安全情报

A collection of 572 posts
安全情报

CVE-2026-42786 - Bandit Buffers Unbounded WebSocket Continuation Frames, Allowing Unauthenticated

📡 GitHub-Advisory · 2026-05-07 CVE-2026-42786 - Bandit Buffers Unbounded WebSocket Continuation Frames, Allowing Unauthenticated CVE-2026-42786 GHSA-pf94-94m9-536p HIGH erlang/bandit CVE: CVE-2026-42786 Summary A single unauthenticated WebSocket client can exhaust server memory in any Bandit-fronted application that accepts WebSocket connections. The fragmented-message reassembly path appends every Continuation{fin: false} frame's payload
阅读时间 1 分钟
安全情报

CVE-2026-39804 - Bandit's unbounded WebSocket inflate causes BEAM OOM with a single frame

📡 GitHub-Advisory · 2026-05-07 CVE-2026-39804 - Bandit's unbounded WebSocket inflate causes BEAM OOM with a single frame CVE-2026-39804 GHSA-frh3-6pv6-rc8j HIGH erlang/bandit CVE: CVE-2026-39804 Summary When a Bandit-fronted server has explicitly enabled WebSocket permessage-deflate (compress: true), an unauthenticated client can OOM the BEAM with a single ~6 MiB WebSocket frame.
阅读时间 1 分钟
安全情报

GHSA-mmpx-jh39-wrv6 - FileBrowser Vulnerable to Stored XSS via SVG File in Public Share (Missing CSP H

📡 GitHub-Advisory · 2026-05-07 GHSA-mmpx-jh39-wrv6 - FileBrowser Vulnerable to Stored XSS via SVG File in Public Share (Missing CSP H GHSA-mmpx-jh39-wrv6 MEDIUM go/github.com/gtsteffaniak/filebrowser CVE: Summary FileBrowser Quantum serves inline SVG files without a Content-Security-Policy header, allowing embedded JavaScript in SVG files to execute when accessed via public share
阅读时间 1 分钟
安全情报

CVE-2026-44542 - FileBrowser Public Share DELETE API Path Traversal Allows Unauthenticated Arbitr

📡 GitHub-Advisory · 2026-05-07 CVE-2026-44542 - FileBrowser Public Share DELETE API Path Traversal Allows Unauthenticated Arbitr CVE-2026-44542 GHSA-fwj3-42wh-8673 CRITICAL go/github.com/gtsteffaniak/filebrowser CVE: CVE-2026-44542 **Summary** Attacker-controlled path input is joined with a trusted base path prior to sanitization, allowing traversal sequences (e.g., ../) to escape the intended shared directory. As
阅读时间 1 分钟
安全情报

CVE-2026-44520 - docling-graph has SSRF via Missing Internal IP Validation in URLInputHandler

📡 GitHub-Advisory · 2026-05-07 CVE-2026-44520 - docling-graph has SSRF via Missing Internal IP Validation in URLInputHandler CVE-2026-44520 GHSA-fqph-j6v6-jvgx MEDIUM pip/docling-graph CVE: CVE-2026-44520 Impact The URLInputHandler class in docling_graph/core/input/handlers.py makes HTTP requests to user-supplied URLs without validating whether the target resolves to a private, loopback, or link-local
阅读时间 1 分钟
安全情报

GHSA-w5p8-4jcx-2j6r - imageproc: integer overflow in kernel size check leads to out-of-bounds read

📡 GitHub-Advisory · 2026-05-07 GHSA-w5p8-4jcx-2j6r - imageproc: integer overflow in kernel size check leads to out-of-bounds read GHSA-w5p8-4jcx-2j6r MEDIUM rust/imageproc CVE: A bounds verification of a slice storage of a 2-dimensional matrix's coefficients (a kernel) would compare the total size against the product of individual dimensions. This would erroneously
阅读时间 1 分钟
安全情报

GHSA-qg8r-f7x3-25f7 - imageproc: Out-of-bounds read via NaN coordinates in bilinear/bicubic sampling

📡 GitHub-Advisory · 2026-05-07 GHSA-qg8r-f7x3-25f7 - imageproc: Out-of-bounds read via NaN coordinates in bilinear/bicubic sampling GHSA-qg8r-f7x3-25f7 MEDIUM rust/imageproc CVE: A bounds check was performed in floating points before a cast to the index passed to an unchecked access function. This checked considered NaN cases improperly, causing them to succeed the
阅读时间 1 分钟
安全情报

CVE-2026-44426 - ShellHub has cross-tenant IDOR in `GET /api/namespaces/:tenant` via API Key bypa

📡 GitHub-Advisory · 2026-05-07 CVE-2026-44426 - ShellHub has cross-tenant IDOR in `GET /api/namespaces/:tenant` via API Key bypa CVE-2026-44426 GHSA-vwx9-7qcf-gg7f MEDIUM go/github.com/shellhub-io/shellhub CVE: CVE-2026-44426 Summary GET /api/namespaces/:tenant returns the full namespace object — including the members list (user IDs, e-mails, roles), settings, and device counts — to
阅读时间 1 分钟
安全情报

GHSA-3v94-mw7p-v465 - hickory-proto: NSEC3 closest-encloser proof validation enters unbounded loop on

📡 GitHub-Advisory · 2026-05-07 GHSA-3v94-mw7p-v465 - hickory-proto: NSEC3 closest-encloser proof validation enters unbounded loop on GHSA-3v94-mw7p-v465 HIGH rust/hickory-proto CVE: The NSEC3 closest-encloser proof validation in hickory-proto's (0.25.0-alpha.3 ... 0.25.2) and hickory-net's (0.26.0-alpha.1 .. 0.26.0) DnssecDnsHandle walks from the QNAME
阅读时间 1 分钟
安全情报

GHSA-258c-965c-p3hc - Daptin's Session Management Vulnerability Leads to Insufficient Session Expirati

📡 GitHub-Advisory · 2026-05-07 GHSA-258c-965c-p3hc - Daptin's Session Management Vulnerability Leads to Insufficient Session Expirati GHSA-258c-965c-p3hc MEDIUM go/github.com/daptin/daptin CVE: Summary A session invalidation vulnerability exists in daptin's authentication system where JSON Web Tokens (JWTs) remain fully valid after a user changes their password. The
阅读时间 1 分钟
安全情报

GHSA-m38g-vww2-mvgx - Talos Linux has a local privilege escalation from untrusted workloads

📡 GitHub-Advisory · 2026-05-07 GHSA-m38g-vww2-mvgx - Talos Linux has a local privilege escalation from untrusted workloads CVE-2026-31431 GHSA-m38g-vww2-mvgx HIGH go/github.com/siderolabs/talos CVE: Summary A vulnerability in the Linux kernel's algif_aead subsystem (CVE-2026-31431, "copy.fail") allows an unprivileged container workload to corrupt arbitrary file page-cache
阅读时间 1 分钟
安全情报

CVE-2026-44514 - Kubetail has a Cross-Site WebSocket Hijacking issue that allows attacker to read

📡 GitHub-Advisory · 2026-05-07 CVE-2026-44514 - Kubetail has a Cross-Site WebSocket Hijacking issue that allows attacker to read CVE-2026-44514 GHSA-v8j7-hp7c-738f MEDIUM go/github.com/kubetail-org/kubetail/modules/dashboard CVE: CVE-2026-44514 Summary Kubetail's dashboard exposes WebSocket endpoints that did not adequately validate the Origin header on connection upgrade. A malicious web
阅读时间 1 分钟
安全情报

CVE-2026-44511 - katalyst-koi: Session cookies can be replayed after user logout

📡 GitHub-Advisory · 2026-05-07 CVE-2026-44511 - katalyst-koi: Session cookies can be replayed after user logout CVE-2026-44511 GHSA-4cx3-3c38-j9vv HIGH rubygems/katalyst-koi CVE: CVE-2026-44511 Impact Admin session cookies were not invalidated when an admin user logged out. An attacker with access to a valid admin session cookie could continue to access admin functionality after
阅读时间 1 分钟
安全情报

CVE-2026-42459 - Free5GC UDM has Improper Input Validation and Generation of Error Messages Conta

📡 GitHub-Advisory · 2026-05-07 CVE-2026-42459 - Free5GC UDM has Improper Input Validation and Generation of Error Messages Conta CVE-2026-42459 GHSA-585v-hcgf-jhfr HIGH go/github.com/free5gc/udm CVE: CVE-2026-42459 Summary The free5GC UDM component fails to validate the supi path parameter in six GET handlers of the nudm-sdm (Subscriber Data Management) service. An
阅读时间 1 分钟
安全情报

CVE-2026-42328 - go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth

📡 GitHub-Advisory · 2026-05-07 CVE-2026-42328 - go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth CVE-2026-42328 GHSA-w239-58x2-q8p5 MEDIUM go/github.com/ipld/go-ipld-prime CVE: CVE-2026-42328 The DAG-CBOR and DAG-JSON decoders recurse on each nested map or list without a depth limit. A payload containing deeply nested collections causes the decoder
阅读时间 1 分钟
安全情报

CVE-2026-44312 - CSS Parser: Improper Certificate Validation allows MITM injection of remote CSS

📡 GitHub-Advisory · 2026-05-07 CVE-2026-44312 - CSS Parser: Improper Certificate Validation allows MITM injection of remote CSS CVE-2026-44312 GHSA-ff6c-w6qf-7xqc MEDIUM rubygems/css_parser CVE: CVE-2026-44312 Summary The CSS Parser gem does not validate HTTPS connections, allowing a Man-in-the-Middle (MITM) attacker to inject or modify CSS content when stylesheets are loaded via HTTPS.
阅读时间 1 分钟
安全情报

CVE-2026-42083 - Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows ac

📡 GitHub-Advisory · 2026-05-07 CVE-2026-42083 - Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows ac CVE-2026-42083 GHSA-6rgm-gr97-x3j5 HIGH go/github.com/free5gc/pcf CVE: CVE-2026-42083 Summary PCF Npcf_SMPolicyControl missing authentication middleware allows unauthenticated access to SM policy handlers and disclosure of subscriber SUPI Details In NewServer(), the smPolicyGroup route group
阅读时间 1 分钟
安全情报

CVE-2026-42081 - Free5GC AMF Bypasses UE Security Capabilities on NGAP PathSwitchRequest

📡 GitHub-Advisory · 2026-05-07 CVE-2026-42081 - Free5GC AMF Bypasses UE Security Capabilities on NGAP PathSwitchRequest CVE-2026-42081 GHSA-77x9-rf64-92gv MEDIUM go/github.com/free5gc/amf CVE: CVE-2026-42081 Summary The AMF in Free5GC v4.2.1 does not verify the UE Security Capabilities received in NGAP PathSwitchRequest messages against its locally stored values, as mandated
阅读时间 1 分钟
[!] CONTACT_CHANNELS

如需商务合作、技术咨询或漏洞反馈,请通过以下离岸节点联系作者。

> PING_AUTHOR (@A1RedTeam)