Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-11525 Vulnerability in undici (CVE-2026-11525)
vulnerability in undici (CVE-2026-11525). Risk of unauthorized operations or information disclosure. Exploitable via ``SameSite``. Mitigation: upgrade to `8.5.0` or later.
UBUNTU-CVE-2026-11525 Vulnerability in node-undici (UBUNTU-CVE-2026-11525)
vulnerability in node-undici (UBUNTU-CVE-2026-11525). Risk of unauthorized operations or information disclosure. Exploitable via `Cookie header`.
UBUNTU-CVE-2026-39199 snes9x 1.63 allows an out-of-bounds write and denial of service via a crafted .ups file.
CVE-2026-55636 Authorization Flaw in github.com/projectcapsule/capsule (CVE-2026-55636)
vulnerability in github.com/projectcapsule/capsule (CVE-2026-55636). Data can be tampered with by attackers. Exploitable via ``rules.resources``. Mitigation: upgrade to `0.13.6` or later.
MAL-2026-6071 Vulnerability in n8n-nodes-security-test-poc (MAL-2026-6071)
vulnerability in n8n-nodes-security-test-poc (MAL-2026-6071). Risk of unauthorized operations or information disclosure.
CVE-2026-25779 Open Redirect in github.com/go-gitea/gitea (CVE-2026-25779)
vulnerability in github.com/go-gitea/gitea (CVE-2026-25779). Risk of unauthorized operations or information disclosure. Exploitable via `Referer header`. Mitigation: upgrade to `1.26.0` or later.
CVE-2026-28737 Cross-Site Scripting (XSS) in code.gitea.io/gitea (CVE-2026-28737)
cross-site scripting in code.gitea.io/gitea (CVE-2026-28737). Confidential information can be exposed externally. Exploitable via ``innerHTML``. Mitigation: upgrade to `1.26.0` or later.
CVE-2026-24791 Authorization Flaw in code.gitea.io/gitea (CVE-2026-24791)
vulnerability in code.gitea.io/gitea (CVE-2026-24791). Confidential information can be exposed externally. Exploitable via `GET /api/v1/users/{privateUser}`. Mitigation: upgrade to `1.26.2` or later.
CVE-2026-22555 Authorization Flaw in code.gitea.io/gitea (CVE-2026-22555)
vulnerability in code.gitea.io/gitea (CVE-2026-22555). Confidential information can be exposed externally. Exploitable via `POST /api/v1/repos/{owner}/{repo}/forks`. Mitigation: upgrade to `1.26.0` or later.
CVE-2026-54324 Vulnerability in github.com/daytonaio/daytona (CVE-2026-54324)
vulnerability in github.com/daytonaio/daytona (CVE-2026-54324). Confidential information can be exposed externally. Mitigation: upgrade to `0.185.0` or later.
CVE-2026-54316 Vulnerability in @anthropic-ai/claude-code (CVE-2026-54316)
vulnerability in @anthropic-ai/claude-code (CVE-2026-54316). Confidential information can be exposed externally. Mitigation: upgrade to `2.1.163` or later.
ROOT-APP-MAVEN-CVE-2025-37731 Vulnerability in io.root.org.elasticsearch:elasticsearch (ROOT-APP-MAVEN-CVE-2025-37731)
vulnerability in io.root.org.elasticsearch:elasticsearch (ROOT-APP-MAVEN-CVE-2025-37731). Confidential information can be exposed externally. Mitigation: upgrade to `9.1.3-root.io.1, 9.2.0-root.io.1, 9.1.3-root.io.2, 9.2.0-root.io.2, 9.1.3-root.io.3` or later.
ROOT-APP-MAVEN-CVE-2025-37727 Vulnerability in io.root.org.elasticsearch:elasticsearch (ROOT-APP-MAVEN-CVE-2025-37727)
vulnerability in io.root.org.elasticsearch:elasticsearch (ROOT-APP-MAVEN-CVE-2025-37727). Confidential information can be exposed externally. Mitigation: upgrade to `9.1.3-root.io.2, 9.1.3-root.io.3` or later.
CVE-2026-54022 Vulnerability in open-webui (CVE-2026-54022)
vulnerability in open-webui (CVE-2026-54022). Confidential information can be exposed externally. Exploitable via ``document_id``. Mitigation: upgrade to `0.8.11` or later.
RLSA-2026:26455 Vulnerability in 389-ds-base (RLSA-2026:26455)
vulnerability in 389-ds-base (RLSA-2026:26455). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0:2.8.0-7.el9_8` or later.
CVE-2026-54021 Authorization Flaw in open-webui (CVE-2026-54021)
vulnerability in open-webui (CVE-2026-54021). Risk of unauthorized operations or information disclosure. Exploitable via `POST /ollama/api/chat/{url_idx}`. Mitigation: upgrade to `>= 0.9.6` or later.
CVE-2026-54019 Vulnerability in open-webui (CVE-2026-54019)
vulnerability in open-webui (CVE-2026-54019). Confidential information can be exposed externally. Exploitable via `POST /api/v1/retrieval/query/collection`. Mitigation: upgrade to `0.9.6` or later.
ROOT-APP-MAVEN-CVE-2025-68390 Vulnerability in io.root.org.elasticsearch.plugin:x-pack-core (ROOT-APP-MAVEN-CVE-2025-68390)
vulnerability in io.root.org.elasticsearch.plugin:x-pack-core (ROOT-APP-MAVEN-CVE-2025-68390). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.2.0-root.io.1, 9.2.0-root.io.2, 9.1.3-root.io.1, 9.1.3-root.io.2, 9.2.0-root.io.3` or later.
CVE-2026-54018 SSRF (Server-Side Request Forgery) in open-webui (CVE-2026-54018)
SSRF in open-webui (CVE-2026-54018). Confidential information can be exposed externally. Mitigation: upgrade to `0.9.6` or later.
CVE-2026-54017 Path Traversal in open-webui (CVE-2026-54017)
path traversal in open-webui (CVE-2026-54017). Confidential information can be exposed externally. Exploitable via `GET /api/v1/terminals/server1/..`. Mitigation: upgrade to `0.9.6` or later.
ROOT-APP-MAVEN-GHSA-wjpw-4j6x-6rwh Vulnerability in io.root.org.eclipse.jetty:jetty-http (ROOT-APP-MAVEN-GHSA-wjpw-4j6x-6rwh)
vulnerability in io.root.org.eclipse.jetty:jetty-http (ROOT-APP-MAVEN-GHSA-wjpw-4j6x-6rwh). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `11.0.26-root.io.1, 11.0.26-root.io.2, 11.0.26-root.io.3` or later.
ROOT-APP-MAVEN-CVE-2024-27309 Vulnerability in io.root.org.apache.kafka:kafka-metadata (ROOT-APP-MAVEN-CVE-2024-27309)
vulnerability in io.root.org.apache.kafka:kafka-metadata (ROOT-APP-MAVEN-CVE-2024-27309). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.6.0-root.io.2, 3.6.0-root.io.3` or later.
CVE-2026-9675 Vulnerability in undici (CVE-2026-9675)
vulnerability in undici (CVE-2026-9675). Risk of unauthorized operations or information disclosure. Exploitable via ``maxPayloadSize``. Mitigation: upgrade to `8.5.0` or later.
UBUNTU-CVE-2026-9675 Vulnerability in node-undici (UBUNTU-CVE-2026-9675)
vulnerability in node-undici (UBUNTU-CVE-2026-9675). Risk of unauthorized operations or information disclosure.
CVE-2026-12151 Vulnerability in undici (CVE-2026-12151)
vulnerability in undici (CVE-2026-12151). Risk of unauthorized operations or information disclosure. Exploitable via ``maxPayloadSize``. Mitigation: upgrade to `8.5.0` or later.
UBUNTU-CVE-2026-12151 Vulnerability in node-undici (UBUNTU-CVE-2026-12151)
vulnerability in node-undici (UBUNTU-CVE-2026-12151). Risk of unauthorized operations or information disclosure.
MAL-2026-6065 Vulnerability in lab-services (MAL-2026-6065)
vulnerability in lab-services (MAL-2026-6065). Risk of unauthorized operations or information disclosure.
CGA-vhhh-3ggv-2x45 CGA-vhhh-3ggv-2x45
CGA-mxwc-vww2-3q6q CGA-mxwc-vww2-3q6q
GHSA-qcr2-hwcg-gf9g Vulnerability in swift-parse-stream (GHSA-qcr2-hwcg-gf9g)
vulnerability in swift-parse-stream (GHSA-qcr2-hwcg-gf9g). Risk of unauthorized operations or information disclosure. Exploitable via ``getPlugin``.
GHSA-8p89-7m4q-45qm Vulnerability in quirky-token (GHSA-8p89-7m4q-45qm)
vulnerability in quirky-token (GHSA-8p89-7m4q-45qm). Risk of unauthorized operations or information disclosure. Exploitable via ``model``.
openSUSE-SU-2026:21079-1 Vulnerability in amazon-ssm-agent (openSUSE-SU-2026:21079-1)
vulnerability in amazon-ssm-agent (openSUSE-SU-2026:21079-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.3.4624.0-160000.1.1` or later.
SUSE-SU-2026:22157-1 Vulnerability in amazon-ssm-agent (SUSE-SU-2026:22157-1)
vulnerability in amazon-ssm-agent (SUSE-SU-2026:22157-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.3.4624.0-160000.1.1` or later.
MINI-rjgp-hvfc-vvgm MINI-rjgp-hvfc-vvgm
MINI-9g3f-jm52-5vcc MINI-9g3f-jm52-5vcc
MINI-rg63-2xpq-3p2j MINI-rg63-2xpq-3p2j
MINI-5c25-v63v-42m8 MINI-5c25-v63v-42m8
MINI-fvcq-7xm6-xvx9 MINI-fvcq-7xm6-xvx9
MINI-jx2c-gf52-2pw6 MINI-jx2c-gf52-2pw6
MINI-7p69-f6m2-cc4r MINI-7p69-f6m2-cc4r
MINI-357x-mh56-h27j MINI-357x-mh56-h27j
MINI-p4w5-hp5r-gr3m MINI-p4w5-hp5r-gr3m
MINI-hr4w-3jv6-88hh MINI-hr4w-3jv6-88hh
MINI-hf8x-63c9-g428 MINI-hf8x-63c9-g428
MINI-g24w-7f5h-r52v MINI-g24w-7f5h-r52v
MINI-5w97-pcgf-v4jp MINI-5w97-pcgf-v4jp
MINI-5273-prf6-h7f2 MINI-5273-prf6-h7f2
MINI-j2xf-p2vr-gwfm MINI-j2xf-p2vr-gwfm
MINI-pr6r-6gjw-3xr9 MINI-pr6r-6gjw-3xr9
MINI-cmrx-jmrx-m2fg MINI-cmrx-jmrx-m2fg

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →