7.5

CVSS3.1

CVE-2026-25949 - Traefik: TCP readTimeout bypass via STARTTLS on Postgres

Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.8, there is a potential vulnerability in Traefik managing STARTTLS requests. An unauthenticated client can bypass Traefik entrypoint respondingTimeouts.readTimeout by sending the 8-byte Postgres SSLRequest (STARTTLS) prelude and then …

📅 Published: Feb. 12, 2026, 8:01 p.m. 🔄 Last Modified: April 17, 2026, 8 p.m.

6.9

CVSS3.1

CVE-2026-25933 - Arduino App Lab has Improper Data Validation in Internal Terminal Interface

Arduino App Lab is a cross-platform IDE for developing Arduino Apps. Prior to 0.4.0, a vulnerability was identified in the Terminal component of the arduino-app-lab application. The issue stems from insufficient sanitization and validation of input data received from connected hardware devices, spe…

📅 Published: Feb. 12, 2026, 7:57 p.m. 🔄 Last Modified: April 17, 2026, 8 p.m.

7.1

CVSS4.0

CVE-2026-25768 - LavinMQ is missing vhost access control

LavinMQ is a high-performance message queue & streaming server. Before 2.6.6, an authenticated user could access metadata in the broker they should not have access to. This vulnerability is fixed in 2.6.6.

📅 Published: Feb. 12, 2026, 7:52 p.m. 🔄 Last Modified: April 18, 2026, 12:45 p.m.

8.6

CVSS4.0

CVE-2026-25767 - LavinMQ has incomplete shovel configuration validation

LavinMQ is a high-performance message queue & streaming server. Before 2.6.8, an authenticated user, with the “Policymaker” tag, could create shovels bypassing access controls. an authenticated user with the "Policymaker" management tag could exploit it to read messages from vhosts they are not aut…

📅 Published: Feb. 12, 2026, 7:49 p.m. 🔄 Last Modified: April 18, 2026, 12:45 p.m.

8.8

CVSS3.1

CVE-2026-25922 - authentik has a Signature Verification Bypass via SAML Assertion Wrapping

authentik is an open-source identity provider. Prior to 2025.8.6, 2025.10.4, and 2025.12.4, when using a SAML Source that has the option Verify Assertion Signature under Verification Certificate enabled and not Verify Response Signature, or does not have the Encryption Certificate setting under Adv…

📅 Published: Feb. 12, 2026, 7:38 p.m. 🔄 Last Modified: April 18, 2026, 12:45 p.m.

8.6

CVSS3.1

CVE-2026-25748 - authentik has a forward authentication bypass with broken cookie

authentik is an open-source identity provider. Prior to 2025.10.4 and 2025.12.4, with a malformed cookie it was possible to bypass authentication when using forward authentication in the authentik Proxy Provider when used in conjunction with Traefik or Caddy as reverse proxy. When a malicious cooki…

📅 Published: Feb. 12, 2026, 7:36 p.m. 🔄 Last Modified: April 17, 2026, 8:15 p.m.

9.1

CVSS3.1

CVE-2026-25227 - authentik affected by Remote Code Execution via Context Key Injection in PropertyMapping Test Endpo…

authentik is an open-source identity provider. From 2021.3.1 to before 2025.8.6, 2025.10.4, and 2025.12.4, when using delegated permissions, a User that has the permission Can view * Property Mapping or Can view Expression Policy is able to execute arbitrary code within the authentik server contain…

📅 Published: Feb. 12, 2026, 7:25 p.m. 🔄 Last Modified: April 18, 2026, 12:45 p.m.

8.9

CVSS4.0

CVE-2026-24895 - FrankenPHP affected by Path Confusion via Unicode casing in CGI path splitting allows execution of …

FrankenPHP is a modern application server for PHP. Prior to 1.11.2, FrankenPHP’s CGI path splitting logic improperly handles Unicode characters during case conversion. The logic computes the split index (for finding .php) on a lowercased copy of the request path but applies that byte index to the o…

📅 Published: Feb. 12, 2026, 7:16 p.m. 🔄 Last Modified: April 17, 2026, 8:15 p.m.

8.7

CVSS4.0

CVE-2026-24894 - FrankenPHP leaks session data between requests in worker mode

FrankenPHP is a modern application server for PHP. Prior to 1.11.2, when running FrankenPHP in worker mode, the $_SESSION superglobal is not correctly reset between requests. This allows a subsequent request processed by the same worker to access the $_SESSION data of the previous request (potentia…

📅 Published: Feb. 12, 2026, 7:12 p.m. 🔄 Last Modified: April 18, 2026, 6:15 p.m.

9.2

CVSS4.0

CVE-2026-24044 - ESS Community Helm Chart has a weak server key generation method

Element Server Suite Community Edition (ESS Community) deploys a Matrix stack using the provided Helm charts and Kubernetes distribution. The ESS Community Helm Chart secrets initialization hook (using matrix-tools container before 0.5.7) is using an insecure Matrix server key generation method, al…

📅 Published: Feb. 12, 2026, 7:06 p.m. 🔄 Last Modified: April 17, 2026, 8:15 p.m.
Total resulsts: 349182
Page 1656 of 34,919
« previous page » next page
Filters