Published issues
kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default
Permalink
CVE-2026-73501
9.1 CRITICAL
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): High (H)
-
Integrity (I): High (H)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): None (N)
updated
1 day, 3 hours ago
by @LeSuisse
Activity log
-
Created suggestion
1 day, 8 hours ago
-
@LeSuisse
accepted
1 day, 4 hours ago
-
@LeSuisse
published on GitHub
1 day, 3 hours ago
kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default
Incorrect Privilege Assignment in GitLab
Permalink
CVE-2025-9486
3.3 LOW
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): High (H)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): Low (L)
-
Integrity (I): Low (L)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): High (H)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): Low (L)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): Low (L)
-
Modified Availability (MA): None (N)
updated
1 day, 3 hours ago
by @LeSuisse
Activity log
-
Created suggestion
1 day, 8 hours ago
-
@LeSuisse
ignored
40 packages
- gitlab-art
- gitlab-duo
- gitlab-kas
- gitlab-ci-ls
- gitlab-pages
- gitlab-shell
- danger-gitlab
- gitlab-clippy
- gitlab-runner
- gitlab-triage
- gitlab-ci-local
- gitlab-timelogs
- gitlab-ci-linter
- gitlab-workhorse
- gitlab-ci-validate
- gitlab-release-cli
- ocamlPackages.gitlab
- gitlab-container-registry
- ocamlPackages.gitlab-jsoo
- ocamlPackages.gitlab-unix
- rubyPackages.gitlab-markup
- terraform-providers.gitlab
- ocamlPackages_latest.gitlab
- gitlab-elasticsearch-indexer
- haskellPackages.gitlab-haskell
- rubyPackages_3_3.gitlab-markup
- rubyPackages_3_4.gitlab-markup
- rubyPackages_4_0.gitlab-markup
- python313Packages.mkdocs-gitlab
- python313Packages.python-gitlab
- python314Packages.mkdocs-gitlab
- python314Packages.python-gitlab
- ocamlPackages_latest.gitlab-jsoo
- ocamlPackages_latest.gitlab-unix
- terraform-providers.gitlabhq_gitlab
- gnomeExtensions.gitlab-time-tracking
- prometheus-gitlab-ci-pipelines-exporter
- vscode-extensions.gitlab.gitlab-workflow
- perlPackages.AlienBuildPluginDownloadGitLab
- perl5Packages.AlienBuildPluginDownloadGitLab
1 day, 4 hours ago
-
@LeSuisse
accepted
1 day, 4 hours ago
-
@LeSuisse
published on GitHub
1 day, 3 hours ago
Incorrect Privilege Assignment in GitLab
Integer Overflow to Buffer Overflow vulnerability in Samsung Open Source …
Permalink
CVE-2026-19588
6.5 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): Required (R)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): Required (R)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): High (H)
updated
1 day, 3 hours ago
by @LeSuisse
Activity log
-
Created suggestion
1 day, 8 hours ago
-
@LeSuisse
ignored
package libsForQt5.rlottie-qml
1 day, 4 hours ago
-
@LeSuisse
accepted
1 day, 4 hours ago
-
@LeSuisse
published on GitHub
1 day, 3 hours ago
Integer Overflow to Buffer Overflow vulnerability in Samsung Open Source …
rlottie
-
==8117b9ee595763f35c0da2c07181203959f0c510
regclient may leak authentication credentials to external blob stores
Permalink
CVE-2026-49349
6.8 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): Required (R)
-
Scope (S): Changed (C)
-
Confidentiality (C): High (H)
-
Integrity (I): None (N)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): Required (R)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Changed (C)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): None (N)
updated
1 day, 3 hours ago
by @LeSuisse
Activity log
-
Created suggestion
1 day, 8 hours ago
-
@LeSuisse
ignored
3 packages
1 day, 4 hours ago
-
@LeSuisse
accepted
1 day, 4 hours ago
-
@LeSuisse
published on GitHub
1 day, 3 hours ago
regclient may leak authentication credentials to external blob stores
tablib versions prior to 3.10.0 Stored XSS via HTML Export Dataset Title
Permalink
CVE-2026-9318
4.8 MEDIUM
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): Active (A)
-
Vulnerable System Impact Confidentiality (VC): Low (L)
-
Vulnerable System Impact Integrity (VI): Low (L)
-
Vulnerable System Impact Availability (VA): None (N)
-
Subsequent System Impact Confidentiality (SC): Low (L)
-
Subsequent System Impact Integrity (SI): Low (L)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): Active (A)
-
Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
-
Modified Vulnerable System Impact Integrity (MVI): Low (L)
-
Modified Vulnerable System Impact Availability (MVA): None (N)
-
Modified Subsequent System Impact Confidentiality (MSC): Low (L)
-
Modified Subsequent System Impact Integrity (MSI): Low (L)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
1 day, 3 hours ago
by @LeSuisse
Activity log
-
Created suggestion
1 day, 8 hours ago
-
@LeSuisse
accepted
1 day, 4 hours ago
-
@LeSuisse
published on GitHub
1 day, 3 hours ago
tablib versions prior to 3.10.0 Stored XSS via HTML Export Dataset Title
RustFS: Object Lock (WORM) protections are treated as absent when bucket metadata cannot be read, allowing retained objects to be deleted
Permalink
CVE-2026-73288
6.1 MEDIUM
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Attack Requirement (AT): Present (P)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): None (N)
-
Vulnerable System Impact Integrity (VI): High (H)
-
Vulnerable System Impact Availability (VA): High (H)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): None (N)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Attack Requirement (MAT): Present (P)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): None (N)
-
Modified Vulnerable System Impact Integrity (MVI): High (H)
-
Modified Vulnerable System Impact Availability (MVA): High (H)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Negligible (N)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
1 day, 3 hours ago
by @LeSuisse
Activity log
-
Created suggestion
1 day, 9 hours ago
-
@LeSuisse
accepted
1 day, 4 hours ago
-
@LeSuisse
published on GitHub
1 day, 3 hours ago
RustFS: Object Lock (WORM) protections are treated as absent when bucket metadata cannot be read, allowing retained objects to be deleted
Material for MkDocs: DOM XSS in search suggestions via query parameter
Permalink
CVE-2026-73295
5.4 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): Required (R)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): Low (L)
-
Integrity (I): Low (L)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): Required (R)
-
Modified Confidentiality (MC): Low (L)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): Low (L)
-
Modified Availability (MA): None (N)
updated
1 day, 3 hours ago
by @LeSuisse
Activity log
-
Created suggestion
1 day, 9 hours ago
-
@LeSuisse
ignored
2 packages
- python313Packages.mkdocs-material-extensions
- python314Packages.mkdocs-material-extensions
1 day, 4 hours ago
-
@LeSuisse
accepted
1 day, 4 hours ago
-
@LeSuisse
published on GitHub
1 day, 3 hours ago
Material for MkDocs: DOM XSS in search suggestions via query parameter
Uncontrolled Resource Consumption vulnerability in Samsung Open Source rlottie allows …
Permalink
CVE-2026-19587
6.5 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): Required (R)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): Required (R)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): High (H)
updated
1 day, 3 hours ago
by @LeSuisse
Activity log
-
Created suggestion
1 day, 9 hours ago
-
@LeSuisse
ignored
package libsForQt5.rlottie-qml
1 day, 4 hours ago
-
@LeSuisse
accepted
1 day, 4 hours ago
-
@LeSuisse
published on GitHub
1 day, 3 hours ago
Uncontrolled Resource Consumption vulnerability in Samsung Open Source rlottie allows …
rlottie
-
==87e166c0a72b6f3110083dd6de0e47dcb9e1c2b5
jupyterlab: Image viewer in JupyterLab allows XSS when opening malicious image in new browser tab
Permalink
CVE-2026-73415
7.5 HIGH
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): Active (A)
-
Vulnerable System Impact Confidentiality (VC): High (H)
-
Vulnerable System Impact Integrity (VI): High (H)
-
Vulnerable System Impact Availability (VA): Low (L)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): None (N)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): Active (A)
-
Modified Vulnerable System Impact Confidentiality (MVC): High (H)
-
Modified Vulnerable System Impact Integrity (MVI): High (H)
-
Modified Vulnerable System Impact Availability (MVA): Low (L)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Negligible (N)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
1 day, 3 hours ago
by @LeSuisse
Activity log
-
Created suggestion
1 day, 9 hours ago
-
@LeSuisse
ignored
16 packages
- python313Packages.jupyterlab-git
- python313Packages.jupyterlab-lsp
- python313Packages.jupyterlab-vim
- python314Packages.jupyterlab-git
- python314Packages.jupyterlab-lsp
- python314Packages.jupyterlab-vim
- python313Packages.jupyterlab-server
- python314Packages.jupyterlab-server
- python313Packages.jupyterlab-widgets
- python314Packages.jupyterlab-widgets
- python313Packages.jupyterlab-git-core
- python313Packages.jupyterlab-pygments
- python314Packages.jupyterlab-git-core
- python314Packages.jupyterlab-pygments
- python313Packages.jupyterlab-execute-time
- python314Packages.jupyterlab-execute-time
1 day, 4 hours ago
-
@LeSuisse
accepted
1 day, 4 hours ago
-
@LeSuisse
published on GitHub
1 day, 3 hours ago
jupyterlab: Image viewer in JupyterLab allows XSS when opening malicious image in new browser tab
jupyterlab
-
==< 4.5.10
-
==>= 4.6.0, < 4.6.2
Seerr: Path traversal to RCE via /avatarproxy image cache filename from upstream ETag
Permalink
CVE-2026-73291
7.1 HIGH
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Adjacent (A)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): Low (L)
-
Integrity (I): High (H)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Adjacent (A)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): Low (L)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): High (H)
updated
1 day, 3 hours ago
by @LeSuisse
Activity log
-
Created suggestion
1 day, 9 hours ago
-
@LeSuisse
ignored
4 packages
- overseerr
- jellyseerr
- python313Packages.python-overseerr
- python314Packages.python-overseerr
1 day, 4 hours ago
-
@LeSuisse
accepted
1 day, 4 hours ago
-
@LeSuisse
published on GitHub
1 day, 3 hours ago
Seerr: Path traversal to RCE via /avatarproxy image cache filename from upstream ETag