8.4

CVSS4.0

CVE-2026-2836 - Cache poisoning via insecure-by-default cache key

A cache poisoning vulnerability has been found in the Pingora HTTP proxy frameworkโ€™s default cache key construction. The issue occurs because the default HTTP cache key implementation generates cache keys using only the URI path, excluding critical factors such as the host header (authority). Operaโ€ฆ

๐Ÿ“… Published: March 4, 2026, 11:44 p.m. ๐Ÿ”„ Last Modified: March 5, 2026, 9:05 a.m.

9.3

CVSS4.0

CVE-2026-2835 - HTTP Request Smuggling via HTTP/1.0 and Transfer-Encoding Misparsing

An HTTP Request Smuggling vulnerability (CWE-444) has been found in Pingora's parsing of HTTP/1.0 and Transfer-Encoding requests. The issue occurs due to improperly allowing HTTP/1.0 request bodies to be close-delimited and incorrect handling of multiple Transfer-Encoding values, allowing attackersโ€ฆ

๐Ÿ“… Published: March 4, 2026, 11:32 p.m. ๐Ÿ”„ Last Modified: March 5, 2026, 9:05 a.m.

5.3

CVSS4.0

CVE-2026-22052 -

ONTAP versions 9.12.1 and higher with S3 NAS buckets are susceptible to an information disclosure vulnerability. Successful exploit could allow an authenticated attacker to view a listing of the contents in a directory for which they lack permission.

๐Ÿ“… Published: March 4, 2026, 11:22 p.m. ๐Ÿ”„ Last Modified: March 5, 2026, 9:05 a.m.

9.3

CVSS4.0

CVE-2026-2833 - HTTP Request Smuggling via Premature Upgrade

An HTTP request smuggling vulnerability (CWE-444) was found in Pingora's handling of HTTP/1.1 connection upgrades. The issue occurs when a Pingora proxy reads a request containing an Upgrade header, causing the proxy to pass through the rest of the bytes on the connection to a backend before the baโ€ฆ

๐Ÿ“… Published: March 4, 2026, 11:20 p.m. ๐Ÿ”„ Last Modified: March 5, 2026, 9:05 a.m.

4.8

CVSS3.1

CVE-2025-41257 - Suprema BioStar 2 Insecure Password Change

Supremaโ€™s BioStar 2 in version 2.9.11.6 allows users to set new password without providing the current one. Exploiting this flaw combined with other vulnerabilities can lead to unauthorized account access and potential system compromise.

๐Ÿ“… Published: March 4, 2026, 10:43 p.m. ๐Ÿ”„ Last Modified: March 5, 2026, 9:05 a.m.

5.7

CVSS4.0

CVE-2026-2297 - SourcelessFileLoader does not use io.open_code()

The import hook in CPython that handles legacy *.pyc files (SourcelessFileLoader) is incorrectly handled in FileLoader (a base class) and so does not use io.open_code() to read the .pyc files. sys.audit handlers for this audit event therefore do not fire.

๐Ÿ“… Published: March 4, 2026, 10:10 p.m. ๐Ÿ”„ Last Modified: March 5, 2026, 9:05 a.m.

6.5

CVSS3.1

CVE-2026-29085 - Hono: SSE Control Field Injection via CR/LF in writeSSE()

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when using streamSSE() in Streaming Helper, the event, id, and retry fields were not validated for carriage return (\r) or newline (\n) characters. Because the SSE protocol uses line breakโ€ฆ

๐Ÿ“… Published: March 4, 2026, 10:09 p.m. ๐Ÿ”„ Last Modified: March 5, 2026, 9:05 a.m.

7.5

CVSS3.1

CVE-2026-29045 - Hono: Arbitrary file access via serveStatic vulnerability

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when using serveStatic together with route-based middleware protections (e.g. app.use('/admin/*', ...)), inconsistent URL decoding allowed protected static resources to be accessed withoutโ€ฆ

๐Ÿ“… Published: March 4, 2026, 10:09 p.m. ๐Ÿ”„ Last Modified: March 5, 2026, 9:05 a.m.

5.4

CVSS3.1

CVE-2026-29086 - Hono: Cookie Attribute Injection via Unsanitized domain and path in setCookie()

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, the setCookie() utility did not validate semicolons (;), carriage returns (\r), or newline characters (\n) in the domain and path options when constructing the Set-Cookie header. Because cโ€ฆ

๐Ÿ“… Published: March 4, 2026, 10:09 p.m. ๐Ÿ”„ Last Modified: March 5, 2026, 9:05 a.m.

6.3

CVSS4.0

CVE-2026-26002 - OnDemand susceptible to malicious input when navigating to a directory.

Open OnDemand is an open-source high-performance computing portal. The Files application in OnDemand versions prior to 4.0.9 and 4.1.3 is susceptible to malicious input when navigating to a directory. This has been patched in versions 4.0.9 and 4.1.3. Versions below this remain susceptible.

๐Ÿ“… Published: March 4, 2026, 10:05 p.m. ๐Ÿ”„ Last Modified: March 5, 2026, 9:05 a.m.
Total resulsts: 336097
Page 33 of 33,610
ยซ previous page ยป next page
Filters