9.2

CVSS4.0

CVE-2026-40946 - Oxia: OIDC token audience validation bypass via SkipClientIDCheck

Oxia is a metadata store and coordination system. Prior to 0.16.2, the OIDC authentication provider unconditionally sets SkipClientIDCheck: true in the go-oidc verifier configuration, disabling the standard audience (aud) claim validation at the library level. This allows tokens issued for unrelate…

πŸ“… Published: April 21, 2026, 9:18 p.m. πŸ”„ Last Modified: April 22, 2026, 8:28 p.m.

8.7

CVSS4.0

CVE-2026-40945 - Oxia: Bearer token exposed in debug log messages on authentication failure

Oxia is a metadata store and coordination system. Prior to 0.16.2, when OIDC authentication fails, the full bearer token is logged at DEBUG level in plaintext. If debug logging is enabled in production, JWT tokens are exposed in application logs and any connected log aggregation system. This vulner…

πŸ“… Published: April 21, 2026, 9:16 p.m. πŸ”„ Last Modified: April 22, 2026, 8:28 p.m.

6.9

CVSS4.0

CVE-2026-40944 - Oxia: TLS CA certificate chain validation fails with multi-certificate PEM bundles

Oxia is a metadata store and coordination system. Prior to 0.16.2, the trustedCertPool() function in the TLS configuration only parses the first PEM block from CA certificate files. When a CA bundle contains multiple certificates (e.g., intermediate + root CA), only the first certificate is loaded.…

πŸ“… Published: April 21, 2026, 9:14 p.m. πŸ”„ Last Modified: April 22, 2026, 8:28 p.m.

8.7

CVSS4.0

CVE-2026-40943 - Oxia: Server crash via race condition in session heartbeat handling

Oxia is a metadata store and coordination system. Prior to 0.16.2, a race condition between session heartbeat processing and session closure can cause the server to panic with send on closed channel. The heartbeat() method uses a blocking channel send while holding a mutex, and under specific timin…

πŸ“… Published: April 21, 2026, 9:13 p.m. πŸ”„ Last Modified: April 22, 2026, 8:28 p.m.

5.3

CVSS4.0

CVE-2026-6829 - nesquena hermes-webui Arbitrary Workspace Directory Access

nesquena hermes-webui contains a trust-boundary failure vulnerability that allows authenticated attackers to set or change a session workspace to an arbitrary existing directory on disk by manipulating workspace path parameters in endpoints such as /api/session/new, /api/session/update, /api/chat/s…

πŸ“… Published: April 21, 2026, 9:09 p.m. πŸ”„ Last Modified: April 22, 2026, 12:18 p.m.

6.3

CVSS4.0

CVE-2026-40942 - DSF: Inverted Time Comparison in OIDC JWKS and Token Cache

The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Prior to 2.1.0, The OIDC JWKS and Metadata Document caches used an inverted time comparison (isBefore instead of isAfter), causing the cache to never return cached values. Every inc…

πŸ“… Published: April 21, 2026, 9:09 p.m. πŸ”„ Last Modified: April 22, 2026, 9:23 p.m.

6.8

CVSS4.0

CVE-2026-40939 - DSF: Missing Session Timeout for OIDC Sessions

The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Prior to 2.1.0, OIDC-authenticated sessions had no configured maximum inactivity timeout. Sessions persisted indefinitely after login, even after the OIDC access token expired. This…

πŸ“… Published: April 21, 2026, 9:07 p.m. πŸ”„ Last Modified: April 22, 2026, 9:23 p.m.

10

CVSS3.1

CVE-2026-40933 - Flowise: Authenticated RCE Via MCP Adapters

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, due to unsafe serialization of stdio commands in the MCP adapter, an authenticated attacker can add an MCP stdio server with an arbitrary command, achieving command execution. The vulnerability …

πŸ“… Published: April 21, 2026, 9 p.m. πŸ”„ Last Modified: April 23, 2026, 3:40 p.m.

5.3

CVSS4.0

CVE-2026-6799 - Comfast CF-N1-S Endpoint mbox-config command injection

A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is some unknown functionality of the file /cgi-bin/mbox-config?method=SET&section=ping_config of the component Endpoint. Performing a manipulation of the argument destination results in command injection. The att…

πŸ“… Published: April 21, 2026, 9 p.m. πŸ”„ Last Modified: April 22, 2026, 12:19 p.m.

8.4

CVSS3.1

CVE-2026-40931 - Complete Bypass of CVE-2026-24884 Patch via Git-Delivered Symlink Poisoning in compressing

Compressing is a compressing and uncompressing lib for node. Prior to 2.1.1 and 1.10.5, the patch for CVE-2026-24884 relies on a purely logical string validation within the isPathWithinParent utility. This check verifies if a resolved path string starts with the destination directory string but fai…

πŸ“… Published: April 21, 2026, 8:57 p.m. πŸ”„ Last Modified: April 23, 2026, 3:49 p.m.
Total resulsts: 346513
Page 83 of 34,652
Β« previous page Β» next page
Filters