Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.8 CVE-2026-54232

vLLM: Dependency Confusion Vulnerability in vLLM Dockerfile_CVE-2026-54232

vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.1, the vLLM Dockerfile is vulnerable to a dependency confus...

vllm-project vllm < 0.22.1 CVE
HIGH 7.5 CVE-2026-41523

vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution_CVE-2026-41523

vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, an assert-based security check in vLLM's activation func...

vllm-project vllm < 0.22.0 CVE
HIGH 8.8 MS:CVE-2026-12439

Chromium: CVE-2026-12439 Use after free in Digital Credentials_MS:CVE-2026-12439

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Rel...

N/A N/A MSCVE
HIGH 7.5 CVE-2026-55603

http-proxy-middleware: multipart/form-data field injection via unescaped CRLF in `fixRequestBody`_CVE-2026-55603

http-proxy-middleware is node.js http-proxy middleware. From 3.0.4 until 3.0.7 and 4.1.1, fixRequestBody() is the library's documented helper for r...

chimurai http-proxy-middleware >= 3.0.4, < 3.0.7 CVE
HIGH 7.1 CVE-2026-39904

Gophish 0.12.1 Denial of Service via Office Document Upload_CVE-2026-39904

Gophish through 0.12.1 contains a denial of service vulnerability that allows authenticated users with the User role to exhaust server memory by up...

gophish gophish CVE
HIGH 8.8 CVE-2026-56324

Capgo – Rate Limit Bypass via User-Controlled device_id Parameter_CVE-2026-56324

Capgo before 12.128.2 contains a rate limit bypass vulnerability in the channel_self endpoint that allows attackers to circumvent rate limiting by ...

Capgo Capgo CVE
HIGH 8.7 CVE-2026-56323

Capgo – Unauthenticated Channel Enumeration and App Oracle via GET /channel_self_CVE-2026-56323

Capgo before 12.128.2 contains an information disclosure vulnerability in the /functions/v1/channel_self endpoint that allows unauthenticated attac...

Capgo Capgo CVE
HIGH 7.1 CVE-2026-56314

Capgo – Deleted Bundle Selection via Missing Deletion Filter in /updates Endpoint_CVE-2026-56314

Capgo before 12.128.12 fails to filter deleted app versions when joining channels during /updates resolution, allowing deleted bundles to remain se...

Capgo Capgo CVE
HIGH 7.1 CVE-2026-56280

Cap-go – Privilege Inversion in Build Log Stream via SSE Disconnect_CVE-2026-56280

Cap-go before 12.128.2 contains a privilege inversion vulnerability in GET /build/logs/:jobId that allows read-only API key holders to cancel runni...

Cap-go capgo CVE
HIGH 7.1 CVE-2026-56221

Cap-go – SQL Injection in Cloudflare Analytics Engine Queries via cloudflare.ts_CVE-2026-56221

Cap-go before 12.128.2 contains multiple SQL injection vulnerabilities in cloudflare.ts where user-controlled values from API request bodies are in...

Cap-go capgo CVE