5.3

CVSS3.1

CVE-2026-39886 - OpenEXR has HTJ2K Signed Integer Overflow in ht_undo_impl()

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. Versions 3.4.0 through 3.4.9 have a signed integer overflow vulnerability in OpenEXR's HTJ2K (High-Throughput JPEG 2000) decompression path. The `ht_undo_…

πŸ“… Published: April 21, 2026, 1:27 a.m. πŸ”„ Last Modified: April 22, 2026, 6:41 p.m.

7.4

CVSS4.0

CVE-2026-39866 - Lawnchair vulnerable to Command Injection via unquoted workflow dispatch input in release_update.yml

Lawnchair is a free, open-source home app for Android. Prior to commit fcba413f55dd47f8a3921445252849126c6266b2, command injection in release_update.yml workflow dispatch input allows arbitrary code execution. Commit fcba413f55dd47f8a3921445252849126c6266b2 patches the issue.

πŸ“… Published: April 21, 2026, 1:19 a.m. πŸ”„ Last Modified: April 25, 2026, 3:55 a.m.

7.7

CVSS4.0

CVE-2026-39861 - Claude Code: Sandbox Escape via Symlink Following Allows Arbitrary File Write Outside Workspace

Claude Code is an agentic coding tool. Prior to version 2.1.64, Claude Code's sandbox did not prevent sandboxed processes from creating symlinks pointing to locations outside the workspace. When Claude Code subsequently wrote to a path within such a symlink, its unsandboxed process followed the sym…

πŸ“… Published: April 21, 2026, 12:56 a.m. πŸ”„ Last Modified: April 23, 2026, 6:36 p.m.

8.8

CVSS3.1

CVE-2026-39386 - Neko has Self-service Privilege Escalation for Authenticated Users

Neko is a a self-hosted virtual browser that runs in Docker and uses WebRTC In versions 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1, any authenticated user can immediately obtain full administrative control of the entire Neko instance (member management, room settings, broadcast control, session t…

πŸ“… Published: April 21, 2026, 12:50 a.m. πŸ”„ Last Modified: April 23, 2026, 6:21 p.m.

2

CVSS4.0

CVE-2026-40264 - OpenBao's Token Store Allows Cross-Namespace Renewal, Revocation

OpenBao is an open source identity-based secrets management system. OpenBao's namespaces provide multi-tenant separation. Prior to version 2.5.3, a tenant who leaks token accessors can have their token revoked or renewed by a privileged administrator in another tenant. This is addressed in v2.5.3.

πŸ“… Published: April 21, 2026, 12:47 a.m. πŸ”„ Last Modified: April 24, 2026, 1:29 p.m.

3.1

CVSS3.1

CVE-2026-39396 - OpenBao has Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, `ExtractPluginFromImage()` in OpenBao's OCI plugin downloader extracts a plugin binary from a container image by streaming decompressed tar data via `io.Copy` with no upper bound on the number of bytes writt…

πŸ“… Published: April 21, 2026, 12:44 a.m. πŸ”„ Last Modified: April 21, 2026, 11:15 p.m.

2

CVSS4.0

CVE-2026-39388 - OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, OpenBao's Certificate authentication method, when a token renewal is requested and `disable_binding=true` is set, attempts to verify the current request's presented mTLS certificate matches the original. Tok…

πŸ“… Published: April 21, 2026, 12:43 a.m. πŸ”„ Last Modified: April 24, 2026, 1:27 p.m.

4.6

CVSS4.0

CVE-2026-39946 - OpenBao allows SQL Injection in PostgreSQL database secrets engine

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, when OpenBao revoked privileges on a role in the PostgreSQL database secrets engine, OpenBao failed to use proper database quoting on schema names provided by PostgreSQL. This could lead to role revocation f…

πŸ“… Published: April 21, 2026, 12:19 a.m. πŸ”„ Last Modified: April 24, 2026, 1:28 p.m.

6.5

CVSS3.1

CVE-2026-39378 - nbconvert has an Arbitrary File Read via Path Traversal in HTMLExporter Image Embedding

The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. In versions 6.5 through 7.17.0, when `HTMLExporter.embed_images=True`, nbconvert's markdown renderer allows arbitrary file read via path traversal in image references. A malicious noteboo…

πŸ“… Published: April 21, 2026, 12:17 a.m. πŸ”„ Last Modified: April 23, 2026, 5:50 p.m.

6.5

CVSS3.1

CVE-2026-39377 - nbconvert has an Arbitrary File Write via Path Traversal in Cell Attachment Filenames

The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. Versions 6.5 through 7.17.0 allow arbitrary file writes to locations outside the intended output directory when processing notebooks containing crafted cell attachment filenames. The `Ext…

πŸ“… Published: April 21, 2026, 12:14 a.m. πŸ”„ Last Modified: April 23, 2026, 5:51 p.m.
Total resulsts: 346554
Page 114 of 34,656
Β« previous page Β» next page
Filters