Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
3.1 LOW
CVE-2026-106588 — OpenSSH sshd Sandbox Bypass

In sshd in OpenSSH through 10.6, use of the macOS 27 (or later) SDK has the side effect of loss of sandboxing, which is potentially unexpected.

openssh | Remote | Misconfiguration
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
3.6 LOW
CVE-2026-106587 — OpenSSH sshd Configuration Option Misinterpretation Vulnerability

In sshd in OpenSSH before 10.6, the value "none" for a configuration option is sometimes interpreted as a filename but was intended to mean that a feature is disabled.

openssh | Misconfiguration
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.7 HIGH
CVE-2026-106509 — Backstage: Improper validation of MkDocs theme configuration in TechDocs

Backstage is an open framework for building developer portals. Prior to 1.14.6, the @backstage/plugin-techdocs-node package is affected by improper validation of mkdocs theme configuration in techdoc…

backstage_plugin-techdocs-node | Remote | Injection
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
5.3 MEDIUM
CVE-2026-106508 — Backstage: Potential file exposure through local TechDocs publisher

Backstage is an open framework for building developer portals. Prior to 1.15.4, the @backstage/plugin-techdocs-node package is affected by potential file exposure through local techdocs publisher. Wh…

backstage_plugin-techdocs-node | Remote | Path Traversal
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
5.3 MEDIUM
CVE-2026-106507 — Backstage: TechDocs arbitrary file read via mkdocs snippets

Backstage is an open framework for building developer portals. Prior to 1.15.4, the @backstage/plugin-techdocs-node package is affected by techdocs arbitrary file read via mkdocs snippets. Unsafe pat…

backstage_plugin-techdocs-node | Remote | Path Traversal
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
5.3 MEDIUM
CVE-2026-106506 — Backstage: Improper input validation in scaffolder task list ordering

Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by improper input validation in scaffolder task list orderi…

Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.7 HIGH
CVE-2026-106505 — Backstage: Bypass of MkDocs configuration sanitizer in TechDocs backend

Backstage is an open framework for building developer portals. Prior to 1.14.6 and 1.15.4, the @backstage/plugin-techdocs-node package is affected by bypass of mkdocs configuration sanitizer in techd…

backstage_plugin-techdocs-node | Remote | Misconfiguration
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
6.5 MEDIUM
CVE-2026-106504 — Backstage: Sensitive information exposure in scaffolder task logs

Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by sensitive information exposure in scaffolder task logs. …

Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
8.1 HIGH
CVE-2026-106503 — Backstage: Scaffolder action input authorization bypass

Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by scaffolder action input authoriz…

Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
5.3 MEDIUM
CVE-2026-106502 — Backstage: Sensitive information may be exposed in Scaffolder task failure events

Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package could expose sensitive information in Scaffolder task failure events. U…

Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
9.6 CRITICAL
CVE-2026-106501 — Backstage: Sensitive information exposure in Scaffolder

Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by sensitive information exposure i…

Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
8.5 HIGH
CVE-2026-106500 — Backstage: Improper task state validation in Scaffolder backend

Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by improper task state validation i…

Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
4.9 MEDIUM
CVE-2026-106499 — Backstage: Secret-derived values may be exposed in scaffolder task logs

Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package could expose secret-derived values in Scaffolder task logs. Deployments…

Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.7 HIGH
CVE-2026-106498 — Backstage: Improper URL validation in catalog entity placeholder resolution

Backstage is an open framework for building developer portals. Prior to 3.5.1, 3.6.2, 3.7.2, 3.8.2 and 3.9.1, the @backstage/plugin-catalog-backend package is affected by improper url validation in c…

backstage_plugin-techdocs-node | Remote | Path Traversal
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
4.3 MEDIUM
CVE-2026-106497 — Backstage: Inconsistent catalog property permission evaluation

Backstage is an open framework for building developer portals. Prior to 3.9.1, the @backstage/plugin-catalog-backend package is affected by inconsistent catalog property permission evaluation. In dep…

backstage_plugin-techdocs-node | Remote | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
3.1 LOW
CVE-2026-106496 — Backstage: Inconsistent enforcement of allowed location types during catalog processing

Backstage is an open framework for building developer portals. Prior to 3.9.1, the @backstage/plugin-catalog-backend package is affected by inconsistent enforcement of allowed location types during c…

backstage_plugin-techdocs-node | Remote | Misconfiguration
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
0.0 NA
CVE-2026-105268 — Gitea issue attachment API allows changing comment attachments

The Gitea API routes for issue attachments (`/api/v1/repos/{owner}/{repo}/issues/{index}/assets/{attachment_id}`) also accepted attachments that belong to comments on the issue. Because the author of…

gitea | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
0.0 NA
CVE-2026-105267 — Gitea tag delete route deletes releases without release permission

The Gitea web route for deleting tags (`POST /{owner}/{repo}/tags/delete`) requires only write access to the Code unit, but shares its handler with release deletion and did not check that the target …

gitea | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
0.0 NA
CVE-2026-104633 — Gitea migration memory exhaustion from zero page size

When migrating a repository from another Gitea instance, Gitea used the page size reported in the source server's API settings to end its paginated downloads. A source that reported `max_response_ite…

gitea | Denial of Service
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
0.0 NA
CVE-2026-101023 — Gitea OAuth2 refresh token grant accepts access tokens

Gitea's OAuth2 token endpoint verified the signature and grant of a token submitted with the `refresh_token` grant type, but not that the token was a refresh token. An unexpired access token for the …

gitea | Authentication
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
Showing 20 of 15432 Results