By severity

Low-severity vulnerabilities

CVEs rated Low by CVSS, with SEC.co remediation and prioritization guidance.

385 published vulnerabilities · page 1 of 4

  • CVE-2026-12386LOW 3.9

    CVE-2026-12386 is a low-severity buffer overflow vulnerability in Pardus Pen, a software tool from Turkey's TUBITAK BILGEM Research Institute. The flaw stems from improper null termination handling in the application, which can allow a local attacker with user privileges to cause a buffer overflow. An attacker would need interactive access and user-level permissions to exploit this issue, limiting its real-world impact to environments where such access is already granted. The vulnerability affects Pardus Pen versions up to and including 4.1.5, with a fix available in version 4.2.1 and later.

  • CVE-2026-15028LOW 3.9

    A security flaw in libarchive allows an attacker to cause a heap overflow by crafting a specially designed tar archive file. The vulnerability exists in how the library handles PAX extended headers, specifically a malformed SUN.holesdata attribute used for sparse files. When a victim opens such a file, it can crash the system (denial of service) or potentially allow the attacker to execute arbitrary code. However, the vulnerability requires local access and user interaction, which limits its immediate threat scope.

  • CVE-2026-30963LOW 3.9

    Capsule is a Kubernetes framework that uses webhooks to prevent tenant administrators from hijacking namespaces—essentially taking control of cluster resources they shouldn't own. The framework checks most update requests, but it misses two specific APIs (namespace/status and namespace/finalize subresources) that can also change namespace ownership markers. Before version 0.13.0, a tenant admin with permission to use these subresources could bypass the webhook protection and seize a namespace. Version 0.13.0 patches this gap by ensuring the webhook intercepts both subresource types.

  • CVE-2026-45642LOW 3.9

    CVE-2026-45642 affects Microsoft's Azure Attestation and Device Health Attestation services, which are used to verify the integrity and trustworthiness of devices and systems. The vulnerability stems from inadequate validation of user-supplied input, allowing an attacker who already has physical access and elevated privileges on a target system to spoof attestation results. This means an attacker could make a compromised or malicious device appear legitimate to systems that rely on attestation checks. The attack requires both physical proximity to the device and administrative-level access, significantly limiting real-world exposure.

  • CVE-2026-55592LOW 3.9

    Dashy, a self-hosted dashboard application, contains a vulnerability in its workspace feature that allows attackers to inject malicious links. When a logged-in user clicks a specially crafted workspace link, it can execute JavaScript code within the user's browser session. This code runs with the same permissions as the Dashy application itself, potentially exposing sensitive data or allowing unauthorized actions. The vulnerability has been patched in version 4.3.7.

  • CVE-2025-12656LOW 3.8

    The WPvivid Backup & Migration plugin for WordPress contains a vulnerability that allows administrators to inadvertently (or maliciously) delete arbitrary directories from the server. The flaw lies in insufficient validation of file paths when canceling a staging site, meaning an authenticated admin could specify any folder path and have it removed. This is restricted to high-privilege accounts, but the impact—permanent data loss—is serious for affected organizations.

  • CVE-2026-0934LOW 3.8

    GitLab EE contains a flaw in how it enforces CI/CD visibility settings on protected environment configurations. An authenticated user with a custom role—even one granted limited permissions—can bypass CI/CD visibility controls to view, create, or delete protected environment settings that should be hidden from them. This affects specific version ranges and requires the attacker to already have some level of authentication and role assignment within the GitLab instance.

  • CVE-2026-10299LOW 3.8

    CVE-2026-10299 is a resource identifier control vulnerability in code-projects Online Hospital Management System version 1.0. An authenticated attacker with high-level privileges can manipulate the 'delid' parameter in the viewdoctortimings.php file to cause unintended modifications or deletion of data. While the flaw requires administrative or high-privilege access and carries a low CVSS score, the availability of public exploit code warrants attention in environments running this system.

  • CVE-2026-13322LOW 3.8

    A memory exhaustion vulnerability exists in KubeVirt's downward metrics virtio-serial server. When a guest VM has this device enabled, a local attacker can repeatedly write data without line breaks, forcing the virt-handler process to allocate unbounded memory until the process crashes. This requires prior VM access and affects deployments where the downward metrics feature is configured.

  • CVE-2026-15326LOW 3.8

    Halo (up to version 2.24.2) contains a path traversal vulnerability in its theme installation functionality. An authenticated administrator with high privileges can manipulate the theme metadata name parameter to write files outside the intended theme directory, potentially overwriting or placing malicious files in unexpected locations on the server. This requires administrative-level access to exploit and does not directly compromise confidentiality, but could lead to integrity and availability issues.

  • CVE-2026-40510LOW 3.8

    OpenSC, a widely-used open-source smart card library, contains a stack buffer overflow flaw in how it processes the Key History Object from PIV (Personal Identity Verification) cards. An attacker with physical access to a system could craft a malicious smart card or USB device that returns an oversized URL field—exceeding 118 bytes—triggering memory corruption. This vulnerability requires the attacker to be physically present at the machine and involves user interaction, limiting its reach but posing a real concern in environments where untrusted hardware may be connected.

  • CVE-2026-40528LOW 3.8

    OpenSC, a widely-used open-source library for working with smart cards and cryptographic tokens, contains a buffer overflow vulnerability in its profile configuration parser. When OpenSC's pkcs15-init tool processes a maliciously crafted configuration file, it can be tricked into copying more data than a buffer can hold, corrupting memory. An attacker would need local access to supply the malicious file and convince a user to run the initialization tool, but successful exploitation could allow memory corruption and potential code execution.

  • CVE-2026-42148LOW 3.8

    Coolify, a self-hosted platform for managing servers and applications, contains a command injection vulnerability in its development helper image build function. An attacker with administrative access who can modify the helper version setting and trigger a build can execute arbitrary commands on the underlying server. The vulnerability is limited to development environments and requires elevated privileges and user interaction, significantly constraining real-world impact. The issue was patched in version 4.0.0-beta.474.

  • CVE-2026-42546LOW 3.8

    OP-TEE, a security component that protects sensitive operations on Arm-based processors, contains a memory leak in its cleanup logic. When the system processes certain types of shared memory requests from the regular Linux kernel, it fails to properly release internal memory references. This causes memory to gradually accumulate and become unusable, eventually forcing the system to restart. The vulnerability only affects systems using non-FF-A configurations with non-contiguous shared memory support and requires local access to trigger.

  • CVE-2026-45683LOW 3.8

    OpenTelemetry eBPF Instrumentation versions prior to 0.9.0 contain a memory disclosure vulnerability in the Java TLS monitoring probe. The vulnerability stems from incorrect kernel memory access calls that allow a local attacker to read sensitive kernel memory and exfiltrate it through the instrumentation telemetry pipeline. This is a localized information disclosure risk that requires local process-level access to exploit.

  • CVE-2026-53763LOW 3.8

    OP-TEE, an open-source trusted execution environment for ARM processors, contains an integer overflow bug in its AES-GCM cryptographic implementation. When processing large amounts of encrypted data or authentication metadata—specifically over 512 megabytes—the flaw causes the authentication tag to be calculated incorrectly. This means encrypted messages could pass validation checks even if they were modified or corrupted in transit. The vulnerability affects all versions from 3.0.0 through 4.10.x; version 4.11.0 and later contain the fix.

  • CVE-2026-53809LOW 3.8

    OpenClaw versions prior to 2026.4.25 contain a policy bypass flaw that weakens access controls for bundled development tools. When an attacker has local access to a system running the embedded runner feature, they can use provider aliases (alternative names for tool repositories) to bypass intended restrictions on which tools they're allowed to use. The vulnerability is context-specific—it only affects configurations where this feature is explicitly enabled—but it does allow unauthorized tool selection outside policy boundaries.

  • CVE-2026-56212LOW 3.8

    Capgo versions before 12.128.2 contain a flaw in how they enforce two-factor authentication policies. A team or organization administrator can mandate that all team members use two-factor authentication, but the system doesn't check whether the administrator themselves has 2FA enabled first. This creates a gap where security policy enforcement becomes inconsistent and opens the door to administrative misuse—an admin could lock team members out of their accounts by enforcing a security requirement they haven't met themselves.

  • CVE-2026-59269LOW 3.8

    CVE-2026-59269 is a privilege escalation vulnerability in Pinniped's Kubernetes authentication system. An attacker with high privileges can manipulate Active Directory group names to trick the Pinniped Supervisor into granting elevated permissions in Kubernetes clusters. The attack requires several specific conditions to align: the supervisor must use Active Directory for authentication, group name filtering must be disabled, the attacker must be able to edit AD group records they belong to, and they must know a valid AD password. This is a narrow but real risk for organizations using Pinniped with misconfigured Active Directory integration.

  • CVE-2026-6816LOW 3.8

    Drupal's TFA Basic Plugins module contains a flaw that allows administrators with user management permissions to access or create recovery codes intended for other users. This bypasses the expected access controls around two-factor authentication recovery mechanisms. The vulnerability is restricted to versions 7.x-1.0 through 7.x-1.2, and exploitation requires administrative privileges, limiting its immediate threat to environments where admin accounts are already compromised or where trust boundaries have been violated.

  • CVE-2026-8074LOW 3.8

    Mattermost has a permission enforcement gap in its user status management API. A User Manager with write access to user management—but explicitly without access to manage integrations or bots—can deactivate bot accounts by directly calling the user active status endpoint. This should not be possible; the API should reject such requests from users lacking bot management permissions. The vulnerability affects Mattermost Server versions 11.7.0 and earlier in the 11.7.x branch, and 10.11.17 and earlier in the 10.11.x branch.

  • CVE-2026-8823LOW 3.8

    Mattermost has a permission validation flaw affecting versions 11.7.0 and 10.11.x up to 10.11.17. When an administrator with limited privileges attempts to demote a user to guest status, the system fails to properly verify whether the target is a bot account. This oversight allows a lower-privileged admin to degrade arbitrary bot accounts—including those managed by higher-privileged administrators—through the standard user demotion API. The impact is confined to integrity and availability concerns within the messaging platform.

  • CVE-2025-0824LOW 3.7

    Hitachi Virtual Storage Platform One Block storage systems lack proper validation controls during firmware updates. An authenticated user with local UI access could potentially apply a malicious or tampered firmware image, leading to integrity compromise or system unavailability. The vulnerability requires specific user interaction and elevated authentication, limiting immediate exposure but creating a meaningful risk in environments where firmware management is not strictly governed.

  • CVE-2025-52609LOW 3.7

    HCL iControl is missing HTTP security headers that would instruct modern web browsers to block cross-site scripting (XSS) attacks. Without these headers—such as Content-Security-Policy or X-XSS-Protection—the application relies on older browser XSS filters that are inconsistently implemented and increasingly deprecated. An attacker could craft malicious input that, when processed by iControl, gets reflected in responses without proper sanitization, potentially allowing script execution in users' browsers.

  • CVE-2026-10169LOW 3.7

    A weakness in the password recovery feature of OUSL-GROUP-BrinaryBrains School Student Management System allows an attacker to manipulate the email parameter in the forgot password function, potentially leading to unauthorized password resets or account takeover. The vulnerability exists in the Login.php controller's ajax_forgot_password endpoint. While exploitable remotely, the attack requires specific conditions and is considered of low severity. Exploit code is publicly available, increasing risk of opportunistic attacks.

  • CVE-2026-10216LOW 3.7

    A vulnerability has been discovered in unitedbyai droidclaw version 0.5.3 and earlier that weakens authentication security on the claim endpoint. The flaw allows attackers to bypass rate limiting or account lockout protections during login attempts, potentially enabling brute-force attacks to guess user credentials. While a public exploit exists, the attack requires specific conditions and technical skill to execute successfully. The vendor has been notified but has not yet released a fix.

  • CVE-2026-10300LOW 3.7

    SGLang version 0.5.10.post1 contains a vulnerability in its inference HTTP endpoint that can be triggered by manipulating the lora_path argument. When an attacker provides a specially crafted lora_path value, the system reaches an assertion condition that causes the service to become unavailable. This is a remote vulnerability requiring network access, though the attack is complex to execute and not trivial to exploit in practice.

  • CVE-2026-10636LOW 3.7

    Zephyr's IPv4 IGMP implementation contains a use-after-free vulnerability in its packet handling logic. After sending an IGMP message, the code attempts to read network interface information from a packet that may have already been freed and returned to memory pools by the network driver or stack. This can happen because the packet's last reference is released during transmission, but the code still tries to access it afterward. The issue is reachable by sending IGMP membership queries to the multicast address 224.0.0.1, or through local multicast operations, without requiring authentication. The practical result is typically unpredictable system behavior, potential crashes, or corruption of network statistics counters.

  • CVE-2026-10657LOW 3.7

    Zephyr's mDNS query handling contains a buffer over-read flaw in its DNS resolver. When checking whether a hostname ends with '.local', the code reads a fixed 7 bytes from the suffix position without verifying the string is long enough. Hostnames ending in shorter suffixes like .org, .com, .io, or a trailing dot cause the comparison to read past the string's null terminator into adjacent memory. On systems with strict memory boundaries (guard pages, memory-domain protections, or address sanitizers), this over-read triggers a crash, resulting in denial of service. The vulnerability only affects devices with mDNS resolver enabled and requires the ability to influence hostname input through configuration, parsed URLs, or application interfaces.

  • CVE-2026-11525LOW 3.7

    Undici, a Node.js HTTP client library, incorrectly parses the SameSite attribute in Set-Cookie headers. Instead of validating that the attribute is exactly 'Strict', 'Lax', or 'None' as the HTTP specification requires, undici accepts any value containing one of those words as a substring and silently converts it to the closest match. This means a server sending a malformed cookie like 'SameSite=NoneOfYourBusiness' will be treated as 'None'—the least restrictive setting—potentially weakening the security properties applications expect from SameSite enforcement.

  • CVE-2026-11555LOW 3.7

    A privilege escalation vulnerability exists in D-Link's DGS-1100-08PD switch running firmware version 1.00.006. The issue resides in how the web interface processes the /etc/boa.conf configuration file, potentially allowing an attacker to modify system settings in ways that bypass normal access restrictions. While a public exploit exists, successful exploitation requires significant technical skill and specific conditions to align. The impact is limited to integrity violations—an attacker cannot read sensitive data or crash the device, only make unauthorized configuration changes.

  • CVE-2026-11956LOW 3.7

    A flaw in TwiN gatus 5.36.0's OIDC session cookie handler can result in session cookies being created without the secure attribute. This means cookies could be transmitted over unencrypted HTTP connections, exposing them to interception. An attacker would need to manipulate the application's session management flow, a process requiring significant technical effort and complex conditions to exploit. While not currently listed on CISA's Known Exploited Vulnerabilities catalog, the issue warrants attention for any deployment handling sensitive authentication flows.

  • CVE-2026-12590LOW 3.7

    body-parser, a widely used Node.js middleware for parsing incoming request bodies, contains a flaw in how it validates the 'limit' configuration option. When administrators accidentally configure the limit parameter with an invalid value—such as an unparseable string or NaN—the parser silently fails to enforce size restrictions instead of raising an alarm. This means requests of any size will be accepted and processed, potentially consuming massive amounts of memory and CPU and causing the application to become unresponsive. The vulnerability affects versions before 1.20.6 (in the 1.x line) and before 2.3.0 (in the 2.x line).

  • CVE-2026-13482LOW 3.7

    SkyPilot, an open-source infrastructure orchestration tool, contains a cryptographic weakness in how it handles user identification. Specifically, the user ID encoding function in the User ID Handler uses an insufficiently strong hashing method. While the vulnerability requires specific conditions to exploit and carries low risk overall, the public availability of exploit details means organizations running affected versions should plan to upgrade.

  • CVE-2026-13490LOW 3.7

    A vulnerability in GLPI (Groupe Linux des Professionnels Informatiques), a popular open-source IT asset and helpdesk management system, allows an attacker to bypass authorization controls when viewing document files. By manipulating the document ID parameter in the document retrieval function, an unauthenticated attacker can potentially access files they should not be permitted to view. The issue affects versions 11.0.5, 11.0.6, and 11.0.7. While the attack is difficult to execute and requires specific conditions, it could expose sensitive documentation stored within GLPI instances.

  • CVE-2026-13491LOW 3.7

    A denial-of-service vulnerability exists in xiaozhi-esp32 versions up to 2.2.6 within the MQTT protocol handler. By manipulating the session_id parameter sent to the Application::GetInstance function, a remote attacker can trigger a crash or service interruption. While the vulnerability is now public and exploits exist, successful exploitation requires specific conditions and technical knowledge, making opportunistic attacks less likely. The vulnerability carries a CVSS 3.1 score of 3.7 (Low severity).

  • CVE-2026-13510LOW 3.7

    SimStudioAI's password protection mechanism in versions up to 0.6.92 uses weak cryptographic hashing, allowing attackers to potentially recover or manipulate password data. While the attack requires specific conditions and has high complexity, a public exploit exists, making this a meaningful concern for organizations using affected versions. The vulnerability affects confidentiality but not integrity or availability.

  • CVE-2026-13587LOW 3.7

    A heap-based buffer overflow vulnerability exists in PcapPlusPlus version 25.05, specifically in the LightPcapNg parser component. An attacker can manipulate a packet length parameter during parsing to trigger memory corruption on systems processing crafted pcapng files. While exploits are publicly available, the attack requires significant complexity and special conditions to execute successfully. The vulnerability carries a low CVSS severity rating due to limited direct impact potential.

  • CVE-2026-13758LOW 3.7

    CryptX is a Perl cryptography library that implements authenticated encryption (AEAD) modes for securing data. A timing vulnerability exists in how the library verifies authentication tags when decrypting data in streaming mode. Instead of using a constant-time comparison, the library's decrypt_done() function compares tags byte-by-byte in a way that leaks information through execution time—it returns faster when more bytes match. An attacker with precise timing measurements could exploit this to forge valid authenticated messages by testing candidate tags and observing which ones take longest to reject, effectively reading the correct tag one byte at a time. This affects GCM, CCM, ChaCha20Poly1305, EAX, and OCB modes, though the single-shot decryption functions remain unaffected.

  • CVE-2026-14738LOW 3.7

    A weakness in the vision feature caching mechanism of exo-explore (up to version 1.0.71) uses an insufficiently strong hashing algorithm to generate cache keys. This allows an attacker positioned on the network to potentially derive or predict cache identifiers, potentially exposing cached image data to unauthorized disclosure. The attack requires significant technical effort and specialized knowledge to execute, and no active exploitation in the wild has been widely documented, though proof-of-concept code has been published.

  • CVE-2026-14935LOW 3.7

    GStreamer's WebRTC component contains a logic bug that inverts a security check for DTLS certificate fingerprints in WebRTC signaling. Instead of requiring remote peers to provide a fingerprint attribute (and accepting only those with valid ones), the code does the opposite: it accepts offers without fingerprints while rejecting those that include them. An attacker positioned to intercept WebRTC setup traffic could exploit this to bypass certificate pinning protections, potentially enabling man-in-the-middle attacks on media streams even when both endpoints intended to use DTLS encryption.

  • CVE-2026-15041LOW 3.7

    389 Directory Server contains a timing-based information disclosure vulnerability in its PBKDF2-SHA256 password hashing implementation. Instead of using a constant-time comparison function, the server uses standard memcmp() to verify password hashes during LDAP authentication. While an attacker could theoretically measure minute timing differences across many bind attempts to extract partial hash information, the practical difficulty is extremely high due to PBKDF2's intentional computational overhead. This is a low-severity issue affecting authentication security rather than availability or integrity.

  • CVE-2026-24761LOW 3.7

    CVE-2026-24761 is an authorization flaw in Kiteworks Secure Data Forms that allows authenticated users to view metadata belonging to other users. Because the system doesn't properly verify who owns a resource before allowing access, a legitimate user can craft requests to retrieve information about files and documents they shouldn't see. The vulnerability requires an attacker to already have valid credentials and involves a higher complexity of exploitation, which limits its risk profile. This affects Kiteworks versions before 9.3.0.

  • CVE-2026-40011LOW 3.7

    CVE-2026-40011 is a low-severity vulnerability in which an attacker can send numerous crafted DNS queries to trigger the insertion of a malformed dynamic block. This results in invalid data being written to the Prometheus monitoring endpoint, causing the scraper to reject it until the block expires. The attack requires specific network conditions and does not enable data theft or system compromise, but does degrade visibility into system health during the attack window.

  • CVE-2026-40208LOW 3.7

    CVE-2026-40208 is a low-severity denial-of-service vulnerability affecting DNS over HTTPS version 3 (DoH3) implementations. An attacker can craft specially malformed DoH3 GET requests containing invalid DATA frames to slow down or temporarily disrupt query processing. The attack requires network access and specific conditions to be met, but does not compromise data confidentiality or integrity.

  • CVE-2026-41000LOW 3.7

    Spring Web Services has a flaw in how it manages replay protection for SOAP messages. When security administrators configure protection against replay attacks—where an attacker re-uses old, valid authentication tokens or timestamps—the system doesn't always enforce those protections correctly. An attacker could potentially replay old username tokens, timestamps, or certain SAML assertions to bypass authentication, even though the operator believed replay protection was active. This is a configuration gap: the replay cache exists but isn't consistently connected to the validation logic that needs it.

  • CVE-2026-41694LOW 3.7

    Spring Security's SAML module decrypts encrypted SAML messages without first verifying they contain a valid digital signature. An attacker can craft malicious SAML responses or logout messages, send them to a vulnerable application, and observe how the application behaves when decrypting attacker-controlled data. By analyzing these responses, an attacker could potentially extract encryption keys or other sensitive information that the application decrypts. This is a low-severity issue because exploitation requires specific conditions and yields limited information exposure.

  • CVE-2026-41848LOW 3.7

    Spring Framework's AntPathMatcher component is susceptible to a Regular Expression Denial of Service (ReDoS) attack. If an attacker can control or influence URL path patterns processed by the matcher, they can craft a malicious pattern that causes excessive CPU consumption, potentially degrading application performance or availability. This vulnerability affects multiple actively supported versions of Spring Framework spanning several release lines.

  • CVE-2026-41852LOW 3.7

    Spring Expression Language (SpEL) in VMware Spring Framework contains a flaw that allows attackers to invoke arbitrary methods with zero arguments even in contexts designed to restrict or prevent such actions. An attacker with network access could exploit this to trigger unintended application logic, potentially leading to denial of service or information disclosure depending on available methods and application design. This affects multiple versions across the 5.3, 6.1, 6.2, and 7.0 release branches.

  • CVE-2026-42004LOW 3.7

    DNSdist, a DNS load balancer and traffic filter, has a vulnerability where attackers can bypass its filtering rules by crafting a specially formed EDNS OPT record. The vulnerability exists because DNSdist ignores the malicious OPT record during its filtering checks, but then rewrites it as a valid OPT record when adding EDNS Client Subnet information. This rewritten record is then passed to backend DNS servers, which see options that DNSdist's filters never evaluated. An attacker would need specific network conditions to exploit this, and the impact is limited to information integrity—no confidentiality or availability risk.

  • CVE-2026-42768LOW 3.7

    OpenSSL's CMS and S/MIME decryption functions contain a flaw that allows attackers to exploit error messages or decryption output to gradually recover encrypted data or forge signatures. The vulnerability exists in two forms: when no recipient certificate is provided, an attacker can craft a message with multiple encryption layers to probe for valid padding patterns; when a certificate is provided but doesn't match, OpenSSL substitutes a random key, which an attacker can use to compare results and refine attacks. The practical risk is low because exploiting it requires the victim's application to expose detailed error codes or decryption results to an untrusted attacker, a scenario OpenSSL's developers consider very unlikely in real-world deployments.

  • CVE-2026-42770LOW 3.7

    A weakness in OpenSSL's handling of X9.42 Diffie-Hellman key exchanges allows a malicious peer to forge domain parameters in a way that bypasses security validation. Specifically, when checking that a peer's public key belongs to the correct mathematical subgroup, OpenSSL uses the peer's own parameters instead of verifying against the local key's parameters. An attacker can exploit this to gradually recover fragments of a victim's private key through repeated key exchange attempts, ultimately reconstructing the entire key via mathematical combination. However, the practical risk is limited to specific scenarios: principally Certificate Management Protocol (CMP) deployments where a Certification Authority or Registration Authority maintains long-lived X9.42 DHX keys, and custom enterprise or government applications using static DHX keys in interactive protocols.

  • CVE-2026-44042LOW 3.7

    UltraVNC Repeater versions up to 1.8.2.2 contain a boundary-checking flaw in the Base64 decoder used to process HTTP Basic authentication credentials. The vulnerability stems from an off-by-one error in the validation logic—the code checks whether decoded output will fit using a strict greater-than (>) comparison instead of greater-than-or-equal (>=). Under current HTTP request constraints, this does not cause exploitable overflow because the Authorization header size is naturally limited; however, the defective check creates a latent condition where a single byte could be written past the intended 1024-byte stack buffer boundary if buffering assumptions change. This is a low-severity finding with limited practical impact in current deployments.

  • CVE-2026-44489LOW 3.7

    Axios, a widely-used HTTP client library for JavaScript, contains a prototype pollution vulnerability in its configuration merging logic. When a developer uses Axios with a proxy configuration, an attacker can pollute the Object.prototype to inject fake username and password values. These polluted values are then automatically included in Proxy-Authorization headers sent with every proxied HTTP request, potentially leaking attacker-controlled credentials or disrupting authentication. The vulnerability affects Axios versions 1.15.2 through 1.15.x and is resolved in version 1.16.0.

  • CVE-2026-44546LOW 3.7

    Daphne, a popular ASGI server for Django applications, contains a header parsing vulnerability that allows attackers to inject additional HTTP headers into requests under specific conditions. The issue arises from a mismatch in how Daphne and the underlying WebSocket library (autobahn) interpret certain whitespace characters as line separators. By crafting requests with specific byte sequences in header values, an attacker can inject headers that the application receives, potentially leading to security bypasses depending on application logic. Daphne versions before 4.2.2 are affected. The vulnerability has a low CVSS score (3.7) and requires specific conditions to exploit, but organizations running affected versions should still apply the patch.

  • CVE-2026-44743LOW 3.7

    CVE-2026-44743 is a low-severity information disclosure vulnerability in SAP Business Objects that allows unauthorized attackers to leak sensitive data through a specific application endpoint. The vulnerability requires specific conditions to be exploitable and does not affect system integrity or availability—only the confidentiality of information is at risk.

  • CVE-2026-46584LOW 3.7

    Apache Camel's mail component has an input validation flaw that allows untrusted data to override email sending configuration. If a Camel route accepts input from external sources (like HTTP requests or message queues) and passes it directly to an SMTP/SMTPS producer without filtering, an attacker can inject malicious mail configuration headers. On older versions (before 4.19.0), this could redirect email traffic to attacker-controlled servers, exposing configured SMTP credentials. On newer versions, the attack is limited to weakening security settings or intercepting message content. The vulnerability only materializes in routes that lack proper input sanitization.

  • CVE-2026-48011LOW 3.7

    Shopware, a popular open-source e-commerce platform, contains a timing-based vulnerability that allows an attacker to discover the usernames of administrator accounts without authentication. By measuring response times during login attempts, an attacker can infer whether a given username belongs to an administrator by observing slight differences in how the system processes valid versus invalid accounts. This is a low-severity issue because it only leaks usernames—not passwords—and requires network access and careful measurement to exploit.

  • CVE-2026-48524LOW 3.7

    PyJWT, a widely-used Python library for handling JSON Web Tokens (JWTs), contains a weakness in how it fetches public signing keys. When a JWT arrives with an unfamiliar key identifier (kid), the library will make a fresh HTTP request to retrieve the correct signing key—without any protection against repeated requests for the same unknown identifier. An attacker can exploit this by sending JWTs with different fake kid values, forcing the library to make outbound requests for each one. While the actual impact depends on whether the signing-key endpoint has its own rate limiting or becomes saturated, the vulnerability allows an attacker to potentially cause a denial-of-service condition through request amplification. This issue is resolved in PyJWT 2.13.0 and later.

  • CVE-2026-48709LOW 3.7

    OliveTin is a web application that lets users execute predefined shell commands through a browser interface. Versions up to 3000.0.0 contain a flaw where one specific API endpoint (ValidateArgumentType) skips authentication checks that all other endpoints perform. When the application is configured to require login for guest users—a stricter security posture—this endpoint remains openly accessible to anyone on the network, allowing attackers to discover which shell commands are available and learn their argument requirements without needing credentials.

  • CVE-2026-48931LOW 3.7

    Node.js has a flaw in how its HTTP Agent handles client-server communication. The vulnerability allows a client to incorrectly accept a server response that arrives before the client has actually sent its request. While the window for exploitation is narrow and requires specific timing conditions, it represents a logic error in the HTTP protocol implementation that could lead to subtle application behavior issues. This affects the three currently supported Node.js release lines.

  • CVE-2026-53537LOW 3.7

    Python-Multipart before version 0.0.30 contains a header parsing vulnerability that could allow an attacker to bypass security controls. The library uses email message parsing for Content-Disposition and Content-Type headers, which automatically decodes RFC 2231/5987 extended parameter syntax (like filename*=). This decoding is not supposed to happen in multipart form data per the relevant RFC standard. An attacker can craft a specially formatted header that gets decoded differently by the vulnerable library than by upstream security tools (WAFs, proxies), potentially smuggling through a different field name or filename than inspectors expect. The risk is relatively low because successful exploitation requires specific conditions and produces only minor integrity issues, not data exposure or system unavailability.

  • CVE-2026-53538LOW 3.7

    Python-Multipart versions before 0.0.30 contain a parser differential vulnerability in how they handle form-encoded data. The library treats semicolons (;) as field separators in form submissions, while modern standards—including web browsers and Python's built-in URL parser—only recognize ampersands (&) as separators. An attacker can exploit this mismatch to inject additional form fields that bypass security inspections performed by upstream components, such as web application firewalls or input validators. The attacker doesn't need special privileges or user interaction, though the attack requires specific conditions to trigger successfully.

  • CVE-2026-53540LOW 3.7

    Python-Multipart, a streaming multipart parser library, contains a vulnerability in how it handles the Content-Length header when parsing form submissions. Before version 0.0.31, the parser fails to validate whether the Content-Length value is valid. An attacker who can send a request with a negative Content-Length header can force the parser to read the entire request body into memory at once, rather than processing it in manageable chunks. This memory exhaustion condition can cause the application to become unresponsive or crash.

  • CVE-2026-53607LOW 3.7

    ApostropheCMS contains a server-side request forgery (SSRF) vulnerability in its file-serving feature. When the 'prettyUrls' option is enabled—a legitimate SEO feature for cleaner file URLs—the system incorrectly trusts the HTTP Host header sent by clients. An attacker can exploit this to make the ApostropheCMS server fetch content from arbitrary hosts on your internal network, potentially revealing information about your network topology and any verbose error messages from internal systems. The vulnerability is present in ApostropheCMS versions 4.30.0 and earlier. While the attacker cannot directly steal file contents across different instances, they can perform network reconnaissance and potentially trigger information disclosure from misconfigured internal services.

  • CVE-2026-53837LOW 3.7

    OpenClaw versions before 2026.5.6 contain a flaw in how they handle Mattermost event processing that allows attackers to bypass direct message (DM) policy restrictions. The vulnerability exists because the application fails to properly check channel type metadata when processing incoming events. An attacker can craft malicious Mattermost events that omit channel type information, causing the application to incorrectly process content that should have been restricted. While the potential impact is limited, this represents an integrity issue that could allow policy circumvention.

  • CVE-2026-5419LOW 3.7

    A timing vulnerability has been discovered in GnuTLS, a widely-used encryption library. When the library decrypts data protected with PKCS#7 padding, the padding verification process takes different amounts of time depending on the content of the padding bytes. An attacker with network access could measure these timing differences to infer information about the padding, potentially revealing details about encrypted messages. This is a subtle flaw that requires precise network-level observation to exploit, making it a low-risk issue in most environments, but one that sophisticated attackers targeting high-value communications might attempt.

  • CVE-2026-54282LOW 3.7

    Starlette versions prior to 1.3.0 contain a flaw in how they reconstruct the request URL from incoming HTTP requests. When a malicious HTTP request contains a path that doesn't start with a forward slash (such as @google.com), the URL parsing logic gets confused about where the authority (hostname) section ends and treats attacker-supplied content as the hostname. Applications that trust the reconstructed request.url.hostname value instead of validating the actual Host header can be tricked into accepting requests as if they came from a different domain. An attacker could exploit this to bypass hostname-based access controls or mislead applications in authentication decisions.

  • CVE-2026-54696LOW 3.7

    Ruby JSON versions 2.9.0 through 2.19.8 contain a heap buffer overflow vulnerability in the JSON generator when handling streamed objects. If a JSON dump or generator operation receives a specially crafted object with an attacker-controlled string near 16 KB in size, the internal buffer can overflow, causing the application to crash. This is a denial-of-service issue that requires specific conditions to trigger but poses minimal impact to confidentiality or integrity. The vulnerability is fixed in version 2.19.9 and later.

  • CVE-2026-54780LOW 3.7

    CoreWCF, a .NET Core implementation of Windows Communication Foundation, has a flaw in how it validates cryptographic signatures on incoming messages. Specifically, the library checks that the overall signature algorithm meets security standards but fails to validate the digest algorithms used for individual message components. This means an attacker could use a weak algorithm like SHA-1 to sign parts of a message, and CoreWCF would still accept it as valid. The risk is limited—the attacker cannot decrypt messages or cause service outages—but they could potentially tamper with message contents in ways that go undetected. Versions 1.8.1 and 1.9.1 and later close this gap.

  • CVE-2026-54891LOW 3.7

    Erlang/OTP's TLS implementation has a flaw in how it validates incoming messages during the connection handshake. When acting as a TLS client, the ssl module fails to reject plaintext data that arrives before the handshake completes. An attacker positioned on the network can send fake, unencrypted messages to the client during setup. These messages are queued and then delivered to the application after the handshake finishes, making the application believe the attacker's data is legitimate server communication. The attacker cannot see responses or control the connection, so the threat is limited to injecting blind, unseen payloads. The vulnerability affects multiple OTP release series and is wider in scope for older TLS versions than for TLS 1.3.

  • CVE-2026-55654LOW 3.7

    OpenSSH has a flaw in how it cleans up authentication indicators when using GSSAPI (Kerberos-based authentication). The vulnerability is a heap memory read that goes out of bounds because the code expects a NULL terminator in an array that is missing. This causes the SSH daemon to crash when handling authentication in specific Kerberos environments, making the service temporarily unavailable. An attacker on the network can trigger this without authentication credentials, though it requires GSSAPI to be enabled and properly configured.

  • CVE-2026-56355LOW 3.7

    GNU Savannah Administration Savane versions through 3.17 contain a flaw where untrusted data is incorrectly used to make authorization decisions. This means an attacker could potentially bypass or manipulate access controls by providing specially crafted input that the system treats as legitimate authorization information. The vulnerability is rated LOW severity because exploitation requires specific conditions and the exposure is limited to information disclosure rather than system compromise or data modification.

  • CVE-2026-56365LOW 3.7

    ImageMagick versions before 7.1.2-19 contain a memory leak in their PNG encoder when processing MNG (Multiple-image Network Graphics) files. An attacker can craft a malicious MNG image that triggers a failure condition in the encoder, causing the application to leak memory repeatedly. If an ImageMagick instance processes many such images without restarting, available memory will eventually be exhausted, causing the service to become unresponsive or crash—a denial-of-service condition. This is a low-severity issue because it requires specific conditions to be met and does not allow unauthorized access or data compromise.

  • CVE-2026-56367LOW 3.7

    ImageMagick, a widely-used image processing library, contains an integer overflow vulnerability in its PSD (Photoshop) file parser. When processing a malformed PSB (large document) file, the RLE decompression routine can miscalculate buffer sizes, leading to out-of-bounds memory reads. This primarily affects 32-bit builds and can result in information disclosure (leaking nearby memory) or application crashes. The attack requires no user interaction and can be triggered remotely by sending a crafted PSB file.

  • CVE-2026-56368LOW 3.7

    ImageMagick versions before 7.1.2-15 contain a memory leak flaw in the image processing code that handles raw pixel data. When processing specially crafted images, the software fails to release memory properly, allowing attackers to exhaust available system memory and cause the application to become unresponsive or crash. This is a network-accessible denial-of-service vector that requires no authentication or user interaction to trigger.

  • CVE-2026-56369LOW 3.7

    ImageMagick before version 7.1.2-22 has a weakness in how it encrypts images using the PasskeyEncipherImage method. The vulnerability stems from reusing the same nonce (a number meant to be used only once) with AES-CTR encryption. When nonces are reused in stream ciphers like AES-CTR, attackers can mathematically recover the original unencrypted image data without knowing the encryption key. This is a cryptographic weakness rather than a traditional code execution flaw, but it completely undermines the confidentiality protection that encryption is supposed to provide.

  • CVE-2026-56373LOW 3.7

    ImageMagick versions before 7.1.2-15 have a memory handling defect in the PDB (Photoshop Document) decoder. When the decoder encounters memory allocation failures, it continues using a pointer that no longer points to valid memory. Attackers can craft malicious PDB files to trigger this condition, causing the application to crash or potentially write a single zero byte to freed memory regions.

  • CVE-2026-56376LOW 3.7

    ImageMagick versions before 7.1.2-15 and 6.9.13-40 contain a memory safety flaw in the meta coder component. When processing certain crafted image files, the application may attempt to write data to memory that has already been freed, especially when internal memory allocation fails. An attacker can exploit this by sending specially designed images to trigger the flaw remotely, causing the ImageMagick process to crash and denying service to legitimate users.

  • CVE-2026-56378LOW 3.7

    ImageMagick versions before 7.1.2-15 and 6.x before 6.9.13-40 contain a flaw in how they process PCD (Kodak Photo CD) image files. When a specially crafted PCD file is decoded, the application reads one byte beyond the allocated heap memory region. This can cause the application to crash (denial of service) or leak a single byte of nearby memory, which could potentially contain sensitive data. The vulnerability requires a user or system to open a malicious PCD file to trigger the issue.

  • CVE-2026-56968LOW 3.7

    GNU SASL, a library that handles authentication protocols, contains a vulnerability in how it processes NTLM authentication challenges from servers. An attacker who controls a malicious server could craft a specially designed challenge to trick the NTLM client into leaking small amounts of memory from the authenticating application. This is a low-severity issue that requires specific conditions to exploit and doesn't allow attackers to modify data or crash systems—only to read sensitive information that might be stored nearby in memory.

  • CVE-2026-57288LOW 3.7

    Jenkins Active Directory Plugin version 2.41.1 and earlier contains a flaw in how it processes usernames during Windows authentication. When a user logs in, the plugin builds a search query to find that user in Active Directory, but it doesn't properly sanitize the username first. This allows an attacker to insert special LDAP characters into the username field to either discover what users exist in your directory or to log in as someone else if they know that person's password—even without knowing the exact username. The vulnerability requires attackers to have network access to Jenkins and knowledge of at least one valid password, making it a limited but real risk.

  • CVE-2026-57946LOW 3.7

    Invidious, an open-source YouTube alternative, contains a flaw in how it controls access to private playlists. Before version 2.20260626.0, an attacker without any account or credentials can retrieve the contents of a private playlist—including video listings, the owner's email address, and other details—by directly requesting the RSS feed for that playlist. The vulnerability requires knowledge of a valid playlist ID but does not require authentication, making it a straightforward information disclosure risk for users with private playlists.

  • CVE-2026-60000LOW 3.7

    OpenSSH versions before 10.4 contain a flaw in how they handle the MaxAuthTries configuration setting when GSSAPI authentication is enabled. An unauthenticated attacker on the network can send a large number of authentication requests to consume server resources, potentially degrading SSH service availability. The vulnerability requires specific conditions (GSSAPI must be configured) and has limited impact, but represents a denial-of-service vector that should be addressed during normal patching cycles.

  • CVE-2026-6733LOW 3.7

    Undici, a popular HTTP client library for Node.js, contains a flaw that allows an attacker controlling an upstream web server to inject fake HTTP responses into a reused connection. When a client finishes one request and sends another over the same connection (a performance optimization called keep-alive), the injected response gets mixed up with the legitimate response from the new request. This causes the application to receive and process the wrong response data. The attack requires the attacker to already control or compromise the upstream server the client connects to.

  • CVE-2026-6976LOW 3.7

    GitLab has patched a vulnerability affecting versions 15.9 through 19.0.1 that allowed authenticated developers to manipulate file names in merge requests, potentially hiding code changes from reviewers. The issue requires a developer-level account and specific interaction steps, making it a low-severity concern primarily relevant to organizations where code review integrity is a priority or where insider risk is elevated.

  • CVE-2026-8651LOW 3.7

    Progress MOVEit Transfer contains a limited authentication bypass vulnerability in its HTTPS module that allows an attacker to spoof authentication under specific conditions. The vulnerability affects versions before 2025.0.7 and versions 2025.1.0 through 2025.1.2. While the impact is constrained—attackers can only achieve integrity manipulation rather than full system compromise—organizations running vulnerable versions should prioritize patching to prevent unauthorized modifications to transferred data.

  • CVE-2026-9143LOW 3.7

    CVE-2026-9143 is a numeric type conversion flaw in NI grpc-device that can silently truncate size values when they exceed the range of their target data type. The vulnerability stems from missing validation checks in the code generation layer. When a size value is too large for the target type, high bits are discarded without warning, potentially causing the service to operate on incorrect or undersized buffers. The issue affects NI grpc-device version 2.17.0 and earlier.

  • CVE-2026-10766LOW 3.6

    MLRun versions up to 1.12.0-rc3 contain a weakness in how they hash dataframes. The vulnerable function in mlrun/utils/helpers.py uses cryptographic methods that are considered inadequate for security purposes. An attacker with local access to a system running MLRun could potentially manipulate or forge data integrity checks, though doing so requires significant technical effort and local privileges. The vulnerability is not currently listed as actively exploited in the wild, but proof-of-concept details have been publicly disclosed.

  • CVE-2026-10775LOW 3.6

    CVE-2026-10775 is a denial-of-service vulnerability in SGLang's cache handling mechanism. An attacker with local system access and user-level privileges can trigger a crash or service interruption by exploiting the data_hash function in the cache handler. The attack requires specific knowledge of the system's cache internals, making it moderately difficult to execute, though proof-of-concept code has been publicly disclosed.

  • CVE-2026-10800LOW 3.6

    PaddlePaddle FastDeploy versions up to 2.4.1 contain a weakness in how the MultimodalHasher component generates hashes for multimodal features. An attacker with local system access and user-level privileges could manipulate the hash_features function to use cryptographically weak hashing, potentially allowing them to forge or predict hash values. This is a low-severity issue that requires both local access and significant technical effort to exploit.

  • CVE-2026-10801LOW 3.6

    A weakness in how ModelScope's ms-swift library (versions up to 4.2.0) hashes cached PIL images creates a local integrity risk. An attacker with local system access and user-level privileges could manipulate image cache validation, potentially leading to cache poisoning or image substitution. The vulnerability requires significant technical effort to exploit and poses limited immediate threat in most environments, but should be addressed before deployment in sensitive workflows.

  • CVE-2026-10803LOW 3.6

    MLflow versions up to 3.10.0 contain a cryptographic weakness in the Dataset Digest Computation module. The vulnerability uses an insufficiently strong hash function for dataset digest operations, which could allow an attacker with local system access and user-level privileges to tamper with dataset integrity checks or trigger application errors. Exploitation requires significant technical effort and local presence on the affected machine.

  • CVE-2026-10804LOW 3.6

    Streamlit versions up to 1.53.0 contain a weak cryptographic hashing vulnerability in its palette handler component. An attacker with local system access and authenticated user privileges can manipulate the hashing function to produce predictable or non-unique hash values, potentially allowing them to bypass integrity checks or cause minor application disruptions. The attack is complex and requires deep knowledge of the affected code path, making opportunistic exploitation unlikely. However, the vulnerability is not currently tracked as an active threat on CISA's Known Exploited Vulnerabilities catalog.

  • CVE-2026-10812LOW 3.6

    GPTCache versions up to 0.1.44 contain a weakness in how it hashes image data used for cache key generation. An attacker with local access to a system running vulnerable GPTCache can manipulate image input parameters to exploit weak cryptographic hashing, potentially causing data integrity issues. The attack requires elevated complexity to execute and is not considered an immediate threat to most deployments, but organizations using GPTCache for image processing should monitor for patches.

  • CVE-2026-10813LOW 3.6

    LMCache versions up to 0.4.6 contain a cryptographic weakness in the KV Cache Handler component, specifically in how it converts hash values to integers. An attacker with local system access could manipulate this weak hash function to potentially compromise data integrity or availability. However, exploiting this requires significant technical complexity and local access privileges, limiting its practical risk in most environments.

  • CVE-2026-11329LOW 3.6

    CVE-2026-11329 is a low-severity weakness in ONNX MLIR's node cache handler that uses weak cryptographic hashing in the hash key generation function. The vulnerability requires local access and elevated privileges to exploit, making it a restricted-scope risk. An attacker with local user permissions could manipulate the hash mechanism to cause minor integrity issues or availability disruptions, but the attack is difficult to execute in practice and does not compromise confidentiality.

  • CVE-2026-11330LOW 3.6

    A cryptographic weakness has been discovered in thedotmack claude-mem versions up to 11.0.1. The Observation Content Hash Handler component uses an insufficiently strong hashing algorithm when processing observation data, which could allow a local attacker with user-level access to manipulate or forge content hashes under specific conditions. This is a localized vulnerability with limited practical exploitability but should be remediated in environments where hash integrity is critical.

  • CVE-2026-13746LOW 3.6

    Snowflake CLI versions before 3.19 contain a flaw where specially crafted command-line arguments can cause unintended SQL statements to execute against a user's Snowflake database. The vulnerability is limited to direct command-line input—an attacker cannot exploit it through project files, configuration repositories, or other indirect channels. Impact is confined to whatever database permissions the affected user already possesses. A fix is available in version 3.19, which requires manual installation.

  • CVE-2026-41974LOW 3.6

    CVE-2026-41974 is a permission control flaw in a service notification system that could be exploited to impact system availability. The vulnerability requires local access and user interaction to trigger, but does not require elevated privileges. The attack surface is confined to the notification subsystem, and successful exploitation would degrade service performance or cause temporary unavailability rather than expose sensitive data or grant unauthorized access.