Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.5 CVE-2025-55639

CVE-2025-55639_CVE-2025-55639

GPAC MP4Box v2.4 was discovered to contain a NULL pointer dereference in the gf_isom_add_track_kind() function at isomedia/isom_write.c. This vulne...

n/a n/a n/a CVE
LOW 3.7 CVE-2026-56968

CVE-2026-56968_CVE-2026-56968

GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosur...

GNU GNU SASL CVE
MEDIUM 5.7 CVE-2026-56117

dhcpcd Heap Use-After-Free via Control Socket Handling_CVE-2026-56117

dhcpcd through 10.3.2, fixed in commit 78ea09e, contains a heap use-after-free vulnerability in the control socket handling within src/control.c th...

NetworkConfiguration dhcpcd CVE
HIGH 7.1 CVE-2026-56116

dhcpcd Memory Leak DoS via IPv6 Router Advertisement Handling_CVE-2026-56116

dhcpcd through 10.3.2, fixed in commit 708b4a5, contains a memory leak vulnerability in the IPv6 Router Advertisement route information handling th...

NetworkConfiguration dhcpcd CVE
MEDIUM 6 CVE-2026-56115

dhcpcd Stack Out-of-Bounds Write in dhcp6_makemessage()_CVE-2026-56115

dhcpcd through 10.3.2, fixed in commit 2f00c7b, contains a one-byte stack out-of-bounds write vulnerability in dhcp6_makemessage() in src/dhcp6.c t...

NetworkConfiguration dhcpcd CVE
MEDIUM 6 CVE-2026-56114

dhcpcd Stack Out-of-Bounds Write in dhcp6_makemessage()_CVE-2026-56114

dhcpcd through 10.3.2, fixed in commit 2f00c7b, contains a one-byte stack out-of-bounds write vulnerability in dhcp6_makemessage() in src/dhcp6.c t...

NetworkConfiguration dhcpcd CVE
MEDIUM 6 CVE-2026-56113

dhcpcd Heap Use-After-Free in dhcp6_deprecateaddrs via DHCPv6 RENEW_CVE-2026-56113

dhcpcd through 10.3.2, fixed in commit 5733d3c, contains a heap use-after-free vulnerability that allows unauthenticated same-link attackers to cra...

NetworkConfiguration dhcpcd CVE
CRITICAL 9.3 CVE-2026-55450

Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak_CVE-2026-55450

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, unauthenticated users can upload any amount of data ...

langflow-ai langflow < 1.9.1 CVE
CRITICAL 9.6 CVE-2026-55447

Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit_CVE-2026-55447

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, by controlling a files that are digested into the RA...

langflow-ai langflow < 1.9.2 CVE
HIGH 7.5 CVE-2026-55446

Langflow: Unauthenticated DoS through multipart form boundary file upload_CVE-2026-55446

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.0.19, an attacker can send a /api/v1/files/upload/ reques...

langflow-ai langflow < 1.0.19 CVE