Published issues
Ansible-core: argument injection in ansible-galaxy collection install via git clone (incomplete fix for cve-2026-11332)
Permalink
CVE-2026-16493
7.8 HIGH
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): Required (R)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): High (H)
-
Integrity (I): High (H)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): Required (R)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): High (H)
updated
5 days, 18 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 21 hours ago
-
@LeSuisse
accepted
6 days, 19 hours ago
-
@LeSuisse
published on GitHub
5 days, 18 hours ago
Ansible-core: argument injection in ansible-galaxy collection install via git clone (incomplete fix for cve-2026-11332)
Duplicati backup software v2.3.0.1 is vulnerable to an incorrect permission assignment vulnerability
updated
5 days, 18 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 10 hours ago
-
@LeSuisse
accepted
5 days, 18 hours ago
-
@LeSuisse
published on GitHub
5 days, 18 hours ago
Duplicati backup software v2.3.0.1 is vulnerable to an incorrect permission assignment vulnerability
Heap-based Buffer Overflow in GNU diffutils
Permalink
CVE-2026-53910
2.1 LOW
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): Present (P)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): None (N)
-
Vulnerable System Impact Integrity (VI): Low (L)
-
Vulnerable System Impact Availability (VA): Low (L)
-
Subsequent System Impact Confidentiality (SC): Low (L)
-
Subsequent System Impact Integrity (SI): Low (L)
-
Subsequent System Impact Availability (SA): Low (L)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): Present (P)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): None (N)
-
Modified Vulnerable System Impact Integrity (MVI): Low (L)
-
Modified Vulnerable System Impact Availability (MVA): Low (L)
-
Modified Subsequent System Impact Confidentiality (MSC): Low (L)
-
Modified Subsequent System Impact Integrity (MSI): Low (L)
-
Modified Subsequent System Impact Availability (MSA): Low (L)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
5 days, 18 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 10 hours ago
-
@LeSuisse
ignored
reference https://g…
5 days, 18 hours ago
-
@LeSuisse
ignored
2 packages
- uutils-diffutils
- minimal-bootstrap.diffutils
5 days, 18 hours ago
-
@LeSuisse
accepted
5 days, 18 hours ago
-
@LeSuisse
restored
package minimal-bootstrap.diffutils
5 days, 18 hours ago
-
@LeSuisse
published on GitHub
5 days, 18 hours ago
Heap-based Buffer Overflow in GNU diffutils
Systemd: systemd-tmpfiles symlink-redirected arbitrary file overwrite via a chase_safe root-to-unprivileged ownership transition bypass
Permalink
CVE-2026-16552
6.3 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): High (H)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): High (H)
updated
5 days, 18 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 10 hours ago
-
@symphorien
ignored
package nagiosPlugins.check_systemd
6 days, 4 hours ago
-
@LeSuisse
ignored
reference https://g…
5 days, 18 hours ago
-
@LeSuisse
ignored
39 packages
- udev
- systemd-lsp
- systemdLibs
- rofi-systemd
- systemd-wait
- systemdUkify
- systemdgenie
- systemdMinimal
- systemd-netlogd
- systemd-bootchart
- systemd-credsubst
- systemd-manager-tui
- systemd-journal2gelf
- systemd-lock-handler
- ocamlPackages.systemd
- phpExtensions.systemd
- haskellPackages.systemd
- php82Extensions.systemd
- php83Extensions.systemd
- php84Extensions.systemd
- php85Extensions.systemd
- systemd-language-server
- update-systemd-resolved
- haskellPackages.systemd-api
- prometheus-systemd-exporter
- haskellPackages.warp-systemd
- ocamlPackages_latest.systemd
- gnomeExtensions.systemd-status
- gnomeExtensions.systemd-manager
- python313Packages.systemd-python
- python314Packages.systemd-python
- haskellPackages.libsystemd-journal
- gnomeExtensions.systemd-manager-neo
- python313Packages.systemdunitparser
- python314Packages.systemdunitparser
- python313Packages.jupyterhub-systemdspawner
- python314Packages.jupyterhub-systemdspawner
- vscode-extensions.coolbear.systemd-unit-file
- gnomeExtensions.systemd-offline-update-indicator
5 days, 18 hours ago
-
@LeSuisse
accepted
5 days, 18 hours ago
-
@LeSuisse
published on GitHub
5 days, 18 hours ago
Systemd: systemd-tmpfiles symlink-redirected arbitrary file overwrite via a chase_safe root-to-unprivileged ownership transition bypass
django-tastypie throttle.py CacheDBThrottle race condition
Permalink
CVE-2026-16208
2.3 LOW
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): Low (L)
-
Vulnerable System Impact Integrity (VI): Low (L)
-
Vulnerable System Impact Availability (VA): Low (L)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): None (N)
-
Subsequent System Impact Availability (SA): None (N)
-
Exploit Maturity (E): Not Defined (X)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
-
Modified Vulnerable System Impact Integrity (MVI): Low (L)
-
Modified Vulnerable System Impact Availability (MVA): Low (L)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Negligible (N)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
updated
5 days, 18 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 10 hours ago
-
@LeSuisse
ignored
4 references
5 days, 18 hours ago
-
@LeSuisse
accepted
5 days, 18 hours ago
-
@LeSuisse
published on GitHub
5 days, 18 hours ago
django-tastypie throttle.py CacheDBThrottle race condition
n8n: security issues < 2.29.8
Permalink
CVE-2026-65592
8.4 HIGH
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): Active (A)
-
Vulnerable System Impact Confidentiality (VC): High (H)
-
Vulnerable System Impact Integrity (VI): High (H)
-
Vulnerable System Impact Availability (VA): None (N)
-
Subsequent System Impact Confidentiality (SC): Low (L)
-
Subsequent System Impact Integrity (SI): Low (L)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): Active (A)
-
Modified Vulnerable System Impact Confidentiality (MVC): High (H)
-
Modified Vulnerable System Impact Integrity (MVI): High (H)
-
Modified Vulnerable System Impact Availability (MVA): None (N)
-
Modified Subsequent System Impact Confidentiality (MSC): Low (L)
-
Modified Subsequent System Impact Integrity (MSI): Low (L)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
5 days, 18 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 10 hours ago
-
@LeSuisse
ignored
3 packages
- n8n-nodes-carbonejs
- n8n-nodes-evolution-api
- n8n-task-runner-launcher
5 days, 18 hours ago
-
@LeSuisse
accepted
5 days, 18 hours ago
-
@LeSuisse
published on GitHub
5 days, 18 hours ago
n8n before 1.123.64 Stored DOM XSS via cachedResultUrl
n8n
-
==2.30.1
-
<1.123.64
-
==2.29.8
-
<2.29.8
-
<2.30.1
-
==1.123.64
Permalink
CVE-2026-65595
8.9 HIGH
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): Present (P)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): High (H)
-
Vulnerable System Impact Integrity (VI): High (H)
-
Vulnerable System Impact Availability (VA): High (H)
-
Subsequent System Impact Confidentiality (SC): High (H)
-
Subsequent System Impact Integrity (SI): Low (L)
-
Subsequent System Impact Availability (SA): Low (L)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): Present (P)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): High (H)
-
Modified Vulnerable System Impact Integrity (MVI): High (H)
-
Modified Vulnerable System Impact Availability (MVA): High (H)
-
Modified Subsequent System Impact Confidentiality (MSC): High (H)
-
Modified Subsequent System Impact Integrity (MSI): Low (L)
-
Modified Subsequent System Impact Availability (MSA): Low (L)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
5 days, 18 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 10 hours ago
-
@LeSuisse
ignored
3 packages
- n8n-nodes-carbonejs
- n8n-nodes-evolution-api
- n8n-task-runner-launcher
5 days, 18 hours ago
-
@LeSuisse
accepted
5 days, 18 hours ago
-
@LeSuisse
published on GitHub
5 days, 18 hours ago
n8n before 2.30.1 Privilege Escalation via Token Exchange
n8n
-
==2.29.8
-
==2.30.1
-
<2.30.1
-
<2.29.8
Permalink
CVE-2026-65597
8.2 HIGH
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): Active (A)
-
Vulnerable System Impact Confidentiality (VC): High (H)
-
Vulnerable System Impact Integrity (VI): Low (L)
-
Vulnerable System Impact Availability (VA): None (N)
-
Subsequent System Impact Confidentiality (SC): High (H)
-
Subsequent System Impact Integrity (SI): Low (L)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): Active (A)
-
Modified Vulnerable System Impact Confidentiality (MVC): High (H)
-
Modified Vulnerable System Impact Integrity (MVI): Low (L)
-
Modified Vulnerable System Impact Availability (MVA): None (N)
-
Modified Subsequent System Impact Confidentiality (MSC): High (H)
-
Modified Subsequent System Impact Integrity (MSI): Low (L)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
5 days, 18 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 10 hours ago
-
@LeSuisse
ignored
3 packages
- n8n-nodes-carbonejs
- n8n-nodes-evolution-api
- n8n-task-runner-launcher
5 days, 18 hours ago
-
@LeSuisse
accepted
5 days, 18 hours ago
-
@LeSuisse
published on GitHub
5 days, 18 hours ago
n8n before 1.123.64 DOM-Based XSS via Unsandboxed iframe
n8n
-
==2.30.1
-
<1.123.64
-
==2.29.8
-
<2.29.8
-
<2.30.1
-
==1.123.64
Permalink
CVE-2026-65598
8.9 HIGH
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Attack Requirement (AT): Present (P)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): High (H)
-
Vulnerable System Impact Integrity (VI): High (H)
-
Vulnerable System Impact Availability (VA): High (H)
-
Subsequent System Impact Confidentiality (SC): High (H)
-
Subsequent System Impact Integrity (SI): Low (L)
-
Subsequent System Impact Availability (SA): Low (L)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Attack Requirement (MAT): Present (P)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): High (H)
-
Modified Vulnerable System Impact Integrity (MVI): High (H)
-
Modified Vulnerable System Impact Availability (MVA): High (H)
-
Modified Subsequent System Impact Confidentiality (MSC): High (H)
-
Modified Subsequent System Impact Integrity (MSI): Low (L)
-
Modified Subsequent System Impact Availability (MSA): Low (L)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
5 days, 18 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 10 hours ago
-
@LeSuisse
ignored
3 packages
- n8n-task-runner-launcher
- n8n-nodes-evolution-api
- n8n-nodes-carbonejs
5 days, 18 hours ago
-
@LeSuisse
accepted
5 days, 18 hours ago
-
@LeSuisse
published on GitHub
5 days, 18 hours ago
n8n before 1.123.64 Remote Code Execution via Git Clone
n8n
-
==2.30.1
-
<1.123.64
-
==2.29.8
-
<2.29.8
-
<2.30.1
-
==1.123.64
Permalink
CVE-2026-65016
7.7 HIGH
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): Present (P)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): High (H)
-
Vulnerable System Impact Integrity (VI): High (H)
-
Vulnerable System Impact Availability (VA): High (H)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): None (N)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): Present (P)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): High (H)
-
Modified Vulnerable System Impact Integrity (MVI): High (H)
-
Modified Vulnerable System Impact Availability (MVA): High (H)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Negligible (N)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
5 days, 18 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 10 hours ago
-
@LeSuisse
ignored
3 packages
- n8n-nodes-carbonejs
- n8n-nodes-evolution-api
- n8n-task-runner-launcher
5 days, 18 hours ago
-
@LeSuisse
accepted
5 days, 18 hours ago
-
@LeSuisse
published on GitHub
5 days, 18 hours ago
n8n before 1.123.64 Privilege Escalation via SSO Instance-Role
n8n
-
==2.30.1
-
<1.123.64
-
==2.29.8
-
<2.29.8
-
<2.30.1
-
==1.123.64
Permalink
CVE-2026-65596
5.1 MEDIUM
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): Present (P)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): Low (L)
-
Vulnerable System Impact Integrity (VI): None (N)
-
Vulnerable System Impact Availability (VA): None (N)
-
Subsequent System Impact Confidentiality (SC): High (H)
-
Subsequent System Impact Integrity (SI): Low (L)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): Present (P)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
-
Modified Vulnerable System Impact Integrity (MVI): None (N)
-
Modified Vulnerable System Impact Availability (MVA): None (N)
-
Modified Subsequent System Impact Confidentiality (MSC): High (H)
-
Modified Subsequent System Impact Integrity (MSI): Low (L)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
5 days, 18 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 10 hours ago
-
@LeSuisse
ignored
3 packages
- n8n-nodes-carbonejs
- n8n-nodes-evolution-api
- n8n-task-runner-launcher
5 days, 18 hours ago
-
@LeSuisse
accepted
5 days, 18 hours ago
-
@LeSuisse
published on GitHub
5 days, 18 hours ago
n8n before 1.123.64 Credential Exfiltration via GraphQL Node
n8n
-
==2.30.1
-
<1.123.64
-
==2.29.8
-
<2.29.8
-
<2.30.1
-
==1.123.64
Permalink
CVE-2026-65589
5.1 MEDIUM
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): Present (P)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): Low (L)
-
Vulnerable System Impact Integrity (VI): None (N)
-
Vulnerable System Impact Availability (VA): None (N)
-
Subsequent System Impact Confidentiality (SC): High (H)
-
Subsequent System Impact Integrity (SI): Low (L)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): Present (P)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
-
Modified Vulnerable System Impact Integrity (MVI): None (N)
-
Modified Vulnerable System Impact Availability (MVA): None (N)
-
Modified Subsequent System Impact Confidentiality (MSC): High (H)
-
Modified Subsequent System Impact Integrity (MSI): Low (L)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
5 days, 18 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 10 hours ago
-
@LeSuisse
ignored
3 packages
- n8n-nodes-carbonejs
- n8n-nodes-evolution-api
- n8n-task-runner-launcher
5 days, 18 hours ago
-
@LeSuisse
accepted
5 days, 18 hours ago
-
@LeSuisse
published on GitHub
5 days, 18 hours ago
n8n before 1.123.64 Credential Exposure via LLM Node Execution Data
n8n
-
==2.30.1
-
<1.123.64
-
==2.29.8
-
<2.29.8
-
<2.30.1
-
==1.123.64
Permalink
CVE-2026-65015
7.2 HIGH
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): Present (P)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): High (H)
-
Vulnerable System Impact Integrity (VI): Low (L)
-
Vulnerable System Impact Availability (VA): None (N)
-
Subsequent System Impact Confidentiality (SC): High (H)
-
Subsequent System Impact Integrity (SI): Low (L)
-
Subsequent System Impact Availability (SA): Low (L)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): Present (P)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): High (H)
-
Modified Vulnerable System Impact Integrity (MVI): Low (L)
-
Modified Vulnerable System Impact Availability (MVA): None (N)
-
Modified Subsequent System Impact Confidentiality (MSC): High (H)
-
Modified Subsequent System Impact Integrity (MSI): Low (L)
-
Modified Subsequent System Impact Availability (MSA): Low (L)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
5 days, 18 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 10 hours ago
-
@LeSuisse
ignored
3 packages
- n8n-nodes-carbonejs
- n8n-nodes-evolution-api
- n8n-task-runner-launcher
5 days, 18 hours ago
-
@LeSuisse
accepted
5 days, 18 hours ago
-
@LeSuisse
published on GitHub
5 days, 18 hours ago
n8n before 2.30.1 Privilege Escalation via run_node_tool
n8n
-
==2.29.8
-
==2.30.1
-
<2.30.1
-
<2.29.8
Permalink
CVE-2026-65593
6.3 MEDIUM
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): Low (L)
-
Vulnerable System Impact Integrity (VI): Low (L)
-
Vulnerable System Impact Availability (VA): None (N)
-
Subsequent System Impact Confidentiality (SC): High (H)
-
Subsequent System Impact Integrity (SI): Low (L)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
-
Modified Vulnerable System Impact Integrity (MVI): Low (L)
-
Modified Vulnerable System Impact Availability (MVA): None (N)
-
Modified Subsequent System Impact Confidentiality (MSC): High (H)
-
Modified Subsequent System Impact Integrity (MSI): Low (L)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
5 days, 18 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 10 hours ago
-
@LeSuisse
ignored
3 packages
- n8n-nodes-carbonejs
- n8n-nodes-evolution-api
- n8n-task-runner-launcher
5 days, 18 hours ago
-
@LeSuisse
accepted
5 days, 18 hours ago
-
@LeSuisse
published on GitHub
5 days, 18 hours ago
n8n before 1.123.64 SSRF via Dynamic Node Parameters
n8n
-
==2.30.1
-
<1.123.64
-
==2.29.8
-
<2.29.8
-
<2.30.1
-
==1.123.64
Permalink
CVE-2026-65594
5.1 MEDIUM
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): Present (P)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): Low (L)
-
Vulnerable System Impact Integrity (VI): Low (L)
-
Vulnerable System Impact Availability (VA): None (N)
-
Subsequent System Impact Confidentiality (SC): High (H)
-
Subsequent System Impact Integrity (SI): Low (L)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): Present (P)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
-
Modified Vulnerable System Impact Integrity (MVI): Low (L)
-
Modified Vulnerable System Impact Availability (MVA): None (N)
-
Modified Subsequent System Impact Confidentiality (MSC): High (H)
-
Modified Subsequent System Impact Integrity (MSI): Low (L)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
5 days, 18 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 10 hours ago
-
@LeSuisse
ignored
3 packages
- n8n-task-runner-launcher
- n8n-nodes-evolution-api
- n8n-nodes-carbonejs
5 days, 18 hours ago
-
@LeSuisse
accepted
5 days, 18 hours ago
-
@LeSuisse
published on GitHub
5 days, 18 hours ago
n8n before 2.30.1 Missing OAuth Authorization Check
n8n
-
==2.29.8
-
==2.30.1
-
<2.30.1
-
<2.29.8
Permalink
CVE-2026-65591
8.9 HIGH
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): Present (P)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): High (H)
-
Vulnerable System Impact Integrity (VI): High (H)
-
Vulnerable System Impact Availability (VA): High (H)
-
Subsequent System Impact Confidentiality (SC): High (H)
-
Subsequent System Impact Integrity (SI): High (H)
-
Subsequent System Impact Availability (SA): Low (L)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): Present (P)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): High (H)
-
Modified Vulnerable System Impact Integrity (MVI): High (H)
-
Modified Vulnerable System Impact Availability (MVA): High (H)
-
Modified Subsequent System Impact Confidentiality (MSC): High (H)
-
Modified Subsequent System Impact Integrity (MSI): High (H)
-
Modified Subsequent System Impact Availability (MSA): Low (L)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
5 days, 18 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 10 hours ago
-
@LeSuisse
ignored
3 packages
- n8n-task-runner-launcher
- n8n-nodes-evolution-api
- n8n-nodes-carbonejs
5 days, 18 hours ago
-
@LeSuisse
accepted
5 days, 18 hours ago
-
@LeSuisse
published on GitHub
5 days, 18 hours ago
n8n before 1.123.64 Sanitizer Bypass Remote Code Execution
n8n
-
==2.30.1
-
<1.123.64
-
==2.29.8
-
<2.29.8
-
<2.30.1
-
==1.123.64
Permalink
CVE-2026-65590
5.5 MEDIUM
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): Present (P)
-
Privileges Required (PR): High (H)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): None (N)
-
Vulnerable System Impact Integrity (VI): None (N)
-
Vulnerable System Impact Availability (VA): None (N)
-
Subsequent System Impact Confidentiality (SC): High (H)
-
Subsequent System Impact Integrity (SI): High (H)
-
Subsequent System Impact Availability (SA): High (H)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): Present (P)
-
Modified Privileges Required (MPR): High (H)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): None (N)
-
Modified Vulnerable System Impact Integrity (MVI): None (N)
-
Modified Vulnerable System Impact Availability (MVA): None (N)
-
Modified Subsequent System Impact Confidentiality (MSC): High (H)
-
Modified Subsequent System Impact Integrity (MSI): High (H)
-
Modified Subsequent System Impact Availability (MSA): High (H)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
5 days, 18 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 10 hours ago
-
@LeSuisse
ignored
3 packages
- n8n-nodes-carbonejs
- n8n-nodes-evolution-api
- n8n-task-runner-launcher
5 days, 18 hours ago
-
@LeSuisse
accepted
5 days, 18 hours ago
-
@LeSuisse
published on GitHub
5 days, 18 hours ago
n8n before 2.30.1 Shell Sandbox Bypass on Linux Windows
n8n
-
==2.29.8
-
==2.30.1
-
<2.30.1
-
<2.29.8
Permalink
CVE-2026-65599
5.1 MEDIUM
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): Present (P)
-
Privileges Required (PR): High (H)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): Low (L)
-
Vulnerable System Impact Integrity (VI): None (N)
-
Vulnerable System Impact Availability (VA): None (N)
-
Subsequent System Impact Confidentiality (SC): High (H)
-
Subsequent System Impact Integrity (SI): Low (L)
-
Subsequent System Impact Availability (SA): Low (L)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): Present (P)
-
Modified Privileges Required (MPR): High (H)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
-
Modified Vulnerable System Impact Integrity (MVI): None (N)
-
Modified Vulnerable System Impact Availability (MVA): None (N)
-
Modified Subsequent System Impact Confidentiality (MSC): High (H)
-
Modified Subsequent System Impact Integrity (MSI): Low (L)
-
Modified Subsequent System Impact Availability (MSA): Low (L)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
5 days, 18 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 10 hours ago
-
@LeSuisse
ignored
3 packages
- n8n-nodes-carbonejs
- n8n-nodes-evolution-api
- n8n-task-runner-launcher
5 days, 18 hours ago
-
@LeSuisse
accepted
5 days, 18 hours ago
-
@LeSuisse
published on GitHub
5 days, 18 hours ago
n8n before 1.123.64 Credential Exposure via JWT Header
n8n
-
==2.30.1
-
<1.123.64
-
==2.29.8
-
<2.29.8
-
<2.30.1
-
==1.123.64
traefik: security issues < 3.7.7
Permalink
CVE-2026-65602
5.3 MEDIUM
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): Present (P)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): None (N)
-
Vulnerable System Impact Integrity (VI): None (N)
-
Vulnerable System Impact Availability (VA): None (N)
-
Subsequent System Impact Confidentiality (SC): High (H)
-
Subsequent System Impact Integrity (SI): High (H)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): Present (P)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): None (N)
-
Modified Vulnerable System Impact Integrity (MVI): None (N)
-
Modified Vulnerable System Impact Availability (MVA): None (N)
-
Modified Subsequent System Impact Confidentiality (MSC): High (H)
-
Modified Subsequent System Impact Integrity (MSI): High (H)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
5 days, 18 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 10 hours ago
-
@LeSuisse
ignored
package traefik-certs-dumper
5 days, 18 hours ago
-
@LeSuisse
accepted
5 days, 18 hours ago
-
@LeSuisse
published on GitHub
5 days, 18 hours ago
Traefik before 3.6.23 IngressRouteTCP ServersTransport Namespace Bypass
traefik
-
<3.6.23
-
<3.7.7
-
==3.6.23
-
==3.7.7
Permalink
CVE-2026-65601
5.3 MEDIUM
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): Present (P)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): None (N)
-
Vulnerable System Impact Integrity (VI): None (N)
-
Vulnerable System Impact Availability (VA): None (N)
-
Subsequent System Impact Confidentiality (SC): High (H)
-
Subsequent System Impact Integrity (SI): High (H)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): Present (P)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): None (N)
-
Modified Vulnerable System Impact Integrity (MVI): None (N)
-
Modified Vulnerable System Impact Availability (MVA): None (N)
-
Modified Subsequent System Impact Confidentiality (MSC): High (H)
-
Modified Subsequent System Impact Integrity (MSI): High (H)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
5 days, 18 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 10 hours ago
-
@LeSuisse
ignored
package traefik-certs-dumper
5 days, 18 hours ago
-
@LeSuisse
accepted
5 days, 18 hours ago
-
@LeSuisse
published on GitHub
5 days, 18 hours ago
Traefik before 3.7.7 Namespace Confusion via HTTPRoute ExtensionRef
Permalink
CVE-2026-65600
7.8 HIGH
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): None (N)
-
Vulnerable System Impact Integrity (VI): None (N)
-
Vulnerable System Impact Availability (VA): None (N)
-
Subsequent System Impact Confidentiality (SC): High (H)
-
Subsequent System Impact Integrity (SI): High (H)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): None (N)
-
Modified Vulnerable System Impact Integrity (MVI): None (N)
-
Modified Vulnerable System Impact Availability (MVA): None (N)
-
Modified Subsequent System Impact Confidentiality (MSC): High (H)
-
Modified Subsequent System Impact Integrity (MSI): High (H)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
5 days, 18 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 10 hours ago
-
@LeSuisse
ignored
package traefik-certs-dumper
5 days, 18 hours ago
-
@LeSuisse
accepted
5 days, 18 hours ago
-
@LeSuisse
published on GitHub
5 days, 18 hours ago
Traefik before v2.11.52 Authentication Bypass via ReplacePathRegex
traefik
-
==2.11.52
-
<2.11.52
-
<3.6.23
-
<3.7.7
-
==3.6.23
-
==3.7.7
unbound: security issues < 1.25.2
Permalink
CVE-2026-54478
3.7 LOW
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): Low (L)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): Low (L)
-
Modified Availability (MA): None (N)
updated
5 days, 18 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 10 hours ago
-
@LeSuisse
ignored
14 packages
- haskellPackages.unbound-generics-unify
- haskellPackages.unbound-kind-generics
- haskellPackages.unbounded-delays
- haskellPackages.unbound-generics
- python314Packages.pyunbound
- python313Packages.pyunbound
- prometheus-unbound-exporter
- lua55Packages.luaunbound
- lua53Packages.luaunbound
- lua52Packages.luaunbound
- lua54Packages.luaunbound
- luajitPackages.luaunbound
- lua51Packages.luaunbound
- luaPackages.luaunbound
5 days, 18 hours ago
-
@LeSuisse
ignored
maintainer @Scrumplex
5 days, 18 hours ago
maintainer.ignore
-
@LeSuisse
accepted
5 days, 18 hours ago
-
@LeSuisse
published on GitHub
5 days, 18 hours ago
DNS Cookie bypass when combined with proxy-protocol use
Permalink
CVE-2026-50251
5.3 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): Low (L)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): Low (L)
updated
5 days, 18 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 10 hours ago
-
@LeSuisse
ignored
14 packages
- haskellPackages.unbound-generics-unify
- haskellPackages.unbound-kind-generics
- haskellPackages.unbound-generics
- python314Packages.pyunbound
- python313Packages.pyunbound
- prometheus-unbound-exporter
- lua55Packages.luaunbound
- lua54Packages.luaunbound
- lua53Packages.luaunbound
- lua52Packages.luaunbound
- lua51Packages.luaunbound
- luaPackages.luaunbound
- haskellPackages.unbounded-delays
- luajitPackages.luaunbound
5 days, 18 hours ago
-
@LeSuisse
accepted
5 days, 18 hours ago
-
@LeSuisse
published on GitHub
5 days, 18 hours ago
Attacker supplied '0.0.0.0'/'::' glue triggers defensive full-cache flush
Permalink
CVE-2026-50045
5.3 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): Low (L)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): Low (L)
updated
5 days, 18 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 10 hours ago
-
@LeSuisse
ignored
14 packages
- haskellPackages.unbound-generics-unify
- haskellPackages.unbound-kind-generics
- haskellPackages.unbounded-delays
- haskellPackages.unbound-generics
- python314Packages.pyunbound
- python313Packages.pyunbound
- prometheus-unbound-exporter
- lua55Packages.luaunbound
- lua54Packages.luaunbound
- lua53Packages.luaunbound
- luaPackages.luaunbound
- luajitPackages.luaunbound
- lua52Packages.luaunbound
- lua51Packages.luaunbound
5 days, 18 hours ago
-
@LeSuisse
ignored
maintainer @Scrumplex
5 days, 18 hours ago
maintainer.ignore
-
@LeSuisse
accepted
5 days, 18 hours ago
-
@LeSuisse
published on GitHub
5 days, 18 hours ago
'max-global-quota' reset by DNSSEC validation restarts
Permalink
CVE-2026-44690
7.5 HIGH
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): High (H)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): None (N)
updated
5 days, 18 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 10 hours ago
-
@LeSuisse
ignored
14 packages
- luaPackages.luaunbound
- lua51Packages.luaunbound
- lua52Packages.luaunbound
- lua53Packages.luaunbound
- lua54Packages.luaunbound
- lua55Packages.luaunbound
- luajitPackages.luaunbound
- prometheus-unbound-exporter
- haskellPackages.unbound-generics-unify
- haskellPackages.unbound-kind-generics
- haskellPackages.unbounded-delays
- haskellPackages.unbound-generics
- python314Packages.pyunbound
- python313Packages.pyunbound
5 days, 18 hours ago
-
@LeSuisse
ignored
maintainer @Scrumplex
5 days, 18 hours ago
maintainer.ignore
-
@LeSuisse
accepted
5 days, 18 hours ago
-
@LeSuisse
published on GitHub
5 days, 18 hours ago
Cross-zone wildcard cache poisoning via RRSIG.labels manipulation
Permalink
CVE-2026-44621
5.9 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): High (H)
updated
5 days, 18 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 10 hours ago
-
@LeSuisse
ignored
14 packages
- lua52Packages.luaunbound
- lua53Packages.luaunbound
- lua54Packages.luaunbound
- lua55Packages.luaunbound
- luajitPackages.luaunbound
- prometheus-unbound-exporter
- python313Packages.pyunbound
- python314Packages.pyunbound
- lua51Packages.luaunbound
- haskellPackages.unbound-generics-unify
- haskellPackages.unbound-kind-generics
- haskellPackages.unbounded-delays
- haskellPackages.unbound-generics
- luaPackages.luaunbound
5 days, 18 hours ago
-
@LeSuisse
accepted
5 days, 18 hours ago
-
@LeSuisse
ignored
maintainer @Scrumplex
5 days, 18 hours ago
maintainer.ignore
-
@LeSuisse
published on GitHub
5 days, 18 hours ago
Libunbound applications configured with 'unwanted-reply-threshold' could eventually be abruptly terminated
Permalink
CVE-2026-56416
4.8 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): Low (L)
-
Availability (A): Low (L)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): Low (L)
-
Modified Availability (MA): Low (L)
updated
5 days, 18 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 10 hours ago
-
@LeSuisse
ignored
15 packages
- luaPackages.luaunbound
- lua51Packages.luaunbound
- lua52Packages.luaunbound
- lua53Packages.luaunbound
- lua54Packages.luaunbound
- lua55Packages.luaunbound
- luajitPackages.luaunbound
- prometheus-unbound-exporter
- python313Packages.pyunbound
- python314Packages.pyunbound
- unbound-with-systemd
- haskellPackages.unbound-generics-unify
- haskellPackages.unbound-kind-generics
- haskellPackages.unbounded-delays
- haskellPackages.unbound-generics
5 days, 18 hours ago
-
@LeSuisse
restored
package unbound-with-systemd
5 days, 18 hours ago
-
@LeSuisse
ignored
maintainer @Scrumplex
5 days, 18 hours ago
maintainer.ignore
-
@LeSuisse
accepted
5 days, 18 hours ago
-
@LeSuisse
published on GitHub
5 days, 18 hours ago
Possible heap buffer overflow when validator canonicalizes RDATA that contains domain name
Permalink
CVE-2026-55991
5.9 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): High (H)
updated
5 days, 18 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 10 hours ago
-
@LeSuisse
ignored
14 packages
- luaPackages.luaunbound
- lua51Packages.luaunbound
- lua52Packages.luaunbound
- lua53Packages.luaunbound
- lua54Packages.luaunbound
- lua55Packages.luaunbound
- luajitPackages.luaunbound
- prometheus-unbound-exporter
- python313Packages.pyunbound
- python314Packages.pyunbound
- haskellPackages.unbound-generics
- haskellPackages.unbounded-delays
- haskellPackages.unbound-kind-generics
- haskellPackages.unbound-generics-unify
5 days, 18 hours ago
-
@LeSuisse
ignored
maintainer @Scrumplex
5 days, 18 hours ago
maintainer.ignore
-
@LeSuisse
accepted
5 days, 18 hours ago
-
@LeSuisse
published on GitHub
5 days, 18 hours ago
Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2
Permalink
CVE-2026-40691
7.5 HIGH
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): High (H)
updated
5 days, 18 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 10 hours ago
-
@LeSuisse
ignored
14 packages
- luaPackages.luaunbound
- lua51Packages.luaunbound
- lua52Packages.luaunbound
- lua53Packages.luaunbound
- lua54Packages.luaunbound
- lua55Packages.luaunbound
- luajitPackages.luaunbound
- prometheus-unbound-exporter
- python313Packages.pyunbound
- python314Packages.pyunbound
- haskellPackages.unbound-generics
- haskellPackages.unbounded-delays
- haskellPackages.unbound-kind-generics
- haskellPackages.unbound-generics-unify
5 days, 18 hours ago
-
@LeSuisse
accepted
5 days, 18 hours ago
-
@LeSuisse
ignored
maintainer @Scrumplex
5 days, 18 hours ago
maintainer.ignore
-
@LeSuisse
published on GitHub
5 days, 18 hours ago
Packet of death for DNSCrypt over TCP
Permalink
CVE-2026-46582
3.7 LOW
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): Low (L)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): Low (L)
-
Modified Availability (MA): None (N)
updated
5 days, 18 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 10 hours ago
-
@LeSuisse
ignored
14 packages
- luaPackages.luaunbound
- lua51Packages.luaunbound
- lua52Packages.luaunbound
- lua53Packages.luaunbound
- lua54Packages.luaunbound
- lua55Packages.luaunbound
- luajitPackages.luaunbound
- prometheus-unbound-exporter
- python313Packages.pyunbound
- python314Packages.pyunbound
- haskellPackages.unbound-generics
- haskellPackages.unbound-generics-unify
- haskellPackages.unbound-kind-generics
- haskellPackages.unbounded-delays
5 days, 18 hours ago
-
@LeSuisse
ignored
maintainer @Scrumplex
5 days, 18 hours ago
maintainer.ignore
-
@LeSuisse
accepted
5 days, 18 hours ago
-
@LeSuisse
published on GitHub
5 days, 18 hours ago
A wildcard replay, as another piece of data, triggers poisoning in the serve expired reply path
Permalink
CVE-2026-56444
5.9 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): High (H)
updated
5 days, 18 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 10 hours ago
-
@LeSuisse
ignored
14 packages
- haskellPackages.unbound-generics-unify
- haskellPackages.unbound-kind-generics
- haskellPackages.unbounded-delays
- haskellPackages.unbound-generics
- python314Packages.pyunbound
- python313Packages.pyunbound
- prometheus-unbound-exporter
- luajitPackages.luaunbound
- lua55Packages.luaunbound
- lua54Packages.luaunbound
- lua53Packages.luaunbound
- lua52Packages.luaunbound
- lua51Packages.luaunbound
- luaPackages.luaunbound
5 days, 18 hours ago
-
@LeSuisse
ignored
maintainer @Scrumplex
5 days, 18 hours ago
maintainer.ignore
-
@LeSuisse
accepted
5 days, 18 hours ago
-
@LeSuisse
published on GitHub
5 days, 18 hours ago
Degradation of resolution service when 'discard-timeout' and 'serve-expired-client-timeout' are combined in unusual configuration
Permalink
CVE-2026-55717
5.9 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): High (H)
updated
5 days, 18 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 10 hours ago
-
@LeSuisse
ignored
14 packages
- haskellPackages.unbound-generics-unify
- haskellPackages.unbound-kind-generics
- haskellPackages.unbounded-delays
- haskellPackages.unbound-generics
- python314Packages.pyunbound
- python313Packages.pyunbound
- prometheus-unbound-exporter
- luajitPackages.luaunbound
- lua55Packages.luaunbound
- lua54Packages.luaunbound
- lua53Packages.luaunbound
- lua52Packages.luaunbound
- lua51Packages.luaunbound
- luaPackages.luaunbound
5 days, 18 hours ago
-
@LeSuisse
ignored
maintainer @Scrumplex
5 days, 18 hours ago
maintainer.ignore
-
@LeSuisse
accepted
5 days, 18 hours ago
-
@LeSuisse
published on GitHub
5 days, 18 hours ago
'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to a crash
Permalink
CVE-2026-55708
3.1 LOW
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): High (H)
-
User Interaction (UI): Required (R)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): Low (L)
-
Integrity (I): Low (L)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): High (H)
-
Modified User Interaction (MUI): Required (R)
-
Modified Confidentiality (MC): Low (L)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): Low (L)
-
Modified Availability (MA): None (N)
updated
5 days, 18 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 10 hours ago
-
@LeSuisse
ignored
14 packages
- lua51Packages.luaunbound
- lua52Packages.luaunbound
- lua53Packages.luaunbound
- lua54Packages.luaunbound
- lua55Packages.luaunbound
- luajitPackages.luaunbound
- prometheus-unbound-exporter
- python313Packages.pyunbound
- python314Packages.pyunbound
- haskellPackages.unbound-generics
- haskellPackages.unbounded-delays
- haskellPackages.unbound-kind-generics
- haskellPackages.unbound-generics-unify
- luaPackages.luaunbound
5 days, 18 hours ago
-
@LeSuisse
ignored
maintainer @Scrumplex
5 days, 18 hours ago
maintainer.ignore
-
@LeSuisse
accepted
5 days, 18 hours ago
-
@LeSuisse
published on GitHub
5 days, 18 hours ago
Privacy/configuration issue when adding local data in views through 'unbound-control'
Permalink
CVE-2026-50248
6.5 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): High (H)
-
Availability (A): Low (L)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): Low (L)
updated
5 days, 18 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 10 hours ago
-
@LeSuisse
ignored
14 packages
- haskellPackages.unbound-generics-unify
- haskellPackages.unbound-kind-generics
- haskellPackages.unbounded-delays
- haskellPackages.unbound-generics
- python314Packages.pyunbound
- python313Packages.pyunbound
- prometheus-unbound-exporter
- luajitPackages.luaunbound
- lua55Packages.luaunbound
- lua54Packages.luaunbound
- lua53Packages.luaunbound
- lua52Packages.luaunbound
- lua51Packages.luaunbound
- luaPackages.luaunbound
5 days, 18 hours ago
-
@LeSuisse
ignored
maintainer @Scrumplex
5 days, 18 hours ago
maintainer.ignore
-
@LeSuisse
accepted
5 days, 18 hours ago
-
@LeSuisse
published on GitHub
5 days, 18 hours ago
BOGUS configured primary hostname accepted for XFR in auth/rpz zones
Permalink
CVE-2026-50252
5.7 MEDIUM
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Adjacent (A)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): Present (P)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): None (N)
-
Vulnerable System Impact Integrity (VI): High (H)
-
Vulnerable System Impact Availability (VA): None (N)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): High (H)
-
Subsequent System Impact Availability (SA): High (H)
-
Exploit Maturity (E): POC (P)
-
Provider Urgency (U): Amber (Amber)
-
Modified Attack Vector (MAV): Adjacent (A)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): Present (P)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): None (N)
-
Modified Vulnerable System Impact Integrity (MVI): High (H)
-
Modified Vulnerable System Impact Availability (MVA): None (N)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): High (H)
-
Modified Subsequent System Impact Availability (MSA): High (H)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
updated
5 days, 18 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 10 hours ago
-
@LeSuisse
ignored
14 packages
- luaPackages.luaunbound
- lua51Packages.luaunbound
- lua52Packages.luaunbound
- lua53Packages.luaunbound
- lua54Packages.luaunbound
- lua55Packages.luaunbound
- luajitPackages.luaunbound
- prometheus-unbound-exporter
- python313Packages.pyunbound
- python314Packages.pyunbound
- haskellPackages.unbound-generics
- haskellPackages.unbounded-delays
- haskellPackages.unbound-kind-generics
- haskellPackages.unbound-generics-unify
5 days, 18 hours ago
-
@LeSuisse
accepted
5 days, 18 hours ago
-
@LeSuisse
ignored
maintainer @Scrumplex
5 days, 18 hours ago
maintainer.ignore
-
@LeSuisse
published on GitHub
5 days, 18 hours ago
Possible cache poisoning attack by mapping source port population per thread
Permalink
CVE-2026-14586
5.9 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): High (H)
updated
5 days, 18 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 10 hours ago
-
@LeSuisse
ignored
14 packages
- luaPackages.luaunbound
- lua51Packages.luaunbound
- lua52Packages.luaunbound
- lua53Packages.luaunbound
- lua54Packages.luaunbound
- lua55Packages.luaunbound
- luajitPackages.luaunbound
- prometheus-unbound-exporter
- python313Packages.pyunbound
- python314Packages.pyunbound
- haskellPackages.unbound-generics
- haskellPackages.unbounded-delays
- haskellPackages.unbound-kind-generics
- haskellPackages.unbound-generics-unify
5 days, 18 hours ago
-
@LeSuisse
accepted
5 days, 18 hours ago
-
@LeSuisse
published on GitHub
5 days, 18 hours ago
Assertion in libngtcp2 when under pressure in high concurrency DNS-over-QUIC environments
Permalink
CVE-2026-50243
6.3 MEDIUM
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): None (N)
-
Vulnerable System Impact Integrity (VI): Low (L)
-
Vulnerable System Impact Availability (VA): None (N)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): Low (L)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): None (N)
-
Modified Vulnerable System Impact Integrity (MVI): Low (L)
-
Modified Vulnerable System Impact Availability (MVA): None (N)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Low (L)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
5 days, 18 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 10 hours ago
-
@LeSuisse
ignored
14 packages
- haskellPackages.unbound-generics-unify
- haskellPackages.unbound-kind-generics
- haskellPackages.unbounded-delays
- haskellPackages.unbound-generics
- python313Packages.pyunbound
- luajitPackages.luaunbound
- lua55Packages.luaunbound
- lua54Packages.luaunbound
- lua53Packages.luaunbound
- lua52Packages.luaunbound
- lua51Packages.luaunbound
- luaPackages.luaunbound
- python314Packages.pyunbound
- prometheus-unbound-exporter
5 days, 18 hours ago
-
@LeSuisse
ignored
maintainer @Scrumplex
5 days, 18 hours ago
maintainer.ignore
-
@LeSuisse
accepted
5 days, 18 hours ago
-
@LeSuisse
published on GitHub
5 days, 18 hours ago
'response-ip'/'rpz' can rewrite BOGUS answers instead of returning SERVFAIL
Permalink
CVE-2026-55973
7.5 HIGH
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): High (H)
updated
5 days, 18 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 10 hours ago
-
@LeSuisse
ignored
14 packages
- haskellPackages.unbound-generics-unify
- haskellPackages.unbound-kind-generics
- haskellPackages.unbounded-delays
- haskellPackages.unbound-generics
- python314Packages.pyunbound
- python313Packages.pyunbound
- prometheus-unbound-exporter
- lua55Packages.luaunbound
- luajitPackages.luaunbound
- lua54Packages.luaunbound
- lua53Packages.luaunbound
- lua52Packages.luaunbound
- lua51Packages.luaunbound
- luaPackages.luaunbound
5 days, 18 hours ago
-
@LeSuisse
ignored
maintainer @Scrumplex
5 days, 18 hours ago
maintainer.ignore
-
@LeSuisse
accepted
5 days, 18 hours ago
-
@LeSuisse
published on GitHub
5 days, 18 hours ago
'dns-error-reporting: yes' leads to stack buffer overflow
Permalink
CVE-2026-44687
3.7 LOW
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): Low (L)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): Low (L)
updated
5 days, 18 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 10 hours ago
-
@LeSuisse
ignored
14 packages
- haskellPackages.unbound-generics-unify
- haskellPackages.unbound-kind-generics
- haskellPackages.unbound-generics
- python313Packages.pyunbound
- prometheus-unbound-exporter
- lua54Packages.luaunbound
- lua52Packages.luaunbound
- lua51Packages.luaunbound
- haskellPackages.unbounded-delays
- python314Packages.pyunbound
- luajitPackages.luaunbound
- lua55Packages.luaunbound
- lua53Packages.luaunbound
- luaPackages.luaunbound
5 days, 18 hours ago
-
@LeSuisse
accepted
5 days, 18 hours ago
-
@LeSuisse
published on GitHub
5 days, 18 hours ago
Off-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward zone by a legitimate parent's NXDOMAIN
Permalink
CVE-2026-42955
3.7 LOW
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): Low (L)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): Low (L)
-
Modified Availability (MA): None (N)
updated
5 days, 18 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 10 hours ago
-
@LeSuisse
ignored
14 packages
- luaPackages.luaunbound
- lua51Packages.luaunbound
- lua52Packages.luaunbound
- lua53Packages.luaunbound
- lua54Packages.luaunbound
- lua55Packages.luaunbound
- luajitPackages.luaunbound
- prometheus-unbound-exporter
- python313Packages.pyunbound
- python314Packages.pyunbound
- haskellPackages.unbound-generics
- haskellPackages.unbound-generics-unify
- haskellPackages.unbound-kind-generics
- haskellPackages.unbounded-delays
5 days, 18 hours ago
-
@LeSuisse
ignored
maintainer @Scrumplex
5 days, 18 hours ago
maintainer.ignore
-
@LeSuisse
accepted
5 days, 18 hours ago
-
@LeSuisse
published on GitHub
5 days, 18 hours ago
Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-time 'ghost domain' delegation renewal via glue records
Permalink
CVE-2026-52863
5.9 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): High (H)
updated
5 days, 18 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 10 hours ago
-
@LeSuisse
ignored
14 packages
- haskellPackages.unbound-generics-unify
- haskellPackages.unbound-kind-generics
- haskellPackages.unbounded-delays
- haskellPackages.unbound-generics
- python314Packages.pyunbound
- python313Packages.pyunbound
- prometheus-unbound-exporter
- lua55Packages.luaunbound
- lua54Packages.luaunbound
- lua53Packages.luaunbound
- lua52Packages.luaunbound
- lua51Packages.luaunbound
- luaPackages.luaunbound
- luajitPackages.luaunbound
5 days, 18 hours ago
-
@LeSuisse
ignored
maintainer @Scrumplex
5 days, 18 hours ago
maintainer.ignore
-
@LeSuisse
accepted
5 days, 18 hours ago
-
@LeSuisse
published on GitHub
5 days, 18 hours ago
Memory corruption could lead to crash and denial of service
Permalink
CVE-2026-50046
5.9 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): High (H)
updated
5 days, 18 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 10 hours ago
-
@LeSuisse
ignored
14 packages
- haskellPackages.unbound-generics-unify
- haskellPackages.unbound-kind-generics
- haskellPackages.unbounded-delays
- haskellPackages.unbound-generics
- python313Packages.pyunbound
- luajitPackages.luaunbound
- lua55Packages.luaunbound
- lua54Packages.luaunbound
- lua53Packages.luaunbound
- lua52Packages.luaunbound
- lua51Packages.luaunbound
- luaPackages.luaunbound
- python314Packages.pyunbound
- prometheus-unbound-exporter
5 days, 18 hours ago
-
@LeSuisse
ignored
maintainer @Scrumplex
5 days, 18 hours ago
maintainer.ignore
-
@LeSuisse
accepted
5 days, 18 hours ago
-
@LeSuisse
published on GitHub
5 days, 18 hours ago
Possible heap use-after-free in an error path when a DoT forwarded query is jostled out
Permalink
CVE-2026-41637
3.7 LOW
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): Low (L)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): Low (L)
updated
5 days, 18 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 10 hours ago
-
@LeSuisse
ignored
14 packages
- haskellPackages.unbound-generics-unify
- haskellPackages.unbound-kind-generics
- haskellPackages.unbounded-delays
- haskellPackages.unbound-generics
- python314Packages.pyunbound
- python313Packages.pyunbound
- prometheus-unbound-exporter
- luajitPackages.luaunbound
- lua55Packages.luaunbound
- lua54Packages.luaunbound
- lua53Packages.luaunbound
- lua52Packages.luaunbound
- lua51Packages.luaunbound
- luaPackages.luaunbound
5 days, 18 hours ago
-
@LeSuisse
ignored
maintainer @Scrumplex
5 days, 18 hours ago
maintainer.ignore
-
@LeSuisse
accepted
5 days, 18 hours ago
-
@LeSuisse
published on GitHub
5 days, 18 hours ago
Degradation of resolution service from improperly accounted client-terminated DNS-over-QUIC queries
Permalink
CVE-2026-55990
5.9 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): High (H)
updated
5 days, 18 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 10 hours ago
-
@LeSuisse
ignored
14 packages
- haskellPackages.unbound-generics-unify
- haskellPackages.unbound-kind-generics
- haskellPackages.unbounded-delays
- haskellPackages.unbound-generics
- python314Packages.pyunbound
- python313Packages.pyunbound
- prometheus-unbound-exporter
- lua55Packages.luaunbound
- lua53Packages.luaunbound
- lua52Packages.luaunbound
- lua51Packages.luaunbound
- luaPackages.luaunbound
- luajitPackages.luaunbound
- lua54Packages.luaunbound
5 days, 18 hours ago
-
@LeSuisse
ignored
maintainer @Scrumplex
5 days, 18 hours ago
maintainer.ignore
-
@LeSuisse
accepted
5 days, 18 hours ago
-
@LeSuisse
published on GitHub
5 days, 18 hours ago
Packet of death for a DNSCrypt misconfigured Unbound
Permalink
CVE-2026-32665
7.5 HIGH
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): High (H)
updated
5 days, 18 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 10 hours ago
-
@LeSuisse
ignored
15 packages
- luaPackages.luaunbound
- lua51Packages.luaunbound
- lua52Packages.luaunbound
- lua53Packages.luaunbound
- lua54Packages.luaunbound
- lua55Packages.luaunbound
- luajitPackages.luaunbound
- prometheus-unbound-exporter
- python313Packages.pyunbound
- unbound-with-systemd
- haskellPackages.unbound-generics-unify
- haskellPackages.unbound-kind-generics
- haskellPackages.unbounded-delays
- haskellPackages.unbound-generics
- python314Packages.pyunbound
5 days, 18 hours ago
-
@LeSuisse
restored
package unbound-with-systemd
5 days, 18 hours ago
-
@LeSuisse
accepted
5 days, 18 hours ago
-
@LeSuisse
ignored
maintainer @Scrumplex
5 days, 18 hours ago
maintainer.ignore
-
@LeSuisse
published on GitHub
5 days, 18 hours ago
Remote DNS-over-QUIC denial of service due to `quic-size` budget bypass
elasticsearch: security issues < 9.3.4
Permalink
CVE-2026-63144
6.5 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): High (H)
updated
6 days, 16 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 21 hours ago
-
@LeSuisse
ignored
31 packages
- elasticsearch-curator
- gitlab-elasticsearch-indexer
- python313Packages.elasticsearch
- python314Packages.elasticsearch
- python313Packages.elasticsearch8
- python314Packages.elasticsearch8
- elasticsearchPlugins.analysis-icu
- elasticsearchPlugins.search-guard
- haskellPackages.log-elasticsearch
- prometheus-elasticsearch-exporter
- terraform-providers.elasticsearch
- elasticsearchPlugins.discovery-ec2
- elasticsearchPlugins.repository-s3
- python313Packages.elasticsearchdsl
- python314Packages.elasticsearchdsl
- elasticsearchPlugins.repository-gcs
- python313Packages.elasticsearch-dsl
- python314Packages.elasticsearch-dsl
- elasticsearchPlugins.analysis-smartcn
- elasticsearchPlugins.analysis-kuromoji
- elasticsearchPlugins.analysis-phonetic
- elasticsearchPlugins.ingest-attachment
- haskellPackages.amazonka-elasticsearch
- python313Packages.django-elasticsearch-dsl
- python314Packages.django-elasticsearch-dsl
- terraform-providers.phillbaker_elasticsearch
- elasticsearch7
- python314Packages.aliyun-python-sdk-elasticsearch
- python313Packages.aliyun-python-sdk-elasticsearch
- python314Packages.pysigma-backend-elasticsearch
- python313Packages.pysigma-backend-elasticsearch
6 days, 16 hours ago
-
@LeSuisse
restored
package elasticsearch7
6 days, 16 hours ago
-
@LeSuisse
accepted
6 days, 16 hours ago
-
@LeSuisse
published on GitHub
6 days, 16 hours ago
Uncontrolled Recursion in Elasticsearch Leading to Denial of Service
Elasticsearch
-
=<9.4.3
-
=<9.3.7
-
=<8.19.18
Permalink
CVE-2026-56145
6.5 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): High (H)
updated
6 days, 16 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 21 hours ago
-
@LeSuisse
ignored
30 packages
- gitlab-elasticsearch-indexer
- python313Packages.elasticsearch
- python314Packages.elasticsearch
- python313Packages.elasticsearch8
- python314Packages.elasticsearch8
- elasticsearchPlugins.analysis-icu
- elasticsearchPlugins.search-guard
- haskellPackages.log-elasticsearch
- prometheus-elasticsearch-exporter
- terraform-providers.elasticsearch
- elasticsearchPlugins.discovery-ec2
- elasticsearchPlugins.repository-s3
- python313Packages.elasticsearchdsl
- python314Packages.elasticsearchdsl
- elasticsearchPlugins.repository-gcs
- python313Packages.elasticsearch-dsl
- python314Packages.elasticsearch-dsl
- elasticsearchPlugins.analysis-smartcn
- elasticsearchPlugins.analysis-kuromoji
- elasticsearchPlugins.analysis-phonetic
- elasticsearchPlugins.ingest-attachment
- haskellPackages.amazonka-elasticsearch
- python313Packages.django-elasticsearch-dsl
- python314Packages.django-elasticsearch-dsl
- python313Packages.aliyun-python-sdk-elasticsearch
- python313Packages.pysigma-backend-elasticsearch
- python314Packages.aliyun-python-sdk-elasticsearch
- python314Packages.pysigma-backend-elasticsearch
- terraform-providers.phillbaker_elasticsearch
- elasticsearch-curator
6 days, 16 hours ago
-
@LeSuisse
accepted
6 days, 16 hours ago
-
@LeSuisse
published on GitHub
6 days, 16 hours ago
Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
Elasticsearch
-
=<9.4.3
-
=<9.3.6
-
=<8.19.17
Permalink
CVE-2026-63263
6.5 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): High (H)
updated
6 days, 16 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 21 hours ago
-
@LeSuisse
ignored
30 packages
- prometheus-elasticsearch-exporter
- terraform-providers.elasticsearch
- elasticsearchPlugins.discovery-ec2
- haskellPackages.log-elasticsearch
- elasticsearchPlugins.repository-s3
- python313Packages.elasticsearchdsl
- python314Packages.elasticsearchdsl
- elasticsearchPlugins.repository-gcs
- python313Packages.elasticsearch-dsl
- python314Packages.elasticsearch-dsl
- elasticsearchPlugins.analysis-smartcn
- elasticsearchPlugins.analysis-kuromoji
- elasticsearchPlugins.analysis-phonetic
- elasticsearchPlugins.ingest-attachment
- haskellPackages.amazonka-elasticsearch
- python313Packages.django-elasticsearch-dsl
- python314Packages.django-elasticsearch-dsl
- terraform-providers.phillbaker_elasticsearch
- elasticsearchPlugins.search-guard
- python313Packages.pysigma-backend-elasticsearch
- elasticsearchPlugins.analysis-icu
- python314Packages.elasticsearch8
- python313Packages.elasticsearch8
- python314Packages.elasticsearch
- python314Packages.aliyun-python-sdk-elasticsearch
- python313Packages.aliyun-python-sdk-elasticsearch
- python314Packages.pysigma-backend-elasticsearch
- python313Packages.elasticsearch
- gitlab-elasticsearch-indexer
- elasticsearch-curator
6 days, 16 hours ago
-
@LeSuisse
accepted
6 days, 16 hours ago
-
@LeSuisse
published on GitHub
6 days, 16 hours ago
Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
Elasticsearch
-
=<9.3.7
-
=<9.4.3
-
=<8.19.18
Permalink
CVE-2026-56144
5.3 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): High (H)
-
Integrity (I): None (N)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): None (N)
updated
6 days, 16 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 21 hours ago
-
@LeSuisse
ignored
30 packages
- elasticsearch-curator
- gitlab-elasticsearch-indexer
- python313Packages.elasticsearch
- python314Packages.elasticsearch
- python313Packages.elasticsearch8
- python314Packages.elasticsearch8
- elasticsearchPlugins.analysis-icu
- elasticsearchPlugins.search-guard
- haskellPackages.log-elasticsearch
- prometheus-elasticsearch-exporter
- terraform-providers.elasticsearch
- elasticsearchPlugins.discovery-ec2
- elasticsearchPlugins.repository-s3
- python313Packages.elasticsearchdsl
- python314Packages.elasticsearchdsl
- elasticsearchPlugins.repository-gcs
- python313Packages.elasticsearch-dsl
- python314Packages.elasticsearch-dsl
- elasticsearchPlugins.analysis-smartcn
- elasticsearchPlugins.analysis-kuromoji
- elasticsearchPlugins.analysis-phonetic
- elasticsearchPlugins.ingest-attachment
- haskellPackages.amazonka-elasticsearch
- python313Packages.django-elasticsearch-dsl
- python314Packages.django-elasticsearch-dsl
- python314Packages.aliyun-python-sdk-elasticsearch
- python313Packages.aliyun-python-sdk-elasticsearch
- python314Packages.pysigma-backend-elasticsearch
- python313Packages.pysigma-backend-elasticsearch
- terraform-providers.phillbaker_elasticsearch
6 days, 16 hours ago
-
@LeSuisse
accepted
6 days, 16 hours ago
-
@LeSuisse
published on GitHub
6 days, 16 hours ago
Incorrect Authorization in Elasticsearch Leading to Information Disclosure
Elasticsearch
-
=<8.19.17
-
=<9.3.6
-
=<9.4.3
Permalink
CVE-2026-63140
6.5 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): High (H)
updated
6 days, 16 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 21 hours ago
-
@LeSuisse
ignored
30 packages
- python314Packages.elasticsearch
- python313Packages.elasticsearch8
- python314Packages.elasticsearch8
- elasticsearchPlugins.analysis-icu
- elasticsearchPlugins.search-guard
- haskellPackages.log-elasticsearch
- prometheus-elasticsearch-exporter
- terraform-providers.elasticsearch
- elasticsearchPlugins.discovery-ec2
- elasticsearchPlugins.repository-s3
- python313Packages.elasticsearchdsl
- python314Packages.elasticsearchdsl
- elasticsearchPlugins.repository-gcs
- python313Packages.elasticsearch-dsl
- python314Packages.elasticsearch-dsl
- elasticsearchPlugins.analysis-smartcn
- elasticsearchPlugins.analysis-kuromoji
- elasticsearchPlugins.analysis-phonetic
- elasticsearchPlugins.ingest-attachment
- haskellPackages.amazonka-elasticsearch
- python313Packages.django-elasticsearch-dsl
- elasticsearch-curator
- gitlab-elasticsearch-indexer
- python313Packages.elasticsearch
- python314Packages.django-elasticsearch-dsl
- terraform-providers.phillbaker_elasticsearch
- python313Packages.pysigma-backend-elasticsearch
- python314Packages.pysigma-backend-elasticsearch
- python313Packages.aliyun-python-sdk-elasticsearch
- python314Packages.aliyun-python-sdk-elasticsearch
6 days, 16 hours ago
-
@LeSuisse
accepted
6 days, 16 hours ago
-
@LeSuisse
published on GitHub
6 days, 16 hours ago
Reachable Assertion in Elasticsearch Leading to Denial of Service
Elasticsearch
-
=<9.3.7
-
=<9.4.3
-
=<8.19.18
Permalink
CVE-2026-63136
6.5 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): High (H)
updated
6 days, 16 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 21 hours ago
-
@LeSuisse
ignored
30 packages
- elasticsearch-curator
- gitlab-elasticsearch-indexer
- python313Packages.elasticsearch
- python314Packages.elasticsearch
- python313Packages.elasticsearch8
- python314Packages.elasticsearch8
- elasticsearchPlugins.analysis-icu
- elasticsearchPlugins.search-guard
- haskellPackages.log-elasticsearch
- prometheus-elasticsearch-exporter
- terraform-providers.elasticsearch
- elasticsearchPlugins.discovery-ec2
- elasticsearchPlugins.repository-s3
- python313Packages.elasticsearchdsl
- python314Packages.elasticsearchdsl
- elasticsearchPlugins.repository-gcs
- python313Packages.elasticsearch-dsl
- python314Packages.elasticsearch-dsl
- elasticsearchPlugins.analysis-smartcn
- elasticsearchPlugins.analysis-kuromoji
- elasticsearchPlugins.analysis-phonetic
- elasticsearchPlugins.ingest-attachment
- haskellPackages.amazonka-elasticsearch
- python313Packages.django-elasticsearch-dsl
- python314Packages.django-elasticsearch-dsl
- terraform-providers.phillbaker_elasticsearch
- python313Packages.pysigma-backend-elasticsearch
- python314Packages.pysigma-backend-elasticsearch
- python313Packages.aliyun-python-sdk-elasticsearch
- python314Packages.aliyun-python-sdk-elasticsearch
6 days, 16 hours ago
-
@LeSuisse
accepted
6 days, 16 hours ago
-
@LeSuisse
published on GitHub
6 days, 16 hours ago
Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
Elasticsearch
-
=<8.19.14
-
=<9.2.8
-
=<9.3.3
s2n-tls: security issues < 1.7.6
Permalink
CVE-2026-16317
8.3 HIGH
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): Present (P)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): None (N)
-
Vulnerable System Impact Integrity (VI): High (H)
-
Vulnerable System Impact Availability (VA): Low (L)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): Low (L)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): Present (P)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): None (N)
-
Modified Vulnerable System Impact Integrity (MVI): High (H)
-
Modified Vulnerable System Impact Availability (MVA): Low (L)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Low (L)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
6 days, 19 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 21 hours ago
-
@LeSuisse
accepted
6 days, 19 hours ago
-
@LeSuisse
published on GitHub
6 days, 19 hours ago
Silent Drop of TLS 1.3 Encrypted Records in s2n-tls
Permalink
CVE-2026-16318
6.9 MEDIUM
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): None (N)
-
Vulnerable System Impact Integrity (VI): None (N)
-
Vulnerable System Impact Availability (VA): Low (L)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): None (N)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): None (N)
-
Modified Vulnerable System Impact Integrity (MVI): None (N)
-
Modified Vulnerable System Impact Availability (MVA): Low (L)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Negligible (N)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
6 days, 19 hours ago
by @LeSuisse
Activity log
-
Created suggestion
6 days, 21 hours ago
-
@LeSuisse
ignored
reference https://s…
6 days, 19 hours ago
-
@LeSuisse
accepted
6 days, 19 hours ago
-
@LeSuisse
published on GitHub
6 days, 19 hours ago
QUIC Transport Parameters Memory Leak During HelloRetryRequest in s2n-tls