Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.8 CVE-2026-49357

Streamable HTTP mode exposes LINE Desktop read/send tools without MCP authentication_CVE-2026-49357

Line Desktop MCP is a project that, while unaffiliated with the official line-bot-mcp-server, allows users to directly operate the LINE Desktop app...

dtwang line-desktop-mcp < 1.1.2 CVE
LOW 2.3 CVE-2026-49231

Apache APISIX: Identity spoofing issue in APISIX opa plugin_CVE-2026-49231

Authentication Bypass by Spoofing vulnerability in opa plugin. An attacker could relay spoofed identity headers to upstream capitalising on non-de...

Apache Software Foundation Apache APISIX 3.5.0 CVE
MEDIUM 6.3 CVE-2026-49230

Apache APISIX: Authentication bypass in jwe-decrypt_CVE-2026-49230

Improper Validation of Integrity Check Value vulnerability in Apache APISIX. The jwe-decrypt plugin under default configuration is vulnerable to a...

Apache Software Foundation Apache APISIX 3.8.0 CVE
LOW 2.1 CVE-2026-48895

Apache APISIX: Cas-auth Host header influence on CAS service URL_CVE-2026-48895

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The attacker could manipulate some client headers to perform a...

Apache Software Foundation Apache APISIX 3.0.0 CVE
MEDIUM 5.3 CVE-2026-48141

Memory leak in NI grpc-device BeginSidebandStream_CVE-2026-48141

There is a memory leak in NI grpc-device BeginSidebandStream that may result in denial of service due to memory exhaustion.  This affects NI grpc-d...

NI grpc-device CVE
MEDIUM 6.5 CVE-2026-48140

Unchecked enum cast vulnerability in NI grpc-device in BeginSidebandStream_CVE-2026-48140

There is an unchecked enum cast vulnerability in NI grpc-device BeginSidebandStream that may allow an attacker to trigger invalid enum states and u...

NI grpc-device CVE
HIGH 7.5 CVE-2026-48139

NULL pointer dereference vulnerability in NI grpc-device data moniker service_CVE-2026-48139

There is a NULL pointer dereference vulnerability in NI grpc-device in the data moniker service that may allow an attacker to cause a denial of ser...

NI grpc-device CVE
HIGH 7.5 CVE-2026-48138

Out-of-bounds read vulnerability in the NI grpc-device streaming API_CVE-2026-48138

There is an out-of-bounds read vulnerability in the NI grpc-device streaming API due to a missing bounds check that may result in a denial of servi...

NI grpc-device CVE
CRITICAL 9.1 CVE-2026-48137

Untrusted pointer dereference in NI grpc-device sideband streaming API_CVE-2026-48137

There is an untrusted pointer dereference vulnerability in the NI grpc-device sideband streaming API that may allow an attacker to cause an arbitra...

NI grpc-device CVE
MEDIUM 6.3 CVE-2026-47341

Apache APISIX: Session replay issue in hmac-auth_CVE-2026-47341

Authentication Bypass by Capture-replay vulnerability in Apache APISIX. Attacker can benefit from certain configurations in hmac-auth to re-use a ...

Apache Software Foundation Apache APISIX 3.11.0 CVE