Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.3 CVE-2026-48513

MessagePack-CSharp: DynamicUnionResolver generated deserializers miss depth enforcement_CVE-2026-48513

MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, runtime-generated union deserializers emitted by DynamicUnionRes...

MessagePack-CSharp MessagePack-CSharp >= 3.1.7, < 3.1.7 CVE
MEDIUM 6.3 CVE-2026-48512

MessagePack-CSharp: JSON conversion APIs can recurse without consistent depth enforcement_CVE-2026-48512

MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePack-CSharp's JSON conversion helpers contain multiple re...

MessagePack-CSharp MessagePack-CSharp >= 3.1.7, < 3.1.7 CVE
MEDIUM 6.3 CVE-2026-48511

MessagePack-CSharp: ExpandoObject formatter can perform quadratic insertion work on untrusted maps_CVE-2026-48511

MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, ExpandoObjectFormatter.Deserialize populates System.Dynamic.Expa...

MessagePack-CSharp MessagePack-CSharp >= 3.1.7, < 3.1.7 CVE
MEDIUM 6.3 CVE-2026-48510

MessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengths_CVE-2026-48510

MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, when MessagePack-CSharp decompresses Lz4Block or Lz4BlockArray p...

MessagePack-CSharp MessagePack-CSharp >= 3.1.7, < 3.1.7 CVE
MEDIUM 6.3 CVE-2026-48509

MessagePack-CSharp: ASP.NET Core MessagePackInputFormatter defaults to TrustedData for HTTP request bodies_CVE-2026-48509

MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, the parameterless MessagePackInputFormatter() constructor uses d...

MessagePack-CSharp MessagePack-CSharp >= 3.1.7, < 3.1.7 CVE
MEDIUM 6.5 CVE-2026-48500

Filament: Unauthenticated temporary file upload on auth pages_CVE-2026-48500

Filament is a collection of full-stack components for accelerated Laravel development. From 3.0.0 until 3.3.52, 4.11.5, and 5.6.5, any schema can c...

filamentphp filament >= 3.0.0, < 3.3.52 CVE
MEDIUM 6.4 CVE-2026-48167

Filament: Unvalidated ImageColumn and ImageEntry values can be used for XSS_CVE-2026-48167

Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5, the ImageColumn and Image...

filamentphp filament >= 4.0.0, < 4.11.5 CVE
MEDIUM 5.3 CVE-2026-48166

Filament: Timing-based user enumeration on login page_CVE-2026-48166

Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5, the login page has an obs...

filamentphp filament >= 4.0.0, < 4.11.5 CVE
MEDIUM 6.5 CVE-2026-48067

Filament: Inconsistent scope enforcement for AttachAction and AssociateAction Select fields_CVE-2026-48067

Filament is a collection of full-stack components for accelerated Laravel development. From filament/actions 4.0.0 until 4.11.4 and 5.6.4 and from ...

filamentphp filament >= 4.0.0, < 4.11.4 CVE
MEDIUM 6.1 CVE-2026-44889

WebOb: Location header normalization during redirect leads to open redirect_CVE-2026-44889

WebOb provides objects for HTTP requests and responses. Prior to 1.8.10, the normalization of the HTTP Location header during a redirect is vulnera...

Pylons webob < 1.8.10 CVE