space-cache.c:655 fs/btrfs/free-space-cache.c:820)\n   load_free_space_cache (fs/btrfs/free-space-cache.c:1017)\n   caching_thread (fs/btrfs/block-group.c:880)\n   btrfs_work_helper (fs/btrfs/async-thread.c:312)\n   process_one_work\n   worker_thread\n   kthread\n   ret_from_fork\n\nfree-space-cache.c:420 is io_ctl_map_page(), inlined into io_ctl_check_crc()\nat line 565, which is why that is the frame KASAN names. The out-of-bounds\nslot is then treated as a struct page and handed to crc32c(), so the bad\nread turns into a GP fault.\n\nAdd the missing check to io_ctl_check_crc(), which is where both the entry\nloop and the bitmap loop end up. When num_entries is too large the load now\nfails like any corrupt cache: __load_free_space_cache() drops it and rebuilds\nthe free space from the extent tree, so a valid cache is never rejected."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/btrfs/free-space-cache.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5b0e95bf607ddd59b39f52d3d55e6581c817b530","lessThan":"33878ba25e2638bc0c61623d7a05c9ca2b74c039","versionType":"git","status":"affected"},{"version":"5b0e95bf607ddd59b39f52d3d55e6581c817b530","lessThan":"404a0b986e0b6e79738fdf1f0ebbbc43b9acd2a2","versionType":"git","status":"affected"},{"version":"5b0e95bf607ddd59b39f52d3d55e6581c817b530","lessThan":"5e1b2ca6b34939e70fb0785e8222b53cf060016f","versionType":"git","status":"affected"},{"version":"5b0e95bf607ddd59b39f52d3d55e6581c817b530","lessThan":"f9fef131fa3f59b857217f522fa5ea430d1b707c","versionType":"git","status":"affected"},{"version":"5b0e95bf607ddd59b39f52d3d55e6581c817b530","lessThan":"a2d8d5647ed854e38f941741aea45b9eb15a6350","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/btrfs/free-space-cache.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.2","status":"affected"},{"version":"0","lessThan":"3.2","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/33878ba25e2638bc0c61623d7a05c9ca2b74c039","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/404a0b986e0b6e79738fdf1f0ebbbc43b9acd2a2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5e1b2ca6b34939e70fb0785e8222b53cf060016f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a2d8d5647ed854e38f941741aea45b9eb15a6350","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f9fef131fa3f59b857217f522fa5ea430d1b707c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64568","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-05T08:16:36.423","lastModified":"2026-08-05T08:16:36.423","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure\n\nieee80211_set_unsol_bcast_probe_resp() calls kfree_rcu() on the old\ntemplate before allocating the replacement. If the kzalloc() then fails,\nit returns -ENOMEM while link->u.ap.unsol_bcast_probe_resp still points\nat the object already queued for freeing. A later update or AP teardown\nre-queues that same rcu_head; the second free is caught by KASAN when the\nRCU sheaf is processed in softirq:\n\n  BUG: KASAN: double-free in rcu_free_sheaf (mm/slub.c:5850)\n  Free of addr ffff88800d06f300 by task exploit/145\n   ...\n   __rcu_free_sheaf_prepare (mm/slub.c:2634 mm/slub.c:2940)\n   rcu_free_sheaf (mm/slub.c:5850)\n   rcu_core (kernel/rcu/tree.c:2617 kernel/rcu/tree.c:2869)\n   handle_softirqs (kernel/softirq.c:622)\n  The buggy address belongs to the cache kmalloc-128 of size 128\n\nQueue the old object for kfree_rcu() only after the new one is published,\nmatching ieee80211_set_probe_resp() and ieee80211_set_s1g_short_beacon()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/mac80211/cfg.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3b1c256eb4aedfc71dd97d5951ccff824b41d628","lessThan":"ca27a81cd77b698e5eb586a011bee6800c7ee4bd","versionType":"git","status":"affected"},{"version":"3b1c256eb4aedfc71dd97d5951ccff824b41d628","lessThan":"d62b55b7c7dc62887d7fd5648fb38f0bfaef53ae","versionType":"git","status":"affected"},{"version":"3b1c256eb4aedfc71dd97d5951ccff824b41d628","lessThan":"0ace76e410d7f7d813b605825a3e593a79c3958f","versionType":"git","status":"affected"},{"version":"3b1c256eb4aedfc71dd97d5951ccff824b41d628","lessThan":"1d067abcd37062426c59ec73dbc4e87a63f33fea","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/mac80211/cfg.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.7","status":"affected"},{"version":"0","lessThan":"6.7","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0ace76e410d7f7d813b605825a3e593a79c3958f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1d067abcd37062426c59ec73dbc4e87a63f33fea","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ca27a81cd77b698e5eb586a011bee6800c7ee4bd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d62b55b7c7dc62887d7fd5648fb38f0bfaef53ae","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64569","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-05T08:16:36.547","lastModified":"2026-08-05T08:16:36.547","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n\n\nOn CONFIG_INET=n builds, mpls_valid_fib_dump_req() walks the parsed\nattribute table itself instead of calling ip_valid_fib_dump_req(). The\nRTA_OIF arm passes tb[RTA_OIF] to nla_get_u32() without checking it is\npresent, so an RTM_GETROUTE dump for AF_MPLS with strict checking and no\nRTA_OIF hits a NULL dereference.\n\nRTM_GETROUTE is RTNL_KIND_GET, which rtnetlink_rcv_msg() permits without\nCAP_NET_ADMIN, so an unprivileged user can trigger it.\n\n  Oops: general protection fault, probably for non-canonical address\n        0xdffffc0000000000: 0000 [#1] SMP KASAN NOPTI\n  KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]\n  RIP: 0010:mpls_valid_fib_dump_req (net/mpls/af_mpls.c:2189)\n  Call Trace:\n   mpls_dump_routes (net/mpls/af_mpls.c:2236)\n   netlink_dump (net/netlink/af_netlink.c:2331)\n   __netlink_dump_start (net/netlink/af_netlink.c:2446)\n   rtnetlink_rcv_msg (net/core/rtnetlink.c:7033)\n   netlink_rcv_skb (net/netlink/af_netlink.c:2556)\n   netlink_unicast (net/netlink/af_netlink.c:1345)\n   netlink_sendmsg (net/netlink/af_netlink.c:1900)\n   __sock_sendmsg (net/socket.c:790)\n   ____sys_sendmsg (net/socket.c:2684)\n   ___sys_sendmsg (net/socket.c:2738)\n   __sys_sendmsg (net/socket.c:2770)\n   do_syscall_64 (arch/x86/entry/syscall_64.c:94)\n   entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\n\nSkip unset attributes, as ip_valid_fib_dump_req() does."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/mpls/af_mpls.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"196cfebf897266c3450519e916bab9daff74e52c","lessThan":"d6eee7cd078aaf9dd75efc801f6c9b608a37cd71","versionType":"git","status":"affected"},{"version":"196cfebf897266c3450519e916bab9daff74e52c","lessThan":"ad6284ced6a15e4abd57ca4d0793b7bd15ca52ce","versionType":"git","status":"affected"},{"version":"196cfebf897266c3450519e916bab9daff74e52c","lessThan":"5f6e7b32bd1fbde10fd31a4143260735ea535b8a","versionType":"git","status":"affected"},{"version":"196cfebf897266c3450519e916bab9daff74e52c","lessThan":"06db79411a280707c7e4bf4b221ff4e664b51502","versionType":"git","status":"affected"},{"version":"196cfebf897266c3450519e916bab9daff74e52c","lessThan":"56d96fededd61192cd7cc8d2b0f36adfd59036c3","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/mpls/af_mpls.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.20","status":"affected"},{"version":"0","lessThan":"4.20","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/06db79411a280707c7e4bf4b221ff4e664b51502","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/56d96fededd61192cd7cc8d2b0f36adfd59036c3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5f6e7b32bd1fbde10fd31a4143260735ea535b8a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ad6284ced6a15e4abd57ca4d0793b7bd15ca52ce","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d6eee7cd078aaf9dd75efc801f6c9b608a37cd71","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64570","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-05T08:16:36.680","lastModified":"2026-08-05T08:16:36.680","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: fix fils_discovery double free on alloc failure\n\nieee80211_set_fils_discovery() calls kfree_rcu() on the old template\nbefore allocating the replacement. If the kzalloc() then fails, it\nreturns -ENOMEM while link->u.ap.fils_discovery still points at the\nobject already queued for freeing. A later update or AP teardown\n(ieee80211_stop_ap()) re-queues that same rcu_head; the second free is\ncaught by KASAN when the RCU sheaf is processed in softirq:\n\n  BUG: KASAN: double-free in rcu_free_sheaf (mm/slub.c:5850)\n  Free of addr ffff88800c065280 by task swapper/0/0\n   ...\n   __rcu_free_sheaf_prepare (mm/slub.c:2634 mm/slub.c:2940)\n   rcu_free_sheaf (mm/slub.c:5850)\n   rcu_core (kernel/rcu/tree.c:2617 kernel/rcu/tree.c:2869)\n   handle_softirqs (kernel/softirq.c:622)\n  The buggy address belongs to the cache kmalloc-96 of size 96\n\nQueue the old object for kfree_rcu() only after the new one is published,\nmatching ieee80211_set_probe_resp() and ieee80211_set_s1g_short_beacon()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/mac80211/cfg.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3b1c256eb4aedfc71dd97d5951ccff824b41d628","lessThan":"e2c55079155a953db669ca1986a985fa286bad95","versionType":"git","status":"affected"},{"version":"3b1c256eb4aedfc71dd97d5951ccff824b41d628","lessThan":"5baaa1042f71dd4b8e418f2cdd516808702d229b","versionType":"git","status":"affected"},{"version":"3b1c256eb4aedfc71dd97d5951ccff824b41d628","lessThan":"1981fba71797ec95e6755fb882cad88899a2a84f","versionType":"git","status":"affected"},{"version":"3b1c256eb4aedfc71dd97d5951ccff824b41d628","lessThan":"286e52a799fa158bdbd77da1426c4d93f9a6e7ad","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/mac80211/cfg.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.7","status":"affected"},{"version":"0","lessThan":"6.7","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1981fba71797ec95e6755fb882cad88899a2a84f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/286e52a799fa158bdbd77da1426c4d93f9a6e7ad","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5baaa1042f71dd4b8e418f2cdd516808702d229b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e2c55079155a953db669ca1986a985fa286bad95","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64571","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-05T08:16:36.797","lastModified":"2026-08-05T08:16:36.797","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: p54: validate RX frame length in p54_rx_eeprom_readback()\n\np54_rx_eeprom_readback() copies the requested EEPROM slice out of a\ndevice-supplied readback frame without checking that the skb actually holds\nthat many bytes. Commit da1b9a55ff11 (\"wifi: p54: prevent buffer-overflow in\np54_rx_eeprom_readback()\") closed the destination overflow by copying a\nfixed priv->eeprom_slice_size (and rejecting a mismatched advertised len),\nbut the source side is still unbounded: nothing verifies the frame is long\nenough to supply that many bytes.\n\nA malicious USB device can send a short frame whose advertised len matches\npriv->eeprom_slice_size while the payload is truncated. The equality check\npasses and memcpy() reads past the end of the skb, leaking adjacent heap:\n\n  BUG: KASAN: slab-out-of-bounds in p54_rx (drivers/net/wireless/intersil/p54/txrx.c:507)\n  Read of size 1016 at addr ffff88800f077114 by task swapper/0/0\n  Call Trace:\n   <IRQ>\n   ...\n   __asan_memcpy (mm/kasan/shadow.c:105)\n   p54_rx (drivers/net/wireless/intersil/p54/txrx.c:507)\n   p54u_rx_cb (drivers/net/wireless/intersil/p54/p54usb.c:163)\n   __usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1657)\n   dummy_timer (drivers/usb/gadget/udc/dummy_hcd.c:2005)\n   ...\n   </IRQ>\n\n  The buggy address belongs to the object at ffff88800f0770c0\n   which belongs to the cache skbuff_small_head of size 704\n  The buggy address is located 84 bytes inside of\n   allocated 704-byte region [ffff88800f0770c0, ffff88800f077380)\n\nCheck that the slice fits in the skb before copying."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/wireless/intersil/p54/txrx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7cb770729ba895f73253dfcd46c3fcba45d896f9","lessThan":"25c3b85af3fc4f8043159b14e65790fc3bbdaf48","versionType":"git","status":"affected"},{"version":"7cb770729ba895f73253dfcd46c3fcba45d896f9","lessThan":"f46f8f9c43fd02f4dd5f716d4bda296a523c04f0","versionType":"git","status":"affected"},{"version":"7cb770729ba895f73253dfcd46c3fcba45d896f9","lessThan":"d38f5d868a0a4770e3bcd0925e16c46acdbc9509","versionType":"git","status":"affected"},{"version":"7cb770729ba895f73253dfcd46c3fcba45d896f9","lessThan":"9096e1f7014174067239a63df18ae5f28301990d","versionType":"git","status":"affected"},{"version":"7cb770729ba895f73253dfcd46c3fcba45d896f9","lessThan":"ebd6d37fa94bee929e0b4c9ca19fdf9b1dcf6cea","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/wireless/intersil/p54/txrx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.28","status":"affected"},{"version":"0","lessThan":"2.6.28","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/25c3b85af3fc4f8043159b14e65790fc3bbdaf48","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9096e1f7014174067239a63df18ae5f28301990d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d38f5d868a0a4770e3bcd0925e16c46acdbc9509","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ebd6d37fa94bee929e0b4c9ca19fdf9b1dcf6cea","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f46f8f9c43fd02f4dd5f716d4bda296a523c04f0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64572","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-05T08:16:36.927","lastModified":"2026-08-05T08:16:36.927","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: fib: free fib_alias with kfree_rcu() on insert error path\n\nfib_table_insert() publishes new_fa into the leaf's fa_list with\nfib_insert_alias() before calling the fib entry notifiers. When a\nnotifier fails, the error path removes new_fa with fib_remove_alias()\n(hlist_del_rcu) and frees it right away with kmem_cache_free().\n\nfib_table_lookup() walks that list under rcu_read_lock() only, so a\nconcurrent lookup that already reached new_fa keeps reading it after the\nfree:\n\n BUG: KASAN: slab-use-after-free in fib_table_lookup (net/ipv4/fib_trie.c:1601)\n Read of size 1 at addr ffff88810676d4eb by task exploit/297\n Call Trace:\n  fib_table_lookup (net/ipv4/fib_trie.c:1601)\n  ip_route_output_key_hash_rcu (net/ipv4/route.c:2814)\n  ip_route_output_key_hash (net/ipv4/route.c:2705)\n  __ip4_datagram_connect (net/ipv4/datagram.c:49)\n  udp_connect (net/ipv4/udp.c:2144)\n  __sys_connect (net/socket.c:2167)\n  __x64_sys_connect (net/socket.c:2173)\n  do_syscall_64\n  entry_SYSCALL_64_after_hwframe\n which belongs to the cache ip_fib_alias of size 56\n\nTriggering the error path needs CAP_NET_ADMIN and a registered fib\nnotifier that can reject a route; a netdevsim device whose IPv4 FIB\nresource is exhausted is enough.\n\nFree new_fa with alias_free_mem_rcu(), as fib_table_delete() already\ndoes for a fib_alias removed from the trie."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ipv4/fib_trie.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a6c76c17df021b141b0d306828c9fe4ba2d2717c","lessThan":"8150b5365f026e72250cacc527ea00be30f40105","versionType":"git","status":"affected"},{"version":"a6c76c17df021b141b0d306828c9fe4ba2d2717c","lessThan":"d007056868723de9c0cc3f5ffaad47a8d468b9a4","versionType":"git","status":"affected"},{"version":"a6c76c17df021b141b0d306828c9fe4ba2d2717c","lessThan":"cb8be318b4432abd88d3172ec157330f27a5f7a7","versionType":"git","status":"affected"},{"version":"a6c76c17df021b141b0d306828c9fe4ba2d2717c","lessThan":"b8d2ea75c76abcd0d72679c2f488271f573e32fb","versionType":"git","status":"affected"},{"version":"a6c76c17df021b141b0d306828c9fe4ba2d2717c","lessThan":"f2f152e94a67bc746afaf05a1b2702c195553112","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ipv4/fib_trie.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.6","status":"affected"},{"version":"0","lessThan":"5.6","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/8150b5365f026e72250cacc527ea00be30f40105","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b8d2ea75c76abcd0d72679c2f488271f573e32fb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cb8be318b4432abd88d3172ec157330f27a5f7a7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d007056868723de9c0cc3f5ffaad47a8d468b9a4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f2f152e94a67bc746afaf05a1b2702c195553112","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64573","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-05T08:16:37.057","lastModified":"2026-08-05T08:16:37.057","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: qca: fix NVM tag length underflow in TLV parser\n\nIn the TLV_TYPE_NVM branch of qca_tlv_check_data() the tag loop bound is\n\"while (idx < length - sizeof(struct tlv_type_nvm))\". \"length\" is a signed\nint from the firmware TLV header and sizeof(struct tlv_type_nvm) is a\nsize_t (12), so \"length\" is converted to size_t and any firmware-supplied\n\"length\" < 12 makes the subtraction wrap to a huge value. The loop body\nthen reads a 12-byte struct tlv_type_nvm past the end of the short\nvmalloc'd firmware buffer (and the EDL_TAG_ID_* handlers can write past it).\n\nRewrite the bound as \"idx + sizeof(struct tlv_type_nvm) <= length\"; both\noperands are non-negative, so it no longer underflows and a \"length\" too\nsmall for one record correctly skips the loop.\n\n  BUG: KASAN: vmalloc-out-of-bounds in qca_download_firmware.isra.0 (drivers/bluetooth/btqca.c:421)\n  Read of size 2 at addr ffffc900000e5004 by task kworker/u9:0/52\n  Workqueue: hci0 hci_power_on\n  Call Trace:\n   ...\n   kasan_report (mm/kasan/report.c:595)\n   qca_download_firmware.isra.0 (drivers/bluetooth/btqca.c:421 drivers/bluetooth/btqca.c:617)\n   qca_uart_setup (drivers/bluetooth/btqca.c:948)\n   qca_setup (drivers/bluetooth/hci_qca.c:2029)\n   hci_uart_setup (drivers/bluetooth/hci_ldisc.c:438)\n   hci_dev_open_sync (net/bluetooth/hci_sync.c:5227)\n   hci_power_on (net/bluetooth/hci_core.c:920)\n   process_one_work (kernel/workqueue.c:3322)\n   worker_thread (kernel/workqueue.c:3486)\n   kthread (kernel/kthread.c:436)\n   ret_from_fork (arch/x86/kernel/process.c:158)\n   ret_from_fork_asm (arch/x86/entry/entry_64.S:245)"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/bluetooth/btqca.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"427281f9498ed614f9aabc80e46ec077c487da6d","lessThan":"70354dbb5f72d9a76da7b031de3cbaf6c7d8fc24","versionType":"git","status":"affected"},{"version":"2e4edfa1e2bd821a317e7d006517dcf2f3fac68d","lessThan":"59fd2f075bca94f030c7c78e94878ea0803d7690","versionType":"git","status":"affected"},{"version":"2e4edfa1e2bd821a317e7d006517dcf2f3fac68d","lessThan":"a087ed960fce54e9302796229e9d545bbc9bcd4a","versionType":"git","status":"affected"},{"version":"2e4edfa1e2bd821a317e7d006517dcf2f3fac68d","lessThan":"4fcfb5b2c736785464ff9745f94c6726c5ee2d85","versionType":"git","status":"affected"},{"version":"2e4edfa1e2bd821a317e7d006517dcf2f3fac68d","lessThan":"c90164ca0f7036942ba088eb7ea8d3f6c2352020","versionType":"git","status":"affected"},{"version":"ed53949cc92e28aaa3463d246942bda1fbb7f307","versionType":"git","status":"affected"},{"version":"1caceadfb50432dbf6d808796cb6c34ebb6d662c","versionType":"git","status":"affected"},{"version":"02f05ed44b71152d5e11d29be28aed91c0489b4e","versionType":"git","status":"affected"},{"version":"6.6.31","lessThan":"6.6.148","versionType":"semver","status":"affected"},{"version":"5.15.159","lessThan":"5.16","versionType":"semver","status":"affected"},{"version":"6.1.91","lessThan":"6.2","versionType":"semver","status":"affected"},{"version":"6.8.10","lessThan":"6.9","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/bluetooth/btqca.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.9","status":"affected"},{"version":"0","lessThan":"6.9","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/4fcfb5b2c736785464ff9745f94c6726c5ee2d85","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/59fd2f075bca94f030c7c78e94878ea0803d7690","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/70354dbb5f72d9a76da7b031de3cbaf6c7d8fc24","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a087ed960fce54e9302796229e9d545bbc9bcd4a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c90164ca0f7036942ba088eb7ea8d3f6c2352020","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64574","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-05T08:16:37.203","lastModified":"2026-08-05T08:16:37.203","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: tear down new links on vif update error path\n\nWhen ieee80211_vif_update_links() adds new links it allocates a link\ncontainer for each and calls ieee80211_link_init() (which registers the\nper-link debugfs files with file->private_data pointing into the container)\nand ieee80211_link_setup(). If the subsequent drv_change_vif_links() fails,\nthe error path restores the old pointers and jumps to 'free', which frees\nthe new containers but never removes their debugfs entries or stops the\nlinks. The debugfs files survive with file->private_data dangling at the\nfreed container, so a later open()+read() (e.g. link-1/txpower)\ndereferences freed memory in ieee80211_if_read_link(), a use-after-free.\n\nThe removal path already dismantles links correctly via\nieee80211_tear_down_links(), which removes each link's keys and debugfs\nentries and calls ieee80211_link_stop(); the add path on the error branch\ndoes not. Commit be1ba9ed221f (\"wifi: mac80211: avoid weird state in error\npath\") hardened this same error path for the link-removal case\n(new_links == 0) but left the newly-added links' teardown unaddressed.\n\ndrv_change_vif_links() can fail at runtime on MLO drivers (internal\nallocation / queue / firmware command failures).\n\nRemove the new links' debugfs entries and stop them before freeing.\n\n  BUG: KASAN: slab-use-after-free in ieee80211_if_read_link (net/mac80211/debugfs_netdev.c:127)\n  Read of size 8 at addr ffff888011290000 by task exploit/145\n  Call Trace:\n   ...\n   ieee80211_if_read_link (net/mac80211/debugfs_netdev.c:127)\n   short_proxy_read (fs/debugfs/file.c:373)\n   vfs_read (fs/read_write.c:572)\n   ksys_read (fs/read_write.c:716)\n   do_syscall_64 (arch/x86/entry/syscall_64.c:94)\n   entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\n  ...\n  Oops: general protection fault, probably for non-canonical address 0xdffffc000000000a\n  RIP: 0010:ieee80211_if_read_link (net/mac80211/debugfs_netdev.c:127)\n  Kernel panic - not syncing: Fatal exception"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/mac80211/link.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"170cd6a66d9a164180eb4dc72d50afa6ce1ce566","lessThan":"329589417214d3b7221432e5b266ed2bba7ff674","versionType":"git","status":"affected"},{"version":"170cd6a66d9a164180eb4dc72d50afa6ce1ce566","lessThan":"c57d97f381306bbfba174e8f708419e007824e0c","versionType":"git","status":"affected"},{"version":"170cd6a66d9a164180eb4dc72d50afa6ce1ce566","lessThan":"0f7eaeb950adb77f71beb546e5ab30f90b41fe6f","versionType":"git","status":"affected"},{"version":"170cd6a66d9a164180eb4dc72d50afa6ce1ce566","lessThan":"901a73523e093beff123b54b1ceaf3113f18acc9","versionType":"git","status":"affected"},{"version":"170cd6a66d9a164180eb4dc72d50afa6ce1ce566","lessThan":"952c02b33f56207a160421bcd61e7ac53c9c59ae","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/mac80211/link.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.4","status":"affected"},{"version":"0","lessThan":"6.4","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc5","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0f7eaeb950adb77f71beb546e5ab30f90b41fe6f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/329589417214d3b7221432e5b266ed2bba7ff674","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/901a73523e093beff123b54b1ceaf3113f18acc9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/952c02b33f56207a160421bcd61e7ac53c9c59ae","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c57d97f381306bbfba174e8f708419e007824e0c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64575","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-05T08:16:37.363","lastModified":"2026-08-05T08:16:37.363","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: tcp: fix double sock release on batch realloc\n\nbpf_iter_tcp_batch() releases the current batch via\nbpf_iter_tcp_put_batch(), which drops the socket refs and rewrites\neach slot with the socket cookie, then grows the batch. cur_sk/end_sk\nare kept for bpf_iter_tcp_resume(), but on realloc failure the function\nreturns ERR_PTR() before resume runs, leaving cur_sk < end_sk over\nslots that now hold cookies rather than sock pointers.\nbpf_iter_tcp_seq_stop() then calls bpf_iter_tcp_put_batch() again and\ndereferences a cookie as a struct sock.\n\nEmpty the batch on the failure path so stop() does not release it\nagain. The sockets were already freed by the first\nbpf_iter_tcp_put_batch(), so nothing leaks, and a later read() rescans\nthe bucket from the start instead of skipping it. The sibling\nGFP_NOWAIT failure path still holds real socket references and is left\nfor stop() to release.\n\n  BUG: KASAN: null-ptr-deref in __sock_gen_cookie\n  Read of size 8 at addr 0000000000000059 by task exploit\n   ...\n   __sock_gen_cookie (net/core/sock_diag.c:28)\n   bpf_iter_tcp_put_batch (net/ipv4/tcp_ipv4.c:2918)\n   bpf_iter_tcp_seq_stop (net/ipv4/tcp_ipv4.c:3270)\n   bpf_seq_read (kernel/bpf/bpf_iter.c:205)\n   vfs_read (fs/read_write.c:572)\n   ksys_read (fs/read_write.c:716)\n   do_syscall_64\n   entry_SYSCALL_64_after_hwframe\n  Kernel panic - not syncing: Fatal exception"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ipv4/tcp_ipv4.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"cdec67a489d4fdae3e83e04fca0419136a83c4c2","lessThan":"9f27c4f0ae35b5390ce4f7a54d3501144e41a54d","versionType":"git","status":"affected"},{"version":"cdec67a489d4fdae3e83e04fca0419136a83c4c2","lessThan":"8a726e9585ffe7bfbfad2b5279277a00973970f3","versionType":"git","status":"affected"},{"version":"cdec67a489d4fdae3e83e04fca0419136a83c4c2","lessThan":"980a813452754f8001704744e92f7aa697c53dd3","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ipv4/tcp_ipv4.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.17","status":"affected"},{"version":"0","lessThan":"6.17","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc5","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/8a726e9585ffe7bfbfad2b5279277a00973970f3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/980a813452754f8001704744e92f7aa697c53dd3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9f27c4f0ae35b5390ce4f7a54d3501144e41a54d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64576","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-05T08:16:37.483","lastModified":"2026-08-05T08:16:37.483","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnexthop: initialize extack in nh_res_bucket_migrate()\n\nnh_res_bucket_migrate() passes an uninitialized netlink_ext_ack to\ncall_nexthop_res_bucket_notifiers(). When\nnh_notifier_res_bucket_info_init() fails (e.g. the kzalloc returns\n-ENOMEM), the error is propagated back before any notifier sets\nextack._msg, and the error path formats the stale pointer with\npr_err_ratelimited(\"%s\\n\", extack._msg). With CONFIG_INIT_STACK_NONE\nthis dereferences uninitialized stack memory:\n\n  Oops: general protection fault, probably for non-canonical address ...\n  KASAN: maybe wild-memory-access in range [...]\n  RIP: 0010:string (lib/vsprintf.c:730)\n   vsnprintf (lib/vsprintf.c:2945)\n   _printk (kernel/printk/printk.c:2504)\n   nh_res_bucket_migrate (net/ipv4/nexthop.c:1816)\n   nh_res_table_upkeep (net/ipv4/nexthop.c:1866)\n   rtm_new_nexthop (net/ipv4/nexthop.c:3323)\n   rtnetlink_rcv_msg (net/core/rtnetlink.c:7076)\n   netlink_sendmsg (net/netlink/af_netlink.c:1900)\n  Kernel panic - not syncing: Fatal exception\n\nZero-initialize extack so _msg is NULL on error paths that never set it."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ipv4/nexthop.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7c37c7e00411b3d1e0c5292368317aca69d1f324","lessThan":"c0936c131a71657afc635d0db2ab096d15d473e1","versionType":"git","status":"affected"},{"version":"7c37c7e00411b3d1e0c5292368317aca69d1f324","lessThan":"3081702ea5aca0aeed9c1ade8eadf6cde8db6b7d","versionType":"git","status":"affected"},{"version":"7c37c7e00411b3d1e0c5292368317aca69d1f324","lessThan":"d536bf205c71f700f6de2086038c3e1d77724715","versionType":"git","status":"affected"},{"version":"7c37c7e00411b3d1e0c5292368317aca69d1f324","lessThan":"18506d7263768d76ac8e057ba55a4d9da50aad66","versionType":"git","status":"affected"},{"version":"7c37c7e00411b3d1e0c5292368317aca69d1f324","lessThan":"6347c5314cee49f364aaf2e40ff15415a57a116e","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ipv4/nexthop.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.13","status":"affected"},{"version":"0","lessThan":"5.13","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc5","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/18506d7263768d76ac8e057ba55a4d9da50aad66","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3081702ea5aca0aeed9c1ade8eadf6cde8db6b7d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6347c5314cee49f364aaf2e40ff15415a57a116e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c0936c131a71657afc635d0db2ab096d15d473e1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d536bf205c71f700f6de2086038c3e1d77724715","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64577","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-05T08:16:37.630","lastModified":"2026-08-05T08:16:37.630","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ngtp: check skb_pull_data() return in gtp1u_send_echo_resp()\n\ngtp1u_send_echo_resp() ignores skb_pull_data()'s return value. Its\ncaller gtp1u_udp_encap_recv() only guarantees 16 bytes (udphdr +\ngtp1_header), but the pull requests 20 (gtp1_header_long + udphdr). For\na 16-19 byte echo request the pull fails and returns NULL without\nadvancing skb->data; execution continues, and the following skb_push()\nplus the IP header pushed by iptunnel_xmit() move skb->data below\nskb->head, tripping skb_under_panic().\n\nFix it by dropping the packet when skb_pull_data() fails.\n\n  skbuff: skb_under_panic: ...\n  kernel BUG at net/core/skbuff.c:214!\n  Call Trace:\n   skb_push (net/core/skbuff.c:2648)\n   iptunnel_xmit (net/ipv4/ip_tunnel_core.c:82)\n   gtp_encap_recv (drivers/net/gtp.c:701 drivers/net/gtp.c:808 drivers/net/gtp.c:920)\n   udp_queue_rcv_one_skb (net/ipv4/udp.c:2388)\n   ...\n  Kernel panic - not syncing: Fatal exception in interrupt"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/gtp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"9af41cc33471ea1efa6f77e188f055cc77d0a5c5","lessThan":"b3c733eaae7f362601c28ac1533d47a961cd3e1c","versionType":"git","status":"affected"},{"version":"9af41cc33471ea1efa6f77e188f055cc77d0a5c5","lessThan":"4fc7923871d176ce0e5fecf4a9b7bb915af790ed","versionType":"git","status":"affected"},{"version":"9af41cc33471ea1efa6f77e188f055cc77d0a5c5","lessThan":"961e9b1e33445f8e42859ecc020c9f60d8b69a8b","versionType":"git","status":"affected"},{"version":"9af41cc33471ea1efa6f77e188f055cc77d0a5c5","lessThan":"cf45d748e437b8dd2dd987f27ee79c8c86f95c88","versionType":"git","status":"affected"},{"version":"9af41cc33471ea1efa6f77e188f055cc77d0a5c5","lessThan":"cd170f051dba9ac146fabcd1b91726487c0cb9fa","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/gtp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.18","status":"affected"},{"version":"0","lessThan":"5.18","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc5","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/4fc7923871d176ce0e5fecf4a9b7bb915af790ed","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/961e9b1e33445f8e42859ecc020c9f60d8b69a8b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b3c733eaae7f362601c28ac1533d47a961cd3e1c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cd170f051dba9ac146fabcd1b91726487c0cb9fa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cf45d748e437b8dd2dd987f27ee79c8c86f95c88","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64578","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-05T08:16:37.760","lastModified":"2026-08-05T08:16:37.760","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: validate compound request size before reading StructureSize2\n\nWhen ksmbd validates a compound (chained) SMB2 request,\nksmbd_smb2_check_message() reads pdu->StructureSize2 without first\nchecking that the compound element is large enough to contain it.\nStructureSize2 is a 2-byte field at offset 64\n(__SMB2_HEADER_STRUCTURE_SIZE) from the start of each element.\n\nThe compound-walking logic only guarantees that a full 64-byte SMB2\nheader is present for the trailing element: when NextCommand is 0, len is\nreduced to the number of bytes remaining after next_smb2_rcv_hdr_off. A\nremote client can craft a compound request whose last element has exactly\n64 bytes, so the 2-byte StructureSize2 read at offset 64 extends one byte\npast the receive buffer, producing a slab-out-of-bounds read.\n\n  BUG: KASAN: slab-out-of-bounds in ksmbd_smb2_check_message (fs/smb/server/smb2misc.c:402)\n  Read of size 2 at addr ffff888012ae31ac by task kworker/0:1/14\n  The buggy address is located 172 bytes inside of allocated 173-byte region\n  Workqueue: ksmbd-io handle_ksmbd_work\n  Call Trace:\n   ...\n   kasan_report (mm/kasan/report.c:595)\n   ksmbd_smb2_check_message (fs/smb/server/smb2misc.c:402)\n   handle_ksmbd_work (fs/smb/server/server.c:119)\n   process_one_work (kernel/workqueue.c:3314)\n   worker_thread (kernel/workqueue.c:3397)\n   kthread (kernel/kthread.c:436)\n   ret_from_fork (arch/x86/kernel/process.c:158)\n   ret_from_fork_asm (arch/x86/entry/entry_64.S:245)\n\nReject any compound element that is too small to hold StructureSize2\nbefore dereferencing it."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/smb/server/smb2misc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9","lessThan":"2c307126ed8e7adddab82b8e31d962d3a2156ab1","versionType":"git","status":"affected"},{"version":"e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9","lessThan":"f7550a91ab211726f59cb137523b7a9eae1ac6eb","versionType":"git","status":"affected"},{"version":"e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9","lessThan":"f0e337e7db67cc1c832958bbb6c4026bdceacfdb","versionType":"git","status":"affected"},{"version":"e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9","lessThan":"ea128f06d2fb2186f0cac0c9f3e953e4d1f5c29a","versionType":"git","status":"affected"},{"version":"e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9","lessThan":"15b38176fd1530372905c602fde51fe89ec8c877","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/smb/server/smb2misc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.15","status":"affected"},{"version":"0","lessThan":"5.15","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/15b38176fd1530372905c602fde51fe89ec8c877","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2c307126ed8e7adddab82b8e31d962d3a2156ab1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ea128f06d2fb2186f0cac0c9f3e953e4d1f5c29a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f0e337e7db67cc1c832958bbb6c4026bdceacfdb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f7550a91ab211726f59cb137523b7a9eae1ac6eb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64579","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-05T08:16:37.893","lastModified":"2026-08-05T08:16:37.893","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert\n\nxfrm_hash_rebuild()'s first loop preallocates the bins/chains the reinsert\nloop needs, so the reinsert (after hlist_del_rcu()) cannot allocate or\nfail. But its guard is inverted: it skips policies with prefixlen <\nthreshold and preallocates for the rest.\n\nprefixlen < threshold is exactly when policy_hash_bysel() returns NULL and\nthe reinsert takes the allocating xfrm_policy_inexact_insert() path. So the\nloop preallocates for the exact policies (which never allocate) and skips\nthe inexact ones, whose bin/node is then allocated GFP_ATOMIC during\nreinsert. On failure the error path only WARN_ONCE()s and continues,\nleaving a poisoned bydst node; the next rebuild's hlist_del_rcu()\ndereferences LIST_POISON2 and takes a GPF. Reachable under memory pressure,\ndeterministic via failslab.\n\nInvert the guard so preallocation covers exactly the reinserted policies;\nthe reinsert then allocates nothing and cannot fail.\n\nCrash:\n  Oops: general protection fault, probably for non-canonical address\n  0xfbd59c0000000024: 0000 [#1] SMP KASAN NOPTI\n  KASAN: maybe wild-memory-access in range [0xdead...]\n  ...\n  Workqueue: events xfrm_hash_rebuild\n  RIP: 0010:xfrm_hash_rebuild+0x5b3/0x1190\n  RAX: dead000000000122   (LIST_POISON2 + offset)\n  ...\n  Call Trace:\n   hlist_del_rcu (include/linux/rculist.h:599)\n   xfrm_hash_rebuild (net/xfrm/xfrm_policy.c:1365)\n   process_one_work (kernel/workqueue.c:3322)\n   worker_thread (kernel/workqueue.c:3486)\n   kthread (kernel/kthread.c:436)\n   ret_from_fork (arch/x86/kernel/process.c:158)\n   ret_from_fork_asm (arch/x86/entry/entry_64.S:245)\n   ...\n  Kernel panic - not syncing: Fatal exception in interrupt"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/xfrm/xfrm_policy.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"24969facd704a5f0dd8e08da86bf32a9ce972bee","lessThan":"d9d9cc21cc90014724a14c447e3d587be9447107","versionType":"git","status":"affected"},{"version":"24969facd704a5f0dd8e08da86bf32a9ce972bee","lessThan":"94c00391a5117530188334f740ce26d3f1256190","versionType":"git","status":"affected"},{"version":"24969facd704a5f0dd8e08da86bf32a9ce972bee","lessThan":"7acc5ed2f33608a3d83b64f50a5766843b6e2485","versionType":"git","status":"affected"},{"version":"24969facd704a5f0dd8e08da86bf32a9ce972bee","lessThan":"6aa3796d18a9fda953ad76a62b57bf6c145cb9ef","versionType":"git","status":"affected"},{"version":"24969facd704a5f0dd8e08da86bf32a9ce972bee","lessThan":"f38f8cce2f7e79775b3db7e8a5eacda04ac908e4","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/xfrm/xfrm_policy.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.0","status":"affected"},{"version":"0","lessThan":"5.0","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/6aa3796d18a9fda953ad76a62b57bf6c145cb9ef","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7acc5ed2f33608a3d83b64f50a5766843b6e2485","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/94c00391a5117530188334f740ce26d3f1256190","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d9d9cc21cc90014724a14c447e3d587be9447107","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f38f8cce2f7e79775b3db7e8a5eacda04ac908e4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64580","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-05T08:16:38.027","lastModified":"2026-08-05T08:16:38.027","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst()\n\nOn the error path where in6_dev_get(dev) returns NULL, xfrm6_fill_dst()\nreleases the device reference with netdev_put() but leaves\nxdst->u.dst.dev set. dst_destroy() later calls netdev_put(dst->dev)\nagain, so the same net_device reference is released twice, underflowing\nits refcount (ref_tracker WARNING + \"unregister_netdevice: waiting for\n<dev> to become free\").\n\nClear xdst->u.dst.dev after the netdev_put(), the same way the XFRM\ndevice-offload paths xfrm_dev_state_add() and xfrm_dev_policy_add() in\nnet/xfrm/xfrm_device.c NULL ->dev when releasing the reference on error.\n\n  ref_tracker: reference already released.\n  ref_tracker: allocated in:\n   xfrm6_fill_dst (net/ipv6/xfrm6_policy.c:86)\n   ...\n   udpv6_sendmsg (net/ipv6/udp.c:1696)\n   ...\n  ref_tracker: freed in:\n   xfrm6_fill_dst (net/ipv6/xfrm6_policy.c:90)\n   ...\n  WARNING: lib/ref_tracker.c:322 at ref_tracker_free+0x58b/0x780\n   dst_destroy (net/core/dst.c:115)\n   rcu_core\n   handle_softirqs\n   ..."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ipv6/xfrm6_policy.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"84c4a9dfbf430861e7588d95ae3ff61535dca351","lessThan":"df6856c2dda9187601d29b5fbd7a81b3b178cedf","versionType":"git","status":"affected"},{"version":"84c4a9dfbf430861e7588d95ae3ff61535dca351","lessThan":"43de8a49335e611adb271bbd52e84dfbc11fc185","versionType":"git","status":"affected"},{"version":"84c4a9dfbf430861e7588d95ae3ff61535dca351","lessThan":"ff636d7b7cba6dea82ecf580415ea57f2c1a11b6","versionType":"git","status":"affected"},{"version":"84c4a9dfbf430861e7588d95ae3ff61535dca351","lessThan":"e078da1b4e11390cff3201c19a9a1fe70c5b934f","versionType":"git","status":"affected"},{"version":"84c4a9dfbf430861e7588d95ae3ff61535dca351","lessThan":"136992de9bb91871084ae52d172610541c76e4d2","versionType":"git","status":"affected"},{"version":"a7e22d0c0e81dde129a51ee413644124f4b59954","versionType":"git","status":"affected"},{"version":"01b0d887f67a388fb2a658ee2bdd74e5ba146818","versionType":"git","status":"affected"},{"version":"a98124aac0b5adc5de8ae54f11322781cb4d85c3","versionType":"git","status":"affected"},{"version":"e27b7bee743d921f037b1da6f071237345bef7c1","versionType":"git","status":"affected"},{"version":"3.0.79","lessThan":"3.1","versionType":"semver","status":"affected"},{"version":"3.2.46","lessThan":"3.3","versionType":"semver","status":"affected"},{"version":"3.4.46","lessThan":"3.5","versionType":"semver","status":"affected"},{"version":"3.9.3","lessThan":"3.10","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ipv6/xfrm6_policy.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.10","status":"affected"},{"version":"0","lessThan":"3.10","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/136992de9bb91871084ae52d172610541c76e4d2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/43de8a49335e611adb271bbd52e84dfbc11fc185","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/df6856c2dda9187601d29b5fbd7a81b3b178cedf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e078da1b4e11390cff3201c19a9a1fe70c5b934f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ff636d7b7cba6dea82ecf580415ea57f2c1a11b6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64581","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-05T08:16:38.177","lastModified":"2026-08-05T08:16:38.177","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: fix sk_dst_cache double-free in xfrm_user_policy()\n\nxfrm_user_policy() clears the socket dst cache with __sk_dst_reset(),\ni.e. the non-atomic __sk_dst_set(sk, NULL): it reads sk_dst_cache with\nrcu_dereference_protected(), stores NULL and dst_release()s the old dst.\nThat is only safe if no other thread modifies sk_dst_cache concurrently.\n\nFor a connected UDP socket that does not hold: the transmit fast path\n(udp_sendmsg -> sk_dst_check -> sk_dst_reset) resets the cache locklessly\nwith an atomic xchg(). A per-socket policy change racing a send can make\nboth sides observe the same old dst and each dst_release() it, dropping\nthe socket's single reference twice and freeing the xfrm_dst bundle while\nit is still referenced:\n\n  BUG: KASAN: slab-use-after-free in dst_release\n  Write of size 4 at addr ffff88801897b6c0 by task exploit/155\n  Call Trace:\n   ...\n   dst_release (... ./include/linux/rcuref.h:109)\n   xfrm_user_policy (./include/net/sock.h:2239 ./include/net/sock.h:2256 net/xfrm/xfrm_state.c:3053)\n   do_ip_setsockopt (net/ipv4/ip_sockglue.c:1347)\n   ip_setsockopt (net/ipv4/ip_sockglue.c:1417)\n   do_sock_setsockopt (net/socket.c:2368)\n   __sys_setsockopt (net/socket.c:2393)\n   __x64_sys_setsockopt (net/socket.c:2396)\n   do_syscall_64 (arch/x86/entry/syscall_64.c:94)\n   entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\n\nReachable by an unprivileged user via a user+network namespace.\n\nUse the atomic sk_dst_reset() so the cache is cleared and released with a\nsingle xchg(): whichever side wins releases the dst once, the other sees\nNULL and does nothing. Behaviour is otherwise unchanged."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/xfrm/xfrm_state.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2b06cdf3e688b98fcc9945873b5d42792bd4eee0","lessThan":"96b678d08268b5f5c6fc99d4289d9b7e334fc683","versionType":"git","status":"affected"},{"version":"2b06cdf3e688b98fcc9945873b5d42792bd4eee0","lessThan":"c283e9ada7fcb7dd4b10592623086b2e6d2f9925","versionType":"git","status":"affected"},{"version":"72f157be2f81910ae759bfe2e5c2256fc4625645","versionType":"git","status":"affected"},{"version":"9e9fe58a92a46c6d154d2901735bf230d91b8507","versionType":"git","status":"affected"},{"version":"adc1ec6cdc20d430aa01b86497220709b9149466","versionType":"git","status":"affected"},{"version":"b54033eb1cfd77aba471269ddd804ed8d3e35dea","versionType":"git","status":"affected"},{"version":"c9e82cb34c3c2ee895af01bc899c6ed0bc6eb04a","versionType":"git","status":"affected"},{"version":"5eef9b51114fcc65651d671add52f267f91b9451","versionType":"git","status":"affected"},{"version":"3.16.52","lessThan":"3.17","versionType":"semver","status":"affected"},{"version":"4.4.163","lessThan":"4.5","versionType":"semver","status":"affected"},{"version":"3.18.101","lessThan":"3.19","versionType":"semver","status":"affected"},{"version":"4.1.52","lessThan":"4.2","versionType":"semver","status":"affected"},{"version":"4.4.123","lessThan":"4.5","versionType":"semver","status":"affected"},{"version":"4.9.89","lessThan":"4.10","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/xfrm/xfrm_state.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.14","status":"affected"},{"version":"0","lessThan":"4.14","versionType":"semver","status":"unaffected"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/96b678d08268b5f5c6fc99d4289d9b7e334fc683","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c283e9ada7fcb7dd4b10592623086b2e6d2f9925","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-6020","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T08:16:40.850","lastModified":"2026-08-05T08:16:40.850","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The ShopLentor plugin for WordPress is vulnerable to arbitrary function execution via the woolentoropt/v1/custom-action REST API endpoint in all versions up to, and including, 3.3.7. This is due to the handle_action() method passing user-supplied input directly to call_user_func() without an allowlist of permitted callbacks. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute arbitrary PHP callable functions via the 'callback' parameter."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"devitemsllc","product":"ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"3.3.7","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-470"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/woolentor-addons/trunk/includes/admin-panel/includes/classes/Api/Custom_Actions.php#L99","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3504292%40woolentor-addons%2Ftrunk&old=3493678%40woolentor-addons%2Ftrunk&sfp_email=&sfph_mail=","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/00138875-d892-460c-b0ce-7a01335d26dc?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-6079","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T08:16:40.997","lastModified":"2026-08-05T08:16:40.997","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Material Dashboard plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on the amd_ajax_target_task_manager() function in all versions up to, and including, 1.4.10. This makes it possible for unauthenticated attackers to enumerate all scheduled tasks (potentially exposing PII), execute arbitrary tasks, and delete any task via the public_amd_ajax_handler AJAX action."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"ho3einie","product":"Material Dashboard","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.4.10","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":3.4}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/material-dashboard/trunk/core/AMDNetwork/AMDNetwork.php#L26","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/material-dashboard/trunk/core/AMDTasks/AMDTasks.php#L514","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?new=3535650%40material-dashboard%2Ftrunk&old=3535649%40material-dashboard%2Ftrunk","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/459b7fef-806c-4f5b-bb31-b7197750e941?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-6147","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T08:16:41.140","lastModified":"2026-08-05T08:16:41.140","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the rest_replace_media() function in all versions up to, and including, 2.1.6. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"lightsyncpro","product":"LightSync Pro – Connect & Sync Cloud Assets | Lightroom, Canva, Figma, Dropbox & Shutterstock","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.1.6","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-434"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/lightsyncpro/tags/2.0.1/includes/admin/class-admin.php#L6755","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/lightsyncpro/tags/2.0.1/includes/admin/class-admin.php#L6814","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3507389%40lightsyncpro%2Ftrunk&old=3476495%40lightsyncpro%2Ftrunk&sfp_email=&sfph_mail=","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9ccdf08b-8b74-4b58-8779-3b07ef2d7b2f?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-6627","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T08:16:41.280","lastModified":"2026-08-05T08:16:41.280","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to unauthorized modification and deletion of Stripe payment credentials in all versions up to, and including, 1.1.1. This is due to missing capability checks and nonce verification on the `wpf_stripe_callback_success()` and `wpf_stripe_disconnect()` functions, both hooked to `admin_init`. The `admin_init` hook fires on `admin-post.php` which is accessible without authentication. This makes it possible for unauthenticated attackers to overwrite the site's Stripe API credentials with attacker-controlled values (redirecting payments to the attacker's Stripe account) or disconnect the Stripe integration entirely by deleting the stored credentials."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"saadiqbal","product":"WPFormify – Stripe Payments with Form and Checkout","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":4.2}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/wpformify/tags/1.1.1/modules/payments/stripe_authorization.php#L49","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/wpformify/tags/1.1.1/modules/payments/stripe_authorization.php#L79","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?new=3557764%40wpformify%2Ftags%2F1.1.2&old=3299310%40wpformify/tags","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/44cd696c-fff3-4942-b2c9-628ba281ba44?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-6639","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T08:16:41.427","lastModified":"2026-08-05T08:16:41.427","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.6. This is due to the `getCurrentTaskResults()` method in `modules/workspace/controller.php` being accessible without authentication or authorization checks. The method is not included in the workspace controller's `getNoncedMethods()` array, the base `getPermissions()` returns an empty array, and all AJAX actions are registered with `wp_ajax_nopriv_` hooks (`classes/frame.php:282`). When tasks are created via features like the Bulk Post Generator, the task parameters — including the OpenAI API key in plaintext, AI prompts, keywords, and full AI model configuration — are stored in the database and returned in the JSON response. This makes it possible for unauthenticated attackers to enumerate sequential task IDs and retrieve sensitive configuration data including API keys."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"wupsales","product":"AI Copilot – Content Generator","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.4.6","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/ai-copilot-content-generator/tags/1.4.6/classes/frame.php#L282","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/ai-copilot-content-generator/tags/1.4.6/modules/workspace/controller.php#L83","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/ai-copilot-content-generator/tags/1.4.6/modules/workspace/models/tasks.php#L106","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?new=3528734%40ai-copilot-content-generator%2Ftrunk&old=3525474%40ai-copilot-content-generator%2Ftrunk","source":"security@wordfence.com"},{"url":"https://wordpress.org/plugins/ai-copilot-content-generator/","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/247b1921-70a6-4e65-819a-2895bc395e9f?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-6972","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T08:16:41.560","lastModified":"2026-08-05T08:16:41.560","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The SKT Skill Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `chart_size` attribute of the `skillwrapper` shortcode in all versions up to, and including, 2.6. This is due to insufficient input sanitization and output escaping on the `chart_size` attribute, which is concatenated directly into an inline `<style>` block. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"sonalsinha21","product":"SKT Skill Bar","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.6","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/skt-skill-bar/tags/2.6/sktskillbar.php#L240","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/skt-skill-bar/tags/2.6/sktskillbar.php#L541","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/skt-skill-bar/tags/2.6/sktskillbar.php#L56","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/skt-skill-bar/trunk/sktskillbar.php#L240","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&new=3565730%40skt-skill-bar%2Ftrunk&old=3565726%40skt-skill-bar%2Ftrunk","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/eb689760-837f-45e6-ba51-a834053be6ae?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-70376","sourceIdentifier":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","published":"2026-08-05T08:16:41.703","lastModified":"2026-08-05T08:16:41.703","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Pluck CMS's admin panel relies solely on a Referer-header comparison (requestedByTheSameDomain() in data/inc/functions.admin.php, gating every admin.php action) for CSRF protection, with no per-request anti-CSRF token anywhere in the admin area. When a request carries no Referer/Host information, the function's elseif branch returns true, treating the request as same-origin. Because a cross-site attacker page can suppress the Referer header (e.g. via <meta name=referrer content=no-referrer>), it can force an authenticated administrator's browser to submit forged admin actions with no valid Referer, including creating pages with raw HTML (stored XSS via the rendered page) and installing PHP modules/themes (remote code execution)."}],"affected":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","affectedData":[{"vendor":"pluck-cms","product":"Pluck CMS","defaultStatus":"unknown","programFiles":["admin.php","data/inc/functions.admin.php"],"versions":[{"version":"0","lessThan":"4.7.21","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","baseScore":9.6,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":6.0}]},"weaknesses":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","description":[{"lang":"en","value":"CWE-352"}]}],"references":[{"url":"https://github.com/pluck-cms/pluck","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}]}},{"cve":{"id":"CVE-2026-70377","sourceIdentifier":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","published":"2026-08-05T08:16:41.830","lastModified":"2026-08-05T08:16:41.830","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"imagecli's `scale <ratio>` pipeline operation (Scale::apply() in src/image_ops.rs) computes output width/height as (dimension as f32 * ratio) as u32 with no upper-bound validation on the CLI-supplied ratio, which is parsed via nom::number::complete::float with no range check. A large ratio (e.g. 100000) causes an attempted allocation of hundreds of terabytes, aborting the process. Any application embedding imagecli as a library and accepting user-controlled pipeline strings is remotely crashable with a single request."}],"affected":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","affectedData":[{"vendor":"theotherphil","product":"imagecli","defaultStatus":"unknown","programFiles":["src/image_ops.rs"],"versions":[{"version":"0","lessThanOrEqual":"0.2.1","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}]},"weaknesses":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","description":[{"lang":"en","value":"CWE-789"}]}],"references":[{"url":"https://github.com/theotherphil/imagecli/issues/66","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}]}},{"cve":{"id":"CVE-2026-70378","sourceIdentifier":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","published":"2026-08-05T08:16:41.957","lastModified":"2026-08-05T08:16:41.957","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"imagecli's `carve <ratio>` pipeline operation (Carve::apply() in src/image_ops.rs) only asserts `ratio <= 1.0`, never validating that the ratio is positive. A negative ratio (e.g. -5) causes the computed target width to saturate to 0 via Rust's defined float-to-uint cast, which is then passed to imageproc::seam_carving::shrink_width — a function that panics when given a width below 2, crashing the process. This shares the same missing-input-validation root cause as the sibling `scale` finding in the same file but is an independently fixable, distinct code path."}],"affected":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","affectedData":[{"vendor":"theotherphil","product":"imagecli","defaultStatus":"unknown","programFiles":["src/image_ops.rs"],"versions":[{"version":"0","lessThanOrEqual":"0.2.1","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}]},"weaknesses":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","description":[{"lang":"en","value":"CWE-1284"}]}],"references":[{"url":"https://github.com/theotherphil/imagecli/issues/67","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}]}},{"cve":{"id":"CVE-2026-71202","sourceIdentifier":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","published":"2026-08-05T08:16:42.080","lastModified":"2026-08-05T08:16:42.080","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The raster Rust crate's crop() function (src/editor.rs) clamps the crop width/height against source dimensions but only clamps the offset_x/offset_y parameters against 0, never against the source width/height. When an offset exceeds the corresponding source dimension, `width2 - offset_x` (or the height equivalent) underflows to a negative i32, which release builds do not trap; the negative value is then cast to usize inside Image::blank()'s Vec::with_capacity() call, triggering a capacity-overflow panic and crashing the process on a single crafted crop request."}],"affected":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","affectedData":[{"vendor":"kosinix","product":"raster","defaultStatus":"unknown","programFiles":["src/editor.rs"],"versions":[{"version":"0","lessThanOrEqual":"0.2.1","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}]},"weaknesses":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","description":[{"lang":"en","value":"CWE-191"}]}],"references":[{"url":"https://github.com/kosinix/raster/issues/30","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}]}},{"cve":{"id":"CVE-2026-71203","sourceIdentifier":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","published":"2026-08-05T08:16:42.203","lastModified":"2026-08-05T08:16:42.203","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"changedetection.io's REST API resources are protected by an @auth.check_token decorator validating the caller's x-api-key header, except the Spec resource registered at /api/v1/full-spec (changedetectionio/api/Spec.py), whose get() method carries neither @auth.check_token nor @validate_openapi_request. An unauthenticated client can retrieve the full merged OpenAPI schema (all endpoint paths, parameters, and registered processor plugins) even when API access control is enabled and every sibling /api/v1/* route correctly requires the key."}],"affected":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","affectedData":[{"vendor":"dgtlmoon","product":"changedetection.io","defaultStatus":"unknown","programFiles":["changedetectionio/api/Spec.py"],"versions":[{"version":"0.55.7","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}]},"weaknesses":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","description":[{"lang":"en","value":"CWE-306"}]}],"references":[{"url":"https://github.com/dgtlmoon/changedetection.io","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}]}},{"cve":{"id":"CVE-2026-71204","sourceIdentifier":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","published":"2026-08-05T08:16:42.327","lastModified":"2026-08-05T08:16:42.327","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"changedetection.io's /settings save handler builds an update dict from form.data['application'] and blind-merges it into the stored application settings via .update(). Because WTForms represents an unchecked checkbox as False rather than 'unchanged', and only the 'password' field is special-cased against this problem, a POST to /settings that omits the api_access_token_enabled field (e.g. a minimal scripted request) silently disables API key enforcement for the entire REST API, exposing the full watch list, history, and configuration to unauthenticated requests."}],"affected":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","affectedData":[{"vendor":"dgtlmoon","product":"changedetection.io","defaultStatus":"unknown","programFiles":["changedetectionio/blueprint/settings/__init__.py","changedetectionio/forms.py"],"versions":[{"version":"0.55.7","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:L","baseScore":6.2,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":0.7,"impactScore":5.5}]},"weaknesses":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]}],"references":[{"url":"https://github.com/dgtlmoon/changedetection.io","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}]}},{"cve":{"id":"CVE-2026-71205","sourceIdentifier":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","published":"2026-08-05T08:16:42.463","lastModified":"2026-08-05T08:16:42.463","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"changedetection.io's /login route checks the submitted password against a single PBKDF2-HMAC-SHA256 hash with no per-IP or per-session rate limiting, failed-attempt counter, or lockout (no rate-limiting library is present in requirements.txt). Because the entire application is protected by one shared password with no per-user accounts, a successful brute-force guess grants full administrative access, including the ability to view/regenerate the API token."}],"affected":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","affectedData":[{"vendor":"dgtlmoon","product":"changedetection.io","defaultStatus":"unknown","programFiles":["changedetectionio/flask_app.py"],"versions":[{"version":"0.55.7","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":2.5}]},"weaknesses":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","description":[{"lang":"en","value":"CWE-307"}]}],"references":[{"url":"https://github.com/dgtlmoon/changedetection.io","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}]}},{"cve":{"id":"CVE-2026-71206","sourceIdentifier":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","published":"2026-08-05T08:16:42.587","lastModified":"2026-08-05T08:16:42.587","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature and returns the embedded claims.Account object unmodified, never re-fetching the account from the database. No session store or token-revocation mechanism exists in the codebase. Deleting an account or demoting it from owner to a regular role has no effect on tokens already issued to that account — a deleted or demoted owner's token continues authenticating with its original owner-level privileges until natural expiry, which can be up to 30 days with 'remember me' enabled."}],"affected":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","affectedData":[{"vendor":"go-shiori","product":"shiori","defaultStatus":"unknown","programFiles":["internal/domains/auth.go"],"versions":[{"version":"0","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","baseScore":8.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":5.5}]},"weaknesses":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","description":[{"lang":"en","value":"CWE-613"}]}],"references":[{"url":"https://github.com/go-shiori/shiori","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}]}},{"cve":{"id":"CVE-2026-71207","sourceIdentifier":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","published":"2026-08-05T08:16:42.717","lastModified":"2026-08-05T08:16:42.717","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Stock-Inventory-Management-System application's login.php assigns raw $_POST username/password values to $_SESSION and builds its authentication query by directly concatenating those session values into a SQL statement with no parameterization or escaping. An unauthenticated remote attacker can submit a payload such as ' OR '1'='1 in the login form to bypass authentication entirely. The same script additionally contains hardcoded administrative credentials (admin/neola) in a post-login conditional check, providing a second, independent full-authentication-bypass path."}],"affected":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","affectedData":[{"vendor":"mrswapnilsahu","product":"Stock-Inventory-Management-System","defaultStatus":"unknown","programFiles":["login.php"],"versions":[{"version":"0","lessThanOrEqual":"1.0","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"weaknesses":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","description":[{"lang":"en","value":"CWE-89"}]}],"references":[{"url":"https://github.com/mrswapnilsahu/Stock-Inventory-Management-System/blob/master/login.php","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}]}},{"cve":{"id":"CVE-2026-71208","sourceIdentifier":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","published":"2026-08-05T08:16:42.847","lastModified":"2026-08-05T08:16:42.847","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"KubeSphere's cluster-controller reconciliation (pkg/utils/clusterclient/clusterclient.go, addCluster) processes every Cluster custom resource's connection configuration and immediately calls Discovery().ServerVersion() against the CRD-specified Kubernetes API endpoint, which is parsed only for URL syntax (url.Parse) with no allow/deny-list for loopback, RFC1918 private ranges, link-local, or cloud-metadata addresses (e.g. 169.254.169.254). A user able to create or update a Cluster CRD can force the controller-manager and apiserver pods to issue outbound requests to arbitrary internal or metadata endpoints."}],"affected":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","affectedData":[{"vendor":"kubesphere","product":"KubeSphere","defaultStatus":"unknown","programFiles":["pkg/utils/clusterclient/clusterclient.go"],"versions":[{"version":"4.0.0","lessThanOrEqual":"4.1.3-rc.0","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","description":[{"lang":"en","value":"CWE-918"}]}],"references":[{"url":"https://github.com/ashikmd7/kubeSphere/blob/main/SSRF%20via%20Cluster%20CRD%20KubeConfig/README.md","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"},{"url":"https://github.com/kubesphere/kubesphere","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}]}},{"cve":{"id":"CVE-2026-71209","sourceIdentifier":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","published":"2026-08-05T08:16:43.110","lastModified":"2026-08-05T08:16:43.110","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated-allowed GET routes against req.path via a regex requiring a literal /items/:id/cover or /authors/:id/image shape, where req.path retains %2F sequences URL-encoded. Express's router decodes the :id route parameter before handler code runs, so a %2F-encoded '../' sequence in :id (e.g. ..%2f..%2f..%2ftmp%2fpwned) passes the literal-path auth-exemption check while resolving to a real path-traversal payload once decoded. CacheManager.handleCoverCache then joins this decoded value into a cache file path and streams the result before any database-backed ownership check. This bypasses the fix applied for CVE-2025-25205 (which anchored the exemption regex and switched it to req.path) and results in unauthenticated arbitrary file read of any file matching the pattern *_<width>[x<height>].<ext> that the service account can read."}],"affected":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","affectedData":[{"vendor":"advplyr","product":"audiobookshelf","defaultStatus":"unknown","programFiles":["server/routers/Auth.js","server/managers/CacheManager.js"],"versions":[{"version":"2.19.1","lessThanOrEqual":"2.35.1","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}]},"weaknesses":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]}],"references":[{"url":"https://github.com/advplyr/audiobookshelf","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"},{"url":"https://github.com/advplyr/audiobookshelf/security/advisories/GHSA-pg8v-5jcv-wrvw","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}]}},{"cve":{"id":"CVE-2026-71210","sourceIdentifier":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","published":"2026-08-05T08:16:43.240","lastModified":"2026-08-05T08:16:43.240","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Mealie's AsyncSafeTransport SSRF guard (mealie/pkgs/safehttp/transport.py) resolves a target hostname once, checks the resolved IP against private-range rules, but then issues the actual outbound HTTP request using the original hostname, which the underlying async transport re-resolves independently. Because the validated IP is never pinned to the actual connection, a DNS-rebinding attacker (returning a public IP to the validation lookup and a private/metadata IP to the real connection) defeats the guard. This is reachable by any authenticated user via /api/recipes/create/url, /api/recipes/test-scrape-url, and /api/recipes/{slug}/image, and the scraper reflects fetched content back to the requester, allowing an authenticated user to read internal HTTP services and cloud-metadata endpoints."}],"affected":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","affectedData":[{"vendor":"mealie-recipes","product":"mealie","defaultStatus":"unknown","programFiles":["mealie/pkgs/safehttp/transport.py"],"versions":[{"version":"0","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":3.6}]},"weaknesses":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","description":[{"lang":"en","value":"CWE-367"}]}],"references":[{"url":"https://github.com/mealie-recipes/mealie","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}]}},{"cve":{"id":"CVE-2026-71211","sourceIdentifier":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","published":"2026-08-05T08:16:43.367","lastModified":"2026-08-05T08:16:43.367","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _create_gateway_secret) with no validation of scheme, host, or IP range; the value is stored verbatim. The gateway proxy endpoint (mlflow/server/gateway_api.py, raw_proxy) subsequently issues an HTTP request to that stored api_base plus a caller-supplied path and returns the full response body. MLflow's existing SSRF guard, _validate_webhook_url (which blocks non-global and metadata IPs), is never invoked anywhere in this gateway secret/proxy code path. The CreateGatewaySecret action additionally has no entry in the permission-validator map, so it requires only basic authentication rather than any specific scope, meaning any authenticated user — including read-only accounts — can create a secret pointing at an internal address and reach it via the proxy endpoint, potentially exposing cloud-instance IAM credentials via metadata services. This is related to CVE-2026-4035, which addresses a distinct mechanism in the same gateway-secret feature (server-side $ENV_VAR resolution inside the api_key field leaking credentials to the configured upstream); the finding here is an independent missing-validation gap in the api_base destination itself, unaffected by that fix."}],"affected":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","affectedData":[{"vendor":"mlflow","product":"mlflow","defaultStatus":"unknown","programFiles":["mlflow/server/handlers.py","mlflow/server/gateway_api.py"],"versions":[{"version":"0","lessThanOrEqual":"3.14.0","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":4.2}]},"weaknesses":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","description":[{"lang":"en","value":"CWE-918"}]}],"references":[{"url":"https://github.com/mlflow/mlflow/tree/v3.14.0/mlflow","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}]}},{"cve":{"id":"CVE-2026-71212","sourceIdentifier":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","published":"2026-08-05T08:16:43.503","lastModified":"2026-08-05T08:16:43.503","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"xidown (a yt-dlp/ffmpeg GUI wrapper) builds its yt-dlp command-line invocation (xidown/core/scanner.py and downloader.py) by appending the user-provided or scanned URL as a bare trailing positional argument, with no '--' end-of-options marker and no scheme validation anywhere in the codebase. Because yt-dlp parses any argument beginning with '-' as a CLI option rather than link text, a crafted 'URL' value such as -U (yt-dlp's self-update flag) or --exec=... is parsed as a real yt-dlp option instead of a URL, altering the tool's control flow before its own URL validation runs. Full code execution via --exec was not demonstrated in the single-URL flow tested, but the underlying argument-injection primitive is confirmed and unmitigated across all call sites."}],"affected":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","affectedData":[{"vendor":"indravoyager","product":"xidown","defaultStatus":"unknown","programFiles":["xidown/core/scanner.py","xidown/core/downloader.py"],"versions":[{"version":"0","lessThanOrEqual":"1.25.1.19","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","baseScore":4.4,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":1.8,"impactScore":2.5}]},"weaknesses":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","description":[{"lang":"en","value":"CWE-88"}]}],"references":[{"url":"https://cwe.mitre.org/data/definitions/88.html","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}]}},{"cve":{"id":"CVE-2026-71213","sourceIdentifier":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","published":"2026-08-05T08:16:43.647","lastModified":"2026-08-05T08:16:43.647","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Typemill's login endpoint (POST /tm/login, ControllerWebAuth::login()) performs no rate-limiting, failed-attempt counting, or account lockout when captcha is disabled, which is the default configuration. An unauthenticated attacker can send unlimited password-guessing requests against any account, including administrators, with no throttling. The only attempt-counting/lockout logic present in the same file protects an optional secondary email-authcode step and does not apply to the primary password check."}],"affected":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","affectedData":[{"vendor":"typemill","product":"typemill","defaultStatus":"unknown","programFiles":["system/typemill/Controllers/ControllerWebAuth.php"],"versions":[{"version":"0","lessThanOrEqual":"2.25.0","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":5.2}]},"weaknesses":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","description":[{"lang":"en","value":"CWE-307"}]}],"references":[{"url":"https://github.com/typemill/typemill","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}]}},{"cve":{"id":"CVE-2026-71214","sourceIdentifier":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","published":"2026-08-05T08:16:43.807","lastModified":"2026-08-05T08:16:43.807","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-server/src/app.ts) derives the caller's Hasura session role via getHasuraSession(), which prefers a session_variables object taken directly from the client-supplied JSON request body over the Authorization header's JWT claims, with no verification that the request actually originated from Hasura. By setting {\"session_variables\":{\"x-hasura-role\":\"aerie_admin\"}} in the body of a request to POST /command-expansion/put-expansion with no Authorization header, an unauthenticated attacker satisfies the role check and can insert arbitrary expansion rules into sequencing.expansion_rule, which govern how spacecraft activities are translated into commands. Separately, POST /put-dictionary is explicitly listed in the ENDPOINTS_WHITELIST and is exempt from any authentication, allowing unauthenticated writes of command dictionaries."}],"affected":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","affectedData":[{"vendor":"NASA-AMMOS","product":"plandev (sequencing-server)","defaultStatus":"unknown","programFiles":["sequencing-server/src/app.ts","sequencing-server/src/utils/hasura.ts"],"versions":[{"version":"0","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"weaknesses":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","description":[{"lang":"en","value":"CWE-306"}]}],"references":[{"url":"https://github.com/NASA-AMMOS/plandev","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}]}},{"cve":{"id":"CVE-2026-71215","sourceIdentifier":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","published":"2026-08-05T08:16:43.940","lastModified":"2026-08-05T08:16:43.940","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by both the include() and extend() template directives, resolves the target file path via path.resolve(root, filename) with no check afterward that the result remains inside root. Because path.resolve() discards root entirely when filename is an absolute path, and does not block '../' traversal sequences, and the resolved path is passed directly to fs.readFileSync() in loader.js with its contents compiled and rendered, an application that lets a sub-template name be influenced by external input (e.g. a query parameter passed into {{include page}}) allows an attacker to read arbitrary files on disk that the Node process can access."}],"affected":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","affectedData":[{"vendor":"art-template","product":"art-template","defaultStatus":"unknown","programFiles":["src/compile/adapter/resolve-filename.js","src/compile/adapter/loader.js"],"versions":[{"version":"0","lessThanOrEqual":"4.13.4","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}]},"weaknesses":[{"source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]}],"references":[{"url":"https://github.com/aui/art-template","source":"309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"}]}},{"cve":{"id":"CVE-2026-7105","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T08:16:44.080","lastModified":"2026-08-05T08:16:44.080","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Xpro Addons plugin for WordPress is vulnerable to unauthorized creation of data due to a missing capability check on the `get_menu_content_editor()` function in all versions up to, and including, 1.5.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create arbitrary published posts of the `xpro_content` custom post type with attacker-controlled titles. The created posts are publicly queryable on the front-end, enabling content injection, SEO spam, and database pollution."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"xpro","product":"Xpro Addons — 140+ Widgets for Elementor","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.5.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/tags/1.5.1/classes/class-ajax-handler.php#L137","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/tags/1.5.1/classes/class-ajax-handler.php#L45","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/tags/1.5.1/classes/class-ajax-handler.php#L64","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/trunk/classes/class-ajax-handler.php#L137","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3519528%40xpro-elementor-addons%2Ftrunk&old=3492377%40xpro-elementor-addons%2Ftrunk&sfp_email=&sfph_mail=","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/eef0796f-f56d-4be3-8fbd-010ac0fb3448?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-7441","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T08:16:44.247","lastModified":"2026-08-05T08:16:44.247","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Simple Yearly Archive plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `posttype` attribute of the `SimpleYearlyArchive` shortcode in all versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"alphawolf","product":"Simple Yearly Archive","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.2.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/simple-yearly-archive/tags/2.2.4/simple-yearly-archive.php#L135","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/simple-yearly-archive/tags/2.2.4/simple-yearly-archive.php#L502","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/simple-yearly-archive/trunk/simple-yearly-archive.php#L135","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?new=3525626%40simple-yearly-archive%2Ftrunk&old=3461850%40simple-yearly-archive%2Ftrunk","source":"security@wordfence.com"},{"url":"https://wordpress.org/plugins/simple-yearly-archive","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e6b35dc7-bd1d-4cdd-808f-41cf2ebfbb1e?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-7444","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T08:16:44.400","lastModified":"2026-08-05T08:16:44.400","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.16. This is due to missing or incorrect nonce validation on the `process_bulk_action()` function of `MWTSA_Stats_Table`. This makes it possible for unauthenticated attackers to delete arbitrary search-term records, including all associated search-history rows, via a forged request granted they can trick a user with access to the plugin's \"Search Analytics\" dashboard page (Administrator by default) into performing an action such as clicking on a link."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"cornelraiu-1","product":"Search Analytics for WP","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.4.16","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.2}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-352"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/search-analytics/tags/1.4.16/admin/includes/class.stats-table.php#L112","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/search-analytics/tags/1.4.16/admin/includes/class.stats-table.php#L125","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/search-analytics/tags/1.4.16/admin/includes/class.stats-table.php#L132","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/search-analytics/tags/1.4.16/admin/includes/class.stats.php#L99","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/search-analytics/trunk/admin/includes/class.stats-table.php#L132","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3525420%40search-analytics%2Ftrunk&old=3525419%40search-analytics%2Ftrunk&sfp_email=&sfph_mail=","source":"security@wordfence.com"},{"url":"https://wordpress.org/plugins/search-analytics/","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d62b8380-1679-40d8-a77f-17c583e88d39?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-7520","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T08:16:44.560","lastModified":"2026-08-05T08:16:44.560","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `sign_in()` and `sign_up()` AJAX handlers in all versions up to, and including, 3.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to relink the site's MailMunch integration to an attacker-controlled MailMunch account by submitting attacker-supplied credentials. Once relinked, all subscriber data captured by the plugin's forms is delivered to the attacker, and the forms/landing pages rendered on the site are pulled from the attacker's MailMunch account."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"mailmunch","product":"Mailmunch Forms for Mailchimp","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"3.2.7","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":5.2}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/mailchimp-forms-by-mailmunch/tags/3.2.7/admin/class-mailchimp-mailmunch-admin.php#L126","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/mailchimp-forms-by-mailmunch/tags/3.2.7/admin/class-mailchimp-mailmunch-admin.php#L134","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/mailchimp-forms-by-mailmunch/tags/3.2.7/includes/class-mailchimp-mailmunch.php#L219","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/mailchimp-forms-by-mailmunch/tags/3.2.7/includes/class-mailmunch-api.php#L354","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/mailchimp-forms-by-mailmunch/tags/3.2.7/includes/class-mailmunch-api.php#L371","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/mailchimp-forms-by-mailmunch/trunk/admin/class-mailchimp-mailmunch-admin.php#L134","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3593826%40mailchimp-forms-by-mailmunch%2Ftags%2F3.2.8&old=3445363%40mailchimp-forms-by-mailmunch%2Ftags%2F3.2.7","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/c9d00ee8-b9df-4044-a5e2-320391d6c9b1?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-7693","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T08:16:44.703","lastModified":"2026-08-05T08:16:44.703","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 2.1.5.1 due to insufficient sanitization of the `file` POST parameter on the `restoreBackup()` AJAX handler. The handler applies `esc_attr()` — an HTML-context sanitizer that does not strip shell metacharacters — and concatenates the result, unquoted, into a `php-cli -f … bmi_restore <file> <remote>` command passed to `exec()`. This makes it possible for authenticated attackers, with Administrator-level access (or any user granted the plugin's `do_backups` capability) and above, to execute arbitrary OS commands as the web-server user, bypassing WordPress hardening constants such as `DISALLOW_FILE_EDIT` and `DISALLOW_FILE_MODS` that would otherwise prevent code execution from the admin UI. This is an incomplete fix of CVE-2023-7002, which patched the same pattern only in the `$_POST['url']` path of `handleQuickMigration()`; the equivalent mitigations (`rawurlencode()` + explicit shell-metachar replacement + double-quoting in `exec()`) were never applied to `$backupName`."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"inisev","product":"Backup Migration","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-77"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/backup-backup/tags/2.1.5.1/includes/ajax.php#L3019","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/backup-backup/tags/2.1.5.1/includes/ajax.php#L3025","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/backup-backup/tags/2.1.5.1/includes/ajax.php#L3422","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/backup-backup/tags/2.1.5.1/includes/ajax.php#L3444","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/backup-backup/tags/2.1.5.1/includes/initializer.php#L136","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/backup-backup/trunk/includes/ajax.php#L3025","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?new=3540041%40backup-backup%2Ftags%2F2.1.5.2&old=3512153%40backup-backup%2Ftags%2F2.1.5.1","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/af6a7052-6dab-42f0-a2af-0cf459d309d7?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-7726","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T08:16:44.840","lastModified":"2026-08-05T08:16:44.840","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Layouts for WPBakery plugin for WordPress is vulnerable to unauthorized actions due to a missing capability check on the `Layouts_WPB_Remote::template_sync()` callback registered via `wp_ajax_nopriv_handle_sync` in all versions up to, and including, 1.1.3. This makes it possible for unauthenticated attackers to force the WordPress server to issue outbound HTTP requests to the plugin vendor's external API (`https://www.layoutsforwpbakery.com/wp-json/layoutsforwpbakery/v1/{templates,categories}`) and to write the JSON-decoded responses verbatim into the site's `wp_options` table via `set_transient()` — at any rate the attacker chooses, with no nonce verification, capability check, or rate limiting."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"techeshta","product":"Layouts for WPBakery","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.1.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":2.5}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/layouts-for-wpbakery/trunk/includes/api/class-layouts-remote.php#L46","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/layouts-for-wpbakery/trunk/includes/api/class-layouts-remote.php#L53","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/layouts-for-wpbakery/trunk/includes/class-layout-importer.php#L25","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?new=3543686%40layouts-for-wpbakery%2Ftrunk&old=3543685%40layouts-for-wpbakery%2Ftrunk","source":"security@wordfence.com"},{"url":"https://wordpress.org/plugins/layouts-for-wpbakery/","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2beaf82f-3709-48de-bcc2-535479c4fafe?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-10059","sourceIdentifier":"secalert@redhat.com","published":"2026-08-05T09:18:13.720","lastModified":"2026-08-05T09:18:13.720","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertently grants the tenant administrator the ability to mint a token for a ServiceAccount with cluster-wide administrative authority. This leads to a privilege escalation, allowing the tenant administrator to gain full control over the cluster."}],"affected":[{"source":"secalert@redhat.com","affectedData":[{"vendor":"Red Hat","product":"Multicluster Engine for Kubernetes","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"multicluster-engine/cluster-curator-controller-rhel9","cpes":["cpe:/a:redhat:multicluster_engine"]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.3,"impactScore":6.0}]},"weaknesses":[{"source":"secalert@redhat.com","type":"Primary","description":[{"lang":"en","value":"CWE-266"}]}],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-10059","source":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2483187","source":"secalert@redhat.com"}]}},{"cve":{"id":"CVE-2026-10090","sourceIdentifier":"secalert@redhat.com","published":"2026-08-05T09:18:14.667","lastModified":"2026-08-05T09:18:14.667","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with namespace-scoped \"edit\" privileges in an ACM hub namespace can create a Channel resource pointing to a Helm repository they control and a Subscription resource referencing it. The app-subscription controller fetches and applies the Helm chart contents with its own elevated authority, without verifying whether the subscription creator holds the \"open-cluster-management:subscription-admin\" role and without restricting applied resources to the subscription namespace. This allows the attacker to include cluster-scoped resources in the Helm chart, such as a ClusterRoleBinding granting the attacker's ServiceAccount the \"cluster-admin\" ClusterRole. Successful exploitation results in full cluster-admin privilege escalation. This contradicts the ACM documentation which states that non-subscription-admin users should have resources deployed into the subscription namespace only."}],"affected":[{"source":"secalert@redhat.com","affectedData":[{"vendor":"Red Hat","product":"Red Hat Advanced Cluster Management for Kubernetes 2","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhacm2/multicluster-operators-subscription-rhel9","cpes":["cpe:/a:redhat:acm:2"]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":9.9,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.1,"impactScore":6.0}]},"weaknesses":[{"source":"secalert@redhat.com","type":"Primary","description":[{"lang":"en","value":"CWE-267"}]}],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-10090","source":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2483292","source":"secalert@redhat.com"}]}},{"cve":{"id":"CVE-2026-8029","sourceIdentifier":"psirt@zte.com.cn","published":"2026-08-05T09:18:16.187","lastModified":"2026-08-05T09:18:16.187","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The ZTE Smart Life app contains an SQL injection vulnerability that allows attackers to execute UNION SELECT statements to query sensitive data in the feedback.db database across tables, including user accounts, phone numbers, feedback content, and local debug log paths, thereby enabling the theft of local privacy data."}],"affected":[{"source":"psirt@zte.com.cn","affectedData":[{"vendor":"ZTE","product":"SmartLife","defaultStatus":"unaffected","versions":[{"version":"ZTE_SL_V5.0.7and all prior released versions","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@zte.com.cn","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:P/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N","baseScore":3.9,"baseSeverity":"LOW","attackVector":"PHYSICAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":0.3,"impactScore":3.6}]},"weaknesses":[{"source":"psirt@zte.com.cn","type":"Secondary","description":[{"lang":"en","value":"CWE-89"}]}],"references":[{"url":"https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/874505866159001729","source":"psirt@zte.com.cn"}]}}]}