Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.1 CVE-2026-39904

Gophish 0.12.1 Denial of Service via Office Document Upload_CVE-2026-39904

Gophish through 0.12.1 contains a denial of service vulnerability that allows authenticated users with the User role to exhaust server memory by up...

gophish gophish CVE
HIGH 8.8 CVE-2026-56324

Capgo – Rate Limit Bypass via User-Controlled device_id Parameter_CVE-2026-56324

Capgo before 12.128.2 contains a rate limit bypass vulnerability in the channel_self endpoint that allows attackers to circumvent rate limiting by ...

Capgo Capgo CVE
HIGH 8.7 CVE-2026-56323

Capgo – Unauthenticated Channel Enumeration and App Oracle via GET /channel_self_CVE-2026-56323

Capgo before 12.128.2 contains an information disclosure vulnerability in the /functions/v1/channel_self endpoint that allows unauthenticated attac...

Capgo Capgo CVE
HIGH 7.1 CVE-2026-56314

Capgo – Deleted Bundle Selection via Missing Deletion Filter in /updates Endpoint_CVE-2026-56314

Capgo before 12.128.12 fails to filter deleted app versions when joining channels during /updates resolution, allowing deleted bundles to remain se...

Capgo Capgo CVE
HIGH 7.1 CVE-2026-56280

Cap-go – Privilege Inversion in Build Log Stream via SSE Disconnect_CVE-2026-56280

Cap-go before 12.128.2 contains a privilege inversion vulnerability in GET /build/logs/:jobId that allows read-only API key holders to cancel runni...

Cap-go capgo CVE
HIGH 7.1 CVE-2026-56221

Cap-go – SQL Injection in Cloudflare Analytics Engine Queries via cloudflare.ts_CVE-2026-56221

Cap-go before 12.128.2 contains multiple SQL injection vulnerabilities in cloudflare.ts where user-controlled values from API request bodies are in...

Cap-go capgo CVE
HIGH 7.6 CVE-2026-55409

Filament: Disabled RichEditor field state can be used for XSS_CVE-2026-55409

Filament is a collection of full-stack components for accelerated Laravel development. From 3.0.0 until 3.3.53, a disabled RichEditor field rendere...

filamentphp filament >= 3.0.0, < 3.3.53 CVE
HIGH 8.7 CVE-2026-54281

Nest: Middleware Bypass on Fastify via Trailing Slash_CVE-2026-54281

Nest is a framework for building scalable Node.js server-side applications. Prior to 11.1.24, an authentication bypass vulnerability exists in @nes...

nestjs nest < 11.1.24 CVE
HIGH 7.5 CVE-2026-48506

MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depth_CVE-2026-48506

MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePackReader.TrySkip() recursively descends into nested arr...

MessagePack-CSharp MessagePack-CSharp >= 3.1.7, < 3.1.7 CVE
HIGH 7.4 CVE-2026-48505

Filament: Multi-factor authentication (app) recovery codes can still be used multiple times via concurrent submission_CVE-2026-48505

Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5, a flaw in the handling of...

filamentphp filament >= 4.0.0, < 4.11.5 CVE