Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
3.1 LOW
CVE-2026-102279 — Laravel: XSS in Debug Page Information

Laravel is a web application framework. Prior to 12.69.0 and 13.30.0, Laravel exception debug pages with APP_DEBUG=true pass attacker-controlled input to a Tippy.js tooltip configured with allowHTML …

framework | Remote | Cross-Site Scripting
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
7.5 HIGH
CVE-2026-102278 — brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exha…

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.20, 2.1.6, 3.0.8, and 5.0.11, deeply nested brace groups cause expand_() to recurse once pe…

brace-expansion | Remote | Denial of Service
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
5.3 MEDIUM
CVE-2026-102277 — brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of se…

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.21, 2.1.7, 3.0.9, and 5.0.12, the expand function handles untrusted {a},b}-shaped patterns …

brace-expansion | Remote | Denial of Service
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
7.5 HIGH
CVE-2026-102276 — brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhausti…

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.19, 2.1.5, 3.0.7, and 5.0.10, crafted brace patterns can exhaust the native stack in parseC…

brace-expansion | Remote | Denial of Service
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
6.5 MEDIUM
CVE-2026-102275 — PyJWT accepts inconsistent OKP x/d JWKs, causing public/private key identity confusion

PyJWT is a Python implementation of JSON Web Token standards. From 2.1.0 until 2.15.0, PyJWT OKPAlgorithm.from_jwk in jwt/algorithms.py is affected because private-JWK import path does not compare t…

pyjwt | Remote | Cryptography
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
5.9 MEDIUM
CVE-2026-102274 — PyJWT: Malformed RSA JWK aborts parsing of an entire JWK Set

PyJWT is a Python implementation of JSON Web Token standards. From 2.9.0 until 2.14.0, PyJWKSet does not catch the plain ValueError raised for malformed RSA JWK components by RSAAlgorithm.from_jwk in…

pyjwt | Remote | Authentication
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
7.4 HIGH
CVE-2026-102273 — PyJWT accepts public JWK containers as HMAC secrets

PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, PyJWT HMACAlgorithm.prepare_key is affected because HMAC key guard only recognizes top-level public JWK forms a…

pyjwt | Remote | Authentication
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
7.4 HIGH
CVE-2026-102272 — PyJWT BOM Bypass

PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, HMACAlgorithm.prepare_key in jwt/algorithms.py is affected because raw-JWK detector does not normalize accepted…

pyjwt | Remote | Authentication
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
7.4 HIGH
CVE-2026-102271 — PyJWT: Public keys in DER form are accepted as HMAC secrets, bypassing the CVE-2022-29217…

PyJWT is a Python implementation of JSON Web Token standards. From 2.4.0 until 2.14.0, PyJWT HMACAlgorithm.prepare_key is affected because asymmetric-key guard relies on textual markers that are abse…

pyjwt | Remote | Cryptography
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
4.4 MEDIUM
CVE-2026-102270 — PyJWT: ReDoS vulnerability when calling the `is_pem_format` function.

PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT is_pem_format is affected because lazy PEM regular expression backtracks extensively. This occurs when a certifica…

pyjwt | Remote | Denial of Service
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
4.8 MEDIUM
CVE-2026-102269 — PyJWT: Non-canonical signature segments enable raw-token revocation bypass

PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT signature segment is affected because signature segment decoding accepts characters outside the canonical Base64UR…

pyjwt | Remote | Cryptography
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
9.1 CRITICAL
CVE-2026-102268 — PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip t…

PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, is_pem_format in jwt/utils.py is affected because is_pem_format does not recognize every PEM representation accepted by …

pyjwt | Remote | Authentication
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
7.4 HIGH
CVE-2026-102267 — PyJWT: PyJWKClient follows redirects when fetching JWKS

PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT PyJWKClient is affected because redirect destinations are not revalidated against the JWKS trust boundary. This oc…

pyjwt | Remote | Supply Chain
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
7.4 HIGH
CVE-2026-102266 — PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation

PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, HMACAlgorithm.from_jwk is affected because PyJWK verification path used the decoded key without applying prepar…

pyjwt | Remote | Authentication
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
5.3 MEDIUM
CVE-2026-102265 — PyJWT: Uncaught RecursionError in jwt.decode() on deeply nested token header

PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, PyJWS._load in jwt/api_jws.py is affected because parser catches ValueError but not RecursionError. This occurs…

pyjwt | Remote | Denial of Service
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
5.5 MEDIUM
CVE-2026-102006 — VxWorks 7 Memory allocation

In Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in the process management subsystem failing to properly release allocated kernel memory before terminating the callin…

vxworks | Memory Corruption
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
5.5 MEDIUM
CVE-2026-102005 — VxWorks Memory Allocation

Wind River VxWorks 7 24.03 through 26.03, a memory leak occurs under specific, non-default configuration states when processing specific service routines, causing the system to terminate operations b…

vxworks | Memory Corruption
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
5.3 MEDIUM
CVE-2026-101918 — PyJWT: Unauthenticated RecursionError DoS in pre-verification payload parse (PyJWKClient.…

PyJWT is a Python implementation of JSON Web Token standards. From 2.0.0a1 until 2.15.0, PyJWT PyJWKClient.get_signing_key_from_jwt is affected because payload parser catches ValueError but not Recur…

pyjwt | Remote | Denial of Service
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
5.3 MEDIUM
CVE-2026-101917 — PyJWT: PyJWKClient still amplifies unauthenticated JWKS fetches on unknown kid values (in…

PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT get_signing_key_from_jwt is affected because unknown kid misses force refreshes without a negative cache or minimu…

pyjwt | Remote | Denial of Service
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
7.4 HIGH
CVE-2026-101916 — @grpc/grpc-js: In certain configurations, getAuthContext can return unauthorized certific…

@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.6 and 1.14.5, getAuthContext does not distinguish authorized from unauthorized peer ce…

Remote | Authentication
Sep 28, 2026 Sep 28, 2026
Sep 28, 2026
Sep 28, 2026
Showing 20 of 14278 Results