<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>vulnfeed</title>
    <link>https://vulnfeed.it</link>
    <description>Daily security vulnerability feed — NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub, OpenStack</description>
    <language>en-us</language>
    <lastBuildDate>Tue, 04 Aug 2026 17:55:00 +0000</lastBuildDate>
    <atom:link href="https://vulnfeed.it/feed.xml" rel="self" type="application/rss+xml"/>
  <item>
    <title>[UNKNOWN] DSA 6403-1: [SECURITY] [DSA 6403-1] nss security update</title>
    <link>https://lists.debian.org/debian-security-announce/2026/msg00314.html</link>
    <description>[SECURITY] [DSA 6403-1] nss security update</description>
    <pubDate>Wed, 29 Jul 2026 19:58:57 +0000</pubDate>
    <guid isPermaLink="false">https://lists.debian.org/debian-security-announce/2026/msg00314.html</guid>
  </item>
  <item>
    <title>[UNKNOWN] USN-8624-1: USN-8624-1: Sinatra vulnerability</title>
    <link>https://ubuntu.com/security/notices/USN-8624-1</link>
    <description>It was discovered that Sinatra did not properly handle header parsing, causing ETag generation to hang when given specific input. A remote attacker could possibly use this issue to cause a denial of service.</description>
    <pubDate>Wed, 29 Jul 2026 19:09:19 +0000</pubDate>
    <guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8624-1</guid>
  </item>
  <item>
    <title>[HIGH] USN-8623-1: USN-8623-1: Linux kernel (NVIDIA) vulnerabilities</title>
    <link>https://ubuntu.com/security/notices/USN-8623-1</link>
    <description>Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - Arm Firmware Framework for ARMv8-A(FFA); (CVE-2026-53354, CVE-2026-64520)</description>
    <pubDate>Wed, 29 Jul 2026 13:53:58 +0000</pubDate>
    <guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8623-1</guid>
  </item>
  <item>
    <title>[HIGH] USN-8622-1: USN-8622-1: Linux kernel (NVIDIA) vulnerabilities</title>
    <link>https://ubuntu.com/security/notices/USN-8622-1</link>
    <description>Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - Arm Firmware Framework for ARMv8-A(FFA); (CVE-2026-53354, CVE-2026-64520)</description>
    <pubDate>Wed, 29 Jul 2026 13:50:57 +0000</pubDate>
    <guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8622-1</guid>
  </item>
  <item>
    <title>[MEDIUM] USN-8620-2: USN-8620-2: Linux kernel (Azure FIPS) vulnerabilities</title>
    <link>https://ubuntu.com/security/notices/USN-8620-2</link>
    <description>Maxim Suhanov discovered that the NTFS file system implementation in the Linux kernel did not properly validate file name length in certain situations, leading to an out-of-bounds read. An attacker could use this to construct a malicious NTFS image that, when mounted and operated on, could expose sensitive information (kernel memory). (CVE-2023-45896) It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local at</description>
    <pubDate>Wed, 29 Jul 2026 07:46:56 +0000</pubDate>
    <guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8620-2</guid>
  </item>
  <item>
    <title>[CRITICAL] USN-8615-2: USN-8615-2: Linux kernel (Raspberry Pi) vulnerabilities</title>
    <link>https://ubuntu.com/security/notices/USN-8615-2</link>
    <description>It was discovered that a logic flaw existed in the XFRM ESP-in-TCP subsystem in the Linux kernel when handling socket buffer fragments. This flaw is known as Fragnesia. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-43503) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - InfiniBand drivers; - STMicroelectronics net</description>
    <pubDate>Wed, 29 Jul 2026 07:43:21 +0000</pubDate>
    <guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8615-2</guid>
  </item>
  <item>
    <title>[UNKNOWN] FG-IR-26-127: Out-Of-Bounds Write in administrative interface</title>
    <link>https://fortiguard.fortinet.com/psirt/FG-IR-26-127</link>
    <description>CVSSv3 Score: 6.7 An out-of-bounds write vulnerability [CWE-787] in FortiWeb CGI daemon may allow a remote privileged attacker to execute arbitrary code or command via crafted HTTP requests. Revised on 2026-04-15 00:00:00</description>
    <pubDate>Wed, 15 Apr 2026 07:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-127</guid>
  </item>
  <item>
    <title>[MEDIUM] FG-IR-26-139: Linux Kernel Vulnerability copy.fail - CVE-2026-31431</title>
    <link>https://fortiguard.fortinet.com/psirt/FG-IR-26-139</link>
    <description>CVSSv3 Score: 7.8 CVE-2026-31431In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly. Revised on 2026-05-13 00:00:00</description>
    <pubDate>Wed, 13 May 2026 07:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-139</guid>
  </item>
  <item>
    <title>[HIGH] FG-IR-26-144: Linux Kernel vulnerability Dirty Frag</title>
    <link>https://fortiguard.fortinet.com/psirt/FG-IR-26-144</link>
    <description>CVSSv3 Score: 7.9 Linux kernel is impacted by CVE-2026-43284 and CVE-2026-43500 which chained together create the Dirty Frag vulnerability.CVE-2026-43284In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP marks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_iter(), so later paths that may modify packet data can first make a private copy. The IPv4/IPv</description>
    <pubDate>Wed, 03 Jun 2026 07:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-144</guid>
  </item>
  <item>
    <title>[UNKNOWN] USN-8561-2: USN-8561-2: FreeRDP regression</title>
    <link>https://ubuntu.com/security/notices/USN-8561-2</link>
    <description>USN-8561-1 fixed vulnerabilities in FreeRDP. Unfortunately, the upgrade to version 3.30.0 introduced a regression in the clipboard functionality. This update fixes the problem. We apologize for the inconvenience. Original advisory details: It was discovered that FreeRDP contained multiple security issues. An attacker could possibly use these issues to obtain sensitive information, cause FreeRDP to crash, resulting in a denial of service, or execute arbitrary code.</description>
    <pubDate>Tue, 28 Jul 2026 18:08:13 +0000</pubDate>
    <guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8561-2</guid>
  </item>
  <item>
    <title>[UNKNOWN] FG-IR-25-545: Trusted hosts bypass via SSH</title>
    <link>https://fortiguard.fortinet.com/psirt/FG-IR-25-545</link>
    <description>CVSSv3 Score: 1.8 An Improper Privilege Management vulnerability [CWE-269] in FortiOS, FortiProxy and FortiPAM may allow an authenticated administrator to bypass the trusted host policy via crafted CLI command. Revised on 2026-05-27 00:00:00</description>
    <pubDate>Tue, 18 Nov 2025 08:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-25-545</guid>
  </item>
  <item>
    <title>[UNKNOWN] FG-IR-24-452: Insertion of Sensitive 2FA Information in logs and debug command</title>
    <link>https://fortiguard.fortinet.com/psirt/FG-IR-24-452</link>
    <description>CVSSv3 Score: 2.6 An Insertion of Sensitive Information into Log File vulnerability [CWE-532] in FortiOS may allow an attacker with at least read-only privileges to retrieve sensitive 2FA-related information via observing logs or via diagnose command. Revised on 2026-06-08 00:00:00</description>
    <pubDate>Tue, 14 Oct 2025 07:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-24-452</guid>
  </item>
  <item>
    <title>[UNKNOWN] FG-IR-26-154: Buffer overread in authd and wad daemon</title>
    <link>https://fortiguard.fortinet.com/psirt/FG-IR-26-154</link>
    <description>CVSSv3 Score: 4.1 A buffer over-read vulnerability [CWE-126] in FortiOS, FortiProxy, and FortiSASE may allow an authenticated remote attacker to return a portion of device memory in the redirect response via submitting a specially crafted request. Revised on 2026-07-14 00:00:00</description>
    <pubDate>Tue, 14 Jul 2026 07:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-154</guid>
  </item>
  <item>
    <title>[UNKNOWN] FG-IR-26-149: Cross-Site Scripting in Domain parameter</title>
    <link>https://fortiguard.fortinet.com/psirt/FG-IR-26-149</link>
    <description>CVSSv3 Score: 5.3 An Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability [CWE-80] in FortiSIEM may allow a privileged administrator to execute unauthorized commands via crafted requests. Revised on 2026-07-14 00:00:00</description>
    <pubDate>Tue, 14 Jul 2026 07:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-149</guid>
  </item>
  <item>
    <title>[UNKNOWN] FG-IR-26-152: Header injection in Web Filter warning page</title>
    <link>https://fortiguard.fortinet.com/psirt/FG-IR-26-152</link>
    <description>CVSSv3 Score: 3.4 An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] in FortiOS and FortiProxy may allow an attacker in possession of a valid web filter override token to inject arbitrary headers via tricking a user into clicking on a crafted link. Revised on 2026-07-14 00:00:00</description>
    <pubDate>Tue, 14 Jul 2026 07:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-152</guid>
  </item>
  <item>
    <title>[UNKNOWN] FG-IR-26-153: Header injection in captive portal authentication form</title>
    <link>https://fortiguard.fortinet.com/psirt/FG-IR-26-153</link>
    <description>CVSSv3 Score: 3.1 An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] in FortiOS and FortiProxy captive portal may allow an attacker able to intercept and modify a user's authentication request to inject arbitrary headers via crafted HTTP requests. Revised on 2026-07-14 00:00:00</description>
    <pubDate>Tue, 14 Jul 2026 07:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-153</guid>
  </item>
  <item>
    <title>[UNKNOWN] FG-IR-26-147: Missed certificate verification in AD Connector communication with FortiClient EMS</title>
    <link>https://fortiguard.fortinet.com/psirt/FG-IR-26-147</link>
    <description>CVSSv3 Score: 6.7 An Improper Certificate Validation vulnerability [CWE-295] in FortiClient EMS may allow a remote unauthenticated attacker to impersonate an AD Connector via a valid API Key. Revised on 2026-07-14 00:00:00</description>
    <pubDate>Tue, 14 Jul 2026 07:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-147</guid>
  </item>
  <item>
    <title>[UNKNOWN] FG-IR-26-146: Out of bounds read in GUI</title>
    <link>https://fortiguard.fortinet.com/psirt/FG-IR-26-146</link>
    <description>CVSSv3 Score: 7.0 An out of bounds read [CWE-125] vulnerability in FortiAuthenticator may allow a remote unauthenticated attacker to retrieve sensitive information via a specially crafted request. Revised on 2026-07-14 00:00:00</description>
    <pubDate>Tue, 14 Jul 2026 07:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-146</guid>
  </item>
  <item>
    <title>[UNKNOWN] FG-IR-26-151: Path traversal in CLI command allows deletion of root file system</title>
    <link>https://fortiguard.fortinet.com/psirt/FG-IR-26-151</link>
    <description>CVSSv3 Score: 5.0 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiOS, FortiPAM, FortiProxy and FortiSwitch Manager may allow a privileged authenticated attacker with physical access to the device to delete the file system via crafted CLI commands. Revised on 2026-07-14 00:00:00</description>
    <pubDate>Tue, 14 Jul 2026 07:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-151</guid>
  </item>
  <item>
    <title>[UNKNOWN] FG-IR-26-150: SSL-VPN Reflected XSS</title>
    <link>https://fortiguard.fortinet.com/psirt/FG-IR-26-150</link>
    <description>CVSSv3 Score: 6.1 An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiOS, FortiProxy, FortiPAM and FortiSwitch-Manager Agentless SSL-VPN may allow an authenticated remote user to execute code or commands via crafted requests. Revised on 2026-07-14 00:00:00</description>
    <pubDate>Tue, 14 Jul 2026 07:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-150</guid>
  </item>
  <item>
    <title>[UNKNOWN] FG-IR-26-148: Stack Buffer Overflow in Log Report</title>
    <link>https://fortiguard.fortinet.com/psirt/FG-IR-26-148</link>
    <description>CVSSv3 Score: 5.9 A Stack-based Buffer Overflow vulnerability [CWE-121] in FortiOS, FortiProxy and FortiPAM may allow a privileged authenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands via crafted HTTP requests. Revised on 2026-07-14 00:00:00</description>
    <pubDate>Tue, 14 Jul 2026 07:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-148</guid>
  </item>
  <item>
    <title>[UNKNOWN] FG-IR-26-155: Supers override fails to properly override supervisor address</title>
    <link>https://fortiguard.fortinet.com/psirt/FG-IR-26-155</link>
    <description>CVSSv3 Score: 6.9 An Improper Restriction of Communication Channel to Intended Endpoints [CWE-923] vulnerability in FortiSIEM Windows Agent may allow an unauthorized attacker on the same local network to execute arbitrary code via spoofing the supervisors hostname when the Windows device is configured with the 'Supers Override' feature. Revised on 2026-07-14 00:00:00</description>
    <pubDate>Tue, 14 Jul 2026 07:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-155</guid>
  </item>
  <item>
    <title>[UNKNOWN] FG-IR-26-145: Unauthenticated VNC access exposed on all interfaces</title>
    <link>https://fortiguard.fortinet.com/psirt/FG-IR-26-145</link>
    <description>CVSSv3 Score: 7.7 An Exposure of Resource to Wrong Sphere vulnerability [CWE-668] in FortiSandbox may allow an unauthenticated attacker to access the VNC server of VMs performing scanning via network requests. Revised on 2026-07-14 00:00:00</description>
    <pubDate>Tue, 14 Jul 2026 07:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-145</guid>
  </item>
  <item>
    <title>[UNKNOWN] FG-IR-26-101: 2FA request can be replayed without a valid token after one successful request</title>
    <link>https://fortiguard.fortinet.com/psirt/FG-IR-26-101</link>
    <description>CVSSv3 Score: 6.7 An Improper authentication vulnerability [CWE-287] in FortiSOAR web GUI may allow an unauthenticated attacker to bypass authentication via replaying captured 2FA request. The attack requires being able to intercept and decrypt authentication traffic and precise timing to replay the request before token expiration. Revised on 2026-04-14 00:00:00</description>
    <pubDate>Tue, 14 Apr 2026 07:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-101</guid>
  </item>
  <item>
    <title>[UNKNOWN] FG-IR-26-115: Arbitrary directory delete on vmimages delete feature</title>
    <link>https://fortiguard.fortinet.com/psirt/FG-IR-26-115</link>
    <description>CVSSv3 Score: 6.2 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiSandbox, FortiSandbox Cloud, FortiSandbox PaaS and FortiSandbox Cloud WEB UI may allow a privileged attacker with super-admin profile and CLI access to delete an arbitrary directory via HTTP crafted requests. Revised on 2026-04-14 00:00:00</description>
    <pubDate>Tue, 14 Apr 2026 07:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-115</guid>
  </item>
  <item>
    <title>[UNKNOWN] FG-IR-26-126: Axios npm Package Compromised</title>
    <link>https://fortiguard.fortinet.com/psirt/FG-IR-26-126</link>
    <description>On March 31, 2026, the Axios npm package was compromised via a maintainer account takeover. Two malicious versions were published - axios@1.14.1 and axios@0.30.4 - which introduced a hidden dependency (plain-crypto-js@4.2.1) able to execute a post‑install script deploying a cross‑platform Remote Access Trojan (RAT) on Windows, macOS, and Linux systems. Revised on 2026-04-14 00:00:00</description>
    <pubDate>Tue, 14 Apr 2026 07:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-126</guid>
  </item>
  <item>
    <title>[UNKNOWN] FG-IR-26-105: Clear-text credentials retrievable with IP modification for LDAP</title>
    <link>https://fortiguard.fortinet.com/psirt/FG-IR-26-105</link>
    <description>CVSSv3 Score: 4.1 A Storing Passwords in a Recoverable Format vulnerability [CWE-257] in FortiSOAR may allow an authenticated remote attacker to retrieve Service account password via server address modification in LDAP configuration. Revised on 2026-04-14 00:00:00</description>
    <pubDate>Tue, 14 Apr 2026 07:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-105</guid>
  </item>
  <item>
    <title>[UNKNOWN] FG-IR-26-104: Clear-text credentials retrievable with IP modification for connectors</title>
    <link>https://fortiguard.fortinet.com/psirt/FG-IR-26-104</link>
    <description>CVSSv3 Score: 4.1 A Storing Passwords in a Recoverable Format vulnerability [CWE-257] in FortiSOAR may allow an authenticated remote attacker to retrieve passwords for multiple installed connectors via server address modification in connector configuration. Revised on 2026-04-14 00:00:00</description>
    <pubDate>Tue, 14 Apr 2026 07:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-104</guid>
  </item>
  <item>
    <title>[UNKNOWN] FG-IR-26-106: Cleartext Credentials in response for API endpoints</title>
    <link>https://fortiguard.fortinet.com/psirt/FG-IR-26-106</link>
    <description>CVSSv3 Score: 6.2 A Cleartext Transmission of Sensitive Information vulnerability [CWE-319] in FortiSOAR may allow an authenticated attacker to view cleartext password in response for Secure Message Exchange and Radius queries, if configured Revised on 2026-04-14 00:00:00</description>
    <pubDate>Tue, 14 Apr 2026 07:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-106</guid>
  </item>
  <item>
    <title>[UNKNOWN] FG-IR-26-113: Credential disclosure in LDAP configuration web page.</title>
    <link>https://fortiguard.fortinet.com/psirt/FG-IR-26-113</link>
    <description>CVSSv3 Score: 2.5 An Insufficiently protected credentials vulnerability [CWE-522] in FortiSanbox and FortiSanbox PaaS GUI may allow an authenticated administrator to read LDAP server credentials via client-side inspection. Revised on 2026-04-14 00:00:00</description>
    <pubDate>Tue, 14 Apr 2026 07:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-113</guid>
  </item>
  <item>
    <title>[UNKNOWN] FG-IR-26-107: Hardcoded symmetric encryption key for Postgresql</title>
    <link>https://fortiguard.fortinet.com/psirt/FG-IR-26-107</link>
    <description>CVSSv3 Score: 5.2 A use of hard-coded cryptographic key vulnerability [CWE 321] in FortiClientEMS may allow an attacker in possession of an encrypted dump of the database to decrypt it. Revised on 2026-04-14 00:00:00</description>
    <pubDate>Tue, 14 Apr 2026 07:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-107</guid>
  </item>
  <item>
    <title>[UNKNOWN] FG-IR-26-121: Heap-based buffer overflow in oftpd daemon</title>
    <link>https://fortiguard.fortinet.com/psirt/FG-IR-26-121</link>
    <description>CVSSv3 Score: 7.3 A heap-based buffer overflow vulnerability [CWE-122] in FortiAnalyzer Cloud oftpd daemon may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests. Successful exploitation would require a large amount of effort in preparation because of ASLR and network segmentation Revised on 2026-04-14 00:00:00</description>
    <pubDate>Tue, 14 Apr 2026 07:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-121</guid>
  </item>
  <item>
    <title>[UNKNOWN] FG-IR-26-108: Integer Overflow Denial of Service in administrative interface</title>
    <link>https://fortiguard.fortinet.com/psirt/FG-IR-26-108</link>
    <description>CVSSv3 Score: 4.4 An Integer Overflow or Wraparound vulnerability [CWE-190] in FortiWeb may allow a privileged authenticated attacker to perform a denial of service of the system via crafted HTTP requests. Revised on 2026-04-14 00:00:00</description>
    <pubDate>Tue, 14 Apr 2026 07:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-108</guid>
  </item>
  <item>
    <title>[UNKNOWN] FG-IR-26-125: Missing Authentication for critical function in CAPWAP daemon</title>
    <link>https://fortiguard.fortinet.com/psirt/FG-IR-26-125</link>
    <description>CVSSv3 Score: 6.2 A missing authentication for critical function vulnerability [CWE-306] in FortiOS and FortiSwitchManager CAPWAP daemon may allow a local unauthenticated attacker on the same local IP subnet to write device configuration via specially crafted requests. To be successful, this attack requires the targeted FortiGate device to run a specific, non default configuration. Revised on 2026-04-14 00:00:00</description>
    <pubDate>Tue, 14 Apr 2026 07:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-125</guid>
  </item>
  <item>
    <title>[UNKNOWN] FG-IR-26-114: Multiple Path traversals in CLI</title>
    <link>https://fortiguard.fortinet.com/psirt/FG-IR-26-114</link>
    <description>CVSSv3 Score: 6.2 Multiple Relative Path Traversal vulnerabilities [CWE-23] in FortiWeb may allow a local privileged attacker to execute unauthorized code on the underlying system via crafted CLI commands. Revised on 2026-04-14 00:00:00</description>
    <pubDate>Tue, 14 Apr 2026 07:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-114</guid>
  </item>
  <item>
    <title>[UNKNOWN] FG-IR-26-102: Multiple SQL Injections</title>
    <link>https://fortiguard.fortinet.com/psirt/FG-IR-26-102</link>
    <description>CVSSv3 Score: 7.1 An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiClientEMS may allow an authenticated attacker to run arbitrary SQL queries on the database via sending crafted requests. Revised on 2026-04-14 00:00:00</description>
    <pubDate>Tue, 14 Apr 2026 07:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-102</guid>
  </item>
  <item>
    <title>[UNKNOWN] FG-IR-26-110: Multiple Stored XSS</title>
    <link>https://fortiguard.fortinet.com/psirt/FG-IR-26-110</link>
    <description>CVSSv3 Score: 4.3 An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiSandbox and FortiSandbox Cloud may allow a privileged attacker to perform a stored XSS attack via crafted HTTP requests. Revised on 2026-04-14 00:00:00</description>
    <pubDate>Tue, 14 Apr 2026 07:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-110</guid>
  </item>
  <item>
    <title>[UNKNOWN] FG-IR-26-100: OS Command Injection through API endpoint</title>
    <link>https://fortiguard.fortinet.com/psirt/FG-IR-26-100</link>
    <description>CVSSv3 Score: 9.1 An Improper Neutralization of Special Elements used in an OS Command ('OS command injection') vulnerability [CWE-78] in FortiSandbox may allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests. Revised on 2026-04-14 00:00:00</description>
    <pubDate>Tue, 14 Apr 2026 07:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-100</guid>
  </item>
  <item>
    <title>[UNKNOWN] FG-IR-26-118: Open Redirection via Import CSV option</title>
    <link>https://fortiguard.fortinet.com/psirt/FG-IR-26-118</link>
    <description>CVSSv3 Score: 2.2 An URL Redirection to Untrusted Site ('Open Redirect') vulnerability [CWE-601] in FortiNAC-F may allow a remote privileged attacker with system administrator role to redirect users to an arbitrary website via crafted CSV file. Revised on 2026-04-14 00:00:00</description>
    <pubDate>Tue, 14 Apr 2026 07:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-118</guid>
  </item>
  <item>
    <title>[UNKNOWN] FG-IR-26-122: Path Traversal in CLI</title>
    <link>https://fortiguard.fortinet.com/psirt/FG-IR-26-122</link>
    <description>CVSSv3 Score: 5.4 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] in the command line interpreter of FortiOS, FortiPAM, FortiProxy and FortiSwitchManager may allow a privileged attacker to achieve arbitrary write or delete files via specifically crafted arguments to existing commands. Revised on 2026-04-14 00:00:00</description>
    <pubDate>Tue, 14 Apr 2026 07:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-122</guid>
  </item>
  <item>
    <title>[UNKNOWN] FG-IR-26-138: Arbitrary log file read in administrative interface</title>
    <link>https://fortiguard.fortinet.com/psirt/FG-IR-26-138</link>
    <description>CVSSv3 Score: 4.0 An Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability [CWE-88] in FortiDeceptor WEB UI may allow an authenticated attacker with at least read-only admin permission to read log files via HTTP crafted requests. Revised on 2026-05-12 00:00:00</description>
    <pubDate>Tue, 12 May 2026 07:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-138</guid>
  </item>
  <item>
    <title>[UNKNOWN] FG-IR-26-131: Command injection in CLI</title>
    <link>https://fortiguard.fortinet.com/psirt/FG-IR-26-131</link>
    <description>CVSSv3 Score: 6.1 An improper neutralization of special elements used in an OS command ("OS Command Injection") vulnerability [CWE-78] in FortiAP, FortiAP-U &amp;amp; FortiAP-W2 CLI may allow an authenticated privileged attacker to execute unauthorized code or commands via crafted CLI requests. Revised on 2026-05-12 00:00:00</description>
    <pubDate>Tue, 12 May 2026 07:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-131</guid>
  </item>
  <item>
    <title>[UNKNOWN] FG-IR-26-137: DoS due to unsafe function in signal handler</title>
    <link>https://fortiguard.fortinet.com/psirt/FG-IR-26-137</link>
    <description>CVSSv3 Score: 5.2 A use of potentially Dangerous Function vulnerability [CWE-676] in FortiAnalyzer and FortiManager API may allow an authenticated attacker to cause a system hang via multiple specially crafted HTTP requests causing crashes. This happens if internal locks are aligned, which is out of control of the attacker. Revised on 2026-05-12 00:00:00</description>
    <pubDate>Tue, 12 May 2026 07:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-137</guid>
  </item>
  <item>
    <title>[UNKNOWN] FG-IR-26-129: Hardcoded Encryption Key Used for VPN Saved Passwords</title>
    <link>https://fortiguard.fortinet.com/psirt/FG-IR-26-129</link>
    <description>CVSSv3 Score: 2.1 A Missing Authorization [CWE-862] in FortiClient Windows may allow an authenticated local attacker to decrypt a currently logged in users VPN password via use of an unprotected DLL function. Revised on 2026-05-12 00:00:00</description>
    <pubDate>Tue, 12 May 2026 07:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-129</guid>
  </item>
  <item>
    <title>[UNKNOWN] FG-IR-26-128: Improper access control on API endpoints</title>
    <link>https://fortiguard.fortinet.com/psirt/FG-IR-26-128</link>
    <description>CVSSv3 Score: 9.1 An Improper Access Control vulnerability [CWE-284] in FortiAuthenticator may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. Revised on 2026-05-12 00:00:00</description>
    <pubDate>Tue, 12 May 2026 07:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-128</guid>
  </item>
  <item>
    <title>[UNKNOWN] FG-IR-26-136: Incorrect global authorization</title>
    <link>https://fortiguard.fortinet.com/psirt/FG-IR-26-136</link>
    <description>CVSSv3 Score: 9.1 A missing authorization vulnerability [CWE-862] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to execute unauthorized code or commands via HTTP requests. Revised on 2026-05-12 00:00:00</description>
    <pubDate>Tue, 12 May 2026 07:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-136</guid>
  </item>
  <item>
    <title>[UNKNOWN] FG-IR-26-133: OS command injection in CLI</title>
    <link>https://fortiguard.fortinet.com/psirt/FG-IR-26-133</link>
    <description>CVSSv3 Score: 6.5 An OS command injection vulnerabtility [CWE-78] in FortiAP and FortiAP-W2 cli may allow an authenticated attacker to execute unauthorized code or commands via a specifically crafted cli command. Revised on 2026-05-12 00:00:00</description>
    <pubDate>Tue, 12 May 2026 07:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-133</guid>
  </item>
  <item>
    <title>[UNKNOWN] FG-IR-26-130: OTP Disclosure via Exported TokenContentProvider</title>
    <link>https://fortiguard.fortinet.com/psirt/FG-IR-26-130</link>
    <description>CVSSv3 Score: 5.0 An improper export of Android application components [CWE-926] in FortiTokenAndroid may allow other applications on the device to read the OTP code via an exported Content Provider URI. Revised on 2026-05-12 00:00:00</description>
    <pubDate>Tue, 12 May 2026 07:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-130</guid>
  </item>
  <item>
    <title>[UNKNOWN] FG-IR-26-123: Out-of-bounds access in CAPWAP daemon</title>
    <link>https://fortiguard.fortinet.com/psirt/FG-IR-26-123</link>
    <description>CVSSv3 Score: 8.3 An Out-Of-Bounds Write vulnerability [CWE-787] in FortiOS capwap daemon may allow an attacker controlling an authenticated FortiAP FortiExtender or FortiSwitch to gain execution privileges on the FortiGate device Revised on 2026-05-12 00:00:00</description>
    <pubDate>Tue, 12 May 2026 07:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-123</guid>
  </item>
  <item>
    <title>[UNKNOWN] FG-IR-26-132: SQL command injection in administrative portal</title>
    <link>https://fortiguard.fortinet.com/psirt/FG-IR-26-132</link>
    <description>CVSSv3 Score: 6.3 An improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiMail may allow an authenticated privileged attacker to execute unauthorized code or commands via specifically crafted HTTP or HTTPS requests. Revised on 2026-05-12 00:00:00</description>
    <pubDate>Tue, 12 May 2026 07:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-132</guid>
  </item>
  <item>
    <title>[UNKNOWN] FG-IR-26-134: User controlled SQL commands</title>
    <link>https://fortiguard.fortinet.com/psirt/FG-IR-26-134</link>
    <description>CVSSv3 Score: 5.1 An improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability [CWE-89] in FortiNDR may allow an authenticated attacker to execute arbitrary SQL commands on selected databases and tables via specifically crafted HTTP requests. Revised on 2026-05-12 00:00:00</description>
    <pubDate>Tue, 12 May 2026 07:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-134</guid>
  </item>
  <item>
    <title>[UNKNOWN] FG-IR-25-1052: LDAP authentication bypass in Agentless VPN and FSSO</title>
    <link>https://fortiguard.fortinet.com/psirt/FG-IR-25-1052</link>
    <description>CVSSv3 Score: 7.5 An Authentication Bypass by Primary Weakness vulnerability [CWE-305] in FortiOS fnbamd may allow an unauthenticated attacker to bypass LDAP authentication of Agentless VPN or FSSO policy, under specific LDAP server configuration. Revised on 2026-07-04 00:00:00</description>
    <pubDate>Tue, 10 Feb 2026 08:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-25-1052</guid>
  </item>
  <item>
    <title>[UNKNOWN] FG-IR-26-140: Improper access control in API endpoints</title>
    <link>https://fortiguard.fortinet.com/psirt/FG-IR-26-140</link>
    <description>CVSSv3 Score: 6.2 An improper access control vulnerability [CWE-284] in FortiPortal API endpoints may allow a remote privileged attacker with organization user role to obtain sensitive network configuration data via crafted HTTP requests. Revised on 2026-06-09 00:00:00</description>
    <pubDate>Tue, 09 Jun 2026 07:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-140</guid>
  </item>
  <item>
    <title>[UNKNOWN] FG-IR-26-143: Restricted CLI escape using Lua</title>
    <link>https://fortiguard.fortinet.com/psirt/FG-IR-26-143</link>
    <description>CVSSv3 Score: 6.0 An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] in FortiOS and FortiProxy may allow an authenticated admin to execute lua scripts via crafted CLI commands. Revised on 2026-06-09 00:00:00</description>
    <pubDate>Tue, 09 Jun 2026 07:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-143</guid>
  </item>
  <item>
    <title>[UNKNOWN] FG-IR-26-141: Second-Order OS Command Injection via JSON Input on start vnc feature</title>
    <link>https://fortiguard.fortinet.com/psirt/FG-IR-26-141</link>
    <description>CVSSv3 Score: 9.1 An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests. Revised on 2026-06-09 00:00:00</description>
    <pubDate>Tue, 09 Jun 2026 07:00:00 +0000</pubDate>
    <guid isPermaLink="false">https://fortiguard.fortinet.com/psirt/FG-IR-26-141</guid>
  </item>
  <item>
    <title>[UNKNOWN] USN-8625-1: USN-8625-1: OpenSSL vulnerability</title>
    <link>https://ubuntu.com/security/notices/USN-8625-1</link>
    <description>It was discovered that OpenSSL incorrectly allocated memory buffers in the SSL/TLS state machine when receiving handshake data. A remote attacker could possibly use this issue to cause OpenSSL to consume excessive memory, leading to a denial of service. This issue is known as the "HollowByte" denial of service.</description>
    <pubDate>Thu, 30 Jul 2026 13:38:32 +0000</pubDate>
    <guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8625-1</guid>
  </item>
  <item>
    <title>[HIGH] DSA 6404-1: [SECURITY] [DSA 6404-1] expat security update</title>
    <link>https://lists.debian.org/debian-security-announce/2026/msg00315.html</link>
    <description>[SECURITY] [DSA 6404-1] expat security update</description>
    <pubDate>Thu, 30 Jul 2026 08:38:59 +0000</pubDate>
    <guid isPermaLink="false">https://lists.debian.org/debian-security-announce/2026/msg00315.html</guid>
  </item>
  <item>
    <title>[MEDIUM] DSA 6410-1: [SECURITY] [DSA 6410-1] libssh security update</title>
    <link>https://lists.debian.org/debian-security-announce/2026/msg00321.html</link>
    <description>[SECURITY] [DSA 6410-1] libssh security update</description>
    <pubDate>Sun, 02 Aug 2026 07:37:01 +0000</pubDate>
    <guid isPermaLink="false">https://lists.debian.org/debian-security-announce/2026/msg00321.html</guid>
  </item>
  <item>
    <title>[UNKNOWN] DSA 6409-1: [SECURITY] [DSA 6409-1] libgd2 security update</title>
    <link>https://lists.debian.org/debian-security-announce/2026/msg00320.html</link>
    <description>[SECURITY] [DSA 6409-1] libgd2 security update</description>
    <pubDate>Sat, 01 Aug 2026 09:24:47 +0000</pubDate>
    <guid isPermaLink="false">https://lists.debian.org/debian-security-announce/2026/msg00320.html</guid>
  </item>
  <item>
    <title>[CRITICAL] DSA 6408-1: [SECURITY] [DSA 6408-1] chromium security update</title>
    <link>https://lists.debian.org/debian-security-announce/2026/msg00319.html</link>
    <description>[SECURITY] [DSA 6408-1] chromium security update</description>
    <pubDate>Sat, 01 Aug 2026 00:55:58 +0000</pubDate>
    <guid isPermaLink="false">https://lists.debian.org/debian-security-announce/2026/msg00319.html</guid>
  </item>
  <item>
    <title>[UNKNOWN] DSA 6407-1: [SECURITY] [DSA 6407-1] incus security update</title>
    <link>https://lists.debian.org/debian-security-announce/2026/msg00318.html</link>
    <description>[SECURITY] [DSA 6407-1] incus security update</description>
    <pubDate>Fri, 31 Jul 2026 21:35:24 +0000</pubDate>
    <guid isPermaLink="false">https://lists.debian.org/debian-security-announce/2026/msg00318.html</guid>
  </item>
  <item>
    <title>[HIGH] DSA 6406-1: [SECURITY] [DSA 6406-1] php8.4 security update</title>
    <link>https://lists.debian.org/debian-security-announce/2026/msg00317.html</link>
    <description>[SECURITY] [DSA 6406-1] php8.4 security update</description>
    <pubDate>Fri, 31 Jul 2026 21:17:27 +0000</pubDate>
    <guid isPermaLink="false">https://lists.debian.org/debian-security-announce/2026/msg00317.html</guid>
  </item>
  <item>
    <title>[MEDIUM] USN-8620-4: USN-8620-4: Linux kernel (Intel IoTG) vulnerabilities</title>
    <link>https://ubuntu.com/security/notices/USN-8620-4</link>
    <description>Maxim Suhanov discovered that the NTFS file system implementation in the Linux kernel did not properly validate file name length in certain situations, leading to an out-of-bounds read. An attacker could use this to construct a malicious NTFS image that, when mounted and operated on, could expose sensitive information (kernel memory). (CVE-2023-45896) It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local at</description>
    <pubDate>Fri, 31 Jul 2026 15:00:56 +0000</pubDate>
    <guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8620-4</guid>
  </item>
  <item>
    <title>[HIGH] DSA 6405-1: [SECURITY] [DSA 6405-1] linux security update</title>
    <link>https://lists.debian.org/debian-security-announce/2026/msg00316.html</link>
    <description>[SECURITY] [DSA 6405-1] linux security update</description>
    <pubDate>Fri, 31 Jul 2026 14:14:07 +0000</pubDate>
    <guid isPermaLink="false">https://lists.debian.org/debian-security-announce/2026/msg00316.html</guid>
  </item>
  <item>
    <title>[MEDIUM] USN-8620-3: USN-8620-3: Linux kernel (Intel IoTG) vulnerabilities</title>
    <link>https://ubuntu.com/security/notices/USN-8620-3</link>
    <description>Maxim Suhanov discovered that the NTFS file system implementation in the Linux kernel did not properly validate file name length in certain situations, leading to an out-of-bounds read. An attacker could use this to construct a malicious NTFS image that, when mounted and operated on, could expose sensitive information (kernel memory). (CVE-2023-45896) It was discovered that some AMD processors did not properly clear data in the floating point divider unit during speculative execution. A local at</description>
    <pubDate>Fri, 31 Jul 2026 09:40:09 +0000</pubDate>
    <guid isPermaLink="false">https://ubuntu.com/security/notices/USN-8620-3</guid>
  </item>
  <item>
    <title>[HIGH] CVE-2026-70472: Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store</title>
    <link>https://github.com/advisories/GHSA-chm3-vqcf-52rx</link>
    <description># Summary 

These endpoints accept a client-controlled `credential` parameter. The server loads credentials by `id` and uses them directly, without checking whether that credential belongs to the caller’s workspace. If an attacker knows another workspace’s `credentialId`, they can use that workspace’s OpenAI key.

# Details

Route permissions (`assistants:*`) only check feature access. They do not check credential ownership. The controller passes `req.query.credential` straight to the service. T</description>
    <pubDate>Tue, 04 Aug 2026 17:51:48 +0000</pubDate>
    <guid isPermaLink="false">https://github.com/advisories/GHSA-chm3-vqcf-52rx</guid>
  </item>
  <item>
    <title>[CRITICAL] CVE-2026-69264: Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation</title>
    <link>https://github.com/advisories/GHSA-4j8x-x6v7-w9rq</link>
    <description>### Summary
Flowise's `CSVAgent` interpolates an attacker-controlled segment of the
`csvFile` data URI directly into a Python source-code template that is then
executed by Pyodide. Because Pyodide is loaded with the default `js` bridge
to `globalThis` (which on Node.js exposes `eval` and dynamic `import()`), the
attacker can break out of the Python string literal, hand a JS string to
`js.eval`, dynamically import any Node built-in module (`fs`, `child_process`,
…), and execute arbitrary file I/O</description>
    <pubDate>Tue, 04 Aug 2026 17:43:48 +0000</pubDate>
    <guid isPermaLink="false">https://github.com/advisories/GHSA-4j8x-x6v7-w9rq</guid>
  </item>
  <item>
    <title>[HIGH] GHSA-88pr-878c-24wf: Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys                                                </title>
    <link>https://github.com/advisories/GHSA-88pr-878c-24wf</link>
    <description>## Summary                                                                                                                                                                                                   
                                          
  Flowise on current `main` allows an authenticated user with
  `documentStores:preview-process` permission to trigger the `S3 Directory`                                                                                                                  </description>
    <pubDate>Tue, 04 Aug 2026 17:43:45 +0000</pubDate>
    <guid isPermaLink="false">https://github.com/advisories/GHSA-88pr-878c-24wf</guid>
  </item>
  <item>
    <title>[HIGH] CVE-2026-70471: Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure</title>
    <link>https://github.com/advisories/GHSA-8r8h-6vcc-xhrv</link>
    <description>## Finding — Unauthorized Workspace Variables disclosure via $vars injection (bypasses variables:view)

  ### What’s wrong (code locations)

  - Variables for the active workspace are fetched without checking “variables:view” at this call site: flowise-src/
    packages/components/src/utils.ts:932
  - Runtime variables are resolved from server environment variables: flowise-src/packages/components/src/utils.ts:976
  - $vars is always injected into the code execution sandbox: flowise-src/packages</description>
    <pubDate>Tue, 04 Aug 2026 17:43:36 +0000</pubDate>
    <guid isPermaLink="false">https://github.com/advisories/GHSA-8r8h-6vcc-xhrv</guid>
  </item>
  <item>
    <title>[CRITICAL] CVE-2026-70470: Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE</title>
    <link>https://github.com/advisories/GHSA-52fh-8v99-63c2</link>
    <description>### Summary
The validatePythonCodeForDataFrame blacklist in packages/components/src/pythonCodeValidator.ts can be bypassed with Unicode homoglyph identifiers, allowing arbitrary Python execution inside Pyodide and full OS command execution on the Flowise host via Pyodide's js module interop. This reopens the RCE paths patched as GHSA-3hjv-c53m-58jj (CSV Agent) and GHSA-v38x-c887-992f (Airtable Agent).

### Details
packages/components/src/pythonCodeValidator.ts gates every call to pyodide.runPyth</description>
    <pubDate>Tue, 04 Aug 2026 17:31:09 +0000</pubDate>
    <guid isPermaLink="false">https://github.com/advisories/GHSA-52fh-8v99-63c2</guid>
  </item>
  <item>
    <title>[HIGH] CVE-2026-69263: Flowise is a drag &amp; drop user interface to build a customized large language model flow. Prior to 3.1.3, the mitigation for CVE-2025-8943 blocked -y and --yes f</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-69263</link>
    <description>Flowise is a drag &amp; drop user interface to build a customized large language model flow. Prior to 3.1.3, the mitigation for CVE-2025-8943 blocked -y and --yes flags on npx, but packages/components/nodes/tools/MCP/core.ts denied only PATH, LD_LIBRARY_PATH, DYLD_LIBRARY_PATH, and NODE_OPTIONS by exact environment-variable name. Because npm reads configuration from npm_config_* variables, setting npm_config_yes=true reproduced --yes behavior without using a blocked flag, causing npx to auto-install</description>
    <pubDate>Tue, 04 Aug 2026 17:17:01 +0000</pubDate>
    <guid isPermaLink="false">https://nvd.nist.gov/vuln/detail/CVE-2026-69263</guid>
  </item>
  <item>
    <title>[HIGH] CVE-2026-69262: Flowise is a drag &amp; drop user interface to build a customized large language model flow. Prior to 3.1.3, `DELETE /api/v1/chatflows/:id` authorized requests with</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-69262</link>
    <description>Flowise is a drag &amp; drop user interface to build a customized large language model flow. Prior to 3.1.3, `DELETE /api/v1/chatflows/:id` authorized requests with checkAnyPermission('chatflows:delete,agentflows:delete'), so possession of either permission was sufficient to reach the delete path. The delete logic then resolved the target record only by id and workspaceId and did not validate the target resource type, allowing a caller with only agentflows:delete to delete a CHATFLOW and a caller wi</description>
    <pubDate>Tue, 04 Aug 2026 17:17:01 +0000</pubDate>
    <guid isPermaLink="false">https://nvd.nist.gov/vuln/detail/CVE-2026-69262</guid>
  </item>
  <item>
    <title>[CRITICAL] CVE-2026-69259: Flowise is a drag &amp; drop user interface to build a customized large language model flow. Prior to 3.1.3, the SQLite Record Manager node in packages/components/n</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-69259</link>
    <description>Flowise is a drag &amp; drop user interface to build a customized large language model flow. Prior to 3.1.3, the SQLite Record Manager node in packages/components/nodes/recordmanager/SQLiteRecordManager/SQLiteRecordManager.ts accepted user-controlled additionalConfig and spread it after the intended database setting, allowing additionalConfig.database to overwrite the SQLite database path. An authenticated attacker using the published Docker image, which ran as root, could write a SQLite database to</description>
    <pubDate>Tue, 04 Aug 2026 17:17:01 +0000</pubDate>
    <guid isPermaLink="false">https://nvd.nist.gov/vuln/detail/CVE-2026-69259</guid>
  </item>
  <item>
    <title>[HIGH] CVE-2026-69258: Flowise is a drag &amp; drop user interface to build a customized large language model flow. Prior to 3.1.3, the unauthenticated POST /api/v1/prediction/:id endpoin</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-69258</link>
    <description>Flowise is a drag &amp; drop user interface to build a customized large language model flow. Prior to 3.1.3, the unauthenticated POST /api/v1/prediction/:id endpoint accepted an overrideConfig object and unconditionally spread it into internal flowConfig and flowData objects in packages/server/src/utils/buildChatflow.ts and packages/server/src/utils/index.ts without checking apiOverrideStatus. This allowed unauthenticated attackers to inject arbitrary properties into the flow execution context of an</description>
    <pubDate>Tue, 04 Aug 2026 17:17:01 +0000</pubDate>
    <guid isPermaLink="false">https://nvd.nist.gov/vuln/detail/CVE-2026-69258</guid>
  </item>
  <item>
    <title>[HIGH] CVE-2026-69257: Flowise is a drag &amp; drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise's HTTP security module httpSecurity.ts did not </title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-69257</link>
    <description>Flowise is a drag &amp; drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise's HTTP security module httpSecurity.ts did not normalize IPv4-mapped IPv6 addresses such as ::ffff:127.0.0.1 and ::ffff:169.254.169.254 before checking them against the deny list. Because ipaddr.js reports these addresses as ipv6 while IPv4 CIDR deny-list entries are ipv4, isDeniedIP() skipped the IPv4 CIDR checks. An attacker who controls DNS resolution for a hostname used by the HTT</description>
    <pubDate>Tue, 04 Aug 2026 17:17:00 +0000</pubDate>
    <guid isPermaLink="false">https://nvd.nist.gov/vuln/detail/CVE-2026-69257</guid>
  </item>
  <item>
    <title>[CRITICAL] CVE-2026-69256: Flowise is a drag &amp; drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent node allowed users to provide Python code </title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-69256</link>
    <description>Flowise is a drag &amp; drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent node allowed users to provide Python code that is executed through pyodide; although a denylist blocked dangerous Python constructs, pandas.read_pickle() could deserialize a pickled payload and achieve code execution without matching the denied words. The affected file is flowise-components/nodes/agents/CSVAgent/CSVAgent.ts, where user-supplied customReadCSVFunc is evaluated as p</description>
    <pubDate>Tue, 04 Aug 2026 17:17:00 +0000</pubDate>
    <guid isPermaLink="false">https://nvd.nist.gov/vuln/detail/CVE-2026-69256</guid>
  </item>
  <item>
    <title>[CRITICAL] CVE-2026-69255: Flowise is a drag &amp; drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent in packages/components/nodes/agents/CSVAge</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-69255</link>
    <description>Flowise is a drag &amp; drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent in packages/components/nodes/agents/CSVAgent/CSVAgent.ts extracted attacker-controlled CSV data with file.split(',').pop() and interpolated it directly into executable Python as base64_string = "${base64String}" before calling Pyodide. The validatePythonCodeForDataFrame() denylist only checked later LLM-generated code and did not validate this initial code block. An authenticated</description>
    <pubDate>Tue, 04 Aug 2026 17:17:00 +0000</pubDate>
    <guid isPermaLink="false">https://nvd.nist.gov/vuln/detail/CVE-2026-69255</guid>
  </item>
  <item>
    <title>[HIGH] CVE-2026-64634: A vulnerability allowing local privilege escalation to the Reporter service context.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-64634</link>
    <description>A vulnerability allowing local privilege escalation to the Reporter service context.</description>
    <pubDate>Tue, 04 Aug 2026 17:16:58 +0000</pubDate>
    <guid isPermaLink="false">https://nvd.nist.gov/vuln/detail/CVE-2026-64634</guid>
  </item>
  <item>
    <title>[CRITICAL] CVE-2026-64633: A vulnerability allowing remote unauthenticated code execution on the agent host.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-64633</link>
    <description>A vulnerability allowing remote unauthenticated code execution on the agent host.</description>
    <pubDate>Tue, 04 Aug 2026 17:16:58 +0000</pubDate>
    <guid isPermaLink="false">https://nvd.nist.gov/vuln/detail/CVE-2026-64633</guid>
  </item>
  <item>
    <title>[HIGH] CVE-2026-64631: A vulnerability allowing a low-privileged user to inject SQL and extract database contents.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-64631</link>
    <description>A vulnerability allowing a low-privileged user to inject SQL and extract database contents.</description>
    <pubDate>Tue, 04 Aug 2026 17:16:58 +0000</pubDate>
    <guid isPermaLink="false">https://nvd.nist.gov/vuln/detail/CVE-2026-64631</guid>
  </item>
  <item>
    <title>[MEDIUM] CVE-2026-64630: A vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared report link.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-64630</link>
    <description>A vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared report link.</description>
    <pubDate>Tue, 04 Aug 2026 17:16:57 +0000</pubDate>
    <guid isPermaLink="false">https://nvd.nist.gov/vuln/detail/CVE-2026-64630</guid>
  </item>
  <item>
    <title>[CRITICAL] CVE-2026-63456: Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentica</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-63456</link>
    <description>Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify potentially sensitive information on the target system.</description>
    <pubDate>Tue, 04 Aug 2026 17:16:57 +0000</pubDate>
    <guid isPermaLink="false">https://nvd.nist.gov/vuln/detail/CVE-2026-63456</guid>
  </item>
  <item>
    <title>[CRITICAL] CVE-2026-63455: Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentica</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-63455</link>
    <description>Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify potentially sensitive information on the target system.</description>
    <pubDate>Tue, 04 Aug 2026 17:16:57 +0000</pubDate>
    <guid isPermaLink="false">https://nvd.nist.gov/vuln/detail/CVE-2026-63455</guid>
  </item>
  <item>
    <title>[HIGH] CVE-2026-58075: A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leveraged toescalate privileges locally.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-58075</link>
    <description>A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leveraged toescalate privileges locally.</description>
    <pubDate>Tue, 04 Aug 2026 17:16:57 +0000</pubDate>
    <guid isPermaLink="false">https://nvd.nist.gov/vuln/detail/CVE-2026-58075</guid>
  </item>
  <item>
    <title>[HIGH] CVE-2026-58074: A vulnerability allowing a high-privileged user to execute arbitrary code on the server.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-58074</link>
    <description>A vulnerability allowing a high-privileged user to execute arbitrary code on the server.</description>
    <pubDate>Tue, 04 Aug 2026 17:16:57 +0000</pubDate>
    <guid isPermaLink="false">https://nvd.nist.gov/vuln/detail/CVE-2026-58074</guid>
  </item>
  <item>
    <title>[CRITICAL] CVE-2026-58073: A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credentials.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-58073</link>
    <description>A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credentials.</description>
    <pubDate>Tue, 04 Aug 2026 17:16:56 +0000</pubDate>
    <guid isPermaLink="false">https://nvd.nist.gov/vuln/detail/CVE-2026-58073</guid>
  </item>
  <item>
    <title>[CRITICAL] CVE-2026-58072: A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead to remotecode execution.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-58072</link>
    <description>A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead to remotecode execution.</description>
    <pubDate>Tue, 04 Aug 2026 17:16:56 +0000</pubDate>
    <guid isPermaLink="false">https://nvd.nist.gov/vuln/detail/CVE-2026-58072</guid>
  </item>
  <item>
    <title>[HIGH] CVE-2026-58071: A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API asPortal Administrator during a short</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-58071</link>
    <description>A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API asPortal Administrator during a short window after an administrator session begins.</description>
    <pubDate>Tue, 04 Aug 2026 17:16:56 +0000</pubDate>
    <guid isPermaLink="false">https://nvd.nist.gov/vuln/detail/CVE-2026-58071</guid>
  </item>
  <item>
    <title>[HIGH] CVE-2026-58067: A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause adenial of service.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-58067</link>
    <description>A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause adenial of service.</description>
    <pubDate>Tue, 04 Aug 2026 17:16:56 +0000</pubDate>
    <guid isPermaLink="false">https://nvd.nist.gov/vuln/detail/CVE-2026-58067</guid>
  </item>
  <item>
    <title>[HIGH] CVE-2026-56848: A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a </title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-56848</link>
    <description>A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free.

This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.</description>
    <pubDate>Tue, 04 Aug 2026 17:16:56 +0000</pubDate>
    <guid isPermaLink="false">https://nvd.nist.gov/vuln/detail/CVE-2026-56848</guid>
  </item>
  <item>
    <title>[MEDIUM] CVE-2026-48121: @langchain/langgraph-checkpoint-mongodb provides a LangGraph.js CheckpointSaver implementation that uses MongoDB for storage. Versions 1.3.0 and below are vulne</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48121</link>
    <description>@langchain/langgraph-checkpoint-mongodb provides a LangGraph.js CheckpointSaver implementation that uses MongoDB for storage. Versions 1.3.0 and below are vulnerable to NoSQL injection: checkpoint identifiers (thread_id, checkpoint_ns, checkpoint_id) from config.configurable are passed into MongoDB find() queries in MongoDBSaver.getTuple() without type enforcement. If an attacker supplies an object payload (such as MongoDB operators $gt or $ne) instead of a string, it can be interpreted as a que</description>
    <pubDate>Tue, 04 Aug 2026 17:16:55 +0000</pubDate>
    <guid isPermaLink="false">https://nvd.nist.gov/vuln/detail/CVE-2026-48121</guid>
  </item>
  <item>
    <title>[HIGH] CVE-2026-18787: A vulnerability was identified in GL.iNet AX1800 up to 4.8.3. The affected element is the function remove_rule of the file /usr/share/gl-ngx/oui-rpc.lua of the </title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-18787</link>
    <description>A vulnerability was identified in GL.iNet AX1800 up to 4.8.3. The affected element is the function remove_rule of the file /usr/share/gl-ngx/oui-rpc.lua of the component RPC Endpoint. The manipulation of the argument args.id leads to command injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.</description>
    <pubDate>Tue, 04 Aug 2026 17:16:48 +0000</pubDate>
    <guid isPermaLink="false">https://nvd.nist.gov/vuln/detail/CVE-2026-18787</guid>
  </item>
  <item>
    <title>[LOW] CVE-2026-18785: A vulnerability was determined in o6 open62541 ca356b088ada7dee824d1b4acd07c1ff07ce242b. Impacted is the function UA_Client_getRemoteDataTypes of the file examp</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-18785</link>
    <description>A vulnerability was determined in o6 open62541 ca356b088ada7dee824d1b4acd07c1ff07ce242b. Impacted is the function UA_Client_getRemoteDataTypes of the file examples/custom_datatype/client_types_custom.c. Executing a manipulation can lead to use after free. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. The project closed the issue report, stating that this is not the official way to report a security vulnerability.</description>
    <pubDate>Tue, 04 Aug 2026 17:16:48 +0000</pubDate>
    <guid isPermaLink="false">https://nvd.nist.gov/vuln/detail/CVE-2026-18785</guid>
  </item>
  <item>
    <title>[LOW] CVE-2026-18784: A vulnerability was found in o6 open62541 up to 1.5.5. This issue affects the function UA_Client_readNodeClassAttribute of the file src/client/ua_client_highlev</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-18784</link>
    <description>A vulnerability was found in o6 open62541 up to 1.5.5. This issue affects the function UA_Client_readNodeClassAttribute of the file src/client/ua_client_highlevel.c. Performing a manipulation results in heap-based buffer overflow. Attacking locally is a requirement. The exploit has been made public and could be used. The project closed the issue report, stating that this is not the official way to report a security vulnerability.</description>
    <pubDate>Tue, 04 Aug 2026 17:16:48 +0000</pubDate>
    <guid isPermaLink="false">https://nvd.nist.gov/vuln/detail/CVE-2026-18784</guid>
  </item>
  <item>
    <title>[LOW] CVE-2026-18775: A vulnerability has been found in NousResearch hermes-agent up to 0.16.0. This vulnerability affects the function browser_snapshot of the file tools/browser_too</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-18775</link>
    <description>A vulnerability has been found in NousResearch hermes-agent up to 0.16.0. This vulnerability affects the function browser_snapshot of the file tools/browser_tool.py of the component Browser Tooling. Such manipulation leads to server-side request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.</description>
    <pubDate>Tue, 04 Aug 2026 17:16:48 +0000</pubDate>
    <guid isPermaLink="false">https://nvd.nist.gov/vuln/detail/CVE-2026-18775</guid>
  </item>
  <item>
    <title>[LOW] CVE-2026-18774: A flaw has been found in NousResearch hermes-agent up to 0.16.0. This affects the function save_url_image of the file agent/image_gen_provider.py of the compone</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-18774</link>
    <description>A flaw has been found in NousResearch hermes-agent up to 0.16.0. This affects the function save_url_image of the file agent/image_gen_provider.py of the component xAI Image Generation Provider. This manipulation causes server-side request forgery. The attack may be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.</description>
    <pubDate>Tue, 04 Aug 2026 17:16:48 +0000</pubDate>
    <guid isPermaLink="false">https://nvd.nist.gov/vuln/detail/CVE-2026-18774</guid>
  </item>
  <item>
    <title>[MEDIUM] CVE-2026-15920: An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.
`django.contrib.admin.utils.display_for_field()` renders `URLField` values as clickabl</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-15920</link>
    <description>An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.
`django.contrib.admin.utils.display_for_field()` renders `URLField` values as clickable links in the admin without validating the URL. A value stored with an unsafe scheme is displayed as a link on changelist and read-only admin pages, which allows cross-site scripting against staff users who click the link.
Exploitation requires the unsafe value to already be stored in the database. `URLField` validation through a `Model</description>
    <pubDate>Tue, 04 Aug 2026 17:16:46 +0000</pubDate>
    <guid isPermaLink="false">https://nvd.nist.gov/vuln/detail/CVE-2026-15920</guid>
  </item>
  <item>
    <title>[MEDIUM] CVE-2026-15830: An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.
GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-15830</link>
    <description>An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.
GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested `GEOMETRYCOLLECTION` objects supplied as well-known text (WKT), well-known binary (WKB), or hex-encoded WKB, which triggers unbounded recursion and a segmentation fault in the underlying GEOS library. Spatial field lookups and the `django.contrib.gis.forms.GeometryField` form field are also affected.
Ea</description>
    <pubDate>Tue, 04 Aug 2026 17:16:46 +0000</pubDate>
    <guid isPermaLink="false">https://nvd.nist.gov/vuln/detail/CVE-2026-15830</guid>
  </item>
  <item>
    <title>[MEDIUM] CVE-2026-15337: An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.
`django.utils.translation.check_for_language()` is subject to a potential denial-of-se</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-15337</link>
    <description>An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8.
`django.utils.translation.check_for_language()` is subject to a potential denial-of-service attack when given many distinct, very long language codes, which are retained as keys in an in-memory cache and consume process memory. Such codes reach the function through the `django.views.i18n.set_language()` view, which is not routed by default. The consumed memory is bounded, since request data is limited by the `DATA_UPLOAD_M</description>
    <pubDate>Tue, 04 Aug 2026 17:16:46 +0000</pubDate>
    <guid isPermaLink="false">https://nvd.nist.gov/vuln/detail/CVE-2026-15337</guid>
  </item>
  <item>
    <title>[HIGH] CVE-2026-15314: Tapo P110 v1
smart Wi-Fi Plug contains an improper boundary validation vulnerability in the
handling of authenticated HTTP request bodies due to insufficient in</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-15314</link>
    <description>Tapo P110 v1
smart Wi-Fi Plug contains an improper boundary validation vulnerability in the
handling of authenticated HTTP request bodies due to insufficient input
validation before memory copy operations. This may lead to buffer overflow condition,
causing the web service process to crash.





Successful exploitation
may cause the web service process to stop responding or restart, resulting in a
denial-of-service condition.</description>
    <pubDate>Tue, 04 Aug 2026 17:16:46 +0000</pubDate>
    <guid isPermaLink="false">https://nvd.nist.gov/vuln/detail/CVE-2026-15314</guid>
  </item>
  </channel>
</rss>