安全情报

A collection of 572 posts
安全情报

CVE-2026-4430 (CVSS 7.8) - Out-of-bounds write vulnerability in The Document Foundation LibreOffice via cra

📡 NVD-Latest · 2026-05-07 CVE-2026-4430 (CVSS 7.8) - Out-of-bounds write vulnerability in The Document Foundation LibreOffice via cra CVE-2026-4430 CVE-2026-4430 CVSS:7.8 Out-of-bounds write vulnerability in The Document Foundation LibreOffice via crafted OOXML documents with mismatched encryption salt parameters. This issue affects LibreOffice: from 26.2 before 26.2.3,
安全情报

CVE-2026-5784 (CVSS 8.8) - Improper neutralization of input during web page generation ('cross-site scripti

📡 NVD-Latest · 2026-05-07 CVE-2026-5784 (CVSS 8.8) - Improper neutralization of input during web page generation ('cross-site scripti CVE-2026-5784 CVE-2026-5784 CVSS:8.8 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Stored XSS. This issue affects DivvyDrive: from
安全情报

CVE-2026-6002 (CVSS 8.8) - Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vu

📡 NVD-Latest · 2026-05-07 CVE-2026-6002 (CVSS 8.8) - Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vu CVE-2026-6002 CVE-2026-6002 CVSS:8.8 Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Cross-Site Scripting (XSS). This issue
安全情报

CVE-2026-41490 (CVSS 8.3) - Dagster is an orchestration platform for the development, production, and observ

📡 NVD-Latest · 2026-05-07 CVE-2026-41490 (CVSS 8.3) - Dagster is an orchestration platform for the development, production, and observ CVE-2026-41490 CVE-2026-41490 CVSS:8.3 Dagster is an orchestration platform for the development, production, and observation of data assets. Prior to Dagster Core version 1.13.1 and prior to Dagster libraries
阅读时间 1 分钟
安全情报

CVE-2026-44788 - SharpCompress has directory traversal via directory entries in WriteToDirectory

📡 GitHub-Advisory · 2026-05-08 CVE-2026-44788 - SharpCompress has directory traversal via directory entries in WriteToDirectory CVE-2026-44788 GHSA-6c8g-7p36-r338 MEDIUM nuget/SharpCompress CVE: CVE-2026-44788 Summary A path traversal vulnerability in IArchive.WriteToDirectory() allows a malicious archive to create directories outside the intended extraction root. For TAR archives, this can be escalated to arbitrary file
阅读时间 1 分钟
安全情报

CVE-2026-44900 - epa4all-client has a VAU Signature bypass

📡 GitHub-Advisory · 2026-05-08 CVE-2026-44900 - epa4all-client has a VAU Signature bypass CVE-2026-44900 GHSA-g8r3-5hwf-qp96 HIGH maven/com.oviva.telematik:epa4all-client CVE: CVE-2026-44900 Impact In SignedPublicKeysTrustValidatorImpl.isTrusted(), the ECDSA signature verification at line 45 discards the boolean return value of Signature.verify(). The method performs certificate chain validation, OCSP check, and signature algorithm
安全情报

CVE-2026-44896 - Mistune has XSS via unescaped figclass/figwidth in Figure directive

📡 GitHub-Advisory · 2026-05-08 CVE-2026-44896 - Mistune has XSS via unescaped figclass/figwidth in Figure directive CVE-2026-44896 GHSA-58cw-g322-p94v MEDIUM pip/mistune CVE: CVE-2026-44896 In src/mistune/directives/image.py, the render_figure() function concatenates figclass and figwidth options directly into HTML attributes without escaping (lines 152-168). This allows attribute injection and XSS
安全情报

CVE-2026-44837 - view_component: System Test Entry Point Path Check Allows Sibling Directory Esca

📡 GitHub-Advisory · 2026-05-08 CVE-2026-44837 - view_component: System Test Entry Point Path Check Allows Sibling Directory Esca CVE-2026-44837 GHSA-hg3h-g7xc-f7vp MEDIUM rubygems/view_component CVE: CVE-2026-44837 Summary The system test entrypoint canonicalizes a user-controlled file path with File.realpath, then checks whether the resolved path starts with the temp directory path. This
阅读时间 1 分钟
安全情报

GHSA-mv93-w799-cj2w - GitPython: Newline injection in config_writer() section parameter bypasses CVE-2

📡 GitHub-Advisory · 2026-05-08 GHSA-mv93-w799-cj2w - GitPython: Newline injection in config_writer() section parameter bypasses CVE-2 CVE-2026-42215 GHSA-mv93-w799-cj2w HIGH pip/GitPython CVE: Summary The patch for CVE-2026-42215 (GitPython 3.1.49) validates newlines only in the value parameter of set_value(). The section and option parameters are passed to configparser without any
阅读时间 1 分钟
安全情报

CVE-2026-44844 - eml_parser has recursion DoS via nested message/rfc822 attachments

📡 GitHub-Advisory · 2026-05-08 CVE-2026-44844 - eml_parser has recursion DoS via nested message/rfc822 attachments CVE-2026-44844 GHSA-g47v-rwmh-r9f8 MEDIUM pip/eml_parser CVE: CVE-2026-44844 Summary EmlParser.get_raw_body_text() recurses unconditionally for every nested message/rfc822 attachment without any depth limit. An attacker who can supply a badly crafted EML file
阅读时间 1 分钟
安全情报

CVE-2026-44843 - LangChain vulnerable to unsafe deserialization of attacker-controlled objects th

📡 GitHub-Advisory · 2026-05-08 CVE-2026-44843 - LangChain vulnerable to unsafe deserialization of attacker-controlled objects th CVE-2026-44843 GHSA-pjwx-r37v-7724 HIGH pip/langchain-core CVE: CVE-2026-44843 LangChain contains older runtime code paths that deserialize run inputs, run outputs, or other application-controlled payloads using overly broad object allowlists. These paths may call load() with allowed_objects="
阅读时间 1 分钟
安全情报

CVE-2026-44330 - free5GC's NEF nnef-pfdmanagement API is unauthenticated; forged bearer tokens ca

📡 GitHub-Advisory · 2026-05-08 CVE-2026-44330 - free5GC's NEF nnef-pfdmanagement API is unauthenticated; forged bearer tokens ca CVE-2026-44330 GHSA-rwww-x45w-p52w CRITICAL go/github.com/free5gc/nef CVE: CVE-2026-44330 Summary free5GC's NEF mounts the nnef-pfdmanagement route group without inbound OAuth2/bearer-token authorization. A network attacker who can reach NEF on the
阅读时间 1 分钟
安全情报

CVE-2026-44329 - free5GC's SMF UPI management interface lacks auth middleware; unauthenticated to

📡 GitHub-Advisory · 2026-05-08 CVE-2026-44329 - free5GC's SMF UPI management interface lacks auth middleware; unauthenticated to CVE-2026-44329 GHSA-3258-qmv8-frp3 CRITICAL go/github.com/free5gc/smf CVE: CVE-2026-44329 Summary free5GC's SMF mounts the UPI management route group without OAuth2/bearer-token authorization middleware. A network attacker who can reach SMF on
阅读时间 1 分钟
[!] CONTACT_CHANNELS

如需商务合作、技术咨询或漏洞反馈,请通过以下离岸节点联系作者。

> PING_AUTHOR (@A1RedTeam)