Published issues
Permalink
CVE-2026-34380
5.9 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): Required (R)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): Low (L)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): Required (R)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): Low (L)
-
Modified Availability (MA): High (H)
updated
5 months, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
5 months, 1 week ago
-
@LeSuisse
ignored
3 packages
- openexrid-unstable
- haskellPackages.openexr-write
- openexr_2
5 months, 1 week ago
-
@LeSuisse
accepted
5 months, 1 week ago
-
@LeSuisse
published on GitHub
5 months, 1 week ago
OpenEXR has a signed integer overflow (undefined behavior) in undo_pxr24_impl may allow bounds-check bypass in PXR24 decompression
openexr
-
==>= 3.3.0, < 3.3.9
-
==>= 3.2.0, < 3.2.7
-
==>= 3.4.0, < 3.4.9
updated
5 months, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
5 months, 1 week ago
-
@LeSuisse
ignored
4 packages
- python312Packages.sagemaker-mlflow
- python313Packages.sagemaker-mlflow
- python314Packages.sagemaker-mlflow
- pkgsRocm.python3Packages.sagemaker-mlflow
5 months, 1 week ago
-
@LeSuisse
accepted
5 months, 1 week ago
-
@LeSuisse
published on GitHub
5 months, 1 week ago
Authorization Bypass in MLflow AJAX Endpoint
Permalink
CVE-2026-35586
6.8 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): High (H)
-
Integrity (I): High (H)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): None (N)
updated
5 months, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
5 months, 1 week ago
-
@LeSuisse
ignored
5 packages
- python312Packages.pyloadapi
- python313Packages.pyloadapi
- python314Packages.pyloadapi
- home-assistant-component-tests.pyload
- tests.home-assistant-component-tests.pyload
5 months, 1 week ago
-
@LeSuisse
accepted
5 months, 1 week ago
-
@LeSuisse
published on GitHub
5 months, 1 week ago
Authorization Bypass for SSL Certificate/Key Configuration Due to Option Name Mismatch in pyload-ng
Permalink
CVE-2026-35523
7.5 HIGH
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): High (H)
-
Integrity (I): None (N)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): None (N)
updated
5 months, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
5 months, 1 week ago
-
@LeSuisse
ignored
5 packages
- strawberry
- strawberry-qt6
- python312Packages.strawberry-django
- python313Packages.strawberry-django
- pkgsRocm.python3Packages.strawberry-django
5 months, 1 week ago
-
@LeSuisse
accepted
5 months, 1 week ago
-
@LeSuisse
published on GitHub
5 months, 1 week ago
Authentication bypass in strawberry-graphql via legacy graphql-ws WebSocket subprotocol
updated
5 months, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
5 months, 1 week ago
-
@LeSuisse
ignored
4 packages
- filebrowser-quantum
- python312Packages.filebrowser-safe
- python313Packages.filebrowser-safe
- python314Packages.filebrowser-safe
5 months, 1 week ago
-
@LeSuisse
accepted
5 months, 1 week ago
-
@LeSuisse
published on GitHub
5 months, 1 week ago
File Browser has an access rule bypass via HasPrefix without trailing separator in path matching
Permalink
CVE-2026-34976
10.0 CRITICAL
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Changed (C)
-
Confidentiality (C): High (H)
-
Integrity (I): High (H)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Changed (C)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): High (H)
updated
5 months, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
5 months, 1 week ago
-
@LeSuisse
ignored
5 packages
- coqPackages.dpdgraph
- perlPackages.GDGraph
- perl5Packages.GDGraph
- perl538Packages.GDGraph
- perl540Packages.GDGraph
5 months, 1 week ago
-
@LeSuisse
accepted
5 months, 1 week ago
-
@LeSuisse
published on GitHub
5 months, 1 week ago
Dgraph Affected by Pre-Auth Database Overwrite + SSRF + File Read via restoreTenant Missing Authorization
Permalink
CVE-2026-34371
6.3 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Scope (S): Changed (C)
-
Confidentiality (C): None (N)
-
Integrity (I): High (H)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Changed (C)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): None (N)
updated
5 months, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
5 months, 1 week ago
-
@LeSuisse
deleted
maintainer @niklaskorz
5 months, 1 week ago
maintainer.delete
-
@LeSuisse
accepted
5 months, 1 week ago
-
@LeSuisse
published on GitHub
5 months, 1 week ago
LibreChat Affected by Arbitrary File Write via `execute_code` Artifact Filename Traversal
Permalink
CVE-2026-35533
7.7 HIGH
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): Required (R)
-
Scope (S): Changed (C)
-
Confidentiality (C): High (H)
-
Integrity (I): High (H)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): Required (R)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Changed (C)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): High (H)
updated
5 months, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
5 months, 1 week ago
-
@LeSuisse
ignored
10 packages
- haskellPackages.promises
- python312Packages.promise
- python313Packages.promise
- python314Packages.promise
- ocamlPackages.promise_jsoo
- python312Packages.heatmiserv3
- python313Packages.heatmiserv3
- python314Packages.heatmiserv3
- haskellPackages.unsafe-promises
- ocamlPackages_latest.promise_jsoo
5 months, 1 week ago
-
@LeSuisse
accepted
5 months, 1 week ago
-
@LeSuisse
published on GitHub
5 months, 1 week ago
mise has a local settings bypass config trust checks
mise
-
==>= 2026.2.18, <= 2026.4.5
updated
5 months, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
5 months, 1 week ago
-
@LeSuisse
ignored
8 packages
- botan2
- emiluaPlugins.botan
- python312Packages.botan3
- python313Packages.botan3
- python314Packages.botan3
- haskellPackages.botan-low
- haskellPackages.botan-bindings
- chickenPackages_5.chickenEggs.botan
5 months, 1 week ago
-
@LeSuisse
accepted
5 months, 1 week ago
-
@LeSuisse
published on GitHub
5 months, 1 week ago
Botan has a certificate authentication bypass due to trust anchor confusion
updated
5 months, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
5 months, 1 week ago
-
@LeSuisse
ignored
8 packages
- emiluaPlugins.botan
- python312Packages.botan3
- python313Packages.botan3
- python314Packages.botan3
- haskellPackages.botan-low
- haskellPackages.botan-bindings
- chickenPackages_5.chickenEggs.botan
- botan2
5 months, 1 week ago
-
@LeSuisse
accepted
5 months, 1 week ago
-
@LeSuisse
published on GitHub
5 months, 1 week ago
Botan has a TLS 1.3 certificate authentication bypass