Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.9 CVE-2026-55568

Guzzle: Silent HTTPS-Proxy Downgrade to Cleartext_CVE-2026-55568

Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, in certain configurations, traffic expected to be protected by TLS on the hop to the prox...

guzzle guzzle < 7.12.1 CVE
MEDIUM 6.3 CVE-2026-54314

n8n: Denial of Service via ZIP decompression in webhook workflow_CVE-2026-54314

n8n is an open source workflow automation platform. Prior to 2.24.0, the Compression node's Decompress operation expanded attacker-controlled archi...

n8n-io n8n < 2.24.0 CVE
MEDIUM 6.5 CVE-2026-54313

n8n: NoSQL Injection in MongoDB Node Find And Replace Operation_CVE-2026-54313

n8n is an open source workflow automation platform. Prior to 2.24.0, an authenticated user with workflow edit access could supply a malicious filte...

n8n-io n8n < 2.24.0 CVE
HIGH 7.2 CVE-2026-54312

n8n: Microsoft SQL Node Prototype Pollution_CVE-2026-54312

n8n is an open source workflow automation platform. Prior to 2.24.0, an authenticated user with permission to create or modify workflows could achi...

n8n-io n8n < 2.24.0 CVE
MEDIUM 6 CVE-2026-54311

n8n: Merge Node SQL Mode Prototype Pollution_CVE-2026-54311

n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, an authenticated user with permission to create or modify workflows...

n8n-io n8n >= 2.26.0, < 2.26.2 CVE
MEDIUM 6.5 CVE-2026-54310

n8n: SQL Injection in Postgres v1/TimesclaeDB Nodes_CVE-2026-54310

n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, an authenticated user with permission to create or modify workflows...

n8n-io n8n >= 2.26.0, < 2.26.2 CVE
HIGH 8.8 CVE-2026-54309

n8n: n8n MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions_CVE-2026-54309

n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, when @n8n/mcp-browser is run in HTTP transport mode, the MCP endpoi...

n8n-io n8n >= 2.26.0, < 2.26.2 CVE
MEDIUM 6.8 CVE-2026-54303

n8n: Reflected XSS via Facebook, WhatsApp, and Microsoft Teams Trigger Webhook Verification Endpoints_CVE-2026-54303

n8n is an open source workflow automation platform. Prior to 2.24.0, an endpoint in the Meta and Microsoft Teams trigger nodes reflects a query par...

n8n-io n8n < 2.24.0 CVE
HIGH 7.1 CVE-2025-62180

Pega Platform versions 8.3.0 through Infinity 25.1.2 are affected by an authorization weakness that may allow authenticated users to access certain additional data via crafted URLs._CVE-2025-62180

Pega Platform versions 8.3.0 through Infinity 25.1.2 are affected by an authorization weakness that may allow authenticated users to access certain...

Pegasystems Pega Infinity 8.3.0 CVE
LOW 3.5 CVE-2025-15619

HCL Connections is vulnerable to broken access control_CVE-2025-15619

HCL Connections contains a broken access control vulnerability that may allow an unauthorized user to view data in a single specific scenario.

HCLSoftware Connections 7.0, 8.0 CVE