Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.9 CVE-2026-54323

Daytona: Git credential leak via git clone with TLS verification disabled_CVE-2026-54323

Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.185.0, the daemon's git clon...

daytonaio daytona < 0.185.0 CVE
HIGH 7.1 CVE-2026-54318

Home Assistant: Exported BroadcastReceiver allows local apps to spoof device location_CVE-2026-54318

Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.5.3, the LocationSensorManager Broa...

home-assistant core < 2026.5.3 CVE
HIGH 7.6 CVE-2026-54317

Home Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LAN_CVE-2026-54317

Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.6.0, the Konnected integration regi...

home-assistant core < 2026.6.0 CVE
CRITICAL 9 CVE-2026-54157

LobeHub: Unauthenticated SSRF in `/webapi/proxy`_CVE-2026-54157

LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to 2.1.57, the /webapi/proxy e...

lobehub lobehub < 2.1.57 CVE
CRITICAL 9.6 CVE-2026-53662

immich: One-click account takeover via XSS in login page continue redirect_CVE-2026-53662

immich is a high performance self-hosted photo and video management solution. From commit 4ffa26c9 until 4eb1003, a reflected cross-site scripting ...

immich-app immich >= main@4ffa26c9, < main@4eb1003 CVE
MEDIUM 4.2 CVE-2026-52846

Caddy: stripHTML template function bypass_CVE-2026-52846

Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, Caddy’s stripHTML template function cannot reliably remove all HT...

caddyserver caddy < 2.11.4 CVE
HIGH 8.1 CVE-2026-52845

Caddy: FastCGI header normalization bypass in `forward_auth copy_headers`_CVE-2026-52845

Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, forward_auth copy_headers deletes the exact client-supplied ident...

caddyserver caddy < 2.11.4 CVE
HIGH 7.5 CVE-2026-52844

Caddy: Windows `file_server` path authorization bypass via encoded backslash_CVE-2026-52844

Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, on Windows, Caddy path matchers treat /private\secret.txt as outs...

caddyserver caddy < 2.11.4 CVE
MEDIUM 5.4 CVE-2026-45692

Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalization_CVE-2026-45692

Caddy is an extensible server platform that uses TLS by default. From 2.4.0 until 2.11.3, the authorization layer and the /config traversal layer d...

caddyserver caddy >= 2.4.0, < 2.11.3 CVE
HIGH 8.1 CVE-2026-45135

Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Files_CVE-2026-45135

Caddy is an extensible server platform that uses TLS by default. From 2.7.0 until 2.11.3, the FastCGI transport's splitPos() in modules/caddyhttp/r...

caddyserver caddy >= 2.7.0, < 2.11.3 CVE