Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.5 CVE-2026-7471

Server-Side Request Forgery (SSRF) in GitLab_CVE-2026-7471

GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that cou...

GitLab GitLab 18.8 CVE
LOW 2.6 CVE-2026-6883

Missing Authorization in GitLab_CVE-2026-6883

GitLab has remediated an issue in GitLab EE affecting all versions from 15.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that cou...

GitLab GitLab 15.7 CVE
LOW 2.7 CVE-2026-2900

Missing Authorization in GitLab_CVE-2026-2900

GitLab has remediated an issue in GitLab EE affecting all versions from 16.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that wh...

GitLab GitLab 16.10 CVE
LOW 2.9 CVE-2026-42578

Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation_CVE-2026-42578

Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs ...

netty netty >= 4.2.0.Alpha1, < 4.2.13.Final CVE
LOW 1.8 CVE-2026-30904

CVE-2026-30904_CVE-2026-30904

Protection Mechanism Failure in Zoom Workplace for iOS before version 7.0.0 may allow an authenticated user to conduct a disclosure of information ...

Zoom Communications Zoom Workplace CVE
LOW 1.1 CVE-2026-0238

Broker VM: Improper Input Validation in Broker VM Certificate and Key Fields_CVE-2026-0238

A vulnerability in Palo Alto Networks Broker VM allows an authenticated administrator to inject arbitrary content into certain Broker VM fields.

Palo Alto Networks Broker VM 30.0 CVE
LOW 3.8 CVE-2026-33585

Arqit SKA-Platform Improper Handling of Parameters Vulnerability_CVE-2026-33585

Improper management of the idle timeout parameter in the Keycloak interface of the Arqit SKA-Platform enables an attacker to impersonate an authent...

Arqit Symmetric Key Agreement Platform CVE
LOW 3.7 CVE-2026-43514

Apache Tomcat: AJP secret compared in non-constant time_CVE-2026-43514

Observable Timing Discrepancy vulnerability when comparing AJP secret in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 1...

Apache Software Foundation Apache Tomcat 11.0.0-M1 CVE
LOW 3.7 CVE-2026-44572

Next.js: Middleware / Proxy redirects can be cache-poisoned_CVE-2026-44572

Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, an external client could send a x-...

vercel next.js >= 12.2.0, < 15.5.16 CVE
LOW 3.7 CVE-2026-44582

Next.js: Cache poisoning via collisions in React Server Component cache-busting_CVE-2026-44582

Next.js is a React framework for building full-stack web applications. From 13.4.6 to before 15.5.16 and 16.2.5, React Server Component responses c...

vercel next.js >= 13.4.6, < 15.5.16 CVE