8.2

CVSS3.1

CVE-2026-24843 - melange QEMU runner could write files outside workspace directory

melange allows users to build apk packages using declarative pipelines. In version 0.11.3 to before 0.40.3, an attacker who can influence the tar stream from a QEMU guest VM could write files outside the intended workspace directory on the host. The retrieveWorkspace function extracts tar entries w…

📅 Published: Feb. 4, 2026, 7:31 p.m. 🔄 Last Modified: April 17, 2026, 11:30 p.m.

6.5

CVSS3.1

CVE-2025-68699 - NanoMQ $share/ Subscription Validation and Forwarding Parsing Inconsistency: NULL Pointer Increment…

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In version 0.24.6, NanoMQ has a protocol parsing / forwarding inconsistency when handling shared subscriptions ($share/). A malformed SUBSCRIBE topic such as $share/ab (missing the second /) is not strictly validated during the s…

📅 Published: Feb. 4, 2026, 7:25 p.m. 🔄 Last Modified: Feb. 20, 2026, 9:20 p.m.

7.5

CVSS3.1

CVE-2026-23897 - Apollo Server is vulnerable to denial of service with `startStandaloneServer`

Apollo Server is an open-source, spec-compliant GraphQL server that's compatible with any GraphQL client, including Apollo Client. In versions from 2.0.0 to 3.13.0, 4.2.0 to before 4.13.0, and 5.0.0 to before 5.4.0, the default configuration of startStandaloneServer from @apollo/server/standalone i…

📅 Published: Feb. 4, 2026, 7:18 p.m. 🔄 Last Modified: April 17, 2026, 11:30 p.m.

7.5

CVSS3.1

CVE-2026-25140 - apko affected by potential unbounded resource consumption in expandapk.ExpandApk on attacker-contro…

apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.1, an attacker who controls or compromises an APK repository used by apko could cause resource exhaustion on the build host. The ExpandApk function in pkg/apk/expandapk/expandapk.g…

📅 Published: Feb. 4, 2026, 7:02 p.m. 🔄 Last Modified: April 17, 2026, 11:30 p.m.

7.5

CVSS3.1

CVE-2026-25121 - apko is vulnerable to path traversal in apko dirFS which allows filesystem writes outside base

apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.1, a path traversal vulnerability was discovered in apko's dirFS filesystem abstraction. An attacker who can supply a malicious APK package (e.g., via a compromised or typosquatted…

📅 Published: Feb. 4, 2026, 7:02 p.m. 🔄 Last Modified: April 17, 2026, 11:30 p.m.

5.5

CVSS3.1

CVE-2026-25122 - apko is vulnerable to unbounded resource consumption in expandapk.Split on attacker-controlled .apk…

apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.0, expandapk.Split drains the first gzip stream of an APK archive via io.Copy(io.Discard, gzi) without explicit bounds. With an attacker-controlled input stream, this can force lar…

📅 Published: Feb. 4, 2026, 7:02 p.m. 🔄 Last Modified: April 17, 2026, 11:30 p.m.

7.8

CVSS3.1

CVE-2026-0536 - GIF File Parsing Stack Based Buffer Overflow

A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

📅 Published: Feb. 4, 2026, 6:12 p.m. 🔄 Last Modified: April 18, 2026, 2 p.m.

6.3

CVSS3.1

CVE-2026-25508 - ESF-IDF Has Memory Safety Vulnerabilities in BLE Provisioning

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.2, 5.4.3, 5.3.4, 5.2.6, and 5.1.6, an out-of-bounds read vulnerability was reported in the BLE ATT Prepare Write handling of the BLE provisioning transport (protocomm_ble). The issue can be triggered by a remot…

📅 Published: Feb. 4, 2026, 5:58 p.m. 🔄 Last Modified: April 17, 2026, 11:30 p.m.

6.3

CVSS3.1

CVE-2026-25507 - ESF-IDF Has Use-after-free Vulnerability in BLE Provisioning

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.2, 5.4.3, 5.3.4, 5.2.6, and 5.1.6, a use-after-free vulnerability was reported in the BLE provisioning transport (protocomm_ble) layer. The issue can be triggered by a remote BLE client while the device is in p…

📅 Published: Feb. 4, 2026, 5:58 p.m. 🔄 Last Modified: April 17, 2026, 11:30 p.m.

6.3

CVSS3.1

CVE-2026-25532 - ESF-IDF is Vulnerable to WPS Enrollee Fragment Integer Underflow

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.2, 5.4.3, 5.3.4, 5.2.6, and 5.1.6, a vulnerability exists in the WPS (Wi-Fi Protected Setup) Enrollee implementation where malformed EAP-WSC packets with truncated payloads can cause integer underflow during fr…

📅 Published: Feb. 4, 2026, 5:58 p.m. 🔄 Last Modified: April 18, 2026, 2 p.m.
Total resulsts: 349182
Page 1801 of 34,919
« previous page » next page
Filters