Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-100670 — Grav CMS 2.0.14 through 2.0.24 Privilege Escalation via Blueprint Guard Bypass

Grav CMS 2.0.14 through 2.0.24 contains a privilege escalation vulnerability in the group and account blueprints. The access map is gated by a `security@: admin.super` guard that is resolved by the f…

grav | Remote | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.7 HIGH
CVE-2026-100669 — Grav before 2.0.25 Sensitive File Disclosure via Case-Variation Bypass

Grav before 2.0.25 ships web server configuration samples whose access-control deny rules are matched case-sensitively. In webserver-configs/web.config (IIS), every deny rule (user_sensitive_folders,…

grav | Remote | Misconfiguration
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
7.1 HIGH
CVE-2026-100668 — Grav before 2.0.25 Sandbox Escape via array Filter

Grav 2.0.0 through 2.0.24 contain a Twig content sandbox escape. The `array` filter (and its identical function form) is on the sandbox allowlist but is registered without the needs_is_sandboxed guar…

grav | Remote | Misconfiguration
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
6.9 MEDIUM
CVE-2026-100667 — grav-plugin-login 3.8.7 through 3.9.6 Two-Factor Authentication Bypass

grav-plugin-login (the Grav CMS Login plugin) versions >= 3.8.7 and < 3.9.7 allow the two-factor authentication challenge to be bypassed for content gated by the authenticated() Twig function or the …

grav | Remote | Authentication
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
7.3 HIGH
CVE-2026-100666 — Netty 4.2.0 through 4.2.17 Response Desynchronization via HttpServerCodec

Netty's HttpServerCodec (io.netty:netty-codec-http) in versions 4.2.0.Final through 4.2.16.Final and in versions up to and including 4.1.136.Final pairs each outbound response with an inbound request…

netty | Remote | Misconfiguration
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.7 HIGH
CVE-2026-100665 — Netty 4.2.11 through 4.2.17 QUIC Hostname Verification Bypass

Netty versions from 4.2.11.Final before 4.2.18.Final contain an incomplete hostname verification fix in the QUIC certificate verification path when using a plain X509TrustManager. The BoringSSLCertif…

netty | Remote | Authentication
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.7 HIGH
CVE-2026-100664 — Netty 4.2.2 through 4.2.15 HTTP/1 Host Header Authority Confusion

Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.2.Final through 4.2.17.Final builds the HTTP/3 :authority pseudo-header from the HTTP/1 Host header before considering the authority of …

netty | Remote | Misconfiguration
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.7 HIGH
CVE-2026-100663 — Netty HTTP/1 CONNECT authority-form mistranslated to malformed HTTP/3

Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.2.Final through 4.2.17.Final does not special-case HTTP/1 CONNECT authority-form request-targets when converting HTTP/1 messages to HTTP/3 i…

netty | Remote | Misconfiguration
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.7 HIGH
CVE-2026-100662 — Netty HTTP/3 QPACK encoder-stream unbounded memory exhaustion DoS

Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.0.Final through 4.2.17.Final contain an uncontrolled resource consumption vulnerability in the QPACK encoder-stream instruction decoder …

netty | Remote | Denial of Service
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.7 HIGH
CVE-2026-100661 — Netty HTTP/3 QPACK Prefixed Integer DoS via Unbounded Accumulation

Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.0.Final through 4.2.17.Final contain a denial-of-service vulnerability in the QPACK prefixed-integer decoder (QpackUtil.decodePrefixedIn…

netty | Remote | Denial of Service
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.7 HIGH
CVE-2026-100660 — Netty before 4.2.18.Final QpackEncoder Unbounded Memory Retention

Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.0.Final through 4.2.17.Final retains unbounded per-stream QPACK encoder state. QpackEncoder stores a queue and a dynamic-table index tracker…

netty | Remote | Denial of Service
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
6.9 MEDIUM
CVE-2026-100659 — Netty 4.2.0 through 4.2.18 HTTP/3 Request Routing Bypass

Netty's HTTP/3 codec (io.netty:netty-codec-http3) in versions 4.2.0.Final through 4.2.17.Final does not enforce the RFC 9114 requirement that the :authority pseudo-header field and a literal host hea…

netty | Remote | Misconfiguration
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
6.9 MEDIUM
CVE-2026-100658 — Netty before 4.1.138.Final Denial of Service via WebSocketServerExtensionHandler

Netty (io.netty:netty-codec-http) contains an unbounded per-connection queue in WebSocketServerExtensionHandler. The handler offers an entry to its per-channel validExtensions queue for every inbound…

netty | Remote | Denial of Service
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.7 HIGH
CVE-2026-100657 — Netty before 4.1.138.Final ByteBuf Leak in StompSubframeDecoder

Netty's STOMP codec (io.netty:netty-codec-stomp) contains a ByteBuf leak in StompSubframeDecoder. Once a frame's declared content-length has been fully read, the decoder allocates a chunk buffer from…

netty | Remote | Memory Corruption
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.7 HIGH
CVE-2026-100656 — Netty HttpServerCodec Unbounded Queue Growth via HTTP/1.1 Pipelining

Netty (io.netty:netty-codec-http) contains an unbounded per-connection queue growth flaw in HttpServerCodec. The codec tracks the HTTP method of each still-unanswered pipelined request; the first 32 …

netty | Remote | Denial of Service
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
7.5 HIGH
CVE-2026-100655 — Netty before 4.1.138.Final Denial of Service via SpdySessionHandler

Netty (io.netty:netty-codec-http) versions up to and including 4.1.137.Final and from 4.2.0.Final through 4.2.17.Final accept an unlimited number of concurrent remote-initiated SPDY streams: SpdySess…

netty | Remote | Denial of Service
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
7.1 HIGH
CVE-2026-100654 — vLLM before 0.29.0 Denial of Service via out-of-range stop_token_ids

vLLM before 0.29.0 accepts user-controlled stop_token_ids on the OpenAI-compatible POST /v1/completions and POST /v1/chat/completions endpoints but validates only that the values are integers, not th…

vllm vllm | Remote | Denial of Service
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.3 HIGH
CVE-2026-100653 — vLLM 0.22.1 before 0.28.0 Incomplete Artifact Pin Propagation

vLLM is an inference and serving engine for large language models. In versions from 0.22.1 through 0.28.0, the operator-supplied model revision pin (--revision / --code-revision) is not propagated to…

vllm vllm | Remote | Supply Chain
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.2 HIGH
CVE-2026-100652 — vLLM 0.22.0 through 0.23.0 Denial of Service via stop_token_ids

vLLM versions 0.22.0 through 0.23.0 fail to validate stop_token_ids against vocabulary bounds in Rust HTTP and gRPC frontends, allowing out-of-vocabulary token IDs to reach MinTokensLogitsProcessor. …

vllm vllm | Remote | Denial of Service
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
7.1 HIGH
CVE-2026-100651 — vllm before 0.29.0 Denial of Service via Decoder Prompt Length Bypass

vLLM before 0.29.0 fails to enforce decoder prompt-length validation on the disaggregated serving endpoint /inference/v1/generate. When the request contains a 'features' (multimodal) payload, vllm/en…

vllm vllm | Remote | Denial of Service
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
Showing 20 of 14442 Results