Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.3 CVE-2026-44911

Apache NiFi: Incorrect Authorization for Configuration Verification Requests_CVE-2026-44911

Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 through 2.9.0 allows clients with read access to sub...

Apache Software Foundation Apache NiFi 1.15.0 CVE
LOW 2.3 CVE-2026-12771

BerriAI litellm M2M JWT user_api_key_auth.py improper authorization_CVE-2026-12771

A vulnerability was identified in BerriAI litellm up to 1.82.2. This affects an unknown function of the file litellm/proxy/auth/user_api_key_auth.p...

BerriAI litellm 1.82.0 CVE
LOW 3.7 CVE-2026-56355

CVE-2026-56355_CVE-2026-56355

GNU Savannah Administration Savane through 3.17 uses untrusted data as part of authorization.

GNU Savane 3.14 CVE
LOW 2.3 CVE-2026-56325

Capgo – App ID Confusion via ILIKE Wildcard in Preview Subdomain Lookup_CVE-2026-56325

Capgo before 12.128.2 uses ILIKE pattern matching instead of exact matching for app_id lookup in the preview subdomain resolver, allowing underscor...

Capgo Capgo CVE
LOW 2.3 CVE-2026-56317

Nuxt – Cross-Site Scripting via NoScript Component Slot Content_CVE-2026-56317

Nuxt before 4.4.7 (and the 3.x branch before 3.21.7) contains a cross-site scripting vulnerability in the NoScript component that writes slot conte...

Nuxt Nuxt 4.0.0 CVE
LOW 3.1 MS:CVE-2026-12458

CVE-2026-12458 Incorrect security UI in Passwords_MS:CVE-2026-12458

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Rel...

N/A N/A MSCVE
LOW 1.3 CVE-2026-48794

Authelia has an Edge Case Access Control Rule Mismatch_CVE-2026-48794

Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-on (SSO) for applications vi...

authelia authelia >= 4.36.0, < 4.39.20 CVE
LOW 2.9 CVE-2026-47203

Authelia Missing Username Canonicalization in Basic Auth (LDAP)_CVE-2026-47203

Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-on (SSO) for applications vi...

authelia authelia >= 4.38.0, < 4.39.20 CVE
LOW 1.8 CVE-2026-48617

CVE-2026-48617_CVE-2026-48617

A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentialit...

nodejs node 22.22.3 CVE
LOW 2.3 CVE-2026-8668

Hardcoded credentials in embedded content_CVE-2026-8668

A static credential embedded in Chef 360 prior to v1.7.0 permitted unauthenticated access to internal message queues.  Queue messages contained ten...

Progress Chef Chef360 CVE