Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.2 MEDIUM
CVE-2026-107361 — Authentication Bypass Using an Alternate Path or Channel in Malcolm

The Arkime live capture service (arkime-live) in Malcolm runs with network_mode: host, exposing port 8005 on all network interfaces (viewHost=0.0.0.0). Arkime trusts the X-Forwarded-User header from …

| Authentication
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
7.1 HIGH
CVE-2026-107362 — Server-Side Request Forgery in Malcolm

Malcolm file-upload component ships the upstream FilePond PHP server (pqina/filepond-server-php) largely unmodified: Dockerfile copies all upstream *.php files and Malcolm only overwrites config.php …

Remote | Server-Side Request Forgery
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
8.1 HIGH
CVE-2026-107333 — Incorrect Authorization in Malcolm

Malcolm's nginx based reverse proxy contains a URL path normalization inconsistency between its Lua based role-based access control (RBAC) authorization layer and nginx's own request routing logic. A…

Remote | Authorization
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
0.0 NA
CVE-2026-107303 — JHipster: Generated Applications Allow Stored XSS via Unrestricted Blob ContentType Opene…

JHipster is a development platform to quickly generate, develop, and deploy modern web applications and microservice architectures. Prior to generator-jhipster 9.4.0 and react-jhipster 1.1.0, generat…

generator-jhipster | Misconfiguration
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.5 MEDIUM
CVE-2026-107336 — Authentication Bypass by Spoofing in Malcolm

Malcolm's front nginx reverse proxy defines a "Dashboards → Arkime shortcut" location using a case-insensitive regex matcher but a case-sensitive rewrite. A request whose path segment is not exact-lo…

Remote | Authentication
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
0.0 NA
CVE-2026-88647 — GnuTLS Hostname Verification Bypass

A hostname verification bypass in GnuTLS v3.8.13 allows attackers to circumvent the Common Name fallback mechanism and eavesdrop on communications via a crafted certificate.

| Cryptography
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
5.5 MEDIUM
CVE-2026-61801 — github.com/moby/sys/user has a possible DoS via unbounded parsing of user and group datab…

The `github.com/moby/sys/user` package provides Go utilities for parsing and looking up entries in Unix-style user and group database files. Versions before 0.4.1 do not sufficiently limit entries wh…

| Denial of Service
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.5 MEDIUM
CVE-2026-50055 — Zimbra Collaboration Suite Sieve Notify Filter Action Bypasses Mail Forwarding Restrictio…

A policy-enforcement flaw in Zimbra Collaboration Suite allows an authenticated user to bypass disabled mail forwarding by using a Sieve notify action to send copies of email content and headers to a…

collaboration_suite | Remote | Authorization
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
7.1 HIGH
CVE-2026-50054 — Zimbra Collaboration Suite GrantRightsRequest SOAP Handler Allows Self-Granting of Undocu…

An authorization flaw in Zimbra Collaboration Suite’s GrantRightsRequest allows an attacker with access to an authenticated account to grant another local account the loginAs right, creating persiste…

collaboration_suite | Remote | Authorization
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.5 MEDIUM
CVE-2026-10631 — Zimbra Collaboration Suite EWS Extension Authorization Bypass via Crafted Composite Folde…

An authorization bypass in the EWS FindItem handler of Zimbra Collaboration Suite 10.1.0 through 10.1.19 allows an authenticated user with EWS enabled to read complete mailbox items, including raw MI…

collaboration_suite | Remote | Authorization
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
0.0 NA
CVE-2026-107709 — Bower decompress-zip has a path traversal vulnerability

A path traversal vulnerability exists in Bower decompress-zip through version 0.3.3. The vulnerability located in `lib/decompress-zip.js` improperly validates archive entry paths during ZIP extractio…

| Path Traversal
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.5 MEDIUM
CVE-2026-107301 — msgpack5: Partial options disable prototype protection

msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, constructing msgpack5 with an empty or partial options object disables the default protoAction: 'error' protection…

Remote | Misconfiguration
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
7.5 HIGH
CVE-2026-107300 — msgpack5: Many buffered values can exhaust the streaming decoder stack

msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder recursively invokes itself for each complete MessagePack value remaining in a chunk. A remot…

Remote | Denial of Service
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
5.9 MEDIUM
CVE-2026-107299 — msgpack5: Reserved byte can cause unbounded stream buffering

msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder treats the reserved MessagePack byte 0xc1 as incomplete input instead of invalid input. When…

Remote | Denial of Service
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
5.3 MEDIUM
CVE-2026-107298 — msgpack5: Deeply nested input can exhaust the decoder stack

msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the array and map decoding paths have no nesting-depth limit, allowing an attacker who can provide MessagePack inp…

Remote | Denial of Service
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
5.9 MEDIUM
CVE-2026-107297 — msgpack5: Quadratic parsing in the streaming decoder

msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder reparses an incomplete array or map from the beginning whenever another chunk arrives. A rem…

Remote | Denial of Service
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
3.7 LOW
CVE-2026-107296 — msgpack5: Decoding negative int64 values mutates the input buffer

msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, decoding a negative signed 64-bit integer modifies the corresponding bytes in the caller-provided input buffer whi…

Remote | Misconfiguration
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
7.6 HIGH
CVE-2026-107295 — `pydantic-ai-slim` web UI `/api/chat` accepts browser-simple cross-origin requests that c…

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 until 1.107.4 and 2.28.0, the Agent.to_web() and clai web development chat endpoint has…

Remote | Misconfiguration
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.5 MEDIUM
CVE-2026-107294 — Pydantic AI: Unbounded memory use when downloading remote content via web_fetch or FileUrl

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.77.0 until 1.107.2 and 2.24.0, web_fetch_tool, the WebFetch local fallback, and remote FileU…

Remote | Denial of Service
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
2.3 LOW
CVE-2026-107293 — Pydantic AI OpenTelemetry instrumentation: retry prompt content is not redacted when `inc…

Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 0.3.4 until 1.107.4 and 2.27.1, OpenTelemetry instrumentation configured with InstrumentationS…

pydantic_ai | Remote | Information Disclosure
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
Showing 20 of 15574 Results