6.5

CVSS3.1

CVE-2026-3114 - Zip Bomb Denial of Service via Unrestricted Archive Decompression

Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to validate decompressed archive entry sizes during file extraction which allows authenticated users with file upload permissions to cause a denial of service via crafted zip archives containing highlโ€ฆ

๐Ÿ“… Published: March 26, 2026, 4:21 p.m. ๐Ÿ”„ Last Modified: March 30, 2026, 8:57 p.m.

7

CVSS3.1

CVE-2026-26074 - EVerest: OCPP201 startup event_queue lock mismatch leads to std::map/std::queue data race

EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to possible `std::map<std::queue>` corruption. The trigger is CSMS GetLog/UpdateFirmware request (network) with an EVSE fault event (physical). This results in TSAN reports concurrent access (data race) tโ€ฆ

๐Ÿ“… Published: March 26, 2026, 4:19 p.m. ๐Ÿ”„ Last Modified: March 31, 2026, 8:08 p.m.

4.9

CVSS3.1

CVE-2026-3116 - Improper Input Validation in Zoom Plugin Webhook Handler

Mattermost Plugins versions <=11.4 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to validate incoming request size which allows an authenticated attacker to cause service disruption via the webhook endpoint. Mattermost Advisory ID: MMSA-2026-00589

๐Ÿ“… Published: March 26, 2026, 4:19 p.m. ๐Ÿ”„ Last Modified: March 30, 2026, 1:26 p.m.

5

CVSS3.1

CVE-2026-3113 - mmctl export download command doesnโ€™t restrict permissions to created file to file owner

Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to set permissions on downloaded bulk export which allows other local users on the server to be able to read contents of the bulk export.. Mattermost Advisory ID: MMSA-2026-00593

๐Ÿ“… Published: March 26, 2026, 4:18 p.m. ๐Ÿ”„ Last Modified: March 30, 2026, 8:57 p.m.

8

CVSS3.1

CVE-2026-3108 - Terminal Escape Injection in mmctl Report Posts Command

Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to sanitize user-controlled post content in the mmctl commands terminal output which allows attackers to manipulate administrator terminals via crafted messages containing ANSI and OSC escape sequenceโ€ฆ

๐Ÿ“… Published: March 26, 2026, 4:16 p.m. ๐Ÿ”„ Last Modified: March 31, 2026, 8:08 p.m.

7.5

CVSS3.1

CVE-2026-4867 - path-to-regexp vulnerable to Regular Expression Denial of Service via multiple route parameters

Impact: A bad regular expression is generated any time you have three or more parameters within a single segment, separated by something that is not a period (.). For example, /:a-:b-:c or /:a-:b-:c-:d. The backtrack protection added in [email protected] only prevents ambiguity for two parametโ€ฆ

๐Ÿ“… Published: March 26, 2026, 4:16 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 6:01 p.m.

5.9

CVSS3.1

CVE-2026-26073 - EVerest: OCPP 1.6 heap corruption caused by lock-free insertion in event_queue

EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to possible `std::queue`/`std::deque` corruption. The trigger is powermeter public key update and EV session/error events (while OCPP not started). This results in a TSAN data race report and an ASAN/UBSAโ€ฆ

๐Ÿ“… Published: March 26, 2026, 4:15 p.m. ๐Ÿ”„ Last Modified: March 31, 2026, 8:08 p.m.

4.2

CVSS3.1

CVE-2026-26072 - EVerest has race-condition-induced std::map corruption in OCPP 1.6 evse_soc_map

EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to `std::map<std::optional>` concurrent access (container/optional corruption possible). The trigger is EV SoC update with powermeter periodic update and unplugging/SessionFinished status. Version 2026.02โ€ฆ

๐Ÿ“… Published: March 26, 2026, 2:50 p.m. ๐Ÿ”„ Last Modified: March 31, 2026, 8:08 p.m.

4.2

CVSS3.1

CVE-2026-26071 - EVerest: OCPP 2.0.1 EVCCID Data Race Leads to Heap Useโ€‘Afterโ€‘Free

EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to `std::string` concurrent access. with heap-use-after-free possible. This is triggered by EVCCID update (EV/ISO15118) and OCPP session/authorization events. Version 2026.02.0 contains a patch.

๐Ÿ“… Published: March 26, 2026, 2:48 p.m. ๐Ÿ”„ Last Modified: March 31, 2026, 8:08 p.m.

4.6

CVSS3.1

CVE-2026-26070 - EVerest: OCPP 2.0.1 EV SoC Update Race Causes Charge Point Crash

EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to `std::map<std::optional>` concurrent access (container/optional corruption possible). The trigger is an EV SoC update with powermeter periodic update and unplugging/SessionFinished state. Version 2026.โ€ฆ

๐Ÿ“… Published: March 26, 2026, 2:45 p.m. ๐Ÿ”„ Last Modified: March 31, 2026, 8:09 p.m.
Total resulsts: 349182
Page 856 of 34,919
ยซ previous page ยป next page
Filters