Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.3 CVE-2026-47206

Dragonfly: RESP Protocol Injection via Lua redis.error_reply() in EvalSerializer_CVE-2026-47206

Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.39.9, Dragonfly has a RESP Protocol Injection via Lua redis...

dragonflydb dragonfly < 1.38.9 CVE
LOW 3.5 CVE-2026-3472

Markdown image rendering bypass in AI bot tool result posts in Mattermost_CVE-2026-3472

Mattermost versions 10.11.x

Mattermost Mattermost 10.11.0 CVE
LOW 2.1 CVE-2026-57940

CVE-2026-57940_CVE-2026-57940

HTMLy 3.1.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the RSS feed import functionality. The function get_feed() in system/adm...

danpros HTMLy 3.1.1 CVE
LOW 2.6 CVE-2026-57926

CVE-2026-57926_CVE-2026-57926

In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack

JetBrains YouTrack CVE
LOW 3.1 CVE-2026-57922

CVE-2026-57922_CVE-2026-57922

In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible

JetBrains YouTrack CVE
LOW 3.3 CVE-2026-48936

CVE-2026-48936_CVE-2026-48936

A flaw in Node.js Permission API can cause a local server to be started (via a Unix domain socket), even without the `--allow-net` permission. T...

nodejs node 26.3.0 CVE
LOW 3.3 CVE-2026-48935

CVE-2026-48935_CVE-2026-48935

A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. `--allow-fs-read`. ...

nodejs node 22.22.3 CVE
LOW 3.8 CVE-2026-13322

Kubevirt: virt-handler-rhel9: kubevirt: unbounded virtio-serial readline in virt-handler causes oom denial of service_CVE-2026-13322

A flaw was found in KubeVirt's downward metrics virtio-serial server. The server reads guest requests using textproto.Reader.ReadLine(), which buff...

Red Hat Red Hat OpenShift Virtualization 4 CVE
LOW 1 CVE-2026-6681

PKCS#7 decode ignores caller output buffer size, writing past buffer bounds_CVE-2026-6681

The PKCS#7 decode path ignores the caller-supplied output buffer size (outputSz), allowing decoded content to be written past the bounds of the pro...

wolfSSL wolfSSL 3.10.0 CVE
LOW 1 CVE-2026-6678

Integer underflow in wc_PKCS7_DecryptOri handling crafted Other Recipient Info_CVE-2026-6678

Integer underflow in wc_PKCS7_DecryptOri when handling crafted Other Recipient Info, leading to incorrect length handling during decryption.

wolfSSL wolfSSL 3.15.5 CVE