Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.7 CVE-2026-23996

FastAPI Api Key has a timing side-channel in verify_key that allows statistical key validity detection_CVE-2026-23996

FastAPI Api Key provides a backend-agnostic library that provides an API key system. Version 1.1.0 has a timing side-channel vulnerability in verif...

Athroniaeth fastapi-api-key < 1.1.0 CVE
LOW 3.5 CVE-2026-24048

Backstage has a Possible SSRF when reading from allowed URL’s in `backend.reading.allow`_CVE-2026-24048

Backstage is an open framework for building developer portals, and @backstage/backend-defaults provides the default implementations and setup for a...

backstage backstage < 0.12.2 CVE
LOW 2.7 CVE-2026-24001

jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch_CVE-2026-24001

jsdiff is a JavaScript text differencing implementation. Prior to versions 8.0.3, 5.2.2, and 4.0.4, attempting to parse a patch whose filename head...

kpdecker jsdiff >= 6.0.0, < 8.0.3 CVE
LOW 1.8 CVE-2026-1225

Malicious logback.xml configuration file allows instantiation of arbitrary classes_CVE-2026-1225

ACE vulnerability in configuration file processing by QOS.CH logback-core up to and including version 1.5.24 in Java applications, allows an attac...

QOS.CH Sarl Logback-core 0.9.20 CVE
LOW 1.3 CVE-2025-12738

Enumeration of restricted property value_CVE-2025-12738

Neo4j Enterprise edition versions prior to 2025.11.2 and 5.26.17 are vulnerable to a potential information disclosure by an attacker who has some l...

neo4j Enterprise Edition CVE
LOW 3.5 CVE-2026-22281

CVE-2026-22281_CVE-2026-22281

Dell PowerScale OneFS, versions 9.5.0.0 through 9.5.1.5, versions 9.6.0.0 through 9.7.1.10, versions 9.8.0.0 through 9.10.1.3, versions starting fr...

Dell PowerScale OneFS N/A CVE
LOW 3.5 CVE-2026-0798

Gitea Release Email Notifications Leak Private Repository Release Details After Access Revocation_CVE-2026-0798

Gitea may send release notification emails for private repositories to users whose access has been revoked. When a repository is changed from publi...

Gitea Gitea Open Source Git Server CVE
LOW 3.7 CVE-2026-0988

Glib: glib: denial of service via integer overflow in g_buffered_input_stream_peek()_CVE-2026-0988

A flaw was found in glib. Missing validation of offset and count parameters in the g_buffered_input_stream_peek() function can lead to an integer o...

Red Hat Red Hat Enterprise Linux 10 CVE
LOW 2.7 CVE-2025-14083

Keycloak-server: keycloak: improper access control in admin rest api leads to information disclosure_CVE-2025-14083

A flaw was found in the Keycloak Admin REST API. This vulnerability allows the exposure of backend schema and rules, potentially leading to targete...

Red Hat Red Hat Build of Keycloak CVE
LOW 3.1 CVE-2026-1035

Org.keycloak.protocol.oidc: keycloak refresh token reuse bypass via toctou race condition_CVE-2026-1035

A flaw was found in the Keycloak server during refresh token processing, specifically in the TokenManager class responsible for enforcing refresh t...

Red Hat Red Hat Build of Keycloak CVE