Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.3 HIGH
CVE-2026-33044 — Home Assistant has stored XSS in Map-card through malicious device name

Home Assistant is open source home automation software that puts local control and privacy first. Starting in version 2020.02 and prior to version 2026.01, an authenticated party can add a malicious …

home-assistant | Remote | Cross-Site Scripting
Mar 27, 2026 Mar 31, 2026
Mar 27, 2026
Mar 31, 2026
8.8 HIGH
CVE-2026-32241 — Flannel vulnerable to cross-node remote code execution via extension backend BackendData …

Flannel is a network fabric for containers, designed for Kubernetes. The Flannel project includes an experimental Extension backend that allows users to easily prototype new backend types. In version…

flannel | Remote | Injection
Mar 27, 2026 Apr 08, 2026
Mar 27, 2026
Apr 08, 2026
6.8 MEDIUM
CVE-2026-31951 — LibreChat's MCP Server Header Injection Enables OAuth Token Theft

LibreChat is a ChatGPT clone with additional features. In versions 0.8.2-rc1 through 0.8.3-rc1, user-created MCP (Model Context Protocol) servers can include arbitrary HTTP headers that undergo crede…

librechat | Remote | Information Disclosure
Mar 27, 2026 Mar 30, 2026
Mar 27, 2026
Mar 30, 2026
5.3 MEDIUM
CVE-2026-31950 — LibreChat's IDOR in SSE Stream Subscription Allows Reading Other Users' Chats

LibreChat is a ChatGPT clone with additional features. In versions 0.8.2-rc2 through 0.8.2-rc3, the SSE streaming endpoint `/api/agents/chat/stream/:streamId` does not verify that the requesting user…

librechat | Remote | Authorization
Mar 27, 2026 Mar 30, 2026
Mar 27, 2026
Mar 30, 2026
7.7 HIGH
CVE-2026-31945 — LibreChat Server-Side Request Forgery using DNS resolution

LibreChat is a ChatGPT clone with additional features. Versions 0.8.2-rc2 through 0.8.2 are vulnerable to a server-side request forgery (SSRF) attack when using agent actions or MCP. Although a previ…

librechat | Remote | Server-Side Request Forgery
Mar 27, 2026 Mar 30, 2026
Mar 27, 2026
Mar 30, 2026
8.5 HIGH
CVE-2026-31943 — LibreChat has SSRF protection bypass via IPv4-mapped IPv6 normalization in isPrivateIP

LibreChat is a ChatGPT clone with additional features. Prior to version 0.8.3, `isPrivateIP()` in `packages/api/src/auth/domain.ts` fails to detect IPv4-mapped IPv6 addresses in their hex-normalized …

librechat | Remote | Server-Side Request Forgery
Mar 27, 2026 Mar 31, 2026
Mar 27, 2026
Mar 31, 2026
Showing 20 of 5686 Results