Tag

#vulnerability

blogHIGH 8.0

Understanding and Defending Against CVE-2026-64258: A Linux Kernel Vulnerability

CVE-2026-64258 is a vulnerability in the Linux kernel that can lead to a NULL pointer dereference. It affects the fuse-uring subsystem and allows an attacker to potentially crash the system or escalate privileges. This analysis provides an in-depth look at the vulnerability, its exploitation mechanics, and defensive strategies.

1 source
articleCRITICAL 9.1

Auth.js Configuration Error Leads to Silent Fail-Open in Existence-Based Auth Checks

A critical vulnerability in Auth.js (next-auth) version 5 allows misconfigured applications to fail open, granting unauthorized access to all users when the auth layer encounters a server-side error. This issue arises from existence-based auth checks evaluating to true for every request, including unauthenticated ones, when the auth object is populated with an error. The vulnerability has a CVSS score of 9.1 and is classified under CWE-636 (Not Failing Securely) and CWE-285 (Improper Authorization).

1 source
articleHIGH 7.0

Inheritance of High-Severity Vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591

Multiple high-severity vulnerabilities have been discovered in the libvips dependency used by the sharp library. These vulnerabilities, with a CVSS score of 7, affect versions of sharp prior to 0.35.0. The vulnerabilities have been patched in sharp version 0.35.3, which includes libvips 8.18.3. Immediate upgrade is recommended to prevent potential exploitation.

1 source
articleCRITICAL 9.0

Critical FFmpeg PixelSmash Flaw Enables Remote Code Execution

A critical vulnerability in FFmpeg's libavcodec library, known as PixelSmash, allows attackers to execute code remotely on video players, media servers, and NAS appliances. This flaw enables attackers to send crafted media files to compromise applications using FFmpeg. The vulnerability is severe, with a potential for widespread impact given FFmpeg's broad deployment across various platforms. Organizations are advised to patch vulnerable systems immediately to prevent potential exploitation.

1 source
newsMEDIUM 6.9

Integer Overflow Vulnerability in libexpat (CVE-2026-56406)

A medium-severity integer overflow vulnerability was discovered in libexpat before version 2.8.2. The vulnerability affects local attackers who can exploit it to achieve high impact on confidentiality and integrity, and low impact on availability. Affected systems should update to version 2.8.2 or later.

1 source
blogHIGH 8.1

Understanding and Defending Against CVE-2025-71348: A Remote Code Execution Vulnerability in picklescan

CVE-2025-71348 is a high-severity vulnerability in the picklescan library, which fails to detect malicious pickle files that can execute arbitrary code. This vulnerability, with a CVSS score of 8.1, allows attackers to craft pickle files that evade detection but execute during pickle.load, enabling remote code execution in supply chain attacks. The vulnerability affects picklescan versions before 0.0.28. Understanding this threat is crucial for defenders to protect against potential supply chain attacks.

1 source
blogHIGH 8.5

Understanding and Defending Against XSS in Gogs .ipynb Files Renderer

Gogs, a self-hosted Git service, is vulnerable to a cross-site scripting (XSS) attack due to an outdated version of notebookjs used to render Jupyter notebook files (.ipynb). The vulnerability, with a CVSS score of 8.5, allows any user with repository creation rights to craft XSS payloads that can take over a victim's account. This educational analysis will delve into the root cause, attack surface, exploitation mechanics, real-world impact, detection, and defense strategies.

1 source
newsHIGH 8.4

@hulumi/policies vulnerability allows bypassing policy packs with forged Pulumi-URN logical name

A high-severity vulnerability in @hulumi/policies allows developers to bypass mandatory hardening checks by naming resources with a trusted substring, affecting multiple cloud providers.

1 source
newsCRITICAL 9.2

stigmem-node Vulnerability: Auth-Disabled Deployments Expose to Broad Anonymous Access

A vulnerability in stigmem-node allows auth-disabled deployments to grant broad anonymous access outside loopback environments. Operators who disabled authentication while binding the node to a non-loopback URL are impacted.

1 source