Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.1 CVE-2026-7846

chatchat-space Langchain-Chatchat OpenAI-Compatible File Upload API openai_routes.py files toctou_CVE-2026-7846

A vulnerability has been found in chatchat-space Langchain-Chatchat up to 0.3.1.3. Impacted is the function files of the file libs/chatchat-server/...

chatchat-space Langchain-Chatchat 0.3.1.0 CVE
LOW 2.1 CVE-2026-7845

chatchat-space Langchain-Chatchat Vision Chat Paste Image dialogue.py PIL.Image.tobytes weak hash_CVE-2026-7845

A flaw has been found in chatchat-space Langchain-Chatchat up to 0.3.1.3. This issue affects the function PIL.Image.tobytes of the file libs/chatch...

chatchat-space Langchain-Chatchat 0.3.1.0 CVE
LOW 2.3 CVE-2026-35192

Session fixation via public cached pages and SESSION_SAVE_EVERY_REQUEST_CVE-2026-35192

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. Response headers do not vary on cookies if a session is not modified, but `SESSI...

djangoproject Django 6.0 CVE
LOW 2.1 CVE-2026-7847

chatchat-space Langchain-Chatchat Uploaded File openai_routes.py _get_file_id random values_CVE-2026-7847

A vulnerability was found in chatchat-space Langchain-Chatchat up to 0.3.1.3. The affected element is the function _get_file_id of the file libs/ch...

chatchat-space Langchain-Chatchat 0.3.1.0 CVE
LOW 2 CVE-2026-43529

OpenClaw < 2026.4.10 - Time-of-Check-Time-of-Use (TOCTOU) Race Condition in exec Script Preflight Validator_CVE-2026-43529

OpenClaw before 2026.4.10 contains a time-of-check-time-of-use vulnerability in the validateScriptFileForShellBleed function that allows local atta...

OpenClaw OpenClaw CVE
LOW 3.7 CVE-2026-43964

CVE-2026-43964_CVE-2026-43964

Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code ...

Postfix Postfix 2.3 CVE
LOW 2.4 CVE-2026-6499

CVE-2026-6499_CVE-2026-6499

Incorrect Permission Assignment for Critical Resource vulnerability in ILM Informatique OpenConcerto allows Replace Binaries. This issue affects O...

ILM Informatique OpenConcerto 1.7.5 CVE
LOW 2.5 CVE-2026-43864

CVE-2026-43864_CVE-2026-43864

mutt before 2.3.2 has a show_sig_summary NULL pointer dereference.

mutt mutt CVE
LOW 3.7 CVE-2026-43863

CVE-2026-43863_CVE-2026-43863

mutt before 2.3.2 has an infinite loop in data_object_to_stream in crypt-gpgme.c.

mutt mutt CVE
LOW 3.7 CVE-2026-43862

CVE-2026-43862_CVE-2026-43862

In mutt before 2.3.2, the imap_auth_gss security level is mishandled.

mutt mutt CVE