Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.3 CVE-2026-42489

domctl lock open to abuse_CVE-2026-42489

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To create and man...

Xen Xen consult Xen advisory XSA-492 CVE
HIGH 8.1 CVE-2026-42488

x86: mismatched mapcache metadata_CVE-2026-42488

Some shadow paging errors paths will switch the page-tables without updating the currently running vCPU reference. This causes a mismatch between ...

Xen Xen consult Xen advisory XSA-494 CVE
HIGH 7.9 CVE-2026-42487

x86 HVM I/O port list traversal_CVE-2026-42487

HVM guest I/O port accesses are subject to either emulation or at least translation. Translations are managed by the device model (via XEN_DOMCTL_...

Xen Xen consult Xen advisory XSA-491 CVE
MEDIUM 5.7 CVE-2026-12539

Docker Sandboxes ICMP egress restriction bypass after daemon restart_CVE-2026-12539

Docker Sandboxes (sbx) blocks ICMP egress with an authorizer applied only at network-creation time, and does not re-apply it to networks rebuilt fr...

Docker Docker Sandboxes 0.14.0 CVE
MEDIUM 6 CVE-2026-12527

CVE-2026-12527_CVE-2026-12527

A broken authorization boundary in the RTSP media delivery pipeline of Shenzhen Liandian Communication Technology LTD V380 IP Camera firmware AppFH...

Shenzhen Liandian Communication Technology LTD V380 IP Camera / AppFHE1_V1.0.6.0 AppFHE1_V1.0.6.020230803 CVE
MEDIUM 5.7 CVE-2026-12039

Docker Sandboxes network egress allowlist bypass via unfiltered DNS resolution_CVE-2026-12039

Docker Sandboxes (sbx) enforces an HTTP/S-only egress allowlist but does not apply it to DNS resolution: the per-network embedded DNS server forwar...

Docker Docker Sandboxes 0.13.0 CVE
HIGH 8.4 CVE-2026-46580

CVE-2026-46580_CVE-2026-46580

In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were automatically loaded and could ...

Eclipse Foundation Eclipse Theia CVE
HIGH 8.4 CVE-2026-44691

CVE-2026-44691_CVE-2026-44691

In Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. .theia/tasks.json, .vscode/tasks.json) could be execute...

Eclipse Foundation Eclipse Theia CVE
HIGH 8.4 CVE-2026-44688

CVE-2026-44688_CVE-2026-44688

In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its prompt context without dis...

Eclipse Foundation Eclipse Theia CVE
MEDIUM 6.7 CVE-2026-22551

CVE-2026-22551_CVE-2026-22551

In Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown image tags from AI responses, triggering HTTP requests to arbitrary extern...

Eclipse Foundation Eclipse Theia CVE