Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.3 CVE-2026-12340

Out-of-bounds heap read in SM2/SM3 certificate Subject Key Identifier computation_CVE-2026-12340

Out-of-bounds heap read during SM2/SM3 certificate signature verification. When parsing a certificate with an SM3wSM2 signature, the Subject Key Id...

wolfSSL wolfSSL 5.6.4 CVE
HIGH 8.7 CVE-2026-11310

X.509 trust-chain bypass in wolfSSL_X509_verify_cert() via untrusted intermediate anchoring_CVE-2026-11310

X.509 trust-chain bypass in the OpenSSL compatibility certificate verifier (wolfSSL_X509_verify_cert()). This affects only builds with --enable-ope...

wolfSSL wolfSSL 5.8.4 CVE
MEDIUM 6.3 CVE-2026-10592

Wildcard DNS SAN bypasses CA name-constraint checks_CVE-2026-10592

Certificates with wildcard DNS SANs (e.g. *.example.com) bypassed CA name-constraint checks. A certificate with a wildcard DNS SAN that should be r...

wolfSSL wolfSSL 3.9.10 CVE
LOW 2.3 CVE-2026-7531

Use-after-free in PQC hybrid key-share handling_CVE-2026-7531

Use-after-free in PQC hybrid key-share handling. This is an incomplete-fix follow-up to CVE-2026-5460 (released in 5.9.1): a malicious TLS 1.3 serv...

wolfSSL wolfSSL 5.8.0 CVE
LOW 2.3 CVE-2026-10512

X25519 x86_64 assembly final reduction leaves non-canonical field element_CVE-2026-10512

The X25519 x86_64 assembly implementation fails to clear the most significant bit during the final modular reduction, so the computed result may no...

wolfSSL wolfSSL 5.6.4 CVE
MEDIUM 6.3 CVE-2026-10097

ML-KEM-1024 x64 AVX2 implicit rejection failure breaks IND-CCA2 security_CVE-2026-10097

ML-KEM-1024 x64 AVX2 implicit rejection failure in the Fujisaki-Okamoto transform breaks IND-CCA2 security, allowing decapsulation to deviate from ...

wolfSSL wolfSSL 5.7.0 CVE
HIGH 7.5 CVE-2025-61027

CVE-2025-61027_CVE-2025-61027

An issue in the t_set_push component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL st...

n/a n/a n/a CVE
HIGH 7.5 CVE-2025-61023

CVE-2025-61023_CVE-2025-61023

An issue in the st_compare component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL st...

n/a n/a n/a CVE
MEDIUM 6.1 CVE-2026-48942

Joomla Extension – getk2.com – Stored-XSS in K2 extension for Joomla < 2.26_CVE-2026-48942

K2 ≤ 2.26 renders the `#__k2_users.image` column directly into HTML `src` attributes via two distinct templates, in both cases without HTML escaping.

getk2.com K2 extension for Joomla 1.0-2.26 CVE
HIGH 8.1 CVE-2026-9800

Keycloak: keycloak policy enforcer: authorization bypass via incorrect uri comparison_CVE-2026-9800

A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role...

Red Hat Red Hat Build of Keycloak CVE