Published issues
Permalink
CVE-2026-44426
6.5 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): High (H)
-
Integrity (I): None (N)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): None (N)
updated
1 month, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
1 month, 1 week ago
-
@LeSuisse
accepted
1 month, 1 week ago
-
@LeSuisse
published on GitHub
1 month, 1 week ago
ShellHub: Cross-tenant IDOR in `GET /api/namespaces/:tenant` via API Key bypasses membership check
Permalink
CVE-2026-44424
6.5 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): High (H)
-
Integrity (I): None (N)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): None (N)
updated
1 month, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
1 month, 1 week ago
-
@LeSuisse
accepted
1 month, 1 week ago
-
@LeSuisse
published on GitHub
1 month, 1 week ago
ShellHub: Cross-tenant IDOR in `GET /api/devices/:uid` discloses device data of any namespace
Permalink
CVE-2026-45033
8.5 HIGH
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): High (H)
-
Vulnerable System Impact Integrity (VI): High (H)
-
Vulnerable System Impact Availability (VA): High (H)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): None (N)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): High (H)
-
Modified Vulnerable System Impact Integrity (MVI): High (H)
-
Modified Vulnerable System Impact Availability (MVA): High (H)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Negligible (N)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
1 month, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
1 month, 1 week ago
-
@LeSuisse
ignored
2 packages
- copilot-cli
- fishPlugins.github-copilot-cli-fish
1 month, 1 week ago
-
@LeSuisse
accepted
1 month, 1 week ago
-
@LeSuisse
published on GitHub
1 month, 1 week ago
GitHub Copilot CLI: Nested Bare Repository Can Execute Arbitrary Commands via core.fsmonitor
Permalink
CVE-2026-42561
7.5 HIGH
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): High (H)
updated
1 month, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
1 month, 1 week ago
-
@LeSuisse
accepted
1 month, 1 week ago
-
@LeSuisse
published on GitHub
1 month, 1 week ago
Python-Multipart: Denial of Service via unbounded multipart part headers
Permalink
CVE-2026-44348
2.5 LOW
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): Required (R)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): Low (L)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): Required (R)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): Low (L)
updated
1 month, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
1 month, 1 week ago
-
@LeSuisse
ignored
2 packages
1 month, 1 week ago
-
@LeSuisse
accepted
1 month, 1 week ago
-
@LeSuisse
published on GitHub
1 month, 1 week ago
PoDoFo: Double-free vulnerability in compute_hash_to_sign()
Permalink
CVE-2026-43908
8.8 HIGH
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): Required (R)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): High (H)
-
Integrity (I): High (H)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): Required (R)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): High (H)
updated
1 month, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
1 month, 1 week ago
-
@LeSuisse
ignored
4 packages
- colmap
- colmapWithCuda
- python313Packages.openimageio
- python314Packages.openimageio
1 month, 1 week ago
-
@LeSuisse
accepted
1 month, 1 week ago
-
@LeSuisse
published on GitHub
1 month, 1 week ago
OpenImageIO: Signed integer overflow in ConvertCbYCrYToRGB leads to heap out-of-bounds write in DPX 4:2:2 decoder
OpenImageIO
-
==< 3.0.18.0
-
==>= 3.1.4.0-beta, < 3.1.13.0
Permalink
CVE-2026-41888
6.3 MEDIUM
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): Present (P)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): None (N)
-
Vulnerable System Impact Integrity (VI): Low (L)
-
Vulnerable System Impact Availability (VA): Low (L)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): None (N)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): Present (P)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): None (N)
-
Modified Vulnerable System Impact Integrity (MVI): Low (L)
-
Modified Vulnerable System Impact Availability (MVA): Low (L)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Negligible (N)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
1 month, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
1 month, 1 week ago
-
@LeSuisse
ignored
23 packages
- protege-distribution
- perlPackages.LinuxDistribution
- perl5Packages.LinuxDistribution
- perl538Packages.LinuxDistribution
- perl540Packages.LinuxDistribution
- perlPackages.DistributionMetadata
- haskellPackages.normaldistribution
- perl5Packages.DistributionMetadata
- perlPackages.ParseLocalDistribution
- haskellPackages.distribution-nixpkgs
- perl538Packages.DistributionMetadata
- perl540Packages.DistributionMetadata
- perl5Packages.ParseLocalDistribution
- perlPackages.StatisticsDistributions
- haskellPackages.distribution-opensuse
- perl5Packages.StatisticsDistributions
- haskellPackages.splitmix-distributions
- perl538Packages.ParseLocalDistribution
- perl540Packages.ParseLocalDistribution
- haskellPackages.ngx-export-distribution
- perl538Packages.StatisticsDistributions
- perl540Packages.StatisticsDistributions
- haskellPackages.distribution-nixpkgs-unstable
1 month, 1 week ago
-
@LeSuisse
accepted
1 month, 1 week ago
-
@LeSuisse
published on GitHub
1 month, 1 week ago
Distribution: Tag deletion bypasses `storage.delete.enabled` configuration
Permalink
CVE-2026-43907
8.3 HIGH
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): Required (R)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): Low (L)
-
Integrity (I): High (H)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): Required (R)
-
Modified Confidentiality (MC): Low (L)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): High (H)
updated
1 month, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
1 month, 1 week ago
-
@LeSuisse
ignored
4 packages
- colmap
- colmapWithCuda
- python313Packages.openimageio
- python314Packages.openimageio
1 month, 1 week ago
-
@LeSuisse
accepted
1 month, 1 week ago
-
@LeSuisse
published on GitHub
1 month, 1 week ago
OpenImageIO: Integer overflow in QueryRGBBufferSizeInternal leads to heap out-of-bounds write in DPX decoder (kCbYCr and kABGR)
OpenImageIO
-
==< 3.0.18.0
-
==>= 3.1.4.0-beta, < 3.1.13.0
Permalink
CVE-2026-7481
8.7 HIGH
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): Required (R)
-
Scope (S): Changed (C)
-
Confidentiality (C): High (H)
-
Integrity (I): High (H)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): Required (R)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Changed (C)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): None (N)
updated
1 month, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
1 month, 1 week ago
-
@LeSuisse
ignored
44 packages
- gitlab-art
- gitlab-duo
- gitlab-kas
- gitlab-ci-ls
- gitlab-pages
- gitlab-shell
- danger-gitlab
- gitlab-clippy
- gitlab-runner
- gitlab-triage
- gitlab-ci-local
- gitlab-timelogs
- gitlab-ci-linter
- gitlab-workhorse
- gitlab-release-cli
- ocamlPackages.gitlab
- vimPlugins.gitlab-vim
- gitlab-container-registry
- ocamlPackages.gitlab-jsoo
- ocamlPackages.gitlab-unix
- rubyPackages.gitlab-markup
- terraform-providers.gitlab
- ocamlPackages_latest.gitlab
- gitlab-elasticsearch-indexer
- haskellPackages.gitlab-haskell
- rubyPackages_3_3.gitlab-markup
- rubyPackages_3_4.gitlab-markup
- rubyPackages_4_0.gitlab-markup
- python312Packages.mkdocs-gitlab
- python312Packages.python-gitlab
- python313Packages.mkdocs-gitlab
- python313Packages.python-gitlab
- python314Packages.mkdocs-gitlab
- python314Packages.python-gitlab
- ocamlPackages_latest.gitlab-jsoo
- ocamlPackages_latest.gitlab-unix
- terraform-providers.gitlabhq_gitlab
- gnomeExtensions.gitlab-time-tracking
- prometheus-gitlab-ci-pipelines-exporter
- vscode-extensions.gitlab.gitlab-workflow
- perlPackages.AlienBuildPluginDownloadGitLab
- perl5Packages.AlienBuildPluginDownloadGitLab
- perl538Packages.AlienBuildPluginDownloadGitLab
- perl540Packages.AlienBuildPluginDownloadGitLab
1 month, 1 week ago
-
@LeSuisse
ignored
5 maintainers
- @globin
- @krav
- @leona-ya
- @yayayayaka
- @talyz
1 month, 1 week ago
maintainer.ignore
-
@LeSuisse
accepted
1 month, 1 week ago
-
@LeSuisse
published on GitHub
1 month, 1 week ago
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
GitLab
-
<18.11.3
-
<18.10.6
-
<18.9.7
Permalink
CVE-2026-6883
2.6 LOW
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): Required (R)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): Low (L)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): Required (R)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): Low (L)
-
Modified Availability (MA): None (N)
updated
1 month, 1 week ago
by @LeSuisse
Activity log
-
Created suggestion
1 month, 1 week ago
-
@LeSuisse
ignored
44 packages
- gitlab-art
- gitlab-duo
- gitlab-kas
- gitlab-ci-ls
- gitlab-pages
- gitlab-shell
- danger-gitlab
- gitlab-clippy
- gitlab-runner
- gitlab-triage
- gitlab-ci-local
- gitlab-timelogs
- gitlab-ci-linter
- gitlab-workhorse
- gitlab-release-cli
- ocamlPackages.gitlab
- vimPlugins.gitlab-vim
- gitlab-container-registry
- ocamlPackages.gitlab-jsoo
- ocamlPackages.gitlab-unix
- rubyPackages.gitlab-markup
- terraform-providers.gitlab
- ocamlPackages_latest.gitlab
- gitlab-elasticsearch-indexer
- haskellPackages.gitlab-haskell
- rubyPackages_3_3.gitlab-markup
- rubyPackages_3_4.gitlab-markup
- rubyPackages_4_0.gitlab-markup
- python312Packages.mkdocs-gitlab
- python312Packages.python-gitlab
- python313Packages.mkdocs-gitlab
- python313Packages.python-gitlab
- python314Packages.mkdocs-gitlab
- python314Packages.python-gitlab
- ocamlPackages_latest.gitlab-jsoo
- ocamlPackages_latest.gitlab-unix
- terraform-providers.gitlabhq_gitlab
- gnomeExtensions.gitlab-time-tracking
- prometheus-gitlab-ci-pipelines-exporter
- vscode-extensions.gitlab.gitlab-workflow
- perlPackages.AlienBuildPluginDownloadGitLab
- perl5Packages.AlienBuildPluginDownloadGitLab
- perl538Packages.AlienBuildPluginDownloadGitLab
- perl540Packages.AlienBuildPluginDownloadGitLab
1 month, 1 week ago
-
@LeSuisse
ignored
5 maintainers
- @talyz
- @leona-ya
- @globin
- @krav
- @yayayayaka
1 month, 1 week ago
maintainer.ignore
-
@LeSuisse
accepted
1 month, 1 week ago
-
@LeSuisse
published on GitHub
1 month, 1 week ago
Missing Authorization in GitLab
GitLab
-
<18.11.3
-
<18.10.6
-
<18.9.7