DEV Community

CVE Reports profile picture

CVE Reports

CVEReports provides daily, automated deep-dives into the latest vulnerabilities, transforming emerging threats into comprehensive technical intelligence.

Joined Joined on  Personal website https://www.cvereports.com
GHSA-9Q4R-4842-93VW: GHSA-9Q4R-4842-93VW: Cross-Tenant SQL Injection in Trigger.dev TSQL Query Compiler

GHSA-9Q4R-4842-93VW: GHSA-9Q4R-4842-93VW: Cross-Tenant SQL Injection in Trigger.dev TSQL Query Compiler

Comments
2 min read
GHSA-4672-HWV6-GQ62: GHSA-4672-HWV6-GQ62: Cross-environment deployment cancellation in Trigger.dev

GHSA-4672-HWV6-GQ62: GHSA-4672-HWV6-GQ62: Cross-environment deployment cancellation in Trigger.dev

Comments
2 min read
GHSA-JQMF-MX4F-HFR6: GHSA-JQMF-MX4F-HFR6: Multiple Remote Code Execution and Security Flaws in Vibe-Trading AI-Agent Pipeline

GHSA-JQMF-MX4F-HFR6: GHSA-JQMF-MX4F-HFR6: Multiple Remote Code Execution and Security Flaws in Vibe-Trading AI-Agent Pipeline

Comments
2 min read
GHSA-5RMQ-CHC7-M22F: GHSA-5RMQ-CHC7-M22F: Arbitrary File Read and Path Traversal in Vibe-Trading Platform

GHSA-5RMQ-CHC7-M22F: GHSA-5RMQ-CHC7-M22F: Arbitrary File Read and Path Traversal in Vibe-Trading Platform

Comments
2 min read
GHSA-V2F8-6655-7GRJ: GHSA-v2f8-6655-7grj: Remote Code Execution and Authentication Bypass in vibe-trading-ai

GHSA-V2F8-6655-7GRJ: GHSA-v2f8-6655-7grj: Remote Code Execution and Authentication Bypass in vibe-trading-ai

Comments
2 min read
CVE-2026-18140: CVE-2026-18140: Uncontrolled Recursion in aws-smithy-json Token Skipping Path

CVE-2026-18140: CVE-2026-18140: Uncontrolled Recursion in aws-smithy-json Token Skipping Path

Comments
2 min read
GHSA-FJ2X-MQQP-3V2W: GHSA-FJ2X-MQQP-3V2W: Sensitive Information Disclosure in Trigger.dev CLI Build Logs

GHSA-FJ2X-MQQP-3V2W: GHSA-FJ2X-MQQP-3V2W: Sensitive Information Disclosure in Trigger.dev CLI Build Logs

Comments
2 min read
CVE-2026-104855: CVE-2026-104855: Sandbox Escape via Reentrant State Desynchronization in Wasmtime Bulk Memory Operations

CVE-2026-104855: CVE-2026-104855: Sandbox Escape via Reentrant State Desynchronization in Wasmtime Bulk Memory Operations

Comments
2 min read
CVE-2026-74802: CVE-2026-74802: Cross-Site WebSocket Hijacking (CSWSH) in SiYuan Knowledge Workspace

CVE-2026-74802: CVE-2026-74802: Cross-Site WebSocket Hijacking (CSWSH) in SiYuan Knowledge Workspace

Comments
2 min read
CVE-2026-74904: CVE-2026-74904: Missing Authorization in SiYuan Note-Taking Application API

CVE-2026-74904: CVE-2026-74904: Missing Authorization in SiYuan Note-Taking Application API

Comments
2 min read
CVE-2026-71416: CVE-2026-71416: Cross-Site WebSocket Hijacking in Headroom Proxy Server

CVE-2026-71416: CVE-2026-71416: Cross-Site WebSocket Hijacking in Headroom Proxy Server

Comments
2 min read
GHSA-CJCG-CXMH-9WCR: GHSA-cjcg-cxmh-9wcr: Unbounded Memory Allocation via HTTP/2 Bomb in praxis-proxy

GHSA-CJCG-CXMH-9WCR: GHSA-cjcg-cxmh-9wcr: Unbounded Memory Allocation via HTTP/2 Bomb in praxis-proxy

Comments
2 min read
GHSA-MWM8-39RW-8826: GHSA-MWM8-39RW-8826: Use-After-Free Vulnerability in Ruby sqlite3 Gem native extension

GHSA-MWM8-39RW-8826: GHSA-MWM8-39RW-8826: Use-After-Free Vulnerability in Ruby sqlite3 Gem native extension

Comments
2 min read
CVE-2026-19484: CVE-2026-19484: Remote Denial of Service via Boyer-Moore-Horspool Integer Wrap-around in @fastify/busboy

CVE-2026-19484: CVE-2026-19484: Remote Denial of Service via Boyer-Moore-Horspool Integer Wrap-around in @fastify/busboy

Comments
2 min read
CVE-2026-19481: CVE-2026-19481: Unauthenticated Remote Denial of Service via Prototype Lookup Crash in @fastify/busboy

CVE-2026-19481: CVE-2026-19481: Unauthenticated Remote Denial of Service via Prototype Lookup Crash in @fastify/busboy

Comments
2 min read
GHSA-P23F-CM6Q-2QP8: GHSA-P23F-CM6Q-2QP8: Workspace Boundary Bypass and Arbitrary File Leak in SiYuan MCP

GHSA-P23F-CM6Q-2QP8: GHSA-P23F-CM6Q-2QP8: Workspace Boundary Bypass and Arbitrary File Leak in SiYuan MCP

Comments
2 min read
GHSA-X8GV-G2G3-65FJ: CVE-2026-82234: Server-Side Request Forgery via DNS-Rebinding TOCTOU in SiYuan Kernel

GHSA-X8GV-G2G3-65FJ: CVE-2026-82234: Server-Side Request Forgery via DNS-Rebinding TOCTOU in SiYuan Kernel

Comments
2 min read
CVE-2026-104861: CVE-2026-104861: Quadratic-time Regular Expression Denial of Service in probe-image-size SVG Parser

CVE-2026-104861: CVE-2026-104861: Quadratic-time Regular Expression Denial of Service in probe-image-size SVG Parser

Comments
2 min read
CVE-2026-10032: CVE-2026-10032: DOM-based Cross-Site Scripting (XSS) via window.open in Google @a2ui/web_core

CVE-2026-10032: CVE-2026-10032: DOM-based Cross-Site Scripting (XSS) via window.open in Google @a2ui/web_core

Comments
2 min read
CVE-2026-59944: CVE-2026-59944: Path Traversal and Symlink Resolution Bypass in Composer

CVE-2026-59944: CVE-2026-59944: Path Traversal and Symlink Resolution Bypass in Composer

Comments
2 min read
GHSA-QXPP-QJG8-X4JV: GHSA-QXPP-QJG8-X4JV: Cross-Tenant Run Replay and Task Injection in Trigger.dev

GHSA-QXPP-QJG8-X4JV: GHSA-QXPP-QJG8-X4JV: Cross-Tenant Run Replay and Task Injection in Trigger.dev

Comments
2 min read
GHSA-XXV7-2VV3-H682: CVE-2026-85650: Server-Side Request Forgery in Trigger.dev Webhook Alert Channel Delivery

GHSA-XXV7-2VV3-H682: CVE-2026-85650: Server-Side Request Forgery in Trigger.dev Webhook Alert Channel Delivery

Comments
2 min read
GHSA-C9XM-49CP-XCR9: GHSA-C9XM-49CP-XCR9: Server-Side Request Forgery in rmcp OAuth Client

GHSA-C9XM-49CP-XCR9: GHSA-C9XM-49CP-XCR9: Server-Side Request Forgery in rmcp OAuth Client

Comments
2 min read
CVE-2026-92945: CVE-2026-92945: Sandbox Escape and Module Allowlist Bypass via Path Prefix Matching in vm2

CVE-2026-92945: CVE-2026-92945: Sandbox Escape and Module Allowlist Bypass via Path Prefix Matching in vm2

Comments
2 min read
CVE-2026-92941: CVE-2026-92941: Sandbox Escape and Process-Wide TLS Trust Store Manipulation in vm2

CVE-2026-92941: CVE-2026-92941: Sandbox Escape and Process-Wide TLS Trust Store Manipulation in vm2

Comments
3 min read
CVE-2026-92944: CVE-2026-92944: Sandbox Escape in vm2 via Stale V8 PromiseThenLookupChain Protector

CVE-2026-92944: CVE-2026-92944: Sandbox Escape in vm2 via Stale V8 PromiseThenLookupChain Protector

Comments
2 min read
CVE-2026-92939: CVE-2026-92939: Critical Sandbox Escape via Host Crypto setEngine Native Code Execution in vm2

CVE-2026-92939: CVE-2026-92939: Critical Sandbox Escape via Host Crypto setEngine Native Code Execution in vm2

Comments
2 min read
CVE-2026-92938: CVE-2026-92938: Remote Code Execution in vm2 via node:sqlite DatabaseSync Sandbox Escape

CVE-2026-92938: CVE-2026-92938: Remote Code Execution in vm2 via node:sqlite DatabaseSync Sandbox Escape

Comments
2 min read
CVE-2026-92937: CVE-2026-92937: Sandbox Escape leading to Remote Code Execution via Promise Indirection in vm2

CVE-2026-92937: CVE-2026-92937: Sandbox Escape leading to Remote Code Execution via Promise Indirection in vm2

Comments
2 min read
CVE-2026-92935: CVE-2026-92935: Remote Code Execution via Array-Shaped Require Config in vm2 NodeVM Sandbox

CVE-2026-92935: CVE-2026-92935: Remote Code Execution via Array-Shaped Require Config in vm2 NodeVM Sandbox

Comments
2 min read
CVE-2026-92949: CVE-2026-92949: Sandbox Escape and State Mutation in vm2 via Accessor Property Descriptor Leak

CVE-2026-92949: CVE-2026-92949: Sandbox Escape and State Mutation in vm2 via Accessor Property Descriptor Leak

Comments
2 min read
CVE-2026-92957: CVE-2026-92957: Sandbox Escape and Remote Code Execution in vm2 via node: Prefix Policy Bypass

CVE-2026-92957: CVE-2026-92957: Sandbox Escape and Remote Code Execution in vm2 via node: Prefix Policy Bypass

Comments
3 min read
CVE-2026-92958: CVE-2026-92958: Built-in Module Denylist Bypass via fs/promises in vm2 NodeVM Subsystem

CVE-2026-92958: CVE-2026-92958: Built-in Module Denylist Bypass via fs/promises in vm2 NodeVM Subsystem

Comments
2 min read
CVE-2026-92951: CVE-2026-92951: Sandbox Escape via External Package Allowlist Bypass in vm2

CVE-2026-92951: CVE-2026-92951: Sandbox Escape via External Package Allowlist Bypass in vm2

Comments
2 min read
CVE-2026-92940: CVE-2026-92940: Host-Realm Credential Exposure and Socket Hijacking via globalAgent in vm2

CVE-2026-92940: CVE-2026-92940: Host-Realm Credential Exposure and Socket Hijacking via globalAgent in vm2

Comments
3 min read
CVE-2026-92950: CVE-2026-92950: Sandbox Escape Vulnerability in vm2 CLI

CVE-2026-92950: CVE-2026-92950: Sandbox Escape Vulnerability in vm2 CLI

Comments
2 min read
CVE-2026-92948: CVE-2026-92948: Sandbox Escape and Remote Code Execution in vm2 via node:test

CVE-2026-92948: CVE-2026-92948: Sandbox Escape and Remote Code Execution in vm2 via node:test

Comments
2 min read
CVE-2026-92952: CVE-2026-92952: Sandbox Escape and State Corruption in vm2 via Node.js-internal Symbol Leak

CVE-2026-92952: CVE-2026-92952: Sandbox Escape and State Corruption in vm2 via Node.js-internal Symbol Leak

Comments
2 min read
CVE-2026-73607: CVE-2026-73607: Missing Authorization in SiYuan /api/storage/getOutlineStorage Leads to Information Disclosure

CVE-2026-73607: CVE-2026-73607: Missing Authorization in SiYuan /api/storage/getOutlineStorage Leads to Information Disclosure

Comments
2 min read
CVE-2026-73609: CVE-2026-73609: Missing Authorization in SiYuan Note getBookmarkLabels Endpoint

CVE-2026-73609: CVE-2026-73609: Missing Authorization in SiYuan Note getBookmarkLabels Endpoint

Comments
2 min read
CVE-2026-76504: CVE-2026-76504: Unauthenticated Authentication Bypass in Cisco Catalyst SD-WAN Manager

CVE-2026-76504: CVE-2026-76504: Unauthenticated Authentication Bypass in Cisco Catalyst SD-WAN Manager

Comments
3 min read
CVE-2026-73606: CVE-2026-73606: Authorization Bypass and Information Disclosure in SiYuan /api/block/getRefIDs Endpoint

CVE-2026-73606: CVE-2026-73606: Authorization Bypass and Information Disclosure in SiYuan /api/block/getRefIDs Endpoint

Comments
2 min read
CVE-2026-73605: CVE-2026-73605: Path Traversal and File Existence Oracle via getUniqueFilename Endpoint in SiYuan

CVE-2026-73605: CVE-2026-73605: Path Traversal and File Existence Oracle via getUniqueFilename Endpoint in SiYuan

Comments
2 min read
CVE-2026-102990: CVE-2026-102990: Regular Expression Denial of Service in basic-ftp Directory Parsing

CVE-2026-102990: CVE-2026-102990: Regular Expression Denial of Service in basic-ftp Directory Parsing

Comments
2 min read
CVE-2026-102821: CVE-2026-102821: Unbounded Memory Exhaustion via CHANNEL_OPEN Flood in russh

CVE-2026-102821: CVE-2026-102821: Unbounded Memory Exhaustion via CHANNEL_OPEN Flood in russh

Comments
2 min read
CVE-2026-102820: CVE-2026-102820: Out-of-Bounds Read and Excessive Memory Allocation in russh pageant

CVE-2026-102820: CVE-2026-102820: Out-of-Bounds Read and Excessive Memory Allocation in russh pageant

Comments
2 min read
CVE-2026-84428: CVE-2026-84428: Schema Validation Bypass in Fastify Header Normalization

CVE-2026-84428: CVE-2026-84428: Schema Validation Bypass in Fastify Header Normalization

Comments
2 min read
CVE-2026-84469: CVE-2026-84469: Request Validation Bypass in Fastify via Loose Boolean Schema Evaluation

CVE-2026-84469: CVE-2026-84469: Request Validation Bypass in Fastify via Loose Boolean Schema Evaluation

Comments
2 min read
CVE-2026-76169: CVE-2026-76169: Authentication Bypass and Encapsulation Violation via Malformed URL Routing Fallback in Fastify

CVE-2026-76169: CVE-2026-76169: Authentication Bypass and Encapsulation Violation via Malformed URL Routing Fallback in Fastify

Comments
2 min read
CVE-2026-84504: CVE-2026-84504: Schema Validation Bypass via Async Validation Result Collision in Fastify

CVE-2026-84504: CVE-2026-84504: Schema Validation Bypass via Async Validation Result Collision in Fastify

Comments
2 min read
CVE-2026-93981: CVE-2026-93981: Cross-Site Scripting via Unescaped SSR Pathways in Hono JSX Engine

CVE-2026-93981: CVE-2026-93981: Cross-Site Scripting via Unescaped SSR Pathways in Hono JSX Engine

Comments
2 min read
GHSA-59CR-6R3X-644W: GHSA-59CR-6R3X-644W: GitPython Submodule Update Path Traversal Can Write Outside the Repository

GHSA-59CR-6R3X-644W: GHSA-59CR-6R3X-644W: GitPython Submodule Update Path Traversal Can Write Outside the Repository

Comments
2 min read
GHSA-C2M8-H5V5-343R: GHSA-C2M8-H5V5-343R: Path Traversal via Improper Link Resolution in Tornado StaticFileHandler

GHSA-C2M8-H5V5-343R: GHSA-C2M8-H5V5-343R: Path Traversal via Improper Link Resolution in Tornado StaticFileHandler

Comments
2 min read
GHSA-CHX6-46F5-W4VP: GHSA-CHX6-46F5-W4VP: Uncontrolled Resource Consumption in Tornado CurlAsyncHTTPClient

GHSA-CHX6-46F5-W4VP: GHSA-CHX6-46F5-W4VP: Uncontrolled Resource Consumption in Tornado CurlAsyncHTTPClient

Comments
2 min read
GHSA-3HV7-MJH2-FV65: GHSA-3HV7-MJH2-FV65: Unbounded Query-String Parsing Denial of Service in Tornado Web Server

GHSA-3HV7-MJH2-FV65: GHSA-3HV7-MJH2-FV65: Unbounded Query-String Parsing Denial of Service in Tornado Web Server

Comments
2 min read
CVE-2026-103001: CVE-2026-103001: State Pollution in PyJWT Option Merging Leads to Claim Verification Bypass

CVE-2026-103001: CVE-2026-103001: State Pollution in PyJWT Option Merging Leads to Claim Verification Bypass

Comments
3 min read
CVE-2026-92081: CVE-2026-92081: Denial of Service via Uncaught Exception on HTTP/2 Response Trailers in Fastify

CVE-2026-92081: CVE-2026-92081: Denial of Service via Uncaught Exception on HTTP/2 Response Trailers in Fastify

Comments
2 min read
CVE-2026-102938: CVE-2026-102938: Configuration Injection and Local Execution Hijack in virtualenv

CVE-2026-102938: CVE-2026-102938: Configuration Injection and Local Execution Hijack in virtualenv

Comments
2 min read
CVE-2026-102930: CVE-2026-102930: Remote Code Execution via Unverified Dynamic Wheel Downloads in virtualenv

CVE-2026-102930: CVE-2026-102930: Remote Code Execution via Unverified Dynamic Wheel Downloads in virtualenv

Comments
2 min read
GHSA-3Q6V-R5MR-HXV8: GHSA-3Q6V-R5MR-HXV8: Algorithmic Complexity Denial of Service in league/commonmark GFM Table Extension

GHSA-3Q6V-R5MR-HXV8: GHSA-3Q6V-R5MR-HXV8: Algorithmic Complexity Denial of Service in league/commonmark GFM Table Extension

Comments
2 min read
loading...