Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-100662 — Netty HTTP/3 QPACK encoder-stream unbounded memory exhaustion DoS

Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.0.Final through 4.2.17.Final contain an uncontrolled resource consumption vulnerability in the QPACK encoder-stream instruction decoder …

Remote | Denial of Service
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
7.5 HIGH
CVE-2026-100661 — Netty HTTP/3 QPACK Prefixed Integer DoS via Unbounded Accumulation

Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.0.Final through 4.2.17.Final contain a denial-of-service vulnerability in the QPACK prefixed-integer decoder (QpackUtil.decodePrefixedIn…

Remote | Denial of Service
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
7.5 HIGH
CVE-2026-100660 — Netty before 4.2.18.Final QpackEncoder Unbounded Memory Retention

Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.0.Final through 4.2.17.Final retains unbounded per-stream QPACK encoder state. QpackEncoder stores a queue and a dynamic-table index tracker…

Remote | Denial of Service
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
6.5 MEDIUM
CVE-2026-100659 — Netty 4.2.0 through 4.2.18 HTTP/3 Request Routing Bypass

Netty's HTTP/3 codec (io.netty:netty-codec-http3) in versions 4.2.0.Final through 4.2.17.Final does not enforce the RFC 9114 requirement that the :authority pseudo-header field and a literal host hea…

Remote | Misconfiguration
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
5.3 MEDIUM
CVE-2026-100658 — Netty before 4.1.138.Final Denial of Service via WebSocketServerExtensionHandler

Netty (io.netty:netty-codec-http) contains an unbounded per-connection queue in WebSocketServerExtensionHandler. The handler offers an entry to its per-channel validExtensions queue for every inbound…

Remote | Denial of Service
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
7.5 HIGH
CVE-2026-100657 — Netty before 4.1.138.Final ByteBuf Leak in StompSubframeDecoder

Netty's STOMP codec (io.netty:netty-codec-stomp) contains a ByteBuf leak in StompSubframeDecoder. Once a frame's declared content-length has been fully read, the decoder allocates a chunk buffer from…

Remote | Memory Corruption
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
7.5 HIGH
CVE-2026-100656 — Netty HttpServerCodec Unbounded Queue Growth via HTTP/1.1 Pipelining

Netty (io.netty:netty-codec-http) contains an unbounded per-connection queue growth flaw in HttpServerCodec. The codec tracks the HTTP method of each still-unanswered pipelined request; the first 32 …

Remote | Denial of Service
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
7.5 HIGH
CVE-2026-100655 — Netty before 4.1.138.Final Denial of Service via SpdySessionHandler

Netty (io.netty:netty-codec-http) versions up to and including 4.1.137.Final and from 4.2.0.Final through 4.2.17.Final accept an unlimited number of concurrent remote-initiated SPDY streams: SpdySess…

Remote | Denial of Service
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
6.5 MEDIUM
CVE-2026-100654 — vLLM before 0.29.0 Denial of Service via out-of-range stop_token_ids

vLLM before 0.29.0 accepts user-controlled stop_token_ids on the OpenAI-compatible POST /v1/completions and POST /v1/chat/completions endpoints but validates only that the values are integers, not th…

vllm | Remote | Denial of Service
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
6.5 MEDIUM
CVE-2026-100653 — vLLM 0.22.1 before 0.28.0 Incomplete Artifact Pin Propagation

vLLM is an inference and serving engine for large language models. In versions from 0.22.1 through 0.28.0, the operator-supplied model revision pin (--revision / --code-revision) is not propagated to…

vllm | Remote | Supply Chain
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
5.9 MEDIUM
CVE-2026-100652 — vLLM 0.22.0 through 0.23.0 Denial of Service via stop_token_ids

vLLM versions 0.22.0 through 0.23.0 fail to validate stop_token_ids against vocabulary bounds in Rust HTTP and gRPC frontends, allowing out-of-vocabulary token IDs to reach MinTokensLogitsProcessor. …

vllm | Remote | Denial of Service
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
6.5 MEDIUM
CVE-2026-100651 — vllm before 0.29.0 Denial of Service via Decoder Prompt Length Bypass

vLLM before 0.29.0 fails to enforce decoder prompt-length validation on the disaggregated serving endpoint /inference/v1/generate. When the request contains a 'features' (multimodal) payload, vllm/en…

vllm | Remote | Denial of Service
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
6.5 MEDIUM
CVE-2026-100650 — vLLM before 0.29.0 Resource Exhaustion via Unbounded Media Materialization

vLLM through 0.29.0 fetches and fully materializes remote or inline media before enforcing its documented media controls (the VLLM_MAX_AUDIO_CLIP_FILESIZE_MB compressed-audio size cap, default 25 MB,…

vllm | Remote | Denial of Service
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
3.7 LOW
CVE-2026-100649 — vLLM before 0.29.0 Resource Limit Bypass via Sampler Subclass

vLLM before 0.29.0 contains a resource-limit bypass vulnerability in PyNvVideoCodec decoder allocation where sampler subclass shadowing allows independent counter increments. Unauthenticated attacker…

vllm | Remote | Misconfiguration
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
5.3 MEDIUM
CVE-2026-100648 — vllm before 0.29.0 Uncontrolled Resource Consumption via Audio Decoding

vllm before 0.29.0 fails to enforce VLLM_MAX_AUDIO_CLIP_FILESIZE_MB limit in multimodal chat audio decoding, allowing unauthenticated clients to bypass file size restrictions. Attackers can submit ov…

vllm | Remote | Denial of Service
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
5.3 MEDIUM
CVE-2026-100647 — vLLM before 0.29.0 CPU Exhaustion via unbounded cache_salt

vLLM versions before 0.29.0 contain a denial-of-service vulnerability in the cache_salt parameter accepted on OpenAI-compatible and Anthropic API endpoints, which lacks maximum length validation and …

vllm | Remote | Denial of Service
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.1 HIGH
CVE-2026-100646 — SiYuan before v3.8.4 Authentication Bypass via Missing Origin Header

SiYuan is a self-hosted personal knowledge management system. In versions up to and including 3.8.3, the kernel's authentication guards (CheckAuth in kernel/model/session.go and IsSessionOriginAllowe…

Remote | Authentication
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.0 HIGH
CVE-2026-100645 — SiYuan 3.7.0 before 3.8.4 Stored XSS via Gallery Kanban

SiYuan versions 3.7.0 before 3.8.4 contain a stored cross-site scripting vulnerability in gallery and kanban database renderers where field descriptions are not escaped in aria-label attributes. In t…

Remote | Cross-Site Scripting
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
7.5 HIGH
CVE-2026-100644 — SiYuan before v3.8.4 SQL Injection via dailyNoteSavePath

SiYuan before v3.8.4 contains a SQL injection vulnerability in the graph query endpoint where the dailyNoteSavePath parameter is concatenated into SQL without escaping. Unauthenticated attackers on p…

Remote | Injection
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.0 HIGH
CVE-2026-100643 — SiYuan before v3.8.4 Stored XSS via Attribute View textarea

SiYuan versions before v3.8.4 fail to properly escape four stored Attribute View values in textarea elements, allowing authenticated attackers to inject JavaScript by modifying field descriptions, te…

Remote | Cross-Site Scripting
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
Showing 20 of 14668 Results