Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.4 CVE-2026-44393

CVE-2026-44393_CVE-2026-44393

An issue was discovered in OpenStack oslo.messaging 1.0.0 through 17.3.0. The oslo.messaging RabbitMQ driver does not perform TLS hostname verifica...

n/a n/a n/a CVE
HIGH 8.8 CVE-2026-43985

Taultulli has CSRF in /configUpdate via missing anti-CSRF and method restriction that allows admin credential takeover_CVE-2026-43985

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose `configUpdate` as a state-changing a...

Tautulli Tautulli < 2.17.1 CVE
HIGH 8.9 CVE-2026-43984

Tautulli has stored XSS in logFile via guest-controlled log_js_errors input_CVE-2026-43984

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose `log_js_errors` to any authenticated...

Tautulli Tautulli < 2.17.1 CVE
CRITICAL 9.1 CVE-2026-50076

Apache Fory: Java ReplaceResolverSerializer deserialization checks bypass_CVE-2026-50076

Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK before 1.1.0 on Java/JVM platforms allows a re...

Apache Software Foundation Apache Fory CVE
HIGH 7.3 CVE-2026-49942

Net::CIDR::Set versions through 0.20 for Perl did not validate network masks_CVE-2026-49942

Net::CIDR::Set versions through 0.20 for Perl did not validate network masks. The mask portion of a network mask could contain Unicode digits such...

RRWO Net::CIDR::Set CVE
HIGH 7.5 CVE-2026-49941

Net::CIDR::Set versions through 0.20 for Perl did not validate IP addresses_CVE-2026-49941

Net::CIDR::Set versions through 0.20 for Perl did not validate IP addresses. The add method called the _encode method to parse addresses. If the a...

RRWO Net::CIDR::Set CVE
MEDIUM 6.5 CVE-2026-49940

Net::CIDR::Set versions through 0.20 for Perl accept non-ASCII IP addresses and netmasks_CVE-2026-49940

Net::CIDR::Set versions through 0.20 for Perl accept non-ASCII IP addresses and netmasks. Unicode digits such as the Arabic-Indic One (U+0661) wer...

RRWO Net::CIDR::Set CVE
HIGH 7.5 CVE-2026-46741

Etsy::StatsD versions through 1.002002 for Perl allow metric injections_CVE-2026-46741

Etsy::StatsD versions through 1.002002 for Perl allow metric injections. The metric names and values are not checked for newlines, colons or pipes...

SANBEG Etsy::StatsD CVE
MEDIUM 5.3 CVE-2026-46739

Net::Statsd versions before 0.13 for Perl allow metric injections_CVE-2026-46739

Net::Statsd versions before 0.13 for Perl allow metric injections. The metric names are not checked for newlines, colons or pipes. Metrics generat...

COSIMO Net::Statsd CVE
MEDIUM 6.9 CVE-2026-41207

netty-incubator-codec-ohttp’s HPKEContext operations may produce empty byte[] on failures_CVE-2026-41207

The netty incubator codec.bhttp is a java language binary http parser. Prior to version 0.0.21.Final, HKDF_expand returns non-NULL on failure. The ...

netty netty-incubator-codec-ohttp < 0.0.21.Final CVE